Compared to CentS, which is a stable server operating system, Ubuntu as a server S often has many aggressive default settings.

  1. Software is configured to start automatically after installation
    While this is generally a good thing, the default security configurations can make it difficult to pinpoint the root cause of issues when troubleshooting. For example, a recent case encountered was PublicCMS deployment showing "Read-only file system" in the startup logs.

  2. The system automatically backs up logs after software starts
    Another convenient yet potentially problematic feature. For instance, if we install the ginx service under the nginx user, but the default account in the log backup service is www-data, this can prevent ginx from writing logs and cause the service to stop.

  3. Letsncrypt updates certificates by default
    Another example of being overly clever. After installing Letsncrypt, the system includes a default certificate renewal service. However, sometimes we need to add post-renewal tasks, such as reloading ginx. If we manually add such a task, the two tasks may run alternately, often leading to issues where the renewed certificate doesn’t take effect. Upon investigation, we might discover that there’s a default scheduled task for Certbot under /etc/cron.d/, which even includes a random delay mechanism, significantly increasing the difficulty of troubleshooting.

/usr/bin/certbot renew --quiet --post-hook "systemctl restart nginx"