Editing 2014 Server Migration

Jump to: navigation, search

Warning: You are not logged in.

Your IP address will be recorded in this page's edit history.
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision Your text
Line 3: Line 3:
 
== Server selection ==
 
== Server selection ==
  
On 2014-06-24, the WPLUG board decided to go with the $10/month [https://www.linode.com/pricing?r=30335eb136f2c5f7fa3429dce9f15bea836f81d3 Linode] plan, locating in their Atlanta datacenterThis plan will approximately halve our current costs and still provide sufficient resources.
+
We are currently hosting with [https://www.linode.com/pricing?r=30335eb136f2c5f7fa3429dce9f15bea836f81d3 Linode] on the $20/month plan.  The new $10/month plan will halve our costs and still provide sufficient resources.  We currently are located in the Atlanta datacenter.  This is good because it is still in the Eastern time zone and is not too far away but should be remote from any disaster that might occur in Pittsburgh.  The only downside is they block some ports, which means Monkeybot needs to be configured to use an alternative port to connect to Freenode IRC.  The Newark datacenter would be closer and doesn't block ports.  However, a large-scale power outage could affect both Pittsburgh and New Jersey.
 +
 
 +
Other options are possible; for example [https://www.digitalocean.com/pricing Digital Ocean] has a $5/month plan that has less horsepower but should still be sufficient for our needs.  The main benefit is that costs would be halved again.
 +
 
 +
You can add your suggestions in this section.  Note that web hosting is not sufficient; we need a virtual private server (VPS) or dedicated server to accommodate our mailing lists and IRC bot.  Since we've been very happy with the service we've gotten from Linode and are comfortable with how it works, please support alternative suggestions with a compelling case for how they'd be an improvement.
  
 
== OS selection ==
 
== OS selection ==
Line 29: Line 33:
 
* Greylisting daemon (Postgrey)
 
* Greylisting daemon (Postgrey)
 
* Fail2ban - could maybe use denyhosts instead
 
* Fail2ban - could maybe use denyhosts instead
* Aide - could be used for intrusion detection
 
  
 
=== Support lifetime ===
 
=== Support lifetime ===
  
 
* CentOS 6 - [http://wiki.centos.org/FAQ/General#head-fe8a0be91ee3e7dea812e8694491e1dde5b75e6d 2020-11-30]
 
* CentOS 6 - [http://wiki.centos.org/FAQ/General#head-fe8a0be91ee3e7dea812e8694491e1dde5b75e6d 2020-11-30]
* CentOS 7 - will probably match RHEL 7 support deadline of [https://access.redhat.com/site/support/policy/updates/errata/#Life_Cycle_Dates 2024-06-30]
+
* CentOS 7 - not released yet, will probably match RHEL 7 support deadline of [https://access.redhat.com/site/support/policy/updates/errata/#Life_Cycle_Dates 2024-06-30]
 
* Debian 7 "wheezy" - [http://en.wikipedia.org/wiki/Debian#Security_updates one year after release of v. 8 "jessie"] ([http://ostatic.com/blog/early-plans-for-debian-8-0-jessie-emerge anticipated mid-2015]), possible [http://www.debian.org/News/2014/20140424.en.html unofficial long-term support] available after that
 
* Debian 7 "wheezy" - [http://en.wikipedia.org/wiki/Debian#Security_updates one year after release of v. 8 "jessie"] ([http://ostatic.com/blog/early-plans-for-debian-8-0-jessie-emerge anticipated mid-2015]), possible [http://www.debian.org/News/2014/20140424.en.html unofficial long-term support] available after that
 
* Ubuntu 14.04 LTS - [http://en.wikipedia.org/wiki/Ubuntu_(operating_system)#Releases 2019-04-17]
 
* Ubuntu 14.04 LTS - [http://en.wikipedia.org/wiki/Ubuntu_(operating_system)#Releases 2019-04-17]
Line 58: Line 61:
 
|postfix
 
|postfix
 
|B 2.6
 
|B 2.6
|B 2.10
+
|B 2.10.1
 
|B 2.9
 
|B 2.9
 
|B 2.11
 
|B 2.11
Line 64: Line 67:
 
|mailman
 
|mailman
 
|B 2.1
 
|B 2.1
|B 2.1
+
|A 2.1.15 <sup>latest</sup>
 
|B 2.1
 
|B 2.1
 
|B 2.1
 
|B 2.1
Line 76: Line 79:
 
|mediawiki
 
|mediawiki
 
|T 1.19<sup>EPEL</sup>
 
|T 1.19<sup>EPEL</sup>
|~
+
|?
 
|B 1.19
 
|B 1.19
 
|A 1.19
 
|A 1.19
Line 82: Line 85:
 
|wordpress
 
|wordpress
 
|T 3.9<sup>EPEL</sup>
 
|T 3.9<sup>EPEL</sup>
|T 3.9<sup>EPEL</sup>
+
|T 3.9.1<sup>EPEL</sup>
 
|B 3.6
 
|B 3.6
 
|A 3.8
 
|A 3.8
Line 88: Line 91:
 
|infobot
 
|infobot
 
|~
 
|~
|~
+
|?
 
|? (not B or A)
 
|? (not B or A)
 
|~
 
|~
Line 94: Line 97:
 
|tt-rss
 
|tt-rss
 
|~
 
|~
|~
+
|?
 
|? (not B or A)
 
|? (not B or A)
 
|A 1.11
 
|A 1.11
Line 100: Line 103:
 
|apache
 
|apache
 
|B 2.2 / A 2.4
 
|B 2.2 / A 2.4
|B 2.4
+
|A 2.4.6<sup>latest</sup>
 
|B 2.2
 
|B 2.2
 
|B 2.4
 
|B 2.4
Line 112: Line 115:
 
|php5
 
|php5
 
|B 5.3 / A 5.4, 5.5
 
|B 5.3 / A 5.4, 5.5
|B 5.4, T 5.5.14<sup>Remi</sup>
+
|A 5.4.16<sup>latest</sup>, T 5.5.13<sup>Remi</sup>
 
|B 5.4
 
|B 5.4
 
|B 5.5
 
|B 5.5
Line 130: Line 133:
 
|perl5
 
|perl5
 
|B 5.10
 
|B 5.10
|B 5.16
+
|B 5.16.3
 
|B 5.14
 
|B 5.14
 
|B 5.18
 
|B 5.18
Line 142: Line 145:
 
|mariadb
 
|mariadb
 
|A 5.5
 
|A 5.5
|B 5.5
+
|A 5.5.35<sup>latest</sup>
 
|? (not B or A)
 
|? (not B or A)
 
|A 5.5
 
|A 5.5
Line 148: Line 151:
 
|fail2ban
 
|fail2ban
 
|T 0.8.7<sup>rf</sup>, 0.8.11<sup>EPEL</sup>
 
|T 0.8.7<sup>rf</sup>, 0.8.11<sup>EPEL</sup>
|T 0.9<sup>EPEL</sup>, 0.8.7<sup>rf</sup>
+
|T 0.8.7<sup>rf</sup>
 
|B 0.8.6
 
|B 0.8.6
 
|A 0.8.11
 
|A 0.8.11
Line 157: Line 160:
 
|B 2.6
 
|B 2.6
 
|[https://launchpad.net/ubuntu/trusty/amd64/denyhosts ~]
 
|[https://launchpad.net/ubuntu/trusty/amd64/denyhosts ~]
|-
 
|aide
 
|B 0.14
 
|B 0.15.1
 
|?
 
|0.16a2
 
 
|}
 
|}
  
Line 172: Line 169:
 
== Migration steps ==
 
== Migration steps ==
  
* <strike>Obtain [https://library.linode.com/networking/ipv6#sph_ipv6-address-pools IPv6 address pool] from Linode (support ticket needed)</strike>
+
Put some stuff here.
** <strike>/etc/sysconfig/network-scripts/ifcfg-eth0 edited, reboot needed to apply - 2600:3c02:e000:0047::2/64 assigned</strike>
+
* <strike>Explore what software to use to help harden up the installation (fail2ban, etc.)</strike> ''Decided to use fail2ban-firewalld''
+
* <strike>Deploy new CentOS 7 instance</strike>
+
* (optional) Set up [https://library.linode.com/remote-access#sph_adding-private-ip-addresses private IPv4 addresses] for transfer between old and new VPS (avoids bandwidth charges)
+
* <strike>Set up SSH (edit sshd_config to tighten up security)</strike>
+
* <strike>Migrate current users to new server</strike>
+
* <strike>Ensure NTP is running, and set timezone to EDT</strike>
+
* <strike>Set up the firewall (either using firewalld, or else [https://fedoraproject.org/wiki/FirewallD?rd=FirewallD/#Using_static_firewall_rules_with_the_iptables_and_ip6tables_services installing iptables and using the old rules])</strike>
+
* <strike>Install Apache, and edit httpd.conf appropriately</strike>
+
* <strike>Install PHP, edit php.ini appropriately, and make sure all needed modules are installed</strike>
+
* <strike>Install MariaDB, add appropriate user(s)/permissions, and edit my.cnf appropriately</strike>
+
* <strike>Install/configure Postgrey</strike>
+
* <strike>Install/configure Postfix</strike>
+
* <strike>Install/configure Mailman</strike>
+
** <strike>archives copied over</strike>
+
* <strike>Install/configure monkeybot</strike>
+
* <strike>Install/configure Tiny Tiny RSS</strike>
+
* <strike>Migrate any other files that must be moved</strike>
+
* <strike>Export current MySQL and import into new MariaDB (be sure to dump/restore final DB before switchover...)</strike>
+
* <strike>Install/configure MediaWiki</strike>
+
* <strike>Set up repeating jobs (log rotation, etc.) via systemd/cron</strike>
+
** <strike>Copy over 'at' job to remind about domain registration expiration</strike>
+
** <strike>Migrate over monkeybot cron jobs</strike> ''Waiting to see if logrotate runs overnight, as we are not sure that run-parts is being run by anything on the new system.''
+
** <strike>Configure log rotation</strike>
+
* <strike>Cut over DNS (or [https://library.linode.com/remote-access#sph_swapping-ip-addresses swap IPv4 addresses])</strike>
+
* Other steps not mentioned above
+
  
 
=== Nice-to-haves ===
 
=== Nice-to-haves ===
  
 
We have an archive of static web pages from the pre-2007 server "penguin" - it would be nice to make this history available somehow.
 
We have an archive of static web pages from the pre-2007 server "penguin" - it would be nice to make this history available somehow.
$9/year Comodo SSL certificate through Namecheap: [https://www.namecheap.com/security/ssl-certificates/comodo.aspx]
 
  
=== Installation Notes ===
 
[https://www.centos.org/forums/viewtopic.php?f=48&t=47284 Installing fail2ban on CentOS 7]
 
  
 
[[Category:Migration]]
 
[[Category:Migration]]

Please note that all contributions to WPLUG may be edited, altered, or removed by other contributors. If you do not want your writing to be edited mercilessly, then do not submit it here.
You are also promising us that you wrote this yourself, or copied it from a public domain or similar free resource (see WPLUG:Copyrights for details). Do not submit copyrighted work without permission!

Cancel | Editing help (opens in new window)