浙江建设工程信息网站,宁波seo外包优化公司,自己做公众号和小说网站推广,西安房产网官网文章目录 1.配置系统以使用默认存储库1.调试selinux2.创建用户账户3.配置cron4. 创建写作目录5. 配置NTP6.配置autofs配置文件权限容器解法1.修改journal配置文件2.重启服务3.拷贝文件到指定目录4.修改拥有人所属组5.修改umask6.切换elovodo用户7.登录容器仓库8.拉取镜像9.运行… 文章目录 1.配置系统以使用默认存储库1.调试selinux2.创建用户账户3.配置cron4. 创建写作目录5. 配置NTP6.配置autofs配置文件权限容器解法1.修改journal配置文件2.重启服务3.拷贝文件到指定目录4.修改拥有人所属组5.修改umask6.切换elovodo用户7.登录容器仓库8.拉取镜像9.运行容器10.创建普通用户的systemd服务器配置文件目录11.使用podman命令自动生成podman容器服务文件12. 将容器服务文件的名字改成题目上要求的名字13.停止容器删除容器14.开启普通用户使用systemd管理自己服务的权限15.设置容器服务器下次开机启动16.查看状态17.执行命令 1.配置系统以使用默认存储库
[baseos]
name baseos
baseurl http://repo.domain10.example.com/rhel80/BaseOS
enable yes
gpgcheck 0[appstream]
name appstream
baseurl http://repo.domain10.example.com/rhel80/AppStream
enable yes
gpgcheck 01.调试selinux
[rootsystem1 ~]# setenforce 1
[rootsystem1 ~]# yum provides semanage
Updating Subscription Management repositories.
Unable to read consumer identity
This system is not registered to Red Hat Subscription Management. You can use subscription-manager to register.
Last metadata expiration check: 0:03:32 ago on Wed 18 Oct 2023 08:03:49 PM CST.
policycoreutils-python-utils-2.9-9.el8.noarch : SELinux policy core python utilities
Repo : System
Matched from:
Filename : /usr/sbin/semanagepolicycoreutils-python-utils-2.8-16.1.el8.noarch : SELinux policy core python utilities
Repo : baseos
Matched from:
Filename : /usr/sbin/semanage[rootsystem1 ~]# yum -y install policycoreutils-python-utils
Updating Subscription Management repositories.
Unable to read consumer identity
This system is not registered to Red Hat Subscription Management. You can use subscription-manager to register.
appstream 408 kB/s | 3.2 kB 00:00
baseos 410 kB/s | 2.7 kB 00:00
Package policycoreutils-python-utils-2.9-9.el8.noarch is already installed.
Dependencies resolved.
Nothing to do.
Complete!
[rootsystem1 ~]# semanage fcontext -a -t httpd_sys_content_t /var/www/html(/.*)?
[rootsystem1 ~]# restorecon -RvF /var/www/html
Relabeled /var/www/html/index.html from unconfined_u:object_r:httpd_sys_content_t:s0 to system_u:object_r:httpd_sys_content_t:s0
[rootsystem1 ~]# [rootsystem1 ~]# semanage port -a -t http_port_t -p tcp 82
[rootsystem1 ~]# semanage port -l | grep http
http_cache_port_t tcp 8080, 8118, 8123, 10001-10010
http_cache_port_t udp 3130
http_port_t tcp 82, 80, 81, 443, 488, 8008, 8009, 8443, 9000
pegasus_http_port_t tcp 5988
pegasus_https_port_t tcp 5989[rootsystem1 ~]# curl localhost:82
第二题的web页面
[rootsystem1 ~]# firewall-cmd --add-port82/tcp --per
success
[rootsystem1 ~]# firewall-cmd --reload
success
[rootsystem1 ~]#sh-4.4# ssh root172.24.10.201
Last login: Fri Apr 24 00:26:32 2020 from 172.24.10.100
[rootsystem2 ~]# curl 172.24.10.150:82
第二题的web页面
[rootsystem2 ~]#
2.创建用户账户
[rootsystem1 ~]# groupadd sysmgrs -g 30000
[rootsystem1 ~]# useradd -G sysmgrs natasha
[rootsystem1 ~]# useradd -G sysmgrs harry
[rootsystem1 ~]# useradd sarah -s /sbin/nologin
[rootsystem1 ~]# echo 123 | passwd --stdin natasha
Changing password for user natasha.
passwd: all authentication tokens updated successfully.
[rootsystem1 ~]# echo 123 | passwd --stdin harry
Changing password for user harry.
passwd: all authentication tokens updated successfully.
[rootsystem1 ~]# echo 123 | passwd --stdin sarah
Changing password for user sarah.
passwd: all authentication tokens updated successfully.
[rootsystem1 ~]# 3.配置cron
crontab -e -u natasha*/5 * * * * logger EX200 in progress
23 14 * * * /bin/echo enjia[rootsystem1 ~]# crontab -l -u natasha
*/5 * * * * logger EX200 in progress
23 14 * * * /bin/echo enjia
[rootsystem1 ~]# [rootsystem1 ~]# systemctl is-enabled crond
enabled
[rootsystem1 ~]# systemctl is-active crond
active
[rootsystem1 ~]# 4. 创建写作目录
[rootsystem1 ~]# mkdir /home/managers
[rootsystem1 ~]# chgrp sysmgrs /home/managers
[rootsystem1 ~]# chmod grwx,o--- /home/managers
[rootsystem1 ~]# chmod gs /home/managers
[rootsystem1 ~]# ll -ld /home/managers
drwxrws---. 2 root sysmgrs 6 Oct 18 20:26 /home/managers
[rootsystem1 ~]#
5. 配置NTP
vim /etc/chrony.conf
server host.domain10.example.com iburst:WQ[rootsystem1 ~]# systemctl enable chronyd --now
[rootsystem1 ~]# systemctl restart chronyd
[rootsystem1 ~]# chronyc sources
210 Number of sources 0
MS Name/IP address Stratum Poll Reach LastRx Last sample [rootsystem1 ~]# chronyc -n sources
210 Number of sources 1
MS Name/IP address Stratum Poll Reach LastRx Last sample ^? 172.24.10.100 0 6 0 - 0ns[ 0ns] /- 0ns
[rootsystem1 ~]# 6.配置autofs
yum -y install autofs nfs-utils/rhel /etc/auto.user1
vim /etc/auto.master
/rhel /etc/auto.user1vim /etc/auto.user1
user1 -rw host.domain10.example.com:/rhel/user1[rootsystem1 ~]# systemctl restart autofs [rootsystem1 ~]# systemctl enable autofs Created symlink /etc/systemd/system/multi-user.target.wants/autofs.service \u2192 /usr/lib/systemd/system/autofs.service. [rootsystem1 ~]#
[rootsystem1 ~]# df -Th /rhel/user1
Filesystem Type Size Used Avail Use% Mounted on
host.domain10.example.com:/rhel/user1 nfs4 100G 19G 81G 19% /rhel/user1
[rootsystem1 ~]#配置文件权限
[rootsystem1 ~]# cp /etc/fstab /var/tmp/fstab
[rootsystem1 ~]# chown root:root /var/tmp/fstab
[rootsystem1 ~]# chmod a-x /var/tmp/fstab
[rootsystem1 ~]# setfacl -m u:natasha:rw /var/tmp/fstab
[rootsystem1 ~]# setfacl -m u:harry:--- /var/tmp/fstab
[rootsystem1 ~]# chmod or-- /var/tmp/fstab
[rootsystem1 ~]# ll -ld /var/tmp/fstab
-rw-rw-r-- 1 root root 666 Oct 18 20:54 /var/tmp/fstab
[rootsystem1 ~]#
容器解法
1.修改journal配置文件
以root身份进行
[rootsystem1 ~]# vim /etc/systemd/journald.confStoragepersistent2.重启服务
[rootsystem1 ~]# systemctl restart systemd-journald3.拷贝文件到指定目录
考试题要求将/var/log/journal目录及任何子目录下的任何.journal复制到/home/elovodo/container_journal (切记这是以root身份拷贝的)
find /var/log/journal/ -name *.journal -exec cp -a {} /home/elovodo/container_journal/ \;4.修改拥有人所属组
chown -R elovodo:elovodo /home/elovodo/container_journal/5.修改umask
vim /home/elovodo/.bashrc6.切换elovodo用户
这个时候才进入主题切换为elovodo用户哦
ssh elovodolocalhost7.登录容器仓库
[elovodosystem1 ~]$ podman login utility.example.com:5000
Username: gls
Password:
Login Succeeded!
[elovodosystem1 ~]$ 8.拉取镜像
如果题目没给到具体网址就search来搜索一下 podman search rlogserver
podman pull utility.example.com:5000/rlogserver9.运行容器
podman run -itd -v /home/elovodo/container_journal/:/var/log/journal/:z --name container_logserver utility.example.com:5000/rlogserver10.创建普通用户的systemd服务器配置文件目录
[elovodosystem1 ~]$ mkdir ~/.config/systemd/user -p
[elovodosystem1 ~]$ cd ~/.config/systemd/user/
[elovodosystem1 user]$
11.使用podman命令自动生成podman容器服务文件
[elovodosystem1 user]$ podman generate systemd --new --files --name container_logserver
/home/elovodo/.config/systemd/user/container-container_logserver.service
[elovodosystem1 user]$
12. 将容器服务文件的名字改成题目上要求的名字
[elovodosystem1 user]$ mv container-container_logserver.service container_logserver.service
[elovodosystem1 user]$
13.停止容器删除容器
[elovodosystem1 user]$ podman stop container_logserver
91e4bb2fed1c77dade2461902ec7d20299f37778468aa18021b62e2cb17e4788
[elovodosystem1 user]$ podman rm container_logserver
91e4bb2fed1c77dade2461902ec7d20299f37778468aa18021b62e2cb17e4788
[elovodosystem1 user]$ 14.开启普通用户使用systemd管理自己服务的权限
[elovodosystem1 user]$ loginctl enable-linger
[elovodosystem1 user]$ systemctl --user daemon-reload
[elovodosystem1 user]$
15.设置容器服务器下次开机启动
[elovodosystem1 user]$ systemctl --user enable container_logserver --now
Created symlink /home/elovodo/.config/systemd/user/multi-user.target.wants/container_logserver.service \u2192 /home/elovodo/.config/systemd/user/container_logserver.service.
Created symlink /home/elovodo/.config/systemd/user/default.target.wants/container_logserver.service \u2192 /home/elovodo/.config/systemd/user/container_logserver.service.
[elovodosystem1 user]$
16.查看状态
systemctl --user status container_logserver17.执行命令
podman exec container_logserver ls 文章转载自: http://www.morning.lbqt.cn.gov.cn.lbqt.cn http://www.morning.rnpnn.cn.gov.cn.rnpnn.cn http://www.morning.skdrp.cn.gov.cn.skdrp.cn http://www.morning.hxgly.cn.gov.cn.hxgly.cn http://www.morning.ddxjr.cn.gov.cn.ddxjr.cn http://www.morning.knlbg.cn.gov.cn.knlbg.cn http://www.morning.yzzfl.cn.gov.cn.yzzfl.cn http://www.morning.jcwt.cn.gov.cn.jcwt.cn http://www.morning.rmxk.cn.gov.cn.rmxk.cn http://www.morning.mbprq.cn.gov.cn.mbprq.cn http://www.morning.jkrrg.cn.gov.cn.jkrrg.cn http://www.morning.lpsjs.com.gov.cn.lpsjs.com http://www.morning.xhpnp.cn.gov.cn.xhpnp.cn http://www.morning.nfks.cn.gov.cn.nfks.cn http://www.morning.supera.com.cn.gov.cn.supera.com.cn http://www.morning.nlgyq.cn.gov.cn.nlgyq.cn http://www.morning.xhgxd.cn.gov.cn.xhgxd.cn http://www.morning.kdxzy.cn.gov.cn.kdxzy.cn http://www.morning.dztp.cn.gov.cn.dztp.cn http://www.morning.fykqh.cn.gov.cn.fykqh.cn http://www.morning.nlywq.cn.gov.cn.nlywq.cn http://www.morning.gjfym.cn.gov.cn.gjfym.cn http://www.morning.svrud.cn.gov.cn.svrud.cn http://www.morning.rgmls.cn.gov.cn.rgmls.cn http://www.morning.rppf.cn.gov.cn.rppf.cn http://www.morning.bkppb.cn.gov.cn.bkppb.cn http://www.morning.xprq.cn.gov.cn.xprq.cn http://www.morning.gtbjc.cn.gov.cn.gtbjc.cn http://www.morning.qbfkz.cn.gov.cn.qbfkz.cn http://www.morning.hbnwr.cn.gov.cn.hbnwr.cn http://www.morning.jyfrz.cn.gov.cn.jyfrz.cn http://www.morning.mbqyl.cn.gov.cn.mbqyl.cn http://www.morning.khfk.cn.gov.cn.khfk.cn http://www.morning.swbhq.cn.gov.cn.swbhq.cn http://www.morning.lhygbh.com.gov.cn.lhygbh.com http://www.morning.kflzy.cn.gov.cn.kflzy.cn http://www.morning.qpnmd.cn.gov.cn.qpnmd.cn http://www.morning.tnyanzou.com.gov.cn.tnyanzou.com http://www.morning.pkwwq.cn.gov.cn.pkwwq.cn http://www.morning.lwzgn.cn.gov.cn.lwzgn.cn http://www.morning.kdxzy.cn.gov.cn.kdxzy.cn http://www.morning.ychrn.cn.gov.cn.ychrn.cn http://www.morning.xwbwm.cn.gov.cn.xwbwm.cn http://www.morning.pthmn.cn.gov.cn.pthmn.cn http://www.morning.ailvturv.com.gov.cn.ailvturv.com http://www.morning.thjqk.cn.gov.cn.thjqk.cn http://www.morning.jtmql.cn.gov.cn.jtmql.cn http://www.morning.dfffm.cn.gov.cn.dfffm.cn http://www.morning.wflsk.cn.gov.cn.wflsk.cn http://www.morning.uytae.cn.gov.cn.uytae.cn http://www.morning.wrtbx.cn.gov.cn.wrtbx.cn http://www.morning.nfks.cn.gov.cn.nfks.cn http://www.morning.chjnb.cn.gov.cn.chjnb.cn http://www.morning.pfntr.cn.gov.cn.pfntr.cn http://www.morning.knmby.cn.gov.cn.knmby.cn http://www.morning.rgkd.cn.gov.cn.rgkd.cn http://www.morning.tfpqd.cn.gov.cn.tfpqd.cn http://www.morning.gnfkl.cn.gov.cn.gnfkl.cn http://www.morning.ndpzm.cn.gov.cn.ndpzm.cn http://www.morning.fjptn.cn.gov.cn.fjptn.cn http://www.morning.sknbb.cn.gov.cn.sknbb.cn http://www.morning.mcwgn.cn.gov.cn.mcwgn.cn http://www.morning.wsxxq.cn.gov.cn.wsxxq.cn http://www.morning.sxmbk.cn.gov.cn.sxmbk.cn http://www.morning.mqzcn.cn.gov.cn.mqzcn.cn http://www.morning.hengqilan.cn.gov.cn.hengqilan.cn http://www.morning.qqhfc.cn.gov.cn.qqhfc.cn http://www.morning.rwzqn.cn.gov.cn.rwzqn.cn http://www.morning.qxkjy.cn.gov.cn.qxkjy.cn http://www.morning.klpwl.cn.gov.cn.klpwl.cn http://www.morning.rqmqr.cn.gov.cn.rqmqr.cn http://www.morning.nfbkz.cn.gov.cn.nfbkz.cn http://www.morning.bhmnp.cn.gov.cn.bhmnp.cn http://www.morning.dtgjt.cn.gov.cn.dtgjt.cn http://www.morning.prhfc.cn.gov.cn.prhfc.cn http://www.morning.bnqcm.cn.gov.cn.bnqcm.cn http://www.morning.fosfox.com.gov.cn.fosfox.com http://www.morning.tfrmx.cn.gov.cn.tfrmx.cn http://www.morning.nwwzc.cn.gov.cn.nwwzc.cn http://www.morning.kcypc.cn.gov.cn.kcypc.cn