Ceci est une ancienne révision du document !
Table des matières
Serveur Perso
Il est basé sur Ubuntu 18.06 server
LVM
Si il est nécessaire d'augmenter la taille de la partition principale, les commandes suivantes peuvent être exécutées.
sudo lvextend -L20G /dev/mapper/ubuntu--vg-ubuntu--lv sudo resize2fs /dev/mapper/ubuntu--vg-ubuntu--lv
Autres commandes utiles
Trouver le volume group du logical volume
lvdisplay -l nom_du_lv
Vérifier qu’il reste assez de place sur le volume group du filesystem
vgdisplay nom_du_vg
Raid
sudo mdadm --create --verbose /dev/md0 --metadata 1.2 --level=mirror --raid-devices=2 /dev/sda1 /dev/sdb1 sudo reboot cat /proc/mdstat sudo mdadm --detail --scan >> my_mdadm.conf
Ensuite j'ai rajouté une ligne (celle du fichier my_mdadm.conf dans le fichier /etc/mdadm/mdadm.conf). Mais je ne sais pas si c'est utile :
# mdadm.conf # # !NB! Run update-initramfs -u after updating this file. # !NB! This will ensure that initramfs has an uptodate copy. # # Please refer to mdadm.conf(5) for information about this file. # # by default (built-in), scan all partitions (/proc/partitions) and all # containers for MD superblocks. alternatively, specify devices to scan, using # wildcards if desired. #DEVICE partitions containers # automatically tag new arrays as belonging to the local system HOMEHOST <system> # instruct the monitoring daemon where to send mail alerts MAILADDR beafrancois@beafrancois.fr # definitions of existing MD arrays ARRAY /dev/md/cahute:0 metadata=1.2 name=cahute:0 UUID=4a1d7069:3a4a17d0:06e37696:8d5c340d # This configuration was auto-generated on Wed, 25 Jul 2018 23:01:52 +0000 by mkconf
sources de logiciels
modifier le fichier /etc/apt/sources.list
deb http://archive.ubuntu.com/ubuntu bionic main universe deb http://archive.ubuntu.com/ubuntu bionic-security main universe deb [arch=amd64] https://download.docker.com/linux/ubuntu bionic stable deb http://archive.ubuntu.com/ubuntu bionic-updates main universe
lxd
Installer lxd
snap install lxd
configurer l'utilisateur courant pour qu'il puisse gérer les conteneurs lxd
sudo usermod -a -G lxd $USER
Préparation réseau
Un bridge réseau est ajouté dans le fichier /etc/netplan/50-cloud-init.yaml
# This file is generated from information provided by
# the datasource. Changes to it will not persist across an instance.
# To disable cloud-init's network configuration capabilities, write a file
# /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg with the following:
# network: {config: disabled}
network:
version: 2
renderer: networkd
ethernets:
enp3s0:
dhcp4: no
bridges:
br0:
dhcp4: yes
interfaces:
- enp3s0
Initialisation de lxd
exécuter la commande
sudo lxd init
Ensuite lors des questions, mettre toutes les options par défaut excepté
- le type de stockage :
zfs - le bridge existe déjà :
br0 - accès au réseau :
yes
Opérations sur les conteneurs
Création d'un conteneur
lxc project create mes-sites -c features.images=false -c features.profiles=false lxc project switch mes-sites lxc launch ubuntu:22.04 webserver lxc launch ubuntu:22.04 dbserver
Se connecter au conteneur
lxc exec dbserver -- sudo --login --user ubuntu
Arréter un conteneur
lxc stop dbserver
Changer l'emplacement des conteneurs
sudo snap stop lxd mv /var/snap/lxd /media/stockage/lxd-container
modifier /etc/fstab en ajoutant la ligne :
/media/stockage/system/lxd-containers /var/snap/lxd none bind 0 0
Commandes utiles
Lister les images
lxc list
Sauvegarde d'un conteneur
lxc export {container} /path/to/{container}-backup-$(date +'%m-%d-%Y').tar.xz
Restauration
lxc import /path/to/{container}-backup.tar.xz
nfs
Installer le serveur nfs:
sudo apt install nfs-kernel-server
Modifier /etc/fstab:
[...] /media/stockage/multimedia /export/multimedia none bind 0 0 /media/stockage/famille /export/famille none bind 0 0 /media/stockage/partage /export/partage none bind 0 0 /media/stockage/homes/francois /export/home/francois none bind 0 0 /media/stockage/homes/beatrice /export/home/beatrice none bind 0 0 /media/stockage/repositories /export/repositories none bind 0 0 [...]
Ensuite modifier le fichier /etc/exports:
# /etc/exports: the access control list for filesystems which may be exported # to NFS clients. See exports(5). # # Example for NFSv2 and NFSv3: # /srv/homes hostname1(rw,sync,no_subtree_check) hostname2(ro,sync,no_subtree_check) # # Example for NFSv4: # /srv/nfs4 gss/krb5i(rw,sync,fsid=0,crossmnt,no_subtree_check) # /srv/nfs4/homes gss/krb5i(rw,sync,no_subtree_check) # /export/multimedia 192.168.1.0/24(rw,no_subtree_check,async) /export/repositories 192.168.1.0/24(rw,no_subtree_check,async) /export/famille 192.168.1.0/24(rw,no_subtree_check,async) /export/partage 192.168.1.0/24(rw,no_subtree_check,async) /export/home/beatrice 192.168.1.0/24(rw,no_subtree_check,async) /export/home/francois 192.168.1.0/24(rw,no_subtree_check,async)
apache2
Les commandes suivantes sont utilisées pour l'install:
sudo apt install apache2
Génération des clefs SSL
sudo mkdir /etc/apache2/ssl sudo openssl req -x509 -nodes -days 1095 -newkey rsa:2048 -out /etc/apache2/ssl/server.crt -keyout /etc/apache2/ssl/server.key sudo chmod -R www-data.www-data /etc/apache2/ssl
Activation du site https et désactivation du site http
sudo a2enmod ssl sudo a2enmod rewrite sudo a2enmod headers sudo a2dissite 000-default sudo a2ensite default-ssl
Puis modification du fichier /etc/apache2/ports.conf
# If you just change the port or add more ports here, you will likely also
# have to change the VirtualHost statement in
# /etc/apache2/sites-enabled/000-default.conf
#Listen 80
<IfModule ssl_module>
Listen 443
</IfModule>
<IfModule mod_gnutls.c>
Listen 443
</IfModule>
# vim: syntax=apache ts=4 sw=4 sts=4 sr noet
Ensuite modification du fichier /etc/apache2/sites-enabled/default-ssl.conf
[...]
# A self-signed (snakeoil) certificate can be created by installing
# the ssl-cert package. See
# /usr/share/doc/apache2/README.Debian.gz for more info.
# If both key and certificate are stored in the same file, only the
# SSLCertificateFile directive is needed.
SSLCertificateFile /etc/apache2/ssl/server.crt
SSLCertificateKeyFile /etc/apache2/ssl/server.key
[...]
Configuration du serveur
Le fichier /etc/apache2/apache2.conf est modifié :
[...]
# Sets the default security model of the Apache2 HTTPD server. It does
# not allow access to the root filesystem outside of /usr/share and /var/www.
# The former is used by web applications packaged in Debian,
# the latter may be used for local directories served by the web server. If
# your system is serving content from a sub-directory in /srv you must allow
# access here, or in any related virtual host.
<Directory />
Options FollowSymLinks
AllowOverride None
Require all denied
</Directory>
#<Directory /usr/share>
# AllowOverride None
# Require all granted
#</Directory>
#<Directory /var/www/>
# Options Indexes FollowSymLinks
# AllowOverride None
# Require all granted
#</Directory>
<Directory /var/www/html/>
Options FollowSymLinks
AllowOverride All
Require all granted
</Directory>
[...]
mysql
sudo apt install mysql-server
Mot de passe root
sudo systemctl stop mysql sudo mkdir /var/run/mysqld; sudo chown mysql /var/run/mysqld sudo mysqld_safe --skip-grant-tables & sudo mysql --user=root mysql
Dans le prompt mysql
update user set authentication_string=PASSWORD('new-password') where user='root';
flush privileges;
Et ensuite, tuer le service démarré en “safe”
Il faut changer le mode d'autentification root
mysql> SELECT User, Host, plugin FROM mysql.user; +------------------+-----------+-----------------------+ | User | Host | plugin | +------------------+-----------+-----------------------+ | root | localhost | auth_socket | | mysql.session | localhost | mysql_native_password | | mysql.sys | localhost | mysql_native_password | | debian-sys-maint | localhost | mysql_native_password | +------------------+-----------+-----------------------+
changement du mode
mysql> ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY 'mypassword'; Query OK, 0 rows affected (0.00 sec) mysql> SELECT User, Host, plugin FROM mysql.user; +------------------+-----------+-----------------------+ | User | Host | plugin | +------------------+-----------+-----------------------+ | root | localhost | mysql_native_password | | mysql.session | localhost | mysql_native_password | | mysql.sys | localhost | mysql_native_password | | debian-sys-maint | localhost | mysql_native_password | +------------------+-----------+-----------------------+ 4 rows in set (0.00 sec) mysql>
php / phpmyadmin
sudo apt install php php-curl php-zip php-mbcrypt php-mbstring php-intl
phpmyadmin
installation de composer
php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');"
php -r "if (hash_file('SHA384', 'composer-setup.php') === '544e09ee996cdf60ece3804abc52599c22b1f40f4323403c44d44fdfdd586475ca9813a858088ffbc1f233e9b180f061') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;"
sudo php composer-setup.php --install-dir=/usr/local/bin --filename=composer
php -r "unlink('composer-setup.php');"
installation de phpmyadmin
cd ~/tmp composer create-project --no-dev phpmyadmin/phpmyadmin
msmtp
installation
sudo apt install msmtp sudo apt install msmtp-mta
fichier de configuration globale /etc/msmtprc
# Example for a system wide configuration file # A system wide configuration file is optional. # If it exists, it usually defines a default account. # This allows msmtp to be used like /usr/sbin/sendmail. account default # The SMTP smarthost. host smtp.free.fr # Construct envelope-from addresses of the form "user@oursite.example". #auto_from on #maildomain oursite.example from maison@beafrancois.fr # Use TLS. #tls on #tls_trust_file /etc/ssl/certs/ca-certificates.crt # Syslog logging with facility LOG_MAIL instead of the default LOG_USER. syslog LOG_MAIL
Exemple de commande pour tester le fonctionnement
printf "Subject:DeQuoiOnParle\nLeCorpsDuMessage" | msmtp francois@beafrancois.fr
Fail2ban
installation
sudo apt install fail2ban
Ajout du fichier de configuration /etc/fail2ban/jail.local
[DEFAULT] bantime = 1h destemail = beafrancois@beafrancois.fr sender = cahute@beafrancois.fr # to ban & send an e-mail with whois report to the destemail. action = %(action_mw)s # same as action_mw but also send relevant log lines #action = %(action_mwl)s
Pour le port spécial sftp, modifier le fichier /etc/fail2ban/jail.d/defaults-debian.conf
[sshd] enabled = true port=ssh,2200
