From d08d3fb9214ba662e0d9d78dfdcde8cc2412c0cc Mon Sep 17 00:00:00 2001 From: key Date: Wed, 29 Jul 2026 15:25:08 +0800 Subject: [PATCH] fix(release): wait for backend readiness --- scripts/release-backend.sh | 22 +++++++++++++++++--- scripts/tests/release-backend-safety.test.sh | 3 +++ 2 files changed, 22 insertions(+), 3 deletions(-) diff --git a/scripts/release-backend.sh b/scripts/release-backend.sh index 5759ef4c..2fc3c421 100644 --- a/scripts/release-backend.sh +++ b/scripts/release-backend.sh @@ -9,6 +9,7 @@ REMOTE_URL="https://peilian.njzhmj.top" REMOTE_BACKUP_ROOT="/opt/wygj/backups" PREFLIGHT_SCRIPT="$ROOT_DIR/scripts/release-preflight.sh" MIN_FREE_RESERVE_BYTES=$((512 * 1024 * 1024)) +PUBLIC_HEALTH_READY_TIMEOUT_SECONDS=90 fail() { echo "release-backend: $*" >&2 @@ -272,6 +273,19 @@ run_public_health() { } } +wait_for_public_health() { + local deadline=$((SECONDS + PUBLIC_HEALTH_READY_TIMEOUT_SECONDS)) + while ((SECONDS < deadline)); do + if run_public_health >/dev/null 2>&1; then + echo "release-backend: public endpoints are ready" + return 0 + fi + sleep 2 + done + echo "release-backend: public endpoints did not become ready within ${PUBLIC_HEALTH_READY_TIMEOUT_SECONDS}s" >&2 + run_public_health +} + run_deploy_plan() { validate_local_artifact inspect_remote_target @@ -420,6 +434,8 @@ perform_deploy() { restore_remote_backup \ "$backup_path/ruoyi-admin.jar" "$remote_current_sha256" "$artifact_sha256" \ || fail "automatic restore failed; use the recorded backup immediately: $backup_path" + wait_for_public_health \ + || fail "candidate activation failed; the original backend was restored but did not become ready" fail "candidate activation failed and the original backend was restored" ;; "$remote_current_sha256") @@ -431,7 +447,7 @@ perform_deploy() { esac fi - if ! run_post_deploy_preflight; then + if ! wait_for_public_health || ! run_post_deploy_preflight; then after_failure_sha="$(get_remote_target_sha)" \ || fail "post-deploy preflight failed and the current target hash is unreadable; inspect $backup_path" case "$after_failure_sha" in @@ -440,7 +456,7 @@ perform_deploy() { restore_remote_backup \ "$backup_path/ruoyi-admin.jar" "$remote_current_sha256" "$artifact_sha256" \ || fail "automatic restore failed; use the recorded backup immediately: $backup_path" - run_public_health \ + wait_for_public_health \ || fail "original backend was restored but public health verification failed" fail "post-deploy preflight failed and the original backend was restored" ;; @@ -552,7 +568,7 @@ REMOTE_ROLLBACK_SAFETY ;; esac fi - if ! run_public_health; then + if ! wait_for_public_health; then after_failure_sha="$(get_remote_target_sha)" \ || fail "rollback health failed and the current target hash is unreadable; inspect $safety_path" case "$after_failure_sha" in diff --git a/scripts/tests/release-backend-safety.test.sh b/scripts/tests/release-backend-safety.test.sh index 8da9b52d..318ce445 100644 --- a/scripts/tests/release-backend-safety.test.sh +++ b/scripts/tests/release-backend-safety.test.sh @@ -118,6 +118,9 @@ grep -Fq 'require_approval "DEPLOY_BACKEND:$expected_sha256"' "$SCRIPT" grep -Fq 'require_approval "ROLLBACK_BACKEND:$expected_sha256"' "$SCRIPT" grep -Fq 'deploy and rollback require a clean Git worktree' "$SCRIPT" grep -Fq 'run_post_deploy_preflight' "$SCRIPT" +grep -Fq 'PUBLIC_HEALTH_READY_TIMEOUT_SECONDS=90' "$SCRIPT" +grep -Fq 'wait_for_public_health' "$SCRIPT" +grep -Fq 'if ! wait_for_public_health || ! run_post_deploy_preflight; then' "$SCRIPT" grep -Fq 'post-deploy preflight failed; restoring' "$SCRIPT" grep -Fq 'rollback health failed; restoring safety copy' "$SCRIPT" grep -Fq 'expected_target_sha="$5"' "$SCRIPT"