Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

CI/CD: optional GITHUB_TOKEN for composer, functional tests never send email, registry secret apply (template !12)

未关闭
#180 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
58/100
Issue 类型
文档
描述清晰度
描述清楚
活跃度
活跃
技术栈
docker, github-actions, helm, kubernetes, php

调研方向

Update content/6.deployment/3.ci-cd.md, especially the variables table at line 73, the bin/devops/setup.sh section around line 147, and run_test_functional around line 167; compare with content/6.deployment/1.docker.md at line 224. Document the token, email-safe test setup, registry secret, Helm defaults, removed VARNISH_TOKEN, and stale GitHub deploy statement using the issue details. Done when the CI/CD guide consistently describes these behaviors and no longer lists the unused variable.

由索引模型根据 Issue 内容生成。

描述

Template MR !12 (components-web-app#123, merged as 1a530d4) changed CI in ways content/6.deployment/3.ci-cd.md should cover.

1. Optional GITHUB_TOKEN for composer (new row in the variables table, plus a note in the bin/devops/setup.sh section, line 147)

  • Without it, composer's ~180 downloads from github.com are anonymous: 60 requests an hour per IP. On a shared runner, installs fail part way through with a 429.
  • A fine-grained token with no permissions is enough. setup.sh turns it into COMPOSER_AUTH and sets COMPOSER_MAX_PARALLEL_HTTP=6. Unset stays unset (an empty token is rejected outright, which is worse than anonymous).
  • build_api passes it to the API image build as the composer_auth build secret, never a build arg, so it stays out of the image history. The build log's github rate limit for this build: line prints 60 (anonymous) or 5000 (token applied).
  • GitHub Actions maps its own secrets.GITHUB_TOKEN on the build step, so nothing needs setting there.
  • Keep this consistent with content/6.deployment/1.docker.md:224, which already mentions GITHUB_TOKEN for local composer update.

2. Functional tests never send real email (the functional tests row at line 73, and run_test_functional at line 167)

  • Every CI variable reaches the test job, and a real environment variable beats api/.env.test, so a project's live MAILER_DSN would deliver any email a test sends (a contact form, a password reset).
  • run_test_functional unsets MAILER_DSN and MAILER_EMAIL, and api/.env.test sets MAILER_DSN=null://null: mail is built and Symfony's mailer assertions still see it, but nothing is delivered. Both halves are needed: without the .env.test line, tests fall back to .env's smtp-relay host, which CI doesn't have, and error.
  • The job also generates a test JWT keypair (lexik:jwt:generate-keypair --skip-if-exists), so tests that sign in work in CI.

3. Smaller changes

  • The registry pull secret is now kubectl applyd, not replace --forced (concurrent releases in one namespace raced with "already exists"). The first deploy after the change prints a harmless one-off warning about a missing last-applied-configuration annotation.
  • helm lint and helm template now pass on the chart's own defaults (jwt-passphrase defaults to "").
  • VARNISH_TOKEN (chart apiSecretToken) is gone: nothing read it. If the docs list it anywhere, remove it.

While there, unrelated: line 416 says "GitHub deploys don't pass these variables" (MAILER_DSN, MAILER_EMAIL, ORPHAN_SCAN*), but line 411 says they do. Since template #102 they do, so 416 looks stale.

主要语言
Vue
星标
0
派生
0
PR 合并指标
30 天内没有已合并 PR

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

components-web-app/docs 的其他 Issue

查看 components-web-app/docs 的全部 Issue

相似的 Issue

更多 DevOps Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。