Editing 2014 Server Migration

Jump to: navigation, search

Warning: You are not logged in.

Your IP address will be recorded in this page's edit history.
The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision Your text
Line 172: Line 172:
 
== Migration steps ==
 
== Migration steps ==
  
* <strike>Obtain [https://library.linode.com/networking/ipv6#sph_ipv6-address-pools IPv6 address pool] from Linode (support ticket needed)</strike>
+
* Obtain [https://library.linode.com/networking/ipv6#sph_ipv6-address-pools IPv6 address pool] from Linode (support ticket needed)
** <strike>/etc/sysconfig/network-scripts/ifcfg-eth0 edited, reboot needed to apply - 2600:3c02:e000:0047::2/64 assigned</strike>
+
* Explore what software to use to help harden up the installation (fail2ban, etc.)
* <strike>Explore what software to use to help harden up the installation (fail2ban, etc.)</strike> ''Decided to use fail2ban-firewalld''
+
 
* <strike>Deploy new CentOS 7 instance</strike>
 
* <strike>Deploy new CentOS 7 instance</strike>
 
* (optional) Set up [https://library.linode.com/remote-access#sph_adding-private-ip-addresses private IPv4 addresses] for transfer between old and new VPS (avoids bandwidth charges)
 
* (optional) Set up [https://library.linode.com/remote-access#sph_adding-private-ip-addresses private IPv4 addresses] for transfer between old and new VPS (avoids bandwidth charges)
* <strike>Set up SSH (edit sshd_config to tighten up security)</strike>
+
* Set up SSH (edit sshd_config to tighten up security)
 
* <strike>Migrate current users to new server</strike>
 
* <strike>Migrate current users to new server</strike>
 
* <strike>Ensure NTP is running, and set timezone to EDT</strike>
 
* <strike>Ensure NTP is running, and set timezone to EDT</strike>
 
* <strike>Set up the firewall (either using firewalld, or else [https://fedoraproject.org/wiki/FirewallD?rd=FirewallD/#Using_static_firewall_rules_with_the_iptables_and_ip6tables_services installing iptables and using the old rules])</strike>
 
* <strike>Set up the firewall (either using firewalld, or else [https://fedoraproject.org/wiki/FirewallD?rd=FirewallD/#Using_static_firewall_rules_with_the_iptables_and_ip6tables_services installing iptables and using the old rules])</strike>
* <strike>Install Apache, and edit httpd.conf appropriately</strike>
+
* Install Apache, and edit httpd.conf appropriately
* <strike>Install PHP, edit php.ini appropriately, and make sure all needed modules are installed</strike>
+
* <strike>Install PHP</strike>, edit php.ini appropriately, and make sure all needed modules are installed
* <strike>Install MariaDB, add appropriate user(s)/permissions, and edit my.cnf appropriately</strike>
+
* <strike>Install MariaDB</strike>, add appropriate user(s)/permissions, and edit my.cnf appropriately
* <strike>Install/configure Postgrey</strike>
+
* Install/configure Postfix
* <strike>Install/configure Postfix</strike>
+
* Install/configure Mailman
* <strike>Install/configure Mailman</strike>
+
* Install/configure monkeybot
** <strike>archives copied over</strike>
+
* Set up Tiny Tiny RSS
* <strike>Install/configure monkeybot</strike>
+
* Migrate any other files that must be moved
* <strike>Install/configure Tiny Tiny RSS</strike>
+
* Export current MySQL and import into new MariaDB
* <strike>Migrate any other files that must be moved</strike>
+
* Install/configure MediaWiki
* <strike>Export current MySQL and import into new MariaDB (be sure to dump/restore final DB before switchover...)</strike>
+
* Set up repeating jobs (log rotation, etc.) via systemd/cron
* <strike>Install/configure MediaWiki</strike>
+
* Cut over DNS (or [https://library.linode.com/remote-access#sph_swapping-ip-addresses swap IPv4 addresses])
* <strike>Set up repeating jobs (log rotation, etc.) via systemd/cron</strike>
+
** <strike>Copy over 'at' job to remind about domain registration expiration</strike>
+
** <strike>Migrate over monkeybot cron jobs</strike> ''Waiting to see if logrotate runs overnight, as we are not sure that run-parts is being run by anything on the new system.''
+
** <strike>Configure log rotation</strike>
+
* <strike>Cut over DNS (or [https://library.linode.com/remote-access#sph_swapping-ip-addresses swap IPv4 addresses])</strike>
+
 
* Other steps not mentioned above
 
* Other steps not mentioned above
  
Line 203: Line 197:
  
 
We have an archive of static web pages from the pre-2007 server "penguin" - it would be nice to make this history available somehow.
 
We have an archive of static web pages from the pre-2007 server "penguin" - it would be nice to make this history available somehow.
$9/year Comodo SSL certificate through Namecheap: [https://www.namecheap.com/security/ssl-certificates/comodo.aspx]
 
  
 
=== Installation Notes ===
 
=== Installation Notes ===

Please note that all contributions to WPLUG may be edited, altered, or removed by other contributors. If you do not want your writing to be edited mercilessly, then do not submit it here.
You are also promising us that you wrote this yourself, or copied it from a public domain or similar free resource (see WPLUG:Copyrights for details). Do not submit copyrighted work without permission!

Cancel | Editing help (opens in new window)