Baseline: pr1 HYC下载站 v2.3 before security/functional fixes

This commit is contained in:
HYC Fixer
2026-08-30 12:12:58 +08:00
commit a8e773839b
77 changed files with 38568 additions and 0 deletions
+25
View File
@@ -0,0 +1,25 @@
# ============================================
# HYC下载站 v2.2 - 环境变量配置示例
# ============================================
# 数据路径
DATA_PATH=./data
DOWNLOADS_PATH=./downloads
DB_PATH=./postgres
# 数据库配置
DB_TYPE=postgresql
DB_HOST=hyc-db
DB_PORT=5432
DB_NAME=hyc
DB_USER=postgres
DB_PASS=your_password_here
# 外部数据库连接 (可选,覆盖上述配置)
# DB_CONN_STR=postgresql://user:pass@host:5432/database
# Redis (可选)
REDIS_PATH=./redis
# 时区
TZ=Asia/Shanghai
+73
View File
@@ -0,0 +1,73 @@
# ============================================
# HYC下载站 v2.2 - Docker 构建配置
# ============================================
# 构建阶段
FROM python:3.11-slim AS builder
WORKDIR /app
# 安装构建依赖
RUN apt-get update && apt-get install -y --no-install-recommends \
gcc \
musl-dev \
libffi-dev \
libssl-dev \
&& rm -rf /var/lib/apt/lists/*
# 安装 Python 依赖
COPY requirements.txt .
RUN pip install --no-cache-dir --prefix=/install -r requirements.txt
# ============================================
# 运行阶段
FROM python:3.11-slim
LABEL maintainer="HYC Download Station"
LABEL description="HYC下载站 v2.2 - 镜像文件服务器 + 下载加速源"
# 环境变量
ENV PYTHONDONTWRITEBYTECODE=1
ENV PYTHONUNBUFFERED=1
ENV HYC_HOME=/app
# 创建工作目录
WORKDIR ${HYC_HOME}
# 复制 Python 和依赖
COPY --from=builder /install /usr/local
# 复制应用代码
COPY main.py .
COPY settings.json .
COPY requirements.txt .
COPY core/ ./core/
COPY api/ ./api/
COPY handlers/ ./handlers/
COPY mirrors/ ./mirrors/
COPY scripts/ ./scripts/
# 创建数据目录
RUN mkdir -p \
/data \
/downloads \
&& chown -R nobody:nogroup /data /downloads
# 设置工作用户
USER nobody
# 挂载卷
VOLUME ["/data", "/downloads"]
# 暴露端口
EXPOSE 8080
# 健康检查
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:8080/api/v1/health')" || exit 1
# 启动命令
CMD ["python", "main.py", \
"--host", "0.0.0.0", \
"--port", "8080", \
"--base-dir", "/downloads"]
+87
View File
@@ -0,0 +1,87 @@
# ============================================
# HYC下载站 v2.2 - 轻量级镜像 (X86_32/ARMv7)
# 适用于低端设备: 2CPU/1G 内存
# ============================================
# 使用 Alpine Linux 作为基础镜像 (极简)
FROM alpine:3.19 AS builder
# 安装 Python 和构建工具
RUN apk add --no-cache \
python3 \
py3-pip \
gcc \
musl-dev \
libffi-dev \
openssl-dev \
cargo \
rust
# 创建虚拟环境
ENV VENV=/opt/venv
RUN python3 -m venv $VENV
ENV PATH="$VENV/bin:$PATH"
# 安装依赖 (使用 --no-cache-dir 减少体积)
COPY requirements.txt /tmp/requirements.txt
RUN pip install --no-cache-dir -r /tmp/requirements.txt
# ============================================
# 运行阶段 - 极简镜像
# ============================================
FROM alpine:3.19
# 安装最小运行时依赖
RUN apk add --no-cache \
python3 \
libffi \
openssl \
libstdc++ \
tzdata \
&& ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime \
&& echo "Asia/Shanghai" > /etc/timezone
# 创建非 root 用户
RUN adduser -D -s /bin/sh hyc
# 设置工作目录
WORKDIR /app
# 从构建阶段复制虚拟环境
COPY --from=builder /opt/venv /opt/venv
ENV PATH="/opt/venv/bin:$PATH"
# 复制应用代码
COPY --chown=hyc:hyc main.py .
COPY --chown=hyc:hyc core/ ./core/
COPY --chown=hyc:hyc api/ ./api/
COPY --chown=hyc:hyc handlers/ ./handlers/
COPY --chown=hyc:hyc mirrors/ ./mirrors/
# 创建数据目录
RUN mkdir -p /data /downloads && chown -R hyc:hyc /data /downloads
# 设置用户
USER hyc
# 挂载卷
VOLUME ["/data", "/downloads"]
# 暴露端口
EXPOSE 8080
# 健康检查
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:8080/api/v1/health')" || exit 1
# 启动命令 (使用虚拟环境中的 Python)
CMD ["python", "main.py", \
"--host", "0.0.0.0", \
"--port", "8080", \
"--base-dir", "/downloads", \
"--config", "/data/config.json", \
"--memory-limit", "512M"]
# 镜像元数据
LABEL maintainer="HYC Download Station"
LABEL description="HYC下载站 v2.2 - 轻量级版本"
+125
View File
@@ -0,0 +1,125 @@
# ============================================
# HYC下载站 v2.2 - 多架构交叉编译 Dockerfile
# 支持: amd64, arm64, arm/v7, i386
# 使用: docker buildx build --platform linux/amd64,linux/arm64,linux/arm/v7 -t hyc:v2.2 .
# ============================================
# ============================================
# 构建阶段 - 所有架构通用
# ============================================
FROM python:3.11-alpine AS builder
# 安装构建依赖 (按架构)
ARG TARGETARCH
RUN case "$TARGETARCH" in \
amd64|x86_64) ARCH_OPTS="-march=x86-64" ;; \
arm64|aarch64) ARCH_OPTS="-march=armv8-a" ;; \
armv7|arm) ARCH_OPTS="-march=armv7-a" ;; \
i386|i686) ARCH_OPTS="-march=i686" ;; \
*) ARCH_OPTS="-march=native" ;; \
esac && \
apk add --no-cache \
python3 \
py3-pip \
gcc \
musl-dev \
libffi-dev \
openssl-dev \
cargo \
rust
# 创建优化编译的虚拟环境
ENV VENV=/opt/venv
ENV CFLAGS="$ARCH_OPTS"
ENV CXXFLAGS="$ARCH_OPTS"
ENV LDFLAGS="-Wl,-O1,--sort-common,--as-needed,-z,relro,-z,now"
RUN python3 -m venv $VENV && \
$VENV/bin/pip install --upgrade pip wheel
# 安装依赖
COPY requirements.txt /tmp/requirements.txt
RUN $VENV/bin/pip install --no-cache-dir \
--platform manylinux2014_${TARGETARCH} \
--only-binary=:all: \
-r /tmp/requirements.txt 2>/dev/null || \
$VENV/bin/pip install --no-cache-dir -r /tmp/requirements.txt
# ============================================
# 运行阶段 - 按架构选择基础镜像
# ============================================
# amd64
FROM --platform=$TARGETOS/$TARGETARCH alpine:3.19 AS runner-amd64
COPY --from=builder /opt/venv /opt/venv
COPY --from=builder /app /app
CMD ["/opt/venv/bin/python", "/app/main.py"]
# arm64
FROM --platform=$TARGETOS/$TARGETARCH alpine:3.19 AS runner-arm64
COPY --from=builder /opt/venv /opt/venv
COPY --from=builder /app /app
CMD ["/opt/venv/bin/python", "/app/main.py"]
# arm/v7
FROM --platform=$TARGETOS/$TARGETARCH alpine:3.19 AS runner-armv7
COPY --from=builder /opt/venv /opt/venv
COPY --from=builder /app /app
CMD ["/opt/venv/bin/python", "/app/main.py"]
# i386
FROM --platform=$TARGETOS/$TARGETARCH alpine:3.19 AS runner-i386
COPY --from=builder /opt/venv /opt/venv
COPY --from=builder /app /app
CMD ["/opt/venv/bin/python", "/app/main.py"]
# ============================================
# 最终清单镜像
# ============================================
FROM --platform=$TARGETOS/$TARGETARCH alpine:3.19 AS final
# 安装运行时依赖
RUN apk add --no-cache \
libffi \
openssl \
libstdc++ \
tzdata \
&& ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime \
&& echo "Asia/Shanghai" > /etc/timezone
# 创建用户
RUN adduser -D -s /bin/sh hyc
# 复制虚拟环境
COPY --from=builder --chown=hyc:hyc /opt/venv /opt/venv
ENV PATH="/opt/venv/bin:$PATH"
# 复制应用
COPY --chown=hyc:hyc main.py .
COPY --chown=hyc:hyc settings.json .
COPY --chown=hyc:hyc requirements.txt .
COPY --chown=hyc:hyc core/ ./core/
COPY --chown=hyc:hyc api/ ./api/
COPY --chown=hyc:hyc handlers/ ./handlers/
COPY --chown=hyc:hyc mirrors/ ./mirrors/
COPY --chown=hyc:hyc scripts/ ./scripts/
# 创建数据目录
RUN mkdir -p /data /downloads && chown -R hyc:hyc /data /downloads
USER hyc
VOLUME ["/data", "/downloads"]
EXPOSE 8080
# 低内存模式
ENV HYC_LOW_MEMORY=1
ENV HYC_WORKERS=1
ENV PYTHONOPTIMIZE=2
ENV PYTHONDONTWRITEBYTECODE=1
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:8080/api/v1/health')" || exit 1
CMD ["python", "main.py", \
"--host", "0.0.0.0", \
"--port", "8080", \
"--memory-limit", "256M"]
+27
View File
@@ -0,0 +1,27 @@
# ============================================
# PyInstaller 多架构构建镜像
# ============================================
FROM python:3.11 AS builder
WORKDIR /app
# 安装构建依赖
RUN apt-get update && apt-get install -y --no-install-recommends \
gcc \
g++ \
musl-dev \
libffi-dev \
libssl-dev \
&& rm -rf /var/lib/apt/lists/*
# 复制整个项目
COPY . .
# 安装 PyInstaller 和项目依赖
RUN pip install --no-cache-dir pyinstaller -r requirements.txt
# 构建可执行文件(使用 .spec 文件生成单文件)
RUN pyinstaller pyinstaller.spec
FROM scratch
COPY --from=builder /app/dist/hyc-download /
+52
View File
@@ -0,0 +1,52 @@
# ============================================
# HYC下载站 v2.3 - 轻量级 Docker Compose
# 适用于: Raspberry Pi, 2CPU/1G 设备
# ============================================
services:
# 轻量级应用服务
hyc-server:
build:
context: ..
dockerfile: docker/Dockerfile.lite
container_name: hyc-download-server
hostname: hyc-server
restart: unless-stopped
ports:
- "8080:8080"
environment:
- TZ=Asia/Shanghai
# 低端设备优化
- PRESET=ultra_low
- PYTHONOPTIMIZE=2
- HYC_LOW_MEMORY=1
volumes:
- ${DATA_PATH:-./data}:/data
- ${DOWNLOADS_PATH:-./downloads}:/downloads
deploy:
resources:
limits:
# 内存限制
memory: 512M
cpus: '1.0'
reservations:
memory: 256M
cpus: '0.5'
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://localhost:8080/api/v1/health')"]
interval: 30s
timeout: 10s
retries: 3
start_period: 10s
labels:
- "com.hyc.version=2.2"
- "com.hyc.preset=ultra_low"
networks:
default:
driver: bridge
volumes:
data:
downloads:
caches:
+57
View File
@@ -0,0 +1,57 @@
# ============================================
# HYC下载站 v2.3 - 树莓派专用配置
# 适用于: Raspberry Pi 3/4/5 (ARMv7/Arm64)
# ============================================
services:
# ARM 优化版本
hyc-server:
# 使用 ARM 专用镜像
image: ${REGISTRY:-hyc-download-station}:${TAG:-v2.3}-arm64
container_name: hyc-download-server
hostname: hyc-server
restart: unless-stopped
privileged: true # 树莓派可能需要
ports:
- "8080:8080"
environment:
- TZ=Asia/Shanghai
# 树莓派优化
- PRESET=low
- PYTHONOPTIMIZE=2
- HYC_LOW_MEMORY=1
# ARM 优化
- PYTHONCPUCOUNT=2
volumes:
- ${DATA_PATH:-./data}:/data
- ${DOWNLOADS_PATH:-./downloads}:/downloads
deploy:
resources:
limits:
# Raspberry Pi 4: 4GB RAM
memory: 1G
cpus: '2.0'
reservations:
memory: 512M
cpus: '1.0'
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://localhost:8080/api/v1/health')"]
interval: 30s
timeout: 10s
retries: 3
labels:
- "com.hyc.platform=raspberry-pi"
- "com.hyc.arch=arm64"
# 温度监控 (树莓派专用)
devices:
- /sys/class/thermal/thermal_zone0:/sys/class/thermal/thermal_zone0
networks:
default:
driver: bridge
volumes:
data:
downloads:
caches:
+87
View File
@@ -0,0 +1,87 @@
# ============================================
# HYC下载站 v2.3 - Docker Compose 配置
# ============================================
services:
# 主应用服务
hyc-server:
build:
context: ..
dockerfile: docker/Dockerfile
container_name: hyc-download-server
hostname: hyc-server
restart: unless-stopped
ports:
- "8080:8080"
environment:
- TZ=Asia/Shanghai
# 数据库配置
- DB_TYPE=${DB_TYPE:-sqlite}
- DB_PATH=/data/hyc.db
# PostgreSQL (可选)
- DB_HOST=${DB_HOST:-}
- DB_PORT=${DB_PORT:-5432}
- DB_NAME=${DB_NAME:-hyc}
- DB_USER=${DB_USER:-postgres}
- DB_PASS=${DB_PASS:-}
# 外部数据库连接 (可选)
- DB_CONN_STR=${DB_CONN_STR:-}
volumes:
- ${DATA_PATH:-./data}:/data
- ${DOWNLOADS_PATH:-./downloads}:/downloads
networks:
- hyc-network
healthcheck:
test: ["CMD", "python", "-c", "import urllib.request; urllib.request.urlopen('http://localhost:8080/api/v1/health')"]
interval: 30s
timeout: 10s
retries: 3
labels:
- "com.hyc.version=2.2"
# PostgreSQL 数据库 (可选)
hyc-db:
image: postgres:15-alpine
container_name: hyc-postgres
restart: unless-stopped
environment:
- POSTGRES_DB=${DB_NAME:-hyc}
- POSTGRES_USER=${DB_USER:-postgres}
- POSTGRES_PASSWORD=${DB_PASS:-postgres}
- TZ=Asia/Shanghai
volumes:
- ${DB_PATH:-./postgres}:/var/lib/postgresql/data
networks:
- hyc-network
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${DB_USER:-postgres} -d ${DB_NAME:-hyc}"]
interval: 30s
timeout: 10s
retries: 3
# Redis 缓存 (可选,用于速率限制)
redis:
image: redis:7-alpine
container_name: hyc-redis
restart: unless-stopped
command: redis-server --appendonly yes
volumes:
- ${REDIS_PATH:-./redis}:/data
networks:
- hyc-network
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 30s
timeout: 10s
retries: 3
networks:
hyc-network:
driver: bridge
volumes:
data:
downloads:
caches:
postgres:
redis: