Files
dsh_ai1net_server/归档/域名迁移_ai1net_20260919/vhosts_dump.txt
T
admin ce8e6ceed9 chore(工作区): 纳入版本控制基线(回收 411 MB 过程产物)
回收 411 MB(470 M → 58.8 M),全部经回收站,可恢复:
- 待清理/(146.2 M,含 relay 分片 128 M 与 42 项过程目录)
- tmp/(32.4 M,按接续棒命名的过程临时区)
- .workbuddy/tmp/(39.5 M)
- 4 份 workbuddy.db 冗余副本(101 M,09-23 事故的坏副本 / 抢救产物)
- tmp/im16/gw/centrifugo 二进制(63.9 M,可重下)+ 缓存残留

入库范围:常驻规则(CODEBUDDY.md / README.md / state.py)、在途接续入口与
接续包、docs/、交付物/、交接单/、归档/、scripts/、.codebuddy/、
.workbuddy/memory/;共 398 件,其中 >60 KB 的 26 件全为文档。

排除(.gitignore):tmp/、待清理/、运行态日志与缓存、*.db 与 DB 备份整目录、
打包二进制(*.tar.gz / *.tgz)、记忆修复前备份。
2026-09-24 07:51:03 +08:00

272 lines
12 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
@@@@@ /www/server/panel/vhost/nginx/alotbuy.com.conf
# alotbuy.com —— DSH 平台站点(2026-09-10 建立,档案 21 场景延伸)
# 走 Cloudflare 代理(橙云),故:
# 1) 用 set_real_ip_from + CF-Connecting-IP 还原真实客户端 IP(否则日志/风控里全是 CF 的 IP)
# 2) 80 端口「代理」而非 301:CF 若为 Flexible,源站 301 会造成 CF 侧循环;改成代理两种模式都能用
# —— 但**必须**把 CF 的 SSL/TLS 模式设为 Full (Strict),否则 CF→源站是明文(凭据裸奔)
# 3) 继承 dsh 站点的关键优化:proxy_buffering off(流式)、gzip_proxied any(930KB bundle 压缩)
# ---- HTTP:代理(不用 301,兼容 CF Flexible;Full (Strict) 下 80 不会被用到)----
server {
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 80;
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
# 2026-09-13:3 个跳转桩页已删除(档案 80 第 7 项 / 档案 81 §四)—— 保留 301 防旧书签 404
location = /desktop.html { return 301 /portal.html; }
location = /plugins.html { return 301 /portal.html#/plugins; }
location = /skills.html { return 301 /portal.html#/skills; }
location / {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_read_timeout 3600s;
proxy_buffering off;
proxy_cache off;
gzip_proxied any;
}
access_log /www/wwwlogs/alotbuy.com.log;
error_log /www/wwwlogs/alotbuy.com.error.log;
}
# ---- HTTPS:门户 + 用户实例子域 ----
server {
# CF 回源 IP → 还原真实客户端 IP(仅本 server 生效)
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
listen 443 ssl;
http2 on;
server_name alotbuy.com www.alotbuy.com *.alotbuy.com;
ssl_certificate /etc/letsencrypt/live/alotbuy.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/alotbuy.com/privkey.pem;
# 2026-09-13:3 个跳转桩页已删除(档案 80 第 7 项 / 档案 81 §四)—— 保留 301 防旧书签 404
location = /desktop.html { return 301 /portal.html; }
location = /plugins.html { return 301 /portal.html#/plugins; }
location = /skills.html { return 301 /portal.html#/skills; }
# ── DSH 覆盖网络中继(自研 relay)────────────────────────────────
# 只在既有 443 server 块里加一个 location:不新增监听口、不新增证书、不动门户其它路径。
# `/status` 不在此前缀下 ⇒ 不会被代理出去(relay 端也只认 RELAY_PATH 前缀)。
location /dshs-relay {
proxy_pass http://127.0.0.1:20080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
proxy_buffering off;
}
location / {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_read_timeout 3600s;
# 流式(dsh 回复/思考逐块下发)+ 反代压缩 + 解除缓冲
proxy_buffering off;
proxy_cache off;
proxy_send_timeout 3600s;
gzip_proxied any;
}
# 内容哈希命名的静态资源 → 长缓存
location ~* ^/assets/ {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_buffering off;
gzip_proxied any;
expires 30d;
}
access_log /www/wwwlogs/alotbuy.com.log;
error_log /www/wwwlogs/alotbuy.com.error.log;
}
@@@@@ /www/server/panel/vhost/nginx/dsh.alotbuy.com.conf
# dsh.alotbuy.com —— 旧域名(2026-09-10 平台迁移到 alotbuy.com 后仅做 301 跳转)
# 用 map + 通配 server_name(比正则 server_name 更稳),保留用户名映射:
# admin.dsh.alotbuy.com → admin.alotbuy.com
# dsh.alotbuy.com → alotbuy.com
# map 必须位于 http 上下文 —— 面板 vhost 文件正是被 include 在 http{} 内,故写在本文件顶层。
map $host $alotbuy_new_host {
default alotbuy.com;
~^(?<label>[^.]+)\.dsh\.alotbuy\.com$ $label.alotbuy.com;
}
server {
listen 80;
server_name dsh.alotbuy.com *.dsh.alotbuy.com;
return 301 https://$alotbuy_new_host$request_uri;
}
server {
listen 443 ssl;
server_name dsh.alotbuy.com *.dsh.alotbuy.com;
ssl_certificate /etc/letsencrypt/live/dsh.alotbuy.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/dsh.alotbuy.com/privkey.pem;
return 301 https://$alotbuy_new_host$request_uri;
}
@@@@@ /www/server/panel/vhost/nginx/relay-direct.conf
# relay-direct.alotbuy.com —— 覆盖网络 **443/TCP 兜底入口**(序④ · L2「去门户站点 conf」)
#
# 为什么要有这个块(而不是往门户块里再加一条 location):
# 门户块 `/www/server/panel/vhost/nginx/alotbuy.com.conf` 由宝塔面板管理 —— 面板重写配置、
# 或人工改坏它,都会**同时**打掉门户与 relay 入口(两者共用一个失败域)。
# 独立 `server_name` ⇒ 本入口与门户块**互不影响**(nginx 精确名优先于 `*.alotbuy.com` 通配)。
#
# ⛔ 零新增:不新增监听口(仍 443/TCP)、不新增证书(复用 `*.alotbuy.com` 那张)、
# 不新增域名/解析记录(`*.alotbuy.com` 泛解析天然覆盖本名)、不新增花费、不新增依赖。
# ⛔ 不碰门户 443 块、不碰 relay 进程(relay 仍是 `127.0.0.1:20080` 的纯 `ws://`,TLS 由 nginx 终结)。
# ✅ 暴露面**只收窄**:本块只承载下面两个端点,其余路径一律 404(不把门户任何路径复制过来)。
#
# 维护:`nginx -t` 通过后再 `nginx -s reload`;回滚 = 删掉本文件后同两步。
# 变更记录:2026-09-17 建立(交接单_443兜底_20260917.md §5 S1)。
server {
listen 443 ssl;
http2 on; # ⚠️ 与门户一致;curl 验收必须带 --http1.1(否则假 404)
server_name relay-direct.alotbuy.com;
ssl_certificate /etc/letsencrypt/live/alotbuy.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/alotbuy.com/privkey.pem;
# ── 中继入口(正文与门户块 `/dshs-relay` 逐字一致,只改 server_name / 证书两处变量)──
location /dshs-relay {
proxy_pass http://127.0.0.1:20080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
proxy_buffering off;
}
# ── 引导目录端点(约定「引导地址 = 中继入口同源」;缺了它兜底入口拿不到签名目录)──
# 只放行这一个路径(`=` 精确匹配)—— 目录端点只有这一个(`directory.ts` 的 DIRECTORY_PATH)。
#
# ⚠️ `Host` 必须改写成既有目录 origin:平台(3080)**先按 Host 做租户路由、再进路由表**,
# 直接用兜底子域回源会命中 `404 {"error":"unknown_user"}`(实测 2026-09-17 09:00)。
# 这是「同源」在入口层的等价翻译 —— 发的就是门户今天在发的同一个请求,**不扩大任何权限**
# (本 location 只放行这一个公开只读路由;本块其余路径一律 404)。
location = /dshs-overlay/bootstrap {
proxy_pass http://127.0.0.1:3080;
proxy_set_header Host alotbuy.com;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_http_version 1.1;
proxy_buffering off;
}
# ── 兜底:本块**只**承载上面两个端点。未知路径 404(可诊断;⛔ 不 return 444,
# 444 是「这个域名不存在」的语义,会让"路径写错"看起来像"域名没配")──
location / { return 404; }
# 说明:本块**故意不复制**门户块的 `set_real_ip_from` 那一组 —— 本块只服务两个机器端点,
# 不依赖客户端 IP(无 ACL / 无限速 / 无风控);日志里出现 CF 回源 IP 不影响可诊断性。
access_log /www/wwwlogs/relay-direct.log;
error_log /www/wwwlogs/relay-direct.error.log;
}
@@@@@ 查找 dsh 用户名映射文件
2:# 用 map + 通配 server_name(比正则 server_name 更稳),保留用户名映射:
5:# map 必须位于 http 上下文 —— 面板 vhost 文件正是被 include 在 http{} 内,故写在本文件顶层。
7:map $host $alotbuy_new_host {
@@@@@ worker/env 文件清单
-rw------- 1 root root 684 Sep 13 15:46 /etc/dshs.env
-rw------- 1 root root 529 Sep 17 08:17 /etc/dshs-worker.env
--- systemctl cat dshs-worker ---
# /etc/systemd/system/dshs-worker.service
[Unit]
Description=DSHS cluster worker agent (this host = 47, local users' instances)
After=network-online.target
[Service]
Type=simple
EnvironmentFile=/etc/dshs-worker.env
ExecStart=/usr/local/bin/node /opt/dshs/lib/cli.js worker --port 19100 --host 127.0.0.1 --host-id w-47 --instance-host 127.0.0.1 --log-level info
Restart=on-failure
RestartSec=3
KillMode=mixed
[Install]
WantedBy=multi-user.target
--- systemctl cat dshs-relay ---
# /etc/systemd/system/dshs-relay.service
[Unit]
Description=dshs relay (loopback-only WebSocket relay for the DSH overlay network)
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/dsh-relay
ExecStart=/usr/local/bin/node /opt/dsh-relay/lib/net/relay/main.js --port 20080 --keys-file /etc/dshs/relay-keys.json --base 19000 --span 3000 --max-hosts 0
Restart=always
RestartSec=1
TimeoutStopSec=5
StandardOutput=journal
StandardError=journal
SyslogIdentifier=dshs-relay
[Install]
WantedBy=multi-user.target
# /etc/systemd/system/dshs-relay.service.d/40-content-probe.conf
# 覆盖网络 序㉔(2026-09-17):内容面**活性自证** —— relay 侧块级内容寻址的判据落点。
#
# 背景:`OBS-17` 第三个判据要求 `local + peer` 命中 ≥ `CONTENT_TIER_HITS_MIN`(=1)。
@@@@@ 两机 SEEDS/RELAY env 命中