Files
sundynix-site/deploy/README.md
T
Blizzard a6257d2fc4 ci: Docker 打包 + Gitea Actions 自动部署到 132
- Dockerfile 四阶段:web/admin 前端构建 → go 静态编译(embed 双前端) → alpine 运行镜像(53MB, 非 root, Asia/Shanghai)
- docker-compose.yml:132 部署用,暴露 8090,env_file 读本机 .env,带 healthcheck
- .gitea/workflows/deploy.yml:push dev → runner 构建 → docker save|gzip → sshpass scp → 132 load+up → 健康检查
- deploy/nginx-site.sundynix.cn.conf:公网 nginx 反代(穿透回源 site.sundynix.cn)
- .env.production.example + deploy/README.md:部署手册(secrets、127:3307 数据库、证书)
- 已本地验证:镜像构建通过 + 容器冒烟(健康/用户端/管理端/logo/RSS/登录)全绿

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-17 13:38:19 +08:00

59 lines
2.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 部署说明
## 拓扑
```
push dev ──▶ Gitea(192.168.100.125:3000)
│ 触发 .gitea/workflows/deploy.yml
act_runner(192.168.100.128)
│ docker build → save → scp
部署机(192.168.100.132) /home/workspace/sundynix-site
│ docker load → compose up → 容器 :8090
│ │ 连
│ MySQL(192.168.100.127:3307)
内网穿透 ──▶ 公网服务器 nginx ──▶ https://site.sundynix.cn
```
## 一次性准备
### 1. Gitea 仓库 Secrets(仓库 → Settings → Actions → Secrets
| Secret | 值 |
|--------|-----|
| `DEPLOY_HOST` | `192.168.100.132` |
| `DEPLOY_USER` | `root` |
| `DEPLOY_PASSWORD` | `sundynix` |
### 2. 部署机 132 准备
```bash
# 装好 docker + compose 插件后:
mkdir -p /home/workspace/sundynix-site
cd /home/workspace/sundynix-site
# 放置生产配置(参考仓库 .env.production.example
vi .env # 改 admin 密码、JWT 密钥
```
`.env` 关键项见 [.env.production.example](../.env.production.example)。数据库指向内网 `192.168.100.127:3307/sundynix_site`(库不存在会自动建表 + 种子)。
### 3. act_runner 128 要求
- 能访问 docker daemon`docker build/save` 可用)
- 能 ssh 到 132workflow 用 sshpass 走密码)
### 4. 公网服务器 nginx
1. 内网穿透把 132:8090 映射到公网机本地端口
2. 用 [nginx-site.sundynix.cn.conf](nginx-site.sundynix.cn.conf) 配置反代,改 `upstream` 为穿透实际端口
3. 证书:`certbot certonly --webroot -w /var/www/certbot -d site.sundynix.cn`
## 日常
- push 到 `dev` 分支自动构建部署;也可在 Gitea Actions 页手动 `workflow_dispatch`
- 回滚:132 上 `docker tag` 保留的旧镜像,或重跑上一次成功的 commit
- 查日志:`docker logs -f sundynix-site`
- 本地手动出包(不走 CI):仓库根 `docker build -t sundynix-site:latest .`