ci: 适配 ephemerd——job 容器无特权且假 socket 不支持 build,弃 buildah 改为 job 内直接 yarn 构建(ubuntu-24.04 镜像,node 预装);runner 由 idealjs 仓 ephemerd 部署管理
Build Tutorial / Build @stack/tutorial (ephemerd) (pull_request) Failing after 12m13s
Build Tutorial / Build @stack/tutorial (ephemerd) (pull_request) Failing after 12m13s
This commit is contained in:
1 parent
1b89e2a8f0
commit
2f2156089e
1 file changed
+11
-34
@@ -1,9 +1,10 @@
|
|||||||
name: Build Tutorial
|
name: Build Tutorial
|
||||||
|
|
||||||
# 主仓库 gitea.idealjs.com/idealjs/stack 的 CI:打包新教程站。
|
# 主仓库 gitea.idealjs.com/idealjs/stack 的 CI:构建校验新教程站。
|
||||||
# 构建环境全部封装在仓库根 Dockerfile(node24-bookworm-slim + yarn4 + npmmirror),
|
# runner 由 ephemerd 管理(每 job 一次性容器,跑完即毁;部署配置见 idealjs 仓 packages/ephemerd)。
|
||||||
# runner 用 buildah 无 daemon 执行——不依赖 runner 宿主的 node/docker,也不碰 github.com。
|
# job 跑在 gitea/runner-images:ubuntu-24.04 内(node 预装);依赖与构建直接在 job 内执行——
|
||||||
# 源码:gitea API tarball(同机房);产物留在镜像 stack-tutorial:ci 内(/repo/apps/tutorial/dist)
|
# ephemerd 的 job 容器无特权且假 docker socket 暂不支持 build,buildah/docker 构建交由部署侧完成。
|
||||||
|
# 源码:gitea API tarball(同机房)
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches: [main]
|
branches: [main]
|
||||||
@@ -13,44 +14,20 @@ on:
|
|||||||
env:
|
env:
|
||||||
YARN_NPM_REGISTRY_SERVER: https://registry.npmmirror.com
|
YARN_NPM_REGISTRY_SERVER: https://registry.npmmirror.com
|
||||||
API: https://gitea.idealjs.com/api/v1/repos/idealjs/stack
|
API: https://gitea.idealjs.com/api/v1/repos/idealjs/stack
|
||||||
# runner 是套娃容器——buildah 的 OCI runtime(runc/crun)在内部过不了 cgroup 关,钉死 chroot 隔离
|
|
||||||
BUILDAH_ISOLATION: chroot
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build @stack/tutorial (buildah)
|
name: Build @stack/tutorial (ephemerd)
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: 拉源码(gitea tarball)
|
- name: 拉源码(gitea tarball)
|
||||||
run: |
|
run: |
|
||||||
wget -q "$API/archive/$GITHUB_SHA.tar.gz" -O /tmp/src.tgz
|
wget -q "$API/archive/$GITHUB_SHA.tar.gz" -O /tmp/src.tgz
|
||||||
tar -xzf /tmp/src.tgz --strip-components=1
|
tar -xzf /tmp/src.tgz --strip-components=1
|
||||||
ls Dockerfile
|
ls package.json
|
||||||
|
|
||||||
- name: 装 buildah(runner 无 docker;buildah 无 daemon 即可构建)
|
- name: 安装依赖(yarn4 经 yarnPath 直调,不经 corepack)
|
||||||
run: |
|
run: node .yarn/releases/yarn-4.9.2.cjs install --immutable
|
||||||
command -v buildah >/dev/null && exit 0
|
|
||||||
# 服务器在阿里云——apk 走阿里镜像源(dl-cdn 直连极慢)
|
|
||||||
sed -i 's#https://dl-cdn.alpinelinux.org#https://mirrors.aliyun.com#g' /etc/apk/repositories
|
|
||||||
# netavark: buildah 配容器网络的助手,alpine 不会随 buildah 自动装
|
|
||||||
apk add --no-cache buildah netavark
|
|
||||||
|
|
||||||
- name: buildah 登录阿里云镜像仓(基座为私有 idealjs/node)
|
- name: 构建
|
||||||
env:
|
run: node .yarn/releases/yarn-4.9.2.cjs workspace @stack/tutorial build
|
||||||
ALIYUN_DOCKER_USERNAME: ${{ secrets.ALIYUN_DOCKER_USERNAME }}
|
|
||||||
ALIYUN_DOCKER_PASSWORD: ${{ secrets.ALIYUN_DOCKER_PASSWORD }}
|
|
||||||
run: |
|
|
||||||
printf '%s' "$ALIYUN_DOCKER_PASSWORD" | buildah login --username "$ALIYUN_DOCKER_USERNAME" --password-stdin registry.cn-hangzhou.aliyuncs.com
|
|
||||||
# authfile 按域名区分——构建走 VPC 端点,需单独 login(凭据相同)
|
|
||||||
printf '%s' "$ALIYUN_DOCKER_PASSWORD" | buildah login --username "$ALIYUN_DOCKER_USERNAME" --password-stdin registry-vpc.cn-hangzhou.aliyuncs.com
|
|
||||||
|
|
||||||
- name: buildah 构建镜像(环境封装在 Dockerfile)
|
|
||||||
run: |
|
|
||||||
# runner 与镜像仓同 region(杭州)——基座走 VPC 内网端点,快且不占公网带宽
|
|
||||||
buildah build --storage-driver=vfs --build-arg BASE_REGISTRY=registry-vpc.cn-hangzhou.aliyuncs.com -f Dockerfile -t stack-tutorial:ci .
|
|
||||||
|
|
||||||
- name: buildah 登出(清掉 runner 上 auth.json 里的凭据;长驻 runner 不留凭据)
|
|
||||||
if: always()
|
|
||||||
run: |
|
|
||||||
buildah logout registry.cn-hangzhou.aliyuncs.com || true
|
|
||||||
buildah logout registry-vpc.cn-hangzhou.aliyuncs.com || true
|
|
||||||
Reference in new issue
Block a user