<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>系统运维 &#187; linux</title>
	<atom:link href="http://www.osyunwei.com/archives/tag/linux-2/feed" rel="self" type="application/rss+xml" />
	<link>https://www.osyunwei.com</link>
	<description>国产化OS/AnolisOS/openEuler/RHEL/CentOS/Rocky Linux/Debian/Ubuntu Linux FreeBSD 服务器教程 &#124; Windows Server 2003/2008/2012/2016/2019/2022/2025服务器教程</description>
	<lastBuildDate>Sun, 04 Oct 2026 06:19:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Linux下安装部署frp开源内网穿透反向代理工具</title>
		<link>https://www.osyunwei.com/archives/17225.html</link>
		<comments>https://www.osyunwei.com/archives/17225.html#comments</comments>
		<pubDate>Fri, 02 Oct 2026 14:04:38 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[frp]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=17225</guid>
		<description><![CDATA[简单介绍： frp（fast reverse proxy）是开源轻量反向代理内网穿透工具，支持 tcp, udp, http, https 协议，C/S 架构： frps：服务端，部署在有公网 IP的服务器 frpc：客户端，部署在内网服务器，主动向外建立长连接 frps 和 frpc版本必须保持一致 具体实现： 1、需要一个公网ip地址，用来安装部署frp服务端frps 2、需要在内网环境中部署一台frp客户端frpc，当做代理服务器 3、用户访问公网ip地址和端口，会先连接到frp客户端，再根据相应的规则去匹配转发，把请求发送到内网中其他主机和端口 4、在服务端需要开启相应的端口（7000，7001，7002，7003等） 安装部署： 1、下载frps frp压缩包同时包含了 frps（frp 服务端）和frpc（frp 客户端） 项目地址：https://github.com/fatedier/frp 下载地址：https://github.com/fatedier/frp/releases/download/v0.71.0/frp_0.71.0_linux_amd64.tar.gz 2、服务端部署 #创建目录 mkdir -p /data/soft mkdir -p /data/server 上传安装包frp_0.71.0_linux_amd64.tar.gz到/data/soft目录下面 #解压 cd /data/soft tar zxvf frp_0.71.0_linux_amd64.tar.gz mv /data/soft/frp_0.71.0_linux_amd64 /data/server/frp #修改服务端配置文件 cp /data/server/frp/frps.toml /data/server/frp/frps.toml.bak vi /data/server/frp/frps.toml bindAddr = [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/17225.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/17225.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>国产化操作系统openEuler 24.03 LTS安装Docker二进制版本</title>
		<link>https://www.osyunwei.com/archives/17134.html</link>
		<comments>https://www.osyunwei.com/archives/17134.html#comments</comments>
		<pubDate>Mon, 31 Aug 2026 09:55:57 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Docker]]></category>
		<category><![CDATA[docker]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=17134</guid>
		<description><![CDATA[准备篇 欧拉操作系统openEuler 24.03-LTS-SP1安装配置图解教程 https://www.osyunwei.com/archives/14957.html 1、关闭selinux #执行以下命令 setenforce 0 sed -i 's/^SELINUX=.*/SELINUX=disabled/' /etc/selinux/config 2、关闭firewall systemctl stop firewalld.service #停止firewall systemctl disable firewalld.service #禁止firewall开机启动 systemctl mask firewalld systemctl stop firewalld yum -y remove firewalld 3、添加docker用户组 groupadd docker #添加普通用户myuser到docker组，使其具有docker命令的执行权限 usermod -aG docker myuser #添加用户到wheel组，用户可以使用sudo权限 usermod -aG wheel myuser #刷新用户组 newgrp docker 4、安装iptables防火墙，安装和运行Docker通常需要iptables yum -y install iptables-services #安装 systemctl enable [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/17134.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/17134.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>国产化操作系统Anolis OS编译安装nginx</title>
		<link>https://www.osyunwei.com/archives/17122.html</link>
		<comments>https://www.osyunwei.com/archives/17122.html#comments</comments>
		<pubDate>Tue, 30 Jun 2026 08:31:29 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Nginx]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[nginx]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=17122</guid>
		<description><![CDATA[操作系统：国产化操作系统Anolis OS AnolisOS-8.x安装配置图解教程 https://www.osyunwei.com/archives/14613.html 安装包下载： 1、nginx https://nginx.org/download/nginx-1.30.3.tar.gz 2、zlib https://www.zlib.net/zlib-1.3.2.tar.gz 3、pcre2 https://github.com/PCRE2Project/pcre2/releases/download/pcre2-10.47/pcre2-10.47.tar.gz 4、openssl https://github.com/openssl/openssl/releases/download/openssl-3.5.7/openssl-3.5.7.tar.gz 安装前准备： 1、防火墙配置 AnolisOS-8.x默认使用的是firewall作为防火墙 firewall-cmd --list-all #显示所有规则（含服务、端口、区域） systemctl status firewalld #检查 firewalld 状态 #开放80 443 端口 firewall-cmd --permanent --add-port=80/tcp firewall-cmd --permanent --add-port=443/tcp firewall-cmd --reload #重新加载防火墙配置 2、关闭SELINUX vi /etc/selinux/config #SELINUX=enforcing #注释掉 #SELINUXTYPE=targeted #注释掉 SELINUX=disabled #增加 :wq! #保存退出 setenforce 0 #使配置立即生效 getenforce #查看 SELinux 当前运行模式 [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/17122.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/17122.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux下nginx使用mkcert创建的https证书</title>
		<link>https://www.osyunwei.com/archives/17092.html</link>
		<comments>https://www.osyunwei.com/archives/17092.html#comments</comments>
		<pubDate>Sun, 10 May 2026 14:40:33 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Nginx]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[nginx]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=17092</guid>
		<description><![CDATA[简单说明： 1、mkcert 是一个用于在本地开发环境中创建受信任的https证书的工具。 2、mkcert通过自动创建并安装一个本地的证书颁发机构（CA）到系统和浏览器的信任库中，解决了传统自签名证书带来的浏览器安全警告问题。 3、在 Linux 环境下，nginx 部署 mkcert 创建的本地受信任的https证书是一个非常实用的配置，在本地或内网通过https访问服务，浏览器不会显示“不安全”的警告。 4、整个过程可以分为四个主要步骤：安装 mkcert、生成本地 CA 和服务器证书、配置 Nginx，以及在客户端建立信任。 安装前准备： 1、防火墙配置 Rocky Linux默认使用的是firewall作为防火墙 firewall-cmd --list-all #显示所有规则（含服务、端口、区域） systemctl status firewalld #检查 firewalld 状态 #开放80 443 端口 firewall-cmd --permanent --add-port=80/tcp firewall-cmd --permanent --add-port=443/tcp firewall-cmd --reload #重新加载防火墙配置 2、关闭SELINUX vi /etc/selinux/config #SELINUX=enforcing #注释掉 #SELINUXTYPE=targeted #注释掉 SELINUX=disabled #增加 :wq! #保存退出 setenforce 0 #使配置立即生效 getenforce [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/17092.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/17092.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux下安装配置WireGuard</title>
		<link>https://www.osyunwei.com/archives/17086.html</link>
		<comments>https://www.osyunwei.com/archives/17086.html#comments</comments>
		<pubDate>Tue, 14 Apr 2026 10:56:57 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=17086</guid>
		<description><![CDATA[简单介绍： WireGuard 是新一代的虚拟专用网内核模块，它以代码极简、性能极高、配置简单著称。 它被直接集成在 Linux 内核中（5.6 版本以上），因此运行效率非常高，非常适合用于异地组网、内网穿透等使用场景。 操作系统： Rocky Linux 10.1 WireGuard 已经内置于新版内核中，Rocky Linux 10 默认使用的是较新的内核（通常是 6.x 版本），而 WireGuard 在 Linux 内核 5.6 版本之后就已经正式合并到主线内核了。 安装配置： 1、关闭SELINUX vi /etc/selinux/config #SELINUX=enforcing #注释掉 #SELINUXTYPE=targeted #注释掉 SELINUX=disabled #增加 :wq! #保存退出 setenforce 0 #使配置立即生效 getenforce #查看 SELinux 当前运行模式 2、防火墙端口配置 Rocky Linux 10.1默认使用的是firewall作为防火墙 firewall-cmd --list-all #显示所有规则（含服务、端口、区域） systemctl status firewalld #检查 firewalld [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/17086.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/17086.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux下使用DNF命令下载安装包到指定目录</title>
		<link>https://www.osyunwei.com/archives/17063.html</link>
		<comments>https://www.osyunwei.com/archives/17063.html#comments</comments>
		<pubDate>Thu, 19 Mar 2026 17:26:48 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[dnf]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[yum]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=17063</guid>
		<description><![CDATA[需求：内网服务器没有yum源，要离线安装依赖包 解决方法：部署一台相同版本的可以联网的服务器，使用DNF命令下载依赖包，上传到内网服务器离线安装。 具体操作： 我们以RHEL 8/9/10系列操作系统为例 1、安装dnf-utils工具包 默认的 dnf 命令只能做基础的安装、卸载和更新。我们需要安装增强工具包 dnf-utils 才能制作离线安装包 dnf install -y dnf-utils #安装工具包 2、创建目录 #创建临时目录，作为虚拟系统根目录，用来计算依赖关系，不会影响真实的系统 mkdir -p /tmp/fake #创建存储目录，下载好的所有 .rpm 文件都保存在这里 mkdir -p /root/yum-rpm-full-x86 3、下载安装包到指定目录 dnf install --installroot=/tmp/fake --downloadonly --downloaddir=/root/yum-rpm-full-x86 \ wget telnet nmap traceroute ntp rsync lrzsz OpenIPMI ipmitool freeipmi screen ncurses-devel bind-utils libffi-devel libnfnetlink-devel libnl3-devel popt-devel tcpdump wireshark \ libtool [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/17063.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/17063.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux系统下RustDesk自建服务器教程</title>
		<link>https://www.osyunwei.com/archives/16887.html</link>
		<comments>https://www.osyunwei.com/archives/16887.html#comments</comments>
		<pubDate>Fri, 13 Feb 2026 08:30:13 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=16887</guid>
		<description><![CDATA[简单说明： RustDesk 是一款可以平替 TeamViewer 的开源软件，旨在提供安全便捷的自建方案。 操作系统：AnolisOS-8.10 AnolisOS-8.x安装配置图解教程 https://www.osyunwei.com/archives/14613.html 1、rustdesk下载 1.1rustdesk服务端下载： https://github.com/rustdesk/rustdesk-server/releases/ https://github.com/rustdesk/rustdesk-server/releases/download/1.1.15/rustdesk-server-linux-amd64.zip 1.2rustdes客户端下载： https://github.com/rustdesk/rustdesk https://github.com/rustdesk/rustdesk/releases/tag/1.4.5 1.2.1windows客户端 https://github.com/rustdesk/rustdesk/releases/download/1.4.5/rustdesk-1.4.5-x86_64.msi 1.2.2Android 手机/平板（ARM64 架构） 的安装包 https://github.com/rustdesk/rustdesk/releases/download/1.4.5/rustdesk-1.4.5-aarch64-signed.apk 说明：rustdesk服务端是部署在AnolisOS-8.10服务器上的，rustdes客户端是安装在windows系统和手机上的。 2、在AnolisOS-8.10服务器部署rustdesk服务端 2.1创建安装目录 mkdir -p /data/server/rustdesk-server 上传rustdesk-server-linux-amd64.zip到这个目录下 2.2关闭SELINUX，AnolisOS-8.x默认已经关闭 vi /etc/selinux/config #SELINUX=enforcing #注释掉 #SELINUXTYPE=targeted #注释掉 SELINUX=disabled #增加 :wq! #保存退出 setenforce 0 #使配置立即生效 getenforce #查看 SELinux 当前运行模式 2.3防火墙配置 AnolisOS-8.x默认使用的是firewall作为防火墙 firewall-cmd --list-all #显示所有规则（含服务、端口、区域） systemctl status firewalld [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/16887.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/16887.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>基于源 IP 白名单的 SSH 会话级 sudo 访问控制方案-实现单账号多权限安全隔离</title>
		<link>https://www.osyunwei.com/archives/16828.html</link>
		<comments>https://www.osyunwei.com/archives/16828.html#comments</comments>
		<pubDate>Thu, 22 Jan 2026 10:10:12 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=16828</guid>
		<description><![CDATA[1、场景描述 服务端ip：192.168.21.159 客户端ip：192.168.21.137、192.168.21.204 1.1 在服务端的主机上创建普通账号autoops #登录服务端主机，创建普通账号 useradd -m -s /bin/bash autoops passwd autoops #设置密码 1.2 设置此账号具有sudo权限 #添加普通用户到wheel组，使其具有sudo权限 gpasswd -a autoops wheel #验证wheel组 cat /etc/group &#124;grep wheel id autoops 可以看到autoops用户已经是在wheel组了 #从普通用户autoops登录服务器 执行sudo cp命令验证，已经具有sudo权限 1.3 设置sudo免密权限 #设置sudo免密执行 vi /etc/sudoers #编辑 autoops ALL=(ALL) NOPASSWD: ALL :wq! #保存退出 现在从autoops登录后执行sudo命令已经不需要再输入密码了 2、设置客户端主机 2.1 创建普通账号autoops #登录所有客户端主机，分别创建普通账号 useradd -m -s /bin/bash autoops passwd [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/16828.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/16828.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux下编译安装Nginx</title>
		<link>https://www.osyunwei.com/archives/16822.html</link>
		<comments>https://www.osyunwei.com/archives/16822.html#comments</comments>
		<pubDate>Mon, 19 Jan 2026 09:40:25 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Nginx]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[nginx]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=16822</guid>
		<description><![CDATA[操作系统：Rocky Linux 10.x Rocky Linux 10.x系统安装配置图解教程 https://www.osyunwei.com/archives/15874.html 安装包下载： 1、nginx https://nginx.org/download/nginx-1.28.1.tar.gz 2、zlib https://www.zlib.net/zlib-1.3.1.tar.gz 3、pcre2 https://github.com/PCRE2Project/pcre2/releases/download/pcre2-10.47/pcre2-10.47.tar.gz 4、openssl https://github.com/openssl/openssl/releases/download/openssl-3.5.4/openssl-3.5.4.tar.gz 安装前准备： 1、防火墙配置 Rocky Linux默认使用的是firewall作为防火墙 firewall-cmd --list-all #显示所有规则（含服务、端口、区域） systemctl status firewalld #检查 firewalld 状态 #开放80 443 端口 firewall-cmd --permanent --add-port=80/tcp firewall-cmd --permanent --add-port=443/tcp firewall-cmd --reload #重新加载防火墙配置 2、关闭SELINUX vi /etc/selinux/config #SELINUX=enforcing #注释掉 #SELINUXTYPE=targeted #注释掉 SELINUX=disabled #增加 :wq! #保存退出 setenforce 0 #使配置立即生效 [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/16822.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/16822.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BCLinux For Euler 21.10安装3节点PanWeiDB数据库集群</title>
		<link>https://www.osyunwei.com/archives/16807.html</link>
		<comments>https://www.osyunwei.com/archives/16807.html#comments</comments>
		<pubDate>Tue, 09 Dec 2025 08:39:27 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=16807</guid>
		<description><![CDATA[简介介绍： PanWeiDB数据库：https://www.panwei.tech/ PanWeiDB是基于openGauss，openGauss基于PostgreSQL 操作系统：BCLinux For Euler 21.10 BCLinux For Euler 21.10安装配置图解教程 https://www.osyunwei.com/archives/13044.html 磐维数据库安装包：PanWeiDB_1.0.0_BCLinuxForEuler21.10_x86.tar.gz ptk安装工具包下载地址： https://docs.mogdb.io/zh/ptk/v1.1/install https://cdn-mogdb.enmotech.com/ptk/latest/ptk_linux_x86_64.tar.gz 主节点ip：10.189.189.184 主机名：panweidb-node01 从节点ip：10.189.189.185 主机名：panweidb-node02 从节点ip：10.189.189.186 主机名：panweidb-node03 准备篇（在3台服务器上都进行操作） 1、关闭selinux sed -i 's/^SELINUX=.*/SELINUX=disabled/' /etc/selinux/config setenforce 0 2、关闭firewall防火墙 vi /etc/yum/pluginconf.d/license-manager.conf enabled=0 #把1修改为0，禁用yum源认证 :wq! #保存退出 systemctl stop firewalld.service systemctl disable firewalld.service systemctl mask firewalld systemctl stop firewalld yum remove firewalld -y #卸载 3、关闭swap交换分区（如果没有swap分区就不需要操作） [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/16807.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/16807.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>使用Nginx实现HTTPS和SSH共用同一个端口访问各自服务</title>
		<link>https://www.osyunwei.com/archives/16800.html</link>
		<comments>https://www.osyunwei.com/archives/16800.html#comments</comments>
		<pubDate>Mon, 08 Dec 2025 09:12:03 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[nginx]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=16800</guid>
		<description><![CDATA[需求： 对外只能开放一个端口，要实现https服务，还要能通过ssh访问Linux服务器 分析： 可以使用Nginx的四层代理（stream 模块） 与 TLS 预读（ssl_preread） 功能 注意：HTTP协议无法通过stream模块的SNI识别，因为stream模块只能识别TLS握手包中的协议信息。 具体操作： Nginx 编译时要包含以下模块才可以： --with-stream --with-stream_ssl_preread_module 验证命令： /data/server/nginx/sbin/nginx -V 2&#62;&#38;1 &#124; grep -o 'with-stream\&#124;with-stream_ssl_preread_module' #有输出即支持 参考资料： Nginx 单端口兼容 HTTP 与 HTTPS：基于 stream 模块与 ssl_preread 的智能分流方案 准备就绪： SSH 服务运行在 22 端口（默认） HTTPS 服务运行在 另一个端口，例如28443 对外只开放9290端口 1、修改nginx配置文件 cp /data/server/nginx/conf/nginx.conf /data/server/nginx/conf/nginx.conf.bak 1.1在nginx主配置文件引入stream模块 mkdir -p /data/server/nginx/conf/stream #创建目录 vi /data/server/nginx/conf/nginx.conf #stream块必须在顶层，和 [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/16800.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/16800.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nginx 单端口兼容 HTTP 与 HTTPS：基于 stream 模块与 ssl_preread 的智能分流方案</title>
		<link>https://www.osyunwei.com/archives/16788.html</link>
		<comments>https://www.osyunwei.com/archives/16788.html#comments</comments>
		<pubDate>Sun, 07 Dec 2025 15:18:53 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[nginx]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=16788</guid>
		<description><![CDATA[需求： 通过一个端口9190可以实现http和https同时访问 例如： http://10.189.189.189:9190/#/public/login https://10.189.189.189:9190/#/public/login 真实的地址是： http协议：http://10.189.189.189:9997/#/public/login https协议：http://10.189.189.189:28443/#/public/login 分析： 1、Nginx 本身无法使用1个端口同时处理 HTTP 和 HTTPS 请求 2、可以通过 stream 模块 + ssl_preread 实现： 监听同一个端口9190，自动识别客户端发来的是 HTTP 还是 HTTPS流量，并分别转发给后端的 HTTP（9997端口） 服务和 HTTPS （28443端口） 服务 3、这样就实现了只用1个端口可以同时访问http和https页面，这不属于“Nginx 在同一端口提供两种协议”，而是通过四层代理智能分流。 4、需要使用新版本的nginx，并启用 --with-stream 和 --with-stream_ssl_preread_module模块 具体操作： 1、检查nginx是否启用--with-stream 和 --with-stream_ssl_preread_module模块 /data/server/nginx/sbin/nginx -V 2&#62;&#38;1 &#124; grep -o 'with-stream\&#124;with-stream_ssl_preread_module' 2、重新编译nginx，添加模块 /data/server/nginx/sbin/nginx -V #查看nginx编译参数，如果未启用，需要添加上面两个模块，重新编译nginx ./configure --prefix=/data/server/nginx --user=www --group=www [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/16788.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/16788.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux系统下安装部署最新版3节点ZooKeeper集群环境</title>
		<link>https://www.osyunwei.com/archives/16748.html</link>
		<comments>https://www.osyunwei.com/archives/16748.html#comments</comments>
		<pubDate>Mon, 13 Oct 2025 10:20:04 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=16748</guid>
		<description><![CDATA[1、ZooKeeper介绍 1.1、ZooKeeper 在 Java 版本 1.8 或更高版本中运行（JDK 8 LTS、JDK 11 LTS、JDK 12 - 不支持 Java 9 和 10），它作为 ZooKeeper 服务器的集合运行，三个 ZooKeeper 服务器是一个整体的最小推荐大小，我们还建议它们在不同的机器上运行。 1.2、ZooKeeper 集群强烈建议使用奇数台机器，例如，在四台机器上，ZooKeeper 只能处理一台机器的故障；如果两台机器发生故障，则其余两台机器不构成多数。但是，如果有五台机器，ZooKeeper 可以处理两台机器的故障。容错集群设置至少需要三台服务器。 1.3、通常三台服务器对于生产安装来说绰绰有余，但为了在维护期间获得最大的可靠性，您可能希望安装五台服务器。 1.4、官方网站： https://zookeeper.apache.org/ 1.5、下载地址： 目前最新版本 https://www.apache.org/dyn/closer.lua/zookeeper/zookeeper-3.9.4/apache-zookeeper-3.9.4-bin.tar.gz 1.6、说明文档： https://zookeeper.apache.org/doc/current/zookeeperAdmin.html 2、部署zookeeper集群，这里使用三台服务器组成集群模式。 操作系统：AnolisOS ip地址：192.168.21.201，192.168.21.202，192.168.21.203 zookeeper默认使用2181端口，集群模式还会用到2888、3888端口，建议zookeeper部署在内网环境中，服务器上关闭防火墙、关闭SELINUX。 分别在三台服务器上操作。 2.1、安装Java ZooKeeper依赖Java才能运行，首先安装Java环境，我们使用Java 25版本 Linux系统下安装Java JDK：https://www.osyunwei.com/archives/16760.html 2.2、安装ZooKeeper mkdir -p /data/server/zookeeper #创建安装目录 mkdir -p /data/server/zookeeper/data #创建数据目录 mkdir -p [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/16748.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/16748.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux下编译安装Apache并支持php</title>
		<link>https://www.osyunwei.com/archives/16731.html</link>
		<comments>https://www.osyunwei.com/archives/16731.html#comments</comments>
		<pubDate>Thu, 11 Sep 2025 08:52:51 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[LAMP]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[php]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=16731</guid>
		<description><![CDATA[前置知识： Rocky Linux 10.x编译安装nginx-1.28.x+mysql-8.4.x+php-8.4.x https://www.osyunwei.com/archives/16714.html 安装包下载： 1、apache https://dlcdn.apache.org/httpd/httpd-2.4.65.tar.gz 2、apr（Apache库文件） https://dlcdn.apache.org//apr/apr-1.7.6.tar.gz 3、apr-util（Apache库文件） https://dlcdn.apache.org//apr/apr-util-1.6.3.tar.gz 4、apache支持php模块 https://dlcdn.apache.org/httpd/mod_fcgid/mod_fcgid-2.3.9.tar.gz 安装apache： 1、安装编译工具包 yum install gcc make apr-devel apr-util-devel pcre2-devel openssl-devel 2、安装apr cd /usr/local/src tar zxvf apr-1.7.6.tar.gz cd apr-1.7.6 ./configure --prefix=/usr/local/apr make -j$(nproc) make install 3、安装apr-util cd /usr/local/src tar zxvf apr-util-1.6.3.tar.gz cd apr-util-1.6.3 ./configure --prefix=/usr/local/apr-util --with-apr=/usr/local/apr make -j$(nproc) make install ls /usr/local/apr-util/lib/libaprutil-1.so [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/16731.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/16731.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux下使用KVM虚拟机制作系统镜像模板</title>
		<link>https://www.osyunwei.com/archives/16548.html</link>
		<comments>https://www.osyunwei.com/archives/16548.html#comments</comments>
		<pubDate>Tue, 15 Jul 2025 11:12:30 +0000</pubDate>
		<dc:creator>qihang01</dc:creator>
				<category><![CDATA[KVM]]></category>
		<category><![CDATA[kvm]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">https://www.osyunwei.com/?p=16548</guid>
		<description><![CDATA[相关连接： 1、Rocky Linux 10.0下安装使用KVM虚拟机 2、Linux下使用KVM虚拟机安装Windows系统 在 KVM 虚拟化环境中，你可以将已经安装好的Linux虚拟机制作成系统镜像模板，供后续快速创建新虚拟机使用。 1、创建一个模板虚拟机 我们使用Rocky-10.0-x86_64-minimal.iso镜像来创建虚拟机 #创建虚拟机 virt-install \ --name rocky10 \ --vcpu 2 \ --memory 4096 \ --disk path=/data/libvirt/images/rocky10.qcow2,size=40,bus=virtio \ --cdrom /data/libvirt/iso/Rocky-10.0-x86_64-minimal.iso \ --network bridge=br0 \ --graphics vnc \ --os-variant rocky10 \ --noautoconsole #虚拟机创建完成后，我们进入web控制台安装系统，直到系统安装完成 2、登录模板虚拟机中进行操作 #模板虚拟机中安装cloud-init工具 #cloud-init工具是实现自动化配置的工具 yum install cloud-init cloud-utils-growpart #验证安装是否成功 rpm -qa &#124; grep cloud-init #查看版本 cloud-init -v [...]<p><a rel="bookmark" href="https://www.osyunwei.com/archives/16548.html" target="_blank">查看全文</a></p>]]></description>
		<wfw:commentRss>https://www.osyunwei.com/archives/16548.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
