ryan
e8778a8641
perf
2026-06-22 11:22:26 +08:00
ryan
7b14e15afb
refactor(frontend): simplify routing paths for certificates, dns-accounts and ip-groups
...
- Remove /websites prefix from TLS certificates and DNS accounts routes.
- Remove /waf prefix from IP groups route.
- Correct relative import paths for shared components.
2026-06-22 10:56:40 +08:00
ryan
3a2878d070
feat(api): integrate TLS certificate renewal into async task framework
...
Replace native goroutines in RenewCertificate logic with Asynq task dispatching to support queue execution, retry capability, and detailed task execution logs.
2026-06-22 10:54:15 +08:00
ryan
df3bcd3d19
perf
2026-06-21 14:51:08 +08:00
ryan
895dec208f
fix(agent): write nginx pid and temp dirs under data_dir for non-root runtime
...
OpenResty running as openflare can no longer write pid or client/proxy temp
paths under the OpenResty install prefix. Templates and apply-time rendering
now use __OPENFLARE_PID_PATH__ and __OPENFLARE_NGINX_CACHE_DIR__ under
data_dir/var/run and data_dir/var/cache/nginx, with legacy pid path patched
at apply. Consolidate runtimeuser path helpers into the main package file so
IDEs resolve references across build tags.
2026-06-21 14:40:10 +08:00
ryan
9d56f02e64
chore(agent): move docker entrypoint script to scripts/
...
Relocate agent-entrypoint.sh from docker/ to scripts/ so operational
shell scripts live in one directory and update Dockerfile.agent copy path.
2026-06-21 14:26:25 +08:00
ryan
40291136b7
fix(openresty): disable server version disclosure in main config template
...
Add server_tokens off to the default OpenResty main config template, seeded
option template, and agent safe fallback config so responses no longer
expose nginx/OpenResty version numbers in Server headers or error pages.
2026-06-21 14:25:32 +08:00
ryan
d3777eac2d
fix(agent): unify agent and openresty runtime user as openflare
...
Introduce the shared openflare service account for the agent process and
OpenResty workers, normalize data_dir ownership on startup, and ensure
managed paths are chowned with 0755/0644 during sync and apply. Docker
entrypoint fixes volume ownership before dropping privileges; local systemd
install runs the service as openflare with CAP_NET_BIND_SERVICE.
2026-06-21 14:25:20 +08:00
ryan
ee047cb351
修复 Pages 站点在未启用 SPA Fallback 时访问根路径 / 返回 404:OpenResty 渲染增加 location = / 精确匹配,通过 try_files 提供入口文件(index 指令在 try_files ... =404 场景下不会作用于根路径)。
2026-06-21 12:18:20 +08:00
ryan
6ed3c0c81f
收敛 Pages 部署包读取路径
2026-06-21 12:04:54 +08:00
ryan
13a375e042
修复 Agent 部署 Pages 问题
2026-06-21 11:53:54 +08:00
ryan
36f11c6ecb
修复代理路由详情认证配置 Tab:移除 PoW 配置(PoW 仅在 WAF 规则组中设置);保留 Basic Auth 保存能力;移除页头重复的「保存当前分区」按钮。
2026-06-21 11:28:50 +08:00
ryan
0f904b4b6d
修复代理路由详情认证配置 Tab:移除 PoW 配置(PoW 仅在 WAF 规则组中设置);保留 Basic Auth 保存能力;移除页头重复的「保存当前分区」按钮。
2026-06-21 11:26:37 +08:00
ryan
a4f6c2ae34
fix(frontend): cap envelope mismatch
2026-06-21 11:20:36 +08:00
ryan
e479ae75e6
修复 Pages 路由发布失败并报 pages module is not available:配置快照发布流程补齐 Pages 项目激活部署解析与 pages_deployment 写入。
2026-06-21 11:12:37 +08:00
ryan
6f267bbf21
修复仪表盘与节点详情「24 小时网络趋势」误按速率展示:改为 OpenResty 入/出站小时流量与近 24 小时总量摘要,Y 轴与 tooltip 自动换算 B/KB/MB/GB。
2026-06-21 11:08:25 +08:00
ryan
ce2b931a78
修复 Pages 上传或节点同步时报 pages file size out of bounds:允许 ZIP 包内的 0 字节文件,并兼容未声明解压大小的 ZIP 条目。
2026-06-21 10:55:48 +08:00
ryan
6e86901a58
修复节点详情 OpenResty 连接数与吞吐显示为「—」:节点可观测 API 将 OpenResty 观测数据合并进 metric_snapshots;指标文案改为「请求/分钟」(近 60 秒窗口),连接数为 0 时正常显示 0。
2026-06-21 10:52:06 +08:00
ryan
42896a8473
仪表盘「24 小时请求趋势」摘要误显示当前小时请求量/错误量:改为汇总近 24 小时总量
2026-06-21 10:43:26 +08:00
ryan
665dd09e11
fix: 修复 Pages 部署包上传报「请求超时,请稍后重试」
2026-06-21 10:39:08 +08:00
ryan
b12a9b0185
fix: 修复应用日志异常膨胀
2026-06-21 10:21:18 +08:00
ryan
a343c7a605
fix: 修复 Agent 使用 volume 映射时 PoW/WAF 运行时配置无法加载
2026-06-21 10:15:18 +08:00
ryan
117d473c27
fix: 修复 WAF 规则组保存/绑定网站时报 of_waf_rule_group_bindings_pkey 冲突
2026-06-20 22:05:30 +08:00
ryan
99f6f3231a
fix: 修复 WAF 规则组保存/绑定网站时报 of_waf_rule_group_bindings_pkey 冲突
2026-06-20 21:33:46 +08:00
ryan
b04a358e5e
fix: 配置版本列表按 created_at 倒序展示
2026-06-20 21:32:18 +08:00
ryan
6fc39d9e80
fix: 修复 WAF 规则组 PoW 策略发布后边缘不生效
2026-06-20 21:05:25 +08:00
ryan
889e79c8b8
fix: 收敛子代理站点标识双轨逻辑
2026-06-20 21:03:13 +08:00
ryan
9bf7e3cd1b
fix: 修复 WAF 规则组 PoW 策略发布后边缘不生效
2026-06-20 20:47:38 +08:00
ryan
8751c0dee3
fix(openflare): mmdb 国家名节点在世界地图使用正确质心
...
- 从 world-geo 生成国家质心表,Server 在仅有 ISO/国家名时补全 geo 坐标
- 全球态势板在缺少经纬度时按 geo_name 解析质心,避免 fallback 到美国
2026-06-20 19:46:33 +08:00
ryan
498a9ed3ff
fix(openflare): Agent 上报 IP 后由 Server 自动解析节点地理位置
...
- 启动时按 of_options.GeoIPProvider 初始化 pkg/geoip(bootstrap + runtime)
- mmdb 模式从内置 GeoLite2 种子到 data/;保存归属方式后热刷新 Provider
- Agent/Relay 心跳在服务端根据 IP 写入 geo 字段,尊重 geo_manual_override
- ipinfo 归属名称改为 City, Region, Country 可读格式
2026-06-20 19:36:17 +08:00
ryan
ec53629971
fix(frontend): 修复配置版本快照侧栏无法滚动
...
将快照与发布预览 Sheet 内容区改为 flex-1 min-h-0 overflow-y-auto,
并固定侧栏高度为 h-svh,与项目内其他可滚动 Sheet 一致。
2026-06-20 19:22:23 +08:00
ryan
6c46f5d24f
fix(openflare): Pages 部署包经 upload 存储下载
...
Agent 下载 Pages 包时统一通过 upload_id 走文件存储 API;legacy
artifact_path 仅用于一次性回填 upload 并清空路径。部署视图暴露
upload_id,并补充回归测试与 changelog。
2026-06-20 19:21:12 +08:00
ryan
e077b12328
fix(frontend): cap envelope mismatch
2026-06-20 19:04:55 +08:00
ryan
570b639e07
fix(agent): commit GeoLite2 mmdb as build fallback
...
Vendor GeoLite2-Country.mmdb in the repository so agent builds still
work when the remote download is unavailable. Update the fetch script
and agent Dockerfile to prefer a fresh download and fall back to the
committed database file.
2026-06-20 14:04:42 +08:00
ryan
3a368119e5
fix(ci): fetch GeoLite2 mmdb before agent build
...
Agent embeds GeoLite2-Country.mmdb but the file is not checked into the
repository. Download it in CI, Docker, and Makefile build paths via
scripts/fetch-agent-geoip-mmdb.sh, and correct the gitignore exception
path for the geoipdata package.
2026-06-20 14:03:43 +08:00
ryan
6e6bce6a03
Optimize CI
2026-06-20 13:53:54 +08:00
ryan
6975a6c290
sync ci
2026-06-20 13:44:24 +08:00
ryan
ef5d5b46af
chore(release): bump version to v1.3.1
...
### 🛠 修复
- 修复了风控中间件测试在 ClickHouse 批写架构迁移后无法正确初始化的问题。
- 修复了 OpenTelemetry trace provider 初始化时 semconv Schema URL 版本冲突导致进程无法启动的问题。
### ⚡ ️ 优化与改进
- 新增 ClickHouse 独立 OLAP 管线,以 goose 迁移作为唯一 schema 来源,并抽取 analytics repository 统一访问日志读写。
- 新增通用 ClickHouse batchwriter 批量写入框架,支持各业务域独立缓冲 flush 管道与默认批处理调优。
- 风控访问日志与管理端日志查询改为经 repository 层批写与查询,移除内联 SQL 与手动 DDL 维护路径。
- OAuth Access Token 与会话校验引入 RAM+Redis 缓存,降低高频鉴权路径的数据库读取压力。
- 上传元数据、Auth Source 与系统配置批量读取接入三层缓存(RAM→Redis→DB),并通过 pub/sub 支持多节点失效同步。
- 上传统计增量更新收敛为单事务写入,减少 ingest/remove 路径的锁竞争与统计偏差风险。
- ClickHouse 迁移与连接初始化增加进程隔离,避免与主库迁移互相阻塞。
- 引入 lifecycle 优雅停机钩子,确保进程退出前 flush 批写缓冲与释放资源。
### 💄 其他/体验
- 新增 cache-framework 与 clickhouse-batchwriter 开发技能,并更新 AGENTS.md Skill 关联索引。
- 登录与 Token 校验路径增加缓存预热,缩短冷启动后首次鉴权延迟。
2026-06-20 11:20:11 +08:00
ryan
a1f6459c09
fix(trace): 使用 NewSchemaless 避免 semconv schema 版本冲突
...
业务 Resource 改为 NewSchemaless 合并,继承 resource.Default() 的 SDK 内置
schema URL,不再硬编码 semconv 版本路径。
2026-06-20 11:20:01 +08:00
ryan
280bb63cbd
chore(release): bump version to v1.3.1
...
### 🛠 修复
- 修复了风控中间件测试在 ClickHouse 批写架构迁移后无法正确初始化的问题。
### ⚡ ️ 优化与改进
- 新增 ClickHouse 独立 OLAP 管线,以 goose 迁移作为唯一 schema 来源,并抽取 analytics repository 统一访问日志读写。
- 新增通用 ClickHouse batchwriter 批量写入框架,支持各业务域独立缓冲 flush 管道与默认批处理调优。
- 风控访问日志与管理端日志查询改为经 repository 层批写与查询,移除内联 SQL 与手动 DDL 维护路径。
- OAuth Access Token 与会话校验引入 RAM+Redis 缓存,降低高频鉴权路径的数据库读取压力。
- 上传元数据、Auth Source 与系统配置批量读取接入三层缓存(RAM→Redis→DB),并通过 pub/sub 支持多节点失效同步。
- 上传统计增量更新收敛为单事务写入,减少 ingest/remove 路径的锁竞争与统计偏差风险。
- ClickHouse 迁移与连接初始化增加进程隔离,避免与主库迁移互相阻塞。
- 引入 lifecycle 优雅停机钩子,确保进程退出前 flush 批写缓冲与释放资源。
### 💄 其他/体验
- 新增 cache-framework 与 clickhouse-batchwriter 开发技能,并更新 AGENTS.md Skill 关联索引。
- 登录与 Token 校验路径增加缓存预热,缩短冷启动后首次鉴权延迟。
2026-06-20 10:51:27 +08:00
ryan
f52c8db21a
perf(cache): 三层缓存框架补强
...
- 新增 cache-framework skill,规范 RAM→Redis→DB 读路径、失效与 pub/sub
- 上传元数据 Otter+Redis 缓存与多节点失效;Auth Source 缓存与 pub/sub
- ListSystemConfigsByKeys 补 Redis 层;上传统计单事务;登录/Token 缓存预热
- cleanup 任务补 upload meta 失效钩子
2026-06-20 10:20:35 +08:00
ryan
cdac1f8a45
perf(cache): 三层缓存框架补强
...
- 新增 cache-framework skill,规范 RAM→Redis→DB 读路径、失效与 pub/sub
- 上传元数据 Otter+Redis 缓存与多节点失效;Auth Source 缓存与 pub/sub
- ListSystemConfigsByKeys 补 Redis 层;上传统计单事务;登录/Token 缓存预热
- cleanup 任务补 upload meta 失效钩子
2026-06-20 10:20:23 +08:00
ryan
8c872f9b32
refactor(bootstrap): 引入解耦的全局生命周期管理器以隔离业务停机钩子
...
- 新建 internal/lifecycle 包,提供全局线程安全的 Shutdown 钩子注册与调度能力。
- 在 chwriter 与 risk_control 初始化阶段通过 OnShutdown 将其 Stop 函数注册到管理器中。
- bootstrap.Stop() 函数仅委托调用 lifecycle.Stop(),不再硬编码引入业务包,防止后续框架同步产生合并冲突。
2026-06-20 09:58:59 +08:00
ryan
d490030b75
fix: test
2026-06-20 09:58:37 +08:00
ryan
200525a1ab
perf: refactor
2026-06-20 09:54:48 +08:00
ryan
cac6e88bc0
perf: refactor
2026-06-20 09:46:29 +08:00
ryan
080be1e03a
perf: access token cache
2026-06-20 09:46:29 +08:00
ryan
2a0ebd16fa
fix(backend): 修复优雅停机失效、系统设置并发读写冲突、文件服务API信封绕过以及测试uploads目录污染
...
- 修复 ClickHouse Batch Writer 与 RiskControl LogWriter 优雅停机,确保退出前队列数据正确刷盘。
- 修复 OpenFlare 系统配置参数全局变量并发读写的 Data Race 冲突,在读取配置时引入读锁保护。
- 修复 upload 模块的 API 错误响应格式,使用 response.Abort* 代替原始的 c.AbortWithStatus 与 c.JSON,保证全局信封格式统一。
- 修复 pkg/utils/network 的 isPrivateIPv4 以使用标准库 net.IP.IsPrivate() 校验,修复 format 的 Bytes2Size 边界,修改大小单位因子变量为只读常量。
- 重构 upload 文件服务与路由器测试,使用 t.TempDir() 代替硬编码的 uploads 相对路径写入和删除,解决测试目录文件污染问题。
2026-06-20 09:33:42 +08:00
ryan
b3a55d4ab5
refactor(core): optimize performance, fix concurrency and clean up AGENTS.md design violations
...
- Concurrency: Added lock protection to WebSocket writes, fixed timer leaks, and prevented config cache listener context leaks.
- Performance: Added memory cache in ObservabilityBufferStore, periodic cleaning in CH Deduplicator, and buffered ZIP batch download writes.
- Design: Introduced Redis caching for OAuth session/tokens, sanitized raw DB error messages, segregated handlers and logics, and standard CAP response envelopes.
2026-06-20 09:09:02 +08:00
ryan
5bed2bae9f
migrate database
2026-06-19 22:18:52 +08:00