AI 摘要
通过DD脚本重装阿里云ECS,配置虚拟内存与系统参数,并利用mihomo和nginx搭建带密码的HTTPS、HTTP、SOCKS5代理,涵盖acme.sh申请泛域名证书、Cloudflare DNS验证、proxyprotocol分流等关键步骤。

一、引子

手里有一个阿里云 99一年 2C2G的机器,一直在吃灰,最近想拿出来干点事,重置系统,进行初始化。

二、DD脚本

  1. 下载
1
curl -O https://cnb.cool/bin456789/reinstall/-/git/raw/main/reinstall.sh || wget -O ${_##*/} $_
  1. 执行
1
bash reinstall.sh rocky 9

可以设置用户名、密码.

  1. 重启
1
reboot

三、初始化

3.1 创建虚拟内存

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
# 1. 看看现状(Swap 那行如果是 0 就是没开)
free -h
df -h /

# 2. 创建 2G swap 文件
sudo fallocate -l 2G /swapfile
# 如果 fallocate 报错(某些老内核/文件系统),改用:
# sudo dd if=/dev/zero of=/swapfile bs=1M count=2048 status=progress

# 3. 权限必须是 600,否则 swapon 会警告甚至拒绝
sudo chmod 600 /swapfile

# 4. 格式化并启用
sudo mkswap /swapfile
sudo swapon /swapfile

# 5. 验证
free -h
swapon --show

# 6. 开机挂载
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

# 7. 调整内核参数
sudo tee -a /etc/sysctl.conf <<'EOF'
vm.swappiness=10
vm.vfs_cache_pressure=50
EOF
sudo sysctl -p

3.2 系统设置

参考

四、搭建代理

利用 mihomo 和 nginx,来搭建带密码的 https(带证书)、http、socks 5 代理。

4.1 安装 nginx

官方安装教程

  1. 安装依赖
1
sudo yum install yum-utils
  1. 编写 repo 源
1
vim /etc/yum.repos.d/nginx.repo
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
[nginx-stable]
name=nginx stable repo
baseurl=https://nginx.org/packages/centos/$releasever/$basearch/
gpgcheck=1
enabled=1
gpgkey=https://nginx.org/keys/nginx_signing.key
module_hotfixes=true

[nginx-mainline]
name=nginx mainline repo
baseurl=https://nginx.org/packages/mainline/centos/$releasever/$basearch/
gpgcheck=1
enabled=0
gpgkey=https://nginx.org/keys/nginx_signing.key
module_hotfixes=true
  1. 安装 nginx
1
sudo yum install nginx
  1. 开机自启
1
systemctl enable --now nginx
  1. 验证 stream 模块
1
nginx -V 2>&1 | grep -o with-stream

4.2 nginx 基础配置

优化一些配置

  1. 备份默认配置,创建必要的目录
1
2
3
mkdir -pv /etc/nginx/{stream.d,logs,http.d}
mv /etc/nginx/nginx.conf /etc/nginx/nginx.conf.bak
mv /etc/nginx/conf.d/default.conf /etc/nginx/conf.d/default.conf.bak
  1. 编写主配置文件
1
vim /etc/nginx/nginx.conf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
user  nginx;
worker_processes auto;

error_log logs/error.log warn;
pid /run/nginx.pid;

events {
worker_connections 1024;
}

# ===== 4层转发(TCP/UDP) =====
stream {
log_format basic '$remote_addr [$time_local] '
'$protocol $status $bytes_sent $bytes_received '
'$session_time';

access_log logs/stream-access.log basic;

include stream.d/*.conf;
}

# ===== 7层反代(HTTP/HTTPS) =====
http {
include mime.types;
default_type application/octet-stream;

log_format main '$remote_addr - $remote_user [$time_local] "$request" '
'$status $body_bytes_sent "$http_referer" '
'"$http_user_agent" "$http_x_forwarded_for"';

access_log logs/access.log main;

sendfile on;
tcp_nopush on;
tcp_nodelay on;
keepalive_timeout 65;
gzip on;

include http.d/*.conf;
}

4.3 证书

使用 acme.sh 来自动申请证书.

4.3.1 域名证书

  1. 克隆仓库
1
git clone https://github.com/acmesh-official/acme.sh
  1. 安装
1
2
cd acme.sh
./acme.sh --install -m admin@bravexist.cn
  1. 刷新配置
1
2
# alias yy="egrep -v '^[[:space:]]*$|^[[:space:]]*#'"
source ~/.bashrc
  1. 验证版本
1
acme.sh --version
  1. 切换 CA 机构
1
acme.sh --set-default-ca --server letsencrypt
  1. CF托管域名,直接使用dns解析来验证域名
  • 获取Token
    个人简介>>>配置文件>>>API令牌>>>创建令牌>>>编辑区域DNS>>>(为令牌设置名称、选域名、设置令牌过期时间)
1

  • 获取账户ID,Account ID
    点击任意域名,概述,右下角,账户ID
1

  1. 传入环境变量
1
2
export CF_Token="你的_Token_字符串"
export CF_Account_ID="你的_Account_ID"
  1. 签发泛域名证书,后续都使用同一张证书
1
acme.sh --issue --dns dns_cf -d *.bravexist.cn
  1. 安装证书
1
mkdir -p /etc/nginx/ssl/bravexist.cn
1
2
3
4
acme.sh --install-cert -d *.bravexist.cn --ecc \
--key-file /etc/nginx/ssl/bravexist.cn/server.key \
--fullchain-file /etc/nginx/ssl/bravexist.cn/server.pem \
--reloadcmd "systemctl reload nginx"
  1. 验证定时任务
1
crontab -l | grep acme.sh

4.3.2 ip证书

  1. 申请证书
1
2
3
4
5
acme.sh --issue -d {{server_ip}} \
--server letsencrypt \
--certificate-profile shortlived \
--days 5 \
--nginx
  1. 安装证书
1
2
3
4
acme.sh --install-cert -d {{server_ip}}   \
--key-file /etc/nginx/ssl/ip-cert.key \
--fullchain-file /etc/nginx/ssl/ip-cert.crt \
--reloadcmd "systemctl reload nginx"
  1. 默认配置
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
server {
listen 127.0.0.1:8443 ssl proxy_protocol;
server_name localhost;
ssl_certificate /etc/nginx/ssl/ip-cert.crt;
ssl_certificate_key /etc/nginx/ssl/ip-cert.key;
ssl_protocols TLSv1.2 TLSv1.3;
location / {
root /usr/share/nginx/html;
index index.html index.htm;
}
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root /usr/share/nginx/html;
}
}
  1. 验证
1
curl https://{{server_ip}}

4.4 nginx 上 ssl 相关的配置

  1. 创建文件夹
1
mkdir /etc/nginx/snippets
  1. ssl 公共的配置
1
vim /etc/nginx/snippets/ssl-common.conf
1
2
3
4
5
6
7
8
9
10
11
ssl_certificate     /etc/nginx/ssl/bravexist.cn/server.pem;
ssl_certificate_key /etc/nginx/ssl/bravexist.cn/server.key;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE+AESGCM:ECDHE+CHACHA20:DHE+AESGCM:!aNULL:!MD5:!3DES;
ssl_prefer_server_ciphers off;
ssl_session_cache shared:SSL:10m;
ssl_session_timeout 1d;
ssl_session_tickets off;
# proxy_protocol 模式下才需要打开
# set_real_ip_from 127.0.0.1;
# real_ip_header proxy_protocol;
  1. 7层反向代理公共配置
1
vim /etc/nginx/snippets/proxy-common.conf
1
2
3
4
5
6
7
8
9
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_buffering off;
proxy_read_timeout 3600;
  1. 自动跳转 https 的配置
1
vim /etc/nginx/http.d/_redirect.conf
1
2
3
4
5
server {
listen 80;
server_name *.bravexist.cn bravexist.cn;
return 301 https://$host$request_uri;
}
  1. 默认 7 层反代 配置
1
vim /etc/nginx/http.d/app.conf.template
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
server {
listen 443 ssl;
http2 on;
server_name app.bravexist.cn;

# proxy_protocol 模式下使用
# listen 127.0.0.1:8443 ssl proxy_protocol;
# server_name app.bravexist.cn;

include snippets/ssl-common.conf;

location / {
proxy_pass http://127.0.0.1:【需要覆盖端口号】;
include snippets/proxy-common.conf;
}
}

4.5 proxy_protocol(可选)

搭建 https 加密代理时需要用到. 在 4 层流量进来后,通过 域名分流。

1
vim /etc/nginx/stream.d/proxy-stream.conf
1
2
3
4
5
6
7
8
9
10
11
12
map $ssl_preread_server_name $backend {
proxy.bravexist.cn 127.0.0.1:7444;
default 127.0.0.1:8443;
}

server {
listen 443;
listen [::]:443;
ssl_preread on;
proxy_pass $backend;
proxy_protocol on;
}

4.5 启动代理

  1. 拉取秘密仓库
1
git clone git@github.com:xxxxxxxx/clash-box.git
  1. 部署
1
2
3
4
cd
cp .env.example .env
vim .env
docker compose up -d --build

4.5.1 http、socks 明文代理

  1. 添加反向代理
  • 面板:http://<你的IP>:7899 (账号见 PANEL_USER / PANEL_PASS)
  • 代理:http://<user>:<pass>@<你的IP>:7890,socks5 同端口
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
server {
# listen 443 ssl;
http2 on;
# server_name app.bravexist.cn;

# proxy_protocol 模式下使用
listen 127.0.0.1:8443 ssl proxy_protocol;
server_name dash.bravexist.cn;

include snippets/ssl-common.conf;

# 隐藏面板路径
location /abc/ {
proxy_pass http://127.0.0.1:7899/;
include snippets/proxy-common.conf;
}

location = /abc { return 301 /abc/; }
}

4.5.2 https 加密代理

  • 代理:http://<user>:<pass>@proxy.bravexist.cn:443