e49922e188
Production incident: quant.taxbaik.com/login threw 28P01 (password
authentication failed) after the July 7 deployment's
appsettings.Production.json carried a stale DB password. Root cause
chain:
1. The DB password for quantengine_app had been rotated at some
point; the new password was saved to
/home/kjh2064/.config/quantengine.env on the server, but that
file was never wired into the quantengine.service systemd unit
(no EnvironmentFile= directive), so it was silently unused.
2. Every appsettings.Production.json we've generated in CI
(including tonight's prepare-release.yml) baked in a PLACEHOLDER
password ("quantengine_app") that was never the real credential
to begin with -- copied forward from an earlier debugging session
without ever being verified against the live DB.
Immediate production fix (out of band, via SSH): patched the active
deployment's appsettings.Production.json with the current working
password (verified via direct psql connection) and restarted the
service. Login confirmed HTTP 200 with a clean journalctl afterward.
This commit fixes the root cause in the pipeline: prepare-release.yml
no longer writes a ConnectionStrings block into the artifact at all.
Baking any DB password (even a correct one) into a build artifact
that ships as a downloadable Gitea Release asset is unsafe and goes
stale on every credential rotation. The correct fix is for
quantengine.service to load ConnectionStrings__DefaultConnection from
/home/kjh2064/.config/quantengine.env via systemd's EnvironmentFile=,
which overrides appsettings.Production.json at runtime per standard
ASP.NET Core configuration precedence. That unit-file edit requires
interactive sudo and must be applied by hand on the server (tracked
separately, not part of this commit).
IMPORTANT: the release quant_20260711.1.6ab270f already published
tonight was built before this fix and still lacks any DB config --
do not deploy it via deploy-prod.yml until the systemd
EnvironmentFile wiring is confirmed on the server, or the login
outage will recur.
184 lines
6.3 KiB
YAML
184 lines
6.3 KiB
YAML
name: Prepare Release
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
version:
|
|
description: 'Release version (auto-generated if empty, e.g. quant_20260711.1.abc1234)'
|
|
required: false
|
|
type: string
|
|
|
|
env:
|
|
DOTNET_VERSION: '10.0.x'
|
|
|
|
jobs:
|
|
build-and-release:
|
|
name: Build & Create Release
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
outputs:
|
|
version: ${{ steps.metadata.outputs.version }}
|
|
commit: ${{ steps.metadata.outputs.commit }}
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup .NET
|
|
uses: actions/setup-dotnet@v4
|
|
with:
|
|
dotnet-version: ${{ env.DOTNET_VERSION }}
|
|
|
|
- name: Generate Metadata
|
|
id: metadata
|
|
run: |
|
|
VERSION_INPUT="${{ github.event.inputs.version }}"
|
|
COMMIT=$(git rev-parse --short HEAD)
|
|
|
|
# Auto-generate version if not provided
|
|
if [ -z "$VERSION_INPUT" ]; then
|
|
TODAY=$(TZ=UTC date +%Y%m%d)
|
|
|
|
# Count releases for today
|
|
RELEASES_TODAY=$(git tag -l "quant_${TODAY}.*" | wc -l)
|
|
DEPLOY_COUNT=$((RELEASES_TODAY + 1))
|
|
|
|
VERSION="quant_${TODAY}.${DEPLOY_COUNT}.${COMMIT}"
|
|
else
|
|
VERSION="$VERSION_INPUT"
|
|
fi
|
|
|
|
echo "version=${VERSION}" >> $GITHUB_OUTPUT
|
|
echo "commit=${COMMIT}" >> $GITHUB_OUTPUT
|
|
echo "Version: $VERSION"
|
|
echo "Commit: $COMMIT"
|
|
|
|
- name: Restore
|
|
run: |
|
|
dotnet restore src/dotnet/QuantEngine.Web/QuantEngine.Web.csproj
|
|
|
|
- name: Build (Release)
|
|
run: |
|
|
dotnet build src/dotnet/QuantEngine.Web/QuantEngine.Web.csproj \
|
|
-c Release \
|
|
--no-restore \
|
|
-p:ContinuousIntegrationBuild=true
|
|
|
|
- name: Publish
|
|
run: |
|
|
dotnet publish src/dotnet/QuantEngine.Web/QuantEngine.Web.csproj \
|
|
-c Release \
|
|
-o ./publish \
|
|
--no-restore \
|
|
--no-build
|
|
|
|
- name: Write Production Config
|
|
run: |
|
|
mkdir -p ./publish
|
|
python3 -c '
|
|
import json
|
|
import pathlib
|
|
|
|
# NOTE: No ConnectionStrings here on purpose. The real DB
|
|
# password lives only in /home/kjh2064/.config/quantengine.env
|
|
# on the production server and is injected via systemd
|
|
# EnvironmentFile (ConnectionStrings__DefaultConnection),
|
|
# which overrides this file at runtime. Never bake secrets
|
|
# into a build artifact that ends up in a Gitea Release.
|
|
config = {
|
|
"Logging": {
|
|
"LogLevel": {
|
|
"Default": "Information"
|
|
}
|
|
}
|
|
}
|
|
|
|
pathlib.Path("./publish/appsettings.Production.json").write_text(
|
|
json.dumps(config, ensure_ascii=False, indent=2),
|
|
encoding="utf-8"
|
|
)'
|
|
|
|
test -s ./publish/appsettings.Production.json || { echo "ERROR: appsettings.Production.json is empty"; exit 1; }
|
|
echo "✓ Production config created (no secrets included)"
|
|
|
|
- name: Package Artifact
|
|
run: |
|
|
VERSION="${{ steps.metadata.outputs.version }}"
|
|
ARTIFACT="quantengine_${VERSION}.tar.gz"
|
|
tar -czf "$ARTIFACT" -C ./publish .
|
|
echo "artifact=${ARTIFACT}" >> $GITHUB_OUTPUT
|
|
echo "✓ Package: $(du -sh $ARTIFACT | cut -f1)"
|
|
file "$ARTIFACT"
|
|
|
|
- name: Create Git Tag
|
|
run: |
|
|
VERSION="${{ steps.metadata.outputs.version }}"
|
|
COMMIT="${{ steps.metadata.outputs.commit }}"
|
|
|
|
git config user.name "Gitea Actions"
|
|
git config user.email "actions@gitea.local"
|
|
|
|
git tag -a "$VERSION" -m "Release $VERSION (commit: $COMMIT)" HEAD
|
|
echo "✓ Local tag created: $VERSION"
|
|
|
|
git push origin "$VERSION"
|
|
echo "✓ Tag pushed: $VERSION"
|
|
|
|
- name: Create Gitea Release
|
|
env:
|
|
VERSION: ${{ steps.metadata.outputs.version }}
|
|
COMMIT: ${{ steps.metadata.outputs.commit }}
|
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
run: |
|
|
ARTIFACT="quantengine_${VERSION}.tar.gz"
|
|
API="https://gitea.taxbaik.com/api/v1"
|
|
REPO="kjh2064/QuantEngineByItz"
|
|
|
|
test -s "$ARTIFACT" || { echo "ERROR: artifact missing: $ARTIFACT"; exit 1; }
|
|
|
|
echo "Creating release $VERSION via Gitea API..."
|
|
RELEASE_JSON=$(curl -sf -X POST \
|
|
-H "Authorization: token ${GITEA_TOKEN}" \
|
|
-H "Content-Type: application/json" \
|
|
-d "{\"tag_name\":\"${VERSION}\",\"name\":\"Release ${VERSION}\",\"body\":\"Release Version: ${VERSION} | Commit: ${COMMIT}\",\"target_commitish\":\"main\"}" \
|
|
"${API}/repos/${REPO}/releases")
|
|
|
|
RELEASE_ID=$(echo "$RELEASE_JSON" | python3 -c "import sys,json; print(json.load(sys.stdin)['id'])")
|
|
|
|
if [ -z "$RELEASE_ID" ] || [ "$RELEASE_ID" = "null" ]; then
|
|
echo "ERROR: Failed to create release"
|
|
echo "$RELEASE_JSON"
|
|
exit 1
|
|
fi
|
|
|
|
echo "✓ Release created: $VERSION (id: $RELEASE_ID)"
|
|
|
|
echo "Uploading artifact..."
|
|
curl -sf -X POST \
|
|
-H "Authorization: token ${GITEA_TOKEN}" \
|
|
-H "Content-Type: multipart/form-data" \
|
|
-F "attachment=@${ARTIFACT}" \
|
|
"${API}/repos/${REPO}/releases/${RELEASE_ID}/assets?name=${ARTIFACT}" \
|
|
-o /dev/null
|
|
|
|
echo "✓ Artifact attached: $ARTIFACT"
|
|
|
|
notification:
|
|
name: Release Notification
|
|
runs-on: ubuntu-latest
|
|
if: always()
|
|
needs: build-and-release
|
|
|
|
steps:
|
|
- name: Notify Release Ready
|
|
if: needs.build-and-release.result == 'success'
|
|
run: |
|
|
echo "════════════════════════════════════════"
|
|
echo "✅ Release Ready for Deployment"
|
|
echo "════════════════════════════════════════"
|
|
echo "Version: ${{ needs.build-and-release.outputs.version }}"
|
|
echo "Commit: ${{ needs.build-and-release.outputs.commit }}"
|
|
echo ""
|
|
echo "Next: Use deploy-prod.yml to deploy this release"
|
|
echo "════════════════════════════════════════"
|