ã¯ããã«
ã€ã³ã¿ãŒãããäžã®FreBSDã®ååæ管çã«é¢ããæ
å ±ãã»ãšãã©ãªããšããäºå®ã«ãããç§ã¯ãã®åºçç©ãæžãããšã奚å±ãããŸããã 確ãã«ãã®äž»é¡ã«é¢ããçŽ æŽãããåºçç©ãèŠã€ããããšãã§ããŸããããããã¯ã»ãšãã©äœå¹Žãåã«æžããããã®ã§ãããJailã®æ°æ©èœãšFreeBSDãªãã¬ãŒãã£ã³ã°ã·ã¹ãã èªäœã«ã¯åœ±é¿ããŸããã
åºçç©ã2ã€ã®éšåã«åããŸãã æåã®éšåã¯FreeBSDã®æºåãšèšå®ã«çŠç¹ãåœãŠã2çªç®ã®éšåã¯Jailã®äœæã«çŠç¹ãåœãŠãŸãã
ããŒã1. FreeBSDã®æºåãšèšå®ã
ããã«æžããããã¹ãŠãæ£ããæ©èœããããã«ã¯ãFreeBSDããŒãžã§ã³11.1ã䜿çšããå¿
èŠããããŸãããã®ããŒãžã§ã³ãããã·ã¹ãã ã¯ãã£ã¹ã¯I / Oã®å¶éãªã©ã®ãµããŒããå«ãããã§ãã ãããäžèŠãªå Žåã¯ãããŒãžã§ã³10.Xãé©ããŠããŸãã
rc.confã«ããã€ãã®ãã©ã¡ãŒã¿ãŒãè¿œå ããŸãã
sysrc jail_enable="YES" sysrc rctl_enable="YES" sysrc rctl_rules="/etc/rctl.conf" sysrc zfs_enable="YES" sysrc ifconfig_em0_alias="192.168.1.105/24"
1è¡ç®ã¯ã·ã¹ãã ã§èªåçã«èµ·åããããã«Jailã«æ瀺ãã2è¡ç®ã¯Jailã®å¶éãå«ããããšã瀺ãã3è¡ç®ã¯å¶éä»ãã®ã«ãŒã«ãã¡ã€ã«ã瀺ããŸãã 4è¡ç®ã¯ãZFSãã¡ã€ã«ã·ã¹ãã ã䜿çšããæ©èœãã¢ã¯ãã£ãã«ããŸãïŒãã¹ãŠã®Jailã¯ZFSããŒãã£ã·ã§ã³ã«ä¿åãããŸãïŒãã·ã¹ãã ããã€ãã£ãUFSãã¡ã€ã«ã·ã¹ãã ã䜿çšããå Žåããã®ãã©ã¡ãŒã¿ãŒãå¿
èŠã§ãã 次ã®ã³ãã³ãã§ZFSãèµ·åã§ããŸãã
/etc/rc.d/zfs start
5è¡ç®ã§ã¯ãè€æ°ã®Jailãå¿
èŠãªå ŽåãJailã®ãšã€ãªã¢ã¹ãäœæããå¿
èŠãªæ°ã®ipãšã€ãªã¢ã¹ãè¿œå ããŸãïŒVMware ESXIã䜿çšããŠããããããããã¯ãŒã¯ã«ãŒãã®ååã¯em0ã§ãããããã«ãŒãã®ååã䜿çšããå¿
èŠããããŸãïŒã
FreeBSDã§ã¯ãããã©ã«ãã§ãã«ãŒãã«ã¯ãªãœãŒã¹ãå¶éããæ©èœãç¡å¹ã«ããŠæ§ç¯ãããŠããŸããã幞ããªããšã«ãã®å¶éã¯ç°¡åã«åé€ã§ãã次ã®ã³ãã³ãã§loader.confãã¡ã€ã«ã«1è¡è¿œå ããã ãã§ãã
echo 'kern.racct.enable="1"' >> /boot/loader.conf
å€æŽã¯ãã·ã¹ãã ã®åèµ·ååŸã«æå¹ã«ãªããŸãã iscsiãããã³ã«ã®ãµããŒããæå¹ã«ããå¿
èŠããããŸããããã¯ã¢ããã¯ãã®ãããã³ã«ãä»ããŠæ£ç¢ºã«å®è¡ãããããã次ã®ã³ãã³ãã§ãµããŒããè¿œå ã§ããŸãã
echo 'iscsi_initiator_load="YES"' >> /boot/loader.conf
å€æŽã¯ãã·ã¹ãã ã®åèµ·ååŸã«æå¹ã«ãªããŸãã
ã·ã¹ãã ã§æåŸã«æ§æããå¿
èŠãããã®ã¯ïŒJailèªäœãé€ãïŒipfwã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ãã 次ã®ã³ãã³ãã¯ãipfwã«ãŒã«ãå«ããã¡ã€ã«ãäœæããŸãã
ee /etc/firewall.sc
ãã®ãã¡ã€ã«ã«ã¯æ¬¡ã®è¡ãå
¥åããå¿
èŠããããŸãã
ipfw -q -f flush c="ipfw -q add " $c 00105 allow tcp from any to 192.168.1.105 80 setup keep-state $c 00110 allow tcp from any to me 22 setup keep-state $c 00140 allow tcp from me to any 443,80,21,53,3260 setup keep-state $c 00143 allow icmp from me to any keep-state $c 00144 allow udp from me to any 53 keep-state $c 40533 deny all from any to any frag $c 40534 deny all from any to any established $c 40535 deny all from any to any
ãããã®ã«ãŒã«ã«ããããã¹ãŠã®Jailã¯ããŒã443ã80ã21ã53ã3260ïŒiscsiïŒãä»ããŠçºä¿¡æ¥ç¶ãè¡ãããšãã§ããSSHãä»ããŠãã¹ãŠã®Jailã«æ¥ç¶ããããšãå¯èœã«ãªããŸãã è¡ïŒ
$c 00105 allow tcp from any to 192.168.1.105 80 setup keep-state
å°æ¥ã®Jailãžã®æ¥ç¶ã¯ãç¹ã«WebãµãŒããŒã«å¯ŸããŠè²¬ä»»ããããŸããä»ã®ããŒããè¿œå ããå¿
èŠãããå Žåã¯ãããããã³ã³ãïŒ80,21,443,68ãªã©ïŒã§åºåã£ãŠæå®ããŸãã udpã«æ¥ç¶ããå¿
èŠãããå Žåãudpãããã³ã«ã«ã¯SYNãã©ã°ããªããããè¡ãã³ããŒããŠtcpãudpã«çœ®ãæããè¡çªå·ãå€æŽããã»ããã¢ãããåé€ããå¿
èŠããããŸãã
$c 00105 allow tcp from any to 192.168.1.105 80,21,22,443 setup keep-state $c 00106 allow udp from any to 192.168.1.105 53 keep-state
次ã®ã³ãã³ããé çªã«å®è¡ããŸãã
sysrc firewall_enable="YES" sysrc firewall_script="/etc/firewall.sc" service ipfw start
ãããã®ã³ãã³ããå®è¡ããåŸãã»ãšãã©ã®å ŽåãSSHçµç±ã§åæ¥ç¶ããå¿
èŠããããŸãã ãã®åæã»ããã¢ããã¯å®äºããŸãããiscsiã¿ãŒã²ãããµãŒããŒã®æ§æã«ç§»ããŸãããã
iSCSIã¿ãŒã²ããã®æ§ææ§æããã«ã¯ããããã¯ãŒã¯äžã®å¥ã®ãµãŒããŒãŸãã¯ä»®æ³ãã·ã³ïŒç§ã®å Žåã®ããã«ïŒãå¿
èŠã§ãã
iscsiã¿ãŒã²ãããèšå®ããã«ã¯ãctldïŒFreeBSDã®äžéšïŒã䜿çšããrc.confã«ãšã³ããªãè¿œå ããŸãã
sysrc ctld_enable="YES"
次ã®ã¹ãããã¯ãctldã®æ§æãã¡ã€ã«ãäœæããããšã§ãã
ee /etc/ctl.conf
äœæãããã¡ã€ã«ã«è¡ãè¿œå ããŸãã
auth-group group1 { chap "user" "password1234" } portal-group pg0 { discovery-auth-group group1 listen 192.168.1.106:3260 } target iqn.iscsi:target1 { alias "Example target" auth-group group1 portal-group pg0 lun 0 { path /dev/md0 size 10G } }
chapè¡ã§ãå¿
èŠãªååãšãã¹ã¯ãŒãïŒå°ãªããšã12æåïŒãæå®ããŸãã 圹è·
ã¿ãŒã²ããè¡ã§ã¯ãå¿
ãiqnã§éå§ããå¿
èŠããããŸãã listenè¡ã§ãçŸåšã®ãµãŒããŒã®IPã¢ãã¬ã¹ãæå®ããŸãã ãã¹è¡ã§ããã£ã¹ã¯ãžã®ãã¹ãæå®ããŸãã
ç©çãã£ã¹ã¯ã䜿çšããå Žåã¯ä»®æ³ããŒããã£ã¹ã¯ãããã«ç€ºããããããæå®ããä»®æ³ããŒããã£ã¹ã¯ã䜿çšããå Žåã¯å
ã«é²ã¿ãŸãã ä»®æ³ããŒããã£ã¹ã¯çšã®ãã¡ã€ã«ãäœæãããã£ã¬ã¯ããªã«ç§»åããŠãã³ãã³ããå®è¡ããŸãã
dd if=/dev/zero of=disk bs=1k count=10m
countãã©ã¡ãŒã¿ãŒã¯ã®ã¬ãã€ãæ°ã«è²¬ä»»ããããŸãããã®å Žåãç°ãªãæ°å€ãæå®ãããš10ã®ã¬ãã€ãã®ãã¡ã€ã«ãäœæãããŸãããã®å Žåãctl.confã§LUN 0ãã©ã¡ãŒã¿ãŒãå€æŽããå¿
èŠããããŸãã ããŒã¿åŠçã«ãããæéã¯æ¯èŒçãããã§ãã ããã»ã¹ãå®äºãããšããã£ã¹ã¯ãã¡ã€ã«ãçŸåšã®ãã©ã«ããŒã«äœæãããã³ãã³ãã§ä»®æ³ããŒããã£ã¹ã¯ãäœæããããã«ã®ã¿æ®ããŸãã
mdconfig -a -t vnode -f disk
ãã®ã³ãã³ããå®è¡ããåŸãä»®æ³ãã£ã¹ã¯ã®ååã衚瀺ãããŸãïŒç§ã®å Žå-md0ïŒãååãç°ãªãå Žåã¯ãctl.confã®LUN 0ãã©ã¡ãŒã¿ãŒãå€æŽããå¿
èŠããããŸãã åèµ·ååŸã«ãã®ãã©ã€ããæ¶ããªãããã«ããã«ã¯ã次ã®ã³ãã³ããå®è¡ããå¿
èŠããããŸãã
sysrc mdconfig_md0="-a -t vnode -f disk"
ãŸãã¯ããã¡ã€ã«ãžã®ãã¹ãæå®ããŸãã
sysrc mdconfig_md0="-a -t vnode -f /home/user/disk"
ã¯ã³ã¿ããå·Š-ãã¡ã€ã¢ãŠã©ãŒã«ããããŸãã ã¡ã€ã³ã·ã¹ãã ãšåæ§ã«ããã¡ã€ã«ãäœæããŸãã
ee /etc/firewall.sc
è¡ãè¿œå ããŸãã
ipfw -q -f flush c="ipfw -q add " $c 00110 allow tcp from any to me 22,3260 setup keep-state $c 00140 allow tcp from me to any 443,80,21,53,3260 setup keep-state $c 00143 allow icmp from me to any keep-state $c 00144 allow udp from me to any 53 keep-state $c 40533 deny all from any to any frag $c 40534 deny all from any to any established $c 40535 deny all from any to any
å€æŽãä¿åãããã次ãå
¥åããŸãã
sysrc firewall_enable="YES" sysrc firewall_script="/etc/firewall.sc" service ipfw start
ããã§iscsiãµãŒããŒã®æ§æãå®äºããŸããã次ã«ãJailãçŽæ¥æ§æããŸãã
ããŒã2.ååæã®æ§æ
FreeBSD 9以éãJailèšå®ã¯å¥ã®ãã¡ã€ã«/etc/jail.confã«ç§»åããŸããã ãã®ãã¡ã€ã«ãäœæããå¿
èŠãªå€æŽãå ããŠãã³ãã³ããå
¥åããŸãããã
ee /etc/jail.conf
ãã®ãã¡ã€ã«ã«ã¯æ¬¡ã®è¡ãå
¥åããå¿
èŠããããŸãã
allow.raw_sockets = 1; exec.clean; exec.start = "/bin/sh /etc/rc"; exec.stop = "/bin/sh /etc/rc.shutdown"; mount.devfs; allow.set_hostname = 1; allow.sysvipc = 1; jail1 { host.hostname = "jail"; path = "/jails/1/"; interface = "em0"; ip4.addr = 192.168.1.105; }
å€æŽãä¿åããããJailç°å¢ã®æ§ç¯ãéå§ã§ããŸãã ãã®ãã¡ã€ã«ã«ãããšãjail1ãšããååã®åäžã®Jailã䜿çšãããŸããè¿œå ã®Jailã䜿çšããå¿
èŠãããå Žåã¯ããã¡ã€ã«ã®å€èŠ³ã次ã®ããã«å€æŽããŸãã
allow.raw_sockets = 1; exec.clean; exec.start = "/bin/sh /etc/rc"; exec.stop = "/bin/sh /etc/rc.shutdown"; mount.devfs; allow.set_hostname = 1; allow.sysvipc = 1; jail1 { host.hostname = "jail"; path = "/jails/1/"; interface = "em0"; ip4.addr = 192.168.1.105; } jail2 { host.hostname = "jail"; path = "/jails/2/"; interface = "em0"; ip4.addr = 192.168.1.107; }
ãã®åºçç©ã§ã¯ãåäžã®ååæã®äœæã«ã€ããŠèª¬æããŸãã 次ã®ã³ãã³ãã䜿çšããŠãå°æ¥ã®ååæçšã®ãã£ã¬ã¯ããªãäœæããŸãã
mkdir -p /jails/1
ç°å¢ãäœæããã«ã¯ãããœãŒã¹ããå¿
èŠã§ããã·ã¹ãã ã®ã€ã³ã¹ããŒã«äžã«ããããã€ã³ã¹ããŒã«ããããSubversionã䜿çšããã®ãæãç°¡åã§ãïŒããªãäžå¿«ãªããã»ã¹ïŒã ç°å¢ãäœæããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŠ/ usr / srcãã£ã¬ã¯ããªã«ç§»åããŸãã
cd /usr/src
ç°å¢ãäœæããã«ã¯ã次ã®ã³ãã³ããå
¥åããŸãã
make -j4 world DESTDIR=/jails/1
ãã®ããã»ã¹ã¯éåžžã«é·ããIntel Core i5 3550ããã»ããµãŒãã·ã¹ãã ã«ã€ã³ã¹ããŒã«ãããŠãããããç°å¢ã®äœæã«ã¯çŽ1æéããããŸããã -j4ãã©ã¡ãŒã¿ãŒã¯ãç°å¢ã³ãã³ãã®äœæã«äœ¿çšãããŸã;æ°åã¯ãããã»ããµãŒå
ã®ã³ã¢ã®æ°ã瀺ããŸã;ããå€ããããé«éã§ãã ç°å¢ãäœæããããã次ã®ã³ãã³ãã䜿çšããŠæ§æãã¡ã€ã«ãjailã«è¿œå ããå¿
èŠããããŸãã
make distribution DESTDIR=/jails/1
ããã§ãç°å¢ã®äœæãå®äºããŸããã 次ã®ã³ãã³ããå
¥åããŸãã
/etc/rc.d/jail start
sshãç¡å¹ã«ãªã£ãŠãããããsshãä»ããŠæ°ããäœæãããJailã«æ¥ç¶ããå¯èœæ§ã¯ãããŸããã jailãå
¥åããã«ã¯ã次ã®ã³ãã³ããå®è¡ããŸãã
jexec jail1
æåã«è¡ãããšã¯ãDNSãµãŒããŒãè¿œå ããããšã§ãã
ee /etc/resolv.conf
äœæãããã¡ã€ã«ã«æ¬¡ã®è¡ãè¿œå ããŸãã
nameserver 8.8.8.8
ã¢ã«ãŠã³ããè¿œå ïŒwheelã°ã«ãŒãã«è¿œå ïŒããrootãã¹ã¯ãŒããäœæããsshãå®è¡ããŸããããã¯ãã¹ãŠã³ãã³ãã§å®è¡ã§ããŸãã
adduser sysrc sshd_enable="YES" service sshd start passwd root
çå€äžã®åžä»€å®ãã€ã³ã¹ããŒã«ããããšããå§ãããŸãïŒ
pkg install mc
mcã®ã€ã³ã¹ããŒã«äžã«ãpythonãperlãªã©ã®å€ãã®äžè¬çãªäŸåé¢ä¿ãè¿œãã€ããŸãã ãããã®æäœãå®è¡ããåŸãexitã³ãã³ãã§æå®ãããjailãçµäºããå¿
èŠããããŸãã 次ã«ãååæãåæ¢ããŸãã
/etc/rc.d/jail stop
5ã€ã®ååæãäœæããå¿
èŠãããç¶æ³ãæ³åããŠãã ããããã®ãããªã¿ã¹ã¯ã«ã¯å€ãã®æéãããããŸããã幞ããªããšã«ããã®ååæã®å
容ã§ã¢ãŒã«ã€ããäœæãããã¡ã€ã«ã®ãã¹ãŠã®æš©éãä¿åã§ããŸãã ãã®ç¶æ³ã§ã¯ãtarã¢ãŒã«ã€ãã圹ç«ã¡ãŸãã jailã§ãã£ã¬ã¯ããªã«è¡ããŸãããïŒ
cd /jails/1
次ã®ã³ãã³ããå®è¡ããŸãã
tar -zcvpf jail.tar *
ã¢ãŒã«ã€ããäœæããããå¥ã®ãã£ã¬ã¯ããªã«ç§»åããå¿
èŠããããŸãïŒãã®ãã£ã¬ã¯ããªã¯åé€ãããŸãïŒã
mv jail.tar /jail.tar
/ jailsãã£ã¬ã¯ããªã¯ããäžå€ããã©ã°ããã¹ãŠã®ãã¡ã€ã«ããåé€ããããŸã§åé€ã§ããŸããã
chflags -R noschg /jails rm -rf /jails/
äœããæ¶ããªãå Žåã¯ãã·ã¹ãã ãåèµ·åããŠrm -rfã³ãã³ããå床å®è¡ããã ãã§ãã ä»®æ³ããŒããã£ã¹ã¯ã®äœæãéå§ãããã£ã¹ã¯çšã®ãã¡ã€ã«ãäœæããŸãããã
dd if=/dev/zero of=disk bs=1k count=10m
ãããŠãä»®æ³ãã£ã¹ã¯èªäœãçŽæ¥ïŒ
mdconfig -a -t vnode -f disk
èªåãã£ã¹ã¯äœæãè¿œå ããŸãã
sysrc mdconfig_md0="-a -t vnode -f disk"
äœæãããã£ã¹ã¯ã®ååïŒååãç°ãªãå ŽåïŒãšãä»®æ³ãã£ã¹ã¯ã®ãã¡ã€ã«ãžã®ãã¹ãæå®ããŸãã 次ã®ã¹ãããã¯ãiscsiãä»ããŠãã©ã€ããèªåçã«æ¥ç¶ããããšã§ãã ãã©ã€ãã«æ£ããæ¥ç¶ããã«ã¯ãæ§æãã¡ã€ã«ãäœæããå¿
èŠããããŸãã
ee /etc/iscsi.conf
ãã®ãã¡ã€ã«ã«æ¬¡ã®å€æŽãå ããŸãã
iscsi_disk{ authmethod=CHAP chapIName=user1 chapSecret=password1234 initiatorname=nxl TargetName=iqn.iscsi:target1 TargetAddress=192.168.1.106:3260,1 LoginTimeout=10 AuthTimeout=10 IdleTimeout=10 ConnFailTimeout=10 AbortTimeout=10 ResetTimeout=10 }
ctl.confãã¡ã€ã«ã®èšå®ããã®è³æã«åŸã£ãŠèšå®ãããŠããå Žåãæ¥ç¶ã¯æ£ããè¡ãããŸãã iscsiãä»ããŠãã£ã¹ã¯ãèªåçã«æ¥ç¶ã§ããå¯äžã®æ¹æ³ã¯ãã¹ã¯ãªãããrc.dã«é
眮ããããšã«ãã£ãŠã®ã¿èŠã€ãããŸããã ãã®ã¹ã¯ãªãããäœæããŸãã
ee /etc/rc.d/iscsi.sc
次ã®è¡ãè¿œå ããŸãã
iscontrol -c /etc/iscsi.conf -n iscsi_disk zfs mount jails/1 /etc/rc.d/jail start
å¥ã®jailãäœæããå Žåããã®ã¹ã¯ãªããã«è¿œå ããå¿
èŠããããšããäºå®ãèæ
®ããå¿
èŠããããŸãïŒããšãã°ãzfs mount jails / 2ïŒã æåã®è¡ã¯iscsiãä»ããŠãã£ã¹ã¯ãæ¥ç¶ãã2è¡ç®ã¯ãã¡ã€ã«ã·ã¹ãã ãããŠã³ãããŸãïŒããŒã«ã«ããŒããã©ã€ãããèœã¡ããå ŽåïŒã3è¡ç®ã¯jailãéå§ããŸãã ãã¡ã€ã«ãå®è¡å¯èœã«ããã ãã§ãã
chmod +x /etc/rc.d/iscsi.sc
ãã®ã¹ã¯ãªãããå®è¡ããããã·ã¹ãã ãåèµ·åãããšããªã¢ãŒãããŒããã©ã€ããæäœã§ããããã«ãªããŸãã ç§ã®å Žåããã£ã¹ã¯ã®ååã¯da1ã§ããã䜿çšããååã䜿çšããå¿
èŠããããŸãã 次ã®2ã€ã®ãã£ã¹ã¯ããzfsããŒã«ãäœæããŸãã
zpool create jails mirror md0 da1
ããŒã ããæšæž¬ã§ããããã«ãzfsããŒã«ã¯ãã©ãŒãªã³ã°ãããŸãã
jailã®ã»ã¯ã·ã§ã³ãäœæããŸãã
zfs create jails/1
ãã®ãã£ã¬ã¯ããªã«5ã®ã¬ãã€ãã®å¶éãå²ãåœãŠãŸãã
zfs set quota=5g jails/1
ã¢ãŒã«ã€ããjailãã/ jails / 1ãã£ã¬ã¯ããªã«ã³ããŒããŠããã®ãã£ã¬ã¯ããªã«ç§»åããŸãã
cp /jail.tar /jails/1 cd /jails/1
ãã®ã¢ãŒã«ã€ãã解åããŠåé€ããŸãã
tar -zxvpf jail.tar rm jail.tar
ååæãå®è¡ããïŒ
/etc/rc.d/jail start
ãããã®æäœã®åŸãSSHãä»ããŠjailã«æ¥ç¶ãããµãŒããŒã«å¿
èŠãªåœ¹å²ãã€ã³ã¹ããŒã«ã§ããŸãã ååæã®å¶éãèšå®ããããã«ã®ã¿æ®ã£ãŠããŸãã rctlãæ§æããã«ã¯ãæ§æãã¡ã€ã«ãè¿œå ããã ãã§ãã
ee /etc/rctl.conf
ãã®ãã¡ã€ã«ã«æ¬¡ã®è¡ãè¿œå ããŸãã
jail:jail1:memoryuse:deny=1073741824 jail:jail1:readbps:throttle=4097152 jail:jail1:writebps:throttle=4097152 jail:jail1:pcpu:deny=50
1è¡ç®ã¯ã¡ã¢ãªã®äœ¿çšã1ã®ã¬ãã€ãã«å¶éãã2è¡ç®ãš3è¡ç®ã¯ãã£ã¹ã¯ãžã®èªã¿æžãã®äœ¿çšã4ã¡ã¬ãã€ãã«å¶éãã4è¡ç®ã¯åã³ã¢ã®äœ¿çšã50ïŒ
ã«å¶éããŸãã ããã¯å¶éã®å®å
šãªãªã¹ãã§ã¯ãããŸãã;ãœãŒã¹ã®ãªã¹ãã§ã¯ãFreeBSDãŠã§ããµã€ããžã®ãªã³ã¯ã瀺ããŸãã ãã®ãã¡ã€ã«ãä¿åããåŸãrctlãåèµ·åããå¿
èŠããããŸãã
service rctl restart
å¶éã¯æåéãæ°ç§ã§æå¹ã«ãªããŸãã
ãªãã·ã§ãã«
ãããçµäºããããšã¯å¯èœã§ãããé害ãçºçããã®ã¯ããŒããã©ã€ãã§ã¯ãªãããµãŒããŒèªäœïŒããšãã°ãæžã蟌ã¿ïŒã§ãããããªç¶æ³ãçºçããå¯èœæ§ããããŸãã ãã®ãããªå Žåããªã¢ãŒããµãŒããŒã«ãããã£ã¹ã¯ã䜿çšã§ããŸããã䜿çšããããšã¯ã§ããŸãããæåã«è¡ãå¿
èŠãããã®ã¯ãctldãµãŒãã¹ãåæ¢ããŠzfsãæå¹ã«ããããšã§ãã
service ctld stop sysrc zfs_enable="YES" /etc/rc.d/zfs start
ãã®åŸã次ã®ã³ãã³ããå
¥åããŸãã
zpool import
ãã®ã³ãã³ããå®è¡ãããšãã€ã³ããŒãå¯èœãªãã¹ãŠã®ããŒã«ïŒãã®å Žåã¯jailsããŒã«ïŒãç»é¢ã«è¡šç€ºããããã£ã¹ã¯åãmd0ã§è¡šç€ºãããŸãã ãã®ããŒã«ãããŠã³ãããã«ã¯ã次ã®ã³ãã³ããå®è¡ããå¿
èŠããããŸãã
zpool import -f jails jails
å¿
ã-fãæå®ããŠãã ãããæå®ããªããšãzpoolã¯ãã®ããŒã«ãå¥ã®ãµãŒããŒã«å±ããŠããããšãèªããŸãã å¿
èŠã«å¿ããŠããã®ããŒã«ã䜿çšããŠãã®ãµãŒããŒã§jailãæ§æããããšãã§ããŸããããã«ãããããŠã³ã¿ã€ã ãæå°éã«æããããŸãã ãã®ãã©ã€ããiscsiã§åã³äœ¿çšããã«ã¯ããã®ããŒã«ãç¡å¹ã«ããå¿
èŠããããŸãã
zpool export jails
ãŸããctldãå®è¡ããŸãã
service ctld start
ãããè¡ãããšãã§ããŸãã
ãã®åºçç©ã®å·çã«å€§ãã«åœ¹ç«ã£ããœãŒã¹ã®ãªã¹ãïŒ
Michael Lucas FreeBSDã 詳现ã¬ã€ãã
www.freebsd.org/cgi/man.cgi?query=rctl&sektion=8www.freebsd.org/doc/ru_RU.KOI8-R/books/handbook/disks-adding.htmldocs.oracle.com/cd/E19253-01/820-0836/gavwn/index.htmlwww.freebsd.org/cgi/man.cgi?query=ctl.conf&sektion=5&apropos=0&manpath=FreeBSD+11.1-RELEASE+and+Ports