MySQL SQL审核平台 inception+archer2.0(亲测)
docker run -d --privileged -v `pwd`/archer_data:/data -p 9306:3306 --name archer --hostname archer --net staticnet --ip 192.168.0.200 eiki/mysql:5.7.24 /usr/sbin/init
docker run -d --privileged -v `pwd`/archer_data:/data -p 9307:3306 -p 9123:9123 --name archer2 --hostname archer2 --net staticnet --ip 192.168.0.201 eiki/mysql:5.7.24 /usr/sbin/init
安装SQLAdvisor
1下载软件包
2 解压tar包
[root@archer5 soft]# tar -xvf Percona-Server-5.6.29-76.2-rddf26fe-el6-x86_64-bundle.tar
Percona-Server-56-debuginfo-5.6.29-rel76.2.el6.x86_64.rpm
Percona-Server-client-56-5.6.29-rel76.2.el6.x86_64.rpm
Percona-Server-devel-56-5.6.29-rel76.2.el6.x86_64.rpm
Percona-Server-server-56-5.6.29-rel76.2.el6.x86_64.rpm
Percona-Server-shared-56-5.6.29-rel76.2.el6.x86_64.rpm
Percona-Server-test-56-5.6.29-rel76.2.el6.x86_64.rpm
Percona-Server-tokudb-56-5.6.29-rel76.2.el6.x86_64.rpm
3 安装
[root@archer5 soft]# yum localinstall Percona-Server-shared-56-5.6.29-rel76.2.el6.x86_64.rpm
[root@archer5 soft]# yum localinstall Percona-Server-client-56-5.6.29-rel76.2.el6.x86_64.rpm
[root@archer5 soft]# yum localinstall Percona-Server-server-56-5.6.29-rel76.2.el6.x86_64.rpm
PLEASE REMEMBER TO SET A PASSWORD FOR THE MySQL root USER !
To do so, start the server, then issue the following commands:
/usr/bin/mysqladmin -u root password 'new-password'
/usr/bin/mysqladmin -u root -h archer5 password 'new-password'
Alternatively you can run:
/usr/bin/mysql_secure_installation
which will also give you the option of removing the test
databases and anonymous user created by default. This is
strongly recommended for production servers.
See the manual for more instructions.
Please report any problems at
https://bugs.launchpad.net/percona-server/+filebug
The latest information about Percona Server is available on the web at
http://www.percona.com/software/percona-server
Support Percona by buying support at
http://www.percona.com/products/mysql-support
Percona Server is distributed with several useful UDF (User Defined Function) from Percona Toolkit.
Run the following commands to create these functions:
mysql -e "CREATE FUNCTION fnv1a_64 RETURNS INTEGER SONAME 'libfnv1a_udf.so'"
mysql -e "CREATE FUNCTION fnv_64 RETURNS INTEGER SONAME 'libfnv_udf.so'"
mysql -e "CREATE FUNCTION murmur_hash RETURNS INTEGER SONAME 'libmurmur_udf.so'"
See http://www.percona.com/doc/percona-server/5.6/management/udf_percona_toolkit.html for more details
vi /etc/my.cnf
/etc/init.d/mysql start
[root@archer5 soft]# mysql -uroot -p
Enter password:
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 2
Server version: 5.6.29-76.2 Percona Server (GPL), Release 76.2, Revision ddf26fe
Copyright (c) 2009-2016 Percona LLC and/or its affiliates
Copyright (c) 2000, 2016, Oracle and/or its affiliates. All rights reserved.
Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
[root@localhost][(none)]>
[root@localhost][(none)]>
[root@localhost][(none)]> show databases;
+--------------------+
| Database |
+--------------------+
| information_schema |
| mysql |
| performance_schema |
| test |
+--------------------+
4 rows in set (0.00 sec)
[root@localhost][(none)]>
[root@localhost][(none)]>
[root@localhost][(none)]> select user,host from mysql.user;
+------+-----------+
| user | host |
+------+-----------+
| root | 127.0.0.1 |
| root | ::1 |
| | archer5 |
| root | archer5 |
| | localhost |
| root | localhost |
+------+-----------+
6 rows in set (0.01 sec)
[root@localhost][(none)]> drop user root@::1;
ERROR 1064 (42000): You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '::1' at line 1
[root@localhost][(none)]> drop user root@'
Query OK, 0 rows affected (0.00 sec)
[root@localhost][(none)]> drop user root@'archer5
Query OK, 0 rows affected (0.00 sec)
[root@localhost][(none)]> drop user root@'127.0.0.1
Query OK, 0 rows affected (0.00 sec)
[root@localhost][(none)]> select user,host from mysql.user;
elect user,host from mysql.user;
+------+-----------+
| user | host |
+------+-----------+
| | archer5 |
| | localhost |
| root | localhost |
+------+-----------+
3 rows in set (0.00 sec)
[root@localhost][(none)]> select user,host from mysql.user;
droarcher5
Query OK, 0 rows affected (0.00 sec)
[root@localhost][(none)]> drop user ''@localhost
Query OK, 0 rows affected (0.02 sec)
[root@localhost][(none)]>
[root@localhost][(none)]>
[root@localhost][(none)]> select user,host from mysql.user;
+------+-----------+
| user | host |
+------+-----------+
| root | localhost |
+------+-----------+
1 row in set (0.00 sec)
[root@localhost][(none)]>
[root@localhost][(none)]>
[root@localhost][(none)]> set password for root@localhost = password('rooT_258
Query OK, 0 rows affected (0.00 sec)
[root@localhost][(none)]>
[root@localhost][(none)]> quit
Bye
[root@archer5 soft]# mysql -uroot -p
Enter password:
ERROR 1045 (28000): Access denied for user 'root'@'localhost' (using password: NO)
[root@archer5 soft]# mysql -uroot -p
Enter password:
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 4
Server version: 5.6.29-76.2 Percona Server (GPL), Release 76.2, Revision ddf26fe
Copyright (c) 2009-2016 Percona LLC and/or its affiliates
Copyright (c) 2000, 2016, Oracle and/or its affiliates. All rights reserved.
Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
[root@localhost][(none)]>
[root@localhost][(none)]>
[root@localhost][(none)]> show databases;
+--------------------+
| Database |
+--------------------+
| information_schema |
| mysql |
| performance_schema |
| test |
+--------------------+
4 rows in set (0.00 sec)
[root@localhost][(none)]>
[root@localhost][(none)]>
[root@localhost][(none)]> quit
Bye
[root@archer5 data]# git clone https://github.com/Meituan-Dianping/SQLAdvisor.git
[root@archer5 data]# yum install cmake libaio-devel libffi-devel glib2 glib2-devel bison gcc gcc-c++ cmake
[root@archer5 data]# yum install -y make cmake libaio-devel libffi-devel glib2 glib2-devel bison gcc gcc-c++
[root@archer5 data]# find / -name libperconaserverclient_r.so
[root@archer5 data]# find / -name libperconaserverclient_r.so.18
/usr/lib64/libperconaserverclient_r.so.18
[root@archer5 data]#
[root@archer5 data]#
[root@archer5 data]# cd /usr/lib64/
[root@archer5 lib64]# ln -s libperconaserverclient_r.so.18 libperconaserverclient_r.so
[root@archer5 data]# cd SQLAdvisor/
[root@archer5 SQLAdvisor]# cmake -DBUILD_CONFIG=mysql_release -DCMAKE_BUILD_TYPE=debug -DCMAKE_INSTALL_PREFIX=/usr/local/sqlparser -DIGNORE_AIO_CHECK=/usr/share/doc/libaio-0.3.109 ./
[root@archer5 SQLAdvisor]# cd ./sqladvisor/
[root@archer5 sqladvisor]# cmake -DCMAKE_BUILD_TYPE=debug ./
[root@archer5 sqladvisor]# make
[root@archer5 sqladvisor]# cp /data/SQLAdvisor/sqladvisor/sqladvisor /usr/bin/sqladvisor
[root@archer5 sqladvisor]# sqladvisor --help
Usage:
sqladvisor [OPTION…] sqladvisor
SQL Advisor Summary
Help Options:
-?, --help Show help options
Application Options:
-f, --defaults-file sqls file
-u, --username username
-p, --password password
-P, --port port
-h, --host host
-d, --dbname database name
-q, --sqls sqls
-v, --verbose 1:output logs 0:output nothing
安装inception
yum -y install cmake bison ncurses-devel gcc gcc-c++ openssl-devel
手动上传inception文件
tar -xf inception.tar -C /usr/local/
chown -R root:root /usr/local/inception/
vi ~/.bash_profile
增加:path=$path:/usr/local/inception/bin
source ~/.bash_profile
启动及检测
nohup /usr/local/inception/bin/Inception --defaults-file=/usr/local/inception/bin/inc.cnf >/dev/null 2>&1 &
nohup sh /usr/local/archer_web/archer/debug.sh >/dev/null 2>&1 &
验证:
mysql -uroot -h127.0.0.1 -P6669
inception get variables;
wget -O m4-1.4.9.tar.gz http://ftp.gnu.org/gnu/m4/m4-1.4.9.tar.gz
tar -zvxf m4-1.4.9.tar.gz
cd m4-1.4.9
./configure
make
make install
wget http://alpha.gnu.org/gnu/bison/bison-2.5.91.tar.xz
xz -d bison-2.5.91.tar.xz
tar xf bison-2.5.91.tar
cd bison-2.5.91
./configure
make && make install
安装完成后:bison -V
wget http://www.openssl.org/source/openssl-1.1.1.tar.gz
tar -zxvf openssl-1.1.1.tar.gz
cd openssl-1.1.1
./config --prefix=/usr/local/openssl shared zlib
make && make install
安装python3
yum install -y make build-essential libssl-dev zlib1g-dev libbz2-dev libreadline-dev libsqlite3-dev wget curl llvm libncurses5-dev libncursesw5-dev xz-utils tk-dev zlib zlib-devel
wget https://www.python.org/ftp/python/3.6.6/Python-3.6.6.tgz
tar -xvf Python-3.6.6.tgz
cd Python-3.6.6
./configure --prefix=/usr/local/python3 --with-openssl=/usr/local/openssl --with-ssl
make && make install
软连接
cp /usr/bin/python /usr/bin/python2.7
ln -fs /usr/local/python3/bin/python3.6 /usr/bin/python
ln -fs /usr/local/python3/bin/pip3 /usr/bin/pip
--------------------------------------------------------------------------------------------------
wget https://www.python.org/ftp/python/3.4.1/Python-3.4.1.tgz
tar -xvf Python-3.4.1.tgz
cd Python-3.4.1
./configure --prefix=/usr/local/python3 --with-openssl=/usr/local/openssl --with-ssl
make && make install
软连接
ln -fs /usr/local/python3/bin/python3.4 /usr/bin/python
ln -fs /usr/local/python3/bin/pip3 /usr/bin/pip
---yum修改
vi /usr/bin/yum #将头部 #!/usr/bin/python 修改为 #!/usr/bin/python2.7
vi /usr/libexec/urlgrabber-ext-down #将头部 #!/usr/bin/python改为/usr/bin/python2.7。
vi /usr/bin/yum-config-manager #将头部 #!/usr/bin/python换成 #!/usr/bin/python2.7
pip install --upgrade pip
--安装archer
mkdir -p /usr/local/archer_web/
cd /usr/local/archer_web
yum -y install git
git clone https://github.com/jly8866/archer.git
--安装setuptools
cd /opt
wget --no-check-certificate https://pypi.python.org/packages/source/s/setuptools/setuptools-19.6.tar.gz#md5=c607dd118eae682c44ed146367a17e26
tar -zxvf setuptools-19.6.tar.gz
cd setuptools-19.6
python setup.py build
python setup.py install
可以看到安装到python3下面了
--安装Django
cd /opt
wget https://pypi.python.org/packages/44/41/bf93934082e9897a56a591a67bacbd9fb74e71244f3f42253432a9e627e6/Django-1.8.17.tar.gz#md5=e76842cdfbcb31286bd44f51e087a04c
tar -zxvf Django-1.8.17.tar.gz
cd Django-1.8.17
python setup.py install
python
>>> import django
>>> django.VERSION
(1, 8, 17, 'final', 0)
>>> exit()
yum -y install libyaml libyaml-devel
--安装Crypto和pymysql
pip install Crypto
pip install pycrypto
pip install pymysql
这里遇到了错误
# pip3 install Crypto
-bash: ./pip3: /usr/bin/python3: bad interpreter: No such file or directory
解决方法:
python3.4 -m pip install Crypto
或者
vim /opt/python3/bin/pip3
将#!/usr/bin/python3改为#!/opt/python3/bin/python3.4
# vim /opt/python3/lib/python3.4/site-packages/pymysql/connections.py
在if int(self.server_version.split(‘.’, 1)[0]) >= 5: 这一行之前加上以下这一句并保存,记得别用tab键用4个空格缩进:
self.server_version = '5.6.24-72.2-log'
--配置archer
cd /usr/local/archer_web/archer
--创建archer DB和inception DB
--进入安装的mysql5.6
mysql -uroot -p'rooT_258'
--grant all privileges on *.* to root@'%' identified by 'P@ssw0rd';
create database archer default character set utf8;
grant all on archer.* to archer_rw@'%' identified by 'P@ssw0rd';
create database inception_db default character set utf8;
grant all on inception_db.* to incep_rw@'%' identified by 'P@ssw0rd';
grant select,create,insert on *.* to incep_rw@'%' identified by 'P@ssw0rd';
10.200.22.33 3306
#create database test default character set utf8; #测试库 建在审核库里了 仅做测试
#grant all on test.* to test@'%' identified by 'test';
#flush privileges;
--修改/usr/local/archer_web/archer/archer/settings.py,如下内容:
vi /usr/local/archer_web/archer/archer/settings.py
#该项目本身的mysql数据库地址
DATABASES = {
'default': {
'ENGINE': 'django.db.backends.mysql',
'NAME': 'archer',
'USER': 'archer_rw',
'PASSWORD': 'P@ssw0rd',
'HOST': '127.0.0.1',
'PORT': '3306'
}
}
#inception组件所在的地址
INCEPTION_HOST = '10.10.3.70'
INCEPTION_PORT = '6669'
#查看回滚SQL时候会用到,这里要告诉archer去哪个mysql里读取inception备份的回滚信息和SQL.
#注意这里要和inception组件的inception.conf里的inception_remote_XX部分保持一致.
INCEPTION_REMOTE_BACKUP_HOST='10.10.3.70'
INCEPTION_REMOTE_BACKUP_PORT=3306
INCEPTION_REMOTE_BACKUP_USER='incep_rw'
INCEPTION_REMOTE_BACKUP_PASSWORD='P@ssw0rd' 这个用户就是在部署inception使用的用户。(这用户应该是和上面创建的incep_rw是一个用户,可以不用创建incep_rw)
--通过model创建archer本身的数据库表
cd /usr/local/archer_web/archer
pip install django_admin_bootstrapped
pip install django_apscheduler
python manage.py makemigrations
python manage.py makemigrations sql
python manage.py migrate
进入数据库查看archer库下的表是否存在
--创建django admin管理员
python manage.py createsuperuser
Username: admin 自己填写用户名
Email address: 邮箱 xuaiqi@vcredit.com
Password: 密码 xaq1234!!
Password (again): 确认密码
Superuser created successfully.
该用户可以登录django admin来管理model。
--启动acher
vi debug.sh
#!/bin/bash
python manage.py runserver 10.10.3.70:9123 端口为9123 此处改为8080了
nohup sh /usr/local/archer_web/archer/debug.sh >/dev/null 2>&1 &
--创建archer系统登录用户
pip install simplejson
通过浏览器访问http://10.138.61.13:9123/admin/sql/users/
可以看到django登录界面:
使用上面创建的用户名密码(admin/和密码)登录:
点击右侧Add用户配置,用户名密码自定义,至少创建一个工程师和一个审核人(用admin用户可以登录)后续新的工程师和审核人用户请用LDAP导入sql_users表或django admin增加
--配置主库地址
通过浏览器访问http://10.138.61.13:9123/admin/sql/master_config
点击右侧Add master_config。这一步是为了告诉archer你要用inception去哪些mysql主库里执行SQL,所用到的用户名密码、端口等。
--正式访问主页
http://10.138.61.13:9123/login/
发起脚本如:
use mysql;
create table t (id int(10));
insert into t values(1);
insert into t values(2);
commit;
select * from t;
如报错:/opt/python3/lib/python3.4/site-packages/pymysql/connections.py in _request_authentication, line 1113
解决办法:
vi /opt/python3/lib/python3.4/site-packages/pymysql/connections.py
... ...
def _request_authentication(self):
# https://dev.mysql.com/doc/internals/en/connection-phase-packets.html#packet-Protocol::HandshakeResponse
self.server_version = '5.6.24-72.2-log' #添加此行
if int(self.server_version.split('.', 1)[0]) >= 5:
... ...
如果遇到rollback的问题,就是给权限的问题,inception配置的连接的数据库的用户的权限,在
grant select,create,insert on *.* to incep_rw@'%' identified by 'P@ssw0rd';
也就是我配置的admin的用户。
inception源码地址:https://github.com/mysql-inception/inception
archer 源码地址:https://github.com/jly8866/archer
MySQL SQL审核平台 inception+archer2.0(亲测)的更多相关文章
- 基于Inception搭建MySQL SQL审核平台Yearing
基于Inception搭建MySQL SQL审核平台Yearing Inception 1. Inceptionj简介 2. Inception安装 2.1 下载和编译 2.2 启动配置 Yearni ...
- MYSQL SQL 审核工具 (inception安装步骤)
http://blog.csdn.net/wulantian/article/category/5825391
- Yearning v1.3.0 发布,Web 端 SQL 审核平台
企业级MYSQL web端 SQL审核平台. Website 官网 www.yearning.io Feature 功能 数据库字典自动生成 SQL查询 查询工单 导出 自动补全,智能提示 查询语句审 ...
- SQL审核平台Yearning部署
SQL审核平台Yearning部署 Yearning优势: Yearning SQL 审计平台 基于Vue.js与Django的整套mysql-sql审核平台解决方案.提供基于Inception的S ...
- centos 7 安装sql 审核工具 inception + archer
系统环境: Centos7 + python2.7 + python3 .... 下载 源码地址:https://github.com/mysql-inception/inception Incept ...
- inception+archery SQL审核平台
关闭防火墙和selinux 宿主机安装mysql,创建archery数据库,并给所有权限,允许远程连接到该数据库 grant all privileges on *.* to 'root'@'%' i ...
- MySQL自动化审核平台部署说明
背景: 关于MySQL的审核的重要性就不说明了,本文的自动化审核是通过Inception和SQLAdvisor实现的,具体的使用可以看它们各自的说明文档.这里大致介绍下如何部署和使用它们,其实该文章也 ...
- Yearning 介绍(SQL审核平台)
介绍 Yearning SQL 审计平台 基于Vue.js与Django的整套mysql-sql审核平台解决方案.提供基于Inception的SQL检测及执行. GitHub:https://gith ...
- SQL审核平台-Yearning安装部署实践
相关文档: https://guide.yearning.io/ yearning简介 http://python.yearning.io/install/ yearning安装 Yearning ...
随机推荐
- Django框架(七)
15 Django组件-中间件 中间件 中间件的概念 中间件顾名思义,是介于request与response处理之间的一道处理过程,相对比较轻量级,并且在全局上改变django的输入与输出.因为改变的 ...
- [luogu P3369]【模板】普通平衡树(Treap/SBT)
[luogu P3369][模板]普通平衡树(Treap/SBT) 题目描述 您需要写一种数据结构(可参考题目标题),来维护一些数,其中需要提供以下操作: 插入x数 删除x数(若有多个相同的数,因只删 ...
- Linux下maven安装
1.下载maven的tar.gz格式文件到/opt文件夹下 2.解压mavenmaven压缩包 tar -xvzf maven.tar.gz -C /usr/local 3.配置maven的环境变量 ...
- Windows查看Java内存使用情况
Windows查看Java程序运行时内存使用情况 1.在cmd命令窗口输入 jconsole ,弹出Java监视和管理控制台窗口 2.连接本地进程,首先需要知道想查看的进程ID ( pid ) 在c ...
- C++实现 电子邮件客户端程序(简易版)
#Windows操作系统下 用命令行工具实现发送邮件(编程前工作) 步骤: 1.telnet连接服务器(以用QQ邮箱向网易邮箱发送邮件为例,端口号25) 2.返回220 说明连接成功 3.ehlo发送 ...
- Tcl脚本整理照片
我那个媳妇啊,典型的只管照不管 理,32G的卡竟然被弄满了. 费好大劲好不容易整理到电脑上,可是都是数字名字,看着都头疼,索性整理下. 首先安装tcl编译环境tcl86,度娘搞的,然后开动: proc ...
- Element分页组件prev-text和next-text属性无效?
前情提要 /(ㄒoㄒ)/~~ 作为刚刚接触 Element 组件的人来说,看文档是第一步,但是当我想要修改分页组件里面的按钮时却遇到了问题. 文档中写到是需要给 prev-text 和 next-te ...
- PHP之缓存雪崩,及解决方法(转)
一.什么是缓存雪崩缓存雪崩就是指缓存由于某些原因(比如 宕机.cache服务挂了或者不响应)整体crash掉了,导致大量请求到达后端数据库,从而导致数据库崩溃,整个系统崩溃,发生灾难. 下面的就是一个 ...
- python学习之路06——字符串
字符串 1.概念 字符串就是由若干个字符组成的有限序列 字符:字母,数字,特殊符号,中文 表示形式:采用的单引号或者双引号 注意:字符串属于不可变实体 2.创建字符串 str1 = "hel ...
- sails.js mvc framework learning
目的:加快开发速度,总结使用方法: menu list: custom controller custom 模块使用 custom model custom middleware custom ser ...