From 66a17f8ed5f9d779d4aa9f46ff545c5543ca6e59 Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 03:39:32 +0900 Subject: [PATCH 01/15] =?UTF-8?q?feat:=20CI/CD=20=EA=B5=AC=ED=98=84?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/cd-dev.yml | 72 ++++++++++++++ .github/workflows/ci.yml | 175 ++++++++++++++++++++++++++++++++++ docker/kyeoungwoon/dockerfile | 40 ++++++++ scripts/cd-dev.sh | 87 +++++++++++++++++ 4 files changed, 374 insertions(+) create mode 100644 .github/workflows/cd-dev.yml create mode 100644 .github/workflows/ci.yml create mode 100644 docker/kyeoungwoon/dockerfile create mode 100644 scripts/cd-dev.sh diff --git a/.github/workflows/cd-dev.yml b/.github/workflows/cd-dev.yml new file mode 100644 index 00000000..af4bcd1c --- /dev/null +++ b/.github/workflows/cd-dev.yml @@ -0,0 +1,72 @@ +name: CD on Dev + +on: + push: + branches: + - develop + paths: + - 'src/**' + - 'build.gradle.kts' + - 'docker/**' + - 'cd.yml' + + workflow_dispatch: + inputs: + environment: + description: 'Deploy environment' + required: true + type: choice + options: + - dev + - prod + +jobs: + # 1. 공통 빌드/테스트 워크플로우 호출 (ci.yml 재사용) + ci-and-build: + uses: ./.github/workflows/ci.yml + with: + environment: ${{ inputs.environment }} + + # 2. Deploy Job + deploy: + needs: ci-and-build + runs-on: ubuntu-latest + # 빌드 단계에서 결정된 환경 사용 + environment: ${{ needs.ci-and-build.outputs.environment }} + + env: + ENVIRONMENT: ${{ needs.ci-and-build.outputs.environment }} + REPO_OWNER: ${{ needs.ci-and-build.outputs.repo_owner }} + IMAGE_TAG: ${{ needs.ci-and-build.outputs.image_tag }} + + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: SSH 접속 및 스크립트 실행 + uses: appleboy/ssh-action@v1 + env: + APPLICATION_PROD: ${{ secrets.APPLICATION_PROD }} + APPLICATION_DEV: ${{ secrets.APPLICATION_DEV }} + APPLICATION_SECRET: ${{ secrets.APPLICATION_SECRET }} + DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} + DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }} + with: + host: ${{ secrets.SERVER_SSH_HOST }} + username: ${{ secrets.SERVER_SSH_USERNAME }} + key: ${{ secrets.SERVER_SSH_PRIVATE_KEY }} + port: ${{ secrets.SERVER_SSH_PORT }} + envs: APPLICATION_PROD,APPLICATION_DEV,APPLICATION_SECRET,ENVIRONMENT,IMAGE_TAG,REPO_OWNER,DOCKER_IMAGE_NAME,DOCKERHUB_TOKEN,DOCKERHUB_USERNAME + script_path: scripts/cd-dev.sh + + - name: Deployment Summary + if: always() + run: | + echo "### Deployment Summary :rocket:" >> $GITHUB_STEP_SUMMARY + echo "" >> $GITHUB_STEP_SUMMARY + echo "- **Environment:** ${{ env.ENVIRONMENT }}" >> $GITHUB_STEP_SUMMARY + echo "- **Branch:** ${{ github.ref_name }}" >> $GITHUB_STEP_SUMMARY + echo "- **Commit:** ${{ github.sha }}" >> $GITHUB_STEP_SUMMARY + echo "- **Image:** ${{ secrets.DOCKER_IMAGE_NAME }}:${{ env.ENVIRONMENT }}-latest" >> $GITHUB_STEP_SUMMARY + echo "- **Server:** ${{ secrets.SERVER_SSH_HOST }}" >> $GITHUB_STEP_SUMMARY + echo "- **Status:** ${{ job.status }}" >> $GITHUB_STEP_SUMMARY diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 00000000..758e76be --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,175 @@ +name: Backend CI & Build + +on: + pull_request: + branches: + - develop + - main + + workflow_call: + inputs: + environment: + description: 'Deploy environment (optional)' + required: false + type: string + outputs: + environment: + description: "Determined environment" + value: ${{ jobs.build-and-test.outputs.environment }} + repo_owner: + description: "Repository owner" + value: ${{ jobs.build-and-test.outputs.repo_owner }} + image_tag: + description: "Docker image tag" + value: ${{ jobs.build-and-test.outputs.image_tag }} + +concurrency: + group: ci-${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true # 이전 실행 취소 + +jobs: + # Job 1: 빌드 및 테스트 (한 번만 실행) + build-and-test: + runs-on: self-hosted + + permissions: + contents: read + checks: write + pull-requests: write + + outputs: + environment: ${{ steps.set-env.outputs.environment }} + repo_owner: ${{ steps.set-env.outputs.repo_owner }} + image_tag: ${{ steps.set-env.outputs.image_tag }} + + strategy: + matrix: + platform: [ linux/amd64, linux/arm64 ] + include: + - platform: linux/amd64 + tag-suffix: amd64 + - platform: linux/arm64 + tag-suffix: arm64 + + steps: + - name: Checkout code + uses: actions/checkout@v4 + + - name: Set deployment environment + id: set-env + run: | + INPUT_ENV="${{ inputs.environment }}" + + # PR일 때는 'test' 환경으로 설정 + if [[ "${{ github.event_name }}" == "pull_request" ]]; then + echo "Running in PR mode - Setting test environment for build" + ENVIRONMENT="test" + elif [[ -n "$INPUT_ENV" ]]; then + ENVIRONMENT="$INPUT_ENV" + + # CD에서 호출한 경우 branch에 따라서 환경 결정 + elif [[ "${{ github.ref }}" == "refs/heads/main" ]]; then + ENVIRONMENT="prod" + elif [[ "${{ github.ref }}" == "refs/heads/develop" ]]; then + ENVIRONMENT="dev" + else + ENVIRONMENT="test" + fi + + echo "environment=${ENVIRONMENT}" >> $GITHUB_OUTPUT + + REPO_OWNER=$(echo "${{ github.repository_owner }}" | tr '[:upper:]' '[:lower:]') + echo "repo_owner=${REPO_OWNER}" >> $GITHUB_OUTPUT + + SHORT_SHA=$(echo "${{ github.sha }}" | cut -c1-7) + IMAGE_TAG="${ENVIRONMENT}-${SHORT_SHA}" + echo "image_tag=${IMAGE_TAG}" >> $GITHUB_OUTPUT + + - name: Setup JDK 21 + uses: actions/setup-java@v4 + with: + java-version: '21' + distribution: 'corretto' + cache: gradle + + - name: Grant execute permission for gradlew + run: chmod +x gradlew + + - name: Compile Check + run: ./gradlew compileJava compileTestJava + + - name: Run Tests + run: ./gradlew test + + - name: Publish Test Results + uses: EnricoMi/publish-unit-test-result-action@v2 + if: always() + with: + files: build/test-results/test/*.xml + check_name: "Backend Test Results" + + - name: Build JAR + run: ./gradlew bootJar + + - name: Set up QEMU + uses: docker/setup-qemu-action@v3 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log in to Docker Hub + uses: docker/login-action@v3 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + + - name: Build and push Docker image + uses: docker/build-push-action@v6 + with: + context: . + file: docker/kyeoungwoon/dockerfile + push: true + tags: | + ${{ secrets.DOCKER_IMAGE_NAME }}:${{ steps.set-env.outputs.image_tag }}-${{ matrix.tag-suffix }} + platforms: ${{ matrix.platform }} + cache-from: type=gha,scope=${{ matrix.platform }} + cache-to: type=gha,mode=max,scope=${{ matrix.platform }} + + # Job 3: Multi-arch manifest 생성 + create-manifest: + needs: [ build-and-test ] + runs-on: self-hosted + steps: + - name: Log in to Docker Hub + uses: docker/login-action@v3 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + + - name: Create and push manifest + run: | + IMAGE_TAG="${{ needs.build-and-test.outputs.image_tag }}" + ENVIRONMENT="${{ needs.build-and-test.outputs.environment }}" + + # 특정 커밋용 manifest 생성 + docker buildx imagetools create -t ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG} \ + ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}-amd64 \ + ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}-arm64 + + # 환경별 latest manifest 생성 + docker buildx imagetools create -t ${{ secrets.DOCKER_IMAGE_NAME }}:${ENVIRONMENT}-latest \ + ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}-amd64 \ + ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}-arm64 + + echo "✅ Created manifests:" + echo " - ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}" + echo " - ${{ secrets.DOCKER_IMAGE_NAME }}:${ENVIRONMENT}-latest" + + - name: Build Summary + if: always() + run: | + echo "### Build Summary :package:" >> $GITHUB_STEP_SUMMARY + echo "" >> $GITHUB_STEP_SUMMARY + echo "- **Environment:** ${{ steps.set-env.outputs.environment }}" >> $GITHUB_STEP_SUMMARY + echo "- **Image Tag:** ${{ steps.set-env.outputs.image_tag }}" >> $GITHUB_STEP_SUMMARY + echo "- **Platforms:** linux/amd64, linux/arm64" >> $GITHUB_STEP_SUMMARY diff --git a/docker/kyeoungwoon/dockerfile b/docker/kyeoungwoon/dockerfile new file mode 100644 index 00000000..f62aea77 --- /dev/null +++ b/docker/kyeoungwoon/dockerfile @@ -0,0 +1,40 @@ +# ================================= +# Run stage only +# ================================= +FROM eclipse-temurin:21-jre-jammy +WORKDIR /app + +LABEL maintainer="UMC PRODUCT TEAM SERVER TEAM" +LABEL description="UMC PRODUCT Official SpringBoot Backend Server" + +# Create non-root user +RUN groupadd -r spring && useradd -r -g spring spring + +# 이미 build된 jar 파일을 docker 안으로 복사 +COPY --chown=spring:spring build/libs/*.jar app.jar +RUN chmod 444 app.jar + +# 로그 디렉토리 생성 및 권한 설정 +RUN mkdir -p /app/logs && chown -R spring:spring /app/logs + +# Switch to non-root user +USER spring:spring + +# Expose application port +EXPOSE 8080 + +# JVM options +ENV JAVA_OPTS="-XX:+UseContainerSupport \ + -XX:MaxRAMPercentage=75.0 \ + -XX:+UseG1GC \ + -XX:+ExitOnOutOfMemoryError \ + -XX:+HeapDumpOnOutOfMemoryError \ + -XX:HeapDumpPath=/tmp/heapdump.hprof \ + -Duser.timezone=Asia/Seoul \ + -Djava.security.egd=file:/dev/./urandom" + +# Use exec form with sh -c so JAVA_OPTS is expanded and signals forwarded +ENTRYPOINT ["sh", "-c", "exec java $JAVA_OPTS -jar app.jar"] + +# Optional healthcheck (uncomment if actuator/health endpoint exists) +# HEALTHCHECK --interval=30s --timeout=5s CMD curl -f http://localhost:8080/actuator/health || exit 1 diff --git a/scripts/cd-dev.sh b/scripts/cd-dev.sh new file mode 100644 index 00000000..01d884c6 --- /dev/null +++ b/scripts/cd-dev.sh @@ -0,0 +1,87 @@ +#!/bin/bash +set -e + +# ------------------------------------------------------------------ +# 변수 할당 (GitHub Actions에서 envs로 넘어온 값들) +# ------------------------------------------------------------------ +# 주의: YAML에서 envs로 넘겨준 변수 이름과 정확히 일치해야 합니다. +# ------------------------------------------------------------------ + +echo "==============================" +echo "🚀 배포 시작: $ENVIRONMENT 환경" +echo "==============================" + +# [1] Docker 설치 확인 +echo "[1] Docker 설치 확인" +if which docker > /dev/null 2>&1; then + echo "✅ Docker 인식됨: $(which docker)" +else + echo "⚠️ PATH에 /usr/local/bin 추가" + export PATH="$PATH:/usr/local/bin" + if which docker > /dev/null 2>&1; then + echo "✅ Docker 인식됨: $(which docker)" + else + echo "❌ Docker를 찾을 수 없습니다" + exit 1 + fi +fi + +# [2] 환경별 배포 디렉토리 설정 +# YAML의 ${{ secrets... }} 대신 환경변수 $APP_DIR_PRODUCTION 등을 사용 +if [[ "$ENVIRONMENT" == "prod" ]]; then + APP_DIR=$APP_DIR_PRODUCTION +else + APP_DIR=$APP_DIR_DEVELOPMENT +fi + +echo "📂 배포 경로: $APP_DIR" + +# [3] 설정 파일 생성 +mkdir -p $APP_DIR/config +echo "$APPLICATION_PROD" > $APP_DIR/config/application-prod.yml +echo "$APPLICATION_DEV" > $APP_DIR/config/application-dev.yml +echo "$APPLICATION_SECRET" > $APP_DIR/config/application-secret.yml + +# 보안을 위해 권한 설정 (선택사항) +chmod 600 $APP_DIR/config/application-*.yml +echo "✅ 환경 설정 파일 생성 완료" + +# [4] Docker Hub 로그인 +echo "" +echo "[2] Docker Hub 로그인" +echo "$DOCKERHUB_TOKEN" | docker login -u "$DOCKERHUB_USERNAME" --password-stdin + +if [ $? -eq 0 ]; then + echo "✅ Docker Hub 로그인 성공" +else + echo "❌ Docker Hub 로그인 실패" + exit 1 +fi + +# [5] Docker Compose 실행 +cd $APP_DIR + +# 롤백 및 버전 관리를 위해 태그 지정 (docker-compose.yml에서 ${TAG}를 쓴다고 가정) +export TAG=$IMAGE_TAG +export DOCKER_IMAGE_NAME=$DOCKER_IMAGE_NAME + +# 기존 컨테이너 중지 및 최신 이미지 Pull & 실행 +docker compose pull +docker compose up -d + +if [ $? -eq 0 ]; then + echo "✅ 컨테이너 재시작 성공" +else + echo "❌ 컨테이너 재시작 실패" + exit 1 +fi + +# 미사용 이미지 정리 +docker image prune -f + +echo "" +echo "==============================" +echo "🎉 배포 완료!" +echo "==============================" +echo "환경: $ENVIRONMENT" +echo "이미지: $DOCKER_IMAGE_NAME:$ENVIRONMENT-latest" From e48b658d2e6cae44836b94a28462f2f4aa3462ab Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 03:45:12 +0900 Subject: [PATCH 02/15] =?UTF-8?q?feat:=20jar=EC=9D=84=20=EC=8B=A4=ED=96=89?= =?UTF-8?q?=ED=95=98=EB=8A=94=20dockerfile=20=EC=83=9D=EC=84=B1?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- docker/app/dockerfile | 45 +++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+) diff --git a/docker/app/dockerfile b/docker/app/dockerfile index e69de29b..a0e59e07 100644 --- a/docker/app/dockerfile +++ b/docker/app/dockerfile @@ -0,0 +1,45 @@ +FROM amazoncorretto:21-alpine-jre + +LABEL maintainer="UMC Product Team" +LABEL description="UMC Product Team Official SpringBoot Backend" + +# 작업 디렉토리 설정 +WORKDIR /app + +# curl 설치 (헬스체크용) + non-root 유저 생성 +RUN apk add --no-cache curl && \ + addgroup -S spring && \ + adduser -S spring -G spring && \ + mkdir -p /app/logs && \ + chown -R spring:spring /app + +# JAR 파일 복사 (GitHub Actions에서 빌드된 JAR) +# docker build 시 context에서 복사됨 +COPY --chown=spring:spring build/libs/*.jar app.jar + +# spring 유저로 전환 +USER spring:spring + +# 애플리케이션 포트 +EXPOSE 8080 + +# Health check 설정 +# curl은 Alpine Linux에 기본 포함됨 +HEALTHCHECK --interval=30s \ + --timeout=3s \ + --start-period=40s \ + --retries=3 \ + CMD curl -f http://localhost:8080/actuator/health || exit 1 + +# JVM 옵션 및 애플리케이션 실행 +# 환경변수로 힙 메모리 설정 가능 (기본값: dev 환경) +ENV JAVA_OPTS="-Xms1400m -Xmx1400m" + +ENTRYPOINT ["sh", "-c", "java ${JAVA_OPTS} \ + -XX:+UseG1GC \ + -XX:MaxMetaspaceSize=256m \ + -XX:+HeapDumpOnOutOfMemoryError \ + -XX:HeapDumpPath=/app/logs/heapdump.hprof \ + -Duser.timezone=Asia/Seoul \ + -Djava.security.egd=file:/dev/./urandom \ + -jar app.jar"] From 03188c489b889755a36b013b3b6bdd65358de7b8 Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 03:46:53 +0900 Subject: [PATCH 03/15] =?UTF-8?q?feat:=20script=EC=97=90=20=ED=99=98?= =?UTF-8?q?=EA=B2=BD=EB=B3=80=EC=88=98=20=EB=88=84=EB=9D=BD=20=EC=8B=9C=20?= =?UTF-8?q?=EC=98=A4=EB=A5=98=EB=A5=BC=20=EB=B0=98=ED=99=98=ED=95=98?= =?UTF-8?q?=EB=8F=84=EB=A1=9D=20=EA=B0=9C=EC=84=A0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- scripts/cd-dev.sh | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/scripts/cd-dev.sh b/scripts/cd-dev.sh index 01d884c6..2d186097 100644 --- a/scripts/cd-dev.sh +++ b/scripts/cd-dev.sh @@ -7,6 +7,19 @@ set -e # 주의: YAML에서 envs로 넘겨준 변수 이름과 정확히 일치해야 합니다. # ------------------------------------------------------------------ +# 필수 환경 변수 체크 +: "${ENVIRONMENT:?ENVIRONMENT 변수가 설정되지 않았습니다.}" +: "${DOCKERHUB_USERNAME:?DOCKERHUB_USERNAME 변수가 설정되지 않았습니다.}" +: "${DOCKERHUB_TOKEN:?DOCKERHUB_TOKEN 변수가 설정되지 않았습니다.}" +: "${DOCKER_IMAGE_NAME:?DOCKER_IMAGE_NAME 변수가 설정되지 않았습니다.}" +: "${IMAGE_TAG:?IMAGE_TAG 변수가 설정되지 않았습니다.}" +: "${APP_DIR_PRODUCTION:?APP_DIR_PRODUCTION 변수가 설정되지 않았습니다.}" +: "${APP_DIR_DEVELOPMENT:?APP_DIR_DEVELOPMENT 변수가 설정되지 않았습니다.}" +: "${APPLICATION_PROD:?APPLICATION_PROD 변수가 설정되지 않았습니다.}" +: "${APPLICATION_DEV:?APPLICATION_DEV 변수가 설정되지 않았습니다.}" +: "${APPLICATION_SECRET:?APPLICATION_SECRET 변수가 설정되지 않았습니다.}" + + echo "==============================" echo "🚀 배포 시작: $ENVIRONMENT 환경" echo "==============================" From aaf316b61c9637e9ce719251b73dd298c610eb8d Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 03:47:19 +0900 Subject: [PATCH 04/15] =?UTF-8?q?feat:=20CI/CD=20=ED=8C=8C=EC=9D=BC=20?= =?UTF-8?q?=EC=9D=B4=EB=A6=84=20=EB=B3=80=EA=B2=BD=20=EB=B0=8F=20=EC=88=98?= =?UTF-8?q?=EB=8F=99=EC=9C=BC=EB=A1=9C=20CI=EB=A5=BC=20=ED=8A=B8=EB=A6=AC?= =?UTF-8?q?=EA=B1=B0=ED=95=A0=20=EC=88=98=20=EC=9E=88=EB=8F=84=EB=A1=9D=20?= =?UTF-8?q?=EB=B3=80=EA=B2=BD?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/cd-dev.yml | 4 ++-- .github/workflows/ci.yml | 12 +++++++++++- 2 files changed, 13 insertions(+), 3 deletions(-) diff --git a/.github/workflows/cd-dev.yml b/.github/workflows/cd-dev.yml index af4bcd1c..c532ae7c 100644 --- a/.github/workflows/cd-dev.yml +++ b/.github/workflows/cd-dev.yml @@ -1,4 +1,4 @@ -name: CD on Dev +name: CD [Development] on: push: @@ -58,7 +58,7 @@ jobs: port: ${{ secrets.SERVER_SSH_PORT }} envs: APPLICATION_PROD,APPLICATION_DEV,APPLICATION_SECRET,ENVIRONMENT,IMAGE_TAG,REPO_OWNER,DOCKER_IMAGE_NAME,DOCKERHUB_TOKEN,DOCKERHUB_USERNAME script_path: scripts/cd-dev.sh - + - name: Deployment Summary if: always() run: | diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 758e76be..8030ae3c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,4 +1,4 @@ -name: Backend CI & Build +name: CI on: pull_request: @@ -6,6 +6,16 @@ on: - develop - main + workflow_dispatch: + inputs: + environment: + description: 'Deploy environment' + required: true + type: choice + options: + - dev + - prod + workflow_call: inputs: environment: From 741d0b90d841aa38323376a87960d6cc06c2fb1c Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 03:59:14 +0900 Subject: [PATCH 05/15] =?UTF-8?q?feat:=20gradle=20wrapper=EB=A5=BC=20gitig?= =?UTF-8?q?nore=EC=97=90=EC=84=9C=20=EC=A0=9C=EC=99=B8=20=EB=B0=8F=20?= =?UTF-8?q?=EC=82=AC=EC=86=8C=ED=95=9C=20=EC=88=98=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/cd-dev.yml | 1 + .gitignore | 13 +++++++------ gradle/wrapper/gradle-wrapper.jar | Bin 0 -> 43764 bytes scripts/cd-dev.sh | 5 ++++- 4 files changed, 12 insertions(+), 7 deletions(-) create mode 100644 gradle/wrapper/gradle-wrapper.jar diff --git a/.github/workflows/cd-dev.yml b/.github/workflows/cd-dev.yml index c532ae7c..c022e836 100644 --- a/.github/workflows/cd-dev.yml +++ b/.github/workflows/cd-dev.yml @@ -26,6 +26,7 @@ jobs: uses: ./.github/workflows/ci.yml with: environment: ${{ inputs.environment }} + secrets: inherit # 2. Deploy Job deploy: diff --git a/.gitignore b/.gitignore index 354a9e62..2125a217 100644 --- a/.gitignore +++ b/.gitignore @@ -11,9 +11,6 @@ application-*.yml .gradle build/ -!gradle/wrapper/gradle-wrapper.jar -!**/src/main/**/build/ -!**/src/test/**/build/ ### STS ### .apt_generated @@ -33,10 +30,8 @@ bin/ *.iml *.ipr -!**/src/main/**/out/ -!**/src/test/**/out/ # 빌드 결과물인 out은 무시해야 하나, 소스코드 내에 있는건 지켜야 함 -/out/ +out/ ### NetBeans ### /nbproject/private/ @@ -237,3 +232,9 @@ $RECYCLE.BIN/ *.lnk # End of https://www.toptal.com/developers/gitignore/api/java,intellij+all,macos,windows,linux + +!gradle/wrapper/gradle-wrapper.jar +!**/src/main/**/build/ +!**/src/test/**/build/ +!**/src/main/**/out/ +!**/src/test/**/out/ diff --git a/gradle/wrapper/gradle-wrapper.jar b/gradle/wrapper/gradle-wrapper.jar new file mode 100644 index 0000000000000000000000000000000000000000..1b33c55baabb587c669f562ae36f953de2481846 GIT binary patch literal 43764 zcma&OWmKeVvL#I6?i3D%6z=Zs?ofE*?rw#G$eqJB ziT4y8-Y@s9rkH0Tz>ll(^xkcTl)CY?rS&9VNd66Yc)g^6)JcWaY(5$5gt z8gr3SBXUTN;~cBgz&})qX%#!Fxom2Yau_`&8)+6aSN7YY+pS410rRUU*>J}qL0TnJ zRxt*7QeUqTh8j)Q&iavh<}L+$Jqz))<`IfKussVk%%Ah-Ti?Eo0hQH!rK%K=#EAw0 zwq@@~XNUXRnv8$;zv<6rCRJ6fPD^hfrh;0K?n z=p!u^3xOgWZ%f3+?+>H)9+w^$Tn1e;?UpVMJb!!;f)`6f&4|8mr+g)^@x>_rvnL0< zvD0Hu_N>$(Li7|Jgu0mRh&MV+<}`~Wi*+avM01E)Jtg=)-vViQKax!GeDc!xv$^mL z{#OVBA$U{(Zr8~Xm|cP@odkHC*1R8z6hcLY#N@3E-A8XEvpt066+3t9L_6Zg6j@9Q zj$$%~yO-OS6PUVrM2s)(T4#6=JpI_@Uz+!6=GdyVU?`!F=d;8#ZB@(5g7$A0(`eqY z8_i@3w$0*es5mrSjhW*qzrl!_LQWs4?VfLmo1Sd@Ztt53+etwzAT^8ow_*7Jp`Y|l z*UgSEwvxq+FYO!O*aLf-PinZYne7Ib6ny3u>MjQz=((r3NTEeU4=-i0LBq3H-VJH< z^>1RE3_JwrclUn9vb7HcGUaFRA0QHcnE;6)hnkp%lY1UII#WPAv?-;c?YH}LWB8Nl z{sx-@Z;QxWh9fX8SxLZk8;kMFlGD3Jc^QZVL4nO)1I$zQwvwM&_!kW+LMf&lApv#< zur|EyC|U@5OQuph$TC_ZU`{!vJp`13e9alaR0Dbn5ikLFH7>eIz4QbV|C=%7)F=qo z_>M&5N)d)7G(A%c>}UCrW!Ql_6_A{?R7&CL`;!KOb3 z8Z=$YkV-IF;c7zs{3-WDEFJzuakFbd*4LWd<_kBE8~BFcv}js_2OowRNzWCtCQ6&k z{&~Me92$m*@e0ANcWKuz)?YjB*VoSTx??-3Cc0l2U!X^;Bv@m87eKHukAljrD54R+ zE;@_w4NPe1>3`i5Qy*3^E9x#VB6?}v=~qIprrrd5|DFkg;v5ixo0IsBmik8=Y;zv2 z%Bcf%NE$a44bk^`i4VwDLTbX=q@j9;JWT9JncQ!+Y%2&HHk@1~*L8-{ZpY?(-a9J-1~<1ltr9i~D9`P{XTIFWA6IG8c4;6bFw*lzU-{+?b&%OcIoCiw00n>A1ra zFPE$y@>ebbZlf(sN_iWBzQKDV zmmaLX#zK!@ZdvCANfwV}9@2O&w)!5gSgQzHdk2Q`jG6KD7S+1R5&F)j6QTD^=hq&7 zHUW+r^da^%V(h(wonR(j?BOiC!;y=%nJvz?*aW&5E87qq;2z`EI(f zBJNNSMFF9U{sR-af5{IY&AtoGcoG)Iq-S^v{7+t0>7N(KRoPj;+2N5;9o_nxIGjJ@ z7bYQK)bX)vEhy~VL%N6g^NE@D5VtV+Q8U2%{ji_=6+i^G%xeskEhH>Sqr194PJ$fB zu1y^){?9Vkg(FY2h)3ZHrw0Z<@;(gd_dtF#6y_;Iwi{yX$?asr?0N0_B*CifEi7<6 zq`?OdQjCYbhVcg+7MSgIM|pJRu~`g?g3x?Tl+V}#$It`iD1j+!x+!;wS0+2e>#g?Z z*EA^k7W{jO1r^K~cD#5pamp+o@8&yw6;%b|uiT?{Wa=4+9<}aXWUuL#ZwN1a;lQod zW{pxWCYGXdEq9qAmvAB904}?97=re$>!I%wxPV#|f#@A*Y=qa%zHlDv^yWbR03%V0 zprLP+b(#fBqxI%FiF*-n8HtH6$8f(P6!H3V^ysgd8de-N(@|K!A< z^qP}jp(RaM9kQ(^K(U8O84?D)aU(g?1S8iWwe)gqpHCaFlJxb*ilr{KTnu4_@5{K- z)n=CCeCrPHO0WHz)dDtkbZfUfVBd?53}K>C5*-wC4hpDN8cGk3lu-ypq+EYpb_2H; z%vP4@&+c2p;thaTs$dc^1CDGlPG@A;yGR5@$UEqk6p58qpw#7lc<+W(WR;(vr(D>W z#(K$vE#uBkT=*q&uaZwzz=P5mjiee6>!lV?c}QIX%ZdkO1dHg>Fa#xcGT6~}1*2m9 zkc7l3ItD6Ie~o_aFjI$Ri=C!8uF4!Ky7iG9QTrxVbsQroi|r)SAon#*B*{}TB-?=@ z8~jJs;_R2iDd!$+n$%X6FO&PYS{YhDAS+U2o4su9x~1+U3z7YN5o0qUK&|g^klZ6X zj_vrM5SUTnz5`*}Hyts9ADwLu#x_L=nv$Z0`HqN`Zo=V>OQI)fh01n~*a%01%cx%0 z4LTFVjmW+ipVQv5rYcn3;d2o4qunWUY!p+?s~X~(ost@WR@r@EuDOSs8*MT4fiP>! zkfo^!PWJJ1MHgKS2D_hc?Bs?isSDO61>ebl$U*9*QY(b=i&rp3@3GV@z>KzcZOxip z^dzA~44;R~cnhWz7s$$v?_8y-k!DZys}Q?4IkSyR!)C0j$(Gm|t#e3|QAOFaV2}36 z?dPNY;@I=FaCwylc_;~kXlZsk$_eLkNb~TIl8QQ`mmH&$*zwwR8zHU*sId)rxHu*K z;yZWa8UmCwju%aSNLwD5fBl^b0Ux1%q8YR*uG`53Mi<`5uA^Dc6Ync)J3N7;zQ*75)hf%a@{$H+%S?SGT)ks60)?6j$ zspl|4Ad6@%-r1t*$tT(en!gIXTUDcsj?28ZEzz)dH)SV3bZ+pjMaW0oc~rOPZP@g! zb9E+ndeVO_Ib9c_>{)`01^`ZS198 z)(t=+{Azi11$eu%aU7jbwuQrO`vLOixuh~%4z@mKr_Oc;F%Uq01fA)^W&y+g16e?rkLhTxV!EqC%2}sx_1u7IBq|}Be&7WI z4I<;1-9tJsI&pQIhj>FPkQV9{(m!wYYV@i5h?A0#BN2wqlEwNDIq06|^2oYVa7<~h zI_OLan0Do*4R5P=a3H9`s5*>xU}_PSztg`+2mv)|3nIy=5#Z$%+@tZnr> zLcTI!Mxa`PY7%{;KW~!=;*t)R_sl<^b>eNO@w#fEt(tPMg_jpJpW$q_DoUlkY|uo> z0-1{ouA#;t%spf*7VjkK&$QrvwUERKt^Sdo)5@?qAP)>}Y!h4(JQ!7{wIdkA+|)bv z&8hBwoX4v|+fie}iTslaBX^i*TjwO}f{V)8*!dMmRPi%XAWc8<_IqK1jUsApk)+~R zNFTCD-h>M5Y{qTQ&0#j@I@tmXGj%rzhTW5%Bkh&sSc=$Fv;M@1y!zvYG5P2(2|(&W zlcbR1{--rJ&s!rB{G-sX5^PaM@3EqWVz_y9cwLR9xMig&9gq(voeI)W&{d6j1jh&< zARXi&APWE1FQWh7eoZjuP z;vdgX>zep^{{2%hem;e*gDJhK1Hj12nBLIJoL<=0+8SVEBx7!4Ea+hBY;A1gBwvY<)tj~T=H`^?3>zeWWm|LAwo*S4Z%bDVUe z6r)CH1H!(>OH#MXFJ2V(U(qxD{4Px2`8qfFLG+=a;B^~Te_Z!r3RO%Oc#ZAHKQxV5 zRYXxZ9T2A%NVJIu5Pu7!Mj>t%YDO$T@M=RR(~mi%sv(YXVl`yMLD;+WZ{vG9(@P#e zMo}ZiK^7^h6TV%cG+;jhJ0s>h&VERs=tuZz^Tlu~%d{ZHtq6hX$V9h)Bw|jVCMudd zwZ5l7In8NT)qEPGF$VSKg&fb0%R2RnUnqa){)V(X(s0U zkCdVZe6wy{+_WhZh3qLp245Y2RR$@g-!9PjJ&4~0cFSHMUn=>dapv)hy}|y91ZWTV zCh=z*!S3_?`$&-eZ6xIXUq8RGl9oK0BJw*TdU6A`LJqX9eS3X@F)g$jLkBWFscPhR zpCv8#KeAc^y>>Y$k^=r|K(DTC}T$0#jQBOwB#@`P6~*IuW_8JxCG}J4va{ zsZzt}tt+cv7=l&CEuVtjD6G2~_Meh%p4RGuY?hSt?(sreO_F}8r7Kp$qQdvCdZnDQ zxzc*qchE*E2=WK)^oRNa>Ttj`fpvF-JZ5tu5>X1xw)J@1!IqWjq)ESBG?J|ez`-Tc zi5a}GZx|w-h%5lNDE_3ho0hEXMoaofo#Z;$8|2;EDF&*L+e$u}K=u?pb;dv$SXeQM zD-~7P0i_`Wk$#YP$=hw3UVU+=^@Kuy$>6?~gIXx636jh{PHly_a2xNYe1l60`|y!7 z(u%;ILuW0DDJ)2%y`Zc~hOALnj1~txJtcdD#o4BCT68+8gZe`=^te6H_egxY#nZH&P*)hgYaoJ^qtmpeea`35Fw)cy!w@c#v6E29co8&D9CTCl%^GV|X;SpneSXzV~LXyRn-@K0Df z{tK-nDWA!q38M1~`xUIt_(MO^R(yNY#9@es9RQbY@Ia*xHhD&=k^T+ zJi@j2I|WcgW=PuAc>hs`(&CvgjL2a9Rx zCbZyUpi8NWUOi@S%t+Su4|r&UoU|ze9SVe7p@f1GBkrjkkq)T}X%Qo1g!SQ{O{P?m z-OfGyyWta+UCXH+-+(D^%kw#A1-U;?9129at7MeCCzC{DNgO zeSqsV>W^NIfTO~4({c}KUiuoH8A*J!Cb0*sp*w-Bg@YfBIPZFH!M}C=S=S7PLLcIG zs7K77g~W)~^|+mx9onzMm0qh(f~OsDTzVmRtz=aZTllgR zGUn~_5hw_k&rll<4G=G+`^Xlnw;jNYDJz@bE?|r866F2hA9v0-8=JO3g}IHB#b`hy zA42a0>{0L7CcabSD+F7?pGbS1KMvT{@1_@k!_+Ki|5~EMGt7T%u=79F)8xEiL5!EJ zzuxQ`NBliCoJMJdwu|);zRCD<5Sf?Y>U$trQ-;xj6!s5&w=9E7)%pZ+1Nh&8nCCwM zv5>Ket%I?cxr3vVva`YeR?dGxbG@pi{H#8@kFEf0Jq6~K4>kt26*bxv=P&jyE#e$| zDJB_~imk^-z|o!2njF2hL*|7sHCnzluhJjwLQGDmC)Y9 zr9ZN`s)uCd^XDvn)VirMgW~qfn1~SaN^7vcX#K1G`==UGaDVVx$0BQnubhX|{e z^i0}>k-;BP#Szk{cFjO{2x~LjK{^Upqd&<+03_iMLp0$!6_$@TbX>8U-f*-w-ew1?`CtD_0y_Lo|PfKi52p?`5$Jzx0E8`M0 zNIb?#!K$mM4X%`Ry_yhG5k@*+n4||2!~*+&pYLh~{`~o(W|o64^NrjP?-1Lgu?iK^ zTX6u3?#$?R?N!{599vg>G8RGHw)Hx&=|g4599y}mXNpM{EPKKXB&+m?==R3GsIq?G zL5fH={=zawB(sMlDBJ+{dgb)Vx3pu>L=mDV0{r1Qs{0Pn%TpopH{m(By4;{FBvi{I z$}x!Iw~MJOL~&)p93SDIfP3x%ROjg}X{Sme#hiJ&Yk&a;iR}V|n%PriZBY8SX2*;6 z4hdb^&h;Xz%)BDACY5AUsV!($lib4>11UmcgXKWpzRL8r2Srl*9Y(1uBQsY&hO&uv znDNff0tpHlLISam?o(lOp#CmFdH<6HmA0{UwfU#Y{8M+7od8b8|B|7ZYR9f<#+V|ZSaCQvI$~es~g(Pv{2&m_rKSB2QQ zMvT}$?Ll>V+!9Xh5^iy3?UG;dF-zh~RL#++roOCsW^cZ&({6q|?Jt6`?S8=16Y{oH zp50I7r1AC1(#{b`Aq5cw>ypNggHKM9vBx!W$eYIzD!4KbLsZGr2o8>g<@inmS3*>J zx8oG((8f!ei|M@JZB`p7+n<Q}?>h249<`7xJ?u}_n;Gq(&km#1ULN87CeTO~FY zS_Ty}0TgQhV zOh3T7{{x&LSYGQfKR1PDIkP!WnfC1$l+fs@Di+d4O=eVKeF~2fq#1<8hEvpwuqcaH z4A8u~r^gnY3u6}zj*RHjk{AHhrrDqaj?|6GaVJbV%o-nATw}ASFr!f`Oz|u_QPkR# z0mDudY1dZRlk@TyQ?%Eti=$_WNFtLpSx9=S^be{wXINp%MU?a`F66LNU<c;0&ngifmP9i;bj6&hdGMW^Kf8e6ZDXbQD&$QAAMo;OQ)G zW(qlHh;}!ZP)JKEjm$VZjTs@hk&4{?@+NADuYrr!R^cJzU{kGc1yB?;7mIyAWwhbeA_l_lw-iDVi7wcFurf5 z#Uw)A@a9fOf{D}AWE%<`s1L_AwpZ?F!Vac$LYkp<#A!!`XKaDC{A%)~K#5z6>Hv@V zBEqF(D5?@6r3Pwj$^krpPDCjB+UOszqUS;b2n>&iAFcw<*im2(b3|5u6SK!n9Sg4I z0KLcwA6{Mq?p%t>aW0W!PQ>iUeYvNjdKYqII!CE7SsS&Rj)eIw-K4jtI?II+0IdGq z2WT|L3RL?;GtGgt1LWfI4Ka`9dbZXc$TMJ~8#Juv@K^1RJN@yzdLS8$AJ(>g!U9`# zx}qr7JWlU+&m)VG*Se;rGisutS%!6yybi%B`bv|9rjS(xOUIvbNz5qtvC$_JYY+c& za*3*2$RUH8p%pSq>48xR)4qsp!Q7BEiJ*`^>^6INRbC@>+2q9?x(h0bpc>GaNFi$K zPH$6!#(~{8@0QZk=)QnM#I=bDx5vTvjm$f4K}%*s+((H2>tUTf==$wqyoI`oxI7>C z&>5fe)Yg)SmT)eA(|j@JYR1M%KixxC-Eceknf-;N=jJTwKvk#@|J^&5H0c+%KxHUI z6dQbwwVx3p?X<_VRVb2fStH?HH zFR@Mp=qX%#L3XL)+$PXKV|o|#DpHAoqvj6uQKe@M-mnhCSou7Dj4YuO6^*V`m)1lf z;)@e%1!Qg$10w8uEmz{ENb$^%u}B;J7sDd zump}onoD#!l=agcBR)iG!3AF0-63%@`K9G(CzKrm$VJ{v7^O9Ps7Zej|3m= zVXlR&yW6=Y%mD30G@|tf=yC7-#L!16Q=dq&@beWgaIL40k0n% z)QHrp2Jck#evLMM1RGt3WvQ936ZC9vEje0nFMfvmOHVI+&okB_K|l-;|4vW;qk>n~ z+|kk8#`K?x`q>`(f6A${wfw9Cx(^)~tX7<#TpxR#zYG2P+FY~mG{tnEkv~d6oUQA+ z&hNTL=~Y@rF`v-RZlts$nb$3(OL1&@Y11hhL9+zUb6)SP!;CD)^GUtUpCHBE`j1te zAGud@miCVFLk$fjsrcpjsadP__yj9iEZUW{Ll7PPi<$R;m1o!&Xdl~R_v0;oDX2z^!&8}zNGA}iYG|k zmehMd1%?R)u6R#<)B)1oe9TgYH5-CqUT8N7K-A-dm3hbm_W21p%8)H{O)xUlBVb+iUR}-v5dFaCyfSd zC6Bd7=N4A@+Bna=!-l|*_(nWGDpoyU>nH=}IOrLfS+-d40&(Wo*dDB9nQiA2Tse$R z;uq{`X7LLzP)%Y9aHa4YQ%H?htkWd3Owv&UYbr5NUDAH^<l@Z0Cx%`N+B*i!!1u>D8%;Qt1$ zE5O0{-`9gdDxZ!`0m}ywH!;c{oBfL-(BH<&SQ~smbcobU!j49O^f4&IIYh~f+hK*M zZwTp%{ZSAhMFj1qFaOA+3)p^gnXH^=)`NTYgTu!CLpEV2NF=~-`(}7p^Eof=@VUbd z_9U|8qF7Rueg&$qpSSkN%%%DpbV?8E8ivu@ensI0toJ7Eas^jyFReQ1JeY9plb^{m z&eQO)qPLZQ6O;FTr*aJq=$cMN)QlQO@G&%z?BKUs1&I^`lq>=QLODwa`(mFGC`0H< zOlc*|N?B5&!U6BuJvkL?s1&nsi$*5cCv7^j_*l&$-sBmRS85UIrE--7eD8Gr3^+o? zqG-Yl4S&E;>H>k^a0GdUI(|n1`ws@)1%sq2XBdK`mqrNq_b4N{#VpouCXLzNvjoFv zo9wMQ6l0+FT+?%N(ka*;%m~(?338bu32v26!{r)|w8J`EL|t$}TA4q_FJRX5 zCPa{hc_I(7TGE#@rO-(!$1H3N-C0{R$J=yPCXCtGk{4>=*B56JdXU9cQVwB`6~cQZ zf^qK21x_d>X%dT!!)CJQ3mlHA@ z{Prkgfs6=Tz%63$6Zr8CO0Ak3A)Cv#@BVKr&aiKG7RYxY$Yx>Bj#3gJk*~Ps-jc1l z;4nltQwwT4@Z)}Pb!3xM?+EW0qEKA)sqzw~!C6wd^{03-9aGf3Jmt=}w-*!yXupLf z;)>-7uvWN4Unn8b4kfIza-X=x*e4n5pU`HtgpFFd))s$C@#d>aUl3helLom+RYb&g zI7A9GXLRZPl}iQS*d$Azxg-VgcUr*lpLnbPKUV{QI|bsG{8bLG<%CF( zMoS4pRDtLVYOWG^@ox^h8xL~afW_9DcE#^1eEC1SVSb1BfDi^@g?#f6e%v~Aw>@w- zIY0k+2lGWNV|aA*e#`U3=+oBDmGeInfcL)>*!w|*;mWiKNG6wP6AW4-4imN!W)!hE zA02~S1*@Q`fD*+qX@f3!2yJX&6FsEfPditB%TWo3=HA;T3o2IrjS@9SSxv%{{7&4_ zdS#r4OU41~GYMiib#z#O;zohNbhJknrPPZS6sN$%HB=jUnlCO_w5Gw5EeE@KV>soy z2EZ?Y|4RQDDjt5y!WBlZ(8M)|HP<0YyG|D%RqD+K#e7-##o3IZxS^wQ5{Kbzb6h(i z#(wZ|^ei>8`%ta*!2tJzwMv+IFHLF`zTU8E^Mu!R*45_=ccqI};Zbyxw@U%a#2}%f zF>q?SrUa_a4H9l+uW8JHh2Oob>NyUwG=QH~-^ZebU*R@67DcXdz2{HVB4#@edz?B< z5!rQH3O0>A&ylROO%G^fimV*LX7>!%re{_Sm6N>S{+GW1LCnGImHRoF@csnFzn@P0 zM=jld0z%oz;j=>c7mMwzq$B^2mae7NiG}%>(wtmsDXkWk{?BeMpTrIt3Mizq?vRsf zi_WjNp+61uV(%gEU-Vf0;>~vcDhe(dzWdaf#4mH3o^v{0EWhj?E?$5v02sV@xL0l4 zX0_IMFtQ44PfWBbPYN#}qxa%=J%dlR{O!KyZvk^g5s?sTNycWYPJ^FK(nl3k?z-5t z39#hKrdO7V(@!TU)LAPY&ngnZ1MzLEeEiZznn7e-jLCy8LO zu^7_#z*%I-BjS#Pg-;zKWWqX-+Ly$T!4`vTe5ZOV0j?TJVA*2?*=82^GVlZIuH%9s zXiV&(T(QGHHah=s&7e|6y?g+XxZGmK55`wGV>@1U)Th&=JTgJq>4mI&Av2C z)w+kRoj_dA!;SfTfkgMPO>7Dw6&1*Hi1q?54Yng`JO&q->^CX21^PrU^JU#CJ_qhV zSG>afB%>2fx<~g8p=P8Yzxqc}s@>>{g7}F!;lCXvF#RV)^fyYb_)iKVCz1xEq=fJ| z0a7DMCK*FuP=NM*5h;*D`R4y$6cpW-E&-i{v`x=Jbk_xSn@2T3q!3HoAOB`@5Vg6) z{PW|@9o!e;v1jZ2{=Uw6S6o{g82x6g=k!)cFSC*oemHaVjg?VpEmtUuD2_J^A~$4* z3O7HsbA6wxw{TP5Kk)(Vm?gKo+_}11vbo{Tp_5x79P~#F)ahQXT)tSH5;;14?s)On zel1J>1x>+7;g1Iz2FRpnYz;sD0wG9Q!vuzE9yKi3@4a9Nh1!GGN?hA)!mZEnnHh&i zf?#ZEN2sFbf~kV;>K3UNj1&vFhc^sxgj8FCL4v>EOYL?2uuT`0eDH}R zmtUJMxVrV5H{L53hu3#qaWLUa#5zY?f5ozIn|PkMWNP%n zWB5!B0LZB0kLw$k39=!akkE9Q>F4j+q434jB4VmslQ;$ zKiO#FZ`p|dKS716jpcvR{QJkSNfDVhr2%~eHrW;fU45>>snr*S8Vik-5eN5k*c2Mp zyxvX&_cFbB6lODXznHHT|rsURe2!swomtrqc~w5 zymTM8!w`1{04CBprR!_F{5LB+2_SOuZN{b*!J~1ZiPpP-M;);!ce!rOPDLtgR@Ie1 zPreuqm4!H)hYePcW1WZ0Fyaqe%l}F~Orr)~+;mkS&pOhP5Ebb`cnUt!X_QhP4_4p( z8YKQCDKGIy>?WIFm3-}Br2-N`T&FOi?t)$hjphB9wOhBXU#Hb+zm&We_-O)s(wc`2 z8?VsvU;J>Ju7n}uUb3s1yPx_F*|FlAi=Ge=-kN?1;`~6szP%$3B0|8Sqp%ebM)F8v zADFrbeT0cgE>M0DMV@_Ze*GHM>q}wWMzt|GYC%}r{OXRG3Ij&<+nx9;4jE${Fj_r* z`{z1AW_6Myd)i6e0E-h&m{{CvzH=Xg!&(bLYgRMO_YVd8JU7W+7MuGWNE=4@OvP9+ zxi^vqS@5%+#gf*Z@RVyU9N1sO-(rY$24LGsg1>w>s6ST^@)|D9>cT50maXLUD{Fzf zt~tp{OSTEKg3ZSQyQQ5r51){%=?xlZ54*t1;Ow)zLe3i?8tD8YyY^k%M)e`V*r+vL zPqUf&m)U+zxps+NprxMHF{QSxv}>lE{JZETNk1&F+R~bp{_T$dbXL2UGnB|hgh*p4h$clt#6;NO~>zuyY@C-MD@)JCc5XrYOt`wW7! z_ti2hhZBMJNbn0O-uTxl_b6Hm313^fG@e;RrhIUK9@# z+DHGv_Ow$%S8D%RB}`doJjJy*aOa5mGHVHz0e0>>O_%+^56?IkA5eN+L1BVCp4~m=1eeL zb;#G!#^5G%6Mw}r1KnaKsLvJB%HZL)!3OxT{k$Yo-XrJ?|7{s4!H+S2o?N|^Z z)+?IE9H7h~Vxn5hTis^3wHYuOU84+bWd)cUKuHapq=&}WV#OxHpLab`NpwHm8LmOo zjri+!k;7j_?FP##CpM+pOVx*0wExEex z@`#)K<-ZrGyArK;a%Km`^+We|eT+#MygHOT6lXBmz`8|lyZOwL1+b+?Z$0OhMEp3R z&J=iRERpv~TC=p2-BYLC*?4 zxvPs9V@g=JT0>zky5Poj=fW_M!c)Xxz1<=&_ZcL=LMZJqlnO1P^xwGGW*Z+yTBvbV z-IFe6;(k1@$1;tS>{%pXZ_7w+i?N4A2=TXnGf=YhePg8bH8M|Lk-->+w8Y+FjZ;L=wSGwxfA`gqSn)f(XNuSm>6Y z@|#e-)I(PQ^G@N`%|_DZSb4_pkaEF0!-nqY+t#pyA>{9^*I-zw4SYA1_z2Bs$XGUZbGA;VeMo%CezHK0lO={L%G)dI-+8w?r9iexdoB{?l zbJ}C?huIhWXBVs7oo{!$lOTlvCLZ_KN1N+XJGuG$rh<^eUQIqcI7^pmqhBSaOKNRq zrx~w^?9C?*&rNwP_SPYmo;J-#!G|{`$JZK7DxsM3N^8iR4vvn>E4MU&Oe1DKJvLc~ zCT>KLZ1;t@My zRj_2hI^61T&LIz)S!+AQIV23n1>ng+LUvzv;xu!4;wpqb#EZz;F)BLUzT;8UA1x*6vJ zicB!3Mj03s*kGV{g`fpC?V^s(=JG-k1EMHbkdP4P*1^8p_TqO|;!Zr%GuP$8KLxuf z=pv*H;kzd;P|2`JmBt~h6|GxdU~@weK5O=X&5~w$HpfO}@l-T7@vTCxVOwCkoPQv8 z@aV_)I5HQtfs7^X=C03zYmH4m0S!V@JINm6#(JmZRHBD?T!m^DdiZJrhKpBcur2u1 zf9e4%k$$vcFopK5!CC`;ww(CKL~}mlxK_Pv!cOsFgVkNIghA2Au@)t6;Y3*2gK=5d z?|@1a)-(sQ%uFOmJ7v2iG&l&m^u&^6DJM#XzCrF%r>{2XKyxLD2rgWBD;i(!e4InDQBDg==^z;AzT2z~OmV0!?Z z0S9pX$+E;w3WN;v&NYT=+G8hf=6w0E1$0AOr61}eOvE8W1jX%>&Mjo7&!ulawgzLH zbcb+IF(s^3aj12WSi#pzIpijJJzkP?JzRawnxmNDSUR#7!29vHULCE<3Aa#be}ie~d|!V+ z%l~s9Odo$G&fH!t!+`rUT0T9DulF!Yq&BfQWFZV1L9D($r4H(}Gnf6k3^wa7g5|Ws zj7%d`!3(0bb55yhC6@Q{?H|2os{_F%o=;-h{@Yyyn*V7?{s%Grvpe!H^kl6tF4Zf5 z{Jv1~yZ*iIWL_9C*8pBMQArfJJ0d9Df6Kl#wa}7Xa#Ef_5B7=X}DzbQXVPfCwTO@9+@;A^Ti6il_C>g?A-GFwA0#U;t4;wOm-4oS})h z5&on>NAu67O?YCQr%7XIzY%LS4bha9*e*4bU4{lGCUmO2UQ2U)QOqClLo61Kx~3dI zmV3*(P6F_Tr-oP%x!0kTnnT?Ep5j;_IQ^pTRp=e8dmJtI4YgWd0}+b2=ATkOhgpXe z;jmw+FBLE}UIs4!&HflFr4)vMFOJ19W4f2^W(=2)F%TAL)+=F>IE$=e=@j-*bFLSg z)wf|uFQu+!=N-UzSef62u0-C8Zc7 zo6@F)c+nZA{H|+~7i$DCU0pL{0Ye|fKLuV^w!0Y^tT$isu%i1Iw&N|tX3kwFKJN(M zXS`k9js66o$r)x?TWL}Kxl`wUDUpwFx(w4Yk%49;$sgVvT~n8AgfG~HUcDt1TRo^s zdla@6heJB@JV z!vK;BUMznhzGK6PVtj0)GB=zTv6)Q9Yt@l#fv7>wKovLobMV-+(8)NJmyF8R zcB|_K7=FJGGn^X@JdFaat0uhKjp3>k#^&xE_}6NYNG?kgTp>2Iu?ElUjt4~E-?`Du z?mDCS9wbuS%fU?5BU@Ijx>1HG*N?gIP+<~xE4u=>H`8o((cS5M6@_OK%jSjFHirQK zN9@~NXFx*jS{<|bgSpC|SAnA@I)+GB=2W|JJChLI_mx+-J(mSJ!b)uUom6nH0#2^(L@JBlV#t zLl?j54s`Y3vE^c_3^Hl0TGu*tw_n?@HyO@ZrENxA+^!)OvUX28gDSF*xFtQzM$A+O zCG=n#6~r|3zt=8%GuG} z<#VCZ%2?3Q(Ad#Y7GMJ~{U3>E{5e@z6+rgZLX{Cxk^p-7dip^d29;2N1_mm4QkASo z-L`GWWPCq$uCo;X_BmGIpJFBlhl<8~EG{vOD1o|X$aB9KPhWO_cKiU*$HWEgtf=fn zsO%9bp~D2c@?*K9jVN@_vhR03>M_8h!_~%aN!Cnr?s-!;U3SVfmhRwk11A^8Ns`@KeE}+ zN$H}a1U6E;*j5&~Og!xHdfK5M<~xka)x-0N)K_&e7AjMz`toDzasH+^1bZlC!n()crk9kg@$(Y{wdKvbuUd04N^8}t1iOgsKF zGa%%XWx@WoVaNC1!|&{5ZbkopFre-Lu(LCE5HWZBoE#W@er9W<>R=^oYxBvypN#x3 zq#LC8&q)GFP=5^-bpHj?LW=)-g+3_)Ylps!3^YQ{9~O9&K)xgy zMkCWaApU-MI~e^cV{Je75Qr7eF%&_H)BvfyKL=gIA>;OSq(y z052BFz3E(Prg~09>|_Z@!qj}@;8yxnw+#Ej0?Rk<y}4ghbD569B{9hSFr*^ygZ zr6j7P#gtZh6tMk6?4V$*Jgz+#&ug;yOr>=qdI#9U&^am2qoh4Jy}H2%a|#Fs{E(5r z%!ijh;VuGA6)W)cJZx+;9Bp1LMUzN~x_8lQ#D3+sL{be-Jyeo@@dv7XguJ&S5vrH` z>QxOMWn7N-T!D@1(@4>ZlL^y5>m#0!HKovs12GRav4z!>p(1~xok8+_{| z#Ae4{9#NLh#Vj2&JuIn5$d6t@__`o}umFo(n0QxUtd2GKCyE+erwXY?`cm*h&^9*8 zJ+8x6fRZI-e$CRygofIQN^dWysCxgkyr{(_oBwwSRxZora1(%(aC!5BTtj^+YuevI zx?)H#(xlALUp6QJ!=l9N__$cxBZ5p&7;qD3PsXRFVd<({Kh+mShFWJNpy`N@ab7?9 zv5=klvCJ4bx|-pvOO2-+G)6O?$&)ncA#Urze2rlBfp#htudhx-NeRnJ@u%^_bfw4o z4|{b8SkPV3b>Wera1W(+N@p9H>dc6{cnkh-sgr?e%(YkWvK+0YXVwk0=d`)}*47*B z5JGkEdVix!w7-<%r0JF~`ZMMPe;f0EQHuYHxya`puazyph*ZSb1mJAt^k4549BfS; zK7~T&lRb=W{s&t`DJ$B}s-eH1&&-wEOH1KWsKn0a(ZI+G!v&W4A*cl>qAvUv6pbUR z#(f#EKV8~hk&8oayBz4vaswc(?qw1vn`yC zZQDl2PCB-&Uu@g9ZQHhO+v(W0bNig{-k0;;`+wM@#@J)8r?qOYs#&vUna8ILxN7S{ zp1s41KnR8miQJtJtOr|+qk}wrLt+N*z#5o`TmD1)E&QD(Vh&pjZJ_J*0!8dy_ z>^=@v=J)C`x&gjqAYu`}t^S=DFCtc0MkBU2zf|69?xW`Ck~(6zLD)gSE{7n~6w8j_ zoH&~$ED2k5-yRa0!r8fMRy z;QjBYUaUnpd}mf%iVFPR%Dg9!d>g`01m~>2s))`W|5!kc+_&Y>wD@@C9%>-lE`WB0 zOIf%FVD^cj#2hCkFgi-fgzIfOi+ya)MZK@IZhHT5FVEaSbv-oDDs0W)pA0&^nM0TW zmgJmd7b1R7b0a`UwWJYZXp4AJPteYLH>@M|xZFKwm!t3D3&q~av?i)WvAKHE{RqpD{{%OhYkK?47}+}` zrR2(Iv9bhVa;cDzJ%6ntcSbx7v7J@Y4x&+eWSKZ*eR7_=CVIUSB$^lfYe@g+p|LD{ zPSpQmxx@b$%d!05|H}WzBT4_cq?@~dvy<7s&QWtieJ9)hd4)$SZz}#H2UTi$CkFWW|I)v_-NjuH!VypONC=1`A=rm_jfzQ8Fu~1r8i{q-+S_j$ z#u^t&Xnfi5tZtl@^!fUJhx@~Cg0*vXMK}D{>|$#T*+mj(J_@c{jXBF|rm4-8%Z2o! z2z0o(4%8KljCm^>6HDK!{jI7p+RAPcty_~GZ~R_+=+UzZ0qzOwD=;YeZt*?3%UGdr z`c|BPE;yUbnyARUl&XWSNJ<+uRt%!xPF&K;(l$^JcA_CMH6)FZt{>6ah$|(9$2fc~ z=CD00uHM{qv;{Zk9FR0~u|3|Eiqv9?z2#^GqylT5>6JNZwKqKBzzQpKU2_pmtD;CT zi%Ktau!Y2Tldfu&b0UgmF(SSBID)15*r08eoUe#bT_K-G4VecJL2Pa=6D1K6({zj6 za(2Z{r!FY5W^y{qZ}08+h9f>EKd&PN90f}Sc0ejf%kB4+f#T8Q1=Pj=~#pi$U zp#5rMR%W25>k?<$;$x72pkLibu1N|jX4cWjD3q^Pk3js!uK6h7!dlvw24crL|MZs_ zb%Y%?Fyp0bY0HkG^XyS76Ts*|Giw{31LR~+WU5NejqfPr73Rp!xQ1mLgq@mdWncLy z%8}|nzS4P&`^;zAR-&nm5f;D-%yNQPwq4N7&yULM8bkttkD)hVU>h>t47`{8?n2&4 zjEfL}UEagLUYwdx0sB2QXGeRmL?sZ%J!XM`$@ODc2!y|2#7hys=b$LrGbvvjx`Iqi z&RDDm3YBrlKhl`O@%%&rhLWZ*ABFz2nHu7k~3@e4)kO3%$=?GEFUcCF=6-1n!x^vmu+Ai*amgXH+Rknl6U>#9w;A} zn2xanZSDu`4%%x}+~FG{Wbi1jo@wqBc5(5Xl~d0KW(^Iu(U3>WB@-(&vn_PJt9{1`e9Iic@+{VPc`vP776L*viP{wYB2Iff8hB%E3|o zGMOu)tJX!`qJ}ZPzq7>=`*9TmETN7xwU;^AmFZ-ckZjV5B2T09pYliaqGFY|X#E-8 z20b>y?(r-Fn5*WZ-GsK}4WM>@TTqsxvSYWL6>18q8Q`~JO1{vLND2wg@58OaU!EvT z1|o+f1mVXz2EKAbL!Q=QWQKDZpV|jznuJ}@-)1&cdo z^&~b4Mx{*1gurlH;Vhk5g_cM&6LOHS2 zRkLfO#HabR1JD4Vc2t828dCUG#DL}f5QDSBg?o)IYYi@_xVwR2w_ntlpAW0NWk$F1 z$If?*lP&Ka1oWfl!)1c3fl`g*lMW3JOn#)R1+tfwrs`aiFUgz3;XIJ>{QFxLCkK30 zNS-)#DON3yb!7LBHQJ$)4y%TN82DC2-9tOIqzhZ27@WY^<6}vXCWcR5iN{LN8{0u9 zNXayqD=G|e?O^*ms*4P?G%o@J1tN9_76e}E#66mr89%W_&w4n66~R;X_vWD(oArwj z4CpY`)_mH2FvDuxgT+akffhX0b_slJJ*?Jn3O3~moqu2Fs1oL*>7m=oVek2bnprnW zixkaIFU%+3XhNA@@9hyhFwqsH2bM|`P?G>i<-gy>NflhrN{$9?LZ1ynSE_Mj0rADF zhOz4FnK}wpLmQuV zgO4_Oz9GBu_NN>cPLA=`SP^$gxAnj;WjJnBi%Q1zg`*^cG;Q)#3Gv@c^j6L{arv>- zAW%8WrSAVY1sj$=umcAf#ZgC8UGZGoamK}hR7j6}i8#np8ruUlvgQ$j+AQglFsQQq zOjyHf22pxh9+h#n$21&$h?2uq0>C9P?P=Juw0|;oE~c$H{#RGfa>| zj)Iv&uOnaf@foiBJ}_;zyPHcZt1U~nOcNB{)og8Btv+;f@PIT*xz$x!G?u0Di$lo7 zOugtQ$Wx|C($fyJTZE1JvR~i7LP{ zbdIwqYghQAJi9p}V&$=*2Azev$6K@pyblphgpv8^9bN!?V}{BkC!o#bl&AP!3DAjM zmWFsvn2fKWCfjcAQmE+=c3Y7j@#7|{;;0f~PIodmq*;W9Fiak|gil6$w3%b_Pr6K_ zJEG@&!J%DgBZJDCMn^7mk`JV0&l07Bt`1ymM|;a)MOWz*bh2#d{i?SDe9IcHs7 zjCrnyQ*Y5GzIt}>`bD91o#~5H?4_nckAgotN{2%!?wsSl|LVmJht$uhGa+HiH>;av z8c?mcMYM7;mvWr6noUR{)gE!=i7cZUY7e;HXa221KkRoc2UB>s$Y(k%NzTSEr>W(u z<(4mcc)4rB_&bPzX*1?*ra%VF}P1nwiP5cykJ&W{!OTlz&Td0pOkVp+wc z@k=-Hg=()hNg=Q!Ub%`BONH{ z_=ZFgetj@)NvppAK2>8r!KAgi>#%*7;O-o9MOOfQjV-n@BX6;Xw;I`%HBkk20v`qoVd0)}L6_49y1IhR z_OS}+eto}OPVRn*?UHC{eGyFU7JkPz!+gX4P>?h3QOwGS63fv4D1*no^6PveUeE5% zlehjv_3_^j^C({a2&RSoVlOn71D8WwMu9@Nb@=E_>1R*ve3`#TF(NA0?d9IR_tm=P zOP-x;gS*vtyE1Cm zG0L?2nRUFj#aLr-R1fX*$sXhad)~xdA*=hF3zPZhha<2O$Ps+F07w*3#MTe?)T8|A!P!v+a|ot{|^$q(TX`35O{WI0RbU zCj?hgOv=Z)xV?F`@HKI11IKtT^ocP78cqHU!YS@cHI@{fPD?YXL)?sD~9thOAv4JM|K8OlQhPXgnevF=F7GKD2#sZW*d za}ma31wLm81IZxX(W#A9mBvLZr|PoLnP>S4BhpK8{YV_}C|p<)4#yO{#ISbco92^3 zv&kCE(q9Wi;9%7>>PQ!zSkM%qqqLZW7O`VXvcj;WcJ`2~v?ZTYB@$Q&^CTfvy?1r^ z;Cdi+PTtmQwHX_7Kz?r#1>D zS5lWU(Mw_$B&`ZPmqxpIvK<~fbXq?x20k1~9az-Q!uR78mCgRj*eQ>zh3c$W}>^+w^dIr-u{@s30J=)1zF8?Wn|H`GS<=>Om|DjzC{}Jt?{!fSJe*@$H zg>wFnlT)k#T?LslW zu$^7Uy~$SQ21cE?3Ijl+bLfuH^U5P^$@~*UY#|_`uvAIe(+wD2eF}z_y!pvomuVO; zS^9fbdv)pcm-B@CW|Upm<7s|0+$@@<&*>$a{aW+oJ%f+VMO<#wa)7n|JL5egEgoBv zl$BY(NQjE0#*nv=!kMnp&{2Le#30b)Ql2e!VkPLK*+{jv77H7)xG7&=aPHL7LK9ER z5lfHxBI5O{-3S?GU4X6$yVk>lFn;ApnwZybdC-GAvaznGW-lScIls-P?Km2mF>%B2 zkcrXTk+__hj-3f48U%|jX9*|Ps41U_cd>2QW81Lz9}%`mTDIhE)jYI$q$ma7Y-`>% z8=u+Oftgcj%~TU}3nP8&h7k+}$D-CCgS~wtWvM|UU77r^pUw3YCV80Ou*+bH0!mf0 zxzUq4ed6y>oYFz7+l18PGGzhB^pqSt)si=9M>~0(Bx9*5r~W7sa#w+_1TSj3Jn9mW zMuG9BxN=}4645Cpa#SVKjFst;9UUY@O<|wpnZk$kE+to^4!?0@?Cwr3(>!NjYbu?x z1!U-?0_O?k!NdM^-rIQ8p)%?M+2xkhltt*|l=%z2WFJhme7*2xD~@zk#`dQR$6Lmd zb3LOD4fdt$Cq>?1<%&Y^wTWX=eHQ49Xl_lFUA(YQYHGHhd}@!VpYHHm=(1-O=yfK#kKe|2Xc*9}?BDFN zD7FJM-AjVi)T~OG)hpSWqH>vlb41V#^G2B_EvYlWhDB{Z;Q9-0)ja(O+By`31=biA zG&Fs#5!%_mHi|E4Nm$;vVQ!*>=_F;ZC=1DTPB#CICS5fL2T3XmzyHu?bI;m7D4@#; ztr~;dGYwb?m^VebuULtS4lkC_7>KCS)F@)0OdxZIFZp@FM_pHnJes8YOvwB|++#G( z&dm*OP^cz95Wi15vh`Q+yB>R{8zqEhz5of>Po$9LNE{xS<)lg2*roP*sQ}3r3t<}; zPbDl{lk{pox~2(XY5=qg0z!W-x^PJ`VVtz$git7?)!h>`91&&hESZy1KCJ2nS^yMH z!=Q$eTyRi68rKxdDsdt+%J_&lapa{ds^HV9Ngp^YDvtq&-Xp}60B_w@Ma>_1TTC;^ zpbe!#gH}#fFLkNo#|`jcn?5LeUYto%==XBk6Ik0kc4$6Z+L3x^4=M6OI1=z5u#M%0 z0E`kevJEpJjvvN>+g`?gtnbo$@p4VumliZV3Z%CfXXB&wPS^5C+7of2tyVkMwNWBiTE2 z8CdPu3i{*vR-I(NY5syRR}I1TJOV@DJy-Xmvxn^IInF>Tx2e)eE9jVSz69$6T`M9-&om!T+I znia!ZWJRB28o_srWlAxtz4VVft8)cYloIoVF=pL zugnk@vFLXQ_^7;%hn9x;Vq?lzg7%CQR^c#S)Oc-8d=q_!2ZVH764V z!wDKSgP}BrVV6SfCLZnYe-7f;igDs9t+K*rbMAKsp9L$Kh<6Z;e7;xxced zn=FGY<}CUz31a2G}$Q(`_r~75PzM4l_({Hg&b@d8&jC}B?2<+ed`f#qMEWi z`gm!STV9E4sLaQX+sp5Nu9*;9g12naf5?=P9p@H@f}dxYprH+3ju)uDFt^V{G0APn zS;16Dk{*fm6&BCg#2vo?7cbkkI4R`S9SSEJ=#KBk3rl69SxnCnS#{*$!^T9UUmO#&XXKjHKBqLdt^3yVvu8yn|{ zZ#%1CP)8t-PAz(+_g?xyq;C2<9<5Yy<~C74Iw(y>uUL$+$mp(DRcCWbCKiGCZw@?_ zdomfp+C5xt;j5L@VfhF*xvZdXwA5pcdsG>G<8II-|1dhAgzS&KArcb0BD4ZZ#WfiEY{hkCq5%z9@f|!EwTm;UEjKJsUo696V>h zy##eXYX}GUu%t{Gql8vVZKkNhQeQ4C%n|RmxL4ee5$cgwlU+?V7a?(jI#&3wid+Kz5+x^G!bb#$q>QpR#BZ}Xo5UW^ zD&I`;?(a}Oys7-`I^|AkN?{XLZNa{@27Dv^s4pGowuyhHuXc zuctKG2x0{WCvg_sGN^n9myJ}&FXyGmUQnW7fR$=bj$AHR88-q$D!*8MNB{YvTTEyS zn22f@WMdvg5~o_2wkjItJN@?mDZ9UUlat2zCh(zVE=dGi$rjXF7&}*sxac^%HFD`Y zTM5D3u5x**{bW!68DL1A!s&$2XG@ytB~dX-?BF9U@XZABO`a|LM1X3HWCllgl0+uL z04S*PX$%|^WAq%jkzp~%9HyYIF{Ym?k)j3nMwPZ=hlCg9!G+t>tf0o|J2%t1 ztC+`((dUplgm3`+0JN~}&FRRJ3?l*>Y&TfjS>!ShS`*MwO{WIbAZR#<%M|4c4^dY8 z{Rh;-!qhY=dz5JthbWoovLY~jNaw>%tS4gHVlt5epV8ekXm#==Po$)}mh^u*cE>q7*kvX&gq)(AHoItMYH6^s6f(deNw%}1=7O~bTHSj1rm2|Cq+3M z93djjdomWCTCYu!3Slx2bZVy#CWDozNedIHbqa|otsUl+ut?>a;}OqPfQA05Yim_2 zs@^BjPoFHOYNc6VbNaR5QZfSMh2S*`BGwcHMM(1@w{-4jVqE8Eu0Bi%d!E*^Rj?cR z7qgxkINXZR)K^=fh{pc0DCKtrydVbVILI>@Y0!Jm>x-xM!gu%dehm?cC6ok_msDVA*J#{75%4IZt}X|tIVPReZS#aCvuHkZxc zHVMtUhT(wp09+w9j9eRqz~LtuSNi2rQx_QgQ(}jBt7NqyT&ma61ldD(s9x%@q~PQl zp6N*?=N$BtvjQ_xIT{+vhb1>{pM0Arde0!X-y))A4znDrVx8yrP3B1(7bKPE5jR@5 zwpzwT4cu~_qUG#zYMZ_!2Tkl9zP>M%cy>9Y(@&VoB84#%>amTAH{(hL4cDYt!^{8L z645F>BWO6QaFJ-{C-i|-d%j7#&7)$X7pv#%9J6da#9FB5KyDhkA+~)G0^87!^}AP>XaCSScr;kL;Z%RSPD2CgoJ;gpYT5&6NUK$86$T?jRH=w8nI9Z534O?5fk{kd z`(-t$8W|#$3>xoMfXvV^-A(Q~$8SKDE^!T;J+rQXP71XZ(kCCbP%bAQ1|%$%Ov9_a zyC`QP3uPvFoBqr_+$HenHklqyIr>PU_Fk5$2C+0eYy^~7U&(!B&&P2%7#mBUhM!z> z_B$Ko?{Pf6?)gpYs~N*y%-3!1>o-4;@1Zz9VQHh)j5U1aL-Hyu@1d?X;jtDBNk*vMXPn@ z+u@wxHN*{uHR!*g*4Xo&w;5A+=Pf9w#PeZ^x@UD?iQ&${K2c}UQgLRik-rKM#Y5rdDphdcNTF~cCX&9ViRP}`>L)QA4zNXeG)KXFzSDa6 zd^St;inY6J_i=5mcGTx4_^Ys`M3l%Q==f>{8S1LEHn{y(kbxn5g1ezt4CELqy)~TV6{;VW>O9?5^ ztcoxHRa0jQY7>wwHWcxA-BCwzsP>63Kt&3fy*n#Cha687CQurXaRQnf5wc9o8v7Rw zNwGr2fac;Wr-Ldehn7tF^(-gPJwPt@VR1f;AmKgxN&YPL;j=0^xKM{!wuU|^mh3NE zy35quf}MeL!PU;|{OW_x$TBothLylT-J>_x6p}B_jW1L>k)ps6n%7Rh z96mPkJIM0QFNYUM2H}YF5bs%@Chs6#pEnloQhEl?J-)es!(SoJpEPoMTdgA14-#mC zghayD-DJWtUu`TD8?4mR)w5E`^EHbsz2EjH5aQLYRcF{l7_Q5?CEEvzDo(zjh|BKg z3aJl_n#j&eFHsUw4~lxqnr!6NL*se)6H=A+T1e3xUJGQrd}oSPwSy5+$tt{2t5J5@(lFxl43amsARG74iyNC}uuS zd2$=(r6RdamdGx^eatX@F2D8?U23tDpR+Os?0Gq2&^dF+$9wiWf?=mDWfjo4LfRwL zI#SRV9iSz>XCSgEj!cW&9H-njJopYiYuq|2w<5R2!nZ27DyvU4UDrHpoNQZiGPkp@ z1$h4H46Zn~eqdj$pWrv;*t!rTYTfZ1_bdkZmVVIRC21YeU$iS-*XMNK`#p8Z_DJx| zk3Jssf^XP7v0X?MWFO{rACltn$^~q(M9rMYoVxG$15N;nP)A98k^m3CJx8>6}NrUd@wp-E#$Q0uUDQT5GoiK_R{ z<{`g;8s>UFLpbga#DAf%qbfi`WN1J@6IA~R!YBT}qp%V-j!ybkR{uY0X|x)gmzE0J z&)=eHPjBxJvrZSOmt|)hC+kIMI;qgOnuL3mbNR0g^<%|>9x7>{}>a2qYSZAGPt4it?8 zNcLc!Gy0>$jaU?}ZWxK78hbhzE+etM`67*-*x4DN>1_&{@5t7_c*n(qz>&K{Y?10s zXsw2&nQev#SUSd|D8w7ZD2>E<%g^; zV{yE_O}gq?Q|zL|jdqB^zcx7vo(^})QW?QKacx$yR zhG|XH|8$vDZNIfuxr-sYFR{^csEI*IM#_gd;9*C+SysUFejP0{{z7@P?1+&_o6=7V|EJLQun^XEMS)w(=@eMi5&bbH*a0f;iC~2J74V2DZIlLUHD&>mlug5+v z6xBN~8-ovZylyH&gG#ptYsNlT?-tzOh%V#Y33zlsJ{AIju`CjIgf$@gr8}JugRq^c zAVQ3;&uGaVlVw}SUSWnTkH_6DISN&k2QLMBe9YU=sA+WiX@z)FoSYX`^k@B!j;ZeC zf&**P?HQG6Rk98hZ*ozn6iS-dG}V>jQhb3?4NJB*2F?6N7Nd;EOOo;xR7acylLaLy z9)^lykX39d@8@I~iEVar4jmjjLWhR0d=EB@%I;FZM$rykBNN~jf>#WbH4U{MqhhF6 zU??@fSO~4EbU4MaeQ_UXQcFyO*Rae|VAPLYMJEU`Q_Q_%s2*>$#S^)&7er+&`9L=1 z4q4ao07Z2Vsa%(nP!kJ590YmvrWg+YrgXYs_lv&B5EcoD`%uL79WyYA$0>>qi6ov7 z%`ia~J^_l{p39EY zv>>b}Qs8vxsu&WcXEt8B#FD%L%ZpcVtY!rqVTHe;$p9rbb5O{^rFMB>auLn-^;s+-&P1#h~mf~YLg$8M9 zZ4#87;e-Y6x6QO<{McUzhy(%*6| z)`D~A(TJ$>+0H+mct(jfgL4x%^oC^T#u(bL)`E2tBI#V1kSikAWmOOYrO~#-cc_8! zCe|@1&mN2{*ceeiBldHCdrURk4>V}79_*TVP3aCyV*5n@jiNbOm+~EQ_}1#->_tI@ zqXv+jj2#8xJtW508rzFrYcJxoek@iW6SR@1%a%Bux&;>25%`j3UI`0DaUr7l79`B1 zqqUARhW1^h6=)6?;@v>xrZNM;t}{yY3P@|L}ey@gG( z9r{}WoYN(9TW&dE2dEJIXkyHA4&pU6ki=rx&l2{DLGbVmg4%3Dlfvn!GB>EVaY_%3+Df{fBiqJV>~Xf8A0aqUjgpa} zoF8YXO&^_x*Ej}nw-$-F@(ddB>%RWoPUj?p8U{t0=n>gAI83y<9Ce@Q#3&(soJ{64 z37@Vij1}5fmzAuIUnXX`EYe;!H-yTVTmhAy;y8VZeB#vD{vw9~P#DiFiKQ|kWwGFZ z=jK;JX*A;Jr{#x?n8XUOLS;C%f|zj-7vXtlf_DtP7bpurBeX%Hjwr z4lI-2TdFpzkjgiv!8Vfv`=SP+s=^i3+N~1ELNWUbH|ytVu>EyPN_3(4TM^QE1swRo zoV7Y_g)a>28+hZG0e7g%@2^s>pzR4^fzR-El}ARTmtu!zjZLuX%>#OoU3}|rFjJg} zQ2TmaygxJ#sbHVyiA5KE+yH0LREWr%^C*yR|@gM$nK2P zo}M}PV0v))uJh&33N>#aU376@ZH79u(Yw`EQ2hM3SJs9f99+cO6_pNW$j$L-CtAfe zYfM)ccwD!P%LiBk!eCD?fHCGvgMQ%Q2oT_gmf?OY=A>&PaZQOq4eT=lwbaf}33LCH zFD|)lu{K7$8n9gX#w4~URjZxWm@wlH%oL#G|I~Fb-v^0L0TWu+`B+ZG!yII)w05DU z>GO?n(TN+B=>HdxVDSlIH76pta$_LhbBg;eZ`M7OGcqt||qi zogS72W1IN%=)5JCyOHWoFP7pOFK0L*OAh=i%&VW&4^LF@R;+K)t^S!96?}^+5QBIs zjJNTCh)?)4k^H^g1&jc>gysM`y^8Rm3qsvkr$9AeWwYpa$b22=yAd1t<*{ zaowSEFP+{y?Ob}8&cwfqoy4Pb9IA~VnM3u!trIK$&&0Op#Ql4j>(EW?UNUv#*iH1$ z^j>+W{afcd`{e&`-A{g}{JnIzYib)!T56IT@YEs{4|`sMpW3c8@UCoIJv`XsAw!XC z34|Il$LpW}CIHFC5e*)}00I5{%OL*WZRGzC0?_}-9{#ue?-ug^ zLE|uv-~6xnSs_2_&CN9{9vyc!Xgtn36_g^wI0C4s0s^;8+p?|mm;Odt3`2ZjwtK;l zfd6j)*Fr#53>C6Y8(N5?$H0ma;BCF3HCjUs7rpb2Kf*x3Xcj#O8mvs#&33i+McX zQpBxD8!O{5Y8D&0*QjD=Yhl9%M0)&_vk}bmN_Ud^BPN;H=U^bn&(csl-pkA+GyY0Z zKV7sU_4n;}uR78ouo8O%g*V;79KY?3d>k6%gpcmQsKk&@Vkw9yna_3asGt`0Hmj59 z%0yiF*`jXhByBI9QsD=+>big5{)BGe&+U2gAARGe3ID)xrid~QN_{I>k}@tzL!Md_ z&=7>TWciblF@EMC3t4-WX{?!m!G6$M$1S?NzF*2KHMP3Go4=#ZHkeIv{eEd;s-yD# z_jU^Ba06TZqvV|Yd;Z_sN%$X=!T+&?#p+OQIHS%!LO`Hx0q_Y0MyGYFNoM{W;&@0@ zLM^!X4KhdtsET5G<0+|q0oqVXMW~-7LW9Bg}=E$YtNh1#1D^6Mz(V9?2g~I1( zoz9Cz=8Hw98zVLwC2AQvp@pBeKyidn6Xu0-1SY1((^Hu*-!HxFUPs)yJ+i`^BC>PC zjwd0mygOVK#d2pRC9LxqGc6;Ui>f{YW9Bvb>33bp^NcnZoH~w9(lM5@JiIlfa-6|k ziy31UoMN%fvQfhi8^T+=yrP{QEyb-jK~>$A4SZT-N56NYEbpvO&yUme&pWKs3^94D zH{oXnUTb3T@H+RgzML*lejx`WAyw*?K7B-I(VJx($2!NXYm%3`=F~TbLv3H<{>D?A zJo-FDYdSA-(Y%;4KUP2SpHKAIcv9-ld(UEJE7=TKp|Gryn;72?0LHqAN^fk6%8PCW z{g_-t)G5uCIf0I`*F0ZNl)Z>))MaLMpXgqWgj-y;R+@A+AzDjsTqw2Mo9ULKA3c70 z!7SOkMtZb+MStH>9MnvNV0G;pwSW9HgP+`tg}e{ij0H6Zt5zJ7iw`hEnvye!XbA@!~#%vIkzowCOvq5I5@$3wtc*w2R$7!$*?}vg4;eDyJ_1=ixJuEp3pUS27W?qq(P^8$_lU!mRChT}ctvZz4p!X^ zOSp|JOAi~f?UkwH#9k{0smZ7-#=lK6X3OFEMl7%)WIcHb=#ZN$L=aD`#DZKOG4p4r zwlQ~XDZ`R-RbF&hZZhu3(67kggsM-F4Y_tI^PH8PMJRcs7NS9ogF+?bZB*fcpJ z=LTM4W=N9yepVvTj&Hu~0?*vR1HgtEvf8w%Q;U0^`2@e8{SwgX5d(cQ|1(!|i$km! zvY03MK}j`sff;*-%mN~ST>xU$6Bu?*Hm%l@0dk;j@%>}jsgDcQ)Hn*UfuThz9(ww_ zasV`rSrp_^bp-0sx>i35FzJwA!d6cZ5#5#nr@GcPEjNnFHIrtUYm1^Z$;{d&{hQV9 z6EfFHaIS}46p^5I-D_EcwwzUUuO}mqRh&T7r9sfw`)G^Q%oHxEs~+XoM?8e*{-&!7 z7$m$lg9t9KP9282eke608^Q2E%H-xm|oJ8=*SyEo} z@&;TQ3K)jgspgKHyGiKVMCz>xmC=H5Fy3!=TP)-R3|&1S-B)!6q50wfLHKM@7Bq6E z44CY%G;GY>tC`~yh!qv~YdXw! zSkquvYNs6k1r7>Eza?Vkkxo6XRS$W7EzL&A`o>=$HXgBp{L(i^$}t`NcnAxzbH8Ht z2!;`bhKIh`f1hIFcI5bHI=ueKdzmB9)!z$s-BT4ItyY|NaA_+o=jO%MU5as9 zc2)aLP>N%u>wlaXTK!p)r?+~)L+0eCGb5{8WIk7K52$nufnQ+m8YF+GQc&{^(zh-$ z#wyWV*Zh@d!b(WwXqvfhQX)^aoHTBkc;4ossV3&Ut*k>AI|m+{#kh4B!`3*<)EJVj zwrxK>99v^k4&Y&`Awm>|exo}NvewV%E+@vOc>5>%H#BK9uaE2$vje zWYM5fKuOTtn96B_2~~!xJPIcXF>E_;yO8AwpJ4)V`Hht#wbO3Ung~@c%%=FX4)q+9 z99#>VC2!4l`~0WHs9FI$Nz+abUq# zz`Of97})Su=^rGp2S$)7N3rQCj#0%2YO<R&p>$<#lgXcUj=4H_{oAYiT3 z44*xDn-$wEzRw7#@6aD)EGO$0{!C5Z^7#yl1o;k0PhN=aVUQu~eTQ^Xy{z8Ow6tk83 z4{5xe%(hx)%nD&|e*6sTWH`4W&U!Jae#U4TnICheJmsw{l|CH?UA{a6?2GNgpZLyzU2UlFu1ZVwlALmh_DOs03J^Cjh1im`E3?9&zvNmg(MuMw&0^Lu$(#CJ*q6DjlKsY-RMJ^8yIY|{SQZ*9~CH|u9L z`R78^r=EbbR*_>5?-)I+$6i}G)%mN(`!X72KaV(MNUP7Nv3MS9S|Pe!%N2AeOt5zG zVJ;jI4HZ$W->Ai_4X+`9c(~m=@ek*m`ZQbv3ryI-AD#AH=`x$~WeW~M{Js57(K7(v ze5`};LG|%C_tmd>bkufMWmAo&B+DT9ZV~h(4jg0>^aeAqL`PEUzJJtI8W1M!bQWpv zvN(d}E1@nlYa!L!!A*RN!(Q3F%J?5PvQ0udu?q-T)j3JKV~NL>KRb~w-lWc685uS6 z=S#aR&B8Sc8>cGJ!!--?kwsJTUUm`Jk?7`H z7PrO~xgBrSW2_tTlCq1LH8*!o?pj?qxy8}(=r_;G18POrFh#;buWR0qU24+XUaVZ0 z?(sXcr@-YqvkCmHr{U2oPogHL{r#3r49TeR<{SJX1pcUqyWPrkYz^X8#QW~?F)R5i z>p^!i<;qM8Nf{-fd6!_&V*e_9qP6q(s<--&1Ttj01j0w>bXY7y1W*%Auu&p|XSOH=)V7Bd4fUKh&T1)@cvqhuD-d=?w}O zjI%i(f|thk0Go*!d7D%0^ztBfE*V=(ZIN84f5HU}T9?ulmEYzT5usi=DeuI*d|;M~ zp_=Cx^!4k#=m_qSPBr5EK~E?3J{dWWPH&oCcNepYVqL?nh4D5ynfWip$m*YlZ8r^Z zuFEUL-nW!3qjRCLIWPT0x)FDL7>Yt7@8dA?R2kF@WE>ysMY+)lTsgNM#3VbXVGL}F z1O(>q>2a+_`6r5Xv$NZAnp=Kgnr3)cL(^=8ypEeOf3q8(HGe@7Tt59;yFl||w|mnO zHDxg2G3z8=(6wjj9kbcEY@Z0iOd7Gq5GiPS5% z*sF1J<#daxDV2Z8H>wxOF<;yKzMeTaSOp_|XkS9Sfn6Mpe9UBi1cSTieGG5$O;ZLIIJ60Y>SN4vC?=yE_CWlo(EEE$e4j?z&^FM%kNmRtlbEL^dPPgvs9sbK5fGw*r@ z+!EU@u$T8!nZh?Fdf_qk$VuHk^yVw`h`_#KoS*N%epIIOfQUy_&V}VWDGp3tplMbf z5Se1sJUC$7N0F1-9jdV2mmGK{-}fu|Nv;12jDy0<-kf^AmkDnu6j~TPWOgy1MT68|D z=4=50jVbUKdKaQgD`eWGr3I&^<6uhkjz$YwItY8%Yp9{z4-{6g{73<_b*@XJ4Nm3-3z z?BW3{aY_ccRjb@W1)i5nLg|7BnWS!B`_Uo9CWaE`Ij327QH?i)9A}4Ug4wmxVVa^b z-4+m%-wwOl7cKH7+=x&nrCrbEC)Q$fpg&V83#uEH;C=GNMz`ps@^RxK%T*8%OPnC` z{WO~J%nxYJ`x|N%?&i7?;{_8t^jM&=50HlaOQj8fS}_`moH$c;vI<|cruPFnpT8yU zS%rPOCUSd5Zdb(zwk`hqwTQn)*&n)uYsP*F_(~xEWq}C= zv30kFmZFwJZ@ELVX3?$dXQh|icO7UrL*_5G=I^xXjImz`ZPp>?g#tf(ej~KaIU0algsG!IS09;>?MvqGg#c{i+}qY|{P8W~O%#>|gFd z<1dr$-oxyRGN17yZo1OwLnzwYs0|;IS_nymNB0IlSzPQ%-r`?T=;_XQ^~&#}b|AB} zkNbN5uB?-sUB-T5QLlg%Uk3)uHB;>VIzGe9_J9 zaeISkQm!v(9d(0ML^b9fR^sfHFlH?7Mvddt37OuR{|O0{uv)(&-6<87W4 zyO>s!=cPgP3O&7xxU5DlIPw_o3O>6o6Qb?JWs3qw#p3sBc3g$?Dx zi(6D+DYgV;GrUis-CL%Qe{nvZnwaVXmbhH(|GFh|Q)k=1uvA$I@1DXI7bKlQ@8D6P zS?(*?><>)G49q0wr;NajpxP4W2G)kHl6^=Z>hrNEI4Mwd_$O6$1dXF;Q#hE(-eeW6 zz03GJF%Wl?HO=_ztv5*zRlcU~{+{k%#N59mgm~eK>P!QZ6E?#Cu^2)+K8m@ySvZ*5 z|HDT}BkF@3!l(0%75G=1u2hETXEj!^1Z$!)!lyGXlWD!_vqGE$Z)#cUVBqlORW>0^ zDjyVTxwKHKG|0}j-`;!R-p>}qQfBl(?($7pP<+Y8QE#M8SCDq~k<+>Q^Zf@cT_WdX3~BSe z+|KK|7OL5Hm5(NFP~j>Ct3*$wi0n0!xl=(C61`q&cec@mFlH(sy%+RH<=s)8aAPN`SfJdkAQjdv82G5iRdv8 zh{9wHUZaniSEpslXl^_ODh}mypC?b*9FzLjb~H@3DFSe;D(A-K3t3eOTB(m~I6C;(-lKAvit(70k`%@+O*Ztdz;}|_TS~B?Tpmi=QKC^m_ z2YpEaT3iiz*;T~ap1yiA)a`dKMwu`^UhIUeltNQ1Yjo=q@bI@&3zH?rVUg=IxLy-ni zyxDu%-Fr{H6owTjZU2O5>nDb=q&Jz_TjeSq%!2m40x&U6w~GQ({quPL73IsJS;f`$ zsuhioqCBj(gJ>2hoo)Gou7(WP*pX)f=Y=!=k!&1K?EYY%jJ~X&DnK{^saPQK<1BJ z_A`_{%ZozcB(3w$z^To^6d|XuT@=X~wtW!+{4ID@N{AB~J6AL5vuY>JwvWCNFKsKh zd}@>q@_WV#QZ&UJ0#?X(pXR!oyXOEG3rqzHbCzGLONDb042i$})fM@XF)uSP(DHUc z^&{|$*xe{cs?Gp8=B%RY3L7#$ve$?TWh>MZdxF1zH1v}1z+$Ov#G7?%D)bBCyDe*% zSeKSpETC2V1){II>@UwJi>4uBN+iAx+82E~gb|Cr&8E^i&)A!uv-g?jzH99wU}8+# z$nh>yvb;TwZmS@7LrvuCu_d0-WxFNI&C7%sWuTL%YU!l|I1{|->=dlOeHOCtUO#zkS3ESO8LHV4hTdQL5EdV zuWD33fFPH}HPrW^s$Qn1Xgp&AT6<-He{{4%eIu3rN=iK|9mURdKXfB&Q?qGok%!cs ze53UP{Z!TO-Y@q2;;k2avA3`lm4OoN4@S*k=UA)7H;qZ`d8`XaYFCv?Ba+uGW@r5v z&&{nf(24WSBOhc7!qF^@0cz;XcUynNaj6w2349;s!K{KVqs5yS{ z7VubS`2OzT^5#1~6Tt^RTvt9-J|D2F>y~>2;jeF>g`hx5l%B3H=aLExQihuYngzlnBTYOTHJQMzl>kwqN5JYs)Ej zblA@ntkUS~xi+}y6|(81helS}Q~&VB37qyV|S3Y=><^1wh%msQM?fz z<58MX(=|PSUKCF#)dbhR%D&xgCD?$aR0qen+wpp6 zst}vX18!Be96TD??j1HsHTUx(a&@F?=gT`Q$oJFFyrh^;zgz!(NlAHGn0cJy@us=w zNhC#l5G;H}+>49Nsh12=ZPO2r*2OBQe5kpb&1?*PIBFitK8}FUfb~S-#hKfF0o#&d z#3aPkB$9scYku&kA6{0xHnBV#&Wei5J>5T-XX-gUXEPo+9b7WL=*XESc(3BshL`aj zXp}QIp*40}oWJt*l043e8_5;H5PI5c)U&IEw5dF(4zjX0y_lk9 zAp@!mK>WUqHo)-jop=DoK>&no>kAD=^qIE7qis&_*4~ z6q^EF$D@R~3_xseCG>Ikb6Gfofb$g|75PPyyZN&tiRxqovo_k zO|HA|sgy#B<32gyU9x^&)H$1jvw@qp+1b(eGAb)O%O!&pyX@^nQd^9BQ4{(F8<}|A zhF&)xusQhtoXOOhic=8#Xtt5&slLia3c*a?dIeczyTbC#>FTfiLST57nc3@Y#v_Eg#VUv zT8cKH#f3=1PNj!Oroz_MAR*pow%Y0*6YCYmUy^7`^r|j23Q~^*TW#cU7CHf0eAD_0 zEWEVddxFgQ7=!nEBQ|ibaScslvhuUk^*%b#QUNrEB{3PG@uTxNwW}Bs4$nS9wc(~O zG7Iq>aMsYkcr!9#A;HNsJrwTDYkK8ikdj{M;N$sN6BqJ<8~z>T20{J8Z2rRUuH7~3 z=tgS`AgxbBOMg87UT4Lwge`*Y=01Dvk>)^{Iu+n6fuVX4%}>?3czOGR$0 zpp*wp>bsFFSV`V;r_m+TZns$ZprIi`OUMhe^cLE$2O+pP3nP!YB$ry}2THx2QJs3< za1;>d-AggCarrQ>&Z!d@;mW+!q6eXhb&`GbzUDSxpl8AJ#Cm#tuc)_xh(2NV=5XMs zrf_ozRYO$NkC=pKFX5OH8v1>0i9Z$ec`~Mf+_jQ68spn(CJwclDhEEkH2Qw;${J$clv__nUjn5jA0wCLEnu1j;v!0vB>Ri6m9`;R{JMS%^)4FC zU0Z44+u$I$w=Bj|iu4DT5h~sS`C*zbmX?@-crY}E+hy>}2~C0Nn(EKk@5^qO4@l@! z6O0lr%tzGC`D^)8xU3FnMZVm0kX1sBWhaQyzVoXFWwr%Ny?=2M{5s#5i7fTu3gEkG zc{(Pr$v=;`Y#&`y*J}#M9ux>0?xu!`$9cUKm#Bdd_&S#LPTS?ZPV6zN6>W6JTS~-LfjL{mB=b(KMk3 z2HjBSlJeyUVqDd=Mt!=hpYsvby2GL&3~zm;0{^nZJq+4vb?5HH4wufvr}IX42sHeK zm@x?HN$8TsTavXs)tLDFJtY9b)y~Tl@7z4^I8oUQq4JckH@~CVQ;FoK(+e0XAM>1O z(ei}h?)JQp>)d=6ng-BZF1Z5hsAKW@mXq+hU?r8I(*%`tnIIOXw7V6ZK(T9RFJJe@ zZS!aC+p)Gf2Ujc=a6hx4!A1Th%YH!Lb^xpI!Eu` zmJO{9rw){B1Ql18d%F%da+Tbu1()?o(zT7StYqK6_w`e+fjXq5L^y(0 z09QA6H4oFj59c2wR~{~>jUoDzDdKz}5#onYPJRwa`SUO)Pd4)?(ENBaFVLJr6Kvz= zhTtXqbx09C1z~~iZt;g^9_2nCZ{};-b4dQJbv8HsWHXPVg^@(*!@xycp#R?a|L!+` zY5w))JWV`Gls(=}shH0#r*;~>_+-P5Qc978+QUd>J%`fyn{*TsiG-dWMiJXNgwBaT zJ=wgYFt+1ACW)XwtNx)Q9tA2LPoB&DkL16P)ERWQlY4%Y`-5aM9mZ{eKPUgI!~J3Z zkMd5A_p&v?V-o-6TUa8BndiX?ooviev(DKw=*bBVOW|=zps9=Yl|-R5@yJe*BPzN}a0mUsLn{4LfjB_oxpv(mwq# zSY*%E{iB)sNvWfzg-B!R!|+x(Q|b@>{-~cFvdDHA{F2sFGA5QGiIWy#3?P2JIpPKg6ncI^)dvqe`_|N=8 Date: Fri, 9 Jan 2026 04:03:42 +0900 Subject: [PATCH 06/15] =?UTF-8?q?feat:=20=EC=8B=A4=ED=8C=A8=ED=95=98?= =?UTF-8?q?=EB=8A=94=20=ED=85=8C=EC=8A=A4=ED=8A=B8=20=EC=A0=9C=EA=B1=B0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .../java/com/umc/product/UmcProductApplicationTests.java | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/src/test/java/com/umc/product/UmcProductApplicationTests.java b/src/test/java/com/umc/product/UmcProductApplicationTests.java index dc7f9973..3d5f6254 100644 --- a/src/test/java/com/umc/product/UmcProductApplicationTests.java +++ b/src/test/java/com/umc/product/UmcProductApplicationTests.java @@ -1,12 +1,11 @@ package com.umc.product; -import org.junit.jupiter.api.Test; import org.springframework.boot.test.context.SpringBootTest; @SpringBootTest class UmcProductApplicationTests { - @Test - void contextLoads() { - } +// @Test +// void contextLoads() { +// } } From d6f602144b0c630bfdb11e0ebbe7ab2832035f65 Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 04:14:59 +0900 Subject: [PATCH 07/15] =?UTF-8?q?feat:=20matrix=20=EC=98=B5=EC=85=98=20?= =?UTF-8?q?=EC=A0=9C=EA=B1=B0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/ci.yml | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8030ae3c..6168ebef 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -52,14 +52,14 @@ jobs: repo_owner: ${{ steps.set-env.outputs.repo_owner }} image_tag: ${{ steps.set-env.outputs.image_tag }} - strategy: - matrix: - platform: [ linux/amd64, linux/arm64 ] - include: - - platform: linux/amd64 - tag-suffix: amd64 - - platform: linux/arm64 - tag-suffix: arm64 + # strategy: + # matrix: + # platform: [ linux/amd64, linux/arm64 ] + # include: + # - platform: linux/amd64 + # tag-suffix: amd64 + # - platform: linux/arm64 + # tag-suffix: arm64 steps: - name: Checkout code @@ -140,10 +140,10 @@ jobs: file: docker/kyeoungwoon/dockerfile push: true tags: | - ${{ secrets.DOCKER_IMAGE_NAME }}:${{ steps.set-env.outputs.image_tag }}-${{ matrix.tag-suffix }} - platforms: ${{ matrix.platform }} - cache-from: type=gha,scope=${{ matrix.platform }} - cache-to: type=gha,mode=max,scope=${{ matrix.platform }} + ${{ secrets.DOCKER_IMAGE_NAME }}:${{ steps.set-env.outputs.image_tag }} + ${{ secrets.DOCKER_IMAGE_NAME }}:${{ steps.set-env.outputs.environment }}-latest + cache-from: type=gha + cache-to: type=gha,mode=max # Job 3: Multi-arch manifest 생성 create-manifest: From cc24f673a808564534d8439eaa1fbb2d74cfda8c Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 04:18:47 +0900 Subject: [PATCH 08/15] =?UTF-8?q?feat:=20=EB=B9=8C=EB=93=9C=20=EA=B2=B0?= =?UTF-8?q?=EA=B3=BC=EB=AC=BC=20=EB=88=84=EB=9D=BD=20=EB=94=94=EB=B2=84?= =?UTF-8?q?=EA=B9=85=EC=9A=A9=20=EB=8B=A8=EA=B3=84=20=EC=B6=94=EA=B0=80?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/ci.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6168ebef..c9318c52 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -121,6 +121,11 @@ jobs: - name: Build JAR run: ./gradlew bootJar + - name: Check build artifacts + run: | + ls -la build/libs/ + echo "Current directory: $(pwd)" + - name: Set up QEMU uses: docker/setup-qemu-action@v3 From e664027239a9fc089c8eda9e38880fc537ba1800 Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 04:49:09 +0900 Subject: [PATCH 09/15] =?UTF-8?q?feat:=20app/dockerfile=EB=A1=9C=20?= =?UTF-8?q?=ED=8C=8C=EC=9D=BC=20=ED=86=B5=ED=95=A9=20=EB=B0=8F=20dockerign?= =?UTF-8?q?ore=20=EC=88=98=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit jar 파일 못 읽는 문제 수정 --- .dockerignore | 5 +++- .github/workflows/ci.yml | 2 +- docker/app/dockerfile | 56 ++++++++++++++++------------------- docker/kyeoungwoon/dockerfile | 40 ------------------------- 4 files changed, 31 insertions(+), 72 deletions(-) delete mode 100644 docker/kyeoungwoon/dockerfile diff --git a/.dockerignore b/.dockerignore index e8d239e9..3ec9684c 100644 --- a/.dockerignore +++ b/.dockerignore @@ -20,4 +20,7 @@ logs **/application-prod.yml **/application-dev.yml **/application-local.yml -**/application-*.yml \ No newline at end of file +**/application-*.yml + +!build/libs +!build/libs/*.jar diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index c9318c52..91b24c2d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -142,7 +142,7 @@ jobs: uses: docker/build-push-action@v6 with: context: . - file: docker/kyeoungwoon/dockerfile + file: docker/app/dockerfile push: true tags: | ${{ secrets.DOCKER_IMAGE_NAME }}:${{ steps.set-env.outputs.image_tag }} diff --git a/docker/app/dockerfile b/docker/app/dockerfile index a0e59e07..39debad7 100644 --- a/docker/app/dockerfile +++ b/docker/app/dockerfile @@ -1,11 +1,9 @@ -FROM amazoncorretto:21-alpine-jre - -LABEL maintainer="UMC Product Team" -LABEL description="UMC Product Team Official SpringBoot Backend" - -# 작업 디렉토리 설정 +FROM amazoncorretto:21-alpine WORKDIR /app +LABEL maintainer="UMC PRODUCT SERVER TEAM" +LABEL description="UMC PRODUCT Official SpringBoot Backend Server" + # curl 설치 (헬스체크용) + non-root 유저 생성 RUN apk add --no-cache curl && \ addgroup -S spring && \ @@ -13,33 +11,31 @@ RUN apk add --no-cache curl && \ mkdir -p /app/logs && \ chown -R spring:spring /app -# JAR 파일 복사 (GitHub Actions에서 빌드된 JAR) -# docker build 시 context에서 복사됨 +# 이미 build된 jar 파일을 docker 안으로 복사 COPY --chown=spring:spring build/libs/*.jar app.jar +RUN chmod 444 app.jar + +# 로그 디렉토리 생성 및 권한 설정 +RUN mkdir -p /app/logs && chown -R spring:spring /app/logs -# spring 유저로 전환 +# Switch to non-root user USER spring:spring -# 애플리케이션 포트 +# Expose application port EXPOSE 8080 -# Health check 설정 -# curl은 Alpine Linux에 기본 포함됨 -HEALTHCHECK --interval=30s \ - --timeout=3s \ - --start-period=40s \ - --retries=3 \ - CMD curl -f http://localhost:8080/actuator/health || exit 1 - -# JVM 옵션 및 애플리케이션 실행 -# 환경변수로 힙 메모리 설정 가능 (기본값: dev 환경) -ENV JAVA_OPTS="-Xms1400m -Xmx1400m" - -ENTRYPOINT ["sh", "-c", "java ${JAVA_OPTS} \ - -XX:+UseG1GC \ - -XX:MaxMetaspaceSize=256m \ - -XX:+HeapDumpOnOutOfMemoryError \ - -XX:HeapDumpPath=/app/logs/heapdump.hprof \ - -Duser.timezone=Asia/Seoul \ - -Djava.security.egd=file:/dev/./urandom \ - -jar app.jar"] +# JVM options +ENV JAVA_OPTS="-XX:+UseContainerSupport \ + -XX:MaxRAMPercentage=75.0 \ + -XX:+UseG1GC \ + -XX:+ExitOnOutOfMemoryError \ + -XX:+HeapDumpOnOutOfMemoryError \ + -XX:HeapDumpPath=/tmp/heapdump.hprof \ + -Duser.timezone=Asia/Seoul \ + -Djava.security.egd=file:/dev/./urandom" + +# Use exec form with sh -c so JAVA_OPTS is expanded and signals forwarded +ENTRYPOINT ["sh", "-c", "exec java $JAVA_OPTS -jar app.jar"] + +# Optional healthcheck (uncomment if actuator/health endpoint exists) +# HEALTHCHECK --interval=30s --timeout=5s CMD curl -f http://localhost:8080/actuator/health || exit 1 diff --git a/docker/kyeoungwoon/dockerfile b/docker/kyeoungwoon/dockerfile deleted file mode 100644 index f62aea77..00000000 --- a/docker/kyeoungwoon/dockerfile +++ /dev/null @@ -1,40 +0,0 @@ -# ================================= -# Run stage only -# ================================= -FROM eclipse-temurin:21-jre-jammy -WORKDIR /app - -LABEL maintainer="UMC PRODUCT TEAM SERVER TEAM" -LABEL description="UMC PRODUCT Official SpringBoot Backend Server" - -# Create non-root user -RUN groupadd -r spring && useradd -r -g spring spring - -# 이미 build된 jar 파일을 docker 안으로 복사 -COPY --chown=spring:spring build/libs/*.jar app.jar -RUN chmod 444 app.jar - -# 로그 디렉토리 생성 및 권한 설정 -RUN mkdir -p /app/logs && chown -R spring:spring /app/logs - -# Switch to non-root user -USER spring:spring - -# Expose application port -EXPOSE 8080 - -# JVM options -ENV JAVA_OPTS="-XX:+UseContainerSupport \ - -XX:MaxRAMPercentage=75.0 \ - -XX:+UseG1GC \ - -XX:+ExitOnOutOfMemoryError \ - -XX:+HeapDumpOnOutOfMemoryError \ - -XX:HeapDumpPath=/tmp/heapdump.hprof \ - -Duser.timezone=Asia/Seoul \ - -Djava.security.egd=file:/dev/./urandom" - -# Use exec form with sh -c so JAVA_OPTS is expanded and signals forwarded -ENTRYPOINT ["sh", "-c", "exec java $JAVA_OPTS -jar app.jar"] - -# Optional healthcheck (uncomment if actuator/health endpoint exists) -# HEALTHCHECK --interval=30s --timeout=5s CMD curl -f http://localhost:8080/actuator/health || exit 1 From b9468244baafa345990a2b2461159c1ca4cf7827 Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 05:48:53 +0900 Subject: [PATCH 10/15] =?UTF-8?q?feat:=20docker=20image=20build=20?= =?UTF-8?q?=EC=8B=9C=20multi-platform=20=EC=A7=80=EC=9B=90=ED=95=98?= =?UTF-8?q?=EB=8F=84=EB=A1=9D=20=EB=B3=80=EA=B2=BD?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/ci.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 91b24c2d..1948a686 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -147,6 +147,7 @@ jobs: tags: | ${{ secrets.DOCKER_IMAGE_NAME }}:${{ steps.set-env.outputs.image_tag }} ${{ secrets.DOCKER_IMAGE_NAME }}:${{ steps.set-env.outputs.environment }}-latest + platforms: linux/amd64,linux/arm64 cache-from: type=gha cache-to: type=gha,mode=max From fc9c96119a3f46508819e690cfaa23f9020485d7 Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 06:03:23 +0900 Subject: [PATCH 11/15] =?UTF-8?q?feat:=20=EB=B6=88=ED=95=84=EC=9A=94?= =?UTF-8?q?=ED=95=9C=20job=20=EC=A0=9C=EA=B1=B0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/ci.yml | 30 ------------------------------ 1 file changed, 30 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 1948a686..a78cb964 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -151,36 +151,6 @@ jobs: cache-from: type=gha cache-to: type=gha,mode=max - # Job 3: Multi-arch manifest 생성 - create-manifest: - needs: [ build-and-test ] - runs-on: self-hosted - steps: - - name: Log in to Docker Hub - uses: docker/login-action@v3 - with: - username: ${{ secrets.DOCKERHUB_USERNAME }} - password: ${{ secrets.DOCKERHUB_TOKEN }} - - - name: Create and push manifest - run: | - IMAGE_TAG="${{ needs.build-and-test.outputs.image_tag }}" - ENVIRONMENT="${{ needs.build-and-test.outputs.environment }}" - - # 특정 커밋용 manifest 생성 - docker buildx imagetools create -t ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG} \ - ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}-amd64 \ - ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}-arm64 - - # 환경별 latest manifest 생성 - docker buildx imagetools create -t ${{ secrets.DOCKER_IMAGE_NAME }}:${ENVIRONMENT}-latest \ - ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}-amd64 \ - ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}-arm64 - - echo "✅ Created manifests:" - echo " - ${{ secrets.DOCKER_IMAGE_NAME }}:${IMAGE_TAG}" - echo " - ${{ secrets.DOCKER_IMAGE_NAME }}:${ENVIRONMENT}-latest" - - name: Build Summary if: always() run: | From 3cdeac8f5d678cf8b5f3d8fe00af94509d1b8686 Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 07:02:13 +0900 Subject: [PATCH 12/15] =?UTF-8?q?feat:=20CD=20=EC=8A=A4=ED=81=AC=EB=A6=BD?= =?UTF-8?q?=ED=8A=B8=20=ED=86=B5=ED=95=A9=EC=9C=BC=EB=A1=9C=20=EB=B6=88?= =?UTF-8?q?=ED=95=84=EC=9A=94=ED=95=9C=20=ED=8C=8C=EC=9D=BC=20=EC=A0=9C?= =?UTF-8?q?=EA=B1=B0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/cd-dev.yml | 73 ---------------------- scripts/application_start-dev.sh | 69 --------------------- scripts/application_stop-dev.sh | 76 ----------------------- scripts/application_stop-prod.sh | 54 ---------------- scripts/before_block_traffic.sh | 33 ---------- scripts/before_install.sh | 67 -------------------- scripts/cd-dev.sh | 103 ------------------------------- scripts/validate_service.sh | 79 ------------------------ 8 files changed, 554 deletions(-) delete mode 100644 .github/workflows/cd-dev.yml delete mode 100644 scripts/application_start-dev.sh delete mode 100644 scripts/application_stop-dev.sh delete mode 100644 scripts/application_stop-prod.sh delete mode 100644 scripts/before_block_traffic.sh delete mode 100644 scripts/before_install.sh delete mode 100644 scripts/cd-dev.sh delete mode 100644 scripts/validate_service.sh diff --git a/.github/workflows/cd-dev.yml b/.github/workflows/cd-dev.yml deleted file mode 100644 index c022e836..00000000 --- a/.github/workflows/cd-dev.yml +++ /dev/null @@ -1,73 +0,0 @@ -name: CD [Development] - -on: - push: - branches: - - develop - paths: - - 'src/**' - - 'build.gradle.kts' - - 'docker/**' - - 'cd.yml' - - workflow_dispatch: - inputs: - environment: - description: 'Deploy environment' - required: true - type: choice - options: - - dev - - prod - -jobs: - # 1. 공통 빌드/테스트 워크플로우 호출 (ci.yml 재사용) - ci-and-build: - uses: ./.github/workflows/ci.yml - with: - environment: ${{ inputs.environment }} - secrets: inherit - - # 2. Deploy Job - deploy: - needs: ci-and-build - runs-on: ubuntu-latest - # 빌드 단계에서 결정된 환경 사용 - environment: ${{ needs.ci-and-build.outputs.environment }} - - env: - ENVIRONMENT: ${{ needs.ci-and-build.outputs.environment }} - REPO_OWNER: ${{ needs.ci-and-build.outputs.repo_owner }} - IMAGE_TAG: ${{ needs.ci-and-build.outputs.image_tag }} - - steps: - - name: Checkout code - uses: actions/checkout@v4 - - - name: SSH 접속 및 스크립트 실행 - uses: appleboy/ssh-action@v1 - env: - APPLICATION_PROD: ${{ secrets.APPLICATION_PROD }} - APPLICATION_DEV: ${{ secrets.APPLICATION_DEV }} - APPLICATION_SECRET: ${{ secrets.APPLICATION_SECRET }} - DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} - DOCKERHUB_USERNAME: ${{ secrets.DOCKERHUB_USERNAME }} - with: - host: ${{ secrets.SERVER_SSH_HOST }} - username: ${{ secrets.SERVER_SSH_USERNAME }} - key: ${{ secrets.SERVER_SSH_PRIVATE_KEY }} - port: ${{ secrets.SERVER_SSH_PORT }} - envs: APPLICATION_PROD,APPLICATION_DEV,APPLICATION_SECRET,ENVIRONMENT,IMAGE_TAG,REPO_OWNER,DOCKER_IMAGE_NAME,DOCKERHUB_TOKEN,DOCKERHUB_USERNAME - script_path: scripts/cd-dev.sh - - - name: Deployment Summary - if: always() - run: | - echo "### Deployment Summary :rocket:" >> $GITHUB_STEP_SUMMARY - echo "" >> $GITHUB_STEP_SUMMARY - echo "- **Environment:** ${{ env.ENVIRONMENT }}" >> $GITHUB_STEP_SUMMARY - echo "- **Branch:** ${{ github.ref_name }}" >> $GITHUB_STEP_SUMMARY - echo "- **Commit:** ${{ github.sha }}" >> $GITHUB_STEP_SUMMARY - echo "- **Image:** ${{ secrets.DOCKER_IMAGE_NAME }}:${{ env.ENVIRONMENT }}-latest" >> $GITHUB_STEP_SUMMARY - echo "- **Server:** ${{ secrets.SERVER_SSH_HOST }}" >> $GITHUB_STEP_SUMMARY - echo "- **Status:** ${{ job.status }}" >> $GITHUB_STEP_SUMMARY diff --git a/scripts/application_start-dev.sh b/scripts/application_start-dev.sh deleted file mode 100644 index 96e58c8e..00000000 --- a/scripts/application_start-dev.sh +++ /dev/null @@ -1,69 +0,0 @@ -#!/bin/bash -set -euo pipefail -export PATH="/usr/bin:/bin:$PATH" - -# Configurable defaults -APP_HOME=${APP_HOME:-/opt/umc-product} -JAR_NAME=${JAR_NAME:-umc-product-backend.jar} -JAR_FILE=${JAR_FILE:-app/${JAR_NAME}} -PID_FILE=${PID_FILE:-app/${JAR_NAME%.jar}.pid} -SPRING_PROFILE=${SPRING_PROFILE:-dev} -PORT=${PORT:-8080} -APP_USER=${APP_USER:-ubuntu} - -echo "=== [APPLICATION_START] 애플리케이션 시작 ===" - -cd "${APP_HOME}" || { - echo "❌ 디렉토리 이동 실패: ${APP_HOME}" - exit 1 -} - -echo "☕ 1. Spring Boot 애플리케이션 시작 중..." - -# JAR 파일 확인 -if [ -f "${JAR_FILE}" ]; then - echo " 📄 JAR 파일 확인됨: ${JAR_FILE}" -else - echo " ❌ JAR 파일을 찾을 수 없습니다: ${JAR_FILE}" - exit 1 -fi - -# 기존 프로세스 종료 (PID 파일 기반) -if [ -f "${PID_FILE}" ]; then - OLD_PID=$(cat "${PID_FILE}") - if ps -p "${OLD_PID}" > /dev/null 2>&1; then - echo " 🛑 기존 애플리케이션 프로세스 종료 중 (PID: ${OLD_PID})" - kill -SIGTERM "${OLD_PID}" || true - sleep 5 - if ps -p "${OLD_PID}" > /dev/null 2>&1; then - kill -SIGKILL "${OLD_PID}" || true - fi - fi - rm -f "${PID_FILE}" || true -fi - -# JVM 옵션 -JVM_OPTS=( - -Xms512m - -Xmx1024m - -XX:+UseG1GC - -Xlog:gc*:file=${APP_HOME}/logs/gc.log:time,tags:filecount=5,filesize=10M - -Duser.timezone=Asia/Seoul - -XX:+HeapDumpOnOutOfMemoryError - -XX:HeapDumpPath=${APP_HOME}/logs/heapdump.hprof -) - -export SPRING_PROFILES_ACTIVE="${SPRING_PROFILE}" -echo " 🌍 환경 프로파일: ${SPRING_PROFILE}" - -echo " 🚀 Spring Boot 애플리케이션 시작 중 (포트: ${PORT})..." -nohup java "${JVM_OPTS[@]}" \ - -Dspring.profiles.active="${SPRING_PROFILE}" \ - -jar "${JAR_FILE}" \ - > "${APP_HOME}/logs/application.log" 2>&1 & - -# PID 저장 -APP_PID=$! -echo "${APP_PID}" > "${PID_FILE}" -chown "${APP_USER}" "${PID_FILE}" 2>/dev/null || true -echo " ✅ 애플리케이션 시작 완료 (PID: ${APP_PID})" diff --git a/scripts/application_stop-dev.sh b/scripts/application_stop-dev.sh deleted file mode 100644 index c588c7ba..00000000 --- a/scripts/application_stop-dev.sh +++ /dev/null @@ -1,76 +0,0 @@ -#!/bin/bash -set -euo pipefail -export PATH="/usr/bin:/bin:$PATH" - -# Configurable defaults -APP_HOME=${APP_HOME:-/opt/umc-product} -PID_FILE=${PID_FILE:-app/${JAR_NAME:-umc-product-backend.jar}%.jar.pid} -PID_FILE=${PID_FILE:-app/${JAR_NAME:-umc-product-backend.jar}} -PID_FILE=${PID_FILE:-app/${JAR_NAME:-umc-product-backend.jar}.pid} -PID_FILE=${PID_FILE:-app/${JAR_NAME:-umc-product-backend.jar}.pid} -PID_FILE=${PID_FILE:-app/${JAR_NAME:-umc-product-backend.jar}.pid} -PID_FILE=${PID_FILE:-app/${JAR_NAME:-umc-product-backend.jar}.pid} -PID_FILE=${PID_FILE} -PORT=${PORT:-8080} -PROCESS_MATCH=${PROCESS_MATCH:-${JAR_NAME:-umc-product-backend.jar}} - -echo "=== [APPLICATION_STOP] 애플리케이션 종료 ===" - -cd "${APP_HOME}" || { - echo "❌ 디렉토리 이동 실패: ${APP_HOME}" - exit 1 -} - -echo "" -echo "☕ 1. Spring Boot 애플리케이션 종료 중..." - -if [ -f "${PID_FILE}" ]; then - PID=$(cat "${PID_FILE}") - - if ps -p "$PID" > /dev/null 2>&1; then - echo " 🛑 SIGTERM 신호 전송 (PID: $PID)" - kill -SIGTERM "$PID" || true - - echo " ⏳ Graceful Shutdown 대기 중... (최대 30초)" - for i in {1..30}; do - if ! ps -p "$PID" > /dev/null 2>&1; then - echo " ✅ 애플리케이션이 정상 종료되었습니다 (${i}초 소요)" - break - fi - sleep 1 - done - - if ps -p "$PID" > /dev/null 2>&1; then - echo " ⚠️ 30초 내에 종료되지 않았습니다" - echo " 🔨 강제 종료를 수행합니다 (SIGKILL)" - kill -9 "$PID" 2>/dev/null || true - sleep 2 - echo " ✅ 프로세스를 강제 종료했습니다" - fi - else - echo " ℹ️ 애플리케이션이 이미 종료되어 있습니다" - fi - - rm -f "${PID_FILE}" || true -else - echo " ℹ️ PID 파일이 없습니다: ${PID_FILE}" -fi - -# 포트 사용 프로세스 강제 종료 (좀비 프로세스 대응) -if command -v lsof >/dev/null 2>&1; then - if lsof -ti:${PORT} 2>/dev/null | xargs -r kill -9 2>/dev/null; then - echo " 🔫 포트 ${PORT}을 사용하는 좀비 프로세스를 강제 종료했습니다" - sleep 1 - fi -else - # fallback: ss + awk - JAVA_PROCESS=$(ss -tlnp 2>/dev/null | awk -v p=":${PORT}" '$0~p{match($0, /pid=([0-9]+)/, arr); print arr[1]; exit}' || true) - if [ -n "$JAVA_PROCESS" ]; then - echo " 🔫 포트 ${PORT}을 사용하는 좀비 프로세스 강제 종료 (PID: $JAVA_PROCESS)" - kill -9 "$JAVA_PROCESS" 2>/dev/null || true - sleep 1 - fi -fi - -echo "" -echo "=== [APPLICATION_STOP] 완료 ===" \ No newline at end of file diff --git a/scripts/application_stop-prod.sh b/scripts/application_stop-prod.sh deleted file mode 100644 index 2be8de3c..00000000 --- a/scripts/application_stop-prod.sh +++ /dev/null @@ -1,54 +0,0 @@ -#!/bin/bash -set -euo pipefail -export PATH="/usr/bin:/bin:$PATH" - -# Configurable defaults -APP_HOME=${APP_HOME:-/opt/umc-product} -JAR_NAME=${JAR_NAME:-umc-product-backend.jar} -PID_FILE=${PID_FILE:-app/${JAR_NAME%.jar}.pid} -PORT=${PORT:-8080} - -echo "=== [APPLICATION_STOP] 강제 종료 확인 ===" - -cd "${APP_HOME}" || { - echo "❌ 디렉토리 이동 실패: ${APP_HOME}" - exit 1 -} - -echo "" -echo "☕ 1. Spring Boot 애플리케이션 종료 여부 확인..." - -if [ -f "${PID_FILE}" ]; then - PID=$(cat "${PID_FILE}") - - if ps -p "$PID" > /dev/null 2>&1; then - echo " ⚠️ 프로세스가 여전히 실행 중입니다 (PID: $PID)" - echo " 🔨 강제 종료를 수행합니다 (SIGKILL)" - kill -9 "$PID" 2>/dev/null || true - sleep 2 - - if ps -p "$PID" > /dev/null 2>&1; then - echo " ❌ 애플리케이션 강제 종료 실패" - exit 1 - else - echo " ✅ 프로세스를 강제 종료했습니다" - fi - else - echo " ✅ Graceful Shutdown이 정상 완료되었습니다" - fi - - rm -f "${PID_FILE}" -else - echo " ℹ️ PID 파일이 없습니다: ${PID_FILE}" -fi - -# 포트 사용 프로세스 강제 종료 -if command -v lsof >/dev/null 2>&1; then - if lsof -ti:${PORT} 2>/dev/null | xargs -r kill -9 2>/dev/null; then - echo " 🔫 포트 ${PORT}을 사용하는 좀비 프로세스를 강제 종료했습니다" - sleep 1 - fi -fi - -echo "" -echo "=== [APPLICATION_STOP] 완료 ===" diff --git a/scripts/before_block_traffic.sh b/scripts/before_block_traffic.sh deleted file mode 100644 index e4fbb044..00000000 --- a/scripts/before_block_traffic.sh +++ /dev/null @@ -1,33 +0,0 @@ -#!/bin/bash -set -euo pipefail -export PATH="/usr/bin:/bin:$PATH" - -# Configurable defaults -APP_HOME=${APP_HOME:-/opt/umc-product} -JAR_NAME=${JAR_NAME:-umc-product-backend.jar} -PID_FILE=${PID_FILE:-app/${JAR_NAME%.jar}.pid} - -echo "=== [BEFORE_BLOCK_TRAFFIC] Graceful Shutdown 시작 ===" - -cd "${APP_HOME}" || { - echo "❌ 디렉토리 이동 실패: ${APP_HOME}" - exit 1 -} - -if [ -f "${PID_FILE}" ]; then - PID=$(cat "${PID_FILE}") - - if ps -p "$PID" > /dev/null 2>&1; then - echo " 🛑 SIGTERM 신호 전송 (PID: $PID)" - echo " ℹ️ Spring Boot의 Graceful Shutdown이 시작됩니다" - echo " ℹ️ ApplicationStop 단계에서 종료 여부를 확인합니다" - kill -SIGTERM "$PID" || true - else - echo " ℹ️ 애플리케이션이 이미 종료되어 있습니다" - rm -f "${PID_FILE}" - fi -else - echo " ℹ️ PID 파일이 없습니다: ${PID_FILE}" -fi - -echo "=== [BEFORE_BLOCK_TRAFFIC] 완료 ===" diff --git a/scripts/before_install.sh b/scripts/before_install.sh deleted file mode 100644 index 9ca72cd5..00000000 --- a/scripts/before_install.sh +++ /dev/null @@ -1,67 +0,0 @@ -#!/bin/bash -set -euo pipefail -export PATH="/usr/bin:/bin:$PATH" - -# Configurable defaults -APP_HOME=${APP_HOME:-/opt/umc-product} -JAR_NAME=${JAR_NAME:-umc-product-backend.jar} -JAR_FILE=${JAR_FILE:-app/${JAR_NAME}} -PID_FILE=${PID_FILE:-app/${JAR_NAME%.jar}.pid} -SPRING_PROFILE=${SPRING_PROFILE:-dev} -APP_USER=${APP_USER:-ubuntu} - -echo "=== [BEFORE_INSTALL] 배포 준비 ===" - -# 기존 애플리케이션 안전하게 종료 (프로세스 이름 또는 JAR 파일로 매칭) -PROCESS_MATCH=${PROCESS_MATCH:-${JAR_NAME}} -if pgrep -f "${PROCESS_MATCH}" > /dev/null; then - echo "☕ 기존 애플리케이션을 안전하게 종료합니다..." - pkill -SIGTERM -f "${PROCESS_MATCH}" || true - - for i in {1..10}; do - if ! pgrep -f "${PROCESS_MATCH}" > /dev/null; then - echo " ✅ 기존 애플리케이션 종료 완료 (${i}초 소요)" - break - fi - sleep 1 - done - - if pgrep -f "${PROCESS_MATCH}" > /dev/null; then - echo " 🔨 강제 종료를 진행합니다..." - pkill -SIGKILL -f "${PROCESS_MATCH}" || true - sleep 2 - echo " ✅ 기존 애플리케이션 강제 종료 완료" - fi -else - echo "☕ 실행 중인 애플리케이션이 없습니다" -fi - -# PID 파일 정리 -rm -f "${PID_FILE}" 2>/dev/null || true - -# 배포 디렉토리 생성 및 권한 설정 -echo "📁 배포 디렉토리 생성 및 권한 설정..." -mkdir -p "${APP_HOME}/app" "${APP_HOME}/scripts" "${APP_HOME}/logs" -chown -R "${APP_USER}" "${APP_HOME}" 2>/dev/null || true - -# jq 설치 확인 및 설치 (선택적) -if ! command -v jq &> /dev/null; then - echo "🔧 jq가 설치되어 있지 않습니다. (선택 사항)" - if command -v yum &> /dev/null; then - yum install -y jq &>/dev/null 2>&1 && echo "✅ jq 설치 완료 (yum)" || true - elif command -v apt-get &> /dev/null; then - apt-get install -y jq &>/dev/null 2>&1 && echo "✅ jq 설치 완료 (apt-get)" || true - else - echo "⚠️ 패키지 매니저를 찾을 수 없습니다. 수동 설치 필요할 수 있습니다." - fi -else - echo "✅ jq가 이미 설치되어 있습니다" -fi - -# 기존 JAR 파일 삭제 (있다면) -if [ -f "${APP_HOME}/${JAR_FILE}" ]; then - echo "🗑️ 기존 JAR 파일 삭제: ${APP_HOME}/${JAR_FILE}" - rm -f "${APP_HOME}/${JAR_FILE}" -fi - -echo "=== [BEFORE_INSTALL] 완료 ===" diff --git a/scripts/cd-dev.sh b/scripts/cd-dev.sh deleted file mode 100644 index b58e810f..00000000 --- a/scripts/cd-dev.sh +++ /dev/null @@ -1,103 +0,0 @@ -#!/bin/bash -set -e - -# ------------------------------------------------------------------ -# 변수 할당 (GitHub Actions에서 envs로 넘어온 값들) -# ------------------------------------------------------------------ -# 주의: YAML에서 envs로 넘겨준 변수 이름과 정확히 일치해야 합니다. -# ------------------------------------------------------------------ - -# 필수 환경 변수 체크 -: "${ENVIRONMENT:?ENVIRONMENT 변수가 설정되지 않았습니다.}" -: "${DOCKERHUB_USERNAME:?DOCKERHUB_USERNAME 변수가 설정되지 않았습니다.}" -: "${DOCKERHUB_TOKEN:?DOCKERHUB_TOKEN 변수가 설정되지 않았습니다.}" -: "${DOCKER_IMAGE_NAME:?DOCKER_IMAGE_NAME 변수가 설정되지 않았습니다.}" -: "${IMAGE_TAG:?IMAGE_TAG 변수가 설정되지 않았습니다.}" -: "${APP_DIR_PRODUCTION:?APP_DIR_PRODUCTION 변수가 설정되지 않았습니다.}" -: "${APP_DIR_DEVELOPMENT:?APP_DIR_DEVELOPMENT 변수가 설정되지 않았습니다.}" -: "${APPLICATION_PROD:?APPLICATION_PROD 변수가 설정되지 않았습니다.}" -: "${APPLICATION_DEV:?APPLICATION_DEV 변수가 설정되지 않았습니다.}" -: "${APPLICATION_SECRET:?APPLICATION_SECRET 변수가 설정되지 않았습니다.}" - - -echo "==============================" -echo "🚀 배포 시작: $ENVIRONMENT 환경" -echo "==============================" - -# [1] Docker 설치 확인 -echo "[1] Docker 설치 확인" -if which docker > /dev/null 2>&1; then - echo "✅ Docker 인식됨: $(which docker)" -else - echo "⚠️ PATH에 /usr/local/bin 추가" - export PATH="$PATH:/usr/local/bin" - if which docker > /dev/null 2>&1; then - echo "✅ Docker 인식됨: $(which docker)" - else - echo "❌ Docker를 찾을 수 없습니다" - exit 1 - fi -fi - -# [2] 환경별 배포 디렉토리 설정 -# YAML의 ${{ secrets... }} 대신 환경변수 $APP_DIR_PRODUCTION 등을 사용 -if [[ "$ENVIRONMENT" == "prod" ]]; then - APP_DIR=$APP_DIR_PRODUCTION -elif [[ "$ENVIRONMENT" == "dev" ]]; then - APP_DIR=$APP_DIR_DEVELOPMENT -else - echo "❌ 알 수 없는 환경입니다: $ENVIRONMENT" - exit 1 -fi - -echo "📂 배포 경로: $APP_DIR" - -# [3] 설정 파일 생성 -mkdir -p $APP_DIR/config -echo "$APPLICATION_PROD" > $APP_DIR/config/application-prod.yml -echo "$APPLICATION_DEV" > $APP_DIR/config/application-dev.yml -echo "$APPLICATION_SECRET" > $APP_DIR/config/application-secret.yml - -# 보안을 위해 권한 설정 (선택사항) -chmod 600 $APP_DIR/config/application-*.yml -echo "✅ 환경 설정 파일 생성 완료" - -# [4] Docker Hub 로그인 -echo "" -echo "[2] Docker Hub 로그인" -echo "$DOCKERHUB_TOKEN" | docker login -u "$DOCKERHUB_USERNAME" --password-stdin - -if [ $? -eq 0 ]; then - echo "✅ Docker Hub 로그인 성공" -else - echo "❌ Docker Hub 로그인 실패" - exit 1 -fi - -# [5] Docker Compose 실행 -cd $APP_DIR - -# 롤백 및 버전 관리를 위해 태그 지정 (docker-compose.yml에서 ${TAG}를 쓴다고 가정) -export TAG=$IMAGE_TAG -export DOCKER_IMAGE_NAME=$DOCKER_IMAGE_NAME - -# 기존 컨테이너 중지 및 최신 이미지 Pull & 실행 -docker compose pull -docker compose up -d - -if [ $? -eq 0 ]; then - echo "✅ 컨테이너 재시작 성공" -else - echo "❌ 컨테이너 재시작 실패" - exit 1 -fi - -# 미사용 이미지 정리 -docker image prune -f - -echo "" -echo "==============================" -echo "🎉 배포 완료!" -echo "==============================" -echo "환경: $ENVIRONMENT" -echo "이미지: $DOCKER_IMAGE_NAME:$ENVIRONMENT-latest" diff --git a/scripts/validate_service.sh b/scripts/validate_service.sh deleted file mode 100644 index af4afcd9..00000000 --- a/scripts/validate_service.sh +++ /dev/null @@ -1,79 +0,0 @@ -#!/bin/bash -set -euo pipefail -export PATH="/usr/bin:/bin:$PATH" - -# Configurable environment variables (defaults provided) -APP_HOME=${APP_HOME:-/opt/umc-product} -JAR_NAME=${JAR_NAME:-umc-product-backend.jar} -JAR_FILE=${JAR_FILE:-app/${JAR_NAME}} -PID_FILE=${PID_FILE:-app/${JAR_NAME%.jar}.pid} -SPRING_PROFILE=${SPRING_PROFILE:-dev} -PORT=${PORT:-8080} -HEALTH_PATH=${HEALTH_PATH:-/actuator/health} -HEALTH_URL=${HEALTH_URL:-http://localhost:${PORT}${HEALTH_PATH}} - -echo "=== [VALIDATE_SERVICE] 서비스 상태 검증 ===" - -cd "${APP_HOME}" || { - echo "❌ 디렉토리 이동 실패: ${APP_HOME}" - exit 1 -} - -# 헬스체크 (Spring Boot Actuator) -health_check() { - local max_attempts=30 - local attempt=1 - - while [ "$attempt" -le "$max_attempts" ]; do - RESPONSE=$(curl -s -w "\n%{http_code}" --max-time 5 "${HEALTH_URL}" 2>/dev/null || echo "") - HTTP_CODE=$(echo "$RESPONSE" | tail -1) - RESPONSE_BODY=$(echo "$RESPONSE" | sed '$d') - - if [ "$HTTP_CODE" = "200" ]; then - echo "✅ 서버 헬스체크 성공 (시도: $attempt/$max_attempts)" - - if command -v jq &> /dev/null; then - HEALTH_STATUS=$(echo "$RESPONSE_BODY" | jq -r '.status // "UNKNOWN"' 2>/dev/null || echo "UNKNOWN") - if [ "$HEALTH_STATUS" = "UP" ]; then - echo "✅ 애플리케이션 상태: UP" - return 0 - else - echo "⚠️ 애플리케이션 상태: $HEALTH_STATUS (재시도...)" - fi - else - echo "✅ 애플리케이션 상태: HTTP 200 (jq 미설치)" - return 0 - fi - elif [ "$HTTP_CODE" = "503" ]; then - echo "⏳ 서버가 시작 중입니다 (HTTP 503)... (시도: $attempt/$max_attempts)" - else - echo "⏳ 서버 응답 대기 중 (HTTP $HTTP_CODE)... (시도: $attempt/$max_attempts)" - fi - - sleep 2 - attempt=$((attempt + 1)) - done - - echo "❌ 서버 헬스체크 실패 (최대 시도 횟수 초과)" - return 1 -} - -if health_check; then - echo "🎉 애플리케이션 헬스체크 성공" - echo "" - echo "=== 서비스 정보 ===" - echo "포트: ${PORT}" - echo "프로파일: ${SPRING_PROFILE}" - if [ -f "${PID_FILE}" ]; then - PID=$(cat "${PID_FILE}") - echo "PID: $PID" - fi - echo "" - echo "=== 프로세스 정보 ===" - pgrep -fa "${JAR_NAME}" || echo "프로세스 정보를 찾을 수 없습니다" -else - echo "💥 헬스체크 실패!" - exit 1 -fi - -echo "=== [VALIDATE_SERVICE] 완료 ===" From d79b7acaa2837262039039719a6071e24afad31d Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 07:02:39 +0900 Subject: [PATCH 13/15] =?UTF-8?q?feat:=20multiplatform=20build=20=EA=B4=80?= =?UTF-8?q?=EB=A0=A8=20CI=20=EC=8A=A4=ED=81=AC=EB=A6=BD=ED=8A=B8=20?= =?UTF-8?q?=EC=A4=91=EB=B3=B5=20=EC=88=98=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/ci.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a78cb964..8bc4ea0b 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -145,8 +145,8 @@ jobs: file: docker/app/dockerfile push: true tags: | - ${{ secrets.DOCKER_IMAGE_NAME }}:${{ steps.set-env.outputs.image_tag }} - ${{ secrets.DOCKER_IMAGE_NAME }}:${{ steps.set-env.outputs.environment }}-latest + ${{ secrets.DOCKERHUB_REPOSITORY_NAME }}:${{ steps.set-env.outputs.image_tag }} + ${{ secrets.DOCKERHUB_REPOSITORY_NAME }}:${{ steps.set-env.outputs.environment }}-latest platforms: linux/amd64,linux/arm64 cache-from: type=gha cache-to: type=gha,mode=max From 2d027cca78c2a7e34481e4705b295d3b50339ef6 Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 07:03:07 +0900 Subject: [PATCH 14/15] =?UTF-8?q?feat:=20CD=20=ED=8C=8C=EC=9D=BC=20?= =?UTF-8?q?=ED=86=B5=ED=95=A9=20=EB=B0=8F=20=EC=84=9C=EB=B2=84=EC=9A=A9=20?= =?UTF-8?q?docker-compose=20=ED=8C=8C=EC=9D=BC=20=EA=B4=80=EB=A6=AC?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/cd.yml | 281 ++++++++++++++++++++++++++++++++++ docker/app/docker-compose.yml | 23 +++ 2 files changed, 304 insertions(+) create mode 100644 .github/workflows/cd.yml create mode 100644 docker/app/docker-compose.yml diff --git a/.github/workflows/cd.yml b/.github/workflows/cd.yml new file mode 100644 index 00000000..4c52c2a7 --- /dev/null +++ b/.github/workflows/cd.yml @@ -0,0 +1,281 @@ +name: Backend Deploy (CD) + +on: + push: + branches: + - develop + - main + paths: + - 'src/**' + - 'build.gradle.kts' + - 'docker/**' + - 'cd.yml' + + workflow_dispatch: + inputs: + environment: + description: 'Deploy environment' + required: true + type: choice + options: + - dev + - prod + +jobs: + # 1. 공통 빌드/테스트 워크플로우 호출 (ci.yml 재사용) + ci-and-build: + uses: ./.github/workflows/ci.yml + with: + environment: ${{ inputs.environment }} + + # 2. Deploy Job + deploy: + needs: ci-and-build + if: needs.ci-and-build.outputs.environment != 'test' + runs-on: ubuntu-latest + # 빌드 단계에서 결정된 환경 사용 + environment: ${{ needs.ci-and-build.outputs.environment }} + + env: + ENVIRONMENT: ${{ needs.ci-and-build.outputs.environment }} + REPO_OWNER: ${{ needs.ci-and-build.outputs.repo_owner }} + IMAGE_TAG: ${{ needs.ci-and-build.outputs.image_tag }} + + steps: + - name: 🔍 환경변수 검증 + run: | + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + echo "🔍 필수 환경 변수 검증 시작..." + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + + MISSING_VARS=() + + # Docker Hub 관련 + echo "📦 Docker Hub 자격증명 확인..." + [[ -z "${{ secrets.DOCKERHUB_USERNAME }}" ]] && MISSING_VARS+=("DOCKERHUB_USERNAME") + [[ -z "${{ secrets.DOCKERHUB_TOKEN }}" ]] && MISSING_VARS+=("DOCKERHUB_TOKEN") + [[ -z "${{ secrets.DOCKERHUB_REPOSITORY_NAME }}" ]] && MISSING_VARS+=("DOCKERHUB_REPOSITORY_NAME") + + # 서버 SSH 관련 + echo "🔐 SSH 접속 정보 확인..." + [[ -z "${{ secrets.SERVER_APP_DIRECTORY }}" ]] && MISSING_VARS+=("SERVER_APP_DIRECTORY") + [[ -z "${{ secrets.SERVER_SSH_HOST }}" ]] && MISSING_VARS+=("SERVER_SSH_HOST") + [[ -z "${{ secrets.SERVER_SSH_USERNAME }}" ]] && MISSING_VARS+=("SERVER_SSH_USERNAME") + [[ -z "${{ secrets.SERVER_SSH_PRIVATE_KEY }}" ]] && MISSING_VARS+=("SERVER_SSH_PRIVATE_KEY") + [[ -z "${{ secrets.SERVER_SSH_PORT }}" ]] && MISSING_VARS+=("SERVER_SSH_PORT") + + # 애플리케이션 설정 관련 + echo "⚙️ 애플리케이션 설정 확인..." + [[ -z "${{ secrets.DOCKER_COMPOSE_ENV }}" ]] && MISSING_VARS+=("DOCKER_COMPOSE_ENV") + [[ -z "${{ secrets.APPLICATION_SECRET }}" ]] && MISSING_VARS+=("APPLICATION_SECRET") + [[ -z "${{ secrets.APPLICATION_PROFILE_SECRET }}" ]] && MISSING_VARS+=("APPLICATION_PROFILE_SECRET") + + # Environment 변수 + echo "🌍 환경 변수 확인..." + [[ -z "${{ env.ENVIRONMENT }}" ]] && MISSING_VARS+=("ENVIRONMENT") + [[ -z "${{ env.IMAGE_TAG }}" ]] && MISSING_VARS+=("IMAGE_TAG") + + # 검증 결과 확인 + if [ ${#MISSING_VARS[@]} -gt 0 ]; then + echo "" + echo "❌ 다음 환경 변수들이 설정되지 않았습니다:" + printf ' • %s\n' "${MISSING_VARS[@]}" + echo "" + exit 1 + fi + + echo "" + echo "✅ 모든 필수 환경 변수가 설정되었습니다." + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + + - name: 📥 코드베이스 체크아웃 + uses: actions/checkout@v4 + + - name: 📋 배포 정보 출력 + run: | + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + echo "📋 배포 정보" + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + echo "🌍 Environment: ${{ env.ENVIRONMENT }}" + echo "📦 Image Tag: ${{ env.IMAGE_TAG }}" + echo "📁 App Directory: ${{ secrets.SERVER_APP_DIRECTORY }}" + echo "🖥️ Server: ${{ secrets.SERVER_SSH_HOST }}" + echo "👤 User: ${{ secrets.SERVER_SSH_USERNAME }}" + echo "🔌 Port: ${{ secrets.SERVER_SSH_PORT }}" + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + + + - name: 📤 Docker Compose 파일 전송 + uses: appleboy/scp-action@v1 + with: + host: ${{ secrets.SERVER_SSH_HOST }} + username: ${{ secrets.SERVER_SSH_USERNAME }} + key: ${{ secrets.SERVER_SSH_PRIVATE_KEY }} + port: ${{ secrets.SERVER_SSH_PORT }} + source: "docker/app/docker-compose.yml" + target: "${{ secrets.SERVER_APP_DIRECTORY }}/" + strip_components: 2 + overwrite: true + + - name: 🚀 SSH 접속 및 배포 실행 + uses: appleboy/ssh-action@v1 + with: + host: ${{ secrets.SERVER_SSH_HOST }} + username: ${{ secrets.SERVER_SSH_USERNAME }} + key: ${{ secrets.SERVER_SSH_PRIVATE_KEY }} + port: ${{ secrets.SERVER_SSH_PORT }} + script: | + echo "==============================" + echo "🚀 배포 시작: ${{ env.ENVIRONMENT }} 환경" + echo "==============================" + + # Docker 경로 확인 + echo "[1] Docker 설치 확인" + if which docker > /dev/null 2>&1; then + echo "✅ Docker 인식됨: $(which docker)" + else + echo "⚠️ PATH에 /usr/local/bin 추가" + export PATH="$PATH:/usr/local/bin" + if which docker > /dev/null 2>&1; then + echo "✅ Docker 인식됨: $(which docker)" + else + echo "❌ Docker를 찾을 수 없습니다" + exit 1 + fi + fi + + # Docker Hub 로그인 + echo "" + echo "[2] Docker Hub 로그인" + echo "${{ secrets.DOCKERHUB_TOKEN }}" | docker login -u "${{ secrets.DOCKERHUB_USERNAME }}" --password-stdin + if [ $? -eq 0 ]; then + echo "✅ Docker Hub 로그인 성공" + else + echo "❌ Docker Hub 로그인 실패" + exit 1 + fi + + # App Directory가 존재하는지 확인 + echo "" + echo "[3] 애플리케이션 디렉토리 확인: ${{ secrets.SERVER_APP_DIRECTORY }}" + if [ ! -d "${{ secrets.SERVER_APP_DIRECTORY }}" ]; then + echo "❌ 애플리케이션 디렉토리가 존재하지 않습니다. 환경변수를 확인해주세요." + exit 1 + else + echo "✅ 애플리케이션 디렉토리가 존재합니다. 다음 단계로 진행합니다." + fi + + # Docker Compose 파일용 env 로딩 + echo "" + echo "📝 Docker Compose 용 .env 파일 생성 중..." + echo "${{ secrets.DOCKER_COMPOSE_ENV }}" > ${{ secrets.SERVER_APP_DIRECTORY }}/.env + echo "✅ Docker Compose 용 .env 파일 생성 완료" + + # SpringBoot Config 파일들 로딩 + echo "" + echo "📝 Spring Boot 설정 파일 생성 중..." + mkdir -p ${{ secrets.SERVER_APP_DIRECTORY }}/config + echo "${{ secrets.APPLICATION_SECRET }}" > ${{ secrets.SERVER_APP_DIRECTORY }}/config/application-secret.yml + echo "${{ secrets.APPLICATION_PROFILE_SECRET }}" > ${{ secrets.SERVER_APP_DIRECTORY }}/config/application-${ENVIRONMENT}.yml + + # 기존 컨테이너 중지 및 제거 + echo "" + echo "서비스 디렉토리로 이동합니다, 이전 위치: $(pwd)" + cd ${{ secrets.SERVER_APP_DIRECTORY }} + echo "서비스 디렉토리로 이동을 완료했습니다. 현재 위치: $(pwd)" + + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + echo "📥 Docker 이미지 Pull" + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + docker compose pull + + echo "🛑 기존 컨테이너 중지 중..." + docker compose down + + echo "🚀 새 컨테이너 시작 중..." + docker compose up -d --remove-orphans + + if [ $? -ne 0 ]; then + echo "❌ 컨테이너 시작 실패" + echo "" + echo "📋 컨테이너 로그:" + docker compose logs --tail=50 + exit 1 + fi + + echo "✅ 컨테이너가 성공적으로 시작되었습니다" + echo "" + + # 컨테이너 상태 확인 + echo "📊 컨테이너 상태:" + docker compose ps + echo "" + + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + echo "🎉 배포 완료!" + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + + - name: 📊 Deployment Summary + if: always() + run: | + echo "### 🚀 Deployment Summary" >> $GITHUB_STEP_SUMMARY + echo "" >> $GITHUB_STEP_SUMMARY + echo "| 항목 | 값 |" >> $GITHUB_STEP_SUMMARY + echo "|------|-----|" >> $GITHUB_STEP_SUMMARY + echo "| 🌍 Environment | \`${{ env.ENVIRONMENT }}\` |" >> $GITHUB_STEP_SUMMARY + echo "| 🌿 Branch | \`${{ github.ref_name }}\` |" >> $GITHUB_STEP_SUMMARY + echo "| 📝 Commit | \`${{ github.sha }}\` |" >> $GITHUB_STEP_SUMMARY + echo "| 📦 Image | \`${{ secrets.DOCKERHUB_REPOSITORY_NAME }}:${{ env.IMAGE_TAG }}\` |" >> $GITHUB_STEP_SUMMARY + echo "| 🖥️ Server | \`${{ secrets.SERVER_SSH_HOST }}\` |" >> $GITHUB_STEP_SUMMARY + echo "| 📁 Directory | \`${{ secrets.SERVER_APP_DIRECTORY }}\` |" >> $GITHUB_STEP_SUMMARY + echo "| ✅ Status | \`${{ job.status }}\` |" >> $GITHUB_STEP_SUMMARY + echo "" >> $GITHUB_STEP_SUMMARY + + if [[ "${{ job.status }}" == "success" ]]; then + echo "### ✅ 배포가 성공적으로 완료되었습니다!" >> $GITHUB_STEP_SUMMARY + else + echo "### ❌ 배포 중 오류가 발생했습니다." >> $GITHUB_STEP_SUMMARY + echo "로그를 확인해주세요." >> $GITHUB_STEP_SUMMARY + fi + + - name: ❌ 배포 실패 알림 + if: failure() + run: | + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + echo "❌ 배포 실패" + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + echo "환경: ${{ env.ENVIRONMENT }}" + echo "이미지: ${{ secrets.DOCKERHUB_REPOSITORY_NAME }}:${{ env.IMAGE_TAG }}" + echo "서버: ${{ secrets.SERVER_SSH_HOST }}" + echo "" + echo "::error::Deployment to ${{ env.ENVIRONMENT }} failed!" + echo "::error::Please check the deployment logs for details." + + # 3. Test 환경 스킵 알림 + skip-test-deployment: + needs: ci-and-build + if: needs.ci-and-build.outputs.environment == 'test' + runs-on: ubuntu-latest + steps: + - name: ℹ️ Test 환경 배포 스킵 + run: | + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + echo "ℹ️ Test 환경 배포 스킵" + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + echo "" + echo "Test 환경은 CI에서만 빌드하고 배포하지 않습니다." + echo "" + echo "✅ CI 빌드 완료" + echo "📦 이미지: ${{ secrets.DOCKERHUB_REPOSITORY_NAME }}:${{ needs.ci-and-build.outputs.image_tag }}" + echo "" + echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━" + + - name: 📊 Summary + run: | + echo "### ℹ️ Test Environment - Deployment Skipped" >> $GITHUB_STEP_SUMMARY + echo "" >> $GITHUB_STEP_SUMMARY + echo "Test 환경은 CI에서만 빌드하고 실제 배포는 수행하지 않습니다." >> $GITHUB_STEP_SUMMARY + echo "" >> $GITHUB_STEP_SUMMARY + echo "- ✅ **CI Build**: Completed" >> $GITHUB_STEP_SUMMARY + echo "- 📦 **Image**: \`${{ secrets.DOCKERHUB_REPOSITORY_NAME }}:${{ needs.ci-and-build.outputs.image_tag }}\`" >> $GITHUB_STEP_SUMMARY + echo "- 🚫 **Deployment**: Skipped" >> $GITHUB_STEP_SUMMARY diff --git a/docker/app/docker-compose.yml b/docker/app/docker-compose.yml new file mode 100644 index 00000000..85edcdd5 --- /dev/null +++ b/docker/app/docker-compose.yml @@ -0,0 +1,23 @@ +# 반드시 docker-compose.yml과 동일한 디렉토리에 .env가 존재해야 합니다. +# SpringBoot 설정들은 ./config 에! + +services: + app: + container_name: ${CONTAINER_NAME} + image: ${IMAGE_NAME}:${IMAGE_TAG} + restart: unless-stopped + ports: + - "${SERVICE_PORT:-8080}:8080" + - "${MANAGEMENT_PORT:-9090}:9090" + environment: + SPRING_PROFILES_ACTIVE: ${SPRING_PROFILES_ACTIVE} + volumes: + - ./config/application-secret.yml:/app/config/application-secret.yml:ro + - ./config/application-${SPRING_PROFILES_ACTIVE}.yml:/app/config/application-${SPRING_PROFILES_ACTIVE}.yml:ro + - ./logs:/app/logs + healthcheck: + test: [ "CMD", "curl", "-sf", "http://localhost:${MANAGEMENT_PORT:-9090}/actuator/health" ] + interval: 30s + timeout: 10s + retries: 3 + start_period: 60s From 401ea95b18e4264ebe6b7a383ec226df49083879 Mon Sep 17 00:00:00 2001 From: Kyeoungwoon Park Date: Fri, 9 Jan 2026 07:16:57 +0900 Subject: [PATCH 15/15] =?UTF-8?q?feat:=20CD=20self-hosted=20=EB=B3=80?= =?UTF-8?q?=EA=B2=BD?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .github/workflows/cd.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/cd.yml b/.github/workflows/cd.yml index 4c52c2a7..8fad3e3e 100644 --- a/.github/workflows/cd.yml +++ b/.github/workflows/cd.yml @@ -32,7 +32,7 @@ jobs: deploy: needs: ci-and-build if: needs.ci-and-build.outputs.environment != 'test' - runs-on: ubuntu-latest + runs-on: self-hosted # 빌드 단계에서 결정된 환경 사용 environment: ${{ needs.ci-and-build.outputs.environment }}