title: 阿里云香港轻量应用服务器使用记录 tags: [] id: '1997' categories:
sudo docker-compose up -d
version: '3'
services:
app:
image: 'jc21/nginx-proxy-manager:latest'
restart: unless-stopped
ports:
- '80:80'
- '81:81'
- '443:443'
volumes:
- ./data:/data
- ./letsencrypt:/etc/letsencrypt
控制台防火墙开放81端口
登录到 http://ip:81
Email: admin@example.com
Password: changeme
sudo ip addr show docker0
反代 Nginx Proxy Manager
控制台防火墙开关闭81端口
[Unit]
Description=/etc/rc.local Compatibility
ConditionPathExists=/etc/rc.local
[Service]
Type=forking
ExecStart=/etc/rc.local start
TimeoutSec=0
StandardOutput=tty
RemainAfterExit=yes
SysVStartPriority=99
cat /tmp/added_script.log
#!/bin/sh -e
## rc.local
#start script
#end script
echo "added sucessfully!" > /tmp/added_script.log
exit 0
#!/bin/bash
/usr/sbin/iptables -F
/usr/sbin/ip6tables -F
/usr/sbin/iptables -I INPUT -s 140.205.201.0/28 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.201.16/29 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.201.32/28 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.225.192/29 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.225.200/30 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.225.184/29 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.225.183/32 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.225.206/32 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.225.205/32 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.225.195/32 -j DROP
/usr/sbin/iptables -I INPUT -s 140.205.225.204/32 -j DROP
/usr/sbin/iptables -A INPUT -i lo -j ACCEPT
/usr/sbin/iptables -A OUTPUT -o lo -j ACCEPT
/usr/sbin/ip6tables -A INPUT -i lo -j ACCEPT
/usr/sbin/ip6tables -A OUTPUT -o lo -j ACCEPT
/usr/sbin/iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
/usr/sbin/iptables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
/usr/sbin/ip6tables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
/usr/sbin/ip6tables -A OUTPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
/usr/sbin/iptables -A INPUT -p tcp ! --dport 22 -j DROP
/usr/sbin/ip6tables -A INPUT -p tcp ! --dport 22 -j DROP
/usr/sbin/iptables -I INPUT -s 172.16.0.0/12 -j ACCEPT
/usr/sbin/iptables -I OUTPUT -s 172.16.0.0/12 -j ACCEPT
/usr/sbin/iptables -I INPUT -p tcp -m multiport --dports 80,443,8024 -j ACCEPT
/usr/sbin/iptables -I INPUT -p udp --dport 6000:6002 -j ACCEPT
/usr/sbin/iptables -I INPUT -p tcp --dport 21000:22000 -j ACCEPT