Ubuntu server setup (VPS):修订间差异
| (未显示同一用户的13个中间版本) | |||
| 第1行: | 第1行: | ||
= | Ubuntu server setup (for new VPS onboarding) | ||
= Installation = | |||
== Ghostty settings == | |||
<syntaxhighlight lang="bash"> | |||
# Fix | |||
# root@riguz4c8g:~# clear | |||
# 'xterm-ghostty': unknown terminal type." | |||
infocmp -x xterm-ghostty | ssh root@83.229.121.141 -- tic -x - | |||
</syntaxhighlight> | |||
== Update system == | == Update system == | ||
<syntaxhighlight lang="bash"> | <syntaxhighlight lang="bash"> | ||
sudo apt update | sudo apt update | ||
sudo apt upgrade | sudo apt full-upgrade -y | ||
sudo apt autoremove --purge -y | |||
</syntaxhighlight> | |||
<syntaxhighlight lang="bash"> | |||
root@riguz4c8g:~# lsb_release -a | |||
No LSB modules are available. | |||
Distributor ID: Ubuntu | |||
Description: Ubuntu 24.04.5 LTS | |||
Release: 24.04 | |||
Codename: noble | |||
</syntaxhighlight> | </syntaxhighlight> | ||
Not recommended to do-release-upgrade (from 24 -> 26) | |||
== System settings == | |||
Add admin user: | |||
<syntaxhighlight lang="bash"> | <syntaxhighlight lang="bash"> | ||
adduser riguz | |||
usermod -aG sudo riguz | |||
</syntaxhighlight> | </syntaxhighlight> | ||
== | |||
== hostname == | |||
<syntaxhighlight lang="bash"> | <syntaxhighlight lang="bash"> | ||
vim /etc/hostname | |||
</syntaxhighlight> | </syntaxhighlight> | ||
| 第27行: | 第49行: | ||
# vim /etc/ssh/sshd_config | # vim /etc/ssh/sshd_config | ||
Port 54194 | |||
PermitRootLogin no | PermitRootLogin no | ||
PasswordAuthentication no | PasswordAuthentication no | ||
| 第32行: | 第55行: | ||
service ssh restart | service ssh restart | ||
ssh -p 50000 | ssh -p 50000 ubuntu@12.98.23.12 | ||
</syntaxhighlight> | |||
Note: for Ubuntu 24.04+ with systemd socket | |||
<syntaxhighlight lang="bash"> | |||
# To change the port | |||
sudo vim /lib/systemd/system/ssh.socket | |||
[Socket] | |||
ListenStream=0.0.0.0:54194 | |||
ListenStream=[::]:54194 | |||
sudo systemctl daemon-reload | |||
sudo systemctl stop ssh.socket | |||
sudo systemctl restart ssh | |||
netstat -anp | grep 54194 | |||
(No info could be read for "-p": geteuid()=1000 but you should be root.) | |||
tcp 0 0 0.0.0.0:54194 0.0.0.0:* LISTEN - | |||
tcp6 0 0 :::54194 :::* LISTEN - | |||
</syntaxhighlight> | |||
== ufw== | |||
<syntaxhighlight lang="bash"> | |||
sudo ufw enable | |||
sudo ufw allow 80 | |||
sudo ufw allow 443 | |||
sudo ufw allow 54194 | |||
sudo ufw status numbered | |||
</syntaxhighlight> | |||
== V2ray == | |||
[[V2Ray global proxy]] | |||
= Web server = | |||
== Ngnix == | |||
<syntaxhighlight lang="bash"> | |||
$ sudo apt install nginx | |||
$ sudo systemctl status nginx | |||
</syntaxhighlight> | </syntaxhighlight> | ||
== Add deploy user (Github actions) == | |||
<syntaxhighlight lang="bash"> | |||
sudo adduser --disabled-password deploy | |||
sudo mkdir -p /home/deploy/.ssh | |||
sudo touch /home/deploy/.ssh/authorized_keys | |||
sudo chmod 700 /home/deploy/.ssh | |||
sudo chmod 600 /home/deploy/.ssh/authorized_keys | |||
sudo chown -R deploy:deploy /home/deploy/.ssh | |||
# generate new key in local pc | |||
ssh-keygen -t ed25519 -C "gh-actions-deploy-$(date +%Y%m%d)" -f ~/.ssh/gh_deploy_new | |||
# save pub key to authorized_keys in server | |||
cat gh_deploy_new.pub | |||
sudo vim /home/deploy/.ssh/authorized_keys | |||
cat gh_deploy_new | |||
# save private key to DEPLOY_KEY | |||
# verify if the key is able to login | |||
ssh -i ~/.ssh/gh_deploy_new -o IdentitiesOnly=yes -p 2222 deploy@83.229.121.141 | |||
</syntaxhighlight> | |||
== Certbot == | |||
Install via pip<ref>https://certbot.eff.org/instructions?ws=nginx&os=pip&commit=%3E</ref> | |||
<syntaxhighlight lang="bash"> | |||
sudo apt install certbot | |||
sudo apt install python3 python3-dev python3-venv libaugeas-dev gcc | |||
sudo python3 -m venv /opt/certbot/ | |||
sudo /opt/certbot/bin/pip install --upgrade pip | |||
sudo /opt/certbot/bin/pip install certbot certbot-nginx | |||
sudo ln -s /opt/certbot/bin/certbot /usr/bin/certbot | |||
sudo certbot --nginx | |||
sudo nginx -s reload | |||
</syntaxhighlight> | |||
[[Category:Linux/Unix]] | [[Category:Linux/Unix]] | ||