• 0 Posts
  • 179 Comments
Joined 2 years ago
cake
Cake day: June 16th, 2023

help-circle
  • We would need more info to help confirm, but watching ids traffic will show you lots of misconfigurations as well as actually suspicious traffic, so this might be a POS device doing stupid stuff.

    Is suricata listening on an internal subnet interface? If you are listening on a public interface, your job sorting through the trash traffic will be difficult because determining source is nearly pointless and your external interface should not know anything about the internal subnet.








  • I love alpine, and I use it where I can. And it has many advantages over other distros and setups. But a declarative, ram-only distro that boots over the network doesn’t help manage non-conformant machines.

    I still need to manage Debian, old centos boxes, Ubuntu machines, and a couple old-as-time sun machines. Nixos isn’t the tool for that job. Ansible has two dependencies: ssh and python, and there are ways around the 2nd one. Ansible works really well here.

    Not trying to bash nixos, here, but I’m not sure why so many users on Lemmy compare ansible and nix, they don’t really operate in the same spaces.




  • If you’re not fond of manipulating config files manually, just use nmcli (from your link):

    You can get an idea of NetworkManager’s settings by running nmcli on the command line.

    It is a bunch simpler. The days of just raw-dogging resolve.conf and nsswitch are long behind us.

    Aren’t these docs an admission that it’s a clusterfuck?

    The Debian wiki admittedly needs work, but it is a wiki, so make an account and update what you think is lacking or unclear.








  • APIs. Or the ends are achieved by sharing data between apps in common data storage. But I prefer to be a tourist in my infrastructure, I no longer hand-bomb changes to systems.

    My design pattern is essentially to integrate more and more of the container creation into config. Right now I’m using ansible and it’s nice. More automation means troubleshooting has fewer variables.

    I had issues yesterday with a package upgrade across several containers, and it ended up being two config changes. I cycle the apps and done. That’s it.