diff --git a/write-server/Dockerfile b/write-server/Dockerfile index 67b9bd61..5ad4c57a 100644 --- a/write-server/Dockerfile +++ b/write-server/Dockerfile @@ -35,13 +35,13 @@ RUN npm run build FROM node:20-alpine AS runner WORKDIR /app -# Install specific Hugo version, git and su-exec +# Install specific Hugo version, git, ssh and su-exec ARG HUGO_VERSION=0.128.2 RUN wget -q https://github.com/gohugoio/hugo/releases/download/v${HUGO_VERSION}/hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz -O /tmp/hugo.tar.gz && \ tar -xzf /tmp/hugo.tar.gz -C /tmp && \ mv /tmp/hugo /usr/local/bin/hugo && \ rm /tmp/hugo.tar.gz && \ - apk add --no-cache git su-exec + apk add --no-cache git openssh-client su-exec # Create non-root user RUN addgroup --system --gid 1001 nodejs && \ diff --git a/write-server/docker-compose.yml b/write-server/docker-compose.yml index 4ea0d22a..3701a72e 100644 --- a/write-server/docker-compose.yml +++ b/write-server/docker-compose.yml @@ -12,7 +12,6 @@ services: restart: unless-stopped ports: - "8016:8016" - - "1313:1313" volumes: # Hugo 博客目录(必须)- 映射宿主机博客根目录到容器内 /blog - ..:/blog @@ -24,6 +23,8 @@ services: - ./backups:/app/backups # 环境变量文件 - ./.env:/app/.env:ro + # SSH 密钥(用于 git push) + - /root/.ssh:/home/nextjs/.ssh:ro environment: - NODE_ENV=production - PORT=8016 diff --git a/write-server/entrypoint.sh b/write-server/entrypoint.sh index 49ea21ff..469ae46d 100644 --- a/write-server/entrypoint.sh +++ b/write-server/entrypoint.sh @@ -27,5 +27,12 @@ su-exec nextjs git config --global user.name "Write Server" 2>/dev/null su-exec nextjs git config --global user.email "write@usj.cc" 2>/dev/null su-exec nextjs git config --global --add safe.directory /blog 2>/dev/null +# 修复 SSH 密钥权限 +if [ -d "/home/nextjs/.ssh" ]; then + chown -R nextjs:nodejs /home/nextjs/.ssh + chmod 700 /home/nextjs/.ssh 2>/dev/null + chmod 600 /home/nextjs/.ssh/* 2>/dev/null +fi + # 以 nextjs 用户启动应用 exec su-exec nextjs "$@" diff --git a/write-server/nginx/conf.d/write-server.conf b/write-server/nginx/conf.d/write-server.conf index fa499483..d15a402f 100644 --- a/write-server/nginx/conf.d/write-server.conf +++ b/write-server/nginx/conf.d/write-server.conf @@ -48,6 +48,15 @@ server { add_header Content-Type text/plain; } + # Hugo 预览代理(不需要认证) + location /preview/ { + auth_request off; + rewrite ^/preview/(.*)$ /$1 break; + proxy_pass http://write-server:1313; + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + } + # 所有其他请求通过 auth_request 验证 location / { auth_request /auth/internal; diff --git a/write-server/src/app/edit/[slug]/page.tsx b/write-server/src/app/edit/[slug]/page.tsx index 87039319..5f7a9838 100644 --- a/write-server/src/app/edit/[slug]/page.tsx +++ b/write-server/src/app/edit/[slug]/page.tsx @@ -73,8 +73,7 @@ export default function EditPostPage({ type="button" onClick={async () => { await fetch("/api/hugo"); - const previewBase = `${location.protocol}//${location.hostname}:1313`; - window.open(`${previewBase}/${post.frontMatter.slug}.html`, "_blank"); + window.open(`/preview/${post.frontMatter.slug}.html`, "_blank"); }} className="flex items-center gap-1.5 px-3 py-1.5 text-[12px] rounded-md border border-line text-muted hover:text-accent hover:border-accent/30 transition-colors" title="预览" diff --git a/write-server/src/app/page.tsx b/write-server/src/app/page.tsx index a89597a0..ced15b42 100644 --- a/write-server/src/app/page.tsx +++ b/write-server/src/app/page.tsx @@ -78,8 +78,7 @@ export default function HomePage() { const handlePreview = async (slug: string) => { await fetch("/api/hugo"); - const previewBase = `${location.protocol}//${location.hostname}:1313`; - window.open(`${previewBase}/${slug}.html`, "_blank"); + window.open(`/preview/${slug}.html`, "_blank"); }; const toggleSelect = (slug: string) => {