-- ·|­û / µù¥U -- ¡@
¡@±b¸¹¡G
¡@±K½X¡G
¡@ | µù¥U | §Ñ°O±K½X
12/13 ·s®Ñ¨ì¡I 10/8 ·s®Ñ¨ì¡I 10/1 ·s®Ñ¨ì¡I 9/24 ·s®Ñ¨ì¡I
ÁʮѬyµ{¡EQ & A¡E¯¸°È¯d¨¥ª©¡E«ÈªA«H½c
¢x 3ds Max¢x Maya¢x Rhino¢x After Effects¢x SketchUp¢x ZBrush¢x Painter¢x Unity¢x
¢x PhotoShop¢x AutoCad¢x MasterCam¢x SolidWorks¢x Creo¢x UG¢x Revit¢x Nuke¢x
¢x C#¢x C¢x C++¢x Java¢x ¹CÀ¸µ{¦¡¢x Linux¢x ´O¤J¦¡¢x PLC¢x FPGA¢x Matlab¢x
¢x Àb«È¢x ¸ê®Æ®w¢x ·j¯Á¤ÞÀº¢x ¼v¹³³B²z¢x Fluent¢x VR+AR¢x ANSYS¢x ²`«×¾Ç²ß¢x
¢x ³æ´¹¤ù¢x AVR¢x OpenGL¢x Arduino¢x Raspberry Pi¢x ¹q¸ô³]­p¢x Cadence¢x Protel¢x
¢x Hadoop¢x Python¢x Stm32¢x Cortex¢x Labview¢x ¤â¾÷µ{¦¡¢x Android¢x iPhone¢x
¥i¬d®Ñ¦W,§@ªÌ,ISBN,3dwoo®Ñ¸¹
¸Ô²Ó®ÑÄy¤ÀÃþ

¼Æ¦r¤Æ¨t²Î¦w¥þ¥[©T§Þ³N

( ²Åé ¦r)
§@ªÌ¡G¥ÕÔÑÔÑ¡B¥Ð±d¡B§õ³Õ¡B°ª±L®p¡B¦¶±dÃþ§O¡G1. -> ¦w¥þ -> ºô¸ô¦w¥þ -> Àb«È§ðÀ»»P¤J«I
ĶªÌ¡G
¥Xª©ªÀ¡G¤H¥Á¶l¹q¥Xª©ªÀ¼Æ¦r¤Æ¨t²Î¦w¥þ¥[©T§Þ³N 3dWoo®Ñ¸¹¡G 56462
¸ß°Ý®ÑÄy½Ð»¡¥X¦¹®Ñ¸¹¡I

¡i¦³®w¦s¡j
NT°â»ù¡G 300 ¤¸

¥Xª©¤é¡G10/1/2024
­¶¼Æ¡G216
¥úºÐ¼Æ¡G0
¯¸ªø±ÀÂË¡G
¦L¨ê¡G¶Â¥Õ¦L¨ê»y¨t¡G ( ²Åé ª© )
¥[¤JÁʪ«¨® ¢x¥[¨ì§Úªº³Ì·R
(½Ð¥ýµn¤J·|­û)
ISBN¡G9787115628671
§@ªÌ§Ç¡@|¡@ĶªÌ§Ç¡@|¡@«e¨¥¡@|¡@¤º®e²¤¶¡@|¡@¥Ø¿ý¡@|¡@§Ç
(²Åé®Ñ¤W©Ò­z¤§¤U¸ü³sµ²¯Ó®É¶O¥\, ®¤¤£¾A¥Î¦b¥xÆW, ­YŪªÌ»Ý­n½Ð¦Û¦æ¹Á¸Õ, ®¤¤£«OÃÒ)
§@ªÌ§Ç¡G

ĶªÌ§Ç¡G

«e¨¥¡G

¤º®e²¤¶¡G

¦w¥þ¥[©T¬O°t¸m«H®§¨t²Îªº¹Lµ{¡A¥¦¥i¥H­°§C«H®§¨t²Î¦w¥þ­·ÀI¡C¥»®Ñ¨t²Î¤¶²Ð¾Þ§@¨t²Î¡B¼Æ¾Ú®w¡B¤¤¶¡¥ó¡B®e¾¹¥|¤jªO¶ôªº¬ÛÃö¦w¥þ°t¸m¡A³q¹L±j¤Æ½ã¸¹¦w¥þ¡B¥[©TªA°È¡B­×§ï¦w¥þ°t¸m¡BÀu¤Æ³X°Ý±±¨îµ¦²¤¡B¼W¥[¦w¥þ¾÷¨îµ¥¤èªk¡A±q­·ÀI¤ÀªR¡B¥[©T¸Ô±¡¡B¥[©T¨BÆJ3­Óºû«×Á¿¸Ñ¨C±ø¦w¥þ°t¸m¶µ¡A¦³§U¤_ŪªÌ¥R¤À¤F¸Ñ¨C±ø¦w¥þ°t¸m¶µ¼ç¦bªº­·ÀI¤Î¦p¦ó¶i¦æ¥[©T¡A¦}¦b¥\¯à©Ê»P¦w¥þ©Ê¤§¶¡´M¨D¥­¿Å¡A¦X²z¥[±j¦w¥þ©Ê¡C
¥»®Ñ¾A¥Î¤_«ü¾É²£«~¬ãµo¤H­û¬ã¨îÀq»{°t¸m¦w¥þªº²£«~¡A³W­S§Þ³N¤H­û¦b¦UÃþ¨t²Î¤Wªº¤é±`¾Þ§@¡AÅý¹Bºû¤H­ûÀò±oÀˬdÀq»{¦w¥þ­·ÀIªº¼Ð·Ç¡AÁקK¤H¬°¦]¯Àªº¥¢»~±a¨Óªº¦w¥þ­·ÀI¡C
¥Ø¿ý¡G

²Ä 1½g ¾Þ§@¨t²Î¦w¥þ

²Ä 1³¹ Linux 3
1.1 ½ã¸¹¦w¥þ 3
1.1.1 ±±¨î¥iµn¿ý½ã¸¹ 3
1.1.2 ¸T¤îroot¥Î¤áµn¿ý 3
1.1.3 ¸T¥Î«D¬¡°Ê¥Î¤á 4
1.1.4 ½T«Oroot¥Î¤áªºGID¬°0 4
1.1.5 ½T«O¶Èroot¥Î¤áªºUID¬°0 4
1.2 ±K½X¦w¥þ 5
1.2.1 ³]¸m±K½X¥Í¦s´Á 5
1.2.2 ³]¸m±K½X´_Âø«× 5
1.2.3 ½T«O¥[±Kºâªk¬°SHA-512 6
1.2.4 ½T«O/etc/shadow±K½X¦r¬q¤£¬°ªÅ 6
1.3 µn¿ý¡B»{ÃÒųÅv 7
1.3.1 °t¸mSSHªA°È 7
1.3.2 ³]¸mµn¿ý¶W®É®É¶¡ 9
1.3.3 ³]¸m±K½XÂê©wµ¦²¤ 10
1.3.4 ¸T¤î°Î¦W¥Î¤áµn¿ý¨t²Î 10
1.3.5 ¸T¥Î¤£¦w¥þªA°È 10
1.3.6 ¸T¥Î¤£¦w¥þªº«È¤áºÝ 11
1.3.7 °t¸m/etc/crontab¤å¥óÅv­­ 12
1.3.8 ½T«Oµn¿ýĵ§i°t¸m¥¿½T 12
1.4 ¤é§Ó¼f­p 13
1.4.1 °t¸mauditdªA°È 13
1.4.2 °t¸mrsyslogªA°È 15
1.4.3 °t¸mjournaldªA°È 15
1.4.4 °t¸m¤é§Ó¤å¥ó³Ì¤pÅv­­ 16
1.5 ¦w¥þ°t¸m 16
1.5.1 ­­¨î¥i¬d¬Ý¾ú¥v©R¥O±ø¼Æ 16
1.5.2 ½T«O¤é§Ó¤å¥ó¤£·|³Q§R°£ 17
1.5.3 iptables°t¸m 17
1.5.4 °t¸m¨t²Î®É¶¡¦P¨B 18
1.5.5 ­­¨îumask­È 20
1.5.6 ­­¨îsu©R¥Oªº³X°Ý 20
1.5.7 SELinux°t¸m 20
1.5.8 ¨t²Î¤å¥óÅv­­°t¸m 21
1.6 ¦w¥þ±Ò°Ê 22
1.6.1 ³]¸m¤Þ¾É¥[¸üµ{§Ç±K½X 22
1.6.2 °t¸m¤Þ¾É¥[¸üµ{§ÇÅv­­ 23
1.6.3 °t¸m³æ¥Î¤á¼Ò¦¡»Ý­n¨­¥÷ÅçÃÒ 23
1.7 ¦w¥þ½sĶ 23
1.7.1 ­­¨î°ïªäÂàÀx 23
1.7.2 ±Ò¥ÎXD/NX¤ä«ù 24
1.7.3 ±Ò¥Î¦a§}ªÅ¶¡¥¬§½ÀH¾÷¤Æ 24
1.7.4 ¸T¤î¦w¸Ëprelink 25
1.8 ¥D¾÷©M¸ô¥Ñ¾¹¨t²Î°t¸m 25
1.8.1 ¸T¤î±µ¦¬·½¸ô¥Ñ¼Æ¾Ú¥] 25
1.8.2 ¸T¤î¼Æ¾Ú¥]Âàµo 26
1.8.3 Ãö³¬ICMP­«©w¦V 26
1.8.4 Ãö³¬¦w¥þICMP­«©w¦V 27
1.8.5 °O¿ý¥iºÃ¼Æ¾Ú¥] 27
1.8.6 ©¿²¤¼s¼½ICMP½Ð¨D 28
1.8.7 ©¿²¤µê°²ICMPÅTÀ³ 28
1.8.8 ±Ò¥Î¤Ï¦V¸ô®|Âàµo 28
1.8.9 ±Ò¥ÎTCP SYN Cookie 29
1.8.10 ¸T¤î±µ¦¬IPv6¸ô¥Ñ¾¹¼s§i 29

²Ä 2³¹ Windows 30
2.1 ½ã¤á¦w¥þ 30
2.1.1 ¸T¥ÎGuest½ã¤á 30
2.1.2 ¸T¥ÎºÞ²z­û½ã¤á 31
2.1.3 §R°£µL¥Î½ã¤á 31
2.1.4 ¤£Åã¥Ü¤W¦¸µn¿ýªº¥Î¤á¦W 32
2.1.5 ¸T¤îªÅ±K½Xµn¿ý¨t²Î 33
2.1.6 ­«©R¦W¨Ó»«©MºÞ²z­û½ã¤á 33
2.1.7 ½T«O¡§½ã¤áÂê©w®É¶¡¡¨³]¸m¬°¡§15¡¨©Î§ó¤jªº­È 34
2.1.8 ½T«O¡§½ã¤áÂê©wìH­È¡¨³]¸m¬°¡§5¡¨©Î§ó¤pªº­È 34
2.1.9 ½T«O¡§­pºâ¾÷½ã¤áÂê©wìH­È¡¨³]¸m¬°¡§10¡¨©Î§ó¤pªº­È 35
2.1.10 ½T«O¡§­«¸m½ã¤áÂê©w­p¼Æ¾¹¡¨³]¸m¬°¡§15¡¨©Î§ó¤jªº­È 35
2.1.11 ±K½X¹L´Á¤§«e´£¿ô¥Î¤á§ó§ï±K½X 36
2.2 ±K½Xµ¦²¤ 36
2.2.1 ±Ò¥Î±K½X´_Âø«×¬ÛÃöµ¦²¤ 36
2.2.2 ½T«O¡§±j¨î±K½X¾ú¥v¡¨³]¸m¬°¡§24¡¨©Î§ó¤jªº­È 37
2.2.3 ³]¸m±K½X¨Ï¥Î´Á­­ 37
2.2.4 ³]¸m³Ì¤p±K½Xªø«× 38
2.3 »{ÃÒ±ÂÅv 38
2.3.1 ©Úµ´Guest¡B¥»¦a½ã¤á±qºôµ¸³X°Ý¦¹­pºâ¾÷ 38
2.3.2 ©Úµ´Guest¡B¥»¦a½ã¤á³q¹L»·µ{®à­±ªA°Èµn¿ý 39
2.3.3 °t¸m»·µ{±j¨îÃö¾÷Åv­­ 39
2.3.4 ­­¨î¥i¥»¦aÃö¾÷ªº¥Î¤á 40
2.3.5 ±ÂÅv¥iµn¿ýªº½ã¤á 40
2.3.6 ¤À°t¥Î¤áÅv­­ 41
2.3.7 ±±¨î³Æ¥÷¤å¥ó©M¥Ø¿ýÅv­­ 42
2.3.8 ±±¨îÁÙ­ì¤å¥ó©M¥Ø¿ýÅv­­ 42
2.3.9 ±±¨îºÞ²z¼f®Ö©M¦w¥þ¤é§ÓÅv­­ 43
2.3.10 ±±¨î¨­¥÷ÅçÃÒ¦Z¼ÒÀÀ«È¤áºÝÅv­­ 43
2.3.11 ±±¨î©Úµ´¥HªA°È¨­¥÷µn¿ýÅv­­ 44
2.4 ¤é§Ó¼f­p 44
2.4.1 ³]¸m¤é§Ó¦sÀx¤å¥ó¤j¤p 45
2.4.2 °t¸m¼f®Öµ¦²¤ 45
2.5 ¨t²Î°t¸m 46
2.5.1 ³]¸m«Ì¹õ«OÅ@µ{§Ç 46
2.5.2 ¦w¥þµn¿ý 46
2.5.3 ­­¨î°Î¦WªTÁ| 47
2.5.4 ¸T¤î¦sÀxºôµ¸¨­¥÷ÅçÃÒªº±K½X©M¾Ì¾Ú 48
2.5.5 ¨Ï¥ÎDoH 48
2.5.6 ³]¸m°ì¦¨­ûµ¦²¤ 49
2.5.7 ±±¨î±qºôµ¸³X°Ý½s¿èª`¥UªíªºÅv­­ 50
2.5.8 ±±¨î¦@¨É¤å¥ó§¨³X°ÝÅv­­ 51
2.5.9 Ãö³¬Windows¦Û°Ê¼½©ñ¥\¯à 52
2.5.10 ­­¨î¬°¶iµ{½Õ¾ã¤º¦s°tÃBÅv­­¥Î¤á 52
2.5.11 °t¸m­×§ï©T¥óÀô¹Ò­ÈÅv­­ 53
2.5.12 °t¸m¥[¸ü©M¨ø¸ü³]³ÆÅX°Êµ{§ÇÅv­­ 54
2.5.13 °t¸m§ó§ï¨t²Î®É¶¡Åv­­ 54
2.5.14 °t¸m§ó§ï®É°ÏÅv­­ 55
2.5.15 °t¸mÀò¨ú¦P¤@·|¸Ü¤¤¥t¤@­Ó¥Î¤áªº¼ÒÀÀ¥OµPÅv­­ 55
2.5.16 ªý¤î­pºâ¾÷¥[¤J®a®x²Õ 56
2.5.17 ªý¤î¥Î¤á©MÀ³¥Îµ{§Ç³X°Ý¦MÀIºô¯¸ 56
2.5.18 ±½´y©Ò¦³¤U¸ü¤å¥ó©Mªþ¥ó 57
2.5.19 ¶}±Ò¹ê®É«OÅ@ 58
2.5.20 ¶}±Ò¦æ¬°ºÊµø 58
2.5.21 ±½´y¥i²¾°ÊÅX°Ê¾¹ 59
2.5.22 ¶}±Ò¦Û°Ê¤U¸ü©M¦w¸Ë§ó·s 59
2.5.23 ¨¾¤î¶¹LWindows Defender SmartScreen 59
2.6 ºôµ¸¦w¥þ 60
2.6.1 LANºÞ²z¾¹°t¸m 60
2.6.2 ³]¸m°ò¤_NTML SSPªº«È¤áºÝ©MªA°È¾¹ªº³Ì¤p·|¸Ü¦w¥þµ¦²¤ 60
2.6.3 ³]¸mLDAP«È¤áºÝñ¦W 61
2.6.4 µn¿ý®É¶¡¨ì´Á®É±j¨îª`¾P 61
2.6.5 ¸T¤îLocalSystem NULL·|¸Ü¦^°h 61
2.6.6 ¸T¤îPKU2U¨­¥÷ÅçÃҽШD¨Ï¥ÎÁp¾÷¼ÐÃÑ 61
2.6.7 °t¸mKerberos¤¹³\ªº¥[±KÃþ«¬ 62
2.6.8 ¤¹³\¥»¦a¨t²Î±N­pºâ¾÷¼ÐÃѥΤ_NTLM 62
2.7 ¥»¦a¦w¥þµ¦²¤ 63
2.7.1 ³]¸m´£°ª­p¹ºÀu¥ý¯ÅÅv­­ 63
2.7.2 ³]¸m³Ð«Ø²Å¸¹Ãì±µÅv­­ 63
2.7.3 ³]¸m½Õ¸Õµ{§ÇÅv­­ 64
2.7.4 ³]¸m¤å¥ó³æ¤@¶iµ{©M¨t²Î©Ê¯àÅv­­ 64
2.7.5 ³]¸m³Ð«Ø¥Ã¤[¦@¨É¹ï¶HÅv­­ 65
2.7.6 ³]¸m³Ð«Ø¥þ§½¹ï¶HÅv­­ 65
2.7.7 ³]¸m³Ð«Ø¤@­Ó¥OµP¹ï¶HÅv­­ 66
2.7.8 ³]¸m°õ¦æ¨÷ºûÅ@¥ô°ÈÅv­­ 67
2.7.9 ³]¸m©Úµ´§@¬°§å³B²z§@·~µn¿ýÅv­­ 67
2.7.10 ³]¸m´À´«¤@­Ó¶iµ{¯Å¥OµPÅv­­ 68
2.7.11 Microsoftºôµ¸«È¤áºÝ¦w¥þ°t¸m 68
2.7.12 Microsoftºôµ¸ªA°È¾¹¦w¥þ°t¸m 69
2.7.13 ¸T¤î±NEveryoneÅv­­À³¥Î¤_°Î¦W¥Î¤á 70
2.7.14 ¸T¤î³]¸m°Î¦W¥Î¤á¥i¥H³X°Ýªººôµ¸¦@¨É 71
2.7.15 ±±¨îÀ³¥Îµ{§Ç¦w¸Ë 71
2.7.16 ¸T¥ÎsshdªA°È 72
2.7.17 ¸T¥ÎFTPªA°È 72
2.7.18 °t¸m°ª¯Å¼f®Öµ¦²¤ 72
2.7.19 ¸T¤î¦bDNS°ìºôµ¸¤W¦w¸Ë©M°t¸mºô¾ô 74
2.7.20 ¸T¤î¦bDNS°ìºôµ¸¤W¨Ï¥ÎInternet³s±µ¦@¨É 74
2.8 Windows Defender¨¾¤õùÙ 75
2.8.1 ¶}±ÒWindows Defender¨¾¯f¬r¥\¯à 75
2.8.2 ¶}±Ò¨¾¤õùÙ 76
2.8.3 °t¸m¤J¯¸©M¥X¯¸³s±µ 77
2.8.4 °t¸m¤é§Ó¤å¥ó 77


²Ä 2½g ¼Æ¾Ú®w¦w¥þ

²Ä3³¹ MySQL 81
3.1 ±J¥D¾÷¦w¥þ°t¸m 81
3.1.1 ¼Æ¾Ú®w¤u§@¥Ø¿ý©M¼Æ¾Ú¥Ø¿ý¦s©ñ¦b±M¥ÎºÏ½L¤À°Ï 81
3.1.2 ¨Ï¥ÎMySQL±M¥Î½ã¸¹±Ò°Ê¶iµ{ 81
3.1.3 ¸T¥ÎMySQL¾ú¥v©R¥O°O¿ý 82
3.1.4 ¸T¤îMYSQL_PWDªº¨Ï¥Î 82
3.1.5 ¸T¤îMySQL¹B¦æ½ã¸¹µn¿ý¨t²Î 83
3.1.6 ¸T¤îMySQL¨Ï¥ÎÀq»{ºÝ¤f 83
3.2 ³Æ¥÷»P®e¨a 83
3.2.1 ¨î©w¼Æ¾Ú®w³Æ¥÷µ¦²¤ 83
3.2.2 ¨Ï¥Î±M¥Î¦sÀx³]³Æ¦s©ñ³Æ¥÷¼Æ¾Ú 84
3.2.3 ³¡¸p¼Æ¾Ú®wÀ³¦h¥D¦h±q 84
3.3 ½ã¸¹»P±K½X¦w¥þ 84
3.3.1 ³]¸m±K½X¥Í¦s©P´Á 84
3.3.2 ³]¸m±K½X´_Âø«× 85
3.3.3 ½T«O¤£¦s¦bªÅ±K½X½ã¸¹ 86
3.3.4 ½T«O¤£¦s¦bµL¥Î½ã¸¹ 86
3.3.5 ­×§ïÀq»{ºÞ²z­û½ã¸¹¦W¬°«Droot¥Î¤á 86
3.4 ¨­¥÷»{ÃÒ³s±µ»P·|¸Ü¶W®É­­¨î 87
3.4.1 Àˬd¼Æ¾Ú®w¬O§_³]¸m³s±µ¹Á¸Õ¦¸¼Æ 87
3.4.2 Àˬd¬O§_­­¨î³s±µ¦a§}»P³]³Æ 88
3.4.3 ­­¨î³æ­Ó¥Î¤áªº³s±µ¼Æ 88
3.4.4 ½T«Ohave_ssl³]¸m¬°yes 88
3.4.5 ½T«O¨Ï¥Î°ª±j«×¥[±K®M¥ó 89
3.4.6 ½T«O¥[¸Ñ±K¨ç¼Æ°t¸m°ª¯Å¥[±Kºâªk 89
3.4.7 ½T«O¨Ï¥Î·sª©¥»TLS¨óij 89
3.5 ¼Æ¾Ú®w¤å¥ó¥Ø¿ýÅv­­ 90
3.5.1 °t¸m¤å¥ó¤Î¥Ø¿ýÅv­­³Ì¤p¤Æ 90
3.5.2 ³Æ¥÷¼Æ¾ÚÅv­­³Ì¤p¤Æ 90
3.5.3 ¤G¶i¨î¤é§ÓÅv­­³Ì¤p¤Æ 90
3.5.4 ¿ù»~¤é§ÓÅv­­³Ì¤p¤Æ 91
3.5.5 ºC¬d¸ß¤é§ÓÅv­­³Ì¤p¤Æ 91
3.5.6 ¤¤Ä~¤é§ÓÅv­­³Ì¤p¤Æ 91
3.5.7 ­­¨î¤é§ÓÅv­­³Ì¤p¤Æ 91
3.5.8 ´¡¥ó¥Ø¿ýÅv­­³Ì¤p¤Æ 92
3.5.9 ±KÆ_ÃҮѤå¥óÅv­­³Ì¤p¤Æ 92
3.6 ¤é§Ó»P¼f­p 92
3.6.1 °t¸m¿ù»~¤é§Ó 92
3.6.2 ½T«Olog-raw³]¸m¬°off 93
3.6.3 °t¸mlog_error_verbosity 93
3.7 ¥Î¤áÅv­­±±¨î 93
3.7.1 ½T«O¶ÈºÞ²z­û½ã¸¹¥i³X°Ý©Ò¦³¼Æ¾Ú®w 93
3.7.2 ½T«Ofile¤£±Â¤©«DºÞ²z­û½ã¸¹ 94
3.7.3 ½T«Oprocess¤£±Â¤©«DºÞ²z­û½ã¸¹ 94
3.7.4 ½T«Osuper¤£±Â¤©«DºÞ²z­û½ã¸¹ 94
3.7.5 ½T«Oshutdown¤£±Â¤©«DºÞ²z­û½ã¸¹ 95
3.7.6 ½T«Ocreate user¤£±Â¤©«DºÞ²z­û½ã¸¹ 95
3.7.7 ½T«Ogrant option¤£±Â¤©«DºÞ²z­û½ã¸¹ 95
3.7.8 ½T«Oreplication slave¤£±Â¤©«DºÞ²z­û½ã¸¹ 95
3.8 °ò¥»¦w¥þ°t¸m 96
3.8.1 ½T«O¦w¸Ë³Ì·s¸É¤B 96
3.8.2 §R°£Àq»{¦w¸Ëªº´ú¸Õ¼Æ¾Ú®wtest 96
3.8.3 ½T«Oallow-suspicious-udfs°t¸m¬°false 96
3.8.4 local_infile°Ñ¼Æ³]©w 97
3.8.5 skip-grant-tables°Ñ¼Æ³]©w 97
3.8.6 daemon_memcached°Ñ¼Æ³]©w 97
3.8.7 secure_file_priv°Ñ¼Æ³]©w 98
3.8.8 sql_mode°Ñ¼Æ³]©w 98
²Ä4³¹ PostgreSQL 99
4.1 ¥Ø¿ý¤å¥óÅv­­ 99
4.1.1 ½T«O°t¸m¤å¥ó¤Î¥Ø¿ýÅv­­¦X²z 99
4.1.2 ³Æ¥÷¼Æ¾ÚÅv­­³Ì¤p¤Æ 99
4.1.3 ¤é§Ó¤å¥óÅv­­³Ì¤p¤Æ 100
4.2 ¤é§Ó»P¼f­p 100
4.2.1 ½T«O¤w¶}±Ò¤é§Ó°O¿ý 100
4.2.2 ½T«O¤w°t¸m¤é§Ó¥Í©R©P´Á 101
4.2.3 ½T«O¤w°t¸m¤é§ÓÂàÀx¤j¤p 101
4.2.4 ½T«O°t¸m¤é§Ó°O¿ý¤º®e§¹¾ã 101
4.2.5 ½T«O¥¿½T°t¸mlog_destinations 102
4.2.6 ½T«O¤w°t¸mlog_truncate_on_rotation 102
4.2.7 ¥¿½T°t¸msyslog_facility 103
4.2.8 ¥¿½T°t¸msyslog_sequence_numbers 103
4.2.9 ¥¿½T°t¸msyslog_split_messages 103
4.2.10 ¥¿½T°t¸msyslog_ident 103
4.2.11 ¥¿½T°t¸mlog_min_ messages 104
4.2.12 ¥¿½T°t¸mlog_min_error_ statement 104
4.2.13 ½T«O¸T¥Îdebug_print_parse 104
4.2.14 ½T«O¸T¥Îdebug_print_rewritten 104
4.2.15 ½T«O¸T¥Îdebug_print_plan 105
4.2.16 ½T«O±Ò¥Îdebug_pretty_print 105
4.2.17 ½T«O±Ò¥Îlog_connections 105
4.2.18 ½T«O±Ò¥Îlog_disconnections 105
4.2.19 ¥¿½T°t¸mlog_error_verbosity 106
4.2.20 ¥¿½T°t¸mlog_hostname 106
4.2.21 ¥¿½T°t¸mlog_statement 106
4.2.22 ¥¿½T°t¸mlog_timezone 107
4.3 ½ã¸¹»P±K½X¦w¥þ 107
4.3.1 ³]¸m±K½X´_Âø«× 107
4.3.2 ³]¸m±K½X¥Í¦s©P´Á 107
4.4 ¨­¥÷»{ÃÒ³s±µ»P·|¸Ü¶W®É­­¨î 108
4.4.1 Àˬd¼Æ¾Ú®w¬O§_³]¸m³s±µ¹Á¸Õ¦¸¼Æ 108
4.4.2 Àˬd¬O§_­­¨î³s±µ¦a§}»P³]³Æ 108
4.4.3 ­­¨î³æ­Ó¥Î¤áªº³s±µ¼Æ 108
4.4.4 ³]¸mµn¿ý®ÕÅç±K½X 109
4.5 ³Æ¥÷»P®e¨a 109
4.5.1 ¨î©w¼Æ¾Ú®w³Æ¥÷µ¦²¤ 109
4.5.2 ³¡¸p¼Æ¾Ú®wÀ³¦h¥D¦h±q 110
4.6 ¥Î¤áÅv­­±±¨î 110
4.7 ¦w¸Ë©M¤É¯Å¦w¥þ°t¸m 110
4.7.1 ½T«O¦w¸Ë¥]¨Ó·½¥i¾a 110
4.7.2 ½T«O¥¿½T°t¸mªA°È¹B¦æ¯Å§O 110
4.7.3 °t¸m¼Æ¾Ú®w¹B¦æ½ã¸¹¤å¥ó±»½X 111

²Ä5³¹ Redis 112
5.1 ¨­¥÷»{ÃÒ³s±µ 112
5.1.1 ­­¨î«È¤áºÝ»{ÃÒ¶W®É®É¶¡ 112
5.1.2 Àˬd¼Æ¾Ú®w¬O§_³]¸m³s±µ¹Á¸Õ¦¸¼Æ 112
5.1.3 °t¸m½ã¸¹Âê©w®É¶¡ 113
5.2 ½ã¸¹±K½X»{ÃÒ 113
5.3 ¥Ø¿ý¤å¥óÅv­­ 113
5.3.1 ½T«O°t¸m¤å¥ó¤Î¥Ø¿ýÅv­­¦X²z 113
5.3.2 ³Æ¥÷¼Æ¾ÚÅv­­³Ì¤p¤Æ 113
5.3.3 ¤é§Ó¤å¥óÅv­­³Ì¤p¤Æ 114
5.4 ³Æ¥÷»P®e¨a 114
5.4.1 ¨î©w¼Æ¾Ú®w³Æ¥÷µ¦²¤ 114
5.4.2 ³¡¸p¼Æ¾Ú®wÀ³¦h¥D¦h±q 114
5.5 ¦w¸Ë»P¤É¯Å 115
5.5.1 ½T«O¨Ï¥Î³Ì·s¦w¸Ë¸É¤B 115
5.5.2 ¨Ï¥ÎRedis±M¥Î½ã¸¹±Ò°Ê¶iµ{ 115
5.5.3 ¸T¤îRedis¹B¦æ½ã¸¹µn¿ý¨t²Î 116
5.5.4 ¸T¤îRedis¨Ï¥ÎÀq»{ºÝ¤f 116
²Ä6³¹ MongoDB 117
6.1 ¦w¸Ë©M¸É¤B 117
6.1.1 ½T«O¨Ï¥Î³Ì·sª©¥»¼Æ¾Ú®w 117
6.1.2 ¨Ï¥ÎMongoDB±M¥Î½ã¸¹±Ò°Ê¶iµ{ 117
6.1.3 ½T«OMongoDB¥¼¨Ï¥ÎÀq»{ºÝ¤f 118
6.1.4 ¸T¤îMongoDB¹B¦æ½ã¸¹µn¿ý¨t²Î 118
6.2 ¨­¥÷»{ÃÒ 119
6.2.1 ½T«O±Ò¥Î¨­¥÷»{ÃÒ 119
6.2.2 ½T«O¥»¾÷µn¿ý¶i¦æ¨­¥÷»{ÃÒ 119
6.2.3 Àˬd¬O§_­­¨î³s±µ¦a§}»P³]³Æ 119
6.2.4 ½T«O¦b¶°¸sÀô¹Ò¤¤±Ò¥Î¨­¥÷»{ÃÒ 120
6.3 ³Æ¥÷»P®e¨a 120
6.3.1 ¨î©w¼Æ¾Ú®w³Æ¥÷µ¦²¤ 120
6.3.2 ³¡¸p¼Æ¾Ú®wÀ³¦h¥D¦h±q 121
6.4 ¤é§Ó»P¼f­p 121
6.4.1 ½T«O¤é§Ó°O¿ý¤º®e§¹¾ã 121
6.4.2 ½T«O²K¥[·s¤é§Óªö¥Î°l¥[¤è¦¡¦Ó¤£¬OÂл\ 121
6.5 ¥Ø¿ý¤å¥óÅv­­ 122
6.5.1 ½T«O°t¸m¤å¥ó¤Î¥Ø¿ýÅv­­¦X²z 122
6.5.2 ³Æ¥÷¼Æ¾ÚÅv­­³Ì¤p¤Æ 122
6.5.3 ¤é§Ó¤å¥óÅv­­³Ì¤p¤Æ 122
6.5.4 ½T«O±KÆ_ÃҮѤå¥óÅv­­³Ì¤p¤Æ 123
6.6 Åv­­±±¨î 123
6.6.1 ½T«O¨Ï¥Î°ò¤_¨¤¦âªº³X°Ý±±¨î 123
6.6.2 ½T«O¨C­Ó¨¤¦â³£¬O¥²­nªº¥BÅv­­³Ì¤p¤Æ 123
6.6.3 Àˬd¨ã¦³root¥Î¤á¨¤¦âªº¥Î¤á 124
6.7 ¶Ç¿é¥[±K 125
6.7.1 ½T«O¸T¥Îª©¥»TLS¨óij 125
6.7.2 ½T«Oºôµ¸¶Ç¿é¨Ï¥ÎTLS¥[±K 125

²Ä3½g ¤¤¶¡¥ó¦w¥þ

²Ä7³¹ Tomcat 129
7.1 ¦w¥þ°t¸m 129
7.1.1 ¥H´¶³q¥Î¤á¹B¦æTomcat 129
7.1.2 ­×§ïÀq»{ºÝ¤f 129
7.1.3 ³]¸m±K½Xªø«×©M´_Âø«× 130
7.1.4 °t¸m¤é§Ó¥\¯à 130
7.1.5 ³]¸m¤ä«ù¨Ï¥ÎHTTPSµ¥¥[±K¨óij 130
7.1.6 ³]¸m³s±µ¶W®É®É¶¡ 131
7.1.7 ¸T¥Î¦MÀIªºHTTP¤èªk 131
7.2 Åv­­±±¨î 132
7.2.1 ¸T¥Îmanager¥\¯à 132
7.2.2 ¸T¤îTomcatÅã¥Ü¤å¥ó¦Cªí 132

²Ä8³¹ Nginx 133
8.1 ¨óij¦w¥þ 133
8.1.1 °t¸mSSL¨óij 133
8.1.2 ­­¨îSSL¨óij©M±K½X 133
8.2 ¦w¥þ°t¸m 134
8.2.1 Ãö³¬Àq»{¿ù»~­¶ªºNginxª©¥»¸¹ 134
8.2.2 ³]¸mclient_body_timeout¶W®É 134
8.2.3 ³]¸mclient_header_timeout¶W®É 134
8.2.4 ³]¸mkeepalive_timeout¶W®É 134
8.2.5 ³]¸msend_timeout¶W®É 134
8.2.6 ³]¸m¥u¤¹³\GET¡BHEAD¡BPOST¤èªk 135
8.2.7 ±±¨î¦}µo³s±µ 135

²Ä9³¹ WebLogic 136
9.1 ¦w¥þ°t¸m 136
9.1.1 ¥H«Droot¥Î¤á¹B¦æWebLogic 136
9.1.2 ³]¸m¥[±K¨óij 136
9.1.3 ³]¸m½ã¸¹Âê©wµ¦²¤ 137
9.1.4 §ó§ïÀq»{ºÝ¤f 137
9.1.5 °t¸m¶W®É°h¥Xµn¿ý 137
9.1.6 °t¸m¤é§Ó¥\¯à 138
9.1.7 ³]¸m±K½X´_Âø«×²Å¦X­n¨D 138
9.2 Åv­­±±¨î 138
9.2.1 ¸T¥Îµo°eªA°È¾¹¼ÐÀY 138
9.2.2 ­­¨îÀ³¥ÎªA°È¾¹Socket¼Æ¶q 139

²Ä 10³¹ JBoss 140
10.1 ½ã¸¹¦w¥þ 140
10.1.1 ³]¸mjmx-consoleµn¿ýªº¥Î¤á¦W¡B±K½X¤Î¨ä´_Âø«× 140
10.1.2 ³]¸mweb serviceµn¿ýªº¥Î¤á¦W¡B±K½X¤Î¨ä´_Âø«× 141
10.2 ¦w¥þ°t¸m 141
10.2.1 ³]¸m¤ä«ù¥[±K¨óij 141
10.2.2 ­×§ïÀq»{ºÝ¤f 142
10.2.3 ³]¸m·|¸Ü¶W®É®É¶¡ 142
10.2.4 ­­¨î¥Ø¿ý¦Cªí³X°Ý 142
10.2.5 °O¿ý¥Î¤áµn¿ý¦æ¬° 143

²Ä 11³¹ Apache 144
11.1 ½ã¸¹¦w¥þ 144
11.1.1 ³]¸mApache¥Î¤á½ã¸¹Shell¥Í®Ä 144
11.1.2 Âê©wApache¥Î¤á½ã¸¹ 144
11.2 ¦w¥þ°t¸m 145
11.2.1 ¸T¥ÎSSL/TLS¨óij 145
11.2.2 ­­¨î¤£¦w¥þªºSSL/TLS 145
11.2.3 ³]¸mTimeout¤p¤_©Îµ¥¤_10 145
11.2.4 ³]¸mKeepAlive¬°On 145
11.2.5 ³]¸mMaxKeepAliveRequests¤j¤_©Îµ¥¤_100 146
11.2.6 ³]¸mKeepAliveTimeout¤p¤_©Îµ¥¤_15 146
11.2.7 ­­¨î©Ò¦³¥Ø¿ýÂл\ 146

²Ä 12³¹ IIS 147
12.1 Åv­­±±¨î 147
12.1.1 ¨ø¸ü¤£»Ý­nªº²Õ¥ó 147
12.1.2 §R°£Àq»{¯¸ÂI 147
12.1.3 ³]¸mºô¯¸¥Ø¿ýÅv­­ 147
12.1.4 ­­¨îÀ³¥Îµ{§ÇÂX®i 148
12.1.5 ­­¨îWebªA°ÈÂX®i 148
12.2 ¦w¥þ°t¸m 148
12.2.1 ¤é§Ó¥\¯à³]¸m 148
12.2.2 ¦Û©w¸q¿ù»~«H®§ 148

²Ä 13³¹ WebSphere 149
13.1 Åv­­±±¨î 149
13.1.1 ±±¨îconfig»Pproperties¥Ø¿ýÅv­­ 149
13.1.2 ¸T¤î¥Ø¿ýÂsÄý 149
13.2 ¦w¥þ°t¸m 150
13.2.1 ¸T¤î¦CªíÅã¥Ü¤å¥ó 150
13.2.2 °t¸m¤é§Ó¥\¯à 150
13.2.3 ±Ò¥Î¥þ§½¦w¥þ©Ê 150
13.2.4 ±Ò¥ÎJava 2¦w¥þ©Ê 151
13.2.5 °t¸m±±¨î»O·|¸Ü¶W®É®É¶¡ 151
13.2.6 ¨ø¸üsample¨Ò¤lµ{§Ç 151

²Ä4½g ®e¾¹¦w¥þ

²Ä 14³¹ Docker 155
14.1 Docker¥D¾÷¦w¥þ°t¸m 156
14.1.1 ½T«Odocker²Õ¤¤¶È¦s¦b¥i«H¥Î¤á 156
14.1.2 ¼f­pDocker¦uÅ@¶iµ{ 156
14.1.3 ¼f­pDocker¤å¥ó©M¥Ø¿ý 156
14.1.4 ½T«ODockerª©¥»³Ì·s 158
14.2 Docker¦uÅ@¶iµ{°t¸m 158
14.2.1 ¥H«Droot¥Î¤á¹B¦æDocker¦uÅ@¶iµ{ 158
14.2.2 ­­¨î¦bÀq»{ºô¾ô¤Wªº®e¾¹¤§¶¡ªººôµ¸¬y¶q 158
14.2.3 ³]¸m¤é§Ó°O¿ý¯Å§O¬°info 159
14.2.4 ¤¹³\Docker§ó§ïiptables 159
14.2.5 ¸T¤î¨Ï¥Î¤£¦w¥þªºª`¥Uªí 159
14.2.6 ¸T¤î¨Ï¥Îaufs¦sÀxÅX°Êµ{§Ç 159
14.2.7 °t¸mDocker¦uÅ@¶iµ{ªºTLS¨­¥÷ÅçÃÒ 160
14.2.8 ¥¿½T°t¸mÀq»{ulimit 160
14.2.9 ±Ò¥Î¥Î¤á©R¦WªÅ¶¡ 160
14.2.10 ½T«O¦w¸Ë±ÂÅv´¡¥ó 161
14.2.11 °t¸m¶°¤¤©M»·µ{¤é§Ó°O¿ý 161
14.2.12 ­­¨î®e¾¹Àò¨ú·sÅv­­ 161
14.2.13 ±Ò¥Î¹ê®ÉÁÙ­ì 161
14.2.14 ½T«O¸T¥ÎUserland¥N²z 162
14.2.15 ¸T¥Î¹êÅç¯S©Ê 162
14.3 Docker¦uÅ@¶iµ{°t¸m¤å¥óÅv­­ 162
14.3.1 °t¸mDocker¬ÛÃö¤å¥óªºÅv­­©MÄÝ¥DÄÝ²Õ 162
14.3.2 °t¸m/etc/docker¥Ø¿ýªºÅv­­©MÄÝ¥DÄÝ²Õ 163
14.3.3 °t¸mDocker¬ÛÃöÃҮѤå¥ó¥Ø¿ýªºÅv­­©MÄÝ¥DÄÝ²Õ 163
14.3.4 °t¸mDockerªA°È¾¹ÃҮѱKÆ_¤å¥óªºÅv­­©MÄÝ¥DÄÝ²Õ 164
14.3.5 °t¸mDocker®M±µ¦r¤å¥óªºÅv­­©MÄÝ¥DÄÝ²Õ 164
14.3.6 °t¸mContainerd®M±µ¦r¤å¥óªºÅv­­©MÄÝ¥DÄÝ²Õ 164
14.4 ®e¾¹Ãè¹³©Mºc«Ø¤å¥ó°t¸m 165
14.4.1 ¥H«Droot¥Î¤á¹B¦æ®e¾¹ 165
14.4.2 ¶È¨Ï¥Î¨ü«H¥ôªº°ò¦Ãè¹³ 165
14.4.3 ¨ø¸ü®e¾¹¤¤¦w¸Ëªº¤£¥²­nªº³n¥ó 165
14.4.4 ½T«OÃè¹³µL¦w¥þº|¬} 166
14.4.5 ±Ò¥ÎDockerªº¤º®e«H¥ô 166
14.4.6 ®e¾¹Ãè¹³¤¤²K¥[°·±dÀˬd 166
14.4.7 ½T«O¦bDockerfiles¤¤¤£³æ¿W¨Ï¥Îupdate«ü¥O 166
14.4.8 §R°£¤£¥²­nªºsetuid©MsetgidÅv­­ 167
14.4.9 Dockerfiles¤¤¨Ï¥ÎCOPY¦Ó¤£¨Ï¥ÎADD 167
14.4.10 §R°£Dockerfiles¤¤ªº±Ó·P«H®§ 168
14.5 ®e¾¹¹B¦æ®É°t¸m 168
14.5.1 ±Ò¥ÎAppArmor°t¸m 168
14.5.2 ³]¸mSELinux¦w¥þ¿ï¶µ 168
14.5.3 §R°£®e¾¹©Ò¦³¤£»Ý­nªº¥\¯à 169
14.5.4 ¤£¨Ï¥Î¯SÅv®e¾¹ 170
14.5.5 ¸T¤î¥HŪ¼g§Î¦¡±¾¸ü¥D¾÷¨t²Î±Ó·P¥Ø¿ý 170
14.5.6 ¸T¤î®e¾¹¤º¹B¦æsshd 171
14.5.7 ½T«O¥¼¬M®g¯SÅvºÝ¤f 172
14.5.8 Ãö³¬®e¾¹«D¥²»ÝºÝ¤f 172
14.5.9 ½T«O®e¾¹¤£¦@¨É¥D¾÷ªººôµ¸©R¦WªÅ¶¡ 173
14.5.10 ­­¨î®e¾¹ªº¥i¥Î¤º¦s 173
14.5.11 ³]¸m®e¾¹ªºCPUìH­È 174
14.5.12 ¦X²z±¾¸ü®e¾¹ªº®Ú¤å¥ó¨t²Î 174
14.5.13 ¬y¶q¸j©w¯S©wªº¥D¾÷ºÝ¤f 174
14.5.14 ³]¸m®e¾¹­«±Òµ¦²¤ 175
14.5.15 ¤£¦@¨É¥D¾÷ªºPID©R¦WªÅ¶¡ 175
14.5.16 ¤£¦@¨É¥D¾÷ªºIPC©R¦WªÅ¶¡ 176
14.5.17 ¤£ª½±µ¼ÉÅS¥D¾÷³]³Æ 176
14.5.18 ³]¸m¨t²Î¸ê·½­­¨î 176
14.5.19 ¸T¤î±N±¾¸ü¶Ç¼½¼Ò¦¡³]¸m¬°¦@¨É 177
14.5.20 ¤£¦@¨É¥D¾÷ªºUTS©R¦WªÅ¶¡ 177
14.5.21 ±Ò¥ÎÀq»{ªºseccomp°t¸m 177
14.5.22 ¸T¤îdocker exec¨Ï¥Î--privileged¿ï¶µ 178
14.5.23 ¸T¤îdocker exec¨Ï¥Î--user=root¿ï¶µ 178
14.5.24 ¨Ï¥ÎÀq»{ªºDocker cgroup 178
14.5.25 ­­¨î®e¾¹Àò¨úÃB¥~ªº¯SÅv 179
14.5.26 ¹B¦æ®ÉÀˬd®e¾¹°·±dª¬ªp 179
14.5.27 ¨Ï¥ÎÃè¹³ªº³Ì·sª©¥» 179
14.5.28 ­­¨î®e¾¹ªºpid­Ó¼Æ 180
14.5.29 ¤£¦@¨É¥D¾÷ªº¥Î¤á©R¦WªÅ¶¡ 180
14.5.30 ¸T¤î®e¾¹¤º¦w¸ËDocker®M±µ¦r 181
14.6 Docker swarm°t¸m 181
14.6.1 «D¥²­n«h¸T¥Îswarm¼Ò¦¡ 181
14.6.2 ³Ð«Ø³Ì¤p¼Æ¶qªººÞ²z¸`ÂI 181
14.6.3 ±NswarmªA°È¸j©w¨ì¯S©w¥D¾÷ºÝ¤f 182
14.6.4 ½T«O©Ò¦³Docker swarmÂл\ºôµ¸§¡¥[±K 182
14.6.5 ½T«Oswarm manager¦b¦Û°ÊÂê©w¼Ò¦¡¤U¹B¦æ 182
14.6.6 ¹jÂ÷ºÞ²z¥­­±¬y¶q»P¼Æ¾Ú¥­­±¬y¶q 183

²Ä 15³¹ Kubernetes 184
15.1 Master Node°t¸m¤å¥ó 185
15.1.1 °t¸mkube-apiserver.yamlªºÄÝ¥DÄݲթMÅv­­ 185
15.1.2 °t¸mkube-controller-manager.yamlªºÄÝ¥DÄݲթMÅv­­ 185
15.1.3 °t¸mkube-scheduler.yamlªºÄÝ¥DÄݲթMÅv­­ 186
15.1.4 °t¸metcd.yamlªºÄÝ¥DÄݲթMÅv­­ 186
15.1.5 °t¸m®e¾¹ºôµ¸±µ¤f¤å¥óªºÄÝ¥DÄݲթMÅv­­ 187
15.1.6 °t¸metcd¼Æ¾Ú¥Ø¿ýªºÄÝ¥DÄݲթMÅv­­ 187
15.1.7 °t¸madmin.confªºÄÝ¥DÄݲթMÅv­­ 188
15.1.8 °t¸mscheduler.confªºÄÝ¥DÄݲթMÅv­­ 188
15.1.9 °t¸mcontroller-manager.confªºÄÝ¥DÄݲթMÅv­­ 189
15.1.10 °t¸mKubernetes PKI ¥Ø¿ý¤Î¤å¥óªºÄÝ¥DÄݲթMÅv­­ 189
15.2 API Server 190
15.2.1 ¤£¨Ï¥Î°ò¥»¨­¥÷»{ÃÒ 190
15.2.2 ¤£¨Ï¥Î°ò¤_¥OµPªº¨­¥÷»{ÃÒ 190
15.2.3 ¨Ï¥ÎHTTPS¶i¦æKubelet³s±µ 191
15.2.4 ±Ò¥Î°ò¤_ÃҮѪºKubelet¨­¥÷»{ÃÒ 191
15.2.5 «Ø¥ß³s±µ«eÅçÃÒKubeletÃÒ®Ñ 191
15.2.6 ¸T¤î±ÂÅv©Ò¦³½Ð¨D 192
15.2.7 ³]¸m¦X²zªº±ÂÅv¤è¦¡ 192
15.2.8 ³]¸m·sPod­«±Ò®É«ö»Ý©Ô¨úÃè¹³ 192
15.2.9 ÁקK¦Û°Ê¤À°tªA°È½ã¸¹ 193
15.2.10 ©Úµ´¦b¤£¦s¦bªº©R¦WªÅ¶¡¤¤³Ð«Ø¹ï¶H 193
15.2.11 ©Úµ´³Ð«Ø¤£¦w¥þªºPod 193
15.2.12 ³]¸m·Ç¤J±±¨î´¡¥óNodeRestriction 194
15.2.13 ¤£¸j©w¤£¦w¥þªºapiserver¦a§} 194
15.2.14 ¤£¸j©w¤£¦w¥þªººÝ¤f 194
15.2.15 ¤£¸T¥Î¦w¥þºÝ¤f 195
15.2.16 ±Ò¥Î¤é§Ó¼f­p 195
15.2.17 ³]¸m¦X¾Aªº¤é§Ó¤å¥ó°Ñ¼Æ 195
15.2.18 ³]¸m¾A·íªºAPIªA°È¾¹½Ð¨D¶W®É°Ñ¼Æ 196
15.2.19 ÅçÃÒ¥OµP¤§«e¥ýÅçÃÒªA°È½ã¸¹ 196
15.2.20 ¬°apiserverªºªA°È½ã¸¹³]¸m¤½Æ_¤å¥ó 196
15.2.21 ³]¸mapiserver©Metcd¤§¶¡ªºTLS³s±µ 197
15.2.22 ³]¸mapiserverªºTLS³s±µ 197
15.2.23 ³]¸metcd¹ï«È¤áºÝªºTLS³s±µ 198
15.2.24 ³]¸m¥[±K¦sÀxetcdÁä­È 198
15.3 ControllerºÞ²z¾¹ 199
15.3.1 ¨C­Ó±±¨î¾¹¨Ï¥Î³æ¿WªºªA°È½ã¸¹¾ÌÃÒ 199
15.3.2 ¬°ControllerªºªA°È½ã¸¹³]¸m¨pÆ_¤å¥ó 199
15.3.3 ³]¸mAPIªA°È¾¹ªºªA°ÈÃÒ®Ñ 200
15.3.4 ¸T¤îController Manager APIªA°È¸j©w«DÀô¦^ªº¤£¦w¥þ¦a§} 200
15.4 scheduler 201
15.4.1 ½T«O--profiling°Ñ¼Æ¬°false 201
15.4.2 ¸T¤îscheduler APIªA°È¸j©w¨ì«DÀô¦^ªº¤£¦w¥þ¦a§} 201
15.5 etcd 201
15.5.1 ¬°etcdªA°È°t¸mTLS¥[±K 201
15.5.2 ¦betcdªA°È¤W±Ò¥Î«È¤áºÝ¨­¥÷»{ÃÒ 202
15.5.3 ¸T¤î¦Ûñ¦WÃҮѥΤ_TLS 202
15.5.4 ³]¸metcdªºTLS³s±µ 202
15.5.5 °t¸metcdªº¹ïµ¥¨­¥÷»{ÃÒ 203
15.5.6 ¸T¤îTLS³s±µ®É¨Ï¥Î¦Ûñ¦WÃÒ®Ñ 203
15.6 Worker¸`ÂI°t¸m¤å¥ó 203
15.6.1 °t¸mKubeletªA°È¤å¥óªºÄÝ¥DÄݲթMÅv­­ 203
15.6.2 °t¸m¥N²zkubeconfig¤å¥óªºÄÝ¥DÄݲթMÅv­­ 204
15.6.3 °t¸mkubelet.conf¤å¥óªºÄÝ¥DÄݲթMÅv­­ 204
15.6.4 °t¸mÃҮѹ{µo¾÷ºc¤å¥óªºÄÝ¥DÄݲթMÅv­­ 205
15.6.5 °t¸mKubelet°t¸m¤å¥óªºÄÝ¥DÄݲթMÅv­­ 205
15.7 Kubelet°t¸m 206
15.7.1 ¸T¤î°Î¦W½Ð¨DKubeletªA°È¾¹ 206
15.7.2 ±Ò¥ÎÅ㦡±ÂÅv 207
15.7.3 ±Ò¥ÎKubeletÃҮѨ­¥÷»{ÃÒ 207
15.7.4 ¸T¥Î¥uŪºÝ¤f 208
15.7.5 ¦X²z³]¸mÀq»{¤º®Ö°Ñ¼Æ­È 208
15.7.6 ¤¹³\KubeletºÞ²ziptables 209
15.7.7 ¤£­nÂл\¸`ÂI¥D¾÷¦W 209
15.7.8 ¦bKubelet¤W³]¸mTLS³s±µ 210
15.7.9 ±Ò¥ÎKubelet«È¤áºÝÃҮѽü´« 210
15.7.10 ±Ò¥ÎKubeletªA°ÈºÝÃҮѽü´« 211
15.8 Kubernetesµ¦²¤ 211
15.8.1 ¸T¤îhostPID³]¸m¬°true 211
15.8.2 ¸T¤îhostIPC³]¸m¬° true 212
15.8.3 ¸T¤îhostNetwork³]¸m¬°true 212
15.8.4 ¸T¤îallowPrivilegeEscalation³]¸m¬°true 213
15.8.5 ¸T¤î¥Hroot¥Î¤á¹B¦æ®e¾¹ 213
15.8.6 ½T«O©Ò¦³©R¦WªÅ¶¡³£©w¸qºôµ¸µ¦²¤ 213
µ²»y 215
§Ç¡G