From 879b97d00c9aadc91dcbf9dfcff6644c9a523504 Mon Sep 17 00:00:00 2001 From: jfmartel Date: Tue, 27 May 2025 08:42:52 -0400 Subject: [PATCH] Config Clickhouse Nouveaux certificats et scripts OVPN pour le VPN --- Clickhouse VM/Bck/config.xml | 1808 +++++++++++++++++ Clickhouse VM/config.xml | 15 +- .../Config MQTT Droplet.PNG | Bin 0 -> 20529 bytes Doc interne/Notes de développement.docx | Bin 44032 -> 43952 bytes .../Edgerouter_Station_Laval.ovpn | 0 OpenVPN/{ => -=Expired=-}/Otarcik202501.ovpn | 0 .../{ => -=Expired=-}/edgerouterchambly.ovpn | 0 OpenVPN/-=Expired=-/fred.ovpn | 268 +++ OpenVPN/-=Expired=-/jf.ovpn | 268 +++ OpenVPN/{ => -=Expired=-}/jf2.ovpn | 0 OpenVPN/{ => -=Expired=-}/jf_Yultek.ovpn | 0 OpenVPN/{ => -=Expired=-}/ka2501.ovpn | 0 OpenVPN/-=Expired=-/pascal.ovpn | 268 +++ OpenVPN/-=Expired=-/remoteclient.ovpn | 269 +++ OpenVPN/-=Expired=-/stationKA2401.ovpn | 269 +++ .../easy-rsa/pki/issued/DO_server.crt | 73 - .../easy-rsa/pki/issued/Otarcik202501.crt | 71 - .../easy-rsa/pki/issued/edgerouterchambly.crt | 71 - .../CA Server/easy-rsa/pki/issued/fred.crt | 71 - OpenVPN/CA Server/easy-rsa/pki/issued/jf.crt | 71 - .../CA Server/easy-rsa/pki/issued/pascal.crt | 71 - .../easy-rsa/pki/issued/remoteclient.crt | 71 - .../easy-rsa/pki/issued/stationKA2401.crt | 71 - .../CA Server/easy-rsa/pki/reqs/DO_server.req | 8 - .../easy-rsa/pki/reqs/Otarcik202501.req | 8 - .../easy-rsa/pki/reqs/edgerouterchambly.req | 8 - OpenVPN/CA Server/easy-rsa/pki/reqs/fred.req | 8 - OpenVPN/CA Server/easy-rsa/pki/reqs/jf.req | 8 - .../CA Server/easy-rsa/pki/reqs/pascal.req | 8 - .../easy-rsa/pki/reqs/remoteclient.req | 8 - .../easy-rsa/pki/reqs/stationKA2401.req | 8 - OpenVPN/Certificates/Certs/DO_server.crt | 71 + OpenVPN/Certificates/Certs/DO_server.req | 8 + OpenVPN/Certificates/Certs/fred.crt | 71 + OpenVPN/Certificates/Certs/fred.req | 8 + OpenVPN/Certificates/Certs/jf.crt | 71 + OpenVPN/Certificates/Certs/jf.req | 8 + OpenVPN/Certificates/Certs/pascal.crt | 71 + OpenVPN/Certificates/Certs/pascal.req | 8 + OpenVPN/Certificates/Certs/remoteclient.req | 8 + OpenVPN/Certificates/Certs/stationKA2401.crt | 71 + OpenVPN/Certificates/Certs/stationKA2401.req | 8 + OpenVPN/Certificates/Certs/stationOT2301.crt | 71 + OpenVPN/fred.ovpn | 95 +- OpenVPN/jf.ovpn | 97 +- OpenVPN/pascal.ovpn | 97 +- OpenVPN/remoteclient.ovpn | 94 +- OpenVPN/stationKA2401.ovpn | 94 +- PWD.txt | 17 +- 49 files changed, 3889 insertions(+), 878 deletions(-) create mode 100644 Clickhouse VM/Bck/config.xml create mode 100644 Config Stations/Station Otarcik OT2301/Config MQTT Droplet.PNG rename OpenVPN/{ => -=Expired=-}/Edgerouter_Station_Laval.ovpn (100%) rename OpenVPN/{ => -=Expired=-}/Otarcik202501.ovpn (100%) rename OpenVPN/{ => -=Expired=-}/edgerouterchambly.ovpn (100%) create mode 100644 OpenVPN/-=Expired=-/fred.ovpn create mode 100644 OpenVPN/-=Expired=-/jf.ovpn rename OpenVPN/{ => -=Expired=-}/jf2.ovpn (100%) rename OpenVPN/{ => -=Expired=-}/jf_Yultek.ovpn (100%) rename OpenVPN/{ => -=Expired=-}/ka2501.ovpn (100%) create mode 100644 OpenVPN/-=Expired=-/pascal.ovpn create mode 100644 OpenVPN/-=Expired=-/remoteclient.ovpn create mode 100644 OpenVPN/-=Expired=-/stationKA2401.ovpn delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/issued/DO_server.crt delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/issued/Otarcik202501.crt delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/issued/edgerouterchambly.crt delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/issued/fred.crt delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/issued/jf.crt delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/issued/pascal.crt delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/issued/remoteclient.crt delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/issued/stationKA2401.crt delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/reqs/DO_server.req delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/reqs/Otarcik202501.req delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/reqs/edgerouterchambly.req delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/reqs/fred.req delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/reqs/jf.req delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/reqs/pascal.req delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/reqs/remoteclient.req delete mode 100644 OpenVPN/CA Server/easy-rsa/pki/reqs/stationKA2401.req create mode 100644 OpenVPN/Certificates/Certs/DO_server.crt create mode 100644 OpenVPN/Certificates/Certs/DO_server.req create mode 100644 OpenVPN/Certificates/Certs/fred.crt create mode 100644 OpenVPN/Certificates/Certs/fred.req create mode 100644 OpenVPN/Certificates/Certs/jf.crt create mode 100644 OpenVPN/Certificates/Certs/jf.req create mode 100644 OpenVPN/Certificates/Certs/pascal.crt create mode 100644 OpenVPN/Certificates/Certs/pascal.req create mode 100644 OpenVPN/Certificates/Certs/remoteclient.req create mode 100644 OpenVPN/Certificates/Certs/stationKA2401.crt create mode 100644 OpenVPN/Certificates/Certs/stationKA2401.req create mode 100644 OpenVPN/Certificates/Certs/stationOT2301.crt diff --git a/Clickhouse VM/Bck/config.xml b/Clickhouse VM/Bck/config.xml new file mode 100644 index 0000000..b68dcb4 --- /dev/null +++ b/Clickhouse VM/Bck/config.xml @@ -0,0 +1,1808 @@ + + + + + trace + /var/log/clickhouse-server/clickhouse-server.log + /var/log/clickhouse-server/clickhouse-server.err.log + + 10M + 1 + + + + + + + + + + + + + + + + + + + + + https://{bucket}.s3.amazonaws.com + + + https://storage.googleapis.com/{bucket} + + + https://{bucket}.oss.aliyuncs.com + + + + + +
+ Access-Control-Allow-Origin + * +
+
+ Access-Control-Allow-Headers + origin, x-requested-with, x-clickhouse-format, x-clickhouse-user, x-clickhouse-key, Authorization +
+
+ Access-Control-Allow-Methods + POST, GET, OPTIONS +
+
+ Access-Control-Max-Age + 86400 +
+
+ + + + + + 8123 + + + 9000 + + + + + + 9004 + + + 9005 + + + + + + + + + + + + 9009 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + 10.118.0.3 + 127.0.0.1 + + + + + + + + + + + + + + + + + + + + 10 + + + + + false + + + /path/to/ssl_cert_file + /path/to/ssl_key_file + + + false + + + /path/to/ssl_ca_cert_file + + + none + + + 0 + + + -1 + -1 + + + false + + + + + + + + + + none + true + true + sslv2,sslv3 + true + + + + RejectCertificateHandler + + + + + true + true + sslv2,sslv3 + true + + + + RejectCertificateHandler + + + + + + + + + 0 + 2 + fair_round_robin + + + 1000 + + + 0 + + + + + 10000 + + + + + + true + + + 2 + + + 4194304 + + + 0 + + + + + + 8589934592 + + + + + + + + + + + + + + + + + + 106700800 + + + + + + /var/lib/clickhouse/caches/ + + false + + + + /mnt/volume_tor1_01/yultek_db/ + + + + + + /var/lib/clickhouse/tmp/ + + + 1 + 1 + 1 + + + sha256_password + + + 12 + + + + + + + + + /var/lib/clickhouse/user_files/ + + + + + + + + + + + + + users.xml + + + + /var/lib/clickhouse/access/ + + + + + + + + true + + + true + + + true + + + true + + + true + + + false + + + 600 + + + + default + + + SQL_ + + + + + + + + + default + + + + + + + + + true + + + false + + ' | sed -e 's|.*>\(.*\)<.*|\1|') + wget https://github.com/ClickHouse/clickhouse-jdbc-bridge/releases/download/v$PKG_VER/clickhouse-jdbc-bridge_$PKG_VER-1_all.deb + apt install --no-install-recommends -f ./clickhouse-jdbc-bridge_$PKG_VER-1_all.deb + clickhouse-jdbc-bridge & + + * [CentOS/RHEL] + export MVN_URL=https://repo1.maven.org/maven2/com/clickhouse/clickhouse-jdbc-bridge/ + export PKG_VER=$(curl -sL $MVN_URL/maven-metadata.xml | grep '' | sed -e 's|.*>\(.*\)<.*|\1|') + wget https://github.com/ClickHouse/clickhouse-jdbc-bridge/releases/download/v$PKG_VER/clickhouse-jdbc-bridge-$PKG_VER-1.noarch.rpm + yum localinstall -y clickhouse-jdbc-bridge-$PKG_VER-1.noarch.rpm + clickhouse-jdbc-bridge & + + Please refer to https://github.com/ClickHouse/clickhouse-jdbc-bridge#usage for more information. + ]]> + + + + + + + + + + + + + + + + localhost + 9000 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + 3600 + + + + 3600 + + + 60 + + + + + + + + + + + + + system + query_log
+ + toYYYYMM(event_date) + + event_date + INTERVAL 15 MINUTE DELETE + + + + + + + 7500 + + 1048576 + + 8192 + + 524288 + + false + + + +
+ + + + system + trace_log
+ + toYYYYMM(event_date) + 0 + 1048576 + 8192 + 524288 + + false + true +
+ + + + system + query_thread_log
+ toYYYYMM(event_date) + 7500 + 1048576 + 8192 + 524288 + false +
+ + + + system + query_views_log
+ toYYYYMM(event_date) + 7500 +
+ + + + system + part_log
+ toYYYYMM(event_date) + 7500 + 1048576 + 8192 + 524288 + false +
+ + + + system + text_log
+ 7500 + 1048576 + 8192 + 524288 + false + none +
+ + + + system + metric_log
+ 7500 + 1048576 + 8192 + 524288 + 1000 + false +
+ + + + system + latency_log
+ 7500 + 1048576 + 8192 + 524288 + 1000 + false +
+ + + + system + error_log
+ 7500 + 1048576 + 8192 + 524288 + 1000 + false +
+ + + + system + query_metric_log
+ 7500 + 1048576 + 8192 + 524288 + 1000 + false +
+ + + + system + asynchronous_metric_log
+ 7000 + 1048576 + 8192 + 524288 + false +
+ + + + + + engine MergeTree + partition by toYYYYMM(finish_date) + order by (finish_date, finish_time_us) + + system + opentelemetry_span_log
+ 7500 + 1048576 + 8192 + 524288 + false +
+ + + + + system + crash_log
+ + + 1000 + 1024 + 1024 + 512 + true +
+ + + + + + + system + processors_profile_log
+ + toYYYYMM(event_date) + 7500 + 1048576 + 8192 + 524288 + false + event_date + INTERVAL 15 MINUTE DELETE +
+ + + + system + asynchronous_insert_log
+ + 7500 + 1048576 + 8192 + 524288 + false + event_date + event_date + INTERVAL 15 MINUTE +
+ + + + system + backup_log
+ toYYYYMM(event_date) + 7500 +
+ + + + system + s3queue_log
+ toYYYYMM(event_date) + 7500 +
+ + + + system + blob_storage_log
+ toYYYYMM(event_date) + 7500 + event_date + INTERVAL 30 DAY +
+ + + + + + + + + + + + + *_dictionary.*ml + + + true + + + true + + + *_function.*ml + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + /clickhouse/task_queue/ddl + + /clickhouse/task_queue/replicas + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + click_cost + any + + 0 + 3600 + + + 86400 + 60 + + + + max + + 0 + 60 + + + 3600 + 300 + + + 86400 + 3600 + + + + + + /var/lib/clickhouse/format_schemas/ + + + /usr/share/clickhouse/protos/ + + + + + + + + + + false + + false + + + https://6f33034cfe684dd7a3ab9875e57b1c8d@o388870.ingest.sentry.io/5226277 + + false + + + + + + + + + + + + + + + + + + + + + + + + + + backups + + + true + + + + + + + + + + + +
diff --git a/Clickhouse VM/config.xml b/Clickhouse VM/config.xml index a4a9489..f88cf33 100644 --- a/Clickhouse VM/config.xml +++ b/Clickhouse VM/config.xml @@ -266,7 +266,8 @@ - 0.0.0.0 + 10.118.0.3 + 127.0.0.1 0 + - 0.9 + 5 + event_date + INTERVAL 15 MINUTE DELETE @@ -1342,7 +1345,7 @@ 8192 524288 false - event_date + INTERVAL 30 DAY DELETE + event_date + INTERVAL 15 MINUTE DELETE