開始輸入,可搜尋發票、服務、域名、工單,以及 更多...
新開通的伺服器預設時區往往是 UTC,日誌時間與本地對不上;時間不準還會導致 HTTPS 證書校驗失敗、定時任務錯亂、二次驗證碼無效。本文介紹如何用 timedatectl 修改 Linux 時區、用 chrony 開啟 NTP 時間同步、修改主機名與 /etc/hosts,以及在 systemd-resolved、NetworkManager 和傳統 resolv.conf 三種情況下正確設定 DNS。適用於 Debian/Ubuntu 與 Rocky Linux/AlmaLinux。
先檢視當前狀態,再從列表中選擇時區名稱。香港伺服器常用 Asia/Hong_Kong,日本為 Asia/Tokyo,俄羅斯為 Europe/Moscow;如果伺服器給多地使用者使用,保持 UTC 也是很好的選擇。修改時區不會改變真即時間,只改變顯示方式;已執行的程式(如 PHP-FPM、MySQL)建議重啟以讀取新時區。
timedatectl # current time, time zone, NTP status
timedatectl list-timezones | grep -E 'Asia|UTC'
timedatectl set-timezone Asia/Hong_Kong # e.g. Asia/Tokyo, Asia/Shanghai, Europe/Moscow, UTC
timedatectl set-local-rtc 0 # keep the hardware clock in UTC
date
chrony 在網路波動時也能快速、穩定地校時,是 Rocky/AlmaLinux 的預設方案,Debian/Ubuntu 上安裝後會替代 systemd-timesyncd。輸出中帶 ^* 的行表示正在使用的時間源,chronyc tracking 可看到當前偏差。
# Debian / Ubuntu (replaces systemd-timesyncd)
apt install -y chrony
systemctl enable --now chrony
# Rocky Linux / AlmaLinux
dnf install -y chrony
systemctl enable --now chronyd
timedatectl set-ntp true
chronyc sources -v # "^*" marks the server currently in use
chronyc tracking # "System time" shows the current offset
預設的發行版時間池一般夠用。如需指定伺服器,編輯 chrony 配置檔案中的 pool/server 行;makestep 允許啟動初期時間偏差較大時直接跳變校正。注意防火牆需允許出站 UDP 123 埠。
# Config file: /etc/chrony/chrony.conf (Debian/Ubuntu) or /etc/chrony.conf (Rocky/AlmaLinux)
# Replace or add the server lines, for example:
pool pool.ntp.org iburst
server time.cloudflare.com iburst
makestep 1.0 3
# Apply and step the clock immediately if it is far off
systemctl restart chrony # chronyd on Rocky/AlmaLinux
chronyc makestep
hostnamectl 修改後立即生效且重啟不丟失。隨後在 /etc/hosts 中加入新主機名,否則 sudo 可能提示 “unable to resolve host”,部分郵件和資料庫程式也會啟動變慢。若系統使用 cloud-init,還需設定 preserve_hostname,避免重啟後被改回。提示符中的主機名要重新登入 SSH 後才會更新。
hostnamectl set-hostname web01.example.com
hostnamectl
# /etc/hosts - make the new name resolve locally
127.0.0.1 localhost
127.0.1.1 web01.example.com web01 # Debian/Ubuntu convention
# or map it to the server's public IP:
# 203.0.113.10 web01.example.com web01
# Images with cloud-init: stop it from resetting the hostname on reboot
grep -n preserve_hostname /etc/cloud/cloud.cfg
sed -i 's/^preserve_hostname:.*/preserve_hostname: true/' /etc/cloud/cloud.cfg
不同發行版管理 DNS 的方式不同,直接編輯 /etc/resolv.conf 可能在重啟後被覆蓋。先看這個檔案是軟連結還是普通檔案、開頭有沒有 “Generated by” 註釋,再決定修改方式。
ls -l /etc/resolv.conf
# -> ../run/systemd/resolve/stub-resolv.conf : managed by systemd-resolved (Ubuntu)
# -> regular file "Generated by NetworkManager": managed by NetworkManager (Rocky/AlmaLinux)
# -> regular file without such comment : edited by hand (common on Debian)
resolvectl status 2>/dev/null | head -n 20
根據上一步結果三選一:Ubuntu 等使用 systemd-resolved 的系統寫入 resolved 的配置片段;Rocky/AlmaLinux 通過 nmcli 修改連線(連線名以 nmcli con show 顯示為準);傳統 Debian 直接編輯 resolv.conf。最後用 getent 測試解析。
# A) systemd-resolved (Ubuntu and some Debian setups)
mkdir -p /etc/systemd/resolved.conf.d
cat > /etc/systemd/resolved.conf.d/dns.conf <<'EOF'
[Resolve]
DNS=1.1.1.1 8.8.8.8 2606:4700:4700::1111
FallbackDNS=9.9.9.9
EOF
systemctl restart systemd-resolved
resolvectl status
# B) NetworkManager (Rocky Linux / AlmaLinux)
nmcli -t -f NAME,DEVICE con show --active
nmcli con mod "System eth0" ipv4.dns "1.1.1.1 8.8.8.8" ipv4.ignore-auto-dns yes
nmcli con up "System eth0"
# C) Plain /etc/resolv.conf (Debian with ifupdown)
cat > /etc/resolv.conf <<'EOF'
nameserver 1.1.1.1
nameserver 8.8.8.8
options timeout:2 attempts:2
EOF
# Test
getent hosts www.imidc.com
nmcli con up 會短暫過載網絡卡,配置錯誤可能導致 SSH 斷開。請確認連線名正確,必要時通過客戶中心提供的控制臺(如有)操作,找不到可提交工單協助。通常是 UDP 123 被防火牆攔截,或 DNS 無法解析時間伺服器域名。先檢查 DNS,再放行出站 UDP 123,或改用可訪問的 NTP 伺服器。
這是 systemd-resolved 的本地存根地址,屬正常現象。真實的上遊 DNS 請用 resolvectl status 檢視,修改方法見步驟 6 的 A。
一般不會,但如果郵件服務、寶塔或資料庫授權中寫死了舊主機名,需要同步修改。郵件伺服器的主機名還應與 rDNS(PTR)記錄一致,可參考“rDNS/PTR”教程。
如果按以上步驟操作後問題仍未解決,請提交工單聯絡 IMIDC 7×24 技術支援,並附上伺服器 IP、系統版本、執行過的命令和完整報錯資訊,方便工程師快速定位。