diff --git a/bbs-go-active/docker-compose.yml b/bbs-go-active/docker-compose.yml index 82d4741..198ba1b 100644 --- a/bbs-go-active/docker-compose.yml +++ b/bbs-go-active/docker-compose.yml @@ -32,7 +32,7 @@ services: dockerfile: Dockerfile context: ./ volumes: - - /data/docker-active:/data + - /data/bbsfiles/active:/data environment: BBSGO_ENV: docker BBSGO_DB_URL: root:123456@tcp(bbs-go-mysql-active:3306)/bbsgo_db?charset=utf8mb4&parseTime=True&multiStatements=true&loc=Local diff --git a/bbs-go-active/server/bbs-go.docker.yaml b/bbs-go-active/server/bbs-go.docker.yaml index c7fe233..a9b2c03 100644 --- a/bbs-go-active/server/bbs-go.docker.yaml +++ b/bbs-go-active/server/bbs-go.docker.yaml @@ -19,7 +19,7 @@ DB: # 上传配置 Uploader: - Enable: aliyunOss + Enable: Local AliyunOss: Host: Bucket: @@ -33,8 +33,8 @@ Uploader: StyleDetail: detail # 本地文件上传 Local: - Host: https://st.mlog.club/ # 上传文件域名 - Path: /data/www/st.mlog.club # 上传目录 + Host: https://image.deepseak.icu/ # 上传文件域名 + Path: /data/activefiles # 上传目录 # 邮件服务器配置,用于邮件通知 Smtp: diff --git a/bbs-go/docker-compose.yml b/bbs-go/docker-compose.yml index 3a6b192..1e6c37f 100644 --- a/bbs-go/docker-compose.yml +++ b/bbs-go/docker-compose.yml @@ -32,7 +32,7 @@ services: dockerfile: Dockerfile context: ./ volumes: - - /data/docker:/data + - /data/bbsfiles/bbs:/data environment: BBSGO_ENV: docker BBSGO_DB_URL: root:123456@tcp(bbs-go-mysql:3306)/bbsgo_db?charset=utf8mb4&parseTime=True&multiStatements=true&loc=Local diff --git a/bbs-go/server/bbs-go.docker.yaml b/bbs-go/server/bbs-go.docker.yaml index a829fd5..b135c9a 100644 --- a/bbs-go/server/bbs-go.docker.yaml +++ b/bbs-go/server/bbs-go.docker.yaml @@ -19,7 +19,7 @@ DB: # 上传配置 Uploader: - Enable: aliyunOss + Enable: Local AliyunOss: Host: Bucket: @@ -33,8 +33,8 @@ Uploader: StyleDetail: detail # 本地文件上传 Local: - Host: https://st.mlog.club/ # 上传文件域名 - Path: /data/www/st.mlog.club # 上传目录 + Host: https://image.deepseak.icu/ # 上传文件域名 + Path: /data/bbsfiles # 上传目录 # 邮件服务器配置,用于邮件通知 Smtp: diff --git a/file-server/Dockerfile b/file-server/Dockerfile new file mode 100644 index 0000000..218eb27 --- /dev/null +++ b/file-server/Dockerfile @@ -0,0 +1,23 @@ +# 构建阶段 +FROM swr.cn-north-4.myhuaweicloud.com/ddn-k8s/docker.io/library/golang:1.24 AS builder + +WORKDIR /app +COPY . . + +# 添加静态编译和优化参数 +RUN CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build \ + -ldflags="-w -s -extldflags '-static'" \ + -o file-server + +RUN ls -alh . + +# 使用最小基础镜像 +FROM swr.cn-north-4.myhuaweicloud.com/ddn-k8s/docker.io/library/alpine:latest +WORKDIR /app + +# 复制二进制文件并设置权限 +COPY --from=builder --chmod=0755 /app/file-server . + +EXPOSE 8080 + +CMD ["./file-server"] \ No newline at end of file diff --git a/file-server/docker-compose.yml b/file-server/docker-compose.yml new file mode 100644 index 0000000..b6eaa03 --- /dev/null +++ b/file-server/docker-compose.yml @@ -0,0 +1,12 @@ +version: '3.8' + +services: + file-server: + build: + context: . + dockerfile: Dockerfile + ports: + - "3004:8080" + volumes: + - /data/bbsfiles:/files + restart: unless-stopped \ No newline at end of file diff --git a/file-server/go.mod b/file-server/go.mod new file mode 100644 index 0000000..c06e8ff --- /dev/null +++ b/file-server/go.mod @@ -0,0 +1,3 @@ +module fileserver + +go 1.23.4 diff --git a/file-server/main.go b/file-server/main.go new file mode 100644 index 0000000..4ae2d74 --- /dev/null +++ b/file-server/main.go @@ -0,0 +1,62 @@ +package main + +import ( + + "fmt" + "log" + "net/http" + "os" + "path/filepath" + "strings" +) + +func main() { + // 硬编码目录配置 + dirs := map[string]string{ + "/bbs": "/files/active/www/active", // 修改右侧路径 + "/active": "/files/bbs/www/bbs", // 添加新条目 + } + + port := 8080 // 固定端口 + mux := http.NewServeMux() + + // 注册所有目录路由 + for prefix, path := range dirs { + absPath, err := filepath.Abs(path) + if err != nil { + log.Fatalf("目录[%s]解析失败: %v", path, err) + } + + if err := os.MkdirAll(absPath, 0755); err != nil { + log.Fatalf("创建目录[%s]失败: %v", absPath, err) + } + + fileServer := secureFileServer(http.Dir(absPath)) + mux.Handle(prefix+"/", http.StripPrefix(prefix, fileServer)) + log.Printf("已挂载目录: %s => %s", prefix, absPath) + } + + // 启动服务器 + serverAddr := fmt.Sprintf(":%d", port) + log.Printf("文件服务器启动在 http://localhost%s", serverAddr) + + if err := http.ListenAndServe(serverAddr, mux); err != nil { + log.Fatalf("服务器启动失败: %v", err) + } +} + +// 安全检查中间件 +func secureFileServer(root http.FileSystem) http.Handler { + return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { + if strings.Contains(r.URL.Path, "..") { + http.Error(w, "无效的路径", http.StatusBadRequest) + return + } + + w.Header().Set("X-Content-Type-Options", "nosniff") + w.Header().Set("X-Frame-Options", "DENY") + w.Header().Set("X-XSS-Protection", "1; mode=block") + + http.FileServer(root).ServeHTTP(w, r) + }) +} \ No newline at end of file diff --git a/nginx/tailscale.conf b/nginx/tailscale.conf new file mode 100644 index 0000000..ddaa696 --- /dev/null +++ b/nginx/tailscale.conf @@ -0,0 +1,27 @@ +server { + listen 30080; + server_name localhost; + + location / { + # 代理配置 + proxy_pass http://localhost:3008; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + + # 跨域配置 + add_header 'Access-Control-Allow-Origin' '*' always; + add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, OPTIONS' always; + add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range' always; + add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range' always; + + # 处理 OPTIONS 请求 + if ($request_method = 'OPTIONS') { + add_header 'Access-Control-Max-Age' 1728000; + add_header 'Content-Type' 'text/plain; charset=utf-8'; + add_header 'Content-Length' 0; + return 204; + } + } +} diff --git a/nginx/updateConfig.sh b/nginx/updateConfig.sh index 2f0c894..08f24c1 100644 --- a/nginx/updateConfig.sh +++ b/nginx/updateConfig.sh @@ -1,14 +1,18 @@ #!/bin/bash -# 备份并覆盖配置文件 -cp /etc/nginx/nginx.conf /etc/nginx/nginx.conf.bak -cp nginx.conf /etc/nginx/ +# 备份并覆盖所有.conf配置文件 +for conf in *.conf; do + cp "/etc/nginx/$conf" "/etc/nginx/${conf}.bak" 2>/dev/null || true + cp "$conf" /etc/nginx/ +done # 测试并重载配置 if nginx -t; then systemctl reload nginx echo "配置已生效,HTTPS已启用" else - echo "配置测试失败,已恢复备份" - cp /etc/nginx/nginx.conf.bak /etc/nginx/nginx.conf -fi + echo "配置测试失败,正在恢复所有备份" + for conf in *.conf; do + mv -f "/etc/nginx/${conf}.bak" "/etc/nginx/$conf" 2>/dev/null || true + done +fi \ No newline at end of file diff --git a/tailscale/config.yaml b/tailscale/config.yaml new file mode 100644 index 0000000..44037fe --- /dev/null +++ b/tailscale/config.yaml @@ -0,0 +1,404 @@ +--- +# headscale will look for a configuration file named `config.yaml` (or `config.json`) in the following order: +# +# - `/etc/headscale` +# - `~/.headscale` +# - current working directory + +# The url clients will connect to. +# Typically this will be a domain like: +# +# https://myheadscale.example.com:443 +# +server_url: http://0.0.0.0:8080 + +# Address to listen to / bind to on the server +# +# For production: +listen_addr: 0.0.0.0:8080 +#isten_addr: 127.0.0.1:8080 + +# Address to listen to /metrics, you may want +# to keep this endpoint private to your internal +# network +# +metrics_listen_addr: 127.0.0.1:9090 + +# Address to listen for gRPC. +# gRPC is used for controlling a headscale server +# remotely with the CLI +# Note: Remote access _only_ works if you have +# valid certificates. +# +# For production: +grpc_listen_addr: 0.0.0.0:50443 +#rpc_listen_addr: 127.0.0.1:50443 + +# Allow the gRPC admin interface to run in INSECURE +# mode. This is not recommended as the traffic will +# be unencrypted. Only enable if you know what you +# are doing. +grpc_allow_insecure: false + +# The Noise section includes specific configuration for the +# TS2021 Noise protocol +noise: + # The Noise private key is used to encrypt the + # traffic between headscale and Tailscale clients when + # using the new Noise-based protocol. + private_key_path: /var/lib/headscale/noise_private.key + +# List of IP prefixes to allocate tailaddresses from. +# Each prefix consists of either an IPv4 or IPv6 address, +# and the associated prefix length, delimited by a slash. +# It must be within IP ranges supported by the Tailscale +# client - i.e., subnets of 100.64.0.0/10 and fd7a:115c:a1e0::/48. +# See below: +# IPv6: https://github.com/tailscale/tailscale/blob/22ebb25e833264f58d7c3f534a8b166894a89536/net/tsaddr/tsaddr.go#LL81C52-L81C71 +# IPv4: https://github.com/tailscale/tailscale/blob/22ebb25e833264f58d7c3f534a8b166894a89536/net/tsaddr/tsaddr.go#L33 +# Any other range is NOT supported, and it will cause unexpected issues. +prefixes: + v4: 100.64.0.0/10 + v6: fd7a:115c:a1e0::/48 + + # Strategy used for allocation of IPs to nodes, available options: + # - sequential (default): assigns the next free IP from the previous given IP. + # - random: assigns the next free IP from a pseudo-random IP generator (crypto/rand). + allocation: sequential + +# DERP is a relay system that Tailscale uses when a direct +# connection cannot be established. +# https://tailscale.com/blog/how-tailscale-works/#encrypted-tcp-relays-derp +# +# headscale needs a list of DERP servers that can be presented +# to the clients. +derp: + server: + # If enabled, runs the embedded DERP server and merges it into the rest of the DERP config + # The Headscale server_url defined above MUST be using https, DERP requires TLS to be in place + enabled: true + + # Region ID to use for the embedded DERP server. + # The local DERP prevails if the region ID collides with other region ID coming from + # the regular DERP config. + region_id: 999 + + # Region code and name are displayed in the Tailscale UI to identify a DERP region + region_code: "headscale" + region_name: "Headscale Embedded DERP" + + # Listens over UDP at the configured address for STUN connections - to help with NAT traversal. + # When the embedded DERP server is enabled stun_listen_addr MUST be defined. + # + # For more details on how this works, check this great article: https://tailscale.com/blog/how-tailscale-works/ + stun_listen_addr: "0.0.0.0:3478" + + # Private key used to encrypt the traffic between headscale DERP + # and Tailscale clients. + # The private key file will be autogenerated if it's missing. + # + private_key_path: /var/lib/headscale/derp_server_private.key + + # This flag can be used, so the DERP map entry for the embedded DERP server is not written automatically, + # it enables the creation of your very own DERP map entry using a locally available file with the parameter DERP.paths + # If you enable the DERP server and set this to false, it is required to add the DERP server to the DERP map using DERP.paths + automatically_add_embedded_derp_region: true + + # For better connection stability (especially when using an Exit-Node and DNS is not working), + # it is possible to optionally add the public IPv4 and IPv6 address to the Derp-Map using: + ipv4: 1.2.3.4 + ipv6: 2001:db8::1 + + # List of externally available DERP maps encoded in JSON + urls: + - https://controlplane.tailscale.com/derpmap/default + + # Locally available DERP map files encoded in YAML + # + # This option is mostly interesting for people hosting + # their own DERP servers: + # https://tailscale.com/kb/1118/custom-derp-servers/ + # + # paths: + # - /etc/headscale/derp-example.yaml + paths: [] + + # If enabled, a worker will be set up to periodically + # refresh the given sources and update the derpmap + # will be set up. + auto_update_enabled: true + + # How often should we check for DERP updates? + update_frequency: 24h + +# Disables the automatic check for headscale updates on startup +disable_check_updates: false + +# Time before an inactive ephemeral node is deleted? +ephemeral_node_inactivity_timeout: 30m + +database: + # Database type. Available options: sqlite, postgres + # Please note that using Postgres is highly discouraged as it is only supported for legacy reasons. + # All new development, testing and optimisations are done with SQLite in mind. + type: sqlite + + # Enable debug mode. This setting requires the log.level to be set to "debug" or "trace". + debug: false + + # GORM configuration settings. + gorm: + # Enable prepared statements. + prepare_stmt: true + + # Enable parameterized queries. + parameterized_queries: true + + # Skip logging "record not found" errors. + skip_err_record_not_found: true + + # Threshold for slow queries in milliseconds. + slow_threshold: 1000 + + # SQLite config + sqlite: + path: /var/lib/headscale/db.sqlite + + # Enable WAL mode for SQLite. This is recommended for production environments. + # https://www.sqlite.org/wal.html + write_ahead_log: true + + # Maximum number of WAL file frames before the WAL file is automatically checkpointed. + # https://www.sqlite.org/c3ref/wal_autocheckpoint.html + # Set to 0 to disable automatic checkpointing. + wal_autocheckpoint: 1000 + + # # Postgres config + # Please note that using Postgres is highly discouraged as it is only supported for legacy reasons. + # See database.type for more information. + # postgres: + # # If using a Unix socket to connect to Postgres, set the socket path in the 'host' field and leave 'port' blank. + # host: localhost + # port: 5432 + # name: headscale + # user: foo + # pass: bar + # max_open_conns: 10 + # max_idle_conns: 10 + # conn_max_idle_time_secs: 3600 + + # # If other 'sslmode' is required instead of 'require(true)' and 'disabled(false)', set the 'sslmode' you need + # # in the 'ssl' field. Refers to https://www.postgresql.org/docs/current/libpq-ssl.html Table 34.1. + # ssl: false + +### TLS configuration +# +## Let's encrypt / ACME +# +# headscale supports automatically requesting and setting up +# TLS for a domain with Let's Encrypt. +# +# URL to ACME directory +acme_url: https://acme-v02.api.letsencrypt.org/directory + +# Email to register with ACME provider +acme_email: "" + +# Domain name to request a TLS certificate for: +tls_letsencrypt_hostname: "" + +# Path to store certificates and metadata needed by +# letsencrypt +# For production: +tls_letsencrypt_cache_dir: /var/lib/headscale/cache + +# Type of ACME challenge to use, currently supported types: +# HTTP-01 or TLS-ALPN-01 +# See: docs/ref/tls.md for more information +tls_letsencrypt_challenge_type: HTTP-01 +# When HTTP-01 challenge is chosen, letsencrypt must set up a +# verification endpoint, and it will be listening on: +# :http = port 80 +tls_letsencrypt_listen: ":http" + +## Use already defined certificates: +tls_cert_path: "" +tls_key_path: "" + +log: + # Output formatting for logs: text or json + format: text + level: info + +## Policy +# headscale supports Tailscale's ACL policies. +# Please have a look to their KB to better +# understand the concepts: https://tailscale.com/kb/1018/acls/ +policy: + # The mode can be "file" or "database" that defines + # where the ACL policies are stored and read from. + mode: file + # If the mode is set to "file", the path to a + # HuJSON file containing ACL policies. + path: "" + +## DNS +# +# headscale supports Tailscale's DNS configuration and MagicDNS. +# Please have a look to their KB to better understand the concepts: +# +# - https://tailscale.com/kb/1054/dns/ +# - https://tailscale.com/kb/1081/magicdns/ +# - https://tailscale.com/blog/2021-09-private-dns-with-magicdns/ +# +# Please note that for the DNS configuration to have any effect, +# clients must have the `--accept-dns=true` option enabled. This is the +# default for the Tailscale client. This option is enabled by default +# in the Tailscale client. +# +# Setting _any_ of the configuration and `--accept-dns=true` on the +# clients will integrate with the DNS manager on the client or +# overwrite /etc/resolv.conf. +# https://tailscale.com/kb/1235/resolv-conf +# +# If you want stop Headscale from managing the DNS configuration +# all the fields under `dns` should be set to empty values. +dns: + # Whether to use [MagicDNS](https://tailscale.com/kb/1081/magicdns/). + magic_dns: false + + # Defines the base domain to create the hostnames for MagicDNS. + # This domain _must_ be different from the server_url domain. + # `base_domain` must be a FQDN, without the trailing dot. + # The FQDN of the hosts will be + # `hostname.base_domain` (e.g., _myhost.example.com_). + base_domain: example.com + + # List of DNS servers to expose to clients. + nameservers: + global: + - 1.1.1.1 + - 1.0.0.1 + - 2606:4700:4700::1111 + - 2606:4700:4700::1001 + + # NextDNS (see https://tailscale.com/kb/1218/nextdns/). + # "abc123" is example NextDNS ID, replace with yours. + # - https://dns.nextdns.io/abc123 + + # Split DNS (see https://tailscale.com/kb/1054/dns/), + # a map of domains and which DNS server to use for each. + split: + {} + # foo.bar.com: + # - 1.1.1.1 + # darp.headscale.net: + # - 1.1.1.1 + # - 8.8.8.8 + + # Set custom DNS search domains. With MagicDNS enabled, + # your tailnet base_domain is always the first search domain. + search_domains: [] + + # Extra DNS records + # so far only A and AAAA records are supported (on the tailscale side) + # See: docs/ref/dns.md + extra_records: [] + # - name: "grafana.myvpn.example.com" + # type: "A" + # value: "100.64.0.3" + # + # # you can also put it in one line + # - { name: "prometheus.myvpn.example.com", type: "A", value: "100.64.0.3" } + # + # Alternatively, extra DNS records can be loaded from a JSON file. + # Headscale processes this file on each change. + # extra_records_path: /var/lib/headscale/extra-records.json + +# Unix socket used for the CLI to connect without authentication +# Note: for production you will want to set this to something like: +unix_socket: /var/run/headscale/headscale.sock +unix_socket_permission: "0770" +# +# headscale supports experimental OpenID connect support, +# it is still being tested and might have some bugs, please +# help us test it. +# OpenID Connect +# oidc: +# only_start_if_oidc_is_available: true +# issuer: "https://your-oidc.issuer.com/path" +# client_id: "your-oidc-client-id" +# client_secret: "your-oidc-client-secret" +# # Alternatively, set `client_secret_path` to read the secret from the file. +# # It resolves environment variables, making integration to systemd's +# # `LoadCredential` straightforward: +# client_secret_path: "${CREDENTIALS_DIRECTORY}/oidc_client_secret" +# # client_secret and client_secret_path are mutually exclusive. +# +# # The amount of time from a node is authenticated with OpenID until it +# # expires and needs to reauthenticate. +# # Setting the value to "0" will mean no expiry. +# expiry: 180d +# +# # Use the expiry from the token received from OpenID when the user logged +# # in, this will typically lead to frequent need to reauthenticate and should +# # only been enabled if you know what you are doing. +# # Note: enabling this will cause `oidc.expiry` to be ignored. +# use_expiry_from_token: false +# +# # Customize the scopes used in the OIDC flow, defaults to "openid", "profile" and "email" and add custom query +# # parameters to the Authorize Endpoint request. Scopes default to "openid", "profile" and "email". +# +# scope: ["openid", "profile", "email", "custom"] +# extra_params: +# domain_hint: example.com +# +# # List allowed principal domains and/or users. If an authenticated user's domain is not in this list, the +# # authentication request will be rejected. +# +# allowed_domains: +# - example.com +# # Note: Groups from keycloak have a leading '/' +# allowed_groups: +# - /headscale +# allowed_users: +# - alice@example.com +# +# # Optional: PKCE (Proof Key for Code Exchange) configuration +# # PKCE adds an additional layer of security to the OAuth 2.0 authorization code flow +# # by preventing authorization code interception attacks +# # See https://datatracker.ietf.org/doc/html/rfc7636 +# pkce: +# # Enable or disable PKCE support (default: false) +# enabled: false +# # PKCE method to use: +# # - plain: Use plain code verifier +# # - S256: Use SHA256 hashed code verifier (default, recommended) +# method: S256 +# +# # Map legacy users from pre-0.24.0 versions of headscale to the new OIDC users +# # by taking the username from the legacy user and matching it with the username +# # provided by the OIDC. This is useful when migrating from legacy users to OIDC +# # to force them using the unique identifier from the OIDC and to give them a +# # proper display name and picture if available. +# # Note that this will only work if the username from the legacy user is the same +# # and there is a possibility for account takeover should a username have changed +# # with the provider. +# # When this feature is disabled, it will cause all new logins to be created as new users. +# # Note this option will be removed in the future and should be set to false +# # on all new installations, or when all users have logged in with OIDC once. +# map_legacy_users: false + +# Logtail configuration +# Logtail is Tailscales logging and auditing infrastructure, it allows the control panel +# to instruct tailscale nodes to log their activity to a remote server. +logtail: + # Enable logtail for this headscales clients. + # As there is currently no support for overriding the log server in headscale, this is + # disabled by default. Enabling this will make your clients send logs to Tailscale Inc. + enabled: false + +# Enabling this option makes devices prefer a random port for WireGuard traffic over the +# default static port 41641. This option is intended as a workaround for some buggy +# firewall devices. See https://tailscale.com/kb/1181/firewalls/ for more information. +randomize_client_port: false \ No newline at end of file diff --git a/tailscale/docker-compose.yml b/tailscale/docker-compose.yml new file mode 100644 index 0000000..fb2ae09 --- /dev/null +++ b/tailscale/docker-compose.yml @@ -0,0 +1,48 @@ +version: "3.9" +services: + headscale: + image: swr.cn-north-4.myhuaweicloud.com/ddn-k8s/docker.io/headscale/headscale:v0.23.0-beta2 + container_name: headscale + restart: unless-stopped + environment: + - HEADSCALE_API_KEY=QC33VFzaUw.u1qwXFap0QpFAQnwkdGuUyvpspL15185A5JnWeFpt_c # Revert to original variable name + command: serve --config /etc/headscale/config.yaml # 明确指定配置文件路径 + volumes: + - ./data/headscale:/var/lib/headscale + # 修正挂载路径冲突问题 ↓ + - ./config.yaml:/etc/headscale/config.yaml # 删除这行 + ports: + - "3008:8080" # Headscale API端口 + - "9090:9090" # Metrics监控端口 + - "50443:50443" # DERP中继端口(可选,若Derper独立部署则无需映射) + cap_add: + - NET_ADMIN + sysctls: + - net.ipv4.ip_forward=1 + + + + + # derper: + # image: swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/yangchuansheng/ip_derper:latest + # container_name: derper + # restart: unless-stopped + # network_mode: host # 绑定宿主机网络 + # environment: + # - DERP_ADDR=:12345 # DERP监听地址(TCP) + # - DERP_STUN_ADDR=:3478 # STUN监听地址(UDP) + # - DERP_CERTS=/app/certs # 证书路径(自签名需挂载) + # - DERP_VERIFY_CLIENTS=false # 允许匿名中继(生产环境建议启用验证) + # volumes: + # - ./certs/derper:/app/certs # 自签名证书挂载(可选) + + headscale-ui: + image: swr.cn-north-4.myhuaweicloud.com/ddn-k8s/ghcr.io/gurucomputing/headscale-ui:2024.02.24-beta1 + container_name: headscale-ui + restart: unless-stopped + environment: + - HTTP_PORT=8000 + - HEADSCALE_API_URL=http://headscale:8080 + - HEADSCALE_API_KEY=QC33VFzaUw.u1qwXFap0QpFAQnwkdGuUyvpspL15185A5JnWeFpt_c # Revert to original variable name + ports: + - "8000:8000" # 访问地址:http://<服务器IP>:8000/web \ No newline at end of file diff --git a/zerotier/docker-compose.yml b/zerotier/docker-compose.yml deleted file mode 100644 index 1ea29fe..0000000 --- a/zerotier/docker-compose.yml +++ /dev/null @@ -1,52 +0,0 @@ -version: '3.8' - -services: - # ZeroTier 控制面板 (ztncui) - ztncui: - image: keynetworks/ztncui:latest - container_name: ztncui - restart: unless-stopped - ports: - - "3443:3443" # HTTPS 控制面板 - - "9995:9993" # Planet 通信 - - "9995:9993/udp" - volumes: - - ./zerotier-data:/var/lib/zerotier-one - environment: - - ZT_TOKEN= $ (cat ./zerotier-data/authtoken.secret) - - HTTPS_HOST=0.0.0.0 - - HTTPS_PORT=3443 - networks: - - zt-network - - # 自建 Planet (根服务器) - planet: - image: xubiaolin/zerotier-planet:latest - container_name: zerotier-planet - restart: unless-stopped - ports: - - "9994:9994" # Planet 端口 - - "9994:9994/udp" - environment: - - IP_ADDR4= $ (curl -s ifconfig.me) # 自动获取公网IP - - ZT_PORT=9994 - networks: - - zt-network - - # Moon 中继服务器 - moon: - image: jonnyan404/zerotier-moon - container_name: zerotier-moon - restart: unless-stopped - ports: - - "9993:9993/udp" # Moon 端口 - volumes: - - ./moon-data:/var/lib/zerotier-one - environment: - - ENDPOINTS= $ (curl -s ifconfig.me)/9993 # 自动设置Moon地址 - networks: - - zt-network - -networks: - zt-network: - driver: bridge