ops: keep production SSH sessions alive
Staging Backend Quality Gate / validate (push) Successful in 10m16s
Staging Backend Quality Gate / publish (push) Successful in 2m8s

This commit is contained in:
Jesse_Chen
2026-08-10 16:17:41 +08:00
parent a0f8118e32
commit 455917a870
3 changed files with 4 additions and 2 deletions
+1 -1
View File
@@ -322,7 +322,7 @@ jobs:
printf '%s\n' "$PRODUCTION_KNOWN_HOSTS" | tr -d '\r' > "$known_hosts_path"
chmod 600 "$key_path" "$known_hosts_path"
ssh-keygen -y -f "$key_path" >/dev/null
ssh_options=(-i "$key_path" -p "$DEPLOY_PORT" -o BatchMode=yes -o IdentitiesOnly=yes -o StrictHostKeyChecking=yes -o "UserKnownHostsFile=$known_hosts_path")
ssh_options=(-i "$key_path" -p "$DEPLOY_PORT" -o BatchMode=yes -o IdentitiesOnly=yes -o ServerAliveInterval=15 -o ServerAliveCountMax=4 -o StrictHostKeyChecking=yes -o "UserKnownHostsFile=$known_hosts_path")
remote="$DEPLOY_USER@$DEPLOY_HOST"
require_current_release_heads() {
[[ "$ALLOW_ROLLBACK" == true ]] && return
@@ -302,7 +302,7 @@ jobs:
printf '%s\n' "$PRODUCTION_KNOWN_HOSTS" | tr -d '\r' > "$known_hosts_path"
chmod 600 "$key_path" "$known_hosts_path"
ssh-keygen -y -f "$key_path" >/dev/null
ssh_options=(-i "$key_path" -p "$DEPLOY_PORT" -o BatchMode=yes -o IdentitiesOnly=yes -o StrictHostKeyChecking=yes -o "UserKnownHostsFile=$known_hosts_path")
ssh_options=(-i "$key_path" -p "$DEPLOY_PORT" -o BatchMode=yes -o IdentitiesOnly=yes -o ServerAliveInterval=15 -o ServerAliveCountMax=4 -o StrictHostKeyChecking=yes -o "UserKnownHostsFile=$known_hosts_path")
remote="$DEPLOY_USER@$DEPLOY_HOST"
require_current_release_heads() {
current_staging="$(curl --fail --silent --show-error --connect-timeout 15 --max-time 60 --retry 3 --retry-all-errors \
@@ -967,6 +967,7 @@ test("Gitea production deploy consumes only gate-attested digests under manual c
assert.match(workflow, /bash '\$incoming\/deploy\/run-production-deploy\.sh'/);
assert.match(workflow, /docker ps -aq[^\n]*com\.docker\.compose\.service=web/);
assert.match(workflow, /state-present-without-container/);
assert.match(workflow, /ServerAliveInterval=15.*ServerAliveCountMax=4/);
assert.doesNotMatch(workflow, /then cat \"\\\$state\\\"/);
assert.doesNotMatch(workflow, /docker compose[^\n]*build|db:migrate/);
});
@@ -1045,6 +1046,7 @@ test("Gitea production schema migration is exact-SHA gated and isolated from ETL
assert.match(workflow, /run-production-migration\.sh/);
assert.match(workflow, /docker ps -aq[^\n]*com\.docker\.compose\.service=web/);
assert.match(workflow, /state-present-without-container/);
assert.match(workflow, /ServerAliveInterval=15.*ServerAliveCountMax=4/);
assert.doesNotMatch(workflow, /then cat "\\\$state\\"/);
assert.doesNotMatch(workflow, /migrate-supabase-production|run-production-deploy|verification_mode|PRODUCTION_URL|CADDY/);