Outils pour utilisateurs

Outils du site


commun:mise_en_place_et_configuration_du_serveur_perso

Ceci est une ancienne révision du document !


Serveur Perso

Il est basé sur Ubuntu 18.06 server

LVM

Si il est nécessaire d'augmenter la taille de la partition principale, les commandes suivantes peuvent être exécutées.

sudo lvextend -L20G /dev/mapper/ubuntu--vg-ubuntu--lv
sudo resize2fs /dev/mapper/ubuntu--vg-ubuntu--lv

Autres commandes utiles

Trouver le volume group du logical volume

lvdisplay -l nom_du_lv

Vérifier qu’il reste assez de place sur le volume group du filesystem

vgdisplay nom_du_vg

Raid

sudo mdadm --create --verbose /dev/md0 --metadata 1.2 --level=mirror --raid-devices=2 /dev/sda1 /dev/sdb1
sudo reboot
cat /proc/mdstat
 
sudo mdadm --detail --scan >> my_mdadm.conf

Ensuite j'ai rajouté une ligne (celle du fichier my_mdadm.conf dans le fichier /etc/mdadm/mdadm.conf). Mais je ne sais pas si c'est utile :

# mdadm.conf
#
# !NB! Run update-initramfs -u after updating this file.
# !NB! This will ensure that initramfs has an uptodate copy.
#
# Please refer to mdadm.conf(5) for information about this file.
#

# by default (built-in), scan all partitions (/proc/partitions) and all
# containers for MD superblocks. alternatively, specify devices to scan, using
# wildcards if desired.
#DEVICE partitions containers

# automatically tag new arrays as belonging to the local system
HOMEHOST <system>

# instruct the monitoring daemon where to send mail alerts
MAILADDR beafrancois@beafrancois.fr

# definitions of existing MD arrays
ARRAY /dev/md/cahute:0 metadata=1.2 name=cahute:0 UUID=4a1d7069:3a4a17d0:06e37696:8d5c340d

# This configuration was auto-generated on Wed, 25 Jul 2018 23:01:52 +0000 by mkconf

sources de logiciels

modifier le fichier /etc/apt/sources.list

deb http://archive.ubuntu.com/ubuntu bionic main universe
deb http://archive.ubuntu.com/ubuntu bionic-security main universe
deb [arch=amd64] https://download.docker.com/linux/ubuntu bionic stable
deb http://archive.ubuntu.com/ubuntu bionic-updates main universe

lxd

Installer lxd

snap install lxd

configurer l'utilisateur courant pour qu'il puisse gérer les conteneurs lxd

sudo usermod -a -G lxd $USER

Préparation réseau

Un bridge réseau est ajouté dans le fichier /etc/netplan/50-cloud-init.yaml

# This file is generated from information provided by
# the datasource.  Changes to it will not persist across an instance.
# To disable cloud-init's network configuration capabilities, write a file
# /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg with the following:
# network: {config: disabled}
network:
    version: 2
    renderer: networkd
    ethernets:
        enp3s0:
            dhcp4: no 
    bridges:
        br0:
            dhcp4: yes
            interfaces:
                - enp3s0

Initialisation de lxd

exécuter la commande

sudo lxd init

Ensuite lors des questions, mettre toutes les options par défaut excepté

  • le type de stockage : zfs
  • le bridge existe déjà : br0
  • accès au réseau : yes

Opérations sur les conteneurs

Création d'un conteneur

lxc project create mes-sites -c features.images=false -c features.profiles=false
lxc project switch mes-sites
lxc launch ubuntu:22.04 webserver
lxc launch ubuntu:22.04 dbserver

Se connecter au conteneur

lxc exec dbserver -- sudo --login --user ubuntu

Arréter un conteneur

lxc stop dbserver

Changer l'emplacement des conteneurs

sudo snap stop lxd
mv /var/snap/lxd /media/stockage/lxd-container

modifier /etc/fstab en ajoutant la ligne :

/media/stockage/system/lxd-containers   /var/snap/lxd                none bind 0 0

Commandes utiles

Lister les images

lxc list

Sauvegarde d'un conteneur

lxc snapshot pwd mdpbackup
lxc publish pwd/mdpbackup --alias mdp-backup
lxc image export mdp-backup .
lxc image delete mdp-backup

Restauration

lxc image import <nom.tar.gz> --alias blah-backup
lxc launch blah-backup some-container-name
lxc image delete blah-backup

nfs

Installer le serveur nfs:

sudo apt install nfs-kernel-server

Modifier /etc/fstab:

[...]
/media/stockage/multimedia       /export/multimedia          none bind 0 0
/media/stockage/famille          /export/famille             none bind 0 0
/media/stockage/partage          /export/partage             none bind 0 0
/media/stockage/homes/francois   /export/home/francois       none bind 0 0
/media/stockage/homes/beatrice   /export/home/beatrice       none bind 0 0
/media/stockage/repositories     /export/repositories        none bind 0 0
[...]

Ensuite modifier le fichier /etc/exports:

# /etc/exports: the access control list for filesystems which may be exported
#               to NFS clients.  See exports(5).
#
# Example for NFSv2 and NFSv3:
# /srv/homes       hostname1(rw,sync,no_subtree_check) hostname2(ro,sync,no_subtree_check)
#
# Example for NFSv4:
# /srv/nfs4        gss/krb5i(rw,sync,fsid=0,crossmnt,no_subtree_check)
# /srv/nfs4/homes  gss/krb5i(rw,sync,no_subtree_check)
#

/export/multimedia      192.168.1.0/24(rw,no_subtree_check,async)
/export/repositories    192.168.1.0/24(rw,no_subtree_check,async)
/export/famille         192.168.1.0/24(rw,no_subtree_check,async)
/export/partage         192.168.1.0/24(rw,no_subtree_check,async)
/export/home/beatrice   192.168.1.0/24(rw,no_subtree_check,async)
/export/home/francois   192.168.1.0/24(rw,no_subtree_check,async)

apache2

Les commandes suivantes sont utilisées pour l'install:

sudo apt install apache2

Génération des clefs SSL

sudo mkdir /etc/apache2/ssl
sudo openssl req -x509 -nodes -days 1095 -newkey rsa:2048 -out /etc/apache2/ssl/server.crt -keyout /etc/apache2/ssl/server.key
sudo chmod -R www-data.www-data /etc/apache2/ssl

Activation du site https et désactivation du site http

sudo a2enmod ssl
sudo a2enmod rewrite
sudo a2enmod headers
sudo a2dissite 000-default
sudo a2ensite default-ssl

Puis modification du fichier /etc/apache2/ports.conf

# If you just change the port or add more ports here, you will likely also
# have to change the VirtualHost statement in
# /etc/apache2/sites-enabled/000-default.conf

#Listen 80

<IfModule ssl_module>
        Listen 443
</IfModule>

<IfModule mod_gnutls.c>
        Listen 443
</IfModule>

# vim: syntax=apache ts=4 sw=4 sts=4 sr noet

Ensuite modification du fichier /etc/apache2/sites-enabled/default-ssl.conf

[...]

                #   A self-signed (snakeoil) certificate can be created by installing
                #   the ssl-cert package. See
                #   /usr/share/doc/apache2/README.Debian.gz for more info.
                #   If both key and certificate are stored in the same file, only the
                #   SSLCertificateFile directive is needed.
                SSLCertificateFile     /etc/apache2/ssl/server.crt
                SSLCertificateKeyFile  /etc/apache2/ssl/server.key

[...]

Configuration du serveur

Le fichier /etc/apache2/apache2.conf est modifié :

[...]

# Sets the default security model of the Apache2 HTTPD server. It does
# not allow access to the root filesystem outside of /usr/share and /var/www.
# The former is used by web applications packaged in Debian,
# the latter may be used for local directories served by the web server. If
# your system is serving content from a sub-directory in /srv you must allow
# access here, or in any related virtual host.
<Directory />
        Options FollowSymLinks
        AllowOverride None
        Require all denied
</Directory>

#<Directory /usr/share>
#       AllowOverride None
#       Require all granted
#</Directory>

#<Directory /var/www/>
#       Options Indexes FollowSymLinks
#       AllowOverride None
#       Require all granted
#</Directory>

<Directory /var/www/html/>
        Options FollowSymLinks
        AllowOverride All
        Require all granted
</Directory>

[...]

mysql

sudo apt install mysql-server

Mot de passe root

sudo systemctl stop mysql
sudo mkdir /var/run/mysqld; sudo chown mysql /var/run/mysqld
sudo mysqld_safe --skip-grant-tables &
sudo mysql --user=root mysql

Dans le prompt mysql

update user set authentication_string=PASSWORD('new-password') where user='root';
flush privileges;

Et ensuite, tuer le service démarré en “safe”

Il faut changer le mode d'autentification root

mysql> SELECT User, Host, plugin FROM mysql.user;
+------------------+-----------+-----------------------+
| User             | Host      | plugin                |
+------------------+-----------+-----------------------+
| root             | localhost | auth_socket           |
| mysql.session    | localhost | mysql_native_password |
| mysql.sys        | localhost | mysql_native_password |
| debian-sys-maint | localhost | mysql_native_password |
+------------------+-----------+-----------------------+

changement du mode

mysql> ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY 'mypassword';
Query OK, 0 rows affected (0.00 sec)
 
mysql> SELECT User, Host, plugin FROM mysql.user;
+------------------+-----------+-----------------------+
| User             | Host      | plugin                |
+------------------+-----------+-----------------------+
| root             | localhost | mysql_native_password |
| mysql.session    | localhost | mysql_native_password |
| mysql.sys        | localhost | mysql_native_password |
| debian-sys-maint | localhost | mysql_native_password |
+------------------+-----------+-----------------------+
4 rows in set (0.00 sec)
 
mysql> 

php / phpmyadmin

sudo apt install php php-curl php-zip  php-mbcrypt php-mbstring php-intl

phpmyadmin

installation de composer

php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');"
php -r "if (hash_file('SHA384', 'composer-setup.php') === '544e09ee996cdf60ece3804abc52599c22b1f40f4323403c44d44fdfdd586475ca9813a858088ffbc1f233e9b180f061') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;"
sudo php composer-setup.php --install-dir=/usr/local/bin --filename=composer
php -r "unlink('composer-setup.php');"

installation de phpmyadmin

cd ~/tmp
composer create-project --no-dev phpmyadmin/phpmyadmin

msmtp

installation

sudo apt install msmtp
sudo apt install msmtp-mta

fichier de configuration globale /etc/msmtprc

# Example for a system wide configuration file

# A system wide configuration file is optional.
# If it exists, it usually defines a default account.
# This allows msmtp to be used like /usr/sbin/sendmail.
account default

# The SMTP smarthost.
host smtp.free.fr

# Construct envelope-from addresses of the form "user@oursite.example".
#auto_from on
#maildomain oursite.example
from maison@beafrancois.fr

# Use TLS.
#tls on
#tls_trust_file /etc/ssl/certs/ca-certificates.crt

# Syslog logging with facility LOG_MAIL instead of the default LOG_USER.
syslog LOG_MAIL

Exemple de commande pour tester le fonctionnement

printf "Subject:DeQuoiOnParle\nLeCorpsDuMessage" | msmtp francois@beafrancois.fr

Fail2ban

installation

sudo apt install fail2ban

Ajout du fichier de configuration /etc/fail2ban/jail.local

[DEFAULT]
bantime = 1h

destemail = beafrancois@beafrancois.fr
sender = cahute@beafrancois.fr

# to ban & send an e-mail with whois report to the destemail.
action = %(action_mw)s

# same as action_mw but also send relevant log lines
#action = %(action_mwl)s

Pour le port spécial sftp, modifier le fichier /etc/fail2ban/jail.d/defaults-debian.conf

[sshd]
enabled = true
port=ssh,2200
commun/mise_en_place_et_configuration_du_serveur_perso.1671287472.txt.gz · Dernière modification : (modification externe)

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki