概述

前面已经介绍了jumpserver的一些概念,今天主要分享如何去搭建jumpserver跳板机,下面一起来看看吧~


组件说明

端口说明

ProtocolServer namePortTCPJumpserver8080TCPCoco2222, 5000TCPGuacamole8081TCPDb3306TCPRedis6379TCPNginx80


环境
一、nginx代理部署

1、关闭防火墙和SELINUX

1.1、设置防火墙

systemctl stop firewalld.service systemctl disable firewalld.service systemctl list-unit-files|grep firewalld

1.2、设置 selinux

setenforce 0 sed -i "s/SELINUX=enforcing/SELINUX=disabled/g" /etc/selinux/config

2、配置yum并升级

for i in /etc/yum.repos.d/*.repo;do cp $i ${i%.repo}.bak;done;rm -rf /etc/yum.repos.d/*.repo wget -P /etc/yum.repos.d/ http://mirrors.aliyun.com/repo/Centos-7.repo >/dev/null 2>&1 yum clean all;yum repolist #安装基本依赖 yum update -y>/dev/null && yum install wget unzip epel-release gcc automake zlib-devel openssl-devel yum-utils git -y >/dev/null 2>&1

jumpserver安装要求(史上最详细的跳板机jumpserver搭建教程)(1)

3、获取 epel-release 源

yum -y install epel-release

4、安装nginx

sudo rpm -Uvh http://nginx.org/packages/centos/7/noarch/RPMS/nginx-release-centos-7-0.el7.ngx.noarch.rpm yum -y install nginx systemctl enable nginx

jumpserver安装要求(史上最详细的跳板机jumpserver搭建教程)(2)

5、安装luna

wget https://github.com/jumpserver/luna/releases/download/1.5.0/luna.tar.gz -O /opt/luna.tar.gz tar -xvf /opt/luna.tar.gz -C /opt # 如果网络有问题导致下载无法完成可以使用下面地址 #wget https://demo.jumpserver.org/download/luna/1.5.0/luna.tar.gz

jumpserver安装要求(史上最详细的跳板机jumpserver搭建教程)(3)


二、数据库部署

1、安装mariadb

cat >/etc/yum.repos.d/mariadb.repo <<EOF [mariadb] name = MariaDB baseurl = http://mirrors.ustc.edu.cn/mariadb/yum/10.1/centos7-amd64 gpgkey=http://mirrors.ustc.edu.cn/mariadb/yum/RPM-GPG-KEY-MariaDB gpgcheck=1 EOF yum clean all;yum makecache;yum repolist yum install mariadb mariadb-devel mariadb-server mariadb-common -y

jumpserver安装要求(史上最详细的跳板机jumpserver搭建教程)(4)

2、数据初始化

systemctl start mariadb #初始化 mysql_secure_installation # 推荐设置 root 密码, 其他选项可以全部 y systemctl stop mariadb

jumpserver安装要求(史上最详细的跳板机jumpserver搭建教程)(5)

jumpserver安装要求(史上最详细的跳板机jumpserver搭建教程)(6)

3、创建 Jumpserver 数据库及授权

systemctl start mariadb mysql -uroot -p create database jumpserver default charset 'utf8'; grant all on jumpserver.* to 'jumpserver'@'*' identified by 'fswl@1234'; grant all on jumpserver.* to 'jumpserver'@'localhost' identified by 'fswl@1234'; flush privileges; quit


篇幅有限,这里主要介绍nginx和mariadb部分,后面会分享更多jumpserver搭建方面的内容,感兴趣的朋友可以关注一下~

jumpserver安装要求(史上最详细的跳板机jumpserver搭建教程)(7)

,