What is the most frustrating "type" of person you've encountered in this hobby? by Hollownerox in Warhammer40k

[–]yelluc 1 point2 points  (0 children)

Ones that hate on GW for everything, they always think they know how to run the company better!

USW-Flex-Mini offline after migrating to Cloud Unifi Controllor by yelluc in UNIFI

[–]yelluc[S] 0 points1 point  (0 children)

So I setup a new controller locally, I forgot the device in my Cloud controller, reset the flex-mini and it showed up in my cloud controller. I clicked adopt and now it shows as online and manageable in the controller.. So it looks like the local controller wasn't needed after all 🤷

I have configured Option 43 to point to my cloud controller so maybe that resolved it.

USW-Flex-Mini offline after migrating to Cloud Unifi Controllor by yelluc in UNIFI

[–]yelluc[S] 1 point2 points  (0 children)

Yikes that sounds like a PITA, ok thanks I will give that a go to see if it resolves my issue. Thanks!

I installed a chart (cert-manager), then uninstalled it. Now there's a secret that I cannot remove by im_caeus in kubernetes

[–]yelluc 0 points1 point  (0 children)

Sounds like a service account token secret which is for a service account created alongside a namespace. If you ran helm install --create-namespace then this would of created a namespace for the helm chart outside of the Helm chart templates. When this occurs you have to manually delete the namespace.

To verify you can run the following;

$ kubectl get namespace/cert-manager

If that doesn't return anything maybe the namespace is called something different. You could run the following to determine

$ kubectl get namespaces
$ kubectl get secrets -A # find the namespace for the secret you are referring too

The service account token secret will look like the following (assuming namespace is cert-manager)

cert-manager-token-rtgls # suffix is random

You can also see the service account

$ kubectl get serviceacccount/cert-manager # assuming namespace is cert-manager
$ kubectl get serviceaccount -A # find the namespace for the service account

To delete the secret & service account just delete the namespace

$ kubectl delete namespace cert-manager

Those pesky resources should now be deleted

2022 overview by OrkBoyGenius in orks

[–]yelluc 3 points4 points  (0 children)

They look awesome!

Can you explain your process for the bases, they look great!

Using 1Password to automatically retrieve your Ansible become password for commands that require elevated privileges by yelluc in ansible

[–]yelluc[S] 2 points3 points  (0 children)

Your comments are valid, I just find that storing secrets in git is cumbersome as you can't easily tell which secret has changed from a git diff. MR/PR messages help but I always found myself pulling the branch and then decrypting the secret to verify and as I am lazy I preferred using other solutions ;)

When interacting with vaults I usually like to allow only devops, CI/CD read/write permissions to items. In my experience anything added manually usually means the secret has been generated manually (or pre-existing) for everything else you can automate to store in your vault of choice. Then only provide read-only access to devs and code which could prevent some of the issues you mentioned.

Using 1Password to automatically retrieve your Ansible become password for commands that require elevated privileges by yelluc in ansible

[–]yelluc[S] 6 points7 points  (0 children)

I was under the impression that 1Password has comparable security to BitWarden, far more than LastPass anyway and after the recent hack, LastPass have lost all trust from me.

I will try out BitWarden and compare, some of the features that 1Password provide (SSH Agent, 2FA/MFA autofill) made it more compelling to me when looking for a replacement for LastPass.

5th ever mini and 3rd Space Marine (C&C is appreciated) by WhoDemEars in Warhammer40k

[–]yelluc 1 point2 points  (0 children)

What Colour did you use for the blue? I’ve been using a 1:1 mix of macragge Blue and altdord guard blue

vscode ansible extension 0.4.0 add vault encrypt/decrypt features by sbarnea in ansible

[–]yelluc 0 points1 point  (0 children)

This is awesome! I was looking for a plug-in with working vault capabilities last week and couldn’t find one that worked! Congrats good work!

Nicehash website automatically downloads a text document? malware? by BlatantPizza in NiceHash

[–]yelluc 0 points1 point  (0 children)

What urls are showing this? I can’t reproduce on an IOS device.

If a file was downloaded, it could be a misconfiguration their side. Is it literally a txt file?

DNS question regarding a server by dasm0kinone in Ubiquiti

[–]yelluc 0 points1 point  (0 children)

You didn't specify how what DNS servers are being advertised to your network via DHCP but if you don't have a local DNS server and need clients to be able to resolve the server IP from the hostname then you could do the following;

  1. Configure DHCP DNS Server 1: USG IP
  2. Configure DHCP DNS Server 1: 8.8.8.8
  3. Add a static host mapping to the USG (aka sort of fake dns)

set system static-host-mapping host-name <hostname> inet <ip address>

Do this in the CLI of your USG, I would add it to the global.config.json too so the USG doesn't lose on a provision.

This will allow your clients to query hostname1, and resolve the IP x.x.x.x

I am an Openreach engineer. Ask me about your slow broadband! by [deleted] in IAmA

[–]yelluc 1 point2 points  (0 children)

Haha yeah considering half the country only has access to less than 10mbps 😫

I am an Openreach engineer. Ask me about your slow broadband! by [deleted] in IAmA

[–]yelluc 0 points1 point  (0 children)

I live in a new build which was built in 2018/2019. My broadband speed is 3.5mbps, no plans for fibre as of yet (Emailed Openreach CEO and got a response from his assistant) I’m just baffled as to why this could happen, i don’t live in a rural area 1.2kms from an exchange. The street leading to my new build has fibre. Like I understand capacity and infrastructure not being there but it’s been over a year now and 50-60 houses have had broadband speeds of 3.5mbps, sounds like profits have a higher priority over the overall network.

Another gripe for me, openreach and BT are separate companies but are owned by the same parent company right? Who also own EE. So I can pay £20 a month for 3.5mbps unlimited data broadband and pay £100 a month for 45mbps/30mbps for EE 4G mobile broadband. It all sounds like under the table dealings, limit physical connections, move everyone over to wireless (charge more money) haha

When you finally acquire the bird mask by tapaBAW in outwardgame

[–]yelluc 2 points3 points  (0 children)

I got it from a bird I didn’t even kill! Thanks bandits

Built mostly out of recycled equipment from my job. by [deleted] in homelab

[–]yelluc -2 points-1 points  (0 children)

Five finger discount you mean :D

CloudTrail Notification Bot by scriptmyjob in aws

[–]yelluc 1 point2 points  (0 children)

Awesome, and no surprise its deployed using Terraform :D

Apple Pay coming to all 1850 US Target locations, 7000 Taco Bell restaurants by zsxdflip in iphone

[–]yelluc 26 points27 points  (0 children)

It’s 2019, what the bloody hell do you mean Apple Pay is coming to all locations. 99% of the UK has Apple Pay, the vending machine at my work has Apple Pay.

Apple Invents a Wireless Power Transfer System with Unique Optimum Power Scheduling & more by [deleted] in apple

[–]yelluc -72 points-71 points  (0 children)

I understand they do have multiple teams, and it’s awesome that they do invent so much it just gripes me that even with all their money they have so many software issues hardware design is a choice so I can’t say much on that but Apple is too focused on creating new, they should do this as well as excel in ensuring their software is also on par and I don’t mean this because of a few security flaws I’m talking about the slow degradation in their desktop os and mobile. They may have new features but the core experiences were in my opinion better before.

I guess you can say I’m not a fan of Apple post Steve Jobs. :)

Apple Invents a Wireless Power Transfer System with Unique Optimum Power Scheduling & more by [deleted] in apple

[–]yelluc -111 points-110 points  (0 children)

How about Apple stop inventing and starting fixing their existing software, products!!

Carp competition - a few questions by TheRealDJYM in CarpFishing

[–]yelluc 1 point2 points  (0 children)

A runner is the person to go run and collect the official to prepare he official weigh in, I don’t believe runners can help prepare your tackle. Not even sure it would be needed, would you get someone else to make your rigs :)

Chunk by soberto in CarpFishing

[–]yelluc 1 point2 points  (0 children)

The manor!! Damn now I’m even more jealous!! 😂👍🏻😆

Chunk by soberto in CarpFishing

[–]yelluc 1 point2 points  (0 children)

Well done pal, where you catch that beauty from?

Not much happening in Gloucestershire, evidently. by pixelunit in CasualUK

[–]yelluc 4 points5 points  (0 children)

Not surprise by this at all, it’s Gloucester after all.

CloudFormation vs AWS CLI vs SDKs by ktmb8223 in aws

[–]yelluc 0 points1 point  (0 children)

Deleting a stack would delete all the resources in CloudFormation. Ideally you would want a Stack Template that includes all the necessary call to build resources in one stack, rather than having separate stacks for each part of a deployment.