Files
lisglosips/docs/SERVER_B_HOMER_MONITORING_RUNBOOK.md
T

124 lines
5.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Server B HOMER 与基础监控 Runbook
本文记录 S06 在 Server B 建立的 HOMER、HEP 接收、Prometheus、Grafana 和 Exporter 基线,以及 Server A 的 Node Exporter 采集入口。当前环境是本地 KVM 开发环境,不是阿里云生产环境。
## 1. 固定版本
| 组件 | 版本/来源 | 管理方式 |
| --- | --- | --- |
| PostgreSQL | `16.14` | Ubuntu 官方包,用于 HOMER 数据库 |
| Heplify Server | `github.com/sipcapture/heplify-server@v1.60.2-0.20260512101233-c74dc3d216ac` | Go 构建,二进制 SHA-256 记录在 `infra/server-b/s06/versions.env` |
| Homer App | `github.com/sipcapture/homer-app@v0.0.0-20251021161517-9b1336352aa0` | Go 构建,监听 `127.0.0.1:9080` |
| Prometheus | `2.45.3` | Ubuntu security/updates 包,自定义 `lisglosips-prometheus.service` |
| Grafana | `13.0.2` | Tsinghua HTTPS 镜像包,包哈希来自官方 Packages 元数据 |
| Node Exporter | `1.7.0` | A/B 两机 Ubuntu 包,自定义 `lisglosips-node-exporter.service` |
| MySQL Exporter | `0.15.0` | Ubuntu 包,监听 `127.0.0.1:9104` |
| PostgreSQL Exporter | `0.15.0` | Ubuntu 包,监听 `127.0.0.1:9187` |
| Redis Exporter | `1.86.0` | Go 构建,监听 `127.0.0.1:9121` |
Docker 与 Compose 已安装但运行时禁用。最初计划使用 HOMER10 Docker 架构,但 Docker/GitHub 对象存储在当前代理链路下下载 blob 反复 EOFS06 改为原生 HOMER7/PostgreSQL/Heplify 部署。不要在后续会话里反复重试 Docker 镜像,除非网络条件已明确修复。
## 2. 目录与端口
| 项目 | 路径/端口 |
| --- | --- |
| HOMER PostgreSQL 数据 | `/data/homer/postgresql` |
| HOMER 配置 | `/etc/homer/webapp_config.json` |
| Heplify HEP UDP | `100.90.90.91:9060/udp` |
| Heplify Metrics | `127.0.0.1:9096` |
| Homer App | `127.0.0.1:9080`,经 `https://homer.lisglosips.local/` 暴露 |
| Prometheus | `127.0.0.1:9090` |
| Grafana | `127.0.0.1:3001`,经 `https://grafana.lisglosips.local/` 暴露 |
| B Node Exporter | `127.0.0.1:9100` |
| A Node Exporter | `100.90.90.90:9100`,仅允许 B 访问 |
开发证书已重新签发,SAN 包含 `grafana.lisglosips.local``homer.lisglosips.local`。本地 CA 公钥副本仍在 `.codex-private/tls/lisglosips-dev-ca.crt`
## 3. 关键服务
Server B
```text
postgresql.service
heplify-server.service
homer-app.service
lisglosips-prometheus.service
grafana-server.service
lisglosips-node-exporter.service
lisglosips-mysqld-exporter.service
lisglosips-postgres-exporter.service
lisglosips-redis-exporter.service
nginx.service
```
Server A
```text
lisglosips-exporter-firewall.service
lisglosips-node-exporter.service
```
A 机使用独立 `nftables``inet lisglosips_s06` 保护 9100,只允许 `100.90.90.91` 抓取。Ubuntu 包自带的 `prometheus-node-exporter.service` 已 mask,避免抢占端口。A/B 两机的 `openipmi.service` 已 mask,因为 KVM 虚拟机不支持该驱动。
## 4. 验收命令
Prometheus targets
```bash
curl -fsS http://127.0.0.1:9090/api/v1/targets
```
预期 7 个 target 全部 `up``prometheus``node/server-a``node/server-b``mysql``postgresql_homer``redis``heplify_server`
HEP 入库测试:从 A 发送 HEPv3 UDP 到 B 的 `9060`,然后在 B 查询 `homer_data.hep_proto_1_call`。S06 验收已确认测试 `INVITE` 入库,`method=INVITE``srcIp=100.90.90.90``dstIp=100.90.90.91`
HTTPS
```bash
curl --fail --cacert /etc/lisglosips/pki/ca/lisglosips-dev-ca.crt \
https://127.0.0.1/api/health
```
Windows 本机可使用:
```powershell
curl.exe --ssl-no-revoke --cacert .codex-private/tls/lisglosips-dev-ca.crt \
--resolve grafana.lisglosips.local:443:100.90.90.91 \
https://grafana.lisglosips.local/api/health
```
Grafana 已预置两个 datasource`Prometheus``HOMER PostgreSQL`;已预置 Dashboard`LisgloSIPS Infrastructure Overview`
## 5. 回滚
S06 变更前备份:
```text
B: /var/backups/lisglosips-s06/20260620T132440Z
A: /var/backups/lisglosips-s06/20260620225517
```
回滚原则:
1. 先停止 S06 新增服务,再恢复备份配置。
2. PostgreSQL 数据目录 `/data/homer/postgresql` 不直接删除;需要退回时先备份当前目录。
3. Nginx 只移除 `grafana.lisglosips.local``homer.lisglosips.local` 站点,不影响 S05 Web 入口。
4. A 机只删除 `inet lisglosips_s06` 表和两个 S06 服务,不碰 OpenSIPS/RTP 配置。
常用命令:
```bash
sudo systemctl stop heplify-server homer-app lisglosips-prometheus grafana-server
sudo systemctl stop lisglosips-mysqld-exporter lisglosips-postgres-exporter lisglosips-redis-exporter
sudo systemctl disable --now lisglosips-exporter-firewall lisglosips-node-exporter
sudo nft delete table inet lisglosips_s06
```
## 6. 已知事项
- 当前 HOMER Web 为最小状态页,HOMER API、HEP 接收和 PostgreSQL 入库已可用;完整 HOMER UI 静态包等网络条件稳定后再补。
- Grafana 插件在线检查已关闭,避免受限网络下反复报错。
- Docker 已安装但禁用,S06 不依赖 Docker 运行。
- A 机 `nftables` 表只保护 Node Exporter 9100,不替代后续 S18/S20 的 Server A 完整防火墙设计。
- 生产迁移时必须替换开发 CA、正式域名、正式安全组和云监控告警策略。