Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
xarph
Jun 18, 2001


This is either the worst bug or the best license enforcement ever: Due to our CFO being away unexpectedly we didn't get our vcenter license renewal approved in time, so right now we're sitting around without support for a few days until our reseller fixes it.

vcenter appliance, out of nowhere, has developed a thing where it lets anyone log in as an AD user with no password. This includes the web client from a linux machine with no knowledge of AD. It also ignores permissions. domain\administrator with no password gets you root. domain\newinternwithnoroles with no password? root.

I can't find anything on the googles about this and it doesn't appear in the known issues for vcenter updates, though some other AD stuff is.

I just snapshotted vcenter appliance so I can try upgrading it to the latest version as a hail-mary, but this poo poo always happens at the worst possible time.

Also, vcenter appliance is terrible and I regret ever deploying it, but vmware doesn't seem to have an upgrade path to the installable windows vcenter that actually lets me use an external database that isn't oracle.

Edit: hail-mary upgrade to 5.1.0 update 1a fixed it.

xarph fucked around with this message at 18:57 on Jul 23, 2013

Adbot
ADBOT LOVES YOU

xarph
Jun 18, 2001


xtal posted:

Maybe this is the wrong thread but does anyone else feel like docker is the javascript of systems? So tired of my coworkers begging to use it for no reason other than hype. I see literally 0 benefit because 0 of its ideas are original

It has a shiny UI and lets engineers get around VM allocation quotas by requesting a VM, installing docker on it, and then blowing up the filesystem by running device-mapper in loopback and running the root filesystem out of space.

So, yes.

xarph
Jun 18, 2001


Maneki Neko posted:

That's where we were at and we basically told our rep to give us X520s or they were getting the whole order back.

Same, but we've concluded that PXE booting in UEFI mode with X710s is basically impossible.

xarph
Jun 18, 2001


Does vcenter 6.5 dropping support for esxi 5.0 actually mean those hypervisors are locked out, or just that vmware support will tell us to get lost? We have some old software that won't build on anything newer than 5.0 because of the changes in the number of empty sockets presented to solaris 10. vmware support's response has been "upgrade to a newer version of java runtime" which is kinda hard since we can't get our customers to upgrade their java, either.

If I have to buy a second vcenter license to move the 5.0 build cluster off to its own environment, I will, but I'd rather keep everything in one pane of glass.

xarph
Jun 18, 2001


SEKCobra posted:

It says it doesn't like it.

Realtek nics are designed to be as cheap as possible and rely on the OS driver doing stuff that any real NIC should be doing on-board. They're basically winmodems for Ethernet. Attempting to make a realtek driver for ESXi is a recipe for disaster and pink screens of death.

xarph
Jun 18, 2001


Dancing Peasant posted:

My group is working to get off of VMWare (for reasons stated already). And while there has been discussion on ProxMox, management and some engineers are leaning towards OpenShift/OpenStack as another solution.

We currently have Windows and RHEL primarily, so is there reason why OS/OS isn't discussed as a viable alternative?

Openstack literally sent my coworker to the hospital from exhaustion while they were trying to figure out how to install it with networking more complex than a flat vlan. And this was after a two month training class with one of the primary financial backers of the openstack foundation.

Openstack is not a product. It is an api specification for independent open source projects that wrap libvert, raw qemu+kvm, iptables, bhyve, hyper-v, chunks of systemd, docker, ceph, etc. The openstack trainer we sent to study under said it was a baggie with an ikea pamphlet and some screws in it, but you're on your own for the particleboard. He was right.

Sometimes they will issue a "release" which works if you use the exact versions they pinned at the time, and in 8 months when you have the message queue fall over or nova is completely wedged from waiting on a blocked qemu or neutron got into a fight with systemd-networkd and now your management network is gone. Your option then is pay mirantis $texas to build an entirely new openstack across the street and then cover the old one in concrete, because all of the upstream openstack projects will go "does it work on a clean install" or "it's fixed in this PR just install that straight into production."

If people give Proxmox stick for being a hobbyist home lab thing, then it's a loving IBM mainframe that has an uptime of 50 years compared to openstack.

Adbot
ADBOT LOVES YOU

xarph
Jun 18, 2001


I've been introduced internally to the "jason api" which is issuing a POST request to an api endpoint which then sits in a queue with an in-progress state until that one guy named Jason wakes up and does the thing you want manually.

This exists in more clouds and saas products than you think. Yes, more than that.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply