From 58094265bba34829cb034c05d3337ca43a647844 Mon Sep 17 00:00:00 2001 From: 28Hus <93303005+28Hus@users.noreply.github.com> Date: Thu, 1 Oct 2026 21:40:00 +0800 Subject: [PATCH] fix: remove default JWT secret from Docker configs --- INSTALL.md | 21 +++++++++++++++------ INSTALL_ZH.md | 21 +++++++++++++++------ README.md | 5 ++++- README_ZH.md | 5 ++++- config.yaml.sample | 2 +- docker-compose.yaml | 2 +- docker/config.yaml | 2 +- docs/deploy/core/001-配置文件说明.md | 3 ++- 8 files changed, 43 insertions(+), 18 deletions(-) diff --git a/INSTALL.md b/INSTALL.md index 50cff9d8..f16e7cf4 100644 --- a/INSTALL.md +++ b/INSTALL.md @@ -42,6 +42,9 @@ This is the fastest way to start a local environment with the main dependencies ```sh git clone https://github.com/rocboss/paopao-ce.git cd paopao-ce +cp config.yaml.sample config.yaml +openssl rand -hex 32 +# Set JWT.Secret in config.yaml to the generated value. docker compose up -d ``` @@ -54,11 +57,11 @@ The default compose setup starts these services: Notes: -- The backend container mounts `./config.yaml.sample` as its runtime config by default. +- The backend container mounts `./config.yaml` as its runtime config. Create it from the sample and set a unique `JWT.Secret` before starting the stack. - Persistent data is stored under `./custom/`. - Optional services such as MinIO, OpenObserve, Pyroscope, and phpMyAdmin are present in `docker-compose.yaml` but commented out by default. -If you want to use a custom config file, replace the mounted file in `docker-compose.yaml`: +The Compose file mounts the local config at `/app/paopao-ce/config.yaml`: ```yaml backend: @@ -92,11 +95,13 @@ docker build -t your/paopao-ce:tag --build-arg EMBED_UI=no . Run a locally built image: +Create `config.yaml` from the sample and set a unique `JWT.Secret` before running either backend image. Generate a value with `openssl rand -hex 32`. + ```sh mkdir -p custom docker run -d -p 8008:8008 \ -v ${PWD}/custom:/app/paopao-ce/custom \ - -v ${PWD}/config.yaml.sample:/app/paopao-ce/config.yaml \ + -v ${PWD}/config.yaml:/app/paopao-ce/config.yaml \ your/paopao-ce:tag ``` @@ -106,7 +111,7 @@ Or use the published image: mkdir -p custom docker run -d -p 8008:8008 \ -v ${PWD}/custom:/app/paopao-ce/custom \ - -v ${PWD}/config.yaml.sample:/app/paopao-ce/config.yaml \ + -v ${PWD}/config.yaml:/app/paopao-ce/config.yaml \ bitbus/paopao-ce:latest ``` @@ -130,18 +135,22 @@ docker run -d -p 8010:80 your/paopao-ce:web ### All-in-one image +Create `config.yaml` from `docker/config.yaml` and set a unique `JWT.Secret` before running either all-in-one image. Generate a value with `openssl rand -hex 32`. + ```sh # Build docker buildx build --build-arg USE_DIST=yes -t your/paopao-ce:all-in-one-latest -f Dockerfile.allinone . # Run a local image docker run --name paopao-ce-allinone -d -p 8000:8008 -p 7700:7700 \ + -v ${PWD}/config.yaml:/app/config.yaml \ -v ./data/custom:/app/custom \ -v ./data/meili_data:/app/meili_data \ your/paopao-ce:all-in-one-latest # Run the published image docker run --name paopao-ce-allinone -d -p 8000:8008 -p 7700:7700 \ + -v ${PWD}/config.yaml:/app/config.yaml \ -v ./data/custom:/app/custom \ -v ./data/meili_data:/app/meili_data \ bitbus/paopao-ce:all-in-one-latest @@ -156,8 +165,8 @@ If you mount a custom `config.yaml`, make sure `Meili.ApiKey` matches the contai ### Backend 1. Initialize your database with the matching SQL file for your chosen database engine. -2. Copy the configuration template. -3. Adjust only the bootstrap-critical settings for your environment. +2. Copy the configuration template and set `JWT.Secret` to a unique value generated with `openssl rand -hex 32`. +3. Adjust the bootstrap-critical settings for your environment. 4. Run or build the backend. ```sh diff --git a/INSTALL_ZH.md b/INSTALL_ZH.md index 51e2e217..e269ded3 100644 --- a/INSTALL_ZH.md +++ b/INSTALL_ZH.md @@ -42,6 +42,9 @@ ```sh git clone https://github.com/rocboss/paopao-ce.git cd paopao-ce +cp config.yaml.sample config.yaml +openssl rand -hex 32 +# 将生成的值填入 config.yaml 的 JWT.Secret。 docker compose up -d ``` @@ -54,11 +57,11 @@ docker compose up -d 说明: -- 后端容器默认会将 `./config.yaml.sample` 挂载为运行配置。 +- 后端容器会将 `./config.yaml` 挂载为运行配置。启动前请从示例复制该文件,并设置唯一的 `JWT.Secret`。 - 持久化数据默认保存在 `./custom/` 目录下。 - `docker-compose.yaml` 中还预留了 MinIO、OpenObserve、Pyroscope、phpMyAdmin 等可选服务,但默认是注释状态。 -如果需要使用自定义配置文件,可将 `docker-compose.yaml` 中的挂载改为: +Compose 配置会将本地配置挂载到 `/app/paopao-ce/config.yaml`: ```yaml backend: @@ -92,11 +95,13 @@ docker build -t your/paopao-ce:tag --build-arg EMBED_UI=no . 运行本地构建镜像: +运行任一后端镜像前,请从示例创建 `config.yaml` 并设置唯一的 `JWT.Secret`。可使用 `openssl rand -hex 32` 生成。 + ```sh mkdir -p custom docker run -d -p 8008:8008 \ -v ${PWD}/custom:/app/paopao-ce/custom \ - -v ${PWD}/config.yaml.sample:/app/paopao-ce/config.yaml \ + -v ${PWD}/config.yaml:/app/paopao-ce/config.yaml \ your/paopao-ce:tag ``` @@ -106,7 +111,7 @@ docker run -d -p 8008:8008 \ mkdir -p custom docker run -d -p 8008:8008 \ -v ${PWD}/custom:/app/paopao-ce/custom \ - -v ${PWD}/config.yaml.sample:/app/paopao-ce/config.yaml \ + -v ${PWD}/config.yaml:/app/paopao-ce/config.yaml \ bitbus/paopao-ce:latest ``` @@ -130,18 +135,22 @@ docker run -d -p 8010:80 your/paopao-ce:web ### All-in-one 镜像 +运行任一全合一镜像前,请从 `docker/config.yaml` 创建 `config.yaml` 并设置唯一的 `JWT.Secret`。可使用 `openssl rand -hex 32` 生成。 + ```sh # 构建 docker buildx build --build-arg USE_DIST=yes -t your/paopao-ce:all-in-one-latest -f Dockerfile.allinone . # 运行本地镜像 docker run --name paopao-ce-allinone -d -p 8000:8008 -p 7700:7700 \ + -v ${PWD}/config.yaml:/app/config.yaml \ -v ./data/custom:/app/custom \ -v ./data/meili_data:/app/meili_data \ your/paopao-ce:all-in-one-latest # 运行已发布镜像 docker run --name paopao-ce-allinone -d -p 8000:8008 -p 7700:7700 \ + -v ${PWD}/config.yaml:/app/config.yaml \ -v ./data/custom:/app/custom \ -v ./data/meili_data:/app/meili_data \ bitbus/paopao-ce:all-in-one-latest @@ -156,8 +165,8 @@ docker run --name paopao-ce-allinone -d -p 8000:8008 -p 7700:7700 \ ### 后端 1. 按照所选数据库导入对应 SQL 初始化脚本。 -2. 复制配置模板。 -3. 只调整与你环境相关的启动关键配置。 +2. 复制配置模板,将 `JWT.Secret` 设置为 `openssl rand -hex 32` 生成的唯一随机值。 +3. 调整与你环境相关的启动关键配置。 4. 启动或构建后端。 ```sh diff --git a/README.md b/README.md index 434fed47..b0da102c 100644 --- a/README.md +++ b/README.md @@ -93,6 +93,9 @@ This is the fastest way to bring up a local environment for evaluation. ```sh git clone https://github.com/rocboss/paopao-ce.git cd paopao-ce +cp config.yaml.sample config.yaml +openssl rand -hex 32 +# Set JWT.Secret in config.yaml to the generated value. docker compose up -d ``` @@ -116,7 +119,7 @@ Then open: #### Backend 1. Import `scripts/paopao-mysql.sql` into MySQL. -2. Copy the sample config and adjust only the bootstrap-critical values for your environment. +2. Copy the sample config, set `JWT.Secret` to a unique value from `openssl rand -hex 32`, and adjust the bootstrap-critical values for your environment. 3. Start the backend. ```sh diff --git a/README_ZH.md b/README_ZH.md index 4e9d9a58..b204737b 100644 --- a/README_ZH.md +++ b/README_ZH.md @@ -93,6 +93,9 @@ PaoPao 是一个完整的开源微社区系统,包含 Go 后端、Vue 3 Web ```sh git clone https://github.com/rocboss/paopao-ce.git cd paopao-ce +cp config.yaml.sample config.yaml +openssl rand -hex 32 +# 将生成的值填入 config.yaml 的 JWT.Secret。 docker compose up -d ``` @@ -116,7 +119,7 @@ docker compose up -d #### 后端 1. 将 `scripts/paopao-mysql.sql` 导入 MySQL。 -2. 复制示例配置,并只调整与你环境相关的启动关键项。 +2. 复制示例配置,将 `JWT.Secret` 设置为 `openssl rand -hex 32` 生成的唯一随机值,并调整与你环境相关的启动关键项。 3. 启动后端服务。 ```sh diff --git a/config.yaml.sample b/config.yaml.sample index f5fdb19e..61052367 100644 --- a/config.yaml.sample +++ b/config.yaml.sample @@ -36,7 +36,7 @@ Redis: - redis:6379 JWT: - Secret: 18a6413dc4fe394c66345ebe501b2f26 + Secret: "" Issuer: paopao-api Expire: 86400 diff --git a/docker-compose.yaml b/docker-compose.yaml index 7135f52c..04f63fe1 100644 --- a/docker-compose.yaml +++ b/docker-compose.yaml @@ -132,7 +132,7 @@ services: - meili # modify below to reflect your custom configure volumes: - - ./config.yaml.sample:/app/paopao-ce/config.yaml + - ./config.yaml:/app/paopao-ce/config.yaml - ./custom:/app/paopao-ce/custom ports: - 8008:8008 diff --git a/docker/config.yaml b/docker/config.yaml index 3253f32b..fc9c65c6 100644 --- a/docker/config.yaml +++ b/docker/config.yaml @@ -31,7 +31,7 @@ Redis: - 127.0.0.1:6379 JWT: - Secret: 18a6413dc4fe394c66345ebe501b2f26 + Secret: "" Issuer: paopao-api Expire: 86400 diff --git a/docs/deploy/core/001-配置文件说明.md b/docs/deploy/core/001-配置文件说明.md index 29282f01..c5b13a29 100644 --- a/docs/deploy/core/001-配置文件说明.md +++ b/docs/deploy/core/001-配置文件说明.md @@ -3,7 +3,8 @@ paopao-ce使用YAML格式的`conf.yml`作为配置文件。[`config.yaml.sample` ```sh cp config.yaml.sample config.yaml -vim config.yaml # 修改参数 +openssl rand -hex 32 # 生成唯一 JWT.Secret 并填入 config.yaml +vim config.yaml # 修改其他参数 paopao-ce ```