heise+ | Linux-Distribution: Warum NixOS mit seinem eigenen Wachstum kämpft
NixOS wächst und gedeiht, doch in der Community des Projekts gibt es ungelöste Konflikte, die das Wachstum gefährden könnten. Eine Zustandsanalyse von NixOS.
Follow #devops from Mastodon or any other Fediverse app and its public posts arrive in your timeline. No vutuv account needed.
@devops@tags.vutuv.de
dev ops, dev-ops
6 posts
Mein Edge-Hosting lief mit Debian, Ansible, OpenResty und HTTP/3 eigentlich völlig unauffällig. Warum ich den produktiven Server trotzdem auf NixOS 26.05 umgezogen habe — und wo der Unterschied zwischen Orchestrierung und echter Deklaration liegt.
Ein funktionierendes Setup, eigentlich
heise+ | Linux-Distribution: Warum NixOS mit seinem eigenen Wachstum kämpft
NixOS wächst und gedeiht, doch in der Community des Projekts gibt es ungelöste Konflikte, die das Wachstum gefährden könnten. Eine Zustandsanalyse von NixOS.
We tweaked our firewalls and our Anubis rules. The attack persisted, but it was contained.
We also scaled our systems to avoid more accidental downtimes caused by these scrapping operations… Then the attackers scaled up their scrapping campaign, and found new ways to bypass our #Anubis config.
This past night I managed to come up with a stricter configuration that blocks virtually all of them (I don’t know for how long this will last, though).
As of now, our Anubis instance is stopping around 40 requests per second.
I know that this is “nothing” for anyone working in very big systems, but bear in mind that this is after I already blocked around 3.5% of all the IPv4 addresses existing, and it accounts for 95% of our traffic. For every legitimate request we have, we have 19 that come from bots.
P.S.: In an ideal world, I would openly share the rules I found to work well… Unfortunately I don’t think that would be a good idea. I don’t want to make the scrappers’ job any easier.
In the latest installment of our #SelfHosting series, @makkes@hachyderm.io explores Seafile, an open source file sync and share platform for teams that want to operate their own cloud storage system.
c’t-Workshop: Docker Advanced – Strategie, Sicherheit, Automation
Wer Container dauerhaft stabil betreiben will, braucht eine tragfähige Strategie. Der Workshop liefert Konzepte für Sicherheit und Automation.
c’t-Workshop: Container sicher planen, automatisieren und betreiben
Wer Container produktiv betreibt, muss mehr beherrschen als Docker-Befehle. Lernen Sie, Images sicher zu verwalten und Deployments gezielt zu automatisieren.
The single-key shortcuts pause while you type, and are off on phones and tablets.