diff --git a/.github/workflows/pr-batch-test-deploy.yml b/.github/workflows/pr-batch-test-deploy.yml index c908ba64..5a9848ce 100644 --- a/.github/workflows/pr-batch-test-deploy.yml +++ b/.github/workflows/pr-batch-test-deploy.yml @@ -63,6 +63,47 @@ jobs: [[ -n "${TEST_RUNTIME_SSH_HOST}" ]] || { echo "::error::Missing secret TEST_RUNTIME_SSH_HOST"; exit 1; } [[ -n "${TEST_RUNTIME_SSH_KEY}" ]] || { echo "::error::Missing secret TEST_RUNTIME_SSH_KEY"; exit 1; } + - name: Prepare deploy key + id: ssh + env: + TEST_RUNTIME_SSH_KEY: ${{ secrets.TEST_RUNTIME_SSH_KEY }} + run: | + key_file="${RUNNER_TEMP}/test-runtime.key" + printf '%s\n' "${TEST_RUNTIME_SSH_KEY}" > "${key_file}" + chmod 600 "${key_file}" + echo "key_file=${key_file}" >> "${GITHUB_OUTPUT}" + + - name: Preflight HK deploy helper + env: + TEST_RUNTIME_SSH_HOST: ${{ secrets.TEST_RUNTIME_SSH_HOST }} + TEST_RUNTIME_SSH_USER: ${{ secrets.TEST_RUNTIME_SSH_USER }} + TEST_RUNTIME_SSH_PORT: ${{ secrets.TEST_RUNTIME_SSH_PORT }} + PUBLIC_URL: ${{ inputs.public_url }} + WEB_BASE_PATH: ${{ inputs.web_base_path }} + run: | + if [[ -z "${PUBLIC_URL}" && -z "${WEB_BASE_PATH}" ]]; then + exit 0 + fi + + ssh_port="${TEST_RUNTIME_SSH_PORT:-22}" + ssh_user="${TEST_RUNTIME_SSH_USER:-skillhub-deploy}" + helper_help="$(ssh \ + -i "${{ steps.ssh.outputs.key_file }}" \ + -o BatchMode=yes \ + -o IdentitiesOnly=yes \ + -o StrictHostKeyChecking=accept-new \ + -o ConnectTimeout=10 \ + -p "${ssh_port}" \ + "${ssh_user}@${TEST_RUNTIME_SSH_HOST}" \ + 'sudo /usr/local/bin/skillhub-test-deploy --help' 2>&1 || true)" + + if ! grep -Fq -- "--public-url" <<<"${helper_help}" || \ + ! grep -Fq -- "--web-base-path" <<<"${helper_help}"; then + echo "::error::HK deploy helper is outdated. Install scripts/skillhub-test-deploy-remote.sh to /usr/local/bin/skillhub-test-deploy before sub-path validation." + echo "${helper_help}" + exit 1 + fi + - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 @@ -128,16 +169,6 @@ jobs: cache-from: type=gha,scope=manual-test-scanner cache-to: type=gha,mode=max,scope=manual-test-scanner - - name: Prepare deploy key - id: ssh - env: - TEST_RUNTIME_SSH_KEY: ${{ secrets.TEST_RUNTIME_SSH_KEY }} - run: | - key_file="${RUNNER_TEMP}/test-runtime.key" - printf '%s\n' "${TEST_RUNTIME_SSH_KEY}" > "${key_file}" - chmod 600 "${key_file}" - echo "key_file=${key_file}" >> "${GITHUB_OUTPUT}" - - name: Deploy batch images to HK test runtime env: TEST_RUNTIME_SSH_HOST: ${{ secrets.TEST_RUNTIME_SSH_HOST }} diff --git a/docs/pr-batch-test-runtime.md b/docs/pr-batch-test-runtime.md index 0bb3db95..078c591b 100644 --- a/docs/pr-batch-test-runtime.md +++ b/docs/pr-batch-test-runtime.md @@ -17,11 +17,11 @@ When you trigger the workflow manually, it: 3. verifies that every PR is still open and targets the chosen base branch 4. merges the selected PR heads onto the base branch in the exact order you supplied 5. fails fast if any PR conflicts with the base branch or with an earlier PR in the batch -6. builds `server`, `web`, and `scanner` images for `linux/amd64` -7. pushes both a floating tag and an immutable tag to GHCR -8. SSHes into the HK test machine as a dedicated deploy user -9. updates the selected non-secret runtime fields in `/opt/skillhub-runtime/.env.release` -10. calls a root-owned deployment wrapper through `sudo` +6. SSHes into the HK test machine as a dedicated deploy user and checks the remote helper version +7. builds `server`, `web`, and `scanner` images for `linux/amd64` +8. pushes both a floating tag and an immutable tag to GHCR +9. calls a root-owned deployment wrapper through `sudo` +10. updates the selected non-secret runtime fields in `/opt/skillhub-runtime/.env.release` 11. runs `docker compose pull && docker compose up -d` through the remote wrapper The floating tag is the shared environment channel. By default it is