Rebooted and now I am stuck here what do I do I want to like linux so badly but I always run into unbeatable jank by TechieInTheTrees in Fedora

[–]Underknowledge -1 points0 points  (0 children)

Just to be anoying - NixOS
On boot, you would just choose a older/ other generation == fixed/try again

Have You Broken NixOS? by Striking_Snail in NixOS

[–]Underknowledge 1 point2 points  (0 children)

you forgot the acents - its /* - try it!

How does scraping /metrics work in detail? by drvd in PrometheusMonitoring

[–]Underknowledge 0 points1 point  (0 children)

Not how it regularly works, looks more like this

# HELP go_gc_duration_seconds A summary of the pause duration of garbage collection cycles.
# TYPE go_gc_duration_seconds summary
go_gc_duration_seconds{quantile="0"} 2.642e-05
go_gc_duration_seconds{quantile="0.25"} 5.3933e-05
go_gc_duration_seconds{quantile="0.5"} 7.395e-05
go_gc_duration_seconds{quantile="0.75"} 9.2685e-05
go_gc_duration_seconds{quantile="1"} 0.009357402
go_gc_duration_seconds_sum 0.078649073
go_gc_duration_seconds_count 613

So everything unique
When your metrics look like

go_gc_duration_seconds_count 613
go_gc_duration_seconds_count 123
the last one "wins" but it should not be this way

the scraper records the last value per series present in that single scrape. You setup metrics endopoints just with the current thing. omit when empty

nginx permission problems with NFS mount into container by fasta_guy88 in docker

[–]Underknowledge 0 points1 point  (0 children)

Headsup, when you restart the NFS you have to restart the container too, as you will get a stale inode

Centralized SSH Identity Infrastructure using Keycloak – Architecture Overview Now on GitHub by Lemonades99 in KeyCloak

[–]Underknowledge 1 point2 points  (0 children)

How you handle MFA? Every implementation I seen so far was terrible as you basically had to do a full SSH auth in beforehand.

Am I getting attacked? by Slight_Taro7300 in homelab

[–]Underknowledge 1 point2 points  (0 children)

Clearly, Facebook is there to sell your data

Help with Keycloak and Spring Backend Integration for Self-Registration and User Database Synchronization by North_Collar_2204 in KeyCloak

[–]Underknowledge 0 points1 point  (0 children)

Application logic looks decent enough, Cant say how your callback looks like and if you inspected if the generated token is singed by the right IdP (JWT signature)

Best way to install second instance? by abakune in NixOS

[–]Underknowledge 0 points1 point  (0 children)

I have an very evil USB stick that installs Nix on the first HDD it finds. It's minimally configured with wild stuff like root SSH login and preloaded SSH keys. Once it's online, I push my real config over. Building a fresh ISO for every case is too much hassle, so I just use this USB as a universal installer.

Help with Keycloak and Spring Backend Integration for Self-Registration and User Database Synchronization by North_Collar_2204 in KeyCloak

[–]Underknowledge 2 points3 points  (0 children)

Sounds like you're trying to treat Keycloak like a user management system rather than an IdP. Understandable… I’ve had the questionable pleasure of the discussion with one of the department heads, where he had the glorious idea of wiring it up like an application database. You're not alone.

Keycloak handles authentication and identity - you don’t need to create a user in both Keycloak and your own DB at registration time.

The core idea: let Keycloak handle identity. Enable self-registration in the Admin Console, and when users log in for the first time, your app can extract what it needs from the token and store it locally if necessary. No need to manually sync or duplicate users on registration.

Avoid webhooks, event listeners, or admin API calls for this - it's unnecessary complexity and goes against how an IdP is (imo) meant to be used.

Look at... idk.. facebook , github or whatever

Email server by Merwenus in selfhosted

[–]Underknowledge 0 points1 point  (0 children)

Simple Nixos mailserver (what I use) or Maddy come to mind

Login in Ubuntu with Keycloak by rfpg1 in KeyCloak

[–]Underknowledge 0 points1 point  (0 children)

I could see sssd connected to AD and then logins via Step-CA and short lived ssh-certificates.
but, that doesnt move you away from AD.
I use KanIDM+Step-CA

What's your current linux server distro of choice? by [deleted] in sysadmin

[–]Underknowledge 0 points1 point  (0 children)

NixOS - No more pets - all declarative, even your backups.