chore(release): verify remote asset hashes
This commit is contained in:
@@ -163,6 +163,8 @@ curl -k -s https://peilian.njzhmj.top/h5/ | sed -n '1,20p'
|
|||||||
```bash
|
```bash
|
||||||
./scripts/release-preflight.sh
|
./scripts/release-preflight.sh
|
||||||
RELEASE_REMOTE_URL=https://peilian.njzhmj.top ./scripts/release-preflight.sh
|
RELEASE_REMOTE_URL=https://peilian.njzhmj.top ./scripts/release-preflight.sh
|
||||||
|
# 发布后核验线上主资源是否与当前本地产物一致
|
||||||
|
RELEASE_REMOTE_URL=https://peilian.njzhmj.top RELEASE_VERIFY_REMOTE_MATCH=true ./scripts/release-preflight.sh
|
||||||
```
|
```
|
||||||
|
|
||||||
发布时必须保留 preflight 输出、远端备份目录和发布后浏览器回归结果;回滚优先使用对应备份目录恢复,再重启后端服务,不能直接覆盖当前线上目录而不留证据。
|
发布时必须保留 preflight 输出、远端备份目录和发布后浏览器回归结果;回滚优先使用对应备份目录恢复,再重启后端服务,不能直接覆盖当前线上目录而不留证据。
|
||||||
|
|||||||
@@ -21,6 +21,14 @@ sha256() {
|
|||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
sha256_stream() {
|
||||||
|
if command -v shasum >/dev/null 2>&1; then
|
||||||
|
shasum -a 256 | awk '{print $1}'
|
||||||
|
else
|
||||||
|
sha256sum | awk '{print $1}'
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
frontend_index="frontend/dist/index.html"
|
frontend_index="frontend/dist/index.html"
|
||||||
mobile_index="mobile-uni/dist/build/h5/index.html"
|
mobile_index="mobile-uni/dist/build/h5/index.html"
|
||||||
backend_jar="backend/ruoyi-admin/target/ruoyi-admin.jar"
|
backend_jar="backend/ruoyi-admin/target/ruoyi-admin.jar"
|
||||||
@@ -63,6 +71,25 @@ if [[ -n "${RELEASE_REMOTE_URL:-}" ]]; then
|
|||||||
else
|
else
|
||||||
fail "remote tenant list check failed: $remote/prod-api/auth/tenant/list"
|
fail "remote tenant list check failed: $remote/prod-api/auth/tenant/list"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
if [[ "${RELEASE_VERIFY_REMOTE_MATCH:-false}" == "true" ]]; then
|
||||||
|
remote_frontend_asset="$(curl -fsS --max-time 15 "$remote/" | sed -nE 's/.*src="(\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)"
|
||||||
|
remote_mobile_asset="$(curl -fsS --max-time 15 "$remote/h5/" | sed -nE 's/.*src="(\/h5\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)"
|
||||||
|
[[ "$remote_frontend_asset" == /assets/*.js ]] || fail "remote frontend entry asset not found"
|
||||||
|
[[ "$remote_mobile_asset" == /h5/assets/*.js ]] || fail "remote mobile H5 entry asset not found"
|
||||||
|
|
||||||
|
remote_frontend_sha256="$(curl -fsS --max-time 15 "$remote$remote_frontend_asset" | sha256_stream)"
|
||||||
|
remote_mobile_sha256="$(curl -fsS --max-time 15 "$remote$remote_mobile_asset" | sha256_stream)"
|
||||||
|
local_frontend_sha256="$(sha256 "$frontend_asset_path")"
|
||||||
|
local_mobile_sha256="$(sha256 "$mobile_asset_path")"
|
||||||
|
echo "remote_frontend_asset=$remote_frontend_asset"
|
||||||
|
echo "remote_frontend_asset_sha256=$remote_frontend_sha256"
|
||||||
|
echo "remote_mobile_asset=$remote_mobile_asset"
|
||||||
|
echo "remote_mobile_asset_sha256=$remote_mobile_sha256"
|
||||||
|
[[ "$remote_frontend_sha256" == "$local_frontend_sha256" ]] || fail "remote frontend asset does not match local build"
|
||||||
|
[[ "$remote_mobile_sha256" == "$local_mobile_sha256" ]] || fail "remote mobile H5 asset does not match local build"
|
||||||
|
echo "remote_asset_match=true"
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
echo "release-preflight: read-only checks passed"
|
echo "release-preflight: read-only checks passed"
|
||||||
|
|||||||
Reference in New Issue
Block a user