fix: 对齐技术架构补齐传输 mTLS 与结构化 JSON 日志(NFR 9 章)

架构核对发现 2 处差距,本次补齐:
- Kafka 上行支持 SSL/SASL_SSL 双向 mTLS(8.2 服务间 mTLS 边缘网关↔总线)
- 网关日志支持结构化 JSON 输出(NFR 可维护:统一日志规范)
- 配置示例与 README 验收口径同步更新
This commit is contained in:
2026-08-04 15:46:09 +08:00
parent f49c0920d4
commit 098125164d
8 changed files with 481 additions and 7 deletions
@@ -51,3 +51,14 @@ kafka:
bootstrap_servers: "10.20.0.10:9092"
topic_prefix: "iaop.ti-cl4" # 模板化 topic:{prefix}.{device_id}.points
batch_size: 500
# 传输安全(NFR 9 章:服务间 mTLS,边缘网关↔总线双向认证)。
# 现场部署必须开启;本地联调可保持 PLAINTEXT。
security:
protocol: SSL # PLAINTEXT | SSL | SASL_SSL
ca_location: "/etc/iaop/certs/ca.crt"
cert_location: "/etc/iaop/certs/gateway.crt"
key_location: "/etc/iaop/certs/gateway.key"
# protocol: SASL_SSL 时追加:
# sasl_mechanism: "PLAIN"
# sasl_username: "edge-gateway"
# sasl_password: "..."