跳转到内容

欢迎来到Riguz的小站!这是一个私人wiki,用来记录一些我的笔记。

Linux server setup:修订间差异

来自WHY42
Riguz​(留言 | 贡献)
创建页面,内容为“ Category:Linux/Unix”
 
Riguz​(留言 | 贡献)
小无编辑摘要
 
(未显示同一用户的14个中间版本)
第1行: 第1行:
Ubuntu server setup (for new VPS onboarding)


= Installation =
== Ghostty settings ==
<syntaxhighlight lang="bash">
# Fix
# root@riguz4c8g:~# clear
# 'xterm-ghostty': unknown terminal type."


infocmp -x xterm-ghostty | ssh root@83.229.121.141 -- tic -x -
</syntaxhighlight>
== Update system ==
<syntaxhighlight lang="bash">
sudo apt update
sudo apt full-upgrade -y
sudo apt autoremove --purge -y
</syntaxhighlight>
<syntaxhighlight lang="bash">
root@riguz4c8g:~# lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description:    Ubuntu 24.04.5 LTS
Release:        24.04
Codename:      noble
</syntaxhighlight>
Not recommended to do-release-upgrade (from 24 -> 26)
== System settings ==
Add admin user:
<syntaxhighlight lang="bash">
adduser riguz
usermod -aG sudo riguz
</syntaxhighlight>
== hostname  ==
<syntaxhighlight lang="bash">
vim /etc/hostname
</syntaxhighlight>
== ssh config ==
<syntaxhighlight lang="bash">
ssh-copy-id -p 50000 ubuntu@12.98.23.12
# vim /etc/ssh/sshd_config
Port 54194
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
service ssh restart
ssh -p 50000 ubuntu@12.98.23.12
</syntaxhighlight>
Note: for Ubuntu 24.04+ with systemd socket
<syntaxhighlight lang="bash">
# To change the port
sudo vim /lib/systemd/system/ssh.socket
[Socket]
ListenStream=0.0.0.0:54194
ListenStream=[::]:54194
sudo systemctl daemon-reload
sudo systemctl stop ssh.socket
sudo systemctl restart ssh
netstat -anp | grep 54194
(No info could be read for "-p": geteuid()=1000 but you should be root.)
tcp        0      0 0.0.0.0:54194          0.0.0.0:*              LISTEN      -
tcp6      0      0 :::54194                :::*                    LISTEN      -
</syntaxhighlight>
== ufw==
<syntaxhighlight lang="bash">
sudo ufw enable
sudo ufw allow 80
sudo ufw allow 443
sudo ufw allow 54194
sudo ufw status numbered
</syntaxhighlight>
== V2ray ==
[[V2Ray global proxy]]
= Web server =
== Ngnix ==
<syntaxhighlight lang="bash">
$ sudo apt install nginx
$ sudo systemctl status nginx
</syntaxhighlight>
== Certbot ==
Install via pip<ref>https://certbot.eff.org/instructions?ws=nginx&os=pip&commit=%3E</ref>
<syntaxhighlight lang="bash">
sudo apt install certbot
sudo apt install python3 python3-dev python3-venv libaugeas-dev gcc
sudo python3 -m venv /opt/certbot/
sudo /opt/certbot/bin/pip install --upgrade pip
sudo /opt/certbot/bin/pip install certbot certbot-nginx
sudo ln -s /opt/certbot/bin/certbot /usr/bin/certbot
sudo certbot --nginx
sudo nginx -s reload
</syntaxhighlight>


[[Category:Linux/Unix]]
[[Category:Linux/Unix]]

2026年10月1日 (四) 16:23的最新版本

Ubuntu server setup (for new VPS onboarding)

Installation

Ghostty settings

# Fix 
# root@riguz4c8g:~# clear
# 'xterm-ghostty': unknown terminal type."

infocmp -x xterm-ghostty | ssh root@83.229.121.141 -- tic -x -

Update system

sudo apt update
sudo apt full-upgrade -y
sudo apt autoremove --purge -y
root@riguz4c8g:~# lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description:    Ubuntu 24.04.5 LTS
Release:        24.04
Codename:       noble

Not recommended to do-release-upgrade (from 24 -> 26)

System settings

Add admin user:

adduser riguz
usermod -aG sudo riguz


hostname

vim /etc/hostname

ssh config

ssh-copy-id -p 50000 ubuntu@12.98.23.12

# vim /etc/ssh/sshd_config
Port 54194
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes

service ssh restart
ssh -p 50000 ubuntu@12.98.23.12

Note: for Ubuntu 24.04+ with systemd socket

# To change the port
sudo vim /lib/systemd/system/ssh.socket
[Socket]
ListenStream=0.0.0.0:54194
ListenStream=[::]:54194

sudo systemctl daemon-reload
sudo systemctl stop ssh.socket
sudo systemctl restart ssh
netstat -anp | grep 54194
(No info could be read for "-p": geteuid()=1000 but you should be root.)
tcp        0      0 0.0.0.0:54194           0.0.0.0:*               LISTEN      -
tcp6       0      0 :::54194                :::*                    LISTEN      -

ufw

sudo ufw enable
sudo ufw allow 80
sudo ufw allow 443
sudo ufw allow 54194
sudo ufw status numbered

V2ray

V2Ray global proxy

Web server

Ngnix

$ sudo apt install nginx
$ sudo systemctl status nginx

Certbot

Install via pip[1]

sudo apt install certbot
sudo apt install python3 python3-dev python3-venv libaugeas-dev gcc
sudo python3 -m venv /opt/certbot/
sudo /opt/certbot/bin/pip install --upgrade pip
sudo /opt/certbot/bin/pip install certbot certbot-nginx
sudo ln -s /opt/certbot/bin/certbot /usr/bin/certbot
sudo certbot --nginx
sudo nginx -s reload