Compare commits

..
151 Commits
Author SHA1 Message Date
CallMeR ee7b34ddf4 更新 SmartDNS 配置 2024-02-20 02:08:33 +08:00
CallMeR 353dc12fca 更新文案描述 2024-02-14 01:54:23 +08:00
CallMeR a410d925f4 更新清理命令 2024-02-13 22:35:06 +08:00
CallMeR 2c48e3a330 优化 ls 命令 2024-02-11 02:11:06 +08:00
CallMeR 2344cd77bf 更新 SmartDNS 参数 2024-02-11 01:55:18 +08:00
CallMeR aba1e70956 更新 SmartDNS 参数 2024-02-11 01:39:02 +08:00
CallMeR bbcbc9fe1e 更新 Dnsmasq 参数 2024-02-09 00:36:35 +08:00
CallMeR 5bce9e1d44 SmartDNS 配置重命名 2024-02-09 00:29:47 +08:00
CallMeR 80f7041632 更新 SmartDNS 参数 2024-02-09 00:27:03 +08:00
CallMeR ffcae17092 更新 SmartDNS 版本 2024-02-09 00:04:29 +08:00
CallMeR 0bd3a7cd36 整合清理命令 2024-01-30 18:17:58 +08:00
CallMeR eddc39bc40 修复 typo 2024-01-30 18:14:52 +08:00
CallMeR 564d56e56f 更新流表语法 2024-01-20 21:52:47 +08:00
CallMeR 80556cacaf 更新流表语法 2024-01-20 19:27:06 +08:00
CallMeR 2c8d775e9e 更新 README 2024-01-17 14:02:25 +08:00
CallMeR 19532baa21 更新 README 2024-01-17 13:59:58 +08:00
CallMeR 2ff27e96c3 默认不启用 IPv6 ULA 网络 2024-01-17 13:54:39 +08:00
CallMeR 979f03052e 修复 typo 2024-01-17 13:22:45 +08:00
CallMeR 3a7a506645 更新文案描述 2024-01-10 16:16:56 +08:00
CallMeR 62c55d9750 调整 Dnsmasq 配置 2024-01-10 15:13:49 +08:00
CallMeR 101b5c64b2 整理文档 2024-01-10 15:05:59 +08:00
CallMeR 497a8c0685 更新 Dnsmasq 配置 2024-01-10 14:46:26 +08:00
CallMeR 00e4fd27e5 调整 Dnsmasq 配置 2024-01-10 14:29:51 +08:00
CallMeR 85d5a3bee5 更新文案描述 2024-01-08 22:31:32 +08:00
CallMeR 2ae4bda8b3 调整 Dnsmasq 格式 2024-01-08 21:55:32 +08:00
CallMeR 12cadb86ad 更新说明 2024-01-08 21:46:38 +08:00
CallMeR 3c9927a362 关闭 TS 服务器 Dnsmasq 的 DNS 缓存 2024-01-08 21:40:23 +08:00
CallMeR d69101077b 更新 offload 匹配 2024-01-07 12:03:45 +08:00
CallMeR 6497efb00a 同步上游更新 2024-01-06 14:59:35 +08:00
CallMeR 79703f9d62 修改 systemd 服务路径 2024-01-05 21:46:56 +08:00
CallMeR 53994238c8 更新文案描述 2024-01-05 21:34:30 +08:00
CallMeR ddcdc18564 修复 Typo 2024-01-01 17:33:04 +08:00
CallMeR f505690ed6 更新文档 2024-01-01 16:29:11 +08:00
CallMeR 96cb5ddcdc 更新文档 2024-01-01 16:19:33 +08:00
CallMeR 2858ba97c4 更新文档 2024-01-01 14:07:06 +08:00
CallMeR 833817d85c 更新文档 2024-01-01 13:54:16 +08:00
CallMeR 7097fb5d73 更新文档 2024-01-01 13:49:38 +08:00
CallMeR 52f3be600b 更新文档 2024-01-01 13:36:04 +08:00
CallMeR 0a9a2ee8fe 更新文档 2024-01-01 13:13:36 +08:00
CallMeR ed3c106e27 更新文档 2024-01-01 13:10:07 +08:00
CallMeR c94d7d31fc 更新文档 2024-01-01 13:00:00 +08:00
CallMeR abf168587d 更新文档 2024-01-01 12:49:36 +08:00
CallMeR 3e9a8eae07 更新文档 2024-01-01 12:02:06 +08:00
CallMeR 090ab28970 整理文档 2023-12-31 22:07:01 +08:00
CallMeR 59ebf178c7 整理文档 2023-12-31 21:09:03 +08:00
CallMeR 249717ed89 更新 TS 测试配置 2023-12-30 22:16:07 +08:00
CallMeR 2520ce4839 更新 nf_conntrack 参数 2023-12-24 01:50:16 +08:00
CallMeR 5d5750f120 更新定时参数 2023-12-21 22:09:33 +08:00
CallMeR f90dd7a7c8 更新 resolv.conf 配置 2023-12-16 23:52:08 +08:00
CallMeR 730773e42b 更新 resolv 配置方法 2023-12-16 16:40:20 +08:00
CallMeR c00e178df3 新增 OVS 工具 2023-12-15 02:25:23 +08:00
CallMeR f8c7676c85 精简非相关配置 2023-12-14 11:32:51 +08:00
CallMeR 29592abb40 更换 SmartDNS 广告规则 2023-12-14 11:30:39 +08:00
CallMeR 62b2641413 更新命令备注 2023-12-14 00:29:13 +08:00
CallMeR 04023ac155 优化文案描述 2023-12-14 00:22:21 +08:00
CallMeR 4dcb3ff7a9 优化文案描述 2023-12-13 23:30:01 +08:00
CallMeR ca30a2f9e9 优化文案描述 2023-12-13 23:14:33 +08:00
CallMeR 88ea495d5a 优化文案描述 2023-12-13 23:12:03 +08:00
CallMeR d08a3acf74 优化文案描述 2023-12-13 20:59:27 +08:00
CallMeR d26f303437 优化文案描述 2023-12-13 20:51:04 +08:00
CallMeR ed0db21a9f 优化文案描述 2023-12-13 20:19:45 +08:00
CallMeR 18e02bc9c8 优化文案描述 2023-12-13 19:59:29 +08:00
CallMeR 6882b01afc 更新文件名 2023-12-13 16:55:19 +08:00
CallMeR fec6ae3e56 更新脚本 2023-12-13 14:45:57 +08:00
CallMeR 660551f2fc 更新 curl 参数 2023-12-12 21:32:02 +08:00
CallMeR 80afa7dfe7 更新 SmartDNS 下载链接 2023-12-12 20:05:34 +08:00
CallMeR 509b344c69 更新 systemd-resolved 配置 2023-12-11 13:22:00 +08:00
CallMeR 3b3a3361fa 更新 curl 参数 2023-12-11 09:47:01 +08:00
CallMeR fba7575503 更新 curl 参数 2023-12-11 02:55:16 +08:00
CallMeR 4d77f0415e 更新 curl 参数 2023-12-11 02:27:42 +08:00
CallMeR 8b35afeec5 修复 curl 命令 2023-12-11 01:12:27 +08:00
CallMeR e0c69c3fa5 统一 crontab 时间 2023-12-10 23:32:46 +08:00
CallMeR 410f6e8d2e 替换 wget 命令 2023-12-10 22:55:40 +08:00
CallMeR 56d9125152 替换 wget 命令 2023-12-10 22:47:21 +08:00
CallMeR 779b75f3a8 更新 SmartDNS 定时器 2023-12-10 19:19:46 +08:00
CallMeR b0c7a2d4ce 优化文案描述 2023-12-10 18:39:15 +08:00
CallMeR b84dbe3872 优化文案描述 2023-12-10 18:31:43 +08:00
CallMeR 1555ec02ca 更新 SmartDNS 配置 2023-12-10 18:00:16 +08:00
CallMeR 906db9eac4 更新脚本变量 2023-12-09 21:17:31 +08:00
CallMeR 0d091d93c1 更新脚本变量 2023-12-09 21:10:04 +08:00
CallMeR b347128ec5 更新脚本变量 2023-12-09 20:58:20 +08:00
CallMeR 1e5a55de64 更新说明信息 2023-12-09 15:22:57 +08:00
CallMeR d052923897 更新文件名 2023-12-09 01:32:16 +08:00
CallMeR ba0afba7eb 更新 SmartDNS 插件脚本 2023-12-08 23:49:03 +08:00
CallMeR 6aa24ecb61 更新 SmartDNS 插件脚本 2023-12-08 23:42:25 +08:00
CallMeR 454ae86aba 更新 SmartDNS 配置 2023-12-08 13:03:17 +08:00
CallMeR 24b087aa1e 更新 SmartDNS 默认端口 2023-12-02 12:22:57 +08:00
CallMeR 56317210a6 更新 lsof 参数 2023-12-02 01:11:16 +08:00
CallMeR d8e7753112 更新 TS 测试配置 2023-12-02 00:44:34 +08:00
CallMeR 4700bc1c52 更新截图 2023-12-01 23:47:29 +08:00
CallMeR 29f6296a1c 更新 TS 测试配置 2023-12-01 18:54:38 +08:00
CallMeR 891d8ef2f6 更新 TS 测试配置 2023-12-01 13:47:44 +08:00
CallMeR e4117816c5 更新 TS 测试配置 2023-12-01 13:30:52 +08:00
CallMeR b109b0d840 更新 TS 测试配置 2023-12-01 00:40:19 +08:00
CallMeR 8bc4dd8587 更新 dnsmasq 配置 2023-11-30 23:20:51 +08:00
CallMeR eef810d850 更新截图 2023-11-30 17:41:18 +08:00
CallMeR 752c233013 更新安装截图 2023-11-30 15:29:44 +08:00
CallMeR 8b62f62420 更新模板虚拟机配置 2023-11-30 12:47:45 +08:00
CallMeR 46d0e0ce4a 更新截图 2023-11-30 12:21:27 +08:00
CallMeR f643128cf5 更新截图 2023-11-30 10:48:20 +08:00
CallMeR 165f6ea9dc 更新 TS 防火墙备注 2023-11-29 14:06:15 +08:00
CallMeR 7fc7ab2466 更新 TS 防火墙备注 2023-11-29 14:01:12 +08:00
CallMeR 2407555015 更新 TS 防火墙 2023-11-29 13:48:55 +08:00
CallMeR 5b65602c07 更新 TS 防火墙 2023-11-28 21:59:39 +08:00
CallMeR a2b1278038 更新备注 2023-11-28 21:52:29 +08:00
CallMeR 07d5ea174a 更新 TS 测试配置 2023-11-28 19:01:35 +08:00
CallMeR 554b2bd6d4 整理文件名 2023-11-28 18:35:55 +08:00
CallMeR 145328fb3c 更新 LXC 文案 2023-11-27 18:00:16 +08:00
CallMeR 9691336e5c 更新 LXC 文案 2023-11-27 17:53:56 +08:00
CallMeR f7ce11e99d 更新 LXC 文案 2023-11-27 17:51:16 +08:00
CallMeR eb631a1cdc 更新 LXC 文案 2023-11-27 14:36:30 +08:00
CallMeR 46ce4e4ee3 更新 SmartDNS 配置 2023-11-27 13:24:28 +08:00
CallMeR 0bd03af309 更新文件名 2023-11-27 12:56:34 +08:00
CallMeR 767c31694d 更新文件名 2023-11-27 12:54:07 +08:00
CallMeR b27372c20d 更新虚拟机 DEB822 配置 2023-11-26 20:58:59 +08:00
CallMeR b830088e5e 更新 PVE 版本 2023-11-25 22:24:54 +08:00
CallMeR 9f5884befb 优化 sysctl 配置 2023-11-24 12:07:45 +08:00
CallMeR 8af7ef896b 更新 dnsmasq 配置 2023-11-18 16:37:19 +08:00
CallMeR 09a60d3ae4 Dnsmasq 插件设置 2023-11-13 12:31:57 +08:00
CallMeR 830655bd52 更新定时任务 2023-11-13 12:21:25 +08:00
CallMeR 95023d68d3 回滚 SmartDNS 配置 2023-11-08 11:55:55 +08:00
CallMeR d8e6a50166 更新 dnsmasq 配置 2023-11-08 11:47:01 +08:00
CallMeR e6d805fba5 更新 SmartDNS 配置 2023-11-07 13:47:34 +08:00
CallMeR 9386f961d1 整理文档 2023-10-29 10:28:30 +08:00
CallMeR b84666a6b6 修复备注信息 2023-10-14 23:34:52 +08:00
CallMeR 07526b9ada 修复备注信息 2023-10-14 23:17:07 +08:00
CallMeR e31338113d 修复 cpupower 文案 2023-10-14 22:36:54 +08:00
CallMeR 7eda1b4eef 更新 SmartDNS 缓存参数 2023-10-10 22:10:45 +08:00
CallMeR 3b1a9e4f00 替换 ldnsutils 2023-10-07 01:45:36 +08:00
CallMeR 7288a7ba8b 更新 N6005 CPU 调度器输出 2023-09-15 14:48:52 +08:00
CallMeR 63631e6ad3 优化 CPU 调度器配置 2023-09-13 13:48:05 +08:00
CallMeR 5ed5ac768b 更新系统默认 qdisc 2023-09-10 16:32:42 +08:00
CallMeR ae5b3e1e82 更新本地域名后缀 2023-09-09 19:17:40 +08:00
CallMeR b7857fcd66 更新本地域名后缀 2023-09-09 19:03:26 +08:00
CallMeR 81101cde20 更新本地域名后缀 2023-09-09 18:30:25 +08:00
CallMeR 99e4a94a9f 更新安装截图 2023-09-09 16:45:06 +08:00
CallMeR c4294612eb 更新安装截图 2023-09-09 16:13:54 +08:00
CallMeR 38df9bd3e4 更新本地域名后缀 2023-09-07 22:36:50 +08:00
CallMeR 0019ac0fbc 修复时间参数说明 2023-08-18 14:32:13 +08:00
CallMeR 1b8caefe58 修复时间参数说明 2023-08-18 14:25:41 +08:00
CallMeR 9804c8964e 修复时间参数说明 2023-08-18 14:20:31 +08:00
CallMeR 861e468aa6 修复定时重启时间 2023-08-18 14:15:36 +08:00
CallMeR 90bc8f942b 修复定时重启时间 2023-08-18 14:12:26 +08:00
CallMeR 09f4738295 更新 SmartDNS 版本 2023-08-13 17:05:53 +08:00
CallMeR ea71df8c8c 更新说明信息 2023-08-07 21:35:47 +08:00
CallMeR 1a8c107333 更新 PVE 官网截图 2023-08-07 21:29:53 +08:00
CallMeR c40ba60a6e 更新 PVE 官网截图 2023-08-07 21:26:36 +08:00
CallMeR 9494d82747 更新 PVE 官网截图 2023-08-07 21:22:59 +08:00
CallMeR f89c38f8d8 更新 PVE 官网截图 2023-08-07 21:14:57 +08:00
CallMeR 6a9202a62b 更新示例 2023-08-01 13:39:06 +08:00
CallMeR 8a10db07d1 更新示例 2023-08-01 13:30:56 +08:00
84 changed files with 2213 additions and 723 deletions
+7 -7
View File
@@ -4,17 +4,17 @@ PVE 系统正式安装之前,需要准备 PVE 的安装镜像和一些必要
### 0.1. PVE 镜像下载 ### 0.1. PVE 镜像下载
PVE 下载地址:https://www.proxmox.com/en/downloads PVE 下载地址:[Proxmox Virtual Environment](https://www.proxmox.com/en/downloads/proxmox-virtual-environment/iso)
页面中可能有多个 PVE 的安装 ISO ,可以根据需要进行选择,目前最新的 `Proxmox VE 8.0 ISO` 作为演示。 页面中有多个 PVE 相关文件,本文以目前最新的 `Proxmox VE 8.1-1 ISO Installer` 作为演示。
![下载PVE ISO文件](img/p01/pve_download_iso.jpeg) 点击 `Proxmox VE 8.x ISO Installer` 链接,进入 PVE 下载页面。
点击 `Proxmox VE 8.x ISO Installer` 链接。 ![PVE下载页面](img/p01/pve_download_iso.jpeg)
下载 ISO 时请注意 `SHA256SUM` ,后续将使用该校验信息对下载下来的 ISO 进行校验,以确保 ISO 文件的完整性。 下载 ISO 时请注意 `SHA256SUM` ,后续将使用该校验信息对下载下来的 ISO 进行校验,以确保 ISO 文件的完整性。
![输入图片说明](img/p01/pve_iso_hash.jpeg) ![下载PVE](img/p01/pve_iso_hash.jpeg)
### 0.2.启动盘制作工具 ### 0.2.启动盘制作工具
@@ -156,7 +156,7 @@ PVE 为最关键的虚拟化层,建议使用强密码,包含大小写字母
FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。 FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
演示中 FQDN 为 `node01.fox.local` ,因此 PVE 的主机名为 `node01` 演示中 FQDN 为 `node01.fox.home.arpa` ,因此 PVE 的主机名为 `node01`
根据规划,PVE 的 IPv4 管理地址为 `172.16.1.254` 根据规划,PVE 的 IPv4 管理地址为 `172.16.1.254`
@@ -166,7 +166,7 @@ FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
|参数|值|说明| |参数|值|说明|
|--|--|--| |--|--|--|
|Hostname (FQDN)|`node01.fox.local`|设置 PVE `域``主机名` | |Hostname (FQDN)|`node01.fox.home.arpa`|设置 PVE `域``主机名` |
|IP Address (CIDR)|`172.16.1.254/24`|设置 PVE IPv4 地址| |IP Address (CIDR)|`172.16.1.254/24`|设置 PVE IPv4 地址|
|Gateway|`172.16.1.1`|设置 PVE IPv4 网关| |Gateway|`172.16.1.1`|设置 PVE IPv4 网关|
|DNS Server|`172.16.1.1`|设置 PVE IPv4 DNS | |DNS Server|`172.16.1.1`|设置 PVE IPv4 DNS |
+18 -13
View File
@@ -64,7 +64,7 @@ deb https://mirrors.ustc.edu.cn/debian-security/ bookworm-security main contrib
默认情况下,PVE 额外启用了 2 个官方源,且为订阅收费制,因此需要替换为免费源。 默认情况下,PVE 额外启用了 2 个官方源,且为订阅收费制,因此需要替换为免费源。
删除 PVE 官方付费软件源,使用以下命令。 删除 PVE 官方付费软件源,执行以下命令。
**注意:rm 为高风险命令,请正确使用,请勿手抖,请勿手抖。** **注意:rm 为高风险命令,请正确使用,请勿手抖,请勿手抖。**
@@ -90,7 +90,7 @@ $ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/pve $VERSION_CODENAME pve
创建完成后对其进行检查。 创建完成后对其进行检查。
```bash ```bash
## 检查PVE免费源 ## 检查 PVE 免费源
$ cat /etc/apt/sources.list.d/ceph-no-subscription.list $ cat /etc/apt/sources.list.d/ceph-no-subscription.list
@@ -116,12 +116,17 @@ deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription
由于该功能暂时未被使用,因此本文只做记录。 由于该功能暂时未被使用,因此本文只做记录。
```bash ```bash
## 替换 CT Templates 源 ## 备份 CT Templates 源
$ cp /usr/share/perl5/PVE/APLInfo.pm /usr/share/perl5/PVE/APLInfo.pm.bak $ cp /usr/share/perl5/PVE/APLInfo.pm /usr/share/perl5/PVE/APLInfo.pm.bak
## 替换 CT Templates 链接
$ sed -i 's|http://download.proxmox.com|https://mirrors.ustc.edu.cn/proxmox|g' /usr/share/perl5/PVE/APLInfo.pm $ sed -i 's|http://download.proxmox.com|https://mirrors.ustc.edu.cn/proxmox|g' /usr/share/perl5/PVE/APLInfo.pm
## 重启 PVE API 守护进程
$ systemctl restart pvedaemon.service
## 更新 CT Templates 列表
$ pveam update
``` ```
### 1.4.镜像同步 ### 1.4.镜像同步
@@ -149,7 +154,7 @@ $ apt dist-upgrade
其中 `unattended-upgrades` 为系统自动更新服务,后续会对其进行配置。 其中 `unattended-upgrades` 为系统自动更新服务,后续会对其进行配置。
`cpufrequtils` 为 CPU 调度器的配置工具,后续会对 CPU 调度算法进行调整。 `linux-cpupower` 为 CPU 调度器的配置工具,后续会对 CPU 调度算法进行调整。
```bash ```bash
## 同步镜像仓库 ## 同步镜像仓库
@@ -159,10 +164,10 @@ $ apt update
$ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base $ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具 ## 安装网络工具
$ apt install iperf iperf3 iftop $ apt install iperf iperf3 iftop openvswitch-switch
## 安装 CPU 调度调整工具 ## 安装 CPU 调度调整工具
$ apt install cpufrequtils $ apt install linux-cpupower
## 根据 CPU 厂商安装 CPU 微码工具 ## 根据 CPU 厂商安装 CPU 微码工具
$ apt install intel-microcode (amd64-microcode) $ apt install intel-microcode (amd64-microcode)
@@ -194,9 +199,9 @@ $ update-pciids
|IPv4|管理地址|`172.16.1.254`|PVE IPv4 地址| |IPv4|管理地址|`172.16.1.254`|PVE IPv4 地址|
||网关地址|`172.16.1.1`|PVE IPv4 网关| ||网关地址|`172.16.1.1`|PVE IPv4 网关|
||DNS 地址|`172.16.1.1`|PVE IPv4 DNS 服务器| ||DNS 地址|`172.16.1.1`|PVE IPv4 DNS 服务器|
|IPv6|管理地址|`fdac::fe`|PVE IPv6 地址| |IPv6|管理地址|`fdac::fe`|PVE IPv6 地址(可选)|
||网关地址|`-`|IPv6 网关将使用 `LLA` 自动配置| ||网关地址|`-`|IPv6 网关将使用 `SLAAC` 自动配置|
||DNS 地址|`fdac::1`|PVE IPv6 DNS 服务器| ||DNS 地址|`fdac::1`|PVE IPv6 DNS 服务器(可选)|
![PVE网络规划](img/p02/pve_net_schematization.png) ![PVE网络规划](img/p02/pve_net_schematization.png)
@@ -248,7 +253,7 @@ $ update-pciids
1. 如非特殊需求,通常情况下 PVE 系统无需使用 IPv6 网络。 1. 如非特殊需求,通常情况下 PVE 系统无需使用 IPv6 网络。
2. 主路由未配置 ULA IPv6 网段时,例如本文演示地址 `fdac::/64` ,无需填写 `IPv6/CIDR` 参数。 2. 主路由未配置 IPv6 ULA 网段时,例如本文演示地址 `fdac::/64` ,无需填写 `IPv6/CIDR` 参数。
3. 通常情况下 IPv6 无需填写 `网关` 参数,IPv6 网关将通过 LLA IPv6 地址自动配置。 3. 通常情况下 IPv6 无需填写 `网关` 参数,IPv6 网关将通过 LLA IPv6 地址自动配置。
@@ -288,9 +293,9 @@ $ update-pciids
在 PVE 系统的安装过程中,设置了 DNS 的 IPv4 地址 `172.16.1.1` ,但并未设置 DNS 的 IPv6 地址。 在 PVE 系统的安装过程中,设置了 DNS 的 IPv4 地址 `172.16.1.1` ,但并未设置 DNS 的 IPv6 地址。
在 PVE 的 DNS 设置页面,手动添加 DNS IPv6 地址,即主路由 LAN 口 ULA IPv6 地址。 在 PVE 的 DNS 设置页面,手动添加 DNS IPv6 地址,即主路由 LAN 口 IPv6 ULA 地址。
同样,若 PVE 不使用 IPv6 网络或主路由未配置 ULA IPv6 网段,本步骤可跳过。 同样,若 PVE 不使用 IPv6 网络或主路由未配置 IPv6 ULA 网段,本步骤可跳过。
![PVE添加IPv6DNS](img/p02/pve_add_ipv6_dns.jpeg) ![PVE添加IPv6DNS](img/p02/pve_add_ipv6_dns.jpeg)
+91 -52
View File
@@ -12,10 +12,10 @@ $ apt update
$ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base $ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具 ## 安装网络工具
$ apt install iperf iperf3 iftop $ apt install iperf iperf3 iftop openvswitch-switch
## 安装 CPU 调度调整工具 ## 安装 CPU 调度调整工具
$ apt install cpufrequtils $ apt install linux-cpupower
## 根据 CPU 厂商安装 CPU 微码工具 ## 根据 CPU 厂商安装 CPU 微码工具
$ apt install intel-microcode (amd64-microcode) $ apt install intel-microcode (amd64-microcode)
@@ -26,7 +26,7 @@ $ update-pciids
## 1.系统时区 ## 1.系统时区
如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以使用以下命令修正。 如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以执行以下命令修正。
输出结果如果和北京时间一致,则代表修改正确。 输出结果如果和北京时间一致,则代表修改正确。
@@ -82,41 +82,45 @@ MS Name/IP address Stratum Poll Reach LastRx Last sample
## 2. CPU 调度器 ## 2. CPU 调度器
安装 `cpufrequtils` 后,需检查 CPU 当前调度器。 安装 `linux-cpupower` 后,需检查 CPU 当前调度器。
```bash ```bash
## 检查 CPU 当前调度器 ## 检查 CPU 当前调度器
$ cpufreq-info $ cpupower -c all frequency-info
#### 设备 CPU - J4125 示例输出 #### 设备 CPU - J4125 示例输出
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
Report errors and bugs to cpufreq@vger.kernel.org, please.
analyzing CPU 0: analyzing CPU 0:
driver: intel_cpufreq driver: intel_cpufreq
CPUs which run at the same hardware frequency: 0 CPUs which run at the same hardware frequency: 0
CPUs which need to have their frequency coordinated by software: 0 CPUs which need to have their frequency coordinated by software: 0
maximum transition latency: 20.0 us. maximum transition latency: 20.0 us
hardware limits: 800 MHz - 2.70 GHz hardware limits: 800 MHz - 2.70 GHz
available cpufreq governors: conservative, ondemand, userspace, powersave, performance, schedutil available cpufreq governors: conservative ondemand userspace powersave performance schedutil
current policy: frequency should be within 800 MHz and 2.70 GHz. current policy: frequency should be within 800 MHz and 2.70 GHz.
The governor "ondemand" may decide which speed to use The governor "ondemand" may decide which speed to use
within this range. within this range.
current CPU frequency is 1.84 GHz. current CPU frequency: Unable to call hardware
current CPU frequency: 800 MHz (asserted by call to kernel)
boost state support:
Supported: yes
Active: yes
#### 设备 CPU - N6005 示例输出 #### 设备 CPU - N6005 示例输出
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
Report errors and bugs to cpufreq@vger.kernel.org, please.
analyzing CPU 0: analyzing CPU 0:
driver: intel_pstate driver: intel_pstate
CPUs which run at the same hardware frequency: 0 CPUs which run at the same hardware frequency: 0
CPUs which need to have their frequency coordinated by software: 0 CPUs which need to have their frequency coordinated by software: 0
maximum transition latency: 4294.55 ms. maximum transition latency: Cannot determine or is not supported.
hardware limits: 800 MHz - 3.30 GHz hardware limits: 800 MHz - 3.30 GHz
available cpufreq governors: performance, powersave available cpufreq governors: performance powersave
current policy: frequency should be within 800 MHz and 3.30 GHz. current policy: frequency should be within 800 MHz and 3.30 GHz.
The governor "performance" may decide which speed to use The governor "performance" may decide which speed to use
within this range. within this range.
current CPU frequency is 2.00 GHz. current CPU frequency: Unable to call hardware
current CPU frequency: 2.00 GHz (asserted by call to kernel)
boost state support:
Supported: yes
Active: yes
``` ```
这里面主要关注两个点: 这里面主要关注两个点:
@@ -140,7 +144,7 @@ performance
CPU 驱动一般不建议手动调整,而 `governor` 后面的参数表示 CPU 当前调度器设置。 CPU 驱动一般不建议手动调整,而 `governor` 后面的参数表示 CPU 当前调度器设置。
接下来,需要了解 CPU 支持的调度器有哪些,使用以下命令。 接下来,需要了解 CPU 支持的调度器有哪些,执行以下命令。
```bash ```bash
## 检查 CPU 调度器支持情况 ## 检查 CPU 调度器支持情况
@@ -159,30 +163,69 @@ performance powersave
- CPU 驱动为 `intel_pstate` 时,推荐使用 `powersave` 调度器。 - CPU 驱动为 `intel_pstate` 时,推荐使用 `powersave` 调度器。
本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器来编辑 `cpufrequtils` 的配置文件。 本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器创建 `cpupower` 的配置文件。
因为该配置文件很长,完整的配置文件可查看 [pve_cpufrequtils.conf](./src/pve_cpufrequtils.conf) 以便对比。
修改完成后,需要重启 PVE 服务器来使参数生效。
```bash ```bash
## 编辑 cpufrequtils 配置文件 ## 创建 cpupower 配置文件
$ nano /etc/init.d/cpufrequtils $ nano /etc/default/cpupower
``` ```
在配置文件中修改以下配置项,并保存。 在配置文件中修改以下配置项,并保存。
```bash ```bash
## cpufrequtils 配置项 # This configuration file is customized by fox,
# Optimize system CPU governors.
ENABLE="true" CPUPOWER_START_OPTS="frequency-set -g powersave"
GOVERNOR="powersave" ## 修改本行的调度器为 powersave CPUPOWER_STOP_OPTS="frequency-set -g performance"
MAX_SPEED="0"
MIN_SPEED="0"
``` ```
PVE 服务器重启完成后需再次查看 CPU 调度器,检验配置文件是否生效 使用 `nano` 编辑器创建 `cpupower` 服务配置文件,以满足系统自动化设置需求
```bash
## 创建 cpupower 服务配置文件
$ nano /etc/systemd/system/cpupower.service
```
在服务配置文件中修改以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize for cpupower systemd service.
[Unit]
Description=Apply cpupower configuration
ConditionVirtualization=!container
After=syslog.target
[Service]
Type=oneshot
EnvironmentFile=/etc/default/cpupower
ExecStart=/usr/bin/cpupower $CPUPOWER_START_OPTS
ExecStop=/usr/bin/cpupower $CPUPOWER_STOP_OPTS
RemainAfterExit=yes
[Install]
WantedBy=multi-user.target
```
由于修改了服务项,需要执行以下命令进行重载。
```bash
## 服务重载
$ systemctl daemon-reload
```
执行以下命令让 `cpupower` 服务开机自启动。
```bash
## 设置 cpupower 服务开机自启
$ systemctl enable cpupower.service
```
修改完成后,需重启 PVE 服务器,并再次查看 CPU 调度器,检验配置文件是否生效。
这里提供两个额外命令,方便实时查看 CPU 当前频率和温度状况。 这里提供两个额外命令,方便实时查看 CPU 当前频率和温度状况。
@@ -196,9 +239,9 @@ $ watch -d sensors
## 3. PVE 定时重启 ## 3. PVE 定时重启
有时需要让 PVE 服务器周期性的定时重启,则可使用以下命令。 有时需要让 PVE 服务器周期性的定时重启,则可执行以下命令。
参数表示每月 `1``16` 号的 `5``0` 执行系统重启命令。 参数表示每月 `1``16` 号的 `02:30` 执行系统重启命令。
```bash ```bash
## 查看系统定时任务 ## 查看系统定时任务
@@ -223,7 +266,7 @@ $ crontab -e
配置系统自动更新之前,需检查系统当前定时器状态。 配置系统自动更新之前,需检查系统当前定时器状态。
后续将手动调整该定时器的时间,使其每 `5`凌晨 `01:30` 进行触发。 后续将手动调整该定时器的时间,使其每 `5` `01:30` 进行触发。
```bash ```bash
## 检查系统定时器 ## 检查系统定时器
@@ -232,17 +275,16 @@ $ systemctl status apt-daily-upgrade.timer
#### 系统定时器示例输出 #### 系统定时器示例输出
● apt-daily-upgrade.timer - Daily apt upgrade and clean activities ● apt-daily-upgrade.timer - Daily apt upgrade and clean activities
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled) Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Active: active (waiting) since Fri 2023-06-23 18:55:58 CST; 1 day 18h ago Active: active (waiting) since Tue 2023-08-01 13:01:19 CST; 27min ago
Until: Fri 2023-06-23 18:55:58 CST; 1 day 18h ago Trigger: Wed 2023-08-02 06:14:50 CST; 16h left
Trigger: Mon 2023-06-26 06:26:25 CST; 16h left
Triggers: ● apt-daily-upgrade.service Triggers: ● apt-daily-upgrade.service
Jun 23 18:55:58 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities. Aug 01 13:01:19 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
``` ```
### 4.2.配置更新策略 ### 4.2.配置更新策略
使用以下命令,启用系统自动更新。 执行以下命令,启用系统自动更新。
执行命令后,使用 “左右” 方向键进行选择,“回车” 键进行确认。 执行命令后,使用 “左右” 方向键进行选择,“回车” 键进行确认。
@@ -307,7 +349,7 @@ $ nano /etc/apt/apt.conf.d/50unattended-upgrades
- 自动重启时间:`02:30` - 自动重启时间:`02:30`
因为该配置文件很长,完整的配置文件可查看 [pve_50unattended_upgrades.conf](./src/pve_50unattended_upgrades.conf) 以便对比。 因为该配置文件很长,完整的配置文件可查看 [pve_50unattended_upgrades.conf](./src/pve/pve_50unattended_upgrades.conf) 以便对比。
```bash ```bash
## 删除以下行前面的注释符 // ,代表启用 ## 删除以下行前面的注释符 // ,代表启用
@@ -342,7 +384,7 @@ Unattended-Upgrade::Automatic-Reboot-Time "02:30";
系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。 系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。
完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve_apt_daily_upgrade.conf) 以便对比。 完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve/pve_apt_daily_upgrade.conf) 以便对比。
```bash ```bash
## 配置系统定时器 ## 配置系统定时器
@@ -375,13 +417,13 @@ $ systemctl status apt-daily-upgrade.timer
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled) Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d
└─override.conf └─override.conf
Active: active (waiting) since Wed 2023-07-26 14:38:06 CST; 11s ago Active: active (waiting) since Tue 2023-08-01 13:37:41 CST; 9s ago
Trigger: Thu 2023-07-27 01:30:00 CST; 10h left Trigger: Wed 2023-08-02 01:30:00 CST; 11h left
Triggers: ● apt-daily-upgrade.service Triggers: ● apt-daily-upgrade.service
Jul 26 14:38:06 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities. Aug 01 13:37:41 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Jul 26 14:38:06 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities... Aug 01 13:37:41 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities...
Jul 26 14:38:06 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities. Aug 01 13:37:41 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
``` ```
## 5.硬件直通 ## 5.硬件直通
@@ -442,7 +484,7 @@ vfio_pci
``` ```
使用以下命令更新 `initramfs` ,更新完成后,建议重启 PVE 服务器。 执行以下命令更新 `initramfs` ,更新完成后,建议重启 PVE 服务器。
```bash ```bash
## 更新 initramfs ## 更新 initramfs
@@ -451,7 +493,7 @@ $ update-initramfs -u -k all
### 5.3.检查硬件直通 ### 5.3.检查硬件直通
PVE 服务器重启完成后,再次使用 SSH 工具登录,并使用以下命令检查硬件直通状态。 PVE 服务器重启完成后,再次使用 SSH 工具登录,并执行以下命令检查硬件直通状态。
主要查看 `IOMMU``Directed I/O``Interrupt Remapping` 的启用状态。 主要查看 `IOMMU``Directed I/O``Interrupt Remapping` 的启用状态。
@@ -491,7 +533,7 @@ $ dmesg | grep -e DMAR -e IOMMU -e AMD-Vi
[ 2.290568] DMAR: Intel(R) Virtualization Technology for Directed I/O [ 2.290568] DMAR: Intel(R) Virtualization Technology for Directed I/O
``` ```
检查系统 `IOMMU` 分组,使用以下命令。 检查系统 `IOMMU` 分组,执行以下命令。
```bash ```bash
## 检查 IOMMU group ## 检查 IOMMU group
@@ -525,7 +567,7 @@ $ find /sys/kernel/iommu_groups/ -type l
## 6.系统清理 ## 6.系统清理
PVE 系统配置完成后,可逐行执行以下命令,对系统进行清理。 PVE 系统配置完成后,可执行以下命令,对系统进行清理。
```bash ```bash
## 清理系统软件包 ## 清理系统软件包
@@ -538,10 +580,7 @@ $ rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
$ find /var/log/ -type f | xargs rm -rvf $ find /var/log/ -type f | xargs rm -rvf
## 清理命令历史记录文件 ## 清理命令历史记录文件
$ rm -rvf ~/.bash_history $ rm -rvf ~/.bash_history && history -c
## 清理命令历史
$ history -c
``` ```
至此 PVE 的系统调整已经完成。 至此 PVE 的系统调整已经完成。
+39 -28
View File
@@ -2,7 +2,7 @@
将虚拟机制作成模板,可在后续新建虚拟机时快速从模板中创建,减少系统安装配置时间。 将虚拟机制作成模板,可在后续新建虚拟机时快速从模板中创建,减少系统安装配置时间。
该虚拟机模板主要作内网 DNS 服务器使用,并会安装 Adguard Home 该虚拟机模板主要作内网 DNS 服务器,由 `Adguard Home``SmartDNS` 提供 DNS 解析服务
本文将使用 Debian 的云镜像 `debian-12-genericcloud-amd64.qcow2` 作为模板虚拟机的镜像。 本文将使用 Debian 的云镜像 `debian-12-genericcloud-amd64.qcow2` 作为模板虚拟机的镜像。
@@ -28,7 +28,7 @@
### 1.3.系统 ### 1.3.系统
SCSI 控制器保持默认 `VirtIO SCSI single` ,并勾选 `Qemu代理` 选项。 SCSI 控制器保持默认 `VirtIO SCSI single` ,机型可选 `q35` ,并勾选 `Qemu代理` 选项。
![虚拟机系统](img/p04/vm_system.jpeg) ![虚拟机系统](img/p04/vm_system.jpeg)
@@ -84,23 +84,23 @@ CPU `类别` 选择 `host` `插槽` 与 `核心` 数根据物理 CPU 核心
### 2.1.删除光驱 ### 2.1.删除光驱
查看虚拟机详情页,在虚拟机硬件配置页面,移除其 `CD/DVD驱动器` 查看虚拟机详情页,在虚拟机 `硬件` 配置页面,移除其 `CD/DVD驱动器`
![虚拟机删除光驱](img/p04/vm_delete_cd.jpeg) ![虚拟机删除光驱](img/p04/vm_delete_cd.jpeg)
### 2.2.导入镜像文件 ### 2.2.导入镜像文件
使用 SSH 工具登录 PVE 服务器,并进入 `tmp` 目录,逐行执行以下命令创建一个文件夹 使用 SSH 工具登录 PVE 服务器,并进入 `tmp` 目录,执行以下命令创建一个目录
```bash ```bash
## 创建存放 Debian 云镜像的临时目录 ## 创建存放 Debian 云镜像的临时目录
$ mkdir -p /tmp/Debian $ mkdir -p /tmp/Debian
## 进入文件夹 ## 进入目录
$ cd /tmp/Debian $ cd /tmp/Debian
``` ```
将 Debian 云镜像传输到该文件夹,并检查 `hash` 将 Debian 云镜像传输到该目录,并检查 `hash`
```bash ```bash
## 下载云镜像校验文件 ## 下载云镜像校验文件
@@ -110,7 +110,7 @@ $ wget https://cloud.debian.org/images/cloud/bookworm/latest/SHA512SUMS
$ wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2 $ wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2
## 检查文件是否存在 ## 检查文件是否存在
$ ls -la $ ls -lah
## 显示校验文件内容 ## 显示校验文件内容
$ cat SHA512SUMS $ cat SHA512SUMS
@@ -119,14 +119,14 @@ $ cat SHA512SUMS
$ sha512sum debian-12-genericcloud-amd64.qcow2 $ sha512sum debian-12-genericcloud-amd64.qcow2
``` ```
确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1000` 确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1001`
```bash ```bash
## 将 qcow2 镜像导入虚拟机中 ## 将 qcow2 镜像导入虚拟机中
$ qm importdisk 1000 debian-12-genericcloud-amd64.qcow2 local-lvm $ qm importdisk 1001 debian-12-genericcloud-amd64.qcow2 local-lvm
#### 镜像导入示例输出 #### 镜像导入示例输出
Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0' Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0'
``` ```
![虚拟机新磁盘](img/p04/vm_unused_hd.jpeg) ![虚拟机新磁盘](img/p04/vm_unused_hd.jpeg)
@@ -157,18 +157,6 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
![虚拟机ci参数](img/p04/vm_ci_details.jpeg) ![虚拟机ci参数](img/p04/vm_ci_details.jpeg)
### 2.4.添加串行端口
部分云镜像需要使用 `serial` 端口作为视频输出端口,否则虚拟机无法启动,因此给模板虚拟机添加串行端口。
点击顶部 `添加` 菜单,选择 `串行端口`
![虚拟机添加串口](img/p04/vm_serial.jpeg)
串行端口编号为 `0`
![虚拟机串口参数](img/p04/vm_serial_details.jpeg)
虚拟机硬件设备修改完成后,如下图所示。 虚拟机硬件设备修改完成后,如下图所示。
![虚拟机全部硬件](img/p04/vm_hardware_all.jpeg) ![虚拟机全部硬件](img/p04/vm_hardware_all.jpeg)
@@ -205,7 +193,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
## 4.设置 Cloud-Init ## 4.设置 Cloud-Init
进入左侧虚拟机 `Cloud-Init` 菜单,可以看到当前虚拟机的初始化参数。 进入左侧虚拟机 `Cloud-Init` 页面,可以看到当前虚拟机的初始化参数。
### 4.1.自动配置 IPv6 ### 4.1.自动配置 IPv6
@@ -215,7 +203,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
|--|--|--| |--|--|--|
|用户|`fox`|新系统的管理员账户| |用户|`fox`|新系统的管理员账户|
|密码|`********`|使用强密码| |密码|`********`|使用强密码|
|DNS域|`fox.local`|内网域名(可选)| |DNS域|`fox.home.arpa`|内网域名(可选)|
|DNS服务器|`172.16.1.1`|本机 DNS 服务器| |DNS服务器|`172.16.1.1`|本机 DNS 服务器|
|SSH公钥|`无`|使用秘钥登录服务器,暂不使用| |SSH公钥|`无`|使用秘钥登录服务器,暂不使用|
|Upgrade packages|`是`|启动时更新软件包,保持默认即可| |Upgrade packages|`是`|启动时更新软件包,保持默认即可|
@@ -237,17 +225,17 @@ Successfully imported disk as 'unused0:local-lvm:vm-1000-disk-0'
### 4.2.手动配置 IPv6 ### 4.2.手动配置 IPv6
当主路由配置了 ULA IPv6 网段,且希望指定内网 DNS 服务器的 ULA IPv6 地址时,需要调整 `Cloud-Init` 参数。 当主路由配置了 IPv6 ULA 网段,且希望指定内网 DNS 服务器的 IPv6 ULA 地址时,需要调整 `Cloud-Init` 参数。
本文 ULA IPv6 演示地址为 `fdac::/64` `DNS服务器``IP配置` 参数调整如下。 本文 IPv6 ULA 演示地址为 `fdac::/64` `DNS服务器``IP配置` 参数调整如下。
|参数|值|说明| |参数|值|说明|
|--|--|--| |--|--|--|
|DNS域|`fox.local`|内网域名(可选)| |DNS域|`fox.home.arpa`|内网域名(可选)|
|DNS服务器|`172.16.1.1 fdac::1`|本机 DNS 服务器| |DNS服务器|`172.16.1.1 fdac::1`|本机 DNS 服务器|
|IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置| |IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置|
`DNS服务器` 参数中需要加入主路由 LAN 口 ULA IPv6 地址。 `DNS服务器` 参数中需要加入主路由 LAN 口 IPv6 ULA 地址。
![CI网络配置](img/p04/vm_ci_dns_ula.jpeg) ![CI网络配置](img/p04/vm_ci_dns_ula.jpeg)
@@ -257,5 +245,28 @@ IPv6 使用静态地址后,并不影响虚拟机通过主路由获取公网 GU
![CI网络配置](img/p04/vm_ci_network_static.jpeg) ![CI网络配置](img/p04/vm_ci_network_static.jpeg)
## 5.设置备注信息
进入左侧虚拟机 `概要` 页面,修改虚拟机的备注信息。
```bash
### 服务器信息
- 系统: Debian12
- 用途: 内网 DNS 服务器 ( 模板 )
- 自启: 否
- 用户: fox
- IPv4 172.16.1.250/24
- IPv6 SLAAC
```
![虚拟机备注](img/p04/vm_notes.jpeg)
至此,模板虚拟机创建完成,可将该虚拟机开机。 至此,模板虚拟机创建完成,可将该虚拟机开机。
+18 -19
View File
@@ -112,13 +112,15 @@ $ sudo vim /etc/apt/sources.list.d/debian.sources
Types: deb Types: deb
URIs: https://mirrors.ustc.edu.cn/debian URIs: https://mirrors.ustc.edu.cn/debian
Suites: bookworm bookworm-updates bookworm-backports Suites: bookworm bookworm-updates
Components: main contrib non-free non-free-firmware Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb Types: deb
URIs: https://mirrors.ustc.edu.cn/debian-security URIs: https://mirrors.ustc.edu.cn/debian-security
Suites: bookworm-security Suites: bookworm-security
Components: main contrib non-free non-free-firmware Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
``` ```
@@ -137,7 +139,7 @@ $ lsattr /etc/apt/sources.list.d/debian.sources
### 1.3.安装软件 ### 1.3.安装软件
软件源设置完成后,需要更新系统,逐行执行以下命令。 软件源设置完成后,需要更新系统,执行以下命令。
```bash ```bash
## 清理不必要的包 ## 清理不必要的包
@@ -160,7 +162,7 @@ $ sudo apt install qemu-guest-agent zsh git htop tmux cron nftables sshguard neo
$ sudo apt install unattended-upgrades powermgmt-base python3-gi $ sudo apt install unattended-upgrades powermgmt-base python3-gi
## 安装网络工具 ## 安装网络工具
$ sudo apt install iperf iperf3 iftop lsof ldnsutils $ sudo apt install iperf iperf3 iftop lsof knot-dnsutils
## 写入磁盘 ## 写入磁盘
$ sudo sync $ sudo sync
@@ -180,30 +182,32 @@ $ sudo nvim /etc/sysctl.d/99-sysctl.conf
在配置文件末尾输入以下配置项,注意配置中间的空格。 在配置文件末尾输入以下配置项,注意配置中间的空格。
```bash ```bash
# This configuration file is customized by fox # This configuration file is customized by fox,
# Optimize system parameters # Optimize sysctl parameters for local DNS server.
kernel.panic = 20 kernel.panic = 20
kernel.panic_on_oops = 1 kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr net.ipv4.tcp_congestion_control = bbr
# Other adjustable system parameters # Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.ipv4.conf.all.log_martians = 1 net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 100 net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_challenge_ack_limit = 1000 net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30 net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120 net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_max_orphans = 4096
net.ipv4.tcp_max_tw_buckets = 4096
net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.use_tempaddr = 0 net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0 net.ipv6.conf.default.use_tempaddr = 0
``` ```
保存该配置文件后,重启系统或者执行以下命令让配置生效。 保存该配置文件后,重启系统或者执行以下命令让配置生效。
@@ -230,10 +234,10 @@ Mon, 26 Jun 2023 16:16:16 +0800
Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。 Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。
调整 NTP 服务器参数,逐行执行以下命令。 调整 NTP 服务器参数,执行以下命令。
```bash ```bash
## 创建 NTP 配置文件的文件夹 ## 创建 NTP 配置文件的目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d $ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件 ## 创建 NTP 配置文件
@@ -335,7 +339,7 @@ $ sudo nvim /etc/apt/apt.conf.d/50unattended-upgrades
根据 “注释” 中相关说明,调整配置文件。 根据 “注释” 中相关说明,调整配置文件。
因为该配置文件很长,完整的配置文件可查看 [debian_50unattended_upgrades.conf](./src/debian_50unattended_upgrades.conf) 以便对比。 因为该配置文件很长,完整的配置文件可查看 [debian_dns_50unattended_upgrades.conf](./src/debian/debian_dns_50unattended_upgrades.conf) 以便对比。
```bash ```bash
## 删除以下行前面的注释符 // ,代表启用 ## 删除以下行前面的注释符 // ,代表启用
@@ -379,7 +383,7 @@ RandomizedDelaySec=0
设置完成后,重启自动更新定时器并检查其状态,执行以下命令。 设置完成后,重启自动更新定时器并检查其状态,执行以下命令。
在输出结果中看到系统自动更新的触发时间为凌晨 `02:00` 则表示设置正确。 在输出结果中看到系统自动更新的触发时间为 `02:00` 则表示设置正确。
```bash ```bash
## 重启触发器 ## 重启触发器
@@ -435,8 +439,6 @@ Do you want to change your default shell to zsh? [Y/n] y
Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。 Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。
逐行执行以下命令,注意命令中的空格。
```bash ```bash
## 清理系统软件包 ## 清理系统软件包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge $ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
@@ -448,10 +450,7 @@ $ sudo rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/*
$ sudo find /var/log/ -type f | xargs sudo rm -rvf $ sudo find /var/log/ -type f | xargs sudo rm -rvf
## 清理命令历史记录文件 ## 清理命令历史记录文件
$ rm -rvf ~/.bash_history ~/.zsh_history $ rm -rvf ~/.bash_history ~/.zsh_history ~/.zcompdump* && history -c
## 清理命令历史
$ history -c
## 关闭系统 ## 关闭系统
$ sudo shutdown now $ sudo shutdown now
@@ -27,23 +27,29 @@
克隆出来的虚拟机的 `Cloud-Init` 参数默认与模板完全一致。 克隆出来的虚拟机的 `Cloud-Init` 参数默认与模板完全一致。
根据 **内部网络地址** 规划,内网 DNS 服务器 IP 地址分别为 根据 **内部网络地址** 规划,内网 DNS 服务器 IPv4 地址规划如下
- `172.16.1.2/24 (fdac::2/64)` - `172.16.1.2/24`
- `172.16.1.3/24 (fdac::3/64)` - `172.16.1.3/24`
因此需要调整新虚拟机的 `Cloud-Init` 参数。 因此需要调整新虚拟机的 `Cloud-Init` 参数。
- `IP配置` 中的 IPv4 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变。 - `IP配置` 中的 IPv4 地址参数为 `172.16.1.2/24` ,网关保持 `172.16.1.1` 不变。
- `IP配置` 中的 IPv6 地址参数为 `fdac::2/64` ,网关保持为空。 - `IP配置` 中的 IPv6 地址参数为 `auto` ,网关保持为空。
需要注意的是,如果修改了 `用户` 参数,相当于新建了一个系统管理员,之前设置的 `oh-my-zsh` 需要在新管理员下重新设置。 需要注意的是,如果修改了 `用户` 参数,相当于新建了一个系统管理员,之前设置的 `oh-my-zsh` 需要在新管理员下重新设置。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_slaac.jpeg) ![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_slaac.jpeg)
当主路由配置了 ULA IPv6 网段,且指定了内网 DNS 服务器的 ULA IPv6 地址时,参数如下 当主路由配置了 IPv6 ULA 网段,内网 DNS 服务器 IPv6 ULA 地址规划如下
- `fdac::2/64`
- `fdac::3/64`
此时需进一步调整新虚拟机的 `Cloud-Init` 参数,让该虚拟机使用指定的 IPv6 ULA 地址,参数如下。
![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_static.jpeg) ![调整新虚拟机Cloud-Init](img/p06/vm_clone_ci_static.jpeg)
@@ -65,26 +71,26 @@
## 4.调整系统端口 ## 4.调整系统端口
设置完成后,将该虚拟机开机,使用 SSH 工具登录,并使用以下命令检查端口占用。 设置完成后,将该虚拟机开机,使用 SSH 工具登录,并执行以下命令检查端口占用。
```bash ```bash
## 检查 53 端口占用 ## 检查 53 端口占用
$ sudo lsof -i :53 $ sudo lsof -n -i :53
#### 端口占用示例输出 #### 端口占用示例输出
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
systemd-r 347 systemd-resolve 17u IPv4 13445 0t0 UDP localhost:domain systemd-r 1797 systemd-resolve 18u IPv4 23024 0t0 UDP 127.0.0.53:domain
systemd-r 347 systemd-resolve 18u IPv4 13446 0t0 TCP localhost:domain (LISTEN) systemd-r 1797 systemd-resolve 19u IPv4 23025 0t0 TCP 127.0.0.53:domain (LISTEN)
systemd-r 347 systemd-resolve 19u IPv4 13447 0t0 UDP localhost:domain systemd-r 1797 systemd-resolve 20u IPv4 23026 0t0 UDP 127.0.0.54:domain
systemd-r 347 systemd-resolve 20u IPv4 13448 0t0 TCP localhost:domain (LISTEN) systemd-r 1797 systemd-resolve 21u IPv4 23027 0t0 TCP 127.0.0.54:domain (LISTEN)
``` ```
当前系统 `53` 端口被 `systemd-resolved.service` 占用,会导致设置 DNS 服务时监听端口失败。 当前系统 `53` 端口被 `systemd-resolved.service` 占用,会导致设置 DNS 服务时监听端口失败。
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,逐行执行以下命令。 为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
```bash ```bash
## 创建 systemd-resolved 配置文件夹 ## 创建 systemd-resolved 配置目录
$ sudo mkdir -p /etc/systemd/resolved.conf.d $ sudo mkdir -p /etc/systemd/resolved.conf.d
## 创建 systemd-resolved 配置文件 ## 创建 systemd-resolved 配置文件
@@ -98,33 +104,31 @@ $ sudo nvim /etc/systemd/resolved.conf.d/server_dns.conf
[Resolve] [Resolve]
DNS=127.0.0.1 DNS=127.0.0.1
DNS=::1
DNSStubListener=no DNSStubListener=no
``` ```
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,逐行执行以下命令。 保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,执行以下命令。
```bash ```bash
## 备份 resolv.conf 配置文件
$ sudo mv /etc/resolv.conf /etc/resolv.conf.bak
## 创建 resolv.conf 软链接 ## 创建 resolv.conf 软链接
$ sudo ln -s /run/systemd/resolve/resolv.conf /etc/resolv.conf $ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
``` ```
配置完成后,需重启 `systemd-resolved.service` 服务,并再次检查系统 `53` 端口占用。 配置完成后,需重启 `systemd-resolved.service` 服务,并再次检查系统 `53` 端口占用。
```bash ```bash
## 重启 systemd-resolved 服务 ## 重启 systemd-resolved.service
$ sudo systemctl restart systemd-resolved.service $ sudo systemctl restart systemd-resolved.service
``` ```
## 5. Adguard Home ## 5. Adguard Home
`Adguard Home` 将采用 `snap` 形式安装,逐行执行以下命令。 `Adguard Home` 将采用 `snap` 形式安装,执行以下命令。
```bash ```bash
## 安装 snap ## 安装 Snap
$ sudo apt install snapd $ sudo apt install snapd
## 安装 Adguard Home ## 安装 Adguard Home
@@ -156,7 +160,7 @@ $ sudo snap set system refresh.timer=mon,2:30,,fri,2:30
### 5.3.定时任务 ### 5.3.定时任务
本步骤为可选操作,主要设置定时重启 `Adguard Home` 本步骤为可选操作,主要用于设置 `Adguard Home` 定时重启
```bash ```bash
## 查看系统定时任务 ## 查看系统定时任务
@@ -179,60 +183,113 @@ $ sudo crontab -e
若需使用 `SmartDNS` 代替 `Adguard Home` ,可使用 Debian 官方源进行安装,但其版本通常较为 “过时” 。 若需使用 `SmartDNS` 代替 `Adguard Home` ,可使用 Debian 官方源进行安装,但其版本通常较为 “过时” 。
```bash
## 安装 SmartDNS
$ sudo apt install smartdns
```
因此,更推荐使用其 Github 仓库中的最新稳定版进行安装,官方仓库请参阅 [pymumu/smartdns](https://github.com/pymumu/smartdns/releases) 。 因此,更推荐使用其 Github 仓库中的最新稳定版进行安装,官方仓库请参阅 [pymumu/smartdns](https://github.com/pymumu/smartdns/releases) 。
下载 `SmartDNS` 最新版本时,请根据系统架构选择合适的版本,逐行执行以下命令 多数情况下,`SmartDNS` 足以提供良好的 DNS 解析服务,但为了进一步优化 DNS 解析流程,推荐与 `Dnsmasq` 嵌套使用
```bash
## 安装 Dnsmasq
$ sudo apt install dnsmasq
```
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
```bash
## 检查 dnsmasq.service
$ sudo systemctl status dnsmasq.service
## 设置 dnsmasq.service 开机自启
$ sudo systemctl enable dnsmasq.service
## 停止 dnsmasq.service
$ sudo systemctl stop dnsmasq.service
```
下载 `SmartDNS` 最新版本时,请根据系统架构选择合适的版本,执行以下命令。
```bash ```bash
## 创建存放 SmartDNS 安装包的临时目录 ## 创建存放 SmartDNS 安装包的临时目录
$ mkdir -p /tmp/SmartDNS $ mkdir -p /tmp/SmartDNS
## 进入文件夹 ## 进入目录
$ cd /tmp/SmartDNS $ cd /tmp/SmartDNS
## 下载 SmartDNS 安装包 ## 下载 SmartDNS 安装包
$ wget https://github.com/pymumu/smartdns/releases/download/Release42/smartdns.1.2023.05.07-1641.x86_64-linux-all.tar.gz $ curl -LR -O https://github.com/pymumu/smartdns/releases/download/Release45/smartdns.1.2024.02.08-0828.x86_64-linux-all.tar.gz
## 解压缩 SmartDNS 安装包 ## 解压缩 SmartDNS 安装包
$ tar zxf smartdns.1.2023.05.07-1641.x86_64-linux-all.tar.gz $ tar zxf smartdns.1.2024.02.08-0828.x86_64-linux-all.tar.gz
## 进入安装包目录 ## 进入安装包目录
$ cd smartdns $ cd smartdns
## 赋予安装脚本执行权限 ## 设置脚本执行权限
$ chmod +x ./install $ chmod +x ./install
## 安装 SmartDNS ## 安装 SmartDNS
$ sudo ./install -i $ sudo ./install -i
``` ```
修改 `SmartDNS` 配置之前,需检查 `smartdns.service` 服务状态,确保该服务开机自启 修改 `SmartDNS` 配置之前,需检查 `smartdns.service` 服务状态,确保该服务开机自启。
```bash ```bash
## 检查 smartdns.service ## 检查 smartdns.service
$ sudo systemctl status smartdns.service $ sudo systemctl status smartdns.service
## 设置 smartdns.service 开机自启 ## 设置 smartdns.service 开机自启
$ sudo systemctl enable smartdns.service $ sudo systemctl enable smartdns.service
``` ```
### 6.1.配置 SmartDNS ### 6.1. SmartDNS 附加配置
本步骤为可选操作,通过安装 `SmartDNS` 附加配置文件,以达到屏蔽广告或加速中国境内域名解析速度的目的。
若需使用 `SmartDNS` 屏蔽广告,则需下载广告规则配置文件。
```bash
## 创建 SmartDNS 配置文件目录
$ sudo mkdir -p /etc/smartdns.d
## 下载广告规则配置文件
$ sudo curl -LR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
```
`SmartDNS` 的加速规则通过 `bash` 脚本安装,脚本生成的配置文件位于 `/etc/smartdns.d` 目录。
关于脚本的详细介绍,请参阅 [SmartDNS China List 安装脚本](https://gitee.com/callmer/smartdns_china_list_installer) 。
```bash
## 下载加速规则安装脚本
$ sudo curl -LR -o /opt/smartdns_plugin.sh https://gitee.com/callmer/smartdns_china_list_installer/raw/main/smartdns_plugin.sh
## 设置脚本可执行权限
$ sudo chmod +x /opt/smartdns_plugin.sh
## 设置脚本文件防篡改
$ sudo chattr +i /opt/smartdns_plugin.sh
## 执行脚本
$ sudo bash /opt/smartdns_plugin.sh
```
### 6.2. SmartDNS 主配置
`SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/) 。 `SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/) 。
若需使用 `SmartDNS` 过滤广告,则需下载其广告过滤配置文件,为可选操作 修改 `SmartDNS` 主配置文件之前,建议关闭 `SmartDNS` 并清理 DNS 缓存文件
```bash ```bash
## 下载广告过滤配置文件 ## 关闭 smartdns.service
$ sudo wget https://anti-ad.net/anti-ad-for-smartdns.conf -O /etc/smartdns/anti-ad-smartdns.conf $ sudo systemctl stop smartdns.service
## 清理缓存
$ sudo rm -rvf /var/cache/smartdns
## 清理进程标识文件
$ sudo rm -rvf /var/run/smartdns.pid /run/smartdns.pid
``` ```
`SmartDNS` 的主配置文件一般位于 `/etc/smartdns` 目录下,修改配置文件之前,使用以下命令将其备份。 `SmartDNS` 的主配置文件一般位于 `/etc/smartdns` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash ```bash
## 备份 SmartDNS 主配置文件 ## 备份 SmartDNS 主配置文件
@@ -250,9 +307,13 @@ $ sudo nvim /etc/smartdns/smartdns.conf
**额外说明:** **额外说明:**
- 当不使用 `anti-ad-smartdns.conf` 进行广告过滤时,需移除主配置文件中对应配置项。 - 由于修改了缓存路径,`SmartDNS` 的缓存将在系统重启时自动删除,请根据实际情况进行调整
- 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整 - `SmartDNS` 端口监听参数为 `6053@lo` ,请根据实际情况进行调整
- `edns-client-subnet` 为 EDNS 客户端子网,演示中 `202.103.24.68` 为湖北武汉市 DNS 服务器地址,请根据实际情况进行调整
- 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整
```bash ```bash
# This configuration file is customized by fox, # This configuration file is customized by fox,
@@ -269,23 +330,30 @@ $ sudo nvim /etc/smartdns/smartdns.conf
# server 2402:4e00:: # server 2402:4e00::
# server 2400:3200::1 # server 2400:3200::1
conf-file /etc/smartdns/anti-ad-smartdns.conf conf-file /etc/smartdns.d/adrules.smartdns.conf
conf-file /etc/smartdns.d/dns-group.china.smartdns.conf
conf-file /etc/smartdns.d/apple.china.smartdns.conf
conf-file /etc/smartdns.d/google.china.smartdns.conf
conf-file /etc/smartdns.d/accelerated-domains.china.smartdns.conf
conf-file /etc/smartdns.d/bogus-nxdomain.china.smartdns.conf
cache-file /tmp/smartdns.cache cache-file /tmp/smartdns.cache
bind [::]:53 log-level notice
bind-tcp [::]:53
bind [::]:6053@lo
bind-tcp [::]:6053@lo
serve-expired yes serve-expired yes
serve-expired-ttl 86400 serve-expired-ttl 64800
serve-expired-reply-ttl 3 serve-expired-reply-ttl 3
prefetch-domain yes prefetch-domain yes
serve-expired-prefetch-time 43200 serve-expired-prefetch-time 21600
speed-check-mode ping,tcp:80,tcp:443
force-qtype-SOA 65 force-qtype-SOA 65
max-query-limit 1024
log-level notice edns-client-subnet 202.103.24.68
server-tcp 119.29.29.29 -group dnspod -exclude-default-group server-tcp 119.29.29.29 -group dnspod -exclude-default-group
server-tcp 2402:4e00:: -group dnspod -exclude-default-group server-tcp 2402:4e00:: -group dnspod -exclude-default-group
@@ -297,9 +365,8 @@ server-tcp 2400:3200::1 -group alidns -exclude-default-group
nameserver /dns.alidns.com/alidns nameserver /dns.alidns.com/alidns
server 172.16.1.1 -group intranet -exclude-default-group server 172.16.1.1 -group intranet -exclude-default-group
server fdac::1 -group intranet -exclude-default-group nameserver /fox.home.arpa/intranet
nameserver /fox.local/intranet domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
domain-rules /fox.local/ -speed-check-mode none -no-cache
server-tls dot.pub server-tls dot.pub
server-tls dns.alidns.com server-tls dns.alidns.com
@@ -309,9 +376,9 @@ server-https https://dns.alidns.com/dns-query
``` ```
### 6.2.定时任务 ### 6.3.定时任务
本步骤为可选操作,主要设置 `SmartDNS` 定时更新广告过滤配置文件和定时重启。 本步骤为可选操作,主要用于设置 `SmartDNS` 定时更新附加配置文件和定时重启。
```bash ```bash
## 编辑系统定时任务,编辑器选择 nano ## 编辑系统定时任务,编辑器选择 nano
@@ -323,11 +390,99 @@ $ sudo crontab -e
```bash ```bash
## 定时任务配置项 ## 定时任务配置项
0 5 * * * /usr/bin/wget -q --tries=10 --retry-connrefused --random-wait https://anti-ad.net/anti-ad-for-smartdns.conf -O /etc/smartdns/anti-ad-smartdns.conf 20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
30 5 * * * /usr/bin/systemctl restart smartdns.service 30 9 * * * /usr/bin/systemctl restart smartdns.service
``` ```
至此,新虚拟机已配置完成,可作为内网 DNS 服务器使用 若使用了 `SmartDNS` 加速规则的安装脚本,由于脚本自带服务重启功能,因此定时任务可修改如下
```bash
## 定时任务配置项
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
30 9 * * * /usr/bin/bash /opt/smartdns_plugin.sh
```
### 6.4.配置 Dnsmasq
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 Dnsmasq 主配置文件
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash
## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
- `Dnsmasq` 有且仅有 `SmartDNS` 作为上游 DNS 服务器
```bash
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local DNS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=1024
max-cache-ttl=7200
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
localise-queries
local-service
no-hosts
no-negcache
no-resolv
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/ipv4only.arpa/
server=/resolver.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/fox.home.arpa/172.16.1.1
server=127.0.0.1#6053
server=::1#6053
```
至此,新虚拟机已配置完成,重启后即可作为内网 DNS 服务器使用。
+617
View File
@@ -0,0 +1,617 @@
## 0.前期准备
某些业务场景下需要构建安全可靠的网络隧道,来打通异地内网环境或从外部访问内网的私有资源。
经过实际测试,当 TS 服务器具有 IPv6 GUA 地址时,能稳定建立隧道。
本文将使用 Debian 云镜像以及 `Tailscale` 来制作内网组网服务器。
对于虚拟机创建部分,请参考 [04.PVE创建模板虚拟机](./04.PVE创建模板虚拟机.md) ,其他 `Cloud-Init` 相关参数如下。
|参数|值|说明|
|--|--|--|
|虚拟机名称|`SVR01`| TS 服务器 `主机名` |
|DNS 域|`fox.home.arpa`| TS 服务器 `Cloud-Init` |
|DNS 服务器|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|IPv4|`172.16.1.4/24`| TS 服务器 `Cloud-Init` |
|IPv4 网关|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|IPv6|`SLAAC`| TS 服务器 `Cloud-Init` |
## 1.配置系统
由于 TS 服务器具备路由功能,所以在配置方法和系统参数方面与内网 DNS 服务器有一些区别。
### 1.1.配置 SSH
与配置内网 DNS 服务器时一样,首先需要调整系统的 SSH 登录权限参数。
在虚拟机的命令行界面,使用 `vim` 编辑器编辑 `sshd` 服务的配置文件,执行以下命令。
```bash
## 编辑 ssh 配置文件
$ sudo vim /etc/ssh/sshd_config.d/server_sshd.conf
```
在配置文件中添加以下配置项,并保存。
```bash
## SSH 配置项
PasswordAuthentication yes
PermitEmptyPasswords no
UseDNS no
```
修改完成后,需要重启 SSH 服务。
```bash
## 重启 sshd
$ sudo systemctl restart ssh.service
```
### 1.2.配置软件源
使用 SSH 工具登录 TS 服务器,常用 SSH 工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。
首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](http://mirrors.ustc.edu.cn/help/debian.html) 镜像站作为演示。
当系统版本发生变化时,请参考使用 snullp 大叔开发的 [配置生成器](https://mirrors.ustc.edu.cn/repogen/) 。
使用 `vim` 编辑器编辑 `debian.sources` 配置文件,执行以下命令。
```bash
## 编辑 debian.sources 配置文件
$ sudo vim /etc/apt/sources.list.d/debian.sources
```
删除里面全部内容,添加以下配置项,并保存。
```bash
## 系统软件源配置项
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian
Suites: bookworm bookworm-updates
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb
URIs: https://mirrors.ustc.edu.cn/debian-security
Suites: bookworm-security
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
```
为了防止 `Cloud-Init` 服务意外修改软件源配置,需要添加文件保护,执行以下命令。
```bash
## 增加文件保护
$ sudo chattr +i /etc/apt/sources.list.d/debian.sources
## 检查文件保护
$ lsattr /etc/apt/sources.list.d/debian.sources
#### 示例输出
----i---------e------- /etc/apt/sources.list.d/debian.sources
```
进一步添加 TS 签名密钥以及软件源,执行以下命令。
```bash
## 添加 TS 签名密钥
$ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.noarmor.gpg | sudo tee /usr/share/keyrings/tailscale-archive-keyring.gpg > /dev/null
## 添加 TS 软件源
$ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.tailscale-keyring.list | sudo tee /etc/apt/sources.list.d/tailscale.list
```
### 1.3.安装软件
软件源设置完成后,需要更新系统,执行以下命令。
```bash
## 清理不必要的包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge
## 更新软件源
$ sudo apt update
## 更新系统
$ sudo apt dist-upgrade
```
接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。
```bash
## 安装系统软件
$ sudo apt install qemu-guest-agent zsh git htop tmux cron nftables sshguard neovim
## 安装系统自动更新工具
$ sudo apt install unattended-upgrades powermgmt-base python3-gi
## 安装网络工具
$ sudo apt install iperf iperf3 iftop lsof knot-dnsutils dnsmasq conntrack
## 安装 TS
$ sudo apt install tailscale
## 写入磁盘
$ sudo sync
```
### 1.4.调整内核模块
使用 `neovim` 编辑器编辑 **内核模块** 配置文件,执行以下命令。
```bash
## 创建 内核模块 配置文件
$ sudo nvim /etc/modules-load.d/server_modules.conf
```
在配置文件中添加以下配置项,并保存。
```bash
# This configuration file is customized by fox,
# Optimize netfilter related modules at system boot.
nf_conntrack
```
### 1.5.调整内核参数
使用 `neovim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
```bash
## 编辑 内核参数 配置文件
$ sudo nvim /etc/sysctl.d/99-sysctl.conf
```
在配置文件末尾输入以下配置项,注意配置中间的空格。
```bash
# This configuration file is customized by fox,
# Optimize sysctl parameters for local TS server.
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
net.ipv4.ip_forward = 1
net.ipv6.conf.all.forwarding = 1
net.ipv6.conf.default.forwarding = 1
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.all.arp_ignore = 1
net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 256
net.ipv4.route.error_burst = 500
net.ipv4.route.error_cost = 100
net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
net.ipv6.conf.all.accept_source_route = 0
net.ipv6.conf.default.accept_source_route = 0
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
net.netfilter.nf_conntrack_acct = 1
net.netfilter.nf_conntrack_checksum = 0
net.netfilter.nf_conntrack_tcp_timeout_established = 7440
```
保存该配置文件后,重启系统或者执行以下命令让配置生效。
```bash
## 让内核参数生效
$ sudo sysctl -f
```
### 1.6.调整系统时间
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
```bash
## 设置系统时区
$ sudo timedatectl set-timezone Asia/Shanghai
## 检查系统时间
$ date -R
```
Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需要调整为使用国内 NTP 服务器。
调整 NTP 服务器参数,执行以下命令。
```bash
## 创建 NTP 配置文件的目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件
$ sudo nvim /etc/systemd/timesyncd.conf.d/server_ntp.conf
```
在配置文件中添加以下配置项,并保存。
```bash
## NTP 配置项
[Time]
NTP=ntp.tencent.com ntp.aliyun.com
```
保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。
```bash
## 重启 chrony 服务
$ sudo systemctl restart systemd-timesyncd.service
## 检查系统 NTP 服务器
$ sudo systemctl status systemd-timesyncd.service
```
### 1.7.配置自动更新
配置系统自动更新策略,执行以下命令,使用键盘 `左右方向键` 进行选择,`回车键` 进行确认。
```bash
## 配置自动更新策略
$ sudo dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”)
#### 系统自动更新示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
```
进一步调整 `20auto-upgrades` 配置文件。
```bash
## 编辑 20auto-upgrades 配置文件
$ sudo nvim /etc/apt/apt.conf.d/20auto-upgrades
```
删除里面全部内容,添加以下配置项,并保存。
配置文件中,用来控制更新周期的参数为 `APT::Periodic::Unattended-Upgrade` `7` 表示更新周期为 `7` 天。
```bash
## 系统更新周期配置项
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "7";
APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1";
```
进一步调整 `50unattended-upgrades` 配置文件。
```bash
## 编辑 50unattended-upgrades 配置文件
$ sudo nvim /etc/apt/apt.conf.d/50unattended-upgrades
```
根据 “注释” 中相关说明,调整配置文件。
因为该配置文件很长,完整的配置文件可查看 [debian_ts_50unattended_upgrades.conf](./src/debian/debian_ts_50unattended_upgrades.conf) 以便对比。
```bash
## 删除以下行前面的注释符 // ,代表启用
"origin=Debian,codename=${distro_codename}-updates";
## 添加 TS 更新项目
"origin=Tailscale,codename=${distro_codename},label=Tailscale";
## 在配置文件末尾增加以下配置项,代表启用,并调整参数
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
```
系统自动更新配置文件修改完成后,需要重设自动更新定时器,执行以下命令。
```bash
## 配置系统定时器
$ sudo systemctl edit apt-daily-upgrade.timer
```
根据配置文件中的提示,在中间空白处填入以下配置项。
```bash
## 定时器配置项
[Timer]
OnCalendar=
OnCalendar=02:00
RandomizedDelaySec=0
```
设置完成后,重启自动更新定时器并检查其状态,执行以下命令。
在输出结果中,看到系统自动更新的触发时间为 `02:00` 则表示设置正确。
```bash
## 重启触发器
$ sudo systemctl restart apt-daily-upgrade.timer
## 再次检查触发器状态
$ sudo systemctl status apt-daily-upgrade.timer
```
### 1.8.配置防火墙
修改防火墙配置之前,需检查 `nftables.service` 服务状态,确保该服务开机自启。
```bash
## 检查 nftables.service
$ sudo systemctl status nftables.service
## 设置 nftables.service 开机自启
$ sudo systemctl enable nftables.service
```
使用 `neovim` 编辑器修改 `nftables` 配置文件,执行以下命令。
```bash
## 备份 nftables 配置文件
$ sudo mv /etc/nftables.conf /etc/nftables.conf.bak
## 创建新的 nftables 配置文件
$ sudo nvim /etc/nftables.conf
```
由于防火墙配置文件很长,因此请查阅文件 [debian_ts_nftables.conf](./src/debian/debian_ts_nftables.conf) 进行复制。
配置完成后,需重启 `nftables.service` 服务。
```bash
## 重启 nftables.service
$ sudo systemctl restart nftables.service
```
### 1.9.调整系统端口
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
```bash
## 创建 systemd-resolved 配置目录
$ sudo mkdir -p /etc/systemd/resolved.conf.d
## 创建 systemd-resolved 配置文件
$ sudo nvim /etc/systemd/resolved.conf.d/server_dns.conf
```
在配置文件中添加以下配置项,并保存。
```bash
## systemd-resolved 配置项
[Resolve]
DNS=127.0.0.1
DNS=::1
DNSStubListener=no
```
保存该配置文件后,还需调整系统 `resolv.conf` 配置文件,执行以下命令。
```bash
## 创建 resolv.conf 软链接
$ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
```
配置完成后,需重启 `systemd-resolved.service` 服务。
```bash
## 重启 systemd-resolved.service
$ sudo systemctl restart systemd-resolved.service
```
### 1.10.配置 Dnsmasq
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
```bash
## 检查 dnsmasq.service
$ sudo systemctl status dnsmasq.service
## 设置 dnsmasq.service 开机自启
$ sudo systemctl enable dnsmasq.service
```
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份。
```bash
## 备份 Dnsmasq 主配置文件
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak
```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash
## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf
```
在编辑器对话框中输入以下内容,并保存。
**额外说明:**
- 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整
- `Dnsmasq` 上游 DNS 服务器分为三类,请根据实际情况进行调整
- `server=/ts.net/100.100.100.100` TS 服务 `MagicDNS` 专用 DNS 服务器
- `server=/fox.home.arpa/172.16.1.1` :内网域名解析 DNS 服务器,通常为主路由地址
- `server` 参数中的其他 DNS 服务器供 TS 服务器自身及其下游设备使用
```bash
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local TS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=1024
max-cache-ttl=7200
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
localise-queries
local-service
no-hosts
no-negcache
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/ipv4only.arpa/
server=/resolver.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1
server=172.16.1.1
```
配置完成后,需重启 `dnsmasq.service` 服务。
```bash
## 重启 dnsmasq.service
$ sudo systemctl restart dnsmasq.service
```
### 1.11.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 返回 home 目录
$ cd
## 使用 curl 安装 oh-my-zsh
$ sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)"
## 或者使用 wget 安装 oh-my-zsh
$ sh -c "$(wget https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh -O -)"
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
```
## 2.配置 Tailscale
根据不同的启动参数,TS 服务将具有不同的业务能力。
若仅需 TS 组网功能,执行以下命令。
```bash
## TS 普通组网模式
$ sudo tailscale up
```
若需 TS 提供 `Exit Node` 功能,执行以下命令。
```bash
## TS Exit Node 模式
$ sudo tailscale up --advertise-exit-node --reset
## TS Exit Node 模式,但不使用 MagicDNS
$ sudo tailscale up --advertise-exit-node --accept-dns=false --reset
```
若需 TS 提供内网路由功能并能访问内网私有服务,执行以下命令。
**额外说明:**
- 请根据内网网段,调整 TS 内网路由参数 `advertise-routes`
```bash
## TS 内网路由模式
$ sudo tailscale up --advertise-exit-node --accept-routes --advertise-routes=172.16.1.0/24 --reset
```
执行命令后,TS 将自动显示登录链接,只需根据链接进行登录操作即可。
至此,TS 服务器已配置完成。
@@ -6,7 +6,7 @@
点击顶部 `添加` 按钮,添加一个 `备份作业` 点击顶部 `添加` 按钮,添加一个 `备份作业`
![添加备份作业](img/p07/vm_new_backup_job.jpeg) ![添加备份作业](img/p08/vm_new_backup_job.jpeg)
### 1.1.常规选项 ### 1.1.常规选项
@@ -28,7 +28,7 @@
**额外说明:** **额外说明:**
1. 计划中的 `*-01,16 03:30` 表示每个月的 1、16 日凌晨 03:30行备份。 1. 计划中的 `*-01,16 03:30` 表示每`1``16` 号的 `03:30`行备份任务
2. `备份作业` 在正确配置收件人邮箱之前,并不能发出邮件。 2. `备份作业` 在正确配置收件人邮箱之前,并不能发出邮件。
@@ -36,13 +36,13 @@
4. 虚拟机列表中,勾选 `备份作业` 需要备份的虚拟机(可多选)。 4. 虚拟机列表中,勾选 `备份作业` 需要备份的虚拟机(可多选)。
![备份作业常规选项](img/p07/vm_job_normal.jpeg) ![备份作业常规选项](img/p08/vm_job_normal.jpeg)
### 1.2.保留选项 ### 1.2.保留选项
该选项将控制备份文件的保留个数,选择保留最近 `3` 份备份文件。 该选项将控制备份文件的保留个数,选择保留最近 `3` 份备份文件。
![备份作业保留选项](img/p07/vm_job_keep.jpeg) ![备份作业保留选项](img/p08/vm_job_keep.jpeg)
### 1.3.日志模板 ### 1.3.日志模板
@@ -52,7 +52,7 @@
点击 `创建` 按钮,`备份作业` 创建完成。 点击 `创建` 按钮,`备份作业` 创建完成。
![备份作业备注选项](img/p07/vm_job_notes.jpeg) ![备份作业备注选项](img/p08/vm_job_notes.jpeg)
## 2.调度模拟器 ## 2.调度模拟器
@@ -60,13 +60,13 @@
鼠标 **单击** 选中一个 `备份作业` ,点击右上角的 `调度模拟器` 鼠标 **单击** 选中一个 `备份作业` ,点击右上角的 `调度模拟器`
![备份作业调度模拟器](img/p07/vm_job_time_test.jpeg) ![备份作业调度模拟器](img/p08/vm_job_time_test.jpeg)
`计划` 处将显示 `备份作业` 的执行时间参数,点击 `模拟` 按钮,在右侧将显示模拟的时间结果。 `计划` 处将显示 `备份作业` 的执行时间参数,点击 `模拟` 按钮,在右侧将显示模拟的时间结果。
确认 `备份作业` 的执行时间周期是否符合预期。 确认 `备份作业` 的执行时间周期是否符合预期。
![备份作业时间模拟](img/p07/vm_job_time.jpeg) ![备份作业时间模拟](img/p08/vm_job_time.jpeg)
至此,虚拟机的自动备份已配置完成。 至此,虚拟机的自动备份已配置完成。
+15 -15
View File
@@ -3,7 +3,7 @@
## 介绍 ## 介绍
PVE 虚拟化平台的安装以及折腾手记。 PVE 虚拟化平台的安装以及折腾手记。
- PVE ISO 版本:8.0-2 (更新时间: 2023-06-22) - PVE ISO 版本:8.1-1 (更新时间: 2023-11-23)
- 演示机: - 演示机:
- CPU:英特尔奔腾 Silver N6005 处理器 - CPU:英特尔奔腾 Silver N6005 处理器
@@ -18,23 +18,23 @@ PVE 虚拟化平台的安装以及折腾手记。
- 网关:`172.16.1.1` - 网关:`172.16.1.1`
- DNS`172.16.1.1` - DNS`172.16.1.1`
- IPv6 网络 - IPv6 网络
- 前缀:`fdac::/64` - 首选 `SLAAC` 自动配置
- IP 地址:`fdac::fe` - IPv6 ULA 网络使用 `fdac::/64` 作为演示
- DNS`fdac::1`
### 系列章节 ### 系列章节
0. [硬件 BIOS 配置](./00.硬件BIOS配置.md) 0. [硬件 BIOS 配置](./00.硬件BIOS配置.md)
1. [PVE 系统安装](./01.PVE系统安装.md) 1. [PVE 系统安装](./01.PVE系统安装.md)
2. [PVE 初始化配置](./02.PVE初始化配置.md) 2. [PVE 初始化配置](./02.PVE初始化配置.md)
3. [PVE 系统调整](./03.PVE系统调整.md) 3. [PVE 系统调整](./03.PVE系统调整.md)
4. [PVE 创建模板虚拟机](./04.PVE创建模板虚拟机.md) 4. [PVE 创建模板虚拟机](./04.PVE创建模板虚拟机.md)
5. [PVE 制作虚拟机模板](./05.PVE制作虚拟机模板.md) 5. [PVE 制作虚拟机模板](./05.PVE制作虚拟机模板.md)
6. [PVE 用模板克隆虚拟机](./06.PVE用模板克隆虚拟机.md) 6. [PVE 制作 DNS 服务器](./06.PVE制作DNS服务器.md)
7. [PVE 自动备份虚拟机](./07.PVE自动备份虚拟机.md) 7. [PVE 制作 TS 服务器](./07.PVE制作TS服务器.md)
8. [PVE 自动备份虚拟机](./08.PVE自动备份虚拟机.md)
### 文章说明 ### 文章说明
1. 本系列文章涉及的部分参数需要手动调整来符合切实使用需求。 1. 本系列文章涉及的部分参数需要手动调整来符合切实使用需求。
2. 随着 PVE 系统的迭代更新,截图中的内容和实际页面显示可能存在差异。 2. 随着 PVE 系统的迭代更新,截图中的内容和实际页面显示可能存在差异。
3. 如需引用,请注明本文出处。 3. 如需引用,请注明本文出处。
Binary file not shown.

Before

Width:  |  Height:  |  Size: 205 KiB

After

Width:  |  Height:  |  Size: 146 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 272 KiB

After

Width:  |  Height:  |  Size: 109 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 283 KiB

After

Width:  |  Height:  |  Size: 115 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 339 KiB

After

Width:  |  Height:  |  Size: 147 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 43 KiB

After

Width:  |  Height:  |  Size: 23 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 279 KiB

After

Width:  |  Height:  |  Size: 114 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 269 KiB

After

Width:  |  Height:  |  Size: 105 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 247 KiB

After

Width:  |  Height:  |  Size: 98 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 216 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 274 KiB

After

Width:  |  Height:  |  Size: 112 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 131 KiB

After

Width:  |  Height:  |  Size: 156 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 204 KiB

After

Width:  |  Height:  |  Size: 51 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 169 KiB

After

Width:  |  Height:  |  Size: 92 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 263 KiB

After

Width:  |  Height:  |  Size: 106 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 413 KiB

After

Width:  |  Height:  |  Size: 401 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 239 KiB

After

Width:  |  Height:  |  Size: 133 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 221 KiB

After

Width:  |  Height:  |  Size: 122 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 74 KiB

After

Width:  |  Height:  |  Size: 73 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 117 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 84 KiB

After

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

After

Width:  |  Height:  |  Size: 78 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 72 KiB

After

Width:  |  Height:  |  Size: 73 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 101 KiB

After

Width:  |  Height:  |  Size: 99 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 108 KiB

After

Width:  |  Height:  |  Size: 107 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 128 KiB

After

Width:  |  Height:  |  Size: 78 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 132 KiB

After

Width:  |  Height:  |  Size: 88 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 173 KiB

After

Width:  |  Height:  |  Size: 124 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 120 KiB

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 72 KiB

After

Width:  |  Height:  |  Size: 47 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 136 KiB

After

Width:  |  Height:  |  Size: 80 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 71 KiB

After

Width:  |  Height:  |  Size: 45 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 78 KiB

After

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

After

Width:  |  Height:  |  Size: 71 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 89 KiB

After

Width:  |  Height:  |  Size: 61 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 77 KiB

After

Width:  |  Height:  |  Size: 49 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 98 KiB

After

Width:  |  Height:  |  Size: 66 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 82 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 92 KiB

After

Width:  |  Height:  |  Size: 56 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 127 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 75 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 84 KiB

After

Width:  |  Height:  |  Size: 55 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 97 KiB

After

Width:  |  Height:  |  Size: 65 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 107 KiB

After

Width:  |  Height:  |  Size: 70 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 66 KiB

After

Width:  |  Height:  |  Size: 55 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 79 KiB

After

Width:  |  Height:  |  Size: 41 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 86 KiB

After

Width:  |  Height:  |  Size: 86 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 88 KiB

After

Width:  |  Height:  |  Size: 88 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 48 KiB

After

Width:  |  Height:  |  Size: 33 KiB

Before

Width:  |  Height:  |  Size: 52 KiB

After

Width:  |  Height:  |  Size: 52 KiB

Before

Width:  |  Height:  |  Size: 136 KiB

After

Width:  |  Height:  |  Size: 136 KiB

Before

Width:  |  Height:  |  Size: 65 KiB

After

Width:  |  Height:  |  Size: 65 KiB

Before

Width:  |  Height:  |  Size: 99 KiB

After

Width:  |  Height:  |  Size: 99 KiB

Before

Width:  |  Height:  |  Size: 114 KiB

After

Width:  |  Height:  |  Size: 114 KiB

Before

Width:  |  Height:  |  Size: 92 KiB

After

Width:  |  Height:  |  Size: 92 KiB

@@ -1,177 +1,177 @@
// Unattended-Upgrade::Origins-Pattern controls which packages are // Unattended-Upgrade::Origins-Pattern controls which packages are
// upgraded. // upgraded.
// //
// Lines below have the format "keyword=value,...". A // Lines below have the format "keyword=value,...". A
// package will be upgraded only if the values in its metadata match // package will be upgraded only if the values in its metadata match
// all the supplied keywords in a line. (In other words, omitted // all the supplied keywords in a line. (In other words, omitted
// keywords are wild cards.) The keywords originate from the Release // keywords are wild cards.) The keywords originate from the Release
// file, but several aliases are accepted. The accepted keywords are: // file, but several aliases are accepted. The accepted keywords are:
// a,archive,suite (eg, "stable") // a,archive,suite (eg, "stable")
// c,component (eg, "main", "contrib", "non-free") // c,component (eg, "main", "contrib", "non-free")
// l,label (eg, "Debian", "Debian-Security") // l,label (eg, "Debian", "Debian-Security")
// o,origin (eg, "Debian", "Unofficial Multimedia Packages") // o,origin (eg, "Debian", "Unofficial Multimedia Packages")
// n,codename (eg, "jessie", "jessie-updates") // n,codename (eg, "jessie", "jessie-updates")
// site (eg, "http.debian.net") // site (eg, "http.debian.net")
// The available values on the system are printed by the command // The available values on the system are printed by the command
// "apt-cache policy", and can be debugged by running // "apt-cache policy", and can be debugged by running
// "unattended-upgrades -d" and looking at the log file. // "unattended-upgrades -d" and looking at the log file.
// //
// Within lines unattended-upgrades allows 2 macros whose values are // Within lines unattended-upgrades allows 2 macros whose values are
// derived from /etc/debian_version: // derived from /etc/debian_version:
// ${distro_id} Installed origin. // ${distro_id} Installed origin.
// ${distro_codename} Installed codename (eg, "buster") // ${distro_codename} Installed codename (eg, "buster")
Unattended-Upgrade::Origins-Pattern { Unattended-Upgrade::Origins-Pattern {
// Codename based matching: // Codename based matching:
// This will follow the migration of a release through different // This will follow the migration of a release through different
// archives (e.g. from testing to stable and later oldstable). // archives (e.g. from testing to stable and later oldstable).
// Software will be the latest available for the named release, // Software will be the latest available for the named release,
// but the Debian release itself will not be automatically upgraded. // but the Debian release itself will not be automatically upgraded.
"origin=Debian,codename=${distro_codename}-updates"; "origin=Debian,codename=${distro_codename}-updates";
// "origin=Debian,codename=${distro_codename}-proposed-updates"; // "origin=Debian,codename=${distro_codename}-proposed-updates";
"origin=Debian,codename=${distro_codename},label=Debian"; "origin=Debian,codename=${distro_codename},label=Debian";
"origin=Debian,codename=${distro_codename},label=Debian-Security"; "origin=Debian,codename=${distro_codename},label=Debian-Security";
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security"; "origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
// Archive or Suite based matching: // Archive or Suite based matching:
// Note that this will silently match a different release after // Note that this will silently match a different release after
// migration to the specified archive (e.g. testing becomes the // migration to the specified archive (e.g. testing becomes the
// new stable). // new stable).
// "o=Debian,a=stable"; // "o=Debian,a=stable";
// "o=Debian,a=stable-updates"; // "o=Debian,a=stable-updates";
// "o=Debian,a=proposed-updates"; // "o=Debian,a=proposed-updates";
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports"; // "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
}; };
// Python regular expressions, matching packages to exclude from upgrading // Python regular expressions, matching packages to exclude from upgrading
Unattended-Upgrade::Package-Blacklist { Unattended-Upgrade::Package-Blacklist {
// The following matches all packages starting with linux- // The following matches all packages starting with linux-
// "linux-"; // "linux-";
// Use $ to explicitely define the end of a package name. Without // Use $ to explicitely define the end of a package name. Without
// the $, "libc6" would match all of them. // the $, "libc6" would match all of them.
// "libc6$"; // "libc6$";
// "libc6-dev$"; // "libc6-dev$";
// "libc6-i686$"; // "libc6-i686$";
// Special characters need escaping // Special characters need escaping
// "libstdc\+\+6$"; // "libstdc\+\+6$";
// The following matches packages like xen-system-amd64, xen-utils-4.1, // The following matches packages like xen-system-amd64, xen-utils-4.1,
// xenstore-utils and libxenstore3.0 // xenstore-utils and libxenstore3.0
// "(lib)?xen(store)?"; // "(lib)?xen(store)?";
// For more information about Python regular expressions, see // For more information about Python regular expressions, see
// https://docs.python.org/3/howto/regex.html // https://docs.python.org/3/howto/regex.html
}; };
// This option allows you to control if on a unclean dpkg exit // This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run // unattended-upgrades will automatically run
// dpkg --force-confold --configure -a // dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed // The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "true"; //Unattended-Upgrade::AutoFixInterruptedDpkg "true";
// Split the upgrade into the smallest possible chunks so that // Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGTERM. This makes the upgrade // they can be interrupted with SIGTERM. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade // a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay) // is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true"; //Unattended-Upgrade::MinimalSteps "true";
// Install all updates when the machine is shutting down // Install all updates when the machine is shutting down
// instead of doing it in the background while the machine is running. // instead of doing it in the background while the machine is running.
// This will (obviously) make shutdown slower. // This will (obviously) make shutdown slower.
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s. // Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
// This allows more time for unattended-upgrades to shut down gracefully // This allows more time for unattended-upgrades to shut down gracefully
// or even install a few packages in InstallOnShutdown mode, but is still a // or even install a few packages in InstallOnShutdown mode, but is still a
// big step back from the 30 minutes allowed for InstallOnShutdown previously. // big step back from the 30 minutes allowed for InstallOnShutdown previously.
// Users enabling InstallOnShutdown mode are advised to increase // Users enabling InstallOnShutdown mode are advised to increase
// InhibitDelayMaxSec even further, possibly to 30 minutes. // InhibitDelayMaxSec even further, possibly to 30 minutes.
//Unattended-Upgrade::InstallOnShutdown "false"; //Unattended-Upgrade::InstallOnShutdown "false";
// Send email to this address for problems or packages upgrades // Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you // If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides // have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com" // 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail ""; //Unattended-Upgrade::Mail "";
// Set this value to one of: // Set this value to one of:
// "always", "only-on-error" or "on-change" // "always", "only-on-error" or "on-change"
// If this is not set, then any legacy MailOnlyOnError (boolean) value // If this is not set, then any legacy MailOnlyOnError (boolean) value
// is used to chose between "only-on-error" and "on-change" // is used to chose between "only-on-error" and "on-change"
//Unattended-Upgrade::MailReport "on-change"; //Unattended-Upgrade::MailReport "on-change";
// Remove unused automatically installed kernel-related packages // Remove unused automatically installed kernel-related packages
// (kernel images, kernel headers and kernel version locked tools). // (kernel images, kernel headers and kernel version locked tools).
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true"; //Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Do automatic removal of newly unused dependencies after the upgrade // Do automatic removal of newly unused dependencies after the upgrade
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true"; //Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
// Do automatic removal of unused packages after the upgrade // Do automatic removal of unused packages after the upgrade
// (equivalent to apt-get autoremove) // (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false"; //Unattended-Upgrade::Remove-Unused-Dependencies "false";
// Automatically reboot *WITHOUT CONFIRMATION* if // Automatically reboot *WITHOUT CONFIRMATION* if
// the file /var/run/reboot-required is found after the upgrade // the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false"; //Unattended-Upgrade::Automatic-Reboot "false";
// Automatically reboot even if there are users currently logged in // Automatically reboot even if there are users currently logged in
// when Unattended-Upgrade::Automatic-Reboot is set to true // when Unattended-Upgrade::Automatic-Reboot is set to true
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true"; //Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
// If automatic reboot is enabled and needed, reboot at the specific // If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately // time instead of immediately
// Default: "now" // Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00"; //Unattended-Upgrade::Automatic-Reboot-Time "02:00";
// Use apt bandwidth limit feature, this example limits the download // Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec // speed to 70kb/sec
//Acquire::http::Dl-Limit "70"; //Acquire::http::Dl-Limit "70";
// Enable logging to syslog. Default is False // Enable logging to syslog. Default is False
// Unattended-Upgrade::SyslogEnable "false"; // Unattended-Upgrade::SyslogEnable "false";
// Specify syslog facility. Default is daemon // Specify syslog facility. Default is daemon
// Unattended-Upgrade::SyslogFacility "daemon"; // Unattended-Upgrade::SyslogFacility "daemon";
// Download and install upgrades only on AC power // Download and install upgrades only on AC power
// (i.e. skip or gracefully stop updates on battery) // (i.e. skip or gracefully stop updates on battery)
// Unattended-Upgrade::OnlyOnACPower "true"; // Unattended-Upgrade::OnlyOnACPower "true";
// Download and install upgrades only on non-metered connection // Download and install upgrades only on non-metered connection
// (i.e. skip or gracefully stop updates on a metered connection) // (i.e. skip or gracefully stop updates on a metered connection)
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true"; // Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
// Verbose logging // Verbose logging
// Unattended-Upgrade::Verbose "false"; // Unattended-Upgrade::Verbose "false";
// Print debugging information both in unattended-upgrades and // Print debugging information both in unattended-upgrades and
// in unattended-upgrade-shutdown // in unattended-upgrade-shutdown
// Unattended-Upgrade::Debug "false"; // Unattended-Upgrade::Debug "false";
// Allow package downgrade if Pin-Priority exceeds 1000 // Allow package downgrade if Pin-Priority exceeds 1000
// Unattended-Upgrade::Allow-downgrade "false"; // Unattended-Upgrade::Allow-downgrade "false";
// When APT fails to mark a package to be upgraded or installed try adjusting // When APT fails to mark a package to be upgraded or installed try adjusting
// candidates of related packages to help APT's resolver in finding a solution // candidates of related packages to help APT's resolver in finding a solution
// where the package can be upgraded or installed. // where the package can be upgraded or installed.
// This is a workaround until APT's resolver is fixed to always find a // This is a workaround until APT's resolver is fixed to always find a
// solution if it exists. (See Debian bug #711128.) // solution if it exists. (See Debian bug #711128.)
// The fallback is enabled by default, except on Debian's sid release because // The fallback is enabled by default, except on Debian's sid release because
// uninstallable packages are frequent there. // uninstallable packages are frequent there.
// Disabling the fallback speeds up unattended-upgrades when there are // Disabling the fallback speeds up unattended-upgrades when there are
// uninstallable packages at the expense of rarely keeping back packages which // uninstallable packages at the expense of rarely keeping back packages which
// could be upgraded or installed. // could be upgraded or installed.
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true"; // Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
Unattended-Upgrade::AutoFixInterruptedDpkg "true"; Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true"; Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true"; Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true"; Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00"; Unattended-Upgrade::Automatic-Reboot-Time "03:00";
@@ -1,25 +1,26 @@
# This configuration file is customized by fox # This configuration file is customized by fox,
# Optimize system parameters # Optimize sysctl parameters for local DNS server.
kernel.panic = 20 kernel.panic = 20
kernel.panic_on_oops = 1 kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel net.core.default_qdisc = fq
net.ipv4.tcp_congestion_control = bbr net.ipv4.tcp_congestion_control = bbr
# Other adjustable system parameters # Other adjustable system parameters
net.ipv4.conf.all.log_martians = 1 net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.ipv4.igmp_max_memberships = 100
net.ipv4.conf.all.log_martians = 1
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30 net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_max_orphans = 4096 net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_max_tw_buckets = 4096 net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0 net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
+49
View File
@@ -0,0 +1,49 @@
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local DNS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=1024
max-cache-ttl=7200
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
localise-queries
local-service
no-hosts
no-negcache
no-resolv
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/ipv4only.arpa/
server=/resolver.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/fox.home.arpa/172.16.1.1
server=127.0.0.1#6053
server=::1#6053
+18
View File
@@ -0,0 +1,18 @@
## 下载加速规则安装脚本
$ sudo curl -LR -o /opt/dnsmasq_plugin.sh https://gitee.com/felixonmars/dnsmasq-china-list/raw/master/install.sh
## 设置脚本可执行权限
$ sudo chmod +x /opt/dnsmasq_plugin.sh
## 设置脚本文件防篡改
$ sudo chattr +i /opt/dnsmasq_plugin.sh
## 执行脚本
$ sudo bash /opt/dnsmasq_plugin.sh
## 设置 crontab
25 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/dnsmasq.d/anti-ad.dnsmasq.conf https://anti-ad.net/anti-ad-for-dnsmasq.conf
35 9 * * * /usr/bin/bash /opt/dnsmasq_plugin.sh
@@ -12,23 +12,30 @@
# server 2402:4e00:: # server 2402:4e00::
# server 2400:3200::1 # server 2400:3200::1
conf-file /etc/smartdns/anti-ad-smartdns.conf conf-file /etc/smartdns.d/adrules.smartdns.conf
conf-file /etc/smartdns.d/dns-group.china.smartdns.conf
conf-file /etc/smartdns.d/apple.china.smartdns.conf
conf-file /etc/smartdns.d/google.china.smartdns.conf
conf-file /etc/smartdns.d/accelerated-domains.china.smartdns.conf
conf-file /etc/smartdns.d/bogus-nxdomain.china.smartdns.conf
cache-file /tmp/smartdns.cache cache-file /tmp/smartdns.cache
bind [::]:53 log-level notice
bind-tcp [::]:53
bind [::]:6053@lo
bind-tcp [::]:6053@lo
serve-expired yes serve-expired yes
serve-expired-ttl 86400 serve-expired-ttl 64800
serve-expired-reply-ttl 3 serve-expired-reply-ttl 3
prefetch-domain yes prefetch-domain yes
serve-expired-prefetch-time 43200 serve-expired-prefetch-time 21600
speed-check-mode ping,tcp:80,tcp:443
force-qtype-SOA 65 force-qtype-SOA 65
max-query-limit 1024
log-level notice edns-client-subnet 202.103.24.68
server-tcp 119.29.29.29 -group dnspod -exclude-default-group server-tcp 119.29.29.29 -group dnspod -exclude-default-group
server-tcp 2402:4e00:: -group dnspod -exclude-default-group server-tcp 2402:4e00:: -group dnspod -exclude-default-group
@@ -40,9 +47,8 @@ server-tcp 2400:3200::1 -group alidns -exclude-default-group
nameserver /dns.alidns.com/alidns nameserver /dns.alidns.com/alidns
server 172.16.1.1 -group intranet -exclude-default-group server 172.16.1.1 -group intranet -exclude-default-group
server fdac::1 -group intranet -exclude-default-group nameserver /fox.home.arpa/intranet
nameserver /fox.local/intranet domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache
domain-rules /fox.local/ -speed-check-mode none -no-cache
server-tls dot.pub server-tls dot.pub
server-tls dns.alidns.com server-tls dns.alidns.com
+14
View File
@@ -0,0 +1,14 @@
# This configuration file is customized by fox,
# Optimize SmartDNS crontab for local DNS server.
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
30 9 * * * /usr/bin/systemctl restart smartdns.service
## Or when the smartdns plugin is installed
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
30 9 * * * /usr/bin/bash /opt/smartdns_plugin.sh
@@ -0,0 +1,72 @@
#!/bin/bash
set -e
WORKDIR="$(mktemp -d)"
CONFDIR="/etc/smartdns.d"
SERVERS=(223.5.5.5 180.184.1.1 119.29.29.29 114.114.114.114)
GROUP=(flash)
# Others: 223.6.6.6 119.28.28.28
# Not using best possible CDN pop: 1.2.4.8 210.2.4.8
# Broken?: 180.76.76.76
CONF_WITH_SERVERS=(accelerated-domains.china google.china apple.china)
CONF_WITH_GROUP=(dns-group.china)
CONF_SIMPLE=(bogus-nxdomain.china)
echo "Checking whether the configuration folder exists..."
if [ ! -d "$CONFDIR" ]; then
mkdir -p "$CONFDIR"
fi
echo "Downloading latest configurations..."
git clone --depth=1 https://gitee.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://pagure.io/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://github.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://bitbucket.org/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://gitlab.com/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://e.coding.net/felixonmars/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 https://codehub.devcloud.huaweicloud.com/dnsmasq-china-list00001/dnsmasq-china-list.git "$WORKDIR"
#git clone --depth=1 http://repo.or.cz/dnsmasq-china-list.git "$WORKDIR"
echo "Removing old configurations..."
for _conf in "${CONF_WITH_SERVERS[@]}" "${CONF_WITH_GROUP[@]}" "${CONF_SIMPLE[@]}"; do
rm -f "$CONFDIR/$_conf"*.conf
done
echo "Installing new configurations..."
for _conf in "${CONF_WITH_SERVERS[@]}" "${CONF_WITH_GROUP[@]}" "${CONF_SIMPLE[@]}"; do
if [[ "${CONF_WITH_SERVERS[@]}" =~ $_conf ]]; then
sed -En 's|^server=/([^/]*)/114.114.114.114$|\1|p' "$WORKDIR/$_conf.conf" | grep -Ev '^#' > "$WORKDIR/$_conf.step1.raw"
sed -En "s/(.*)/nameserver \\/\\1\\/${GROUP[@]}/p" "$WORKDIR/$_conf.step1.raw" > "$WORKDIR/$_conf.step2.raw"
cp "$WORKDIR/$_conf.step2.raw" "$CONFDIR/$_conf.smartdns.conf"
fi
if [[ "${CONF_WITH_GROUP[@]}" =~ $_conf ]]; then
for _server in "${SERVERS[@]}"; do
echo "server $_server -group ${GROUP[@]} -exclude-default-group" >> "$WORKDIR/$_conf.raw"
done
cp "$WORKDIR/$_conf.raw" "$CONFDIR/$_conf.smartdns.conf"
fi
if [[ "${CONF_SIMPLE[@]}" =~ $_conf ]]; then
sed -e "s|=| |" "$WORKDIR/$_conf.conf" > "$WORKDIR/$_conf.raw"
cp "$WORKDIR/$_conf.raw" "$CONFDIR/$_conf.smartdns.conf"
fi
done
echo "Restarting smartdns service..."
if hash systemctl 2>/dev/null; then
systemctl restart smartdns
elif hash service 2>/dev/null; then
service smartdns restart
elif hash rc-service 2>/dev/null; then
rc-service smartdns restart
elif hash busybox 2>/dev/null && [[ -d "/etc/init.d" ]]; then
/etc/init.d/smartdns restart
else
echo "Now please restart smartdns since I don't know how to do it."
fi
echo "Cleaning up..."
rm -r "$WORKDIR"
@@ -1,10 +1,12 @@
Types: deb Types: deb
URIs: https://mirrors.ustc.edu.cn/debian URIs: https://mirrors.ustc.edu.cn/debian
Suites: bookworm bookworm-updates bookworm-backports Suites: bookworm bookworm-updates
Components: main contrib non-free non-free-firmware Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb Types: deb
URIs: https://mirrors.ustc.edu.cn/debian-security URIs: https://mirrors.ustc.edu.cn/debian-security
Suites: bookworm-security Suites: bookworm-security
Components: main contrib non-free non-free-firmware Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
@@ -0,0 +1,5 @@
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "7";
APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1";
@@ -0,0 +1,178 @@
// Unattended-Upgrade::Origins-Pattern controls which packages are
// upgraded.
//
// Lines below have the format "keyword=value,...". A
// package will be upgraded only if the values in its metadata match
// all the supplied keywords in a line. (In other words, omitted
// keywords are wild cards.) The keywords originate from the Release
// file, but several aliases are accepted. The accepted keywords are:
// a,archive,suite (eg, "stable")
// c,component (eg, "main", "contrib", "non-free")
// l,label (eg, "Debian", "Debian-Security")
// o,origin (eg, "Debian", "Unofficial Multimedia Packages")
// n,codename (eg, "jessie", "jessie-updates")
// site (eg, "http.debian.net")
// The available values on the system are printed by the command
// "apt-cache policy", and can be debugged by running
// "unattended-upgrades -d" and looking at the log file.
//
// Within lines unattended-upgrades allows 2 macros whose values are
// derived from /etc/debian_version:
// ${distro_id} Installed origin.
// ${distro_codename} Installed codename (eg, "buster")
Unattended-Upgrade::Origins-Pattern {
// Codename based matching:
// This will follow the migration of a release through different
// archives (e.g. from testing to stable and later oldstable).
// Software will be the latest available for the named release,
// but the Debian release itself will not be automatically upgraded.
"origin=Debian,codename=${distro_codename}-updates";
// "origin=Debian,codename=${distro_codename}-proposed-updates";
"origin=Debian,codename=${distro_codename},label=Debian";
"origin=Debian,codename=${distro_codename},label=Debian-Security";
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
"origin=Tailscale,codename=${distro_codename},label=Tailscale";
// Archive or Suite based matching:
// Note that this will silently match a different release after
// migration to the specified archive (e.g. testing becomes the
// new stable).
// "o=Debian,a=stable";
// "o=Debian,a=stable-updates";
// "o=Debian,a=proposed-updates";
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
};
// Python regular expressions, matching packages to exclude from upgrading
Unattended-Upgrade::Package-Blacklist {
// The following matches all packages starting with linux-
// "linux-";
// Use $ to explicitely define the end of a package name. Without
// the $, "libc6" would match all of them.
// "libc6$";
// "libc6-dev$";
// "libc6-i686$";
// Special characters need escaping
// "libstdc\+\+6$";
// The following matches packages like xen-system-amd64, xen-utils-4.1,
// xenstore-utils and libxenstore3.0
// "(lib)?xen(store)?";
// For more information about Python regular expressions, see
// https://docs.python.org/3/howto/regex.html
};
// This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run
// dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "true";
// Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGTERM. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true";
// Install all updates when the machine is shutting down
// instead of doing it in the background while the machine is running.
// This will (obviously) make shutdown slower.
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
// This allows more time for unattended-upgrades to shut down gracefully
// or even install a few packages in InstallOnShutdown mode, but is still a
// big step back from the 30 minutes allowed for InstallOnShutdown previously.
// Users enabling InstallOnShutdown mode are advised to increase
// InhibitDelayMaxSec even further, possibly to 30 minutes.
//Unattended-Upgrade::InstallOnShutdown "false";
// Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail "";
// Set this value to one of:
// "always", "only-on-error" or "on-change"
// If this is not set, then any legacy MailOnlyOnError (boolean) value
// is used to chose between "only-on-error" and "on-change"
//Unattended-Upgrade::MailReport "on-change";
// Remove unused automatically installed kernel-related packages
// (kernel images, kernel headers and kernel version locked tools).
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Do automatic removal of newly unused dependencies after the upgrade
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
// Do automatic removal of unused packages after the upgrade
// (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false";
// Automatically reboot *WITHOUT CONFIRMATION* if
// the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false";
// Automatically reboot even if there are users currently logged in
// when Unattended-Upgrade::Automatic-Reboot is set to true
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
// If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately
// Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00";
// Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec
//Acquire::http::Dl-Limit "70";
// Enable logging to syslog. Default is False
// Unattended-Upgrade::SyslogEnable "false";
// Specify syslog facility. Default is daemon
// Unattended-Upgrade::SyslogFacility "daemon";
// Download and install upgrades only on AC power
// (i.e. skip or gracefully stop updates on battery)
// Unattended-Upgrade::OnlyOnACPower "true";
// Download and install upgrades only on non-metered connection
// (i.e. skip or gracefully stop updates on a metered connection)
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
// Verbose logging
// Unattended-Upgrade::Verbose "false";
// Print debugging information both in unattended-upgrades and
// in unattended-upgrade-shutdown
// Unattended-Upgrade::Debug "false";
// Allow package downgrade if Pin-Priority exceeds 1000
// Unattended-Upgrade::Allow-downgrade "false";
// When APT fails to mark a package to be upgraded or installed try adjusting
// candidates of related packages to help APT's resolver in finding a solution
// where the package can be upgraded or installed.
// This is a workaround until APT's resolver is fixed to always find a
// solution if it exists. (See Debian bug #711128.)
// The fallback is enabled by default, except on Debian's sid release because
// uninstallable packages are frequent there.
// Disabling the fallback speeds up unattended-upgrades when there are
// uninstallable packages at the expense of rarely keeping back packages which
// could be upgraded or installed.
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
+64
View File
@@ -0,0 +1,64 @@
# This configuration file is customized by fox,
# Optimize sysctl parameters for local TS server.
kernel.panic = 20
kernel.panic_on_oops = 1
net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr
net.ipv4.ip_forward = 1
net.ipv6.conf.all.forwarding = 1
net.ipv6.conf.default.forwarding = 1
# Other adjustable system parameters
net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.all.arp_ignore = 1
net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1
net.ipv4.igmp_max_memberships = 256
net.ipv4.route.error_burst = 500
net.ipv4.route.error_cost = 100
net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1
net.ipv6.conf.all.accept_ra = 0
net.ipv6.conf.default.accept_ra = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0
net.ipv6.conf.all.accept_source_route = 0
net.ipv6.conf.default.accept_source_route = 0
net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0
net.netfilter.nf_conntrack_acct = 1
net.netfilter.nf_conntrack_checksum = 0
net.netfilter.nf_conntrack_tcp_timeout_established = 7440
+49
View File
@@ -0,0 +1,49 @@
# This configuration file is customized by fox,
# Optimize dnsmasq parameters for local TS server.
# Main Config
conf-dir=/etc/dnsmasq.d/,*.conf
conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log
log-async=20
cache-size=1024
max-cache-ttl=7200
edns-packet-max=1232
rebind-domain-ok=/fox.home.arpa/
bind-dynamic
bogus-priv
domain-needed
localise-queries
local-service
no-hosts
no-negcache
no-round-robin
rebind-localhost-ok
stop-dns-rebind
# DNS Filter
server=/alt/
server=/home.arpa/
server=/ipv4only.arpa/
server=/resolver.arpa/
server=/example/
server=/bind/
server=/invalid/
server=/local/
server=/localhost/
server=/onion/
server=/test/
# DNS Server
server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1
server=172.16.1.1
+177
View File
@@ -0,0 +1,177 @@
#!/usr/sbin/nft -f
# This configuration file is customized by fox,
# Optimize nftables rules for local TS server.
table inet router
flush table inet router
table inet router {
#
# Flowtable
#
flowtable ft {
hook ingress priority filter;
devices = { eth0 };
counter;
}
#
# Filter rules
#
chain input {
type filter hook input priority filter; policy drop;
iif "lo" accept comment "defconf: accept traffic from loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle inbound flows"
tcp flags syn / fin,syn,rst,ack counter jump syn_flood comment "defconf: rate limit TCP-SYN packets"
iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic"
iifname "tailscale0" counter jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related flow add @ft comment "defconf: track forwarded flows"
ct state vmap { established : accept, related : accept } comment "defconf: handle forwarded flows"
iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic"
iifname "tailscale0" counter jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic"
}
chain output {
type filter hook output priority filter; policy accept;
oif "lo" accept comment "defconf: accept traffic towards loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle outbound flows"
oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic"
oifname "tailscale0" counter jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic"
}
chain prerouting {
type filter hook prerouting priority filter; policy accept;
iifname "eth0" jump helper_lan comment "defconf: handle LAN IPv4 / IPv6 helper assignment"
iifname "tailscale0" jump helper_tailscale comment "tsconf: handle TS IPv4 / IPv6 helper assignment"
}
chain syn_flood {
limit rate 200/second burst 100 packets return comment "defconf: accept SYN packets below rate-limit"
counter drop comment "defconf: drop excess packets"
}
chain input_lan {
ct status dnat counter accept comment "lanconf: accept port redirect"
jump accept_from_lan
}
chain forward_lan {
jump accept_to_tailscale comment "tsconf: accept LAN to TS forward"
ct status dnat counter accept comment "lanconf: accept port forward"
jump accept_to_lan
}
chain output_lan {
jump accept_to_lan
}
chain helper_lan {
}
chain accept_from_lan {
iifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
}
chain accept_to_lan {
meta nfproto ipv4 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv4 leakage"
meta nfproto ipv6 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv6 leakage"
oifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
}
chain input_tailscale {
jump accept_from_tailscale
}
chain forward_tailscale {
counter jump accept_to_lan comment "tsconf: accept TS to LAN forward"
counter jump accept_to_tailscale
}
chain output_tailscale {
counter jump accept_to_tailscale
}
chain helper_tailscale {
}
chain accept_from_tailscale {
iifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
}
chain accept_to_tailscale {
oifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic"
}
#
# NAT rules
#
chain dstnat {
type nat hook prerouting priority dstnat; policy accept;
iifname "eth0" meta l4proto { tcp, udp } th dport domain jump dstnat_lan comment "defconf: handle LAN IPv4 / IPv6 dstnat traffic"
}
chain srcnat {
type nat hook postrouting priority srcnat; policy accept;
oifname "eth0" jump srcnat_lan comment "defconf: handle LAN IPv4 / IPv6 srcnat traffic"
}
chain dstnat_lan {
meta nfproto ipv4 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv4 DNS redirect"
meta nfproto ipv6 meta l4proto { tcp, udp } th dport domain counter redirect to domain comment "lanconf: LAN IPv6 DNS redirect"
}
chain srcnat_lan {
meta nfproto ipv4 counter masquerade comment "defconf: masquerade IPv4 LAN traffic"
meta nfproto ipv6 counter masquerade comment "defconf: masquerade IPv6 LAN traffic"
}
#
# Raw rules (notrack)
#
chain raw_prerouting {
type filter hook prerouting priority raw; policy accept;
}
chain raw_output {
type filter hook output priority raw; policy accept;
}
#
# Mangle rules
#
chain mangle_prerouting {
type filter hook prerouting priority mangle; policy accept;
}
chain mangle_postrouting {
type filter hook postrouting priority mangle; policy accept;
}
chain mangle_input {
type filter hook input priority mangle; policy accept;
}
chain mangle_output {
type route hook output priority mangle; policy accept;
}
chain mangle_forward {
type filter hook forward priority mangle; policy accept;
}
}
+5
View File
@@ -0,0 +1,5 @@
# This configuration file is customized by fox,
# Optimize netfilter related modules at system boot.
nf_conntrack
@@ -1,5 +1,5 @@
APT::Periodic::Update-Package-Lists "1"; APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "5"; APT::Periodic::Unattended-Upgrade "5";
APT::Periodic::AutocleanInterval "1"; APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1"; APT::Periodic::CleanInterval "1";
@@ -1,179 +1,179 @@
// Unattended-Upgrade::Origins-Pattern controls which packages are // Unattended-Upgrade::Origins-Pattern controls which packages are
// upgraded. // upgraded.
// //
// Lines below have the format "keyword=value,...". A // Lines below have the format "keyword=value,...". A
// package will be upgraded only if the values in its metadata match // package will be upgraded only if the values in its metadata match
// all the supplied keywords in a line. (In other words, omitted // all the supplied keywords in a line. (In other words, omitted
// keywords are wild cards.) The keywords originate from the Release // keywords are wild cards.) The keywords originate from the Release
// file, but several aliases are accepted. The accepted keywords are: // file, but several aliases are accepted. The accepted keywords are:
// a,archive,suite (eg, "stable") // a,archive,suite (eg, "stable")
// c,component (eg, "main", "contrib", "non-free") // c,component (eg, "main", "contrib", "non-free")
// l,label (eg, "Debian", "Debian-Security") // l,label (eg, "Debian", "Debian-Security")
// o,origin (eg, "Debian", "Unofficial Multimedia Packages") // o,origin (eg, "Debian", "Unofficial Multimedia Packages")
// n,codename (eg, "jessie", "jessie-updates") // n,codename (eg, "jessie", "jessie-updates")
// site (eg, "http.debian.net") // site (eg, "http.debian.net")
// The available values on the system are printed by the command // The available values on the system are printed by the command
// "apt-cache policy", and can be debugged by running // "apt-cache policy", and can be debugged by running
// "unattended-upgrades -d" and looking at the log file. // "unattended-upgrades -d" and looking at the log file.
// //
// Within lines unattended-upgrades allows 2 macros whose values are // Within lines unattended-upgrades allows 2 macros whose values are
// derived from /etc/debian_version: // derived from /etc/debian_version:
// ${distro_id} Installed origin. // ${distro_id} Installed origin.
// ${distro_codename} Installed codename (eg, "buster") // ${distro_codename} Installed codename (eg, "buster")
Unattended-Upgrade::Origins-Pattern { Unattended-Upgrade::Origins-Pattern {
// Codename based matching: // Codename based matching:
// This will follow the migration of a release through different // This will follow the migration of a release through different
// archives (e.g. from testing to stable and later oldstable). // archives (e.g. from testing to stable and later oldstable).
// Software will be the latest available for the named release, // Software will be the latest available for the named release,
// but the Debian release itself will not be automatically upgraded. // but the Debian release itself will not be automatically upgraded.
"origin=Debian,codename=${distro_codename}-updates"; "origin=Debian,codename=${distro_codename}-updates";
// "origin=Debian,codename=${distro_codename}-proposed-updates"; // "origin=Debian,codename=${distro_codename}-proposed-updates";
"origin=Debian,codename=${distro_codename},label=Debian"; "origin=Debian,codename=${distro_codename},label=Debian";
"origin=Debian,codename=${distro_codename},label=Debian-Security"; "origin=Debian,codename=${distro_codename},label=Debian-Security";
"origin=Debian,codename=${distro_codename}-security,label=Debian-Security"; "origin=Debian,codename=${distro_codename}-security,label=Debian-Security";
"origin=Proxmox,codename=${distro_codename},label=Proxmox Debian Repository"; "origin=Proxmox,codename=${distro_codename},label=Proxmox Debian Repository";
// "origin=Proxmox,codename=${distro_codename},label=Proxmox Ceph Debian Repository"; // "origin=Proxmox,codename=${distro_codename},label=Proxmox Ceph Debian Repository";
// Archive or Suite based matching: // Archive or Suite based matching:
// Note that this will silently match a different release after // Note that this will silently match a different release after
// migration to the specified archive (e.g. testing becomes the // migration to the specified archive (e.g. testing becomes the
// new stable). // new stable).
// "o=Debian,a=stable"; // "o=Debian,a=stable";
// "o=Debian,a=stable-updates"; // "o=Debian,a=stable-updates";
// "o=Debian,a=proposed-updates"; // "o=Debian,a=proposed-updates";
// "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports"; // "o=Debian Backports,a=${distro_codename}-backports,l=Debian Backports";
}; };
// Python regular expressions, matching packages to exclude from upgrading // Python regular expressions, matching packages to exclude from upgrading
Unattended-Upgrade::Package-Blacklist { Unattended-Upgrade::Package-Blacklist {
// The following matches all packages starting with linux- // The following matches all packages starting with linux-
// "linux-"; // "linux-";
// Use $ to explicitely define the end of a package name. Without // Use $ to explicitely define the end of a package name. Without
// the $, "libc6" would match all of them. // the $, "libc6" would match all of them.
// "libc6$"; // "libc6$";
// "libc6-dev$"; // "libc6-dev$";
// "libc6-i686$"; // "libc6-i686$";
// Special characters need escaping // Special characters need escaping
// "libstdc\+\+6$"; // "libstdc\+\+6$";
// The following matches packages like xen-system-amd64, xen-utils-4.1, // The following matches packages like xen-system-amd64, xen-utils-4.1,
// xenstore-utils and libxenstore3.0 // xenstore-utils and libxenstore3.0
// "(lib)?xen(store)?"; // "(lib)?xen(store)?";
// For more information about Python regular expressions, see // For more information about Python regular expressions, see
// https://docs.python.org/3/howto/regex.html // https://docs.python.org/3/howto/regex.html
}; };
// This option allows you to control if on a unclean dpkg exit // This option allows you to control if on a unclean dpkg exit
// unattended-upgrades will automatically run // unattended-upgrades will automatically run
// dpkg --force-confold --configure -a // dpkg --force-confold --configure -a
// The default is true, to ensure updates keep getting installed // The default is true, to ensure updates keep getting installed
//Unattended-Upgrade::AutoFixInterruptedDpkg "true"; //Unattended-Upgrade::AutoFixInterruptedDpkg "true";
// Split the upgrade into the smallest possible chunks so that // Split the upgrade into the smallest possible chunks so that
// they can be interrupted with SIGTERM. This makes the upgrade // they can be interrupted with SIGTERM. This makes the upgrade
// a bit slower but it has the benefit that shutdown while a upgrade // a bit slower but it has the benefit that shutdown while a upgrade
// is running is possible (with a small delay) // is running is possible (with a small delay)
//Unattended-Upgrade::MinimalSteps "true"; //Unattended-Upgrade::MinimalSteps "true";
// Install all updates when the machine is shutting down // Install all updates when the machine is shutting down
// instead of doing it in the background while the machine is running. // instead of doing it in the background while the machine is running.
// This will (obviously) make shutdown slower. // This will (obviously) make shutdown slower.
// Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s. // Unattended-upgrades increases logind's InhibitDelayMaxSec to 30s.
// This allows more time for unattended-upgrades to shut down gracefully // This allows more time for unattended-upgrades to shut down gracefully
// or even install a few packages in InstallOnShutdown mode, but is still a // or even install a few packages in InstallOnShutdown mode, but is still a
// big step back from the 30 minutes allowed for InstallOnShutdown previously. // big step back from the 30 minutes allowed for InstallOnShutdown previously.
// Users enabling InstallOnShutdown mode are advised to increase // Users enabling InstallOnShutdown mode are advised to increase
// InhibitDelayMaxSec even further, possibly to 30 minutes. // InhibitDelayMaxSec even further, possibly to 30 minutes.
//Unattended-Upgrade::InstallOnShutdown "false"; //Unattended-Upgrade::InstallOnShutdown "false";
// Send email to this address for problems or packages upgrades // Send email to this address for problems or packages upgrades
// If empty or unset then no email is sent, make sure that you // If empty or unset then no email is sent, make sure that you
// have a working mail setup on your system. A package that provides // have a working mail setup on your system. A package that provides
// 'mailx' must be installed. E.g. "user@example.com" // 'mailx' must be installed. E.g. "user@example.com"
//Unattended-Upgrade::Mail ""; //Unattended-Upgrade::Mail "";
// Set this value to one of: // Set this value to one of:
// "always", "only-on-error" or "on-change" // "always", "only-on-error" or "on-change"
// If this is not set, then any legacy MailOnlyOnError (boolean) value // If this is not set, then any legacy MailOnlyOnError (boolean) value
// is used to chose between "only-on-error" and "on-change" // is used to chose between "only-on-error" and "on-change"
//Unattended-Upgrade::MailReport "on-change"; //Unattended-Upgrade::MailReport "on-change";
// Remove unused automatically installed kernel-related packages // Remove unused automatically installed kernel-related packages
// (kernel images, kernel headers and kernel version locked tools). // (kernel images, kernel headers and kernel version locked tools).
//Unattended-Upgrade::Remove-Unused-Kernel-Packages "true"; //Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
// Do automatic removal of newly unused dependencies after the upgrade // Do automatic removal of newly unused dependencies after the upgrade
//Unattended-Upgrade::Remove-New-Unused-Dependencies "true"; //Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
// Do automatic removal of unused packages after the upgrade // Do automatic removal of unused packages after the upgrade
// (equivalent to apt-get autoremove) // (equivalent to apt-get autoremove)
//Unattended-Upgrade::Remove-Unused-Dependencies "false"; //Unattended-Upgrade::Remove-Unused-Dependencies "false";
// Automatically reboot *WITHOUT CONFIRMATION* if // Automatically reboot *WITHOUT CONFIRMATION* if
// the file /var/run/reboot-required is found after the upgrade // the file /var/run/reboot-required is found after the upgrade
//Unattended-Upgrade::Automatic-Reboot "false"; //Unattended-Upgrade::Automatic-Reboot "false";
// Automatically reboot even if there are users currently logged in // Automatically reboot even if there are users currently logged in
// when Unattended-Upgrade::Automatic-Reboot is set to true // when Unattended-Upgrade::Automatic-Reboot is set to true
//Unattended-Upgrade::Automatic-Reboot-WithUsers "true"; //Unattended-Upgrade::Automatic-Reboot-WithUsers "true";
// If automatic reboot is enabled and needed, reboot at the specific // If automatic reboot is enabled and needed, reboot at the specific
// time instead of immediately // time instead of immediately
// Default: "now" // Default: "now"
//Unattended-Upgrade::Automatic-Reboot-Time "02:00"; //Unattended-Upgrade::Automatic-Reboot-Time "02:00";
// Use apt bandwidth limit feature, this example limits the download // Use apt bandwidth limit feature, this example limits the download
// speed to 70kb/sec // speed to 70kb/sec
//Acquire::http::Dl-Limit "70"; //Acquire::http::Dl-Limit "70";
// Enable logging to syslog. Default is False // Enable logging to syslog. Default is False
// Unattended-Upgrade::SyslogEnable "false"; // Unattended-Upgrade::SyslogEnable "false";
// Specify syslog facility. Default is daemon // Specify syslog facility. Default is daemon
// Unattended-Upgrade::SyslogFacility "daemon"; // Unattended-Upgrade::SyslogFacility "daemon";
// Download and install upgrades only on AC power // Download and install upgrades only on AC power
// (i.e. skip or gracefully stop updates on battery) // (i.e. skip or gracefully stop updates on battery)
// Unattended-Upgrade::OnlyOnACPower "true"; // Unattended-Upgrade::OnlyOnACPower "true";
// Download and install upgrades only on non-metered connection // Download and install upgrades only on non-metered connection
// (i.e. skip or gracefully stop updates on a metered connection) // (i.e. skip or gracefully stop updates on a metered connection)
// Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true"; // Unattended-Upgrade::Skip-Updates-On-Metered-Connections "true";
// Verbose logging // Verbose logging
// Unattended-Upgrade::Verbose "false"; // Unattended-Upgrade::Verbose "false";
// Print debugging information both in unattended-upgrades and // Print debugging information both in unattended-upgrades and
// in unattended-upgrade-shutdown // in unattended-upgrade-shutdown
// Unattended-Upgrade::Debug "false"; // Unattended-Upgrade::Debug "false";
// Allow package downgrade if Pin-Priority exceeds 1000 // Allow package downgrade if Pin-Priority exceeds 1000
// Unattended-Upgrade::Allow-downgrade "false"; // Unattended-Upgrade::Allow-downgrade "false";
// When APT fails to mark a package to be upgraded or installed try adjusting // When APT fails to mark a package to be upgraded or installed try adjusting
// candidates of related packages to help APT's resolver in finding a solution // candidates of related packages to help APT's resolver in finding a solution
// where the package can be upgraded or installed. // where the package can be upgraded or installed.
// This is a workaround until APT's resolver is fixed to always find a // This is a workaround until APT's resolver is fixed to always find a
// solution if it exists. (See Debian bug #711128.) // solution if it exists. (See Debian bug #711128.)
// The fallback is enabled by default, except on Debian's sid release because // The fallback is enabled by default, except on Debian's sid release because
// uninstallable packages are frequent there. // uninstallable packages are frequent there.
// Disabling the fallback speeds up unattended-upgrades when there are // Disabling the fallback speeds up unattended-upgrades when there are
// uninstallable packages at the expense of rarely keeping back packages which // uninstallable packages at the expense of rarely keeping back packages which
// could be upgraded or installed. // could be upgraded or installed.
// Unattended-Upgrade::Allow-APT-Mark-Fallback "true"; // Unattended-Upgrade::Allow-APT-Mark-Fallback "true";
Unattended-Upgrade::AutoFixInterruptedDpkg "true"; Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true"; Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true"; Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true"; Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "02:30"; Unattended-Upgrade::Automatic-Reboot-Time "02:30";
@@ -1,23 +1,23 @@
### Editing /etc/systemd/system/apt-daily-upgrade.timer.d/override.conf ### Editing /etc/systemd/system/apt-daily-upgrade.timer.d/override.conf
### Anything between here and the comment below will become the new contents of the file ### Anything between here and the comment below will become the new contents of the file
[Timer] [Timer]
OnCalendar= OnCalendar=
OnCalendar=01:30 OnCalendar=01:30
RandomizedDelaySec=0 RandomizedDelaySec=0
### Lines below this comment will be discarded ### Lines below this comment will be discarded
### /lib/systemd/system/apt-daily-upgrade.timer ### /lib/systemd/system/apt-daily-upgrade.timer
# [Unit] # [Unit]
# Description=Daily apt upgrade and clean activities # Description=Daily apt upgrade and clean activities
# After=apt-daily.timer # After=apt-daily.timer
# #
# [Timer] # [Timer]
# OnCalendar=*-*-* 6:00 # OnCalendar=*-*-* 6:00
# RandomizedDelaySec=60m # RandomizedDelaySec=60m
# Persistent=true # Persistent=true
# #
# [Install] # [Install]
# WantedBy=timers.target # WantedBy=timers.target
@@ -1,101 +1,101 @@
#!/bin/sh #!/bin/sh
### BEGIN INIT INFO ### BEGIN INIT INFO
# Provides: cpufrequtils # Provides: cpufrequtils
# Required-Start: $remote_fs loadcpufreq # Required-Start: $remote_fs loadcpufreq
# Required-Stop: # Required-Stop:
# Default-Start: 2 3 4 5 # Default-Start: 2 3 4 5
# Default-Stop: # Default-Stop:
# Short-Description: set CPUFreq kernel parameters # Short-Description: set CPUFreq kernel parameters
# Description: utilities to deal with CPUFreq Linux # Description: utilities to deal with CPUFreq Linux
# kernel support # kernel support
### END INIT INFO ### END INIT INFO
# #
DESC="CPUFreq Utilities" DESC="CPUFreq Utilities"
PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
CPUFREQ_SET=/usr/bin/cpufreq-set CPUFREQ_SET=/usr/bin/cpufreq-set
CPUFREQ_INFO=/usr/bin/cpufreq-info CPUFREQ_INFO=/usr/bin/cpufreq-info
CPUFREQ_OPTIONS="" CPUFREQ_OPTIONS=""
# use lsb-base # use lsb-base
. /lib/lsb/init-functions . /lib/lsb/init-functions
# Which governor to use. Must be one of the governors listed in: # Which governor to use. Must be one of the governors listed in:
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors # cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors
# #
# and which limits to set. Both MIN_SPEED and MAX_SPEED must be values # and which limits to set. Both MIN_SPEED and MAX_SPEED must be values
# listed in: # listed in:
# cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies # cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_frequencies
# a value of 0 for any of the two variables will disabling the use of # a value of 0 for any of the two variables will disabling the use of
# that limit variable. # that limit variable.
# #
# WARNING: the correct kernel module must already be loaded or compiled in. # WARNING: the correct kernel module must already be loaded or compiled in.
# #
# Set ENABLE to "true" to let the script run at boot time. # Set ENABLE to "true" to let the script run at boot time.
# #
# eg: ENABLE="true" # eg: ENABLE="true"
# GOVERNOR="ondemand" # GOVERNOR="ondemand"
# MAX_SPEED=1000 # MAX_SPEED=1000
# MIN_SPEED=500 # MIN_SPEED=500
ENABLE="true" ENABLE="true"
GOVERNOR="powersave" GOVERNOR="powersave"
MAX_SPEED="0" MAX_SPEED="0"
MIN_SPEED="0" MIN_SPEED="0"
check_governor_avail() { check_governor_avail() {
info="/sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors" info="/sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors"
if [ -f $info ] && grep -q "\<$GOVERNOR\>" $info ; then if [ -f $info ] && grep -q "\<$GOVERNOR\>" $info ; then
return 0; return 0;
fi fi
return 1; return 1;
} }
[ -x $CPUFREQ_SET ] || exit 0 [ -x $CPUFREQ_SET ] || exit 0
if [ -f /etc/default/cpufrequtils ] ; then if [ -f /etc/default/cpufrequtils ] ; then
. /etc/default/cpufrequtils . /etc/default/cpufrequtils
fi fi
# if not enabled then exit gracefully # if not enabled then exit gracefully
[ "$ENABLE" = "true" ] || exit 0 [ "$ENABLE" = "true" ] || exit 0
if [ -n "$MAX_SPEED" ] && [ $MAX_SPEED != "0" ] ; then if [ -n "$MAX_SPEED" ] && [ $MAX_SPEED != "0" ] ; then
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --max $MAX_SPEED" CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --max $MAX_SPEED"
fi fi
if [ -n "$MIN_SPEED" ] && [ $MIN_SPEED != "0" ] ; then if [ -n "$MIN_SPEED" ] && [ $MIN_SPEED != "0" ] ; then
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --min $MIN_SPEED" CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --min $MIN_SPEED"
fi fi
if [ -n "$GOVERNOR" ] ; then if [ -n "$GOVERNOR" ] ; then
CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --governor $GOVERNOR" CPUFREQ_OPTIONS="$CPUFREQ_OPTIONS --governor $GOVERNOR"
fi fi
CPUS=$(cat /proc/stat|sed -ne 's/^cpu\([[:digit:]]\+\).*/\1/p') CPUS=$(cat /proc/stat|sed -ne 's/^cpu\([[:digit:]]\+\).*/\1/p')
RETVAL=0 RETVAL=0
case "$1" in case "$1" in
start|force-reload|restart|reload) start|force-reload|restart|reload)
log_action_begin_msg "$DESC: Setting $GOVERNOR CPUFreq governor" log_action_begin_msg "$DESC: Setting $GOVERNOR CPUFreq governor"
if check_governor_avail ; then if check_governor_avail ; then
for cpu in $CPUS ; do for cpu in $CPUS ; do
log_action_cont_msg "CPU${cpu}" log_action_cont_msg "CPU${cpu}"
$CPUFREQ_SET --cpu $cpu $CPUFREQ_OPTIONS 2>&1 > /dev/null || \ $CPUFREQ_SET --cpu $cpu $CPUFREQ_OPTIONS 2>&1 > /dev/null || \
RETVAL=$? RETVAL=$?
done done
log_action_end_msg $RETVAL "" log_action_end_msg $RETVAL ""
else else
log_action_cont_msg "disabled, governor not available" log_action_cont_msg "disabled, governor not available"
log_action_end_msg $RETVAL log_action_end_msg $RETVAL
fi fi
;; ;;
stop) stop)
;; ;;
*) *)
echo "Usage: $0 {start|stop|restart|reload|force-reload}" echo "Usage: $0 {start|stop|restart|reload|force-reload}"
exit 1 exit 1
esac esac
exit 0 exit 0
+6
View File
@@ -0,0 +1,6 @@
# This configuration file is customized by fox,
# Optimize system CPU governors.
CPUPOWER_START_OPTS="frequency-set -g powersave"
CPUPOWER_STOP_OPTS="frequency-set -g performance"
+18
View File
@@ -0,0 +1,18 @@
# This configuration file is customized by fox,
# Optimize for cpupower systemd service.
[Unit]
Description=Apply cpupower configuration
ConditionVirtualization=!container
After=syslog.target
[Service]
Type=oneshot
EnvironmentFile=/etc/default/cpupower
ExecStart=/usr/bin/cpupower $CPUPOWER_START_OPTS
ExecStop=/usr/bin/cpupower $CPUPOWER_STOP_OPTS
RemainAfterExit=yes
[Install]
WantedBy=multi-user.target