標籤:主機 基礎知識 密碼 帳號
Rsync
一、基礎知識
1、rsync:是傳輸輸工具,類似於scp
Scp的用法要知道遠程主機的密碼和帳號
檔案在本地上傳到遠程
Scp [option] source file [[[email protected]]host1:] destions /file
檔案在遠程下載到本地
Scp [option] [[[email protected]]host1:] destions /file source /file
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-25848" border="0" alt="wps_clip_image-25848" src="http://img1.51cto.com/attachment/201408/24/8400375_1408872747wfFN.png" width="706" height="320" />
rsync ?.a fast, versatile, remote (and local) file-copying tool man手冊對rsync的解釋
快速、通用、遠程和本地主機cp file的tool
# yum -y install xinetd# chkconfig rsync onRpm -ql rsync/etc/xinetd.d/rsync 服務啟動指令碼/etc/rsyncd.conf 服務配置/etc/rsyncd.passwd# service xinetd start 服務啟動
監聽於873/tcp 監聽連接埠
rsync特點:
1、可以鏡像儲存整個分類樹或檔案系統;
2、較高的資料轉送效率;
3、可以藉助於ssh實現安全資料轉送;
4、支援匿名傳輸;
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-418" border="0" alt="wps_clip_image-418" src="http://img1.51cto.com/attachment/201408/24/8400375_1408872752T0FS.png" width="725" height="299" />
rsync演算法
rsync命令的工作模式:
第一種模式:shell模式,也稱作本地模式;第二種模式:遠程shell模式,可以利用ssh協議承載其遠程傳輸過程;第三種模式:列表模式,僅列出源中的內容,-nv第四種模式:服務模式,此時rsync工作為守護進程,能接收用戶端的資料同步請求;rsync命令的選項:-n: 同步測試,不執行真正的同步過程;-v: --verbose 詳細輸出模式-q: --quiet 靜默模式-c: --checksum,開啟校正功能-r: --recursive 遞迴複製注意:rsync命令中,如果源路徑是目錄,且給複製路徑時末尾有/,則會複製目錄中的內容,而非目錄本向;
如果末尾沒有/,則會同步目錄本身及目錄中的所有檔案;目標路徑末尾是否有/無關緊要;
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-5661" border="0" alt="wps_clip_image-5661" src="http://img1.51cto.com/attachment/201408/24/8400375_1408872760rRvw.png" width="738" height="188" />
上面的事傳送目錄
下面的是傳送目錄下的所有內容
-a: --archive 歸檔,保留檔案的原有屬性;-p: --perms保留檔案的許可權;-t: --times保留檔案的時間戳記;-l: 保留符號連結-g: --group 保留屬組-o: (--owner) 保留屬主-D:same as --devices --specials 保留裝置檔案-e --rsh=COMMAND ssh: 使用ssh作為傳輸承載;-z: --compress 壓縮後傳輸;--progress: 顯示進度條--stats: 顯示如何執行壓縮和傳輸
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-19697" border="0" alt="wps_clip_image-19697" src="http://img1.51cto.com/attachment/201408/24/8400375_1408872775CIRI.png" width="713" height="369" />
rsync的服務模式:
1、設定rsync伺服器端# yum -y install xinetd# chkconfig rsync on2、為rsync提供設定檔/etc/rsyncd.conf二、設定檔分兩段:全域配置段:1個共用配置段:多個[SHARE_NAME]配置樣本: 全域嗎、配置段# Global Settingsuid = nobody 匿名使用者gid = nobody 匿名組use chroot = no 允許使用者出自己的家目錄max connections = 10 最大請求串連數strict modes = yes 屬性pid file = /var/run/rsyncd.pid pid檔案log file = /var/log/rsyncd.log 記錄檔共用配置段# Directory to be synced[tools] 共用名稱path = /data 真實共用目錄ignore errors = yes 忽視錯誤read only = no 不允許讀操作write only = no 不允許寫操作hosts allow = 172.16.0.0/16 允許那個網段的來傳輸hosts deny = * 除了上面的拒絕所有list = false 查看目錄檔案uid = root root身份共用gid = root root組身份共用3、啟動服務Access via rsync daemon:檔案在遠程一般下載方式,(拉取)下載Pull: rsync [OPTION...] [[email protected]]HOST::SRC... [DEST]共用方式拉取rsync [OPTION...] rsync://[[email protected]]HOST[:PORT]/SRC... [DEST]檔案在本地上傳檔案Push: rsync [OPTION...] SRC... [[email protected]]HOST::DEST共用方式上傳rsync [OPTION...] SRC... rsync://[[email protected]]HOST[:PORT]/DEST在用戶端,使用週期性任務計劃; 可以同步資料inotify: 在伺服器端,可用於定義監控指定的目錄下的所有檔案,一旦有檔案的中繼資料發生改變,即會通知用戶端來拉取;rsync + inotify: sersync
4、服務端啟用使用者認證的功能
在共用定義處加配置:
[tools]path = /dataignore errors = yesread only = nowrite only = nohosts allow = 172.16.0.0/16hosts deny = *list = falseuid = rootgid = root auth users = USERNAME LIST 認證使用者列表;使用者與使用者用“,”隔開secrets file = /etc/rsyncd.passwd 使用者密碼儲存位置,記住使用者的密碼不可以超過8個字元
說明: USERNAME LIST為以逗號分隔的在rsyncd.passwd中存在使用者名稱的列表;
(2)建立密碼檔案/etc/rsyncd.passwd
username:password 密碼檔案格式書寫
此檔案不能允許其它使用者有存取權限,且密碼不能超過8個字元;
三、實驗,完成rsync的共用及基於認證的功能
Vmware1 用戶端 172.16.1.143
Vmware2 服務端 172.16.1.140
配置好ip時,最好先相互ping一下,確保能正常通訊,另外最好關閉防火牆,或者配置防火牆策略,不然影響實驗結果
服務端
Yum -y install xinetd
Servcie xinetd restart
服務配置 /etc/xinetd.d/rsync
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-28825" border="0" alt="wps_clip_image-28825" src="http://img1.51cto.com/attachment/201408/24/8400375_1408872787W0dJ.png" width="717" height="352" />
Vim /etc/rsyncd.conf
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-32362" border="0" alt="wps_clip_image-32362" src="http://img1.51cto.com/attachment/201408/24/8400375_1408873348lPJF.png" width="732" height="451" />
基於密碼認證的使用者密碼配置
注意密碼檔案的許可權
Chmod 600 /etc/rsyncd.passwd
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-14092" border="0" alt="wps_clip_image-14092" src="http://img1.51cto.com/attachment/201408/24/8400375_1408873351g900.png" width="320" height="117" />
實驗結果
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-16787" border="0" alt="wps_clip_image-16787" src="http://img1.51cto.com/attachment/201408/24/8400375_1408873356mcff.png" width="639" height="89" />
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-13483" border="0" alt="wps_clip_image-13483" src="http://img1.51cto.com/attachment/201408/24/8400375_1408873370ZONM.png" width="641" height="309" />
四、實驗
Inotify 介紹
Inotify 是一種強大的、細粒度的、非同步檔案系統事件監控機制,linux核心從2.6.13起,加入了Inotify支援,
通過Inotify可以監控檔案系統中添加、刪除,修改、移動等各種細微事件,利用這個核心介面,第三方軟體
就可以監控檔案系統下檔案的各種變化情況,而inotify-tools就是這樣的一個第三方軟體。
Inotifywait是一個監控等待事件,可以配合shell指令碼使用它,下面介紹一下常用的一些參數:
inotifywait,用來監視檔案的變化
inotifywatch,用來統計檔案系統訪問的次數,監視檔案的中繼資料
l -m, 即--monitor,表示始終保持事件監聽狀態。
l -r, 即--recursive,表示遞迴查詢目錄。
l -q, 即--quiet,表示列印出監控事件。
l -e, 即--event,通過此參數可以指定要監控的事件,常見的事件有modify、delete、create、attrib等。
工作
650) this.width=650;" src="http://s3.51cto.com/wyfs02/M02/47/5D/wKioL1P5u5XSk2wkAACqvZ9JZ9Y733.jpg" title="36020140824180821577.jpg" alt="wKioL1P5u5XSk2wkAACqvZ9JZ9Y733.jpg" />
服務端配置
1、下載軟體
http://nchc.dl.sourceforge.net/project/inotify-tools/inotify-tools/3.13/
Tar xf inotify-tools/3.13 -C /usr/local
Cd inotify
./configure --frefix=/usr/local/inotify
Mak &&make install
Yum install xinetd -y
vim /etc/xinetd.d/rsync
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-21384" border="0" alt="wps_clip_image-21384" src="http://img1.51cto.com/attachment/201408/24/8400375_1408873381hd3x.png" width="555" height="283" />
Vim /etc/rsyncd.conf
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-15859" border="0" alt="wps_clip_image-15859" src="http://img1.51cto.com/attachment/201408/24/8400375_1408873392B3f0.png" width="569" height="299" />
Service xinetd restart
Ss -tnl 看873是否監聽
建立目錄 mkdir /momo
2、提供更新控制指令碼
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-23392" border="0" alt="wps_clip_image-23392" src="http://img1.51cto.com/attachment/201408/24/8400375_1408873403VOh6.png" width="698" height="322" />
指令碼控制推送
vim /bin/inotify.sh
#!/bin/bash
trap ‘echo "stop"‘ INT
source=/momo
Host=172.16.1.13
Dest=tools
Host1=172.16.1.23
/usr/local/bin/inotifywait -mrq -e modify,delete,create,attrib /momo | while read line
do
/usr/bin/rsync -ahqz -e ssh --delete --progress -v --stats ${source}/ ${Host}::$Dest
/usr/bin/rsync -ahqz -e ssh --delete --progress -v --stats ${source}/ ${Host1}::$Dest
done
3、密鑰認證
產生密鑰
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-6143" border="0" alt="wps_clip_image-6143" src="http://img1.51cto.com/attachment/201408/24/8400375_1408873428n1xg.png" width="690" height="273" />
給用戶端認證密鑰
650) this.width=650;" style="border-top-width:0px;border-bottom-width:0px;border-left-width:0px;" title="wps_clip_image-25248" border="0" alt="wps_clip_image-25248" src="http://img1.51cto.com/attachment/201408/24/8400375_1408873446lh1h.png" width="696" height="291" />
儲存到用戶端/etc/.sshd/authorized_keys檔案中
用戶端配置
統一安裝服務配置下面的內容,建共用目錄,重啟,查看監聽,環境很重要,iptables,
vim /etc/rsyncd.conf
# Global Settings
uid = nobady
gid = nobady
use chroot = no
max connections = 10
strict modes = yes
pid file = /var/run/rsyncd.pid
log file = /var/log/rsyncd.log
# Directory to be synced
[tools]
path = /momo
ignore errors = yes
read only = no
write only = no
hosts allow = 172.16.1.0/16
hosts deny = *
list = true
uid = root
gid = root
最後驗證的話,服務端開啟指令碼,然後在服務端共用目錄中添加,修改檔案,在用戶端哪裡可以同步得到更新,同時可以再服務端用命令查看
inotifywait,用來監視檔案的變化
inotifywatch,用來統計檔案系統訪問的次數,監視檔案的中繼資料
實驗中應該注意些什麼,環境的搭建,原理及思路,最重要的是指令碼,排錯等
Rsync + Inotify