ãçæ³çãªãã¯ã©ã¹ã¿ãŒã«é¢ããäžé£ã®èšäºã®ç¶ããšããŠãä¿¡é Œæ§ãé«ããçç£æ§ãé«ãã管çããããWebã·ã¹ãã ãäœæããããã®ã¬ã·ããå ±æããããšæããŸãã
ãµã€ãããã³Webã·ã¹ãã ã®ä¿¡é Œæ§ãšé«éæ§ã確ä¿ããããã«ãåœç€Ÿã§ã¯åžå Žã§å©çšå¯èœãªæè¡çæ段ã®èª¿æ»ãå®æœããŸããã ç§ãã¡ã¯ã·ã³ãã«ãªç®æšã«å°ãããŸããïŒã·ã¹ãã ã®ã¹ã±ãŒã©ããªãã£ãšé«ãããã©ãŒãã³ã¹ãåæã«éæããããšã
å®éãã¯ã©ã¹ã¿ãŒã¯ãŒãããæ§ç¯ãããŸããã ããã³ããšã³ãããã¯ãšã³ãã¢ãŒããã¯ãã£ããããŸããã ããŒã¿ããŒã¹ã¯MariaDB Galeraã«éããããã¹ãŠã®ãµã€ãã¯çµ±åãããWebããŒãã«ç§»åããŸããã
é·æéã®äœæ¥ãçŽäºãè°è«ã®éçšã§ã ã¢ã¯ããã¹ãåãã§å ±æã§ããæ¢è£œã®ãœãªã¥ãŒã·ã§ã³ãçãŸããŸããã ç§ãã¡ã¯å©ããããã«ååšããŸãã
ãçæ³çãªãã¯ã©ã¹ã¿ãŒã«é¢ããä»ã®åºçç©
- PHPãµã€ããé«éåããæé©åããŸãã PHPçšã®ãµãŒããŒãã»ããã¢ãããããšãã«éžæãããã¯ãããžãŒ
- ãçæ³çãªãã¯ã©ã¹ã¿ãŒã ããŒã3.1 MySQLãã«ããã¹ã¿ãŒã¯ã©ã¹ã¿ãŒã®ãããã€
- ãçæ³çãªãã¯ã©ã¹ã¿ãŒã ããŒã2.2ïŒã¢ã¯ã»ã¹ããããã¹ã±ãŒã©ãã«ãªWebãµãŒããŒãããžãã¹ãå®ãããã®æé«ã®ãã¯ãããžãŒ
- hetznerã®ä»®æ³ã¯ã©ã¹ã¿ãŒã«ã€ããŠ
- ããã³ããšã³ãïŒCentOSäžã®NGINX + KeepalivedïŒvrrpïŒ
- CentOSäžã®PerconaãŸãã¯Galeraã®HAPRoxyã Zabbixã§ã®èšå®ãšç£èŠ
- nginx + php-fpmããã³mariadbã«ä¹ã£ãZabbix 2.2
次ã«ãããã€ãã®éèŠãªåŽé¢ã«ã€ããŠèª¬æããŸãã
- Proxmoxã«åºã¥ããHetznerã®ä»®æ³ã¯ã©ã¹ã¿ãŒã®äŸã䜿çšããŠãå®å šã§ã¹ã±ãŒã©ãã«ãªWebã·ã¹ãã ããããã€ããæ¹æ³
- 1ã€ã®ç¡æã®äŸ¿å©ãªã³ã³ãããŒã«ããã«ãããã¹ãŠã®ã·ã¹ãã ãç°¡åã«ç®¡çããæ¹æ³
- ææ°ã®ãã¯ãããžãŒã䜿çšããŠæ倧ã®ããã©ãŒãã³ã¹ãšã»ãã¥ãªãã£ãå®çŸããæ¹æ³
ãã®èšäºãä»ã®äœçŸãã®èšäºãšã©ãéãã®ããšå°ãããããããŸããã
- CentOSããŒã¹ã®ç¡æã®ISPConfig Webããã·ã¥ããŒãã®ã»ããã¢ããæ¹æ³ïŒDebianç°å¢ã§ã®ããã·ã¥ããŒãã®äœ¿çšã«é¢ããå ¬åŒããã¥ã¡ã³ãã®èª¬æïŒ
- ISPConfig Webããã«èªäœãapache2ãªãã§åäœããããã«èšå®ããæ¹æ³ïŒããã¥ã¡ã³ãã§ã¯ãApache2ã§äœ¿çšããããšã匷ãæšå¥šããŠããŸãïŒ
- nginx + php-phmããã³apache2 + php-fpm / mod_phpããã¯ãšã³ãã䜿çšããŠçç£çãªphpã¢ããªã±ãŒã·ã§ã³ãµãŒããŒãäœæããããã®ã¬ã·ããå ±æããŸãã
- MySQLã®ä»£ããã«MariaDBã®ã€ã³ã¹ããŒã«ãšèšå®ã«ã€ããŠèª¬æããŸã
ã³ã³ã»ããïŒ
- ããšãã°ãç¡æã®Proxmoxã·ã¹ãã ã«åºã¥ããã€ããŒãã€ã¶ãŒãåãäžããŸã
- ãµãŒãã¹ããšã«ãOpenVZã«åºã¥ããŠç¬èªã®ä»®æ³ç°å¢ãäœæããŸãïŒåªãã補åãæäŸããŠãããParallelsã®ååã«æè¬ããŸãïŒ
- gw.localã³ã³ãããŒããããiptablesã䜿çšããŠåã ã®ããŒããä»ã®ã³ã³ãããŒã«è»¢éããŸã
- ispããããŸãã nginx + php-fpm ISPConfigã³ã³ãããŒã«ããã«ãå®è¡ããããŒã«ã«
- front01.local nginxã¯ããã®ã¢ããã¹ããªãŒã ïŒãµã€ãã®å®è¡ãµãŒããŒïŒã®1ã€ã«ãã©ãã£ãã¯ããããã·ããã¢ãŒãã§å®è¡ãããŸãã
- php podã©ã³ã¿ã€ã ãååšããapp01.localããããŸãã apache + php-fpm / mod_phpãŸãã¯nginx + php-fpm
- ã¡ã€ã³ã®MariaDBããŒã¿ããŒã¹ãååšããdb.localããããŸã
app01.localãé€ããã¹ãŠã®ãµãŒããŒã§ãsshãå«ããã¹ãŠã®æªäœ¿çšã®ãµãŒãã¹ãåé€ããããããã®éã®çžäºäœçšã¯ã°ã¬ãŒã®ãã©ã€ããŒããããã¯ãŒã¯ãä»ããŠè¡ãããŸãã ãµã€ãã®éçšã«å¿ èŠãªãããªãã¯ãããã¯ãŒã¯ã«å¯ŸããŠéãããŠããããŒãïŒ80ã443ãªã©ïŒã®ã¿
Proxmoxã®æ¢ç¥ã®åé¡
äœæãããã³ã³ããã®èªåããŒããæå¹ã«ããããšãå¿ããªãã§ãã ãã
vmbr1ããªããžã®ãããã¯ãŒã¯ãäœæãããšãProxmoxã¯ä»®æ³åeth0ãä»ãããããäœæãããããã¯ãŒã¯ãåé€ããŠããã¹ãŠãæ£ããããçŽãå¿ èŠããããŸã
ã³ã³ãããå ¥åããã«ã¯ãã³ã³ãããèµ·åããã¿ãŒããã«ã§ã³ãã³ãvzctl enter container_numberãå ¥åããå¿ èŠããããŸã
Proxmoxã«é¢ããèšäºïŒåé ã®ãªã³ã¯ïŒã§ãå ¬åŒã®ãããªãã¯ãããã¯ãŒã¯ã®ãã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã«ãèšè¿°ããããã¡ã€ã«ã䜿çšãããšè¿°ã¹ãŸããããããã¯çæ³çã«ã¯ç§ãã¡ä»¥å€ã«ã¯ç¥ãããã¹ãã§ã¯ãããŸããã
nano /etc/iptables.up.rules
*nat :PREROUTING ACCEPT [2164:136969] :POSTROUTING ACCEPT [58:3659] :OUTPUT ACCEPT [0:0] # Nat -A POSTROUTING -o vmbr0 -j MASQUERADE # ISPConfig Web Panel -A PREROUTING -d *.*.*182/32 -p tcp -m tcp --dport 8080 -j DNAT --to-destination 192.168.8.3:8080 -A PREROUTING -d *.*.*.182/32 -p tcp -m tcp --dport 8081 -j DNAT --to-destination 192.168.8.3:8081 # app01. ssh server -A PREROUTING -d *.*.*.182/32 -p tcp -m tcp --dport 22 -j DNAT --to-destination 192.168.8.4:22 COMMIT
ïŒãã€ããŒãã€ã¶ãŒã®SSHããŒãã2222ã«å€æŽããŸã
nano /etc/ssh/sshd_config
Port 2222
ãã¹ãŠã®ã³ã³ããã®äžè¬çãªããªã»ãã
ïŒISPConfigãšãŒãžã§ã³ãããããã¹ãŠã®ã³ã³ããã§ããããã®è¡ãå¿ ãhostsãã¡ã€ã«ã«è¿œå ããŠãã ããã
nano /etc/hosts
192.168.8.1 gw.local 192.168.8.2 front01.local 192.168.8.3 isp.local 192.168.8.4 app01.local 192.168.8.5 db01.local
ïŒã¿ã€ã ãŸãŒã³ã
ln -sf /usr/share/zoneinfo/Europe/Moscow /etc/localtime
yum install wget nano wget ntpdate -y
ïŒãããã®ãªããžããªã¯ããã¹ãã§ãããªããªããããã§ã¯åºæ¬ãªããžããªã«ãªãå€ãã®ããã±ãŒãžãèŠã€ããããã§ãã
wget http://dl.fedoraproject.org/pub/epel/6/x86_64/epel-release-6-8.noarch.rpm wget http://rpms.famillecollet.com/enterprise/remi-release-6.rpm sudo rpm -Uvh remi-release-6*.rpm epel-release-6*.rpm rm *.rpm -f
ïŒãã®ãªããžããªã¯äŸ¿å©ã§ãããããã©ã«ãã§ãªãã«ããŸã
rpm --import http://dag.wieers.com/rpm/packages/RPM-GPG-KEY.dag.txt cd /tmp wget http://dag.wieers.com/rpm/packages/rpmforge-release/rpmforge-release-0.3.6-1.el5.rf.x86_64.rpm && rpm -ivh rpmforge-release-0.3.6-1.el5.rf.x86_64.rpm
ïŒãªãã«ããŸãã--enablerepo = rpmforgeã䜿çšããŸã
sed -i 's/enabled = 1/enabled = 0/g' /etc/yum.repos.d/rpmforge.repo
ïŒããããããã¯Webã·ã¹ãã ã®çç ã§ããã管çè ãä»äºã§å¿ èŠãšãããã®ãæ¬åœã«ãããããããŸãã ããªããã°ãªããªã
wget -q -O - http://www.atomicorp.com/installers/atomic | sh
ïŒäŸ¿å©ãªãœãããŠã§ã¢ãå ¥ãã
yum install nano mc screen sudo nscd htop ntp zip unzip pigz iotop sysstat lsof strace atop multitail -y yum --enablerepo=rpmforge install htop -y
ïŒãã®ã³ã³ããã®äžèŠãªãµãŒãã¹ãåé€ãã
yum remove -y sendmail httpd sshd samba bind openssh -y
ïŒã·ã¹ãã ã®æŽæ°
yum update -y
ïŒmysqlãåé€
yum remove mysql* mysql-*
ïŒãµãŒãã¹ç®çã®ISPConfigã«mariadbãã€ã³ã¹ããŒã«ãã
yum install mariadb-server mariadb-devel mariadb-client -y
ïŒcronãã€ã³ã¹ããŒã«
yum install -y cronie cronie-anacron crontabs sysstat -y
ïŒcronãèµ·åã«è¿œå ããŠå®è¡
/etc/init.d/crond start && chkconfig crond on
ïŒmariadbãã«ã¹ã¿ãã€ãºãã
nano /etc/my.cnf
[mysqld] skip-name-resolve default_storage_engine=InnoDB innodb_file_per_table = 1 # network connect_timeout = 60 wait_timeout = 28800 max_connections = 200 max_allowed_packet = 512M max_connect_errors = 1000 # performance query_cache_size = 32M tmp_table_size = 32M max_heap_table_size = 32M thread_cache_size = 16 table_open_cache = 600 innodb_flush_log_at_trx_commit = 2 innodb_flush_method = O_DIRECT transaction-isolation = READ-COMMITTED log_error = /var/log/mysql/mysql-error.log #slow_query_log_file = /var/log/mysql/mysql-slow.log
ïŒmariadbãã¹ã¿ãŒãã¢ããã«è¿œå
chkconfig --levels 235 mysqld on && /etc/init.d/mysqld start
gw.localç°å¢ã®ã»ããã¢ãã
CentOS 64ç°å¢ã§OpenVZã³ã³ããïŒæ°ããCTïŒãäœæããå¿ èŠããããŸããã®ä»®æ³ãã·ã³ã¯ããããªãã¯ããã³ãã©ã€ããŒããããã¯ãŒã¯ã«å¯Ÿå¿ããŸãã
eth1ãããã¯ãŒã¯ïŒä»ã®ã³ã³ãããŒãšå¯Ÿè©±ããããã®ãã©ã€ããŒããããã¯ãŒã¯ïŒã«ã¯ãeth0ïŒãããªãã¯ãããã€ããŒãããã¯ãŒã¯ïŒããã³vmbr1ãšããååã®vmbr0ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ãå¿ èŠã§ãã
ãã®ä»®æ³ãã·ã³ã«ã¯ã128 MBãè¶ ããRAMã¯å¿ èŠãããŸããã
gw.localã³ã³ããèªäœã«ãããã¯ãŒã¯ãèšå®ããŸããã
ã³ã³ããå ã®ãããã¯ãŒã¯ïŒ
vi /etc/sysconfig/network-scripts/ifcfg-eth0
DEVICE=eth0 BOOTPROTO=static ONBOOT=yes IPADDR=xxx237 NETMASK=255.255.255.0 GATEWAY=xxx1
vi /etc/sysconfig/network-scripts/ifcfg-eth1
DEVICE=eth1 BOOTPROTO=static ONBOOT=yes IPADDR=192.168.8.1 NETWORK=192.168.8.0
ïŒçŸåšã®iptablesã«ãŒã«ãä¿å
/etc/init.d/iptables save
ïŒå€éšããžãã¹ã¢ãã¬ã¹ã®* natã»ã¯ã·ã§ã³ã«ã«ãŒã«ãè¿œå ããŸã
vi /etc/sysconfig/iptables
-A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 80 -j DNAT --to-destination 192.168.8.2:80 -A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 443 -j DNAT --to-destination 192.168.8.2:443 -A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 25 -j DNAT --to-destination 192.168.8.5:25 -A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 110 -j DNAT --to-destination 192.168.8.5:110 -A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 145 -j DNAT --to-destination 192.168.8.5:145 -A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 995 -j DNAT --to-destination 192.168.8.5:995 -A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 465 -j DNAT --to-destination 192.168.8.5:465 -A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 587 -j DNAT --to-destination 192.168.8.5:587 -A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 143 -j DNAT --to-destination 192.168.8.5:143 -A PREROUTING -d *.*.*.237/32 -p tcp -m tcp --dport 993 -j DNAT --to-destination 192.168.8.5:993 -A POSTROUTING -o eth0 -j MASQUERADE
ïŒãã©ãã£ãã¯è»¢éãèš±å¯
echo "net.ipv4.ip_forward = 1" >> /etc/sysctl.conf sysctl -p
ç°å¢front01.localã®èšå®
CentOS 64ç°å¢ã§OpenVZã³ã³ãããŒïŒæ°ããCTïŒãäœæããå¿ èŠããããŸããã®ä»®æ³ãã·ã³ã¯ãgw.localãã転éãããããŒã80ããã³443ã«å¯Ÿå¿ããŸãã ãã®ã³ã³ããã«ã¯nginxãã€ã³ã¹ããŒã«ãããŠãããapp01.localã®ãµã€ããžã®ãã¹ãŠã®ãªã¯ãšã¹ãããããã·ããŸã
nginxã®èšå®æé èªäœã¯ããã®èšäºãçæ³çãªãwwwã¯ã©ã¹ã¿ãŒã§è©³ãã説æãããŠããŸãã ããŒã1.ããã³ããšã³ãïŒCentOSã§ã®NGINX + KeepalivedïŒvrrpïŒ
ãã®ã³ã³ããã«ã¯ããã©ã€ããŒããããã¯ãŒã¯ïŒ vmbr1 ïŒ 192.168.8.2ã®ã¢ãã¬ã¹ããããæäœã«ã¯1024 MB以äžã®RAMãå¿ èŠã§ãã
ããã¯ããããã¯ãŒã¯ãã³ã³ããèªäœã§ã©ã®ããã«èŠãããã§ãã
vi /etc/sysconfig/network-scripts/ifcfg-eth1
DEVICE=eth1 BOOTPROTO=static ONBOOT=yes IPADDR=192.168.8.2 NETWORK=192.168.8.0 GATEWAY=192.168.8.1
ç°å¢ã®èšå®ispã
CentOS 64ç°å¢ã§OpenVZã³ã³ãããŒïŒæ°ããCTïŒãäœæããå¿ èŠããããŸããã®ä»®æ³ãã·ã³ã¯ãISPConfigã³ã³ãããŒã«ããã«ãæäŸããŸãã èšäºã®åé ã§ãããã«ã¯ãããªãã¯ãããªãã¯ã¢ãã¬ã¹ã«ãã£ãŠæäŸãããããŒã8080ããã³8081ã§å©çšã§ããããšã瀺ããŸããã
ãã®ã³ã³ããã«ã¯ããã©ã€ããŒããããã¯ãŒã¯ã¢ãã¬ã¹ïŒ vmbr1 ïŒ 192.168.8.3ããããçŽ384 MBã®RAMãå¿ èŠã§ãã
ïŒãã®ã³ã³ããã®ãããã¯ãŒã¯èšå®ïŒ
/etc/sysconfig/network-scripts/ifcfg-eth1
DEVICE=eth1 BOOTPROTO=static ONBOOT=yes IPADDR=192.168.8.3 NETWORK=192.168.8.0 GATEWAY=192.168.8.100
ïŒISPConfigããã«ã®WebãµãŒããŒã³ã³ããŒãã³ããã€ã³ã¹ããŒã«ãã
yum install php-mysql php nginx php-fpm postfix patch -y
ïŒæšæºã®nginxã°ãªãŒãã£ã³ã°ã§èšå®ãåé€
rm -f /etc/nginx/conf.d/default.conf rm -f /etc/nginx/conf.d/virtual.conf rm -f /etc/nginx/conf.d/ssl.conf
ïŒnginxãšphp-fpmãè¿œå ããŠããªãŒãããŒãããŠå®è¡ããŸã
chkconfig --levels 235 php-fpm on && /etc/init.d/php-fpm start chkconfig --levels 235 nginx on && /etc/init.d/nginx start
ïŒISPConfigãšãŒãžã§ã³ãããã©ã¡ãŒã¿ãŒã«ã€ããŠäžå€®ã®isp.localããŒã¿ããŒã¹ã«æ¥ç¶ã§ããããã«ãã
mysql
CREATE USER 'root'@'192.168.8.%' IDENTIFIED BY 'c2HZqsMmiBKa'; GRANT ALL PRIVILEGES ON * . * TO 'root'@'192.168.8.%' IDENTIFIED BY 'c2HZqsMmiBKa' WITH GRANT OPTION; flush privileges;
ïŒphpMyAdminãã€ã³ã¹ããŒã«
yum install phpmyadmin -y
ïŒphpmyadminã§phpMyAdminã·ã³ããªãã¯ãªã³ã¯ãäœæãã
ln -s /usr/share/phpMyAdmin/ /usr/share/phpmyadmin
nano /etc/phpMyAdmin/config.inc.php
$cfg['blowfish_secret'] = '46a30e4ed1cf83.14522379'; /* YOU MUST FILL IN THIS FOR COOKIE AUTH! */ $cfg['Servers'][$i]['host'] = 'db01.local'; // MySQL hostname or IP address $cfg['Servers'][$i]['port'] = '3306'; // MySQL port - leave blank for default port $cfg['Servers'][$i]['auth_type'] = 'cookie'; // Authentication method (config, http or cookie based)?
ïŒISPConfigãã€ã³ã¹ããŒã«
cd /usr/src/ wget http://www.ispconfig.org/downloads/ISPConfig-3-stable.tar.gz tar xfz ISPConfig-3-stable.tar.gz cd ispconfig3_install/install/ php -q install.php
ïŒå¯Ÿè©±åã€ã³ã¹ããŒã«ãŠã£ã¶ãŒãã®è³ªåã«çããŸã
>>åæèšå®
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒRedhatãŸãã¯äºææ§ã®ãããäžæãªããŒãžã§ã³ã
以äžã¯ããã©ã€ããªèšå®ã«é¢ããããã€ãã®è³ªåã§ãã®ã§ã泚æããŠãã ããã
ããã©ã«ãå€ã¯[è§æ¬åŒ§]ã§å²ãŸããåãå ¥ããããŸãã
ãåŒçšããªãã§ãçµäºããã¿ããããŠãã€ã³ã¹ããŒã©ãŒãåæ¢ããŸãã
èšèªãéžæïŒenãdeïŒ[ en ]ïŒ
ã€ã³ã¹ããŒã«ã¢ãŒãïŒæšæºããšãã¹ããŒãïŒ[æšæº]ïŒ ãšãã¹ããŒã
ãµãŒããŒã®å®å šä¿®é£Ÿãã¹ãåïŒFQDNïŒãäŸïŒserver1.domain.tld [ isp.local ]ïŒ
MySQLãµãŒããŒã®ãã¹ãå[ localhost ]ïŒ
MySQLã«ãŒããŠãŒã¶ãŒå[ root ]ïŒ
MySQLã«ãŒããã¹ã¯ãŒã[]ïŒ
äœæããMySQLããŒã¿ããŒã¹[ dbispconfig ]ïŒ
MySQLæåã»ãã[ utf8 ]ïŒ
次ã®2ã€ã®è³ªåã¯ãå éšISPConfigããŒã¿ããŒã¹ã®ãŠãŒã¶ãŒãšãã¹ã¯ãŒãã«é¢ãããã®ã§ãã
ãŠãŒã¶ãŒåãšããŠãispconfigãã§ãããã©ã³ãã ãªãã¹ã¯ãŒãã§ããããã©ã«ããåãå ¥ããããšããå§ãããŸãã
å¥ã®ãã¹ã¯ãŒãã䜿çšããå Žåã¯ããã¹ã¯ãŒãã«æ°åãšæåã®ã¿ã䜿çšããŠãã ããã
ISPConfig mysqlããŒã¿ããŒã¹ã®ãŠãŒã¶ãŒå[ ispconfig ]ïŒ
ISPConfig mysqlããŒã¿ããŒã¹ãã¹ã¯ãŒã[ 1850fcffe2fc0b1ca2707c3e27c5eec4 ]ïŒ
ãã®ãµãŒããŒãæ¢åã®ISPConfigãã«ããµãŒããŒã»ããã¢ããïŒyãnïŒ[ n ]ã«åå ãããŸãã
Apacheãšnginxãæ€åºãããŸããã ISPConfigã«äœ¿çšãããµãŒããŒãéžæïŒïŒapacheãnginxïŒ[apache]ïŒ nginx
ISPConfigãµãŒããŒã¬ã³ãŒããããŒã¿ããŒã¹ã«è¿œå ããŠããŸãã
ã¡ãŒã«ã®æ§æïŒyãnïŒ[y]ïŒ n
Jailkitã®æ§æïŒyãnïŒ[y]ïŒ n
FTPãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ y
Pureftpdã®æ§æ
DNSãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ n
ãã³ãïŒãã®ãµãŒããŒãISPConfigã€ã³ã¿ãŒãã§ãŒã¹ãå®è¡ããå Žåã¯ããConfigure nginx Serverããªãã·ã§ã³ã§ãyããéžæããŸãã
nginxãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ y
nginxã®æ§æ
Apps vhostã®æ§æ
ãã¡ã€ã¢ãŠã©ãŒã«ãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ y
Bastille Firewallã®æ§æ
ISPConfig Webã€ã³ã¿ãŒãã§ã€ã¹ã®ã€ã³ã¹ããŒã«ïŒyãnïŒ[y]ïŒ y
ISPConfigã®ã€ã³ã¹ããŒã«
ISPConfigããŒã[ 8080 ]ïŒ
ISPConfig Webã€ã³ã¿ãŒãã§ãŒã¹ã®SSLãæå¹ã«ããŸãïŒyãnïŒ[y]ïŒ y
RSAç§å¯éµã4096ãããé·ã®ã¢ãžã¥ã©ã¹ã®çæ
.................................................. .............. ++
.................................................. .................................................. ................... ++
eã¯65537ïŒ0x10001ïŒã§ã
çµã¿èŸŒãŸããæ å ±ã®å ¥åãæ±ããããŸã
蚌ææžèŠæ±ã«ã
å ¥åããããšããŠããã®ã¯ãèå¥åãŸãã¯DNãšåŒã°ãããã®ã§ãã
ããªãã®æ°ã®ãã£ãŒã«ãããããŸããã空çœã®ãŸãŸã«ããããšãã§ããŸã
äžéšã®ãã£ãŒã«ãã«ã¯ããã©ã«ãå€ããããŸããã
ããããå ¥åãããšããã£ãŒã«ãã¯ç©ºçœã®ãŸãŸã«ãªããŸãã
-åœåïŒ2æåã®ã³ãŒãïŒ[XX]ïŒ Ru
å·ãŸãã¯çã®ååïŒãã«ããŒã ïŒ[]ïŒ ã¢ã¹ã¯ã¯
å°ååïŒäŸïŒéœåžïŒ[ããã©ã«ãã®éœåž]ïŒ ã¢ã¹ã¯ã¯
çµç¹åïŒäŒç€Ÿãªã©ïŒ[Default Company Ltd]ïŒ isp.local
çµç¹åäœåïŒã»ã¯ã·ã§ã³ãªã©ïŒ[]ïŒ IT
å ±éåïŒäŸïŒèªåã®ååãŸãã¯ãµãŒããŒã®ãã¹ãåïŒ[]ïŒ isp.local
ã¡ãŒã«ã¢ãã¬ã¹[]ïŒ
次ã®ãè¿œå ãå±æ§ãå ¥åããŠãã ãã
蚌ææžãªã¯ãšã¹ããšãšãã«éä¿¡ãããŸã
ãã£ã¬ã³ãžãã¹ã¯ãŒã[]ïŒ
ãªãã·ã§ã³ã®äŒç€Ÿå[]ïŒ
RSAããŒãæžã
DBServerã®æ§æ
ISPConfig crontabã®ã€ã³ã¹ããŒã«
ã«ãŒãã®crontabã¯ãããŸãã
php-fpmã®ãªããŒãïŒ[OK]
nginxã®ãªããŒãïŒ[OK]
ã€ã³ã¹ããŒã«ãå®äºããŸããã
ïŒISPConfigããã«ããµãŒãã¹ãããªãã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ããŒã8080ã«è»¢éããŸãã
https://__ip:8080/
ããã©ã«ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãïŒ admin
ïŒ ãã®ãµã€ãã«ã€ã³ã¹ããŒã«ãããŠããISPConfigã®ããŒãžã§ã³ã§æ¢ç¥ã®åé¡ã確èªããŸãã æŽæ°ããã°ã©ã ä»ãã®ããããããå Žåã¯ãããããé©çšããŸã
cd /usr/local/ispconfig/server/scripts wget http://www.ispconfig.org/downloads/ispconfig_patch chmod 700 ispconfig_patch chown root:root ispconfig_patch ln -s /usr/local/ispconfig/server/scripts/ispconfig_patch /usr/local/bin/ispconfig_patch
ïŒããã¯å©çšå¯èœãªãå·çæç¹ã§ã®ãããã®ãªã¹ãã§ã
ISPConfig 3.0.5.3ã®ããã
ãããIDïŒ 3053_langedit
æ¥ä»ïŒ2013-09-25
説æïŒãã®ãããã¯ãèšèªãã¡ã€ã«ãšãã£ã¿ã®UTF-8ãšã³ã³ãŒãã£ã³ã°ã®åé¡ã解決ããŸãã
ãããIDïŒ 3053_langimport
説æïŒãã®ãããã¯ãèšèªãã¡ã€ã«ã€ã³ããŒã¿ãŒã«å³å¯ãªè§£æã«ãŒãã³ãè¿œå ããŸãã
ãããIDïŒ 3053_backupdownload
説æïŒãã®ãããã¯ãWebãµã€ãã®ããã¯ã¢ããã®ããŠã³ããŒããšåŸ©å ã«é¢ããåé¡ãä¿®æ£ããŸãã
ãããIDïŒ 3053_apsdelââete
説æïŒãã®ãããã¯ãAPSã€ã³ã¹ã¿ã³ã¹ãåé€ããéã®åé¡ãä¿®æ£ããŸãã
ãããIDïŒ 3053_ftpuser
説æïŒãã®ãããã«ãããFSïŒ3089-FTPãŠãŒã¶ãŒãªãã·ã§ã³-ãšã©ãŒãä¿®æ£ãããŸãããã®ãã¡ã€ã³ã«å¯Ÿããæš©éããããŸããã
ãããIDïŒ 3053_phpversion
説æïŒãã®ãããã¯ãã¯ã©ã€ã¢ã³ããWebãµã€ãã®phpããŒãžã§ã³ãå€æŽã§ããªãåé¡ãä¿®æ£ããŸãã ã¯ã©ã€ã¢ã³ãã€ã³ã¿ãŒãã§ãŒã¹ã«è¡šç€ºãããå¯äžã®phpéžæãªãã·ã§ã³ã¯ãããã©ã«ããã§ãã
ãããIDïŒ 3053_sysini
説æïŒãã®ãããã¯ãFSïŒ3086-ãã«ããµãŒããŒèšå®ã§ã®sys_iniã¢ã¯ã»ã¹ã«é¢ããSQLã¯ãšãªèŠåãä¿®æ£ããŸãã
ãããIDïŒ 3053_dashboard
説æïŒãã®ãããã¯ãããã·ã¥ããŒãã®è¡šç€ºã®åé¡ïŒã¯ã©ãŒã¿ããŒãã«ã®éè€ïŒãä¿®æ£ããŸãã
ïŒphpMyAdminãæ åœããã»ã¯ã·ã§ã³ã®ã³ã¡ã³ããå€ããŸã
nano /etc/nginx/sites-enabled/000-ispconfig.vhost
location /phpmyadmin { root /usr/share/; index index.php index.html index.htm; location ~ ^/phpmyadmin/(.+\.php)$ { try_files $uri =404; root /usr/share/; include /etc/nginx/fastcgi_params; fastcgi_pass unix:/var/lib/php5-fpm/ispconfig.sock; fastcgi_param HTTPS on; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $request_filename; } location ~* ^/phpmyadmin/(.+\.(jpg|jpeg|gif|css|png|js|ico|html|xml|txt))$ { root /usr/share/; } } location /phpMyAdmin { rewrite ^/* /phpmyadmin last; }
/etc/init.d/nginx reload
ç°å¢app01.localã®èšå®ïŒapache2 + php-fpmïŒ
CentOS 64ç°å¢ã§OpenVZã³ã³ããïŒæ°ããCTïŒãäœæããå¿ èŠããããŸããã®ä»®æ³ãã·ã³ã¯ãphpã§æžããããµã€ããæäŸããŸãã äžè¬ã«ãapache2ã¯nginxãããã¯ããã«é ããéçãã¡ã€ã«ïŒã°ã©ãã£ãã¯ãã¹ã¯ãªãããã¹ã¿ã€ã«ãªã©ïŒãæäŸããŸãããŸããmod_phpãšçµã¿åãããŠãçä¿¡ãªã¯ãšã¹ãã®åŠçã«å€ãã®ã¡ã¢ãªãæ¶è²»ããŸãã ããã¯ãapache2ã¢ãŒããã¯ãã£èªäœã«ãããã®ã§ãã ã¡ã¢ãªæ¶è²»ã®åé¡ãphp-fpmã䜿çšããŠè§£æ±ºã§ããå Žåãé ãéçãšã®ã¿èª¿æŽã§ããfront.localã®nginxåŽã®ãã£ãã·ã¥ã§ãããéšââåçã«è£æ£ã§ããŸãã
apache2ã䜿çšããã®ã¯ã.htaccessãŸãã¯apache2å°çšã®ã¢ãžã¥ãŒã«ã䜿çšããå¿ èŠãããå Žåã«ã®ã¿æå³ããããŸãã
ãã®ä»®æ³ãã·ã³ã®sshããŒãã¯ãµãŒãã¹ãããªãã¯ã¢ãã¬ã¹ãã転éãããããŒã80ã¯front.localãããããã·ãããŸã
ãã®ã³ã³ããã«ã¯ãã©ã€ããŒããããã¯ãŒã¯ïŒ vmbr1 ïŒ 192.168.8.4ã®ã¢ãã¬ã¹ãããããã®ä»®æ³ãã·ã³ã®RAMã«ä¿åãã䟡å€ã¯ãããŸãããäžè¬çã«ã¯4ã20 GBã«ãªããŸãã
ïŒãã®ã³ã³ããã®ãããã¯ãŒã¯èšå®ïŒ
vi /etc/sysconfig/network-scripts/ifcfg-eth1
DEVICE=eth1 BOOTPROTO=static ONBOOT=yes IPADDR=192.168.8.4 NETWORK=192.168.8.0 GATEWAY=192.168.8.100
ïŒWebãµãŒããŒã³ã³ããŒãã³ããã€ã³ã¹ããŒã«ãã
yum install mod_rpaf memcached ntp httpd php php-mysql php-mbstring php-mcrypt rpm-build openssl-devel cyrus-sasl-devel pkgconfig zlib-devel pcre-devel openldap-devel postgresql-devel expect libtool-ltdl-devel openldap-servers libtool gdbm-devel pam-devel gamin-devel mod_ssl php-fpm php-cli php-gd php-imap php-ldap php-odbc php-pear php-xml php-xmlrpc php-pecl-apc php-magpierss php-snmp php-tidy spawn-fcgi openssl perl-TimeDate httpd-devel ruby ruby-devel webalizer perl-DateTime-Format-HTTP perl-DateTime-Format-Builder perl-TimeDate libevent-devel php-pecl-memcache mod_fcgid subversion git php-soap -y yum install --enablerepo=rpmforge mod_fastcgi mod_suphp -y
ïŒãµãŒãã¹ãã¹ã¿ãŒãã¢ããã«è¿œå ããŠéå§ãã
chkconfig --levels 235 php-fpm on && /etc/init.d/php-fpm start chkconfig --levels 235 httpd on && /etc/init.d/httpd start chkconfig --levels 235 memcached on && /etc/init.d/memcached start
ïŒPHPã¢ãžã¥ãŒã«ã®æåã¢ã»ã³ããªã®å Žåãéçºè ã®ã³ââã³ããŒãã³ããã€ã³ã¹ããŒã«ããŸã
yum groupinstall 'Development Tools' -y
ïŒphp.iniã®æå°éã®å€æŽ
sed -i "s/^error_reporting =.*/error_reporting = E_ALL \& \~E_NOTICE/g" /etc/php.ini sed -i "s/^;cgi.fix_pathinfo =.*/cgi.fix_pathinfo = 1/g" /etc/php.ini sed -i "s/^;date.timezone =.*/date.timezone = Europe\/Moscow/g" /etc/php.ini sed -i "s/^max_execution_time =.*/max_execution_time = 600/g" /etc/php.ini sed -i "s/^max_input_time =.*/max_input_time = 600/g" /etc/php.ini sed -i "s/^memory_limit =.*/memory_limit = 512M/g" /etc/php.ini sed -i "s/^post_max_size =.*/post_max_size = 500M/g" /etc/php.ini sed -i "s/^upload_max_filesize =.*/upload_max_filesize = 2000M/g" /etc/php.ini sed -i "s/^max_file_uploads =.*/max_file_uploads = 200/g" /etc/php.ini sed -i "s/^short_open_tag =.*/short_open_tag = On/g" /etc/php.ini sed -i "s/^upload_max_filesize =.*/upload_max_filesize = 500M/g" /etc/php.ini sed -i "s/;realpath_cache_size =.*/realpath_cache_size = 4096k/g" /etc/php.ini
ïŒxdebugã¢ãžã¥ãŒã«ããã«ãããŸãïŒã³ãŒãã®ãããã°ãšåé¡ã®ç¹å®ã«åœ¹ç«ã¡ãŸãïŒ
yum install php-devel php-pear pecl install Xdebug
nano /etc/php.d/xdebug.ini
[xdebug] zend_extension="/usr/lib64/php/modules/xdebug.so" xdebug.remote_enable = 1
php -v
No log handling enabled - turning on stderr logging Created directory: /var/lib/net-snmp/mib_indexes PHP 5.4.24 (cli) (built: Jan 13 2014 12:36:47) Copyright (c) 1997-2013 The PHP Group Zend Engine v2.4.0, Copyright (c) 1998-2013 Zend Technologies with Xdebug v2.2.3, Copyright (c) 2002-2013, by Derick Retha
ïŒPHPã¢ãžã¥ãŒã«ã®ã€ã³ã¹ããŒã«-Zend Guard
cd /usr/src/ && wget wget http://downloads.zend.com/guard/6.0.0/ZendGuardLoader-70429-PHP-5.4-linux-glibc23-x86_64.tar.gz tar xzvf ZendGuardLoader-7* -C /usr/local/ chmod -R 755 /usr/local/ZendGuardLoader-70429-PHP-5.4-linux-glibc23-x86_64/ mv /usr/local/ZendGuardLoader-70429-PHP-5.4-linux-glibc23-x86_64/ /usr/local/Zend
nano /etc/php.d/zend.ini
zend_extension=/usr/local/Zend/php-5.4.x/ZendGuardLoader.so
php -v
PHP 5.4.24 (cli) (built: Jan 13 2014 12:36:47) Copyright (c) 1997-2013 The PHP Group Zend Engine v2.4.0, Copyright (c) 1998-2013 Zend Technologies with Xdebug v2.2.3, Copyright (c) 2002-2013, by Derick Rethans with Zend Guard Loader v3.3, Copyright (c) 1998-2013, by Zend Technologies
ïŒPHPã®ãªãã³ãŒããã£ãã·ã³ã°ã¢ãžã¥ãŒã«ãæå¹ã«ãã-APC
sed -i "s/^apc.enabled=.*/apc.enabled=1/g" /etc/php.d/apc.ini sed -i "s/^apc.shm_size=.*/apc.shm_size=256M/g" /etc/php.d/apc.ini sed -i "s/;apc.num_files_hint=.*/apc.num_files_hint=20000/g" /etc/php.d/apc.ini sed -i "s/;apc.user_entries_hint=.*/apc.user_entries_hint=20000/g" /etc/php.d/apc.ini sed -i "s/;apc.ttl=.*/apc.ttl=86400/g" /etc/php.d/apc.ini sed -i "s/;apc.user_ttl=.*/apc.user_ttl=7200/g" /etc/php.d/apc.ini sed -i "s/;apc.gc_ttl=.*/apc.gc_ttl=86400/g" /etc/php.d/apc.ini sed -i "s/;apc.cache_by_default=.*/apc.cache_by_default=1/g" /etc/php.d/apc.ini sed -i "s/;apc.max_file_size=.*/apc.max_file_size=10M/g" /etc/php.d/apc.ini
ïŒsuphpã¢ãžã¥ãŒã«ã®æ§æ
mkdir -p /root/backup/etc mv /etc/httpd/conf.d/suphp.conf /root/backup/ && nano /etc/httpd/conf.d/suphp.conf
LoadModule suphp_module modules/mod_suphp.so suPHP_Engine on suPHP_ConfigPath /etc/suphp.conf
mv /etc/suphp.conf /root/backup/etcsuphp.conf && nano /etc/suphp.conf
[global] ;Path to logfile logfile=/var/log/httpd/suphp.log ;Loglevel loglevel=info ;User Apache is running as webserver_user=apache ;Path all scripts have to be in docroot=/ ;Path to chroot() to before executing script ;chroot=/mychroot ; Security options allow_file_group_writeable=true allow_file_others_writeable=false allow_directory_group_writeable=true allow_directory_others_writeable=false ;Check wheter script is within DOCUMENT_ROOT check_vhost_docroot=true ;Send minor error messages to browser errors_to_browser=false ;PATH environment variable env_path=/bin:/usr/bin ;Umask to set, specify in octal notation umask=0077 ; Minimum UID min_uid=100 ; Minimum GID min_gid=100 [handlers] ;Handler for php-scripts x-httpd-suphp="php:/usr/bin/php-cgi" ;Handler for CGI-scripts x-suphp-cgi="execute:!self"
ïŒmod_rpafãèšå®ããŸãã3çªç®ã®ã¢ãã¬ã¹ã¯ãµãŒããŒã®ãããªãã¯Webã¢ãã¬ã¹ã§ã
nano /etc/httpd/conf.d/mod_rpaf.conf
<IfModule mod_rpaf.c> RPAF_Enable On RPAF_ProxyIPs 127.0.0.1 192.168.8.2 *.*.*.237 RPAF_Header X-Forwarded-For RPAF_SetHostName On RPAF_SetHTTPS On RPAF_SetPort On </IfModule>
ïŒFastCgiWrapperããªãã«ãã
nano /etc/httpd/conf.d/fastcgi.conf
sed -i "s/^FastCgiWrapper .*/FastCgiWrapper Off/g" /etc/httpd/conf.d/fastcgi.conf
ïŒISPConfigãã€ã³ã¹ããŒã«
cd /usr/src/ wget http://www.ispconfig.org/downloads/ISPConfig-3-stable.tar.gz tar xfz ISPConfig-3-stable.tar.gz cd ispconfig3_install/install/ php -q install.php
ïŒå¯Ÿè©±åã€ã³ã¹ããŒã«ãŠã£ã¶ãŒãã®è³ªåã«çããŸã
>>åæèšå®
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒRedhatãŸãã¯äºææ§ã®ãããäžæãªããŒãžã§ã³ã
以äžã¯ããã©ã€ããªèšå®ã«é¢ããããã€ãã®è³ªåã§ãã®ã§ã泚æããŠãã ããã
ããã©ã«ãå€ã¯[è§æ¬åŒ§]ã§å²ãŸããåãå ¥ããããŸãã
ãåŒçšããªãã§ãçµäºããã¿ããããŠãã€ã³ã¹ããŒã©ãŒãåæ¢ããŸãã
èšèªãéžæïŒenãdeïŒ[ en ]ïŒ
ã€ã³ã¹ããŒã«ã¢ãŒãïŒæšæºããšãã¹ããŒãïŒ[æšæº]ïŒ ãšãã¹ããŒã
ãµãŒããŒã®å®å šä¿®é£Ÿãã¹ãåïŒFQDNïŒãäŸïŒserver1.domain.tld [ app01.local ]ïŒ
MySQLãµãŒããŒã®ãã¹ãå[ localhost ]ïŒ
MySQLã«ãŒããŠãŒã¶ãŒå[ root ]ïŒ
MySQLã«ãŒããã¹ã¯ãŒã[]ïŒ
äœæããMySQLããŒã¿ããŒã¹[ dbispconfig ]ïŒ
MySQLæåã»ãã[ utf8 ]ïŒ
次ã®2ã€ã®è³ªåã¯ãå éšISPConfigããŒã¿ããŒã¹ã®ãŠãŒã¶ãŒãšãã¹ã¯ãŒãã«é¢ãããã®ã§ãã
ãŠãŒã¶ãŒåãšããŠãispconfigãã§ãããã©ã³ãã ãªãã¹ã¯ãŒãã§ããããã©ã«ããåãå ¥ããããšããå§ãããŸãã
å¥ã®ãã¹ã¯ãŒãã䜿çšããå Žåã¯ããã¹ã¯ãŒãã«æ°åãšæåã®ã¿ã䜿çšããŠãã ããã
ISPConfig mysqlããŒã¿ããŒã¹ã®ãŠãŒã¶ãŒå[ ispconfig ]ïŒ
ISPConfig mysqlããŒã¿ããŒã¹ãã¹ã¯ãŒã[ 8b8295ae2a50a39a1a00da65df0bee72 ]ïŒ
ãã®ãµãŒããŒãæ¢åã®ISPConfigãã«ããµãŒããŒã»ããã¢ããã«åå ãããŸãïŒyãnïŒ[n]ïŒ y
MySQLãã¹ã¿ãŒãµãŒããŒã®ãã¹ãå[]ïŒ isp.local
MySQLãã¹ã¿ãŒãµãŒããŒã®ã«ãŒããŠãŒã¶ãŒå[ root ]ïŒ
MySQLãã¹ã¿ãŒãµãŒããŒã®ã«ãŒããã¹ã¯ãŒã[]ïŒ c2HZqsMmiBKa
MySQLãã¹ã¿ãŒãµãŒããŒã®ããŒã¿ããŒã¹å[ dbispconfig ]ïŒ
ISPConfigãµãŒããŒã¬ã³ãŒããããŒã¿ããŒã¹ã«è¿œå ããŠããŸãã
ã¡ãŒã«ã®æ§æïŒyãnïŒ[y]ïŒ n
Jailkitã®æ§æïŒyãnïŒ[y]ïŒ n
FTPãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ y
Pureftpdã®æ§æ
pure-ftpdã®åæ¢ïŒ[OK]
pure-ftpdã®èµ·åïŒ[OK]
DNSãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ n
ãã³ãïŒãã®ãµãŒããŒãISPConfigã€ã³ã¿ãŒãã§ãŒã¹ãå®è¡ããå Žåã¯ããApacheãµãŒããŒã®æ§æããªãã·ã§ã³ã§ãyããéžæããŸãã
ApacheãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ y
Apacheã®æ§æ
Vloggerã®æ§æ
Apps vhostã®æ§æ
ãã¡ã€ã¢ãŠã©ãŒã«ãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ y
Bastille Firewallã®æ§æ
ISPConfig Webã€ã³ã¿ãŒãã§ã€ã¹ã®ã€ã³ã¹ããŒã«ïŒyãnïŒ[n]ïŒ n
DBServerã®æ§æ
ISPConfig crontabã®ã€ã³ã¹ããŒã«
ã«ãŒãã®crontabã¯ãããŸãã
httpdã®åæ¢ïŒ[OK]
[2014幎1æ23æ¥13:46:44] [èŠå] NameVirtualHost *ïŒ80ã«ã¯VirtualHostsããããŸãã
[æš1æ23æ¥13:46:44 2014] [èŠå] NameVirtualHost *ïŒ443ã«ã¯VirtualHostããããŸãã
[2014幎1æ23æ¥13:46:44] [èŠå] NameVirtualHost *ïŒ80ã«ã¯VirtualHostsããããŸãã
httpdã®éå§ïŒ[OK]
ã€ã³ã¹ããŒã«ãå®äºããŸããã
ç°å¢db01ãèšå®ããŸãã
CentOS 64ç°å¢ã§OpenVZã³ã³ãããŒïŒæ°ããCTïŒãäœæããå¿ èŠããããŸãããµã€ãã®Mariadbã¯ããã®in vitroãã·ã³ã«é 眮ãããŸãã
ãã®ããŒãã®ISPConfigã¯ã©ã¹ã¿ãŒãžã®è¿œå ã«ã€ããŠã®ã¿èª¬æããŸãã 次ã®èšäºã§ã¯ãMySQLã®æé©åã«é¢ãã質åãæ®ããŸãã
ãã®ã³ã³ããã«ã¯ããã©ã€ããŒããããã¯ãŒã¯ïŒ vmbr1 ïŒ 192.168.8.5ã®ã¢ãã¬ã¹ããããŸããããŒã¿ããŒã¹ãµãŒããŒã®RAMã®éãç¯çŽããªãã§ãã ããããã®å Žåã¯4 GBã®RAMãšããŸãããæ·±å»ãªã¿ã¹ã¯ã®å Žåã20 GBã¯å°ãããªããŸãã
ããã¯ããããã¯ãŒã¯ãã³ã³ããèªäœã§ã©ã®ããã«èŠãããã§ãã
vi /etc/sysconfig/network-scripts/ifcfg-eth1
DEVICE=eth1 BOOTPROTO=static ONBOOT=yes IPADDR=192.168.8.5 NETWORK=192.168.8.0 GATEWAY=192.168.8.100
ïŒISPConfigããã«ã®phpã³ã³ããŒãã³ããã€ã³ã¹ããŒã«
yum install php-mysql php -y
ïŒã¹ã¿ãŒãã¢ããããåé€ããŠapache2ããªãã«ãã
chkconfig httpd off && /etc/init.d/httpd stop
ïŒISPConfigãã€ã³ã¹ããŒã«
cd /usr/src/ wget http://www.ispconfig.org/downloads/ISPConfig-3-stable.tar.gz tar xfz ISPConfig-3-stable.tar.gz cd ispconfig3_install/install/ php -q install.php
ïŒå¯Ÿè©±åã€ã³ã¹ããŒã«ãŠã£ã¶ãŒãã®è³ªåã«çããŸã
>>åæèšå®
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒRedhatãŸãã¯äºææ§ã®ãããäžæãªããŒãžã§ã³ã
以äžã¯ããã©ã€ããªèšå®ã«é¢ããããã€ãã®è³ªåã§ãã®ã§ã泚æããŠãã ããã
ããã©ã«ãå€ã¯[è§æ¬åŒ§]ã§å²ãŸããåãå ¥ããããŸãã
ãåŒçšããªãã§ãçµäºããã¿ããããŠãã€ã³ã¹ããŒã©ãŒãåæ¢ããŸãã
èšèªã®éžæïŒenãdeïŒ[en]ïŒ en
ã€ã³ã¹ããŒã«ã¢ãŒãïŒæšæºããšãã¹ããŒãïŒ[æšæº]ïŒ ãšãã¹ããŒã
ãµãŒããŒã®å®å šä¿®é£Ÿãã¹ãåïŒFQDNïŒãäŸïŒserver1.domain.tld [ db01.local ]ïŒ
MySQLãµãŒããŒã®ãã¹ãå[ localhost ]ïŒ
MySQLã«ãŒããŠãŒã¶ãŒå[ root ]ïŒ
MySQLã«ãŒããã¹ã¯ãŒã[]ïŒ
äœæããMySQLããŒã¿ããŒã¹[ dbispconfig ]ïŒ
MySQLæåã»ãã[ utf8 ]ïŒ
次ã®2ã€ã®è³ªåã¯ãå éšISPConfigããŒã¿ããŒã¹ã®ãŠãŒã¶ãŒãšãã¹ã¯ãŒãã«é¢ãããã®ã§ãã
ãŠãŒã¶ãŒåãšããŠãispconfigãã§ãããã©ã³ãã ãªãã¹ã¯ãŒãã§ããããã©ã«ããåãå ¥ããããšããå§ãããŸãã
å¥ã®ãã¹ã¯ãŒãã䜿çšããå Žåã¯ããã¹ã¯ãŒãã«æ°åãšæåã®ã¿ã䜿çšããŠãã ããã
ISPConfig mysqlããŒã¿ããŒã¹ã®ãŠãŒã¶ãŒå[ ispconfig ]ïŒ
ISPConfig mysqlããŒã¿ããŒã¹ãã¹ã¯ãŒã[ 06cd6c11370b50a83eb0a3d3907a3581 ]ïŒ
ãã®ãµãŒããŒãæ¢åã®ISPConfigãã«ããµãŒããŒã»ããã¢ããã«åå ãããŸãïŒyãnïŒ[n]ïŒ y
MySQLãã¹ã¿ãŒãµãŒããŒã®ãã¹ãå[]ïŒ isp.local
MySQLãã¹ã¿ãŒãµãŒããŒã®ã«ãŒããŠãŒã¶ãŒå[ root ]ïŒ
MySQLãã¹ã¿ãŒãµãŒããŒã®ã«ãŒããã¹ã¯ãŒã[]ïŒ c2HZqsMmiBKa
MySQLãã¹ã¿ãŒãµãŒããŒã®ããŒã¿ããŒã¹å[ dbispconfig ]ïŒ
ISPConfigãµãŒããŒã¬ã³ãŒããããŒã¿ããŒã¹ã«è¿œå ããŠããŸãã
ã¡ãŒã«ã®æ§æïŒyãnïŒ[y]ïŒ n
Jailkitã®æ§æïŒyãnïŒ[y]ïŒ n
FTPãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ n
DNSãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ n
ãã³ãïŒãã®ãµãŒããŒãISPConfigã€ã³ã¿ãŒãã§ãŒã¹ãå®è¡ããå Žåã¯ããApacheãµãŒããŒã®æ§æããªãã·ã§ã³ã§ãyããéžæããŸãã
ApacheãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ n
ãã¡ã€ã¢ãŠã©ãŒã«ãµãŒããŒã®æ§æïŒyãnïŒ[y]ïŒ y
Bastille Firewallã®æ§æ
ISPConfig Webã€ã³ã¿ãŒãã§ã€ã¹ã®ã€ã³ã¹ããŒã«ïŒyãnïŒ[n]ïŒ n
DBServerã®æ§æ
ISPConfig crontabã®ã€ã³ã¹ããŒã«
ã«ãŒãã®crontabã¯ãããŸãã
httpdã®åæ¢ïŒ[倱æ]
httpdã®éå§ïŒ[OK]
ã€ã³ã¹ããŒã«ãå®äºããŸããã
ISPConfigã®æŠèŠïŒ
ISPConfig Webããã«ã§ã®æ¿èªåŸãã¹ã¿ãŒãããŒãžã«ç§»åããŸãã
ããŒã« - ãã¹ã¯ãŒããšèšèª ã èšèªãå€æŽããã³ã³ãããŒã«ããã«ã«ã¢ã¯ã»ã¹ããããã®åŒ·åãªãã¹ã¯ãŒããäœæããŸãã
ã·ã¹ãã - ãµãŒããŒãµãŒãã¹ ããµãŒããŒããäžèŠãªåœ¹å²ãåé€ããŸãã
ISPConfigãåäžã®ããŒããå¥ã®ããŒãã®ãã©ãŒã«ããããšãã§ãããšããäºå®ã«æ³šæãåèµ·ããããšæããŸãã ã€ãŸã ãµãŒãã¹ãšãŠãŒã¶ãŒã®æ§æã¯ãè€æ°ã®ãµãŒããŒã§åæã«åãã«ãªããŸãã ãµãŒããŒãã©ãŒã§ãã©ãŒã®ããŒããéžæããå¿ èŠããããŸã
ãµãŒããŒæ§æ - ãµãŒããŒã»ã¯ã·ã§ã³ã®åãµãŒããŒã§ã ãã°ã¬ãã«ããããã°ã«èšå®ããŸãã ããã§ãISPConfigãã¯ã©ã¹ã¿ãŒã®ããŒãã§å®è¡ãããã¹ãŠã®ã¢ã¯ã·ã§ã³ã確èªã§ããŸã
tail -f -n 1000 /var/log/ispconfig/ispconfig.log
ãµãŒããŒæ§æã«ã¯ããã«Webã»ã¯ã·ã§ã³ãããããã®äžã«PermissionsããããŸããåããã¡ã€ã«ã¹ãã¬ãŒãžïŒcephãocfs2ãªã©ïŒã«è€æ°ã®WebãµãŒããŒãã©ãŒãããå Žåã æŽæ°æã«ãã©ã«ããŒããŒããã·ã§ã³ãèšå®ã ã LinuxãŠãŒã¶ãŒIDãwebidã«æ¥ç¶ãããã§ãã¯ããã¯ã¹ããã§ãã¯ããå¿ èŠããããŸã ã ããã«ãããç°ãªããã©ãŒäžã®guid / uidãšãŠãŒã¶ãŒããã³ã°ã«ãŒããããã³ãããã®åå/ã°ã«ãŒãã®éãã«é¢ããåé¡ãåé¿ã§ããŸãã ãŠãŒã¶ãŒã®ãã©ã«ããŒæ§é ãå€æŽããå Žåã¯ã[ Webãã©ã«ããŒãäžå€ïŒæ¡åŒµå±æ§ïŒã«ãã]ãã§ãã¯ããã¯ã¹ããªãã«ããŸãã ãããå¿ããå Žåã¯ã chatrtr -iã³ãã³ãã圹ç«ã¡ãŸãã 次ã®éèŠãªã»ã¯ã·ã§ã³ïŒ Rescue ãã¯ã©ãã·ã¥ãçºçããå Žåã«éèŠãªãµãŒãã¹ã®èªåèµ·åãæå¹ã«ããŸãããåèµ·åããªããµãŒãã¹ã®åèµ·åãç¡å¹ã«ããããšãå¿ããªãã§ãã ããã
ãã¹ããŠãŒã¶ãŒãäœæããŸãããïŒ ã¯ã©ã€ã¢ã³ã - ã¯ã©ã€ã¢ã³ãã è¿œå ã ã ã¢ãã¬ã¹ ã é£çµ¡å ã ãã°ã€ã³ ã ãã¹ã¯ãŒããå ¥åããŠãã ãã ïŒäŸ¿å©ãªãã¹ã¯ãŒããžã§ãã¬ãŒã¿ãŒããããŸãïŒã å¶éã«å ã㊠ã ããã©ã«ãã®WebãµãŒããŒãšèš±å¯ãããWebãµãŒããŒã®åäœã¢ãŒããéžæããŸãã
php-fpmãšmod_phpãåæã«ãµããŒãããããã«app01.localãæ§æããŸããã 顧客ã®ãªã¹ãã«æ»ããæ°ããäœæããããã®ãå ¥åããŸãã
ãµã€ã - æ°ãããŠã§ããµã€ããè¿œå
ãµã€ãåãšå¿ èŠãªphpããã¯ãšã³ããæå®ããŸãã
ã¯ã©ã¹ã¿æ§æã®ISPConfigã¯ããã¹ãŠã®å€æŽãåæ ããã®ã«æéããããããšã«æ³šæããŠãã ããã
ãµã€ãã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããæ段ãšããŠã sshã䜿çšããŸããWindowsã§ã¯WinSCPã䜿çšãããšäŸ¿å©ã§ãã ãã®æ¹æ³ã¯ãåŸæ¥ã®FTPãããã¯ããã«å®å šã§ãã
ã¢ã¯ã»ã¹ããã«ã¯ã Shell Userã»ã¯ã·ã§ã³ã§SSHãŠãŒã¶ãŒãäœæããå¿ èŠããããŸãã
ãŠãŒã¶ãŒåããã¹ã¯ãŒããããã³å¿ èŠã«å¿ããŠããŒãæå®ããå¿ èŠããããŸãã ISPConfigã¢ã«ãŠã³ãã®ã¢ã«ãŠã³ãã®ãã¬ãã£ãã¯ã¹ããŠãŒã¶ãŒã«è¿œå ãããããšã«æ³šæããŠãã ããã
MySQLã䜿çšããã«ã¯ã ããŒã¿ããŒã¹ãŠãŒã¶ãŒã»ã¯ã·ã§ã³ã§ãŠãŒã¶ãŒãäœæããå¿ èŠããããŸããISPConfigã·ã¹ãã ã®IDããã°ã€ã³ã«è¿œå ãããŸãã
ããŒã¿ããŒã¹ã»ã¯ã·ã§ã³ã§ãµã€ãã®1ã€ã«ããŒã¿ããŒã¹ãäœæããŸããæ°ããããŒã¿ããŒã¹ã®ååãæå®ããå¿ èŠããããŸãããã®ããŒã¿ããŒã¹ãå±ãããµã€ããæå®ããããšãå¿ããªãã§ãã ãããäœæãããŠãŒã¶ãŒãéžæãã ãªã¢ãŒãã¢ã¯ã»ã¹ããã¯ã¹ããã§ãã¯ããŸãã¢ããªã±ãŒã·ã§ã³ãµãŒããŒã«é¢é£ããŠïŒã ãã¬ãã£ãã¯ã¹ãååã«è¿œå ãããããšãå¿ããªãã§ãã ããã
phpMyAdminã«ã¢ã¯ã»ã¹ããã«ã¯ã[ ããŒã¿ããŒã¹]ã»ã¯ã·ã§ã³ã®ä»»æã®ããŒã¿ããŒã¹ã®è¿ãã«ãã察å¿ããã¢ã€ã³ã³ãã¯ãªãã¯ããŸãã
phpMyAdminã§èªåèªèº«ãèŠã€ãã
ãã¡ã€ãã«
ãµã€ããååšããapp01.localã¯ãããŒã22ã®ãããªãã¯ãµãŒãã¹ãããã¯ãŒã¯ã§å©çšã§ããŸãã WinSCP , :
, web
index.html index.php
<?php // , INFO_ALL phpinfo(); // . // phpinfo(8) . phpinfo(INFO_MODULES); ?>
, php-fpm/mod_php
, :