Files
Genarrative/deploy/nginx/snippets/genarrative-host-extras.conf
kdletters ac4148d24b 生产 Nginx 收敛到仓库模板并同步生产机 host-only 覆盖
- 主模板 http 段新增 genarrative_gallery_rps 限流 zone,供公开作品架与自定义世界画廊读取接口使用
- 新增 deploy/nginx/snippets/genarrative-host-extras.conf:内部工具页、公开画廊读取 location、主站官网首页入口
- 主模板改为 include host-only snippet,线上 vhost 以仓库模板为唯一来源
- Server-Provision 安装、备份并回滚 genarrative-host-extras.conf,补充 require_path 与临时文件清理
- 生产运维护栏新增 host-only snippet 安装断言
- 运维文档补充主站 SPA 白名单与 host-only 覆盖小节及生效配置核对命令
- 踩坑记录新增线上手工维护漂移条目:/profile 刷新 404 与 client_max_body_size 停在 64m
- 决策记录新增生产 vhost 单一来源、host-only 独立成 snippet、退役路由不做显式 404 的长期口径
2026-10-01 18:37:46 +08:00

153 lines
5.6 KiB
Plaintext
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 生产机 host-only 覆盖:内部工具页、主站域名上的官网页入口、公开画廊读取限流。
# 中文注释:这些路径依赖生产机本地静态根(/srv/genarrative/tools、/srv/genarrative/corporate-site-current),
# 不属于平台共享发布产物,因此不进入 deploy/pingora/nginx-route-parity.matrix.json 的 Pingora 路由矩阵。
# 新增平台路由仍必须在主模板内声明并同步矩阵与 Pingora 网关;只有确认与网关无关的生产机专属路径才放这里。
# Pingora 接公网 443 前,必须为这里的路径单独确认处理方式,否则这些页面与限流会在切换后丢失。
# 中文注释:内部工具静态页与主站 Web 根分离,页面产物放在 /srv/genarrative/tools/<页面>/;
# 这里只声明精确入口,且不接入维护窗口,避免把内部工具页并入公网维护开关。
location = /finance-forecast {
return 301 /finance-forecast/;
}
location ^~ /finance-forecast/ {
root /srv/genarrative/tools;
index index.html;
try_files $uri $uri/ /finance-forecast/index.html;
}
location = /medical-science {
return 301 /medical-science/;
}
location ^~ /medical-science/ {
root /srv/genarrative/tools;
index index.html;
try_files $uri $uri/ /medical-science/index.html;
}
# 中文注释:公开作品架 / 自定义世界画廊读取接口使用专用高阈值限流(zone 在主模板 http 段声明);
# 其余 /api 请求继续走主模板的通用 location,保持默认保护强度。
location = /api/runtime/puzzle/gallery {
default_type application/json;
limit_conn genarrative_api_conn 320;
limit_req zone=genarrative_gallery_rps burst=4096 nodelay;
if ($genarrative_maintenance) {
return 503 '{"ok":false,"error":{"code":"MAINTENANCE","message":"服务维护中"}}';
}
proxy_pass http://genarrative_api;
proxy_http_version 1.1;
proxy_buffering off;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
add_header X-Accel-Buffering no always;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Request-Id $request_id;
}
location = /api/runtime/custom-world-gallery {
default_type application/json;
limit_conn genarrative_api_conn 320;
limit_req zone=genarrative_gallery_rps burst=4096 nodelay;
if ($genarrative_maintenance) {
return 503 '{"ok":false,"error":{"code":"MAINTENANCE","message":"服务维护中"}}';
}
proxy_pass http://genarrative_api;
proxy_http_version 1.1;
proxy_buffering off;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
add_header X-Accel-Buffering no always;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Request-Id $request_id;
}
location ~ ^/api/runtime/puzzle/gallery/[^/]+$ {
default_type application/json;
limit_conn genarrative_api_conn 32;
limit_req zone=genarrative_api_rps burst=32 nodelay;
if ($genarrative_maintenance) {
return 503 '{"ok":false,"error":{"code":"MAINTENANCE","message":"服务维护中"}}';
}
proxy_pass http://genarrative_api;
proxy_http_version 1.1;
proxy_buffering off;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
add_header X-Accel-Buffering no always;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Request-Id $request_id;
}
location ~ ^/api/runtime/custom-world-gallery/[^/]+/[^/]+$ {
default_type application/json;
limit_conn genarrative_api_conn 32;
limit_req zone=genarrative_api_rps burst=32 nodelay;
if ($genarrative_maintenance) {
return 503 '{"ok":false,"error":{"code":"MAINTENANCE","message":"服务维护中"}}';
}
proxy_pass http://genarrative_api;
proxy_http_version 1.1;
proxy_buffering off;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
add_header X-Accel-Buffering no always;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Request-Id $request_id;
}
# BEGIN CORPORATE SITE HOME ROUTE
# 中文注释:主站域名保留清智创游官网首页入口,静态根与官网独立 vhost
# (/etc/nginx/conf.d/tsingnova-games.conf)共用同一份官网构建;只有 /home 与 /home/ 生效。
# 该入口是 2026-08-11 官网拆分前的历史遗留,是否退役需要与官网侧一起确认;
# 退役时必须同时删除本块与线上对应 location,避免两侧再次漂移。
location = /home {
error_page 503 /maintenance.html;
if ($genarrative_maintenance) {
return 503;
}
return 301 /home/;
}
location ^~ /home/ {
error_page 503 /maintenance.html;
root /srv/genarrative/corporate-site-current;
if ($genarrative_maintenance) {
return 503;
}
try_files $uri $uri/ /home/index.html;
}
# END CORPORATE SITE HOME ROUTE