修复清智创游官网引擎下载接口路由
Project CI / AI game creator shell Rust crates (push) Has been cancelled
Project CI / Backend tests (push) Has been cancelled
Project CI / Native shell tests (push) Has been cancelled
Project CI / Frontend tests (push) Has been cancelled
Project CI / Repository checks (push) Has been cancelled
Project CI / AI game creator shell web tests (push) Has been cancelled
Project CI / AI game creator shell Rust lane 1/2 (push) Has been cancelled
Project CI / AI game creator shell Rust lane 2/2 (push) Has been cancelled
Project CI / AI game creator shell Rust smoke (push) Has been cancelled
Project CI / AI game creator shell Rust crates (push) Has been cancelled
Project CI / Backend tests (push) Has been cancelled
Project CI / Native shell tests (push) Has been cancelled
Project CI / Frontend tests (push) Has been cancelled
Project CI / Repository checks (push) Has been cancelled
Project CI / AI game creator shell web tests (push) Has been cancelled
Project CI / AI game creator shell Rust lane 1/2 (push) Has been cancelled
Project CI / AI game creator shell Rust lane 2/2 (push) Has been cancelled
Project CI / AI game creator shell Rust smoke (push) Has been cancelled
新增 tsingnovagames.com 独立 Nginx vhost 并代理 /api 到 api-server 补充官网 /home/ 静态首页与下载接口回归测试 同步生产运维验收与排障说明
This commit is contained in:
@@ -47,6 +47,79 @@ server {
|
||||
}
|
||||
}
|
||||
|
||||
# 清智创游官网独立静态站点:根页面位于 /home/index.html,API 仍由当前 api-server 提供。
|
||||
# 该 vhost 不依赖主站 SERVER_ALIASES,避免域名落入静态站点后对 /api 返回 Nginx 404。
|
||||
server {
|
||||
listen 80;
|
||||
server_name tsingnovagames.com www.tsingnovagames.com;
|
||||
return 301 https://$host$request_uri;
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl http2;
|
||||
server_name tsingnovagames.com www.tsingnovagames.com;
|
||||
access_log /var/log/nginx/genarrative.access.log genarrative_upstream;
|
||||
error_log /var/log/nginx/genarrative.error.log warn;
|
||||
|
||||
ssl_certificate /etc/letsencrypt/live/genarrative.example.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/genarrative.example.com/privkey.pem;
|
||||
|
||||
root /srv/genarrative/web;
|
||||
index index.html;
|
||||
|
||||
include /etc/nginx/snippets/genarrative-maintenance.conf;
|
||||
|
||||
location ~ ^/api(?:/|$) {
|
||||
default_type application/json;
|
||||
client_max_body_size 210m;
|
||||
limit_conn genarrative_api_conn 64;
|
||||
limit_req zone=genarrative_api_rps burst=64 nodelay;
|
||||
|
||||
if ($genarrative_maintenance) {
|
||||
return 503 '{"ok":false,"error":{"code":"MAINTENANCE","message":"服务维护中"}}';
|
||||
}
|
||||
|
||||
proxy_pass http://genarrative_api;
|
||||
proxy_http_version 1.1;
|
||||
proxy_buffering off;
|
||||
proxy_read_timeout 3600s;
|
||||
proxy_send_timeout 3600s;
|
||||
add_header X-Accel-Buffering no always;
|
||||
proxy_set_header Connection "";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header X-Forwarded-Host $host;
|
||||
proxy_set_header X-Request-Id $request_id;
|
||||
}
|
||||
|
||||
location = / {
|
||||
error_page 503 /maintenance.html;
|
||||
|
||||
if ($genarrative_maintenance) {
|
||||
return 503;
|
||||
}
|
||||
|
||||
try_files /home/index.html =404;
|
||||
}
|
||||
|
||||
location ^~ /home/ {
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
|
||||
location / {
|
||||
error_page 503 /maintenance.html;
|
||||
error_page 404 /404.html;
|
||||
|
||||
if ($genarrative_maintenance) {
|
||||
return 503;
|
||||
}
|
||||
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
}
|
||||
|
||||
server {
|
||||
listen 443 ssl http2;
|
||||
server_name genarrative.example.com;
|
||||
|
||||
@@ -112,6 +112,19 @@
|
||||
},
|
||||
"docs": ["`/assets/*`"]
|
||||
},
|
||||
{
|
||||
"id": "official_home_assets",
|
||||
"samplePath": "/home/assets/index.js",
|
||||
"expect": {
|
||||
"kind": "static",
|
||||
"root": "web",
|
||||
"mode": "exact"
|
||||
},
|
||||
"nginx": {
|
||||
"production": ["location ^~ /home/", "try_files $uri $uri/ =404;"]
|
||||
},
|
||||
"docs": ["/home/"]
|
||||
},
|
||||
{
|
||||
"id": "generic_api_proxy",
|
||||
"samplePath": "/api/assets/history",
|
||||
|
||||
@@ -10,6 +10,7 @@
|
||||
- 默认转发 `api-server` 到 `127.0.0.1:8082`。
|
||||
- 默认转发最小 SpacetimeDB 公网路由到 `127.0.0.1:3101`。
|
||||
- 默认静态目录为 `/srv/genarrative/web`,维护开关文件为 `/var/lib/genarrative/maintenance/enabled`。
|
||||
- 清智创游官网独立域名的 `/home/` 静态资源仍由 Nginx 独立 vhost 提供;`/api/*` 必须进入 api-server,不能回退为静态 404。
|
||||
- 静态响应会显式写入 `Cache-Control`:HTML / SPA fallback 默认 `no-cache`,Vite 指纹静态资源默认 `public, max-age=31536000, immutable`,其它静态资源默认 `no-cache`。三档分别由 `GENARRATIVE_PINGORA_GATEWAY_HTML_CACHE_CONTROL`、`GENARRATIVE_PINGORA_GATEWAY_ASSET_CACHE_CONTROL` 和 `GENARRATIVE_PINGORA_GATEWAY_STATIC_CACHE_CONTROL` 覆盖,配置值禁止换行或 NUL,避免响应头注入。静态文件还会按 metadata 写入弱 `ETag`、`Last-Modified` 与 `Accept-Ranges: bytes`,并对 `GET` / `HEAD` 的 `If-None-Match`、`If-Modified-Since` 返回 `304`;单段 `Range: bytes=` 返回 `206 + Content-Range`,越界范围返回 `416 + Content-Range: bytes */<len>`,保持 HTML `no-cache` 下的浏览器协商缓存和 Nginx 直连体验一致。
|
||||
- `/api` 通用路由同时按 `Content-Length` 与实际流式请求体累计字节数执行大小上限,避免客户端省略长度头绕过网关保护。
|
||||
- `GENARRATIVE_PINGORA_GATEWAY_PROBE_TOKEN` 非空时,`/__genarrative_pingora/healthz` 可用同名探针 header 做本机 shadow 健康检查;未带 token 或 token 不匹配时仍返回 404。
|
||||
|
||||
@@ -4,6 +4,22 @@
|
||||
|
||||
主站 Vite 将 `/api/client-downloads` 转发到当前 `runtimeServerTarget`。通过 `npm run dev:api-server` 与 `npm run dev:web` 联调时,先确认运行日志与 `.app/dev-stack.json` 的实际 API 地址,检查 `/healthz`,再从 Vite 同源访问 `/api/client-downloads`;正常应返回 `downloads` 平台列表、`unavailablePlatforms` 和 `Cache-Control: no-store`,不能落入 SPA HTML fallback。渠道 404 表示未发布,单端失败只影响对应平台;公网 OSS 清单没有官网 CORS,浏览器不直接读取该清单。
|
||||
|
||||
### 清智创游官网独立域名路由
|
||||
|
||||
清智创游官网 `tsingnovagames.com` / `www.tsingnovagames.com` 的首页静态资源位于同一 Web 根目录的 `/home/`,首页“游戏引擎”入口按同源请求 `/api/client-downloads`。生产 Nginx 必须让这两个域名进入包含 `/api` 反代的主站 `server block`,并把该域名根路径重写到 `/home/`;否则页面可以打开,但接口会被静态站点直接返回 HTML 404,前端显示“暂时无法获取下载信息,请稍后重试”。
|
||||
|
||||
`Genarrative-Server-Provision` 在 `SERVER_NAME=genarrative.world`(或 `www.genarrative.world`)且使用 `production-https` 时会自动补入这两个官网别名,并渲染 `/home/` 根路径兼容规则。修改后需重新执行一次正式服务器配置发布并 reload Nginx,不要只重启 api-server:
|
||||
|
||||
```bash
|
||||
curl -fsS -D ~/data/tmp/tsingnova-client-download.headers \
|
||||
https://tsingnovagames.com/api/client-downloads \
|
||||
-o ~/data/tmp/tsingnova-client-download.json
|
||||
jq . ~/data/tmp/tsingnova-client-download.json
|
||||
grep -i '^cache-control: no-store' ~/data/tmp/tsingnova-client-download.headers
|
||||
```
|
||||
|
||||
验收必须同时满足:接口返回 `200 application/json`,响应包含 `downloads` 与 `unavailablePlatforms`,并带 `Cache-Control: no-store`;`https://tsingnovagames.com/` 仍返回官网首页。若接口仍返回 Nginx 404,优先检查 `nginx -T` 中 `server_name` 是否包含上述两个域名以及 `/api` location 是否指向 `genarrative_api`。
|
||||
|
||||
## 构建回归的隔离与发布文件权限
|
||||
|
||||
Git hook 的临时仓库测试必须清除子进程继承的仓库定位环境(例如 `GIT_DIR`、`GIT_WORK_TREE`、`GIT_INDEX_FILE`);仅设置 `cwd` 不能隔离 Git。回归应从带这些变量的外层仓库运行,验证外层引用、索引与配置不变。临时测试文件必须留在独立目录并清理,不得通过测试生成主仓库提交或覆盖 ESLint、Prettier 配置。修复 lint 配置时保留原有规则、忽略范围与零警告门禁,不以关闭规则代替排障。
|
||||
|
||||
@@ -0,0 +1,28 @@
|
||||
import { readFileSync } from 'node:fs';
|
||||
|
||||
import { describe, expect, it } from 'vitest';
|
||||
|
||||
const productionNginx = readFileSync('deploy/nginx/genarrative.conf', 'utf8');
|
||||
const provisionScript = readFileSync(
|
||||
'scripts/jenkins-server-provision.sh',
|
||||
'utf8',
|
||||
);
|
||||
|
||||
describe('清智创游官网引擎下载路由', () => {
|
||||
it('生产 Nginx 为官网域名提供独立 vhost 和 API 反代', () => {
|
||||
expect(productionNginx).toContain(
|
||||
'server_name tsingnovagames.com www.tsingnovagames.com;',
|
||||
);
|
||||
expect(productionNginx).toMatch(
|
||||
/server_name tsingnovagames\.com www\.tsingnovagames\.com;[\s\S]*?location ~ \^\/api\(\?:\/\|\$\)[\s\S]*?proxy_pass http:\/\/genarrative_api;/u,
|
||||
);
|
||||
expect(productionNginx).toContain('try_files /home/index.html =404;');
|
||||
expect(productionNginx).toContain('location ^~ /home/');
|
||||
});
|
||||
|
||||
it('Server-Provision 会把正式证书路径渲染进官网 vhost', () => {
|
||||
expect(provisionScript).toContain(
|
||||
's|/etc/letsencrypt/live/genarrative.example.com/|/etc/letsencrypt/live/${SERVER_NAME}/|g',
|
||||
);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user