Files
kumomta/docs/tutorial/system_preparation.md
T
Wez Furlong 1dd39c3043 docs: console-ify the tutorial section
It looks more conventional this way.
I switched a few sysadmin sections away from `sudo -s` to
non-privileged commands that use sudo; most of those were to
deal with `sudo echo > file` not being able to write to `file` as root.

Those are replaced by `echo | sudo tee file >/dev/null` which allows
running only the file writing part as root.
2023-03-14 20:26:03 -07:00

4.0 KiB

System Preparation

Doing the basics

Reguardless of what system you deploy, there are things you need to do to prepare the OS.

  • Update to the latest patches
  • Install basic testing and support tools
  • Turn off services that are wasteful or can interfere
  • Tune the use of memory and file access for best performance
  • Automate updates and startup for resilliency

Rocky Linux Example

Rocky Linux is very similar to CentOS, as is Alma and RHEL The instructions below are shown for a Rocky 8 system but with slight modification, should work for any DNF package management system. For Amazon Linux (AL2) the instructions are identical, but replace "dnf" with "yum".

# Do basic updates 
$ sudo dnf clean all
$ sudo dnf update -y

# Grab some handy tools
$ sudo dnf install -y chrony wget bind bind-utils telnet curl mlocate unzip sudo cronie

$ sudo systemctl enable chrony

# Slightly more optional handy tools for dev work
$ sudo dnf install -y make gcc firewalld sysstat

!!! note The following commands must be executed as the root user

Then run these:

# Make sure it all stays up to date
# Run a dnf update at 3AM daily
$ echo "0 3 * * * root /usr/bin/dnf update -y >/dev/null 2>&1" | sudo tee /etc/cron.d/dnf-updates >/dev/null

# Tune sysctl setings. Note that these are suggestions, 
#  you should tune according to your specific build

$ echo "
vm.max_map_count = 768000
net.core.rmem_default = 32768
net.core.wmem_default = 32768
net.core.rmem_max = 262144
net.core.wmem_max = 262144
fs.file-max = 250000
net.ipv4.ip_local_port_range = 5000 63000
net.ipv4.tcp_tw_reuse = 1
kernel.shmmax = 68719476736
net.core.somaxconn = 1024
vm.nr_hugepages = 20
kernel.shmmni = 4096
" | sudo tee -a /etc/sysctl.conf > /dev/null

$ sudo /sbin/sysctl -p /etc/sysctl.conf

Ubuntu Linux Example

The instructions below are shown for an Ubuntu 22 system but with slight modification, should work for any APT package management system.

# Do basic updates 
$ sudo apt-get -y update
$ sudo apt-get -y upgrade

# Grab some handy tools
$ sudo apt-get install -y chrony wget bind9 bind9-utils telnet curl mlocate unzip sudo cron

$ sudo systemctl enable chrony

# Slightly more optional handy tools for dev work
$ sudo apt-get install -y make gcc firewalld sysstat

!!! note The following commands must be executed as the root user


# Make sure it all stays up to date
# Run a dnf update at 3AM daily
$ sudo echo "0 3 * * * root /usr/bin/apt-get update -y >/dev/null 2>&1" | sudo tee /etc/cron.d/apt-get-updates >/dev/null
$ sudo echo "5 3 * * * root /usr/bin/apt-get upgrade -y >/dev/null 2>&1" | sudo tee -a /etc/cron.d/apt-get-updates >/dev/null

# Tune sysctl setings. Note that these are suggestions, you should tune according to your specific build

$ echo "
vm.max_map_count = 768000
net.core.rmem_default = 32768
net.core.wmem_default = 32768
net.core.rmem_max = 262144
net.core.wmem_max = 262144
fs.file-max = 250000
net.ipv4.ip_local_port_range = 5000 63000
net.ipv4.tcp_tw_reuse = 1
kernel.shmmax = 68719476736
net.core.somaxconn = 1024
vm.nr_hugepages = 20
kernel.shmmni = 4096
" | sudo tee -a /etc/sysctl.conf >/dev/null

$ sudo /sbin/sysctl -p /etc/sysctl.conf

OS Hardening

Above the basics of any system deloyment, you may also want to do some "hardening". This is the process of minimizing exposure to threats. This is not a comprehensive list, but are some of the common things you should do to protect your system.

  • Disabling unnecessary services like postfix and qpidd
$ sudo systemctl stop  postfix.service
$ sudo systemctl disable postfix.service
$ sudo systemctl stop  qpidd.service
$ sudo systemctl disable qpidd.service
  • Firewall
  • SSH config
  • Switch to keypair only

TBD

Beyond the basics of any system deloyment, you may also want to do some "hardening". This is the process of minimizing exposure to threats. This is not a comprehensive list, but are some of the common things you should do to protect your system.

  • Disabling unnecessary services
  • Firewall
  • SSH config
  • Switch to keypair only