# 在应用机本机 mysqld 上创建空库 inquiry_robot(表稍后 Flyway)。 # 口令:优先 E:\wwwroot\ops\.mysql_root_stash.tmp,否则尝试现网 application-database-credentials.json 中的 mysql_password。 # 不向 stdout 打印任何口令。副作用:改 E:\wwwroot\.env 的 MYSQL/PG HOST 为 127.0.0.1。 $ErrorActionPreference = "Stop" $mysql = "C:\yutongda\tools\mysql-8.0.39-winx64\bin\mysql.exe" $psql = "C:\yutongda\tools\pgsql\bin\psql.exe" $secrets = Get-Content "E:\wwwroot\ops\inquiry_robot_db_secrets.json" -Raw | ConvertFrom-Json $dbCred = Get-Content "C:\yutongda\secure\application-database-credentials.json" -Raw | ConvertFrom-Json function Test-MysqlRoot([string]$pass) { if ([string]::IsNullOrWhiteSpace($pass)) { return $false } $out = & $mysql -h 127.0.0.1 -P 3306 -u root "-p$pass" --connect-timeout=8 -e "SELECT 'root_ok' AS r" 2>&1 | Out-String return ($out -match "root_ok") } Write-Output "=== resolve local mysql root ===" $rootPass = $null $stash = "E:\wwwroot\ops\.mysql_root_stash.tmp" if (Test-Path $stash) { $candidate = (Get-Content $stash -Raw).Trim() if (Test-MysqlRoot $candidate) { $rootPass = $candidate Write-Output ("root_from=stash len=" + $rootPass.Length) } } if (-not $rootPass) { $candidate = [string]$dbCred.mysql_password if (Test-MysqlRoot $candidate) { $rootPass = $candidate Write-Output ("root_from=app_db_cred.mysql_password len=" + $rootPass.Length) Set-Content -Path $stash -Value $rootPass -Encoding ascii -NoNewline } } if (-not $rootPass) { # 再试 postgres 口令等同机复用(少数环境) $candidate = [string]$dbCred.postgres_password if (Test-MysqlRoot $candidate) { $rootPass = $candidate Write-Output ("root_from=app_db_cred.postgres_password len=" + $rootPass.Length) Set-Content -Path $stash -Value $rootPass -Encoding ascii -NoNewline } } if (-not $rootPass) { throw "local mysql root auth failed" } Write-Output "MYSQL_ROOT_OK" $mysqlPass = [string]$secrets.mysql_password if ([string]::IsNullOrWhiteSpace($mysqlPass)) { throw "missing inquiry_robot mysql_password in secrets json" } # 写临时 SQL,避免 PowerShell 对反引号/括号的解析问题 $sqlPath = "E:/wwwroot/ops/sql/_run_create_inquiry_robot_mysql.sql" $sql = @" CREATE DATABASE IF NOT EXISTS ``inquiry_robot`` DEFAULT CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci; CREATE USER IF NOT EXISTS 'inquiry_robot'@'localhost' IDENTIFIED BY '$mysqlPass'; CREATE USER IF NOT EXISTS 'inquiry_robot'@'127.0.0.1' IDENTIFIED BY '$mysqlPass'; CREATE USER IF NOT EXISTS 'inquiry_robot'@'%' IDENTIFIED BY '$mysqlPass'; ALTER USER 'inquiry_robot'@'localhost' IDENTIFIED BY '$mysqlPass'; ALTER USER 'inquiry_robot'@'127.0.0.1' IDENTIFIED BY '$mysqlPass'; ALTER USER 'inquiry_robot'@'%' IDENTIFIED BY '$mysqlPass'; GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'localhost'; GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'127.0.0.1'; GRANT ALL PRIVILEGES ON ``inquiry_robot``.* TO 'inquiry_robot'@'%'; FLUSH PRIVILEGES; SELECT 'mysql_create_ok' AS s; "@ Set-Content -Path $sqlPath -Value $sql -Encoding ascii Write-Output "=== create empty MySQL DB/user ===" $createOut = & $mysql -h 127.0.0.1 -P 3306 -u root "-p$rootPass" --connect-timeout=15 -e "source $sqlPath" 2>&1 | Out-String $createOut -split "`r?`n" | ForEach-Object { if ($_ -match 'Using a password|IDENTIFIED BY') { return } if ($_ -match 'password') { return } $_ } if ($createOut -notmatch "mysql_create_ok") { throw "mysql create failed" } Write-Output "=== smoke as inquiry_robot ===" $smoke = & $mysql -h 127.0.0.1 -P 3306 -u inquiry_robot "-p$mysqlPass" --connect-timeout=8 inquiry_robot -e "SELECT 'mysql_app_ok' AS s; SHOW TABLES;" 2>&1 | Out-String $smoke -split "`r?`n" | ForEach-Object { if ($_ -match 'Using a password') { return } $_ } if ($smoke -notmatch "mysql_app_ok") { throw "mysql app smoke failed" } Write-Output "MYSQL_CREATED_OK" Write-Output "=== confirm PG app user ===" $env:PGPASSWORD = [string]$secrets.pg_password $pgSmoke = & $psql -h 127.0.0.1 -p 5432 -U inquiry_robot_runtime -d inquiry_robot_runtime -tAc "SELECT 'pg_app_ok'" 2>&1 Write-Output ("PG=" + (($pgSmoke | ForEach-Object {"$_"}) -join " ")) if (($pgSmoke | Out-String) -notmatch "pg_app_ok") { throw "pg app smoke failed" } Remove-Item Env:PGPASSWORD -ErrorAction SilentlyContinue Write-Output "=== patch .env hosts to 127.0.0.1 ===" $envPath = "E:\wwwroot\.env" $lines = Get-Content $envPath $out = foreach ($line in $lines) { if ($line -match '^MYSQL_HOST=') { 'MYSQL_HOST=127.0.0.1' } elseif ($line -match '^PG_HOST=') { 'PG_HOST=127.0.0.1' } elseif ($line -match '^YTD_MYSQL_URL=') { 'YTD_MYSQL_URL=jdbc:mysql://127.0.0.1:3306/inquiry_robot?characterEncoding=UTF-8&useUnicode=true&useSSL=false&allowPublicKeyRetrieval=true&tinyInt1isBit=false&serverTimezone=Asia/Shanghai' } elseif ($line -match '^MYSQL_PASSWORD=') { "MYSQL_PASSWORD=$($secrets.mysql_password)" } elseif ($line -match '^PG_PASSWORD=') { "PG_PASSWORD=$($secrets.pg_password)" } else { $line } } Set-Content $envPath -Value $out -Encoding UTF8 if (Test-Path "E:\wwwroot\agent\current") { Copy-Item $envPath "E:\wwwroot\agent\current\.env" -Force } # 清理含明文口令的临时 SQL(secrets 已在 json/.env) Remove-Item $sqlPath -Force -ErrorAction SilentlyContinue $status = @{ mysqlHost = "127.0.0.1" mysqlDb = "inquiry_robot" mysqlCreated = $true pgHost = "127.0.0.1" pgDb = "inquiry_robot_runtime" pgCreated = $true note = "Empty DBs on APP-SERVER local mysqld/postgres (C:\yutongda\tools), not 10.206.0.14. Tables via Flyway later." updatedAt = (Get-Date).ToString("o") needDba = $false } | ConvertTo-Json Set-Content "E:\wwwroot\ops\data-plane-status.json" -Value $status -Encoding UTF8 Write-Output $status Write-Output "CREATE_ALL_DONE"