1 .ssh[edit | edit source]
mkdir .ssh then use sftp to pull in contents from another system.
2 sudoers[edit | edit source]
Activate wheel with no password
3 grub[edit | edit source]
# vi /etc/default/grub
GRUB_TERMINAL_INPUT="console serial"
GRUB_TERMINAL_OUTPUT="console serial"
GRUB_CMDLINE_LINUX="crashkernel=auto resume=/dev/mapper/V0uv029-swap rd.lvm.lv=V0uv029/root rd.lvm.lv=V0uv029/swap console=ttyS0"
GRUB_SERIAL_COMMAND="serial --unit=0 --speed=115200 --word=8 --parity=no --stop=1"For RHEL 9, the GRUB_CMDLIN_LINUX needs to end with console=tty0 console=ttyS0,115200
# grub2-mkconfig -o /boot/grub2/grub.cfg
But for Rocky 9.3 and later, an extra qualifier is needed:
# grub2-mkconfig -o /boot/grub2/grub.cfg --update-bls-cmdline
4 dnf and files in /etc/yum.repos.d[edit | edit source]
# yum install wget
#
# #for CentOS
# mv CentOS-Linux-AppStream.repo CentOS-Linux-AppStream.repo-ORIG
# echo > CentOS-Linux-AppStream.repo
# mv CentOS-Linux-BaseOS.repo CentOS-Linux-BaseOS.repo-ORIG
# echo > CentOS-Linux-BaseOS.repo
# wget http://wort/KitsNet/KitsNet-v8.repo
#
# #for Rocky v8
# mv Rocky-AppStream.repo Rocky-AppStream.repo-ORIG
# echo > Rocky-AppStream.repo
# mv Rocky-BaseOS.repo Rocky-BaseOS.repo-ORIG
# echo > Rocky-BaseOS.repo
# wget http://wort/KitsNet/KitsNet-Rv8.repo
#
# #for Rocky v9
# wget http://wort/KitsNet/KitsNet-Rv9.repo
# mv rocky.repo rocky.repo-ORIG
# cp rocky.repo-ORIG rocky.repo
# #manually edit rocky.repo to comment out [baseos] and [appstream] stanzas
#
# dnf clean all
# dnf list
5 Packages, packages, packages...[edit | edit source]
# dnf install -y epel-release
# dnf config-manager --set-enabled powertools #(prior to Rocky Linux 9.0)
# dnf config-manager --enable crb #(Rocky Linux 9.0 onward)
# dnf install -y yum-utils net-tools lsof rsync vnstat screen sysstat ncdu vim bind-utils python3 vim dnf-automatic glances
The first KitsNet build with Rocky Linux v8.4 generated a system without rsyslog installed nor syslog started. As a result, most logs from /var/log were missing. dnf install rsyslog installed the missing packages and enabled and started the service.
6 Fix glances[edit | edit source]
As per disk_io_counters() fails on Linux kernel 4.19, there is a bug in the psutil python module that causes it to fail on reporting Disk I/O counters in newer kernels. This in turn causes the glances utility to fail to report Disk I/O counters. The fix is to patch the _pslinux.py file in the psutil module.
# ls -al /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
-rw-r--r--. 1 root root 74870 Jul 3 09:56 /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
# grep "fields_len == 14" /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
elif fields_len == 14:
# sed -i 's#fields_len == 14:#fields_len == 14 or fields_len == 18:#g' /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
# grep "fields_len == 14" /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
elif fields_len == 14 or fields_len == 18:
7 python[edit | edit source]
# alternatives --set python /usr/bin/python3 #Prior to Rocky Linux 9 only
8 chrony/ntp configuration[edit | edit source]
See https://www.golinuxcloud.com/configure-chrony-ntp-server-client-force-sync/ for more information.
Edit /etc/chrony.conf to bypass pool, enable log and allow 192.168.0.0/16 statements
As of 10/3/2023, radix has defined CNAMEs for time, time1 and time2, pointing to wort, courvoisier and radix respectively. Probably should be using these in the server statements, unless DHCP is actually passing the NTP servers properly. server statement should have the iburst parameter as well to make initial sync more timely.
# systemctl restart chronyd
# systemctl status chronyd
# timedatectl
# chronyc tracking
# chronyc activity
9 logwatch[edit | edit source]
# dnf install -y logwatch
# vi /etc/logwatch/conf/logwatch.conf
Add line: Format = html
10 rsyslog[edit | edit source]
Add to the end of /etc/rsyslog.conf the line: *.* @192.168.15.80:514 and restart the rsyslog service.
11 postfix[edit | edit source]
Update /etc/aliases with reroot@lan.kitsnet.us then
# dnf install -y postfix
# newaliases
# systemctl enable postfix --now
# systemctl status postfix
12 Zabbix client[edit | edit source]
# firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.15.64/32" port protocol="tcp" port="10050" accept'
# firewall-cmd --permanent --add-rich-rule='rule family="ipv6" port port="10050" protocol="tcp" accept'
# firewall-cmd --reload
# dnf install -y https://repo.zabbix.com/zabbix/5.0/rhel/8/x86_64/zabbix-release-5.0-1.el8.noarch.rpm
# #(for Rocky 9 use https://repo.zabbix.com/zabbix/5.0/rhel/9/x86_64/zabbix-release-5.0-3.el9.noarch.rpm)
# #(for CentOS 7 use https://repo.zabbix.com/zabbix/5.0/rhel/7/x86_64/zabbix-release-5.0-1.el7.noarch.rpm)
# dnf clean all
# dnf install -y zabbix-agent2
# vi /etc/zabbix/zabbix_agent2.conf
Change the two lines with server IP address and Hostname directove:
Server=192.168.15.0/24,zoco.lan.kitsnet.us,2603:7000:9800:4742::e04,fd06:8328:ea57::e04
ServerActive=zabbix.lan.kitsnet.us
#Hostname=Zabbix server
save and then:
# systemctl enable zabbix-agent2 --now
13 Automatic updates[edit | edit source]
The configuration file is /etc/dnf/automatic.conf Set apply_updates = yes
# sudo systemctl enable --now dnf-automatic.timer
# systemctl list-timers *dnf-*
14 Backup[edit | edit source]
14.1 Install Veeam and scripts[edit | edit source]
# #do either
# dnf install -y http://wort/KitsNet/Veeam/veeam-release-el8-1.0.8-1.x86_64.rpm && dnf check-update -y
# #or
# dnf install -y http://wort/KitsNet/Veeam/veeam-release-el9-1.0.8-1.x86_64.rpm && dnf check-update -y
# dnf install -y veeam nfs-utils KNveeam
Clean install with Rocky 9 was weird last time (3/17/2023). The wrong version of blksnap installed. To get it right, I had to explicitly reference blksnap at the head of the dnf install list that included veeam.
14.2 Prep NFS export on \bkup[edit | edit source]
# mkdir /backups/Linux/newhost
# vi /etc/exports
Add line: /backups/Linux/newhost newhost(rw,sync,no_root_squash,no_all_squash) 192.168.15.##(rw,sync,no_root_squash,no_all_squash)
# exportfs -ra
14.3 Configure Veeam Backup Job[edit | edit source]
- Jobname
<Newhost>-all - Destination: Shared folder to NFS path
bkup/ backups/Linux/<newhost> - Advanced, Scripts, Post-job
/usr/local/sbin/veeam_backup_status-email - For Active Directory Domain Controllers, specify a the Pre-job script as
/usr/local/sbin/backup_samba-ad-dc - A reboot is necessary before running the first backup on el9 based systems in order to load the necessary modules to support snapshots
15 Housekeeping[edit | edit source]
15.1 Install miscellaneous KitsNet tools[edit | edit source]
# dnf install -y KNsysmisc
15.2 Schedule check for current kernel version[edit | edit source]
Add the following entry to the root crontab
0 0 * * * sleep $(( RANDOM \% 14400)); /usr/local/sbin/KernelCurrent -r
This form will reboot the system if the kernel is found to be out of date.