Ukukhishwa kwe-Proxmox VE 6.1, ikhithi yokusabalalisa yokuhlela umsebenzi wamaseva abonakalayo

kwenzeka ukukhululwa I-Proxmox Virtual Environment 6.1, ukusatshalaliswa kwe-Linux okukhethekile okusekelwe ku-Debian GNU/Linux, okuhloswe ngayo ukusebenzisa nokugcina amaseva abonakalayo kusetshenziswa i-LXC ne-KVM futhi kungasebenza njengokumiselela imikhiqizo efana ne-VMware vSphere, i-Microsoft Hyper-V ne-Citrix XenServer. Usayizi wokufaka iso isithombe 776 MB.

I-Proxmox VE ihlinzeka ngezindlela zokusebenzisa isistimu yeseva ye-turnkey, esekelwe kuwebhu, yezinga lezimboni eklanyelwe ukuphatha amakhulu noma izinkulungwane zemishini ebonakalayo. Ukusabalalisa kunamathuluzi akhelwe ngaphakathi okuhlela izipele zezindawo ezibonakalayo kanye nosekelo lokuhlanganisa olutholakala ngaphandle kwebhokisi, okuhlanganisa ikhono lokuthutha izindawo ezibonakalayo ukusuka endaweni eyodwa kuya kwenye ngaphandle kokumisa umsebenzi. Phakathi kwezici zesixhumi esibonakalayo sewebhu: ukusekelwa kwekhonsoli ye-VNC evikelekile; lawula ukufinyelela kuzo zonke izinto ezitholakalayo (i-VM, isitoreji, ama-node, njll.) ngokusekelwe ezindimeni; ukusekelwa kwezindlela ezihlukahlukene zokuqinisekisa (MS ADS, LDAP, Linux PAM, Proxmox VE ubuqiniso).

В udaba olusha:

  • I-database yephakheji ivumelaniswa ne-Debian 10.2. I-Linux kernel ibuyekezelwe enguqulweni engu-5.3. Ukwengeza, i-Linux 5.0 kernel ihlinzekwa ngokusekelwe kumaphakheji avela ku-Ubuntu 19.04 ngokusekelwa kwe-ZFS. Izinguqulo ezibuyekeziwe
    Ceph Nautilus 14.2.4.1, Corosync 3.0, LXC 3.2, QEMU 4.1.1 kanye ne-ZFS 0.8.2;

  • Izinguquko kusixhumi esibonakalayo sewebhu
    • Manje usungahlela imingcele yokumisa yezinga lesikhungo sedatha eyengeziwe nge-GUI, okuhlanganisa izilungiselelo zokuqinisekisa izinto ezimbili kanye nomkhawulo wezinga leqoqo lomkhawulokudonsa wezinhlobo ezilandelayo zethrafikhi: ukufuduka, ukwenza ikhophi/ukubuyisela, ukwenza i-cloning, ukunyakaza kwediski.
    • Ukuthuthukiswa kokuqinisekiswa kwezinto ezimbili ukuze kuvunyelwe ukusetshenziswa kokhiye wehadiwe ye-TOTP.
    • I-GUI yeselula: ukungena ngemvume okufakiwe kwama-akhawunti omsebenzisi anosekelo lokuqinisekisa izici ezimbili ze-TOTP.
    • Umsebenzi oqhubekayo wokuguqula izithonjana zisuke ku-raster ziye kumafomethi e-vectorized zisuka ku-Font Awesome.
    • Imodi yokukala ye-noVNC manje ingashintshwa esigabeni esithi "Izilungiselelo zami".
    • Inkinobho entsha ethi "Run Now" ukuze usebenzise imisebenzi yokwenza isipele yeqoqo elibanzi.
    • Uma ufake ifupdown2, ungakwazi manje ukushintsha ukucushwa kwenethiwekhi futhi uyibuyekeze kusukela ku-GUI, ngaphandle kokuqalisa kabusha.
  • Izinguquko zeziqukathi
    • Kwenziwe izinguquko ezisalindile zeziqukathi. Ungenza izinguquko kusiqukathi esisebenzayo futhi zizosetshenziswa ngesikhathi esilandelayo lapho isiqukathi siqaliswa kabusha.
    • Qalisa kabusha isiqukathi esisebenzayo nge-GUI, i-API kanye nesixhumi esibonakalayo somugqa womyalo (CLI).
    • Izindawo zokukhweza ezishisayo zisebenzisa i-mount API entsha etholakala ku-Linux 5.3 kernel.
    • Isekela ukukhishwa kwakamuva kokusatshalaliswa kwe-GNU/Linux okufana ne-Fedora 31, CentOS 8 kanye ne-Ubuntu 19.10.
  • Izinguquko ku-SPICE
    • Amadivayisi omsindo manje angangezwa nge-GUI (asikho isidingo sokuhlela ifayela lokumisa).
    • Izikhombisi manje zingabiwa phakathi kweklayenti le-SPICE kanye nomshini obonakalayo (lesi sici sisabhekwa njengesilingo).
    • Unganika amandla usekelo lokusakaza ividiyo, okusiza ukuthuthukisa ukusebenza lapho unikezela ngezindawo zokubonisa ezishintsha ngokushesha, njengalapho ubuka ividiyo.
    • Idivayisi ye-SPICE USB manje isekela i-USB3 (QEMU >= 4.1).
  • Ukuthuthukiswa kokwenza isipele nokubuyisela ukusebenza
    • Imishini ebonakalayo enama-IOthreads anikwe amandla kuzilungiselelo zayo manje isingenziwa ikhophi yasenqolobaneni.
    • Kungenzeka ukuqalisa mathupha imisebenzi eyisipele ehleliwe kusuka esikhungweni sedatha kusixhumanisi esibonakalayo.
  • Ukuthuthukiswa kwesitaki se-HA
    • Inqubomgomo entsha yokuvala "thutha". Uma uyinika amandla lapho ucisha, izinsiza ezisebenzayo zizodluliselwa kwenye indawo. Uma i-node ibuya ku-inthanethi, uma izinsiza zingasuswanga mathupha kwenye indawo okwamanje, izinsiza zizobuyiselwa emuva.
    • Umyalo omusha 'i-crm-command stop'. Ivala umshini/isitsha esibonakalayo ngesikhathi sokuvala esishiwo futhi imise kanzima uma isikhathi sokuvala sicaciswe njengokuthi "0". Umyalo wokumisa umshini obonakalayo noma isiqukathi manje uzobiza le crm-command entsha.
  • Ukuthuthukiswa kwe-QEMU
    • Izizinda ngaphandle kokuthi '0000' zivunyelwe ukudlula kwe-PCI(e).
    • Ikholi entsha ye-API "qalisa kabusha". Ikuvumela ukuthi usebenzise izinguquko ezisalindile ngaphandle kokuthi ulinde isivakashi ukuthi sivale ngaphambi kokusiqalisa futhi.
    • Kulungiswe inkinga yokuphela kwesikhathi yokuqapha ye-QEMU evimbe izipele ekuphumeleleni ekucushweni okuthile.
    • I-PCI(e) passthrough isekela amadivayisi afika kwangu-16 PCI(e).
    • Ukusekelwa kwama-QEMU Guest Agents asebenzisa i-ISA serial port (hhayi i-VirtIO) yokuxhumana, leyo, phakathi kwezinye izinto, ezovumela ukusetshenziswa kwama-QEMU Guest Agents ku-FreeBSD.
  • Ukuthuthukiswa okujwayelekile kwezihambeli ezibonakalayo
    • “Omaka” bengeziwe ekucushweni kwesistimu yesivakashi. Lolu lwazi lwe-meta lungaba usizo ezintweni ezifana nokuphathwa kokucushwa (okungakasekelwa ku-GUI).
    • I-VM/CT: I-“Purge” ifunde ukususa umshini ohambelanayo obonakalayo noma isiqukathi emisebenzini yokuphindaphinda noma izipele lapho ibhujiswa.
      • Ukuzinza kweqoqo
        • Amaphutha amaningi akhonjiwe futhi alungiswa enhla nomfula (ngokubambisana ne-corosync ne-kronosnet).
        • Izinkinga ezixazululiwe abanye abasebenzisi ababehlangabezana nazo lapho beshintsha i-MTU.
        • I-pmxcfs ihlolwe kusetshenziswa i-ASAN (AddressSanitizer) kanye ne-UBSAN (Undefined Behavior Sanitizer), okuphumele ekulungisweni kwezinkinga ezihlukahlukene ezingaba khona ezimweni ezithile ezisemaphethelweni.
      • Uhlelo lokugcina
        • Kuvunyelwe ukwenza ngokwezifiso izakhiwo ezingajwayelekile "zendawo yokukhuphuka" ze-ZFS.
        • Ukusetshenziswa kwamafayela we-.img njengenye indlela yezithombe ze-.iso kuvunyelwe.
        • Ukuthuthukiswa okuhlukahlukene kwe-iSCSI.
        • Usekelo lwe-ZFS olusetshenzwe kabusha ku-iSCSI enomhlinzeki oqondiwe we-LIO.
        • Inikeza ukusekelwa kwazo zonke izici ezinikezwa ama-kernels amasha nge-Ceph ne-KRBD.
      • Ukuthuthukiswa okuhlukahlukene
        • I-firewall yengeze ukusekelwa kwamatafula aluhlaza kanye nokusetshenziswa kwawo ukuvikela ekuhlaselweni kwe-Synflood.
        • Kwenziwe ukuvuselela okuzenzakalelayo kwesitifiketi esizisayinele amaviki ama-2 ngaphambi kokuphelelwa yisikhathi.
        • Isikhathi sokufaneleka sezitifiketi ezisanda kukhiqizwa sehlisiwe (iminyaka emi-2 esikhundleni seminyaka eyi-10). Ushintsho lwenziwe ngoba ezinye iziphequluli zesimanje zikhala ngesikhathi eside kakhulu sokufaneleka kwesitifiketi.
      • Ukuhlolwa kobufakazi bezingxenye zemibhalo (isitayela nohlelo lolimi) kwenziwa. Amadokhumenti okuphatha i-Ceph anwetshiwe.
      • Ukulungiswa kwamaphutha okuningi nezibuyekezo zephakheji (bona imininingwane egcwele ku i-bugtracker и Amakhosombe we-GIT).

      Source: opennet.ru

Engeza amazwana