Last active
May 26, 2026 09:45
-
-
Save cloverstd/1f5a93ee11456aeae34b4be6fab9ad96 to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #!/bin/sh | |
| set -eu | |
| export DEBIAN_FRONTEND=noninteractive | |
| USERNAME=cloverstd | |
| apt update && apt install -y curl sudo dnsutils ufw ssh-import-id ssh libcap2-bin | |
| # 创建用户(禁用密码登录,仅密钥) | |
| adduser --gecos "" --disabled-password "$USERNAME" | |
| usermod -aG sudo "$USERNAME" | |
| echo "$USERNAME ALL=(ALL) NOPASSWD: ALL" > /etc/sudoers.d/90-"$USERNAME" | |
| chmod 0440 /etc/sudoers.d/90-"$USERNAME" | |
| # 导入 SSH 公钥 | |
| runuser -u "$USERNAME" -- bash -c "ssh-import-id-gh $USERNAME" || true | |
| runuser -u "$USERNAME" -- bash -c "ssh-import-id-lp $USERNAME" || true | |
| # 关键:校验已成功导入公钥,否则不锁 SSH,避免把自己关在门外 | |
| AUTH_KEYS="/home/$USERNAME/.ssh/authorized_keys" | |
| if [ ! -s "$AUTH_KEYS" ]; then | |
| echo "错误:$AUTH_KEYS 为空或不存在,密钥导入失败。" | |
| echo "已跳过禁用密码/root 登录,请手动检查后再加固 SSH。" | |
| exit 1 | |
| fi | |
| # 加固 SSH | |
| sed -i '/^PermitRootLogin/d' /etc/ssh/sshd_config | |
| sed -i '/^PasswordAuthentication/d' /etc/ssh/sshd_config | |
| echo "PasswordAuthentication no" >> /etc/ssh/sshd_config | |
| echo "PermitRootLogin no" >> /etc/ssh/sshd_config | |
| sshd -t # 配置有误立即退出,不 reload 坏配置 | |
| systemctl reload ssh | |
| # 防火墙 | |
| ufw allow 22/tcp | |
| ufw --force enable | |
| # 开启 BBR(幂等,写到独立文件避免重复 append) | |
| cat > /etc/sysctl.d/99-bbr.conf <<'EOF' | |
| net.core.default_qdisc=fq | |
| net.ipv4.tcp_congestion_control=bbr | |
| EOF | |
| sysctl --system | |
| # Docker | |
| curl -sf https://get.docker.com | sh - | |
| usermod -aG docker "$USERNAME" | |
| # nexttrace | |
| curl -fL -s -o /usr/local/bin/nexttrace \ | |
| https://github.com/nxtrace/NTrace-core/releases/download/v1.3.2/nexttrace_linux_amd64 | |
| chmod +x /usr/local/bin/nexttrace | |
| setcap cap_net_raw,cap_net_admin+eip /usr/local/bin/nexttrace |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #!/bin/sh | |
| set -eu | |
| export DEBIAN_FRONTEND=noninteractive | |
| USERNAME=cloverstd | |
| apt update && apt install -y curl sudo dnsutils ufw ssh-import-id libcap2-bin | |
| # 创建用户(禁用密码登录,仅密钥) | |
| adduser --gecos "" --disabled-password "$USERNAME" | |
| usermod -aG sudo "$USERNAME" | |
| echo "$USERNAME ALL=(ALL) NOPASSWD: ALL" > /etc/sudoers.d/90-"$USERNAME" | |
| chmod 0440 /etc/sudoers.d/90-"$USERNAME" | |
| # 导入 SSH 公钥 | |
| runuser -u "$USERNAME" -- bash -c "ssh-import-id-gh $USERNAME" || true | |
| runuser -u "$USERNAME" -- bash -c "ssh-import-id-lp $USERNAME" || true | |
| # 关键:校验已成功导入公钥,否则不锁 SSH,避免把自己关在门外 | |
| AUTH_KEYS="/home/$USERNAME/.ssh/authorized_keys" | |
| if [ ! -s "$AUTH_KEYS" ]; then | |
| echo "错误:$AUTH_KEYS 为空或不存在,密钥导入失败。" | |
| echo "已跳过禁用密码/root 登录,请手动检查后再加固 SSH。" | |
| exit 1 | |
| fi | |
| # 加固 SSH | |
| sed -i '/^PermitRootLogin/d' /etc/ssh/sshd_config | |
| sed -i '/^PasswordAuthentication/d' /etc/ssh/sshd_config | |
| echo "PasswordAuthentication no" >> /etc/ssh/sshd_config | |
| echo "PermitRootLogin no" >> /etc/ssh/sshd_config | |
| sshd -t # 配置有误立即退出,不 reload 坏配置 | |
| systemctl reload ssh | |
| # 防火墙 | |
| ufw allow 22/tcp | |
| ufw --force enable | |
| # 开启 BBR(幂等,写到独立文件避免重复 append) | |
| cat > /etc/sysctl.d/99-bbr.conf <<'EOF' | |
| net.core.default_qdisc=fq | |
| net.ipv4.tcp_congestion_control=bbr | |
| EOF | |
| sysctl --system | |
| # Docker | |
| curl -sf https://get.docker.com | sh - | |
| usermod -aG docker "$USERNAME" | |
| # nexttrace | |
| curl -fL -s -o /usr/local/bin/nexttrace \ | |
| https://github.com/nxtrace/NTrace-core/releases/download/v1.3.2/nexttrace_linux_amd64 | |
| chmod +x /usr/local/bin/nexttrace | |
| setcap cap_net_raw,cap_net_admin+eip /usr/local/bin/nexttrace |
cloverstd
commented
May 26, 2026
Author
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment