/srv/irclogs.ubuntu.com/2017/07/19/#ubuntu-server.txt

sonu_nkhi , i am facing some critical issue with my ubuntu server.. it is giving me "Error:Server unexpectedly closed network connection04:16
sonu_nkError:Could not connect to server" ... but it was working tomorrow perfect. with same credentials i tried today and its giving me error.. i cant access SFTP , No webmin working and no SSH working04:16
sarnoldI believe that's the error message you would get if tcpd (hosts.allow, hosts.deny, hosts_options) would give if an address isn't allowed04:17
sarnoldmaybe it's run out of RAM and is OOMing?04:18
sonu_nksarnold, what are the step for troubleshooting ?04:19
sarnoldsonu_nk: I think you're stuck looking at the console at this point04:22
sonu_nkmy ubntu server installed on Linode04:22
sarnolddo they have remote console services? if not, you'll have to hit the reboot button and hope there's something useful in the logs04:23
sonu_nkremote console services04:24
sonu_nkexist there04:24
sonu_nkhttps://paste.ubuntu.com/25123475/ see my log here which i tried to access via remote console sarnold04:29
sarnoldsonu_nk: ewwww04:30
sarnoldI'm out of ideas04:31
sarnoldsonu_nk: once you've got a prompt on that system please run ubuntu-bug systemd-logind and please fill it out as best you can. That's crazy.04:33
sarnoldI've got to run, good luck04:33
sonu_nkok sarnold thankyou04:33
sonu_nk"Network Helper did not run: could not determine distribution or distribution version  " this message coming when i reboot ubuntu server via linode panel04:52
cpaelzergood morning05:36
hheemorn05:50
lordievaderGood morning06:27
m1dnight_Hey guys, I'm trying to configure squid-deb-proxy but I keep getting TCP_MISS/404 in the access.log, but also 404's in the store.log..07:45
m1dnight_I can find a lot of data on the first problem, but not on the second07:46
m1dnight_Any pointers?07:46
m1dnight_I've even put "http_acccess allow all" in the file, to make sure that's not the issue.07:46
cpaelzerm1dnight_: are yu setting it up like https://wiki.ubuntu.com/SquidDebProxy or anything more complex?07:49
m1dnight_The basic configuration without any changes, honestly. Well, except the http_access allow all to be sure.07:50
m1dnight_Is there a setting I can use to cache _everything_?07:51
m1dnight_That's what I was going to test right now.07:51
cpaelzerin general if you only look for apt/deb caching you might check out apt-cacher-ng07:54
cpaelzernot so sure on squid conf - maybe just "." like refresh_pattern . 0 40% 4032007:55
cpaelzerhttp://www.squid-cache.org/Doc/config/refresh_pattern/ will be of help07:55
cpaelzerbut all hits I found warned you to please not cache too huge files there07:55
m1dnight_also, what does it mean for  line to be bungled?08:17
m1dnight_Bungled /path/to/conf.conf line 21:...08:17
cpaelzerrbasak: nacc: on https://code.launchpad.net/~paelzer/ubuntu/+source/multipath-tools/+git/multipath-tools/+merge/32761808:32
cpaelzerrbasak: nacc: if we are going to upload multipath-tools before the current artful-proposed will leave proposed do we need to jump through all the loops to make the merge apply?08:33
cpaelzerrbasak: or could one just accept and merge the upload tag and I upload as-is and things would work?08:33
cpaelzerit is kind of a race against time with only i386 dep8 tests missing due to the huge queue08:35
rbasakcpaelzer: I think it'd be fine to just add a new commit importing that changelog entry into the merge result.08:37
cpaelzerthat would certainly be easier08:37
rbasakcpaelzer: the only thing the importer cares about to preserve rich history is that the upload tag's tree matches the archive.08:37
cpaelzerok, then I'll prepare that way and you can merge/mark-upload tag just before I upload08:37
rbasakcpaelzer: and then next time that commit can just be dropped when following our usual merge workflow.08:37
rbasakack08:37
cpaelzerrbasak: ok, done - ready to merge and tag as upload so I can upload the actual change08:45
cpaelzerrbasak: or do you want to upload the change as well as part of the mergeing?08:45
rbasakcpaelzer: do you have an upload tag I can pull from somewhere please, and I can push that before you upload?08:49
cpaelzerhead of merge-artful should be it, I can tag and make it available if that helps08:50
* rbasak looks08:51
cpaelzerrbasak: cd2f5a906c08:52
rbasakOh, that should be fine, sorry. I had assumed you were sponsoring for someone else or something.08:52
cpaelzerI pushed it, but didn't set the upload tag on it as that usually is on the "accept the merge" task08:52
cpaelzerno my merge08:52
rbasak(because I hadn't really paid attention; sorry)08:52
cpaelzerfine08:52
cpaelzerenough involved people in that merge, but hey 3 reviews on day 1 is good08:52
cpaelzerrbasak: my dput is ready and waiting, just ping me once it is merged on USDI (or if there are any issues)08:54
rbasakcpaelzer: upload tag pushed08:54
rbasakcpaelzer: I didn't review or anything. In theory an uploader should be able to push an upload tag, but we don't have Launchpad ref wildcard ACLs yet. So I'm just being an ACL for you :)08:54
cpaelzerok for me08:55
cpaelzerand uploaded that way (and accepted) as reviewed and acked, thanks rbasak08:56
cpaelzerrbasak: will you set the MP to merged then?08:56
cpaelzerso that it drops off the active reviews queue?08:56
rbasakDone08:56
* rbasak should write a bot or something :-/08:56
cpaelzerthanks again08:56
cpaelzerif you are an ACL be a bot as well :-)08:57
rbasak:)08:57
cpaelzerwe are going the first steps, but I like the linter09:00
cpaelzerI didn't ask about that before, but has it a mode to lint before upload - to keep the silly mistakes hidden to others :-)09:01
cpaelzerrbasak: nacc: ^^?09:01
rbasakI believe so.09:01
cpaelzerok, then next merges get even more clean09:01
cpaelzerI really like to see that every time a merge comes by it gets easier due to our  improved process and tooling09:02
rbasakcpaelzer: just "git ubuntu lint" and it'll look at HEAD.09:02
cpaelzerfreeing up some time to fix things :-)09:02
cpaelzeroh nacc pushed it to the snap already09:02
* cpaelzer is testing the linter09:02
m1dnight_If you do apt-get update, what is actually being downloaded? I'm looking for the proper name09:15
m1dnight_package descriptions?09:15
lordievaderm1dnight_: More a list of available packages and versions of a repo.09:15
GMBeniaminHello guys! I was here last night with a problem regarding not being able to connect to internet with my new server. Is there someone willing to help me?09:19
rbasakm1dnight_: package metadata. You could call them indexes. Look in /var/lib/apt/lists/. It's plain text and is exactly what was downloaded.09:36
sonu_nkDoes the SSL include XSS protection as well?10:35
fgintherrbasak, I attached a testing summary to https://bugs.launchpad.net/bugs/1701350, please let me know if that meets your needs11:37
ubottuLaunchpad bug 1701350 in walinuxagent (Ubuntu Zesty) "WA Linux Agent 2.2.14" [High,Fix committed]11:37
rbasakfginther: that looks great. Thanks!11:41
linuxlovehi12:02
linuxloveanyone here ?12:03
lordievadero/12:03
linuxlovei used a2dismod mpm_perfork12:04
linuxloveand enabled e2enmod worker12:04
linuxlovemy apache has crashed12:04
linuxlove [mpm_prefork:notice] [pid 15351] AH00169: caught SIGTERM, shutting down12:04
linuxlovei see this12:04
linuxlovewhat should i do ?12:05
lordievaderRestart apache?12:05
linuxlovewhen i restart apache12:06
linuxlovei get error12:06
linuxloveim on ubuntu server 16.0412:07
lordievaderOnly that error above, or some others too?12:07
linuxlovei saw that in /var/log/apache2/error.log12:08
nacclinuxlove: that's not an error that's a log you restarted it12:09
=== JanC is now known as Guest74368
=== JanC_ is now known as JanC
linuxlovewhen i restart i see12:09
linuxloveJob for apache2.service failed because the control process exited with error code. See "systemctl status apache2.service" and "journalctl -xe" for details.12:10
linuxloveubuntu245@ubuntu245:/var/log/apache2$12:10
nacclinuxlove: ok, so pastebin those outputs12:10
linuxlovehttps://pastebin.com/LK6mM5ZQ12:14
nacclinuxlove: see the latter output12:14
nacclinuxlove: your config fails the test12:14
nacclinuxlove: iirc, check /var/log/apache2/error.log or so12:14
linuxlovenacc,12:18
linuxlovehttps://pastebin.com/j0X50Bzn12:18
linuxloveits latest in error.log12:18
nacclinuxlove: those segmentatin fauls are rather concerning12:20
linuxlovewhat should i do now ?12:20
linuxlovehow can i find cause of error ?12:22
linuxloveapache crashed just when i disabled mpm perfork and enabled worker12:23
linuxlovethis all i know at moment12:23
linuxlovewhats solution ?12:25
nacclinuxlove: switch back to prefork?12:27
linuxlovei did12:28
linuxlove$sudo a2dismod mpm_worker12:28
linuxlove$sudo a2enmod mpm_event12:28
linuxlovebut i cant restart apache212:28
lordievaderHow default is your (apache) config?12:59
MorpheusXNL__any apache guru's in here14:04
=== ashleyd is now known as ashd
thebwtso wait: you disabled prefork and enabled worker which causes the crash; then you disabled worker and enabled event and it still crashes. Did you switch back to prefork ever?17:46
Masterphihow do i allow a user to run reboot?21:32
sarnoldMasterphi: you can add a sudo entry to your sudoers file; it's a bit of a brutal manpage, though, so I suggest skimming to the end, reading the examples, and looking through the manpage to answer questions..21:52
sarnoldMasterphi: I have a feeling it'd be best to give the exact command line arguments you want the user to use in the sudoers file; without args means it can be called with any args, which might be a bit much21:53
Epx998misery is our new datacenter22:22
sarnold:(22:22
Epx998chassis labels are merely rack locations, if you want to know what server youre looking at, nslookup the rack location22:23
Epx998not so snazzy when trying to reimage 18 servers, not in a row22:23
Epx998boss got us 10gb, i suggested we disable onbaord nics to WAR the ub bug with off board interfaces, was told no.. now go reimage said servers22:23
Epx998you got to nslookup a rack location, swap cables, kickstart, rename interface, reboot and swap cables22:24
sarnoldso the label says "row 3 rack 10 server 22" rather than "s1292835" ?22:24
Epx998racks are hot like the sun and no soda machine in this DC22:24
Epx998dc2-04-1222:24
Epx998as an example, row 4 slot 1222:24
Epx998which is just a dns alias, so when you look it up, you'll get the real hostname22:25
Epx998then we ordered dells without enterprise licensing or something22:25
sarnoldoh crap no idrac?22:25
Epx998so forget remote console22:25
sarnoldDOOOMED22:25
Epx998its wonky idrac22:25
sarnoldthat's going to take more than a soda machine22:25
Epx998this new manager we poached from google, hes great and data solutions but hes built out two DC's and i HATE going to either for these reasons22:26
Epx998we hired 2 data center techs - soo us engineers could actually work - yet im still here at the DC22:26
Epx998im just annoyed hehe22:26
Epx998these dells have a serial port, i asked for a serial console switch, nopee. didnt get that either22:26
Epx998the new VP of our business unit only cared about reducing build turn around time, so no one in charge is thinking about supporting the infrastructure we are building out, we are cutting corners and paying for it22:28
Epx998make builds quicker, support the infra is an after thought22:28
Epx998ok my rant is over22:28
sarnoldit was a good one though :)22:32
sarnoldme, I just bought the one machine for my basement, and when I saw that e.g. dell wanted extra currency for their remote console stuff and lenovo .. well, Icouldn't even figure out how to work the lenovo order forms, let alone be frustrated that they charged money for the remote access key ..22:33
sarnold.. sent me straight to supermicro. super cheap. everything included. it's like staying at a cheap hotel that has fast and free wifi without hassles.22:33
Epx998yeah my mgr who bought our first dells said we didnt need enterprise, i was asked if we need it, my answer was (yes if we want remote console)22:34
Epx998that manager was in austin, not santa clara and his local DC was in his building where as mine are a drive away22:35
Epx998then we hired a replacement but....... alas turn around times22:35
Epx998supermicro eh22:35
Epx998we trialed some microservers from them, seemed ok22:35
Epx998remote was weird tho, the ones i liked the most were huawei - they were very helpful22:35
Epx998our newer hp's have ilo licenses, which is nice - not sure why we didnt do it on these dells22:36
sarnoldno kidding? I got a giggle that huawei sells "datacenter in a box", a shipping container pre-stocked with servers and power and networking and whatnot. it arrives, you supply power and it does the rest.22:36
Epx998oh wait so the issue is, its a non-shared port and we didnt order a switch to support the 2nd port for idrac22:36
Epx998my last gig, we boughut supermicro premade racks and shipped them to the uk22:37
Epx998plug n play - was kind of nice, but when working on supermicros, take aspirin and bandaids22:37
Epx998try getting serials for asset tagging ha.22:38
sarnoldoh man no separate management network? that makes it hard to protect against bmc/idrac etc flaws :( maybe that's not a huge deal in a build farm, but still22:38
Epx998nope - ive been asking for that since our first DC22:38
Epx9983 datacenters deep, no mgmt network22:39
Epx998we dont even have a seperate network to our netapp22:42
Epx998and we are huge data consumers across our network22:42
Epx998thought is with 10g its ok22:42
sarnold_today_ it's okay with 10g..22:47
sarnoldI had the impression most big sites were going with storage networks, 'application' networks, and one or two management networks (depending if they want something isolated for ssh to work on)22:48
Epx998and done22:53
Epx998sarnold: we are growing real fast, hard to plan everything - but there are 2 of us on this team. im the only guy who wasnt hired by trhis mgr22:54
Epx998and im 8/10 times ignored, despite i have trhe most extensive datacenter bring experience22:54
Epx998ok back to the office, i need a soda22:55
sarnoldsee ya Epx998 :)22:55
tomreynEpx998-: here's the solution (well workaround) for the shitty management: get 'replacement' serial cables, cross connect servers using them, so you can still conect to servers when network links fail, and can at least have basic OOB management.23:43
tomreynthe medium term goal is to get them fired, though ;)23:44
Epx998-lol23:46
Epx998-i like my workmates more or less23:46
=== Epx998- is now known as Epx998
tomreyntwo options: replace mgmt, or get yourself and your friends hired by someone with a clue23:50
tomreynthe latter is probably a lot less hassle23:50
Epx998well i dont want to sound rude, but that wont happen23:50
Epx998for typical silicon valley reasons23:51
tomreynsilicon valley = mgmt wont be replaced by people with a clue AND there ar eno other companies with less silly management who would hire you and your friends?23:52
Epx998not exactly23:52
tomreyni'm not really into silicon valley, but i wasn't aware it's that doomed ;)23:52
Epx998there is a trend here23:53
tomreynbecoming clueless in management? oh right, i heard about your president.23:53
Epx998ha there is that23:53
Epx998middle americas fault that one23:54
Epx998the coasts voted blue23:54
tomreynsure, silly con vally needs immigrants to grow cheap.23:54
Epx998forgot what I was going to do with the rest of my date23:59

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!