docs(middleware): 添加stunnel4中间件部署与配置指南
新增stunnel4中间件的详细部署文档,包含安装步骤、UAT/生产环境配置、环境切换流程、常见问题排查等内容。该文档用于指导安全连接OSL交易所的SSL/TLS隧道配置。
This commit is contained in:
@@ -0,0 +1,171 @@
|
||||
# stunnel4 中间件部署与配置指南
|
||||
|
||||
## 1. 概述
|
||||
|
||||
stunnel4 是一个用于加密 TCP 连接的开源工具,在本项目中仅用于连接 OSL 交易所。它通过在客户端和服务器之间建立 SSL/TLS 隧道,确保数据传输的安全性。
|
||||
|
||||
## 2. 安装
|
||||
|
||||
### 2.1 下载地址
|
||||
|
||||
- 通用下载地址:[https://pkgs.org/search/?q=stunnel4](https://pkgs.org/search/?q=stunnel4)
|
||||
- Ubuntu 24.04 LTS 版本下载地址:[http://archive.ubuntu.com/ubuntu/pool/universe/s/stunnel4/stunnel4_5.72-1build2_amd64.deb](http://archive.ubuntu.com/ubuntu/pool/universe/s/stunnel4/stunnel4_5.72-1build2_amd64.deb)
|
||||
|
||||
### 2.2 安装流程
|
||||
|
||||
1. 下载 deb 包到服务器
|
||||
|
||||
```bash
|
||||
wget http://archive.ubuntu.com/ubuntu/pool/universe/s/stunnel4/stunnel4_5.72-1build2_amd64.deb
|
||||
```
|
||||
|
||||
2. 安装 deb 包
|
||||
|
||||
```bash
|
||||
sudo dpkg -i stunnel4_5.72-1build2_amd64.deb
|
||||
```
|
||||
|
||||
3. 安装依赖(如果需要)
|
||||
|
||||
```bash
|
||||
sudo apt-get install -f
|
||||
```
|
||||
|
||||
## 3. 配置
|
||||
|
||||
### 3.1 UAT 环境配置
|
||||
|
||||
配置文件路径:`/etc/stunnel/stunnel.conf`
|
||||
|
||||
```ini
|
||||
socket = l:TCP_NODELAY=1
|
||||
socket = r:TCP_NODELAY=1
|
||||
sslVersionMin = TLSv1.2
|
||||
sslVersionMax = all
|
||||
TIMEOUTconnect = 30
|
||||
delay = yes
|
||||
debug = 7
|
||||
cert = /etc/stunnel/stunnel_client_dlsec.crt
|
||||
key = /etc/stunnel/stunnel_client.key
|
||||
output = /var/log/stunnel4/stunnel.log
|
||||
|
||||
[om]
|
||||
sni = uat-ndsdlsecom-osl
|
||||
client = yes
|
||||
accept = 0.0.0.0:440
|
||||
connect = fix-test.oslsandbox.com:443
|
||||
|
||||
[dc]
|
||||
sni = uat-ndsdlsecdc-osl
|
||||
client = yes
|
||||
accept = 0.0.0.0:441
|
||||
connect = fix-test.oslsandbox.com:443
|
||||
```
|
||||
|
||||
### 3.2 生产环境配置
|
||||
|
||||
配置文件路径:`/etc/stunnel/stunnel.conf.pro`
|
||||
|
||||
```ini
|
||||
socket = l:TCP_NODELAY=1
|
||||
socket = r:TCP_NODELAY=1
|
||||
sslVersionMin = TLSv1.2
|
||||
sslVersionMax = all
|
||||
TIMEOUTconnect = 30
|
||||
delay = yes
|
||||
debug = 7
|
||||
cert = /etc/stunnel/stunnel_client.crt
|
||||
key = /etc/stunnel/stunnel_client.key
|
||||
output = /var/log/stunnel4/stunnel.log
|
||||
|
||||
[om]
|
||||
sni = prod-ndsdlsecom-osl
|
||||
client = yes
|
||||
accept = 0.0.0.0:440
|
||||
connect = fixtrade.osl.com:443
|
||||
|
||||
[dc]
|
||||
sni = prod-ndsdlsecdc-osl
|
||||
client = yes
|
||||
accept = 0.0.0.0:441
|
||||
connect = fixtrade.osl.com:443
|
||||
```
|
||||
|
||||
## 4. 环境切换
|
||||
|
||||
### 4.1 从 UAT 切换到生产环境
|
||||
|
||||
1. 停止 stunnel4 服务
|
||||
|
||||
```bash
|
||||
sudo systemctl stop stunnel4
|
||||
```
|
||||
|
||||
2. 查找并终止占用端口 440 的进程
|
||||
|
||||
```bash
|
||||
sudo netstat -aonp | grep 440
|
||||
# 找到对应的 PID,使用以下命令终止进程
|
||||
sudo kill -9 {PID}
|
||||
```
|
||||
|
||||
3. 重命名配置文件
|
||||
|
||||
```bash
|
||||
sudo mv /etc/stunnel/stunnel.conf /etc/stunnel/stunnel.conf.uat
|
||||
sudo mv /etc/stunnel/stunnel.conf.pro /etc/stunnel/stunnel.conf
|
||||
```
|
||||
|
||||
4. 启动 stunnel4 服务
|
||||
|
||||
```bash
|
||||
sudo systemctl start stunnel4
|
||||
```
|
||||
|
||||
### 4.2 其他切换注意事项
|
||||
|
||||
1. **OMC 配置修改**:
|
||||
- 进入 OMC 系统
|
||||
- 导航至 `Base -> Market API Session`
|
||||
- 修改对应的 session 账号密码
|
||||
|
||||
2. **Nacos 配置确认**:
|
||||
- 打开 `quick-fix-client.yml` 配置
|
||||
- 确认 `enabledSession` 连接的 session
|
||||
- 确认配置 session 的 `SocketConnectHost` 是否为 web server 的 IP
|
||||
|
||||
## 5. 部署架构
|
||||
|
||||
- stunnel4 安装在 web server 上
|
||||
- 开启端口 440 与 441
|
||||
- AP server 通过 web server 的内网 IP 连接
|
||||
|
||||
## 6. 常见问题与排查
|
||||
|
||||
### 6.1 连接问题
|
||||
|
||||
- 确认 stunnel4 服务是否正常运行:`sudo systemctl status stunnel4`
|
||||
- 检查端口是否正常监听:`sudo netstat -aonp | grep 440`
|
||||
- 查看日志文件:`tail -f /var/log/stunnel4/stunnel.log`
|
||||
|
||||
### 6.2 证书问题
|
||||
|
||||
- 确认证书文件路径是否正确
|
||||
- 检查证书文件权限是否正确
|
||||
- 验证证书是否过期
|
||||
|
||||
## 7. 相关命令
|
||||
|
||||
- 启动服务:`sudo systemctl start stunnel4`
|
||||
- 停止服务:`sudo systemctl stop stunnel4`
|
||||
- 重启服务:`sudo systemctl restart stunnel4`
|
||||
- 查看服务状态:`sudo systemctl status stunnel4`
|
||||
- 查看端口占用:`sudo netstat -aonp | grep 440`
|
||||
- 查看日志:`tail -f /var/log/stunnel4/stunnel.log`
|
||||
|
||||
## 8. 注意事项
|
||||
|
||||
- stunnel4 仅用于连接 OSL 交易所
|
||||
- 切换环境时务必按照上述步骤操作,确保服务正常运行
|
||||
- 定期检查 stunnel4 服务状态和日志,确保连接稳定
|
||||
- 确保证书文件的安全性,避免泄露
|
||||
Reference in New Issue
Block a user