feat(infra/domains): 域名池 + CDN 前置 + 签名端点分发 (tsk_NU9JuUweHWMt)
- domains.md: 四组域名隔离登记 + 冷备池 ≥5 + 启用流程(不含身份信息) - cdn/terraform: Cloudflare 配置即代码(WAF/bot/速率限制/代理DNS/回源鉴权注入)+ 30min 重放 Runbook - server/internal/originauth: 回源鉴权中间件,非 CDN 网段或鉴权头不符一律 403,支持双值轮换 - tools/endpoint-signer: 离线 Ed25519 签名 CLI(端点 + 公告文档,单调版本防回滚,key_id 双公钥轮换) - tools/publish-mirrors: ≥3 镜像发布 + hash 一致性校验 + 故障转移取回 - CLIENT-CONTRACT.md: schema/验签/防回滚/合并/兜底链/channel 客户端契约 - 出站独立出口要求写入部署文档;私钥/token/身份信息一律不入库 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
# Proxied DNS records. proxied = true keeps the origin IP hidden behind the CDN
|
||||
# (doc/05 §2 源站 IP 隐藏). The origin must NEVER have had an unproxied A record
|
||||
# (historic DNS is the most common leak path).
|
||||
resource "cloudflare_record" "api" {
|
||||
for_each = toset(var.api_hostnames)
|
||||
|
||||
zone_id = var.zone_id
|
||||
name = each.value
|
||||
type = "A"
|
||||
content = var.origin_ip
|
||||
proxied = true
|
||||
ttl = 1 # 1 = automatic (required when proxied)
|
||||
|
||||
comment = "pangolin api/distribution endpoint (managed by terraform)"
|
||||
}
|
||||
Reference in New Issue
Block a user