-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathatom.xml
585 lines (518 loc) · 42.8 KB
/
atom.xml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="zh-CN">
<title type="text">如我所见</title>
<subtitle type="html">这是站点描述</subtitle>
<updated>2022-01-12T16:04:31+08:00</updated>
<id>https://example.com/</id>
<link rel="alternate" type="text/html" href="https://example.com/" />
<link rel="self" type="application/atom+xml" href="https://example.com/atom.xml" />
<author>
<name>iaeieue</name>
<uri>https://example.com/</uri>
<email>[email protected]</email>
</author>
<rights>[CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/deed.zh)</rights>
<generator uri="https://gohugo.io/" version="0.91.2">Hugo</generator>
<entry>
<title type="text">饥荒服务器搭建流程</title>
<link rel="alternate" type="text/html" href="https://example.com/posts/%E9%A5%A5%E8%8D%92%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%90%AD%E5%BB%BA%E6%B5%81%E7%A8%8B%E8%AE%B0%E5%BD%95/" />
<id>https://example.com/posts/%E9%A5%A5%E8%8D%92%E6%9C%8D%E5%8A%A1%E5%99%A8%E6%90%AD%E5%BB%BA%E6%B5%81%E7%A8%8B%E8%AE%B0%E5%BD%95/</id>
<updated>2022-01-12T16:00:54+08:00</updated>
<published>2022-01-12T15:43:35+08:00</published>
<author>
<name>iaeieue</name>
<uri>https://example.com/</uri>
<email>[email protected]</email>
</author>
<rights>[CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/deed.zh)</rights><summary type="html">记录一下自己饥荒服务器搭建流程。 ..着重号..测试 系统配置 操作系统:Ubuntu Server 18.04.1……</summary>
<content type="html"><p>记录一下自己饥荒服务器搭建流程。</p>
<p>..着重号..测试</p>
<h2 id="系统配置">系统配置</h2>
<ul>
<li>操作系统:Ubuntu Server 18.04.1 LTS 64bit</li>
<li>CPU:2核</li>
<li>内存:4GB</li>
<li>系统盘:80GB SSD</li>
<li>带宽:8Mbps(1200GB/月)</li>
</ul>
<p>之后改成Ubuntu20了</p>
<h2 id="配置服务器防火墙">配置服务器防火墙</h2>
<p>开启10888、10999、10998 端口 使用UDP协议</p>
<h2 id="使用密钥通过root用户连接主机">使用密钥通过root用户连接主机</h2>
<p>腾讯云的Ubuntu机子默认不能使用root用户登录,所以需要进行配置。</p>
<h3 id="创建密钥并绑定服务器">创建密钥并绑定服务器</h3>
<p>服务器关了再创</p>
<h3 id="使用finalshell登录服务器">使用FinalShell登录服务器</h3>
<p>到此依然只能用ubuntu账号通过密钥登录,使用root还需要配置</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span><span class="lnt">5
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">sudo passwd root
su - root
cat /home/ubuntu/.ssh/authorized_keys &gt;&gt; /root/.ssh/authorized_keys
passwd -d root
</code></pre></td></tr></table>
</div>
</div><p>这时重新配置FinalShell,使用root账号即可登录</p>
<h2 id="配置steamcmd">配置steamcmd</h2>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">dpkg --add-architecture i386
apt update
<span class="c1"># libsdl2-2.0-0:i386 必须安装否则会有SDL报错</span>
<span class="c1"># libcurl4-gnutls-dev:i386 如果没有则会在开启服务器的时候出现问题,可能是因为启动服务器用了bin里的程序</span>
apt install lib32gcc1 lib32stdc++6 libsdl2-2.0-0:i386 libcurl4-gnutls-dev:i386
useradd -m dst
passwd dst
su - dst
mkdir steamcmd <span class="o">&amp;&amp;</span> <span class="nb">cd</span> steamcmd <span class="o">&amp;&amp;</span> wget https://steamcdn-a.akamaihd.net/client/installer/steamcmd_linux.tar.gz <span class="o">&amp;&amp;</span> tar -xvzf steamcmd_linux.tar.gz
./steamcmd.sh
</code></pre></td></tr></table>
</div>
</div><pre tabindex="0"><code class="language-steamcmd" data-lang="steamcmd">force_install_dir /home/dst/dstserver
login anonymous
app_update 343050 validate
quit
</code></pre><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="nb">cd</span> /home/dst/dstserver/bin
<span class="nb">echo</span> <span class="s2">&#34;./dontstarve_dedicated_server_nullrenderer -console -cluster ruwosuojian -shard Master&#34;</span> &gt; master_start.sh <span class="o">&amp;&amp;</span> <span class="nb">echo</span> <span class="s2">&#34;./dontstarve_dedicated_server_nullrenderer -console -cluster ruwosuojian -shard Caves&#34;</span> &gt; caves_start.sh <span class="o">&amp;&amp;</span> chmod +x master_start.sh caves_start.sh
</code></pre></td></tr></table>
</div>
</div><p>先运行一遍指令,生成存档。</p>
<p>使用本地的饥荒创建世界后进行如下操作。
dedicated_server_mods_setup.lua 文件放在/home/dst/dstserver/mods
cluster_token.txt cluster.ini 放在存档的根目录
modoverrides.lua leveldataoverride.lua server.ini 分别放入Master、Caves</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">screen -S master ./master_start.sh
screen -S caves ./caves_start.sh
</code></pre></td></tr></table>
</div>
</div><h2 id="配置dst用户开机启动服务器">配置dst用户开机启动服务器</h2>
<blockquote>
<p>systemd 用户实例在用户首次登陆时启动,并在最后一个会话退出时终止。 但有时候,对于一些不依赖于会话的用户进程,在系统启动时加载用户实例,在会话全部结束时,也不停止用户实例是比较有用的。Lingering 就是用来实现这个的。 使用以下命令来启用驻留指定用户:</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">loginctl enable-linger username
</code></pre></td></tr></table>
</div>
</div></blockquote>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span><span class="lnt">14
</span><span class="lnt">15
</span><span class="lnt">16
</span><span class="lnt">17
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">loginctl enable-linger dst
<span class="nb">export</span> <span class="nv">XDG_RUNTIME_DIR</span><span class="o">=</span>/run/user/<span class="k">$(</span>id -u<span class="k">)</span> <span class="o">&amp;&amp;</span> systemctl --user import-environment PATH
<span class="c1"># 验证是否配置正确</span>
systemctl --user show-environment
systemctl --user <span class="nb">enable</span> dstmaster
systemctl --user <span class="nb">enable</span> dstcaves
systemctl --user daemon-reload
systemctl --user status dstcaves
<span class="c1"># 查看日志</span>
journalctl --user -u dstmaster -n <span class="m">20</span> -f
journalctl --user -u dstcaves -n <span class="m">20</span> -f
</code></pre></td></tr></table>
</div>
</div><p>就为了个以dst用户开机启动dst服务器,真是给我整吐了
之后最好还要加一个定时备份存档</p>
<!-- echo "XDG_RUNTIME_DIR=/run/user/$(id -u)" > ~/.config/environment.d/env.conf -->
<!-- echo "export XDG_RUNTIME_DIR=/run/user/$(id -u)\nsystemctl --user import-environment PATH" >> ~/.bashrc -->
<p><a href="https://wiki.archlinux.org/title/Systemd_(%E7%AE%80%E4%BD%93%E4%B8%AD%E6%96%87)/User_(%E7%AE%80%E4%BD%93%E4%B8%AD%E6%96%87)#%E9%9A%8F%E7%B3%BB%E7%BB%9F%E8%87%AA%E5%8A%A8%E5%90%AF%E5%258">https://wiki.archlinux.org/title/Systemd_(%E7%AE%80%E4%BD%93%E4%B8%AD%E6%96%87)/User_(%E7%AE%80%E4%BD%93%E4%B8%AD%E6%96%87)#%E9%9A%8F%E7%B3%BB%E7%BB%9F%E8%87%AA%E5%8A%A8%E5%90%AF%E5%8</a></p>
</content>
</entry>
<entry>
<title type="text">Nginx+Trojan Go搭建</title>
<link rel="alternate" type="text/html" href="https://example.com/posts/nginx+trojan-go%E6%90%AD%E5%BB%BA/" />
<id>https://example.com/posts/nginx+trojan-go%E6%90%AD%E5%BB%BA/</id>
<updated>2022-01-12T15:42:33+08:00</updated>
<published>2022-01-12T15:42:10+08:00</published>
<author>
<name>iaeieue</name>
<uri>https://example.com/</uri>
<email>[email protected]</email>
</author>
<rights>[CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/deed.zh)</rights><summary type="html">配置系统Nginx服务 使用 apt 进行前置软件安装 1 2 apt update apt install nginx screen curl unzip 创建站点文件夹,并编……</summary>
<content type="html"><h2 id="配置系统nginx服务">配置系统Nginx服务</h2>
<p>使用 apt 进行前置软件安装</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">apt update
apt install nginx screen curl unzip
</code></pre></td></tr></table>
</div>
</div><p>创建站点文件夹,并编写测试网页文件</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">mkdir -p /var/www/baoshuma.top
vi /var/www/baoshuma.top/index.html
</code></pre></td></tr></table>
</div>
</div><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span><span class="lnt">14
</span><span class="lnt">15
</span><span class="lnt">16
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-html" data-lang="html"><span class="cp">&lt;!DOCTYPE html&gt;</span>
<span class="p">&lt;</span><span class="nt">html</span> <span class="na">lang</span><span class="o">=</span><span class="s">&#34;en&#34;</span><span class="p">&gt;</span>
<span class="p">&lt;</span><span class="nt">head</span><span class="p">&gt;</span>
<span class="p">&lt;</span><span class="nt">meta</span> <span class="na">charset</span><span class="o">=</span><span class="s">&#34;UTF-8&#34;</span><span class="p">&gt;</span>
<span class="p">&lt;</span><span class="nt">meta</span> <span class="na">http-equiv</span><span class="o">=</span><span class="s">&#34;X-UA-Compatible&#34;</span> <span class="na">content</span><span class="o">=</span><span class="s">&#34;IE=edge&#34;</span><span class="p">&gt;</span>
<span class="p">&lt;</span><span class="nt">meta</span> <span class="na">name</span><span class="o">=</span><span class="s">&#34;viewport&#34;</span> <span class="na">content</span><span class="o">=</span><span class="s">&#34;width=device-width, initial-scale=1.0&#34;</span><span class="p">&gt;</span>
<span class="p">&lt;</span><span class="nt">title</span><span class="p">&gt;</span>Document<span class="p">&lt;/</span><span class="nt">title</span><span class="p">&gt;</span>
<span class="p">&lt;/</span><span class="nt">head</span><span class="p">&gt;</span>
<span class="p">&lt;</span><span class="nt">body</span><span class="p">&gt;</span>
<span class="p">&lt;</span><span class="nt">h1</span><span class="p">&gt;</span>Example Page<span class="p">&lt;/</span><span class="nt">h1</span><span class="p">&gt;</span>
This is content......
<span class="p">&lt;/</span><span class="nt">body</span><span class="p">&gt;</span>
<span class="p">&lt;/</span><span class="nt">html</span><span class="p">&gt;</span>
</code></pre></td></tr></table>
</div>
</div><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">vi /etc/nginx/sites-available/baoshuma.top
</code></pre></td></tr></table>
</div>
</div><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span><span class="lnt">14
</span><span class="lnt">15
</span><span class="lnt">16
</span><span class="lnt">17
</span><span class="lnt">18
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-service" data-lang="service"><span class="err">server</span> <span class="err">{</span>
<span class="err">listen</span> <span class="err">80</span><span class="c">;</span>
<span class="err">root</span> <span class="err">/var/www/baoshuma.top</span><span class="c">;</span>
<span class="err">index</span> <span class="err">index.html</span> <span class="err">index.htm</span> <span class="err">index.nginx-debian.html</span><span class="c">;</span>
<span class="err">server_name</span> <span class="err">baoshuma.top</span> <span class="err">www.baoshuma.top</span><span class="c">;</span>
<span class="err">location</span> <span class="err">/</span> <span class="err">{</span>
<span class="na">try_files $uri $uri/ </span><span class="o">=</span><span class="s">404;</span>
<span class="err">}</span>
<span class="na">if ( $remote_addr !</span><span class="o">=</span><span class="s"> 127.0.0.1 ) {</span>
<span class="err">rewrite</span> <span class="err">^/(.*)$</span> <span class="err">https://baoshuma.top/$1</span> <span class="err">redirect</span><span class="c">;</span>
<span class="err">}</span>
<span class="err">access_log</span> <span class="err">/var/log/nginx/baoshuma.top.access.log</span><span class="c">;</span>
<span class="err">error_log</span> <span class="err">/var/log/nginx/baoshuma.top.error.log</span><span class="c">;</span>
<span class="err">}</span>
</code></pre></td></tr></table>
</div>
</div><p>创建软连接并重启nginx服务</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">ln -s /etc/nginx/sites-available/baoshuma.top /etc/nginx/sites-enabled
systemctl restart nginx
</code></pre></td></tr></table>
</div>
</div><h2 id="通过acmesh进行ssl证书自动化">通过ACME.SH进行SSL证书自动化</h2>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span><span class="lnt">5
</span><span class="lnt">6
</span><span class="lnt">7
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">curl https://get.acme.sh <span class="p">|</span> sh
acme.sh --set-default-ca --server letsencrypt
<span class="nb">export</span> <span class="nv">CF_Key</span><span class="o">=</span><span class="s2">&#34;XXX&#34;</span>
<span class="nb">export</span> <span class="nv">CF_Email</span><span class="o">=</span><span class="s2">&#34;XXX&#34;</span>
acme.sh --issue --dns dns_cf -d baoshuma.top -d <span class="s1">&#39;*.baoshuma.top&#39;</span> -k ec-256
mkdir -p /etc/nginx/ssl
acme.sh --installcert -d baoshuma.top --fullchain-file /etc/nginx/ssl/fullchain.cer --key-file /etc/nginx/ssl/baoshuma.top.key --ecc
</code></pre></td></tr></table>
</div>
</div><h2 id="配置trojan-go">配置Trojan-Go</h2>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span><span class="lnt">5
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">wget https://github.com/p4gefau1t/trojan-go/releases/download/v0.10.6/trojan-go-linux-amd64.zip
mkdir -p /etc/trojan-go/<span class="o">{</span>bin,conf,logs<span class="o">}</span>
unzip -d /etc/trojan-go/bin trojan-go-linux-amd64.zip
rm trojan-go-linux-amd64.zip
vi /etc/trojan-go/conf/server.json
</code></pre></td></tr></table>
</div>
</div><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span><span class="lnt">14
</span><span class="lnt">15
</span><span class="lnt">16
</span><span class="lnt">17
</span><span class="lnt">18
</span><span class="lnt">19
</span><span class="lnt">20
</span><span class="lnt">21
</span><span class="lnt">22
</span><span class="lnt">23
</span><span class="lnt">24
</span><span class="lnt">25
</span><span class="lnt">26
</span><span class="lnt">27
</span><span class="lnt">28
</span><span class="lnt">29
</span><span class="lnt">30
</span><span class="lnt">31
</span><span class="lnt">32
</span><span class="lnt">33
</span><span class="lnt">34
</span><span class="lnt">35
</span><span class="lnt">36
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-json" data-lang="json"><span class="p">{</span>
<span class="nt">&#34;run_type&#34;</span><span class="p">:</span> <span class="s2">&#34;server&#34;</span><span class="p">,</span>
<span class="nt">&#34;local_addr&#34;</span><span class="p">:</span> <span class="s2">&#34;0.0.0.0&#34;</span><span class="p">,</span>
<span class="nt">&#34;local_port&#34;</span><span class="p">:</span> <span class="mi">443</span><span class="p">,</span>
<span class="nt">&#34;remote_addr&#34;</span><span class="p">:</span> <span class="s2">&#34;127.0.0.1&#34;</span><span class="p">,</span>
<span class="nt">&#34;remote_port&#34;</span><span class="p">:</span> <span class="mi">80</span><span class="p">,</span>
<span class="nt">&#34;password&#34;</span><span class="p">:</span> <span class="p">[</span>
<span class="s2">&#34;XXX&#34;</span>
<span class="p">],</span>
<span class="nt">&#34;log_level&#34;</span><span class="p">:</span> <span class="mi">1</span><span class="p">,</span>
<span class="nt">&#34;log_file&#34;</span><span class="p">:</span> <span class="s2">&#34;/etc/trojan-go/logs/trojan-go-access.log&#34;</span><span class="p">,</span>
<span class="nt">&#34;ssl&#34;</span><span class="p">:</span> <span class="p">{</span>
<span class="nt">&#34;verify&#34;</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
<span class="nt">&#34;verify_hostname&#34;</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
<span class="nt">&#34;cert&#34;</span><span class="p">:</span> <span class="s2">&#34;/etc/nginx/ssl/fullchain.cer&#34;</span><span class="p">,</span>
<span class="nt">&#34;key&#34;</span><span class="p">:</span> <span class="s2">&#34;/etc/nginx/ssl/baoshuma.top.key&#34;</span><span class="p">,</span>
<span class="nt">&#34;key_password&#34;</span><span class="p">:</span> <span class="s2">&#34;&#34;</span><span class="p">,</span>
<span class="nt">&#34;curves&#34;</span><span class="p">:</span> <span class="s2">&#34;&#34;</span><span class="p">,</span>
<span class="nt">&#34;cipher&#34;</span><span class="p">:</span> <span class="s2">&#34;&#34;</span><span class="p">,</span>
<span class="nt">&#34;prefer_server_cipher&#34;</span><span class="p">:</span> <span class="kc">false</span><span class="p">,</span>
<span class="nt">&#34;sni&#34;</span><span class="p">:</span> <span class="s2">&#34;baoshuma.top&#34;</span><span class="p">,</span>
<span class="nt">&#34;alpn&#34;</span><span class="p">:</span> <span class="p">[</span>
<span class="s2">&#34;http/1.1&#34;</span>
<span class="p">],</span>
<span class="nt">&#34;reuse_session&#34;</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
<span class="nt">&#34;session_ticket&#34;</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
<span class="nt">&#34;plain_http_response&#34;</span><span class="p">:</span> <span class="s2">&#34;&#34;</span><span class="p">,</span>
<span class="nt">&#34;fallback_addr&#34;</span><span class="p">:</span> <span class="s2">&#34;127.0.0.1&#34;</span><span class="p">,</span>
<span class="nt">&#34;fallback_port&#34;</span><span class="p">:</span> <span class="mi">80</span><span class="p">,</span>
<span class="nt">&#34;fingerprint&#34;</span><span class="p">:</span> <span class="s2">&#34;&#34;</span>
<span class="p">},</span>
<span class="nt">&#34;tcp&#34;</span><span class="p">:</span> <span class="p">{</span>
<span class="nt">&#34;no_delay&#34;</span><span class="p">:</span> <span class="kc">true</span><span class="p">,</span>
<span class="nt">&#34;keep_alive&#34;</span><span class="p">:</span> <span class="kc">true</span>
<span class="p">}</span>
<span class="p">}</span>
</code></pre></td></tr></table>
</div>
</div><p>配置Trojan-Go开机自启服务</p>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">vi /lib/systemd/system/trojan-go.service
</code></pre></td></tr></table>
</div>
</div><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt"> 1
</span><span class="lnt"> 2
</span><span class="lnt"> 3
</span><span class="lnt"> 4
</span><span class="lnt"> 5
</span><span class="lnt"> 6
</span><span class="lnt"> 7
</span><span class="lnt"> 8
</span><span class="lnt"> 9
</span><span class="lnt">10
</span><span class="lnt">11
</span><span class="lnt">12
</span><span class="lnt">13
</span><span class="lnt">14
</span><span class="lnt">15
</span><span class="lnt">16
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-service" data-lang="service"><span class="k">[Unit]</span>
<span class="na">Description</span><span class="o">=</span><span class="s">Trojan-Go - An unidentifiable mechanism that helps you bypass GFW</span>
<span class="na">Documentation</span><span class="o">=</span><span class="s">https://p4gefau1t.github.io/trojan-go</span>
<span class="na">After</span><span class="o">=</span><span class="s">network.target nss-lookup.target</span>
<span class="k">[Service]</span>
<span class="na">CapabilityBoundingSet</span><span class="o">=</span><span class="s">CAP_NET_ADMIN CAP_NET_BIND_SERVICE</span>
<span class="na">AmbientCapabilities</span><span class="o">=</span><span class="s">CAP_NET_ADMIN CAP_NET_BIND_SERVICE</span>
<span class="na">NoNewPrivileges</span><span class="o">=</span><span class="s">true</span>
<span class="na">ExecStart</span><span class="o">=</span><span class="s">/etc/trojan-go/bin/trojan-go -config /etc/trojan-go/conf/server.json</span>
<span class="na">Restart</span><span class="o">=</span><span class="s">on-failure</span>
<span class="na">RestartSec</span><span class="o">=</span><span class="s">10s</span>
<span class="na">LimitNOFILE</span><span class="o">=</span><span class="s">infinity</span>
<span class="k">[Install]</span>
<span class="na">WantedBy</span><span class="o">=</span><span class="s">multi-user.target</span>
</code></pre></td></tr></table>
</div>
</div><div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span><span class="lnt">5
</span><span class="lnt">6
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash">systemctl <span class="nb">enable</span> trojan-go
systemctl daemon-reload
systemctl start trojan-go
systemctl status trojan-go
journalctl -u trojan-go -n <span class="m">20</span> -f
</code></pre></td></tr></table>
</div>
</div><h2 id="bbrcake">BBR+cake</h2>
<div class="highlight"><div class="chroma">
<table class="lntable"><tr><td class="lntd">
<pre tabindex="0" class="chroma"><code><span class="lnt">1
</span><span class="lnt">2
</span><span class="lnt">3
</span><span class="lnt">4
</span><span class="lnt">5
</span><span class="lnt">6
</span><span class="lnt">7
</span><span class="lnt">8
</span></code></pre></td>
<td class="lntd">
<pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="nb">echo</span> <span class="s1">&#39;net.core.default_qdisc=cake&#39;</span> <span class="p">|</span> tee -a /etc/sysctl.conf
<span class="nb">echo</span> <span class="s1">&#39;net.ipv4.tcp_congestion_control=bbr&#39;</span> <span class="p">|</span> tee -a /etc/sysctl.conf
sysctl -p
lsmod <span class="p">|</span> egrep bbr
reboot
</code></pre></td></tr></table>
</div>
</div></content>
</entry>
<entry>
<title type="text">Hello World</title>
<link rel="alternate" type="text/html" href="https://example.com/posts/hello-world/" />
<id>https://example.com/posts/hello-world/</id>
<updated>2022-01-11T17:07:42+08:00</updated>
<published>2022-01-11T17:07:42+08:00</published>
<author>
<name>iaeieue</name>
<uri>https://example.com/</uri>
<email>[email protected]</email>
</author>
<rights>[CC BY-NC-SA 4.0](https://creativecommons.org/licenses/by-nc-sa/4.0/deed.zh)</rights><summary type="html"></summary>
<content type="html"></content>
</entry>
</feed>