ailien-uat.aliyun-ecs.conf 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430
  1. # ============================================================
  2. # UAT 完整配置:uat.ailien.shop(443 + 80 跳转)
  3. # 仓库路径:alien_cloud/docs/nginx/conf.d/temp/ailien-uat.aliyun-ecs.conf
  4. #
  5. # 【部署说明】
  6. # - 本文件在 conf.d/temp/ 下,不会被主配置 include conf.d/*.conf 自动加载。
  7. # - 上线:复制或软链到 Nginx 宿主机,例如:
  8. # cp docs/nginx/conf.d/temp/ailien-uat.aliyun-ecs.conf /alien_prod/nginx/conf.d/ailien-uat.conf
  9. # - 依赖同目录上级:conf.d/00-common.conf(limit_req_zone payment_prepay、map $cors_origin)
  10. # - 片段:conf.d/temp/ailien-uat.inc.temp-tus-upload-verify-locations.conf(/files、/upload、/verify)
  11. #
  12. # 【路由分工】(与 upaibm_system Python 网关、Java alien-gateway 一致)
  13. # /ai/、/ai/ws → uat_ai_service(H100 upaibm gateway,UAT 端口 9300,勿用 30019)
  14. # /api/、/ → uat_gateway(alien-gateway,ECS 私网 IP + 宿主机映射端口)
  15. # /alienStore/ 等 → 可直连 store/second/dining,降低网关单点故障影响
  16. #
  17. # 【upstream 核对】部署前在 Nginx 容器/宿主机执行 docker ps,对照宿主机 PORTS 修改下方 IP:端口。
  18. # - 阿里云 ECS 私网示例:172.23.9.202(勿用公网 EIP 作 upstream,易 upstream timed out)
  19. # - AI 网关(upaibm):192.168.2.250:9300(见 upaibm_system gateway_service/.env.uat)
  20. # ============================================================
  21. # 阿里云 ECS:Java 微服务与 alien-gateway(VPC 私网 IP)
  22. upstream uat_gateway {
  23. server 172.23.9.202:8001;
  24. # server 172.23.9.202:18000; # 若 compose 映射为 18000→容器 8000,改为此行并注释上一行
  25. keepalive 32;
  26. }
  27. upstream uat_store {
  28. server 172.23.9.202:30014;
  29. # server 172.23.9.202:13004; # 部分 compose:13004→容器 30004
  30. keepalive 8;
  31. }
  32. upstream uat_second {
  33. server 172.23.9.202:30015;
  34. # server 172.23.9.202:13005; # 部分 compose:13005→容器 30005
  35. keepalive 8;
  36. }
  37. upstream uat_dining {
  38. server 172.23.9.202:30019;
  39. # server 39.106.135.88:30019; # dining 若在其它机器,改为实际 IP:端口
  40. keepalive 8;
  41. }
  42. # 预生产 AI(upaibm_system gateway_service,Consul + /ai/{service}/...)
  43. upstream uat_ai_service {
  44. server 39.106.135.88:9300;
  45. # server 172.23.9.202:9300; # 若 AI 网关与 Java 同机且映射 9300,可改为此行
  46. keepalive 32;
  47. }
  48. # 本机 upload 栈 nginx-gateway(docker-compose: 0.0.0.0:40007->80)
  49. upstream uat_upload_stack {
  50. server 127.0.0.1:40007;
  51. keepalive 8;
  52. }
  53. # 商户端 Tus/简单上传:同源 /ai-upload/ → 回环本 server 443(对齐 VITE_PROXY /ai-upload)
  54. upstream upl_ai_upload {
  55. server uat.ailien.shop:443;
  56. keepalive 8;
  57. }
  58. # --------------- UAT:https://uat.ailien.shop (443) ---------------
  59. server {
  60. listen 443 ssl;
  61. http2 on;
  62. server_name uat.ailien.shop;
  63. ssl_certificate /etc/nginx/ssl/ailien.shop.pem;
  64. ssl_certificate_key /etc/nginx/ssl/ailien.shop.key;
  65. ssl_session_timeout 1d;
  66. ssl_protocols TLSv1.2 TLSv1.3;
  67. ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;
  68. access_log /var/log/nginx/uat/uat.ailien.shop.access.log main;
  69. error_log /var/log/nginx/uat/uat.ailien.shop.error.log warn;
  70. # 微信公众号 JS 接口安全域名校验(须在 location / 及网关代理之前)
  71. # 后台填写:uat.ailien.shop 磁盘:/cert/MP_verify_u6feCTxr5iTTBeIx.txt
  72. location = /MP_verify_u6feCTxr5iTTBeIx.txt {
  73. alias /cert/MP_verify_u6feCTxr5iTTBeIx.txt;
  74. default_type text/plain;
  75. add_header Content-Type "text/plain; charset=utf-8";
  76. }
  77. # 商户端前端:https://uat.ailien.shop/group_web_merchant/
  78. location /group_web_merchant/ {
  79. root /alien_uat/nginx/html;
  80. index index.html;
  81. try_files $uri $uri/ @uat_merchant_spa;
  82. }
  83. location @uat_merchant_spa {
  84. root /alien_uat/nginx/html;
  85. try_files /group_web_merchant/index.html =404;
  86. }
  87. location = /group_web_merchant {
  88. return 301 $scheme://$host/group_web_merchant/;
  89. }
  90. # GroupWeb:https://uat.ailien.shop/group_web/ 中台
  91. location /group_web/ {
  92. root /alien_uat/nginx/html;
  93. index index.html;
  94. try_files $uri $uri/ @uat_group_spa;
  95. }
  96. location @uat_group_spa {
  97. root /alien_uat/nginx/html;
  98. try_files /group_web/index.html =404;
  99. }
  100. location = /group_web {
  101. return 301 $scheme://$host/group_web/;
  102. }
  103. # GroupLawyerWeb:https://uat.ailien.shop/group_lawyer_web/
  104. location /group_lawyer_web/ {
  105. root /alien_uat/nginx/html;
  106. index index.html;
  107. try_files $uri $uri/ @uat_lawyer_spa;
  108. }
  109. location @uat_lawyer_spa {
  110. root /alien_uat/nginx/html;
  111. try_files /group_lawyer_web/index.html =404;
  112. }
  113. location = /group_lawyer_web {
  114. return 301 $scheme://$host/group_lawyer_web/;
  115. }
  116. # HBuilder 分享页等:勿走网关,否则 Spring Whitelabel 404。须写在 location / 之前。
  117. location ^~ /h5/HBuilderProjects/ {
  118. root /alien_uat/nginx/html;
  119. try_files $uri =404;
  120. add_header Cache-Control "public, max-age=300";
  121. }
  122. # AI WebSocket(wss://uat.ailien.shop/ai/ws/... → upaibm gateway)
  123. location /ai/ws {
  124. proxy_pass http://uat_ai_service;
  125. proxy_http_version 1.1;
  126. proxy_set_header Upgrade $http_upgrade;
  127. proxy_set_header Connection $connection_upgrade;
  128. proxy_set_header Host $host;
  129. proxy_set_header X-Real-IP $remote_addr;
  130. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  131. proxy_set_header X-Forwarded-Proto $scheme;
  132. proxy_connect_timeout 60s;
  133. proxy_send_timeout 3600s;
  134. proxy_read_timeout 3600s;
  135. }
  136. # AI HTTP(/ai/life-manager/... 等,upaibm Python 微服务)
  137. location /ai/ {
  138. if ($request_method = 'OPTIONS') {
  139. add_header 'Access-Control-Allow-Origin' $cors_origin;
  140. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  141. add_header 'Access-Control-Allow-Headers' '*';
  142. add_header 'Access-Control-Allow-Credentials' 'true';
  143. add_header 'Access-Control-Max-Age' 3600;
  144. add_header 'Content-Length' 0;
  145. return 204;
  146. }
  147. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  148. add_header 'Access-Control-Allow-Credentials' 'true' always;
  149. proxy_pass http://uat_ai_service;
  150. proxy_http_version 1.1;
  151. proxy_set_header Host $host;
  152. proxy_set_header X-Real-IP $remote_addr;
  153. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  154. proxy_set_header X-Forwarded-Proto $scheme;
  155. proxy_connect_timeout 60s;
  156. proxy_send_timeout 300s;
  157. proxy_read_timeout 300s;
  158. }
  159. # WebSocket 直连 alien-store:/alienStore/socket/xxx → /socket/xxx
  160. location /alienStore/socket/ {
  161. rewrite ^/alienStore/socket/(.*)$ /socket/$1 break;
  162. proxy_pass http://uat_store;
  163. proxy_http_version 1.1;
  164. proxy_set_header Upgrade $http_upgrade;
  165. proxy_set_header Connection $connection_upgrade;
  166. proxy_set_header Host $host;
  167. proxy_set_header X-Real-IP $remote_addr;
  168. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  169. proxy_set_header X-Forwarded-Proto $scheme;
  170. proxy_connect_timeout 60s;
  171. proxy_send_timeout 3600s;
  172. proxy_read_timeout 3600s;
  173. }
  174. # HTTP 直连 alien-store(网关故障时 App 仍可访问 store API)
  175. location /alienStore/ {
  176. if ($request_method = 'OPTIONS') {
  177. add_header 'Access-Control-Allow-Origin' $cors_origin;
  178. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  179. add_header 'Access-Control-Allow-Headers' '*';
  180. add_header 'Access-Control-Allow-Credentials' 'true';
  181. add_header 'Access-Control-Max-Age' 3600;
  182. add_header 'Content-Length' 0;
  183. return 204;
  184. }
  185. proxy_hide_header Access-Control-Allow-Origin;
  186. proxy_hide_header Access-Control-Allow-Credentials;
  187. proxy_hide_header Access-Control-Allow-Methods;
  188. proxy_hide_header Access-Control-Allow-Headers;
  189. proxy_hide_header Access-Control-Expose-Headers;
  190. proxy_hide_header Access-Control-Max-Age;
  191. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  192. add_header 'Access-Control-Allow-Credentials' 'true' always;
  193. add_header Vary Origin always;
  194. proxy_pass http://uat_store;
  195. proxy_http_version 1.1;
  196. proxy_set_header Host $host;
  197. proxy_set_header X-Real-IP $remote_addr;
  198. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  199. proxy_set_header X-Forwarded-Proto $scheme;
  200. proxy_set_header Upgrade $http_upgrade;
  201. proxy_set_header Connection $connection_upgrade;
  202. proxy_connect_timeout 60s;
  203. proxy_send_timeout 3600s;
  204. proxy_read_timeout 3600s;
  205. }
  206. # HTTP 直连 alien-second
  207. location /alienSecond/ {
  208. if ($request_method = 'OPTIONS') {
  209. add_header 'Access-Control-Allow-Origin' $cors_origin;
  210. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  211. add_header 'Access-Control-Allow-Headers' '*';
  212. add_header 'Access-Control-Allow-Credentials' 'true';
  213. add_header 'Access-Control-Max-Age' 3600;
  214. add_header 'Content-Length' 0;
  215. return 204;
  216. }
  217. proxy_hide_header Access-Control-Allow-Origin;
  218. proxy_hide_header Access-Control-Allow-Credentials;
  219. proxy_hide_header Access-Control-Allow-Methods;
  220. proxy_hide_header Access-Control-Allow-Headers;
  221. proxy_hide_header Access-Control-Expose-Headers;
  222. proxy_hide_header Access-Control-Max-Age;
  223. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  224. add_header 'Access-Control-Allow-Credentials' 'true' always;
  225. add_header Vary Origin always;
  226. proxy_pass http://uat_second;
  227. proxy_http_version 1.1;
  228. proxy_set_header Host $host;
  229. proxy_set_header X-Real-IP $remote_addr;
  230. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  231. proxy_set_header X-Forwarded-Proto $scheme;
  232. proxy_set_header Upgrade $http_upgrade;
  233. proxy_set_header Connection $connection_upgrade;
  234. proxy_connect_timeout 60s;
  235. proxy_send_timeout 3600s;
  236. proxy_read_timeout 3600s;
  237. }
  238. # 点餐 SSE 长连接:直连 alien-dining
  239. location /alienDining/store/order/sse/ {
  240. rewrite ^/alienDining/(.*)$ /$1 break;
  241. proxy_pass http://uat_dining;
  242. proxy_http_version 1.1;
  243. proxy_set_header Host $host;
  244. proxy_set_header X-Real-IP $remote_addr;
  245. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  246. proxy_set_header X-Forwarded-Proto $scheme;
  247. proxy_connect_timeout 60s;
  248. proxy_send_timeout 86400s;
  249. proxy_read_timeout 86400s;
  250. proxy_buffering off;
  251. }
  252. # 支付预下单限流(依赖 00-common.conf 中 limit_req_zone payment_prepay)
  253. location ~* payment/prePay {
  254. limit_req zone=payment_prepay burst=1 nodelay;
  255. limit_req_status 429;
  256. add_header X-Payment-Limit "applied" always;
  257. rewrite ^/api/(.*)$ /$1 break;
  258. proxy_pass http://uat_gateway;
  259. proxy_http_version 1.1;
  260. proxy_set_header Host $host;
  261. proxy_set_header X-Real-IP $remote_addr;
  262. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  263. proxy_set_header X-Forwarded-Proto $scheme;
  264. proxy_set_header Upgrade $http_upgrade;
  265. proxy_set_header Connection $connection_upgrade;
  266. proxy_connect_timeout 60s;
  267. proxy_send_timeout 3600s;
  268. proxy_read_timeout 3600s;
  269. if ($request_method = 'OPTIONS') {
  270. add_header 'Access-Control-Allow-Origin' $cors_origin;
  271. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  272. add_header 'Access-Control-Allow-Headers' '*';
  273. add_header 'Access-Control-Allow-Credentials' 'true';
  274. add_header 'Access-Control-Max-Age' 3600;
  275. add_header 'Content-Length' 0;
  276. return 204;
  277. }
  278. proxy_hide_header Access-Control-Allow-Origin;
  279. proxy_hide_header Access-Control-Allow-Credentials;
  280. proxy_hide_header Access-Control-Allow-Methods;
  281. proxy_hide_header Access-Control-Allow-Headers;
  282. proxy_hide_header Access-Control-Expose-Headers;
  283. proxy_hide_header Access-Control-Max-Age;
  284. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  285. add_header 'Access-Control-Allow-Credentials' 'true' always;
  286. add_header Vary Origin always;
  287. }
  288. # /api/xxx → 去前缀后转发 Java alien-gateway
  289. location /api/ {
  290. rewrite ^/api/(.*)$ /$1 break;
  291. proxy_pass http://uat_gateway;
  292. proxy_http_version 1.1;
  293. proxy_set_header Host $host;
  294. proxy_set_header X-Real-IP $remote_addr;
  295. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  296. proxy_set_header X-Forwarded-Proto $scheme;
  297. proxy_set_header Upgrade $http_upgrade;
  298. proxy_set_header Connection $connection_upgrade;
  299. proxy_connect_timeout 60s;
  300. proxy_send_timeout 3600s;
  301. proxy_read_timeout 3600s;
  302. if ($request_method = 'OPTIONS') {
  303. add_header 'Access-Control-Allow-Origin' $cors_origin;
  304. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  305. add_header 'Access-Control-Allow-Headers' '*';
  306. add_header 'Access-Control-Allow-Credentials' 'true';
  307. add_header 'Access-Control-Max-Age' 3600;
  308. add_header 'Content-Length' 0;
  309. return 204;
  310. }
  311. proxy_hide_header Access-Control-Allow-Origin;
  312. proxy_hide_header Access-Control-Allow-Credentials;
  313. proxy_hide_header Access-Control-Allow-Methods;
  314. proxy_hide_header Access-Control-Allow-Headers;
  315. proxy_hide_header Access-Control-Expose-Headers;
  316. proxy_hide_header Access-Control-Max-Age;
  317. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  318. add_header 'Access-Control-Allow-Credentials' 'true' always;
  319. add_header Vary Origin always;
  320. }
  321. # 静态上传目录(宿主机 /uploads)
  322. location ^~ /uploads/ {
  323. alias /uploads/;
  324. try_files $uri =404;
  325. add_header Cache-Control "public, max-age=86400";
  326. }
  327. # 商户端同源上传代理:/ai-upload/ → https://uat.ailien.shop(去掉 /ai-upload 前缀)
  328. location = /ai-upload {
  329. return 301 $scheme://$host/ai-upload/;
  330. }
  331. location ^~ /ai-upload/ {
  332. rewrite ^/ai-upload(.*)$ $1 break;
  333. proxy_pass https://upl_ai_upload;
  334. proxy_http_version 1.1;
  335. proxy_set_header Connection "";
  336. proxy_ssl_server_name on;
  337. proxy_ssl_name uat.ailien.shop;
  338. proxy_set_header Host uat.ailien.shop;
  339. proxy_set_header X-Real-IP $remote_addr;
  340. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  341. proxy_set_header X-Forwarded-Proto $scheme;
  342. proxy_connect_timeout 60s;
  343. proxy_send_timeout 3600s;
  344. proxy_read_timeout 3600s;
  345. client_max_body_size 0;
  346. proxy_request_buffering off;
  347. }
  348. # Tus /upload /verify(片段与 conf.d/temp/ailien-uat.inc.temp-tus-upload-verify-locations.conf 同步)
  349. include conf.d/temp/ailien-uat.inc.temp-tus-upload-verify-locations.conf;
  350. # 其余请求 → Java alien-gateway
  351. location / {
  352. if ($request_method = 'OPTIONS') {
  353. add_header 'Access-Control-Allow-Origin' $cors_origin;
  354. add_header 'Access-Control-Allow-Methods' 'GET, POST, PUT, DELETE, PATCH, OPTIONS';
  355. add_header 'Access-Control-Allow-Headers' '*';
  356. add_header 'Access-Control-Allow-Credentials' 'true';
  357. add_header 'Access-Control-Max-Age' 3600;
  358. add_header 'Content-Length' 0;
  359. return 204;
  360. }
  361. proxy_hide_header Access-Control-Allow-Origin;
  362. proxy_hide_header Access-Control-Allow-Credentials;
  363. proxy_hide_header Access-Control-Allow-Methods;
  364. proxy_hide_header Access-Control-Allow-Headers;
  365. proxy_hide_header Access-Control-Expose-Headers;
  366. proxy_hide_header Access-Control-Max-Age;
  367. add_header 'Access-Control-Allow-Origin' $cors_origin always;
  368. add_header 'Access-Control-Allow-Credentials' 'true' always;
  369. add_header Vary Origin always;
  370. proxy_pass http://uat_gateway;
  371. proxy_http_version 1.1;
  372. proxy_set_header Upgrade $http_upgrade;
  373. proxy_set_header Connection $connection_upgrade;
  374. proxy_set_header Host $host;
  375. proxy_set_header X-Real-IP $remote_addr;
  376. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  377. proxy_set_header X-Forwarded-Proto $scheme;
  378. proxy_connect_timeout 60s;
  379. proxy_send_timeout 3600s;
  380. proxy_read_timeout 3600s;
  381. }
  382. }
  383. # --------------- UAT:HTTP 80 → HTTPS 443(微信域名校验文件须 HTTP 可访问) ---------------
  384. server {
  385. listen 80;
  386. server_name uat.ailien.shop;
  387. access_log /var/log/nginx/uat/uat.ailien.shop.80.access.log main;
  388. error_log /var/log/nginx/uat/uat.ailien.shop.80.error.log warn;
  389. location = /MP_verify_u6feCTxr5iTTBeIx.txt {
  390. alias /cert/MP_verify_u6feCTxr5iTTBeIx.txt;
  391. default_type text/plain;
  392. add_header Content-Type "text/plain; charset=utf-8";
  393. }
  394. location / {
  395. return 301 https://$host$request_uri;
  396. }
  397. }