{"id":38,"date":"2025-12-25T11:53:45","date_gmt":"2025-12-25T11:53:45","guid":{"rendered":"https:\/\/wordpress-zwpas.wasmer.app\/?p=38"},"modified":"2026-01-14T14:03:55","modified_gmt":"2026-01-14T14:03:55","slug":"alpine-nat%e5%b0%8f%e9%b8%a1%e9%83%a8%e7%bd%b2komari%e9%9d%a2%e6%9d%bf","status":"publish","type":"post","link":"https:\/\/nav.rr.kg\/?p=38","title":{"rendered":"\u3010\u5168\u7cfb\u7edf\u901a\u7528\u3011VPS \u4e00\u952e\u90e8\u7f72 Komari \u9762\u677f + Cloudflare Tunnel"},"content":{"rendered":"\n<p>\u624b\u91cc\u6709\u5404\u79cd\u4e0d\u540c\u7cfb\u7edf\u7684 VPS\uff08Debian, Ubuntu, Alpine\uff09\uff1f\u60f3\u88c5\u4e2a\u63a2\u9488\u76d1\u63a7\uff0c\u4f46\u4e0d\u60f3\u9488\u5bf9\u6bcf\u4e2a\u7cfb\u7edf\u53bb\u6539\u5b89\u88c5\u547d\u4ee4\uff1f<\/p>\n\n\n\n<p>\u672c\u6587\u63d0\u4f9b\u4e00\u4e2a\u5168\u81ea\u52a8\u901a\u7528\u811a\u672c\uff0c\u81ea\u52a8\u8bc6\u522b\u64cd\u4f5c\u7cfb\u7edf\uff08Systemd\/OpenRC\uff09\u548c CPU \u67b6\u6784\uff08AMD64\/ARM64\uff09\uff0c\u5e76\u4e14\u9488\u5bf9\u5c0f\u5185\u5b58 NAT \u673a\u5668\u8fdb\u884c\u4e86\u4f18\u5316\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u2728 \u811a\u672c\u7279\u70b9<\/h2>\n\n\n\n<p><br>1. \u5168\u7cfb\u7edf\u517c\u5bb9\uff1a\u81ea\u52a8\u8bc6\u522b Debian \/ Ubuntu \/ CentOS \/ Alpine\u3002<\/p>\n\n\n\n<p>2. \u5168\u67b6\u6784\u517c\u5bb9\uff1a\u81ea\u52a8\u8bc6\u522b x86_64 \/ arm64\u3002<\/p>\n\n\n\n<p>3. \u8fdb\u7a0b\u81ea\u52a8\u5b88\u62a4\uff1a\u65e0\u8bba\u662f Systemd \u8fd8\u662f OpenRC\uff0c\u5747\u914d\u7f6e\u4e86\u5d29\u6e83\u81ea\u52a8\u91cd\u542f\u673a\u5236\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u4e00\u6b65\uff1a\u5728 VPS \u4e0a\u8fd0\u884c\u901a\u7528\u811a\u672c<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u767b\u5f55 Cloudflare Zero Trust \u9762\u677f\uff0c\u83b7\u53d6\u4f60\u7684 Tunnel Token\u3002<\/li>\n<\/ol>\n\n\n\n<p>2. \u590d\u5236\u4e0b\u65b9\u4ee3\u7801\uff0c\u52a1\u5fc5\u4fee\u6539\u7b2c\u4e00\u884c\u7684 CF_TOKEN \u4e3a\u4f60\u81ea\u5df1\u7684\u3002<\/p>\n\n\n\n<p>3. \u5c06\u6574\u6bb5\u4ee3\u7801\u7c98\u8d34\u5230 SSH \u7ec8\u7aef\u4e2d\uff0c\u56de\u8f66\u6267\u884c\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#!\/bin\/sh\n\n# ================= \u914d\u7f6e\u533a\u57df =================\nexport CF_TOKEN=\"eyJhIjoi...\"  # &lt;--- \u8bf7\u5728\u8fd9\u91cc\u586b\u5165 Tunnel Token\n# ===========================================\n\necho \"\u23f3 \u6b63\u5728\u5f00\u59cb\u90e8\u7f72 (\u65e5\u5fd7\u7248)...\"\n\n# --- 1. \u73af\u5883\u51c6\u5907 ---\nif &#91; -x \"$(command -v apk)\" ]; then\n    apk add --no-cache curl wget\nelif &#91; -x \"$(command -v apt-get)\" ]; then\n    apt-get update &amp;&amp; apt-get install -y curl wget\nelif &#91; -x \"$(command -v yum)\" ]; then\n    yum install -y curl wget\nfi\n\n# --- 2. \u4e0b\u8f7d\u4e0e\u6e05\u7406 ---\nARCH=$(uname -m | sed 's\/x86_64\/amd64\/;s\/aarch64\/arm64\/')\nmkdir -p \/opt\/komari\n# \u505c\u6b62\u65e7\u8fdb\u7a0b\npkill -f komari\n# \u26a0\ufe0f \u5173\u952e\uff1a\u5220\u9664\u65e7\u6570\u636e\uff0c\u5f3a\u5236\u91cd\u7f6e\u5bc6\u7801\nrm -rf \/opt\/komari\/data\n\necho \"\u2b07\ufe0f  \u6b63\u5728\u4e0b\u8f7d\u7ec4\u4ef6...\"\nwget -qO \/opt\/komari\/komari \"https:\/\/github.com\/komari-monitor\/komari\/releases\/latest\/download\/komari-linux-${ARCH}\"\nchmod +x \/opt\/komari\/komari\nwget -qO \/usr\/local\/bin\/cloudflared \"https:\/\/github.com\/cloudflare\/cloudflared\/releases\/latest\/download\/cloudflared-linux-${ARCH}\"\nchmod +x \/usr\/local\/bin\/cloudflared\n\n# --- 3. \u914d\u7f6e\u670d\u52a1 (\u5f00\u542f\u65e5\u5fd7\u8bb0\u5f55) ---\n\nif pidof systemd >\/dev\/null 2>&amp;1 || &#91; -d \/run\/systemd\/system ]; then\n    # Systemd: \u4f7f\u7528 sh -c \u91cd\u5b9a\u5411\u65e5\u5fd7\u5230\u6587\u4ef6\n    cat > \/etc\/systemd\/system\/komari.service &lt;&lt;EOF\n&#91;Unit]\nDescription=Komari Monitor\nAfter=network.target\n&#91;Service]\nType=simple\nExecStart=\/bin\/sh -c '\/opt\/komari\/komari server > \/var\/log\/komari.log 2>&amp;1'\nWorkingDirectory=\/opt\/komari\nRestart=always\nRestartSec=5\n&#91;Install]\nWantedBy=multi-user.target\nEOF\n    # Cloudflared \u4e0d\u9700\u8981\u770b\u65e5\u5fd7\uff0c\u4f9d\u7136\u9759\u9ed8\n    cat > \/etc\/systemd\/system\/cloudflared.service &lt;&lt;EOF\n&#91;Unit]\nDescription=Cloudflare Tunnel\nAfter=network.target\n&#91;Service]\nType=simple\nExecStart=\/usr\/local\/bin\/cloudflared tunnel run --token ${CF_TOKEN}\nRestart=always\nRestartSec=5\nStandardOutput=null\nStandardError=null\n&#91;Install]\nWantedBy=multi-user.target\nEOF\n    systemctl daemon-reload\n    systemctl enable --now komari cloudflared\n\nelif &#91; -f \/sbin\/openrc-run ]; then\n    # OpenRC: \u539f\u751f\u652f\u6301\u65e5\u5fd7\u6587\u4ef6\u914d\u7f6e\n    cat > \/etc\/init.d\/komari &lt;&lt;EOF\n#!\/sbin\/openrc-run\nname=\"komari\"\ncommand=\"\/opt\/komari\/komari\"\ncommand_args=\"server\"\ncommand_user=\"root\"\ndirectory=\"\/opt\/komari\"\npidfile=\"\/run\/komari.pid\"\ncommand_background=\"yes\"\noutput_log=\"\/var\/log\/komari.log\"\nerror_log=\"\/var\/log\/komari.log\"\nrespawn_delay=5\ndepend() { need net; }\nEOF\n    cat > \/etc\/init.d\/cloudflared &lt;&lt;EOF\n#!\/sbin\/openrc-run\nname=\"cloudflared\"\ncommand=\"\/usr\/local\/bin\/cloudflared\"\ncommand_args=\"tunnel run --token ${CF_TOKEN}\"\ncommand_user=\"root\"\npidfile=\"\/run\/cloudflared.pid\"\ncommand_background=\"yes\"\noutput_log=\"\/dev\/null\"\nerror_log=\"\/dev\/null\"\nrespawn_delay=5\ndepend() { need net; use dns; }\nEOF\n    chmod +x \/etc\/init.d\/komari \/etc\/init.d\/cloudflared\n    rc-update add komari default\n    rc-update add cloudflared default\n    service komari restart\n    service cloudflared restart\nfi\n\n# --- 4. \u7ed3\u679c\u63d0\u793a ---\necho \"================================================\"\necho \"\u2705 \u90e8\u7f72\u5df2\u5b8c\u6210\uff01\"\necho \"\"\necho \"\ud83d\udd0d \u67e5\u770b\u521d\u59cb\u5bc6\u7801\uff0c\u8bf7\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\uff1a\"\necho \"   grep -E 'Password|User' \/var\/log\/komari.log\"\necho \"\"<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u7b2c\u4e8c\u6b65\uff1a\u914d\u7f6e Cloudflare \u516c\u7f51\u6620\u5c04\uff08\u5fc5\u505a\uff09<\/h2>\n\n\n\n<p><br>\u811a\u672c\u8fd0\u884c\u6210\u529f\u540e\uff0cCloudflare Tunnel \u5df2\u7ecf\u6253\u901a\uff0c\u4f46\u8fd8\u9700\u8981\u5728 CF \u540e\u53f0\u5c06\u6d41\u91cf\u8f6c\u53d1\u5230 Komari \u7684\u9ed8\u8ba4\u7aef\u53e3 25774\u3002<\/p>\n\n\n\n<p>\u56de\u5230 Cloudflare Zero Trust \u9762\u677f\u3002<\/p>\n\n\n\n<p>\u70b9\u51fb\u5de6\u4fa7\u83dc\u5355 Networks -&gt; Tunnels\u3002<\/p>\n\n\n\n<p>\u627e\u5230\u72b6\u6001\u663e\u793a\u4e3a Healthy \u7684 Tunnel\uff0c\u70b9\u51fb\u53f3\u4fa7\u7684\u4e09\u4e2a\u70b9\uff0c\u9009\u62e9 Configure\u3002<\/p>\n\n\n\n<p>\u70b9\u51fb\u4e0a\u65b9\u7684 Public Hostname \u6807\u7b7e\u9875\uff0c\u70b9\u51fb Add a public hostname\u3002<\/p>\n\n\n\n<p>\u586b\u5199\u5173\u952e\u4fe1\u606f\uff08\u5982\u4e0b\u56fe\u914d\u7f6e\uff09\uff1a<\/p>\n\n\n\n<p>Subdomain: \u8f93\u5165\u4f60\u60f3\u8981\u7684\u524d\u7f00\uff08\u4f8b\u5982 status\uff09\u3002<\/p>\n\n\n\n<p>Domain: \u9009\u62e9\u4f60\u7684\u57df\u540d\u3002<\/p>\n\n\n\n<p>Path: \u7559\u7a7a\u3002<\/p>\n\n\n\n<p>Service:<\/p>\n\n\n\n<p>Type \u9009\u62e9 HTTP<\/p>\n\n\n\n<p>URL \u586b\u5199 localhost:25774<\/p>\n\n\n\n<p>\u70b9\u51fb\u53f3\u4e0b\u89d2\u7684 Save hostname \u4fdd\u5b58\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\ud83c\udf89 \u5b8c\u6210<\/h2>\n\n\n\n<p><br>\u73b0\u5728\uff0c\u6253\u5f00\u6d4f\u89c8\u5668\u8bbf\u95ee http(s):status.\u4f60\u7684\u57df\u540d.com\uff0c\u5373\u53ef\u770b\u5230 Komari \u63a2\u9488\u9762\u677f\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u5378\u8f7d\u8fc7\u7a0b\u4e5f\u975e\u5e38\u7b80\u5355\u3002\u4e3a\u4e86\u65b9\u4fbf\u4f60\uff0c\u6211\u540c\u6837\u51c6\u5907\u4e86\u4e00\u4e2a\u201c\u5168\u7cfb\u7edf\u901a\u7528\u201d\u7684\u5378\u8f7d\u811a\u672c\u3002<\/strong><\/h2>\n\n\n\n<p>\u5b83\u4f1a\u81ea\u52a8\u68c0\u6d4b\u4f60\u7684\u7cfb\u7edf\uff08Systemd \u6216 OpenRC\uff09\uff0c\u505c\u6b62\u670d\u52a1\u3001\u53d6\u6d88\u5f00\u673a\u81ea\u542f\u3001\u5e76\u5220\u9664\u76f8\u5173\u7684\u6587\u4ef6\u3002<\/p>\n\n\n\n<p>\ud83d\uddd1\ufe0f \u4e00\u952e\u5378\u8f7d\u811a\u672c<br>\u590d\u5236\u4e0b\u9762\u7684\u4ee3\u7801\u5230 SSH \u7ec8\u7aef\u8fd0\u884c\u5373\u53ef\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#!\/bin\/sh\n\necho \"\u26a0\ufe0f  \u6b63\u5728\u5f00\u59cb\u5378\u8f7d Komari \u548c Cloudflared...\"\n\n# --- 1. \u505c\u6b62\u670d\u52a1\u5e76\u6e05\u7406\u542f\u52a8\u9879 ---\n\nif pidof systemd &gt;\/dev\/null 2&gt;&amp;1 || &#91; -d \/run\/systemd\/system ]; then\n    echo \"\u2699\ufe0f  \u68c0\u6d4b\u5230 Systemd\uff0c\u6b63\u5728\u505c\u6b62\u5e76\u79fb\u9664\u670d\u52a1...\"\n    # \u5ffd\u7565\u9519\u8bef\u8f93\u51fa\uff0c\u9632\u6b62\u670d\u52a1\u672c\u8eab\u6ca1\u8fd0\u884c\u5bfc\u81f4\u811a\u672c\u4e2d\u65ad\n    systemctl stop komari cloudflared 2&gt;\/dev\/null\n    systemctl disable komari cloudflared 2&gt;\/dev\/null\n    rm -f \/etc\/systemd\/system\/komari.service\n    rm -f \/etc\/systemd\/system\/cloudflared.service\n    systemctl daemon-reload\n\nelif &#91; -f \/sbin\/openrc-run ]; then\n    echo \"\u2699\ufe0f  \u68c0\u6d4b\u5230 OpenRC (Alpine)\uff0c\u6b63\u5728\u505c\u6b62\u5e76\u79fb\u9664\u670d\u52a1...\"\n    service komari stop 2&gt;\/dev\/null\n    service cloudflared stop 2&gt;\/dev\/null\n    rc-update del komari default 2&gt;\/dev\/null\n    rc-update del cloudflared default 2&gt;\/dev\/null\n    rm -f \/etc\/init.d\/komari\n    rm -f \/etc\/init.d\/cloudflared\nfi\n\n# --- 2. \u5220\u9664\u6587\u4ef6\u548c\u76ee\u5f55 ---\necho \"\ud83d\uddd1\ufe0f  \u6b63\u5728\u6e05\u7406\u6587\u4ef6...\"\n\n# \u5220\u9664 Komari \u4e3b\u7a0b\u5e8f\u548c\u914d\u7f6e\u76ee\u5f55\nrm -rf \/opt\/komari\n\n# \u5220\u9664 Cloudflared \u4e8c\u8fdb\u5236\u6587\u4ef6\n# \u6ce8\u610f\uff1a\u5982\u679c\u4f60\u8fd9\u53f0\u673a\u5668\u4e0a\u8fd8\u8fd0\u884c\u7740\u5176\u4ed6\u975e\u672c\u6b21\u5b89\u88c5\u7684 Tunnel\uff0c\u8bf7\u6ce8\u91ca\u6389\u4e0b\u9762\u8fd9\u4e00\u884c\nrm -f \/usr\/local\/bin\/cloudflared\n\n# \u6e05\u7406 PID \u6587\u4ef6\nrm -f \/run\/komari.pid \/run\/cloudflared.pid\n\necho \"------------------------------------------------\"\necho \"\u2705 \u5378\u8f7d\u5b8c\u6210\uff01\u6240\u6709\u76f8\u5173\u670d\u52a1\u548c\u6587\u4ef6\u5df2\u6e05\u9664\u3002\"\necho \"------------------------------------------------\"<\/code><\/pre>\n\n\n\n<p>\u26a0\ufe0f \u522b\u5fd8\u4e86\u6700\u540e\u4e00\u6b65\uff1a\u6e05\u7406 Cloudflare \u540e\u53f0<br>\u811a\u672c\u53ea\u80fd\u6e05\u7406\u4f60 VPS \u4e0a\u7684\u6587\u4ef6\uff0c\u65e0\u6cd5\u64cd\u4f5c\u4f60\u7684 Cloudflare \u8d26\u6237\u3002\u5378\u8f7d\u540e\uff0c\u5efa\u8bae\u53bb Cloudflare \u540e\u53f0\u505a\u4e2a\u6536\u5c3e\uff1a<\/p>\n\n\n\n<p>\u767b\u5f55 Cloudflare Zero Trust \u9762\u677f\u3002<\/p>\n\n\n\n<p>\u8fdb\u5165 Networks -&gt; Tunnels\u3002<\/p>\n\n\n\n<p>\u4f60\u5e94\u8be5\u4f1a\u770b\u5230\u4e4b\u524d\u7684 Tunnel \u72b6\u6001\u53d8\u6210\u4e86 Down\uff08\u56e0\u4e3a VPS \u4e0a\u7684\u670d\u52a1\u88ab\u5220\u4e86\uff09\u3002<\/p>\n\n\n\n<p>\u70b9\u51fb\u53f3\u4fa7\u4e09\u4e2a\u70b9\uff0c\u9009\u62e9 Delete \u5220\u9664\u8fd9\u4e2a\u4e0d\u518d\u4f7f\u7528\u7684 Tunnel\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u624b\u91cc\u6709\u5404\u79cd\u4e0d\u540c\u7cfb\u7edf\u7684 VPS\uff08Debian, Ubuntu, Alpine\uff09\uff1f\u60f3\u88c5\u4e2a\u63a2\u9488\u76d1\u63a7\uff0c\u4f46\u4e0d\u60f3\u9488\u5bf9\u6bcf\u4e2a\u7cfb\u7edf\u53bb\u6539\u5b89\u88c5\u547d\u4ee4\uff1f \u672c\u6587\u63d0\u4f9b\u4e00\u4e2a\u5168\u81ea\u52a8\u901a\u7528\u811a\u672c\uff0c\u81ea\u52a8&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-38","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/nav.rr.kg\/index.php?rest_route=\/wp\/v2\/posts\/38","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nav.rr.kg\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nav.rr.kg\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nav.rr.kg\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nav.rr.kg\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=38"}],"version-history":[{"count":0,"href":"https:\/\/nav.rr.kg\/index.php?rest_route=\/wp\/v2\/posts\/38\/revisions"}],"wp:attachment":[{"href":"https:\/\/nav.rr.kg\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=38"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nav.rr.kg\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=38"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nav.rr.kg\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=38"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}