chore(ci): 新增 tools/push-all.sh —— 一条命令推代码 + 推镜像
- Token 只从 GITEA_TOKEN 环境变量读,不落 .git/config / URL / reflog - 用 -c credential.helper= 屏蔽 GCM:非交互会话里它会挂住等弹窗 - docker login 用 --password-stdin,Token 不进命令行历史 - 支持可选版本 tag:tools/push-all.sh 1.1.0 - DEPLOYMENT.md 补 5.0 节,说明脚本行为与手工推送的替代做法
这个提交包含在:
+23
-2
@@ -200,9 +200,30 @@ server {
|
||||
|
||||
---
|
||||
|
||||
## 五、把镜像推到 Gitea 注册表
|
||||
## 五、把代码与镜像推到 Gitea
|
||||
|
||||
Gitea 自带容器注册表(`registry/2.0`)。目标是 `git.iwali.top/wangchuanli/workbuddy-portal`。
|
||||
Gitea 自带容器注册表(`registry/2.0`)。代码仓库与镜像的目标都是 `git.iwali.top/wangchuanli/workbuddy-portal`。
|
||||
|
||||
### 5.0 一条命令推代码 + 推镜像
|
||||
|
||||
准备好 Gitea **Access Token**(「设置 → 应用 → 生成令牌」,勾选 `repo` + `write:package`)后:
|
||||
|
||||
```bash
|
||||
export GITEA_TOKEN=<你的令牌>
|
||||
tools/push-all.sh # 推 main 分支 + 镜像 latest
|
||||
tools/push-all.sh 1.1.0 # 同时打一个版本 tag 并推送
|
||||
```
|
||||
|
||||
脚本做的事:
|
||||
|
||||
1. `git push origin main` —— 用 `http.extraHeader` 传 Basic 认证,Token **只在环境变量里**,
|
||||
不会写进 `.git/config`、URL 或 reflog;同时用 `-c credential.helper=` 屏蔽凭据助手
|
||||
(否则在非交互 / 无桌面会话里 Git Credential Manager 会挂住等弹窗)。
|
||||
2. `docker compose build` —— 镜像名本身就是注册表地址。
|
||||
3. `docker login` + `docker push`(`--password-stdin`,Token 不进命令行历史)。
|
||||
|
||||
> 不用脚本、手工推也行:`git push origin main` 弹出凭据窗口时,
|
||||
> 用户名填 `wangchuanli`,**密码处填 Access Token**(不是网页登录密码)。
|
||||
|
||||
### 5.1 准备:本机允许 HTTP 注册表
|
||||
|
||||
|
||||
在新工单中引用
屏蔽一个用户