4762 字
24 分钟
Linux基础(6):Linux软件包管理体系详解

[!NOTE] 运维核心技能导读 软件包管理是Linux系统运维的核心技能之一。与Windows系统不同,Linux提供了多种软件安装方式,每种方式都有其独特的原理、优缺点和适用场景。本文将基于经典模型,详细讲解yum/apt、rpm/dpkg、二进制安装和编译安装四种主流方式,涵盖Ubuntu、CentOS 9 Stream、银河麒麟等主流发行版。

一、yum/apt方式:自动化包管理(★★★★★ 最重要)#

通过网络从官方或第三方软件仓库下载预编译好的软件包及其所有依赖包,自动完成安装、配置和升级过程。

你只需要告诉系统你想吃什么(软件名),系统会自动帮你下单(下载)、配送(安装),连餐具(依赖包)都一起给你送来,全程无需操心。 ::

1.1 RHEL系:DNF/YUM 命令详解与源管理#

CentOS 9 Stream、openEuler等RHEL系发行版已全面使用 DNF 作为默认包管理器,yum 是向下兼容的软链接。

1.1.1 常用DNF/YUM 命令#

RHEL系常用包管理命令
# 安装软件(最常用,-y表示自动确认所有提示)
dnf install nginx -y
# 卸载软件
dnf remove nginx -y
# 更新所有已安装的软件
dnf update -y
# 查看某个文件属于哪个软件包
dnf provides /etc/nginx/nginx.conf
# 清理并生成新的缓存
dnf clean all
dnf makecache

1.1.2 DNF源配置详解#

DNF的源配置文件存储在 /etc/yum.repos.d/ 目录,默认文件通常为 redhat.repo 或 CentOS-Base.repo。当默认源速度慢或无法访问时,可切换至国内镜像源加速。

国内常用DNF镜像源对比表:

镜像源URL示例特点推荐度
阿里云https://mirrors.aliyun.com/centos/速度快,文档全★★★★★
清华大学https://mirrors.tuna.tsinghua.edu.cn/centos/带宽充足,学术背书★★★★★
网易https://mirrors.163.com/centos/老牌厂商,稳定性好★★★★
搜狐https://mirrors.sohu.com/centos/国内CDN加速★★★

完整DNF源替换步骤:

备份原始源配置
# 1. 备份原始源文件(安全第一!)
sudo mkdir -p /etc/yum.repos.d/backup
sudo cp /etc/yum.repos.d/redhat.repo /etc/yum.repos.d/backup/redhat.repo.bak
# 2. 清空原有源配置
sudo rm -f /etc/yum.repos.d/*.repo
切换至阿里云镜像源
# 获取系统发行版信息(本例为CentOS 9 Stream)
DISTVER=$(cat /etc/os-release | grep VERSION_ID | cut -d'=' -f2 | tr -d '"')
# 创建新的源配置文件
sudo tee /etc/yum.repos.d/aliyun.repo > /dev/null << 'EOF'
[BaseOS]
name=CentOS Stream $releasever - BaseOS
baseurl=https://mirrors.aliyun.com/centos-stream/$releasever/BaseOS/$basearch/os/
enabled=1
gpgcheck=1
gpgkey=https://mirrors.aliyun.com/centos/RPM-GPG-KEY-centosofficial
[AppStream]
name=CentOS Stream $releasever - AppStream
baseurl=https://mirrors.aliyun.com/centos-stream/$releasever/AppStream/$basearch/os/
enabled=1
gpgcheck=1
gpgkey=https://mirrors.aliyun.com/centos/RPM-GPG-KEY-centosofficial
[Extras]
name=CentOS Stream $releasever - Extras
baseurl=https://mirrors.aliyun.com/centos-stream/$releasever/extras/$basearch/os/
enabled=1
gpgcheck=1
gpgkey=https://mirrors.aliyun.com/centos/RPM-GPG-KEY-centosofficial
EOF
# 3. 刷新缓存并验证
sudo dnf clean all
sudo dnf makecache
sudo dnf repolist # 验证源配置是否正确加载
  • 办公网/校园网:优先选用清华/网易源,避免国际链路拥堵
  • 云服务器:同地域源速度最快(阿里云ECS建议用官方源)
  • 内网环境:应搭建本地Nexus私有源,所有服务器指向内网地址 ::

1.2 Debian系:APT 命令详解与源管理#

Ubuntu、Debian等发行版使用 APT 作为默认包管理器,提供了更友好的交互界面。

1.2.1 常用APT 命令#

Debian系常用包管理命令
# 更新软件源索引(大坑警告:安装前必须执行!)
apt update
# 安装软件
apt install nginx -y
# 卸载软件并删除配置文件(纯净卸载)
apt purge nginx -y
# 搜索软件包
apt search nginx
# 列出所有已安装的软件包
apt list --installed
# 列出可升级的软件
apt list --upgradable
# 升级已安装的软件包
apt upgrade -y

1.2.2 APT源配置详解#

APT的源配置分为两类文件:

  • 主配置文件:/etc/apt/sources.list(系统源)
  • 自定义源目录:/etc/apt/sources.list.d/(第三方源,推荐使用)

Ubuntu常见LTS版本对应名称:

Ubuntu 20.04 LTS → focal
Ubuntu 22.04 LTS → jammy
Ubuntu 24.04 LTS → noble
Debian 11 (Bullseye) → bullseye
Debian 12 (Bookworm) → bookworm

国内常用APT镜像源对比表:

镜像源URL示例Ubuntu支持版本推荐度
阿里云https://mirrors.aliyun.com/ubuntu/全版本★★★★★
清华大学https://mirrors.tuna.tsinghua.edu.cn/ubuntu/全版本★★★★★
网易163http://mirrors.163.com/ubuntu/全版本★★★★
腾讯云https://mirrors.tencent.com/ubuntu/全版本★★★★

完整APT源替换步骤(以Ubuntu 22.04 + 阿里云为例):

APT源完整替换
# 1. 备份原始source list
sudo cp /etc/apt/sources.list /etc/apt/sources.list.bak
# 2. 获取Ubuntu版本代号
UBUNTU_VERSION=$(lsb_release -cs)
echo "检测到系统版本代号:$UBUNTU_VERSION"
# 3. 清空并重新配置sources.list
sudo tee /etc/apt/sources.list > /dev/null << EOF
# 阿里云官方源
deb https://mirrors.aliyun.com/ubuntu/ $UBUNTU_VERSION main restricted universe multiverse
deb-src https://mirrors.aliyun.com/ubuntu/ $UBUNTU_VERSION main restricted universe multiverse
# Ubuntu更新源
deb https://mirrors.aliyun.com/ubuntu/ ${UBUNTU_VERSION}-updates main restricted universe multiverse
deb-src https://mirrors.aliyun.com/ubuntu/ ${UBUNTU_VERSION}-updates main restricted universe multiverse
# Ubuntu安全更新源
deb https://mirrors.aliyun.com/ubuntu/ ${UBUNTU_VERSION}-security main restricted universe multiverse
deb-src https://mirrors.aliyun.com/ubuntu/ ${UBUNTU_VERSION}-security main restricted universe multiverse
# Ubuntu回溯源(仅保留latest)
deb https://mirrors.aliyun.com/ubuntu/ ${UBUNTU_VERSION}-backports main restricted universe multiverse
deb-src https://mirrors.aliyun.com/ubuntu/ ${UBUNTU_VERSION}-backports main restricted universe multiverse
EOF
# 4. 刷新缓存并验证
sudo apt clean
sudo apt update
sudo apt list --upgradable # 查看可升级包列表
  • sources.list 与 sources.list.d 冲突:sources.list.d中的源会覆盖sources.list,建议统一管理
  • PPA(Personal Package Archive)污染:第三方PPA更新频繁易拉低系统稳定性,生产环境谨慎添加
  • HTTPS vs HTTP:阿里云支持HTTPS,建议使用HTTPS避免中间人攻击 ::

二、rpm/dpkg方式:底层包管理(★★★ 重要)#

手动下载单个软件包文件(.rpm或.deb格式),使用系统底层工具进行安装。

这种方式不会自动解决依赖关系。如果你安装的A包依赖B包,系统会报错退出,你必须自己先去找到并安装B包。这在复杂软件极易陷入依赖链死循环。 ::

2.1 RHEL系:RPM 操作详解#

RPM是Red Hat Package Manager的缩写,RPM文件的命名规范为:

软件包名-版本号-发行号.架构.rpm
例如:nginx-1.20.1-13.el9.x86_64.rpm

2.1.1 RPM核心参数速查表#

rpm参数详解速查表
# ======================== RPM参数完整对照表 ========================
# 【安装相关参数】
-i # --install 安装新软件包
-U # --upgrade 升级软件包(已安装则升级,未安装则安装)
-F # --freshen 更新软件包(仅更新已安装的包,未安装则忽略)
-v # --verbose 显示详细信息
-h # --hash 以#显示安装进度条(通常与-i、-U、-F搭配)
--force # 强制安装,忽略冲突警告
# 【卸载相关参数】
-e # --erase 卸载指定软件包
--nodeps # 忽略依赖关系,强制卸载
# 【查询相关参数】
-q # --query 查询已安装的软件包
-a # --all 查询所有已安装包(与-q搭配)
-i # --info 显示软件包信息
-l # --list 列出软件包包含的所有文件
-f # --file 查询指定文件属于哪个包(必须写全路径)
-c # --configfiles 列出软件包的所有配置文件
-d # --docfiles 列出软件包的所有文档文件
-R # --requires 查看软件包的依赖关系
--changelog 显示软件包变更日志
# 【校验相关参数】
-V # --verify 验证软件包文件完整性
--check-signature 校验软件包数字签名

2.1.2 RPM增删改查操作实战#

【增】安装软件包:

RPM安装操作详解
# 最基础安装(显示进度条,显示详细信息)
rpm -ivh nginx-1.20.1-13.el9.x86_64.rpm
# 升级安装(如果已安装则升级,否则安装)
rpm -Uvh nginx-1.22.0-15.el9.x86_64.rpm
# 强制安装(忽略文件冲突和依赖警告,危险操作!)
rpm -ivh --force --nodeps nginx-1.20.1-13.el9.x86_64.rpm
# 只更新已安装的包(新包若未安装则不处理)
rpm -Fvh nginx-1.22.0-15.el9.x86_64.rpm

【删】卸载软件包:

RPM卸载操作详解
# 标准卸载(保留配置文件)
rpm -e nginx
# 强制卸载(忽略依赖关系)
rpm -e --nodeps nginx
# 卸载并删除所有相关文件(危险操作,可能破坏系统)
rpm -e --allmatches nginx

【改】升级/降级软件包:

RPM升级/降级操作
# 升级到新版本(推荐方式)
rpm -Uvh nginx-1.22.0-15.el9.x86_64.rpm
# 降级到旧版本(需要手动下载旧包)
rpm -Uvh --oldpackage nginx-1.20.1-13.el9.x86_64.rpm

【查】查询软件包信息:

RPM查询操作详解
# 查询所有已安装的软件包
rpm -qa | grep nginx
# 查看某个包的详细信息(需指定完整包名)
rpm -qi nginx-1.20.1-13.el9.x86_64
# 查看软件包安装了哪些文件(必须用完整包名或-a配合管道)
rpm -ql nginx | head -20
# 重点!查询某个文件属于哪个包(必须写绝对路径)
rpm -qf /etc/nginx/nginx.conf
rpm -qf /usr/sbin/nginx
# 查看软件包的依赖关系
rpm -qR nginx
# 查看软件包的配置文件清单
rpm -qc nginx
# 列出软件包变更日志
rpm -q --changelog nginx | head -20
# 校验软件包的数字签名
rpm -K nginx-1.20.1-13.el9.x86_64.rpm

2.2 Debian系:DPKG 操作详解#

DPKG是Debian Package Manager的缩写。DPKG文件的命名规范为:

软件包名_版本号-修订号_架构.deb
例如:nginx_1.18.0-0ubuntu1_amd64.deb

2.2.1 DPKG核心参数速查表#

dpkg参数详解速查表
# ======================== DPKG参数完整对照表 ========================
# 【安装相关参数】
-i # --install 安装软件包
-R # --recursive 递归安装目录中的所有.deb文件
# 【卸载相关参数】
-r # --remove 卸载包(保留配置文件)
-P # --purge 卸载包(删除配置文件,彻底清除)
--force-all 强制执行(可能破坏系统,危险)
# 【查询相关参数】
-l # --list 列出已安装的包
-L # --listfiles 列出某个包包含的所有文件
-s # --status 查询某个包的状态
-S # --search 查询文件属于哪个包
-p # --print-avail 显示未安装包的可用信息
# 【校验相关参数】
-C # --audit 找出系统中已损坏的包
--verify 校验包的完整性
# 【管理参数】
--configure 重新配置已安装的包
--contents 查看包内容
--info 显示包的详细信息

2.2.2 DPKG增删改查操作实战#

【增】安装软件包:

DPKG安装操作详解
# 标准安装单个deb包
dpkg -i nginx_1.18.0-0ubuntu1_amd64.deb
# 递归安装目录中所有deb文件(批量安装)
dpkg -R -i /path/to/deb/directory/

【删】卸载软件包:

DPKG卸载操作详解
# 卸载包但保留配置文件(可快速重装)
dpkg -r nginx
# 彻底卸载包并删除配置文件(一般用这个)
dpkg -P nginx
# 强制卸载(无视依赖警告,危险)
dpkg -r --force-all nginx

【改】重新配置已安装包:

DPKG配置管理
# 重新配置已安装的包(修复损坏配置)
dpkg --configure nginx
# 配置所有未完全配置的包
dpkg --configure -a
# 修复因依赖问题中断的安装
apt install -f

【查】查询软件包信息:

DPKG查询操作详解
# 列出所有已安装的软件包
dpkg -l | grep nginx
# 查询某个包的状态(ii表示已正常安装)
dpkg -s nginx
# 列出某个包安装的所有文件
dpkg -L nginx | head -20
# 重点!查询某个文件属于哪个包(不需要全路径)
dpkg -S /etc/nginx/nginx.conf
dpkg -S nginx.conf
# 显示未安装包的详细信息
dpkg -p nginx
# 查看包内容(不解包)
dpkg --contents nginx_1.18.0-0ubuntu1_amd64.deb | head -20
# 找出系统中已损坏的包
dpkg -C
# 校验包的完整性
dpkg --verify nginx
操作RPM命令DPKG命令
安装rpm -ivh xxx.rpmdpkg -i xxx.deb
卸载(保留配置)rpm -edpkg -r
卸载(删除配置)rpm -edpkg -P
查询文件属于哪个包rpm -qf 文件dpkg -S 文件
查询包含的文件rpm -ql 包名dpkg -L 包名
::

适用场景:没有网络的内网离线环境、安装单体小软件,或是进行 系统崩溃后的底层抢修恢复 工作。


三、二进制安装方式:绿色免安装(★★★★ 重要)#

软件开发商已经将软件编译好并打包成压缩包,用户下载后直接解压即可使用,类似于Windows的”绿色免安装版”。很多知名开源项目如Prometheus都在GitHub上提供二进制包:

prometheus
/
prometheus
Waiting for api.github.com...
00K
0K
0K
Waiting...

3.1 二进制安装基础操作#

3.1.1 实战演示:二进制部署 Prometheus#

一键环境初始化
# 1. 下载二进制包并解压
wget https://github.com/prometheus/prometheus/releases/download/v2.45.0/prometheus-2.45.0.linux-amd64.tar.gz
tar -zxvf prometheus-2.45.0.linux-amd64.tar.gz -C /opt/
# 2. 创建软链接(高阶技巧:方便后期平滑升级配置)
ln -s /opt/prometheus-2.45.0.linux-amd64 /opt/prometheus

为了方便全局调用,我们通常需要注入环境变量。

/etc/profile
# /etc/profile 系统环境变量配置文件
# ... 其他配置项省略 ...
export PATH=$PATH:/opt/prometheus

强烈建议为二进制软件编写 systemd 服务文件接管生命周期管理:

/etc/systemd/system/prometheus.service
[Unit]
Description=Prometheus Monitoring System
After=network.target
[Service]
User=root
ExecStart=/opt/prometheus/prometheus --config.file=/opt/prometheus/prometheus.yml
Restart=on-failure
[Install]
WantedBy=multi-user.target
启动并设置自启
systemctl daemon-reload
systemctl enable --now prometheus

3.2 企业级二进制安装最佳实践#

在实际生产环境中,仅做”解压即用”是不够的。企业运维必须围绕安全性、隔离性、可维护性、可追溯性进行规范化部署。

3.2.1 创建专用用户与权限隔离#

创建应用专用用户
# 1. 创建prometheus专用用户(-s /bin/false 禁止登录,-M 不创建home)
sudo useradd -r -s /bin/false -M prometheus
# 2. 创建程序目录并设置权限
sudo mkdir -p /opt/prometheus-{2.45.0.linux-amd64,data,config,logs}
sudo chown -R prometheus:prometheus /opt/prometheus*
# 3. 为可执行文件赋予执行权限
sudo chmod +x /opt/prometheus-2.45.0.linux-amd64/prometheus
sudo chmod +x /opt/prometheus-2.45.0.linux-amd64/promtool
# 4. 创建软链接并调整权限
sudo ln -s /opt/prometheus-2.45.0.linux-amd64 /opt/prometheus
sudo chown -h prometheus:prometheus /opt/prometheus
  • 禁止root运行业务进程:减小安全风险,一个应用被攻击不会获得系统最高权限
  • -s /bin/false:创建系统用户但禁止登录shell(对于守护进程最安全)
  • -M 不创建home目录:减少不必要的目录污染 ::

3.2.2 标准化目录结构与配置分离#

目录结构规范化部署
# 创建标准的目录结构
sudo mkdir -p /opt/prometheus-2.45.0.linux-amd64 # 二进制程序目录
sudo mkdir -p /data/prometheus/data # 数据存储目录
sudo mkdir -p /data/prometheus/config # 配置文件目录
sudo mkdir -p /var/log/prometheus # 日志目录
sudo mkdir -p /etc/prometheus # 系统级配置(符号链接)
# 配置文件分离示例
sudo cat > /data/prometheus/config/prometheus.yml << 'EOF'
global:
scrape_interval: 15s
evaluation_interval: 15s
external_labels:
cluster: 'prod-cluster'
scrape_configs:
- job_name: 'prometheus'
static_configs:
- targets: ['localhost:9090']
EOF
# 创建符号链接(方便系统级访问)
sudo ln -s /data/prometheus/config/prometheus.yml /etc/prometheus/prometheus.yml
# 调整权限
sudo chown -R prometheus:prometheus /data/prometheus /var/log/prometheus
sudo chmod 750 /data/prometheus/{data,config} /var/log/prometheus

3.2.3 Systemd服务文件规范编写#

/etc/systemd/system/prometheus.service
# Prometheus 生产级systemd服务配置
[Unit]
Description=Prometheus Time Series Database & Monitoring Engine
Documentation=https://prometheus.io/docs/
After=network-online.target
Wants=network-online.target
[Service]
# 用户隔离与安全
User=prometheus
Group=prometheus
ProtectSystem=strict
ProtectHome=yes
NoNewPrivileges=true
# 启动配置(注意:数据目录指向/data而非/opt)
Type=simple
ExecStart=/opt/prometheus/prometheus \
--config.file=/data/prometheus/config/prometheus.yml \
--storage.tsdb.path=/data/prometheus/data \
--web.listen-address=:9090 \
--web.enable-admin-api
# 进程管理
Restart=on-failure
RestartSec=10s
TimeoutStopSec=30s
# 日志输出
StandardOutput=journal
StandardError=journal
SyslogIdentifier=prometheus
[Install]
WantedBy=multi-user.target
服务启动与验证
# 重新加载systemd配置
sudo systemctl daemon-reload
# 启用自启并启动服务
sudo systemctl enable --now prometheus
# 查看服务状态
sudo systemctl status prometheus
# 查看日志(实时跟踪)
sudo journalctl -u prometheus -f

3.2.4 日志轮转与管理#

/etc/logrotate.d/prometheus
# Prometheus日志轮转配置
/var/log/prometheus/*.log {
daily # 每天轮转一次
rotate 14 # 保留14天的日志
compress # 压缩历史日志
missingok # 日志文件不存在不报错
notifempty # 空日志不轮转
create 0640 prometheus prometheus # 新日志权限
sharedscripts
postrotate
/bin/systemctl reload prometheus > /dev/null 2>&1 || true
endscript
}
验证日志轮转配置
# 测试配置是否正确
logrotate -d /etc/logrotate.d/prometheus
# 手动执行一次轮转(强制)
logrotate -f /etc/logrotate.d/prometheus

3.2.5 版本管理与零停机升级#

二进制版本升级标准流程
# 1. 下载新版本
cd /opt
wget https://github.com/prometheus/prometheus/releases/download/v2.46.0/prometheus-2.46.0.linux-amd64.tar.gz
tar -zxvf prometheus-2.46.0.linux-amd64.tar.gz
# 2. 复制配置文件到新版本目录
cp -r /opt/prometheus-2.45.0.linux-amd64/{prometheus.yml,console*} /opt/prometheus-2.46.0.linux-amd64/
# 3. 验证新版本的启动参数(重点!)
/opt/prometheus-2.46.0.linux-amd64/prometheus --version
/opt/prometheus-2.46.0.linux-amd64/promtool check config prometheus.yml
# 4. 更新软链接(原子操作)
ln -snf /opt/prometheus-2.46.0.linux-amd64 /opt/prometheus
# 5. 重启服务
systemctl restart prometheus
# 6. 验证服务状态
systemctl status prometheus
curl http://localhost:9090/-/healthy
# 7. 验证无问题后保留旧版本15天(以便快速回滚)
# 可选:rm -rf /opt/prometheus-2.45.0.linux-amd64

3.2.6 健康检查与监控集成#

健康检查脚本示例
5 collapsed lines
#!/bin/bash
# /usr/local/bin/prometheus-healthcheck.sh
PROMETHEUS_URL="http://localhost:9090"
TIMEOUT=5
# 1. 检查进程是否存在
if ! pgrep -f "[/]opt/prometheus/prometheus" > /dev/null; then
echo "CRITICAL: Prometheus process not found"
exit 2
fi
# 2. 检查HTTP健康端点
HEALTH_RESPONSE=$(curl -s -m $TIMEOUT "${PROMETHEUS_URL}/-/healthy")
if [ $? -ne 0 ]; then
echo "CRITICAL: Failed to connect to Prometheus"
exit 2
fi
# 3. 检查是否处于ready状态
READY_RESPONSE=$(curl -s -m $TIMEOUT "${PROMETHEUS_URL}/-/ready")
if [ "$READY_RESPONSE" != "Prometheus is Ready." ]; then
echo "WARNING: Prometheus not fully ready"
exit 1
fi
echo "OK: Prometheus is healthy"
exit 0
集成到Zabbix/Nagios监控
# 赋予执行权限
chmod +x /usr/local/bin/prometheus-healthcheck.sh
# Nagios配置示例(/etc/nagios/objects/local.cfg)
define service{
use local-service
host_name prometheus-server
service_description Prometheus Health
check_command check_local_mrtg_data!"/usr/local/bin/prometheus-healthcheck.sh"!10!20
check_interval 3
max_check_attempts 3
}

3.2.7 备份与灾难恢复#

备份策略与脚本
8 collapsed lines
#!/bin/bash
# /usr/local/bin/prometheus-backup.sh
BACKUP_DIR="/backup/prometheus"
DATA_DIR="/data/prometheus/data"
CONFIG_DIR="/data/prometheus/config"
KEEP_DAYS=30
mkdir -p $BACKUP_DIR
# 1. 配置文件备份(每天)
tar -czf $BACKUP_DIR/config-$(date +%Y%m%d).tar.gz $CONFIG_DIR
# 2. 数据库快照备份(推荐每周一次,用于大规模集群)
# 利用prometheus的快照API而非直接复制
curl -s http://localhost:9090/api/v1/admin/tsdb/snapshot | jq -r '.data.name'
# 3. 清理30天前的备份
find $BACKUP_DIR -type f -name "config-*.tar.gz" -mtime +$KEEP_DAYS -delete
# 4. 上传到远程存储(S3/OSS/MinIO等)
aws s3 cp $BACKUP_DIR s3://my-backup-bucket/prometheus/ --recursive
echo "Backup completed at $(date)"
恢复流程
# 1. 停止Prometheus服务
systemctl stop prometheus
# 2. 恢复配置文件
tar -xzf /backup/prometheus/config-20240101.tar.gz -C /
# 3. 恢复数据(若配置了快照)
# 恢复所有配置后重启即可(prometheus会自动检测TSDB)
# 4. 启动服务并验证
systemctl start prometheus
curl http://localhost:9090/api/v1/query?query=up

3.2.8 安全加固:防火墙与SELinux#

防火墙配置
# FirewallD配置(RHEL系)
firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="10.0.0.0/8" port protocol="tcp" port="9090" accept'
# 或者UFW配置(Ubuntu系)
ufw allow from 10.0.0.0/8 to any port 9090
# 验证规则
firewall-cmd --list-all
SELinux策略(如必要)
# 为prometheus二进制设置安全上下文
semanage fcontext -a -t admin_home_t "/opt/prometheus(.*)"
semanage fcontext -a -t admin_home_t "/data/prometheus(.*)"
restorecon -R /opt/prometheus /data/prometheus
# 允许prometheus绑定非标准端口
semanage port -a -t http_port_t -p tcp 9090

四、编译安装方式:狂热控制(★★★)#

从软件官方下载源代码,在本地机器上使用编译器转化为可执行文件。

编译时长会吃光服务器CPU资源,大型软件(如MySQL)单次编译可能耗时数十至数小时,且后期升级和卸载极为繁琐。 ::

实战演示:定制化编译安装 Nginx#

编译安装全周期操作
6 collapsed lines
# 1. 安装编译底层依赖
dnf install gcc make pcre-devel zlib-devel openssl-devel -y
# 2. 下载并解压源码
wget https://nginx.org/download/nginx-1.24.0.tar.gz
tar -zxvf nginx-1.24.0.tar.gz && cd nginx-1.24.0
# 3. 核心步骤:编译参数预检与模块定制
./configure \
--prefix=/usr/local/nginx \
--with-http_ssl_module \
--with-http_v2_module
# 4. 释放CPU算力:多线程编译 (-j 指定物理核心数)
make -j 4
# 5. 最终生成注入
make install

五、四种安装方式横向评测对比#

安装流派底层运作逻辑核心优势致命短板黄金适用场景
Yum/Apt自动云端下发,智能解题依赖极简运维,自动追踪CVE补丁过分依赖公网环境,版本守旧90%的日常标准化基建
二进制法解压即得,独立沙箱生态跨平台污染为零,追新速度快运维成本转嫁给人工(Path/Service)云原生组件(K8s/Grafana)
Rpm/Dpkg离线拆包,强制手动布线无网离线秒装,单包轻盈地狱级手动填补依赖链漏洞纯内网防线极简隔离部署
源码编译算力转换代码,掌控全部底层极致性能裁剪,功能模块100%自定义耗费恐怖生命周期(编译/排错/难卸载)特殊模块集成/异构硬件压榨

六、生产环境最佳实践准则#

  1. 能自动绝不手动:yum/apt永远是T0级别的首选,除非存在刚性版本需求。
  2. 内网降维打击:没有外部网络不是用 rpm 受苦的借口,应立即搭建局域网 Nexus/Artifactory 私有仓库,让内网服务器全用上内网 yum/apt。
  3. 软链接版本控制法:手动部署二进制包时,严格采用 真实目录(带版本号) + 快捷方式(指向真实),秒速回滚无痛升级。
  4. 统一命名空间:自建软件严禁东塞西放,强制收容于 /opt (大组件) 或 /usr/local (工具集)。
  5. 系统总线接管:只要是长期驻留的守护进程,必须撰写 Systemd Service 文件注册为系统生命级进程,严禁使用 nohup 或 screen 等野路子长期挂载。
  6. 隐藏配置文件加密:涉及敏感受权的连接凭证要使用 :spoiler[Vault 或环境密钥管理] 注入,防止配置文件裸奔泄漏。 ::
Linux基础(6):Linux软件包管理体系详解
https://www.6ixblog.site/posts/linux-basic-6/
作者
Licwic
发布于
2025-01-07
许可协议
CC BY-NC-SA 4.0