Files
blog/write-server/DEPLOYMENT.md
T
2026-06-21 20:42:44 +08:00

690 lines
11 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Write Server Linux 部署指南
本文档提供详细的 Linux 部署步骤,包括手动部署、Docker 部署和 systemd 配置。
## 目录
- [系统要求](#系统要求)
- [快速开始](#快速开始)
- [手动部署](#手动部署)
- [Docker 部署](#docker-部署)
- [Nginx 配置](#nginx-配置)
- [SSL 证书配置](#ssl-证书配置)
- [systemd 服务配置](#systemd-服务配置)
- [防火墙配置](#防火墙配置)
- [监控和日志](#监控和日志)
- [备份策略](#备份策略)
- [性能优化](#性能优化)
- [故障排查](#故障排查)
## 系统要求
### 最低配置
- **操作系统**: Ubuntu 20.04+, Debian 11+, CentOS 8+, RHEL 8+
- **CPU**: 1 核
- **内存**: 512MB
- **磁盘**: 10GB
- **Node.js**: 18+ (推荐 20 LTS)
- **Hugo**: 0.116+ (extended 版本)
### 推荐配置
- **CPU**: 2 核
- **内存**: 2GB
- **磁盘**: 50GB(取决于博客内容量)
- **Node.js**: 20 LTS
- **Hugo**: 0.128+
## 快速开始
### 方式一:一键安装(推荐)
```bash
# 1. 克隆项目
git clone <your-repo-url>
cd write-server
# 2. 运行安装脚本
chmod +x scripts/*.sh
./scripts/install.sh
# 3. 配置环境变量
cp .env.example .env
nano .env
# 4. 启动服务
./scripts/start.sh
```
### 方式二:Docker 快速启动
```bash
# 1. 克隆项目
git clone <your-repo-url>
cd write-server
# 2. 配置环境变量
cp .env.example .env
nano .env
# 3. 启动 Docker 容器
docker-compose up -d
# 4. 查看日志
docker-compose logs -f
```
## 手动部署
### 1. 安装系统依赖
#### Ubuntu/Debian
```bash
# 更新系统
sudo apt update
sudo apt upgrade -y
# 安装基础工具
sudo apt install -y curl wget git build-essential
# 安装 Node.js 20
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs
# 验证安装
node --version
npm --version
# 安装 Hugo
HUGO_VERSION="0.128.2"
wget https://github.com/gohugoio/hugo/releases/download/v${HUGO_VERSION}/hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz
tar -xzf hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz
sudo mv hugo /usr/local/bin/
rm hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz
# 验证 Hugo
hugo version
# 安装 PM2
sudo npm install -g pm2
```
#### CentOS/RHEL/Fedora
```bash
# 更新系统
sudo yum update -y
# 安装基础工具
sudo yum install -y curl wget git gcc-c++ make
# 安装 Node.js 20
curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash -
sudo yum install -y nodejs
# 验证安装
node --version
npm --version
# 安装 Hugo(同上)
# 安装 PM2
sudo npm install -g pm2
```
### 2. 部署应用
```bash
# 克隆项目
git clone <your-repo-url>
cd write-server
# 安装依赖
npm install
# 配置环境变量
cp .env.example .env
nano .env # 编辑配置
# 构建项目
npm run build
# 创建必要目录
mkdir -p logs backups recycle
# 启动服务
pm2 start ecosystem.config.js
```
### 3. 验证部署
```bash
# 检查进程状态
pm2 status
# 查看日志
pm2 logs write-server
# 测试访问
curl http://localhost:8016/api/stats
```
## Docker 部署
### 1. 安装 Docker
```bash
# Ubuntu/Debian
sudo apt install -y docker.io docker-compose
sudo systemctl start docker
sudo systemctl enable docker
sudo usermod -aG docker $USER
# CentOS/RHEL
sudo yum install -y docker
sudo systemctl start docker
sudo systemctl enable docker
sudo usermod -aG docker $USER
# 重新登录以应用组权限
```
### 2. 配置环境变量
```bash
cp .env.example .env
nano .env
```
**必填配置:**
```bash
BLOG_ROOT=/path/to/your/hugo/blog # 宿主机上的博客路径
PORT=8016
```
### 3. 启动容器
```bash
# 构建并启动
docker-compose up -d
# 查看状态
docker-compose ps
# 查看日志
docker-compose logs -f
```
### 4. 管理容器
```bash
# 停止容器
docker-compose down
# 重启容器
docker-compose restart
# 进入容器
docker exec -it write-server sh
# 查看资源使用
docker stats write-server
```
## Nginx 配置
### 1. 安装 Nginx
```bash
# Ubuntu/Debian
sudo apt install -y nginx
# CentOS/RHEL
sudo yum install -y nginx
```
### 2. 配置反向代理
```bash
# 复制配置文件
sudo cp nginx/conf.d/write-server.conf /etc/nginx/conf.d/
# 编辑配置
sudo nano /etc/nginx/conf.d/write-server.conf
```
**修改内容:**
```nginx
server {
listen 80;
server_name write.your-domain.com; # 替换为你的域名
location / {
proxy_pass http://127.0.0.1:8016;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
```
### 3. 测试并重启 Nginx
```bash
# 测试配置
sudo nginx -t
# 重启 Nginx
sudo systemctl restart nginx
sudo systemctl enable nginx
```
## SSL 证书配置
### 使用 Let's Encrypt(免费)
```bash
# 安装 Certbot
sudo apt install -y certbot python3-certbot-nginx
# 获取证书
sudo certbot --nginx -d write.your-domain.com
# 自动续期测试
sudo certbot renew --dry-run
# 设置自动续期
sudo crontab -e
# 添加:0 12 * * * /usr/bin/certbot renew --quiet
```
### 手动配置 SSL
```nginx
server {
listen 443 ssl http2;
server_name write.your-domain.com;
ssl_certificate /etc/nginx/ssl/fullchain.pem;
ssl_certificate_key /etc/nginx/ssl/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
location / {
proxy_pass http://127.0.0.1:8016;
# ... 其他代理配置
}
}
# HTTP 重定向
server {
listen 80;
server_name write.your-domain.com;
return 301 https://$server_name$request_uri;
}
```
## systemd 服务配置
### 1. 创建服务文件
```bash
sudo cp systemd/write-server.service /etc/systemd/system/
# 编辑服务文件
sudo nano /etc/systemd/system/write-server.service
```
**修改以下配置:**
```ini
[Unit]
Description=Write Server - Hugo Blog Admin
After=network.target
[Service]
Type=simple
User=your-username # 修改为你的用户名
Group=your-group # 修改为你的用户组
WorkingDirectory=/path/to/write-server # 修改为项目路径
Environment=NODE_ENV=production
Environment=PORT=8016
EnvironmentFile=/path/to/write-server/.env # 修改为 .env 路径
ExecStart=/usr/bin/node /path/to/write-server/.next/standalone/server.js
Restart=always
RestartSec=10
[Install]
WantedBy=multi-user.target
```
### 2. 启用并启动服务
```bash
# 重新加载 systemd
sudo systemctl daemon-reload
# 启用服务(开机自启)
sudo systemctl enable write-server
# 启动服务
sudo systemctl start write-server
# 检查状态
sudo systemctl status write-server
```
### 3. 管理服务
```bash
# 启动服务
sudo systemctl start write-server
# 停止服务
sudo systemctl stop write-server
# 重启服务
sudo systemctl restart write-server
# 查看状态
sudo systemctl status write-server
# 查看日志
sudo journalctl -u write-server -f
```
## 防火墙配置
### UFW(Ubuntu/Debian)
```bash
# 允许 SSH
sudo ufw allow ssh
# 允许 HTTP/HTTPS
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
# 如果需要直接访问(不推荐)
sudo ufw allow 8016/tcp
# 启用防火墙
sudo ufw enable
# 查看状态
sudo ufw status
```
### firewalld(CentOS/RHEL)
```bash
# 允许 HTTP/HTTPS
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
# 如果需要直接访问
sudo firewall-cmd --permanent --add-port=8016/tcp
# 重新加载配置
sudo firewall-cmd --reload
# 查看状态
sudo firewall-cmd --list-all
```
## 监控和日志
### 日志位置
- **应用日志**: `logs/app.log`
- **PM2 日志**: `logs/pm2-out.log`, `logs/pm2-error.log`
- **Nginx 日志**: `/var/log/nginx/`
- **systemd 日志**: `sudo journalctl -u write-server`
### 日志轮转
创建日志轮转配置:
```bash
sudo nano /etc/logrotate.d/write-server
```
**内容:**
```
/path/to/write-server/logs/*.log {
daily
missingok
rotate 14
compress
delaycompress
notifempty
create 0640 your-user your-group
}
```
### 监控脚本
创建简单的监控脚本:
```bash
#!/bin/bash
# monitor.sh
# 检查服务状态
if ! curl -s http://localhost:8016/api/stats > /dev/null; then
echo "服务异常,正在重启..."
sudo systemctl restart write-server
# 发送告警邮件(可选)
fi
```
添加到 crontab:
```bash
crontab -e
# 每 5 分钟检查一次
*/5 * * * * /path/to/monitor.sh
```
## 备份策略
### 自动备份
```bash
# 添加到 crontab
crontab -e
# 每天凌晨 2 点备份
0 2 * * * /path/to/write-server/scripts/backup.sh
# 每周日备份并上传到远程存储
0 3 * * 0 /path/to/write-server/scripts/backup.sh && /path/to/upload-to-s3.sh
```
### 备份内容
- 博客内容(content/posts/)
- 配置文件(.env)
- 回收站数据
- Nginx 配置
- systemd 服务文件
### 恢复备份
```bash
# 查看可用备份
ls -lh backups/
# 恢复指定备份
./scripts/restore.sh backups/write-server-20260101_120000.tar.gz
```
## 性能优化
### 1. Node.js 优化
```bash
# 使用 PM2 集群模式(多核 CPU)
pm2 start ecosystem.config.js -i max
# 或在 ecosystem.config.js 中修改
# instances: "max"
# exec_mode: "cluster"
```
### 2. Nginx 优化
在 nginx.conf 中添加:
```nginx
# 启用 Gzip
gzip on;
gzip_vary on;
gzip_min_length 1000;
gzip_types text/plain text/css application/json application/javascript;
# 缓存静态资源
location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg)$ {
expires 1y;
add_header Cache-Control "public, immutable";
}
```
### 3. 系统优化
```bash
# 增加文件描述符限制
sudo nano /etc/security/limits.conf
# 添加:
# your-user soft nofile 65536
# your-user hard nofile 65536
# 优化内核参数
sudo nano /etc/sysctl.conf
# 添加:
# net.core.somaxconn = 65535
# net.ipv4.tcp_max_syn_backlog = 65535
```
## 故障排查
### 常见问题
#### 1. 服务无法启动
```bash
# 查看详细错误
pm2 logs write-server --lines 100
# 或
sudo journalctl -u write-server -n 100
# 检查端口占用
lsof -i :8016
netstat -tulpn | grep 8016
```
#### 2. 无法访问博客内容
```bash
# 检查 BLOG_ROOT 配置
cat .env | grep BLOG_ROOT
# 检查目录权限
ls -la /path/to/blog
# 修复权限
sudo chown -R your-user:your-group /path/to/blog
```
#### 3. Hugo 预览失败
```bash
# 检查 Hugo 是否安装
hugo version
# 手动启动 Hugo 预览
cd /path/to/blog
hugo server -D
```
#### 4. 图片上传失败
```bash
# 检查目录权限
ls -la /path/to/blog/static
# 检查磁盘空间
df -h
# 检查文件大小限制(nginx.conf)
client_max_body_size 50m;
```
### 性能问题排查
```bash
# 查看 CPU 和内存使用
top
htop
# 查看 Node.js 进程
ps aux | grep node
# 查看网络连接
netstat -tulpn | grep 8016
# 查看磁盘 I/O
iotop
```
## 安全建议
1. **使用 HTTPS** - 配置 SSL 证书
2. **限制访问** - 配置防火墙和 Nginx 访问控制
3. **定期更新** - 保持系统和依赖更新
4. **强密码** - 使用强密码和 API Token
5. **备份加密** - 对备份文件进行加密
6. **日志审计** - 定期检查访问日志
7. **最小权限** - 使用非 root 用户运行服务
8. **Fail2ban** - 防止暴力破解攻击
## 更新升级
```bash
# 拉取最新代码
git pull origin main
# 安装新依赖
npm install
# 重新构建
npm run build
# 重启服务
pm2 restart write-server
# 或
sudo systemctl restart write-server
```
## 回滚版本
```bash
# 查看 Git 历史
git log --oneline
# 回滚到指定版本
git checkout <commit-hash>
# 重新部署
npm install
npm run build
pm2 restart write-server
```