# 部署说明 ## 拓扑 ``` push dev ──▶ Gitea(192.168.100.125:3000) │ 触发 .gitea/workflows/deploy.yml ▼ act_runner(192.168.100.128) │ docker build → save → scp ▼ 部署机(192.168.100.132) /home/workspace/sundynix-site │ docker load → compose up → 容器 :8090 │ │ 连 │ MySQL(192.168.100.127:3307) ▼ 内网穿透 ──▶ 公网服务器 nginx ──▶ https://site.sundynix.cn ``` ## 一次性准备 ### 1. Gitea 仓库 Secrets(仓库 → Settings → Actions → Secrets) | Secret | 值 | |--------|-----| | `DEPLOY_HOST` | `192.168.100.132` | | `DEPLOY_USER` | `root` | | `DEPLOY_PASSWORD` | `sundynix` | ### 2. 部署机 132 准备 ```bash # 装好 docker + compose 插件后: mkdir -p /home/workspace/sundynix-site cd /home/workspace/sundynix-site # 放置生产配置(参考仓库 .env.production.example) vi .env # 改 admin 密码、JWT 密钥 ``` `.env` 关键项见 [.env.production.example](../.env.production.example)。数据库指向内网 `192.168.100.127:3307/sundynix_site`(库不存在会自动建表 + 种子)。 ### 3. act_runner 128 要求 - 能访问 docker daemon(`docker build/save` 可用) - 能 ssh 到 132(workflow 用 sshpass 走密码) ### 4. 公网服务器 nginx 1. 内网穿透把 132:8090 映射到公网机本地端口 2. 用 [nginx-site.sundynix.cn.conf](nginx-site.sundynix.cn.conf) 配置反代,改 `upstream` 为穿透实际端口 3. 证书:`certbot certonly --webroot -w /var/www/certbot -d site.sundynix.cn` ## 日常 - push 到 `dev` 分支自动构建部署;也可在 Gitea Actions 页手动 `workflow_dispatch` - 回滚:132 上 `docker tag` 保留的旧镜像,或重跑上一次成功的 commit - 查日志:`docker logs -f sundynix-site` - 本地手动出包(不走 CI):仓库根 `docker build -t sundynix-site:latest .`