# 安装指南是否应告知用户先运行 apt update 和 apt upgrade？

**URL:** https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106
**Category:** Self-hosting
**Created:** [2021 年10 月 26 日 09:59 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106 "2021-10-26T09:59:28Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### 作者： ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### 发布日期： [2021 年10 月 26 日 09:59 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/1 "2021-10-26T09:59:28Z")

</div>

继续讨论来自 [自托管实例的问题](https://meta.discourse.org/t/problem-with-self-hosted-instance/207088)：

我觉得这种情况已经见过太多次了：人们按照安装指南操作后，回来反馈说安装失败。

依我之见，如果在安装指南中添加一个步骤，在安装前运行 `apt update` 和 `apt upgrade`，就能在问题出现之前解决它。

运行这些命令不会造成任何损害，反而有助于在创建 Docker 容器等之前确保软件是最新的。

大家对此有什么看法吗？

---

<div class="post-metadata">

### 作者： ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### 发布日期： [2021 年10 月 26 日 11:47 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/2 "2021-10-26T11:47:53Z")

</div>

添加一些关于如何设置自动升级的内容是个不错的主意。

---

<div class="post-metadata">

### 作者： ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### 发布日期： [2021 年10 月 26 日 11:54 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/3 "2021-10-26T11:54:25Z")

</div>

好的，我想建议这个

 ![image](https://global.discourse-cdn.com/meta/original/3X/8/0/80b64ba9cbb488a2eca6c9bf63df4723189b987d.png)

---

<div class="post-metadata">

### 作者： ![osioke](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/osioke/32/238946_2.png) [@osioke](https://meta.discourse.org/u/osioke)
#### 发布日期： [2021 年10 月 26 日 13:01 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/4 "2021-10-26T13:01:56Z")

</div>

那太棒了！请为此提交一个 PR 🙂

---

<div class="post-metadata">

### 作者： ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### 发布日期： [2021 年10 月 26 日 13:04 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/5 "2021-10-26T13:04:15Z")

</div>

> <https://github.com/discourse/discourse/pull/14719>
>
> install-cloud.md file update

---

<div class="post-metadata">

### 作者： ![leonardo](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/leonardo/32/228634_2.png) [@leonardo](https://meta.discourse.org/u/leonardo)
#### 发布日期： [2021 年10 月 27 日 13:29 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/8 "2021-10-27T13:29:15Z")

</div>

嗨，Gavin！  
我在 PR 上留了一条小评论，方便时请查看。  
除此之外，看起来不错。谢谢你修复了那个漏洞 🙂

---

<div class="post-metadata">

### 作者： ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### 发布日期： [2021 年10 月 27 日 13:32 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/9 "2021-10-27T13:32:53Z")

</div>

我没看到评论，只看到编辑

我眼花了吗？

---

<div class="post-metadata">

### 作者： ![leonardo](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/leonardo/32/228634_2.png) [@leonardo](https://meta.discourse.org/u/leonardo)
#### 发布日期： [2021 年10 月 27 日 13:35 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/10 "2021-10-27T13:35:42Z")

</div>

抱歉——我已经很久没用过 GitHub 的审查系统了。我的审查一直处于待处理状态：🙃  
您现在应该能看到它了。

---

<div class="post-metadata">

### 作者： ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### 发布日期： [2021 年10 月 27 日 13:42 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/11 "2021-10-27T13:42:24Z")

</div>

别担心 🙂

我已经做了修改。

谢谢 🙂

---

<div class="post-metadata">

### 作者： ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### 发布日期： [2021 年10 月 27 日 15:15 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/12 "2021-10-27T15:15:52Z")

</div>

> [@IAmGav](#):
>
> 我觉得这种情况见过太多次了：人们按照安装指南操作，然后回来反馈说安装没有成功。
> 
> 依我之见，如果在安装指南的安装步骤之前增加一个章节，要求先运行 `apt update` 和 `apt upgrade`，就能在问题出现之前就将其解决。

这属于_非 sequitur_（推论不相关）。

你能给出任何可复现的问题，证明这个额外步骤能切实解决吗？

---

<div class="post-metadata">

### 作者： ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### 发布日期： [2021 年10 月 28 日 09:38 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/13 "2021-10-28T09:38:26Z")

</div>

稍微相关的是，我发现看到“恭喜，您已安装 Discourse！🎉”屏幕时，兴奋之情让我暂时忘记了指南的其余部分。🙂 我最终想起了“安装后维护”，但或许在“访问您的云服务器”和“安装 Discourse”之间可以添加一个“准备您的云服务器（可选）”部分？该部分可以包含 dpkg-reconfigure -plow unattended-upgrades、apt install libpam-cracklib 和 fail2ban 的相关信息，以及 apt-get update/upgrade 等内容。

---

<div class="post-metadata">

### 作者： ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### 发布日期： [2021 年10 月 28 日 11:36 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/14 "2021-10-28T11:36:01Z")

</div>

> [@Falco](#):
>
> 你能给我一个可重现的问题，说明这个额外步骤在实际中能解决什么吗？

我表示怀疑。

> [@JammyDodger](#):
>
> 或许可以有一个“准备您的云服务器”的指南。

这主意不错。也许可以指向一些其他人已经在维护的相关指南。

编辑：而且，找到一个只需做 5 件事而不是 25 件事的指南，看起来会是个挑战。

我认为主要是以下几点：

- 配置 apt 以实现自动升级和重启
- 安装 fail2ban（不过如果没有 SSH 密码访问权限，我不确定它是否必要）
- 确保 SSH 不允许密码登录（现在 Digital Ocean 提供了无需密码的专用 Shell 控制台，这要容易得多）

---

<div class="post-metadata">

### 作者： ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### 发布日期： [2021 年10 月 28 日 12:53 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/15 "2021-10-28T12:53:17Z")

</div>

防火墙信息怎么样？

- 如果您需要或想要默认防火墙，请在 Ubuntu 上启用 ufw，或在 CentOS/RHEL 上使用 firewalld。

---

<div class="post-metadata">

### 作者： ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### 发布日期： [2021 年10 月 28 日 12:59 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/16 "2021-10-28T12:59:24Z")

</div>

如果您需要或想要防火墙，您可以在其他地方了解相关信息。

---

<div class="post-metadata">

### 作者： ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### 发布日期： [2021 年10 月 28 日 13:13 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/17 "2021-10-28T13:13:29Z")

</div>

我必须向您在此方面的丰富经验致敬，但我最初的设想是将这些内容从现有的 [安装后维护](https://github.com/discourse/discourse/blob/main/docs/INSTALL-cloud.md#post-install-maintenance) 部分移至 [安装 Discourse](https://github.com/discourse/discourse/blob/main/docs/INSTALL-cloud.md#install-discourse) 上方的一个新章节，以便使其更加显眼、不易被忽略。（至少对我来说，一旦看到屏幕上出现 🎉，我立刻就把服务器抛在脑后，只想去探索我的新玩具 🙂）

> ### 准备您的云服务器（可选）
> 
> - 我们强烈建议您为操作系统启用自动安全更新。在 Ubuntu 上，请使用 `dpkg-reconfigure -plow unattended-upgrades` 命令。在 CentOS/RHEL 上，请使用 `yum-cron` 包。
> - 如果您使用的是密码而非 SSH 密钥，请务必设置强 root 密码。在 Ubuntu 上，请使用 `apt install libpam-cracklib` 包。我们还推荐使用 fail2ban，它会在 IP 地址尝试超过 3 次密码重试时将其封锁 10 分钟。  
> Ubuntu: `apt install fail2ban`  
> CentOS/RHEL: `sudo dnf install fail2ban`
> - 如果您需要或想要默认防火墙，请在 Ubuntu 上启用 ufw，或在 CentOS/RHEL 上使用 firewalld。

我不够了解，无法推荐具体的删减或补充内容。🙂

---

<div class="post-metadata">

### 作者： ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)
#### 发布日期： [2021 年10 月 28 日 13:15 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/18 "2021-10-28T13:15:52Z")

</div>

> [@JammyDodger](#):
>
> 最初的设想是将这些内容从现有的 [安装后维护](https://github.com/discourse/discourse/blob/main/docs/INSTALL-cloud.md#post-install-maintenance) 部分移至 [安装 Discourse](https://github.com/discourse/discourse/blob/main/docs/INSTALL-cloud.md#install-discourse) 上方的一个新章节，以使其更加显眼、不易被忽略。

哈哈。好吧，显然我也没有阅读它们。🤷‍♂️

但根据我的经验，你很难让人去阅读某些内容。

---

<div class="post-metadata">

### 作者： ![Jonathan5](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jonathan5/32/197134_2.png) [@Jonathan5](https://meta.discourse.org/u/Jonathan5)
#### 发布日期： [2021 年10 月 28 日 19:12 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/19 "2021-10-28T19:12:14Z")

</div>

这里需要执行 `git pull` 吗？

```plaintext
cd /var/discourse
git pull
./launcher rebuild app

```

我希望不需要，因为我从未这样做过。它似乎是重建过程的一部分。

---

<div class="post-metadata">

### 作者： ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### 发布日期： [2021 年10 月 28 日 19:14 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/20 "2021-10-28T19:14:09Z")

</div>

我也从未使用过 `git pull`

我得到的是

```plaintext
root@discourse-testing:~# cd /var/discourse/
root@discourse-testing:/var/discourse# git pull
Already up to date.
root@discourse-testing:/var/discourse#

```

---

<div class="post-metadata">

### 作者： ![IAmGav](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/iamgav/32/235598_2.png) [@IAmGav](https://meta.discourse.org/u/IAmGav)
#### 发布日期： [2021 年10 月 28 日 19:53 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/22 "2021-10-28T19:53:53Z")

</div>

@Falco

所以我重新构建了测试 Droplet

 ![image](https://global.discourse-cdn.com/meta/original/3X/7/2/72fa3eae5cdb6db4cd8ebe7af12a4346af51c280.png)

我严格按照官方安装指南操作。

但安装失败了。

 ![image](https://global.discourse-cdn.com/meta/original/3X/6/5/6532f162f410222d53228c10000192b717bc53bf.png)

我运行了

```plaintext
apt-get update
apt-get upgrade
./launcher rebuild app

```

安装成功。

 ![image](https://global.discourse-cdn.com/meta/original/3X/e/3/e3a24be6291cc4308f49f8817742c2d7e6e3a220.png)

---

<div class="post-metadata">

### 作者： ![Jonathan5](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jonathan5/32/197134_2.png) [@Jonathan5](https://meta.discourse.org/u/Jonathan5)
#### 发布日期： [2021 年10 月 28 日 21:27 UTC](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106/23 "2021-10-28T21:27:59Z")

</div>

> [@merefield](#):
>
> 并非总是必要，但这是为了获取更新：[discourse/discourse\_docker: Discourse 的 Docker 镜像 (github.com)](https://github.com/discourse/discourse_docker)？

您 **确定** 这不是作为重建过程的一部分自动完成的吗？为了保险起见，我已经将其添加到了我的待办事项列表中，但如果做了任何不必要的额外工作，那将是一种遗憾。

[下一页](https://meta.discourse.org/t/should-the-install-guide-tell-people-to-run-apt-update-apt-upgrade-first/207106.md?page=2)
