Compare commits

...
269 Commits
Author SHA1 Message Date
CallMeR 8c26dd2569 更新广告列表 2024-11-26 12:50:51 +08:00
CallMeR ae963404b7 更新广告列表 2024-11-24 22:16:03 +08:00
CallMeR 96f89812de 更新版本号 2024-11-24 17:28:13 +08:00
CallMeR 968d0637dd 更新截图版本 2024-11-24 17:23:44 +08:00
CallMeR 1166516576 更新 DNS sysctl 参数 2024-11-02 15:37:49 +08:00
CallMeR f664975bcc 更新 DNS sysctl 参数 2024-10-29 14:01:39 +08:00
CallMeR 26fa0b0c10 修复描述错误,Fix: https://gitee.com/callmer/routeros_toss_notes/issues/IB0HER 2024-10-29 13:26:00 +08:00
CallMeR ac2740f888 更新系统 sysctl 参数 2024-10-28 00:32:12 +08:00
CallMeR aa1a12757b 更新系统 sysctl 参数 2024-10-24 18:23:26 +08:00
CallMeR ccef3195ff 更新系统 sysctl 参数 2024-10-23 10:12:01 +08:00
CallMeR dd3bda21f5 更新系统 sysctl 参数 2024-10-22 15:28:58 +08:00
CallMeR 547389c182 更新系统 sysctl 参数 2024-10-22 14:18:09 +08:00
CallMeR ace58ce24d 更新 TS 服务器流控算法 2024-10-21 23:30:53 +08:00
CallMeR adaeb4a650 新增 BTRFS 调整内容 2024-10-19 02:26:04 +08:00
CallMeR fa29b0d633 更新系统 sysctl 参数 2024-10-17 12:57:46 +08:00
CallMeR 94273ae2b6 RFC 9460
Service Binding and Parameter Specification via the DNS (SVCB and HTTPS Resource Records)
2024-10-14 17:53:10 +08:00
CallMeR 2d32561415 更新 SmartDNS 过期缓存 2024-10-13 17:06:50 +08:00
CallMeR 0dcfa86d11 更新 SmartDNS 加速脚本 2024-10-13 16:32:44 +08:00
CallMeR 557ae16217 更新清理缓存命令 2024-10-09 23:43:17 +08:00
CallMeR 49083bf184 更新 SmartDNS 清理缓存 2024-10-08 23:48:01 +08:00
CallMeR 9634a10686 更新清理命令 2024-10-08 23:30:52 +08:00
CallMeR 6f7c78b749 更新清理命令 2024-10-08 23:16:46 +08:00
CallMeR 04fc40c8e1 更新清理命令 2024-10-08 23:08:24 +08:00
CallMeR 05ba8586ae 更新 SmartDNS 参数 2024-10-08 22:56:27 +08:00
CallMeR e8cb9b14f4 更新示例输出 2024-10-07 18:08:24 +08:00
CallMeR 7b794c11e4 更新 NTP 服务器 2024-10-07 18:04:33 +08:00
CallMeR d4673a204a 更新实例输出 2024-10-07 18:00:03 +08:00
CallMeR 95913b4d0d 更新 NTP 服务器 2024-10-07 17:52:02 +08:00
CallMeR 964fc699e3 Revert 更新 SmartDNS 参数 2024-10-05 17:44:11 +08:00
CallMeR b3b147ab37 更新 SmartDNS 广告列表 2024-09-27 23:05:48 +08:00
CallMeR cdcc71462b 更新 SmartDNS 参数 2024-09-27 16:05:05 +08:00
CallMeR 999a06f938 更新 Nftables 规则 2024-09-27 14:30:48 +08:00
CallMeR 4bf1e1d523 更新 Nftables 规则 2024-09-27 14:01:18 +08:00
CallMeR ddc60fd6f1 更换 SmartDNS 广告列表 2024-09-19 15:44:11 +08:00
CallMeR c94872a931 更新 SmartDNS 缓存参数 2024-09-15 12:20:03 +08:00
CallMeR d09bd30a25 更新上游 DNS 2024-09-05 13:55:10 +08:00
CallMeR cc5ec05502 更新 SmartDNS 上游 DNS 2024-09-03 13:59:54 +08:00
CallMeR e0894f3e13 更新 PVE 版本 2024-08-24 19:44:32 +08:00
CallMeR 360d5b6cab 更新 DNS 缓存参数 2024-08-24 03:23:26 +08:00
CallMeR 8d2cab7155 更新备注 2024-08-17 22:37:05 +08:00
CallMeR afb5a5859c 更新 Dnsmasq 配置 2024-08-15 19:07:27 +08:00
CallMeR 53c3fe877a 更新 SmartDNS 上游 DoT / DoH 服务器 2024-08-14 21:40:22 +08:00
CallMeR 835cbf9b43 更新上游 DNS 服务器 2024-08-07 22:52:54 +08:00
CallMeR 1b97935413 更新 SmartDNS 插件 2024-08-07 13:30:38 +08:00
CallMeR fc67f6f575 更新 SmartDNS 上游 DNS 2024-08-07 13:22:22 +08:00
CallMeR bc5ea890ad 更新 Dnsmasq 参数 2024-08-02 20:14:17 +08:00
CallMeR fefcd16f82 更新 SmartDNS 参数 2024-08-02 20:10:24 +08:00
CallMeR 10050fa7ff 更新 SmartDNS Plugin 2024-08-02 10:46:49 +08:00
CallMeR 20086c63f7 调整 Dnsmasq 配置 2024-08-02 10:29:56 +08:00
CallMeR 619b96a6fc 调整 SmartDNS 参数 2024-08-02 00:37:42 +08:00
CallMeR 4fbb729d85 关闭 SmartDNS 过期缓存并调整响应 TTL 2024-07-29 01:13:05 +08:00
CallMeR 78fd87188c 停用 Dnsmasq 的 negative 缓存 2024-07-27 11:23:48 +08:00
CallMeR 8a737cfb34 优化 SmartDNS 配置 2024-07-24 23:31:45 +08:00
CallMeR fcfd177593 移除 SmartDNS EDNS 参数 2024-07-24 21:53:31 +08:00
CallMeR 1336af517e 更新 DNS 服务器流控算法 2024-07-22 17:12:01 +08:00
CallMeR b0beb5177f 更新 DNS 服务器流控算法 2024-07-19 12:37:05 +08:00
CallMeR 921bd8bb31 更新 TS 服务器流控算法 2024-07-19 12:35:08 +08:00
CallMeR ff1a1a43a7 更新截图 2024-07-02 15:23:20 +08:00
CallMeR 9a9173df92 更新系统更新命令 2024-07-02 11:01:58 +08:00
CallMeR e9ca2b5cda 更新备注信息 2024-06-28 15:33:05 +08:00
CallMeR 0695f8b6b9 Revert 替换广告屏蔽列表 2024-06-28 12:31:22 +08:00
CallMeR 1657411b7e 更新备注信息 2024-06-28 00:14:16 +08:00
CallMeR 14007e78b8 替换广告屏蔽列表 2024-06-27 16:56:10 +08:00
CallMeR 7318726847 修复段落标题 2024-06-26 15:05:08 +08:00
CallMeR 374c55cbb3 修复目录路径 2024-06-26 15:03:00 +08:00
CallMeR 7df6ea76b7 更新文案描述 2024-06-26 14:55:57 +08:00
CallMeR 5e0a8aac54 更新文案描述 2024-06-26 14:53:35 +08:00
CallMeR 8dd1f08f27 更新终端工具 2024-06-26 14:43:59 +08:00
CallMeR 9873dd74d1 更新 SmartDNS 版本 2024-06-13 11:29:38 +08:00
CallMeR ffaa26a050 更新配置文件备注 2024-05-23 02:12:07 +08:00
CallMeR b17ef026ad 更新文案描述 2024-05-21 12:50:30 +08:00
CallMeR 808094ae3c 更新脚本文件命名 2024-05-20 22:17:58 +08:00
CallMeR 609fcf579b 更新配置文件命名 2024-05-20 21:32:38 +08:00
CallMeR 022da7d3f9 更新配置文件命名 2024-05-20 16:18:29 +08:00
CallMeR afb2678f68 使用 btop 代替 htop 2024-05-16 13:21:15 +08:00
CallMeR 4ed96a4d38 更新文案说明 2024-04-28 12:09:53 +08:00
CallMeR f7ff85a805 更新 PVE 版本号 2024-04-26 13:50:02 +08:00
CallMeR 101fc96feb 更新自动备份截图 2024-04-26 13:48:52 +08:00
CallMeR 01f39562ff 新增 sshguard 工具 2024-04-26 12:36:28 +08:00
CallMeR 933bdca053 更新部分截图 2024-04-26 11:56:14 +08:00
CallMeR 748faac28b 更换 SmartDNS 广告列表 2024-04-23 13:28:57 +08:00
CallMeR fe8fbff04c 更新 Dnsmasq 缓存设置 2024-04-23 10:39:00 +08:00
CallMeR 50f49ed956 更新 SmartDNS 缓存设置 2024-04-23 10:36:39 +08:00
CallMeR b809ecd035 更新 PVE 软件源替换命令 2024-04-21 21:12:55 +08:00
CallMeR eda1d36130 更新 Dnsmasq 配置 2024-03-21 10:52:33 +08:00
CallMeR c9bf9ae2fd 更新 Dnsmasq 配置 2024-03-20 22:41:13 +08:00
CallMeR 38ac1f9702 更新 Dnsmasq 配置 2024-03-19 18:36:36 +08:00
CallMeR f493c774ab 更新 SmartDNS 配置 2024-03-19 12:06:18 +08:00
CallMeR 09a35e9c31 关闭 Dnsmasq 缓存 2024-03-19 10:13:17 +08:00
CallMeR a1e992c956 更新 SmartDNS 配置 2024-03-19 10:04:27 +08:00
CallMeR 360542f9d4 更新 Dnsmasq 参数 2024-03-18 21:45:12 +08:00
CallMeR e5a8d8b491 更新截图 2024-03-18 14:14:47 +08:00
CallMeR 3ce5fdba6a 更新截图 2024-03-18 14:09:10 +08:00
CallMeR 5ec78ce639 更新 Debian 云镜像 2024-03-18 13:50:30 +08:00
CallMeR b597af908d 更新 SmartDNS 缓存参数 2024-03-16 13:34:26 +08:00
CallMeR 6f085030b3 更新 Dnsmasq 缓存参数 2024-03-16 13:25:07 +08:00
CallMeR 82497488ed 更新 TS 自动更新 2024-03-01 20:26:31 +08:00
CallMeR ee7b34ddf4 更新 SmartDNS 配置 2024-02-20 02:08:33 +08:00
CallMeR 353dc12fca 更新文案描述 2024-02-14 01:54:23 +08:00
CallMeR a410d925f4 更新清理命令 2024-02-13 22:35:06 +08:00
CallMeR 2c48e3a330 优化 ls 命令 2024-02-11 02:11:06 +08:00
CallMeR 2344cd77bf 更新 SmartDNS 参数 2024-02-11 01:55:18 +08:00
CallMeR aba1e70956 更新 SmartDNS 参数 2024-02-11 01:39:02 +08:00
CallMeR bbcbc9fe1e 更新 Dnsmasq 参数 2024-02-09 00:36:35 +08:00
CallMeR 5bce9e1d44 SmartDNS 配置重命名 2024-02-09 00:29:47 +08:00
CallMeR 80f7041632 更新 SmartDNS 参数 2024-02-09 00:27:03 +08:00
CallMeR ffcae17092 更新 SmartDNS 版本 2024-02-09 00:04:29 +08:00
CallMeR 0bd3a7cd36 整合清理命令 2024-01-30 18:17:58 +08:00
CallMeR eddc39bc40 修复 typo 2024-01-30 18:14:52 +08:00
CallMeR 564d56e56f 更新流表语法 2024-01-20 21:52:47 +08:00
CallMeR 80556cacaf 更新流表语法 2024-01-20 19:27:06 +08:00
CallMeR 2c8d775e9e 更新 README 2024-01-17 14:02:25 +08:00
CallMeR 19532baa21 更新 README 2024-01-17 13:59:58 +08:00
CallMeR 2ff27e96c3 默认不启用 IPv6 ULA 网络 2024-01-17 13:54:39 +08:00
CallMeR 979f03052e 修复 typo 2024-01-17 13:22:45 +08:00
CallMeR 3a7a506645 更新文案描述 2024-01-10 16:16:56 +08:00
CallMeR 62c55d9750 调整 Dnsmasq 配置 2024-01-10 15:13:49 +08:00
CallMeR 101b5c64b2 整理文档 2024-01-10 15:05:59 +08:00
CallMeR 497a8c0685 更新 Dnsmasq 配置 2024-01-10 14:46:26 +08:00
CallMeR 00e4fd27e5 调整 Dnsmasq 配置 2024-01-10 14:29:51 +08:00
CallMeR 85d5a3bee5 更新文案描述 2024-01-08 22:31:32 +08:00
CallMeR 2ae4bda8b3 调整 Dnsmasq 格式 2024-01-08 21:55:32 +08:00
CallMeR 12cadb86ad 更新说明 2024-01-08 21:46:38 +08:00
CallMeR 3c9927a362 关闭 TS 服务器 Dnsmasq 的 DNS 缓存 2024-01-08 21:40:23 +08:00
CallMeR d69101077b 更新 offload 匹配 2024-01-07 12:03:45 +08:00
CallMeR 6497efb00a 同步上游更新 2024-01-06 14:59:35 +08:00
CallMeR 79703f9d62 修改 systemd 服务路径 2024-01-05 21:46:56 +08:00
CallMeR 53994238c8 更新文案描述 2024-01-05 21:34:30 +08:00
CallMeR ddcdc18564 修复 Typo 2024-01-01 17:33:04 +08:00
CallMeR f505690ed6 更新文档 2024-01-01 16:29:11 +08:00
CallMeR 96cb5ddcdc 更新文档 2024-01-01 16:19:33 +08:00
CallMeR 2858ba97c4 更新文档 2024-01-01 14:07:06 +08:00
CallMeR 833817d85c 更新文档 2024-01-01 13:54:16 +08:00
CallMeR 7097fb5d73 更新文档 2024-01-01 13:49:38 +08:00
CallMeR 52f3be600b 更新文档 2024-01-01 13:36:04 +08:00
CallMeR 0a9a2ee8fe 更新文档 2024-01-01 13:13:36 +08:00
CallMeR ed3c106e27 更新文档 2024-01-01 13:10:07 +08:00
CallMeR c94d7d31fc 更新文档 2024-01-01 13:00:00 +08:00
CallMeR abf168587d 更新文档 2024-01-01 12:49:36 +08:00
CallMeR 3e9a8eae07 更新文档 2024-01-01 12:02:06 +08:00
CallMeR 090ab28970 整理文档 2023-12-31 22:07:01 +08:00
CallMeR 59ebf178c7 整理文档 2023-12-31 21:09:03 +08:00
CallMeR 249717ed89 更新 TS 测试配置 2023-12-30 22:16:07 +08:00
CallMeR 2520ce4839 更新 nf_conntrack 参数 2023-12-24 01:50:16 +08:00
CallMeR 5d5750f120 更新定时参数 2023-12-21 22:09:33 +08:00
CallMeR f90dd7a7c8 更新 resolv.conf 配置 2023-12-16 23:52:08 +08:00
CallMeR 730773e42b 更新 resolv 配置方法 2023-12-16 16:40:20 +08:00
CallMeR c00e178df3 新增 OVS 工具 2023-12-15 02:25:23 +08:00
CallMeR f8c7676c85 精简非相关配置 2023-12-14 11:32:51 +08:00
CallMeR 29592abb40 更换 SmartDNS 广告规则 2023-12-14 11:30:39 +08:00
CallMeR 62b2641413 更新命令备注 2023-12-14 00:29:13 +08:00
CallMeR 04023ac155 优化文案描述 2023-12-14 00:22:21 +08:00
CallMeR 4dcb3ff7a9 优化文案描述 2023-12-13 23:30:01 +08:00
CallMeR ca30a2f9e9 优化文案描述 2023-12-13 23:14:33 +08:00
CallMeR 88ea495d5a 优化文案描述 2023-12-13 23:12:03 +08:00
CallMeR d08a3acf74 优化文案描述 2023-12-13 20:59:27 +08:00
CallMeR d26f303437 优化文案描述 2023-12-13 20:51:04 +08:00
CallMeR ed0db21a9f 优化文案描述 2023-12-13 20:19:45 +08:00
CallMeR 18e02bc9c8 优化文案描述 2023-12-13 19:59:29 +08:00
CallMeR 6882b01afc 更新文件名 2023-12-13 16:55:19 +08:00
CallMeR fec6ae3e56 更新脚本 2023-12-13 14:45:57 +08:00
CallMeR 660551f2fc 更新 curl 参数 2023-12-12 21:32:02 +08:00
CallMeR 80afa7dfe7 更新 SmartDNS 下载链接 2023-12-12 20:05:34 +08:00
CallMeR 509b344c69 更新 systemd-resolved 配置 2023-12-11 13:22:00 +08:00
CallMeR 3b3a3361fa 更新 curl 参数 2023-12-11 09:47:01 +08:00
CallMeR fba7575503 更新 curl 参数 2023-12-11 02:55:16 +08:00
CallMeR 4d77f0415e 更新 curl 参数 2023-12-11 02:27:42 +08:00
CallMeR 8b35afeec5 修复 curl 命令 2023-12-11 01:12:27 +08:00
CallMeR e0c69c3fa5 统一 crontab 时间 2023-12-10 23:32:46 +08:00
CallMeR 410f6e8d2e 替换 wget 命令 2023-12-10 22:55:40 +08:00
CallMeR 56d9125152 替换 wget 命令 2023-12-10 22:47:21 +08:00
CallMeR 779b75f3a8 更新 SmartDNS 定时器 2023-12-10 19:19:46 +08:00
CallMeR b0c7a2d4ce 优化文案描述 2023-12-10 18:39:15 +08:00
CallMeR b84dbe3872 优化文案描述 2023-12-10 18:31:43 +08:00
CallMeR 1555ec02ca 更新 SmartDNS 配置 2023-12-10 18:00:16 +08:00
CallMeR 906db9eac4 更新脚本变量 2023-12-09 21:17:31 +08:00
CallMeR 0d091d93c1 更新脚本变量 2023-12-09 21:10:04 +08:00
CallMeR b347128ec5 更新脚本变量 2023-12-09 20:58:20 +08:00
CallMeR 1e5a55de64 更新说明信息 2023-12-09 15:22:57 +08:00
CallMeR d052923897 更新文件名 2023-12-09 01:32:16 +08:00
CallMeR ba0afba7eb 更新 SmartDNS 插件脚本 2023-12-08 23:49:03 +08:00
CallMeR 6aa24ecb61 更新 SmartDNS 插件脚本 2023-12-08 23:42:25 +08:00
CallMeR 454ae86aba 更新 SmartDNS 配置 2023-12-08 13:03:17 +08:00
CallMeR 24b087aa1e 更新 SmartDNS 默认端口 2023-12-02 12:22:57 +08:00
CallMeR 56317210a6 更新 lsof 参数 2023-12-02 01:11:16 +08:00
CallMeR d8e7753112 更新 TS 测试配置 2023-12-02 00:44:34 +08:00
CallMeR 4700bc1c52 更新截图 2023-12-01 23:47:29 +08:00
CallMeR 29f6296a1c 更新 TS 测试配置 2023-12-01 18:54:38 +08:00
CallMeR 891d8ef2f6 更新 TS 测试配置 2023-12-01 13:47:44 +08:00
CallMeR e4117816c5 更新 TS 测试配置 2023-12-01 13:30:52 +08:00
CallMeR b109b0d840 更新 TS 测试配置 2023-12-01 00:40:19 +08:00
CallMeR 8bc4dd8587 更新 dnsmasq 配置 2023-11-30 23:20:51 +08:00
CallMeR eef810d850 更新截图 2023-11-30 17:41:18 +08:00
CallMeR 752c233013 更新安装截图 2023-11-30 15:29:44 +08:00
CallMeR 8b62f62420 更新模板虚拟机配置 2023-11-30 12:47:45 +08:00
CallMeR 46d0e0ce4a 更新截图 2023-11-30 12:21:27 +08:00
CallMeR f643128cf5 更新截图 2023-11-30 10:48:20 +08:00
CallMeR 165f6ea9dc 更新 TS 防火墙备注 2023-11-29 14:06:15 +08:00
CallMeR 7fc7ab2466 更新 TS 防火墙备注 2023-11-29 14:01:12 +08:00
CallMeR 2407555015 更新 TS 防火墙 2023-11-29 13:48:55 +08:00
CallMeR 5b65602c07 更新 TS 防火墙 2023-11-28 21:59:39 +08:00
CallMeR a2b1278038 更新备注 2023-11-28 21:52:29 +08:00
CallMeR 07d5ea174a 更新 TS 测试配置 2023-11-28 19:01:35 +08:00
CallMeR 554b2bd6d4 整理文件名 2023-11-28 18:35:55 +08:00
CallMeR 145328fb3c 更新 LXC 文案 2023-11-27 18:00:16 +08:00
CallMeR 9691336e5c 更新 LXC 文案 2023-11-27 17:53:56 +08:00
CallMeR f7ce11e99d 更新 LXC 文案 2023-11-27 17:51:16 +08:00
CallMeR eb631a1cdc 更新 LXC 文案 2023-11-27 14:36:30 +08:00
CallMeR 46ce4e4ee3 更新 SmartDNS 配置 2023-11-27 13:24:28 +08:00
CallMeR 0bd03af309 更新文件名 2023-11-27 12:56:34 +08:00
CallMeR 767c31694d 更新文件名 2023-11-27 12:54:07 +08:00
CallMeR b27372c20d 更新虚拟机 DEB822 配置 2023-11-26 20:58:59 +08:00
CallMeR b830088e5e 更新 PVE 版本 2023-11-25 22:24:54 +08:00
CallMeR 9f5884befb 优化 sysctl 配置 2023-11-24 12:07:45 +08:00
CallMeR 8af7ef896b 更新 dnsmasq 配置 2023-11-18 16:37:19 +08:00
CallMeR 09a60d3ae4 Dnsmasq 插件设置 2023-11-13 12:31:57 +08:00
CallMeR 830655bd52 更新定时任务 2023-11-13 12:21:25 +08:00
CallMeR 95023d68d3 回滚 SmartDNS 配置 2023-11-08 11:55:55 +08:00
CallMeR d8e6a50166 更新 dnsmasq 配置 2023-11-08 11:47:01 +08:00
CallMeR e6d805fba5 更新 SmartDNS 配置 2023-11-07 13:47:34 +08:00
CallMeR 9386f961d1 整理文档 2023-10-29 10:28:30 +08:00
CallMeR b84666a6b6 修复备注信息 2023-10-14 23:34:52 +08:00
CallMeR 07526b9ada 修复备注信息 2023-10-14 23:17:07 +08:00
CallMeR e31338113d 修复 cpupower 文案 2023-10-14 22:36:54 +08:00
CallMeR 7eda1b4eef 更新 SmartDNS 缓存参数 2023-10-10 22:10:45 +08:00
CallMeR 3b1a9e4f00 替换 ldnsutils 2023-10-07 01:45:36 +08:00
CallMeR 7288a7ba8b 更新 N6005 CPU 调度器输出 2023-09-15 14:48:52 +08:00
CallMeR 63631e6ad3 优化 CPU 调度器配置 2023-09-13 13:48:05 +08:00
CallMeR 5ed5ac768b 更新系统默认 qdisc 2023-09-10 16:32:42 +08:00
CallMeR ae5b3e1e82 更新本地域名后缀 2023-09-09 19:17:40 +08:00
CallMeR b7857fcd66 更新本地域名后缀 2023-09-09 19:03:26 +08:00
CallMeR 81101cde20 更新本地域名后缀 2023-09-09 18:30:25 +08:00
CallMeR 99e4a94a9f 更新安装截图 2023-09-09 16:45:06 +08:00
CallMeR c4294612eb 更新安装截图 2023-09-09 16:13:54 +08:00
CallMeR 38df9bd3e4 更新本地域名后缀 2023-09-07 22:36:50 +08:00
CallMeR 0019ac0fbc 修复时间参数说明 2023-08-18 14:32:13 +08:00
CallMeR 1b8caefe58 修复时间参数说明 2023-08-18 14:25:41 +08:00
CallMeR 9804c8964e 修复时间参数说明 2023-08-18 14:20:31 +08:00
CallMeR 861e468aa6 修复定时重启时间 2023-08-18 14:15:36 +08:00
CallMeR 90bc8f942b 修复定时重启时间 2023-08-18 14:12:26 +08:00
CallMeR 09f4738295 更新 SmartDNS 版本 2023-08-13 17:05:53 +08:00
CallMeR ea71df8c8c 更新说明信息 2023-08-07 21:35:47 +08:00
CallMeR 1a8c107333 更新 PVE 官网截图 2023-08-07 21:29:53 +08:00
CallMeR c40ba60a6e 更新 PVE 官网截图 2023-08-07 21:26:36 +08:00
CallMeR 9494d82747 更新 PVE 官网截图 2023-08-07 21:22:59 +08:00
CallMeR f89c38f8d8 更新 PVE 官网截图 2023-08-07 21:14:57 +08:00
CallMeR 6a9202a62b 更新示例 2023-08-01 13:39:06 +08:00
CallMeR 8a10db07d1 更新示例 2023-08-01 13:30:56 +08:00
CallMeR 17ab25b998 统一时间规划 2023-07-26 14:57:51 +08:00
CallMeR 17ae656734 更新 SmartDNS 配置 2023-07-25 18:31:52 +08:00
CallMeR b28bb464c1 更新 SmartDNS 配置 2023-07-23 13:39:18 +08:00
CallMeR 0fd5dc83f2 更新 SmartDNS 配置 2023-07-23 03:28:02 +08:00
CallMeR ee64d1e961 更新 SmartDNS 描述 2023-07-16 23:55:33 +08:00
CallMeR 636bbfb62b 更新 Adguard Home 描述 2023-07-16 23:49:43 +08:00
CallMeR bb19e4f7dd 更新 SmartDNS 测试配置 2023-07-16 20:14:59 +08:00
CallMeR b8a0db90a3 更新 SmartDNS 测试配置 2023-07-16 04:29:23 +08:00
CallMeR ec7034f2f1 更新代码编辑器 2023-07-16 01:59:58 +08:00
CallMeR 60f0b0940c 更新 SmartDNS 配置 2023-07-16 01:52:45 +08:00
CallMeR a8da3fa115 更新 SmartDNS 配置 2023-07-16 01:48:13 +08:00
CallMeR 37373fbdcd 更新 SmartDNS 配置 2023-07-16 01:34:05 +08:00
CallMeR e96b379620 更新 PVE 制作虚拟机模板 2023-07-16 01:23:04 +08:00
CallMeR 4795c730c9 更新文案描述 2023-07-06 18:05:56 +08:00
CallMeR bf4d22b10b 更新代码编辑器 2023-07-01 21:54:05 +08:00
CallMeR 22806b5657 修复文案描述 2023-06-29 17:45:25 +08:00
CallMeR 9f86e73f61 更新 PVE 虚拟机克隆 2023-06-28 13:04:33 +08:00
CallMeR fdceec75ba 更新 PVE 制作虚拟机模板 2023-06-28 00:30:32 +08:00
CallMeR 182a939f5e 更新 PVE 系统调整 2023-06-28 00:24:19 +08:00
CallMeR b71d013431 更新 PVE 虚拟机克隆 2023-06-28 00:12:07 +08:00
CallMeR e64d6f9b7f 更新 PVE 创建模板虚拟机 2023-06-27 22:32:10 +08:00
98 changed files with 2735 additions and 890 deletions
+21 -15
View File
@@ -4,17 +4,17 @@ PVE 系统正式安装之前,需要准备 PVE 的安装镜像和一些必要
### 0.1. PVE 镜像下载
PVE 下载地址:https://www.proxmox.com/en/downloads
PVE 下载地址:[Proxmox Virtual Environment](https://www.proxmox.com/en/downloads/proxmox-virtual-environment/iso)
页面中可能有多个 PVE 的安装 ISO ,可以根据需要进行选择,目前最新的 `Proxmox VE 8.0 ISO` 作为演示。
页面中有多个 PVE 相关文件,本文以目前最新的 `Proxmox VE 8.3-1 ISO Installer` 作为演示。
![下载PVE ISO文件](img/p01/pve_download_iso.jpeg)
点击 `Proxmox VE 8.x ISO Installer` 链接,进入 PVE 下载页面。
点击 `Proxmox VE 8.x ISO Installer` 链接。
![PVE下载页面](img/p01/pve_download_iso.jpeg)
下载 ISO 时请注意 `SHA256SUM` ,后续将使用该校验信息对下载下来的 ISO 进行校验,以确保 ISO 文件的完整性。
![输入图片说明](img/p01/pve_iso_hash.jpeg)
![下载PVE](img/p01/pve_iso_hash.jpeg)
### 0.2.启动盘制作工具
@@ -50,25 +50,31 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
![Rufus写盘工具](img/p01/pve_rufus.jpeg)
### 0.3. SSH 工具
### 0.3.终端工具
考虑到配置 PVE 服务器、路由器、DNS 服务器时,需要在 CLI 中输入命令,因此这里推荐几个常用的 SSH 工具。
考虑到配置 PVE 服务器、路由器、DNS 服务器时,需要在 CLI 中输入命令,因此这里推荐几个常用的终端工具。
#### Tabby
#### Windows Terminal
官方网站地址:https://tabby.sh
官方网站地址:https://aka.ms/terminal
基于 Electron 开发的开源跨平台终端工具,内部集成了 SFTP ,可以在 Github 平台上进行下载。
Microsoft 官方终端工具,可以在 Github 平台或 Microsoft 应用商店中进行下载。
支持 Windows 、macOS 、Linux 。
![Windows Terminal](img/p01/pve_win_terminal.png)
![Tabby SSH工具](img/p01/pve_tabby.png)
#### Termius
官方地址:https://termius.com/
企业级终端工具,支持 Windows、macOS、Linux 系统以及移动端系统。
![Termius](img/p01/pve_termius.jpeg)
#### MobaXterm
官方地址:https://mobaxterm.mobatek.net
功能强大的 SSH 工具,仅支持 Windows 。
功能强大的终端工具,仅支持 Windows 系统
![MobaXterm](img/p01/pve_mobaxterm.png)
@@ -156,7 +162,7 @@ PVE 为最关键的虚拟化层,建议使用强密码,包含大小写字母
FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
演示中 FQDN 为 `node01.fox.local` ,因此 PVE 的主机名为 `node01`
演示中 FQDN 为 `node01.fox.home.arpa` ,因此 PVE 的主机名为 `node01`
根据规划,PVE 的 IPv4 管理地址为 `172.16.1.254`
@@ -166,7 +172,7 @@ FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
|参数|值|说明|
|--|--|--|
|Hostname (FQDN)|`node01.fox.local`|设置 PVE `域``主机名` |
|Hostname (FQDN)|`node01.fox.home.arpa`|设置 PVE `域``主机名` |
|IP Address (CIDR)|`172.16.1.254/24`|设置 PVE IPv4 地址|
|Gateway|`172.16.1.1`|设置 PVE IPv4 网关|
|DNS Server|`172.16.1.1`|设置 PVE IPv4 DNS |
+52 -39
View File
@@ -12,7 +12,7 @@
### 1.1.系统软件源
使用 SSH 工具登录到 PVE 服务器,首先对现有的软件源配置进行备份。
使用终端工具登录到 PVE 服务器,首先对现有的软件源配置进行备份。
```bash
## 进入系统软件源配置文件目录
@@ -64,37 +64,47 @@ deb https://mirrors.ustc.edu.cn/debian-security/ bookworm-security main contrib
默认情况下,PVE 额外启用了 2 个官方源,且为订阅收费制,因此需要替换为免费源。
删除 PVE 官方付费软件源,使用以下命令。
首先创建 PVE 费软件源,执行以下命令。
```bash
## 创建 PVE 免费软件源
$ source /etc/os-release
$ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/pve $VERSION_CODENAME pve-no-subscription" > /etc/apt/sources.list.d/pve-no-subscription.list
```
对于 Proxmox Backup Server 和 Proxmox Mail Gateway,请将以上命令中的 `pve` 分别替换为 `pbs``pmg`
进一步创建 PVE Ceph 免费软件源,Ceph 软件源为 PVE 8 之后默认安装,执行以下命令。
```bash
## 创建 PVE Ceph 免费软件源脚本
if [ -f /etc/apt/sources.list.d/ceph.list ]; then
CEPH_CODENAME=`ceph -v | grep ceph | awk '{print $(NF-1)}'`
source /etc/os-release
echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-$CEPH_CODENAME $VERSION_CODENAME no-subscription" > /etc/apt/sources.list.d/ceph-no-subscription.list
fi
```
最后,删除 PVE 官方付费软件源,执行以下命令。
**注意:rm 为高风险命令,请正确使用,请勿手抖,请勿手抖。**
```bash
## 删除付费软件源
$ rm -rvf /etc/apt/sources.list.d/*.list
```
创建 PVE 免费软件源。
**注意:该命令为三行,在输入时请逐行输入并回车执行。**
```bash
## 创建 PVE 免费源
$ source /etc/os-release
$ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy $VERSION_CODENAME no-subscription" > /etc/apt/sources.list.d/ceph-no-subscription.list
$ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/pve $VERSION_CODENAME pve-no-subscription" > /etc/apt/sources.list.d/pve-no-subscription.list
$ rm -rvf /etc/apt/sources.list.d/pve-enterprise.list /etc/apt/sources.list.d/ceph.list
```
创建完成后对其进行检查。
```bash
## 检查PVE免费源
$ cat /etc/apt/sources.list.d/ceph-no-subscription.list
## 检查 PVE 免费源
$ cat /etc/apt/sources.list.d/pve-no-subscription.list
$ cat /etc/apt/sources.list.d/ceph-no-subscription.list
```
如果输出结果中有 USTC 的镜像地址,则表示命令已经正确执行。
@@ -102,11 +112,11 @@ $ cat /etc/apt/sources.list.d/pve-no-subscription.list
```bash
#### PVE 免费软件源示例输出
#### Ceph
deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy bookworm no-subscription
#### PVE
deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription
#### Ceph
deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy bookworm no-subscription
```
### 1.3. PVE CT 源
@@ -116,12 +126,17 @@ deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription
由于该功能暂时未被使用,因此本文只做记录。
```bash
## 替换 CT Templates 源
## 备份 CT Templates 源
$ cp /usr/share/perl5/PVE/APLInfo.pm /usr/share/perl5/PVE/APLInfo.pm.bak
## 替换 CT Templates 链接
$ sed -i 's|http://download.proxmox.com|https://mirrors.ustc.edu.cn/proxmox|g' /usr/share/perl5/PVE/APLInfo.pm
## 重启 PVE API 守护进程
$ systemctl restart pvedaemon.service
## 更新 CT Templates 列表
$ pveam update
```
### 1.4.镜像同步
@@ -138,7 +153,7 @@ $ apt clean && apt autoclean && apt autoremove --purge
$ apt update
## 更新系统
$ apt dist-upgrade
$ apt full-upgrade
```
## 2.安装必要软件
@@ -149,20 +164,20 @@ $ apt dist-upgrade
其中 `unattended-upgrades` 为系统自动更新服务,后续会对其进行配置。
`cpufrequtils` 为 CPU 调度器的配置工具,后续会对 CPU 调度算法进行调整。
`linux-cpupower` 为 CPU 调度器的配置工具,后续会对 CPU 调度算法进行调整。
```bash
## 同步镜像仓库
$ apt update
## 安装系统软件
$ apt install htop lm-sensors unzip vim tmux unattended-upgrades powermgmt-base
$ apt install btop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具
$ apt install iperf iperf3 iftop
$ apt install iperf iperf3 iftop sshguard openvswitch-switch
## 安装 CPU 调度调整工具
$ apt install cpufrequtils
$ apt install linux-cpupower
## 根据 CPU 厂商安装 CPU 微码工具
$ apt install intel-microcode (amd64-microcode)
@@ -194,9 +209,9 @@ $ update-pciids
|IPv4|管理地址|`172.16.1.254`|PVE IPv4 地址|
||网关地址|`172.16.1.1`|PVE IPv4 网关|
||DNS 地址|`172.16.1.1`|PVE IPv4 DNS 服务器|
|IPv6|管理地址|`fdac::fe`|PVE IPv6 地址|
||网关地址|`-`|IPv6 网关将使用 `LLA` 自动配置|
||DNS 地址|`fdac::1`|PVE IPv6 DNS 服务器|
|IPv6|管理地址|`fdac::fe`|PVE IPv6 地址(可选)|
||网关地址|`-`|IPv6 网关将使用 `SLAAC` 自动配置|
||DNS 地址|`fdac::1`|PVE IPv6 DNS 服务器(可选)|
![PVE网络规划](img/p02/pve_net_schematization.png)
@@ -248,11 +263,9 @@ $ update-pciids
1. 如非特殊需求,通常情况下 PVE 系统无需使用 IPv6 网络。
2. 根据实际测试,仅 PVE 纯内部网桥( `vmbr4` )可通过主路由获取公网 GUA IPv6 地址
2. 主路由未配置 IPv6 ULA 网段时,例如本文演示地址 `fdac::/64` ,无需填写 `IPv6/CIDR` 参数
3. 主路由未配置 ULA IPv6 网段时,例如本文演示地址 `fdac::/64` ,无需填写 `IPv6/CIDR` 参数
4. 通常情况下 IPv6 无需填写 `网关` 参数,IPv6 网关将通过 LLA IPv6 地址自动配置。
3. 通常情况下 IPv6 无需填写 `网关` 参数,IPv6 网关将通过 LLA IPv6 地址自动配置
![最后的物理接口网桥](img/p02/pve_br_last_phyport_ipv6.jpeg)
@@ -290,9 +303,9 @@ $ update-pciids
在 PVE 系统的安装过程中,设置了 DNS 的 IPv4 地址 `172.16.1.1` ,但并未设置 DNS 的 IPv6 地址。
在 PVE 的 DNS 设置页面,手动添加 DNS IPv6 地址,即主路由 LAN 口 ULA IPv6 地址。
在 PVE 的 DNS 设置页面,手动添加 DNS IPv6 地址,即主路由 LAN 口 IPv6 ULA 地址。
同样,若 PVE 不使用 IPv6 网络或主路由未配置 ULA IPv6 网段,本步骤可跳过。
同样,若 PVE 不使用 IPv6 网络或主路由未配置 IPv6 ULA 网段,本步骤可跳过。
![PVE添加IPv6DNS](img/p02/pve_add_ipv6_dns.jpeg)
+169 -71
View File
@@ -9,13 +9,13 @@
$ apt update
## 安装系统软件
$ apt install htop lm-sensors unzip vim tmux unattended-upgrades powermgmt-base
$ apt install btop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具
$ apt install iperf iperf3 iftop
$ apt install iperf iperf3 iftop sshguard openvswitch-switch
## 安装 CPU 调度调整工具
$ apt install cpufrequtils
$ apt install linux-cpupower
## 根据 CPU 厂商安装 CPU 微码工具
$ apt install intel-microcode (amd64-microcode)
@@ -26,7 +26,7 @@ $ update-pciids
## 1.系统时区
如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以使用以下命令修正。
如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以执行以下命令修正。
输出结果如果和北京时间一致,则代表修改正确。
@@ -43,9 +43,7 @@ Sun, 25 Jun 2023 12:12:12 +0800
Debian 系统常用 `systemd-timesyncd.service` 来同步时间,而 PVE 系统使用 `chrony.service` 来同步时间。
为了使用国内的 NTP 服务器,需要对 `chrony.service` 进行配置。
执行以下命令对 `chrony` 的配置文件进行修改。
为了使用国内的 NTP 服务器,需要对 `chrony.service` 进行配置,执行以下命令
```bash
## 编辑 chrony 配置文件
@@ -61,12 +59,13 @@ $ nano /etc/chrony/chrony.conf
# pool 2.debian.pool.ntp.org iburst ## 在这行前面增加注释符 # 来注释
# Use Custom vendor zone.
pool ntp.tencent.com iburst
pool ntp.aliyun.com iburst
pool ntp.tencent.com iburst
pool cn.pool.ntp.org iburst
```
保存该配置文件后,需重启 `chrony` 服务,并再次检查系统 NTP 服务器地址。
保存该配置文件后,需重启 `chrony.service` ,并再次检查系统 NTP 服务器地址。
```bash
## 重启 chrony 服务
@@ -78,54 +77,62 @@ $ chronyc sources -V
#### 系统 NTP 服务器示例输出
MS Name/IP address Stratum Poll Reach LastRx Last sample
===============================================================================
^+ 106.55.184.199 2 6 17 11 +752us[ +273us] +/- 40ms
^* 203.107.6.88 2 6 17 11 -1868us[-2348us] +/- 17ms
^- 203.107.6.88 2 6 7 2 +987us[+1251us] +/- 23ms
^? 106.55.184.199 2 6 11 1 -501us[ -501us] +/- 60ms
^- electrode.felixc.at 2 6 7 2 +3532us[ +663us] +/- 121ms
^* 119.28.206.193 2 6 15 1 +184us[-2686us] +/- 53ms
^- 119.28.183.184 2 6 7 2 +512us[-2358us] +/- 47ms
^+ time.cloudflare.com 3 6 13 1 -85us[-2955us] +/- 106ms
```
## 2. CPU 调度器
安装 `cpufrequtils` 后,需检查 CPU 当前调度器。
安装 `linux-cpupower` 后,需检查 CPU 当前调度器。
```bash
## 检查 CPU 当前调度器
$ cpufreq-info
$ cpupower -c all frequency-info
#### 设备 CPU - J4125 示例输出
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
Report errors and bugs to cpufreq@vger.kernel.org, please.
analyzing CPU 0:
driver: intel_cpufreq
CPUs which run at the same hardware frequency: 0
CPUs which need to have their frequency coordinated by software: 0
maximum transition latency: 20.0 us.
maximum transition latency: 20.0 us
hardware limits: 800 MHz - 2.70 GHz
available cpufreq governors: conservative, ondemand, userspace, powersave, performance, schedutil
available cpufreq governors: conservative ondemand userspace powersave performance schedutil
current policy: frequency should be within 800 MHz and 2.70 GHz.
The governor "ondemand" may decide which speed to use
within this range.
current CPU frequency is 1.84 GHz.
current CPU frequency: Unable to call hardware
current CPU frequency: 800 MHz (asserted by call to kernel)
boost state support:
Supported: yes
Active: yes
#### 设备 CPU - N6005 示例输出
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
Report errors and bugs to cpufreq@vger.kernel.org, please.
analyzing CPU 0:
driver: intel_pstate
CPUs which run at the same hardware frequency: 0
CPUs which need to have their frequency coordinated by software: 0
maximum transition latency: 4294.55 ms.
maximum transition latency: Cannot determine or is not supported.
hardware limits: 800 MHz - 3.30 GHz
available cpufreq governors: performance, powersave
available cpufreq governors: performance powersave
current policy: frequency should be within 800 MHz and 3.30 GHz.
The governor "performance" may decide which speed to use
within this range.
current CPU frequency is 2.00 GHz.
current CPU frequency: Unable to call hardware
current CPU frequency: 2.00 GHz (asserted by call to kernel)
boost state support:
Supported: yes
Active: yes
```
这里面主要关注两个点:
- driver: `intel_cpufreq``intel_pstate`
- driver: `intel_cpufreq``intel_pstate`
- current policy: `governor "ondemand"``governor "performance"`
- current policy: `governor "ondemand"``governor "performance"`
还有另外一个命令可用来显示 CPU 当前调度器。
@@ -142,7 +149,7 @@ performance
CPU 驱动一般不建议手动调整,而 `governor` 后面的参数表示 CPU 当前调度器设置。
接下来,需要了解 CPU 支持的调度器有哪些,使用以下命令。
接下来,需要了解 CPU 支持的调度器有哪些,执行以下命令。
```bash
## 检查 CPU 调度器支持情况
@@ -161,30 +168,69 @@ performance powersave
- CPU 驱动为 `intel_pstate` 时,推荐使用 `powersave` 调度器。
本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器来编辑 `cpufrequtils` 的配置文件。
因为该配置文件很长,完整的配置文件可查看 [pve_cpufrequtils.conf](./src/pve_cpufrequtils.conf) 以便对比。
修改完成后,需要重启 PVE 服务器来使参数生效。
本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器创建 `cpupower` 的配置文件。
```bash
## 编辑 cpufrequtils 配置文件
$ nano /etc/init.d/cpufrequtils
## 创建 cpupower 配置文件
$ nano /etc/default/cpupower
```
在配置文件中修改以下配置项,并保存。
```bash
## cpufrequtils 配置项
# This configuration file is customized by fox,
# Optimize system CPU governors.
ENABLE="true"
GOVERNOR="powersave" ## 修改本行的调度器为 powersave
MAX_SPEED="0"
MIN_SPEED="0"
CPUPOWER_START_OPTS="frequency-set -g powersave"
CPUPOWER_STOP_OPTS="frequency-set -g performance"
```
PVE 服务器重启完成后需再次查看 CPU 调度器,检验配置文件是否生效
使用 `nano` 编辑器创建 `cpupower` 服务配置文件,以满足系统自动化设置需求
```bash
## 创建 cpupower 服务配置文件
$ nano /etc/systemd/system/cpupower.service
```
在服务配置文件中修改以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize for cpupower systemd service.
[Unit]
Description=Apply cpupower configuration
ConditionVirtualization=!container
After=syslog.target
[Service]
Type=oneshot
EnvironmentFile=/etc/default/cpupower
ExecStart=/usr/bin/cpupower $CPUPOWER_START_OPTS
ExecStop=/usr/bin/cpupower $CPUPOWER_STOP_OPTS
RemainAfterExit=yes
[Install]
WantedBy=multi-user.target
```
由于修改了服务项,需要执行以下命令进行重载。
```bash
## 服务重载
$ systemctl daemon-reload
```
执行以下命令让 `cpupower` 服务开机自启动。
```bash
## 设置 cpupower 服务开机自启
$ systemctl enable cpupower.service
```
修改完成后,需重启 PVE 服务器,并再次查看 CPU 调度器,检验配置文件是否生效。
这里提供两个额外命令,方便实时查看 CPU 当前频率和温度状况。
@@ -198,9 +244,9 @@ $ watch -d sensors
## 3. PVE 定时重启
有时需要让 PVE 服务器周期性的定时重启,则可使用以下命令。
有时需要让 PVE 服务器周期性的定时重启,则可执行以下命令。
参数表示每月 `1``16` 号的 `5``0` 执行系统重启命令。
参数表示每月 `1``16` 号的 `02:30` 执行系统重启命令。
```bash
## 查看系统定时任务
@@ -215,7 +261,7 @@ $ crontab -e
```bash
## 定时任务配置项
0 5 1,16 * * /usr/sbin/reboot
30 2 1,16 * * /usr/sbin/reboot
```
@@ -225,7 +271,7 @@ $ crontab -e
配置系统自动更新之前,需检查系统当前定时器状态。
后续将手动调整该定时器的时间,使其每 `5`凌晨 `02:00` 进行触发。
后续将手动调整该定时器的时间,使其每 `5` `01:30` 进行触发。
```bash
## 检查系统定时器
@@ -234,17 +280,16 @@ $ systemctl status apt-daily-upgrade.timer
#### 系统定时器示例输出
● apt-daily-upgrade.timer - Daily apt upgrade and clean activities
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Active: active (waiting) since Fri 2023-06-23 18:55:58 CST; 1 day 18h ago
Until: Fri 2023-06-23 18:55:58 CST; 1 day 18h ago
Trigger: Mon 2023-06-26 06:26:25 CST; 16h left
Active: active (waiting) since Tue 2023-08-01 13:01:19 CST; 27min ago
Trigger: Wed 2023-08-02 06:14:50 CST; 16h left
Triggers: ● apt-daily-upgrade.service
Jun 23 18:55:58 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Aug 01 13:01:19 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
```
### 4.2.配置更新策略
使用以下命令,启用系统自动更新。
执行以下命令,启用系统自动更新。
执行命令后,使用 “左右” 方向键进行选择,“回车” 键进行确认。
@@ -258,7 +303,7 @@ $ dpkg-reconfigure -plow unattended-upgrades
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
```
进一步调整 apt 的 `20auto-upgrades` 配置文件。
进一步调整 `20auto-upgrades` 配置文件。
```bash
## 进入 apt 的配置目录
@@ -282,7 +327,7 @@ APT::Periodic::CleanInterval "1";
```
进一步调整 apt 的 `50unattended-upgrades` 配置文件。
进一步调整 `50unattended-upgrades` 配置文件。
```bash
## 编辑 50unattended-upgrades 配置文件
@@ -307,9 +352,9 @@ $ nano /etc/apt/apt.conf.d/50unattended-upgrades
- 自动重启:开启。
- 自动重启时间:`05:00`
- 自动重启时间:`02:30`
因为该配置文件很长,完整的配置文件可查看 [pve_50unattended_upgrades.conf](./src/pve_50unattended_upgrades.conf) 以便对比。
因为该配置文件很长,完整的配置文件可查看 [pve_50unattended_upgrades.conf](./src/pve/pve_50unattended_upgrades.conf) 以便对比。
```bash
## 删除以下行前面的注释符 // ,代表启用
@@ -336,7 +381,7 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "05:00";
Unattended-Upgrade::Automatic-Reboot-Time "02:30";
```
@@ -344,7 +389,7 @@ Unattended-Upgrade::Automatic-Reboot-Time "05:00";
系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。
完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve_apt_daily_upgrade.conf) 以便对比。
完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve/pve_apt_daily_upgrade.conf) 以便对比。
```bash
## 配置系统定时器
@@ -358,7 +403,7 @@ $ systemctl edit apt-daily-upgrade.timer
[Timer]
OnCalendar=
OnCalendar=02:00
OnCalendar=01:30
RandomizedDelaySec=0
```
@@ -377,14 +422,13 @@ $ systemctl status apt-daily-upgrade.timer
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d
└─override.conf
Active: active (waiting) since Sun 2023-06-25 14:35:06 CST; 9s ago
Until: Sun 2023-06-25 14:35:06 CST; 9s ago
Trigger: Mon 2023-06-26 02:00:00 CST; 11h left
Active: active (waiting) since Tue 2023-08-01 13:37:41 CST; 9s ago
Trigger: Wed 2023-08-02 01:30:00 CST; 11h left
Triggers: ● apt-daily-upgrade.service
Jun 25 14:35:06 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Jun 25 14:35:06 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities...
Jun 25 14:35:06 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Aug 01 13:37:41 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Aug 01 13:37:41 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities...
Aug 01 13:37:41 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
```
## 5.硬件直通
@@ -393,7 +437,7 @@ Jun 25 14:35:06 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt u
参考官方文档 [qm_pci_passthrough](https://pve.proxmox.com/pve-docs/pve-admin-guide.html#qm_pci_passthrough) 和 [Pci passthrough](https://pve.proxmox.com/wiki/Pci_passthrough) 开启 PVE 硬件直通功能。
使用 SSH 工具登录到 PVE 服务器,编辑系统 `Grub` 的配置文件 `/etc/default/grub`
使用终端工具登录到 PVE 服务器,编辑系统 `Grub` 的配置文件 `/etc/default/grub`
```bash
## 编辑 Grub 配置文件
@@ -445,7 +489,7 @@ vfio_pci
```
使用以下命令更新 `initramfs` ,更新完成后,建议重启 PVE 服务器。
执行以下命令更新 `initramfs` ,更新完成后,建议重启 PVE 服务器。
```bash
## 更新 initramfs
@@ -454,7 +498,7 @@ $ update-initramfs -u -k all
### 5.3.检查硬件直通
PVE 服务器重启完成后,再次使用 SSH 工具登录,并使用以下命令检查硬件直通状态。
PVE 服务器重启完成后,再次使用终端工具登录,并执行以下命令检查硬件直通状态。
主要查看 `IOMMU``Directed I/O``Interrupt Remapping` 的启用状态。
@@ -494,7 +538,7 @@ $ dmesg | grep -e DMAR -e IOMMU -e AMD-Vi
[ 2.290568] DMAR: Intel(R) Virtualization Technology for Directed I/O
```
检查系统 `IOMMU` 分组,使用以下命令。
检查系统 `IOMMU` 分组,执行以下命令。
```bash
## 检查 IOMMU group
@@ -526,9 +570,66 @@ $ find /sys/kernel/iommu_groups/ -type l
/sys/kernel/iommu_groups/9/devices/0000:00:1c.6
```
## 6.系统清理
## 6. BTRFS 调整
PVE 系统配置完成后,可逐条执行以下命令,对系统进行清理。
**额外说明:**
1. 本节专为 `BTRFS` 单盘 `RAID0`(条带模式)安装的 PVE 系统设计,使用其他安装模式时,请跳过此节。
2. `BTRFS` 文件系统当前仍为技术预览状态,请谨慎操作。
3. 有关在 PVE 中使用 `BTRFS` 的详情,请参阅 [Proxmox VE - BTRFS](https://pve.proxmox.com/wiki/BTRFS) 。
安装 PVE 时,若使用了 `BTRFS` 单盘 `RAID0` 的安装模式,系统默认未启用 swap 和 zstd 压缩,需要手动开启。
通常情况下,内存与 swap 的 **推荐** 比例为 `1:1` 。本机具有 `16GB` 内存,因此设置 `16GB` swap 空间。
执行以下命令,在 `BTRFS` 文件系统中创建子卷,并配置激活 swapfile 。
```bash
## 创建用于存放交换文件的子卷
$ btrfs subvolume create /swap
## 在子卷中创建 16GB 的交换文件
$ btrfs filesystem mkswapfile --size 16g --uuid clear /swap/swapfile
## 激活交换文件
$ swapon /swap/swapfile
```
此时还需进一步修改系统的 `fstab` 配置文件,以启用 `BTRFS` 的 zstd 压缩功能并确保 swap 在系统启动时自动激活。
```bash
## 编辑 fstab 配置文件
$ nano /etc/fstab
```
`fstab` 为系统关键配置文件,直接影响系统启动,修改此文件时,请注意以下几点:
- 仅修改根目录 `/` 对应的挂载选项,添加 `compress=zstd` 参数。
- 在文件末尾新增一行,添加 swap 的自动挂载。
-**不要** 修改其余配置参数,尤其是设备的唯一标识符( `UUID` ),切勿修改。
修改完成后,示例如下。
```bash
#### 系统 fstab 示例配置
# <file system> <mount point> <type> <options> <dump> <pass>
UUID=<DO-NOT-EDIT-YOUR-UUID> / btrfs defaults,compress=zstd 0 1
UUID=<YOUR-UUID> /boot/efi vfat defaults 0 1
proc /proc proc defaults 0 0
/swap/swapfile none swap defaults 0 0
```
## 7.系统清理
PVE 系统配置完成后,可执行以下命令,对系统进行清理。
```bash
## 清理系统软件包
@@ -541,10 +642,7 @@ $ rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
$ find /var/log/ -type f | xargs rm -rvf
## 清理命令历史记录文件
$ rm -rvf ~/.bash_history
## 清理命令历史
$ history -c
$ rm -rvf ~/.bash_history && history -c
```
至此 PVE 的系统调整已经完成。
+54 -44
View File
@@ -2,13 +2,13 @@
将虚拟机制作成模板,可在后续新建虚拟机时快速从模板中创建,减少系统安装配置时间。
该虚拟机模板主要作内网 DNS 服务器使用,并会安装 Adguard Home
该虚拟机模板主要作内网 DNS 服务器,由 `Adguard Home``SmartDNS` 提供 DNS 解析服务
本文将使用 Debian 的云镜像 `debian-12-genericcloud-amd64.qcow2` 作为模板虚拟机的镜像。
本文将使用 Debian 的云镜像 `debian-12-generic-amd64.qcow2` 作为模板虚拟机的镜像。
访问 [Debian Official Cloud Images](https://cloud.debian.org/images/cloud/) 官方网站,下载最新版 `Bookworm` 云镜像以及对应的校验文件。
![下载镜像](img/p04/download_genericcloud_image_qcow2.jpeg)
![下载镜像](img/p04/download_generic_image_qcow2.jpg)
## 1.创建虚拟机
@@ -28,7 +28,7 @@
### 1.3.系统
SCSI 控制器保持默认 `VirtIO SCSI single` ,并勾选 `Qemu代理` 选项。
SCSI 控制器保持默认 `VirtIO SCSI single` ,机型可选 `q35` ,并勾选 `Qemu代理` 选项。
![虚拟机系统](img/p04/vm_system.jpeg)
@@ -84,52 +84,49 @@ CPU `类别` 选择 `host` `插槽` 与 `核心` 数根据物理 CPU 核心
### 2.1.删除光驱
查看虚拟机详情页,在虚拟机硬件配置页面,移除其 `CD/DVD驱动器`
查看虚拟机详情页,在虚拟机 `硬件` 配置页面,移除其 `CD/DVD驱动器`
![虚拟机删除光驱](img/p04/vm_delete_cd.jpeg)
### 2.2.导入镜像文件
使用 SSH 工具登录 PVE 服务器,并进入 `tmp` 目录,逐条执行以下命令创建一个文件夹
使用终端工具登录 PVE 服务器,并进入 `/tmp` 目录,执行以下命令创建一个目录
```bash
## 进入 tmp 目录
$ cd /tmp
## 创建存放 Debian 云镜像的临时目录
$ mkdir -p /tmp/Debian
## 创建文件夹
$ mkdir Debian
## 进入文件夹
$ cd Debian
## 进入目录
$ cd /tmp/Debian
```
将 Debian 云镜像传输到该文件夹,并检查 `hash`
将 Debian 云镜像传输到该目录,并检查 `hash`
```bash
## 下载云镜像校验文件
$ wget https://cloud.debian.org/images/cloud/bookworm/latest/SHA512SUMS
## 下载云镜像
$ wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2
$ wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-generic-amd64.qcow2
## 检查文件是否存在
$ ls -la
$ ls -lah
## 显示校验文件内容
$ cat SHA512SUMS
## 计算文件 hash
$ sha512sum debian-12-genericcloud-amd64.qcow2
$ sha512sum debian-12-generic-amd64.qcow2
```
确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1000`
确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1001`
```bash
## 将 qcow2 镜像导入虚拟机中
$ qm importdisk 1000 debian-12-genericcloud-amd64.qcow2 local-lvm
$ qm importdisk 1001 debian-12-generic-amd64.qcow2 local-lvm
#### 镜像导入示例输出
Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0'
```
![虚拟机新磁盘](img/p04/vm_unused_hd.jpeg)
@@ -160,18 +157,6 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
![虚拟机ci参数](img/p04/vm_ci_details.jpeg)
### 2.4.添加串行端口
部分云镜像需要使用 `serial` 端口作为视频输出端口,否则虚拟机无法启动,因此给模板虚拟机添加串行端口。
点击顶部 `添加` 菜单,选择 `串行端口`
![虚拟机添加串口](img/p04/vm_serial.jpeg)
串行端口编号为 `0`
![虚拟机串口参数](img/p04/vm_serial_details.jpeg)
虚拟机硬件设备修改完成后,如下图所示。
![虚拟机全部硬件](img/p04/vm_hardware_all.jpeg)
@@ -208,7 +193,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
## 4.设置 Cloud-Init
进入左侧虚拟机 `Cloud-Init` 菜单,可以看到当前虚拟机的初始化参数。
进入左侧虚拟机 `Cloud-Init` 页面,可以看到当前虚拟机的初始化参数。
### 4.1.自动配置 IPv6
@@ -216,20 +201,21 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
|参数|值|说明|
|--|--|--|
|用户|fox|新系统的管理员账户|
|密码|********|使用强密码|
|DNS域|fox.local|内网域名(可选)|
|DNS服务器|`172.16.1.1 127.0.0.1`|本机DNS服务器,用空格隔开|
|SSH公钥||使用秘钥登录服务器,暂不使用|
|用户|`fox`|新系统的管理员账户|
|密码|`********`|使用强密码|
|DNS域|`fox.home.arpa`|内网域名(可选)|
|DNS服务器|`172.16.1.1`|本机 DNS 服务器|
|SSH公钥|`无`|使用秘钥登录服务器,暂不使用|
|Upgrade packages|`是`|启动时更新软件包,保持默认即可|
|IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=auto`|模板的 IP 设置|
**额外说明:**
1. 修改 `Cloud-Init` 参数时,需要在虚拟机关机情况下修改才会生效。
2. `DNS服务器` 设置部分,如果先设置了 `127.0.0.1` 作为 DNS 服务器,后续其他 DNS 的 IP 地址将被忽略
2. `DNS服务器` 参数支持输入多个 IPv4 / IPv6 地址,使用空格隔开
此时内网没有其他 DNS 服务器,因此将 `DNS服务器` 设置为 `172.16.1.1 127.0.0.1` IP 之间用空格隔开
3. 当前 `DNS服务器` 参数为主路由 LAN 口 IPv4 地址,确保虚拟机能正常联网
![CI网络配置](img/p04/vm_ci_dns.jpeg)
@@ -239,16 +225,17 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
### 4.2.手动配置 IPv6
当主路由配置了 ULA IPv6 网段,且希望指定内网 DNS 服务器的 ULA IPv6 地址时,需要调整 `Cloud-Init` 参数。
当主路由配置了 IPv6 ULA 网段,且希望指定内网 DNS 服务器的 IPv6 ULA 地址时,需要调整 `Cloud-Init` 参数。
本文 ULA IPv6 演示地址为 `fdac::/64` `DNS服务器``IP配置` 参数调整如下。
本文 IPv6 ULA 演示地址为 `fdac::/64` `DNS服务器``IP配置` 参数调整如下。
|参数|值|说明|
|--|--|--|
|DNS服务器|`172.16.1.1 fdac::1 127.0.0.1`|本机DNS服务器,用空格隔开|
|DNS域|`fox.home.arpa`|内网域名(可选)|
|DNS服务器|`172.16.1.1 fdac::1`|本机 DNS 服务器|
|IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置|
`DNS服务器` 参数中需要加入主路由 LAN 口 ULA IPv6 地址。
`DNS服务器` 参数中需要加入主路由 LAN 口 IPv6 ULA 地址。
![CI网络配置](img/p04/vm_ci_dns_ula.jpeg)
@@ -258,5 +245,28 @@ IPv6 使用静态地址后,并不影响虚拟机通过主路由获取公网 GU
![CI网络配置](img/p04/vm_ci_network_static.jpeg)
## 5.设置备注信息
进入左侧虚拟机 `概要` 页面,修改虚拟机的备注信息。
```bash
### 服务器信息
- 系统: Debian12
- 用途: 内网 DNS 服务器 ( 模板 )
- 自启: 否
- 用户: fox
- IPv4 172.16.1.250/24
- IPv6 SLAAC
```
![虚拟机备注](img/p04/vm_notes.jpeg)
至此,模板虚拟机创建完成,可将该虚拟机开机。
+61 -56
View File
@@ -21,8 +21,8 @@
- 保存文件,按下键盘 `Esc` 键,退出编辑模式,再输入组合键 `:wq` 即可保存。
```bash
## 编辑 ssh 配置文件
$ sudo vim /etc/ssh/sshd_config.d/server_sshd.conf
## 编辑 SSH 配置文件
$ sudo vim /etc/ssh/sshd_config.d/10-server-sshd.conf
```
在配置文件中添加以下配置项,并保存。
@@ -39,17 +39,17 @@ UseDNS no
修改完成后,需要重启 SSH 服务。
```bash
## 重启 sshd
## 重启 ssh.service
$ sudo systemctl restart ssh.service
```
### 1.2.配置软件源
使用 SSH 工具登录模板虚拟机,常用 SSH 工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。
使用终端工具登录模板虚拟机,常用终端工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。
首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](http://mirrors.ustc.edu.cn/help/debian.html) 镜像站作为演示。
首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](https://mirrors.ustc.edu.cn) 镜像站作为演示。
当系统版本发生变化时,请参考使用 snullp 大叔开发的 [配置生成器](https://mirrors.ustc.edu.cn/repogen/) 。
当系统版本发生变化时,请参考 USTC 镜像站的官方说明 [USTC Mirror Help - Debian](https://mirrors.ustc.edu.cn/help/debian.html) 。
Debian12 云镜像的软件源配置采用了 `DEB822` 格式,新版 `sources.list` 配置文件内容如下。
@@ -89,7 +89,6 @@ $ cat /etc/apt/mirrors/debian-security.list
#### 关联配置文件示例输出 (关联部分 2 )
https://deb.debian.org/debian-security
```
因此,修改 Debian12 软件源的方式也有两种,本文将尝试使用第 `2` 种修改方案。
@@ -112,13 +111,15 @@ $ sudo vim /etc/apt/sources.list.d/debian.sources
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian
Suites: bookworm bookworm-updates bookworm-backports
Suites: bookworm bookworm-updates
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian-security
Suites: bookworm-security
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
```
@@ -137,30 +138,30 @@ $ lsattr /etc/apt/sources.list.d/debian.sources
### 1.3.安装软件
软件源设置完成后,需要更新系统,逐行执行以下命令。
软件源设置完成后,需要更新系统,执行以下命令。
```bash
## 清理不必要的包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
$ sudo bash -c 'apt clean && apt autoclean && apt autoremove --purge'
## 更新软件源
$ sudo apt update
## 更新系统
$ sudo apt dist-upgrade
$ sudo apt full-upgrade
```
接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。
```bash
## 安装系统软件
$ sudo apt install qemu-guest-agent zsh git htop tmux cron nftables sshguard
$ sudo apt install qemu-guest-agent zsh git btop tmux cron nftables sshguard neovim
## 安装系统自动更新工具
$ sudo apt install unattended-upgrades powermgmt-base python3-gi
## 安装网络工具
$ sudo apt install iperf iperf3 iftop lsof ldnsutils
$ sudo apt install iperf iperf3 iftop lsof knot-dnsutils
## 写入磁盘
$ sudo sync
@@ -170,40 +171,48 @@ $ sudo sync
由于该 Debian 虚拟机模板将用于克隆内网 DNS 服务器,因此需要调整内核参数来简单优化性能。
使用 `vim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
使用 `neovim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
```bash
## 编辑 内核参数 配置文件
$ sudo vim /etc/sysctl.d/99-sysctl.conf
$ sudo nvim /etc/sysctl.d/99-sysctl.conf
```
在配置文件末尾输入以下配置项,注意配置中间的空格。
```bash
# This configuration file is customized by fox
# Optimize system parameters
# This configuration file is customized by fox,
# Optimize sysctl parameters for local DNS server.
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
net.ipv4.tcp_congestion_control = cubic
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.somaxconn = 8192
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 100
net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_max_orphans = 4096
net.ipv4.tcp_max_tw_buckets = 4096
net.ipv4.tcp_syncookies = 1
net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 16384 262144 8388608
net.ipv4.tcp_wmem = 32768 524288 16777216
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
```
保存该配置文件后,重启系统或者执行以下命令让配置生效。
@@ -215,7 +224,7 @@ $ sudo sysctl -f
### 1.5.调整系统时间
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
```bash
## 设置系统时区
@@ -230,23 +239,24 @@ Mon, 26 Jun 2023 16:16:16 +0800
Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。
调整 NTP 服务器参数,逐行执行以下命令。
调整 NTP 服务器参数,执行以下命令。
```bash
## 创建 NTP 配置文件的文件夹
$ sudo mkdir /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件的目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件
$ sudo vim /etc/systemd/timesyncd.conf.d/server_ntp.conf
$ sudo nvim /etc/systemd/timesyncd.conf.d/10-server-ntp.conf
```
在配置文件中添加以下配置项,并保存。
```bash
## NTP 配置项
# This configuration file is customized by fox,
# Optimize system NTP server.
[Time]
NTP=ntp.tencent.com ntp.aliyun.com
NTP=ntp.aliyun.com ntp.tencent.com cn.pool.ntp.org
```
@@ -266,20 +276,20 @@ $ sudo systemctl status systemd-timesyncd.service
#### NTP 服务示例输出
● systemd-timesyncd.service - Network Time Synchronization
Loaded: loaded (/lib/systemd/system/systemd-timesyncd.service; enabled; preset: enabled)
Active: active (running) since Mon 2023-06-26 16:16:00 CST; 16s ago
Active: active (running) since Mon 2024-10-07 18:06:29 CST; 9s ago
Docs: man:systemd-timesyncd.service(8)
Main PID: 18829 (systemd-timesyn)
Status: "Contacted time server 106.55.184.199:123 (ntp.tencent.com)."
Tasks: 2 (limit: 2355)
Main PID: 1706 (systemd-timesyn)
Status: "Contacted time server 203.107.6.88:123 (ntp.aliyun.com)."
Tasks: 2 (limit: 2315)
Memory: 1.4M
CPU: 37ms
CPU: 113ms
CGroup: /system.slice/systemd-timesyncd.service
└─18829 /lib/systemd/systemd-timesyncd
└─1706 /lib/systemd/systemd-timesyncd
Jun 26 16:48:00 DNST01 systemd[1]: Starting systemd-timesyncd.service - Network Time Synchronization...
Jun 26 16:48:00 DNST01 systemd[1]: Started systemd-timesyncd.service - Network Time Synchronization.
Jun 26 16:48:00 DNST01 systemd-timesyncd[18829]: Contacted time server 106.55.184.199:123 (ntp.tencent.com).
Jun 26 16:48:00 DNST01 systemd-timesyncd[18829]: Initial clock synchronization to Mon 2023-06-26 16:16:16.000000 CST.
Oct 07 18:06:29 DNS01 systemd[1]: Starting systemd-timesyncd.service - Network Time Synchronization...
Oct 07 18:06:29 DNS01 systemd[1]: Started systemd-timesyncd.service - Network Time Synchronization.
Oct 07 18:06:29 DNS01 systemd-timesyncd[1706]: Contacted time server 203.107.6.88:123 (ntp.aliyun.com).
Oct 07 18:06:29 DNS01 systemd-timesyncd[1706]: Initial clock synchronization to Mon 2024-10-07 18:06:29.499548 CST.
```
### 1.6.配置自动更新
@@ -305,11 +315,11 @@ $ sudo dpkg-reconfigure -plow unattended-upgrades
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
```
接下来调整 apt 的 `20auto-upgrades` 配置文件。
进一步调整 `20auto-upgrades` 配置文件。
```bash
## 编辑 20auto-upgrades 配置文件
$ sudo vim /etc/apt/apt.conf.d/20auto-upgrades
$ sudo nvim /etc/apt/apt.conf.d/20auto-upgrades
```
删除里面全部内容,添加以下配置项,并保存。
@@ -326,16 +336,16 @@ APT::Periodic::CleanInterval "1";
```
进一步调整 apt 的 `50unattended-upgrades` 配置文件。
进一步调整 `50unattended-upgrades` 配置文件。
```bash
## 编辑 50unattended-upgrades 配置文件
$ sudo vim /etc/apt/apt.conf.d/50unattended-upgrades
$ sudo nvim /etc/apt/apt.conf.d/50unattended-upgrades
```
根据 “注释” 中相关说明,调整配置文件。
因为该配置文件很长,完整的配置文件可查看 [debian_50unattended_upgrades.conf](./src/debian_50unattended_upgrades.conf) 以便对比。
因为该配置文件很长,完整的配置文件可查看 [debian_dns_50unattended_upgrades.conf](./src/debian/debian_dns_50unattended_upgrades.conf) 以便对比。
```bash
## 删除以下行前面的注释符 // ,代表启用
@@ -354,7 +364,7 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:30";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
```
@@ -379,7 +389,7 @@ RandomizedDelaySec=0
设置完成后,重启自动更新定时器并检查其状态,执行以下命令。
在输出结果中看到系统自动更新的触发时间为凌晨 `02:00` 则表示设置正确。
在输出结果中看到系统自动更新的触发时间为 `02:00` 则表示设置正确。
```bash
## 重启触发器
@@ -406,7 +416,7 @@ $ sudo crontab -e
```bash
## 定时任务配置项
0 6 8,24 * * /usr/sbin/reboot
30 4 8,24 * * /usr/sbin/reboot
```
@@ -435,23 +445,18 @@ Do you want to change your default shell to zsh? [Y/n] y
Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。
逐条执行以下命令,注意命令中的空格。
```bash
## 清理系统软件包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
$ sudo bash -c 'apt clean && apt autoclean && apt autoremove --purge'
## 清理系统缓存
$ sudo rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
$ sudo bash -c 'find /var/cache/apt /var/cache/smartdns /var/lib/apt/lists /tmp -type f -print -delete'
## 清理系统日志
$ sudo find /var/log/ -type f | xargs sudo rm -rvf
$ sudo find /var/log/ -type f -print -delete
## 清理命令历史记录文件
$ rm -rvf ~/.bash_history ~/.zsh_history
## 清理命令历史
$ history -c
$ rm -rvf ~/.bash_history ~/.zsh_history ~/.zcompdump* && history -c
## 关闭系统
$ sudo shutdown now
+479
View File
@@ -0,0 +1,479 @@
## 1.克隆虚拟机
在上一篇文章 [05.PVE制作虚拟机模板](./05.PVE制作虚拟机模板.md) 中,已经制作好了虚拟机模板。
接下来将使用该模板克隆出新的虚拟机,并安装 Adguard Home 作为内网的 DNS 服务器。
鼠标 **右键单击** 虚拟机模板,在弹出的菜单中选择 `克隆`
![克隆虚拟机](img/p06/vm_clone.jpeg)
在弹出的虚拟机克隆对话框中,根据实际情况及下方表格内容,修改虚拟机参数。
|参数|值|说明|
|--|--|--|
|目标节点|`node01`|当前 PVE 服务器节点|
|VM ID|`201`|可自定义,不能与现存虚拟机 `VM ID` 相同|
|名称|`DNS01`|可自定义,`Cloud-Init` 将使用该名称作为虚拟机 `hostname` |
|模式|`完整克隆`|选择虚拟机的克隆模式|
|目标存储|`local-lvm`|克隆出的虚拟机文件存储位置|
修改参数后,点击 `克隆` ,即可使用该模板克隆出新的虚拟机。
![克隆虚拟机参数](img/p06/vm_clone_vmid.jpeg)
## 2.调整 Cloud-Init
克隆出来的虚拟机的 `Cloud-Init` 参数默认与模板完全一致。
根据 **内部网络地址** 规划,内网 DNS 服务器 IPv4 地址规划如下:
- `172.16.1.2/24`
- `172.16.1.3/24`
因此需要调整新虚拟机的 `Cloud-Init` 参数。
- `IP配置` 中的 IPv4 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变。
- `IP配置` 中的 IPv6 地址参数为 `auto` ,网关保持为空。
需要注意的是,如果修改了 `用户` 参数,相当于新建了一个系统管理员,之前设置的 `oh-my-zsh` 需要在新管理员下重新设置。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_slaac.jpeg)
当主路由配置了 IPv6 ULA 网段,内网 DNS 服务器 IPv6 ULA 地址规划如下:
- `fdac::2/64`
- `fdac::3/64`
此时需进一步调整新虚拟机的 `Cloud-Init` 参数,让该虚拟机使用指定的 IPv6 ULA 地址,参数如下。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_static.jpeg)
## 3.调整配置参数
在 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) 中提到过,新虚拟机需要修改配置参数才能自动启动。
进入左侧虚拟机 `选项` 页面,将虚拟机 `开机自启动` 参数设置为 `是`
![克隆虚拟机自动启动](img/p06/vm_clone_autostart.jpeg)
鼠标 **双击** `启动/关机顺序` 选项,可调整虚拟机的自动开机参数。
`启动/关机顺序``2` ,表示该虚拟机第 `2` 个启动,倒数第 `2` 个关机。
`启动延时``10` ,表示该虚拟机启动后,延迟 `10` 秒再启动下一个虚拟机。
![克隆虚拟机自动启动顺序](img/p06/vm_clone_autostart_order.jpeg)
## 4.调整系统端口
设置完成后,将该虚拟机开机,使用终端工具登录,并执行以下命令检查端口占用。
```bash
## 检查 53 端口占用
$ sudo lsof -n -i :53
#### 端口占用示例输出
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
systemd-r 1797 systemd-resolve 18u IPv4 23024 0t0 UDP 127.0.0.53:domain
systemd-r 1797 systemd-resolve 19u IPv4 23025 0t0 TCP 127.0.0.53:domain (LISTEN)
systemd-r 1797 systemd-resolve 20u IPv4 23026 0t0 UDP 127.0.0.54:domain
systemd-r 1797 systemd-resolve 21u IPv4 23027 0t0 TCP 127.0.0.54:domain (LISTEN)
```
当前系统 `53` 端口被 `systemd-resolved.service` 占用,会导致设置 DNS 服务时监听端口失败。
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
```bash
## 创建 systemd-resolved 配置目录
$ sudo mkdir -p /etc/systemd/resolved.conf.d
## 创建 systemd-resolved 配置文件
$ sudo nvim /etc/systemd/resolved.conf.d/10-server-dns.conf
```
在配置文件中添加以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize system resolve parameters for local DNS server.
[Resolve]
DNS=127.0.0.1
DNS=::1
DNSStubListener=no
```
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,执行以下命令。
```bash
## 创建 resolv.conf 软链接
$ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
```
配置完成后,需重启 `systemd-resolved.service` 服务,并再次检查系统 `53` 端口占用。
```bash
## 重启 systemd-resolved.service
$ sudo systemctl restart systemd-resolved.service
```
## 5. Adguard Home
`Adguard Home` 将采用 `snap` 形式安装,执行以下命令。
```bash
## 安装 Snap
$ sudo apt install snapd
## 安装 Adguard Home
$ sudo snap install adguard-home
```
### 5.1.自动更新
查看 `Snap` 当前的更新策略,执行以下命令。
```bash
## 显示当前 Snap 自动更新设置
$ sudo snap refresh --time
```
`Snap` 自动更新时间设置为每天 `2:30-3:30``14:30-15:30` 两个时间段。
```bash
## 修改 Snap 自动更新时间
$ sudo snap set system refresh.timer=2:30-3:30,14:30-15:30
## 其他 Snap 自动更新时间设置语法参考
$ sudo snap set system refresh.timer=mon,2:30,,fri,2:30
```
### 5.2.配置 Adguard Home
关于 `Adguard Home` 配置相关内容,请参阅 [Adguard Home 折腾手记](https://gitee.com/callmer/agh_toss_notes) 。
### 5.3.定时任务
本步骤为可选操作,主要用于设置 `Adguard Home` 定时重启。
```bash
## 查看系统定时任务
$ sudo crontab -l
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
30 4 * * * /usr/bin/snap restart adguard-home
```
## 6. SmartDNS
若需使用 `SmartDNS` 代替 `Adguard Home` ,可使用 Debian 官方源进行安装,但其版本通常较为 “过时” 。
因此,更推荐使用其 Github 仓库中的最新稳定版进行安装,官方仓库请参阅 [pymumu/smartdns](https://github.com/pymumu/smartdns/releases) 。
多数情况下,`SmartDNS` 足以提供良好的 DNS 解析服务,但为了进一步优化 DNS 解析流程,推荐与 `Dnsmasq` 嵌套使用。
```bash
## 安装 Dnsmasq
$ sudo apt install dnsmasq
```
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
```bash
## 检查 dnsmasq.service
$ sudo systemctl status dnsmasq.service
## 设置 dnsmasq.service 开机自启
$ sudo systemctl enable dnsmasq.service
## 停止 dnsmasq.service
$ sudo systemctl stop dnsmasq.service
```
下载 `SmartDNS` 最新版本时,请根据系统架构选择合适的版本,执行以下命令。
```bash
## 创建存放 SmartDNS 安装包的临时目录
$ mkdir -p /tmp/SmartDNS
## 进入目录
$ cd /tmp/SmartDNS
## 下载 SmartDNS 安装包
$ curl -LR -O https://github.com/pymumu/smartdns/releases/download/Release46/smartdns.1.2024.06.12-2222.x86_64-linux-all.tar.gz
## 解压缩 SmartDNS 安装包
$ tar zxf smartdns.1.2024.06.12-2222.x86_64-linux-all.tar.gz
## 进入安装包目录
$ cd smartdns
## 设置脚本可执行权限
$ chmod +x ./install
## 安装 SmartDNS
$ sudo ./install -i
```
修改 `SmartDNS` 配置之前,需检查 `smartdns.service` 服务状态,确保该服务开机自启。
```bash
## 检查 smartdns.service
$ sudo systemctl status smartdns.service
## 设置 smartdns.service 开机自启
$ sudo systemctl enable smartdns.service
```
### 6.1. SmartDNS 附加配置
本步骤为可选操作,通过安装 `SmartDNS` 附加配置文件,以达到屏蔽广告或加速中国境内域名解析速度的目的。
若需使用 `SmartDNS` 屏蔽广告,则需下载广告规则配置文件。
```bash
## 创建 SmartDNS 配置文件目录
$ sudo mkdir -p /etc/smartdns.d
## 下载广告规则配置文件
$ sudo curl -LR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
```
`SmartDNS` 的加速规则通过 `bash` 脚本安装,脚本生成的配置文件位于 `/etc/smartdns.d` 目录。
关于脚本的详细介绍,请参阅 [SmartDNS China List 安装脚本](https://gitee.com/callmer/smartdns_china_list_installer) 。
```bash
## 下载加速规则安装脚本
$ sudo curl -LR -o /opt/smartdns-plugin.sh https://gitee.com/callmer/smartdns_china_list_installer/raw/main/smartdns_plugin.sh
## 设置脚本可执行权限
$ sudo chmod +x /opt/smartdns-plugin.sh
## 设置脚本文件防篡改
$ sudo chattr +i /opt/smartdns-plugin.sh
## 执行脚本
$ sudo bash /opt/smartdns-plugin.sh
```
### 6.2. SmartDNS 主配置
`SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/) 。
修改 `SmartDNS` 主配置文件之前,建议关闭 `SmartDNS` 并清理 DNS 缓存文件。
```bash
## 关闭 smartdns.service
$ sudo systemctl stop smartdns.service
## 清理缓存
$ sudo rm -rvf /var/cache/smartdns*
## 清理进程标识文件
$ sudo rm -rvf /var/run/smartdns.pid /run/smartdns.pid
```
`SmartDNS` 的主配置文件一般位于 `/etc/smartdns` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 SmartDNS 主配置文件
$ sudo mv /etc/smartdns/smartdns.conf /etc/smartdns/smartdns.conf.bak
```
使用 `neovim` 编辑器创建 `SmartDNS` 主配置文件,执行以下命令。
```bash
## 创建 SmartDNS 主配置文件
$ sudo nvim /etc/smartdns/smartdns.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 由于修改了缓存路径,`SmartDNS` 的缓存将在系统重启时自动删除,请根据实际情况进行调整
- `SmartDNS` 端口监听参数为 `6053@lo` ,请根据实际情况进行调整
- 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整
```bash
# This configuration file is customized by fox,
# Optimize SmartDNS parameters for local DNS server.
#
# For use common DNS server as upstream DNS server,
# please modify 'server' parameter according to
# your network environment.
#
# eg:
# server 223.5.5.5
# server 180.184.1.1
# server 119.29.29.29
# server 114.114.114.114
# server 2402:4e00::
# server 2400:3200::1
conf-file /etc/smartdns.d/*.conf
log-level notice
bind [::]:6053@lo
bind-tcp [::]:6053@lo
cache-size 32768
max-query-limit 1024
max-reply-ip-num 24
prefetch-domain yes
serve-expired yes
serve-expired-ttl 129600
serve-expired-reply-ttl 30
serve-expired-prefetch-time 28800
rr-ttl-min 60
rr-ttl-max 28800
rr-ttl-reply-max 14400
server 172.16.1.1 -group intranet -exclude-default-group
nameserver /fox.home.arpa/intranet
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
server-tcp 180.184.2.2 -bootstrap-dns
server-tcp 114.114.115.115 -bootstrap-dns
server-tcp 2400:3200:baba::1 -bootstrap-dns
server-tcp 2400:7fc0:849e:200::4 -bootstrap-dns
server-tls dot.pub
server-tls dns.alidns.com
server-https https://doh.pub/dns-query
server-https https://dns.alidns.com/dns-query
```
### 6.3.定时任务
本步骤为可选操作,主要用于设置 `SmartDNS` 定时更新附加配置文件和定时重启。
```bash
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
30 9 * * * /usr/bin/systemctl restart smartdns.service
```
若使用了 `SmartDNS` 加速规则的安装脚本,由于脚本自带服务重启功能,因此定时任务可修改如下。
```bash
## 定时任务配置项
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
30 9 * * * /usr/bin/bash /opt/smartdns-plugin.sh
```
### 6.4.配置 Dnsmasq
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 Dnsmasq 主配置文件
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash
## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
- `Dnsmasq` 有且仅有 `SmartDNS` 作为上游 DNS 服务器
```bash
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local DNS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=7200
fast-dns-retry=1800
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-negcache
no-resolv
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/lan/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/fox.home.arpa/172.16.1.1
server=127.0.0.1#6053
server=::1#6053
```
至此,新虚拟机已配置完成,重启后即可作为内网 DNS 服务器使用。
-125
View File
@@ -1,125 +0,0 @@
## 1.克隆虚拟机
在上一篇文章 [05.PVE制作虚拟机模板](./05.PVE制作虚拟机模板.md) 中,已经制作好了虚拟机模板。
接下来将使用该模板克隆出新的虚拟机,并安装 Adguard Home 作为内网的 DNS 服务器。
鼠标 **右键单击** 虚拟机模板,在弹出的菜单中选择 `克隆`
![克隆虚拟机](img/p06/vm_clone.jpeg)
在弹出的虚拟机克隆对话框中,根据实际情况及下方表格内容,修改虚拟机参数。
|参数|值|说明|
|--|--|--|
|目标节点|`node01`|当前 PVE 服务器节点|
|VM ID|`201`|可自定义,不能与现存虚拟机 `VM ID` 相同|
|名称|`DNS01`|可自定义,`Cloud-Init` 将使用该名称作为虚拟机 `hostname` |
|模式|`完整克隆`|选择虚拟机的克隆模式|
|目标存储|`local-lvm`|克隆出的虚拟机文件存储位置|
修改参数后,点击 `克隆` ,即可使用该模板克隆出新的虚拟机。
![克隆虚拟机参数](img/p06/vm_clone_vmid.jpeg)
## 2.调整 Cloud-Init
克隆出来的虚拟机的 `Cloud-Init` 参数默认与模板完全一致。
根据 **内部网络地址** 规划,内网 DNS 服务器 IP 地址分别为:
- `172.16.1.2/24 (fdac::2/64)`
- `172.16.1.3/24 (fdac::3/64)`
因此需要调整新虚拟机的 `Cloud-Init` 参数。
- `IP配置` 中的 IPv4 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变。
- `IP配置` 中的 IPv6 地址参数为 `fdac::2/64` ,网关保持为空。
需要注意的是,如果修改了 `用户` 参数,相当于新建了一个系统管理员,之前设置的 `oh-my-zsh` 需要在新管理员下重新设置。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_slaac.jpeg)
当主路由配置了 ULA IPv6 网段,且指定了内网 DNS 服务器的 ULA IPv6 地址时,参数如下。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_static.jpeg)
## 3.调整配置参数
在 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) 中提到过,新虚拟机需要修改配置参数才能自动启动。
进入左侧虚拟机 `选项` 页面,将虚拟机 `开机自启动` 参数设置为 `是`
![克隆虚拟机自动启动](img/p06/vm_clone_autostart.jpeg)
鼠标 **双击** `启动/关机顺序` 选项,可调整虚拟机的自动开机参数。
`启动/关机顺序``2` ,表示该虚拟机第 `2` 个启动,倒数第 `2` 个关机。
`启动延时``10` ,表示该虚拟机在 PVE 启动后,延迟 `10` 秒后自动启动。
![克隆虚拟机自动启动顺序](img/p06/vm_clone_autostart_order.jpeg)
## 4.安装 Adguard Home
设置完成后,将该虚拟机开机,并使用 SSH 工具登录。
Adguard Home 将采用 `snap` 形式安装,逐行执行以下命令。
```bash
## 安装 snap
$ sudo apt install snapd
## 安装 Adguard Home
$ sudo snap install adguard-home
```
### 4.1. Snap 自动更新
查看 Snap 当前的更新策略,执行以下命令。
```bash
## 显示当前 Snap 自动更新设置
$ sudo snap refresh --time
```
将 Snap 自动更新时间设置为每天 `2:30-3:30``14:30-15:30` 两个时间段。
```bash
## 修改 Snap 自动更新时间
$ sudo snap set system refresh.timer=2:30-3:30,14:30-15:30
## 其他 Snap 自动更新时间设置语法参考
$ sudo snap set system refresh.timer=mon,2:30,,fri,2:30
```
### 4.2. Snap 定时任务
本步骤为可选操作,主要设置定时重启 Snap 服务。
```bash
## 查看系统定时任务
$ sudo crontab -l
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
0 5 * * * /usr/bin/snap restart adguard-home
```
## 5.配置 Adguard Home
关于 Adguard Home 配置相关内容,请参阅 [Adguard Home 折腾手记](https://gitee.com/callmer/agh_toss_notes) 。
至此,新虚拟机已配置完成,可作为内网 DNS 服务器使用。
+632
View File
@@ -0,0 +1,632 @@
## 0.前期准备
某些业务场景下需要构建安全可靠的网络隧道,来打通异地内网环境或从外部访问内网的私有资源。
经过实际测试,当 TS 服务器具有 IPv6 GUA 地址时,能稳定建立隧道。
本文将使用 Debian 云镜像以及 `Tailscale` 来制作内网组网服务器。
对于虚拟机创建部分,请参考 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) ,其他 `Cloud-Init` 相关参数如下。
|参数|值|说明|
|--|--|--|
|虚拟机名称|`SVR01`| TS 服务器 `主机名` |
|DNS 域|`fox.home.arpa`| TS 服务器 `Cloud-Init` |
|DNS 服务器|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|IPv4|`172.16.1.4/24`| TS 服务器 `Cloud-Init` |
|IPv4 网关|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|IPv6|`SLAAC`| TS 服务器 `Cloud-Init` |
## 1.配置系统
由于 TS 服务器具备路由功能,所以在配置方法和系统参数方面与内网 DNS 服务器有一些区别。
### 1.1.配置 SSH
与配置内网 DNS 服务器时一样,首先需要调整系统的 SSH 登录权限参数。
在虚拟机的命令行界面,使用 `vim` 编辑器编辑 `sshd` 服务的配置文件,执行以下命令。
```bash
## 编辑 SSH 配置文件
$ sudo vim /etc/ssh/sshd_config.d/10-server-sshd.conf
```
在配置文件中添加以下配置项,并保存。
```bash
## SSH 配置项
PasswordAuthentication yes
PermitEmptyPasswords no
UseDNS no
```
修改完成后,需要重启 SSH 服务。
```bash
## 重启 ssh.service
$ sudo systemctl restart ssh.service
```
### 1.2.配置软件源
使用终端工具登录 TS 服务器,常用终端工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。
首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](https://mirrors.ustc.edu.cn) 镜像站作为演示。
当系统版本发生变化时,请参考 USTC 镜像站的官方说明 [USTC Mirror Help - Debian](https://mirrors.ustc.edu.cn/help/debian.html) 。
使用 `vim` 编辑器编辑 `debian.sources` 配置文件,执行以下命令。
```bash
## 编辑 debian.sources 配置文件
$ sudo vim /etc/apt/sources.list.d/debian.sources
```
删除里面全部内容,添加以下配置项,并保存。
```bash
## 系统软件源配置项
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian
Suites: bookworm bookworm-updates
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian-security
Suites: bookworm-security
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
```
为了防止 `Cloud-Init` 服务意外修改软件源配置,需要添加文件保护,执行以下命令。
```bash
## 增加文件保护
$ sudo chattr +i /etc/apt/sources.list.d/debian.sources
## 检查文件保护
$ lsattr /etc/apt/sources.list.d/debian.sources
#### 示例输出
----i---------e------- /etc/apt/sources.list.d/debian.sources
```
进一步添加 TS 签名密钥以及软件源,执行以下命令。
```bash
## 添加 TS 签名密钥
$ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.noarmor.gpg | sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg > /dev/null
## 添加 TS 软件源
$ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.tailscale-keyring.list | sudo tee /etc/apt/sources.list.d/tailscale.list
```
### 1.3.安装软件
软件源设置完成后,需要更新系统,执行以下命令。
```bash
## 清理不必要的包
$ sudo bash -c 'apt clean && apt autoclean && apt autoremove --purge'
## 更新软件源
$ sudo apt update
## 更新系统
$ sudo apt full-upgrade
```
接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。
```bash
## 安装系统软件
$ sudo apt install qemu-guest-agent zsh git btop tmux cron nftables sshguard neovim
## 安装系统自动更新工具
$ sudo apt install unattended-upgrades powermgmt-base python3-gi
## 安装网络工具
$ sudo apt install iperf iperf3 iftop lsof knot-dnsutils dnsmasq conntrack
## 安装 TS
$ sudo apt install tailscale
## 写入磁盘
$ sudo sync
```
### 1.4.调整内核模块
使用 `neovim` 编辑器编辑 **内核模块** 配置文件,执行以下命令。
```bash
## 创建 内核模块 配置文件
$ sudo nvim /etc/modules-load.d/10-server-modules.conf
```
在配置文件中添加以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize netfilter related modules at system boot.
nf_conntrack
```
### 1.5.调整内核参数
使用 `neovim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
```bash
## 编辑 内核参数 配置文件
$ sudo nvim /etc/sysctl.d/99-sysctl.conf
```
在配置文件末尾输入以下配置项,注意配置中间的空格。
```bash
# This configuration file is customized by fox,
# Optimize sysctl parameters for local TS server.
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
net.ipv4.ip_forward = 1
net.ipv6.conf.all.forwarding = 1
net.ipv6.conf.default.forwarding = 1
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768
net.core.somaxconn = 8192
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.all.arp_ignore = 1
net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 256
net.ipv4.route.error_burst = 500
net.ipv4.route.error_cost = 100
net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 16384 262144 8388608
net.ipv4.tcp_wmem = 32768 524288 16777216
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
net.ipv6.conf.all.accept_source_route = 0
net.ipv6.conf.default.accept_source_route = 0
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
net.netfilter.nf_conntrack_acct = 1
net.netfilter.nf_conntrack_checksum = 0
net.netfilter.nf_conntrack_tcp_timeout_established = 7440
```
保存该配置文件后,重启系统或者执行以下命令让配置生效。
```bash
## 让内核参数生效
$ sudo sysctl -f
```
### 1.6.调整系统时间
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
```bash
## 设置系统时区
$ sudo timedatectl set-timezone Asia/Shanghai
## 检查系统时间
$ date -R
```
Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。
调整 NTP 服务器参数,执行以下命令。
```bash
## 创建 NTP 配置文件的目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件
$ sudo nvim /etc/systemd/timesyncd.conf.d/10-server-ntp.conf
```
在配置文件中添加以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize system NTP server.
[Time]
NTP=ntp.aliyun.com ntp.tencent.com cn.pool.ntp.org
```
保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。
```bash
## 重启 chrony 服务
$ sudo systemctl restart systemd-timesyncd.service
## 检查系统 NTP 服务器
$ sudo systemctl status systemd-timesyncd.service
```
### 1.7.配置自动更新
配置系统自动更新策略,执行以下命令,使用键盘 `左右方向键` 进行选择,`回车键` 进行确认。
```bash
## 配置自动更新策略
$ sudo dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”)
#### 系统自动更新示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
```
进一步调整 `20auto-upgrades` 配置文件。
```bash
## 编辑 20auto-upgrades 配置文件
$ sudo nvim /etc/apt/apt.conf.d/20auto-upgrades
```
删除里面全部内容,添加以下配置项,并保存。
配置文件中,用来控制更新周期的参数为 `APT::Periodic::Unattended-Upgrade` `7` 表示更新周期为 `7` 天。
```bash
## 系统更新周期配置项
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "7";
APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1";
```
进一步调整 `50unattended-upgrades` 配置文件。
```bash
## 编辑 50unattended-upgrades 配置文件
$ sudo nvim /etc/apt/apt.conf.d/50unattended-upgrades
```
根据 “注释” 中相关说明,调整配置文件。
因为该配置文件很长,完整的配置文件可查看 [debian_ts_50unattended_upgrades.conf](./src/debian/debian_ts_50unattended_upgrades.conf) 以便对比。
```bash
## 删除以下行前面的注释符 // ,代表启用
"origin=Debian,codename=${distro_codename}-updates";
## 添加 TS 更新项目
"origin=Tailscale,codename=${distro_codename},label=Tailscale";
## 在配置文件末尾增加以下配置项,代表启用,并调整参数
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
```
系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。
```bash
## 配置系统定时器
$ sudo systemctl edit apt-daily-upgrade.timer
```
根据配置文件中的提示,在中间空白处填入以下配置项。
```bash
## 定时器配置项
[Timer]
OnCalendar=
OnCalendar=02:00
RandomizedDelaySec=0
```
设置完成后,重启自动更新定时器并检查其状态,执行以下命令。
在输出结果中,看到系统自动更新的触发时间为 `02:00` 则表示设置正确。
```bash
## 重启触发器
$ sudo systemctl restart apt-daily-upgrade.timer
## 再次检查触发器状态
$ sudo systemctl status apt-daily-upgrade.timer
```
### 1.8.配置防火墙
修改防火墙配置之前,需检查 `nftables.service` 服务状态,确保该服务开机自启。
```bash
## 检查 nftables.service
$ sudo systemctl status nftables.service
## 设置 nftables.service 开机自启
$ sudo systemctl enable nftables.service
```
使用 `neovim` 编辑器修改 `nftables` 配置文件,执行以下命令。
```bash
## 备份 nftables 配置文件
$ sudo mv /etc/nftables.conf /etc/nftables.conf.bak
## 创建新的 nftables 配置文件
$ sudo nvim /etc/nftables.conf
```
由于防火墙配置文件很长,因此请查阅文件 [debian_ts_nftables.conf](./src/debian/debian_ts_nftables.conf) 进行复制。
配置完成后,需重启 `nftables.service` 服务。
```bash
## 重启 nftables.service
$ sudo systemctl restart nftables.service
```
### 1.9.调整系统端口
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
```bash
## 创建 systemd-resolved 配置目录
$ sudo mkdir -p /etc/systemd/resolved.conf.d
## 创建 systemd-resolved 配置文件
$ sudo nvim /etc/systemd/resolved.conf.d/10-server-dns.conf
```
在配置文件中添加以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize system resolve parameters for local TS server.
[Resolve]
DNS=127.0.0.1
DNS=::1
DNSStubListener=no
```
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,执行以下命令。
```bash
## 创建 resolv.conf 软链接
$ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
```
配置完成后,需重启 `systemd-resolved.service` 服务。
```bash
## 重启 systemd-resolved.service
$ sudo systemctl restart systemd-resolved.service
```
### 1.10.配置 Dnsmasq
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
```bash
## 检查 dnsmasq.service
$ sudo systemctl status dnsmasq.service
## 设置 dnsmasq.service 开机自启
$ sudo systemctl enable dnsmasq.service
```
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 Dnsmasq 主配置文件
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash
## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
- `Dnsmasq` 上游 DNS 服务器分为三类,请根据实际情况进行调整
- `server=/ts.net/100.100.100.100` TS 服务 `MagicDNS` 专用 DNS 服务器
- `server=/fox.home.arpa/172.16.1.1` :内网域名解析 DNS 服务器,通常为主路由地址
- `server` 参数中的其他 DNS 服务器供 TS 服务器自身及其下游设备使用
```bash
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local TS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=7200
fast-dns-retry=1800
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-negcache
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/lan/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1
server=172.16.1.1
```
配置完成后,需重启 `dnsmasq.service` 服务。
```bash
## 重启 dnsmasq.service
$ sudo systemctl restart dnsmasq.service
```
### 1.11.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 返回 home 目录
$ cd
## 使用 curl 安装 oh-my-zsh
$ sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)"
## 或者使用 wget 安装 oh-my-zsh
$ sh -c "$(wget https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh -O -)"
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
```
## 2.配置 Tailscale
根据不同的启动参数,TS 服务将具有不同的业务能力。
若仅需 TS 组网功能,执行以下命令。
```bash
## TS 普通组网模式
$ sudo tailscale up
```
若需 TS 提供 `Exit Node` 功能,执行以下命令。
```bash
## TS Exit Node 模式
$ sudo tailscale up --advertise-exit-node --reset
## TS Exit Node 模式,但不使用 MagicDNS
$ sudo tailscale up --advertise-exit-node --accept-dns=false --reset
```
若需 TS 提供内网路由功能并能访问内网私有服务,执行以下命令。
**额外说明:**
- 请根据内网网段,调整 TS 内网路由参数 `advertise-routes`
```bash
## TS 内网路由模式
$ sudo tailscale up --advertise-exit-node --accept-routes --advertise-routes=172.16.1.0/24 --reset
```
执行命令后,TS 将自动显示登录链接,只需根据链接进行登录操作即可。
目前 TS 将跟随系统自动更新,若需额外开启 TS 的自动更新功能,执行以下命令。
```bash
## TS 开启自动更新
$ sudo tailscale set --auto-update
## TS 关闭自动更新
$ sudo tailscale set --auto-update=false
```
至此,TS 服务器已配置完成。
@@ -6,7 +6,7 @@
点击顶部 `添加` 按钮,添加一个 `备份作业`
![添加备份作业](img/p07/vm_new_backup_job.jpeg)
![添加备份作业](img/p08/vm_new_backup_job.jpeg)
### 1.1.常规选项
@@ -18,17 +18,17 @@
|存储|`local`|选择存放备份文件的路径|
|计划|`*-01,16 03:30`|`备份作业` 执行的时间计划|
|选择模式|`包括选中的VMs`|执行备份的虚拟机对象|
|通知模式|`默认(自动)`|执行备份时的通知模式,保持默认即可|
|发送邮箱至|`your_email@domain.com`|`备份作业` 邮件的收件人邮箱|
|电子邮件|`始终通知`|何时发送 `备份作业` 邮件提醒|
|发送邮件|`总是`|发送 `备份作业` 邮件提醒的条件|
|压缩|`ZSTD`|选择备份文件的压缩算法|
|模式|`停止`|选择备份虚拟机的方式,推荐使用 `停止` |
|启用|**勾选**|表示该 `备份作业` 为启用状态|
|作业评论|`Backup Your Server :)`|`备份作业` 的备注信息,使用英文输入|
|重复错过|**勾选**|表示当意外错过备份执行时间后,将重试备份|
**额外说明:**
1. 计划中的 `*-01,16 03:30` 表示每个月的 1、16 日凌晨 03:30行备份。
1. 计划中的 `*-01,16 03:30` 表示每`1``16` 号的 `03:30`行备份任务
2. `备份作业` 在正确配置收件人邮箱之前,并不能发出邮件。
@@ -36,15 +36,15 @@
4. 虚拟机列表中,勾选 `备份作业` 需要备份的虚拟机(可多选)。
![备份作业常规选项](img/p07/vm_job_normal.jpeg)
![备份作业常规选项](img/p08/vm_job_normal.jpeg)
### 1.2.保留选项
该选项将控制备份文件的保留个数,选择保留最近 `3` 份备份文件。
![备份作业保留选项](img/p07/vm_job_keep.jpeg)
![备份作业保留选项](img/p08/vm_job_keep.jpeg)
### 1.3.日志模板
### 1.3.备注模板
该选项将按照设置的内容,自动重命名备份文件。
@@ -52,7 +52,13 @@
点击 `创建` 按钮,`备份作业` 创建完成。
![备份作业备注选项](img/p07/vm_job_notes.jpeg)
![备份作业备注选项](img/p08/vm_job_notes.jpeg)
### 1.4.高级选项
该选项提供 `备份作业` 进行时的高级可调参数,仅需勾选 `重复错过` 选项即可。
![备份作业高级选项](img/p08/vm_job_advanced.jpeg)
## 2.调度模拟器
@@ -60,13 +66,13 @@
鼠标 **单击** 选中一个 `备份作业` ,点击右上角的 `调度模拟器`
![备份作业调度模拟器](img/p07/vm_job_time_test.jpeg)
![备份作业调度模拟器](img/p08/vm_job_time_test.jpeg)
`计划` 处将显示 `备份作业` 的执行时间参数,点击 `模拟` 按钮,在右侧将显示模拟的时间结果。
确认 `备份作业` 的执行时间周期是否符合预期。
![备份作业时间模拟](img/p07/vm_job_time.jpeg)
![备份作业时间模拟](img/p08/vm_job_time.jpeg)
至此,虚拟机的自动备份已配置完成。
+19 -19
View File
@@ -3,13 +3,13 @@
## 介绍
PVE 虚拟化平台的安装以及折腾手记。
- PVE ISO 版本:8.0-2 (更新时间: 2023-06-22)
- PVE ISO 版本:8.3-1 (更新时间: 2024-11-21)
- 演示机:
- CPU英特尔奔腾 Silver N6005 处理器
- 内存:16 GB
- 网卡:英特尔以太网控制器 I226-V
- 硬盘:500 GB NVMe 固态硬盘
- CPUN6005
- 内存:16GB DDR4
- 网卡:I226-V
- 硬盘:500GB NVMe
- PVE 网络:
- IPv4 网络
@@ -18,23 +18,23 @@ PVE 虚拟化平台的安装以及折腾手记。
- 网关:`172.16.1.1`
- DNS`172.16.1.1`
- IPv6 网络
- 前缀:`fdac::/64`
- IP 地址:`fdac::fe`
- DNS`fdac::1`
- 首选 `SLAAC` 自动配置
- IPv6 ULA 网络使用 `fdac::/64` 作为演示
### 系列章节
0. [硬件 BIOS 配置](./00.硬件BIOS配置.md)
1. [PVE 系统安装](./01.PVE系统安装.md)
2. [PVE 初始化配置](./02.PVE初始化配置.md)
3. [PVE 系统调整](./03.PVE系统调整.md)
4. [PVE 创建模板虚拟机](./04.PVE创建模板虚拟机.md)
5. [PVE 制作虚拟机模板](./05.PVE制作虚拟机模板.md)
6. [PVE 用模板克隆虚拟机](./06.PVE用模板克隆虚拟机.md)
7. [PVE 自动备份虚拟机](./07.PVE自动备份虚拟机.md)
0. [硬件 BIOS 配置](./00.硬件BIOS配置.md)
1. [PVE 系统安装](./01.PVE系统安装.md)
2. [PVE 初始化配置](./02.PVE初始化配置.md)
3. [PVE 系统调整](./03.PVE系统调整.md)
4. [PVE 创建模板虚拟机](./04.PVE创建模板虚拟机.md)
5. [PVE 制作虚拟机模板](./05.PVE制作虚拟机模板.md)
6. [PVE 制作 DNS 服务器](./06.PVE制作DNS服务器.md)
7. [PVE 制作 TS 服务器](./07.PVE制作TS服务器.md)
8. [PVE 自动备份虚拟机](./08.PVE自动备份虚拟机.md)
### 文章说明
1. 本系列文章涉及的部分参数需要手动调整来符合切实使用需求。
2. 随着 PVE 系统的迭代更新,截图中的内容和实际页面显示可能存在差异。
3. 如需引用,请注明本文出处。
1. 本系列文章涉及的部分参数需要手动调整来符合切实使用需求。
2. 随着 PVE 系统的迭代更新,截图中的内容和实际页面显示可能存在差异。
3. 如需引用,请注明本文出处。
Binary file not shown.

Before

Width:  |  Height:  |  Size: 205 KiB

After

Width:  |  Height:  |  Size: 211 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 272 KiB

After

Width:  |  Height:  |  Size: 280 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 283 KiB

After

Width:  |  Height:  |  Size: 300 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 339 KiB

After

Width:  |  Height:  |  Size: 147 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 43 KiB

After

Width:  |  Height:  |  Size: 23 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 279 KiB

After

Width:  |  Height:  |  Size: 292 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 269 KiB

After

Width:  |  Height:  |  Size: 265 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 247 KiB

After

Width:  |  Height:  |  Size: 98 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 216 KiB

After

Width:  |  Height:  |  Size: 186 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 274 KiB

After

Width:  |  Height:  |  Size: 294 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 131 KiB

After

Width:  |  Height:  |  Size: 220 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 204 KiB

After

Width:  |  Height:  |  Size: 111 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 169 KiB

After

Width:  |  Height:  |  Size: 271 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 599 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 160 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 263 KiB

After

Width:  |  Height:  |  Size: 106 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 413 KiB

After

Width:  |  Height:  |  Size: 370 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 239 KiB

After

Width:  |  Height:  |  Size: 133 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 221 KiB

After

Width:  |  Height:  |  Size: 122 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 199 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 74 KiB

After

Width:  |  Height:  |  Size: 73 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 579 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 322 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 117 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 84 KiB

After

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 79 KiB

After

Width:  |  Height:  |  Size: 78 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 81 KiB

After

Width:  |  Height:  |  Size: 73 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 100 KiB

After

Width:  |  Height:  |  Size: 99 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 107 KiB

After

Width:  |  Height:  |  Size: 107 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 128 KiB

After

Width:  |  Height:  |  Size: 78 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 132 KiB

After

Width:  |  Height:  |  Size: 88 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 173 KiB

After

Width:  |  Height:  |  Size: 124 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 120 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 72 KiB

After

Width:  |  Height:  |  Size: 47 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 136 KiB

After

Width:  |  Height:  |  Size: 80 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 71 KiB

After

Width:  |  Height:  |  Size: 45 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 78 KiB

After

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

After

Width:  |  Height:  |  Size: 71 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 89 KiB

After

Width:  |  Height:  |  Size: 61 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 77 KiB

After

Width:  |  Height:  |  Size: 49 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 98 KiB

After

Width:  |  Height:  |  Size: 66 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 187 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 92 KiB

After

Width:  |  Height:  |  Size: 56 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 127 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 75 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 84 KiB

After

Width:  |  Height:  |  Size: 55 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 97 KiB

After

Width:  |  Height:  |  Size: 65 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 107 KiB

After

Width:  |  Height:  |  Size: 70 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 66 KiB

After

Width:  |  Height:  |  Size: 55 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 79 KiB

After

Width:  |  Height:  |  Size: 41 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 88 KiB

After

Width:  |  Height:  |  Size: 86 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 87 KiB

After

Width:  |  Height:  |  Size: 88 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 48 KiB

After

Width:  |  Height:  |  Size: 33 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 52 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 136 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 65 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 99 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 92 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 384 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 127 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 300 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 151 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 220 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 201 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 171 KiB

@@ -1,177 +1,177 @@
// Unattended-Upgrade::Origins-Pattern controls which packages are
// upgraded.
//
// Lines below have the format "keyword=value,...". A
// package will be upgraded only if the values in its metadata match
// all the supplied keywords in a line. (In other words, omitted
// keywords are wild cards.) The keywords originate from the Release
// file, but several aliases are accepted. The accepted keywords are:
// a,archive,suite (eg, "stable")
// c,component (eg, "main", "contrib", "non-free")
// l,label (eg, "Debian", "Debian-Security")
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
// n,codename (eg, "jessie", "jessie-updates")
// site (eg, "http.debian.net")
// The available values on the system are printed by the command
// "apt-cache policy", and can be debugged by running
// "unattended-upgrades -d" and looking at the log file.
//
// Within lines unattended-upgrades allows 2 macros whose values are
// derived from /etc/debian_version:
// ${distro_id} Installed origin.
// ${distro_codename} Installed codename (eg, "buster")
Unattended-Upgrade::Origins-Pattern {
// Codename based matching:
// This will follow the migration of a release through different
// archives (e.g. from testing to stable and later oldstable).
// Software will be the latest available for the named release,
// but the Debian release itself will not be automatically upgraded.
"origin=Debian,codename=${distro_codename}-updates";
// "origin=Debian,codename=${distro_codename}-proposed-updates";
"origin=Debian,codename=${distro_codename},label=Debian";
"origin=Debian,codename=${distro_codename},label=Debian-Security";
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
// Archive or Suite based matching:
// Note that this will silently match a different release after
// migration to the specified archive (e.g. testing becomes the
// new stable).
// "o=Debian,a=stable";
// "o=Debian,a=stable-updates";
// "o=Debian,a=proposed-updates";
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
};
// Python regular expressions, matching packages to exclude from upgrading
Unattended-Upgrade::Package-Blacklist {
// The following matches all packages starting with linux-
// "linux-";
// Use $ to explicitely define the end of a package name. Without
// the $, "libc6" would match all of them.
// "libc6$";
// "libc6-dev$";
// "libc6-i686$";
// Special characters need escaping
// "libstdc\+\+6$";
// The following matches packages like xen-system-amd64, xen-utils-4.1,
// xenstore-utils and libxenstore3.0
// "(lib)?xen(store)?";
// For more information about Python regular expressions, see
// https://docs.python.org/3/howto/regex.html
};
// This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run
// dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
// Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGTERM. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true";
// Install all updates when the machine is shutting down
// instead of doing it in the background while the machine is running.
// This will (obviously) make shutdown slower.
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
// This allows more time for unattended-upgrades to shut down gracefully
// or even install a few packages in InstallOnShutdown mode, but is still a
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
// Users enabling InstallOnShutdown mode are advised to increase
// InhibitDelayMaxSec even further, possibly to 30 minutes.
//Unattended-Upgrade::InstallOnShutdown "false";
// Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail "";
// Set this value to one of:
// "always", "only-on-error" or "on-change"
// If this is not set, then any legacy MailOnlyOnError (boolean) value
// is used to chose between "only-on-error" and "on-change"
//Unattended-Upgrade::MailReport "on-change";
// Remove unused automatically installed kernel-related packages
// (kernel images, kernel headers and kernel version locked tools).
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Do automatic removal of newly unused dependencies after the upgrade
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
// Do automatic removal of unused packages after the upgrade
// (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
// Automatically reboot *WITHOUT CONFIRMATION* if
// the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false";
// Automatically reboot even if there are users currently logged in
// when Unattended-Upgrade::Automatic-Reboot is set to true
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
// If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately
// Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
// Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec
//Acquire::http::Dl-Limit "70";
// Enable logging to syslog. Default is False
// Unattended-Upgrade::SyslogEnable "false";
// Specify syslog facility. Default is daemon
// Unattended-Upgrade::SyslogFacility "daemon";
// Download and install upgrades only on AC power
// (i.e. skip or gracefully stop updates on battery)
// Unattended-Upgrade::OnlyOnACPower "true";
// Download and install upgrades only on non-metered connection
// (i.e. skip or gracefully stop updates on a metered connection)
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
// Verbose logging
// Unattended-Upgrade::Verbose "false";
// Print debugging information both in unattended-upgrades and
// in unattended-upgrade-shutdown
// Unattended-Upgrade::Debug "false";
// Allow package downgrade if Pin-Priority exceeds 1000
// Unattended-Upgrade::Allow-downgrade "false";
// When APT fails to mark a package to be upgraded or installed try adjusting
// candidates of related packages to help APT's resolver in finding a solution
// where the package can be upgraded or installed.
// This is a workaround until APT's resolver is fixed to always find a
// solution if it exists. (See Debian bug #711128.)
// The fallback is enabled by default, except on Debian's sid release because
// uninstallable packages are frequent there.
// Disabling the fallback speeds up unattended-upgrades when there are
// uninstallable packages at the expense of rarely keeping back packages which
// could be upgraded or installed.
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:30";
// Unattended-Upgrade::Origins-Pattern controls which packages are
// upgraded.
//
// Lines below have the format "keyword=value,...". A
// package will be upgraded only if the values in its metadata match
// all the supplied keywords in a line. (In other words, omitted
// keywords are wild cards.) The keywords originate from the Release
// file, but several aliases are accepted. The accepted keywords are:
// a,archive,suite (eg, "stable")
// c,component (eg, "main", "contrib", "non-free")
// l,label (eg, "Debian", "Debian-Security")
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
// n,codename (eg, "jessie", "jessie-updates")
// site (eg, "http.debian.net")
// The available values on the system are printed by the command
// "apt-cache policy", and can be debugged by running
// "unattended-upgrades -d" and looking at the log file.
//
// Within lines unattended-upgrades allows 2 macros whose values are
// derived from /etc/debian_version:
// ${distro_id} Installed origin.
// ${distro_codename} Installed codename (eg, "buster")
Unattended-Upgrade::Origins-Pattern {
// Codename based matching:
// This will follow the migration of a release through different
// archives (e.g. from testing to stable and later oldstable).
// Software will be the latest available for the named release,
// but the Debian release itself will not be automatically upgraded.
"origin=Debian,codename=${distro_codename}-updates";
// "origin=Debian,codename=${distro_codename}-proposed-updates";
"origin=Debian,codename=${distro_codename},label=Debian";
"origin=Debian,codename=${distro_codename},label=Debian-Security";
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
// Archive or Suite based matching:
// Note that this will silently match a different release after
// migration to the specified archive (e.g. testing becomes the
// new stable).
// "o=Debian,a=stable";
// "o=Debian,a=stable-updates";
// "o=Debian,a=proposed-updates";
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
};
// Python regular expressions, matching packages to exclude from upgrading
Unattended-Upgrade::Package-Blacklist {
// The following matches all packages starting with linux-
// "linux-";
// Use $ to explicitely define the end of a package name. Without
// the $, "libc6" would match all of them.
// "libc6$";
// "libc6-dev$";
// "libc6-i686$";
// Special characters need escaping
// "libstdc\+\+6$";
// The following matches packages like xen-system-amd64, xen-utils-4.1,
// xenstore-utils and libxenstore3.0
// "(lib)?xen(store)?";
// For more information about Python regular expressions, see
// https://docs.python.org/3/howto/regex.html
};
// This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run
// dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
// Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGTERM. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true";
// Install all updates when the machine is shutting down
// instead of doing it in the background while the machine is running.
// This will (obviously) make shutdown slower.
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
// This allows more time for unattended-upgrades to shut down gracefully
// or even install a few packages in InstallOnShutdown mode, but is still a
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
// Users enabling InstallOnShutdown mode are advised to increase
// InhibitDelayMaxSec even further, possibly to 30 minutes.
//Unattended-Upgrade::InstallOnShutdown "false";
// Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail "";
// Set this value to one of:
// "always", "only-on-error" or "on-change"
// If this is not set, then any legacy MailOnlyOnError (boolean) value
// is used to chose between "only-on-error" and "on-change"
//Unattended-Upgrade::MailReport "on-change";
// Remove unused automatically installed kernel-related packages
// (kernel images, kernel headers and kernel version locked tools).
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Do automatic removal of newly unused dependencies after the upgrade
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
// Do automatic removal of unused packages after the upgrade
// (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
// Automatically reboot *WITHOUT CONFIRMATION* if
// the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false";
// Automatically reboot even if there are users currently logged in
// when Unattended-Upgrade::Automatic-Reboot is set to true
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
// If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately
// Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
// Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec
//Acquire::http::Dl-Limit "70";
// Enable logging to syslog. Default is False
// Unattended-Upgrade::SyslogEnable "false";
// Specify syslog facility. Default is daemon
// Unattended-Upgrade::SyslogFacility "daemon";
// Download and install upgrades only on AC power
// (i.e. skip or gracefully stop updates on battery)
// Unattended-Upgrade::OnlyOnACPower "true";
// Download and install upgrades only on non-metered connection
// (i.e. skip or gracefully stop updates on a metered connection)
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
// Verbose logging
// Unattended-Upgrade::Verbose "false";
// Print debugging information both in unattended-upgrades and
// in unattended-upgrade-shutdown
// Unattended-Upgrade::Debug "false";
// Allow package downgrade if Pin-Priority exceeds 1000
// Unattended-Upgrade::Allow-downgrade "false";
// When APT fails to mark a package to be upgraded or installed try adjusting
// candidates of related packages to help APT's resolver in finding a solution
// where the package can be upgraded or installed.
// This is a workaround until APT's resolver is fixed to always find a
// solution if it exists. (See Debian bug #711128.)
// The fallback is enabled by default, except on Debian's sid release because
// uninstallable packages are frequent there.
// Disabling the fallback speeds up unattended-upgrades when there are
// uninstallable packages at the expense of rarely keeping back packages which
// could be upgraded or installed.
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
+32
View File
@@ -0,0 +1,32 @@
# This configuration file is customized by fox,
# Optimize sysctl parameters for local DNS server.
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = cubic
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.somaxconn = 8192
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 16384 262144 8388608
net.ipv4.tcp_wmem = 32768 524288 16777216
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
+47
View File
@@ -0,0 +1,47 @@
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local DNS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=7200
fast-dns-retry=1800
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-negcache
no-resolv
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/lan/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/fox.home.arpa/172.16.1.1
server=127.0.0.1#6053
server=::1#6053
+18
View File
@@ -0,0 +1,18 @@
## 下载加速规则安装脚本
$ sudo curl -LR -o /opt/dnsmasq-plugin.sh https://gitee.com/felixonmars/dnsmasq-china-list/raw/master/install.sh
## 设置脚本可执行权限
$ sudo chmod +x /opt/dnsmasq-plugin.sh
## 设置脚本文件防篡改
$ sudo chattr +i /opt/dnsmasq-plugin.sh
## 执行脚本
$ sudo bash /opt/dnsmasq-plugin.sh
## 设置 crontab
25 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/dnsmasq.d/anti-ad.dnsmasq.conf https://anti-ad.net/anti-ad-for-dnsmasq.conf
35 9 * * * /usr/bin/bash /opt/dnsmasq-plugin.sh
+52
View File
@@ -0,0 +1,52 @@
# This configuration file is customized by fox,
# Optimize SmartDNS parameters for local DNS server.
#
# For use common DNS server as upstream DNS server,
# please modify 'server' parameter according to
# your network environment.
#
# eg:
# server 223.5.5.5
# server 180.184.1.1
# server 119.29.29.29
# server 114.114.114.114
# server 2402:4e00::
# server 2400:3200::1
conf-file /etc/smartdns.d/*.conf
log-level notice
bind [::]:6053@lo
bind-tcp [::]:6053@lo
cache-size 32768
max-query-limit 1024
max-reply-ip-num 24
prefetch-domain yes
serve-expired yes
serve-expired-ttl 129600
serve-expired-reply-ttl 30
serve-expired-prefetch-time 28800
rr-ttl-min 60
rr-ttl-max 28800
rr-ttl-reply-max 14400
server 172.16.1.1 -group intranet -exclude-default-group
nameserver /fox.home.arpa/intranet
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
server-tcp 180.184.2.2 -bootstrap-dns
server-tcp 114.114.115.115 -bootstrap-dns
server-tcp 2400:3200:baba::1 -bootstrap-dns
server-tcp 2400:7fc0:849e:200::4 -bootstrap-dns
server-tls dot.pub
server-tls dns.alidns.com
server-https https://doh.pub/dns-query
server-https https://dns.alidns.com/dns-query
+14
View File
@@ -0,0 +1,14 @@
# This configuration file is customized by fox,
# Optimize SmartDNS crontab for local DNS server.
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
30 9 * * * /usr/bin/systemctl restart smartdns.service
## Or when the smartdns plugin is installed
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
30 9 * * * /usr/bin/bash /opt/smartdns-plugin.sh
@@ -0,0 +1,72 @@
#!/bin/bash
set -e
WORKDIR="$(mktemp -d)"
CONFDIR="/etc/smartdns.d"
SERVERS=(223.5.5.5 180.184.1.1 119.29.29.29 114.114.114.114 2402:4e00:: 2400:3200::1)
GROUP=(flash)
# Others: 223.6.6.6 119.28.28.28
# Not using best possible CDN pop: 1.2.4.8 210.2.4.8
# Broken?: 180.76.76.76
CONF_WITH_SERVERS=(accelerated-domains.china google.china apple.china)
CONF_WITH_GROUP=(dns-group.china)
CONF_SIMPLE=(bogus-nxdomain.china)
echo "Checking whether the configuration folder exists..."
if [ ! -d "$CONFDIR" ]; then
mkdir -p "$CONFDIR"
fi
echo "Downloading latest configurations..."
git clone --depth=1 https://gitee.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://pagure.io/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://github.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://bitbucket.org/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://gitlab.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://e.coding.net/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://codehub.devcloud.huaweicloud.com/dnsmasq-china-list00001/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 http://repo.or.cz/dnsmasq-china-list.git "$WORKDIR"
echo "Removing old configurations..."
for _conf in "${CONF_WITH_SERVERS[@]}" "${CONF_WITH_GROUP[@]}" "${CONF_SIMPLE[@]}"; do
rm -f "$CONFDIR/$_conf"*.conf
done
echo "Installing new configurations..."
for _conf in "${CONF_WITH_SERVERS[@]}" "${CONF_WITH_GROUP[@]}" "${CONF_SIMPLE[@]}"; do
if [[ "${CONF_WITH_SERVERS[@]}" =~ $_conf ]]; then
sed -En 's|^server=/([^/]*)/114.114.114.114$|\1|p' "$WORKDIR/$_conf.conf" | grep -Ev '^#' > "$WORKDIR/$_conf.step1.raw"
sed -En "s/(.*)/nameserver \\/\\1\\/${GROUP[@]}/p" "$WORKDIR/$_conf.step1.raw" > "$WORKDIR/$_conf.step2.raw"
cp "$WORKDIR/$_conf.step2.raw" "$CONFDIR/$_conf.smartdns.conf"
fi
if [[ "${CONF_WITH_GROUP[@]}" =~ $_conf ]]; then
for _server in "${SERVERS[@]}"; do
echo "server $_server -group ${GROUP[@]} -exclude-default-group" >> "$WORKDIR/$_conf.raw"
done
cp "$WORKDIR/$_conf.raw" "$CONFDIR/$_conf.smartdns.conf"
fi
if [[ "${CONF_SIMPLE[@]}" =~ $_conf ]]; then
sed -e "s|=| |" "$WORKDIR/$_conf.conf" > "$WORKDIR/$_conf.raw"
cp "$WORKDIR/$_conf.raw" "$CONFDIR/$_conf.smartdns.conf"
fi
done
echo "Restarting smartdns service..."
if hash systemctl 2>/dev/null; then
systemctl restart smartdns
elif hash service 2>/dev/null; then
service smartdns restart
elif hash rc-service 2>/dev/null; then
rc-service smartdns restart
elif hash busybox 2>/dev/null && [[ -d "/etc/init.d" ]]; then
/etc/init.d/smartdns restart
else
echo "Now please restart smartdns since I don't know how to do it."
fi
echo "Cleaning up..."
rm -r "$WORKDIR"
@@ -1,10 +1,12 @@
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian
Suites: bookworm bookworm-updates bookworm-backports
Suites: bookworm bookworm-updates
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian-security
Suites: bookworm-security
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
@@ -0,0 +1,5 @@
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "7";
APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1";
@@ -0,0 +1,178 @@
// Unattended-Upgrade::Origins-Pattern controls which packages are
// upgraded.
//
// Lines below have the format "keyword=value,...". A
// package will be upgraded only if the values in its metadata match
// all the supplied keywords in a line. (In other words, omitted
// keywords are wild cards.) The keywords originate from the Release
// file, but several aliases are accepted. The accepted keywords are:
// a,archive,suite (eg, "stable")
// c,component (eg, "main", "contrib", "non-free")
// l,label (eg, "Debian", "Debian-Security")
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
// n,codename (eg, "jessie", "jessie-updates")
// site (eg, "http.debian.net")
// The available values on the system are printed by the command
// "apt-cache policy", and can be debugged by running
// "unattended-upgrades -d" and looking at the log file.
//
// Within lines unattended-upgrades allows 2 macros whose values are
// derived from /etc/debian_version:
// ${distro_id} Installed origin.
// ${distro_codename} Installed codename (eg, "buster")
Unattended-Upgrade::Origins-Pattern {
// Codename based matching:
// This will follow the migration of a release through different
// archives (e.g. from testing to stable and later oldstable).
// Software will be the latest available for the named release,
// but the Debian release itself will not be automatically upgraded.
"origin=Debian,codename=${distro_codename}-updates";
// "origin=Debian,codename=${distro_codename}-proposed-updates";
"origin=Debian,codename=${distro_codename},label=Debian";
"origin=Debian,codename=${distro_codename},label=Debian-Security";
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
"origin=Tailscale,codename=${distro_codename},label=Tailscale";
// Archive or Suite based matching:
// Note that this will silently match a different release after
// migration to the specified archive (e.g. testing becomes the
// new stable).
// "o=Debian,a=stable";
// "o=Debian,a=stable-updates";
// "o=Debian,a=proposed-updates";
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
};
// Python regular expressions, matching packages to exclude from upgrading
Unattended-Upgrade::Package-Blacklist {
// The following matches all packages starting with linux-
// "linux-";
// Use $ to explicitely define the end of a package name. Without
// the $, "libc6" would match all of them.
// "libc6$";
// "libc6-dev$";
// "libc6-i686$";
// Special characters need escaping
// "libstdc\+\+6$";
// The following matches packages like xen-system-amd64, xen-utils-4.1,
// xenstore-utils and libxenstore3.0
// "(lib)?xen(store)?";
// For more information about Python regular expressions, see
// https://docs.python.org/3/howto/regex.html
};
// This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run
// dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
// Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGTERM. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true";
// Install all updates when the machine is shutting down
// instead of doing it in the background while the machine is running.
// This will (obviously) make shutdown slower.
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
// This allows more time for unattended-upgrades to shut down gracefully
// or even install a few packages in InstallOnShutdown mode, but is still a
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
// Users enabling InstallOnShutdown mode are advised to increase
// InhibitDelayMaxSec even further, possibly to 30 minutes.
//Unattended-Upgrade::InstallOnShutdown "false";
// Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail "";
// Set this value to one of:
// "always", "only-on-error" or "on-change"
// If this is not set, then any legacy MailOnlyOnError (boolean) value
// is used to chose between "only-on-error" and "on-change"
//Unattended-Upgrade::MailReport "on-change";
// Remove unused automatically installed kernel-related packages
// (kernel images, kernel headers and kernel version locked tools).
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Do automatic removal of newly unused dependencies after the upgrade
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
// Do automatic removal of unused packages after the upgrade
// (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
// Automatically reboot *WITHOUT CONFIRMATION* if
// the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false";
// Automatically reboot even if there are users currently logged in
// when Unattended-Upgrade::Automatic-Reboot is set to true
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
// If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately
// Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
// Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec
//Acquire::http::Dl-Limit "70";
// Enable logging to syslog. Default is False
// Unattended-Upgrade::SyslogEnable "false";
// Specify syslog facility. Default is daemon
// Unattended-Upgrade::SyslogFacility "daemon";
// Download and install upgrades only on AC power
// (i.e. skip or gracefully stop updates on battery)
// Unattended-Upgrade::OnlyOnACPower "true";
// Download and install upgrades only on non-metered connection
// (i.e. skip or gracefully stop updates on a metered connection)
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
// Verbose logging
// Unattended-Upgrade::Verbose "false";
// Print debugging information both in unattended-upgrades and
// in unattended-upgrade-shutdown
// Unattended-Upgrade::Debug "false";
// Allow package downgrade if Pin-Priority exceeds 1000
// Unattended-Upgrade::Allow-downgrade "false";
// When APT fails to mark a package to be upgraded or installed try adjusting
// candidates of related packages to help APT's resolver in finding a solution
// where the package can be upgraded or installed.
// This is a workaround until APT's resolver is fixed to always find a
// solution if it exists. (See Debian bug #711128.)
// The fallback is enabled by default, except on Debian's sid release because
// uninstallable packages are frequent there.
// Disabling the fallback speeds up unattended-upgrades when there are
// uninstallable packages at the expense of rarely keeping back packages which
// could be upgraded or installed.
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
+69
View File
@@ -0,0 +1,69 @@
# This configuration file is customized by fox,
# Optimize sysctl parameters for local TS server.
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
net.ipv4.ip_forward = 1
net.ipv6.conf.all.forwarding = 1
net.ipv6.conf.default.forwarding = 1
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768
net.core.somaxconn = 8192
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.all.arp_ignore = 1
net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 256
net.ipv4.route.error_burst = 500
net.ipv4.route.error_cost = 100
net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 16384 262144 8388608
net.ipv4.tcp_wmem = 32768 524288 16777216
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
net.ipv6.conf.all.accept_source_route = 0
net.ipv6.conf.default.accept_source_route = 0
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
net.netfilter.nf_conntrack_acct = 1
net.netfilter.nf_conntrack_checksum = 0
net.netfilter.nf_conntrack_tcp_timeout_established = 7440
+47
View File
@@ -0,0 +1,47 @@
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local TS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=7200
fast-dns-retry=1800
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-negcache
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/lan/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1
server=172.16.1.1
+181
View File
@@ -0,0 +1,181 @@
#!/usr/sbin/nft -f
# This configuration file is customized by fox,
# Optimize nftables rules for local TS server.
table inet router
flush table inet router
table inet router {
#
# Flowtable
#
flowtable ft {
hook ingress priority filter;
devices = { eth0 };
counter;
}
#
# Filter rules
#
chain input {
type filter hook input priority filter; policy drop;
ct state established,related accept comment "defconf: handle inbound flows"
iif "lo" accept comment "defconf: accept traffic from loopback"
ct state new meta l4proto tcp jump syn_flood comment "defconf: rate limit new TCP connections"
iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic"
iifname "tailscale0" counter jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related goto handle_offload comment "defconf: handle forwarded flows"
iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic"
iifname "tailscale0" counter jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic"
}
chain output {
type filter hook output priority filter; policy accept;
ct state established,related accept comment "defconf: handle outbound flows"
oif "lo" accept comment "defconf: accept traffic towards loopback"
oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic"
oifname "tailscale0" counter jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic"
}
chain prerouting {
type filter hook prerouting priority filter; policy accept;
iifname "eth0" jump helper_lan comment "defconf: handle LAN IPv4 / IPv6 helper assignment"
iifname "tailscale0" jump helper_tailscale comment "tsconf: handle TS IPv4 / IPv6 helper assignment"
}
chain syn_flood {
limit rate 200/second burst 100 packets return comment "defconf: accept new TCP connections below rate-limit"
counter drop comment "defconf: drop excess new TCP connections"
}
chain handle_offload {
flow add @ft accept comment "defconf: track forwarded flows"
accept
}
chain input_lan {
ct status dnat accept comment "lanconf: accept port redirect"
jump accept_from_lan
}
chain forward_lan {
jump accept_to_tailscale comment "tsconf: accept LAN to TS forward"
ct status dnat accept comment "lanconf: accept port forward"
jump accept_to_lan
}
chain output_lan {
jump accept_to_lan
}
chain helper_lan {
}
chain accept_from_lan {
iifname "eth0" accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
}
chain accept_to_lan {
meta nfproto ipv4 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv4 leakage"
meta nfproto ipv6 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv6 leakage"
oifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
}
chain input_tailscale {
jump accept_from_tailscale
}
chain forward_tailscale {
counter jump accept_to_lan comment "tsconf: accept TS to LAN forward"
counter jump accept_to_tailscale
}
chain output_tailscale {
counter jump accept_to_tailscale
}
chain helper_tailscale {
}
chain accept_from_tailscale {
iifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
}
chain accept_to_tailscale {
oifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
}
#
# NAT rules
#
chain dstnat {
type nat hook prerouting priority dstnat; policy accept;
iifname "eth0" meta l4proto { tcp, udp } th dport domain jump dstnat_lan comment "defconf: handle LAN IPv4 / IPv6 dstnat traffic"
}
chain srcnat {
type nat hook postrouting priority srcnat; policy accept;
oifname "eth0" jump srcnat_lan comment "defconf: handle LAN IPv4 / IPv6 srcnat traffic"
}
chain dstnat_lan {
meta nfproto ipv4 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv4 DNS redirect"
meta nfproto ipv6 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv6 DNS redirect"
}
chain srcnat_lan {
meta nfproto ipv4 counter masquerade comment "defconf: masquerade IPv4 LAN traffic"
meta nfproto ipv6 counter masquerade comment "defconf: masquerade IPv6 LAN traffic"
}
#
# Raw rules (notrack)
#
chain raw_prerouting {
type filter hook prerouting priority raw; policy accept;
}
chain raw_output {
type filter hook output priority raw; policy accept;
}
#
# Mangle rules
#
chain mangle_prerouting {
type filter hook prerouting priority mangle; policy accept;
}
chain mangle_postrouting {
type filter hook postrouting priority mangle; policy accept;
}
chain mangle_input {
type filter hook input priority mangle; policy accept;
}
chain mangle_output {
type route hook output priority mangle; policy accept;
}
chain mangle_forward {
type filter hook forward priority mangle; policy accept;
}
}
+5
View File
@@ -0,0 +1,5 @@
# This configuration file is customized by fox,
# Optimize netfilter related modules at system boot.
nf_conntrack
-25
View File
@@ -1,25 +0,0 @@
# This configuration file is customized by fox
# Optimize system parameters
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
# Other adjustable system parameters
net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 100
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_max_orphans = 4096
net.ipv4.tcp_max_tw_buckets = 4096
net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
@@ -1,5 +1,5 @@
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "5";
APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1";
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "5";
APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1";
@@ -1,179 +1,179 @@
// Unattended-Upgrade::Origins-Pattern controls which packages are
// upgraded.
//
// Lines below have the format "keyword=value,...". A
// package will be upgraded only if the values in its metadata match
// all the supplied keywords in a line. (In other words, omitted
// keywords are wild cards.) The keywords originate from the Release
// file, but several aliases are accepted. The accepted keywords are:
// a,archive,suite (eg, "stable")
// c,component (eg, "main", "contrib", "non-free")
// l,label (eg, "Debian", "Debian-Security")
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
// n,codename (eg, "jessie", "jessie-updates")
// site (eg, "http.debian.net")
// The available values on the system are printed by the command
// "apt-cache policy", and can be debugged by running
// "unattended-upgrades -d" and looking at the log file.
//
// Within lines unattended-upgrades allows 2 macros whose values are
// derived from /etc/debian_version:
// ${distro_id} Installed origin.
// ${distro_codename} Installed codename (eg, "buster")
Unattended-Upgrade::Origins-Pattern {
// Codename based matching:
// This will follow the migration of a release through different
// archives (e.g. from testing to stable and later oldstable).
// Software will be the latest available for the named release,
// but the Debian release itself will not be automatically upgraded.
"origin=Debian,codename=${distro_codename}-updates";
// "origin=Debian,codename=${distro_codename}-proposed-updates";
"origin=Debian,codename=${distro_codename},label=Debian";
"origin=Debian,codename=${distro_codename},label=Debian-Security";
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
"origin=Proxmox,codename=${distro_codename},label=Proxmox Debian Repository";
// "origin=Proxmox,codename=${distro_codename},label=Proxmox Ceph Debian Repository";
// Archive or Suite based matching:
// Note that this will silently match a different release after
// migration to the specified archive (e.g. testing becomes the
// new stable).
// "o=Debian,a=stable";
// "o=Debian,a=stable-updates";
// "o=Debian,a=proposed-updates";
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
};
// Python regular expressions, matching packages to exclude from upgrading
Unattended-Upgrade::Package-Blacklist {
// The following matches all packages starting with linux-
// "linux-";
// Use $ to explicitely define the end of a package name. Without
// the $, "libc6" would match all of them.
// "libc6$";
// "libc6-dev$";
// "libc6-i686$";
// Special characters need escaping
// "libstdc\+\+6$";
// The following matches packages like xen-system-amd64, xen-utils-4.1,
// xenstore-utils and libxenstore3.0
// "(lib)?xen(store)?";
// For more information about Python regular expressions, see
// https://docs.python.org/3/howto/regex.html
};
// This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run
// dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
// Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGTERM. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true";
// Install all updates when the machine is shutting down
// instead of doing it in the background while the machine is running.
// This will (obviously) make shutdown slower.
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
// This allows more time for unattended-upgrades to shut down gracefully
// or even install a few packages in InstallOnShutdown mode, but is still a
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
// Users enabling InstallOnShutdown mode are advised to increase
// InhibitDelayMaxSec even further, possibly to 30 minutes.
//Unattended-Upgrade::InstallOnShutdown "false";
// Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail "";
// Set this value to one of:
// "always", "only-on-error" or "on-change"
// If this is not set, then any legacy MailOnlyOnError (boolean) value
// is used to chose between "only-on-error" and "on-change"
//Unattended-Upgrade::MailReport "on-change";
// Remove unused automatically installed kernel-related packages
// (kernel images, kernel headers and kernel version locked tools).
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Do automatic removal of newly unused dependencies after the upgrade
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
// Do automatic removal of unused packages after the upgrade
// (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
// Automatically reboot *WITHOUT CONFIRMATION* if
// the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false";
// Automatically reboot even if there are users currently logged in
// when Unattended-Upgrade::Automatic-Reboot is set to true
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
// If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately
// Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
// Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec
//Acquire::http::Dl-Limit "70";
// Enable logging to syslog. Default is False
// Unattended-Upgrade::SyslogEnable "false";
// Specify syslog facility. Default is daemon
// Unattended-Upgrade::SyslogFacility "daemon";
// Download and install upgrades only on AC power
// (i.e. skip or gracefully stop updates on battery)
// Unattended-Upgrade::OnlyOnACPower "true";
// Download and install upgrades only on non-metered connection
// (i.e. skip or gracefully stop updates on a metered connection)
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
// Verbose logging
// Unattended-Upgrade::Verbose "false";
// Print debugging information both in unattended-upgrades and
// in unattended-upgrade-shutdown
// Unattended-Upgrade::Debug "false";
// Allow package downgrade if Pin-Priority exceeds 1000
// Unattended-Upgrade::Allow-downgrade "false";
// When APT fails to mark a package to be upgraded or installed try adjusting
// candidates of related packages to help APT's resolver in finding a solution
// where the package can be upgraded or installed.
// This is a workaround until APT's resolver is fixed to always find a
// solution if it exists. (See Debian bug #711128.)
// The fallback is enabled by default, except on Debian's sid release because
// uninstallable packages are frequent there.
// Disabling the fallback speeds up unattended-upgrades when there are
// uninstallable packages at the expense of rarely keeping back packages which
// could be upgraded or installed.
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "05:00";
// Unattended-Upgrade::Origins-Pattern controls which packages are
// upgraded.
//
// Lines below have the format "keyword=value,...". A
// package will be upgraded only if the values in its metadata match
// all the supplied keywords in a line. (In other words, omitted
// keywords are wild cards.) The keywords originate from the Release
// file, but several aliases are accepted. The accepted keywords are:
// a,archive,suite (eg, "stable")
// c,component (eg, "main", "contrib", "non-free")
// l,label (eg, "Debian", "Debian-Security")
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
// n,codename (eg, "jessie", "jessie-updates")
// site (eg, "http.debian.net")
// The available values on the system are printed by the command
// "apt-cache policy", and can be debugged by running
// "unattended-upgrades -d" and looking at the log file.
//
// Within lines unattended-upgrades allows 2 macros whose values are
// derived from /etc/debian_version:
// ${distro_id} Installed origin.
// ${distro_codename} Installed codename (eg, "buster")
Unattended-Upgrade::Origins-Pattern {
// Codename based matching:
// This will follow the migration of a release through different
// archives (e.g. from testing to stable and later oldstable).
// Software will be the latest available for the named release,
// but the Debian release itself will not be automatically upgraded.
"origin=Debian,codename=${distro_codename}-updates";
// "origin=Debian,codename=${distro_codename}-proposed-updates";
"origin=Debian,codename=${distro_codename},label=Debian";
"origin=Debian,codename=${distro_codename},label=Debian-Security";
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
"origin=Proxmox,codename=${distro_codename},label=Proxmox Debian Repository";
// "origin=Proxmox,codename=${distro_codename},label=Proxmox Ceph Debian Repository";
// Archive or Suite based matching:
// Note that this will silently match a different release after
// migration to the specified archive (e.g. testing becomes the
// new stable).
// "o=Debian,a=stable";
// "o=Debian,a=stable-updates";
// "o=Debian,a=proposed-updates";
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
};
// Python regular expressions, matching packages to exclude from upgrading
Unattended-Upgrade::Package-Blacklist {
// The following matches all packages starting with linux-
// "linux-";
// Use $ to explicitely define the end of a package name. Without
// the $, "libc6" would match all of them.
// "libc6$";
// "libc6-dev$";
// "libc6-i686$";
// Special characters need escaping
// "libstdc\+\+6$";
// The following matches packages like xen-system-amd64, xen-utils-4.1,
// xenstore-utils and libxenstore3.0
// "(lib)?xen(store)?";
// For more information about Python regular expressions, see
// https://docs.python.org/3/howto/regex.html
};
// This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run
// dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
// Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGTERM. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true";
// Install all updates when the machine is shutting down
// instead of doing it in the background while the machine is running.
// This will (obviously) make shutdown slower.
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
// This allows more time for unattended-upgrades to shut down gracefully
// or even install a few packages in InstallOnShutdown mode, but is still a
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
// Users enabling InstallOnShutdown mode are advised to increase
// InhibitDelayMaxSec even further, possibly to 30 minutes.
//Unattended-Upgrade::InstallOnShutdown "false";
// Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail "";
// Set this value to one of:
// "always", "only-on-error" or "on-change"
// If this is not set, then any legacy MailOnlyOnError (boolean) value
// is used to chose between "only-on-error" and "on-change"
//Unattended-Upgrade::MailReport "on-change";
// Remove unused automatically installed kernel-related packages
// (kernel images, kernel headers and kernel version locked tools).
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Do automatic removal of newly unused dependencies after the upgrade
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
// Do automatic removal of unused packages after the upgrade
// (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
// Automatically reboot *WITHOUT CONFIRMATION* if
// the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false";
// Automatically reboot even if there are users currently logged in
// when Unattended-Upgrade::Automatic-Reboot is set to true
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
// If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately
// Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
// Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec
//Acquire::http::Dl-Limit "70";
// Enable logging to syslog. Default is False
// Unattended-Upgrade::SyslogEnable "false";
// Specify syslog facility. Default is daemon
// Unattended-Upgrade::SyslogFacility "daemon";
// Download and install upgrades only on AC power
// (i.e. skip or gracefully stop updates on battery)
// Unattended-Upgrade::OnlyOnACPower "true";
// Download and install upgrades only on non-metered connection
// (i.e. skip or gracefully stop updates on a metered connection)
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
// Verbose logging
// Unattended-Upgrade::Verbose "false";
// Print debugging information both in unattended-upgrades and
// in unattended-upgrade-shutdown
// Unattended-Upgrade::Debug "false";
// Allow package downgrade if Pin-Priority exceeds 1000
// Unattended-Upgrade::Allow-downgrade "false";
// When APT fails to mark a package to be upgraded or installed try adjusting
// candidates of related packages to help APT's resolver in finding a solution
// where the package can be upgraded or installed.
// This is a workaround until APT's resolver is fixed to always find a
// solution if it exists. (See Debian bug #711128.)
// The fallback is enabled by default, except on Debian's sid release because
// uninstallable packages are frequent there.
// Disabling the fallback speeds up unattended-upgrades when there are
// uninstallable packages at the expense of rarely keeping back packages which
// could be upgraded or installed.
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "02:30";
@@ -1,23 +1,23 @@
### Editing /etc/systemd/system/apt-daily-upgrade.timer.d/override.conf
### Anything between here and the comment below will become the new contents of the file
[Timer]
OnCalendar=
OnCalendar=02:00
RandomizedDelaySec=0
### Lines below this comment will be discarded
### /lib/systemd/system/apt-daily-upgrade.timer
# [Unit]
# Description=Daily apt upgrade and clean activities
# After=apt-daily.timer
#
# [Timer]
# OnCalendar=*-*-* 6:00
# RandomizedDelaySec=60m
# Persistent=true
#
# [Install]
# WantedBy=timers.target
### Editing /etc/systemd/system/apt-daily-upgrade.timer.d/override.conf
### Anything between here and the comment below will become the new contents of the file
[Timer]
OnCalendar=
OnCalendar=01:30
RandomizedDelaySec=0
### Lines below this comment will be discarded
### /lib/systemd/system/apt-daily-upgrade.timer
# [Unit]
# Description=Daily apt upgrade and clean activities
# After=apt-daily.timer
#
# [Timer]
# OnCalendar=*-*-* 6:00
# RandomizedDelaySec=60m
# Persistent=true
#
# [Install]
# WantedBy=timers.target
@@ -1,101 +1,101 @@
#!/bin/sh
### BEGIN INIT INFO
# Provides: cpufrequtils
# Required-Start: $remote_fs loadcpufreq
# Required-Stop:
# Default-Start: 2 3 4 5
# Default-Stop:
# Short-Description: set CPUFreq kernel parameters
# Description: utilities to deal with CPUFreq Linux
# kernel support
### END INIT INFO
#
DESC="CPUFreq Utilities"
PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
CPUFREQ_SET=/usr/bin/cpufreq-set
CPUFREQ_INFO=/usr/bin/cpufreq-info
CPUFREQ_OPTIONS=""
# use lsb-base
. /lib/lsb/init-functions
# Which governor to use. Must be one of the governors listed in:
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors
#
# and which limits to set. Both MIN_SPEED and MAX_SPEED must be values
# listed in:
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies
# a value of 0 for any of the two variables will disabling the use of
# that limit variable.
#
# WARNING: the correct kernel module must already be loaded or compiled in.
#
# Set ENABLE to "true" to let the script run at boot time.
#
# eg: ENABLE="true"
# GOVERNOR="ondemand"
# MAX_SPEED=1000
# MIN_SPEED=500
ENABLE="true"
GOVERNOR="powersave"
MAX_SPEED="0"
MIN_SPEED="0"
check_governor_avail() {
info="/sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors"
if [ -f $info ] && grep -q "\<$GOVERNOR\>" $info ; then
return 0;
fi
return 1;
}
[ -x $CPUFREQ_SET ] || exit 0
if [ -f /etc/default/cpufrequtils ] ; then
. /etc/default/cpufrequtils
fi
# if not enabled then exit gracefully
[ "$ENABLE" = "true" ] || exit 0
if [ -n "$MAX_SPEED" ] && [ $MAX_SPEED != "0" ] ; then
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --max $MAX_SPEED"
fi
if [ -n "$MIN_SPEED" ] && [ $MIN_SPEED != "0" ] ; then
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --min $MIN_SPEED"
fi
if [ -n "$GOVERNOR" ] ; then
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --governor $GOVERNOR"
fi
CPUS=$(cat /proc/stat|sed -ne 's/^cpu\([[:digit:]]\+\).*/\1/p')
RETVAL=0
case "$1" in
start|force-reload|restart|reload)
log_action_begin_msg "$DESC: Setting $GOVERNOR CPUFreq governor"
if check_governor_avail ; then
for cpu in $CPUS ; do
log_action_cont_msg "CPU${cpu}"
$CPUFREQ_SET --cpu $cpu $CPUFREQ_OPTIONS 2>&1 > /dev/null || \
RETVAL=$?
done
log_action_end_msg $RETVAL ""
else
log_action_cont_msg "disabled, governor not available"
log_action_end_msg $RETVAL
fi
;;
stop)
;;
*)
echo "Usage: $0 {start|stop|restart|reload|force-reload}"
exit 1
esac
exit 0
#!/bin/sh
### BEGIN INIT INFO
# Provides: cpufrequtils
# Required-Start: $remote_fs loadcpufreq
# Required-Stop:
# Default-Start: 2 3 4 5
# Default-Stop:
# Short-Description: set CPUFreq kernel parameters
# Description: utilities to deal with CPUFreq Linux
# kernel support
### END INIT INFO
#
DESC="CPUFreq Utilities"
PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
CPUFREQ_SET=/usr/bin/cpufreq-set
CPUFREQ_INFO=/usr/bin/cpufreq-info
CPUFREQ_OPTIONS=""
# use lsb-base
. /lib/lsb/init-functions
# Which governor to use. Must be one of the governors listed in:
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors
#
# and which limits to set. Both MIN_SPEED and MAX_SPEED must be values
# listed in:
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies
# a value of 0 for any of the two variables will disabling the use of
# that limit variable.
#
# WARNING: the correct kernel module must already be loaded or compiled in.
#
# Set ENABLE to "true" to let the script run at boot time.
#
# eg: ENABLE="true"
# GOVERNOR="ondemand"
# MAX_SPEED=1000
# MIN_SPEED=500
ENABLE="true"
GOVERNOR="powersave"
MAX_SPEED="0"
MIN_SPEED="0"
check_governor_avail() {
info="/sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors"
if [ -f $info ] && grep -q "\<$GOVERNOR\>" $info ; then
return 0;
fi
return 1;
}
[ -x $CPUFREQ_SET ] || exit 0
if [ -f /etc/default/cpufrequtils ] ; then
. /etc/default/cpufrequtils
fi
# if not enabled then exit gracefully
[ "$ENABLE" = "true" ] || exit 0
if [ -n "$MAX_SPEED" ] && [ $MAX_SPEED != "0" ] ; then
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --max $MAX_SPEED"
fi
if [ -n "$MIN_SPEED" ] && [ $MIN_SPEED != "0" ] ; then
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --min $MIN_SPEED"
fi
if [ -n "$GOVERNOR" ] ; then
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --governor $GOVERNOR"
fi
CPUS=$(cat /proc/stat|sed -ne 's/^cpu\([[:digit:]]\+\).*/\1/p')
RETVAL=0
case "$1" in
start|force-reload|restart|reload)
log_action_begin_msg "$DESC: Setting $GOVERNOR CPUFreq governor"
if check_governor_avail ; then
for cpu in $CPUS ; do
log_action_cont_msg "CPU${cpu}"
$CPUFREQ_SET --cpu $cpu $CPUFREQ_OPTIONS 2>&1 > /dev/null || \
RETVAL=$?
done
log_action_end_msg $RETVAL ""
else
log_action_cont_msg "disabled, governor not available"
log_action_end_msg $RETVAL
fi
;;
stop)
;;
*)
echo "Usage: $0 {start|stop|restart|reload|force-reload}"
exit 1
esac
exit 0
+6
View File
@@ -0,0 +1,6 @@
# This configuration file is customized by fox,
# Optimize system CPU governors.
CPUPOWER_START_OPTS="frequency-set -g powersave"
CPUPOWER_STOP_OPTS="frequency-set -g performance"
+18
View File
@@ -0,0 +1,18 @@
# This configuration file is customized by fox,
# Optimize for cpupower systemd service.
[Unit]
Description=Apply cpupower configuration
ConditionVirtualization=!container
After=syslog.target
[Service]
Type=oneshot
EnvironmentFile=/etc/default/cpupower
ExecStart=/usr/bin/cpupower $CPUPOWER_START_OPTS
ExecStop=/usr/bin/cpupower $CPUPOWER_STOP_OPTS
RemainAfterExit=yes
[Install]
WantedBy=multi-user.target