docs(diagrams): 新增凭证调度状态机图 #160
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| jobs: | |
| backend: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 | |
| - uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5 | |
| - run: uv sync --frozen | |
| - name: Ruff | |
| run: uv run ruff check src tests scripts | |
| - name: 测试与覆盖率(门槛 100%) | |
| run: uv run pytest -q --cov=src --cov-report=term --cov-fail-under=100 | |
| frontend: | |
| runs-on: ubuntu-latest | |
| defaults: | |
| run: | |
| working-directory: web | |
| steps: | |
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 | |
| - uses: pnpm/action-setup@b906affcce14559ad1aafd4ab0e942779e9f58b1 # v4 | |
| with: | |
| version: 10 | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 | |
| with: | |
| node-version: 24 | |
| cache: pnpm | |
| cache-dependency-path: web/pnpm-lock.yaml | |
| - run: pnpm install --frozen-lockfile | |
| - run: pnpm exec tsc --noEmit | |
| - run: pnpm exec vitest run | |
| - run: pnpm build | |
| compose: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 | |
| - name: 校验 compose 语法 | |
| run: docker compose config --quiet | |
| env: | |
| APP_SECRET: ci-placeholder-secret | |
| - name: 构建镜像并启动(验证 compose 可真实运行) | |
| run: | | |
| mkdir -p data secrets | |
| # 容器以 uid 1001 (appuser) 运行,挂载目录必须可写, | |
| # 否则 SQLite 打不开、服务崩溃重启,health 永远不通 | |
| sudo chown -R 1001:1001 data secrets | |
| docker build -t coding2api:ci . | |
| # 用户名必须是 admin:compose 的 ADMIN_USERNAMES 默认 admin, | |
| # B5 引导要求至少一个活跃 admin,否则启动直接 Traceback。 | |
| printf 'admin:%s\n' "$(docker run --rm coding2api:ci python -c 'from src.auth.users import create_password_hash;print(create_password_hash("cipw"))')" > secrets/users.txt | |
| # --build 必须带:否则 compose 会去 registry 拉 image: 指向的已发布镜像, | |
| # 测的就不是本次构建的代码了(曾因此长期静默通过)。 | |
| APP_SECRET=ci-placeholder-secret docker compose up -d --build | |
| # 120s:启动预热会真连上游拉模型列表(zen 免费层还要逐个探活)。 | |
| for _ in $(seq 1 60); do | |
| if curl -fsS http://127.0.0.1:8000/health >/dev/null; then break; fi | |
| sleep 2 | |
| done | |
| # 失败排查线索:容器日志(含启动 Traceback) | |
| docker logs coding2api --tail 80 | |
| curl -fsS http://127.0.0.1:8000/health | |
| APP_SECRET=ci-placeholder-secret docker compose down |