Category: Administration

Okerr hybrid monitoring system overview

Two years ago I already did a post A simple failover for the okerr website. Now there is some development of the project, and I also published the source code of the okerr server part under an open license, which is why I decided to write this short review on Habr. [ full size ] Who might be interested You might be interested if you […]

Simple website failover (monitoring + dynamic DNS)

In this article, I want to show how easy and free it is to make a failover scheme for a website (or any other Internet service) on a combination of okerr monitoring and a dynamic DNS service. That is, in case of any problems with the main site (from the problem with "PHP Error" on the page, to lack of space or just a suspiciously small number of orders […]

Speed ​​up Internet requests and sleep peacefully

Netflix is ​​the market leader in Internet TV, the company that created and actively develops this segment. Netflix is ​​known not only for its vast catalog of movies and TV shows, accessible from almost every corner of the planet and any device with a display, but also for its reliable infrastructure and unique engineering culture. A clear example of the Netflix approach to developing and maintaining complex systems at DevOops 2019 presented […]

What has changed in Capacity Tier when Veeam became v10

Capacity Tier (or as we call it inside vim - captir) appeared back in the days of Veeam Backup and Replication 9.5 Update 4 under the name Archive Tier. The idea behind it is to make it possible to move backups that have fallen out of the so-called operational restore window to object storages. This helped free up disk space for […]

MskDotNet Meetup at Raiffeisenbank 11/06

Together with the MskDotNET Community, we invite you to an online meetup on June 11: we will discuss nullabilily issues in the .NET platform, the use of a functional approach in development using the Unit, Tagged Union, Optional and Result types, we will analyze working with HTTP in the .NET platform and show the use of our own engine to work with HTTP. There are many more interesting things prepared - join us! What will we talk about 19.00 [...]

How Time Synchronization Became Secure

How do you make sure time per se doesn't lie when you have a million big and small devices interacting with each other? TCP/IP? After all, each of them has a clock, and the time must be correct on all of them. This problem cannot be circumvented without NTP. Let's imagine for a moment that one segment of the industrial IT infrastructure is experiencing difficulties […]

The problem of outdated root certificates. Let's Encrypt and smart TVs are next in line

In order for a browser to authenticate a website, it presents itself as a valid chain of certificates. A typical chain is shown at the top and may have more than one intermediate certificate. The minimum number of certificates in a valid chain is three. The root certificate is the heart of the certification authority. It is literally built into your OS or browser, it is physically present on your device. You can't change it from […]

10 Common Kubernetes Mistakes

Note. transl.: the authors of this article are engineers from a small Czech company called pipetail. They managed to put together a wonderful list of [sometimes banal, but still] such actual problems and misconceptions associated with the operation of Kubernetes clusters. Over the years of using Kubernetes, we have worked with a large number of clusters (both managed and unmanaged - on GCP, AWS and Azure). […]

In-memory architecture for web services: basic technology and principles

In-Memory is a set of data storage concepts when they are stored in the application's RAM, and the disk is used for backup. In classical approaches, data is stored on disk and memory is stored in cache. For example, a web application with a backend for processing data requests them from the storage: it receives, transforms, and a lot of data is transferred over the network. In In-Memory, calculations are sent to data - in […]

Elastic Locked Up: Enabling Elasticsearch Cluster Security Options for Inside and Outside Access

Elastic Stack is a well-known tool in the SIEM systems market (actually, not only them). It can collect a lot of different-sized data, both sensitive and not very sensitive. It is not entirely correct if access to the Elastic Stack elements themselves is not protected. By default, all Elastic boxed elements (Elasticsearch, Logstash, Kibana, and Beats collectors) operate on open protocols. A […]

Remote Desktop through the eyes of an attacker

1. Introduction Companies that did not have remote access systems in place deployed them on an emergency basis a couple of months ago. Not all administrators were ready for such a “heat”, as a result, security lapses: incorrect configuration of services or even installation of outdated versions of software with previously discovered vulnerabilities. Some of these omissions have already returned like a boomerang, others were more fortunate, […]

Hosting and dedicated servers: answering questions. Part 4

In this series of articles, we want to address the questions that people have when dealing with hosting providers and dedicated servers in particular. We conducted most of the discussions on English-language forums, trying to help users first of all with advice, and not self-promotion, giving the most detailed and impartial answer, because our experience in the field has been over 14 years, hundreds of […]

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster