跳转到内容

Admin API

FF1 Master 提供 REST API,用于批量运维与脚本化操作。路径前缀 /api/,用 API Token(Bearer)认证,按 scope 授权。

在控制台签发 API Token(GET/POST /api/tokens),调用时带:

Authorization: Bearer <token>

Scope 形如 resource:action:

Scope能力
nodes:read / nodes:write节点读 / 写
rules:read / rules:write转发规则读 / 写
tunnels:read / tunnels:write隧道读 / 写
users:read / users:write用户读 / 写
audit:read审计只读
license:read授权只读
*全部(谨慎使用)
领域路径
登录POST /api/auth/login
TokenGET/POST /api/tokens、DELETE /api/tokens/{id}
节点GET /api/nodes、GET/PUT/DELETE /api/nodes/{id}、POST /api/nodes
节点装机POST /api/nodes/{id}/install-ssh、POST /api/nodes/{id}/reinstall
转发规则GET/POST /api/rules、GET/PUT /api/rules/{id}、POST /api/rules/{id}/sync
隧道GET/POST /api/tunnels、GET/PUT/DELETE /api/tunnels/{id}
设置GET/PATCH /api/settings
审计GET /api/audit-logs
仪表盘GET /api/dashboard、GET /api/dashboard/traffic

批量操作:POST /api/nodes/batch-delete、POST /api/rules/batch-delete 等。

列出节点:

Terminal window
curl -sS -H "Authorization: Bearer $FF1_TOKEN" \
"https://master.example.com/api/nodes"

新建并下发一条转发规则后触发同步:

Terminal window
curl -sS -X POST -H "Authorization: Bearer $FF1_TOKEN" \
"https://master.example.com/api/rules/123/sync"
  • Token 权限大,按最小 scope 签发,勿泄露
  • 写操作记入 审计日志
  • 批量脚本注意速率,避免与在线运维争用 SQLite 写锁