Skip to content

Commit cbabac4

Browse files
committed
fix(ci): compose job 真跑本次构建镜像并建 admin 用户
- 带 --build:compose 同时有 build:/image:,不带 --build 会去 registry 拉已发布镜像,导致 compose job 长期没测本次代码(v0.2.0 之前无 B5 引导, 换到 v0.2.1 后暴露) - users.txt 用户改为 admin,匹配 compose 的 ADMIN_USERNAMES 默认值, 否则 B5 引导报 no active admin account 直接启动失败 - 健康等待放宽到 120s:启动预热会真连上游拉模型列表 - 补静态回归测试锁定上述两点
1 parent a89d3c2 commit cbabac4

2 files changed

Lines changed: 23 additions & 3 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -52,9 +52,14 @@ jobs:
5252
# 否则 SQLite 打不开、服务崩溃重启,health 永远不通
5353
sudo chown -R 1001:1001 data secrets
5454
docker build -t coding2api:ci .
55-
printf 'ci:%s\n' "$(docker run --rm coding2api:ci python -c 'from src.auth.users import create_password_hash;print(create_password_hash("cipw"))')" > secrets/users.txt
56-
APP_SECRET=ci-placeholder-secret docker compose up -d
57-
for _ in $(seq 1 30); do
55+
# 用户名必须是 admin:compose 的 ADMIN_USERNAMES 默认 admin,
56+
# B5 引导要求至少一个活跃 admin,否则启动直接 Traceback。
57+
printf 'admin:%s\n' "$(docker run --rm coding2api:ci python -c 'from src.auth.users import create_password_hash;print(create_password_hash("cipw"))')" > secrets/users.txt
58+
# --build 必须带:否则 compose 会去 registry 拉 image: 指向的已发布镜像,
59+
# 测的就不是本次构建的代码了(曾因此长期静默通过)。
60+
APP_SECRET=ci-placeholder-secret docker compose up -d --build
61+
# 120s:启动预热会真连上游拉模型列表(zen 免费层还要逐个探活)。
62+
for _ in $(seq 1 60); do
5863
if curl -fsS http://127.0.0.1:8000/health >/dev/null; then break; fi
5964
sleep 2
6065
done

‎tests/test_deployment_assets.py‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -144,6 +144,21 @@ def test_ci_workflow_paths_match_repository():
144144
assert "--cov-fail-under=100" in workflow
145145

146146

147+
def test_ci_compose_job_builds_fresh_image_with_admin_user():
148+
"""compose job 必须真跑本次构建的镜像,且用户文件里要有 admin。
149+
150+
两个坑都曾静默通过:
151+
* compose 同时写了 `build:` 与 `image:`,`up` 不带 `--build` 时会去
152+
registry 拉 `image:` 指向的已发布镜像 —— 测的不是本次代码;
153+
* B5 引导要求至少一个活跃 admin,而 compose 的 ADMIN_USERNAMES 默认
154+
`admin`,users.txt 建 `ci` 会直接启动失败。
155+
"""
156+
workflow = (ROOT / ".github" / "workflows" / "ci.yml").read_text(encoding="utf-8")
157+
assert "docker compose up -d --build" in workflow, "compose up 必须 --build"
158+
assert "printf 'admin:" in workflow, "users.txt 必须建 admin 用户"
159+
assert "printf 'ci:" not in workflow
160+
161+
147162
# -------------------------------------------------─ macOS launchd 部署产物
148163

149164
LAUNCHD_TEMPLATE = ROOT / "deploy" / "launchd" / "com.coding2api.plist"

0 commit comments

Comments
 (0)