[步骤] WordPress 静态网站的生成 (离线使用版的静态网站)

步骤一:在本地电脑上安装必要的软件

1.1 在本地电脑上下载并安装 LocalWP 软件

登录此网站以后点击下载并安装

Home

(步骤略)

1.2 在本地电脑上下载并安装 Traktor 软件

登录此网站以后点击下载并安装

https://traktor.wp-migration.com

(步骤略)

步骤二:在 WordPress 网站上安装必要的插件

2.1 在正式的 WordPress 网站上安装 All-in-One WP Migration and Backup 插件

登录 WordPress 后台 –> Plugins –> Add plugin –> 在 Search PLugin 的文字栏里输入 “All-in-One WP Migration and Backup” –> 按下回车键 –> Install Now

2.2 在正式的 WordPress 网站上安装 Simply Static 插件

登录 WordPress 后台 –> Plugins –> Add plugin –> 在 Search PLugin 的文字栏里输入 “Simply Static” –> 按下回车键 –> Install Now

步骤三:在正式的 WordPress 网站上设置 Simply Static 插件

3.1 在正式的 WordPress 网站上激活 Simply Static 插件

登录 WordPress 后台 –> Plugins –> Installed Plugins –> Simply Static –> Activate

3.2 在正式的 WordPress 网站上将 Simply Static 插件的 Replacing URLs 修改为 Offline Usage

登录 WordPress 后台 –> Simply Static –> Settings –> General –> Replacing URLs –> Offline Usage –> 将网页下拉到底 –> Save Settings

(注意:一定要点击 Save Settings 否则此步骤将白做)

3.3 在正式的 WordPress 网站上禁用 Simply Static 插件

登录 WordPress 后台 –> Plugins –> Installed Plugins –> Simply Static –> Deactivate

步骤四:在正式的 WordPress 网站上将网站全量备份并下载到本地

4.1 在正式的 WordPress 网站上激活 All-in-One WP Migration and Backup 插件

登录 WordPress 后台 –> Plugins –> Installed Plugins –> All-in-One WP Migration and Backup –> Activate

4.2 在正式的 WordPress 网站上生成并下载网站的全量备份文件包

登录 WordPress 后台 –> All-in-One WP Migration –> Export –> EXPORT SITE TO –> FILE –> 等待进程完成后点击下载 –> CLOSE

(注意:成功备份后生成的网站的全量备份文件包会以 xpress 后缀结尾)

4.3 在正式的 WordPress 网站上删除存留的文件(必须要做)

登录 WordPress 后台 –> All-in-One WP Migration –> Export –> Backups –> … –> Delete — OK

4.4 在正式的 WordPress 网站上禁用 All-in-One WP Migration and Backup 插件 (必须要做)

登录 WordPress 后台 –> Plugins –> Installed Plugins –> All-in-One WP Migration and Backup –> Deactivate

(补充:此步骤必须要做,目的是为了避免等会将备份文件错误地恢复到正式的 WordPress 网站上)

步骤五:退出正式的 WordPress 网站后台 (必须要做)

位于右上角的头像 –> Log Out

(补充:此步骤必须要做,目的是为了避免等会将备份文件错误的恢复到正式的 WordPress 网站上)

步骤六:彻底关闭正式的 WordPress 网站的网页 (必须要做)

(步骤略)

(补充:此步骤必须要做,目的是为了避免等会将备份文件错误的恢复到正式的 WordPress 网站上)

步骤七:在本地电脑使用 Traktor 软件检验网站的全量备份文件包是否完整

7.1 在本地电脑使用 Traktor 软件检验网站的全量备份文件包是否完整

打开 Tracktor 软件 –> 将网站的全量备份文件包拖入窗口中

(补充:当窗口右下角的 “Extract to…” 按键从灰色变成白色则代表此文件包通过校验)

(
注意:
1) 这里的全量备份文件包是指步骤 4.2 中下载的文件
2) 校验成功后不要点击 “Extract to…” 按键
3) 全量备份文件包以 xpress 后缀结尾
)

7.2 在本地电脑关闭 Traktor 软件

(步骤略)

步骤八:在本地电脑通过 LocalWP 软件使用网站的全量备份文件包将正式的 WordPress 网站的全部数据恢复到本地的 WordPress 测试网站

8.1 在本地电脑通过 LocalWP 软件创建本地的 WordPress 测试网站

打开 LocalWP 软件 –> Create a new site –> Create a new site –> Continue –> 在 What’s your site’s name 的文字栏里输入:“local” –> Continue –> Preferred –> Continue –> 在 WordPress username 的文字栏里输入:“local” –>
在 WordPress password 的文字栏里输入:“local” –> Add Site

(注意:这里每次输入的 “local” 绝对不能换成和正式的 WordPress 网站相同的对应值,这样做是为了在登录时明白这是新创建的网站,避免将备份文件错误恢复到正式的网站上)

8.2 登录本地的 WordPress 测试网站的后台

点击在 LocalWP 软件的窗口上的 Open site –> 确认网站首页有类似 “Hello world!” 之类的提示是新网站 –> 在浏览器上输入 “http://local.local/wp-login.php” –> Username or Email Address 的文字栏里输入:“local” –> 在 Password 的文字栏里输入:“local” –> Log in

(注意:这里每次输入的 “local” 绝对不能换成和正式的 WordPress 网站相同的对应值,否则你有可能会进入正式的网站上然后进行误操作然后造成不可挽回的后果)

8.3 在本地的 WordPress 测试网站的后台安装 All-in-One WP Migration and Backup 插件

登录 WordPress 后台 –> Plugins –> Add plugin –> 在 Search PLugin 的文字栏里输入 “All-in-One WP Migration and Backup” –> 按下回车键 –> Install Now

(注意:如果这里的 All-in-One WP Migration and Backup 插件在你安装前就已经安装好了,则代表你有可能进入正式的 WordPress 网站操作,请立即停止此操作并关闭所有网页和浏览器,然后重新开始步骤 8.2)

8.4 在本地电脑通过 LocalWP 软件使用网站的全量备份文件包将正式的 WordPress 网站的全部数据恢复到本地的 WordPress 测试网站

8.4.1 在本地 WordPress 测试网站上激活 All-in-One WP Migration and Backup 插件

登录 WordPress 后台 –> Plugins –> Installed Plugins –> All-in-One WP Migration and Backup –> Activate

8.4.2 在本地电脑通过 LocalWP 软件使用网站的全量备份文件包将正式的 WordPress 网站的全部数据恢复到本地的 WordPress 测试网站

登录 WordPress 后台 –> All-in-One WP Migration –> Import –> IMPORT FROM –> FILE –> 选择 将网站的全量备份文件包 –> Upload –> PROCEED –> FINISH

(注意:这里的全量备份文件包是指步骤 4.2 中下载的文件)

步骤九:在本地电脑立刻删除用完后的网站的全量备份文件包 (必须要做)

(步骤略)

(补充:此步骤必须要做,目的是为了避免等会将备份文件错误的恢复到正式的 WordPress 网站上)

步骤十:在本地电脑立刻在回收站中彻底消灭完后的网站的全量备份文件包 (必须要做)

(步骤略)

(补充:此步骤必须要做,目的是为了避免等会将备份文件错误的恢复到正式的 WordPress 网站上)

步骤十一:在本地 WordPress 测试网站上生成静态网站

11.1 登录使用网站的全量备份文件包还原后的本地 WordPress 测试网站

在浏览器上输入 “http://local.local/login” –> 用你正式的 WordPress 网站的登录信息登录本地 WordPress 测试网站

(补充:这里以正式的 WordPress 网站的后台登录入口后缀是 login 为例,如果登录入口后缀是 wp-login.php 则这里应该输入的网址是 http://local.local/login)

(注意:这里每次输入的 “local” 绝对不能换成和正式的 WordPress 网站相同的对应值,否则你有可能会进入正式的网站上然后进行误操作然后造成不可挽回的后果)

11.2 禁用任何安全插件 (必须要做)

登录 WordPress 后台 –> Plugins –> Installed Plugins –> All-In-One Security (AIOS) –> Deactivate

(补充:这里以禁用 All-In-One Security (AIOS) 安全插件为例)

11.3 激活 Simply Static 插件

登录 WordPress 后台 –> Plugins –> Installed Plugins –> Simply Static –> Activate

11.4 在本地 WordPress 测试网站上生成静态网站

Simply Static –> Generate –> Push –> 等待 Activity Log 窗口里显示 Dong! Finished –> Click here to download

(注意:此步骤会消耗大量时间,最终会下载 1 个以 simply-static 开头的压缩包,此压缩包就是静态网站的压缩包)

11.5 检查本地电脑的垃圾箱确保静态网站的压缩包没有被删除

如果以 simply-static 开头的压缩包在垃圾箱里,则需要把移动到正式的目录里

步骤十二:在本地电脑立刻删除用完后的本地 WordPress 测试网站 (必须要做)

右键点击在 LocalWP 软件的窗口上的 local –> Delete –> 确保 Move site files to trash 前面的勾有勾上 –> Delete site

(补充:此步骤必须要做,目的是为了避免等会将备份文件错误的恢复到正式的 WordPress 网站上)

步骤十三:在本地电脑立刻在回收站中彻底消灭完后的本地 WordPress 测试网站 (必须要做)

(步骤略)

(补充:此步骤必须要做,目的是为了避免等会将备份文件错误的恢复到正式的 WordPress 网站上)

[内容] WordPress 网站数据去隐私化

内容一:修改登录 MariaDB 数据库的用户的密码

1.1 目的

目的是不让拿到这份 WordPress 网站数据的人知道登录数据库的用户的密码

1.2 案例

1.2.1 设置变量
1.2.1.1 要设置的变量

1) WordPress 登录 MariaDB 数据库的用户
2) 登录 MariaDB 数据库的用户的新密码

1.2.1.2 设置变量的命令
# dbuser=ec
# dbuserpw=eternalcenter
1.2.2 执行修改登录 MariaDB 数据库的用户的密码的命令
# mysql -uroot -p'eternalcenter' -e "alter user \"$dbuser\"@\"localhost\" identified by \"$dbuserpw\";"
# sudo sed -i "s/define('DB_PASSWORD', .*);/define('DB_PASSWORD', \'$dbuserpw\');/" wp-config.php

(注意:这里的 ”mysql -uroot -p’eternalcenter’ ……”“ 中 “eternalcenter“ 是指 MariaDB 数据库 root 用户的密码,需要修改成 MariaDB 数据库的 root 用户密码)

内容二:修改 MariaDB 数据库中用于登录 WordPress 网站后台的用户的密码

2.1 目的

目的是不让拿到这份 WordPress 网站数据的人知道登录网站的用户的密码,同时杜绝别人利用存储在 MariaDB 数据库中密码的 HASH 值伪造网站 Cookie 直接绕过用户和密码登录 WordPress 后台

2.2 案例

2.2.1 设置变量
1.2.1.1 要设置的变量

1) 要修改用户密码所在的库
2) 要修改用户密码所在的表
3) 要修改密码的用户
4) 此用户的新密码

1.2.1.2 设置变量的命令
# db=ec
# tb=ec_users
# user='Mingyu Zhu'
# newpw=eternalcenter
1.2.2 执行修改 MySQL 数据库中用于登录 WordPress 网站后台的用户的密码的命令
# mysql -uroot -p'eternalcenter' -e "update $db.$tb set user_pass = md5(\'$newpw\') where user_login = \'$user\';"

(注意:这里的 ”mysql -uroot -p’eternalcenter’ ……”“ 中 “eternalcenter“ 是指 MariaDB 数据库 root 用户的密码,需要修改成 MariaDB 数据库的 root 用户密码)

(补充:当他人想要伪造网站 Cookie 时至少需要 WordPress 网站文件中 AUTH_KEY 等参数的值、MariaDB 数据库中存储的密码的部分 HASH 值、以及 WordPress 网站临时生成的一个 Token,我们这里通过隐藏原网站的密码 HASH 值杜绝他人伪造网站 Cookie)

内容三:修改 WordPress 网站文件中的 AUTH_KEY 等参数的值

杜绝别人利用存储在 WordPress 网站文件的 AUTH_KEY 等参数的值伪造网站 Cookie 直接绕过用户和密码登录 WordPress 后台

3.1 在 WordPress 项目的官方网站上获得一份新的 AUTH_KEY 等参数的值

通过浏览器打开下面的网址

https://api.wordpress.org/secret-key/1.1/salt

(补充:如果网路正常,新的 AUTH_KEY 等参数的值会在浏览器中显示)

3.2 更新 WordPress 网站文件中的 AUTH_KEY 等参数的值

# vi wp-config.php

(用在步骤 3.1 中获取的新值覆盖对应的旧值,步骤略)

(补充:当他人想要伪造网站 Cookie 时至少需要 WordPress 网站文件中 AUTH_KEY 等参数的值、MariaDB 数据库中存储的密码的部分 HASH 值、以及 WordPress 网站临时生成的一个 Token,我们这里通过隐藏原网站的 AUTH_KEY 等参数的值杜绝他人伪造网站 Cookie)

WordPress 值得使用的主题和插件

主题

Twenty Seventeen

Twenty Seventeen 是一个开源的 WordPress 主题,非常适合目录较多的网站,首页能够巧妙地将图片和文字结合在一起。

插件

All-In-One Security (AIOS)

All-In-One Security (AIOS) 是一个开源的 WordPress 安全插件,使用的是和 WordPress 一样的开源协议 GPLv2 (GNU General Public License, version 2),比较全面地对 WordPress 进行安全加强,安装了这个插件以后,基本上就不需要再安装其他安全插件。

(
注意:如果将安装了 All-In-One Security (AIOS) 插件的 WordPress 网站在备份又进行还原后登录后台出现问题,可以直接移走存放这个插件的文件夹

# mv /<the directory of WordPress website files storage>/wp-content/plugins/<the folder of the plugin> /tmp

之后就可以正常登录了,并且登陆地址也还原成 WordPress 的默认登录地址:

http://<Your Website URL>/wp-login.php

)

All-in-One WP Migration and Backup

All-in-One WP Migration and Backup 是一个开源的 WordPress 备份和还原插件,使用的是和 WordPress 一样的开源协议 GPLv2 (GNU General Public License, version 2),可以将此 WordPress 进行全量备份和还原。

(
注意:All-in-One WP Migration and Backup 生成的备份文件的文件后缀是 .wpress。在使用前一定要检查此文件是否完整,检查方法如下:
1) 在 All-in-One WP Migration and Backup 的官网 https://traktor.wp-migration.com 上下载 Tractor 软件进行解压测试,如果解压测试中没有报错则此文件极大概率是完整
2) 在测试环境里进行 WordPress 网站的还原测试,如果还原成功且网站里随机抽查的文章都能正常打开,随机下载的图片都能正常下载,且后台也能登录,则此文件极大概率是完整

必要时可以通过 WordPress 官方修复工具检查和修复 WordPress 数据库,方法如下:

)

Easy Table of Contents

Easy Table of Contents 是一个开源的 WordPress 目录生成插件,使用的是和 WordPress 一样的开源协议 GPLv2 (GNU General Public License, version 2),可以自动将 WordPress 文章的标题转换成文章目录并放在文章前面的插件,不同的标记等级能形成不同的目录等级。

Easy WP SMTP

Easy WP SMTP 是一个开源的 WordPress 邮件插件,可以实现 WordPress 通过 SMTP 发送邮件。

Simply Static

Simply Static 是一个开源的 WordPress 动态网站转静态网站插件,使用的是和 WordPress 一样的开源协议 GPLv2 (GNU General Public License, version 2),可以将动态网站转换成静态网站。

WP-Optimize – Clean, Compress, Cache

WP-Optimize – Clean, Compress, Cache 是一个开源的 WordPress 网站性能优化插件,可以删除无用数据等等。

Health Check & Troubleshooting

Health Check & Troubleshooting 是一个开源的 WordPress 网站健康度检测插件,可以检测网站的各项健康指标。

Username Changer

Username Changer 是一个开源的修改 WordPress 用户名的插件,可以修改用户名

Edit Author Slug

Edit Author Slug 是一个开源的修改 WordPress 用户名下文章链接的插件,可以修改用户发布文章的链接,默认情况下用户发布文章的链接是:https://<domain name>/author/<username>/

[工具] Shell 自动化部署 LNMP + SSL 平台 (Fedora 35 版)

介绍

基本信息

作者:朱明宇
名称:自动化部署 LNMP + SSL 平台
作用:自动化安装 LNMP + SSL,即通过 Linux、Nginx、MariaDB、PHP、php-fpm、SSL,实现 HTTPS

使用方法

1. 将网站的网页数据备份、网站的 SSL 公钥、网站的 SSL 私钥、网站的数据库备份和本脚本,5 个文件放在同一目录下
2. 如果没有网站的数据库备份则将网页数据备份、网站的 SSL 公钥、网站的 SSL 私钥和本脚本,4 个文件放在同一目录下
3. 在此脚本的分割线内写入相应的内容
4. 服务器都要开启 SELinux
5. 给此脚本添加执行权限
6. 执行此脚本:./<此脚本>

脚本分割线里的变量

1. webdomain=”eternalcenter.com” #网站的域名,注意不要在前面加任何前缀
2. webtar=”eternalcenter-backup-*.tar.gz”网站的网页数据备份,如果没有这个备份,可以下载一个开源的 WordPress 网页程序
3. webcrt=”eternalcenter.com.crt” #网站 SSL 的公钥,可以自己创建也可以在 FreeSSL 上申请
4. webkey=”eternalcenter.com.key” #网站 SSL 的私钥,可以自己创建也可以在 FreeSSL 上申请
5. sqlbackup=”eternalcenter-backup-*.sql” #网站数据库数据备份,如果没有这个备份(数据库是全量备份),则这里可以为空
6. db=”ec” #网站在数据库中的库名
7. dbuser=”ec” #网站在数据库中的用户名
8. dbuserpw=”eternalcenter” #网站在数据库中的用户密码
9. dbrootpw=”eternalcenter” #数据库的 root 密码

注意

1. 服务器的系统需要是 Fedora 35 版本
2. 服务器系统要配置好可用的软件源
3. 服务器要能够连接外网

脚本

#!/bin/bash

####################### Separator ########################
webdomain="eternalcenter.com"
webtar="eternalcenter-backup-*.tar.gz"
webcrt="eternalcenter.com.crt"
webkey="eternalcenter.com.key"
sqlbackup="eternalcenter-backup-*.sql"
db="ec"
dbuser="ec"
dbuserpw="eternalcenter"
dbrootpw="eternalcenter"
####################### Separator ########################

#Determine whether SELinux is on
getenforce | grep Enforcing
if [ $? -ne 0 ];then
	echo "SELinux is not set to enforcing mode and cannot continue"
	exit 2
fi

#Determine whether the required file exists
ls $webtar
if [ $? -ne 0 ];then
	echo "No web page data backup, unable to continue"
	exit 2
fi

ls $webcrt
if [ $? -ne 0 ];then
	echo "Cannot continue without site public key"
	exit 2
fi

ls $webkey
if [ $? -ne 0 ];then
	echo "Unable to continue without site private key"
	exit 2
fi

#Update system
yum clean all
yum repolist
yum makecache
yum -y update

#Make sure the required software is installed
yum -y install tar
yum -y install firewalld

#Deploying Nginx
yum -y install nginx

echo 'worker_processes  1;

events {
    worker_connections  1024;
}

http {
    limit_req_zone $binary_remote_addr zone=one:10m rate=1r/s;
    include       mime.types;
    default_type  application/octet-stream;

    sendfile        on;

    keepalive_timeout  60;
    client_body_timeout 20s;
    client_header_timeout 10s;
    send_timeout 30s;

    server {
        listen       80;
        limit_req zone=one burst=5;
        server_name www.eternalcenter.com eternalcenter.com;

        rewrite ^/(.*)$ https://eternalcenter.com/$1 permanent;
      
        error_page   500 502 503 504  /50x.html;
        location = /50x.html {
            root   html;
        }

        }

    server {
        listen       443 ssl;
        server_name www.eternalcenter.com eternalcenter.com;

        if ($request_method !~ ^(GET|POST)$){
        return 444;
        }

        ssl_certificate      /etc/nginx/ssl/eternalcenter.com.crt;
        ssl_certificate_key  /etc/nginx/ssl/eternalcenter.com.key;

        ssl_session_cache    shared:SSL:1m;
        ssl_session_timeout  5m;

        ssl_ciphers  HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers  on;

        location ~ \.php$ {
            fastcgi_pass 127.0.0.1:9000;
            fastcgi_index index.php;
            include fastcgi.conf;
            fastcgi_param  SCRIPT_FILENAME  /usr/share/nginx/html/$fastcgi_script_name;
            include fastcgi_params;
        } 

        location / {
        root html;
        index index.php index.html index.htm;

        if (-f $request_filename/index.html){rewrite (.) $1/index.html break;}
        if (-f $request_filename/index.php){rewrite (.) $1/index.php;}
        if (!-f $request_filename){rewrite (.) /index.php;}
        
        }

        location ~ ^/\.user\.ini {
        deny all;
        }
    
        location ~*\.(jpd|jpeg|gif|png|css|js|ico|xml)$ {
        expires 30d;
        }

        error_page  404              /404.html;

        }

        gzip on;
	gzip_min_length 1000;
	gzip_comp_level 4;
	gzip_types text/plain test/css application/json application/x-javascript text/xml application/xml
	application/xml+rss text/javascripts;

	client_header_buffer_size 1k;
	large_client_header_buffers 4 4k;

	open_file_cache max=2000 inactive=20s;
	open_file_cache_valid  60s;
	open_file_cache_min_uses 5;
	open_file_cache_errors off;

}' > /etc/nginx/nginx.conf

sed -i "s/server_name www.eternalcenter.com eternalcenter.com;/server_name www.$webdomain $webdomain;/" /etc/nginx/nginx.conf
sed -i "s@rewrite ^/(.*)$ https://eternalcenter.com/\$1 permanent@rewrite ^/(.*)$ https://$webdomain/\$1 permanent@" /etc/nginx/nginx.conf;
sed -i "s/eternalcenter.com.crt/$webcrt/" /etc/nginx/nginx.conf
sed -i "s/eternalcenter.com.key/$webkey/" /etc/nginx/nginx.conf

mkdir /etc/nginx/ssl
mv $webcrt /etc/nginx/ssl
mv $webkey /etc/nginx/ssl
chcon -t httpd_config_t /etc/nginx/ssl/$webcrt
chcon -t httpd_config_t /etc/nginx/ssl/$webkey
chcon -t httpd_config_t /etc/nginx/ssl/

rm -rf /usr/share/nginx/html/*
tar -xvf $webtar -C /usr/share/nginx/html/ && rm -rf $webtar
chcon -t httpd_sys_content_t -R /usr/share/nginx/html/*

yum -y install sendmail
yum -y install policycoreutils
setsebool -P httpd_can_network_connect 1
setsebool -P httpd_can_network_connect_db 1
setsebool -P httpd_can_sendmail 1
setsebool -P httpd_can_connect_ftp 1
setsebool -P httpd_unified 1
setsebool -P httpd_enable_cgi 1
setsebool -P httpd_builtin_scripting 1
setsebool -P mysql_connect_http 1

systemctl start nginx
systemctl enable nginx

#Deploy MariaDB
yum -y install mariadb mariadb-server

grep "^log_bin=" /etc/my.cnf.d/mariadb-server.cnf
if [ $? -ne 0 ];then
	sed -i '/^datadir/a log_bin=ec' /etc/my.cnf.d/mariadb-server.cnf
fi

grep "^binlog_format=" /etc/my.cnf.d/mariadb-server.cnf
if [ $? -ne 0 ];then
	sed -i '/^datadir/a binlog_format=\"mixed\"' /etc/my.cnf.d/mariadb-server.cnf
fi

grep "^server_id=" /etc/my.cnf.d/mariadb-server.cnf
if [ $? -ne 0 ];then
	sed -i '/^datadir/a server_id=51' /etc/my.cnf.d/mariadb-server.cnf
fi

sed -i 's/^plugin-load-add=auth_gssapi.so/#plugin-load-add=auth_gssapi.so/' /etc/my.cnf.d/auth_gssapi.cnf

sed -i '/^user=.*/d' /etc/my.cnf.d/mariadb-server.cnf
sed -i "/\[mysqld\]/a user=mysql" /etc/my.cnf.d/mariadb-server.cnf

sed -i '/^bind-address=.*/d' /etc/my.cnf.d/mariadb-server.cnf
sed -i "/\[mysqld\]/a bind-address=127.0.0.1" /etc/my.cnf.d/mariadb-server.cnf

chown -R mysql /var/lib/mysql

systemctl start mariadb
systemctl enable mariadb

ls $sqlbackup
if [ $? -ne 0 ];then
        mysql -uroot -e "create database $db;"
        mysql -uroot -e "create user \"$dbuser\"@\"localhost\" identified by \"$dbuserpw\";"
        mysql -uroot -e "grant all privileges on $db.* to \"$dbuser\"@\"localhost\" identified by \"$dbuserpw\";"
        mysql -uroot -e "set password for 'root'@'localhost'=password(\"$dbrootpw\")"
else
        mysql -uroot -e "create database $db;"
        mysql -uroot $db < $sqlbackup
	mysql -uroot -e "create user \"$dbuser\"@\"localhost\" identified by \"$dbuserpw\";"
	mysql -uroot -e "grant all privileges on $db.* to \"$dbuser\"@\"localhost\" identified by \"$dbuserpw\";"
	mysql -uroot -e "set password for 'root'@'localhost'=password(\"$dbrootpw\")"
	rm -rf $sqlbackup
fi
	
systemctl restart mariadb

#Deploy PHP
yum -y install php php-fpm php-mysqlnd php-gd php-mbstring php-opcache php-json php-xml php-xmlrpc php-pecl-zip php-pecl-imagick php-intl php-bcmath
useradd php-fpm -s /sbin/nologin
chown -R php-fpm:php-fpm /usr/share/nginx/html

sed -i /"^user =.*"/d /etc/php-fpm.conf
sed -i /"^group =.*"/d /etc/php-fpm.conf
sed -i /"^listen =.*"/d /etc/php-fpm.conf
sed -i /"^[www]"/d /etc/php-fpm.conf
sed -i /"^pm = .*"/d /etc/php-fpm.conf
sed -i /"^pm.start_servers = .*"/d /etc/php-fpm.conf
sed -i /"^pm.min_spare_servers = .*"/d /etc/php-fpm.conf
sed -i /"^pm.max_spare_servers = .*"/d /etc/php-fpm.conf
sed -i /"^pm.max_children = .*"/d /etc/php-fpm.conf
sed -i /"^pm.max_requests = .*"/d /etc/php-fpm.conf
sed -i /"^request_terminate_timeout = .*"/d /etc/php-fpm.conf

echo '[www]' >> /etc/php-fpm.conf
echo 'user = php-fpm' >> /etc/php-fpm.conf
echo 'group = php-fpm' >> /etc/php-fpm.conf
echo 'listen = 127.0.0.1:9000' >> /etc/php-fpm.conf
echo 'pm = dynamic' >> /etc/php-fpm.conf
echo 'pm.start_servers = 2' >> /etc/php-fpm.conf
echo 'pm.min_spare_servers = 2' >> /etc/php-fpm.conf
echo 'pm.max_spare_servers = 4' >> /etc/php-fpm.conf
echo 'pm.max_children = 4' >> /etc/php-fpm.conf
echo 'pm.max_requests = 1024' >> /etc/php-fpm.conf
echo 'request_terminate_timeout = 300' >> /etc/php-fpm.conf

systemctl start php-fpm
systemctl enable php-fpm

#Improve system performance
grep "^* soft nofile" /etc/security/limits.conf
if [ $? -ne 0 ];then
	echo '* soft nofile 1024' >> /etc/security/limits.conf
fi

grep "^* hard nofile" /etc/security/limits.conf
if [ $? -ne 0 ];then
	echo '* hard nofile 1024' >> /etc/security/limits.conf
fi

#Open firewall
systemctl start firewalld
systemctl enable firewalld
firewall-cmd --add-service=http --permanent
firewall-cmd --add-service=https --permanent
firewall-cmd --reload

#Limit log space
yum -y install rsyslog
systemctl enable --now rsyslog

echo "/var/log/mariadb/mariadb.log {
        create 600 mysql mysql
        notifempty
	daily
        rotate 3
        missingok
        compress
    postrotate
	# just if mysqld is really running
        if [ -e /run/mariadb/mariadb.pid ]
        then
           kill -1 $(</run/mariadb/mariadb.pid)
        fi
    endscript
}" > /etc/logrotate.d/mariadb

echo "/var/log/nginx/*log {
    create 0664 nginx root
    size 1024M
    rotate 1
    missingok
    notifempty
    compress
    sharedscripts
    postrotate
        /bin/kill -USR1 `cat /run/nginx.pid 2>/dev/null` 2>/dev/null || true
    endscript
}" > /etc/logrotate.d/nginx

echo "/var/log/php-fpm/*log {
    size 100M
    rotate 1
    missingok
    notifempty
    sharedscripts
    delaycompress
    postrotate
        /bin/kill -SIGUSR1 `cat /run/php-fpm/php-fpm.pid 2>/dev/null` 2>/dev/null || true
    endscript
}" > /etc/logrotate.d/php-fpm

echo "/var/log/cron
/var/log/maillog
/var/log/messages
/var/log/secure
/var/log/spooler
{
    size 100M
    rotate 1
    missingok
    sharedscripts
    postrotate
        /usr/bin/systemctl kill -s HUP rsyslog.service >/dev/null 2>&1 || true
    endscript
}" > /etc/logrotate.d/rsyslog

#Delete this script
scriptwhere=`readlink -f "$0"`
rm -rf $scriptwhere

#Restart the system
reboot

[工具] Shell 自动化部署 LNMP + SSL 平台 (openSUSE Leap 15 版)

介绍

基本信息

作者:朱明宇
名称:自动化部署 LNMP + SSL 平台
作用:自动化安装 LNMP + SSL,即通过 Linux、Nginx、MariaDB、PHP、php-fpm、SSL,实现 HTTPS

使用方法

1. 将网站的网页数据备份、网站的 SSL 公钥、网站的 SSL 私钥、网站的数据库备份和本脚本,5 个文件放在同一目录下
2. 如果没有网站的数据库备份则将网页数据备份、网站的 SSL 公钥、网站的 SSL 私钥和本脚本,4 个文件放在同一目录下
3. 在此脚本的分割线内写入相应的内容
4. 开启系统的 selinux
5. 给此脚本添加执行权限
6. 执行此脚本:./<执行本脚本>

脚本分割线里的变量

1. webdomain=”eternalcenter.com” #网站的域名,注意不要在前面加任何前缀
2. webtar=”eternalcenter-backup-*.tar.gz” #网站的网页数据备份,如果没有这个备份,可以下载一个开源的 WordPress 网页程序
3. webcrt=”eternalcenter.com.crt” #网站 SSL 的公钥,可以自己创建也可以在 FreeSSl 上申请
4. webkey=”eternalcenter.com.key” #网站 SSL 的私钥,可以自己创建也可以在 FreeSSL 上申请
5. sqlbackup=”eternalcenter-backup-*.sql” #网站数据库数据备份,如果没有这个备份(数据库是全量备份),则这里可以为空
6. db=”ec” #网站在数据库中库
7. dbuser=”ec” #网站在数据库中的用户
8. dbuserpw=”eternalcenter” #网站在数据库中的用户密码
9. dbrootpw=”eternalcenter” #数据库的 root 密码

注意

1. 服务器的系统需要是 openSUSE 15 版本
2. 服务器系统要配置好可用的软件源(最好是软件数量最多的官方版本)
3. 服务器要能够连接外网

脚本

#!/bin/bash

####################### Separator ########################
webdomain="eternalcenter.com"
webtar="eternalcenter-backup-*.tar.gz"
webcrt="eternalcenter.com.crt"
webkey="eternalcenter.com.key"
sqlbackup="eternalcenter-backup-*.sql"
db="ec"
dbuser="ec"
dbuserpw="eternalcenter"
dbrootpw="eternalcenter"
####################### Separator ########################

#判断所需文件是否存在
ls $webtar
if [ $? -ne 0 ];then
	echo "没有网页数据备份,无法继续"
	exit 2
fi

ls $webcrt
if [ $? -ne 0 ];then
	echo "没有网站公钥,无法继续"
	exit 2
fi

ls $webkey
if [ $? -ne 0 ];then
	echo "没有网站私钥,无法继续"
	exit 2
fi

#更新系统
zypper ref
zypper -n update

#确保必需软件已经安装
zypper -n in tar
zypper -n in firewalld


#部署 Nginx
zypper -n in nginx

echo 'worker_processes  1;

events {
    worker_connections  1024;
}

http {
    limit_req_zone $binary_remote_addr zone=one:10m rate=1r/s;
    include       mime.types;
    default_type  application/octet-stream;

    sendfile        on;

    keepalive_timeout  60;
    client_body_timeout 20s;
    client_header_timeout 10s;
    send_timeout 30s;

    server {
        listen       80;
        limit_req zone=one burst=5;
        server_name www.eternalcenter.com eternalcenter.com;

        rewrite ^/(.*)$ https://eternalcenter.com/$1 permanent;
      
        error_page   500 502 503 504  /50x.html;
        location = /50x.html {
            root   html;
        }

        }

    server {
        listen 443 ssl;
        server_name www.eternalcenter.com eternalcenter.com;

        if ($request_method !~ ^(GET|POST)$){
        return 444;
        }

        ssl_certificate      /etc/nginx/ssl/eternalcenter.com.crt;
        ssl_certificate_key  /etc/nginx/ssl/eternalcenter.com.key;

        ssl_session_cache    shared:SSL:1m;
        ssl_session_timeout  5m;

        ssl_ciphers  HIGH:!aNULL:!MD5;
        ssl_prefer_server_ciphers  on;

        root /srv/www/htdocs;

        location / {
            index index.php;
            try_files $uri $uri/ /index.php$is_args$args;
            if (-f $request_filename/index.html){rewrite (.) $1/index.html break;}
            if (-f $request_filename/index.php){rewrite (.) $1/index.php;}
            if (!-f $request_filename){rewrite (.) /index.php;}
        }

        location ~ \.php$ {
            include fastcgi_params;
	    include fastcgi.conf;
            fastcgi_pass 127.0.0.1:9000;
            fastcgi_index index.php;
            fastcgi_param SCRIPT_FILENAME /srv/www/htdocs/$fastcgi_script_name;

        }
	
	location ~ ^/\.user\.ini {
            deny all;
        }

        location ~*\.(jpd|jpeg|gif|png|css|js|ico|xml)$ {
            expires 30d;
        }

        error_page  404              /404.html;
    }

        gzip on;
	gzip_min_length 1000;
	gzip_comp_level 4;
	gzip_types text/plain test/css application/json application/x-javascript text/xml application/xml
	application/xml+rss text/javascripts;

	client_header_buffer_size 1k;

	open_file_cache_valid  60s;
	open_file_cache_min_uses 5;
	open_file_cache_errors off;

}' > /etc/nginx/nginx.conf

sed -i "s/server_name www.eternalcenter.com eternalcenter.com;/server_name www.$webdomain $webdomain;/" /etc/nginx/nginx.conf
sed -i "s@rewrite ^/(.*)$ https://eternalcenter.com/\$1 permanent@rewrite ^/(.*)$ https://$webdomain/\$1 permanent@" /etc/nginx/nginx.conf;
sed -i "s/eternalcenter.com.crt/$webcrt/" /etc/nginx/nginx.conf
sed -i "s/eternalcenter.com.key/$webkey/" /etc/nginx/nginx.conf

mkdir /etc/nginx/ssl
mv $webcrt /etc/nginx/ssl
mv $webkey /etc/nginx/ssl

rm -rf /srv/www/htdocs/*
tar -xvf $webtar -C /srv/www/htdocs/ && rm -rf $webtar

zypper -n in policycoreutils

systemctl start nginx
systemctl enable nginx

#部署 MariaDB
zypper -n in mariadb mariadb-server

grep "^log_bin=" /etc/my.cnf
if [ $? -ne 0 ];then
	sed -i '/^datadir/a log_bin=ec' /etc/my.cnf
fi

grep "^binlog_format=" /etc/my.cnf
if [ $? -ne 0 ];then
	sed -i '/^datadir/a binlog_format=\"mixed\"' /etc/my.cnf
fi

grep "^server_id=" /etc/my.cnf
if [ $? -ne 0 ];then
	sed -i '/^datadir/a server_id=51' /etc/my.cnf
fi

sed -i 's/^plugin-load-add=auth_gssapi.so/#plugin-load-add=auth_gssapi.so/' /etc/my.cnf

sed -i '/^user=.*/d' /etc/my.cnf
sed -i "/\[mysqld\]/a user=mysql" /etc/my.cnf

sed -i '/^bind-address=.*/d' /etc/my.cnf
sed -i "/\[mysqld\]/a bind-address=127.0.0.1" /etc/my.cnf

systemctl start mariadb
systemctl enable mariadb

chown -R mysql:mysql /var/lib/mysql

ls $sqlbackup
if [ $? -ne 0 ];then
        mysql -uroot -e "create database $db;"
        mysql -uroot -e "create user \"$dbuser\"@\"localhost\" identified by \"$dbuserpw\";"
        mysql -uroot -e "grant all privileges on $db.* to \"$dbuser\"@\"localhost\" identified by \"$dbuserpw\";"
        mysql -uroot -e "set password for 'root'@'localhost'=password(\"$dbrootpw\")"
else
        mysql -uroot -e "create database $db;"
        mysql -uroot $db < $sqlbackup
        mysql -uroot -e "create user \"$dbuser\"@\"localhost\" identified by \"$dbuserpw\";"
        mysql -uroot -e "grant all privileges on $db.* to \"$dbuser\"@\"localhost\" identified by \"$dbuserpw\";"
        mysql -uroot -e "set password for 'root'@'localhost'=password(\"$dbrootpw\")"
        rm -rf $sqlbackup
fi
	
systemctl restart mariadb

#部署 PHP
zypper -n in php7 php7-fpm php7-mysql php7-gd php7-mbstring php7-opcache php7-json php7-xmlrpc php7-zlib
useradd php-fpm -s /sbin/nologin
groupadd php-fpm
chown -R php-fpm:php-fpm /srv/www/htdocs
cp /etc/php7/fpm/php-fpm.conf.default /etc/php7/fpm/php-fpm.conf

sed -i /"^user =.*"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^group =.*"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^listen =.*"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^[www]"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^pm = .*"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^pm.start_servers = .*"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^pm.min_spare_servers = .*"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^pm.max_spare_servers = .*"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^pm.max_children = .*"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^pm.max_requests = .*"/d /etc/php7/fpm/php-fpm.conf
sed -i /"^request_terminate_timeout = .*"/d /etc/php7/fpm/php-fpm.conf

echo '[www]' >> /etc/php7/fpm/php-fpm.conf
echo 'user = php-fpm' >> /etc/php7/fpm/php-fpm.conf
echo 'group = php-fpm' >> /etc/php7/fpm/php-fpm.conf
echo 'listen = 127.0.0.1:9000' >> /etc/php7/fpm/php-fpm.conf
echo 'pm = dynamic' >> /etc/php7/fpm/php-fpm.conf
echo 'pm.start_servers = 2' >> /etc/php7/fpm/php-fpm.conf
echo 'pm.min_spare_servers = 2' >> /etc/php7/fpm/php-fpm.conf
echo 'pm.max_spare_servers = 4' >> /etc/php7/fpm/php-fpm.conf
echo 'pm.max_children = 4' >> /etc/php7/fpm/php-fpm.conf
echo 'pm.max_requests = 1024' >> /etc/php7/fpm/php-fpm.conf
echo 'request_terminate_timeout = 300' >> /etc/php7/fpm/php-fpm.conf

systemctl start php-fpm
systemctl enable php-fpm

#提高系统性能
grep "^* soft nofile" /etc/security/limits.conf
if [ $? -ne 0 ];then
	echo '* soft nofile 1024' >> /etc/security/limits.conf
fi

grep "^* hard nofile" /etc/security/limits.conf
if [ $? -ne 0 ];then
	echo '* hard nofile 1024' >> /etc/security/limits.conf
fi

#打开防火墙
systemctl start firewalld
systemctl enable firewalld
firewall-cmd --add-port=80/tcp --permanent
firewall-cmd --add-port=443/tcp --permanent
firewall-cmd --reload

#限制日志占用空间
echo "/var/log/mariadb/mariadb.log {
        create 600 mysql mysql
        notifempty
	daily
        rotate 3
        missingok
        compress
    postrotate
	# just if mysqld is really running
        if [ -e /run/mariadb/mariadb.pid ]
        then
           kill -1 $(</run/mariadb/mariadb.pid)
        fi
    endscript
}" > /etc/logrotate.d/mariadb

echo "/var/log/nginx/*log {
    create 0664 nginx root
    size 1024M
    rotate 1
    missingok
    notifempty
    compress
    sharedscripts
    postrotate
        /bin/kill -USR1 `cat /run/nginx.pid 2>/dev/null` 2>/dev/null || true
    endscript
}" > /etc/logrotate.d/nginx

echo "/var/log/php-fpm/*log {
    size 100M
    rotate 1
    missingok
    notifempty
    sharedscripts
    delaycompress
    postrotate
        /bin/kill -SIGUSR1 `cat /run/php-fpm/php-fpm.pid 2>/dev/null` 2>/dev/null || true
    endscript
}" > /etc/logrotate.d/php-fpm

echo "/var/log/cron
/var/log/maillog
/var/log/messages
/var/log/secure
/var/log/spooler
{
    size 100M
    rotate 1
    missingok
    sharedscripts
    postrotate
        /usr/bin/systemctl kill -s HUP rsyslog.service >/dev/null 2>&1 || true
    endscript
}" > /etc/logrotate.d/syslog

#删除此脚本
scriptwhere=`readlink -f "$0"`
rm -rf $scriptwhere

#重启系统
reboot