2024年6月8日 星期六

Zabbix 7.0 LTS 版本試裝

 備妥 LAPP (Liunx Apache PostgreSQL PHP) 或

 LAMP (Liunx Apache MYSQL PHP) ....的運行環境

我的安裝順序 Liunx Apache Mysql (MariadDB) PHP ,

因為之前已測試過 LibreNMS 在 Oracle 9 的運行環境. 

故這次僅需加裝上PostgreSQL即可.在安裝之前先看了一下  release_notes 資訊,

進而得知它支援 TimescaleDB 2.13 與  PostgreSQL 16 ,

之前都是亂裝一通導致 Zabbix 裝不起來的情事.GG

所以先行將 PostgreSQL 16 + TimescaleDB 2.13 的組合先行安裝.


https://www.zabbix.com/release_notes


==> Updated max supported TimescaleDB version to 2.13 Server

==> Increased PostgreSQL maximum supported version to 16


PostgreSQL 16 可參考如下 URL 

https://www.postgresql.org/download/


因為我是使用 Oracle Linux 所以是看這個.

https://www.postgresql.org/download/linux/redhat/

安裝操作依官網 SOP 即可...

# Install the repository RPM:

sudo dnf install -y https://download.postgresql.org/pub/repos/yum/reporpms/EL-9-x86_64/pgdg-redhat-repo-latest.noarch.rpm


# Disable the built-in PostgreSQL module:

sudo dnf -qy module disable postgresql


# Install PostgreSQL:

sudo dnf install -y postgresql16-server


# Optionally initialize the database and enable automatic start:


sudo /usr/pgsql-16/bin/postgresql-16-setup initdb

sudo systemctl enable postgresql-16

sudo systemctl start postgresql-16


PostgreSQL安裝完成後,重要的設定及安裝程式會放置在這二處


[root@Oracle9 pgsql-16]# pwd

/usr/pgsql-16

[root@Oracle9 16]# pwd

/var/lib/pgsql/16


為方便後續的操作及使用

vi  /etc/profile

最下方處加上如下設定.

PATH=$PATH:/usr/pgsql-16/bin/

export PATH

PGDATA=/var/lib/pgsql/16/data

export PGDATA

及做一些必要的 postgresql 服務設定.

vi /var/lib/pgsql/16/data/pg_hba.conf 

vi /var/lib/pgsql/16/data/postgresql.conf 

===============================================

TimescaleDB 可參考如下 URL 

https://packagecloud.io/timescale/timescaledb/install

因為我是要下載及安裝指定版本,故我選擇用手動下載及安裝的方式進行之.

TimescaleDB 2.13  可參考如下 URL 

https://packagecloud.io/timescale/timescaledb

下載

wget --content-disposition "https://packagecloud.io/timescale/timescaledb/packages/el/9/timescaledb-2-loader-postgresql-16-2.13.0-0.el9.x86_64.rpm/download.rpm?distro_version_id=240"

wget --content-disposition "https://packagecloud.io/timescale/timescaledb/packages/el/9/timescaledb-2-postgresql-16-2.13.0-0.el9.x86_64.rpm/download.rpm?distro_version_id=240"

wget --content-disposition "https://packagecloud.io/timescale/timescaledb/packages/el/9/timescaledb-tools-0.15.0-0.el9.x86_64.rpm/download.rpm?distro_version_id=240"

手動安裝 timescaledb-2-postgresql-16-2.13

[root@Oracle9 tmp]# cd timescaledb-2-pg16/

[root@Oracle9 timescaledb-2-pg16]# ll

total 3032

-rw-r--r-- 1 root root   28055 Nov 29  2023 timescaledb-2-loader-postgresql-16-2.13.0-0.el9.x86_64.rpm

-rw-r--r-- 1 root root  684479 Nov 29  2023 timescaledb-2-postgresql-16-2.13.0-0.el9.x86_64.rpm

-rw-r--r-- 1 root root 2386633 Nov  6  2023 timescaledb-tools-0.15.0-0.el9.x86_64.rpm

[root@Oracle9 timescaledb-2-pg16]# rpm -ivh timescaledb-tools-0.15.0-0.el9.x86_64.rpm 

Verifying...                          ################################# [100%]

Preparing...                          ################################# [100%]

Updating / installing...

   1:timescaledb-tools-0.15.0-0.el9   ################################# [100%]


[root@Oracle9 timescaledb-2-pg16]# rpm -ivh timescaledb-2-loader-postgresql-16-2.13.0-0.el9.x86_64.rpm 

Verifying...                          ################################# [100%]

Preparing...                          ################################# [100%]

Updating / installing...

   1:timescaledb-2-loader-postgresql-1################################# [100%]

Using pg_config located at /usr/pgsql-16/bin/pg_config to finish installation...


[root@Oracle9 timescaledb-2-pg16]# rpm -ivh timescaledb-2-postgresql-16-2.13.0-0.el9.x86_64.rpm 

Verifying...                          ################################# [100%]

Preparing...                          ################################# [100%]

Updating / installing...

   1:timescaledb-2-postgresql-16-2.13.################################# [100%]

Using pg_config located at /usr/pgsql-16/bin/pg_config to finish installation...


TimescaleDB has been installed. You need to update your postgresql.conf file

to load the library by adding 'timescaledb' to your shared_preload_libraries.

The easiest way to do this (and more configuration) is to use timescaledb-tune:

timescaledb-tune --pg-config=/usr/pgsql-16/bin/pg_config


依指示做  timescaledb-tune  


[root@Oracle9 timescaledb-2-pg16]# timescaledb-tune --pg-config=/usr/pgsql-16/bin/pg_config

Using postgresql.conf at this path:

/var/lib/pgsql/16/data/postgresql.conf


Is this correct? [(y)es/(n)o]: y

Writing backup to:

/tmp/timescaledb_tune.backup202406091011


shared_preload_libraries needs to be updated

Current:

#shared_preload_libraries = ''

Recommended:

shared_preload_libraries = 'timescaledb'

Is this okay? [(y)es/(n)o]: y

success: shared_preload_libraries will be updated


Tune memory/parallelism/WAL and other settings? [(y)es/(n)o]: y

Recommendations based on 7.31 GB of available memory and 4 CPUs for PostgreSQL 16


Memory settings recommendations

Current:

shared_buffers = 128MB

#effective_cache_size = 4GB

#maintenance_work_mem = 64MB

#work_mem = 4MB

Recommended:

shared_buffers = 1871MB

effective_cache_size = 5614MB

maintenance_work_mem = 958185kB

work_mem = 4790kB

Is this okay? [(y)es/(s)kip/(q)uit]: y

success: memory settings will be updated


Parallelism settings recommendations

Current:

missing: timescaledb.max_background_workers

#max_worker_processes = 8

#max_parallel_workers_per_gather = 2

#max_parallel_workers = 8

Recommended:

timescaledb.max_background_workers = 16

max_worker_processes = 23

max_parallel_workers_per_gather = 2

max_parallel_workers = 4

Is this okay? [(y)es/(s)kip/(q)uit]: y

success: parallelism settings will be updated


WAL settings recommendations

Current:

#wal_buffers = -1

min_wal_size = 80MB

Recommended:

wal_buffers = 16MB

min_wal_size = 512MB

Is this okay? [(y)es/(s)kip/(q)uit]: y

success: WAL settings will be updated


Background writer settings recommendations

Current:

Recommended:

Is this okay? [(y)es/(s)kip/(q)uit]: y

success: background writer settings will be updated


Miscellaneous settings recommendations

Current:

#default_statistics_target = 100

#random_page_cost = 4.0

#checkpoint_completion_target = 0.9

#max_locks_per_transaction = 64

#autovacuum_max_workers = 3

#autovacuum_naptime = 1min

#effective_io_concurrency = 1

Recommended:

default_statistics_target = 100

random_page_cost = 1.1

checkpoint_completion_target = 0.9

max_locks_per_transaction = 64

autovacuum_max_workers = 10

autovacuum_naptime = 10

effective_io_concurrency = 256

Is this okay? [(y)es/(s)kip/(q)uit]: y

success: miscellaneous settings will be updated

Saving changes to: /var/lib/pgsql/16/data/postgresql.conf

[root@Oracle9 timescaledb-2-pg16]# 

====>   systemctl restart postgresql-16

到這裡 Zabbix 安裝的前置作業應該差不多完成了.

==============================================

Zabbix 安裝及設定可參考如下 URL 

https://www.zabbix.com/download

我是看這裡操作的.

https://www.zabbix.com/download?zabbix=7.0&os_distribution=oracle_linux&os_version=9&components=server_frontend_agent&db=pgsql&ws=apache

安裝操作依官網 SOP 即可...大致如下....

PS 我是使用 Oracle Linux 9 所以有些許小異動...

A

# echo "excludepkgs=zabbix*" >> /etc/yum.repos.d/oracle-epel-ol9.repo 

# rpm -Uvh https://repo.zabbix.com/zabbix/7.0/oracle/9/x86_64/zabbix-release-7.0-2.el9.noarch.rpm

# dnf clean all

B

# dnf install zabbix-server-pgsql zabbix-web-pgsql zabbix-apache-conf zabbix-sql-scripts zabbix-selinux-policy zabbix-agent

C

# sudo -u postgres createuser --pwprompt zabbix

# sudo -u postgres createdb -O zabbix zabbix

#zcat /usr/share/zabbix-sql-scripts/postgresql/server.sql.gz | sudo -u zabbix psql zabbix

D

vi /etc/zabbix/zabbix_server.conf

....

DBHost=127.0.0.1

DBName=zabbix

DBSchema=public

DBUser=zabbix

DBPassword=zabbix

.....

E

# systemctl restart zabbix-server zabbix-agent httpd php-fpm

# systemctl enable zabbix-server zabbix-agent httpd php-fpm

=====================================================

[root@Oracle9 data]# netstat -antlp | grep "LISTEN" 

tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      792/sshd: /usr/sbin 

tcp        0      0 0.0.0.0:111             0.0.0.0:*               LISTEN      1/systemd           

tcp        0      0 0.0.0.0:37989           0.0.0.0:*               LISTEN      -                   

tcp        0      0 127.0.0.1:44321         0.0.0.0:*               LISTEN      1071/pmcd           

tcp        0      0 0.0.0.0:38035           0.0.0.0:*               LISTEN      841/rpc.statd       

tcp        0      0 0.0.0.0:10050           0.0.0.0:*               LISTEN      9173/zabbix_agentd  

tcp        0      0 0.0.0.0:10051           0.0.0.0:*               LISTEN      9175/zabbix_server  

tcp        0      0 0.0.0.0:2049            0.0.0.0:*               LISTEN      -                   

tcp        0      0 127.0.0.1:4330          0.0.0.0:*               LISTEN      2544/pmlogger       

tcp        0      0 127.0.0.1:199           0.0.0.0:*               LISTEN      837/snmpd           

tcp        0      0 127.0.0.1:5432          0.0.0.0:*               LISTEN      7767/postgres       

tcp        0      0 0.0.0.0:3306            0.0.0.0:*               LISTEN      939/mariadbd        

tcp        0      0 127.0.0.1:6010          0.0.0.0:*               LISTEN      3338/sshd: XXXX 

tcp        0      0 0.0.0.0:20048           0.0.0.0:*               LISTEN      869/rpc.mountd      

tcp6       0      0 :::22                   :::*                    LISTEN      792/sshd: /usr/sbin 

tcp6       0      0 :::111                  :::*                    LISTEN      1/systemd           

tcp6       0      0 :::80                   :::*                    LISTEN      9923/httpd          

tcp6       0      0 ::1:44321               :::*                    LISTEN      1071/pmcd           

tcp6       0      0 :::41563                :::*                    LISTEN      -                   

tcp6       0      0 :::10050                :::*                    LISTEN      9173/zabbix_agentd  

tcp6       0      0 :::10051                :::*                    LISTEN      9175/zabbix_server  

tcp6       0      0 :::2049                 :::*                    LISTEN      -                   

tcp6       0      0 ::1:5432                :::*                    LISTEN      7767/postgres       

tcp6       0      0 ::1:6010                :::*                    LISTEN      3338/sshd: XRCD2 

tcp6       0      0 ::1:4330                :::*                    LISTEN      2544/pmlogger       

tcp6       0      0 :::3306                 :::*                    LISTEN      939/mariadbd        

tcp6       0      0 :::20048                :::*                    LISTEN      869/rpc.mountd      

tcp6       0      0 :::36655                :::*                    LISTEN      841/rpc.statd       

[root@Oracle9 data]# 

=================================================================

Zabbix 加裝 timescaledb

https://www.zabbix.com/documentation/current/en/manual/appendix/install/timescaledb

安裝操作依官網 SOP 即可...大致如下....

[root@Oracle9 yum.repos.d]# echo "CREATE EXTENSION IF NOT EXISTS timescaledb CASCADE;" | sudo -u postgres psql zabbix

WARNING:  

WELCOME TO

 _____ _                               _     ____________  

|_   _(_)                             | |    |  _  \ ___ \ 

  | |  _ _ __ ___   ___  ___  ___ __ _| | ___| | | | |_/ / 

  | | | |  _ ` _ \ / _ \/ __|/ __/ _` | |/ _ \ | | | ___ \ 

  | | | | | | | | |  __/\__ \ (_| (_| | |  __/ |/ /| |_/ /

  |_| |_|_| |_| |_|\___||___/\___\__,_|_|\___|___/ \____/

               Running version 2.13.0

For more information on TimescaleDB, please visit the following links:


 1. Getting started: https://docs.timescale.com/timescaledb/latest/getting-started

 2. API reference documentation: https://docs.timescale.com/api/latest


Note: TimescaleDB collects anonymous reports to better understand and assist our users.

For more information and how to disable, please see our docs https://docs.timescale.com/timescaledb/latest/how-to-guides/configuration/telemetry.


CREATE EXTENSION

[root@Oracle9 yum.repos.d]# 


[root@Oracle9 timescaledb]# cat /usr/share/zabbix-sql-scripts/postgresql/timescaledb/schema.sql | sudo -u zabbix psql zabbix

NOTICE:  function base36_decode(pg_catalog.varchar) does not exist, skipping

DROP FUNCTION

CREATE FUNCTION

NOTICE:  function cuid_timestamp(pg_catalog.varchar) does not exist, skipping

DROP FUNCTION

CREATE FUNCTION

NOTICE:  PostgreSQL version 16.3 is valid

NOTICE:  TimescaleDB extension is detected

NOTICE:  TimescaleDB version 2.13.0 is valid

WARNING:  column type "character varying" used for "source" does not follow best practices

HINT:  Use datatype TEXT instead.

WARNING:  column type "character varying" used for "value" does not follow best practices

HINT:  Use datatype TEXT instead.

WARNING:  column type "character varying" used for "auditid" does not follow best practices

HINT:  Use datatype TEXT instead.

WARNING:  column type "character varying" used for "username" does not follow best practices

HINT:  Use datatype TEXT instead.

WARNING:  column type "character varying" used for "ip" does not follow best practices

HINT:  Use datatype TEXT instead.

WARNING:  column type "character varying" used for "resource_cuid" does not follow best practices

HINT:  Use datatype TEXT instead.

WARNING:  column type "character varying" used for "resourcename" does not follow best practices

HINT:  Use datatype TEXT instead.

WARNING:  column type "character varying" used for "recordsetid" does not follow best practices

HINT:  Use datatype TEXT instead.

NOTICE:  TimescaleDB is configured successfully

DO

[root@Oracle9 timescaledb]#

======================================================

檢查看看

[root@Oracle9 timescaledb]# su - postgres

[postgres@Oracle9 ~]$ psql

psql (16.3)

Type "help" for help.


postgres=# \l

                                                       List of databases

   Name    |  Owner   | Encoding | Locale Provider |   Collate   |    Ctype    | ICU Locale | ICU Rules |   Access privileges   

-----------+----------+----------+-----------------+-------------+-------------+------------+-----------+-----------------------

 postgres  | postgres | UTF8     | libc            | en_US.UTF-8 | en_US.UTF-8 |            |           | 

 template0 | postgres | UTF8     | libc            | en_US.UTF-8 | en_US.UTF-8 |            |           | =c/postgres          +

           |          |          |                 |             |             |            |           | postgres=CTc/postgres

 template1 | postgres | UTF8     | libc            | en_US.UTF-8 | en_US.UTF-8 |            |           | =c/postgres          +

           |          |          |                 |             |             |            |           | postgres=CTc/postgres

 zabbix    | zabbix   | UTF8     | libc            | en_US.UTF-8 | en_US.UTF-8 |            |           | 

(4 rows)


postgres=# \dn+

                                       List of schemas

  Name  |       Owner       |           Access privileges            |      Description       

--------+-------------------+----------------------------------------+------------------------

 public | pg_database_owner | pg_database_owner=UC/pg_database_owner+| standard public schema

        |                   | =U/pg_database_owner                   | 

(1 row)



postgres=# exit

[postgres@Oracle9 ~]$ exit

logout

[root@Oracle9 data]# 


DEMO





壓測工具

https://pypi.org/project/cpu-load-generator/


LineNotify Alert DEMO






2024年5月12日 星期日

GlusterFS-server加NFS-ganesha大亂測

 事前導讀及參考資訊

https://xrcd2.blogspot.com/2022/04/glusterfs-samba.html

https://www.server-world.info/en/note?os=CentOS_Stream_9&p=glusterfs11&f=1

https://core.vmware.com/resource/nfs-iscsi-multipathing-vsphere

測試架構

192.168.100.201 Rocky  Linux  nfs1     glusterfs-server+nfs-ganesha

192.168.100.202 Rocky  Linux  nfs2     glusterfs-server+nfs-ganesha

192.168.100.x   Oracle Linux  Oracle9  glusterfs/nfsclient test

192.168.100.111 ESXi NFS Client 

192.168.100.222 PVE  Glusterfs Client + Client

===========================

操作及設定簡要記錄

fdisk /dev/nvme0n2

mkfs.xfs /dev/nvme0n2p1

mkdir /syncdisk

blkid

vi /etc/fstab


UUID=33548bbf-a5be-4d08-ab25-28e68dc438f5 /syncdisk   xfs   defaults   0 0



vi /etc/hosts

192.168.100.201 nfs1 
192.168.100.202     nfs2

[root@nfs1 ~]# df -h
Filesystem      Size  Used Avail Use% Mounted on
devtmpfs        4.0M     0  4.0M   0% /dev
tmpfs           3.8G     0  3.8G   0% /dev/shm
tmpfs           1.5G  9.4M  1.5G   1% /run
/dev/nvme0n1p2   44G  6.8G   38G  16% /
/dev/nvme0n1p1  960M  469M  492M  49% /boot
/dev/nvme0n2p1   20G  175M   20G   1% /syncdisk
tmpfs           766M   36K  766M   1% /run/user/1000
[root@nfs1 ~]# 


  dnf install centos-release-gluster11.noarch 
  dnf install centos-release-nfs-ganesha5.noarch 
  dnf --enablerepo=crb install python3-pyxattr
  dnf install   glusterfs-server


[root@nfs1 yum.repos.d]# systemctl enable --now glusterd
[root@nfs1 yum.repos.d]# gluster --version
glusterfs 11.1
Repository revision: git://git.gluster.org/glusterfs.git
Copyright (c) 2006-2016 Red Hat, Inc. <https://www.gluster.org/>
GlusterFS comes with ABSOLUTELY NO WARRANTY.
It is licensed to you under your choice of the GNU Lesser
General Public License, version 3 or any later version (LGPLv3
or later), or the GNU General Public License, version 2 (GPLv2),
in all cases as published by the Free Software Foundation.
[root@nfs1 yum.repos.d]# gluster peer probe nfs2
peer probe: success
[root@nfs1 yum.repos.d]# gluster peer status 
Number of Peers: 1

Hostname: nfs2
Uuid: bc6daa49-a8ca-438c-871c-45a978ea4251
State: Peer in Cluster (Connected)

[root@nfs1 yum.repos.d]# gluster volume create nfsvolume replica 2 transport tcp nfs1:/syncdisk/nfs nfs2:/syncdisk/nfs
Replica 2 volumes are prone to split-brain. Use Arbiter or Replica 3 to avoid this. See: http://docs.gluster.org/en/latest/Administrator-Guide/Split-brain-and-ways-to-deal-with-it/.
Do you still want to continue?
 (y/n) y
volume create: nfsvolume: success: please start the volume to access data

[root@nfs1 yum.repos.d]# gluster volume info 
 
Volume Name: nfsvolume
Type: Replicate
Volume ID: 776a642f-53fe-47ee-924a-20a45a911304
Status: Created
Snapshot Count: 0
Number of Bricks: 1 x 2 = 2
Transport-type: tcp
Bricks:
Brick1: nfs1:/syncdisk/nfs
Brick2: nfs2:/syncdisk/nfs
Options Reconfigured:
cluster.granular-entry-heal: on
storage.fips-mode-rchecksum: on
transport.address-family: inet
nfs.disable: on
performance.client-io-threads: off
[root@nfs1 yum.repos.d]# 


[root@nfs1 yum.repos.d]# gluster volume start nfsvolume
volume start: nfsvolume: success
[root@nfs1 yum.repos.d]# 


[root@nfs2 ~]#  mount -t glusterfs nfs1:/nfsvolume /mnt
[root@nfs2 ~]# df 
Filesystem      1K-blocks    Used Available Use% Mounted on
devtmpfs             4096       0      4096   0% /dev
tmpfs             3918632       0   3918632   0% /dev/shm
tmpfs             1567456    9600   1557856   1% /run
/dev/nvme0n1p2   46064640 7125096  38939544  16% /
/dev/nvme0n2p1   20904960  179044  20725916   1% /syncdisk
/dev/nvme0n1p1     983040  479448    503592  49% /boot
tmpfs              783724      36    783688   1% /run/user/1000
nfs1:/nfsvolume  20904960  388092  20516868   2% /mnt

[root@nfs2 ~]#  echo "GlusterFS write test from nfs2" > /mnt/test.txt
[root@nfs2 ~]# ls -la /syncdisk/nfs/*
-rw-r--r-- 2 root root 21 May 11 12:57 /syncdisk/nfs/test.txt
[root@nfs2 ~]# 


[root@nfs1 yum.repos.d]# ls -la /syncdisk/nfs/*
-rw-r--r-- 2 root root 21 May 11 12:57 /syncdisk/nfs/test.txt
[root@nfs1 yum.repos.d]# 


mkdir /syncgfs 

vi /etc/fstab 



[root@nfs1 nfs]# cat /etc/fstab 

#
# /etc/fstab
# Created by anaconda on Tue Feb 20 23:34:32 2024
#
# Accessible filesystems, by reference, are maintained under '/dev/disk/'.
# See man pages fstab(5), findfs(8), mount(8) and/or blkid(8) for more info.
#
# After editing this file, run 'systemctl daemon-reload' to update systemd
# units generated from this file.
#
UUID=c5d392e3-edbd-44e3-bd92-0053aec8bc10 /                       xfs     defaults        0 0
UUID=6fe1dba6-5999-491c-9679-c32ee4c84490 /boot                   xfs     defaults        0 0
UUID=d631d923-aa38-475f-9609-8283d3a598dc none                    swap    defaults        0 0
UUID=33548bbf-a5be-4d08-ab25-28e68dc438f5 /syncdisk   xfs   defaults   0 0
nfs1:/nfsvolume /syncgfs glusterfs   defaults,_netdev   0 0
[root@nfs1 nfs]# 



[root@nfs2 syncgfs]# cat /etc/fstab 

#
# /etc/fstab
# Created by anaconda on Tue Feb 20 23:34:32 2024
#
# Accessible filesystems, by reference, are maintained under '/dev/disk/'.
# See man pages fstab(5), findfs(8), mount(8) and/or blkid(8) for more info.
#
# After editing this file, run 'systemctl daemon-reload' to update systemd
# units generated from this file.
#
UUID=c5d392e3-edbd-44e3-bd92-0053aec8bc10 /                       xfs     defaults        0 0
UUID=6fe1dba6-5999-491c-9679-c32ee4c84490 /boot                   xfs     defaults        0 0
UUID=d631d923-aa38-475f-9609-8283d3a598dc none                    swap    defaults        0 0
UUID=575c8913-d8df-4d79-857e-4b586c439b52 /syncdisk   xfs   defaults   0 0 
nfs2:/nfsvolume         /syncgfs        glusterfs                 defaults,_netdev        0 0
[root@nfs2 syncgfs]# 


dnf install nfs-ganesha-vfs nfs-ganesha nfs-ganesha-gluster


[root@nfs1 nfs]# cp /etc/ganesha/ganesha.conf /etc/ganesha/ganesha.conf.org
[root@nfs1 nfs]# vi /etc/ganesha/ganesha.conf




###################################################
#
# Ganesha Config Example
#
# This is a commented example configuration file for Ganesha.  It is not
# complete, but only has some common configuration options.  See the man pages
# for complete documentation.
#
###################################################

## These are core parameters that affect Ganesha as a whole.
NFS_CORE_PARAM {
## Allow NFSv3 to mount paths with the Pseudo path, the same as NFSv4,
## instead of using the physical paths.
mount_path_pseudo = true;

## Configure the protocols that Ganesha will listen for.  This is a hard
## limit, as this list determines which sockets are opened.  This list
## can be restricted per export, but cannot be expanded.
Protocols = 3,4;
}

## These are defaults for exports.  They can be overridden per-export.
EXPORT_DEFAULTS {
## Access type for clients.  Default is None, so some access must be
## given either here or in the export itself.
Access_Type = RW;
}

## Configure settings for the object handle cache
#MDCACHE {
## The point at which object cache entries will start being reused.
#Entries_HWMark = 100000;
#}

## Configure an export for some file tree
EXPORT
{
## Export Id (mandatory, each EXPORT must have a unique Export_Id)
Export_Id = 12345;

## Exported path (mandatory)
Path = /nfsha;

## Pseudo Path (required for NFSv4 or if mount_path_pseudo = true)
Pseudo = /nfsha;

## Restrict the protocols that may use this export.  This cannot allow
## access that is denied in NFS_CORE_PARAM.
Protocols = 3,4;

## Access type for clients.  Default is None, so some access must be
## given. It can be here, in the EXPORT_DEFAULTS, or in a CLIENT block
Access_Type = RW;

## Whether to squash various users.
Squash = No_root_squash;

## Allowed security types for this export
Sectype = sys;

## Exporting FSAL
FSAL {
Name = GLUSTER;
hostname="192.168.100.201";
volume="nfsvolume";
}
}

## Configure logging.  Default is to log to Syslog.  Basic logging can also be
## configured from the command line
LOG {
## Default log level for all components
Default_Log_Level = WARN;

## Configure per-component log levels.
#Components {
#FSAL = INFO;
#NFS4 = EVENT;
#}

## Where to log
#Facility {
#name = FILE;
#destination = "/var/log/ganesha.log";
#enable = active;
#}
}



[root@nfs1 nfs]#  systemctl disable --now nfs-server
[root@nfs1 nfs]#  systemctl enable --now nfs-ganesha
Created symlink /etc/systemd/system/multi-user.target.wants/nfs-ganesha.service → /usr/lib/systemd/system/nfs-ganesha.service.
Created symlink /etc/systemd/system/nfs-ganesha.service.wants/nfs-ganesha-lock.service → /usr/lib/systemd/system/nfs-ganesha-lock.service.

[root@nfs1 nfs]# showmount -e localhost
Export list for localhost:
/nfsha (everyone)
[root@nfs1 nfs]# 





[root@Oracle9 ~]# yum install nfsv4-client-utils.x86_64 nfs-utils.x86_64


[root@Oracle9 mnt]# 

vi /ets/hosts

192.168.100.201 nfs1
192.168.100.202 nfs2


mkdir /mnt/HA-NFS


[root@Oracle9 mnt]# mount -t nfs4 nfs1:/nfsha /mnt/HA-NFS/


[root@Oracle9 mnt]# df -h
Filesystem      Size  Used Avail Use% Mounted on
devtmpfs        4.0M     0  4.0M   0% /dev
tmpfs           3.7G     0  3.7G   0% /dev/shm
tmpfs           1.5G  9.2M  1.5G   1% /run
/dev/nvme0n1p3   45G   11G   35G  23% /
/dev/nvme0n1p1  960M  707M  254M  74% /boot
tmpfs           749M   36K  749M   1% /run/user/0
tmpfs           749M   36K  749M   1% /run/user/1001
nfs1:/nfsha      20G  379M   20G   2% /mnt/HA-NFS
[root@Oracle9 mnt]# 



[root@Oracle9 mnt]# cat  /mnt/HA-NFS/test.txt 
GlusterFS write test from nfs 1 
GlusterFS write test from nfs 2 

[root@Oracle9 mnt]# echo "GlusterFS write test from Oracle-Client  " >> /mnt/HA-NFS/test.txt 
[root@Oracle9 mnt]# 


[root@Oracle9 mnt]# cat /mnt/HA-NFS/test.txt 
GlusterFS write test from nfs 1 
GlusterFS write test from nfs 2 
GlusterFS write test from Oracle-Client  
[root@Oracle9 mnt]# 

[root@nfs1 nfs]# cat /syncdisk/nfs/test.txt 
GlusterFS write test from nfs 1 
GlusterFS write test from nfs 2 
GlusterFS write test from Oracle-Client  
[root@nfs1 nfs]# 


[root@nfs2 syncgfs]# cat /syncdisk/nfs/test.txt 
GlusterFS write test from nfs 1 
GlusterFS write test from nfs 2 
GlusterFS write test from Oracle-Client  
[root@nfs2 syncgfs]# 


[root@Oracle9 mnt]# umount /mnt/HA-NFS 
[root@Oracle9 mnt]# mount -t nfs4 nfs2:/nfsha /mnt/HA-NFS/

[root@Oracle9 mnt]# echo "GlusterFS write test2 from Oracle-Client  " >> /mnt/HA-NFS/test.txt 
[root@Oracle9 mnt]# 

[root@nfs1 nfs]# cat /syncdisk/nfs/test.txt 
GlusterFS write test from nfs 1 
GlusterFS write test from nfs 2 
GlusterFS write test from Oracle-Client  
GlusterFS write test2 from Oracle-Client  
[root@nfs1 nfs]# 


[root@nfs2 syncgfs]# cat /syncdisk/nfs/test.txt 
GlusterFS write test from nfs 1 
GlusterFS write test from nfs 2 
GlusterFS write test from Oracle-Client  
GlusterFS write test2 from Oracle-Client  
[root@nfs2 syncgfs]# 





ESXi

[root@localhost:~] esxcli storage nfs41 list
Volume Name  Host(s)                          Share   Accessible  Mounted  Read-Only  Security   isPE  Hardware Acceleration
-----------  -------------------------------  ------  ----------  -------  ---------  --------  -----  ---------------------
gfs-storage  192.168.100.201,192.168.100.202  /nfsha        true     true      false  AUTH_SYS  false  Not Supported
[root@localhost:~] 




[root@localhost:~] vim-cmd hostsvc/datastore/info gfs-storage
(vim.host.NasDatastoreInfo) {
   name = "gfs-storage", 
   url = "/vmfs/volumes/d3b21ae2-01cd6b50-0000-000000000000", 
   freeSpace = 14566449152, 
   maxFileSize = 70368744177664, 
   maxVirtualDiskCapacity = 68169720922112, 
   maxMemoryFileSize = 70368744177664, 
   timestamp = "2024-05-11T09:42:04.121385Z", 
   containerId = <unset>, 
   aliasOf = <unset>, 
   datastoreFormat = <unset>, 
   logicalSectorSize = <unset>, 
   physicalSectorSize = <unset>, 
   nas = (vim.host.NasVolume) {
      type = "NFS41", 
      name = "gfs-storage", 
      capacity = 21406679040, 
      remoteHost = "192.168.100.201", 
      remotePath = "/nfsha", 
      userName = <unset>, 
      remoteHostNames = (string) [
         "192.168.100.201", 
         "192.168.100.202"
      ], 
      securityType = "AUTH_SYS", 
      protocolEndpoint = false
   }
}
(vim.Datastore.HostMount) [
   (vim.Datastore.HostMount) {
      key = 'vim.HostSystem:ha-host', 
      mountInfo = (vim.host.MountInfo) {
         path = "/vmfs/volumes/d3b21ae2-01cd6b50-0000-000000000000", 
         accessMode = "readWrite", 
         mounted = true, 
         accessible = true, 
         inaccessibleReason = <unset>, 
         vmknicName = "None", 
         vmknicActive = false, 
         mountFailedReason = <unset>, 
         numTcpConnections = 1
      }
   }
]
[root@localhost:~]


[root@localhost:~] esxcli storage filesystem list
Mount Point                                        Volume Name                                 UUID                                 Mounted  Type            Size          Free
-------------------------------------------------  ------------------------------------------  -----------------------------------  -------  ------  ------------  ------------
/vmfs/volumes/d3b21ae2-01cd6b50-0000-000000000000  gfs-storage                                 d3b21ae2-01cd6b50-0000-000000000000     true  NFS41    21406679040   14566449152
/vmfs/volumes/654e469c-44d19cd7-8715-000c2921ee83  datastore1                                  654e469c-44d19cd7-8715-000c2921ee83     true  VMFS-6  137170518016   99963895808
/vmfs/volumes/654e469c-378e9fe6-73ec-000c2921ee83  OSDATA-654e469c-378e9fe6-73ec-000c2921ee83  654e469c-378e9fe6-73ec-000c2921ee83     true  VMFSOS  128580583424  125292249088
/vmfs/volumes/507161ab-d84dd9c3-c4a7-a5422027a503  BOOTBANK1                                   507161ab-d84dd9c3-c4a7-a5422027a503     true  vfat      4293591040    4000317440
/vmfs/volumes/d9628348-1545f094-5e85-a3d31d093e2e  BOOTBANK2                                   d9628348-1545f094-5e85-a3d31d093e2e     true  vfat      4293591040    4293525504
[root@localhost:~] 

PVE






ESXi  NFS

不同的儲存供應商有不同的方法來啟用此功能,
但通常 NAS 伺服器使用 no_root_squash 選項。
如果 NAS 伺服器不授予 root 存取權限,
仍然可以在主機上掛載 NFS 資料儲存。

但是,您無法在資料儲存上建立任何虛擬機器

2024年4月27日 星期六

TrueNAS SCALE 試裝

 TrueNAS-SCALE-24.04.0.iso

重點設定項目如下.

(1)儲存 => 建  RAID

(2)認證 => 建 帳密

(3)資料表 => 建 資料集 設定權限

(4)共用 => 設定及啟用共用服務 SMB/NFS/iSCSI/









2024年3月15日 星期五

使用 PHP 試寫 LibreNMS 串接 Jandi 通知

 LibreNMS 預設是支援常見的 Line Notify,但不支援 Jandi 的.

所以試寫一個 Jandi 的 alert-transports 


Demo 如下所示.


PS:以下程式的串接寫下僅適用於 librenms-22.12.x 以下的版本.

而且是抄改自  Linenotify.php 原碼,如下所示


[root@Oracle9 Transport]# pwd

/opt/librenms/LibreNMS/Alert/Transport

[root@Oracle9 Transport]# cat Linenotify.php

<?php

/**

 * LINE Notify Transport

 */


namespace LibreNMS\Alert\Transport;


use LibreNMS\Alert\Transport;

use LibreNMS\Util\Proxy;


class Linenotify extends Transport

{

    protected $name = 'LINE Notify';


    public function deliverAlert($obj, $opts)

    {

        $opts['line-notify-access-token'] = $this->config['line-notify-access-token'];


        return $this->contactLinenotify($obj, $opts);

    }


    private function contactLinenotify($obj, $opts)

    {

        $lineUrl = 'https://notify-api.line.me/api/notify';

        $lineHead = ['Authorization: Bearer ' . $opts['line-notify-access-token']];

        $lineFields = ['message' => $obj['msg']];


        $curl = curl_init();

        Proxy::applyToCurl($curl);

        curl_setopt($curl, CURLOPT_URL, $lineUrl);

        curl_setopt($curl, CURLOPT_HTTPHEADER, $lineHead);

        curl_setopt($curl, CURLOPT_NOBODY, false);

        curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);

        curl_setopt($curl, CURLOPT_POST, true);

        curl_setopt($curl, CURLOPT_POSTFIELDS, $lineFields);

        curl_exec($curl);

        $code = curl_getinfo($curl, CURLINFO_HTTP_CODE);

        curl_close($curl);

        if ($code != 200) {

            return 'HTTP Status code ' . $code;

        }


        return true;

    }


    public static function configTemplate()

    {

        return [

            'config' => [

                [

                    'title' => 'Token',

                    'name' => 'line-notify-access-token',

                    'descr' => 'LINE Notify Token',

                    'type' => 'text',

                ],

            ],

            'validation' => [

                'line-notify-access-token' => 'required|string',

            ],

        ];

    }

}

[root@Oracle9 Transport]#


抄改成 Jandi 的程式如下所示 


[root@Oracle9 Transport]# pwd

/opt/librenms/LibreNMS/Alert/Transport

[root@Oracle9 Transport]# cat Jandi.php

<?php

/**

 * Jandi webhook Transport

 */



namespace LibreNMS\Alert\Transport;


use LibreNMS\Alert\Transport;

use LibreNMS\Util\Proxy;


class Jandi extends Transport

{


    protected $name = 'Jandi';



    public function deliverAlert($obj, $opts)

    {

        $opts['jandi-webhook-access-token'] = $this->config['jandi-webhook-access-token'];

        $opts['jandi-webhook-access-rec'] = $this->config['jandi-webhook-access-rec'];

        return $this->contactLineNotify($obj, $opts);

    }


    private function contactLinenotify($obj, $opts)

    {

        $webhooktoken=$opts['jandi-webhook-access-token'];

        $webhookid=$opts['jandi-webhook-access-rec'];

        $lineUrl = "https://wh.jandi.com/connect-api/webhook/$webhooktoken/$webhookid";

        $lineHead = ['Accept: application/vnd.tosslab.jandi-v2+json','Content-Type: application/json'];

        // $lineFields = [body' => body , 'connectColor' => '#FAC11B' , 'connectInfo' => [ 'title' => title , 'description' => $obj['msg'] ] ];


        $jmsg=$obj['msg'];


        $nowtime=date('Y-m-d H:i:s');


        $lineFields = <<<DATA

        {

        "body" : "$nowtime",

        "connectColor" : "#FAC11B",

        "connectInfo" : [

           { "title" : "AlertMessage",

             "description" : "$jmsg"

           }

         ]

        }

        DATA;


        // $lineFields = ["body" => body];

        $curl = curl_init();

        curl_setopt($curl, CURLOPT_URL, $lineUrl);

        curl_setopt($curl, CURLOPT_HTTPHEADER, $lineHead);

        curl_setopt($curl, CURLOPT_NOBODY, false);

        curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);

        curl_setopt($curl, CURLOPT_POST, true);

        curl_setopt($curl, CURLOPT_POSTFIELDS, $lineFields);

        curl_exec($curl);

        $code = curl_getinfo($curl, CURLINFO_HTTP_CODE);

        curl_close($curl);

        if ($code != 200) {

            return 'HTTP Status code ' . $code;

        }


        return true;

    }


    public static function configTemplate()

    {

        return [

            'config' => [

                [

                    'title' => 'Jandi WebHook Token',

                    'name' => 'jandi-webhook-access-token',

                    'descr' => 'Jandi WEBHOOK Token',

                    'type' => 'text',

                ],

                [

                    'title' => 'Jandi WebHook Recipient',

                    'name' => 'jandi-webhook-access-rec',

                    'descr' => 'Jandi WEBHOOK Recipient',

                    'type' => 'text',

                ],


            ],

            'validation' => [

                'jandi-webhook-access-token' => 'required|string',

                'jandi-webhook-access-rec' => 'required|string',

            ],

        ];

    }

}

[root@Oracle9 Transport]#


DEMO












2023年11月2日 星期四

Synology NAS 透過 WebHook 機制發 Alert 到 Line Notify

申請 Token URL 如下

https://notify-bot.line.me/zh_TW/

CURL 測試方式示意

curl -X POST -H 'Authorization: Bearer [LineNotify]' -F 'message=TestMessage' https://notify-api.line.me/api/notify

實際運用:

curl -X POST -H 'Authorization: Bearer XXXXXXXXXXXXXXXXXXXXXXXXXX -F 'message=TestMessage' https://notify-api.line.me/api/notify


LineNotify API URL 

https://notify-api.line.me/api/notify


 圖解:



Webhook 網址:請輸入

https://notify-api.line.me/api/notify?message=%40%40TEXT%40%40




 HTTP請求

其實就是最上面那個 CURL 的用法,只是改成以 WEB  輸入的方式呈現.
觀念是一樣的.


可以經由 發送測試通知 去驗證是否正常




如果正常應該會收到如下的 Alert 訊息



FortiGate 也是可以比照辦理.




如有興趣詳見:










2023年10月28日 星期六

FortiGate Automation webhook 加 Line Notify API Webhook 實驗

 延續做實驗

接續 Line Notify API Webhook 實驗

https://xrcd2.blogspot.com/2023/09/line-notify-api-webhook.html


再加入 FortiGate Automation webhook 做進階實驗

簡要架構

FTG--> Automation webhook ->LineNotifyAPI-webhook-Server-->Alert---> LineNotify

 (以下實驗架構)

實務上的用法較正確的做法如下所示

 FTG-> Automation webhook -> https://notify-api.line.me/api/notify --> Alert---> LineNotify

 (一般用法)

申請 Token URL 如下

https://notify-bot.line.me/zh_TW/


CURL 測試方式

curl -X POST -H 'Authorization: Bearer [access_token]' -F 'message=TestMessage' https://notify-api.line.me/api/notify


實驗截圖開始














正常的用法可能長這樣 直打  https://notify-api.line.me/api/notify



Debug 

正常發出訊息


傳送訊息加入 %%log%%  

看來有將 log 訊息加上,但可能死在 json 或 curl 不支援 %%log%% ,可能是 保留字 吧.

有空再研究啦!


Demo




以上畫面的截取為 FTG7 如使用 FTG  6 的畫面如下所示





我是在家中的 IP 分享器底下的 VM 去做實驗的

如果直打 https://notify-api.line.me/api/notify 問題會死在 

auto_curl_perform()-107: Curl perform error:35 - SSL connect error.

__action_webhook_status()-150: Failed to perform curl for url:https://notify-api.line.me/api/notify.

__run_action()-298: Error when running service for stitch:AdminLoginAlert action:SendAlert2Line.

但很怪的是 VM 上網對外是全開的.

且用 CURL 去測也是正常的.. GG

FortiOS 的底層的 curl 可能很不一般吧..(很神奇的那一種) ..~^_^~.


WAN IP unknown




最後手段








終於成功啦!