chore(仓库对齐): 文档库结构治理 + IM/插件线落地
build / build-and-scan (push) Canceled after 0s

文档库:目录改为编号制(01-规范/02-架构设计/03-数据库/04-调整方案/
05-交接单/06-ops/07-scripts/08-skills/09-archive),顶层散文件归入 01-规范/;
INDEX.md 与 docs-manifest.json 重刷(档案 146 篇);旧目录名引用全量对齐。

IM 线:src/im/**(SDK / hub / store / presence / ws / gateway-token)、
src/web/routes/im.ts、src/db/plugin-data/**、src/supervisor/plugin-assembly.ts
及对应 test/**。

插件线:poc/{im-agent-bridge,im-connection-gateway,im-conversation-tabs,
business-plugins-im,carbon-mcp-probe}、src/web/routes/{sessions,overlay-device}.ts、
src/net/relay/{device-grant,instance-credential}.ts。

仓库卫生:清出 40 个历史误入库 / 已改名文件(34 个交接单归档 + 6 个旧结构,
本地均有副本);dsh-server-docs/.gitignore 补 tmp/;交接单不入库(政策)。
This commit is contained in:
admin committed 2026-09-24 07:25:16 +08:00
1 parent 3d8f50e366
commit e6207aa691
239 files changed
+34477 -14633

No files matched your search

@@ -0,0 +1,148 @@
# alotbuy.com —— 旧域(2026-09-10 建立为门户站点;**2026-09-19 降级为 301 过渡装置**)
#
# 为什么"降级"而不是"删除"(判据见 04-调整方案/135):
# ① 老书签 / 外链不 404(301 到新域**同名子域**,保留用户名映射)
# ② 已入网节点的**旧域中继入口**仍可透传 ⇒ 不断线(见下方保留的 location)
# ③ 软回滚路径保留:`cp alotbuy.com.conf.bak-dompurge-<ts> alotbuy.com.conf && nginx -t && nginx -s reload`
# ⛔ 退役条件 = **旧域 30 天访问量为 0**(看 /www/wwwlogs/alotbuy.com.log)→ 连
# `dsh.alotbuy.com.conf`、`relay-direct.conf` 一并删。
#
# 唯三**不** 301 的路径(其余一律 301 到新域):
# /dshs-relay → 127.0.0.1:20080(自研 relay WebSocket;旧域入口,SEEDS 已不再引导)
# /dshs-overlay/bootstrap → 127.0.0.1:3080(覆盖网络目录只读路由)
# /.well-known/acme-challenge/(ACME 落点,续期不掉链)
#
# map 必须位于 http 上下文 —— 面板 vhost 文件正是被 include 在 http{} 内,故写在本文件顶层。
# ⚠️ 与 `dsh.alotbuy.com.conf` 的 map 是**两个不同变量名**,不冲突;
# `*.dsh.alotbuy.com` 由那个文件**更长的通配 server_name** 接管,不进本文件的 map。
# ⚠️ 301 目标是**不同主机**(ai1net.com,CF 侧已是 Full(strict))⇒ 不存在"源站 301 造成 CF 循环"。
# 故 80 端口可以直接 301(原门户块当年为兼容 CF Flexible 才用代理)。
map $host $alotbuy_301_host {
default ai1net.com;
~^(?<lb301>[^.]+)\.alotbuy\.com$ $lb301.ai1net.com;
}
# ---- HTTP:301 到新域(旧域不再承载门户)----
server {
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 80;
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
# ── ACME 挑战(续期用;`^~` 优先于下面的 `location /`)──
location ^~ /.well-known/acme-challenge/ {
root /www/server/nginx/html;
default_type text/plain;
access_log off;
}
# ── 覆盖网络中继(保留:已入网节点仍可能持旧域地址)──
location /dshs-relay {
proxy_pass http://127.0.0.1:20080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
proxy_buffering off;
}
location = /dshs-overlay/bootstrap {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_buffering off;
}
location / { return 301 https://$alotbuy_301_host$request_uri; }
access_log /www/wwwlogs/alotbuy.com.log;
error_log /www/wwwlogs/alotbuy.com.error.log;
}
# ---- HTTPS:301 到新域(同上)----
server {
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 443 ssl;
http2 on;
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
ssl_certificate /etc/letsencrypt/live/alotbuy.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/alotbuy.com/privkey.pem;
location ^~ /.well-known/acme-challenge/ {
root /www/server/nginx/html;
default_type text/plain;
access_log off;
}
# ── 覆盖网络中继(保留)──
location /dshs-relay {
proxy_pass http://127.0.0.1:20080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
proxy_buffering off;
}
location = /dshs-overlay/bootstrap {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_buffering off;
}
location / { return 301 https://$alotbuy_301_host$request_uri; }
access_log /www/wwwlogs/alotbuy.com.log;
error_log /www/wwwlogs/alotbuy.com.error.log;
}
@@ -0,0 +1,24 @@
# dsh.alotbuy.com —— 旧域名(2026-09-10 平台迁移到 alotbuy.com 后仅做 301 跳转)
# 用 map + 通配 server_name(比正则 server_name 更稳),保留用户名映射:
# admin.dsh.alotbuy.com → admin.alotbuy.com
# dsh.alotbuy.com → alotbuy.com
# map 必须位于 http 上下文 —— 面板 vhost 文件正是被 include 在 http{} 内,故写在本文件顶层。
map $host $alotbuy_new_host {
default alotbuy.com;
~^(?<label>[^.]+)\.dsh\.alotbuy\.com$ $label.alotbuy.com;
}
server {
listen 80;
server_name dsh.alotbuy.com *.dsh.alotbuy.com;
return 301 https://$alotbuy_new_host$request_uri;
}
server {
listen 443 ssl;
server_name dsh.alotbuy.com *.dsh.alotbuy.com;
ssl_certificate /etc/letsencrypt/live/dsh.alotbuy.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/dsh.alotbuy.com/privkey.pem;
return 301 https://$alotbuy_new_host$request_uri;
}
@@ -0,0 +1,50 @@
#!/usr/bin/env bash
# 切换 DSH 平台服务域名 → alotbuy.com(2026-09-10)
# 幂等;带备份;drain 采用「按 pid 结束」而非 pkill -f(避免杀掉自身 ssh 会话)
set -euo pipefail
NEW_BASE=alotbuy.com
NEW_COOKIE=.alotbuy.com
ENV=/etc/dshs.env
TS=$(date +%Y%m%d-%H%M)
echo "=== 1) 备份 env ==="
cp -a "$ENV" "$ENV.bak-$TS"
echo " 备份: $ENV.bak-$TS"
echo "=== 2) 写入新域名 ==="
sed -i "s|^DSHS_BASE_DOMAIN=.*|DSHS_BASE_DOMAIN=$NEW_BASE|" "$ENV"
sed -i "s|^DSHS_COOKIE_DOMAIN=.*|DSHS_COOKIE_DOMAIN=$NEW_COOKIE|" "$ENV"
grep -E 'BASE_DOMAIN|COOKIE_DOMAIN' "$ENV" | sed 's/^/ /'
echo "=== 3) drain:停编排器 → 结束残留实例/scope → 起编排器 ==="
systemctl stop dshs
sleep 2
# 3a. 按 pid 结束 dsh 子进程(uid 形如 dsh-xxxx)
for pid in $(ps -eo pid,user,args | awk '$2 ~ /^dsh-/ {print $1}'); do
kill "$pid" 2>/dev/null || true
done
# 3b. 结束 bwrap 包装进程(用 grep 中括号技巧避免匹配自身)
for pid in $(ps -eo pid,args | grep "[b]wrap --ro-bind" | awk '{print $1}'); do
kill "$pid" 2>/dev/null || true
done
sleep 2
# 3c. 收尾残留 scope
systemctl list-units --type=scope --all --no-legend 'dsh-*' 2>/dev/null | awk '{print $1}' | while read -r u; do
[ -n "$u" ] && systemctl stop "$u" 2>/dev/null || true
done
sleep 1
echo " 残留实例数: $(ps -eo user,args | grep -c '[d]sh --profile' || true)"
echo "=== 4) 启动编排器 ==="
systemctl start dshs
sleep 3
echo " 服务: $(systemctl is-active dshs) / enabled=$(systemctl is-enabled dshs)"
echo " 编排器 pid: $(pgrep -f lib/cli.js | head -1)"
echo "=== 5) 自检 ==="
curl -sk -o /dev/null -w " 源站 https://alotbuy.com/login.html → %{http_code}\n" \
--resolve alotbuy.com:443:127.0.0.1 https://alotbuy.com/login.html
curl -s -o /dev/null -w " 经 CF https://alotbuy.com/login.html → %{http_code}\n" -m 15 \
https://alotbuy.com/login.html
echo " 完成(旧域名 301 见 dsh.alotbuy.com.conf)"