GitHub Actions CI/CD 从零搭建:push 后 60 秒自动上线

背景 服务器上跑着 Flask 项目,每次改代码都要手动 SSH 上去、git pull、docker compose up -d。麻烦,而且容易忘步骤。

想做到:本地改完代码,git push 一下,服务器自动更新。 原因 手工部署的问题:

问题 后果
每次要 SSH 上去 麻烦,耗时间
步骤多容易漏 忘了重启容器,改了不生效
出错没法回滚 改崩了要手动修

CI/CD 的价值:代码 push 到 GitHub 后,由 GitHub Actions 自动 SSH 到服务器执行部署脚本。一次配置,以后都是自动的。

解决 第一步:确认服务器能连 GitHub 服务器需要能 git pull。生成一对密钥:

bash 复制代码
ssh-keygen -t ed25519 -f ~/.ssh/github_dashboard -C "server-key" -N ""
cat ~/.ssh/github_dashboard.pub

把公钥贴到 GitHub 仓库 → Settings → Deploy keys → Add deploy key,勾选 Allow write access。

配置 ~/.ssh/config:

bash 复制代码
Host github-dashboard
  HostName github.com
  User git
  IdentityFile ~/.ssh/github_dashboard
  IdentitiesOnly yes

测试:

bash 复制代码
ssh -T git@github-dashboard
# Hi YOUR_USERNAME/repo-name! You've successfully authenticated...

第二步:生成 CI 专用密钥 方向相反------这次是"GitHub Actions → 服务器"。

bash 复制代码
ssh-keygen -t ed25519 -f ~/.ssh/ci_deploy_key -C "gh-actions-deploy" -N ""

# 公钥装到服务器自己
cat ~/.ssh/ci_deploy_key.pub >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys

# 测试
ssh -i ~/.ssh/ci_deploy_key ubuntu@127.0.0.1 "whoami"
# 输出 ubuntu

第三步:配置 GitHub Secrets 仓库 → Settings → Secrets and variables → Actions → 新建 4 个:

Name 值
SSH_HOST 你的服务器 IP
SSH_USER ubuntu(或你的用户名)
SSH_PORT 22
SSH_KEY ci_deploy_key 私钥全文(cat ~/.ssh/ci_deploy_key 复制)

⚠️ SSH_KEY 粘贴时包含 -----BEGIN... 和 -----END... 两行,一字不差。 第四步:写 workflow 在项目里创建 .github/workflows/deploy.yml: name: Deploy

bash 复制代码
on:
  push:
    branches: [ main ]

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - name: SSH 部署
        uses: appleboy/ssh-action@v1.0.3
        with:
          host:     ${{ secrets.SSH_HOST }}
          username: ${{ secrets.SSH_USER }}
          key:      ${{ secrets.SSH_KEY }}
          port:     ${{ secrets.SSH_PORT }}
          script:   /home/ubuntu/app/deploy.sh

第五步:写部署脚本 服务器上创建 /home/ubuntu/app/deploy.sh:

bash 复制代码
#!/bin/bash
set -e

cd /home/ubuntu/app
git fetch --all
git reset --hard origin/main
docker compose up -d --build

# 健康检查
sleep 5
curl -fsS http://127.0.0.1:8081/api/health || exit 1

echo "✅ 部署成功"
bash 复制代码
chmod +x deploy.sh

第六步:提交 + 触发

bash 复制代码
git add .github/ deploy.sh
git commit -m "ci: 添加自动部署"
git push

去 GitHub 仓库 → Actions 标签,看到 workflow 正在跑。1 分钟后变绿。

改了代码再次 push,就能看到服务器自动更新。 三个坑 坑 1:SSH_KEY 粘贴格式错

GitHub Secrets 里粘私钥时,首尾的 -----BEGIN 和 -----END 两行必须都在。少一行,Actions 会报 invalid key。

坑 2:服务器没有 Docker 权限

Actions SSH 到服务器后执行 docker compose,如果 ubuntu 用户不在 docker 组里,会报 permission denied。 检查:

bash 复制代码
id ubuntu | grep docker
# 没输出就执行:
sudo usermod -aG docker ubuntu

坑 3:deploy.sh 没执行权限

脚本要用 chmod +x deploy.sh。否则 Actions 会报 Permission denied。

生活小插曲:昨天本来说今天早上去爬山的,结果下雨了,没爬成。

相关推荐
王潇9831 小时前
零依赖、单文件:一套自创的分析框架,和它的三个应用站点
github
阿俊在Coding2 小时前
从 0 实现最小 Coding Agent:读懂 Pi 生产级 Agent 的骨架
github
开开心心就好2 小时前
二维码批量生成导出工具,离线可用完全免费
java·前端·人工智能·智能手机·github·excel·visual studio
wflynn2 小时前
GitHub 日榜趋势速报 | 2026-10-03
开源·github
本地化文档2 小时前
pygmt-docs-l10n
python·github·gitcode·sphinx·pygmt·gmt·crowdin
workflower3 小时前
从生成式模型开始的技术延伸
人工智能·机器学习·机器人·云计算·无人机
wflynn3 小时前
GitHub 今日推荐|REDox:64 位 token 表示结构化数据,内存占用降 70% 支持多格式互转
开源·c#·github
miofly3 小时前
GitHub 周榜趋势速报 | 2026-10-04
开源·github
miofly3 小时前
GitHub 日榜趋势速报 | 2026-10-04
开源·github