feat(ssl): 证书签发链路搬到国内机 Docker,清理 1Panel 过期证书
架构定案(B+C):CF Worker 免费版 CPU 硬顶 10ms(cron 同), 不再购买 Paid($5/月≈¥36),改为—— B. Worker 留免费版 + 代码优化(把 CPU 压进预算) C. 签发+部署整条链路搬国内机 Docker 容器 代码 - acme.ts: 缓存 signingKey 为 Promise,单次签发 importKey 12→1 次 (实测 importKey 126µs / sign 84µs;一次签发 3.3ms → 1.4ms) - deployer.ts: 新增 DogeCloudDeployer.ping();修正 cert_id → id 的注释 - dnsprovider.ts: 新增 RemoteDns(把 DNS-01 写 TXT 委托给国内机 cn-dns-helper) - tools/certkeeper-config.mjs: 域名配置抽为唯一事实源(两个消费方共用) - tools/export-certkeeper-data.mjs: 导出国内机数据目录 新增部署单元 - deploy/cn-certkeeper: 签发+部署容器(只绑 127.0.0.1:8019,compose 管理) 含 FileKV(文件系统版 KVNamespace)、带鉴权 HTTP、每日 4:10 续期 - deploy/cn-dns-helper: DNS-01 写 TXT 助手(只绑 127.0.0.1:8018) 文档 - 函数版证书管家-方案.md 新增第九章:B+C 定案、实测 CPU 数据、 容器验收记录、1Panel 过期证书清理记录、t-t.live 两套管理冲突 - 标注旧 8.3 节「免费版跑不了签发」为未实测误判 一并纳入:.gitignore 忽略 deploy/cn-certkeeper/lib/(tsc 编译产物)
This commit is contained in:
1 parent
a3bc10c68c
commit
1427c47dcf
15 files changed
+1387
-52
No files matched your search
@@ -0,0 +1,22 @@
|
||||
services:
|
||||
cn-dns-helper:
|
||||
build: /srv/cn-dns-helper
|
||||
image: cn-dns-helper:local
|
||||
container_name: cn-dns-helper
|
||||
restart: unless-stopped
|
||||
# ★ 只绑本机回环:外部经 1Panel/openresty 反代进来,容器端口不直接暴露
|
||||
ports:
|
||||
- "127.0.0.1:8018:8018"
|
||||
environment:
|
||||
# CF_API_TOKEN:有 Zone/DNS 权限的 Cloudflare token(从 certimate 迁出)
|
||||
CF_API_TOKEN: ${CF_API_TOKEN:?}
|
||||
# DNS_HELPER_TOKEN:Worker 侧调用本服务的共享密钥,两边必须一致
|
||||
DNS_HELPER_TOKEN: ${DNS_HELPER_TOKEN:?}
|
||||
BIND_HOST: 0.0.0.0
|
||||
BIND_PORT: "8018"
|
||||
healthcheck:
|
||||
test: ["CMD", "node", "-e", "fetch('http://127.0.0.1:8018/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
retries: 3
|
||||
start_period: 10s
|
||||
Reference in new issue
Block a user