Meidokon Wiki
  • Comments
  • Immutable Page
  • Menu
    • Navigation
    • RecentChanges
    • FindPage
    • Local Site Map
    • Help
    • HelpContents
    • HelpOnMoinWikiSyntax
    • Display
    • Attachments
    • Info
    • Raw Text
    • Print View
    • Edit
    • Load
    • Save
  • Login

Useful(?) links

  • furinkan's stuff

  • Postfix snippets


  • SystemInfo

  • This sidebar

Navigation

  • FrontPage
  • RecentChanges
  • FindPage
  • HelpContents

Upload page content

You can upload content for the page named below. If you change the page name, you can also upload content for another page. If the page name is empty, we derive the page name from the file name.

File to load page content from
Page name
Comment

MeidokonWiki:
  • servers
  • basti

basti

This is going to be a higher-security network services host, mostly to host LDAP and maybe some associated services.

  • Maxtang MAX-N100-A5 Mini PC (Intel N100, 4x E-cores, 16gb RAM)
    • Intel N100, 6MB cache, up to 3.4GHz
    • 1x SODIMM slot, DDR4
    • 2x 1gb NIC ports
    • M2 2280 slot for PCIe 3.0 4x NVME/SATA
    • M2 2280 slot for PCIe 3.0 1x NVME
    • M2 2230 slot for wifi and bluetooth
    • 2x HDMI 2.0, 1x USB 2.0, 3x USB 3.2, 1x audio jack
    • 120x120x36mm
    • Internal PSU draws 1.5A from mains, producing ~45W DC power
  • Box specs
    • Colour: grey
    • Memory: 16gb
    • Storage: 512gb
    • PN: GM0MAXN100001005
    • SN: DT2024120402001
  • AlmaLinux 9.5

  • LAN MACs
    • enp1s0: e8:ff:1e:d5:60:7a (this is the primary NIC, despite having a higher MAC address)

    • enp2s0: e8:ff:1e:d5:60:79

  • located at home

Contents

  1. basti
    1. Build notes
      1. Prepare network
      2. OS imaging
      3. What do we want to even install here anyway?
    2. FreeIPA
    3. MikroDash
    4. gitea
    5. Local almalinux mirror
    6. iscsi notes

Build notes

This is a mix of notes from the previous provisioning, plus what I did when I renamed her from krolik to basti. I did this build around 2026-05-18

Build a clean Alma10 system than add FreeIPA to it.

rename krolik to basti

basti 300 IN A 192.168.53.10

Prepare network

This will live in a new VLAN, attached to hoshino, with firewalling eventually added.

Prepare hoshino:

  • Prepare bridge
    • VLAN 20, INFRA
    • Bridge VLAN on bridge1 (ports Et1-6)
    • Untagged on port 5,6 (amaris, basti)
  • Create interface-VLAN
    • name VLAN20_INFRA
    • on bridge1
  • Add an IP address on the VLAN
    • 192.168.53.1/24
    • network 192.168.53.0
    • on interface VLAN20_INFRA
  • Prep DHCP server on hoshino for the build, create the Network
    • address 192.168.53.0/24
    • gateway 192.168.53.1
    • mask 24
    • DNS server 8.8.8.8
    • domain thighhighs.top
    • next server 192.168.1.25
    • boot file name grub/grubx64-improved.efi
  • Create an IP pool for it
    • name: INFRA
    • addresses: 192.168.53.10-192.168.53.30
    • next pool: none
  • Create a DHCP Server for the segment
    • name: infra
    • interface: VLAN20_INFRA
    • address pool: INFRA
  • Update DHCP lease for basti to give correct address
    • address: 192.168.53.10
    • MAC: E8:FF:1E:D5:60:7A

    • server: infra

Boot it up and hope it works!

Do firewalling on hoshino:

  • We can't use in/out ports because it's part of the bridge, and we don't want to enable ip-firewalling on the bridge because it'll slow it down, so we'll just use src/dst IPs for now.
  • Google this error for details: "in-bridge-port matcher not possible when bridge use-ip-firewall is disabled"

OS imaging

We're now using servers/neru to serve TFTP and HTTP for PXE boot, no need to have a whole linux machine dedicated to it. Slightly harder to maintain, but should be more bulletproof and doesn't need as much maintenance. A USB stick hosts the bootloader and configs for TFTP, and we run nginx in a container to serve netinstall images from the same directory (/usb1p1/srv/)

Editing kickstart configs is kinda a pain in the arse now because you can't just run vim on the device, but you can edit remotely via an SSHFS mount.

What do we want to even install here anyway?

  • FreeIPA?
  • Mrepo? http://dag.wiee.rs/home-made/mrepo/

    • https://github.com/dagwieers/mrepo

  • MikroDash: https://github.com/SecOps-7/MikroDash

dnf install mtr traceroute

FreeIPA

Start on the QSG: https://www.freeipa.org/page/Quick_Start_Guide

TBC

MikroDash

This is kinda nice.

Run it like this:

docker run -d -p 3081:3081 -v /persist/mikrodash:/data --name mikrodash --restart=unless-stopped ghcr.io/secops-7/mikrodash:latest

Configure targets:

[root@krolik mikrodash]# gzip -c routers.json | base64
H4sICNo3A2oAA3JvdXRlcnMuanNvbgDF1ltv4jgUB/D3+RSor4yLHTu+rLQPhALlVsqtBVb7YMc2
yQAJjZPSYbTffUM7nZGg81oURUJ/J1asn87h/POlUvlR3pXKVayv/qpcMa6VJ30fIB0qQHwDAafS
AmGUolyYUFN59fXtjY1UZnN8CVVAJTKbWCbvS1Hq8uPKW3qdR/EqOt7uOk937w/t0uz4EGce/5nk
G1cGVm6c+Z10EmfCIjMnK4UzWSK3x/hqG6+zVEsX/dpaOrdPs9cjPdT8vpOWFPfVb/Pk4Z6ShLJD
PTn0p4f5rL/rIFhLn9ei9eCNMxXU8ySIxJO8X03h3+/7aWNlsck79rihyRGI3e9jxMlqKrOVeT0x
un693hfV/ibdJwO1Ox4MQQh/5bPdeSq1Nrp+3Acxxn1BfOb7yC8X//t6KmUQxhJpD3CMSiljFFBG
UVBuwSjmoWFSnUnhUmor17HM8/TU6j2/rJZp8Wo+yehhXa1NXxrhfTeAtzcLOAxYrxfdwG74lDeD
+8Zg8eA13XY4W6SL2M512A3/pBWZDH0GFqWUEP4hlmWlJTIEGK0QIJhgwD0tAdYYhyH2yhKzZ1ik
xLJZnMfylAoJ7xpRXn47+WSeKpXjaTdRqrfYPYvZBKu+o5o/PfrkpmnxobOr19qzKBHjajDruVEY
w+Vjdb+Lkv2leYQHOfE+5KGUWe5hAUzoa0C0gEDx8lfZ8wzkSgjqmTMe/9j1UhfFyVkp/YwvW0m4
wdeQpGgl57TbG6/atdbIo6vAb7JuVxV3tVW4R8VyOfQhXXBe53wIp3Vqxo+Di1MxTr2P2x71CLU0
ZCBEygIiSQiUZzDwNCdaCko5Om97tKRax65scKdSb+lloVrzJmtnm+Cmmc98R+cz23P5rivCYVDX
z9Hev9vb1iIu0uloLLsLkwV37RUXgbv94x/UJ0H5EJcX/BBKCOt7mkngUVtCcU4BV0aC0CossZVY
GH0GxUoomcXulOmYXRZp7Xs89OBkMnEParcRNd3YZ4vHzdLF9emIPUdMey8t/nTYsnVzPNhHi5ci
qdan4+XFkRDChLAPkbhRhFtYjnsY0nKICClQmGpgBefYMmOJD8+Q+LGazHkpmQvXke7PcNBOo6n2
sm/17+auZ5pNGBXFbIQKMxrn45g9y27e3tjddms7kxeewFXUGLnOxYkIxPxjIoaYUFz5APuwHB1o
OT9IKiTgmkiNLYSInxOJkigxWXFqdMwuizTeF41ogwRCSZK4u2CVrft5z63NujMJbv2iP3gK1rWw
cIHfY3nn2+1jbam/D4Z5zi+OxAQVr/Pdl3//B0z/kIQ5DQAA

[root@krolik mikrodash]# gzip -c settings.json | base64
H4sICMC2CWoAA3NldHRpbmdzLmpzb24AZZJPc9owEMXv+RSMz4XaTuLYnemhgaZxC0wG1DY9ru31
n0FIHkmGMJ1+90rYxnIYLub3Vm9X+/T3ZjJxBG8UimculfNp4niRP/OCcBaGM8/5MOgvXBg9fPAj
ixIqNVSiwTGMmcS0EajFHKi01Z8ShWkE2b5iow4gjZnTsgxzaKiKc4NQlSi6cTKQZe+RN6JiO2CD
0pusYL7lJP7ms+3qDdz4B/efBQnm63IHyz+nuvZO89dN9J08gjqo+uMxL55IrDbr17vPrVtdseIr
g4RiZl/RYAKiwHZbs/OvO8EpnXPGzAD3ruteIAG6Q2HwrY0fgWXHKlPl+/qN3oduo7HnXjgUOPBh
HF2+PUmFe0192+R3JZCi7LsOwq+ajZ01e9LFR6D0/SRxLhWo5upGcQ4pGhqMbF7a6UalX0R9NcKi
TOv+cEsVr9fmZP+nW9nA8m5C0hZ6LT3UbKFTJ/bpPbz1KfgX/7KSiovTqmL6qbU7OXOgKNS8bkgp
UJacmqwjSzI3WvLzFr3OSnC5wKQpRm8bUlUdzgGhiI2JEwQPeejfRlNM77PpXRa50yTUX0kSoBsm
URT46FyitdIastU8ZtqwX/ZI6XY4Ym20I2RWgXo4zq4crNBHfMmLq1r7rRrh5t9/S/dElzwEAAA=

gitea

nginx configs

/etc/nginx/conf.d/almalinux.conf
    server {
        listen       80;
        listen       [::]:80;
        server_name  mirror.thighhighs.top;
        root         /usr/share/nginx/html;

        location /almalinux/mirrorlist {
            alias /persist/almalinux_mirrorlists ;
            autoindex on;
        }
        location /almalinux {
            alias /persist/almalinux_repos ;
            autoindex on;
        }


"/etc/nginx/conf.d/gitea.conf"
server {
    listen       80;
    listen       [::]:80;
    server_name  git.thighhighs.top;
    root         /usr/share/nginx/html;

    location / {
        client_max_body_size 512M;
        proxy_pass       http://localhost:3000;
        proxy_set_header Connection $http_connection;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

Run gitea as a service:

"gitea.service"
# THIS FILE IS MANAGED BY ANSIBLE. MANUAL CHANGES MAY BE DESTROYED.
# vim: syntax=systemd
[Unit]
Description=containerised Gitea
After=docker.service persist-gitea.mount
Requires=docker.service persist-gitea.mount

[Service]
Environment=USER_UID=2000
Environment=USER_GID=2000
Environment=HTTP_PORT=3000
Environment=SSH_PORT=2222
Environment='GITEA_IMAGE=docker.io/gitea/gitea:1.23.4'

ExecStart=docker run --rm --name="gitea" -e USER_UID=${USER_UID} -e USER_GID=${USER_GID} -p ${HTTP_PORT}:3000 -p ${SSH_PORT}:22 -v /persist/gitea/data:/data -v /etc/timezone:/etc/timezone:ro -v /etc/localtime:/etc/localtime:ro ${GITEA_IMAGE}

Restart=on-failure
RestartSec=10s

[Install]
WantedBy=multi-user.target

And filesystem mounts:

"persist-almalinux_repos.mount"
[Unit]
Description=Filesystem for Almalinux dnf repos
Requires=iscsi.service

[Mount]
What=/dev/disk/by-uuid/7f55bc8f-ebd1-4159-8572-6332539f7f13
Where=/persist/almalinux_repos
Type=xfs
Options=noatime,_netdev
TimeoutSec=20

[Install]
WantedBy=default.target



"persist-gitea.mount"
[Unit]
Description=Filesystem for gitea data
Requires=iscsi.service

[Mount]
What=/dev/disk/by-uuid/c1ef0078-ed22-4a08-9e5b-24aa5b815d5e
Where=/persist/gitea
Type=xfs
Options=noatime,_netdev
TimeoutSec=20

[Install]
WantedBy=default.target

Local almalinux mirror

sync-alma-mirror-from-upstream.service

# THIS FILE IS MANAGED BY ANSIBLE. MANUAL CHANGES MAY BE DESTROYED.
# vim: syntax=systemd
[Unit]
Description=rsync the AlmaLinux package mirror

After=persist-almalinux_repos.mount
Requires=persist-almalinux_repos.mount

[Service]
Type=oneshot
Nice=19
IOSchedulingClass=2
IOSchedulingPriority=7
ExecStart=/usr/bin/rsync -rlptvSH --bwlimit=80m --exclude=.~tmp~ --delete-delay --delay-updates rsync://rsync.repo.almalinux.org/almalinux/ /persist/almalinux_repos/
Restart=on-failure
RestartSec=5min




"sync-alma-mirror-from-upstream.timer"

# THIS FILE IS MANAGED BY ANSIBLE. MANUAL CHANGES MAY BE DESTROYED.
# vim: syntax=systemd
[Unit]
Description=AlmaLinux repo rsync
Requires=persist-almalinux_repos.mount
After=persist-almalinux_repos.mount

[Timer]
OnBootSec=30min
OnUnitInactiveSec=13h
RandomizedDelaySec=10m

[Install]
WantedBy=timers.target

[root@krolik system]# base64 /persist/mirrorlists.tar.gz
H4sIAAAAAAAAA+3X3WqDMBwFcK/3FF702nyoCdvd9gK96AOMbMgUdAlJCj7+or0YK5vWLjhmzw+K
YgPRnv+BairrGueJajvVNu/H/rlrrNW2DRcdSaKggSzL8RicH8dzVshCMh6WhXWslDlL0jLO9tOO
ziubponV2k+tm/v+nzKT+d9nZYQZuDz/nHIZrjPBc4r81zCfvzLGeVupLvP9db/AELAoih/zZzT/
mj8P4yKTlEZ+1m/deP619+aBkFPoma+bt3r4uMxr8zkU4yA8GnMYB4HsXpSrlH2tiXbk7q8fAX5h
vv9D1tpdXf7kkv7T8/7zvED/17Cg/09hEPYHlH9T5vtf9d6q1fsvBPq/hgX9Pw0C+r8pM/2Pssf4
/iflgvd/wYf//zxMXZQbmHLj/QcAAAAAAAAAAACAbfoAVea3QwAoAAA=

ansible is done, now setup nginx with it to serve the repo

iscsi notes

basti attaches iscsi LUNs from fenny so it doesn't need much local storage.

[root@krolik iscsi]# tree
.
├── ifaces
├── isns
├── nodes
│   └── iqn.2011-08.com.asustor:fs6812x-437849.krolik
│       └── 192.168.32.18,3260,1
│           └── default
├── send_targets
│   └── fenny.thighhighs.top,3260
│       ├── iqn.2011-08.com.asustor:fs6812x-437849.krolik,192.168.32.18,3260,1,default -> /var/lib/iscsi/nodes/iqn.2011-08.com.asustor:fs6812x-437849.krolik/192.168.32.18,3260,1
│       └── st_config
├── slp
└── static




[root@basti ~]# iscsiadm -m discovery -t sendtargets -p fenny.thighhighs.top
192.168.32.18:3260,1 iqn.2011-08.com.asustor:fs6812x-437849..basti

[root@basti ~]# iscsiadm -m node -T iqn.2011-08.com.asustor:fs6812x-437849..basti -l
Login to [iface: default, target: iqn.2011-08.com.asustor:fs6812x-437849..basti, portal: 192.168.32.18,3260] successful.
[root@basti ~]# lsscsi
[1:0:0:0]    disk    ATA      NGFF 2280 512GB  3A0   /dev/sda
[2:0:0:0]    disk    ASUSTOR  iSCSI Storage    380   /dev/sdb
[2:0:0:1]    disk    ASUSTOR  iSCSI Storage    380   /dev/sdc

[root@basti ~]# iscsiadm  -m node -L automatic
  • MoinMoin Powered
  • Python Powered
  • GPL licensed
  • Valid HTML 4.01
MoinMoin Release 1.9.11 [Revision release], Copyright by Juergen Hermann et al.