Files
dsh_ai1net_server/归档/域名迁移_ai1net_20260919/pending/ai1net.com.conf
T
admin ce8e6ceed9 chore(工作区): 纳入版本控制基线(回收 411 MB 过程产物)
回收 411 MB(470 M → 58.8 M),全部经回收站,可恢复:
- 待清理/(146.2 M,含 relay 分片 128 M 与 42 项过程目录)
- tmp/(32.4 M,按接续棒命名的过程临时区)
- .workbuddy/tmp/(39.5 M)
- 4 份 workbuddy.db 冗余副本(101 M,09-23 事故的坏副本 / 抢救产物)
- tmp/im16/gw/centrifugo 二进制(63.9 M,可重下)+ 缓存残留

入库范围:常驻规则(CODEBUDDY.md / README.md / state.py)、在途接续入口与
接续包、docs/、交付物/、交接单/、归档/、scripts/、.codebuddy/、
.workbuddy/memory/;共 398 件,其中 >60 KB 的 26 件全为文档。

排除(.gitignore):tmp/、待清理/、运行态日志与缓存、*.db 与 DB 备份整目录、
打包二进制(*.tar.gz / *.tgz)、记忆修复前备份。
2026-09-24 07:51:03 +08:00

156 lines
6.7 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# ai1net.com —— DSH 平台站点(2026-09-19 建立:域名 alotbuy.com → ai1net.com 迁移)
# 本文件与 alotbuy.com.conf **逐字同构**,只改三处:域名、证书路径、ACME 挑战落点。
# 1) 走 Cloudflare 代理(橙云)⇒ 必须 Full (strict):CF→源站证书须覆盖该主机名,否则 526
# 2) 80 端口「代理」而非 301:CF 若为 Flexible,源站 301 会造成 CF 侧循环
# 3) set_real_ip_from + CF-Connecting-IP 还原真实客户端 IP
# 4) proxy_buffering off(流式)+ gzip_proxied any(930KB bundle 压缩)
#
# ⚠️ 状态:**待启用**。启用前置 = 证书 /etc/letsencrypt/live/ai1net.com/{fullchain,privkey}.pem
# 存在(SAN 含 ai1net.com + *.ai1net.com)。证书未就绪前启用本文件 ⇒ nginx 起不来 ⇒ 门户全挂。
#
# 🔴 前置(2026-09-19 复验结论,⛔ 别照旧说"必须切 Full(strict)"):
# https 访客:CF→源站**已是 HTTPS 且在校验证书**(`https://ai1net.com` 现报 526 = 该校验的产物
# ⇒ zone 本已是 **Full (strict)**;Flexible 下 https 访客会 200 而不是 526)⇒ **无需再改模式**。
# http 访客:CF→源站走 **HTTP:80**(实测标记文件可经 http 取回)⇒ 与 alotbuy 的真实差别只在
# 「**Always Use HTTPS**」未开。⚠️ 未开时经 http 访问本块 = 明文回源
# ⇒ 建议在 CF 开启 Always Use HTTPS(边缘 301 掉),开启后源站 80 永不被用到(与 alotbuy 一致)。
# ---- HTTP:代理(不用 301,兼容 CF Flexible;Full (Strict) 下 80 不会被用到)----
server {
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 80;
server_name ai1net.com www.ai1net.com *.ai1net.com;
# ── ACME 挑战(http-01 续期用;`^~` 优先于下面的 `location /`)──
# 2026-09-19:本域名走 DNS-01 签发,但保留 webroot 落点 ⇒ 两条路都能续期,且回滚不掉链。
location ^~ /.well-known/acme-challenge/ {
root /www/server/nginx/html;
default_type text/plain;
access_log off;
}
location = /desktop.html { return 301 /portal.html; }
location = /plugins.html { return 301 /portal.html#/plugins; }
location = /skills.html { return 301 /portal.html#/skills; }
location / {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_read_timeout 3600s;
proxy_buffering off;
proxy_cache off;
gzip_proxied any;
}
access_log /www/wwwlogs/ai1net.com.log;
error_log /www/wwwlogs/ai1net.com.error.log;
}
# ---- HTTPS:门户 + 用户实例子域(<user>.ai1net.com)----
server {
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 443 ssl;
http2 on;
server_name ai1net.com www.ai1net.com *.ai1net.com;
ssl_certificate /etc/letsencrypt/live/ai1net.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/ai1net.com/privkey.pem;
location ^~ /.well-known/acme-challenge/ {
root /www/server/nginx/html;
default_type text/plain;
access_log off;
}
location = /desktop.html { return 301 /portal.html; }
location = /plugins.html { return 301 /portal.html#/plugins; }
location = /skills.html { return 301 /portal.html#/skills; }
# ── DSH 覆盖网络中继(自研 relay)—— 与门户块 alotbuy.com.conf 逐字一致 ──
location /dshs-relay {
proxy_pass http://127.0.0.1:20080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
proxy_buffering off;
}
location / {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_read_timeout 3600s;
proxy_buffering off;
proxy_cache off;
proxy_send_timeout 3600s;
gzip_proxied any;
}
# 内容哈希命名的静态资源 → 长缓存
location ~* ^/assets/ {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_buffering off;
gzip_proxied any;
expires 30d;
}
access_log /www/wwwlogs/ai1net.com.log;
error_log /www/wwwlogs/ai1net.com.error.log;
}