Repository navigation
将栈空间使用改为无限(避免不正常的RE),将 Docker 镜像发布至 GHCR 并更新 Compose 部署配置 #1213
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
9f05a56
8e5be6c
04b3ee4
8cdc30c
521738b
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,70 @@ | ||
| name: Publish Docker images to GHCR | ||
|
|
||
| on: | ||
| push: | ||
| branches: | ||
| - master | ||
| tags: | ||
| - 'v*' | ||
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| contents: read | ||
| packages: write | ||
|
|
||
| jobs: | ||
| publish: | ||
| name: Build and push ${{ matrix.name }} | ||
| runs-on: ubuntu-latest | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| include: | ||
| - name: backend | ||
| image: hydro-backend | ||
| context: ./install/docker/backend | ||
| - name: judge | ||
| image: hydro-judge | ||
| context: ./install/docker/judge | ||
|
|
||
| steps: | ||
| - name: Check out repository | ||
| uses: actions/checkout@v4 | ||
|
|
||
| - name: Set up QEMU | ||
| uses: docker/setup-qemu-action@v3 | ||
|
|
||
| - name: Set up Docker Buildx | ||
| uses: docker/setup-buildx-action@v3 | ||
|
|
||
| - name: Lowercase GitHub owner for GHCR | ||
| run: echo "OWNER_LC=${GITHUB_REPOSITORY_OWNER,,}" >> "$GITHUB_ENV" | ||
|
|
||
| - name: Log in to GHCR | ||
| uses: docker/login-action@v3 | ||
| with: | ||
| registry: ghcr.io | ||
| username: ${{ github.actor }} | ||
| password: ${{ secrets.GITHUB_TOKEN }} | ||
|
|
||
| - name: Extract Docker metadata | ||
| id: meta | ||
| uses: docker/metadata-action@v5 | ||
| with: | ||
| images: ghcr.io/${{ env.OWNER_LC }}/${{ matrix.image }} | ||
| tags: | | ||
| type=ref,event=branch | ||
| type=ref,event=tag | ||
| type=sha,prefix=sha- | ||
| type=raw,value=latest,enable={{is_default_branch}} | ||
|
|
||
| - name: Build and push ${{ matrix.name }} image | ||
| uses: docker/build-push-action@v6 | ||
| with: | ||
| context: ${{ matrix.context }} | ||
| file: ${{ matrix.context }}/Dockerfile | ||
| push: true | ||
| tags: ${{ steps.meta.outputs.tags }} | ||
| labels: ${{ steps.meta.outputs.labels }} | ||
| cache-from: type=gha,scope=${{ matrix.image }} | ||
| cache-to: type=gha,mode=max,scope=${{ matrix.image }} | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -13,10 +13,12 @@ services: | |
| timeout: 10s | ||
| retries: 5 | ||
| start_period: 30s | ||
|
|
||
| oj-backend: | ||
| build: ./backend | ||
| image: ghcr.io/hydro-dev/hydro-backend:latest | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win ✅ Runtime observed🏁 Script executed: set -eu
printf '%s\n' '--- changed files ---'
git diff --name-only 402509dadfaa1b3dc375dce523c2cc5b5ba2bdc4 8cdc30c74cbaacdd7732a8fbd9a1c37bffc75a3c -- install/docker .github README.md docs 2>/dev/null || true
printf '%s\n' '--- compose diff ---'
git diff --unified=60 402509dadfaa1b3dc375dce523c2cc5b5ba2bdc4 8cdc30c74cbaacdd7732a8fbd9a1c37bffc75a3c -- install/docker/docker-compose.yml
printf '%s\n' '--- GHCR/image references ---'
rg -n -i --glob '!node_modules' --glob '!dist' 'ghcr\.io|docker login|docker/login|packages:write|hydro-backend|hydro-judge|oj-backend|oj-judge' .github install docs README.md 2>/dev/null | head -240
printf '%s\n' '--- candidate files ---'
git ls-files | rg '(^|/)(docker-compose|compose|.*docker.*|.*deploy.*|.*workflow.*|README|readme)' | head -200Repository: hydro-dev/Hydro Length of output: 4139 🤖 get_repo_knowledge executed:
Length of output: 834 🏁 Script executed: set -u
printf '%s\n' '--- GHCR workflow ---'
cat -n .github/workflows/docker-ghcr.yml
printf '%s\n' '--- Docker README ---'
cat -n install/docker/README.md
printf '%s\n' '--- repository auth/deployment references ---'
rg -n -i 'ghcr|docker login|registry|private|public|pull|compose up|docker compose' install/docker .github README.md README-EN.md 2>/dev/null || true
printf '%s\n' '--- GHCR registry probes ---'
for image in hydro-backend hydro-judge; do
echo "### $image"
curl -sS -D - -o /dev/null --max-time 15 "https://ghcr.io/v2/hydro-dev/$image/manifests/latest" 2>&1 | sed -n '1,12p'
doneRepository: hydro-dev/Hydro Length of output: 7834 🏁 Script executed: set -u
for image in hydro-backend hydro-judge; do
echo "### $image"
token_json="$(curl -fsS --max-time 15 "https://ghcr.io/token?service=ghcr.io&scope=repository:hydro-dev/$image:pull" 2>&1)" || {
printf '%s\n' "$token_json"
continue
}
printf '%s\n' "$token_json" | python3 -c 'import json,sys; d=json.load(sys.stdin); print("anonymous_token_returned=" + str(bool(d.get("token") or d.get("access_token"))))'
token="$(printf '%s\n' "$token_json" | python3 -c 'import json,sys; d=json.load(sys.stdin); print(d.get("token") or d.get("access_token") or "")')"
if [ -n "$token" ]; then
curl -sS -D - -o /dev/null --max-time 15 \
-H "Authorization: Bearer $token" \
-H 'Accept: application/vnd.docker.distribution.manifest.v2+json' \
"https://ghcr.io/v2/hydro-dev/$image/manifests/latest" 2>&1 | sed -n '1,12p'
fi
doneRepository: hydro-dev/Hydro Length of output: 285 Make both GHCR packages anonymously pullable or configure deployment authentication. The anonymous GHCR token request returns 🤖 Prompt for AI Agents |
||
| container_name: oj-backend | ||
| restart: always | ||
| pull_policy: always | ||
| depends_on: | ||
| oj-mongo: | ||
| condition: service_healthy | ||
|
|
@@ -33,11 +35,16 @@ services: | |
| retries: 3 | ||
| start_period: 30s | ||
| start_interval: 5s | ||
| ulimits: | ||
| stack: | ||
| soft: -1 | ||
| hard: -1 | ||
|
|
||
| oj-judge: | ||
| build: ./judge | ||
| image: ghcr.io/hydro-dev/hydro-judge:latest | ||
| container_name: oj-judge | ||
| restart: always | ||
| pull_policy: always | ||
| privileged: true | ||
| depends_on: | ||
| oj-backend: | ||
|
|
@@ -46,3 +53,7 @@ services: | |
| volumes: | ||
| - ./judge/judge.yaml:/root/.hydro/judge.yaml | ||
| - ./judge/mount.yaml:/root/.hydro/mount.yaml | ||
| ulimits: | ||
| stack: | ||
| soft: -1 | ||
| hard: -1 | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: hydro-dev/Hydro
Length of output: 2030
🌐 Web query:
docker metadata-action v5 README flavor latest auto type=ref,event=tag💡 Result:
🏁 Script executed:
Repository: hydro-dev/Hydro
Length of output: 4878
🤖 get_repo_knowledge executed:
get_repo_knowledge hydro-dev/Hydro /tmp/coderabbit-repo-knowledge/hydro-dev-hydro-ab2df59dLength of output: 850
Prevent version tags from updating
latest.docker/metadata-action@v5generateslatestfortype=ref,event=tagwhenlatest=auto. The raw entry's default-branch condition does not disable this behavior. Av*tag can therefore update the image consumed by both Compose services. Setflavor: latest=falseso only the conditional raw entry controlslatest.Proposed change
with: images: ghcr.io/${{ env.OWNER_LC }}/${{ matrix.image }} + flavor: latest=false tags: | type=ref,event=branch type=ref,event=tag🤖 Prompt for AI Agents