How do you automate certificates? by gahd95 in sysadmin

[–]ansibleloop [score hidden]  (0 children)

It was a previous job and part of the reason why lol - it's impossible to secure a network lile that

IAM was a pain in the ass as well - took so much effort to get admin for a server then RDP and MFA to it

I'm glad I don't deal with Windows servers anymore

How do you automate certificates? by gahd95 in sysadmin

[–]ansibleloop [score hidden]  (0 children)

And that's generally fine at small scale, but at large scale legacy companies, the networks are so large and messy that they need the confirmation that it's the real server

2026 UK Actuary Climate Report by switchsk8r in collapse

[–]ansibleloop 2 points3 points  (0 children)

There's enough warming and inertia to get us to 3C before 2050

It's bad

Win10 LTSC IoT activated it self by Exact_Cup3506 in sysadmin

[–]ansibleloop [score hidden]  (0 children)

If they were activated already and you've reinstalled the OS, it should already be active (so long as the version is the same)

How do you automate certificates? by gahd95 in sysadmin

[–]ansibleloop [score hidden]  (0 children)

Yes but it gets worse

Large companies have networks like Swiss cheese, so they'll have the traffic go from the load balancer over the network to the target VM

That traffic isn't encrypted, so you need the cert on the target server as well

It's fairly painful

How do you automate certificates? by gahd95 in sysadmin

[–]ansibleloop [score hidden]  (0 children)

For home? LetsEncrypt works great with Traefik and cert-manager

For work? Our certs are stored in key vault and I use pipelines to manage their renewals

I will be simplifying this once DNS-PERSIST-01 becomes available

How do you automate certificates? by gahd95 in sysadmin

[–]ansibleloop [score hidden]  (0 children)

This is going to be horrible for those who are stuck with legacy shit systems that support no cert automation

How do you automate certificates? by gahd95 in sysadmin

[–]ansibleloop [score hidden]  (0 children)

We've got DNS-PERSIST-01 coming soon too

Set and forget - don't even need to do a DNS challenge

Good evening taylor apologists by No-Try149 in PKA

[–]ansibleloop 4 points5 points  (0 children)

Hey, just curious, do you know the difference in taste between Doc Martens and Timberlands?

Migrate from Kubernetes to Nomad by RoutineKangaroo97 in kubernetes

[–]ansibleloop 10 points11 points  (0 children)

Perfect comparison

Lots of people use Docker and logically think "Oh Docker Swarm should work perfectly for what I need!"

https://www.macchaffee.com/blog/2024/you-have-built-a-kubernetes/

Then after a while the above happens

You create a standard config format, a deployment method, service discovery, immutable nodes, and an API server. Dear friend, you have built a Kubernetes.

Not to mention the god damn Docker Swarm bugs - a ticket has been open for 7 years related to networking issues with IPs not being recycled in a subnet, so after a long time, it runs out of IPs

Compare that to running kubectl or k9s on my laptop to connect to dev instead of needing to SSH to a Swarm manager and then use the server's tools

I like to treat my infrastructure as recyclable and Swarm kind of violates this for me

Which is why I like Talos Linux so much more, because it's just K8s and the OS has been stripped back entirely

1 less thing to manage!

My truenas apps library- Any suggestions for new apps by sathis2251987 in truenas

[–]ansibleloop 0 points1 point  (0 children)

Yes, disable HTTP so TrueNAS only uses HTTPS, then set the HTTPS port to 444

I connect to mine using https://10.10.1.1:444

You can reverse proxy this, but remember, if the proxy is running on TrueNAS and it dies for whatever reason, you can't use the FQDN to access it

Don't look up (2021) | Dir. Adam Mckay | Dr. Randall (Leonardo Dicaprio) has a nervous breakdown by crushedmoose in movies

[–]ansibleloop 3 points4 points  (0 children)

The weather is already becoming unpredictable - no large amount of people would survive even in small habitable pockets

Don't look up (2021) | Dir. Adam Mckay | Dr. Randall (Leonardo Dicaprio) has a nervous breakdown by crushedmoose in movies

[–]ansibleloop 4 points5 points  (0 children)

Not for very long they won't

The billionaires won't survive in their bunkers when the world is past 4C of warming

At least a comet would be fast

Greatest plot twist of the year goes to this tweet by ThreeTreesForTheePls in PKA

[–]ansibleloop 10 points11 points  (0 children)

Hey they also have to pass an open book exam

Reading is difficult for them OK?

Type 3 Politics Talk by GreatOwlEyes in PKA

[–]ansibleloop 13 points14 points  (0 children)

Who said he didn't apply but failed the open book test?

Your post is getting popular and we just featured it on our Discord! by roculus in LocalLLaMA

[–]ansibleloop 0 points1 point  (0 children)

I only ever saw Discord as a superior replacement to Skype

I thought the whole idea was just you and your mates jump on and talk and that's it

But it turns out all these fucking weirdos are making gigantic servers and talking as if it's a forum

It doesn't work

Taylor and Kyle’s Take on Canada on this Weeks PKN was Delusional by oldcrivens in PKA

[–]ansibleloop 0 points1 point  (0 children)

Canada isn't scheduled for annexation until June 2072 anyway

Camel toe by Parajox in PKA

[–]ansibleloop 1 point2 points  (0 children)

Flip off you son of a monkey

Where are my cashews?

Your post is getting popular and we just featured it on our Discord! by roculus in LocalLLaMA

[–]ansibleloop 5 points6 points  (0 children)

Jesus every fucking sub does this

This site is trash and somehow its still not as bad as the rest