Files
admin-go/manifest/config/config.yaml
T
19904408334 9312c159a2 feat(login): 增加登录 IP 地区闸门限制
基于 config.yaml 的 loginIpFilter 配置,仅允许中国大陆网段、内部保留地址及 allowIps 中的 IP 登录,拒绝境外 IP,并新增不可伪造的 GetRealClientIP 获取客户端真实 IP。
2026-09-04 17:29:35 +08:00

120 lines
4.1 KiB
YAML

server:
name: "admin-go"
address: ":8808"
serverRoot: "resource/public"
dumpRouterMap: false
routeOverWrite: true
openapiPath: "/api.json"
swaggerPath: "/swagger"
NameToUriType: 3
maxHeaderBytes: "20KB"
clientMaxBodySize: "50MB"
# Logging配置
logPath: "resource/log/server" # 日志文件存储目录路径,建议使用绝对路径。默认为空,表示关闭
logStdout: true # 日志是否输出到终端。默认为true
errorStack: true # 当Server捕获到异常时是否记录堆栈信息到日志中。默认为true
errorLogEnabled: true # 是否记录异常日志信息到日志中。默认为true
errorLogPattern: "error-{Ymd}.log" # 异常错误日志文件格式。默认为"error-{Ymd}.log"
accessLogEnabled: true # 是否记录访问日志。默认为false
accessLogPattern: "access-{Ymd}.log" # 访问日志文件格式。默认为"access-{Ymd}.log"
logger:
path: "resource/log/run"
file: "{Y-m-d}.log"
level: "all"
stdout: true
# Database.
database:
default:
- type: "pgsql"
host: "192.168.0.83"
port: "15432"
user: "sql9f15b63fd203b36e"
pass: "1ec94b1acdaf57b66030242d418fad5a"
name: "admin"
role: "master"
maxIdle: "5"
maxOpen: "20"
maxLifetime: "60s"
charset : "utf8mb4" #数据库编码
debug : true
dryRun : false #空跑
- type: "pgsql"
host: "192.168.0.83"
port: "15432"
user: "sql9f15b63fd203b36e"
pass: "1ec94b1acdaf57b66030242d418fad5a"
name: "admin"
role: "slave"
maxIdle: "5"
maxOpen: "20"
maxLifetime: "60s"
charset: "utf8mb4" #数据库编码
debug: true
dryRun: false #空跑
gfToken:
cacheKey: "gfToken:"
timeOut: 10800
maxRefresh: 5400
multiLogin: true
encryptKey: "5ace42cd685d42cf934ef519ea27f7d7" #49c54195e750b04e74a8429b17896586
cacheModel: "redis" #缓存模式 memory OR redis OR dist
distPath: "./resource/data/distTokenDb" #使用磁盘缓存时配置数据缓存的目录
excludePaths:
- "/api/v1/system/login"
# 登录 IP 地区闸门: 开启后仅允许「中国大陆网段 / 内部·保留地址 / allowIps」的 IP 登录,
# 国外 IP 一律拒绝。enabled 置 false 可整体关闭(紧急恢复), 不影响已登录会话。
loginIpFilter:
enabled: true
allowIps: [] # 显式放行 IP(不受地区限制), 如办公网/跳板出口公网 IP
denyMsg: "当前网络环境不允许登录"
# Redis 配置示例
redis:
# 单实例配置
default:
address: 192.168.0.83:6379
db: 1
idleTimeout: "60s" #连接最大空闲时间,使用时间字符串例如30s/1m/1d
maxConnLifetime: "90s" #连接最长存活时间,使用时间字符串例如30s/1m/1d
waitTimeout: "60s" #等待连接池连接的超时时间,使用时间字符串例如30s/1m/1d
dialTimeout: "30s" #TCP连接的超时时间,使用时间字符串例如30s/1m/1d
readTimeout: "30s" #TCP的Read操作超时时间,使用时间字符串例如30s/1m/1d
writeTimeout: "30s" #TCP的Write操作超时时间,使用时间字符串例如30s/1m/1d
maxActive: 100
system:
notCheckAuthAdminIds: [1] #无需验证后台权限的用户id
dataDir: "./resource/data"
cache:
model: "redis" #缓存模式 memory OR redis OR dist
distPath: "./resource/data/distCacheDb" #使用磁盘缓存时配置数据缓存的目录
prefix: "gFastV3Cache:" #缓存前缀
#casbin配置
casbin:
modelFile: "./resource/casbin/rbac_model.conf"
policyFile: "./resource/casbin/rbac_policy.csv"
# CLI.
gfcli:
gen:
dao:
- link: "mysql:gfast3:gfast333@tcp(192.168.0.212:3306)/gfast-v32"
tables: "tools_gen_table,tools_gen_table_column"
removePrefix: "gf_"
descriptionTag: true
noModelComment: true
path: "./internal/app/system"
# 文件上传服务地址,与oss模块minio中的endpoint(filePrefix需要加http://)一致
filePrefix: "http://192.168.0.83:9000"
consul:
address: 192.168.0.83:8500
jaeger: #链路追踪
addr: 192.168.0.83:4318