部署上线
本章讲解生产环境部署授权系统的最佳实践,包括服务器选型、Nginx 配置、HTTPS、数据库备份、监控。
1. 服务器要求
| 项 | 最低 | 推荐 |
|---|---|---|
| CPU | 1 核 | 2 核+ |
| 内存 | 1 GB | 2 GB+ |
| 硬盘 | 20 GB | 40 GB+ SSD |
| 带宽 | 1 Mbps | 5 Mbps+ |
| PHP | 7.4 | 8.0+ |
| MySQL | 5.7 | 8.0+ |
2. Nginx 配置示例
server {
listen 80;
server_name license.example.com;
return 301 https://$server_name$request_uri;
}
server {
listen 443 ssl http2;
server_name license.example.com;
# SSL 证书(Let's Encrypt)
ssl_certificate /etc/nginx/ssl/license.example.com.crt;
ssl_certificate_key /etc/nginx/ssl/license.example.com.key;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers HIGH:!aNULL:!MD5;
# 安全头
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
# 站点根目录
root /www/wwwroot/license.example.com;
index index.php;
# 隐藏敏感文件
location ~ /\.(?!well-known).* {
deny all;
}
location ~* /(inc|docs|api)/.*\.(sql|bak|log|env|ini)$ {
deny all;
}
# PHP 处理
location ~ \.php$ {
fastcgi_pass unix:/tmp/php-cgi-82.sock;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
fastcgi_read_timeout 60;
}
# API 路由特殊处理(防缓存)
location ~ ^/api/ {
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
try_files $uri $uri/ /index.php?$query_string;
}
# 静态资源缓存
location ~* \.(css|js|jpg|jpeg|png|gif|ico|svg|woff2?)$ {
expires 30d;
add_header Cache-Control "public, immutable";
access_log off;
}
# 日志
access_log /var/log/nginx/license.example.com.access.log;
error_log /var/log/nginx/license.example.com.error.log;
}
3. PHP-FPM 配置
编辑 /www/server/php/82/etc/php-fpm.conf 或 www.conf:
[www]
pm = dynamic
pm.max_children = 30
pm.start_servers = 5
pm.min_spare_servers = 5
pm.max_spare_servers = 20
pm.max_requests = 500
; PHP 脚本超时
request_terminate_timeout = 60s
; 上传限制
file_uploads = On
upload_max_filesize = 10M
post_max_size = 10M
4. MySQL 配置
编辑 /etc/my.cnf:
[mysqld]
character-set-server = utf8mb4
collation-server = utf8mb4_unicode_ci
default-storage-engine = InnoDB
# 性能
innodb_buffer_pool_size = 256M
innodb_log_file_size = 64M
max_connections = 100
# 慢查询日志
slow_query_log = 1
long_query_time = 2
slow_query_log_file = /var/log/mysql/slow.log
5. 数据库自动备份
创建 /www/wwwroot/backup.sh:
#!/bin/bash
# 每日凌晨 3 点备份
BACKUP_DIR=/www/backup/license-server
DATE=$(date +%Y%m%d_%H%M%S)
KEEP_DAYS=30
mkdir -p $BACKUP_DIR
# 备份数据库
mysqldump -u license_user -p'your-password' \
--single-transaction --routines --triggers \
license_server | gzip > $BACKUP_DIR/db_$DATE.sql.gz
# 清理 30 天前的备份
find $BACKUP_DIR -name "db_*.sql.gz" -mtime +$KEEP_DAYS -delete
# 上传到 OSS(可选)
# ossutil cp $BACKUP_DIR/db_$DATE.sql.gz oss://your-bucket/license-server/
设置 cron:
chmod +x /www/wwwroot/backup.sh
echo "0 3 * * * /www/wwwroot/backup.sh" >> /etc/crontab
systemctl reload crond
6. 监控与告警
健康检查接口
创建 health.php:
<?php
require_once __DIR__ . '/inc/functions.php';
header('Content-Type: application/json');
try {
$db = get_db();
$db->query("SELECT 1");
// 检查关键表是否存在
$tables = ['lic_users', 'lic_products', 'lic_licenses', 'lic_orders'];
foreach ($tables as $t) {
$db->query("SELECT 1 FROM " . table($t) . " LIMIT 1");
}
echo json_encode([
'status' => 'ok',
'time' => date('c'),
'version' => '1.0.0',
]);
} catch (Exception $e) {
http_response_code(500);
echo json_encode([
'status' => 'error',
'message' => $e->getMessage(),
]);
}
使用外部监控(如 UptimeRobot)每 5 分钟 ping 一次:
https://license.example.com/health.php
日志清理
编辑 /etc/logrotate.d/license-server:
/var/log/nginx/license.example.com.*.log {
daily
rotate 30
compress
delaycompress
missingok
notifempty
create 0640 www-data adm
sharedscripts
postrotate
[ -f /var/run/nginx.pid ] && kill -USR1 $(cat /var/run/nginx.pid)
endscript
}
7. 上线 Checklist
- 数据库密码使用强密码(≥ 16 字符)
-
HMAC_SALT和API_SECRET已改为随机字符串 - 删除
install.php、patch_*.php、debug.php等脚本 - 关闭
WP_DEBUG(如使用 WordPress) - 关闭 PHP
display_errors - 配置 HTTPS(Let's Encrypt)
- 配置防火墙(仅开放 80/443/22)
- 数据库自动备份已启用
- 监控告警已配置
- 易支付回调地址白名单已配置
- 测试授权验证全流程
- 测试支付回调
部署完成后,记得阅读 安全建议 加固系统。