<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>72602 :: Ay Docs</title>
    <link>https://ops.docs.72602.space/csp/72602/index.html</link>
    <description>Scope This section is the single source of truth for 72602 cluster operations.&#xA;Topology Public ECS: 47.110.67.161 (2C4G, cn-hangzhou, zone cn-hangzhou-i) Active ingress domain: 72602.space; legacy .72602.online routes are retired ArgoCD host: argocd.72602.space k3s node: 72602-minipc (192.168.0.25, MiniPC N100 28G+1TB NVMe) SSH reverse tunnel: :10021 (main), :10022 (backup and Mailu loopback) Web tunnel: WireGuard UDP 51820 between ECS and minipc Ingress NodePort: 32080 (HTTP), 32443 (HTTPS) Ingress class: nginx Ingress namespace: basic-components cert-manager issuer: lets-encrypt Storage class: local-path (default, RWO) OS: Ubuntu 26.04 LTS (minipc) k3s version: v1.34.6+k3s1 (installed via install.sh) Traffic Path Web:</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 07 Mar 2024 15:00:59 +0800</lastBuildDate>
    <atom:link href="https://ops.docs.72602.space/csp/72602/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Runtime Secret Recovery</title>
      <link>https://ops.docs.72602.space/csp/72602/runtime-secret-recovery/index.html</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://ops.docs.72602.space/csp/72602/runtime-secret-recovery/index.html</guid>
      <description>This runbook documents the narrowly scoped 2026-08-02 recovery of a small, approved whitelist of missing runtime Secrets from a pre-incident k3s etcd snapshot. It does not restore the production cluster, databases, PVC contents, or application data. Do not reuse the old snapshot or whitelist as a generic current recovery recipe: later deployments added dependencies such as sub2api-mcp, and any future recovery must use a newly approved snapshot and an explicitly reviewed object list.</description>
    </item>
    <item>
      <title>ECS Security Group</title>
      <link>https://ops.docs.72602.space/csp/72602/security-group-auto-update/index.html</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://ops.docs.72602.space/csp/72602/security-group-auto-update/index.html</guid>
      <description>安全组 IP 自动更新 背景 72602-minipc 的 ISP 不定期更换公网 IP，而阿里云 ECS (ecs-99) 安全组限制了 SSH 端口只能从特定 IP 访问。&#xA;当公网 IP 变化时：&#xA;SSH 反向隧道断开 无法通过 ssh aaron@47.110.67.161 -p 10022 访问 无法直接 ssh root@47.110.67.161 解决方案 定时检测公网 IP，变化时统一协调两处 consumer：阿里云 ECS 安全组的 TCP 22 / 10021 / 10022 / 3128 / 56396 与 UDP 51820 规则，以及 ECS 本机 UFW 的 51820/udp（comment wg 72602-minipc）与 3128/tcp （comment squid 72602-minipc）规则。所有云端写操作统一从 72602-minipc 上的同一个 5 分钟 systemd timer 发起；ECS 上只放一个最小化、root-only 的 forced-command 助手负责 UFW 这一侧。</description>
    </item>
    <item>
      <title>Network Tunnels</title>
      <link>https://ops.docs.72602.space/csp/72602/tunnel/index.html</link>
      <pubDate>Thu, 07 Mar 2024 15:00:59 +0800</pubDate>
      <guid>https://ops.docs.72602.space/csp/72602/tunnel/index.html</guid>
      <description>72602 使用两类独立隧道；ZJLAB 的 SSH 入口是另一组 ECS loopback-only 监听器，不能与本页的公网 72602 入口混用：&#xA;SSH 主入口：10021 SSH 备入口：10022 Web 数据通道：WireGuard UDP 51820 目标 ECS：47.110.67.161 (ecs-99) ZJLAB 使用 ECS ProxyJump 访问 10023（primary）和 10024（backup）。这 两个端口只绑定 ECS loopback，由独立监控进程检查并通过 DingTalk 告警；它们 没有公网安全组规则。&#xA;公网 Web 80/443 固定由 ECS HAProxy 监听，经 WireGuard 转发到 72602-minipc 的 ingress NodePort。SSH 不再承载 Web；10022 仍保留 Mailu loopback forwards。&#xA;快速连接命令：&#xA;以下命令仅适用于当前登记在 ECS 安全组白名单中的来源客户端，并使用 SSH 密钥认证；10021/10022 不是面向任意公网客户端的开放入口。&#xA;ssh -p 10021 aaron@47.110.67.161 ssh -p 10022 aaron@47.110.67.161 上线顺序建议：&#xA;先在 72602-minipc 创建并启动 10022（备入口） 验证 ECS 已监听 10022 再创建并启动 10021（主入口） 最后做外网双端口连通性验证 完整步骤、故障恢复与运维命令见子页面。</description>
    </item>
  </channel>
</rss>