feat(pages): 支持 Remote 部署源同步

新增部署源配置与运行态模型、安全下载、租约续期、原子激活和失败补偿。

接入内部任务与脱敏前端交互,并阻止数据库 Trace 和日志展开敏感查询参数。
This commit is contained in:
deqiying
2026-07-19 17:36:51 +08:00
parent 4e8ec23264
commit 38b0516937
58 changed files with 9858 additions and 1075 deletions
+56 -16
View File
@@ -5,9 +5,11 @@
package httppool
import (
"context"
"crypto/tls"
"net"
"net/http"
"net/url"
"sync"
"time"
@@ -30,28 +32,66 @@ var (
once sync.Once
)
// TransportOptions configures the request-specific parts of a pooled HTTP
// transport. Pool sizes and timeout defaults remain managed by this package.
// A nil Proxy explicitly disables proxy use.
type TransportOptions struct {
Proxy func(*http.Request) (*url.URL, error)
DialContext func(context.Context, string, string) (net.Conn, error)
TLSClientConfig *tls.Config
ResponseHeaderTimeout time.Duration
TraceFilter func(*http.Request) bool
}
// NewTransport returns an independently configurable pooled transport wrapped
// with OTel instrumentation. The supplied TLS configuration is cloned before
// use so later caller mutations cannot change an active transport.
func NewTransport(options TransportOptions) http.RoundTripper {
dialContext := options.DialContext
if dialContext == nil {
dialContext = (&net.Dialer{
Timeout: dialTimeout,
KeepAlive: dialKeepAlive,
}).DialContext
}
tlsConfig := options.TLSClientConfig
if tlsConfig == nil {
tlsConfig = &tls.Config{}
} else {
tlsConfig = tlsConfig.Clone()
}
if tlsConfig.ClientSessionCache == nil {
tlsConfig.ClientSessionCache = tls.NewLRUClientSessionCache(tlsSessionCacheSize)
}
transport := &http.Transport{
Proxy: options.Proxy,
DialContext: dialContext,
ForceAttemptHTTP2: true,
MaxIdleConns: maxIdleConns,
MaxIdleConnsPerHost: maxIdleConnsPerHost,
IdleConnTimeout: idleConnTimeout,
TLSHandshakeTimeout: tlsHandshakeTimeout,
ResponseHeaderTimeout: options.ResponseHeaderTimeout,
ExpectContinueTimeout: expectContinueTimeout,
TLSClientConfig: tlsConfig,
}
otelOptions := make([]otelhttp.Option, 0, 1)
if options.TraceFilter != nil {
otelOptions = append(otelOptions, otelhttp.WithFilter(options.TraceFilter))
}
return otelhttp.NewTransport(transport, otelOptions...)
}
// DefaultTransport returns a globally shared, optimized http.RoundTripper
// with OTel instrumentation. It maintains a pool of idle TCP connections
// across hosts.
func DefaultTransport() http.RoundTripper {
once.Do(func() {
transport := &http.Transport{
defaultTransport = NewTransport(TransportOptions{
Proxy: http.ProxyFromEnvironment,
DialContext: (&net.Dialer{
Timeout: dialTimeout,
KeepAlive: dialKeepAlive,
}).DialContext,
ForceAttemptHTTP2: true,
MaxIdleConns: maxIdleConns,
MaxIdleConnsPerHost: maxIdleConnsPerHost,
IdleConnTimeout: idleConnTimeout,
TLSHandshakeTimeout: tlsHandshakeTimeout,
ExpectContinueTimeout: expectContinueTimeout,
TLSClientConfig: &tls.Config{
ClientSessionCache: tls.NewLRUClientSessionCache(tlsSessionCacheSize),
},
}
defaultTransport = otelhttp.NewTransport(transport)
})
})
return defaultTransport
}