Category: Administration

What is DevOps

Defining DevOps is quite complex, which is why discussions about it tend to resurface continually. On Habr alone, there are thousands of publications on this topic. But if you're reading this, you likely know what DevOps is. Because I don’t. Hi, my name is Alexander Titov (@osminog), and we will just talk about DevOps, and I'll share my experiences. I spent a lot of time thinking about how to make my story useful, so there will be many questions here—those […]

Choosing the nearest nodes in the network

Network latency significantly affects the performance of applications or services that interact with the network. The lower the latency, the higher the performance. This is true for any network service, ranging from a regular website to a database or network storage. A good example is the Domain Name System (DNS). DNS is inherently a distributed system, with root nodes scattered […]

Delegating the reverse zone of a subnet smaller than /24 in BIND. How it works

Once, I faced the task of granting one of my clients the right to edit PTR records for the given /28 subnet. I don't have automation for editing BIND settings externally. So I decided to take a different approach—delegate a piece of the PTR zone of the /24 subnet to the client. It seemed simple enough—just set the subnet correctly and point to the desired […]

Optimization of email storage operations in Zimbra Collaboration Suite.

In one of our previous articles regarding infrastructure planning when deploying the Zimbra Collaboration Suite in enterprises, it was mentioned that the primary limitation when operating this solution is the read/write speed of disk devices in mail storage systems. Indeed, at a time when several hundred employees are simultaneously accessing the same mail storage, the bandwidth for […]

Sometimes less is more. When reducing load leads to increased latency

As with most posts, a problem arose with a distributed service, let’s call this service Alvin. This time, I didn't discover the issue myself; it was reported to me by the client-side team. One day, I woke up to a disgruntled email about significant delays with Alvin, which we planned to launch soon. Specifically, the client was facing a 99th percentile delay in […]

Exchange Vulnerability: How to Detect Domain Administrator Privilege Escalation

This year’s vulnerability discovered in Exchange allows any user in the domain to gain domain administrator rights and compromise Active Directory (AD) and other connected hosts. Today, we will explain how this attack works and how to detect it. Here’s how the attack operates: The attacker seizes the account of any domain user with an active mailbox to subscribe to the […]

Data center in Frankfurt: Telehouse DC

In May, RUVDS opened a new hermetic zone in Germany, in the country's largest financial and telecommunications city, Frankfurt. The highly reliable Telehouse Frankfurt data center is one of the data centers of the European company Telehouse (headquartered in London), which is in turn a subsidiary of the global Japanese telecommunications corporation KDDI. We have discussed our other sites multiple times before. Today, we will talk about […]

To Rook or not to Rook — that is the question

At the beginning of this month, on May 3rd, a significant release of the 'management system for distributed data storage in Kubernetes' was announced — Rook 1.0.0. Over a year ago, we published a general overview of Rook. At that time, we were asked to share our practical experience with it — and now, just at this important milestone in the project's history, we are pleased to […]

Monitoring the status of SSDs in Qsan arrays

The use of solid-state drives in the field of data storage is no longer surprising. SSDs have firmly entered the IT equipment landscape ranging from personal computers and laptops to servers and storage systems. Over time, several generations of SSDs have emerged, each offering improved performance, reliability, and maximum capacity. But the question of monitoring write resources […]

Store SSH keys securely

I want to discuss how to securely store SSH keys on your local machine without fearing that some application might steal or decrypt them. This article will be helpful for those who haven't found an elegant solution since the paranoia of 2018 and continue to store keys in $HOME/.ssh. To address this issue, I propose using KeePassXC, which is one of the best managers […]

Rook — a 'self-managed' data storage solution for Kubernetes

On January 29, the technical committee of the CNCF (Cloud Native Computing Foundation), which is behind Kubernetes, Prometheus, and other Open Source products from the container and cloud native realm, announced the acceptance of the Rook project into its ranks. This is a great opportunity to get to know this 'orchestrator of distributed data storage systems in Kubernetes' better. What is Rook? Rook is written in Go and […]

Automating the management of Let's Encrypt SSL certificates using DNS-01 challenge and AWS

This post outlines the steps for automating SSL certificate management from Let's Encrypt CA using the DNS-01 challenge and AWS. acme-dns-route53 is a tool that will allow us to implement this feature. It can work with SSL certificates from Let's Encrypt, store them in Amazon Certificate Manager, use Route53 API to implement the DNS-01 challenge, and, finally, push notifications to […]

Buy reliable website hosting with DDoS protection, VPS VDS servers šŸ”„ Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster