ci: 构建改 buildah + Dockerfile——环境封装镜像(node24-alpine/yarn4/npmmirror),runner 零依赖零 daemon 零 github;产物经镜像挂载层取 node 上传
This commit is contained in:
1 parent
c9fcf82495
commit
ecf2909b7a
3 files changed
+41
-29
No files matched your search
@@ -0,0 +1,8 @@
|
|||||||
|
# buildah/docker 构建上下文瘦身
|
||||||
|
.git
|
||||||
|
**/node_modules
|
||||||
|
**/dist
|
||||||
|
**/test-results
|
||||||
|
**/playwright-report
|
||||||
|
apps/design-lab/e2e
|
||||||
|
.zcode*
|
||||||
@@ -1,10 +1,10 @@
|
|||||||
name: Build Tutorial
|
name: Build Tutorial
|
||||||
|
|
||||||
# 主仓库 gitea.idealjs.com/idealjs/stack 的 CI:打包新教程站。
|
# 主仓库 gitea.idealjs.com/idealjs/stack 的 CI:打包新教程站。
|
||||||
# 全 shell、零外部 action——runner 连 github.com 不稳(actions 下载常超时):
|
# 构建环境全部封装在 apps/tutorial/Dockerfile(node24-alpine + yarn4 + npmmirror),
|
||||||
# 源码:gitea API tarball(同机房,不走 github)
|
# runner 用 buildah 无 daemon 执行——不依赖 runner 宿主的 node/docker,也不碰 github.com。
|
||||||
# node:自有 release 资产(提取自 node:24.14.0-alpine,镜像在阿里云 idealjs/node)
|
# 源码:gitea API tarball(同机房)
|
||||||
# 产物:滚动 release「ci-dist」资产(node 解析 JSON 上传)
|
# 产物:滚动 release「ci-dist」资产(node 取自镜像挂载层,原生 fetch 上传)
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches: [main]
|
branches: [main]
|
||||||
@@ -12,47 +12,36 @@ on:
|
|||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
env:
|
env:
|
||||||
NODE_DIST: https://gitea.idealjs.com/attachments/edad7a7e-3b3d-4d1b-9551-1a978fdf95d1
|
|
||||||
YARN_NPM_REGISTRY_SERVER: https://registry.npmmirror.com
|
YARN_NPM_REGISTRY_SERVER: https://registry.npmmirror.com
|
||||||
API: https://gitea.idealjs.com/api/v1/repos/idealjs/stack
|
API: https://gitea.idealjs.com/api/v1/repos/idealjs/stack
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
name: Build @stack/tutorial
|
name: Build @stack/tutorial (buildah)
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- name: 拉源码(gitea tarball)
|
- name: 拉源码(gitea tarball)
|
||||||
run: |
|
run: |
|
||||||
wget -q "$API/archive/$GITHUB_SHA.tar.gz" -O /tmp/src.tgz
|
wget -q "$API/archive/$GITHUB_SHA.tar.gz" -O /tmp/src.tgz
|
||||||
tar -xzf /tmp/src.tgz --strip-components=1
|
tar -xzf /tmp/src.tgz --strip-components=1
|
||||||
ls apps/tutorial/package.json
|
ls apps/tutorial/Dockerfile
|
||||||
|
|
||||||
- name: 装便携 node 24(musl bundle,自有资产)
|
- name: 装 buildah(runner 无 docker;buildah 无 daemon 即可构建)
|
||||||
|
run: command -v buildah >/dev/null || apk add --no-cache buildah
|
||||||
|
|
||||||
|
- name: buildah 构建镜像(环境封装在 Dockerfile)
|
||||||
run: |
|
run: |
|
||||||
wget -q "$NODE_DIST" -O /tmp/node.tar.xz
|
buildah build --storage-driver=vfs -f apps/tutorial/Dockerfile -t stack-tutorial:ci .
|
||||||
mkdir -p "$RUNNER_TEMP/node"
|
|
||||||
tar -xJf /tmp/node.tar.xz -C "$RUNNER_TEMP/node" --strip-components=1
|
|
||||||
echo "$RUNNER_TEMP/node/bin" >> "$GITHUB_PATH"
|
|
||||||
# alpine node 动态依赖 libstdc++/libgcc——bundle 自带,指给它
|
|
||||||
echo "LD_LIBRARY_PATH=$RUNNER_TEMP/node/lib" >> "$GITHUB_ENV"
|
|
||||||
export LD_LIBRARY_PATH="$RUNNER_TEMP/node/lib"
|
|
||||||
"$RUNNER_TEMP/node/bin/node" -v
|
|
||||||
|
|
||||||
- name: 安装依赖(corepack yarn4,registry 走 npmmirror)
|
- name: 取产物并上传 release(node 取自镜像挂载层)
|
||||||
run: |
|
|
||||||
# 镜像自带的 yarn1 断链(指向未提取的 /opt/yarn-*),清掉让 corepack 接管
|
|
||||||
rm -f "$(dirname "$(command -v node)")/yarn" "$(dirname "$(command -v node)")/yarnpkg"
|
|
||||||
corepack enable
|
|
||||||
yarn install --immutable
|
|
||||||
|
|
||||||
- name: 构建(Vite MPA:教程七页 + 博客 + 设计系统四册)
|
|
||||||
run: yarn workspace @stack/tutorial build
|
|
||||||
|
|
||||||
- name: 产物上传(滚动 release 资产;权限不足仅告警不红)
|
|
||||||
env:
|
env:
|
||||||
TOK: ${{ secrets.CI_TOKEN || github.token }}
|
TOK: ${{ secrets.CI_TOKEN || github.token }}
|
||||||
run: |
|
run: |
|
||||||
tar -czf /tmp/tutorial-dist.tar.gz -C apps/tutorial/dist .
|
CID=$(buildah from localhost/stack-tutorial:ci)
|
||||||
|
MNT=$(buildah mount "$CID")
|
||||||
|
ls "$MNT/repo/apps/tutorial/dist/index.html"
|
||||||
|
tar -czf /tmp/tutorial-dist.tar.gz -C "$MNT/repo/apps/tutorial/dist" .
|
||||||
|
export LD_LIBRARY_PATH="$MNT/usr/lib"
|
||||||
cat > /tmp/upload.mjs <<'JS'
|
cat > /tmp/upload.mjs <<'JS'
|
||||||
const API = process.env.API
|
const API = process.env.API
|
||||||
const H = { Authorization: `token ${process.env.TOK}` }
|
const H = { Authorization: `token ${process.env.TOK}` }
|
||||||
@@ -71,4 +60,6 @@ jobs:
|
|||||||
const up = await fetch(`${API}/releases/${rid}/assets?name=tutorial-dist.tar.gz`, { method: 'POST', headers: H, body: fd })
|
const up = await fetch(`${API}/releases/${rid}/assets?name=tutorial-dist.tar.gz`, { method: 'POST', headers: H, body: fd })
|
||||||
console.log(up.ok ? `产物下载:${(await up.json()).browser_download_url}` : `上传失败 ${up.status}`)
|
console.log(up.ok ? `产物下载:${(await up.json()).browser_download_url}` : `上传失败 ${up.status}`)
|
||||||
JS
|
JS
|
||||||
node /tmp/upload.mjs
|
"$MNT/usr/local/bin/node" /tmp/upload.mjs
|
||||||
|
buildah unmount "$CID" >/dev/null 2>&1 || true
|
||||||
|
buildah rm "$CID" >/dev/null 2>&1 || true
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
# 教程站构建镜像——CI 用 buildah(无 daemon)执行,本地 docker/podman build 同样可用。
|
||||||
|
# 基座走 daocloud 公共镜像(国内快、免登录);与阿里云 idealjs/node:24.14.0-alpine 同源。
|
||||||
|
FROM docker.m.daocloud.io/library/node:24.14.0-alpine
|
||||||
|
|
||||||
|
ENV YARN_NPM_REGISTRY_SERVER=https://registry.npmmirror.com
|
||||||
|
WORKDIR /repo
|
||||||
|
|
||||||
|
# monorepo 全量上下文(.dockerignore 瘦身);依赖与构建同层——lockfile 由 --immutable 锁定
|
||||||
|
COPY . .
|
||||||
|
RUN rm -f /usr/local/bin/yarn /usr/local/bin/yarnpkg \
|
||||||
|
&& corepack enable \
|
||||||
|
&& yarn install --immutable \
|
||||||
|
&& yarn workspace @stack/tutorial build
|
||||||
Reference in new issue
Block a user