mirror of
https://github.com/iflytek/skillhub.git
synced 2026-10-09 03:17:52 +00:00
Adds the DingTalk credentials to every path that actually delivers configuration: compose.release.yml (which has no env_file, so variables must be listed explicitly), the Helm secret template and values, the k8s deployment and its secret example. validate-release-config.sh gains DingTalk in its provider loop, so a half-configured pair is rejected the same way. Documents the three-stage strategy contract in the authentication design: a table mapping each deviation -- authorize parameters, token exchange, userinfo loading -- to its interface and current implementations, plus the rule that a provider must never make account decisions itself. Deployment notes and both FAQs now cover DingTalk, including the shared trap with Feishu: their emails are admin-recorded and never confirmed, so emailVerified is always false and an EMAIL_DOMAIN access policy would reject every login through either provider. Signed-off-by: XiaoSeS <87064762+XiaoSeS@users.noreply.github.com>
45 lines
1.5 KiB
Text
45 lines
1.5 KiB
Text
# SkillHub Secret 配置
|
||
# 复制此文件为 secret.yaml 并修改值
|
||
# cp secret.yaml.example secret.yaml
|
||
|
||
apiVersion: v1
|
||
kind: Secret
|
||
metadata:
|
||
name: skillhub-secret
|
||
type: Opaque
|
||
stringData:
|
||
# PostgreSQL 连接配置
|
||
# 使用外部数据库:修改主机地址和端口
|
||
# 使用内置数据库(overlays/with-infra):保持 postgres:5432
|
||
spring-datasource-url: jdbc:postgresql://postgres:5432/skillhub
|
||
spring-datasource-username: skillhub
|
||
spring-datasource-password: change-me
|
||
|
||
# Redis 数据节点密码(单机、Sentinel 与 Cluster 共用;无密码时留空)
|
||
redis-password: ""
|
||
# Redis Sentinel 独立密码;与数据节点相同时也可填写同一个值
|
||
redis-sentinel-password: ""
|
||
|
||
# Bootstrap 管理员密码(敏感)
|
||
bootstrap-admin-password: ChangeMe!2026
|
||
|
||
# GitHub OAuth(可选,用于 GitHub 登录)
|
||
oauth2-github-client-id: ""
|
||
oauth2-github-client-secret: ""
|
||
|
||
# 飞书 OAuth(可选,用于飞书登录;留空则登录页不展示该入口)
|
||
oauth2-feishu-client-id: ""
|
||
oauth2-feishu-client-secret: ""
|
||
|
||
# 钉钉 OAuth(可选,用于钉钉登录;留空则登录页不展示该入口)
|
||
oauth2-dingtalk-client-id: ""
|
||
oauth2-dingtalk-client-secret: ""
|
||
|
||
# LLM 配置(可选,用于技能扫描)
|
||
skill-scanner-llm-api-key: ""
|
||
skill-scanner-llm-base-url: ""
|
||
skill-scanner-llm-model: ""
|
||
|
||
# S3 存储配置(可选,使用 S3/OSS 时配置)
|
||
skillhub-storage-s3-access-key: ""
|
||
skillhub-storage-s3-secret-key: ""
|