1、新建.env里写上 TUNNEL_TOKEN=你的tunnel key
2、docker-compose.yml
version: '3.8'
services:
komari:
image: ghcr.io/komari-monitor/komari:latest
container_name: komari
restart: unless-stopped
volumes:
- ./data:/app/data
# ports:
# - "25774:25774" # 强烈建议:既然用 CF Tunnel,就不需要暴露到宿主机了。这可以防止他人通过 IP 直连绕过 CF
networks:
- tunnel_network
cloudflared:
image: cloudflare/cloudflared:latest
container_name: cloudflared
restart: unless-stopped
command: tunnel --no-autoupdate run --token ${TUNNEL_TOKEN}
networks:
- tunnel_network
networks:
tunnel_network:
name: komari_tunnel_net
隧道的地址填:http://komari:25774
3、为了更安全可以加上application-policy验证,登录可以验证github或自己邮箱验证码
同时保护了/api/clients目录 不用设白名单。这样更安全,也方便。
参见 https://www.nodeseek.com/post-786082-1
能防得住路径穿透这类漏洞吗
@lehuoyisheng #1 auth key的参数就是为了防路径穿透吧 cf帮你挡