Ubuntu server setup (VPS):修订间差异
外观
小无编辑摘要 |
|||
| (未显示同一用户的2个中间版本) | |||
| 第93行: | 第93行: | ||
$ sudo apt install nginx | $ sudo apt install nginx | ||
$ sudo systemctl status nginx | $ sudo systemctl status nginx | ||
</syntaxhighlight> | |||
== Add deploy user (Github actions) == | |||
<syntaxhighlight lang="bash"> | |||
sudo adduser --disabled-password deploy | |||
sudo mkdir -p /home/deploy/.ssh | |||
sudo touch /home/deploy/.ssh/authorized_keys | |||
sudo chmod 700 /home/deploy/.ssh | |||
sudo chmod 600 /home/deploy/.ssh/authorized_keys | |||
sudo chown -R deploy:deploy /home/deploy/.ssh | |||
# generate new key in local pc | |||
ssh-keygen -t ed25519 -C "gh-actions-deploy-$(date +%Y%m%d)" -f ~/.ssh/gh_deploy_new | |||
# save pub key to authorized_keys in server | |||
cat gh_deploy_new.pub | |||
sudo vim /home/deploy/.ssh/authorized_keys | |||
cat gh_deploy_new | |||
# save private key to DEPLOY_KEY | |||
# verify if the key is able to login | |||
ssh -i ~/.ssh/gh_deploy_new -o IdentitiesOnly=yes -p 2222 deploy@83.229.121.141 | |||
</syntaxhighlight> | </syntaxhighlight> | ||
2026年10月4日 (日) 13:58的最新版本
Ubuntu server setup (for new VPS onboarding)
Installation
Ghostty settings
# Fix
# root@riguz4c8g:~# clear
# 'xterm-ghostty': unknown terminal type."
infocmp -x xterm-ghostty | ssh root@83.229.121.141 -- tic -x -
Update system
sudo apt update
sudo apt full-upgrade -y
sudo apt autoremove --purge -y
root@riguz4c8g:~# lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description: Ubuntu 24.04.5 LTS
Release: 24.04
Codename: noble
Not recommended to do-release-upgrade (from 24 -> 26)
System settings
Add admin user:
adduser riguz
usermod -aG sudo riguz
hostname
vim /etc/hostname
ssh config
ssh-copy-id -p 50000 ubuntu@12.98.23.12
# vim /etc/ssh/sshd_config
Port 54194
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
service ssh restart
ssh -p 50000 ubuntu@12.98.23.12
Note: for Ubuntu 24.04+ with systemd socket
# To change the port
sudo vim /lib/systemd/system/ssh.socket
[Socket]
ListenStream=0.0.0.0:54194
ListenStream=[::]:54194
sudo systemctl daemon-reload
sudo systemctl stop ssh.socket
sudo systemctl restart ssh
netstat -anp | grep 54194
(No info could be read for "-p": geteuid()=1000 but you should be root.)
tcp 0 0 0.0.0.0:54194 0.0.0.0:* LISTEN -
tcp6 0 0 :::54194 :::* LISTEN -
ufw
sudo ufw enable
sudo ufw allow 80
sudo ufw allow 443
sudo ufw allow 54194
sudo ufw status numbered
V2ray
Web server
Ngnix
$ sudo apt install nginx
$ sudo systemctl status nginx
Add deploy user (Github actions)
sudo adduser --disabled-password deploy
sudo mkdir -p /home/deploy/.ssh
sudo touch /home/deploy/.ssh/authorized_keys
sudo chmod 700 /home/deploy/.ssh
sudo chmod 600 /home/deploy/.ssh/authorized_keys
sudo chown -R deploy:deploy /home/deploy/.ssh
# generate new key in local pc
ssh-keygen -t ed25519 -C "gh-actions-deploy-$(date +%Y%m%d)" -f ~/.ssh/gh_deploy_new
# save pub key to authorized_keys in server
cat gh_deploy_new.pub
sudo vim /home/deploy/.ssh/authorized_keys
cat gh_deploy_new
# save private key to DEPLOY_KEY
# verify if the key is able to login
ssh -i ~/.ssh/gh_deploy_new -o IdentitiesOnly=yes -p 2222 deploy@83.229.121.141
Certbot
Install via pip[1]
sudo apt install certbot
sudo apt install python3 python3-dev python3-venv libaugeas-dev gcc
sudo python3 -m venv /opt/certbot/
sudo /opt/certbot/bin/pip install --upgrade pip
sudo /opt/certbot/bin/pip install certbot certbot-nginx
sudo ln -s /opt/certbot/bin/certbot /usr/bin/certbot
sudo certbot --nginx
sudo nginx -s reload