Jenkinsfile 5.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169
  1. pipeline {
  2. agent any
  3. options {
  4. buildDiscarder(logRotator(numToKeepStr: '5'))
  5. timestamps()
  6. }
  7. parameters {
  8. string(name: 'BRANCH', defaultValue: 'uat', description: '要部署到UAT的分支')
  9. booleanParam(name: 'SKIP_APPROVAL', defaultValue: false, description: '跳过人工审批(谨慎使用)')
  10. }
  11. environment {
  12. // UAT 代码检出目录
  13. CHECKOUT_BASE = "/docker/python-uat"
  14. CODE_DIR = "/docker/python-uat"
  15. // Dockerfile 路径
  16. DOCKERFILE_STORE = "alien_store/Dockerfile"
  17. DOCKERFILE_GATEWAY = "alien_gateway/Dockerfile"
  18. DOCKERFILE_CONTRACT = "alien_contract/Dockerfile"
  19. // 如需推送远端 Registry,填写地址,否则留空
  20. REGISTRY = ""
  21. REGISTRY_CRED = "registry-cred-id"
  22. // 镜像标签统一使用 uat
  23. IMAGE_STORE = "${REGISTRY ? REGISTRY + '/alien_store:uat-' + env.BUILD_NUMBER : 'alien_store:uat'}"
  24. IMAGE_GATEWAY = "${REGISTRY ? REGISTRY + '/alien_gateway:uat-' + env.BUILD_NUMBER : 'alien_gateway:uat'}"
  25. IMAGE_CONTRACT = "${REGISTRY ? REGISTRY + '/alien_contract:uat-' + env.BUILD_NUMBER : 'alien_contract:uat'}"
  26. // 容器名(store 不要再用 esign-uat,会和真正的 e签宝容器撞名)
  27. CONTAINER_NAME_STORE = "alien_store_py-uat"
  28. CONTAINER_NAME_GATEWAY = "alien_gateway_py-uat"
  29. CONTAINER_NAME_CONTRACT = "alien_contract_py-uat"
  30. // 容器内端口(必须与各服务 Dockerfile 中 uvicorn 监听端口一致)
  31. PORT_STORE = "8001"
  32. PORT_GATEWAY = "43333"
  33. PORT_CONTRACT = "8002"
  34. // 使用独立的 UAT 网络
  35. DOCKER_NET = "alien_net_uat"
  36. // UAT 日志目录
  37. LOG_ROOT = "/docker/python-uat/logs"
  38. }
  39. stages {
  40. stage('Checkout') {
  41. steps {
  42. echo ">>> UAT环境:拉取分支 ${params.BRANCH} 到 ${CHECKOUT_BASE} ..."
  43. sh "mkdir -p ${CHECKOUT_BASE}"
  44. dir("${CHECKOUT_BASE}") {
  45. git branch: "${params.BRANCH}",
  46. credentialsId: 'gogs-alien-cloud-uat',
  47. url: 'http://8.152.195.41:3000/alien/alien_py_cloud'
  48. }
  49. }
  50. }
  51. stage('人工审批') {
  52. when {
  53. expression { !params.SKIP_APPROVAL }
  54. }
  55. steps {
  56. script {
  57. def userInput = input(
  58. id: 'UATDeployConfirm',
  59. message: "是否将分支 ${params.BRANCH} 部署到 UAT 环境?",
  60. ok: '确认部署',
  61. submitter: 'admin,release-manager',
  62. parameters: [
  63. booleanParam(name: 'CONFIRM', defaultValue: true, description: '我确认部署到UAT')
  64. ]
  65. )
  66. }
  67. }
  68. }
  69. stage('Build Images') {
  70. steps {
  71. script {
  72. if (env.REGISTRY?.trim()) {
  73. withDockerRegistry(credentialsId: env.REGISTRY_CRED, url: "") {
  74. dir(env.CODE_DIR) {
  75. sh "docker build -f ${DOCKERFILE_STORE} -t ${IMAGE_STORE} ."
  76. sh "docker build -f ${DOCKERFILE_GATEWAY} -t ${IMAGE_GATEWAY} ."
  77. sh "docker build -f ${DOCKERFILE_CONTRACT} -t ${IMAGE_CONTRACT} ."
  78. }
  79. }
  80. } else {
  81. dir(env.CODE_DIR) {
  82. sh "docker build -f ${DOCKERFILE_STORE} -t ${IMAGE_STORE} ."
  83. sh "docker build -f ${DOCKERFILE_GATEWAY} -t ${IMAGE_GATEWAY} ."
  84. sh "docker build -f ${DOCKERFILE_CONTRACT} -t ${IMAGE_CONTRACT} ."
  85. }
  86. }
  87. }
  88. }
  89. }
  90. stage('Push Images') {
  91. when { expression { return env.REGISTRY?.trim() as boolean } }
  92. steps {
  93. withDockerRegistry(credentialsId: env.REGISTRY_CRED, url: "") {
  94. sh "docker push ${IMAGE_STORE}"
  95. sh "docker push ${IMAGE_GATEWAY}"
  96. sh "docker push ${IMAGE_CONTRACT}"
  97. }
  98. }
  99. }
  100. stage('Deploy') {
  101. steps {
  102. script {
  103. echo ">>> UAT 部署镜像: ${IMAGE_STORE} / ${IMAGE_GATEWAY} / ${IMAGE_CONTRACT}"
  104. sh """
  105. # 创建 UAT 专用网络
  106. docker network create ${DOCKER_NET} 2>/dev/null || true
  107. # 创建日志目录
  108. mkdir -p ${LOG_ROOT}/store ${LOG_ROOT}/gateway ${LOG_ROOT}/contract
  109. # 停止旧容器(不会误删 java 的 gateway-uat / store-uat / 真正的 esign-uat 等)
  110. docker rm -f ${CONTAINER_NAME_STORE} ${CONTAINER_NAME_GATEWAY} ${CONTAINER_NAME_CONTRACT} 2>/dev/null || true
  111. # 1) 先启动下游:store
  112. # 只走 docker 内部网络,不向宿主机暴露端口(避免与 java gateway-uat 抢 8001)
  113. docker run -d --name ${CONTAINER_NAME_STORE} \\
  114. --network ${DOCKER_NET} \\
  115. -v ${LOG_ROOT}/store:/app/common/logs/alien_store \\
  116. --restart unless-stopped \\
  117. ${IMAGE_STORE}
  118. # 2) 再启动下游:contract
  119. # 只走 docker 内部网络,不向宿主机暴露端口
  120. docker run -d --name ${CONTAINER_NAME_CONTRACT} \\
  121. --network ${DOCKER_NET} \\
  122. -v ${LOG_ROOT}/contract:/app/common/logs/alien_contract \\
  123. --restart unless-stopped \\
  124. ${IMAGE_CONTRACT}
  125. # 3) 最后启动网关:gateway(依赖上面两个下游;唯一对外暴露的入口)
  126. docker run -d --name ${CONTAINER_NAME_GATEWAY} \\
  127. --network ${DOCKER_NET} \\
  128. -p ${PORT_GATEWAY}:${PORT_GATEWAY} \\
  129. -v ${LOG_ROOT}/gateway:/app/common/logs/alien_gateway \\
  130. -e STORE_BASE_URL=http://${CONTAINER_NAME_STORE}:${PORT_STORE} \\
  131. -e CONTRACT_BASE_URL=http://${CONTAINER_NAME_CONTRACT}:${PORT_CONTRACT} \\
  132. --restart unless-stopped \\
  133. ${IMAGE_GATEWAY}
  134. """
  135. }
  136. }
  137. }
  138. }
  139. post {
  140. success {
  141. echo "UAT 环境部署成功!"
  142. }
  143. failure {
  144. echo "UAT 环境部署失败,请检查日志。"
  145. }
  146. always {
  147. cleanWs()
  148. }
  149. }
  150. }