forked from bai/curriculum-project-hub
ecbc2c8666
runner.ts: 启用 SDK 内置沙箱(bubblewrap/seatbelt),写入限制在 workspace, denyRead 敏感路径,failIfUnavailable 硬拒非沙箱运行。bypassPermissions 保留 (headless 无交互),沙箱是硬边界而非权限提示层。 install_service.sh: 默认 service user 从 root 改为 cph-hub;env 模板修正 OPENROUTER_API_KEY → ANTHROPIC_AUTH_TOKEN/ANTHROPIC_BASE_URL/ANTHROPIC_API_KEY (与 server.ts 实际读取一致);补 __BASE_DIR__ sed 替换。 cph-hub.service: AssertPathExists=/usr/bin/bwrap 强制沙箱依赖;NoNewPrivileges。 不加 ProtectSystem/ProtectHome(会破坏 cph render-cache 与 bwrap user-namespace)。 trigger.ts: 权限闸门去掉 if (senderOpenId !== '') 短路——缺 open_id 一律 fail-closed 拒绝,不再静默跳过;role gate 同步去掉冗余守卫(已由上游保证)。 顺手把 JSON.parse(msg.content) 的 inline cast 换成 Zod schema parse (FileMessageContentSchema / TextMessageContentSchema)。 ADR-0018: 状态改为 Accepted+implemented,机制段写定 SDK 沙箱,网络决定为开放, Open Questions 更新。
67 lines
2.1 KiB
Bash
Executable File
67 lines
2.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Install the cph-hub systemd service on a host. Idempotent.
|
|
#
|
|
# Prerequisites already on the host: Node.js, npm, PostgreSQL, systemd.
|
|
# The Hub repo is expected at HUB_DIR (default /srv/curriculum-project-hub/hub)
|
|
# with `npm ci` + `npm run build` already run by deploy_platform.sh.
|
|
#
|
|
# Usage:
|
|
# sudo BASE=/srv/curriculum-project-hub bash deploy/install_service.sh
|
|
set -euo pipefail
|
|
|
|
BASE="${BASE:-/srv/curriculum-project-hub}"
|
|
HUB_DIR="${HUB_DIR:-$BASE/hub}"
|
|
SERVICE_USER="${SERVICE_USER:-cph-hub}"
|
|
HOST="${HOST:-127.0.0.1}"
|
|
PORT="${PORT:-8788}"
|
|
ENV_FILE="${ENV_FILE:-$BASE/.secrets/platform.env}"
|
|
NODE_BIN="${NODE_BIN:-$(command -v node || true)}"
|
|
|
|
if [ -z "$NODE_BIN" ]; then
|
|
echo "node must be on PATH, or set NODE_BIN." >&2
|
|
exit 1
|
|
fi
|
|
if [ ! -d "$HUB_DIR" ]; then
|
|
echo "HUB_DIR not found: $HUB_DIR (set HUB_DIR or clone the repo there)." >&2
|
|
exit 1
|
|
fi
|
|
if [ ! -f "$HUB_DIR/dist/server.js" ]; then
|
|
echo "build missing: run 'npm ci && npm run build' in $HUB_DIR first." >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Seed the env file if absent. Secrets stay on the server, never in the repo.
|
|
if [ ! -f "$ENV_FILE" ]; then
|
|
install -d -m 0700 "$(dirname "$ENV_FILE")"
|
|
cat >"$ENV_FILE" <<EOF
|
|
NODE_ENV=production
|
|
DATABASE_URL=postgresql://paradigm:change-me@127.0.0.1:5432/paradigm
|
|
# Claude Code SDK auth via OpenRouter's Anthropic Skin (ADR-0017).
|
|
# ANTHROPIC_AUTH_TOKEN = your OpenRouter API key; ANTHROPIC_API_KEY must be empty.
|
|
ANTHROPIC_BASE_URL=https://openrouter.ai/api
|
|
ANTHROPIC_AUTH_TOKEN=
|
|
ANTHROPIC_API_KEY=
|
|
FEISHU_APP_ID=
|
|
FEISHU_APP_SECRET=
|
|
FEISHU_BOT_OPEN_ID=
|
|
PORT=$PORT
|
|
HOST=$HOST
|
|
EOF
|
|
echo "Seeded $ENV_FILE — edit it to fill in ANTHROPIC_AUTH_TOKEN and Feishu creds, then re-run."
|
|
exit 0
|
|
fi
|
|
|
|
# Render the unit with concrete paths.
|
|
UNIT=/etc/systemd/system/cph-hub.service
|
|
sed \
|
|
-e "s|__SERVICE_USER__|$SERVICE_USER|g" \
|
|
-e "s|__HUB_DIR__|$HUB_DIR|g" \
|
|
-e "s|__BASE_DIR__|$BASE|g" \
|
|
-e "s|__ENV_FILE__|$ENV_FILE|g" \
|
|
-e "s|__NODE_BIN__|$NODE_BIN|g" \
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable cph-hub.service
|
|
echo "Installed cph-hub.service. Start with: systemctl start cph-hub"
|
|
echo "Check health: curl http://127.0.0.1:$PORT/api/healthz"
|