keithzg | Yeah, I try to stay on top of news and otherwise check whenever I have downtime and don't think it'll disrupt anyone, and as well check on weekends. | 00:04 |
---|---|---|
keithzg | Today everyone at the office has emptied out quite early, for instance, so it's time for some updates :D | 00:04 |
bekks | Unless we're talking about kernel updates, users most likely dont even notice non-downtime patches. | 00:05 |
keithzg | True true. | 00:05 |
keithzg | It does depend on the role of the system though; on our Subversion server, for instance, if either subversion, apache2, or sshfs were updated while a commit was being made it *might* cause issues. | 00:07 |
keithzg | Conversely, with our bugtracker they'd pretty much have to be hitting submit on something at the *exact* wrong time. | 00:08 |
keithzg | Time for kernel updates today anyways, thanks to the security fixes. | 00:14 |
keithzg | (is there a bot for referencing security notices in this channel? I guess I can just paste the URL: http://www.ubuntu.com/usn/usn-2823-1/ ) | 00:15 |
=== Lcawte is now known as Lcawte|Away | ||
=== KnownSyntax_ is now known as KnownSyntax | ||
samy1028 | Does anyone have a pointer on best practices when increasing allocated HD in an Ubuntu Server VM using LVM? For server 2012r2 I can dymaically increase the space in ESXi / vCenter and then just extend the volume in the still running server 2012r2 VM. | 03:42 |
samy1028 | Can this be done in Linux / Ubuntu-Server? | 03:43 |
quantic | samy1028: insufficient data. How is the space presented to the VM? | 03:43 |
samy1028 | quantic, sorry for the delay, was off reading docs. | 04:30 |
samy1028 | quantic, I want to setup 2 HD's for an ubuntu server VM. | 04:31 |
samy1028 | 1st HD has 40GB (operating system) | 04:31 |
samy1028 | 2nd HD has 5TB (mounted under /var/logs/devices) | 04:32 |
samy1028 | In the future I will probably need to increase this to 8TB or even 10TB. | 04:32 |
samy1028 | Can I increase this 2nd HD allocation to 10TB and have Linux see it without a reboot like Windows can? | 04:33 |
payload | why are the package servers so slow | 05:08 |
=== IdleOne is now known as Guest25649 | ||
=== Lcawte|Away is now known as Lcawte | ||
=== Guest25649 is now known as IdleOne | ||
=== Lcawte is now known as Lcawte|Away | ||
=== Lcawte|Away is now known as Lcawte | ||
=== Lcawte is now known as Lcawte|Away | ||
=== Ursinha_ is now known as Ursinha | ||
=== Piper-Off is now known as Monthrect | ||
sorin-mihai | anyone can guild me to get a maas installed corectly? | 15:43 |
sorin-mihai | er, guide | 15:43 |
=== MACscr1 is now known as MACscr | ||
sorin-mihai | so... nobody using maas? | 16:42 |
jpds | sorin-mihai: sudo apt-get install maas maas-dhcp maas-dns | 16:44 |
jpds | sorin-mihai: Then go to the web UI and setup your networks | 16:45 |
jpds | sorin-mihai: And that's pretty much it | 16:45 |
sorin-mihai | not really... | 16:45 |
jpds | sorin-mihai: And why not? | 16:45 |
sorin-mihai | one sec | 16:45 |
sorin-mihai | so i have already a maas-ens3 network, auto created... | 16:47 |
jpds | sorin-mihai: OK | 16:59 |
sorin-mihai | jpds, so, i added network... | 17:06 |
sorin-mihai | but i still have the error "Boot image import process not started. Nodes will not be able to provision without boot images. Visit the boot images page to start the import." | 17:07 |
sorin-mihai | and pressing Import images does nothing. | 17:07 |
jpds | sorin-mihai: Check tcpdump | 17:08 |
jpds | sorin-mihai: Those boot images aren't small | 17:08 |
sorin-mihai | i see nothing else than the ssh connection | 17:09 |
Luke | hey guys. I want to set up a shared dir but use ACLs to enforce that the group and group permissions are always preserved | 17:35 |
Luke | anyone know a good guide for that? | 17:35 |
=== cpaelzer_ is now known as cpaelzer | ||
sarnold | Luke: normally it's sufficient to set the setgid bit on the directory | 18:14 |
sarnold | Luke: do you have apps or users that violate that agreement? | 18:14 |
Luke | not sure | 18:15 |
Luke | sarnold: it's mercurial is the app | 18:15 |
Luke | i want multiple users to be able to push to the mercurial shared folder as their own users via ssh | 18:15 |
sarnold | Luke: I'd try the setgid directory first and see how that works out | 18:17 |
Luke | ok thanks | 18:17 |
Luke | i | 18:17 |
Luke | i've never set this up myself before. in the past we had IT professionals do it and we always had problems even with setguid | 18:17 |
Luke | not sure why exactly | 18:17 |
Luke | i want the user to be always set to a generic user as well | 18:17 |
Luke | so like hg:hg user:group would always be all files recurisvely in the folder | 18:18 |
Luke | even if I push as luke:hg | 18:18 |
sarnold | ahh, that part probably requires having a daemon on the system do all the work on behalf of users | 18:18 |
Luke | then the hg group is what gives the full permission | 18:18 |
sarnold | or all the users sharing a single userid, which is somewhat gross to think about.. | 18:18 |
Luke | mercurial doesn't use a daemon. it just runs as the user on demand | 18:18 |
sarnold | and no one's written a daemon wrapper? | 18:19 |
Luke | well i guess even if the files were all owned by different users but the group is enforced, that may be fine | 18:19 |
Luke | sarnold: no. what would that look like? | 18:19 |
Luke | ssh is the daemon in this case | 18:19 |
sarnold | Luke: it might be a wrapper around the hg binary on the server.. | 18:19 |
Luke | and do what? | 18:20 |
sarnold | eww | 18:20 |
sarnold | I just thought of something a bit gross but might accomplish this | 18:20 |
Luke | hg is a program just like cat or mv so it doesnt make sense to daemonize it | 18:20 |
sarnold | are there usrs on the server that shouldn't have access? | 18:20 |
Luke | yeah probably | 18:20 |
Luke | though not currently | 18:20 |
Luke | all the necessary users have access via a group | 18:21 |
sarnold | alright, then the complex method.. set the hg executable to hg:hg, set the setuid and setgid bits on the executable so it runs with that user and group. But the trick is to store the hg executable in a directory that is only accessible to members of the allowed group. | 18:22 |
Luke | hmm isee | 18:22 |
sarnold | so stuff it in /usr/local/sarnoldsuglyhack/bin/hg | 18:22 |
Luke | right | 18:22 |
sarnold | set /usr/local/sarnoldsuglyhack to root:lukesproject 750 | 18:23 |
Luke | it seems like i should be able to leave hg bin alone and just have the files themselves always be owned by the same user and group recursively | 18:23 |
sarnold | then users not in lukesproject group can't traverse the directory to the setuid / setgid hg executable | 18:23 |
sarnold | Luke: owner is the tricky bit. unix isn't really set up to make that easy. | 18:23 |
Luke | what about just group? | 18:23 |
Luke | all the files can be owned by whatever user randomly created the file but the group would be the shared group with 7 permissions | 18:24 |
sarnold | for group, there's the setgid bit on directories, but processes are free to set the gid on any file they have permission to modify, so they could change it. and probably some do. | 18:24 |
Luke | as long as mercurial doesn't setgid on it we're fine | 18:26 |
Luke | i'll have to mess aroudn with these ideas. thank you | 18:27 |
sarnold | have fun :) | 18:28 |
ponyofdeath | hi, do I need to re-compile the apache2 deb to get fips support in 12.04? | 18:39 |
hallyn | dannf: (i assume answer is no, but) have you by chance looked at all into enabling seccomp in qemu on other arches? | 19:35 |
hallyn | just asking since you did the version loosening patch :) | 19:35 |
=== Monthrect is now known as Piper-Off | ||
=== Lcawte|Away is now known as Lcawte | ||
beisner | coreycb, o/ | 21:11 |
Rar9 | hi can some help me with this error | 21:11 |
Rar9 | adduser: Warning: The home directory `/var/lib/zookeeper' does not belong to the user you are currently creating. | 21:11 |
Rar9 | update-alternatives: using /etc/zookeeper/conf_example to provide /etc/zookeeper/conf (zookeeper-conf) in auto mode | 21:11 |
Rar9 | Setting up zookeeperd (3.4.5+dfsg-1) | 21:11 |
Rar9 | what do i need to change ? | 21:12 |
tarpman | Rar9: where is the error? | 21:12 |
coreycb | beisner, o/ | 21:12 |
Rar9 | when i enter sudo apt-get install zookeeperd | 21:13 |
bekks | Rar9: And where is the error? | 21:14 |
Rar9 | so is the process running now or do i have to do something to the directory owner? | 21:14 |
beisner | coreycb, sanity check on http://paste.ubuntu.com/13651987/ for Juno proposed --> updates plz | 21:14 |
bekks | Rar9: Did the command finish? | 21:15 |
Rar9 | adduser: Warning: The home directory `/var/lib/zookeeper' does not belong to the user you are currently creating. | 21:15 |
Rar9 | last line is "zookeeper start/running, process 1744" | 21:15 |
bekks | Rar9: Did the command "sudo apt-get install zookeeperd" finish - yes or no? | 21:15 |
tarpman | Rar9: "Warning" is not an error. | 21:15 |
Rar9 | sorry I´m a windows user :-( | 21:16 |
Rar9 | I just want to setup Basic Auth for Solr 5.3.1 | 21:16 |
Rar9 | and are struggling with zookeeper already | 21:16 |
coreycb | beisner, looks like glanceclient was already promoted but looks good other than that | 21:17 |
bekks | < bekks> Rar9: Did the command "sudo apt-get install zookeeperd" finish - yes or no? | 21:17 |
Rar9 | bekks the command finished... just with the warning. | 21:18 |
beisner | coreycb, looks to me like python-glanceclient | 1:0.14.0-0ubuntu1~cloud1 from proposed will supersede 1:0.14.0-0ubuntu1~cloud0 in updates. unless my report needs +1hr that is. | 21:19 |
bekks | Rar9: So without errors. And zookeeper was installed. | 21:19 |
Rar9 | how do i check if its now running? | 21:20 |
bekks | ps -ef | grep zookeeper | 21:20 |
bekks | If it isnt running, start it. | 21:21 |
Rar9 | ok. looks like it started | 21:22 |
coreycb | beisner, sorry, you're right. the cloud archive report is showing it green for some reason, threw me off. | 21:23 |
beisner | pesky colors anyhow | 21:23 |
Rar9 | so i don´t have to worry about the user permission for zookeeper? | 21:24 |
beisner | coreycb, ok juno proposed pushed to updates. thanks for your work on all that! | 21:27 |
coreycb | beisner, thanks! | 21:27 |
Rar9 | Now for Solr Basic Authentification how do i create Usernames and passwords (as a sha256(password+salt) hash) ?? | 21:28 |
trippeh | huh. qemu security update restarted my VMs. | 22:09 |
trippeh | that must be new :P | 22:09 |
Sling | my vm's restart themselves when they get kernel updates :) | 22:11 |
Sling | unattended-upgrades ftw | 22:11 |
trippeh | of course VMs without the start-at-boot flag set didnt start :P | 22:15 |
trippeh | ah, libvirt-bin updated around the same time, for a minor apparmor profile change looks like. | 22:24 |
trippeh | I wonder if it rebooted vms before or after qemu got its fixes. | 22:24 |
trippeh | *checks* | 22:24 |
trippeh | after, lookslike | 22:30 |
trippeh | lucky. | 22:30 |
=== Lcawte is now known as Lcawte|Away |
Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!