ãAmazon Linuxã§ããããã®ãã¨ã¯è¶³ããã®ã§ããããã¾ã«ã客æ§ã®ãæå®ããã§CentOSãä½¿ãæ©ä¼ãããã¾ãã
ãå°ãåã¾ã§ã¯è¦ªåãªã©ããã®èª°ããä½ã£ã¦ãããAMIãAMIã®èªä½ã試ã¿ããããªãã£ãã®ã§ãããä»ã¯ãªãã£ã·ã£ã«ãªAMIãç¨æããã¦ãã¾ãã®ã§ãããã使ã£ã¦ã¿ããã¨ã«ãã¾ããã
ãEC2ã¤ã³ã¹ã¿ã³ã¹ãç«ã¦ããã¨ããã人ã§ããããããã§ãã¾ãã
ãç½ ã£ã½ãç®æãããã¤ãããã¾ãã®ã§ãå¾ããç¶ã人ã®ããã«ç½ ãã¤ã³ããè¨ãã¦ããã¾ããåèã«ãªãã°å¹¸ãã§ãã 5åç¨åº¦ã§èªããæéã§ãããç¶ããèªãããªã³ã¯ãã¯ãªãã¯ãã¦ãã²èªãã§ã¿ã¦ãã ããã
ã¨ããããEC2ã¤ã³ã¹ã¿ã³ã¹ãä½ã
ã
â»ã»ãã¥ãªãã£ã°ã«ã¼ãããã¼ãã¢ãªã©ããªããã°ãããããä½ã£ã¦ãããã¨ããããããã¾ããã
AWS Management Consoleã§EC2ã¤ã³ã¹ã¿ã³ã¹ãä½ããã¤ãã®æé ã§ã
AWS Marketplaceã§ãCentOSããæ¤ç´¢ãã¾ãã
ã
CentOS6.3 x86_64ã®AMIãæ¤ç´¢ãã鏿ãã¾ãã
ã
CentOSã®å©ç¨æãã®ãã®ã¯ç¡æã«æè¬ãã¤ã¤ãç¶ãã¾ãã
ã
ã¤ã³ã¹ã¿ã³ã¹ã¿ã¤ãï¼ã°ã¬ã¼ãï¼ãã»ãã¥ãªãã£ã°ã«ã¼ãããã¼ãã¢ãªã©
EC2ã¤ã³ã¹ã¿ã³ã¹ãä½ãã®ã«å¿
è¦ãªé
ç®ã鏿ãã¦ã¤ã³ã¹ã¿ã³ã¹ãä½ãã¾ãã
ï¼ããã§ã»ãã¥ãªãã£ã°ã«ã¼ãããã¼ãã¢ãªã©ãå¿
è¦ã«ãªãã¾ãï¼
ã
ããã°ã£ã¦ã¤ã³ã¹ã¿ã³ã¹ãä½ã£ã¦ããã¾ãã
ã
ã¤ã³ã¹ã¿ã³ã¹ãã§ãã¾ãããAWS Management Consoleãè¦ãã¨ã¡ããã¨ã§ãã¦ã¾ãã
ã
CentOSã俺è²ã«æãã
ã
ããã®ã¾ã¾ä½¿ã£ã¦ãè¯ãã®ã§ãããå¿ è¦é½åº¦ãã¨ã«AWS Marketplaceããä½ãã®ãé¢åãªã®ã§ã俺è²ã«æããCentOSãä½ãã¾ãããã¤ã³ã¹ã¿ã³ã¹ã忢ãã¦AMIãä½ãã¾ãã忢ããªãã¦ãAMIã¯ä½ãã¾ããã忢ããã»ãã確å®ãªAMIãä½ããã¨ãã§ãã¾ããï¼AMIãä½ã£ããä¸è¦ã«ãªãã¤ã³ã¹ã¿ã³ã¹ãªã®ã§æ¢ãã¦ãã¾ãã¾ãï¼
ãAMIãä½ã£ããããã®AMIããã¤ã³ã¹ã¿ã³ã¹ãä½ãã¾ãã
ã
ã好ã¿ã®AZãããã¯VPCã«ã ã好ã¿ã®ã°ã¬ã¼ãã§ä½ãã¾ããï¼ããã§ã¯m1.smallï¼
ã
rootããªã¥ã¼ã ã®ãã£ã¹ã¯ãµã¤ãºãã好ã¿ã§ã
ã
swapé åã«ããããã®ã¨ãã§ã¡ã©ã«ã¹ãã¬ã¼ã¸ãå²ãå½ã¦ã¦ããã¾ãã
m1.smallã®å ´åãã¨ãã§ã¡ã©ã«ã¹ãã¬ã¼ã¸ã¯1ã¤(0çª)ã§150GBãå²ãå½ã¦ã§ãã¾ãã
ã¤ã³ã¹ã¿ã³ã¹ã¿ã¤ãã§å²ãå½ã¦ãããæ°ã容éãç°ãªãã¾ãã詳ããã¯ã調ã¹ãã ããã
ã
ã¤ã³ã¹ã¿ã³ã¹ãã§ããããsshã§ãã°ã¤ã³ãã¾ããAmazon Linuxã§ã¯ãec2-userãã§ãããCentOSã§ã¯ãrootãã§ããç½ ã£ã½ããã¤ã³ã
$ ssh -i ./ï¼éµãã¡ã¤ã«ï¼ root@ï¼ã¤ã³ã¹ã¿ã³ã¹åï¼
ã
å¢ãããããªã¥ã¼ã ã使ããããã«ãã¾ãã[root@ip-10-132-133-227 ~]# df -h Filesystem Size Used Avail Use% Mounted on /dev/xvde 7.9G 621M 6.9G 9% / tmpfs 828M 0 828M 0% /dev/shm [root@ip-10-132-133-227 ~]# resize2fs /dev/xvde resize2fs 1.41.12 (17-May-2010) Filesystem at /dev/xvde is mounted on /; on-line resizing required old desc_blocks = 1, new_desc_blocks = 2 Performing an on-line resize of /dev/xvde to 5242880 (4k) blocks. The filesystem on /dev/xvde is now 5242880 blocks long. [root@ip-10-132-133-227 ~]# df -h Filesystem Size Used Avail Use% Mounted on /dev/xvde 20G 625M 19G 4% / tmpfs 828M 0 828M 0% /dev/shm
ã
ã¨ãã§ã¡ã©ã«ã¹ãã¬ã¼ã¸ãswapé åã«ãã¾ãã[root@ip-10-132-133-227 ~]# free total used free shared buffers cached Mem: 1695376 139208 1556168 0 9872 40972 -/+ buffers/cache: 88364 1607012 Swap: 0 0 0 [root@ip-10-132-133-227 ~]# mkswap -c /dev/xvdf mkswap: /dev/xvdf: warning: don't erase bootbits sectors on whole disk. Use -f to force. Setting up swapspace version 1, size = 156352508 KiB no label, UUID=646f6ff5-d08d-4330-9eb3-72b9381dfe17 [root@ip-10-132-133-227 ~]# mkswap -f /dev/xvdf Setting up swapspace version 1, size = 156352508 KiB no label, UUID=d5ee486a-34e4-46eb-aa94-1ead1de3d907 [root@ip-10-132-133-227 ~]# swapon /dev/xvdf [root@ip-10-132-133-227 ~]# free total used free shared buffers cached Mem: 1695376 219524 1475852 0 4260 12424 -/+ buffers/cache: 202840 1492536 Swap: 156352504 0 156352504 [root@ip-10-132-133-227 ~]# vi /etc/fstab /dev/xvde / ext4 defaults 0 0 devpts /dev/pts devpts gid=5,mode=620 0 0 tmpfs /dev/shm tmpfs defaults 0 0 proc /proc proc defaults 0 0 sysfs /sys sysfs defaults 0 0 /dev/xvdf swap swap defaults 0 0ããâ追å
ã
ã¿ã¤ã ã¾ã¼ã³ãæ¥æ¬ã«ãã¾ããï¼ã好ã¿ã§ï¼[root@ip-10-132-133-227 ~]# date 2013å¹´ 2æ 20æ¥ æ°´ææ¥ 13:54:01 UTC [root@ip-10-132-133-227 ~]# cp -p /usr/share/zoneinfo/Japan /etc/localtime cp: overwrite `/etc/localtime'? y [root@ip-10-132-133-227 ~]# date 2013å¹´ 2æ 20æ¥ æ°´ææ¥ 22:56:04 JST
ã
SELinuxãæå¹ã«ãªã£ã¦ããã®ã§ãè¬ããªããç¡å¹ã«ãã¾ããããããªãããï¼ã好ã¿ã§ï¼ç½ ã£ã½ããã¤ã³ã[root@ip-10-132-133-227 ~]# getenforce Enforcing [root@ip-10-132-133-227 ~]# setenforce 0 [root@ip-10-132-133-227 ~]# getenforce Permissive [root@ip-10-132-133-227 ~]# vi /etc/sysconfig/selinux # This file controls the state of SELinux on the system. # SELINUX= can take one of these three values: # enforcing - SELinux security policy is enforced. # permissive - SELinux prints warnings instead of enforcing. # disabled - No SELinux policy is loaded. SELINUX=disabledããâãdisabledãã«å¤æ´ # SELINUXTYPE= can take one of these two values: # targeted - Targeted processes are protected, # mls - Multi Level Security protection. SELINUXTYPE=targeted
ã
iptablesãåãã¦ãã¾ããã»ãã¥ãªãã£ã°ã«ã¼ãã§ãã£ã«ã¿ãªã³ã°ãè¡ããªãäºéè¨å®ã«ãªã£ã¦ãã¾ããå¿ããé ã«æãã¬ç½ ã«ãªãã®ã§æ¢ãã¦ãã¾ãã¾ããï¼ã好ã¿ã§ï¼ç½ ã£ã½ããã¤ã³ã
[root@ip-10-132-133-227 ~]# iptables -L Chain INPUT (policy ACCEPT) target prot opt source destination ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED ACCEPT icmp -- anywhere anywhere ACCEPT all -- anywhere anywhere ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:ssh REJECT all -- anywhere anywhere reject-with icmp-host-prohibited Chain FORWARD (policy ACCEPT) target prot opt source destination REJECT all -- anywhere anywhere reject-with icmp-host-prohibited Chain OUTPUT (policy ACCEPT) target prot opt source destination [root@ip-10-132-133-227 ~]# /etc/rc.d/init.d/iptables stop iptables: Flushing firewall rules: [ OK ] iptables: Setting chains to policy ACCEPT: filter [ OK ] iptables: Unloading modules: [ OK ] [root@ip-10-132-133-227 ~]# chkconfig iptables off [root@ip-10-132-133-227 ~]# chkconfig --list iptables iptables 0:off 1:off 2:off 3:off 4:off 5:off 6:off
ã
ã²ã¨ã¨ãã調æ´ããã¨ãªãã¾ããããAMIãä½ã£ã¦ããã¾ãããã俺è²ã«æããCentOSãã§ãã¾ãããgccãªã©éçºãã¼ã«ãå°å ¥ããã¦ããªãã®ã§ãyum groupinstall "Development Tools"ããå®è¡ãå°å ¥ãã¦ããã®ãããã§ãããã
ã
ã¾ã¨ã
ã
- ã¤ã³ã¹ã¿ã³ã¹ãç«ã¦ãã ããªãAmazon Linuxã¨ããã¦éãã¯ããã¾ããã§ããã
- ãªãã£ã·ã£ã«ãAMIãæä¾ãã¦ããã¨ããã®ã¯ãã¯ãå¼·ã¿ã§ããã客æ§ã¯ç£å°ã«ãã ããããæã¡ã§ãã
- ã©ãããã®ããã¨ããããã°ã°ã£ãã¨ããããã¡ãã®ããã° CentOSå ¬å¼AMIã®èµ·åã¨ServerProtectã®ã¤ã³ã¹ãã¼ã« ãè¦ã¤ãã¦ãã¨ã¦ãåèã«ãªãã¾ãããã¨ããããéãé³¥ãã¿ãããªã¾ããã®å±éã«ã
- ã¤ã³ã¹ã¿ã³ã¹ãç«ã¦ãå¾ããã¼ã¸ã§ã³æå®ã§åããã±ã¼ã¸ãã¤ã³ã¹ãã¼ã«ãã使¥ããããRPMã®ä¾åæ§ã«ã ãã¶è¦ãããããã®ã§ãããããã¯ã¾ãå¥ã®ã話ã