Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ee7b34ddf4 | ||
|
|
353dc12fca | ||
|
|
a410d925f4 | ||
|
|
2c48e3a330 | ||
|
|
2344cd77bf | ||
|
|
aba1e70956 | ||
|
|
bbcbc9fe1e | ||
|
|
5bce9e1d44 | ||
|
|
80f7041632 | ||
|
|
ffcae17092 | ||
|
|
0bd3a7cd36 | ||
|
|
eddc39bc40 | ||
|
|
564d56e56f | ||
|
|
80556cacaf | ||
|
|
2c8d775e9e | ||
|
|
19532baa21 | ||
|
|
2ff27e96c3 | ||
|
|
979f03052e | ||
|
|
3a7a506645 | ||
|
|
62c55d9750 | ||
|
|
101b5c64b2 | ||
|
|
497a8c0685 | ||
|
|
00e4fd27e5 | ||
|
|
85d5a3bee5 | ||
|
|
2ae4bda8b3 | ||
|
|
12cadb86ad | ||
|
|
3c9927a362 | ||
|
|
d69101077b | ||
|
|
6497efb00a | ||
|
|
79703f9d62 | ||
|
|
53994238c8 | ||
|
|
ddcdc18564 | ||
|
|
f505690ed6 | ||
|
|
96cb5ddcdc | ||
|
|
2858ba97c4 | ||
|
|
833817d85c | ||
|
|
7097fb5d73 | ||
|
|
52f3be600b | ||
|
|
0a9a2ee8fe | ||
|
|
ed3c106e27 | ||
|
|
c94d7d31fc | ||
|
|
abf168587d | ||
|
|
3e9a8eae07 | ||
|
|
090ab28970 | ||
|
|
59ebf178c7 | ||
|
|
249717ed89 | ||
|
|
2520ce4839 | ||
|
|
5d5750f120 | ||
|
|
f90dd7a7c8 | ||
|
|
730773e42b | ||
|
|
c00e178df3 | ||
|
|
f8c7676c85 | ||
|
|
29592abb40 | ||
|
|
62b2641413 | ||
|
|
04023ac155 | ||
|
|
4dcb3ff7a9 | ||
|
|
ca30a2f9e9 | ||
|
|
88ea495d5a | ||
|
|
d08a3acf74 | ||
|
|
d26f303437 | ||
|
|
ed0db21a9f | ||
|
|
18e02bc9c8 | ||
|
|
6882b01afc | ||
|
|
fec6ae3e56 | ||
|
|
660551f2fc | ||
|
|
80afa7dfe7 | ||
|
|
509b344c69 | ||
|
|
3b3a3361fa | ||
|
|
fba7575503 | ||
|
|
4d77f0415e | ||
|
|
8b35afeec5 | ||
|
|
e0c69c3fa5 | ||
|
|
410f6e8d2e | ||
|
|
56d9125152 | ||
|
|
779b75f3a8 | ||
|
|
b0c7a2d4ce | ||
|
|
b84dbe3872 | ||
|
|
1555ec02ca | ||
|
|
906db9eac4 | ||
|
|
0d091d93c1 | ||
|
|
b347128ec5 | ||
|
|
1e5a55de64 | ||
|
|
d052923897 | ||
|
|
ba0afba7eb | ||
|
|
6aa24ecb61 | ||
|
|
454ae86aba | ||
|
|
24b087aa1e | ||
|
|
56317210a6 | ||
|
|
d8e7753112 | ||
|
|
4700bc1c52 | ||
|
|
29f6296a1c | ||
|
|
891d8ef2f6 | ||
|
|
e4117816c5 | ||
|
|
b109b0d840 | ||
|
|
8bc4dd8587 | ||
|
|
eef810d850 | ||
|
|
752c233013 | ||
|
|
8b62f62420 | ||
|
|
46d0e0ce4a | ||
|
|
f643128cf5 | ||
|
|
165f6ea9dc | ||
|
|
7fc7ab2466 | ||
|
|
2407555015 | ||
|
|
5b65602c07 | ||
|
|
a2b1278038 | ||
|
|
07d5ea174a | ||
|
|
554b2bd6d4 | ||
|
|
145328fb3c | ||
|
|
9691336e5c | ||
|
|
f7ce11e99d | ||
|
|
eb631a1cdc | ||
|
|
46ce4e4ee3 | ||
|
|
0bd03af309 | ||
|
|
767c31694d | ||
|
|
b27372c20d | ||
|
|
b830088e5e | ||
|
|
9f5884befb | ||
|
|
8af7ef896b | ||
|
|
09a60d3ae4 | ||
|
|
830655bd52 | ||
|
|
95023d68d3 | ||
|
|
d8e6a50166 | ||
|
|
e6d805fba5 | ||
|
|
9386f961d1 | ||
|
|
b84666a6b6 | ||
|
|
07526b9ada | ||
|
|
e31338113d | ||
|
|
7eda1b4eef | ||
|
|
3b1a9e4f00 | ||
|
|
7288a7ba8b | ||
|
|
63631e6ad3 | ||
|
|
5ed5ac768b | ||
|
|
ae5b3e1e82 | ||
|
|
b7857fcd66 | ||
|
|
81101cde20 | ||
|
|
99e4a94a9f | ||
|
|
c4294612eb | ||
|
|
38df9bd3e4 | ||
|
|
0019ac0fbc | ||
|
|
1b8caefe58 | ||
|
|
9804c8964e | ||
|
|
861e468aa6 | ||
|
|
90bc8f942b | ||
|
|
09f4738295 | ||
|
|
ea71df8c8c | ||
|
|
1a8c107333 | ||
|
|
c40ba60a6e | ||
|
|
9494d82747 | ||
|
|
f89c38f8d8 | ||
|
|
6a9202a62b | ||
|
|
8a10db07d1 | ||
|
|
17ab25b998 | ||
|
|
17ae656734 | ||
|
|
b28bb464c1 | ||
|
|
0fd5dc83f2 | ||
|
|
ee64d1e961 | ||
|
|
636bbfb62b | ||
|
|
bb19e4f7dd | ||
|
|
b8a0db90a3 | ||
|
|
ec7034f2f1 | ||
|
|
60f0b0940c | ||
|
|
a8da3fa115 | ||
|
|
37373fbdcd | ||
|
|
e96b379620 | ||
|
|
4795c730c9 | ||
|
|
bf4d22b10b | ||
|
|
22806b5657 |
@@ -4,17 +4,17 @@ PVE 系统正式安装之前,需要准备 PVE 的安装镜像和一些必要
|
||||
|
||||
### 0.1. PVE 镜像下载
|
||||
|
||||
PVE 下载地址:https://www.proxmox.com/en/downloads
|
||||
PVE 下载地址:[Proxmox Virtual Environment](https://www.proxmox.com/en/downloads/proxmox-virtual-environment/iso)
|
||||
|
||||
页面中可能有多个 PVE 的安装 ISO ,可以根据需要进行选择,目前以最新的 `Proxmox VE 8.0 ISO` 作为演示。
|
||||
页面中有多个 PVE 相关文件,本文以目前最新的 `Proxmox VE 8.1-1 ISO Installer` 作为演示。
|
||||
|
||||

|
||||
点击 `Proxmox VE 8.x ISO Installer` 链接,进入 PVE 下载页面。
|
||||
|
||||
点击 `Proxmox VE 8.x ISO Installer` 链接。
|
||||

|
||||
|
||||
下载 ISO 时请注意 `SHA256SUM` ,后续将使用该校验信息对下载下来的 ISO 进行校验,以确保 ISO 文件的完整性。
|
||||
|
||||

|
||||

|
||||
|
||||
### 0.2.启动盘制作工具
|
||||
|
||||
@@ -156,7 +156,7 @@ PVE 为最关键的虚拟化层,建议使用强密码,包含大小写字母
|
||||
|
||||
FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
|
||||
|
||||
演示中 FQDN 为 `node01.fox.local` ,因此 PVE 的主机名为 `node01` 。
|
||||
演示中 FQDN 为 `node01.fox.home.arpa` ,因此 PVE 的主机名为 `node01` 。
|
||||
|
||||
根据规划,PVE 的 IPv4 管理地址为 `172.16.1.254` 。
|
||||
|
||||
@@ -166,7 +166,7 @@ FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
|
||||
|
||||
|参数|值|说明|
|
||||
|--|--|--|
|
||||
|Hostname (FQDN)|`node01.fox.local`|设置 PVE `域` 和 `主机名` |
|
||||
|Hostname (FQDN)|`node01.fox.home.arpa`|设置 PVE `域` 和 `主机名` |
|
||||
|IP Address (CIDR)|`172.16.1.254/24`|设置 PVE IPv4 地址|
|
||||
|Gateway|`172.16.1.1`|设置 PVE IPv4 网关|
|
||||
|DNS Server|`172.16.1.1`|设置 PVE IPv4 DNS |
|
||||
|
||||
@@ -64,7 +64,7 @@ deb https://mirrors.ustc.edu.cn/debian-security/ bookworm-security main contrib
|
||||
|
||||
默认情况下,PVE 额外启用了 2 个官方源,且为订阅收费制,因此需要替换为免费源。
|
||||
|
||||
删除 PVE 官方付费软件源,使用以下命令。
|
||||
删除 PVE 官方付费软件源,执行以下命令。
|
||||
|
||||
**注意:rm 为高风险命令,请正确使用,请勿手抖,请勿手抖。**
|
||||
|
||||
@@ -90,7 +90,7 @@ $ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/pve $VERSION_CODENAME pve
|
||||
创建完成后对其进行检查。
|
||||
|
||||
```bash
|
||||
## 检查PVE免费源
|
||||
## 检查 PVE 免费源
|
||||
|
||||
$ cat /etc/apt/sources.list.d/ceph-no-subscription.list
|
||||
|
||||
@@ -116,12 +116,17 @@ deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription
|
||||
由于该功能暂时未被使用,因此本文只做记录。
|
||||
|
||||
```bash
|
||||
## 替换 CT Templates 源
|
||||
|
||||
## 备份 CT Templates 源
|
||||
$ cp /usr/share/perl5/PVE/APLInfo.pm /usr/share/perl5/PVE/APLInfo.pm.bak
|
||||
|
||||
## 替换 CT Templates 链接
|
||||
$ sed -i 's|http://download.proxmox.com|https://mirrors.ustc.edu.cn/proxmox|g' /usr/share/perl5/PVE/APLInfo.pm
|
||||
|
||||
## 重启 PVE API 守护进程
|
||||
$ systemctl restart pvedaemon.service
|
||||
|
||||
## 更新 CT Templates 列表
|
||||
$ pveam update
|
||||
```
|
||||
|
||||
### 1.4.镜像同步
|
||||
@@ -149,20 +154,20 @@ $ apt dist-upgrade
|
||||
|
||||
其中 `unattended-upgrades` 为系统自动更新服务,后续会对其进行配置。
|
||||
|
||||
`cpufrequtils` 为 CPU 调度器的配置工具,后续会对 CPU 调度算法进行调整。
|
||||
`linux-cpupower` 为 CPU 调度器的配置工具,后续会对 CPU 调度算法进行调整。
|
||||
|
||||
```bash
|
||||
## 同步镜像仓库
|
||||
$ apt update
|
||||
|
||||
## 安装系统软件
|
||||
$ apt install htop lm-sensors unzip vim tmux unattended-upgrades powermgmt-base
|
||||
$ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
|
||||
|
||||
## 安装网络工具
|
||||
$ apt install iperf iperf3 iftop
|
||||
$ apt install iperf iperf3 iftop openvswitch-switch
|
||||
|
||||
## 安装 CPU 调度调整工具
|
||||
$ apt install cpufrequtils
|
||||
$ apt install linux-cpupower
|
||||
|
||||
## 根据 CPU 厂商安装 CPU 微码工具
|
||||
$ apt install intel-microcode (amd64-microcode)
|
||||
@@ -194,9 +199,9 @@ $ update-pciids
|
||||
|IPv4|管理地址|`172.16.1.254`|PVE IPv4 地址|
|
||||
||网关地址|`172.16.1.1`|PVE IPv4 网关|
|
||||
||DNS 地址|`172.16.1.1`|PVE IPv4 DNS 服务器|
|
||||
|IPv6|管理地址|`fdac::fe`|PVE IPv6 地址|
|
||||
||网关地址|`-`|IPv6 网关将使用 `LLA` 自动配置|
|
||||
||DNS 地址|`fdac::1`|PVE IPv6 DNS 服务器|
|
||||
|IPv6|管理地址|`fdac::fe`|PVE IPv6 地址(可选)|
|
||||
||网关地址|`-`|IPv6 网关将使用 `SLAAC` 自动配置|
|
||||
||DNS 地址|`fdac::1`|PVE IPv6 DNS 服务器(可选)|
|
||||
|
||||

|
||||
|
||||
@@ -248,11 +253,9 @@ $ update-pciids
|
||||
|
||||
1. 如非特殊需求,通常情况下 PVE 系统无需使用 IPv6 网络。
|
||||
|
||||
2. 根据实际测试,仅 PVE 纯内部网桥( `vmbr4` )可通过主路由获取公网 GUA IPv6 地址。
|
||||
2. 主路由未配置 IPv6 ULA 网段时,例如本文演示地址 `fdac::/64` ,无需填写 `IPv6/CIDR` 参数。
|
||||
|
||||
3. 主路由未配置 ULA IPv6 网段时,例如本文演示地址 `fdac::/64` ,无需填写 `IPv6/CIDR` 参数。
|
||||
|
||||
4. 通常情况下 IPv6 无需填写 `网关` 参数,IPv6 网关将通过 LLA IPv6 地址自动配置。
|
||||
3. 通常情况下 IPv6 无需填写 `网关` 参数,IPv6 网关将通过 LLA IPv6 地址自动配置。
|
||||
|
||||

|
||||
|
||||
@@ -290,9 +293,9 @@ $ update-pciids
|
||||
|
||||
在 PVE 系统的安装过程中,设置了 DNS 的 IPv4 地址 `172.16.1.1` ,但并未设置 DNS 的 IPv6 地址。
|
||||
|
||||
在 PVE 的 DNS 设置页面,手动添加 DNS IPv6 地址,即主路由 LAN 口 ULA IPv6 地址。
|
||||
在 PVE 的 DNS 设置页面,手动添加 DNS IPv6 地址,即主路由 LAN 口 IPv6 ULA 地址。
|
||||
|
||||
同样,若 PVE 不使用 IPv6 网络或主路由未配置 ULA IPv6 网段,本步骤可跳过。
|
||||
同样,若 PVE 不使用 IPv6 网络或主路由未配置 IPv6 ULA 网段,本步骤可跳过。
|
||||
|
||||

|
||||
|
||||
|
||||
@@ -9,13 +9,13 @@
|
||||
$ apt update
|
||||
|
||||
## 安装系统软件
|
||||
$ apt install htop lm-sensors unzip vim tmux unattended-upgrades powermgmt-base
|
||||
$ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
|
||||
|
||||
## 安装网络工具
|
||||
$ apt install iperf iperf3 iftop
|
||||
$ apt install iperf iperf3 iftop openvswitch-switch
|
||||
|
||||
## 安装 CPU 调度调整工具
|
||||
$ apt install cpufrequtils
|
||||
$ apt install linux-cpupower
|
||||
|
||||
## 根据 CPU 厂商安装 CPU 微码工具
|
||||
$ apt install intel-microcode (amd64-microcode)
|
||||
@@ -26,7 +26,7 @@ $ update-pciids
|
||||
|
||||
## 1.系统时区
|
||||
|
||||
如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以使用以下命令修正。
|
||||
如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以执行以下命令修正。
|
||||
|
||||
输出结果如果和北京时间一致,则代表修改正确。
|
||||
|
||||
@@ -82,41 +82,45 @@ MS Name/IP address Stratum Poll Reach LastRx Last sample
|
||||
|
||||
## 2. CPU 调度器
|
||||
|
||||
安装好 `cpufrequtils` 后,需检查 CPU 当前调度器。
|
||||
安装 `linux-cpupower` 后,需检查 CPU 当前调度器。
|
||||
|
||||
```bash
|
||||
## 检查 CPU 当前调度器
|
||||
$ cpufreq-info
|
||||
$ cpupower -c all frequency-info
|
||||
|
||||
#### 设备 CPU - J4125 示例输出
|
||||
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
|
||||
Report errors and bugs to cpufreq@vger.kernel.org, please.
|
||||
analyzing CPU 0:
|
||||
driver: intel_cpufreq
|
||||
CPUs which run at the same hardware frequency: 0
|
||||
CPUs which need to have their frequency coordinated by software: 0
|
||||
maximum transition latency: 20.0 us.
|
||||
maximum transition latency: 20.0 us
|
||||
hardware limits: 800 MHz - 2.70 GHz
|
||||
available cpufreq governors: conservative, ondemand, userspace, powersave, performance, schedutil
|
||||
available cpufreq governors: conservative ondemand userspace powersave performance schedutil
|
||||
current policy: frequency should be within 800 MHz and 2.70 GHz.
|
||||
The governor "ondemand" may decide which speed to use
|
||||
within this range.
|
||||
current CPU frequency is 1.84 GHz.
|
||||
current CPU frequency: Unable to call hardware
|
||||
current CPU frequency: 800 MHz (asserted by call to kernel)
|
||||
boost state support:
|
||||
Supported: yes
|
||||
Active: yes
|
||||
|
||||
#### 设备 CPU - N6005 示例输出
|
||||
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
|
||||
Report errors and bugs to cpufreq@vger.kernel.org, please.
|
||||
analyzing CPU 0:
|
||||
driver: intel_pstate
|
||||
CPUs which run at the same hardware frequency: 0
|
||||
CPUs which need to have their frequency coordinated by software: 0
|
||||
maximum transition latency: 4294.55 ms.
|
||||
maximum transition latency: Cannot determine or is not supported.
|
||||
hardware limits: 800 MHz - 3.30 GHz
|
||||
available cpufreq governors: performance, powersave
|
||||
available cpufreq governors: performance powersave
|
||||
current policy: frequency should be within 800 MHz and 3.30 GHz.
|
||||
The governor "performance" may decide which speed to use
|
||||
within this range.
|
||||
current CPU frequency is 2.00 GHz.
|
||||
current CPU frequency: Unable to call hardware
|
||||
current CPU frequency: 2.00 GHz (asserted by call to kernel)
|
||||
boost state support:
|
||||
Supported: yes
|
||||
Active: yes
|
||||
```
|
||||
|
||||
这里面主要关注两个点:
|
||||
@@ -140,7 +144,7 @@ performance
|
||||
|
||||
CPU 驱动一般不建议手动调整,而 `governor` 后面的参数表示 CPU 当前调度器设置。
|
||||
|
||||
接下来,需要了解 CPU 支持的调度器有哪些,使用以下命令。
|
||||
接下来,需要了解 CPU 支持的调度器有哪些,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 检查 CPU 调度器支持情况
|
||||
@@ -159,30 +163,69 @@ performance powersave
|
||||
|
||||
- CPU 驱动为 `intel_pstate` 时,推荐使用 `powersave` 调度器。
|
||||
|
||||
本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器来编辑 `cpufrequtils` 的配置文件。
|
||||
|
||||
因为该配置文件很长,完整的配置文件可查看 [pve_cpufrequtils.conf](./src/pve_cpufrequtils.conf) 以便对比。
|
||||
|
||||
修改完成后,需要重启 PVE 服务器来使参数生效。
|
||||
本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器创建 `cpupower` 的配置文件。
|
||||
|
||||
```bash
|
||||
## 编辑 cpufrequtils 配置文件
|
||||
$ nano /etc/init.d/cpufrequtils
|
||||
## 创建 cpupower 配置文件
|
||||
$ nano /etc/default/cpupower
|
||||
```
|
||||
|
||||
在配置文件中修改以下配置项,并保存。
|
||||
|
||||
```bash
|
||||
## cpufrequtils 配置项
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize system CPU governors.
|
||||
|
||||
ENABLE="true"
|
||||
GOVERNOR="powersave" ## 修改本行的调度器为 powersave
|
||||
MAX_SPEED="0"
|
||||
MIN_SPEED="0"
|
||||
CPUPOWER_START_OPTS="frequency-set -g powersave"
|
||||
CPUPOWER_STOP_OPTS="frequency-set -g performance"
|
||||
|
||||
```
|
||||
|
||||
PVE 服务器重启完成后需再次查看 CPU 调度器,检验配置文件是否生效。
|
||||
使用 `nano` 编辑器创建 `cpupower` 服务配置文件,以满足系统自动化设置需求。
|
||||
|
||||
```bash
|
||||
## 创建 cpupower 服务配置文件
|
||||
$ nano /etc/systemd/system/cpupower.service
|
||||
```
|
||||
|
||||
在服务配置文件中修改以下配置项,并保存。
|
||||
|
||||
```bash
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize for cpupower systemd service.
|
||||
|
||||
[Unit]
|
||||
Description=Apply cpupower configuration
|
||||
ConditionVirtualization=!container
|
||||
After=syslog.target
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
EnvironmentFile=/etc/default/cpupower
|
||||
ExecStart=/usr/bin/cpupower $CPUPOWER_START_OPTS
|
||||
ExecStop=/usr/bin/cpupower $CPUPOWER_STOP_OPTS
|
||||
RemainAfterExit=yes
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
|
||||
```
|
||||
|
||||
由于修改了服务项,需要执行以下命令进行重载。
|
||||
|
||||
```bash
|
||||
## 服务重载
|
||||
$ systemctl daemon-reload
|
||||
```
|
||||
|
||||
执行以下命令让 `cpupower` 服务开机自启动。
|
||||
|
||||
```bash
|
||||
## 设置 cpupower 服务开机自启
|
||||
$ systemctl enable cpupower.service
|
||||
```
|
||||
|
||||
修改完成后,需重启 PVE 服务器,并再次查看 CPU 调度器,检验配置文件是否生效。
|
||||
|
||||
这里提供两个额外命令,方便实时查看 CPU 当前频率和温度状况。
|
||||
|
||||
@@ -196,9 +239,9 @@ $ watch -d sensors
|
||||
|
||||
## 3. PVE 定时重启
|
||||
|
||||
有时需要让 PVE 服务器周期性的定时重启,则可使用以下命令。
|
||||
有时需要让 PVE 服务器周期性的定时重启,则可执行以下命令。
|
||||
|
||||
参数表示每月 `1` 、 `16` 号的 `5` 点 `0` 分执行系统重启命令。
|
||||
参数表示每月 `1` 、 `16` 号的 `02:30` 执行系统重启命令。
|
||||
|
||||
```bash
|
||||
## 查看系统定时任务
|
||||
@@ -213,7 +256,7 @@ $ crontab -e
|
||||
```bash
|
||||
## 定时任务配置项
|
||||
|
||||
0 5 1,16 * * /usr/sbin/reboot
|
||||
30 2 1,16 * * /usr/sbin/reboot
|
||||
|
||||
```
|
||||
|
||||
@@ -223,7 +266,7 @@ $ crontab -e
|
||||
|
||||
配置系统自动更新之前,需检查系统当前定时器状态。
|
||||
|
||||
后续将手动调整该定时器的时间,使其每 `5` 天凌晨 `02:00` 进行触发。
|
||||
后续将手动调整该定时器的时间,使其每 `5` 天的 `01:30` 进行触发。
|
||||
|
||||
```bash
|
||||
## 检查系统定时器
|
||||
@@ -232,17 +275,16 @@ $ systemctl status apt-daily-upgrade.timer
|
||||
#### 系统定时器示例输出
|
||||
● apt-daily-upgrade.timer - Daily apt upgrade and clean activities
|
||||
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
|
||||
Active: active (waiting) since Fri 2023-06-23 18:55:58 CST; 1 day 18h ago
|
||||
Until: Fri 2023-06-23 18:55:58 CST; 1 day 18h ago
|
||||
Trigger: Mon 2023-06-26 06:26:25 CST; 16h left
|
||||
Active: active (waiting) since Tue 2023-08-01 13:01:19 CST; 27min ago
|
||||
Trigger: Wed 2023-08-02 06:14:50 CST; 16h left
|
||||
Triggers: ● apt-daily-upgrade.service
|
||||
|
||||
Jun 23 18:55:58 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
|
||||
Aug 01 13:01:19 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
|
||||
```
|
||||
|
||||
### 4.2.配置更新策略
|
||||
|
||||
使用以下命令,启用系统自动更新。
|
||||
执行以下命令,启用系统自动更新。
|
||||
|
||||
执行命令后,使用 “左右” 方向键进行选择,“回车” 键进行确认。
|
||||
|
||||
@@ -305,9 +347,9 @@ $ nano /etc/apt/apt.conf.d/50unattended-upgrades
|
||||
|
||||
- 自动重启:开启。
|
||||
|
||||
- 自动重启时间:`05:00` 。
|
||||
- 自动重启时间:`02:30` 。
|
||||
|
||||
因为该配置文件很长,完整的配置文件可查看 [pve_50unattended_upgrades.conf](./src/pve_50unattended_upgrades.conf) 以便对比。
|
||||
因为该配置文件很长,完整的配置文件可查看 [pve_50unattended_upgrades.conf](./src/pve/pve_50unattended_upgrades.conf) 以便对比。
|
||||
|
||||
```bash
|
||||
## 删除以下行前面的注释符 // ,代表启用
|
||||
@@ -334,7 +376,7 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "05:00";
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "02:30";
|
||||
|
||||
```
|
||||
|
||||
@@ -342,7 +384,7 @@ Unattended-Upgrade::Automatic-Reboot-Time "05:00";
|
||||
|
||||
系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。
|
||||
|
||||
完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve_apt_daily_upgrade.conf) 以便对比。
|
||||
完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve/pve_apt_daily_upgrade.conf) 以便对比。
|
||||
|
||||
```bash
|
||||
## 配置系统定时器
|
||||
@@ -356,7 +398,7 @@ $ systemctl edit apt-daily-upgrade.timer
|
||||
|
||||
[Timer]
|
||||
OnCalendar=
|
||||
OnCalendar=02:00
|
||||
OnCalendar=01:30
|
||||
RandomizedDelaySec=0
|
||||
|
||||
```
|
||||
@@ -375,14 +417,13 @@ $ systemctl status apt-daily-upgrade.timer
|
||||
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
|
||||
Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d
|
||||
└─override.conf
|
||||
Active: active (waiting) since Sun 2023-06-25 14:35:06 CST; 9s ago
|
||||
Until: Sun 2023-06-25 14:35:06 CST; 9s ago
|
||||
Trigger: Mon 2023-06-26 02:00:00 CST; 11h left
|
||||
Active: active (waiting) since Tue 2023-08-01 13:37:41 CST; 9s ago
|
||||
Trigger: Wed 2023-08-02 01:30:00 CST; 11h left
|
||||
Triggers: ● apt-daily-upgrade.service
|
||||
|
||||
Jun 25 14:35:06 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
|
||||
Jun 25 14:35:06 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities...
|
||||
Jun 25 14:35:06 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
|
||||
Aug 01 13:37:41 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
|
||||
Aug 01 13:37:41 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities...
|
||||
Aug 01 13:37:41 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
|
||||
```
|
||||
|
||||
## 5.硬件直通
|
||||
@@ -443,7 +484,7 @@ vfio_pci
|
||||
|
||||
```
|
||||
|
||||
使用以下命令更新 `initramfs` ,更新完成后,建议重启 PVE 服务器。
|
||||
执行以下命令更新 `initramfs` ,更新完成后,建议重启 PVE 服务器。
|
||||
|
||||
```bash
|
||||
## 更新 initramfs
|
||||
@@ -452,7 +493,7 @@ $ update-initramfs -u -k all
|
||||
|
||||
### 5.3.检查硬件直通
|
||||
|
||||
PVE 服务器重启完成后,再次使用 SSH 工具登录,并使用以下命令检查硬件直通状态。
|
||||
PVE 服务器重启完成后,再次使用 SSH 工具登录,并执行以下命令检查硬件直通状态。
|
||||
|
||||
主要查看 `IOMMU` 、 `Directed I/O` 或 `Interrupt Remapping` 的启用状态。
|
||||
|
||||
@@ -492,7 +533,7 @@ $ dmesg | grep -e DMAR -e IOMMU -e AMD-Vi
|
||||
[ 2.290568] DMAR: Intel(R) Virtualization Technology for Directed I/O
|
||||
```
|
||||
|
||||
检查系统 `IOMMU` 分组,使用以下命令。
|
||||
检查系统 `IOMMU` 分组,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 检查 IOMMU group
|
||||
@@ -526,7 +567,7 @@ $ find /sys/kernel/iommu_groups/ -type l
|
||||
|
||||
## 6.系统清理
|
||||
|
||||
PVE 系统配置完成后,可逐条执行以下命令,对系统进行清理。
|
||||
PVE 系统配置完成后,可执行以下命令,对系统进行清理。
|
||||
|
||||
```bash
|
||||
## 清理系统软件包
|
||||
@@ -539,10 +580,7 @@ $ rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
|
||||
$ find /var/log/ -type f | xargs rm -rvf
|
||||
|
||||
## 清理命令历史记录文件
|
||||
$ rm -rvf ~/.bash_history
|
||||
|
||||
## 清理命令历史
|
||||
$ history -c
|
||||
$ rm -rvf ~/.bash_history && history -c
|
||||
```
|
||||
|
||||
至此 PVE 的系统调整已经完成。
|
||||
|
||||
@@ -2,7 +2,7 @@
|
||||
|
||||
将虚拟机制作成模板,可在后续新建虚拟机时快速从模板中创建,减少系统安装配置时间。
|
||||
|
||||
该虚拟机模板主要作为内网 DNS 服务器使用,并会安装 Adguard Home 。
|
||||
该虚拟机模板主要用作内网 DNS 服务器,由 `Adguard Home` 或 `SmartDNS` 提供 DNS 解析服务。
|
||||
|
||||
本文将使用 Debian 的云镜像 `debian-12-genericcloud-amd64.qcow2` 作为模板虚拟机的镜像。
|
||||
|
||||
@@ -28,7 +28,7 @@
|
||||
|
||||
### 1.3.系统
|
||||
|
||||
SCSI 控制器保持默认 `VirtIO SCSI single` ,并勾选 `Qemu代理` 选项。
|
||||
SCSI 控制器保持默认 `VirtIO SCSI single` ,机型可选 `q35` ,并勾选 `Qemu代理` 选项。
|
||||
|
||||

|
||||
|
||||
@@ -84,26 +84,23 @@ CPU `类别` 选择 `host` ,`插槽` 与 `核心` 数根据物理 CPU 核心
|
||||
|
||||
### 2.1.删除光驱
|
||||
|
||||
查看虚拟机详情页,在虚拟机硬件配置页面,移除其 `CD/DVD驱动器` 。
|
||||
查看虚拟机详情页,在虚拟机 `硬件` 配置页面,移除其 `CD/DVD驱动器` 。
|
||||
|
||||

|
||||
|
||||
### 2.2.导入镜像文件
|
||||
|
||||
使用 SSH 工具登录 PVE 服务器,并进入 `tmp` 目录,逐条执行以下命令创建一个文件夹。
|
||||
使用 SSH 工具登录 PVE 服务器,并进入 `tmp` 目录,执行以下命令创建一个目录。
|
||||
|
||||
```bash
|
||||
## 进入 tmp 目录
|
||||
$ cd /tmp
|
||||
## 创建存放 Debian 云镜像的临时目录
|
||||
$ mkdir -p /tmp/Debian
|
||||
|
||||
## 创建文件夹
|
||||
$ mkdir Debian
|
||||
|
||||
## 进入文件夹
|
||||
$ cd Debian
|
||||
## 进入目录
|
||||
$ cd /tmp/Debian
|
||||
```
|
||||
|
||||
将 Debian 云镜像传输到该文件夹,并检查 `hash` 。
|
||||
将 Debian 云镜像传输到该目录,并检查 `hash` 。
|
||||
|
||||
```bash
|
||||
## 下载云镜像校验文件
|
||||
@@ -113,7 +110,7 @@ $ wget https://cloud.debian.org/images/cloud/bookworm/latest/SHA512SUMS
|
||||
$ wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2
|
||||
|
||||
## 检查文件是否存在
|
||||
$ ls -la
|
||||
$ ls -lah
|
||||
|
||||
## 显示校验文件内容
|
||||
$ cat SHA512SUMS
|
||||
@@ -122,14 +119,14 @@ $ cat SHA512SUMS
|
||||
$ sha512sum debian-12-genericcloud-amd64.qcow2
|
||||
```
|
||||
|
||||
确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1000` 。
|
||||
确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1001` 。
|
||||
|
||||
```bash
|
||||
## 将 qcow2 镜像导入虚拟机中
|
||||
$ qm importdisk 1000 debian-12-genericcloud-amd64.qcow2 local-lvm
|
||||
$ qm importdisk 1001 debian-12-genericcloud-amd64.qcow2 local-lvm
|
||||
|
||||
#### 镜像导入示例输出
|
||||
Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
|
||||
Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0'
|
||||
```
|
||||
|
||||

|
||||
@@ -160,18 +157,6 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
|
||||
|
||||

|
||||
|
||||
### 2.4.添加串行端口
|
||||
|
||||
部分云镜像需要使用 `serial` 端口作为视频输出端口,否则虚拟机无法启动,因此给模板虚拟机添加串行端口。
|
||||
|
||||
点击顶部 `添加` 菜单,选择 `串行端口` 。
|
||||
|
||||

|
||||
|
||||
串行端口编号为 `0` 。
|
||||
|
||||

|
||||
|
||||
虚拟机硬件设备修改完成后,如下图所示。
|
||||
|
||||

|
||||
@@ -208,7 +193,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
|
||||
|
||||
## 4.设置 Cloud-Init
|
||||
|
||||
进入左侧虚拟机 `Cloud-Init` 菜单,可以看到当前虚拟机的初始化参数。
|
||||
进入左侧虚拟机 `Cloud-Init` 页面,可以看到当前虚拟机的初始化参数。
|
||||
|
||||
### 4.1.自动配置 IPv6
|
||||
|
||||
@@ -218,7 +203,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
|
||||
|--|--|--|
|
||||
|用户|`fox`|新系统的管理员账户|
|
||||
|密码|`********`|使用强密码|
|
||||
|DNS域|`fox.local`|内网域名(可选)|
|
||||
|DNS域|`fox.home.arpa`|内网域名(可选)|
|
||||
|DNS服务器|`172.16.1.1`|本机 DNS 服务器|
|
||||
|SSH公钥|`无`|使用秘钥登录服务器,暂不使用|
|
||||
|Upgrade packages|`是`|启动时更新软件包,保持默认即可|
|
||||
@@ -240,17 +225,17 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
|
||||
|
||||
### 4.2.手动配置 IPv6
|
||||
|
||||
当主路由配置了 ULA IPv6 网段,且希望指定内网 DNS 服务器的 ULA IPv6 地址时,需要调整 `Cloud-Init` 参数。
|
||||
当主路由配置了 IPv6 ULA 网段,且希望指定内网 DNS 服务器的 IPv6 ULA 地址时,需要调整 `Cloud-Init` 参数。
|
||||
|
||||
本文 ULA IPv6 演示地址为 `fdac::/64` ,`DNS服务器` 和 `IP配置` 参数调整如下。
|
||||
本文 IPv6 ULA 演示地址为 `fdac::/64` ,`DNS服务器` 和 `IP配置` 参数调整如下。
|
||||
|
||||
|参数|值|说明|
|
||||
|--|--|--|
|
||||
|DNS域|`fox.local`|内网域名(可选)|
|
||||
|DNS域|`fox.home.arpa`|内网域名(可选)|
|
||||
|DNS服务器|`172.16.1.1 fdac::1`|本机 DNS 服务器|
|
||||
|IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置|
|
||||
|
||||
`DNS服务器` 参数中需要加入主路由 LAN 口 ULA IPv6 地址。
|
||||
`DNS服务器` 参数中需要加入主路由 LAN 口 IPv6 ULA 地址。
|
||||
|
||||

|
||||
|
||||
@@ -260,5 +245,28 @@ IPv6 使用静态地址后,并不影响虚拟机通过主路由获取公网 GU
|
||||
|
||||

|
||||
|
||||
## 5.设置备注信息
|
||||
|
||||
进入左侧虚拟机 `概要` 页面,修改虚拟机的备注信息。
|
||||
|
||||
```bash
|
||||
### 服务器信息
|
||||
|
||||
- 系统: Debian12
|
||||
|
||||
- 用途: 内网 DNS 服务器 ( 模板 )
|
||||
|
||||
- 自启: 否
|
||||
|
||||
- 用户: fox
|
||||
|
||||
- IPv4: 172.16.1.250/24
|
||||
|
||||
- IPv6: SLAAC
|
||||
|
||||
```
|
||||
|
||||

|
||||
|
||||
至此,模板虚拟机创建完成,可将该虚拟机开机。
|
||||
|
||||
|
||||
@@ -112,13 +112,15 @@ $ sudo vim /etc/apt/sources.list.d/debian.sources
|
||||
|
||||
Types: deb
|
||||
URIs: https://mirrors.ustc.edu.cn/debian
|
||||
Suites: bookworm bookworm-updates bookworm-backports
|
||||
Suites: bookworm bookworm-updates
|
||||
Components: main contrib non-free non-free-firmware
|
||||
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
|
||||
|
||||
Types: deb
|
||||
URIs: https://mirrors.ustc.edu.cn/debian-security
|
||||
Suites: bookworm-security
|
||||
Components: main contrib non-free non-free-firmware
|
||||
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
|
||||
|
||||
```
|
||||
|
||||
@@ -137,7 +139,7 @@ $ lsattr /etc/apt/sources.list.d/debian.sources
|
||||
|
||||
### 1.3.安装软件
|
||||
|
||||
软件源设置完成后,需要更新系统,逐行执行以下命令。
|
||||
软件源设置完成后,需要更新系统,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 清理不必要的包
|
||||
@@ -154,13 +156,13 @@ $ sudo apt dist-upgrade
|
||||
|
||||
```bash
|
||||
## 安装系统软件
|
||||
$ sudo apt install qemu-guest-agent zsh git htop tmux cron nftables sshguard
|
||||
$ sudo apt install qemu-guest-agent zsh git htop tmux cron nftables sshguard neovim
|
||||
|
||||
## 安装系统自动更新工具
|
||||
$ sudo apt install unattended-upgrades powermgmt-base python3-gi
|
||||
|
||||
## 安装网络工具
|
||||
$ sudo apt install iperf iperf3 iftop lsof ldnsutils
|
||||
$ sudo apt install iperf iperf3 iftop lsof knot-dnsutils
|
||||
|
||||
## 写入磁盘
|
||||
$ sudo sync
|
||||
@@ -170,40 +172,42 @@ $ sudo sync
|
||||
|
||||
由于该 Debian 虚拟机模板将用于克隆内网 DNS 服务器,因此需要调整内核参数来简单优化性能。
|
||||
|
||||
使用 `vim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
|
||||
使用 `neovim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 编辑 内核参数 配置文件
|
||||
$ sudo vim /etc/sysctl.d/99-sysctl.conf
|
||||
$ sudo nvim /etc/sysctl.d/99-sysctl.conf
|
||||
```
|
||||
|
||||
在配置文件末尾输入以下配置项,注意配置中间的空格。
|
||||
|
||||
```bash
|
||||
# This configuration file is customized by fox
|
||||
# Optimize system parameters
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize sysctl parameters for local DNS server.
|
||||
|
||||
kernel.panic = 20
|
||||
kernel.panic_on_oops = 1
|
||||
|
||||
net.core.default_qdisc = fq_codel
|
||||
net.core.default_qdisc = fq
|
||||
net.ipv4.tcp_congestion_control = bbr
|
||||
|
||||
# Other adjustable system parameters
|
||||
|
||||
net.core.netdev_budget = 600
|
||||
net.core.netdev_budget_usecs = 20000
|
||||
|
||||
net.ipv4.conf.all.log_martians = 1
|
||||
|
||||
net.ipv4.igmp_max_memberships = 100
|
||||
net.ipv4.igmp_max_memberships = 256
|
||||
|
||||
net.ipv4.tcp_challenge_ack_limit = 1000
|
||||
net.ipv4.tcp_fin_timeout = 30
|
||||
net.ipv4.tcp_keepalive_time = 120
|
||||
net.ipv4.tcp_max_orphans = 4096
|
||||
net.ipv4.tcp_max_tw_buckets = 4096
|
||||
net.ipv4.tcp_syncookies = 1
|
||||
|
||||
net.ipv6.conf.all.use_tempaddr = 0
|
||||
net.ipv6.conf.default.use_tempaddr = 0
|
||||
|
||||
```
|
||||
|
||||
保存该配置文件后,重启系统或者执行以下命令让配置生效。
|
||||
@@ -230,14 +234,14 @@ Mon, 26 Jun 2023 16:16:16 +0800
|
||||
|
||||
Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。
|
||||
|
||||
调整 NTP 服务器参数,逐行执行以下命令。
|
||||
调整 NTP 服务器参数,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 NTP 配置文件的文件夹
|
||||
$ sudo mkdir /etc/systemd/timesyncd.conf.d
|
||||
## 创建 NTP 配置文件的目录
|
||||
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d
|
||||
|
||||
## 创建 NTP 配置文件
|
||||
$ sudo vim /etc/systemd/timesyncd.conf.d/server_ntp.conf
|
||||
$ sudo nvim /etc/systemd/timesyncd.conf.d/server_ntp.conf
|
||||
```
|
||||
|
||||
在配置文件中添加以下配置项,并保存。
|
||||
@@ -309,7 +313,7 @@ Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
|
||||
|
||||
```bash
|
||||
## 编辑 20auto-upgrades 配置文件
|
||||
$ sudo vim /etc/apt/apt.conf.d/20auto-upgrades
|
||||
$ sudo nvim /etc/apt/apt.conf.d/20auto-upgrades
|
||||
```
|
||||
|
||||
删除里面全部内容,添加以下配置项,并保存。
|
||||
@@ -330,12 +334,12 @@ APT::Periodic::CleanInterval "1";
|
||||
|
||||
```bash
|
||||
## 编辑 50unattended-upgrades 配置文件
|
||||
$ sudo vim /etc/apt/apt.conf.d/50unattended-upgrades
|
||||
$ sudo nvim /etc/apt/apt.conf.d/50unattended-upgrades
|
||||
```
|
||||
|
||||
根据 “注释” 中相关说明,调整配置文件。
|
||||
|
||||
因为该配置文件很长,完整的配置文件可查看 [debian_50unattended_upgrades.conf](./src/debian_50unattended_upgrades.conf) 以便对比。
|
||||
因为该配置文件很长,完整的配置文件可查看 [debian_dns_50unattended_upgrades.conf](./src/debian/debian_dns_50unattended_upgrades.conf) 以便对比。
|
||||
|
||||
```bash
|
||||
## 删除以下行前面的注释符 // ,代表启用
|
||||
@@ -354,7 +358,7 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "04:30";
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
|
||||
|
||||
```
|
||||
|
||||
@@ -379,7 +383,7 @@ RandomizedDelaySec=0
|
||||
|
||||
设置完成后,重启自动更新定时器并检查其状态,执行以下命令。
|
||||
|
||||
在输出结果中看到系统自动更新的触发时间为凌晨 `02:00` 则表示设置正确。
|
||||
在输出结果中,看到系统自动更新的触发时间为 `02:00` 则表示设置正确。
|
||||
|
||||
```bash
|
||||
## 重启触发器
|
||||
@@ -406,7 +410,7 @@ $ sudo crontab -e
|
||||
```bash
|
||||
## 定时任务配置项
|
||||
|
||||
0 6 8,24 * * /usr/sbin/reboot
|
||||
30 4 8,24 * * /usr/sbin/reboot
|
||||
|
||||
```
|
||||
|
||||
@@ -435,8 +439,6 @@ Do you want to change your default shell to zsh? [Y/n] y
|
||||
|
||||
Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。
|
||||
|
||||
逐条执行以下命令,注意命令中的空格。
|
||||
|
||||
```bash
|
||||
## 清理系统软件包
|
||||
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
|
||||
@@ -448,10 +450,7 @@ $ sudo rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
|
||||
$ sudo find /var/log/ -type f | xargs sudo rm -rvf
|
||||
|
||||
## 清理命令历史记录文件
|
||||
$ rm -rvf ~/.bash_history ~/.zsh_history
|
||||
|
||||
## 清理命令历史
|
||||
$ history -c
|
||||
$ rm -rvf ~/.bash_history ~/.zsh_history ~/.zcompdump* && history -c
|
||||
|
||||
## 关闭系统
|
||||
$ sudo shutdown now
|
||||
|
||||
@@ -0,0 +1,488 @@
|
||||
## 1.克隆虚拟机
|
||||
|
||||
在上一篇文章 [05.PVE制作虚拟机模板](./05.PVE制作虚拟机模板.md) 中,已经制作好了虚拟机模板。
|
||||
|
||||
接下来将使用该模板克隆出新的虚拟机,并安装 Adguard Home 作为内网的 DNS 服务器。
|
||||
|
||||
鼠标 **右键单击** 虚拟机模板,在弹出的菜单中选择 `克隆` 。
|
||||
|
||||

|
||||
|
||||
在弹出的虚拟机克隆对话框中,根据实际情况及下方表格内容,修改虚拟机参数。
|
||||
|
||||
|参数|值|说明|
|
||||
|--|--|--|
|
||||
|目标节点|`node01`|当前 PVE 服务器节点|
|
||||
|VM ID|`201`|可自定义,不能与现存虚拟机 `VM ID` 相同|
|
||||
|名称|`DNS01`|可自定义,`Cloud-Init` 将使用该名称作为虚拟机 `hostname` |
|
||||
|模式|`完整克隆`|选择虚拟机的克隆模式|
|
||||
|目标存储|`local-lvm`|克隆出的虚拟机文件存储位置|
|
||||
|
||||
修改参数后,点击 `克隆` ,即可使用该模板克隆出新的虚拟机。
|
||||
|
||||

|
||||
|
||||
|
||||
## 2.调整 Cloud-Init
|
||||
|
||||
克隆出来的虚拟机的 `Cloud-Init` 参数默认与模板完全一致。
|
||||
|
||||
根据 **内部网络地址** 规划,内网 DNS 服务器 IPv4 地址规划如下:
|
||||
|
||||
- `172.16.1.2/24`
|
||||
|
||||
- `172.16.1.3/24`
|
||||
|
||||
因此需要调整新虚拟机的 `Cloud-Init` 参数。
|
||||
|
||||
- `IP配置` 中的 IPv4 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变。
|
||||
|
||||
- `IP配置` 中的 IPv6 地址参数为 `auto` ,网关保持为空。
|
||||
|
||||
需要注意的是,如果修改了 `用户` 参数,相当于新建了一个系统管理员,之前设置的 `oh-my-zsh` 需要在新管理员下重新设置。
|
||||
|
||||

|
||||
|
||||
当主路由配置了 IPv6 ULA 网段,内网 DNS 服务器 IPv6 ULA 地址规划如下:
|
||||
|
||||
- `fdac::2/64`
|
||||
|
||||
- `fdac::3/64`
|
||||
|
||||
此时需进一步调整新虚拟机的 `Cloud-Init` 参数,让该虚拟机使用指定的 IPv6 ULA 地址,参数如下。
|
||||
|
||||

|
||||
|
||||
## 3.调整配置参数
|
||||
|
||||
在 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) 中提到过,新虚拟机需要修改配置参数才能自动启动。
|
||||
|
||||
进入左侧虚拟机 `选项` 页面,将虚拟机 `开机自启动` 参数设置为 `是` 。
|
||||
|
||||

|
||||
|
||||
鼠标 **双击** `启动/关机顺序` 选项,可调整虚拟机的自动开机参数。
|
||||
|
||||
`启动/关机顺序` 为 `2` ,表示该虚拟机第 `2` 个启动,倒数第 `2` 个关机。
|
||||
|
||||
`启动延时` 为 `10` ,表示该虚拟机在 PVE 启动后,延迟 `10` 秒后自动启动。
|
||||
|
||||

|
||||
|
||||
## 4.调整系统端口
|
||||
|
||||
设置完成后,将该虚拟机开机,使用 SSH 工具登录,并执行以下命令检查端口占用。
|
||||
|
||||
```bash
|
||||
## 检查 53 端口占用
|
||||
$ sudo lsof -n -i :53
|
||||
|
||||
#### 端口占用示例输出
|
||||
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
|
||||
systemd-r 1797 systemd-resolve 18u IPv4 23024 0t0 UDP 127.0.0.53:domain
|
||||
systemd-r 1797 systemd-resolve 19u IPv4 23025 0t0 TCP 127.0.0.53:domain (LISTEN)
|
||||
systemd-r 1797 systemd-resolve 20u IPv4 23026 0t0 UDP 127.0.0.54:domain
|
||||
systemd-r 1797 systemd-resolve 21u IPv4 23027 0t0 TCP 127.0.0.54:domain (LISTEN)
|
||||
```
|
||||
|
||||
当前系统 `53` 端口被 `systemd-resolved.service` 占用,会导致设置 DNS 服务时监听端口失败。
|
||||
|
||||
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 systemd-resolved 配置目录
|
||||
$ sudo mkdir -p /etc/systemd/resolved.conf.d
|
||||
|
||||
## 创建 systemd-resolved 配置文件
|
||||
$ sudo nvim /etc/systemd/resolved.conf.d/server_dns.conf
|
||||
```
|
||||
|
||||
在配置文件中添加以下配置项,并保存。
|
||||
|
||||
```bash
|
||||
## systemd-resolved 配置项
|
||||
|
||||
[Resolve]
|
||||
DNS=127.0.0.1
|
||||
DNS=::1
|
||||
DNSStubListener=no
|
||||
|
||||
```
|
||||
|
||||
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 resolv.conf 软链接
|
||||
$ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
|
||||
```
|
||||
|
||||
配置完成后,需重启 `systemd-resolved.service` 服务,并再次检查系统 `53` 端口占用。
|
||||
|
||||
```bash
|
||||
## 重启 systemd-resolved.service
|
||||
$ sudo systemctl restart systemd-resolved.service
|
||||
```
|
||||
|
||||
## 5. Adguard Home
|
||||
|
||||
`Adguard Home` 将采用 `snap` 形式安装,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 安装 Snap
|
||||
$ sudo apt install snapd
|
||||
|
||||
## 安装 Adguard Home
|
||||
$ sudo snap install adguard-home
|
||||
```
|
||||
|
||||
### 5.1.自动更新
|
||||
|
||||
查看 `Snap` 当前的更新策略,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 显示当前 Snap 自动更新设置
|
||||
$ sudo snap refresh --time
|
||||
```
|
||||
|
||||
将 `Snap` 自动更新时间设置为每天 `2:30-3:30` 和 `14:30-15:30` 两个时间段。
|
||||
|
||||
```bash
|
||||
## 修改 Snap 自动更新时间
|
||||
$ sudo snap set system refresh.timer=2:30-3:30,14:30-15:30
|
||||
|
||||
## 其他 Snap 自动更新时间设置语法参考
|
||||
$ sudo snap set system refresh.timer=mon,2:30,,fri,2:30
|
||||
```
|
||||
|
||||
### 5.2.配置 Adguard Home
|
||||
|
||||
关于 `Adguard Home` 配置相关内容,请参阅 [Adguard Home 折腾手记](https://gitee.com/callmer/agh_toss_notes) 。
|
||||
|
||||
### 5.3.定时任务
|
||||
|
||||
本步骤为可选操作,主要用于设置 `Adguard Home` 定时重启。
|
||||
|
||||
```bash
|
||||
## 查看系统定时任务
|
||||
$ sudo crontab -l
|
||||
|
||||
## 编辑系统定时任务,编辑器选择 nano
|
||||
$ sudo crontab -e
|
||||
```
|
||||
|
||||
在配置文件末尾,增加以下配置项。
|
||||
|
||||
```bash
|
||||
## 定时任务配置项
|
||||
|
||||
30 4 * * * /usr/bin/snap restart adguard-home
|
||||
|
||||
```
|
||||
|
||||
## 6. SmartDNS
|
||||
|
||||
若需使用 `SmartDNS` 代替 `Adguard Home` ,可使用 Debian 官方源进行安装,但其版本通常较为 “过时” 。
|
||||
|
||||
因此,更推荐使用其 Github 仓库中的最新稳定版进行安装,官方仓库请参阅 [pymumu/smartdns](https://github.com/pymumu/smartdns/releases) 。
|
||||
|
||||
多数情况下,`SmartDNS` 足以提供良好的 DNS 解析服务,但为了进一步优化 DNS 解析流程,推荐与 `Dnsmasq` 嵌套使用。
|
||||
|
||||
```bash
|
||||
## 安装 Dnsmasq
|
||||
$ sudo apt install dnsmasq
|
||||
```
|
||||
|
||||
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
|
||||
|
||||
```bash
|
||||
## 检查 dnsmasq.service
|
||||
$ sudo systemctl status dnsmasq.service
|
||||
|
||||
## 设置 dnsmasq.service 开机自启
|
||||
$ sudo systemctl enable dnsmasq.service
|
||||
|
||||
## 停止 dnsmasq.service
|
||||
$ sudo systemctl stop dnsmasq.service
|
||||
```
|
||||
|
||||
下载 `SmartDNS` 最新版本时,请根据系统架构选择合适的版本,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建存放 SmartDNS 安装包的临时目录
|
||||
$ mkdir -p /tmp/SmartDNS
|
||||
|
||||
## 进入目录
|
||||
$ cd /tmp/SmartDNS
|
||||
|
||||
## 下载 SmartDNS 安装包
|
||||
$ curl -LR -O https://github.com/pymumu/smartdns/releases/download/Release45/smartdns.1.2024.02.08-0828.x86_64-linux-all.tar.gz
|
||||
|
||||
## 解压缩 SmartDNS 安装包
|
||||
$ tar zxf smartdns.1.2024.02.08-0828.x86_64-linux-all.tar.gz
|
||||
|
||||
## 进入安装包目录
|
||||
$ cd smartdns
|
||||
|
||||
## 设置脚本可执行权限
|
||||
$ chmod +x ./install
|
||||
|
||||
## 安装 SmartDNS
|
||||
$ sudo ./install -i
|
||||
```
|
||||
|
||||
修改 `SmartDNS` 配置之前,需检查 `smartdns.service` 服务状态,确保该服务开机自启。
|
||||
|
||||
```bash
|
||||
## 检查 smartdns.service
|
||||
$ sudo systemctl status smartdns.service
|
||||
|
||||
## 设置 smartdns.service 开机自启
|
||||
$ sudo systemctl enable smartdns.service
|
||||
```
|
||||
|
||||
### 6.1. SmartDNS 附加配置
|
||||
|
||||
本步骤为可选操作,通过安装 `SmartDNS` 附加配置文件,以达到屏蔽广告或加速中国境内域名解析速度的目的。
|
||||
|
||||
若需使用 `SmartDNS` 屏蔽广告,则需下载广告规则配置文件。
|
||||
|
||||
```bash
|
||||
## 创建 SmartDNS 配置文件目录
|
||||
$ sudo mkdir -p /etc/smartdns.d
|
||||
|
||||
## 下载广告规则配置文件
|
||||
$ sudo curl -LR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
|
||||
```
|
||||
|
||||
`SmartDNS` 的加速规则通过 `bash` 脚本安装,脚本生成的配置文件位于 `/etc/smartdns.d` 目录。
|
||||
|
||||
关于脚本的详细介绍,请参阅 [SmartDNS China List 安装脚本](https://gitee.com/callmer/smartdns_china_list_installer) 。
|
||||
|
||||
```bash
|
||||
## 下载加速规则安装脚本
|
||||
$ sudo curl -LR -o /opt/smartdns_plugin.sh https://gitee.com/callmer/smartdns_china_list_installer/raw/main/smartdns_plugin.sh
|
||||
|
||||
## 设置脚本可执行权限
|
||||
$ sudo chmod +x /opt/smartdns_plugin.sh
|
||||
|
||||
## 设置脚本文件防篡改
|
||||
$ sudo chattr +i /opt/smartdns_plugin.sh
|
||||
|
||||
## 执行脚本
|
||||
$ sudo bash /opt/smartdns_plugin.sh
|
||||
```
|
||||
|
||||
### 6.2. SmartDNS 主配置
|
||||
|
||||
`SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/) 。
|
||||
|
||||
修改 `SmartDNS` 主配置文件之前,建议关闭 `SmartDNS` 并清理 DNS 缓存文件。
|
||||
|
||||
```bash
|
||||
## 关闭 smartdns.service
|
||||
$ sudo systemctl stop smartdns.service
|
||||
|
||||
## 清理缓存
|
||||
$ sudo rm -rvf /var/cache/smartdns
|
||||
|
||||
## 清理进程标识文件
|
||||
$ sudo rm -rvf /var/run/smartdns.pid /run/smartdns.pid
|
||||
```
|
||||
|
||||
`SmartDNS` 的主配置文件一般位于 `/etc/smartdns` 目录下,修改配置文件之前,执行以下命令将其备份。
|
||||
|
||||
```bash
|
||||
## 备份 SmartDNS 主配置文件
|
||||
$ sudo mv /etc/smartdns/smartdns.conf /etc/smartdns/smartdns.conf.bak
|
||||
```
|
||||
|
||||
使用 `neovim` 编辑器创建 `SmartDNS` 主配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 SmartDNS 主配置文件
|
||||
$ sudo nvim /etc/smartdns/smartdns.conf
|
||||
```
|
||||
|
||||
在编辑器对话框中输入以下内容,并保存。
|
||||
|
||||
**额外说明:**
|
||||
|
||||
- 由于修改了缓存路径,`SmartDNS` 的缓存将在系统重启时自动删除,请根据实际情况进行调整
|
||||
|
||||
- `SmartDNS` 端口监听参数为 `6053@lo` ,请根据实际情况进行调整
|
||||
|
||||
- `edns-client-subnet` 为 EDNS 客户端子网,演示中 `202.103.24.68` 为湖北武汉市 DNS 服务器地址,请根据实际情况进行调整
|
||||
|
||||
- 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整
|
||||
|
||||
```bash
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize SmartDNS parameters for local DNS server.
|
||||
#
|
||||
# For use common DNS server as upstream DNS server,
|
||||
# please modify 'server' parameter according to
|
||||
# your network environment.
|
||||
#
|
||||
# eg:
|
||||
# server 119.29.29.29
|
||||
# server 223.5.5.5
|
||||
# server 114.114.114.114
|
||||
# server 2402:4e00::
|
||||
# server 2400:3200::1
|
||||
|
||||
conf-file /etc/smartdns.d/adrules.smartdns.conf
|
||||
|
||||
conf-file /etc/smartdns.d/dns-group.china.smartdns.conf
|
||||
conf-file /etc/smartdns.d/apple.china.smartdns.conf
|
||||
conf-file /etc/smartdns.d/google.china.smartdns.conf
|
||||
conf-file /etc/smartdns.d/accelerated-domains.china.smartdns.conf
|
||||
conf-file /etc/smartdns.d/bogus-nxdomain.china.smartdns.conf
|
||||
|
||||
cache-file /tmp/smartdns.cache
|
||||
|
||||
log-level notice
|
||||
|
||||
bind [::]:6053@lo
|
||||
bind-tcp [::]:6053@lo
|
||||
|
||||
serve-expired yes
|
||||
serve-expired-ttl 64800
|
||||
serve-expired-reply-ttl 3
|
||||
prefetch-domain yes
|
||||
serve-expired-prefetch-time 21600
|
||||
|
||||
force-qtype-SOA 65
|
||||
max-query-limit 1024
|
||||
edns-client-subnet 202.103.24.68
|
||||
|
||||
server-tcp 119.29.29.29 -group dnspod -exclude-default-group
|
||||
server-tcp 2402:4e00:: -group dnspod -exclude-default-group
|
||||
nameserver /doh.pub/dnspod
|
||||
nameserver /dot.pub/dnspod
|
||||
|
||||
server-tcp 223.5.5.5 -group alidns -exclude-default-group
|
||||
server-tcp 2400:3200::1 -group alidns -exclude-default-group
|
||||
nameserver /dns.alidns.com/alidns
|
||||
|
||||
server 172.16.1.1 -group intranet -exclude-default-group
|
||||
nameserver /fox.home.arpa/intranet
|
||||
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
|
||||
|
||||
server-tls dot.pub
|
||||
server-tls dns.alidns.com
|
||||
|
||||
server-https https://doh.pub/dns-query
|
||||
server-https https://dns.alidns.com/dns-query
|
||||
|
||||
```
|
||||
|
||||
### 6.3.定时任务
|
||||
|
||||
本步骤为可选操作,主要用于设置 `SmartDNS` 定时更新附加配置文件和定时重启。
|
||||
|
||||
```bash
|
||||
## 编辑系统定时任务,编辑器选择 nano
|
||||
$ sudo crontab -e
|
||||
```
|
||||
|
||||
在配置文件末尾,增加以下配置项。
|
||||
|
||||
```bash
|
||||
## 定时任务配置项
|
||||
|
||||
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
|
||||
|
||||
30 9 * * * /usr/bin/systemctl restart smartdns.service
|
||||
|
||||
```
|
||||
|
||||
若使用了 `SmartDNS` 加速规则的安装脚本,由于脚本自带服务重启功能,因此定时任务可修改如下。
|
||||
|
||||
```bash
|
||||
## 定时任务配置项
|
||||
|
||||
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
|
||||
|
||||
30 9 * * * /usr/bin/bash /opt/smartdns_plugin.sh
|
||||
```
|
||||
|
||||
### 6.4.配置 Dnsmasq
|
||||
|
||||
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份。
|
||||
|
||||
```bash
|
||||
## 备份 Dnsmasq 主配置文件
|
||||
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
|
||||
```
|
||||
|
||||
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 Dnsmasq 主配置文件
|
||||
$ sudo nvim /etc/dnsmasq.conf
|
||||
```
|
||||
|
||||
在编辑器对话框中输入以下内容,并保存。
|
||||
|
||||
**额外说明:**
|
||||
|
||||
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
|
||||
|
||||
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
|
||||
|
||||
- `Dnsmasq` 有且仅有 `SmartDNS` 作为上游 DNS 服务器
|
||||
|
||||
```bash
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize dnsmasq parameters for local DNS server.
|
||||
|
||||
# Main Config
|
||||
|
||||
conf-dir=/etc/dnsmasq.d/,*.conf
|
||||
conf-file=/etc/dnsmasq.conf
|
||||
|
||||
log-facility=/var/log/dnsmasq.log
|
||||
log-async=20
|
||||
|
||||
cache-size=1024
|
||||
max-cache-ttl=7200
|
||||
edns-packet-max=1232
|
||||
rebind-domain-ok=/fox.home.arpa/
|
||||
|
||||
bind-dynamic
|
||||
bogus-priv
|
||||
domain-needed
|
||||
localise-queries
|
||||
local-service
|
||||
no-hosts
|
||||
no-negcache
|
||||
no-resolv
|
||||
no-round-robin
|
||||
rebind-localhost-ok
|
||||
stop-dns-rebind
|
||||
|
||||
# DNS Filter
|
||||
|
||||
server=/alt/
|
||||
server=/home.arpa/
|
||||
server=/ipv4only.arpa/
|
||||
server=/resolver.arpa/
|
||||
server=/example/
|
||||
server=/bind/
|
||||
server=/invalid/
|
||||
server=/local/
|
||||
server=/localhost/
|
||||
server=/onion/
|
||||
server=/test/
|
||||
|
||||
# DNS Server
|
||||
|
||||
server=/fox.home.arpa/172.16.1.1
|
||||
|
||||
server=127.0.0.1#6053
|
||||
server=::1#6053
|
||||
|
||||
```
|
||||
|
||||
至此,新虚拟机已配置完成,重启后即可作为内网 DNS 服务器使用。
|
||||
|
||||
@@ -1,181 +0,0 @@
|
||||
## 1.克隆虚拟机
|
||||
|
||||
在上一篇文章 [05.PVE制作虚拟机模板](./05.PVE制作虚拟机模板.md) 中,已经制作好了虚拟机模板。
|
||||
|
||||
接下来将使用该模板克隆出新的虚拟机,并安装 Adguard Home 作为内网的 DNS 服务器。
|
||||
|
||||
鼠标 **右键单击** 虚拟机模板,在弹出的菜单中选择 `克隆` 。
|
||||
|
||||

|
||||
|
||||
在弹出的虚拟机克隆对话框中,根据实际情况及下方表格内容,修改虚拟机参数。
|
||||
|
||||
|参数|值|说明|
|
||||
|--|--|--|
|
||||
|目标节点|`node01`|当前 PVE 服务器节点|
|
||||
|VM ID|`201`|可自定义,不能与现存虚拟机 `VM ID` 相同|
|
||||
|名称|`DNS01`|可自定义,`Cloud-Init` 将使用该名称作为虚拟机 `hostname` |
|
||||
|模式|`完整克隆`|选择虚拟机的克隆模式|
|
||||
|目标存储|`local-lvm`|克隆出的虚拟机文件存储位置|
|
||||
|
||||
修改参数后,点击 `克隆` ,即可使用该模板克隆出新的虚拟机。
|
||||
|
||||

|
||||
|
||||
|
||||
## 2.调整 Cloud-Init
|
||||
|
||||
克隆出来的虚拟机的 `Cloud-Init` 参数默认与模板完全一致。
|
||||
|
||||
根据 **内部网络地址** 规划,内网 DNS 服务器 IP 地址分别为:
|
||||
|
||||
- `172.16.1.2/24 (fdac::2/64)`
|
||||
|
||||
- `172.16.1.3/24 (fdac::3/64)`
|
||||
|
||||
因此需要调整新虚拟机的 `Cloud-Init` 参数。
|
||||
|
||||
- `IP配置` 中的 IPv4 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变。
|
||||
|
||||
- `IP配置` 中的 IPv6 地址参数为 `fdac::2/64` ,网关保持为空。
|
||||
|
||||
需要注意的是,如果修改了 `用户` 参数,相当于新建了一个系统管理员,之前设置的 `oh-my-zsh` 需要在新管理员下重新设置。
|
||||
|
||||

|
||||
|
||||
当主路由配置了 ULA IPv6 网段,且指定了内网 DNS 服务器的 ULA IPv6 地址时,参数如下。
|
||||
|
||||

|
||||
|
||||
## 3.调整配置参数
|
||||
|
||||
在 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) 中提到过,新虚拟机需要修改配置参数才能自动启动。
|
||||
|
||||
进入左侧虚拟机 `选项` 页面,将虚拟机 `开机自启动` 参数设置为 `是` 。
|
||||
|
||||

|
||||
|
||||
鼠标 **双击** `启动/关机顺序` 选项,可调整虚拟机的自动开机参数。
|
||||
|
||||
`启动/关机顺序` 为 `2` ,表示该虚拟机第 `2` 个启动,倒数第 `2` 个关机。
|
||||
|
||||
`启动延时` 为 `10` ,表示该虚拟机在 PVE 启动后,延迟 `10` 秒后自动启动。
|
||||
|
||||

|
||||
|
||||
## 4.调整系统端口
|
||||
|
||||
设置完成后,将该虚拟机开机,并使用 SSH 工具登录。
|
||||
|
||||
Adguard Home 需监听系统 `53` 端口来提供 DNS 服务,使用以下命令检查端口占用。
|
||||
|
||||
```bash
|
||||
## 检查 53 端口占用
|
||||
$ sudo lsof -i :53
|
||||
|
||||
#### 端口占用示例输出
|
||||
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
|
||||
systemd-r 347 systemd-resolve 17u IPv4 13445 0t0 UDP localhost:domain
|
||||
systemd-r 347 systemd-resolve 18u IPv4 13446 0t0 TCP localhost:domain (LISTEN)
|
||||
systemd-r 347 systemd-resolve 19u IPv4 13447 0t0 UDP localhost:domain
|
||||
systemd-r 347 systemd-resolve 20u IPv4 13448 0t0 TCP localhost:domain (LISTEN)
|
||||
```
|
||||
|
||||
当前系统 `53` 端口被 `systemd-resolved.service` 占用,会导致 Adguard Home 监听端口失败。
|
||||
|
||||
为了正常使用 Adguard Home ,需要对 `systemd-resolved.service` 进行配置,逐行执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 systemd-resolved 配置文件夹
|
||||
$ sudo mkdir -p /etc/systemd/resolved.conf.d
|
||||
|
||||
## 创建 systemd-resolved 配置文件
|
||||
$ sudo vim /etc/systemd/resolved.conf.d/adguardhome.conf
|
||||
```
|
||||
|
||||
在配置文件中添加以下配置项,并保存。
|
||||
|
||||
```bash
|
||||
## systemd-resolved 配置项
|
||||
|
||||
[Resolve]
|
||||
DNS=127.0.0.1
|
||||
DNSStubListener=no
|
||||
|
||||
```
|
||||
|
||||
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,逐行执行以下命令。
|
||||
|
||||
```bash
|
||||
## 备份 resolv.conf 配置文件
|
||||
$ sudo mv /etc/resolv.conf /etc/resolv.conf.bak
|
||||
|
||||
## 创建 resolv.conf 软链接
|
||||
$ sudo ln -s /run/systemd/resolve/resolv.conf /etc/resolv.conf
|
||||
```
|
||||
|
||||
配置完成后,需重启 `systemd-resolved.service` 服务,并再次检查系统 `53` 端口占用。
|
||||
|
||||
```bash
|
||||
## 重启 systemd-resolved 服务
|
||||
$ sudo systemctl restart systemd-resolved.service
|
||||
```
|
||||
|
||||
## 5.安装 Adguard Home
|
||||
|
||||
Adguard Home 将采用 `snap` 形式安装,逐行执行以下命令。
|
||||
|
||||
```bash
|
||||
## 安装 snap
|
||||
$ sudo apt install snapd
|
||||
|
||||
## 安装 Adguard Home
|
||||
$ sudo snap install adguard-home
|
||||
```
|
||||
|
||||
### 5.1. Snap 自动更新
|
||||
|
||||
查看 Snap 当前的更新策略,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 显示当前 Snap 自动更新设置
|
||||
$ sudo snap refresh --time
|
||||
```
|
||||
|
||||
将 Snap 自动更新时间设置为每天 `2:30-3:30` 和 `14:30-15:30` 两个时间段。
|
||||
|
||||
```bash
|
||||
## 修改 Snap 自动更新时间
|
||||
$ sudo snap set system refresh.timer=2:30-3:30,14:30-15:30
|
||||
|
||||
## 其他 Snap 自动更新时间设置语法参考
|
||||
$ sudo snap set system refresh.timer=mon,2:30,,fri,2:30
|
||||
```
|
||||
|
||||
### 5.2. Snap 定时任务
|
||||
|
||||
本步骤为可选操作,主要设置定时重启 Snap 服务。
|
||||
|
||||
```bash
|
||||
## 查看系统定时任务
|
||||
$ sudo crontab -l
|
||||
|
||||
## 编辑系统定时任务,编辑器选择 nano
|
||||
$ sudo crontab -e
|
||||
```
|
||||
|
||||
在配置文件末尾,增加以下配置项。
|
||||
|
||||
```bash
|
||||
## 定时任务配置项
|
||||
|
||||
0 5 * * * /usr/bin/snap restart adguard-home
|
||||
|
||||
```
|
||||
|
||||
## 6.配置 Adguard Home
|
||||
|
||||
关于 Adguard Home 配置相关内容,请参阅 [Adguard Home 折腾手记](https://gitee.com/callmer/agh_toss_notes) 。
|
||||
|
||||
至此,新虚拟机已配置完成,可作为内网 DNS 服务器使用。
|
||||
|
||||
@@ -0,0 +1,617 @@
|
||||
## 0.前期准备
|
||||
|
||||
某些业务场景下需要构建安全可靠的网络隧道,来打通异地内网环境或从外部访问内网的私有资源。
|
||||
|
||||
经过实际测试,当 TS 服务器具有 IPv6 GUA 地址时,能稳定建立隧道。
|
||||
|
||||
本文将使用 Debian 云镜像以及 `Tailscale` 来制作内网组网服务器。
|
||||
|
||||
对于虚拟机创建部分,请参考 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) ,其他 `Cloud-Init` 相关参数如下。
|
||||
|
||||
|参数|值|说明|
|
||||
|--|--|--|
|
||||
|虚拟机名称|`SVR01`| TS 服务器 `主机名` |
|
||||
|DNS 域|`fox.home.arpa`| TS 服务器 `Cloud-Init` |
|
||||
|DNS 服务器|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|
||||
|IPv4|`172.16.1.4/24`| TS 服务器 `Cloud-Init` |
|
||||
|IPv4 网关|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|
||||
|IPv6|`SLAAC`| TS 服务器 `Cloud-Init` |
|
||||
|
||||
## 1.配置系统
|
||||
|
||||
由于 TS 服务器具备路由功能,所以在配置方法和系统参数方面与内网 DNS 服务器有一些区别。
|
||||
|
||||
### 1.1.配置 SSH
|
||||
|
||||
与配置内网 DNS 服务器时一样,首先需要调整系统的 SSH 登录权限参数。
|
||||
|
||||
在虚拟机的命令行界面,使用 `vim` 编辑器编辑 `sshd` 服务的配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 编辑 ssh 配置文件
|
||||
$ sudo vim /etc/ssh/sshd_config.d/server_sshd.conf
|
||||
```
|
||||
|
||||
在配置文件中添加以下配置项,并保存。
|
||||
|
||||
```bash
|
||||
## SSH 配置项
|
||||
|
||||
PasswordAuthentication yes
|
||||
PermitEmptyPasswords no
|
||||
UseDNS no
|
||||
|
||||
```
|
||||
|
||||
修改完成后,需要重启 SSH 服务。
|
||||
|
||||
```bash
|
||||
## 重启 sshd
|
||||
$ sudo systemctl restart ssh.service
|
||||
```
|
||||
|
||||
### 1.2.配置软件源
|
||||
|
||||
使用 SSH 工具登录 TS 服务器,常用 SSH 工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。
|
||||
|
||||
首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](http://mirrors.ustc.edu.cn/help/debian.html) 镜像站作为演示。
|
||||
|
||||
当系统版本发生变化时,请参考使用 snullp 大叔开发的 [配置生成器](https://mirrors.ustc.edu.cn/repogen/) 。
|
||||
|
||||
使用 `vim` 编辑器编辑 `debian.sources` 配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 编辑 debian.sources 配置文件
|
||||
$ sudo vim /etc/apt/sources.list.d/debian.sources
|
||||
```
|
||||
|
||||
删除里面全部内容,添加以下配置项,并保存。
|
||||
|
||||
```bash
|
||||
## 系统软件源配置项
|
||||
|
||||
Types: deb
|
||||
URIs: https://mirrors.ustc.edu.cn/debian
|
||||
Suites: bookworm bookworm-updates
|
||||
Components: main contrib non-free non-free-firmware
|
||||
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
|
||||
|
||||
Types: deb
|
||||
URIs: https://mirrors.ustc.edu.cn/debian-security
|
||||
Suites: bookworm-security
|
||||
Components: main contrib non-free non-free-firmware
|
||||
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
|
||||
|
||||
```
|
||||
|
||||
为了防止 `Cloud-Init` 服务意外修改软件源配置,需要添加文件保护,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 增加文件保护
|
||||
$ sudo chattr +i /etc/apt/sources.list.d/debian.sources
|
||||
|
||||
## 检查文件保护
|
||||
$ lsattr /etc/apt/sources.list.d/debian.sources
|
||||
|
||||
#### 示例输出
|
||||
----i---------e------- /etc/apt/sources.list.d/debian.sources
|
||||
```
|
||||
|
||||
进一步添加 TS 签名密钥以及软件源,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 添加 TS 签名密钥
|
||||
$ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.noarmor.gpg | sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg > /dev/null
|
||||
|
||||
## 添加 TS 软件源
|
||||
$ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.tailscale-keyring.list | sudo tee /etc/apt/sources.list.d/tailscale.list
|
||||
```
|
||||
|
||||
### 1.3.安装软件
|
||||
|
||||
软件源设置完成后,需要更新系统,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 清理不必要的包
|
||||
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
|
||||
|
||||
## 更新软件源
|
||||
$ sudo apt update
|
||||
|
||||
## 更新系统
|
||||
$ sudo apt dist-upgrade
|
||||
```
|
||||
|
||||
接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。
|
||||
|
||||
```bash
|
||||
## 安装系统软件
|
||||
$ sudo apt install qemu-guest-agent zsh git htop tmux cron nftables sshguard neovim
|
||||
|
||||
## 安装系统自动更新工具
|
||||
$ sudo apt install unattended-upgrades powermgmt-base python3-gi
|
||||
|
||||
## 安装网络工具
|
||||
$ sudo apt install iperf iperf3 iftop lsof knot-dnsutils dnsmasq conntrack
|
||||
|
||||
## 安装 TS
|
||||
$ sudo apt install tailscale
|
||||
|
||||
## 写入磁盘
|
||||
$ sudo sync
|
||||
```
|
||||
|
||||
### 1.4.调整内核模块
|
||||
|
||||
使用 `neovim` 编辑器编辑 **内核模块** 配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 内核模块 配置文件
|
||||
$ sudo nvim /etc/modules-load.d/server_modules.conf
|
||||
```
|
||||
|
||||
在配置文件中添加以下配置项,并保存。
|
||||
|
||||
```bash
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize netfilter related modules at system boot.
|
||||
|
||||
nf_conntrack
|
||||
|
||||
```
|
||||
|
||||
### 1.5.调整内核参数
|
||||
|
||||
使用 `neovim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 编辑 内核参数 配置文件
|
||||
$ sudo nvim /etc/sysctl.d/99-sysctl.conf
|
||||
```
|
||||
|
||||
在配置文件末尾输入以下配置项,注意配置中间的空格。
|
||||
|
||||
```bash
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize sysctl parameters for local TS server.
|
||||
|
||||
kernel.panic = 20
|
||||
kernel.panic_on_oops = 1
|
||||
|
||||
net.core.default_qdisc = fq_codel
|
||||
net.ipv4.tcp_congestion_control = bbr
|
||||
|
||||
net.ipv4.ip_forward = 1
|
||||
|
||||
net.ipv6.conf.all.forwarding = 1
|
||||
net.ipv6.conf.default.forwarding = 1
|
||||
|
||||
# Other adjustable system parameters
|
||||
|
||||
net.core.netdev_budget = 600
|
||||
net.core.netdev_budget_usecs = 20000
|
||||
|
||||
net.core.rps_sock_flow_entries = 32768
|
||||
|
||||
net.ipv4.conf.all.accept_redirects = 0
|
||||
net.ipv4.conf.default.accept_redirects = 0
|
||||
|
||||
net.ipv4.conf.all.accept_source_route = 0
|
||||
net.ipv4.conf.default.accept_source_route = 0
|
||||
|
||||
net.ipv4.conf.all.arp_ignore = 1
|
||||
net.ipv4.conf.default.arp_ignore = 1
|
||||
|
||||
net.ipv4.conf.all.rp_filter = 2
|
||||
net.ipv4.conf.default.rp_filter = 2
|
||||
|
||||
net.ipv4.conf.all.log_martians = 1
|
||||
|
||||
net.ipv4.igmp_max_memberships = 256
|
||||
|
||||
net.ipv4.route.error_burst = 500
|
||||
net.ipv4.route.error_cost = 100
|
||||
|
||||
net.ipv4.route.redirect_load = 2
|
||||
net.ipv4.route.redirect_silence = 2048
|
||||
|
||||
net.ipv4.tcp_challenge_ack_limit = 1000
|
||||
net.ipv4.tcp_fin_timeout = 30
|
||||
net.ipv4.tcp_keepalive_time = 120
|
||||
net.ipv4.tcp_syncookies = 1
|
||||
|
||||
net.ipv6.conf.all.accept_ra = 0
|
||||
net.ipv6.conf.default.accept_ra = 0
|
||||
|
||||
net.ipv6.conf.all.accept_redirects = 0
|
||||
net.ipv6.conf.default.accept_redirects = 0
|
||||
|
||||
net.ipv6.conf.all.accept_source_route = 0
|
||||
net.ipv6.conf.default.accept_source_route = 0
|
||||
|
||||
net.ipv6.conf.all.use_tempaddr = 0
|
||||
net.ipv6.conf.default.use_tempaddr = 0
|
||||
|
||||
net.netfilter.nf_conntrack_acct = 1
|
||||
net.netfilter.nf_conntrack_checksum = 0
|
||||
net.netfilter.nf_conntrack_tcp_timeout_established = 7440
|
||||
|
||||
```
|
||||
|
||||
保存该配置文件后,重启系统或者执行以下命令让配置生效。
|
||||
|
||||
```bash
|
||||
## 让内核参数生效
|
||||
$ sudo sysctl -f
|
||||
```
|
||||
|
||||
### 1.6.调整系统时间
|
||||
|
||||
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
|
||||
|
||||
```bash
|
||||
## 设置系统时区
|
||||
$ sudo timedatectl set-timezone Asia/Shanghai
|
||||
|
||||
## 检查系统时间
|
||||
$ date -R
|
||||
```
|
||||
|
||||
Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。
|
||||
|
||||
调整 NTP 服务器参数,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 NTP 配置文件的目录
|
||||
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d
|
||||
|
||||
## 创建 NTP 配置文件
|
||||
$ sudo nvim /etc/systemd/timesyncd.conf.d/server_ntp.conf
|
||||
```
|
||||
|
||||
在配置文件中添加以下配置项,并保存。
|
||||
|
||||
```bash
|
||||
## NTP 配置项
|
||||
|
||||
[Time]
|
||||
NTP=ntp.tencent.com ntp.aliyun.com
|
||||
|
||||
```
|
||||
|
||||
保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。
|
||||
|
||||
```bash
|
||||
## 重启 chrony 服务
|
||||
$ sudo systemctl restart systemd-timesyncd.service
|
||||
|
||||
## 检查系统 NTP 服务器
|
||||
$ sudo systemctl status systemd-timesyncd.service
|
||||
```
|
||||
|
||||
### 1.7.配置自动更新
|
||||
|
||||
配置系统自动更新策略,执行以下命令,使用键盘 `左右方向键` 进行选择,`回车键` 进行确认。
|
||||
|
||||
```bash
|
||||
## 配置自动更新策略
|
||||
$ sudo dpkg-reconfigure -plow unattended-upgrades
|
||||
|
||||
## 选择 “是” (“YES”)
|
||||
|
||||
#### 系统自动更新示例输出
|
||||
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
|
||||
```
|
||||
|
||||
进一步调整 `20auto-upgrades` 配置文件。
|
||||
|
||||
```bash
|
||||
## 编辑 20auto-upgrades 配置文件
|
||||
$ sudo nvim /etc/apt/apt.conf.d/20auto-upgrades
|
||||
```
|
||||
|
||||
删除里面全部内容,添加以下配置项,并保存。
|
||||
|
||||
配置文件中,用来控制更新周期的参数为 `APT::Periodic::Unattended-Upgrade` ,`7` 表示更新周期为 `7` 天。
|
||||
|
||||
```bash
|
||||
## 系统更新周期配置项
|
||||
|
||||
APT::Periodic::Update-Package-Lists "1";
|
||||
APT::Periodic::Unattended-Upgrade "7";
|
||||
APT::Periodic::AutocleanInterval "1";
|
||||
APT::Periodic::CleanInterval "1";
|
||||
|
||||
```
|
||||
|
||||
进一步调整 `50unattended-upgrades` 配置文件。
|
||||
|
||||
```bash
|
||||
## 编辑 50unattended-upgrades 配置文件
|
||||
$ sudo nvim /etc/apt/apt.conf.d/50unattended-upgrades
|
||||
```
|
||||
|
||||
根据 “注释” 中相关说明,调整配置文件。
|
||||
|
||||
因为该配置文件很长,完整的配置文件可查看 [debian_ts_50unattended_upgrades.conf](./src/debian/debian_ts_50unattended_upgrades.conf) 以便对比。
|
||||
|
||||
```bash
|
||||
## 删除以下行前面的注释符 // ,代表启用
|
||||
|
||||
"origin=Debian,codename=${distro_codename}-updates";
|
||||
|
||||
## 添加 TS 更新项目
|
||||
|
||||
"origin=Tailscale,codename=${distro_codename},label=Tailscale";
|
||||
|
||||
## 在配置文件末尾增加以下配置项,代表启用,并调整参数
|
||||
|
||||
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
|
||||
|
||||
```
|
||||
|
||||
系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 配置系统定时器
|
||||
$ sudo systemctl edit apt-daily-upgrade.timer
|
||||
```
|
||||
|
||||
根据配置文件中的提示,在中间空白处填入以下配置项。
|
||||
|
||||
```bash
|
||||
## 定时器配置项
|
||||
|
||||
[Timer]
|
||||
OnCalendar=
|
||||
OnCalendar=02:00
|
||||
RandomizedDelaySec=0
|
||||
|
||||
```
|
||||
|
||||
设置完成后,重启自动更新定时器并检查其状态,执行以下命令。
|
||||
|
||||
在输出结果中,看到系统自动更新的触发时间为 `02:00` 则表示设置正确。
|
||||
|
||||
```bash
|
||||
## 重启触发器
|
||||
$ sudo systemctl restart apt-daily-upgrade.timer
|
||||
|
||||
## 再次检查触发器状态
|
||||
$ sudo systemctl status apt-daily-upgrade.timer
|
||||
```
|
||||
|
||||
### 1.8.配置防火墙
|
||||
|
||||
修改防火墙配置之前,需检查 `nftables.service` 服务状态,确保该服务开机自启。
|
||||
|
||||
```bash
|
||||
## 检查 nftables.service
|
||||
$ sudo systemctl status nftables.service
|
||||
|
||||
## 设置 nftables.service 开机自启
|
||||
$ sudo systemctl enable nftables.service
|
||||
```
|
||||
|
||||
使用 `neovim` 编辑器修改 `nftables` 配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 备份 nftables 配置文件
|
||||
$ sudo mv /etc/nftables.conf /etc/nftables.conf.bak
|
||||
|
||||
## 创建新的 nftables 配置文件
|
||||
$ sudo nvim /etc/nftables.conf
|
||||
```
|
||||
|
||||
由于防火墙配置文件很长,因此请查阅文件 [debian_ts_nftables.conf](./src/debian/debian_ts_nftables.conf) 进行复制。
|
||||
|
||||
配置完成后,需重启 `nftables.service` 服务。
|
||||
|
||||
```bash
|
||||
## 重启 nftables.service
|
||||
$ sudo systemctl restart nftables.service
|
||||
```
|
||||
|
||||
### 1.9.调整系统端口
|
||||
|
||||
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 systemd-resolved 配置目录
|
||||
$ sudo mkdir -p /etc/systemd/resolved.conf.d
|
||||
|
||||
## 创建 systemd-resolved 配置文件
|
||||
$ sudo nvim /etc/systemd/resolved.conf.d/server_dns.conf
|
||||
```
|
||||
|
||||
在配置文件中添加以下配置项,并保存。
|
||||
|
||||
```bash
|
||||
## systemd-resolved 配置项
|
||||
|
||||
[Resolve]
|
||||
DNS=127.0.0.1
|
||||
DNS=::1
|
||||
DNSStubListener=no
|
||||
|
||||
```
|
||||
|
||||
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 resolv.conf 软链接
|
||||
$ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
|
||||
```
|
||||
|
||||
配置完成后,需重启 `systemd-resolved.service` 服务。
|
||||
|
||||
```bash
|
||||
## 重启 systemd-resolved.service
|
||||
$ sudo systemctl restart systemd-resolved.service
|
||||
```
|
||||
|
||||
### 1.10.配置 Dnsmasq
|
||||
|
||||
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
|
||||
|
||||
```bash
|
||||
## 检查 dnsmasq.service
|
||||
$ sudo systemctl status dnsmasq.service
|
||||
|
||||
## 设置 dnsmasq.service 开机自启
|
||||
$ sudo systemctl enable dnsmasq.service
|
||||
```
|
||||
|
||||
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份。
|
||||
|
||||
```bash
|
||||
## 备份 Dnsmasq 主配置文件
|
||||
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
|
||||
```
|
||||
|
||||
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
|
||||
|
||||
```bash
|
||||
## 创建 Dnsmasq 主配置文件
|
||||
$ sudo nvim /etc/dnsmasq.conf
|
||||
```
|
||||
|
||||
在编辑器对话框中输入以下内容,并保存。
|
||||
|
||||
**额外说明:**
|
||||
|
||||
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
|
||||
|
||||
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
|
||||
|
||||
- `Dnsmasq` 上游 DNS 服务器分为三类,请根据实际情况进行调整
|
||||
- `server=/ts.net/100.100.100.100` :TS 服务 `MagicDNS` 专用 DNS 服务器
|
||||
- `server=/fox.home.arpa/172.16.1.1` :内网域名解析 DNS 服务器,通常为主路由地址
|
||||
- `server` 参数中的其他 DNS 服务器供 TS 服务器自身及其下游设备使用
|
||||
|
||||
```bash
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize dnsmasq parameters for local TS server.
|
||||
|
||||
# Main Config
|
||||
|
||||
conf-dir=/etc/dnsmasq.d/,*.conf
|
||||
conf-file=/etc/dnsmasq.conf
|
||||
|
||||
log-facility=/var/log/dnsmasq.log
|
||||
log-async=20
|
||||
|
||||
cache-size=1024
|
||||
max-cache-ttl=7200
|
||||
edns-packet-max=1232
|
||||
rebind-domain-ok=/fox.home.arpa/
|
||||
|
||||
bind-dynamic
|
||||
bogus-priv
|
||||
domain-needed
|
||||
localise-queries
|
||||
local-service
|
||||
no-hosts
|
||||
no-negcache
|
||||
no-round-robin
|
||||
rebind-localhost-ok
|
||||
stop-dns-rebind
|
||||
|
||||
# DNS Filter
|
||||
|
||||
server=/alt/
|
||||
server=/home.arpa/
|
||||
server=/ipv4only.arpa/
|
||||
server=/resolver.arpa/
|
||||
server=/example/
|
||||
server=/bind/
|
||||
server=/invalid/
|
||||
server=/local/
|
||||
server=/localhost/
|
||||
server=/onion/
|
||||
server=/test/
|
||||
|
||||
# DNS Server
|
||||
|
||||
server=/ts.net/100.100.100.100
|
||||
|
||||
server=/fox.home.arpa/172.16.1.1
|
||||
|
||||
server=172.16.1.1
|
||||
|
||||
```
|
||||
|
||||
配置完成后,需重启 `dnsmasq.service` 服务。
|
||||
|
||||
```bash
|
||||
## 重启 dnsmasq.service
|
||||
$ sudo systemctl restart dnsmasq.service
|
||||
```
|
||||
|
||||
### 1.11.配置 ZSH
|
||||
|
||||
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
|
||||
|
||||
```bash
|
||||
## 返回 home 目录
|
||||
$ cd
|
||||
|
||||
## 使用 curl 安装 oh-my-zsh
|
||||
$ sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)"
|
||||
|
||||
## 或者使用 wget 安装 oh-my-zsh
|
||||
$ sh -c "$(wget https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh -O -)"
|
||||
|
||||
## 询问是否切换默认 shell,输入 Y
|
||||
|
||||
#### 示例输出
|
||||
Time to change your default shell to zsh:
|
||||
Do you want to change your default shell to zsh? [Y/n] y
|
||||
```
|
||||
|
||||
## 2.配置 Tailscale
|
||||
|
||||
根据不同的启动参数,TS 服务将具有不同的业务能力。
|
||||
|
||||
若仅需 TS 组网功能,执行以下命令。
|
||||
|
||||
```bash
|
||||
## TS 普通组网模式
|
||||
$ sudo tailscale up
|
||||
```
|
||||
|
||||
若需 TS 提供 `Exit Node` 功能,执行以下命令。
|
||||
|
||||
```bash
|
||||
## TS Exit Node 模式
|
||||
$ sudo tailscale up --advertise-exit-node --reset
|
||||
|
||||
## TS Exit Node 模式,但不使用 MagicDNS
|
||||
$ sudo tailscale up --advertise-exit-node --accept-dns=false --reset
|
||||
```
|
||||
|
||||
若需 TS 提供内网路由功能并能访问内网私有服务,执行以下命令。
|
||||
|
||||
**额外说明:**
|
||||
|
||||
- 请根据内网网段,调整 TS 内网路由参数 `advertise-routes`
|
||||
|
||||
```bash
|
||||
## TS 内网路由模式
|
||||
$ sudo tailscale up --advertise-exit-node --accept-routes --advertise-routes=172.16.1.0/24 --reset
|
||||
```
|
||||
|
||||
执行命令后,TS 将自动显示登录链接,只需根据链接进行登录操作即可。
|
||||
|
||||
至此,TS 服务器已配置完成。
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
|
||||
点击顶部 `添加` 按钮,添加一个 `备份作业` 。
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.1.常规选项
|
||||
|
||||
@@ -28,7 +28,7 @@
|
||||
|
||||
**额外说明:**
|
||||
|
||||
1. 计划中的 `*-01,16 03:30` 表示每个月的 1、16 日凌晨 03:30 进行备份。
|
||||
1. 计划中的 `*-01,16 03:30` 表示每月 `1` 、`16` 号的 `03:30` 执行备份任务。
|
||||
|
||||
2. `备份作业` 在正确配置收件人邮箱之前,并不能发出邮件。
|
||||
|
||||
@@ -36,13 +36,13 @@
|
||||
|
||||
4. 虚拟机列表中,勾选 `备份作业` 需要备份的虚拟机(可多选)。
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.2.保留选项
|
||||
|
||||
该选项将控制备份文件的保留个数,选择保留最近 `3` 份备份文件。
|
||||
|
||||

|
||||

|
||||
|
||||
### 1.3.日志模板
|
||||
|
||||
@@ -52,7 +52,7 @@
|
||||
|
||||
点击 `创建` 按钮,`备份作业` 创建完成。
|
||||
|
||||

|
||||

|
||||
|
||||
## 2.调度模拟器
|
||||
|
||||
@@ -60,13 +60,13 @@
|
||||
|
||||
鼠标 **单击** 选中一个 `备份作业` ,点击右上角的 `调度模拟器` 。
|
||||
|
||||

|
||||

|
||||
|
||||
`计划` 处将显示 `备份作业` 的执行时间参数,点击 `模拟` 按钮,在右侧将显示模拟的时间结果。
|
||||
|
||||
确认 `备份作业` 的执行时间周期是否符合预期。
|
||||
|
||||

|
||||

|
||||
|
||||
至此,虚拟机的自动备份已配置完成。
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
## 介绍
|
||||
PVE 虚拟化平台的安装以及折腾手记。
|
||||
|
||||
- PVE ISO 版本:8.0-2 (更新时间: 2023-06-22)
|
||||
- PVE ISO 版本:8.1-1 (更新时间: 2023-11-23)
|
||||
|
||||
- 演示机:
|
||||
- CPU:英特尔奔腾 Silver N6005 处理器
|
||||
@@ -18,23 +18,23 @@ PVE 虚拟化平台的安装以及折腾手记。
|
||||
- 网关:`172.16.1.1`
|
||||
- DNS:`172.16.1.1`
|
||||
- IPv6 网络
|
||||
- 前缀:`fdac::/64`
|
||||
- IP 地址:`fdac::fe`
|
||||
- DNS:`fdac::1`
|
||||
- 首选 `SLAAC` 自动配置
|
||||
- IPv6 ULA 网络使用 `fdac::/64` 作为演示
|
||||
|
||||
### 系列章节
|
||||
|
||||
0. [硬件 BIOS 配置](./00.硬件BIOS配置.md)
|
||||
1. [PVE 系统安装](./01.PVE系统安装.md)
|
||||
2. [PVE 初始化配置](./02.PVE初始化配置.md)
|
||||
3. [PVE 系统调整](./03.PVE系统调整.md)
|
||||
4. [PVE 创建模板虚拟机](./04.PVE创建模板虚拟机.md)
|
||||
5. [PVE 制作虚拟机模板](./05.PVE制作虚拟机模板.md)
|
||||
6. [PVE 用模板克隆虚拟机](./06.PVE用模板克隆虚拟机.md)
|
||||
7. [PVE 自动备份虚拟机](./07.PVE自动备份虚拟机.md)
|
||||
0. [硬件 BIOS 配置](./00.硬件BIOS配置.md)
|
||||
1. [PVE 系统安装](./01.PVE系统安装.md)
|
||||
2. [PVE 初始化配置](./02.PVE初始化配置.md)
|
||||
3. [PVE 系统调整](./03.PVE系统调整.md)
|
||||
4. [PVE 创建模板虚拟机](./04.PVE创建模板虚拟机.md)
|
||||
5. [PVE 制作虚拟机模板](./05.PVE制作虚拟机模板.md)
|
||||
6. [PVE 制作 DNS 服务器](./06.PVE制作DNS服务器.md)
|
||||
7. [PVE 制作 TS 服务器](./07.PVE制作TS服务器.md)
|
||||
8. [PVE 自动备份虚拟机](./08.PVE自动备份虚拟机.md)
|
||||
|
||||
### 文章说明
|
||||
|
||||
1. 本系列文章涉及的部分参数需要手动调整来符合切实使用需求。
|
||||
2. 随着 PVE 系统的迭代更新,截图中的内容和实际页面显示可能存在差异。
|
||||
3. 如需引用,请注明本文出处。
|
||||
1. 本系列文章涉及的部分参数需要手动调整来符合切实使用需求。
|
||||
2. 随着 PVE 系统的迭代更新,截图中的内容和实际页面显示可能存在差异。
|
||||
3. 如需引用,请注明本文出处。
|
||||
|
||||
|
Before Width: | Height: | Size: 205 KiB After Width: | Height: | Size: 146 KiB |
|
Before Width: | Height: | Size: 272 KiB After Width: | Height: | Size: 109 KiB |
|
Before Width: | Height: | Size: 283 KiB After Width: | Height: | Size: 115 KiB |
|
Before Width: | Height: | Size: 339 KiB After Width: | Height: | Size: 147 KiB |
|
Before Width: | Height: | Size: 43 KiB After Width: | Height: | Size: 23 KiB |
|
Before Width: | Height: | Size: 279 KiB After Width: | Height: | Size: 114 KiB |
|
Before Width: | Height: | Size: 269 KiB After Width: | Height: | Size: 105 KiB |
|
Before Width: | Height: | Size: 247 KiB After Width: | Height: | Size: 98 KiB |
|
Before Width: | Height: | Size: 216 KiB After Width: | Height: | Size: 76 KiB |
|
Before Width: | Height: | Size: 274 KiB After Width: | Height: | Size: 112 KiB |
|
Before Width: | Height: | Size: 131 KiB After Width: | Height: | Size: 156 KiB |
|
Before Width: | Height: | Size: 204 KiB After Width: | Height: | Size: 51 KiB |
|
Before Width: | Height: | Size: 169 KiB After Width: | Height: | Size: 92 KiB |
|
Before Width: | Height: | Size: 263 KiB After Width: | Height: | Size: 106 KiB |
|
Before Width: | Height: | Size: 413 KiB After Width: | Height: | Size: 401 KiB |
|
Before Width: | Height: | Size: 239 KiB After Width: | Height: | Size: 133 KiB |
|
Before Width: | Height: | Size: 221 KiB After Width: | Height: | Size: 122 KiB |
|
Before Width: | Height: | Size: 74 KiB After Width: | Height: | Size: 73 KiB |
|
Before Width: | Height: | Size: 117 KiB After Width: | Height: | Size: 76 KiB |
|
Before Width: | Height: | Size: 84 KiB After Width: | Height: | Size: 46 KiB |
|
Before Width: | Height: | Size: 76 KiB After Width: | Height: | Size: 78 KiB |
|
Before Width: | Height: | Size: 72 KiB After Width: | Height: | Size: 73 KiB |
|
Before Width: | Height: | Size: 101 KiB After Width: | Height: | Size: 99 KiB |
|
Before Width: | Height: | Size: 108 KiB After Width: | Height: | Size: 107 KiB |
|
Before Width: | Height: | Size: 128 KiB After Width: | Height: | Size: 78 KiB |
|
Before Width: | Height: | Size: 132 KiB After Width: | Height: | Size: 88 KiB |
|
Before Width: | Height: | Size: 173 KiB After Width: | Height: | Size: 124 KiB |
|
Before Width: | Height: | Size: 120 KiB After Width: | Height: | Size: 76 KiB |
|
Before Width: | Height: | Size: 72 KiB After Width: | Height: | Size: 47 KiB |
|
Before Width: | Height: | Size: 136 KiB After Width: | Height: | Size: 80 KiB |
|
Before Width: | Height: | Size: 71 KiB After Width: | Height: | Size: 45 KiB |
|
Before Width: | Height: | Size: 78 KiB After Width: | Height: | Size: 46 KiB |
|
Before Width: | Height: | Size: 114 KiB After Width: | Height: | Size: 71 KiB |
|
Before Width: | Height: | Size: 89 KiB After Width: | Height: | Size: 61 KiB |
|
Before Width: | Height: | Size: 77 KiB After Width: | Height: | Size: 49 KiB |
|
Before Width: | Height: | Size: 98 KiB After Width: | Height: | Size: 66 KiB |
|
After Width: | Height: | Size: 82 KiB |
|
Before Width: | Height: | Size: 92 KiB After Width: | Height: | Size: 56 KiB |
|
Before Width: | Height: | Size: 127 KiB |
|
Before Width: | Height: | Size: 75 KiB |
|
Before Width: | Height: | Size: 84 KiB After Width: | Height: | Size: 55 KiB |
|
Before Width: | Height: | Size: 97 KiB After Width: | Height: | Size: 65 KiB |
|
Before Width: | Height: | Size: 107 KiB After Width: | Height: | Size: 70 KiB |
|
Before Width: | Height: | Size: 66 KiB After Width: | Height: | Size: 55 KiB |
|
Before Width: | Height: | Size: 79 KiB After Width: | Height: | Size: 41 KiB |
|
Before Width: | Height: | Size: 86 KiB After Width: | Height: | Size: 86 KiB |
|
Before Width: | Height: | Size: 88 KiB After Width: | Height: | Size: 88 KiB |
|
Before Width: | Height: | Size: 48 KiB After Width: | Height: | Size: 33 KiB |
|
Before Width: | Height: | Size: 52 KiB After Width: | Height: | Size: 52 KiB |
|
Before Width: | Height: | Size: 136 KiB After Width: | Height: | Size: 136 KiB |
|
Before Width: | Height: | Size: 65 KiB After Width: | Height: | Size: 65 KiB |
|
Before Width: | Height: | Size: 99 KiB After Width: | Height: | Size: 99 KiB |
|
Before Width: | Height: | Size: 114 KiB After Width: | Height: | Size: 114 KiB |
|
Before Width: | Height: | Size: 92 KiB After Width: | Height: | Size: 92 KiB |
@@ -1,177 +1,177 @@
|
||||
// Unattended-Upgrade::Origins-Pattern controls which packages are
|
||||
// upgraded.
|
||||
//
|
||||
// Lines below have the format "keyword=value,...". A
|
||||
// package will be upgraded only if the values in its metadata match
|
||||
// all the supplied keywords in a line. (In other words, omitted
|
||||
// keywords are wild cards.) The keywords originate from the Release
|
||||
// file, but several aliases are accepted. The accepted keywords are:
|
||||
// a,archive,suite (eg, "stable")
|
||||
// c,component (eg, "main", "contrib", "non-free")
|
||||
// l,label (eg, "Debian", "Debian-Security")
|
||||
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
|
||||
// n,codename (eg, "jessie", "jessie-updates")
|
||||
// site (eg, "http.debian.net")
|
||||
// The available values on the system are printed by the command
|
||||
// "apt-cache policy", and can be debugged by running
|
||||
// "unattended-upgrades -d" and looking at the log file.
|
||||
//
|
||||
// Within lines unattended-upgrades allows 2 macros whose values are
|
||||
// derived from /etc/debian_version:
|
||||
// ${distro_id} Installed origin.
|
||||
// ${distro_codename} Installed codename (eg, "buster")
|
||||
Unattended-Upgrade::Origins-Pattern {
|
||||
// Codename based matching:
|
||||
// This will follow the migration of a release through different
|
||||
// archives (e.g. from testing to stable and later oldstable).
|
||||
// Software will be the latest available for the named release,
|
||||
// but the Debian release itself will not be automatically upgraded.
|
||||
"origin=Debian,codename=${distro_codename}-updates";
|
||||
// "origin=Debian,codename=${distro_codename}-proposed-updates";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian-Security";
|
||||
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
|
||||
|
||||
// Archive or Suite based matching:
|
||||
// Note that this will silently match a different release after
|
||||
// migration to the specified archive (e.g. testing becomes the
|
||||
// new stable).
|
||||
// "o=Debian,a=stable";
|
||||
// "o=Debian,a=stable-updates";
|
||||
// "o=Debian,a=proposed-updates";
|
||||
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
|
||||
};
|
||||
|
||||
// Python regular expressions, matching packages to exclude from upgrading
|
||||
Unattended-Upgrade::Package-Blacklist {
|
||||
// The following matches all packages starting with linux-
|
||||
// "linux-";
|
||||
|
||||
// Use $ to explicitely define the end of a package name. Without
|
||||
// the $, "libc6" would match all of them.
|
||||
// "libc6$";
|
||||
// "libc6-dev$";
|
||||
// "libc6-i686$";
|
||||
|
||||
// Special characters need escaping
|
||||
// "libstdc\+\+6$";
|
||||
|
||||
// The following matches packages like xen-system-amd64, xen-utils-4.1,
|
||||
// xenstore-utils and libxenstore3.0
|
||||
// "(lib)?xen(store)?";
|
||||
|
||||
// For more information about Python regular expressions, see
|
||||
// https://docs.python.org/3/howto/regex.html
|
||||
};
|
||||
|
||||
// This option allows you to control if on a unclean dpkg exit
|
||||
// unattended-upgrades will automatically run
|
||||
// dpkg --force-confold --configure -a
|
||||
// The default is true, to ensure updates keep getting installed
|
||||
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
// Split the upgrade into the smallest possible chunks so that
|
||||
// they can be interrupted with SIGTERM. This makes the upgrade
|
||||
// a bit slower but it has the benefit that shutdown while a upgrade
|
||||
// is running is possible (with a small delay)
|
||||
//Unattended-Upgrade::MinimalSteps "true";
|
||||
|
||||
// Install all updates when the machine is shutting down
|
||||
// instead of doing it in the background while the machine is running.
|
||||
// This will (obviously) make shutdown slower.
|
||||
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
|
||||
// This allows more time for unattended-upgrades to shut down gracefully
|
||||
// or even install a few packages in InstallOnShutdown mode, but is still a
|
||||
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
|
||||
// Users enabling InstallOnShutdown mode are advised to increase
|
||||
// InhibitDelayMaxSec even further, possibly to 30 minutes.
|
||||
//Unattended-Upgrade::InstallOnShutdown "false";
|
||||
|
||||
// Send email to this address for problems or packages upgrades
|
||||
// If empty or unset then no email is sent, make sure that you
|
||||
// have a working mail setup on your system. A package that provides
|
||||
// 'mailx' must be installed. E.g. "user@example.com"
|
||||
//Unattended-Upgrade::Mail "";
|
||||
|
||||
// Set this value to one of:
|
||||
// "always", "only-on-error" or "on-change"
|
||||
// If this is not set, then any legacy MailOnlyOnError (boolean) value
|
||||
// is used to chose between "only-on-error" and "on-change"
|
||||
//Unattended-Upgrade::MailReport "on-change";
|
||||
|
||||
// Remove unused automatically installed kernel-related packages
|
||||
// (kernel images, kernel headers and kernel version locked tools).
|
||||
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
// Do automatic removal of newly unused dependencies after the upgrade
|
||||
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
// Do automatic removal of unused packages after the upgrade
|
||||
// (equivalent to apt-get autoremove)
|
||||
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
|
||||
|
||||
// Automatically reboot *WITHOUT CONFIRMATION* if
|
||||
// the file /var/run/reboot-required is found after the upgrade
|
||||
//Unattended-Upgrade::Automatic-Reboot "false";
|
||||
|
||||
// Automatically reboot even if there are users currently logged in
|
||||
// when Unattended-Upgrade::Automatic-Reboot is set to true
|
||||
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
|
||||
|
||||
// If automatic reboot is enabled and needed, reboot at the specific
|
||||
// time instead of immediately
|
||||
// Default: "now"
|
||||
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
|
||||
|
||||
// Use apt bandwidth limit feature, this example limits the download
|
||||
// speed to 70kb/sec
|
||||
//Acquire::http::Dl-Limit "70";
|
||||
|
||||
// Enable logging to syslog. Default is False
|
||||
// Unattended-Upgrade::SyslogEnable "false";
|
||||
|
||||
// Specify syslog facility. Default is daemon
|
||||
// Unattended-Upgrade::SyslogFacility "daemon";
|
||||
|
||||
// Download and install upgrades only on AC power
|
||||
// (i.e. skip or gracefully stop updates on battery)
|
||||
// Unattended-Upgrade::OnlyOnACPower "true";
|
||||
|
||||
// Download and install upgrades only on non-metered connection
|
||||
// (i.e. skip or gracefully stop updates on a metered connection)
|
||||
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
|
||||
|
||||
// Verbose logging
|
||||
// Unattended-Upgrade::Verbose "false";
|
||||
|
||||
// Print debugging information both in unattended-upgrades and
|
||||
// in unattended-upgrade-shutdown
|
||||
// Unattended-Upgrade::Debug "false";
|
||||
|
||||
// Allow package downgrade if Pin-Priority exceeds 1000
|
||||
// Unattended-Upgrade::Allow-downgrade "false";
|
||||
|
||||
// When APT fails to mark a package to be upgraded or installed try adjusting
|
||||
// candidates of related packages to help APT's resolver in finding a solution
|
||||
// where the package can be upgraded or installed.
|
||||
// This is a workaround until APT's resolver is fixed to always find a
|
||||
// solution if it exists. (See Debian bug #711128.)
|
||||
// The fallback is enabled by default, except on Debian's sid release because
|
||||
// uninstallable packages are frequent there.
|
||||
// Disabling the fallback speeds up unattended-upgrades when there are
|
||||
// uninstallable packages at the expense of rarely keeping back packages which
|
||||
// could be upgraded or installed.
|
||||
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
|
||||
|
||||
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "04:30";
|
||||
|
||||
// Unattended-Upgrade::Origins-Pattern controls which packages are
|
||||
// upgraded.
|
||||
//
|
||||
// Lines below have the format "keyword=value,...". A
|
||||
// package will be upgraded only if the values in its metadata match
|
||||
// all the supplied keywords in a line. (In other words, omitted
|
||||
// keywords are wild cards.) The keywords originate from the Release
|
||||
// file, but several aliases are accepted. The accepted keywords are:
|
||||
// a,archive,suite (eg, "stable")
|
||||
// c,component (eg, "main", "contrib", "non-free")
|
||||
// l,label (eg, "Debian", "Debian-Security")
|
||||
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
|
||||
// n,codename (eg, "jessie", "jessie-updates")
|
||||
// site (eg, "http.debian.net")
|
||||
// The available values on the system are printed by the command
|
||||
// "apt-cache policy", and can be debugged by running
|
||||
// "unattended-upgrades -d" and looking at the log file.
|
||||
//
|
||||
// Within lines unattended-upgrades allows 2 macros whose values are
|
||||
// derived from /etc/debian_version:
|
||||
// ${distro_id} Installed origin.
|
||||
// ${distro_codename} Installed codename (eg, "buster")
|
||||
Unattended-Upgrade::Origins-Pattern {
|
||||
// Codename based matching:
|
||||
// This will follow the migration of a release through different
|
||||
// archives (e.g. from testing to stable and later oldstable).
|
||||
// Software will be the latest available for the named release,
|
||||
// but the Debian release itself will not be automatically upgraded.
|
||||
"origin=Debian,codename=${distro_codename}-updates";
|
||||
// "origin=Debian,codename=${distro_codename}-proposed-updates";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian-Security";
|
||||
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
|
||||
|
||||
// Archive or Suite based matching:
|
||||
// Note that this will silently match a different release after
|
||||
// migration to the specified archive (e.g. testing becomes the
|
||||
// new stable).
|
||||
// "o=Debian,a=stable";
|
||||
// "o=Debian,a=stable-updates";
|
||||
// "o=Debian,a=proposed-updates";
|
||||
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
|
||||
};
|
||||
|
||||
// Python regular expressions, matching packages to exclude from upgrading
|
||||
Unattended-Upgrade::Package-Blacklist {
|
||||
// The following matches all packages starting with linux-
|
||||
// "linux-";
|
||||
|
||||
// Use $ to explicitely define the end of a package name. Without
|
||||
// the $, "libc6" would match all of them.
|
||||
// "libc6$";
|
||||
// "libc6-dev$";
|
||||
// "libc6-i686$";
|
||||
|
||||
// Special characters need escaping
|
||||
// "libstdc\+\+6$";
|
||||
|
||||
// The following matches packages like xen-system-amd64, xen-utils-4.1,
|
||||
// xenstore-utils and libxenstore3.0
|
||||
// "(lib)?xen(store)?";
|
||||
|
||||
// For more information about Python regular expressions, see
|
||||
// https://docs.python.org/3/howto/regex.html
|
||||
};
|
||||
|
||||
// This option allows you to control if on a unclean dpkg exit
|
||||
// unattended-upgrades will automatically run
|
||||
// dpkg --force-confold --configure -a
|
||||
// The default is true, to ensure updates keep getting installed
|
||||
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
// Split the upgrade into the smallest possible chunks so that
|
||||
// they can be interrupted with SIGTERM. This makes the upgrade
|
||||
// a bit slower but it has the benefit that shutdown while a upgrade
|
||||
// is running is possible (with a small delay)
|
||||
//Unattended-Upgrade::MinimalSteps "true";
|
||||
|
||||
// Install all updates when the machine is shutting down
|
||||
// instead of doing it in the background while the machine is running.
|
||||
// This will (obviously) make shutdown slower.
|
||||
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
|
||||
// This allows more time for unattended-upgrades to shut down gracefully
|
||||
// or even install a few packages in InstallOnShutdown mode, but is still a
|
||||
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
|
||||
// Users enabling InstallOnShutdown mode are advised to increase
|
||||
// InhibitDelayMaxSec even further, possibly to 30 minutes.
|
||||
//Unattended-Upgrade::InstallOnShutdown "false";
|
||||
|
||||
// Send email to this address for problems or packages upgrades
|
||||
// If empty or unset then no email is sent, make sure that you
|
||||
// have a working mail setup on your system. A package that provides
|
||||
// 'mailx' must be installed. E.g. "user@example.com"
|
||||
//Unattended-Upgrade::Mail "";
|
||||
|
||||
// Set this value to one of:
|
||||
// "always", "only-on-error" or "on-change"
|
||||
// If this is not set, then any legacy MailOnlyOnError (boolean) value
|
||||
// is used to chose between "only-on-error" and "on-change"
|
||||
//Unattended-Upgrade::MailReport "on-change";
|
||||
|
||||
// Remove unused automatically installed kernel-related packages
|
||||
// (kernel images, kernel headers and kernel version locked tools).
|
||||
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
// Do automatic removal of newly unused dependencies after the upgrade
|
||||
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
// Do automatic removal of unused packages after the upgrade
|
||||
// (equivalent to apt-get autoremove)
|
||||
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
|
||||
|
||||
// Automatically reboot *WITHOUT CONFIRMATION* if
|
||||
// the file /var/run/reboot-required is found after the upgrade
|
||||
//Unattended-Upgrade::Automatic-Reboot "false";
|
||||
|
||||
// Automatically reboot even if there are users currently logged in
|
||||
// when Unattended-Upgrade::Automatic-Reboot is set to true
|
||||
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
|
||||
|
||||
// If automatic reboot is enabled and needed, reboot at the specific
|
||||
// time instead of immediately
|
||||
// Default: "now"
|
||||
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
|
||||
|
||||
// Use apt bandwidth limit feature, this example limits the download
|
||||
// speed to 70kb/sec
|
||||
//Acquire::http::Dl-Limit "70";
|
||||
|
||||
// Enable logging to syslog. Default is False
|
||||
// Unattended-Upgrade::SyslogEnable "false";
|
||||
|
||||
// Specify syslog facility. Default is daemon
|
||||
// Unattended-Upgrade::SyslogFacility "daemon";
|
||||
|
||||
// Download and install upgrades only on AC power
|
||||
// (i.e. skip or gracefully stop updates on battery)
|
||||
// Unattended-Upgrade::OnlyOnACPower "true";
|
||||
|
||||
// Download and install upgrades only on non-metered connection
|
||||
// (i.e. skip or gracefully stop updates on a metered connection)
|
||||
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
|
||||
|
||||
// Verbose logging
|
||||
// Unattended-Upgrade::Verbose "false";
|
||||
|
||||
// Print debugging information both in unattended-upgrades and
|
||||
// in unattended-upgrade-shutdown
|
||||
// Unattended-Upgrade::Debug "false";
|
||||
|
||||
// Allow package downgrade if Pin-Priority exceeds 1000
|
||||
// Unattended-Upgrade::Allow-downgrade "false";
|
||||
|
||||
// When APT fails to mark a package to be upgraded or installed try adjusting
|
||||
// candidates of related packages to help APT's resolver in finding a solution
|
||||
// where the package can be upgraded or installed.
|
||||
// This is a workaround until APT's resolver is fixed to always find a
|
||||
// solution if it exists. (See Debian bug #711128.)
|
||||
// The fallback is enabled by default, except on Debian's sid release because
|
||||
// uninstallable packages are frequent there.
|
||||
// Disabling the fallback speeds up unattended-upgrades when there are
|
||||
// uninstallable packages at the expense of rarely keeping back packages which
|
||||
// could be upgraded or installed.
|
||||
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
|
||||
|
||||
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
|
||||
|
||||
@@ -1,25 +1,26 @@
|
||||
# This configuration file is customized by fox
|
||||
# Optimize system parameters
|
||||
|
||||
kernel.panic = 20
|
||||
kernel.panic_on_oops = 1
|
||||
|
||||
net.core.default_qdisc = fq_codel
|
||||
net.ipv4.tcp_congestion_control = bbr
|
||||
|
||||
# Other adjustable system parameters
|
||||
|
||||
net.ipv4.conf.all.log_martians = 1
|
||||
|
||||
net.ipv4.igmp_max_memberships = 100
|
||||
|
||||
net.ipv4.tcp_challenge_ack_limit = 1000
|
||||
net.ipv4.tcp_fin_timeout = 30
|
||||
net.ipv4.tcp_keepalive_time = 120
|
||||
net.ipv4.tcp_max_orphans = 4096
|
||||
net.ipv4.tcp_max_tw_buckets = 4096
|
||||
net.ipv4.tcp_syncookies = 1
|
||||
|
||||
net.ipv6.conf.all.use_tempaddr = 0
|
||||
net.ipv6.conf.default.use_tempaddr = 0
|
||||
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize sysctl parameters for local DNS server.
|
||||
|
||||
kernel.panic = 20
|
||||
kernel.panic_on_oops = 1
|
||||
|
||||
net.core.default_qdisc = fq
|
||||
net.ipv4.tcp_congestion_control = bbr
|
||||
|
||||
# Other adjustable system parameters
|
||||
|
||||
net.core.netdev_budget = 600
|
||||
net.core.netdev_budget_usecs = 20000
|
||||
|
||||
net.ipv4.conf.all.log_martians = 1
|
||||
|
||||
net.ipv4.igmp_max_memberships = 256
|
||||
|
||||
net.ipv4.tcp_challenge_ack_limit = 1000
|
||||
net.ipv4.tcp_fin_timeout = 30
|
||||
net.ipv4.tcp_keepalive_time = 120
|
||||
net.ipv4.tcp_syncookies = 1
|
||||
|
||||
net.ipv6.conf.all.use_tempaddr = 0
|
||||
net.ipv6.conf.default.use_tempaddr = 0
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize dnsmasq parameters for local DNS server.
|
||||
|
||||
# Main Config
|
||||
|
||||
conf-dir=/etc/dnsmasq.d/,*.conf
|
||||
conf-file=/etc/dnsmasq.conf
|
||||
|
||||
log-facility=/var/log/dnsmasq.log
|
||||
log-async=20
|
||||
|
||||
cache-size=1024
|
||||
max-cache-ttl=7200
|
||||
edns-packet-max=1232
|
||||
rebind-domain-ok=/fox.home.arpa/
|
||||
|
||||
bind-dynamic
|
||||
bogus-priv
|
||||
domain-needed
|
||||
localise-queries
|
||||
local-service
|
||||
no-hosts
|
||||
no-negcache
|
||||
no-resolv
|
||||
no-round-robin
|
||||
rebind-localhost-ok
|
||||
stop-dns-rebind
|
||||
|
||||
# DNS Filter
|
||||
|
||||
server=/alt/
|
||||
server=/home.arpa/
|
||||
server=/ipv4only.arpa/
|
||||
server=/resolver.arpa/
|
||||
server=/example/
|
||||
server=/bind/
|
||||
server=/invalid/
|
||||
server=/local/
|
||||
server=/localhost/
|
||||
server=/onion/
|
||||
server=/test/
|
||||
|
||||
# DNS Server
|
||||
|
||||
server=/fox.home.arpa/172.16.1.1
|
||||
|
||||
server=127.0.0.1#6053
|
||||
server=::1#6053
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
## 下载加速规则安装脚本
|
||||
$ sudo curl -LR -o /opt/dnsmasq_plugin.sh https://gitee.com/felixonmars/dnsmasq-china-list/raw/master/install.sh
|
||||
|
||||
## 设置脚本可执行权限
|
||||
$ sudo chmod +x /opt/dnsmasq_plugin.sh
|
||||
|
||||
## 设置脚本文件防篡改
|
||||
$ sudo chattr +i /opt/dnsmasq_plugin.sh
|
||||
|
||||
## 执行脚本
|
||||
$ sudo bash /opt/dnsmasq_plugin.sh
|
||||
|
||||
## 设置 crontab
|
||||
|
||||
25 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/dnsmasq.d/anti-ad.dnsmasq.conf https://anti-ad.net/anti-ad-for-dnsmasq.conf
|
||||
|
||||
35 9 * * * /usr/bin/bash /opt/dnsmasq_plugin.sh
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize SmartDNS parameters for local DNS server.
|
||||
#
|
||||
# For use common DNS server as upstream DNS server,
|
||||
# please modify 'server' parameter according to
|
||||
# your network environment.
|
||||
#
|
||||
# eg:
|
||||
# server 119.29.29.29
|
||||
# server 223.5.5.5
|
||||
# server 114.114.114.114
|
||||
# server 2402:4e00::
|
||||
# server 2400:3200::1
|
||||
|
||||
conf-file /etc/smartdns.d/adrules.smartdns.conf
|
||||
|
||||
conf-file /etc/smartdns.d/dns-group.china.smartdns.conf
|
||||
conf-file /etc/smartdns.d/apple.china.smartdns.conf
|
||||
conf-file /etc/smartdns.d/google.china.smartdns.conf
|
||||
conf-file /etc/smartdns.d/accelerated-domains.china.smartdns.conf
|
||||
conf-file /etc/smartdns.d/bogus-nxdomain.china.smartdns.conf
|
||||
|
||||
cache-file /tmp/smartdns.cache
|
||||
|
||||
log-level notice
|
||||
|
||||
bind [::]:6053@lo
|
||||
bind-tcp [::]:6053@lo
|
||||
|
||||
serve-expired yes
|
||||
serve-expired-ttl 64800
|
||||
serve-expired-reply-ttl 3
|
||||
prefetch-domain yes
|
||||
serve-expired-prefetch-time 21600
|
||||
|
||||
force-qtype-SOA 65
|
||||
max-query-limit 1024
|
||||
edns-client-subnet 202.103.24.68
|
||||
|
||||
server-tcp 119.29.29.29 -group dnspod -exclude-default-group
|
||||
server-tcp 2402:4e00:: -group dnspod -exclude-default-group
|
||||
nameserver /doh.pub/dnspod
|
||||
nameserver /dot.pub/dnspod
|
||||
|
||||
server-tcp 223.5.5.5 -group alidns -exclude-default-group
|
||||
server-tcp 2400:3200::1 -group alidns -exclude-default-group
|
||||
nameserver /dns.alidns.com/alidns
|
||||
|
||||
server 172.16.1.1 -group intranet -exclude-default-group
|
||||
nameserver /fox.home.arpa/intranet
|
||||
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
|
||||
|
||||
server-tls dot.pub
|
||||
server-tls dns.alidns.com
|
||||
|
||||
server-https https://doh.pub/dns-query
|
||||
server-https https://dns.alidns.com/dns-query
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize SmartDNS crontab for local DNS server.
|
||||
|
||||
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
|
||||
|
||||
30 9 * * * /usr/bin/systemctl restart smartdns.service
|
||||
|
||||
|
||||
## Or when the smartdns plugin is installed
|
||||
|
||||
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
|
||||
|
||||
30 9 * * * /usr/bin/bash /opt/smartdns_plugin.sh
|
||||
|
||||
@@ -0,0 +1,72 @@
|
||||
#!/bin/bash
|
||||
set -e
|
||||
|
||||
WORKDIR="$(mktemp -d)"
|
||||
CONFDIR="/etc/smartdns.d"
|
||||
SERVERS=(223.5.5.5 180.184.1.1 119.29.29.29 114.114.114.114)
|
||||
GROUP=(flash)
|
||||
# Others: 223.6.6.6 119.28.28.28
|
||||
# Not using best possible CDN pop: 1.2.4.8 210.2.4.8
|
||||
# Broken?: 180.76.76.76
|
||||
|
||||
CONF_WITH_SERVERS=(accelerated-domains.china google.china apple.china)
|
||||
CONF_WITH_GROUP=(dns-group.china)
|
||||
CONF_SIMPLE=(bogus-nxdomain.china)
|
||||
|
||||
echo "Checking whether the configuration folder exists..."
|
||||
if [ ! -d "$CONFDIR" ]; then
|
||||
mkdir -p "$CONFDIR"
|
||||
fi
|
||||
|
||||
echo "Downloading latest configurations..."
|
||||
git clone --depth=1 https://gitee.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
|
||||
#git clone --depth=1 https://pagure.io/dnsmasq-china-list.git "$WORKDIR"
|
||||
#git clone --depth=1 https://github.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
|
||||
#git clone --depth=1 https://bitbucket.org/felixonmars/dnsmasq-china-list.git "$WORKDIR"
|
||||
#git clone --depth=1 https://gitlab.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
|
||||
#git clone --depth=1 https://e.coding.net/felixonmars/dnsmasq-china-list.git "$WORKDIR"
|
||||
#git clone --depth=1 https://codehub.devcloud.huaweicloud.com/dnsmasq-china-list00001/dnsmasq-china-list.git "$WORKDIR"
|
||||
#git clone --depth=1 http://repo.or.cz/dnsmasq-china-list.git "$WORKDIR"
|
||||
|
||||
echo "Removing old configurations..."
|
||||
for _conf in "${CONF_WITH_SERVERS[@]}" "${CONF_WITH_GROUP[@]}" "${CONF_SIMPLE[@]}"; do
|
||||
rm -f "$CONFDIR/$_conf"*.conf
|
||||
done
|
||||
|
||||
echo "Installing new configurations..."
|
||||
for _conf in "${CONF_WITH_SERVERS[@]}" "${CONF_WITH_GROUP[@]}" "${CONF_SIMPLE[@]}"; do
|
||||
if [[ "${CONF_WITH_SERVERS[@]}" =~ $_conf ]]; then
|
||||
sed -En 's|^server=/([^/]*)/114.114.114.114$|\1|p' "$WORKDIR/$_conf.conf" | grep -Ev '^#' > "$WORKDIR/$_conf.step1.raw"
|
||||
sed -En "s/(.*)/nameserver \\/\\1\\/${GROUP[@]}/p" "$WORKDIR/$_conf.step1.raw" > "$WORKDIR/$_conf.step2.raw"
|
||||
cp "$WORKDIR/$_conf.step2.raw" "$CONFDIR/$_conf.smartdns.conf"
|
||||
fi
|
||||
|
||||
if [[ "${CONF_WITH_GROUP[@]}" =~ $_conf ]]; then
|
||||
for _server in "${SERVERS[@]}"; do
|
||||
echo "server $_server -group ${GROUP[@]} -exclude-default-group" >> "$WORKDIR/$_conf.raw"
|
||||
done
|
||||
cp "$WORKDIR/$_conf.raw" "$CONFDIR/$_conf.smartdns.conf"
|
||||
fi
|
||||
|
||||
if [[ "${CONF_SIMPLE[@]}" =~ $_conf ]]; then
|
||||
sed -e "s|=| |" "$WORKDIR/$_conf.conf" > "$WORKDIR/$_conf.raw"
|
||||
cp "$WORKDIR/$_conf.raw" "$CONFDIR/$_conf.smartdns.conf"
|
||||
fi
|
||||
done
|
||||
|
||||
echo "Restarting smartdns service..."
|
||||
if hash systemctl 2>/dev/null; then
|
||||
systemctl restart smartdns
|
||||
elif hash service 2>/dev/null; then
|
||||
service smartdns restart
|
||||
elif hash rc-service 2>/dev/null; then
|
||||
rc-service smartdns restart
|
||||
elif hash busybox 2>/dev/null && [[ -d "/etc/init.d" ]]; then
|
||||
/etc/init.d/smartdns restart
|
||||
else
|
||||
echo "Now please restart smartdns since I don't know how to do it."
|
||||
fi
|
||||
|
||||
echo "Cleaning up..."
|
||||
rm -r "$WORKDIR"
|
||||
|
||||
@@ -1,10 +1,12 @@
|
||||
Types: deb
|
||||
URIs: https://mirrors.ustc.edu.cn/debian
|
||||
Suites: bookworm bookworm-updates bookworm-backports
|
||||
Suites: bookworm bookworm-updates
|
||||
Components: main contrib non-free non-free-firmware
|
||||
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
|
||||
|
||||
Types: deb
|
||||
URIs: https://mirrors.ustc.edu.cn/debian-security
|
||||
Suites: bookworm-security
|
||||
Components: main contrib non-free non-free-firmware
|
||||
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
APT::Periodic::Update-Package-Lists "1";
|
||||
APT::Periodic::Unattended-Upgrade "7";
|
||||
APT::Periodic::AutocleanInterval "1";
|
||||
APT::Periodic::CleanInterval "1";
|
||||
|
||||
@@ -0,0 +1,178 @@
|
||||
// Unattended-Upgrade::Origins-Pattern controls which packages are
|
||||
// upgraded.
|
||||
//
|
||||
// Lines below have the format "keyword=value,...". A
|
||||
// package will be upgraded only if the values in its metadata match
|
||||
// all the supplied keywords in a line. (In other words, omitted
|
||||
// keywords are wild cards.) The keywords originate from the Release
|
||||
// file, but several aliases are accepted. The accepted keywords are:
|
||||
// a,archive,suite (eg, "stable")
|
||||
// c,component (eg, "main", "contrib", "non-free")
|
||||
// l,label (eg, "Debian", "Debian-Security")
|
||||
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
|
||||
// n,codename (eg, "jessie", "jessie-updates")
|
||||
// site (eg, "http.debian.net")
|
||||
// The available values on the system are printed by the command
|
||||
// "apt-cache policy", and can be debugged by running
|
||||
// "unattended-upgrades -d" and looking at the log file.
|
||||
//
|
||||
// Within lines unattended-upgrades allows 2 macros whose values are
|
||||
// derived from /etc/debian_version:
|
||||
// ${distro_id} Installed origin.
|
||||
// ${distro_codename} Installed codename (eg, "buster")
|
||||
Unattended-Upgrade::Origins-Pattern {
|
||||
// Codename based matching:
|
||||
// This will follow the migration of a release through different
|
||||
// archives (e.g. from testing to stable and later oldstable).
|
||||
// Software will be the latest available for the named release,
|
||||
// but the Debian release itself will not be automatically upgraded.
|
||||
"origin=Debian,codename=${distro_codename}-updates";
|
||||
// "origin=Debian,codename=${distro_codename}-proposed-updates";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian-Security";
|
||||
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
|
||||
"origin=Tailscale,codename=${distro_codename},label=Tailscale";
|
||||
|
||||
// Archive or Suite based matching:
|
||||
// Note that this will silently match a different release after
|
||||
// migration to the specified archive (e.g. testing becomes the
|
||||
// new stable).
|
||||
// "o=Debian,a=stable";
|
||||
// "o=Debian,a=stable-updates";
|
||||
// "o=Debian,a=proposed-updates";
|
||||
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
|
||||
};
|
||||
|
||||
// Python regular expressions, matching packages to exclude from upgrading
|
||||
Unattended-Upgrade::Package-Blacklist {
|
||||
// The following matches all packages starting with linux-
|
||||
// "linux-";
|
||||
|
||||
// Use $ to explicitely define the end of a package name. Without
|
||||
// the $, "libc6" would match all of them.
|
||||
// "libc6$";
|
||||
// "libc6-dev$";
|
||||
// "libc6-i686$";
|
||||
|
||||
// Special characters need escaping
|
||||
// "libstdc\+\+6$";
|
||||
|
||||
// The following matches packages like xen-system-amd64, xen-utils-4.1,
|
||||
// xenstore-utils and libxenstore3.0
|
||||
// "(lib)?xen(store)?";
|
||||
|
||||
// For more information about Python regular expressions, see
|
||||
// https://docs.python.org/3/howto/regex.html
|
||||
};
|
||||
|
||||
// This option allows you to control if on a unclean dpkg exit
|
||||
// unattended-upgrades will automatically run
|
||||
// dpkg --force-confold --configure -a
|
||||
// The default is true, to ensure updates keep getting installed
|
||||
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
// Split the upgrade into the smallest possible chunks so that
|
||||
// they can be interrupted with SIGTERM. This makes the upgrade
|
||||
// a bit slower but it has the benefit that shutdown while a upgrade
|
||||
// is running is possible (with a small delay)
|
||||
//Unattended-Upgrade::MinimalSteps "true";
|
||||
|
||||
// Install all updates when the machine is shutting down
|
||||
// instead of doing it in the background while the machine is running.
|
||||
// This will (obviously) make shutdown slower.
|
||||
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
|
||||
// This allows more time for unattended-upgrades to shut down gracefully
|
||||
// or even install a few packages in InstallOnShutdown mode, but is still a
|
||||
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
|
||||
// Users enabling InstallOnShutdown mode are advised to increase
|
||||
// InhibitDelayMaxSec even further, possibly to 30 minutes.
|
||||
//Unattended-Upgrade::InstallOnShutdown "false";
|
||||
|
||||
// Send email to this address for problems or packages upgrades
|
||||
// If empty or unset then no email is sent, make sure that you
|
||||
// have a working mail setup on your system. A package that provides
|
||||
// 'mailx' must be installed. E.g. "user@example.com"
|
||||
//Unattended-Upgrade::Mail "";
|
||||
|
||||
// Set this value to one of:
|
||||
// "always", "only-on-error" or "on-change"
|
||||
// If this is not set, then any legacy MailOnlyOnError (boolean) value
|
||||
// is used to chose between "only-on-error" and "on-change"
|
||||
//Unattended-Upgrade::MailReport "on-change";
|
||||
|
||||
// Remove unused automatically installed kernel-related packages
|
||||
// (kernel images, kernel headers and kernel version locked tools).
|
||||
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
// Do automatic removal of newly unused dependencies after the upgrade
|
||||
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
// Do automatic removal of unused packages after the upgrade
|
||||
// (equivalent to apt-get autoremove)
|
||||
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
|
||||
|
||||
// Automatically reboot *WITHOUT CONFIRMATION* if
|
||||
// the file /var/run/reboot-required is found after the upgrade
|
||||
//Unattended-Upgrade::Automatic-Reboot "false";
|
||||
|
||||
// Automatically reboot even if there are users currently logged in
|
||||
// when Unattended-Upgrade::Automatic-Reboot is set to true
|
||||
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
|
||||
|
||||
// If automatic reboot is enabled and needed, reboot at the specific
|
||||
// time instead of immediately
|
||||
// Default: "now"
|
||||
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
|
||||
|
||||
// Use apt bandwidth limit feature, this example limits the download
|
||||
// speed to 70kb/sec
|
||||
//Acquire::http::Dl-Limit "70";
|
||||
|
||||
// Enable logging to syslog. Default is False
|
||||
// Unattended-Upgrade::SyslogEnable "false";
|
||||
|
||||
// Specify syslog facility. Default is daemon
|
||||
// Unattended-Upgrade::SyslogFacility "daemon";
|
||||
|
||||
// Download and install upgrades only on AC power
|
||||
// (i.e. skip or gracefully stop updates on battery)
|
||||
// Unattended-Upgrade::OnlyOnACPower "true";
|
||||
|
||||
// Download and install upgrades only on non-metered connection
|
||||
// (i.e. skip or gracefully stop updates on a metered connection)
|
||||
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
|
||||
|
||||
// Verbose logging
|
||||
// Unattended-Upgrade::Verbose "false";
|
||||
|
||||
// Print debugging information both in unattended-upgrades and
|
||||
// in unattended-upgrade-shutdown
|
||||
// Unattended-Upgrade::Debug "false";
|
||||
|
||||
// Allow package downgrade if Pin-Priority exceeds 1000
|
||||
// Unattended-Upgrade::Allow-downgrade "false";
|
||||
|
||||
// When APT fails to mark a package to be upgraded or installed try adjusting
|
||||
// candidates of related packages to help APT's resolver in finding a solution
|
||||
// where the package can be upgraded or installed.
|
||||
// This is a workaround until APT's resolver is fixed to always find a
|
||||
// solution if it exists. (See Debian bug #711128.)
|
||||
// The fallback is enabled by default, except on Debian's sid release because
|
||||
// uninstallable packages are frequent there.
|
||||
// Disabling the fallback speeds up unattended-upgrades when there are
|
||||
// uninstallable packages at the expense of rarely keeping back packages which
|
||||
// could be upgraded or installed.
|
||||
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
|
||||
|
||||
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
|
||||
|
||||
@@ -0,0 +1,64 @@
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize sysctl parameters for local TS server.
|
||||
|
||||
kernel.panic = 20
|
||||
kernel.panic_on_oops = 1
|
||||
|
||||
net.core.default_qdisc = fq_codel
|
||||
net.ipv4.tcp_congestion_control = bbr
|
||||
|
||||
net.ipv4.ip_forward = 1
|
||||
|
||||
net.ipv6.conf.all.forwarding = 1
|
||||
net.ipv6.conf.default.forwarding = 1
|
||||
|
||||
# Other adjustable system parameters
|
||||
|
||||
net.core.netdev_budget = 600
|
||||
net.core.netdev_budget_usecs = 20000
|
||||
|
||||
net.core.rps_sock_flow_entries = 32768
|
||||
|
||||
net.ipv4.conf.all.accept_redirects = 0
|
||||
net.ipv4.conf.default.accept_redirects = 0
|
||||
|
||||
net.ipv4.conf.all.accept_source_route = 0
|
||||
net.ipv4.conf.default.accept_source_route = 0
|
||||
|
||||
net.ipv4.conf.all.arp_ignore = 1
|
||||
net.ipv4.conf.default.arp_ignore = 1
|
||||
|
||||
net.ipv4.conf.all.rp_filter = 2
|
||||
net.ipv4.conf.default.rp_filter = 2
|
||||
|
||||
net.ipv4.conf.all.log_martians = 1
|
||||
|
||||
net.ipv4.igmp_max_memberships = 256
|
||||
|
||||
net.ipv4.route.error_burst = 500
|
||||
net.ipv4.route.error_cost = 100
|
||||
|
||||
net.ipv4.route.redirect_load = 2
|
||||
net.ipv4.route.redirect_silence = 2048
|
||||
|
||||
net.ipv4.tcp_challenge_ack_limit = 1000
|
||||
net.ipv4.tcp_fin_timeout = 30
|
||||
net.ipv4.tcp_keepalive_time = 120
|
||||
net.ipv4.tcp_syncookies = 1
|
||||
|
||||
net.ipv6.conf.all.accept_ra = 0
|
||||
net.ipv6.conf.default.accept_ra = 0
|
||||
|
||||
net.ipv6.conf.all.accept_redirects = 0
|
||||
net.ipv6.conf.default.accept_redirects = 0
|
||||
|
||||
net.ipv6.conf.all.accept_source_route = 0
|
||||
net.ipv6.conf.default.accept_source_route = 0
|
||||
|
||||
net.ipv6.conf.all.use_tempaddr = 0
|
||||
net.ipv6.conf.default.use_tempaddr = 0
|
||||
|
||||
net.netfilter.nf_conntrack_acct = 1
|
||||
net.netfilter.nf_conntrack_checksum = 0
|
||||
net.netfilter.nf_conntrack_tcp_timeout_established = 7440
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize dnsmasq parameters for local TS server.
|
||||
|
||||
# Main Config
|
||||
|
||||
conf-dir=/etc/dnsmasq.d/,*.conf
|
||||
conf-file=/etc/dnsmasq.conf
|
||||
|
||||
log-facility=/var/log/dnsmasq.log
|
||||
log-async=20
|
||||
|
||||
cache-size=1024
|
||||
max-cache-ttl=7200
|
||||
edns-packet-max=1232
|
||||
rebind-domain-ok=/fox.home.arpa/
|
||||
|
||||
bind-dynamic
|
||||
bogus-priv
|
||||
domain-needed
|
||||
localise-queries
|
||||
local-service
|
||||
no-hosts
|
||||
no-negcache
|
||||
no-round-robin
|
||||
rebind-localhost-ok
|
||||
stop-dns-rebind
|
||||
|
||||
# DNS Filter
|
||||
|
||||
server=/alt/
|
||||
server=/home.arpa/
|
||||
server=/ipv4only.arpa/
|
||||
server=/resolver.arpa/
|
||||
server=/example/
|
||||
server=/bind/
|
||||
server=/invalid/
|
||||
server=/local/
|
||||
server=/localhost/
|
||||
server=/onion/
|
||||
server=/test/
|
||||
|
||||
# DNS Server
|
||||
|
||||
server=/ts.net/100.100.100.100
|
||||
|
||||
server=/fox.home.arpa/172.16.1.1
|
||||
|
||||
server=172.16.1.1
|
||||
|
||||
@@ -0,0 +1,177 @@
|
||||
#!/usr/sbin/nft -f
|
||||
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize nftables rules for local TS server.
|
||||
|
||||
table inet router
|
||||
flush table inet router
|
||||
|
||||
table inet router {
|
||||
#
|
||||
# Flowtable
|
||||
#
|
||||
|
||||
flowtable ft {
|
||||
hook ingress priority filter;
|
||||
devices = { eth0 };
|
||||
counter;
|
||||
}
|
||||
|
||||
|
||||
#
|
||||
# Filter rules
|
||||
#
|
||||
|
||||
chain input {
|
||||
type filter hook input priority filter; policy drop;
|
||||
iif "lo" accept comment "defconf: accept traffic from loopback"
|
||||
ct state vmap { established : accept, related : accept } comment "defconf: handle inbound flows"
|
||||
tcp flags syn / fin,syn,rst,ack counter jump syn_flood comment "defconf: rate limit TCP-SYN packets"
|
||||
iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic"
|
||||
iifname "tailscale0" counter jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic"
|
||||
}
|
||||
|
||||
chain forward {
|
||||
type filter hook forward priority filter; policy drop;
|
||||
ct state established,related flow add @ft comment "defconf: track forwarded flows"
|
||||
ct state vmap { established : accept, related : accept } comment "defconf: handle forwarded flows"
|
||||
iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic"
|
||||
iifname "tailscale0" counter jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic"
|
||||
}
|
||||
|
||||
chain output {
|
||||
type filter hook output priority filter; policy accept;
|
||||
oif "lo" accept comment "defconf: accept traffic towards loopback"
|
||||
ct state vmap { established : accept, related : accept } comment "defconf: handle outbound flows"
|
||||
oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic"
|
||||
oifname "tailscale0" counter jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic"
|
||||
}
|
||||
|
||||
chain prerouting {
|
||||
type filter hook prerouting priority filter; policy accept;
|
||||
iifname "eth0" jump helper_lan comment "defconf: handle LAN IPv4 / IPv6 helper assignment"
|
||||
iifname "tailscale0" jump helper_tailscale comment "tsconf: handle TS IPv4 / IPv6 helper assignment"
|
||||
}
|
||||
|
||||
chain syn_flood {
|
||||
limit rate 200/second burst 100 packets return comment "defconf: accept SYN packets below rate-limit"
|
||||
counter drop comment "defconf: drop excess packets"
|
||||
}
|
||||
|
||||
chain input_lan {
|
||||
ct status dnat counter accept comment "lanconf: accept port redirect"
|
||||
jump accept_from_lan
|
||||
}
|
||||
|
||||
chain forward_lan {
|
||||
jump accept_to_tailscale comment "tsconf: accept LAN to TS forward"
|
||||
ct status dnat counter accept comment "lanconf: accept port forward"
|
||||
jump accept_to_lan
|
||||
}
|
||||
|
||||
chain output_lan {
|
||||
jump accept_to_lan
|
||||
}
|
||||
|
||||
chain helper_lan {
|
||||
}
|
||||
|
||||
chain accept_from_lan {
|
||||
iifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
|
||||
}
|
||||
|
||||
chain accept_to_lan {
|
||||
meta nfproto ipv4 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv4 leakage"
|
||||
meta nfproto ipv6 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv6 leakage"
|
||||
oifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
|
||||
}
|
||||
|
||||
chain input_tailscale {
|
||||
jump accept_from_tailscale
|
||||
}
|
||||
|
||||
chain forward_tailscale {
|
||||
counter jump accept_to_lan comment "tsconf: accept TS to LAN forward"
|
||||
counter jump accept_to_tailscale
|
||||
}
|
||||
|
||||
chain output_tailscale {
|
||||
counter jump accept_to_tailscale
|
||||
}
|
||||
|
||||
chain helper_tailscale {
|
||||
}
|
||||
|
||||
chain accept_from_tailscale {
|
||||
iifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
|
||||
}
|
||||
|
||||
chain accept_to_tailscale {
|
||||
oifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
|
||||
}
|
||||
|
||||
|
||||
#
|
||||
# NAT rules
|
||||
#
|
||||
|
||||
chain dstnat {
|
||||
type nat hook prerouting priority dstnat; policy accept;
|
||||
iifname "eth0" meta l4proto { tcp, udp } th dport domain jump dstnat_lan comment "defconf: handle LAN IPv4 / IPv6 dstnat traffic"
|
||||
}
|
||||
|
||||
chain srcnat {
|
||||
type nat hook postrouting priority srcnat; policy accept;
|
||||
oifname "eth0" jump srcnat_lan comment "defconf: handle LAN IPv4 / IPv6 srcnat traffic"
|
||||
}
|
||||
|
||||
chain dstnat_lan {
|
||||
meta nfproto ipv4 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv4 DNS redirect"
|
||||
meta nfproto ipv6 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv6 DNS redirect"
|
||||
}
|
||||
|
||||
chain srcnat_lan {
|
||||
meta nfproto ipv4 counter masquerade comment "defconf: masquerade IPv4 LAN traffic"
|
||||
meta nfproto ipv6 counter masquerade comment "defconf: masquerade IPv6 LAN traffic"
|
||||
}
|
||||
|
||||
|
||||
#
|
||||
# Raw rules (notrack)
|
||||
#
|
||||
|
||||
chain raw_prerouting {
|
||||
type filter hook prerouting priority raw; policy accept;
|
||||
}
|
||||
|
||||
chain raw_output {
|
||||
type filter hook output priority raw; policy accept;
|
||||
}
|
||||
|
||||
|
||||
#
|
||||
# Mangle rules
|
||||
#
|
||||
|
||||
chain mangle_prerouting {
|
||||
type filter hook prerouting priority mangle; policy accept;
|
||||
}
|
||||
|
||||
chain mangle_postrouting {
|
||||
type filter hook postrouting priority mangle; policy accept;
|
||||
}
|
||||
|
||||
chain mangle_input {
|
||||
type filter hook input priority mangle; policy accept;
|
||||
}
|
||||
|
||||
chain mangle_output {
|
||||
type route hook output priority mangle; policy accept;
|
||||
}
|
||||
|
||||
chain mangle_forward {
|
||||
type filter hook forward priority mangle; policy accept;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize netfilter related modules at system boot.
|
||||
|
||||
nf_conntrack
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
APT::Periodic::Update-Package-Lists "1";
|
||||
APT::Periodic::Unattended-Upgrade "5";
|
||||
APT::Periodic::AutocleanInterval "1";
|
||||
APT::Periodic::CleanInterval "1";
|
||||
|
||||
APT::Periodic::Update-Package-Lists "1";
|
||||
APT::Periodic::Unattended-Upgrade "5";
|
||||
APT::Periodic::AutocleanInterval "1";
|
||||
APT::Periodic::CleanInterval "1";
|
||||
|
||||
@@ -1,179 +1,179 @@
|
||||
// Unattended-Upgrade::Origins-Pattern controls which packages are
|
||||
// upgraded.
|
||||
//
|
||||
// Lines below have the format "keyword=value,...". A
|
||||
// package will be upgraded only if the values in its metadata match
|
||||
// all the supplied keywords in a line. (In other words, omitted
|
||||
// keywords are wild cards.) The keywords originate from the Release
|
||||
// file, but several aliases are accepted. The accepted keywords are:
|
||||
// a,archive,suite (eg, "stable")
|
||||
// c,component (eg, "main", "contrib", "non-free")
|
||||
// l,label (eg, "Debian", "Debian-Security")
|
||||
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
|
||||
// n,codename (eg, "jessie", "jessie-updates")
|
||||
// site (eg, "http.debian.net")
|
||||
// The available values on the system are printed by the command
|
||||
// "apt-cache policy", and can be debugged by running
|
||||
// "unattended-upgrades -d" and looking at the log file.
|
||||
//
|
||||
// Within lines unattended-upgrades allows 2 macros whose values are
|
||||
// derived from /etc/debian_version:
|
||||
// ${distro_id} Installed origin.
|
||||
// ${distro_codename} Installed codename (eg, "buster")
|
||||
Unattended-Upgrade::Origins-Pattern {
|
||||
// Codename based matching:
|
||||
// This will follow the migration of a release through different
|
||||
// archives (e.g. from testing to stable and later oldstable).
|
||||
// Software will be the latest available for the named release,
|
||||
// but the Debian release itself will not be automatically upgraded.
|
||||
"origin=Debian,codename=${distro_codename}-updates";
|
||||
// "origin=Debian,codename=${distro_codename}-proposed-updates";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian-Security";
|
||||
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
|
||||
"origin=Proxmox,codename=${distro_codename},label=Proxmox Debian Repository";
|
||||
// "origin=Proxmox,codename=${distro_codename},label=Proxmox Ceph Debian Repository";
|
||||
|
||||
// Archive or Suite based matching:
|
||||
// Note that this will silently match a different release after
|
||||
// migration to the specified archive (e.g. testing becomes the
|
||||
// new stable).
|
||||
// "o=Debian,a=stable";
|
||||
// "o=Debian,a=stable-updates";
|
||||
// "o=Debian,a=proposed-updates";
|
||||
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
|
||||
};
|
||||
|
||||
// Python regular expressions, matching packages to exclude from upgrading
|
||||
Unattended-Upgrade::Package-Blacklist {
|
||||
// The following matches all packages starting with linux-
|
||||
// "linux-";
|
||||
|
||||
// Use $ to explicitely define the end of a package name. Without
|
||||
// the $, "libc6" would match all of them.
|
||||
// "libc6$";
|
||||
// "libc6-dev$";
|
||||
// "libc6-i686$";
|
||||
|
||||
// Special characters need escaping
|
||||
// "libstdc\+\+6$";
|
||||
|
||||
// The following matches packages like xen-system-amd64, xen-utils-4.1,
|
||||
// xenstore-utils and libxenstore3.0
|
||||
// "(lib)?xen(store)?";
|
||||
|
||||
// For more information about Python regular expressions, see
|
||||
// https://docs.python.org/3/howto/regex.html
|
||||
};
|
||||
|
||||
// This option allows you to control if on a unclean dpkg exit
|
||||
// unattended-upgrades will automatically run
|
||||
// dpkg --force-confold --configure -a
|
||||
// The default is true, to ensure updates keep getting installed
|
||||
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
// Split the upgrade into the smallest possible chunks so that
|
||||
// they can be interrupted with SIGTERM. This makes the upgrade
|
||||
// a bit slower but it has the benefit that shutdown while a upgrade
|
||||
// is running is possible (with a small delay)
|
||||
//Unattended-Upgrade::MinimalSteps "true";
|
||||
|
||||
// Install all updates when the machine is shutting down
|
||||
// instead of doing it in the background while the machine is running.
|
||||
// This will (obviously) make shutdown slower.
|
||||
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
|
||||
// This allows more time for unattended-upgrades to shut down gracefully
|
||||
// or even install a few packages in InstallOnShutdown mode, but is still a
|
||||
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
|
||||
// Users enabling InstallOnShutdown mode are advised to increase
|
||||
// InhibitDelayMaxSec even further, possibly to 30 minutes.
|
||||
//Unattended-Upgrade::InstallOnShutdown "false";
|
||||
|
||||
// Send email to this address for problems or packages upgrades
|
||||
// If empty or unset then no email is sent, make sure that you
|
||||
// have a working mail setup on your system. A package that provides
|
||||
// 'mailx' must be installed. E.g. "user@example.com"
|
||||
//Unattended-Upgrade::Mail "";
|
||||
|
||||
// Set this value to one of:
|
||||
// "always", "only-on-error" or "on-change"
|
||||
// If this is not set, then any legacy MailOnlyOnError (boolean) value
|
||||
// is used to chose between "only-on-error" and "on-change"
|
||||
//Unattended-Upgrade::MailReport "on-change";
|
||||
|
||||
// Remove unused automatically installed kernel-related packages
|
||||
// (kernel images, kernel headers and kernel version locked tools).
|
||||
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
// Do automatic removal of newly unused dependencies after the upgrade
|
||||
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
// Do automatic removal of unused packages after the upgrade
|
||||
// (equivalent to apt-get autoremove)
|
||||
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
|
||||
|
||||
// Automatically reboot *WITHOUT CONFIRMATION* if
|
||||
// the file /var/run/reboot-required is found after the upgrade
|
||||
//Unattended-Upgrade::Automatic-Reboot "false";
|
||||
|
||||
// Automatically reboot even if there are users currently logged in
|
||||
// when Unattended-Upgrade::Automatic-Reboot is set to true
|
||||
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
|
||||
|
||||
// If automatic reboot is enabled and needed, reboot at the specific
|
||||
// time instead of immediately
|
||||
// Default: "now"
|
||||
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
|
||||
|
||||
// Use apt bandwidth limit feature, this example limits the download
|
||||
// speed to 70kb/sec
|
||||
//Acquire::http::Dl-Limit "70";
|
||||
|
||||
// Enable logging to syslog. Default is False
|
||||
// Unattended-Upgrade::SyslogEnable "false";
|
||||
|
||||
// Specify syslog facility. Default is daemon
|
||||
// Unattended-Upgrade::SyslogFacility "daemon";
|
||||
|
||||
// Download and install upgrades only on AC power
|
||||
// (i.e. skip or gracefully stop updates on battery)
|
||||
// Unattended-Upgrade::OnlyOnACPower "true";
|
||||
|
||||
// Download and install upgrades only on non-metered connection
|
||||
// (i.e. skip or gracefully stop updates on a metered connection)
|
||||
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
|
||||
|
||||
// Verbose logging
|
||||
// Unattended-Upgrade::Verbose "false";
|
||||
|
||||
// Print debugging information both in unattended-upgrades and
|
||||
// in unattended-upgrade-shutdown
|
||||
// Unattended-Upgrade::Debug "false";
|
||||
|
||||
// Allow package downgrade if Pin-Priority exceeds 1000
|
||||
// Unattended-Upgrade::Allow-downgrade "false";
|
||||
|
||||
// When APT fails to mark a package to be upgraded or installed try adjusting
|
||||
// candidates of related packages to help APT's resolver in finding a solution
|
||||
// where the package can be upgraded or installed.
|
||||
// This is a workaround until APT's resolver is fixed to always find a
|
||||
// solution if it exists. (See Debian bug #711128.)
|
||||
// The fallback is enabled by default, except on Debian's sid release because
|
||||
// uninstallable packages are frequent there.
|
||||
// Disabling the fallback speeds up unattended-upgrades when there are
|
||||
// uninstallable packages at the expense of rarely keeping back packages which
|
||||
// could be upgraded or installed.
|
||||
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
|
||||
|
||||
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "05:00";
|
||||
|
||||
// Unattended-Upgrade::Origins-Pattern controls which packages are
|
||||
// upgraded.
|
||||
//
|
||||
// Lines below have the format "keyword=value,...". A
|
||||
// package will be upgraded only if the values in its metadata match
|
||||
// all the supplied keywords in a line. (In other words, omitted
|
||||
// keywords are wild cards.) The keywords originate from the Release
|
||||
// file, but several aliases are accepted. The accepted keywords are:
|
||||
// a,archive,suite (eg, "stable")
|
||||
// c,component (eg, "main", "contrib", "non-free")
|
||||
// l,label (eg, "Debian", "Debian-Security")
|
||||
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
|
||||
// n,codename (eg, "jessie", "jessie-updates")
|
||||
// site (eg, "http.debian.net")
|
||||
// The available values on the system are printed by the command
|
||||
// "apt-cache policy", and can be debugged by running
|
||||
// "unattended-upgrades -d" and looking at the log file.
|
||||
//
|
||||
// Within lines unattended-upgrades allows 2 macros whose values are
|
||||
// derived from /etc/debian_version:
|
||||
// ${distro_id} Installed origin.
|
||||
// ${distro_codename} Installed codename (eg, "buster")
|
||||
Unattended-Upgrade::Origins-Pattern {
|
||||
// Codename based matching:
|
||||
// This will follow the migration of a release through different
|
||||
// archives (e.g. from testing to stable and later oldstable).
|
||||
// Software will be the latest available for the named release,
|
||||
// but the Debian release itself will not be automatically upgraded.
|
||||
"origin=Debian,codename=${distro_codename}-updates";
|
||||
// "origin=Debian,codename=${distro_codename}-proposed-updates";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian";
|
||||
"origin=Debian,codename=${distro_codename},label=Debian-Security";
|
||||
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
|
||||
"origin=Proxmox,codename=${distro_codename},label=Proxmox Debian Repository";
|
||||
// "origin=Proxmox,codename=${distro_codename},label=Proxmox Ceph Debian Repository";
|
||||
|
||||
// Archive or Suite based matching:
|
||||
// Note that this will silently match a different release after
|
||||
// migration to the specified archive (e.g. testing becomes the
|
||||
// new stable).
|
||||
// "o=Debian,a=stable";
|
||||
// "o=Debian,a=stable-updates";
|
||||
// "o=Debian,a=proposed-updates";
|
||||
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
|
||||
};
|
||||
|
||||
// Python regular expressions, matching packages to exclude from upgrading
|
||||
Unattended-Upgrade::Package-Blacklist {
|
||||
// The following matches all packages starting with linux-
|
||||
// "linux-";
|
||||
|
||||
// Use $ to explicitely define the end of a package name. Without
|
||||
// the $, "libc6" would match all of them.
|
||||
// "libc6$";
|
||||
// "libc6-dev$";
|
||||
// "libc6-i686$";
|
||||
|
||||
// Special characters need escaping
|
||||
// "libstdc\+\+6$";
|
||||
|
||||
// The following matches packages like xen-system-amd64, xen-utils-4.1,
|
||||
// xenstore-utils and libxenstore3.0
|
||||
// "(lib)?xen(store)?";
|
||||
|
||||
// For more information about Python regular expressions, see
|
||||
// https://docs.python.org/3/howto/regex.html
|
||||
};
|
||||
|
||||
// This option allows you to control if on a unclean dpkg exit
|
||||
// unattended-upgrades will automatically run
|
||||
// dpkg --force-confold --configure -a
|
||||
// The default is true, to ensure updates keep getting installed
|
||||
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
// Split the upgrade into the smallest possible chunks so that
|
||||
// they can be interrupted with SIGTERM. This makes the upgrade
|
||||
// a bit slower but it has the benefit that shutdown while a upgrade
|
||||
// is running is possible (with a small delay)
|
||||
//Unattended-Upgrade::MinimalSteps "true";
|
||||
|
||||
// Install all updates when the machine is shutting down
|
||||
// instead of doing it in the background while the machine is running.
|
||||
// This will (obviously) make shutdown slower.
|
||||
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
|
||||
// This allows more time for unattended-upgrades to shut down gracefully
|
||||
// or even install a few packages in InstallOnShutdown mode, but is still a
|
||||
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
|
||||
// Users enabling InstallOnShutdown mode are advised to increase
|
||||
// InhibitDelayMaxSec even further, possibly to 30 minutes.
|
||||
//Unattended-Upgrade::InstallOnShutdown "false";
|
||||
|
||||
// Send email to this address for problems or packages upgrades
|
||||
// If empty or unset then no email is sent, make sure that you
|
||||
// have a working mail setup on your system. A package that provides
|
||||
// 'mailx' must be installed. E.g. "user@example.com"
|
||||
//Unattended-Upgrade::Mail "";
|
||||
|
||||
// Set this value to one of:
|
||||
// "always", "only-on-error" or "on-change"
|
||||
// If this is not set, then any legacy MailOnlyOnError (boolean) value
|
||||
// is used to chose between "only-on-error" and "on-change"
|
||||
//Unattended-Upgrade::MailReport "on-change";
|
||||
|
||||
// Remove unused automatically installed kernel-related packages
|
||||
// (kernel images, kernel headers and kernel version locked tools).
|
||||
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
// Do automatic removal of newly unused dependencies after the upgrade
|
||||
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
// Do automatic removal of unused packages after the upgrade
|
||||
// (equivalent to apt-get autoremove)
|
||||
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
|
||||
|
||||
// Automatically reboot *WITHOUT CONFIRMATION* if
|
||||
// the file /var/run/reboot-required is found after the upgrade
|
||||
//Unattended-Upgrade::Automatic-Reboot "false";
|
||||
|
||||
// Automatically reboot even if there are users currently logged in
|
||||
// when Unattended-Upgrade::Automatic-Reboot is set to true
|
||||
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
|
||||
|
||||
// If automatic reboot is enabled and needed, reboot at the specific
|
||||
// time instead of immediately
|
||||
// Default: "now"
|
||||
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
|
||||
|
||||
// Use apt bandwidth limit feature, this example limits the download
|
||||
// speed to 70kb/sec
|
||||
//Acquire::http::Dl-Limit "70";
|
||||
|
||||
// Enable logging to syslog. Default is False
|
||||
// Unattended-Upgrade::SyslogEnable "false";
|
||||
|
||||
// Specify syslog facility. Default is daemon
|
||||
// Unattended-Upgrade::SyslogFacility "daemon";
|
||||
|
||||
// Download and install upgrades only on AC power
|
||||
// (i.e. skip or gracefully stop updates on battery)
|
||||
// Unattended-Upgrade::OnlyOnACPower "true";
|
||||
|
||||
// Download and install upgrades only on non-metered connection
|
||||
// (i.e. skip or gracefully stop updates on a metered connection)
|
||||
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
|
||||
|
||||
// Verbose logging
|
||||
// Unattended-Upgrade::Verbose "false";
|
||||
|
||||
// Print debugging information both in unattended-upgrades and
|
||||
// in unattended-upgrade-shutdown
|
||||
// Unattended-Upgrade::Debug "false";
|
||||
|
||||
// Allow package downgrade if Pin-Priority exceeds 1000
|
||||
// Unattended-Upgrade::Allow-downgrade "false";
|
||||
|
||||
// When APT fails to mark a package to be upgraded or installed try adjusting
|
||||
// candidates of related packages to help APT's resolver in finding a solution
|
||||
// where the package can be upgraded or installed.
|
||||
// This is a workaround until APT's resolver is fixed to always find a
|
||||
// solution if it exists. (See Debian bug #711128.)
|
||||
// The fallback is enabled by default, except on Debian's sid release because
|
||||
// uninstallable packages are frequent there.
|
||||
// Disabling the fallback speeds up unattended-upgrades when there are
|
||||
// uninstallable packages at the expense of rarely keeping back packages which
|
||||
// could be upgraded or installed.
|
||||
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
|
||||
|
||||
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
|
||||
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot "true";
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot-Time "02:30";
|
||||
|
||||
@@ -1,23 +1,23 @@
|
||||
### Editing /etc/systemd/system/apt-daily-upgrade.timer.d/override.conf
|
||||
### Anything between here and the comment below will become the new contents of the file
|
||||
|
||||
[Timer]
|
||||
OnCalendar=
|
||||
OnCalendar=02:00
|
||||
RandomizedDelaySec=0
|
||||
|
||||
### Lines below this comment will be discarded
|
||||
|
||||
### /lib/systemd/system/apt-daily-upgrade.timer
|
||||
# [Unit]
|
||||
# Description=Daily apt upgrade and clean activities
|
||||
# After=apt-daily.timer
|
||||
#
|
||||
# [Timer]
|
||||
# OnCalendar=*-*-* 6:00
|
||||
# RandomizedDelaySec=60m
|
||||
# Persistent=true
|
||||
#
|
||||
# [Install]
|
||||
# WantedBy=timers.target
|
||||
|
||||
### Editing /etc/systemd/system/apt-daily-upgrade.timer.d/override.conf
|
||||
### Anything between here and the comment below will become the new contents of the file
|
||||
|
||||
[Timer]
|
||||
OnCalendar=
|
||||
OnCalendar=01:30
|
||||
RandomizedDelaySec=0
|
||||
|
||||
### Lines below this comment will be discarded
|
||||
|
||||
### /lib/systemd/system/apt-daily-upgrade.timer
|
||||
# [Unit]
|
||||
# Description=Daily apt upgrade and clean activities
|
||||
# After=apt-daily.timer
|
||||
#
|
||||
# [Timer]
|
||||
# OnCalendar=*-*-* 6:00
|
||||
# RandomizedDelaySec=60m
|
||||
# Persistent=true
|
||||
#
|
||||
# [Install]
|
||||
# WantedBy=timers.target
|
||||
|
||||
@@ -1,101 +1,101 @@
|
||||
#!/bin/sh
|
||||
### BEGIN INIT INFO
|
||||
# Provides: cpufrequtils
|
||||
# Required-Start: $remote_fs loadcpufreq
|
||||
# Required-Stop:
|
||||
# Default-Start: 2 3 4 5
|
||||
# Default-Stop:
|
||||
# Short-Description: set CPUFreq kernel parameters
|
||||
# Description: utilities to deal with CPUFreq Linux
|
||||
# kernel support
|
||||
### END INIT INFO
|
||||
#
|
||||
|
||||
DESC="CPUFreq Utilities"
|
||||
|
||||
PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
|
||||
CPUFREQ_SET=/usr/bin/cpufreq-set
|
||||
CPUFREQ_INFO=/usr/bin/cpufreq-info
|
||||
CPUFREQ_OPTIONS=""
|
||||
|
||||
# use lsb-base
|
||||
. /lib/lsb/init-functions
|
||||
|
||||
# Which governor to use. Must be one of the governors listed in:
|
||||
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors
|
||||
#
|
||||
# and which limits to set. Both MIN_SPEED and MAX_SPEED must be values
|
||||
# listed in:
|
||||
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies
|
||||
# a value of 0 for any of the two variables will disabling the use of
|
||||
# that limit variable.
|
||||
#
|
||||
# WARNING: the correct kernel module must already be loaded or compiled in.
|
||||
#
|
||||
# Set ENABLE to "true" to let the script run at boot time.
|
||||
#
|
||||
# eg: ENABLE="true"
|
||||
# GOVERNOR="ondemand"
|
||||
# MAX_SPEED=1000
|
||||
# MIN_SPEED=500
|
||||
|
||||
ENABLE="true"
|
||||
GOVERNOR="powersave"
|
||||
MAX_SPEED="0"
|
||||
MIN_SPEED="0"
|
||||
|
||||
check_governor_avail() {
|
||||
info="/sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors"
|
||||
if [ -f $info ] && grep -q "\<$GOVERNOR\>" $info ; then
|
||||
return 0;
|
||||
fi
|
||||
return 1;
|
||||
}
|
||||
|
||||
[ -x $CPUFREQ_SET ] || exit 0
|
||||
|
||||
if [ -f /etc/default/cpufrequtils ] ; then
|
||||
. /etc/default/cpufrequtils
|
||||
fi
|
||||
|
||||
# if not enabled then exit gracefully
|
||||
[ "$ENABLE" = "true" ] || exit 0
|
||||
|
||||
if [ -n "$MAX_SPEED" ] && [ $MAX_SPEED != "0" ] ; then
|
||||
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --max $MAX_SPEED"
|
||||
fi
|
||||
|
||||
if [ -n "$MIN_SPEED" ] && [ $MIN_SPEED != "0" ] ; then
|
||||
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --min $MIN_SPEED"
|
||||
fi
|
||||
|
||||
if [ -n "$GOVERNOR" ] ; then
|
||||
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --governor $GOVERNOR"
|
||||
fi
|
||||
|
||||
CPUS=$(cat /proc/stat|sed -ne 's/^cpu\([[:digit:]]\+\).*/\1/p')
|
||||
RETVAL=0
|
||||
case "$1" in
|
||||
start|force-reload|restart|reload)
|
||||
log_action_begin_msg "$DESC: Setting $GOVERNOR CPUFreq governor"
|
||||
if check_governor_avail ; then
|
||||
for cpu in $CPUS ; do
|
||||
log_action_cont_msg "CPU${cpu}"
|
||||
$CPUFREQ_SET --cpu $cpu $CPUFREQ_OPTIONS 2>&1 > /dev/null || \
|
||||
RETVAL=$?
|
||||
done
|
||||
log_action_end_msg $RETVAL ""
|
||||
else
|
||||
log_action_cont_msg "disabled, governor not available"
|
||||
log_action_end_msg $RETVAL
|
||||
fi
|
||||
;;
|
||||
stop)
|
||||
;;
|
||||
*)
|
||||
echo "Usage: $0 {start|stop|restart|reload|force-reload}"
|
||||
exit 1
|
||||
esac
|
||||
|
||||
exit 0
|
||||
|
||||
#!/bin/sh
|
||||
### BEGIN INIT INFO
|
||||
# Provides: cpufrequtils
|
||||
# Required-Start: $remote_fs loadcpufreq
|
||||
# Required-Stop:
|
||||
# Default-Start: 2 3 4 5
|
||||
# Default-Stop:
|
||||
# Short-Description: set CPUFreq kernel parameters
|
||||
# Description: utilities to deal with CPUFreq Linux
|
||||
# kernel support
|
||||
### END INIT INFO
|
||||
#
|
||||
|
||||
DESC="CPUFreq Utilities"
|
||||
|
||||
PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
|
||||
CPUFREQ_SET=/usr/bin/cpufreq-set
|
||||
CPUFREQ_INFO=/usr/bin/cpufreq-info
|
||||
CPUFREQ_OPTIONS=""
|
||||
|
||||
# use lsb-base
|
||||
. /lib/lsb/init-functions
|
||||
|
||||
# Which governor to use. Must be one of the governors listed in:
|
||||
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors
|
||||
#
|
||||
# and which limits to set. Both MIN_SPEED and MAX_SPEED must be values
|
||||
# listed in:
|
||||
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies
|
||||
# a value of 0 for any of the two variables will disabling the use of
|
||||
# that limit variable.
|
||||
#
|
||||
# WARNING: the correct kernel module must already be loaded or compiled in.
|
||||
#
|
||||
# Set ENABLE to "true" to let the script run at boot time.
|
||||
#
|
||||
# eg: ENABLE="true"
|
||||
# GOVERNOR="ondemand"
|
||||
# MAX_SPEED=1000
|
||||
# MIN_SPEED=500
|
||||
|
||||
ENABLE="true"
|
||||
GOVERNOR="powersave"
|
||||
MAX_SPEED="0"
|
||||
MIN_SPEED="0"
|
||||
|
||||
check_governor_avail() {
|
||||
info="/sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors"
|
||||
if [ -f $info ] && grep -q "\<$GOVERNOR\>" $info ; then
|
||||
return 0;
|
||||
fi
|
||||
return 1;
|
||||
}
|
||||
|
||||
[ -x $CPUFREQ_SET ] || exit 0
|
||||
|
||||
if [ -f /etc/default/cpufrequtils ] ; then
|
||||
. /etc/default/cpufrequtils
|
||||
fi
|
||||
|
||||
# if not enabled then exit gracefully
|
||||
[ "$ENABLE" = "true" ] || exit 0
|
||||
|
||||
if [ -n "$MAX_SPEED" ] && [ $MAX_SPEED != "0" ] ; then
|
||||
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --max $MAX_SPEED"
|
||||
fi
|
||||
|
||||
if [ -n "$MIN_SPEED" ] && [ $MIN_SPEED != "0" ] ; then
|
||||
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --min $MIN_SPEED"
|
||||
fi
|
||||
|
||||
if [ -n "$GOVERNOR" ] ; then
|
||||
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --governor $GOVERNOR"
|
||||
fi
|
||||
|
||||
CPUS=$(cat /proc/stat|sed -ne 's/^cpu\([[:digit:]]\+\).*/\1/p')
|
||||
RETVAL=0
|
||||
case "$1" in
|
||||
start|force-reload|restart|reload)
|
||||
log_action_begin_msg "$DESC: Setting $GOVERNOR CPUFreq governor"
|
||||
if check_governor_avail ; then
|
||||
for cpu in $CPUS ; do
|
||||
log_action_cont_msg "CPU${cpu}"
|
||||
$CPUFREQ_SET --cpu $cpu $CPUFREQ_OPTIONS 2>&1 > /dev/null || \
|
||||
RETVAL=$?
|
||||
done
|
||||
log_action_end_msg $RETVAL ""
|
||||
else
|
||||
log_action_cont_msg "disabled, governor not available"
|
||||
log_action_end_msg $RETVAL
|
||||
fi
|
||||
;;
|
||||
stop)
|
||||
;;
|
||||
*)
|
||||
echo "Usage: $0 {start|stop|restart|reload|force-reload}"
|
||||
exit 1
|
||||
esac
|
||||
|
||||
exit 0
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize system CPU governors.
|
||||
|
||||
CPUPOWER_START_OPTS="frequency-set -g powersave"
|
||||
CPUPOWER_STOP_OPTS="frequency-set -g performance"
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
# This configuration file is customized by fox,
|
||||
# Optimize for cpupower systemd service.
|
||||
|
||||
[Unit]
|
||||
Description=Apply cpupower configuration
|
||||
ConditionVirtualization=!container
|
||||
After=syslog.target
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
EnvironmentFile=/etc/default/cpupower
|
||||
ExecStart=/usr/bin/cpupower $CPUPOWER_START_OPTS
|
||||
ExecStop=/usr/bin/cpupower $CPUPOWER_STOP_OPTS
|
||||
RemainAfterExit=yes
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
|
||||