Compare commits

...
198 Commits
Author SHA1 Message Date
CallMeR 1336af517e 更新 DNS 服务器流控算法 2024-07-22 17:12:01 +08:00
CallMeR b0beb5177f 更新 DNS 服务器流控算法 2024-07-19 12:37:05 +08:00
CallMeR 921bd8bb31 更新 TS 服务器流控算法 2024-07-19 12:35:08 +08:00
CallMeR ff1a1a43a7 更新截图 2024-07-02 15:23:20 +08:00
CallMeR 9a9173df92 更新系统更新命令 2024-07-02 11:01:58 +08:00
CallMeR e9ca2b5cda 更新备注信息 2024-06-28 15:33:05 +08:00
CallMeR 0695f8b6b9 Revert 替换广告屏蔽列表 2024-06-28 12:31:22 +08:00
CallMeR 1657411b7e 更新备注信息 2024-06-28 00:14:16 +08:00
CallMeR 14007e78b8 替换广告屏蔽列表 2024-06-27 16:56:10 +08:00
CallMeR 7318726847 修复段落标题 2024-06-26 15:05:08 +08:00
CallMeR 374c55cbb3 修复目录路径 2024-06-26 15:03:00 +08:00
CallMeR 7df6ea76b7 更新文案描述 2024-06-26 14:55:57 +08:00
CallMeR 5e0a8aac54 更新文案描述 2024-06-26 14:53:35 +08:00
CallMeR 8dd1f08f27 更新终端工具 2024-06-26 14:43:59 +08:00
CallMeR 9873dd74d1 更新 SmartDNS 版本 2024-06-13 11:29:38 +08:00
CallMeR ffaa26a050 更新配置文件备注 2024-05-23 02:12:07 +08:00
CallMeR b17ef026ad 更新文案描述 2024-05-21 12:50:30 +08:00
CallMeR 808094ae3c 更新脚本文件命名 2024-05-20 22:17:58 +08:00
CallMeR 609fcf579b 更新配置文件命名 2024-05-20 21:32:38 +08:00
CallMeR 022da7d3f9 更新配置文件命名 2024-05-20 16:18:29 +08:00
CallMeR afb2678f68 使用 btop 代替 htop 2024-05-16 13:21:15 +08:00
CallMeR 4ed96a4d38 更新文案说明 2024-04-28 12:09:53 +08:00
CallMeR f7ff85a805 更新 PVE 版本号 2024-04-26 13:50:02 +08:00
CallMeR 101fc96feb 更新自动备份截图 2024-04-26 13:48:52 +08:00
CallMeR 01f39562ff 新增 sshguard 工具 2024-04-26 12:36:28 +08:00
CallMeR 933bdca053 更新部分截图 2024-04-26 11:56:14 +08:00
CallMeR 748faac28b 更换 SmartDNS 广告列表 2024-04-23 13:28:57 +08:00
CallMeR fe8fbff04c 更新 Dnsmasq 缓存设置 2024-04-23 10:39:00 +08:00
CallMeR 50f49ed956 更新 SmartDNS 缓存设置 2024-04-23 10:36:39 +08:00
CallMeR b809ecd035 更新 PVE 软件源替换命令 2024-04-21 21:12:55 +08:00
CallMeR eda1d36130 更新 Dnsmasq 配置 2024-03-21 10:52:33 +08:00
CallMeR c9bf9ae2fd 更新 Dnsmasq 配置 2024-03-20 22:41:13 +08:00
CallMeR 38ac1f9702 更新 Dnsmasq 配置 2024-03-19 18:36:36 +08:00
CallMeR f493c774ab 更新 SmartDNS 配置 2024-03-19 12:06:18 +08:00
CallMeR 09a35e9c31 关闭 Dnsmasq 缓存 2024-03-19 10:13:17 +08:00
CallMeR a1e992c956 更新 SmartDNS 配置 2024-03-19 10:04:27 +08:00
CallMeR 360542f9d4 更新 Dnsmasq 参数 2024-03-18 21:45:12 +08:00
CallMeR e5a8d8b491 更新截图 2024-03-18 14:14:47 +08:00
CallMeR 3ce5fdba6a 更新截图 2024-03-18 14:09:10 +08:00
CallMeR 5ec78ce639 更新 Debian 云镜像 2024-03-18 13:50:30 +08:00
CallMeR b597af908d 更新 SmartDNS 缓存参数 2024-03-16 13:34:26 +08:00
CallMeR 6f085030b3 更新 Dnsmasq 缓存参数 2024-03-16 13:25:07 +08:00
CallMeR 82497488ed 更新 TS 自动更新 2024-03-01 20:26:31 +08:00
CallMeR ee7b34ddf4 更新 SmartDNS 配置 2024-02-20 02:08:33 +08:00
CallMeR 353dc12fca 更新文案描述 2024-02-14 01:54:23 +08:00
CallMeR a410d925f4 更新清理命令 2024-02-13 22:35:06 +08:00
CallMeR 2c48e3a330 优化 ls 命令 2024-02-11 02:11:06 +08:00
CallMeR 2344cd77bf 更新 SmartDNS 参数 2024-02-11 01:55:18 +08:00
CallMeR aba1e70956 更新 SmartDNS 参数 2024-02-11 01:39:02 +08:00
CallMeR bbcbc9fe1e 更新 Dnsmasq 参数 2024-02-09 00:36:35 +08:00
CallMeR 5bce9e1d44 SmartDNS 配置重命名 2024-02-09 00:29:47 +08:00
CallMeR 80f7041632 更新 SmartDNS 参数 2024-02-09 00:27:03 +08:00
CallMeR ffcae17092 更新 SmartDNS 版本 2024-02-09 00:04:29 +08:00
CallMeR 0bd3a7cd36 整合清理命令 2024-01-30 18:17:58 +08:00
CallMeR eddc39bc40 修复 typo 2024-01-30 18:14:52 +08:00
CallMeR 564d56e56f 更新流表语法 2024-01-20 21:52:47 +08:00
CallMeR 80556cacaf 更新流表语法 2024-01-20 19:27:06 +08:00
CallMeR 2c8d775e9e 更新 README 2024-01-17 14:02:25 +08:00
CallMeR 19532baa21 更新 README 2024-01-17 13:59:58 +08:00
CallMeR 2ff27e96c3 默认不启用 IPv6 ULA 网络 2024-01-17 13:54:39 +08:00
CallMeR 979f03052e 修复 typo 2024-01-17 13:22:45 +08:00
CallMeR 3a7a506645 更新文案描述 2024-01-10 16:16:56 +08:00
CallMeR 62c55d9750 调整 Dnsmasq 配置 2024-01-10 15:13:49 +08:00
CallMeR 101b5c64b2 整理文档 2024-01-10 15:05:59 +08:00
CallMeR 497a8c0685 更新 Dnsmasq 配置 2024-01-10 14:46:26 +08:00
CallMeR 00e4fd27e5 调整 Dnsmasq 配置 2024-01-10 14:29:51 +08:00
CallMeR 85d5a3bee5 更新文案描述 2024-01-08 22:31:32 +08:00
CallMeR 2ae4bda8b3 调整 Dnsmasq 格式 2024-01-08 21:55:32 +08:00
CallMeR 12cadb86ad 更新说明 2024-01-08 21:46:38 +08:00
CallMeR 3c9927a362 关闭 TS 服务器 Dnsmasq 的 DNS 缓存 2024-01-08 21:40:23 +08:00
CallMeR d69101077b 更新 offload 匹配 2024-01-07 12:03:45 +08:00
CallMeR 6497efb00a 同步上游更新 2024-01-06 14:59:35 +08:00
CallMeR 79703f9d62 修改 systemd 服务路径 2024-01-05 21:46:56 +08:00
CallMeR 53994238c8 更新文案描述 2024-01-05 21:34:30 +08:00
CallMeR ddcdc18564 修复 Typo 2024-01-01 17:33:04 +08:00
CallMeR f505690ed6 更新文档 2024-01-01 16:29:11 +08:00
CallMeR 96cb5ddcdc 更新文档 2024-01-01 16:19:33 +08:00
CallMeR 2858ba97c4 更新文档 2024-01-01 14:07:06 +08:00
CallMeR 833817d85c 更新文档 2024-01-01 13:54:16 +08:00
CallMeR 7097fb5d73 更新文档 2024-01-01 13:49:38 +08:00
CallMeR 52f3be600b 更新文档 2024-01-01 13:36:04 +08:00
CallMeR 0a9a2ee8fe 更新文档 2024-01-01 13:13:36 +08:00
CallMeR ed3c106e27 更新文档 2024-01-01 13:10:07 +08:00
CallMeR c94d7d31fc 更新文档 2024-01-01 13:00:00 +08:00
CallMeR abf168587d 更新文档 2024-01-01 12:49:36 +08:00
CallMeR 3e9a8eae07 更新文档 2024-01-01 12:02:06 +08:00
CallMeR 090ab28970 整理文档 2023-12-31 22:07:01 +08:00
CallMeR 59ebf178c7 整理文档 2023-12-31 21:09:03 +08:00
CallMeR 249717ed89 更新 TS 测试配置 2023-12-30 22:16:07 +08:00
CallMeR 2520ce4839 更新 nf_conntrack 参数 2023-12-24 01:50:16 +08:00
CallMeR 5d5750f120 更新定时参数 2023-12-21 22:09:33 +08:00
CallMeR f90dd7a7c8 更新 resolv.conf 配置 2023-12-16 23:52:08 +08:00
CallMeR 730773e42b 更新 resolv 配置方法 2023-12-16 16:40:20 +08:00
CallMeR c00e178df3 新增 OVS 工具 2023-12-15 02:25:23 +08:00
CallMeR f8c7676c85 精简非相关配置 2023-12-14 11:32:51 +08:00
CallMeR 29592abb40 更换 SmartDNS 广告规则 2023-12-14 11:30:39 +08:00
CallMeR 62b2641413 更新命令备注 2023-12-14 00:29:13 +08:00
CallMeR 04023ac155 优化文案描述 2023-12-14 00:22:21 +08:00
CallMeR 4dcb3ff7a9 优化文案描述 2023-12-13 23:30:01 +08:00
CallMeR ca30a2f9e9 优化文案描述 2023-12-13 23:14:33 +08:00
CallMeR 88ea495d5a 优化文案描述 2023-12-13 23:12:03 +08:00
CallMeR d08a3acf74 优化文案描述 2023-12-13 20:59:27 +08:00
CallMeR d26f303437 优化文案描述 2023-12-13 20:51:04 +08:00
CallMeR ed0db21a9f 优化文案描述 2023-12-13 20:19:45 +08:00
CallMeR 18e02bc9c8 优化文案描述 2023-12-13 19:59:29 +08:00
CallMeR 6882b01afc 更新文件名 2023-12-13 16:55:19 +08:00
CallMeR fec6ae3e56 更新脚本 2023-12-13 14:45:57 +08:00
CallMeR 660551f2fc 更新 curl 参数 2023-12-12 21:32:02 +08:00
CallMeR 80afa7dfe7 更新 SmartDNS 下载链接 2023-12-12 20:05:34 +08:00
CallMeR 509b344c69 更新 systemd-resolved 配置 2023-12-11 13:22:00 +08:00
CallMeR 3b3a3361fa 更新 curl 参数 2023-12-11 09:47:01 +08:00
CallMeR fba7575503 更新 curl 参数 2023-12-11 02:55:16 +08:00
CallMeR 4d77f0415e 更新 curl 参数 2023-12-11 02:27:42 +08:00
CallMeR 8b35afeec5 修复 curl 命令 2023-12-11 01:12:27 +08:00
CallMeR e0c69c3fa5 统一 crontab 时间 2023-12-10 23:32:46 +08:00
CallMeR 410f6e8d2e 替换 wget 命令 2023-12-10 22:55:40 +08:00
CallMeR 56d9125152 替换 wget 命令 2023-12-10 22:47:21 +08:00
CallMeR 779b75f3a8 更新 SmartDNS 定时器 2023-12-10 19:19:46 +08:00
CallMeR b0c7a2d4ce 优化文案描述 2023-12-10 18:39:15 +08:00
CallMeR b84dbe3872 优化文案描述 2023-12-10 18:31:43 +08:00
CallMeR 1555ec02ca 更新 SmartDNS 配置 2023-12-10 18:00:16 +08:00
CallMeR 906db9eac4 更新脚本变量 2023-12-09 21:17:31 +08:00
CallMeR 0d091d93c1 更新脚本变量 2023-12-09 21:10:04 +08:00
CallMeR b347128ec5 更新脚本变量 2023-12-09 20:58:20 +08:00
CallMeR 1e5a55de64 更新说明信息 2023-12-09 15:22:57 +08:00
CallMeR d052923897 更新文件名 2023-12-09 01:32:16 +08:00
CallMeR ba0afba7eb 更新 SmartDNS 插件脚本 2023-12-08 23:49:03 +08:00
CallMeR 6aa24ecb61 更新 SmartDNS 插件脚本 2023-12-08 23:42:25 +08:00
CallMeR 454ae86aba 更新 SmartDNS 配置 2023-12-08 13:03:17 +08:00
CallMeR 24b087aa1e 更新 SmartDNS 默认端口 2023-12-02 12:22:57 +08:00
CallMeR 56317210a6 更新 lsof 参数 2023-12-02 01:11:16 +08:00
CallMeR d8e7753112 更新 TS 测试配置 2023-12-02 00:44:34 +08:00
CallMeR 4700bc1c52 更新截图 2023-12-01 23:47:29 +08:00
CallMeR 29f6296a1c 更新 TS 测试配置 2023-12-01 18:54:38 +08:00
CallMeR 891d8ef2f6 更新 TS 测试配置 2023-12-01 13:47:44 +08:00
CallMeR e4117816c5 更新 TS 测试配置 2023-12-01 13:30:52 +08:00
CallMeR b109b0d840 更新 TS 测试配置 2023-12-01 00:40:19 +08:00
CallMeR 8bc4dd8587 更新 dnsmasq 配置 2023-11-30 23:20:51 +08:00
CallMeR eef810d850 更新截图 2023-11-30 17:41:18 +08:00
CallMeR 752c233013 更新安装截图 2023-11-30 15:29:44 +08:00
CallMeR 8b62f62420 更新模板虚拟机配置 2023-11-30 12:47:45 +08:00
CallMeR 46d0e0ce4a 更新截图 2023-11-30 12:21:27 +08:00
CallMeR f643128cf5 更新截图 2023-11-30 10:48:20 +08:00
CallMeR 165f6ea9dc 更新 TS 防火墙备注 2023-11-29 14:06:15 +08:00
CallMeR 7fc7ab2466 更新 TS 防火墙备注 2023-11-29 14:01:12 +08:00
CallMeR 2407555015 更新 TS 防火墙 2023-11-29 13:48:55 +08:00
CallMeR 5b65602c07 更新 TS 防火墙 2023-11-28 21:59:39 +08:00
CallMeR a2b1278038 更新备注 2023-11-28 21:52:29 +08:00
CallMeR 07d5ea174a 更新 TS 测试配置 2023-11-28 19:01:35 +08:00
CallMeR 554b2bd6d4 整理文件名 2023-11-28 18:35:55 +08:00
CallMeR 145328fb3c 更新 LXC 文案 2023-11-27 18:00:16 +08:00
CallMeR 9691336e5c 更新 LXC 文案 2023-11-27 17:53:56 +08:00
CallMeR f7ce11e99d 更新 LXC 文案 2023-11-27 17:51:16 +08:00
CallMeR eb631a1cdc 更新 LXC 文案 2023-11-27 14:36:30 +08:00
CallMeR 46ce4e4ee3 更新 SmartDNS 配置 2023-11-27 13:24:28 +08:00
CallMeR 0bd03af309 更新文件名 2023-11-27 12:56:34 +08:00
CallMeR 767c31694d 更新文件名 2023-11-27 12:54:07 +08:00
CallMeR b27372c20d 更新虚拟机 DEB822 配置 2023-11-26 20:58:59 +08:00
CallMeR b830088e5e 更新 PVE 版本 2023-11-25 22:24:54 +08:00
CallMeR 9f5884befb 优化 sysctl 配置 2023-11-24 12:07:45 +08:00
CallMeR 8af7ef896b 更新 dnsmasq 配置 2023-11-18 16:37:19 +08:00
CallMeR 09a60d3ae4 Dnsmasq 插件设置 2023-11-13 12:31:57 +08:00
CallMeR 830655bd52 更新定时任务 2023-11-13 12:21:25 +08:00
CallMeR 95023d68d3 回滚 SmartDNS 配置 2023-11-08 11:55:55 +08:00
CallMeR d8e6a50166 更新 dnsmasq 配置 2023-11-08 11:47:01 +08:00
CallMeR e6d805fba5 更新 SmartDNS 配置 2023-11-07 13:47:34 +08:00
CallMeR 9386f961d1 整理文档 2023-10-29 10:28:30 +08:00
CallMeR b84666a6b6 修复备注信息 2023-10-14 23:34:52 +08:00
CallMeR 07526b9ada 修复备注信息 2023-10-14 23:17:07 +08:00
CallMeR e31338113d 修复 cpupower 文案 2023-10-14 22:36:54 +08:00
CallMeR 7eda1b4eef 更新 SmartDNS 缓存参数 2023-10-10 22:10:45 +08:00
CallMeR 3b1a9e4f00 替换 ldnsutils 2023-10-07 01:45:36 +08:00
CallMeR 7288a7ba8b 更新 N6005 CPU 调度器输出 2023-09-15 14:48:52 +08:00
CallMeR 63631e6ad3 优化 CPU 调度器配置 2023-09-13 13:48:05 +08:00
CallMeR 5ed5ac768b 更新系统默认 qdisc 2023-09-10 16:32:42 +08:00
CallMeR ae5b3e1e82 更新本地域名后缀 2023-09-09 19:17:40 +08:00
CallMeR b7857fcd66 更新本地域名后缀 2023-09-09 19:03:26 +08:00
CallMeR 81101cde20 更新本地域名后缀 2023-09-09 18:30:25 +08:00
CallMeR 99e4a94a9f 更新安装截图 2023-09-09 16:45:06 +08:00
CallMeR c4294612eb 更新安装截图 2023-09-09 16:13:54 +08:00
CallMeR 38df9bd3e4 更新本地域名后缀 2023-09-07 22:36:50 +08:00
CallMeR 0019ac0fbc 修复时间参数说明 2023-08-18 14:32:13 +08:00
CallMeR 1b8caefe58 修复时间参数说明 2023-08-18 14:25:41 +08:00
CallMeR 9804c8964e 修复时间参数说明 2023-08-18 14:20:31 +08:00
CallMeR 861e468aa6 修复定时重启时间 2023-08-18 14:15:36 +08:00
CallMeR 90bc8f942b 修复定时重启时间 2023-08-18 14:12:26 +08:00
CallMeR 09f4738295 更新 SmartDNS 版本 2023-08-13 17:05:53 +08:00
CallMeR ea71df8c8c 更新说明信息 2023-08-07 21:35:47 +08:00
CallMeR 1a8c107333 更新 PVE 官网截图 2023-08-07 21:29:53 +08:00
CallMeR c40ba60a6e 更新 PVE 官网截图 2023-08-07 21:26:36 +08:00
CallMeR 9494d82747 更新 PVE 官网截图 2023-08-07 21:22:59 +08:00
CallMeR f89c38f8d8 更新 PVE 官网截图 2023-08-07 21:14:57 +08:00
CallMeR 6a9202a62b 更新示例 2023-08-01 13:39:06 +08:00
CallMeR 8a10db07d1 更新示例 2023-08-01 13:30:56 +08:00
CallMeR 17ab25b998 统一时间规划 2023-07-26 14:57:51 +08:00
CallMeR 17ae656734 更新 SmartDNS 配置 2023-07-25 18:31:52 +08:00
CallMeR b28bb464c1 更新 SmartDNS 配置 2023-07-23 13:39:18 +08:00
CallMeR 0fd5dc83f2 更新 SmartDNS 配置 2023-07-23 03:28:02 +08:00
98 changed files with 2598 additions and 1090 deletions
+21 -15
View File
@@ -4,17 +4,17 @@ PVE 系统正式安装之前,需要准备 PVE 的安装镜像和一些必要
### 0.1. PVE 镜像下载 ### 0.1. PVE 镜像下载
PVE 下载地址:https://www.proxmox.com/en/downloads PVE 下载地址:[Proxmox Virtual Environment](https://www.proxmox.com/en/downloads/proxmox-virtual-environment/iso)
页面中可能有多个 PVE 的安装 ISO ,可以根据需要进行选择,目前最新的 `Proxmox VE 8.0 ISO` 作为演示。 页面中有多个 PVE 相关文件,本文以目前最新的 `Proxmox VE 8.2-1 ISO Installer` 作为演示。
![下载PVE ISO文件](img/p01/pve_download_iso.jpeg) 点击 `Proxmox VE 8.x ISO Installer` 链接,进入 PVE 下载页面。
点击 `Proxmox VE 8.x ISO Installer` 链接。 ![PVE下载页面](img/p01/pve_download_iso.jpeg)
下载 ISO 时请注意 `SHA256SUM` ,后续将使用该校验信息对下载下来的 ISO 进行校验,以确保 ISO 文件的完整性。 下载 ISO 时请注意 `SHA256SUM` ,后续将使用该校验信息对下载下来的 ISO 进行校验,以确保 ISO 文件的完整性。
![输入图片说明](img/p01/pve_iso_hash.jpeg) ![下载PVE](img/p01/pve_iso_hash.jpeg)
### 0.2.启动盘制作工具 ### 0.2.启动盘制作工具
@@ -50,25 +50,31 @@ PVE 下载地址:https://www.proxmox.com/en/downloads
![Rufus写盘工具](img/p01/pve_rufus.jpeg) ![Rufus写盘工具](img/p01/pve_rufus.jpeg)
### 0.3. SSH 工具 ### 0.3.终端工具
考虑到配置 PVE 服务器、路由器、DNS 服务器时,需要在 CLI 中输入命令,因此这里推荐几个常用的 SSH 工具。 考虑到配置 PVE 服务器、路由器、DNS 服务器时,需要在 CLI 中输入命令,因此这里推荐几个常用的终端工具。
#### Tabby #### Windows Terminal
官方网站地址:https://tabby.sh 官方网站地址:https://aka.ms/terminal
基于 Electron 开发的开源跨平台终端工具,内部集成了 SFTP ,可以在 Github 平台上进行下载。 Microsoft 官方终端工具,可以在 Github 平台或 Microsoft 应用商店中进行下载。
支持 Windows 、macOS 、Linux 。 ![Windows Terminal](img/p01/pve_win_terminal.png)
![Tabby SSH工具](img/p01/pve_tabby.png) #### Termius
官方地址:https://termius.com/
企业级终端工具,支持 Windows、macOS、Linux 系统以及移动端系统。
![Termius](img/p01/pve_termius.jpeg)
#### MobaXterm #### MobaXterm
官方地址:https://mobaxterm.mobatek.net 官方地址:https://mobaxterm.mobatek.net
功能强大的 SSH 工具,仅支持 Windows 。 功能强大的终端工具,仅支持 Windows 系统
![MobaXterm](img/p01/pve_mobaxterm.png) ![MobaXterm](img/p01/pve_mobaxterm.png)
@@ -156,7 +162,7 @@ PVE 为最关键的虚拟化层,建议使用强密码,包含大小写字母
FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。 FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
演示中 FQDN 为 `node01.fox.local` ,因此 PVE 的主机名为 `node01` 演示中 FQDN 为 `node01.fox.home.arpa` ,因此 PVE 的主机名为 `node01`
根据规划,PVE 的 IPv4 管理地址为 `172.16.1.254` 根据规划,PVE 的 IPv4 管理地址为 `172.16.1.254`
@@ -166,7 +172,7 @@ FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
|参数|值|说明| |参数|值|说明|
|--|--|--| |--|--|--|
|Hostname (FQDN)|`node01.fox.local`|设置 PVE `域``主机名` | |Hostname (FQDN)|`node01.fox.home.arpa`|设置 PVE `域``主机名` |
|IP Address (CIDR)|`172.16.1.254/24`|设置 PVE IPv4 地址| |IP Address (CIDR)|`172.16.1.254/24`|设置 PVE IPv4 地址|
|Gateway|`172.16.1.1`|设置 PVE IPv4 网关| |Gateway|`172.16.1.1`|设置 PVE IPv4 网关|
|DNS Server|`172.16.1.1`|设置 PVE IPv4 DNS | |DNS Server|`172.16.1.1`|设置 PVE IPv4 DNS |
+51 -36
View File
@@ -12,7 +12,7 @@
### 1.1.系统软件源 ### 1.1.系统软件源
使用 SSH 工具登录到 PVE 服务器,首先对现有的软件源配置进行备份。 使用终端工具登录到 PVE 服务器,首先对现有的软件源配置进行备份。
```bash ```bash
## 进入系统软件源配置文件目录 ## 进入系统软件源配置文件目录
@@ -64,37 +64,47 @@ deb https://mirrors.ustc.edu.cn/debian-security/ bookworm-security main contrib
默认情况下,PVE 额外启用了 2 个官方源,且为订阅收费制,因此需要替换为免费源。 默认情况下,PVE 额外启用了 2 个官方源,且为订阅收费制,因此需要替换为免费源。
删除 PVE 官方付费软件源,使用以下命令。 首先创建 PVE 费软件源,执行以下命令。
```bash
## 创建 PVE 免费软件源
$ source /etc/os-release
$ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/pve $VERSION_CODENAME pve-no-subscription" > /etc/apt/sources.list.d/pve-no-subscription.list
```
对于 Proxmox Backup Server 和 Proxmox Mail Gateway,请将以上命令中的 `pve` 分别替换为 `pbs``pmg`
进一步创建 PVE Ceph 免费软件源,Ceph 软件源为 PVE 8 之后默认安装,执行以下命令。
```bash
## 创建 PVE Ceph 免费软件源脚本
if [ -f /etc/apt/sources.list.d/ceph.list ]; then
CEPH_CODENAME=`ceph -v | grep ceph | awk '{print $(NF-1)}'`
source /etc/os-release
echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-$CEPH_CODENAME $VERSION_CODENAME no-subscription" > /etc/apt/sources.list.d/ceph-no-subscription.list
fi
```
最后,删除 PVE 官方付费软件源,执行以下命令。
**注意:rm 为高风险命令,请正确使用,请勿手抖,请勿手抖。** **注意:rm 为高风险命令,请正确使用,请勿手抖,请勿手抖。**
```bash ```bash
## 删除付费软件源 ## 删除付费软件源
$ rm -rvf /etc/apt/sources.list.d/*.list $ rm -rvf /etc/apt/sources.list.d/pve-enterprise.list /etc/apt/sources.list.d/ceph.list
```
创建 PVE 免费软件源。
**注意:该命令为三行,在输入时请逐行输入并回车执行。**
```bash
## 创建 PVE 免费源
$ source /etc/os-release
$ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy $VERSION_CODENAME no-subscription" > /etc/apt/sources.list.d/ceph-no-subscription.list
$ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/pve $VERSION_CODENAME pve-no-subscription" > /etc/apt/sources.list.d/pve-no-subscription.list
``` ```
创建完成后对其进行检查。 创建完成后对其进行检查。
```bash ```bash
## 检查PVE免费源 ## 检查 PVE 免费源
$ cat /etc/apt/sources.list.d/ceph-no-subscription.list
$ cat /etc/apt/sources.list.d/pve-no-subscription.list $ cat /etc/apt/sources.list.d/pve-no-subscription.list
$ cat /etc/apt/sources.list.d/ceph-no-subscription.list
``` ```
如果输出结果中有 USTC 的镜像地址,则表示命令已经正确执行。 如果输出结果中有 USTC 的镜像地址,则表示命令已经正确执行。
@@ -102,11 +112,11 @@ $ cat /etc/apt/sources.list.d/pve-no-subscription.list
```bash ```bash
#### PVE 免费软件源示例输出 #### PVE 免费软件源示例输出
#### Ceph
deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy bookworm no-subscription
#### PVE #### PVE
deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription
#### Ceph
deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy bookworm no-subscription
``` ```
### 1.3. PVE CT 源 ### 1.3. PVE CT 源
@@ -116,12 +126,17 @@ deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription
由于该功能暂时未被使用,因此本文只做记录。 由于该功能暂时未被使用,因此本文只做记录。
```bash ```bash
## 替换 CT Templates 源 ## 备份 CT Templates 源
$ cp /usr/share/perl5/PVE/APLInfo.pm /usr/share/perl5/PVE/APLInfo.pm.bak $ cp /usr/share/perl5/PVE/APLInfo.pm /usr/share/perl5/PVE/APLInfo.pm.bak
## 替换 CT Templates 链接
$ sed -i 's|http://download.proxmox.com|https://mirrors.ustc.edu.cn/proxmox|g' /usr/share/perl5/PVE/APLInfo.pm $ sed -i 's|http://download.proxmox.com|https://mirrors.ustc.edu.cn/proxmox|g' /usr/share/perl5/PVE/APLInfo.pm
## 重启 PVE API 守护进程
$ systemctl restart pvedaemon.service
## 更新 CT Templates 列表
$ pveam update
``` ```
### 1.4.镜像同步 ### 1.4.镜像同步
@@ -138,7 +153,7 @@ $ apt clean && apt autoclean && apt autoremove --purge
$ apt update $ apt update
## 更新系统 ## 更新系统
$ apt dist-upgrade $ apt full-upgrade
``` ```
## 2.安装必要软件 ## 2.安装必要软件
@@ -149,20 +164,20 @@ $ apt dist-upgrade
其中 `unattended-upgrades` 为系统自动更新服务,后续会对其进行配置。 其中 `unattended-upgrades` 为系统自动更新服务,后续会对其进行配置。
`cpufrequtils` 为 CPU 调度器的配置工具,后续会对 CPU 调度算法进行调整。 `linux-cpupower` 为 CPU 调度器的配置工具,后续会对 CPU 调度算法进行调整。
```bash ```bash
## 同步镜像仓库 ## 同步镜像仓库
$ apt update $ apt update
## 安装系统软件 ## 安装系统软件
$ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base $ apt install btop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具 ## 安装网络工具
$ apt install iperf iperf3 iftop $ apt install iperf iperf3 iftop sshguard openvswitch-switch
## 安装 CPU 调度调整工具 ## 安装 CPU 调度调整工具
$ apt install cpufrequtils $ apt install linux-cpupower
## 根据 CPU 厂商安装 CPU 微码工具 ## 根据 CPU 厂商安装 CPU 微码工具
$ apt install intel-microcode (amd64-microcode) $ apt install intel-microcode (amd64-microcode)
@@ -194,9 +209,9 @@ $ update-pciids
|IPv4|管理地址|`172.16.1.254`|PVE IPv4 地址| |IPv4|管理地址|`172.16.1.254`|PVE IPv4 地址|
||网关地址|`172.16.1.1`|PVE IPv4 网关| ||网关地址|`172.16.1.1`|PVE IPv4 网关|
||DNS 地址|`172.16.1.1`|PVE IPv4 DNS 服务器| ||DNS 地址|`172.16.1.1`|PVE IPv4 DNS 服务器|
|IPv6|管理地址|`fdac::fe`|PVE IPv6 地址| |IPv6|管理地址|`fdac::fe`|PVE IPv6 地址(可选)|
||网关地址|`-`|IPv6 网关将使用 `LLA` 自动配置| ||网关地址|`-`|IPv6 网关将使用 `SLAAC` 自动配置|
||DNS 地址|`fdac::1`|PVE IPv6 DNS 服务器| ||DNS 地址|`fdac::1`|PVE IPv6 DNS 服务器(可选)|
![PVE网络规划](img/p02/pve_net_schematization.png) ![PVE网络规划](img/p02/pve_net_schematization.png)
@@ -248,7 +263,7 @@ $ update-pciids
1. 如非特殊需求,通常情况下 PVE 系统无需使用 IPv6 网络。 1. 如非特殊需求,通常情况下 PVE 系统无需使用 IPv6 网络。
2. 主路由未配置 ULA IPv6 网段时,例如本文演示地址 `fdac::/64` ,无需填写 `IPv6/CIDR` 参数。 2. 主路由未配置 IPv6 ULA 网段时,例如本文演示地址 `fdac::/64` ,无需填写 `IPv6/CIDR` 参数。
3. 通常情况下 IPv6 无需填写 `网关` 参数,IPv6 网关将通过 LLA IPv6 地址自动配置。 3. 通常情况下 IPv6 无需填写 `网关` 参数,IPv6 网关将通过 LLA IPv6 地址自动配置。
@@ -288,9 +303,9 @@ $ update-pciids
在 PVE 系统的安装过程中,设置了 DNS 的 IPv4 地址 `172.16.1.1` ,但并未设置 DNS 的 IPv6 地址。 在 PVE 系统的安装过程中,设置了 DNS 的 IPv4 地址 `172.16.1.1` ,但并未设置 DNS 的 IPv6 地址。
在 PVE 的 DNS 设置页面,手动添加 DNS IPv6 地址,即主路由 LAN 口 ULA IPv6 地址。 在 PVE 的 DNS 设置页面,手动添加 DNS IPv6 地址,即主路由 LAN 口 IPv6 ULA 地址。
同样,若 PVE 不使用 IPv6 网络或主路由未配置 ULA IPv6 网段,本步骤可跳过。 同样,若 PVE 不使用 IPv6 网络或主路由未配置 IPv6 ULA 网段,本步骤可跳过。
![PVE添加IPv6DNS](img/p02/pve_add_ipv6_dns.jpeg) ![PVE添加IPv6DNS](img/p02/pve_add_ipv6_dns.jpeg)
+97 -59
View File
@@ -9,13 +9,13 @@
$ apt update $ apt update
## 安装系统软件 ## 安装系统软件
$ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base $ apt install btop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具 ## 安装网络工具
$ apt install iperf iperf3 iftop $ apt install iperf iperf3 iftop sshguard openvswitch-switch
## 安装 CPU 调度调整工具 ## 安装 CPU 调度调整工具
$ apt install cpufrequtils $ apt install linux-cpupower
## 根据 CPU 厂商安装 CPU 微码工具 ## 根据 CPU 厂商安装 CPU 微码工具
$ apt install intel-microcode (amd64-microcode) $ apt install intel-microcode (amd64-microcode)
@@ -26,7 +26,7 @@ $ update-pciids
## 1.系统时区 ## 1.系统时区
如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以使用以下命令修正。 如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以执行以下命令修正。
输出结果如果和北京时间一致,则代表修改正确。 输出结果如果和北京时间一致,则代表修改正确。
@@ -82,41 +82,45 @@ MS Name/IP address Stratum Poll Reach LastRx Last sample
## 2. CPU 调度器 ## 2. CPU 调度器
安装 `cpufrequtils` 后,需检查 CPU 当前调度器。 安装 `linux-cpupower` 后,需检查 CPU 当前调度器。
```bash ```bash
## 检查 CPU 当前调度器 ## 检查 CPU 当前调度器
$ cpufreq-info $ cpupower -c all frequency-info
#### 设备 CPU - J4125 示例输出 #### 设备 CPU - J4125 示例输出
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
Report errors and bugs to cpufreq@vger.kernel.org, please.
analyzing CPU 0: analyzing CPU 0:
driver: intel_cpufreq driver: intel_cpufreq
CPUs which run at the same hardware frequency: 0 CPUs which run at the same hardware frequency: 0
CPUs which need to have their frequency coordinated by software: 0 CPUs which need to have their frequency coordinated by software: 0
maximum transition latency: 20.0 us. maximum transition latency: 20.0 us
hardware limits: 800 MHz - 2.70 GHz hardware limits: 800 MHz - 2.70 GHz
available cpufreq governors: conservative, ondemand, userspace, powersave, performance, schedutil available cpufreq governors: conservative ondemand userspace powersave performance schedutil
current policy: frequency should be within 800 MHz and 2.70 GHz. current policy: frequency should be within 800 MHz and 2.70 GHz.
The governor "ondemand" may decide which speed to use The governor "ondemand" may decide which speed to use
within this range. within this range.
current CPU frequency is 1.84 GHz. current CPU frequency: Unable to call hardware
current CPU frequency: 800 MHz (asserted by call to kernel)
boost state support:
Supported: yes
Active: yes
#### 设备 CPU - N6005 示例输出 #### 设备 CPU - N6005 示例输出
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
Report errors and bugs to cpufreq@vger.kernel.org, please.
analyzing CPU 0: analyzing CPU 0:
driver: intel_pstate driver: intel_pstate
CPUs which run at the same hardware frequency: 0 CPUs which run at the same hardware frequency: 0
CPUs which need to have their frequency coordinated by software: 0 CPUs which need to have their frequency coordinated by software: 0
maximum transition latency: 4294.55 ms. maximum transition latency: Cannot determine or is not supported.
hardware limits: 800 MHz - 3.30 GHz hardware limits: 800 MHz - 3.30 GHz
available cpufreq governors: performance, powersave available cpufreq governors: performance powersave
current policy: frequency should be within 800 MHz and 3.30 GHz. current policy: frequency should be within 800 MHz and 3.30 GHz.
The governor "performance" may decide which speed to use The governor "performance" may decide which speed to use
within this range. within this range.
current CPU frequency is 2.00 GHz. current CPU frequency: Unable to call hardware
current CPU frequency: 2.00 GHz (asserted by call to kernel)
boost state support:
Supported: yes
Active: yes
``` ```
这里面主要关注两个点: 这里面主要关注两个点:
@@ -140,7 +144,7 @@ performance
CPU 驱动一般不建议手动调整,而 `governor` 后面的参数表示 CPU 当前调度器设置。 CPU 驱动一般不建议手动调整,而 `governor` 后面的参数表示 CPU 当前调度器设置。
接下来,需要了解 CPU 支持的调度器有哪些,使用以下命令。 接下来,需要了解 CPU 支持的调度器有哪些,执行以下命令。
```bash ```bash
## 检查 CPU 调度器支持情况 ## 检查 CPU 调度器支持情况
@@ -159,30 +163,69 @@ performance powersave
- CPU 驱动为 `intel_pstate` 时,推荐使用 `powersave` 调度器。 - CPU 驱动为 `intel_pstate` 时,推荐使用 `powersave` 调度器。
本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器来编辑 `cpufrequtils` 的配置文件。 本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器创建 `cpupower` 的配置文件。
因为该配置文件很长,完整的配置文件可查看 [pve_cpufrequtils.conf](./src/pve_cpufrequtils.conf) 以便对比。
修改完成后,需要重启 PVE 服务器来使参数生效。
```bash ```bash
## 编辑 cpufrequtils 配置文件 ## 创建 cpupower 配置文件
$ nano /etc/init.d/cpufrequtils $ nano /etc/default/cpupower
``` ```
在配置文件中修改以下配置项,并保存。 在配置文件中修改以下配置项,并保存。
```bash ```bash
## cpufrequtils 配置项 # This configuration file is customized by fox,
# Optimize system CPU governors.
ENABLE="true" CPUPOWER_START_OPTS="frequency-set -g powersave"
GOVERNOR="powersave" ## 修改本行的调度器为 powersave CPUPOWER_STOP_OPTS="frequency-set -g performance"
MAX_SPEED="0"
MIN_SPEED="0"
``` ```
PVE 服务器重启完成后需再次查看 CPU 调度器,检验配置文件是否生效 使用 `nano` 编辑器创建 `cpupower` 服务配置文件,以满足系统自动化设置需求
```bash
## 创建 cpupower 服务配置文件
$ nano /etc/systemd/system/cpupower.service
```
在服务配置文件中修改以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize for cpupower systemd service.
[Unit]
Description=Apply cpupower configuration
ConditionVirtualization=!container
After=syslog.target
[Service]
Type=oneshot
EnvironmentFile=/etc/default/cpupower
ExecStart=/usr/bin/cpupower $CPUPOWER_START_OPTS
ExecStop=/usr/bin/cpupower $CPUPOWER_STOP_OPTS
RemainAfterExit=yes
[Install]
WantedBy=multi-user.target
```
由于修改了服务项,需要执行以下命令进行重载。
```bash
## 服务重载
$ systemctl daemon-reload
```
执行以下命令让 `cpupower` 服务开机自启动。
```bash
## 设置 cpupower 服务开机自启
$ systemctl enable cpupower.service
```
修改完成后,需重启 PVE 服务器,并再次查看 CPU 调度器,检验配置文件是否生效。
这里提供两个额外命令,方便实时查看 CPU 当前频率和温度状况。 这里提供两个额外命令,方便实时查看 CPU 当前频率和温度状况。
@@ -196,9 +239,9 @@ $ watch -d sensors
## 3. PVE 定时重启 ## 3. PVE 定时重启
有时需要让 PVE 服务器周期性的定时重启,则可使用以下命令。 有时需要让 PVE 服务器周期性的定时重启,则可执行以下命令。
参数表示每月 `1``16` 号的 `5``0` 执行系统重启命令。 参数表示每月 `1``16` 号的 `02:30` 执行系统重启命令。
```bash ```bash
## 查看系统定时任务 ## 查看系统定时任务
@@ -213,7 +256,7 @@ $ crontab -e
```bash ```bash
## 定时任务配置项 ## 定时任务配置项
0 5 1,16 * * /usr/sbin/reboot 30 2 1,16 * * /usr/sbin/reboot
``` ```
@@ -223,7 +266,7 @@ $ crontab -e
配置系统自动更新之前,需检查系统当前定时器状态。 配置系统自动更新之前,需检查系统当前定时器状态。
后续将手动调整该定时器的时间,使其每 `5`凌晨 `02:00` 进行触发。 后续将手动调整该定时器的时间,使其每 `5` `01:30` 进行触发。
```bash ```bash
## 检查系统定时器 ## 检查系统定时器
@@ -232,17 +275,16 @@ $ systemctl status apt-daily-upgrade.timer
#### 系统定时器示例输出 #### 系统定时器示例输出
● apt-daily-upgrade.timer - Daily apt upgrade and clean activities ● apt-daily-upgrade.timer - Daily apt upgrade and clean activities
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled) Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Active: active (waiting) since Fri 2023-06-23 18:55:58 CST; 1 day 18h ago Active: active (waiting) since Tue 2023-08-01 13:01:19 CST; 27min ago
Until: Fri 2023-06-23 18:55:58 CST; 1 day 18h ago Trigger: Wed 2023-08-02 06:14:50 CST; 16h left
Trigger: Mon 2023-06-26 06:26:25 CST; 16h left
Triggers: ● apt-daily-upgrade.service Triggers: ● apt-daily-upgrade.service
Jun 23 18:55:58 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities. Aug 01 13:01:19 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
``` ```
### 4.2.配置更新策略 ### 4.2.配置更新策略
使用以下命令,启用系统自动更新。 执行以下命令,启用系统自动更新。
执行命令后,使用 “左右” 方向键进行选择,“回车” 键进行确认。 执行命令后,使用 “左右” 方向键进行选择,“回车” 键进行确认。
@@ -305,9 +347,9 @@ $ nano /etc/apt/apt.conf.d/50unattended-upgrades
- 自动重启:开启。 - 自动重启:开启。
- 自动重启时间:`05:00` - 自动重启时间:`02:30`
因为该配置文件很长,完整的配置文件可查看 [pve_50unattended_upgrades.conf](./src/pve_50unattended_upgrades.conf) 以便对比。 因为该配置文件很长,完整的配置文件可查看 [pve_50unattended_upgrades.conf](./src/pve/pve_50unattended_upgrades.conf) 以便对比。
```bash ```bash
## 删除以下行前面的注释符 // ,代表启用 ## 删除以下行前面的注释符 // ,代表启用
@@ -334,7 +376,7 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "05:00"; Unattended-Upgrade::Automatic-Reboot-Time "02:30";
``` ```
@@ -342,7 +384,7 @@ Unattended-Upgrade::Automatic-Reboot-Time "05:00";
系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。 系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。
完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve_apt_daily_upgrade.conf) 以便对比。 完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve/pve_apt_daily_upgrade.conf) 以便对比。
```bash ```bash
## 配置系统定时器 ## 配置系统定时器
@@ -356,7 +398,7 @@ $ systemctl edit apt-daily-upgrade.timer
[Timer] [Timer]
OnCalendar= OnCalendar=
OnCalendar=02:00 OnCalendar=01:30
RandomizedDelaySec=0 RandomizedDelaySec=0
``` ```
@@ -375,14 +417,13 @@ $ systemctl status apt-daily-upgrade.timer
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled) Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d
└─override.conf └─override.conf
Active: active (waiting) since Sun 2023-06-25 14:35:06 CST; 9s ago Active: active (waiting) since Tue 2023-08-01 13:37:41 CST; 9s ago
Until: Sun 2023-06-25 14:35:06 CST; 9s ago Trigger: Wed 2023-08-02 01:30:00 CST; 11h left
Trigger: Mon 2023-06-26 02:00:00 CST; 11h left
Triggers: ● apt-daily-upgrade.service Triggers: ● apt-daily-upgrade.service
Jun 25 14:35:06 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities. Aug 01 13:37:41 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Jun 25 14:35:06 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities... Aug 01 13:37:41 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities...
Jun 25 14:35:06 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities. Aug 01 13:37:41 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
``` ```
## 5.硬件直通 ## 5.硬件直通
@@ -391,7 +432,7 @@ Jun 25 14:35:06 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt u
参考官方文档 [qm_pci_passthrough](https://pve.proxmox.com/pve-docs/pve-admin-guide.html#qm_pci_passthrough) 和 [Pci passthrough](https://pve.proxmox.com/wiki/Pci_passthrough) 开启 PVE 硬件直通功能。 参考官方文档 [qm_pci_passthrough](https://pve.proxmox.com/pve-docs/pve-admin-guide.html#qm_pci_passthrough) 和 [Pci passthrough](https://pve.proxmox.com/wiki/Pci_passthrough) 开启 PVE 硬件直通功能。
使用 SSH 工具登录到 PVE 服务器,编辑系统 `Grub` 的配置文件 `/etc/default/grub` 使用终端工具登录到 PVE 服务器,编辑系统 `Grub` 的配置文件 `/etc/default/grub`
```bash ```bash
## 编辑 Grub 配置文件 ## 编辑 Grub 配置文件
@@ -443,7 +484,7 @@ vfio_pci
``` ```
使用以下命令更新 `initramfs` ,更新完成后,建议重启 PVE 服务器。 执行以下命令更新 `initramfs` ,更新完成后,建议重启 PVE 服务器。
```bash ```bash
## 更新 initramfs ## 更新 initramfs
@@ -452,7 +493,7 @@ $ update-initramfs -u -k all
### 5.3.检查硬件直通 ### 5.3.检查硬件直通
PVE 服务器重启完成后,再次使用 SSH 工具登录,并使用以下命令检查硬件直通状态。 PVE 服务器重启完成后,再次使用终端工具登录,并执行以下命令检查硬件直通状态。
主要查看 `IOMMU``Directed I/O``Interrupt Remapping` 的启用状态。 主要查看 `IOMMU``Directed I/O``Interrupt Remapping` 的启用状态。
@@ -492,7 +533,7 @@ $ dmesg | grep -e DMAR -e IOMMU -e AMD-Vi
[ 2.290568] DMAR: Intel(R) Virtualization Technology for Directed I/O [ 2.290568] DMAR: Intel(R) Virtualization Technology for Directed I/O
``` ```
检查系统 `IOMMU` 分组,使用以下命令。 检查系统 `IOMMU` 分组,执行以下命令。
```bash ```bash
## 检查 IOMMU group ## 检查 IOMMU group
@@ -526,7 +567,7 @@ $ find /sys/kernel/iommu_groups/ -type l
## 6.系统清理 ## 6.系统清理
PVE 系统配置完成后,可逐行执行以下命令,对系统进行清理。 PVE 系统配置完成后,可执行以下命令,对系统进行清理。
```bash ```bash
## 清理系统软件包 ## 清理系统软件包
@@ -539,10 +580,7 @@ $ rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
$ find /var/log/ -type f | xargs rm -rvf $ find /var/log/ -type f | xargs rm -rvf
## 清理命令历史记录文件 ## 清理命令历史记录文件
$ rm -rvf ~/.bash_history $ rm -rvf ~/.bash_history && history -c
## 清理命令历史
$ history -c
``` ```
至此 PVE 的系统调整已经完成。 至此 PVE 的系统调整已经完成。
+43 -32
View File
@@ -2,13 +2,13 @@
将虚拟机制作成模板,可在后续新建虚拟机时快速从模板中创建,减少系统安装配置时间。 将虚拟机制作成模板,可在后续新建虚拟机时快速从模板中创建,减少系统安装配置时间。
该虚拟机模板主要作内网 DNS 服务器使用,并会安装 Adguard Home 该虚拟机模板主要作内网 DNS 服务器,由 `Adguard Home``SmartDNS` 提供 DNS 解析服务
本文将使用 Debian 的云镜像 `debian-12-genericcloud-amd64.qcow2` 作为模板虚拟机的镜像。 本文将使用 Debian 的云镜像 `debian-12-generic-amd64.qcow2` 作为模板虚拟机的镜像。
访问 [Debian Official Cloud Images](https://cloud.debian.org/images/cloud/) 官方网站,下载最新版 `Bookworm` 云镜像以及对应的校验文件。 访问 [Debian Official Cloud Images](https://cloud.debian.org/images/cloud/) 官方网站,下载最新版 `Bookworm` 云镜像以及对应的校验文件。
![下载镜像](img/p04/download_genericcloud_image_qcow2.jpeg) ![下载镜像](img/p04/download_generic_image_qcow2.jpg)
## 1.创建虚拟机 ## 1.创建虚拟机
@@ -28,7 +28,7 @@
### 1.3.系统 ### 1.3.系统
SCSI 控制器保持默认 `VirtIO SCSI single` ,并勾选 `Qemu代理` 选项。 SCSI 控制器保持默认 `VirtIO SCSI single` ,机型可选 `q35` ,并勾选 `Qemu代理` 选项。
![虚拟机系统](img/p04/vm_system.jpeg) ![虚拟机系统](img/p04/vm_system.jpeg)
@@ -84,49 +84,49 @@ CPU `类别` 选择 `host` `插槽` 与 `核心` 数根据物理 CPU 核心
### 2.1.删除光驱 ### 2.1.删除光驱
查看虚拟机详情页,在虚拟机硬件配置页面,移除其 `CD/DVD驱动器` 查看虚拟机详情页,在虚拟机 `硬件` 配置页面,移除其 `CD/DVD驱动器`
![虚拟机删除光驱](img/p04/vm_delete_cd.jpeg) ![虚拟机删除光驱](img/p04/vm_delete_cd.jpeg)
### 2.2.导入镜像文件 ### 2.2.导入镜像文件
使用 SSH 工具登录 PVE 服务器,并进入 `tmp` 目录,逐行执行以下命令创建一个文件夹 使用终端工具登录 PVE 服务器,并进入 `/tmp` 目录,执行以下命令创建一个目录
```bash ```bash
## 创建存放 Debian 云镜像的临时目录 ## 创建存放 Debian 云镜像的临时目录
$ mkdir -p /tmp/Debian $ mkdir -p /tmp/Debian
## 进入文件夹 ## 进入目录
$ cd /tmp/Debian $ cd /tmp/Debian
``` ```
将 Debian 云镜像传输到该文件夹,并检查 `hash` 将 Debian 云镜像传输到该目录,并检查 `hash`
```bash ```bash
## 下载云镜像校验文件 ## 下载云镜像校验文件
$ wget https://cloud.debian.org/images/cloud/bookworm/latest/SHA512SUMS $ wget https://cloud.debian.org/images/cloud/bookworm/latest/SHA512SUMS
## 下载云镜像 ## 下载云镜像
$ wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2 $ wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-generic-amd64.qcow2
## 检查文件是否存在 ## 检查文件是否存在
$ ls -la $ ls -lah
## 显示校验文件内容 ## 显示校验文件内容
$ cat SHA512SUMS $ cat SHA512SUMS
## 计算文件 hash ## 计算文件 hash
$ sha512sum debian-12-genericcloud-amd64.qcow2 $ sha512sum debian-12-generic-amd64.qcow2
``` ```
确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1000` 确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1001`
```bash ```bash
## 将 qcow2 镜像导入虚拟机中 ## 将 qcow2 镜像导入虚拟机中
$ qm importdisk 1000 debian-12-genericcloud-amd64.qcow2 local-lvm $ qm importdisk 1001 debian-12-generic-amd64.qcow2 local-lvm
#### 镜像导入示例输出 #### 镜像导入示例输出
Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0' Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0'
``` ```
![虚拟机新磁盘](img/p04/vm_unused_hd.jpeg) ![虚拟机新磁盘](img/p04/vm_unused_hd.jpeg)
@@ -157,18 +157,6 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
![虚拟机ci参数](img/p04/vm_ci_details.jpeg) ![虚拟机ci参数](img/p04/vm_ci_details.jpeg)
### 2.4.添加串行端口
部分云镜像需要使用 `serial` 端口作为视频输出端口,否则虚拟机无法启动,因此给模板虚拟机添加串行端口。
点击顶部 `添加` 菜单,选择 `串行端口`
![虚拟机添加串口](img/p04/vm_serial.jpeg)
串行端口编号为 `0`
![虚拟机串口参数](img/p04/vm_serial_details.jpeg)
虚拟机硬件设备修改完成后,如下图所示。 虚拟机硬件设备修改完成后,如下图所示。
![虚拟机全部硬件](img/p04/vm_hardware_all.jpeg) ![虚拟机全部硬件](img/p04/vm_hardware_all.jpeg)
@@ -205,7 +193,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
## 4.设置 Cloud-Init ## 4.设置 Cloud-Init
进入左侧虚拟机 `Cloud-Init` 菜单,可以看到当前虚拟机的初始化参数。 进入左侧虚拟机 `Cloud-Init` 页面,可以看到当前虚拟机的初始化参数。
### 4.1.自动配置 IPv6 ### 4.1.自动配置 IPv6
@@ -215,7 +203,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
|--|--|--| |--|--|--|
|用户|`fox`|新系统的管理员账户| |用户|`fox`|新系统的管理员账户|
|密码|`********`|使用强密码| |密码|`********`|使用强密码|
|DNS域|`fox.local`|内网域名(可选)| |DNS域|`fox.home.arpa`|内网域名(可选)|
|DNS服务器|`172.16.1.1`|本机 DNS 服务器| |DNS服务器|`172.16.1.1`|本机 DNS 服务器|
|SSH公钥|`无`|使用秘钥登录服务器,暂不使用| |SSH公钥|`无`|使用秘钥登录服务器,暂不使用|
|Upgrade packages|`是`|启动时更新软件包,保持默认即可| |Upgrade packages|`是`|启动时更新软件包,保持默认即可|
@@ -237,17 +225,17 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
### 4.2.手动配置 IPv6 ### 4.2.手动配置 IPv6
当主路由配置了 ULA IPv6 网段,且希望指定内网 DNS 服务器的 ULA IPv6 地址时,需要调整 `Cloud-Init` 参数。 当主路由配置了 IPv6 ULA 网段,且希望指定内网 DNS 服务器的 IPv6 ULA 地址时,需要调整 `Cloud-Init` 参数。
本文 ULA IPv6 演示地址为 `fdac::/64` `DNS服务器``IP配置` 参数调整如下。 本文 IPv6 ULA 演示地址为 `fdac::/64` `DNS服务器``IP配置` 参数调整如下。
|参数|值|说明| |参数|值|说明|
|--|--|--| |--|--|--|
|DNS域|`fox.local`|内网域名(可选)| |DNS域|`fox.home.arpa`|内网域名(可选)|
|DNS服务器|`172.16.1.1 fdac::1`|本机 DNS 服务器| |DNS服务器|`172.16.1.1 fdac::1`|本机 DNS 服务器|
|IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置| |IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置|
`DNS服务器` 参数中需要加入主路由 LAN 口 ULA IPv6 地址。 `DNS服务器` 参数中需要加入主路由 LAN 口 IPv6 ULA 地址。
![CI网络配置](img/p04/vm_ci_dns_ula.jpeg) ![CI网络配置](img/p04/vm_ci_dns_ula.jpeg)
@@ -257,5 +245,28 @@ IPv6 使用静态地址后,并不影响虚拟机通过主路由获取公网 GU
![CI网络配置](img/p04/vm_ci_network_static.jpeg) ![CI网络配置](img/p04/vm_ci_network_static.jpeg)
## 5.设置备注信息
进入左侧虚拟机 `概要` 页面,修改虚拟机的备注信息。
```bash
### 服务器信息
- 系统: Debian12
- 用途: 内网 DNS 服务器 ( 模板 )
- 自启: 否
- 用户: fox
- IPv4 172.16.1.250/24
- IPv6 SLAAC
```
![虚拟机备注](img/p04/vm_notes.jpeg)
至此,模板虚拟机创建完成,可将该虚拟机开机。 至此,模板虚拟机创建完成,可将该虚拟机开机。
+30 -31
View File
@@ -21,8 +21,8 @@
- 保存文件,按下键盘 `Esc` 键,退出编辑模式,再输入组合键 `:wq` 即可保存。 - 保存文件,按下键盘 `Esc` 键,退出编辑模式,再输入组合键 `:wq` 即可保存。
```bash ```bash
## 编辑 ssh 配置文件 ## 编辑 SSH 配置文件
$ sudo vim /etc/ssh/sshd_config.d/server_sshd.conf $ sudo vim /etc/ssh/sshd_config.d/10-server-sshd.conf
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
@@ -39,17 +39,17 @@ UseDNS no
修改完成后,需要重启 SSH 服务。 修改完成后,需要重启 SSH 服务。
```bash ```bash
## 重启 sshd ## 重启 ssh.service
$ sudo systemctl restart ssh.service $ sudo systemctl restart ssh.service
``` ```
### 1.2.配置软件源 ### 1.2.配置软件源
使用 SSH 工具登录模板虚拟机,常用 SSH 工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。 使用终端工具登录模板虚拟机,常用终端工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。
首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](http://mirrors.ustc.edu.cn/help/debian.html) 镜像站作为演示。 首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](https://mirrors.ustc.edu.cn) 镜像站作为演示。
当系统版本发生变化时,请参考使用 snullp 大叔开发的 [配置生成器](https://mirrors.ustc.edu.cn/repogen/) 。 当系统版本发生变化时,请参考 USTC 镜像站的官方说明 [USTC Mirror Help - Debian](https://mirrors.ustc.edu.cn/help/debian.html) 。
Debian12 云镜像的软件源配置采用了 `DEB822` 格式,新版 `sources.list` 配置文件内容如下。 Debian12 云镜像的软件源配置采用了 `DEB822` 格式,新版 `sources.list` 配置文件内容如下。
@@ -89,7 +89,6 @@ $ cat /etc/apt/mirrors/debian-security.list
#### 关联配置文件示例输出 (关联部分 2 ) #### 关联配置文件示例输出 (关联部分 2 )
https://deb.debian.org/debian-security https://deb.debian.org/debian-security
``` ```
因此,修改 Debian12 软件源的方式也有两种,本文将尝试使用第 `2` 种修改方案。 因此,修改 Debian12 软件源的方式也有两种,本文将尝试使用第 `2` 种修改方案。
@@ -112,13 +111,15 @@ $ sudo vim /etc/apt/sources.list.d/debian.sources
Types: deb Types: deb
URIs: https://mirrors.ustc.edu.cn/debian URIs: https://mirrors.ustc.edu.cn/debian
Suites: bookworm bookworm-updates bookworm-backports Suites: bookworm bookworm-updates
Components: main contrib non-free non-free-firmware Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb Types: deb
URIs: https://mirrors.ustc.edu.cn/debian-security URIs: https://mirrors.ustc.edu.cn/debian-security
Suites: bookworm-security Suites: bookworm-security
Components: main contrib non-free non-free-firmware Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
``` ```
@@ -137,7 +138,7 @@ $ lsattr /etc/apt/sources.list.d/debian.sources
### 1.3.安装软件 ### 1.3.安装软件
软件源设置完成后,需要更新系统,逐行执行以下命令。 软件源设置完成后,需要更新系统,执行以下命令。
```bash ```bash
## 清理不必要的包 ## 清理不必要的包
@@ -147,20 +148,20 @@ $ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
$ sudo apt update $ sudo apt update
## 更新系统 ## 更新系统
$ sudo apt dist-upgrade $ sudo apt full-upgrade
``` ```
接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。 接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。
```bash ```bash
## 安装系统软件 ## 安装系统软件
$ sudo apt install qemu-guest-agent zsh git htop tmux cron nftables sshguard neovim $ sudo apt install qemu-guest-agent zsh git btop tmux cron nftables sshguard neovim
## 安装系统自动更新工具 ## 安装系统自动更新工具
$ sudo apt install unattended-upgrades powermgmt-base python3-gi $ sudo apt install unattended-upgrades powermgmt-base python3-gi
## 安装网络工具 ## 安装网络工具
$ sudo apt install iperf iperf3 iftop lsof ldnsutils $ sudo apt install iperf iperf3 iftop lsof knot-dnsutils
## 写入磁盘 ## 写入磁盘
$ sudo sync $ sudo sync
@@ -180,8 +181,8 @@ $ sudo nvim /etc/sysctl.d/99-sysctl.conf
在配置文件末尾输入以下配置项,注意配置中间的空格。 在配置文件末尾输入以下配置项,注意配置中间的空格。
```bash ```bash
# This configuration file is customized by fox # This configuration file is customized by fox,
# Optimize system parameters # Optimize sysctl parameters for local DNS server.
kernel.panic = 20 kernel.panic = 20
kernel.panic_on_oops = 1 kernel.panic_on_oops = 1
@@ -191,19 +192,21 @@ net.ipv4.tcp_congestion_control = bbr
# Other adjustable system parameters # Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.ipv4.conf.all.log_martians = 1 net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 100 net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_challenge_ack_limit = 1000 net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30 net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120 net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_max_orphans = 4096
net.ipv4.tcp_max_tw_buckets = 4096
net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.use_tempaddr = 0 net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0 net.ipv6.conf.default.use_tempaddr = 0
``` ```
保存该配置文件后,重启系统或者执行以下命令让配置生效。 保存该配置文件后,重启系统或者执行以下命令让配置生效。
@@ -230,20 +233,21 @@ Mon, 26 Jun 2023 16:16:16 +0800
Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。 Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。
调整 NTP 服务器参数,逐行执行以下命令。 调整 NTP 服务器参数,执行以下命令。
```bash ```bash
## 创建 NTP 配置文件的文件夹 ## 创建 NTP 配置文件的目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d $ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件 ## 创建 NTP 配置文件
$ sudo nvim /etc/systemd/timesyncd.conf.d/server_ntp.conf $ sudo nvim /etc/systemd/timesyncd.conf.d/10-server-ntp.conf
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
```bash ```bash
## NTP 配置项 # This configuration file is customized by fox,
# Optimize system NTP server.
[Time] [Time]
NTP=ntp.tencent.com ntp.aliyun.com NTP=ntp.tencent.com ntp.aliyun.com
@@ -335,7 +339,7 @@ $ sudo nvim /etc/apt/apt.conf.d/50unattended-upgrades
根据 “注释” 中相关说明,调整配置文件。 根据 “注释” 中相关说明,调整配置文件。
因为该配置文件很长,完整的配置文件可查看 [debian_50unattended_upgrades.conf](./src/debian_50unattended_upgrades.conf) 以便对比。 因为该配置文件很长,完整的配置文件可查看 [debian_dns_50unattended_upgrades.conf](./src/debian/debian_dns_50unattended_upgrades.conf) 以便对比。
```bash ```bash
## 删除以下行前面的注释符 // ,代表启用 ## 删除以下行前面的注释符 // ,代表启用
@@ -354,7 +358,7 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:30"; Unattended-Upgrade::Automatic-Reboot-Time "03:00";
``` ```
@@ -379,7 +383,7 @@ RandomizedDelaySec=0
设置完成后,重启自动更新定时器并检查其状态,执行以下命令。 设置完成后,重启自动更新定时器并检查其状态,执行以下命令。
在输出结果中看到系统自动更新的触发时间为凌晨 `02:00` 则表示设置正确。 在输出结果中看到系统自动更新的触发时间为 `02:00` 则表示设置正确。
```bash ```bash
## 重启触发器 ## 重启触发器
@@ -406,7 +410,7 @@ $ sudo crontab -e
```bash ```bash
## 定时任务配置项 ## 定时任务配置项
0 6 8,24 * * /usr/sbin/reboot 30 4 8,24 * * /usr/sbin/reboot
``` ```
@@ -435,8 +439,6 @@ Do you want to change your default shell to zsh? [Y/n] y
Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。 Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。
逐行执行以下命令,注意命令中的空格。
```bash ```bash
## 清理系统软件包 ## 清理系统软件包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge $ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
@@ -448,10 +450,7 @@ $ sudo rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
$ sudo find /var/log/ -type f | xargs sudo rm -rvf $ sudo find /var/log/ -type f | xargs sudo rm -rvf
## 清理命令历史记录文件 ## 清理命令历史记录文件
$ rm -rvf ~/.bash_history ~/.zsh_history $ rm -rvf ~/.bash_history ~/.zsh_history ~/.zcompdump* && history -c
## 清理命令历史
$ history -c
## 关闭系统 ## 关闭系统
$ sudo shutdown now $ sudo shutdown now
+481
View File
@@ -0,0 +1,481 @@
## 1.克隆虚拟机
在上一篇文章 [05.PVE制作虚拟机模板](./05.PVE制作虚拟机模板.md) 中,已经制作好了虚拟机模板。
接下来将使用该模板克隆出新的虚拟机,并安装 Adguard Home 作为内网的 DNS 服务器。
鼠标 **右键单击** 虚拟机模板,在弹出的菜单中选择 `克隆`
![克隆虚拟机](img/p06/vm_clone.jpeg)
在弹出的虚拟机克隆对话框中,根据实际情况及下方表格内容,修改虚拟机参数。
|参数|值|说明|
|--|--|--|
|目标节点|`node01`|当前 PVE 服务器节点|
|VM ID|`201`|可自定义,不能与现存虚拟机 `VM ID` 相同|
|名称|`DNS01`|可自定义,`Cloud-Init` 将使用该名称作为虚拟机 `hostname` |
|模式|`完整克隆`|选择虚拟机的克隆模式|
|目标存储|`local-lvm`|克隆出的虚拟机文件存储位置|
修改参数后,点击 `克隆` ,即可使用该模板克隆出新的虚拟机。
![克隆虚拟机参数](img/p06/vm_clone_vmid.jpeg)
## 2.调整 Cloud-Init
克隆出来的虚拟机的 `Cloud-Init` 参数默认与模板完全一致。
根据 **内部网络地址** 规划,内网 DNS 服务器 IPv4 地址规划如下:
- `172.16.1.2/24`
- `172.16.1.3/24`
因此需要调整新虚拟机的 `Cloud-Init` 参数。
- `IP配置` 中的 IPv4 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变。
- `IP配置` 中的 IPv6 地址参数为 `auto` ,网关保持为空。
需要注意的是,如果修改了 `用户` 参数,相当于新建了一个系统管理员,之前设置的 `oh-my-zsh` 需要在新管理员下重新设置。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_slaac.jpeg)
当主路由配置了 IPv6 ULA 网段,内网 DNS 服务器 IPv6 ULA 地址规划如下:
- `fdac::2/64`
- `fdac::3/64`
此时需进一步调整新虚拟机的 `Cloud-Init` 参数,让该虚拟机使用指定的 IPv6 ULA 地址,参数如下。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_static.jpeg)
## 3.调整配置参数
在 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) 中提到过,新虚拟机需要修改配置参数才能自动启动。
进入左侧虚拟机 `选项` 页面,将虚拟机 `开机自启动` 参数设置为 `是`
![克隆虚拟机自动启动](img/p06/vm_clone_autostart.jpeg)
鼠标 **双击** `启动/关机顺序` 选项,可调整虚拟机的自动开机参数。
`启动/关机顺序``2` ,表示该虚拟机第 `2` 个启动,倒数第 `2` 个关机。
`启动延时``10` ,表示该虚拟机在 PVE 启动后,延迟 `10` 秒后自动启动。
![克隆虚拟机自动启动顺序](img/p06/vm_clone_autostart_order.jpeg)
## 4.调整系统端口
设置完成后,将该虚拟机开机,使用终端工具登录,并执行以下命令检查端口占用。
```bash
## 检查 53 端口占用
$ sudo lsof -n -i :53
#### 端口占用示例输出
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
systemd-r 1797 systemd-resolve 18u IPv4 23024 0t0 UDP 127.0.0.53:domain
systemd-r 1797 systemd-resolve 19u IPv4 23025 0t0 TCP 127.0.0.53:domain (LISTEN)
systemd-r 1797 systemd-resolve 20u IPv4 23026 0t0 UDP 127.0.0.54:domain
systemd-r 1797 systemd-resolve 21u IPv4 23027 0t0 TCP 127.0.0.54:domain (LISTEN)
```
当前系统 `53` 端口被 `systemd-resolved.service` 占用,会导致设置 DNS 服务时监听端口失败。
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
```bash
## 创建 systemd-resolved 配置目录
$ sudo mkdir -p /etc/systemd/resolved.conf.d
## 创建 systemd-resolved 配置文件
$ sudo nvim /etc/systemd/resolved.conf.d/10-server-dns.conf
```
在配置文件中添加以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize system resolve parameters for local DNS server.
[Resolve]
DNS=127.0.0.1
DNS=::1
DNSStubListener=no
```
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,执行以下命令。
```bash
## 创建 resolv.conf 软链接
$ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
```
配置完成后,需重启 `systemd-resolved.service` 服务,并再次检查系统 `53` 端口占用。
```bash
## 重启 systemd-resolved.service
$ sudo systemctl restart systemd-resolved.service
```
## 5. Adguard Home
`Adguard Home` 将采用 `snap` 形式安装,执行以下命令。
```bash
## 安装 Snap
$ sudo apt install snapd
## 安装 Adguard Home
$ sudo snap install adguard-home
```
### 5.1.自动更新
查看 `Snap` 当前的更新策略,执行以下命令。
```bash
## 显示当前 Snap 自动更新设置
$ sudo snap refresh --time
```
`Snap` 自动更新时间设置为每天 `2:30-3:30``14:30-15:30` 两个时间段。
```bash
## 修改 Snap 自动更新时间
$ sudo snap set system refresh.timer=2:30-3:30,14:30-15:30
## 其他 Snap 自动更新时间设置语法参考
$ sudo snap set system refresh.timer=mon,2:30,,fri,2:30
```
### 5.2.配置 Adguard Home
关于 `Adguard Home` 配置相关内容,请参阅 [Adguard Home 折腾手记](https://gitee.com/callmer/agh_toss_notes) 。
### 5.3.定时任务
本步骤为可选操作,主要用于设置 `Adguard Home` 定时重启。
```bash
## 查看系统定时任务
$ sudo crontab -l
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
30 4 * * * /usr/bin/snap restart adguard-home
```
## 6. SmartDNS
若需使用 `SmartDNS` 代替 `Adguard Home` ,可使用 Debian 官方源进行安装,但其版本通常较为 “过时” 。
因此,更推荐使用其 Github 仓库中的最新稳定版进行安装,官方仓库请参阅 [pymumu/smartdns](https://github.com/pymumu/smartdns/releases) 。
多数情况下,`SmartDNS` 足以提供良好的 DNS 解析服务,但为了进一步优化 DNS 解析流程,推荐与 `Dnsmasq` 嵌套使用。
```bash
## 安装 Dnsmasq
$ sudo apt install dnsmasq
```
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
```bash
## 检查 dnsmasq.service
$ sudo systemctl status dnsmasq.service
## 设置 dnsmasq.service 开机自启
$ sudo systemctl enable dnsmasq.service
## 停止 dnsmasq.service
$ sudo systemctl stop dnsmasq.service
```
下载 `SmartDNS` 最新版本时,请根据系统架构选择合适的版本,执行以下命令。
```bash
## 创建存放 SmartDNS 安装包的临时目录
$ mkdir -p /tmp/SmartDNS
## 进入目录
$ cd /tmp/SmartDNS
## 下载 SmartDNS 安装包
$ curl -LR -O https://github.com/pymumu/smartdns/releases/download/Release46/smartdns.1.2024.06.12-2222.x86_64-linux-all.tar.gz
## 解压缩 SmartDNS 安装包
$ tar zxf smartdns.1.2024.06.12-2222.x86_64-linux-all.tar.gz
## 进入安装包目录
$ cd smartdns
## 设置脚本可执行权限
$ chmod +x ./install
## 安装 SmartDNS
$ sudo ./install -i
```
修改 `SmartDNS` 配置之前,需检查 `smartdns.service` 服务状态,确保该服务开机自启。
```bash
## 检查 smartdns.service
$ sudo systemctl status smartdns.service
## 设置 smartdns.service 开机自启
$ sudo systemctl enable smartdns.service
```
### 6.1. SmartDNS 附加配置
本步骤为可选操作,通过安装 `SmartDNS` 附加配置文件,以达到屏蔽广告或加速中国境内域名解析速度的目的。
若需使用 `SmartDNS` 屏蔽广告,则需下载广告规则配置文件。
```bash
## 创建 SmartDNS 配置文件目录
$ sudo mkdir -p /etc/smartdns.d
## 下载广告规则配置文件
$ sudo curl -LR -o /etc/smartdns.d/anti-ad.smartdns.conf https://anti-ad.net/anti-ad-for-smartdns.conf
```
`SmartDNS` 的加速规则通过 `bash` 脚本安装,脚本生成的配置文件位于 `/etc/smartdns.d` 目录。
关于脚本的详细介绍,请参阅 [SmartDNS China List 安装脚本](https://gitee.com/callmer/smartdns_china_list_installer) 。
```bash
## 下载加速规则安装脚本
$ sudo curl -LR -o /opt/smartdns-plugin.sh https://gitee.com/callmer/smartdns_china_list_installer/raw/main/smartdns_plugin.sh
## 设置脚本可执行权限
$ sudo chmod +x /opt/smartdns-plugin.sh
## 设置脚本文件防篡改
$ sudo chattr +i /opt/smartdns-plugin.sh
## 执行脚本
$ sudo bash /opt/smartdns-plugin.sh
```
### 6.2. SmartDNS 主配置
`SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/) 。
修改 `SmartDNS` 主配置文件之前,建议关闭 `SmartDNS` 并清理 DNS 缓存文件。
```bash
## 关闭 smartdns.service
$ sudo systemctl stop smartdns.service
## 清理缓存
$ sudo rm -rvf /var/cache/smartdns
## 清理进程标识文件
$ sudo rm -rvf /var/run/smartdns.pid /run/smartdns.pid
```
`SmartDNS` 的主配置文件一般位于 `/etc/smartdns` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 SmartDNS 主配置文件
$ sudo mv /etc/smartdns/smartdns.conf /etc/smartdns/smartdns.conf.bak
```
使用 `neovim` 编辑器创建 `SmartDNS` 主配置文件,执行以下命令。
```bash
## 创建 SmartDNS 主配置文件
$ sudo nvim /etc/smartdns/smartdns.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 由于修改了缓存路径,`SmartDNS` 的缓存将在系统重启时自动删除,请根据实际情况进行调整
- `SmartDNS` 端口监听参数为 `6053@lo` ,请根据实际情况进行调整
- `edns-client-subnet` 为 EDNS 客户端子网,演示中 `202.103.24.68` 为湖北武汉市 DNS 服务器地址,请根据实际情况进行调整
- 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整
```bash
# This configuration file is customized by fox,
# Optimize SmartDNS parameters for local DNS server.
#
# For use common DNS server as upstream DNS server,
# please modify 'server' parameter according to
# your network environment.
#
# eg:
# server 119.29.29.29
# server 223.5.5.5
# server 114.114.114.114
# server 2402:4e00::
# server 2400:3200::1
conf-file /etc/smartdns.d/*.conf
cache-file /tmp/smartdns.cache
log-level notice
bind [::]:6053@lo
bind-tcp [::]:6053@lo
serve-expired yes
serve-expired-ttl 129600
serve-expired-reply-ttl 30
prefetch-domain yes
serve-expired-prefetch-time 21600
force-qtype-SOA 65
max-query-limit 1024
edns-client-subnet 202.103.24.68
server-tcp 119.29.29.29 -group dnspod -exclude-default-group
server-tcp 2402:4e00:: -group dnspod -exclude-default-group
nameserver /doh.pub/dnspod
nameserver /dot.pub/dnspod
server-tcp 223.5.5.5 -group alidns -exclude-default-group
server-tcp 2400:3200::1 -group alidns -exclude-default-group
nameserver /dns.alidns.com/alidns
server 172.16.1.1 -group intranet -exclude-default-group
nameserver /fox.home.arpa/intranet
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
server-tls dot.pub
server-tls dns.alidns.com
server-https https://doh.pub/dns-query
server-https https://dns.alidns.com/dns-query
```
### 6.3.定时任务
本步骤为可选操作,主要用于设置 `SmartDNS` 定时更新附加配置文件和定时重启。
```bash
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/anti-ad.smartdns.conf https://anti-ad.net/anti-ad-for-smartdns.conf
30 9 * * * /usr/bin/systemctl restart smartdns.service
```
若使用了 `SmartDNS` 加速规则的安装脚本,由于脚本自带服务重启功能,因此定时任务可修改如下。
```bash
## 定时任务配置项
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/anti-ad.smartdns.conf https://anti-ad.net/anti-ad-for-smartdns.conf
30 9 * * * /usr/bin/bash /opt/smartdns-plugin.sh
```
### 6.4.配置 Dnsmasq
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 Dnsmasq 主配置文件
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash
## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
- `Dnsmasq` 有且仅有 `SmartDNS` 作为上游 DNS 服务器
```bash
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local DNS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=10800
fast-dns-retry=1800
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-resolv
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/lan/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/fox.home.arpa/172.16.1.1
server=127.0.0.1#6053
server=::1#6053
```
至此,新虚拟机已配置完成,重启后即可作为内网 DNS 服务器使用。
-332
View File
@@ -1,332 +0,0 @@
## 1.克隆虚拟机
在上一篇文章 [05.PVE制作虚拟机模板](./05.PVE制作虚拟机模板.md) 中,已经制作好了虚拟机模板。
接下来将使用该模板克隆出新的虚拟机,并安装 Adguard Home 作为内网的 DNS 服务器。
鼠标 **右键单击** 虚拟机模板,在弹出的菜单中选择 `克隆`
![克隆虚拟机](img/p06/vm_clone.jpeg)
在弹出的虚拟机克隆对话框中,根据实际情况及下方表格内容,修改虚拟机参数。
|参数|值|说明|
|--|--|--|
|目标节点|`node01`|当前 PVE 服务器节点|
|VM ID|`201`|可自定义,不能与现存虚拟机 `VM ID` 相同|
|名称|`DNS01`|可自定义,`Cloud-Init` 将使用该名称作为虚拟机 `hostname` |
|模式|`完整克隆`|选择虚拟机的克隆模式|
|目标存储|`local-lvm`|克隆出的虚拟机文件存储位置|
修改参数后,点击 `克隆` ,即可使用该模板克隆出新的虚拟机。
![克隆虚拟机参数](img/p06/vm_clone_vmid.jpeg)
## 2.调整 Cloud-Init
克隆出来的虚拟机的 `Cloud-Init` 参数默认与模板完全一致。
根据 **内部网络地址** 规划,内网 DNS 服务器 IP 地址分别为:
- `172.16.1.2/24 (fdac::2/64)`
- `172.16.1.3/24 (fdac::3/64)`
因此需要调整新虚拟机的 `Cloud-Init` 参数。
- `IP配置` 中的 IPv4 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变。
- `IP配置` 中的 IPv6 地址参数为 `fdac::2/64` ,网关保持为空。
需要注意的是,如果修改了 `用户` 参数,相当于新建了一个系统管理员,之前设置的 `oh-my-zsh` 需要在新管理员下重新设置。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_slaac.jpeg)
当主路由配置了 ULA IPv6 网段,且指定了内网 DNS 服务器的 ULA IPv6 地址时,参数如下。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_static.jpeg)
## 3.调整配置参数
在 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) 中提到过,新虚拟机需要修改配置参数才能自动启动。
进入左侧虚拟机 `选项` 页面,将虚拟机 `开机自启动` 参数设置为 `是`
![克隆虚拟机自动启动](img/p06/vm_clone_autostart.jpeg)
鼠标 **双击** `启动/关机顺序` 选项,可调整虚拟机的自动开机参数。
`启动/关机顺序``2` ,表示该虚拟机第 `2` 个启动,倒数第 `2` 个关机。
`启动延时``10` ,表示该虚拟机在 PVE 启动后,延迟 `10` 秒后自动启动。
![克隆虚拟机自动启动顺序](img/p06/vm_clone_autostart_order.jpeg)
## 4.调整系统端口
设置完成后,将该虚拟机开机,使用 SSH 工具登录,并使用以下命令检查端口占用。
```bash
## 检查 53 端口占用
$ sudo lsof -i :53
#### 端口占用示例输出
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
systemd-r 347 systemd-resolve 17u IPv4 13445 0t0 UDP localhost:domain
systemd-r 347 systemd-resolve 18u IPv4 13446 0t0 TCP localhost:domain (LISTEN)
systemd-r 347 systemd-resolve 19u IPv4 13447 0t0 UDP localhost:domain
systemd-r 347 systemd-resolve 20u IPv4 13448 0t0 TCP localhost:domain (LISTEN)
```
当前系统 `53` 端口被 `systemd-resolved.service` 占用,会导致设置 DNS 服务时监听端口失败。
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,逐行执行以下命令。
```bash
## 创建 systemd-resolved 配置文件夹
$ sudo mkdir -p /etc/systemd/resolved.conf.d
## 创建 systemd-resolved 配置文件
$ sudo nvim /etc/systemd/resolved.conf.d/server_dns.conf
```
在配置文件中添加以下配置项,并保存。
```bash
## systemd-resolved 配置项
[Resolve]
DNS=127.0.0.1
DNSStubListener=no
```
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,逐行执行以下命令。
```bash
## 备份 resolv.conf 配置文件
$ sudo mv /etc/resolv.conf /etc/resolv.conf.bak
## 创建 resolv.conf 软链接
$ sudo ln -s /run/systemd/resolve/resolv.conf /etc/resolv.conf
```
配置完成后,需重启 `systemd-resolved.service` 服务,并再次检查系统 `53` 端口占用。
```bash
## 重启 systemd-resolved 服务
$ sudo systemctl restart systemd-resolved.service
```
## 5. Adguard Home
`Adguard Home` 将采用 `snap` 形式安装,逐行执行以下命令。
```bash
## 安装 snap
$ sudo apt install snapd
## 安装 Adguard Home
$ sudo snap install adguard-home
```
### 5.1.自动更新
查看 `Snap` 当前的更新策略,执行以下命令。
```bash
## 显示当前 Snap 自动更新设置
$ sudo snap refresh --time
```
`Snap` 自动更新时间设置为每天 `2:30-3:30``14:30-15:30` 两个时间段。
```bash
## 修改 Snap 自动更新时间
$ sudo snap set system refresh.timer=2:30-3:30,14:30-15:30
## 其他 Snap 自动更新时间设置语法参考
$ sudo snap set system refresh.timer=mon,2:30,,fri,2:30
```
### 5.2.配置 Adguard Home
关于 `Adguard Home` 配置相关内容,请参阅 [Adguard Home 折腾手记](https://gitee.com/callmer/agh_toss_notes) 。
### 5.3.定时任务
本步骤为可选操作,主要设置定时重启 `Adguard Home`
```bash
## 查看系统定时任务
$ sudo crontab -l
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
0 5 * * * /usr/bin/snap restart adguard-home
```
## 6. SmartDNS
若需使用 `SmartDNS` 代替 `Adguard Home` ,可使用 Debian 官方源进行安装,但其版本通常较为 “过时” 。
```bash
## 安装 SmartDNS
$ sudo apt install smartdns
```
因此,更推荐使用其 Github 仓库中的最新稳定版进行安装,官方仓库请参阅 [pymumu/smartdns](https://github.com/pymumu/smartdns/releases) 。
下载 `SmartDNS` 最新版本时,请根据系统架构选择合适的版本,逐行执行以下命令。
```bash
## 创建存放 SmartDNS 安装包的临时目录
$ mkdir -p /tmp/SmartDNS
## 进入文件夹
$ cd /tmp/SmartDNS
## 下载 SmartDNS 安装包
$ wget https://github.com/pymumu/smartdns/releases/download/Release42/smartdns.1.2023.05.07-1641.x86_64-linux-all.tar.gz
## 解压缩 SmartDNS 安装包
$ tar zxf smartdns.1.2023.05.07-1641.x86_64-linux-all.tar.gz
## 进入安装包目录
$ cd smartdns
## 赋予安装脚本执行权限
$ chmod +x ./install
## 安装 SmartDNS
$ sudo ./install -i
```
修改 `SmartDNS` 配置之前,需检查 `smartdns.service` 服务状态,确保该服务开机自启动。
```bash
## 检查 smartdns.service
$ sudo systemctl status smartdns.service
## 设置 smartdns.service 开机自启动
$ sudo systemctl enable smartdns.service
```
### 6.1.配置 SmartDNS
`SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/) 。
若需使用 `SmartDNS` 过滤广告,则需下载其广告过滤配置文件,为可选操作。
```bash
## 下载广告过滤配置文件
$ sudo wget https://anti-ad.net/anti-ad-for-smartdns.conf -O /etc/smartdns/anti-ad-smartdns.conf
```
`SmartDNS` 的主配置文件一般位于 `/etc/smartdns` 目录下,修改配置文件之前,使用以下命令将其备份。
```bash
## 备份 SmartDNS 主配置文件
$ sudo mv /etc/smartdns/smartdns.conf /etc/smartdns/smartdns.conf.bak
```
使用 `neovim` 编辑器创建 `SmartDNS` 主配置文件,执行以下命令。
```bash
## 创建 SmartDNS 主配置文件
$ sudo nvim /etc/smartdns/smartdns.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 当不使用 `anti-ad-smartdns.conf` 进行广告过滤时,需移除主配置文件中对应配置项。
- 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整。
- 若仅需 `DoT` / `DoH` 作为上游 DNS 服务器,可移除 `server-tcp` 相关配置项。
```bash
# This configuration file is customized by fox,
# Optimize SmartDNS parameters for local DNS server.
conf-file /etc/smartdns/anti-ad-smartdns.conf
bind [::]:53
bind-tcp [::]:53
serve-expired yes
serve-expired-ttl 86400
serve-expired-reply-ttl 3
prefetch-domain yes
serve-expired-prefetch-time 43200
speed-check-mode ping,tcp:80,tcp:443
force-qtype-SOA 65
log-level warn
server 119.29.29.29 -group dnspod
server 2402:4e00:: -group dnspod
server 223.5.5.5 -group alidns
server 2400:3200::1 -group alidns
nameserver /doh.pub/dnspod
nameserver /dot.pub/dnspod
nameserver /dns.alidns.com/alidns
server 172.16.1.1 -group fox
server fdac::1 -group fox
nameserver /fox.local/fox
domain-rules /fox.local/ -no-cache -speed-check-mode none
server-tcp 119.29.29.29
server-tcp 223.5.5.5
server-tcp 114.114.114.114
server-tcp 2402:4e00::
server-tcp 2400:3200::1
server-tcp 2400:3200:baba::1
server-tls 1.12.12.12 -spki-pin 5TIMjgyMhA0qmPdK+AM9LX6vNI/9EPBydh/ZXdfcYmI= -host-name dot.pub
server-tls 120.53.53.53 -spki-pin 5TIMjgyMhA0qmPdK+AM9LX6vNI/9EPBydh/ZXdfcYmI= -host-name dot.pub
server-tls 223.5.5.5 -spki-pin ZwR21gnCMTzsM6VWtnb/azufgYegWWuhE9reP5tamWU= -host-name dns.alidns.com
server-tls 223.6.6.6 -spki-pin ZwR21gnCMTzsM6VWtnb/azufgYegWWuhE9reP5tamWU= -host-name dns.alidns.com
server-https https://doh.pub/dns-query
server-https https://dns.alidns.com/dns-query
```
### 6.2.定时任务
本步骤为可选操作,主要设置 `SmartDNS` 定时更新广告过滤配置文件和定时重启。
```bash
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
0 5 * * * /usr/bin/wget -q --tries=10 --retry-connrefused --random-wait https://anti-ad.net/anti-ad-for-smartdns.conf -O /etc/smartdns/anti-ad-smartdns.conf
30 5 * * * /usr/bin/systemctl restart smartdns.service
```
至此,新虚拟机已配置完成,可作为内网 DNS 服务器使用。
+627
View File
@@ -0,0 +1,627 @@
## 0.前期准备
某些业务场景下需要构建安全可靠的网络隧道,来打通异地内网环境或从外部访问内网的私有资源。
经过实际测试,当 TS 服务器具有 IPv6 GUA 地址时,能稳定建立隧道。
本文将使用 Debian 云镜像以及 `Tailscale` 来制作内网组网服务器。
对于虚拟机创建部分,请参考 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) ,其他 `Cloud-Init` 相关参数如下。
|参数|值|说明|
|--|--|--|
|虚拟机名称|`SVR01`| TS 服务器 `主机名` |
|DNS 域|`fox.home.arpa`| TS 服务器 `Cloud-Init` |
|DNS 服务器|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|IPv4|`172.16.1.4/24`| TS 服务器 `Cloud-Init` |
|IPv4 网关|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|IPv6|`SLAAC`| TS 服务器 `Cloud-Init` |
## 1.配置系统
由于 TS 服务器具备路由功能,所以在配置方法和系统参数方面与内网 DNS 服务器有一些区别。
### 1.1.配置 SSH
与配置内网 DNS 服务器时一样,首先需要调整系统的 SSH 登录权限参数。
在虚拟机的命令行界面,使用 `vim` 编辑器编辑 `sshd` 服务的配置文件,执行以下命令。
```bash
## 编辑 SSH 配置文件
$ sudo vim /etc/ssh/sshd_config.d/10-server-sshd.conf
```
在配置文件中添加以下配置项,并保存。
```bash
## SSH 配置项
PasswordAuthentication yes
PermitEmptyPasswords no
UseDNS no
```
修改完成后,需要重启 SSH 服务。
```bash
## 重启 ssh.service
$ sudo systemctl restart ssh.service
```
### 1.2.配置软件源
使用终端工具登录 TS 服务器,常用终端工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。
首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](https://mirrors.ustc.edu.cn) 镜像站作为演示。
当系统版本发生变化时,请参考 USTC 镜像站的官方说明 [USTC Mirror Help - Debian](https://mirrors.ustc.edu.cn/help/debian.html) 。
使用 `vim` 编辑器编辑 `debian.sources` 配置文件,执行以下命令。
```bash
## 编辑 debian.sources 配置文件
$ sudo vim /etc/apt/sources.list.d/debian.sources
```
删除里面全部内容,添加以下配置项,并保存。
```bash
## 系统软件源配置项
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian
Suites: bookworm bookworm-updates
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian-security
Suites: bookworm-security
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
```
为了防止 `Cloud-Init` 服务意外修改软件源配置,需要添加文件保护,执行以下命令。
```bash
## 增加文件保护
$ sudo chattr +i /etc/apt/sources.list.d/debian.sources
## 检查文件保护
$ lsattr /etc/apt/sources.list.d/debian.sources
#### 示例输出
----i---------e------- /etc/apt/sources.list.d/debian.sources
```
进一步添加 TS 签名密钥以及软件源,执行以下命令。
```bash
## 添加 TS 签名密钥
$ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.noarmor.gpg | sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg > /dev/null
## 添加 TS 软件源
$ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.tailscale-keyring.list | sudo tee /etc/apt/sources.list.d/tailscale.list
```
### 1.3.安装软件
软件源设置完成后,需要更新系统,执行以下命令。
```bash
## 清理不必要的包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
## 更新软件源
$ sudo apt update
## 更新系统
$ sudo apt full-upgrade
```
接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。
```bash
## 安装系统软件
$ sudo apt install qemu-guest-agent zsh git btop tmux cron nftables sshguard neovim
## 安装系统自动更新工具
$ sudo apt install unattended-upgrades powermgmt-base python3-gi
## 安装网络工具
$ sudo apt install iperf iperf3 iftop lsof knot-dnsutils dnsmasq conntrack
## 安装 TS
$ sudo apt install tailscale
## 写入磁盘
$ sudo sync
```
### 1.4.调整内核模块
使用 `neovim` 编辑器编辑 **内核模块** 配置文件,执行以下命令。
```bash
## 创建 内核模块 配置文件
$ sudo nvim /etc/modules-load.d/10-server-modules.conf
```
在配置文件中添加以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize netfilter related modules at system boot.
nf_conntrack
```
### 1.5.调整内核参数
使用 `neovim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
```bash
## 编辑 内核参数 配置文件
$ sudo nvim /etc/sysctl.d/99-sysctl.conf
```
在配置文件末尾输入以下配置项,注意配置中间的空格。
```bash
# This configuration file is customized by fox,
# Optimize sysctl parameters for local TS server.
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = cake
net.ipv4.tcp_congestion_control = bbr
net.ipv4.ip_forward = 1
net.ipv6.conf.all.forwarding = 1
net.ipv6.conf.default.forwarding = 1
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.all.arp_ignore = 1
net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 256
net.ipv4.route.error_burst = 500
net.ipv4.route.error_cost = 100
net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
net.ipv6.conf.all.accept_source_route = 0
net.ipv6.conf.default.accept_source_route = 0
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
net.netfilter.nf_conntrack_acct = 1
net.netfilter.nf_conntrack_checksum = 0
net.netfilter.nf_conntrack_tcp_timeout_established = 7440
```
保存该配置文件后,重启系统或者执行以下命令让配置生效。
```bash
## 让内核参数生效
$ sudo sysctl -f
```
### 1.6.调整系统时间
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
```bash
## 设置系统时区
$ sudo timedatectl set-timezone Asia/Shanghai
## 检查系统时间
$ date -R
```
Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。
调整 NTP 服务器参数,执行以下命令。
```bash
## 创建 NTP 配置文件的目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件
$ sudo nvim /etc/systemd/timesyncd.conf.d/10-server-ntp.conf
```
在配置文件中添加以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize system NTP server.
[Time]
NTP=ntp.tencent.com ntp.aliyun.com
```
保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。
```bash
## 重启 chrony 服务
$ sudo systemctl restart systemd-timesyncd.service
## 检查系统 NTP 服务器
$ sudo systemctl status systemd-timesyncd.service
```
### 1.7.配置自动更新
配置系统自动更新策略,执行以下命令,使用键盘 `左右方向键` 进行选择,`回车键` 进行确认。
```bash
## 配置自动更新策略
$ sudo dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”)
#### 系统自动更新示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
```
进一步调整 `20auto-upgrades` 配置文件。
```bash
## 编辑 20auto-upgrades 配置文件
$ sudo nvim /etc/apt/apt.conf.d/20auto-upgrades
```
删除里面全部内容,添加以下配置项,并保存。
配置文件中,用来控制更新周期的参数为 `APT::Periodic::Unattended-Upgrade` `7` 表示更新周期为 `7` 天。
```bash
## 系统更新周期配置项
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "7";
APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1";
```
进一步调整 `50unattended-upgrades` 配置文件。
```bash
## 编辑 50unattended-upgrades 配置文件
$ sudo nvim /etc/apt/apt.conf.d/50unattended-upgrades
```
根据 “注释” 中相关说明,调整配置文件。
因为该配置文件很长,完整的配置文件可查看 [debian_ts_50unattended_upgrades.conf](./src/debian/debian_ts_50unattended_upgrades.conf) 以便对比。
```bash
## 删除以下行前面的注释符 // ,代表启用
"origin=Debian,codename=${distro_codename}-updates";
## 添加 TS 更新项目
"origin=Tailscale,codename=${distro_codename},label=Tailscale";
## 在配置文件末尾增加以下配置项,代表启用,并调整参数
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
```
系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。
```bash
## 配置系统定时器
$ sudo systemctl edit apt-daily-upgrade.timer
```
根据配置文件中的提示,在中间空白处填入以下配置项。
```bash
## 定时器配置项
[Timer]
OnCalendar=
OnCalendar=02:00
RandomizedDelaySec=0
```
设置完成后,重启自动更新定时器并检查其状态,执行以下命令。
在输出结果中,看到系统自动更新的触发时间为 `02:00` 则表示设置正确。
```bash
## 重启触发器
$ sudo systemctl restart apt-daily-upgrade.timer
## 再次检查触发器状态
$ sudo systemctl status apt-daily-upgrade.timer
```
### 1.8.配置防火墙
修改防火墙配置之前,需检查 `nftables.service` 服务状态,确保该服务开机自启。
```bash
## 检查 nftables.service
$ sudo systemctl status nftables.service
## 设置 nftables.service 开机自启
$ sudo systemctl enable nftables.service
```
使用 `neovim` 编辑器修改 `nftables` 配置文件,执行以下命令。
```bash
## 备份 nftables 配置文件
$ sudo mv /etc/nftables.conf /etc/nftables.conf.bak
## 创建新的 nftables 配置文件
$ sudo nvim /etc/nftables.conf
```
由于防火墙配置文件很长,因此请查阅文件 [debian_ts_nftables.conf](./src/debian/debian_ts_nftables.conf) 进行复制。
配置完成后,需重启 `nftables.service` 服务。
```bash
## 重启 nftables.service
$ sudo systemctl restart nftables.service
```
### 1.9.调整系统端口
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
```bash
## 创建 systemd-resolved 配置目录
$ sudo mkdir -p /etc/systemd/resolved.conf.d
## 创建 systemd-resolved 配置文件
$ sudo nvim /etc/systemd/resolved.conf.d/10-server-dns.conf
```
在配置文件中添加以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize system resolve parameters for local TS server.
[Resolve]
DNS=127.0.0.1
DNS=::1
DNSStubListener=no
```
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,执行以下命令。
```bash
## 创建 resolv.conf 软链接
$ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
```
配置完成后,需重启 `systemd-resolved.service` 服务。
```bash
## 重启 systemd-resolved.service
$ sudo systemctl restart systemd-resolved.service
```
### 1.10.配置 Dnsmasq
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
```bash
## 检查 dnsmasq.service
$ sudo systemctl status dnsmasq.service
## 设置 dnsmasq.service 开机自启
$ sudo systemctl enable dnsmasq.service
```
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 Dnsmasq 主配置文件
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash
## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
- `Dnsmasq` 上游 DNS 服务器分为三类,请根据实际情况进行调整
- `server=/ts.net/100.100.100.100` TS 服务 `MagicDNS` 专用 DNS 服务器
- `server=/fox.home.arpa/172.16.1.1` :内网域名解析 DNS 服务器,通常为主路由地址
- `server` 参数中的其他 DNS 服务器供 TS 服务器自身及其下游设备使用
```bash
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local TS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=10800
fast-dns-retry=1800
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/lan/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1
server=172.16.1.1
```
配置完成后,需重启 `dnsmasq.service` 服务。
```bash
## 重启 dnsmasq.service
$ sudo systemctl restart dnsmasq.service
```
### 1.11.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 返回 home 目录
$ cd
## 使用 curl 安装 oh-my-zsh
$ sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)"
## 或者使用 wget 安装 oh-my-zsh
$ sh -c "$(wget https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh -O -)"
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
```
## 2.配置 Tailscale
根据不同的启动参数,TS 服务将具有不同的业务能力。
若仅需 TS 组网功能,执行以下命令。
```bash
## TS 普通组网模式
$ sudo tailscale up
```
若需 TS 提供 `Exit Node` 功能,执行以下命令。
```bash
## TS Exit Node 模式
$ sudo tailscale up --advertise-exit-node --reset
## TS Exit Node 模式,但不使用 MagicDNS
$ sudo tailscale up --advertise-exit-node --accept-dns=false --reset
```
若需 TS 提供内网路由功能并能访问内网私有服务,执行以下命令。
**额外说明:**
- 请根据内网网段,调整 TS 内网路由参数 `advertise-routes`
```bash
## TS 内网路由模式
$ sudo tailscale up --advertise-exit-node --accept-routes --advertise-routes=172.16.1.0/24 --reset
```
执行命令后,TS 将自动显示登录链接,只需根据链接进行登录操作即可。
目前 TS 将跟随系统自动更新,若需额外开启 TS 的自动更新功能,执行以下命令。
```bash
## TS 开启自动更新
$ sudo tailscale set --auto-update
## TS 关闭自动更新
$ sudo tailscale set --auto-update=false
```
至此,TS 服务器已配置完成。
@@ -6,7 +6,7 @@
点击顶部 `添加` 按钮,添加一个 `备份作业` 点击顶部 `添加` 按钮,添加一个 `备份作业`
![添加备份作业](img/p07/vm_new_backup_job.jpeg) ![添加备份作业](img/p08/vm_new_backup_job.jpeg)
### 1.1.常规选项 ### 1.1.常规选项
@@ -18,17 +18,17 @@
|存储|`local`|选择存放备份文件的路径| |存储|`local`|选择存放备份文件的路径|
|计划|`*-01,16 03:30`|`备份作业` 执行的时间计划| |计划|`*-01,16 03:30`|`备份作业` 执行的时间计划|
|选择模式|`包括选中的VMs`|执行备份的虚拟机对象| |选择模式|`包括选中的VMs`|执行备份的虚拟机对象|
|通知模式|`默认(自动)`|执行备份时的通知模式,保持默认即可|
|发送邮箱至|`your_email@domain.com`|`备份作业` 邮件的收件人邮箱| |发送邮箱至|`your_email@domain.com`|`备份作业` 邮件的收件人邮箱|
|电子邮件|`始终通知`|何时发送 `备份作业` 邮件提醒| |发送邮件|`总是`|发送 `备份作业` 邮件提醒的条件|
|压缩|`ZSTD`|选择备份文件的压缩算法| |压缩|`ZSTD`|选择备份文件的压缩算法|
|模式|`停止`|选择备份虚拟机的方式,推荐使用 `停止` | |模式|`停止`|选择备份虚拟机的方式,推荐使用 `停止` |
|启用|**勾选**|表示该 `备份作业` 为启用状态| |启用|**勾选**|表示该 `备份作业` 为启用状态|
|作业评论|`Backup Your Server :)`|`备份作业` 的备注信息,使用英文输入| |作业评论|`Backup Your Server :)`|`备份作业` 的备注信息,使用英文输入|
|重复错过|**勾选**|表示当意外错过备份执行时间后,将重试备份|
**额外说明:** **额外说明:**
1. 计划中的 `*-01,16 03:30` 表示每个月的 1、16 日凌晨 03:30行备份。 1. 计划中的 `*-01,16 03:30` 表示每`1``16` 号的 `03:30`行备份任务
2. `备份作业` 在正确配置收件人邮箱之前,并不能发出邮件。 2. `备份作业` 在正确配置收件人邮箱之前,并不能发出邮件。
@@ -36,15 +36,15 @@
4. 虚拟机列表中,勾选 `备份作业` 需要备份的虚拟机(可多选)。 4. 虚拟机列表中,勾选 `备份作业` 需要备份的虚拟机(可多选)。
![备份作业常规选项](img/p07/vm_job_normal.jpeg) ![备份作业常规选项](img/p08/vm_job_normal.jpeg)
### 1.2.保留选项 ### 1.2.保留选项
该选项将控制备份文件的保留个数,选择保留最近 `3` 份备份文件。 该选项将控制备份文件的保留个数,选择保留最近 `3` 份备份文件。
![备份作业保留选项](img/p07/vm_job_keep.jpeg) ![备份作业保留选项](img/p08/vm_job_keep.jpeg)
### 1.3.日志模板 ### 1.3.备注模板
该选项将按照设置的内容,自动重命名备份文件。 该选项将按照设置的内容,自动重命名备份文件。
@@ -52,7 +52,13 @@
点击 `创建` 按钮,`备份作业` 创建完成。 点击 `创建` 按钮,`备份作业` 创建完成。
![备份作业备注选项](img/p07/vm_job_notes.jpeg) ![备份作业备注选项](img/p08/vm_job_notes.jpeg)
### 1.4.高级选项
该选项提供 `备份作业` 进行时的高级可调参数,仅需勾选 `重复错过` 选项即可。
![备份作业高级选项](img/p08/vm_job_advanced.jpeg)
## 2.调度模拟器 ## 2.调度模拟器
@@ -60,13 +66,13 @@
鼠标 **单击** 选中一个 `备份作业` ,点击右上角的 `调度模拟器` 鼠标 **单击** 选中一个 `备份作业` ,点击右上角的 `调度模拟器`
![备份作业调度模拟器](img/p07/vm_job_time_test.jpeg) ![备份作业调度模拟器](img/p08/vm_job_time_test.jpeg)
`计划` 处将显示 `备份作业` 的执行时间参数,点击 `模拟` 按钮,在右侧将显示模拟的时间结果。 `计划` 处将显示 `备份作业` 的执行时间参数,点击 `模拟` 按钮,在右侧将显示模拟的时间结果。
确认 `备份作业` 的执行时间周期是否符合预期。 确认 `备份作业` 的执行时间周期是否符合预期。
![备份作业时间模拟](img/p07/vm_job_time.jpeg) ![备份作业时间模拟](img/p08/vm_job_time.jpeg)
至此,虚拟机的自动备份已配置完成。 至此,虚拟机的自动备份已配置完成。
+6 -6
View File
@@ -3,7 +3,7 @@
## 介绍 ## 介绍
PVE 虚拟化平台的安装以及折腾手记。 PVE 虚拟化平台的安装以及折腾手记。
- PVE ISO 版本:8.0-2 (更新时间: 2023-06-22) - PVE ISO 版本:8.2-1 (更新时间: 2024-04-24)
- 演示机: - 演示机:
- CPU:英特尔奔腾 Silver N6005 处理器 - CPU:英特尔奔腾 Silver N6005 处理器
@@ -18,9 +18,8 @@ PVE 虚拟化平台的安装以及折腾手记。
- 网关:`172.16.1.1` - 网关:`172.16.1.1`
- DNS`172.16.1.1` - DNS`172.16.1.1`
- IPv6 网络 - IPv6 网络
- 前缀:`fdac::/64` - 首选 `SLAAC` 自动配置
- IP 地址:`fdac::fe` - IPv6 ULA 网络使用 `fdac::/64` 作为演示
- DNS`fdac::1`
### 系列章节 ### 系列章节
@@ -30,8 +29,9 @@ PVE 虚拟化平台的安装以及折腾手记。
3. [PVE 系统调整](./03.PVE系统调整.md) 3. [PVE 系统调整](./03.PVE系统调整.md)
4. [PVE 创建模板虚拟机](./04.PVE创建模板虚拟机.md) 4. [PVE 创建模板虚拟机](./04.PVE创建模板虚拟机.md)
5. [PVE 制作虚拟机模板](./05.PVE制作虚拟机模板.md) 5. [PVE 制作虚拟机模板](./05.PVE制作虚拟机模板.md)
6. [PVE 用模板克隆虚拟机](./06.PVE用模板克隆虚拟机.md) 6. [PVE 制作 DNS 服务器](./06.PVE制作DNS服务器.md)
7. [PVE 自动备份虚拟机](./07.PVE自动备份虚拟机.md) 7. [PVE 制作 TS 服务器](./07.PVE制作TS服务器.md)
8. [PVE 自动备份虚拟机](./08.PVE自动备份虚拟机.md)
### 文章说明 ### 文章说明
Binary file not shown.

Before

Width:  |  Height:  |  Size: 205 KiB

After

Width:  |  Height:  |  Size: 209 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 272 KiB

After

Width:  |  Height:  |  Size: 280 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 283 KiB

After

Width:  |  Height:  |  Size: 300 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 339 KiB

After

Width:  |  Height:  |  Size: 147 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 43 KiB

After

Width:  |  Height:  |  Size: 23 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 279 KiB

After

Width:  |  Height:  |  Size: 292 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 269 KiB

After

Width:  |  Height:  |  Size: 265 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 247 KiB

After

Width:  |  Height:  |  Size: 98 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 216 KiB

After

Width:  |  Height:  |  Size: 186 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 274 KiB

After

Width:  |  Height:  |  Size: 294 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 131 KiB

After

Width:  |  Height:  |  Size: 217 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 204 KiB

After

Width:  |  Height:  |  Size: 111 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 169 KiB

After

Width:  |  Height:  |  Size: 271 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 599 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 160 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 263 KiB

After

Width:  |  Height:  |  Size: 106 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 413 KiB

After

Width:  |  Height:  |  Size: 401 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 239 KiB

After

Width:  |  Height:  |  Size: 133 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 221 KiB

After

Width:  |  Height:  |  Size: 122 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 199 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 74 KiB

After

Width:  |  Height:  |  Size: 73 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 579 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 322 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 117 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 84 KiB

After

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

After

Width:  |  Height:  |  Size: 78 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 72 KiB

After

Width:  |  Height:  |  Size: 73 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 101 KiB

After

Width:  |  Height:  |  Size: 99 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 108 KiB

After

Width:  |  Height:  |  Size: 107 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 128 KiB

After

Width:  |  Height:  |  Size: 78 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 132 KiB

After

Width:  |  Height:  |  Size: 88 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 173 KiB

After

Width:  |  Height:  |  Size: 124 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 120 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 72 KiB

After

Width:  |  Height:  |  Size: 47 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 136 KiB

After

Width:  |  Height:  |  Size: 80 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 71 KiB

After

Width:  |  Height:  |  Size: 45 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 78 KiB

After

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

After

Width:  |  Height:  |  Size: 71 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 89 KiB

After

Width:  |  Height:  |  Size: 61 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 77 KiB

After

Width:  |  Height:  |  Size: 49 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 98 KiB

After

Width:  |  Height:  |  Size: 66 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 187 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 92 KiB

After

Width:  |  Height:  |  Size: 56 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 127 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 75 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 84 KiB

After

Width:  |  Height:  |  Size: 55 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 97 KiB

After

Width:  |  Height:  |  Size: 65 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 107 KiB

After

Width:  |  Height:  |  Size: 70 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 66 KiB

After

Width:  |  Height:  |  Size: 55 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 79 KiB

After

Width:  |  Height:  |  Size: 41 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 86 KiB

After

Width:  |  Height:  |  Size: 86 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 88 KiB

After

Width:  |  Height:  |  Size: 88 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 48 KiB

After

Width:  |  Height:  |  Size: 33 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 52 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 136 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 65 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 99 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 92 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 384 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 127 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 300 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 151 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 220 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 201 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 171 KiB

@@ -173,5 +173,5 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:30"; Unattended-Upgrade::Automatic-Reboot-Time "03:00";
@@ -1,5 +1,5 @@
# This configuration file is customized by fox # This configuration file is customized by fox,
# Optimize system parameters # Optimize sysctl parameters for local DNS server.
kernel.panic = 20 kernel.panic = 20
kernel.panic_on_oops = 1 kernel.panic_on_oops = 1
@@ -9,15 +9,16 @@ net.ipv4.tcp_congestion_control = bbr
# Other adjustable system parameters # Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.ipv4.conf.all.log_martians = 1 net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 100 net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_challenge_ack_limit = 1000 net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30 net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120 net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_max_orphans = 4096
net.ipv4.tcp_max_tw_buckets = 4096
net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.use_tempaddr = 0 net.ipv6.conf.all.use_tempaddr = 0
+47
View File
@@ -0,0 +1,47 @@
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local DNS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=10800
fast-dns-retry=1800
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-resolv
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/lan/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/fox.home.arpa/172.16.1.1
server=127.0.0.1#6053
server=::1#6053
+18
View File
@@ -0,0 +1,18 @@
## 下载加速规则安装脚本
$ sudo curl -LR -o /opt/dnsmasq_plugin.sh https://gitee.com/felixonmars/dnsmasq-china-list/raw/master/install.sh
## 设置脚本可执行权限
$ sudo chmod +x /opt/dnsmasq_plugin.sh
## 设置脚本文件防篡改
$ sudo chattr +i /opt/dnsmasq_plugin.sh
## 执行脚本
$ sudo bash /opt/dnsmasq_plugin.sh
## 设置 crontab
25 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/dnsmasq.d/anti-ad.dnsmasq.conf https://anti-ad.net/anti-ad-for-dnsmasq.conf
35 9 * * * /usr/bin/bash /opt/dnsmasq_plugin.sh
+52
View File
@@ -0,0 +1,52 @@
# This configuration file is customized by fox,
# Optimize SmartDNS parameters for local DNS server.
#
# For use common DNS server as upstream DNS server,
# please modify 'server' parameter according to
# your network environment.
#
# eg:
# server 119.29.29.29
# server 223.5.5.5
# server 114.114.114.114
# server 2402:4e00::
# server 2400:3200::1
conf-file /etc/smartdns.d/*.conf
cache-file /tmp/smartdns.cache
log-level notice
bind [::]:6053@lo
bind-tcp [::]:6053@lo
serve-expired yes
serve-expired-ttl 129600
serve-expired-reply-ttl 30
prefetch-domain yes
serve-expired-prefetch-time 21600
force-qtype-SOA 65
max-query-limit 1024
edns-client-subnet 202.103.24.68
server-tcp 119.29.29.29 -group dnspod -exclude-default-group
server-tcp 2402:4e00:: -group dnspod -exclude-default-group
nameserver /doh.pub/dnspod
nameserver /dot.pub/dnspod
server-tcp 223.5.5.5 -group alidns -exclude-default-group
server-tcp 2400:3200::1 -group alidns -exclude-default-group
nameserver /dns.alidns.com/alidns
server 172.16.1.1 -group intranet -exclude-default-group
nameserver /fox.home.arpa/intranet
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
server-tls dot.pub
server-tls dns.alidns.com
server-https https://doh.pub/dns-query
server-https https://dns.alidns.com/dns-query
+14
View File
@@ -0,0 +1,14 @@
# This configuration file is customized by fox,
# Optimize SmartDNS crontab for local DNS server.
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/anti-ad.smartdns.conf https://anti-ad.net/anti-ad-for-smartdns.conf
30 9 * * * /usr/bin/systemctl restart smartdns.service
## Or when the smartdns plugin is installed
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/anti-ad.smartdns.conf https://anti-ad.net/anti-ad-for-smartdns.conf
30 9 * * * /usr/bin/bash /opt/smartdns-plugin.sh
@@ -0,0 +1,72 @@
#!/bin/bash
set -e
WORKDIR="$(mktemp -d)"
CONFDIR="/etc/smartdns.d"
SERVERS=(223.5.5.5 180.184.1.1 119.29.29.29 114.114.114.114)
GROUP=(flash)
# Others: 223.6.6.6 119.28.28.28
# Not using best possible CDN pop: 1.2.4.8 210.2.4.8
# Broken?: 180.76.76.76
CONF_WITH_SERVERS=(accelerated-domains.china google.china apple.china)
CONF_WITH_GROUP=(dns-group.china)
CONF_SIMPLE=(bogus-nxdomain.china)
echo "Checking whether the configuration folder exists..."
if [ ! -d "$CONFDIR" ]; then
mkdir -p "$CONFDIR"
fi
echo "Downloading latest configurations..."
git clone --depth=1 https://gitee.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://pagure.io/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://github.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://bitbucket.org/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://gitlab.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://e.coding.net/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://codehub.devcloud.huaweicloud.com/dnsmasq-china-list00001/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 http://repo.or.cz/dnsmasq-china-list.git "$WORKDIR"
echo "Removing old configurations..."
for _conf in "${CONF_WITH_SERVERS[@]}" "${CONF_WITH_GROUP[@]}" "${CONF_SIMPLE[@]}"; do
rm -f "$CONFDIR/$_conf"*.conf
done
echo "Installing new configurations..."
for _conf in "${CONF_WITH_SERVERS[@]}" "${CONF_WITH_GROUP[@]}" "${CONF_SIMPLE[@]}"; do
if [[ "${CONF_WITH_SERVERS[@]}" =~ $_conf ]]; then
sed -En 's|^server=/([^/]*)/114.114.114.114$|\1|p' "$WORKDIR/$_conf.conf" | grep -Ev '^#' > "$WORKDIR/$_conf.step1.raw"
sed -En "s/(.*)/nameserver \\/\\1\\/${GROUP[@]}/p" "$WORKDIR/$_conf.step1.raw" > "$WORKDIR/$_conf.step2.raw"
cp "$WORKDIR/$_conf.step2.raw" "$CONFDIR/$_conf.smartdns.conf"
fi
if [[ "${CONF_WITH_GROUP[@]}" =~ $_conf ]]; then
for _server in "${SERVERS[@]}"; do
echo "server $_server -group ${GROUP[@]} -exclude-default-group" >> "$WORKDIR/$_conf.raw"
done
cp "$WORKDIR/$_conf.raw" "$CONFDIR/$_conf.smartdns.conf"
fi
if [[ "${CONF_SIMPLE[@]}" =~ $_conf ]]; then
sed -e "s|=| |" "$WORKDIR/$_conf.conf" > "$WORKDIR/$_conf.raw"
cp "$WORKDIR/$_conf.raw" "$CONFDIR/$_conf.smartdns.conf"
fi
done
echo "Restarting smartdns service..."
if hash systemctl 2>/dev/null; then
systemctl restart smartdns
elif hash service 2>/dev/null; then
service smartdns restart
elif hash rc-service 2>/dev/null; then
rc-service smartdns restart
elif hash busybox 2>/dev/null && [[ -d "/etc/init.d" ]]; then
/etc/init.d/smartdns restart
else
echo "Now please restart smartdns since I don't know how to do it."
fi
echo "Cleaning up..."
rm -r "$WORKDIR"
@@ -1,10 +1,12 @@
Types: deb Types: deb
URIs: https://mirrors.ustc.edu.cn/debian URIs: https://mirrors.ustc.edu.cn/debian
Suites: bookworm bookworm-updates bookworm-backports Suites: bookworm bookworm-updates
Components: main contrib non-free non-free-firmware Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb Types: deb
URIs: https://mirrors.ustc.edu.cn/debian-security URIs: https://mirrors.ustc.edu.cn/debian-security
Suites: bookworm-security Suites: bookworm-security
Components: main contrib non-free non-free-firmware Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
@@ -0,0 +1,5 @@
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "7";
APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1";
@@ -0,0 +1,178 @@
// Unattended-Upgrade::Origins-Pattern controls which packages are
// upgraded.
//
// Lines below have the format "keyword=value,...". A
// package will be upgraded only if the values in its metadata match
// all the supplied keywords in a line. (In other words, omitted
// keywords are wild cards.) The keywords originate from the Release
// file, but several aliases are accepted. The accepted keywords are:
// a,archive,suite (eg, "stable")
// c,component (eg, "main", "contrib", "non-free")
// l,label (eg, "Debian", "Debian-Security")
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
// n,codename (eg, "jessie", "jessie-updates")
// site (eg, "http.debian.net")
// The available values on the system are printed by the command
// "apt-cache policy", and can be debugged by running
// "unattended-upgrades -d" and looking at the log file.
//
// Within lines unattended-upgrades allows 2 macros whose values are
// derived from /etc/debian_version:
// ${distro_id} Installed origin.
// ${distro_codename} Installed codename (eg, "buster")
Unattended-Upgrade::Origins-Pattern {
// Codename based matching:
// This will follow the migration of a release through different
// archives (e.g. from testing to stable and later oldstable).
// Software will be the latest available for the named release,
// but the Debian release itself will not be automatically upgraded.
"origin=Debian,codename=${distro_codename}-updates";
// "origin=Debian,codename=${distro_codename}-proposed-updates";
"origin=Debian,codename=${distro_codename},label=Debian";
"origin=Debian,codename=${distro_codename},label=Debian-Security";
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
"origin=Tailscale,codename=${distro_codename},label=Tailscale";
// Archive or Suite based matching:
// Note that this will silently match a different release after
// migration to the specified archive (e.g. testing becomes the
// new stable).
// "o=Debian,a=stable";
// "o=Debian,a=stable-updates";
// "o=Debian,a=proposed-updates";
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
};
// Python regular expressions, matching packages to exclude from upgrading
Unattended-Upgrade::Package-Blacklist {
// The following matches all packages starting with linux-
// "linux-";
// Use $ to explicitely define the end of a package name. Without
// the $, "libc6" would match all of them.
// "libc6$";
// "libc6-dev$";
// "libc6-i686$";
// Special characters need escaping
// "libstdc\+\+6$";
// The following matches packages like xen-system-amd64, xen-utils-4.1,
// xenstore-utils and libxenstore3.0
// "(lib)?xen(store)?";
// For more information about Python regular expressions, see
// https://docs.python.org/3/howto/regex.html
};
// This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run
// dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
// Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGTERM. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true";
// Install all updates when the machine is shutting down
// instead of doing it in the background while the machine is running.
// This will (obviously) make shutdown slower.
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
// This allows more time for unattended-upgrades to shut down gracefully
// or even install a few packages in InstallOnShutdown mode, but is still a
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
// Users enabling InstallOnShutdown mode are advised to increase
// InhibitDelayMaxSec even further, possibly to 30 minutes.
//Unattended-Upgrade::InstallOnShutdown "false";
// Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail "";
// Set this value to one of:
// "always", "only-on-error" or "on-change"
// If this is not set, then any legacy MailOnlyOnError (boolean) value
// is used to chose between "only-on-error" and "on-change"
//Unattended-Upgrade::MailReport "on-change";
// Remove unused automatically installed kernel-related packages
// (kernel images, kernel headers and kernel version locked tools).
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Do automatic removal of newly unused dependencies after the upgrade
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
// Do automatic removal of unused packages after the upgrade
// (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
// Automatically reboot *WITHOUT CONFIRMATION* if
// the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false";
// Automatically reboot even if there are users currently logged in
// when Unattended-Upgrade::Automatic-Reboot is set to true
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
// If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately
// Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
// Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec
//Acquire::http::Dl-Limit "70";
// Enable logging to syslog. Default is False
// Unattended-Upgrade::SyslogEnable "false";
// Specify syslog facility. Default is daemon
// Unattended-Upgrade::SyslogFacility "daemon";
// Download and install upgrades only on AC power
// (i.e. skip or gracefully stop updates on battery)
// Unattended-Upgrade::OnlyOnACPower "true";
// Download and install upgrades only on non-metered connection
// (i.e. skip or gracefully stop updates on a metered connection)
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
// Verbose logging
// Unattended-Upgrade::Verbose "false";
// Print debugging information both in unattended-upgrades and
// in unattended-upgrade-shutdown
// Unattended-Upgrade::Debug "false";
// Allow package downgrade if Pin-Priority exceeds 1000
// Unattended-Upgrade::Allow-downgrade "false";
// When APT fails to mark a package to be upgraded or installed try adjusting
// candidates of related packages to help APT's resolver in finding a solution
// where the package can be upgraded or installed.
// This is a workaround until APT's resolver is fixed to always find a
// solution if it exists. (See Debian bug #711128.)
// The fallback is enabled by default, except on Debian's sid release because
// uninstallable packages are frequent there.
// Disabling the fallback speeds up unattended-upgrades when there are
// uninstallable packages at the expense of rarely keeping back packages which
// could be upgraded or installed.
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
+64
View File
@@ -0,0 +1,64 @@
# This configuration file is customized by fox,
# Optimize sysctl parameters for local TS server.
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = cake
net.ipv4.tcp_congestion_control = bbr
net.ipv4.ip_forward = 1
net.ipv6.conf.all.forwarding = 1
net.ipv6.conf.default.forwarding = 1
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.all.arp_ignore = 1
net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 256
net.ipv4.route.error_burst = 500
net.ipv4.route.error_cost = 100
net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
net.ipv6.conf.all.accept_source_route = 0
net.ipv6.conf.default.accept_source_route = 0
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
net.netfilter.nf_conntrack_acct = 1
net.netfilter.nf_conntrack_checksum = 0
net.netfilter.nf_conntrack_tcp_timeout_established = 7440
+47
View File
@@ -0,0 +1,47 @@
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local TS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=2048
max-cache-ttl=10800
fast-dns-retry=1800
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
local-service
no-hosts
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/lan/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1
server=172.16.1.1
+177
View File
@@ -0,0 +1,177 @@
#!/usr/sbin/nft -f
# This configuration file is customized by fox,
# Optimize nftables rules for local TS server.
table inet router
flush table inet router
table inet router {
#
# Flowtable
#
flowtable ft {
hook ingress priority filter;
devices = { eth0 };
counter;
}
#
# Filter rules
#
chain input {
type filter hook input priority filter; policy drop;
iif "lo" accept comment "defconf: accept traffic from loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle inbound flows"
tcp flags syn / fin,syn,rst,ack counter jump syn_flood comment "defconf: rate limit TCP-SYN packets"
iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic"
iifname "tailscale0" counter jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related flow add @ft comment "defconf: track forwarded flows"
ct state vmap { established : accept, related : accept } comment "defconf: handle forwarded flows"
iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic"
iifname "tailscale0" counter jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic"
}
chain output {
type filter hook output priority filter; policy accept;
oif "lo" accept comment "defconf: accept traffic towards loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle outbound flows"
oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic"
oifname "tailscale0" counter jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic"
}
chain prerouting {
type filter hook prerouting priority filter; policy accept;
iifname "eth0" jump helper_lan comment "defconf: handle LAN IPv4 / IPv6 helper assignment"
iifname "tailscale0" jump helper_tailscale comment "tsconf: handle TS IPv4 / IPv6 helper assignment"
}
chain syn_flood {
limit rate 200/second burst 100 packets return comment "defconf: accept SYN packets below rate-limit"
counter drop comment "defconf: drop excess packets"
}
chain input_lan {
ct status dnat counter accept comment "lanconf: accept port redirect"
jump accept_from_lan
}
chain forward_lan {
jump accept_to_tailscale comment "tsconf: accept LAN to TS forward"
ct status dnat counter accept comment "lanconf: accept port forward"
jump accept_to_lan
}
chain output_lan {
jump accept_to_lan
}
chain helper_lan {
}
chain accept_from_lan {
iifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
}
chain accept_to_lan {
meta nfproto ipv4 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv4 leakage"
meta nfproto ipv6 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv6 leakage"
oifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
}
chain input_tailscale {
jump accept_from_tailscale
}
chain forward_tailscale {
counter jump accept_to_lan comment "tsconf: accept TS to LAN forward"
counter jump accept_to_tailscale
}
chain output_tailscale {
counter jump accept_to_tailscale
}
chain helper_tailscale {
}
chain accept_from_tailscale {
iifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
}
chain accept_to_tailscale {
oifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
}
#
# NAT rules
#
chain dstnat {
type nat hook prerouting priority dstnat; policy accept;
iifname "eth0" meta l4proto { tcp, udp } th dport domain jump dstnat_lan comment "defconf: handle LAN IPv4 / IPv6 dstnat traffic"
}
chain srcnat {
type nat hook postrouting priority srcnat; policy accept;
oifname "eth0" jump srcnat_lan comment "defconf: handle LAN IPv4 / IPv6 srcnat traffic"
}
chain dstnat_lan {
meta nfproto ipv4 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv4 DNS redirect"
meta nfproto ipv6 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv6 DNS redirect"
}
chain srcnat_lan {
meta nfproto ipv4 counter masquerade comment "defconf: masquerade IPv4 LAN traffic"
meta nfproto ipv6 counter masquerade comment "defconf: masquerade IPv6 LAN traffic"
}
#
# Raw rules (notrack)
#
chain raw_prerouting {
type filter hook prerouting priority raw; policy accept;
}
chain raw_output {
type filter hook output priority raw; policy accept;
}
#
# Mangle rules
#
chain mangle_prerouting {
type filter hook prerouting priority mangle; policy accept;
}
chain mangle_postrouting {
type filter hook postrouting priority mangle; policy accept;
}
chain mangle_input {
type filter hook input priority mangle; policy accept;
}
chain mangle_output {
type route hook output priority mangle; policy accept;
}
chain mangle_forward {
type filter hook forward priority mangle; policy accept;
}
}
+5
View File
@@ -0,0 +1,5 @@
# This configuration file is customized by fox,
# Optimize netfilter related modules at system boot.
nf_conntrack
-49
View File
@@ -1,49 +0,0 @@
# This configuration file is customized by fox,
# Optimize SmartDNS parameters for local DNS server.
conf-file /etc/smartdns/anti-ad-smartdns.conf
bind [::]:53
bind-tcp [::]:53
serve-expired yes
serve-expired-ttl 86400
serve-expired-reply-ttl 3
prefetch-domain yes
serve-expired-prefetch-time 43200
speed-check-mode ping,tcp:80,tcp:443
force-qtype-SOA 65
log-level warn
server 119.29.29.29 -group dnspod
server 2402:4e00:: -group dnspod
server 223.5.5.5 -group alidns
server 2400:3200::1 -group alidns
nameserver /doh.pub/dnspod
nameserver /dot.pub/dnspod
nameserver /dns.alidns.com/alidns
server 172.16.1.1 -group fox
server fdac::1 -group fox
nameserver /fox.local/fox
domain-rules /fox.local/ -no-cache -speed-check-mode none
server-tcp 119.29.29.29
server-tcp 223.5.5.5
server-tcp 114.114.114.114
server-tcp 2402:4e00::
server-tcp 2400:3200::1
server-tcp 2400:3200:baba::1
server-tls 1.12.12.12 -spki-pin 5TIMjgyMhA0qmPdK+AM9LX6vNI/9EPBydh/ZXdfcYmI= -host-name dot.pub
server-tls 120.53.53.53 -spki-pin 5TIMjgyMhA0qmPdK+AM9LX6vNI/9EPBydh/ZXdfcYmI= -host-name dot.pub
server-tls 223.5.5.5 -spki-pin ZwR21gnCMTzsM6VWtnb/azufgYegWWuhE9reP5tamWU= -host-name dns.alidns.com
server-tls 223.6.6.6 -spki-pin ZwR21gnCMTzsM6VWtnb/azufgYegWWuhE9reP5tamWU= -host-name dns.alidns.com
server-https https://doh.pub/dns-query
server-https https://dns.alidns.com/dns-query
@@ -175,5 +175,5 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "05:00"; Unattended-Upgrade::Automatic-Reboot-Time "02:30";
@@ -3,7 +3,7 @@
[Timer] [Timer]
OnCalendar= OnCalendar=
OnCalendar=02:00 OnCalendar=01:30
RandomizedDelaySec=0 RandomizedDelaySec=0
### Lines below this comment will be discarded ### Lines below this comment will be discarded
+6
View File
@@ -0,0 +1,6 @@
# This configuration file is customized by fox,
# Optimize system CPU governors.
CPUPOWER_START_OPTS="frequency-set -g powersave"
CPUPOWER_STOP_OPTS="frequency-set -g performance"
+18
View File
@@ -0,0 +1,18 @@
# This configuration file is customized by fox,
# Optimize for cpupower systemd service.
[Unit]
Description=Apply cpupower configuration
ConditionVirtualization=!container
After=syslog.target
[Service]
Type=oneshot
EnvironmentFile=/etc/default/cpupower
ExecStart=/usr/bin/cpupower $CPUPOWER_START_OPTS
ExecStop=/usr/bin/cpupower $CPUPOWER_STOP_OPTS
RemainAfterExit=yes
[Install]
WantedBy=multi-user.target