构建、部署与验收文档:Makefile、冒烟脚本、systemd/Caddy、决策与验收报告

- Makefile:web / sync-assets(go:embed 约束拷贝)/ build / linux /
  test / smoke / dev / vulncheck;版本信息 ldflags 注入
- scripts/smoke.sh:构建冒烟(§8.3-6)——起服务断言 SPA 资源 200 +
  正确 MIME、meta 注入、安全头、私有不可见(19 项断言)
- deploy:pure-note.service(沙箱加固)、每日 gc+backup 的
  maint service/timer(03:00 Persistent)、Caddyfile 反代示例
- docs/decisions.md:35 条实施决策留档(D1–D35)
- docs/acceptance.md:§9.3 检查单逐项证据、§13 测试组映射、
  §12 里程碑门、浏览器端到端走查记录
- README.md:快速开始、测试、部署与升级/恢复 SOP
This commit is contained in:
2026-09-08 08:15:02 +08:00
parent e9316c9169
commit 183676428e
9 changed files with 442 additions and 0 deletions
+7
View File
@@ -0,0 +1,7 @@
# deploy/Caddyfile — 反代示例(唯一可信代理,自动 TLS)
# 程序监听 127.0.0.1:8080,Caddy 追加 X-Forwarded-For,
# 服务端以 --behind-proxy 取 XFF 最右条目作为客户端 IP(§14)。
example.com {
encode zstd gzip
reverse_proxy 127.0.0.1:8080
}
+11
View File
@@ -0,0 +1,11 @@
# /etc/systemd/system/pure-note-maint.service
# 每日维护:先 gc(--commit)后备份(§10.3)
[Unit]
Description=Pure Note daily maintenance (gc + backup)
After=pure-note.service
[Service]
Type=oneshot
User=purenote
ExecStart=/opt/pure-note/pure-note gc --data-dir /opt/pure-note/data --commit
ExecStart=/opt/pure-note/pure-note backup --data-dir /opt/pure-note/data /backup/pure-note-%%F.db
+10
View File
@@ -0,0 +1,10 @@
# /etc/systemd/system/pure-note-maint.timer
[Unit]
Description=Daily Pure Note maintenance (gc + backup)
[Timer]
OnCalendar=03:00
Persistent=true
[Install]
WantedBy=timers.target
+26
View File
@@ -0,0 +1,26 @@
# /etc/systemd/system/pure-note.service
[Unit]
Description=Pure Note - minimalist high-security private notes + blog
After=network.target
[Service]
User=purenote
WorkingDirectory=/opt/pure-note
ExecStart=/opt/pure-note/pure-note serve --addr 127.0.0.1:8080 \
--data-dir /opt/pure-note/data --behind-proxy
Restart=on-failure
RestartSec=5
# 沙箱加固(§10.2)
NoNewPrivileges=true
PrivateTmp=true
ProtectSystem=strict
ProtectHome=true
ReadWritePaths=/opt/pure-note/data
MemoryDenyWriteExecute=true
ProtectKernelTunables=true
ProtectControlGroups=true
RestrictSUIDSGID=true
[Install]
WantedBy=multi-user.target