chore(工作区): 全量入库 + 补齐 .gitignore(以工作区为准)
- 变更规模:新增 514 / 修改 62 / 重命名 155 / 删除 4(归档重组与文档轮次) - .gitignore 修:`归档/**/db-cwd归一-备份-*/` —— 原规则写绝对层级(归档/db-cwd归一-…), 目录搬进 归档/配置与备份/ 后**静默失效**,43 MB 的 DB 备份又变成未跟踪 - .gitignore 补:嵌套 git 内部数据(归档/内嵌git-20261008/、归档/skills-git-旧线-20261007/dotgit-原样移出/) - .gitignore 补:运行态与部署副本(.workbuddy/collab/、.workbuddy/tools/、.workbuddy/.load-pending、.workbuddy/tmp-*) - .gitignore 补:备份件(*.bak-*) - 未跟踪文件从 2190 降到 890(其余为 归档/ 归档件与 .workbuddy/memory/ 知识文件,按口径入库)
This commit is contained in:
1 parent
30b46dbd0c
commit
c1b5e4d966
735 files changed
+153192
-2415
No files matched your search
@@ -0,0 +1,271 @@
|
||||
@@@@@ /www/server/panel/vhost/nginx/alotbuy.com.conf
|
||||
# alotbuy.com —— DSH 平台站点(2026-09-10 建立,档案 21 场景延伸)
|
||||
# 走 Cloudflare 代理(橙云),故:
|
||||
# 1) 用 set_real_ip_from + CF-Connecting-IP 还原真实客户端 IP(否则日志/风控里全是 CF 的 IP)
|
||||
# 2) 80 端口「代理」而非 301:CF 若为 Flexible,源站 301 会造成 CF 侧循环;改成代理两种模式都能用
|
||||
# —— 但**必须**把 CF 的 SSL/TLS 模式设为 Full (Strict),否则 CF→源站是明文(凭据裸奔)
|
||||
# 3) 继承 dsh 站点的关键优化:proxy_buffering off(流式)、gzip_proxied any(930KB bundle 压缩)
|
||||
|
||||
|
||||
# ---- HTTP:代理(不用 301,兼容 CF Flexible;Full (Strict) 下 80 不会被用到)----
|
||||
server {
|
||||
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
|
||||
set_real_ip_from 173.245.48.0/20;
|
||||
set_real_ip_from 103.21.244.0/22;
|
||||
set_real_ip_from 103.22.200.0/22;
|
||||
set_real_ip_from 103.31.4.0/22;
|
||||
set_real_ip_from 141.101.64.0/18;
|
||||
set_real_ip_from 108.162.192.0/18;
|
||||
set_real_ip_from 190.93.240.0/20;
|
||||
set_real_ip_from 188.114.96.0/20;
|
||||
set_real_ip_from 197.234.240.0/22;
|
||||
set_real_ip_from 198.41.128.0/17;
|
||||
set_real_ip_from 162.158.0.0/15;
|
||||
set_real_ip_from 104.16.0.0/13;
|
||||
set_real_ip_from 104.24.0.0/14;
|
||||
set_real_ip_from 172.64.0.0/13;
|
||||
set_real_ip_from 131.0.72.0/22;
|
||||
set_real_ip_from 2400:cb00::/32;
|
||||
set_real_ip_from 2606:4700::/32;
|
||||
set_real_ip_from 2803:f800::/32;
|
||||
set_real_ip_from 2405:b500::/32;
|
||||
set_real_ip_from 2405:8100::/32;
|
||||
set_real_ip_from 2a06:98c0::/29;
|
||||
set_real_ip_from 2c0f:f248::/32;
|
||||
real_ip_header CF-Connecting-IP;
|
||||
listen 80;
|
||||
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
|
||||
# 2026-09-13:3 个跳转桩页已删除(档案 80 第 7 项 / 档案 81 §四)—— 保留 301 防旧书签 404
|
||||
location = /desktop.html { return 301 /portal.html; }
|
||||
location = /plugins.html { return 301 /portal.html#/plugins; }
|
||||
location = /skills.html { return 301 /portal.html#/skills; }
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:3080;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
proxy_read_timeout 3600s;
|
||||
proxy_buffering off;
|
||||
proxy_cache off;
|
||||
gzip_proxied any;
|
||||
}
|
||||
access_log /www/wwwlogs/alotbuy.com.log;
|
||||
error_log /www/wwwlogs/alotbuy.com.error.log;
|
||||
}
|
||||
|
||||
# ---- HTTPS:门户 + 用户实例子域 ----
|
||||
server {
|
||||
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
|
||||
set_real_ip_from 173.245.48.0/20;
|
||||
set_real_ip_from 103.21.244.0/22;
|
||||
set_real_ip_from 103.22.200.0/22;
|
||||
set_real_ip_from 103.31.4.0/22;
|
||||
set_real_ip_from 141.101.64.0/18;
|
||||
set_real_ip_from 108.162.192.0/18;
|
||||
set_real_ip_from 190.93.240.0/20;
|
||||
set_real_ip_from 188.114.96.0/20;
|
||||
set_real_ip_from 197.234.240.0/22;
|
||||
set_real_ip_from 198.41.128.0/17;
|
||||
set_real_ip_from 162.158.0.0/15;
|
||||
set_real_ip_from 104.16.0.0/13;
|
||||
set_real_ip_from 104.24.0.0/14;
|
||||
set_real_ip_from 172.64.0.0/13;
|
||||
set_real_ip_from 131.0.72.0/22;
|
||||
set_real_ip_from 2400:cb00::/32;
|
||||
set_real_ip_from 2606:4700::/32;
|
||||
set_real_ip_from 2803:f800::/32;
|
||||
set_real_ip_from 2405:b500::/32;
|
||||
set_real_ip_from 2405:8100::/32;
|
||||
set_real_ip_from 2a06:98c0::/29;
|
||||
set_real_ip_from 2c0f:f248::/32;
|
||||
real_ip_header CF-Connecting-IP;
|
||||
listen 443 ssl;
|
||||
http2 on;
|
||||
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
|
||||
ssl_certificate /etc/letsencrypt/live/alotbuy.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/alotbuy.com/privkey.pem;
|
||||
|
||||
# 2026-09-13:3 个跳转桩页已删除(档案 80 第 7 项 / 档案 81 §四)—— 保留 301 防旧书签 404
|
||||
location = /desktop.html { return 301 /portal.html; }
|
||||
location = /plugins.html { return 301 /portal.html#/plugins; }
|
||||
location = /skills.html { return 301 /portal.html#/skills; }
|
||||
# ── DSH 覆盖网络中继(自研 relay)────────────────────────────────
|
||||
# 只在既有 443 server 块里加一个 location:不新增监听口、不新增证书、不动门户其它路径。
|
||||
# `/status` 不在此前缀下 ⇒ 不会被代理出去(relay 端也只认 RELAY_PATH 前缀)。
|
||||
location /dshs-relay {
|
||||
proxy_pass http://127.0.0.1:20080;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
proxy_set_header Host $host;
|
||||
proxy_read_timeout 3600s;
|
||||
proxy_send_timeout 3600s;
|
||||
proxy_buffering off;
|
||||
}
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:3080;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
proxy_read_timeout 3600s;
|
||||
# 流式(dsh 回复/思考逐块下发)+ 反代压缩 + 解除缓冲
|
||||
proxy_buffering off;
|
||||
proxy_cache off;
|
||||
proxy_send_timeout 3600s;
|
||||
gzip_proxied any;
|
||||
}
|
||||
# 内容哈希命名的静态资源 → 长缓存
|
||||
location ~* ^/assets/ {
|
||||
proxy_pass http://127.0.0.1:3080;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_http_version 1.1;
|
||||
proxy_buffering off;
|
||||
gzip_proxied any;
|
||||
expires 30d;
|
||||
}
|
||||
access_log /www/wwwlogs/alotbuy.com.log;
|
||||
error_log /www/wwwlogs/alotbuy.com.error.log;
|
||||
}
|
||||
@@@@@ /www/server/panel/vhost/nginx/dsh.alotbuy.com.conf
|
||||
# dsh.alotbuy.com —— 旧域名(2026-09-10 平台迁移到 alotbuy.com 后仅做 301 跳转)
|
||||
# 用 map + 通配 server_name(比正则 server_name 更稳),保留用户名映射:
|
||||
# admin.dsh.alotbuy.com → admin.alotbuy.com
|
||||
# dsh.alotbuy.com → alotbuy.com
|
||||
# map 必须位于 http 上下文 —— 面板 vhost 文件正是被 include 在 http{} 内,故写在本文件顶层。
|
||||
|
||||
map $host $alotbuy_new_host {
|
||||
default alotbuy.com;
|
||||
~^(?<label>[^.]+)\.dsh\.alotbuy\.com$ $label.alotbuy.com;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 80;
|
||||
server_name dsh.alotbuy.com *.dsh.alotbuy.com;
|
||||
return 301 https://$alotbuy_new_host$request_uri;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name dsh.alotbuy.com *.dsh.alotbuy.com;
|
||||
ssl_certificate /etc/letsencrypt/live/dsh.alotbuy.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/dsh.alotbuy.com/privkey.pem;
|
||||
return 301 https://$alotbuy_new_host$request_uri;
|
||||
}
|
||||
@@@@@ /www/server/panel/vhost/nginx/relay-direct.conf
|
||||
# relay-direct.alotbuy.com —— 覆盖网络 **443/TCP 兜底入口**(序④ · L2「去门户站点 conf」)
|
||||
#
|
||||
# 为什么要有这个块(而不是往门户块里再加一条 location):
|
||||
# 门户块 `/www/server/panel/vhost/nginx/alotbuy.com.conf` 由宝塔面板管理 —— 面板重写配置、
|
||||
# 或人工改坏它,都会**同时**打掉门户与 relay 入口(两者共用一个失败域)。
|
||||
# 独立 `server_name` ⇒ 本入口与门户块**互不影响**(nginx 精确名优先于 `*.alotbuy.com` 通配)。
|
||||
#
|
||||
# ⛔ 零新增:不新增监听口(仍 443/TCP)、不新增证书(复用 `*.alotbuy.com` 那张)、
|
||||
# 不新增域名/解析记录(`*.alotbuy.com` 泛解析天然覆盖本名)、不新增花费、不新增依赖。
|
||||
# ⛔ 不碰门户 443 块、不碰 relay 进程(relay 仍是 `127.0.0.1:20080` 的纯 `ws://`,TLS 由 nginx 终结)。
|
||||
# ✅ 暴露面**只收窄**:本块只承载下面两个端点,其余路径一律 404(不把门户任何路径复制过来)。
|
||||
#
|
||||
# 维护:`nginx -t` 通过后再 `nginx -s reload`;回滚 = 删掉本文件后同两步。
|
||||
# 变更记录:2026-09-17 建立(交接单_443兜底_20260917.md §5 S1)。
|
||||
|
||||
server {
|
||||
listen 443 ssl;
|
||||
http2 on; # ⚠️ 与门户一致;curl 验收必须带 --http1.1(否则假 404)
|
||||
server_name relay-direct.alotbuy.com;
|
||||
ssl_certificate /etc/letsencrypt/live/alotbuy.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/alotbuy.com/privkey.pem;
|
||||
|
||||
# ── 中继入口(正文与门户块 `/dshs-relay` 逐字一致,只改 server_name / 证书两处变量)──
|
||||
location /dshs-relay {
|
||||
proxy_pass http://127.0.0.1:20080;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
proxy_set_header Host $host;
|
||||
proxy_read_timeout 3600s;
|
||||
proxy_send_timeout 3600s;
|
||||
proxy_buffering off;
|
||||
}
|
||||
|
||||
# ── 引导目录端点(约定「引导地址 = 中继入口同源」;缺了它兜底入口拿不到签名目录)──
|
||||
# 只放行这一个路径(`=` 精确匹配)—— 目录端点只有这一个(`directory.ts` 的 DIRECTORY_PATH)。
|
||||
#
|
||||
# ⚠️ `Host` 必须改写成既有目录 origin:平台(3080)**先按 Host 做租户路由、再进路由表**,
|
||||
# 直接用兜底子域回源会命中 `404 {"error":"unknown_user"}`(实测 2026-09-17 09:00)。
|
||||
# 这是「同源」在入口层的等价翻译 —— 发的就是门户今天在发的同一个请求,**不扩大任何权限**
|
||||
# (本 location 只放行这一个公开只读路由;本块其余路径一律 404)。
|
||||
location = /dshs-overlay/bootstrap {
|
||||
proxy_pass http://127.0.0.1:3080;
|
||||
proxy_set_header Host alotbuy.com;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_http_version 1.1;
|
||||
proxy_buffering off;
|
||||
}
|
||||
|
||||
# ── 兜底:本块**只**承载上面两个端点。未知路径 404(可诊断;⛔ 不 return 444,
|
||||
# 444 是「这个域名不存在」的语义,会让"路径写错"看起来像"域名没配")──
|
||||
location / { return 404; }
|
||||
|
||||
# 说明:本块**故意不复制**门户块的 `set_real_ip_from` 那一组 —— 本块只服务两个机器端点,
|
||||
# 不依赖客户端 IP(无 ACL / 无限速 / 无风控);日志里出现 CF 回源 IP 不影响可诊断性。
|
||||
access_log /www/wwwlogs/relay-direct.log;
|
||||
error_log /www/wwwlogs/relay-direct.error.log;
|
||||
}
|
||||
@@@@@ 查找 dsh 用户名映射文件
|
||||
2:# 用 map + 通配 server_name(比正则 server_name 更稳),保留用户名映射:
|
||||
5:# map 必须位于 http 上下文 —— 面板 vhost 文件正是被 include 在 http{} 内,故写在本文件顶层。
|
||||
7:map $host $alotbuy_new_host {
|
||||
@@@@@ worker/env 文件清单
|
||||
-rw------- 1 root root 684 Sep 13 15:46 /etc/dshs.env
|
||||
-rw------- 1 root root 529 Sep 17 08:17 /etc/dshs-worker.env
|
||||
--- systemctl cat dshs-worker ---
|
||||
# /etc/systemd/system/dshs-worker.service
|
||||
[Unit]
|
||||
Description=DSHS cluster worker agent (this host = 47, local users' instances)
|
||||
After=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
EnvironmentFile=/etc/dshs-worker.env
|
||||
ExecStart=/usr/local/bin/node /opt/dshs/lib/cli.js worker --port 19100 --host 127.0.0.1 --host-id w-47 --instance-host 127.0.0.1 --log-level info
|
||||
Restart=on-failure
|
||||
RestartSec=3
|
||||
KillMode=mixed
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
--- systemctl cat dshs-relay ---
|
||||
# /etc/systemd/system/dshs-relay.service
|
||||
[Unit]
|
||||
Description=dshs relay (loopback-only WebSocket relay for the DSH overlay network)
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
WorkingDirectory=/opt/dsh-relay
|
||||
ExecStart=/usr/local/bin/node /opt/dsh-relay/lib/net/relay/main.js --port 20080 --keys-file /etc/dshs/relay-keys.json --base 19000 --span 3000 --max-hosts 0
|
||||
Restart=always
|
||||
RestartSec=1
|
||||
TimeoutStopSec=5
|
||||
StandardOutput=journal
|
||||
StandardError=journal
|
||||
SyslogIdentifier=dshs-relay
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
|
||||
# /etc/systemd/system/dshs-relay.service.d/40-content-probe.conf
|
||||
# 覆盖网络 序㉔(2026-09-17):内容面**活性自证** —— relay 侧块级内容寻址的判据落点。
|
||||
#
|
||||
# 背景:`OBS-17` 第三个判据要求 `local + peer` 命中 ≥ `CONTENT_TIER_HITS_MIN`(=1)。
|
||||
@@@@@ 两机 SEEDS/RELAY env 命中
|
||||
Reference in new issue
Block a user