fix(scanner): align deployment health checks and upload limits

Signed-off-by: dongmucat <1127093059@qq.com>
This commit is contained in:
dongmucat 2026-09-18 10:39:55 +08:00
parent 9bbadca31b
commit 475c49702c
9 changed files with 63 additions and 3 deletions

37
.github/workflows/pr-scanner-image.yml vendored Normal file
View file

@ -0,0 +1,37 @@
name: PR Scanner Image
on:
pull_request:
paths:
- 'scanner/**'
- 'scripts/tests/scanner-2-1-contract-test.sh'
- '.github/workflows/pr-scanner-image.yml'
permissions:
contents: read
jobs:
scanner-contract:
name: Scanner contract (${{ matrix.arch }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
arch: [amd64, arm64]
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3
- name: Build scanner image
uses: docker/build-push-action@v6
with:
context: scanner
platforms: linux/${{ matrix.arch }}
tags: skillhub-scanner-contract:${{ matrix.arch }}-${{ github.sha }}
load: true
- name: Run scanner contract
env:
SCANNER_IMAGE: skillhub-scanner-contract:${{ matrix.arch }}-${{ github.sha }}
run: bash scripts/tests/scanner-2-1-contract-test.sh

View file

@ -4,9 +4,16 @@ on:
pull_request:
paths:
- 'scripts/**'
- 'scanner/**'
- 'docker-compose.yml'
- '.env.release.example'
- '.env.release.draft'
- 'compose.release.yml'
- 'deploy/k8s/base/configmap.yaml'
- 'deploy/k8s/base/scanner-deployment.yaml'
- 'charts/skillhub/values.yaml'
- 'charts/skillhub/values.schema.json'
- 'charts/skillhub/templates/scanner-deployment.yaml'
- 'server/Dockerfile'
- 'Makefile'
- 'web/Dockerfile'
@ -36,6 +43,10 @@ jobs:
- uses: actions/setup-node@v4
with:
node-version: '21'
- uses: actions/setup-python@v5
with:
python-version: '3.11'
- run: python -m unittest discover -s scanner/tests -p 'test_*.py'
- run: bash scripts/tests/publish-cli-test.sh
- run: bash scripts/tests/runtime-secret-test.sh
- run: bash scripts/tests/validate-release-config-test.sh

View file

@ -56,6 +56,8 @@ spec:
{{- with .Values.scanner.extraEnv }}
{{- toYaml . | nindent 12 }}
{{- end }}
- name: SKILLHUB_SCANNER_MAX_UPLOAD_SIZE_BYTES
value: {{ .Values.scanner.maxUploadSizeBytes | quote }}
resources:
{{- toYaml .Values.scanner.resources | nindent 12 }}
readinessProbe:

View file

@ -462,10 +462,11 @@
{
"type": "object",
"additionalProperties": false,
"required": ["enabled", "replicaCount", "image", "service", "resources", "extraEnv", "podAnnotations", "imagePullSecrets", "nodeSelector", "tolerations", "affinity", "probes", "autoscaling", "podDisruptionBudget"],
"required": ["enabled", "replicaCount", "maxUploadSizeBytes", "image", "service", "resources", "extraEnv", "podAnnotations", "imagePullSecrets", "nodeSelector", "tolerations", "affinity", "probes", "autoscaling", "podDisruptionBudget"],
"properties": {
"enabled": { "type": "boolean" },
"replicaCount": { "type": "integer", "minimum": 1 },
"maxUploadSizeBytes": { "type": "integer", "minimum": 1 },
"image": { "$ref": "#/definitions/image" },
"service": {
"type": "object",

View file

@ -433,6 +433,7 @@ web:
scanner:
enabled: true
replicaCount: 1
maxUploadSizeBytes: 110100480
image:
registry: ""
tag: ""

View file

@ -8,8 +8,9 @@ services:
SKILL_SCANNER_LLM_MODEL: ${SKILL_SCANNER_LLM_MODEL:-}
SKILLHUB_SCANNER_MAX_CONCURRENT_SCANS: ${SKILLHUB_SCANNER_MAX_CONCURRENT_SCANS:-1}
SKILLHUB_SCANNER_HARD_TIMEOUT_SECONDS: ${SKILLHUB_SCANNER_HARD_TIMEOUT_SECONDS:-930}
SKILLHUB_SCANNER_MAX_UPLOAD_SIZE_BYTES: ${SKILLHUB_SCANNER_MAX_UPLOAD_SIZE_BYTES:-110100480}
healthcheck:
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8000/health"]
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/health', timeout=2).read()"]
interval: 10s
timeout: 5s
retries: 10

View file

@ -39,6 +39,7 @@ data:
skill-scan-reclaim-min-idle: PT16M
skill-scanner-max-concurrent-scans: "1"
skill-scanner-hard-timeout-seconds: "930"
skill-scanner-max-upload-size-bytes: "110100480"
# Bootstrap 管理员配置(非敏感)
bootstrap-admin-enabled: "true"

View file

@ -50,6 +50,11 @@ spec:
configMapKeyRef:
name: skillhub-config
key: skill-scanner-hard-timeout-seconds
- name: SKILLHUB_SCANNER_MAX_UPLOAD_SIZE_BYTES
valueFrom:
configMapKeyRef:
name: skillhub-config
key: skill-scanner-max-upload-size-bytes
readinessProbe:
httpGet:
path: /health

View file

@ -7,8 +7,9 @@ services:
SKILL_SCANNER_LLM_API_KEY: ${SKILL_SCANNER_LLM_API_KEY:-}
SKILL_SCANNER_LLM_BASE_URL: ${SKILL_SCANNER_LLM_BASE_URL:-}
SKILL_SCANNER_LLM_MODEL: ${SKILL_SCANNER_LLM_MODEL:-}
SKILLHUB_SCANNER_MAX_UPLOAD_SIZE_BYTES: ${SKILLHUB_SCANNER_MAX_UPLOAD_SIZE_BYTES:-110100480}
healthcheck:
test: ["CMD", "wget", "-qO-", "http://127.0.0.1:8000/health"]
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/health', timeout=2).read()"]
interval: 10s
timeout: 5s
retries: 5