Live-build方法构建debian和ubuntu

一、构建和说明

Live-build 是 Debian/Ubuntu 官方原生维护的标准镜像构建工具,整体非常靠谱‌,是目前构建自定义 Debian/Ubuntu Live 系统、嵌入式根文件系统和定制发行版的主流工业级方案。它的可靠性经过了十多年社区验证,Debian 官方的 Live 镜像本身就是用它构建的。

1.首先下载并安装live-build

清理旧版:sudo apt-get remove live-build

下载:git clone https://salsa.debian.org/live-team/live-build.git --depth 1 -b debian/1%20230131

编译安装:

cd live-build

rm -rf manpages/po/

sudo make install -j8

上述使用20230131版本,也可以使用最新的20250814版本进行安装。

2.准备构建环境:

sudo apt-get install binfmt-support qemu-user-static

说明如下:

live-build:Debian 官方的 Live 镜像构建工具套件。

debootstrap:负责构建最小的 Debian 根文件系统。

qemu-user-static:关键,让 x86 机器能通过用户态模拟执行 arm64 程序,没有它无法完成跨架构构建

3.编译构建:

创建一个文件夹存放构建脚本build_rootfs.sh和所需的需要安装的软件列表live.list.chroot和相关文件系统配置00*.chroot文件,仅需这三大类并保持全程联网,即可。

构建过程会先下载基础系统,再安装你指定的软件包,最后打包成镜像。 首次构建耗时较长,网络波动可能导致失败,重跑一般能续上

4.说明:

创建一个根工程文件夹用于存放构建中的诸多文件

软件包列表:在 config/package-lists/ 下新建 .list.chroot 文件,每行写一个包名,比如 vim、network-manager。

自定义文件:想往镜像里塞自己的配置或脚本,放到 config/includes.chroot/ 下,目录结构会原样合并进目标系统的根目录。

钩子脚本:需要构建过程中执行额外命令(比如设置默认密码、启用 SSH),放到 config/hooks/ 下并加上执行权限。

lb config 后生成的目录结构,可以自行查找其功能。

二、问题分析:

我这边使用live-build 20250814 从 https://salsa.debian.org/live-team/live-build.git 进行下载和安装,由于是第一次进行构建,过程中出现了很多错误,记录一下表现和解决方法:

**问题1:使用lb config --h 或者lb config ---help来查看lb config的输入参数有哪些以及各个参数的含义有效值。**我使用的版本如下:

复制代码
NAME
       lb_config - Create config directory

SYNOPSIS
       lb config {-h|--help|-u|--usage|-v|--version}

       lb config
            [--apt apt|apt-get|aptitude]
            [--apt-http-proxy URL]
            [--apt-indices true|false]
            [--apt-options OPTION|"OPTIONS"]
            [--apt-pipeline DEPTH]
            [--apt-recommends true|false]
            [--apt-secure true|false]
            [--apt-source-archives true|false]
            [--aptitude-options OPTION|"OPTIONS"]
            [-a|--architecture ARCHITECTURE]
            [--archive-areas ARCHIVE_AREA|"ARCHIVE_AREAS"]
            [--backports true|false]
            [--binary-filesystem fat16|fat32|ext2|ext3|ext4|ntfs]
            [-b|--binary-image iso|iso-hybrid|netboot|tar|hdd]
            [--bootappend-install PARAMETER|"PARAMETERS"]
            [--bootappend-live PARAMETER|"PARAMETERS"]
            [--bootappend-live-failsafe PARAMETER|"PARAMETERS"]
            [--bootloaders grub-legacy|grub-pc|syslinux|grub-efi|"BOOTLOADERS"]
            [--bootstrap-qemu-arch ARCH]
            [--bootstrap-qemu-exclude PACKAGE|"PACKAGES"]
            [--bootstrap-qemu-static PATH]
            [--breakpoints]
            [--build-with-chroot true|false]
            [--cache true|false]
            [--cache-indices true|false]
            [--cache-packages true|false]
            [--cache-stages bootstrap|chroot|rootfs|"STAGES"]
            [--checksums md5|sha1|sha224|sha256|sha384|sha512|none]
            [--chroot-filesystem ext2|ext3|ext4|squashfs|jffs2|none|plain]
            [--chroot-squashfs-compression-level LEVEL]
            [--chroot-squashfs-compression-type gzip|lzma|lzo|lz4|xz|zstd]
            [--clean]
            [--color]
            [--compression bzip2|gzip|lzip|xz|none]
            [-c|--conffile FILE]
            [--config GIT_URL::GIT_BRANCH]
            [--debconf-frontend dialog|editor|noninteractive|readline]
            [--debconf-priority low|medium|high|critical]
            [--debian-installer cdrom|netinst|netboot|businesscard|live|none]
            [--debian-installer-distribution daily|git|CODENAME]
            [--debian-installer-gui true|false]
            [--debian-installer-preseedfile FILE|URL]
            [--debootstrap-options OPTION|"OPTIONS"]
            [--debootstrap-script SCRIPT]
            [--debug]
            [-d|--distribution CODENAME]
            [--distribution-chroot CODENAME]
            [--distribution-binary CODENAME]
            [--dm-verity]
            [--dm-verity-fec NB_ROOTS]
            [--dm-verity-sign SIGN_SCRIPT]
            [--dump]
            [--firmware-binary true|false]
            [--firmware-chroot true|false]
            [--force]
            [--gzip-options OPTION|"OPTIONS"]
            [--hdd-label LABEL]
            [--hdd-partition-start START]
            [--hdd-size SIZE]
            [--ignore-system-defaults]
            [--image-name NAME]
            [--initramfs none|live-boot|dracut-live]
            [--initramfs-compression bzip2|gzip|lzma]
            [--initsystem sysvinit|systemd|none]
            [--interactive true|shell|x11|xnest|false]
            [--iso-application NAME]
            [--iso-preparer NAME]
            [--iso-publisher NAME]
            [--iso-volume NAME]
            [--jffs2-eraseblock SIZE]
            [--keyring-packages PACKAGE|"PACKAGES"]
            [-k|--linux-flavours FLAVOUR|"FLAVOURS"]
            [--linux-packages PACKAGE|"PACKAGES"]
            [--loadlin true|false]
            [--memtest memtest86+|memtest86|none]
            [--mirror-binary URL]
            [--mirror-binary-security URL]
            [--mirror-bootstrap URL]
            [--mirror-chroot URL]
            [--mirror-chroot-security URL]
            [--mirror-debian-installer URL]
            [--mode debian]
            [--net-tarball true|false]
            [--no-color]
            [--onie true|false]
            [--onie-kernel-cmdline OPTION|"OPTIONS"]
            [--parent-archive-areas ARCHIVE_AREA|"ARCHIVE_AREAS"]
            [--parent-debian-installer-distribution daily|git|CODENAME]
            [--parent-distribution CODENAME]
            [--parent-distribution-chroot CODENAME]
            [--parent-distribution-binary CODENAME]
            [--parent-mirror-binary URL]
            [--parent-mirror-binary-security URL]
            [-m|--parent-mirror-bootstrap URL]
            [--parent-mirror-chroot URL]
            [--parent-mirror-chroot-security URL]
            [--parent-mirror-debian-installer URL]
            [--quiet]
            [--security true|false]
            [--source true|false]
            [-s|--source-images iso|netboot|tar|hdd|"IMAGES"]
            [--swap-file-path PATH]
            [--swap-file-size MB]
            [--system live|normal]
            [--uefi-secure-boot auto|enable|disable]
            [--updates true|false]
            [--utc-time true|false]
            [--validate]
            [--verbose]
            [--win32-loader true|false]
            [--zsync true|false]

描述太多,不再这里给出。

这里给出我是用的脚本里的几个参数的详细描述如下:

复制代码
--mirror-bootstrap "https://mirrors.aliyun.com/debian" #初始引导阶段(安装最基础系统文件)使用的软件源
     --mirror-chroot "https://mirrors.aliyun.com/debian"   #Chroot 阶段(安装额外软件包、配置系统时)使用的软件源
     --mirror-chroot-security ""                         #Chroot 阶段的安全更新源,空字符串表示‌不添加‌安全更新源
     --mirror-binary "https://mirrors.aliyun.com/debian"   #最终生成的 Live 系统运行时使用的软件源镜像
     --mirror-binary-security ""                         #最终系统的安全更新源。设置为空不包含安全更新源条目
     --apt-indices false                                 #不在最终镜像中保留 APT 的软件包索引文件
     --apt-recommends false                             #安装软件包时,只安装"必需"(Depends)的依赖最小化安装
     --apt-secure false                                  #禁用 APT 对软件仓库 Release 文件的 GPG 签名验证
     --architecture arm64                               #指定目标系统的 CPU 架构为 ARM64 (AArch64)
     --archive-areas 'main contrib'  #指定从软件源中获取哪些区域的包main: Debian 自由软件;contrib: 依赖非自由软件的自由软件
     --backports false             #不启用 Debian Backports 源。保持系统软件版本的稳定性,不引入较新的回溯移植包
     --binary-filesystem ext4       #如果生成的是块设备镜像(如 hdd/img),则使用 ext4 文件系统
     --binary-images tar           #最终生成的镜像格式为 ‌tar 压缩包
     --bootappend-live "hostname=FSU username=root"   #设置 Live 系统启动时的内核命令行参数,将系统主机名设置为 "FSU",指定默认登录用户为 root
     --bootstrap-qemu-arch arm64  #指定在 Bootstrap 阶段使用的 QEMU 模拟架构
     --bootstrap-qemu-static /usr/bin/qemu-aarch64-static   #指定用于模拟 ARM64指令的静态 QEMU二进制文件路径
     --cache true               #启用本地缓存总开关,用于重构建时加速
     --cache-indices true         #缓存下载的 Package 索引文件
     --cache-packages true       #缓存下载的 .deb 安装包文件
     --chroot-filesystem none     #构建过程中,不创建 squashfs 或其他压缩的 chroot 文件系统层,直接使用目录结构。这有助于调试和加快构建速度
     --compression gzip         #对最终生成的 tar 包使用 gzip 压缩
     --debootstrap-options "--variant=minbase --include=apt-transport-https,gnupg" \
     --distribution bullseye       #指定 Debian 的版本代号为 ‌Bullseye‌ (Debian 11)
     --gzip-options '-9 --rsyncable' #传递给 gzip 的参数,-9: 最高压缩率,减小文件体积。--rsyncable: 使压缩后的文件对 rsync 更友好,如果文件只有微小变化,rsync 传输时只需同步改变的部分。
     --linux-flavours none       #不自动安装任何 Linux 内核风格的包
     --linux-packages none      #不安装额外的 Linux 相关包
     --mode debian            #设置构建模式为标准的 Debian 模式(区别于 Ubuntu 或其他衍生版模式)
     --security false            #全局禁用安全更新相关的处理逻辑
     --system normal           #构建一个标准的完整系统
     --updates false            #禁用 updates 存档(通常用于点版本更新)。进一步精简源列表

问题2:使用中科大源http://mirrors.ustc.edu.cn/debian时会有问题,疑似其对自动连接有监测,导致无法下载,问题如下,解决方法就是切换可用的源。

复制代码
lb bootstrap_debootstrap
P: Begin bootstrapping system...
P: If the following stage fails, the most likely cause of the problem is with your mirror configuration or a caching proxy.
P: Running debootstrap (download-only)...
I: Retrieving InRelease
I: Retrieving Release
E: Failed getting release file http://mirrors.ustc.edu.cn/debian/dists/bullseye/Release
E: An unexpected failure occurred, exiting...

问题3:报debian-archive-keyring.gpg错误,问题日志如下,解决方法从源中找到对应的debian-archive-keyring安装包,解压并放置于宿主机上的/usr/share/keyrings/中。

复制代码
P: Begin bootstrapping system...
P: If the following stage fails, the most likely cause of the problem is with your mirror configuration or a caching proxy.
P: Running debootstrap (download-only)...
I: Retrieving InRelease
I: Checking Release signature
E: Release signed by unknown key (key id xxxxxxx)
   The specified keyring /usr/share/keyrings/debian-archive-keyring.gpg may be incorrect or out of date.
   You can find the latest Debian release key at https://ftp-master.debian.org/keys.html
E: An unexpected failure occurred, exiting...

解决方法:

从https://mirrors.aliyun.com/debian/pool/main/d/debian-archive-keyring/debian-archive-keyring_2025.1_all.deb中下载,并手动提取.

创建解压目录:mkdir -p /tmp/keyring-extract && cd /tmp/keyring-extract

解压 .deb 包:ar x ../debian-archive-keyring_2025.1_all.deb

解压data.tar.xz获取gpg文件:tar xf data.tar.xz

并备份保留电脑上原来的keyring 将新的解压进去即可。

问题4:自定义的app组件不对导致安装出问题,问题如下,解决方法:逐一检查live.list.chroot中的自定义app。

复制代码
P: Begin bootstrapping system...
P: If the following stage fails, the most likely cause of the problem is with your mirror configuration or a caching proxy.
P: Running debootstrap (download-only)...
I: Retrieving InRelease
I: Retrieving Packages
I: Validating Packages
^CE: Interrupt caught ... exiting
W: Unexpected early exit caught, attempting cleanup...
E: An unexpected failure occurred, exiting...

问题5:自定义app名字(systemd-journald)错误在软件源上找不到,删除即可。

复制代码
P: Begin installing packages (install pass)...
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
E: Unable to locate package systemd-journald
E: An unexpected failure occurred, exiting...
P: Begin unmounting filesystems...
P: Saving caches...

问题6:配置--cache-stages true 使用错误,出现错误打印如下,删除即可。

复制代码
lb installer_chroot
P: Begin copying chroot for the installer...
cp: cannot stat 'cache/bootstrap': No such file or directory
E: An unexpected failure occurred, exiting...
P: Begin unmounting filesystems...
P: Saving caches...
chroot: cannot change root directory to 'chroot': No such file or directory
或者
P: Begin mounting /sys...
[2026-09-30 09:45:01] lb chroot_debianchroot install
P: Configuring file /etc/debian_chroot
/usr/lib/live/build/chroot_debianchroot: 47: cannot create chroot/etc/debian_chroot: Directory nonexistent
E: An unexpected failure occurred, exiting...
P: Begin unmounting filesystems...
P: Saving caches...
chroot: failed to run command '/usr/bin/env': No such file or directory

问题7:修改配置后,新配置不生效,未进行完全清除上次编译的配置,

清理后重新生成配置文件,问题如下:

复制代码
P: Setting up clean exit handler
[2026-09-29 09:17:27] lb chroot_cache restore
[2026-09-29 09:17:27] lb chroot_prep install all mode-archives-chroot
E: the following stage is required to be done first: config
E: An unexpected failure occurred, exiting...
P: Begin unmounting filesystems...
P: Saving caches...
Reading package lists... Done
Building dependency tree... Done

三、可用脚本示例:

build_rootfs.sh(下述为ubuntu jammy版本和上述debian11有区别,请注意):

复制代码
#!/bin/bash

# Live Build 自动化构建脚本
# 用于构建基于 Debian Bullseye 的 ARM64 嵌入式 RootFS
# 用法:
#   ./build_rootfs.sh          # 开始或继续编译 (lb build)
#   ./build_rootfs.sh cleanall # 完全清理项目 (lb clean --purge)

set -e

# 定义颜色输出,增强可读性
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
NC='\033[0m' # No Color

log_info() {
    echo -e "${GREEN}[INFO]${NC} $1"
}

log_warn() {
    echo -e "${YELLOW}[WARN]${NC} $1"
}

log_error() {
    echo -e "${RED}[ERROR]${NC} $1"
}

# 检查 live-build 是否安装
check_dependencies() {
    if ! command -v lb &> /dev/null; then
        log_error "live-build (lb) 未安装。请先运行: sudo apt-get install live-build"
        exit 1
    fi
    
    # 检查 qemu-user-static 是否安装,这对于交叉构建 ARM64 至关重要
    if [ ! -f "/usr/bin/qemu-aarch64-static" ]; then
        log_warn "未找到 /usr/bin/qemu-aarch64-static。"
        log_warn "如果在 x86_64 主机上构建 ARM64,请运行: sudo apt-get install qemu-user-static"
        # 不强制退出,因为用户可能在原生 ARM64 机器上构建
    fi
}

#稳定时不使用cache

#不稳定时使用cache加速编译
#     --cache true \
#	 --cache-indices true \
#	 --cache-packages true \
# 配置 Live Build 参数
configure_live_build() {
    log_info "正在配置 Live Build 参数..."
    
    export LB_BOOTSTRAP_INCLUDE="apt-transport-https gnupg"
    
    lb config \
     --mirror-bootstrap "https://mirrors.aliyun.com/ubuntu-ports/" \
     --mirror-chroot "https://mirrors.aliyun.com/ubuntu-ports/" \
     --mirror-chroot-security "https://mirrors.aliyun.com/ubuntu-ports/" \
     --mirror-binary "https://mirrors.aliyun.com/ubuntu-ports/" \
     --mirror-binary-security "https://mirrors.aliyun.com/ubuntu-ports/" \
     --apt-indices false \
     --apt-recommends false \
     --apt-secure true \
     --architecture arm64 \
     --archive-areas 'main restricted universe multiverse' \
     --backports true \
     --binary-filesystem ext4 \
     --binary-images tar \
     --bootappend-live "hostname=FSU username=root" \
     --bootstrap-qemu-arch arm64 \
     --bootstrap-qemu-static /usr/bin/qemu-aarch64-static \
     --cache true \
     --cache-indices true \
     --cache-packages true \
     --chroot-filesystem none \
     --compression gzip \
     --debootstrap-options "--variant=minbase --include=apt-transport-https,gnupg" \
     --distribution jammy \
     --gzip-options '-9 --rsyncable' \
     --linux-flavours none \
     --linux-packages none \
     --mode debian \
     --security true \
     --system normal \
     --updates false
	
    if [ $? -eq 0 ]; then
        log_info "配置成功"
    else
        log_error "配置失败"
        exit 1
    fi
	if [ -f live.list.chroot ];then
		log_info "使用 live.list.chroot .... "
		cp live.list.chroot config/package-lists/live.list.chroot 
		chmod 777 config/package-lists/live.list.chroot 
		log_info "使用 live.list.chroot 成功"
	fi
	
	cp 00*.chroot config/hooks/live 
	chmod 777 config/hooks/live/* 
	log_info "使用 00*.chroot 成功"
	log_info "自定义配置成功"

}

# 执行清理操作
do_clean() {
	log_info "正在备份 cache ..."
	if [ "$1" = "clean" ];then
		if [ -d cache ];then
			mv cache cache_bak
			log_info "备份 cache success"
		else
			log_info "无 cache 不需要备份"
		fi
	fi
	log_info "正在执行完全清理 ($1 )..."
	# --purge 会删除 config/ 目录以外的所有生成文件和缓存,彻底重置构建环境
	if [ "$1" = "cleanall" ];then
		lb clean --purge
	else
		lb clean
	fi
	
	# 额外清理可能残留的二进制目录,确保干净
	if [ -d "binary" ]; then
		rm -rf binary
		log_info "已移除 binary 目录"
	fi
	
	# 如果希望连 config 也重置,可以取消下面注释
	if [ -d "config" ]; then
		rm -rf config
		log_info "已移除 config 目录"
	fi
	if [ -d ".build" ]; then
		rm -rf .build
		log_info "已移除 .build 目录"
	fi
	if [ "$1" = "clean" ];then
		if [ -d cache_bak ];then
			mv cache_bak cache
			log_info "还原 cache success"
		fi
	fi
    log_info "清理完成。项目已重置。"
	
}

# 执行清理操作
gen_img() {
	if [ -e rootfs.img ];then
		rm rootfs.img
	fi
	if [ ! -d mnt ];then
		mkdir mnt
	fi
	if [ -d binary ];then
		size=$(du binary --max-depth=0 -m | cut -f1)
		aligned_size=$(( (size + 63) / 64 * 64 ))
		if [ $aligned_size -ge $size ];then
			echo "rootfs size:$size change to $aligned_size"
			dd if=/dev/zero of=rootfs.img bs=1M count=$aligned_size
			mkfs.ext4 -F -b 1024 -L rootfs rootfs.img
			mount rootfs.img mnt
			cp -rfpa binary/* mnt/
			sleep 2
			umount mnt
			rm mnt -R
			e2fsck -p -f rootfs.img
			resize2fs -M rootfs.img
			chmod 777 rootfs.img
			echo "build rootfs.img  success!"
		else
			echo "rootfs size:$size aligned size:$aligned_size error!"
			echo "build rootfs.img  faild!"
		fi
	else
		echo "no find binary !"
		echo "build rootfs.img  faild!"
	fi
}

# 执行构建操作
do_build() {
    log_info "检查配置是否存在..."
    
    # 如果 config 目录不存在,先进行配置
    if [ ! -d "config" ]; then
        log_warn "未找到 config/ 目录,正在初始化配置..."
        configure_live_build
		log_info "初始化配置 (lb config) 完成,请修改后进行编译 "
		exit 0
    else
        log_info "发现现有配置,将使用当前配置进行构建。"
        log_warn "如果需要更新配置,请先运行 './build_rootfs.sh cleanall' 或手动修改 config/ 下的文件。"
    fi

    log_info "开始构建镜像 (lb build)..."
    log_info "这可能需要一段时间,请耐心等待..."
    
    # 执行构建
    # live-build 会自动读取 config/ 下的配置
    lb build

    if [ $? -eq 0 ]; then
        log_info "构建成功!"
		gen_img
        log_info "生成的镜像位于 binary 目录下和 rootfs.img"
        if [ -d "binary" ]; then
            ls -lh binary/
        fi
    else
        log_error "构建失败。请检查上方日志以获取详细错误信息。"
        exit 1
    fi
}

# 主逻辑
main() {
    check_dependencies

    case "${1}" in
        cleanall)
            do_clean cleanall
            ;;
        clean)
            do_clean clean
            ;;
        config)
            configure_live_build
            ;;
        "")
            do_build
            ;;
        *)
            echo "用法: $0 [cleanall]"
            echo "  无参数   : 开始或继续编译 (lb build)"
            echo "  cleanall : 完全清理项目 (lb clean --purge)"
            exit 1
            ;;
    esac
}

main "$@"

live.list.chroot(我这边需要单独安装的软件包):

复制代码
kmod
sudo
udev
vim-tiny
tcpd
traceroute
tree
tftp-hpa
lsof
psmisc
ifupdown
iputils-ping
vsftpd
openssh-server
procps
net-tools
unzip
zip
fdisk
systemd
systemd-sysv

0001-setup-system.chroot(安装后执行的命令)

复制代码
#!/bin/sh
#1.设置用户名和密码
echo "I: set root user password"
echo "root:xxxxxx" | chpasswd
#2.修改systemd默认参数,设置日志,启动超时时间,日志输出无颜色
echo "I: modify /etc/systemd/system.conf"
sed -i 's/#LogLevel=info/LogLevel=warning/' /etc/systemd/system.conf
sed -i 's/#LogTarget=journal-or-kmsg/LogTarget=journal/' /etc/systemd/system.conf
sed -i 's/#LogColor=yes/LogColor=no/' /etc/systemd/system.conf
sed -i '/Storage/c\Storage=auto' /etc/systemd/journald.conf
sed -i '/SystemMaxUse/c\SystemMaxUse=200M' /etc/systemd/journald.conf
sed -i '/SystemMaxFileSize/c\SystemMaxFileSize=2M' /etc/systemd/journald.conf
sed -i '/MaxRetentionSec/c\MaxRetentionSec=7day' /etc/systemd/journald.conf
sed -i '/MaxFileSec/c\MaxFileSec=1week' /etc/systemd/journald.conf
sed -i '/LogColor/c\LogColor=no' /etc/systemd/system.conf
sed -i '/DefaultTimeoutStartSec/c\DefaultTimeoutStartSec=15s' /etc/systemd/system.conf
sed -i '/DefaultTimeoutStopSec/c\DefaultTimeoutStopSec=15s' /etc/systemd/system.conf

#3.设置vim兼容性问题
echo "I: modify /etc/vim/vimrc.tiny"
sed -i '/set compatible/i\set backspace=2' /etc/vim/vimrc.tiny
sed -i '/set compatible/c\set nocompatible' /etc/vim/vimrc.tiny
#4.设置主机名为FSU
echo "I: modify /etc/hostname"
echo "FSU" > /etc/hostname

#5.设置主机环境参数
echo "I: modify /etc/profile"
rm /etc/profile -f
cat > /etc/profile << 'EOF'
export PATH=\"/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\"

if [ "$PS1" ]; then
	if [ "`id -u`" -eq 0 ]; then
		export PS1='\u@\h:\w#'
	else
		export PS1='\u@\h:\w$'
	fi
fi

export TZ='CST-8' 
alias ll='ls -al'

EOF
#6.设置主机网络参数
echo "I: modify /etc/network/interfaces"

cat > /etc/profile << 'EOF'
auto lo
iface lo inet loopback

auto eth0
iface eth0 inet static
	#ipv4 net ip
	address 192.168.5.254
	#ipv4 net netmask
	netmask 255.255.255.0
	#ipv4 net gateway 
	gateway 192.168.5.1

EOF
#7.设置主机sshd允许root登录
echo "I: modify /etc/ssh/sshd_config"
sed -i '/#PermitRootLogin/c\PermitRootLogin yes' /etc/ssh/sshd_config

#8.设置emmc登陆后自动扩展分区使其容量正确
echo "I: add  /etc/my_resize2fs"
# 写入自定义/etc/my_resize2fs内容
cat > /etc/my_resize2fs << 'EOF'
#!/bin/sh

#Find the number of the mounted primary partition
mmcblk0p_list=$(lsblk | grep "/" | awk -F 'mmcblk0p' '{print $2}' | awk -F ' ' '{print $1}')
if [ -n "$mmcblk0p_list" ]; then
	echo "Execute expansion command:resize2fs begin"
	echo "$mmcblk0p_list" | while read -r line; do
		part=$(echo ${line} | sed -n 's/[^0-9]*//gp')
		if [ -n $part ]; then
			dev_name="/dev/mmcblk0p${part}"
			echo "resize2fs ${dev_name}"
			echo $(resize2fs ${dev_name})
		fi
	done
	echo "Execute expansion command:resize2fs end"
fi

exit 0
EOF
# 给rc.local添加可执行权限
chmod +x /etc/my_resize2fs

#9.设置开机自启动rc.local服务并运行/etc/rc.local脚本
echo "I: setup rc.local"

# 写入自定义rc.local内容,可按需替换为你需要的开机执行命令
cat > /etc/rc.local << 'EOF'
#!/bin/sh

echo "exe rc.local"
if [ ! -f  /etc/ssh/ssh_host_rsa_key ];then
	echo "gen sshd key...."
	/usr/bin/ssh-keygen -A
	echo "gen sshd key success"
fi

if [ -e /etc/my_resize2fs ];then
	chmod 755 /etc/my_resize2fs
	/etc/my_resize2fs
	mv /etc/my_resize2fs /etc/my_resize2fs_bak
fi

echo "exe rc.local end exit"

exit 0
EOF

# 给rc.local添加可执行权限
chmod +x /etc/rc.local

# 启用systemd下的rc.local服务
systemctl enable rc-local

#11.优化系统,关闭无关软件的运行
echo "I: setup Disable unnecessary startup services"

# 停止并禁用包列表更新定时器
systemctl disable apt-daily.timer
# 停止并禁用自动升级定时器
systemctl disable apt-daily-upgrade.timer
mkdir /etc/apt/apt.conf.d -p
cat > /etc/apt/apt.conf.d/20auto-upgrades << 'EOF'
APT::Periodic::Update-Package-Lists "0";
APT::Periodic::Unattended-Upgrade "0";
EOF

#非ssd禁用 e2scrub_all.timer 服务
systemctl disable e2scrub_all.timer
systemctl disable e2scrub_reap.service
#非ssd禁用 TRIM 指令无效 服务
systemctl disable fstrim.timer
#禁用 远程文件系统挂载服务
systemctl disable remote-fs.target

#禁用 pstore在内核崩溃时调试信息(如内核日志尾部 dmesg、堆栈回溯跟踪等)保存到非易失性存储器中
#systemctl disable systemd-pstore.service
相关推荐
byte轻骑兵1 小时前
【BlueZ 】netlink 在 BlueZ 中的应用:用户态与内核态的配置消息传递
linux·bluez·电脑蓝牙·嵌入式蓝牙
xbzb1 小时前
Nginx 反向代理总 404?Location 匹配与 proxy_pass 尾斜杠避坑手册
linux·运维·nginx·虚拟主机
Julien20042 小时前
CGroups 资源控制组
linux·运维·服务器·ssh·学习方法
皓月盈江2 小时前
Linux Debian系统安装Google Chrome谷歌浏览器教程
linux·chrome·debian·谷歌浏览器
Vcaker2 小时前
Linux学习37-rook-ceph部署
linux·运维·学习
Mortalbreeze2 小时前
MySQL 基础篇(二):数据库和数据表的基本操作
linux·服务器·数据库·mysql
阳光九叶草LXGZXJ2 小时前
Linux-学习-12-JDK安装
java·linux·运维·学习
夜听莺儿鸣13 小时前
502-003_Linux 中断与异常(一):从Linux角度理解中断与异常
linux·中断与异常·linux中断
杨云龙UP13 小时前
TDengine 3.4.2.8 Community 三节点三副本生产集群部署实战(DNode/MNode/taosAdapter/Explorer)
大数据·linux·运维·数据库·tdengine·时序库