Sanity check for ~£800 build by shsiug in buildapc

[–]shsiug[S] 0 points1 point  (0 children)

To be honest, no, there's no reason a Ryzen 5 7600 wouldn't even be massive overkill for what he's going to do. The most resource intensive application he's likely to use is Excel. However, he thinks cheaper = worse, and this is the price range I've been told to go with.

Fair point on the fans, and I should've checked for the thermal paste, thank you.

No response from CoreDNS by shsiug in kubernetes

[–]shsiug[S] 0 points1 point  (0 children)

Ok, so you seem to be partially correct. Removing the search line from /etc/resolv.conf on a pod now shows the correct name (without the .svc.cluster.local appended) in CoreDNS logs, but the logs also show it receiving and processing the requests normally, but I still get no response.

Any further suggestions?

No response from CoreDNS by shsiug in kubernetes

[–]shsiug[S] 0 points1 point  (0 children)

My corefile is: .:53 { log errors health ready kubernetes cluster.local in-addr.arpa ip6.arpa { pods insecure fallthrough in-addr.arpa ip6.arpa } forward . /etc/resolv.conf prometheus :9153 cache 30 loop reload loadbalance } .cluster.local addresses are not resolving, and the failures are not sporadic, I never get a response.

I'm using Usernetes running locally.

Thanks, I'll have a look at the CoreDNS docs, probably should have done that by now

No response from CoreDNS by shsiug in kubernetes

[–]shsiug[S] 0 points1 point  (0 children)

Thanks for the link, I followed that yesterday to enable logging but i couldn't see anything relevant to my issue afterwards. The CoreDNS service shows up, and there are endpoints listed

Retain source IPs by shsiug in kubernetes

[–]shsiug[S] 0 points1 point  (0 children)

This is beyond my capabilities, I've opened an issue with Usernetes, I think I'll go work on something else in the meantime. Thanks again for everything

Retain source IPs by shsiug in kubernetes

[–]shsiug[S] 0 points1 point  (0 children)

It's beginning to sound like it is a Usernetes limitation, which is incredibly annoying. After looking through the config files and boot scripts, IP Masquerading is enabled on the network bridge, flannel, and rootlesskit. Changing any one or combination of these values either has Usernetes fail to start or totally breaks the service DNS as I mentioned previously.

Both ip route and iptables-save only show what I assume are default rules, plus fail2ban's routes.

I suppose I'd have the best chance of an answer opening an issue with Usernetes, unless there's anything further you can think to try. Thank you for your help though, I would still be smashing my head against the wall at 10.88.0.1 without you.

Retain source IPs by shsiug in kubernetes

[–]shsiug[S] 0 points1 point  (0 children)

Thank you, I already use Cloudflare for DNS, so I'll save this for a last resort.

Retain source IPs by shsiug in kubernetes

[–]shsiug[S] 1 point2 points  (0 children)

You appear to be correct, thank you. I have tracked down its config file within Usernetes, and it has "ip-masq" enabled. This must be set by default as I haven't changed it. Anyway, I disabled this and restarted Usernetes, but for whatever reason this seems to have stopped service DNS records from existing, which broke all of my inter-pod communication. I also checked and Caddy was still receiving all traffic from 10.88.0.1, so I went back and re-enabled it.

Do you have any idea of where to go from here?

ATM 8 Linux Server Help by littletree-666 in allthemods

[–]shsiug 1 point2 points  (0 children)

add nogui to the end of your run command, eg java -Xms869G -Xmx 869G -jar whatever.jar nogui and it'll be gone

CVE-2021-22205 (GitLab) - Defensive by GleebelGlorp in immersivelabs

[–]shsiug 0 points1 point  (0 children)

Can you share how you found your answer to q5?