Refactor Gitea production deployment process to utilize SSH for remote operations
Deploy production / deploy (push) Failing after 8s
Deploy production / deploy (push) Failing after 8s
- Updated deployment specification to reflect the new architecture involving servers A, B, and C. - Revised README to describe the new deployment method using Gitea Runner and SSH. - Modified `compose.production.yaml` to remove build context and use image tags directly. - Enhanced deployment documentation to clarify configuration steps and environment variable requirements. - Introduced `deploy-remote.sh` script for handling remote deployment tasks over SSH. - Added unit tests for deployment scripts to ensure robustness and error handling. - Updated `deploy-production.sh` to streamline image pulling and deployment processes.
This commit is contained in:
@@ -1,5 +1,17 @@
|
||||
# Gitea 生产部署
|
||||
|
||||
## 当前部署方式(2026-09-24)
|
||||
|
||||
本节替代下方历史记录中的同机构建部署方案。A 运行 Gitea/Packages,Runner 构建并推送两个提交标签镜像,通过 SSH 在 B 的独立发布目录执行 pull、预检、互斥迁移及健康检查;生产 Compose 不含 build。现有数据库、项目名、端口和 Gitea 应用配置沿用。
|
||||
|
||||
数据库独立部署在 C,B 的 backend 和 migrate 通过 `DATABASE_URL` 使用 C 的内网地址。生产 Compose 使用默认网络,移除 `DATABASE_NETWORK` 外部网络声明及工作流、部署脚本的传递和必填校验。
|
||||
|
||||
SSH 采用用户指定的 Gitea Secrets:`PROD_SSH_KEY`、`PROD_HOST`、`PROD_USER`,补充主机公钥校验 `PROD_KNOWN_HOSTS` 与可选端口 `PROD_PORT`。镜像前缀、B 部署目录和构建平台可配置。应用环境经 SSH stdin 传递,不生成应用凭据文件;SSH 和 Docker 认证临时目录结束时清理。
|
||||
|
||||
任务与验证见 [两机镜像部署](issues/01-remote-deployment.md)。本任务只修改本地文件及进行隔离验证,不推送镜像或操作真实 B。
|
||||
|
||||
## 历史方案
|
||||
|
||||
采用已选择的 compound 经验 1,经当前项目核验:复用锁定依赖的 Dockerfile、单 worker 和数据库健康接口;新增独立生产 Compose、外部 PostgreSQL 配置、同机 host Runner 工作流。生产凭据通过 Gitea Secrets 注入,非敏感配置通过 Variables 注入,不生成凭据文件。数据库网络为可配置参数,不沿用旧项目常量作为强制约定。
|
||||
|
||||
部署在构建完成后停止写入、执行一次性迁移,再启动健康检查。固定项目名与按提交标记镜像;使用宿主机文件锁串行化。保留本地和独立公网部署的现有行为。不执行远程部署、不修改知识库。
|
||||
|
||||
Reference in New Issue
Block a user