private:emcc:infrastruktura
Rozdíly
Zde můžete vidět rozdíly mezi vybranou verzí a aktuální verzí dané stránky.
| Obě strany předchozí revizePředchozí verzeNásledující verze | Předchozí verze | ||
| private:emcc:infrastruktura [2023/11/07 06:11] – [Hosting - CoolHousing] snemec | private:emcc:infrastruktura [2025/09/09 05:34] (aktuální) – [Kralupy kancl] snemec | ||
|---|---|---|---|
| Řádek 1: | Řádek 1: | ||
| + | ====== CESX server Ktiš ====== | ||
| + | |||
| + | Server Supermicro x11ssm-f, v provozu od 12.2018 | ||
| + | |||
| + | https:// | ||
| + | |||
| + | X11SSM-F - SUPERMICRO MB s1151 C236, | ||
| + | BX80677E31270V6 - INTEL Xeon E3-1270 v6 Kaby Lake / 4 jádra / 3,8 GHz / 8MB / LGA1151\\ | ||
| + | M391A2K43BB1-CRC - SAMSUNG 16GB DDR4 2400 2Rx8 ECC UDIMM 4ks\\ | ||
| + | |||
| + | ====== IP adresace ====== | ||
| + | |||
| + | IPMI: https:// | ||
| + | PROXMOX: https:// | ||
| + | PROXMOX-MAILGW: | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | |||
| + | **Disky: | ||
| + | |||
| + | < | ||
| + | root@ubuntu:/ | ||
| + | Disk /dev/sda: 111.8 GiB, 120034123776 bytes, 234441648 sectors | ||
| + | Disk /dev/sdc: 1.8 TiB, 2000398934016 bytes, 3907029168 sectors | ||
| + | Disk /dev/sdd: 1.8 TiB, 2000398934016 bytes, 3907029168 sectors | ||
| + | Disk /dev/sdb: 111.8 GiB, 120034123776 bytes, 234441648 sectors | ||
| + | Disk /dev/sde: 1.8 TiB, 2000398934016 bytes, 3907029168 sectors | ||
| + | Disk /dev/sdg: 1.8 TiB, 2000398934016 bytes, 3907029168 sectors | ||
| + | Disk /dev/sdh: 1.8 TiB, 2000398934016 bytes, 3907029168 sectors | ||
| + | Disk /dev/sdf: 1.8 TiB, 2000398934016 bytes, 3907029168 sectors | ||
| + | </ | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | ===== Restart serveru ===== | ||
| + | |||
| + | Po restartu je potřeba zkontrolovat, | ||
| + | |||
| + | < | ||
| + | root@ubuntu:/ | ||
| + | default via 81.2.210.1 dev eno1 proto static | ||
| + | 10.6.0.0/24 via 10.13.238.10 dev lxdbr0 | ||
| + | 10.13.238.0/ | ||
| + | 81.2.210.0/ | ||
| + | 81.2.210.128/ | ||
| + | </ | ||
| + | |||
| + | a že se nastartoval firewall v LXC containeru '' | ||
| + | |||
| + | < | ||
| + | lxc exec ovpn -- bash | ||
| + | |||
| + | iptables -L | ||
| + | </ | ||
| + | |||
| + | |||
| + | ===== Seznam kontejnerů ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | root@cesx: | ||
| + | 100 running | ||
| + | 103 running | ||
| + | 104 running | ||
| + | 109 running | ||
| + | 110 running | ||
| + | 119 running | ||
| + | |||
| + | |||
| + | ALL | ||
| + | |||
| + | VMID | ||
| + | 100 running | ||
| + | 101 stopped | ||
| + | 102 stopped | ||
| + | 103 running | ||
| + | 104 running | ||
| + | 105 stopped | ||
| + | 106 stopped | ||
| + | 107 stopped | ||
| + | 108 stopped | ||
| + | 109 running | ||
| + | 110 running | ||
| + | 111 stopped | ||
| + | 112 stopped | ||
| + | 113 stopped | ||
| + | 114 stopped | ||
| + | 115 stopped | ||
| + | 116 stopped | ||
| + | 117 stopped | ||
| + | 118 stopped | ||
| + | 119 running | ||
| + | </ | ||
| + | |||
| + | Konfigurace pro '' | ||
| + | |||
| + | < | ||
| + | root@cesx: | ||
| + | arch: amd64 | ||
| + | cores: 1 | ||
| + | hostname: HAProxy | ||
| + | memory: 4096 | ||
| + | net0: name=eth0, | ||
| + | ostype: debian | ||
| + | rootfs: vspool03: | ||
| + | swap: 512 | ||
| + | |||
| + | root@cesx: | ||
| + | arch: amd64 | ||
| + | cores: 1 | ||
| + | hostname: HAProxy | ||
| + | memory: 4096 | ||
| + | net0: name=eth0, | ||
| + | ostype: debian | ||
| + | rootfs: vspool03: | ||
| + | swap: 512 | ||
| + | |||
| + | root@cesx: | ||
| + | arch: amd64 | ||
| + | cores: 2 | ||
| + | hostname: thematrade-sklad | ||
| + | memory: 8192 | ||
| + | net0: name=eth0, | ||
| + | ostype: debian | ||
| + | rootfs: vspool03: | ||
| + | swap: 4096 | ||
| + | |||
| + | root@cesx: | ||
| + | arch: amd64 | ||
| + | cores: 1 | ||
| + | features: nesting=1 | ||
| + | hostname: ovpn | ||
| + | memory: 4096 | ||
| + | net0: name=eth0, | ||
| + | ostype: debian | ||
| + | rootfs: vspool01: | ||
| + | swap: 4096 | ||
| + | |||
| + | root@cesx: | ||
| + | arch: amd64 | ||
| + | cores: 4 | ||
| + | hostname: mailgwprx | ||
| + | memory: 8192 | ||
| + | net0: name=eth0, | ||
| + | ostype: debian | ||
| + | rootfs: vspool02: | ||
| + | swap: 8192 | ||
| + | |||
| + | </ | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | ===== Blejd servery Sitel ===== | ||
| + | |||
| + | ==== BLEJD01 ==== | ||
| + | |||
| + | **IP WAN:** 81.2.210.7 - dočasná adresa\\ | ||
| + | **IP LAN:** 192.168.133.11\\ | ||
| + | **IP LXD:** 10.115.144.1\\ | ||
| + | |||
| + | === LXC Containery === | ||
| + | |||
| + | bankerat01, dokuwiki, mailgw02, mailsrv, nextcloud, www02 | ||
| + | |||
| + | === Záloha === | ||
| + | |||
| + | LXD kontejnery jsou uloženy na ZFS poolu.\\ | ||
| + | Každý kontejner je zálohován pomocí lokálního zfs snapshotu.\\ | ||
| + | Jednou denně se provádí replikace poolu na sousední server - BLEJD01 a na BCKSERVER v Kralupech. | ||
| + | |||
| + | Replikace na srv. BLEJD02\\ | ||
| + | / | ||
| + | Replikace na srv. BCKSRV\\ | ||
| + | / | ||
| + | | ||
| + | |||
| + | ==== BLEJD02 ==== | ||
| + | |||
| + | **IP WAN:** 81.2.210.108\\ | ||
| + | **IP LAN:** 192.168.133.12\\ | ||
| + | **IP LXD:** 10.115.145.1\\ | ||
| + | |||
| + | === LXC Containery === | ||
| + | |||
| + | aspvwp, fastech, mailgw01, skolawp, wiki, www, www-staticpages, | ||
| + | |||
| + | === Záloha === | ||
| + | |||
| + | LXD kontejnery jsou uloženy na ZFS poolu.\\ | ||
| + | Každý kontejner je zálohován pomocí lokálního zfs snapshotu.\\ | ||
| + | Jednou denně se provádí replikace poolu na sousední server - BLEJD01 a na BCKSERVER v Kralupech. | ||
| + | |||
| + | Replikace na srv. BLEJD01\\ | ||
| + | / | ||
| + | Replikace na srv. BCKSRV\\ | ||
| + | / | ||
| + | |||
| + | ===== Bios update ===== | ||
| + | |||
| + | **Servery Asrock e3c224d4i-14s** | ||
| + | |||
| + | https:// | ||
| + | |||
| + | Po provedení aktualizace bios(u) jeden server nenaběhl. IPMI bylo funkční, bylo možné se dostat do menu bios(u), ale server nenabootoval. Vypadalo to, že při pokus nabootovat " | ||
| + | |||
| + | Po opětovném provedení update biosu se závada odstranila. | ||
| + | |||
| + | |||
| + | ===== ISPConfig ===== | ||
| + | |||
| + | ISPConfig: https:// | ||
| + | PHPMyAdmin: https:// | ||
| + | |||
| + | ===== Backup log ===== | ||
| + | |||
| + | Informace o stavu záloh\\ | ||
| + | |||
| + | http:// | ||
| + | |||
| + | |||
| + | ====== Kralupy kancl ====== | ||
| + | |||
| + | **OLD** Veřejná IP - KNVNET do 21.5.2025: 89.239.25.64\\ | ||
| + | **Veřejná IP - KNVNET od 21.5.2025: | ||
| + | |||
| + | ===== Router KNV-NET ===== | ||
| + | |||
| + | |||
| + | **Huawei HG8245H**\\ | ||
| + | |||
| + | Router od KNVNET. | ||
| + | Dostupný přes VPN na adrese http:// | ||
| + | Na routeru je nastaven port forwarding na linux FW Krafwka. | ||
| + | |||
| + | ===== Switch Mikrotik | ||
| + | |||
| + | |||
| + | http:// | ||
| + | |||
| + | |||
| + | ===== Backup servery ===== | ||
| + | |||
| + | |||
| + | IP: 10.199.1.50 - old - bežné PC - původně jako CESX v Sitelu\\ | ||
| + | |||
| + | IP: 10.199.1.51 - ASROCK 32GB 8x4TB HDD - ZFS RaidZ2 - dostupný diskový prostor cca 20TB\\ | ||
| + | OS: Debian 10\\ | ||
| + | IPMI: http:// | ||
| + | |||
| + | ===== PPTP VPN ===== | ||
| + | |||
| + | **Linux Krafwka**\\ | ||
| + | <code bash / | ||
| + | option / | ||
| + | logwtmp | ||
| + | localip 10.199.5.201 | ||
| + | remoteip 10.199.5.202-220, | ||
| + | </ | ||
| + | |||
| + | <code bash / | ||
| + | # Secrets for authentication using CHAP | ||
| + | # client | ||
| + | |||
| + | lamauser01 | ||
| + | lamauser02 | ||
| + | iauser01 | ||
| + | buser01 | ||
| + | </ | ||
| + | |||
| + | |||
| + | **Mikrotik**\\ | ||
| + | {{: | ||
| + | {{: | ||
| + | {{: | ||
| + | |||
| + | |||
| + | |||
| + | ==== Kralupy test server Intel - IPMI - PROXMOX ==== | ||
| + | |||
| + | **IPMI IP:** http:// | ||
| + | **MAC:** 00: | ||
| + | **Proxmox IP: **https:// | ||
| + | ===== Etherwake NB Lenovo Kralupy ===== | ||
| + | |||
| + | Na **fw krafka** je ve složce / | ||
| + | |||
| + | ===== Mail server POKR - iredmail ===== | ||
| + | Testovací mail server\\ | ||
| + | IP: 10.199.1.151\\ | ||
| + | iredadmin: https:// | ||
| + | mail: https:// | ||
| + | ==== Certifikaty LE ==== | ||
| + | |||
| + | https:// | ||
| + | |||
| + | |||
| + | ==== SPF, DKIM, DMARC ==== | ||
| + | |||
| + | https:// | ||
| + | |||
| + | **DNS záznamy**\\ | ||
| + | https:// | ||
| + | |||
| + | https:// | ||
| + | |||
| + | |||
| + | |||
| + | ==== Konfigurační záznamy - umístění ==== | ||
| + | |||
| + | https:// | ||
| + | |||
| + | |||
| + | ===== Hosting - CoolHousing ===== | ||
| + | |||
| + | Coolhouse, hosting | ||
| + | |||
| + | https:// | ||
| + | |||
| + | **Administrace: | ||
| + | https:// | ||
| + | |||
| + | IP: 87.236.197.237, | ||
| + | |||
| + | **Server Dell PowerEdge R620 ** | ||
| + | |||
| + | **iDrac je vypnutý** | ||
| + | iDrac: https:// | ||
| + | root/ | ||
| + | |||
| + | Proxmox: https:// | ||
| + | 2 x CPU, 128GB RAM, 2 x 1TB SSD, 2 x 4TB SSD\\ | ||
| + | Přístup povolen z Kralup a Veltrus\\ | ||
| + | |||
| + | |||
| + | Rozmístění disků\\ | ||
| + | {{: | ||
| + | |||
| + | - SSD 1TB - Boot disk - sda | ||
| + | - SSD 1TB - zatím nepoužitý | ||
| + | - SSD 4TB - ZFS mirror | ||
| + | - SSD 4TB - ZFS mirror | ||
| + | |||
| + | sda:\\ | ||
| + | Model Family: | ||
| + | Device Model: | ||
| + | Serial Number: | ||
| + | |||
| + | sdb:\\ | ||
| + | Model Family: | ||
| + | Device Model: | ||
| + | Serial Number: | ||
| + | |||
| + | sdc:\\ | ||
| + | Model Family: | ||
| + | Device Model: | ||
| + | Serial Number: | ||
| + | |||
| + | sdd:\\ | ||
| + | Model Family: | ||
| + | Device Model: | ||
| + | Serial Number: | ||
| + | |||
| + | |||
| + | V serveru je flash Bios radice Perc H710 mini - řadic je nastaven v transparentním módu\\ | ||
| + | https:// | ||
| + | |||
| + | |||
| + | ==== Poštovni server - postak ==== | ||
| + | |||
| + | Poštovní server iRedMail\\ | ||
| + | Administrace\\ | ||
| + | URL: https:// | ||
| + | |||
| + | RoundCube\\ | ||
| + | URL: https:// | ||
| + | |||
| + | MailGW - Proxmox Mail Gateway - PMG\\ | ||
| + | URL: https:// | ||
| + | |||
| + | |||
| + | |||
| + | |||
