You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将Airbnb Knowledge Feed部署至公网并设置密码保护?

公网部署Airbnb Knowledge Repo 实操指南

我之前也折腾过Airbnb Knowledge Repo的公网部署,踩过不少小坑,给你分享几个实用的方案,一步步解决你的问题:

第一步:先让服务能被公网访问

你现在用knowledge_repo --repo app/ deploy启动gunicorn并绑定到0.0.0.0:7000,这一步是对的,但还需要做这些配置:

1. 针对云服务器/VPS的配置

如果用的是自己的云服务器(比如AWS、阿里云、DigitalOcean):

  • 先确认服务器有公网IP:在服务器终端运行curl ifconfig.me就能查到
  • 开放端口权限:
    • 系统防火墙层面:Ubuntu/Debian用ufw allow 7000/tcp,CentOS用firewall-cmd --permanent --add-port=7000/tcp && firewall-cmd --reload
    • 云服务商安全组:在对应平台的控制台里,添加入站规则,允许外部访问7000端口

2. 本地机器临时测试方案

如果只是想临时把本地服务暴露给公网测试,推荐用ngrok:

  • 下载安装ngrok后,在终端运行ngrok http 7000
  • 它会生成一个类似https://abc123.ngrok.io的公网URL,其他人就能通过这个链接访问你的Knowledge Repo了(注意这只是临时方案,重启ngrok后URL会变)

3. 绑定自定义域名(可选)

如果有自己的域名,先把域名解析到你的服务器公网IP,然后用Nginx做反向代理:
创建或修改Nginx配置文件(比如/etc/nginx/sites-available/knowledge-repo):

server {
    listen 80;
    server_name your-domain.com; # 替换成你的域名

    location / {
        proxy_pass http://localhost:7000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    }
}

启用配置并重启Nginx:

ln -s /etc/nginx/sites-available/knowledge-repo /etc/nginx/sites-enabled/
nginx -t && systemctl restart nginx

之后访问http://your-domain.com就能直接进入你的知识库了。

第二步:添加密码保护

要给站点加权限验证,有两种简单的方式:

1. Nginx HTTP Basic Auth(推荐)

这种方式不需要修改知识库代码,配置更灵活:

  • 先安装密码生成工具:Ubuntu/Debian用apt install apache2-utils,CentOS用yum install httpd-tools
  • 生成密码文件:
    htpasswd -c /etc/nginx/.htpasswd your-username # 替换成你想设置的用户名
    
    输入两次密码后,修改Nginx的location块,添加认证规则:
    location / {
        proxy_pass http://localhost:7000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
    
        # 新增以下两行
        auth_basic "Restricted Knowledge Repo";
        auth_basic_user_file /etc/nginx/.htpasswd;
    }
    
    重启Nginx后,访问站点就会弹出用户名密码验证框。

2. 直接修改知识库配置

如果不想用Nginx,也可以通过Flask的基础认证插件实现:

  • 创建config.py文件,内容如下:
    from flask_basicauth import BasicAuth
    
    # 设置用户名和密码
    BASIC_AUTH_USERNAME = "your-username"
    BASIC_AUTH_PASSWORD = "your-password"
    BASIC_AUTH_FORCE = True  # 强制所有页面都需要认证
    
    def init_app(app):
        basic_auth = BasicAuth(app)
    
  • 启动服务时指定配置文件:
    knowledge_repo --repo app/ --config config.py deploy
    

第三步:部署到Paas平台(以Heroku为例)

如果不想维护自己的服务器,用Heroku部署更省心:

  1. 在项目根目录创建Procfile:
    web: knowledge_repo --repo app/ deploy -p $PORT
    
    Heroku会自动把平台分配的端口通过$PORT环境变量传给服务。
  2. 创建requirements.txt,列出依赖:
    knowledge-repo
    gunicorn
    
  3. 登录Heroku并推送代码:
    heroku login
    heroku create your-app-name # 替换成你的应用名
    git add .
    git commit -m "Deploy Knowledge Repo to Heroku"
    git push heroku master
    
  4. 给Heroku应用添加密码保护:
    heroku plugins:install heroku-http-auth
    heroku http-auth:set your-username your-password
    
    部署完成后,访问https://your-app-name.herokuapp.com就能看到带密码验证的知识库了。

最后验证

不管用哪种方案,部署后记得做两个测试:

  • 用非本地的设备(比如手机流量)访问你的公网地址,确认能打开Knowledge Feed
  • 验证密码保护是否生效,确保未授权用户无法访问

内容的提问来源于stack exchange,提问作者Alex

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:30:50