PVE web portal hardening

2025-01-09 作者:

本文:配置fail2ban实现PVE web登录入口的暴破防护。

On a Proxmox VE host accessible to the public internet, using fail2ban to protect SSH away from malicious traffic is fairly common, but what about the web management portal?

I’ve got a blog post talking about that, which seems promising. However it’s already version 8.x, I’m learning something about journald, and so far it’s good to me – I don’t want reinstall the rsyslog just for this, then how can I get it work? Let’s find out.

WHAT HAPPENED

Daily routine, check the system journal with something like journalctl --since='yesterday' .

CUSTOMIZED CONF FOR FAIL2BAN

The filter rule of  /etc/fail2ban/filter.d/pvedaemon.conf .

Then enable the jail in  /etc/fail2ban/jail.local .

CHECK THE RESULT

Restart the fail2ban service, here it goes.

Then we can also check the  iptables -nvL and  fail2ban.log for some more detail – try it by yourself, could be interesting.

References: 1 2

完整阅读本篇»

Pi 5b运行Proxmox VE

2024-12-09 作者:

使用Proxmox-Port,成功在Pi 5b上搞起PVE。

其上又装了个Arch、Rocky9和WoA(Windows on Arm),把host和三个vm都塞进一张32G tf卡,加之WoA的一些特定配置,过程是崎岖了一点,但结果还是显而易见的 —— 这一天还是来了,PVE on aarch64。

Arm Linux KVM再带Linux vm是蛮有实际意义的,家里已经用了两年多了(外加incus容器),只不过那块RK3399没搞pve,用的是更传统的libvirt。

pi 5b走kvm虚拟化运行arch和win两台vm

得益于树莓派5b不错的性能,简单操作一下WoA,体验上也不再是行为艺术。至于WoA本身是不是行为艺术,只能说高通的X Elite明显还是拖不动微软的意兴阑珊,不由得让人想起当年Nokia、木马哥和Win Phone的那场爱恨情仇。

完整阅读本篇»

RK3566流畅运行X64 win应用?

2024-04-05 作者:

Well, Windows x64 binaries now mostly seem to be working well on Wine (x64, Dynarec for ARM64) on Incus/LXC containers on Armbian aarch64 on an ARM SBC like RasPi or its counterparts with Rockchip RK3xxx series processors.

Btw, let’s celebrate the 1st LTS release of Incus, version 6.0.


在Linux平台使用wine运行win32程序?

Wine项目距今30多年历史了,完全不稀奇。

如果是跑在Linux arm64/aarch64上呢?

也还好……纯软件转译x86指令集,应该跑的像幻灯片吧?之前你不是KVM装过一次Win7 x64,玩成了行为艺术咩?

如果是一张价钱不足100块的RK3566 sbc,先跑Armbian,其上跑incus(lxc)容器,再跑Wine x64,最后运行Win64程序,然后我说除了启动慢点儿(毕竟emmc就那点io),运行还蛮流畅,您怎么想?

完整阅读本篇»

RK3566之armvirt转发能力

2024-03-02 作者:

一言以蔽之,同用双核,略逊Pi 4B,明显不如RK3399。虽然制程和频率双双强过BCM2711(Pi 4B),但A55相比A72应该还是有明显差距的…吧,当然发行版对比也略有差异(尽管都基于debian),无法精确对比哈。

至于想劝俺上什么iStoreOS就算了,原因在之前提过,尽管估计物理跑NAT(开启软件流量分载)大概率能接近跑满千兆转发,但选型喜好是很个人的事情,总觉得所谓all-in-one在架构上反过来(upside down)不好玩。

数据上,iperf3上行700左右,下行850,看起来即使另外两核跑个容器带点儿负载,保障个500Mbps宽带应该没啥鸭梨。

完整阅读本篇»

从lxd迁移到incus

2024-02-27 作者:

Let’s talk about migration from lxd to incus. As for the reason, well I guess we have seen too much of this kinda “show” in the past half decade (just like CentOS to Rocky) so here is what happened in case you’re interested.

Technically I won’t take this as a tutorial since with the well-prepared tool lxd-to-incus by Stéphane Graber (Author of both lxd and incus) there’s nothing to do but simply running it, then everything seems working well.

PS: Tested PASS on both Debian Bookworm AMD64 (on Linux KVM based vm) and Armbian Bookworm ARM64 (on RK3566 based SBC).

这些年,同类剧本真是没少看。一言不合就闭源,一言不合就拉分支,完全不新鲜,具体就不多说了,开工干活。其实吧,作者给了迁移工具 lxd-to-incus ,所以实话说没啥可干的,执行一下就可以验证迁移后的结果了。


先检查系统现状。Check the system status at first.

然后根据文档,安装incus。Now install the incus (by Zabbly) according to the documentation.

从安装过程看,至少创建了一个用户,两个组,以及不少于6个systemd服务。

完整阅读本篇»

Rasp Pi 5B vs. Intel N100?

2024-01-15 作者:

我先给一句话总结,之后再慢慢解释:

当两个不同的细分市场的产品,在各自的领域站稳脚跟(也即拿到主要份额)后,无论出于产品代次的需要、抵御外部威胁的需要、抑或资本市场的需要,均会体现出向另外一个领域渗透的特征。

 

Talking about a specific industry, when different products designed for different market segments obtained dominant shares of their own segments, almost every of them would consider invading neighbors (segments around) – no matter the needs come from product roadmap, external threats or even the capital market.

解释:一个字,卷。


最近有人问我,自制软路由/NAS是买arm还是x86_64。如果是小10年(Pi 2B上市)甚至5年前,我只会说,萝卜青菜各有所爱,不可一概而论,还得看需求更关注什么。

前者具备体积、功耗/散热、价格、专芯专用(如hw-nat)的优势,后者则表现出强性能、AIO的独特能力。

而放眼如今,早已是 –

“双兔傍地走,安能辨我是雄雌。”

 

Pi 5B和N100,以极其接近的价格,差不多两倍的功耗,给出了差不多2倍的性能 – 选择再也不如之前那般容易。

  • BCM2712/RK3588性能有限么?干掉一个6~7代的移动版i5应该不是问题。
  • Pi 5B还能被动散热么?对不起,3B那个连廉价散热片都可以不贴的时代已经过去了。
  • ARM还是只能docker不能vm么?哦,不仅kvm没问题(虽不见得有VT-x/AMD-V的性能),听说外设直通都有眉目了。
  • 我家弱电箱还是太小了,x86不能让我凿墙吧?巴掌大还带双SFP+来一套?(PS:别期待万兆小包跑满)

完整阅读本篇»