๐Ÿ“– LDAP & Kerberos
๐Ÿ“– LDAP & Kerberos
Kerberos 1kinit <user> # obtain a ticket. 2klist # list the tickets in the cache. Services 1systemctl status slapd # OpenLDAP server. 2systemctl status sssd # System Security Services Daemon. LDAP - search 1ldapsearch -x -h <ldap-host> -b "ou=People,dc=example,dc=com" uid=<user> DN components: cn : common name ou : organizational unit o : organization c : country dc : domain component LDAP - add / modify 1# LDIF = the commands between EOF 2# -W prompts for the LDAP admin password 3# -w passes the password (put it in a variable) 4# bind_dn : the DN that acts as the LDAP bind user 5 6export bind_dn="CN=directory manager,DC=example,DC=org" 7 8# Modify an entry 9ldapadd -W -D "$bind_dn" -h $ldap_server -p 389 <<EOT 10dn: cn=user,ou=wiki,dc=example,dc=com 11changetype: modify 12add: memberUid 13memberUid: $login 14EOT 15 16# Create a new entry 17ldapadd -w $LDAPpwd -D "$bind_dn" -h $ldap_server -p 389 <<EOT 18dn: uid=${login},ou=People,dc=example,dc=org 19uid: ${login} 20loginShell: /bin/bash 21uidNumber: ${uid} 22gidNumber: 47110 23homeDirectory: /home/${login} 24shadowLastChange: 0 25shadowMax: -1 26objectClass: account 27objectClass: posixaccount 28objectClass: shadowaccount 29objectClass: top 30gecos: ${gecos} 31cn: ${gecos} 32userPassword: {CRYPT}`perl -e 'print crypt("${login}", "${login}")'` 33EOT
๐Ÿ” PAM
๐Ÿ” PAM
/etc/pam.d In /etc/pam.d, there is one PAM file per service. Syntax: module_type control_flag path_to_module_agent Module types auth โ€” authentication. account โ€” account-based restrictions (validity, time of day, etc.). session โ€” things that run at login/logout. password โ€” password updates. Control flags required โ€” success needed; a failure is reported but only after the rest of the stack has run. requisite โ€” like required, but a failure returns immediately without running the rest of the stack. sufficient โ€” if this module succeeds, it is the last module tested in the stack. optional โ€” its result is only taken into account if no other module succeeded or failed. [value=action value=action2 ...] โ€” advanced control: map a module result to a specific action. Sample:
๐Ÿ›ก๏ธ sudo
๐Ÿ›ก๏ธ sudo
/etc/sudoers The /etc/sudoers file contains the set of UNIX operating-system privileges that the local administrator has granted to UNIX users. In no case should this file be edited directly with vi; it must be edited with visudo. 1sudo : execute a command as root. 2sudo su : become root and stay root. 3sudoers : file listing the commands allowed for certain users as the superuser (or another user). 4visudo -cs : strict syntax check of the sudoers file. sudo -i is equivalent to su - in terms of rights. with sudo -i, the user password is asked. with su -, the root password is asked. Verification 1sudo -l -U <user> Rules 1# "user" runs "sudo -u target All_the_commands" 2user server=(target) NOPASSWD: ALL With aliases 1Host_Alias LOAD_BALANCERS = server1,server2 2 3Cmnd_Alias SET_VIP = \ 4/sbin/ip addr add 192.168.10.12/20 broadcast 192.168.15.255 dev eth0 label eth0\:0, \ 5/sbin/ip addr del 192.168.10.12/20 dev eth0, \ 6/sbin/arping -U -c 1 -I eth0 192.168.10.12 7 8loaduser LOAD_BALANCERS=(root) NOPASSWD: SET_VIP 9syncuser LOAD_BALANCERS=(root) NOPASSWD: SET_VIP
โฐ Jobs & Background
โฐ Jobs & Background
Schedule a task (at / batch) 1at : schedule a task to run at a later time (/!\ it executes what you give it on stdin). 2 ex : at 18:22 < "date; ps -ef | wc -l" 3 or : at now + 5 hours then type your commands then ctrl + d 4at -q a 16:05 tomorrow : -q defines the queue (a-z), i.e. the priority. 5at -c <job_number> : see the context and the commands of the task. 6atq : list the pending jobs (= at -l). 7atrm : delete a job. 8 9batch : schedule a task when the load average is below a threshold. Run jobs in the background 1jobs -l : list the running tasks. 1# Nohup in series 2for i in {1..6}; do echo "nohup sh -c \"shred -vfz -n 3 /dev/cciss/c0d${i} > nohup${i}.out 2>&1 \" &" ; done | bash Three points to remember:
๐ŸŽฏ CPU Affinity
๐ŸŽฏ CPU Affinity
Source : http://www.glennklockwood.com/hpc-howtos/process-affinity.html Taskset 1sudo apt-get install util-linux # or: yum install util-linux 2taskset -c 1 script.sh # run script.sh on CPU number 1 (-c: CPU, -p: PID) 3taskset -c 1,2,3 script.sh # give it several CPUs. Numactl 1numactl --cpunodebind=0 simulation.x 2numactl --cpunodebind=0 --membind=0 simulation.x 3numactl -C 0 -N 0 simulation.x 4numactl -C +0,1,2,3 simulation.x # similar to taskset 5numactl -H # see which memory corresponds to a CPU Note: with numactl, unlike taskset, you cannot change the CPU affinity of a process on the fly.
๐Ÿ› Tracing (strace / ltrace / gstack)
๐Ÿ› Tracing (strace / ltrace / gstack)
Strace - trace system calls 1strace -tt -p 24503 2 3strace -o strace01.out -e open -f bash --login -i # see the files opened during a bash connection. 4 # -o redirects the output / -e filters the system calls / -f follows forks (child processes) 5 6strace -f <binary_script> 2> trace.log : stdout -> the binary command result, stderr -> the binary's system calls. Ltrace - trace library calls ltrace traces shared-library calls (like strace, but at the library-call level).
๐Ÿ“Š Process Monitoring (pidstat)
๐Ÿ“Š Process Monitoring (pidstat)
pidstat reports the CPU, memory, I/O and context-switch activity of processes. Report the process context-switching activity 1# pidstat -w -p 3446 2 5 2Linux 3.10.0-123.13.2.el7.x86_64 (localhost.localdomain) 12/26/2014 3_x86_64_ (1 CPU) 407:23:38 AM UID PID cswch/s nvcswch/s Command 507:23:40 AM 0 3446 0.50 0.00 sshd 607:23:42 AM 0 3446 0.50 0.00 sshd 707:23:44 AM 0 3446 0.50 0.00 sshd 807:23:46 AM 0 3446 0.50 0.00 sshd 907:23:48 AM 0 3446 0.50 0.00 sshd 10Average: 0 3446 0.50 0.00 sshd cswch/s : number of voluntary context switches the task made per second. (A voluntary context switch occurs when a task blocks because it requires a resource that is unavailable.) nvcswch/s : number of non-voluntary context switches the task made per second. (An involuntary context switch takes place when a task executes for the duration of its time slice and is then forced to relinquish the processor.) Page faults and memory 1pidstat -r -p <PID> 3600 72 # every hour, 72 times - practical for long-term monitoring. 2 3pidstat -r -p <PID> 50 12 407:26:44 PM PID minflt/s majflt/s VSZ RSS %MEM Command 507:27:34 PM 13775 1.64 0.00 34957320 18183312 55.30 java minflt/s : number of minor faults the task has made per second โ€” those which did not require loading a memory page from disk. majflt/s : number of major faults the task has made per second โ€” those which required loading a memory page from disk. VSZ : Virtual Size โ€” the virtual memory usage of the entire task in kilobytes. RSS : Resident Set Size โ€” the non-swapped physical memory used by the task in kilobytes. Disk I/O 1pidstat -d -p <PID> 50 12 pidstat -d reports I/O statistics (kernels 2.6.20 and later only). The following values are displayed:
๐Ÿ” Find & Inspect Processes
๐Ÿ” Find & Inspect Processes
Find a process 1ps -fp <pid> # find a process by its PID. 2pidof httpd # find the PIDs of httpd. 3pidstat -lp <pid> # process name with all its complete arguments. 4 # for a tomcat or weblogic process, you can split the arguments with: sed 's/ -/\n -/g' 5pidstat -C "mysql" # find a process by its name (gives the PID and CPU load). The process tree 1pstree -pu # the process tree with PID and user (if pstree is not installed, use the alternatives below). 1ps -ejH 2 PID PGID SID TTY TIME CMD 3 1 1 1 ? 00:00:37 init 411016 11009 11009 ? 00:00:00 sshd 511017 11017 11017 pts/12 00:00:00 bash 611125 11125 11017 pts/12 00:00:00 telnet 1ps axjf 2 PPID PID PGID SID TTY TPGID STAT UID TIME COMMAND 3 0 1 1 1 ? -1 Ss 0 0:37 init [5] 4 8617 10610 10610 10610 ? -1 Ss 0 0:00 \_ sshd: support [priv] 510610 10710 10610 10610 ? -1 S 5027 0:00 \_ sshd: support@notty 610710 10711 10711 10711 ? -1 Ss 5027 0:00 \_ sshd: support@internal-sftp-server 1ps faux 2USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND 3root 1 0.0 0.0 10372 696 ? Ss Aug09 0:37 init [5] 4user1 4168 0.0 0.0 8728 968 ? Ss Aug24 0:00 | \_ /bin/bash -c perl /data/supports/scripts/SRAM_asr5k.pl &>/dev/null 5user1 4174 0.0 0.0 34068 5044 ? S Aug24 0:00 | \_ perl /data/supports/SRAM_asr5k.pl 6user1 4188 0.0 0.0 8728 984 ? S Aug24 0:00 | \_ sh -c grep -c SRAM /data/syslogCOLLECT/LTE_*/*/*.20160824.log /proc The /proc filesystem exposes per-process information:
๐Ÿ–ฅ Out-of-Band Management
๐Ÿ–ฅ Out-of-Band Management
Out-of-band management refers to accessing and controlling a server (console, power on/off, BIOS, remote media) through a dedicated management channel that is separate from the normal data path. “In-band” means going through the OS and its network interface; “out-of-band” uses an independent controller (a BMC โ€” Baseboard Management Controller) with its own network port, so it still works even when the OS is down, the machine is hung, or the network stack is broken. RSA is one vendor/technology family of out-of-band access.
๐Ÿ” ISO Checksum
๐Ÿ” ISO Checksum
Verify an ISO image To verify that an ISO image is good: compute its checksum with a sha1 or sha256 key, then compare it with the key published on the official website. 1sha256sum image.iso 2sha1sum image.iso
๐Ÿš€ KickStart
๐Ÿš€ KickStart
KickStart Technology that allows deploying servers with a predefined configuration (Red Hat’s equivalent of Solaris JumpStart). Default volume manager : LVM. See the LVM page for details.
๐Ÿง Unix Families
๐Ÿง Unix Families
The Unix variants Unix proprietary GNU / Linux BSD / open source Mainframe Virtualisation AIX Debian FreeBSD MVS (IBM) VMware / VirtualBox HP-UX Slackware NetBSD SCOS (Bull) Cloud (IaaS) SunOS (BSD fork) โ†’ Solaris SUSE OpenBSD OpenStack (IaaS/SaaS) IRIX (SGI) Red Hat FreeBSD โ†’ macOS Fedora openSUSE CentOS Ubuntu (Debian) Mint The Unix families Early SunOS (1โ€“4) was BSD-derived; from Solaris 2 / SunOS 5 onward it is System V (SVR4) based โ€” hence Solaris is listed under System V while the variants table notes its BSD fork. Historically, Unix split into two main branches:
๐Ÿ“ˆ Performance Monitoring & Tuning
๐Ÿ“ˆ Performance Monitoring & Tuning
How to approach performance monitoring and tuning in Linux, and the various subsystems (and performance metrics) that need to be monitored. On a very high level, the following four subsystems need to be monitored: CPU Memory I/O Network 1. CPU Four critical performance metrics for the CPU: context switch, run queue, CPU utilization, and load average. Context Switch When the CPU switches from one process (or thread) to another, it is called a context switch. When a process switch happens, the kernel stores the current state of the CPU (of a process or thread) in memory. The kernel also retrieves the previously stored state (of a process or thread) from memory and puts it in the CPU. Context switching is essential for multitasking of the CPU. However, a higher level of context switching can cause performance issues. Run Queue The run queue indicates the total number of active processes in the current queue for the CPU. When the CPU is ready to execute a process, it picks it up from the run queue based on the priority of the process. Note that processes that are in a sleep state, or I/O wait state, are not in the run queue. A higher number of processes in the run queue can therefore cause performance issues. CPU Utilization Indicates how much of the CPU is currently being used. 100% CPU utilization means the system is fully loaded. Load Average Indicates the average CPU load over a specific time period. On Linux, load average is displayed for the last 1 minute, 5 minutes, and 15 minutes. This helps to see whether the overall load on the system is going up or down. For example, a load average of 0.75 1.70 2.10 indicates that the load is coming down (0.75 = last 1 minute, 1.70 = last 5 minutes, 2.10 = last 15 minutes). Note that this load average is calculated by combining both the total number of processes in the queue, and the total number of processes in the uninterruptible task status. 2. Network A good understanding of TCP/IP concepts is helpful when analyzing any network issue. For network interfaces, monitor the total number of packets (and bytes) received/sent through the interface, the number of packets dropped, etc. 3. I/O I/O wait is the amount of time the CPU is waiting for I/O. Consistent high I/O wait on the system indicates a problem in the disk subsystem. Monitor reads/second and writes/second. These are measured in blocks, i.e. the number of blocks read/written per second. They are also referred to as bi and bo (block in and block out). tps indicates total transactions per second, which is the sum of rtps (read transactions per second) and wtps (write transactions per second). 4. Memory RAM is the physical memory. If you have 4 GB of RAM installed, you have 4 GB of physical memory. Virtual memory = swap space available on disk + physical memory. The virtual memory contains both user space and kernel space. Using a 32-bit or a 64-bit system makes a big difference in determining how much memory a process can use: On a 32-bit system a process can only access a maximum of 4 GB of virtual memory. On a 64-bit system there is no such limitation. Unused RAM is used by the kernel as filesystem cache. Linux swaps when it needs more memory than the physical memory. When it swaps, it writes the least-used memory pages from the physical memory to the swap space on the disk. Lots of swapping can cause performance issues: the disk is much slower than the physical memory, and it takes time to swap the memory pages from RAM to disk. The subsystems are interrelated All four subsystems are interrelated. Just because you see a high reads/second, writes/second, or I/O wait, it does not mean the issue is with the I/O subsystem. It also depends on what the application is doing. In most cases, the performance issue is caused by the application running on the Linux system.
๐Ÿงน Disk Cleanup
๐Ÿงน Disk Cleanup
Find old files 1find . -type f -mtime +150 -exec ls -lrt {} \; | more 2find . -maxdepth 1 -name "*.log" -mtime +10 -exec ls -lrt {} \; 3find . -mtime +150 -exec rm -f {} \; The find loop is cheaper than a shell loop (for ...). You can make it even more efficient by batching the rm calls: 1find . -type f -print -exec rm -- "{}" + # note the "+" instead of the usual "\;" See which directories use the most space 1du -max . # list all the FS sub-directories (-x avoids filesystems other than the requested one, "." = search from where you are) 2du -sh * # show the total without listing the sub-directories (h = human readable) 3du -max . | sort -n | tail -30 # the 30 largest files/directories 4du -ks * | sort -n # size in kilobytes of all files and directories, where you are 5du -hsc * | sort -h # from smallest to largest 6ls -lrS # list files by size (in bytes) - note: ls -l does not give the true value contained in a directory 7du -ch /dir/ # size of the directories contained in /dir/ (with suffix) then the total Reduce / Truncate a file 1perl -e 'truncate "wanted_file", 100000' 2truncate -s 0 /ftpusers/ftp.upload.log File deleted but space still held by a process 1lsof +aL1 # "+L1" selects open files that have been "unlinked" (deleted but still open) 2lsof -nP | grep '(deleted)' 3find /proc/*/fd -type f -links 0 -exec ls -lrt {} \; # [SunOS] There are two solutions:
๐Ÿ’พ Backup & Sync
๐Ÿ’พ Backup & Sync
Rsync The classic formula 1rsync -arv --info=progress2 photo backup_photo a = archive โ€” preserves permissions (owner, group), times, symbolic links and devices. r = recursive โ€” copies directories and sub-directories. v = verbose โ€” prints what is being copied. Examples 1rsync -apvz --stats --update --exclude gsast/olap_cubes --exclude gsast/param user@server-src:/export/ user@server-dest:/home/ 2rsync -av -e ssh root@192.168.1.10:/backup/DUMP/* . 3rsync -azp --stats root@oracle-src:/ec/sw/oracle/client/product/12.2.0.1/network/mesg/ ~/mesg/ 4rsync -azp /home/user/mesg/ root@oracle-dest.example.com:/ec/sw/oracle/client/product/12.2.0.1/network/mesg/ 5 6ssh root@oracle-dest.example.com "ls -lrt /ec/sw/oracle/client/product/12.2.0.1/network/mesg/" 7ssh root@oracle-dest.example.com "chown oracle:dc_dba /ec/sw/oracle/client/product/12.2.0.1/network/mesg/*" 8 9rsync -aS --delete --rsh /export/home backup-host:/export/save Propagate deletions to the backup If you delete files in the source directory, rsync does not propagate the deletion to the backup directory unless you add the --delete option.
๐Ÿ—œ Compression
๐Ÿ—œ Compression
Zip / Unzip 1zip <archive.zip> <file1> <file2> # compress files. 2zip -r <archive.zip> <directory> # compress a directory. 3unzip archive_name.zip [-d directory] # decompress an archive. Gzip / Gunzip gzip is based on the Deflate algorithm (a combination of the LZ77 and Huffman algorithms). 1gzip -l # show the size of the uncompressed file. 2gzip <file> # compress. 3gunzip <file.gz> | gzip -d <file.gz> # decompress. 4gzip -9 <my_file> # compress a file optimally. 5gzip -c <file1> <file2> > compressed_file.gz # compress several files into a single one. Bzip2 / Bunzip2 bzip2 is an alternative to gzip, more efficient but slower.
โŒจ๏ธ Bash Shortcut
โŒจ๏ธ Bash Shortcut
Most usefull shortcuts Ctrl + r : Reverse search. (ctrl+r to go back through the history). Ctrl + l : Clear the screen (instead of using the “clear” command). Ctrl + p : Repeat the last command. Ctrl + x + Ctrl + e : Edit the current command in an external editor (need to define export EDITOR=vim). Ctrl + shift + v : Copy / paste in Linux. Ctrl + a : Move to the beginning of the line. Ctrl + e : Move to the end of the line. Ctrl + xx : Move to the opposite end of the line. Ctrl + left : Move left one word. Ctrl + right : Move right one word.
โ˜๏ธ Cloud-Init
โ˜๏ธ Cloud-Init
Troubleshooting cloud-init status --wait usefull for scripting, waiting cloud-init to finish before going to next step. cloud-init status --long 1status: done 2extended_status: done 3boot_status_code: enabled-by-generator 4last_update: Thu, 01 Jan 1970 00:00:55 +0000 5detail: DataSourceNoCloud [seed=/dev/sr0] 6errors: [] 7recoverable_errors: {} sudo cloud-init analyze show 1-- Boot Record 01 -- 2The total time elapsed since completing an event is printed after the "@" character. 3The time the event takes is printed after the "+" character. 4 5Starting stage: init-local 6|`->no cache found @00.00600s +00.00000s 7|`->found local data from DataSourceNoCloud @00.01500s +00.12600s 8Finished stage: (init-local) 00.75400 seconds 9 10Starting stage: init-network 11|`->restored from cache with run check: DataSourceNoCloud [seed=/dev/sr0] @04.21100s +00.00200s 12|`->setting up datasource @04.22800s +00.00000s 13|`->reading and applying user-data @04.23400s +00.00500s 14|`->reading and applying vendor-data @04.23900s +00.00000s 15|`->reading and applying vendor-data2 @04.23900s +00.00000s 16|`->activating datasource @04.27100s +00.00100s 17|`->config-seed_random ran successfully and took 0.000 seconds @04.29500s +00.00100s 18|`->config-write_files ran successfully and took 0.001 seconds @04.29600s +00.00100s 19|`->config-growpart ran successfully and took 0.562 seconds @04.29700s +00.56200s 20|`->config-resizefs ran successfully and took 0.193 seconds @04.86000s +00.19200s 21|`->config-mounts ran successfully and took 0.001 seconds @05.05200s +00.00100s 22|`->config-set_hostname ran successfully and took 0.004 seconds @05.05300s +00.00500s 23|`->config-update_hostname ran successfully and took 0.001 seconds @05.05800s +00.00100s 24|`->config-update_etc_hosts ran successfully and took 0.005 seconds @05.05900s +00.00500s 25|`->config-users_groups ran successfully and took 0.216 seconds @05.06400s +00.21600s 26|`->config-ssh ran successfully and took 0.404 seconds @05.28100s +00.40400s 27|`->config-set_passwords ran successfully and took 0.001 seconds @05.68500s +00.00200s 28Finished stage: (init-network) 01.50000 seconds 29 30Starting stage: modules-config 31|`->config-ssh_import_id ran successfully and took 0.001 seconds @07.43300s +00.00100s 32|`->config-locale ran successfully and took 0.003 seconds @07.43400s +00.00300s 33|`->config-grub_dpkg ran successfully and took 0.352 seconds @07.43700s +00.35200s 34|`->config-apt_configure ran successfully and took 0.049 seconds @07.79000s +00.04800s 35|`->config-timezone ran successfully and took 0.007 seconds @07.83900s +00.00700s 36|`->config-runcmd ran successfully and took 0.001 seconds @07.84600s +00.00100s 37|`->config-byobu ran successfully and took 0.000 seconds @07.84700s +00.00100s 38Finished stage: (modules-config) 00.45400 seconds 39 40Starting stage: modules-final 41|`->config-package_update_upgrade_install ran successfully and took 26.632 seconds @20.56700s +26.63300s 42|`->config-write_files_deferred ran successfully and took 0.001 seconds @47.20000s +00.00200s 43|`->config-reset_rmc ran successfully and took 0.000 seconds @47.20200s +00.00100s 44|`->config-scripts_vendor ran successfully and took 0.001 seconds @47.20300s +00.00000s 45|`->config-scripts_per_once ran successfully and took 0.000 seconds @47.20300s +00.00100s 46|`->config-scripts_per_boot ran successfully and took 0.000 seconds @47.20400s +00.00000s 47|`->config-scripts_per_instance ran successfully and took 0.000 seconds @47.20400s +00.00100s 48|`->config-scripts_user ran successfully and took 0.558 seconds @47.20500s +00.55800s 49|`->config-ssh_authkey_fingerprints ran successfully and took 0.005 seconds @47.76400s +00.00500s 50|`->config-keys_to_console ran successfully and took 0.054 seconds @47.76900s +00.05500s 51|`->config-install_hotplug ran successfully and took 0.001 seconds @47.82400s +00.00100s 52|`->config-final_message ran successfully and took 0.001 seconds @47.82500s +00.00100s 53Finished stage: (modules-final) 27.29600 seconds Check the logs: sudo tail -n 50 /var/log/cloud-init-output.log
โš“ Harbor
โœ๏ธ Vim
โœ๏ธ Vim
Tutorials https://vimvalley.com/ https://vim-adventures.com/ https://www.vimgolf.com/ Plugins 1# HCL 2mkdir -p ~/.vim/pack/jvirtanen/start 3cd ~/.vim/pack/jvirtanen/start 4git clone https://github.com/jvirtanen/vim-hcl.git 5 6# Justfile 7mkdir -p ~/.vim/pack/vendor/start 8cd ~/.vim/pack/vendor/start 9git clone https://github.com/NoahTheDuke/vim-just.git Fun Facts trigger a vim tutorial vimtutor the most powerful commands: . : Repeat the last modification. * : Where the cursor is located, keeps the word in memory and goes to the next occurrence. .* : together, repeat an action on the next word.
๐ŸŒ… UV
๐ŸŒ… UV
Install 1# curl method 2curl -LsSf https://astral.sh/uv/install.sh | sh 3 4# Pip method 5pip install uv Quick example 1pyenv install 3.12 2pyenv local 3.12 3python -m venv .venv 4source .venv/bin/activate 5pip install pandas 6python 7 8# equivalent in uv 9uv run --python 3.12 --with pandas python Usefull 1uv python list --only-installed 2uv python install 3.12 3uv venv /path/to/environment --python 3.12 4uv pip install django 5uv pip compile requirements.in -o requirements.txt 6 7uv init myproject 8uv sync 9uv run manage.py runserver Run as script Put before the import statements: 1#!/usr/bin/env -S uv run --script 2# /// script 3# requires-python = ">=3.12" 4# dependencies = [ 5# "ffmpeg-normalize", 6# ] 7# /// Then can be run with uv run sync-flickr-dates.py. uv will create a Python 3.12 venv for us. For me this is in ~/.cache/uv (which you can find via uv cache dir).
๐ŸŒ Network troubleshooting
๐ŸŒ Network troubleshooting
Troubleshoot DNS vi dns.yml 1apiVersion: v1 2kind: Pod 3metadata: 4 name: dnsutils 5 namespace: default 6spec: 7 containers: 8 - name: dnsutils 9 image: registry.k8s.io/e2e-test-images/jessie-dnsutils:1.3 10 command: 11 - sleep 12 - "infinity" 13 imagePullPolicy: IfNotPresent 14 restartPolicy: Always deploy dnsutils 1k apply -f dns.yml 2pod/dnsutils created 3 4kubectl get pods dnsutils 5NAME READY STATUS RESTARTS AGE 6dnsutils 1/1 Running 0 36s Troubleshoot with dnsutils 1kubectl exec -i -t dnsutils -- nslookup kubernetes.default 2;; connection timed out; no servers could be reached 3command terminated with exit code 1 4 5kubectl exec -ti dnsutils -- cat /etc/resolv.conf 6search default.svc.cluster.local svc.cluster.local cluster.local example.local 7nameserver 10.43.0.10 8options ndots:5 9 10kubectl get endpoints kube-dns --namespace=kube-system 11NAME ENDPOINTS AGE 12kube-dns 10.42.0.6:53,10.42.0.6:53,10.42.0.6:9153 5d1h 13 14kubectl get svc kube-dns --namespace=kube-system 15NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE 16kube-dns ClusterIP 10.43.0.10 <none> 53/UDP,53/TCP,9153/TCP 5d1h CURL 1cat << EOF > curl.yml 2apiVersion: v1 3kind: Pod 4metadata: 5 name: curl 6 namespace: default 7spec: 8 containers: 9 - name: curl 10 image: curlimages/curl 11 command: 12 - sleep 13 - "infinity" 14 imagePullPolicy: IfNotPresent 15 restartPolicy: Always 16EOF 17 18k apply -f curl.yml 19 20#Test du DNS 21kubectl exec -i -t curl -- curl -v telnet://10.43.0.10:53 22kubectl exec -i -t curl -- curl -v telnet://kube-dns.kube-system.svc.cluster.local:53 23kubectl exec -i -t curl -- nslookup kube-dns.kube-system.svc.cluster.local 24 25curl -k -I --resolve subdomain.domain.com:52.165.230.62 https:/subdomain.domain.com/
๐ŸŽก Helm
๐ŸŽก Helm
Administration See what is currently installed 1helm list -A 2NAME NAMESPACE REVISION UPDATED STATUS CHART APP VERSION 3nesux3 default 1 2022-08-12 20:01:16.0982324 +0200 CEST deployed nexus3-1.0.6 3.37.3 Install/Uninstall 1helm status nesux3 2helm uninstall nesux3 3helm install nexus3 <chart> # chart URL or path 4helm history nexus3 5 6# work even if already installed 7helm upgrade --install ingress-nginx ${DIR}/helm/ingress-nginx \ 8 --namespace=ingress-nginx \ 9 --create-namespace \ 10 -f ${DIR}/helm/ingress-values.yml 11 12#Make helm unsee an apps (it does not delete the apps) 13kubectl delete secret -l owner=helm,name=argo-cd Handle Helm Repo and Charts 1#Handle repo 2helm repo list 3helm repo add gitlab https://charts.gitlab.io/ 4helm repo update 5 6#Pretty usefull to configure 7helm show values elastic/eck-operator 8helm show values grafana/grafana --version 8.5.1 9 10#See different version available 11helm search repo hashicorp/vault 12helm search repo hashicorp/vault -l 13 14# download a chart 15helm fetch ingress/ingress-nginx --untar
๐ŸŽซ Certificates Authority
๐ŸŽซ Certificates Authority
Trust a CA on Linux host 1# [RHEL] RootCA from DC need to be installed on host: 2cp my-domain-issuing.crt /etc/pki/ca-trust/source/anchors/my_domain_issuing.crt 3cp my-domain-rootca.crt /etc/pki/ca-trust/source/anchors/my_domain_rootca.crt 4update-ca-trust extract 5 6# [Ubuntu] 7sudo apt-get install -y ca-certificates 8sudo cp local-ca.crt /usr/local/share/ca-certificates 9sudo update-ca-certificates
๐ŸŽฒ Kubectl
๐ŸŽฒ Kubectl
Connection to k8s cluster Kubeconfig Define KUBECONFIG in your profile 1# Default one 2KUBECONFIG=~/.kube/config 3 4# Several context - to keep splited 5KUBECONFIG=~/.kube/k3sup-lab:~/.kube/k3s-dev 6 7# Or can be specified in command 8kubectl get pods --kubeconfig=admin-kube-config View and Set 1kubectl config view 2kubectl config current-context 3 4kubectl config set-context \ 5dev-context \ 6--namespace=dev-namespace \ 7--cluster=docker-desktop \ 8--user=dev-user 9 10kubectl config use-context lab Switch context 1#set Namespace 2kubectl config set-context --current --namespace=nexus3 3kubectl config get-contexts Kubecm The problem with the kubeconfig is that it get nexted in one kubeconfig and difficult to manage on long term. The best way to install it, is with Arkade arkade get kubecm - see arkade.
๐Ÿญ Docker
๐Ÿญ Docker
See also documentation about Podman and Docker How to use a docker regsitry 1# list index catalog 2curl https://registry.k3s.example.com/v2/_catalog | jq 3 4# List tags available regarding an image 5curl https://registry.k3s.example.com/v2/myhaproxy/tags/list 6 7# list index catalog - with user/password 8curl https://registry-admin:<PWD>@registry.k3s.example.com/v2/_catalog | jq 9 10# list index catalog - when you need to specify the CA 11curl -u user:password https://<url>:<port>/v2/_catalog --cacert ca.crt | jq 12 13# list index catalog - for OCP 14curl -u user:password https://<url>:<port>/v2/ocp4/openshift4/tags/list | jq 15 16# Login to registry with podman 17podman login -u registry-admin -p <PWD> registry.k3s.example.com 18 19# Push images in the registry 20skopeo copy "--dest-creds=registry-admin:<PWD>" docker://docker.io/goharbor/harbor-core:v2.6.1 docker://registry.k3s.example.com/goharbor/harbor-core:v2.6.1 Install a Local private docker registry Change Docker Daemon config to allow insecure connection with your ip 1ip a 2sudo vi /etc/docker/daemon.json 1{ 2"insecure-registries": ["192.168.1.11:5000"] 3} 1sudo systemctl restart docker 2docker info Check docker config
๐Ÿ„ RKE2
๐Ÿ„ RKE2
General Checks Nice gist to troubleshoot etcd link 1journalctl -u rke2-server.service -f 2 3tail -f /var/lib/rancher/rke2/agent/containerd/containerd.log 4 5tail -f /var/lib/rancher/rke2/agent/logs/kubelet.log 6 7# crictl 8export CRI_CONFIG_FILE=/var/lib/rancher/rke2/agent/etc/crictl.yaml 9/var/lib/rancher/rke2/bin/crictl ps 10 11/var/lib/rancher/rke2/bin/crictl --config /var/lib/rancher/rke2/agent/etc/crictl.yaml ps 12 13/var/lib/rancher/rke2/bin/crictl --runtime-endpoint unix:///run/k3s/containerd/containerd.sock ps -a 14 15/var/lib/rancher/rke2/bin/ctr --address /run/k3s/containerd/containerd.sock --namespace k8s.io container ls 16 17# Kubectl 18export KUBECONFIG=/etc/rancher/rke2/rke2.yaml 19export PATH=$PATH:/usr/local/bin/:/var/lib/rancher/rke2/bin/ 20kubectl get addon -A Check etcd endpoint status 1export CRI_CONFIG_FILE=/var/lib/rancher/rke2/agent/etc/crictl.yaml 2etcdcontainer=$(/var/lib/rancher/rke2/bin/crictl ps --label io.kubernetes.container.name=etcd --quiet) 3/var/lib/rancher/rke2/bin/crictl exec $etcdcontainer sh -c "ETCDCTL_ENDPOINTS='https://127.0.0.1:2379' ETCDCTL_CACERT='/var/lib/rancher/rke2/server/tls/etcd/server-ca.crt' ETCDCTL_CERT='/var/lib/rancher/rke2/server/tls/etcd/server-client.crt' ETCDCTL_KEY='/var/lib/rancher/rke2/server/tls/etcd/server-client.key' ETCDCTL_API=3 etcdctl endpoint status --cluster --write-out=table" Check etcd health status 1export CRI_CONFIG_FILE=/var/lib/rancher/rke2/agent/etc/crictl.yaml 2etcdcontainer=$(/var/lib/rancher/rke2/bin/crictl ps --label io.kubernetes.container.name=etcd --quiet) 3/var/lib/rancher/rke2/bin/crictl exec $etcdcontainer sh -c "ETCDCTL_ENDPOINTS='https://127.0.0.1:2379' ETCDCTL_CACERT='/var/lib/rancher/rke2/server/tls/etcd/server-ca.crt' ETCDCTL_CERT='/var/lib/rancher/rke2/server/tls/etcd/server-client.crt' ETCDCTL_KEY='/var/lib/rancher/rke2/server/tls/etcd/server-client.key' ETCDCTL_API=3 etcdctl endpoint health --cluster --write-out=table"
๐Ÿ‹ Digital Ocean
๐Ÿ‹ Digital Ocean
Install Client 1# most simple 2arkade get doctl 3 4# normal way 5curl -OL https://github.com/digitalocean/doctl/releases/download/v1.104.0/doctl-1.104.0-linux-amd64.tar.gz 6tar xf doctl-1.104.0-linux-amd64.tar.gz 7mv doctl /usr/local/bin 8 9# Auto-Completion ZSH 10 doctl completion zsh > $ZSH/completions/_doctl Basics find possible droplet 1doctl compute region list 2doctl compute size list 3doctl compute image list-distribution 4doctl compute image list --public Auth 1doctl auth init --context test 2doctl auth list 3doctl auth switch --context test2 Create Project 1doctl projects create --name rkub --environment staging --purpose "stage rkub with github workflows" Create VM 1doctl compute ssh-key list 2doctl compute droplet create test --region fra1 --image rockylinux-9-x64 --size s-1vcpu-1gb --ssh-keys <fingerprint> 3doctl compute droplet delete test -f with Terraform 1export DO_PAT="dop_v1_xxxxxxxxxxxxxxxx" 2doctl auth init --context rkub 3 4# inside a dir with a tf file 5terraform init 6terraform validate 7terraform plan -var "do_token=${DO_PAT}" 8terraform apply -var "do_token=${DO_PAT}" -auto-approve 9 10# clean apply 11terraform plan -out=infra.tfplan -var "do_token=${DO_PAT}" 12terraform apply infra.tfplan 13 14# Control 15terraform show terraform.tfstate 16 17# Destroy 18terraform plan -destroy -out=terraform.tfplan -var "do_token=${DO_PAT}" 19terraform apply terraform.tfplan Connect to Droplet with private ssh key ssh root@$(terraform output -json ip_address_workers | jq -r ‘.[0]’) -i .key
๐Ÿ Cobra
๐Ÿ Cobra
A Command Builder for Go Cobra is a Go library for building command-line applications. It is used by many well-known tools from the Go ecosystem because it gives us a convenient structure for: commands subcommands arguments flags validation help shell completion error handling A Cobra application usually reads naturally: 1app command argument --flag value For example: 1git clone repository --bare 2kubectl get pods --namespace production A useful introduction is also available here:
๐ŸŽ K3D
๐ŸŽ K3D
K3D equal k3s in a container. a tools to create single- and multi-node k3s clusters. Our favorite use case, is with podman and rootless. So there is some customization upstream to do. One downside Iโ€™ve found with k3d is that the Kubernetes version it uses is behind the current k3s release. Note for ARM PC: 1sudo apt install qemu-user-static 2podman run --rm --privileged multiarch/qemu-user-static --reset -p yes Install 1# Manual way 2curl -s https://raw.githubusercontent.com/k3d-io/k3d/main/install.sh | bash 3 4# or with arkade: 5arkade get k3d 6 7# Auto-completion 8k3d completion zsh > "$ZSH/completions/_k3d" Tweaks for podman and rootless The issue: 1k3d cluster create test 2 3ERRO[0000] Failed to get nodes for cluster 'test': docker failed to get containers with labels 'map[k3d.cluster:test]': failed to list containers: permission denied while trying to connect to the Docker daemon socket at unix:///var/run/docker.sock: Get "http://%2Fvar%2Frun%2Fdocker.sock/v1.46/containers/json?all=1&filters=%7B%22label%22%3A%7B%22app%3Dk3d%22%3Atrue%2C%22k3d.cluster%3Dtest%22%3Atrue%7D%7D": dial unix /var/run/docker.sock: connect: permission denied The solution: 1# TODO 2loginctl enable-linger $(whoami) 3 4# Either reload terminal or do below: 5export XDG_RUNTIME_DIR=/tmp/run-$(id -u) 6mkdir -p $XDG_RUNTIME_DIR 7chmod 700 $XDG_RUNTIME_DIR 8 9sudo mkdir -p /etc/containers/containers.conf.d 10sudo sh -c "echo 'service_timeout=0' > /etc/containers/containers.conf.d/timeout.conf" 11 12sudo ln -s /run/podman/podman.sock /var/run/docker.sock 13 14XDG_RUNTIME_DIR=${XDG_RUNTIME_DIR:-/run/user/$(id -u)} 15export DOCKER_HOST=unix://$XDG_RUNTIME_DIR/podman/podman.sock 16export DOCKER_SOCK=$XDG_RUNTIME_DIR/podman/podman.sock 17 18systemctl --user enable --now podman.socket If /sys/fs/cgroup/cgroup.controllers is present on your system, you are using v2, otherwise you are using v1.