Files
dsh_ai1net_server/归档/迁移/域名迁移_ai1net_20260919/pending/relay-direct.ai1net.com.conf
T

52 lines
2.7 KiB
Plaintext
Raw Normal View History

# relay-direct.ai1net.com —— 覆盖网络 **443/TCP 兜底入口**(域名迁移版 · 2026-09-19 建立)
#
# 与 live 的 relay-direct.conf(alotbuy 版)**逐字同构**,只改三处:
# 1) server_name relay-direct.alotbuy.com → relay-direct.ai1net.com
# 2) 证书 复用 ai1net.com 那张(`*.ai1net.com` 已含本名 ⇒ ⛔ 不新增证书)
# 3) 引导目录端点 Host 改写 alotbuy.com → ai1net.com(必须与 DSHS_BASE_DOMAIN 同步!
# 平台先按 Host 做租户路由、再进路由表;用兜底子域直接回源会命中 404 unknown_user)
#
# ⛔ 零新增:不新增监听口(仍 443/TCP)、不新增证书、不新增域名/解析记录(`*.ai1net.com` 泛解析天然覆盖)。
# ✅ 暴露面只收窄:本块只承载下面两个端点,其余路径一律 404(不复制门户任何路径)。
#
# ⚠️ 状态:**待启用**。前置 = 证书 /etc/letsencrypt/live/ai1net.com/ 就绪。
# 维护:`nginx -t` 通过后再 `nginx -s reload`;回滚 = 删掉本文件后同两步。
#
# 🔴 cutover 连带项(同一批做,否则留半破状态):
# · relay-direct.conf(alotbuy 版)的 Host 改写也须由 alotbuy.com → ai1net.com
# · dsh.alotbuy.com.conf(旧域名 301 块)的 map 目标须由 <label>.alotbuy.com → <label>.ai1net.com
server {
listen 443 ssl;
http2 on; # ⚠️ 与门户一致;curl 验收必须带 --http1.1(否则假 404)
server_name relay-direct.ai1net.com;
ssl_certificate /etc/letsencrypt/live/ai1net.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/ai1net.com/privkey.pem;
# ── 中继入口(正文与门户块 /dshs-relay 逐字一致)──
location /dshs-relay {
proxy_pass http://127.0.0.1:20080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
proxy_buffering off;
}
# ── 引导目录端点(引导地址 = 中继入口同源;缺了它兜底入口拿不到签名目录)──
location = /dshs-overlay/bootstrap {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host ai1net.com;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_buffering off;
}
# ── 兜底:未知路径 404(可诊断;⛔ 不 return 444)──
location / { return 404; }
access_log /www/wwwlogs/relay-direct.ai1net.log;
error_log /www/wwwlogs/relay-direct.ai1net.error.log;
}