feat(ci/cd): Implement release-based deployment with two-workflow architecture
- Add prepare-release.yml: Manual release creation workflow * Builds code, generates appsettings.Production.json * Packages artifact (.tar.gz) * Creates git tag and Gitea Release with attached artifact - Refactor deploy-prod.yml: Release-based deployment workflow * Fetch Release stage: Query Gitea Releases, download artifact * Pre-Check stage: Verify SSH credentials and release integrity * Deploy stage: Upload, extract, symlink, restart service * Health Check stage: 5-point verification (HTTP, CSS, login, service, release) * Report stage: Final deployment status * Now triggered via workflow_dispatch with release version input * Removes on:push trigger (manual release selection required) - Update CLAUDE.md: * Document two-workflow architecture * Add release creation and deployment procedures * Update SSH key configuration with GITEA_TOKEN requirement * Clarify CI/CD-Only Deployment Mandate with release traceability * Add complete deployment flow documentation **Motivation**: - Separate build/release phase from deployment phase - Enable release tagging for version control and rollback - Reduce build time on re-deployments (use cached releases) - Improve deployment auditability via git tags and Gitea Releases - Match taxbaik-pattern release management strategy Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
+124
-104
@@ -1,9 +1,12 @@
|
||||
name: Deploy to Production
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ main ]
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
release:
|
||||
description: 'Release version to deploy (e.g., v0.1.20260711, or leave empty for latest)'
|
||||
required: false
|
||||
type: string
|
||||
|
||||
concurrency:
|
||||
group: deploy-prod-main
|
||||
@@ -14,104 +17,94 @@ env:
|
||||
DEPLOY_USER: kjh2064
|
||||
DEPLOY_PORT: 22
|
||||
SERVICE_NAME: quantengine
|
||||
DOTNET_VERSION: '10.0.x'
|
||||
REPO: kjh2064/QuantEngineByItz
|
||||
|
||||
jobs:
|
||||
build:
|
||||
name: Build Release
|
||||
fetch-release:
|
||||
name: Fetch Release Artifact
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 15
|
||||
timeout-minutes: 10
|
||||
outputs:
|
||||
artifact-name: ${{ steps.metadata.outputs.artifact }}
|
||||
commit-hash: ${{ steps.metadata.outputs.commit }}
|
||||
timestamp: ${{ steps.metadata.outputs.timestamp }}
|
||||
release-tag: ${{ steps.fetch.outputs.tag }}
|
||||
artifact-name: ${{ steps.fetch.outputs.artifact }}
|
||||
artifact-size: ${{ steps.fetch.outputs.size }}
|
||||
commit-hash: ${{ steps.fetch.outputs.commit }}
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Setup .NET
|
||||
uses: actions/setup-dotnet@v4
|
||||
with:
|
||||
dotnet-version: ${{ env.DOTNET_VERSION }}
|
||||
|
||||
- name: Generate Metadata
|
||||
id: metadata
|
||||
- name: Fetch Release Info
|
||||
id: fetch
|
||||
run: |
|
||||
COMMIT=$(git rev-parse --short HEAD)
|
||||
TIMESTAMP=$(TZ=UTC date +%Y%m%d_%H%M%S)
|
||||
ARTIFACT="quantengine_${TIMESTAMP}_${COMMIT}.tar.gz"
|
||||
RELEASE_INPUT="${{ github.event.inputs.release }}"
|
||||
TOKEN="${{ secrets.GITEA_TOKEN }}"
|
||||
REPO="${{ env.REPO }}"
|
||||
|
||||
if [ -z "$RELEASE_INPUT" ]; then
|
||||
# Fetch latest release
|
||||
RELEASE_URL="https://gitea.taxbaik.com/api/v1/repos/$REPO/releases/latest"
|
||||
else
|
||||
# Fetch specific release
|
||||
RELEASE_URL="https://gitea.taxbaik.com/api/v1/repos/$REPO/releases/tags/$RELEASE_INPUT"
|
||||
fi
|
||||
|
||||
RELEASE=$(curl -s -H "Authorization: token $TOKEN" "$RELEASE_URL")
|
||||
TAG=$(echo "$RELEASE" | jq -r '.tag_name')
|
||||
COMMIT=$(echo "$RELEASE" | jq -r '.target_commitish' | cut -c1-7)
|
||||
|
||||
if [ "$TAG" = "null" ] || [ -z "$TAG" ]; then
|
||||
echo "ERROR: Release not found"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Find artifact in assets
|
||||
ARTIFACT=$(echo "$RELEASE" | jq -r '.assets[0].name')
|
||||
SIZE=$(echo "$RELEASE" | jq -r '.assets[0].size')
|
||||
|
||||
if [ "$ARTIFACT" = "null" ] || [ -z "$ARTIFACT" ]; then
|
||||
echo "ERROR: No artifacts found in release $TAG"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "tag=${TAG}" >> $GITHUB_OUTPUT
|
||||
echo "artifact=${ARTIFACT}" >> $GITHUB_OUTPUT
|
||||
echo "size=${SIZE}" >> $GITHUB_OUTPUT
|
||||
echo "commit=${COMMIT}" >> $GITHUB_OUTPUT
|
||||
echo "timestamp=${TIMESTAMP}" >> $GITHUB_OUTPUT
|
||||
|
||||
- name: Restore
|
||||
echo "✓ Release: $TAG"
|
||||
echo "✓ Artifact: $ARTIFACT"
|
||||
echo "✓ Size: $SIZE bytes"
|
||||
|
||||
- name: Download Release Artifact
|
||||
run: |
|
||||
dotnet restore src/dotnet/QuantEngine.Web/QuantEngine.Web.csproj
|
||||
TAG="${{ steps.fetch.outputs.tag }}"
|
||||
ARTIFACT="${{ steps.fetch.outputs.artifact }}"
|
||||
TOKEN="${{ secrets.GITEA_TOKEN }}"
|
||||
REPO="${{ env.REPO }}"
|
||||
|
||||
- name: Build (Release)
|
||||
run: |
|
||||
dotnet build src/dotnet/QuantEngine.Web/QuantEngine.Web.csproj \
|
||||
-c Release \
|
||||
--no-restore \
|
||||
-p:ContinuousIntegrationBuild=true
|
||||
DOWNLOAD_URL="https://gitea.taxbaik.com/api/v1/repos/$REPO/releases/download/$TAG/$ARTIFACT"
|
||||
|
||||
- name: Publish
|
||||
run: |
|
||||
dotnet publish src/dotnet/QuantEngine.Web/QuantEngine.Web.csproj \
|
||||
-c Release \
|
||||
-o ./publish \
|
||||
--no-restore \
|
||||
--no-build
|
||||
echo "Downloading: $DOWNLOAD_URL"
|
||||
curl -L -H "Authorization: token $TOKEN" \
|
||||
-o "$ARTIFACT" \
|
||||
"$DOWNLOAD_URL"
|
||||
|
||||
- name: Write Production Config
|
||||
run: |
|
||||
mkdir -p ./publish
|
||||
DEPLOY_HOST="${{ secrets.DEPLOY_HOST }}"
|
||||
DEPLOY_USER="${{ secrets.DEPLOY_USER }}"
|
||||
if [ ! -f "$ARTIFACT" ]; then
|
||||
echo "ERROR: Failed to download artifact"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# appsettings.Production.json 생성
|
||||
python3 -c '
|
||||
import json
|
||||
import pathlib
|
||||
echo "✓ Downloaded: $(du -sh $ARTIFACT)"
|
||||
|
||||
config = {
|
||||
"ConnectionStrings": {
|
||||
"DefaultConnection": "Host=127.0.0.1;Database=quantenginedb;Username=quantengine_app;Password=quantengine_app;Search Path=quantengine;"
|
||||
},
|
||||
"Logging": {
|
||||
"LogLevel": {
|
||||
"Default": "Information"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
pathlib.Path("./publish/appsettings.Production.json").write_text(
|
||||
json.dumps(config, ensure_ascii=False, indent=2),
|
||||
encoding="utf-8"
|
||||
)'
|
||||
|
||||
test -s ./publish/appsettings.Production.json || { echo "ERROR: appsettings.Production.json is empty"; exit 1; }
|
||||
echo "✓ Production config created"
|
||||
|
||||
- name: Package Artifact
|
||||
run: |
|
||||
ARTIFACT="${{ steps.metadata.outputs.artifact }}"
|
||||
tar -czf "$ARTIFACT" -C ./publish .
|
||||
echo "✓ Package: $(du -sh $ARTIFACT | cut -f1)"
|
||||
file "$ARTIFACT"
|
||||
|
||||
- name: Upload Artifact
|
||||
- name: Upload to Actions
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: build-${{ github.run_number }}
|
||||
name: release-artifact
|
||||
path: quantengine_*.tar.gz
|
||||
retention-days: 7
|
||||
retention-days: 1
|
||||
|
||||
pre-deploy-check:
|
||||
name: Pre-Deployment Verification
|
||||
runs-on: ubuntu-latest
|
||||
needs: build
|
||||
needs: fetch-release
|
||||
timeout-minutes: 5
|
||||
|
||||
steps:
|
||||
@@ -131,28 +124,27 @@ jobs:
|
||||
[ -z "${{ secrets.DEPLOY_USER }}" ] && { echo "ERROR: DEPLOY_USER not configured"; exit 1; }
|
||||
echo "✓ All secrets configured"
|
||||
|
||||
- name: Verify Build Artifact
|
||||
- name: Verify Release Artifact
|
||||
run: |
|
||||
if [ "${{ needs.build.outputs.artifact-name }}" = "" ]; then
|
||||
echo "ERROR: Build artifact not generated"
|
||||
if [ "${{ needs.fetch-release.outputs.artifact-name }}" = "" ]; then
|
||||
echo "ERROR: Release artifact not found"
|
||||
exit 1
|
||||
fi
|
||||
echo "✓ Artifact: ${{ needs.build.outputs.artifact-name }}"
|
||||
echo "✓ Release: ${{ needs.fetch-release.outputs.release-tag }}"
|
||||
echo "✓ Artifact: ${{ needs.fetch-release.outputs.artifact-name }}"
|
||||
echo "✓ Commit: ${{ needs.fetch-release.outputs.commit-hash }}"
|
||||
|
||||
deploy:
|
||||
name: Deploy to Production
|
||||
runs-on: ubuntu-latest
|
||||
needs: [ build, pre-deploy-check ]
|
||||
needs: [ fetch-release, pre-deploy-check ]
|
||||
timeout-minutes: 30
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Download Artifact
|
||||
- name: Download Release Artifact
|
||||
uses: actions/download-artifact@v4
|
||||
with:
|
||||
name: build-${{ github.run_number }}
|
||||
name: release-artifact
|
||||
|
||||
- name: Setup SSH
|
||||
run: |
|
||||
@@ -178,20 +170,23 @@ jobs:
|
||||
ssh-keyscan -p ${{ env.DEPLOY_PORT }} ${{ env.DEPLOY_HOST }} >> ~/.ssh/known_hosts 2>/dev/null || true
|
||||
echo "✓ SSH configured"
|
||||
|
||||
- name: Upload Artifact
|
||||
- name: Upload Release Artifact
|
||||
run: |
|
||||
ARTIFACT="${{ needs.build.outputs.artifact-name }}"
|
||||
ARTIFACT="${{ needs.fetch-release.outputs.artifact-name }}"
|
||||
echo "Uploading: $ARTIFACT"
|
||||
ls -lh "$ARTIFACT"
|
||||
|
||||
scp -i ~/.ssh/deploy_key \
|
||||
-P ${{ env.DEPLOY_PORT }} \
|
||||
-o StrictHostKeyChecking=accept-new \
|
||||
"$ARTIFACT" ${{ env.DEPLOY_USER }}@${{ env.DEPLOY_HOST }}:/tmp/
|
||||
echo "✓ Artifact uploaded"
|
||||
echo "✓ Release artifact uploaded"
|
||||
|
||||
- name: Deploy & Verify
|
||||
run: |
|
||||
ARTIFACT="${{ needs.build.outputs.artifact-name }}"
|
||||
COMMIT="${{ needs.build.outputs.commit-hash }}"
|
||||
TIMESTAMP="${{ needs.build.outputs.timestamp }}"
|
||||
ARTIFACT="${{ needs.fetch-release.outputs.artifact-name }}"
|
||||
RELEASE_TAG="${{ needs.fetch-release.outputs.release-tag }}"
|
||||
COMMIT="${{ needs.fetch-release.outputs.commit-hash }}"
|
||||
|
||||
ssh -i ~/.ssh/deploy_key \
|
||||
-p ${{ env.DEPLOY_PORT }} \
|
||||
@@ -200,12 +195,13 @@ jobs:
|
||||
set -e
|
||||
|
||||
ARTIFACT='$ARTIFACT'
|
||||
RELEASE_TAG='$RELEASE_TAG'
|
||||
COMMIT='$COMMIT'
|
||||
TIMESTAMP='$TIMESTAMP'
|
||||
DEPLOY_HOME=$HOME
|
||||
DEPLOY_DIR="$DEPLOY_HOME/deployments/quantengine_${TIMESTAMP}_${COMMIT}"
|
||||
DEPLOY_DIR="$DEPLOY_HOME/deployments/quantengine_${RELEASE_TAG}_${COMMIT}"
|
||||
|
||||
echo "=== Deployment Start ==="
|
||||
echo "Release: $RELEASE_TAG"
|
||||
echo "Artifact: $ARTIFACT"
|
||||
echo "Commit: $COMMIT"
|
||||
echo "Deploy Dir: $DEPLOY_DIR"
|
||||
@@ -215,6 +211,7 @@ jobs:
|
||||
echo "【 1/4 Extract Artifact 】"
|
||||
mkdir -p "$DEPLOY_DIR"
|
||||
tar -xzf "/tmp/$ARTIFACT" -C "$DEPLOY_DIR"
|
||||
rm -f "/tmp/$ARTIFACT"
|
||||
echo "✓ Extraction complete"
|
||||
|
||||
# 2. Verify
|
||||
@@ -224,7 +221,12 @@ jobs:
|
||||
echo "ERROR: QuantEngine.Web.dll not found"
|
||||
exit 1
|
||||
fi
|
||||
if [ ! -f "$DEPLOY_DIR/appsettings.Production.json" ]; then
|
||||
echo "ERROR: appsettings.Production.json not found"
|
||||
exit 1
|
||||
fi
|
||||
echo "✓ DLL verified"
|
||||
echo "✓ Config verified"
|
||||
|
||||
# 3. Update Symlink
|
||||
echo ""
|
||||
@@ -243,10 +245,25 @@ jobs:
|
||||
post-deploy-check:
|
||||
name: Health Check & Verification
|
||||
runs-on: ubuntu-latest
|
||||
needs: [ build, deploy ]
|
||||
needs: [ fetch-release, deploy ]
|
||||
timeout-minutes: 10
|
||||
|
||||
steps:
|
||||
- name: Setup SSH (for service check)
|
||||
run: |
|
||||
mkdir -p ~/.ssh
|
||||
SSH_KEY_B64="${{ secrets.DEPLOY_SSH_KEY_B64 }}"
|
||||
SSH_KEY_RAW="${{ secrets.DEPLOY_SSH_KEY }}"
|
||||
|
||||
if [ -n "$SSH_KEY_B64" ]; then
|
||||
printf '%s' "$SSH_KEY_B64" | base64 -d > ~/.ssh/deploy_key
|
||||
elif [ -n "$SSH_KEY_RAW" ]; then
|
||||
printf '%s' "$SSH_KEY_RAW" | base64 -d > ~/.ssh/deploy_key
|
||||
fi
|
||||
|
||||
chmod 600 ~/.ssh/deploy_key 2>/dev/null || true
|
||||
ssh-keyscan -p 22 ${{ env.DEPLOY_HOST }} >> ~/.ssh/known_hosts 2>/dev/null || true
|
||||
|
||||
- name: Health Check
|
||||
run: |
|
||||
set -e
|
||||
@@ -289,8 +306,8 @@ jobs:
|
||||
echo "⚠ [4/5] Service status: $SERVICE_STATUS"
|
||||
fi
|
||||
|
||||
# Check 5: Commit verified
|
||||
echo "✓ [5/5] Deployment commit: ${{ needs.build.outputs.commit-hash }}"
|
||||
# Check 5: Release verified
|
||||
echo "✓ [5/5] Deployment release: ${{ needs.fetch-release.outputs.release-tag }} (commit: ${{ needs.fetch-release.outputs.commit-hash }})"
|
||||
|
||||
echo ""
|
||||
echo "✅ All health checks passed!"
|
||||
@@ -311,14 +328,15 @@ jobs:
|
||||
name: Deployment Report
|
||||
runs-on: ubuntu-latest
|
||||
if: always()
|
||||
needs: [ build, deploy, post-deploy-check ]
|
||||
needs: [ fetch-release, deploy, post-deploy-check ]
|
||||
|
||||
steps:
|
||||
- name: Report Status
|
||||
run: |
|
||||
COMMIT="${{ needs.build.outputs.commit-hash }}"
|
||||
ARTIFACT="${{ needs.build.outputs.artifact-name }}"
|
||||
BUILD_STATUS="${{ needs.build.result }}"
|
||||
RELEASE="${{ needs.fetch-release.outputs.release-tag }}"
|
||||
COMMIT="${{ needs.fetch-release.outputs.commit-hash }}"
|
||||
ARTIFACT="${{ needs.fetch-release.outputs.artifact-name }}"
|
||||
FETCH_STATUS="${{ needs.fetch-release.result }}"
|
||||
DEPLOY_STATUS="${{ needs.deploy.result }}"
|
||||
CHECK_STATUS="${{ needs.post-deploy-check.result }}"
|
||||
|
||||
@@ -326,18 +344,20 @@ jobs:
|
||||
echo "║ Deployment Report ║"
|
||||
echo "╚════════════════════════════════════════════╝"
|
||||
echo ""
|
||||
echo "Release: $RELEASE"
|
||||
echo "Commit: $COMMIT"
|
||||
echo "Artifact: $ARTIFACT"
|
||||
echo ""
|
||||
echo "【 Status 】"
|
||||
echo "Build: $([ "$BUILD_STATUS" = "success" ] && echo "✓" || echo "✗") $BUILD_STATUS"
|
||||
echo "Fetch: $([ "$FETCH_STATUS" = "success" ] && echo "✓" || echo "✗") $FETCH_STATUS"
|
||||
echo "Deploy: $([ "$DEPLOY_STATUS" = "success" ] && echo "✓" || echo "✗") $DEPLOY_STATUS"
|
||||
echo "Health: $([ "$CHECK_STATUS" = "success" ] && echo "✓" || echo "✗") $CHECK_STATUS"
|
||||
echo ""
|
||||
|
||||
if [ "$BUILD_STATUS" = "success" ] && [ "$DEPLOY_STATUS" = "success" ] && [ "$CHECK_STATUS" = "success" ]; then
|
||||
if [ "$FETCH_STATUS" = "success" ] && [ "$DEPLOY_STATUS" = "success" ] && [ "$CHECK_STATUS" = "success" ]; then
|
||||
echo "✅ Deployment Successful"
|
||||
echo "Server: 178.104.200.7"
|
||||
echo "Release: $RELEASE"
|
||||
exit 0
|
||||
else
|
||||
echo "❌ Deployment Failed"
|
||||
|
||||
Reference in New Issue
Block a user