mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-04 07:06:36 +08:00
feat: replace cert_dir with support_dir in agent and server configurations
- Updated README.md to reflect the new support_dir for auxiliary files. - Refactored agent main.go to use support_dir instead of cert_dir. - Modified config.go to replace cert_dir with support_dir and added legacy support. - Adjusted config tests to validate support_dir usage. - Changed nginx manager to utilize support_dir for file paths. - Updated server configuration to use support_dir for SSL certificates. - Revised documentation to clarify the new configuration parameters. - Enhanced security checks for support file paths to prevent traversal attacks.
This commit is contained in:
+9
-8
@@ -256,8 +256,8 @@ go run ./cmd/agent -config ./agent.json
|
||||
"openresty_path": "/usr/local/openresty/nginx/sbin/openresty",
|
||||
"main_config_path": "/usr/local/openresty/nginx/conf/nginx.conf",
|
||||
"route_config_path": "/usr/local/openresty/nginx/conf/conf.d/atsflare_routes.conf",
|
||||
"cert_dir": "/usr/local/openresty/nginx/conf/certs",
|
||||
"openresty_cert_dir": "/usr/local/openresty/nginx/conf/certs",
|
||||
"support_dir": "/usr/local/openresty/nginx/conf/support",
|
||||
"openresty_support_dir": "/usr/local/openresty/nginx/conf/support",
|
||||
"openresty_observability_port": 18081,
|
||||
"state_path": "./data/agent-state.json",
|
||||
"heartbeat_interval": 10000,
|
||||
@@ -282,8 +282,8 @@ go run ./cmd/agent -config ./agent.json
|
||||
| `data_dir` | Agent 数据目录,用于存储托管配置、证书和状态文件 | 否 | 配置文件所在目录下的 `data` 子目录 | `./data` |
|
||||
| `main_config_path` | 第五版主配置接管时 OpenResty 主配置文件写入路径 | 第五版本机模式建议必填 | Docker 模式可使用受管默认路径;本机模式建议显式设置 | `/usr/local/openresty/nginx/conf/nginx.conf` |
|
||||
| `route_config_path` | 路由配置文件写入路径 | 否 | 默认为 `data_dir` 下托管路径 | `/etc/nginx/conf.d/atsflare_routes.conf` |
|
||||
| `cert_dir` | Agent 在本机写入证书文件的目录 | 否 | 默认为 `data_dir` 下托管证书目录 | `./data/etc/nginx/certs` |
|
||||
| `openresty_cert_dir` | OpenResty 实际读取证书的目录 | 否 | 本机模式默认等于 `cert_dir`;Docker 模式默认 `/etc/nginx/atsflare-certs` | `/usr/local/openresty/nginx/conf/certs` |
|
||||
| `support_dir` | Agent 在本机写入受管附属文件的目录,当前包含证书与 Lua 观测脚本 | 否 | 默认为 `data_dir` 下托管 support 目录 | `./data/etc/nginx/support` |
|
||||
| `openresty_support_dir` | OpenResty 实际读取受管附属文件的目录 | 否 | 本机模式默认等于 `support_dir`;Docker 模式默认 `/etc/nginx/atsflare-support` | `/usr/local/openresty/nginx/conf/support` |
|
||||
| `state_path` | Agent 本地状态文件路径 | 否 | 默认为 `data_dir` 下托管状态文件 | `./data/agent-state.json` |
|
||||
| `heartbeat_interval` | 心跳间隔 | 否 | `10000` 毫秒 | `10000` |
|
||||
| `request_timeout` | HTTP 请求超时时间 | 否 | `10000` 毫秒 | `10000` |
|
||||
@@ -297,6 +297,7 @@ go run ./cmd/agent -config ./agent.json
|
||||
* `node_name` 与 `node_ip` 未填写时会自动探测;若自动探测失败,配置校验会报错
|
||||
* 未配置 `openresty_path` 时,默认为 Docker OpenResty 模式
|
||||
* `openresty_observability_port` 默认仅绑定本地回环地址;若节点本机已有端口冲突,可改为其他未占用端口
|
||||
* 为兼容旧节点,Agent 仍可读取历史字段 `cert_dir` / `openresty_cert_dir`,但保存配置时会统一写回 `support_dir` / `openresty_support_dir`
|
||||
* 配置保存时,`agent_version`、`nginx_version` 由程序运行时维护,不需要写入 JSON
|
||||
* 第五版主配置接管完成后,本机模式下应优先通过 `main_config_path` 由 Agent 写入受管主配置,而不是依赖节点手工维护 include 规则
|
||||
|
||||
@@ -308,14 +309,14 @@ go run ./cmd/agent -config ./agent.json
|
||||
| --- | --- |
|
||||
| `main_config_path` | 第五版 Docker 模式默认可落在 `data_dir/etc/nginx/nginx.conf`;本机模式建议显式配置 |
|
||||
| `route_config_path` | `data_dir/etc/nginx/conf.d/atsflare_routes.conf` |
|
||||
| `cert_dir` | `data_dir/etc/nginx/certs` |
|
||||
| `support_dir` | `data_dir/etc/nginx/support` |
|
||||
| `state_path` | `data_dir/var/lib/atsflare/agent-state.json` |
|
||||
|
||||
Docker OpenResty 模式下:
|
||||
|
||||
| 字段 | 默认值 |
|
||||
| --- | --- |
|
||||
| `openresty_cert_dir` | `/etc/nginx/atsflare-certs` |
|
||||
| `openresty_support_dir` | `/etc/nginx/atsflare-support` |
|
||||
|
||||
补充说明:
|
||||
|
||||
@@ -347,8 +348,8 @@ Docker OpenResty 模式下:
|
||||
"openresty_path": "/usr/local/openresty/nginx/sbin/openresty",
|
||||
"main_config_path": "/usr/local/openresty/nginx/conf/nginx.conf",
|
||||
"route_config_path": "/usr/local/openresty/nginx/conf/conf.d/atsflare_routes.conf",
|
||||
"cert_dir": "/usr/local/openresty/nginx/conf/certs",
|
||||
"openresty_cert_dir": "/usr/local/openresty/nginx/conf/certs"
|
||||
"support_dir": "/usr/local/openresty/nginx/conf/support",
|
||||
"openresty_support_dir": "/usr/local/openresty/nginx/conf/support"
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
+3
-3
@@ -263,7 +263,7 @@ export LOG_LEVEL='info'
|
||||
|
||||
验证点:
|
||||
|
||||
1. 首次启动后确认 `data/etc/nginx/nginx.conf`、`data/etc/nginx/conf.d/atsflare_routes.conf` 与 `data/etc/nginx/certs` 已由 Agent 创建
|
||||
1. 首次启动后确认 `data/etc/nginx/nginx.conf`、`data/etc/nginx/conf.d/atsflare_routes.conf` 与 `data/etc/nginx/support` 已由 Agent 创建
|
||||
2. 确认容器实际挂载了主配置、路由目录和证书目录
|
||||
3. 确认宿主机本地可访问 `http://127.0.0.1:18081/atsflare/observability` 与 `http://127.0.0.1:18081/atsflare/stub_status`
|
||||
3. 在管理端发布一次新版本后,确认节点 `current_version` 追平激活版本
|
||||
@@ -293,8 +293,8 @@ docker exec atsflare-openresty openresty -t
|
||||
"openresty_path": "/usr/local/openresty/nginx/sbin/openresty",
|
||||
"main_config_path": "/usr/local/openresty/nginx/conf/nginx.conf",
|
||||
"route_config_path": "/usr/local/openresty/nginx/conf/conf.d/atsflare_routes.conf",
|
||||
"cert_dir": "/usr/local/openresty/nginx/conf/certs",
|
||||
"openresty_cert_dir": "/usr/local/openresty/nginx/conf/certs",
|
||||
"support_dir": "/usr/local/openresty/nginx/conf/support",
|
||||
"openresty_support_dir": "/usr/local/openresty/nginx/conf/support",
|
||||
"openresty_observability_port": 18081
|
||||
}
|
||||
```
|
||||
|
||||
@@ -59,7 +59,7 @@
|
||||
|
||||
维护期内优先处理以下高风险或高敏感问题:
|
||||
|
||||
* Agent 写入 `support_files` 时缺少对目标路径必须位于 `cert_dir` 内的强约束,存在路径穿越风险
|
||||
* Agent 写入 `support_files` 时缺少对目标路径必须位于 `support_dir` 内的强约束,存在路径穿越风险
|
||||
* 手动上传 Server 二进制后会执行 `--version` 检测,属于高敏感执行链路,必须进一步加固
|
||||
|
||||
---
|
||||
@@ -106,7 +106,7 @@
|
||||
* 为 Agent 支持文件写入增加安全路径校验
|
||||
* 拒绝绝对路径
|
||||
* 拒绝 `..` 跳目录
|
||||
* 通过 `filepath.Rel` 或安全辅助函数确认最终路径仍位于 `cert_dir` 内
|
||||
* 通过 `filepath.Rel` 或安全辅助函数确认最终路径仍位于 `support_dir` 内
|
||||
* `writeSupportFiles`、`restore`、未来新增的写文件入口全部复用同一套安全函数
|
||||
* 收紧手动上传升级链路
|
||||
* 明确只允许 root 用户
|
||||
@@ -214,4 +214,4 @@
|
||||
|
||||
* 评估配置接口压缩与更细粒度 manifest 同步
|
||||
* 评估手动上传升级链路的更安全替代实现
|
||||
* 根据实际运行数据决定是否继续做更细的持久化优化
|
||||
* 根据实际运行数据决定是否继续做更细的持久化优化
|
||||
|
||||
Reference in New Issue
Block a user