MariaDB max_connections, table_open_cache stuck

copy my-hugh.cnf to /etc/my.cnf.d/

editing
/etc/sysctl.conf
fs.file-max = 2459688

editing
/etc/security/limits.conf
mysql           soft    nofile         4096
mysql           hard    nofile         4096

editing
/etc/my.cnf.d/my-hugh.cnf
max_connections=1024
max_user_connections=1024
table_open_cache = 4096
table_definition_cache = 4096
open_files_limit=4096


ref:
https://codepoets.co.uk/2015/mysql-max_connections-stuck-on-214/

http://blog.endpoint.com/2013/12/increasing-mysql-55-maxconnections-on.html

GeoIP Update

系統
CentOS

https://github.com/maxmind/geoipupdate

先到官方 git clone
$ git clone https://github.com/maxmind/geoipupdate
$ cd geoipupdate
$ ./bootstrap

使用 bootstrap 遇到問題要裝以下幾項
yum install autoconf automake libtool

執行並安裝
$ ./configure
$ make
$ sudo make install


可能會遇到錯誤, curl, zlib 安裝
yum install curl-devel zlib-devel


設定下載參數
http://dev.maxmind.com/geoip/geoipupdate/

照上方步驟安裝完 geoipupdate 後會自動寫一份 config 到
/usr/local/etc/GeoIP.conf
修改這份 config 並 mark 原本設定
UserId XXX
LicenseKey XXX
ProductIds GeoIP2-City GeoIP2-Country


然後手動新增資料夾
/usr/local/share/GeoIP

第一次執行 geoipupdate
檔案會寫入
/usr/local/share/GeoIP

設定排程 /etc/crontab
52 11 * * 6 /usr/local/bin/geoipupdate

Clickjacking 防範

NGINX 設定

add_header X-Frame-Options "SAMEORIGIN";

參考文章
https://developer.mozilla.org/zh-TW/docs/Web/HTTP/X-Frame-Options
https://geekflare.com/add-x-frame-options-nginx/
http://devco.re/blog/2014/04/08/security-issues-of-http-headers-2-content-security-policy/

SELinux 影響 ssh with key login

如果沒有關閉 SELinux 
ssh 使用 rsa 登入時會遇到錯誤, 
上傳 key 後時要記得更新資料夾權限

restorecon -Rv /folder

就可以正常使用了

[Solve] rsync Argument list too long

因為 UNIX 有限制 ARG_MAX 大小
資料夾底下檔案太多就會出現 Argument list too long

rsync 也一樣, 所以先使用 rsync -n 來跑一次資料夾要同步的檔案, 這裡就不用下星號, 但要注意資料夾 [來源] [目的地] 的位置, 寫錯就會傳錯層級

1. use rsync dry run
rsync -n source/path desc


2. rsync source/path desc


參考文章:
https://hugepang.wordpress.com/2011/06/08/solution-bash-usrlocalbinrsync-argument-list-too-long/


http://blog.xuite.net/jyoutw/xtech/20025390-rsync%E5%8F%83%E6%95%B8%E8%A9%B3%E8%A7%A3--990209

SSH With key login Failure


假如 .ssh, authorized_keys 權限正確, 
但還是無法使用 ssh key 登入
請嘗試在 server 端下以下指令修正資料目錄位置

restorecon -FRvv ~/.ssh

在重新測試是否可順利連結