Ceci est une ancienne révision du document !
Table des matières
Serveur Perso
Serveur basé sur une Debian 12 (bookworm) AMD64.
Disques
- disque SSD monté normalement avec partitions physiques:
- / (~50G)
- /home (~200G)
- disque RAID 2x 2T (voir ci-dessous)
Raid
sudo mdadm --create --verbose /dev/md0 --metadata 1.2 --level=mirror --raid-devices=2 /dev/sda1 /dev/sdb1 sudo reboot cat /proc/mdstat sudo mdadm --detail --scan >> my_mdadm.conf
Ensuite j'ai rajouté une ligne (celle du fichier my_mdadm.conf dans le fichier /etc/mdadm/mdadm.conf). Mais je ne sais pas si c'est utile :
# mdadm.conf # # !NB! Run update-initramfs -u after updating this file. # !NB! This will ensure that initramfs has an uptodate copy. # # Please refer to mdadm.conf(5) for information about this file. # # by default (built-in), scan all partitions (/proc/partitions) and all # containers for MD superblocks. alternatively, specify devices to scan, using # wildcards if desired. #DEVICE partitions containers # automatically tag new arrays as belonging to the local system HOMEHOST <system> # instruct the monitoring daemon where to send mail alerts MAILADDR beafrancois@beafrancois.fr # definitions of existing MD arrays ARRAY /dev/md/cahute:0 metadata=1.2 name=cahute:0 UUID=4a1d7069:3a4a17d0:06e37696:8d5c340d # This configuration was auto-generated on Wed, 25 Jul 2018 23:01:52 +0000 by mkconf
sources de logiciels
modifier le fichier /etc/apt/sources.list
deb http://archive.ubuntu.com/ubuntu bionic main universe deb http://archive.ubuntu.com/ubuntu bionic-security main universe deb [arch=amd64] https://download.docker.com/linux/ubuntu bionic stable deb http://archive.ubuntu.com/ubuntu bionic-updates main universe
lxd
Installer lxd
snap install lxd
configurer l'utilisateur courant pour qu'il puisse gérer les conteneurs lxd
sudo usermod -a -G lxd $USER
Préparation réseau
Un bridge réseau est ajouté dans le fichier /etc/netplan/50-cloud-init.yaml
# This file is generated from information provided by
# the datasource. Changes to it will not persist across an instance.
# To disable cloud-init's network configuration capabilities, write a file
# /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg with the following:
# network: {config: disabled}
network:
version: 2
renderer: networkd
ethernets:
enp3s0:
dhcp4: no
bridges:
br0:
dhcp4: yes
interfaces:
- enp3s0
Initialisation de lxd
exécuter la commande
sudo lxd init
Ensuite lors des questions, mettre toutes les options par défaut excepté
- le type de stockage :
zfs - le bridge existe déjà :
br0 - accès au réseau :
yes
Opérations sur les conteneurs
Création d'un conteneur
lxc project create mes-sites -c features.images=false -c features.profiles=false lxc project switch mes-sites lxc launch ubuntu:22.04 webserver lxc launch ubuntu:22.04 dbserver
Se connecter au conteneur
lxc exec dbserver -- sudo --login --user ubuntu
Arréter un conteneur
lxc stop dbserver
Changer l'emplacement des conteneurs
sudo snap stop lxd mv /var/snap/lxd /media/stockage/lxd-container
modifier /etc/fstab en ajoutant la ligne :
/media/stockage/system/lxd-containers /var/snap/lxd none bind 0 0
Commandes utiles
Lister les images
lxc list
Sauvegarde d'un conteneur
lxc export {container} /path/to/{container}-backup-$(date +'%m-%d-%Y').tar.xz
Restauration
lxc import /path/to/{container}-backup.tar.xz
nfs
Installer le serveur nfs:
sudo apt install nfs-kernel-server
Modifier /etc/fstab:
[...] /media/stockage/multimedia /export/multimedia none bind 0 0 /media/stockage/famille /export/famille none bind 0 0 /media/stockage/partage /export/partage none bind 0 0 /media/stockage/homes/francois /export/home/francois none bind 0 0 /media/stockage/homes/beatrice /export/home/beatrice none bind 0 0 /media/stockage/repositories /export/repositories none bind 0 0 [...]
Ensuite modifier le fichier /etc/exports:
# /etc/exports: the access control list for filesystems which may be exported # to NFS clients. See exports(5). # # Example for NFSv2 and NFSv3: # /srv/homes hostname1(rw,sync,no_subtree_check) hostname2(ro,sync,no_subtree_check) # # Example for NFSv4: # /srv/nfs4 gss/krb5i(rw,sync,fsid=0,crossmnt,no_subtree_check) # /srv/nfs4/homes gss/krb5i(rw,sync,no_subtree_check) # /export/multimedia 192.168.1.0/24(rw,no_subtree_check,async) /export/repositories 192.168.1.0/24(rw,no_subtree_check,async) /export/famille 192.168.1.0/24(rw,no_subtree_check,async) /export/partage 192.168.1.0/24(rw,no_subtree_check,async) /export/home/beatrice 192.168.1.0/24(rw,no_subtree_check,async) /export/home/francois 192.168.1.0/24(rw,no_subtree_check,async)
apache2
Les commandes suivantes sont utilisées pour l'install:
sudo apt install apache2
Génération des clefs SSL
sudo mkdir /etc/apache2/ssl sudo openssl req -x509 -nodes -days 1095 -newkey rsa:2048 -out /etc/apache2/ssl/server.crt -keyout /etc/apache2/ssl/server.key sudo chmod -R www-data.www-data /etc/apache2/ssl
Activation du site https et désactivation du site http
sudo a2enmod ssl sudo a2enmod rewrite sudo a2enmod headers sudo a2dissite 000-default sudo a2ensite default-ssl
Puis modification du fichier /etc/apache2/ports.conf
# If you just change the port or add more ports here, you will likely also
# have to change the VirtualHost statement in
# /etc/apache2/sites-enabled/000-default.conf
#Listen 80
<IfModule ssl_module>
Listen 443
</IfModule>
<IfModule mod_gnutls.c>
Listen 443
</IfModule>
# vim: syntax=apache ts=4 sw=4 sts=4 sr noet
Ensuite modification du fichier /etc/apache2/sites-enabled/default-ssl.conf
[...]
# A self-signed (snakeoil) certificate can be created by installing
# the ssl-cert package. See
# /usr/share/doc/apache2/README.Debian.gz for more info.
# If both key and certificate are stored in the same file, only the
# SSLCertificateFile directive is needed.
SSLCertificateFile /etc/apache2/ssl/server.crt
SSLCertificateKeyFile /etc/apache2/ssl/server.key
[...]
Configuration du serveur
Le fichier /etc/apache2/apache2.conf est modifié :
[...]
# Sets the default security model of the Apache2 HTTPD server. It does
# not allow access to the root filesystem outside of /usr/share and /var/www.
# The former is used by web applications packaged in Debian,
# the latter may be used for local directories served by the web server. If
# your system is serving content from a sub-directory in /srv you must allow
# access here, or in any related virtual host.
<Directory />
Options FollowSymLinks
AllowOverride None
Require all denied
</Directory>
#<Directory /usr/share>
# AllowOverride None
# Require all granted
#</Directory>
#<Directory /var/www/>
# Options Indexes FollowSymLinks
# AllowOverride None
# Require all granted
#</Directory>
<Directory /var/www/html/>
Options FollowSymLinks
AllowOverride All
Require all granted
</Directory>
[...]
mysql
sudo apt install mysql-server
Mot de passe root
sudo systemctl stop mysql sudo mkdir /var/run/mysqld; sudo chown mysql /var/run/mysqld sudo mysqld_safe --skip-grant-tables & sudo mysql --user=root mysql
Dans le prompt mysql
update user set authentication_string=PASSWORD('new-password') where user='root';
flush privileges;
Et ensuite, tuer le service démarré en “safe”
Il faut changer le mode d'autentification root
mysql> SELECT User, Host, plugin FROM mysql.user; +------------------+-----------+-----------------------+ | User | Host | plugin | +------------------+-----------+-----------------------+ | root | localhost | auth_socket | | mysql.session | localhost | mysql_native_password | | mysql.sys | localhost | mysql_native_password | | debian-sys-maint | localhost | mysql_native_password | +------------------+-----------+-----------------------+
changement du mode
mysql> ALTER USER 'root'@'localhost' IDENTIFIED WITH mysql_native_password BY 'mypassword'; Query OK, 0 rows affected (0.00 sec) mysql> SELECT User, Host, plugin FROM mysql.user; +------------------+-----------+-----------------------+ | User | Host | plugin | +------------------+-----------+-----------------------+ | root | localhost | mysql_native_password | | mysql.session | localhost | mysql_native_password | | mysql.sys | localhost | mysql_native_password | | debian-sys-maint | localhost | mysql_native_password | +------------------+-----------+-----------------------+ 4 rows in set (0.00 sec) mysql>
php / phpmyadmin
sudo apt install php php-curl php-zip php-mbcrypt php-mbstring php-intl
phpmyadmin
installation de composer
php -r "copy('https://getcomposer.org/installer', 'composer-setup.php');"
php -r "if (hash_file('SHA384', 'composer-setup.php') === '544e09ee996cdf60ece3804abc52599c22b1f40f4323403c44d44fdfdd586475ca9813a858088ffbc1f233e9b180f061') { echo 'Installer verified'; } else { echo 'Installer corrupt'; unlink('composer-setup.php'); } echo PHP_EOL;"
sudo php composer-setup.php --install-dir=/usr/local/bin --filename=composer
php -r "unlink('composer-setup.php');"
installation de phpmyadmin
cd ~/tmp composer create-project --no-dev phpmyadmin/phpmyadmin
msmtp
installation
sudo apt install msmtp sudo apt install msmtp-mta
fichier de configuration globale /etc/msmtprc
# Example for a system wide configuration file # A system wide configuration file is optional. # If it exists, it usually defines a default account. # This allows msmtp to be used like /usr/sbin/sendmail. account default # The SMTP smarthost. host smtp.free.fr # Construct envelope-from addresses of the form "user@oursite.example". #auto_from on #maildomain oursite.example from maison@beafrancois.fr # Use TLS. #tls on #tls_trust_file /etc/ssl/certs/ca-certificates.crt # Syslog logging with facility LOG_MAIL instead of the default LOG_USER. syslog LOG_MAIL
Exemple de commande pour tester le fonctionnement
printf "Subject:DeQuoiOnParle\nLeCorpsDuMessage" | msmtp francois@beafrancois.fr
Fail2ban
installation
sudo apt install fail2ban
Ajout du fichier de configuration /etc/fail2ban/jail.local
[DEFAULT] bantime = 1h destemail = beafrancois@beafrancois.fr sender = cahute@beafrancois.fr # to ban & send an e-mail with whois report to the destemail. action = %(action_mw)s # same as action_mw but also send relevant log lines #action = %(action_mwl)s
Pour le port spécial sftp, modifier le fichier /etc/fail2ban/jail.d/defaults-debian.conf
[sshd] enabled = true port=ssh,2200
