upload+accessKey

This commit is contained in:
ryan
2026-06-07 21:21:06 +08:00
parent 360a26f109
commit 70a13dc107
35 changed files with 4763 additions and 1321 deletions
+53 -76
View File
@@ -1,88 +1,89 @@
# LINUX DO Credit Config
# Copy to config.yaml for runtime
# Refreshing — Full-Stack Boilerplate Config
# Copy this file to config.yaml and fill in your values.
# Fields marked with <...> are required; others have sensible defaults.
# App
# ─── Application ────────────────────────────────────────────────────────────────
app:
app_name: "linux-do-credit"
env: "development" # development, testing, production
app_name: "refreshing"
env: "development" # development | testing | production
addr: ":8000"
node_id: 1 # 分布式节点 ID (0-1023),不同实例必须不同
node_id: 1 # Snowflake node ID (0-1023). Must be unique per instance.
graceful_shutdown_timeout: 30
session_cookie_name: "linux_do_credit_session_id" # change this in local dev env
session_secret: "<uniq string>" # you can't change this after first time start
session_domain: ".linux.do"
session_age: 86400
session_cookie_name: "refreshing_session_id" # Change to something unique before deploy
session_secret: "<uniq-random-string>" # Cannot be changed after first start
session_domain: "" # e.g. ".yourdomain.com"
session_age: 86400 # Session lifetime in seconds (default: 24h)
session_secure: false
session_http_only: false
api_prefix: "/api"
frontend_url: "http://localhost:3000"
frontend_pay_url: "http://localhost:3000/paying"
# OAuth2/OIDC(优先)
# ─── Default OAuth2 / OIDC Provider (optional) ──────────────────────────────────
# You can configure additional OIDC providers at runtime via the admin panel.
oauth2:
client_id: "<OAUTH2_CLIENT_ID>"
client_secret: "<OAUTH2_CLIENT_SECRET>"
redirect_uri: "<OAUTH2_REDIRECT_URI>"
issuer: "https://connect.linux.do/" # OIDC Issuer URL,用于自动发现端点
authorization_endpoint: "https://connect.linux.do/oauth2/authorize"
token_endpoint: "https://connect.linux.do/oauth2/token"
user_endpoint: "https://connect.linux.do/api/user"
issuer: "" # OIDC Issuer URL for auto-discovery (recommended)
authorization_endpoint: "" # Leave empty if issuer is set
token_endpoint: ""
user_endpoint: ""
# DB
# 支持两种模式:Standalone(单节点)、Primary-Replica(读写分离)
# ─── PostgreSQL ─────────────────────────────────────────────────────────────────
# Supports Standalone and Primary-Replica (read/write split) modes.
database:
enabled: true
host: "127.0.0.1"
port: 5432
username: "postgres"
password: ""
database: "linux_do_credit"
database: "refreshing"
max_idle_conn: 16
max_open_conn: 128
conn_max_lifetime: 1800
conn_max_idle_time: 600
log_level: "info" # error, warn, info, debug, silent
log_level: "info" # error | warn | info | debug | silent
ssl_mode: "disable"
time_zone: "Asia/Shanghai"
application_name: "pay-server"
# pgb改为true,默认false
time_zone: "UTC"
application_name: "refreshing-server"
prefer_simple_protocol: false
search_path: "public"
statement_cache_capacity: 256
default_query_exec_mode: "cache_statement"
slow_threshold: 200ms
# Optional read replicas:
# replicas:
# - host: "replica1.db.local"
# - host: "replica1.db.internal"
# port: 5432
# - host: "replica2.db.local"
# - host: "replica2.db.internal"
# port: 5432
# clickhouse
# ─── ClickHouse (optional) ──────────────────────────────────────────────────────
clickhouse:
enabled: false
hosts:
- "127.0.0.1:9000"
username: "default"
password: ""
database: "linux_do_credit"
database: "refreshing"
max_idle_conn: 10
max_open_conn: 100
conn_max_lifetime: 3600
dial_timeout: 5
block_buffer_size: 10
# Redis
# 支持三种模式:Standalone(单节点)、Sentinel(高可用)、Cluster(水平扩展)
# ─── Redis ──────────────────────────────────────────────────────────────────────
# Supports Standalone, Sentinel (HA), and Cluster modes.
redis:
enabled: true
addrs:
- "127.0.0.1:6379"
username: ""
password: ""
db: 0 # Cluster 模式忽略此项
cluster_mode: false # true 启用 Cluster 模式
master_name: "" # 非空启用 Sentinel 模式
key_prefix: "credit:"
db: 0 # Ignored in Cluster mode
cluster_mode: false # Set true to enable Cluster mode
master_name: "" # Set non-empty to enable Sentinel mode
key_prefix: "refreshing:"
pool_size: 100
min_idle_conn: 10
dial_timeout: 5
@@ -92,28 +93,22 @@ redis:
pool_timeout: 4
conn_max_idle_time: 300
# Log
# ─── Logging ────────────────────────────────────────────────────────────────────
log:
level: "info" # debug, info, warn, error, fatal, panic
format: "json" # text, json
output: "stdout" # stdout, file
level: "info" # debug | info | warn | error | fatal | panic
format: "json" # text | json
output: "stdout" # stdout | file
file_path: "./logs/app.log"
max_size: 100
max_age: 30
max_size: 100 # MB per log file
max_age: 30 # Days to retain old log files
max_backups: 10
compress: true
# Scheduler
# ─── Task Scheduler (Cron) ──────────────────────────────────────────────────────
scheduler:
update_user_gamification_scores_task_cron: "0 2 * * *"
dispute_auto_refund_dispatch_interval_seconds: 3
auto_refund_expired_disputes_task_cron: "0 0 * * *"
sync_orders_to_clickhouse_task_cron: "10 0 * * *"
refund_expired_red_envelopes_task_cron: "0 1 * * *"
cleanup_unused_uploads_task_cron: "0 */2 * * *"
settle_pending_payments_task_cron: "0 * * * *"
cleanup_unused_uploads_task_cron: "0 */2 * * *" # Clean up orphaned upload records
# Worker
# ─── Async Task Worker ──────────────────────────────────────────────────────────
worker:
concurrency: 20
strict_priority: false
@@ -124,41 +119,23 @@ worker:
priority: 5
- name: default
priority: 3
# 积分更新速率限制:rate 次/period 秒
gamification_score_rate_limit:
rate: 1 # 允许的请求次数
period: 3 # 时间周期(秒)
# linuxDo
linuxDo:
api_key: "<LINUX_DO_API_KEY>"
# OpenAPI Risk
openapi_risk:
enabled: false
base_url: "https://audit.example.com"
username: "<OPENAPI_USERNAME>"
password: "<OPENAPI_PASSWORD>"
cache_ttl_seconds: 3600
prompt_risk_levels: []
block_risk_levels: []
# OpenTelemetry
# ─── OpenTelemetry Tracing ──────────────────────────────────────────────────────
otel:
sampling_rate: 0.1 # 采样率 0.0-1.0
sampling_rate: 0.1 # Trace sampling rate (0.0 – 1.0)
# S3 Compatible Storage
# 支持 AWS S3、MinIO、Cloudflare R2、腾讯 COS 等 S3 兼容存储
# ─── S3-Compatible File Storage ─────────────────────────────────────────────────
# Compatible with AWS S3, MinIO, Cloudflare R2, Tencent COS, etc.
s3:
enabled: true
endpoint: "https://<Account ID>.r2.cloudflarestorage.com"
enabled: false
endpoint: "https://<account-id>.r2.cloudflarestorage.com"
region: "auto"
bucket: "<Bucket Name>"
bucket: "<bucket-name>"
access_key_id: "<S3_ACCESS_KEY_ID>"
secret_access_key: "<S3_SECRET_ACCESS_KEY>"
path_style: false # MinIO 等自托管服务设为 true
key_prefix: "" # 对象 key 前缀,如 "uploads/",可用于分目录存储
cdn_url: "" # CDN 域名(如 https://cdn.example.com),为空则直接读 S3
path_style: false # Set true for self-hosted S3 (e.g. MinIO)
key_prefix: "" # Optional prefix for all object keys, e.g. "uploads/"
cdn_url: "" # CDN base URL (e.g. https://cdn.example.com); falls back to S3 if empty
local_cache:
enabled: false
cache_dir: "./s3_cache"