Jenkinsfile 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207
  1. pipeline {
  2. agent any
  3. options {
  4. buildDiscarder(logRotator(numToKeepStr: '10'))
  5. timestamps()
  6. disableConcurrentBuilds()
  7. }
  8. // 设计原则:
  9. // - 无 parameters 块,所以"Build Now"直接跑、不弹窗
  10. // - 环境(APP_ENV) 与 分支(BRANCH) 都从 Jenkins 自动注入的 GIT_BRANCH 推断
  11. // GIT_BRANCH 来自每个 Job 的 SCM 配置(Branch Specifier *​/dev、*​/sit、*​/uat 之一)
  12. // - 因此每台机器上 Job 唯一要配的就是 Branch Specifier,三台机器的 Jenkinsfile 内容完全一致
  13. stages {
  14. stage('Resolve Environment') {
  15. // 从 Jenkins 注入的 GIT_BRANCH 推断 APP_ENV
  16. // GIT_BRANCH 形如 "origin/uat" / "uat" / "refs/heads/uat",统一去前缀
  17. steps {
  18. script {
  19. def raw = env.GIT_BRANCH ?: env.BRANCH_NAME ?: ''
  20. def branch = raw.replaceFirst('^origin/', '').replaceFirst('^refs/heads/', '').trim()
  21. if (!(branch in ['dev', 'sit', 'uat'])) {
  22. error """
  23. ============ 无法识别当前部署环境 ============
  24. Jenkins 注入的 GIT_BRANCH = '${env.GIT_BRANCH}'
  25. 解析后的分支名 = '${branch}'
  26. 期望分支必须是 dev / sit / uat 之一。
  27. 请检查 Job 配置中的 Branch Specifier 是否正确:
  28. DEV 服务器 → */dev
  29. SIT 服务器 → */sit
  30. UAT 服务器 → */uat
  31. =============================================
  32. """.stripIndent()
  33. }
  34. // 把推断结果写回 env,后续 stage 用 env.APP_ENV 而不是 params.APP_ENV
  35. env.APP_ENV = branch
  36. env.BRANCH = branch
  37. // 派生命名规则(容器名/网络/日志/镜像 TAG 全部以 APP_ENV 区分)
  38. env.IMAGE_TAG = "${env.APP_ENV}-${env.BUILD_NUMBER}"
  39. env.IMAGE_STORE = "alien_store:${env.IMAGE_TAG}"
  40. env.IMAGE_GATEWAY = "alien_gateway:${env.IMAGE_TAG}"
  41. env.IMAGE_CONTRACT = "alien_contract:${env.IMAGE_TAG}"
  42. env.CONTAINER_NAME_STORE = "alien_store_py-${env.APP_ENV}"
  43. env.CONTAINER_NAME_GATEWAY = "alien_gateway_py-${env.APP_ENV}"
  44. env.CONTAINER_NAME_CONTRACT = "alien_contract_py-${env.APP_ENV}"
  45. env.DOCKER_NET = "alien_net_${env.APP_ENV}"
  46. env.LOG_ROOT = "/docker/python-${env.APP_ENV}/logs"
  47. }
  48. }
  49. }
  50. stage('Show Build Info') {
  51. steps {
  52. echo "============================================================"
  53. echo " 部署环境 : ${env.APP_ENV} (来自 GIT_BRANCH=${env.GIT_BRANCH})"
  54. echo " 部署分支 : ${env.BRANCH}"
  55. echo " 镜像 TAG : ${env.IMAGE_TAG}"
  56. echo " 容器网络 : ${env.DOCKER_NET}"
  57. echo " 日志根目录: ${env.LOG_ROOT}"
  58. echo "============================================================"
  59. }
  60. }
  61. stage('Load Env Port Mapping') {
  62. // 从 .env.${APP_ENV} 解析 GATEWAY_PORT,作为 docker -p 宿主端口映射用
  63. steps {
  64. script {
  65. def envFile = ".env.${env.APP_ENV}"
  66. if (!fileExists(envFile)) {
  67. error "缺少环境配置文件: ${envFile}(仓库里应该有这份;请检查 .gitignore 是否误屏蔽)"
  68. }
  69. def gatewayPort = sh(
  70. script: "grep -E '^GATEWAY_PORT=' ${envFile} | head -n1 | cut -d= -f2 | tr -d '\"' | tr -d \"'\"",
  71. returnStdout: true
  72. ).trim()
  73. if (!gatewayPort) {
  74. gatewayPort = "33333"
  75. }
  76. env.GATEWAY_PORT = gatewayPort
  77. echo "从 ${envFile} 解析到 GATEWAY_PORT=${env.GATEWAY_PORT}"
  78. }
  79. }
  80. }
  81. stage('Build Images') {
  82. steps {
  83. script {
  84. def buildArgs = "--build-arg APP_ENV=${env.APP_ENV}"
  85. sh "docker build ${buildArgs} -f alien_store/Dockerfile -t ${env.IMAGE_STORE} ."
  86. sh "docker build ${buildArgs} -f alien_gateway/Dockerfile -t ${env.IMAGE_GATEWAY} ."
  87. sh "docker build ${buildArgs} -f alien_contract/Dockerfile -t ${env.IMAGE_CONTRACT} ."
  88. }
  89. }
  90. }
  91. stage('Deploy') {
  92. steps {
  93. script {
  94. echo ">>> [${env.APP_ENV}] 部署镜像: ${env.IMAGE_STORE} / ${env.IMAGE_GATEWAY} / ${env.IMAGE_CONTRACT}"
  95. sh """
  96. set -e
  97. docker network create ${env.DOCKER_NET} 2>/dev/null || true
  98. mkdir -p ${env.LOG_ROOT}/store ${env.LOG_ROOT}/gateway ${env.LOG_ROOT}/contract
  99. docker rm -f ${env.CONTAINER_NAME_STORE} ${env.CONTAINER_NAME_GATEWAY} ${env.CONTAINER_NAME_CONTRACT} 2>/dev/null || true
  100. # 1) 下游:store
  101. # APP_ENV=${env.APP_ENV} 让 config.py 加载镜像内的 .env.${env.APP_ENV}
  102. docker run -d --name ${env.CONTAINER_NAME_STORE} \\
  103. --network ${env.DOCKER_NET} \\
  104. -e APP_ENV=${env.APP_ENV} \\
  105. -v ${env.LOG_ROOT}/store:/app/common/logs/alien_store \\
  106. --restart unless-stopped \\
  107. ${env.IMAGE_STORE}
  108. # 2) 下游:contract
  109. docker run -d --name ${env.CONTAINER_NAME_CONTRACT} \\
  110. --network ${env.DOCKER_NET} \\
  111. -e APP_ENV=${env.APP_ENV} \\
  112. -v ${env.LOG_ROOT}/contract:/app/common/logs/alien_contract \\
  113. --restart unless-stopped \\
  114. ${env.IMAGE_CONTRACT}
  115. # 3) 网关:gateway(唯一对外端口)
  116. # -e GATEWAY_PORT=... 是关键:必须覆盖 Dockerfile 的默认 33333,
  117. # 否则容器内 uvicorn 会监听默认端口,导致与宿主机映射端口对不上
  118. # pydantic-settings 也是环境变量优先于 .env 文件
  119. docker run -d --name ${env.CONTAINER_NAME_GATEWAY} \\
  120. --network ${env.DOCKER_NET} \\
  121. -p ${env.GATEWAY_PORT}:${env.GATEWAY_PORT} \\
  122. -e APP_ENV=${env.APP_ENV} \\
  123. -e GATEWAY_PORT=${env.GATEWAY_PORT} \\
  124. -e STORE_BASE_URL=http://${env.CONTAINER_NAME_STORE}:8001 \\
  125. -e CONTRACT_BASE_URL=http://${env.CONTAINER_NAME_CONTRACT}:8002 \\
  126. -v ${env.LOG_ROOT}/gateway:/app/common/logs/alien_gateway \\
  127. --restart unless-stopped \\
  128. ${env.IMAGE_GATEWAY}
  129. """
  130. }
  131. }
  132. }
  133. stage('Smoke Test') {
  134. // 注意:Jenkins 本身可能跑在 Docker 容器里,无法直接 curl 宿主机端口。
  135. // 这里采取两层验证:
  136. // 1) 硬验证:3 个业务容器必须都在 running 状态(不通过则 fail)
  137. // 2) 软验证:通过 docker exec 进入 gateway 容器内部跑 /health 自检
  138. // (HTTP 失败只 warn,不让 Pipeline 失败,因为这只代表 Jenkins 的网络位置看不到,
  139. // 不代表服务对外不可用,需要人工从其他位置验证)
  140. steps {
  141. script {
  142. sleep(time: 5, unit: 'SECONDS')
  143. def containers = [
  144. env.CONTAINER_NAME_STORE,
  145. env.CONTAINER_NAME_CONTRACT,
  146. env.CONTAINER_NAME_GATEWAY
  147. ]
  148. def allRunning = true
  149. containers.each { c ->
  150. def status = sh(
  151. returnStdout: true,
  152. script: "docker inspect -f '{{.State.Status}}' ${c} 2>/dev/null || echo missing"
  153. ).trim()
  154. echo " ${c}: ${status}"
  155. if (status != 'running') {
  156. allRunning = false
  157. sh "docker logs --tail 50 ${c} || true"
  158. }
  159. }
  160. if (!allRunning) {
  161. error "存在容器未处于 running 状态,部署失败"
  162. }
  163. echo "✓ 3 个业务容器均在 running 状态"
  164. def healthCmd = """docker exec ${env.CONTAINER_NAME_GATEWAY} python -c 'import urllib.request as u; r=u.urlopen("http://localhost:${env.GATEWAY_PORT}/health", timeout=3); print("HTTP", r.status, r.read(200).decode())'"""
  165. def rc = sh(returnStatus: true, script: healthCmd)
  166. if (rc == 0) {
  167. echo "✓ gateway /health 通过"
  168. } else {
  169. echo "⚠️ gateway /health 未通过(容器在跑但 HTTP 自检失败,请从外部手动验证:curl http://<host>:${env.GATEWAY_PORT}/health)"
  170. }
  171. }
  172. }
  173. }
  174. }
  175. post {
  176. success {
  177. echo "[${env.APP_ENV}] 环境部署成功!请从外部访问 http://<host>:${env.GATEWAY_PORT}/health 验证"
  178. }
  179. failure {
  180. echo "[${env.APP_ENV}] 环境部署失败,请检查上面日志。"
  181. }
  182. always {
  183. cleanWs()
  184. }
  185. }
  186. }