Files
lunar-mini/.gitea/workflows/miniapp-preview.yml
T
gouki b507d6c154
Publish Mini Program Dev Version / publish (push) Canceled after 0s
Build and Publish Server / build (push) Canceled after 0s
feat(ci): 迁移到 hk runner + Release 产物分发,解除对 doc79 runner 的依赖
- 两个工作流 runs-on 改为 hk(在线);Go/Node 工具链自包含下载+工作区缓存
- 后端产物改为发布 Gitea Release 附件(server-v<版本>),与 runner 位置解耦
- deploy-watch.sh 重写为从 Release 拉取:匿名/令牌 HTTPS 下载、包结构预检、
  按 release id 幂等、失败下轮重试
- 移除对 /ci-artifacts 本机目录的依赖(原设计要求 runner 与生产同机)
- PULL_DEPLOY.md 架构图同步更新
2026-08-09 17:17:23 +00:00

160 lines
6.7 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
name: Publish Mini Program Dev Version
on:
workflow_dispatch:
push:
branches:
- main
paths:
- "mini/**"
- ".gitea/workflows/miniapp-preview.yml"
jobs:
publish:
# hk runner(海外,宿主机直接执行;可直连微信与 Telegram/Discord
runs-on: hk
steps:
- uses: https://gitea.neatcn.com/gouki/action-checkout@v4
with:
# Need recent commit subjects for the WeChat upload remark.
fetch-depth: 20
- name: Prepare Node toolchain
run: |
# 优先复用 runner 宿主机缓存的工具链(工作目录持久化)
TOOLDIR="$RUNNER_WORKSPACE/.lunar-toolchain"
mkdir -p "$TOOLDIR"
if [ -x "$TOOLDIR/node/bin/node" ]; then
echo "复用缓存 Node 工具链"
else
wget -q --tries=2 --timeout=60 -O "$TOOLDIR/node.tgz" \
"https://nodejs.org/dist/v22.12.0/node-v22.12.0-linux-x64.tar.xz" \
|| wget -q --tries=2 --timeout=60 -O "$TOOLDIR/node.tgz" \
"https://mirrors.aliyun.com/nodejs-release/v22.12.0/node-v22.12.0-linux-x64.tar.xz"
rm -rf "$TOOLDIR/node-v22.12.0-linux-x64"
tar -C "$TOOLDIR" -xJf "$TOOLDIR/node.tgz"
mv "$TOOLDIR/node-v22.12.0-linux-x64" "$TOOLDIR/node"
rm -f "$TOOLDIR/node.tgz"
fi
"$TOOLDIR/node/bin/node" --version
echo "PATH=$TOOLDIR/node/bin:$PATH" >> "$GITEA_ENV"
- name: Verify Node runtime
run: node --version
- name: Install dependencies
working-directory: mini
run: npm ci
- name: Run tests
working-directory: mini
run: npm test
- name: Configure production API and app version
working-directory: mini
env:
MINIAPP_BUILD_NUMBER: ${{ gitea.run_number }}
MINIAPP_VERSION_OVERRIDE: ${{ vars.MINIAPP_VERSION_OVERRIDE }}
GITEA_SHA: ${{ gitea.sha }}
run: |
test -n "$MINIAPP_BUILD_NUMBER"
VERSION="$(node -e 'const {resolveVersion}=require("./ci/resolve-version.cjs"); process.stdout.write(resolveVersion(process.cwd()))')"
test -n "$VERSION"
mkdir -p ci-artifacts
printf '%s\n' "$VERSION" > ci-artifacts/resolved-version.txt
echo "Resolved Mini Program version for build+upload: $VERSION"
# 注入版本号到 utils/version.js
BUILD_TIME="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
COMMIT_SHORT="${GITEA_SHA:0:7}"
cat > utils/version.js <<EOF
/**
* 版本号配置文件
* 此文件由 CI 构建时自动生成,请勿手动修改
*/
module.exports = {
version: "$VERSION",
buildNumber: "$MINIAPP_BUILD_NUMBER",
buildTime: "$BUILD_TIME",
commitSha: "$COMMIT_SHORT",
};
EOF
echo "Version info injected into utils/version.js:"
cat utils/version.js
- name: Materialize the upload key
env:
WECHAT_CI_PRIVATE_KEY: ${{ secrets.WECHAT_CI_PRIVATE_KEY }}
run: |
test -n "$WECHAT_CI_PRIVATE_KEY"
umask 077
printf '%s' "$WECHAT_CI_PRIVATE_KEY" > "$RUNNER_TEMP/wechat-ci.key"
- name: Upload WeChat development version
working-directory: mini
env:
MINIAPP_APPID: ${{ vars.MINIAPP_APPID }}
MINIAPP_ROBOT: ${{ vars.MINIAPP_ROBOT }}
# Prefer the version resolved before build so UI label matches WeChat upload.
MINIAPP_BUILD_NUMBER: ${{ gitea.run_number }}
MINIAPP_VERSION_OVERRIDE: ${{ vars.MINIAPP_VERSION_OVERRIDE }}
WECHAT_CI_PRIVATE_KEY_PATH: ${{ runner.temp }}/wechat-ci.key
MINIAPP_UPLOAD_RESULT: ${{ gitea.workspace }}/mini/ci-artifacts/upload-result.json
MINIAPP_VERSION_LABEL: ${{ gitea.sha }}
MINIAPP_UPLOAD_DESC_ITEMS: "3"
MINIAPP_UPLOAD_DESC_MAX: "100"
run: |
test -n "$MINIAPP_APPID"
test -n "$MINIAPP_BUILD_NUMBER"
test -s ci-artifacts/resolved-version.txt
RESOLVED_VERSION="$(tr -d '\n' < ci-artifacts/resolved-version.txt)"
# Force upload to the same version that was baked into the JS bundle.
export MINIAPP_VERSION_OVERRIDE="$RESOLVED_VERSION"
mkdir -p ci-artifacts
node -e 'const c=require("./project.config.json"); if(c.appid!==process.env.MINIAPP_APPID){console.error("MINIAPP_APPID mismatch with project.config.json", process.env.MINIAPP_APPID, c.appid); process.exit(1)}'
node -e 'const {resolveVersion}=require("./ci/resolve-version.cjs"); console.log("Resolved Mini Program version:", resolveVersion(process.cwd()))'
node -e 'const {resolveUploadDesc}=require("./ci/resolve-upload-desc.cjs"); console.log("Resolved upload remark:", resolveUploadDesc({repoRoot:require("path").resolve(".."), versionLabel:process.env.MINIAPP_VERSION_LABEL}))'
# Normalize PEM newlines that may be flattened when stored in Secrets.
python3 - <<'PY'
from pathlib import Path
import os
key_path = Path(os.environ["WECHAT_CI_PRIVATE_KEY_PATH"])
text = key_path.read_text()
if "\\n" in text and "BEGIN" in text:
text = text.replace("\\n", "\n")
text = text.replace("\r\n", "\n").strip() + "\n"
key_path.write_text(text)
content = key_path.read_text()
assert "BEGIN" in content and "PRIVATE KEY" in content, "WECHAT_CI_PRIVATE_KEY is not a PEM private key"
print("private_key_lines=", len(content.splitlines()))
PY
node ci/upload-ci.cjs
test -s ci-artifacts/upload-result.json
cat ci-artifacts/upload-result.json
- name: Send success notification
if: success()
env:
TELEGRAM_BOT_TOKEN: ${{ secrets.TELEGRAM_BOT_TOKEN }}
TELEGRAM_CHAT_ID: ${{ secrets.TELEGRAM_CHAT_ID }}
DISCORD_WEBHOOK_URL: ${{ secrets.DISCORD_WEBHOOK_URL }}
run: |
VERSION="$(tr -d '\n' < mini/ci-artifacts/resolved-version.txt)"
bash .gitea/scripts/notify.sh success "小程序开发版上传成功" "版本: ${VERSION}"
- name: Send failure notification
if: failure()
env:
TELEGRAM_BOT_TOKEN: ${{ secrets.TELEGRAM_BOT_TOKEN }}
TELEGRAM_CHAT_ID: ${{ secrets.TELEGRAM_CHAT_ID }}
DISCORD_WEBHOOK_URL: ${{ secrets.DISCORD_WEBHOOK_URL }}
run: |
bash .gitea/scripts/notify.sh failure \
"小程序开发版上传失败" \
"请检查 Actions 日志了解失败原因"
- name: Remove temporary credentials
if: always()
run: rm -f "$RUNNER_TEMP/wechat-ci.key"