fix: 加固生产部署权限与测试网络

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
gouki
2026-07-16 12:57:24 +08:00
co-authored by Cursor
parent 37c5e1f0d8
commit c412331154
4 changed files with 13 additions and 4 deletions
+6
View File
@@ -1,5 +1,11 @@
# Changelog # Changelog
## 1.0.2 - 2026-07-15
- Use the service hostname for isolated MySQL API tests.
- Add group-writable release permissions for the 1Panel PHP runtime user.
- Pin consuming workflows to immutable toolkit release tags.
## 1.0.0 - 2026-07-15 ## 1.0.0 - 2026-07-15
- Add a path-filtered Laravel verification and 1Panel deployment workflow. - Add a path-filtered Laravel verification and 1Panel deployment workflow.
@@ -20,6 +20,7 @@ done
release_id="${RELEASE_ID:-$(date -u +%Y%m%d%H%M%S)}" release_id="${RELEASE_ID:-$(date -u +%Y%m%d%H%M%S)}"
keep_releases="${KEEP_RELEASES:-5}" keep_releases="${KEEP_RELEASES:-5}"
php_user="${PHP_RUNTIME_USER:-1000:1000}" php_user="${PHP_RUNTIME_USER:-1000:1000}"
php_group="${PHP_RUNTIME_GROUP:-1000}"
dry_run="${DRY_RUN:-false}" dry_run="${DRY_RUN:-false}"
host_release="$DEPLOY_ROOT/releases/$release_id" host_release="$DEPLOY_ROOT/releases/$release_id"
container_release="$CONTAINER_DEPLOY_ROOT/releases/$release_id" container_release="$CONTAINER_DEPLOY_ROOT/releases/$release_id"
@@ -104,6 +105,8 @@ run rsync -a --delete \
--exclude='storage' \ --exclude='storage' \
--exclude='vendor' \ --exclude='vendor' \
"$SOURCE_DIR/" "$host_release/" "$SOURCE_DIR/" "$host_release/"
run chgrp -R "$php_group" "$host_release"
run chmod -R g+rwX "$host_release"
run ln -s ../../shared/.env "$host_release/.env" run ln -s ../../shared/.env "$host_release/.env"
run ln -s ../../shared/storage "$host_release/storage" run ln -s ../../shared/storage "$host_release/storage"
+3 -3
View File
@@ -12,14 +12,14 @@ on:
jobs: jobs:
verify: verify:
runs-on: ubuntu-latest runs-on: ubuntu-latest
env:
DB_HOST: mysql
services: services:
mysql: mysql:
image: mysql:8.0 image: mysql:8.0
env: env:
MYSQL_ALLOW_EMPTY_PASSWORD: "yes" MYSQL_ALLOW_EMPTY_PASSWORD: "yes"
MYSQL_DATABASE: new_pet_test MYSQL_DATABASE: new_pet_test
ports:
- 3306:3306
options: >- options: >-
--health-cmd="mysqladmin ping" --health-cmd="mysqladmin ping"
--health-interval=10s --health-interval=10s
@@ -69,7 +69,7 @@ jobs:
with: with:
name: server-build name: server-build
path: server/public/build path: server/public/build
- uses: https://gitea.neatcn.com/pets/deployment-toolkit/actions/laravel-release@v1 - uses: https://gitea.neatcn.com/pets/deployment-toolkit/actions/laravel-release@v1.0.2
with: with:
source-dir: server source-dir: server
deploy-root: ${{ vars.SERVER_DEPLOY_ROOT }} deploy-root: ${{ vars.SERVER_DEPLOY_ROOT }}
+1 -1
View File
@@ -42,7 +42,7 @@ jobs:
test -n "$WECHAT_CI_PRIVATE_KEY" test -n "$WECHAT_CI_PRIVATE_KEY"
umask 077 umask 077
printf '%s' "$WECHAT_CI_PRIVATE_KEY" > "$RUNNER_TEMP/wechat-ci.key" printf '%s' "$WECHAT_CI_PRIVATE_KEY" > "$RUNNER_TEMP/wechat-ci.key"
- uses: https://gitea.neatcn.com/pets/deployment-toolkit/actions/wechat-preview@v1 - uses: https://gitea.neatcn.com/pets/deployment-toolkit/actions/wechat-preview@v1.0.2
with: with:
project-path: miniapp project-path: miniapp
appid: ${{ vars.MINIAPP_APPID }} appid: ${{ vars.MINIAPP_APPID }}