è¡šé¡ã®éããŠã§ããµãŒããŒã®ç«ãŠçŽãã§ãããããVPSäžã§CentOS Stream9çKUSANAGI9ã䜿ããããã«ãªã£ããããã®ã§ãã®éVPSã®OSããšåã€ã³ã¹ããŒã«ããŠãããŸãã
äœãããªãã¡ããããªãã£ãã®ãã»ãããã¡ãªæé ããäœãå€ããã®ããããããããšãæ¯åå¿ãã¡ããã®ã§ã§ããã ãèšé²ã«æ®ããæ¹ãããããªãšæããäœãåèã«ããã®ããšããå«ãæžããŠãããã°ãšæããŸããèªã¿è¿ãã°æ·¡ã ãšæžãããã€ãŸããªãèšäºã§ãã
ãããããã«æžããŠãããšããããšã¯äœæ¥ãå®éãããããšãæå³ããŸããããã®éãã«ããã°ä»ã®ç°å¢ã§ãããŸããããšãããã®ã§ã¯å šããªãã®ã§ãããããããŸãããã®èšäºã®å€§éã®ãªã³ã¯ã¯ãã®å€ããæ¯èŒçè¿ããã¡ã«ãªã³ã¯åããšãªããªã¹ã¯ã®é«ããªã³ã¯ã§ããããšã«çæé ããããEOLããããã¥ã¡ã³ããªããŠæ®ãããªãããã£ãŠè©±ã
移è¡åã®æºå
ä»åã¯VPSã®OSåã€ã³ã¹ããŒã«ãšããããšã§ãæãŸãããªãã®ã§ããæ¢åã®ãµãŒããŒèªäœãæ¶ãé£ãã§ããŸããŸããå¥ã§VPSãç«ãŠãŠç§»è¡ããã®ãçæ³ã§ããäœäºç®ãªã®ã§ãããåŸãŸãããããã§ããå¿ãããããšãããæ»ããªãã®ã§æ éã«ã
æ²ããè£äºæ
移è¡åã®OSãªãã§ããCentOS Stream8çKUSANAGI9ã䜿çšããŠãŸããããããåãKUSANAGIãªã®ã§å®ã¯kusanagi migrateã³ãã³ãã䜿ãããã§ããããã䜿ãã°ç°¡åã«ç§»è¡ãåºæ¥ãâŠãã®ã¯ãã§ããã
ç°¡åã«èšããšãå¶ç¶ãã®ããŒãžã§ã³ã«éã£ãŠkusanagi migrateã³ãã³ããå®è¡ã§ããªãã£ããã§ããããããšã¯ç¥ãããäœãç°å¢ã«å¯ŸããŠè¡ã£ãã«ã¹ã¿ãã€ãºãæªãã³ãã³ãã䜿ããªããªã£ããšæã蟌ãã ç§ã¯ãã¹ãŠãæåã§ç§»è¡ããããã§ããã¢ããããŒããé åžããããããã°ã§ãã£ãããšãç¥ã£ãæã«ã¯ãã¹ãŠã®äœæ¥ãå®äºããŠãããŸããã
ããã¥ã¡ã³ãã«ãŒãã®ããã¯ã¢ãã
KUSANAGI9ã®ããã¥ã¡ã³ãã«ãŒãã¯/home/kusanagi/<profile>/DocumentRootã§ãã®ã§ããããã®ãŸãŸzipã¢ãŒã«ã€ãã«ããŠããŠã³ããŒãããŠãããŸããã
ãããWordPressç°å¢ãªããã¯ããã¥ã¡ã³ãã«ãŒãå€ã«ããã¯ã¢ãããã¹ããã¡ã€ã«ããã£ããããŸãããïŒå¿ããªãã§ãã
ããŒã¿ããŒã¹ã®ããã¯ã¢ãã
“2.6.1. mariadb-dump ã䜿çšããè«çããã¯ã¢ããã®å®è¡”ã«åãWordPressã®ããŒã¿ããŒã¹ã.sqlãã¡ã€ã«ã«ããã¯ã¢ããããŸããã
mariadb-dump --databases tellaresdo > tellaresdo.sql
ãã®ä»ã®ããã¯ã¢ãããªã©
ããŒã¿ãšããŠããã¯ã¢ããããã®ã¯ãã®çšåºŠã§ãããå人çã«ã«ã¹ã¿ãã€ãºããèšå®ãããŒãã·ã§ã³çãã¡ã¢ããŠãããæ¹ãããã§ããKUSANAGI9ã®WAFã䜿ã人ãªã©ã¯ããã£ãŠããšã¯æããŸããnaxsiã®ãã°çãå¿ããã«ã
VPSã®OSãåã€ã³ã¹ããŒã«
OSãåã€ã³ã¹ããŒã«ããŸãããã以éåŒãè¿ããŸããã
äžèšKUSANAGI9ã®å ¬åŒããã¥ã¡ã³ãéãã«ãã£ãŠããã°âŠãšæžãã¯ãã ã£ããã§ãããã¡ãã®ããã¥ã¡ã³ãã¯CentOS Stream 8çã®æ å ±ã§ããCentOS Stream 9çã¯å€æŽç¹ãè¥å¹²ããã®ã§äžèšããããVPSã®CentOS Stream 9ã®ããã¥ã¡ã³ããšäœµããŠèªãã æ¹ãããã§ãã
ãããããããšããã ãšããã©ã«ããŠãŒã¶ãŒã¯rootã§ã¯ãªããªããŸããããªããªãrootãŠãŒã¶ãŒã¯ããã©ã«ãã§ç¡å¹åãããŠãããcentosãŠãŒã¶ãŒã«sudoersãä»äžãããŠããæ§æã«ãªããŸããrootã§å®è¡ããå¿ èŠãããã³ãã³ããcentosã§ãã°ã€ã³ããäžã§sudoã§ã³ãã³ããå®è¡ãã圢ã«ãªããŸãã
ãŸããSELinuxã«é¢ããŠã¯ããã©ã«ãã§Permissiveã§ãããã«ãŒãã«ãã©ã¡ãŒã¿ã§ç¡å¹åãããŠããŸãã
移è¡å ã®äœæ¥
ã¹ã¯ããé åã®äœæ
ã¡ã¢ãªã®å°ãªãVPSã§ã¯ãããããªããšdnfãåããŠãããªããã§ããç§ã®VPSã¯ã¡ã¢ãª1GBã®å®ããã©ã³ãªã®ã§dnfãéäžã§KilledãããŠããŸãããªãã§ã ããã£ãŠæã£ãããããå¿ããŠãŸããã
sudo dd if=/dev/zero of=/swapfile bs=1M count=4096 sudo chmod 600 /swapfile sudo mkswap /swapfile sudo swapon /swapfile echo "/swapfile none swap sw 0 0" | sudo tee -a /etc/fstab
ãªããKUSANAGI9ã®æšå¥šã¡ã¢ãªéã¯4GBãªã®ã§KUSANAGI9ã®å šåã¯çºæ®ã§ããªãç°å¢ã§ããCDNéãã®ã§ããŸãé¢ä¿ãªãã®ã§ããã
IPv6ã®æå¹å
ãããVPSã§ã¯IPv6ãããã©ã«ãç¡å¹ãªã®ã§æå¹åããŸããå ¬åŒããã¥ã¡ã³ãéãããã®ãäžçªããã§ãããã
cloudflaredã®ã€ã³ã¹ããŒã«ãšèšå®
ããŸããã®èŸºã®æ§æã«èšåãããããšã»ãã¥ãªãã£ãªã¹ã¯ã®é瀺ã«ç¹ããã®ã§ãµã¯ããšæµããŸããCloudflare packagesã«åã£ãŠcloudflaredãã€ã³ã¹ããŒã«ããŸããããã€ãåŸã«å€§åé¡ãèµ·ãããŸãã
Cloudflare Zero Trustã®æ¹ã ãšrpmãããŠã³ããŒãããŠã®ã€ã³ã¹ããŒã«ãæ¡å ãããŸããå人çã«ã¯ãã®æ¹æ³ã䟿å©ã§ãã
ããšãããã£ãšæµãã€ãã§ã«ããã人ã«ã ãããã話ãããã§NetworkManagerã§ã«ãŒãããã¯ã¢ãã¬ã¹ãè¿œå ããããã«ãããŒæ¥ç¶ãäœæããŸããäœã®çºã§ããããïŒããããã172.16.0.2ã¯WARPèªèº«ã«äœ¿çšãããŠãŠäœ¿ããªããããã§ãããããŸãåããªãã£ããå€ããŠã¿ãŠãã ãããããã§ãã£ãŠããæ¹æ³ã§æ¥ç¶ã確èªåºæ¥ããfirewalldã®å šããŒããéããŸãã
ãã®èŸºã¯ãŸããã»ãã®æ©äŒã«ã¡ãã£ãšã ã玹ä»åºæ¥ãããšæã£ãŠãŸãã
sudo nmcli connection add type dummy ifname dummy0 ipv4.method manual ipv4.addresses 172.16.xxx.xxx/xx ipv6.method disabled
SELinuxã®èšå® [è©°ã¿ããäºæ¡]
VPSå¢ïŒïŒïŒGRUB_TIMEOUTã¯çµ¶å¯Ÿé·ãã«å»¶ã°ããŠããïŒïŒïŒ
ããããããããŸã§ã¯SELinuxã«é»ãŸããŠèµ·åãå®äºåºæ¥ãªããªãå¯èœæ§ããããšæã£ãŠãªãã£ãã
SElinuxãenforcingã«ããŠãrebootããŠããgetenforceãããäœæ ããŸã Disabledã ã£ããã§ãããããã§å è¿°ã®ã«ãŒãã«ãã©ã¡ãŒã¿ã®å€ã«æ°ä»ãããã®ãŸãŸã«ãŒãã«ãã©ã¡ãŒã¿ãselinux=1ã«ããŠrebootããŸããã
èµ·åããªããªããŸãã
rebootåŸãã€ãŸã§çµã£ãŠãsshã§å ¥ããªãã®ã§VPS管çç»é¢ããVNCã³ã³ãœãŒã«ãèŠããcloudflaredãšsshdãSELinuxã«é»ãŸããŠèµ·åã«ãŒãã«çªå ¥ããŠãŸããããããããã
ãã®ç¶æ ããSELinuxãäžæŠç¡å¹åããã«ã¯grub2ã®åŸ æ©ç»é¢ããã«ãŒãã«ãã©ã¡ãŒã¿ãèµ·ååã«å€æŽãããããããŸããããã®åŸ æ©æéã§ããGRUB_TIMEOUTããã©ã«ãå€ã¯5ã5ç§ãããããŸããã
VPS管çç»é¢ãã匷å¶åèµ·åããããŠ5ç§ä»¥å ã«VNCã³ã³ãœãŒã«ãéããŠEããŒãæŒãå¿ èŠããããŸãã匷å¶åèµ·åããããŠããVNCã³ã³ãœãŒã«ã䜿çšå¯èœã«ãªããŸã§ã©ã°ãããããšãèãããšã»ãŒäžå¯èœã§ããâŠãã¡ããšã§äœåºŠãè©Šããçµæå¥è·¡çã«ã§ããŸãããæ¬åœã«è©°ãã ãšæãããŸãOSåã€ã³ã¹ããŒã«ããããçŽããâŠããšé ãæ±ããŠãããšããã§ããã
ããŸãPermissiveã§AVCãšã©ãŒåããªããèŠããïŒãã£ãŠèšãããŠããã®éãã§ãããªãã®ã§ãããããã§ãEnforcingã«ãããšãã«ç¢ºå®ã«èµ·åããä¿èšŒã¯ãªããšããããšãããã§ç¥ããŸãããæ¹ããŠèšããŸãã
VPSå¢ïŒïŒïŒGRUB_TIMEOUTã¯çµ¶å¯Ÿé·ãã«å»¶ã°ããŠããïŒïŒïŒ
ãããªããã§ãã®èŸºãåèã«ããŠGRUB_TIMEOUTãé·ãããŠãããŸããã
sudo vi /etc/default/grub sudo grub2-mkconfig -o /boot/grub2/grub.cfg
ãã¡ãããã®ãŸãŸåèµ·åãããäžæçã«å€æŽããã«ãŒãã«ãã©ã¡ãŒã¿ã¯æ»ã£ãŠããŸãã®ã§ããã®åã«åèµ·åã«ãŒãæã«è¡šç€ºãããŠããAVCãšã©ãŒããSELinuxããªã·ãŒãäœã£ãŠé©çšããŠãããŸããã
ã¡ãªã¿ã«ç§ã¯SELinuxåå¿è ãªã®ã§åºæ¬çã«ããªã·ãŒãäœããšãã¯auditãã°ãaudit2allowã«æããŠçæããã.teãã¡ã€ã«ãåèã«äœããŸããOSåã€ã³ã¹ããŒã«åã¯.teãã¡ã€ã«ãèªãŸãã«èšãããããŸãŸsemanageã§é©çšããŠããããã®æããã¯æé·ããŠãŸããå€åã
KUSANAGIã®èšå®
åºæ¬çã«äžèšå ¬åŒããã¥ã¡ã³ãã®èšãéãã«ããŸãããããããŠèšããªãinitãšprovisionãªã©ã¯ã«ãŒãæš©éãå¿ èŠã§ãããŸããéçšã®æ¹åæ§ã«ãã£ãŠã¯initã§äœæãããkusanagiã¢ã«ãŠã³ããsudoersã«è¿œå ããæ¹ãããå ŽåããããŸãã
ããã¥ã¡ã³ãã«ãŒãã®åŸ©å
ããã¯ã¢ããããŠããzipã¢ãŒã«ã€ããã¢ããããŒãããŠæ°ããããã¥ã¡ã³ãã«ãŒãã«å±éããŸãããå±éåŸã®ãã¡ã€ã«ããã£ã¬ã¯ããªã®ããŒããã·ã§ã³ãæ£ãããèŠãŠãããæ¹ãããã§ãã
ããšãKUSANAGIã§ã¯ããã¥ã¡ã³ãã«ãŒããéåžžãšç°ãªãå Žæã«ããé¢ä¿ã§ãã£ã¬ã¯ããªã®ã¿ã€ããWebãµãŒããŒã«ããã¹ãã¿ã€ãã«ãªã£ãŠããŸããããã®ãŸãŸã ãšã¢ã¯ã»ã¹ã§ããªãã®ã§httpd_sys_content_tãŸãã¯httpd_sys_rw_content_tã«å€æŽããŠãããŸããããWordPressã¯æŽæ°çã§æžãæããçºçããã®ã§httpd_sys_rw_content_tã®ã»ããããã§ãããã®åé²åŸ¡åã¯å£ããŸãã
ããŒã¿ããŒã¹ã®åŸ©å
ããŒã¿ããŒã¹ã®åŸ©å ã¯ç°¡åã§ããããã ãwp-config.phpãæ©èœããåã«ãã£ãŠãããªããšèªåã§äœãããDBãšè¡çªããããªâŠãªããŠâŠ
mariadb < tellaresdo.sql
cronã®èšå®
DISABLE_WP_CRONç°å¢ãªã®ã§èšå®ããå¿ èŠããããŸããã
(crontab -l; echo "* * * * * /opt/kusanagi/php/bin/php -q /home/kusanagi/tellaresdo/DocumentRoot/wp-cron.php >/dev/null") | crontab -
ãã®ä»ã®åŸ©å
ãã®ä»ã«ã¹ã¿ãã€ãºã现ã ããèšå®ãå¿ èŠæ§ã®ç²Ÿæ»ãå«ã確èªãã€ã€åŸ©å ããŠãããŸãã
WordPressç°å¢ã§å¿ããã¡ãªäºãšããã°ãSMTPãµãŒããŒã䜿ããã©ã°ã€ã³çå°å ¥ããŠãªããã°WordPressãã¡ãŒã«ãéãæçšã«opendkimçã§DKIMã®èšå®ããã£ãŠãŸãããïŒãããã£ãèšå®ããå¿ããªãããã
è«žã 確èªãããå®äºã§ãã
ãŸãšã
ããŸããŸãã°ããããŒãžã§ã³ã«ã¶ã¡åœãã£ãŠèŠããªãäœæ¥ããã矜ç®ã«ãªã£ããSELinuxãšå€§ä¹±éãç¹°ãåºãããããäžæ¹ã§ãæ®éã®LinuxãµãŒããŒã§ã¯ãããã¡ãªnginxã®confãæžããšãããããããšã¯ã»ãšãã©ããã«èšå®ãå®äºã§ããŸããããããKUSANAGIãµãŒããŒã®å©ç¹ã ãšæããŸãã
移è¡ã®èšäºã§ããåŒã£æãããã¡ãªãã€ã³ãããŸãšããã®ã§æ°èŠæ§ç¯ã®éãåèçšåºŠã«ã¯ãªãããšæããŸããã¿ããªãKUSANAGI9ã䜿ããç°å¢ãªã䜿ã£ãŠã¿ãŠãïŒ
ãã次ã®ç§»è¡ããããšãããkusanagi migrateã³ãã³ãããã¡ããšäœ¿ãããšãããªãïŒ