{"id":76,"date":"2025-12-23T19:00:41","date_gmt":"2025-12-23T11:00:41","guid":{"rendered":"https:\/\/www.huaweicloud.online\/?p=76"},"modified":"2025-12-23T19:00:41","modified_gmt":"2025-12-23T11:00:41","slug":"maxkey%e5%8d%95%e7%82%b9%e7%99%bb%e5%bd%95%e7%b3%bb%e7%bb%9f%e8%af%a6%e7%bb%86%e9%83%a8%e7%bd%b2%e6%96%b9%e6%a1%88","status":"publish","type":"post","link":"https:\/\/www.huaweicloud.online\/index.php\/2025\/12\/23\/maxkey%e5%8d%95%e7%82%b9%e7%99%bb%e5%bd%95%e7%b3%bb%e7%bb%9f%e8%af%a6%e7%bb%86%e9%83%a8%e7%bd%b2%e6%96%b9%e6%a1%88\/","title":{"rendered":"MaxKey\u5355\u70b9\u767b\u5f55\u7cfb\u7edf\u8be6\u7ec6\u90e8\u7f72\u65b9\u6848"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u9879\u76ee\u6982\u8ff0<br>1.1 \u9879\u76ee\u80cc\u666f<br>MaxKey\u662f\u4e1a\u754c\u9886\u5148\u7684\u4f01\u4e1a\u7ea7IAM\u8eab\u4efd\u7ba1\u7406\u548c\u8ba4\u8bc1\u4ea7\u54c1\uff0c\u652f\u6301OAuth 2.x\/OpenID Connect\u3001SAML 2.0\u3001JWT\u3001CAS\u7b49\u6807\u51c6\u534f\u8bae\uff0c\u63d0\u4f9b\u7edf\u4e00\u8eab\u4efd\u8ba4\u8bc1\u3001\u5355\u70b9\u767b\u5f55\uff08SSO\uff09\u3001RBAC\u6743\u9650\u7ba1\u7406\u548c\u8d44\u6e90\u7ba1\u7406\u7b49\u80fd\u529b\u3002<\/li>\n<\/ol>\n\n\n\n<p>1.2 \u90e8\u7f72\u76ee\u6807<br>\u6784\u5efa\u9ad8\u53ef\u7528\u3001\u53ef\u6269\u5c55\u7684\u7edf\u4e00\u8eab\u4efd\u8ba4\u8bc1\u5e73\u53f0<\/p>\n\n\n\n<p>\u652f\u63015000+\u7528\u6237\u5e76\u53d1\u8bbf\u95ee<\/p>\n\n\n\n<p>\u5b9e\u73b0\u4e0e\u73b0\u6709\u4e1a\u52a1\u7cfb\u7edf\u7684\u65e0\u7f1d\u96c6\u6210<\/p>\n\n\n\n<p>\u786e\u4fdd\u7cfb\u7edf\u5b89\u5168\u6027\u548c\u7a33\u5b9a\u6027<\/p>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li>\u7cfb\u7edf\u67b6\u6784\u8bbe\u8ba1<br>2.1 \u90e8\u7f72\u67b6\u6784<br>text<br>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br>\u2502 \u8d1f\u8f7d\u5747\u8861\u5c42 \u2502<br>\u2502 (Nginx\/HAProxy) \u2502<br>\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518<br>\u2502 \u2502<br>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u25bc\u2500\u2500\u2500\u2500\u2500\u2510 \u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u25bc\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br>\u2502 MaxKey\u5e94\u7528\u8282\u70b91 \u2502 \u2502 MaxKey\u5e94\u7528\u8282\u70b92 \u2502<br>\u2502 (Docker\u5bb9\u5668) \u2502 \u2502 (Docker\u5bb9\u5668) \u2502<br>\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2518 \u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518<br>\u2502 \u2502<br>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u25bc\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u25bc\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br>\u2502 Redis\u96c6\u7fa4(\u54e8\u5175\u6a21\u5f0f) \u2502<br>\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518<br>\u2502 \u2502<br>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u25bc\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u25bc\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br>\u2502 MySQL\u4e3b\u4ece\u96c6\u7fa4 \u2502<br>\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518<br>2.2 \u6280\u672f\u6808<br>\u5e94\u7528\u670d\u52a1\u5668: Tomcat 9\/JDK 11<\/li>\n<\/ol>\n\n\n\n<p>\u6570\u636e\u5e93: MySQL 8.0 \u96c6\u7fa4<\/p>\n\n\n\n<p>\u7f13\u5b58: Redis 6.x \u96c6\u7fa4<\/p>\n\n\n\n<p>\u53cd\u5411\u4ee3\u7406: Nginx 1.20+<\/p>\n\n\n\n<p>\u5bb9\u5668: Docker 20.10+ \/ Docker Compose<\/p>\n\n\n\n<p>\u76d1\u63a7: Prometheus + Grafana<\/p>\n\n\n\n<p>\u65e5\u5fd7: ELK Stack<\/p>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li>\u73af\u5883\u8981\u6c42<br>3.1 \u786c\u4ef6\u914d\u7f6e<br>\u89d2\u8272 CPU \u5185\u5b58 \u5b58\u50a8 \u6570\u91cf<br>\u5e94\u7528\u8282\u70b9 4\u6838 8GB 100GB 2<br>\u6570\u636e\u5e93\u8282\u70b9 4\u6838 16GB 500GB 2<br>Redis\u8282\u70b9 2\u6838 4GB 50GB 3<br>Nginx\u8282\u70b9 2\u6838 4GB 50GB 2<br>3.2 \u8f6f\u4ef6\u8981\u6c42<br>\u64cd\u4f5c\u7cfb\u7edf: CentOS 7.9+\/Ubuntu 20.04+<\/li>\n<\/ol>\n\n\n\n<p>Docker: 20.10.0+<\/p>\n\n\n\n<p>Docker Compose: 2.0.0+<\/p>\n\n\n\n<p>MySQL: 8.0.26+<\/p>\n\n\n\n<p>Redis: 6.2.6+<\/p>\n\n\n\n<p>Nginx: 1.20.1+<\/p>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li>\u8be6\u7ec6\u90e8\u7f72\u6b65\u9aa4<br>4.1 \u73af\u5883\u51c6\u5907<br>4.1.1 \u7cfb\u7edf\u521d\u59cb\u5316<br>bash<\/li>\n<\/ol>\n\n\n\n<h1 class=\"wp-block-heading\">\u6240\u6709\u8282\u70b9\u6267\u884c<\/h1>\n\n\n\n<p>sudo hostnamectl set-hostname maxkey-node1<br>sudo systemctl stop firewalld<br>sudo systemctl disable firewalld<br>sudo setenforce 0<br>sudo sed -i &#8216;s\/SELINUX=enforcing\/SELINUX=disabled\/g&#8217; \/etc\/selinux\/config<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u65f6\u95f4\u540c\u6b65<\/h1>\n\n\n\n<p>sudo yum install -y ntpdate<br>sudo ntpdate ntp.aliyun.com<br>sudo echo &#8220;0 *\/12 * * * \/usr\/sbin\/ntpdate ntp.aliyun.com&#8221; &gt;&gt; \/var\/spool\/cron\/root<br>4.1.2 Docker\u5b89\u88c5<br>bash<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u5b89\u88c5\u4f9d\u8d56<\/h1>\n\n\n\n<p>sudo yum install -y yum-utils device-mapper-persistent-data lvm2<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u6dfb\u52a0Docker\u6e90<\/h1>\n\n\n\n<p>sudo yum-config-manager &#8211;add-repo https:\/\/download.docker.com\/linux\/centos\/docker-ce.repo<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u5b89\u88c5Docker<\/h1>\n\n\n\n<p>sudo yum install -y docker-ce docker-ce-cli containerd.io<br>sudo systemctl start docker<br>sudo systemctl enable docker<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u5b89\u88c5Docker Compose<\/h1>\n\n\n\n<p>sudo curl -L &#8220;https:\/\/github.com\/docker\/compose\/releases\/download\/v2.17.2\/docker-compose-$(uname -s)-$(uname -m)&#8221; \\<br>-o \/usr\/local\/bin\/docker-compose<br>sudo chmod +x \/usr\/local\/bin\/docker-compose<br>4.2 \u6570\u636e\u5e93\u90e8\u7f72<br>4.2.1 MySQL\u4e3b\u4ece\u914d\u7f6e<br>\u4e3b\u8282\u70b9\u914d\u7f6e (maxkey-mysql-master):<\/p>\n\n\n\n<p>ini<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\/etc\/mysql\/my.cnf<\/h1>\n\n\n\n<p>[mysqld]<br>server-id=1<br>log-bin=mysql-bin<br>binlog-format=ROW<br>expire_logs_days=7<br>max_binlog_size=100M<br>binlog_cache_size=4M<br>max_binlog_cache_size=512M<br>\u4ece\u8282\u70b9\u914d\u7f6e (maxkey-mysql-slave):<\/p>\n\n\n\n<p>ini<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\/etc\/mysql\/my.cnf<\/h1>\n\n\n\n<p>[mysqld]<br>server-id=2<br>relay-log=mysql-relay-bin<br>read_only=1<br>4.2.2 \u4f7f\u7528Docker Compose\u90e8\u7f72MySQL<br>yaml<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">docker-compose-mysql.yml<\/h1>\n\n\n\n<p>version: &#8216;3.8&#8217;<br>services:<br>mysql-master:<br>image: mysql:8.0.26<br>container_name: maxkey-mysql-master<br>restart: always<br>environment:<br>MYSQL_ROOT_PASSWORD: ${MYSQL_ROOT_PASSWORD}<br>MYSQL_DATABASE: maxkey<br>MYSQL_USER: maxkey<br>MYSQL_PASSWORD: ${MYSQL_PASSWORD}<br>ports:<br>&#8211; &#8220;3306:3306&#8221;<br>volumes:<br>&#8211; .\/mysql\/master\/data:\/var\/lib\/mysql<br>&#8211; .\/mysql\/master\/conf:\/etc\/mysql\/conf.d<br>&#8211; .\/mysql\/master\/init:\/docker-entrypoint-initdb.d<br>networks:<br>&#8211; maxkey-network<\/p>\n\n\n\n<p>mysql-slave:<br>image: mysql:8.0.26<br>container_name: maxkey-mysql-slave<br>restart: always<br>environment:<br>MYSQL_ROOT_PASSWORD: ${MYSQL_ROOT_PASSWORD}<br>ports:<br>&#8211; &#8220;3307:3306&#8221;<br>volumes:<br>&#8211; .\/mysql\/slave\/data:\/var\/lib\/mysql<br>&#8211; .\/mysql\/slave\/conf:\/etc\/mysql\/conf.d<br>networks:<br>&#8211; maxkey-network<\/p>\n\n\n\n<p>networks:<br>maxkey-network:<br>driver: bridge<br>4.2.3 \u521d\u59cb\u5316\u6570\u636e\u5e93<br>sql<br>&#8212; \u5728\u4e3b\u8282\u70b9\u6267\u884c<br>CREATE DATABASE IF NOT EXISTS maxkey DEFAULT CHARSET utf8mb4 COLLATE utf8mb4_unicode_ci;<br>CREATE USER &#8216;maxkey&#8217;@&#8217;%&#8217; IDENTIFIED BY &#8216;${MYSQL_PASSWORD}&#8217;;<br>GRANT ALL PRIVILEGES ON maxkey.* TO &#8216;maxkey&#8217;@&#8217;%&#8217;;<br>FLUSH PRIVILEGES;<br>4.3 Redis\u96c6\u7fa4\u90e8\u7f72<br>4.3.1 Docker Compose\u914d\u7f6e<br>yaml<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">docker-compose-redis.yml<\/h1>\n\n\n\n<p>version: &#8216;3.8&#8217;<br>services:<br>redis-node1:<br>image: redis:6.2.6-alpine<br>container_name: redis-node1<br>command: redis-server &#8211;port 6379 &#8211;cluster-enabled yes &#8211;cluster-config-file nodes.conf &#8211;cluster-node-timeout 5000 &#8211;appendonly yes<br>ports:<br>&#8211; &#8220;6379:6379&#8221;<br>volumes:<br>&#8211; .\/redis\/node1\/data:\/data<br>networks:<br>&#8211; maxkey-network<\/p>\n\n\n\n<p>redis-node2:<br>image: redis:6.2.6-alpine<br>container_name: redis-node2<br>command: redis-server &#8211;port 6380 &#8211;cluster-enabled yes &#8211;cluster-config-file nodes.conf &#8211;cluster-node-timeout 5000 &#8211;appendonly yes<br>ports:<br>&#8211; &#8220;6380:6380&#8221;<br>volumes:<br>&#8211; .\/redis\/node2\/data:\/data<br>networks:<br>&#8211; maxkey-network<\/p>\n\n\n\n<p>redis-node3:<br>image: redis:6.2.6-alpine<br>container_name: redis-node3<br>command: redis-server &#8211;port 6381 &#8211;cluster-enabled yes &#8211;cluster-config-file nodes.conf &#8211;cluster-node-timeout 5000 &#8211;appendonly yes<br>ports:<br>&#8211; &#8220;6381:6381&#8221;<br>volumes:<br>&#8211; .\/redis\/node3\/data:\/data<br>networks:<br>&#8211; maxkey-network<\/p>\n\n\n\n<p>networks:<br>maxkey-network:<br>driver: bridge<br>4.3.2 \u521b\u5efaRedis\u96c6\u7fa4<br>bash<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u8fdb\u5165\u4efb\u4e00Redis\u5bb9\u5668<\/h1>\n\n\n\n<p>docker exec -it redis-node1 sh<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u521b\u5efa\u96c6\u7fa4<\/h1>\n\n\n\n<p>redis-cli &#8211;cluster create \\<br>172.18.0.4:6379 \\<br>172.18.0.5:6380 \\<br>172.18.0.6:6381 \\<br>&#8211;cluster-replicas 0<br>4.4 MaxKey\u5e94\u7528\u90e8\u7f72<br>4.4.1 \u4e0b\u8f7d\u548c\u51c6\u5907MaxKey<br>bash<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u521b\u5efa\u5de5\u4f5c\u76ee\u5f55<\/h1>\n\n\n\n<p>mkdir -p \/opt\/maxkey &amp;&amp; cd \/opt\/maxkey<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u4e0b\u8f7d\u6700\u65b0\u7248\u672c<\/h1>\n\n\n\n<p>wget https:\/\/github.com\/dromara\/MaxKey\/releases\/download\/v4.0.0\/maxkey-4.0.0-ga.zip<br>unzip maxkey-4.0.0-ga.zip<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u51c6\u5907Dockerfile<\/h1>\n\n\n\n<p>cat &gt; Dockerfile &lt;&lt; EOF<br>FROM tomcat:9.0-jdk11-openjdk-slim<br>LABEL maintainer=&#8221;maxkey@example.com&#8221;<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u5220\u9664\u9ed8\u8ba4\u5e94\u7528<\/h1>\n\n\n\n<p>RUN rm -rf \/usr\/local\/tomcat\/webapps\/*<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u62f7\u8d1dMaxKey\u5e94\u7528<\/h1>\n\n\n\n<p>COPY maxkey-web-maxkey-4.0.0-ga.war \/usr\/local\/tomcat\/webapps\/ROOT.war<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u521b\u5efa\u89e3\u538b\u76ee\u5f55<\/h1>\n\n\n\n<p>RUN mkdir -p \/usr\/local\/tomcat\/webapps\/ROOT<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u89e3\u538bWAR\u5305<\/h1>\n\n\n\n<p>RUN unzip \/usr\/local\/tomcat\/webapps\/ROOT.war -d \/usr\/local\/tomcat\/webapps\/ROOT\/<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u62f7\u8d1d\u914d\u7f6e\u6587\u4ef6<\/h1>\n\n\n\n<p>COPY application.properties \/usr\/local\/tomcat\/webapps\/ROOT\/WEB-INF\/classes\/<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u66b4\u9732\u7aef\u53e3<\/h1>\n\n\n\n<p>EXPOSE 8080<\/p>\n\n\n\n<p>CMD [&#8220;catalina.sh&#8221;, &#8220;run&#8221;]<br>EOF<br>4.4.2 \u5e94\u7528\u914d\u7f6e\u6587\u4ef6<br>properties<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">application.properties<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">\u6570\u636e\u5e93\u914d\u7f6e<\/h1>\n\n\n\n<p>maxkey.db.type=mysql<br>maxkey.db.url=jdbc:mysql:\/\/maxkey-mysql-master:3306\/maxkey?useUnicode=true&amp;characterEncoding=utf8&amp;useSSL=false&amp;serverTimezone=Asia\/Shanghai<br>maxkey.db.username=maxkey<br>maxkey.db.password=${MYSQL_PASSWORD}<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">Redis\u914d\u7f6e<\/h1>\n\n\n\n<p>maxkey.redis.host=redis-node1,redis-node2,redis-node3<br>maxkey.redis.port=6379,6380,6381<br>maxkey.redis.password=<br>maxkey.redis.cluster=true<br>maxkey.redis.timeout=10000<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u4f1a\u8bdd\u914d\u7f6e<\/h1>\n\n\n\n<p>server.servlet.session.timeout=7200<br>server.servlet.session.cookie.http-only=true<br>server.servlet.session.cookie.secure=false<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u5b89\u5168\u914d\u7f6e<\/h1>\n\n\n\n<p>maxkey.sso.cookie.domain=.example.com<br>maxkey.sso.cookie.path=\/<br>4.4.3 Docker Compose\u90e8\u7f72\u5e94\u7528<br>yaml<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">docker-compose-app.yml<\/h1>\n\n\n\n<p>version: &#8216;3.8&#8217;<br>services:<br>maxkey-app1:<br>build: .<br>container_name: maxkey-app1<br>restart: always<br>ports:<br>&#8211; &#8220;8081:8080&#8221;<br>environment:<br>&#8211; JAVA_OPTS=-Xms2g -Xmx2g -XX:+UseG1GC -Djava.security.egd=file:\/dev\/.\/urandom<br>volumes:<br>&#8211; .\/logs\/app1:\/usr\/local\/tomcat\/logs<br>depends_on:<br>&#8211; mysql-master<br>&#8211; redis-node1<br>networks:<br>&#8211; maxkey-network<br>healthcheck:<br>test: [&#8220;CMD&#8221;, &#8220;curl&#8221;, &#8220;-f&#8221;, &#8220;http:\/\/localhost:8080\/login&#8221;]<br>interval: 30s<br>timeout: 10s<br>retries: 3<\/p>\n\n\n\n<p>maxkey-app2:<br>build: .<br>container_name: maxkey-app2<br>restart: always<br>ports:<br>&#8211; &#8220;8082:8080&#8221;<br>environment:<br>&#8211; JAVA_OPTS=-Xms2g -Xmx2g -XX:+UseG1GC -Djava.security.egd=file:\/dev\/.\/urandom<br>volumes:<br>&#8211; .\/logs\/app2:\/usr\/local\/tomcat\/logs<br>depends_on:<br>&#8211; mysql-master<br>&#8211; redis-node1<br>networks:<br>&#8211; maxkey-network<br>healthcheck:<br>test: [&#8220;CMD&#8221;, &#8220;curl&#8221;, &#8220;-f&#8221;, &#8220;http:\/\/localhost:8080\/login&#8221;]<br>interval: 30s<br>timeout: 10s<br>retries: 3<\/p>\n\n\n\n<p>networks:<br>maxkey-network:<br>external: true<br>4.5 Nginx\u8d1f\u8f7d\u5747\u8861\u914d\u7f6e<br>4.5.1 Nginx\u914d\u7f6e\u6587\u4ef6<br>nginx<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\/etc\/nginx\/nginx.conf<\/h1>\n\n\n\n<p>user nginx;<br>worker_processes auto;<br>error_log \/var\/log\/nginx\/error.log warn;<br>pid \/var\/run\/nginx.pid;<\/p>\n\n\n\n<p>events {<br>worker_connections 1024;<br>use epoll;<br>}<\/p>\n\n\n\n<p>http {<br>include \/etc\/nginx\/mime.types;<br>default_type application\/octet-stream;<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>log_format main '$remote_addr - $remote_user &#91;$time_local] \"$request\" '\n                '$status $body_bytes_sent \"$http_referer\" '\n                '\"$http_user_agent\" \"$http_x_forwarded_for\"';\n\naccess_log \/var\/log\/nginx\/access.log main;\n\nsendfile on;\ntcp_nopush on;\ntcp_nodelay on;\nkeepalive_timeout 65;\ntypes_hash_max_size 2048;\n\n# \u5f00\u542fgzip\u538b\u7f29\ngzip on;\ngzip_min_length 1k;\ngzip_comp_level 2;\ngzip_types text\/plain text\/css text\/xml text\/javascript application\/json application\/javascript application\/xml+rss;\n\n# \u8d1f\u8f7d\u5747\u8861\u914d\u7f6e\nupstream maxkey_backend {\n    least_conn;\n    server 192.168.1.101:8081 max_fails=3 fail_timeout=30s;\n    server 192.168.1.102:8082 max_fails=3 fail_timeout=30s;\n    keepalive 32;\n}\n\nserver {\n    listen 80;\n    server_name sso.example.com;\n\n    # \u91cd\u5b9a\u5411\u5230HTTPS\n    return 301 https:\/\/$server_name$request_uri;\n}\n\nserver {\n    listen 443 ssl http2;\n    server_name sso.example.com;\n\n    ssl_certificate \/etc\/nginx\/ssl\/sso.example.com.crt;\n    ssl_certificate_key \/etc\/nginx\/ssl\/sso.example.com.key;\n    ssl_protocols TLSv1.2 TLSv1.3;\n    ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384;\n    ssl_prefer_server_ciphers off;\n    ssl_session_cache shared:SSL:10m;\n    ssl_session_timeout 10m;\n\n    # \u5b89\u5168\u5934\n    add_header X-Frame-Options SAMEORIGIN;\n    add_header X-Content-Type-Options nosniff;\n    add_header X-XSS-Protection \"1; mode=block\";\n    add_header Strict-Transport-Security \"max-age=31536000; includeSubDomains\" always;\n\n    location \/ {\n        proxy_pass http:\/\/maxkey_backend;\n        proxy_set_header Host $host;\n        proxy_set_header X-Real-IP $remote_addr;\n        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;\n        proxy_set_header X-Forwarded-Proto $scheme;\n\n        proxy_connect_timeout 30s;\n        proxy_read_timeout 60s;\n        proxy_send_timeout 60s;\n        proxy_buffering off;\n    }\n\n    # \u5065\u5eb7\u68c0\u67e5\n    location \/health {\n        access_log off;\n        return 200 \"healthy\\n\";\n        add_header Content-Type text\/plain;\n    }\n\n    # \u9759\u6001\u8d44\u6e90\u7f13\u5b58\n    location ~* \\.(jpg|jpeg|png|gif|ico|css|js)$ {\n        expires 1y;\n        add_header Cache-Control \"public, immutable\";\n        proxy_pass http:\/\/maxkey_backend;\n    }\n}<\/code><\/pre>\n\n\n\n<p>}<br>4.5.2 Docker\u90e8\u7f72Nginx<br>yaml<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">docker-compose-nginx.yml<\/h1>\n\n\n\n<p>version: &#8216;3.8&#8217;<br>services:<br>nginx:<br>image: nginx:1.20-alpine<br>container_name: maxkey-nginx<br>restart: always<br>ports:<br>&#8211; &#8220;80:80&#8221;<br>&#8211; &#8220;443:443&#8221;<br>volumes:<br>&#8211; .\/nginx\/conf:\/etc\/nginx<br>&#8211; .\/nginx\/logs:\/var\/log\/nginx<br>&#8211; .\/nginx\/ssl:\/etc\/nginx\/ssl<br>networks:<br>&#8211; maxkey-network<br>4.6 \u76d1\u63a7\u548c\u65e5\u5fd7\u914d\u7f6e<br>4.6.1 Prometheus\u914d\u7f6e<br>yaml<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">prometheus.yml<\/h1>\n\n\n\n<p>global:<br>scrape_interval: 15s<br>evaluation_interval: 15s<\/p>\n\n\n\n<p>scrape_configs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>job_name: &#8216;maxkey-app&#8217;<br>metrics_path: &#8216;\/actuator\/prometheus&#8217;<br>static_configs:\n<ul class=\"wp-block-list\">\n<li>targets: [&#8216;maxkey-app1:8080&#8217;, &#8216;maxkey-app2:8080&#8217;]<br>labels:<br>application: &#8216;maxkey&#8217;<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>job_name: &#8216;nginx&#8217;<br>static_configs:\n<ul class=\"wp-block-list\">\n<li>targets: [&#8216;nginx:9113&#8217;]<br>labels:<br>service: &#8216;nginx&#8217;<br>4.6.2 \u5e94\u7528\u76d1\u63a7\u914d\u7f6e<br>\u5728application.properties\u4e2d\u6dfb\u52a0\uff1a<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>properties<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u76d1\u63a7\u914d\u7f6e<\/h1>\n\n\n\n<p>management.endpoints.web.exposure.include=health,info,metrics,prometheus<br>management.metrics.export.prometheus.enabled=true<br>management.endpoint.health.show-details=always<\/p>\n\n\n\n<ol start=\"5\" class=\"wp-block-list\">\n<li>\u521d\u59cb\u5316\u914d\u7f6e<br>5.1 \u6570\u636e\u5e93\u521d\u59cb\u5316<br>bash<\/li>\n<\/ol>\n\n\n\n<h1 class=\"wp-block-heading\">\u6267\u884c\u6570\u636e\u5e93\u521d\u59cb\u5316\u811a\u672c<\/h1>\n\n\n\n<p>mysql -h maxkey-mysql-master -u maxkey -p maxkey &lt; \/opt\/maxkey\/sql\/maxkey.sql<br>mysql -h maxkey-mysql-master -u maxkey -p maxkey &lt; \/opt\/maxkey\/sql\/maxkey_data.sql<br>5.2 MaxKey\u521d\u59cb\u914d\u7f6e<br>\u8bbf\u95ee https:\/\/sso.example.com<\/p>\n\n\n\n<p>\u4f7f\u7528\u9ed8\u8ba4\u7ba1\u7406\u5458\u767b\u5f55\uff1a<\/p>\n\n\n\n<p>\u7528\u6237\u540d\uff1aadministrator<\/p>\n\n\n\n<p>\u5bc6\u7801\uff1amaxkey<\/p>\n\n\n\n<p>\u4fee\u6539\u7ba1\u7406\u5458\u5bc6\u7801<\/p>\n\n\n\n<p>\u914d\u7f6e\u7ec4\u7ec7\u67b6\u6784<\/p>\n\n\n\n<p>\u5bfc\u5165\u7528\u6237\u6216\u914d\u7f6eLDAP\u8fde\u63a5<\/p>\n\n\n\n<p>\u914d\u7f6e\u5e94\u7528\u96c6\u6210<\/p>\n\n\n\n<p>5.3 \u5e94\u7528\u96c6\u6210\u914d\u7f6e<br>\u4ee5\u96c6\u6210GitLab\u4e3a\u4f8b\uff1a<\/p>\n\n\n\n<p>yaml<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">GitLab OAuth\u914d\u7f6e<\/h1>\n\n\n\n<p>applicationName: GitLab<br>applicationKey: gitlab<br>applicationSecret: ${GITLAB_SECRET}<br>redirectUri: https:\/\/sso.example.com\/oauth\/authorize<br>provider: gitlab<br>scope: read_user openid profile email<\/p>\n\n\n\n<ol start=\"6\" class=\"wp-block-list\">\n<li>\u5907\u4efd\u548c\u6062\u590d\u7b56\u7565<br>6.1 \u6570\u636e\u5e93\u5907\u4efd<br>bash<\/li>\n<\/ol>\n\n\n\n<h1 class=\"wp-block-heading\">!\/bin\/bash<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">backup_mysql.sh<\/h1>\n\n\n\n<p>BACKUP_DIR=&#8221;\/backup\/mysql&#8221;<br>DATE=$(date +%Y%m%d_%H%M%S)<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u5907\u4efd\u6570\u636e\u5e93<\/h1>\n\n\n\n<p>mysqldump -h maxkey-mysql-master -u maxkey -p${MYSQL_PASSWORD} \\<br>&#8211;single-transaction \\<br>&#8211;routines \\<br>&#8211;triggers \\<br>&#8211;events \\<br>maxkey | gzip &gt; ${BACKUP_DIR}\/maxkey_${DATE}.sql.gz<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u4fdd\u7559\u6700\u8fd17\u5929\u5907\u4efd<\/h1>\n\n\n\n<p>find ${BACKUP_DIR} -name &#8220;maxkey_*.sql.gz&#8221; -mtime +7 -delete<br>6.2 Redis\u5907\u4efd<br>bash<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">!\/bin\/bash<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">backup_redis.sh<\/h1>\n\n\n\n<p>BACKUP_DIR=&#8221;\/backup\/redis&#8221;<br>DATE=$(date +%Y%m%d_%H%M%S)<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u5907\u4efdRedis<\/h1>\n\n\n\n<p>redis-cli &#8211;cluster backup ${BACKUP_DIR}\/redis_${DATE}.rdb<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">\u4fdd\u7559\u6700\u8fd17\u5929\u5907\u4efd<\/h1>\n\n\n\n<p>find ${BACKUP_DIR} -name &#8220;redis_*.rdb&#8221; -mtime +7 -delete<\/p>\n\n\n\n<ol start=\"7\" class=\"wp-block-list\">\n<li>\u5b89\u5168\u914d\u7f6e<br>7.1 SSL\/TLS\u914d\u7f6e<br>bash<\/li>\n<\/ol>\n\n\n\n<h1 class=\"wp-block-heading\">\u4f7f\u7528Let&#8217;s Encrypt\u83b7\u53d6\u8bc1\u4e66<\/h1>\n\n\n\n<p>certbot certonly &#8211;nginx -d sso.example.com \\<br>&#8211;email admin@example.com \\<br>&#8211;agree-tos \\<br>&#8211;non-interactive<br>7.2 \u5b89\u5168\u52a0\u56fa<br>\u4fee\u6539\u9ed8\u8ba4\u7aef\u53e3<\/p>\n\n\n\n<p>\u914d\u7f6e\u9632\u706b\u5899\u89c4\u5219<\/p>\n\n\n\n<p>\u542f\u7528WAF\u9632\u62a4<\/p>\n\n\n\n<p>\u5b9a\u671f\u5b89\u5168\u626b\u63cf<\/p>\n\n\n\n<p>\u5ba1\u8ba1\u65e5\u5fd7\u76d1\u63a7<\/p>\n\n\n\n<ol start=\"8\" class=\"wp-block-list\">\n<li>\u7ef4\u62a4\u548c\u76d1\u63a7<br>8.1 \u65e5\u5e38\u7ef4\u62a4\u4efb\u52a1<br>\u76d1\u63a7\u7cfb\u7edf\u8d44\u6e90\u4f7f\u7528\u60c5\u51b5<\/li>\n<\/ol>\n\n\n\n<p>\u68c0\u67e5\u65e5\u5fd7\u6587\u4ef6\u4e2d\u7684\u9519\u8bef\u4fe1\u606f<\/p>\n\n\n\n<p>\u5b9a\u671f\u5907\u4efd\u6570\u636e\u5e93\u548c\u914d\u7f6e\u6587\u4ef6<\/p>\n\n\n\n<p>\u66f4\u65b0\u7cfb\u7edf\u548c\u5e94\u7528\u8865\u4e01<\/p>\n\n\n\n<p>8.2 \u76d1\u63a7\u6307\u6807<br>\u5e94\u7528\u54cd\u5e94\u65f6\u95f4<\/p>\n\n\n\n<p>\u7cfb\u7edf\u8d1f\u8f7d<\/p>\n\n\n\n<p>\u6570\u636e\u5e93\u8fde\u63a5\u6570<\/p>\n\n\n\n<p>\u7f13\u5b58\u547d\u4e2d\u7387<\/p>\n\n\n\n<p>\u9519\u8bef\u7387<\/p>\n\n\n\n<ol start=\"9\" class=\"wp-block-list\">\n<li>\u6545\u969c\u6392\u9664<br>9.1 \u5e38\u89c1\u95ee\u9898<br>\u5e94\u7528\u65e0\u6cd5\u542f\u52a8\uff1a\u68c0\u67e5\u65e5\u5fd7\u6587\u4ef6\uff0c\u786e\u8ba4\u6570\u636e\u5e93\u8fde\u63a5<\/li>\n<\/ol>\n\n\n\n<p>\u5355\u70b9\u767b\u5f55\u5931\u8d25\uff1a\u68c0\u67e5Redis\u96c6\u7fa4\u72b6\u6001<\/p>\n\n\n\n<p>\u6027\u80fd\u4e0b\u964d\uff1a\u68c0\u67e5\u6570\u636e\u5e93\u8fde\u63a5\u6c60\u548c\u7f13\u5b58\u547d\u4e2d\u7387<\/p>\n\n\n\n<p>9.2 \u6545\u969c\u6062\u590d\u6d41\u7a0b<br>\u786e\u8ba4\u6545\u969c\u73b0\u8c61\u548c\u5f71\u54cd\u8303\u56f4<\/p>\n\n\n\n<p>\u68c0\u67e5\u5e94\u7528\u65e5\u5fd7\u548c\u7cfb\u7edf\u76d1\u63a7<\/p>\n\n\n\n<p>\u6839\u636e\u6545\u969c\u7c7b\u578b\u6267\u884c\u6062\u590d\u64cd\u4f5c<\/p>\n\n\n\n<p>\u9a8c\u8bc1\u6062\u590d\u7ed3\u679c<\/p>\n\n\n\n<p>\u8bb0\u5f55\u6545\u969c\u62a5\u544a\u548c\u6539\u8fdb\u63aa\u65bd<\/p>\n\n\n\n<ol start=\"10\" class=\"wp-block-list\">\n<li>\u9644\u5f55<br>10.1 \u914d\u7f6e\u6587\u4ef6\u6a21\u677f<br>\u6240\u6709\u914d\u7f6e\u6587\u4ef6\u6a21\u677f\u53ef\u5728 \/opt\/maxkey\/config-templates\/ \u76ee\u5f55\u627e\u5230<\/li>\n<\/ol>\n\n\n\n<p>10.2 \u90e8\u7f72\u68c0\u67e5\u6e05\u5355<br>\u73af\u5883\u51c6\u5907\u5b8c\u6210<\/p>\n\n\n\n<p>\u6570\u636e\u5e93\u96c6\u7fa4\u90e8\u7f72\u5b8c\u6210<\/p>\n\n\n\n<p>Redis\u96c6\u7fa4\u90e8\u7f72\u5b8c\u6210<\/p>\n\n\n\n<p>MaxKey\u5e94\u7528\u90e8\u7f72\u5b8c\u6210<\/p>\n\n\n\n<p>Nginx\u8d1f\u8f7d\u5747\u8861\u914d\u7f6e\u5b8c\u6210<\/p>\n\n\n\n<p>SSL\u8bc1\u4e66\u914d\u7f6e\u5b8c\u6210<\/p>\n\n\n\n<p>\u76d1\u63a7\u7cfb\u7edf\u90e8\u7f72\u5b8c\u6210<\/p>\n\n\n\n<p>\u5907\u4efd\u7b56\u7565\u914d\u7f6e\u5b8c\u6210<\/p>\n\n\n\n<p>\u5b89\u5168\u52a0\u56fa\u5b8c\u6210<\/p>\n\n\n\n<p>\u6d4b\u8bd5\u9a8c\u8bc1\u901a\u8fc7<\/p>\n\n\n\n<p>10.3 \u6027\u80fd\u6d4b\u8bd5\u5efa\u8bae<br>\u4f7f\u7528JMeter\u8fdb\u884c\u538b\u529b\u6d4b\u8bd5\uff0c\u9a8c\u8bc1\u7cfb\u7edf\u5728\u4ee5\u4e0b\u573a\u666f\u4e0b\u7684\u8868\u73b0\uff1a<\/p>\n\n\n\n<p>500\u7528\u6237\u5e76\u53d1\u767b\u5f55<\/p>\n\n\n\n<p>1000\u7528\u6237\u5e76\u53d1\u8bbf\u95ee<\/p>\n\n\n\n<p>\u4f1a\u8bdd\u6301\u4e45\u5316\u6d4b\u8bd5<\/p>\n\n\n\n<p>\u6545\u969c\u5207\u6362\u6d4b\u8bd5<\/p>\n\n\n\n<p>\u90e8\u7f72\u5b8c\u6210\u65f6\u95f4\u9884\u4f30\uff1a4-6\u5c0f\u65f6<br>\u4eba\u5458\u8981\u6c42\uff1a2\u540d\u4e2d\u7ea7\u8fd0\u7ef4\u5de5\u7a0b\u5e08<br>\u6ce8\u610f\u4e8b\u9879\uff1a\u751f\u4ea7\u73af\u5883\u90e8\u7f72\u524d\u52a1\u5fc5\u5728\u6d4b\u8bd5\u73af\u5883\u5145\u5206\u9a8c\u8bc1<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1.2 \u90e8\u7f72\u76ee\u6807\u6784\u5efa\u9ad8\u53ef\u7528\u3001\u53ef\u6269\u5c55\u7684\u7edf\u4e00 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[5],"tags":[],"class_list":["post-76","post","type-post","status-publish","format-standard","hentry","category-5"],"_links":{"self":[{"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/posts\/76","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/comments?post=76"}],"version-history":[{"count":1,"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/posts\/76\/revisions"}],"predecessor-version":[{"id":77,"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/posts\/76\/revisions\/77"}],"wp:attachment":[{"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/media?parent=76"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/categories?post=76"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.huaweicloud.online\/index.php\/wp-json\/wp\/v2\/tags?post=76"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}