Files
pangolin/server/Makefile
T
wangjia f03d2dc8a6 feat(agent): node agent — enroll/mTLS, heartbeat, command stream, sing-box 用户表 (tsk__R8M4jEw43JR)
与控制面同仓同 go.mod,新增节点 agent 实现:

- proto/agent/v1/agent.proto + internal/pb/agentv1:冻结的控制面↔agent gRPC 契约
  (Enroll/Register/Heartbeat/Subscribe/Ack/ReportUsage)。仓库尚无 protoc 流水线,
  暂以手写 Go 类型 + JSON gRPC codec 实现,与 proto 1:1 对应,待 protoc 接入即可替换。
- internal/agentd:
  - enroll.go:首启生成 EC 密钥+CSR,持 bootstrap token 调 Enroll 换 90d 节点证书
    (CN=node_uuid),落 /etc/pangolin-agent/,此后 mTLS。
  - conn.go(agent.go)+creds.go:mTLS 主动拨号 + 指数退避重连;重连携带 last_command_id;
    Register 取 ConfigSnapshot 全量配置覆盖本地。
  - heartbeat.go:30s 上报 peer/带宽/CPU + config_version;need_full_resync→全量同步。
  - command.go:消费 Subscribe,Upsert/Revoke/Rotate/ApplyConfig/Lifecycle 幂等处理后
    Ack(at-least-once,按 command_id 去重)。
  - singbox.go+render.go:内存用户表 + 落盘 state.json(仅 dp_uuid+expires_at);任何变更
    渲染完整 sing-box 配置(REALITY users[uuid,flow] + Hy2 users[派生口令])→ 500ms 去抖
    合并 → systemd 重启。
  - ttl.go:凭证 TTL 定时移除并上报。
  - usage.go:按 dp_uuid 聚合上报,绝无 user_id/email/目的地址。
  - derive.go:Hy2 口令 = HMAC-SHA256(key, dp_uuid),与控制面同源派生。
- cmd/agent:入口(flag/env 配置)。
- infra/cloud-init/{node.yaml.tmpl,install-node.sh,README.md}:一段式安装,下载锁定版本
  二进制并校验 SHA-256,systemd 拉管,首启即 Enroll/Register。shellcheck -S warning 通过。

测试(bufconn mock 控制面,无需 docker):Enroll→Register→Heartbeat 全流转;Upsert/Revoke
渲染正确;Rotate 宽限期新旧并存到点移除;TTL 自动移除并上报;断流重连 last_command_id
续发不丢不重;need_full_resync 触发重注册;state.json 恢复;去抖合并;扫描确认无身份字段。
go test -race ./internal/agentd/... ./internal/pb/... 通过;go vet ./... 通过。

落实 doc/04 §2 节点无状态化与 doc/06 §3 数据面红线(节点仅见 dp_uuid)。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 12:26:58 +08:00

46 lines
2.3 KiB
Makefile
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
.PHONY: build test test-unit test-integration vet lint generate migrate-up migrate-down build-codegen deps
# ── deps ───────────────────────────────────────────────────────────────────────
deps:
go mod tidy
go mod download
# ── build ──────────────────────────────────────────────────────────────────────
build:
go build ./...
build-codegen: ## 激活码批次生成 CLI
go build -o bin/codegen ./cmd/codegen
build-agent: ## 节点 agent 二进制(部署到加速节点)
go build -o bin/pangolin-agent ./cmd/agent
# ── test ───────────────────────────────────────────────────────────────────────
test:
go test ./...
test-unit: ## 单测(不依赖外部服务)
go test -count=1 -race ./internal/codes/... -run 'Test[^I][^n][^t]'
test-agent: ## 节点 agent 单测 + 集成(bufconn mock 控制面,无需 docker
go test -count=1 -race ./internal/agentd/... ./internal/pb/...
test-integration: ## 集成测试(需本机 dockertestcontainers
go test -count=1 ./internal/codes/... -run TestInt
# ── vet / lint ─────────────────────────────────────────────────────────────────
vet:
go vet ./...
lint:
golangci-lint run ./...
# ── generate ───────────────────────────────────────────────────────────────────
generate:
@echo "generate: not yet configured (see task 1d)"
# ── migrate ────────────────────────────────────────────────────────────────────
migrate-up:
@echo "migrate-up: see cmd/migrate"
migrate-down:
@echo "migrate-down: see cmd/migrate"