构建、部署与验收文档:Makefile、冒烟脚本、systemd/Caddy、决策与验收报告

- Makefile:web / sync-assets(go:embed 约束拷贝)/ build / linux /
  test / smoke / dev / vulncheck;版本信息 ldflags 注入
- scripts/smoke.sh:构建冒烟(§8.3-6)——起服务断言 SPA 资源 200 +
  正确 MIME、meta 注入、安全头、私有不可见(19 项断言)
- deploy:pure-note.service(沙箱加固)、每日 gc+backup 的
  maint service/timer(03:00 Persistent)、Caddyfile 反代示例
- docs/decisions.md:35 条实施决策留档(D1–D35)
- docs/acceptance.md:§9.3 检查单逐项证据、§13 测试组映射、
  §12 里程碑门、浏览器端到端走查记录
- README.md:快速开始、测试、部署与升级/恢复 SOP
This commit is contained in:
2026-09-08 08:15:02 +08:00
parent e9316c9169
commit 183676428e
9 changed files with 442 additions and 0 deletions
+26
View File
@@ -0,0 +1,26 @@
# /etc/systemd/system/pure-note.service
[Unit]
Description=Pure Note - minimalist high-security private notes + blog
After=network.target
[Service]
User=purenote
WorkingDirectory=/opt/pure-note
ExecStart=/opt/pure-note/pure-note serve --addr 127.0.0.1:8080 \
--data-dir /opt/pure-note/data --behind-proxy
Restart=on-failure
RestartSec=5
# 沙箱加固(§10.2)
NoNewPrivileges=true
PrivateTmp=true
ProtectSystem=strict
ProtectHome=true
ReadWritePaths=/opt/pure-note/data
MemoryDenyWriteExecute=true
ProtectKernelTunables=true
ProtectControlGroups=true
RestrictSUIDSGID=true
[Install]
WantedBy=multi-user.target