forked from EduCraft/curriculum-project-hub
ce767e9cab
FeishuRead(ADR-0003): feishuContextTool 从 stub 换成真实 lark im.v1.message.get(单条 trigger/reply/status_card)+ list(thread 回复); ADR-0003 chat 授权不变式不变(handler 已 gate)。 StatusCard: sendCard + buildRunStatusCard——完成/出错发 interactive card (status 文案 + model 选择器 + 取消按钮带 runId),替代纯文本。 Permission(ADR-0004, project-wise): triggerAgent 查 PermissionGrant 对 project 的 edit+ 能力(manage⊇edit 单调);sender open_id 当 principal (子类型学 OPEN,务实选择,permission.ts 标注);per-artifact OPEN; settings 组合规则 OPEN。无权限回 '无权限触发'。 Deploy: cph-hub.service systemd unit(ExecStartPre 跑 prisma migrate)+ install_service.sh(idempotent,seed env)+ deploy_platform.sh (rsync + npm ci + build + restart + healthz)。 client.ts 抽 createLarkClient/startFeishuListenerWithClient,tools 与 ws 共用同一 client。 tsc rc=0;prisma validate 通过;deploy 脚本 bash -n 通过。
63 lines
1.9 KiB
Bash
Executable File
63 lines
1.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Install the cph-hub systemd service on a host. Idempotent.
|
|
#
|
|
# Prerequisites already on the host: Node.js, npm, PostgreSQL, systemd.
|
|
# The Hub repo is expected at HUB_DIR (default /srv/curriculum-project-hub/hub)
|
|
# with `npm ci` + `npm run build` already run by deploy_platform.sh.
|
|
#
|
|
# Usage:
|
|
# sudo BASE=/srv/curriculum-project-hub bash deploy/install_service.sh
|
|
set -euo pipefail
|
|
|
|
BASE="${BASE:-/srv/curriculum-project-hub}"
|
|
HUB_DIR="${HUB_DIR:-$BASE/hub}"
|
|
SERVICE_USER="${SERVICE_USER:-root}"
|
|
HOST="${HOST:-127.0.0.1}"
|
|
PORT="${PORT:-8788}"
|
|
ENV_FILE="${ENV_FILE:-$BASE/.secrets/platform.env}"
|
|
NODE_BIN="${NODE_BIN:-$(command -v node || true)}"
|
|
|
|
if [ -z "$NODE_BIN" ]; then
|
|
echo "node must be on PATH, or set NODE_BIN." >&2
|
|
exit 1
|
|
fi
|
|
if [ ! -d "$HUB_DIR" ]; then
|
|
echo "HUB_DIR not found: $HUB_DIR (set HUB_DIR or clone the repo there)." >&2
|
|
exit 1
|
|
fi
|
|
if [ ! -f "$HUB_DIR/dist/server.js" ]; then
|
|
echo "build missing: run 'npm ci && npm run build' in $HUB_DIR first." >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Seed the env file if absent. Secrets stay on the server, never in the repo.
|
|
if [ ! -f "$ENV_FILE" ]; then
|
|
install -d -m 0700 "$(dirname "$ENV_FILE")"
|
|
cat >"$ENV_FILE" <<EOF
|
|
NODE_ENV=production
|
|
DATABASE_URL=postgresql://paradigm:change-me@127.0.0.1:5432/paradigm
|
|
OPENROUTER_API_KEY=
|
|
FEISHU_APP_ID=
|
|
FEISHU_APP_SECRET=
|
|
FEISHU_BOT_OPEN_ID=
|
|
PORT=$PORT
|
|
HOST=$HOST
|
|
EOF
|
|
echo "Seeded $ENV_FILE — edit it to fill in OPENROUTER_API_KEY and Feishu creds, then re-run."
|
|
exit 0
|
|
fi
|
|
|
|
# Render the unit with concrete paths.
|
|
UNIT=/etc/systemd/system/cph-hub.service
|
|
sed \
|
|
-e "s|__SERVICE_USER__|$SERVICE_USER|g" \
|
|
-e "s|__HUB_DIR__|$HUB_DIR|g" \
|
|
-e "s|__ENV_FILE__|$ENV_FILE|g" \
|
|
-e "s|__NODE_BIN__|$NODE_BIN|g" \
|
|
"$HUB_DIR/deploy/cph-hub.service" >"$UNIT"
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable cph-hub.service
|
|
echo "Installed cph-hub.service. Start with: systemctl start cph-hub"
|
|
echo "Check health: curl http://127.0.0.1:$PORT/api/healthz"
|