diff --git a/.gitignore b/.gitignore index 0f0d5f13..077ebe52 100644 --- a/.gitignore +++ b/.gitignore @@ -44,9 +44,9 @@ go.work.sum .DS_Store .codex-cache -/.gomodcache/ -*.mmdb -!openflare_agent/internal/geoipdata/GeoLite2-Country.mmdb - -*-source -*-source.* +/.gomodcache/ +*.mmdb +!openflare_agent/internal/geoipdata/GeoLite2-Country.mmdb + +*-source +*-source.* diff --git a/README.md b/README.md index 227ead57..51f6a00c 100644 --- a/README.md +++ b/README.md @@ -2,11 +2,13 @@ # OpenFlare -轻量、自托管的 OpenResty 控制面,用于管理反向代理规则、配置发布、节点同步、TLS 证书与基础可观测能力。 +**[📖 English](./README.md) | [中文](./README.zh-CN.md)** + +A lightweight, self-hosted control plane for OpenResty that manages reverse proxy rules, configuration releases, node synchronization, TLS certificates, and observability. -

license @@ -19,34 +21,34 @@

> [!WARNING] -> 使用 `root` 用户初次登录系统后,务必修改默认密码 `123456`。 -> -> BETA 版本为开发测试阶段的临时产物,可能存在未知问题,请勿在生产环境使用。 +> After the first login with the `root` user, you **must** change the default password `123456`. +> +> This BETA version is a temporary product in the development and testing phase. It may contain unknown issues and should not be used in production environments. -## 文档 +## Documentation **https://open-flare.pages.dev** -常用入口: +Quick links: -* [快速开始](https://open-flare.pages.dev/guide/quick-start) -* [部署说明](https://open-flare.pages.dev/guide/deployment) -* [配置项参考](https://open-flare.pages.dev/reference/configuration) -* [系统设计](https://open-flare.pages.dev/design/) +* [Quick Start](https://open-flare.pages.dev/guide/quick-start) +* [Deployment Guide](https://open-flare.pages.dev/reference/deployment) +* [Configuration Reference](https://open-flare.pages.dev/reference/configuration) +* [System Design](https://open-flare.pages.dev/design/) -## 核心能力 +## Core Features -* 反向代理网站配置与多域名绑定 -* 配置预览、发布、激活与历史回滚 -* Agent 自动注册、心跳、同步、校验、reload 与失败回滚 -* OpenResty 主配置、性能参数、缓存参数与 Lua 资源托管 -* WAF 全局/自定义规则组,支持 IP/IP 段与国家级地域黑白名单 -* TLS 证书、域名资产、节点凭证与版本状态管理 -* 请求聚合、访问分析、资源快照、健康事件与节点详情 +* **Reverse Proxy Configuration**: Website management and multi-domain binding +* **Configuration Lifecycle**: Preview, release, activation, and historical rollback +* **Agent Management**: Auto-registration, heartbeat, sync, validation, reload, and failure rollback +* **OpenResty Administration**: Main configuration, performance tuning, caching, and Lua resource hosting +* **WAF Protection**: Global and custom rule groups with IP/CIDR and geographic blacklist/whitelist +* **Certificate Management**: TLS certificates, domain assets, node credentials, and version control +* **Observability**: Request aggregation, access analytics, resource snapshots, health events, and node metrics -## 快速开始 +## Quick Start -### 1. 启动 Server +### 1. Launch Server ```yaml services: @@ -87,22 +89,20 @@ volumes: docker compose up -d ``` -访问地址:`http://localhost:3000` +Access at: `http://localhost:3000` -默认账号: +Default credentials: -* 用户名:`root` -* 密码:`123456` +* Username: `root` +* Password: `123456` -### 2. 安装 Agent +### 2. Install Agent -安装 Agent 前请先在节点上安装 OpenResty,或改用内置 OpenResty 的 Agent Docker 镜像。 +Before installing an Agent, install OpenResty on the target node, or use the Docker image with OpenResty built-in. -你可以在控制面板的节点管理->详情->节点信息->节点标识与部署复制安装命令,或直接使用下面的脚本: +You can copy the installation command from the Dashboard → Node Management → Details → Node Info, or use the script below: -#### Docker 部署 - -Docker 部署可直接运行 Agent 镜像: +#### Docker Deployment ```bash docker pull ghcr.io/rain-kl/openflare-agent:latest @@ -114,9 +114,9 @@ docker run -d --name openflare-agent --restart unless-stopped \ ghcr.io/rain-kl/openflare-agent:latest ``` -#### 本地部署 +#### Local Installation -使用 `discovery_token` 接入: +Using `discovery_token`: ```bash curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \ @@ -124,7 +124,7 @@ curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/inst --discovery-token YOUR_DISCOVERY_TOKEN ``` -使用节点专属 `agent_token`: +Using node-specific `agent_token`: ```bash curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \ @@ -132,63 +132,62 @@ curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/inst --agent-token YOUR_AGENT_TOKEN ``` -安装脚本默认写入 `/opt/openflare-agent`,创建 `openflare-agent.service`,自动查找 `openresty`,并可重复执行以重装或升级 Agent。 +The installation script defaults to `/opt/openflare-agent`, creates a `openflare-agent.service`, auto-detects `openresty`, and supports re-execution for upgrades. -### 3. 卸载 Agent +### 3. Uninstall Agent -如需彻底卸载 Agent 并清空本地数据,可执行: +To completely uninstall the Agent and clean local data: ```bash curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/uninstall-agent.sh | bash ``` -卸载脚本会先停止并移除 `openflare-agent.service`、删除整个 `/opt/openflare-agent` 目录,不会删除本机 OpenResty。 +The uninstall script stops and removes the `openflare-agent.service`, deletes the `/opt/openflare-agent` directory, and does not remove OpenResty. -### 4. 发布第一份配置 +### 4. Deploy Your First Configuration -1. 登录管理端并新增反代规则 -2. 在发布前查看预览或变更摘要 -3. 激活新版本 -4. Agent 通过 WebSocket 通知或后续 heartbeat 拉取并应用配置 +1. Log in to the dashboard and create a reverse proxy rule +2. Preview changes or view the changelog before publishing +3. Activate the new version +4. Agents receive notifications via WebSocket or pull configuration on next heartbeat -版本号格式固定为 `YYYYMMDD-NNN`,历史版本不可变,回滚通过重新激活旧版本完成。 +Versions are immutable with format `YYYYMMDD-NNN`. Rollback is performed by reactivating a previous version. +## UI Preview -## 界面预览 - -### 仪表盘总览 +### Dashboard Overview ![OpenFlare dashboard overview](./docs/assets/readme/dashboard-overview.png) -### 节点详情 +### Node Details ![OpenFlare node detail](./docs/assets/readme/node-detail.png) -### 配置新增 +### Proxy Configuration ![OpenFlare version release](./docs/assets/readme/proxy-route-detail.png) -## 管理端与接口 +## Management Panel & API -管理端当前覆盖: +The management panel includes: -* 反代规则 -* 配置版本 -* 节点管理 -* 应用记录 -* TLS 证书 -* 域名管理 -* WAF 规则组 -* 用户管理 -* 设置 -* 版本更新 -* POW 规则 +* Reverse Proxy Rules +* Configuration Versions +* Node Management +* Application History +* TLS Certificates +* Domain Management +* WAF Rule Groups +* User Management +* Settings +* Version Updates +* POW Rules -登录管理端后,可访问 Swagger UI:`/swagger/index.html` +After logging in to the dashboard, access Swagger UI at: `/swagger/index.html` -## 开源协议 +## License -本项目采用 [Apache License 2.0](./LICENSE) 开源。 +This project is licensed under [Apache License 2.0](./LICENSE). ## Star History diff --git a/README.zh-CN.md b/README.zh-CN.md new file mode 100644 index 00000000..227ead57 --- /dev/null +++ b/README.zh-CN.md @@ -0,0 +1,201 @@ +
+ +# OpenFlare + +轻量、自托管的 OpenResty 控制面,用于管理反向代理规则、配置发布、节点同步、TLS 证书与基础可观测能力。 + +
+ +

+ license + + + release + + + ghcr + +

+ +> [!WARNING] +> 使用 `root` 用户初次登录系统后,务必修改默认密码 `123456`。 +> +> BETA 版本为开发测试阶段的临时产物,可能存在未知问题,请勿在生产环境使用。 + +## 文档 + +**https://open-flare.pages.dev** + +常用入口: + +* [快速开始](https://open-flare.pages.dev/guide/quick-start) +* [部署说明](https://open-flare.pages.dev/guide/deployment) +* [配置项参考](https://open-flare.pages.dev/reference/configuration) +* [系统设计](https://open-flare.pages.dev/design/) + +## 核心能力 + +* 反向代理网站配置与多域名绑定 +* 配置预览、发布、激活与历史回滚 +* Agent 自动注册、心跳、同步、校验、reload 与失败回滚 +* OpenResty 主配置、性能参数、缓存参数与 Lua 资源托管 +* WAF 全局/自定义规则组,支持 IP/IP 段与国家级地域黑白名单 +* TLS 证书、域名资产、节点凭证与版本状态管理 +* 请求聚合、访问分析、资源快照、健康事件与节点详情 + +## 快速开始 + +### 1. 启动 Server + +```yaml +services: + postgres: + image: postgres:17-alpine + restart: unless-stopped + environment: + POSTGRES_DB: openflare + POSTGRES_USER: openflare + POSTGRES_PASSWORD: replace-with-strong-password + volumes: + - postgres-data:/var/lib/postgresql/data + healthcheck: + test: ["CMD-SHELL", "pg_isready -U openflare -d openflare"] + interval: 10s + timeout: 5s + retries: 5 + + openflare: + image: ghcr.io/rain-kl/openflare:latest + restart: unless-stopped + depends_on: + postgres: + condition: service_healthy + ports: + - "3000:3000" + environment: + SESSION_SECRET: replace-with-random-string + DSN: postgres://openflare:replace-with-strong-password@postgres:5432/openflare?sslmode=disable + GIN_MODE: release + LOG_LEVEL: info + +volumes: + postgres-data: +``` + +```bash +docker compose up -d +``` + +访问地址:`http://localhost:3000` + +默认账号: + +* 用户名:`root` +* 密码:`123456` + +### 2. 安装 Agent + +安装 Agent 前请先在节点上安装 OpenResty,或改用内置 OpenResty 的 Agent Docker 镜像。 + +你可以在控制面板的节点管理->详情->节点信息->节点标识与部署复制安装命令,或直接使用下面的脚本: + +#### Docker 部署 + +Docker 部署可直接运行 Agent 镜像: + +```bash +docker pull ghcr.io/rain-kl/openflare-agent:latest +docker rm -f openflare-agent 2>/dev/null || true +docker run -d --name openflare-agent --restart unless-stopped \ + -p 80:80 -p 443:443 \ + -e OPENFLARE_SERVER_URL=http://your-server:3000 \ + -e OPENFLARE_AGENT_TOKEN=YOUR_AGENT_TOKEN \ + ghcr.io/rain-kl/openflare-agent:latest +``` + +#### 本地部署 + +使用 `discovery_token` 接入: + +```bash +curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \ + --server-url http://your-server:3000 \ + --discovery-token YOUR_DISCOVERY_TOKEN +``` + +使用节点专属 `agent_token`: + +```bash +curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \ + --server-url http://your-server:3000 \ + --agent-token YOUR_AGENT_TOKEN +``` + +安装脚本默认写入 `/opt/openflare-agent`,创建 `openflare-agent.service`,自动查找 `openresty`,并可重复执行以重装或升级 Agent。 + +### 3. 卸载 Agent + +如需彻底卸载 Agent 并清空本地数据,可执行: + +```bash +curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/uninstall-agent.sh | bash +``` + +卸载脚本会先停止并移除 `openflare-agent.service`、删除整个 `/opt/openflare-agent` 目录,不会删除本机 OpenResty。 + +### 4. 发布第一份配置 + +1. 登录管理端并新增反代规则 +2. 在发布前查看预览或变更摘要 +3. 激活新版本 +4. Agent 通过 WebSocket 通知或后续 heartbeat 拉取并应用配置 + +版本号格式固定为 `YYYYMMDD-NNN`,历史版本不可变,回滚通过重新激活旧版本完成。 + + +## 界面预览 + +### 仪表盘总览 + +![OpenFlare dashboard overview](./docs/assets/readme/dashboard-overview.png) + +### 节点详情 + +![OpenFlare node detail](./docs/assets/readme/node-detail.png) + +### 配置新增 + +![OpenFlare version release](./docs/assets/readme/proxy-route-detail.png) + +## 管理端与接口 + +管理端当前覆盖: + +* 反代规则 +* 配置版本 +* 节点管理 +* 应用记录 +* TLS 证书 +* 域名管理 +* WAF 规则组 +* 用户管理 +* 设置 +* 版本更新 +* POW 规则 + +登录管理端后,可访问 Swagger UI:`/swagger/index.html` + +## 开源协议 + +本项目采用 [Apache License 2.0](./LICENSE) 开源。 + +## Star History + + + + + + Star History Chart + + diff --git a/docker-compose.yaml b/docker-compose.yaml index 4f1636d6..cf9b87ff 100644 --- a/docker-compose.yaml +++ b/docker-compose.yaml @@ -36,16 +36,17 @@ services: extra_hosts: - "host.docker.internal:host-gateway" - openflared: + + openflare-flared: build: context: . dockerfile: openflared/Dockerfile - container_name: openflared - network_mode: host + container_name: openflare-flared + network_mode: "host" restart: unless-stopped + volumes: + - ./openflared/data/:/app/data environment: - OPENFLARE_SERVER_URL: http://host.docker.internal:3000 - OPENFLARE_TUNNEL_TOKEN: 85464eeb72c49abc430569d6b9c77f78 - LOG_LEVEL: "debug" - extra_hosts: - - "host.docker.internal:host-gateway" \ No newline at end of file + OPENFLARE_SERVER_URL: "http://host.docker.internal:3000" + OPENFLARE_TUNNEL_TOKEN: 4888482fd0e1e3331111e51a8db1333b + diff --git a/openflared/.gitignore b/openflared/.gitignore new file mode 100644 index 00000000..5fac6285 --- /dev/null +++ b/openflared/.gitignore @@ -0,0 +1 @@ +/data/ \ No newline at end of file