构建、部署与验收文档:Makefile、冒烟脚本、systemd/Caddy、决策与验收报告
- Makefile:web / sync-assets(go:embed 约束拷贝)/ build / linux / test / smoke / dev / vulncheck;版本信息 ldflags 注入 - scripts/smoke.sh:构建冒烟(§8.3-6)——起服务断言 SPA 资源 200 + 正确 MIME、meta 注入、安全头、私有不可见(19 项断言) - deploy:pure-note.service(沙箱加固)、每日 gc+backup 的 maint service/timer(03:00 Persistent)、Caddyfile 反代示例 - docs/decisions.md:35 条实施决策留档(D1–D35) - docs/acceptance.md:§9.3 检查单逐项证据、§13 测试组映射、 §12 里程碑门、浏览器端到端走查记录 - README.md:快速开始、测试、部署与升级/恢复 SOP
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
# deploy/Caddyfile — 反代示例(唯一可信代理,自动 TLS)
|
||||
# 程序监听 127.0.0.1:8080,Caddy 追加 X-Forwarded-For,
|
||||
# 服务端以 --behind-proxy 取 XFF 最右条目作为客户端 IP(§14)。
|
||||
example.com {
|
||||
encode zstd gzip
|
||||
reverse_proxy 127.0.0.1:8080
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
# /etc/systemd/system/pure-note-maint.service
|
||||
# 每日维护:先 gc(--commit)后备份(§10.3)
|
||||
[Unit]
|
||||
Description=Pure Note daily maintenance (gc + backup)
|
||||
After=pure-note.service
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
User=purenote
|
||||
ExecStart=/opt/pure-note/pure-note gc --data-dir /opt/pure-note/data --commit
|
||||
ExecStart=/opt/pure-note/pure-note backup --data-dir /opt/pure-note/data /backup/pure-note-%%F.db
|
||||
@@ -0,0 +1,10 @@
|
||||
# /etc/systemd/system/pure-note-maint.timer
|
||||
[Unit]
|
||||
Description=Daily Pure Note maintenance (gc + backup)
|
||||
|
||||
[Timer]
|
||||
OnCalendar=03:00
|
||||
Persistent=true
|
||||
|
||||
[Install]
|
||||
WantedBy=timers.target
|
||||
@@ -0,0 +1,26 @@
|
||||
# /etc/systemd/system/pure-note.service
|
||||
[Unit]
|
||||
Description=Pure Note - minimalist high-security private notes + blog
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
User=purenote
|
||||
WorkingDirectory=/opt/pure-note
|
||||
ExecStart=/opt/pure-note/pure-note serve --addr 127.0.0.1:8080 \
|
||||
--data-dir /opt/pure-note/data --behind-proxy
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
|
||||
# 沙箱加固(§10.2)
|
||||
NoNewPrivileges=true
|
||||
PrivateTmp=true
|
||||
ProtectSystem=strict
|
||||
ProtectHome=true
|
||||
ReadWritePaths=/opt/pure-note/data
|
||||
MemoryDenyWriteExecute=true
|
||||
ProtectKernelTunables=true
|
||||
ProtectControlGroups=true
|
||||
RestrictSUIDSGID=true
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user