set +e echo "=== [S1] /etc/cloudflare.ini 存在性与键名(值不打印) ===" ls -l /etc/cloudflare.ini 2>/dev/null grep -oE '^[a-zA-Z_]+' /etc/cloudflare.ini 2>/dev/null | sort -u | tr '\n' ' '; echo echo "=== [S2] 该令牌能看到的 zone(只报名字与 id 前 8 位) ===" python3 - <<'PY' 2>&1 | head -20 import configparser, json, urllib.request cp = configparser.ConfigParser() try: cp.read('/etc/cloudflare.ini') sec = cp['dns_cloudflare'] if cp.has_section('dns_cloudflare') else cp[cp.sections()[0]] d = dict(sec) except Exception as e: print('读取失败:', e); raise SystemExit tok = d.get('dns_cloudflare_api_token') email = d.get('dns_cloudflare_email') key = d.get('dns_cloudflare_api_key') print('凭据形态: token' if tok else ('key+email' if key else '未知')) def call(path): url = 'https://api.cloudflare.com/client/v4' + path req = urllib.request.Request(url) if tok is not None: req.add_header('Authorization', 'Bearer ' + tok) else: req.add_header('X-Auth-Email', email or '') req.add_header('X-Auth-Key', key or '') try: with urllib.request.urlopen(req, timeout=20) as r: return json.loads(r.read().decode()) except Exception as e: return {'error': str(e)} r = call('/zones?per_page=50') if 'result' in r: zs = r['result'] print('可管理 zone 数 =', len(zs)) for z in zs[:20]: print(' -', z['name'], z['id'][:8], z.get('status')) names = {z['name'] for z in zs} print('含 ai1net.com ?', 'ai1net.com' in names) print('含 alotbuy.com ?', 'alotbuy.com' in names) else: print('查询结果:', json.dumps(r)[:200]) PY echo "=== [S3] dsh.alotbuy.com 证书 SAN ===" openssl x509 -in /etc/letsencrypt/live/dsh.alotbuy.com/fullchain.pem -noout -ext subjectAltName 2>/dev/null | tr ',' '\n' | head -8 echo "=== [S4] certbot 版本 & 是否可非交互 ===" certbot --version 2>&1 | head -1 echo "=== [S5] nginx -t 基线 ===" nginx -t 2>&1 | tail -1