Files
blog/deploy/cn-certkeeper/docker-compose.yml
T
zqlit 1427c47dcf feat(ssl): 证书签发链路搬到国内机 Docker,清理 1Panel 过期证书
架构定案(B+C):CF Worker 免费版 CPU 硬顶 10ms(cron 同),
不再购买 Paid($5/月≈¥36),改为——
  B. Worker 留免费版 + 代码优化(把 CPU 压进预算)
  C. 签发+部署整条链路搬国内机 Docker 容器

代码
- acme.ts: 缓存 signingKey 为 Promise,单次签发 importKey 12→1 次
  (实测 importKey 126µs / sign 84µs;一次签发 3.3ms → 1.4ms)
- deployer.ts: 新增 DogeCloudDeployer.ping();修正 cert_id → id 的注释
- dnsprovider.ts: 新增 RemoteDns(把 DNS-01 写 TXT 委托给国内机 cn-dns-helper)
- tools/certkeeper-config.mjs: 域名配置抽为唯一事实源(两个消费方共用)
- tools/export-certkeeper-data.mjs: 导出国内机数据目录

新增部署单元
- deploy/cn-certkeeper: 签发+部署容器(只绑 127.0.0.1:8019,compose 管理)
  含 FileKV(文件系统版 KVNamespace)、带鉴权 HTTP、每日 4:10 续期
- deploy/cn-dns-helper: DNS-01 写 TXT 助手(只绑 127.0.0.1:8018)

文档
- 函数版证书管家-方案.md 新增第九章:B+C 定案、实测 CPU 数据、
  容器验收记录、1Panel 过期证书清理记录、t-t.live 两套管理冲突
- 标注旧 8.3 节「免费版跑不了签发」为未实测误判

一并纳入:.gitignore 忽略 deploy/cn-certkeeper/lib/(tsc 编译产物)
2026-10-06 18:28:55 +08:00

37 lines
1.5 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
services:
cn-certkeeper:
build: /srv/cn-certkeeper
image: cn-certkeeper:local
container_name: cn-certkeeper
restart: unless-stopped
# ★ 只绑本机回环:容器内的 HOST 必须是 0.0.0.0,否则 -p 映射进不来
# (docker 的端口映射打的是容器 IP,不是容器内的 127.0.0.1)。
# 外部要访问就经 1Panel/openresty 反代,容器端口不直接对公网。
ports:
- "127.0.0.1:8019:8019"
environment:
# 时区:日志和「每日 4:10 续期」都按这个走,不设就成 UTC(差 8 小时)
TZ: Asia/Shanghai
DATA_DIR: /data
HOST: 0.0.0.0
PORT: "8019"
# AUTH_TOKEN:HTTP 接口的共享密钥(人工触发 / 查状态用)
AUTH_TOKEN: ${AUTH_TOKEN:?}
# TOKEN_SECRET:★ 必须与 Cloudflare Worker 侧**完全一致** ——
# 凭据是用它派生 AES 密钥加密的,不一致就整片解不开。
TOKEN_SECRET: ${TOKEN_SECRET:?}
# 每天 04:10(北京时间)跑一次续期检查
RENEW_HOUR: "4"
RENEW_MINUTE: "10"
# 启动时做一次只读探测(只握手看剩余天数,不签发、不写 DNS)
RUN_ON_START: check
PROBE_TIMEOUT_MS: "10000"
volumes:
- /srv/cn-certkeeper/data:/data
healthcheck:
test: ["CMD", "node", "-e", "fetch('http://127.0.0.1:8019/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"]
interval: 60s
timeout: 8s
retries: 3
start_period: 15s