Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions .github/workflows/sync-cloud-run-env.yml
Original file line number Diff line number Diff line change
Expand Up @@ -231,11 +231,13 @@ jobs:
env_sync_enabled=true
fi
else
if [ "${ENABLE_GITHUB_CLOUD_RUN_DEPLOY:-}" = "true" ]; then
if [ "${ENABLE_GITHUB_CLOUD_RUN_DEPLOY:-}" = "true" ] \
&& { [ "${GITHUB_EVENT_NAME:-}" != "workflow_dispatch" ] || [ "${INPUT_DEPLOY_IMAGE:-true}" = "true" ]; }; then
deploy_enabled=true
fi

if [ "${ENABLE_GITHUB_ENV_SYNC:-}" = "true" ]; then
if [ "${ENABLE_GITHUB_ENV_SYNC:-}" = "true" ] \
&& { [ "${GITHUB_EVENT_NAME:-}" != "workflow_dispatch" ] || [ "${INPUT_SYNC_ENV:-true}" = "true" ]; }; then
env_sync_enabled=true
fi
fi
Expand Down
1 change: 1 addition & 0 deletions docs/ibkr_runtime_rollout.md
Original file line number Diff line number Diff line change
Expand Up @@ -292,6 +292,7 @@ gcloud storage buckets add-iam-policy-binding "gs://run-sources-${PROJECT_ID}-${
5. **通过受保护的部署 workflow 触发同步或镜像发布**
- 标准路径是 `Deploy Cloud Run` workflow;`configured` 必须提供精确的 `configured_service`,禁止默认扫全部 inventory。
- 镜像发布与 env 同步默认 `--no-traffic`:只准备候选 revision,不改当前流量。
- 只更新已批准目标的镜像时,明确设置 `deploy_image=true`、`sync_env=false`;只同步配置则设置 `deploy_image=false`、`sync_env=true`。两项仍受仓库级部署/同步开关约束,且必须指定精确 `configured_service`。这样通知等纯代码发布不会顺带改 Secret、运行开关或 Scheduler。
- `approve_traffic_shift` / `approve_scheduler_sync` 默认 `false`;显式打开后才切流量或启停 Scheduler,并做读回失败停止。
- 流量切换前会验证已部署目标与待发布策略均仍在准入目录。
- 不要把临时的 `gcloud run services update --image ...` 当作常规发布方式:它会绕过策略准入、运行身份与 Paper/Shadow/Live 语义校验。
Expand Down
2 changes: 2 additions & 0 deletions tests/test_sync_cloud_run_env_workflow.sh
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,8 @@ grep -Fq 'ENABLE_MAIN_PUSH_CLOUD_RUN_AUTOMATION: ${{ vars.ENABLE_MAIN_PUSH_CLOUD
grep -Fq 'target:' "$workflow_file"
grep -Fq 'default: hk-verify' "$workflow_file"
grep -Fq 'INPUT_DEPLOY_IMAGE: ${{ inputs.deploy_image }}' "$workflow_file"
grep -Fq '[ "${INPUT_DEPLOY_IMAGE:-true}" = "true" ]; }; then' "$workflow_file"
grep -Fq '[ "${INPUT_SYNC_ENV:-true}" = "true" ]; }; then' "$workflow_file"
grep -Fq 'INPUT_APPROVE_TRAFFIC_SHIFT: ${{ inputs.approve_traffic_shift }}' "$workflow_file"
grep -Fq 'INPUT_APPROVE_SCHEDULER_SYNC: ${{ inputs.approve_scheduler_sync }}' "$workflow_file"
grep -Fq 'Apply HK verify-only dispatch defaults' "$workflow_file"
Expand Down
Loading