feat(config): 涉密内容外置到配置目录(档案 140)
把散落在代码里的真实部署值统一收进 config/,代码改为引用配置, 使仓库副本/开源导出不再带出生产域名、IP、内网路径与凭据。 新增 config/:platform.env.example(模板)· load.sh(shell 加载器)· index.cjs(node 加载器)· README.md(键一览与优先级)。 真实值放 config/platform.env —— 已 .gitignore 排除,不入库、不进导出。 TS 侧新增 src/platform-paths.ts 作部署路径的唯一解析处(零副作用): platformDir/stateDir/backupDir/artifactDir/installDir/scriptPath。 config.ts 接入这些字段;内置中继种子由生产 URL 改为空(改由 DSHS_OVERLAY_BOOTSTRAP_SEEDS 提供)。修掉 5 处硬编码绝对路径, src/** 注释中性化 116 行/53 文件。 scripts/** 36 个内部运维脚本:真令牌/PG 口令/隧道目标/主机号/路径 一律改从配置取;web/wake.html 的注册域白名单改为运行时从 location.hostname 推导;test/** 夹具 119 行/13 文件改 RFC 2606/5737 保留值,并把「内置种子必须为空」固化为回归断言。 取证:tsc 0 错;npm test 373/375(唯一失败 lease 属既有); 全仓扫描(大小写不敏感)代码面涉密标识 = 0;已部署 47 并零回归 (/opt/dsh/* 未搬家,/var/lib/dshs/platform 未被误建)。
This commit is contained in:
1 parent
9c2e7975ac
commit
452924d89c
100 files changed
+1167
-453
No files matched your search
+15
-15
@@ -9,8 +9,8 @@
|
||||
*
|
||||
* | hostId | dsh_hosts.endpoint(2026-09-16 实测) | 真实语义 |
|
||||
* |---|---|---|
|
||||
* | `w-106` | `http://127.0.0.1:19000` | 经 47 上 sshd 的反向隧道落点 |
|
||||
* | `w-47` | `http://127.0.0.1:19100` | 同机直连(node 自己监听) |
|
||||
* | `w-2` | `http://127.0.0.1:19000` | 经 47 上 sshd 的反向隧道落点 |
|
||||
* | `w-1` | `http://127.0.0.1:19100` | 同机直连(node 自己监听) |
|
||||
*/
|
||||
import { test } from 'node:test'
|
||||
import assert from 'node:assert/strict'
|
||||
@@ -27,8 +27,8 @@ import { LocalRendezvous, ManagerSshRendezvous, RendezvousRegistry } from '../li
|
||||
|
||||
/** 现网真实两条(2026-09-16 在 47 上 `SELECT id, endpoint FROM dsh_hosts` 实测)。 */
|
||||
const LIVE_HOSTS = [
|
||||
{ hostId: 'w-106', endpoint: 'http://127.0.0.1:19000', via: VIA_MANAGER_SSH },
|
||||
{ hostId: 'w-47', endpoint: 'http://127.0.0.1:19100', via: VIA_LOCAL },
|
||||
{ hostId: 'w-2', endpoint: 'http://127.0.0.1:19000', via: VIA_MANAGER_SSH },
|
||||
{ hostId: 'w-1', endpoint: 'http://127.0.0.1:19100', via: VIA_LOCAL },
|
||||
]
|
||||
|
||||
test('S0 等价性:旧 agentUrl 取址与可达性取址逐字相等', () => {
|
||||
@@ -75,9 +75,9 @@ test('parseReachability:https / 裸 host:port / 尾斜杠 三种兼容面', ()
|
||||
|
||||
test('可达性优先于旧 agentUrl', () => {
|
||||
const host = {
|
||||
hostId: 'w-106',
|
||||
hostId: 'w-2',
|
||||
agentUrl: 'http://stale.example:1',
|
||||
reachability: { hostId: 'w-106', via: VIA_MANAGER_SSH, address: '127.0.0.1:19000', scheme: 'http' },
|
||||
reachability: { hostId: 'w-2', via: VIA_MANAGER_SSH, address: '127.0.0.1:19000', scheme: 'http' },
|
||||
}
|
||||
assert.equal(agentBaseUrlOf(host), 'http://127.0.0.1:19000')
|
||||
})
|
||||
@@ -88,31 +88,31 @@ test('两者皆缺 ⇒ 抛错(禁止静默打到空地址)', () => {
|
||||
})
|
||||
|
||||
test('LocalRendezvous:命中给 local,未命中回 undefined 不抛', async () => {
|
||||
const table = new Map([['w-47', '127.0.0.1:19100']])
|
||||
const table = new Map([['w-1', '127.0.0.1:19100']])
|
||||
const rv = new LocalRendezvous((id) => table.get(id))
|
||||
assert.equal(rv.id, VIA_LOCAL)
|
||||
assert.equal(rv.dialTarget(), '(direct)')
|
||||
assert.deepEqual(await rv.resolve('w-47'), {
|
||||
hostId: 'w-47',
|
||||
assert.deepEqual(await rv.resolve('w-1'), {
|
||||
hostId: 'w-1',
|
||||
networkId: 'ops',
|
||||
via: VIA_LOCAL,
|
||||
address: '127.0.0.1:19100',
|
||||
scheme: 'http',
|
||||
})
|
||||
assert.equal(await rv.resolve('w-106'), undefined)
|
||||
assert.equal(await rv.resolve('w-2'), undefined)
|
||||
})
|
||||
|
||||
test('ManagerSshRendezvous:解析出的基址必须等于现网 endpoint(S2 迁移判据)', async () => {
|
||||
const table = new Map([
|
||||
['w-106', '127.0.0.1:19000'],
|
||||
['w-47', '127.0.0.1:19100'],
|
||||
['w-2', '127.0.0.1:19000'],
|
||||
['w-1', '127.0.0.1:19100'],
|
||||
])
|
||||
const rv = new ManagerSshRendezvous({
|
||||
target: 'root@47.77.182.89:32022',
|
||||
target: 'root@203.0.113.10:32022',
|
||||
addressOf: (id) => table.get(id),
|
||||
})
|
||||
assert.equal(rv.id, VIA_MANAGER_SSH)
|
||||
assert.equal(rv.dialTarget(), 'root@47.77.182.89:32022')
|
||||
assert.equal(rv.dialTarget(), 'root@203.0.113.10:32022')
|
||||
for (const h of LIVE_HOSTS) {
|
||||
const resolved = await rv.resolve(h.hostId)
|
||||
assert.equal(agentBaseUrl(resolved), h.endpoint, `${h.hostId} 迁移后基址变了`)
|
||||
@@ -142,7 +142,7 @@ test('S2:via → Rendezvous → Reachability 后取址与旧 agentUrl 逐条
|
||||
const hostAddresses = new Map()
|
||||
const rendezvous = new RendezvousRegistry([
|
||||
new LocalRendezvous((id) => hostAddresses.get(id)),
|
||||
new ManagerSshRendezvous({ target: 'ssh://root@47.77.182.89:32022', addressOf: (id) => hostAddresses.get(id) }),
|
||||
new ManagerSshRendezvous({ target: 'ssh://root@203.0.113.10:32022', addressOf: (id) => hostAddresses.get(id) }),
|
||||
])
|
||||
// hostsProvider 第一遍:同步地址表
|
||||
for (const row of rows) {
|
||||
|
||||
Reference in new issue
Block a user