<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Network Tunnels :: Ay Docs</title>
    <link>https://ops.docs.72602.space/csp/72602/tunnel/index.html</link>
    <description>72602 使用两类独立隧道；ZJLAB 的 SSH 入口是另一组 ECS loopback-only 监听器，不能与本页的公网 72602 入口混用：&#xA;SSH 主入口：10021 SSH 备入口：10022 Web 数据通道：WireGuard UDP 51820 目标 ECS：47.110.67.161 (ecs-99) ZJLAB 使用 ECS ProxyJump 访问 10023（primary）和 10024（backup）。这 两个端口只绑定 ECS loopback，由独立监控进程检查并通过 DingTalk 告警；它们 没有公网安全组规则。&#xA;公网 Web 80/443 固定由 ECS HAProxy 监听，经 WireGuard 转发到 72602-minipc 的 ingress NodePort。SSH 不再承载 Web；10022 仍保留 Mailu loopback forwards。&#xA;快速连接命令：&#xA;以下命令仅适用于当前登记在 ECS 安全组白名单中的来源客户端，并使用 SSH 密钥认证；10021/10022 不是面向任意公网客户端的开放入口。&#xA;ssh -p 10021 aaron@47.110.67.161 ssh -p 10022 aaron@47.110.67.161 上线顺序建议：&#xA;先在 72602-minipc 创建并启动 10022（备入口） 验证 ECS 已监听 10022 再创建并启动 10021（主入口） 最后做外网双端口连通性验证 完整步骤、故障恢复与运维命令见子页面。</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Mon, 01 Jan 0001 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://ops.docs.72602.space/csp/72602/tunnel/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>72602-minipc → ecs-99</title>
      <link>https://ops.docs.72602.space/csp/72602/tunnel/minipc-ecs/index.html</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://ops.docs.72602.space/csp/72602/tunnel/minipc-ecs/index.html</guid>
      <description>SSH 反向隧道：72602-minipc → ecs-99（双入口） 本文档是 72602-minipc 的当前参考方案；执行前应核对 live unit、ECS 安全组、 SSH banner 和监控状态，目标是避免单端口掉线导致完全失联。&#xA;主入口：10021 备入口：10022 两个端口由两个独立 service 维护 一、架构 已登记且获安全组授权的来源客户端 ecs-99 (47.110.67.161) 72602-minipc (192.168.0.25) ssh -p 10021 aaron@47.110.67.161 -&gt; 0.0.0.0:10021 (sshd) --SSH reverse--&gt; localhost:22 ssh -p 10022 aaron@47.110.67.161 -&gt; 0.0.0.0:10022 (sshd) --SSH reverse--&gt; localhost:22 ECS HAProxy :25/:465/:587/:993 -&gt; 127.0.0.1:10225/:10465/:10587/:10993 (sshd) --SSH reverse--&gt; minipc hostPort :25/:465/:587/:993 说明：反向隧道必须由 72602-minipc 主动发起。0.0.0.0 是 ECS 上 sshd 的 reverse-bind，并不等于对任意公网来源开放；安全组来源限制、SSH key 认证、已建立的 SSH child/session、banner 和监控恢复都必须分别验证。</description>
    </item>
    <item>
      <title>WireGuard Web Tunnel</title>
      <link>https://ops.docs.72602.space/csp/72602/tunnel/wireguard-web/index.html</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://ops.docs.72602.space/csp/72602/tunnel/wireguard-web/index.html</guid>
      <description>WireGuard Web Tunnel 公网 Web 入口固定由 ECS HAProxy 持有，HAProxy 通过 WireGuard 访问 72602-minipc 的 ingress-nginx NodePort。TLS 仍由 ingress-nginx 和 cert-manager 管理；ECS 不复制证书，不启用 PROXY protocol，也不终止 TLS。&#xA;Internet TCP 80/443 -&gt; ECS HAProxy -&gt; primary: WireGuard 10.77.0.1 &lt;-&gt; 10.77.0.2 over UDP 51820 -&gt; minipc TCP 32080/32443 -&gt; ingress-nginx -&gt; backup: ECS-loopback SSH Web path 127.0.0.1:18080/18443 -&gt; minipc TCP 32080/32443 -&gt; ingress-nginx The WireGuard and SSH Web paths are alternative HAProxy backends, not a serial chain. The SSH Web fallback is an independent ECS-loopback service; its host-local unit and credentials are kept in private host state/ ops-private, not reproduced in this repository.</description>
    </item>
  </channel>
</rss>