Files
blog/scripts/setup-cnb-remotes.sh
T
zqlit e0218b42bb docs: 迁 CNB 前的架构决策文档 + 构建骨架
- 决策文档:架构总览 / 代码源与构建平台选型 / CNB构建落地方案 /
  EdgeOne双区域 / Gitee / 阿里云ESA / 精简方案
- CNB 构建骨架:deploy/Dockerfile、bin/linux/hugo
  (84MB,linux/amd64 extended 0.128.2,供 CNB 容器 COPY 用)
- scripts/setup-cnb-remotes.sh:双远端切换(CNB 主仓 + GitHub 备份)
- .gitignore 补 .workbuddy/(工作数据不入库)
2026-10-04 12:40:17 +08:00

100 lines
4.0 KiB
Bash
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
#!/usr/bin/env bash
# 把主仓从「GitHub + 自建 Gitea 双推」切换成「CNB 主仓 + GitHub 备份」
#
# 为什么不用「一个 remote 挂多个 pushurl」:
# 实测(2026-10-04)git 对多个 pushurl 是「顺序推、遇错即停」——
# 第一个失败,后面的远端一个都不会推。那就失去备份意义了。
# 故拆成两个 remote + 一个 alias,两段各自独立、互不阻塞。
#
# 用法:bash scripts/setup-cnb-remotes.sh https://cnb.cool/<组织>/<仓库>
# 附带令牌(可直接把凭据写进系统凭据管理器):
# CNB_TOKEN='你的令牌' bash scripts/setup-cnb-remotes.sh https://cnb.cool/<组织>/<仓库>
# 回退:脚本会把改动前的配置备份到 .workbuddy-backup/git-remotes.<时间戳>.txt
set -euo pipefail
CNB_URL="${1:-}"
GH_URL="${GH_URL:-git@github.com:zqlit/blog.git}"
if [ -z "$CNB_URL" ]; then
cat <<'USAGE'
用法:bash scripts/setup-cnb-remotes.sh https://cnb.cool/<组织>/<仓库>
提示:
· CNB 仓库地址直接用仓库页地址,带不带 .git 都行
· CNB 不支持 SSH,只能 HTTPS + 访问令牌(用户名固定填 cnb,密码填令牌)
· 令牌在「个人设置 → 访问令牌」创建,勾选「代码仓库 → 读写」
USAGE
exit 1
fi
case "$CNB_URL" in
https://cnb.cool/*) ;;
*) echo "地址看起来不是 CNB 的:$CNB_URL"; exit 1 ;;
esac
ROOT="$(git rev-parse --show-toplevel)"
cd "$ROOT"
STAMP="$(date +%Y%m%d-%H%M%S)"
BACKUP=".workbuddy-backup/git-remotes.$STAMP.txt"
mkdir -p .workbuddy-backup
{
echo "# 改动前的 git 远端配置($STAMP)"
echo "# 用途:回退参考。本文件含明文凭据,勿提交、勿外传。"
echo
echo "## git remote -v"
git remote -v
echo
echo "## 原始 remote.* 配置"
git config --get-regexp '^remote\.' || true
} > "$BACKUP"
echo "原配置已备份:$BACKUP"
# 1) origin = CNB(主仓,fetch + push)
git remote remove origin 2>/dev/null || true
git remote add origin "$CNB_URL"
# 2) gh = GitHub(备份)
git remote remove gh 2>/dev/null || true
git remote add gh "$GH_URL"
# 3) 自建 Gitea 暂时留着当只读参考。确认新链路稳定后再手工执行:
# git remote remove gitea
# 4) 一条命令推两段。用「;」而不是「&&」——CNB 失败时照样把 GitHub 推上去
git config alias.pushall '!git push origin main; git push gh main'
# 5) 凭据:CNB 只认 HTTPS + 令牌(用户名固定 cnb)
#
# 本机全局 helper 是 GCM(git-credential-manager.exe)。实测它对 cnb.cool 这类
# 第三方 HTTPS 远端会**每次都弹窗**,而且 GCM_INTERACTIVE=never +
# GIT_TERMINAL_PROMPT=0 都压不住 —— git ls-remote 直接挂死(timeout 25s 未返回)。
# → 本仓显式改用 wincred:同样写 Windows 凭据管理器(加密),但没有 UI 弹窗。
# (另:PortableGit 未打包 git-credential-store,exec-path / mingw64/bin 都没有)
if [ -n "${CNB_TOKEN:-}" ]; then
git config --local credential.helper ""
git config --local credential.https://cnb.cool.helper wincred
printf 'protocol=https\nhost=cnb.cool\nusername=cnb\npassword=%s\n\n' "$CNB_TOKEN" \
| git credential-wincred store
echo "凭据已写入 Windows 凭据管理器(wincred,无弹窗);本仓已屏蔽 GCM"
else
echo "未提供 CNB_TOKEN,已跳过凭据写入。需要时重跑:"
echo " CNB_TOKEN='你的令牌' bash scripts/setup-cnb-remotes.sh $CNB_URL"
fi
echo
echo "=== 当前远端 ==="
git remote -v | sed -E 's#://[^@/]*@#://***@#g'
echo
echo "=== 令牌权限检查(CNB 常见坑)==="
echo " · 令牌须在「个人设置 → 访问令牌」勾选 repo-code(读写)"
echo " 只勾了其它 scope 会报 403:token does not have the repo-code:r scope"
echo " · 使用范围(Scope of Use)要涵盖本仓库/"
echo " · 用户名固定 cnb,密码填令牌(不支持 SSH)"
echo
echo "=== 下一步 ==="
echo " git push origin main # 推到 CNB(首次会传全量历史,约 588MB)"
echo " git push gh main # 推到 GitHub 备份"
echo " git pushall # 两段一起"