在 CentOS 上用 nohup 跑程序时,如果想把日志加密保存,常见做法不是直接让 nohup 加密,而是:
程序日志 → 明文临时输出 → 加密管道 / 定时加密 → 加密日志文件
下面给你几种实用方案,从简单到规范。
nohup + gpg 实时加密(推荐)利用管道,在写入时就加密。
gpg --gen-key
记住你的 key id 或邮箱。
nohup your_command \
| gpg -e -r your_email@example.com \
> app.log.gpg 2>&1 &
✅ 优点
❌ 缺点
查看日志:
gpg -d app.log.gpg
nohup 写明文 + 定时加密(简单)适合对实时性要求不高。
nohup your_command > app.log 2>&1 &
然后加 crontab:
0 * * * * gpg -e -r your_email@example.com -o app.log.gpg app.log && rm -f app.log
⚠️ 明文会短暂存在,注意权限:
chmod 600 app.log
openssl 对称加密(密码方式)不想用 GPG 密钥时可用。
nohup your_command \
| openssl enc -aes-256-cbc -salt -pass pass:YourPass \
> app.log.enc 2>&1 &
解密:
openssl enc -d -aes-256-cbc -pass pass:YourPass -in app.log.enc
⚠️ 密码在命令行可见,建议用 -pass file:。
如果是服务程序:
rsyslogrsyslog 用 omfile + gpg 或 logrotate + encrypt适合安全合规场景。
umask 077
chmod 600 *.log *.gpg *.enc
如果你能告诉我:
我可以直接给你一套可复制的完整脚本。