added:增加Linux-server

This commit is contained in:
Vaica committed 2026-06-21 20:42:44 +08:00
1 parent 712116d21d
commit bd96aadb2f
90 files changed
+16784 -1

No files matched your search

+689
View File
@@ -0,0 +1,689 @@
# Write Server Linux 部署指南
本文档提供详细的 Linux 部署步骤,包括手动部署、Docker 部署和 systemd 配置。
## 目录
- [系统要求](#系统要求)
- [快速开始](#快速开始)
- [手动部署](#手动部署)
- [Docker 部署](#docker-部署)
- [Nginx 配置](#nginx-配置)
- [SSL 证书配置](#ssl-证书配置)
- [systemd 服务配置](#systemd-服务配置)
- [防火墙配置](#防火墙配置)
- [监控和日志](#监控和日志)
- [备份策略](#备份策略)
- [性能优化](#性能优化)
- [故障排查](#故障排查)
## 系统要求
### 最低配置
- **操作系统**: Ubuntu 20.04+, Debian 11+, CentOS 8+, RHEL 8+
- **CPU**: 1 核
- **内存**: 512MB
- **磁盘**: 10GB
- **Node.js**: 18+ (推荐 20 LTS)
- **Hugo**: 0.116+ (extended 版本)
### 推荐配置
- **CPU**: 2 核
- **内存**: 2GB
- **磁盘**: 50GB(取决于博客内容量)
- **Node.js**: 20 LTS
- **Hugo**: 0.128+
## 快速开始
### 方式一:一键安装(推荐)
```bash
# 1. 克隆项目
git clone <your-repo-url>
cd write-server
# 2. 运行安装脚本
chmod +x scripts/*.sh
./scripts/install.sh
# 3. 配置环境变量
cp .env.example .env
nano .env
# 4. 启动服务
./scripts/start.sh
```
### 方式二:Docker 快速启动
```bash
# 1. 克隆项目
git clone <your-repo-url>
cd write-server
# 2. 配置环境变量
cp .env.example .env
nano .env
# 3. 启动 Docker 容器
docker-compose up -d
# 4. 查看日志
docker-compose logs -f
```
## 手动部署
### 1. 安装系统依赖
#### Ubuntu/Debian
```bash
# 更新系统
sudo apt update
sudo apt upgrade -y
# 安装基础工具
sudo apt install -y curl wget git build-essential
# 安装 Node.js 20
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs
# 验证安装
node --version
npm --version
# 安装 Hugo
HUGO_VERSION="0.128.2"
wget https://github.com/gohugoio/hugo/releases/download/v${HUGO_VERSION}/hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz
tar -xzf hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz
sudo mv hugo /usr/local/bin/
rm hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz
# 验证 Hugo
hugo version
# 安装 PM2
sudo npm install -g pm2
```
#### CentOS/RHEL/Fedora
```bash
# 更新系统
sudo yum update -y
# 安装基础工具
sudo yum install -y curl wget git gcc-c++ make
# 安装 Node.js 20
curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash -
sudo yum install -y nodejs
# 验证安装
node --version
npm --version
# 安装 Hugo(同上)
# 安装 PM2
sudo npm install -g pm2
```
### 2. 部署应用
```bash
# 克隆项目
git clone <your-repo-url>
cd write-server
# 安装依赖
npm install
# 配置环境变量
cp .env.example .env
nano .env # 编辑配置
# 构建项目
npm run build
# 创建必要目录
mkdir -p logs backups recycle
# 启动服务
pm2 start ecosystem.config.js
```
### 3. 验证部署
```bash
# 检查进程状态
pm2 status
# 查看日志
pm2 logs write-server
# 测试访问
curl http://localhost:8016/api/stats
```
## Docker 部署
### 1. 安装 Docker
```bash
# Ubuntu/Debian
sudo apt install -y docker.io docker-compose
sudo systemctl start docker
sudo systemctl enable docker
sudo usermod -aG docker $USER
# CentOS/RHEL
sudo yum install -y docker
sudo systemctl start docker
sudo systemctl enable docker
sudo usermod -aG docker $USER
# 重新登录以应用组权限
```
### 2. 配置环境变量
```bash
cp .env.example .env
nano .env
```
**必填配置:**
```bash
BLOG_ROOT=/path/to/your/hugo/blog # 宿主机上的博客路径
PORT=8016
```
### 3. 启动容器
```bash
# 构建并启动
docker-compose up -d
# 查看状态
docker-compose ps
# 查看日志
docker-compose logs -f
```
### 4. 管理容器
```bash
# 停止容器
docker-compose down
# 重启容器
docker-compose restart
# 进入容器
docker exec -it write-server sh
# 查看资源使用
docker stats write-server
```
## Nginx 配置
### 1. 安装 Nginx
```bash
# Ubuntu/Debian
sudo apt install -y nginx
# CentOS/RHEL
sudo yum install -y nginx
```
### 2. 配置反向代理
```bash
# 复制配置文件
sudo cp nginx/conf.d/write-server.conf /etc/nginx/conf.d/
# 编辑配置
sudo nano /etc/nginx/conf.d/write-server.conf
```
**修改内容:**
```nginx
server {
listen 80;
server_name write.your-domain.com; # 替换为你的域名
location / {
proxy_pass http://127.0.0.1:8016;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
```
### 3. 测试并重启 Nginx
```bash
# 测试配置
sudo nginx -t
# 重启 Nginx
sudo systemctl restart nginx
sudo systemctl enable nginx
```
## SSL 证书配置
### 使用 Let's Encrypt(免费)
```bash
# 安装 Certbot
sudo apt install -y certbot python3-certbot-nginx
# 获取证书
sudo certbot --nginx -d write.your-domain.com
# 自动续期测试
sudo certbot renew --dry-run
# 设置自动续期
sudo crontab -e
# 添加:0 12 * * * /usr/bin/certbot renew --quiet
```
### 手动配置 SSL
```nginx
server {
listen 443 ssl http2;
server_name write.your-domain.com;
ssl_certificate /etc/nginx/ssl/fullchain.pem;
ssl_certificate_key /etc/nginx/ssl/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
location / {
proxy_pass http://127.0.0.1:8016;
# ... 其他代理配置
}
}
# HTTP 重定向
server {
listen 80;
server_name write.your-domain.com;
return 301 https://$server_name$request_uri;
}
```
## systemd 服务配置
### 1. 创建服务文件
```bash
sudo cp systemd/write-server.service /etc/systemd/system/
# 编辑服务文件
sudo nano /etc/systemd/system/write-server.service
```
**修改以下配置:**
```ini
[Unit]
Description=Write Server - Hugo Blog Admin
After=network.target
[Service]
Type=simple
User=your-username # 修改为你的用户名
Group=your-group # 修改为你的用户组
WorkingDirectory=/path/to/write-server # 修改为项目路径
Environment=NODE_ENV=production
Environment=PORT=8016
EnvironmentFile=/path/to/write-server/.env # 修改为 .env 路径
ExecStart=/usr/bin/node /path/to/write-server/.next/standalone/server.js
Restart=always
RestartSec=10
[Install]
WantedBy=multi-user.target
```
### 2. 启用并启动服务
```bash
# 重新加载 systemd
sudo systemctl daemon-reload
# 启用服务(开机自启)
sudo systemctl enable write-server
# 启动服务
sudo systemctl start write-server
# 检查状态
sudo systemctl status write-server
```
### 3. 管理服务
```bash
# 启动服务
sudo systemctl start write-server
# 停止服务
sudo systemctl stop write-server
# 重启服务
sudo systemctl restart write-server
# 查看状态
sudo systemctl status write-server
# 查看日志
sudo journalctl -u write-server -f
```
## 防火墙配置
### UFW(Ubuntu/Debian)
```bash
# 允许 SSH
sudo ufw allow ssh
# 允许 HTTP/HTTPS
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
# 如果需要直接访问(不推荐)
sudo ufw allow 8016/tcp
# 启用防火墙
sudo ufw enable
# 查看状态
sudo ufw status
```
### firewalld(CentOS/RHEL)
```bash
# 允许 HTTP/HTTPS
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
# 如果需要直接访问
sudo firewall-cmd --permanent --add-port=8016/tcp
# 重新加载配置
sudo firewall-cmd --reload
# 查看状态
sudo firewall-cmd --list-all
```
## 监控和日志
### 日志位置
- **应用日志**: `logs/app.log`
- **PM2 日志**: `logs/pm2-out.log`, `logs/pm2-error.log`
- **Nginx 日志**: `/var/log/nginx/`
- **systemd 日志**: `sudo journalctl -u write-server`
### 日志轮转
创建日志轮转配置:
```bash
sudo nano /etc/logrotate.d/write-server
```
**内容:**
```
/path/to/write-server/logs/*.log {
daily
missingok
rotate 14
compress
delaycompress
notifempty
create 0640 your-user your-group
}
```
### 监控脚本
创建简单的监控脚本:
```bash
#!/bin/bash
# monitor.sh
# 检查服务状态
if ! curl -s http://localhost:8016/api/stats > /dev/null; then
echo "服务异常,正在重启..."
sudo systemctl restart write-server
# 发送告警邮件(可选)
fi
```
添加到 crontab:
```bash
crontab -e
# 每 5 分钟检查一次
*/5 * * * * /path/to/monitor.sh
```
## 备份策略
### 自动备份
```bash
# 添加到 crontab
crontab -e
# 每天凌晨 2 点备份
0 2 * * * /path/to/write-server/scripts/backup.sh
# 每周日备份并上传到远程存储
0 3 * * 0 /path/to/write-server/scripts/backup.sh && /path/to/upload-to-s3.sh
```
### 备份内容
- 博客内容(content/posts/)
- 配置文件(.env)
- 回收站数据
- Nginx 配置
- systemd 服务文件
### 恢复备份
```bash
# 查看可用备份
ls -lh backups/
# 恢复指定备份
./scripts/restore.sh backups/write-server-20260101_120000.tar.gz
```
## 性能优化
### 1. Node.js 优化
```bash
# 使用 PM2 集群模式(多核 CPU)
pm2 start ecosystem.config.js -i max
# 或在 ecosystem.config.js 中修改
# instances: "max"
# exec_mode: "cluster"
```
### 2. Nginx 优化
在 nginx.conf 中添加:
```nginx
# 启用 Gzip
gzip on;
gzip_vary on;
gzip_min_length 1000;
gzip_types text/plain text/css application/json application/javascript;
# 缓存静态资源
location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg)$ {
expires 1y;
add_header Cache-Control "public, immutable";
}
```
### 3. 系统优化
```bash
# 增加文件描述符限制
sudo nano /etc/security/limits.conf
# 添加:
# your-user soft nofile 65536
# your-user hard nofile 65536
# 优化内核参数
sudo nano /etc/sysctl.conf
# 添加:
# net.core.somaxconn = 65535
# net.ipv4.tcp_max_syn_backlog = 65535
```
## 故障排查
### 常见问题
#### 1. 服务无法启动
```bash
# 查看详细错误
pm2 logs write-server --lines 100
# 或
sudo journalctl -u write-server -n 100
# 检查端口占用
lsof -i :8016
netstat -tulpn | grep 8016
```
#### 2. 无法访问博客内容
```bash
# 检查 BLOG_ROOT 配置
cat .env | grep BLOG_ROOT
# 检查目录权限
ls -la /path/to/blog
# 修复权限
sudo chown -R your-user:your-group /path/to/blog
```
#### 3. Hugo 预览失败
```bash
# 检查 Hugo 是否安装
hugo version
# 手动启动 Hugo 预览
cd /path/to/blog
hugo server -D
```
#### 4. 图片上传失败
```bash
# 检查目录权限
ls -la /path/to/blog/static
# 检查磁盘空间
df -h
# 检查文件大小限制(nginx.conf)
client_max_body_size 50m;
```
### 性能问题排查
```bash
# 查看 CPU 和内存使用
top
htop
# 查看 Node.js 进程
ps aux | grep node
# 查看网络连接
netstat -tulpn | grep 8016
# 查看磁盘 I/O
iotop
```
## 安全建议
1. **使用 HTTPS** - 配置 SSL 证书
2. **限制访问** - 配置防火墙和 Nginx 访问控制
3. **定期更新** - 保持系统和依赖更新
4. **强密码** - 使用强密码和 API Token
5. **备份加密** - 对备份文件进行加密
6. **日志审计** - 定期检查访问日志
7. **最小权限** - 使用非 root 用户运行服务
8. **Fail2ban** - 防止暴力破解攻击
## 更新升级
```bash
# 拉取最新代码
git pull origin main
# 安装新依赖
npm install
# 重新构建
npm run build
# 重启服务
pm2 restart write-server
# 或
sudo systemctl restart write-server
```
## 回滚版本
```bash
# 查看 Git 历史
git log --oneline
# 回滚到指定版本
git checkout <commit-hash>
# 重新部署
npm install
npm run build
pm2 restart write-server
```