Showing posts with label Ubuntu. Show all posts
Showing posts with label Ubuntu. Show all posts

Tuesday, May 26, 2015

Ubuntu 14.04 - Mysql Galera Cluster for Wordpress

This cluster has 2 nodes run in multi master mode

Installing cluster
sudo apt-key adv --recv-keys --keyserver keyserver.ubuntu.com 0xcbcb082a1bb943db
sudo add-apt-repository 'deb http://mirror3.layerjet.com/mariadb/repo/5.5/ubuntu trusty main'
sudo apt-get update -y ; sudo apt-get install -y galera mariadb-galera-server rsync

Configuring cluster
On each of the host in the cluster add this configuration
vi /etc/mysql/conf.d/galera.cnf
[mysqld]
#mysql settings
binlog_format=ROW
default-storage-engine=innodb
innodb_autoinc_lock_mode=2
query_cache_size=0
query_cache_type=0
bind-address=0.0.0.0
#galera settings
wsrep_provider=/usr/lib/galera/libgalera_smm.so
wsrep_cluster_name="my_wsrep_cluster"
wsrep_cluster_address="gcomm://192.20.3.31,192.20.3.32"
wsrep_sst_method=rsync

Stop MariaDB instance in all of the Galera hosts
sudo service mysql stop

Init the Galera cluster on my 1st node by start MariaDB
sudo service mysql start --wsrep-new-cluster

Just start MariaDB on my 2nd node
sudo service mysql start

To prevent startup error on 2nd node we need to copy /etc/mysql/debian.cnf content from node1 to node2 and then restart MariaDB on 2nd node

Confirm cluster status has started
mysql -u root -p -e 'SELECT VARIABLE_VALUE as "cluster size" FROM INFORMATION_SCHEMA.GLOBAL_STATUS WHERE VARIABLE_NAME="wsrep_cluster_size"'
Enter password: 
+--------------+
| cluster size |
+--------------+
| 2            |
+--------------+
From now on the data will sync between both hosts. To test it try create one database from 1st node then go to 2nd node and see it is there.
On 1st node
mysql -u root -p
create database HelloWorld;

On 2nd node
mysql -u root -p
show databases;
if Helloworld database was there. That's kool. We're ready to go.

Grant Remote privilege to remote user on DBcluster
On one of the DB host (node1 or node2)
mysql -u root -p
create user 'handsome'@'%' identified by handsome_password;
grant all privileges on Database_name . * to  'handsome'@'%';
flush privileges;
show grants for 'handsome'@'%';

Note: 
Replace handsome with your username or root
Replace Database_name with your DB name or * to grant privileges on all Database

DNS setting
On my premise DNS server I add a Round Robin DNS record point to 2 Galera host
dbcluster -> 192.20.3.31
dbcluster -> 192.20.3.32

On my PHP app server I can connect to the dbcluster with this command
mysql -u root -p -h dbcluster 

If it not work, you could have a look on MariaDB log

Reference link:
https://www.linode.com/docs/databases/mariadb/clustering-with-mariadb-and-galera

Thursday, May 21, 2015

Ubuntu 14.04 - GlusterFS for Wordpress

Here's my setup:  Client -> Varnish cache -> 2 x Worpdress -> Memcached -> 2 x MariaDB

I need to sync Wordpress folder on both Machine, just have a look on NFS, CEPH, GlusterFS and I go with GlusterFS
sudo apt-get -y install glusterfs-server

If you don't have a on premise DNS server, we can add the server name in to hosts files
192.20.1.1    srvr-phpnode1.mydomain.vn    srvr-phpnode1    
192.20.1.2    srvr-phpnode2.mydomain.vn    srvr-phpnode2

Create a directory for Gluster Volume on both hosts
mkdir /gluster-volume

Check for other peer status
sudo gluster peer probe srvr-phpnode2
peer probe: success

sudo gluster peer status
Number of Peers: 1

Hostname: srvr-phpnode2
Port: 24007
Uuid: 225698cb-a84f-4b5b-8537-27732d752aba
State: Peer in Cluster (Connected)

Glusterfs distributed vs Replica mode (GlusterFS docs):
Distributed mean data distributes across the available bricks in a volume: write 100 files, on average, 50 on one server, and 50 on another. This is faster than a “replicated” volume, but isn’t as popular since it doesn’t give you two of the most sought after features of Gluster — multiple copies of the data, and automatic failover if something goes wrong

Create wwwVol volume on host srvr-phpnode1
sudo gluster volume create wwwVol replica 2 transport tcp srvr-phpnode1:/gluster-volume srvr-phpnode2:/gluster-volume force

(GlusterFS docs): we tell it to make the volume a replica volume, and to keep a copy of the data on at least 2 bricks at any given time. Since we only have two bricks total, this means each server will house a copy of the data. Lastly, we specify which nodes to use, and which bricks on those nodes. The order here is important when you have more bricks

sudo gluster volume start wwwVol
sudo gluster volume info

Volume Name: wwwVol
Type: Replicate
Volume ID: 8c1430d4-8b25-4967-9a46-39287cdedbb2
Status: Started
Number of Bricks: 1 x 2 = 2
Transport-type: tcp
Bricks:
Brick1: srvr-phpnode1:/gluster-volume
Brick2: srvr-phpnode2:/gluster-volume

We need /var/www will be on GlusterFS so we will mount wwwVol to /var/www on both hosts
On both hosts
mkdir /var/www

On phpnode1
vi /etc/fstab
srvr-phpnode1:/wwwVol /var/www glusterfs defaults,_netdev 0 0

mount -a 

On phpnode2
vi /etc/fstab
srvr-phpnode2:/wwwVol /var/www glusterfs defaults,_netdev 0 0
mount -a 

Other GlusterFS command
gluster volume stop VOLNAME
gluster volume delete VOLNAME

gluster volume remove-brick VOLNAME wnode1:/www
http://www.gluster.org/community/documentation/index.php/Gluster_3.1:_Deleting_Volumes
http://www.gluster.org/community/documentation/index.php/Basic_Gluster_Troubleshooting

Ubuntu 14.04 - Memcached server for Wordpress

First thing first: memcache vs memcached

According to http://blackbe.lt/php-memcache-vs-memcached/
PHP has two separate module implementations wrapping the memcached (as in memcache daemon) server.

The memcache module utilizes this daemon directly, whereas the memcached module wraps the libMemcached client library and contains some added bonuses.
Memcached module will be faster than memcache module => I'll go with Memcached module

Install Memcached daemon on my dedicate Memcached host

sudo apt-get install memcached libmemcached-tools

My memcache server listen all of its address. So edit /etc/memcached.conf
-m 20000      #amount of RAM in MB
-p 11211      #listen port 11211
-l 0.0.0.0    #listen on all interfaces

Install memcached client
In other Wordpress PHP server we need to install memcahed client and server (optional):
sudo apt-get install php5-memcached memcached libmemcached-tools php-pear
sudo mkdir /etc/php5/conf.d
ln -s /etc/php5/mods-available/memcached.ini /etc/php5/conf.d/memcached.ini

I need to store Php sessions in Memcached because store in memory will be faster than disk 
Default is session.save_handler = files
Add to /etc/php5/conf.d/memcached.ini
[Session]
session.save_handler = memcached
session.save_path = "tcp://localhost:11211"

Wordpress and Memcached
Finally edit Wordpress wp-config file to add list of Memcached server for Wordpress Total cache plugin
global $memcached_servers;
$memcached_servers = array('default' => array('192.1.3.30:11211','192.1.1.11:11211','192.1.1.12:11211'));

Now your Wordpress can Memcached it.

Monday, April 27, 2015

Ubuntu 14.04 - Canon E500 network printing and scanning at home

Recently switch my Mom machine from Windows 7 to Ubuntu Gnome 14.04 which's my favorite one. So I need to share Canon E500 (USB) printing and scanning for my other devices over Network.
I set this host with static IP: 192.168.1.10

Install Canon E500 driver

sudo add-apt-repository ppa:inameiname/stable
sudo apt-get update -y
sudo apt-get install -y cnijfilter-e500series scangearmp-e500series

Now I can add the printer from Printer Config
For Scanner: I use ScanGear instead of Simple Scan

Sharing Printer

This step is share printing service over network
Cups printing running on port 631 localhost -> go to CUPS admin at http://localhost:631/admin
In the Server part setting: Check these options
  • Share printers connected to this system
  • Allow printing from the Internet
  • Allow remote administration
  • Allow users to cancel any job (not just their own)  //this is my home purpose
=> Change Settings -> wait for Cup restarting

Manage E500 printer via CUPS. Now we need to access CUPS by its IP address, I also leave the printer name as E500-series
http://192.168.1.10:631/printers  make sure the printer E500-series is available otherwise add it to
From here you can print any test pages, maintenance, etc...I don't need to set any allowed user. Just me and my mom

Sharing Scanner

On the server (E500 connect directly via USB) tell sane to run as server
sudo vi /etc/default/saned
Run=no -> Run=yes

Allow user from my subnet
sudo vi /etc/sane.d/saned.conf
## Access list
192.168.1.0/24

service saned restart

On the client
sudo vi  /etc/sane.d/net.conf
## saned hosts
192.168.1.10
connect_timeout = 60

Open Xsane and wait for Scanner discovery

Tuesday, December 9, 2014

Ubuntu server auto mount iSCSi storage

Install Open-iSCSI initiator
apt-get install open-iscsi

configuration file could be located at /etc/iscsi/iscsid.conf or ~/.iscsid.conf.
node.startup = automatic
node.session.auth.username = MY-ISCSI-USER
node.session.auth.password = MY-ISCSI-PASSWORD
discovery.sendtargets.auth.username = MY-ISCSI-USER
discovery.sendtargets.auth.password = MY-ISCSI-PASSWORD

Discover iSCSi Target
iscsiadm -m discovery -t sendtargets -p 172.31.1.150

Login to target
iscsiadm --mode node --targetname iqn.1992-04.com.emc:cx.fcnma082600013.a0 --portal 172.31.1.150 --login

Note: remember login to your iSCSi server (SAN) then allow your server connection
Make sure you auto connect to iSCSi server target when server start up
vi /etc/iscsi/nodes/iqn.1992-04.com.emc\:cx.fcnma082600013.b1/172.31.2.151\,3260\,3/default

node.startup = automatic

Restart service
/etc/init.d/open-iscsi restart

Format and mount the iSCSi volume

dmesg or fdisk -l, or look at /var/log/messages to find new devices
You can use LVM or partition your disk now
fdisk /dev/sde

Format a partition ext4 or xfs or brtfs
mkfs.ext4 /dev/sde1

Mount file system
mkdir /backupdata
mount /dev/sde1 /backupdata

Add mount point to /etc/fstab 
/dev/sde1  /backupdata ext4 defaults 0 0

Monday, December 8, 2014

Bonding Network Card Ubuntu 14.04

Make sure your Cisco Switch support 802.3ad, then group 2 interface ports together
Router> enable
Router# configure terminal
Router(config)# interface port-channel 1
Router(config-if)# interface g1/0/24
Router(config-if)# channel-group 1 mode active
Router(config-if)# exit
Router(config)# interface g1/0/23
Router(config-if)# channel-group 1 mode active
Router(config-if)# end
Router# copy run start

Bonding mode: http://www.mjmwired.net/kernel/Documentation/networking/bonding.txt#508
802.3ad or 4 : IEEE 802.3ad Dynamic link aggregation. Creates aggregation groups that share the same speed and duplex settings. Utilizes all slaves in the active aggregator according to the 802.3ad specification.

Bonding network card on Ubuntu Server
apt-get install ifenslave-2.6
echo "bonding" >> /etc/modules
modprobe bonding

vi /etc/network/interface
auto em1
iface em1 inet manual
bond-master bond0
bond-primary em1

auto em2
iface em2 inet manual
bond-master bond0

auto bond0
iface bond0 inet static
bond-slaves none
bond-mode 4
bond-miimon 100
        address 192.168.1.111
        netmask 255.255.0.0
        network 192.168.0.0
        broadcast 192.168.255.255
        gateway 192.168.1.1
        dns-nameservers 192.168.1.1 

Reboot server and wait a little bit for the bond interface become active

http://www.paulmellors.net/ubuntu-server-14-04-lts-nic-bonding/
http://ilostmynotes.blogspot.com/2009/04/bridging-bonded-network-interface-on.html

Thursday, December 4, 2014

Ubuntu - 3 tricks to copy DVD into iso file

Built in command

cat /dev/sr0 > /home/Documents/mydisk.iso
dd if=/dev/sr0 of=/home/Documents/mydisk.iso

If both cat, and dd not work because of '/dev/sr0': Input/output error
If I run dmesg, I recieve a lot of Buffer I/O error on device sr0

Try ddrescue in Ubuntu the package is gddrescue
sudo apt-get install gddrescue
ddrescue --direct --block-size=2048 --no-split /dev/sr0 /home/Documents/mydisk.iso

Now you can open iso file with VLC

Tuesday, June 10, 2014

Ubuntu Network Manager cannot connect to WPA2/PEAP/MSCHAPv2 network without CA_Certificate

Quick way to fix all the Wireless network that require Certificate, you don't have to provide your certificate.
Use incrontab to pull the trigger automatically when you connect to Wireless network that require Certificate, the script will add a mozilla External Root Certificate when your Network Manager create Wireless SSiD connection on /etc/NetworkManager/system-connections/

sudo -i
incrontab -e
/etc/NetworkManager/system-connections/ IN_CREATE sleep 3; grep -rl 'system-ca-certs=true' /etc/NetworkManager/system-connections/ | xargs sed -i '/system-ca-certs=true/a ca-cert=/usr/share/ca-certificates/mozila/AddTrust_External_Root.crt'


Wednesday, June 4, 2014

Customize default desktop environment settings for Gnome-centric Linux distributions

Some of you are probably wondering why would you want to spend your time fiddling with default desktop environment settings customization, when you can easily customize everything to your liking inside you own user account? Most probably you'd want to do this when you're re-mastering your favorite Linux distribution using tools like OS4 system imager (fork of the now discontinued Remastersys) or Relinux. In this article I'll show you how to handle this task elegantly using GSettings vendor overrides.

Introduction

First some background. GSettings provides a convenient API for storing and retrieving application settings, similar to system registry inside one of the popular proprietary operating system. Applications can define key/value pairs their application is using by installing .gschema.xml files, and then use GSettings API to manipulate the values. GSettings also provides mechanisms for distribution vendors to override default key/value pairs for specific applications by using .gschema.override files.

Pick the right schema file

First thing we need to do is picking the key/value pair which controls the setting whose defaults we want to modify. We do this using command line tools like "gsettings list-schemas" or "gsettings list-recursively" or using GUI tools like "dconf-editor". For the sake of simplicity and to better illustrate this process, in this article I'll use dconf-editor. On a Debian based distributions like Ubuntu we will find dconf-editor inside dconf-tools package:
sudo apt-get install dconf-tools
Now that we have all the tools lets imagine we want to change default fonts our Gnome-centric desktop environment like Gnome 3, Unity or Cinnamon is using. Using dconf-editor we can edit settings for current user account, but most importantly find GSettings schemas and key/value pairs we're interested in:
org.gnome.desktop.interface
  • font-name
  • document-font-name
  • monospace-font-name
org.gnome.desktop.wm.preferences
  • titlebar-font
Here's screenshot displaying one section of org.gnome.desktop.interface schema inside dconf-editor:


Create .gschema.override file

Now when we have all of the information we can use our favorite editor to create the .gschema.override file:
sudo nano /usr/share/glib-2.0/schemas/60_our-own.gschema.override
The 60 is override priority, here I usually use 60 because most Linux distribution vendors use priority of 50 or less. Now we place following inside that file:

[org.gnome.desktop.interface]font-name='Ubuntu 12' document-font-name='Sans 12' monospace-font-name='Ubuntu Mono 14' 
[org.gnome.desktop.wm.preferences] titlebar-font='Ubuntu Bold 12'
We exit and save using Ctrl^X and then compile GSettings schemas to reflect our changes like this:
sudo glib-compile-schemas /usr/share/glib-2.0/schemas/
After system restart desktop environment for all new users and existing users who haven't changed desktop environment fonts will use fonts we have specified inside our .gschema.override file. This way we can easily tweak almost every aspect of our desktop environment interface, and in the end easily create our own flavor of the Linux distro using remastersys-like tools. That's what I call flexible operating system, don't you agree?

How I customize My Cinnamon

gsettings set org.cinnamon.desktop.background picture-uri file:///usr/share/backgrounds/myWallpaper.jpg
gsettings set org.cinnamon.desktop.background picture-options stretched
gsettings set org.cinnamon.settings-daemon.peripherals.touchpad disable-while-typing true
gsettings set org.cinnamon.settings-daemon.peripherals.touchpad motion-acceleration 2
gsettings set org.cinnamon.settings-daemon.peripherals.touchpad motion-threshold 2
gsettings set org.cinnamon.settings-daemon.peripherals.touchpad scroll-method two-finger-scrolling
gsettings set org.cinnamon.settings-daemon.peripherals.touchpad tap-to-click true
gsettings set org.cinnamon.settings-daemon.peripherals.touchpad touchpad-enabled true

How to add your shorcut to Cinnamon

Monday, June 2, 2014

How to sync Windows folder to Ubuntu permanent

apt-get install cifs-utils

Mounting unprotected (guest) network folders

sudo mkdir /media/windowsshare

Then edit your /etc/fstab file (with root privileges) to add this line:
//servername/sharename /media/windowsshare cifs guest,uid=1000,iocharset=utf8 0 0

guest indicates you don't need a password to access the share,
uid=1000 makes the Linux user specified by the id the owner of the mounted share, allowing them to rename files,
iocharset=utf8 allows access to files with names in non-English languages. This doesn't work with shares of devices like the Buffalo Tera Station, or Windows machines that export their shares using ISO8895-15.

If there is any space in the server path, you need to replace it by \040, for example
//servername/My\040Documents

After you add the entry to /etc/fstab type:
sudo mount -a

Mount password protected network folders

The quickest way to auto-mounting a password-protected share is to edit /etc/fstab (with root privileges), to add this line:
//servername/sharename /media/windowsshare cifs username=msusername,password=mspassword,iocharset=utf8,sec=ntlm 0 0

This is not a good idea however: /etc/fstab is readable by everyone and so is your Windows password in it. The way around this is to use a credentials file. This is a file that contains just the username and password.

Using a text editor, create a file for your remote servers logon credential:
vi ~/.smbcredentials

Enter your Windows username and password in the file:
username=msusername
password=mspassword
Change the permissions of the file to prevent unwanted access to your credentials:
chmod 600 ~/.smbcredentials

Then edit your /etc/fstab file (with root privileges) to add this line (replacing the insecure line in the example above, if you added it):
//servername/sharename /media/windowsshare cifs credentials=/home/ubuntuusername/.smbcredentials,iocharset=utf8,sec=ntlm 0 0

Save the file, exit the editor. Finally, test the fstab entry by issuing:
sudo mount -a

If there are no errors, you should test how it works after a reboot. Your remote share should mount automatically.

Special permissions

If you need special permission (like chmod etc.), you'll need to add a uid (short for 'user id') or gid (for 'group id') parameter to the share's mount options.
//servername/sharename /media/windowsshare cifs uid=ubuntuuser,credentials=/home/ubuntuuser/.smbcredentials,iocharset=utf8,sec=ntlm 0 0

Sync Localdir with Sharedir

rsync -avz /media/windowsshare/ /var/www/app/img/

Sync every 5 minutes
su - www-data
crontab -e
* 5 * * * rsync -avz /media/windowsshare/ /var/www/app/img/ > /dev/null 2>&1


https://wiki.ubuntu.com/MountWindowsSharesPermanently