added:增加Linux-server
This commit is contained in:
1 parent
712116d21d
commit
bd96aadb2f
90 files changed
+16784
-1
No files matched your search
@@ -0,0 +1,689 @@
|
||||
# Write Server Linux 部署指南
|
||||
|
||||
本文档提供详细的 Linux 部署步骤,包括手动部署、Docker 部署和 systemd 配置。
|
||||
|
||||
## 目录
|
||||
|
||||
- [系统要求](#系统要求)
|
||||
- [快速开始](#快速开始)
|
||||
- [手动部署](#手动部署)
|
||||
- [Docker 部署](#docker-部署)
|
||||
- [Nginx 配置](#nginx-配置)
|
||||
- [SSL 证书配置](#ssl-证书配置)
|
||||
- [systemd 服务配置](#systemd-服务配置)
|
||||
- [防火墙配置](#防火墙配置)
|
||||
- [监控和日志](#监控和日志)
|
||||
- [备份策略](#备份策略)
|
||||
- [性能优化](#性能优化)
|
||||
- [故障排查](#故障排查)
|
||||
|
||||
## 系统要求
|
||||
|
||||
### 最低配置
|
||||
|
||||
- **操作系统**: Ubuntu 20.04+, Debian 11+, CentOS 8+, RHEL 8+
|
||||
- **CPU**: 1 核
|
||||
- **内存**: 512MB
|
||||
- **磁盘**: 10GB
|
||||
- **Node.js**: 18+ (推荐 20 LTS)
|
||||
- **Hugo**: 0.116+ (extended 版本)
|
||||
|
||||
### 推荐配置
|
||||
|
||||
- **CPU**: 2 核
|
||||
- **内存**: 2GB
|
||||
- **磁盘**: 50GB(取决于博客内容量)
|
||||
- **Node.js**: 20 LTS
|
||||
- **Hugo**: 0.128+
|
||||
|
||||
## 快速开始
|
||||
|
||||
### 方式一:一键安装(推荐)
|
||||
|
||||
```bash
|
||||
# 1. 克隆项目
|
||||
git clone <your-repo-url>
|
||||
cd write-server
|
||||
|
||||
# 2. 运行安装脚本
|
||||
chmod +x scripts/*.sh
|
||||
./scripts/install.sh
|
||||
|
||||
# 3. 配置环境变量
|
||||
cp .env.example .env
|
||||
nano .env
|
||||
|
||||
# 4. 启动服务
|
||||
./scripts/start.sh
|
||||
```
|
||||
|
||||
### 方式二:Docker 快速启动
|
||||
|
||||
```bash
|
||||
# 1. 克隆项目
|
||||
git clone <your-repo-url>
|
||||
cd write-server
|
||||
|
||||
# 2. 配置环境变量
|
||||
cp .env.example .env
|
||||
nano .env
|
||||
|
||||
# 3. 启动 Docker 容器
|
||||
docker-compose up -d
|
||||
|
||||
# 4. 查看日志
|
||||
docker-compose logs -f
|
||||
```
|
||||
|
||||
## 手动部署
|
||||
|
||||
### 1. 安装系统依赖
|
||||
|
||||
#### Ubuntu/Debian
|
||||
|
||||
```bash
|
||||
# 更新系统
|
||||
sudo apt update
|
||||
sudo apt upgrade -y
|
||||
|
||||
# 安装基础工具
|
||||
sudo apt install -y curl wget git build-essential
|
||||
|
||||
# 安装 Node.js 20
|
||||
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
|
||||
sudo apt install -y nodejs
|
||||
|
||||
# 验证安装
|
||||
node --version
|
||||
npm --version
|
||||
|
||||
# 安装 Hugo
|
||||
HUGO_VERSION="0.128.2"
|
||||
wget https://github.com/gohugoio/hugo/releases/download/v${HUGO_VERSION}/hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz
|
||||
tar -xzf hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz
|
||||
sudo mv hugo /usr/local/bin/
|
||||
rm hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz
|
||||
|
||||
# 验证 Hugo
|
||||
hugo version
|
||||
|
||||
# 安装 PM2
|
||||
sudo npm install -g pm2
|
||||
```
|
||||
|
||||
#### CentOS/RHEL/Fedora
|
||||
|
||||
```bash
|
||||
# 更新系统
|
||||
sudo yum update -y
|
||||
|
||||
# 安装基础工具
|
||||
sudo yum install -y curl wget git gcc-c++ make
|
||||
|
||||
# 安装 Node.js 20
|
||||
curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash -
|
||||
sudo yum install -y nodejs
|
||||
|
||||
# 验证安装
|
||||
node --version
|
||||
npm --version
|
||||
|
||||
# 安装 Hugo(同上)
|
||||
|
||||
# 安装 PM2
|
||||
sudo npm install -g pm2
|
||||
```
|
||||
|
||||
### 2. 部署应用
|
||||
|
||||
```bash
|
||||
# 克隆项目
|
||||
git clone <your-repo-url>
|
||||
cd write-server
|
||||
|
||||
# 安装依赖
|
||||
npm install
|
||||
|
||||
# 配置环境变量
|
||||
cp .env.example .env
|
||||
nano .env # 编辑配置
|
||||
|
||||
# 构建项目
|
||||
npm run build
|
||||
|
||||
# 创建必要目录
|
||||
mkdir -p logs backups recycle
|
||||
|
||||
# 启动服务
|
||||
pm2 start ecosystem.config.js
|
||||
```
|
||||
|
||||
### 3. 验证部署
|
||||
|
||||
```bash
|
||||
# 检查进程状态
|
||||
pm2 status
|
||||
|
||||
# 查看日志
|
||||
pm2 logs write-server
|
||||
|
||||
# 测试访问
|
||||
curl http://localhost:8016/api/stats
|
||||
```
|
||||
|
||||
## Docker 部署
|
||||
|
||||
### 1. 安装 Docker
|
||||
|
||||
```bash
|
||||
# Ubuntu/Debian
|
||||
sudo apt install -y docker.io docker-compose
|
||||
sudo systemctl start docker
|
||||
sudo systemctl enable docker
|
||||
sudo usermod -aG docker $USER
|
||||
|
||||
# CentOS/RHEL
|
||||
sudo yum install -y docker
|
||||
sudo systemctl start docker
|
||||
sudo systemctl enable docker
|
||||
sudo usermod -aG docker $USER
|
||||
|
||||
# 重新登录以应用组权限
|
||||
```
|
||||
|
||||
### 2. 配置环境变量
|
||||
|
||||
```bash
|
||||
cp .env.example .env
|
||||
nano .env
|
||||
```
|
||||
|
||||
**必填配置:**
|
||||
|
||||
```bash
|
||||
BLOG_ROOT=/path/to/your/hugo/blog # 宿主机上的博客路径
|
||||
PORT=8016
|
||||
```
|
||||
|
||||
### 3. 启动容器
|
||||
|
||||
```bash
|
||||
# 构建并启动
|
||||
docker-compose up -d
|
||||
|
||||
# 查看状态
|
||||
docker-compose ps
|
||||
|
||||
# 查看日志
|
||||
docker-compose logs -f
|
||||
```
|
||||
|
||||
### 4. 管理容器
|
||||
|
||||
```bash
|
||||
# 停止容器
|
||||
docker-compose down
|
||||
|
||||
# 重启容器
|
||||
docker-compose restart
|
||||
|
||||
# 进入容器
|
||||
docker exec -it write-server sh
|
||||
|
||||
# 查看资源使用
|
||||
docker stats write-server
|
||||
```
|
||||
|
||||
## Nginx 配置
|
||||
|
||||
### 1. 安装 Nginx
|
||||
|
||||
```bash
|
||||
# Ubuntu/Debian
|
||||
sudo apt install -y nginx
|
||||
|
||||
# CentOS/RHEL
|
||||
sudo yum install -y nginx
|
||||
```
|
||||
|
||||
### 2. 配置反向代理
|
||||
|
||||
```bash
|
||||
# 复制配置文件
|
||||
sudo cp nginx/conf.d/write-server.conf /etc/nginx/conf.d/
|
||||
|
||||
# 编辑配置
|
||||
sudo nano /etc/nginx/conf.d/write-server.conf
|
||||
```
|
||||
|
||||
**修改内容:**
|
||||
|
||||
```nginx
|
||||
server {
|
||||
listen 80;
|
||||
server_name write.your-domain.com; # 替换为你的域名
|
||||
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:8016;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
### 3. 测试并重启 Nginx
|
||||
|
||||
```bash
|
||||
# 测试配置
|
||||
sudo nginx -t
|
||||
|
||||
# 重启 Nginx
|
||||
sudo systemctl restart nginx
|
||||
sudo systemctl enable nginx
|
||||
```
|
||||
|
||||
## SSL 证书配置
|
||||
|
||||
### 使用 Let's Encrypt(免费)
|
||||
|
||||
```bash
|
||||
# 安装 Certbot
|
||||
sudo apt install -y certbot python3-certbot-nginx
|
||||
|
||||
# 获取证书
|
||||
sudo certbot --nginx -d write.your-domain.com
|
||||
|
||||
# 自动续期测试
|
||||
sudo certbot renew --dry-run
|
||||
|
||||
# 设置自动续期
|
||||
sudo crontab -e
|
||||
# 添加:0 12 * * * /usr/bin/certbot renew --quiet
|
||||
```
|
||||
|
||||
### 手动配置 SSL
|
||||
|
||||
```nginx
|
||||
server {
|
||||
listen 443 ssl http2;
|
||||
server_name write.your-domain.com;
|
||||
|
||||
ssl_certificate /etc/nginx/ssl/fullchain.pem;
|
||||
ssl_certificate_key /etc/nginx/ssl/privkey.pem;
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_ciphers HIGH:!aNULL:!MD5;
|
||||
|
||||
location / {
|
||||
proxy_pass http://127.0.0.1:8016;
|
||||
# ... 其他代理配置
|
||||
}
|
||||
}
|
||||
|
||||
# HTTP 重定向
|
||||
server {
|
||||
listen 80;
|
||||
server_name write.your-domain.com;
|
||||
return 301 https://$server_name$request_uri;
|
||||
}
|
||||
```
|
||||
|
||||
## systemd 服务配置
|
||||
|
||||
### 1. 创建服务文件
|
||||
|
||||
```bash
|
||||
sudo cp systemd/write-server.service /etc/systemd/system/
|
||||
|
||||
# 编辑服务文件
|
||||
sudo nano /etc/systemd/system/write-server.service
|
||||
```
|
||||
|
||||
**修改以下配置:**
|
||||
|
||||
```ini
|
||||
[Unit]
|
||||
Description=Write Server - Hugo Blog Admin
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=your-username # 修改为你的用户名
|
||||
Group=your-group # 修改为你的用户组
|
||||
WorkingDirectory=/path/to/write-server # 修改为项目路径
|
||||
Environment=NODE_ENV=production
|
||||
Environment=PORT=8016
|
||||
EnvironmentFile=/path/to/write-server/.env # 修改为 .env 路径
|
||||
ExecStart=/usr/bin/node /path/to/write-server/.next/standalone/server.js
|
||||
Restart=always
|
||||
RestartSec=10
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
```
|
||||
|
||||
### 2. 启用并启动服务
|
||||
|
||||
```bash
|
||||
# 重新加载 systemd
|
||||
sudo systemctl daemon-reload
|
||||
|
||||
# 启用服务(开机自启)
|
||||
sudo systemctl enable write-server
|
||||
|
||||
# 启动服务
|
||||
sudo systemctl start write-server
|
||||
|
||||
# 检查状态
|
||||
sudo systemctl status write-server
|
||||
```
|
||||
|
||||
### 3. 管理服务
|
||||
|
||||
```bash
|
||||
# 启动服务
|
||||
sudo systemctl start write-server
|
||||
|
||||
# 停止服务
|
||||
sudo systemctl stop write-server
|
||||
|
||||
# 重启服务
|
||||
sudo systemctl restart write-server
|
||||
|
||||
# 查看状态
|
||||
sudo systemctl status write-server
|
||||
|
||||
# 查看日志
|
||||
sudo journalctl -u write-server -f
|
||||
```
|
||||
|
||||
## 防火墙配置
|
||||
|
||||
### UFW(Ubuntu/Debian)
|
||||
|
||||
```bash
|
||||
# 允许 SSH
|
||||
sudo ufw allow ssh
|
||||
|
||||
# 允许 HTTP/HTTPS
|
||||
sudo ufw allow 80/tcp
|
||||
sudo ufw allow 443/tcp
|
||||
|
||||
# 如果需要直接访问(不推荐)
|
||||
sudo ufw allow 8016/tcp
|
||||
|
||||
# 启用防火墙
|
||||
sudo ufw enable
|
||||
|
||||
# 查看状态
|
||||
sudo ufw status
|
||||
```
|
||||
|
||||
### firewalld(CentOS/RHEL)
|
||||
|
||||
```bash
|
||||
# 允许 HTTP/HTTPS
|
||||
sudo firewall-cmd --permanent --add-service=http
|
||||
sudo firewall-cmd --permanent --add-service=https
|
||||
|
||||
# 如果需要直接访问
|
||||
sudo firewall-cmd --permanent --add-port=8016/tcp
|
||||
|
||||
# 重新加载配置
|
||||
sudo firewall-cmd --reload
|
||||
|
||||
# 查看状态
|
||||
sudo firewall-cmd --list-all
|
||||
```
|
||||
|
||||
## 监控和日志
|
||||
|
||||
### 日志位置
|
||||
|
||||
- **应用日志**: `logs/app.log`
|
||||
- **PM2 日志**: `logs/pm2-out.log`, `logs/pm2-error.log`
|
||||
- **Nginx 日志**: `/var/log/nginx/`
|
||||
- **systemd 日志**: `sudo journalctl -u write-server`
|
||||
|
||||
### 日志轮转
|
||||
|
||||
创建日志轮转配置:
|
||||
|
||||
```bash
|
||||
sudo nano /etc/logrotate.d/write-server
|
||||
```
|
||||
|
||||
**内容:**
|
||||
|
||||
```
|
||||
/path/to/write-server/logs/*.log {
|
||||
daily
|
||||
missingok
|
||||
rotate 14
|
||||
compress
|
||||
delaycompress
|
||||
notifempty
|
||||
create 0640 your-user your-group
|
||||
}
|
||||
```
|
||||
|
||||
### 监控脚本
|
||||
|
||||
创建简单的监控脚本:
|
||||
|
||||
```bash
|
||||
#!/bin/bash
|
||||
# monitor.sh
|
||||
|
||||
# 检查服务状态
|
||||
if ! curl -s http://localhost:8016/api/stats > /dev/null; then
|
||||
echo "服务异常,正在重启..."
|
||||
sudo systemctl restart write-server
|
||||
# 发送告警邮件(可选)
|
||||
fi
|
||||
```
|
||||
|
||||
添加到 crontab:
|
||||
|
||||
```bash
|
||||
crontab -e
|
||||
# 每 5 分钟检查一次
|
||||
*/5 * * * * /path/to/monitor.sh
|
||||
```
|
||||
|
||||
## 备份策略
|
||||
|
||||
### 自动备份
|
||||
|
||||
```bash
|
||||
# 添加到 crontab
|
||||
crontab -e
|
||||
|
||||
# 每天凌晨 2 点备份
|
||||
0 2 * * * /path/to/write-server/scripts/backup.sh
|
||||
|
||||
# 每周日备份并上传到远程存储
|
||||
0 3 * * 0 /path/to/write-server/scripts/backup.sh && /path/to/upload-to-s3.sh
|
||||
```
|
||||
|
||||
### 备份内容
|
||||
|
||||
- 博客内容(content/posts/)
|
||||
- 配置文件(.env)
|
||||
- 回收站数据
|
||||
- Nginx 配置
|
||||
- systemd 服务文件
|
||||
|
||||
### 恢复备份
|
||||
|
||||
```bash
|
||||
# 查看可用备份
|
||||
ls -lh backups/
|
||||
|
||||
# 恢复指定备份
|
||||
./scripts/restore.sh backups/write-server-20260101_120000.tar.gz
|
||||
```
|
||||
|
||||
## 性能优化
|
||||
|
||||
### 1. Node.js 优化
|
||||
|
||||
```bash
|
||||
# 使用 PM2 集群模式(多核 CPU)
|
||||
pm2 start ecosystem.config.js -i max
|
||||
|
||||
# 或在 ecosystem.config.js 中修改
|
||||
# instances: "max"
|
||||
# exec_mode: "cluster"
|
||||
```
|
||||
|
||||
### 2. Nginx 优化
|
||||
|
||||
在 nginx.conf 中添加:
|
||||
|
||||
```nginx
|
||||
# 启用 Gzip
|
||||
gzip on;
|
||||
gzip_vary on;
|
||||
gzip_min_length 1000;
|
||||
gzip_types text/plain text/css application/json application/javascript;
|
||||
|
||||
# 缓存静态资源
|
||||
location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg)$ {
|
||||
expires 1y;
|
||||
add_header Cache-Control "public, immutable";
|
||||
}
|
||||
```
|
||||
|
||||
### 3. 系统优化
|
||||
|
||||
```bash
|
||||
# 增加文件描述符限制
|
||||
sudo nano /etc/security/limits.conf
|
||||
# 添加:
|
||||
# your-user soft nofile 65536
|
||||
# your-user hard nofile 65536
|
||||
|
||||
# 优化内核参数
|
||||
sudo nano /etc/sysctl.conf
|
||||
# 添加:
|
||||
# net.core.somaxconn = 65535
|
||||
# net.ipv4.tcp_max_syn_backlog = 65535
|
||||
```
|
||||
|
||||
## 故障排查
|
||||
|
||||
### 常见问题
|
||||
|
||||
#### 1. 服务无法启动
|
||||
|
||||
```bash
|
||||
# 查看详细错误
|
||||
pm2 logs write-server --lines 100
|
||||
|
||||
# 或
|
||||
sudo journalctl -u write-server -n 100
|
||||
|
||||
# 检查端口占用
|
||||
lsof -i :8016
|
||||
netstat -tulpn | grep 8016
|
||||
```
|
||||
|
||||
#### 2. 无法访问博客内容
|
||||
|
||||
```bash
|
||||
# 检查 BLOG_ROOT 配置
|
||||
cat .env | grep BLOG_ROOT
|
||||
|
||||
# 检查目录权限
|
||||
ls -la /path/to/blog
|
||||
|
||||
# 修复权限
|
||||
sudo chown -R your-user:your-group /path/to/blog
|
||||
```
|
||||
|
||||
#### 3. Hugo 预览失败
|
||||
|
||||
```bash
|
||||
# 检查 Hugo 是否安装
|
||||
hugo version
|
||||
|
||||
# 手动启动 Hugo 预览
|
||||
cd /path/to/blog
|
||||
hugo server -D
|
||||
```
|
||||
|
||||
#### 4. 图片上传失败
|
||||
|
||||
```bash
|
||||
# 检查目录权限
|
||||
ls -la /path/to/blog/static
|
||||
|
||||
# 检查磁盘空间
|
||||
df -h
|
||||
|
||||
# 检查文件大小限制(nginx.conf)
|
||||
client_max_body_size 50m;
|
||||
```
|
||||
|
||||
### 性能问题排查
|
||||
|
||||
```bash
|
||||
# 查看 CPU 和内存使用
|
||||
top
|
||||
htop
|
||||
|
||||
# 查看 Node.js 进程
|
||||
ps aux | grep node
|
||||
|
||||
# 查看网络连接
|
||||
netstat -tulpn | grep 8016
|
||||
|
||||
# 查看磁盘 I/O
|
||||
iotop
|
||||
```
|
||||
|
||||
## 安全建议
|
||||
|
||||
1. **使用 HTTPS** - 配置 SSL 证书
|
||||
2. **限制访问** - 配置防火墙和 Nginx 访问控制
|
||||
3. **定期更新** - 保持系统和依赖更新
|
||||
4. **强密码** - 使用强密码和 API Token
|
||||
5. **备份加密** - 对备份文件进行加密
|
||||
6. **日志审计** - 定期检查访问日志
|
||||
7. **最小权限** - 使用非 root 用户运行服务
|
||||
8. **Fail2ban** - 防止暴力破解攻击
|
||||
|
||||
## 更新升级
|
||||
|
||||
```bash
|
||||
# 拉取最新代码
|
||||
git pull origin main
|
||||
|
||||
# 安装新依赖
|
||||
npm install
|
||||
|
||||
# 重新构建
|
||||
npm run build
|
||||
|
||||
# 重启服务
|
||||
pm2 restart write-server
|
||||
# 或
|
||||
sudo systemctl restart write-server
|
||||
```
|
||||
|
||||
## 回滚版本
|
||||
|
||||
```bash
|
||||
# 查看 Git 历史
|
||||
git log --oneline
|
||||
|
||||
# 回滚到指定版本
|
||||
git checkout <commit-hash>
|
||||
|
||||
# 重新部署
|
||||
npm install
|
||||
npm run build
|
||||
pm2 restart write-server
|
||||
```
|
||||
Reference in new issue
Block a user