Files
Mujoco_WASM/deploy/cadworld/bootstrap-tls.sh
T
chenlin f3a8a38acd
web-platform-ci / Standalone decision service (no cloud credentials) (push) Has been cancelled
web-platform-ci / TypeScript, lint, unit, build (push) Has been cancelled
web-platform-ci / Playwright E2E (push) Has been cancelled
lekiwi-compatibility / cpu-compatibility (push) Has been cancelled
web-platform-ci / Standalone decision service (no cloud credentials) (pull_request) Has been cancelled
web-platform-ci / TypeScript, lint, unit, build (pull_request) Has been cancelled
web-platform-ci / Playwright E2E (pull_request) Has been cancelled
lekiwi-compatibility / cpu-compatibility (pull_request) Has been cancelled
feat: release v1.0.1 CADWorld 网站与 LeKiwi 智能抓放
集成同源 BYOK 会话隔离、精简模型设置、官方订阅入口和 HTTPS 发布运维;保留本地训练/调参与控制能力。同步 npm 版本及 CHANGELOG,记录公网真实 API 验收仍待用户凭据。
2026-09-24 09:57:41 +08:00

35 lines
1.8 KiB
Bash

#!/usr/bin/env bash
# One-time installation. Existing domain configuration is never silently overwritten.
set -euo pipefail
root=/opt/cadworld-sim
base=/opt/1panel/apps/openresty/openresty
conf=$base/conf/conf.d/cadworld-sim.robotquan.com.conf
source_dir=$(cd -- "$(dirname -- "$0")" && pwd)
[[ ! -e "$conf" ]] || { echo 'Domain vhost already exists; inspect/backup it first.' >&2; exit 1; }
mkdir -p "$root/backups" "$base/www/acme/cadworld-sim.robotquan.com" "$base/www/ssl/cadworld-sim.robotquan.com"
chmod 700 "$root/backups" "$base/www/ssl/cadworld-sim.robotquan.com"
tar -czf "$root/backups/openresty-pre-cadworld.tar.gz" -C "$base" conf
cp "$source_dir/compose.yaml" "$root/compose.yaml"
printf 'CADWORLD_RELEASE=bootstrap\n' > "$root/release.env"
# HTTP only serves challenges. No API or credentials until a trusted certificate exists.
printf '%s\n' \
'server {' \
' listen 80; server_name cadworld-sim.robotquan.com;' \
' location ^~ /.well-known/acme-challenge/ { root /www/acme/cadworld-sim.robotquan.com; default_type text/plain; }' \
' location / { return 503; }' \
'}' > "$conf"
docker exec 1Panel-openresty-m72w nginx -t
docker exec 1Panel-openresty-m72w nginx -s reload
docker compose --env-file "$root/release.env" -f "$root/compose.yaml" run --rm -T --interactive=false certbot certonly \
--non-interactive --agree-tos --register-unsafely-without-email \
--webroot -w /var/www/acme -d cadworld-sim.robotquan.com
cp "$source_dir/openresty.conf" "$conf"
docker exec 1Panel-openresty-m72w nginx -t
docker exec 1Panel-openresty-m72w nginx -s reload
cp "$source_dir/renew-certificate.sh" "$root/renew-certificate.sh"
chmod 700 "$root/renew-certificate.sh"
cp "$source_dir/cadworld-certificate.service" /etc/systemd/system/
cp "$source_dir/cadworld-certificate.timer" /etc/systemd/system/
systemctl daemon-reload
systemctl enable --now cadworld-certificate.timer