Excalidraw

An open source virtual hand-drawn style whiteboard.

Accessing IT-Tools

  • 打开浏览器并访问: https://<SERVER_IP>
  • A browser SSL warning is expected (self-signed certificate)
  • Authentication is required (Basic Auth popup)
  • Authentication method: HTTP Basic Auth
  • Credentials are stored securely in: /root/.cloudzy-creds

重要文件和目录

  • 安装目录: /root/excalidraw
  • Docker Compose 文件: /root/excalidraw/docker-compose.yml
  • 已保存的凭据: /root/.cloudzy-creds
  • Nginx virtual host: /etc/nginx/sites-available/excalidraw.conf
  • Basic Auth file: /etc/nginx/auth/excalidraw.htpasswd
  • TLS certificates: /etc/nginx/ssl

安全注意事项

  • IT-Tools is not exposed directly to the network.
  • Only Nginx listens on public ports.
  • Access is protected via Basic Auth.
  • TLS uses a self-signed certificate.
  • Credentials are stored with restrictive permissions.

为域名启用SSL

1. 将您的域名指向服务器IP地址。

2. 编辑 Nginx 配置文件并替换两处 server_name <IP>; 使用您的域名 (<your-domain>) 同时适用于 HTTP(端口 80)和 HTTPS(端口 443)的封堵:

vim /etc/nginx/sites-available/excalidraw.conf

3. 安装 Certbot:

apt install -y certbot python3-certbot-nginx

4. 运行以下命令以生成有效的 Let’s Encrypt 证书:

certbot certonly --nginx --non-interactive --agree-tos --email [email protected] -d yourdomain.com

5. 在 Nginx 配置中替换 SSL 路径:

vim /etc/nginx/sites-available/excalidraw.conf
# Before:
    # ssl_certificate /etc/nginx/ssl/fullchain.pem;
    # ssl_certificate_key /etc/nginx/ssl/privkey.pem;
# After:
    # ssl_certificate /etc/letsencrypt/live/yourdomain.com/fullchain.pem;
    # ssl_certificate_key /etc/letsencrypt/live/yourdomain.com/privkey.pem;

6. 重启 Nginx 以应用更改:

systemctl restart nginx

7. 打开浏览器并访问: https://yourdomain.com

注释

  • Self-hosted instance does not yet support features like sharing or collaboration.
  • Always check Nginx and Docker logs if encountering issues.

申请详情