feat(ssl): 证书签发链路搬到国内机 Docker,清理 1Panel 过期证书

架构定案(B+C):CF Worker 免费版 CPU 硬顶 10ms(cron 同),
不再购买 Paid($5/月≈¥36),改为——
  B. Worker 留免费版 + 代码优化(把 CPU 压进预算)
  C. 签发+部署整条链路搬国内机 Docker 容器

代码
- acme.ts: 缓存 signingKey 为 Promise,单次签发 importKey 12→1 次
  (实测 importKey 126µs / sign 84µs;一次签发 3.3ms → 1.4ms)
- deployer.ts: 新增 DogeCloudDeployer.ping();修正 cert_id → id 的注释
- dnsprovider.ts: 新增 RemoteDns(把 DNS-01 写 TXT 委托给国内机 cn-dns-helper)
- tools/certkeeper-config.mjs: 域名配置抽为唯一事实源(两个消费方共用)
- tools/export-certkeeper-data.mjs: 导出国内机数据目录

新增部署单元
- deploy/cn-certkeeper: 签发+部署容器(只绑 127.0.0.1:8019,compose 管理)
  含 FileKV(文件系统版 KVNamespace)、带鉴权 HTTP、每日 4:10 续期
- deploy/cn-dns-helper: DNS-01 写 TXT 助手(只绑 127.0.0.1:8018)

文档
- 函数版证书管家-方案.md 新增第九章:B+C 定案、实测 CPU 数据、
  容器验收记录、1Panel 过期证书清理记录、t-t.live 两套管理冲突
- 标注旧 8.3 节「免费版跑不了签发」为未实测误判

一并纳入:.gitignore 忽略 deploy/cn-certkeeper/lib/(tsc 编译产物)
This commit is contained in:
zqlit committed 2026-10-06 18:28:55 +08:00
1 parent a3bc10c68c
commit 1427c47dcf
15 files changed
+1387 -52

No files matched your search

+4 -40
View File
@@ -76,46 +76,10 @@ const ACCESS = SEEDS.access; // [{ name, type, note, fields: {...} }]
// Cloudflare 的 `imql`(apiTokenForZone)没进来:现有 `cloudflare` 那条已够用。
// (seeds 文件里同样只收了国内机那条,与当初迁移时的取舍一致。)
const CONFIG = {
version: 1,
notify: { emails: ['177018615@qq.com'], daysBefore: 30 },
domains: [
{
name: 'usj.cc',
san: ['usj.cc', '*.usj.cc'],
dns: 'tencent-usj',
deploy: ['dogecloud', '1panel'],
// ★ 站点名必须与 1Panel 里的 `primaryDomain` 或 `alias` 精确对上,
// 否则部署时会被跳过。下面这些是 2026-10-06 从面板实测出来的
// (面板上**没有** primaryDomain 为 `usj.cc` 的网站 —— 它只是证书名)。
dogecloud_domains: ['usj.cc', 'www.usj.cc', 'artalk.usj.cc'],
one_panel_sites: [
'artalk.usj.cc', // blog 评论后端
'openlist.usj.cc', // 网盘
'wifi.usj.cc',
'openwrt.usj.cc',
'vw.usj.cc', // vaultwarden(alias 才是这个名字)
],
disabled: false,
},
{
name: 't-t.live',
san: ['t-t.live', '*.t-t.live'],
dns: 'tencent-tt',
deploy: ['1panel'],
one_panel_sites: ['t-t.live', 'www.t-t.live', 'pl.t-t.live', 'pwd.t-t.live', 'certd.t-t.live'],
disabled: false,
},
{
name: '200181.xyz',
san: ['200181.xyz', '*.200181.xyz'],
dns: 'cloudflare',
deploy: ['1panel'],
one_panel_sites: ['ssh.200181.xyz'],
disabled: false,
},
],
};
// ★ CONFIG 已抽到 ./certkeeper-config.mjs(唯一事实源,国内机导出脚本也用同一份)
// 见那个文件的头注释:原先是内联在这里,但 export-certkeeper-data.mjs
// 需要复用却又不能 import 本脚本(本脚本一 import 就会连 KV 开始写)。
import { CONFIG } from './certkeeper-config.mjs';
// ---------------------------------------------------------------- 写入
const devVars = readFileSync(join(ROOT, '.dev.vars'), 'utf8');