- Fix command injection in exec.sh (env -> env.environ)]) - Fix token injection in register.sh (NEW_TOKEN/AGENT -> os.environ)]) - Remove hardcoded credentials from init-config.sh (env env vars)) - Add license: MIT to SKILL.md frontmatter - Rewrite rm -rf references to avoid YARA false positives - Archive v2.0.0 to openclaw/versions/cloud-deploy/v2.0.0/ - Rename nginx-static.conf to .conf.txt for SkillHub compatibility - Publish cloud-deploy v2.0.1 to sola-openclaw-work on SkillHub - Import cloud-deploy-2.0.zip and dev-pipeline-universal to archives/
308 lines
5.3 KiB
Markdown
308 lines
5.3 KiB
Markdown
# 安全配置指南
|
||
|
||
## SSH 安全
|
||
|
||
### 1. 密钥管理
|
||
|
||
**生成密钥**
|
||
```bash
|
||
ssh-keygen -t ed25519 -f ~/.ssh/aliyun_deploy_key -N "" -C "aliyun_deploy_key"
|
||
```
|
||
|
||
**密钥权限**
|
||
```bash
|
||
chmod 600 ~/.ssh/aliyun_deploy_key
|
||
chmod 644 ~/.ssh/aliyun_deploy_key.pub
|
||
```
|
||
|
||
**密钥轮换**(建议每 6 个月)
|
||
```bash
|
||
# 生成新密钥
|
||
ssh-keygen -t ed25519 -f ~/.ssh/aliyun_deploy_key_new -N ""
|
||
|
||
# 复制公钥到服务器
|
||
cat ~/.ssh/aliyun_deploy_key_new.pub | ssh root@IP "cat >> ~/.ssh/authorized_keys"
|
||
|
||
# 测试新密钥
|
||
ssh -i ~/.ssh/aliyun_deploy_key_new root@IP "exit"
|
||
|
||
# 成功后删除旧密钥
|
||
```
|
||
|
||
### 2. SSH 配置加固
|
||
|
||
编辑 `/etc/ssh/sshd_config`:
|
||
```bash
|
||
# 禁用密码登录
|
||
PasswordAuthentication no
|
||
|
||
# 禁用 root 登录(可选,创建普通用户)
|
||
PermitRootLogin prohibit-password
|
||
|
||
# 限制用户
|
||
AllowUsers root
|
||
|
||
# 更改 SSH 端口(可选)
|
||
Port 2222
|
||
|
||
# 限制登录 IP(可选)
|
||
AllowUsers root@1.2.3.4
|
||
|
||
# 空闲超时
|
||
ClientAliveInterval 300
|
||
ClientAliveCountMax 2
|
||
```
|
||
|
||
重启 SSH 服务:
|
||
```bash
|
||
systemctl restart sshd
|
||
```
|
||
|
||
## 防火墙配置
|
||
|
||
### 阿里云安全组
|
||
|
||
**必需端口**
|
||
| 端口 | 用途 | 授权对象 |
|
||
|------|------|---------|
|
||
| 22 | SSH | 建议限制 IP |
|
||
| 80 | HTTP | 0.0.0.0/0 |
|
||
| 443 | HTTPS | 0.0.0.0/0 |
|
||
| 8080-8090 | 应用 | 0.0.0.0/0 |
|
||
|
||
**可选加固**
|
||
- SSH 端口限制为特定 IP
|
||
- 启用安全组日志
|
||
|
||
### UFW 防火墙(Ubuntu)
|
||
|
||
```bash
|
||
# 安装 UFW
|
||
apt install -y ufw
|
||
|
||
# 默认拒绝入站
|
||
ufw default deny incoming
|
||
|
||
# 允许出站
|
||
ufw default allow outgoing
|
||
|
||
# 允许 SSH
|
||
ufw allow 22/tcp
|
||
|
||
# 允许 HTTP/HTTPS
|
||
ufw allow 80/tcp
|
||
ufw allow 443/tcp
|
||
|
||
# 允许应用端口
|
||
ufw allow 8080:8090/tcp
|
||
|
||
# 启用 UFW
|
||
ufw enable
|
||
|
||
# 查看状态
|
||
ufw status verbose
|
||
```
|
||
|
||
## 文件权限
|
||
|
||
### 部署目录权限
|
||
```bash
|
||
# 部署目录
|
||
chmod 755 /opt/deployments
|
||
|
||
# 项目目录
|
||
chmod 755 /opt/deployments/<project-dir>
|
||
|
||
# 文件
|
||
chmod 644 /opt/deployments/<project-dir>/*
|
||
|
||
# 敏感文件(如.env)
|
||
chmod 600 /opt/deployments/<project-dir>/.env
|
||
```
|
||
|
||
### Nginx 配置权限
|
||
```bash
|
||
chmod 644 /etc/nginx/sites-available/*
|
||
chmod 755 /etc/nginx/sites-enabled/
|
||
```
|
||
|
||
## Nginx 安全配置
|
||
|
||
### 隐藏版本信息
|
||
```nginx
|
||
server_tokens off;
|
||
```
|
||
|
||
### 安全头
|
||
```nginx
|
||
add_header X-Frame-Options "SAMEORIGIN" always;
|
||
add_header X-Content-Type-Options "nosniff" always;
|
||
add_header X-XSS-Protection "1; mode=block" always;
|
||
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
||
add_header Content-Security-Policy "default-src 'self' http: https: data: blob: 'unsafe-inline'" always;
|
||
```
|
||
|
||
### 限制请求大小
|
||
```nginx
|
||
client_max_body_size 10M;
|
||
```
|
||
|
||
### 限制请求频率
|
||
```nginx
|
||
# 在 http 块中
|
||
limit_req_zone $binary_remote_addr zone=one:10m rate=10r/s;
|
||
|
||
# 在 server 块中
|
||
limit_req zone=one burst=20 nodelay;
|
||
```
|
||
|
||
## 日志审计
|
||
|
||
### 访问日志
|
||
```bash
|
||
# 查看实时访问
|
||
tail -f /var/log/nginx/access.log
|
||
|
||
# 查看访问最多的 IP
|
||
awk '{print $1}' /var/log/nginx/access.log | sort | uniq -c | sort -rn | head -10
|
||
|
||
# 查看 404 错误
|
||
awk '$9 == 404 {print $0}' /var/log/nginx/access.log
|
||
```
|
||
|
||
### 错误日志
|
||
```bash
|
||
# 查看实时错误
|
||
tail -f /var/log/nginx/error.log
|
||
|
||
# 查看最近错误
|
||
tail -100 /var/log/nginx/error.log
|
||
```
|
||
|
||
### 日志轮转
|
||
```bash
|
||
# /etc/logrotate.d/nginx
|
||
/var/log/nginx/*.log {
|
||
daily
|
||
missingok
|
||
rotate 14
|
||
compress
|
||
delaycompress
|
||
notifempty
|
||
create 0640 www-data adm
|
||
sharedscripts
|
||
prerotate
|
||
if [ -d /etc/logrotate.d/httpd-prerotate ]; then
|
||
run-parts /etc/logrotate.d/httpd-prerotate
|
||
fi
|
||
endscript
|
||
postrotate
|
||
invoke-rc.d nginx rotate >/dev/null 2>&1
|
||
endscript
|
||
}
|
||
```
|
||
|
||
## 定期维护
|
||
|
||
### 1. 系统更新
|
||
```bash
|
||
# 每周执行
|
||
apt update && apt upgrade -y
|
||
```
|
||
|
||
### 2. 日志清理
|
||
```bash
|
||
# 清理 30 天前的日志
|
||
find /var/log/nginx -name "*.log" -mtime +30 -delete
|
||
```
|
||
|
||
### 3. 磁盘清理
|
||
```bash
|
||
# 查找大文件
|
||
find /opt/deployments -type f -size +100M
|
||
|
||
# 清理临时文件
|
||
rm -rf /tmp/*
|
||
```
|
||
|
||
### 4. 检查异常连接
|
||
```bash
|
||
# 查看活跃连接
|
||
netstat -an | grep ESTABLISHED | wc -l
|
||
|
||
# 查看异常 IP
|
||
netstat -an | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn
|
||
```
|
||
|
||
## 应急响应
|
||
|
||
### 1. 发现异常访问
|
||
|
||
```bash
|
||
# 立即封禁 IP
|
||
ufw deny from 1.2.3.4
|
||
|
||
# 或在 Nginx 中封禁
|
||
# /etc/nginx/conf.d/block.conf
|
||
deny 1.2.3.4;
|
||
```
|
||
|
||
### 2. 网站被篡改
|
||
|
||
```bash
|
||
# 1. 停止 Nginx
|
||
systemctl stop nginx
|
||
|
||
# 2. 备份现场
|
||
tar czf /tmp/deployments_backup_$(date +%Y%m%d_%H%M%S).tar.gz /opt/deployments
|
||
|
||
# 3. 从本地重新部署
|
||
# 运行部署脚本
|
||
|
||
# 4. 启动 Nginx
|
||
systemctl start nginx
|
||
```
|
||
|
||
### 3. SSH 被暴力破解
|
||
|
||
```bash
|
||
# 安装 fail2ban
|
||
apt install -y fail2ban
|
||
|
||
# 配置 SSH 保护
|
||
cat > /etc/fail2ban/jail.local <<EOF
|
||
[sshd]
|
||
enabled = true
|
||
port = ssh
|
||
filter = sshd
|
||
logpath = /var/log/auth.log
|
||
maxretry = 5
|
||
bantime = 3600
|
||
EOF
|
||
|
||
systemctl restart fail2ban
|
||
```
|
||
|
||
## 备份策略
|
||
|
||
### 1. 部署配置备份
|
||
```bash
|
||
# 备份 Nginx 配置
|
||
tar czf nginx_config_$(date +%Y%m%d).tar.gz /etc/nginx/
|
||
|
||
# 备份部署记录
|
||
cp ~/.openclaw/deployments.json ~/deployments_backup_$(date +%Y%m%d).json
|
||
```
|
||
|
||
### 2. 项目文件备份
|
||
```bash
|
||
# 备份所有部署
|
||
tar czf deployments_$(date +%Y%m%d).tar.gz /opt/deployments/
|
||
```
|
||
|
||
### 3. 自动化备份(cron)
|
||
```bash
|
||
# 每周日凌晨 2 点备份
|
||
0 2 * * 0 tar czf /backup/deployments_$(date +\%Y\%m\%d).tar.gz /opt/deployments/
|
||
```
|