<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="https://v1sta.xyz/wp-content/plugins/pretty-rss-feeds/xslt/pretty-feed.xsl" type="text/xsl" media="screen" ?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/">

<channel>
	<title>2026年2月5日 &#8211; 景の域</title>
	<atom:link href="https://v1sta.xyz/2026/02/05/feed/" rel="self" type="application/rss+xml" />
	<link>https://v1sta.xyz</link>
	<description>远景的幻想空间</description>
	<lastBuildDate>Fri, 31 Jul 2026 07:52:16 +0000</lastBuildDate>
	<language>zh-Hans</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://v1sta.xyz/wp-content/uploads/2026/03/V1sta-Orb-Output512-2-60x60.png</url>
	<title>2026年2月5日 &#8211; 景の域</title>
	<link>https://v1sta.xyz</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>飞牛更新系统</title>
		<link>https://v1sta.xyz/tech/%e9%a3%9e%e7%89%9b%e6%9b%b4%e6%96%b0%e7%b3%bb%e7%bb%9f/</link>
					<comments>https://v1sta.xyz/tech/%e9%a3%9e%e7%89%9b%e6%9b%b4%e6%96%b0%e7%b3%bb%e7%bb%9f/#respond</comments>
		
		<dc:creator><![CDATA[域主 V1STA]]></dc:creator>
		<pubDate>Thu, 05 Feb 2026 08:59:42 +0000</pubDate>
				<category><![CDATA[技术]]></category>
		<category><![CDATA[NAS]]></category>
		<category><![CDATA[飞牛]]></category>
		<guid isPermaLink="false">https://v1sta.xyz/?p=2887</guid>

					<description><![CDATA[https://club.fnnas.com/forum.php?mod=viewthread&#38;tid &#8230; <a href="https://v1sta.xyz/tech/%e9%a3%9e%e7%89%9b%e6%9b%b4%e6%96%b0%e7%b3%bb%e7%bb%9f/" class="more-link">继续阅读<span class="screen-reader-text">飞牛更新系统</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><a href="https://club.fnnas.com/forum.php?mod=viewthread&amp;tid=33052&amp;extra=page%3D1">https://club.fnnas.com/forum.php?mod=viewthread&amp;tid=33052&amp;extra=page%3D1</a></p>
</blockquote>



<h5 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> 问题解析</h5>



<p class="wp-block-paragraph"><strong>由于部分用户提前升级了这部分文件，导致官方OTA过程无法正常升级，提示安装失败。</strong></p>



<h5 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> 解决办法：</h5>



<p class="wp-block-paragraph">输入账号密码登录终端接显示器到系统后台或者使用ssh登录</p>



<p class="wp-block-paragraph">终端进入ROOT环境，不会操作请看教程，显示为root@主机名后执行下面的命令</p>



<pre class="wp-block-code"><code>curl  http://static2.fnnas.com/aptfix/fixapt.sh | bash</code></pre>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><a href="https://v2ex.com/t/1189392">https://v2ex.com/t/1189392</a></p>
</blockquote>



<p class="wp-block-paragraph">短评：果然国产的东西还是草台班子……无亚于投资朝鲜企业——没有规范的市场规则和基本的技术培训。虽然我确实要承认飞牛对新手的学习曲线很友好、而且文件结构划分先进。飞牛适合我放不下的人直接上手，而不适合我和我的IT同行长期利用。</p>

<p><a href="https://v1sta.xyz/tech/%e9%a3%9e%e7%89%9b%e6%9b%b4%e6%96%b0%e7%b3%bb%e7%bb%9f/" rel="nofollow">来源</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://v1sta.xyz/tech/%e9%a3%9e%e7%89%9b%e6%9b%b4%e6%96%b0%e7%b3%bb%e7%bb%9f/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<enclosure url="https://v1sta.xyz/wp-content/uploads/2026/03/V1sta-Orb-Output512-2.png" length="199214" type="image/png"/><media:content url="https://v1sta.xyz/wp-content/uploads/2026/03/V1sta-Orb-Output512-2.png" width="512" height="512" medium="image" type="image/png"/>	</item>
		<item>
		<title>Ubuntu服务器安装Cockpit面板记录</title>
		<link>https://v1sta.xyz/tech/ubuntu-server-cockpit/</link>
					<comments>https://v1sta.xyz/tech/ubuntu-server-cockpit/#comments</comments>
		
		<dc:creator><![CDATA[域主 V1STA]]></dc:creator>
		<pubDate>Wed, 04 Feb 2026 17:29:45 +0000</pubDate>
				<category><![CDATA[技术]]></category>
		<guid isPermaLink="false">https://v1sta.xyz/?p=2878</guid>

					<description><![CDATA[前言介绍 Cockpit是由红帽公司（Red Hat）开发的一款服务器管理面板。 这个服务器面板适合中小型企业 &#8230; <a href="https://v1sta.xyz/tech/ubuntu-server-cockpit/" class="more-link">继续阅读<span class="screen-reader-text">Ubuntu服务器安装Cockpit面板记录</span> <span class="meta-nav">&#8594;</span></a>]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">前言介绍</h2>



<p class="wp-block-paragraph">Cockpit是由红帽公司（Red Hat）开发的一款服务器管理面板。</p>



<p class="wp-block-paragraph">这个服务器面板适合中小型企业业务用途的管理，包括了很多基本的功能，比如性能仪表盘、网络、磁盘、用户的管理。<br>这些基础功能免费，也是自由软件。有了Cockpit，添加用户SSH密钥、执行系统更新、配置防火墙这些低级任务操作轻而易举，<br>节约了去终端的时间、减少指令残留污染终端历史。</p>



<details class="wp-block-details is-layout-flow wp-block-details-is-layout-flow"><summary>详细介绍</summary>
<p class="wp-block-paragraph">Cockpit一般会预装在各类红帽系服务器的系统上（RHEL、CentOS、Fedora Server、OpenSUSE），<br>非红帽系统比如Debian系也可以用，也包括Ubuntu这样的系统。<br>网上亦有在HP MicroServer Gen8这样的NAS向服务器安装Cockpit管理的案例，<br>适合老派服务器维护者，对应Windows的Admin Center。</p>



<p class="wp-block-paragraph">比如说此前我就用Cockpit控制了一个接了声卡的数播虚拟机，去重启总是宕机的Mopidy服务，比手动去终端敲指令省事，毕竟重复任务有些愚蠢。后期会发文章介绍。</p>



<p class="wp-block-paragraph">Cockpit本身对系统的破坏性小，不像那些主机面板有自己的配置文件，Cockpit的配置都是与系统同步，兼容性很好。<br>此外Cockpit也是一个可扩展的管理平台，因此可以开发相应的插件以扩展功能。<br>有管理ZFS的、管理容器的、管理SMB/NFS网络共享的、管理虚拟机的、管理集群的……<br>不过像Web服务器那种暂时还很稀少，管理Nginx略显麻烦，不过编辑Nginx文件本身也不应该是Cockpit该干的事情。</p>



<p class="wp-block-paragraph">Cockpit新版的界面强行迎合了MD3和GTK4那样的圆角UI，个人觉得缺少了企业级的严谨美学，不过其实也没有不能接受。稳定为重，因此Cockpit没啥可以美化的空间。</p>
</details>



<p class="wp-block-paragraph">本文以安装了Webinoly的Ubuntu 24.04 LTS为环境配置蓝本，通过Webinoly的Nginx反向代理+客户端私有CA证书验证（类似网银盾）实现安全访问，并配置firewalld防火墙设定。</p>



<h2 class="wp-block-heading">安装</h2>



<p class="wp-block-paragraph">Ubuntu Backports软件源提供了Cockpit的支持，可使用如下命令检测版本号安装：</p>



<pre class="wp-block-code"><code>. /etc/os-release
sudo apt install -t ${VERSION_CODENAME}-backports cockpit</code></pre>



<p class="wp-block-paragraph">安装之后，通过任意的服务器地址+9090端口，用非root权限的管理员用户即可访问Cockpit面板，<br>如果没有这样的用户，请先 <code>adduser</code> 。<br>现在来确认一下Cockpit在HTTP端口是否运行正常吧。</p>



<span id="more-2878"></span>



<h3 class="wp-block-heading">修改端口</h3>



<p class="wp-block-paragraph">安全起见、以及后面防火墙的配置需要，并不建议直接访问Cockpit的HTTP 9090端口。<br>因此，需要修改Cockpit的系统监听端口仅允许本地访问。</p>



<p class="wp-block-paragraph">编辑 <code>/etc/systemd/system/cockpit.socket.d/listen.conf</code> 配置文件：</p>



<pre class="wp-block-code"><code>&#91;Socket]
ListenStream=
ListenStream=127.0.0.1:9090</code></pre>



<p class="wp-block-paragraph">第一行设置为空是有意为之的，参见 https://cockpit-project.org/guide/latest/guide#listen</p>



<p class="wp-block-paragraph">可以使用SSH转发的方式将其转到本地客户机的127.0.0.1:9090端口进行访问，VSCode也行。像VPS这类服务器，尽量不要直接通过HTTP协议访问公网地址操作Cockpit管理面板。</p>



<p class="wp-block-paragraph">不过SSH直接转发端口有一些弊端：</p>



<ul class="wp-block-list">
<li>手机不方便直接访问</li>



<li>浏览器会提示不安全，没有证书认证不便统一管理</li>
</ul>



<p class="wp-block-paragraph">稍后，将配置使用Nginx反向代理，配置自签名CA的客户端证书（mTLS）通过HTTPS访问加强安全性。</p>



<h2 class="wp-block-heading">NGINX 反代</h2>



<p class="wp-block-paragraph">反代建议使用域名，这样使用mTLS会方便一些。</p>



<h3 class="wp-block-heading">创建自签证书</h3>



<p class="wp-block-paragraph">可以通过openssl创建，也可以使用mkcert这类自动化工具。</p>



<pre class="wp-block-code"><code>#!/usr/bin/env bash
openssl genpkey -algorithm RSA -out ca.key
openssl req -new -x509 -key ca.key -out ca.crt
openssl genpkey -algorithm RSA -out server.key
openssl req -new -key server.key -out server.csr
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out server.crt
openssl genpkey -algorithm RSA -out client.key
openssl req -new -key client.key -out client.csr
openssl x509 -req -in client.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out client.crt
openssl pkcs12 -export -out client.pfx -inkey client.key -in client.crt -certfile ca.crt</code></pre>



<p class="wp-block-paragraph">参考了：<a href="https://predmet.ch/infra/cockpit_mtls">https://predmet.ch/infra/cockpit_mtls</a></p>



<p class="wp-block-paragraph">mkcert更简单：</p>



<pre class="wp-block-code"><code># 生成自签CA（位于./.local/share/mkcert）
mkcert -install
# 签发服务端证书
mkcert your.domain *.your.domain IP.add.re.ss
# 签发客户端证书
mkcert -client your.domain *.your.domain IP.add.re.ss
# 依然参照
openssl pkcs12 -export -out client.pfx -inkey client.key -in client.crt -certfile ca.crt</code></pre>



<p class="wp-block-paragraph">以下是mkcert的<a href="https://github.com/FiloSottile/mkcert?tab=readme-ov-file#advanced-options">使用参数</a>：</p>



<pre class="wp-block-code"><code>    -cert-file FILE, -key-file FILE, -p12-file FILE
        Customize the output paths.

    -client
        Generate a certificate for client authentication.

    -ecdsa
        Generate a certificate with an ECDSA key.

    -pkcs12
        Generate a ".p12" PKCS #12 file, also know as a ".pfx" file,
        containing certificate and key for legacy applications.

    -csr CSR
        Generate a certificate based on the supplied CSR. Conflicts with
        all other flags and arguments except -install and -cert-file.</code></pre>



<p class="wp-block-paragraph">最终的目的是导出一份p12/pfx文件，并安装到设备的信任区域。Windows需要手动指定受信任根证书颁发者区域，Android设备同理，需要手动安装。</p>



<h3 class="wp-block-heading">创建域名反代</h3>



<p class="wp-block-paragraph">使用Webinoly的site命令创建空白网站（纯HTML）：</p>



<pre class="wp-block-code"><code>site your.domain -empty 
site your.domain -ssl=on -ssl-crt=/dir/crt.file -ssl-key=/dir/key.file </code></pre>



<p class="wp-block-paragraph">导航到 sites-available 目录中的域名配置，定位到WebinolyCustom部分，添加反代配置后保存重载。</p>



<pre class="wp-block-code"><code># WebinolyCustom

    location / {
        # Required to proxy the connection to Cockpit
        proxy_pass http://127.0.0.1:9090;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_ssl_verify off;
        # Required for web sockets to function
        proxy_http_version 1.1;
        proxy_buffering off;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        # Pass ETag header from Cockpit to clients.
        # See: https://github.com/cockpit-project/cockpit/issues/5239
        gzip off;
       }

# WebinolyCustomEnd</code></pre>



<p class="wp-block-paragraph">如有需要，可一并更改端口号。<br>测试域名访问，不过直接访问而没做Cockpit端回源验证，大概率直接白屏或登不进去。<br>因此需要编辑 /etc/cockpit/cockpit.conf 配置文件：</p>



<pre class="wp-block-code"><code>&#91;WebService]
Origins = https://your.domain:port wss://your.domain:port https://127.0.0.1:9090 wss://127.0.0.1:9090
ProtocolHeader = X-Forwarded-Proto
ForwardedForHeader = X-Forwarded-For</code></pre>



<p class="wp-block-paragraph">此时访问浏览器应该可以正常访问了。接下来是客户端证书验证：</p>



<h3 class="wp-block-heading">配置mTLS（客户端证书验证）</h3>



<p class="wp-block-paragraph">回到域名配置文件，定位到 <code># WebinolySSLCustomCert</code> 部分，插入客户端证书CA的配置代码：</p>



<pre class="wp-block-code"><code>ssl_client_certificate "/dir/ca.crt";
ssl_verify_client on;</code></pre>



<p class="wp-block-paragraph">保存重载，此时回到浏览器再次测试域名，可使用隐私模式或者额外的浏览器尝试，<br>此时应该提示有提示使用证书的界面（类似于网银盾）</p>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img data-dominant-color="232e36" data-has-transparency="false" style="--dominant-color: #232e36;" fetchpriority="high" decoding="async" width="535" height="299" sizes="(max-width: 535px) 100vw, 535px" src="https://v1sta.xyz/wp-content/uploads/2026/02/image-30.png" alt="" class="wp-image-2880 not-transparent" srcset="https://v1sta.xyz/wp-content/uploads/2026/02/image-30.png 535w, https://v1sta.xyz/wp-content/uploads/2026/02/image-30-300x168.png 300w" /></figure>
</div>


<h2 class="wp-block-heading">插件</h2>



<p class="wp-block-paragraph">Cockpit提供了一些插件，可在此处查看：</p>



<p class="wp-block-paragraph"><a href="https://cockpit-project.org/applications">https://cockpit-project.org/applications</a></p>



<p class="wp-block-paragraph">因为安装在Ubuntu的VPS上，而非红帽系Linux，所以仅简短介绍一些能用的插件。Cockpit插件本身不多，详细了解还请查看上文applications介绍页。</p>



<h2 class="wp-block-heading">安装防火墙</h2>



<p class="wp-block-paragraph">Cockpit支持管理基于firewalld的防火墙规则，通过apt方式安装防火墙：</p>



<pre class="wp-block-code"><code>apt install firewalld
firewall-cmd --state</code></pre>



<p class="wp-block-paragraph">在「网络」页面下，新冒出「防火墙」栏目，「编辑规则和区域」可进入防火墙规则的编辑页面。</p>



<h3 class="wp-block-heading">诊断报告</h3>



<pre class="wp-block-code"><code>apt-get install cockpit-sosreport</code></pre>



<h3 class="wp-block-heading">软件包管理器</h3>



<p class="wp-block-paragraph">基于PackageKit的Cockpit软件包管理插件，<br>不过实测Ubuntu使用不佳，Debian好一些，仅供参考。</p>



<p class="wp-block-paragraph"><a href="https://github.com/hatlabs/cockpit-package-manager-debian/releases/tag/v0.1.1-1">https://github.com/hatlabs/cockpit-package-manager-debian/releases/tag/v0.1.1-1</a></p>



<p class="wp-block-paragraph">安装：</p>



<pre class="wp-block-code"><code>sudo dpkg -i cockpit-package-manager_0.1.1-1_all.deb
sudo apt-get install -f  # Install any missing dependencies</code></pre>

<p><a href="https://v1sta.xyz/tech/ubuntu-server-cockpit/" rel="nofollow">来源</a></p>]]></content:encoded>
					
					<wfw:commentRss>https://v1sta.xyz/tech/ubuntu-server-cockpit/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
		<enclosure url="https://v1sta.xyz/wp-content/uploads/2026/02/image-30.png" length="16668" type="image/png"/><media:content url="https://v1sta.xyz/wp-content/uploads/2026/02/image-30.png" width="535" height="299" medium="image" type="image/png"/>	</item>
	</channel>
</rss>
