mirror of
https://gitcode.com/JianFeeeee/ModelRouter.git
synced 2026-10-03 23:54:06 +00:00
打包时把本地 config.yaml(gitignored,含运维真实密钥)原样复制成 config.example.yaml,而 postinst 在首次安装且 /etc 无配置时又把它 cp 成生产配置 ⇒ 每次安装都得到一个同值的、公开已知的 admin key。 实测该 key(sk-gw-local-0001)在生产上真实有效(/v1/models 返回 200, 而网关监听 0.0.0.0)。 三处修正: - 新增 packaging/config.example.yaml(受 git 跟踪的净化模板), gateway_keys 留空、sources 留空,并写明不要填死值。 - core-dist.sh / nfpm.yaml 改为打包该模板,不再碰本地 config.yaml。 - postinst.sh 不再投递示例配置:留空文件会让网关启动但拒绝所有请求 (无门可入)。改为让二进制首启时自行生成随机 admin key 并打印 —— 每次安装都不同,且开箱可用。示例文件仅作为 /usr/share 下的参考保留。 实测首启:生成 sk-gw-838d66a1... 并打印,与旧的共享固定值不同。
32 lines
1.3 KiB
Bash
Executable File
32 lines
1.3 KiB
Bash
Executable File
#!/bin/sh
|
|
# llmsproxy core package postinst
|
|
set -e
|
|
|
|
# Runtime state belongs under /etc/llmsproxy just like the production layout:
|
|
# runtime.json holds keys/created sources and is NOT touched on reinstall.
|
|
mkdir -p /etc/llmsproxy/adapters
|
|
|
|
if [ -f /etc/llmsproxy/config.yaml ]; then
|
|
echo "llmsproxy: keeping existing /etc/llmsproxy/config.yaml"
|
|
else
|
|
# Do NOT seed a starter config here. Packaging/installing one used to hand
|
|
# everyone the same file, and while it was copied from the maintainer's
|
|
# live config it shipped a real, working admin key (sk-gw-local-0001) to
|
|
# every install.
|
|
#
|
|
# Instead, leave the file absent: on first start the binary's EnsureDefault
|
|
# path creates config.yaml with a FRESH RANDOM admin key and logs it, which
|
|
# is both unique per install and actually usable. The packaged
|
|
# config.example.yaml stays in /usr/share as a reference template only.
|
|
#
|
|
# (Seeding it with gateway_keys: [] would be worse: the gateway would start
|
|
# but reject every request, with no way in except editing the file.)
|
|
echo "llmsproxy: no /etc/llmsproxy/config.yaml — a random admin key will be generated on first start"
|
|
fi
|
|
|
|
# systemd
|
|
if command -v systemctl >/dev/null 2>&1; then
|
|
systemctl daemon-reload >/dev/null 2>&1 || true
|
|
echo "llmsproxy: use 'systemctl enable --now llmsproxy' to start"
|
|
fi
|
|
exit 0 |