fix(web): 烤入所有 nginx 配置,按 APP_ENV 运行时切换,彻底解决 staging/prod 配置错乱 #1853

Merged
auto-approve-bot merged 2 commits from fix/nginx-config-per-env into develop 2026-09-11 09:02:02 +08:00
Owner

问题

web Dockerfile 通过 ARG NGINX_CONF 在构建时烤入单个 nginx 配置。但 CI 从 develop 分支构建时始终使用 nginx-staging.conf,导致生产镜像内的默认 nginx 配置指向 xiaoxia-api-staging:8000,在生产环境容器重启后出现 502。

修复方案

  • 将 3 份 nginx 配置(nginx.conf / nginx-staging.conf / nginx-production.conf)全部烤入镜像
  • 新增 nginx-entrypoint.sh,容器启动时根据 APP_ENV 环境变量 symlink 正确的配置到 /etc/nginx/conf.d/default.conf
  • CI pipeline 移除 3 处 NGINX_CONF 构建参数
  • 部署脚本改为传入 APP_ENV=staging/production
  • compose.yml 同步更新

效果

  • 同一个镜像可在 staging 和 production 运行,nginx 路由由环境变量决定
  • 彻底消除「镜像构建时烤错配置」的风险
  • 部署脚本不再依赖宿主机上的 nginx 配置文件路径

变更文件

  • infra/docker/web.Dockerfile — 烤入 3 份 nginx 配置 + entrypoint
  • infra/docker/web-artifact.Dockerfile — 同步修改
  • infra/docker/nginx-entrypoint.sh — 新增,运行时配置选择器
  • .gitea/workflows/ci-pipeline.yml — 移除 NGINX_CONF 参数
  • infra/docker/deploy-production-registry.sh — 添加 APP_ENV=production
  • infra/docker/deploy-staging-registry.sh — 添加 APP_ENV=staging,移除 volume 挂载
  • infra/docker/deploy-staging.sh — 移除 WEB_NGINX_CONF
  • infra/docker/compose.yml — NGINX_ENV → APP_ENV
## 问题 web Dockerfile 通过 `ARG NGINX_CONF` 在构建时烤入单个 nginx 配置。但 CI 从 develop 分支构建时始终使用 `nginx-staging.conf`,导致生产镜像内的默认 nginx 配置指向 `xiaoxia-api-staging:8000`,在生产环境容器重启后出现 502。 ## 修复方案 - 将 3 份 nginx 配置(nginx.conf / nginx-staging.conf / nginx-production.conf)全部烤入镜像 - 新增 `nginx-entrypoint.sh`,容器启动时根据 `APP_ENV` 环境变量 symlink 正确的配置到 `/etc/nginx/conf.d/default.conf` - CI pipeline 移除 3 处 `NGINX_CONF` 构建参数 - 部署脚本改为传入 `APP_ENV=staging/production` - compose.yml 同步更新 ## 效果 - **同一个镜像**可在 staging 和 production 运行,nginx 路由由环境变量决定 - 彻底消除「镜像构建时烤错配置」的风险 - 部署脚本不再依赖宿主机上的 nginx 配置文件路径 ## 变更文件 - `infra/docker/web.Dockerfile` — 烤入 3 份 nginx 配置 + entrypoint - `infra/docker/web-artifact.Dockerfile` — 同步修改 - `infra/docker/nginx-entrypoint.sh` — 新增,运行时配置选择器 - `.gitea/workflows/ci-pipeline.yml` — 移除 NGINX_CONF 参数 - `infra/docker/deploy-production-registry.sh` — 添加 APP_ENV=production - `infra/docker/deploy-staging-registry.sh` — 添加 APP_ENV=staging,移除 volume 挂载 - `infra/docker/deploy-staging.sh` — 移除 WEB_NGINX_CONF - `infra/docker/compose.yml` — NGINX_ENV → APP_ENV
xiaoxia added 1 commit 2026-09-11 08:43:22 +08:00
fix(web): bake all nginx configs into image, select via APP_ENV at runtime
CI/CD Pipeline / Dedup Check - skip PR tests when covered by push pipeline (pull_request) Successful in 2s
CI/CD Pipeline / Check if frontend-only change (pull_request) Successful in 2s
CI/CD Pipeline / PR Build API Image (pull_request) Failing after 23s
CI/CD Pipeline / PR Build Worker Image (pull_request) Failing after 23s
Preview Deploy / Deploy Preview Environment (pull_request) Successful in 56s
CI/CD Pipeline / Validate - Style (pull_request) Successful in 1m26s
CI/CD Pipeline / Validate - Python (mypy + alembic) (pull_request) Successful in 1m27s
CI/CD Pipeline / Integration Tests (pull_request) Successful in 1m47s
PR Automation / Auto Approve on CI Green (pull_request) Successful in 2m44s
CI/CD Pipeline / Validate - Security (pull_request) Successful in 5m13s
AI Code Review / AI Code Review (pull_request) Successful in 6m17s
CI/CD Pipeline / Unit Tests (pull_request) Successful in 6m41s
CI/CD Pipeline / Production Browser E2E (pull_request) Has been skipped
CI/CD Pipeline / CI Gate (pull_request) Failing after 2s
PR Automation / Auto Merge on CI Green + Approved (pull_request) Successful in 4m9s
CI/CD Pipeline / Deploy Production (pull_request) Failing after 126h33m42s
CI/CD Pipeline / Build Production API Image (pull_request) Failing after 126h33m43s
CI/CD Pipeline / Retag skipped Staging Worker Image (pull_request) Failing after 126h40m16s
CI/CD Pipeline / Build Staging API Image (pull_request) Failing after 126h40m21s
CI/CD Pipeline / PR Build Web Image (pull_request) Failing after 126h40m10s
CI/CD Pipeline / Frontend Lint (pull_request) Failing after 126h40m11s
CI/CD Pipeline / Staging E2E Tests (pull_request) Failing after 126h39m53s
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (pull_request) Failing after 126h39m59s
CI/CD Pipeline / Retag skipped Staging Web Image (pull_request) Failing after 126h40m3s
CI/CD Pipeline / Retag skipped Staging API Image (pull_request) Failing after 126h40m4s
CI/CD Pipeline / Build Staging Worker Image (pull_request) Failing after 126h40m8s
CI/CD Pipeline / Build Staging Web Image (pull_request) Failing after 126h40m8s
CI/CD Pipeline / Check push changed paths (pull_request) Failing after 126h40m15s
CI/CD Pipeline / ACR Image Cleanup (pull_request) Failing after 126h39m53s
CI/CD Pipeline / Build Production Worker Image (pull_request) Failing after 126h33m30s
CI/CD Pipeline / Build Production Web Image (pull_request) Failing after 126h33m30s
CI/CD Pipeline / Canary Release to Production (pull_request) Failing after 126h33m29s
CI/CD Pipeline / Staging API Integration Tests (pull_request) Failing after 126h39m53s
CI/CD Pipeline / Frontend Unit Tests (pull_request) Failing after 126h40m10s
fa65a401a5
Problem: web Dockerfile used ARG NGINX_CONF to bake a single nginx config
at build time. CI always built from develop branch with nginx-staging.conf,
so the production image also contained the staging nginx config pointing to
xiaoxia-api-staging:8000, causing 502 in production after restarts.

Fix:
- Bake all 3 nginx configs (default/nginx.conf, nginx-staging.conf,
  nginx-production.conf) into the web image
- Add nginx-entrypoint.sh that symlinks the correct config based on
  APP_ENV (staging/production) at container startup
- Remove NGINX_CONF build arg from CI pipeline (3 occurrences)
- Update deploy scripts to pass APP_ENV to web container
- Update compose.yml to use APP_ENV instead of NGINX_ENV

This ensures a single image artifact works for both staging and production,
with the correct nginx upstream selected at runtime via environment variable.

🚀 预览环境已部署

项目 详情
PR号 #1853
预览链接 https://pr-1853.preview.xiaoxiajianji.com
API环境 staging

💡 预览环境使用 staging API 数据,请勿在预览环境中操作重要数据。

🔄 每次提交新代码后预览环境会自动更新。

🗑️ PR 关闭或合并后,预览环境会自动清理。

🚀 **预览环境已部署** | 项目 | 详情 | |------|------| | PR号 | #1853 | | 预览链接 | [https://pr-1853.preview.xiaoxiajianji.com](https://pr-1853.preview.xiaoxiajianji.com) | | API环境 | staging | > 💡 预览环境使用 staging API 数据,请勿在预览环境中操作重要数据。 > > 🔄 每次提交新代码后预览环境会自动更新。 > > 🗑️ PR 关闭或合并后,预览环境会自动清理。
xiaoxia added 1 commit 2026-09-11 08:51:59 +08:00
chore: remove empty if blocks after removing NGINX_CONF
CI/CD Pipeline / Dedup Check - skip PR tests when covered by push pipeline (pull_request) Successful in 2s
CI/CD Pipeline / Check if frontend-only change (pull_request) Successful in 2s
CI/CD Pipeline / PR Build API Image (pull_request) Successful in 27s
CI/CD Pipeline / PR Build Worker Image (pull_request) Successful in 27s
Preview Deploy / Deploy Preview Environment (pull_request) Successful in 1m16s
CI/CD Pipeline / Validate - Python (mypy + alembic) (pull_request) Successful in 1m31s
CI/CD Pipeline / Integration Tests (pull_request) Successful in 1m33s
CI/CD Pipeline / Validate - Style (pull_request) Successful in 1m58s
PR Automation / Auto Approve on CI Green (pull_request) Successful in 2m49s
CI/CD Pipeline / Validate - Security (pull_request) Successful in 4m33s
AI Code Review / AI Code Review (pull_request) Successful in 6m21s
CI/CD Pipeline / Unit Tests (pull_request) Successful in 9m15s
CI/CD Pipeline / CI Gate (pull_request) Successful in 1s
CI/CD Pipeline / Production Browser E2E (pull_request) Has been skipped
PR Automation / Auto Merge on CI Green + Approved (pull_request) Successful in 7m4s
ACR Cleanup / ACR Image Cleanup (pull_request_target) Successful in 6s
Preview Cleanup / Cleanup Preview Environment (pull_request) Successful in 22s
CI/CD Pipeline / Deploy Production (pull_request) Failing after 126h22m29s
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (pull_request) Failing after 126h31m42s
CI/CD Pipeline / Frontend Unit Tests (pull_request) Failing after 126h31m45s
CI/CD Pipeline / Build Staging API Image (pull_request) Failing after 126h31m50s
CI/CD Pipeline / PR Build Web Image (pull_request) Failing after 126h31m32s
CI/CD Pipeline / Staging E2E Tests (pull_request) Failing after 126h31m26s
CI/CD Pipeline / Retag skipped Staging Web Image (pull_request) Failing after 126h31m32s
CI/CD Pipeline / Retag skipped Staging API Image (pull_request) Failing after 126h31m32s
CI/CD Pipeline / Build Staging Worker Image (pull_request) Failing after 126h31m37s
CI/CD Pipeline / Build Staging Web Image (pull_request) Failing after 126h31m37s
CI/CD Pipeline / Check push changed paths (pull_request) Failing after 126h31m38s
CI/CD Pipeline / ACR Image Cleanup (pull_request) Failing after 126h31m26s
CI/CD Pipeline / Canary Release to Production (pull_request) Failing after 126h22m16s
CI/CD Pipeline / Build Production Worker Image (pull_request) Failing after 126h22m17s
CI/CD Pipeline / Build Production Web Image (pull_request) Failing after 126h22m17s
CI/CD Pipeline / Staging API Integration Tests (pull_request) Failing after 126h31m26s
CI/CD Pipeline / Retag skipped Staging Worker Image (pull_request) Failing after 126h31m31s
CI/CD Pipeline / Frontend Lint (pull_request) Failing after 126h31m33s
CI/CD Pipeline / Build Production API Image (pull_request) Failing after 126h57m23s
100538a704
auto-approve-bot merged commit 29ca51da9c into develop 2026-09-11 09:02:02 +08:00
auto-approve-bot deleted branch fix/nginx-config-per-env 2026-09-11 09:02:02 +08:00

🗑️ 预览环境已清理

PR #1853 已关闭或合并,对应的预览环境已被清理。

如有需要,可以重新打开 PR 来重新生成预览环境。

🗑️ **预览环境已清理** PR #1853 已关闭或合并,对应的预览环境已被清理。 > 如有需要,可以重新打开 PR 来重新生成预览环境。
Sign in to join this conversation.