/images/avatar.png

在华硕路由器 (AC56U) 上安装 AdGuardHome

下载并刷入 Asuswrt-Merlin 固件 (v384.6)

https://www.asuswrt-merlin.net/ https://sourceforge.net/projects/asuswrt-merlin/files/RT-AC56U/Release/RT-AC56U_384.6_0.zip/download

准备 USB 驱动器

  1. 通过 SSH 登录到路由器 (ssh admin@router_ip)
  2. fdisk /dev/sda
  3. mkfs.ext3 /dev/sda[1,2]

启用 JFFS 自定义脚本和配置

Administration -> System -> Persistent JFFS2 partition -> Enable JFFS custom scripts and configs (‘yes’)

执行 Entware-Setup 以在 USB 驱动器上启用 /opt 挂载

新刷入的固件 (v384.6) 已经包含 entware-setup.sh。 供参考:https://github.com/RMerl/asuswrt-merlin/blob/master/release/src/router/others/entware-setup.sh

添加 GitLab CI Runner

设置标准的 RHEL/AlmaLinux 8.5 VM

  1. Docker 代理设置:

    cat /etc/systemd/system/docker.service.d/http-proxy.conf 
    [Service]
    Environment="HTTP_PROXY=http://proxy.lbs.alcatel-lucent.com:8000" "HTTPS_PROXY=http://proxy.lbs.alcatel-lucent.com:8000" "NO_PROXY=orbw-artifactory.ca.alcatel-lucent.com"
  2. 不安全(私有)注册表:

    cat /etc/docker/daemon.json 
    {
        "insecure-registries" : [ "orbw-artifactory.ca.alcatel-lucent.com:8081" ]
    }

安装 GitLab Runner

docker run -d --name gitlab-runner --restart always -v /home/cloud-user/config:/etc/gitlab-runner -v /var/run/docker.sock:/var/run/docker.sock orbw-artifactory.ca.alcatel-lucent.com:8081/nokia-nsp-docker-virtual/gitlab/gitlab-runner:latest

GitLab Runner 注册

docker run --rm -it -v /home/cloud-user/config:/etc/gitlab-runner orbw-artifactory.ca.alcatel-lucent.com:8081/nokia-nsp-docker-virtual/gitlab/gitlab-runner:latest register

配置示例:

关于 SELinux

来自互联网的一些阅读材料。

Docker 默认安全选项

https://docs.docker.com/engine/security/seccomp/

# docker info
Client:
 Context:    default
 Debug Mode: false
 Plugins:
  app: Docker App (Docker Inc., v0.9.1-beta3)
  buildx: Build with BuildKit (Docker Inc., v0.6.1-docker)
  scan: Docker Scan (Docker Inc., v0.8.0)

Server:
 Containers: 17
  Running: 15
  Paused: 0
  Stopped: 2
 Images: 16
 Server Version: 20.10.8
 Storage Driver: overlay2
  Backing Filesystem: extfs
  Supports d_type: true
  Native Overlay Diff: true
  userxattr: false
 Logging Driver: json-file
 Cgroup Driver: systemd
 Cgroup Version: 1
 Plugins:
  Volume: local
  Network: bridge host ipvlan macvlan null overlay
  Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
 Swarm: inactive
 Runtimes: runc io.containerd.runc.v2 io.containerd.runtime.v1.linux
 Default Runtime: runc
 Init Binary: docker-init
 containerd version: e25210fe30a0a703442421b0f60afac609f950a3
 runc version: v1.0.1-0-g4144b63
 init version: de40ad0
 Security Options:
  seccomp
   Profile: default
 Kernel Version: 3.10.0-1160.42.2.el7.x86_64
 Operating System: Red Hat Enterprise Linux Server 7.9 (Maipo)
 OSType: linux
 Architecture: x86_64
 CPUs: 8
 Total Memory: 23.39GiB
 Name: gene-k8s-k8sc-node1
 ID: VGBN:P5LX:RTQG:OX67:INYM:ZUHD:W6NQ:FWWL:KUV5:NZ6N:2DKH:ZIYL
 Docker Root Dir: /opt/nsp/docker
 Debug Mode: false
  Registry: https://index.docker.io/v1/
 Labels:
 Experimental: false
 Insecure Registries:
   127.0.0.0/8
 Live Restore Enabled: false

WARNING: API is accessible on http://0.0.0.0:2375 without encryption.
         Access to the remote API is equivalent to root access on the host. Refer
         to the 'Docker daemon attack surface' section in the documentation for
         more information: https://docs.docker.com/go/attack-surface/
[root@gene-k8s-k8sc-node1 ~]# sestatus 
SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
SELinux root directory:         /etc/selinux
Loaded policy name:             targeted
Current mode:                   permissive
Mode from config file:          permissive
Policy MLS status:              enabled
Policy deny_unknown status:     allowed
Max kernel policy version:      31
[root@gene-k8s-k8sc-node1 ~]# ps -eZ | grep docker
system_u:system_r:unconfined_service_t:s0 1254 ? 00:00:00 docker
system_u:system_r:container_runtime_t:s0 30862 ? 00:02:10 dockerd
system_u:system_r:container_runtime_t:s0 30976 ? 00:00:00 docker
[root@gene-k8s-k8sc-node1 ~]# docker context ls
NAME        DESCRIPTION                               DOCKER ENDPOINT               KUBERNETES ENDPOINT                ORCHESTRATOR
default *   Current DOCKER_HOST based configuration   unix:///var/run/docker.sock   https://127.0.0.1:6443 (default)   swarm

https://cheatsheetseries.owasp.org/cheatsheets/Docker_Security_Cheat_Sheet.html

最正确的生活方式:身勤、心善、气和

《淮南子》说:“与其临渊羡鱼,不如退而结网。”

身勤

《增广贤文》有言:“一生之计在于勤。”

清代著名书法家何绍基,知道女儿在准备嫁妆时,从京城寄回了一个轻飘飘的箱子。 大婚当日,他的女儿春梅和丈夫将箱子打开,看到箱子空空,什么也没有。 仅在箱子底部,明明白白地写着一个大字——“勤”。这对新婚夫妇看后,一番沉思,领悟到了父亲的深远用意。 此后,一字嫁妆“勤”成了夫妻俩的持家之道、兴家之方。 正所谓,一勤天下无难事,一懒世间万事休,“勤”字是当之无愧的人生第一要义。 做人做事,都应该要把勤当作根本,一分耕耘,必有一分收获。 前路有风有雨,没有谁能够无往不利,但天道酬勤,上天不会辜负每一个勤奋向上的人。 时间不等人,我们要把握当下,勤奋、积极和自律,才能行稳致远,越走越顺。