Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
81ad54cbe9 | ||
|
|
33518cec15 | ||
|
|
13976f0416 | ||
|
|
c384d28039 | ||
|
|
8da8fea50c | ||
|
|
d71720766c | ||
|
|
93d6fc0b80 | ||
|
|
f3ca708e55 | ||
|
|
41d08376da | ||
|
|
98b6d79cfe | ||
|
|
904502d9da | ||
|
|
a1eb073c74 | ||
|
|
3d2977d2a0 | ||
|
|
31b0659d75 | ||
|
|
f6430ea773 | ||
|
|
da5db050d8 | ||
|
|
5ad063bda2 | ||
|
|
05565fc0c1 | ||
|
|
09daf53713 | ||
|
|
2a4f368e9f | ||
|
|
5ec21db627 | ||
|
|
cc4a0873a1 | ||
|
|
0db7f90f28 | ||
|
|
776526006d | ||
|
|
415578e5c8 | ||
|
|
49727dc60c | ||
|
|
8e1b3fb4ae | ||
|
|
f571ec523f | ||
|
|
4484d09ba0 | ||
|
|
3c4966b3e7 | ||
|
|
febf67b7e0 | ||
|
|
4264612643 | ||
|
|
0eed6a3e3a | ||
|
|
e67966fe0d | ||
|
|
d312e5b0b3 | ||
|
|
e1fbda0150 | ||
|
|
08ffbf1e37 | ||
|
|
035e65db2c | ||
|
|
5832cfc2a3 | ||
|
|
956dc1bf48 | ||
|
|
7a2c3034c2 | ||
|
|
252580cb9e | ||
|
|
e8dbdcb201 | ||
|
|
264c5ee1c1 | ||
|
|
0e992e2b21 | ||
|
|
7305c0dc70 | ||
|
|
6d8c36bb54 | ||
|
|
9a68f1afeb | ||
|
|
0bfcd004c0 | ||
|
|
583b7aef9e | ||
|
|
3765fcb0a9 | ||
|
|
861eeeb8f3 | ||
|
|
26bfbbaf82 | ||
|
|
bc8faee58e | ||
|
|
fcb86be893 | ||
|
|
167cede538 | ||
|
|
90d5c87956 | ||
|
|
d2ec02ea8c | ||
|
|
9a86b6881e | ||
|
|
7e32a67130 | ||
|
|
72c213b963 | ||
|
|
197bc34e12 | ||
|
|
022a7dd510 | ||
|
|
1052c721f4 | ||
|
|
c231fcd1da | ||
|
|
0eb12962e1 | ||
|
|
0c51f26f82 | ||
|
|
fe4e9e1358 | ||
|
|
96b645ea3e | ||
|
|
84c061db04 | ||
|
|
1563998163 | ||
|
|
49cb54403f | ||
|
|
e2c059ca43 | ||
|
|
28efcd6176 | ||
|
|
777c11ae9d | ||
|
|
8e53115099 | ||
|
|
7799eb2831 | ||
|
|
28ad2b3bda | ||
|
|
b55242e71b | ||
|
|
9bd9b83479 | ||
|
|
8eb6867b4a | ||
|
|
de0b318dab | ||
|
|
141302b10c | ||
|
|
20f0475202 | ||
|
|
5113e66d94 | ||
|
|
90996ccb8f | ||
|
|
0e591cf3aa | ||
|
|
5dde89bb2e | ||
|
|
ede84757b6 | ||
|
|
45685ad64c | ||
|
|
9a522fccc0 | ||
|
|
37e0655dcb | ||
|
|
f74737333a | ||
|
|
cdd8aca0db | ||
|
|
a50b32e706 | ||
|
|
3bb9c27428 | ||
|
|
386a4a50b6 | ||
|
|
5c55801cb0 | ||
|
|
90c5f696e7 | ||
|
|
4795e235de | ||
|
|
65339774ce | ||
|
|
bc34401bb9 | ||
|
|
e4201b4cd2 | ||
|
|
148203337b | ||
|
|
9540825394 | ||
|
|
d732994b35 | ||
|
|
c96432431d | ||
|
|
c15a850fc9 | ||
|
|
f5284878e4 | ||
|
|
5070552b46 | ||
|
|
9245800904 | ||
|
|
47161bd9f4 | ||
|
|
c3347e0abb | ||
|
|
dc182e274b | ||
|
|
60eaa76f4f | ||
|
|
9cfef89a55 | ||
|
|
830c5867d9 | ||
|
|
a65439d173 | ||
|
|
5c1faec47c | ||
|
|
bcfe3c4101 | ||
|
|
0031518178 | ||
|
|
1e37a1b2a1 | ||
|
|
9efbb63d3d | ||
|
|
a20135f828 |
@@ -2,64 +2,66 @@
|
||||
|
||||
进入 `Advanced` 菜单的子菜单 `CPU Configuration` :
|
||||
|
||||

|
||||

|
||||
|
||||
检查 `Intel (VMX) Virtualization Technology` 选项为 `Enabled` 状态:
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
## 2.CPU功耗确认
|
||||
|
||||
进入 `Advanced` 菜单的子菜单 `Power & Performance` :
|
||||
|
||||

|
||||

|
||||
|
||||
进入 `CPU - Power Management Control` :
|
||||
|
||||

|
||||

|
||||
|
||||
确认 `C states` 选项为 `Enabled` 状态:
|
||||
检查 `C states` , **默认** 选项为 `Enabled` 状态。
|
||||
|
||||

|
||||
如果遇到网卡 **无法跑满** 的情况,可以尝试将该选项关闭:
|
||||
|
||||

|
||||
|
||||
再进入 `HDC Control` 菜单的子菜单 `View/Configure Turbo Options` :
|
||||
|
||||

|
||||

|
||||
|
||||
确认以下内容
|
||||
检查以下内容,适当调整以改变功耗墙:
|
||||
- `Power Limit 1 Override` 选项:`Enabled`
|
||||
- `Power Limit 1` 选项:`15000`
|
||||
- `Power Limit 1 Time Window` 选项:为最大 `128`
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
## 3.来电自启确认
|
||||
|
||||
进入 `Advanced` 菜单的子菜单 `Hardware Monitor` :
|
||||
|
||||

|
||||

|
||||
|
||||
确认 `Restore AC Power Loss` 选项为 `Power On` 状态:
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
## 4.设置快速启动
|
||||
|
||||
PVE 系统安装完成后,进入 `Boot` 菜单,将 `Fast Boot` 选项设置为 `Enabled` 状态:
|
||||
|
||||

|
||||

|
||||
|
||||
调整系统启动顺序,将 `Proxmox` 设置为第一启动项,并关闭其他启动项内容:
|
||||
|
||||

|
||||

|
||||
|
||||
最后保存 BIOS 设置 `Save Changes and Exit` :
|
||||
|
||||

|
||||

|
||||
|
||||
使用键盘左右方向键选择 `yes` 并回车键执行保存:
|
||||
|
||||

|
||||

|
||||
@@ -7,13 +7,13 @@ PVE 系统正式安装之前,需要准备 PVE 的安装镜像和一些必要
|
||||
|
||||
PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||

|
||||

|
||||
|
||||
点击 `Proxmox VE 7.x ISO Installer` 链接。此处可能有多个 PVE 的安装 ISO,可以根据需要进行选择。
|
||||
|
||||
此处我以目前最新的 `Proxmox VE 7.2 ISO` 作为演示。
|
||||
|
||||

|
||||

|
||||
|
||||
下载 ISO 时请注意 `SHA256SUM` ,后续将使用该校验信息对下载下来的 ISO 进行校验,以确保 ISO 文件的完整性。
|
||||
|
||||
@@ -32,7 +32,7 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||
缺点是只支持 Windows、Linux。
|
||||
|
||||

|
||||

|
||||
|
||||
#### Etcher
|
||||
|
||||
@@ -42,7 +42,7 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||
支持 Windows、macOS、Linux。
|
||||
|
||||

|
||||

|
||||
|
||||
#### Rufus
|
||||
|
||||
@@ -50,7 +50,7 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||
轻便小巧的写盘工具,仅支持 Windows。
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
### 0.3.SSH工具
|
||||
@@ -65,7 +65,7 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||
支持 Windows、macOS、Linux。
|
||||
|
||||

|
||||

|
||||
|
||||
#### MobaXterm
|
||||
|
||||
@@ -73,12 +73,12 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||
功能强大的 SSH 工具,仅支持 Windows。
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
## 1.PVE系统安装
|
||||
## 01.PVE系统安装
|
||||
|
||||
由于机型不同,BIOS 的设置也不同,所以本教程不演示具体如何将机器设置成从 U 盘启动。
|
||||
由于机型不同,BIOS 的设置也不同,所以本文不演示具体如何将机器设置成从 U 盘启动。
|
||||
|
||||
在设置BIOS时需要注意以下几点:
|
||||
- 暂时关闭 **“安全启动”**
|
||||
@@ -92,7 +92,7 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||
我使用 Ventoy 进行设备引导后,出现如下画面,选择 PVE 的安装 ISO :
|
||||
|
||||

|
||||

|
||||
|
||||
等待引导跑码完成后,即进入 PVE 的安装界面。
|
||||
|
||||
@@ -100,11 +100,11 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||
选择第一项 `Install Proxmox VE` 开始安装 PVE 。
|
||||
|
||||

|
||||

|
||||
|
||||
设备将会继续跑码,直到 EULA 最终用户许可协议出现,选择 `I agree` 。
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.3.PVE磁盘选项
|
||||
|
||||
@@ -112,7 +112,7 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||
可以通过下拉框选择希望安装 PVE 的物理磁盘。
|
||||
|
||||

|
||||

|
||||
|
||||
点击磁盘列表右侧的 **Options** ,对 PVE 的磁盘安装参数进行一些调整。
|
||||
|
||||
@@ -120,7 +120,7 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
|
||||
如果设备安装的内存比较小,比如只有 `4GB` 、`8GB` ,可以酌情考虑将 `swapsize` 改大,比如 `8`(此处无需填写单位 GB )。
|
||||
|
||||

|
||||

|
||||
|
||||
虽然 PVE 系统会根据设备安装的内存大小自动计算合理的 `swapsize` ,但我安装了 `16GB` 内存,因此我此处仅给了 `4GB` 的空间作为交换空间。
|
||||
|
||||
@@ -130,7 +130,7 @@ PVE 此时处于未接入互联网的 “离线” 安装状态,因此不会
|
||||
|
||||
在 `Contry` 处手动输入 `China` ,下方的 `Time zone` 将自动变更为 `Asia/Shanghai` 。
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.5.PVE账户与邮箱
|
||||
|
||||
@@ -138,7 +138,7 @@ PVE 为最关键的虚拟化层,建议使用强密码,包含大小写字母
|
||||
|
||||
`Email` 必须为一个 “合法” 的邮箱地址,不然系统会判定邮箱地址不合法并拒绝继续安装。
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.6.PVE网络设置
|
||||
|
||||
@@ -148,36 +148,36 @@ PVE 必须选择一个管理网口,默认情况下,PVE 会使用编号较小
|
||||
|
||||
当 PVE 完全安装好之后, **会在 PVE 提供的 WEB 页面中对该管理网口设置进行调整** 。
|
||||
|
||||

|
||||

|
||||
|
||||
根据我们之前的规划,对 PVE 的管理 IP(`172.16.1.250`)进行设置。
|
||||
根据我们之前的规划,对 PVE 的管理 IP(`172.16.1.254`)进行设置。
|
||||
|
||||
需要说明的是 `Hostname` ,即 PVE 主机的名称,PVE 将使用输入的 “二级域名” 的名称作为自己的名称。
|
||||
|
||||
演示内容输入的为 `hyper.fox.lab` ,因此 PVE 获取的主机名称为 `hyper` 。
|
||||
演示内容输入的为 `node01.fox.local` ,因此 PVE 获取的主机名称为 `node01` 。
|
||||
|
||||
我们规划未来主路由的IP地址为 `172.16.1.1` ,因此我们网关和 DNS 地址均使用该地址。
|
||||
|
||||
- Hostname (FQDN)
|
||||
- hyper.fox.lab
|
||||
- node01.fox.local
|
||||
- IP Address (CIDR)
|
||||
- 172.16.1.250/24
|
||||
- 172.16.1.254/24
|
||||
- Gateway
|
||||
- 172.16.1.1
|
||||
- DNS Server
|
||||
- 172.16.1.1
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.7.PVE参数确认与安装
|
||||
|
||||
最后会显示出当前 PVE 安装的配置清单,确认无误后即可开始安装。
|
||||
|
||||

|
||||

|
||||
|
||||
安装完成后,PVE 会告知用户登录的 `IP 地址` 和 `端口` 。
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
## 2.PVE安装后检查
|
||||
@@ -186,11 +186,11 @@ PVE 安装完成后会自动重启,等待系统重启完成会显示如下界
|
||||
|
||||
**注意:Linux 操作系统,在输入密码时是不显示任何字符信息的,输入完成后输入回车即可。**
|
||||
|
||||

|
||||

|
||||
|
||||
登录系统后,我们使用一些命令来查看一些基本信息:
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
```bash
|
||||
@@ -1,8 +1,8 @@
|
||||
## 1.更换系统软件源
|
||||
|
||||
在上一篇文章 [1.PVE系统安装](./1.PVE系统安装.md) 中,我们从刚装好的 PVE 系统中获取了系统的一些参数:
|
||||
在上一篇文章 [01.PVE系统安装](./01.PVE系统安装.md) 中,我们从刚装好的 PVE 系统中获取了系统的一些参数:
|
||||
|
||||

|
||||

|
||||
|
||||
此处显示出 PVE 底层使用的是 Debian 的系统,代号为 `bullseye` 。
|
||||
|
||||
@@ -42,20 +42,20 @@ sed -i 's|^deb http://security.debian.org|deb https://mirrors.ustc.edu.cn/debian
|
||||
cat /etc/apt/sources.list
|
||||
```
|
||||
|
||||
如果输出结果中有 USTC 的镜像地址,则表示命令已经正确执行:
|
||||
如果输出结果中有 USTC 的镜像地址,则表示命令已经正确执行。
|
||||
|
||||
如果希望能更新 CPU 的 `microcode` ,则需要手动添加镜像的 `non-free` 参数,完整系统源示例如下:
|
||||
|
||||
```bash
|
||||
## 输出内容参考:
|
||||
deb https://mirrors.ustc.edu.cn/debian bullseye main contrib non-free
|
||||
|
||||
deb https://mirrors.ustc.edu.cn/debian bullseye main contrib
|
||||
|
||||
deb https://mirrors.ustc.edu.cn/debian bullseye-updates main contrib
|
||||
deb https://mirrors.ustc.edu.cn/debian bullseye-updates main contrib non-free
|
||||
|
||||
# security updates
|
||||
deb https://mirrors.ustc.edu.cn/debian-security bullseye-security main contrib
|
||||
deb https://mirrors.ustc.edu.cn/debian-security bullseye-security main contrib non-free
|
||||
```
|
||||
|
||||
此处我放出 Debian Bullseye 的完整镜像源以供参考, **非常不建议** 将 PVE 的系统源替换成完整的 Debian 源,以避免出现问题。
|
||||
此处我放出 Debian Bullseye 的完整镜像源以供参考, **非常不建议** 将 PVE 的系统源替换成完整的 Debian 源,以避免系统故障。
|
||||
|
||||
```bash
|
||||
## Debian Bullseye 完整源 (USTC)
|
||||
@@ -75,7 +75,7 @@ deb https://mirrors.ustc.edu.cn/debian-security/ bullseye-security main contrib
|
||||
|
||||
可以看到,PVE 的系统源和 Debian 完整源的差异在于 `non-free` 和 `bullseye-backports` 。
|
||||
|
||||
如果小伙伴在一些软件或者驱动(比如闭源 GPU 驱动)上遇到问题,可以尝试将 PVE 的系统源替换成 Debian 的完整源来尝试解决问题。
|
||||
如果小伙伴在一些软件或者驱动(比如闭源 GPU 驱动)上遇到麻烦,才需尝试 Debian 的完整镜像源。
|
||||
|
||||
### 1.2.PVE 订阅源替换
|
||||
|
||||
@@ -154,7 +154,7 @@ apt dist-upgrade
|
||||
|
||||
考虑到 **“离线”** 安装时无法同步系统源,因此该步骤可以等到 PVE 中安装好了 RouterOS 软路由或其他路由系统并正确连接 Internet 后再执行。
|
||||
|
||||
或者家庭网络环境中还有一个 172.16.1.0/24 网段的,已经连接 Internet 的路由器 A。将路由器 A 的LAN 口与 PVE 的管理网口连接,此时 PVE 可访问外网。
|
||||
或者家庭网络环境中还有一个 `172.16.1.0/24` 网段的,已经连接 Internet 的路由器 A ,将路由器 A 的 LAN 口与 PVE 的管理网口连接,此时 PVE 可访问外网。
|
||||
|
||||
|
||||
## 2.安装必要软件
|
||||
@@ -166,16 +166,23 @@ apt dist-upgrade
|
||||
apt update
|
||||
|
||||
## 安装系统软件
|
||||
apt install htop lm-sensors unzip fail2ban vim tmux unattended-upgrades apt-listchanges powermgmt-base
|
||||
apt install htop lm-sensors unzip vim tmux unattended-upgrades apt-listchanges powermgmt-base
|
||||
|
||||
## 安装网络工具
|
||||
apt install iperf iperf3 iftop net-tools ethtool
|
||||
apt install iperf iperf3 iftop ethtool
|
||||
|
||||
## 安装CPU调度调整工具
|
||||
apt install cpufrequtils
|
||||
|
||||
## 根据CPU厂商安装CPU微码工具
|
||||
apt install intel-microcode (amd64-microcode)
|
||||
|
||||
## 更新 PCI 数据库
|
||||
update-pciids
|
||||
|
||||
```
|
||||
|
||||
其中 `fail2ban` 和 `unattended-upgrades` 为两个服务,后续会对其进行配置。
|
||||
其中 `unattended-upgrades` 为系统自动更新服务,后续会对其进行配置。
|
||||
|
||||
`cpufrequtils` 为 CPU 调度器的配置工具,后续会对 CPU 调度算法进行调整。
|
||||
|
||||
@@ -188,14 +195,14 @@ apt install cpufrequtils
|
||||
|
||||
访问 PVE 的 WEB 管理界面,对 PVE 的网络进行一些调整。
|
||||
|
||||

|
||||

|
||||
|
||||
在设置 PVE 的网络之前,需要对网络内部结构做一个规划。
|
||||
|
||||
在前篇的网络地址段规划时,我们有如下规划内容:
|
||||
- PVE IP:172.16.1.250/24
|
||||
- PVE 网关:172.16.1.1
|
||||
- PVE DNS:172.16.1.1
|
||||
- PVE IP: `172.16.1.254/24` (IPv6: `fdac::fe/64` )
|
||||
- PVE 网关: `172.16.1.1` (IPv6 网关将使用 `Link-Local Address` 自动配置)
|
||||
- PVE DNS: `172.16.1.1` (IPv6 DNS: `fdac::1` )
|
||||
|
||||
我们预计在 PVE 内部安装 RouterOS 用于主路由,2 个 Adguard Home 虚拟机用于提供内网的 DNS 服务以及去广告,且 RouterOS 需要能让 PVE 自身访问外网。
|
||||
|
||||
@@ -203,45 +210,49 @@ apt install cpufrequtils
|
||||
|
||||
先放出 PVE 网桥设置完成后的配置页面:
|
||||
|
||||

|
||||

|
||||
|
||||
在实地考察了 PVE 软路由在弱电箱的摆放位置后,本次决定使用 ETH0 口,也就是第一个物理网口,作为 RouterOS 的拨号网口,ETH3 口作为 PVE 的管理网口。
|
||||
|
||||
在初次登录 PVE 的 WEB 管理后台,并访问网络管理页面时,会发现只有一个 vmbr0。
|
||||
在初次登录 PVE 的 WEB 管理后台,并访问网络管理页面时,会发现只有一个 `vmbr0` 。
|
||||
|
||||
该 vmbr0 绑定的物理口为列表中的第一个网口,且在 CIDR 和 网关处有 IP 地址参数,说明 vmbr0 就是目前的管理网口。造成该状态的原因是我们在安装 PVE 阶段,选择的网口就是第一个网口。因此我们需要对其进行修改。
|
||||
该 `vmbr0` 绑定的物理口为列表中的第一个网口,且在 `CIDR` 和 `网关` 处有 IP 地址参数,说明 `vmbr0` 就是目前的管理网口。
|
||||
|
||||
造成该状态的原因是我们在安装 PVE 阶段,选择的网口就是第一个网口,因此我们需要对其进行修改。
|
||||
|
||||
首先我们需要对每个物理网口创建网桥,并对其进行配置修改,在修改完成前, **请不要点击“应用配置”** ,不然会导致 PVE 无法访问。
|
||||
|
||||
### 3.1.修改默认网桥 vmbr0
|
||||
|
||||
首先双击 vmbr0 ,进入配置界面:
|
||||
首先双击 `vmbr0` ,进入配置界面:
|
||||
|
||||

|
||||

|
||||
|
||||
删除“IPv4/CIDR”和“网关”信息,确保“自动启动”为勾选状态。
|
||||
删除 `IPv4/CIDR` 和 `网关` 信息,确保 `自动启动` 为勾选状态。
|
||||
|
||||
在备注处填写“For WAN”,然后点击“OK”。
|
||||
在备注处填写 `For WAN` ,然后点击 `OK` 按钮。
|
||||
|
||||
### 3.2.物理网口创建网桥
|
||||
|
||||
点击左上角的“创建”,选择“Linux Bridge”:
|
||||
点击左上角的 `创建` 按钮,选择 `Linux Bridge` :
|
||||
|
||||

|
||||

|
||||
|
||||
因为 vmbr0 名称已被使用,因此名称处填写 `vmbr1`,桥接端口填写顺序的第二个网卡名称,我演示这里为 `enp3s0`。
|
||||
因为 `vmbr0` 名称已被使用,因此名称处填写 `vmbr1` ,桥接端口填写顺序的第二个网卡名称,我演示这里为 `enp3s0`。
|
||||
|
||||

|
||||

|
||||
|
||||
确保“自动启动”为勾选状态,在备注处填写“For LAN1”,点击“创建”。
|
||||
确保 `自动启动` 为勾选状态,在备注处填写 `For LAN1` ,点击 `创建` 按钮。
|
||||
|
||||
然后,依次创建所有物理接口的内部网桥,直到最后一个:
|
||||
|
||||

|
||||

|
||||
|
||||
在创建最后一个物理网口的 PVE 网桥时,需要额外填写 IPv4 和网关内容。
|
||||
在创建最后一个物理网口的 PVE 网桥时,需要额外配置 `IPv4` 地址和对应的 `网关` 参数。
|
||||
|
||||
在所有物理网口的 PVE 网桥创建完成后,可以点击“应用配置”按钮,此时页面会失去连接。
|
||||
`IPv6` 仅需填写地址,无需填写 `网关` 参数。
|
||||
|
||||
在所有物理网口的 PVE 网桥创建完成后,可以点击 `应用配置` 按钮,此时页面会失去连接。
|
||||
|
||||
无需担心,只需要将电脑的网线从 PVE 物理机的第一个网口拔出,并插入到最后一个网口即可。
|
||||
|
||||
@@ -249,7 +260,7 @@ apt install cpufrequtils
|
||||
|
||||
### 3.3.创建 PVE 纯内部网桥
|
||||
|
||||

|
||||

|
||||
|
||||
纯内部网桥的创建方法与创建物理网口的网桥方法基本一致,唯一区别是在 **“桥接端口”处为空** 即可。
|
||||
|
||||
@@ -262,8 +273,17 @@ apt install cpufrequtils
|
||||
此时如果 OPNsense 和 RouterOS 均使用了绑定物理网口的 PVE 网桥,则需要用网线在 PVE 服务器外面连接两个网口,浪费宝贵的网线不说,还占用了网口,得不偿失。而使用纯内部网桥则可以很好的解决该问题,有了这个纯内部网桥,不论多少个虚拟机使用了该网桥,只要是同网段,都可以相互访问。
|
||||
|
||||
|
||||
## 4.后续配置
|
||||
## 4.配置 PVE DNS 服务器
|
||||
|
||||
在 PVE 的安装过程中设置了 PVE 服务器的 DNS 地址为 `172.16.1.1` ,但并未设置 DNS 的 IPv6 地址。
|
||||
|
||||
在 PVE 系统的 DNS 设置页面中,新增 DNS 服务器的 IPv6 地址,即主路由的 LAN IPv6 地址:
|
||||
|
||||

|
||||
|
||||
|
||||
## 5.后续配置
|
||||
|
||||
至此,PVE的初始化配置完成。
|
||||
|
||||
后续将会对 PVE 的一些服务进行配置,例如安全加固、调整 CPU 的调度算法节能省钱、PVE的自动更新等内容。
|
||||
后续将会对 PVE 的一些服务进行配置,例如安全加固、调整 CPU 的调度算法节能省钱、PVE 的自动更新等内容。
|
||||
@@ -1,6 +1,6 @@
|
||||
## 0.必要条件
|
||||
|
||||
在上一篇文章 [2.PVE初始化配置](./2.PVE初始化配置.md) 中,我们已经初始化了 PVE 系统,接下来需要对 PVE 系统进一步调整。
|
||||
在上一篇文章 [02.PVE初始化配置](./02.PVE初始化配置.md) 中,我们已经初始化了 PVE 系统,接下来需要对 PVE 系统进一步调整。
|
||||
|
||||
在 PVE 系统调整之前,请确保必要的软件包已经安装完成。
|
||||
|
||||
@@ -9,87 +9,25 @@
|
||||
apt update
|
||||
|
||||
## 安装系统软件
|
||||
apt install htop lm-sensors unzip fail2ban vim tmux unattended-upgrades apt-listchanges powermgmt-base
|
||||
apt install htop lm-sensors unzip vim tmux unattended-upgrades apt-listchanges powermgmt-base
|
||||
|
||||
## 安装网络工具
|
||||
apt install iperf iperf3 iftop net-tools ethtool
|
||||
apt install iperf iperf3 iftop ethtool
|
||||
|
||||
## 安装CPU调度调整工具
|
||||
apt install cpufrequtils
|
||||
|
||||
## 根据CPU厂商安装CPU微码工具
|
||||
apt install intel-microcode (amd64-microcode)
|
||||
|
||||
## 更新 PCI 数据库
|
||||
update-pciids
|
||||
|
||||
```
|
||||
|
||||
本篇教程后续命令,均在 SSH 终端下完成。
|
||||
本文后续命令,均在 SSH 终端下完成。
|
||||
|
||||
|
||||
## 1.Fail2ban 配置
|
||||
|
||||
安装好 `fail2ban` 后,检查其服务状态:
|
||||
|
||||
```bash
|
||||
## 检查 Fail2ban 系统服务状态
|
||||
systemctl status fail2ban.service
|
||||
```
|
||||
|
||||
在 `Loaded` 行,检查是否存在 `enable` :
|
||||
|
||||
```bash
|
||||
## 参考输出
|
||||
|
||||
● fail2ban.service - Fail2Ban Service
|
||||
Loaded: loaded (/lib/systemd/system/fail2ban.service; enabled; vendor preset: enabled)
|
||||
Active: active (running) since Sat 2022-07-16 05:03:53 CST; 4 days ago
|
||||
Docs: man:fail2ban(1)
|
||||
Process: 777 ExecStartPre=/bin/mkdir -p /run/fail2ban (code=exited, status=0/SUCCESS)
|
||||
Main PID: 792 (fail2ban-server)
|
||||
Tasks: 5 (limit: 18904)
|
||||
Memory: 13.3M
|
||||
CPU: 4min 53.764s
|
||||
CGroup: /system.slice/fail2ban.service
|
||||
└─792 /usr/bin/python3 /usr/bin/fail2ban-server -xf start
|
||||
|
||||
Jul 16 05:03:53 hyper systemd[1]: Starting Fail2Ban Service...
|
||||
Jul 16 05:03:53 hyper systemd[1]: Started Fail2Ban Service.
|
||||
Jul 16 05:03:53 hyper fail2ban-server[792]: Server ready
|
||||
```
|
||||
|
||||
其中第 1 个 `enable` 表示当前服务开机自动启动,第 2 个 `enable` 表示该软件的默认启用状态。
|
||||
|
||||
如果第 1 个不为 `enable` 状态,需要用以下命令进行调整:
|
||||
|
||||
```bash
|
||||
## 开机自启 fail2ban 服务
|
||||
systemctl enable fail2ban.service
|
||||
|
||||
## 参考输出
|
||||
Synchronizing state of fail2ban.service with SysV service script with /lib/systemd/systemd-sysv-install.
|
||||
Executing: /lib/systemd/systemd-sysv-install enable fail2ban
|
||||
Created symlink /etc/systemd/system/multi-user.target.wants/fail2ban.service → /lib/systemd/system/fail2ban.service.
|
||||
```
|
||||
|
||||
执行完成后,再次通过前面的命令检查服务自启状态。
|
||||
|
||||
后续如果想查看 `Fail2ban` 有关 `sshd` 的执行状态,可使用如下命令:
|
||||
|
||||
```bash
|
||||
## 检查 sshd 的执行情况
|
||||
fail2ban-client status sshd
|
||||
|
||||
## 参考输出
|
||||
Status for the jail: sshd
|
||||
|- Filter
|
||||
| |- Currently failed: 0
|
||||
| |- Total failed: 0
|
||||
| `- File list: /var/log/auth.log
|
||||
`- Actions
|
||||
|- Currently banned: 0
|
||||
|- Total banned: 0
|
||||
`- Banned IP list:
|
||||
```
|
||||
|
||||
如果均为 0 ,表示当前 PVE 系统没有 SSH 错误密码的尝试记录。
|
||||
|
||||
|
||||
## 2.系统时区配置
|
||||
## 1.系统时区配置
|
||||
|
||||
如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以使用以下命令修正:
|
||||
|
||||
@@ -104,36 +42,106 @@ date -R
|
||||
Wed, 20 Jul 2022 16:21:28 +0800
|
||||
```
|
||||
|
||||
输出结果如果和北京时间一致,则代表修改正确。
|
||||
输出结果如果和北京时间一致,则代表修改正确。
|
||||
|
||||
Debian 系统常用 `systemd-timesyncd.service` 来同步时间,而 PVE 系统使用 `chrony.service` 来同步时间。
|
||||
|
||||
## 3.CPU调度器配置
|
||||
为了使用国内的 NTP 服务器,需要对 `chrony.service` 进行配置。
|
||||
|
||||
执行以下命令对 `chrony` 的配置文件进行修改:
|
||||
|
||||
```bash
|
||||
## 编辑 chrony 配置文件
|
||||
nano /etc/chrony/chrony.conf
|
||||
```
|
||||
|
||||
在编辑器对话框中,将 `pool 2.debian.pool.ntp.org iburst` 这行内容 “注释” 掉,并添加国内的 NTP 服务器,参考如下内容:
|
||||
|
||||
```bash
|
||||
## chrony 服务配置文件示例
|
||||
|
||||
# Use Debian vendor zone.
|
||||
# pool 2.debian.pool.ntp.org iburst ## 在这行前面增加注释符 # 来注释
|
||||
|
||||
# Use Custom vendor zone.
|
||||
pool ntp.tencent.com iburst
|
||||
pool ntp.aliyun.com iburst
|
||||
```
|
||||
|
||||
保存该配置文件后,重启 `chrony` 服务:
|
||||
|
||||
```bash
|
||||
## 重启 chrony 服务
|
||||
systemctl restart chrony.service
|
||||
```
|
||||
|
||||
再检查系统 NTP 服务器是否被正确修改:
|
||||
|
||||
```bash
|
||||
## 检查系统 NTP 服务器
|
||||
chronyc sources -V
|
||||
```
|
||||
|
||||
如果输出以下类似内容,则表示系统 NTP 服务设置正确:
|
||||
|
||||
```bash
|
||||
## NTP 服务示例输出
|
||||
|
||||
MS Name/IP address Stratum Poll Reach LastRx Last sample
|
||||
===============================================================================
|
||||
^+ 139.199.215.251 2 10 177 244 -1669us[-1757us] +/- 67ms
|
||||
^* 203.107.6.88 2 10 377 105 -1005us[-1094us] +/- 19ms
|
||||
```
|
||||
|
||||
## 2.CPU调度器配置
|
||||
|
||||
安装好 `cpufrequtils` 后,先检查当前 CPU 的调度器:
|
||||
|
||||
```bash
|
||||
## 检查 CPU 当前调度器
|
||||
cpufreq-info
|
||||
```
|
||||
**设备 CPU - J4125 参考输出** :
|
||||
|
||||
## 参考输出
|
||||
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
|
||||
Report errors and bugs to cpufreq@vger.kernel.org, please.
|
||||
analyzing CPU 0:
|
||||
driver: intel_cpufreq
|
||||
CPUs which run at the same hardware frequency: 0
|
||||
CPUs which need to have their frequency coordinated by software: 0
|
||||
maximum transition latency: 20.0 us.
|
||||
hardware limits: 800 MHz - 2.90 GHz
|
||||
available cpufreq governors: conservative, ondemand, userspace, powersave, performance, schedutil
|
||||
current policy: frequency should be within 800 MHz and 2.90 GHz.
|
||||
The governor "ondemand" may decide which speed to use
|
||||
within this range.
|
||||
current CPU frequency is 952 MHz.
|
||||
```bash
|
||||
## J4125 参考输出
|
||||
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
|
||||
Report errors and bugs to cpufreq@vger.kernel.org, please.
|
||||
analyzing CPU 0:
|
||||
driver: intel_cpufreq
|
||||
CPUs which run at the same hardware frequency: 0
|
||||
CPUs which need to have their frequency coordinated by software: 0
|
||||
maximum transition latency: 20.0 us.
|
||||
hardware limits: 800 MHz - 2.70 GHz
|
||||
available cpufreq governors: conservative, ondemand, userspace, powersave, performance, schedutil
|
||||
current policy: frequency should be within 800 MHz and 2.70 GHz.
|
||||
The governor "ondemand" may decide which speed to use
|
||||
within this range.
|
||||
current CPU frequency is 1.84 GHz.
|
||||
```
|
||||
|
||||
**设备 CPU - N5105 参考输出** :
|
||||
|
||||
```bash
|
||||
## N5105 参考输出
|
||||
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
|
||||
Report errors and bugs to cpufreq@vger.kernel.org, please.
|
||||
analyzing CPU 0:
|
||||
driver: intel_pstate
|
||||
CPUs which run at the same hardware frequency: 0
|
||||
CPUs which need to have their frequency coordinated by software: 0
|
||||
maximum transition latency: 4294.55 ms.
|
||||
hardware limits: 800 MHz - 2.90 GHz
|
||||
available cpufreq governors: performance, powersave
|
||||
current policy: frequency should be within 800 MHz and 2.90 GHz.
|
||||
The governor "performance" may decide which speed to use
|
||||
within this range.
|
||||
current CPU frequency is 1.36 GHz.
|
||||
```
|
||||
|
||||
这里面主要关注两个点:
|
||||
- driver: intel_cpufreq
|
||||
- current policy: governor "ondemand"
|
||||
- driver: `intel_cpufreq` 或 `intel_pstate`
|
||||
- current policy: `governor "ondemand"` 或 `governor "performance"`
|
||||
|
||||
当然还有另外一个命令可以用来显示 CPU 调度器:
|
||||
|
||||
@@ -141,11 +149,14 @@ analyzing CPU 0:
|
||||
## 检查 CPU 当前调度器
|
||||
cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_governor
|
||||
|
||||
## 参考输出
|
||||
## J4125 参考输出
|
||||
ondemand
|
||||
|
||||
## N5105 参考输出
|
||||
performance
|
||||
```
|
||||
|
||||
驱动一般不建议手动调整,而 `governor "ondemand"` 则显示了当前 CPU 的调度器是什么。
|
||||
驱动一般不建议手动调整,而 `governor` 后面的参数则显示了当前 CPU 的调度器是什么。
|
||||
|
||||
接下来,我们需要了解当前系统 CPU 支持的调度器有哪些:
|
||||
|
||||
@@ -153,13 +164,20 @@ ondemand
|
||||
## 检查 CPU 调度器支持情况
|
||||
cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors
|
||||
|
||||
## 参考输出
|
||||
## J4125 参考输出
|
||||
conservative ondemand userspace powersave performance schedutil
|
||||
|
||||
## N5105 参考输出
|
||||
performance powersave
|
||||
```
|
||||
|
||||
这里有很多种调度器可供选择,至于每种调度器有什么优劣,欢迎大家深度挖掘。
|
||||
根据 CPU 所使用的驱动不同,可选调度器也不同,至于每种调度器有什么优劣,欢迎大家深度挖掘。
|
||||
|
||||
本教程以使用 `schedutil` 调度器为演示。
|
||||
CPU 驱动为 `intel_pstate` 时,建议使用 `powersave` 调度器。
|
||||
|
||||
CPU 驱动为 `intel_cpufreq` 时,建议使用 `schedutil` 调度器。
|
||||
|
||||
本文以使用 `powersave` 调度器为演示。
|
||||
|
||||
使用 `vim` 编辑器来编辑 `cpufrequtils` 的配置文件:
|
||||
|
||||
@@ -170,14 +188,14 @@ vim /etc/init.d/cpufrequtils
|
||||
## 在配置文件中修改调度器
|
||||
|
||||
ENABLE="true"
|
||||
GOVERNOR="schedutil" ## 修改本行的调度器为 schedutil
|
||||
GOVERNOR="powersave" ## 修改本行的调度器为 powersave
|
||||
MAX_SPEED="0"
|
||||
MIN_SPEED="0"
|
||||
```
|
||||
|
||||
按 `i` 键进入编辑模式,`esc` 键退出编辑模式,`:wq` 命令保存退出。
|
||||
|
||||
因为该配置文件很长,教程中留下一份已配置好的文件 [Fox_PVE_Cpufrequtils.conf](./src/Fox_PVE_Cpufrequtils.conf) ,以便对比。
|
||||
因为该配置文件很长,文章中留下一份已配置好的文件 [pve_cpufrequtils.conf](./src/pve_cpufrequtils.conf) ,以便对比。
|
||||
|
||||
修改完成后,需要重新启动 PVE 服务器来使参数生效。
|
||||
|
||||
@@ -193,8 +211,7 @@ watch cat /sys/devices/system/cpu/cpu[0-9]*/cpufreq/scaling_cur_freq
|
||||
watch sensors
|
||||
```
|
||||
|
||||
|
||||
## 4.PVE 定时重启配置
|
||||
## 3.PVE定时重启配置
|
||||
|
||||
有时候我们需要让 PVE 服务器周期性的定时重启,则可使用以下命令:
|
||||
|
||||
@@ -215,10 +232,9 @@ crontab -e
|
||||
crontab -l
|
||||
```
|
||||
|
||||
## 4.PVE系统自动更新
|
||||
|
||||
## 5.PVE系统自动更新
|
||||
|
||||
### 5.1.检查系统定时器
|
||||
### 4.1.检查系统定时器
|
||||
|
||||
配置系统自动更新之前,先检查当前系统定时器状态:
|
||||
|
||||
@@ -235,12 +251,12 @@ systemctl status apt-daily-upgrade.timer
|
||||
Trigger: Thu 2022-07-17 06:52:50 CST; 13h left
|
||||
Triggers: ● apt-daily-upgrade.service
|
||||
|
||||
Jul 16 12:03:53 hyper systemd[1]: Started Daily apt upgrade and clean activities.
|
||||
Jul 16 12:03:53 node01 systemd[1]: Started Daily apt upgrade and clean activities.
|
||||
```
|
||||
|
||||
我们后续将手动调整该定时器的时间为,每 10 天的凌晨 02:00 进行触发。
|
||||
|
||||
### 5.2.配置自动更新策略
|
||||
### 4.2.配置自动更新策略
|
||||
|
||||
```bash
|
||||
## 配置自动更新策略
|
||||
@@ -277,13 +293,13 @@ APT::Periodic::CleanInterval "1";
|
||||
## 编辑 50unattended-upgrades 配置文件
|
||||
vim 50unattended-upgrades
|
||||
|
||||
## 取消了以下行前面的注释,代表启用
|
||||
## 删除以下行前面的注释符 // ,代表启用
|
||||
"origin=Debian,codename=${distro_codename}-updates";
|
||||
|
||||
## 添加了 PVE 本身的更新项目
|
||||
"origin=Proxmox,codename=${distro_codename},label=Proxmox Debian Repository";
|
||||
|
||||
## 取消以下行的前面注释,代表启用,并调整参数
|
||||
## 删除以下行前面的注释符,代表启用,并调整参数
|
||||
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
@@ -307,11 +323,11 @@ Unattended-Upgrade::Automatic-Reboot-Time "05:00";
|
||||
- 自动重启:开启。
|
||||
- 自动重启时间:05:00。
|
||||
|
||||
因为该配置文件很长,教程中留下一份 PVE 7.2 中已配置好的文件 [Fox_PVE_50unattended_Upgrades.conf](./src/Fox_PVE_50unattended_Upgrades.conf),以便对比。
|
||||
因为该配置文件很长,文章中留下一份 PVE 7.2 中已配置好的文件 [pve_50unattended_upgrades.conf](./src/pve_50unattended_upgrades.conf) ,以便对比。
|
||||
|
||||
仔细再仔细确认无误后,`esc` 键退出编辑模式,`:wq` 命令保存退出。
|
||||
|
||||
### 5.3.重设自动更新触发器
|
||||
### 4.3.重设自动更新触发器
|
||||
|
||||
```bash
|
||||
## 重设自动更新触发器时间为凌晨 02:00
|
||||
@@ -324,7 +340,7 @@ OnCalendar=02:00
|
||||
RandomizedDelaySec=0
|
||||
```
|
||||
|
||||
完整的配置文件可查看 [Fox_PVE_Apt_Daily_Upgrade.conf](./src/Fox_PVE_Apt_Daily_Upgrade.conf),以便对比。
|
||||
完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve_apt_daily_upgrade.conf),以便对比。
|
||||
|
||||
设置完成后重启自动更新的触发器:
|
||||
|
||||
@@ -344,9 +360,9 @@ systemctl status apt-daily-upgrade.timer
|
||||
Trigger: Thu 2022-07-21 02:00:00 CST; 8h left
|
||||
Triggers: ● apt-daily-upgrade.service
|
||||
|
||||
Jul 20 17:36:40 hyper systemd[1]: Stopped Daily apt upgrade and clean activities.
|
||||
Jul 20 17:36:40 hyper systemd[1]: Stopping Daily apt upgrade and clean activities.
|
||||
Jul 20 17:36:40 hyper systemd[1]: Started Daily apt upgrade and clean activities.
|
||||
Jul 20 17:36:40 node01 systemd[1]: Stopped Daily apt upgrade and clean activities.
|
||||
Jul 20 17:36:40 node01 systemd[1]: Stopping Daily apt upgrade and clean activities.
|
||||
Jul 20 17:36:40 node01 systemd[1]: Started Daily apt upgrade and clean activities.
|
||||
```
|
||||
|
||||
至此 PVE 的系统调整已经完成,重启设备后,可以愉快使用了。
|
||||
@@ -6,7 +6,7 @@
|
||||
|
||||
访问 [Debian Official Cloud Images](https://cloud.debian.org/images/cloud/) 官方网站,下载最新版 `Bullseye` 云镜像以及对应的校验文件:
|
||||
|
||||

|
||||

|
||||
|
||||
该虚拟机模板主要作为内网 DNS 服务器使用,并会安装 Adguard Home 。
|
||||
|
||||
@@ -18,7 +18,7 @@
|
||||
|
||||
节点即本机,`VM ID` 和 `名称` 可以自由定义。
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.2.操作系统
|
||||
|
||||
@@ -26,17 +26,21 @@
|
||||
|
||||
操作系统类别选择 `Linux` 、版本选择 `5.x - 2.6 Kernel` 即可。
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.3.系统
|
||||
|
||||
系统部分需要修改一些内容,以满足 Debian 使用 `UEFI` 启动需求。
|
||||
|
||||
显卡使用 `SPICE` ,机型使用 `q35` ,SCSI 控制器选择 `VirtIO SCSI single` ,勾选 `Qemu代理` 选项。
|
||||
显卡选择 `默认`,图中使用的 `SPICE` 仅供测试。
|
||||
|
||||
机型一般选择 `默认` 即可,使用 `q35` 主要为了测试 `UEFI` 启动。
|
||||
|
||||
SCSI 控制器选择 `VirtIO SCSI single` ,勾选 `Qemu代理` 选项。
|
||||
|
||||
在固件处需要针对 `UEFI` 进行调整,BIOS 选择 `OVMF (UEFI)` ,勾选 `添加EFI磁盘` ,EFI 存储选择 `local-lvm` :
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.4.磁盘
|
||||
|
||||
@@ -44,39 +48,41 @@
|
||||
|
||||
由于使用 Cloud Image 制作虚拟机模板,此处删除所有磁盘:
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.5.CPU
|
||||
|
||||
CPU类别选择 `host` ,核心根据物理 CPU 核心数进行酌情设置,推荐启用 `NUMA` :
|
||||
CPU类别选择 `host` ,核心根据物理 CPU 核心数进行酌情设置。
|
||||
|
||||

|
||||
若 PVE 服务器内有多颗物理 CPU ,则推荐启用 `NUMA` :
|
||||
|
||||

|
||||
|
||||
### 1.6.内存
|
||||
|
||||
内存一般 2G 足够使用,关闭 `Ballooning` 设备选项:
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.7.网络
|
||||
|
||||
在 PVE 的 [网络设置](./2.PVE初始化配置.md#3配置-pve-网桥和管理网口) 中,曾创建了一个没有桥接任何物理网口的内部网桥。
|
||||
在 PVE 的 [网络设置](./02.PVE初始化配置.md#3配置-pve-网桥和管理网口) 中,曾创建了一个没有桥接任何物理网口的内部网桥。
|
||||
|
||||
并且该网桥接口为主路由 RouterOS 的 LAN 的成员接口。
|
||||
|
||||
因此 Debian 虚拟机的网络设备选择该内部网桥即可,演示环境为 `vmbr4` :
|
||||
|
||||

|
||||

|
||||
|
||||
取消网口的 `防火墙` ,并根据虚拟机 vCPU 数,指定 `Multiqueue` 的数量,演示环境为 `2` :
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.8.确认
|
||||
|
||||
接下来查看设置总览,确认无误,即可点击 “完成” :
|
||||
|
||||

|
||||

|
||||
|
||||
## 2.调整虚拟机硬件参数
|
||||
|
||||
@@ -84,7 +90,7 @@ CPU类别选择 `host` ,核心根据物理 CPU 核心数进行酌情设置,
|
||||
|
||||
此时,查看虚拟机详情页,可以看到我们刚才创建的 Debian 虚拟机,删除 `CD/DVD驱动器` :
|
||||
|
||||

|
||||

|
||||
|
||||
### 2.2.虚拟机导入磁盘镜像
|
||||
|
||||
@@ -121,21 +127,21 @@ qm importdisk 1000 debian-11-genericcloud-amd64.qcow2 local-lvm
|
||||
Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-1'
|
||||
```
|
||||
|
||||

|
||||

|
||||
|
||||
鼠标 **双击** 该未使用的磁盘,勾选 `IO thread` ,点击添加按钮:
|
||||
|
||||

|
||||

|
||||
|
||||
刚导入的磁盘只有 `2G` 磁盘空间,为了后续方便使用,先给磁盘扩容 `16G` 的磁盘空间。
|
||||
|
||||
鼠标 **单击** 选中该磁盘,选择页面顶部 `Disk Action` 菜单的子菜单 `Resize` :
|
||||
|
||||

|
||||

|
||||
|
||||
在弹出的对话框中,给该磁盘增加 `16G` 磁盘空间:
|
||||
|
||||

|
||||

|
||||
|
||||
### 2.3.虚拟机添加CloudInit设备
|
||||
|
||||
@@ -143,11 +149,11 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-1'
|
||||
|
||||
点击顶部 `添加` 按钮,选择 `CloudInit设备` :
|
||||
|
||||

|
||||

|
||||
|
||||
`总线/设备` 选择 `SCSI` ,编号为 `1` ,存储选择 `local-lvm` :
|
||||
|
||||

|
||||

|
||||
|
||||
### 2.4.虚拟机添加串行端口
|
||||
|
||||
@@ -155,15 +161,15 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-1'
|
||||
|
||||
点击顶部 `添加` 按钮,选择 `串行端口` :
|
||||
|
||||

|
||||

|
||||
|
||||
串行端口编号为 `0` :
|
||||
|
||||

|
||||

|
||||
|
||||
虚拟机硬件设备修改完成后,如下图所示:
|
||||
|
||||

|
||||

|
||||
|
||||
## 3.调整虚拟机配置参数
|
||||
|
||||
@@ -184,13 +190,13 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-1'
|
||||
|
||||
然后点击 `OK` 按钮:
|
||||
|
||||

|
||||

|
||||
|
||||
### 3.2.修改平板指针设置
|
||||
|
||||
关闭 `使用平板指针` 选项,可以一定程度上降低虚拟机的 CPU 使用率。
|
||||
|
||||

|
||||

|
||||
|
||||
## 4.设置Cloud-Init
|
||||
|
||||
@@ -202,10 +208,10 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-1'
|
||||
|--|--|--|
|
||||
|用户|fox|新系统的管理员账户|
|
||||
|密码|********|使用强密码|
|
||||
|DNS域|fox.lab|内网域名(可选)|
|
||||
|DNS服务器|`172.16.1.1 127.0.0.1`|本机DNS服务器,用空格隔开|
|
||||
|DNS域|fox.local|内网域名(可选)|
|
||||
|DNS服务器|`172.16.1.1 fdac::1 127.0.0.1`|本机DNS服务器,用空格隔开|
|
||||
|SSH公钥|无|使用秘钥登录服务器,暂不使用|
|
||||
|IP配置(net0)|`ip=172.16.1.240/24,gw=172.16.1.1`|模板的 IP 设置|
|
||||
|IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置|
|
||||
|
||||
**说明:**
|
||||
|
||||
@@ -213,12 +219,12 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-1'
|
||||
|
||||
在 `DNS服务器` 设置部分,如果先设置了 `127.0.0.1` 作为虚拟机 DNS 服务器,后续其他 DNS 的 IP 地址将被虚拟机忽略。
|
||||
|
||||
此时内网没有其他 DNS 服务器存在,因此 `DNS服务器` 先设置为 `172.16.1.1 127.0.0.1` ,IP 之间用空格隔开。
|
||||
此时内网没有其他 DNS 服务器存在,因此 `DNS服务器` 先设置为 `172.16.1.1 fdac::1 127.0.0.1` ,IP 之间用空格隔开。
|
||||
|
||||
在使用 Debian 模板克隆出新虚拟机之后,再对新虚拟机调整 IP 设置比较好。
|
||||
|
||||
`Cloud-Init` 的 `IP配置` ,如下图所示:
|
||||
|
||||

|
||||

|
||||
|
||||
设置完成后,Debian 虚拟机必要参数全部设置完成,可以将该虚拟机开机。
|
||||
@@ -1,6 +1,6 @@
|
||||
## 1.配置Debian系统
|
||||
|
||||
在上一篇文章 [4.PVE创建模板虚拟机](./4.PVE创建模板虚拟机.md) 中,我们已经创建好了用于制作虚拟机模板的 Debian 虚拟机。
|
||||
在上一篇文章 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) 中,我们已经创建好了用于制作虚拟机模板的 Debian 虚拟机。
|
||||
|
||||
并调整了模板虚拟机的硬件参数、配置参数,但还需对 Debian 系统进行调整。
|
||||
|
||||
@@ -10,13 +10,13 @@
|
||||
|
||||
因为 Debian 的云镜像默认使用秘钥登录,因此切换到左侧菜单的 `控制台` 进行操作:
|
||||
|
||||

|
||||

|
||||
|
||||
在 Debian 虚拟机的命令行界面,使用 `nano` 编辑器编辑 `sshd` 服务的配置文件,执行以下命令:
|
||||
|
||||
```bash
|
||||
## 编辑 ssh 配置文件
|
||||
sudo nano /etc/ssh/sshd_config.d/fox_sshd.conf
|
||||
sudo nano /etc/ssh/sshd_config.d/fox_sshd.conf
|
||||
```
|
||||
|
||||
在编辑器对话框中输入以下内容,注意命令中间的空格:
|
||||
@@ -25,6 +25,8 @@ sudo nano /etc/ssh/sshd_config.d/fox_sshd.conf
|
||||
PasswordAuthentication yes
|
||||
|
||||
PermitEmptyPasswords no
|
||||
|
||||
UseDNS no
|
||||
```
|
||||
|
||||
`nano` 编辑器常用操作如下:
|
||||
@@ -42,11 +44,11 @@ sudo systemctl restart ssh.service
|
||||
|
||||
### 1.2.配置系统软件源
|
||||
|
||||
使用 SSH 工具登录 Debian 虚拟机,常用 SSH 工具可以看之前的文章中的 [SSH 工具推荐](./1.PVE系统安装.md#03ssh工具) 。
|
||||
使用 SSH 工具登录 Debian 虚拟机,常用 SSH 工具可以看之前文章中的 [SSH 工具推荐](./01.PVE系统安装.md#03ssh工具) 。
|
||||
|
||||
首先需要对 Debian 系统的软件源进行修改,这里使用 USTC 的软件源。
|
||||
首先需要对 Debian 系统的软件源进行修改,这里使用 USTC 镜像站作为演示。
|
||||
|
||||
如果以后系统版本发生变化,参考使用 snullp 大叔开发的 [配置生成器](https://mirrors.ustc.edu.cn/repogen/) 。
|
||||
以后当系统版本发生变化时,请参考使用 snullp 大叔开发的 [配置生成器](https://mirrors.ustc.edu.cn/repogen/) 。
|
||||
|
||||
逐条执行以下命令:
|
||||
|
||||
@@ -77,7 +79,7 @@ deb https://mirrors.ustc.edu.cn/debian-security/ bullseye-security main contrib
|
||||
# deb-src https://mirrors.ustc.edu.cn/debian-security/ bullseye-security main contrib non-free
|
||||
```
|
||||
|
||||
更新软件源的同步内容,并更新系统,逐条执行以下命令:
|
||||
更新软件源的同步内容,并更新系统,逐条执行以下命令:
|
||||
|
||||
```bash
|
||||
## 清理不必要的包
|
||||
@@ -94,16 +96,22 @@ sudo apt dist-upgrade
|
||||
|
||||
```bash
|
||||
## 安装系统软件
|
||||
sudo apt install qemu-guest-agent zsh git curl htop lm-sensors fail2ban vim tmux unattended-upgrades apt-listchanges powermgmt-base
|
||||
sudo apt install qemu-guest-agent zsh git curl htop lm-sensors vim tmux nftables sshguard
|
||||
|
||||
## 安装系统自动更新工具
|
||||
sudo apt install unattended-upgrades apt-listchanges powermgmt-base python3-gi
|
||||
|
||||
## 安装网络工具
|
||||
sudo apt install iperf iperf3 iftop lsof dnsutils
|
||||
sudo apt install iperf iperf3 iftop lsof ldnsutils dhcpcd5
|
||||
|
||||
## 安装 snap
|
||||
sudo apt install snapd
|
||||
|
||||
## 安装 Adguard Home
|
||||
sudo snap install adguard-home
|
||||
|
||||
## 写入磁盘
|
||||
sudo sync
|
||||
```
|
||||
|
||||
Adguard Home 安装完成后,先停止其服务:
|
||||
@@ -113,11 +121,11 @@ Adguard Home 安装完成后,先停止其服务:
|
||||
sudo snap stop adguard-home
|
||||
```
|
||||
|
||||
### 1.3.配置系统网卡
|
||||
### 1.3.配置网卡IPv4
|
||||
|
||||
使用 `Cloud-Init` 并给虚拟机分配了 IP 地址后,虚拟机的网卡还会从路由器的 DHCP 再获取一个 IP 地址。
|
||||
使用 `Cloud-Init` 并给虚拟机分配了静态 IPv4 地址后,虚拟机的网卡还会从路由器的 DHCP 再获取一个 IPv4 地址。
|
||||
|
||||
这个功能在给虚拟机添加网卡设备时很有用,但本 Debian 虚拟机模板的使用场景只需要一个静态 IP 地址,因此需要禁用网卡自动获取 IP 地址的功能。
|
||||
这个功能在给虚拟机添加网卡设备时很有用,但本 Debian 虚拟机模板的使用场景只需要一个静态 IPv4 地址,因此需要禁用网卡自动获取 IPv4 地址的功能。
|
||||
|
||||
执行以下命令对网卡的配置文件进行修改:
|
||||
|
||||
@@ -136,48 +144,112 @@ sudo nano /etc/network/interfaces
|
||||
# and /etc/network/cloud-ifupdown-helper. Dynamically generated
|
||||
# configuration fragments are stored in /run:
|
||||
# source-directory /run/network/interfaces.d ## 在这行前面增加注释符 # 来注释
|
||||
|
||||
```
|
||||
|
||||
将配置保存后,可以将模板虚拟机重启。
|
||||
|
||||
在系统重启完成后,执行以下命令检查系统的 IP 地址状态:
|
||||
在系统重启完成后,执行以下命令检查系统的 IPv4 地址状态:
|
||||
|
||||
```bash
|
||||
## 检查系统 IP 地址状态
|
||||
ip a
|
||||
```
|
||||
|
||||
如果系统网卡有且仅有一个 IP 地址,且该 IP 地址与 `Cloud-Init` 中设置的 IP 地址相同,则表示系统网卡已正确设置。
|
||||
如果系统网卡有且仅有一个 IPv4 地址,且该 IPv4 地址与 `Cloud-Init` 中设置的 IPv4 地址相同,则表示系统网卡已正确设置。
|
||||
|
||||
### 1.4.调整系统内核参数
|
||||
### 1.4.配置网卡IPv6
|
||||
|
||||
由于该 Debian 虚拟机模板将用于克隆内网 DNS 服务器,因此需要调整一部分系统内核参数来简单优化性能。
|
||||
使用 `Cloud-Init` 并给虚拟机分配了静态 IPv6 地址后,该地址为私有 ULA 地址,此时虚拟机的网卡不会以 `SLAAC` 的方式配置 IPv6 地址。
|
||||
|
||||
执行以下命令对 `sysctl` 的配置文件进行修改:
|
||||
如果上级路由器没有设置 `NAT66` ,且将公网 GUA 地址的 `Prefix` 通告到内网时,虚拟机将无法自动生成 GUA 地址,从而导致无法访问 IPv6 网络。
|
||||
|
||||
因此引入 `dhcpcd` 工具,在正确配置虚拟机 IPv6 地址的同时,保持与 `Cloud-Init` 网卡配置的兼容性。
|
||||
|
||||
执行以下命令对网卡的配置文件进行修改:
|
||||
|
||||
```bash
|
||||
## 调整系统内核参数
|
||||
sudo nano /etc/sysctl.conf
|
||||
## 备份 dhcpcd 配置文件
|
||||
sudo mv /etc/dhcpcd.conf /etc/dhcpcd.conf.bak
|
||||
|
||||
## 修改 dhcpcd 配置文件
|
||||
sudo nano /etc/dhcpcd.conf
|
||||
```
|
||||
|
||||
在编辑器对话框中输入以下内容,注意命令中间的空格:
|
||||
|
||||
```bash
|
||||
# This configuration file is customized by fox
|
||||
# Optimize dhcpcd parameters for dns server
|
||||
|
||||
# Only configure IPv6
|
||||
ipv6only
|
||||
|
||||
# Inform the DHCP server of our hostname for DDNS.
|
||||
hostname
|
||||
|
||||
# A list of options to request from the DHCP server.
|
||||
nooption domain_name_servers, domain_name, domain_search, host_name
|
||||
option classless_static_routes
|
||||
|
||||
# Respect the network MTU.
|
||||
option interface_mtu
|
||||
|
||||
# A ServerID is required by RFC2131.
|
||||
require dhcp_server_identifier
|
||||
|
||||
# Generate Stable Private IPv6 Addresses based from the DUID
|
||||
slaac private
|
||||
|
||||
# Don't send any ARP requests.
|
||||
noarp
|
||||
```
|
||||
|
||||
保存该配置文件后,重启系统或者执行以下命令重启 `dhcpcd` 服务:
|
||||
|
||||
```bash
|
||||
## 重启 dhcpcd 服务
|
||||
sudo systemctl restart dhcpcd.service
|
||||
```
|
||||
|
||||
### 1.5.调整系统内核参数
|
||||
|
||||
由于该 Debian 虚拟机模板将用于克隆内网 DNS 服务器,因此需要调整一部分系统内核参数来简单优化性能。
|
||||
|
||||
使用 `nano` 编辑器编辑 **内核参数** 配置文件,执行以下命令:
|
||||
|
||||
```bash
|
||||
## 编辑 内核参数 配置文件
|
||||
sudo nano /etc/sysctl.d/99-sysctl.conf
|
||||
```
|
||||
|
||||
在配置文件末尾输入以下内容,注意命令中间的空格:
|
||||
|
||||
```bash
|
||||
# This configuration file is customized by fox
|
||||
# Optimize system parameters
|
||||
|
||||
kernel.panic = 20
|
||||
kernel.panic_on_oops = 1
|
||||
|
||||
net.core.default_qdisc = fq_codel
|
||||
net.ipv4.tcp_congestion_control = bbr
|
||||
|
||||
net.ipv6.conf.all.disable_ipv6 = 1
|
||||
# Other adjustable system parameters
|
||||
|
||||
net.ipv4.tcp_fastopen = 1
|
||||
net.ipv4.conf.all.log_martians = 1
|
||||
|
||||
net.ipv4.igmp_max_memberships = 100
|
||||
|
||||
net.ipv4.tcp_challenge_ack_limit = 1000
|
||||
net.ipv4.tcp_fin_timeout = 30
|
||||
net.ipv4.tcp_keepalive_time = 120
|
||||
net.ipv4.tcp_max_orphans = 4096
|
||||
net.ipv4.tcp_max_tw_buckets = 4096
|
||||
net.ipv4.tcp_syncookies = 1
|
||||
net.ipv4.tcp_notsent_lowat = 131072
|
||||
|
||||
net.ipv4.tcp_ecn = 1
|
||||
net.ipv4.tcp_sack = 1
|
||||
net.ipv4.tcp_dsack = 1
|
||||
net.ipv6.conf.all.use_tempaddr = 0
|
||||
net.ipv6.conf.default.use_tempaddr = 0
|
||||
|
||||
net.ipv4.icmp_ratelimit = 50
|
||||
```
|
||||
|
||||
保存该配置文件后,重启系统或者执行以下命令让配置生效:
|
||||
@@ -187,7 +259,7 @@ net.ipv4.icmp_ratelimit = 50
|
||||
sudo sysctl -f
|
||||
```
|
||||
|
||||
### 1.5.调整系统时间
|
||||
### 1.6.调整系统时间
|
||||
|
||||
默认情况下的 Debian 云镜像的系统时间可能不正确,执行以下命令将系统时区设置为中国时区:
|
||||
|
||||
@@ -252,9 +324,9 @@ MS Name/IP address Stratum Poll Reach LastRx Last sample
|
||||
^* 203.107.6.88 2 10 377 105 -1005us[-1094us] +/- 19ms
|
||||
```
|
||||
|
||||
### 1.6.配置系统自动更新
|
||||
### 1.7.配置系统自动更新
|
||||
|
||||
配置 Debian 模板虚拟机的系统自动更新,与配置 PVE 系统自动更新方法基本一致,参阅 [PVE系统自动更新](./3.PVE系统调整.md#5pve系统自动更新) 。
|
||||
配置 Debian 模板虚拟机的系统自动更新,与配置 PVE 系统自动更新方法基本一致,参阅 [PVE系统自动更新](./03.PVE系统调整.md#5pve系统自动更新) 。
|
||||
|
||||
配置系统更新之前,先检查当前系统定时器状态:
|
||||
|
||||
@@ -290,7 +362,7 @@ APT::Periodic::AutocleanInterval "1";
|
||||
APT::Periodic::CleanInterval "1";
|
||||
```
|
||||
|
||||
其中,用来控制系统更新周期的为 `APT::Periodic::Unattended-Upgrade` 这行内容,其中的“5”表示更新周期为“5”天。
|
||||
其中,用来控制系统更新周期的为 `APT::Periodic::Unattended-Upgrade` 这行内容,其中参数 `"5"` 表示更新周期为 `5` 天。
|
||||
|
||||
再调整 apt 的 `50unattended-upgrades` 配置文件,所有修改项目汇聚如下:
|
||||
|
||||
@@ -318,6 +390,8 @@ Unattended-Upgrade::Automatic-Reboot "true";
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "04:30";
|
||||
```
|
||||
|
||||
因为该配置文件很长,文章中留下一份 Debian 中已配置好的文件 [debian_50unattended_upgrades.conf](./src/debian_50unattended_upgrades.conf) ,以便对比。
|
||||
|
||||
两个配置文件均修改完成后,需要重设系统自动更新触发器,执行以下命令:
|
||||
|
||||
```bash
|
||||
@@ -343,7 +417,7 @@ sudo systemctl status apt-daily-upgrade.timer
|
||||
|
||||
在输出结果中看到系统自动更新的触发时间为凌晨 `02:00` 则表示设置正确。
|
||||
|
||||
### 1.7.配置Snap自动更新
|
||||
### 1.8.配置Snap自动更新
|
||||
|
||||
先查看 Snap 当前的更新策略,执行以下命令:
|
||||
|
||||
@@ -362,7 +436,7 @@ sudo snap set system refresh.timer=2:30-3:30,14:30-15:30
|
||||
sudo snap set system refresh.timer=mon,2:30,,fri,2:30
|
||||
```
|
||||
|
||||
### 1.8.配置系统定时任务
|
||||
### 1.9.配置系统定时任务
|
||||
|
||||
本步骤为可选操作,主要设置定时重启 Snap 服务以及操作系统。
|
||||
|
||||
@@ -374,11 +448,11 @@ sudo crontab -l
|
||||
sudo crontab -e
|
||||
|
||||
## 定时重启 Snap 服务、操作系统
|
||||
0 5 * * * snap restart adguard-home
|
||||
0 5 * * * /usr/bin/snap restart adguard-home
|
||||
0 6 8,24 * * /usr/sbin/reboot
|
||||
```
|
||||
|
||||
### 1.9.配置ZSH
|
||||
### 1.10.配置ZSH
|
||||
|
||||
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置:
|
||||
|
||||
@@ -398,7 +472,7 @@ Time to change your default shell to zsh:
|
||||
Do you want to change your default shell to zsh? [Y/n] y
|
||||
```
|
||||
|
||||
### 1.10.清理系统
|
||||
### 1.11.清理系统
|
||||
|
||||
Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。
|
||||
|
||||
@@ -427,7 +501,7 @@ history -c
|
||||
|
||||
在左侧虚拟机列表中,鼠标 **右键单击** Debian 模板虚拟机,在弹出的菜单中选择 `转换成模板` :
|
||||
|
||||

|
||||

|
||||
|
||||
需要说明的是,虚拟机 `转换成模板` 的操作是不可逆的。
|
||||
|
||||
@@ -466,8 +540,8 @@ iface ens18 inet static
|
||||
address 172.16.1.2/24
|
||||
gateway 172.16.1.1
|
||||
# dns-* options are implemented by the resolvconf package, if installed
|
||||
dns-nameservers 172.16.1.3
|
||||
dns-search fox.lab
|
||||
dns-nameservers 172.16.1.2
|
||||
dns-search fox.local
|
||||
```
|
||||
|
||||
检查系统的 `hosts` ,执行以下命令:
|
||||
@@ -479,7 +553,7 @@ cat /etc/hosts
|
||||
## 示例输出
|
||||
|
||||
127.0.0.1 localhost
|
||||
172.16.1.2 dns001.fox.lab dns001
|
||||
172.16.1.2 dns01.fox.local dns01
|
||||
|
||||
# The following lines are desirable for IPv6 capable hosts
|
||||
::1 localhost ip6-localhost ip6-loopback
|
||||
@@ -497,9 +571,10 @@ sudo vim /etc/resolv.conf
|
||||
在编辑器对话框中输入以下内容,注意命令中间的空格:
|
||||
|
||||
```bash
|
||||
search fox.lab
|
||||
search fox.local
|
||||
nameserver 172.16.1.2
|
||||
nameserver fdac::2
|
||||
nameserver 127.0.0.1
|
||||
nameserver 172.16.1.3
|
||||
```
|
||||
|
||||
Debian 普通镜像使用 `systemd-timesyncd.service` 来同步系统时间,检查服务状态:
|
||||
@@ -516,7 +591,7 @@ sudo systemctl status systemd-timesyncd.service
|
||||
sudo mkdir /etc/systemd/timesyncd.conf.d
|
||||
|
||||
## 创建 NTP 配置文件
|
||||
sudo nano /etc/systemd/timesyncd.conf.d/server-ntp.conf
|
||||
sudo nano /etc/systemd/timesyncd.conf.d/server_ntp.conf
|
||||
```
|
||||
|
||||
在 nano 编辑器对话框中输入以下内容,并保存:
|
||||
@@ -1,24 +1,24 @@
|
||||
## 1.克隆虚拟机
|
||||
|
||||
在上一篇文章 [5.PVE创建模板虚拟机](./5.PVE制作虚拟机模板.md) 中,我们已经制作好了虚拟机模板。
|
||||
在上一篇文章 [5.PVE创建模板虚拟机](./05.PVE制作虚拟机模板.md) 中,我们已经制作好了虚拟机模板。
|
||||
|
||||
接下来将使用该模板克隆出新的虚拟机,并使用 Adguard Home 作为内网的 DNS 服务器。
|
||||
|
||||
鼠标 **右键单击** 虚拟机模板,在弹出的菜单中选择 `克隆` :
|
||||
|
||||

|
||||

|
||||
|
||||
在弹出的虚拟机克隆对话框中,根据实际情况及下方表格内容,修改虚拟机参数:
|
||||
|
||||
|参数|值|说明|
|
||||
|--|--|--|
|
||||
|目标节点|hyper|当前 PVE 服务器节点|
|
||||
|目标节点|node01|当前 PVE 服务器节点|
|
||||
|VM ID|501|可自由定义,不能与现存虚拟机 `VM ID` 相同|
|
||||
|名称|DNS001|可自由定义,`Cloud-Init` 将使用该名称作为虚拟机 `hostname` |
|
||||
|名称|DNS01|可自由定义,`Cloud-Init` 将使用该名称作为虚拟机 `hostname` |
|
||||
|模式|完整克隆|选择虚拟机的克隆模式|
|
||||
|目标存储|local-lvm|克隆出的虚拟机文件存储位置|
|
||||
|
||||

|
||||

|
||||
|
||||
参数修改完成后,点击 `克隆` 按钮即可使用该模板克隆出新的虚拟机。
|
||||
|
||||
@@ -26,30 +26,35 @@
|
||||
|
||||
克隆出来的虚拟机的 `Cloud-Init` 参数默认与模板完全一致。
|
||||
|
||||
根据之前的网络规划,内网 DNS 服务器 IP 地址分别为 `172.16.1.2/24` 、 `172.16.1.3/24` 。
|
||||
根据之前的网络规划,内网 DNS 服务器 IP 地址分别为:
|
||||
- `172.16.1.2/24 (fdac::2/64)`
|
||||
- `172.16.1.3/24 (fdac::3/64)`
|
||||
|
||||
因此需要调整新虚拟机的 `Cloud-Init` 参数:
|
||||
|
||||

|
||||

|
||||
|
||||
- `DNS服务器` 参数为 `172.16.1.3 127.0.0.1`
|
||||
- `IP配置` 中的 IP 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变
|
||||
- `DNS服务器` 参数为 `172.16.1.3 fdac::3 127.0.0.1`
|
||||
- `IP配置` 中的 IPv4 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变
|
||||
- `IP配置` 中的 IPv6 地址参数为 `fdac::2/64` ,网关保持为空
|
||||
|
||||
这样设置的用意是,让内网两台 DNS 服务器相互提供 DNS 服务。
|
||||
|
||||
但如果内网中仅需一台 DNS 服务器,则 `DNS服务器` 参数可设为本机地址,即 `172.16.1.2 fdac::2 127.0.0.1` 。
|
||||
|
||||
此处需要注意的是,如果修改了 `用户` 参数,相当于新建了一个系统管理员,之前设置的 `oh-my-zsh` 需要在新管理员下重新设置。
|
||||
|
||||
## 3.调整新虚拟机配置参数
|
||||
|
||||
在创建模板虚拟机的文章中有提到过,新虚拟机需要修改 [配置参数](./4.PVE创建模板虚拟机.md#3调整虚拟机配置参数) 才能自动启动。
|
||||
在创建模板虚拟机的文章中有提到过,新虚拟机需要修改 [配置参数](./04.PVE创建模板虚拟机.md#3调整虚拟机配置参数) 才能自动启动。
|
||||
|
||||
将新虚拟机的 `开机自启动` 设置为 `是` 。
|
||||
|
||||

|
||||

|
||||
|
||||
鼠标 **双击** `启动/关机顺序` 选项,调整新虚拟机的自动开机参数:
|
||||
|
||||

|
||||

|
||||
|
||||
`启动/关机顺序` 为 `2` ,表示该虚拟机第二个启动,倒数第二个关机。
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
|
||||
点击顶部 `添加` 按钮,添加一个备份作业:
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.1.备份作业-常规选项
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
|
||||
|参数|值|说明|
|
||||
|--|--|--|
|
||||
|节点|hyper|选择当前 PVE 服务器节点|
|
||||
|节点|node01|选择当前 PVE 服务器节点|
|
||||
|存储|local|选择存放备份文件的路径|
|
||||
|计划|`*-01,16 03:30`|备份作业执行的时间计划|
|
||||
|选择模式|包括选中的VMs|执行备份的虚拟机对象|
|
||||
@@ -28,7 +28,7 @@
|
||||
|
||||
在下方虚拟机列表中,勾选备份作业需要备份的虚拟机(可多选):
|
||||
|
||||

|
||||

|
||||
|
||||
**说明:**
|
||||
|
||||
@@ -42,7 +42,7 @@ PVE 在正确配置邮件发送功能之前,并不能发出邮件。
|
||||
|
||||
该选项将控制备份文件的保留个数,选择保留最近 3 次的备份文件:
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.3.备份作业-Note Template
|
||||
|
||||
@@ -50,7 +50,7 @@ PVE 在正确配置邮件发送功能之前,并不能发出邮件。
|
||||
|
||||
在 Backup Notes 右侧文本框中输入 `{{vmid}}_{{guestname}}_Auto_Backup` :
|
||||
|
||||

|
||||

|
||||
|
||||
点击 `创建` 按钮,备份作业创建完成。
|
||||
|
||||
@@ -60,10 +60,10 @@ PVE 在正确配置邮件发送功能之前,并不能发出邮件。
|
||||
|
||||
鼠标 **单击** 选中一个备份作业,点击右上角的 `调度模拟器` :
|
||||
|
||||

|
||||

|
||||
|
||||
`计划` 处将显示 `备份作业` 的执行时间参数,点击 `模拟` 按钮,在右侧将显示模拟的时间结果:
|
||||
|
||||

|
||||

|
||||
|
||||
确认备份作业的执行时间周期是否符合预期。
|
||||
@@ -0,0 +1,127 @@
|
||||
## 1.修改系统Grub参数
|
||||
|
||||
参考官方文档 [qm_pci_passthrough](https://pve.proxmox.com/pve-docs/pve-admin-guide.html#qm_pci_passthrough) 和 [Pci passthrough](https://pve.proxmox.com/wiki/Pci_passthrough) 开启 PVE 硬件直通功能。
|
||||
|
||||
使用 SSH 工具登录到 PVE 服务器,编辑系统 Grub 的配置文件 `/etc/default/grub` :
|
||||
|
||||
```bash
|
||||
## 编辑 Grub 配置文件
|
||||
nano /etc/default/grub
|
||||
```
|
||||
|
||||
在 `nano` 编辑器对话框中修改 `GRUB_CMDLINE_LINUX_DEFAULT` 参数,注意命令中间的空格:
|
||||
|
||||
```bash
|
||||
## Intel 处理器添加参数
|
||||
GRUB_CMDLINE_LINUX_DEFAULT="quiet intel_iommu=on iommu=pt"
|
||||
```
|
||||
|
||||
根据官方文档的说明,AMD 处理器下硬件直通功能将会自动打开,否则需要手动修改 Grub 配置文件:
|
||||
|
||||
```bash
|
||||
## AMD 处理器添加参数
|
||||
GRUB_CMDLINE_LINUX_DEFAULT="quiet amd_iommu=on iommu=pt"
|
||||
```
|
||||
|
||||
修改并保存后,需要更新系统 Grub :
|
||||
|
||||
```bash
|
||||
## 更新系统 Grub
|
||||
update-grub
|
||||
```
|
||||
|
||||
## 2.加载系统内核模块
|
||||
|
||||
修改系统 `/etc/modules` 配置文件,增加必要的系统模块:
|
||||
|
||||
```bash
|
||||
## 编辑系统配置文件
|
||||
nano /etc/modules
|
||||
```
|
||||
|
||||
在配置文件末尾输入以下内容:
|
||||
|
||||
```txt
|
||||
vfio
|
||||
vfio_iommu_type1
|
||||
vfio_pci
|
||||
vfio_virqfd
|
||||
```
|
||||
|
||||
将配置文件保存,并重启 PVE 服务器。
|
||||
|
||||
PVE 服务器重启完成后,再次使用 SSH 工具登录,并使用以下命令检查硬件直通状态:
|
||||
|
||||
```bash
|
||||
## 检查系统硬件直通状态
|
||||
dmesg | grep -e DMAR -e IOMMU -e AMD-Vi
|
||||
```
|
||||
|
||||
检查 `IOMMU` 、 `Directed I/O` 或 `Interrupt Remapping` 的启用状态。
|
||||
|
||||
N5105 处理器示例输出如下:
|
||||
|
||||
```txt
|
||||
[ 0.016437] ACPI: DMAR 0x00000000787BF000 000088 (v02 INTEL EDK2 00000002 01000013)
|
||||
[ 0.016472] ACPI: Reserving DMAR table memory at [mem 0x787bf000-0x787bf087]
|
||||
[ 0.052437] DMAR: IOMMU enabled
|
||||
[ 0.144431] DMAR: Host address width 39
|
||||
[ 0.144432] DMAR: DRHD base: 0x000000fed90000 flags: 0x0
|
||||
[ 0.144439] DMAR: dmar0: reg_base_addr fed90000 ver 4:0 cap 1c0000c40660462 ecap 49e2ff0505e
|
||||
[ 0.144441] DMAR: DRHD base: 0x000000fed91000 flags: 0x1
|
||||
[ 0.144446] DMAR: dmar1: reg_base_addr fed91000 ver 1:0 cap d2008c40660462 ecap f050da
|
||||
[ 0.144449] DMAR: RMRR base: 0x0000007b800000 end: 0x0000007fbfffff
|
||||
[ 0.144452] DMAR-IR: IOAPIC id 2 under DRHD base 0xfed91000 IOMMU 1
|
||||
[ 0.144453] DMAR-IR: HPET id 0 under DRHD base 0xfed91000
|
||||
[ 0.144454] DMAR-IR: Queued invalidation will be enabled to support x2apic and Intr-remapping.
|
||||
[ 0.146335] DMAR-IR: Enabled IRQ remapping in x2apic mode
|
||||
[ 0.333509] pci 0000:00:02.0: DMAR: Skip IOMMU disabling for graphics
|
||||
[ 0.410824] DMAR: No ATSR found
|
||||
[ 0.410824] DMAR: No SATC found
|
||||
[ 0.410826] DMAR: IOMMU feature fl1gp_support inconsistent
|
||||
[ 0.410827] DMAR: IOMMU feature pgsel_inv inconsistent
|
||||
[ 0.410829] DMAR: IOMMU feature nwfs inconsistent
|
||||
[ 0.410829] DMAR: IOMMU feature pds inconsistent
|
||||
[ 0.410830] DMAR: IOMMU feature eafs inconsistent
|
||||
[ 0.410831] DMAR: IOMMU feature prs inconsistent
|
||||
[ 0.410831] DMAR: IOMMU feature nest inconsistent
|
||||
[ 0.410832] DMAR: IOMMU feature mts inconsistent
|
||||
[ 0.410832] DMAR: IOMMU feature sc_support inconsistent
|
||||
[ 0.410833] DMAR: IOMMU feature dev_iotlb_support inconsistent
|
||||
[ 0.410835] DMAR: dmar0: Using Queued invalidation
|
||||
[ 0.410838] DMAR: dmar1: Using Queued invalidation
|
||||
[ 0.412755] DMAR: Intel(R) Virtualization Technology for Directed I/O
|
||||
```
|
||||
|
||||
检查系统 `IOMMU` 分组:
|
||||
|
||||
```bash
|
||||
## 检查 IOMMU group
|
||||
find /sys/kernel/iommu_groups/ -type l
|
||||
```
|
||||
|
||||
示例输出如下:
|
||||
|
||||
```txt
|
||||
/sys/kernel/iommu_groups/7/devices/0000:00:1c.4
|
||||
/sys/kernel/iommu_groups/15/devices/0000:04:00.0
|
||||
/sys/kernel/iommu_groups/5/devices/0000:00:17.0
|
||||
/sys/kernel/iommu_groups/13/devices/0000:02:00.0
|
||||
/sys/kernel/iommu_groups/3/devices/0000:00:14.2
|
||||
/sys/kernel/iommu_groups/3/devices/0000:00:14.0
|
||||
/sys/kernel/iommu_groups/11/devices/0000:00:1f.0
|
||||
/sys/kernel/iommu_groups/11/devices/0000:00:1f.5
|
||||
/sys/kernel/iommu_groups/11/devices/0000:00:1f.3
|
||||
/sys/kernel/iommu_groups/11/devices/0000:00:1f.4
|
||||
/sys/kernel/iommu_groups/1/devices/0000:00:02.0
|
||||
/sys/kernel/iommu_groups/8/devices/0000:00:1c.5
|
||||
/sys/kernel/iommu_groups/16/devices/0000:05:00.0
|
||||
/sys/kernel/iommu_groups/6/devices/0000:00:1c.0
|
||||
/sys/kernel/iommu_groups/14/devices/0000:03:00.0
|
||||
/sys/kernel/iommu_groups/4/devices/0000:00:16.0
|
||||
/sys/kernel/iommu_groups/12/devices/0000:01:00.0
|
||||
/sys/kernel/iommu_groups/2/devices/0000:00:04.0
|
||||
/sys/kernel/iommu_groups/10/devices/0000:00:1c.7
|
||||
/sys/kernel/iommu_groups/0/devices/0000:00:00.0
|
||||
/sys/kernel/iommu_groups/9/devices/0000:00:1c.6
|
||||
```
|
||||
@@ -11,24 +11,30 @@ PVE 虚拟化平台的安装以及折腾手记。
|
||||
- 硬盘:SSD 512G
|
||||
|
||||
- 内部网络:
|
||||
- IP地址:172.16.1.250
|
||||
- 子网掩码:255.255.255.0
|
||||
- 网关:172.16.1.1
|
||||
- DNS:172.16.1.1
|
||||
- IPv4 网络
|
||||
- IP 地址:172.16.1.254
|
||||
- 子网掩码:255.255.255.0
|
||||
- 网关:172.16.1.1
|
||||
- DNS:172.16.1.1
|
||||
- IPv6 网络
|
||||
- 前缀:fdac::/64
|
||||
- IP 地址:fdac::fe
|
||||
- DNS:fdac::1
|
||||
|
||||
### 教程章节
|
||||
### 系列章节
|
||||
|
||||
0. [硬件BIOS配置](./0.硬件BIOS配置.md)
|
||||
1. [PVE系统安装](./1.PVE系统安装.md)
|
||||
2. [PVE初始化配置](./2.PVE初始化配置.md)
|
||||
3. [PVE系统调整](./3.PVE系统调整.md)
|
||||
4. [PVE创建模板虚拟机](./4.PVE创建模板虚拟机.md)
|
||||
5. [PVE制作虚拟机模板](./5.PVE制作虚拟机模板.md)
|
||||
6. [PVE用模板克隆虚拟机](./6.PVE用模板克隆虚拟机.md)
|
||||
7. [PVE自动备份虚拟机](./7.PVE自动备份虚拟机.md)
|
||||
0. [硬件BIOS配置](./00.硬件BIOS配置.md)
|
||||
1. [PVE系统安装](./01.PVE系统安装.md)
|
||||
2. [PVE初始化配置](./02.PVE初始化配置.md)
|
||||
3. [PVE系统调整](./03.PVE系统调整.md)
|
||||
4. [PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md)
|
||||
5. [PVE制作虚拟机模板](./05.PVE制作虚拟机模板.md)
|
||||
6. [PVE用模板克隆虚拟机](./06.PVE用模板克隆虚拟机.md)
|
||||
7. [PVE自动备份虚拟机](./07.PVE自动备份虚拟机.md)
|
||||
8. [PVE开启硬件直通功能](./08.PVE开启硬件直通功能.md)
|
||||
|
||||
### 教程说明
|
||||
### 文章说明
|
||||
|
||||
1. 本教程涉及的部分参数需要人为调整来符合切实使用需求。
|
||||
1. 本系列文章涉及的部分参数需要手动调整来符合切实使用需求。
|
||||
2. 随着 PVE 系统的迭代更新,截图中的内容和实际页面显示可能存在差异。
|
||||
3. 如需引用,请注明本教程出处。
|
||||
3. 如需引用,请注明本文出处。
|
||||
|
||||
|
Before Width: | Height: | Size: 138 KiB |
|
Before Width: | Height: | Size: 128 KiB |
|
Before Width: | Height: | Size: 597 KiB After Width: | Height: | Size: 597 KiB |
|
Before Width: | Height: | Size: 698 KiB After Width: | Height: | Size: 698 KiB |
|
Before Width: | Height: | Size: 298 KiB After Width: | Height: | Size: 298 KiB |
|
Before Width: | Height: | Size: 528 KiB After Width: | Height: | Size: 528 KiB |
|
Before Width: | Height: | Size: 375 KiB After Width: | Height: | Size: 375 KiB |
|
Before Width: | Height: | Size: 236 KiB After Width: | Height: | Size: 236 KiB |
|
Before Width: | Height: | Size: 281 KiB After Width: | Height: | Size: 281 KiB |
|
Before Width: | Height: | Size: 338 KiB After Width: | Height: | Size: 338 KiB |
|
Before Width: | Height: | Size: 232 KiB After Width: | Height: | Size: 232 KiB |
|
Before Width: | Height: | Size: 448 KiB After Width: | Height: | Size: 448 KiB |
|
Before Width: | Height: | Size: 410 KiB After Width: | Height: | Size: 410 KiB |
|
Before Width: | Height: | Size: 596 KiB After Width: | Height: | Size: 596 KiB |
|
Before Width: | Height: | Size: 725 KiB After Width: | Height: | Size: 725 KiB |
|
Before Width: | Height: | Size: 257 KiB After Width: | Height: | Size: 257 KiB |
|
Before Width: | Height: | Size: 898 KiB After Width: | Height: | Size: 898 KiB |
|
Before Width: | Height: | Size: 70 KiB After Width: | Height: | Size: 70 KiB |
|
Before Width: | Height: | Size: 978 KiB After Width: | Height: | Size: 978 KiB |
|
Before Width: | Height: | Size: 942 KiB After Width: | Height: | Size: 942 KiB |
|
Before Width: | Height: | Size: 75 KiB After Width: | Height: | Size: 75 KiB |
|
Before Width: | Height: | Size: 959 KiB After Width: | Height: | Size: 959 KiB |
|
Before Width: | Height: | Size: 862 KiB After Width: | Height: | Size: 862 KiB |
|
Before Width: | Height: | Size: 774 KiB After Width: | Height: | Size: 774 KiB |
|
Before Width: | Height: | Size: 599 KiB After Width: | Height: | Size: 599 KiB |
|
Before Width: | Height: | Size: 921 KiB After Width: | Height: | Size: 921 KiB |
|
Before Width: | Height: | Size: 143 KiB After Width: | Height: | Size: 143 KiB |
|
Before Width: | Height: | Size: 47 KiB After Width: | Height: | Size: 47 KiB |
|
Before Width: | Height: | Size: 325 KiB After Width: | Height: | Size: 325 KiB |
|
Before Width: | Height: | Size: 157 KiB After Width: | Height: | Size: 157 KiB |
|
Before Width: | Height: | Size: 355 KiB After Width: | Height: | Size: 355 KiB |
|
Before Width: | Height: | Size: 599 KiB After Width: | Height: | Size: 599 KiB |
|
Before Width: | Height: | Size: 868 KiB After Width: | Height: | Size: 868 KiB |
|
Before Width: | Height: | Size: 335 KiB After Width: | Height: | Size: 335 KiB |
|
Before Width: | Height: | Size: 734 KiB After Width: | Height: | Size: 734 KiB |
|
After Width: | Height: | Size: 83 KiB |
|
Before Width: | Height: | Size: 161 KiB After Width: | Height: | Size: 161 KiB |
|
After Width: | Height: | Size: 156 KiB |
|
Before Width: | Height: | Size: 54 KiB After Width: | Height: | Size: 54 KiB |
|
Before Width: | Height: | Size: 197 KiB After Width: | Height: | Size: 197 KiB |
|
Before Width: | Height: | Size: 77 KiB After Width: | Height: | Size: 77 KiB |
|
After Width: | Height: | Size: 74 KiB |
|
Before Width: | Height: | Size: 169 KiB After Width: | Height: | Size: 169 KiB |
|
Before Width: | Height: | Size: 272 KiB After Width: | Height: | Size: 272 KiB |
|
Before Width: | Height: | Size: 148 KiB After Width: | Height: | Size: 148 KiB |
|
Before Width: | Height: | Size: 173 KiB After Width: | Height: | Size: 173 KiB |
|
After Width: | Height: | Size: 103 KiB |
|
Before Width: | Height: | Size: 193 KiB After Width: | Height: | Size: 193 KiB |
|
Before Width: | Height: | Size: 125 KiB After Width: | Height: | Size: 125 KiB |
|
Before Width: | Height: | Size: 214 KiB After Width: | Height: | Size: 214 KiB |
|
Before Width: | Height: | Size: 174 KiB After Width: | Height: | Size: 174 KiB |
|
Before Width: | Height: | Size: 73 KiB After Width: | Height: | Size: 73 KiB |
|
Before Width: | Height: | Size: 184 KiB After Width: | Height: | Size: 184 KiB |
|
Before Width: | Height: | Size: 62 KiB After Width: | Height: | Size: 62 KiB |
|
Before Width: | Height: | Size: 163 KiB After Width: | Height: | Size: 163 KiB |
|
Before Width: | Height: | Size: 176 KiB After Width: | Height: | Size: 176 KiB |
|
Before Width: | Height: | Size: 90 KiB After Width: | Height: | Size: 90 KiB |
|
Before Width: | Height: | Size: 77 KiB After Width: | Height: | Size: 77 KiB |
|
Before Width: | Height: | Size: 126 KiB After Width: | Height: | Size: 126 KiB |
|
Before Width: | Height: | Size: 99 KiB After Width: | Height: | Size: 99 KiB |
|
Before Width: | Height: | Size: 95 KiB After Width: | Height: | Size: 95 KiB |
|
Before Width: | Height: | Size: 191 KiB After Width: | Height: | Size: 191 KiB |
|
Before Width: | Height: | Size: 164 KiB After Width: | Height: | Size: 164 KiB |
|
Before Width: | Height: | Size: 107 KiB After Width: | Height: | Size: 107 KiB |
|
Before Width: | Height: | Size: 175 KiB After Width: | Height: | Size: 175 KiB |
|
Before Width: | Height: | Size: 160 KiB After Width: | Height: | Size: 160 KiB |
|
Before Width: | Height: | Size: 62 KiB After Width: | Height: | Size: 62 KiB |
|
Before Width: | Height: | Size: 57 KiB After Width: | Height: | Size: 57 KiB |
|
Before Width: | Height: | Size: 72 KiB After Width: | Height: | Size: 72 KiB |
|
Before Width: | Height: | Size: 163 KiB After Width: | Height: | Size: 163 KiB |
|
Before Width: | Height: | Size: 49 KiB After Width: | Height: | Size: 49 KiB |
|
After Width: | Height: | Size: 96 KiB |
|
Before Width: | Height: | Size: 55 KiB After Width: | Height: | Size: 55 KiB |
|
Before Width: | Height: | Size: 48 KiB After Width: | Height: | Size: 48 KiB |
|
Before Width: | Height: | Size: 208 KiB After Width: | Height: | Size: 208 KiB |
|
Before Width: | Height: | Size: 64 KiB After Width: | Height: | Size: 64 KiB |
|
Before Width: | Height: | Size: 81 KiB After Width: | Height: | Size: 81 KiB |
|
Before Width: | Height: | Size: 104 KiB After Width: | Height: | Size: 104 KiB |
|
Before Width: | Height: | Size: 131 KiB After Width: | Height: | Size: 131 KiB |
|
Before Width: | Height: | Size: 200 KiB |
|
Before Width: | Height: | Size: 93 KiB |
@@ -0,0 +1,164 @@
|
||||
// Unattended-Upgrade::Origins-Pattern controls which packages are
|
||||
// upgraded.
|
||||
//
|
||||
// Lines below have the format "keyword=value,...". A
|
||||
// package will be upgraded only if the values in its metadata match
|
||||
// all the supplied keywords in a line. (In other words, omitted
|
||||
// keywords are wild cards.) The keywords originate from the Release
|
||||
// file, but several aliases are accepted. The accepted keywords are:
|
||||
// a,archive,suite (eg, "stable")
|
||||
// c,component (eg, "main", "contrib", "non-free")
|
||||
// l,label (eg, "Debian", "Debian-Security")
|
||||
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
|
||||
// n,codename (eg, "jessie", "jessie-updates")
|
||||
// site (eg, "http.debian.net")
|
||||
// The available values on the system are printed by the command
|
||||
// "apt-cache policy", and can be debugged by running
|
||||
// "unattended-upgrades -d" and looking at the log file.
|
||||
//
|
||||
// Within lines unattended-upgrades allows 2 macros whose values are
|
||||
// derived from /etc/debian_version:
|
||||
// ${distro_id} Installed origin.
|
||||
// ${distro_codename} Installed codename (eg, "buster")
|
||||
Unattended-Upgrade::Origins-Pattern {
|
||||
// Codename based matching:
|
||||
// This will follow the migration of a release through different
|
||||
// archives (e.g. from testing to stable and later oldstable).
|
||||
// Software will be the latest available for the named release,
|
||||
// but the Debian release itself will not be automatically upgraded.
|
||||
"origin=Debian,codename=${distro_codename}-updates";
|
||||
// "origin=Debian,codename=${distro_codename}-proposed-updates";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian-Security";
|
||||
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
|
||||
|
||||
// Archive or Suite based matching:
|
||||
// Note that this will silently match a different release after
|
||||
// migration to the specified archive (e.g. testing becomes the
|
||||
// new stable).
|
||||
// "o=Debian,a=stable";
|
||||
// "o=Debian,a=stable-updates";
|
||||
// "o=Debian,a=proposed-updates";
|
||||
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
|
||||
};
|
||||
|
||||
// Python regular expressions, matching packages to exclude from upgrading
|
||||
Unattended-Upgrade::Package-Blacklist {
|
||||
// The following matches all packages starting with linux-
|
||||
// "linux-";
|
||||
|
||||
// Use $ to explicitely define the end of a package name. Without
|
||||
// the $, "libc6" would match all of them.
|
||||
// "libc6$";
|
||||
// "libc6-dev$";
|
||||
// "libc6-i686$";
|
||||
|
||||
// Special characters need escaping
|
||||
// "libstdc\+\+6$";
|
||||
|
||||
// The following matches packages like xen-system-amd64, xen-utils-4.1,
|
||||
// xenstore-utils and libxenstore3.0
|
||||
// "(lib)?xen(store)?";
|
||||
|
||||
// For more information about Python regular expressions, see
|
||||
// https://docs.python.org/3/howto/regex.html
|
||||
};
|
||||
|
||||
// This option allows you to control if on a unclean dpkg exit
|
||||
// unattended-upgrades will automatically run
|
||||
// dpkg --force-confold --configure -a
|
||||
// The default is true, to ensure updates keep getting installed
|
||||
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
// Split the upgrade into the smallest possible chunks so that
|
||||
// they can be interrupted with SIGTERM. This makes the upgrade
|
||||
// a bit slower but it has the benefit that shutdown while a upgrade
|
||||
// is running is possible (with a small delay)
|
||||
//Unattended-Upgrade::MinimalSteps "true";
|
||||
|
||||
// Install all updates when the machine is shutting down
|
||||
// instead of doing it in the background while the machine is running.
|
||||
// This will (obviously) make shutdown slower.
|
||||
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
|
||||
// This allows more time for unattended-upgrades to shut down gracefully
|
||||
// or even install a few packages in InstallOnShutdown mode, but is still a
|
||||
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
|
||||
// Users enabling InstallOnShutdown mode are advised to increase
|
||||
// InhibitDelayMaxSec even further, possibly to 30 minutes.
|
||||
//Unattended-Upgrade::InstallOnShutdown "false";
|
||||
|
||||
// Send email to this address for problems or packages upgrades
|
||||
// If empty or unset then no email is sent, make sure that you
|
||||
// have a working mail setup on your system. A package that provides
|
||||
// 'mailx' must be installed. E.g. "user@example.com"
|
||||
//Unattended-Upgrade::Mail "";
|
||||
|
||||
// Set this value to one of:
|
||||
// "always", "only-on-error" or "on-change"
|
||||
// If this is not set, then any legacy MailOnlyOnError (boolean) value
|
||||
// is used to chose between "only-on-error" and "on-change"
|
||||
//Unattended-Upgrade::MailReport "on-change";
|
||||
|
||||
// Remove unused automatically installed kernel-related packages
|
||||
// (kernel images, kernel headers and kernel version locked tools).
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
// Do automatic removal of newly unused dependencies after the upgrade
|
||||
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
// Do automatic removal of unused packages after the upgrade
|
||||
// (equivalent to apt-get autoremove)
|
||||
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
|
||||
// Automatically reboot *WITHOUT CONFIRMATION* if
|
||||
// the file /var/run/reboot-required is found after the upgrade
|
||||
Unattended-Upgrade::Automatic-Reboot "true";
|
||||
|
||||
// Automatically reboot even if there are users currently logged in
|
||||
// when Unattended-Upgrade::Automatic-Reboot is set to true
|
||||
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
|
||||
|
||||
// If automatic reboot is enabled and needed, reboot at the specific
|
||||
// time instead of immediately
|
||||
// Default: "now"
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "04:30";
|
||||
|
||||
// Use apt bandwidth limit feature, this example limits the download
|
||||
// speed to 70kb/sec
|
||||
//Acquire::http::Dl-Limit "70";
|
||||
|
||||
// Enable logging to syslog. Default is False
|
||||
// Unattended-Upgrade::SyslogEnable "false";
|
||||
|
||||
// Specify syslog facility. Default is daemon
|
||||
// Unattended-Upgrade::SyslogFacility "daemon";
|
||||
|
||||
// Download and install upgrades only on AC power
|
||||
// (i.e. skip or gracefully stop updates on battery)
|
||||
// Unattended-Upgrade::OnlyOnACPower "true";
|
||||
|
||||
// Download and install upgrades only on non-metered connection
|
||||
// (i.e. skip or gracefully stop updates on a metered connection)
|
||||
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
|
||||
|
||||
// Verbose logging
|
||||
// Unattended-Upgrade::Verbose "false";
|
||||
|
||||
// Print debugging information both in unattended-upgrades and
|
||||
// in unattended-upgrade-shutdown
|
||||
// Unattended-Upgrade::Debug "false";
|
||||
|
||||
// Allow package downgrade if Pin-Priority exceeds 1000
|
||||
// Unattended-Upgrade::Allow-downgrade "false";
|
||||
|
||||
// When APT fails to mark a package to be upgraded or installed try adjusting
|
||||
// candidates of related packages to help APT's resolver in finding a solution
|
||||
// where the package can be upgraded or installed.
|
||||
// This is a workaround until APT's resolver is fixed to always find a
|
||||
// solution if it exists. (See Debian bug #711128.)
|
||||
// The fallback is enabled by default, except on Debian's sid release because
|
||||
// uninstallable packages are frequent there.
|
||||
// Disabling the fallback speeds up unattended-upgrades when there are
|
||||
// uninstallable packages at the expense of rarely keeping back packages which
|
||||
// could be upgraded or installed.
|
||||
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
|
||||
@@ -0,0 +1,25 @@
|
||||
# This configuration file is customized by fox
|
||||
# Optimize system parameters
|
||||
|
||||
kernel.panic = 20
|
||||
kernel.panic_on_oops = 1
|
||||
|
||||
net.core.default_qdisc = fq_codel
|
||||
net.ipv4.tcp_congestion_control = bbr
|
||||
|
||||
# Other adjustable system parameters
|
||||
|
||||
net.ipv4.conf.all.log_martians = 1
|
||||
|
||||
net.ipv4.igmp_max_memberships = 100
|
||||
|
||||
net.ipv4.tcp_challenge_ack_limit = 1000
|
||||
net.ipv4.tcp_fin_timeout = 30
|
||||
net.ipv4.tcp_keepalive_time = 120
|
||||
net.ipv4.tcp_max_orphans = 4096
|
||||
net.ipv4.tcp_max_tw_buckets = 4096
|
||||
net.ipv4.tcp_syncookies = 1
|
||||
|
||||
net.ipv6.conf.all.use_tempaddr = 0
|
||||
net.ipv6.conf.default.use_tempaddr = 0
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
# This configuration file is customized by fox
|
||||
# Optimize dhcpcd parameters for dns server
|
||||
|
||||
# Only configure IPv6
|
||||
ipv6only
|
||||
|
||||
# Inform the DHCP server of our hostname for DDNS.
|
||||
hostname
|
||||
|
||||
# A list of options to request from the DHCP server.
|
||||
nooption domain_name_servers, domain_name, domain_search, host_name
|
||||
option classless_static_routes
|
||||
|
||||
# Respect the network MTU.
|
||||
option interface_mtu
|
||||
|
||||
# A ServerID is required by RFC2131.
|
||||
require dhcp_server_identifier
|
||||
|
||||
# Generate Stable Private IPv6 Addresses based from the DUID
|
||||
slaac private
|
||||
|
||||
# Don't send any ARP requests.
|
||||
noarp
|
||||
@@ -40,7 +40,7 @@ CPUFREQ_OPTIONS=""
|
||||
# MIN_SPEED=500
|
||||
|
||||
ENABLE="true"
|
||||
GOVERNOR="schedutil"
|
||||
GOVERNOR="powersave"
|
||||
MAX_SPEED="0"
|
||||
MIN_SPEED="0"
|
||||
|
||||