This repository has been archived on 2026-08-15. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
pve_toss_notes/03.PVE系统调整.md
T
2023-03-07 18:51:48 +08:00

370 lines
12 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
## 0.必要条件
在上一篇文章 [02.PVE初始化配置](./02.PVE初始化配置.md) 中,我们已经初始化了 PVE 系统,接下来需要对 PVE 系统进一步调整。
在 PVE 系统调整之前,请确保必要的软件包已经安装完成。
```bash
## 同步镜像仓库
apt update
## 安装系统软件
apt install htop lm-sensors unzip vim tmux unattended-upgrades apt-listchanges powermgmt-base
## 安装网络工具
apt install iperf iperf3 iftop ethtool
## 安装CPU调度调整工具
apt install cpufrequtils
## 根据CPU厂商安装CPU微码工具
apt install intel-microcode (amd64-microcode)
## 更新 PCI 数据库
update-pciids
```
本文后续命令,均在 SSH 终端下完成。
## 1.系统时区配置
如果在安装 PVE 系统时选错了时区,导致系统时间和北京时间不一致,可以使用以下命令修正:
```bash
## 修改系统时区
timedatectl set-timezone Asia/Shanghai
## 检查系统时间
date -R
## 参考输出
Wed, 20 Jul 2022 16:21:28 +0800
```
输出结果如果和北京时间一致,则代表修改正确。
Debian 系统常用 `systemd-timesyncd.service` 来同步时间,而 PVE 系统使用 `chrony.service` 来同步时间。
为了使用国内的 NTP 服务器,需要对 `chrony.service` 进行配置。
执行以下命令对 `chrony` 的配置文件进行修改:
```bash
## 编辑 chrony 配置文件
nano /etc/chrony/chrony.conf
```
在编辑器对话框中,将 `pool 2.debian.pool.ntp.org iburst` 这行内容 “注释” 掉,并添加国内的 NTP 服务器,参考如下内容:
```bash
## chrony 服务配置文件示例
# Use Debian vendor zone.
# pool 2.debian.pool.ntp.org iburst ## 在这行前面增加注释符 # 来注释
# Use Custom vendor zone.
pool ntp.tencent.com iburst
pool ntp.aliyun.com iburst
```
保存该配置文件后,重启 `chrony` 服务:
```bash
## 重启 chrony 服务
systemctl restart chrony.service
```
再检查系统 NTP 服务器是否被正确修改:
```bash
## 检查系统 NTP 服务器
chronyc sources -V
```
如果输出以下类似内容,则表示系统 NTP 服务设置正确:
```bash
## NTP 服务示例输出
MS Name/IP address Stratum Poll Reach LastRx Last sample
===============================================================================
^+ 139.199.215.251 2 10 177 244 -1669us[-1757us] +/- 67ms
^* 203.107.6.88 2 10 377 105 -1005us[-1094us] +/- 19ms
```
## 2.CPU调度器配置
安装好 `cpufrequtils` 后,先检查当前 CPU 的调度器:
```bash
## 检查 CPU 当前调度器
cpufreq-info
```
**设备 CPU - J4125 参考输出**
```bash
## J4125 参考输出
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
Report errors and bugs to cpufreq@vger.kernel.org, please.
analyzing CPU 0:
driver: intel_cpufreq
CPUs which run at the same hardware frequency: 0
CPUs which need to have their frequency coordinated by software: 0
maximum transition latency: 20.0 us.
hardware limits: 800 MHz - 2.70 GHz
available cpufreq governors: conservative, ondemand, userspace, powersave, performance, schedutil
current policy: frequency should be within 800 MHz and 2.70 GHz.
The governor "ondemand" may decide which speed to use
within this range.
current CPU frequency is 1.84 GHz.
```
**设备 CPU - N5105 参考输出**
```bash
## N5105 参考输出
cpufrequtils 008: cpufreq-info (C) Dominik Brodowski 2004-2009
Report errors and bugs to cpufreq@vger.kernel.org, please.
analyzing CPU 0:
driver: intel_pstate
CPUs which run at the same hardware frequency: 0
CPUs which need to have their frequency coordinated by software: 0
maximum transition latency: 4294.55 ms.
hardware limits: 800 MHz - 2.90 GHz
available cpufreq governors: performance, powersave
current policy: frequency should be within 800 MHz and 2.90 GHz.
The governor "performance" may decide which speed to use
within this range.
current CPU frequency is 1.36 GHz.
```
这里面主要关注两个点:
- driver: `intel_cpufreq``intel_pstate`
- current policy: `governor "ondemand"``governor "performance"`
当然还有另外一个命令可以用来显示 CPU 调度器:
```bash
## 检查 CPU 当前调度器
cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_governor
## J4125 参考输出
ondemand
## N5105 参考输出
performance
```
驱动一般不建议手动调整,而 `governor` 后面的参数则显示了当前 CPU 的调度器是什么。
接下来,我们需要了解当前系统 CPU 支持的调度器有哪些:
```bash
## 检查 CPU 调度器支持情况
cat /sys/devices/system/cpu/cpu0/cpufreq/scaling_available_governors
## J4125 参考输出
conservative ondemand userspace powersave performance schedutil
## N5105 参考输出
performance powersave
```
根据 CPU 所使用的驱动不同,可选调度器也不同,至于每种调度器有什么优劣,欢迎大家深度挖掘。
CPU 驱动为 `intel_pstate` 时,建议使用 `powersave` 调度器。
CPU 驱动为 `intel_cpufreq` 时,建议使用 `schedutil` 调度器。
本文以使用 `powersave` 调度器为演示。
使用 `vim` 编辑器来编辑 `cpufrequtils` 的配置文件:
```bash
## 修改 cpufrequtils 配置文件
vim /etc/init.d/cpufrequtils
## 在配置文件中修改调度器
ENABLE="true"
GOVERNOR="powersave" ## 修改本行的调度器为 powersave
MAX_SPEED="0"
MIN_SPEED="0"
```
`i` 键进入编辑模式,`esc` 键退出编辑模式,`:wq` 命令保存退出。
因为该配置文件很长,文章中留下一份已配置好的文件 [pve_cpufrequtils.conf](./src/pve_cpufrequtils.conf) ,以便对比。
修改完成后,需要重新启动 PVE 服务器来使参数生效。
PVE 服务器重启完成后记得重新检查当前 CPU 的调度器,看配置文件是否生效。
这里提供两个命令,分别来实时查看当前 CPU 的频率和内部温度传感器的数值:
```bash
## 查看 CPU 当前频率
watch cat /sys/devices/system/cpu/cpu[0-9]*/cpufreq/scaling_cur_freq
## 查看内部温度
watch sensors
```
## 3.PVE定时重启配置
有时候我们需要让 PVE 服务器周期性的定时重启,则可使用以下命令:
```bash
## 编辑系统 crontab
crontab -e
## 选择 nano 编辑器,粘贴以下内容并保存
0 5 1,16 * * /usr/sbin/reboot
```
这表示每月 1、16 号的 5 点 0 分执行系统重启命令。
可以使用以下命令来查看当前系统的计划任务:
```bash
## 显示系统 crontab
crontab -l
```
## 4.PVE系统自动更新
### 4.1.检查系统定时器
配置系统自动更新之前,先检查当前系统定时器状态:
```bash
## 检查系统定时器
systemctl status apt-daily-upgrade.timer
## 示例输出
● apt-daily-upgrade.timer - Daily apt upgrade and clean activities
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; vendor preset: enabled)
Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d
└─override.conf
Active: active (waiting) since Sat 2022-07-16 07:03:53 CST; 4 days ago
Trigger: Thu 2022-07-17 06:52:50 CST; 13h left
Triggers: ● apt-daily-upgrade.service
Jul 16 12:03:53 node01 systemd[1]: Started Daily apt upgrade and clean activities.
```
我们后续将手动调整该定时器的时间为,每 10 天的凌晨 02:00 进行触发。
### 4.2.配置自动更新策略
```bash
## 配置自动更新策略
dpkg-reconfigure -plow unattended-upgrades
## 选择 “是” (“YES”)
## 示例输出
Creating config file /etc/apt/apt.conf.d/20auto-upgrades with new version
```
执行命令后,使用“左右”方向键进行选择,“回车”键进行确认。
然后开始调整 apt 的 `20auto-upgrades` 配置文件:
```bash
## 进入 apt 的配置目录
cd /etc/apt/apt.conf.d
## 编辑 20auto-upgrades 配置文件
vim 20auto-upgrades
## 删除里面全部内容并填写以下内容
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "10";
APT::Periodic::AutocleanInterval "1";
APT::Periodic::CleanInterval "1";
```
其中,用来控制 PVE 更新周期的为 `APT::Periodic::Unattended-Upgrade` 这行内容,其中的 “10” 表示更新周期为 “10” 天。
接下来调整 apt 的 `50unattended-upgrades` 配置文件,所有修改项目汇聚如下:
```bash
## 编辑 50unattended-upgrades 配置文件
vim 50unattended-upgrades
## 删除以下行前面的注释符 // ,代表启用
"origin=Debian,codename=${distro_codename}-updates";
## 添加了 PVE 本身的更新项目
"origin=Proxmox,codename=${distro_codename},label=Proxmox Debian Repository";
## 删除以下行前面的注释符,代表启用,并调整参数
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
Unattended-Upgrade::Remove-New-Unused-Dependencies "true";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "05:00";
```
分别表示:
- 启用了 Debian bullseye-updates 相关更新。
- 增加并启用 PVE 自有仓库的更新,确保不会遗漏自有仓库的更新内容。
- 自动修复被打断的Dpkg安装。
- 自动移除无用的的内核包。
- 自动移除因更新而出现的无用依赖包。
- 自动移除以前的无用依赖包。
- 自动重启:开启。
- 自动重启时间:05:00。
因为该配置文件很长,文章中留下一份 PVE 7.2 中已配置好的文件 [pve_50unattended_upgrades.conf](./src/pve_50unattended_upgrades.conf) ,以便对比。
仔细再仔细确认无误后,`esc` 键退出编辑模式,`:wq` 命令保存退出。
### 4.3.重设自动更新触发器
```bash
## 重设自动更新触发器时间为凌晨 02:00
systemctl edit apt-daily-upgrade.timer
## 根据文件中的提示,在中间空白处填入以下内容
[Timer]
OnCalendar=
OnCalendar=02:00
RandomizedDelaySec=0
```
完整的配置文件可查看 [pve_apt_daily_upgrade.conf](./src/pve_apt_daily_upgrade.conf),以便对比。
设置完成后重启自动更新的触发器:
```bash
## 重启触发器
systemctl restart apt-daily-upgrade.timer
## 再次检查触发器状态
systemctl status apt-daily-upgrade.timer
## 参考输出
● apt-daily-upgrade.timer - Daily apt upgrade and clean activities
Loaded: loaded (/lib/systemd/system/apt-daily-upgrade.timer; enabled; vendor preset: enabled)
Drop-In: /etc/systemd/system/apt-daily-upgrade.timer.d
└─override.conf
Active: active (waiting) since Wed 2022-07-20 17:36:40 CST; 11s ago
Trigger: Thu 2022-07-21 02:00:00 CST; 8h left
Triggers: ● apt-daily-upgrade.service
Jul 20 17:36:40 node01 systemd[1]: Stopped Daily apt upgrade and clean activities.
Jul 20 17:36:40 node01 systemd[1]: Stopping Daily apt upgrade and clean activities.
Jul 20 17:36:40 node01 systemd[1]: Started Daily apt upgrade and clean activities.
```
至此 PVE 的系统调整已经完成,重启设备后,可以愉快使用了。
Plug in & Forget :)