From db443673d210a782b720b4a573729f9d605028ef Mon Sep 17 00:00:00 2001 From: "nepomuk.gail" Date: Mon, 14 Sep 2026 09:39:47 +0000 Subject: [PATCH] install.sh build-b92cb45 --- install.sh | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/install.sh b/install.sh index 6886b9e..2ba4bf6 100644 --- a/install.sh +++ b/install.sh @@ -533,6 +533,20 @@ if [[ -f "$INSTALL_DIR/deploy/hapx-ui-netcfg.sudoers" ]]; then fi fi +# Speicher- und Protokollvorgaben. Die Voreinstellungen einer frischen +# Ubuntu/Debian-Installation sind fuer einen Reverse Proxy falsch gewaehlt: +# vm.swappiness 60 schiebt den Arbeitsspeicher von HAProxy auf die Platte, +# sobald der Dateizwischenspeicher waechst, und das Journal hat keinen Deckel, +# obwohl auf einem Proxy fast jeder Eintrag eine HAProxy-Anfragezeile ist, die +# ohnehin in /var/log/haproxy.log landet. Nur setzen, wenn noch nichts da ist. +if [[ -x /usr/local/sbin/hapx-ui-netcfg && ! -f /etc/sysctl.d/90-hapx-haproxy.conf ]]; then + if /usr/local/sbin/hapx-ui-netcfg tune apply >/dev/null 2>&1; then + success "Kernvorgaben: BBR + fq, groessere Puffer, vm.swappiness=10, Journal auf 500M gedeckelt" + else + warn "Speicher-/Protokollvorgaben konnten nicht gesetzt werden" + fi +fi + # ── Step 5d: certexport system user (SSH cert-export feature) ──────────────── # Idempotent — runs on both fresh install and --update. Creates the unprivileged # certexport system user, the directory layout, the sshd Match block, and the