
系统版本:CentOS Linux release 7.6.1810 (Core)






  1. [root@localhost ~]# systemctl stop firewalld
  2. [root@localhost ~]# systemctl disable firewalld
  3. [root@localhost ~]# setenforce 0
  4. [root@localhost ~]# sed -i "s/SELINUX=enforcing/SELINUX=disabled/g" /etc/sysconfig/selinux


  1. [root@localhost ~]# yum -y install wget gcc epel-release git


  1. [root@localhost ~]# yum -y install redis
  2. [root@localhost ~]# systemctl enable redis
  3. [root@localhost ~]# systemctl start redis
  4. [root@localhost ~]# systemctl status redis
  5. [root@localhost ~]# netstat -lnupt |grep redis
  6. tcp 0 0* LISTEN 19387/redis-server


  1. [root@localhost ~]# yum -y install mariadb mariadb-devel mariadb-server MariaDB-shared
  2. [root@localhost ~]# systemctl enable mariadb
  3. [root@localhost ~]# systemctl start mariadb
  4. [root@localhost ~]# netstat -lnupt |grep mysqld
  5. tcp 0 0* LISTEN 19721/mysqld
  6. #设置Mariadb数据库管理员密码
  7. [root@localhost ~]# mysqladmin -uroot -p password 'ABCabc-123'
  8. #创建JumpServer所使用的数据库用户,并授权
  9. [root@localhost ~]# mysql -uroot -p'ABCabc-123'
  10. MariaDB [(none)]> create database jumpserver default charset 'utf8';
  11. MariaDB [(none)]> grant all on jumpserver.* to 'jumpserver'@'' identified by 'ABCabc-123';
  12. MariaDB [(none)]> flush privileges;
  13. MariaDB [(none)]> exit


  1. [root@localhost ~]# yum -y install nginx
  2. [root@localhost ~]# systemctl enable nginx


  1. [root@localhost ~]# yum -y install epel-release.noarch yum-utils
  2. [root@localhost ~]# yum-config-manager --add-repo http://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo
  3. [root@localhost ~]# yum -y install device-mapper-persistent-data lvm2
  4. [root@localhost ~]# yum -y install docker-ce
  5. [root@localhost ~]# systemctl start docker
  6. [root@localhost ~]# systemctl enable docker
  7. [root@localhost ~]# curl -sSL https://get.daocloud.io/daotools/set_mirror.sh | sh -s http://f1361db2.m.daocloud.io
  8. [root@localhost ~]# systemctl restart docker
  9. [root@localhost ~]# systemctl status docker



  1. [root@localhost ~]# yum -y install python36 python36-devel
  2. #开启Python3.6虚拟运行环境,"py3"是这个虚拟环境名,可以自定义
  3. [root@localhost ~]# cd /opt
  4. [root@localhost opt]# python3.6 -m venv py3
  5. #退出虚拟环境可以使用"deactivate"命令
  6. [root@localhost opt]# source /opt/py3/bin/activate
  7. #看到下面的提示符代表成功, 以后运行JumpServer都要先运行以上"source"命令, 载入环境后默认以下所有命令均在该虚拟环境中运行
  8. (py3) [root@localhost opt]#



  1. #下载JumpServer
  2. (py3) [root@localhost opt]# git clone --depth=1 https://github.com/jumpserver/jumpserver.git
  3. #安装软件包依赖
  4. (py3) [root@localhost opt]# yum -y install $(cat /opt/jumpserver/requirements/rpm_requirements.txt)
  5. #安装Python依赖
  6. (py3) [root@localhost opt]# pip install --upgrade pip setuptools
  7. (py3) [root@localhost opt]# pip install -r /opt/jumpserver/requirements/requirements.txt
  8. #生成加密密钥
  9. [root@localhost jumpserver]# cat /dev/urandom | tr -dc A-Za-z0-9 | head -c 49
  10. mTUbunBOhz6FqY06MWidwklGzROg3Od9k68FDJQda044CLRRH
  11. #生成引导令牌
  12. [root@localhost jumpserver]# cat /dev/urandom | tr -dc A-Za-z0-9 | head -c 16
  13. 4dNPSDcgKguMLx0b
  14. #配置JumpServer
  15. (py3) [root@localhost opt]# cd jumpserver/
  16. (py3) [root@localhost jumpserver]# cp config_example.yml config.yml
  17. (py3) [root@localhost jumpserver]# vim config.yml
  18. SECRET_KEY: mTUbunBOhz6FqY06MWidwklGzROg3Od9k68FDJQda044CLRRH #设置加密密钥
  19. BOOTSTRAP_TOKEN: 4dNPSDcgKguMLx0b #设置引导令牌
  20. DEBUG: false #设置禁用调试模式
  21. LOG_LEVEL: ERROR #设置日志级别为ERROR级别
  22. SESSION_EXPIRE_AT_BROWSER_CLOSE: true #设置当浏览器关闭时Session过期
  23. DB_ENGINE: mysql #设置使用的数据库为MYSQL(Mariadb)
  24. DB_HOST: #设置MYSQL数据库连接地址
  25. DB_PORT: 3306 #设置MYSQL数据库连接端口
  26. DB_USER: jumpserver #设置MYSQL数据库连接账号
  27. DB_PASSWORD: ABCabc-123 #设置MYSQL数据库连接密码
  28. DB_NAME: jumpserver #设置MYSQL数据库名
  29. HTTP_BIND_HOST: #设置JumpServer WEB服务监听地址
  30. HTTP_LISTEN_PORT: 8080 #设置JumpServer WEB服务监听端口
  31. REDIS_HOST: #设置Redis连接地址
  32. REDIS_PORT: 6379 #设置Redis连接端口
  33. #将JumpServer服务交给系统管理(system),并运行服务
  34. (py3) [root@localhost jumpserver]# wget -O /usr/lib/systemd/system/jms.service https://demo.jumpserver.org/download/shell/centos/jms.service
  35. (py3) [root@localhost jumpserver]# chmod 755 /usr/lib/systemd/system/jms.service
  36. (py3) [root@localhost jumpserver]# vim /usr/lib/systemd/system/jms.service
  37. [Unit]
  38. Description=jms
  39. After=network.target mariadb.service redis.service docker.service
  40. Wants=mariadb.service redis.service docker.service
  41. [Service]
  42. Type=forking
  43. Environment="PATH=/opt/py3/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/root/bin"
  44. ExecStart=/opt/jumpserver/jms start -d
  45. ExecReload=
  46. ExecStop=/opt/jumpserver/jms stop
  47. [Install]
  48. WantedBy=multi-user.target
  49. (py3) [root@localhost jumpserver]# systemctl daemon-reload
  50. (py3) [root@localhost jumpserver]# systemctl start jms
  51. (py3) [root@localhost jumpserver]# systemctl enable jms
  52. (py3) [root@localhost jumpserver]# systemctl status jms
  53. (py3) [root@localhost jumpserver]# netstat -lnupt |grep 8080
  54. tcp 0 0* LISTEN 36499/python3.6



koko :基于SSH协议,为用户提供JumpServer的操作终端。

guacamole :基于HTML5的VNC查看器,允许用户在WEB-UI管理控制台中进行VNC远程操作。

  1. (py3) [root@localhost jumpserver]# Server_IP=`ip addr | grep inet | egrep -v '(|inet6|docker)' | awk '{print $2}' | tr -d "addr:" | head -n 1 | cut -d / -f1`
  2. (py3) [root@localhost jumpserver]# BOOTSTRAP_TOKEN='4dNPSDcgKguMLx0b'
  3. (py3) [root@localhost jumpserver]# docker run --name jms_koko -d -p 2222:2222 -p -e CORE_HOST=http://$Server_IP:8080 -e BOOTSTRAP_TOKEN=$BOOTSTRAP_TOKEN --restart=always jumpserver/jms_koko:1.5.2
  4. (py3) [root@localhost jumpserver]# docker run --name jms_guacamole -d -p -e JUMPSERVER_SERVER=http://$Server_IP:8080 -e BOOTSTRAP_TOKEN=$BOOTSTRAP_TOKEN --restart=always jumpserver/jms_guacamole:1.5.2
  5. (py3) [root@localhost jumpserver]# docker ps
  6. [root@localhost ~]# netstat -lnupt |grep 5000
  7. tcp 0 0* LISTEN 37806/docker-proxy
  8. [root@localhost ~]# netstat -lnupt |grep 8081
  9. tcp 0 0* LISTEN 38042/docker-proxy



  1. (py3) [root@localhost jumpserver]# cd /opt
  2. (py3) [root@localhost opt]# wget https://demo.jumpserver.org/download/luna/1.5.2/luna.tar.gz
  3. (py3) [root@localhost opt]# tar xf luna.tar.gz
  4. (py3) [root@localhost opt]# chown -R root:root luna



  1. (py3) [root@localhost opt]# rm -rf /etc/nginx/conf.d/default.conf
  2. (py3) [root@localhost opt]# vim /etc/nginx/nginx.conf
  3. user nginx;
  4. worker_processes auto;
  5. error_log /var/log/nginx/error.log;
  6. pid /run/nginx.pid;
  7. include /usr/share/nginx/modules/*.conf;
  8. events {
  9. worker_connections 1024;
  10. }
  11. http {
  12. log_format main '$remote_addr - $remote_user [$time_local] "$request" '
  13. '$status $body_bytes_sent "$http_referer" '
  14. '"$http_user_agent" "$http_x_forwarded_for"';
  15. access_log /var/log/nginx/access.log main;
  16. sendfile on;
  17. tcp_nopush on;
  18. tcp_nodelay on;
  19. keepalive_timeout 65;
  20. types_hash_max_size 2048;
  21. include /etc/nginx/mime.types;
  22. default_type application/octet-stream;
  23. include /etc/nginx/conf.d/*.conf;
  24. }
  25. (py3) [root@localhost opt]# vim /etc/nginx/conf.d/jumpserver.conf
  26. server {
  27. listen 80;
  28. client_max_body_size 100m;
  29. #限制文件上传大小。
  30. location /luna/ {
  31. try_files $uri / /index.html;
  32. alias /opt/luna/;
  33. }
  34. #前端页面-luna目录路径
  35. location /media/ {
  36. add_header Content-Encoding gzip;
  37. root /opt/jumpserver/data/;
  38. }
  39. #录像数据。
  40. location /static/ {
  41. root /opt/jumpserver/data/;
  42. }
  43. #静态数据。
  44. location /socket.io/ {
  45. proxy_pass http://localhost:5000/socket.io/;
  46. proxy_buffering off;
  47. proxy_http_version 1.1;
  48. proxy_set_header Upgrade $http_upgrade;
  49. proxy_set_header Connection "upgrade";
  50. proxy_set_header X-Real-IP $remote_addr;
  51. proxy_set_header Host $host;
  52. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  53. access_log off;
  54. }
  55. location /coco/ {
  56. proxy_pass http://localhost:5000/coco/;
  57. proxy_set_header X-Real-IP $remote_addr;
  58. proxy_set_header Host $host;
  59. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  60. access_log off;
  61. }
  62. location /guacamole/ {
  63. proxy_pass http://localhost:8081/;
  64. proxy_buffering off;
  65. proxy_http_version 1.1;
  66. proxy_set_header Upgrade $http_upgrade;
  67. proxy_set_header Connection $http_connection;
  68. proxy_set_header X-Real-IP $remote_addr;
  69. proxy_set_header Host $host;
  70. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  71. access_log off;
  72. }
  73. location / {
  74. proxy_pass http://localhost:8080;
  75. proxy_set_header X-Real-IP $remote_addr;
  76. proxy_set_header Host $host;
  77. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  78. }
  79. }
  80. (py3) [root@localhost opt]# nginx -t
  81. nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
  82. nginx: configuration file /etc/nginx/nginx.conf test is successful
  83. (py3) [root@localhost opt]# systemctl start nginx
  84. (py3) [root@localhost opt]# systemctl enable nginx
  85. (py3) [root@localhost opt]# systemctl status nginx







  1. [root@localhost ~]# ssh -p 2222 admin@
  2. admin@'s password:
  3. Administrator, 欢迎使用Jumpserver开源堡垒机系统
  4. 1) 输入 ID 进行直接登陆.
  5. 2) 输入 部分IP、主机名、备注 进行进行搜索登录(如果唯一).
  6. 3) 输入 / + IP, 主机名 or 备注 进行搜索, 如: /192.168.
  7. 4) 输入 p 进行显示您有权限的主机.
  8. 5) 输入 g 进行显示您有权限的节点.
  9. 6) 输入 r 进行刷新最新的机器和节点信息.
  10. 7) 输入 h 进行显示帮助.
  11. 8) 输入 q 进行退出.
  12. Opt> q


