Files
2026-02-03 12:25:40 +00:00

447 lines
12 KiB
YAML

# OpenClaw AKS 部署文件
# 包含沙箱功能 (DinD 模式)
#
# 部署步骤:
# 1. 先将 ACR 附加到 AKS: az aks update --name <aks> --resource-group <rg> --attach-acr openclawacr
# 2. 部署: kubectl apply -f openclaw-deploy.yaml
# 3. 查看状态: kubectl get pods -n openclaw
# 4. 查看日志: kubectl logs -n openclaw -l app=openclaw -c gateway -f
---
apiVersion: v1
kind: Namespace
metadata:
name: openclaw
---
# Secret: 存储敏感信息
apiVersion: v1
kind: Secret
metadata:
name: openclaw-secrets
namespace: openclaw
type: Opaque
stringData:
# Gateway 认证令牌
OPENCLAW_GATEWAY_TOKEN: "07f99167450cffe6c236a3da36ac3c029f708bee54d742820b523b990d3ba0d4"
# LiteLLM API Key
LITELLM_API_KEY: "sk-litellm-taiji-prod-8f3a9b2c4d5e6f7g"
# 飞书配置
FEISHU_APP_ID: "cli_a90af793703a9bcc"
FEISHU_APP_SECRET: "16Df1ByGy5frbdj7Vm5azbLOSBcprbaw"
# Telegram Bot Token
TELEGRAM_BOT_TOKEN: "8550418255:AAF50xr0MvNwZ4lqpW5PI5tZQ9uRZymKWvc"
# Gateway Auth Token (Web UI 用)
GATEWAY_AUTH_TOKEN: "6b8c483a5495fa1a0babe425504fcbf0633bb1ca8e8ed0fa0a89dfa30267636a"
---
# ConfigMap: OpenClaw 配置文件
apiVersion: v1
kind: ConfigMap
metadata:
name: openclaw-config
namespace: openclaw
data:
openclaw.json: |
{
"meta": {
"lastTouchedVersion": "2026.1.30"
},
"models": {
"providers": {
"litellm": {
"baseUrl": "https://litellm.graystone-fb459c5d.southeastasia.azurecontainerapps.io/v1",
"apiKey": "${LITELLM_API_KEY}",
"api": "openai-completions",
"models": [
{
"id": "taiji/gemini-2.5-flash",
"name": "Gemini 2.5 Flash",
"reasoning": false,
"input": ["text"],
"cost": { "input": 0, "output": 0, "cacheRead": 0, "cacheWrite": 0 },
"contextWindow": 1000000,
"maxTokens": 8192
}
]
}
}
},
"agents": {
"defaults": {
"model": {
"primary": "litellm/taiji/gemini-2.5-flash"
},
"models": {
"litellm/taiji/gemini-2.5-flash": {
"alias": "gemini-2.5-flash"
}
},
"workspace": "/home/node/.openclaw/workspace",
"compaction": { "mode": "safeguard" },
"maxConcurrent": 4,
"subagents": { "maxConcurrent": 8 },
"sandbox": {
"mode": "all",
"workspaceAccess": "rw",
"scope": "agent",
"docker": {
"image": "openclawacr.azurecr.io/openclaw-sandbox:arm64",
"network": "bridge"
},
"browser": {
"enabled": true,
"image": "openclawacr.azurecr.io/openclaw-sandbox-browser:arm64"
}
}
}
},
"messages": {
"ackReactionScope": "group-mentions"
},
"commands": {
"native": "auto",
"nativeSkills": "auto"
},
"channels": {
"telegram": {
"enabled": true,
"dmPolicy": "pairing",
"botToken": "${TELEGRAM_BOT_TOKEN}",
"groupPolicy": "allowlist",
"streamMode": "partial"
},
"feishu": {
"appId": "${FEISHU_APP_ID}",
"appSecret": "${FEISHU_APP_SECRET}",
"enabled": true,
"connectionMode": "websocket",
"dmPolicy": "open",
"groupPolicy": "open"
}
},
"gateway": {
"port": 18789,
"mode": "local",
"bind": "lan",
"auth": {
"mode": "token",
"token": "${GATEWAY_AUTH_TOKEN}"
},
"http": {
"endpoints": {
"chatCompletions": { "enabled": true }
}
}
},
"plugins": {
"entries": {
"telegram": { "enabled": true },
"feishu": { "enabled": true }
},
"installs": {
"feishu": {
"source": "npm",
"spec": "@m1heng-clawd/feishu",
"installPath": "/home/node/.openclaw/extensions/feishu",
"version": "0.1.6"
}
}
},
"tools": {
"sandbox": {
"tools": {
"allow": [
"exec", "process", "read", "write", "edit", "browser",
"sessions_list", "sessions_history", "sessions_send", "sessions_spawn", "session_status"
],
"deny": ["canvas", "nodes", "cron", "discord", "gateway"]
}
}
}
}
---
# PersistentVolumeClaim: 存储 workspace 和配置数据
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: openclaw-data
namespace: openclaw
spec:
accessModes:
- ReadWriteOnce
storageClassName: managed-csi # Azure AKS 默认存储类
resources:
requests:
storage: 10Gi
---
# Deployment: OpenClaw Gateway + DinD Sidecar
apiVersion: apps/v1
kind: Deployment
metadata:
name: openclaw
namespace: openclaw
labels:
app: openclaw
spec:
replicas: 1
selector:
matchLabels:
app: openclaw
template:
metadata:
labels:
app: openclaw
spec:
# 初始化容器:准备配置文件 + 安装飞书插件
initContainers:
# 第一步:使用 OpenClaw 镜像安装飞书插件
- name: plugin-install
image: openclawacr.azurecr.io/openclaw:arm64
command:
- sh
- -c
- |
echo "=== Installing Feishu plugin ==="
cd /home/node
# 创建必要目录
mkdir -p /data/extensions /data/workspace /data/sandboxes
# 安装飞书插件到持久化目录
if [ ! -d "/data/extensions/feishu/node_modules" ]; then
echo "Installing @m1heng-clawd/feishu plugin..."
npm pack @m1heng-clawd/feishu --pack-destination /tmp
mkdir -p /data/extensions/feishu
tar -xzf /tmp/m1heng-clawd-feishu-*.tgz -C /data/extensions/feishu --strip-components=1
cd /data/extensions/feishu && npm install --production
echo "Plugin installed successfully"
else
echo "Plugin already installed, skipping..."
fi
ls -la /data/extensions/feishu/
volumeMounts:
- name: data
mountPath: /data
# 第二步:准备配置文件(替换环境变量)
- name: config-init
image: busybox:1.36
command:
- sh
- -c
- |
# 复制配置文件并替换环境变量占位符
cp /config-template/openclaw.json /config/openclaw.json
sed -i "s|\${LITELLM_API_KEY}|$LITELLM_API_KEY|g" /config/openclaw.json
sed -i "s|\${FEISHU_APP_ID}|$FEISHU_APP_ID|g" /config/openclaw.json
sed -i "s|\${FEISHU_APP_SECRET}|$FEISHU_APP_SECRET|g" /config/openclaw.json
sed -i "s|\${TELEGRAM_BOT_TOKEN}|$TELEGRAM_BOT_TOKEN|g" /config/openclaw.json
sed -i "s|\${GATEWAY_AUTH_TOKEN}|$GATEWAY_AUTH_TOKEN|g" /config/openclaw.json
echo "Config initialized successfully"
cat /config/openclaw.json
env:
- name: LITELLM_API_KEY
valueFrom:
secretKeyRef:
name: openclaw-secrets
key: LITELLM_API_KEY
- name: FEISHU_APP_ID
valueFrom:
secretKeyRef:
name: openclaw-secrets
key: FEISHU_APP_ID
- name: FEISHU_APP_SECRET
valueFrom:
secretKeyRef:
name: openclaw-secrets
key: FEISHU_APP_SECRET
- name: TELEGRAM_BOT_TOKEN
valueFrom:
secretKeyRef:
name: openclaw-secrets
key: TELEGRAM_BOT_TOKEN
- name: GATEWAY_AUTH_TOKEN
valueFrom:
secretKeyRef:
name: openclaw-secrets
key: GATEWAY_AUTH_TOKEN
volumeMounts:
- name: config-template
mountPath: /config-template
- name: config
mountPath: /config
- name: data
mountPath: /data
containers:
# ========== Gateway 容器 ==========
- name: gateway
image: openclawacr.azurecr.io/openclaw:arm64
ports:
- containerPort: 18789
name: http
- containerPort: 18790
name: bridge
env:
- name: HOME
value: "/home/node"
- name: TERM
value: "xterm-256color"
- name: OPENCLAW_GATEWAY_TOKEN
valueFrom:
secretKeyRef:
name: openclaw-secrets
key: OPENCLAW_GATEWAY_TOKEN
# Docker 连接到 DinD sidecar
- name: DOCKER_HOST
value: "tcp://localhost:2375"
volumeMounts:
- name: config
mountPath: /home/node/.openclaw/openclaw.json
subPath: openclaw.json
- name: data
mountPath: /home/node/.openclaw/workspace
subPath: workspace
- name: data
mountPath: /home/node/.openclaw/sandboxes
subPath: sandboxes
- name: data
mountPath: /home/node/.openclaw/extensions
subPath: extensions
command:
- node
- dist/index.js
- gateway
- --bind
- lan
- --port
- "18789"
resources:
requests:
memory: "512Mi"
cpu: "250m"
limits:
memory: "2Gi"
cpu: "2000m"
readinessProbe:
httpGet:
path: /health
port: 18789
initialDelaySeconds: 10
periodSeconds: 10
livenessProbe:
httpGet:
path: /health
port: 18789
initialDelaySeconds: 30
periodSeconds: 30
# ========== DinD Sidecar (用于沙箱) ==========
- name: dind
image: docker:24-dind
securityContext:
privileged: true # DinD 需要特权模式
env:
- name: DOCKER_TLS_CERTDIR
value: "" # 禁用 TLS,内部通信
ports:
- containerPort: 2375
name: docker
volumeMounts:
- name: docker-storage
mountPath: /var/lib/docker
- name: data
mountPath: /home/node/.openclaw/workspace
subPath: workspace
- name: data
mountPath: /home/node/.openclaw/sandboxes
subPath: sandboxes
resources:
requests:
memory: "512Mi"
cpu: "250m"
limits:
memory: "4Gi"
cpu: "2000m"
volumes:
- name: config-template
configMap:
name: openclaw-config
- name: config
emptyDir: {}
- name: data
persistentVolumeClaim:
claimName: openclaw-data
- name: docker-storage
emptyDir: {}
---
# Service: 暴露 Gateway 端口
apiVersion: v1
kind: Service
metadata:
name: openclaw
namespace: openclaw
spec:
selector:
app: openclaw
ports:
- name: http
port: 18789
targetPort: 18789
- name: bridge
port: 18790
targetPort: 18790
type: ClusterIP
---
# Ingress: 外部访问 (可选,需要 Ingress Controller)
# 如果使用 Azure Application Gateway 或 nginx-ingress
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: openclaw
namespace: openclaw
annotations:
# 如果使用 nginx-ingress:
# kubernetes.io/ingress.class: nginx
# nginx.ingress.kubernetes.io/websocket-services: openclaw
# 如果使用 Azure Application Gateway:
# kubernetes.io/ingress.class: azure/application-gateway
kubernetes.io/ingress.class: nginx
nginx.ingress.kubernetes.io/proxy-read-timeout: "3600"
nginx.ingress.kubernetes.io/proxy-send-timeout: "3600"
nginx.ingress.kubernetes.io/websocket-services: "openclaw"
# 启用 HTTPS 重定向(可选,如果希望强制 HTTPS)
# nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
# TLS 配置:使用自签名证书
# 使用前需要先运行: ./generate-self-signed-cert.sh <your-domain> openclaw openclaw-tls
tls:
- hosts:
- openclaw.yourdomain.com # ← 修改为你的域名
secretName: openclaw-tls # ← 对应 Kubernetes Secret 名称
rules:
- host: openclaw.yourdomain.com # ← 修改为你的域名
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: openclaw
port:
number: 18789