Ubuntu server setup (VPS):修订间差异
| (未显示同一用户的5个中间版本) | |||
| 第1行: | 第1行: | ||
Ubuntu server setup | Ubuntu server setup (for new VPS onboarding) | ||
= | = Installation = | ||
== Ghostty settings == | |||
<syntaxhighlight lang="bash"> | <syntaxhighlight lang="bash"> | ||
# Fix | |||
# root@riguz4c8g:~# clear | |||
# 'xterm-ghostty': unknown terminal type." | |||
infocmp -x xterm-ghostty | ssh root@83.229.121.141 -- tic -x - | |||
</syntaxhighlight> | </syntaxhighlight> | ||
== Update system == | == Update system == | ||
<syntaxhighlight lang="bash"> | <syntaxhighlight lang="bash"> | ||
sudo apt update | sudo apt update | ||
sudo apt upgrade | sudo apt full-upgrade -y | ||
sudo apt autoremove --purge -y | |||
</syntaxhighlight> | |||
<syntaxhighlight lang="bash"> | |||
root@riguz4c8g:~# lsb_release -a | |||
No LSB modules are available. | |||
Distributor ID: Ubuntu | |||
Description: Ubuntu 24.04.5 LTS | |||
Release: 24.04 | |||
Codename: noble | |||
</syntaxhighlight> | </syntaxhighlight> | ||
Not recommended to do-release-upgrade (from 24 -> 26) | |||
== System settings == | |||
Add admin user: | |||
<syntaxhighlight lang="bash"> | <syntaxhighlight lang="bash"> | ||
adduser riguz | |||
usermod -aG sudo riguz | |||
</syntaxhighlight> | </syntaxhighlight> | ||
== | |||
== hostname == | |||
<syntaxhighlight lang="bash"> | <syntaxhighlight lang="bash"> | ||
vim /etc/hostname | |||
</syntaxhighlight> | </syntaxhighlight> | ||
| 第35行: | 第49行: | ||
# vim /etc/ssh/sshd_config | # vim /etc/ssh/sshd_config | ||
Port 54194 | |||
PermitRootLogin no | PermitRootLogin no | ||
PasswordAuthentication no | PasswordAuthentication no | ||
| 第41行: | 第56行: | ||
service ssh restart | service ssh restart | ||
ssh -p 50000 ubuntu@12.98.23.12 | ssh -p 50000 ubuntu@12.98.23.12 | ||
</syntaxhighlight> | |||
Note: for Ubuntu 24.04+ with systemd socket | |||
<syntaxhighlight lang="bash"> | |||
# To change the port | |||
sudo vim /lib/systemd/system/ssh.socket | |||
[Socket] | |||
ListenStream=0.0.0.0:54194 | |||
ListenStream=[::]:54194 | |||
sudo systemctl daemon-reload | |||
sudo systemctl stop ssh.socket | |||
sudo systemctl restart ssh | |||
netstat -anp | grep 54194 | |||
(No info could be read for "-p": geteuid()=1000 but you should be root.) | |||
tcp 0 0 0.0.0.0:54194 0.0.0.0:* LISTEN - | |||
tcp6 0 0 :::54194 :::* LISTEN - | |||
</syntaxhighlight> | </syntaxhighlight> | ||
| 第48行: | 第80行: | ||
sudo ufw allow 80 | sudo ufw allow 80 | ||
sudo ufw allow 443 | sudo ufw allow 443 | ||
sudo ufw allow | sudo ufw allow 54194 | ||
sudo ufw status numbered | sudo ufw status numbered | ||
</syntaxhighlight> | </syntaxhighlight> | ||
| 第61行: | 第93行: | ||
$ sudo apt install nginx | $ sudo apt install nginx | ||
$ sudo systemctl status nginx | $ sudo systemctl status nginx | ||
</syntaxhighlight> | |||
== Add deploy user (Github actions) == | |||
<syntaxhighlight lang="bash"> | |||
sudo adduser --disabled-password deploy | |||
sudo mkdir -p /home/deploy/.ssh | |||
sudo touch /home/deploy/.ssh/authorized_keys | |||
sudo chmod 700 /home/deploy/.ssh | |||
sudo chmod 600 /home/deploy/.ssh/authorized_keys | |||
sudo chown -R deploy:deploy /home/deploy/.ssh | |||
# generate new key in local pc | |||
ssh-keygen -t ed25519 -C "gh-actions-deploy-$(date +%Y%m%d)" -f ~/.ssh/gh_deploy_new | |||
# save pub key to authorized_keys in server | |||
cat gh_deploy_new.pub | |||
sudo vim /home/deploy/.ssh/authorized_keys | |||
cat gh_deploy_new | |||
# save private key to DEPLOY_KEY | |||
# verify if the key is able to login | |||
ssh -i ~/.ssh/gh_deploy_new -o IdentitiesOnly=yes -p 2222 deploy@83.229.121.141 | |||
</syntaxhighlight> | </syntaxhighlight> | ||