Memo

🐎 K3D
🐎 K3D
K3D equal k3s in a container. a tools to create single- and multi-node k3s clusters. Our favorite use case, is with podman and rootless. So there is some customization upstream to do. One downside I’ve found with k3d is that the Kubernetes version it uses is behind the current k3s release. Note for ARM PC: 1sudo apt install qemu-user-static 2podman run --rm --privileged multiarch/qemu-user-static --reset -p yes Install 1# Manual way 2curl -s https://raw.githubusercontent.com/k3d-io/k3d/main/install.sh | bash 3 4# or with arkade: 5arkade get k3d 6 7# Auto-completion 8k3d completion zsh > "$ZSH/completions/_k3d" Tweaks for podman and rootless The issue: 1k3d cluster create test 2 3ERRO[0000] Failed to get nodes for cluster 'test': docker failed to get containers with labels 'map[k3d.cluster:test]': failed to list containers: permission denied while trying to connect to the Docker daemon socket at unix:///var/run/docker.sock: Get "http://%2Fvar%2Frun%2Fdocker.sock/v1.46/containers/json?all=1&filters=%7B%22label%22%3A%7B%22app%3Dk3d%22%3Atrue%2C%22k3d.cluster%3Dtest%22%3Atrue%7D%7D": dial unix /var/run/docker.sock: connect: permission denied The solution: 1# TODO 2loginctl enable-linger $(whoami) 3 4# Either reload terminal or do below: 5export XDG_RUNTIME_DIR=/tmp/run-$(id -u) 6mkdir -p $XDG_RUNTIME_DIR 7chmod 700 $XDG_RUNTIME_DIR 8 9sudo mkdir -p /etc/containers/containers.conf.d 10sudo sh -c "echo 'service_timeout=0' > /etc/containers/containers.conf.d/timeout.conf" 11 12sudo ln -s /run/podman/podman.sock /var/run/docker.sock 13 14XDG_RUNTIME_DIR=${XDG_RUNTIME_DIR:-/run/user/$(id -u)} 15export DOCKER_HOST=unix://$XDG_RUNTIME_DIR/podman/podman.sock 16export DOCKER_SOCK=$XDG_RUNTIME_DIR/podman/podman.sock 17 18systemctl --user enable --now podman.socket If /sys/fs/cgroup/cgroup.controllers is present on your system, you are using v2, otherwise you are using v1.
Networks
GoDog
Golang
Golang
Installation Install Go: 1GO_VERSION="1.21.0" 2 3wget https://go.dev/dl/go${GO_VERSION}.linux-amd64.tar.gz 4sudo rm -rf /usr/local/go 5sudo tar -C /usr/local -xzf go${GO_VERSION}.linux-amd64.tar.gz 6 7export PATH="/usr/local/go/bin:$PATH" 8 9go version To keep Go available after reboot: 1echo 'export PATH="/usr/local/go/bin:$PATH"' >> ~/.bashrc 2source ~/.bashrc Create a project 1mkdir myapp 2cd myapp 3 4go mod init myapp A go.mod file is created: 1myapp/ 2└── go.mod It describes the Go module and its dependencies. Hello World Create main.go: 1package main 2 3import "fmt" 4 5func main() { 6 fmt.Println("Hello World") 7} 1go run . 2go build This creates a binary: ./myapp
Hugo
Projects
Projects
Just a short list of personnal projects, I am currently working on.
🚩 Firewalld
🚩 Firewalld
Basic Troubleshooting 1# Get the state 2firewall-cmd --state 3systemctl status firewalld 4 5# Get infos 6firewall-cmd --get-default-zone 7firewall-cmd --get-active-zones 8firewall-cmd --get-zones 9firewall-cmd --set-default-zone=home 10 11firewall-cmd --permanent --zone=FedoraWorkstation --add-source=00:FF:B0:CB:30:0A 12firewall-cmd --permanent --zone=FedoraWorkstation --add-service=ssh 13 14firewall-cmd --get-log-denied 15firewall-cmd --set-log-denied=<all, unicast, broadcast, multicast, or off> Add/Remove/List Services 1#Remove 2firewall-cmd --zone=public --add-service=ftp --permanent 3firewall-cmd --zone=public --remove-service=ftp --permanent 4firewall-cmd --zone=public --remove-port=53/tcp --permanent 5firewall-cmd --zone=public --list-services 6 7# Add 8firewall-cmd --zone=public --new-service=portal --permanent 9firewall-cmd --zone=public --service=portal --add-port=8080/tcp --permanent 10firewall-cmd --zone=public --service=portal --add-port=8443/tcp --permanent 11firewall-cmd --zone=public --add-service=portal --permanent 12firewall-cmd --reload 13 14firewall-cmd --zone=public --new-service=k3s-server --permanent 15firewall-cmd --zone=public --service=k3s-server --add-port=443/tcp --permanent 16firewall-cmd --zone=public --service=k3s-server --add-port=6443/tcp --permanent 17firewall-cmd --zone=public --service=k3s-server --add-port=8472/udp --permanent 18firewall-cmd --zone=public --service=k3s-server --add-port=10250/tcp --permanent 19firewall-cmd --zone=public --add-service=k3s-server --permanent 20firewall-cmd --reload 21 22firewall-cmd --zone=public --new-service=quay --permanent 23firewall-cmd --zone=public --service=quay --add-port=8443/tcp --permanent 24firewall-cmd --zone=public --add-service=quay --permanent 25firewall-cmd --reload 26 27firewall-cmd --get-services # It's also possible to add a service from list 28firewall-cmd --runtime-to-permanent Checks and Get infos list open port by services 1for s in `firewall-cmd --list-services`; do echo $s; firewall-cmd --permanent --service "$s" --get-ports; done; 2 3sudo sh -c 'for s in `firewall-cmd --list-services`; do echo $s; firewall-cmd --permanent --service "$s" --get-ports; done;' 4ssh 522/tcp 6dhcpv6-client 7546/udp Check one service 1firewall-cmd --info-service cfrm-IC 2cfrm-IC 3 ports: 7780/tcp 8440/tcp 8443/tcp 4 protocols: 5 source-ports: 6 modules: 7 destination: List zones and services associated 1firewall-cmd --list-all 2public (active) 3 target: default 4 icmp-block-inversion: no 5 interfaces: ens192 6 sources: 7 services: ssh dhcpv6-client https Oracle nimsoft 8 ports: 10050/tcp 1521/tcp 9 protocols: 10 masquerade: no 11 forward-ports: 12 source-ports: 13 icmp-blocks: 14 rich rules: 1firewall-cmd --zone=backup --list-all Get active zones 1firewall-cmd --get-active-zones 2backup 3 interfaces: ens224 4public 5 interfaces: ens192 Tree folder 1ls /etc/firewalld/ 2firewalld.conf helpers/ icmptypes/ ipsets/ lockdown-whitelist.xml services/ zones/ IPSET 1firewall-cmd --get-ipset-types 2firewall-cmd --permanent --get-ipsets 3firewall-cmd --permanent --info-ipset=integration 4firewall-cmd --ipset=integration --get-entries 5 6firewall-cmd --permanent --new-ipset=test --type=hash:net 7firewall-cmd --ipset=local-blocklist --add-entry=103.133.104.0/23
⚙️ Systemd
⚙️ Systemd
systemd replaces the SysV init system: services are managed with systemctl, and runlevels map to targets. 1systemctl status <unit> # status of a service. 2systemctl start|stop|restart <unit> # run / stop / restart. 3systemctl enable|disable <unit> # start at boot (or not). 4systemctl isolate multi-user.target # equivalent of runlevel 3. 5systemctl set-default multi-user.target # change the default target. 6systemctl get-default See the Runlevels & Shutdown page for the classic runlevel table.
👢 Boot
👢 Boot
The Boot - starting process - The BIOS is started automatically and detects the peripherals. - Loads the boot routine from the MBR (Master Boot Record) - it is the boot disk, located on the first sector of the hard disk. - The MBR contains a loader that loads the "second stage loader": this is the "boot loader" specific to the system being loaded. -> Linux uses LILO (Linux Loader) or GRUB (Grand Unified Bootloader). - LILO loads the kernel into memory, decompresses it, and passes it the parameters. - The kernel mounts the `/` filesystem (from there, the commands in `/sbin` and `/bin` are available). - The kernel runs its first process: `init`. LILO is a legacy bootloader (obsolete), superseded by GRUB and now GRUB2. The LILO section below is kept for historical reference. LILO configuration LILO can offer several kernels as choices. The default choice: “Linux”. /etc/lilo.conf : configuration of the kernel parameters. /sbin/lilo : to write the new parameters to disk. -> creates the /boot/map file, which contains the physical blocks where the boot program is located.
🔄 Data Guard
🔄 Data Guard
Synchronisation mechanism between two databases in Active/Passive. Switchover 1dgmgrl sys@orcl 2DGMGRL> switchover to 'orcl'; Check primary / standby 1echo -e "set heading off;\n select database_role FROM v\$database;" | sqlplus -S / as sysdba 2# PHYSICAL STANDBY (or PRIMARY) 3 4echo -e "set heading off;\n select open_mode FROM v\$database;" | sqlplus -S / as sysdba 5# MOUNTED (a standby is mounted, not open) PRIMARY + READ WRITE → primary. PHYSICAL STANDBY + MOUNTED → standby.
🕵️ Auditing
🕵️ Auditing
Enable auditing 1ALTER SYSTEM SET audit_trail = DB, EXTENDED SCOPE = SPFILE; -- detailed user actions. 2SHOW PARAMETER audit_trail; -- default NONE → set it to EXTENDED where possible. 3SHOW PARAMETER audit; -- the full audit configuration. Audit users 1AUDIT SELECT TABLE, UPDATE TABLE, INSERT TABLE BY hr BY SESSION; 2AUDIT SELECT TABLE, UPDATE TABLE, INSERT TABLE BY hr BY SESSION WHENEVER SUCCESSFUL; 3AUDIT SELECT TABLE, UPDATE TABLE, INSERT TABLE BY hr BY SESSION WHENEVER NOT SUCCESSFUL; 4AUDIT SELECT TABLE, UPDATE TABLE, INSERT TABLE BY hr BY ACCESS; 5AUDIT SELECT TABLE, UPDATE TABLE, INSERT TABLE BY hr BY ACCESS WHENEVER SUCCESSFUL; 6AUDIT SELECT TABLE, UPDATE TABLE, INSERT TABLE BY hr BY ACCESS WHENEVER NOT SUCCESSFUL; 7 8AUDIT ALL BY ACCESS; -- alternatively, audit everything. Audit tables 1AUDIT SELECT, INSERT, UPDATE ON hr.employees BY SESSION; 2AUDIT SELECT, INSERT, UPDATE ON hr.employees BY SESSION WHENEVER SUCCESSFUL; 3AUDIT SELECT, INSERT, UPDATE ON hr.employees BY SESSION WHENEVER NOT SUCCESSFUL; 4AUDIT SELECT, INSERT, UPDATE ON hr.employees BY ACCESS; 5AUDIT SELECT, INSERT, UPDATE ON hr.employees BY ACCESS WHENEVER SUCCESSFUL; 6AUDIT SELECT, INSERT, UPDATE ON hr.employees BY ACCESS WHENEVER NOT SUCCESSFUL; View the audit trail 1SELECT * FROM dba_audit_trail WHERE username = 'HR'; -- the audited actions of a user. 2SELECT * FROM dba_stmt_audit_opts; -- the user-level audits enabled. 3SELECT * FROM dba_obj_audit_opts; -- the object-level audits enabled.
💾 Backup & Recovery (RMAN)
💾 Backup & Recovery (RMAN)
Connect 1rman 2RMAN> connect target 1rman target / With a recovery catalog: 1rman target sys/<pwd>@orcl catalog repo/<pwd>@rmancat 1RMAN> CONFIGURE CONTROLFILE AUTOBACKUP ON; -- enables restoring the CONTROLFILE. 2RMAN> SHOW ALL; -- the whole RMAN configuration. Backup 1RMAN> BACKUP DATABASE; -- full backup. 2RMAN> BACKUP DATABASE PLUS ARCHIVELOG; -- full + archived logs. 3RMAN> BACKUP INCREMENTAL LEVEL 0 DATABASE; -- level 0 = baseline. 4RMAN> BACKUP INCREMENTAL LEVEL 1 DATABASE; -- level 1 = incremental. 5RMAN> BACKUP CUMULATIVE INCREMENTAL LEVEL 1 DATABASE; -- cumulative increments. 6RMAN> BACKUP AS COMPRESSED BACKUPSET DATABASE; -- compressed full backup. 7RMAN> BACKUP ARCHIVELOG UNTIL TIME 'sysdate - 1/24' ALL DELETE INPUT; Run a script: