chore(docs): 文档库并入代码仓(R4 选 a)+ 索引/台账跟进

1) dsh-server-docs/ 从工作区(原 E:\...\aliyun-dsh-server\dsh-server-docs)**整体并入本仓**,
   保留目录名 ⇒ 仓库内 dsh-server-docs/... 的相对引用天然继续有效;旧目录(含其 .git)已归档到
   工作区 _中间产物_待清理/,未随本提交带入。
2) .gitattributes:新增 `dsh-server-docs/** -text` —— 原文档库是 `* -text` + autocrlf=false,
   必须保持纯 LF,否则会被本仓的 CRLF 规则翻掉。
3) 活引用里的绝对路径已全部改到新位置(docs 的 INDEX / README / scripts / skills + 用户级 skills
   + ~/.workbuddy/settings.json 的 hooks);历史档案(04-调整方案/、archive/)按「只增不改」未动。
   ⚠️ hooks 路径改动需「完全重启会话」才生效(配置是会话启动快照)。
4) 交接单/T08:新增 §16「生产整体切换执行记录」(形态 / 落地动作 / **4 个只有真上线才暴露的真 bug** /
   验收证据 / 回滚命令 / 残留项);台账 T08 行 → 已完成并归档;03-路线图 §二 登记 T08 收尾项。
5) 统一称谓:**「本机」只指跑 WorkBuddy 的开发机**,47 / 106 一律写「远程服务器」。
This commit is contained in:
admin committed 2026-09-15 18:47:13 +08:00
1 parent c70d5d860e
commit 5ad755116e
173 files changed
+27632

No files matched your search

+115
View File
@@ -0,0 +1,115 @@
# alotbuy.com —— DSH 平台站点(2026-09-10 建立,档案 21 场景延伸)
# 走 Cloudflare 代理(橙云),故:
# 1) 用 set_real_ip_from + CF-Connecting-IP 还原真实客户端 IP(否则日志/风控里全是 CF 的 IP)
# 2) 80 端口「代理」而非 301:CF 若为 Flexible,源站 301 会造成 CF 侧循环;改成代理两种模式都能用
# —— 但**必须**把 CF 的 SSL/TLS 模式设为 Full (Strict),否则 CF→源站是明文(凭据裸奔)
# 3) 继承 dsh 站点的关键优化:proxy_buffering off(流式)、gzip_proxied any(930KB bundle 压缩)
# ---- HTTP:代理(不用 301,兼容 CF Flexible;Full (Strict) 下 80 不会被用到)----
server {
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 80;
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
location / {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_read_timeout 3600s;
proxy_buffering off;
proxy_cache off;
gzip_proxied any;
}
access_log /www/wwwlogs/alotbuy.com.log;
error_log /www/wwwlogs/alotbuy.com.error.log;
}
# ---- HTTPS:门户 + 用户实例子域 ----
server {
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 443 ssl;
http2 on;
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
ssl_certificate /etc/letsencrypt/live/alotbuy.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/alotbuy.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_read_timeout 3600s;
# 流式(dsh 回复/思考逐块下发)+ 反代压缩 + 解除缓冲
proxy_buffering off;
proxy_cache off;
proxy_send_timeout 3600s;
gzip_proxied any;
}
# 内容哈希命名的静态资源 → 长缓存
location ~* ^/assets/ {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_buffering off;
gzip_proxied any;
expires 30d;
}
access_log /www/wwwlogs/alotbuy.com.log;
error_log /www/wwwlogs/alotbuy.com.error.log;
}
@@ -0,0 +1,24 @@
# dsh.alotbuy.com —— 旧域名(2026-09-10 平台迁移到 alotbuy.com 后仅做 301 跳转)
# 用 map + 通配 server_name(比正则 server_name 更稳),保留用户名映射:
# admin.dsh.alotbuy.com → admin.alotbuy.com
# dsh.alotbuy.com → alotbuy.com
# map 必须位于 http 上下文 —— 面板 vhost 文件正是被 include 在 http{} 内,故写在本文件顶层。
map $host $alotbuy_new_host {
default alotbuy.com;
~^(?<label>[^.]+)\.dsh\.alotbuy\.com$ $label.alotbuy.com;
}
server {
listen 80;
server_name dsh.alotbuy.com *.dsh.alotbuy.com;
return 301 https://$alotbuy_new_host$request_uri;
}
server {
listen 443 ssl;
server_name dsh.alotbuy.com *.dsh.alotbuy.com;
ssl_certificate /etc/letsencrypt/live/dsh.alotbuy.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/dsh.alotbuy.com/privkey.pem;
return 301 https://$alotbuy_new_host$request_uri;
}
@@ -0,0 +1,50 @@
#!/usr/bin/env bash
# 切换 DSH 平台服务域名 → alotbuy.com(2026-09-10)
# 幂等;带备份;drain 采用「按 pid 结束」而非 pkill -f(避免杀掉自身 ssh 会话)
set -euo pipefail
NEW_BASE=alotbuy.com
NEW_COOKIE=.alotbuy.com
ENV=/etc/dshs.env
TS=$(date +%Y%m%d-%H%M)
echo "=== 1) 备份 env ==="
cp -a "$ENV" "$ENV.bak-$TS"
echo " 备份: $ENV.bak-$TS"
echo "=== 2) 写入新域名 ==="
sed -i "s|^DSHS_BASE_DOMAIN=.*|DSHS_BASE_DOMAIN=$NEW_BASE|" "$ENV"
sed -i "s|^DSHS_COOKIE_DOMAIN=.*|DSHS_COOKIE_DOMAIN=$NEW_COOKIE|" "$ENV"
grep -E 'BASE_DOMAIN|COOKIE_DOMAIN' "$ENV" | sed 's/^/ /'
echo "=== 3) drain:停编排器 → 结束残留实例/scope → 起编排器 ==="
systemctl stop dshs
sleep 2
# 3a. 按 pid 结束 dsh 子进程(uid 形如 dsh-xxxx)
for pid in $(ps -eo pid,user,args | awk '$2 ~ /^dsh-/ {print $1}'); do
kill "$pid" 2>/dev/null || true
done
# 3b. 结束 bwrap 包装进程(用 grep 中括号技巧避免匹配自身)
for pid in $(ps -eo pid,args | grep "[b]wrap --ro-bind" | awk '{print $1}'); do
kill "$pid" 2>/dev/null || true
done
sleep 2
# 3c. 收尾残留 scope
systemctl list-units --type=scope --all --no-legend 'dsh-*' 2>/dev/null | awk '{print $1}' | while read -r u; do
[ -n "$u" ] && systemctl stop "$u" 2>/dev/null || true
done
sleep 1
echo " 残留实例数: $(ps -eo user,args | grep -c '[d]sh --profile' || true)"
echo "=== 4) 启动编排器 ==="
systemctl start dshs
sleep 3
echo " 服务: $(systemctl is-active dshs) / enabled=$(systemctl is-enabled dshs)"
echo " 编排器 pid: $(pgrep -f lib/cli.js | head -1)"
echo "=== 5) 自检 ==="
curl -sk -o /dev/null -w " 源站 https://alotbuy.com/login.html → %{http_code}\n" \
--resolve alotbuy.com:443:127.0.0.1 https://alotbuy.com/login.html
curl -s -o /dev/null -w " 经 CF https://alotbuy.com/login.html → %{http_code}\n" -m 15 \
https://alotbuy.com/login.html
echo " 完成(旧域名 301 见 dsh.alotbuy.com.conf)"