AI 摘要
通过DD脚本重装阿里云ECS,配置虚拟内存与系统参数,并利用mihomo和nginx搭建带密码的HTTPS、HTTP、SOCKS5代理,涵盖acme.sh申请泛域名证书、Cloudflare DNS验证、proxyprotocol分流等关键步骤。
一、引子
手里有一个阿里云 99一年 2C2G的机器,一直在吃灰,最近想拿出来干点事,重置系统,进行初始化。
二、DD脚本
- 下载
1
| curl -O https://cnb.cool/bin456789/reinstall/-/git/raw/main/reinstall.sh || wget -O ${_##*/} $_
|
- 执行
1
| bash reinstall.sh rocky 9
|
可以设置用户名、密码.
- 重启
三、初始化
3.1 创建虚拟内存
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
| free -h df -h /
sudo fallocate -l 2G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile sudo swapon /swapfile
free -h swapon --show
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
sudo tee -a /etc/sysctl.conf <<'EOF' vm.swappiness=10 vm.vfs_cache_pressure=50 EOF sudo sysctl -p
|
3.2 系统设置
参考
四、搭建代理
利用 mihomo 和 nginx,来搭建带密码的 https(带证书)、http、socks 5 代理。
4.1 安装 nginx
官方安装教程
- 安装依赖
1
| sudo yum install yum-utils
|
- 编写 repo 源
1
| vim /etc/yum.repos.d/nginx.repo
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
| [nginx-stable] name=nginx stable repo baseurl=https://nginx.org/packages/centos/$releasever/$basearch/ gpgcheck=1 enabled=1 gpgkey=https://nginx.org/keys/nginx_signing.key module_hotfixes=true
[nginx-mainline] name=nginx mainline repo baseurl=https://nginx.org/packages/mainline/centos/$releasever/$basearch/ gpgcheck=1 enabled=0 gpgkey=https://nginx.org/keys/nginx_signing.key module_hotfixes=true
|
- 安装 nginx
- 开机自启
1
| systemctl enable --now nginx
|
- 验证
stream 模块
1
| nginx -V 2>&1 | grep -o with-stream
|
4.2 nginx 基础配置
优化一些配置
- 备份默认配置,创建必要的目录
1 2 3
| mkdir -pv /etc/nginx/{stream.d,logs,http.d} mv /etc/nginx/nginx.conf /etc/nginx/nginx.conf.bak mv /etc/nginx/conf.d/default.conf /etc/nginx/conf.d/default.conf.bak
|
- 编写主配置文件
1
| vim /etc/nginx/nginx.conf
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40
| user nginx; worker_processes auto;
error_log logs/error.log warn; pid /run/nginx.pid;
events { worker_connections 1024; }
stream { log_format basic '$remote_addr [$time_local] ' '$protocol $status $bytes_sent $bytes_received ' '$session_time';
access_log logs/stream-access.log basic;
include stream.d/*.conf; }
http { include mime.types; default_type application/octet-stream;
log_format main '$remote_addr - $remote_user [$time_local] "$request" ' '$status $body_bytes_sent "$http_referer" ' '"$http_user_agent" "$http_x_forwarded_for"';
access_log logs/access.log main;
sendfile on; tcp_nopush on; tcp_nodelay on; keepalive_timeout 65; gzip on;
include http.d/*.conf; }
|
4.3 证书
使用 acme.sh 来自动申请证书.
4.3.1 域名证书
- 克隆仓库
1
| git clone https://github.com/acmesh-official/acme.sh
|
- 安装
1 2
| cd acme.sh ./acme.sh --install -m admin@bravexist.cn
|
- 刷新配置
- 验证版本
- 切换 CA 机构
1
| acme.sh --set-default-ca --server letsencrypt
|
- CF托管域名,直接使用dns解析来验证域名
- 获取Token
个人简介>>>配置文件>>>API令牌>>>创建令牌>>>编辑区域DNS>>>(为令牌设置名称、选域名、设置令牌过期时间)
- 获取账户ID,
Account ID
点击任意域名,概述,右下角,账户ID
- 传入环境变量
1 2
| export CF_Token="你的_Token_字符串" export CF_Account_ID="你的_Account_ID"
|
- 签发泛域名证书,后续都使用同一张证书
1
| acme.sh --issue --dns dns_cf -d *.bravexist.cn
|
- 安装证书
1
| mkdir -p /etc/nginx/ssl/bravexist.cn
|
1 2 3 4
| acme.sh --install-cert -d *.bravexist.cn --ecc \ --key-file /etc/nginx/ssl/bravexist.cn/server.key \ --fullchain-file /etc/nginx/ssl/bravexist.cn/server.pem \ --reloadcmd "systemctl reload nginx"
|
- 验证定时任务
1
| crontab -l | grep acme.sh
|
4.3.2 ip证书
- 申请证书
1 2 3 4 5
| acme.sh --issue -d {{server_ip}} \ --server letsencrypt \ --certificate-profile shortlived \ --days 5 \ --nginx
|
- 安装证书
1 2 3 4
| acme.sh --install-cert -d {{server_ip}} \ --key-file /etc/nginx/ssl/ip-cert.key \ --fullchain-file /etc/nginx/ssl/ip-cert.crt \ --reloadcmd "systemctl reload nginx"
|
- 默认配置
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
| server { listen 127.0.0.1:8443 ssl proxy_protocol; server_name localhost; ssl_certificate /etc/nginx/ssl/ip-cert.crt; ssl_certificate_key /etc/nginx/ssl/ip-cert.key; ssl_protocols TLSv1.2 TLSv1.3; location / { root /usr/share/nginx/html; index index.html index.htm; } error_page 500 502 503 504 /50x.html; location = /50x.html { root /usr/share/nginx/html; } }
|
- 验证
1
| curl https://{{server_ip}}
|
4.4 nginx 上 ssl 相关的配置
- 创建文件夹
1
| mkdir /etc/nginx/snippets
|
ssl 公共的配置
1
| vim /etc/nginx/snippets/ssl-common.conf
|
1 2 3 4 5 6 7 8 9 10 11
| ssl_certificate /etc/nginx/ssl/bravexist.cn/server.pem ssl_certificate_key /etc/nginx/ssl/bravexist.cn/server.key ssl_protocols TLSv1.2 TLSv1.3 ssl_ciphers ECDHE+AESGCM:ECDHE+CHACHA20:DHE+AESGCM:!aNULL:!MD5:!3DES ssl_prefer_server_ciphers off ssl_session_cache shared:SSL:10m ssl_session_timeout 1d ssl_session_tickets off
|
- 7层反向代理公共配置
1
| vim /etc/nginx/snippets/proxy-common.conf
|
1 2 3 4 5 6 7 8 9
| proxy_http_version 1.1 proxy_set_header Host $host proxy_set_header X-Real-IP $remote_addr proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for proxy_set_header X-Forwarded-Proto $scheme proxy_set_header Upgrade $http_upgrade proxy_set_header Connection "upgrade" proxy_buffering off proxy_read_timeout 3600
|
- 自动跳转 https 的配置
1
| vim /etc/nginx/http.d/_redirect.conf
|
1 2 3 4 5
| server { listen 80; server_name *.bravexist.cn bravexist.cn; return 301 https://$host$request_uri; }
|
- 默认 7 层反代 配置
1
| vim /etc/nginx/http.d/app.conf.template
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
| server { listen 443 ssl; http2 on; server_name app.bravexist.cn;
include snippets/ssl-common.conf;
location / { proxy_pass http://127.0.0.1:【需要覆盖端口号】; include snippets/proxy-common.conf; } }
|
4.5 proxy_protocol(可选)
搭建 https 加密代理时需要用到. 在 4 层流量进来后,通过 域名分流。
1
| vim /etc/nginx/stream.d/proxy-stream.conf
|
1 2 3 4 5 6 7 8 9 10 11 12
| map $ssl_preread_server_name $backend { proxy.bravexist.cn 127.0.0.1:7444; default 127.0.0.1:8443; }
server { listen 443; listen [::]:443; ssl_preread on; proxy_pass $backend; proxy_protocol on; }
|
4.5 启动代理
- 拉取秘密仓库
1
| git clone git@github.com:xxxxxxxx/clash-box.git
|
- 部署
1 2 3 4
| cd cp .env.example .env vim .env docker compose up -d --build
|
4.5.1 http、socks 明文代理
- 添加反向代理
- 面板:http://<你的IP>:7899 (账号见
PANEL_USER / PANEL_PASS)
- 代理:
http://<user>:<pass>@<你的IP>:7890,socks5 同端口
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20
| server { http2 on;
listen 127.0.0.1:8443 ssl proxy_protocol; server_name dash.bravexist.cn;
include snippets/ssl-common.conf;
location /abc/ { proxy_pass http://127.0.0.1:7899/; include snippets/proxy-common.conf; } location = /abc { return 301 /abc/; } }
|
4.5.2 https 加密代理
- 代理:
http://<user>:<pass>@proxy.bravexist.cn:443