mod
This commit is contained in:
@@ -33,3 +33,9 @@ build/
|
||||
.vscode/
|
||||
.DS_Store
|
||||
*/.DS_Store
|
||||
|
||||
|
||||
AGENTS.md
|
||||
CLAUDE.md
|
||||
.claude
|
||||
.omo
|
||||
@@ -1 +0,0 @@
|
||||
-T 1C -U -Dskiptests=true -Dmaven.compile.fork=true
|
||||
@@ -76,42 +76,91 @@ TOPIAM(Top Identity and Access Management),是一款开源的身份管理
|
||||
+ [阿里云计算巢部署](https://topiam.cn/docs/deployment/deployment-alibaba-cloud-computenest/)
|
||||
+ [更多方式](https://eiam.topiam.cn/docs/deployment/)
|
||||
|
||||
## 微信公众号
|
||||
## 部署
|
||||
### 准备工作:确保本地构建成功
|
||||
在项目根目录执行完整构建(跳过测试)
|
||||
```
|
||||
./mvnw clean package -DskipTests -Dlicense.skip=true -Dformatter.skip=true
|
||||
```
|
||||
|
||||
欢迎关注 TOPIAM 微信公众号,接收产品最新动态。
|
||||
```
|
||||
cd /Users/yhtx/Documents/jupyter/ai/topiam
|
||||
|
||||
<img src="/images/wxmp-qr.png" alt="wxmp" width="200px">
|
||||
# 1. 先清理并重新构建 Console 前端(验证前端兼容性)
|
||||
cd eiam-console/src/main/console-fe
|
||||
pnpm install --registry=https://registry.npmmirror.com
|
||||
pnpm run build:dev
|
||||
|
||||
## 版权声明
|
||||
# 2. 全量 Maven 构建(跳过测试)
|
||||
cd /Users/yhtx/Documents/jupyter/ai/topiam
|
||||
./mvnw clean package -DskipTests -Dlicense.skip=true -Dformatter.skip=true -pl eiam-console -am
|
||||
```
|
||||
完整三模块本地构建验证
|
||||
```
|
||||
# 按依赖顺序构建
|
||||
./mvnw clean install -DskipTests -Dlicense.skip=true -Dformatter.skip=true -pl eiam-console,eiam-portal,eiam-openapi -am
|
||||
```
|
||||
|
||||
开源不代表免费,`TOPIAM` 遵循 AGPL-3.0 开源协议发布,并提供技术交流学习,但绝不允许修改后和衍生的代码做为闭源的商业软件发布和销售! 如果需要将本产品在本地进行任何附带商业化性质行为使用,请联系项目负责人进行商业授权,以遵守 AGPL 协议保证您的正常使用。
|
||||
|
||||
如果您**需要将本产品进行二次开发、更改并进行任何附带商业化性质行为使用**,请联系我们进行商业授权,以遵守 `AGPL-3.0` 协议保证您的正常使用。
|
||||
三个独立启动脚本:
|
||||
|
||||
目前在国内 `GPL` 协议**具备合同特征,是一种民事法律行为** ,属于我国《合同法》调整的范围。 `TOPIAM` 项目团队保留诉讼权利。
|
||||
脚本 服务 端口 说明
|
||||
start-console.sh Console 管理后台 1898 含 -Pdev 前端热构建
|
||||
start-portal.sh Portal 用户门户 1989 含 -Pdev 前端热构建
|
||||
start-openapi.sh OpenAPI 开放接口 1988 纯后端,无 -Pdev
|
||||
使用方法
|
||||
开三个终端分别运行:
|
||||
|
||||
[相关案例:违反 `GPL` 协议赔偿 50 万,国内首例!](https://mp.weixin.qq.com/s/YQ6sNjbDS-P7BViLZIsaoA)
|
||||
### 终端 1
|
||||
`./start-console.sh`
|
||||
|
||||
> 本项目采用 `AGPL` 开源协议(抄袭牟利索赔100万)。
|
||||
### 终端 2
|
||||
`./start-portal.sh`
|
||||
|
||||
> 使用必须遵守国家法律法规,不允许非法项目使用,后果自负。
|
||||
### 终端 3
|
||||
`./start-openapi.sh`
|
||||
|
||||
## 参与贡献
|
||||
访问地址
|
||||
服务 地址
|
||||
Console http://localhost:1898
|
||||
Portal http://localhost:1989
|
||||
OpenAPI http://localhost:1988/doc.html
|
||||
登录:admin / topiam.cn 123456
|
||||
|
||||
我们强烈欢迎有兴趣的开发者参与到项目建设中来,同时欢迎大家对项目提出宝贵意见建议和功能需求,项目正在积极开发,欢迎 PR 👏。
|
||||
保留 start-remote.sh 作为统一入口(可选)
|
||||
### 仍可用于检查连通性
|
||||
`./start-remote.sh all`
|
||||
|
||||
强烈推荐阅读 [《提问的智慧》](https://github.com/ryanhanwu/How-To-Ask-Questions-The-Smart-Way)、[《如何向开源社区提问题》](https://github.com/seajs/seajs/issues/545)
|
||||
和 [《如何有效地报告 Bug》](http://www.chiark.greenend.org.uk/%7Esgtatham/bugs-cn.html)、[《如何向开源项目提交无法解答的问题》](https://zhuanlan.zhihu.com/p/25795393)
|
||||
,更好的问题更容易获得帮助。
|
||||
现在有四个构建脚本:
|
||||
|
||||
## Star History
|
||||
脚本 用途
|
||||
build-console.sh 仅构建 Console 镜像
|
||||
build-portal.sh 仅构建 Portal 镜像
|
||||
build-openapi.sh 仅构建 OpenAPI 镜像
|
||||
build-images.sh 一次性构建三个(原脚本)
|
||||
使用方法
|
||||
### 单独构建某个模块(默认版本 1.1.0-dev,本地仓库)
|
||||
```
|
||||
./build-console.sh
|
||||
./build-portal.sh
|
||||
./build-openapi.sh
|
||||
```
|
||||
|
||||
[](https://star-history.com/#topiam/eiam&Date)
|
||||
### 指定版本和仓库
|
||||
```
|
||||
./build-console.sh v1.2.0 registry.cn-hangzhou.aliyuncs.com/my-ns
|
||||
./build-portal.sh v1.2.0 registry.cn-hangzhou.aliyuncs.com/my-ns
|
||||
./build-openapi.sh v1.2.0 registry.cn-hangzhou.aliyuncs.com/my-ns
|
||||
```
|
||||
## 开发流程建议
|
||||
### 1. 修改 Console 代码后
|
||||
`./build-console.sh`
|
||||
|
||||
## FOSSA Status
|
||||
### 2. 修改 Portal 代码后
|
||||
`./build-portal.sh`
|
||||
|
||||
[](https://app.fossa.com/projects/git%2Bgithub.com%2Ftopiam%2Feiam?ref=badge_large)
|
||||
|
||||
## License
|
||||
|
||||
<img src='https://www.gnu.org/graphics/agplv3-with-text-162x68.png' alt="license">
|
||||
### 3. 发布前全量构建
|
||||
```
|
||||
./build-images.sh v1.2.0 registry.cn-hangzhou.aliyuncs.com/my-ns
|
||||
```
|
||||
利用 Docker 层缓存,单模块构建通常只需 30-60 秒(只重新编译变更模块)。
|
||||
Executable
+17
@@ -0,0 +1,17 @@
|
||||
#!/usr/bin/env bash
|
||||
# 构建 Console 镜像
|
||||
|
||||
set -e
|
||||
VERSION="${1:-1.1.0-dev}"
|
||||
REGISTRY="${2:-localhost}"
|
||||
|
||||
echo "🔨 构建 Console 镜像: ${REGISTRY}/topiam-console:${VERSION}"
|
||||
|
||||
cd /Users/yhtx/Documents/jupyter/ai/topiam
|
||||
docker build \
|
||||
--build-arg BUILDKIT_INLINE_CACHE=1 \
|
||||
-t ${REGISTRY}/topiam-console:${VERSION} \
|
||||
-f eiam-console/Dockerfile \
|
||||
.
|
||||
|
||||
echo "✅ Console 镜像构建完成"
|
||||
Executable
+17
@@ -0,0 +1,17 @@
|
||||
#!/usr/bin/env bash
|
||||
# 构建 OpenAPI 镜像
|
||||
|
||||
set -e
|
||||
VERSION="${1:-1.1.0-dev}"
|
||||
REGISTRY="${2:-localhost}"
|
||||
|
||||
echo "🔨 构建 OpenAPI 镜像: ${REGISTRY}/topiam-openapi:${VERSION}"
|
||||
|
||||
cd /Users/yhtx/Documents/jupyter/ai/topiam
|
||||
docker build \
|
||||
--build-arg BUILDKIT_INLINE_CACHE=1 \
|
||||
-t ${REGISTRY}/topiam-openapi:${VERSION} \
|
||||
-f eiam-openapi/Dockerfile \
|
||||
.
|
||||
|
||||
echo "✅ OpenAPI 镜像构建完成"
|
||||
Executable
+17
@@ -0,0 +1,17 @@
|
||||
#!/usr/bin/env bash
|
||||
# 构建 Portal 镜像
|
||||
|
||||
set -e
|
||||
VERSION="${1:-1.1.0-dev}"
|
||||
REGISTRY="${2:-localhost}"
|
||||
|
||||
echo "🔨 构建 Portal 镜像: ${REGISTRY}/topiam-portal:${VERSION}"
|
||||
|
||||
cd /Users/yhtx/Documents/jupyter/ai/topiam
|
||||
docker build \
|
||||
--build-arg BUILDKIT_INLINE_CACHE=1 \
|
||||
-t ${REGISTRY}/topiam-portal:${VERSION} \
|
||||
-f eiam-portal/Dockerfile \
|
||||
.
|
||||
|
||||
echo "✅ Portal 镜像构建完成"
|
||||
@@ -0,0 +1,144 @@
|
||||
version: '3.8'
|
||||
|
||||
# =============================================
|
||||
# TOPIAM 生产环境部署
|
||||
# =============================================
|
||||
|
||||
services:
|
||||
# ---- Console 管理后台 ----
|
||||
topiam-console:
|
||||
image: topiam-console:1.1.0-dev
|
||||
container_name: topiam-console
|
||||
environment:
|
||||
- TZ=Asia/Shanghai
|
||||
- SPRING_PROFILES_ACTIVE=remote
|
||||
# 数据库
|
||||
- SPRING_DATASOURCE_URL=jdbc:mysql://100.74.125.93:3306/topiam?serverTimezone=GMT%2B8&useUnicode=true&characterEncoding=UTF-8&autoReconnect=true&useSSL=false&allowPublicKeyRetrieval=true&rewriteBatchedStatements=true
|
||||
- SPRING_DATASOURCE_USERNAME=topiam
|
||||
- SPRING_DATASOURCE_PASSWORD=topiam
|
||||
# Redis
|
||||
- SPRING_DATA_REDIS_HOST=100.74.125.93
|
||||
- SPRING_DATA_REDIS_PORT=6379
|
||||
- SPRING_DATA_REDIS_PASSWORD=redis
|
||||
# Elasticsearch
|
||||
- SPRING_ELASTICSEARCH_URIS=http://100.74.125.93:9200
|
||||
# RabbitMQ
|
||||
- SPRING_RABBITMQ_HOST=100.74.125.93
|
||||
- SPRING_RABBITMQ_PORT=5672
|
||||
- SPRING_RABBITMQ_USERNAME=rabbitmq
|
||||
- SPRING_RABBITMQ_PASSWORD=rabbitmq
|
||||
- SPRING_RABBITMQ_VIRTUAL_HOST=/
|
||||
# 服务地址(按实际域名修改)
|
||||
- TOPIAM_SERVER_CONSOLE_PUBLIC_BASE_URL=http://your-domain.com:1898
|
||||
- TOPIAM_SERVER_PORTAL_PUBLIC_BASE_URL=http://your-domain.com:1989
|
||||
- TOPIAM_SERVER_OPENAPI_PUBLIC_BASE_URL=http://your-domain.com:1988
|
||||
ports:
|
||||
- "1898:1898"
|
||||
restart: unless-stopped
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 2G
|
||||
reservations:
|
||||
memory: 1G
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:1898/actuator/health"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
start_period: 60s
|
||||
logging:
|
||||
driver: "json-file"
|
||||
options:
|
||||
max-size: "100m"
|
||||
max-file: "3"
|
||||
|
||||
# ---- Portal 用户门户 ----
|
||||
topiam-portal:
|
||||
image: topiam-portal:1.1.0-dev
|
||||
container_name: topiam-portal
|
||||
environment:
|
||||
- TZ=Asia/Shanghai
|
||||
- SPRING_PROFILES_ACTIVE=remote
|
||||
- SPRING_DATASOURCE_URL=jdbc:mysql://100.74.125.93:3306/topiam?serverTimezone=GMT%2B8&useUnicode=true&characterEncoding=UTF-8&autoReconnect=true&useSSL=false&allowPublicKeyRetrieval=true&rewriteBatchedStatements=true
|
||||
- SPRING_DATASOURCE_USERNAME=topiam
|
||||
- SPRING_DATASOURCE_PASSWORD=topiam
|
||||
- SPRING_DATA_REDIS_HOST=100.74.125.93
|
||||
- SPRING_DATA_REDIS_PORT=6379
|
||||
- SPRING_DATA_REDIS_PASSWORD=redis
|
||||
- SPRING_ELASTICSEARCH_URIS=http://100.74.125.93:9200
|
||||
- SPRING_RABBITMQ_HOST=100.74.125.93
|
||||
- SPRING_RABBITMQ_PORT=5672
|
||||
- SPRING_RABBITMQ_USERNAME=rabbitmq
|
||||
- SPRING_RABBITMQ_PASSWORD=rabbitmq
|
||||
- SPRING_RABBITMQ_VIRTUAL_HOST=/
|
||||
ports:
|
||||
- "1989:1989"
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
topiam-console:
|
||||
condition: service_healthy
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 2G
|
||||
reservations:
|
||||
memory: 1G
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:1989/actuator/health"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
start_period: 60s
|
||||
logging:
|
||||
driver: "json-file"
|
||||
options:
|
||||
max-size: "100m"
|
||||
max-file: "3"
|
||||
|
||||
# ---- OpenAPI 开放接口 ----
|
||||
topiam-openapi:
|
||||
image: topiam-openapi:1.1.0-dev
|
||||
container_name: topiam-openapi
|
||||
environment:
|
||||
- TZ=Asia/Shanghai
|
||||
- SPRING_PROFILES_ACTIVE=remote
|
||||
- SPRING_DATASOURCE_URL=jdbc:mysql://100.74.125.93:3306/topiam?serverTimezone=GMT%2B8&useUnicode=true&characterEncoding=UTF-8&autoReconnect=true&useSSL=false&allowPublicKeyRetrieval=true&rewriteBatchedStatements=true
|
||||
- SPRING_DATASOURCE_USERNAME=topiam
|
||||
- SPRING_DATASOURCE_PASSWORD=topiam
|
||||
- SPRING_DATA_REDIS_HOST=100.74.125.93
|
||||
- SPRING_DATA_REDIS_PORT=6379
|
||||
- SPRING_DATA_REDIS_PASSWORD=redis
|
||||
- SPRING_ELASTICSEARCH_URIS=http://100.74.125.93:9200
|
||||
- SPRING_RABBITMQ_HOST=100.74.125.93
|
||||
- SPRING_RABBITMQ_PORT=5672
|
||||
- SPRING_RABBITMQ_USERNAME=rabbitmq
|
||||
- SPRING_RABBITMQ_PASSWORD=rabbitmq
|
||||
- SPRING_RABBITMQ_VIRTUAL_HOST=/
|
||||
ports:
|
||||
- "1988:1988"
|
||||
restart: unless-stopped
|
||||
depends_on:
|
||||
topiam-console:
|
||||
condition: service_healthy
|
||||
deploy:
|
||||
resources:
|
||||
limits:
|
||||
memory: 1G
|
||||
reservations:
|
||||
memory: 512M
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:1988/actuator/health"]
|
||||
interval: 30s
|
||||
timeout: 10s
|
||||
retries: 3
|
||||
start_period: 40s
|
||||
logging:
|
||||
driver: "json-file"
|
||||
options:
|
||||
max-size: "100m"
|
||||
max-file: "3"
|
||||
|
||||
networks:
|
||||
default:
|
||||
name: topiam-network
|
||||
@@ -1,21 +1,3 @@
|
||||
#
|
||||
# TOPIAM Employee - Employee Identity and Access Management
|
||||
# Copyright © 2022-Present Jinan Yuanchuang Network Technology Co., Ltd. (support@topiam.cn)
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU Affero General Public License as published by
|
||||
# the Free Software Foundation, either version 3 of the License, or
|
||||
# (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU Affero General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU Affero General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
#
|
||||
|
||||
version: '3'
|
||||
|
||||
services:
|
||||
|
||||
+127
-43
@@ -1,52 +1,136 @@
|
||||
#
|
||||
# eiam-console - Employee Identity and Access Management
|
||||
# Copyright © 2022-Present Jinan Yuanchuang Network Technology Co., Ltd. (support@topiam.cn)
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU Affero General Public License as published by
|
||||
# the Free Software Foundation, either version 3 of the License, or
|
||||
# (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU Affero General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU Affero General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
#
|
||||
# =============================================
|
||||
# TOPIAM Console - 多阶段构建(简化 Maven 配置)
|
||||
# =============================================
|
||||
|
||||
FROM azul/zulu-openjdk:17-jre as build
|
||||
WORKDIR /workspace/app
|
||||
# ---- 阶段 1: 前端构建 ----
|
||||
FROM m.daocloud.io/docker.io/library/node:22.12.0-alpine AS frontend-builder
|
||||
|
||||
ARG JAR_FILE=target/topiam-employee-console-*.jar
|
||||
COPY ${JAR_FILE} target/application.jar
|
||||
RUN java -Djarmode=layertools -jar target/application.jar extract --destination target/extracted
|
||||
WORKDIR /build/console-fe
|
||||
|
||||
FROM azul/zulu-openjdk:17-jre
|
||||
# 配置 pnpm 和镜像源
|
||||
RUN npm config set registry https://registry.npmmirror.com && \
|
||||
npm install -g pnpm@9.15.1
|
||||
|
||||
ARG EXTRACTED=/workspace/app/target/extracted
|
||||
WORKDIR topiam
|
||||
COPY --from=build ${EXTRACTED}/dependencies/ ./
|
||||
COPY --from=build ${EXTRACTED}/spring-boot-loader/ ./
|
||||
COPY --from=build ${EXTRACTED}/snapshot-dependencies/ ./
|
||||
COPY --from=build ${EXTRACTED}/application/ ./
|
||||
# 先复制 package.json 利用缓存
|
||||
COPY eiam-console/src/main/console-fe/package.json eiam-console/src/main/console-fe/pnpm-lock.yaml* ./
|
||||
RUN pnpm install --frozen-lockfile --ignore-scripts
|
||||
|
||||
# 复制源码并构建
|
||||
COPY eiam-console/src/main/console-fe/ ./
|
||||
ENV UMI_ENV=dev
|
||||
RUN npm run build:dev
|
||||
|
||||
|
||||
ENV TZ=Asia/Shanghai
|
||||
RUN sed -i 's/archive.ubuntu.com/cn.archive.ubuntu.com/g' /etc/apt/sources.list \
|
||||
&& apt-get update \
|
||||
&& ln -snf /usr/share/zoneinfo/$TZ /etc/localtime && echo $TZ > /etc/timezone \
|
||||
&& apt-get clean \
|
||||
&& apt-get autoclean \
|
||||
&& apt-get autoremove -y \
|
||||
&& apt-get install -y curl \
|
||||
&& apt-get install -y iputils-ping \
|
||||
&& apt-get install -y wget \
|
||||
&& apt-get install -y tzdata \
|
||||
&& apt-get install -y fontconfig \
|
||||
&& rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* \
|
||||
# ---- 阶段 2: 后端构建 ----
|
||||
FROM m.daocloud.io/docker.io/library/maven:3.9-eclipse-temurin-17 AS backend-builder
|
||||
|
||||
WORKDIR /build
|
||||
|
||||
# 设置 Maven 参数(避免配置文件冲突)
|
||||
ENV MAVEN_OPTS="-Xmx2048m -Xms1024m -Djava.awt.headless=true -Dmaven.multiModuleProjectDirectory=/build"
|
||||
|
||||
# 复制父 pom 和所有模块 pom(父 pom 需要所有子模块存在)
|
||||
COPY pom.xml .
|
||||
COPY eiam-common/pom.xml eiam-common/pom.xml
|
||||
COPY eiam-core/pom.xml eiam-core/pom.xml
|
||||
COPY eiam-audit/pom.xml eiam-audit/pom.xml
|
||||
COPY eiam-application/pom.xml eiam-application/pom.xml
|
||||
COPY eiam-application/eiam-application-core/pom.xml eiam-application/eiam-application-core/pom.xml
|
||||
COPY eiam-application/eiam-application-oidc/pom.xml eiam-application/eiam-application-oidc/pom.xml
|
||||
COPY eiam-application/eiam-application-jwt/pom.xml eiam-application/eiam-application-jwt/pom.xml
|
||||
COPY eiam-application/eiam-application-form/pom.xml eiam-application/eiam-application-form/pom.xml
|
||||
COPY eiam-application/eiam-application-all/pom.xml eiam-application/eiam-application-all/pom.xml
|
||||
COPY eiam-protocol/pom.xml eiam-protocol/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-core/pom.xml eiam-protocol/eiam-protocol-core/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-form/pom.xml eiam-protocol/eiam-protocol-form/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-jwt/pom.xml eiam-protocol/eiam-protocol-jwt/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-oidc/pom.xml eiam-protocol/eiam-protocol-oidc/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-all/pom.xml eiam-protocol/eiam-protocol-all/pom.xml
|
||||
COPY eiam-authentication/pom.xml eiam-authentication/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-core/pom.xml eiam-authentication/eiam-authentication-core/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-dingtalk/pom.xml eiam-authentication/eiam-authentication-dingtalk/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-feishu/pom.xml eiam-authentication/eiam-authentication-feishu/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-qq/pom.xml eiam-authentication/eiam-authentication-qq/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-wechat/pom.xml eiam-authentication/eiam-authentication-wechat/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-github/pom.xml eiam-authentication/eiam-authentication-github/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-wechatwork/pom.xml eiam-authentication/eiam-authentication-wechatwork/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-gitee/pom.xml eiam-authentication/eiam-authentication-gitee/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-alipay/pom.xml eiam-authentication/eiam-authentication-alipay/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-sms/pom.xml eiam-authentication/eiam-authentication-sms/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-mail/pom.xml eiam-authentication/eiam-authentication-mail/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-all/pom.xml eiam-authentication/eiam-authentication-all/pom.xml
|
||||
COPY eiam-identity-source/pom.xml eiam-identity-source/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-core/pom.xml eiam-identity-source/eiam-identity-source-core/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-dingtalk/pom.xml eiam-identity-source/eiam-identity-source-dingtalk/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-feishu/pom.xml eiam-identity-source/eiam-identity-source-feishu/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-all/pom.xml eiam-identity-source/eiam-identity-source-all/pom.xml
|
||||
COPY eiam-synchronizer/pom.xml eiam-synchronizer/pom.xml
|
||||
COPY eiam-portal/pom.xml eiam-portal/pom.xml
|
||||
COPY eiam-openapi/pom.xml eiam-openapi/pom.xml
|
||||
COPY eiam-console/pom.xml eiam-console/pom.xml
|
||||
|
||||
# 下载依赖(离线模式)
|
||||
RUN mvn dependency:go-offline -B -pl eiam-console -am
|
||||
|
||||
# 复制前端构建产物
|
||||
COPY --from=frontend-builder /build/console-fe/build eiam-console/src/main/console-fe/build
|
||||
|
||||
# 复制后端源码并编译打包
|
||||
COPY eiam-common eiam-common
|
||||
COPY eiam-core eiam-core
|
||||
COPY eiam-audit eiam-audit
|
||||
COPY eiam-application eiam-application
|
||||
COPY eiam-protocol eiam-protocol
|
||||
COPY eiam-authentication eiam-authentication
|
||||
COPY eiam-identity-source eiam-identity-source
|
||||
COPY eiam-synchronizer eiam-synchronizer
|
||||
COPY eiam-console/src eiam-console/src
|
||||
|
||||
RUN mvn clean package -pl eiam-console -am -P!dev -DskipTests -Dlicense.skip=true -Dformatter.skip=true -Dmaven.javadoc.skip=true
|
||||
|
||||
|
||||
# ---- 阶段 3: 运行时镜像 ----
|
||||
FROM eclipse-temurin:17-jre-alpine
|
||||
|
||||
# 安装基础工具:字体、时区、curl(健康检查用)
|
||||
RUN apk add --no-cache \
|
||||
tzdata \
|
||||
fontconfig \
|
||||
curl \
|
||||
&& ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime \
|
||||
&& echo "Asia/Shanghai" > /etc/timezone
|
||||
|
||||
# 创建非 root 用户
|
||||
RUN addgroup -g 1000 -S topiam && \
|
||||
adduser -u 1000 -S -G topiam topiam
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# 复制 jar 包
|
||||
COPY --from=backend-builder /build/eiam-console/target/topiam-employee-console-*.jar app.jar
|
||||
|
||||
# 修改文件所有者
|
||||
RUN chown -R topiam:topiam /app
|
||||
|
||||
# 切换非 root 用户
|
||||
USER topiam
|
||||
|
||||
# 暴露端口
|
||||
EXPOSE 1898
|
||||
|
||||
ENTRYPOINT ["java","-XX:TieredStopAtLevel=1","-Djava.security.egd=file:/dev/./urandom","-Dspring.main.lazy-initialization=false","org.springframework.boot.loader.launch.JarLauncher"]
|
||||
# JVM 参数优化
|
||||
ENV JAVA_OPTS="-Xms512m -Xmx1024m \
|
||||
-XX:+UseG1GC \
|
||||
-XX:MaxGCPauseMillis=200 \
|
||||
-XX:+HeapDumpOnOutOfMemoryError \
|
||||
-XX:HeapDumpPath=/app/heapdump.hprof \
|
||||
-Djava.security.egd=file:/dev/./urandom \
|
||||
-Dfile.encoding=UTF-8 \
|
||||
-Duser.timezone=Asia/Shanghai"
|
||||
|
||||
# 健康检查
|
||||
HEALTHCHECK --interval=30s --timeout=10s --start-period=60s --retries=3 \
|
||||
CMD curl -f http://localhost:1898/actuator/health || exit 1
|
||||
|
||||
# 启动入口
|
||||
ENTRYPOINT ["sh", "-c", "java $JAVA_OPTS -Dspring.profiles.active=remote -jar app.jar"]
|
||||
|
||||
+19
-25
@@ -131,47 +131,41 @@
|
||||
<build>
|
||||
<plugins>
|
||||
<!--编译打包前端项目-->
|
||||
<!-- 直接用系统已安装的 node/pnpm -->
|
||||
<plugin>
|
||||
<groupId>com.github.eirslett</groupId>
|
||||
<artifactId>frontend-maven-plugin</artifactId>
|
||||
<version>${frontend-maven-plugin.version}</version>
|
||||
<configuration>
|
||||
<installDirectory>target</installDirectory>
|
||||
<workingDirectory>src/main/console-fe</workingDirectory>
|
||||
</configuration>
|
||||
<groupId>org.codehaus.mojo</groupId>
|
||||
<artifactId>exec-maven-plugin</artifactId>
|
||||
<version>3.1.0</version>
|
||||
<executions>
|
||||
<execution>
|
||||
<id>install node and pnpm</id>
|
||||
<goals>
|
||||
<goal>install-node-and-pnpm</goal>
|
||||
</goals>
|
||||
<phase>generate-resources</phase>
|
||||
<configuration>
|
||||
<nodeDownloadRoot>https://mirrors.aliyun.com/nodejs-release/</nodeDownloadRoot>
|
||||
<nodeVersion>v22.12.0</nodeVersion>
|
||||
<pnpmVersion>v9.15.1</pnpmVersion>
|
||||
</configuration>
|
||||
</execution>
|
||||
<execution>
|
||||
<id>pnpm install</id>
|
||||
<goals>
|
||||
<goal>pnpm</goal>
|
||||
<goal>exec</goal>
|
||||
</goals>
|
||||
<phase>generate-resources</phase>
|
||||
<configuration>
|
||||
<arguments>install</arguments>
|
||||
<pnpmRegistryURL>https://registry.npmmirror.com</pnpmRegistryURL>
|
||||
<pnpmInheritsProxyConfigFromMaven>true</pnpmInheritsProxyConfigFromMaven>
|
||||
<executable>pnpm</executable>
|
||||
<workingDirectory>src/main/console-fe</workingDirectory>
|
||||
<arguments>
|
||||
<argument>install</argument>
|
||||
<argument>--registry=https://registry.npmmirror.com</argument>
|
||||
<argument>--ignore-scripts</argument>
|
||||
</arguments>
|
||||
</configuration>
|
||||
</execution>
|
||||
<execution>
|
||||
<id>pnpm run build</id>
|
||||
<goals>
|
||||
<goal>pnpm</goal>
|
||||
<goal>exec</goal>
|
||||
</goals>
|
||||
<phase>generate-resources</phase>
|
||||
<configuration>
|
||||
<arguments>run build:dev</arguments>
|
||||
<executable>pnpm</executable>
|
||||
<workingDirectory>src/main/console-fe</workingDirectory>
|
||||
<arguments>
|
||||
<argument>run</argument>
|
||||
<argument>build:dev</argument>
|
||||
</arguments>
|
||||
</configuration>
|
||||
</execution>
|
||||
</executions>
|
||||
|
||||
@@ -54,7 +54,7 @@
|
||||
"antd-img-crop": "^4.24.0",
|
||||
"antd-style": "^3.7.1",
|
||||
"classnames": "^2.5.1",
|
||||
"codemirror": "^6.0.1",
|
||||
"codemirror": "5.65.19",
|
||||
"content-security-policy-parser": "^0.6.0",
|
||||
"copy-to-clipboard": "^3.3.3",
|
||||
"crypto-js": "^4.2.0",
|
||||
|
||||
+4866
-4004
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,5 @@
|
||||
allowBuilds:
|
||||
core-js: true
|
||||
core-js-pure: true
|
||||
es5-ext: true
|
||||
esbuild: true
|
||||
@@ -0,0 +1,72 @@
|
||||
spring:
|
||||
datasource:
|
||||
url: jdbc:mysql://100.74.125.93:3306/topiam?serverTimezone=GMT%2B8&useUnicode=true&characterEncoding=UTF-8&autoReconnect=true&useSSL=false&allowPublicKeyRetrieval=true&rewriteBatchedStatements=true
|
||||
username: topiam
|
||||
password: topiam
|
||||
driver-class-name: com.mysql.cj.jdbc.Driver
|
||||
hikari:
|
||||
maximum-pool-size: 20
|
||||
minimum-idle: 5
|
||||
connection-timeout: 30000
|
||||
idle-timeout: 600000
|
||||
max-lifetime: 1800000
|
||||
|
||||
data:
|
||||
redis:
|
||||
host: 100.74.125.93
|
||||
port: 6379
|
||||
password: redis
|
||||
database: 0
|
||||
timeout: 5000ms
|
||||
lettuce:
|
||||
pool:
|
||||
max-active: 20
|
||||
max-idle: 10
|
||||
min-idle: 5
|
||||
shutdown-timeout: 100ms
|
||||
|
||||
elasticsearch:
|
||||
uris: http://100.74.125.93:9200
|
||||
connection-timeout: 5000ms
|
||||
socket-timeout: 10000ms
|
||||
|
||||
rabbitmq:
|
||||
host: 100.74.125.93
|
||||
port: 5672
|
||||
username: rabbitmq
|
||||
password: rabbitmq
|
||||
virtual-host: /
|
||||
publisher-confirm-type: correlated
|
||||
publisher-returns: true
|
||||
dynamic: true
|
||||
listener:
|
||||
simple:
|
||||
acknowledge-mode: manual
|
||||
concurrency: 5
|
||||
max-concurrency: 20
|
||||
prefetch: 10
|
||||
|
||||
# SpringDoc 配置
|
||||
springdoc:
|
||||
swagger-ui:
|
||||
enabled: true
|
||||
path: /swagger-ui.html
|
||||
api-docs:
|
||||
path: /v3/api-docs
|
||||
|
||||
# TOPIAM 服务配置
|
||||
topiam:
|
||||
server:
|
||||
console-public-base-url: http://100.74.125.93:1898
|
||||
portal-public-base-url: http://100.74.125.93:1989
|
||||
openapi-public-base-url: http://100.74.125.93:1988
|
||||
synchronizer-public-base-url: http://100.74.125.93:1986
|
||||
|
||||
# 可选:日志配置
|
||||
logging:
|
||||
level:
|
||||
cn.topiam: debug
|
||||
org.springframework.web: info
|
||||
org.hibernate.SQL: warn
|
||||
pattern:
|
||||
console: "%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] %-5level %logger{36} - %msg%n"
|
||||
+98
-43
@@ -1,53 +1,108 @@
|
||||
#
|
||||
# eiam-openapi - Employee Identity and Access Management
|
||||
# Copyright © 2022-Present Jinan Yuanchuang Network Technology Co., Ltd. (support@topiam.cn)
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU Affero General Public License as published by
|
||||
# the Free Software Foundation, either version 3 of the License, or
|
||||
# (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU Affero General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU Affero General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
#
|
||||
# =============================================
|
||||
# TOPIAM OpenAPI - 多阶段构建(纯后端,无前端)
|
||||
# =============================================
|
||||
|
||||
FROM azul/zulu-openjdk:17-jre as build
|
||||
WORKDIR /workspace/app
|
||||
# ---- 阶段 1: 后端构建 ----
|
||||
FROM m.daocloud.io/docker.io/library/maven:3.9-eclipse-temurin-17 AS backend-builder
|
||||
|
||||
ARG JAR_FILE=target/topiam-employee-openapi-*.jar
|
||||
COPY ${JAR_FILE} target/application.jar
|
||||
RUN java -Djarmode=layertools -jar target/application.jar extract --destination target/extracted
|
||||
WORKDIR /build
|
||||
|
||||
FROM azul/zulu-openjdk:17-jre
|
||||
# 设置 Maven 参数(避免配置文件冲突)
|
||||
ENV MAVEN_OPTS="-Xmx2048m -Xms1024m -Djava.awt.headless=true -Dmaven.multiModuleProjectDirectory=/build"
|
||||
|
||||
ARG EXTRACTED=/workspace/app/target/extracted
|
||||
WORKDIR topiam
|
||||
COPY --from=build ${EXTRACTED}/dependencies/ ./
|
||||
COPY --from=build ${EXTRACTED}/spring-boot-loader/ ./
|
||||
COPY --from=build ${EXTRACTED}/snapshot-dependencies/ ./
|
||||
COPY --from=build ${EXTRACTED}/application/ ./
|
||||
# 复制父 pom 和所有模块 pom(父 pom 需要所有子模块存在)
|
||||
COPY pom.xml .
|
||||
COPY eiam-common/pom.xml eiam-common/pom.xml
|
||||
COPY eiam-core/pom.xml eiam-core/pom.xml
|
||||
COPY eiam-audit/pom.xml eiam-audit/pom.xml
|
||||
COPY eiam-application/pom.xml eiam-application/pom.xml
|
||||
COPY eiam-application/eiam-application-core/pom.xml eiam-application/eiam-application-core/pom.xml
|
||||
COPY eiam-application/eiam-application-oidc/pom.xml eiam-application/eiam-application-oidc/pom.xml
|
||||
COPY eiam-application/eiam-application-jwt/pom.xml eiam-application/eiam-application-jwt/pom.xml
|
||||
COPY eiam-application/eiam-application-form/pom.xml eiam-application/eiam-application-form/pom.xml
|
||||
COPY eiam-application/eiam-application-all/pom.xml eiam-application/eiam-application-all/pom.xml
|
||||
COPY eiam-protocol/pom.xml eiam-protocol/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-core/pom.xml eiam-protocol/eiam-protocol-core/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-form/pom.xml eiam-protocol/eiam-protocol-form/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-jwt/pom.xml eiam-protocol/eiam-protocol-jwt/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-oidc/pom.xml eiam-protocol/eiam-protocol-oidc/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-all/pom.xml eiam-protocol/eiam-protocol-all/pom.xml
|
||||
COPY eiam-authentication/pom.xml eiam-authentication/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-core/pom.xml eiam-authentication/eiam-authentication-core/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-dingtalk/pom.xml eiam-authentication/eiam-authentication-dingtalk/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-feishu/pom.xml eiam-authentication/eiam-authentication-feishu/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-qq/pom.xml eiam-authentication/eiam-authentication-qq/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-wechat/pom.xml eiam-authentication/eiam-authentication-wechat/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-github/pom.xml eiam-authentication/eiam-authentication-github/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-wechatwork/pom.xml eiam-authentication/eiam-authentication-wechatwork/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-gitee/pom.xml eiam-authentication/eiam-authentication-gitee/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-alipay/pom.xml eiam-authentication/eiam-authentication-alipay/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-sms/pom.xml eiam-authentication/eiam-authentication-sms/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-mail/pom.xml eiam-authentication/eiam-authentication-mail/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-all/pom.xml eiam-authentication/eiam-authentication-all/pom.xml
|
||||
COPY eiam-identity-source/pom.xml eiam-identity-source/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-core/pom.xml eiam-identity-source/eiam-identity-source-core/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-dingtalk/pom.xml eiam-identity-source/eiam-identity-source-dingtalk/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-feishu/pom.xml eiam-identity-source/eiam-identity-source-feishu/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-all/pom.xml eiam-identity-source/eiam-identity-source-all/pom.xml
|
||||
COPY eiam-synchronizer/pom.xml eiam-synchronizer/pom.xml
|
||||
COPY eiam-console/pom.xml eiam-console/pom.xml
|
||||
COPY eiam-portal/pom.xml eiam-portal/pom.xml
|
||||
COPY eiam-openapi/pom.xml eiam-openapi/pom.xml
|
||||
|
||||
# 下载依赖(离线模式)
|
||||
RUN mvn dependency:go-offline -B -pl eiam-openapi -am
|
||||
|
||||
# 复制后端源码并编译打包
|
||||
COPY eiam-common eiam-common
|
||||
COPY eiam-core eiam-core
|
||||
COPY eiam-audit eiam-audit
|
||||
COPY eiam-openapi/src eiam-openapi/src
|
||||
|
||||
RUN mvn clean package -pl eiam-openapi -am -P!dev -DskipTests -Dlicense.skip=true -Dformatter.skip=true -Dmaven.javadoc.skip=true
|
||||
|
||||
|
||||
ENV TZ=Asia/Shanghai
|
||||
RUN sed -i 's/archive.ubuntu.com/cn.archive.ubuntu.com/g' /etc/apt/sources.list \
|
||||
&& apt-get update \
|
||||
&& ln -snf /usr/share/zoneinfo/$TZ /etc/localtime && echo $TZ > /etc/timezone \
|
||||
&& apt-get clean \
|
||||
&& apt-get autoclean \
|
||||
&& apt-get autoremove -y \
|
||||
&& apt-get install -y curl \
|
||||
&& apt-get install -y iputils-ping \
|
||||
&& apt-get install -y wget \
|
||||
&& apt-get install -y tzdata \
|
||||
&& apt-get install -y fontconfig \
|
||||
&& rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* \
|
||||
# ---- 阶段 2: 运行时镜像 ----
|
||||
FROM eclipse-temurin:17-jre-alpine
|
||||
|
||||
# 安装基础工具
|
||||
RUN apk add --no-cache \
|
||||
tzdata \
|
||||
curl \
|
||||
&& ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime \
|
||||
&& echo "Asia/Shanghai" > /etc/timezone
|
||||
|
||||
# 创建非 root 用户
|
||||
RUN addgroup -g 1000 -S topiam && \
|
||||
adduser -u 1000 -S -G topiam topiam
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# 复制 jar 包
|
||||
COPY --from=backend-builder /build/eiam-openapi/target/topiam-employee-openapi-*.jar app.jar
|
||||
|
||||
# 修改文件所有者
|
||||
RUN chown -R topiam:topiam /app
|
||||
|
||||
# 切换非 root 用户
|
||||
USER topiam
|
||||
|
||||
# 暴露端口
|
||||
EXPOSE 1988
|
||||
|
||||
ENTRYPOINT ["java","-XX:TieredStopAtLevel=1","-Djava.security.egd=file:/dev/./urandom","-Dspring.main.lazy-initialization=false","org.springframework.boot.loader.launch.JarLauncher"]
|
||||
# JVM 参数优化(OpenAPI 较轻量,内存可适当减小)
|
||||
ENV JAVA_OPTS="-Xms256m -Xmx512m \
|
||||
-XX:+UseG1GC \
|
||||
-XX:MaxGCPauseMillis=200 \
|
||||
-XX:+HeapDumpOnOutOfMemoryError \
|
||||
-XX:HeapDumpPath=/app/heapdump.hprof \
|
||||
-Djava.security.egd=file:/dev/./urandom \
|
||||
-Dfile.encoding=UTF-8 \
|
||||
-Duser.timezone=Asia/Shanghai"
|
||||
|
||||
# 健康检查
|
||||
HEALTHCHECK --interval=30s --timeout=10s --start-period=40s --retries=3 \
|
||||
CMD curl -f http://localhost:1988/actuator/health || exit 1
|
||||
|
||||
# 启动入口
|
||||
ENTRYPOINT ["sh", "-c", "java $JAVA_OPTS -Dspring.profiles.active=remote -jar app.jar"]
|
||||
|
||||
@@ -0,0 +1,72 @@
|
||||
spring:
|
||||
datasource:
|
||||
url: jdbc:mysql://100.74.125.93:3306/topiam?serverTimezone=GMT%2B8&useUnicode=true&characterEncoding=UTF-8&autoReconnect=true&useSSL=false&allowPublicKeyRetrieval=true&rewriteBatchedStatements=true
|
||||
username: topiam
|
||||
password: topiam
|
||||
driver-class-name: com.mysql.cj.jdbc.Driver
|
||||
hikari:
|
||||
maximum-pool-size: 20
|
||||
minimum-idle: 5
|
||||
connection-timeout: 30000
|
||||
idle-timeout: 600000
|
||||
max-lifetime: 1800000
|
||||
|
||||
data:
|
||||
redis:
|
||||
host: 100.74.125.93
|
||||
port: 6379
|
||||
password: redis
|
||||
database: 0
|
||||
timeout: 5000ms
|
||||
lettuce:
|
||||
pool:
|
||||
max-active: 20
|
||||
max-idle: 10
|
||||
min-idle: 5
|
||||
shutdown-timeout: 100ms
|
||||
|
||||
elasticsearch:
|
||||
uris: http://100.74.125.93:9200
|
||||
connection-timeout: 5000ms
|
||||
socket-timeout: 10000ms
|
||||
|
||||
rabbitmq:
|
||||
host: 100.74.125.93
|
||||
port: 5672
|
||||
username: rabbitmq
|
||||
password: rabbitmq
|
||||
virtual-host: /
|
||||
publisher-confirm-type: correlated
|
||||
publisher-returns: true
|
||||
dynamic: true
|
||||
listener:
|
||||
simple:
|
||||
acknowledge-mode: manual
|
||||
concurrency: 5
|
||||
max-concurrency: 20
|
||||
prefetch: 10
|
||||
|
||||
# SpringDoc 配置
|
||||
springdoc:
|
||||
swagger-ui:
|
||||
enabled: true
|
||||
path: /swagger-ui.html
|
||||
api-docs:
|
||||
path: /v3/api-docs
|
||||
|
||||
# TOPIAM 服务配置
|
||||
topiam:
|
||||
server:
|
||||
console-public-base-url: http://100.74.125.93:1898
|
||||
portal-public-base-url: http://100.74.125.93:1989
|
||||
openapi-public-base-url: http://100.74.125.93:1988
|
||||
synchronizer-public-base-url: http://100.74.125.93:1986
|
||||
|
||||
# 可选:日志配置
|
||||
logging:
|
||||
level:
|
||||
cn.topiam: debug
|
||||
org.springframework.web: info
|
||||
org.hibernate.SQL: warn
|
||||
pattern:
|
||||
console: "%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] %-5level %logger{36} - %msg%n"
|
||||
+123
-43
@@ -1,54 +1,134 @@
|
||||
#
|
||||
# eiam-portal - Employee Identity and Access Management
|
||||
# Copyright © 2022-Present Jinan Yuanchuang Network Technology Co., Ltd. (support@topiam.cn)
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify
|
||||
# it under the terms of the GNU Affero General Public License as published by
|
||||
# the Free Software Foundation, either version 3 of the License, or
|
||||
# (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU Affero General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU Affero General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
#
|
||||
# =============================================
|
||||
# TOPIAM Portal - 多阶段构建(简化 Maven 配置)
|
||||
# =============================================
|
||||
|
||||
FROM azul/zulu-openjdk:17-jre as build
|
||||
WORKDIR /workspace/app
|
||||
# ---- 阶段 1: 前端构建 ----
|
||||
FROM m.daocloud.io/docker.io/library/node:22.12.0-alpine AS frontend-builder
|
||||
|
||||
ARG JAR_FILE=target/topiam-employee-portal-*.jar
|
||||
COPY ${JAR_FILE} target/application.jar
|
||||
RUN java -Djarmode=layertools -jar target/application.jar extract --destination target/extracted
|
||||
WORKDIR /build/portal-fe
|
||||
|
||||
FROM azul/zulu-openjdk:17-jre
|
||||
# 配置 pnpm 和镜像源
|
||||
RUN npm config set registry https://registry.npmmirror.com && \
|
||||
npm install -g pnpm@9.15.1
|
||||
|
||||
# 先复制 package.json 利用缓存
|
||||
COPY eiam-portal/src/main/portal-fe/package.json eiam-portal/src/main/portal-fe/pnpm-lock.yaml* ./
|
||||
RUN pnpm install --frozen-lockfile --ignore-scripts
|
||||
|
||||
# 复制源码并构建
|
||||
COPY eiam-portal/src/main/portal-fe/ ./
|
||||
ENV UMI_ENV=dev
|
||||
RUN npm run build:dev
|
||||
|
||||
|
||||
# ---- 阶段 2: 后端构建 ----
|
||||
FROM m.daocloud.io/docker.io/library/maven:3.9-eclipse-temurin-17 AS backend-builder
|
||||
|
||||
ARG EXTRACTED=/workspace/app/target/extracted
|
||||
WORKDIR topiam
|
||||
COPY --from=build ${EXTRACTED}/dependencies/ ./
|
||||
COPY --from=build ${EXTRACTED}/spring-boot-loader/ ./
|
||||
COPY --from=build ${EXTRACTED}/snapshot-dependencies/ ./
|
||||
COPY --from=build ${EXTRACTED}/application/ ./
|
||||
WORKDIR /build
|
||||
|
||||
ENV TZ=Asia/Shanghai
|
||||
RUN sed -i 's/archive.ubuntu.com/cn.archive.ubuntu.com/g' /etc/apt/sources.list \
|
||||
&& apt-get update \
|
||||
&& ln -snf /usr/share/zoneinfo/$TZ /etc/localtime && echo $TZ > /etc/timezone \
|
||||
&& apt-get clean \
|
||||
&& apt-get autoclean \
|
||||
&& apt-get autoremove -y \
|
||||
&& apt-get install -y curl \
|
||||
&& apt-get install -y iputils-ping \
|
||||
&& apt-get install -y wget \
|
||||
&& apt-get install -y tzdata \
|
||||
&& apt-get install -y fontconfig \
|
||||
&& rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* \
|
||||
# 设置 Maven 参数(避免配置文件冲突)
|
||||
ENV MAVEN_OPTS="-Xmx2048m -Xms1024m -Djava.awt.headless=true -Dmaven.multiModuleProjectDirectory=/build"
|
||||
|
||||
# 复制父 pom 和所有模块 pom
|
||||
COPY pom.xml .
|
||||
COPY eiam-common/pom.xml eiam-common/pom.xml
|
||||
COPY eiam-core/pom.xml eiam-core/pom.xml
|
||||
COPY eiam-audit/pom.xml eiam-audit/pom.xml
|
||||
COPY eiam-application/pom.xml eiam-application/pom.xml
|
||||
COPY eiam-application/eiam-application-core/pom.xml eiam-application/eiam-application-core/pom.xml
|
||||
COPY eiam-application/eiam-application-oidc/pom.xml eiam-application/eiam-application-oidc/pom.xml
|
||||
COPY eiam-application/eiam-application-jwt/pom.xml eiam-application/eiam-application-jwt/pom.xml
|
||||
COPY eiam-application/eiam-application-form/pom.xml eiam-application/eiam-application-form/pom.xml
|
||||
COPY eiam-application/eiam-application-all/pom.xml eiam-application/eiam-application-all/pom.xml
|
||||
COPY eiam-protocol/pom.xml eiam-protocol/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-core/pom.xml eiam-protocol/eiam-protocol-core/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-form/pom.xml eiam-protocol/eiam-protocol-form/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-jwt/pom.xml eiam-protocol/eiam-protocol-jwt/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-oidc/pom.xml eiam-protocol/eiam-protocol-oidc/pom.xml
|
||||
COPY eiam-protocol/eiam-protocol-all/pom.xml eiam-protocol/eiam-protocol-all/pom.xml
|
||||
COPY eiam-authentication/pom.xml eiam-authentication/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-core/pom.xml eiam-authentication/eiam-authentication-core/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-dingtalk/pom.xml eiam-authentication/eiam-authentication-dingtalk/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-feishu/pom.xml eiam-authentication/eiam-authentication-feishu/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-qq/pom.xml eiam-authentication/eiam-authentication-qq/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-wechat/pom.xml eiam-authentication/eiam-authentication-wechat/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-github/pom.xml eiam-authentication/eiam-authentication-github/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-wechatwork/pom.xml eiam-authentication/eiam-authentication-wechatwork/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-gitee/pom.xml eiam-authentication/eiam-authentication-gitee/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-alipay/pom.xml eiam-authentication/eiam-authentication-alipay/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-sms/pom.xml eiam-authentication/eiam-authentication-sms/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-mail/pom.xml eiam-authentication/eiam-authentication-mail/pom.xml
|
||||
COPY eiam-authentication/eiam-authentication-all/pom.xml eiam-authentication/eiam-authentication-all/pom.xml
|
||||
COPY eiam-console/pom.xml eiam-console/pom.xml
|
||||
COPY eiam-openapi/pom.xml eiam-openapi/pom.xml
|
||||
COPY eiam-portal/pom.xml eiam-portal/pom.xml
|
||||
COPY eiam-identity-source/pom.xml eiam-identity-source/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-core/pom.xml eiam-identity-source/eiam-identity-source-core/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-dingtalk/pom.xml eiam-identity-source/eiam-identity-source-dingtalk/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-feishu/pom.xml eiam-identity-source/eiam-identity-source-feishu/pom.xml
|
||||
COPY eiam-identity-source/eiam-identity-source-all/pom.xml eiam-identity-source/eiam-identity-source-all/pom.xml
|
||||
COPY eiam-synchronizer/pom.xml eiam-synchronizer/pom.xml
|
||||
|
||||
# 下载依赖(离线模式)
|
||||
RUN mvn dependency:go-offline -B -pl eiam-portal -am
|
||||
|
||||
# 复制前端构建产物
|
||||
COPY --from=frontend-builder /build/portal-fe/build eiam-portal/src/main/portal-fe/build
|
||||
|
||||
# 复制后端源码并编译打包
|
||||
COPY eiam-common eiam-common
|
||||
COPY eiam-core eiam-core
|
||||
COPY eiam-audit eiam-audit
|
||||
COPY eiam-application eiam-application
|
||||
COPY eiam-protocol eiam-protocol
|
||||
COPY eiam-authentication eiam-authentication
|
||||
COPY eiam-portal/src eiam-portal/src
|
||||
|
||||
RUN mvn clean package -pl eiam-portal -am -P!dev -DskipTests -Dlicense.skip=true -Dformatter.skip=true -Dmaven.javadoc.skip=true
|
||||
|
||||
|
||||
# ---- 阶段 3: 运行时镜像 ----
|
||||
FROM eclipse-temurin:17-jre-alpine
|
||||
|
||||
# 安装基础工具
|
||||
RUN apk add --no-cache \
|
||||
tzdata \
|
||||
fontconfig \
|
||||
curl \
|
||||
&& ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime \
|
||||
&& echo "Asia/Shanghai" > /etc/timezone
|
||||
|
||||
# 创建非 root 用户
|
||||
RUN addgroup -g 1000 -S topiam && \
|
||||
adduser -u 1000 -S -G topiam topiam
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# 复制 jar 包
|
||||
COPY --from=backend-builder /build/eiam-portal/target/topiam-employee-portal-*.jar app.jar
|
||||
|
||||
# 修改文件所有者
|
||||
RUN chown -R topiam:topiam /app
|
||||
|
||||
# 切换非 root 用户
|
||||
USER topiam
|
||||
|
||||
# 暴露端口
|
||||
EXPOSE 1989
|
||||
|
||||
ENTRYPOINT ["java","-XX:TieredStopAtLevel=1","-Djava.security.egd=file:/dev/./urandom","-Dspring.main.lazy-initialization=false","org.springframework.boot.loader.launch.JarLauncher"]
|
||||
# JVM 参数优化
|
||||
ENV JAVA_OPTS="-Xms512m -Xmx1024m \
|
||||
-XX:+UseG1GC \
|
||||
-XX:MaxGCPauseMillis=200 \
|
||||
-XX:+HeapDumpOnOutOfMemoryError \
|
||||
-XX:HeapDumpPath=/app/heapdump.hprof \
|
||||
-Djava.security.egd=file:/dev/./urandom \
|
||||
-Dfile.encoding=UTF-8 \
|
||||
-Duser.timezone=Asia/Shanghai"
|
||||
|
||||
# 健康检查
|
||||
HEALTHCHECK --interval=30s --timeout=10s --start-period=60s --retries=3 \
|
||||
CMD curl -f http://localhost:1989/actuator/health || exit 1
|
||||
|
||||
# 启动入口
|
||||
ENTRYPOINT ["sh", "-c", "java $JAVA_OPTS -Dspring.profiles.active=remote -jar app.jar"]
|
||||
|
||||
+4400
-3006
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,72 @@
|
||||
spring:
|
||||
datasource:
|
||||
url: jdbc:mysql://100.74.125.93:3306/topiam?serverTimezone=GMT%2B8&useUnicode=true&characterEncoding=UTF-8&autoReconnect=true&useSSL=false&allowPublicKeyRetrieval=true&rewriteBatchedStatements=true
|
||||
username: topiam
|
||||
password: topiam
|
||||
driver-class-name: com.mysql.cj.jdbc.Driver
|
||||
hikari:
|
||||
maximum-pool-size: 20
|
||||
minimum-idle: 5
|
||||
connection-timeout: 30000
|
||||
idle-timeout: 600000
|
||||
max-lifetime: 1800000
|
||||
|
||||
data:
|
||||
redis:
|
||||
host: 100.74.125.93
|
||||
port: 6379
|
||||
password: redis
|
||||
database: 0
|
||||
timeout: 5000ms
|
||||
lettuce:
|
||||
pool:
|
||||
max-active: 20
|
||||
max-idle: 10
|
||||
min-idle: 5
|
||||
shutdown-timeout: 100ms
|
||||
|
||||
elasticsearch:
|
||||
uris: http://100.74.125.93:9200
|
||||
connection-timeout: 5000ms
|
||||
socket-timeout: 10000ms
|
||||
|
||||
rabbitmq:
|
||||
host: 100.74.125.93
|
||||
port: 5672
|
||||
username: rabbitmq
|
||||
password: rabbitmq
|
||||
virtual-host: /
|
||||
publisher-confirm-type: correlated
|
||||
publisher-returns: true
|
||||
dynamic: true
|
||||
listener:
|
||||
simple:
|
||||
acknowledge-mode: manual
|
||||
concurrency: 5
|
||||
max-concurrency: 20
|
||||
prefetch: 10
|
||||
|
||||
# SpringDoc 配置
|
||||
springdoc:
|
||||
swagger-ui:
|
||||
enabled: true
|
||||
path: /swagger-ui.html
|
||||
api-docs:
|
||||
path: /v3/api-docs
|
||||
|
||||
# TOPIAM 服务配置
|
||||
topiam:
|
||||
server:
|
||||
console-public-base-url: http://100.74.125.93:1898
|
||||
portal-public-base-url: http://100.74.125.93:1989
|
||||
openapi-public-base-url: http://100.74.125.93:1988
|
||||
synchronizer-public-base-url: http://100.74.125.93:1986
|
||||
|
||||
# 可选:日志配置
|
||||
logging:
|
||||
level:
|
||||
cn.topiam: debug
|
||||
org.springframework.web: info
|
||||
org.hibernate.SQL: warn
|
||||
pattern:
|
||||
console: "%d{yyyy-MM-dd HH:mm:ss.SSS} [%thread] %-5level %logger{36} - %msg%n"
|
||||
@@ -1,23 +1,4 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!--
|
||||
|
||||
TOPIAM Employee - Employee Identity and Access Management
|
||||
Copyright © 2022-Present Jinan Yuanchuang Network Technology Co., Ltd. (support@topiam.cn)
|
||||
|
||||
This program is free software: you can redistribute it and/or modify
|
||||
it under the terms of the GNU Affero General Public License as published by
|
||||
the Free Software Foundation, either version 3 of the License, or
|
||||
(at your option) any later version.
|
||||
|
||||
This program is distributed in the hope that it will be useful,
|
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
GNU Affero General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU Affero General Public License
|
||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
-->
|
||||
<project xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://maven.apache.org/POM/4.0.0"
|
||||
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/xsd/maven-4.0.0.xsd">
|
||||
<modelVersion>4.0.0</modelVersion>
|
||||
|
||||
Executable
+11
@@ -0,0 +1,11 @@
|
||||
#!/usr/bin/env bash
|
||||
# 启动 Console 管理后台 (端口 1898)
|
||||
|
||||
set -e
|
||||
PROJECT_ROOT="/Users/yhtx/Documents/jupyter/ai/topiam"
|
||||
|
||||
echo "🚀 启动 Console (端口 1898)..."
|
||||
cd "$PROJECT_ROOT/eiam-console"
|
||||
../mvnw spring-boot:run -Pdev \
|
||||
-Dspring-boot.run.jvmArguments="-Dspring.profiles.active=remote" \
|
||||
-Dlicense.skip=true -Dformatter.skip=true
|
||||
Executable
+11
@@ -0,0 +1,11 @@
|
||||
#!/usr/bin/env bash
|
||||
# 启动 OpenAPI 开放接口 (端口 1988)
|
||||
|
||||
set -e
|
||||
PROJECT_ROOT="/Users/yhtx/Documents/jupyter/ai/topiam"
|
||||
|
||||
echo "🚀 启动 OpenAPI (端口 1988)..."
|
||||
cd "$PROJECT_ROOT/eiam-openapi"
|
||||
../mvnw spring-boot:run \
|
||||
-Dspring-boot.run.jvmArguments="-Dspring.profiles.active=remote" \
|
||||
-Dlicense.skip=true -Dformatter.skip=true
|
||||
Executable
+11
@@ -0,0 +1,11 @@
|
||||
#!/usr/bin/env bash
|
||||
# 启动 Portal 用户门户 (端口 1989)
|
||||
|
||||
set -e
|
||||
PROJECT_ROOT="/Users/yhtx/Documents/jupyter/ai/topiam"
|
||||
|
||||
echo "🚀 启动 Portal (端口 1989)..."
|
||||
cd "$PROJECT_ROOT/eiam-portal"
|
||||
../mvnw spring-boot:run -Pdev \
|
||||
-Dspring-boot.run.jvmArguments="-Dspring.profiles.active=remote" \
|
||||
-Dlicense.skip=true -Dformatter.skip=true
|
||||
@@ -1,22 +1,3 @@
|
||||
<!--
|
||||
|
||||
TOPIAM Employee - Employee Identity and Access Management
|
||||
Copyright © 2022-Present Jinan Yuanchuang Network Technology Co., Ltd. (support@topiam.cn)
|
||||
|
||||
This program is free software: you can redistribute it and/or modify
|
||||
it under the terms of the GNU Affero General Public License as published by
|
||||
the Free Software Foundation, either version 3 of the License, or
|
||||
(at your option) any later version.
|
||||
|
||||
This program is distributed in the hope that it will be useful,
|
||||
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
GNU Affero General Public License for more details.
|
||||
|
||||
You should have received a copy of the GNU Affero General Public License
|
||||
along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
|
||||
-->
|
||||
<profiles version="1">
|
||||
<profile kind="CodeFormatterProfile" name="TopIAM Convention" version="1">
|
||||
<setting id="org.eclipse.jdt.core.formatter.comment.insert_new_line_before_root_tags" value="insert"/>
|
||||
|
||||
Reference in New Issue
Block a user