跳到內容
繁體中文

安裝包與離線安裝

安裝包是 Linux 主機的主要部署入口。發行附件包含安裝包、SHA-256 清單、Sigstore 驗證資料、映像清單,以及對應架構的離線映像包。支援 x86_64 與 aarch64。取得附件後先驗證,再安裝。

從 1.14.0 起,Linux 主機可執行固定檔名的發行版引導腳本。它下載最新版安裝包與 SHA256SUMS、核對安裝包 SHA-256 後解壓到 /opt/custodexa,並交給 custodexa.sh 選單:

Terminal window
set -o pipefail
curl -fsSL https://github.com/custodexa/custodexa/releases/latest/download/get-custodexa.sh | sudo bash

指定版本及目錄:

Terminal window
set -o pipefail
curl -fsSL https://github.com/custodexa/custodexa/releases/latest/download/get-custodexa.sh | sudo bash -s -- --version 1.14.0 --dir /srv/custodexa

若要先檢視引導腳本:

Terminal window
curl -fsSLO https://github.com/custodexa/custodexa/releases/latest/download/get-custodexa.sh
sudo bash get-custodexa.sh

在 Bash 或 Zsh 中先執行 set -o pipefail,引導腳本下載失敗時整段管線才會回報非零結束碼。先下載再執行時,請確認下載成功後才執行第二行。將 CX_GET_RELEASE_BASE 指向其他發行端點,表示同時信任該來源的安裝包與 SHA256SUMS;雜湊相符本身不證明發行者身分。

引導腳本不驗證安裝包簽章;請依下方步驟手動驗證。映像簽章由 custodexa.sh 處理。已有部署不會覆寫,而是交給現有的管理腳本。

從 1.14.0 Release 取得 custodexa-1.14.0.tar.gz、SHA256SUMS 與 SHA256SUMS.sigstore.json,在附件所在目錄執行:

Terminal window
sha256sum --ignore-missing -c SHA256SUMS
cosign verify-blob --bundle SHA256SUMS.sigstore.json \
--certificate-identity "https://github.com/custodexa/custodexa/.github/workflows/release-images.yml@refs/tags/v1.14.0" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
SHA256SUMS
sudo tar -xzf custodexa-1.14.0.tar.gz -C /opt
sudo /opt/custodexa/custodexa.sh install

安裝程序檢查主機與 Docker 環境、產生 .env、取得並驗證映像、啟動服務及等候健康檢查。映像依本機已有、離線包、GHCR、Docker Hub、原始碼建置的順序取得。資料落在 DATA_PATH。初始化密碼只供首次登入,登入後依畫面更換。

安裝入口是 custodexa.sh。install 與選單可選「自動」或「從安裝包內原始碼建置」;指令使用 --images-from auto|source,未指定即為 auto。自動來源依序查看本機映像、離線包、GHCR、Docker Hub,最後才在本機建置。選 source 會核對安裝包內原始碼後建置 backend 與 frontend;上游映像、基底映像與建置依賴仍須取得,不是完全離線選項。--images <映像包> 只與 auto 併用。取得與核對等長步驟會先顯示 [ .. ],完成後顯示 [ OK ]、[WARN] 或 [FAIL]。

Terminal window
sudo /opt/custodexa/custodexa.sh install --images-from source

下載與主機架構相符的 custodexa-images-1.14.0-amd64.tar 或 aarch64 對應附件,並將同版 SHA256SUMS 放在映像包所在目錄。以下以兩個檔案都位於 /srv/custodexa-1.14.0/ 為例,先載入再安裝:

Terminal window
sudo /opt/custodexa/custodexa.sh load /srv/custodexa-1.14.0/custodexa-images-1.14.0-amd64.tar
sudo /opt/custodexa/custodexa.sh install

不帶參數執行 sudo /opt/custodexa/custodexa.sh 可開啟互動選單,選擇安裝、載入映像、狀態、升級與備份。--help 列出子命令;--lang zh-TW、--lang en、--lang ja 指定選單語言。安裝後以 sudo /opt/custodexa/custodexa.sh status 檢查服務與版本。

部署完成後,登入事件與受管會話進入稽核。文字會話的指令紀錄供搜尋,錄影是事實來源;無回顯輸入不留指令文字紀錄。查詢主控台的結構化語句紀錄則是該查詢的事實來源。