8 Commits
Author SHA1 Message Date
nepomuk.gail 6f7b557366 install.sh build-a152b71 2026-09-22 15:41:48 +00:00
nepomuk.gail 015ceed423 install.sh build-4d823a6 2026-09-22 15:21:18 +00:00
nepomuk.gail 127536e962 install.sh build-d2eb190 2026-09-22 14:57:30 +00:00
nepomuk.gail 49615527d3 install.sh build-fee857b 2026-09-17 15:08:22 +00:00
nepomuk.gail 234af182f5 install.sh build-f91082f 2026-09-14 12:54:26 +00:00
nepomuk.gail 518d79ec3e install.sh build-7b107ef 2026-09-14 10:37:37 +00:00
nepomuk.gail db443673d2 install.sh build-b92cb45 2026-09-14 09:39:47 +00:00
nepomuk.gail 52aa278610 install.sh build-0e6b324 2026-09-11 15:00:53 +00:00
+14
View File
@@ -533,6 +533,20 @@ if [[ -f "$INSTALL_DIR/deploy/hapx-ui-netcfg.sudoers" ]]; then
fi
fi
# Speicher- und Protokollvorgaben. Die Voreinstellungen einer frischen
# Ubuntu/Debian-Installation sind fuer einen Reverse Proxy falsch gewaehlt:
# vm.swappiness 60 schiebt den Arbeitsspeicher von HAProxy auf die Platte,
# sobald der Dateizwischenspeicher waechst, und das Journal hat keinen Deckel,
# obwohl auf einem Proxy fast jeder Eintrag eine HAProxy-Anfragezeile ist, die
# ohnehin in /var/log/haproxy.log landet. Nur setzen, wenn noch nichts da ist.
if [[ -x /usr/local/sbin/hapx-ui-netcfg && ! -f /etc/sysctl.d/90-hapx-haproxy.conf ]]; then
if /usr/local/sbin/hapx-ui-netcfg tune apply >/dev/null 2>&1; then
success "Kernvorgaben: BBR + fq, groessere Puffer, vm.swappiness=10, Journal auf 500M gedeckelt"
else
warn "Speicher-/Protokollvorgaben konnten nicht gesetzt werden"
fi
fi
# ── Step 5d: certexport system user (SSH cert-export feature) ────────────────
# Idempotent — runs on both fresh install and --update. Creates the unprivileged
# certexport system user, the directory layout, the sshd Match block, and the