From 0ff820bae3beb5e7472d71f032ceebd3d5df28e2 Mon Sep 17 00:00:00 2001 From: wusumac <736139669@qq.com> Date: Wed, 12 Aug 2026 12:40:04 +0800 Subject: [PATCH] ops: add ZSpace NAS deployment --- Dockerfile.nas | 42 +++++++++++++++++++++++++++++++++++++++++ deploy/nas/README.md | 26 +++++++++++++++++++++++++ deploy/nas/compose.yaml | 41 ++++++++++++++++++++++++++++++++++++++++ 3 files changed, 109 insertions(+) create mode 100644 Dockerfile.nas create mode 100644 deploy/nas/README.md create mode 100644 deploy/nas/compose.yaml diff --git a/Dockerfile.nas b/Dockerfile.nas new file mode 100644 index 00000000..9b562197 --- /dev/null +++ b/Dockerfile.nas @@ -0,0 +1,42 @@ +# Build the customized Plainleaf client and Rust server for an amd64 NAS. +FROM node:24.13.0-bookworm-slim AS client-builder + +RUN apt-get update \ + && apt-get install -y --no-install-recommends ca-certificates git \ + && rm -rf /var/lib/apt/lists/* + +WORKDIR /src +COPY . . + +ARG GITHUB_SHA=unknown +RUN npm ci \ + && npm run build + +FROM rust:bookworm AS server-builder + +WORKDIR /src +COPY --from=client-builder /src /src + +RUN cargo build --locked --release -p silverbullet \ + && strip target/release/silverbullet + +FROM debian:bookworm-slim + +RUN apt-get update \ + && apt-get install -y --no-install-recommends ca-certificates curl git openssh-client tini \ + && rm -rf /var/lib/apt/lists/* + +ENV SB_HOSTNAME=0.0.0.0 \ + SB_FOLDER=/space \ + SB_PORT=3000 \ + SB_NAME=Plainleaf \ + SB_SHELL_BACKEND=off + +COPY --from=server-builder /src/target/release/silverbullet /usr/local/bin/plainleaf + +EXPOSE 3000 +HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=5 \ + CMD curl --fail "http://127.0.0.1:${SB_PORT}/.instance" || exit 1 + +ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/bin/plainleaf"] +CMD ["--single"] diff --git a/deploy/nas/README.md b/deploy/nas/README.md new file mode 100644 index 00000000..b6ed9962 --- /dev/null +++ b/deploy/nas/README.md @@ -0,0 +1,26 @@ +# Plainleaf on ZSpace NAS + +This deployment builds the customized Plainleaf source on an amd64 ZSpace NAS. +It keeps deployment files and Markdown data separate: + +- Deployment: `个人空间/docker/plainleaf` +- Markdown space: `个人空间/笔记管理/Plainleaf` + +The server listens on NAS port `3000`, runs as the NAS account's UID/GID, and +has SilverBullet shell execution disabled. Authentication is supplied through a +deployment-local `.env` file that must not be committed. + +The intended `.env` keys are: + +```dotenv +PLAINLEAF_GIT_SHA=94d310d71211de57339724a9ad5cb21f214e101a +PLAINLEAF_IMAGE_TAG=94d310d7 +PLAINLEAF_UID=1001 +PLAINLEAF_GID=1001 +PLAINLEAF_PORT=3000 +PLAINLEAF_SPACE_PATH=/tmp/zfsv3/sata11/13616066635/data/笔记管理/Plainleaf +PLAINLEAF_USER=your-user:your-password +``` + +Do not commit the real `.env` file. Do not expose the service publicly until a +separate HTTPS reverse-proxy configuration has been verified. diff --git a/deploy/nas/compose.yaml b/deploy/nas/compose.yaml new file mode 100644 index 00000000..e9e9e5e7 --- /dev/null +++ b/deploy/nas/compose.yaml @@ -0,0 +1,41 @@ +name: plainleaf + +services: + plainleaf: + build: + context: ../.. + dockerfile: Dockerfile.nas + args: + GITHUB_SHA: ${PLAINLEAF_GIT_SHA:-unknown} + image: plainleaf:${PLAINLEAF_IMAGE_TAG:-local} + container_name: plainleaf + restart: unless-stopped + user: "${PLAINLEAF_UID:-1001}:${PLAINLEAF_GID:-1001}" + environment: + SB_HOSTNAME: 0.0.0.0 + SB_PORT: 3000 + SB_FOLDER: /space + SB_NAME: Plainleaf + SB_USER: ${PLAINLEAF_USER:?Set PLAINLEAF_USER in the NAS deployment .env file} + SB_SHELL_BACKEND: "off" + ports: + - "${PLAINLEAF_PORT:-3000}:3000" + volumes: + - "${PLAINLEAF_SPACE_PATH:?Set PLAINLEAF_SPACE_PATH in the NAS deployment .env file}:/space" + security_opt: + - no-new-privileges:true + cap_drop: + - ALL + init: false + healthcheck: + test: ["CMD", "curl", "--fail", "http://127.0.0.1:3000/.instance"] + interval: 30s + timeout: 5s + start_period: 20s + retries: 5 + networks: + - plainleaf + +networks: + plainleaf: + name: plainleaf_network