# Meerkat **Repository Path**: fsscms/Meerkat ## Basic Information - **Project Name**: Meerkat - **Description**: Meerkat服务器集群实时监控平台 - **Primary Language**: Unknown - **License**: MIT - **Default Branch**: main - **Homepage**: https://monitor.phpframe.org/# - **GVP Project**: No ## Statistics - **Stars**: 1 - **Forks**: 0 - **Created**: 2026-09-30 - **Last Updated**: 2026-10-11 ## Categories & Tags **Categories**: Uncategorized **Tags**: influxdb, Gin, Postgresql, gorm, vue3 ## README # Meerkat服务器集群实时监控平台
Logo “meerkat”在中文中通常翻译为猫鼬或狐獴,属于獴科的一种小型食肉哺乳动物,原产于非洲南部,它们喜欢群居生活,跟小伙伴在一起的时候,总有一个专职“站岗放哨”的哨兵,发现危险后,通过不同频率组合的叫声传递超过20种信息,精准指示天敌类型(如鹰隼、狐狸)和方位,让其它小伙伴及时警觉危险。Meerkat服务器集群实时监控平台的寓意也是像狐獴一样,及早发现服务器的状态异常,及时预警。
背景痛点:如果你是公司的运维人员,要管理几十上百台裸金属服务器,虚拟机,Docker容器,K8s节点,你必须时刻紧盯上面的服务状态,负载性能等各项指标,时刻24小时stand By。 meerkat-admin就是为解决这个痛点而来的,现在有个狐獴帮你主动报警,及时介入。 Agent端一旦部署在客户机上,主动采集指标,向中心机汇聚、存储与展示,几分钟后就可以在web dashboard看到各项指标。 **指标不经 Telegraf 直写 InfluxDB**,经 **monitor-agent** 用 **mTLS gRPC** 上报到 **Collector**。 ### 演示网址:https://monitor.phpframe.org/ 商业部署联系作者微信:xdbyvibm6 (注明来意) 已完成的功能: - [x]内置ssh控制台,可以用户名连接,密钥连接; - [x]sftp模块,管理服务器文件上传,下载,删除,重命名; - [x]高危命令过滤,防止出现服务器崩盘; - [x]SSH命令会话审计,录像回放; - [x]计划任务,计划任务日志; - [x]还内置了一套完整的后台管理系统,基于Gin Gorm, Sqlite,(包括完整的用户、部门、角色、岗位、菜单、字典、系统设置、缓存、系统日志、附件等)可以单独独立出来; 下一步计划: - [ ]完成RDP远程连接,操作 - [ ]告警参数设置 - [ ]告警日志留存 - [ ]告警通知,短信、飞书、邮件等 - [ ]接入大模型对告警进行分析处理,形成报告 - [ ]命令编排等 本仓库是**源码 + 本机开发运行包**的合集(多个 Go module),**未使用 Docker**。第三方组件用系统安装包或工作区已解压的二进制;Windows / Linux 均提供一键脚本(见 [§8](#8-一键脚本总览))。 --- ## 目录 1. [项目概况](#1-项目概况) 2. [架构与数据流](#2-架构与数据流) 3. [技术栈(按端)](#3-技术栈按端) 4. [需要安装的软件(Agent 端 vs 中心端)](#4-需要安装的软件agent-端-vs-中心端) 5. [仓库目录](#5-仓库目录) 6. [编译(Windows / Linux,amd64 / arm64)](#6-编译windows--linuxamd64--arm64) 7. [部署与必改配置](#7-部署与必改配置) 8. [一键脚本总览](#8-一键脚本总览) 9. [Windows 操作手册](#9-windows-操作手册) 10. [Linux 操作手册(Ubuntu / Debian 系)](#10-linux-操作手册ubuntu--debian-系) 11. [健康检查:端口、进程、HTTP](#11-健康检查端口进程http) 12. [证书(mTLS)](#12-证书mtls) 13. [配置文件索引](#13-配置文件索引) 14. [安全与更多文档](#14-安全与更多文档) --- ## 1. 项目概况 | 概念 | 说明 | | --- | --- | | **用途** | 多机 CPU / 内存 / 磁盘 / 网络 / 进程等指标采集;中心控制台查看列表、详情、趋势与告警状态 | | **规划网段** | 被监控机可以内网机房、混合云、信创环境 `可以部署内网、可跨网段、跨云、例如192.168.1~99`,中心机 `192.168.1.100`(本机开发可全部 `localhost`) | | **被监控机** | **Telegraf** 采集 → **monitor-agent** 接收、缓存、上报 | | **中心机** | **Collector** 接入 Agent;**PostgreSQL** 存资产/心跳/告警;**InfluxDB** 存时序;**webserver + Vue** 提供登录与 API | | 角色 | 源码目录 | 典型产物 / 运行目录 | | --- | --- | --- | | 采集器 | `Telegraf/` | `Telegraf/telegraf.exe` 或系统 `telegraf` | | Agent | `client/` | `client/monitor-agent.exe` 或 `dist/linux-*/monitor-agent` | | Collector | `server/` | `server/collector.exe` 或 `dist/linux-*/collector` | | Web API | `webserver/` | `webserver/webserver.exe` 或 `dist/linux-*/webserver` | | 控制台 | `web/` | 开发 `pnpm dev`(:3000);生产 `web/dist` + Nginx | 协议源文件唯一:`server/api/proto/collector/v1/collector.proto`。修改后需 `protoc` 重新生成并**同时**重启 Agent 与 Collector。 --- ## 2. 架构与数据流 ### 2.1 部署视图 ```text 中心机 ┌────────────────────────────────────────────────────────────┐ │ 浏览器 :3000 ──► Vue(/dev-api 代理到 webserver :8090) │ │ webserver :8090 ──读──► PostgreSQL :5432、InfluxDB :8086 │ │ Collector :9500 (mTLS gRPC) ──写──► PG + InfluxDB │ │ Collector 管理 HTTPS :8080(自签 CA) │ └────────────────────────────┬───────────────────────────────┘ │ gRPC + mTLS ┌────────────────────┼────────────────────┐ ▼ ▼ ▼ 被监控机 A 被监控机 B 被监控机 N Telegraf → :9510 同左 同左 monitor-agent monitor-agent monitor-agent health :9511 health :9511 health :9511 ``` ### 2.2 关键访问关系 | 从 | 到 | 地址 / 说明 | | --- | --- | --- | | Telegraf | 本机 Agent | `http://127.0.0.1:9510/v1/telegraf/metrics`(仅回环,成功 `204`) | | Agent | Collector | `server_address`,如 `192.168.1.100:9500`,mTLS | | Collector / webserver | PostgreSQL | 默认 `localhost:5432` | | Collector / webserver | InfluxDB | 默认 `http://localhost:8086`,org `hkc`,bucket `bucket` | | Vue 开发 | webserver | `web/.env.development` → `VITE_APP_API_URL=http://localhost:8090` | 跨机部署时:Agent 的 `server_address` 改为中心 IP/域名;**服务端证书 SAN 须包含该地址**。Telegraf 输出 URL **始终本机 9510**,不要写成中心地址。 ### 2.3 时序(简图) ```mermaid sequenceDiagram participant T as Telegraf participant A as monitor-agent participant C as Collector participant P as PostgreSQL participant I as InfluxDB participant W as webserver T->>A: POST 指标 :9510 A->>C: gRPC Metrics (mTLS) C->>P: 资产/心跳/Outbox C->>I: 时序写入 W->>P: 读列表/详情 W->>I: Flux 查趋势 ``` --- ## 3. 技术栈(按端) ### 3.1 自研程序(Go / 前端) | 组件 | 技术 | 说明 | | --- | --- | --- | | monitor-agent | Go **1.27+**,`CGO_ENABLED=0` | gRPC 客户端、SQLite 积压、HTTP 收 Telegraf | | collector | Go 1.27+ | gRPC 服务端、GORM、Influx 写入、Outbox | | webserver | Go 1.27+,Gin、JWT | 登录/菜单/监控 API;会话 SQLite | | 控制台 | Vue **3**、Vite、TypeScript、Element Plus、ECharts、**pnpm** | 仅中心机需要(开发或构建静态资源) | | RPC | gRPC + Protobuf | `protoc` 31+ 推荐;插件 `protoc-gen-go` / `protoc-gen-go-grpc` | | 传输安全 | mTLS | 测试证书:`client/cmd/certgen` 或 `scripts/cert/Generate-mTLSCerts.ps1` | ### 3.2 第三方(按机器角色) 见下一节「安装清单」。Agent 端**不需要** PostgreSQL / InfluxDB / Collector / webserver。 --- ## 4. 需要安装的软件(Agent 端 vs 中心端) ### 4.1 被监控机(Agent 主机) | 软件 | 版本(本仓库验证) | 是否必须 | 官方站点 | | --- | --- | --- | --- | | **monitor-agent** | 自编译 | 必须 | 本仓库 `client/` | | **Telegraf** | **1.40+**(工作区自带 1.40.1) | 必须 | https://www.influxdata.com/time-series-platform/telegraf | | **Go** | **1.27+** | 仅编译机需要 | https://go.dev/dl/ | | MySQL / Redis / PostgreSQL 等 | 视 `telegraf.conf` 插件 | 可选采集目标 | 各上游官网 | **不需要**:InfluxDB、PostgreSQL、Collector、webserver、Node.js。 ### 4.2 中心机(Server 主机) | 软件 | 版本(本仓库验证) | 是否必须 | 官方站点 | | --- | --- | --- | --- | | **PostgreSQL** | **16+** 推荐 | 必须 | https://www.postgresql.org/download/ | | **InfluxDB** | **2.x** | 必须 | https://docs.influxdata.com/influxdb/v2/ | | **collector** / **webserver** | 自编译 | 必须 | 本仓库 `server/`、`webserver/` | | **Go** | 1.27+ | 仅编译机需要 | https://go.dev/dl/ | | **Node.js LTS** + **pnpm** | LTS + 9.x 常见 | 开发控制台必须;生产可只部署 `web/dist` | https://nodejs.org/ https://pnpm.io/ | | **protoc** | 31+(改 proto 时) | 开发 | https://github.com/protocolbuffers/protobuf/releases | **不需要**:在被监控机上安装 Telegraf 以外的中心组件。 ### 4.3 工作区自带(Windows 开发包,可选) | 内容 | 路径 | | --- | --- | | protoc | `protoc64/bin/protoc.exe` | | InfluxDB 2 Windows 二进制 | `influxdb2/influxdb2_windows_amd64/influxd.exe` | | Telegraf Windows 二进制 | `Telegraf/telegraf.exe` | > **InfluxDB 启动**:`setup-windows.ps1` / `setup-linux.sh` **均不**自动拉起 InfluxDB;请用 `scripts/windows/server/start.ps1` 或 `scripts/linux/server/start.sh`。Windows 上 `start.ps1` 使用 `%USERPROFILE%\.influxdbv2`(避免与工作区错误 bolt 路径冲突)。 --- ## 5. 仓库目录 ```text monitor/ ├── client/ Agent、certgen ├── server/ Collector ├── webserver/ 监控后台 HTTP API ├── web/ Vue 控制台 ├── Monitor/ Windows Agent 运行目录(exe、config、certs、state) ├── Telegraf/ Telegraf 发行包与 telegraf.conf ├── influxdb2/ InfluxDB 2 Windows 发行包(可选) ├── protoc64/ protoc(可选) ├── scripts/ setup、windows/*、linux/*、cert/* ├── dist/ 交叉编译输出 linux-amd64 / linux-arm64 └── doc/ 补充备忘 ``` --- ## 6. 编译(Windows / Linux,amd64 / arm64) 统一要求:`CGO_ENABLED=0`(Agent / Collector / webserver 均不依赖 CGO)。 ### 6.1 Windows 本机(amd64) 在**包根目录**执行,或先 `cd` 到对应子目录: ```powershell $root = "C:\Users\Administrator\Desktop\monitor" # 改成你的路径 $env:CGO_ENABLED = "0" Set-Location "$root\client" go test ./... go build -trimpath -ldflags "-s -w" -o "$root\client\monitor-agent.exe" .\cmd\monitor-agent Set-Location "$root\server" go build -trimpath -ldflags "-s -w" -o "$root\server\collector.exe" .\cmd\collector Set-Location "$root\webserver" go build -trimpath -ldflags "-s -w" -o "$root\webserver\webserver.exe" .\cmd\webserver ``` 也可运行 `powershell -File .\scripts\setup-windows.ps1`(含 `web\` 下 `pnpm install`、证书、编译)。参数:`-SkipInstall`、`-BuildOnly`。 ### 6.2 Linux 本机(amd64 / arm64) ```bash ROOT=/opt/monitor # 改成你的路径 export CGO_ENABLED=0 cd "$ROOT/client" && go build -trimpath -ldflags "-s -w" -o "$ROOT/dist/linux-amd64/monitor-agent" ./cmd/monitor-agent cd "$ROOT/server" && go build -trimpath -ldflags "-s -w" -o "$ROOT/dist/linux-amd64/collector" ./cmd/collector cd "$ROOT/webserver" && go build -trimpath -ldflags "-s -w" -o "$ROOT/dist/linux-amd64/webserver" ./cmd/webserver ``` 本机为 **arm64** 时,把输出目录改为 `dist/linux-arm64`(或在 arm64 机器上直接编译到该目录)。 `./scripts/setup-linux.sh` 从 [go.dev](https://go.dev/dl/) 安装 **Go 1.27.1** 到 `/usr/local/go`(不用 apt 的旧版 `golang-go`),按本机架构编译到 `dist/linux-amd64/` 或 `dist/linux-arm64/`。环境变量写入 `scripts/linux/monitor.env` 与 `/etc/monitor/monitor.env`,执行前: ```bash set -a && source /etc/monitor/monitor.env && set +a # 或 source /path/to/monitor/scripts/linux/monitor.env ``` 可选 `GO_VERSION=1.27.1`、`GO_INSTALL_DIR=/usr/local/go`。Go 的 `PATH` 会写入 `/etc/profile.d/monitor-go.sh`,并在 `/etc/bash.bashrc` 中 `source`(login 与面板终端均可用)。业务变量见 `/etc/monitor/monitor.env`;可选 `MONITOR_ENV_AUTO=1` 在登录时一并加载(`/etc/profile.d/monitor-env.sh`)。示例见 `scripts/linux/monitor.env.example`。 ### 6.3 交叉编译(在 Windows 上出 Linux 包) ```powershell $root = "C:\Users\Administrator\Desktop\monitor" New-Item -ItemType Directory -Force "$root\dist\linux-amd64","$root\dist\linux-arm64" | Out-Null $env:CGO_ENABLED = "0" # amd64 $env:GOOS = "linux"; $env:GOARCH = "amd64" go build -C "$root\client" -trimpath -ldflags "-s -w" -o "$root\dist\linux-amd64\monitor-agent" ./cmd/monitor-agent go build -C "$root\server" -trimpath -ldflags "-s -w" -o "$root\dist\linux-amd64\collector" ./cmd/collector go build -C "$root\webserver" -trimpath -ldflags "-s -w" -o "$root\dist\linux-amd64\webserver" ./cmd/webserver # arm64 $env:GOARCH = "arm64" go build -C "$root\client" -trimpath -ldflags "-s -w" -o "$root\dist\linux-arm64\monitor-agent" ./cmd/monitor-agent go build -C "$root\server" -trimpath -ldflags "-s -w" -o "$root\dist\linux-arm64\collector" ./cmd/collector go build -C "$root\webserver" -trimpath -ldflags "-s -w" -o "$root\dist\linux-arm64\webserver" ./cmd/webserver Remove-Item Env:GOOS, Env:GOARCH, Env:CGO_ENABLED -ErrorAction SilentlyContinue ``` ### 6.4 前端 ```powershell Set-Location C:\Users\Administrator\Desktop\monitor\web pnpm install pnpm build # 生产静态资源 → web/dist pnpm dev # 开发 :3000 ``` --- ## 7. 部署与必改配置 ### 7.1 启动顺序(逻辑依赖) ```text 中心:PostgreSQL → InfluxDB(初始化 org/bucket/token)→ Collector → webserver →(仅 Windows 开发机)`pnpm dev`;Linux 中心机用 `pnpm build` + Nginx 或本机手动 `pnpm dev` 被监控:monitor-agent → Telegraf ``` ### 7.2 中心机必改/必核对 | 文件 | 改什么 | | --- | --- | | `server/configs/server.local.yaml` | `postgres.*`、`influx.url/token/org/bucket`、`tls` 证书路径、`grpc_address` | | `webserver/configs/webserver.yaml` | 同上 PG/Influx;`jwt.secret`;`http_address`(默认 `:8090`) | | 环境变量(推荐生产) | `MONITOR_INFLUX_TOKEN`、`WEBSERVER_JWT_SECRET`、`WEBSERVER_ADMIN_PASSWORD`、`MONITOR_POSTGRES_PASSWORD` | Influx 首次初始化:浏览器打开 `http://<中心>:8086`,**org=`hkc`**,**bucket=`bucket`**,创建 **write** Token 写入 yaml 或环境变量。 ### 7.3 被监控机必改/必核对 | 文件 | 改什么 | | --- | --- | | `client/configs/agent.yaml`(或 `/etc/monitor-agent/agent.yaml`) | **`agent_id` 全局唯一**;`server_address` 为中心 `IP:9500`;`ca_file` / `cert_file` / `key_file` | | `Telegraf/telegraf.conf` | 输出 URL 保持 `http://127.0.0.1:9510/v1/telegraf/metrics`;标签环境变量与 Agent 一致 | | 证书 | 各机复制同一套 **`ca.pem` + `client.pem` + `client-key.pem`**(测试环境共用一张 client 证即可) | ### 7.4 Linux 中心机文件落位示例 ```bash sudo install -Dm755 collector /usr/local/bin/monitor-collector sudo install -Dm755 webserver /usr/local/bin/monitor-webserver sudo install -Dm600 server.local.yaml /etc/monitor-server/server.yaml sudo install -Dm600 webserver.yaml /etc/monitor-webserver/webserver.yaml sudo install -Dm600 ca.pem server.pem server-key.pem /etc/monitor-server/certs/ ``` webserver 工作目录需可写 `data/webserver.db`(SQLite)。 ### 7.5 Linux 被监控机示例 ```bash sudo install -Dm755 monitor-agent /usr/local/bin/monitor-agent sudo install -Dm600 agent.yaml /etc/monitor-agent/agent.yaml sudo install -Dm600 ca.pem client.pem client-key.pem /etc/monitor-agent/certs/ # systemd: client/packaging/monitor-agent.service ``` --- ## 8. 一键脚本总览 脚本从自身路径**上溯三层**定位包根目录,路径与绝对安装位置无关。 | 脚本 | 平台 | 作用 | | --- | --- | --- | | `scripts/setup-windows.ps1` | Windows | 检查/安装依赖、`web` 的 `pnpm install`、生成证书、编译三端;**不启动 InfluxDB** | | `scripts/windows/server/start.ps1` | Windows | PG 检查、**重启 Influx**(`.influxdbv2`)、Collector、webserver、**pnpm dev + 打开浏览器** | | `scripts/windows/server/stop.ps1` | Windows | 停前端 :3000、collector、webserver、Influx;`-Infra` 另停 PostgreSQL | | `scripts/windows/agent/start.ps1` | Windows | monitor-agent + Telegraf(可见控制台) | | `scripts/windows/agent/stop.ps1` | Windows | telegraf + monitor-agent | | `scripts/cert/Generate-mTLSCerts.ps1` | Windows | 默认 Go certgen → `client/certs` | | `scripts/setup-linux.sh` | Linux | 安装 **Go 1.27.1**、写 `monitor.env`、apt 装 PG/Influx/Telegraf(可跳过)、编译到 `dist/linux-*`;**不启动 InfluxDB** | | `scripts/linux/server/start.sh` | Linux | PG、Influx、Collector、webserver;**不启动** `pnpm dev` | | `scripts/linux/server/stop.sh` | Linux | 停中心进程;`INFRA=1` 停 PostgreSQL | | `scripts/linux/agent/start.sh` | Linux | agent + telegraf | | `scripts/linux/agent/stop.sh` | Linux | agent + telegraf | --- ## 9. Windows 操作手册 ### 9.1 首次准备 ```powershell cd C:\Users\Administrator\Desktop\monitor powershell -ExecutionPolicy Bypass -File .\scripts\setup-windows.ps1 ``` ### 9.2 启动 / 停止 ```powershell # 中心机(本机可同时当中心) powershell -File .\scripts\windows\server\start.ps1 # 被监控机(或本机第二套 Agent) powershell -File .\scripts\windows\agent\start.ps1 # 停止 powershell -File .\scripts\windows\server\stop.ps1 powershell -File .\scripts\windows\agent\stop.ps1 # powershell -File .\scripts\windows\server\stop.ps1 -Infra # 含 PostgreSQL ``` `start.ps1` 未设置 `WEBSERVER_ADMIN_PASSWORD` 时默认 `Monitor123!`;首次 SQLite 无用户时会创建 **admin**。 ### 9.3 手动启动(排障用) 见 `doc/windows-local-startup.md`;核心端口见 [§11](#11-健康检查端口进程http)。 --- ## 10. Linux 操作手册(Ubuntu / Debian 系) ### 10.1 首次准备 ```bash cd /path/to/monitor chmod +x scripts/setup-linux.sh scripts/linux/**/*.sh ./scripts/setup-linux.sh # 可选:SKIP_INSTALL=1 ./scripts/setup-linux.sh ``` `setup-linux.sh` 会尝试拉起 PostgreSQL(若已装但未监听),**不会**启动 InfluxDB;Influx 由下一节的 `server/start.sh` 负责。Go 的 PATH 安装后对新终端自动生效;当前 shell 可 `source /etc/profile.d/monitor-go.sh`。启服务前再 `source /etc/monitor/monitor.env` 以加载 `MONITOR_ROOT`、`MONITOR_INFLUX_TOKEN` 等。 ### 10.2 启动 / 停止 ```bash ./scripts/linux/server/start.sh ./scripts/linux/agent/start.sh ./scripts/linux/server/stop.sh ./scripts/linux/agent/stop.sh # INFRA=1 ./scripts/linux/server/stop.sh ``` ### 10.3 前端(Linux 中心机) ```bash cd web && pnpm install && pnpm dev # 或 pnpm build 后由 Nginx 托管 dist,反代 API 到 :8090 ``` ### 10.4 arm64 服务器 使用 `dist/linux-arm64/` 下二进制,或在该机器上按 [§6.2](#62-linux-本机amd64--arm64) 编译;配置与 amd64 相同。 --- ## 11. 健康检查:端口、进程、HTTP ### 11.1 端口一览 | 端口 | 组件 | 所在机器 | | --- | --- | --- | | 5432 | PostgreSQL | 中心 | | 8086 | InfluxDB | 中心 | | 9500 | Collector gRPC | 中心 | | 8080 | Collector 管理 HTTPS | 中心 | | 8090 | webserver | 中心 | | 3000 | Vite 开发 / 静态站 | 中心(开发) | | 9510 | Agent 收 Telegraf | 被监控(仅 127.0.0.1) | | 9511 | Agent healthz | 被监控(仅 127.0.0.1) | ### 11.2 Windows:批量查端口 ```powershell $ports = 5432,8086,9500,8080,8090,3000,9510,9511 foreach ($p in $ports) { $up = [bool](netstat -ano | Select-String ":$p\s+\S+\s+LISTENING") "{0,5} {1}" -f $p, $(if ($up) { "LISTEN" } else { "down" }) } ``` ### 11.3 Windows:进程 ```powershell Get-Process postgres,influxd,collector,webserver,monitor-agent,telegraf,node -ErrorAction SilentlyContinue | Format-Table Id, ProcessName, StartTime -AutoSize ``` ### 11.4 Linux:端口与进程 ```bash ss -lnt | grep -E ':(5432|8086|9500|8080|8090|3000|9510|9511)\b' pgrep -a influxd; pgrep -a collector; pgrep -a webserver; pgrep -a monitor-agent; pgrep -a telegraf ``` ### 11.5 HTTP 探活 ```powershell # 中心 Invoke-WebRequest http://127.0.0.1:8086/health -UseBasicParsing Invoke-WebRequest http://127.0.0.1:8090/healthz -UseBasicParsing # code 00000 curl.exe --ssl-no-revoke --cacert .\client\certs\ca.pem https://localhost:8080/healthz # Agent Invoke-WebRequest http://127.0.0.1:9511/healthz -UseBasicParsing # Telegraf → Agent 通路(期望 204) Invoke-WebRequest -Method POST -Uri http://127.0.0.1:9510/v1/telegraf/metrics ` -ContentType "text/plain" -Body "probe,source=manual value=1i" -UseBasicParsing ``` ```bash curl -sS http://127.0.0.1:8086/health curl -sS http://127.0.0.1:8090/healthz curl -sS http://127.0.0.1:9511/healthz ``` 浏览器:开发环境 http://localhost:3000 ,登录 **admin** / 初始密码(见 `WEBSERVER_ADMIN_PASSWORD`)。 --- ## 12. 证书(mTLS) 测试环境一键生成(**共用一张 client 证**,多机复制 `ca.pem` + `client.pem` + `client-key.pem`): ```powershell powershell -File .\scripts\cert\Generate-mTLSCerts.ps1 ``` 或: ```powershell cd client go run .\cmd\certgen -out ..\client\certs ``` | 文件 | 用途 | | --- | --- | | `ca.pem` | 双方信任根 | | `server.pem` / `server-key.pem` | 仅 Collector 中心机 | | `client.pem` / `client-key.pem` | 所有 Agent(可复制分发) | 轮换/吊销:重新生成整套证书,替换文件并重启 Collector 与全部 Agent。Windows 生成的 PEM 可直接用于 Linux。 --- ## 13. 配置文件索引 | 文件 | 用途 | | --- | --- | | `client/configs/agent.yaml` | 本机 Windows Agent | | `client/configs/agent.example.yaml` | Linux 模板 | | `client/configs/agent.windows.yaml` | Windows 模板 | | `server/configs/server.local.yaml` | Collector 本机配置 | | `server/configs/server.local.example.yaml` | 示例 | | `webserver/configs/webserver.yaml` | Web API | | `web/.env.development` | 前端开发代理与 API 地址 | | `Telegraf/telegraf.conf` | 本机 Telegraf | | `client/telegraf/telegraf.conf.template` | Linux Telegraf 模板 | 环境变量覆盖(webserver):`WEBSERVER_JWT_SECRET`、`WEBSERVER_ADMIN_PASSWORD`、`MONITOR_POSTGRES_PASSWORD`、`MONITOR_INFLUX_TOKEN` — 详见 `webserver/README.md`。 --- ## 14. 安全与更多文档 - 口令、Influx Token、JWT **不要提交 git**;生产用环境变量或权限受限的配置文件。 - Agent 监听 **9510 / 9511 仅 127.0.0.1**;Telegraf 不要携带中心写 Token。 - 中心故障时:Agent SQLite 积压、Telegraf 磁盘 buffer,恢复后追送。 | 文档 | 内容 | | --- | --- | | [doc/windows-local-startup.md](doc/windows-local-startup.md) | Windows 本机细节、systemd 摘录 | | [doc/telegraf-monitor-agent-deployment.md](doc/telegraf-monitor-agent-deployment.md) | Agent + Telegraf 部署 | | [server/README_ZH.md](server/README_ZH.md) | Collector | | [webserver/README.md](webserver/README.md) | webserver 配置、编译、运行 | | [project-idea-v3.md](project-idea-v3.md) | 原始方案与后续规划 |