Token导航 LogoToken导航TokenDH.com
待分类需要联网github未标认证来源可访问许可证需确认审计通过

salvo-tls-acme齐射极限

Agent Skill

salvo-tls-acme 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

294

周安装

12

GitHub Stars

16

下载量

94
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:salvo-tls-acme(齐射极限)
来源仓库:https://github.com/salvo-rs/salvo-skills
仓库路径:skills/salvo-tls-acme
安装命令:
npx skills add https://github.com/salvo-rs/salvo-skills --skill salvo-tls-acme
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/salvo-rs/salvo-skills --skill salvo-tls-acme

简介

salvo-tls-acme 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息。

  • 适合在 Codex、Claude、Cursor、Gemini CLI 中围绕仓库状态、代码变更或协作事项进行整理时使用。
  • 通过 npx skills add 命令从指定 GitHub 仓库安装,具体用法需结合原始 README 核验。
  • 安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写操作。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Salvo TLS and ACME

Static TLS with Rustls

[dependencies]
salvo = { version = "0.89.3", features = ["rustls"] }
use salvo::prelude::*;
use salvo::conn::rustls::{Keycert, RustlsConfig};

#[handler]
async fn hello() -> &'static str { "Hello HTTPS" }

#[tokio::main]
async fn main() {
    let router = Router::new().get(hello);

    let config = RustlsConfig::new(
        Keycert::new()
            .cert_from_path("certs/cert.pem").unwrap()
            .key_from_path("certs/key.pem").unwrap()
    );

    let acceptor = TcpListener::new("0.0.0.0:443").rustls(config).bind().await;
    Server::new(acceptor).serve(router).await;
}

Loading from memory:

let cert = include_bytes!("../certs/cert.pem");
let key = include_bytes!("../certs/key.pem");
let config = RustlsConfig::new(Keycert::new().cert(cert.as_slice()).key(key.as_slice()));

HTTP/2 is enabled automatically with Rustls.

ACME (Let's Encrypt)

[dependencies]
salvo = { version = "0.89.3", features = ["acme"] }

ACME is an extension trait on TcpListener — there is NO AcmeListener::builder() constructor. Use .acme() on the listener and chain config.

HTTP-01 challenge

HTTP-01 needs port 80 open for challenge responses. http01_challenge(&mut router) mounts the challenge handler into your router automatically.

use salvo::prelude::*;

#[handler]
async fn hello() -> &'static str { "Hello Let's Encrypt" }

#[tokio::main]
async fn main() {
    let mut router = Router::new().get(hello);

    let listener = TcpListener::new("0.0.0.0:443")
        .acme()
        .cache_path("/tmp/letsencrypt")
        .add_domain("example.com")
        .http01_challenge(&mut router);

    // Bind 443 (TLS) + 80 (challenges) together.
    let acceptor = listener.join(TcpListener::new("0.0.0.0:80")).bind().await;
    Server::new(acceptor).serve(router).await;
}

TLS-ALPN-01 challenge

No port 80 required; challenges run over the TLS handshake on 443.

let acceptor = TcpListener::new("0.0.0.0:443")
    .acme()
    .cache_path("/tmp/letsencrypt")
    .add_domain("example.com")
    // .tls_alpn01_challenge() is the default; call explicitly to be clear
    .bind()
    .await;

Staging directory (testing)

Let's Encrypt staging avoids production rate limits while testing:

use salvo::conn::acme::{AcmeListener, LETS_ENCRYPT_STAGING};

let listener = TcpListener::new("0.0.0.0:443")
    .acme()
    .directory("letsencrypt-staging", LETS_ENCRYPT_STAGING)
    .cache_path("/tmp/letsencrypt-staging")
    .add_domain("example.com")
    .http01_challenge(&mut router);

Note: use .directory(name, url) — there is no .directory_url(...) method. Use .http01_challenge(&mut router) / .tls_alpn01_challenge() / .dns01_challenge(solver) — there is no .challenge_type(...) method.

Multiple domains and contacts

.add_domain("example.com")
.add_domain("www.example.com")
.add_contact("mailto:admin@example.com")

Or pass a Vec:

.domains(vec!["example.com".into(), "www.example.com".into()])
.contacts(vec!["mailto:admin@example.com".into()])

Key types

use salvo::conn::acme::KeyType;
.key_type(KeyType::EcdsaP256)  // default; also Rsa2048/4096, Ed25519, ...

Force HTTP-to-HTTPS redirect

Use the built-in ForceHttps middleware (needs force-https feature) instead of writing a custom handler:

salvo = { version = "0.89.3", features = ["rustls", "force-https"] }
use salvo::prelude::*;

let service = Service::new(router).hoop(ForceHttps::new().https_port(443));

let acceptor = TcpListener::new("0.0.0.0:443")
    .rustls(tls_config)
    .join(TcpListener::new("0.0.0.0:80"))
    .bind()
    .await;
Server::new(acceptor).serve(service).await;

HTTP/3 (QUIC)

salvo = { version = "0.89.3", features = ["quinn"] }

QuinnListener takes a quinn ServerConfig (built from RustlsConfig) and an address — NOT a cert_path/key_path builder.

use salvo::prelude::*;
use salvo::conn::rustls::{Keycert, RustlsConfig};

let config = RustlsConfig::new(
    Keycert::new()
        .cert(include_bytes!("../certs/cert.pem").as_slice())
        .key(include_bytes!("../certs/key.pem").as_slice())
);

let listener = TcpListener::new(("0.0.0.0", 443)).rustls(config.clone());
let acceptor = QuinnListener::new(config.build_quinn_config().unwrap(), ("0.0.0.0", 443))
    .join(listener)
    .bind()
    .await;
Server::new(acceptor).serve(router).await;

Security headers (HSTS)

#[handler]
async fn hsts(_req: &mut Request, _depot: &mut Depot, res: &mut Response, ctrl: &mut FlowCtrl) {
    res.headers_mut().insert(
        "strict-transport-security",
        "max-age=31536000; includeSubDomains; preload".parse().unwrap(),
    );
    ctrl.call_next(_req, _depot, res).await;
}

Related Skills

  • salvo-graceful-shutdown: graceful shutdown for HTTPS servers
  • salvo-cors: CORS and other security headers

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

34.1%
按下载量换算32

Claude

31.28%
按下载量换算29

Cursor

17.48%
按下载量换算16

Gemini CLI

9.4%
按下载量换算9

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills