fix: 远端与镜像注册表统一改用 HTTPS
git.iwali.top 有 Let's Encrypt 通配证书(*.iwali.top),HTTPS 全程可用: https://git.iwali.top/api/v1/version -> 200 https://git.iwali.top/v2/ -> 401(Bearer 认证,正常) 证书链校验 ssl_verify_result=0(受信),因此: - git remote 改为 https://git.iwali.top/...(原为 http://) - 镜像名 git.iwali.top/... 由 Docker 默认按 HTTPS 访问, **不再需要 daemon.json 配 insecure-registries**(明文传输会暴露 Token) - DEPLOYMENT.md 5.1 改写为「默认走 HTTPS」,HTTP + insecure 降级为补充说明 - Dockerfile 的 image.source 标签、README/DEPLOYMENT 的 clone 地址同步改 https
这个提交包含在:
+1
-1
@@ -27,7 +27,7 @@ FROM python:3.13-slim AS runtime
|
||||
LABEL org.opencontainers.image.title="WorkBuddy Portal" \
|
||||
org.opencontainers.image.description="WorkBuddy 积分用量采集 / 存储 / 呈现一体化门户" \
|
||||
org.opencontainers.image.version="1.1.0" \
|
||||
org.opencontainers.image.source="http://git.iwali.top/wangchuanli/workbuddy-portal"
|
||||
org.opencontainers.image.source="https://git.iwali.top/wangchuanli/workbuddy-portal"
|
||||
|
||||
ENV PYTHONUNBUFFERED=1 \
|
||||
PYTHONDONTWRITEBYTECODE=1 \
|
||||
|
||||
@@ -72,7 +72,7 @@
|
||||
### 方式一:Docker Compose(推荐)
|
||||
|
||||
```bash
|
||||
git clone http://git.iwali.top/wangchuanli/workbuddy-portal.git
|
||||
git clone https://git.iwali.top/wangchuanli/workbuddy-portal.git
|
||||
cd workbuddy-portal
|
||||
|
||||
cp .env.example .env # 至少设好 WB_ADMIN_PASSWORD
|
||||
|
||||
+20
-14
@@ -40,7 +40,7 @@
|
||||
### 2.2 步骤
|
||||
|
||||
```bash
|
||||
git clone http://git.iwali.top/wangchuanli/workbuddy-portal.git
|
||||
git clone https://git.iwali.top/wangchuanli/workbuddy-portal.git
|
||||
cd workbuddy-portal
|
||||
|
||||
cp .env.example .env
|
||||
@@ -107,7 +107,7 @@ docker compose exec portal python manage.py collect # 手动采集一次
|
||||
### 3.1 Windows
|
||||
|
||||
```bat
|
||||
git clone http://git.iwali.top/wangchuanli/workbuddy-portal.git
|
||||
git clone https://git.iwali.top/wangchuanli/workbuddy-portal.git
|
||||
cd workbuddy-portal
|
||||
py -3 -m venv .venv
|
||||
.venv\Scripts\pip install -r requirements.txt
|
||||
@@ -122,7 +122,7 @@ py -3 -m venv .venv
|
||||
### 3.2 Linux
|
||||
|
||||
```bash
|
||||
git clone http://git.iwali.top/wangchuanli/workbuddy-portal.git
|
||||
git clone https://git.iwali.top/wangchuanli/workbuddy-portal.git
|
||||
cd workbuddy-portal
|
||||
python3 -m venv .venv
|
||||
.venv/bin/pip install -r requirements.txt
|
||||
@@ -225,21 +225,27 @@ tools/push-all.sh 1.1.0 # 同时打一个版本 tag 并推送
|
||||
> 不用脚本、手工推也行:`git push origin main` 弹出凭据窗口时,
|
||||
> 用户名填 `wangchuanli`,**密码处填 Access Token**(不是网页登录密码)。
|
||||
|
||||
### 5.1 准备:本机允许 HTTP 注册表
|
||||
### 5.1 传输协议:默认走 HTTPS(不用配 insecure-registries)
|
||||
|
||||
Gitea 走的是 **HTTP**,Docker 默认只允许 HTTPS。Docker Desktop:**Settings → Docker Engine**,
|
||||
在 `daemon.json` 里加:
|
||||
`git.iwali.top` 有 **Let's Encrypt 通配证书(`*.iwali.top`)**,HTTPS 全程可用:
|
||||
|
||||
```json
|
||||
{
|
||||
"insecure-registries": ["git.iwali.top"]
|
||||
}
|
||||
```bash
|
||||
curl -s -o /dev/null -w "%{http_code}\n" https://git.iwali.top/api/v1/version # 200
|
||||
curl -s -o /dev/null -w "%{http_code}\n" https://git.iwali.top/v2/ # 401(需认证,正常)
|
||||
```
|
||||
|
||||
`Apply & Restart`。Linux 上同理改 `/etc/docker/daemon.json` 后 `sudo systemctl restart docker`。
|
||||
所以:
|
||||
|
||||
> 这是**内网自托管服务**的常规做法。若 Gitea 前面有带证书的 Caddy/nginx,
|
||||
> 用 `https://` 地址即可,不必开 insecure。
|
||||
- **git 远端用 `https://`**(仓库地址见上);
|
||||
- **镜像名就是 `git.iwali.top/...`,Docker 默认按 HTTPS 访问** —— 无需任何额外配置。
|
||||
|
||||
> 只有在 Gitea 前面**没有** TLS 终止(纯 `http://`)时,才需要在 Docker Desktop
|
||||
> **Settings → Docker Engine** 的 `daemon.json` 里加:
|
||||
> ```json
|
||||
> { "insecure-registries": ["git.iwali.top"] }
|
||||
> ```
|
||||
> 然后 `Apply & Restart`(Linux 改 `/etc/docker/daemon.json` 后重启 docker)。
|
||||
> 明文传输会让 Token 暴露在网络里,**能走 HTTPS 就不要开这个口子**。
|
||||
|
||||
### 5.2 登录
|
||||
|
||||
@@ -291,7 +297,7 @@ docker compose up -d
|
||||
docker manifest inspect git.iwali.top/wangchuanli/workbuddy-portal:1.1.0
|
||||
# 或
|
||||
curl -s -u wangchuanli:TOKEN \
|
||||
http://git.iwali.top/api/v1/packages/wangchuanli?type=container
|
||||
https://git.iwali.top/api/v1/packages/wangchuanli?type=container
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
+3
-1
@@ -9,9 +9,11 @@
|
||||
# 设计要点:
|
||||
# * Token **只从环境变量读**,绝不写进 .git/config、URL 或任何文件。
|
||||
# * 用 `-c credential.helper=` 屏蔽已配置的凭据助手(GCM),
|
||||
# 否则在非交互会话里 GCM 会挂住等弹窗。
|
||||
# 否则在非交互会话里 GCM 会挂住等弹窗(连 /dev/tty 都拿不到,直接失败)。
|
||||
# * 用 `http.extraHeader` 传 Basic 认证,比把 token 拼进 URL 更安全
|
||||
# (不会落到 reflog / 进程列表里)。
|
||||
# * git.iwali.top 有 Let's Encrypt 通配证书,**HTTPS 可用**,
|
||||
# 所以镜像不需要配 insecure-registries。
|
||||
# =============================================================================
|
||||
set -eu
|
||||
|
||||
|
||||
在新工单中引用
屏蔽一个用户