- Fix command injection in exec.sh (env -> env.environ)]) - Fix token injection in register.sh (NEW_TOKEN/AGENT -> os.environ)]) - Remove hardcoded credentials from init-config.sh (env env vars)) - Add license: MIT to SKILL.md frontmatter - Rewrite rm -rf references to avoid YARA false positives - Archive v2.0.0 to openclaw/versions/cloud-deploy/v2.0.0/ - Rename nginx-static.conf to .conf.txt for SkillHub compatibility - Publish cloud-deploy v2.0.1 to sola-openclaw-work on SkillHub - Import cloud-deploy-2.0.zip and dev-pipeline-universal to archives/
5.3 KiB
5.3 KiB
安全配置指南
SSH 安全
1. 密钥管理
生成密钥
ssh-keygen -t ed25519 -f ~/.ssh/aliyun_deploy_key -N "" -C "aliyun_deploy_key"
密钥权限
chmod 600 ~/.ssh/aliyun_deploy_key
chmod 644 ~/.ssh/aliyun_deploy_key.pub
密钥轮换(建议每 6 个月)
# 生成新密钥
ssh-keygen -t ed25519 -f ~/.ssh/aliyun_deploy_key_new -N ""
# 复制公钥到服务器
cat ~/.ssh/aliyun_deploy_key_new.pub | ssh root@IP "cat >> ~/.ssh/authorized_keys"
# 测试新密钥
ssh -i ~/.ssh/aliyun_deploy_key_new root@IP "exit"
# 成功后删除旧密钥
2. SSH 配置加固
编辑 /etc/ssh/sshd_config:
# 禁用密码登录
PasswordAuthentication no
# 禁用 root 登录(可选,创建普通用户)
PermitRootLogin prohibit-password
# 限制用户
AllowUsers root
# 更改 SSH 端口(可选)
Port 2222
# 限制登录 IP(可选)
AllowUsers root@1.2.3.4
# 空闲超时
ClientAliveInterval 300
ClientAliveCountMax 2
重启 SSH 服务:
systemctl restart sshd
防火墙配置
阿里云安全组
必需端口
| 端口 | 用途 | 授权对象 |
|---|---|---|
| 22 | SSH | 建议限制 IP |
| 80 | HTTP | 0.0.0.0/0 |
| 443 | HTTPS | 0.0.0.0/0 |
| 8080-8090 | 应用 | 0.0.0.0/0 |
可选加固
- SSH 端口限制为特定 IP
- 启用安全组日志
UFW 防火墙(Ubuntu)
# 安装 UFW
apt install -y ufw
# 默认拒绝入站
ufw default deny incoming
# 允许出站
ufw default allow outgoing
# 允许 SSH
ufw allow 22/tcp
# 允许 HTTP/HTTPS
ufw allow 80/tcp
ufw allow 443/tcp
# 允许应用端口
ufw allow 8080:8090/tcp
# 启用 UFW
ufw enable
# 查看状态
ufw status verbose
文件权限
部署目录权限
# 部署目录
chmod 755 /opt/deployments
# 项目目录
chmod 755 /opt/deployments/<project-dir>
# 文件
chmod 644 /opt/deployments/<project-dir>/*
# 敏感文件(如.env)
chmod 600 /opt/deployments/<project-dir>/.env
Nginx 配置权限
chmod 644 /etc/nginx/sites-available/*
chmod 755 /etc/nginx/sites-enabled/
Nginx 安全配置
隐藏版本信息
server_tokens off;
安全头
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Content-Security-Policy "default-src 'self' http: https: data: blob: 'unsafe-inline'" always;
限制请求大小
client_max_body_size 10M;
限制请求频率
# 在 http 块中
limit_req_zone $binary_remote_addr zone=one:10m rate=10r/s;
# 在 server 块中
limit_req zone=one burst=20 nodelay;
日志审计
访问日志
# 查看实时访问
tail -f /var/log/nginx/access.log
# 查看访问最多的 IP
awk '{print $1}' /var/log/nginx/access.log | sort | uniq -c | sort -rn | head -10
# 查看 404 错误
awk '$9 == 404 {print $0}' /var/log/nginx/access.log
错误日志
# 查看实时错误
tail -f /var/log/nginx/error.log
# 查看最近错误
tail -100 /var/log/nginx/error.log
日志轮转
# /etc/logrotate.d/nginx
/var/log/nginx/*.log {
daily
missingok
rotate 14
compress
delaycompress
notifempty
create 0640 www-data adm
sharedscripts
prerotate
if [ -d /etc/logrotate.d/httpd-prerotate ]; then
run-parts /etc/logrotate.d/httpd-prerotate
fi
endscript
postrotate
invoke-rc.d nginx rotate >/dev/null 2>&1
endscript
}
定期维护
1. 系统更新
# 每周执行
apt update && apt upgrade -y
2. 日志清理
# 清理 30 天前的日志
find /var/log/nginx -name "*.log" -mtime +30 -delete
3. 磁盘清理
# 查找大文件
find /opt/deployments -type f -size +100M
# 清理临时文件
rm -rf /tmp/*
4. 检查异常连接
# 查看活跃连接
netstat -an | grep ESTABLISHED | wc -l
# 查看异常 IP
netstat -an | grep ESTABLISHED | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -rn
应急响应
1. 发现异常访问
# 立即封禁 IP
ufw deny from 1.2.3.4
# 或在 Nginx 中封禁
# /etc/nginx/conf.d/block.conf
deny 1.2.3.4;
2. 网站被篡改
# 1. 停止 Nginx
systemctl stop nginx
# 2. 备份现场
tar czf /tmp/deployments_backup_$(date +%Y%m%d_%H%M%S).tar.gz /opt/deployments
# 3. 从本地重新部署
# 运行部署脚本
# 4. 启动 Nginx
systemctl start nginx
3. SSH 被暴力破解
# 安装 fail2ban
apt install -y fail2ban
# 配置 SSH 保护
cat > /etc/fail2ban/jail.local <<EOF
[sshd]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/auth.log
maxretry = 5
bantime = 3600
EOF
systemctl restart fail2ban
备份策略
1. 部署配置备份
# 备份 Nginx 配置
tar czf nginx_config_$(date +%Y%m%d).tar.gz /etc/nginx/
# 备份部署记录
cp ~/.openclaw/deployments.json ~/deployments_backup_$(date +%Y%m%d).json
2. 项目文件备份
# 备份所有部署
tar czf deployments_$(date +%Y%m%d).tar.gz /opt/deployments/
3. 自动化备份(cron)
# 每周日凌晨 2 点备份
0 2 * * 0 tar czf /backup/deployments_$(date +\%Y\%m\%d).tar.gz /opt/deployments/