Commit Graph

1180 Commits

Author SHA1 Message Date
Haitao Pan
e6d5a8d5e3 feat(ci): add Docker Hub namespace support and push workflow 2025-12-06 22:03:02 +08:00
Haitao Pan
c176f3bbcf deploy: remove init service and drop unused workspace volume bindings 2025-12-06 21:21:40 +08:00
Haitao Pan
b38e3199b6 deploy: remove compose version and fix init command YAML formatting 2025-12-06 21:04:08 +08:00
Haitao Pan
209d6edeee deploy: switch docker-compose to use GHCR images instead of local builds 2025-12-06 21:00:30 +08:00
Haitao Pan
7ab9c496b7 ci: force GHCR images to public; update docker-compose to use postgres-runtime 2025-12-06 20:48:53 +08:00
Haitao Pan
ccb367d558 ci(build-service): switch base images to official Node/Golang for consistent builds
Replaced legacy GHCR base-image fallbacks with the official upstream images:
- node:22-bookworm (builder)
- node:22-slim (runtime)
- golang:1.25 (Go services)
2025-12-06 20:27:09 +08:00
81195b3144 Update OpenResty GeoIP base image and patch libraries (#767) 2025-12-06 20:19:27 +08:00
4b09dc8589 Prefer local manifests for dashboard builds (#768) 2025-12-06 20:16:38 +08:00
a5fbe511c5 Improve dashboard security baseline (#766) 2025-12-06 19:58:00 +08:00
Haitao Pan
0612c8e016 base(openresty-geoip): ship default GeoLite2 mmdb + geoip.conf bootstrap 2025-12-06 19:55:10 +08:00
cf1cbc7178 chore: bump quic-go dependencies (#765) 2025-12-06 19:39:02 +08:00
Haitao Pan
89f3c5006a chore(ci): remove unused Go/Node base images from build matrix 2025-12-06 19:28:53 +08:00
Haitao Pan
7a4ac4071a docker(dashboard): upgrade base image packages in both build and runtime stages 2025-12-06 19:19:19 +08:00
Haitao Pan
faa87a7e2b ci(base-images): fix Trivy scan ref (matrix.service → matrix.image) 2025-12-06 19:03:30 +08:00
Haitao Pan
8fb3da7ed0 ci(service-images): switch default base images to upstream node/go 2025-12-06 18:59:43 +08:00
189ecf20a8 fix: update dashboard glob dependency (#764) 2025-12-06 18:54:24 +08:00
Haitao Pan
e4ec3aa1e9 ci(base-images): add Trivy vuln scan for built images 2025-12-06 18:52:18 +08:00
Haitao Pan
bd0b0c4477 base-images: switch go-runtime to golang:1.25 and node-builder to bookworm 2025-12-06 18:36:30 +08:00
a39fe5d778 chore(account): bump quic-go (#763) 2025-12-06 18:20:24 +08:00
dependabot[bot]
3b468d2efc build(deps): bump golang.org/x/crypto in /rag-server (#761)
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.44.0 to 0.45.0.
- [Commits](https://github.com/golang/crypto/compare/v0.44.0...v0.45.0)

---
updated-dependencies:
- dependency-name: golang.org/x/crypto
  dependency-version: 0.45.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-12-06 17:27:10 +08:00
dependabot[bot]
51973b7208 build(deps): bump github.com/quic-go/quic-go in /rag-server (#762)
Bumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) from 0.54.0 to 0.54.1.
- [Release notes](https://github.com/quic-go/quic-go/releases)
- [Commits](https://github.com/quic-go/quic-go/compare/v0.54.0...v0.54.1)

---
updated-dependencies:
- dependency-name: github.com/quic-go/quic-go
  dependency-version: 0.54.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-12-06 17:26:36 +08:00
Haitao Pan
365af9f9d8 ci(build-service-images): switch base images to public upstream defaults
Replaced internal GHCR base images with upstream Node and Go images
(node:22-bookworm, node:22-slim, golang:1.25) to avoid auth failures
and unblock builds on fresh runners. Downstream logic unchanged.
2025-12-06 16:41:38 +08:00
Haitao Pan
517e8ca04b dashboard: drop registry override and clean up build steps 2025-12-06 16:25:40 +08:00
fb90057091 Fix cloud IaC service detail import (#760) 2025-12-06 16:13:52 +08:00
055e1d2635 Handle client-only rendering for IaC service page (#759) 2025-12-06 16:06:59 +08:00
5f5e47cb33 Fix unique keys in Cloud IaC catalog (#758) 2025-12-06 15:46:04 +08:00
Haitao Pan
1c1a09df0a updat dashboard/Dockerfile 2025-12-06 13:22:33 +08:00
2a4b63db09 Fix dashboard Docker build dependencies (#757) 2025-12-06 11:50:31 +08:00
Haitao Pan
e96833fc33 build(dashboard): bump node base images to 22-bookworm and use yarn for next build 2025-12-06 11:37:36 +08:00
c6ba42fdca Fix matrix support references in composite actions (#756) 2025-12-06 11:29:54 +08:00
1cd712ebb9 Fix download page type import (#755) 2025-12-06 11:21:30 +08:00
a0a92fe918 Rebuild docker-compose stack for XControl (#754) 2025-12-06 11:11:20 +08:00
9e13bd8255 Use public Node images for dashboard build (#753) 2025-12-06 11:01:37 +08:00
53dbd235c4 Fix account module path (#751)
* Fix module path for account service

* Restructure account module path
2025-12-06 10:32:31 +08:00
5abced6290 Fix rag-server module path (#752)
* Fix rag-server module path

* Align rag-server module imports
2025-12-06 10:27:24 +08:00
Haitao Pan
c5823ddf57 fix(makefile): add idempotent go mod init for account and rag-server 2025-12-06 10:09:06 +08:00
Haitao Pan
b94b9266bb fix(go-modules): correct module paths for account and rag-server
Split repositories into two standalone Go modules and fixed their
respective Makefile init targets. Updated:

- account: module → `account`
- rag-server: module → `rag-server`
2025-12-06 10:00:34 +08:00
Haitao Pan
42c3b1ecb7 chore(docker): bump Go base image to 1.25 for account and rag-server 2025-12-05 00:41:45 +08:00
Haitao Pan
eb91a7fa52 feat: add go modules for account & rag-server services 2025-12-05 00:38:33 +08:00
Haitao Pan
f9d120fc3e fix(rag-server): correct Dockerfile WORKDIR so go.mod is detected during build 2025-12-04 23:44:55 +08:00
Haitao Pan
595ad65292 fix(rag-server): correct Dockerfile WORKDIR so go.mod is detected during build 2025-12-04 23:37:22 +08:00
Haitao Pan
05a1db3aa2 fix(docker): install curl in builder image for init-go 2025-12-04 23:25:09 +08:00
Haitao Pan
eaa1412bcb build: ensure Go init runs before binary compilation 2025-12-04 23:20:47 +08:00
Haitao Pan
c1f78ee1da fix(docker): expose GO_VERSION arg in builder stages
Builder images install Go SDK and must receive GO_VERSION explicitly.
Adds missing ARG to account and rag-server Dockerfiles.
2025-12-04 23:15:00 +08:00
Haitao Pan
7601669fd4 build: drop ARG gymnastics; embed Go install in builder stages 2025-12-04 23:11:20 +08:00
Haitao Pan
447f60ba51 ci(docker): simplify Go builder pipeline and trim runtime images 2025-12-04 22:57:12 +08:00
Haitao Pan
87d2e90244 fix(docker): add default go-runtime image arg for account and rag-server builds 2025-12-04 22:42:40 +08:00
Haitao Pan
ce0f0e10c9 fix(docker): align account build stages with go-runtime INSTALL_GO args 2025-12-04 22:23:18 +08:00
Haitao Pan
cb291a0868 fix(ci): add checkout step for local actions and rename pipeline to XControl Unified CI/CD Pipeline 2025-12-04 22:15:49 +08:00
Haitao Pan
9cda9f67d7 feat(docker): enhance go-runtime with optional Go SDK and unify rag-server multi-stage build 2025-12-04 22:09:05 +08:00