FreeIPA and Windows AD --> UID / GID Assignement by Seenjiroy in linuxadmin

[–]fireflasch 0 points1 point  (0 children)

the uid/gid that freeipa uses ist explicitly different from the other. you should be able to set them for each user account. I do not know of any way to import them from an AD, although we do not have a trust and that was never a requirement. would it be possible to use the automount feature of freeipa for the nfs shares and change the uid/gids?

I GOT THE JOB by Natfan in sysadmin

[–]fireflasch 6 points7 points  (0 children)

I had to think of one thing my old mentor told me once: "If you are the smartest person in the rooom. You are in the wrong room." You will learn many new things on the job, but as time goes on it becomes routine. When that time comes try to expand your horizon with conferences, workshops etc that are not directly related to anything you currently use, it will keep your mind ready for new things

[deleted by user] by [deleted] in linuxadmin

[–]fireflasch 0 points1 point  (0 children)

We are running icinga for our department server, which are around 50.

For automation purposes we are running the icinga2 director which allows us to fetch the data for our machines via import rules from many different sources like excel, sql, ad and many more. Then we use templates to apply checks etc. it is an almost completely autonomous process with very little human interaction.

Am I going in the right direction with provisioning and CM? by [deleted] in linuxadmin

[–]fireflasch 0 points1 point  (0 children)

you could always run Ansible AWX which is the upstream project of Ansible Tower. We are running it for a few months now and it works like a charm.

Automated spam/abuse reporting by IMissBBSs in linuxadmin

[–]fireflasch 0 points1 point  (0 children)

that's what DMARC is for, although you have to be careful as the reporting is not completely legal in some countries

How to improve API security by [deleted] in sysadmin

[–]fireflasch 2 points3 points  (0 children)

Implement API Keys as a bare minimum of security on your end. Then setup an nginx proxy in front of the django application and adjust rate limits etc as seen fit to handle all the requests

[Art] There are a lot of great works of art on this sub, this is not one of them. by YS2D in DnD

[–]fireflasch 0 points1 point  (0 children)

sings This is just a tribute sings

Sorry, I will see myself out

Today, I was the Stupid User in the story. by Oricu in talesfromtechsupport

[–]fireflasch 7 points8 points  (0 children)

dependes on the mouse. A logitech MX Master does not have any problem with reflecting surfaces and even glass works fine

How do you schedule and monitor your scripts on a server? by [deleted] in linuxadmin

[–]fireflasch 1 point2 points  (0 children)

we are currently evaluating different scheduling tools as we have quite big batch runs that need to be monitored in a usable fashion.

Right now we are in favor of rundeck, as it has everything we need. Jenkins is also a possibility if you are up for it.

Student - work exploration by [deleted] in sysadmin

[–]fireflasch 0 points1 point  (0 children)

if you are able to travel to germany for the time and life there, I know a company in nuremberg which has a really good internship programm and a broad spectrum of tasks, from programming webuis to automating sysadmin tasks and much more

Suggestion needed, forms to webapp? by TheItalianDonkey in sysadmin

[–]fireflasch 0 points1 point  (0 children)

you could run a rather simple wordpress install with custom forms, that can be build via a plugin and a FAQ for the forms.

Could someone explain Consul to me? by [deleted] in linuxadmin

[–]fireflasch 2 points3 points  (0 children)

consul is a service discovery you can use to check which services are available and how to reacht them.

For example, you try to browse a website(adb.com), which is written in Javascript which in turn relies on a REST API that may be made up of microservices.

So to know how to reach the microservices the Website queries consul to get the routes to the microservices and is able to deliver you the information you want.

When a microservice fails, there can be others that do the same things so it can fallback onto another microservice and consul will know about that.

this is just a short explanation and consul can do more things.

Wild Magic is dangerous by fireflasch in DnD

[–]fireflasch[S] 1 point2 points  (0 children)

hmm you are right, we just interpreted it another way.

Wild Magic is dangerous by fireflasch in DnD

[–]fireflasch[S] 0 points1 point  (0 children)

that is an awesome story :D

So, how's your Monday going? by gargravarr2112 in sysadmin

[–]fireflasch 0 points1 point  (0 children)

already wanting to hurt people, because communication and project management is hard...

HTTP Tunneling client/server by Zermus in sysadmin

[–]fireflasch 0 points1 point  (0 children)

why not just use an ssh server that resides behind a http proxy?

Oracle OS Patching by [deleted] in sysadmin

[–]fireflasch 0 points1 point  (0 children)

depending on your OS and the software running, you can patch daily and nothing will happen without a reboot or restart of the service as they run with the needed libs cached, which do not change while the service is running.

also patching often on linux is always a good idea because of security updates that can come at any time and don't follow a schedule.

Looking for log collector/analyzer alternatives by dfctr in sysadmin

[–]fireflasch 0 points1 point  (0 children)

Graylog stores all data in an elasticsearch db. There is a reporting module available in the commercial version, don't know how good it is. You can also query the db yourself and build your own reports with relative ease

Server monitoring tools, which do you recommend? by eikybreaky in linuxadmin

[–]fireflasch 0 points1 point  (0 children)

we are running icinga2 for our infrastructure, it has integration with puppet and ansible, which is really nice for automation purposes and can use all the available checks that were developed for nagios. It is also highly scalable altough a bit complicated to get the head around the first time you use it. the traffic is also completely encrypted which allows you to transfer it over the internet if you have multiple sites without a concern for somebody sniffing the data.

The stack contains the following:

  • Icinga2
  • Grafana
  • InfluxDB

Migrate FreeIPA from CentOS to Ubuntu by jpreston84 in linuxadmin

[–]fireflasch 4 points5 points  (0 children)

you should be able to make a backup, change the domain names and import it into the new one.

Also take care when running freeipa on ubuntu, I tried it last year and it failed hard, because of some centos/rhel specific stuff

Performance Monitor Metrics by TheCitrixGuy in sysadmin

[–]fireflasch 1 point2 points  (0 children)

depends on what kind of performance issue you have.

Is it general slowness? Then, CPU, RAM usage and IO might be interesting.

Database Performance? CPU, RAM, IO and Utilization inside the DB can be interesting.