服务与计划任务
RHEL 9 用 systemctl 管理服务,crontab 做定时任务,chrony 对时,以及 NFS 共享目录与 autofs 按需挂载。
本页目录
「服务」就是开机后一直在后台干活的程序(远程登录的 sshd、计划任务的 crond 等)。这一篇把考试高频的四件事串起来:管服务 → 定时执行 → 时间同步 → 目录共享。
系列:从 RHCSA 到 RHCE · 第 11 / 17 篇 上一篇:分区与 LVM下一篇:httpd 与 SELinux总目录:系列索引
环境说明
- 系统:RHEL 9
- 身份:root
- 前置:基础命令、用户权限;NFS 小节最好有两台互通的机器(或同一台理解概念)
1. systemctl:服务的总开关
RHEL 用 systemd 管理服务,命令是 systemctl。
七个最常用动作
| 你想… | 命令 |
|---|---|
| 看是否在跑 | systemctl status 服务名 |
| 启动 | systemctl start 服务名 |
| 停止 | systemctl stop 服务名 |
| 重启(改配置后) | systemctl restart 服务名 |
| 设为开机自启 | systemctl enable 服务名 |
| 取消开机自启 | systemctl disable 服务名 |
| 看是否开机自启 | systemctl is-enabled 服务名 |
一步「现在启动 + 开机自启」:
systemctl enable 服务名 --now
跟着做一遍(用 crond)
systemctl status crond
按 q 退出 status 界面。看关键两行:
Active: active (running)—— 正在跑Loaded: ...; enabled; ...—— 已配置开机自启
试停再开:
systemctl stop crond
systemctl status crond
systemctl start crond
systemctl is-enabled crond
systemctl disable crond
systemctl enable crond
| 状态词 | 含义 |
|---|---|
| active (running) | 正在运行 |
| inactive (dead) | 没在跑 |
| enabled | 开机会自动起 |
| disabled | 开机不会自动起 |
考点:改完配置文件要
restart(或reload,若服务支持);只改文件不重启,往往「看起来没生效」。 易错:start只解决「这一次」;忘了enable,重启机器服务又没了。
2. 计划任务:cron
它是什么
让系统在固定时间自动执行命令,例如:
- 每天凌晨 3 点清理
/tmp - 每周五备份
- 每隔 5 分钟写一条日志(练习用)
背后是 crond 服务——所以要先保证它在跑:
systemctl enable crond --now
systemctl status crond
时间格式(必背)
分 时 日 月 周 要执行的命令
| 字段 | 范围 | 说明 |
|---|---|---|
| 分 | 0–59 | |
| 时 | 0–23 | |
| 日 | 1–31 | |
| 月 | 1–12 | |
| 周 | 0–7 | 0 和 7 常都表示周日 |
| 写法 | 含义 |
|---|---|
| * | 每一个(每分/每时…) |
| */5 | 每隔 5 个单位 |
| 5 3 * * * | 每天 3:05 |
例子:
12 12 12 12 * 命令 → 每年 12 月 12 日 12:12
12 12 * * * 命令 → 每天 12:12
12 * * * * 命令 → 每小时第 12 分
* * * * * 命令 → 每分钟
*/5 * * * * 命令 → 每隔 5 分钟
写一条计划任务
编辑当前用户的任务表:
crontab -e
VIM 里加入一行(练习:每隔 5 分钟往系统日志写一句话):
*/5 * * * * logger "hello rhcsa"
保存退出。查看:
crontab -l
指定用户:
crontab -e -u root
crontab -l -u root
怎么验证真的执行了
logger 会往系统日志写一行:
logger "manual test"
grep "hello rhcsa" /var/log/messages
# 或
grep "manual test" /var/log/messages
等几分钟再 grep,应能看到 cron 自动写入的记录(具体日志文件名因环境而异,也可能是 journalctl)。
journalctl -t logger --no-pager | tail
易错:
crond没启动,任务永远不跑。 易错:时间字段写反(分在前,不是年)。 易错:命令没写绝对路径时,cron 的环境 PATH 很精简——考试题面一般给完整命令;保险时用/usr/bin/logger这类绝对路径。
3. 时间同步:chrony
多台机器时间差太多,日志和证书都会出问题。RHEL 9 用 chrony 做 NTP 同步。
客户端配置(把本机时间对准某台时间服务器)
dnf -y install chrony
vim /etc/chrony.conf
在文件开头附近加一行(IP 换成你的时间服务器):
server 192.168.56.1 iburst
| 关键字 | 含义 |
|---|---|
| server | 我要向谁对时 |
| iburst | 刚启动时尽快多测几次,加速同步 |
systemctl enable chronyd --now
date
chronyc sources
看 chronyc sources 第一列:
| 符号 | 含义 |
|---|---|
| ^* | 当前正用这个源,同步成功 |
| ^? | 还不可用 / 未同步上 |
^* server1.lab0.example.com 10 6 37 52 ...
故意改错时间再同步(加深理解)
date
date -s "01:22:00"
date
# 等 chrony 同步,或重启 chronyd
systemctl restart chronyd
sleep 5
date
chronyc sources
考点:改
/etc/chrony.conf后systemctl enable chronyd --now,用chronyc sources看^*。 练习环境:课堂常把server1配成 NTP 服务端,客户端server指向它的 IP;步骤与本文相同。
服务端概念(了解即可)
时间服务器会在 chrony.conf 里写类似:
allow 172.25.0.0/24
local stratum 10
表示:允许哪个网段来对时;自己作为第几层时间源。考试若只做客户端,可略过。
4. NFS:把目录共享出去
它是什么
NFS(Network File System)让一台机器把某个目录「借」给别的机器挂载使用,看起来就像本地目录。
角色:
| 角色 | 干什么 |
|---|---|
| 服务端 | 安装 nfs-utils,配置 /etc/exports,启动 nfs-server |
| 客户端 | 安装 nfs-utils,把服务端目录挂到自己的目录上 |
下面服务端 IP 记为 192.168.56.1,共享目录 /rhome/ldapuser0(名字可自定义)。
4.1 服务端
dnf -y install nfs-utils
mkdir -p /rhome/ldapuser0
vim /etc/exports
一行配置:
/rhome/ldapuser0 *(rw)
| 部分 | 含义 |
|---|---|
| 第 1 列 | 共享哪个目录 |
| 第 2 列 | 谁可以访问(* 所有人;也可写 IP/网段) |
| rw / ro | 可读写 / 只读 |
练习时若希望客户端 root 也能直接写(默认有 root_squash,客户端 root 会被「压」成匿名用户,可能没权限写),可在服务端目录放开写权限,或在 exports 里加 no_root_squash(考试按题面要求即可):
chmod o+w /rhome/ldapuser0
# 或 exports 写成:/rhome/ldapuser0 *(rw,no_root_squash)
systemctl enable nfs-server --now
exportfs -v
4.2 客户端:永久挂载(写 fstab)
dnf -y install nfs-utils
mkdir -p /data
vim /etc/fstab
192.168.56.1:/rhome/ldapuser0 /data nfs defaults,_netdev 0 0
_netdev 表示这是网络设备,等网络就绪再挂,比只写 defaults 更稳妥。
mount -a
df -h
ls /data
和本地分区挂载很像,只是「设备」写成了 服务器IP:路径,类型是 nfs。
测试写入(服务端若给的是 rw,且目录权限允许):
touch /data/from-client.txt
ls /data
若报 Permission denied:多半是服务端目录权限或 root_squash,回到服务端 chmod o+w 或按题面调整 exports。
卸载:
umount /data
4.3 客户端:autofs 按需挂载(考试常见)
写 fstab 是「开机就挂」。autofs 是「你一 cd 进去才挂,用完可自动卸」。
dnf -y install autofs
vim /etc/auto.master
在开头加一行:
/rhome /etc/auto.rule
| 第 1 列 | 挂载点父目录(如 /rhome,不必事先 mkdir) | | 第 2 列 | 规则文件路径(自定义文件名) |
新建规则文件:
vim /etc/auto.rule
ldapuser0 -fstype=nfs,rw 192.168.56.1:/rhome/ldapuser0
| 部分 | 含义 |
|---|---|
| ldapuser0 | 客户端将出现 /rhome/ldapuser0 |
| -fstype=nfs,rw | 类型与读写 |
| 最后一列 | 服务端的哪条共享 |
systemctl enable autofs --now
验证:
ls /rhome # 可能看不到子目录,属正常
cd /rhome/ldapuser0 # 触发挂载
ls
考点:fstab 永久挂 vs autofs 按需挂;auto.master 与自定义 rule 文件的两行配置。 易错:rule 文件路径和 auto.master 里写的不一致。 易错:服务端没启
nfs-server,客户端mount -a失败。
5. 推荐练习路径
A. 服务(10 分钟)
systemctl status crond
systemctl stop crond
systemctl status crond
systemctl start crond
systemctl is-enabled crond
systemctl enable crond --now
B. cron(15 分钟)
systemctl enable crond --now
crontab -e
# 加入:*/5 * * * * logger "hello rhcsa"
crontab -l
# 等 5 分钟后:
grep hello /var/log/messages || journalctl --no-pager | tail -20
C. chrony(15 分钟,需有时间源)
date -s "01:22:00"
date
# 确认 chrony.conf 有 server 行后
systemctl restart chronyd
sleep 8
date
chronyc sources
# 若时间差很大仍对不齐,可强制步进一次:
chronyc makestep
date
D. NFS(20 分钟,双机)
- 服务端:exports +
nfs-server --now - 客户端:fstab 或 autofs
df -h看到 NFS 行,touch测试
6. 速查表
| 目标 | 命令/文件 |
|---|---|
| 服务状态/启停 | systemctl status/start/stop/restart 服务 |
| 开机自启 | systemctl enable/disable 服务 |
| 现在+开机 | systemctl enable 服务 --now |
| 编辑计划任务 | crontab -e / crontab -l |
| 时间五段 | 分 时 日 月 周 命令 |
| 时间同步 | /etc/chrony.conf + chronyc sources |
| NFS 导出 | /etc/exports + nfs-server |
| 客户端挂 NFS | fstab 或 autofs(/etc/auto.master + rule) |
考点与易错
考点:
systemctl启停与自启;cron 五段;chrony 的server ... iburst与^*;NFS exports 与客户端 fstab/autofs。 易错:只start不enable,重启后服务消失。 易错:cron 分钟/小时顺序写反。 易错:改了 chrony.conf 不 restart chronyd。 易错:autofs 规则里 IP/路径与服务端 exports 不一致。 练习环境:课堂 NTP/NFS 服务端若是server1,客户端配置里的 IP 换成题面地址即可。
小结
- 服务用
systemctl:running 管这一次,enabled 管开机。 - 定时用
crontab:记住 分 时 日 月 周;先保证crond在跑。 - 对时用 chrony:
server x.x.x.x iburst,chronyc sources看^*。 - 共享用 NFS:服务端
/etc/exports,客户端 fstab 永久挂或 autofs 按需挂。
下一篇搭 Web 服务,并处理「网页打不开」时的防火墙与 SELinux。
系列导航:总目录 · 上一篇:分区与 LVM · 下一篇:httpd 与 SELinux