<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Kang</title><link>https://kangyufei.net/</link><description>一个生活在日本的中国人，记录东京日常、出行、日本旅行与亲身经历中的生活经验。</description><language>zh-CN</language><atom:link href="https://kangyufei.net/index.xml" rel="self" type="application/rss+xml"/><item><title>如何在磁盘故障导致 I/O 错误时通过 SSH 强制重启 Linux 服务器（Magic SysRq 技巧）</title><link>https://kangyufei.net/blog/linux/%E5%A6%82%E4%BD%95%E5%9C%A8%E7%A3%81%E7%9B%98%E6%95%85%E9%9A%9C%E5%AF%BC%E8%87%B4-i-o-%E9%94%99%E8%AF%AF%E6%97%B6%E9%80%9A%E8%BF%87-ssh-%E5%BC%BA%E5%88%B6%E9%87%8D%E5%90%AF-linux-%E6%9C%8D%E5%8A%A1/</link><guid>https://kangyufei.net/blog/linux/%E5%A6%82%E4%BD%95%E5%9C%A8%E7%A3%81%E7%9B%98%E6%95%85%E9%9A%9C%E5%AF%BC%E8%87%B4-i-o-%E9%94%99%E8%AF%AF%E6%97%B6%E9%80%9A%E8%BF%87-ssh-%E5%BC%BA%E5%88%B6%E9%87%8D%E5%90%AF-linux-%E6%9C%8D%E5%8A%A1/</guid><pubDate>Thu, 17 Apr 2025 15:39:51 +0900</pubDate><description> 关键词：Magic SysRq key、/proc/sysrq-trigger、硬复位、emergency sync、只读挂载
背景与问题 当 Linux 服务器的块设备（磁盘）出现严重故障，整个文件系统会被内核自动重新挂载为 只读，所有普通读写操作都会抛出 Input/output error。如果此时你仍保持着 SSH 会话，虽然能敲命令，但绝大多数二进制文件、shell 内置以外的工具都无法正常执行。</description></item><item><title>如何使用BP35A1获取电表数据</title><link>https://kangyufei.net/blog/iot/%E5%A6%82%E4%BD%95%E4%BD%BF%E7%94%A8bp35a1%E8%8E%B7%E5%8F%96%E7%94%B5%E8%A1%A8%E6%95%B0%E6%8D%AE/</link><guid>https://kangyufei.net/blog/iot/%E5%A6%82%E4%BD%95%E4%BD%BF%E7%94%A8bp35a1%E8%8E%B7%E5%8F%96%E7%94%B5%E8%A1%A8%E6%95%B0%E6%8D%AE/</guid><pubDate>Sun, 22 Dec 2024 15:18:19 +0900</pubDate><description>1. 前言 在日本居住过的朋友，大多知道家里都会安装 智能电表（Smart Meter），这类电表通常内置了 ECHONET Lite 协议和 Wi-SUN 通信功能。通过向电力公司申请 B Route ID 和 B Route密码，我们可以自己动手采集自家实时用电信息，用于做能源监控、家居自动化或者数据可视化。</description></item><item><title>OpenWrt系统升级指南：从22.03升级到23.05.2</title><link>https://kangyufei.net/blog/uncategorized/openwrt%E7%B3%BB%E7%BB%9F%E5%8D%87%E7%BA%A7%E6%8C%87%E5%8D%97%EF%BC%9A%E4%BB%8E22-03%E5%8D%87%E7%BA%A7%E5%88%B023-05-2/</link><guid>https://kangyufei.net/blog/uncategorized/openwrt%E7%B3%BB%E7%BB%9F%E5%8D%87%E7%BA%A7%E6%8C%87%E5%8D%97%EF%BC%9A%E4%BB%8E22-03%E5%8D%87%E7%BA%A7%E5%88%B023-05-2/</guid><pubDate>Sat, 03 Feb 2024 15:13:20 +0900</pubDate><description>在不破坏分区和不用重新配置系统的前提下，对x86_64的OpenWrt系统进行升级是一项重要且需要谨慎处理的任务。本文将提供详细的升级步骤，确保您能顺利完成升级过程。
准备工作 在执行升级之前，请务必备份重要数据，并在操作过程中注意事项。</description></item><item><title>Esphome 控制普通电风扇</title><link>https://kangyufei.net/blog/iot/esphome-%E6%8E%A7%E5%88%B6%E6%99%AE%E9%80%9A%E7%94%B5%E9%A3%8E%E6%89%87/</link><guid>https://kangyufei.net/blog/iot/esphome-%E6%8E%A7%E5%88%B6%E6%99%AE%E9%80%9A%E7%94%B5%E9%A3%8E%E6%89%87/</guid><pubDate>Mon, 27 Jun 2022 12:04:01 +0900</pubDate><description>近来天气渐热。遂购入一台普通可充电小风扇。此风扇的电源和风速调节只有一个按钮。且无遥控器。刚好家里还有几片剩余没有用的ESP12 。试试能不能改装一下远程控制，接入home-assisstant。
因为此风扇自带电池。内部按钮是个未知的MCU控制的，测量发现MCU的供电电压是3.6v左右。也可以用来给ESP供电。按钮是低电平触发。所以只要用ESP控制GPIO给按钮低电平就可以控制这个风扇了。</description></item><item><title>HeimVision A80S唤醒灯接入Home Assistant</title><link>https://kangyufei.net/blog/iot/heimvision-a80s%E5%94%A4%E9%86%92%E7%81%AF%E6%8E%A5%E5%85%A5home-assistant/</link><guid>https://kangyufei.net/blog/iot/heimvision-a80s%E5%94%A4%E9%86%92%E7%81%AF%E6%8E%A5%E5%85%A5home-assistant/</guid><pubDate>Sat, 16 Apr 2022 23:01:53 +0900</pubDate><description>一.关于HeimVision A80S HeimVision是一个功能还算比较丰富的唤醒灯。唤醒灯作为夜灯的亮度也相当不错。自带收音机。
https://www.heimvision.com/products/heimvision-a80s-sunrise-alarm-clock-wake-up-light
主要功能如下：
唤醒灯 20档亮度 2个闹钟 收音机 时钟 LED WIFI 二.改造背景 A80S官方没有app。IOT功能使用的是中国厂商TuyaSmart的方案。可以使用TuyaSmart和Smart Life这两个app来控制各项功能。我家里的所有智能家居设备都是通过自建的HomeAssistant来控制的。虽然Hass也支持Tuya接入。但是支持的比较残废。一直在尝试有无更好的远程控制方案。</description></item><item><title>使用openresty自动生成letsencrypt证书</title><link>https://kangyufei.net/blog/linux/%E4%BD%BF%E7%94%A8openresty%E8%87%AA%E5%8A%A8%E7%94%9F%E6%88%90letsencrypt%E8%AF%81%E4%B9%A6/</link><guid>https://kangyufei.net/blog/linux/%E4%BD%BF%E7%94%A8openresty%E8%87%AA%E5%8A%A8%E7%94%9F%E6%88%90letsencrypt%E8%AF%81%E4%B9%A6/</guid><pubDate>Sun, 03 Apr 2022 22:52:20 +0900</pubDate><description>openresty支持lua插件。最近看到有个第三方的auto ssl的实现。做个docker image，方便使用。
nginx.conf # user nobody; worker_processes 1; #error_log logs/error.log; #error_log logs/error.log notice; #error_log logs/error.log info; #pid logs/nginx.pid; events { worker_connections 1024; } http { include mime.types; default_type application/octet-stream; client_body_temp_path /var/run/openresty/nginx-client-body; proxy_temp_path /var/run/openresty/nginx-proxy; fastcgi_temp_path /var/run/openresty/nginx-fastcgi; uwsgi_temp_path /var/run/openresty/nginx-uwsgi; scgi_temp_path /var/run/openresty/nginx-scgi; sendfile on; #tcp_nopush on; keepalive_timeout 65; gzip on; lua_shared_dict auto_ssl 1m; lua_shared_dict auto_ssl_settings 64k; # A DNS resolver must be defined for OCSP stapling to function. # # This example uses Google's DNS server. You may want to use your system's # default DNS servers, which can be found in /etc/resolv.conf. If your network # is not IPv6 compatible, you may wish to disable IPv6 results by using the # "ipv6=off" flag (like "resolver 8.8.8.8 ipv6=off"). resolver 8.8.8.8; # Initial setup tasks. init_by_lua_block { auto_ssl = (require "resty.auto-ssl").new() auto_ssl:set("allow_domain", function(domain) return true end) -- auto_ssl:set("storage_adapter", "resty.auto-ssl.storage_adapters.redis") -- auto_ssl:set("redis", { -- host = "REDIS_HOST" -- }) auto_ssl:init() } init_worker_by_lua_block { auto_ssl:init_worker() } server { listen 80; server_name _ ; # Endpoint used for performing domain verification with Let's Encrypt. location /.well-known/acme-challenge/ { content_by_lua_block { auto_ssl:challenge_server() } } location / { return 301 https://$host$request_uri; } } server { listen 127.0.0.1:8999; # Increase the body buffer size, to ensure the internal POSTs can always # parse the full POST contents into memory. client_body_buffer_size 128k; client_max_body_size 128k; location / { content_by_lua_block { auto_ssl:hook_server() } } } server { listen 443 ssl; server_name _; ssl_certificate_by_lua_block { auto_ssl:ssl_certificate() } ssl_certificate /etc/ssl/resty-auto-ssl-fallback.crt; ssl_certificate_key /etc/ssl/resty-auto-ssl-fallback.key; location / { root html; index index.html index.htm; } } include /etc/nginx/conf.d/*.conf; } gen_ssl.sh openssl req -new -newkey rsa:2048 -days 3650 -nodes -x509 \ -subj '/CN=sni-support-required-for-valid-ssl' \ -keyout /etc/ssl/resty-auto-ssl-fallback.key \ -out /etc/ssl/resty-auto-ssl-fallback.crt Dockerfile： FROM openresty/openresty:1.19.3.2-2-alpine-fat COPY config/nginx.conf /usr/local/openresty/nginx/conf/nginx.conf COPY config/gen_ssl.sh /bin/gen_ssl.sh RUN apk add --no-cache \ bash \ curl \ diffutils \ grep \ openssl \ sed RUN luarocks install lua-resty-auto-ssl &amp;&amp; \ sh /bin/gen_ssl.sh Build docker build -t openresty-ssl . Run docker run -p 80:80 -p 443:443 -v $(pwd)/auto_ssl:/etc/resty-auto-ssl --name openresty -d openresty-ssl Github https://github.com/yufeikang/openresty-docker</description></item><item><title>Nginx 动态转发端口</title><link>https://kangyufei.net/blog/linux/nginx-%E5%8A%A8%E6%80%81%E8%BD%AC%E5%8F%91%E7%AB%AF%E5%8F%A3/</link><guid>https://kangyufei.net/blog/linux/nginx-%E5%8A%A8%E6%80%81%E8%BD%AC%E5%8F%91%E7%AB%AF%E5%8F%A3/</guid><pubDate>Sun, 03 Apr 2022 22:37:22 +0900</pubDate><description>配置：
server { server_name ~^(?&lt;port&gt;\d+)\-port\.example\.com$; listen 80; if ($port = '') { return 406; } location / { proxy_pass http://YOUR_DEVELOP_PC_IP:$port; proxy_redirect off; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "Upgrade"; proxy_set_header Host $host; } } nginx配置如上设置。可以比较方便的使用home server的公网ip临时暴露pc的端口。方便工作中的开发调试。
最重要的是nginx上面也可以使用统配域名证书将API暴露成https协议。</description></item><item><title>Wireguard 打造私人局域网</title><link>https://kangyufei.net/blog/linux/wireguard-%E6%89%93%E9%80%A0%E7%A7%81%E4%BA%BA%E5%B1%80%E5%9F%9F%E7%BD%91/</link><guid>https://kangyufei.net/blog/linux/wireguard-%E6%89%93%E9%80%A0%E7%A7%81%E4%BA%BA%E5%B1%80%E5%9F%9F%E7%BD%91/</guid><pubDate>Sun, 03 Apr 2022 21:28:51 +0900</pubDate><description> 为了外出的时能够方便访问到家庭局域网server的资源，通常的做法是吧资源端口暴露到公网。如果依赖资源很多，配置麻烦也不安全
Wireguard 是一个轻量。内核级别的VPN实现。严格来说它只是一个peer-to-peer的工具。只是可以配合Linux 的iptables实现路由和转发功能，从而实现一个VPN网络。</description></item><item><title>Docker 安装 Wireguard Server</title><link>https://kangyufei.net/blog/linux/docker-install-wireguard-server/</link><guid>https://kangyufei.net/blog/linux/docker-install-wireguard-server/</guid><pubDate>Sun, 03 Apr 2022 15:17:03 +0900</pubDate><description>使用linuxserver.io 的docker image搭建Wireguard server。
envfile： SERVERURL=EXTRNAL_IP_OR_DOMAIN # 外部ip SERVERPORT=51820 # 希望的端口号 PEERS=3 # 希望生成的client配置个数 PEERDNS=YOUR_DNS INTERNAL_SUBNET=10.6.0.0/24 # WG子网 ALLOWEDIPS=10.6.0.0/24 # 支持多个，`,` 分割，可以用0.0.0.0/0转发所以流量 一些字段说明： ALLOWEDIPS是一系列ip段。配置了这个字段后wg客户端会将这些网段路由到wg接口，可以把INTERNAL_SUBNET加进去。这样可以让peer之间互通。也可以把0.0.0.0/0加进去。这样客户端的所有流量都会转发到server去。 为什么说wiregruard轻量呢。因为wireguard只是在系统添加了条路由表而已！它不本身并不负责什么路由工作。</description></item></channel></rss>