-
Notifications
You must be signed in to change notification settings - Fork 0
fix: BrokenPipeError no healthz + painel server-side, i18n, log persistente e credencial de recuperacao #1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
18 commits
Select commit
Hold shift + click to select a range
cb2b74c
feat: log persistente, credencial de recuperacao e resiliencia do ser…
elielsousa-pathbit 670f6f8
feat(web): dashboard server-side, i18n com bandeiras, logs do cron e …
elielsousa-pathbit 6886c79
chore: remove emojis da saida de terminal
elielsousa-pathbit ebe67a5
merge: reconcilia a evolucao do painel com a traducao para ingles
elielsousa-pathbit dcd3d02
docs: wiki versionada no repo com publicacao automatica
elielsousa-pathbit 4a96f3e
fix(tests): torna a sondagem do provedor local deterministica
elielsousa-pathbit d5ebd65
fix: valida credenciais de verdade, corrige deteccao de instancia loc…
elielsousa-pathbit 9fea9cf
merge: integra master e padroniza testStatus como "active"
elielsousa-pathbit 8f1d630
feat: senha com politica de forca gravada como hash no sqlite e refre…
elielsousa-pathbit aa5313c
fix: healthz voltou a quebrar no merge, e credenciais vivas sumiram d…
elielsousa-pathbit b2fa106
fix: elimina a senha de fabrica e a retencao de packages que apagava …
elielsousa-pathbit 91e51db
fix(ci): remove input inexistente da politica de retencao
elielsousa-pathbit 185f1a8
chore(security): retencao ciente de multi-arch e fim das senhas de ex…
elielsousa-pathbit 620b702
fix(auth): senha vazia no ambiente nao pode travar a troca pela tela
elielsousa-pathbit 0cb959d
fix: despacho de providers, persistencia da sondagem e armazenamento …
elielsousa-pathbit 5781cc7
feat: saida de rede por conta (leitura) e documentacao de multi-sessao
elielsousa-pathbit 65f6ebe
fix: cabecalho de autenticacao, Ollama hospedado, CSP das bandeiras e…
elielsousa-pathbit b12cbb2
test: stack de teste propria do repositorio, sem depender de artigo
elielsousa-pathbit File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,29 +1,87 @@ | ||
| name: Purge Packages | ||
| name: Package Retention | ||
|
|
||
| # Mantem o registro enxuto sem nunca derrubar o que esta em uso. | ||
| # | ||
| # Historico: a primeira versao deste arquivo nao era limpeza. Com | ||
| # min-versions-to-keep: 0 e delete-only-untagged-versions: false ela apagava | ||
| # TODAS as versoes e em seguida removia o proprio package via API. Quem | ||
| # estivesse puxando ghcr.io/pathbit/9rtksyncatest ficava sem imagem. | ||
| # | ||
| # A segunda versao corrigia isso, mas usava actions/delete-package-versions, | ||
| # que trata cada manifesto como uma versao independente. O build e multi-arch | ||
| # (linux/amd64 + linux/arm64): o buildx publica um manifest list com a tag e um | ||
| # manifesto SEM TAG por plataforma. Descartar "versoes sem tag" apaga | ||
| # justamente as camadas que a tag referencia, e o pull passa a falhar com | ||
| # "manifest unknown" mesmo com a tag intacta no registro. | ||
| # | ||
| # Por isso a limpeza aqui usa uma action que resolve o manifest list antes de | ||
| # apagar: um manifesto sem tag so e descartado se nenhuma tag preservada | ||
| # apontar para ele. | ||
|
|
||
| on: | ||
| workflow_dispatch: | ||
| inputs: | ||
| keep: | ||
| description: "Quantas versoes marcadas manter" | ||
| required: false | ||
| default: "3" | ||
| dry-run: | ||
| description: "Simular: lista o que seria apagado sem apagar" | ||
| required: false | ||
| default: "false" | ||
| schedule: | ||
| # Semanal, domingo 04:00 UTC: o acumulo vem dos builds, nao do relogio. | ||
| - cron: "0 4 * * 0" | ||
| workflow_run: | ||
| workflows: ["Release and Docker Package"] | ||
| types: [completed] | ||
|
|
||
| permissions: | ||
| packages: write | ||
|
|
||
| concurrency: | ||
| group: package-retention-9rtksync | ||
| cancel-in-progress: false | ||
|
|
||
| jobs: | ||
| purge: | ||
| retention: | ||
| name: Apply retention policy | ||
| runs-on: ubuntu-latest | ||
| # Depois de um release, so faz sentido limpar se o release funcionou. | ||
| if: >- | ||
| github.event_name != 'workflow_run' || | ||
| github.event.workflow_run.conclusion == 'success' | ||
| steps: | ||
| - name: Purge package versions | ||
| uses: actions/delete-package-versions@v5 | ||
| - name: Apply retention policy | ||
| uses: dataaxiom/ghcr-cleanup-action@v1.2.2 | ||
| with: | ||
| package-name: '9rtksync' | ||
| package-type: 'container' | ||
| min-versions-to-keep: 0 | ||
| delete-only-untagged-versions: 'false' | ||
| continue-on-error: true | ||
| token: ${{ secrets.GITHUB_TOKEN }} | ||
| owner: ${{ github.repository_owner }} | ||
| packages: 9rtksync | ||
| # Guarda as N imagens marcadas mais recentes, com as camadas de | ||
| # plataforma de cada uma. 'latest' fica de fora da contagem por | ||
| # seguranca, ainda que por construcao ela aponte para a mais nova. | ||
| keep-n-tagged: ${{ github.event.inputs.keep || '3' }} | ||
| exclude-tags: latest | ||
| # Apaga apenas manifestos orfaos de verdade: os que sobraram de | ||
| # builds ja aposentados e nao pertencem a nenhuma tag preservada. | ||
| delete-untagged: true | ||
| # Restos de execucoes anteriores: manifest list cujas camadas de | ||
| # plataforma ja nao existem (nao ha o que puxar delas). | ||
| delete-ghost-images: true | ||
| delete-partial-images: true | ||
| delete-orphaned-images: true | ||
| # Confere no registro se cada digest referenciado existe mesmo, e | ||
| # registra o resultado no log da execucao. | ||
| validate: true | ||
| dry-run: ${{ github.event.inputs.dry-run || 'false' }} | ||
|
|
||
| - name: Force delete package via GitHub API | ||
| - name: Report what survived | ||
| if: always() | ||
| env: | ||
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| run: | | ||
| curl -X DELETE \ | ||
| -H "Accept: application/vnd.github+json" \ | ||
| -H "Authorization: Bearer $GH_TOKEN" \ | ||
| https://api.github.com/orgs/pathbit/packages/container/9rtksync || true | ||
| echo "### Versoes mantidas em 9rtksync" >> "$GITHUB_STEP_SUMMARY" | ||
| gh api "/orgs/${{ github.repository_owner }}/packages/container/9rtksync/versions" \ | ||
| --jq '.[] | "- \(.name[0:19]) tags: \(.metadata.container.tags | join(", "))"' \ | ||
| >> "$GITHUB_STEP_SUMMARY" || echo "- (nao foi possivel listar)" >> "$GITHUB_STEP_SUMMARY" |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,62 @@ | ||
| name: Publish Wiki | ||
|
|
||
| # The wiki is generated from docs/wiki/ so the documentation is reviewed in pull | ||
| # requests like any other change, instead of being edited straight in the wiki | ||
| # where nothing gates it. | ||
| # | ||
| # First run requires the wiki to already exist: GitHub only creates the | ||
| # <repo>.wiki.git repository after the first page is saved through the web UI. | ||
| # Create any page once and this workflow takes over from there. | ||
|
|
||
| on: | ||
| push: | ||
| branches: [master] | ||
| paths: | ||
| - "docs/wiki/**" | ||
| - ".github/workflows/publish-wiki.yml" | ||
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| contents: write | ||
|
|
||
| concurrency: | ||
| group: publish-wiki | ||
| cancel-in-progress: false | ||
|
|
||
| jobs: | ||
| publish: | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v4 | ||
|
|
||
| - name: Clone the wiki | ||
| id: clone | ||
| run: | | ||
| if git clone "https://x-access-token:${{ secrets.GITHUB_TOKEN }}@github.com/${{ github.repository }}.wiki.git" wiki; then | ||
| echo "ok=true" >> "$GITHUB_OUTPUT" | ||
| else | ||
| echo "ok=false" >> "$GITHUB_OUTPUT" | ||
| echo "::warning::Wiki repository not found. Create the first page through the GitHub UI once, then re-run this workflow." | ||
| fi | ||
|
|
||
| - name: Sync pages | ||
| if: steps.clone.outputs.ok == 'true' | ||
| run: | | ||
| # Replace the whole page set so a deleted source file disappears from the wiki too. | ||
| find wiki -maxdepth 1 -name '*.md' -delete | ||
| cp docs/wiki/*.md wiki/ | ||
|
|
||
| - name: Commit and push | ||
| if: steps.clone.outputs.ok == 'true' | ||
| working-directory: wiki | ||
| run: | | ||
| git config user.name "github-actions[bot]" | ||
| git config user.email "41898282+github-actions[bot]@users.noreply.github.com" | ||
| git add -A | ||
| if git diff --cached --quiet; then | ||
| echo "Wiki already up to date." | ||
| exit 0 | ||
| fi | ||
| git commit -m "docs: sync wiki from ${{ github.sha }}" | ||
| git push |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changing the default listener to 9090 breaks existing deployments that published the previously documented
-p 9190:9190mapping without also settingWEB_PORT: after upgrading, the host port forwards to container port 9190 while the server listens on 9090. The repository README still publishes that mapping, its 9190 default, andhttp://localhost:9190, so both upgrades and documented default CLI use lead users to an unreachable dashboard. Retain compatibility or update the public configuration and migration guidance together.Useful? React with 👍 / 👎.