Category: Administration

Dissecting the MRI II: Metamaterials in MRI

A screwdriver whizzed past my ear. With a loud clang, it came to a halt against the cryostat's casing. Cursing under my breath, I decided to take a break. Unscrewing bolts in a magnetic field of 1.5 tesla with a steel tool is not the best idea. The field, like an invisible adversary, constantly tries to wrench the tool from my hands, orient it along its magnetic lines, and thrust it as far as possible.

Life with Kubernetes: How the Spanish HTTP Server Was Unforgiving

A representative of our client, whose application stack resides in the Microsoft Cloud (Azure), reported a problem: recently, some requests from clients in Europe have started to end in a 400 (Bad Request) error. All applications are written in .NET and deployed in Kubernetes… One of the applications is an API, through which all traffic ultimately flows. This traffic is handled by an HTTP server […]

Not just with a VPN. A quick guide on how to protect yourself and your data.

Hello, Habr. It's us, the VPN service HideMy.name. We are currently operating temporarily at the mirror site HideMyna.me. Why? On July 20, 2018, Roskomnadzor added us to the list of banned resources due to a ruling by the Medvedev District Court in Yoshkar-Ola. The court ruled that visitors to our site have unrestricted access to extremist materials #withoutregistrationandsms, and somehow found the book "Mein Kampf" by Adolf […]

When encryption isn’t enough: we discuss physical access to the device

In February, we published an article titled "Not Just VPNs: A Cheat Sheet on How to Secure Yourself and Your Data." One of the comments prompted us to write a follow-up article. This part is a standalone source of information, but we still recommend reading both posts. The new post focuses on data security (messaging, photos, videos, and all that) in messengers […]

DDoS Assistance: How We Conduct Stress and Load Testing

Variti develops bot protection and DDoS attack prevention, as well as conducts stress and load testing. At the HighLoad++ 2018 conference, we discussed how to secure resources against various types of attacks. To put it briefly: isolate parts of the system, use cloud services and CDN, and regularly update. However, without specialized security companies, you won't be able to manage on your own 🙂 Before reading […]

User in Docker

Andrey Kopylov, our technical director, loves, actively uses, and advocates for Docker. In a new article, he explains how to create users in Docker. Proper management of users, why users should not be left with root privileges, and how to solve the issue of indicator mismatch in Dockerfile. All processes in the container will run as the root user unless specified otherwise. This may seem very convenient, as this user […]

Reducing downtime risks through Shared Nothing architecture

The topic of fault tolerance in storage systems is always relevant, as in our age of widespread virtualization and resource consolidation, a storage system is the component whose failure will lead not just to a minor incident, but to prolonged service downtimes. Therefore, modern storage systems consist of many redundant components (including controllers). But is this protection sufficient? Absolutely all […]

Building a fault-tolerant solution based on Oracle RAC and AccelStor Shared-Nothing architecture

Many Enterprise applications and virtualization systems have their own mechanisms for building fault-tolerant solutions. In particular, Oracle RAC (Oracle Real Application Cluster) represents a cluster of two or more Oracle database servers working together to balance the load and ensure fault tolerance at the server/application level. To operate in this mode, a shared storage is required, acting as […]

Mandatory rights distribution model in FreeBSD

Introduction To ensure an additional level of server security, a mandatory access distribution model can be used. This publication will describe how to run Apache in a jail with access only to the components necessary for the correct operation of Apache and PHP. This principle can be applied to restrict not only Apache but also any other stack. Preparation […]

Buildroot — Part 1. General information, building a minimal system, configuration via menu

Introduction In this series of articles, I want to discuss the Buildroot distribution build system and share my experiences with its customization. This will include practical experience in creating a small OS with a graphical interface and minimal functionality. First of all, it is important not to confuse the build system with the distribution. Buildroot can assemble a system from a set of packages that it has been provided. Buildroot is based on makefiles and therefore […]

Is dead monitoring dead? — Long live monitoring

Since 2008, our company has primarily been engaged in infrastructure management and round-the-clock technical support for web projects: we have over 400 clients, which accounts for about 15% of e-commerce in Russia. Accordingly, the support involves a very diverse architecture. If something goes down, we are obliged to fix it within 15 minutes. But to understand that an incident has occurred, it is necessary to monitor the project and respond to incidents. […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster