我的全过程,在考虑要不要让AI优化下,网上收集整合的
更新软件包和系统并清理"孤儿包"
# Debian/Ubuntu 系统(apt)
apt update && apt upgrade -y && apt dist-upgrade -y && apt full-upgrade -y && apt autoremove -y
# CentOS/RHEL 8+(dnf)
sudo dnf check-update && sudo dnf upgrade -y && sudo dnf distro-sync -y && sudo dnf autoremove -y
# CentOS/RHEL 7及之前(yum)
sudo yum check-update && sudo yum update -y && sudo yum upgrade -y && sudo yum autoremove -y
# Fedora(dnf)
sudo dnf check-update && sudo dnf upgrade -y && sudo dnf autoremove -y
# Arch Linux(pacman)
sudo pacman -Sy && sudo pacman -Syu --noconfirm && sudo pacman -Rns $(pacman -Qdtq) --noconfirm
系统参数优化
- 内核参数调整:例如,增加 TCP 缓冲区大小、修改系统队列长度等,这些改变有助于提高网络吞吐量和减少延迟。
- 性能优化:安装和配置
Tuned 和其他系统性能优化工具来自动调整和优化服务器的运行状态。
- 资源限制:例如,设置文件打开数量的限制,这可以防止某些类型的资源耗尽攻击。
#
bash <(wget -qO- https://raw.githubusercontent.com/jerry048/Tune/main/tune.sh) -t
网络加速
echo "net.core.default_qdisc=fq" >> /etc/sysctl.conf
echo "net.ipv4.tcp_congestion_control=bbr" >> /etc/sysctl.conf
sysctl -p
sysctl net.ipv4.tcp_available_congestion_control
lsmod | grep bbr
wget -N --no-check-certificate "https://raw.githubusercontent.com/chiakge/Linux-NetSpeed/master/tcp.sh" && chmod +x tcp.sh && ./tcp.sh
wget -O tcpx.sh "https://github.com/ylx2016/Linux-NetSpeed/raw/master/tcpx.sh" && chmod +x tcpx.sh && ./tcpx.sh
bash <(wget -qO- https://raw.githubusercontent.com/jerry048/Tune/main/tune.sh) -x
sudo reboot
lsmod | grep bbr
wget --no-check-certificate https://github.com/teddysun/across/raw/master/bbr.sh && chmod +x bbr.sh && ./bbr.sh
安装swap
bash <(wget -qO- https://fool.im/swap.sh)
修改时区
apt install -y locales
echo "Asia/Shanghai" > /etc/timezone && \
dpkg-reconfigure -f noninteractive tzdata && \
sed -i -e 's/# en_US.UTF-8 UTF-8/en_US.UTF-8 UTF-8/' /etc/locale.gen && \
echo 'LANG="en_US.UTF-8"'>/etc/default/locale && \
dpkg-reconfigure --frontend=noninteractive locales && \
update-locale LANG=en_US.UTF-8
echo "Asia/Shanghai" > /etc/timezone
apt install sudo curl wget nano -y
sudo timedatectl set-timezone Asia/Shanghai
timedatectl
修改日志最大容量
echo "SystemMaxUse=512M" >> /etc/systemd/journald.conf
echo "SystemMaxFileSize=32M" >> /etc/systemd/journald.conf
echo "RuntimeMaxUse=32M" >> /etc/systemd/journald.conf
echo "RuntimeMaxFileSize=4M" >> /etc/systemd/journald.conf
systemctl restart systemd-journald.service
SSH
sed -i 's/^Port.*$/Port 2233/' /etc/ssh/sshd_config
sed -i 's/^#LoginGraceTime.*$/LoginGraceTime 30/' /etc/ssh/sshd_config
sed -i 's/^#MaxAuthTries.*$/MaxAuthTries 3/' /etc/ssh/sshd_config
sed -i 's/^#RSAAuthentication.*$/RSAAuthentication yes/' /etc/ssh/sshd_config
sed -i 's/^#PubkeyAuthentication/PubkeyAuthentication/' /etc/ssh/sshd_config
sed -i 's/^#AuthorizedKeysFile/AuthorizedKeysFile/' /etc/ssh/sshd_config
sed -i 's/^#TCPKeepAlive/TCPKeepAlive/' /etc/ssh/sshd_config
sed -i 's/^#ClientAliveInterval.*$/ClientAliveInterval 600/' /etc/ssh/sshd_config
sed -i 's/^#ClientAliveCountMax.*$/ClientAliveCountMax 3/' /etc/ssh/sshd_config
防止爆破Fail2ban
安装Fail2ban
apt install fail2ban rsyslog python3-systemd
配置Fail2Ban
fail2ban 的配置文件通常位于 /etc/fail2ban/ 目录下,fail2ban 的.conf 配置文件都是可以被.local 覆盖,所以配置方式建议是添加.local 文件,不修改原来的配置文件
nano /etc/fail2ban/jail.local
配置文件如下
[DEFAULT]
ignoreip = 127.0.0.1/8
allowipv6 = auto
backend = systemd
[sshd]
enabled = true
filter = sshd
port = ssh
action = iptables[name=SSH, port=ssh, protocol=tcp]
logpath = /var/log/auth.log
bantime = 1w
bantime.increment = true
bantime.factor = 2
bantime.maxtime = 8w
findtime = 5m
maxretry = 3
[nginx-dir-scan]
enabled = true
filter = nginx-dir-scan
action = iptables[name=nginx-dir-scan, port="http,https", protocol=tcp]
logpath = /www/wwwlogs/*access.log
maxretry = 1
bantime = 9d
findtime = 5m
[nginx-cc]
enabled = true
port = http,https
filter = nginx-cc
action = %(action_mwl)s
maxretry = 20
findtime = 60
bantime = 9d
logpath = /www/wwwlogs/*access.log
[nginx-http-auth]
enabled = true
filter = nginx-http-auth
mode = fallback
port = http,https
logpath = /www/wwwlogs/*error.log
maxretry = 3
bantime = 3600
action = iptables[name=nginx-limit-req, port="http,https", protocol=tcp]
[nginx-limit-req]
enabled = true
filter = nginx-limit-req
port = http,https
logpath = /www/wwwlogs/*access.log
action = iptables[name=nginx-limit-req, port="http,https", protocol=tcp]
maxretry = 5
bantime = 3600
[nginx-botsearch]
enabled = true
filter = nginx-botsearch
port = http,https
logpath = /www/wwwlogs/*access.log
action = iptables[name=nginx-botsearch, port="http,https", protocol=tcp]
maxretry = 5
bantime = 3600
[nginx-bad-request]
enabled = true
filter = nginx-bad-request
port = http,https
logpath = /www/wwwlogs/*access.log
action = iptables[name=nginx-bad-request, port="http,https", protocol=tcp]
maxretry = 5
bantime = 3600
[php-url-fopen]
enabled = true
filter = php-url-fopen
port = http,https
logpath = /www/wwwlogs/*access.log
action = iptables[name=php-url-fopen, port="http,https", protocol=tcp]
maxretry = 5
bantime = 3600
可选配置
[vsftpd-notification]
enabled = true
filter = vsftpd
action = sendmail-whois[name=VSFTPD, [email protected]]
logpath = /var/log/vsftpd.log
maxretry = 5
bantime = 9d
[vsftpd-iptables]
enabled = true
filter = vsftpd
action = iptables[name=VSFTPD, port=ftp, protocol=tcp]
sendmail-whois[name=VSFTPD, [email protected]]
logpath = /var/log/vsftpd.log
maxretry = 5
bantime = 9d
过滤器
nginx-cc
nano /etc/fail2ban/filter.d/nginx-cc.conf
#填写如下内容
[Definition]
failregex = <HOST> -.*- .*HTTP/1.* .* .*$
ignoreregex =
nginx-dir-scan
nano /etc/fail2ban/filter.d/nginx-dir-scan.conf
[Definition]
failregex = <HOST> -.*- .*Mozilla/4.0* .* .*$
ignoreregex =
常用命令
# 设置开机自动启动 fail2ban
sudo systemctl enable fail2ban
# 重新启动 fail2ban
sudo systemctl restart fail2ban
# 停止 fail2ban 的状态
sudo systemctl stop fail2ban
# 查看 fail2ban 的状态
sudo systemctl status fail2ban
# 查看所有可用 jail 的状态
fail2ban-client status
# 验证配置是否生效
tail -f /var/log/auth.log
fail2ban-client status sshd
# 解封所有IP
fail2ban-client unban --all
# 解封指定IP
# fail2ban-client unban <IP> ... <IP>
fail2ban-client unban 1.1.1.1
#删除特定服务的(如sshd)被ban IP
fail2ban-client set sshd delignoreip 1.1.1.1
# 完全卸载fail2ban
sudo apt remove fail2ban && apt purge fail2ban && apt autoremove
rm /etc/fail2ban/ -rf
# 显示配置以及错误
sudo fail2ban-client -d
删除多余日志
#fail2ban日志 开机自删+定时删日志
logdelete="./fail2banlogdelete.sh"
cat>"${logdelete}"<<EOF
#!/bin/bash
find /path/to/nginx/ -mtime +15 -name "*.log" | xargs -i mv {} /root/RecycleBin/;
find /usr/local/nginx/logs/ -mtime +15 -name "*.log" | xargs -i mv {} /root/RecycleBin/;
find /var/log/ -mtime +15 -name "*.log" | xargs -i mv {} /root/RecycleBin/;
find /root/RecycleBin/ -name "*.log" -exec rm -rf {} \;
EOF
cp ./fail2banlogdelete.sh /etc/init.d/
#读挡并赋予权限
chmod +777 /etc/init.d/fail2banlogdelete.sh
update-rc.d ./fail2banlogdelete.sh defaults 90
cd
(echo "0 0 */15 * * bash /etc/init.d/fail2banlogdelete.sh >>/dev/null 2>&1" ; crontab -l )| crontab
cd
一键生成密钥
wget -O key.sh https://raw.githubusercontent.com/yuju520/Script/main/key.sh && chmod +x key.sh && clear && ./key.sh
Docker
安装
# 海外服务器 方法1
wget -qO- get.docker.com | bash
# 海外服务器 方法2
curl -fsSL https://get.docker.com -o get-docker.sh && sh get-docker.sh
# 大陆服务器
curl https://install.1panel.live/docker-install -o docker-install && sudo bash ./docker-install && rm -f ./docker-install
# 开机自启
sudo systemctl enable docker
# 卸载
sudo apt-get purge docker-ce docker-ce-cli containerd.io
sudo apt-get remove docker docker-engine
sudo rm -rf /var/lib/docker
sudo rm -rf /var/lib/containerd
# 查看docker 版本
docker -v
# 查看docker compose版本 Docker18.06.0-ce 版本就开始自带 Docker Compose
docker compose version
Linux硬盘清理
systemd-journal 日志清理
设置
nano /etc/systemd/journald.conf
SystemMaxUse=5M
SystemMaxFileSize=2M
SystemKeepFiles=1
journalctl --vacuum-time=1week
systemctl restart systemd-journald