- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
All Stories
Yesterday
Already deployed on db-A.
rOBSIDIAN329bc358fc01 refers to table orbeon_form_data_attach, permission is needed for that one too, but missing in rOPS (was a hotfix on Complector)
Actually, we use the same database name than for MariaDB / MySQl:
Mon, Nov 10
Bruteforce attack scenario possible, so we're only interested by usernames defined in users.sls, not by "root" (can't login by SSH) or generic accounts like "docker" (doesn't exist):
Checking the RabbitMQ Monitoring with Prometheus guide:
- we're OK for cluster name
- to get sensible values for rate() in Grafana, we need to configure Prometheus to scrape RabbitMQ every 15s ; according Prometheus configuration, the value scrape_interval can be set at job level
Grafana dashboard was full N/A.
Did a run this night to update Certbot files, states are currently correct:
Vault is now alive and used for credentials provisioned by Salt.
Sun, Nov 9
$ ssh dwellers netstat -rn Kernel IP routing table Destination Gateway Genmask Flags MSS Window irtt Iface 0.0.0.0 51.210.99.254 0.0.0.0 UG 0 0 0 ens192 0.0.0.0 172.27.27.1 0.0.0.0 UG 0 0 0 ens224 51.210.99.254 0.0.0.0 255.255.255.255 UH 0 0 0 ens192 51.255.124.0 0.0.0.0 255.255.255.240 U 0 0 0 ens192 [... (routes for drake/docker) ...]
Alkane doesn't need any new account. We can send a request to an URL and it will be run by the deploy user.
Eglide is still not configured from Complector with a salt-ssh roster, so running it locally:
Confirmed by shark key is correct.