Compare commits

...
147 Commits
Author SHA1 Message Date
CallMeR c69fedc984 更新截图 2025-02-02 21:58:17 +08:00
CallMeR 1915273f81 更新截图 2025-02-02 21:34:44 +08:00
CallMeR 8a72ccebbe 更新截图 2025-02-02 21:19:19 +08:00
CallMeR 4600694a36 更新截图 2025-02-02 21:02:06 +08:00
CallMeR fad611823f 更新上游 DNS 2025-02-01 02:16:40 +08:00
CallMeR f13d108c7b 更新文案描述 2025-01-24 23:08:13 +08:00
CallMeR cb205dda2f 更新文案描述 2025-01-20 18:55:03 +08:00
CallMeR d613ea63a1 更新截图 2025-01-20 18:22:16 +08:00
CallMeR 664bf13a20 更新截图 2025-01-20 17:56:45 +08:00
CallMeR ccd3942725 调整部分时间相关参数 2025-01-18 09:26:33 +08:00
CallMeR 573468ca94 调整 Nftables MTU Fixing 2025-01-17 01:34:54 +08:00
CallMeR 2c22ba9212 更新 TS 服务器参数 2025-01-16 17:57:50 +08:00
CallMeR c1c6282713 更新系统软件 2025-01-16 13:08:52 +08:00
CallMeR 8cca306890 调整 Nftables Offload 2025-01-15 21:38:01 +08:00
CallMeR 6b49519190 精简 SYSCTL 参数 2025-01-15 18:21:03 +08:00
CallMeR 688d6e0809 精简 SYSCTL 参数 2025-01-15 17:45:48 +08:00
CallMeR ad51e789de 调整 Nftables Offload 2025-01-15 15:00:05 +08:00
CallMeR 0a7fda4e15 更新 Dnsmasq 参数 2025-01-14 15:25:36 +08:00
CallMeR 100c012314 更新系统软件 2025-01-14 14:55:13 +08:00
CallMeR 945b25304d 简化 oh-my-zsh 安装 2025-01-14 10:42:58 +08:00
CallMeR 82066a8a21 更新备注 2025-01-13 18:02:25 +08:00
CallMeR f8b3bfd75e 更新备注 2025-01-13 17:56:11 +08:00
CallMeR 36d4809b37 调整 Dnsmasq 参数 2025-01-13 16:18:32 +08:00
CallMeR b7e6978342 更新文案描述 2025-01-13 15:39:58 +08:00
CallMeR 03ee8135c8 Fix newline ( 2025-01-08 22:28:27 +08:00
CallMeR 1ce40c7a36 更新内核参数 2025-01-08 22:13:00 +08:00
CallMeR 8d2f3e98de 调整域名顺序 2025-01-08 17:57:25 +08:00
CallMeR c3e0205fdf 调整 SmartDNS 内网域名策略 2025-01-08 17:51:51 +08:00
CallMeR a606d3f6e4 调整 Dnsmasq 内网域名策略 2025-01-08 17:46:19 +08:00
CallMeR 42e0359d03 更新内核参数 2025-01-08 12:09:16 +08:00
CallMeR 0377b500b6 跟进 ICANN | SAC113 调整内网域名 2025-01-07 22:34:03 +08:00
CallMeR 90c7adc62d 精简 TS 防火墙 2025-01-07 13:25:40 +08:00
CallMeR 17c0a3f87d 优化文案描述 2025-01-06 23:48:33 +08:00
CallMeR 3143d46834 更新文案描述 2025-01-06 23:37:32 +08:00
CallMeR 4dda73f087 更新文案描述 2025-01-06 23:29:04 +08:00
CallMeR 45bcf699d9 更新文案描述 2025-01-06 23:18:07 +08:00
CallMeR d153773b1f 更新清理目录 2025-01-06 18:09:39 +08:00
CallMeR 7d8da1f68e 更新清理命令 2025-01-06 18:01:14 +08:00
CallMeR 641aa555b9 更新清理命令 2025-01-06 17:54:23 +08:00
CallMeR 34e55b8daa 更新文案描述 2025-01-06 17:25:31 +08:00
CallMeR 777e4bb9d7 更新清理命令 2025-01-06 17:23:57 +08:00
CallMeR 7dceb23655 更新清理命令 2025-01-06 17:19:22 +08:00
CallMeR 81c5c3456a 整理文档结构 2025-01-06 17:11:27 +08:00
CallMeR 0731dd1fde 更新 Dnsmasq 参数 2025-01-06 02:12:11 +08:00
CallMeR 7e62ab3012 更新 TS 防火墙 2024-12-29 22:52:52 +08:00
CallMeR 14022aebbf 更新 TS 防火墙 2024-12-29 01:51:28 +08:00
CallMeR 8738625ad9 更新文案描述 2024-12-26 13:22:46 +08:00
CallMeR 51a6d0005d 更新文案描述 2024-12-26 13:20:10 +08:00
CallMeR f3a4231218 调整 TS 服务器 Dnsmasq 配置 2024-12-26 12:42:03 +08:00
CallMeR 422384497c 修复描述错误 2024-12-03 13:41:33 +08:00
CallMeR 8c26dd2569 更新广告列表 2024-11-26 12:50:51 +08:00
CallMeR ae963404b7 更新广告列表 2024-11-24 22:16:03 +08:00
CallMeR 96f89812de 更新版本号 2024-11-24 17:28:13 +08:00
CallMeR 968d0637dd 更新截图版本 2024-11-24 17:23:44 +08:00
CallMeR 1166516576 更新 DNS sysctl 参数 2024-11-02 15:37:49 +08:00
CallMeR f664975bcc 更新 DNS sysctl 参数 2024-10-29 14:01:39 +08:00
CallMeR 26fa0b0c10 修复描述错误,Fix: https://gitee.com/callmer/routeros_toss_notes/issues/IB0HER 2024-10-29 13:26:00 +08:00
CallMeR ac2740f888 更新系统 sysctl 参数 2024-10-28 00:32:12 +08:00
CallMeR aa1a12757b 更新系统 sysctl 参数 2024-10-24 18:23:26 +08:00
CallMeR ccef3195ff 更新系统 sysctl 参数 2024-10-23 10:12:01 +08:00
CallMeR dd3bda21f5 更新系统 sysctl 参数 2024-10-22 15:28:58 +08:00
CallMeR 547389c182 更新系统 sysctl 参数 2024-10-22 14:18:09 +08:00
CallMeR ace58ce24d 更新 TS 服务器流控算法 2024-10-21 23:30:53 +08:00
CallMeR adaeb4a650 新增 BTRFS 调整内容 2024-10-19 02:26:04 +08:00
CallMeR fa29b0d633 更新系统 sysctl 参数 2024-10-17 12:57:46 +08:00
CallMeR 94273ae2b6 RFC 9460
Service Binding and Parameter Specification via the DNS (SVCB and HTTPS Resource Records)
2024-10-14 17:53:10 +08:00
CallMeR 2d32561415 更新 SmartDNS 过期缓存 2024-10-13 17:06:50 +08:00
CallMeR 0dcfa86d11 更新 SmartDNS 加速脚本 2024-10-13 16:32:44 +08:00
CallMeR 557ae16217 更新清理缓存命令 2024-10-09 23:43:17 +08:00
CallMeR 49083bf184 更新 SmartDNS 清理缓存 2024-10-08 23:48:01 +08:00
CallMeR 9634a10686 更新清理命令 2024-10-08 23:30:52 +08:00
CallMeR 6f7c78b749 更新清理命令 2024-10-08 23:16:46 +08:00
CallMeR 04fc40c8e1 更新清理命令 2024-10-08 23:08:24 +08:00
CallMeR 05ba8586ae 更新 SmartDNS 参数 2024-10-08 22:56:27 +08:00
CallMeR e8cb9b14f4 更新示例输出 2024-10-07 18:08:24 +08:00
CallMeR 7b794c11e4 更新 NTP 服务器 2024-10-07 18:04:33 +08:00
CallMeR d4673a204a 更新实例输出 2024-10-07 18:00:03 +08:00
CallMeR 95913b4d0d 更新 NTP 服务器 2024-10-07 17:52:02 +08:00
CallMeR 964fc699e3 Revert 更新 SmartDNS 参数 2024-10-05 17:44:11 +08:00
CallMeR b3b147ab37 更新 SmartDNS 广告列表 2024-09-27 23:05:48 +08:00
CallMeR cdcc71462b 更新 SmartDNS 参数 2024-09-27 16:05:05 +08:00
CallMeR 999a06f938 更新 Nftables 规则 2024-09-27 14:30:48 +08:00
CallMeR 4bf1e1d523 更新 Nftables 规则 2024-09-27 14:01:18 +08:00
CallMeR ddc60fd6f1 更换 SmartDNS 广告列表 2024-09-19 15:44:11 +08:00
CallMeR c94872a931 更新 SmartDNS 缓存参数 2024-09-15 12:20:03 +08:00
CallMeR d09bd30a25 更新上游 DNS 2024-09-05 13:55:10 +08:00
CallMeR cc5ec05502 更新 SmartDNS 上游 DNS 2024-09-03 13:59:54 +08:00
CallMeR e0894f3e13 更新 PVE 版本 2024-08-24 19:44:32 +08:00
CallMeR 360d5b6cab 更新 DNS 缓存参数 2024-08-24 03:23:26 +08:00
CallMeR 8d2cab7155 更新备注 2024-08-17 22:37:05 +08:00
CallMeR afb5a5859c 更新 Dnsmasq 配置 2024-08-15 19:07:27 +08:00
CallMeR 53c3fe877a 更新 SmartDNS 上游 DoT / DoH 服务器 2024-08-14 21:40:22 +08:00
CallMeR 835cbf9b43 更新上游 DNS 服务器 2024-08-07 22:52:54 +08:00
CallMeR 1b97935413 更新 SmartDNS 插件 2024-08-07 13:30:38 +08:00
CallMeR fc67f6f575 更新 SmartDNS 上游 DNS 2024-08-07 13:22:22 +08:00
CallMeR bc5ea890ad 更新 Dnsmasq 参数 2024-08-02 20:14:17 +08:00
CallMeR fefcd16f82 更新 SmartDNS 参数 2024-08-02 20:10:24 +08:00
CallMeR 10050fa7ff 更新 SmartDNS Plugin 2024-08-02 10:46:49 +08:00
CallMeR 20086c63f7 调整 Dnsmasq 配置 2024-08-02 10:29:56 +08:00
CallMeR 619b96a6fc 调整 SmartDNS 参数 2024-08-02 00:37:42 +08:00
CallMeR 4fbb729d85 关闭 SmartDNS 过期缓存并调整响应 TTL 2024-07-29 01:13:05 +08:00
CallMeR 78fd87188c 停用 Dnsmasq 的 negative 缓存 2024-07-27 11:23:48 +08:00
CallMeR 8a737cfb34 优化 SmartDNS 配置 2024-07-24 23:31:45 +08:00
CallMeR fcfd177593 移除 SmartDNS EDNS 参数 2024-07-24 21:53:31 +08:00
CallMeR 1336af517e 更新 DNS 服务器流控算法 2024-07-22 17:12:01 +08:00
CallMeR b0beb5177f 更新 DNS 服务器流控算法 2024-07-19 12:37:05 +08:00
CallMeR 921bd8bb31 更新 TS 服务器流控算法 2024-07-19 12:35:08 +08:00
CallMeR ff1a1a43a7 更新截图 2024-07-02 15:23:20 +08:00
CallMeR 9a9173df92 更新系统更新命令 2024-07-02 11:01:58 +08:00
CallMeR e9ca2b5cda 更新备注信息 2024-06-28 15:33:05 +08:00
CallMeR 0695f8b6b9 Revert 替换广告屏蔽列表 2024-06-28 12:31:22 +08:00
CallMeR 1657411b7e 更新备注信息 2024-06-28 00:14:16 +08:00
CallMeR 14007e78b8 替换广告屏蔽列表 2024-06-27 16:56:10 +08:00
CallMeR 7318726847 修复段落标题 2024-06-26 15:05:08 +08:00
CallMeR 374c55cbb3 修复目录路径 2024-06-26 15:03:00 +08:00
CallMeR 7df6ea76b7 更新文案描述 2024-06-26 14:55:57 +08:00
CallMeR 5e0a8aac54 更新文案描述 2024-06-26 14:53:35 +08:00
CallMeR 8dd1f08f27 更新终端工具 2024-06-26 14:43:59 +08:00
CallMeR 9873dd74d1 更新 SmartDNS 版本 2024-06-13 11:29:38 +08:00
CallMeR ffaa26a050 更新配置文件备注 2024-05-23 02:12:07 +08:00
CallMeR b17ef026ad 更新文案描述 2024-05-21 12:50:30 +08:00
CallMeR 808094ae3c 更新脚本文件命名 2024-05-20 22:17:58 +08:00
CallMeR 609fcf579b 更新配置文件命名 2024-05-20 21:32:38 +08:00
CallMeR 022da7d3f9 更新配置文件命名 2024-05-20 16:18:29 +08:00
CallMeR afb2678f68 使用 btop 代替 htop 2024-05-16 13:21:15 +08:00
CallMeR 4ed96a4d38 更新文案说明 2024-04-28 12:09:53 +08:00
CallMeR f7ff85a805 更新 PVE 版本号 2024-04-26 13:50:02 +08:00
CallMeR 101fc96feb 更新自动备份截图 2024-04-26 13:48:52 +08:00
CallMeR 01f39562ff 新增 sshguard 工具 2024-04-26 12:36:28 +08:00
CallMeR 933bdca053 更新部分截图 2024-04-26 11:56:14 +08:00
CallMeR 748faac28b 更换 SmartDNS 广告列表 2024-04-23 13:28:57 +08:00
CallMeR fe8fbff04c 更新 Dnsmasq 缓存设置 2024-04-23 10:39:00 +08:00
CallMeR 50f49ed956 更新 SmartDNS 缓存设置 2024-04-23 10:36:39 +08:00
CallMeR b809ecd035 更新 PVE 软件源替换命令 2024-04-21 21:12:55 +08:00
CallMeR eda1d36130 更新 Dnsmasq 配置 2024-03-21 10:52:33 +08:00
CallMeR c9bf9ae2fd 更新 Dnsmasq 配置 2024-03-20 22:41:13 +08:00
CallMeR 38ac1f9702 更新 Dnsmasq 配置 2024-03-19 18:36:36 +08:00
CallMeR f493c774ab 更新 SmartDNS 配置 2024-03-19 12:06:18 +08:00
CallMeR 09a35e9c31 关闭 Dnsmasq 缓存 2024-03-19 10:13:17 +08:00
CallMeR a1e992c956 更新 SmartDNS 配置 2024-03-19 10:04:27 +08:00
CallMeR 360542f9d4 更新 Dnsmasq 参数 2024-03-18 21:45:12 +08:00
CallMeR e5a8d8b491 更新截图 2024-03-18 14:14:47 +08:00
CallMeR 3ce5fdba6a 更新截图 2024-03-18 14:09:10 +08:00
CallMeR 5ec78ce639 更新 Debian 云镜像 2024-03-18 13:50:30 +08:00
CallMeR b597af908d 更新 SmartDNS 缓存参数 2024-03-16 13:34:26 +08:00
CallMeR 6f085030b3 更新 Dnsmasq 缓存参数 2024-03-16 13:25:07 +08:00
CallMeR 82497488ed 更新 TS 自动更新 2024-03-01 20:26:31 +08:00
70 changed files with 537 additions and 454 deletions
+17 -11
View File
@@ -6,7 +6,7 @@ PVE 系统正式安装之前,需要准备 PVE 的安装镜像和一些必要
PVE 下载地址:[Proxmox Virtual Environment](https://www.proxmox.com/en/downloads/proxmox-virtual-environment/iso) PVE 下载地址:[Proxmox Virtual Environment](https://www.proxmox.com/en/downloads/proxmox-virtual-environment/iso)
页面中有多个 PVE 相关文件,本文以目前最新的 `Proxmox VE 8.1-1 ISO Installer` 作为演示。 页面中有多个 PVE 相关文件,本文以目前最新的 `Proxmox VE 8.3-1 ISO Installer` 作为演示。
点击 `Proxmox VE 8.x ISO Installer` 链接,进入 PVE 下载页面。 点击 `Proxmox VE 8.x ISO Installer` 链接,进入 PVE 下载页面。
@@ -50,25 +50,31 @@ PVE 下载地址:[Proxmox Virtual Environment](https://www.proxmox.com/en/down
![Rufus写盘工具](img/p01/pve_rufus.jpeg) ![Rufus写盘工具](img/p01/pve_rufus.jpeg)
### 0.3. SSH 工具 ### 0.3.终端工具
考虑到配置 PVE 服务器、路由器、DNS 服务器时,需要在 CLI 中输入命令,因此这里推荐几个常用的 SSH 工具。 考虑到配置 PVE 服务器、路由器、DNS 服务器时,需要在 CLI 中输入命令,因此这里推荐几个常用的终端工具。
#### Tabby #### Windows Terminal
官方网站地址:https://tabby.sh 官方网站地址:https://aka.ms/terminal
基于 Electron 开发的开源跨平台终端工具,内部集成了 SFTP ,可以在 Github 平台上进行下载。 Microsoft 官方终端工具,可以在 Github 平台或 Microsoft 应用商店中进行下载。
支持 Windows 、macOS 、Linux 。 ![Windows Terminal](img/p01/pve_win_terminal.png)
![Tabby SSH工具](img/p01/pve_tabby.png) #### Termius
官方地址:https://termius.com/
企业级终端工具,支持 Windows、macOS、Linux 系统以及移动端系统。
![Termius](img/p01/pve_termius.jpeg)
#### MobaXterm #### MobaXterm
官方地址:https://mobaxterm.mobatek.net 官方地址:https://mobaxterm.mobatek.net
功能强大的 SSH 工具,仅支持 Windows 。 功能强大的终端工具,仅支持 Windows 系统
![MobaXterm](img/p01/pve_mobaxterm.png) ![MobaXterm](img/p01/pve_mobaxterm.png)
@@ -156,7 +162,7 @@ PVE 为最关键的虚拟化层,建议使用强密码,包含大小写字母
FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。 FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
演示中 FQDN 为 `node01.fox.home.arpa` ,因此 PVE 的主机名为 `node01` 演示中 FQDN 为 `node01.fox.internal` ,因此 PVE 的主机名为 `node01`
根据规划,PVE 的 IPv4 管理地址为 `172.16.1.254` 根据规划,PVE 的 IPv4 管理地址为 `172.16.1.254`
@@ -166,7 +172,7 @@ FQDN 为 PVE 的域,PVE 将使用 FQDN 中的二级域名作为其主机名。
|参数|值|说明| |参数|值|说明|
|--|--|--| |--|--|--|
|Hostname (FQDN)|`node01.fox.home.arpa`|设置 PVE `域``主机名` | |Hostname (FQDN)|`node01.fox.internal`|设置 PVE `域``主机名` |
|IP Address (CIDR)|`172.16.1.254/24`|设置 PVE IPv4 地址| |IP Address (CIDR)|`172.16.1.254/24`|设置 PVE IPv4 地址|
|Gateway|`172.16.1.1`|设置 PVE IPv4 网关| |Gateway|`172.16.1.1`|设置 PVE IPv4 网关|
|DNS Server|`172.16.1.1`|设置 PVE IPv4 DNS | |DNS Server|`172.16.1.1`|设置 PVE IPv4 DNS |
+32 -29
View File
@@ -12,10 +12,10 @@
### 1.1.系统软件源 ### 1.1.系统软件源
使用 SSH 工具登录到 PVE 服务器,首先对现有的软件源配置进行备份。 使用终端工具登录到 PVE 服务器,首先对现有的软件源配置进行备份。
```bash ```bash
## 进入系统软件源配置文件目录 ## 进入系统软件源配置目录
$ cd /etc/apt $ cd /etc/apt
## 查看系统默认镜像配置 ## 查看系统默认镜像配置
@@ -64,48 +64,51 @@ deb https://mirrors.ustc.edu.cn/debian-security/ bookworm-security main contrib
默认情况下,PVE 额外启用了 2 个官方源,且为订阅收费制,因此需要替换为免费源。 默认情况下,PVE 额外启用了 2 个官方源,且为订阅收费制,因此需要替换为免费源。
删除 PVE 官方付费软件源,执行以下命令。 首先创建 PVE 费软件源,执行以下命令。
```bash
## 创建 PVE 免费软件源
$ source /etc/os-release
$ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/pve $VERSION_CODENAME pve-no-subscription" > /etc/apt/sources.list.d/pve-no-subscription.list
```
对于 Proxmox Backup Server 和 Proxmox Mail Gateway,请将以上命令中的 `pve` 分别替换为 `pbs``pmg`
进一步创建 PVE Ceph 免费软件源,Ceph 软件源为 PVE 8 之后默认安装,执行以下命令。
```bash
## 创建 PVE Ceph 免费软件源脚本
if [ -f /etc/apt/sources.list.d/ceph.list ]; then
CEPH_CODENAME=`ceph -v | grep ceph | awk '{print $(NF-1)}'`
source /etc/os-release
echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-$CEPH_CODENAME $VERSION_CODENAME no-subscription" > /etc/apt/sources.list.d/ceph-no-subscription.list
fi
```
最后,删除 PVE 官方付费软件源,执行以下命令。
**注意:rm 为高风险命令,请正确使用,请勿手抖,请勿手抖。** **注意:rm 为高风险命令,请正确使用,请勿手抖,请勿手抖。**
```bash ```bash
## 删除付费软件源 ## 删除付费软件源
$ rm -rvf /etc/apt/sources.list.d/*.list $ rm -rvf /etc/apt/sources.list.d/pve-enterprise.list /etc/apt/sources.list.d/ceph.list
```
创建 PVE 免费软件源。
**注意:该命令为三行,在输入时请逐行输入并回车执行。**
```bash
## 创建 PVE 免费源
$ source /etc/os-release
$ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy $VERSION_CODENAME no-subscription" > /etc/apt/sources.list.d/ceph-no-subscription.list
$ echo "deb https://mirrors.ustc.edu.cn/proxmox/debian/pve $VERSION_CODENAME pve-no-subscription" > /etc/apt/sources.list.d/pve-no-subscription.list
``` ```
创建完成后对其进行检查。 创建完成后对其进行检查。
```bash ```bash
## 检查 PVE 免费源 ## 检查 PVE 免费源
$ cat /etc/apt/sources.list.d/*
$ cat /etc/apt/sources.list.d/ceph-no-subscription.list
$ cat /etc/apt/sources.list.d/pve-no-subscription.list
``` ```
如果输出结果中有 USTC 的镜像地址,则表示命令已经正确执行。 如果输出结果中有 USTC 的镜像地址,则表示命令已经正确执行。
```bash ```bash
#### PVE 免费软件源示例输出 #### PVE 免费软件源示例输出
#### Ceph
deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy bookworm no-subscription deb https://mirrors.ustc.edu.cn/proxmox/debian/ceph-quincy bookworm no-subscription
#### PVE
deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription deb https://mirrors.ustc.edu.cn/proxmox/debian/pve bookworm pve-no-subscription
``` ```
@@ -143,7 +146,7 @@ $ apt clean && apt autoclean && apt autoremove --purge
$ apt update $ apt update
## 更新系统 ## 更新系统
$ apt dist-upgrade $ apt full-upgrade
``` ```
## 2.安装必要软件 ## 2.安装必要软件
@@ -161,10 +164,10 @@ $ apt dist-upgrade
$ apt update $ apt update
## 安装系统软件 ## 安装系统软件
$ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base $ apt install btop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具 ## 安装网络工具
$ apt install iperf iperf3 iftop openvswitch-switch $ apt install iperf iperf3 iftop sshguard openvswitch-switch
## 安装 CPU 调度调整工具 ## 安装 CPU 调度调整工具
$ apt install linux-cpupower $ apt install linux-cpupower
+100 -38
View File
@@ -4,15 +4,17 @@
在 PVE 系统调整之前,请确认必要的软件包已经安装完成,本文后续命令均在 SSH 终端下执行。 在 PVE 系统调整之前,请确认必要的软件包已经安装完成,本文后续命令均在 SSH 终端下执行。
关于 [Neovim](https://neovim.io/) 的基础使用方法,请参阅:[Neovim 基本操作](https://www.bing.com/search?q=neovim+%E5%9F%BA%E6%9C%AC%E6%93%8D%E4%BD%9C) 。
```bash ```bash
## 同步镜像仓库 ## 同步镜像仓库
$ apt update $ apt update
## 安装系统软件 ## 安装系统软件
$ apt install htop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base $ apt install btop lm-sensors unzip neovim tmux unattended-upgrades powermgmt-base
## 安装网络工具 ## 安装网络工具
$ apt install iperf iperf3 iftop openvswitch-switch $ apt install iperf iperf3 iftop sshguard openvswitch-switch
## 安装 CPU 调度调整工具 ## 安装 CPU 调度调整工具
$ apt install linux-cpupower $ apt install linux-cpupower
@@ -38,7 +40,7 @@ $ timedatectl set-timezone Asia/Shanghai
$ date -R $ date -R
#### 系统时间示例输出 #### 系统时间示例输出
Sun, 25 Jun 2023 12:12:12 +0800 Mon, 20 Jan 2025 18:24:41 +0800
``` ```
Debian 系统常用 `systemd-timesyncd.service` 来同步时间,而 PVE 系统使用 `chrony.service` 来同步时间。 Debian 系统常用 `systemd-timesyncd.service` 来同步时间,而 PVE 系统使用 `chrony.service` 来同步时间。
@@ -47,7 +49,7 @@ Debian 系统常用 `systemd-timesyncd.service` 来同步时间,而 PVE 系统
```bash ```bash
## 编辑 chrony 配置文件 ## 编辑 chrony 配置文件
$ nano /etc/chrony/chrony.conf $ nvim /etc/chrony/chrony.conf
``` ```
在编辑器对话框中,将 `pool 2.debian.pool.ntp.org iburst` “注释” 掉,并添加国内的 NTP 服务器。 在编辑器对话框中,将 `pool 2.debian.pool.ntp.org iburst` “注释” 掉,并添加国内的 NTP 服务器。
@@ -59,15 +61,16 @@ $ nano /etc/chrony/chrony.conf
# pool 2.debian.pool.ntp.org iburst ## 在这行前面增加注释符 # 来注释 # pool 2.debian.pool.ntp.org iburst ## 在这行前面增加注释符 # 来注释
# Use Custom vendor zone. # Use Custom vendor zone.
pool ntp.tencent.com iburst
pool ntp.aliyun.com iburst pool ntp.aliyun.com iburst
pool ntp.tencent.com iburst
pool cn.pool.ntp.org iburst
``` ```
保存该配置文件后,需重启 `chrony.service` ,并再次检查系统 NTP 服务器地址。 保存该配置文件后,需重启 `chrony.service` ,并再次检查系统 NTP 服务器地址。
```bash ```bash
## 重启 chrony 服务 ## 重启 chrony.service
$ systemctl restart chrony.service $ systemctl restart chrony.service
## 检查系统 NTP 服务器 ## 检查系统 NTP 服务器
@@ -76,8 +79,12 @@ $ chronyc sources -V
#### 系统 NTP 服务器示例输出 #### 系统 NTP 服务器示例输出
MS Name/IP address Stratum Poll Reach LastRx Last sample MS Name/IP address Stratum Poll Reach LastRx Last sample
=============================================================================== ===============================================================================
^+ 106.55.184.199 2 6 17 11 +752us[ +273us] +/- 40ms ^* 203.107.6.88 2 6 17 0 -875us[-2496us] +/- 22ms
^* 203.107.6.88 2 6 17 11 -1868us[-2348us] +/- 17ms ^- 106.55.184.199 2 6 17 3 -1331us[-1331us] +/- 50ms
^- time.neu.edu.cn 2 6 17 8 +935us[ +935us] +/- 23ms
^- 119.28.206.193 2 6 65 5 +33us[ +33us] +/- 65ms
^- electrode.felixc.at 2 6 17 11 -1320us[-1320us] +/- 126ms
^- dns1.synet.edu.cn 1 6 17 13 -44us[ -44us] +/- 22ms
``` ```
## 2. CPU 调度器 ## 2. CPU 调度器
@@ -97,10 +104,10 @@ analyzing CPU 0:
hardware limits: 800 MHz - 2.70 GHz hardware limits: 800 MHz - 2.70 GHz
available cpufreq governors: conservative ondemand userspace powersave performance schedutil available cpufreq governors: conservative ondemand userspace powersave performance schedutil
current policy: frequency should be within 800 MHz and 2.70 GHz. current policy: frequency should be within 800 MHz and 2.70 GHz.
The governor "ondemand" may decide which speed to use The governor "performance" may decide which speed to use
within this range. within this range.
current CPU frequency: Unable to call hardware current CPU frequency: Unable to call hardware
current CPU frequency: 800 MHz (asserted by call to kernel) current CPU frequency: 2.60 GHz (asserted by call to kernel)
boost state support: boost state support:
Supported: yes Supported: yes
Active: yes Active: yes
@@ -136,7 +143,7 @@ analyzing CPU 0:
$ cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_governor $ cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_governor
#### 设备 CPU - J4125 示例输出 #### 设备 CPU - J4125 示例输出
ondemand performance
#### 设备 CPU - N6005 示例输出 #### 设备 CPU - N6005 示例输出
performance performance
@@ -163,11 +170,11 @@ performance powersave
- CPU 驱动为 `intel_pstate` 时,推荐使用 `powersave` 调度器。 - CPU 驱动为 `intel_pstate` 时,推荐使用 `powersave` 调度器。
本文使用 `powersave` 调度器为演示,使用 `nano` 编辑器创建 `cpupower` 的配置文件。 本文使用 `powersave` 调度器为演示,使用 `neovim` 编辑器创建 `cpupower` 的配置文件。
```bash ```bash
## 创建 cpupower 配置文件 ## 创建 cpupower 默认配置文件
$ nano /etc/default/cpupower $ nvim /etc/default/cpupower
``` ```
在配置文件中修改以下配置项,并保存。 在配置文件中修改以下配置项,并保存。
@@ -181,11 +188,11 @@ CPUPOWER_STOP_OPTS="frequency-set -g performance"
``` ```
使用 `nano` 编辑器创建 `cpupower` 服务配置文件,以满足系统自动化设置需求。 进一步创建 `cpupower` 服务配置文件,以满足系统自动化设置需求。
```bash ```bash
## 创建 cpupower 服务配置文件 ## 创建 cpupower.service 配置文件
$ nano /etc/systemd/system/cpupower.service $ nvim /etc/systemd/system/cpupower.service
``` ```
在服务配置文件中修改以下配置项,并保存。 在服务配置文件中修改以下配置项,并保存。
@@ -275,11 +282,11 @@ $ systemctl status apt-daily-upgrade.timer
#### 系统定时器示例输出 #### 系统定时器示例输出
● apt-daily-upgrade.timer - Daily apt upgrade and clean activities ● apt-daily-upgrade.timer - Daily apt upgrade and clean activities
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled) Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Active: active (waiting) since Tue 2023-08-01 13:01:19 CST; 27min ago Active: active (waiting) since Mon 2025-01-20 18:12:44 CST; 19min ago
Trigger: Wed 2023-08-02 06:14:50 CST; 16h left Trigger: Tue 2025-01-21 06:52:19 CST; 12h left
Triggers: ● apt-daily-upgrade.service Triggers: ● apt-daily-upgrade.service
Aug 01 13:01:19 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities. Jan 20 18:12:44 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
``` ```
### 4.2.配置更新策略 ### 4.2.配置更新策略
@@ -292,10 +299,8 @@ Aug 01 13:01:19 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt u
## 配置自动更新策略 ## 配置自动更新策略
$ dpkg-reconfigure -plow unattended-upgrades $ dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”) ## 选择 “是”
<Yes>
#### 系统自动更新示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
``` ```
进一步调整 `20auto-upgrades` 配置文件。 进一步调整 `20auto-upgrades` 配置文件。
@@ -305,7 +310,7 @@ Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
$ cd /etc/apt/apt.conf.d $ cd /etc/apt/apt.conf.d
## 编辑 20auto-upgrades 配置文件 ## 编辑 20auto-upgrades 配置文件
$ nano /etc/apt/apt.conf.d/20auto-upgrades $ nvim /etc/apt/apt.conf.d/20auto-upgrades
``` ```
删除里面全部内容,添加以下配置项,并保存。 删除里面全部内容,添加以下配置项,并保存。
@@ -326,7 +331,7 @@ APT::Periodic::CleanInterval "1";
```bash ```bash
## 编辑 50unattended-upgrades 配置文件 ## 编辑 50unattended-upgrades 配置文件
$ nano /etc/apt/apt.conf.d/50unattended-upgrades $ nvim /etc/apt/apt.conf.d/50unattended-upgrades
``` ```
配置文件中,被修改的参数解释如下: 配置文件中,被修改的参数解释如下:
@@ -417,13 +422,13 @@ $ systemctl status apt-daily-upgrade.timer
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled) Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; preset: enabled)
Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d
└─override.conf └─override.conf
Active: active (waiting) since Tue 2023-08-01 13:37:41 CST; 9s ago Active: active (waiting) since Mon 2025-01-20 18:43:03 CST; 7s ago
Trigger: Wed 2023-08-02 01:30:00 CST; 11h left Trigger: Tue 2025-01-21 01:30:00 CST; 6h left
Triggers: ● apt-daily-upgrade.service Triggers: ● apt-daily-upgrade.service
Aug 01 13:37:41 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities. Jan 20 18:43:03 node01 systemd[1]: Stopped apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
Aug 01 13:37:41 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities... Jan 20 18:43:03 node01 systemd[1]: Stopping apt-daily-upgrade.timer - Daily apt upgrade and clean activities...
Aug 01 13:37:41 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities. Jan 20 18:43:03 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt upgrade and clean activities.
``` ```
## 5.硬件直通 ## 5.硬件直通
@@ -432,11 +437,11 @@ Aug 01 13:37:41 node01 systemd[1]: Started apt-daily-upgrade.timer - Daily apt u
参考官方文档 [qm_pci_passthrough](https://pve.proxmox.com/pve-docs/pve-admin-guide.html#qm_pci_passthrough) 和 [Pci passthrough](https://pve.proxmox.com/wiki/Pci_passthrough) 开启 PVE 硬件直通功能。 参考官方文档 [qm_pci_passthrough](https://pve.proxmox.com/pve-docs/pve-admin-guide.html#qm_pci_passthrough) 和 [Pci passthrough](https://pve.proxmox.com/wiki/Pci_passthrough) 开启 PVE 硬件直通功能。
使用 SSH 工具登录到 PVE 服务器,编辑系统 `Grub` 的配置文件 `/etc/default/grub` 使用终端工具登录到 PVE 服务器,编辑系统 `Grub` 的配置文件 `/etc/default/grub`
```bash ```bash
## 编辑 Grub 配置文件 ## 编辑 Grub 配置文件
$ nano /etc/default/grub $ nvim /etc/default/grub
``` ```
在编辑器对话框中修改 `GRUB_CMDLINE_LINUX_DEFAULT` 参数,注意命令中间的空格。 在编辑器对话框中修改 `GRUB_CMDLINE_LINUX_DEFAULT` 参数,注意命令中间的空格。
@@ -470,7 +475,7 @@ $ update-grub
```bash ```bash
## 编辑系统配置文件 ## 编辑系统配置文件
$ nano /etc/modules $ nvim /etc/modules
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
@@ -493,7 +498,7 @@ $ update-initramfs -u -k all
### 5.3.检查硬件直通 ### 5.3.检查硬件直通
PVE 服务器重启完成后,再次使用 SSH 工具登录,并执行以下命令检查硬件直通状态。 PVE 服务器重启完成后,再次使用终端工具登录,并执行以下命令检查硬件直通状态。
主要查看 `IOMMU``Directed I/O``Interrupt Remapping` 的启用状态。 主要查看 `IOMMU``Directed I/O``Interrupt Remapping` 的启用状态。
@@ -565,7 +570,64 @@ $ find /sys/kernel/iommu_groups/ -type l
/sys/kernel/iommu_groups/9/devices/0000:00:1c.6 /sys/kernel/iommu_groups/9/devices/0000:00:1c.6
``` ```
## 6.系统清理 ## 6. BTRFS 调整
**额外说明:**
1. 本节专为 `BTRFS` 单盘 `RAID0`(条带模式)安装的 PVE 系统设计,使用其他安装模式时,请跳过此节。
2. `BTRFS` 文件系统当前仍为技术预览状态,请谨慎操作。
3. 有关在 PVE 中使用 `BTRFS` 的详情,请参阅 [Proxmox VE - BTRFS](https://pve.proxmox.com/wiki/BTRFS) 。
安装 PVE 时,若使用了 `BTRFS` 单盘 `RAID0` 的安装模式,系统默认未启用 swap 和 zstd 压缩,需要手动开启。
通常情况下,内存与 swap 的 **推荐** 比例为 `1:1` 。本机具有 `16GB` 内存,因此设置 `16GB` swap 空间。
执行以下命令,在 `BTRFS` 文件系统中创建子卷,并配置激活 swapfile 。
```bash
## 创建用于存放交换文件的子卷
$ btrfs subvolume create /swap
## 在子卷中创建 16GB 的交换文件
$ btrfs filesystem mkswapfile --size 16g --uuid clear /swap/swapfile
## 激活交换文件
$ swapon /swap/swapfile
```
此时还需进一步修改系统的 `fstab` 配置文件,以启用 `BTRFS` 的 zstd 压缩功能并确保 swap 在系统启动时自动激活。
```bash
## 编辑 fstab 配置文件
$ nvim /etc/fstab
```
`fstab` 为系统关键配置文件,直接影响系统启动,修改此文件时,请注意以下几点:
- 仅修改根目录 `/` 对应的挂载选项,添加 `compress=zstd` 参数。
- 在文件末尾新增一行,添加 swap 的自动挂载。
-**不要** 修改其余配置参数,尤其是设备的唯一标识符( `UUID` ),切勿修改。
修改完成后,示例如下。
```bash
#### 系统 fstab 示例配置
# <file system> <mount point> <type> <options> <dump> <pass>
UUID=<DO-NOT-EDIT-YOUR-UUID> / btrfs defaults,compress=zstd 0 1
UUID=<YOUR-UUID> /boot/efi vfat defaults 0 1
proc /proc proc defaults 0 0
/swap/swapfile none swap defaults 0 0
```
## 7.系统清理
PVE 系统配置完成后,可执行以下命令,对系统进行清理。 PVE 系统配置完成后,可执行以下命令,对系统进行清理。
@@ -574,10 +636,10 @@ PVE 系统配置完成后,可执行以下命令,对系统进行清理。
$ apt clean && apt autoclean && apt autoremove --purge $ apt clean && apt autoclean && apt autoremove --purge
## 清理系统缓存 ## 清理系统缓存
$ rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/* $ bash -c 'find /var/cache/apt/ /var/lib/apt/lists/ /tmp/ -type f -print -delete'
## 清理系统日志 ## 清理系统日志
$ find /var/log/ -type f | xargs rm -rvf $ bash -c 'find /var/log/ -type f -print -delete'
## 清理命令历史记录文件 ## 清理命令历史记录文件
$ rm -rvf ~/.bash_history && history -c $ rm -rvf ~/.bash_history && history -c
+21 -13
View File
@@ -4,11 +4,11 @@
该虚拟机模板主要用作内网 DNS 服务器,由 `Adguard Home``SmartDNS` 提供 DNS 解析服务。 该虚拟机模板主要用作内网 DNS 服务器,由 `Adguard Home``SmartDNS` 提供 DNS 解析服务。
本文将使用 Debian 的云镜像 `debian-12-genericcloud-amd64.qcow2` 作为模板虚拟机的镜像。 本文将使用 Debian 的云镜像 `debian-12-generic-amd64.qcow2` 作为模板虚拟机的镜像。
访问 [Debian Official Cloud Images](https://cloud.debian.org/images/cloud/) 官方网站,下载最新版 `Bookworm` 云镜像以及对应的校验文件。 访问 [Debian Official Cloud Images](https://cloud.debian.org/images/cloud/) 官方网站,下载最新版 `Bookworm` 云镜像以及对应的校验文件。
![下载镜像](img/p04/download_genericcloud_image_qcow2.jpeg) ![下载镜像](img/p04/download_generic_image_qcow2.jpeg)
## 1.创建虚拟机 ## 1.创建虚拟机
@@ -90,7 +90,7 @@ CPU `类别` 选择 `host` `插槽` 与 `核心` 数根据物理 CPU 核心
### 2.2.导入镜像文件 ### 2.2.导入镜像文件
使用 SSH 工具登录 PVE 服务器,并进入 `tmp` 目录,执行以下命令创建一个目录。 使用终端工具登录 PVE 服务器,并进入 `/tmp` 目录,执行以下命令创建一个目录。
```bash ```bash
## 创建存放 Debian 云镜像的临时目录 ## 创建存放 Debian 云镜像的临时目录
@@ -107,7 +107,7 @@ $ cd /tmp/Debian
$ wget https://cloud.debian.org/images/cloud/bookworm/latest/SHA512SUMS $ wget https://cloud.debian.org/images/cloud/bookworm/latest/SHA512SUMS
## 下载云镜像 ## 下载云镜像
$ wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2 $ wget https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-generic-amd64.qcow2
## 检查文件是否存在 ## 检查文件是否存在
$ ls -lah $ ls -lah
@@ -116,34 +116,42 @@ $ ls -lah
$ cat SHA512SUMS $ cat SHA512SUMS
## 计算文件 hash ## 计算文件 hash
$ sha512sum debian-12-genericcloud-amd64.qcow2 $ sha512sum debian-12-generic-amd64.qcow2
``` ```
确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1001` 确认无误后,将镜像文件导入刚才创建的虚拟机,命令中的 `VM ID` 需要根据实际情况替换,演示为 `1001`
```bash ```bash
## 将 qcow2 镜像导入虚拟机中 ## 将 qcow2 镜像导入虚拟机中
$ qm importdisk 1001 debian-12-genericcloud-amd64.qcow2 local-lvm $ qm importdisk 1001 debian-12-generic-amd64.qcow2 local-lvm
#### 镜像导入示例输出 #### 镜像导入示例输出
Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0' unused0: successfully imported disk 'local-lvm:vm-1001-disk-0'
``` ```
磁盘导入成功后,虚拟机硬件列表中将显示一块未使用的磁盘设备,可鼠标 **双击** 该设备进行配置调整。
![虚拟机新磁盘](img/p04/vm_unused_hd.jpeg) ![虚拟机新磁盘](img/p04/vm_unused_hd.jpeg)
鼠标 **双击** 该未使用的磁盘,点击 `添加` 当宿主机使用 `SSD` 作为物理存储设备,并且虚拟磁盘采用 `精简置备` Thin Provisioning 模式时,可考虑开启以下选项:
- `丢弃` (Discard) 选项,有助于存储空间回收。
- `SSD仿真` SSD Emulation) 选项,让虚拟机将虚拟磁盘视为 `SSD` 存储设备。
在弹出的对话框中,确认 `IO thread` 选项为 **勾选** 状态,并点击 `添加`
![虚拟机使用该磁盘](img/p04/vm_enable_hd.jpeg) ![虚拟机使用该磁盘](img/p04/vm_enable_hd.jpeg)
导入的镜像只有 `2G` 磁盘空间,为了后续方便使用,需要对磁盘进行扩容。 导入的镜像只有 `3G` 磁盘空间,为了后续方便使用,需要对磁盘进行扩容。
鼠标 **单击** 选中该磁盘,选择页面顶部 `磁盘操作` 菜单的子菜单 `调整大小` 鼠标 **单击** 选中该磁盘,选择页面顶部 `磁盘操作` 菜单的子菜单 `调整大小`
![虚拟机磁盘扩容](img/p04/vm_hd_resize.jpeg) ![虚拟机磁盘扩容](img/p04/vm_hd_resize.jpeg)
在弹出的对话框中,给该磁盘增加 `18G` 磁盘空间。 在弹出的对话框中,给该磁盘增加 `21G` 磁盘空间。
![虚拟机磁盘增加18G](img/p04/vm_hd_18g.jpeg) ![虚拟机磁盘增加18G](img/p04/vm_hd_scale_up.jpeg)
### 2.3.添加 CloudInit ### 2.3.添加 CloudInit
@@ -203,7 +211,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0'
|--|--|--| |--|--|--|
|用户|`fox`|新系统的管理员账户| |用户|`fox`|新系统的管理员账户|
|密码|`********`|使用强密码| |密码|`********`|使用强密码|
|DNS域|`fox.home.arpa`|内网域名(可选)| |DNS域|`fox.internal`|内网域名(可选)|
|DNS服务器|`172.16.1.1`|本机 DNS 服务器| |DNS服务器|`172.16.1.1`|本机 DNS 服务器|
|SSH公钥|`无`|使用秘钥登录服务器,暂不使用| |SSH公钥|`无`|使用秘钥登录服务器,暂不使用|
|Upgrade packages|`是`|启动时更新软件包,保持默认即可| |Upgrade packages|`是`|启动时更新软件包,保持默认即可|
@@ -231,7 +239,7 @@ Successfully imported disk as 'unused0:local-lvm:vm-1001-disk-0'
|参数|值|说明| |参数|值|说明|
|--|--|--| |--|--|--|
|DNS域|`fox.home.arpa`|内网域名(可选)| |DNS域|`fox.internal`|内网域名(可选)|
|DNS服务器|`172.16.1.1 fdac::1`|本机 DNS 服务器| |DNS服务器|`172.16.1.1 fdac::1`|本机 DNS 服务器|
|IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置| |IP配置(net0)|`ip=172.16.1.250/24,gw=172.16.1.1,ip6=fdac::fa/64`|模板的 IP 设置|
+63 -61
View File
@@ -21,8 +21,8 @@
- 保存文件,按下键盘 `Esc` 键,退出编辑模式,再输入组合键 `:wq` 即可保存。 - 保存文件,按下键盘 `Esc` 键,退出编辑模式,再输入组合键 `:wq` 即可保存。
```bash ```bash
## 编辑 ssh 配置文件 ## 编辑 SSH 配置文件
$ sudo vim /etc/ssh/sshd_config.d/server_sshd.conf $ sudo vim /etc/ssh/sshd_config.d/10-server-sshd.conf
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
@@ -39,17 +39,17 @@ UseDNS no
修改完成后,需要重启 SSH 服务。 修改完成后,需要重启 SSH 服务。
```bash ```bash
## 重启 sshd ## 重启 ssh.service
$ sudo systemctl restart ssh.service $ sudo systemctl restart ssh.service
``` ```
### 1.2.配置软件源 ### 1.2.配置软件源
使用 SSH 工具登录模板虚拟机,常用 SSH 工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。 使用终端工具登录模板虚拟机,常用终端工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。
首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](http://mirrors.ustc.edu.cn/help/debian.html) 镜像站作为演示。 首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](https://mirrors.ustc.edu.cn) 镜像站作为演示。
当系统版本发生变化时,请参考使用 snullp 大叔开发的 [配置生成器](https://mirrors.ustc.edu.cn/repogen/) 。 当系统版本发生变化时,请参考 USTC 镜像站的官方说明 [USTC Mirror Help - Debian](https://mirrors.ustc.edu.cn/help/debian.html) 。
Debian12 云镜像的软件源配置采用了 `DEB822` 格式,新版 `sources.list` 配置文件内容如下。 Debian12 云镜像的软件源配置采用了 `DEB822` 格式,新版 `sources.list` 配置文件内容如下。
@@ -89,7 +89,6 @@ $ cat /etc/apt/mirrors/debian-security.list
#### 关联配置文件示例输出 (关联部分 2 ) #### 关联配置文件示例输出 (关联部分 2 )
https://deb.debian.org/debian-security https://deb.debian.org/debian-security
``` ```
因此,修改 Debian12 软件源的方式也有两种,本文将尝试使用第 `2` 种修改方案。 因此,修改 Debian12 软件源的方式也有两种,本文将尝试使用第 `2` 种修改方案。
@@ -143,20 +142,20 @@ $ lsattr /etc/apt/sources.list.d/debian.sources
```bash ```bash
## 清理不必要的包 ## 清理不必要的包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge $ sudo bash -c 'apt clean && apt autoclean && apt autoremove --purge'
## 更新软件源 ## 更新软件源
$ sudo apt update $ sudo apt update
## 更新系统 ## 更新系统
$ sudo apt dist-upgrade $ sudo apt full-upgrade
``` ```
接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。 接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。
```bash ```bash
## 安装系统软件 ## 安装系统软件
$ sudo apt install qemu-guest-agent zsh git htop tmux cron nftables sshguard neovim $ sudo apt install qemu-guest-agent zsh git btop tmux logrotate cron nftables sshguard neovim
## 安装系统自动更新工具 ## 安装系统自动更新工具
$ sudo apt install unattended-upgrades powermgmt-base python3-gi $ sudo apt install unattended-upgrades powermgmt-base python3-gi
@@ -168,7 +167,27 @@ $ sudo apt install iperf iperf3 iftop lsof knot-dnsutils
$ sudo sync $ sudo sync
``` ```
### 1.4.调整内核参数 ### 1.4.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 使用清华大学镜像站安装 oh-my-zsh
$ cd && git clone --depth=1 https://mirrors.tuna.tsinghua.edu.cn/git/ohmyzsh.git
$ cd ohmyzsh/tools && REMOTE=https://mirrors.tuna.tsinghua.edu.cn/git/ohmyzsh.git sh install.sh
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
## oh-my-zsh 安装后清理
$ cd && rm -rvf ohmyzsh .bash_history .zsh_history .shell.pre-oh-my-zsh
```
### 1.5.调整内核参数
由于该 Debian 虚拟机模板将用于克隆内网 DNS 服务器,因此需要调整内核参数来简单优化性能。 由于该 Debian 虚拟机模板将用于克隆内网 DNS 服务器,因此需要调整内核参数来简单优化性能。
@@ -188,22 +207,27 @@ $ sudo nvim /etc/sysctl.d/99-sysctl.conf
kernel.panic = 20 kernel.panic = 20
kernel.panic_on_oops = 1 kernel.panic_on_oops = 1
net.core.default_qdisc = fq net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr net.ipv4.tcp_congestion_control = cubic
# Other adjustable system parameters # Other adjustable system parameters
net.core.netdev_budget = 600 net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000 net.core.netdev_budget_usecs = 20000
net.ipv4.conf.all.log_martians = 1 net.core.somaxconn = 8192
net.core.rmem_max = 26214400
net.core.wmem_max = 655360
net.ipv4.igmp_max_memberships = 256 net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_challenge_ack_limit = 1000 net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fastopen = 3
net.ipv4.tcp_fin_timeout = 30 net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120 net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 4096 87380 26214400
net.ipv4.tcp_wmem = 4096 16384 655360
net.ipv6.conf.all.use_tempaddr = 0 net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0 net.ipv6.conf.default.use_tempaddr = 0
@@ -217,7 +241,7 @@ net.ipv6.conf.default.use_tempaddr = 0
$ sudo sysctl -f $ sudo sysctl -f
``` ```
### 1.5.调整系统时间 ### 1.6.调整系统时间
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。 默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
@@ -237,27 +261,28 @@ Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需
调整 NTP 服务器参数,执行以下命令。 调整 NTP 服务器参数,执行以下命令。
```bash ```bash
## 创建 NTP 配置文件的目录 ## 创建 NTP 配置目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d $ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件 ## 创建 NTP 配置文件
$ sudo nvim /etc/systemd/timesyncd.conf.d/server_ntp.conf $ sudo nvim /etc/systemd/timesyncd.conf.d/10-server-ntp.conf
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
```bash ```bash
## NTP 配置项 # This configuration file is customized by fox,
# Optimize system NTP server.
[Time] [Time]
NTP=ntp.tencent.com ntp.aliyun.com NTP=ntp.aliyun.com ntp.tencent.com cn.pool.ntp.org
``` ```
保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。 保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。
```bash ```bash
## 重启 chrony 服务 ## 重启 systemd-timesyncd.service
$ sudo systemctl restart systemd-timesyncd.service $ sudo systemctl restart systemd-timesyncd.service
## 检查系统 NTP 服务器 ## 检查系统 NTP 服务器
@@ -270,23 +295,23 @@ $ sudo systemctl status systemd-timesyncd.service
#### NTP 服务示例输出 #### NTP 服务示例输出
● systemd-timesyncd.service - Network Time Synchronization ● systemd-timesyncd.service - Network Time Synchronization
Loaded: loaded (/lib/systemd/system/systemd-timesyncd.service; enabled; preset: enabled) Loaded: loaded (/lib/systemd/system/systemd-timesyncd.service; enabled; preset: enabled)
Active: active (running) since Mon 2023-06-26 16:16:00 CST; 16s ago Active: active (running) since Mon 2024-10-07 18:06:29 CST; 9s ago
Docs: man:systemd-timesyncd.service(8) Docs: man:systemd-timesyncd.service(8)
Main PID: 18829 (systemd-timesyn) Main PID: 1706 (systemd-timesyn)
Status: "Contacted time server 106.55.184.199:123 (ntp.tencent.com)." Status: "Contacted time server 203.107.6.88:123 (ntp.aliyun.com)."
Tasks: 2 (limit: 2355) Tasks: 2 (limit: 2315)
Memory: 1.4M Memory: 1.4M
CPU: 37ms CPU: 113ms
CGroup: /system.slice/systemd-timesyncd.service CGroup: /system.slice/systemd-timesyncd.service
└─18829 /lib/systemd/systemd-timesyncd └─1706 /lib/systemd/systemd-timesyncd
Jun 26 16:48:00 DNST01 systemd[1]: Starting systemd-timesyncd.service - Network Time Synchronization... Oct 07 18:06:29 DNS01 systemd[1]: Starting systemd-timesyncd.service - Network Time Synchronization...
Jun 26 16:48:00 DNST01 systemd[1]: Started systemd-timesyncd.service - Network Time Synchronization. Oct 07 18:06:29 DNS01 systemd[1]: Started systemd-timesyncd.service - Network Time Synchronization.
Jun 26 16:48:00 DNST01 systemd-timesyncd[18829]: Contacted time server 106.55.184.199:123 (ntp.tencent.com). Oct 07 18:06:29 DNS01 systemd-timesyncd[1706]: Contacted time server 203.107.6.88:123 (ntp.aliyun.com).
Jun 26 16:48:00 DNST01 systemd-timesyncd[18829]: Initial clock synchronization to Mon 2023-06-26 16:16:16.000000 CST. Oct 07 18:06:29 DNS01 systemd-timesyncd[1706]: Initial clock synchronization to Mon 2024-10-07 18:06:29.499548 CST.
``` ```
### 1.6.配置自动更新 ### 1.7.配置自动更新
配置 Debian 云镜像的系统自动更新,与配置 PVE 系统自动更新方法基本一致,参阅 [03.PVE系统调整](./03.PVE系统调整.md) 。 配置 Debian 云镜像的系统自动更新,与配置 PVE 系统自动更新方法基本一致,参阅 [03.PVE系统调整](./03.PVE系统调整.md) 。
@@ -303,10 +328,8 @@ $ sudo systemctl status apt-daily-upgrade.timer
## 配置自动更新策略 ## 配置自动更新策略
$ sudo dpkg-reconfigure -plow unattended-upgrades $ sudo dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”) ## 选择 “是”
<Yes>
#### 系统自动更新示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
``` ```
进一步调整 `20auto-upgrades` 配置文件。 进一步调整 `20auto-upgrades` 配置文件。
@@ -393,7 +416,7 @@ $ sudo systemctl restart apt-daily-upgrade.timer
$ sudo systemctl status apt-daily-upgrade.timer $ sudo systemctl status apt-daily-upgrade.timer
``` ```
### 1.7.配置定时任务 ### 1.8.配置定时任务
本步骤为可选操作,主要设置系统定时重启。 本步骤为可选操作,主要设置系统定时重启。
@@ -414,40 +437,19 @@ $ sudo crontab -e
``` ```
### 1.8.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 返回 home 目录
$ cd
## 使用 curl 安装 oh-my-zsh
$ sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)"
## 或者使用 wget 安装 oh-my-zsh
$ sh -c "$(wget https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh -O -)"
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
```
### 1.9.清理系统 ### 1.9.清理系统
Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。 Debian 模板虚拟机已经配置完成,在将其转换为模板前需要对系统进行清理。
```bash ```bash
## 清理系统软件包 ## 清理系统软件包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge $ sudo bash -c 'apt clean && apt autoclean && apt autoremove --purge'
## 清理系统缓存 ## 清理系统缓存
$ sudo rm -rvf /var/cache/apt/* /var/lib/apt/lists/* /tmp/* $ sudo bash -c 'find /var/cache/apt/ /var/cache/smartdns/ /var/lib/apt/lists/ /tmp/ -type f -print -delete'
## 清理系统日志 ## 清理系统日志
$ sudo find /var/log/ -type f | xargs sudo rm -rvf $ sudo bash -c 'find /var/log/ -type f -print -delete'
## 清理命令历史记录文件 ## 清理命令历史记录文件
$ rm -rvf ~/.bash_history ~/.zsh_history ~/.zcompdump* && history -c $ rm -rvf ~/.bash_history ~/.zsh_history ~/.zcompdump* && history -c
+79 -92
View File
@@ -65,13 +65,13 @@
`启动/关机顺序``2` ,表示该虚拟机第 `2` 个启动,倒数第 `2` 个关机。 `启动/关机顺序``2` ,表示该虚拟机第 `2` 个启动,倒数第 `2` 个关机。
`启动延时``10` ,表示该虚拟机在 PVE 启动后,延迟 `10`后自动启动 `启动延时``15` ,表示该虚拟机启动后,延迟 `15`再启动下一个虚拟机
![克隆虚拟机自动启动顺序](img/p06/vm_clone_autostart_order.jpeg) ![克隆虚拟机自动启动顺序](img/p06/vm_clone_autostart_order.jpeg)
## 4.调整系统端口 ## 4.调整系统端口
设置完成后,将该虚拟机开机,使用 SSH 工具登录,并执行以下命令检查端口占用。 设置完成后,将该虚拟机开机,使用终端工具登录,并执行以下命令检查端口占用。
```bash ```bash
## 检查 53 端口占用 ## 检查 53 端口占用
@@ -94,13 +94,14 @@ systemd-r 1797 systemd-resolve 21u IPv4 23027 0t0 TCP 127.0.0.54:domai
$ sudo mkdir -p /etc/systemd/resolved.conf.d $ sudo mkdir -p /etc/systemd/resolved.conf.d
## 创建 systemd-resolved 配置文件 ## 创建 systemd-resolved 配置文件
$ sudo nvim /etc/systemd/resolved.conf.d/server_dns.conf $ sudo nvim /etc/systemd/resolved.conf.d/10-server-dns.conf
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
```bash ```bash
## systemd-resolved 配置项 # This configuration file is customized by fox,
# Optimize system resolve parameters for local DNS server.
[Resolve] [Resolve]
DNS=127.0.0.1 DNS=127.0.0.1
@@ -215,10 +216,10 @@ $ mkdir -p /tmp/SmartDNS
$ cd /tmp/SmartDNS $ cd /tmp/SmartDNS
## 下载 SmartDNS 安装包 ## 下载 SmartDNS 安装包
$ curl -LR -O https://github.com/pymumu/smartdns/releases/download/Release45/smartdns.1.2024.02.08-0828.x86_64-linux-all.tar.gz $ curl -LR -O https://github.com/pymumu/smartdns/releases/download/Release46/smartdns.1.2024.06.12-2222.x86_64-linux-all.tar.gz
## 解压缩 SmartDNS 安装包 ## 解压缩 SmartDNS 安装包
$ tar zxf smartdns.1.2024.02.08-0828.x86_64-linux-all.tar.gz $ tar zxf smartdns.1.2024.06.12-2222.x86_64-linux-all.tar.gz
## 进入安装包目录 ## 进入安装包目录
$ cd smartdns $ cd smartdns
@@ -247,11 +248,11 @@ $ sudo systemctl enable smartdns.service
若需使用 `SmartDNS` 屏蔽广告,则需下载广告规则配置文件。 若需使用 `SmartDNS` 屏蔽广告,则需下载广告规则配置文件。
```bash ```bash
## 创建 SmartDNS 配置文件目录 ## 创建 SmartDNS 配置目录
$ sudo mkdir -p /etc/smartdns.d $ sudo mkdir -p /etc/smartdns.d
## 下载广告规则配置文件 ## 下载广告规则配置文件
$ sudo curl -LR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf $ sudo curl -LR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
``` ```
`SmartDNS` 的加速规则通过 `bash` 脚本安装,脚本生成的配置文件位于 `/etc/smartdns.d` 目录。 `SmartDNS` 的加速规则通过 `bash` 脚本安装,脚本生成的配置文件位于 `/etc/smartdns.d` 目录。
@@ -260,19 +261,49 @@ $ sudo curl -LR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/sma
```bash ```bash
## 下载加速规则安装脚本 ## 下载加速规则安装脚本
$ sudo curl -LR -o /opt/smartdns_plugin.sh https://gitee.com/callmer/smartdns_china_list_installer/raw/main/smartdns_plugin.sh $ sudo curl -LR -o /opt/smartdns-plugin.sh https://gitee.com/callmer/smartdns_china_list_installer/raw/main/smartdns_plugin.sh
## 设置脚本可执行权限 ## 设置脚本可执行权限
$ sudo chmod +x /opt/smartdns_plugin.sh $ sudo chmod +x /opt/smartdns-plugin.sh
## 设置脚本文件防篡改 ## 设置脚本文件防篡改
$ sudo chattr +i /opt/smartdns_plugin.sh $ sudo chattr +i /opt/smartdns-plugin.sh
## 执行脚本 ## 执行脚本
$ sudo bash /opt/smartdns_plugin.sh $ sudo bash /opt/smartdns-plugin.sh
``` ```
### 6.2. SmartDNS 主配置 ### 6.2.定时任务
本步骤为可选操作,主要用于设置 `SmartDNS` 定时更新附加配置文件和定时重启。
```bash
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
30 9 * * * /usr/bin/systemctl restart smartdns.service
```
若使用了 `SmartDNS` 加速规则的安装脚本,由于脚本自带服务重启功能,因此定时任务可修改如下。
```bash
## 定时任务配置项
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
30 9 * * * /usr/bin/bash /opt/smartdns-plugin.sh
```
### 6.3. SmartDNS 主配置
`SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/) 。 `SmartDNS` 配置较为复杂,可按需制定各类 DNS 请求规则,建议先查阅官方提供的 [配置指导](https://pymumu.github.io/smartdns/config/basic-config/) 和 [配置选项](https://pymumu.github.io/smartdns/configuration/) 。
@@ -282,9 +313,6 @@ $ sudo bash /opt/smartdns_plugin.sh
## 关闭 smartdns.service ## 关闭 smartdns.service
$ sudo systemctl stop smartdns.service $ sudo systemctl stop smartdns.service
## 清理缓存
$ sudo rm -rvf /var/cache/smartdns
## 清理进程标识文件 ## 清理进程标识文件
$ sudo rm -rvf /var/run/smartdns.pid /run/smartdns.pid $ sudo rm -rvf /var/run/smartdns.pid /run/smartdns.pid
``` ```
@@ -307,12 +335,8 @@ $ sudo nvim /etc/smartdns/smartdns.conf
**额外说明:** **额外说明:**
- 由于修改了缓存路径,`SmartDNS` 的缓存将在系统重启时自动删除,请根据实际情况进行调整
- `SmartDNS` 端口监听参数为 `6053@lo` ,请根据实际情况进行调整 - `SmartDNS` 端口监听参数为 `6053@lo` ,请根据实际情况进行调整
- `edns-client-subnet` 为 EDNS 客户端子网,演示中 `202.103.24.68` 为湖北武汉市 DNS 服务器地址,请根据实际情况进行调整
- 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整 - 检查配置文件中关于本地域名及其上游 DNS 服务器相关配置,请根据实际情况进行调整
```bash ```bash
@@ -324,49 +348,42 @@ $ sudo nvim /etc/smartdns/smartdns.conf
# your network environment. # your network environment.
# #
# eg: # eg:
# server 119.29.29.29
# server 223.5.5.5 # server 223.5.5.5
# server 180.184.1.1
# server 119.29.29.29
# server 114.114.114.114 # server 114.114.114.114
# server 2402:4e00:: # server 2402:4e00::
# server 2400:3200::1 # server 2400:3200::1
conf-file /etc/smartdns.d/adrules.smartdns.conf conf-file /etc/smartdns.d/*.conf
conf-file /etc/smartdns.d/dns-group.china.smartdns.conf
conf-file /etc/smartdns.d/apple.china.smartdns.conf
conf-file /etc/smartdns.d/google.china.smartdns.conf
conf-file /etc/smartdns.d/accelerated-domains.china.smartdns.conf
conf-file /etc/smartdns.d/bogus-nxdomain.china.smartdns.conf
cache-file /tmp/smartdns.cache
log-level notice log-level notice
bind [::]:6053@lo bind [::]:6053@lo
bind-tcp [::]:6053@lo bind-tcp [::]:6053@lo
serve-expired yes cache-size 32768
serve-expired-ttl 64800
serve-expired-reply-ttl 3
prefetch-domain yes
serve-expired-prefetch-time 21600
force-qtype-SOA 65
max-query-limit 1024 max-query-limit 1024
edns-client-subnet 202.103.24.68 max-reply-ip-num 24
server-tcp 119.29.29.29 -group dnspod -exclude-default-group prefetch-domain yes
server-tcp 2402:4e00:: -group dnspod -exclude-default-group
nameserver /doh.pub/dnspod
nameserver /dot.pub/dnspod
server-tcp 223.5.5.5 -group alidns -exclude-default-group serve-expired yes
server-tcp 2400:3200::1 -group alidns -exclude-default-group serve-expired-ttl 129600
nameserver /dns.alidns.com/alidns serve-expired-reply-ttl 30
serve-expired-prefetch-time 28800
rr-ttl-min 60
rr-ttl-max 28800
rr-ttl-reply-max 14400
server 172.16.1.1 -group intranet -exclude-default-group server 172.16.1.1 -group intranet -exclude-default-group
nameserver /fox.home.arpa/intranet nameserver /internal/intranet
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache domain-rules /internal/ -speed-check-mode none -no-cache
server-tcp 180.184.1.1 -bootstrap-dns
server-tcp 114.114.114.114 -bootstrap-dns
server-tcp 2400:3200::1 -bootstrap-dns
server-tls dot.pub server-tls dot.pub
server-tls dns.alidns.com server-tls dns.alidns.com
@@ -376,50 +393,20 @@ server-https https://dns.alidns.com/dns-query
``` ```
### 6.3.定时任务
本步骤为可选操作,主要用于设置 `SmartDNS` 定时更新附加配置文件和定时重启。
```bash
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
30 9 * * * /usr/bin/systemctl restart smartdns.service
```
若使用了 `SmartDNS` 加速规则的安装脚本,由于脚本自带服务重启功能,因此定时任务可修改如下。
```bash
## 定时任务配置项
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf
30 9 * * * /usr/bin/bash /opt/smartdns_plugin.sh
```
### 6.4.配置 Dnsmasq ### 6.4.配置 Dnsmasq
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份 `Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令。
```bash ```bash
## 备份 Dnsmasq 配置文件 ## 创建 Dnsmasq 配置目录
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak $ sudo mkdir -p /etc/dnsmasq.d
``` ```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。 使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash ```bash
## 创建 Dnsmasq 主配置文件 ## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf $ sudo nvim /etc/dnsmasq.d/10-server-dnsmasq.conf
``` ```
在编辑器对话框中输入以下内容,并保存。 在编辑器对话框中输入以下内容,并保存。
@@ -428,7 +415,7 @@ $ sudo nvim /etc/dnsmasq.conf
- 请根据系统内存使用情况,调整缓存参数 `cache-size` - 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整 - 配置文件中内网域名为 `fox.internal` ,请根据实际情况进行调整
- `Dnsmasq` 有且仅有 `SmartDNS` 作为上游 DNS 服务器 - `Dnsmasq` 有且仅有 `SmartDNS` 作为上游 DNS 服务器
@@ -444,16 +431,16 @@ conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log log-facility=/var/log/dnsmasq.log
log-async=20 log-async=20
cache-size=1024 cache-size=2048
max-cache-ttl=7200 max-cache-ttl=7200
edns-packet-max=1232 fast-dns-retry=1800
rebind-domain-ok=/fox.home.arpa/
interface=eth0
rebind-domain-ok=/fox.internal/
bind-dynamic bind-dynamic
bogus-priv bogus-priv
domain-needed domain-needed
localise-queries
local-service
no-hosts no-hosts
no-negcache no-negcache
no-resolv no-resolv
@@ -464,12 +451,12 @@ stop-dns-rebind
# DNS Filter # DNS Filter
server=/alt/ server=/alt/
server=/home.arpa/
server=/ipv4only.arpa/
server=/resolver.arpa/
server=/example/
server=/bind/ server=/bind/
server=/example/
server=/home.arpa/
server=/internal/
server=/invalid/ server=/invalid/
server=/lan/
server=/local/ server=/local/
server=/localhost/ server=/localhost/
server=/onion/ server=/onion/
@@ -477,7 +464,7 @@ server=/test/
# DNS Server # DNS Server
server=/fox.home.arpa/172.16.1.1 server=/fox.internal/172.16.1.1
server=127.0.0.1#6053 server=127.0.0.1#6053
server=::1#6053 server=::1#6053
+110 -74
View File
@@ -11,7 +11,7 @@
|参数|值|说明| |参数|值|说明|
|--|--|--| |--|--|--|
|虚拟机名称|`SVR01`| TS 服务器 `主机名` | |虚拟机名称|`SVR01`| TS 服务器 `主机名` |
|DNS 域|`fox.home.arpa`| TS 服务器 `Cloud-Init` | |DNS 域|`fox.internal`| TS 服务器 `Cloud-Init` |
|DNS 服务器|`172.16.1.1`| TS 服务器 `Cloud-Init` | |DNS 服务器|`172.16.1.1`| TS 服务器 `Cloud-Init` |
|IPv4|`172.16.1.4/24`| TS 服务器 `Cloud-Init` | |IPv4|`172.16.1.4/24`| TS 服务器 `Cloud-Init` |
|IPv4 网关|`172.16.1.1`| TS 服务器 `Cloud-Init` | |IPv4 网关|`172.16.1.1`| TS 服务器 `Cloud-Init` |
@@ -28,8 +28,8 @@
在虚拟机的命令行界面,使用 `vim` 编辑器编辑 `sshd` 服务的配置文件,执行以下命令。 在虚拟机的命令行界面,使用 `vim` 编辑器编辑 `sshd` 服务的配置文件,执行以下命令。
```bash ```bash
## 编辑 ssh 配置文件 ## 编辑 SSH 配置文件
$ sudo vim /etc/ssh/sshd_config.d/server_sshd.conf $ sudo vim /etc/ssh/sshd_config.d/10-server-sshd.conf
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
@@ -46,17 +46,17 @@ UseDNS no
修改完成后,需要重启 SSH 服务。 修改完成后,需要重启 SSH 服务。
```bash ```bash
## 重启 sshd ## 重启 ssh.service
$ sudo systemctl restart ssh.service $ sudo systemctl restart ssh.service
``` ```
### 1.2.配置软件源 ### 1.2.配置软件源
使用 SSH 工具登录 TS 服务器,常用 SSH 工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。 使用终端工具登录 TS 服务器,常用终端工具请参阅 [01.PVE系统安装](./01.PVE系统安装.md) 。
首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](http://mirrors.ustc.edu.cn/help/debian.html) 镜像站作为演示。 首先需要对 Debian 系统软件源进行修改,这里使用 [USTC](https://mirrors.ustc.edu.cn) 镜像站作为演示。
当系统版本发生变化时,请参考使用 snullp 大叔开发的 [配置生成器](https://mirrors.ustc.edu.cn/repogen/) 。 当系统版本发生变化时,请参考 USTC 镜像站的官方说明 [USTC Mirror Help - Debian](https://mirrors.ustc.edu.cn/help/debian.html) 。
使用 `vim` 编辑器编辑 `debian.sources` 配置文件,执行以下命令。 使用 `vim` 编辑器编辑 `debian.sources` 配置文件,执行以下命令。
@@ -113,20 +113,20 @@ $ curl -fsSL https://pkgs.tailscale.com/stable/debian/bookworm.tailscale-keyring
```bash ```bash
## 清理不必要的包 ## 清理不必要的包
$ sudo apt clean && sudo apt autoclean && sudo apt autoremove --purge $ sudo bash -c 'apt clean && apt autoclean && apt autoremove --purge'
## 更新软件源 ## 更新软件源
$ sudo apt update $ sudo apt update
## 更新系统 ## 更新系统
$ sudo apt dist-upgrade $ sudo apt full-upgrade
``` ```
接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。 接下来安装系统必要软件,安装 `iperf3` 后,系统将询问是否将其作为系统服务开机自启,选择 `no` 即可。
```bash ```bash
## 安装系统软件 ## 安装系统软件
$ sudo apt install qemu-guest-agent zsh git htop tmux cron nftables sshguard neovim $ sudo apt install qemu-guest-agent zsh git btop tmux logrotate cron nftables sshguard neovim
## 安装系统自动更新工具 ## 安装系统自动更新工具
$ sudo apt install unattended-upgrades powermgmt-base python3-gi $ sudo apt install unattended-upgrades powermgmt-base python3-gi
@@ -141,13 +141,33 @@ $ sudo apt install tailscale
$ sudo sync $ sudo sync
``` ```
### 1.4.调整内核模块 ### 1.4.配置 ZSH
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 使用清华大学镜像站安装 oh-my-zsh
$ cd && git clone --depth=1 https://mirrors.tuna.tsinghua.edu.cn/git/ohmyzsh.git
$ cd ohmyzsh/tools && REMOTE=https://mirrors.tuna.tsinghua.edu.cn/git/ohmyzsh.git sh install.sh
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
## oh-my-zsh 安装后清理
$ cd && rm -rvf ohmyzsh .bash_history .zsh_history .shell.pre-oh-my-zsh
```
### 1.5.调整内核模块
使用 `neovim` 编辑器编辑 **内核模块** 配置文件,执行以下命令。 使用 `neovim` 编辑器编辑 **内核模块** 配置文件,执行以下命令。
```bash ```bash
## 创建 内核模块 配置文件 ## 创建 内核模块 配置文件
$ sudo nvim /etc/modules-load.d/server_modules.conf $ sudo nvim /etc/modules-load.d/10-server-modules.conf
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
@@ -160,7 +180,7 @@ nf_conntrack
``` ```
### 1.5.调整内核参数 ### 1.6.调整内核参数
使用 `neovim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。 使用 `neovim` 编辑器编辑 **内核参数** 配置文件,执行以下命令。
@@ -192,6 +212,9 @@ net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000 net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768 net.core.rps_sock_flow_entries = 32768
net.core.somaxconn = 8192
net.core.rmem_max = 26214400
net.core.wmem_max = 655360
net.ipv4.conf.all.accept_redirects = 0 net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0 net.ipv4.conf.default.accept_redirects = 0
@@ -205,7 +228,8 @@ net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2 net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2 net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1 net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.igmp_max_memberships = 256 net.ipv4.igmp_max_memberships = 256
@@ -216,12 +240,12 @@ net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048 net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_challenge_ack_limit = 1000 net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fastopen = 3
net.ipv4.tcp_fin_timeout = 30 net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120 net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 4096 87380 26214400
net.ipv6.conf.all.accept_ra = 0 net.ipv4.tcp_wmem = 4096 16384 655360
net.ipv6.conf.default.accept_ra = 0
net.ipv6.conf.all.accept_redirects = 0 net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0 net.ipv6.conf.default.accept_redirects = 0
@@ -245,7 +269,7 @@ net.netfilter.nf_conntrack_tcp_timeout_established = 7440
$ sudo sysctl -f $ sudo sysctl -f
``` ```
### 1.6.调整系统时间 ### 1.7.调整系统时间
默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。 默认情况下 Debian 云镜像的系统时间需要调整,执行以下命令将系统时区设置为中国时区。
@@ -262,34 +286,35 @@ Debian 云镜像默认使用 `systemd-timesyncd.service` 同步时间,且需
调整 NTP 服务器参数,执行以下命令。 调整 NTP 服务器参数,执行以下命令。
```bash ```bash
## 创建 NTP 配置文件的目录 ## 创建 NTP 配置目录
$ sudo mkdir -p /etc/systemd/timesyncd.conf.d $ sudo mkdir -p /etc/systemd/timesyncd.conf.d
## 创建 NTP 配置文件 ## 创建 NTP 配置文件
$ sudo nvim /etc/systemd/timesyncd.conf.d/server_ntp.conf $ sudo nvim /etc/systemd/timesyncd.conf.d/10-server-ntp.conf
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
```bash ```bash
## NTP 配置项 # This configuration file is customized by fox,
# Optimize system NTP server.
[Time] [Time]
NTP=ntp.tencent.com ntp.aliyun.com NTP=ntp.aliyun.com ntp.tencent.com cn.pool.ntp.org
``` ```
保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。 保存该配置文件后,需重启 `systemd-timesyncd.service` 服务,并再次检查系统 NTP 服务器地址。
```bash ```bash
## 重启 chrony 服务 ## 重启 systemd-timesyncd.service
$ sudo systemctl restart systemd-timesyncd.service $ sudo systemctl restart systemd-timesyncd.service
## 检查系统 NTP 服务器 ## 检查系统 NTP 服务器
$ sudo systemctl status systemd-timesyncd.service $ sudo systemctl status systemd-timesyncd.service
``` ```
### 1.7.配置自动更新 ### 1.8.配置自动更新
配置系统自动更新策略,执行以下命令,使用键盘 `左右方向键` 进行选择,`回车键` 进行确认。 配置系统自动更新策略,执行以下命令,使用键盘 `左右方向键` 进行选择,`回车键` 进行确认。
@@ -297,10 +322,8 @@ $ sudo systemctl status systemd-timesyncd.service
## 配置自动更新策略 ## 配置自动更新策略
$ sudo dpkg-reconfigure -plow unattended-upgrades $ sudo dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”) ## 选择 “是”
<Yes>
#### 系统自动更新示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
``` ```
进一步调整 `20auto-upgrades` 配置文件。 进一步调整 `20auto-upgrades` 配置文件。
@@ -356,7 +379,7 @@ Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00"; Unattended-Upgrade::Automatic-Reboot-Time "13:00";
``` ```
@@ -374,7 +397,7 @@ $ sudo systemctl edit apt-daily-upgrade.timer
[Timer] [Timer]
OnCalendar= OnCalendar=
OnCalendar=02:00 OnCalendar=12:00
RandomizedDelaySec=0 RandomizedDelaySec=0
``` ```
@@ -391,7 +414,7 @@ $ sudo systemctl restart apt-daily-upgrade.timer
$ sudo systemctl status apt-daily-upgrade.timer $ sudo systemctl status apt-daily-upgrade.timer
``` ```
### 1.8.配置防火墙 ### 1.9.配置防火墙
修改防火墙配置之前,需检查 `nftables.service` 服务状态,确保该服务开机自启。 修改防火墙配置之前,需检查 `nftables.service` 服务状态,确保该服务开机自启。
@@ -422,7 +445,7 @@ $ sudo nvim /etc/nftables.conf
$ sudo systemctl restart nftables.service $ sudo systemctl restart nftables.service
``` ```
### 1.9.调整系统端口 ### 1.10.调整系统端口
为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。 为了正常使用 `53` 端口,需要对 `systemd-resolved.service` 进行配置,执行以下命令。
@@ -431,13 +454,14 @@ $ sudo systemctl restart nftables.service
$ sudo mkdir -p /etc/systemd/resolved.conf.d $ sudo mkdir -p /etc/systemd/resolved.conf.d
## 创建 systemd-resolved 配置文件 ## 创建 systemd-resolved 配置文件
$ sudo nvim /etc/systemd/resolved.conf.d/server_dns.conf $ sudo nvim /etc/systemd/resolved.conf.d/10-server-dns.conf
``` ```
在配置文件中添加以下配置项,并保存。 在配置文件中添加以下配置项,并保存。
```bash ```bash
## systemd-resolved 配置项 # This configuration file is customized by fox,
# Optimize system resolve parameters for local TS server.
[Resolve] [Resolve]
DNS=127.0.0.1 DNS=127.0.0.1
@@ -460,7 +484,7 @@ $ sudo ln -sf /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
$ sudo systemctl restart systemd-resolved.service $ sudo systemctl restart systemd-resolved.service
``` ```
### 1.10.配置 Dnsmasq ### 1.11.配置 Dnsmasq
检查 `dnsmasq.service` 服务状态,确保该服务开机自启。 检查 `dnsmasq.service` 服务状态,确保该服务开机自启。
@@ -472,18 +496,18 @@ $ sudo systemctl status dnsmasq.service
$ sudo systemctl enable dnsmasq.service $ sudo systemctl enable dnsmasq.service
``` ```
`Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令将其备份 `Dnsmasq` 的主配置文件一般位于 `/etc` 目录下,修改配置文件之前,执行以下命令。
```bash ```bash
## 备份 Dnsmasq 配置文件 ## 创建 Dnsmasq 配置目录
$ sudo mv /etc/dnsmasq.conf /etc/dnsmasq.conf.bak $ sudo mkdir -p /etc/dnsmasq.d
``` ```
使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。 使用 `neovim` 编辑器创建 `Dnsmasq` 主配置文件,执行以下命令。
```bash ```bash
## 创建 Dnsmasq 主配置文件 ## 创建 Dnsmasq 主配置文件
$ sudo nvim /etc/dnsmasq.conf $ sudo nvim /etc/dnsmasq.d/10-server-dnsmasq.conf
``` ```
在编辑器对话框中输入以下内容,并保存。 在编辑器对话框中输入以下内容,并保存。
@@ -492,11 +516,11 @@ $ sudo nvim /etc/dnsmasq.conf
- 请根据系统内存使用情况,调整缓存参数 `cache-size` - 请根据系统内存使用情况,调整缓存参数 `cache-size`
- 配置文件中内网域名为 `fox.home.arpa` ,请根据实际情况进行调整 - 配置文件中内网域名为 `fox.internal` ,请根据实际情况进行调整
- `Dnsmasq` 上游 DNS 服务器分为三类,请根据实际情况进行调整 - `Dnsmasq` 上游 DNS 服务器分为三类,请根据实际情况进行调整
- `server=/ts.net/100.100.100.100` TS 服务 `MagicDNS` 专用 DNS 服务器 - `server=/ts.net/100.100.100.100` TS 服务 `MagicDNS` 专用 DNS 服务器
- `server=/fox.home.arpa/172.16.1.1` :内网域名解析 DNS 服务器,通常为主路由地址 - `server=/fox.internal/172.16.1.1` :内网域名解析 DNS 服务器,通常为主路由地址
- `server` 参数中的其他 DNS 服务器供 TS 服务器自身及其下游设备使用 - `server` 参数中的其他 DNS 服务器供 TS 服务器自身及其下游设备使用
```bash ```bash
@@ -511,18 +535,19 @@ conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log log-facility=/var/log/dnsmasq.log
log-async=20 log-async=20
cache-size=1024 cache-size=2048
max-cache-ttl=7200 max-cache-ttl=7200
edns-packet-max=1232 fast-dns-retry=1800
rebind-domain-ok=/fox.home.arpa/
interface=eth0
rebind-domain-ok=/fox.internal/
bind-dynamic bind-dynamic
bogus-priv bogus-priv
domain-needed domain-needed
localise-queries
local-service
no-hosts no-hosts
no-negcache no-negcache
no-resolv
no-round-robin no-round-robin
rebind-localhost-ok rebind-localhost-ok
stop-dns-rebind stop-dns-rebind
@@ -530,12 +555,12 @@ stop-dns-rebind
# DNS Filter # DNS Filter
server=/alt/ server=/alt/
server=/home.arpa/
server=/ipv4only.arpa/
server=/resolver.arpa/
server=/example/
server=/bind/ server=/bind/
server=/example/
server=/home.arpa/
server=/internal/
server=/invalid/ server=/invalid/
server=/lan/
server=/local/ server=/local/
server=/localhost/ server=/localhost/
server=/onion/ server=/onion/
@@ -545,7 +570,7 @@ server=/test/
server=/ts.net/100.100.100.100 server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1 server=/fox.internal/172.16.1.1
server=172.16.1.1 server=172.16.1.1
@@ -558,31 +583,12 @@ server=172.16.1.1
$ sudo systemctl restart dnsmasq.service $ sudo systemctl restart dnsmasq.service
``` ```
### 1.11.配置 ZSH ## 2. Tailscale
`Zsh` 是比 `Bash` 好用的 `Shell` 程序,使用 `oh-my-zsh` 进行配置。
```bash
## 返回 home 目录
$ cd
## 使用 curl 安装 oh-my-zsh
$ sh -c "$(curl -fsSL https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh)"
## 或者使用 wget 安装 oh-my-zsh
$ sh -c "$(wget https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh -O -)"
## 询问是否切换默认 shell,输入 Y
#### 示例输出
Time to change your default shell to zsh:
Do you want to change your default shell to zsh? [Y/n] y
```
## 2.配置 Tailscale
根据不同的启动参数,TS 服务将具有不同的业务能力。 根据不同的启动参数,TS 服务将具有不同的业务能力。
### 2.1.启动模式
若仅需 TS 组网功能,执行以下命令。 若仅需 TS 组网功能,执行以下命令。
```bash ```bash
@@ -613,5 +619,35 @@ $ sudo tailscale up --advertise-exit-node --accept-routes --advertise-routes=172
执行命令后,TS 将自动显示登录链接,只需根据链接进行登录操作即可。 执行命令后,TS 将自动显示登录链接,只需根据链接进行登录操作即可。
### 2.2.自动更新
目前 TS 将跟随系统自动更新,若需额外开启 TS 的自动更新功能,执行以下命令。
```bash
## TS 开启自动更新
$ sudo tailscale set --auto-update
## TS 关闭自动更新
$ sudo tailscale set --auto-update=false
```
### 2.3.定时任务
本步骤为可选操作,主要用于设置 TS 定时重启。
```bash
## 编辑系统定时任务,编辑器选择 nano
$ sudo crontab -e
```
在配置文件末尾,增加以下配置项。
```bash
## 定时任务配置项
30 10 * * * /usr/bin/systemctl restart tailscaled.service
```
至此,TS 服务器已配置完成。 至此,TS 服务器已配置完成。
+9 -3
View File
@@ -18,13 +18,13 @@
|存储|`local`|选择存放备份文件的路径| |存储|`local`|选择存放备份文件的路径|
|计划|`*-01,16 03:30`|`备份作业` 执行的时间计划| |计划|`*-01,16 03:30`|`备份作业` 执行的时间计划|
|选择模式|`包括选中的VMs`|执行备份的虚拟机对象| |选择模式|`包括选中的VMs`|执行备份的虚拟机对象|
|通知模式|`默认(自动)`|执行备份时的通知模式,保持默认即可|
|发送邮箱至|`your_email@domain.com`|`备份作业` 邮件的收件人邮箱| |发送邮箱至|`your_email@domain.com`|`备份作业` 邮件的收件人邮箱|
|电子邮件|`始终通知`|何时发送 `备份作业` 邮件提醒| |发送邮件|`总是`|发送 `备份作业` 邮件提醒的条件|
|压缩|`ZSTD`|选择备份文件的压缩算法| |压缩|`ZSTD`|选择备份文件的压缩算法|
|模式|`停止`|选择备份虚拟机的方式,推荐使用 `停止` | |模式|`停止`|选择备份虚拟机的方式,推荐使用 `停止` |
|启用|**勾选**|表示该 `备份作业` 为启用状态| |启用|**勾选**|表示该 `备份作业` 为启用状态|
|作业评论|`Backup Your Server :)`|`备份作业` 的备注信息,使用英文输入| |作业评论|`Backup Your Server :)`|`备份作业` 的备注信息,使用英文输入|
|重复错过|**勾选**|表示当意外错过备份执行时间后,将重试备份|
**额外说明:** **额外说明:**
@@ -44,7 +44,7 @@
![备份作业保留选项](img/p08/vm_job_keep.jpeg) ![备份作业保留选项](img/p08/vm_job_keep.jpeg)
### 1.3.日志模板 ### 1.3.备注模板
该选项将按照设置的内容,自动重命名备份文件。 该选项将按照设置的内容,自动重命名备份文件。
@@ -54,6 +54,12 @@
![备份作业备注选项](img/p08/vm_job_notes.jpeg) ![备份作业备注选项](img/p08/vm_job_notes.jpeg)
### 1.4.高级选项
该选项提供 `备份作业` 进行时的高级可调参数,仅需勾选 `重复错过` 选项即可。
![备份作业高级选项](img/p08/vm_job_advanced.jpeg)
## 2.调度模拟器 ## 2.调度模拟器
在创建完成 `备份作业` 后,可以使用 `调度模拟器` 来模拟 `备份作业` 的执行时间。 在创建完成 `备份作业` 后,可以使用 `调度模拟器` 来模拟 `备份作业` 的执行时间。
+5 -5
View File
@@ -3,13 +3,13 @@
## 介绍 ## 介绍
PVE 虚拟化平台的安装以及折腾手记。 PVE 虚拟化平台的安装以及折腾手记。
- PVE ISO 版本:8.1-1 (更新时间: 2023-11-23) - PVE ISO 版本:8.3-1 (更新时间: 2024-11-21)
- 演示机: - 演示机:
- CPU英特尔奔腾 Silver N6005 处理器 - CPUN6005
- 内存:16 GB - 内存:16GB DDR4
- 网卡:英特尔以太网控制器 I226-V - 网卡:I226-V
- 硬盘:500 GB NVMe 固态硬盘 - 硬盘:500GB NVMe
- PVE 网络: - PVE 网络:
- IPv4 网络 - IPv4 网络
Binary file not shown.

Before

Width:  |  Height:  |  Size: 146 KiB

After

Width:  |  Height:  |  Size: 211 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 109 KiB

After

Width:  |  Height:  |  Size: 293 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 115 KiB

After

Width:  |  Height:  |  Size: 308 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 147 KiB

After

Width:  |  Height:  |  Size: 455 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 23 KiB

After

Width:  |  Height:  |  Size: 48 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

After

Width:  |  Height:  |  Size: 303 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 105 KiB

After

Width:  |  Height:  |  Size: 318 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 98 KiB

After

Width:  |  Height:  |  Size: 269 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

After

Width:  |  Height:  |  Size: 203 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 112 KiB

After

Width:  |  Height:  |  Size: 303 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 156 KiB

After

Width:  |  Height:  |  Size: 220 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 51 KiB

After

Width:  |  Height:  |  Size: 194 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 92 KiB

After

Width:  |  Height:  |  Size: 331 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 599 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 160 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 106 KiB

After

Width:  |  Height:  |  Size: 281 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 401 KiB

After

Width:  |  Height:  |  Size: 370 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 133 KiB

After

Width:  |  Height:  |  Size: 429 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 122 KiB

After

Width:  |  Height:  |  Size: 375 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 199 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 73 KiB

After

Width:  |  Height:  |  Size: 133 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 499 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 322 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

After

Width:  |  Height:  |  Size: 196 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 46 KiB

After

Width:  |  Height:  |  Size: 143 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 78 KiB

After

Width:  |  Height:  |  Size: 123 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 73 KiB

After

Width:  |  Height:  |  Size: 125 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 99 KiB

After

Width:  |  Height:  |  Size: 158 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 107 KiB

After

Width:  |  Height:  |  Size: 168 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 78 KiB

After

Width:  |  Height:  |  Size: 192 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 88 KiB

After

Width:  |  Height:  |  Size: 223 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 76 KiB

After

Width:  |  Height:  |  Size: 184 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 47 KiB

After

Width:  |  Height:  |  Size: 129 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 80 KiB

After

Width:  |  Height:  |  Size: 205 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 71 KiB

After

Width:  |  Height:  |  Size: 185 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 135 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 61 KiB

After

Width:  |  Height:  |  Size: 139 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 82 KiB

After

Width:  |  Height:  |  Size: 154 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 65 KiB

After

Width:  |  Height:  |  Size: 179 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 70 KiB

After

Width:  |  Height:  |  Size: 175 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 157 KiB

After

Width:  |  Height:  |  Size: 252 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 100 KiB

After

Width:  |  Height:  |  Size: 198 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 86 KiB

After

Width:  |  Height:  |  Size: 129 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 88 KiB

After

Width:  |  Height:  |  Size: 133 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 288 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 52 KiB

After

Width:  |  Height:  |  Size: 79 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 136 KiB

After

Width:  |  Height:  |  Size: 198 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 65 KiB

After

Width:  |  Height:  |  Size: 92 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 99 KiB

After

Width:  |  Height:  |  Size: 231 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 114 KiB

After

Width:  |  Height:  |  Size: 144 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 92 KiB

After

Width:  |  Height:  |  Size: 110 KiB

+9 -4
View File
@@ -4,22 +4,27 @@
kernel.panic = 20 kernel.panic = 20
kernel.panic_on_oops = 1 kernel.panic_on_oops = 1
net.core.default_qdisc = fq net.core.default_qdisc = fq_codel
net.ipv4.tcp_congestion_control = bbr net.ipv4.tcp_congestion_control = cubic
# Other adjustable system parameters # Other adjustable system parameters
net.core.netdev_budget = 600 net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000 net.core.netdev_budget_usecs = 20000
net.ipv4.conf.all.log_martians = 1 net.core.somaxconn = 8192
net.core.rmem_max = 26214400
net.core.wmem_max = 655360
net.ipv4.igmp_max_memberships = 256 net.ipv4.igmp_max_memberships = 256
net.ipv4.tcp_challenge_ack_limit = 1000 net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fastopen = 3
net.ipv4.tcp_fin_timeout = 30 net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120 net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 4096 87380 26214400
net.ipv4.tcp_wmem = 4096 16384 655360
net.ipv6.conf.all.use_tempaddr = 0 net.ipv6.conf.all.use_tempaddr = 0
net.ipv6.conf.default.use_tempaddr = 0 net.ipv6.conf.default.use_tempaddr = 0
+10 -10
View File
@@ -9,16 +9,16 @@ conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log log-facility=/var/log/dnsmasq.log
log-async=20 log-async=20
cache-size=1024 cache-size=2048
max-cache-ttl=7200 max-cache-ttl=7200
edns-packet-max=1232 fast-dns-retry=1800
rebind-domain-ok=/fox.home.arpa/
interface=eth0
rebind-domain-ok=/fox.internal/
bind-dynamic bind-dynamic
bogus-priv bogus-priv
domain-needed domain-needed
localise-queries
local-service
no-hosts no-hosts
no-negcache no-negcache
no-resolv no-resolv
@@ -29,12 +29,12 @@ stop-dns-rebind
# DNS Filter # DNS Filter
server=/alt/ server=/alt/
server=/home.arpa/
server=/ipv4only.arpa/
server=/resolver.arpa/
server=/example/
server=/bind/ server=/bind/
server=/example/
server=/home.arpa/
server=/internal/
server=/invalid/ server=/invalid/
server=/lan/
server=/local/ server=/local/
server=/localhost/ server=/localhost/
server=/onion/ server=/onion/
@@ -42,7 +42,7 @@ server=/test/
# DNS Server # DNS Server
server=/fox.home.arpa/172.16.1.1 server=/fox.internal/172.16.1.1
server=127.0.0.1#6053 server=127.0.0.1#6053
server=::1#6053 server=::1#6053
+5 -5
View File
@@ -1,18 +1,18 @@
## 下载加速规则安装脚本 ## 下载加速规则安装脚本
$ sudo curl -LR -o /opt/dnsmasq_plugin.sh https://gitee.com/felixonmars/dnsmasq-china-list/raw/master/install.sh $ sudo curl -LR -o /opt/dnsmasq-plugin.sh https://gitee.com/felixonmars/dnsmasq-china-list/raw/master/install.sh
## 设置脚本可执行权限 ## 设置脚本可执行权限
$ sudo chmod +x /opt/dnsmasq_plugin.sh $ sudo chmod +x /opt/dnsmasq-plugin.sh
## 设置脚本文件防篡改 ## 设置脚本文件防篡改
$ sudo chattr +i /opt/dnsmasq_plugin.sh $ sudo chattr +i /opt/dnsmasq-plugin.sh
## 执行脚本 ## 执行脚本
$ sudo bash /opt/dnsmasq_plugin.sh $ sudo bash /opt/dnsmasq-plugin.sh
## 设置 crontab ## 设置 crontab
25 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/dnsmasq.d/anti-ad.dnsmasq.conf https://anti-ad.net/anti-ad-for-dnsmasq.conf 25 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/dnsmasq.d/anti-ad.dnsmasq.conf https://anti-ad.net/anti-ad-for-dnsmasq.conf
35 9 * * * /usr/bin/bash /opt/dnsmasq_plugin.sh 35 9 * * * /usr/bin/bash /opt/dnsmasq-plugin.sh
+20 -27
View File
@@ -6,49 +6,42 @@
# your network environment. # your network environment.
# #
# eg: # eg:
# server 119.29.29.29
# server 223.5.5.5 # server 223.5.5.5
# server 180.184.1.1
# server 119.29.29.29
# server 114.114.114.114 # server 114.114.114.114
# server 2402:4e00:: # server 2402:4e00::
# server 2400:3200::1 # server 2400:3200::1
conf-file /etc/smartdns.d/adrules.smartdns.conf conf-file /etc/smartdns.d/*.conf
conf-file /etc/smartdns.d/dns-group.china.smartdns.conf
conf-file /etc/smartdns.d/apple.china.smartdns.conf
conf-file /etc/smartdns.d/google.china.smartdns.conf
conf-file /etc/smartdns.d/accelerated-domains.china.smartdns.conf
conf-file /etc/smartdns.d/bogus-nxdomain.china.smartdns.conf
cache-file /tmp/smartdns.cache
log-level notice log-level notice
bind [::]:6053@lo bind [::]:6053@lo
bind-tcp [::]:6053@lo bind-tcp [::]:6053@lo
serve-expired yes cache-size 32768
serve-expired-ttl 64800
serve-expired-reply-ttl 3
prefetch-domain yes
serve-expired-prefetch-time 21600
force-qtype-SOA 65
max-query-limit 1024 max-query-limit 1024
edns-client-subnet 202.103.24.68 max-reply-ip-num 24
server-tcp 119.29.29.29 -group dnspod -exclude-default-group prefetch-domain yes
server-tcp 2402:4e00:: -group dnspod -exclude-default-group
nameserver /doh.pub/dnspod
nameserver /dot.pub/dnspod
server-tcp 223.5.5.5 -group alidns -exclude-default-group serve-expired yes
server-tcp 2400:3200::1 -group alidns -exclude-default-group serve-expired-ttl 129600
nameserver /dns.alidns.com/alidns serve-expired-reply-ttl 30
serve-expired-prefetch-time 28800
rr-ttl-min 60
rr-ttl-max 28800
rr-ttl-reply-max 14400
server 172.16.1.1 -group intranet -exclude-default-group server 172.16.1.1 -group intranet -exclude-default-group
nameserver /fox.home.arpa/intranet nameserver /internal/intranet
domain-rules /fox.home.arpa/ -speed-check-mode none -no-cache domain-rules /internal/ -speed-check-mode none -no-cache
server-tcp 180.184.1.1 -bootstrap-dns
server-tcp 114.114.114.114 -bootstrap-dns
server-tcp 2400:3200::1 -bootstrap-dns
server-tls dot.pub server-tls dot.pub
server-tls dns.alidns.com server-tls dns.alidns.com
+3 -3
View File
@@ -1,14 +1,14 @@
# This configuration file is customized by fox, # This configuration file is customized by fox,
# Optimize SmartDNS crontab for local DNS server. # Optimize SmartDNS crontab for local DNS server.
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf 20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
30 9 * * * /usr/bin/systemctl restart smartdns.service 30 9 * * * /usr/bin/systemctl restart smartdns.service
## Or when the smartdns plugin is installed ## Or when the smartdns plugin is installed
20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/adrules.smartdns.conf https://adrules.top/smart-dns.conf 20 9 * * * /usr/bin/curl --retry-connrefused --retry 5 --retry-delay 5 --retry-max-time 60 -fsSLR -o /etc/smartdns.d/neodevhost.smartdns.conf https://neodev.team/lite_smartdns.conf
30 9 * * * /usr/bin/bash /opt/smartdns_plugin.sh 30 9 * * * /usr/bin/bash /opt/smartdns-plugin.sh
+1 -1
View File
@@ -3,7 +3,7 @@ set -e
WORKDIR="$(mktemp -d)" WORKDIR="$(mktemp -d)"
CONFDIR="/etc/smartdns.d" CONFDIR="/etc/smartdns.d"
SERVERS=(223.5.5.5 180.184.1.1 119.29.29.29 114.114.114.114) SERVERS=(223.5.5.5 180.184.1.1 119.29.29.29 114.114.114.114 2402:4e00:: 2400:3200::1)
GROUP=(flash) GROUP=(flash)
# Others: 223.6.6.6 119.28.28.28 # Others: 223.6.6.6 119.28.28.28
# Not using best possible CDN pop: 1.2.4.8 210.2.4.8 # Not using best possible CDN pop: 1.2.4.8 210.2.4.8
+9 -5
View File
@@ -18,6 +18,9 @@ net.core.netdev_budget = 600
net.core.netdev_budget_usecs = 20000 net.core.netdev_budget_usecs = 20000
net.core.rps_sock_flow_entries = 32768 net.core.rps_sock_flow_entries = 32768
net.core.somaxconn = 8192
net.core.rmem_max = 26214400
net.core.wmem_max = 655360
net.ipv4.conf.all.accept_redirects = 0 net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0 net.ipv4.conf.default.accept_redirects = 0
@@ -31,7 +34,8 @@ net.ipv4.conf.default.arp_ignore = 1
net.ipv4.conf.all.rp_filter = 2 net.ipv4.conf.all.rp_filter = 2
net.ipv4.conf.default.rp_filter = 2 net.ipv4.conf.default.rp_filter = 2
net.ipv4.conf.all.log_martians = 1 net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.igmp_max_memberships = 256 net.ipv4.igmp_max_memberships = 256
@@ -42,12 +46,12 @@ net.ipv4.route.redirect_load = 2
net.ipv4.route.redirect_silence = 2048 net.ipv4.route.redirect_silence = 2048
net.ipv4.tcp_challenge_ack_limit = 1000 net.ipv4.tcp_challenge_ack_limit = 1000
net.ipv4.tcp_fastopen = 3
net.ipv4.tcp_fin_timeout = 30 net.ipv4.tcp_fin_timeout = 30
net.ipv4.tcp_keepalive_time = 120 net.ipv4.tcp_keepalive_time = 120
net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_notsent_lowat = 131072
net.ipv4.tcp_rmem = 4096 87380 26214400
net.ipv6.conf.all.accept_ra = 0 net.ipv4.tcp_wmem = 4096 16384 655360
net.ipv6.conf.default.accept_ra = 0
net.ipv6.conf.all.accept_redirects = 0 net.ipv6.conf.all.accept_redirects = 0
net.ipv6.conf.default.accept_redirects = 0 net.ipv6.conf.default.accept_redirects = 0
+11 -10
View File
@@ -9,18 +9,19 @@ conf-file=/etc/dnsmasq.conf
log-facility=/var/log/dnsmasq.log log-facility=/var/log/dnsmasq.log
log-async=20 log-async=20
cache-size=1024 cache-size=2048
max-cache-ttl=7200 max-cache-ttl=7200
edns-packet-max=1232 fast-dns-retry=1800
rebind-domain-ok=/fox.home.arpa/
interface=eth0
rebind-domain-ok=/fox.internal/
bind-dynamic bind-dynamic
bogus-priv bogus-priv
domain-needed domain-needed
localise-queries
local-service
no-hosts no-hosts
no-negcache no-negcache
no-resolv
no-round-robin no-round-robin
rebind-localhost-ok rebind-localhost-ok
stop-dns-rebind stop-dns-rebind
@@ -28,12 +29,12 @@ stop-dns-rebind
# DNS Filter # DNS Filter
server=/alt/ server=/alt/
server=/home.arpa/
server=/ipv4only.arpa/
server=/resolver.arpa/
server=/example/
server=/bind/ server=/bind/
server=/example/
server=/home.arpa/
server=/internal/
server=/invalid/ server=/invalid/
server=/lan/
server=/local/ server=/local/
server=/localhost/ server=/localhost/
server=/onion/ server=/onion/
@@ -43,7 +44,7 @@ server=/test/
server=/ts.net/100.100.100.100 server=/ts.net/100.100.100.100
server=/fox.home.arpa/172.16.1.1 server=/fox.internal/172.16.1.1
server=172.16.1.1 server=172.16.1.1
+31 -61
View File
@@ -7,6 +7,7 @@ table inet router
flush table inet router flush table inet router
table inet router { table inet router {
# #
# Flowtable # Flowtable
# #
@@ -24,48 +25,46 @@ table inet router {
chain input { chain input {
type filter hook input priority filter; policy drop; type filter hook input priority filter; policy drop;
ct state established,related accept comment "defconf: handle inbound flows"
iif "lo" accept comment "defconf: accept traffic from loopback" iif "lo" accept comment "defconf: accept traffic from loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle inbound flows" ct state new meta l4proto tcp jump syn_flood comment "defconf: rate limit new TCP connections"
tcp flags syn / fin,syn,rst,ack counter jump syn_flood comment "defconf: rate limit TCP-SYN packets"
iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic" iifname "eth0" jump input_lan comment "defconf: handle LAN IPv4 / IPv6 input traffic"
iifname "tailscale0" counter jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic" iifname "tailscale0" jump input_tailscale comment "tsconf: handle TS IPv4 / IPv6 input traffic"
} }
chain forward { chain forward {
type filter hook forward priority filter; policy drop; type filter hook forward priority filter; policy drop;
ct state established,related flow add @ft comment "defconf: track forwarded flows" ct state established,related goto handle_offload comment "defconf: handle forwarded flows"
ct state vmap { established : accept, related : accept } comment "defconf: handle forwarded flows"
iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic" iifname "eth0" jump forward_lan comment "defconf: handle LAN IPv4 / IPv6 forward traffic"
iifname "tailscale0" counter jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic" iifname "tailscale0" jump forward_tailscale comment "tsconf: handle TS IPv4 / IPv6 forward traffic"
} }
chain output { chain output {
type filter hook output priority filter; policy accept; type filter hook output priority filter; policy accept;
ct state established,related accept comment "defconf: handle outbound flows"
oif "lo" accept comment "defconf: accept traffic towards loopback" oif "lo" accept comment "defconf: accept traffic towards loopback"
ct state vmap { established : accept, related : accept } comment "defconf: handle outbound flows"
oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic" oifname "eth0" jump output_lan comment "defconf: handle LAN IPv4 / IPv6 output traffic"
oifname "tailscale0" counter jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic" oifname "tailscale0" jump output_tailscale comment "tsconf: handle TS IPv4 / IPv6 output traffic"
}
chain prerouting {
type filter hook prerouting priority filter; policy accept;
iifname "eth0" jump helper_lan comment "defconf: handle LAN IPv4 / IPv6 helper assignment"
iifname "tailscale0" jump helper_tailscale comment "tsconf: handle TS IPv4 / IPv6 helper assignment"
} }
chain syn_flood { chain syn_flood {
limit rate 200/second burst 100 packets return comment "defconf: accept SYN packets below rate-limit" limit rate 200/second burst 100 packets return comment "defconf: accept new TCP connections below rate-limit"
counter drop comment "defconf: drop excess packets" counter drop comment "defconf: drop excess new TCP connections"
}
chain handle_offload {
flow add @ft comment "defconf: track forwarded flows"
accept
} }
chain input_lan { chain input_lan {
ct status dnat counter accept comment "lanconf: accept port redirect" ct status dnat accept comment "lanconf: accept port redirect"
jump accept_from_lan jump accept_from_lan
} }
chain forward_lan { chain forward_lan {
jump accept_to_tailscale comment "tsconf: accept LAN to TS forward" jump accept_to_tailscale comment "tsconf: accept LAN to TS forwarding"
ct status dnat counter accept comment "lanconf: accept port forward" ct status dnat accept comment "lanconf: accept port forwards"
jump accept_to_lan jump accept_to_lan
} }
@@ -73,17 +72,13 @@ table inet router {
jump accept_to_lan jump accept_to_lan
} }
chain helper_lan {
}
chain accept_from_lan { chain accept_from_lan {
iifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic" iifname "eth0" accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
} }
chain accept_to_lan { chain accept_to_lan {
meta nfproto ipv4 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv4 leakage" meta nfproto ipv4 oifname "eth0" ct state invalid counter drop comment "defconf: prevent LAN NATv4 leakage"
meta nfproto ipv6 oifname "eth0" ct state invalid counter drop comment "defconf: prevent NATv6 leakage" oifname "eth0" accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
oifname "eth0" counter accept comment "defconf: accept LAN IPv4 / IPv6 traffic"
} }
chain input_tailscale { chain input_tailscale {
@@ -91,23 +86,22 @@ table inet router {
} }
chain forward_tailscale { chain forward_tailscale {
counter jump accept_to_lan comment "tsconf: accept TS to LAN forward" jump accept_to_lan comment "tsconf: accept TS to LAN forwarding"
counter jump accept_to_tailscale jump accept_to_tailscale
} }
chain output_tailscale { chain output_tailscale {
counter jump accept_to_tailscale jump accept_to_tailscale
}
chain helper_tailscale {
} }
chain accept_from_tailscale { chain accept_from_tailscale {
iifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic" meta nfproto ipv4 iifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 traffic"
meta nfproto ipv6 iifname "tailscale0" counter accept comment "tsconf: accept TS IPv6 traffic"
} }
chain accept_to_tailscale { chain accept_to_tailscale {
oifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 / IPv6 traffic" meta nfproto ipv4 oifname "tailscale0" counter accept comment "tsconf: accept TS IPv4 traffic"
meta nfproto ipv6 oifname "tailscale0" counter accept comment "tsconf: accept TS IPv6 traffic"
} }
@@ -131,21 +125,7 @@ table inet router {
} }
chain srcnat_lan { chain srcnat_lan {
meta nfproto ipv4 counter masquerade comment "defconf: masquerade IPv4 LAN traffic" meta nfproto ipv4 counter masquerade comment "defconf: masquerade LAN IPv4 traffic"
meta nfproto ipv6 counter masquerade comment "defconf: masquerade IPv6 LAN traffic"
}
#
# Raw rules (notrack)
#
chain raw_prerouting {
type filter hook prerouting priority raw; policy accept;
}
chain raw_output {
type filter hook output priority raw; policy accept;
} }
@@ -153,24 +133,14 @@ table inet router {
# Mangle rules # Mangle rules
# #
chain mangle_prerouting {
type filter hook prerouting priority mangle; policy accept;
}
chain mangle_postrouting { chain mangle_postrouting {
type filter hook postrouting priority mangle; policy accept; type filter hook postrouting priority mangle; policy accept;
} oifname "eth0" tcp flags syn / fin,syn,rst tcp option maxseg size set rt mtu comment "defconf: zone LAN IPv4 / IPv6 egress MTU fixing"
chain mangle_input {
type filter hook input priority mangle; policy accept;
}
chain mangle_output {
type route hook output priority mangle; policy accept;
} }
chain mangle_forward { chain mangle_forward {
type filter hook forward priority mangle; policy accept; type filter hook forward priority mangle; policy accept;
iifname "eth0" tcp flags syn / fin,syn,rst tcp option maxseg size set rt mtu comment "defconf: zone LAN IPv4 / IPv6 ingress MTU fixing"
} }
} }