- 新增 nginx 反代配置(HTTPS + 本机 8080,含 1Panel 建站替代说明) - 新增 docker-compose.yml(端口仅绑定 127.0.0.1,env_file 注入生产变量) - PULL_DEPLOY.md 重写为完整一次性安装指南:域名/证书/微信合法域名/ 生产环境变量模板/容器/脚本/timer/验证清单 - AUTO_DEPLOY_1PANEL.md 标记废弃(SSH 手工方式违反安全红线)
3.1 KiB
3.1 KiB
doc79 同机拉取式部署配置(一次性)
安全原则:CI 只构建、不部署;任何 AI 与流水线都不允许 SSH 到服务器执行命令。 部署由服务器本地的 watcher 监听 CI 产物目录自动完成。本文档的所有命令由管理员本人在 doc79 上执行一次。
架构
push main → Gitea Actions 构建(runner 与 doc79 同机)→ 产物写入 /ci-artifacts
↓
systemd timer 每分钟运行 deploy-watch.sh → 发现新 sha256 → deploy.sh 原子切换 + 重启容器 + 健康检查
↓
nginx (lunar.neatcn.com, HTTPS) → 127.0.0.1:8080 lunar-server 容器
一次性安装步骤
1. 域名与 HTTPS(lunar.neatcn.com)
- DNS:将
lunar.neatcn.comA 记录指向 doc79 公网 IP; - 站点:1Panel → 网站 → 创建反向代理网站,域名
lunar.neatcn.com→http://127.0.0.1:8080, 申请 Let's Encrypt 证书并开启 HTTPS(参考.gitea/deploy/nginx-lunar.neatcn.com.conf); - 微信公众平台 → 开发管理 → 服务器域名:将
https://lunar.neatcn.com加入 request 合法域名。
2. 生产环境变量(切勿写入仓库)
sudo mkdir -p /opt/lunar/production /opt/lunar/backups /opt/lunar/scripts
sudo tee /opt/lunar/production/.env > /dev/null <<'EOF'
SERVER_ENV=production
SERVER_PORT=8080
DB_HOST=<数据库地址>
DB_PORT=3306
DB_USER=<用户名>
DB_PASSWORD=<密码>
DB_NAME=lunar
JWT_SECRET=<强随机值,至少32位>
MINI_APP_ID=<小程序AppID>
MINI_APP_SECRET=<小程序AppSecret>
WECHAT_PAY_APIKEY=<支付API密钥>
WECHAT_PAY_MCHID=<商户号>
ADMIN_PASSWORD=<后台登录密码>
CORS_ORIGINS=https://lunar.neatcn.com
EOF
sudo chmod 600 /opt/lunar/production/.env
3. 启动容器
# 从仓库 .gitea/deploy/ 复制 docker-compose.yml
sudo cp docker-compose.yml /opt/lunar/docker-compose.yml
cd /opt/lunar && sudo docker compose up -d
(首次启动时 /opt/lunar/production/current 还不存在,容器会重启失败, 待第 5 步 watcher 完成首次部署后自动恢复;或先手工 mkdir 空目录。)
4. 安装部署脚本
# 从仓库 .gitea/scripts/ 复制
sudo cp deploy.sh deploy-watch.sh /opt/lunar/scripts/
sudo chmod +x /opt/lunar/scripts/*.sh
5. systemd timer(每分钟轮询)
sudo tee /etc/systemd/system/lunar-deploy-watch.service > /dev/null <<'EOF'
[Unit]
Description=Lunar pull-based deploy watcher
[Service]
Type=oneshot
ExecStart=/bin/bash /opt/lunar/scripts/deploy-watch.sh
EOF
sudo tee /etc/systemd/system/lunar-deploy-watch.timer > /dev/null <<'EOF'
[Unit]
Description=Run lunar deploy watcher every minute
[Timer]
OnBootSec=1min
OnUnitActiveSec=1min
[Install]
WantedBy=timers.target
EOF
sudo systemctl daemon-reload
sudo systemctl enable --now lunar-deploy-watch.timer
验证
systemctl list-timers | grep lunar
tail -f /opt/lunar/deploy-watch.log
curl -s https://lunar.neatcn.com/api/version # 应返回版本 JSON
回滚
deploy.sh 健康检查失败会自动回滚;手工回滚使用 /opt/lunar/backups/ 下的备份包重新执行 deploy.sh。