From 2f92e4f3450fc76f6edae4c8901bbf47097ef38a Mon Sep 17 00:00:00 2001 From: Codex Date: Thu, 16 Jul 2026 15:40:35 +0200 Subject: [PATCH] =?UTF-8?q?feat:=20=E7=BB=9F=E4=B8=80=E5=88=86=E5=8F=91?= =?UTF-8?q?=E7=AE=A1=E7=90=86=E5=91=98=E5=AF=86=E7=A0=81?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- .agents/skills/unidesk-secret/SKILL.md | 76 +++++++++++++++++++ .../skills/unidesk-secret/agents/openai.yaml | 4 + .../references/operations.md | 11 +-- config/hwlab-node-lanes.yaml | 15 ++-- config/hwlab-web-probe-sentinel/profiles.yaml | 28 +++---- .../secrets.auth-session-switch.yaml | 10 ++- .../secrets.fake-echo.yaml | 5 +- .../secrets.mdtodo.yaml | 5 +- ...ecrets.workbench-dsflash-go-secondary.yaml | 5 +- .../secrets.workbench-dsflash-go.yaml | 5 +- config/pikaoa.yaml | 6 +- config/secrets-distribution.yaml | 33 ++++---- docs/reference/yaml-first-ops.md | 4 +- scripts/src/hwlab-node/public-exposure.ts | 2 +- scripts/src/hwlab-node/utils.ts | 2 +- 15 files changed, 150 insertions(+), 61 deletions(-) create mode 100644 .agents/skills/unidesk-secret/SKILL.md create mode 100644 .agents/skills/unidesk-secret/agents/openai.yaml diff --git a/.agents/skills/unidesk-secret/SKILL.md b/.agents/skills/unidesk-secret/SKILL.md new file mode 100644 index 00000000..dce61d12 --- /dev/null +++ b/.agents/skills/unidesk-secret/SKILL.md @@ -0,0 +1,76 @@ +--- +name: unidesk-secret +description: UniDesk 统一管理员密码的 YAML-first 分发与清理技能。用户提到统一管理员密码、unified-admin-password、OA/PikaOA、SelfMedia、HWLAB/lab、Sub2Rank 或 ApiState 的管理员密码轮换、Secret 同步、开发版与生产版密码对齐、清理服务级 admin password 时使用。 +--- + +# UniDesk 统一管理员密码 + +遵循 `Skill(cli-spec)`,只通过 owning YAML、领域受控 CLI 和 `web-probe` 分发与验收,不读取、打印或从运行面反解密码。 + +## 唯一事实源 + +- 统一管理员密码只保存在 `/root/.unidesk/.env/unified-admin-password.txt`。 +- 文件必须是 owner-only `0600` raw file,只包含一行密码。 +- `config/secrets-distribution.yaml` 声明 raw-file source 和 Kubernetes `targetKey` 映射。 +- `config/pikaoa.yaml` 声明 PikaOA development/release 管理员密码来源。 +- `config/hwlab-node-lanes.yaml` 声明 HWLAB development/production bootstrap admin hash 来源。 +- `config/hwlab-web-probe-sentinel/*.yaml` 的 bootstrap-admin 和 admin account 来源必须指向同一文件。 +- 各应用可以保留不同 `targetKey`、Secret 名和 hash transform,但不得保留不同密码来源。 + +## 明确边界 + +- 统一以下管理员登录: + - PikaOA `pikaoa` 与 `pikaoa-dev`; + - SelfMedia `selfmedia` 与 `selfmedia-production`; + - HWLAB `v03` 与 `production`; + - Sub2Rank/ApiState 的 `APISTATE_WEB_PASSWORD`。 +- 不统一以下非管理员凭据: + - PikaOA employee 密码; + - API key、session secret、admin token; + - 数据库密码和 FRP token; + - Sub2Rank 访问 Sub2API 的 `SUB2API_ADMIN_PASSWORD`; + - HWLAB 第二测试账号和 OpenCode 账号密码。 + +## 分发流程 + +1. 先确认 source 文件 presence、字节数、SHA-256 fingerprint 和 `0600`,不得输出内容。 +2. 检查 owning YAML 中所有管理员 sourceRef 均指向统一文件。 +3. 对每个 Secret scope 先执行 `secrets plan`,再执行 `secrets sync --confirm`,最后按 job ID 查询终态并执行 `secrets status`。 +4. HWLAB 先执行 `hwlab nodes secret ensure --node NC01 --lane --name --dry-run`,确认后改为 `--confirm` 同步 hash Secret 和 rollout。 +5. 用领域 status/validate 确认 Secret key presence、fingerprint、Deployment rollout 和 health;输出必须保持 `valuesPrinted=false`。 +6. 用 `web-probe` 从 owning YAML 选择 public origin,分别验证 development 与 production 管理员登录。 +7. 只有所有目标分发和登录验收通过后,才清理旧服务级密码文件或 env 键。 + +Secret 分发高频入口: + +```bash +bun scripts/cli.ts secrets plan --config config/secrets-distribution.yaml --scope --target +bun scripts/cli.ts secrets sync --config config/secrets-distribution.yaml --scope --target --confirm +bun scripts/cli.ts secrets status --config config/secrets-distribution.yaml --scope --target +``` + +目标矩阵: + +- `pikaoa` / `pikaoa-nc01`; +- `pikaoa-dev` / `pikaoa-dev-nc01`; +- `selfmedia` / `selfmedia-nc01`; +- `selfmedia-production` / `selfmedia-production-nc01`; +- `sub2rank` / `sub2rank-nc01`。 + +## 清理规则 + +- 删除 `pikaoa-admin-password.txt` 和含不可见字符的旧 unified 文件名。 +- 从 `selfmedia-access.env` 删除 `SELFMEDIA_ADMIN_PASSWORD`,保留 username、API key 和 session secret。 +- 从 `platform-infra/apistate.env` 删除 `APISTATE_WEB_PASSWORD`,保留 API key 和 session secret。 +- 删除只包含 `HWLAB_BOOTSTRAP_ADMIN_PASSWORD` 的旧 bootstrap-admin env 文件。 +- `hwlab.auth` 或 `HWLAB_admin.txt` 若同时保存用户名,只删除密码行并保留用户名;owning YAML 不得再引用其密码行。 +- 清理后重新执行 plan,确认旧 source 不再是 required source,统一 source 仍为 present。 +- 禁止用 Secret decode、Pod env、数据库或日志回填旧来源。 + +## 验收判定 + +- 所有声明只引用一个管理员密码 sourceRef。 +- Secret sync 成功,consumer rollout 成功,status key presence 完整。 +- PikaOA、SelfMedia、HWLAB、Sub2Rank/ApiState 的 development/production 目标按实际存在矩阵通过管理员登录。 +- 旧服务级管理员密码来源已删除或移除对应键。 +- 全程只披露路径、键、presence、fingerprint、字节数、job/trace/artifact ID 和状态。 diff --git a/.agents/skills/unidesk-secret/agents/openai.yaml b/.agents/skills/unidesk-secret/agents/openai.yaml new file mode 100644 index 00000000..76d8cf93 --- /dev/null +++ b/.agents/skills/unidesk-secret/agents/openai.yaml @@ -0,0 +1,4 @@ +interface: + display_name: "UniDesk 统一管理员密码" + short_description: "统一分发、验证并清理 UniDesk 各服务管理员密码来源" + default_prompt: "使用 YAML-first 入口统一规划、分发、验证并清理管理员密码来源。" diff --git a/.agents/skills/unidesk-selfmedia/references/operations.md b/.agents/skills/unidesk-selfmedia/references/operations.md index fe226295..5f70d84d 100644 --- a/.agents/skills/unidesk-selfmedia/references/operations.md +++ b/.agents/skills/unidesk-selfmedia/references/operations.md @@ -2,11 +2,12 @@ ## 管理员凭据分发 -- 在 owner-only `/root/.unidesk/.env/selfmedia-access.env` 中维护以下键: - - `SELFMEDIA_ADMIN_USERNAME`; - - `SELFMEDIA_ADMIN_PASSWORD`; - - `SELFMEDIA_API_KEY`; - - `SELFMEDIA_SESSION_SECRET`。 +- 在 owner-only 文件中维护凭据: + - `/root/.unidesk/.env/unified-admin-password.txt` 只保存统一管理员密码; + - `/root/.unidesk/.env/selfmedia-access.env` 保存以下非密码键: + - `SELFMEDIA_ADMIN_USERNAME`; + - `SELFMEDIA_API_KEY`; + - `SELFMEDIA_SESSION_SECRET`。 - 不用 `cat`、`source`、`env`、Pod env 或 Secret decode 检查值。 - 先预检 sourceRef、键和 fingerprint: diff --git a/config/hwlab-node-lanes.yaml b/config/hwlab-node-lanes.yaml index 9aeb3efe..67b697e9 100644 --- a/config/hwlab-node-lanes.yaml +++ b/config/hwlab-node-lanes.yaml @@ -73,8 +73,9 @@ lanes: bootstrapAdmin: username: admin displayName: HWLAB v0.3 Admin - passwordSourceRef: hwlab/nc01-v03-bootstrap-admin.env - passwordSourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD + passwordSourceRef: /root/.unidesk/.env/unified-admin-password.txt + passwordSourceKey: contents + passwordSourceLine: 1 passwordHashTransform: hwlab-sha256 secretName: hwlab-v03-bootstrap-admin secretKey: password-hash @@ -181,9 +182,9 @@ lanes: displayName: HWLAB v0.3 Admin usernameSourceRef: /root/.unidesk/.env/hwlab.auth usernameSourceLine: 1 - passwordSourceRef: /root/.unidesk/.env/hwlab.auth - passwordSourceKey: HWLAB_ADMIN_PASSWORD - passwordSourceLine: 2 + passwordSourceRef: /root/.unidesk/.env/unified-admin-password.txt + passwordSourceKey: contents + passwordSourceLine: 1 passwordHashTransform: hwlab-sha256 secretName: hwlab-v03-bootstrap-admin secretKey: password-hash @@ -309,7 +310,9 @@ lanes: apiUrl: https://lab.hwpod.com bootstrapAdmin: displayName: HWLAB Production Admin - passwordSourceRef: hwlab/nc01-production-bootstrap-admin.env + passwordSourceRef: /root/.unidesk/.env/unified-admin-password.txt + passwordSourceKey: contents + passwordSourceLine: 1 secretName: hwlab-production-bootstrap-admin codeAgentProvider: secretName: hwlab-production-code-agent-provider diff --git a/config/hwlab-web-probe-sentinel/profiles.yaml b/config/hwlab-web-probe-sentinel/profiles.yaml index aa682282..122e5e72 100644 --- a/config/hwlab-web-probe-sentinel/profiles.yaml +++ b/config/hwlab-web-probe-sentinel/profiles.yaml @@ -153,9 +153,9 @@ baselines: secrets: jd01BootstrapSource: purpose: bootstrap-admin - sourceRef: /root/.unidesk/.env/HWLAB_admin.txt - sourceKey: HWLAB_ADMIN_PASSWORD - sourceLine: 2 + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 dsflashPromptSource: purpose: prompt-set sourceRef: hwlab/web-probe-sentinel-dsflash-go.env @@ -187,17 +187,17 @@ nodes: extends: templates.webProbeSentinelCicd secrets: sources: - - sourceLine: 2 - sourceKey: HWLAB_ADMIN_PASSWORD - sourceRef: /root/.unidesk/.env/HWLAB_admin.txt + - sourceLine: 1 + sourceKey: contents + sourceRef: /root/.unidesk/.env/unified-admin-password.txt purpose: bootstrap-admin - sourceKey: DSFLASH_GO_TOOL_CALL_10X_PROMPTS_JSON sourceRef: hwlab/web-probe-sentinel-dsflash-go.env purpose: prompt-set - purpose: account-a - sourceRef: /root/.unidesk/.env/HWLAB_admin.txt - sourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD - sourceLine: 2 + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 format: web-account-json usernameSourceRef: /root/.unidesk/.env/HWLAB_admin.txt usernameSourceLine: 1 @@ -269,14 +269,16 @@ nodes: secrets: sources: - purpose: bootstrap-admin - sourceRef: "hwlab/${nodeLower}-${lane}-bootstrap-admin.env" - sourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 - sourceKey: DSFLASH_GO_TOOL_CALL_10X_PROMPTS_JSON sourceRef: hwlab/web-probe-sentinel-dsflash-go.env purpose: prompt-set - purpose: account-a - sourceRef: "hwlab/${nodeLower}-${lane}-bootstrap-admin.env" - sourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 format: web-account-json username: admin - purpose: account-b diff --git a/config/hwlab-web-probe-sentinel/secrets.auth-session-switch.yaml b/config/hwlab-web-probe-sentinel/secrets.auth-session-switch.yaml index b8160039..07da2a82 100644 --- a/config/hwlab-web-probe-sentinel/secrets.auth-session-switch.yaml +++ b/config/hwlab-web-probe-sentinel/secrets.auth-session-switch.yaml @@ -8,11 +8,13 @@ sentinel: secrets: sources: - purpose: bootstrap-admin - sourceRef: hwlab/d601-v03-bootstrap-admin.env - sourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 - purpose: account-a - sourceRef: hwlab/d601-v03-bootstrap-admin.env - sourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 format: web-account-json username: admin - purpose: account-b diff --git a/config/hwlab-web-probe-sentinel/secrets.fake-echo.yaml b/config/hwlab-web-probe-sentinel/secrets.fake-echo.yaml index 26943d91..3b73cef9 100644 --- a/config/hwlab-web-probe-sentinel/secrets.fake-echo.yaml +++ b/config/hwlab-web-probe-sentinel/secrets.fake-echo.yaml @@ -9,8 +9,9 @@ sentinel: secrets: sources: - purpose: bootstrap-admin - sourceRef: hwlab/d518-v03-bootstrap-admin.env - sourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 - purpose: prompt-set sourceRef: hwlab/web-probe-sentinel-fake-echo.env sourceKey: FAKE_ECHO_SENTINEL_PROMPTS_JSON diff --git a/config/hwlab-web-probe-sentinel/secrets.mdtodo.yaml b/config/hwlab-web-probe-sentinel/secrets.mdtodo.yaml index a51ce981..9e66b52a 100644 --- a/config/hwlab-web-probe-sentinel/secrets.mdtodo.yaml +++ b/config/hwlab-web-probe-sentinel/secrets.mdtodo.yaml @@ -8,8 +8,9 @@ sentinel: secrets: sources: - purpose: bootstrap-admin - sourceRef: hwlab/d601-v03-bootstrap-admin.env - sourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 - purpose: frp-token sourceRef: platform-infra/pk01-frp.env sourceKey: FRP_TOKEN diff --git a/config/hwlab-web-probe-sentinel/secrets.workbench-dsflash-go-secondary.yaml b/config/hwlab-web-probe-sentinel/secrets.workbench-dsflash-go-secondary.yaml index 45aa54e1..1471dc53 100644 --- a/config/hwlab-web-probe-sentinel/secrets.workbench-dsflash-go-secondary.yaml +++ b/config/hwlab-web-probe-sentinel/secrets.workbench-dsflash-go-secondary.yaml @@ -8,8 +8,9 @@ sentinel: secrets: sources: - purpose: bootstrap-admin - sourceRef: hwlab/d518-v03-bootstrap-admin.env - sourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 - purpose: prompt-set sourceRef: hwlab/web-probe-sentinel-dsflash-go.env sourceKey: DSFLASH_GO_TOOL_CALL_10X_PROMPTS_JSON diff --git a/config/hwlab-web-probe-sentinel/secrets.workbench-dsflash-go.yaml b/config/hwlab-web-probe-sentinel/secrets.workbench-dsflash-go.yaml index db57256b..a17759d4 100644 --- a/config/hwlab-web-probe-sentinel/secrets.workbench-dsflash-go.yaml +++ b/config/hwlab-web-probe-sentinel/secrets.workbench-dsflash-go.yaml @@ -8,8 +8,9 @@ sentinel: secrets: sources: - purpose: bootstrap-admin - sourceRef: hwlab/d601-v03-bootstrap-admin.env - sourceKey: HWLAB_BOOTSTRAP_ADMIN_PASSWORD + sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents + sourceLine: 1 - purpose: prompt-set sourceRef: hwlab/web-probe-sentinel-dsflash-go.env sourceKey: DSFLASH_GO_TOOL_CALL_10X_PROMPTS_JSON diff --git a/config/pikaoa.yaml b/config/pikaoa.yaml index 3e484da6..55d4b21e 100644 --- a/config/pikaoa.yaml +++ b/config/pikaoa.yaml @@ -125,7 +125,7 @@ developmentRuntime: administrator: username: admin password: - sourceRef: ~/.unidesk/.env/pikaoa-admin-password.txt + sourceRef: /root/.unidesk/.env/unified-admin-password.txt targetKey: PIKAOA_BOOTSTRAP_ADMIN_PASSWORD employee: username: employee @@ -350,7 +350,7 @@ releaseRuntime: administrator: username: admin password: - sourceRef: ~/.unidesk/.env/pikaoa-admin-password.txt + sourceRef: /root/.unidesk/.env/unified-admin-password.txt targetKey: PIKAOA_BOOTSTRAP_ADMIN_PASSWORD employee: username: employee @@ -601,7 +601,7 @@ delivery: bootstrapUsers: administrator: username: admin - passwordSourceRef: ~/.unidesk/.env/pikaoa-admin-password.txt + passwordSourceRef: /root/.unidesk/.env/unified-admin-password.txt employee: username: employee passwordSourceRef: ~/.unidesk/.env/pikaoa-employee-password.txt diff --git a/config/secrets-distribution.yaml b/config/secrets-distribution.yaml index 1534838f..7f312f75 100644 --- a/config/secrets-distribution.yaml +++ b/config/secrets-distribution.yaml @@ -85,15 +85,11 @@ sources: - sourceRef: platform-infra/apistate.env type: env requiredKeys: - - APISTATE_WEB_PASSWORD - APISTATE_API_KEY - APISTATE_SESSION_SECRET createIfMissing: enabled: true randomBase64Url: - APISTATE_WEB_PASSWORD: - bytes: 32 - prefix: asp_ APISTATE_API_KEY: bytes: 32 prefix: ask_ @@ -173,14 +169,14 @@ sources: createIfMissing: enabled: false externalFiles: - - sourceRef: ~/.unidesk/.env/pikaoa-admin-password.txt + - sourceRef: /root/.unidesk/.env/unified-admin-password.txt type: raw-file required: true createIfMissing: enabled: true randomBase64Url: bytes: 24 - prefix: poa_ + prefix: admin_ - sourceRef: ~/.unidesk/.env/pikaoa-employee-password.txt type: raw-file required: true @@ -193,7 +189,6 @@ sources: type: env requiredKeys: - SELFMEDIA_ADMIN_USERNAME - - SELFMEDIA_ADMIN_PASSWORD - SELFMEDIA_API_KEY - SELFMEDIA_SESSION_SECRET createIfMissing: @@ -201,9 +196,6 @@ sources: values: SELFMEDIA_ADMIN_USERNAME: admin randomBase64Url: - SELFMEDIA_ADMIN_PASSWORD: - bytes: 32 - prefix: smp_ SELFMEDIA_API_KEY: bytes: 32 prefix: smk_ @@ -240,6 +232,11 @@ targets: namespace: platform-infra scope: sub2rank enabled: true + consumerRollout: + deployments: + - sub2rank + timeoutSeconds: 180 + pollIntervalSeconds: 5 - id: hwlab-jd01-v03 route: JD01:k3s namespace: hwlab-v03 @@ -304,7 +301,7 @@ kubernetesSecrets: - sourceRef: platform-infra/pikaoa.env sourceKey: OA_ADMIN_TOKEN targetKey: OA_ADMIN_TOKEN - - sourceRef: ~/.unidesk/.env/pikaoa-admin-password.txt + - sourceRef: /root/.unidesk/.env/unified-admin-password.txt sourceKey: contents targetKey: PIKAOA_BOOTSTRAP_ADMIN_PASSWORD - sourceRef: ~/.unidesk/.env/pikaoa-employee-password.txt @@ -324,7 +321,7 @@ kubernetesSecrets: - sourceRef: platform-infra/pikaoa-dev.env sourceKey: OA_ADMIN_TOKEN targetKey: OA_ADMIN_TOKEN - - sourceRef: ~/.unidesk/.env/pikaoa-admin-password.txt + - sourceRef: /root/.unidesk/.env/unified-admin-password.txt sourceKey: contents targetKey: PIKAOA_BOOTSTRAP_ADMIN_PASSWORD - sourceRef: ~/.unidesk/.env/pikaoa-employee-password.txt @@ -338,8 +335,8 @@ kubernetesSecrets: - sourceRef: /root/.unidesk/.env/selfmedia-access.env sourceKey: SELFMEDIA_ADMIN_USERNAME targetKey: admin-username - - sourceRef: /root/.unidesk/.env/selfmedia-access.env - sourceKey: SELFMEDIA_ADMIN_PASSWORD + - sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents targetKey: admin-password - sourceRef: /root/.unidesk/.env/selfmedia-access.env sourceKey: SELFMEDIA_API_KEY @@ -374,8 +371,8 @@ kubernetesSecrets: - sourceRef: /root/.unidesk/.env/selfmedia-access.env sourceKey: SELFMEDIA_ADMIN_USERNAME targetKey: admin-username - - sourceRef: /root/.unidesk/.env/selfmedia-access.env - sourceKey: SELFMEDIA_ADMIN_PASSWORD + - sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents targetKey: admin-password - sourceRef: /root/.unidesk/.env/selfmedia-access.env sourceKey: SELFMEDIA_API_KEY @@ -407,8 +404,8 @@ kubernetesSecrets: secretName: sub2rank-secrets type: Opaque data: - - sourceRef: platform-infra/apistate.env - sourceKey: APISTATE_WEB_PASSWORD + - sourceRef: /root/.unidesk/.env/unified-admin-password.txt + sourceKey: contents targetKey: APISTATE_WEB_PASSWORD - sourceRef: platform-infra/apistate.env sourceKey: APISTATE_API_KEY diff --git a/docs/reference/yaml-first-ops.md b/docs/reference/yaml-first-ops.md index 7fc432d9..d20e77d6 100644 --- a/docs/reference/yaml-first-ops.md +++ b/docs/reference/yaml-first-ops.md @@ -41,8 +41,8 @@ - 最小 smoke 示例只用于证明通用规则,不构成第二配置真相: - 读取 `config/pikaoa.yaml#releaseRuntime.targets.NC01.runtime.administrator.password`; - - 可直接得到管理员用户名、密码 `sourceRef` 与 `targetKey`; - - 修改密码应编辑该 `sourceRef`,再走 PikaOA/Secret 分发的领域受控入口; + - 可直接得到管理员用户名、统一密码 `sourceRef` 与 `targetKey`; + - 修改密码应编辑 `/root/.unidesk/.env/unified-admin-password.txt`,再走 PikaOA/Secret 分发的领域受控入口; - 到此停止,无需读取 PikaOA 源码、数据库或 Kubernetes Secret。 本文定义 UniDesk 的 YAML-first 异构分布式运维架构,是将节点、lane、服务、Secret、公开暴露、数据库、rollout 和探针决策收敛为声明式配置与可复用 CLI 执行的长期参考。具体数值归属于 `config/` 下的 YAML;本文只定义归属关系和架构。 diff --git a/scripts/src/hwlab-node/public-exposure.ts b/scripts/src/hwlab-node/public-exposure.ts index 774f8086..11f804c0 100644 --- a/scripts/src/hwlab-node/public-exposure.ts +++ b/scripts/src/hwlab-node/public-exposure.ts @@ -61,7 +61,7 @@ export function isSafeWebProbeScriptArtifactPath(value: string): boolean { export function parseSecretOptions(args: string[]): NodeSecretOptions { const [actionRaw] = args; if (actionRaw !== "status" && actionRaw !== "ensure" && actionRaw !== "cleanup-owned-postgres" && actionRaw !== "cleanup-obsolete") { - throw new Error("secret usage: status|ensure --node NODE --lane vNN --name hwlab-vNN-openfga|hwlab-vNN-master-server-admin-api-key|hwlab-vNN-bootstrap-admin|hwlab-cloud-api-vNN-db|hwlab-vNN-code-agent-provider [--dry-run|--confirm] | cleanup-owned-postgres --node NODE --lane vNN [--dry-run|--confirm] | cleanup-obsolete --node NODE --lane vNN --name hwpod-vNN-db [--dry-run|--confirm]"); + throw new Error("secret usage: status|ensure --node NODE --lane LANE --name SECRET [--dry-run|--confirm] | cleanup-owned-postgres --node NODE --lane LANE [--dry-run|--confirm] | cleanup-obsolete --node NODE --lane LANE --name SECRET [--dry-run|--confirm]"); } const node = requiredOption(args, "--node"); assertNodeId(node); diff --git a/scripts/src/hwlab-node/utils.ts b/scripts/src/hwlab-node/utils.ts index be4d2f1d..9b3f804c 100644 --- a/scripts/src/hwlab-node/utils.ts +++ b/scripts/src/hwlab-node/utils.ts @@ -85,7 +85,7 @@ export function positiveIntegerOption(args: string[], name: string, defaultValue } export function assertLane(value: string): void { - if (!/^v[0-9]{2,}$/u.test(value)) throw new Error(`--lane must look like v03/v04, got ${value}`); + if (!/^[A-Za-z0-9_-]+$/u.test(value)) throw new Error(`--lane must be a simple YAML lane id, got ${value}`); } export function assertNodeId(value: string): void {