mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-11 09:46:37 +08:00
[优化] 更新文档
This commit is contained in:
@@ -4,7 +4,7 @@
|
||||
|
||||
**[📖 English](./README.md) | [中文](./README.zh-CN.md)**
|
||||
|
||||
A lightweight, self-hosted control plane for OpenResty that manages reverse proxy rules, configuration releases, node synchronization, TLS certificates, and observability.
|
||||
OpenFlare is an open-source CDN orchestration and edge security platform. It supports reverse proxies, centralized configuration synchronization, secure intranet penetration (Tunnels), dynamic WAF protection, and anti-CC challenges.
|
||||
|
||||
</div>
|
||||
|
||||
@@ -21,9 +21,9 @@ A lightweight, self-hosted control plane for OpenResty that manages reverse prox
|
||||
</p>
|
||||
|
||||
> [!WARNING]
|
||||
> After the first login with the `root` user, you **must** change the default password `123456`.
|
||||
>
|
||||
> This BETA version is a temporary product in the development and testing phase. It may contain unknown issues and should not be used in production environments.
|
||||
> After logging in for the first time with the `root` user, make sure to change the default password `123456`.
|
||||
>
|
||||
> The BETA version is a temporary product for the development and testing phase. It may contain unknown issues and should not be used in production environments.
|
||||
|
||||
## Documentation
|
||||
|
||||
@@ -31,20 +31,22 @@ A lightweight, self-hosted control plane for OpenResty that manages reverse prox
|
||||
|
||||
Quick links:
|
||||
|
||||
* [Quick Start](https://open-flare.pages.dev/guide/quick-start)
|
||||
* [Deployment Guide](https://open-flare.pages.dev/reference/deployment)
|
||||
* [Quick Start](https://open-flare.pages.dev/en/guide/quick-start)
|
||||
* [Deployment Guide](https://open-flare.pages.dev/en/guide/deployment)
|
||||
* [Configuration Reference](https://open-flare.pages.dev/reference/configuration)
|
||||
* [System Design](https://open-flare.pages.dev/design/)
|
||||
|
||||
## Core Features
|
||||
|
||||
* **Reverse Proxy Configuration**: Website management and multi-domain binding
|
||||
* **Configuration Lifecycle**: Preview, release, activation, and historical rollback
|
||||
* **Agent Management**: Auto-registration, heartbeat, sync, validation, reload, and failure rollback
|
||||
* **OpenResty Administration**: Main configuration, performance tuning, caching, and Lua resource hosting
|
||||
* **WAF Protection**: Global and custom rule groups with IP/CIDR and geographic blacklist/whitelist
|
||||
* **Certificate Management**: TLS certificates, domain assets, node credentials, and version control
|
||||
* **Observability**: Request aggregation, access analytics, resource snapshots, health events, and node metrics
|
||||
* **Centralized Real-Time Config Sync**: Sync configurations across all nodes in real time via WebSockets and heartbeats with sub-second hot reload. Instantly retrieve alerts and statuses. No manual SSH login or online patching required.
|
||||
* **Distributed CDN Orchestration**: Orchestrate scattered and independent OpenResty nodes into a highly collaborative distributed Content Delivery Network (CDN) fleet, supporting website-level multi-domain aggregation, upstream Keepalive, and multi-origin load balancing.
|
||||
* **Secure Intranet Penetration (Tunnels)**: An open-source alternative to Cloudflare Tunnels. Expose local intranet services securely to the public network without a public IP or exposing inbound ports.
|
||||
* **Edge WAF Safety Protection**: Provides global and custom rule groups, supporting IP/CIDR filtering, MaxMind GeoIP country-level regional access control, asynchronous differential synchronization of IP group members without Nginx reloads, and custom block responses.
|
||||
* **Anti-CC & Human-Machine Challenge (PoW)**: Built-in high-performance client-side cryptographic Proof of Work challenges (similar to Turnstile) to block and intercept botnets and scrapers at the gateway edge in seconds.
|
||||
* **Publish & Sync Model**: Based on immutable configuration versions (`YYYYMMDD-NNN`), preview and compare differences before publishing, a single globally active version, and one-click sub-second rollbacks.
|
||||
* **Three-Stage Disaster Recovery & Rollback**: Supports automatic node backup rollback, a built-in safety fallback page (Port 80/503 keeping status monitoring and security interception active), and an abnormal configuration blocklist.
|
||||
* **Automated Certificate Hosting**: Supports dynamic certificate upload, automatic multi-domain certificate matching and binding, ACME automatic renewal, and full lifecycle status tracking.
|
||||
* **Unified Observability**: Aggregates node request counts, provides real-time access analysis, host/Nginx resource snapshots, health logs, and a re-upload buffer for network fluctuations.
|
||||
|
||||
## Quick Start
|
||||
|
||||
@@ -98,12 +100,14 @@ Default credentials:
|
||||
|
||||
### 2. Install Agent
|
||||
|
||||
Before installing an Agent, install OpenResty on the target node, or use the Docker image with OpenResty built-in.
|
||||
Before installing an Agent, please install OpenResty on the target node first, or use the Agent Docker image with OpenResty built-in.
|
||||
|
||||
You can copy the installation command from the Dashboard → Node Management → Details → Node Info, or use the script below:
|
||||
You can copy the installation command from **Node Management -> Details -> Node Info -> Node Token & Deployment** in the control panel, or directly use the scripts below:
|
||||
|
||||
#### Docker Deployment
|
||||
|
||||
For Docker deployment, you can directly run the Agent image:
|
||||
|
||||
```bash
|
||||
docker pull ghcr.io/rain-kl/openflare-agent:latest
|
||||
docker rm -f openflare-agent 2>/dev/null || true
|
||||
@@ -116,7 +120,7 @@ docker run -d --name openflare-agent --restart unless-stopped \
|
||||
|
||||
#### Local Installation
|
||||
|
||||
Using `discovery_token`:
|
||||
Using `discovery_token` to register:
|
||||
|
||||
```bash
|
||||
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
|
||||
@@ -132,26 +136,26 @@ curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/inst
|
||||
--agent-token YOUR_AGENT_TOKEN
|
||||
```
|
||||
|
||||
The installation script defaults to `/opt/openflare-agent`, creates a `openflare-agent.service`, auto-detects `openresty`, and supports re-execution for upgrades.
|
||||
The installation script defaults to `/opt/openflare-agent`, creates a `openflare-agent.service`, automatically searches for `openresty`, and can be executed repeatedly to reinstall or upgrade the Agent.
|
||||
|
||||
### 3. Uninstall Agent
|
||||
|
||||
To completely uninstall the Agent and clean local data:
|
||||
To completely uninstall the Agent and clear local data, run:
|
||||
|
||||
```bash
|
||||
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/uninstall-agent.sh | bash
|
||||
```
|
||||
|
||||
The uninstall script stops and removes the `openflare-agent.service`, deletes the `/opt/openflare-agent` directory, and does not remove OpenResty.
|
||||
The uninstallation script will stop and remove the `openflare-agent.service`, and delete the entire `/opt/openflare-agent` directory. It will not delete the local OpenResty installation.
|
||||
|
||||
### 4. Deploy Your First Configuration
|
||||
### 4. Publish Your First Configuration
|
||||
|
||||
1. Log in to the dashboard and create a reverse proxy rule
|
||||
2. Preview changes or view the changelog before publishing
|
||||
3. Activate the new version
|
||||
4. Agents receive notifications via WebSocket or pull configuration on next heartbeat
|
||||
1. Log in to the management panel and add a reverse proxy rule.
|
||||
2. View the preview or change summary before publishing.
|
||||
3. Activate the new version.
|
||||
4. Agents will receive the configuration and apply it via WebSocket notification or subsequent heartbeats.
|
||||
|
||||
Versions are immutable with format `YYYYMMDD-NNN`. Rollback is performed by reactivating a previous version.
|
||||
The version number format is fixed as `YYYYMMDD-NNN`. Historical versions are immutable, and rollback is achieved by reactivating an older version.
|
||||
|
||||
## UI Preview
|
||||
|
||||
@@ -174,7 +178,7 @@ The management panel includes:
|
||||
* Reverse Proxy Rules
|
||||
* Configuration Versions
|
||||
* Node Management
|
||||
* Application History
|
||||
* Application Records
|
||||
* TLS Certificates
|
||||
* Domain Management
|
||||
* WAF Rule Groups
|
||||
|
||||
Reference in New Issue
Block a user