[{"data":1,"prerenderedAt":338},["ShallowReactive",2],{"site-data":3,"article-90":143,"article-show-hot-90":172,"article-show-new-90":262},{"settings":4,"categorys":35,"tree":97,"models":118,"search_model_select":128,"nav_list":130},{"changefreq":5,"changyan_app_id":6,"changyan_app_key":6,"copy":7,"description":8,"editor":9,"file":6,"guest_feedback":10,"head_html":6,"icp":11,"index_banner":12,"index_banner_bg":13,"is_excel":14,"is_watermark":10,"keywords":15,"links":16,"logo":17,"lzcms_banner":6,"lzcms_banner_link":18,"member_register_enabled":14,"qq_app_id":6,"qq_app_key":6,"qr_code":6,"search_model":19,"site_closedreason":6,"site_idea":6,"site_idea1":20,"site_idea2":21,"site_idea3":22,"site_name":23,"site_statistice":6,"site_status":14,"site_url":18,"sitemap_model":19,"stationmaster_motto":24,"stationmaster_name":25,"stationmaster_occupation":26,"stationmaster_qq":27,"stationmaster_qqnet":28,"stationmaster_qqnet_code":29,"threshold":14,"title_add":30,"watermark":6,"watermark_alpha":31,"watermark_height":32,"watermark_locate":33,"watermark_width":34},"weekly","","版权所有 © \u003Ca class=\"site_url\" href=\"https://zhl123.com\">2026 zhl123.com\u003C/a>","linux、Python、mysql、docker、k8s技术交流","layedit","0","粤ICP备15054664号-1","/uploads/images/20181109/7a86191de8b8bb60e9c6b54d8b27c5cc.jpg","#xe604","1","linux、Python、mysql、docker、k8s","{\"1\":{\"id\":\"1\",\"link_url\":\"https://linux.org\",\"logo\":\"\",\"name\":\"linux\",\"sort\":\"0\",\"status\":\"1\"}}","/uploads/images/20181109/e7305012448aed257176dd591846f50a.png","https://zhl123.com","2","学无止境\n学习，探索，研究，从不了解到了解，从无知到掌握，到灵活运用，在不断的学习中加深认识。由浅入深，由表及里。","业精于勤\n“业精于勤荒于嬉”，精深的业技靠的是勤学、刻苦努力，靠的是争分夺秒的勤学苦练才会有精深的技术。得在认真，失在随便。","工匠精神\n精益求精，注重细节，追求完美和极致，不惜花费时间精力，孜孜不倦，反复改进产品，把99%提高到99.99%。","linux","业精于勤、学无止境、工匠精神","廖地金","高级Linux运维工程师","1256636645","592958303","\u003Ca target=\"_blank\" href=\"//shang.qq.com/wpa/qunwpa?idkey=09be7d1a682073783fd636102e666393169b8a8aac8f3393da1de57bcaa821a0\">\u003Cimg border=\"0\" src=\"//pub.idqqimg.com/wpa/images/group.png\" alt=\"Linux技术\" title=\"Linux技术\">\u003C/a>"," | Python | mysql | docker | k8s 技术交流","100","300","9","500",{"0":36,"17":51,"18":60,"19":63,"20":67,"21":71,"22":76,"25":80,"26":83,"27":89,"29":94},{"children":37},{"0":38,"25":43,"26":48},[39,40,41,42],25,21,22,26,[44,45,46,47],17,18,19,20,[49,50],27,29,{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},"index",1,"list","article",2,"文章模型","show","/article/lists?category_id=17",{"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},"python","/article/lists?category_id=18",{"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},"容器技术",3,"/article/lists?category_id=19",{"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},"负载均衡",4,"/article/lists?category_id=20",{"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},"分享无价",0,5,"/article/lists?category_id=21",{"create_time":6,"description":6,"id":41,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":77,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":78,"subtitle":6,"update_time":6,"url":79},"随笔",6,"/article/lists?category_id=22",{"create_time":6,"description":6,"id":39,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":81,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":73,"subtitle":6,"update_time":6,"url":82},"学无止境","/article/lists?category_id=25",{"create_time":6,"description":6,"id":42,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":84,"model_id":65,"model_name":85,"name":86,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":87,"subtitle":6,"update_time":6,"url":88},"picture","图集模型","关于",8,"/picture/lists?category_id=26",{"create_time":6,"description":6,"id":49,"image_url":6,"index_template":52,"is_cover":53,"is_menu":73,"keywords":6,"list_template":54,"model_code":90,"model_id":53,"model_name":91,"name":92,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":93},"page","单页模型","关于博主","/page/27",{"create_time":6,"description":6,"id":50,"image_url":6,"index_template":52,"is_cover":73,"is_menu":73,"keywords":6,"list_template":54,"model_id":73,"name":95,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":96},"留言","/feedback",[98,108,110,112],{"children":99,"create_time":6,"description":6,"id":39,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":81,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":73,"subtitle":6,"update_time":6,"url":82},[100,102,104,106],{"children":101,"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},[],{"children":103,"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},[],{"children":105,"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},[],{"children":107,"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},[],{"children":109,"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},[],{"children":111,"create_time":6,"description":6,"id":41,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":77,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":78,"subtitle":6,"update_time":6,"url":79},[],{"children":113,"create_time":6,"description":6,"id":42,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":84,"model_id":65,"model_name":85,"name":86,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":87,"subtitle":6,"update_time":6,"url":88},[114,116],{"children":115,"create_time":6,"description":6,"id":49,"image_url":6,"index_template":52,"is_cover":53,"is_menu":73,"keywords":6,"list_template":54,"model_code":90,"model_id":53,"model_name":91,"name":92,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":93},[],{"children":117,"create_time":6,"description":6,"id":50,"image_url":6,"index_template":52,"is_cover":73,"is_menu":73,"keywords":6,"list_template":54,"model_id":73,"name":95,"parent_id":42,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":47,"subtitle":6,"update_time":6,"url":96},[],{"1":119,"2":120,"3":121,"4":122,"5":125},{"id":53,"index_template":52,"list_template":54,"name":91,"show_template":58,"status":73,"tablename":90},{"id":56,"index_template":52,"list_template":54,"name":57,"show_template":58,"status":73,"tablename":55},{"id":65,"index_template":52,"list_template":54,"name":85,"show_template":58,"status":73,"tablename":84},{"id":69,"index_template":52,"list_template":54,"name":123,"show_template":58,"status":73,"tablename":124},"链接模型","link",{"id":74,"index_template":52,"list_template":54,"name":126,"show_template":58,"status":73,"tablename":127},"下载模型","download",[129],{"id":56,"name":57,"tablename":55},[131,137,139,141],{"children":132,"create_time":6,"description":6,"id":39,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":81,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":73,"subtitle":6,"update_time":6,"url":82},[133,134,135,136],{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},{"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},{"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},{"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},{"children":138,"create_time":6,"description":6,"id":40,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":72,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":74,"subtitle":6,"update_time":6,"url":75},[],{"children":140,"create_time":6,"description":6,"id":41,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":77,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":78,"subtitle":6,"update_time":6,"url":79},[],{"children":142,"create_time":6,"description":6,"id":42,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":84,"model_id":65,"model_name":85,"name":86,"parent_id":73,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":87,"subtitle":6,"update_time":6,"url":88},[],{"article":144,"breadcrumb":155,"category":159,"next":160,"prev":163,"second_categorys":166,"seo":171},{"id":145,"category_id":44,"title":146,"keywords":147,"description":148,"image_url":6,"content":149,"content_md":150,"url":151,"hits":152,"is_recommend":73,"is_top":73,"create_time":153,"update_time":154},90,"Centos7 快速配置Let's encrypt通配符证书","通配符,证书","一、说明利用certbot工具配置Let’s encrypt通配符证书，所域名下所有的子域名都能方便的使用 https证书，而且完全免费。值得关注的是，Let’s encrypt通配符证书只是针对二级域名，并不能针对主域名，如*.zhl123.com和zhl123.com 被认为是两个域名，如果和我一样使用的是主域名，在申请的时候需要注意都要申请。二、环境 操作系统：CentOS Linux release 7.5.1804 (Core)配置域名：zhl123.com，","\u003Cp align=\"left\">\u003Cstrong>一、说明\u003C/strong>\u003C/p>\u003Cp align=\"left\">&nbsp;\u003C/p>\u003Cp>利用certbot工具配置Let’s encrypt通配符证书，所域名下所有的子域名都能方便的使用 https证书，而且完全免费。值得关注的是，\u003C/p>\u003Cp>Let’s encrypt通配符证书只是针对二级域名，并不能针对主域名，如*.zhl123.com和zhl123.com 被认为是两个域名，\u003C/p>\u003Cp>如果和我一样使用的是主域名，在申请的时候需要注意都要申请。\u003Cbr>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp id=\"配置环境\">\u003Cstrong>二、环境\u003C/strong>\u003C/p>\u003Cp>&nbsp;\u003C/p>\u003Cp>操作系统：CentOS Linux release 7.5.1804 (Core)\u003C/p>\u003Cp>\u003Cbr>配置域名：zhl123.com，*.zhl123.com\u003C/p>\u003Cp>&nbsp;\u003C/p>\u003Cp id=\"步骤\">\u003Cstrong>三、步骤\u003C/strong>\u003C/p>\u003Cp>&nbsp;\u003C/p>\u003Cp id=\"1-获取certbot\">1. 获取Certbot\u003C/p>\u003Cp># 下载\u003Cbr>[root@localhost ~]# wget \u003Ca href=\"https://dl.eff.org/certbot-auto\">https://dl.eff.org/certbot-auto\u003C/a>\u003Cbr># 设为可执行权限\u003Cbr>[root@localhost ~]# chmod u+x certbot-auto\u003C/p>\u003Cp id=\"2-申请证书\">2. 申请证书\u003C/p>\u003Cp>&nbsp;\u003C/p>\u003Cp>[root@localhost ~]# ./certbot-auto certonly&nbsp; -d \"*.zhl123.com\" -d \"zhl123.com\" --manual --preferred-challenges dns-01&nbsp; --server \u003Ca href=\"https://acme-v02.api.letsencrypt.org/directory\">https://acme-v02.api.letsencrypt.org/directory\u003C/a>\u003C/p>\u003Cp>\u003Cbr>参数说明：\u003C/p>\u003Cp>-certonly，表示安装模式，Certbot 有安装模式和验证模式两种类型的插件。\u003Cbr>-manual，表示手动安装插件，Certbot 有很多插件，不同的插件都可以申请证书，用户可以根据需要自行选择。\u003Cbr>-d，为哪些主机申请证书，如果是通配符，输入 *.hubinqiang.com（替换为自己的域名）。\u003Cbr>-preferred-challenges，使用 DNS 方式校验域名所有权。\u003Cbr>-server，Let’s Encrypt ACME v2 版本使用的服务器不同于 v1 版本，需要显示指定。\u003Cbr>注意：将zhl123.com替换为自己的域名。可以通过多个-d 参数添加多个主机。\u003Cbr>\u003C/p>\u003Cp>申请过程中需要如下确认：\u003C/p>\u003Cp>Creating virtual environment...\u003Cbr>Installing Python packages...\u003Cbr>Installation succeeded.\u003Cbr>Saving debug log to /var/log/letsencrypt/letsencrypt.log\u003Cbr>Plugins selected: Authenticator manual, Installer None\u003Cbr>Enter email address (used for urgent renewal and security notices) (Enter 'c' to\u003Cbr>cancel): \u003Ca href=\"mailto:12345@qq.com\">12345@qq.com\u003C/a>\u003C/p>\u003Cp>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003Cbr>Please read the Terms of Service at\u003Cbr>\u003Ca href=\"https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf\">https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf\u003C/a>. You must\u003Cbr>agree in order to register with the ACME server at\u003Cbr>\u003Ca href=\"https://acme-v02.api.letsencrypt.org/directory\">https://acme-v02.api.letsencrypt.org/directory\u003C/a>\u003Cbr>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003Cbr>(A)gree/(C)ancel: A\u003C/p>\u003Cp>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003Cbr>Would you be willing to share your email address with the Electronic Frontier\u003Cbr>Foundation, a founding partner of the Let's Encrypt project and the non-profit\u003Cbr>organization that develops Certbot? We'd like to send you email about our work\u003Cbr>encrypting the web, EFF news, campaigns, and ways to support digital freedom.\u003Cbr>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003Cbr>(Y)es/(N)o: Y\u003Cbr>Obtaining a new certificate\u003Cbr>Performing the following challenges:\u003Cbr>dns-01 challenge for zhl123.com\u003Cbr>dns-01 challenge for zhl123.com\u003C/p>\u003Cp>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003Cbr>NOTE: The IP of this machine will be publicly logged as having requested this\u003Cbr>certificate. If you're running certbot in manual mode on a machine that is not\u003Cbr>your server, please ensure you're okay with that.\u003C/p>\u003Cp>Are you OK with your IP being logged?\u003Cbr>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003Cbr>(Y)es/(N)o: Y\u003C/p>\u003Cp>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003C/p>\u003Cp>在域名 DNS 解析中添加 TXT记录：\u003C/p>\u003Cp>\u003Cbr>Please deploy a DNS TXT record under the name\u003Cbr>_acme-challenge.zhl123.com with the following value:\u003C/p>\u003Cp>hwiixYGDrbozBBmveWtsiI5pJTu5CZJVk3WiYR26DgE\u003C/p>\u003Cp>Before continuing, verify the record is deployed.\u003Cbr>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003Cbr>Press Enter to Continue\u003C/p>\u003Cp>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003Cbr>Please deploy a DNS TXT record under the name\u003Cbr>_acme-challenge.zhl123.com with the following value:\u003C/p>\u003Cp>zvW8FMXw81O4t_Drx6tQ1xENk897dg5zHeirZP0a4GI\u003C/p>\u003Cp>Before continuing, verify the record is deployed.\u003Cbr>(This must be set up in addition to the previous challenges; do not remove,\u003Cbr>replace, or undo the previous challenge tasks yet. Note that you might be\u003Cbr>asked to create multiple distinct TXT records with the same name. This is\u003Cbr>permitted by DNS standards.)\u003C/p>\u003Cp>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\u003Cbr>Press Enter to Continue\u003Cbr>Waiting for verification...\u003Cbr>Cleaning up challenges\u003C/p>\u003Cp align=\"center\" style=\"text-align: left;\">\u003Cimg src=\"/uploads/layedit/20181115/6a23e5cb83669bdea5a1af2e8996029e.png\" alt=\"1115.png\">\u003Cbr>\u003C/p>\u003Cp>注意：若申请了多个主机，需要添加多个 TXT 记录。要求给 _acme-challenge.zhl123.com 配置 TXT 记录，在没有确认 TXT 记录生效之前不要回车执行。\u003C/p>\u003Cp>确认生效后会有如下提示：\u003C/p>\u003Cp>IMPORTANT NOTES:\u003Cbr>&nbsp;- Congratulations! Your certificate and chain have been saved at:\u003Cbr>&nbsp;&nbsp; /etc/letsencrypt/live/zhl123.com/fullchain.pem\u003Cbr>&nbsp;&nbsp; Your key file has been saved at:\u003Cbr>&nbsp;&nbsp; /etc/letsencrypt/live/zhl123.com/privkey.pem\u003Cbr>&nbsp;&nbsp; Your cert will expire on 2019-02-13. To obtain a new or tweaked\u003Cbr>&nbsp;&nbsp; version of this certificate in the future, simply run certbot-auto\u003Cbr>&nbsp;&nbsp; again. To non-interactively renew *all* of your certificates, run\u003Cbr>&nbsp;&nbsp; \"certbot-auto renew\"\u003Cbr>&nbsp;- Your account credentials have been saved in your Certbot\u003Cbr>&nbsp;&nbsp; configuration directory at /etc/letsencrypt. You should make a\u003Cbr>&nbsp;&nbsp; secure backup of this folder now. This configuration directory will\u003Cbr>&nbsp;&nbsp; also contain certificates and private keys obtained by Certbot so\u003Cbr>&nbsp;&nbsp; making regular backups of this folder is ideal.\u003Cbr>&nbsp;- If you like Certbot, please consider supporting our work by:\u003C/p>\u003Cp>&nbsp;&nbsp; Donating to ISRG / Let's Encrypt:&nbsp;&nbsp; \u003Ca href=\"https://letsencrypt.org/donate\">https://letsencrypt.org/donate\u003C/a>\u003Cbr>\u003C/p>\u003Cp>&nbsp;&nbsp; Donating to EFF:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; \u003Ca href=\"https://eff.org/donate-le\">https://eff.org/donate-le\u003C/a>\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>\u003Cb>3. 配置证书\u003C/b>\u003C/p>\u003Cp>在 nginx 中配置的片段：\u003C/p>\u003Cp>server {\u003C/p>\u003Cp>&nbsp; &nbsp; server_name zhl123.com;\u003C/p>\u003Cp>&nbsp; &nbsp; listen 443 http2 ssl;\u003C/p>\u003Cp>&nbsp; &nbsp; ssl on;\u003C/p>\u003Cp>&nbsp; &nbsp; ssl_certificate /etc/letsencrypt/live/zhl123.com/fullchain.pem;\u003C/p>\u003Cp>&nbsp; &nbsp; ssl_certificate_key /etc/letsencrypt/live/zhl123.com/privkey.pem;\u003C/p>\u003Cp>&nbsp; &nbsp; ssl_trusted_certificate &nbsp;/etc/letsencrypt/live/zhl123.com/chain.pem;\u003C/p>\u003Cp>\u003Cbr>\u003C/p>\u003Cp>重启 nginx 查看效果。\u003C/p>\u003Cdiv>\u003Cbr>\u003C/div>\u003Cp>\u003Cimg src=\"/uploads/layedit/20181115/6473f7a41629b5cf36ee1779f1082f97.png\" alt=\"1116.png\">\u003Cbr>\u003C/p>\u003Cp>\u003Cb>4. 证书更新\u003C/b>\u003C/p>\u003Cp>Let’s encrypt 的免费证书默认有效期为 90 天，到期后如果要续期可以执行：\u003C/p>\u003Cpre>\u003Ccode>$ ./certbot-auto certonly  -d *.example.com -d *.example.org -d www.example.cn  --manual --preferred-challenges dns  --dry-run --manual-auth-hook /脚本目录/au.sh\u003C/code>\u003C/pre>\u003Cp>详情请参考：https://github.com/ywdblog/certbot-letencrypt-wildcardcertificates-alydns-au\u003C/p>\u003Cp>\u003C/p>","**一、说明**\n\n \n\n利用certbot工具配置Let’s encrypt通配符证书，所域名下所有的子域名都能方便的使用 https证书，而且完全免费。值得关注的是，\n\nLet’s encrypt通配符证书只是针对二级域名，并不能针对主域名，如*.zhl123.com和zhl123.com 被认为是两个域名，\n\n如果和我一样使用的是主域名，在申请的时候需要注意都要申请。\n\n**二、环境**\n\n \n\n操作系统：CentOS Linux release 7.5.1804 (Core)\n\n配置域名：zhl123.com，*.zhl123.com\n\n \n\n**三、步骤**\n\n \n\n1. 获取Certbot\n\n# 下载\n[root@localhost ~]# wget [https://dl.eff.org/certbot-auto](https://dl.eff.org/certbot-auto)\n# 设为可执行权限\n[root@localhost ~]# chmod u+x certbot-auto\n\n2. 申请证书\n\n \n\n[root@localhost ~]# ./certbot-auto certonly  -d \"*.zhl123.com\" -d \"zhl123.com\" --manual --preferred-challenges dns-01  --server [https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory)\n\n参数说明：\n\n-certonly，表示安装模式，Certbot 有安装模式和验证模式两种类型的插件。\n-manual，表示手动安装插件，Certbot 有很多插件，不同的插件都可以申请证书，用户可以根据需要自行选择。\n-d，为哪些主机申请证书，如果是通配符，输入 *.hubinqiang.com（替换为自己的域名）。\n-preferred-challenges，使用 DNS 方式校验域名所有权。\n-server，Let’s Encrypt ACME v2 版本使用的服务器不同于 v1 版本，需要显示指定。\n注意：将zhl123.com替换为自己的域名。可以通过多个-d 参数添加多个主机。\n\n申请过程中需要如下确认：\n\nCreating virtual environment...\nInstalling Python packages...\nInstallation succeeded.\nSaving debug log to /var/log/letsencrypt/letsencrypt.log\nPlugins selected: Authenticator manual, Installer None\nEnter email address (used for urgent renewal and security notices) (Enter 'c' to\ncancel): [12345@qq.com](mailto:12345@qq.com)\n\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\nPlease read the Terms of Service at\n[https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf](https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf). You must\nagree in order to register with the ACME server at\n[https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory)\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\n(A)gree/(C)ancel: A\n\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\nWould you be willing to share your email address with the Electronic Frontier\nFoundation, a founding partner of the Let's Encrypt project and the non-profit\norganization that develops Certbot? We'd like to send you email about our work\nencrypting the web, EFF news, campaigns, and ways to support digital freedom.\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\n(Y)es/(N)o: Y\nObtaining a new certificate\nPerforming the following challenges:\ndns-01 challenge for zhl123.com\ndns-01 challenge for zhl123.com\n\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\nNOTE: The IP of this machine will be publicly logged as having requested this\ncertificate. If you're running certbot in manual mode on a machine that is not\nyour server, please ensure you're okay with that.\n\nAre you OK with your IP being logged?\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\n(Y)es/(N)o: Y\n\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\n\n在域名 DNS 解析中添加 TXT记录：\n\nPlease deploy a DNS TXT record under the name\n_acme-challenge.zhl123.com with the following value:\n\nhwiixYGDrbozBBmveWtsiI5pJTu5CZJVk3WiYR26DgE\n\nBefore continuing, verify the record is deployed.\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\nPress Enter to Continue\n\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\nPlease deploy a DNS TXT record under the name\n_acme-challenge.zhl123.com with the following value:\n\nzvW8FMXw81O4t_Drx6tQ1xENk897dg5zHeirZP0a4GI\n\nBefore continuing, verify the record is deployed.\n(This must be set up in addition to the previous challenges; do not remove,\nreplace, or undo the previous challenge tasks yet. Note that you might be\nasked to create multiple distinct TXT records with the same name. This is\npermitted by DNS standards.)\n\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\nPress Enter to Continue\nWaiting for verification...\nCleaning up challenges\n\n![1115.png](/uploads/layedit/20181115/6a23e5cb83669bdea5a1af2e8996029e.png)\n\n注意：若申请了多个主机，需要添加多个 TXT 记录。要求给 _acme-challenge.zhl123.com 配置 TXT 记录，在没有确认 TXT 记录生效之前不要回车执行。\n\n确认生效后会有如下提示：\n\nIMPORTANT NOTES:\n - Congratulations! Your certificate and chain have been saved at:\n   /etc/letsencrypt/live/zhl123.com/fullchain.pem\n   Your key file has been saved at:\n   /etc/letsencrypt/live/zhl123.com/privkey.pem\n   Your cert will expire on 2019-02-13. To obtain a new or tweaked\n   version of this certificate in the future, simply run certbot-auto\n   again. To non-interactively renew *all* of your certificates, run\n   \"certbot-auto renew\"\n - Your account credentials have been saved in your Certbot\n   configuration directory at /etc/letsencrypt. You should make a\n   secure backup of this folder now. This configuration directory will\n   also contain certificates and private keys obtained by Certbot so\n   making regular backups of this folder is ideal.\n - If you like Certbot, please consider supporting our work by:\n\n   Donating to ISRG / Let's Encrypt:   [https://letsencrypt.org/donate](https://letsencrypt.org/donate)\n\n   Donating to EFF:                    [https://eff.org/donate-le](https://eff.org/donate-le)\n\n**3. 配置证书**\n\n在 nginx 中配置的片段：\n\nserver {\n\n    server_name zhl123.com;\n\n    listen 443 http2 ssl;\n\n    ssl on;\n\n    ssl_certificate /etc/letsencrypt/live/zhl123.com/fullchain.pem;\n\n    ssl_certificate_key /etc/letsencrypt/live/zhl123.com/privkey.pem;\n\n    ssl_trusted_certificate  /etc/letsencrypt/live/zhl123.com/chain.pem;\n\n重启 nginx 查看效果。\n\n![1116.png](/uploads/layedit/20181115/6473f7a41629b5cf36ee1779f1082f97.png)\n\n**4. 证书更新**\n\nLet’s encrypt 的免费证书默认有效期为 90 天，到期后如果要续期可以执行：\n\n```\n$ ./certbot-auto certonly  -d *.example.com -d *.example.org -d www.example.cn  --manual --preferred-challenges dns  --dry-run --manual-auth-hook /脚本目录/au.sh\n```\n\n详情请参考：https://github.com/ywdblog/certbot-letencrypt-wildcardcertificates-alydns-au","/article/90",6017,"2018-11-15 11:28:19","2019-02-19 12:00:15",[156,157,158],{"id":39,"name":81,"url":82},{"id":44,"name":23,"url":59},{"id":145,"name":146,"url":151},{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},{"title":161,"url":162},"时间戳引起的网站访问不了的问题(net.ipv4.tcp_timestamps)","/article/92",{"title":164,"url":165},"Centos7 lvm逻辑卷 把home空间转移给根","/article/86",[167,168,169,170],{"create_time":6,"description":6,"id":44,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":23,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":53,"subtitle":6,"update_time":6,"url":59},{"create_time":6,"description":6,"id":45,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":61,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":56,"subtitle":6,"update_time":6,"url":62},{"create_time":6,"description":6,"id":46,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":64,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":65,"subtitle":6,"update_time":6,"url":66},{"create_time":6,"description":6,"id":47,"image_url":6,"index_template":52,"is_cover":53,"is_menu":53,"keywords":6,"list_template":54,"model_code":55,"model_id":56,"model_name":57,"name":68,"parent_id":39,"seo_description":6,"seo_keywords":6,"seo_title":6,"show_template":58,"sort":69,"subtitle":6,"update_time":6,"url":70},{"description":148,"keywords":147,"title":146},[173,182,191,200,209,218,227,236,245,253],{"id":174,"category_id":44,"title":175,"keywords":176,"description":177,"image_url":6,"url":178,"hits":179,"is_recommend":73,"is_top":73,"create_time":180,"update_time":181},101,"开启 HTTPS 并获得 ssllabs 满分的过程","开启,获得,满分,过程","准备工作确保你要申请证书的域名都解析到了这台服务器上，且能直接通过域名访问。使用官网推荐的CertBot获取证书。在CertBot官网选择一下环境(比如我选Nginx on Ubuntu 17.04)就可以看到入门教程了。安装CertBot12345apt-get updateapt-get install software-properties-commonadd-apt-repository ppa:certbot/certbotapt-get updateapt-get","/article/101",18546,"2019-11-26 16:12:11","2019-11-26 16:23:16",{"id":183,"category_id":44,"title":184,"keywords":185,"description":186,"image_url":6,"url":187,"hits":188,"is_recommend":73,"is_top":73,"create_time":189,"update_time":190},113,"在CentOS 7中添加命令自动补全功能","命令自动补全,centos","在CentOS 7中，默认情况下并不会安装命令补全包，需要手动安装才能使用命令补全功能。以下是在CentOS 7中安装命令补全包的方法：1. bash-completion：这是一个针对Bash shell的命令补全软件包，可以提供对系统命令、用户自定义命令和文件路径的自动补全功能。可以通过以下命令安装：```sudo yum install bash-completion```安装完成后，需要在/etc/profile配置文件中添加以下内容：```if [ -f /etc/bash_compl","/article/113",14948,"2023-05-16 10:54:01","2023-05-16 10:57:28",{"id":192,"category_id":44,"title":193,"keywords":194,"description":195,"image_url":6,"url":196,"hits":197,"is_recommend":53,"is_top":73,"create_time":198,"update_time":199},94,"Centos7 安装 openvas ","openvas,开放式漏洞评估系统，installing openvas centos-7","一、描述OpenVAS，即开放式漏洞评估系统，是一个用于评估目标漏洞的杰出框架。功能十分强大，最重要的是，它是“开源”的——就是免费的意思啦～它与著名的Nessus“本是同根生”，在Nessus商业化之后仍然坚持开源，号称“当前最好用的开源漏洞扫描工具”。最新版的Kali Linux(kali 3.0)不再自带OpenVAS了，所以我们要自己部署OpenVAS漏洞检测系统。其核心部件是一个服务器，包括一套网络漏洞测试程序，可以检测远程系统和应用程序中的安全问题。但是它的最常用用途是检测目标网络或","/article/94",14690,"2019-01-14 17:43:42","2019-01-14 18:16:36",{"id":201,"category_id":44,"title":202,"keywords":203,"description":204,"image_url":6,"url":205,"hits":206,"is_recommend":73,"is_top":73,"create_time":207,"update_time":208},99,"Centos7 利用iptables防止nmap工具防端口扫描","iptables","一、Nmap介绍       Nmap（NetworkMapper）是一款开放源代码的网络探测和安全审核工具。它用于快速扫描一个网络和一台主机开放的端口，还能使用TCP/IP协议栈特征探测远程主机的操作系统类型。nmap支持很多扫描技术，例如：UDP、TCPconnect()、TCPSYN(半开扫描)、ftp代理(bounce攻击)、反向标志、ICMP、FIN、ACK扫描、圣诞树(XmasTree)、SYN扫描和null扫描。Nmap最初是用于Unix系统","/article/99",14415,"2019-07-09 21:27:00","2019-07-09 21:57:53",{"id":210,"category_id":46,"title":211,"keywords":212,"description":213,"image_url":6,"url":214,"hits":215,"is_recommend":73,"is_top":73,"create_time":216,"update_time":217},61,"Docker 推荐的启动方式","推荐,启动,方式","# cat DockerfileFROM openjdk:8-alpineWORKDIR /ADD ./target/*.jar app.jarEXPOSE 9999COPY docker-entrypoint.sh /RUN chmod +x /docker-entrypoint.shENTRYPOINT [“/docker-entrypoint.sh”]CMD [“java”,”-server”,”-Duser.timezone=GMT+08″,”-jar”,”/app.jar”]# cat","/article/61",14347,"2018-10-22 13:55:47","2018-10-22 13:56:10",{"id":219,"category_id":44,"title":220,"keywords":221,"description":222,"image_url":6,"url":223,"hits":224,"is_recommend":73,"is_top":73,"create_time":225,"update_time":226},107,"Acme.sh 给 SSL 证书自动续期失败的解决方法","HTTP/1.1 200 OK,Server: Bayou Tech Web Srv 1.0,Content-Encoding: none,Content-Length: 5,Content-Type","一、Acme.sh 自动续期失败的症状问题描述如下，续期的时候，提示如下错误：root@dc:~# \"/data/acme.sh\"/acme.sh --cron --home \"/data/acme.sh\" &gt; /dev/null[Sun Nov 10 23:52:17 CST 2020] Error, can not get domain token entry example.com[Sun Nov 10 23:52:17 CST 2020] Please check log file","/article/107",12618,"2021-09-03 10:44:18","2021-09-03 10:46:23",{"id":228,"category_id":44,"title":229,"keywords":230,"description":231,"image_url":6,"url":232,"hits":233,"is_recommend":53,"is_top":73,"create_time":234,"update_time":235},93,"ELK+Filebeat+Kafka+ZooKeeper 构建海量日志分析平台","Filebeat,Kafka","一、说明1.Filebeat是一个日志文件托运工具，在你的服务器上安装客户端后，filebeat会监控日志目录或者指定的日志文件，追踪读取这些文件（追踪文件的变化，不停的读）2.Kafka是一种高吞吐量的分布式发布订阅消息系统，它可以处理消费者规模的网站中的所有动作流数据3.Logstash是一根具备实时数据传输能力的管道，负责将数据信息从管道的输入端传输到管道的输出端；与此同时这根管道还可以让你根据自己的需求在中间加上滤网，Logstash提供里很多功能强大的滤网以满足你的各种应用场景4.El","/article/93",12190,"2018-12-24 16:40:08","2018-12-26 11:53:38",{"id":237,"category_id":46,"title":238,"keywords":239,"description":240,"image_url":6,"url":241,"hits":242,"is_recommend":53,"is_top":73,"create_time":243,"update_time":244},81,"kubernetes 1.12.1 高可用安装之部署Dashboard","安装Dashboard","创建Dashboard需要CoreDNS部署成功之后再安装Dashboard。[root@master01 ~]# wget https://zhl123.com/download/k8s/Dashboard.tgz[root@master01 ~]# tar xf Dashboard.tgz[root@master01 ~]# kubectl create -f Dashboard/[root@master01 Dashboard]# kubectl get svc -n kube-syste","/article/81",12037,"2018-10-26 09:54:41","2018-10-26 16:59:19",{"id":246,"category_id":44,"title":247,"keywords":6,"description":248,"image_url":6,"url":249,"hits":250,"is_recommend":73,"is_top":73,"create_time":251,"update_time":252},100,"用 Nginx 给 Cookie 增加 Secure 和 HttpOnly","在 nginx 的 location 中配置12# 只支持 proxy 模式下设置，SameSite 不需要可删除，如果想更安全可以把 SameSite 设置为 Strictproxy_cookie_path / \"/; httponly; secure; SameSite=Lax\";示例1234567891011121314151617181920212223242526server {    listen 443 ssl http2;    server_name www.zhl123.cn","/article/100",11848,"2019-11-26 16:10:57","2019-11-26 16:23:45",{"id":254,"category_id":44,"title":255,"keywords":256,"description":257,"image_url":6,"url":258,"hits":259,"is_recommend":73,"is_top":73,"create_time":260,"update_time":261},41,"Tomcat 安全配置与性能优化","tomcat，性能优化","1. JVM&nbsp;1.1. 使用 Server JRE 替代JDK。&nbsp;服务器上不要安装JDK，请使用 Server JRE. 服务器上根本不需要编译器，代码应该在Release服务器上完成编译打包工作。&nbsp;理由：一旦服务器被控制，可以防止在其服务器上编译其他恶意代码并植入到你的程序中。&nbsp;1.2. JAVA_OPTS&nbsp;export JAVA_OPTS=\"-server -Xms512m -Xmx4096m &nbsp;-XX:PermSize=64M -","/article/41",11623,"2016-09-01 17:06:36","2018-10-18 17:06:58",[263,271,279,287,295,303,311,319,328,337],{"id":264,"category_id":40,"title":265,"keywords":6,"description":266,"image_url":6,"url":267,"hits":268,"is_recommend":73,"is_top":73,"create_time":269,"update_time":270},123,"Agent Skill 精选集：最值得收藏的 Agent Skills Top 10","如果你正在用 Claude Code 或 Codex，一定对&nbsp;Agent Skills&nbsp;不陌生。通过安装&nbsp;Agent Skills，你可以让这些 AI 助手变得更强——不用每次都解释你的需求，它们直接就知道该怎么做。最近有人在 GitHub 上做了一个采样调查，统计了哪些 Skills 的质量最佳和最受欢迎。我整理了这份&nbsp;Top 10 榜单，加上使用场景和适合人群，帮你快速找到最有用的那几个。Top 10 最受欢迎的 Agent Skills1. Skil","/article/123",270,"2026-01-19 18:49:12","2026-01-19 18:52:01",{"id":272,"category_id":44,"title":273,"keywords":6,"description":274,"image_url":6,"url":275,"hits":276,"is_recommend":73,"is_top":73,"create_time":277,"update_time":278},122,"Nginx性能调优18条黄金法则：支撑10万并发的配置模板","一、概述1.1 背景介绍说实话，Nginx调优这事儿我踩过无数坑。记得2019年双11，我们电商平台流量暴涨，Nginx直接扛不住了，QPS从平时的2万飙升到8万，响应时间从50ms飙到了2秒，最后还是靠临时加机器扛过去的。那次事故之后，我花了大半年时间专门研究Nginx的性能极限，总结出了这20条黄金法则。Nginx作为目前最流行的Web服务器和反向代理，官方数据显示单机可以轻松处理10万+的并发连接。但实际生产环境中，很多同学拿到默认配置就直接上了，结果发现连1万并发都扛不住。问题不在Ngi","/article/122",337,"2026-01-12 11:11:50","2026-01-12 11:12:28",{"id":280,"category_id":46,"title":281,"keywords":6,"description":282,"image_url":6,"url":283,"hits":284,"is_recommend":73,"is_top":73,"create_time":285,"update_time":286},121,"Docker 镜像优化与安全扫描：将镜像体积压缩 70%","1. 适用场景 & 前置条件项目要求适用场景容器化应用镜像体积过大（> 500MB），构建时间长（> 10分钟），存在安全漏洞（CVE高危）OSRHEL/CentOS 7.9+ 或 Ubuntu 20.04+内核Linux Kernel 3.10+软件版本Docker 20.10+ 或 Podman 3.0+，Trivy 0.40+（安全扫描工具）资源规格2C4G（最小）/ 4C8G（推荐），磁盘 50GB+（存储镜像与缓存）网络可访问 Docker Hub/阿里云镜像仓库（","/article/121",309,"2026-01-06 11:54:35","2026-01-06 12:01:59",{"id":288,"category_id":44,"title":289,"keywords":6,"description":290,"image_url":6,"url":291,"hits":292,"is_recommend":73,"is_top":73,"create_time":293,"update_time":294},120,"用 Prometheus Recording Rules 把告警噪声砍掉 70%(二)","五、故障排查和监控5.1 故障排查◆ 5.1.1 日志查看# 查看 Prometheus 日志中的规则评估错误journalctl -u prometheus | grep -i&nbsp;\"rule\"&nbsp;|&nbsp;tail&nbsp;-50# 查看规则评估耗时curl -s http://localhost:9090/api/v1/rules | jq&nbsp;'.data.groups[].rules[] | select(.health != \"ok\")'# Kubernet","/article/120",282,"2026-01-06 11:53:50","2026-01-06 11:54:33",{"id":296,"category_id":44,"title":297,"keywords":6,"description":298,"image_url":6,"url":299,"hits":300,"is_recommend":73,"is_top":73,"create_time":301,"update_time":302},119,"用 Prometheus Recording Rules 把告警噪声砍掉 70%(一)","一、概述1.1 背景介绍在大规模微服务架构下，Prometheus 告警系统往往会陷入一个尴尬的境地：告警太多，运维团队开始选择性忽略；告警太少，真正的故障又可能漏掉。我在某电商平台负责监控体系建设时，团队每天要处理超过 2000 条告警，其中 70% 以上是重复的、关联的或者短暂抖动产生的噪声。Recording Rules 是 Prometheus 提供的预计算机制，可以将复杂的查询表达式预先计算并存储为新的时间序列。通过合理设计 Recording Rules，我们不仅能显著降低 Prom","/article/119",301,"2026-01-06 11:51:58","2026-01-06 11:53:45",{"id":304,"category_id":44,"title":305,"keywords":6,"description":306,"image_url":6,"url":307,"hits":308,"is_recommend":73,"is_top":73,"create_time":309,"update_time":310},118,"GitOps 落地实践：ArgoCD + Kustomize 实现声明式基础设施管理(二)","四、最佳实践和注意事项4.1 最佳实践4.1.1 性能优化优化点一：减少 Git 轮询频率# argocd-cm ConfigMapapiVersion:&nbsp;v1kind:&nbsp;ConfigMapmetadata:&nbsp;&nbsp;name:&nbsp;argocd-cm&nbsp;&nbsp;namespace:&nbsp;argocddata:&nbsp;&nbsp;timeout.reconciliation:&nbsp;300s&nbsp;&nbsp;# 默认 180","/article/118",305,"2026-01-06 11:49:00","2026-01-06 11:49:34",{"id":312,"category_id":44,"title":313,"keywords":6,"description":314,"image_url":6,"url":315,"hits":316,"is_recommend":73,"is_top":73,"create_time":317,"update_time":318},117,"GitOps 落地实践：ArgoCD + Kustomize 实现声明式基础设施管理(一)","一、概述1.1 背景介绍GitOps 作为云原生时代的运维范式，将 Git 作为基础设施和应用配置的单一事实来源，通过声明式配置和自动化同步机制，实现了配置管理的版本控制、审计追溯和快速回滚。ArgoCD 作为 CNCF 毕业项目，提供了完整的 GitOps 工作流，支持多集群管理、RBAC 权限控制、SSO 集成等企业级特性。结合 Kustomize 的配置管理能力，能够优雅地解决多环境配置差异、敏感信息管理、配置复用等问题。在传统的 CI/CD 流程中，往往由 CI 工具直接执行 kubec","/article/117",310,"2026-01-06 11:45:03","2026-01-06 11:48:56",{"id":320,"category_id":40,"title":321,"keywords":322,"description":323,"image_url":6,"url":324,"hits":325,"is_recommend":73,"is_top":73,"create_time":326,"update_time":327},116,"运维部门年度2025工作总结与2026工作规划应该如何写？","运维部门年度2025工作总结,2026工作规划","2025年，运维部在公司“数字化转型深化”战略引领下，以“稳定为基、效率为纲、安全为盾、创新为翼”为核心导向，全面支撑核心业务系统运行、推动技术架构迭代、强化团队能力建设。 全年实现核心业务系统可用性99.985%，较2024年提升0.02个百分点；故障平均恢复时间（MTTR）从42分钟压缩至29分钟，下降31%；云资源成本同比降低16.8%，自动化运维覆盖率从65%提升至83%，未发生重大生产安全事故，圆满完成年度目标。现将全年工作及2026年规划汇报如下：2025年核心工作成果（数","/article/116",297,"2026-01-06 11:20:58","2026-01-06 11:44:04",{"id":329,"category_id":40,"title":330,"keywords":331,"description":332,"image_url":6,"url":333,"hits":334,"is_recommend":73,"is_top":73,"create_time":335,"update_time":336},115,"Kubernetes 100个常用命令","100 个 Kubectl 命令","这篇文章是关于使用 Kubectl 进行 Kubernetes 诊断的指南。列出了 100 个 Kubectl 命令，这些命令对于诊断 Kubernetes 集群中的问题非常有用。这些问题包括但不限于：•&nbsp;集群信息•&nbsp;Pod 诊断•&nbsp;服务诊断•&nbsp;部署诊断•&nbsp;网络诊断•&nbsp;持久卷和持久卷声明诊断•&nbsp;资源使用情况•&nbsp;安全和授权•&nbsp;节点故障排除•&nbsp;其他诊断命令：文章还提到了许多其他命令，如资源扩展和自动扩","/article/115",3642,"2023-11-02 14:09:30","2023-11-02 14:10:05",{"id":183,"category_id":44,"title":184,"keywords":185,"description":186,"image_url":6,"url":187,"hits":188,"is_recommend":73,"is_top":73,"create_time":189,"update_time":190},1784716029074]