Umbiko we-Habr postmortem: uwele ephephandabeni

Ukuphela kokuqala nokuqala kwenyanga yesibili yehlobo lika-2019 kwaba nzima futhi kumakwe ngamaconsi amakhulu amaningana ezinsizakalweni ze-IT zomhlaba wonke. Phakathi kweziphawulekayo: izigameko ezimbili ezibucayi kwingqalasizinda ye-CloudFlare (esokuqala - sinezandla ezigwegwile nesimo sengqondo sokudebeselela i-BGP engxenyeni yama-ISP athile avela e-USA; okwesibili - ngokusatshalaliswa okuyisigwegwe kwe-CF uqobo, ethinte wonke umuntu osebenzisa i-CF , futhi lezi yizinsizakalo eziningi eziphawulekayo) nokusebenza okungazinzile kwengqalasizinda ye-Facebook CDN (kuthinte yonke imikhiqizo ye-FB, kuhlanganise ne-Instagram ne-WhatsApp). Kwadingeka futhi sibambeke ekusabalaliseni, nakuba ukuphuma kwethu bekungabonakali kangako uma kuqhathaniswa nesizinda somhlaba. Umuntu useqalile ukuhudula izindiza ezinophephela emhlane ezimnyama kanye nozungu β€œabazimele,” ngakho-ke sikhipha ukuhlolwa kwesidumbu somphakathi ngesigameko sethu.

Umbiko we-Habr postmortem: uwele ephephandabeni

03.07.2019, 16: 05
Izinkinga ngezinsiza zaqala ukurekhodwa, okufana nokuqhekeka kokuxhumeka kwenethiwekhi yangaphakathi. Njengoba bengazange bahlole yonke into ngokugcwele, baqala ukuphutha ukusebenza kwesiteshi sangaphandle ku-DataLine, njengoba kwacaca ukuthi inkinga yayingokufinyelela kwenethiwekhi yangaphakathi ku-Inthanethi (NAT), kuze kube seqophelweni lokubeka iseshini ye-BGP ku-DataLine.

03.07.2019, 16: 35
Kwaba sobala ukuthi okokusebenza okuhlinzeka ngokuhunyushwa kwekheli lenethiwekhi nokufinyelela kusuka kunethiwekhi yendawo yesayithi kuya ku-inthanethi (NAT) yehlulekile. Imizamo yokuqalisa kabusha imishini ayizange iholele kunoma yini, ukufuna ezinye izinketho zokuhlela ukuxhumeka kwaqala ngaphambi kokuthola impendulo evela ekusekelweni kobuchwepheshe, kusukela kokuhlangenwe nakho, lokhu cishe kwakungeke kusize.

Inkinga yaba mbi nakakhulu ukuthi le mishini iphinde yanqamula ukuxhumana okungenayo kwabasebenzi be-VPN yamakhasimende, futhi umsebenzi wokutakula kude kwaba nzima kakhulu ukuwenza.

03.07.2019, 16: 40
Sizamile ukuvuselela isikimu se-NAT esiyisipele esasivele sisebenze kahle ngaphambili. Kodwa kwacaca ukuthi ukulungiswa okuningi kwenethiwekhi kwenza lolu hlelo lucishe lungasebenzi ngokuphelele, ngoba ukubuyiselwa kwalo kwakungakwazi, okungcono kakhulu, kungasebenzi, noma, okubi kakhulu, kuphule lokho osekuvele kusebenza.

Saqala ukusebenza emibonweni embalwa yokudlulisa ithrafikhi kusethi yama-routers amasha asebenzela umgogodla, kodwa abonakala engasebenzi ngenxa yezici zokusatshalaliswa kwemizila kunethiwekhi eyinhloko.

03.07.2019, 17: 05
Ngesikhathi esifanayo, inkinga yabonakala endleleni yokuxazulula igama kumaseva wegama, okuholele emaphutheni ekuxazululeni iziphetho kuzinhlelo zokusebenza, futhi baqala ukugcwalisa ngokushesha amafayela abamba amarekhodi ngamarekhodi ezinsizakalo ezibucayi.

03.07.2019, 17: 27
Ukusebenza okulinganiselwe kuka-Habr kubuyiselwe.

03.07.2019, 17: 43
Kodwa ekugcineni, kwatholakala isisombululo esiphephile sokuhlela ithrafikhi ngomunye wemizila yomngcele, eyafakwa ngokushesha. Uxhumo lwe-inthanethi lubuyiselwe.

Emaminithini ambalwa alandelayo, izaziso eziningi zavela ezinhlelweni zokuqapha mayelana nokubuyiselwa komsebenzi wama-ejenti aqaphayo, kodwa ezinye zezinsizakalo zibonakale zingasebenzi ngenxa yokuthi indlela yokuxazulula amagama eziphakelini zamagama (dns) yaphukile.

Umbiko we-Habr postmortem: uwele ephephandabeni

03.07.2019, 17: 52
I-NS iqalwe kabusha futhi inqolobane yasulwa. Ukuxazulula kubuyisiwe.

03.07.2019, 17: 55
Zonke izinsiza zaqala ukusebenza ngaphandle kwe-MK, Freelansim neToaster.

03.07.2019, 18: 02
UMK noFreelansim baqale ukusebenza.

03.07.2019, 18: 07
Buyisa iseshini ye-BGP engenacala nge-DataLine.

03.07.2019, 18: 25
Baqala ukurekhoda izinkinga ngezinsiza, okwakubangelwa ushintsho ekhelini langaphandle le-NAT pool kanye nokungabikho kwayo ku-acl yezinsizakalo eziningi, ezalungiswa ngokushesha. I-Toaster yaqala ukusebenza ngaso leso sikhathi.

03.07.2019, 20: 30
Siqaphele amaphutha ahlobene ne-Telegram bots. Kuvele ukuthi bakhohlwe ukubhalisa ikheli langaphandle kuma-acl ambalwa (amaseva elibamba), elalungiswa ngokushesha.

Umbiko we-Habr postmortem: uwele ephephandabeni

okutholakele

  • Imishini, eyake yatshala ukungabaza mayelana nokufaneleka kwayo, yehlulekile. Kwakukhona izinhlelo zokuyiqeda emsebenzini, ngoba iphazamise ukuthuthukiswa kwenethiwekhi futhi yaba nezinkinga zokuhambisana, kodwa ngesikhathi esifanayo yenza umsebenzi obalulekile, yingakho noma yikuphi ukushintshwa kwakunzima ngobuchwepheshe ngaphandle kokuphazamisa izinsizakalo. Manje ungaqhubeka.
  • Inkinga ye-DNS ingagwenywa ngokuyisondeza kunethiwekhi entsha yomgogodla ngaphandle kwenethiwekhi ye-NAT futhi isenoxhumano olugcwele kunethiwekhi empunga ngaphandle kokuhumusha (okwakuyisu ngaphambi kwesigameko).
  • Akufanele usebenzise amagama wesizinda lapho uhlanganisa amaqoqo e-RDBMS, njengoba kulula ukushintsha ngokusobala ikheli le-IP akudingekile ikakhulukazi, njengoba ukukhohlisa okunjalo kusadinga ukwakhiwa kabusha kweqoqo. Lesi sinqumo sanqunywa yizizathu zomlando futhi, okokuqala, ngokusobala kwezindawo zokugcina ngamagama ekucushweni kwe-RDBMS. Ngokuvamile, isicupho sakudala.
  • Empeleni, izivivinyo eziqhathaniswa "nobukhosi be-Runet" zenziwe; kukhona okumele ucabange ngakho mayelana nokuqinisa amandla okusinda okuzimele.

Source: www.habr.com

Engeza amazwana