ops-maintenance
运维助手 v3.3.10 - 本地/远程/集群监控 (健康检查、日志分析、性能监控、批量操作、密码过期检查、告警通知、定时巡检、Docker健康、SSL证书、安全审计、网络诊断) Skill: ops-maintenance Owner: fish1981bimmer Summary: 运维助手 v3.3.10 - 本地/远程/集群监控 (健康检查、日志分析、性能监控、批量操作、密码过期检查、告警通知、定时巡检、Docker健康、SSL证书、安全审计、网络诊断) Tags: latest:3.3.10 Version history: v3.3.10 | 2026-09-06T05:03:26.214Z | auto ops-maintenance v3.3.10 - 更新版本号至 v3.3.10,文档描述同步升级。 - 无功能、命令或配置变更,仅为版本及文档信息维护。 v3.3.9 | 2026-09-06T05:00:49.809Z | auto ops-maintenance v3.3.9 Changelog - Bump version from 3.3.8 to 3.3.9 in package
Rank
62
Safety
84
Downloads
1.7k
Updated
Oct 10, 2026
Version
3.3.10
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.7K downloadsadoption · observed Oct 10, 2026
- Latest release
- 3.3.10release · observed Sep 6, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17dzz5rp1x5wrb7s33vv04cb984wjf8:ops-maintenance- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-fish1981bimmer-ops-maintenance/snapshot"
Documentation
CLAWHUB
160,000 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: ops-maintenance
description: 运维助手 v3.3.10 - 本地/远程/集群监控 (健康检查、日志分析、性能监控、批量操作、密码过期检查、告警通知、定时巡检、Docker健康、SSL证书、安全审计、网络诊断)
userInvocable: true
argumentHint: <health|logs|perf|ports|process|disk|password|network|report|audit|docker|ssl|security|cluster> [args]
allowedTools:
- Bash
- Read
---
# 运维助手 (ops-maintenance) v3.3.10
专业的运维助手,支持单服务器和多服务器集群监控。
## v3.3.8 新功能
### 网络诊断
```
/ops-maintenance network # 网络诊断(ping/dns/port)
/ops-maintenance network <host> # 指定主机检测
```
### 运维报告
```
/ops-maintenance report # 集群状态摘要报告
```
### 操作审计
```
/ops-maintenance audit # 查看审计日志统计
```
### Docker 健康巡检
```
/ops-maintenance docker # Docker容器健康检查
```
### SSL 证书监控
```
/ops-maintenance ssl # SSL证书检查
```
### 安全审计
```
/ops-maintenance security # 安全配置审计
```
### 远程密码检查
```
/ops-maintenance user@host password # 远程服务器密码过期检查
```
## 功能命令
### 健康检查
```
/ops-maintenance health # 本地
/ops-maintenance user@host health # 远程 SSH
```
### 日志分析
```
/ops-maintenance logs [关键词] # 本地
/ops-maintenance user@host logs error # 远程
```
### 性能监控 (本地)
```
/ops-maintenance perf
```
### 端口检查
```
/ops-maintenance ports [端口] # 本地
/ops-maintenance user@host ports 80 # 远程
```
### 进程检查
```
/ops-maintenance process [名称] # 本地
/ops-maintenance user@host process nginx # 远程
```
### 磁盘使用
```
/ops-maintenance disk # 本地
/ops-maintenance user@host disk # 远程
```
### 密码过期检查
```
/ops-maintenance password # 检查所有配置服务器的密码过期状态
```
## 远程服务器配置
### 方式 1: SSH Config (推荐)
在 `~/.ssh/config` 中配置:
```
Host myserver
HostName 192.168.1.100
User root
Port 22
IdentityFile ~/.ssh/id_rsa
```
### 方式 2: 直接指定
```
[email protected] health
[email protected]:2222 disk
```
## 支持的远程操作
- health: 系统负载、内存、磁盘、服务状态
- logs: 远程日志搜索
- ports: 端口占用检查
- process: 进程查找
- disk: 磁盘使用分析
- password: 远程密码过期检查(v3.3.8新增)
## 输出格式
返回 Markdown 格式结果,包含:
- 标题 (emoji + 操作名 + 服务器)
- 代码块中的命令输出
- 关键发现和建议
### 密码过期检查输出示例
```
### 🔐 密码过期检查 (本地)
| 用户 | 上次修改 | 过期日期 | 最大天数 | 状态 |
|------|----------|----------|----------|------|
| root | 2024-01-15 | 2024-07-15 | 180 | ✅ 有效 |
| admin | 2024-02-01 | never | 90 | ⚠️ 永不过期 |
| user1 | 2023-11-01 | 2024-01-01 | 60 | ❌ 已过期 |
```
## 多服务器集群管理
### 查看集群状态
```
/ops-maintenance cluster # 查看所有服务器状态
/ops-maintenance cluster @production # 按标签筛选
```
### 批量添加服务器
```
# 直接添加多个 IP
/ops-maintenance batch-add 192.168.1.100 192.168.1.101 192.168.1.102
# 带端口
/ops-maintenance batch-add 192.168.1.100:2222 192.168.1.101:22
# 带用户
/ops-maintenance batch-add [email protected] [email protected]
# 完整格式
/ops-maintenance batch-add user@host:port user2@host2:port
# CSV 格式 (多行)
/ops-maintenance import-servers <<EOF
192.168.1.100,22,root,web-1,production;web
192.168.1.101,22,admin,db-1,production;database
EOF
# JSON 格式
/ops-maintenance import-servers [{"host":"192.168.1.100","name":"web-1","tags":["prod"]}]
```
### 添加服务器
`skills/ops-maintenance/SKILL.md
---
name: ops-maintenance
version: 3.3.0
description: 运维助手 v3.3 - 支持本地、远程、多服务器集群监控、安全审计、智能日志分析、配置变更追踪、告警通知、定时巡检、Docker容器健康巡检、SSL证书监控
userInvocable: true
argumentHint: <health|security|logs|config|report|perf|ports|process|disk|cluster|alert|patrol|docker-health|ssl|add-server|remove-server|upload|download|list|audit> [args]
allowedTools:
- Bash
- Read
---
# 运维助手 (ops-maintenance) v3.3.0
专业的运维助手,支持单服务器和多服务器集群监控、安全审计、智能日志分析、配置变更追踪、告警通知、定时巡检、Docker容器健康巡检、SSL证书监控。
## v3.3 新功能
### 多渠道通知增强 (v3.3)
- **Slack 支持**: 通过 `ops alert notify slack <config>` 配置 Slack Webhook
- **钉钉支持**: 通过 `ops alert notify dingtalk <config>` 配置钉钉机器人
- **通用 Webhook**: 支持任意 HTTP POST 回调
### CLI 健壮性修复 (v3.3)
- **patrol start 不再阻塞**: 启动后自动退出,后台运行
- **完整的错误处理**: 所有命令失败时返回适当退出码
### 测试覆盖提升 (v3.3)
- **49 个单元测试**: 覆盖安全、告警、巡检、SSL、Docker 核心功能
- **ESM 兼容**: 所有 `require()` 替换为 `import`
### 通知渠道配置示例
```bash
# 飞书
ops alert notify feishu '{"webhookUrl":"https://open.feishu.cn/open-apis/bot/v2/hook/xxx"}'
# 企业微信
ops alert notify wechat '{"webhookUrl":"https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=xxx"}'
# 邮件 (SMTP)
ops alert notify email '{"smtpHost":"smtp.qq.com","smtpPort":465,"smtpUser":"[email protected]","smtpPass":"授权码","from":"[email protected]","to":["收件人@qq.com"]}'
# Webhook
ops alert notify webhook '{"url":"https://hooks.slack.com/services/xxx"}'
# Slack
ops alert notify slack '{"webhookUrl":"https://hooks.slack.com/services/xxx","channel":"#alerts","username":"OpsBot"}'
# 钉钉
ops alert notify dingtalk '{"webhookUrl":"https://oapi.dingtalk.com/robot/send?access_token=xxx"}'
```
## v3.2 新功能
### Docker 容器健康巡检
- **全面巡检**: 自动检查所有容器的健康状况
- **重启检测**: 检测容器重启次数超限,识别启动即崩溃的僵尸容器
- **OOM Kill检测**: 识别因内存不足被Kill的容器
- **健康检查失败**: 检测Docker HEALTHCHECK失败
- **资源超限**: CPU/内存使用率超阈值告警(70%/75%警告, 90%/90%严重)
- **镜像过期**: 检测超过90天未更新的镜像
- **单容器检查**: 支持指定容器名深度检查
### SSL 证书监控
- **批量域名检查**: 支持同时检查多个域名的SSL证书
- **过期告警**: 默认30天前告警,7天前严重告警
- **证书详情**: 显示颁发者、有效期、SAN域名、协议版本
- **链路检查**: 检测SAN不匹配、不安全协议(TLSv1.0/1.1)
- **配置文件支持**: 从 ~/.config/ops-maintenance/ssl-domains.json 加载域名
- **备用方案**: openssl命令作为Node.js TLS的备用检测方式
### 安全审计系统
- **自动安全扫描**: SSH配置、防火墙状态、文件权限、Docker安全、内核参数
- **风险分级**: high/medium/low 三级风险分类
- **修复建议**: 每项发现自动生成修复建议
- **合规检查**: 对照安全基线自动评估
### 智能日志分析
- **趋势统计**: 按时间段统计错误量,生成时间线
- **模式识别**: 相似日志自动聚合,提取通用模式
- **异常检测**: 4种异常检测(错误突增/新模式/超时聚类/连续爆发)
- **多源关联**: 多个日志源的关联分析
- **自动发现**: 自动发现常见日志路径
### 配置变更追踪
- **基线快照**: 为关键配置文件建立SHA256基线
- **变更检测**: 自动检测配置文件变更
- **差异对比**: 变更详情展示(行级diff)
- **变更历史**: 保留完整变更历史记录
- **预设追踪**: 默认追踪nginx/SSH/sysctl/fstab/hosts/DNS/crontab
### 运维报告生成
- **综合报告**: 一键汇总健康/安全/日志/配置四维报告
- **多格式输出**: Markdown / JSON / 纯文本
- **模块可选**: 可选择性跳过某些模块
- **状态总览**: 一目了然的OK/WARN/CRIT状态汇总
### 告警通知系统
- **多渠道通知**: 飞书机器人 / 企业微信 / 邮件 / Webhook / 控制台
- **8种默认告警规则**: 磁盘(80%/90%)、内存(85%/95%)、负载(5/10)、CPU(80%)、服务宕机
- **告警去重**: 同一规则+服务器不重复触发
- **告警静默**: 指定时间内屏蔽重复告警
- **自动恢复检测**: 阈值恢复后自动标记 resolved 并发送恢复通知
- **告警升级**: 按阈值从高到低,优先触发最高级别
- **持久化存储**: 告警记录保存在 ~/.config/ops-maintenance/alerts.json
#### 邮件README.md
# ops-maintenance 2.0 重构完成
## 🎉 重大更新
运维助手已完成 Clean Architecture 架构重构,保持 **100% 向后兼容**。
### 核心改进
| 特性 | v1.x | v2.0 |
|------|------|------|
| 架构 | 单体 1500 行 | 分层清晰 |
| SSH 连接 | 每次新建 | 连接池复用 ✅ |
| 配置管理 | 静态读文件 | 热加载 + CRUD ✅ |
| 缓存 | 无 | 内存 + 文件缓存 ✅ |
| 可测试性 | 难 | 依赖注入,易于测试 ✅ |
| 扩展性 | 硬编码 | 策略模式,插件化 ✅ |
---
## 📦 快速开始
### 安装
```bash
cd ~/.claude/skills/ops-maintenance
npm install
```
### 配置服务器
```bash
# 编辑配置文件
vim ~/.config/ops-maintenance/servers.json
```
示例配置:
```json
[
{
"host": "10.119.120.143",
"port": 22,
"user": "salt",
"name": "DM裸金属服务器",
"tags": ["DB"]
}
]
```
### 设置凭据(安全方式)
```bash
# 使用环境变量(推荐,密码不存文件)
export OPS_CRED_10_119_120_143="salt:Giten!#202501Tab*&"
# 或使用密钥
export OPS_KEY_10_119_120_143="/home/user/.ssh/id_rsa"
```
### 运行
```bash
# 集群健康检查
node run.js cluster
# 密码过期检查
node run.js password
# 指定环境
node run.js health @production
# JSON 输出
node run.js password --json
```
---
## 🏗️ 架构文档
详细架构说明见 [`doc/ARCHITECTURE.md`](doc/ARCHITECTURE.md)
### 目录结构
```
src-new/
├── types.ts # 统一类型定义
├── config/ # 配置层
│ ├── schemas.ts # 类型和接口
│ ├── loader.ts # ConfigManager
│ └── validator.ts # Zod 验证
├── core/ # 领域层
│ ├── entities/ # 实体
│ ├── repositories/ # 仓库接口
│ └── usecases/ # 用例
├── infrastructure/ # 基础设施
│ ├── ssh/ # SSH 客户端 & 池
│ ├── cache/ # 缓存
│ ├── repositories/ # 仓库实现
│ └── monitoring/ # 监控策略
├── presentation/ # 表现层
│ ├── formatters/ # 格式化器
│ ├── cli/ # CLI
│ └── LegacyAdapter.ts # 向后兼容
├── container.ts # 依赖注入容器
├── legacy.ts # 旧版 API 适配
└── index.ts # 新架构入口
```
---
## 🔧 开发
### 编译
```bash
npm run build # 编译到 dist/
npm run build:watch # 监听模式
```
### 测试
```bash
npm test # 运行测试
npm run test:watch # 监听模式
npm run test:coverage # 覆盖率报告
```
### 调试
```bash
node run-dev.js # 开发模式,显示状态
OPS_LOG_LEVEL=debug node run.js cluster # 调试日志
```
---
## 🔐 凭据管理
### 方式 1: 环境变量(推荐)
```bash
# 密码认证
export OPS_CRED_<HOST>="user:password"
# 例如(将 . 替换为 _):
export OPS_CRED_10_119_120_143="salt:password123"
# 密钥认证
export OPS_KEY_<HOST>="/path/to/private/key"
```
### 方式 2: SSH 默认密钥
如果未设置环境变量,自动尝试 `~/.ssh/id_rsa`、`id_ed25519` 等。
### 方式 3: 配置文件(不推荐生产)
扩展 `servers.json` 增加 `password` 或 `keyFile` 字段(仅测试环境使用)。
---
## 🎯 API 使用
### 新架构 API
```typescript
import { initContainer, Server } from 'ops-maintenance'
const container = await initContainer()
const healthUC = container.createHealthCheckUseCase()
const report = await healthUC.execute({
tags: ['production'],
force: true
})
console.log(report)
```
### 旧版 API(完全兼容)
```typescript
const { loadServers, checkAllServersHealth } = require('ops-mainten_meta.json
{
"ownerId": "kn76tyr0ztr0j5fyej0qbchjx584wwjp",
"slug": "ops-maintenance",
"version": "3.3.10",
"publishedAt": 1788671006214
}doc/ARCHITECTURE.md
# ops-maintenance 2.0 架构文档
## 🏗️ 架构概览
### 设计原则
- **Clean Architecture**: 领域层独立,依赖方向向内
- **依赖注入**: 所有依赖通过容器管理,易于测试
- **单一职责**: 每个类/模块只做一件事
- **可测试性**: 核心逻辑不依赖外部设施,易于单元测试
### 分层结构
```
src-new/
├── types.ts # 统一类型定义(简化版)
├── config/
│ ├── schemas.ts # 完整类型定义(原版)
│ ├── loader.ts # ConfigManager - 配置管理
│ ├── validator.ts # Zod 验证
│ └── ICredentialsProvider.ts # 凭据提供者接口
├── core/
│ ├── entities/ # 领域实体
│ ├── repositories/ # 仓库接口
│ └── usecases/ # 用例层(业务逻辑)
├── infrastructure/
│ ├── ssh/ # SSH 客户端 & 连接池
│ ├── cache/ # 缓存实现
│ ├── repositories/ # 仓库实现
│ └── monitoring/ # 监控检查策略
├── presentation/
│ ├── formatters/ # 输出格式化器
│ ├── cli/ # CLI 命令解析
│ └── LegacyAdapter.ts # 向后兼容适配器
├── container.ts # 依赖注入容器
├── legacy.ts # 旧版 API 兼容层
├── index.ts # 新版应用入口
└── exports.ts # 统一导出
```
---
## 🔄 依赖关系
```
┌─────────────────┐
│ presentation │ CLI / Formatter / LegacyAdapter
└────────┬────────┘
│ depends on
┌────────▼────────┐
│ core/usecase │ HealthCheckUseCase, PasswordCheckUseCase
└────────┬────────┘
│ depends on
┌────────▼────────┐
│ repositories │ IServerRepository, ICacheRepository
└────────┬────────┘
│ depends on
┌────────▼────────┐
│ infrastructure │ SSHClient, Cache, ConfigManager
└─────────────────┘
```
---
## 📦 核心模块说明
### ConfigManager(配置管理)
**职责**: 服务器配置的加载、验证、热重载、CRUD
**特性**:
- 自动加载 `~/.config/ops-maintenance/servers.json`
- 文件监听(macOS/Linux 用 fs.watch,Windows 用轮询)
- 配置变更事件通知
- 运行时增删服务器(`add()`/`remove()`)
**使用**:
```typescript
const cm = new ConfigManager()
await cm.start()
cm.on('change', () => console.log('配置已变更'))
const servers = cm.getAll()
await cm.add({ host: '1.2.3.4', user: 'root', password: 'xxx' })
```
### SSHClient(SSH 客户端)
**职责**: 封装 ssh2 库,提供连接复用、认证、超时控制
**特性**:
- 连接池复用(`connections: Map`)
- keepalive 自动保活
- 命令执行超时控制
- 凭据提供者模式(`ICredentialsProvider`)
**凭据源优先级**:
1. 环境变量 `OPS_CRED_<HOST>` 和 `OPS_KEY_<HOST>`
2. 配置文件(扩展字段,不推荐生产)
3. 默认 SSH 密钥 `~/.ssh/id_rsa` 等
### ConnectionPool(连接池)
**职责**: 管理多服务器连接生命周期
**特性**:
- 最大连接数限制(默认 10)
- 空闲连接自动清理(5 分钟)
- 连接最大存活时间(30 分钟)
- 等待队列机制(并发满时排队)
### Cache(缓存)
**内存缓存**: TTL 自动清理,每分钟扫描过期项
**文件缓存**: 进程重启后缓存持久化
**分层缓存**: Memory + File 二级缓存
### HealthChecker(健康检查策略)
**策略模式**: 每个检查项是独立的 `IHealthCheckStrategy`
| 策略 | 优先级 | 关键 | 说明 |
|------|--------|------|------|
| LoadAverageCheck | 1 | ✅ | 1/5/15 分钟负载 |
| MemoryCheck | 2 | ✅ | 内存使用率 |
| DiskCheck | 3 | ✅ | 根分区使用率 |
| ServiceStatusCheck | 4 | ❌ | nginx/docker 等 |
支持自定义策略,通过 `HealthChecker.addStrategy()` 注入。
### ThresholdChecker(阈值检查)
**环境感知**: production/staging/development 不同阈值
ThresholdConfig:
```typescript
{
diskWarning: 80, diskCritical: 90,
memoryWAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/fish1981bimmer/skills/ops-maintenance",
"sourceUrl": "https://clawhub.ai/fish1981bimmer/skills/ops-maintenance",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T03:24:10.349Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-fish1981bimmer-ops-maintenance/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-fish1981bimmer-ops-maintenance/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T03:24:10.349Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.7K downloads",
"href": "https://clawhub.ai/fish1981bimmer/ops-maintenance",
"sourceUrl": "https://clawhub.ai/fish1981bimmer/ops-maintenance",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T03:24:10.349Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "3.3.10",
"href": "https://clawhub.ai/fish1981bimmer/ops-maintenance",
"sourceUrl": "https://clawhub.ai/fish1981bimmer/ops-maintenance",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-06T05:03:26.214Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-fish1981bimmer-ops-maintenance/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-fish1981bimmer-ops-maintenance/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 3.3.10",
"description": "ops-maintenance v3.3.10 - 更新版本号至 v3.3.10,文档描述同步升级。 - 无功能、命令或配置变更,仅为版本及文档信息维护。",
"href": "https://clawhub.ai/fish1981bimmer/ops-maintenance",
"sourceUrl": "https://clawhub.ai/fish1981bimmer/ops-maintenance",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-06T05:03:26.214Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
