mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-10 17:26:38 +08:00
[优化] 文档优化
This commit is contained in:
@@ -2,11 +2,13 @@
|
|||||||
|
|
||||||
# OpenFlare
|
# OpenFlare
|
||||||
|
|
||||||
轻量、自托管的 OpenResty 控制面,用于管理反向代理规则、配置发布、节点同步、TLS 证书与基础可观测能力。
|
**[📖 English](./README.md) | [中文](./README.zh-CN.md)**
|
||||||
|
|
||||||
|
A lightweight, self-hosted control plane for OpenResty that manages reverse proxy rules, configuration releases, node synchronization, TLS certificates, and observability.
|
||||||
|
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<p align="center
|
<p align="center">
|
||||||
<a href="https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/LICENSE">
|
<a href="https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/LICENSE">
|
||||||
<img src="https://img.shields.io/github/license/Rain-kl/OpenFlare?color=brightgreen" alt="license">
|
<img src="https://img.shields.io/github/license/Rain-kl/OpenFlare?color=brightgreen" alt="license">
|
||||||
</a>
|
</a>
|
||||||
@@ -19,34 +21,34 @@
|
|||||||
</p>
|
</p>
|
||||||
|
|
||||||
> [!WARNING]
|
> [!WARNING]
|
||||||
> 使用 `root` 用户初次登录系统后,务必修改默认密码 `123456`。
|
> After the first login with the `root` user, you **must** change the default password `123456`.
|
||||||
>
|
>
|
||||||
> BETA 版本为开发测试阶段的临时产物,可能存在未知问题,请勿在生产环境使用。
|
> This BETA version is a temporary product in the development and testing phase. It may contain unknown issues and should not be used in production environments.
|
||||||
|
|
||||||
## 文档
|
## Documentation
|
||||||
|
|
||||||
**https://open-flare.pages.dev**
|
**https://open-flare.pages.dev**
|
||||||
|
|
||||||
常用入口:
|
Quick links:
|
||||||
|
|
||||||
* [快速开始](https://open-flare.pages.dev/guide/quick-start)
|
* [Quick Start](https://open-flare.pages.dev/guide/quick-start)
|
||||||
* [部署说明](https://open-flare.pages.dev/guide/deployment)
|
* [Deployment Guide](https://open-flare.pages.dev/reference/deployment)
|
||||||
* [配置项参考](https://open-flare.pages.dev/reference/configuration)
|
* [Configuration Reference](https://open-flare.pages.dev/reference/configuration)
|
||||||
* [系统设计](https://open-flare.pages.dev/design/)
|
* [System Design](https://open-flare.pages.dev/design/)
|
||||||
|
|
||||||
## 核心能力
|
## Core Features
|
||||||
|
|
||||||
* 反向代理网站配置与多域名绑定
|
* **Reverse Proxy Configuration**: Website management and multi-domain binding
|
||||||
* 配置预览、发布、激活与历史回滚
|
* **Configuration Lifecycle**: Preview, release, activation, and historical rollback
|
||||||
* Agent 自动注册、心跳、同步、校验、reload 与失败回滚
|
* **Agent Management**: Auto-registration, heartbeat, sync, validation, reload, and failure rollback
|
||||||
* OpenResty 主配置、性能参数、缓存参数与 Lua 资源托管
|
* **OpenResty Administration**: Main configuration, performance tuning, caching, and Lua resource hosting
|
||||||
* WAF 全局/自定义规则组,支持 IP/IP 段与国家级地域黑白名单
|
* **WAF Protection**: Global and custom rule groups with IP/CIDR and geographic blacklist/whitelist
|
||||||
* TLS 证书、域名资产、节点凭证与版本状态管理
|
* **Certificate Management**: TLS certificates, domain assets, node credentials, and version control
|
||||||
* 请求聚合、访问分析、资源快照、健康事件与节点详情
|
* **Observability**: Request aggregation, access analytics, resource snapshots, health events, and node metrics
|
||||||
|
|
||||||
## 快速开始
|
## Quick Start
|
||||||
|
|
||||||
### 1. 启动 Server
|
### 1. Launch Server
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
services:
|
services:
|
||||||
@@ -87,22 +89,20 @@ volumes:
|
|||||||
docker compose up -d
|
docker compose up -d
|
||||||
```
|
```
|
||||||
|
|
||||||
访问地址:`http://localhost:3000`
|
Access at: `http://localhost:3000`
|
||||||
|
|
||||||
默认账号:
|
Default credentials:
|
||||||
|
|
||||||
* 用户名:`root`
|
* Username: `root`
|
||||||
* 密码:`123456`
|
* Password: `123456`
|
||||||
|
|
||||||
### 2. 安装 Agent
|
### 2. Install Agent
|
||||||
|
|
||||||
安装 Agent 前请先在节点上安装 OpenResty,或改用内置 OpenResty 的 Agent Docker 镜像。
|
Before installing an Agent, install OpenResty on the target node, or use the Docker image with OpenResty built-in.
|
||||||
|
|
||||||
你可以在控制面板的节点管理->详情->节点信息->节点标识与部署复制安装命令,或直接使用下面的脚本:
|
You can copy the installation command from the Dashboard → Node Management → Details → Node Info, or use the script below:
|
||||||
|
|
||||||
#### Docker 部署
|
#### Docker Deployment
|
||||||
|
|
||||||
Docker 部署可直接运行 Agent 镜像:
|
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
docker pull ghcr.io/rain-kl/openflare-agent:latest
|
docker pull ghcr.io/rain-kl/openflare-agent:latest
|
||||||
@@ -114,9 +114,9 @@ docker run -d --name openflare-agent --restart unless-stopped \
|
|||||||
ghcr.io/rain-kl/openflare-agent:latest
|
ghcr.io/rain-kl/openflare-agent:latest
|
||||||
```
|
```
|
||||||
|
|
||||||
#### 本地部署
|
#### Local Installation
|
||||||
|
|
||||||
使用 `discovery_token` 接入:
|
Using `discovery_token`:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
|
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
|
||||||
@@ -124,7 +124,7 @@ curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/inst
|
|||||||
--discovery-token YOUR_DISCOVERY_TOKEN
|
--discovery-token YOUR_DISCOVERY_TOKEN
|
||||||
```
|
```
|
||||||
|
|
||||||
使用节点专属 `agent_token`:
|
Using node-specific `agent_token`:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
|
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
|
||||||
@@ -132,63 +132,62 @@ curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/inst
|
|||||||
--agent-token YOUR_AGENT_TOKEN
|
--agent-token YOUR_AGENT_TOKEN
|
||||||
```
|
```
|
||||||
|
|
||||||
安装脚本默认写入 `/opt/openflare-agent`,创建 `openflare-agent.service`,自动查找 `openresty`,并可重复执行以重装或升级 Agent。
|
The installation script defaults to `/opt/openflare-agent`, creates a `openflare-agent.service`, auto-detects `openresty`, and supports re-execution for upgrades.
|
||||||
|
|
||||||
### 3. 卸载 Agent
|
### 3. Uninstall Agent
|
||||||
|
|
||||||
如需彻底卸载 Agent 并清空本地数据,可执行:
|
To completely uninstall the Agent and clean local data:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/uninstall-agent.sh | bash
|
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/uninstall-agent.sh | bash
|
||||||
```
|
```
|
||||||
|
|
||||||
卸载脚本会先停止并移除 `openflare-agent.service`、删除整个 `/opt/openflare-agent` 目录,不会删除本机 OpenResty。
|
The uninstall script stops and removes the `openflare-agent.service`, deletes the `/opt/openflare-agent` directory, and does not remove OpenResty.
|
||||||
|
|
||||||
### 4. 发布第一份配置
|
### 4. Deploy Your First Configuration
|
||||||
|
|
||||||
1. 登录管理端并新增反代规则
|
1. Log in to the dashboard and create a reverse proxy rule
|
||||||
2. 在发布前查看预览或变更摘要
|
2. Preview changes or view the changelog before publishing
|
||||||
3. 激活新版本
|
3. Activate the new version
|
||||||
4. Agent 通过 WebSocket 通知或后续 heartbeat 拉取并应用配置
|
4. Agents receive notifications via WebSocket or pull configuration on next heartbeat
|
||||||
|
|
||||||
版本号格式固定为 `YYYYMMDD-NNN`,历史版本不可变,回滚通过重新激活旧版本完成。
|
Versions are immutable with format `YYYYMMDD-NNN`. Rollback is performed by reactivating a previous version.
|
||||||
|
|
||||||
|
## UI Preview
|
||||||
|
|
||||||
## 界面预览
|
### Dashboard Overview
|
||||||
|
|
||||||
### 仪表盘总览
|
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
### 节点详情
|
### Node Details
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
### 配置新增
|
### Proxy Configuration
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
## 管理端与接口
|
## Management Panel & API
|
||||||
|
|
||||||
管理端当前覆盖:
|
The management panel includes:
|
||||||
|
|
||||||
* 反代规则
|
* Reverse Proxy Rules
|
||||||
* 配置版本
|
* Configuration Versions
|
||||||
* 节点管理
|
* Node Management
|
||||||
* 应用记录
|
* Application History
|
||||||
* TLS 证书
|
* TLS Certificates
|
||||||
* 域名管理
|
* Domain Management
|
||||||
* WAF 规则组
|
* WAF Rule Groups
|
||||||
* 用户管理
|
* User Management
|
||||||
* 设置
|
* Settings
|
||||||
* 版本更新
|
* Version Updates
|
||||||
* POW 规则
|
* POW Rules
|
||||||
|
|
||||||
登录管理端后,可访问 Swagger UI:`/swagger/index.html`
|
After logging in to the dashboard, access Swagger UI at: `/swagger/index.html`
|
||||||
|
|
||||||
## 开源协议
|
## License
|
||||||
|
|
||||||
本项目采用 [Apache License 2.0](./LICENSE) 开源。
|
This project is licensed under [Apache License 2.0](./LICENSE).
|
||||||
|
|
||||||
## Star History
|
## Star History
|
||||||
|
|
||||||
|
|||||||
+201
@@ -0,0 +1,201 @@
|
|||||||
|
<div align="center">
|
||||||
|
|
||||||
|
# OpenFlare
|
||||||
|
|
||||||
|
轻量、自托管的 OpenResty 控制面,用于管理反向代理规则、配置发布、节点同步、TLS 证书与基础可观测能力。
|
||||||
|
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<p align="center
|
||||||
|
<a href="https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/LICENSE">
|
||||||
|
<img src="https://img.shields.io/github/license/Rain-kl/OpenFlare?color=brightgreen" alt="license">
|
||||||
|
</a>
|
||||||
|
<a href="https://github.com/Rain-kl/OpenFlare/releases/latest">
|
||||||
|
<img src="https://img.shields.io/github/v/release/Rain-kl/OpenFlare?color=brightgreen&include_prereleases" alt="release">
|
||||||
|
</a>
|
||||||
|
<a href="https://github.com/Rain-kl/OpenFlare/pkgs/container/openflare">
|
||||||
|
<img src="https://img.shields.io/badge/GHCR-ghcr.io%2Frain--kl%2Fopenflare-brightgreen" alt="ghcr">
|
||||||
|
</a>
|
||||||
|
</p>
|
||||||
|
|
||||||
|
> [!WARNING]
|
||||||
|
> 使用 `root` 用户初次登录系统后,务必修改默认密码 `123456`。
|
||||||
|
>
|
||||||
|
> BETA 版本为开发测试阶段的临时产物,可能存在未知问题,请勿在生产环境使用。
|
||||||
|
|
||||||
|
## 文档
|
||||||
|
|
||||||
|
**https://open-flare.pages.dev**
|
||||||
|
|
||||||
|
常用入口:
|
||||||
|
|
||||||
|
* [快速开始](https://open-flare.pages.dev/guide/quick-start)
|
||||||
|
* [部署说明](https://open-flare.pages.dev/guide/deployment)
|
||||||
|
* [配置项参考](https://open-flare.pages.dev/reference/configuration)
|
||||||
|
* [系统设计](https://open-flare.pages.dev/design/)
|
||||||
|
|
||||||
|
## 核心能力
|
||||||
|
|
||||||
|
* 反向代理网站配置与多域名绑定
|
||||||
|
* 配置预览、发布、激活与历史回滚
|
||||||
|
* Agent 自动注册、心跳、同步、校验、reload 与失败回滚
|
||||||
|
* OpenResty 主配置、性能参数、缓存参数与 Lua 资源托管
|
||||||
|
* WAF 全局/自定义规则组,支持 IP/IP 段与国家级地域黑白名单
|
||||||
|
* TLS 证书、域名资产、节点凭证与版本状态管理
|
||||||
|
* 请求聚合、访问分析、资源快照、健康事件与节点详情
|
||||||
|
|
||||||
|
## 快速开始
|
||||||
|
|
||||||
|
### 1. 启动 Server
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
services:
|
||||||
|
postgres:
|
||||||
|
image: postgres:17-alpine
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
POSTGRES_DB: openflare
|
||||||
|
POSTGRES_USER: openflare
|
||||||
|
POSTGRES_PASSWORD: replace-with-strong-password
|
||||||
|
volumes:
|
||||||
|
- postgres-data:/var/lib/postgresql/data
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD-SHELL", "pg_isready -U openflare -d openflare"]
|
||||||
|
interval: 10s
|
||||||
|
timeout: 5s
|
||||||
|
retries: 5
|
||||||
|
|
||||||
|
openflare:
|
||||||
|
image: ghcr.io/rain-kl/openflare:latest
|
||||||
|
restart: unless-stopped
|
||||||
|
depends_on:
|
||||||
|
postgres:
|
||||||
|
condition: service_healthy
|
||||||
|
ports:
|
||||||
|
- "3000:3000"
|
||||||
|
environment:
|
||||||
|
SESSION_SECRET: replace-with-random-string
|
||||||
|
DSN: postgres://openflare:replace-with-strong-password@postgres:5432/openflare?sslmode=disable
|
||||||
|
GIN_MODE: release
|
||||||
|
LOG_LEVEL: info
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
postgres-data:
|
||||||
|
```
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker compose up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
访问地址:`http://localhost:3000`
|
||||||
|
|
||||||
|
默认账号:
|
||||||
|
|
||||||
|
* 用户名:`root`
|
||||||
|
* 密码:`123456`
|
||||||
|
|
||||||
|
### 2. 安装 Agent
|
||||||
|
|
||||||
|
安装 Agent 前请先在节点上安装 OpenResty,或改用内置 OpenResty 的 Agent Docker 镜像。
|
||||||
|
|
||||||
|
你可以在控制面板的节点管理->详情->节点信息->节点标识与部署复制安装命令,或直接使用下面的脚本:
|
||||||
|
|
||||||
|
#### Docker 部署
|
||||||
|
|
||||||
|
Docker 部署可直接运行 Agent 镜像:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker pull ghcr.io/rain-kl/openflare-agent:latest
|
||||||
|
docker rm -f openflare-agent 2>/dev/null || true
|
||||||
|
docker run -d --name openflare-agent --restart unless-stopped \
|
||||||
|
-p 80:80 -p 443:443 \
|
||||||
|
-e OPENFLARE_SERVER_URL=http://your-server:3000 \
|
||||||
|
-e OPENFLARE_AGENT_TOKEN=YOUR_AGENT_TOKEN \
|
||||||
|
ghcr.io/rain-kl/openflare-agent:latest
|
||||||
|
```
|
||||||
|
|
||||||
|
#### 本地部署
|
||||||
|
|
||||||
|
使用 `discovery_token` 接入:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
|
||||||
|
--server-url http://your-server:3000 \
|
||||||
|
--discovery-token YOUR_DISCOVERY_TOKEN
|
||||||
|
```
|
||||||
|
|
||||||
|
使用节点专属 `agent_token`:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
|
||||||
|
--server-url http://your-server:3000 \
|
||||||
|
--agent-token YOUR_AGENT_TOKEN
|
||||||
|
```
|
||||||
|
|
||||||
|
安装脚本默认写入 `/opt/openflare-agent`,创建 `openflare-agent.service`,自动查找 `openresty`,并可重复执行以重装或升级 Agent。
|
||||||
|
|
||||||
|
### 3. 卸载 Agent
|
||||||
|
|
||||||
|
如需彻底卸载 Agent 并清空本地数据,可执行:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/uninstall-agent.sh | bash
|
||||||
|
```
|
||||||
|
|
||||||
|
卸载脚本会先停止并移除 `openflare-agent.service`、删除整个 `/opt/openflare-agent` 目录,不会删除本机 OpenResty。
|
||||||
|
|
||||||
|
### 4. 发布第一份配置
|
||||||
|
|
||||||
|
1. 登录管理端并新增反代规则
|
||||||
|
2. 在发布前查看预览或变更摘要
|
||||||
|
3. 激活新版本
|
||||||
|
4. Agent 通过 WebSocket 通知或后续 heartbeat 拉取并应用配置
|
||||||
|
|
||||||
|
版本号格式固定为 `YYYYMMDD-NNN`,历史版本不可变,回滚通过重新激活旧版本完成。
|
||||||
|
|
||||||
|
|
||||||
|
## 界面预览
|
||||||
|
|
||||||
|
### 仪表盘总览
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
### 节点详情
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
### 配置新增
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
## 管理端与接口
|
||||||
|
|
||||||
|
管理端当前覆盖:
|
||||||
|
|
||||||
|
* 反代规则
|
||||||
|
* 配置版本
|
||||||
|
* 节点管理
|
||||||
|
* 应用记录
|
||||||
|
* TLS 证书
|
||||||
|
* 域名管理
|
||||||
|
* WAF 规则组
|
||||||
|
* 用户管理
|
||||||
|
* 设置
|
||||||
|
* 版本更新
|
||||||
|
* POW 规则
|
||||||
|
|
||||||
|
登录管理端后,可访问 Swagger UI:`/swagger/index.html`
|
||||||
|
|
||||||
|
## 开源协议
|
||||||
|
|
||||||
|
本项目采用 [Apache License 2.0](./LICENSE) 开源。
|
||||||
|
|
||||||
|
## Star History
|
||||||
|
|
||||||
|
<a href="https://www.star-history.com/?repos=Rain-kl%2FOpenFlare&type=date&legend=bottom-right">
|
||||||
|
<picture>
|
||||||
|
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/chart?repos=Rain-kl/OpenFlare&type=date&theme=dark&legend=top-left" />
|
||||||
|
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/chart?repos=Rain-kl/OpenFlare&type=date&legend=top-left" />
|
||||||
|
<img alt="Star History Chart" src="https://api.star-history.com/chart?repos=Rain-kl/OpenFlare&type=date&legend=top-left" />
|
||||||
|
</picture>
|
||||||
|
</a>
|
||||||
+9
-8
@@ -36,16 +36,17 @@ services:
|
|||||||
extra_hosts:
|
extra_hosts:
|
||||||
- "host.docker.internal:host-gateway"
|
- "host.docker.internal:host-gateway"
|
||||||
|
|
||||||
openflared:
|
|
||||||
|
openflare-flared:
|
||||||
build:
|
build:
|
||||||
context: .
|
context: .
|
||||||
dockerfile: openflared/Dockerfile
|
dockerfile: openflared/Dockerfile
|
||||||
container_name: openflared
|
container_name: openflare-flared
|
||||||
network_mode: host
|
network_mode: "host"
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
volumes:
|
||||||
|
- ./openflared/data/:/app/data
|
||||||
environment:
|
environment:
|
||||||
OPENFLARE_SERVER_URL: http://host.docker.internal:3000
|
OPENFLARE_SERVER_URL: "http://host.docker.internal:3000"
|
||||||
OPENFLARE_TUNNEL_TOKEN: 85464eeb72c49abc430569d6b9c77f78
|
OPENFLARE_TUNNEL_TOKEN: 4888482fd0e1e3331111e51a8db1333b
|
||||||
LOG_LEVEL: "debug"
|
|
||||||
extra_hosts:
|
|
||||||
- "host.docker.internal:host-gateway"
|
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
/data/
|
||||||
Reference in New Issue
Block a user