31 lines
1.1 KiB
Markdown
31 lines
1.1 KiB
Markdown
# ops/ — 群晖主机侧运维脚本
|
||
|
||
## openclaw-webhook-iptables.sh
|
||
|
||
让 **Gitea 的 webhook 能送达 OpenClaw 容器**(`172.21.0.2:8899`)。
|
||
|
||
- **作用**:在群晖主机上维护两条 iptables 规则
|
||
1. `nat PREROUTING`:主机 8899 → 容器 172.21.0.2:8899(DNAT)
|
||
2. `DOCKER-USER`:放行跨 docker 网络转发(插到最前,绕过隔离 DROP)
|
||
- **幂等**:重复运行不会产生重复规则
|
||
- **需 root**;开机时自动等待 `DOCKER-USER` 链就绪(最多 ~3 分钟)
|
||
|
||
### 部署
|
||
```sh
|
||
sudo mkdir -p /volume1/scripts
|
||
sudo cp ops/openclaw-webhook-iptables.sh /volume1/scripts/
|
||
sudo chmod +x /volume1/scripts/openclaw-webhook-iptables.sh
|
||
```
|
||
DSM → 控制面板 → 任务计划 → 新增(触发的任务)→ 用户账号 root → 计划「开机启动」→ 运行命令:
|
||
```
|
||
sh /volume1/scripts/openclaw-webhook-iptables.sh
|
||
```
|
||
|
||
### 变量
|
||
- `OC_IP`:OpenClaw 容器 IP(默认 `172.21.0.2`)。容器重建后 IP 若变化需同步修改。
|
||
- `PORT`:接收服务端口(默认 `8899`)
|
||
|
||
### 相关
|
||
- 排障全过程与最终方案见 issue **#24**
|
||
- webhook 目标 URL:`http://192.168.27.11:8899/gitea`
|