From e129e4939f421ce809014044162d2f037a7bbcc4 Mon Sep 17 00:00:00 2001 From: Bachir Soussi Chiadmi Date: Wed, 17 Apr 2019 18:18:47 +0200 Subject: [PATCH] zabbix urbackup --- assets/urbackup.service | 13 + assets/zabbix/misc/02periodic | 2 + assets/zabbix/promox-ct.conf | 5 + assets/zabbix/scripts/nginx-stat.py | 91 + .../zbx_linux_container_template.xml | 2487 +++++++++++++++++ .../zabbix/templates/zbx_template_nginx.xml | 560 ++++ assets/zabbix/userparameter_mysql.conf | 18 + assets/zabbix/userparameter_nginx.conf | 21 + bin/bash.sh | 2 + bin/dotfiles.sh | 23 +- bin/lemp.sh | 139 +- bin/misc.sh | 8 +- bin/urbackup.sh | 81 + bin/zabbix.sh | 94 + install.sh | 7 +- readme.md | 29 +- 16 files changed, 3417 insertions(+), 163 deletions(-) create mode 100644 assets/urbackup.service create mode 100644 assets/zabbix/misc/02periodic create mode 100644 assets/zabbix/promox-ct.conf create mode 100644 assets/zabbix/scripts/nginx-stat.py create mode 100644 assets/zabbix/templates/zbx_linux_container_template.xml create mode 100644 assets/zabbix/templates/zbx_template_nginx.xml create mode 100644 assets/zabbix/userparameter_mysql.conf create mode 100644 assets/zabbix/userparameter_nginx.conf create mode 100644 bin/urbackup.sh create mode 100755 bin/zabbix.sh diff --git a/assets/urbackup.service b/assets/urbackup.service new file mode 100644 index 0000000..497fc4d --- /dev/null +++ b/assets/urbackup.service @@ -0,0 +1,13 @@ +#!/sbin/openrc-run +# $Id$ + +URBACKUPCLIENT_CONFIG="/etc/conf.d/urbackupclient" +URBACKUPCLIENT_PIDFILE="/var/run/urbackupclient.pid" + +command="/usr/local/sbin/urbackupclientbackend" +command_args="-c ${URBACKUPCLIENT_CONFIG} -w ${URBACKUPCLIENT_PIDFILE} -d" +pidfile="${URBACKUPCLIENT_PIDFILE}" + +depend() { + use logger net urbackupsrv +} diff --git a/assets/zabbix/misc/02periodic b/assets/zabbix/misc/02periodic new file mode 100644 index 0000000..18ec023 --- /dev/null +++ b/assets/zabbix/misc/02periodic @@ -0,0 +1,2 @@ +APT::Periodic::Enable "1"; +APT::Periodic::Update-Package-Lists "1"; diff --git a/assets/zabbix/promox-ct.conf b/assets/zabbix/promox-ct.conf new file mode 100644 index 0000000..97c1c89 --- /dev/null +++ b/assets/zabbix/promox-ct.conf @@ -0,0 +1,5 @@ +# https://support.zabbix.com/browse/ZBX-12164 +# https://github.com/kvaps/zabbix-linux-container-template +UserParameter=ct.memory.size[*],free -b | awk '$ 1 == "Mem:" {total=$ 2; used=($ 3+$ 5); pused=(($ 3+$ 5)*100/$ 2); free=$ 4; pfree=($ 4*100/$ 2); shared=$ 5; buffers=$ 6; cache=$ 6; available=($ 6+$ 7); pavailable=(($ 6+$ 7)*100/$ 2); if("$1" == "") {printf("%.0f", total )} else {printf("%.0f", $1 "" )} }' +UserParameter=ct.swap.size[*],free -b | awk '$ 1 == "Swap:" {total=$ 2; used=$ 3; free=$ 4; pfree=($ 4*100/$ 2); pused=($ 3*100/$ 2); if("$1" == "") {printf("%.0f", free )} else {printf("%.0f", $1 "" )} }' +UserParameter=ct.cpu.load[*],uptime | awk -F'[, ]+' '{avg1=$(NF-2); avg5=$(NF-1); avg15=$(NF)}{print $2/'$(nproc)'}' diff --git a/assets/zabbix/scripts/nginx-stat.py b/assets/zabbix/scripts/nginx-stat.py new file mode 100644 index 0000000..6a8ce43 --- /dev/null +++ b/assets/zabbix/scripts/nginx-stat.py @@ -0,0 +1,91 @@ +#!/usr/bin/python +# +# Options: +# +# -a active +# -a accepted +# -a handled +# -a requests +# -a reading +# -a writing +# -a waiting +# + + +import sys +import getopt +import urllib2 +import re +import ssl + + +def usage(): + print "usage: nginx-stat.py -h 127.0.0.1 -p 80 -a [active|accepted|handled|request|reading|writing|waiting]" + sys.exit(2) + + +def main(): + + # Default values + host = "localhost" + port = "80" + getInfo = "None" + proto = "http" + _headers = {} + gcontext = "" + + + if len(sys.argv) < 2: + usage() + + try: + opts, _ = getopt.getopt(sys.argv[1:], "h:p:a:") + except getopt.GetoptError: + usage() + + # Assign parameters as variables + for opt, arg in opts: + if opt == "-h": + host = arg + if opt == "-p": + port = arg + if opt == "-a": + getInfo = arg + + if port == "443": + proto = "https" + _headers = {'X-Mashape-Key': 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX'} + gcontext = ssl.SSLContext(ssl.PROTOCOL_TLSv1_2) + + url = proto + "://" + host + ":" + port + "/nginx_status/" + request = urllib2.Request(url, headers=_headers) + result = urllib2.urlopen(request, context=gcontext) + + buffer = re.findall(r'\d{1,8}', result.read()) + +## Format: +## Active connections: 196 +## server accepts handled requests +## 272900 272900 328835 +## Reading: 0 Writing: 6 Waiting: 190 + + if getInfo == "active": + print buffer[0] + elif getInfo == "accepted": + print buffer[1] + elif getInfo == "handled": + print buffer[2] + elif getInfo == "requests": + print buffer[3] + elif getInfo == "reading": + print buffer[4] + elif getInfo == "writing": + print buffer[5] + elif getInfo == "waiting": + print buffer[6] + else: + print "unknown" + sys.exit(1) + +if __name__ == "__main__": + main() diff --git a/assets/zabbix/templates/zbx_linux_container_template.xml b/assets/zabbix/templates/zbx_linux_container_template.xml new file mode 100644 index 0000000..017bcd3 --- /dev/null +++ b/assets/zabbix/templates/zbx_linux_container_template.xml @@ -0,0 +1,2487 @@ + + + 3.4 + 2018-01-25T15:03:17Z + + + Templates + + + + + + + + {Template Linux Container:vfs.file.cksum[/etc/passwd].diff(0)}>0 + 0 + + /etc/passwd has been changed on {HOST.NAME} + 0 + + + 0 + 2 + + 0 + 0 + + + + + {Template Linux Container:kernel.maxfiles.last(0)}<1024 + 0 + + Configured max number of opened files is too low on {HOST.NAME} + 0 + + + 0 + 1 + + 0 + 0 + + + + + {Template Linux Container:kernel.maxproc.last(0)}<256 + 0 + + Configured max number of processes is too low on {HOST.NAME} + 0 + + + 0 + 1 + + 0 + 0 + + + + + {Template Linux Container:system.cpu.util[,iowait].avg(5m)}>75 + 0 + + Disk I/O is overloaded on {HOST.NAME} + 0 + + + 0 + 2 + OS spends significant time waiting for I/O (input/output) operations. It could be indicator of performance issues with storage system. + 0 + 0 + + + + + {Template Linux Container:system.uname.diff(0)}>0 + 0 + + Host information was changed on {HOST.NAME} + 0 + + + 0 + 1 + + 0 + 0 + + + + + {Template Linux Container:system.hostname.diff(0)}>0 + 0 + + Hostname was changed on {HOST.NAME} + 0 + + + 0 + 1 + + 0 + 0 + + + + + {Template Linux Container:ct.memory.size[available].last(0)}<20M + 0 + + Lack of available memory on server {HOST.NAME} + 0 + + + 0 + 3 + + 0 + 0 + + + + + {Template Linux Container:ct.swap.size[pused].last(0)}>50 + 0 + + Lack of free swap space on {HOST.NAME} + 0 + + + 1 + 2 + It probably means that the systems requires more physical memory. + 0 + 0 + + + + + {Template Linux Container:ct.cpu.load[percpu,avg1].avg(5m)}>20 + 0 + + Processor load is too high on {HOST.NAME} + 0 + + + 0 + 2 + + 0 + 0 + + + + + {Template Linux Container:proc.num[].avg(5m)}>1000 + 0 + + Too many processes on {HOST.NAME} + 0 + + + 0 + 2 + + 0 + 0 + + + + + {Template Linux Container:proc.num[,,run].avg(5m)}>100 + 0 + + Too many processes running on {HOST.NAME} + 0 + + + 0 + 2 + + 0 + 0 + + + + + {Template Linux Container:system.uptime.change(0)}<0 + 0 + + {HOST.NAME} has just been restarted + 0 + + + 0 + 1 + + 0 + 0 + + + + + + + CPU jumps + 900 + 200 + 0.0000 + 100.0000 + 1 + 1 + 0 + 1 + 0 + 0.0000 + 0.0000 + 0 + 0 + 0 + 0 + + + 0 + 0 + 009900 + 0 + 2 + 0 + + Template Linux Container + system.cpu.switches + + + + 1 + 0 + 000099 + 0 + 2 + 0 + + Template Linux Container + system.cpu.intr + + + + + + CPU load + 900 + 200 + 0.0000 + 100.0000 + 1 + 1 + 0 + 1 + 0 + 0.0000 + 0.0000 + 1 + 0 + 0 + 0 + + + 0 + 0 + 009900 + 0 + 2 + 0 + + Template Linux Container + ct.cpu.load[percpu,avg1] + + + + 1 + 0 + 000099 + 0 + 2 + 0 + + Template Linux Container + ct.cpu.load[percpu,avg5] + + + + 2 + 0 + 990000 + 0 + 2 + 0 + + Template Linux Container + ct.cpu.load[percpu,avg15] + + + + + + CPU utilization + 900 + 200 + 0.0000 + 100.0000 + 1 + 0 + 1 + 1 + 0 + 0.0000 + 0.0000 + 1 + 1 + 0 + 0 + + + 0 + 1 + FF5555 + 0 + 2 + 0 + + Template Linux Container + system.cpu.util[,steal] + + + + 1 + 1 + 55FF55 + 0 + 2 + 0 + + Template Linux Container + system.cpu.util[,softirq] + + + + 2 + 1 + 009999 + 0 + 2 + 0 + + Template Linux Container + system.cpu.util[,interrupt] + + + + 3 + 1 + 990099 + 0 + 2 + 0 + + Template Linux Container + system.cpu.util[,nice] + + + + 4 + 1 + 999900 + 0 + 2 + 0 + + Template Linux Container + system.cpu.util[,iowait] + + + + 5 + 1 + 990000 + 0 + 2 + 0 + + Template Linux Container + system.cpu.util[,system] + + + + 6 + 1 + 000099 + 0 + 2 + 0 + + Template Linux Container + system.cpu.util[,user] + + + + 7 + 1 + 009900 + 0 + 2 + 0 + + Template Linux Container + system.cpu.util[,idle] + + + + + + Memory usage + 900 + 200 + 0.0000 + 100.0000 + 1 + 1 + 0 + 1 + 0 + 0.0000 + 0.0000 + 1 + 2 + 0 + + Template Linux Container + ct.memory.size[total] + + + + 0 + 1 + BB0000 + 0 + 2 + 0 + + Template Linux Container + ct.memory.size[total] + + + + 1 + 1 + 00C800 + 0 + 2 + 0 + + Template Linux Container + ct.memory.size[available] + + + + + + Swap usage + 600 + 340 + 0.0000 + 0.0000 + 0 + 0 + 2 + 1 + 0 + 0.0000 + 0.0000 + 0 + 0 + 0 + 0 + + + 0 + 0 + AA0000 + 0 + 2 + 0 + + Template Linux Container + ct.swap.size[used] + + + + 1 + 0 + 00AA00 + 0 + 2 + 2 + + Template Linux Container + ct.swap.size[total] + + + + + + diff --git a/assets/zabbix/templates/zbx_template_nginx.xml b/assets/zabbix/templates/zbx_template_nginx.xml new file mode 100644 index 0000000..5aae3d2 --- /dev/null +++ b/assets/zabbix/templates/zbx_template_nginx.xml @@ -0,0 +1,560 @@ + + + 3.4 + 2017-12-20T20:10:24Z + + + Templates + + + + + + + + Nginx Connection Status + 900 + 200 + 0.0000 + 100.0000 + 1 + 1 + 0 + 1 + 0 + 0.0000 + 0.0000 + 0 + 0 + 0 + 0 + + + 0 + 5 + 00C800 + 0 + 2 + 0 + + Template App Nginx + nginx.active[{HOST.IP},{$NGINX_PORT}] + + + + 1 + 0 + 0000C8 + 0 + 2 + 0 + + Template App Nginx + nginx.reading[{HOST.IP},{$NGINX_PORT}] + + + + 2 + 0 + C80000 + 0 + 2 + 0 + + Template App Nginx + nginx.waiting[{HOST.IP},{$NGINX_PORT}] + + + + 3 + 0 + C800C8 + 0 + 2 + 0 + + Template App Nginx + nginx.writing[{HOST.IP},{$NGINX_PORT}] + + + + + + Nginx Requests Statistics + 900 + 200 + 0.0000 + 100.0000 + 1 + 1 + 0 + 1 + 0 + 0.0000 + 0.0000 + 0 + 0 + 0 + 0 + + + 0 + 5 + 00C800 + 0 + 2 + 0 + + Template App Nginx + nginx.handled[{HOST.IP},{$NGINX_PORT}] + + + + 1 + 0 + 0000C8 + 0 + 2 + 0 + + Template App Nginx + nginx.accepted[{HOST.IP},{$NGINX_PORT}] + + + + 2 + 0 + C80000 + 0 + 2 + 0 + + Template App Nginx + nginx.total[{HOST.IP},{$NGINX_PORT}] + + + + + + diff --git a/assets/zabbix/userparameter_mysql.conf b/assets/zabbix/userparameter_mysql.conf new file mode 100644 index 0000000..ebd516d --- /dev/null +++ b/assets/zabbix/userparameter_mysql.conf @@ -0,0 +1,18 @@ +# For all the following commands HOME should be set to the directory that has .my.cnf file with password information. + +# Flexible parameter to grab global variables. On the frontend side, use keys like mysql.status[Com_insert]. +# Key syntax is mysql.status[variable]. +UserParameter=mysql.status[*],echo "show global status where Variable_name='$1';" | HOME=/var/lib/zabbix mysql -N | awk '{print $$2}' + +# Flexible parameter to determine database or table size. On the frontend side, use keys like mysql.size[zabbix,history,data]. +# Key syntax is mysql.size[,,]. +# Database may be a database name or "all". Default is "all". +# Table may be a table name or "all". Default is "all". +# Type may be "data", "index", "free" or "both". Both is a sum of data and index. Default is "both". +# Database is mandatory if a table is specified. Type may be specified always. +# Returns value in bytes. +# 'sum' on data_length or index_length alone needed when we are getting this information for whole database instead of a single table +UserParameter=mysql.size[*],bash -c 'echo "select sum($(case "$3" in both|"") echo "data_length+index_length";; data|index) echo "$3_length";; free) echo "data_free";; esac)) from information_schema.tables$([[ "$1" = "all" || ! "$1" ]] || echo " where table_schema=\"$1\"")$([[ "$2" = "all" || ! "$2" ]] || echo "and table_name=\"$2\"");" | HOME=/var/lib/zabbix mysql -N' + +UserParameter=mysql.ping,HOME=/var/lib/zabbix mysqladmin ping | grep -c alive +UserParameter=mysql.version,mysql -V diff --git a/assets/zabbix/userparameter_nginx.conf b/assets/zabbix/userparameter_nginx.conf new file mode 100644 index 0000000..c7b3843 --- /dev/null +++ b/assets/zabbix/userparameter_nginx.conf @@ -0,0 +1,21 @@ +# in nginx config: +# location /nginx_status { +# # Turn on nginx stats +# stub_status on; +# # I do not need logs for stats +# access_log off; +# # Security: Only allow access from IP # +# allow $1; +# # Send rest of the world to /dev/null # +# deny all; +# } + +UserParameter=nginx.accepted[*],/etc/zabbix/zabbix_agentd.scripts/nginx-stat.py -h $1 -p $2 -a accepted +UserParameter=nginx.active[*],/etc/zabbix/zabbix_agentd.scripts/nginx-stat.py -h $1 -p $2 -a active +UserParameter=nginx.handled[*],/etc/zabbix/zabbix_agentd.scripts/nginx-stat.py -h $1 -p $2 -a handled +UserParameter=nginx.reading[*],/etc/zabbix/zabbix_agentd.scripts/nginx-stat.py -h $1 -p $2 -a reading +UserParameter=nginx.total[*],/etc/zabbix/zabbix_agentd.scripts/nginx-stat.py -h $1 -p $2 -a requests +UserParameter=nginx.waiting[*],/etc/zabbix/zabbix_agentd.scripts/nginx-stat.py -h $1 -p $2 -a waiting +UserParameter=nginx.writing[*],/etc/zabbix/zabbix_agentd.scripts/nginx-stat.py -h $1 -p $2 -a writing + +UserParameter=nginx.version,nginx -v 2>&1 diff --git a/bin/bash.sh b/bin/bash.sh index 5784959..0fbc70d 100755 --- a/bin/bash.sh +++ b/bin/bash.sh @@ -3,3 +3,5 @@ apk add bash bash-doc bash-completion sed -i 's/root:\/bin\/ash/root:\/bin\/bash/g' /etc/passwd + +exec bash diff --git a/bin/dotfiles.sh b/bin/dotfiles.sh index b0adf16..eae8e0c 100755 --- a/bin/dotfiles.sh +++ b/bin/dotfiles.sh @@ -7,27 +7,8 @@ echo ' |___/\___/\__|_| |_|_\___/__/ ' #installing better prompt and some goodies -echo "Installing shell prompt for current user $USER " +echo "Installing dot files for current user" sleep 2 -# -# # get the current position -# _cwd="$(pwd)" -# -# # check for assets forlder -# _assets="$_cwd/assets" -# if [ ! -d "$_assets" ]; then -# _assets="$_cwd/../assets" -# if [ ! -d "$_assets" ]; then -# echo "!! can't find assets directory !!" -# exit -# fi -# fi -# -# cp "$_assets"/dotfiles/.vimrc /home/"$USER"/ -# cp -r "$_assets"/dotfiles/.vim /home/"$USER"/ -# -# cp "$_assets"/dotfiles/.inputrc /home/"$USER"/ - # get the current position _cwd="$(pwd)" @@ -39,4 +20,4 @@ source ~/.bashrc # return to working directory cd "$_cwd" -echo "Dot files installed for $USER" +echo "Dot files installed" diff --git a/bin/lemp.sh b/bin/lemp.sh index c2fe2bf..943c3b2 100755 --- a/bin/lemp.sh +++ b/bin/lemp.sh @@ -59,7 +59,7 @@ echo -e ' ' echo -e "Installing PHP 7.0" sleep 3 -apk add php7 php7-fpm php7-pdo_mysql php7-opcache php7-curl php7-mbstring php7-zip php7-xml php7-gd php7-mcrypt php7-imagick +apk add php7 php7-fpm php7-pdo_mysql php7-opcache php7-curl php7-mbstring php7-zip php7-xml php7-gd php7-mcrypt php7-imagick php7-phar echo -e "Configuring PHP" @@ -123,33 +123,30 @@ echo -e "Nginx installed" # echo -e "You can access it at yourip/phpmyadmin" echo -e ' - ____ ___ - / __ \___ ____/ (_)____ - / /_/ / _ \/ __ / / ___/ - / _, _/ __/ /_/ / (__ ) -/_/ |_|\___/\__,_/_/____/ + _ _ + _ _ ___ __| (_)___ + | `_/ -_) _` | (_-< + |_| \___\__,_|_/__/ ' echo -e "Installing Redis" sleep 3 -apk add redis-server php-redis +apk add redis php7-pecl-redis # TODO set maxmemory=2gb # TODO set maxmemory-policy=volatile-lru # TODO comment all save line -systemctl enable redis-server -systemctl restart redis-server -systemctl restart php7.0-fpm +rc-update add redis +service redis start +service php-fpm7 restart echo -e "Redis installed" echo -e ' - ______ - / ____/___ ____ ___ ____ ____ ________ _____ - / / / __ \/ __ `__ \/ __ \/ __ \/ ___/ _ \/ ___/ -/ /___/ /_/ / / / / / / /_/ / /_/ (__ ) __/ / -\____/\____/_/ /_/ /_/ .___/\____/____/\___/_/ - /_/ + __ ___ _ __ _ __ ___ ___ ___ _ _ + / _/ _ \ ` \| `_ \/ _ (_- /etc/monit/monitrc -# -# # TODO setup webaccess -# passok=0 -# while [ "$passok" = "0" ] -# do -# echo -n "Write web access password to monit" -# read passwda -# echo -n "ReWrite web access password to monit" -# read passwdb -# if [ "$passwda" = "$passwdb" ]; then -# sed -i 's/PASSWD_TO_REPLACE/$passwda/g' /etc/monit/monitrc -# passok=1 -# else -# echo -e "pass words don't match, please try again" -# fi -# done -# -# # TODO setup mail settings -# sed -i "s/server1\.example\.com/$HOSTNAME/g" /etc/monit/monitrc -# -# mkdir /var/www/html/monit -# echo -e "hello" > /var/www/html/monit/token -# -# service monit start -# -# echo -e "Monit installed" - - -# echo -e ' -# ___ __ __ -# / |_ _______/ /_____ _/ /_ -# / /| | | /| / / ___/ __/ __ `/ __/ -# / ___ | |/ |/ (__ ) /_/ /_/ / /_ -# /_/ |_|__/|__/____/\__/\__,_/\__/ -#' -# echo -e "Installing Awstat" -# sleep 3 -# apt-get --yes --force-yes install awstats -# # Configure AWStats -# temp=`grep -i sitedomain /etc/awstats/awstats.conf.local | wc -l` -# if [ $temp -lt 1 ]; then -# echo SiteDomain="$_domain" >> /etc/awstats/awstats.conf.local -# fi -# # Disable Awstats from executing every 10 minutes. Put a hash in front of any line. -# sed -i 's/^[^#]/#&/' /etc/cron.d/awstats -# echo -e "Awstat installed" diff --git a/bin/misc.sh b/bin/misc.sh index 35e4a34..ce3db2e 100755 --- a/bin/misc.sh +++ b/bin/misc.sh @@ -15,12 +15,12 @@ echo '@edge http://dl-cdn.alpinelinux.org/alpine/edge/main @edgecommunity http://dl-cdn.alpinelinux.org/alpine/edge/community @testing http://dl-cdn.alpinelinux.org/alpine/edge/testing' >> /etc/apk/repositories -apk add vim curl +apk update + +apk add procps vim curl tmux etckeeper htop lynx unzip # needrestart + # sed -i "s/^# en_GB.UTF-8/en_GB.UTF-8/g" /etc/locale.gen # locale-gen -# apt-get --yes --force-yes install ntp -# dpkg-reconfigure tzdata -apk add tmux etckeeper htop lynx unzip # needrestart apk add tzdata TIMEZONE="Europe/Paris" diff --git a/bin/urbackup.sh b/bin/urbackup.sh new file mode 100644 index 0000000..1bc7fd1 --- /dev/null +++ b/bin/urbackup.sh @@ -0,0 +1,81 @@ +#!/bin/sh + + +echo -e ' + _ _ _ _ ___ _ _ _ + | | | |_ _| |__ __ _ __| |___ _ _ __ / __| | (_)___ _ _| |_ + | |_| | _| _ \/ _` / _| / / || | _ \ | (__| |__| / -_) \ _| + \___/|_| |_.__/\__,_\__|_\_\\_,_| .__/ \___|____|_\___|_||_\__| + |_| +' + +if [ "$EUID" -ne 0 ]; then + echo "Please run as root" + exit +fi + +# get the current position +_cwd="$(pwd)" +# check for assets forlder +_assets="$_cwd/assets" +if [ ! -d "$_assets" ]; then + _assets="$_cwd/../assets" + if [ ! -d "$_assets" ]; then + echo "!! can't find assets directory !!" + exit + fi +fi + +# install urbackup client +# https://www.urbackup.org/client_debian_ubuntu_install.html +# https://blog.stephane-huc.net/systeme/debian/urbackup_client_gui +# https://urbackup.atlassian.net/wiki/spaces/US/pages/9142274/Headless+Linux+client+setup + +# Install the dependencies UrBackup needs +# apt install build-essential "g++" "libcrypto++-dev" libz-dev -y +apk add linux-headers "g++" zlib zlid-dev "crypto++@testing" "crypto++dev@testing" + +ln -s /usr/lib/libcryptopp.so /usr/lib/libcryptopp.so.5.6 + +# Download the UrBackup client source files and extract them +wget -P /tmp/ https://hndl.urbackup.org/Client/latest/urbackup-client-2.3.4.0.tar.gz +cd /tmp +tar xzf /tmp/urbackup-client-2.3.4.0.tar.gz + +# Build the UrBackup client and install it +cd /tmp/urbackup-client-2.3.4.0 +./configure --enable-headless +make -j4 +make install + +# Make sure that the UrBackup client backend runs correctly +# urbackupclientbackend -v info + +# configure +echo -n "Please provide the urbackup-server's ip : " +read _ip +echo -n "Please provide the internet_authkey of server : " +read _authkey +echo -n "Please provide the computer name of this client : " +read _computername + +echo "internet_server=$_ip +internet_server_port=55415 +internet_authkey=$_authkey +internet_mode_enabled=true +internet_image_backups_def=false +default_dirs_def=/etc;var/www;/var/backups/mysql +startup_backup_delay_def=3 +computername=$_computername" > /usr/local/var/urbackup/data/settings.cfg + +# firewall +ufw allow from "$_ip" to any port 35621 +ufw allow from "$_ip" to any port 35622 +ufw allow from "$_ip" to any port 35623 + +# install and enable openrc service +cp "$_assets"/urbackup.service /etc/init.d/urbackup +chmod a+x /etc/init.d/urbackup + +rc-update add urbackup +service urbackup start diff --git a/bin/zabbix.sh b/bin/zabbix.sh new file mode 100755 index 0000000..ebfd9ee --- /dev/null +++ b/bin/zabbix.sh @@ -0,0 +1,94 @@ +#!/bin/sh + + +echo -e ' + _ _ _ + _____ _| |__| |__(_)__ + |_ / _` | `_ \ `_ \ / _| + /__\__,_|_.__/_.__/_\__| +' + +. bin/checkroot.sh + +# get the current position +_cwd="$(pwd)" +# check for assets forlder +_assets="$_cwd/assets" +if [ ! -d "$_assets" ]; then + _assets="$_cwd/../assets" + if [ ! -d "$_assets" ]; then + echo "!! can't find assets directory !!" + exit + fi +fi + +apk add zabbix-agent + +# configure +echo -n "Please provide the current server's public ip : " +read _cur_ip +echo -n "Please provide the zabbix-server's ip : " +read _ip +echo -n "Please provide the hostname of this agent : " +read _host_name +echo -n "Please provide the mysql root password : " +read _root_mysql_passwd + + + + +# configure zabbix agent +sed -i "s#Server=127.0.0.1#Server=$_ip#g" /etc/zabbix/zabbix_agentd.conf +sed -i "s#ServerActive=127.0.0.1#ServerActive=$_ip#g" /etc/zabbix/zabbix_agentd.conf +sed -i "s#Hostname=Zabbix server#Hostname=$_host_name#g" /etc/zabbix/zabbix_agentd.conf + +_agent_conf_d="/etc/zabbix/zabbix_agentd.d" +mkdir $_agent_conf_d +sed -i "s|#\ Include=$|Include= $_agent_conf_d|g" /etc/zabbix/zabbix_agentd.conf + +# apk +# check for alpine security updates + +# # MYSQL +# # https://serverfault.com/questions/737018/zabbix-user-parameter-mysql-status-setting-home +# # create zabbix user home +# mkdir /var/lib/zabbix +# # generate random password for zabbix mysql user +# _passwd="$(< /dev/urandom tr -dc _A-Z-a-z-0-9 | head -c12)" +# # add mysql credentials to zabbix home +# printf "[client]\n +# user=zabbix\n +# password=$_passwd" > /var/lib/zabbix/.my.cnf +# # create zabbix mysql user +# mysql -uroot -p"$_root_mysql_passwd" -e "CREATE USER 'zabbix' IDENTIFIED BY '$_passwd';" +# mysql -uroot -p"$_root_mysql_passwd" -e "GRANT USAGE ON *.* TO 'zabbix'@'localhost' IDENTIFIED BY '$_passwd';" +# # add zabbix-agent parameter +# cp "$_assets"/zabbix/userparameter_mysql.conf "$_agent_conf_d"/ + +# NGINX +# https://github.com/sfuerte/zbx-nginx +# nginxconf already included in default.nginxconf asset +sed -i "s/# allow CURRENT-SERVER-IP/allow $_cur_ip/g" /etc/nginx/sites-available/default +cp "$_assets"/zabbix/userparameter_nginx.conf "$_agent_conf_d"/ +mkdir /etc/zabbix/zabbix_agentd.scripts +cp "$_assets"/zabbix/scripts/nginx-stat.py /etc/zabbix/zabbix_agentd.scripts/ +chmod +x /etc/zabbix/zabbix_agentd.scripts/nginx-stat.py + +echo -n "This is box is a proxmox CT? [Y|n] " +read yn +yn=${yn:-y} +if [ "$yn" = "Y" ] || [ "$yn" = "y" ]; then + cp "$_assets"/zabbix/proxmox-ct.conf "$_agent_conf_d"/ +fi + +# allow comm. port with zabbix-server +ufw allow from "$_ip" to any port 22 +ufw allow from "$_ip" to any port 10050 +# ufw allow from "$_ip" to any port 10051 + +rc-update add zabbix-agent +service zabbix-agent restart + +echo -e "Zabbix-agent installed and configured, please add the host $_host_name in your zabbix-server" +echo -e "And import requested templates in assets/zabbix/templates/" +# echo -e "zabbix user mysql password is $_passwd" diff --git a/install.sh b/install.sh index a9e003a..900fee2 100755 --- a/install.sh +++ b/install.sh @@ -23,13 +23,16 @@ fi _cwd="$(pwd)" . bin/upgrade -. bin/dotfiles.sh . bin/bash +. bin/misc.sh +. bin/dotfiles.sh . bin/user.sh . bin/ssh.sh -. bin/misc.sh . bin/ufw.sh . bin/fail2ban.sh . bin/knockd.sh # . bin/email.sh . bin/lemp.sh +# . bin/vhost.sh +. bin/zabbix.sh +# . bin/urbackup.sh diff --git a/readme.md b/readme.md index 9777df6..e6fcab4 100644 --- a/readme.md +++ b/readme.md @@ -1,22 +1,26 @@ # Install web server and secure it on alpine linux - [x] upgrade -- [x] adduser +- [x] bash - [x] misc -- [x] Ufw (to be replaced by awall) +- [x] dotfiles +- [x] user +- [x] secure openssh +- [x] Ufw (may be eventualy replaced by awall ?) - [x] Fail2ban -- [ ] Proftpd -- [ ] Knockd -- [ ] Mariadb -- [ ] php7-fpm -- [ ] Nginx +- [x] Knockd +- [ ] Mariadb (bug https://bugs.alpinelinux.org/issues/9046) +- [x] php7-fpm +- [x] Nginx +- [x] drush +- [x] composer - [ ] letsencrypt - [ ] vhosts -- [ ] redis +- [x] redis +- [x] zabbix-agent +- [x] urbackup-client - [ ] git barre repos -- [ ] zabbix-agent -- [ ] urbackup-client -- [ ] dotfiles and more +- [ ] Proftpd ## how to use it on a fresh install @@ -36,7 +40,6 @@ git clone https://figureslibres.io/gogs/bachir/alpine-web-server.git ``` su cd alpine-web-server -chmod a+x install.sh . install.sh ``` @@ -44,5 +47,3 @@ chmod a+x install.sh ``` . bin/misc.sh ``` - -## ref