Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

LochNessMonster posted:

I guess what he means with config drift is people (more aptly named idiots) who start messing with config files and not just changing them in the central place (git) and then pushing it to all apropriate servers (if it's not already happening automatically).

This means server 1 has a different config than server 2-20 making it a unique little snowflake and troubleshooting it a major bitch.

In a cattle environment it's no biggy. Kill it and spin up a new one. In a pet environment you start womdering why something works on all but 1 server. Or even worse, why only one of your servers is working great and the rest is a pile of poo poo.

No config management/enforcement is hell.
Couldn't SELinux prevent this?

Adbot
ADBOT LOVES YOU

RFC2324
Jun 7, 2012

http 418

anthonypants posted:

Couldn't SELinux prevent this?

not if people have access to root, which I would assume they have if they are loving with configs

Dr. Arbitrary
Mar 15, 2006

Bleak Gremlin

Methanar posted:

I want to expand on this a little bit, because the very idea of cattle VMs is foreign if you're coming from an internal position at some not-technology company. If you've got stuff like maybe an on-prem installation of FileMaker and a handful of other little fish Windows things at some company with 100 salesmen/accountants/logistics people, it's basically useless to you and not relevant.

Remember when this guy was out picking up trash as part of his job responsibilities?

If you're a lurker and you've got weird ideas about getting into IT, this is how quickly you can go from being poo poo on, to being "The poo poo" in IT, if you work to stay ahead of the curve.

Corsair Pool Boy
Dec 17, 2004
College Slice

Dr. Arbitrary posted:

Remember when this guy was out picking up trash as part of his job responsibilities?

If you're a lurker and you've got weird ideas about getting into IT, this is how quickly you can go from being poo poo on, to being "The poo poo" in IT, if you work to stay ahead of the curve.

Plot twist: the automation leaves him with enough free time that they still make him pick up trash.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


MANime in the sheets posted:

Plot twist: the automation leaves him with enough free time that they still make him pick up trash.

Catch 22 bitch. Now go get your shine box.

Proteus Jones
Feb 28, 2013



Dr. Arbitrary posted:

Remember when this guy was out picking up trash as part of his job responsibilities?

If you're a lurker and you've got weird ideas about getting into IT, this is how quickly you can go from being poo poo on, to being "The poo poo" in IT, if you work to stay ahead of the curve.

I was just thinking the same thing too. Methanar has come a long from interning in the depths of the Canadian wilds.


jaegerx posted:

Catch 22 bitch. Now go get your shine box.

Hopefully he's developed the soft skills necessary for this industry. Namely "research time" and "training"

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.

Dr. Arbitrary posted:

Remember when this guy was out picking up trash as part of his job responsibilities?

If you're a lurker and you've got weird ideas about getting into IT, this is how quickly you can go from being poo poo on, to being "The poo poo" in IT, if you work to stay ahead of the curve.

Very true.

I keep meaning to say it whenever I see posts from Methanar, but seriously, great job dude. It's nice to see your career take off like this. I'm always happy when SH/SC guys manage to get away from the poo poo and step into something legitimately worth their time.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


Wrath of the Bitch King posted:

Very true.

I keep meaning to say it whenever I see posts from Methanar, but seriously, great job dude. It's nice to see your career take off like this. I'm always happy when SH/SC guys manage to get away from the poo poo and step into something legitimately worth their time.

Poor dick trauma

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

Wrath of the Bitch King posted:

Very true.

I keep meaning to say it whenever I see posts from Methanar, but seriously, great job dude. It's nice to see your career take off like this. I'm always happy when SH/SC guys manage to get away from the poo poo and step into something legitimately worth their time.

A buddy of mine is tired of working customer service for a bank and wants to give IT a try and asked what step #1 is. I told him it's absolutely spending the $10 for a forums account and checking sh/sc every single day until you're successful.

Corsair Pool Boy
Dec 17, 2004
College Slice

Nitramster posted:

Amen.

I'll be updating my resume today. If anyone in the L.A. area wants to network, send me an email: Nitramster at gmail. I'd be happy to buy any of you a beer.

Are you a DCI? If so, for how long? I lasted about 3 months before looking to get out, and another 4 or 5 before I was gone. I had kind of enjoyed Geek Squad up to that point, but being a supervisor was a total shitshow.

Corsair Pool Boy fucked around with this message at 06:31 on Oct 2, 2017

Mr. Fix It
Oct 26, 2000

💀ayyy💀


RFC2324 posted:

Well, poo poo. I know in my puppet systems I have my systems refresh config from the central repo on a regular basis. You want to change a config, its gonna revert pretty quick, and if you need to tinker, you need to shut down the puppet agent, which will alert that something funny is going on.

People disabling puppet "temporarily" to prevent some locally set tweaks from being overwritten is the bane of my existence. Put it in puppet, you fucks.

RFC2324
Jun 7, 2012

http 418

Mr. Fix It posted:

People disabling puppet "temporarily" to prevent some locally set tweaks from being overwritten is the bane of my existence. Put it in puppet, you fucks.

add a cron job to re-enable puppet every 30 minutes?

Mr. Fix It
Oct 26, 2000

💀ayyy💀


RFC2324 posted:

add a cron job to re-enable puppet every 30 minutes?

Don't tempt me. I could even do it remotely so that can't disable puppet and the cron. I think that keeping track of who's doing it and where and naming and shaming might be more effective with my team, though.


I think I have project for the week.

Zorak of Michigan
Jun 10, 2006


I can't even wrap my head around people who have Puppet but want to circumvent it. If it was one of our operations people, that would let them in for a scolding. For anyone else. a sudden and startling change in their sudo privileges.

18 Character Limit
Apr 6, 2007

Screw you, Abed;
I can fix this!
Nap Ghost

RFC2324 posted:

add a cron job to re-enable puppet every 30 minutes?

You probably wouldn't be surprised the amount of damage that can occur in 30 minutes if you're fighting someone else over configuration. God help you if you're still monitoring cattle like pets.

RFC2324
Jun 7, 2012

http 418

Zorak of Michigan posted:

I can't even wrap my head around people who have Puppet but want to circumvent it. If it was one of our operations people, that would let them in for a scolding. For anyone else. a sudden and startling change in their sudo privileges.

I do it in lab environments, but to do it in prod is insane.

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Let me tell you about chattr +i or puppet agent disable.

(Use the reporting tools to make sure runs are happening and happening cleanly. Fix your culture when that poo poo happens.)

Corsair Pool Boy
Dec 17, 2004
College Slice
Anyone here familiar with using LogicMonitor for network equipment monitoring?

We added it about ~6 months ago for companies that didn't want to VPN/re-IP to get onto our hosted Solarwinds setup. I've never seen a more incomprehensible, non-intuitive GUI than this thing - the descriptions are obtuse and contain almost no information. It doesn't look like much (if any) effort was made to tune alerts on our end before deployment, so 99% of what we do end up working on ends with us just turning the alert off.

If there's a good resource on how to navigate/manage/administrate LM out there, I'd very much appreciate it.

Methanar
Sep 26, 2013

by the sex ghost

Proteus Jones posted:

I was just thinking the same thing too. Methanar has come a long from interning in the depths of the Canadian wilds.


Hopefully he's developed the soft skills necessary for this industry. Namely "research time" and "training"

Thanks guys :3:

That was all really nice to read after a long trip. (I just got to NYC for training this week!)

Methanar fucked around with this message at 07:28 on Oct 2, 2017

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


Am I the only one who's a fan of inbox zero? Or am I one of those weirdos who reads all his email...

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
I mark everything as read and hope for the best

Edit: Actually I don't use subfolders in my mailbox except for auto-move rules for white noise, but I am pretty OCD about making sure I don't have an "unread mail" notification on any platform.

Twlight
Feb 18, 2005

I brag about getting free drinks from my boss to make myself feel superior
Fun Shoe

PCjr sidecar posted:

Let me tell you about chattr +i or puppet agent disable.

(Use the reporting tools to make sure runs are happening and happening cleanly. Fix your culture when that poo poo happens.)

If people want to test their puppet, let them spin that poo poo up in docker and test away. We've got this hilarious two tier system where some people use testing and some done because ~*reasons*~ those reasons are basically groups that don't speak to each other and its a shame

Docjowles
Apr 9, 2009

PCjr sidecar posted:

Let me tell you about chattr +i

loving triggered

When I first started this job I swear half the servers had some random rear end file with the immutable flag set so Chef wouldn't overwrite it. It blew my mind that someone thought this was OK to do.

Now if developers need to change a managed file, they can open a drat pull request against the cookbook and have it deployed. As god intended.

Twlight
Feb 18, 2005

I brag about getting free drinks from my boss to make myself feel superior
Fun Shoe

Docjowles posted:

loving triggered

When I first started this job I swear half the servers had some random rear end file with the immutable flag set so Chef wouldn't overwrite it. It blew my mind that someone thought this was OK to do.

Now if developers need to change a managed file, they can open a drat pull request against the cookbook and have it deployed. As god intended.

we had some chattr poo poo going on too, we had to have a big sit down and remove sudo access for this poo poo.

Dick Trauma
Nov 30, 2007

God damn it, you've got to be kind.

jaegerx posted:

Poor dick trauma

I HAVE BEEN SUMMONED



ENJOY YOUR GOOD STUFF WHILE IT LASTS MWAHAHAH

Kashuno
Oct 9, 2012

Where the hell is my SWORD?
Grimey Drawer
Real quick that talk about cattle servers and killing them when poo poo goes wrong was super helpful to me just this very day! We had an SFTP server that was having trouble running some scripts I made 6 months ago that had worked fine until Friday. I tried a few things and traced back the issue, but nothing I could figure out was solving it. I came in today fully expecting to have to deep dive into things and see where the problem was stemming from, but when I thought about it I just decided it was much much faster to kill the problem server and spin up a new VM. Took all of 10 minutes to transfer the scripts and files that I needed over and things were back up and running. Thanks thread.

YOLOsubmarine
Oct 19, 2004

When asked which Pokemon he evolved into, Kamara pauses.

"Motherfucking, what's that big dragon shit? That orange motherfucker. Charizard."

Well, NetApp Insight certainly qualifies as my worst conference ever so far.

TheFace
Oct 4, 2004

Fuck anyone that doesn't wanna be this beautiful

big money big clit posted:

Well, NetApp Insight certainly qualifies as my worst conference ever so far.

Details?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
There's probably a thread about the shooting in GBS or D&D if you don't want to check the news.

TheFace
Oct 4, 2004

Fuck anyone that doesn't wanna be this beautiful

anthonypants posted:

There's probably a thread about the shooting in GBS or D&D if you don't want to check the news.

Derp, didn't realize the location... oops

CLAM DOWN
Feb 13, 2007




big money big clit posted:

Well, NetApp Insight certainly qualifies as my worst conference ever so far.

Well yeah, of course it does, you went to a loving NetApp conference

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


So...

Azure AD Pass-through Authentication is now GA nearly eliminating ADFS Farms. Azure DNS supports Private Virtual Networks and with AD-as-a-Service removes the need for Azure IaaS DCs.

RIP Windows System Administration.

YOLOsubmarine
Oct 19, 2004

When asked which Pokemon he evolved into, Kamara pauses.

"Motherfucking, what's that big dragon shit? That orange motherfucker. Charizard."

CLAM DOWN posted:

Well yeah, of course it does, you went to a loving NetApp conference

Hopefully we evaluate our future technology partnerships more strongly on the criteria of "will this partnership lead to police bursting into my hotel room at 4am and pointing a gun at me before searching the place."

MC Fruit Stripe
Nov 26, 2002

around and around we go

big money big clit posted:

Hopefully we evaluate our future technology partnerships more strongly on the criteria of "will this partnership lead to police bursting into my hotel room at 4am and pointing a gun at me before searching the place."
Did they really? I know you're in that hotel

One of my guys is a few hotels down

YOLOsubmarine
Oct 19, 2004

When asked which Pokemon he evolved into, Kamara pauses.

"Motherfucking, what's that big dragon shit? That orange motherfucker. Charizard."

MC Fruit Stripe posted:

Did they really? I know you're in that hotel

One of my guys is a few hotels down

Yea, they did a room to room search of every room in the place, at least as far as I can tell. My coworker was on the 32nd floor not too far from the shooter and she was evacuated and hasn't been allowed back to her room since.

The Fool
Oct 16, 2003


Tab8715 posted:

So...

Azure AD Pass-through Authentication is now GA nearly eliminating ADFS Farms. Azure DNS supports Private Virtual Networks and with AD-as-a-Service removes the need for Azure IaaS DCs.

RIP Windows System Administration.

One of our subsidiaries just finished spinning up an on-prem ADFS farm. It won't be going away anytime soon.

I have ADFS, DC and WAP VM's in Azure right now myself. If I can demonstrate that pass-through auth meets all of our requirements, there's a half-dozen images I'll be able to take down.

JHVH-1
Jun 28, 2002
Blockchain in the cloud as a service. Finally we will have synergy https://console.bluemix.net/catalog/services/blockchain/

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

big money big clit posted:

Yea, they did a room to room search of every room in the place, at least as far as I can tell. My coworker was on the 32nd floor not too far from the shooter and she was evacuated and hasn't been allowed back to her room since.

One of our guys was 3 doors down from the shooter. He has no idea when they'll let him back in his room, dude doesn't even have his ID/wallet on him.

Tab8715 posted:

So...

Azure AD Pass-through Authentication is now GA nearly eliminating ADFS Farms. Azure DNS supports Private Virtual Networks and with AD-as-a-Service removes the need for Azure IaaS DCs.

RIP Windows System Administration.

It wont' disappear, but it's a decent pivot for sure. Co-Management between cloud and on prem was a big theme at Ignite this year. Cloud primary/only is coming though, my advice is stay up to date with all of it.

skipdogg fucked around with this message at 18:44 on Oct 2, 2017

YOLOsubmarine
Oct 19, 2004

When asked which Pokemon he evolved into, Kamara pauses.

"Motherfucking, what's that big dragon shit? That orange motherfucker. Charizard."

skipdogg posted:

One of our guys was 3 doors down from the shooter. He has no idea when they'll let him back in his room, dude doesn't even have his ID/wallet on him.

Same for her. She just wants to get the hell out and go home, but she can't get on a plane because she has no ID. Also still wearing her pajamas.

Adbot
ADBOT LOVES YOU

Walked
Apr 14, 2003

Tab8715 posted:

So...

Azure AD Pass-through Authentication is now GA nearly eliminating ADFS Farms. Azure DNS supports Private Virtual Networks and with AD-as-a-Service removes the need for Azure IaaS DCs.

RIP Windows System Administration.

If you're in IT (especially Windows administration) and arent actively learning / practicing coding, you're screwed. "Classic" Windows administration approaches are going to be dead in the near future. Dont dig your own grave by ignoring what's happening in the field.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply