Compare commits
10
Commits
build-926b320
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6f7b557366 | ||
|
|
015ceed423 | ||
|
|
127536e962 | ||
|
|
49615527d3 | ||
|
|
234af182f5 | ||
|
|
518d79ec3e | ||
|
|
db443673d2 | ||
|
|
52aa278610 | ||
|
|
b48663aad0 | ||
|
|
de59c9281c |
+14
@@ -533,6 +533,20 @@ if [[ -f "$INSTALL_DIR/deploy/hapx-ui-netcfg.sudoers" ]]; then
|
|||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Speicher- und Protokollvorgaben. Die Voreinstellungen einer frischen
|
||||||
|
# Ubuntu/Debian-Installation sind fuer einen Reverse Proxy falsch gewaehlt:
|
||||||
|
# vm.swappiness 60 schiebt den Arbeitsspeicher von HAProxy auf die Platte,
|
||||||
|
# sobald der Dateizwischenspeicher waechst, und das Journal hat keinen Deckel,
|
||||||
|
# obwohl auf einem Proxy fast jeder Eintrag eine HAProxy-Anfragezeile ist, die
|
||||||
|
# ohnehin in /var/log/haproxy.log landet. Nur setzen, wenn noch nichts da ist.
|
||||||
|
if [[ -x /usr/local/sbin/hapx-ui-netcfg && ! -f /etc/sysctl.d/90-hapx-haproxy.conf ]]; then
|
||||||
|
if /usr/local/sbin/hapx-ui-netcfg tune apply >/dev/null 2>&1; then
|
||||||
|
success "Kernvorgaben: BBR + fq, groessere Puffer, vm.swappiness=10, Journal auf 500M gedeckelt"
|
||||||
|
else
|
||||||
|
warn "Speicher-/Protokollvorgaben konnten nicht gesetzt werden"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
# ── Step 5d: certexport system user (SSH cert-export feature) ────────────────
|
# ── Step 5d: certexport system user (SSH cert-export feature) ────────────────
|
||||||
# Idempotent — runs on both fresh install and --update. Creates the unprivileged
|
# Idempotent — runs on both fresh install and --update. Creates the unprivileged
|
||||||
# certexport system user, the directory layout, the sshd Match block, and the
|
# certexport system user, the directory layout, the sshd Match block, and the
|
||||||
|
|||||||
Reference in New Issue
Block a user