实现步骤
由于bind主从集群安装完成后, 用webmin管理的话, 在新创建主区域后, 无法自动同步到从节点, 现在找到解决办法了
用Virtualmin去做主dns,去管理slave dns
- 在Post-Installation Wizard界面配置主从节点信息
- 在server index里将从节点加入, 用户名密码可以用webmin的主帐号 admin
- 在bind dns管理里在cluster slave servers里
加入dns slave cluster改变的文件还是蛮多的:
/etc/webmin/virtual-server/config
/etc/webmin/servers/1592326172.serv
所以最好调cgi接口去做改动
完了以后, 就可以主从自动同步了
其中修改完的virtual-server/config文件是这样的:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 |
avail_mail=1 quotas=1 defnodbname=0 bccs=0 mail_system=0 clamscan_cmd=clamscan sent_folder=Sent bw_ftplog_rotated=1 avail_change-user=1 rs_endpoint=https://identity.api.rackspacecloud.com/v1.0 edit_quota=1 nopostfix_extra_user=0 show_mailuser=1 webmin=1 avail_webminlog=0 maillog_period=30 vpopmail_group=vchkpw defmquota=51200 homes_dir=homes postgres=0 dependent_mail=0 php_vars=+memory_limit=32M nolink_certs=0 maillog_hide=0 reseller_template=none rs_snet=0 dbfnorename=0 pbzip2=0 check_apache=0 backup_feature_logrotate=1 leave_acl=0 avail_phpini=1 spam_white=0 backup_feature_webalizer=1 secmx_nodns=0 newuser_to_mailbox=1 dir=3 remote_alias=1 virtual_skel=/etc/skel groupsame=0 max_backups=3 mysql_chgrp=1 other_doms=0 show_sysinfo=2 auto_letsencrypt=0 defmongrelslimit=4 show_validation=0 gacl_root=${HOME} edit_ftp=1 avail_mailboxes=1 delete_logs=0 show_uquotas=0 defforceunder=0 alias_types=1,2,5,6,7,8,9,10,11,12,13 spam_lock=0 postfix_ssl=1 spam_trap_black=0 avail_passwd=1 from_reseller=0 preload_mode=0 aliascopy=1 gzip_mysql=1 avail_filemin=1 show_nf=master,reseller,domain vpopmail_user=vpopmail vpopmail_owner=0 gacl_groups=${GROUP} proxy_pass=0 other_users=0 show_lastlogin=0 display_max= backup_feature_mysql=1 avail_file=1 vpopmail_maildir=mail avail_bind8=1 collect_restart=0 default_procmail=0 tlsa_records=0 local_template=none can_letsencrypt=0 dovecot_ssl=1 avail_webalizer=1 bw_backup=1 check_ports=1 defuquota=1048576 bind_sub=yes mysql_mkdb=1 delete_indom=0 show_tabs=0 spamclear=none newdom_aliases=postmaster=${EMAILTO} webmaster=${EMAILTO} abuse=${EMAILTO} hostmaster=${EMAILTO} clam_delivery=/dev/null ftp_shell=/bin/false avail_dns=1 usermin_switch=1 status=0 alias_mode=1 drafts_folder=Drafts user_template=none avail_mysql=1 shell=/dev/null auto_redirect=0 show_ugroup=0 jailkit_root=/home/chroot stats_noedit=1 domains_sort=sub subdomain_template=none unix=3 hard_quotas=1 ssl=0 logrotate=1 lookup_domain_serial=0 upload_tries=3 backup_feature_virtualmin=1 defujail=0 webalizer_nocron=0 update_template=default generics=0 collect_noall=0 mysql=1 mysql_db=${PREFIX} all_namevirtual=0 name_max=20 avail_postgres=1 hashpass=0 avail_custom=0 backup_onebyone=1 backup_feature_dir=1 show_features=0 disable_mail=0 web_admin=1 avail_updown=0 php_suexec=0 allow_upper=0 defquota=1048576 show_mailsize=0 home_backup=virtualmin-backup avail_at=1 warnbw_template=default key_size=2048 webmin_ssl=1 ldap=0 hashtypes=* mysql_nouser=0 bw_maillog=auto avail_cron=1 force_email=0 passwd_mode=0 bw_notify=24 usermin_ssl=1 apache_star=0 web_webmail=1 append_style=0 show_quotas=0 initsub_template=1 avail_shell=0 avail_proc=2 template_auto=1 name_mode=0 unix_shell=/bin/bash /bin/sh edit_homes=0 backup_rotated=0 compression=0 web=0 bw_owner=1 logrotate_shared=yes avail_telnet=1 iface=eth0 avail_web=1 collect_notemp=0 disable=unix,mail,web,dns,mysql,postgres,ftp backup_feature_web=1 ip6enabled=0 ruby_suexec=-1 backuplog_days=7 output_command=0 dns_check=1 show_pass=1 stats_pass=1 mysql_nopass=0 apache_config=ServerName ${DOM} ServerAlias www.${DOM} ServerAlias mail.${DOM} DocumentRoot ${HOME}/public_html ErrorLog /var/log/virtualmin/${DOM}_error_log CustomLog /var/log/virtualmin/${DOM}_access_log combined ScriptAlias /cgi-bin/ ${HOME}/cgi-bin/ DirectoryIndex index.html index.htm index.php index.php4 index.php5 <Directory ${HOME}/public_html> Options -Indexes +IncludesNOEXEC +SymLinksIfOwnerMatch allow from all AllowOverride All </Directory> <Directory ${HOME}/cgi-bin> allow from all AllowOverride All </Directory> avail_htaccess-htpasswd=1 quota_commands=0 show_preview=2 dns=1 limitnoalias=0 bw_period=30 init_template=0 dns_prins=1 longname=0 proftpd_config=ServerName ${DOM} <Anonymous ${HOME}/ftp> User ftp Group ftp UserAlias anonymous ftp <Limit WRITE> DenyAll </Limit> RequireValidShell off ExtendedLog ${HOME}/logs/ftp.log </Anonymous> mem_low=256 backup_feature_unix=1 capabilities=none gacl_umode=1 jail_age=24 hide_alias=0 edit_afiles=1 trash_folder=Trash plan_auto=1 backup_feature_dns=1 ldap_mail=0 post_check=1 domain_template=none ldap_mailstore=$HOME/Maildir/ collect_interval=5 mx_validate=1 spam_client=spamassassin nodeniedssh=1 cert_type=sha2 gacl_ugroups=${GROUP} aws_cmd=aws batch_create=1 vpopmail_dir=/home/vpopmail index_cols=dom,user,owner,users,aliases newupdate_to_mailbox=1 append=1 backup_feature_mail=1 backup_feature_ssl=1 webmin_theme=* avail_spam=1 ldap_unix=1 ftp=0 spam=0 max_manual=0 ham_trap_white=0 reseller_unix=0 vpopmail_auto=/usr/local/bin/autorespond ipfollow=0 mail=0 bw_template=default backup_fmt=2 virus=0 pigz=0 statussslcert=1 avail_syslog=1 backup_feature_postgres=1 bw_nomailout=0 webalizer=0 max_all=1 delete_virts=0 dns_ip=* virt6=1 virt=1 first_version=6.09 old_defip=172.20.47.59 old_defip6=fe80::487:3eff:fe00:aed backup_feature_all=1 allow_subdoms=0 scriptlatest_enabled=1 allow_symlinks=0 allow_modphp=0 mysql_user_size=80 mysql_size=huge stats_hdir= domalias= php_noedit=0 bind_dmarcruf= disabled_web= dnssec_alg= othergroups= logrotate_config= statusemail= html_dir= defipfollow= deftmpl_nousers= php_ini_5.4= dnssec= php_ini_5.8= web_sslport=443 php_ini_7.4= mysql_conns=none php_ini_7.9= statustimeout= tmpl_outlook_autoconfig=none gacl_users= php_ini_5.2= namedconf= bind_spfhosts= ip_ranges6= newuser_aliases= phpver= dns_view= php_fpm= php_ini_5.7= web_urlport= php_ini_5.9= web_user= web_urlsslport= newdom_cc= defsafeunder= logrotate_files= defaliasdomslimit=* web_sslprotos= web_admindom= php_ini_7.1= html_perms=750 statustmpl= php_ini_7.3= statusonly=0 defdomslimit= phpchildren= defmailboxlimit= defcapabilities=none bind_spfall= tmpl_autoconfig=none php_ini_7.8= dns_ns=ns2.yyuap.com apache_ssl_config= default_exclude= defresources=none defaliaslimit= domains_group= dbgroup= virtual_skel_subs=0 bccto=none postgres_encoding=none mysql_hosts= mysql_wild= namedconf_no_also_notify= bind_dmarc= php_ini_5= def_webalizer= web_ssi_suffix= webmin_group= bind_config= spamtrap=none php_ini_7.2= defbwlimit= bind_master=ns1.yyuap.com mysql_charset= php_ini_5.3= extra_prefix= php_ini_7.7= defdbslimit= web_ssi=2 bind_dmarcpct=100 namedconf_no_allow_transfer= ftp_dir= defushell=none mysql_uconns=none php_ini_7.6= php_ini_5.6= mailgroup= web_writelogs= web_webmaildom= domalias_type=0 stats_dir= web_port=80 ip_ranges= bind_replace= disabled_url= defnorename= featurelimits=none mysql_collate= bind_dmarcp=none php_ini_7.0= bind_dmarcextra= php_ini_7.5= mysql_suffix= ftpgroup= bind_spfincludes= newdom_bcc= virtual_skel_nosubs= bind_indom= defrealdomslimit=* newdom_alias_bounce=0 bind_dmarcrua= last_check=1592358795 php_ini_5.5= bind_spf= newdom_subject=虚拟服务器已创建 dns_ttl= dns_records= bind_mx= dnssec_single= defugroup=none wizard_run=1 plugins_inactive= plugins= group_quotas= mail_quotas= home_quotas= |
ansible-playbook实现
ansible-playbook是这样写的:
bind.yml:
其中配置virtual server时, 一开始本来想调用uri,但是发现步骤太多麻烦而不生效,后来就直接用模板来做了
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 |
--- - name: "create server id" shell: perl -e 'print (time()+int(rand(20)))' register: server_id with_items: - "{{ groups['bind-dns'] }}" when: inventory_hostname in groups['bind-dns'] - set_fact: server_id: "{{ server_id['results'][0]['stdout']}}" when: inventory_hostname in groups['bind-dns'] - name: define paramiters for dns servers set_fact: server_id: "{{ server_id }}" prins: "ns1.{{ ns_domain }}" secns: "{{ secns|default([]) + ['ns' + (ansible_loop.index+1)|string + '.' + ns_domain] }}" old_defip: "{{ inventory_hostname }}" with_items: - "{{ groups['bind-dns'] }}" loop_control: extended: yes when: inventory_hostname in groups['bind-dns'] - name: "add hosts into /etc/hosts for bind servers" lineinfile: dest: /etc/hosts regexp: '.*{{ item }}.*$' line: "{{ hostvars[item].inventory_hostname }} {{ hostvars[item].ansible_fqdn }} ns{{ ansible_loop.index }}.{{ ns_domain }}" state: present with_items: - "{{ groups['bind-dns'] }}" loop_control: extended: yes when: inventory_hostname in groups['bind-dns'] - name: "login webmin to create a cookie" uri: url: http://127.0.0.1:20000/session_login.cgi method: POST body_format: form-urlencoded status_code: [301,302] body: user: admin pass: admin123 enter: Sign in return_content: yes headers: Cookie: "testing=1" register: login run_once: true delegate_to: "{{ groups['bind-dns'][0] }}" - name: config virtual-server template: src: virtual-server-config.j2 dest: /etc/webmin/virtual-server/config mode: '0711' run_once: true delegate_to: "{{ groups['bind-dns'][0] }}" - name: check and reload Virtualmin uri: url: http://127.0.0.1:20000/virtual-server/check.cgi? validate_certs: no method: GET #return_content: yes headers: Cookie: "{{ login.set_cookie }}" status_code: [200] run_once: true delegate_to: "{{ groups['bind-dns'][0] }}" # - name: "config virtual-server step by step" # shell: # cmd: | # url='http://127.0.0.1:20000/virtual-server/wizard.cgi' # curl -H "Cookie: {{ login.set_cookie }}" $url?step=1&preload=0&parse=Next # curl -H "Cookie: {{ login.set_cookie }}" $url?step=2&mysql=0&postgres=0&parse=Next # curl -H "Cookie: {{ login.set_cookie }}" $url?step=3&prins={{ prins }}.&secns={{ secns }}.&prins_skip=1&parse=Next # curl -H "Cookie: {{ login.set_cookie }}" $url?step=4&hashpass=0&parse=Next # curl -H "Cookie: {{ login.set_cookie }}" $url?step=5&parse=Next # run_once: true # delegate_to: "{{ groups['bind-dns'][0] }}" # register: curl # - name: config wizard # uri: # url: http://127.0.0.1:20000/virtual-server/wizard.cgi # validate_certs: no # method: POST # #return_content: yes # headers: # Cookie: "{{ login.set_cookie }}" # status_code: [200,301,302] # body_format: form-urlencoded # body: # mysql: 0 # postgres: 0 # preload: 0 # lookup: 0 # prins: "{{ prins }}" # prins_skip: 1 # secns: "{{ secns }}" # hashpass: 0 # run_once: true # delegate_to: "{{ groups['bind-dns'][0] }}" # - name: modify virtual server plugin # uri: # url: http://127.0.0.1:20000/virtual-server/save_newfeatures.cgi # validate_certs: no # method: POST # #return_content: yes # headers: # Cookie: "{{ login.set_cookie }}" # status_code: [200,301,302] # body_format: form-urlencoded # body: # fmods: dns # factive: dns # save: '%E4%BF%9D%E5%AD%98' # run_once: true # delegate_to: "{{ groups['bind-dns'][0] }}" # create server index - name: "add servers to webmin cluster" shell: cmd: | cat > /etc/webmin/servers/{{ hostvars[item].server_id }}.serv << EOF pass=admin123 ssl=0 checkssl= port=20000 host={{ item }} group= desc= user=admin id={{ hostvars[item].server_id }} type=centos fast=1 EOF run_once: true delegate_to: "{{ groups['bind-dns'][0] }}" with_items: - "{{ groups['bind-dns'][1:] }}" - name: add dns slave servers to dns master server uri: url: http://127.0.0.1:20000/bind8/slave_add.cgi validate_certs: no method: POST #return_content: yes headers: Cookie: "{{ login.set_cookie }}" status_code: [200,301,302] body_format: form-urlencoded body: server: '{{ hostvars[item].server_id }}' view_def: 1 view: '' sec: 1 sync: 1 name_def: 0 name: "{{ secns[ansible_loop.index0] }}" run_once: true delegate_to: "{{ groups['bind-dns'][0] }}" with_items: - "{{ groups['bind-dns'][1:] }}" loop_control: extended: yes - name: "Setting the Master IP Address" lineinfile: dest: /etc/webmin/bind8/config regexp: '^this_ip.*$' line: "this_ip={{ groups['bind-dns'][0] }}" state: present run_once: true delegate_to: "{{ groups['bind-dns'][0] }}" - name: Basic Setup of DNS server uri: url: http://127.0.0.1:20000/bind8/save_zonedef.cgi validate_certs: no method: POST #return_content: yes headers: Cookie: "{{ login.set_cookie }}" status_code: [200,301,302] body_format: form-urlencoded body: refresh: 10800 refunit: '' retry: 3600 retunit: '' expiry: 604800 expunit: minimum: 38400 minunit: name_0: type_0: A value_0_def: 1 name_1: type_1: A value_1_def: 1 include_def: 1 email: 'iuap_admin@yonyou.com' prins_def: 0 prins: '{{ prins }}' dnssec: 0 alg: RSASHA1 size_def: 1 size: single: 0 allow-transfer_def: 0 allow-transfer: acl1 allow-query_def: 0 allow-query: any also-notify_def: 1 also-notify: master: ignore slave: response: notify: run_once: true delegate_to: "{{ groups['bind-dns'][0] }}" - name: "add new user bind for manage dns" lineinfile: dest: /etc/webmin/miniserv.users line: "bind:$1$73641827$.K742ybaJY33hg1vQQlQL/::::::::0::::" run_once: true delegate_to: "{{item}}" loop: "{{ groups['bind-dns'] }}" - name: "add user bind acl for manage dns" lineinfile: dest: /etc/webmin/webmin.acl line: "bind: bind8" run_once: true delegate_to: "{{item}}" loop: "{{ groups['bind-dns'] }}" - name: "create bind.acl file" file: path: "/etc/webmin/bind.acl" state: touch mode: '0611' run_once: true delegate_to: "{{item}}" loop: "{{ groups['bind-dns'] }}" - name: "add bind acl for user" shell: cmd: | cat > /etc/webmin/bind.acl << 'EOF' rpc=2 nodot=0 webminsearch=1 uedit_mode=0 gedit_mode=0 feedback=2 otherdirs= readonly=0 fileunix=root uedit= negative=0 root=/ uedit2= gedit= gedit2= EOF run_once: true delegate_to: "{{item}}" loop: "{{ groups['bind-dns'] }}" - name: "set language to zh_CN for user bind" lineinfile: dest: /etc/webmin/config line: 'lang_bind=zh_CN.UTF-8' run_once: true delegate_to: "{{item}}" loop: "{{ groups['bind-dns'] }}" # add cron job for backup configure file - name: define parameter for backup.pl set_fact: script_dir: "backup-config" script: "backup.pl" - name: create backup script template: src: run_perl.j2 dest: /etc/webmin/{{ script_dir }}/{{ script }} mode: '0755' run_once: true delegate_to: "{{item}}" loop: "{{ groups['bind-dns'] }}" - name: "create cron jobs" shell: cmd: | cron_job_id=$(perl -e 'print time().$$') job_dir=/etc/webmin/{{ script_dir }}/backups backup_dir=/data/backup/bind mkdir -p $job_dir $backup_dir cat > $job_dir/${cron_job_id}.backup << EOF configfile= dest=/data/backup/bind/bind_config others= post=conf="$backup_dir/bind_config"; conf_time=\${conf}_\$(date +%F-%H-%M); [[ -f "\$conf" ]] && echo "move \$conf to \$conf_time" && mv \$conf \$conf_time pre= email= mins=0 mods=bind8 sched=1 id=$cron_job_id hours=0 days=* nofiles= emode=0 weekdays=* months=* EOF grep -q "${cron_job_id}" /var/spool/cron/root || echo "0 0 * * * /etc/webmin/backup-config/backup.pl ${cron_job_id}" >> /var/spool/cron/root run_once: true delegate_to: "{{item}}" loop: "{{ groups['bind-dns'] }}" |
templates/virtual-server-config.j2模板:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 |
avail_mail=1 quotas=1 defnodbname=0 bccs=0 mail_system=0 clamscan_cmd=clamscan sent_folder=Sent bw_ftplog_rotated=1 avail_change-user=1 rs_endpoint=https://identity.api.rackspacecloud.com/v1.0 edit_quota=1 nopostfix_extra_user=0 show_mailuser=1 webmin=1 avail_webminlog=0 maillog_period=30 vpopmail_group=vchkpw defmquota=51200 homes_dir=homes postgres=0 dependent_mail=0 php_vars=+memory_limit=32M nolink_certs=0 maillog_hide=0 reseller_template=none rs_snet=0 dbfnorename=0 pbzip2=0 check_apache=0 backup_feature_logrotate=1 leave_acl=0 avail_phpini=1 spam_white=0 backup_feature_webalizer=1 secmx_nodns=0 newuser_to_mailbox=1 dir=3 remote_alias=1 virtual_skel=/etc/skel groupsame=0 max_backups=3 mysql_chgrp=1 other_doms=0 show_sysinfo=2 auto_letsencrypt=0 defmongrelslimit=4 show_validation=0 gacl_root=${HOME} edit_ftp=1 avail_mailboxes=1 delete_logs=0 show_uquotas=0 defforceunder=0 alias_types=1,2,5,6,7,8,9,10,11,12,13 spam_lock=0 postfix_ssl=1 spam_trap_black=0 avail_passwd=1 from_reseller=0 preload_mode=0 aliascopy=1 gzip_mysql=1 avail_filemin=1 show_nf=master,reseller,domain vpopmail_user=vpopmail vpopmail_owner=0 gacl_groups=${GROUP} proxy_pass=0 other_users=0 show_lastlogin=0 display_max= backup_feature_mysql=1 avail_file=1 vpopmail_maildir=mail avail_bind8=1 collect_restart=0 default_procmail=0 tlsa_records=0 local_template=none can_letsencrypt=0 dovecot_ssl=1 avail_webalizer=1 bw_backup=1 check_ports=1 defuquota=1048576 bind_sub=yes mysql_mkdb=1 delete_indom=0 show_tabs=0 spamclear=none newdom_aliases=postmaster=${EMAILTO} webmaster=${EMAILTO} abuse=${EMAILTO} hostmaster=${EMAILTO} clam_delivery=/dev/null ftp_shell=/bin/false avail_dns=1 usermin_switch=1 status=0 alias_mode=1 drafts_folder=Drafts user_template=none avail_mysql=1 shell=/dev/null auto_redirect=0 show_ugroup=0 jailkit_root=/home/chroot stats_noedit=1 domains_sort=sub subdomain_template=none unix=3 hard_quotas=1 ssl=0 logrotate=1 lookup_domain_serial=0 upload_tries=3 backup_feature_virtualmin=1 defujail=0 webalizer_nocron=0 update_template=default generics=0 collect_noall=0 mysql=1 mysql_db=${PREFIX} all_namevirtual=0 name_max=20 avail_postgres=1 hashpass=0 avail_custom=0 backup_onebyone=1 backup_feature_dir=1 show_features=0 disable_mail=0 web_admin=1 avail_updown=0 php_suexec=0 allow_upper=0 defquota=1048576 show_mailsize=0 home_backup=virtualmin-backup avail_at=1 warnbw_template=default key_size=2048 webmin_ssl=1 ldap=0 hashtypes=* mysql_nouser=0 bw_maillog=auto avail_cron=1 force_email=0 passwd_mode=0 bw_notify=24 usermin_ssl=1 apache_star=0 web_webmail=1 append_style=0 show_quotas=0 initsub_template=1 avail_shell=0 avail_proc=2 template_auto=1 name_mode=0 unix_shell=/bin/bash /bin/sh edit_homes=0 backup_rotated=0 compression=0 web=0 bw_owner=1 logrotate_shared=yes avail_telnet=1 iface=eth0 avail_web=1 collect_notemp=0 disable=unix,mail,web,dns,mysql,postgres,ftp backup_feature_web=1 ip6enabled=0 ruby_suexec=-1 backuplog_days=7 output_command=0 dns_check=1 show_pass=1 stats_pass=1 mysql_nopass=0 apache_config=ServerName ${DOM} ServerAlias www.${DOM} ServerAlias mail.${DOM} DocumentRoot ${HOME}/public_html ErrorLog /var/log/virtualmin/${DOM}_error_log CustomLog /var/log/virtualmin/${DOM}_access_log combined ScriptAlias /cgi-bin/ ${HOME}/cgi-bin/ DirectoryIndex index.html index.htm index.php index.php4 index.php5 <Directory ${HOME}/public_html> Options -Indexes +IncludesNOEXEC +SymLinksIfOwnerMatch allow from all AllowOverride All </Directory> <Directory ${HOME}/cgi-bin> allow from all AllowOverride All </Directory> avail_htaccess-htpasswd=1 quota_commands=0 show_preview=2 dns=1 limitnoalias=0 bw_period=30 init_template=0 dns_prins=1 longname=0 proftpd_config=ServerName ${DOM} <Anonymous ${HOME}/ftp> User ftp Group ftp UserAlias anonymous ftp <Limit WRITE> DenyAll </Limit> RequireValidShell off ExtendedLog ${HOME}/logs/ftp.log </Anonymous> mem_low=256 backup_feature_unix=1 capabilities=none gacl_umode=1 jail_age=24 hide_alias=0 edit_afiles=1 trash_folder=Trash plan_auto=1 backup_feature_dns=1 ldap_mail=0 post_check=1 domain_template=none ldap_mailstore=$HOME/Maildir/ collect_interval=5 mx_validate=1 spam_client=spamassassin nodeniedssh=1 cert_type=sha2 gacl_ugroups=${GROUP} aws_cmd=aws batch_create=1 vpopmail_dir=/home/vpopmail index_cols=dom,user,owner,users,aliases newupdate_to_mailbox=1 append=1 backup_feature_mail=1 backup_feature_ssl=1 webmin_theme=* avail_spam=1 ldap_unix=1 ftp=0 spam=0 max_manual=0 ham_trap_white=0 reseller_unix=0 vpopmail_auto=/usr/local/bin/autorespond ipfollow=0 mail=0 bw_template=default backup_fmt=2 virus=0 pigz=0 statussslcert=1 avail_syslog=1 backup_feature_postgres=1 bw_nomailout=0 webalizer=0 max_all=1 delete_virts=0 dns_ip=* virt6=1 virt=1 first_version=6.09 old_defip={{ old_defip }} old_defip6= backup_feature_all=1 allow_subdoms=0 scriptlatest_enabled=1 allow_symlinks=0 allow_modphp=0 mysql_user_size=80 mysql_size=huge stats_hdir= domalias= php_noedit=0 bind_dmarcruf= disabled_web= dnssec_alg= othergroups= logrotate_config= statusemail= html_dir= defipfollow= deftmpl_nousers= php_ini_5.4= dnssec= php_ini_5.8= web_sslport=443 php_ini_7.4= mysql_conns=none php_ini_7.9= statustimeout= tmpl_outlook_autoconfig=none gacl_users= php_ini_5.2= namedconf= bind_spfhosts= ip_ranges6= newuser_aliases= phpver= dns_view= php_fpm= php_ini_5.7= web_urlport= php_ini_5.9= web_user= web_urlsslport= newdom_cc= defsafeunder= logrotate_files= defaliasdomslimit=* web_sslprotos= web_admindom= php_ini_7.1= html_perms=750 statustmpl= php_ini_7.3= statusonly=0 defdomslimit= phpchildren= defmailboxlimit= defcapabilities=none bind_spfall= tmpl_autoconfig=none php_ini_7.8= dns_ns={% for s in secns %}{{ s }}. {% endfor %} apache_ssl_config= default_exclude= defresources=none defaliaslimit= domains_group= dbgroup= virtual_skel_subs=0 bccto=none postgres_encoding=none mysql_hosts= mysql_wild= namedconf_no_also_notify= bind_dmarc= php_ini_5= def_webalizer= web_ssi_suffix= webmin_group= bind_config= spamtrap=none php_ini_7.2= defbwlimit= bind_master={{ prins }} mysql_charset= php_ini_5.3= extra_prefix= php_ini_7.7= defdbslimit= web_ssi=2 bind_dmarcpct=100 namedconf_no_allow_transfer= ftp_dir= defushell=none mysql_uconns=none php_ini_7.6= php_ini_5.6= mailgroup= web_writelogs= web_webmaildom= domalias_type=0 stats_dir= web_port=80 ip_ranges= bind_replace= disabled_url= defnorename= featurelimits=none mysql_collate= bind_dmarcp=none php_ini_7.0= bind_dmarcextra= php_ini_7.5= mysql_suffix= ftpgroup= bind_spfincludes= newdom_bcc= virtual_skel_nosubs= bind_indom= defrealdomslimit=* newdom_alias_bounce=0 bind_dmarcrua= last_check=1592358795 php_ini_5.5= bind_spf= newdom_subject=虚拟服务器已创建 dns_ttl= dns_records= bind_mx= dnssec_single= defugroup=none wizard_run=1 plugins_inactive= plugins= group_quotas= mail_quotas= home_quotas= |
defaults/main.yml
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 |
--- # defaults file for webmin webmin_version: 1.941 virtualmin_version: 6.09.gpl webmin_dir: /etc/webmin uninstall_webmin: false upgrade_webmin: false webmin_packages: - perl - perl-libwww-perl - perl-DBI - perl-DBD-MySQL - perl-GD - perl-HTML-Parser - perl-devel - openssl - perl-Encode-Detect - perl-Net-SSLeay - perl-Socket6 - perl-IO-Socket-INET6 mysql_database: ns_domain: yyuap.com |
参考以下文章:
Introduction
This tutorial will show you how to install Virtualmin/Webmin on an Ubuntu cloud server and how to setup a DNS Master and a DNS Slave server. The setup covers all required steps.
Please note that this setup is for the Ubuntu cloud server, however it could possibly work for other cloud server OS distress.
Overview
- Requirements
- Notes
- First steps
- Installing the primary server
- Installing the secondary server
- Configure Cluster and DNS
- Pointing the main domain to DigitalOcean’s name servers
- Other options
Requirements
- Two Ubuntu 12.04 LTS (x32/x64) cloud servers
- Primary server (minimum: 1GB, 1CPU, 30SSD; optimal: up to your needs)
- Secondary server (minimum: 512MB)
- Domain name – Set its name servers to DigitalOcean’s name servers. (Maybe you can do this after server install because of the technical check.)
Notes
Virtualmin is a powerful web hosting control panel. You can manage your virtual domains, mailboxes, and databases. It is based on Webmin, a powerful control panel, which you can manage your server with.
Important: You cannot manage your main domain’s DNS as we use DigitalOcean’s name servers, so you have to setup your DNS records on the DigitalOcean control panel. If you create a virtual server in Virtualmin, you HAVE TO disable DNS.
First Steps
Let’s start. Create two droplets (cloud servers). For the first usage, I recommend the following configurations:
- Primary server
- 1GB RAM
- 1 CPU
- Ubuntu 12.04 LTS x64
- server1.example.com
- 198.199.103.8
- Virtualmin
- Secondary server
- 512MB RAM
- 1 CPU
- Ubuntu 12.04 LTS x64
- server2.example.com
- 198.199.103.178
- Webmin
If you don’t know how to create cloud servers, please refer to this article.
Please note: Virtualmin only works with LTS versions. (For other OS, please check the compatibility here.)
In this tutorial I use the hostname server1.example.com with the IP address 198.199.103.8 and the hostname server2.example.com with the IP address 198.199.103.178. These settings might differ for you, so you have to replace them where appropriate.
Setting up domain DNS (optional)
Now go to the Networking tab in the Control Panel. Enter your domain name (example.com
in this example) in the Add a domain field:
Click on the A record type. In the HOSTNAME field, enter “server1” and in the WILL DIRECT TO field, type 198.199.103.8
(our IP address in this example). Click the Create Record button when you are finished. Repeat this process again, using “server2” as the hostname the second time.
Optional: You can create Address records to have ns1.example.com and ns2.example.com keeping with the convention of naming name servers nsN.domain.tld.
You don’t have to point the domain to DigitalOcean’s name servers. You can use your provider’s name servers for the main domain. This will be discussed later.
Other notes: This tutorial assumes that you are logged in with root user. If not, please get root permissions, because I omit the sudo:
1 |
sudo su |
Installing the Primary Server
This server will be our primary DNS and Virtualmin server. The first step is to edit the hosts file:
1 |
nano /etc/hosts |
Make it look like this:
1 2 3 4 5 6 7 8 9 10 |
127.0.0.1 localhost 198.199.103.8 server1.example.com server1 ns1.example.com 198.199.103.178 server2.example.com server2 ns2.example.com # The following lines are desirable for IPv6 capable hosts ::1 ip6-localhost ip6-loopback fe00::0 ip6-localnet ff00::0 ip6-mcastprefix ff02::1 ip6-allnodes ff02::2 ip6-allrouters |
Make sure your system has a fully-qualified domain name:
1 |
hostname -f |
You should see server1.example.com
Now download the script and install Virtualmin:
1 2 3 |
wget http://software.virtualmin.com/gpl/scripts/install.sh chmod +x install.sh ./install.sh |
Answer ‘y’ for the asked question. There sould be no more questions. After the installation you can login here:
1 |
https://server1.example.com:10000 |
or
1 |
https://198.199.103.8:10000 |
Login with root. You will see a Post-Installation Wizard. For now just click next until you see this:
Make the settings look like the picture (You can also enter server1.example.com as primary, and server2.example.com as secondary DNS). If you confirmed that DNS has refreshed correctly, you can omit checking the checkbox.
Keep clicking next until the end of wizard.
Installing the Secondary Server
This server will be our secondary DNS and Webmin server
The first step is to edit the hosts file again:
1 |
nano /etc/hosts |
Make it look like this:
1 2 3 4 5 6 7 8 9 10 |
127.0.0.1 localhost 198.199.103.178 server2.example.com server2 ns2.example.com 198.199.103.8 server1.example.com server1 ns1.example.com # The following lines are desirable for IPv6 capable hosts ::1 ip6-localhost ip6-loopback fe00::0 ip6-localnet ff00::0 ip6-mcastprefix ff02::1 ip6-allnodes ff02::2 ip6-allrouters |
Add the Webmin repositories to sources.list and install Webmin:
1 2 3 4 5 |
echo "deb http://download.webmin.com/download/repository sarge contrib" >> /etc/apt/sources.list.d/webmin.list echo "deb http://webmin.mirror.somersettechsolutions.co.uk/repository sarge contrib" >> /etc/apt/sources.list.d/webmin.list wget -O - http://www.webmin.com/jcameron-key.asc | apt-key add - apt-get update apt-get install -y webmin |
Install BIND9 DNS server:
1 |
apt-get install bind9 |
After the installation you can login here:
1 |
https://server2.example.com:10000 |
or
1 |
https://198.199.103.178:10000 |
Configuring Cluster and DNS
Configuring Webmin Server
Go back to the Virtualmin server. Log in with root and go to the Webmin section. Browse Webmin>Webmin Servers Index.
Click Register a new server.
Enter server2.example.com as the hostname of your slave server.
Select Ubuntu OS as OS type.
Select a Link type of Login via Webmin with username, and enter the authentication details for your root account.
Change Make fast RPC calls? to Yes.
Click Save.
Configuring Secondary DNS
Now go to Servers>BIND DNS Server and click on Cluster Slave Servers.
In the Add server drop-down menu, select your slave server (if it’s the only server you’ve added, you won’t have to select it, as it will already be selected).
Set the Create secondary on slave when creating locally? option to Yes.
If you have already created any domains on your Virtualmin server, set the Create all existing master zones on slave? option to Yes.
If you entered ns2.example.com in the Post-Installation Wizard as secondary name server, then change the Name for NS record option to textbox and enter it.
Click Add server and return to the Module Index.
Click Apply Configuration in the right corner.
Setting the Master IP Address (optional)
By default, Virtualmin will use the IP address that the master server’s hostname resolves to as the IP that the slaves should contact to transfer records. However, on some systems this IP is 127.0.0.1, which will not work. If you edited the hosts file at the beginning of the tutorial this should not be a problem, but I’ll show you how to solve this.
Go to Servers>BIND DNS Server, and click on Module Config.
In the Cluster slave servers section, find the Default master server IP for remote slave zones field.
Enter the IP address of your master server.
Click Save. Any DNS zones created from now on will use that IP.
Click Apply Configuration in the right corner.
Please note: that it won’t update existing DNS zones.
Basic Setup of DNS server
There are some more options that you should check. Go to Servers>BIND DNS Server and click on Zone defaults
Set the Default email address to an existing email address (Some technical check requires to set an existing email address).
Set Default nameserver for master domains to ns1.example.com (optional).
Click Apply Configuration in the right corner.
Create new DNS zone
Now it’s time to test our settings. Click on Create master Zone. Enter your domain name.
Check your settings (By default, the IP address for address records will be the primary server’s IP address).
Click Create.
Check your master zone on primary and slave zone on the secondary server.
Pointing the Main Domain to DigitalOcean’s Name Servers
The most common problem is that in some cases there is a technical check which requires an email address. That email address is set in the DNS zone file, which is hostmaster@domain.tld, postmaster@domain.tld, etc. by default. Some domain providers let you edit this email address, but most of them do not.
You can solve this problem by pointing the domain to DigitalOcean’s name servers. Of course you can’t do that immediately. After completing this tutorial you have to create a virtual domain in postfix module and create an alias for hostmaster@domain.tld or you can create a virtual server in Virtualmin for domain example.com, which will create these aliases for you, but remember to disable DNS zone.
Other Options
If you want only DNS management, you can install two Webmin instances instead of Virtualmin and Webmin, but this way you have to create DNS records manually. It is the same as Webmin installation above, but you have to do it twice. From Configure Cluster and DNS the steps are the same.
You can use your secondary DNS server for more than one Virtualmin server. In this case the primary DNS server is the virtualmin server, the secondary is the webmin server. This means that you have several Virtualmin servers which are primary DNS servers and you have only one secondary server.
You can use two Virtualmin server as DNS servers. In this case each virtualmin server wil conatin the master zone for the domains added to them. This means that if you create a virtual server in virtualmin1, then virtualmin1 will be the primary DNS server for that domain.
All done!
You have successfully finished this tutorial.
https://www.digitalocean.com/community/tutorials/how-to-setup-dns-slave-auto-configuration-using-virtualmin-webmin-on-ubuntu
0 Comments