fix(release): support backend-only verification
This commit is contained in:
+3
-1
@@ -171,9 +171,11 @@ RELEASE_REMOTE_URL=https://peilian.njzhmj.top ./scripts/release-preflight.sh
|
||||
RELEASE_REMOTE_URL=https://peilian.njzhmj.top RELEASE_VERIFY_REMOTE_MATCH=true ./scripts/release-preflight.sh
|
||||
# 同时校验线上 schema、资料处理连接 SQL 与后端 jar;后端发布验收不得省略 schema 门禁
|
||||
RELEASE_REMOTE_URL=https://peilian.njzhmj.top RELEASE_VERIFY_REMOTE_MATCH=true RELEASE_VERIFY_REMOTE_SCHEMA=true RELEASE_VERIFY_REMOTE_BACKEND=true ./scripts/release-preflight.sh
|
||||
# 仅发布后端时,显式跳过未发布的管理端/H5 hash;后端模块和 schema 仍会严格校验
|
||||
RELEASE_REMOTE_URL=https://peilian.njzhmj.top RELEASE_VERIFY_REMOTE_MATCH=true RELEASE_VERIFY_REMOTE_STATIC=false RELEASE_VERIFY_REMOTE_SCHEMA=true RELEASE_VERIFY_REMOTE_BACKEND=true ./scripts/release-preflight.sh
|
||||
```
|
||||
|
||||
`RELEASE_VERIFY_REMOTE_BACKEND=true` 必须与 `RELEASE_VERIFY_REMOTE_MATCH=true`、`RELEASE_VERIFY_REMOTE_SCHEMA=true` 同时使用;预检会同时打印整包 jar SHA-256 和 `ruoyi-aihr` 模块内容 SHA-256,实际匹配以模块内容 hash 为准。schema 门禁会拒绝 AIHR 与框架租户字段排序规则不一致,并执行资料处理页依赖的 `aihr_knowledge_attach`/`sys_oss` 连接检查。远端后端默认核对 `/opt/wygj/app/ruoyi-admin.jar`,如发布路径不同可通过 `RELEASE_REMOTE_BACKEND_PATH` 覆盖;路径必须是安全的绝对路径。
|
||||
`RELEASE_VERIFY_REMOTE_BACKEND=true` 必须与 `RELEASE_VERIFY_REMOTE_MATCH=true`、`RELEASE_VERIFY_REMOTE_SCHEMA=true` 同时使用;预检会同时打印整包 jar SHA-256 和 `ruoyi-aihr` 模块内容 SHA-256,实际匹配以模块内容 hash 为准。schema 门禁会拒绝 AIHR 与框架租户字段排序规则不一致,并执行资料处理页依赖的 `aihr_knowledge_attach`/`sys_oss` 连接检查。`RELEASE_VERIFY_REMOTE_STATIC=false` 只允许用于后端单组件发布,避免用未发布的本地静态包覆盖或阻断线上前端;默认仍严格核对管理端和 H5。远端后端默认核对 `/opt/wygj/app/ruoyi-admin.jar`,如发布路径不同可通过 `RELEASE_REMOTE_BACKEND_PATH` 覆盖;路径必须是安全的绝对路径。
|
||||
|
||||
带 `RELEASE_REMOTE_URL` 时,预检同时校验租户接口 JSON 的业务 `code=200`;HTTP 200 但业务返回 401/405 会判定失败。
|
||||
|
||||
|
||||
@@ -217,22 +217,26 @@ if [[ -n "${RELEASE_REMOTE_URL:-}" ]]; then
|
||||
fi
|
||||
|
||||
if [[ "${RELEASE_VERIFY_REMOTE_MATCH:-false}" == "true" ]]; then
|
||||
remote_frontend_asset="$(curl -fsS --max-time 15 "$remote/" | sed -nE 's/.*src="(\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)"
|
||||
remote_mobile_asset="$(curl -fsS --max-time 15 "$remote/h5/" | sed -nE 's/.*src="(\/h5\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)"
|
||||
[[ "$remote_frontend_asset" == /assets/*.js ]] || fail "remote frontend entry asset not found"
|
||||
[[ "$remote_mobile_asset" == /h5/assets/*.js ]] || fail "remote mobile H5 entry asset not found"
|
||||
if [[ "${RELEASE_VERIFY_REMOTE_STATIC:-true}" == "true" ]]; then
|
||||
remote_frontend_asset="$(curl -fsS --max-time 15 "$remote/" | sed -nE 's/.*src="(\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)"
|
||||
remote_mobile_asset="$(curl -fsS --max-time 15 "$remote/h5/" | sed -nE 's/.*src="(\/h5\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)"
|
||||
[[ "$remote_frontend_asset" == /assets/*.js ]] || fail "remote frontend entry asset not found"
|
||||
[[ "$remote_mobile_asset" == /h5/assets/*.js ]] || fail "remote mobile H5 entry asset not found"
|
||||
|
||||
remote_frontend_sha256="$(curl -fsS --max-time 15 "$remote$remote_frontend_asset" | sha256_stream)"
|
||||
remote_mobile_sha256="$(curl -fsS --max-time 15 "$remote$remote_mobile_asset" | sha256_stream)"
|
||||
local_frontend_sha256="$(sha256 "$frontend_asset_path")"
|
||||
local_mobile_sha256="$(sha256 "$mobile_asset_path")"
|
||||
echo "remote_frontend_asset=$remote_frontend_asset"
|
||||
echo "remote_frontend_asset_sha256=$remote_frontend_sha256"
|
||||
echo "remote_mobile_asset=$remote_mobile_asset"
|
||||
echo "remote_mobile_asset_sha256=$remote_mobile_sha256"
|
||||
[[ "$remote_frontend_sha256" == "$local_frontend_sha256" ]] || fail "remote frontend asset does not match local build"
|
||||
[[ "$remote_mobile_sha256" == "$local_mobile_sha256" ]] || fail "remote mobile H5 asset does not match local build"
|
||||
echo "remote_asset_match=true"
|
||||
remote_frontend_sha256="$(curl -fsS --max-time 15 "$remote$remote_frontend_asset" | sha256_stream)"
|
||||
remote_mobile_sha256="$(curl -fsS --max-time 15 "$remote$remote_mobile_asset" | sha256_stream)"
|
||||
local_frontend_sha256="$(sha256 "$frontend_asset_path")"
|
||||
local_mobile_sha256="$(sha256 "$mobile_asset_path")"
|
||||
echo "remote_frontend_asset=$remote_frontend_asset"
|
||||
echo "remote_frontend_asset_sha256=$remote_frontend_sha256"
|
||||
echo "remote_mobile_asset=$remote_mobile_asset"
|
||||
echo "remote_mobile_asset_sha256=$remote_mobile_sha256"
|
||||
[[ "$remote_frontend_sha256" == "$local_frontend_sha256" ]] || fail "remote frontend asset does not match local build"
|
||||
[[ "$remote_mobile_sha256" == "$local_mobile_sha256" ]] || fail "remote mobile H5 asset does not match local build"
|
||||
echo "remote_asset_match=true"
|
||||
else
|
||||
echo "remote_static_match=skipped"
|
||||
fi
|
||||
|
||||
if [[ "${RELEASE_VERIFY_REMOTE_BACKEND:-false}" == "true" ]]; then
|
||||
command -v ssh >/dev/null 2>&1 || fail "ssh is required for remote backend verification"
|
||||
|
||||
Reference in New Issue
Block a user