ืขื ืŸ ืœืžื˜ืจื•ืช ืฆื“ืงื”: ืžื“ืจื™ืš ื”ื’ื™ืจื”

ืขื ืŸ ืœืžื˜ืจื•ืช ืฆื“ืงื”: ืžื“ืจื™ืš ื”ื’ื™ืจื”

ืœืคื ื™ ื–ืžืŸ ืœื ืจื‘, Mail.Ru Cloud Solutions (MCS) ื•ืฉื™ืจื•ืช Dobro Mail.Ru ื”ืฉื™ืงื• ืืช ื”ืคืจื•ื™ืงื˜ "ืขื ืŸ ืœืืจื’ื•ื ื™ ืฆื“ืงื”", ืฉื‘ื–ื›ื•ืชื ืืจื’ื•ื ื™ื ืœืœื ืžื˜ืจื•ืช ืจื•ื•ื— ื™ื›ื•ืœื™ื ืœื”ืฉื™ื’ ืืช ื”ืžืฉืื‘ื™ื ืฉืœ ืคืœื˜ืคื•ืจืžืช ื”ืขื ืŸ MCS ื‘ื—ื™ื ื. ืงืจืŸ ืฆื“ืงื”"ืืจื™ืชืžื˜ื™ืงื” ืฉืœ ื˜ื•ื‘ยป ืœืงื— ื—ืœืง ื‘ืคืจื•ื™ืงื˜ ื•ืคืจืก ื‘ื”ืฆืœื—ื” ื—ืœืง ืžื”ืชืฉืชื™ืช ืฉืœื• ืžื‘ื•ืกืกืช MCS.

ืœืื—ืจ ื”ืขื‘ืจืช ื”ืื™ืžื•ืช, NPO ื™ื›ื•ืœ ืœืงื‘ืœ ืงื™ื‘ื•ืœืช ื•ื™ืจื˜ื•ืืœื™ืช ืž-MCS, ืืš ืชืฆื•ืจื” ื ื•ืกืคืช ื“ื•ืจืฉืช ื›ื™ืฉื•ืจื™ื ืžืกื•ื™ืžื™ื. ื‘ื—ื•ืžืจ ื–ื”, ืื ื• ืจื•ืฆื™ื ืœืฉืชืฃ ื”ื ื—ื™ื•ืช ืกืคืฆื™ืคื™ื•ืช ืœื”ื’ื“ืจืช ืฉืจืช ืžื‘ื•ืกืก ืื•ื‘ื•ื ื˜ื• ืœื™ื ื•ืงืก ืœื”ืคืขืœืช ืืชืจ ื”ื‘ืกื™ืก ื”ืจืืฉื™ ื•ืžืกืคืจ ืชืช-ื“ื•ืžื™ื™ื ื™ื ื‘ืืžืฆืขื•ืช ืชืขื•ื“ื•ืช SSL ื‘ื—ื™ื ื. ืขื‘ื•ืจ ืจื‘ื™ื, ื–ื” ื™ื”ื™ื” ืžื“ืจื™ืš ืคืฉื•ื˜, ืืš ืื ื• ืžืงื•ื•ื™ื ืฉื”ื ื™ืกื™ื•ืŸ ืฉืœื ื• ื™ื•ืขื™ืœ ืœืขืžื•ืชื•ืช ืื—ืจื•ืช, ื•ืœื ืจืง.

ืœื™ื“ื™ืขืชืš: ืžื” ืืชื” ื™ื›ื•ืœ ืœืงื‘ืœ ืž-MCS? 4 ืžืขื‘ื“ื™ื, 32 GB RAM, 1 TB HDD, ืื•ื‘ื•ื ื˜ื• ืœื™ื ื•ืงืก OS, 500 GB ืื—ืกื•ืŸ ืื•ื‘ื™ื™ืงื˜ื™ื.

ืฉืœื‘ 1: ื”ืคืขืœ ืืช ื”ืฉืจืช ื”ื•ื•ื™ืจื˜ื•ืืœื™

ื‘ื•ืื• ื ื™ื’ืฉ ื™ืฉืจ ืœืขื ื™ื™ืŸ ื•ื ื™ืฆื•ืจ ืืช ื”ืฉืจืช ื”ื•ื•ื™ืจื˜ื•ืืœื™ ืฉืœื ื• (ื”ืžื›ื•ื ื” "ืžื•ืคืข") ื‘ื—ืฉื‘ื•ืŸ ื”ืื™ืฉื™ ืฉืœืš ื‘-MCS. ื‘ื—ื ื•ืช ื”ืืคืœื™ืงืฆื™ื•ืช, ืขืœื™ืš ืœื‘ื—ื•ืจ ื•ืœื”ืชืงื™ืŸ ืขืจื™ืžืช LAMP ืžื•ื›ื ื”, ืฉื”ื™ื ืงื‘ื•ืฆื” ืฉืœ ืชื•ื›ื ื•ืช ืฉืจืช (LAMP = Linux, Apache, MySQL, PHP) ื”ื ื—ื•ืฆื•ืช ืœื”ืคืขืœืช ืจื•ื‘ ืืชืจื™ ื”ืื™ื ื˜ืจื ื˜.

ืขื ืŸ ืœืžื˜ืจื•ืช ืฆื“ืงื”: ืžื“ืจื™ืš ื”ื’ื™ืจื”
ืขื ืŸ ืœืžื˜ืจื•ืช ืฆื“ืงื”: ืžื“ืจื™ืš ื”ื’ื™ืจื”
ืขื ืŸ ืœืžื˜ืจื•ืช ืฆื“ืงื”: ืžื“ืจื™ืš ื”ื’ื™ืจื”
ื‘ื—ืจ ืืช ืชืฆื•ืจืช ื”ืฉืจืช ื”ืžืชืื™ืžื” ื•ืฆื•ืจ ืžืคืชื— SSH ื—ื“ืฉ. ืœืื—ืจ ืœื—ื™ืฆื” ืขืœ ื›ืคืชื•ืจ "ื”ืชืงืŸ", ื”ื”ืชืงื ื” ืฉืœ ื”ืฉืจืช ื•ืขืจื™ืžืช LAMP ืชืชื—ื™ืœ, ื–ื” ื™ื™ืงื— ื–ืžืŸ ืžื”. ื”ืžืขืจื›ืช ืชืฆื™ืข ื’ื ืœื”ื•ืจื™ื“ ืžืคืชื— ืคืจื˜ื™ ืœืžื—ืฉื‘ ืฉืœืš ื›ื“ื™ ืœื ื”ืœ ืืช ื”ืžื›ื•ื ื” ื”ื•ื™ืจื˜ื•ืืœื™ืช ื“ืจืš ื”ืงื•ื ืกื•ืœื”, ืœืฉืžื•ืจ ืื•ืชื”.

ืœืื—ืจ ื”ืชืงื ืช ื”ืืคืœื™ืงืฆื™ื”, ื‘ื•ืื• ื ื’ื“ื™ืจ ืžื™ื“ ืืช ื—ื•ืžืช ื”ืืฉ, ื–ื” ื ืขืฉื” ื’ื ื‘ื—ืฉื‘ื•ืŸ ื”ืื™ืฉื™ ืฉืœื›ื: ืขื‘ื•ืจ ืœืงื˜ืข "ืžื—ืฉื•ื‘ ืขื ืŸ -> ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช" ื•ื‘ื—ืจ "ื”ื’ื“ืจืช ื—ื•ืžืช ื”ืืฉ":

ืขื ืŸ ืœืžื˜ืจื•ืช ืฆื“ืงื”: ืžื“ืจื™ืš ื”ื’ื™ืจื”
ืขืœื™ืš ืœื”ื•ืกื™ืฃ ื”ืจืฉืื” ืœืชืขื‘ื•ืจื” ื ื›ื ืกืช ื“ืจืš ื™ืฆื™ืื•ืช 80 ื•-9997. ื–ื” ื ื—ื•ืฅ ื‘ืขืชื™ื“ ื›ื“ื™ ืœื”ืชืงื™ืŸ ืชืขื•ื“ื•ืช SSL ื•ืœืขื‘ื•ื“ ืขื phpMyAdmin. ื›ืชื•ืฆืื” ืžื›ืš, ืžืขืจื›ืช ื”ื›ืœืœื™ื ืฆืจื™ื›ื” ืœื”ื™ืจืื•ืช ื›ืš:

ืขื ืŸ ืœืžื˜ืจื•ืช ืฆื“ืงื”: ืžื“ืจื™ืš ื”ื’ื™ืจื”
ื›ืขืช ืืชื” ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ืœืฉืจืช ืฉืœืš ื‘ืืžืฆืขื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ SSH. ื›ื“ื™ ืœืขืฉื•ืช ื–ืืช, ื”ืงืœื“ ืืช ื”ืคืงื•ื“ื” ื”ื‘ืื”, ืชื•ืš ื”ืฆื‘ืขื” ืขืœ ืžืงืฉ SSH ื‘ืžื—ืฉื‘ ืฉืœืš ื•ื›ืชื•ื‘ืช ื”-IP ื”ื—ื™ืฆื•ื ื™ืช ืฉืœ ื”ืฉืจืช ืฉืœืš (ืชื•ื›ืœ ืœืžืฆื•ื ืื•ืชื” ื‘ืกืขื™ืฃ "ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช"):

$ ssh -i /ะฟัƒั‚ัŒ/ะบ/ะบะปัŽั‡ัƒ/key.pem ubuntu@<ip_ัะตั€ะฒะตั€ะฐ>

ื‘ืขืช ื”ืชื—ื‘ืจื•ืช ืœืฉืจืช ื‘ืคืขื ื”ืจืืฉื•ื ื”, ืžื•ืžืœืฅ ืœื”ืชืงื™ืŸ ื‘ื• ืืช ื›ืœ ื”ืขื“ื›ื•ื ื™ื ื”ืขื“ื›ื ื™ื™ื ื•ืœืืชื—ืœ ืื•ืชื•. ืœืฉื ื›ืš, ื”ืคืขืœ ืืช ื”ืคืงื•ื“ื•ืช ื”ื‘ืื•ืช:

$ sudo apt-get update

ื”ืžืขืจื›ืช ืชืงื‘ืœ ืจืฉื™ืžื” ืฉืœ ืขื“ื›ื•ื ื™ื, ืชืชืงื™ืŸ ืื•ืชื ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื” ื–ื• ื•ืชืคืขืœ ืœืคื™ ื”ื”ื•ืจืื•ืช:

$ sudo apt-get upgrade

ืœืื—ืจ ื”ืชืงื ืช ื”ืขื“ื›ื•ื ื™ื, ื”ืคืขืœ ืžื—ื“ืฉ ืืช ื”ืฉืจืช:

$ sudo reboot

ืฉืœื‘ 2: ื”ื’ื“ืจ ืžืืจื—ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื

ืขืžื•ืชื•ืช ืจื‘ื•ืช ืฆืจื™ื›ื•ืช ืœืชื—ื–ืง ืžืกืคืจ ื“ื•ืžื™ื™ื ื™ื ืื• ืชืช-ื“ื•ืžื™ื™ื ื™ื ื‘ื•-ื–ืžื ื™ืช (ืœื“ื•ื’ืžื”, ืืชืจ ืจืืฉื™ ื•ืžืกืคืจ ื“ืคื™ ื ื—ื™ืชื” ืœืงืžืคื™ื™ื ื™ื ืคืจืกื•ืžื™ื™ื ื•ื›ื•'). ื›ืœ ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžืžื•ืงื ื‘ื ื•ื—ื•ืช ืขืœ ืฉืจืช ืื—ื“ ืขืœ ื™ื“ื™ ื™ืฆื™ืจืช ืžืกืคืจ ืžืืจื—ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื.

ืจืืฉื™ืช ืขืœื™ื ื• ืœื™ืฆื•ืจ ืžื‘ื ื” ืกืคืจื™ื•ืช ืขื‘ื•ืจ ื”ืืชืจื™ื ืฉื™ื•ืฆื’ื• ืœืžื‘ืงืจื™ื. ื‘ื•ืื• ื ื™ืฆื•ืจ ื›ืžื” ืกืคืจื™ื•ืช:

$ sudo mkdir -p /var/www/a-dobra.ru/public_html

$ sudo mkdir -p /var/www/promo.a-dobra.ru/public_html

ื•ืฆื™ื™ืŸ ืืช ื”ื‘ืขืœื™ื ืฉืœ ื”ืžืฉืชืžืฉ ื”ื ื•ื›ื—ื™:

$ sudo chown -R $USER:$USER /var/www/a-dobra.ru/public_html

$ sudo chown -R $USER:$USER /var/www/promo.a-dobra.ru/public_html

ืžืฉืชื ื” $USER ืžื›ื™ืœ ืืช ืฉื ื”ืžืฉืชืžืฉ ืชื—ืชื™ื• ืืชื” ืžื—ื•ื‘ืจ ื›ืขืช (ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื–ื”ื• ื”ืžืฉืชืžืฉ ubuntu). ื›ืขืช ื”ืžืฉืชืžืฉ ื”ื ื•ื›ื—ื™ ื”ื•ื ื”ื‘ืขืœื™ื ืฉืœ ืกืคืจื™ื•ืช public_html ืฉื‘ื”ืŸ ื ืื—ืกืŸ ืืช ื”ืชื•ื›ืŸ.

ื›ืžื• ื›ืŸ, ืขืœื™ื ื• ืœืขืจื•ืš ืžืขื˜ ืืช ื”ื”ืจืฉืื•ืช ื›ื“ื™ ืœื•ื•ื“ื ืฉืžืชืืคืฉืจืช ื’ื™ืฉืช ืงืจื™ืื” ืœืกืคืจื™ื™ืช ื”ืื™ื ื˜ืจื ื˜ ื”ืžืฉื•ืชืคืช ื•ืœื›ืœ ื”ืงื‘ืฆื™ื ื•ื”ืชื™ืงื™ื•ืช ืฉื”ื™ื ืžื›ื™ืœื”. ื–ื” ื”ื›ืจื—ื™ ื›ื“ื™ ืฉื“ืคื™ ื”ืืชืจ ื™ื•ืฆื’ื• ื›ื”ืœื›ื”:

$ sudo chmod -R 755 /var/www

ื›ืขืช ืืžื•ืจื•ืช ืœื”ื™ื•ืช ืœืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ืฉืœืš ืืช ื”ื”ืจืฉืื•ืช ื”ื“ืจื•ืฉื•ืช ืœื• ื›ื“ื™ ืœื”ืฆื™ื’ ืืช ื”ืชื•ื›ืŸ. ื‘ื ื•ืกืฃ, ืœืžืฉืชืžืฉ ืฉืœืš ื™ืฉ ื›ืขืช ืืช ื”ื™ื›ื•ืœืช ืœื™ืฆื•ืจ ืชื•ื›ืŸ ื‘ืกืคืจื™ื•ืช ื”ื ื“ืจืฉื•ืช.

ื™ืฉ ื›ื‘ืจ ืงื•ื‘ืฅ index.php ื‘ืกืคืจื™ื™ืช /var/www/html, ื‘ื•ืื• ื ืขืชื™ืง ืื•ืชื• ืœืกืคืจื™ื•ืช ื”ื—ื“ืฉื•ืช ืฉืœื ื• - ื–ื” ื™ื”ื™ื” ื”ืชื•ื›ืŸ ืฉืœื ื• ืœืขืช ืขืชื”:

$ cp /var/www/html/index.php /var/www/a-dobra.ru/public_html/index.php

$ cp /var/www/html/index.php /var/www/promo.a-dobra.ru/public_html/index.php

ื›ืขืช ืขืœื™ืš ืœื•ื•ื“ื ืฉื”ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื’ืฉืช ืœืืชืจ ืฉืœืš. ืœืฉื ื›ืš, ืชื—ื™ืœื” ื ื’ื“ื™ืจ ืืช ืงื‘ืฆื™ ื”ืžืืจื— ื”ื•ื•ื™ืจื˜ื•ืืœื™ื™ื, ืืฉืจ ืงื•ื‘ืขื™ื ื›ื™ืฆื“ ืฉืจืช ื”ืื™ื ื˜ืจื ื˜ ืฉืœ Apache ื™ื’ื™ื‘ ืœื‘ืงืฉื•ืช ืœื“ื•ืžื™ื™ื ื™ื ืฉื•ื ื™ื.

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืœ- Apache ื™ืฉ ืงื•ื‘ืฅ ืžืืจื— ื•ื™ืจื˜ื•ืืœื™ 000-default.conf ืฉืื ื• ื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ื• ื›ื ืงื•ื“ืช ื”ืชื—ืœื”. ืื ื—ื ื• ื”ื•ืœื›ื™ื ืœื”ืขืชื™ืง ืืช ื–ื” ื›ื“ื™ ืœื™ืฆื•ืจ ืงื‘ืฆื™ ืžืืจื— ื•ื™ืจื˜ื•ืืœื™ ืขื‘ื•ืจ ื›ืœ ืื—ื“ ืžื”ื“ื•ืžื™ื™ื ื™ื ืฉืœื ื•. ื ืชื—ื™ืœ ืขื ื“ื•ืžื™ื™ืŸ ืื—ื“, ืชื’ื“ื™ืจ ืื•ืชื•, ื ืขืชื™ืง ืื•ืชื• ืœื“ื•ืžื™ื™ืŸ ืื—ืจ, ื•ืื– ื ื‘ืฆืข ืฉื•ื‘ ืืช ื”ืขืจื™ื›ื•ืช ื”ื ื“ืจืฉื•ืช.

ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ืื•ื‘ื•ื ื˜ื• ื“ื•ืจืฉืช ืฉืœื›ืœ ืงื•ื‘ืฅ ืžืืจื— ื•ื™ืจื˜ื•ืืœื™ ื™ื”ื™ื” ืกื™ื•ืžืช *.conf.

ื ืชื—ื™ืœ ื‘ื”ืขืชืงืช ื”ืงื•ื‘ืฅ ืขื‘ื•ืจ ื”ื“ื•ืžื™ื™ืŸ ื”ืจืืฉื•ืŸ:

$ sudo cp /etc/apache2/sites-available/000-default.conf /etc/apache2/sites-available/a-dobra.ru.conf

ืคืชื— ืงื•ื‘ืฅ ื—ื“ืฉ ื‘ืขื•ืจืš ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ:

$ sudo nano /etc/apache2/sites-available/a-dobra.ru.conf

ืขืจื•ืš ืืช ื”ื ืชื•ื ื™ื ื›ื“ืœืงืžืŸ, ืชื•ืš ืฆื™ื•ืŸ ื™ืฆื™ืื” 80, ืขื‘ื•ืจ ื”ื ืชื•ื ื™ื ืฉืœืš ServerAdmin, ServerName, ServerAlias, ื›ืžื• ื’ื ืืช ื”ื ืชื™ื‘ ืœืกืคืจื™ื™ืช ื”ื‘ืกื™ืก ืฉืœ ื”ืืชืจ ืฉืœืš, ืฉืžื•ืจ ืืช ื”ืงื•ื‘ืฅ (Ctrl+X, ื•ืื– Y):

<VirtualHost *:80>
 
    ServerAdmin [email protected]
    ServerName a-dobra.ru
    ServerAlias www.a-dobra.ru
 
    DocumentRoot /var/www/a-dobra.ru/public_html
    ErrorLog ${APACHE_LOG_DIR}/error.log
    CustomLog ${APACHE_LOG_DIR}/access.log combined
 
    <Directory /var/www/a-dobra.ru/public_html>
        Options -Indexes +FollowSymLinks +MultiViews
        AllowOverride All
        Require all granted
    </Directory>
 
    <FilesMatch .php$>
        SetHandler "proxy:unix:/var/run/php/php7.2-fpm.sock|fcgi://localhost/"
    </FilesMatch>
 
</VirtualHost>

ServerName ืžื’ื“ื™ืจ ืืช ื”ื“ื•ืžื™ื™ืŸ ื”ืจืืฉื™, ืฉืขืœื™ื• ืœื”ืชืื™ื ืœืฉื ื”ืžืืจื— ื”ื•ื•ื™ืจื˜ื•ืืœื™. ื–ื” ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืฉื ื”ื“ื•ืžื™ื™ืŸ ืฉืœืš. ืฉืึฐื ึดื™ึธื”, ServerAlias, ืžื’ื“ื™ืจ ืฉืžื•ืช ืื—ืจื™ื ืฉื™ืฉ ืœืคืจืฉ ื›ืื™ืœื• ื–ื” ื”ื™ื” ื”ืชื—ื•ื ื”ืจืืฉื™. ื–ื” ื ื•ื— ืœืฉื™ืžื•ืฉ ื‘ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ื ื•ืกืคื™ื, ืœืžืฉืœ ื‘ืืžืฆืขื•ืช www.

ื‘ื•ืื• ื ืขืชื™ืง ืืช ื”ืชืฆื•ืจื” ื”ื–ื• ืขื‘ื•ืจ ืžืืจื— ืื—ืจ ื•ื’ื ื ืขืจื•ืš ืื•ืชื” ื‘ืื•ืชื• ืื•ืคืŸ:

$ sudo cp /etc/apache2/sites-available/a-dobra.ru.conf /etc/apache2/sites-available/promo.a-dobra.ru.conf

ืืชื” ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืžืกืคืจ ืžื“ืจื™ื›ื™ื ื•ืžืืจื—ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื ืขื‘ื•ืจ ืืชืจื™ ื”ืื™ื ื˜ืจื ื˜ ืฉืœืš ื›ื›ืœ ืฉืชืจืฆื”! ื›ืขืช, ืœืื—ืจ ืฉื™ืฆืจื ื• ืืช ืงื‘ืฆื™ ื”ืžืืจื— ื”ื•ื•ื™ืจื˜ื•ืืœื™ื™ื ืฉืœื ื•, ืขืœื™ื ื• ืœื”ืคืขื™ืœ ืื•ืชื. ืื ื• ื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช a2ensite ื›ื“ื™ ืœืืคืฉืจ ื›ืœ ืื—ื“ ืžื”ืืชืจื™ื ืฉืœื ื• ื›ืš:

$ sudo a2ensite a-dobra.ru.conf

$ sudo a2ensite promo.a-dobra.ru.conf 

ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื™ืฆื™ืื” 80 ืกื’ื•ืจื” ื‘-LAMP, ื•ื ืฆื˜ืจืš ืื•ืชื” ืžืื•ื—ืจ ื™ื•ืชืจ ื›ื“ื™ ืœื”ืชืงื™ืŸ ืื™ืฉื•ืจ SSL. ืื– ื‘ื•ืื• ื ืขืจื•ืš ืžื™ื“ ืืช ื”ืงื•ื‘ืฅ ports.conf ื•ืื– ื ืคืขื™ืœ ืžื—ื“ืฉ ืืช Apache:

$ sudo nano /etc/apache2/ports.conf

ื”ื•ืกืฃ ืฉื•ืจื” ื—ื“ืฉื” ื•ืฉืžื•ืจ ืืช ื”ืงื•ื‘ืฅ ื›ืš ืฉื™ื™ืจืื” ื›ืš:

Listen 80
Listen 443
Listen 9997

ืœืื—ืจ ื”ืฉืœืžืช ื”ื”ื’ื“ืจื•ืช, ืขืœื™ืš ืœื”ืคืขื™ืœ ืžื—ื“ืฉ ืืช Apache ื›ื“ื™ ืฉื›ืœ ื”ืฉื™ื ื•ื™ื™ื ื™ื™ื›ื ืกื• ืœืชื•ืงืฃ:

$ sudo systemctl reload apache2

ืฉืœื‘ 3: ื”ื’ื“ืจ ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ

ืœืื—ืจ ืžื›ืŸ, ืขืœื™ืš ืœื”ื•ืกื™ืฃ ืจืฉื•ืžื•ืช DNS ืฉื™ืฆื‘ื™ืขื• ืขืœ ื”ืฉืจืช ื”ื—ื“ืฉ ืฉืœืš. ื›ื“ื™ ืœื ื”ืœ ื“ื•ืžื™ื™ื ื™ื, ืงืจืŸ Arithmetic of Good ืฉืœื ื• ืžืฉืชืžืฉืช ื‘ืฉื™ืจื•ืช dns-master.ru, ื ืฆื™ื’ ื–ืืช ืขื ื“ื•ื’ืžื”.

ื”ื’ื“ืจืช ืจืฉื•ืžื” A ืขื‘ื•ืจ ื”ื“ื•ืžื™ื™ืŸ ื”ืจืืฉื™ ืžืฆื•ื™ื ืช ื‘ื“ืจืš ื›ืœืœ ื›ื“ืœืงืžืŸ (ืกื™ืžืŸ @):

ืขื ืŸ ืœืžื˜ืจื•ืช ืฆื“ืงื”: ืžื“ืจื™ืš ื”ื’ื™ืจื”
ืจืฉื•ืžืช A ืขื‘ื•ืจ ืชืช-ื“ื•ืžื™ื™ื ื™ื ืžื•ื’ื“ืจืช ื‘ื“ืจืš ื›ืœืœ ื›ืš:

ืขื ืŸ ืœืžื˜ืจื•ืช ืฆื“ืงื”: ืžื“ืจื™ืš ื”ื’ื™ืจื”
ื›ืชื•ื‘ืช ื”-IP ื”ื™ื ื”ื›ืชื•ื‘ืช ืฉืœ ืฉืจืช ืœื™ื ื•ืงืก ืฉื™ืฆืจื ื• ื–ื” ืขืชื”. ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ TTL = 3600.

ืœืื—ืจ ื–ืžืŸ ืžื”, ื ื™ืชืŸ ื™ื”ื™ื” ืœื‘ืงืจ ื‘ืืชืจ ืฉืœืš, ืืš ืœืขืช ืขืชื” ืจืง ื“ืจืš http://. ื‘ืฉืœื‘ ื”ื‘ื ื ื•ืกื™ืฃ ืชืžื™ื›ื” https://.

ืฉืœื‘ 4: ื”ื’ื“ืจ ืื™ืฉื•ืจื™ SSL ื‘ื—ื™ื ื

ืืชื” ื™ื›ื•ืœ ืœืงื‘ืœ ื‘ื—ื™ื ื ืชืขื•ื“ื•ืช SSL ืฉืœ Let's Encrypt ืขื‘ื•ืจ ื”ืืชืจ ื”ืจืืฉื™ ืฉืœืš ื•ื›ืœ ืชืช-ื”ื“ื•ืžื™ื™ื ื™ื. ืืชื” ื™ื›ื•ืœ ื’ื ืœื”ื’ื“ื™ืจ ืืช ื”ื—ื™ื“ื•ืฉ ื”ืื•ื˜ื•ืžื˜ื™ ืฉืœื”ื, ื•ื–ื” ืžืื•ื“ ื ื•ื—. ื›ื“ื™ ืœืงื‘ืœ ืื™ืฉื•ืจื™ SSL, ื”ืชืงืŸ ืืช Certbot ื‘ืฉืจืช ืฉืœืš:

$ sudo add-apt-repository ppa:certbot/certbot

ื”ืชืงืŸ ืืช ื—ื‘ื™ืœืช Certbot ืขื‘ื•ืจ Apache ื‘ืืžืฆืขื•ืช apt:

$ sudo apt install python-certbot-apache 

ื›ืขืช Certbot ืžื•ื›ืŸ ืœืฉื™ืžื•ืฉ, ื”ืคืขืœ ืืช ื”ืคืงื•ื“ื”:

$ sudo certbot --apache -d a-dobra.ru -d www.a-dobra.ru -d promo.a-dobra.ru

ืคืงื•ื“ื” ื–ื• ืžืจื™ืฅ ืืช certbot, keys -d ืœื”ื’ื“ื™ืจ ืืช ืฉืžื•ืช ื”ื“ื•ืžื™ื™ื ื™ื ืฉืขื‘ื•ืจื ื™ืฉ ืœื”ื ืคื™ืง ืืช ื”ืื™ืฉื•ืจ.

ืื ื–ื• ื”ืคืขื ื”ืจืืฉื•ื ื” ืฉืืชื” ืžืคืขื™ืœ ืืช certbot, ืชืชื‘ืงืฉ ืœื”ื–ื™ืŸ ืืช ื›ืชื•ื‘ืช ื”ื“ื•ื"ืœ ืฉืœืš ื•ืœื”ืกื›ื™ื ืœืชื ืื™ ื”ืฉื™ืžื•ืฉ ื‘ืฉื™ืจื•ืช. ืœืื—ืจ ืžื›ืŸ, certbot ื™ื™ืฆื•ืจ ืงืฉืจ ืขื ืฉืจืช Let's Encrypt ื•ืœืื—ืจ ืžื›ืŸ ื™ื•ื•ื“ื ืฉืืชื” ื‘ืืžืช ืฉื•ืœื˜ ื‘ื“ื•ืžื™ื™ืŸ ืฉืขื‘ื•ืจื• ื‘ื™ืงืฉืช ืืช ื”ืื™ืฉื•ืจ.

ืื ื”ื›ืœ ื”ืœืš ื›ืฉื•ืจื”, certbot ื™ืฉืืœ ืื™ืš ืืชื” ืจื•ืฆื” ืœื”ื’ื“ื™ืจ ืืช ืชืฆื•ืจืช ื”-HTTPS:

Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: No redirect - Make no further changes to the webserver configuration.
2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for
new sites, or if you're confident your site works on HTTPS. You can undo this
change by editing your web server's configuration.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel):

ืื ื• ืžืžืœื™ืฆื™ื ืœื‘ื—ื•ืจ ื‘ืืคืฉืจื•ืช 2 ื•ืœืœื—ื•ืฅ ืขืœ ENTER. ื”ืชืฆื•ืจื” ืชืขื•ื“ื›ืŸ ื•- Apache ื™ื•ืคืขืœ ืžื—ื“ืฉ ื›ื“ื™ ืœื”ื—ื™ืœ ืืช ื”ืฉื™ื ื•ื™ื™ื.

ื›ืขืช ื”ืื™ืฉื•ืจื™ื ืฉืœืš ืžื•ืจื™ื“ื™ื, ืžื•ืชืงื ื™ื ื•ืคื•ืขืœื™ื. ื ืกื” ืœื˜ืขื•ืŸ ืžื—ื“ืฉ ืืช ื”ืืชืจ ืฉืœืš ืขื https:// ื•ืชืจืื” ืืช ืกืžืœ ื”ืื‘ื˜ื—ื” ื‘ื“ืคื“ืคืŸ ืฉืœืš. ืื ืืชื” ื‘ื•ื“ืง ืืช ื”ืฉืจืช ืฉืœืš ืžื‘ื—ืŸ ืฉืจืช SSL Labs, ื”ื•ื ื™ืงื‘ืœ ืฆื™ื•ืŸ ื'.

ืชืขื•ื“ื•ืช Let's Encrypt ืชืงืคื•ืช ืœ-90 ื™ื•ื ื‘ืœื‘ื“, ืืš ื—ื‘ื™ืœืช ื”-certbot ืฉื”ืชืงื ื• ื–ื” ืขืชื” ืชื—ื“ืฉ ืืช ื”ืื™ืฉื•ืจื™ื ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™. ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ืชื”ืœื™ืš ื”ืขื“ื›ื•ืŸ, ืื ื• ื™ื›ื•ืœื™ื ืœื‘ืฆืข ืจื™ืฆื” ื™ื‘ืฉื” ืฉืœ certbot:

$ sudo certbot renew --dry-run 

ืื ืื™ื ืš ืจื•ืื” ืฉื’ื™ืื•ืช ื›ืชื•ืฆืื” ืžื”ืคืขืœืช ืคืงื•ื“ื” ื–ื•, ืื– ื”ื›ืœ ืขื•ื‘ื“!

ืฉืœื‘ 5: ื’ืฉ ืœ-MySQL ื•-phpMyAdmin

ืืชืจื™ ืื™ื ื˜ืจื ื˜ ืจื‘ื™ื ืžืฉืชืžืฉื™ื ื‘ืžืื’ืจื™ ืžื™ื“ืข. ื”ื›ืœื™ phpMyAdmin ืœื ื™ื”ื•ืœ ืžืกื“ื™ ื ืชื•ื ื™ื ื›ื‘ืจ ืžื•ืชืงืŸ ื‘ืฉืจืช ืฉืœื ื•. ื›ื“ื™ ืœื’ืฉืช ืืœื™ื•, ืขื‘ื•ืจ ืืœ ื”ื“ืคื“ืคืŸ ืฉืœืš ื‘ืืžืฆืขื•ืช ืงื™ืฉื•ืจ ื›ืžื•:

https://<ip-ะฐะดั€ะตั ัะตั€ะฒะตั€ะฐ>:9997

ืืช ื”ืกื™ืกืžื” ืœื’ื™ืฉื” ืœืฉื•ืจืฉ ื ื™ืชืŸ ืœืงื‘ืœ ื‘ื—ืฉื‘ื•ืŸ ื”ืื™ืฉื™ ืฉืœืš ื‘-MCS (https://mcs.mail.ru/app/services/marketplace/apps/). ืืœ ืชืฉื›ื— ืœืฉื ื•ืช ืืช ืกื™ืกืžืช ื”ืฉื•ืจืฉ ืฉืœืš ื‘ืคืขื ื”ืจืืฉื•ื ื” ืฉืืชื” ืžืชื—ื‘ืจ!

ืฉืœื‘ 6: ื”ื’ื“ืจ ื”ืขืœืืช ืงื‘ืฆื™ื ื‘ืืžืฆืขื•ืช SFTP

ืœืžืคืชื—ื™ื ื™ื”ื™ื” ื ื•ื— ืœื”ืขืœื•ืช ืงื‘ืฆื™ื ืœืืชืจ ืฉืœืš ื‘ืืžืฆืขื•ืช SFTP. ืœืฉื ื›ืš, ื ื™ืฆื•ืจ ืžืฉืชืžืฉ ื—ื“ืฉ, ืงืจื ืœื• ืžื ื”ืœ ื”ืืชืจ:

$ sudo adduser webmaster

ื”ืžืขืจื›ืช ืชื‘ืงืฉ ืžืžืš ืœื”ื’ื“ื™ืจ ืกื™ืกืžื” ื•ืœื”ื–ื™ืŸ ื›ืžื” ื ืชื•ื ื™ื ืื—ืจื™ื.

ืฉื™ื ื•ื™ ื”ื‘ืขืœื™ื ืฉืœ ื”ืกืคืจื™ื™ื” ืขื ื”ืืชืจ ืฉืœืš:

$ sudo chown -R webmaster:webmaster /var/www/a-dobra.ru/public_html

ื›ืขืช ื ืฉื ื” ืืช ืชืฆื•ืจืช SSH ื›ืš ืฉืœืžืฉืชืžืฉ ื”ื—ื“ืฉ ืชื”ื™ื” ื’ื™ืฉื” ืจืง ืœ-SFTP ื•ืœื ืœืžืกื•ืฃ SSH:

$ sudo nano /etc/ssh/sshd_config

ื’ืœื•ืœ ืขื“ ื”ืกื•ืฃ ืฉืœ ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ื•ื”ื•ืกืฃ ืืช ื”ื‘ืœื•ืง ื”ื‘ื:

Match User webmaster
ForceCommand internal-sftp
PasswordAuthentication yes
ChrootDirectory /var/www/a-dobra.ru
PermitTunnel no
AllowAgentForwarding no
AllowTcpForwarding no
X11Forwarding no

ืฉืžื•ืจ ืืช ื”ืงื•ื‘ืฅ ื•ื”ืคืขืœ ืžื—ื“ืฉ ืืช ื”ืฉื™ืจื•ืช:

$ sudo systemctl restart sshd

ืขื›ืฉื™ื• ืืชื” ื™ื›ื•ืœ ืœื”ืชื—ื‘ืจ ืœืฉืจืช ื“ืจืš ื›ืœ ืœืงื•ื— SFTP, ืœืžืฉืœ, ื“ืจืš FileZilla.

ืกืš ื”ื›ืœ

  1. ืขื›ืฉื™ื• ืืชื” ื™ื•ื“ืข ืื™ืš ืœื™ืฆื•ืจ ืกืคืจื™ื•ืช ื—ื“ืฉื•ืช ื•ืœื”ื’ื“ื™ืจ ืžืืจื—ื™ื ื•ื™ืจื˜ื•ืืœื™ื™ื ืขื‘ื•ืจ ืืชืจื™ ื”ืื™ื ื˜ืจื ื˜ ืฉืœืš ื‘ืื•ืชื• ืฉืจืช.
  2. ืืชื” ื™ื›ื•ืœ ื‘ืงืœื•ืช ืœื™ืฆื•ืจ ืืช ืื™ืฉื•ืจื™ ื”-SSL ื”ื“ืจื•ืฉื™ื - ื–ื” ื‘ื—ื™ื ื, ื•ื”ื ื™ืชืขื“ื›ื ื• ืื•ื˜ื•ืžื˜ื™ืช.
  3. ืืชื” ื™ื›ื•ืœ ืœืขื‘ื•ื“ ื‘ื ื•ื—ื•ืช ืขื ืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ MySQL ื“ืจืš ื”-phpMyAdmin ื”ืžื•ื›ืจ.
  4. ื™ืฆื™ืจืช ื—ืฉื‘ื•ื ื•ืช SFTP ื—ื“ืฉื™ื ื•ื”ื’ื“ืจืช ื–ื›ื•ื™ื•ืช ื’ื™ืฉื” ืื™ื ื ื“ื•ืจืฉื™ื ืžืืžืฅ ืจื‘. ื ื™ืชืŸ ืœื”ืขื‘ื™ืจ ื—ืฉื‘ื•ื ื•ืช ื›ืืœื” ืœืžืคืชื—ื™ ืื™ื ื˜ืจื ื˜ ื•ืžื ื”ืœื™ ืืชืจื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™.
  5. ืืœ ืชืฉื›ื— ืœืขื“ื›ืŸ ืืช ื”ืžืขืจื›ืช ืžืขืช ืœืขืช, ื•ืื ื• ืžืžืœื™ืฆื™ื ื’ื ืœื‘ืฆืข ื’ื™ื‘ื•ื™ื™ื - ื‘-MCS ืืชื” ื™ื›ื•ืœ ืœืฆืœื "ืชืžื•ื ื•ืช" ืฉืœ ื›ืœ ื”ืžืขืจื›ืช ื‘ืœื—ื™ืฆื” ืื—ืช, ื•ืœืื—ืจ ืžื›ืŸ, ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืœื”ืคืขื™ืœ ืชืžื•ื ื•ืช ืฉืœืžื•ืช.

ืžืฉืื‘ื™ื ืžืฉื•ืžืฉื™ื ืฉืขืฉื•ื™ื™ื ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ื™ื:

https://www.digitalocean.com/community/tutorials/apache-ubuntu-14-04-lts-ru
https://www.digitalocean.com/community/tutorials/apache-let-s-encrypt-ubuntu-18-04-ru
https://www.digitalocean.com/community/tutorials/how-to-enable-sftp-without-shell-access-on-ubuntu-18-04

ืื’ื‘, ื›ืืŸ ืืชื” ื™ื›ื•ืœ ืœืงืจื•ื ื‘-VC ื›ื™ืฆื“ ื”ืงืจืŸ ืฉืœื ื• ืคืจืกื” ืคืœื˜ืคื•ืจืžื” ืœื—ื™ื ื•ืš ืžืงื•ื•ืŸ ืœื™ืชื•ืžื™ื ื”ืžื‘ื•ืกืกืช ืขืœ ืขื ืŸ MCS.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”