# 第 73 次部署 # 💡 全局变量块 variables: - &APP_REGISTRY "push.lovestory.cyou" - &APP_PULL_REGISTRY "registry.lovestory.cyou" - &PROJECT_NAME "abhors/demo" - &CONTAINER_NAME "demo-container" - &DEPLOY_HOST "43.143.243.136" - &DEPLOY_PORT "22" - &DEPLOY_USER_SECRET "136_ssh_user" - &DEPLOY_PASS_SECRET "136_ssh_password" steps: - name: Java 构建 image: library/maven:3.9.6-eclipse-temurin-17 pull: true commands: - mvn clean package -DskipTests volumes: - /tmp/maven-cache:/root/.m2 when: event: [push, pull_request] branch: master - name: 官方标准构建与推送 (DinD) image: woodpeckerci/plugin-docker-buildx:latest-insecure privileged: true # 👈 官方 DinD 模式必须开启特权 settings: repo: push.lovestory.cyou/abhors/demo registry: push.lovestory.cyou insecure: true username: from_secret: nexus_docker_username password: from_secret: nexus_docker_password output: type=image,push=true # 💡 官方标准解法 1:把国内加速源灌进内部的 BuildKit 编译器 # 这样它在解析 Dockerfile 里的 FROM 基础镜像时,才不会去连外网 buildkit_config: | [registry."docker.io"] mirrors = ["docker.1ms.run", "dockerpull.org", "1ms.run"] [registry."push.lovestory.cyou"] http = true insecure = true # 💡 官方标准解法 2:把国内加速源灌进外层的 Docker 守护进程 # 这样它在第一步启动时,就能通过国内镜像秒拉 moby/buildkit,绝不超时 config: | { "registry-mirrors": [ "https://docker.1ms.run", "https://dockerpull.org", "https://1ms.run" ], "insecure-registries": [ "registry.lovestory.cyou", "push.lovestory.cyou" ] } when: event: push branch: master - name: 远程终端部署 image: registry.lovestory.cyou/appleboy/drone-ssh:latest settings: host: *DEPLOY_HOST port: *DEPLOY_PORT username: from_secret: *DEPLOY_USER_SECRET password: from_secret: *DEPLOY_PASS_SECRET secrets: [ nexus_docker_username, nexus_docker_password ] envs: [ nexus_docker_username, nexus_docker_password ] script: - echo "=========================================" - echo "🚀 开始部署节点:*DEPLOY_HOST" - echo "=========================================" - docker login --username "$nexus_docker_username" --password "$nexus_docker_password" "push.lovestory.cyou" - docker stop "demo-container" || true - docker rm "demo-container" || true - docker pull "push.lovestory.cyou/abhors/demo:latest" - docker run -d --name "demo-container" -p 8080:8080 --restart always "push.lovestory.cyou/abhors/demo:latest" when: event: push branch: master