Post

🟒 πŸ‡©πŸ‡ͺ Skrime VPS IPV6 Only

🟒 πŸ‡©πŸ‡ͺ Skrime VPS IPV6 Only

Skrime - ParamΓ©trage

Double authentification

EPYC KVM Server

VPS EPYC KVM Server 1G debian

  • 1 vCPU Cores
  • 1 GB RAM
  • 10 GB Nvme
  • IPv4: AUCUNE
  • IPv6: 2a14:7c0:1002:19a8::
  • Gateway: 2a14:7c0:1000::
  • OS: Debian 13

On se connecte en root sur le VPS

1
ssh root@2a14:7c0:1002:19a8::

Date et heure + Synchro

Activer le fuseau Europe/Paris

1
timedatectl set-timezone Europe/Paris

Horloge système synchronisée : timedatectl

1
2
3
4
5
6
7
               Local time: Mon 2026-09-14 15:33:09 CEST
           Universal time: Mon 2026-09-14 13:33:09 UTC
                 RTC time: Mon 2026-09-14 13:33:09
                Time zone: Europe/Paris (CEST, +0200)
System clock synchronized: yes
              NTP service: active
          RTC in local TZ: no

Reconfigurer locales

Activer uniquement en_US.UTF-8 et fr_FR.UTF-8

1
dpkg-reconfigure locales

Default en_US.UTF-8

1
2
3
Generating locales (this might take a while)...
  fr_FR.UTF-8... done
Generation complete.

Motd

Motd (ASCII Small Mono 12 )

1
nano /etc/motd
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
 β–—β–„β–– β–—β––        β–ˆ               β–—β–– β–—β––β–—β–„β–„β––  β–—β–„β––    β–„β–„β–„β–—β–„β–„β–– β–—β–– β–—β––β–—β–„β––         
β–—β–›β–€β–œ β–β–Œ        β–€               β–β–ˆ β–ˆβ–˜β–β–›β–€β–œβ––β–—β–›β–€β–œ    β–€β–ˆβ–€β–β–›β–€β–œβ––β–β–ˆ β–ˆβ–˜β–ˆβ–€β–œ         
▐▙   β–β–Œβ–Ÿβ–› β–ˆβ–Ÿβ–ˆβ–Œβ–ˆβ–ˆ  β–β–ˆβ–™β–ˆβ–– β–Ÿβ–ˆβ–™     β–ˆ β–ˆ β–β–Œ β–β–Œβ–β–™       β–ˆ β–β–Œ β–β–Œ β–ˆ β–ˆβ–β–Œβ–„β––         
 β–œβ–ˆβ–™ β–β–™β–ˆ  β–ˆβ–˜   β–ˆ  β–β–Œβ–ˆβ–β–Œβ–β–™β–„β–Ÿβ–Œ    β–ˆ β–ˆ β–β–ˆβ–ˆβ–›  β–œβ–ˆβ–™     β–ˆ β–β–ˆβ–ˆβ–›  β–ˆ β–ˆβ–β–ˆβ–€β–ˆβ––        
   β–œβ–Œβ–β–›β–ˆβ–– β–ˆ    β–ˆ  β–β–Œβ–ˆβ–β–Œβ–β–›β–€β–€β–˜    β–β–ˆβ–Œ β–β–Œ      β–œβ–Œ    β–ˆ β–β–Œ    β–β–ˆβ–Œβ–β–Œ β–β–Œ        
β–β–„β–„β–Ÿβ–˜β–β–Œβ–β–™ β–ˆ  β–—β–„β–ˆβ–„β––β–β–Œβ–ˆβ–β–Œβ–β–ˆβ–„β–„β–Œ    β–β–ˆβ–Œ β–β–Œ   β–β–„β–„β–Ÿβ–˜   β–„β–ˆβ–„β–β–Œ    β–β–ˆβ–Œβ–β–ˆβ–„β–ˆβ–˜        
 β–€β–€β–˜ β–β–˜ β–€β–˜β–€  β–β–€β–€β–€β–˜β–β–˜β–€β–β–˜ ▝▀▀     β–β–€β–˜ β–β–˜    β–€β–€β–˜    β–€β–€β–€β–β–˜    β–β–€β–˜ β–β–€β–˜         
β–—β–„β–„       β–—β––     β–ˆ                β–—β–„   β–„β–„β––                                
β–β–›β–€β–ˆ      β–β–Œ     β–€                β–›β–ˆ  β–β–€β–€β–ˆβ––                               
β–β–Œ β–β–Œ β–Ÿβ–ˆβ–™ β–β–™β–ˆβ–™  β–ˆβ–ˆ   β–Ÿβ–ˆβ–ˆβ––β–β–™β–ˆβ–ˆβ––     β–ˆ     β–Ÿβ–Œ                               
β–β–Œ β–β–Œβ–β–™β–„β–Ÿβ–Œβ–β–› β–œβ–Œ  β–ˆ   β–˜β–„β–Ÿβ–Œβ–β–› β–β–Œ     β–ˆ   β–β–ˆβ–ˆ                                
β–β–Œ β–β–Œβ–β–›β–€β–€β–˜β–β–Œ β–β–Œ  β–ˆ  β–—β–ˆβ–€β–œβ–Œβ–β–Œ β–β–Œ     β–ˆ     β–œβ–Œ                               
β–β–™β–„β–ˆ β–β–ˆβ–„β–„β–Œβ–β–ˆβ–„β–ˆβ–˜β–—β–„β–ˆβ–„β––β–β–™β–„β–ˆβ–Œβ–β–Œ β–β–Œ   β–—β–„β–ˆβ–„β––β–β–„β–„β–ˆβ–˜                               
▝▀▀   ▝▀▀ β–β–˜β–€β–˜ β–β–€β–€β–€β–˜ β–€β–€β–β–˜β–β–˜ β–β–˜   β–β–€β–€β–€β–˜ β–€β–€β–˜                                
 β–„β–„β––       β–—β–„  β–—β–„β–—β–„β–„β–„β––     β–—β–„β––   β–—β–„  β–—β–„β––  β–—β–„β–– β–„β–„β––   β–—β–„  β–—β–„β––       β–—β–„β––     
β–β–€β–€β–ˆβ––      β–›β–ˆ  β–Ÿβ–ˆβ–β–€β–€β–ˆβ–Œ     β–ˆβ–€β–ˆ   β–›β–ˆ  β–ˆβ–€β–ˆ  β–ˆβ–€β–ˆβ–β–€β–€β–ˆβ––  β–›β–ˆ β–—β–ˆβ–€β–ˆβ––     β–—β–ˆβ–€β–ˆβ––    
   β–β–Œ β–Ÿβ–ˆβ–ˆβ––  β–ˆ β–β–˜β–ˆβ–„ β–—β–ˆ β–Ÿβ–ˆβ–ˆβ––β–β–Œ β–β–Œβ–„  β–ˆ β–β–Œ β–β–Œβ–β–Œ β–β–Œ  β–β–Œβ–„  β–ˆ β–β–Œ β–β–Œ β–Ÿβ–ˆβ–ˆβ––β–β–™ β–Ÿβ–Œβ–„β–„  
  β–—β–›  β–˜β–„β–Ÿβ–Œ  β–ˆβ–—β–› β–ˆβ–ˆ β–β–Œβ–β–›  β–˜β–β–Œβ–ˆβ–β–Œβ–ˆ  β–ˆ β–β–Œβ–ˆβ–β–Œβ–β–Œβ–ˆβ–β–Œ β–—β–› β–ˆ  β–ˆ β–β–ˆβ–„β–ˆβ–Œ β–˜β–„β–Ÿβ–Œ β–ˆβ–ˆβ–ˆ β–ˆβ–ˆ  
 β–—β–›  β–—β–ˆβ–€β–œβ–Œ  β–ˆβ–β–ˆβ–ˆβ–ˆβ–Œ β–ˆ β–β–Œ   β–β–Œ β–β–Œ   β–ˆ β–β–Œ β–β–Œβ–β–Œ β–β–Œβ–—β–›     β–ˆ  β–β–€β–β–Œβ–—β–ˆβ–€β–œβ–Œβ–β–› β–œβ–Œ    
β–—β–ˆβ–„β–„β––β–β–™β–„β–ˆβ–Œβ–—β–„β–ˆβ–„β–– β–ˆβ–ˆβ–β–Œ β–β–ˆβ–„β–„β–Œ β–ˆβ–„β–ˆ β–ˆβ–—β–„β–ˆβ–„β––β–ˆβ–„β–ˆ  β–ˆβ–„β–ˆβ–—β–ˆβ–„β–„β––β–ˆβ–—β–„β–ˆβ–„β––β–™β–„β–ˆ β–β–™β–„β–ˆβ–Œβ–β–ˆβ–„β–ˆβ–˜β–ˆβ–ˆ  
β–β–€β–€β–€β–˜ β–€β–€β–β–˜β–β–€β–€β–€β–˜ β–€β–€β–€   ▝▀▀  β–β–€β–˜ β–€β–β–€β–€β–€β–˜β–β–€β–˜  β–β–€β–˜β–β–€β–€β–€β–˜β–€β–β–€β–€β–€β–˜β–β–€β–˜  β–€β–€β–β–˜ β–β–€β–˜ β–€β–€  

CrΓ©er un utilisateur

crΓ©er le premier utilisateur avec mot de passe

1
adduser skim

Ajout Γ  sudoers

1
2
3
apt install sudo   # installΓ© par dΓ©faut
#
echo "skim     ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers.d/10-skim

Pour lire le journal système

1
usermod -a -G adm skim

Hostname

1
hostnamectl
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
 Static hostname: vm9471
       Icon name: computer-vm
         Chassis: vm πŸ–΄
      Machine ID: 7ad5bfee2fd84522a0cffd4bd115bbe4
         Boot ID: 0ffd571b93f3496f9e5d9bc852d38078
    Product UUID: 7ad5bfee-2fd8-4522-a0cf-fd4bd115bbe4
  Virtualization: kvm
Operating System: Debian GNU/Linux 13 (trixie)                
          Kernel: Linux 6.12.107+deb13-cloud-amd64
    Architecture: x86-64
 Hardware Vendor: QEMU
  Hardware Model: Standard PC _i440FX + PIIX, 1996_
Firmware Version: rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org
   Firmware Date: Tue 2014-04-01
    Firmware Age: 12y 5month 2w                               

RedΓ©marrage VPS

RedΓ©marrer le VPS

1
systemctl reboot

OpenSSH, clΓ© et script

A - Ordinateur de bureau

GΓ©nΓ©rer une paire de clΓ© curve25519-sha256 (ECDH avec Curve25519 et SHA2) pour une liaison SSH avec le serveur.

1
ssh-keygen -t ed25519 -o -a 100 -f ~/.ssh/skrime-ed25519

Envoyer les clΓ©s publiques sur le serveur KVM

1
ssh-copy-id -i ~/.ssh/skrime-ed25519.pub skim@2a14:7c0:1002:19a8::

B - Serveur KVM

On se connecte via SSH

1
ssh skim@2a14:7c0:1002:19a8::

Modifier la configuration serveur SSH dans le VPS

1
sudo nano /etc/ssh/sshd_config.d/10-skim.conf

Ajouter

1
2
3
4
Port 51002
PasswordAuthentication no
PermitRootLogin no
X11Forwarding no

Relancer le serveur

1
sudo systemctl restart sshd

Test connexion depuis ordinateur de bureau

1
ssh -p 51002 -i ~/.ssh/skrime-ed25519 skim@2a14:7c0:1002:19a8::

Historique de la ligne de commande

Ajoutez la recherche d’historique de la ligne de commande au terminal Se connecter en utilisateur debian Tapez un dΓ©but de commande prΓ©cΓ©dent, puis utilisez shift + up (flΓ¨che haut) pour rechercher l’historique filtrΓ© avec le dΓ©but de la commande.

1
2
3
# Global, tout utilisateur
echo '"\e[1;2A": history-search-backward' | sudo tee -a /etc/inputrc
echo '"\e[1;2B": history-search-forward' | sudo tee -a /etc/inputrc

Outils

Installer les outils

1
2
sudo apt update
sudo apt install rsync jq

Parefeu UFW

Installation Debian / Ubuntu

1
sudo apt install ufw

Pour faire gΓ©rer IPv6 par UFW uniquement, activez IPv6 dans UFW, puis dΓ©sactivez la partie IPv4 d’UFW.

Γ‰ditez la configuration :

1
sudo nano /etc/default/ufw

VΓ©rifiez ou modifiez :

1
IPV6=yes

Désactivez UFW avant de modifier ses règles :

1
sudo ufw disable

Les règles

1
2
sudo ufw allow 51002/tcp  # port SSH
sudo ufw allow https      # port 443

Activer le parefeu

1
sudo ufw enable

Command may disrupt existing ssh connections. Proceed with operation (y|n)? y

Firewall is active and enabled on system startup

VΓ©rifier : sudo ufw status

1
2
3
4
5
6
7
8
Status: active

To                         Action      From
--                         ------      ----
51002/tcp                  ALLOW       Anywhere                  
443                        ALLOW       Anywhere                  
51002/tcp (v6)             ALLOW       Anywhere (v6)             
443 (v6)                   ALLOW       Anywhere (v6)             

Agent beszel

Beszel, c'est le nom d'une solution de supervision open source qui se distingue par sa légèreté et sa simplicité de déploiement.

Lien Agent beszel VPS IPV6 only

chirpy.xoyize.xyz

Zone DNS OVH xoyize.xyz

Ajout IPV6 domaine chirpy.xoyize.xyz

1
2
3
4
5
6
7
8
9
$TTL 3600
@	IN SOA dns106.ovh.net. tech.ovh.net. (2089402221 86400 3600 3600000 60)
        IN NS     dns106.ovh.net.
        IN NS     ns106.ovh.net.
        IN A     164.132.198.38
        IN AAAA     2001:41d0:404:200::7ec4
*        IN A     164.132.198.38
*        IN AAAA     2001:41d0:404:200::7ec4
chirpy        IN AAAA     2a14:7c0:1002:19a8::

Caddy

Installer serveur caddy

1
sudo apt install caddy

On va crΓ©er un dossier local

1
2
sudo mkdir -p /srv/media/chirpy
sudo chown $USER:$USER /srv/media/chirpy

Dans le fichier de configuration /etc/caddy/Caddyfile, ajouter les lignes suivantes

1
2
3
4
chirpy.xoyize.xyz {
root * /srv/media/chirpy/
file_server
}

RedΓ©marrer le serveur

1
sudo systemctl restart caddy

Lien https://chirpy.xoyize.xyz

Cet article est sous licence CC BY 4.0 par l'auteur.