跳转到内容

欢迎来到Riguz的小站!这是一个私人wiki,用来记录一些我的笔记。

Linux server setup:修订间差异

来自WHY42
Riguz​(留言 | 贡献)
Riguz​(留言 | 贡献)
小无编辑摘要
 
(未显示同一用户的4个中间版本)
第1行: 第1行:
=System settings =
Ubuntu server setup (for new VPS onboarding)
 
= Installation =
== Ghostty settings ==
<syntaxhighlight lang="bash">
# Fix
# root@riguz4c8g:~# clear
# 'xterm-ghostty': unknown terminal type."
 
infocmp -x xterm-ghostty | ssh root@83.229.121.141 -- tic -x -
</syntaxhighlight>
 
== Update system ==
== Update system ==
<syntaxhighlight lang="bash">
<syntaxhighlight lang="bash">
sudo apt update
sudo apt update
sudo apt upgrade
sudo apt full-upgrade -y
do-release-upgrade
sudo apt autoremove --purge -y
</syntaxhighlight>


reboot
<syntaxhighlight lang="bash">
root@riguz4c8g:~# lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description:    Ubuntu 24.04.5 LTS
Release:        24.04
Codename:      noble
</syntaxhighlight>
</syntaxhighlight>


== hostname  ==
Not recommended to do-release-upgrade (from 24 -> 26)


== System settings ==
Add admin user:
<syntaxhighlight lang="bash">
<syntaxhighlight lang="bash">
vim /etc/hostname
adduser riguz
usermod -aG sudo riguz
</syntaxhighlight>
</syntaxhighlight>


== user ==
 
== hostname  ==
 
<syntaxhighlight lang="bash">
<syntaxhighlight lang="bash">
adduser ubuntu
vim /etc/hostname
usermod -aG sudo ubuntu
</syntaxhighlight>
</syntaxhighlight>


第27行: 第49行:


# vim /etc/ssh/sshd_config
# vim /etc/ssh/sshd_config
Port 54194
PermitRootLogin no
PermitRootLogin no
PasswordAuthentication no
PasswordAuthentication no
第33行: 第56行:
service ssh restart
service ssh restart
ssh -p 50000 ubuntu@12.98.23.12
ssh -p 50000 ubuntu@12.98.23.12
</syntaxhighlight>
Note: for Ubuntu 24.04+ with systemd socket
<syntaxhighlight lang="bash">
# To change the port
sudo vim /lib/systemd/system/ssh.socket
[Socket]
ListenStream=0.0.0.0:54194
ListenStream=[::]:54194
sudo systemctl daemon-reload
sudo systemctl stop ssh.socket
sudo systemctl restart ssh
netstat -anp | grep 54194
(No info could be read for "-p": geteuid()=1000 but you should be root.)
tcp        0      0 0.0.0.0:54194          0.0.0.0:*              LISTEN      -
tcp6      0      0 :::54194                :::*                    LISTEN      -
</syntaxhighlight>
</syntaxhighlight>


第40行: 第80行:
sudo ufw allow 80
sudo ufw allow 80
sudo ufw allow 443
sudo ufw allow 443
sudo ufw allow 50000
sudo ufw allow 54194
sudo ufw status numbered
sudo ufw status numbered
</syntaxhighlight>
</syntaxhighlight>

2026年10月1日 (四) 16:23的最新版本

Ubuntu server setup (for new VPS onboarding)

Installation

Ghostty settings

# Fix 
# root@riguz4c8g:~# clear
# 'xterm-ghostty': unknown terminal type."

infocmp -x xterm-ghostty | ssh root@83.229.121.141 -- tic -x -

Update system

sudo apt update
sudo apt full-upgrade -y
sudo apt autoremove --purge -y
root@riguz4c8g:~# lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description:    Ubuntu 24.04.5 LTS
Release:        24.04
Codename:       noble

Not recommended to do-release-upgrade (from 24 -> 26)

System settings

Add admin user:

adduser riguz
usermod -aG sudo riguz


hostname

vim /etc/hostname

ssh config

ssh-copy-id -p 50000 ubuntu@12.98.23.12

# vim /etc/ssh/sshd_config
Port 54194
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes

service ssh restart
ssh -p 50000 ubuntu@12.98.23.12

Note: for Ubuntu 24.04+ with systemd socket

# To change the port
sudo vim /lib/systemd/system/ssh.socket
[Socket]
ListenStream=0.0.0.0:54194
ListenStream=[::]:54194

sudo systemctl daemon-reload
sudo systemctl stop ssh.socket
sudo systemctl restart ssh
netstat -anp | grep 54194
(No info could be read for "-p": geteuid()=1000 but you should be root.)
tcp        0      0 0.0.0.0:54194           0.0.0.0:*               LISTEN      -
tcp6       0      0 :::54194                :::*                    LISTEN      -

ufw

sudo ufw enable
sudo ufw allow 80
sudo ufw allow 443
sudo ufw allow 54194
sudo ufw status numbered

V2ray

V2Ray global proxy

Web server

Ngnix

$ sudo apt install nginx
$ sudo systemctl status nginx

Certbot

Install via pip[1]

sudo apt install certbot
sudo apt install python3 python3-dev python3-venv libaugeas-dev gcc
sudo python3 -m venv /opt/certbot/
sudo /opt/certbot/bin/pip install --upgrade pip
sudo /opt/certbot/bin/pip install certbot certbot-nginx
sudo ln -s /opt/certbot/bin/certbot /usr/bin/certbot
sudo certbot --nginx
sudo nginx -s reload