Files
ryan e7b8fb2f99 docs(i18n): 同步 24 篇旧英文文档与中文最新内容
guide 9 篇(quick-start/first-site/sso/troubleshooting/tunnel-usage/waf-usage/waf-ip-group-expr/credits/index)、deployment 7 篇(deployment/server/agent/relay/openflared/upgrade/index)、reference 3 篇(configuration/cli/index)、design 5 篇(architecture/agent-design/tunnel-design/waf-design/index)全部按中文最新版重写同步;waf-usage/waf-design 按新版 DAG 模型重写;修复 reference 中文锚点链接;vitepress 构建 43 个英文页面全绿
2026-08-16 23:27:18 +08:00

5.3 KiB

Deployment Guide

You will learn: OpenFlare's recommended deployment approaches, Server and Agent runtime requirements, source startup, integration steps, and upgrade/uninstall entries.

Production recommends PostgreSQL as the Server DB, with APP_SESSION_SECRET etc. configured via config.yaml or env vars. The full Docker Compose deployment requires Redis; ClickHouse is optional for massive access logs and observability time series (see the repo root docker-compose.yaml). The Agent supports both Docker deployment and a local install script; the Docker image bundles the OpenResty binary. Log-DB determination and switching: Log Store Decoupling.

Deployment Topology

Standard Reverse Proxy Traffic Path

Browser
  |
  v
OpenFlare Server :3000
  |
  | Agent API / heartbeat / config pull
  v
OpenFlare Agent
  |
  v
OpenResty binary
  |
  v
Origin service

Intranet Penetration Traffic Path

Browser
  |
  v
OpenResty (Agent, WAF/HTTPS termination)      <-- TunnelRelay node
  |
  | proxy_pass (127.0.0.1:{vhost_port})
  v
OpenFlareRelay (frps process)                 <-- TunnelRelay node
  |
  | frp tunnel protocol
  v
OpenFlared (frpc client)                      <-- intranet server
  |
  v
Internal Service (192.168.x.x)

Prerequisites

Hardware Recommendations

Component Reference (entry) Reference (production) Notes
Server control plane 1 core / 2 GB RAM / 20 GB disk 2 cores / 4 GB RAM / 50 GB+ disk expand disk by access-log retention and concurrent traffic
Agent data plane 1 core / 512 MB RAM / 2 GB disk 2 cores / 2 GB RAM / 10 GB+ disk expand by OpenResty concurrent proxy connections and WAF interception
Relay node 1 core / 1 GB RAM / 5 GB disk 2 cores / 2 GB RAM / 20 GB disk frps relay throughput limited by bandwidth and CPU
OpenFlared client 1 core / 256 MB RAM / 1 GB disk 1 core / 512 MB RAM / 5 GB disk runs independently in the intranet, tiny footprint

Docker Compose Server Deployment

The repo root provides a full docker-compose.yaml (PostgreSQL, Redis, ClickHouse, Jaeger).

curl -o .env.example https://raw.githubusercontent.com/Rain-kl/OpenFlare/refs/heads/main/.env.example
cp .env.example .env
# edit .env; at minimum change APP_SESSION_SECRET and the DB passwords
docker compose up -d
docker compose ps
docker compose logs -f openflare

First visit http://localhost:3000; default account admin / 12345678. Change the default password immediately after login.

Source Startup

First build the admin frontend:

cd frontend
corepack enable
pnpm install
pnpm build:embed

Then start the Server (repo root):

cp config.example.yaml config.yaml
export APP_SESSION_SECRET='replace-with-a-long-random-string'
# optional: use PostgreSQL
# export DB_HOST=127.0.0.1 DB_USERNAME=postgres DB_PASSWORD=postgres DB_NAME=openflare
go run main.go all

Listens on :3000 by default (controlled by app.addr in config.yaml or APP_ADDR).

Docker is the recommended Agent deployment. The Agent image is built on the OpenResty image, bundling the Agent controller and the OpenResty binary. Without an explicit node_ip, the Agent prefers fetching the real egress IP via a third-party API, avoiding registering the Docker bridge address as the node IP.

docker pull ghcr.io/rain-kl/openflare-agent:latest
docker rm -f openflare-agent 2>/dev/null || true
docker run -d --name openflare-agent --restart unless-stopped \
  -p 80:80 -p 443:443/tcp -p 443:443/udp \
  -v openflare-agent-pages:/data/var/lib/openflare/pages \
  -e OPENFLARE_SERVER_URL=http://your-server:3000 \
  -e OPENFLARE_AGENT_TOKEN=YOUR_AGENT_TOKEN \
  ghcr.io/rain-kl/openflare-agent:latest

The named volume openflare-agent-pages persists the Pages deployment dir; rebuilding the container doesn't require re-pulling static site packages.

Agent Access (script install)

Besides Docker, the install script can deploy the Agent to the local host. The script registers the low-privilege openflare service account and runs the systemd service as that user, using Linux Capabilities to safely listen on privileged ports 80/443.

Auto-register with discovery_token:

curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
  --server-url http://your-server:3000 \
  --discovery-token YOUR_DISCOVERY_TOKEN

With node-specific agent_token:

curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
  --server-url http://your-server:3000 \
  --agent-token YOUR_AGENT_TOKEN

Install script parameters:

Parameter Description
--server-url Server address, required
--discovery-token first-time auto-registration Token, one of two with --agent-token
--agent-token node-specific Token, one of two with --discovery-token
--install-dir install dir, default /opt/openflare-agent
--openresty-path OpenResty binary path; auto-finds openresty when omitted
--repo GitHub repo for downloading the Agent, default Rain-kl/OpenFlare
--no-service don't create the systemd service

Confirm state:

systemctl status openflare-agent
journalctl -u openflare-agent -f