## page was renamed from servers/krolik = basti = This is going to be a higher-security network services host, mostly to host LDAP and maybe some associated services. * Maxtang MAX-N100-A5 Mini PC (Intel N100, 4x E-cores, 16gb RAM) * Intel N100, 6MB cache, up to 3.4GHz * 1x SODIMM slot, DDR4 * 2x 1gb NIC ports * M2 2280 slot for PCIe 3.0 4x NVME/SATA * M2 2280 slot for PCIe 3.0 1x NVME * M2 2230 slot for wifi and bluetooth * 2x HDMI 2.0, 1x USB 2.0, 3x USB 3.2, 1x audio jack * 120x120x36mm * Internal PSU draws 1.5A from mains, producing ~45W DC power * Box specs * Colour: grey * Memory: 16gb * Storage: 512gb * PN: GM0MAXN100001005 * SN: DT2024120402001 * AlmaLinux 9.5 * LAN MACs * `enp1s0: e8:ff:1e:d5:60:7a` (this is the primary NIC, despite having a higher MAC address) * `enp2s0: e8:ff:1e:d5:60:79` * located at home <> == Build notes == This is a mix of notes from the previous provisioning, plus what I did when I renamed her from krolik to basti. I did this build around 2026-05-18 Build a clean Alma10 system than add FreeIPA to it. rename krolik to basti {{{ basti 300 IN A 192.168.53.10 }}} === Prepare network === This will live in a new VLAN, attached to hoshino, with firewalling eventually added. Prepare hoshino: * Prepare bridge * VLAN 20, INFRA * Bridge VLAN on bridge1 (ports Et1-6) * Untagged on port 5,6 (amaris, basti) * Create interface-VLAN * name VLAN20_INFRA * on bridge1 * Add an IP address on the VLAN * 192.168.53.1/24 * network 192.168.53.0 * on interface VLAN20_INFRA * Prep DHCP server on hoshino for the build, create the Network * address 192.168.53.0/24 * gateway 192.168.53.1 * mask 24 * DNS server 8.8.8.8 * domain thighhighs.top * next server 192.168.1.25 * boot file name grub/grubx64-improved.efi * Create an IP pool for it * name: INFRA * addresses: 192.168.53.10-192.168.53.30 * next pool: none * Create a DHCP Server for the segment * name: infra * interface: VLAN20_INFRA * address pool: INFRA * Update DHCP lease for basti to give correct address * address: 192.168.53.10 * MAC: E8:FF:1E:D5:60:7A * server: infra Boot it up and hope it works! Do firewalling on hoshino: * We can't use in/out ports because it's part of the bridge, and we don't want to enable ip-firewalling on the bridge because it'll slow it down, so we'll just use src/dst IPs for now. * Google this error for details: "in-bridge-port matcher not possible when bridge use-ip-firewall is disabled" === OS imaging === We're now using [[servers/neru]] to serve TFTP and HTTP for PXE boot, no need to have a whole linux machine dedicated to it. Slightly harder to maintain, but should be more bulletproof and doesn't need as much maintenance. A USB stick hosts the bootloader and configs for TFTP, and we run nginx in a container to serve netinstall images from the same directory (`/usb1p1/srv/`) Editing kickstart configs is kinda a pain in the arse now because you can't just run vim on the device, but you can edit remotely via an SSHFS mount. === What do we want to even install here anyway? === * FreeIPA? * Mrepo? http://dag.wiee.rs/home-made/mrepo/ * https://github.com/dagwieers/mrepo * MikroDash: https://github.com/SecOps-7/MikroDash {{{ dnf install mtr traceroute }}} == FreeIPA == Start on the QSG: https://www.freeipa.org/page/Quick_Start_Guide TBC == MikroDash == This is kinda nice. Run it like this: {{{ docker run -d -p 3081:3081 -v /persist/mikrodash:/data --name mikrodash --restart=unless-stopped ghcr.io/secops-7/mikrodash:latest }}} Configure targets: {{{ [root@krolik mikrodash]# gzip -c routers.json | base64 H4sICNo3A2oAA3JvdXRlcnMuanNvbgDF1ltv4jgUB/D3+RSor4yLHTu+rLQPhALlVsqtBVb7YMc2 yQAJjZPSYbTffUM7nZGg81oURUJ/J1asn87h/POlUvlR3pXKVayv/qpcMa6VJ30fIB0qQHwDAafS AmGUolyYUFN59fXtjY1UZnN8CVVAJTKbWCbvS1Hq8uPKW3qdR/EqOt7uOk937w/t0uz4EGce/5nk G1cGVm6c+Z10EmfCIjMnK4UzWSK3x/hqG6+zVEsX/dpaOrdPs9cjPdT8vpOWFPfVb/Pk4Z6ShLJD PTn0p4f5rL/rIFhLn9ei9eCNMxXU8ySIxJO8X03h3+/7aWNlsck79rihyRGI3e9jxMlqKrOVeT0x un693hfV/ibdJwO1Ox4MQQh/5bPdeSq1Nrp+3Acxxn1BfOb7yC8X//t6KmUQxhJpD3CMSiljFFBG UVBuwSjmoWFSnUnhUmor17HM8/TU6j2/rJZp8Wo+yehhXa1NXxrhfTeAtzcLOAxYrxfdwG74lDeD +8Zg8eA13XY4W6SL2M512A3/pBWZDH0GFqWUEP4hlmWlJTIEGK0QIJhgwD0tAdYYhyH2yhKzZ1ik xLJZnMfylAoJ7xpRXn47+WSeKpXjaTdRqrfYPYvZBKu+o5o/PfrkpmnxobOr19qzKBHjajDruVEY w+Vjdb+Lkv2leYQHOfE+5KGUWe5hAUzoa0C0gEDx8lfZ8wzkSgjqmTMe/9j1UhfFyVkp/YwvW0m4 wdeQpGgl57TbG6/atdbIo6vAb7JuVxV3tVW4R8VyOfQhXXBe53wIp3Vqxo+Di1MxTr2P2x71CLU0 ZCBEygIiSQiUZzDwNCdaCko5Om97tKRax65scKdSb+lloVrzJmtnm+Cmmc98R+cz23P5rivCYVDX z9Hev9vb1iIu0uloLLsLkwV37RUXgbv94x/UJ0H5EJcX/BBKCOt7mkngUVtCcU4BV0aC0CossZVY GH0GxUoomcXulOmYXRZp7Xs89OBkMnEParcRNd3YZ4vHzdLF9emIPUdMey8t/nTYsnVzPNhHi5ci qdan4+XFkRDChLAPkbhRhFtYjnsY0nKICClQmGpgBefYMmOJD8+Q+LGazHkpmQvXke7PcNBOo6n2 sm/17+auZ5pNGBXFbIQKMxrn45g9y27e3tjddms7kxeewFXUGLnOxYkIxPxjIoaYUFz5APuwHB1o OT9IKiTgmkiNLYSInxOJkigxWXFqdMwuizTeF41ogwRCSZK4u2CVrft5z63NujMJbv2iP3gK1rWw cIHfY3nn2+1jbam/D4Z5zi+OxAQVr/Pdl3//B0z/kIQ5DQAA [root@krolik mikrodash]# gzip -c settings.json | base64 H4sICMC2CWoAA3NldHRpbmdzLmpzb24AZZJPc9owEMXv+RSMz4XaTuLYnemhgaZxC0wG1DY9ru31 n0FIHkmGMJ1+90rYxnIYLub3Vm9X+/T3ZjJxBG8UimculfNp4niRP/OCcBaGM8/5MOgvXBg9fPAj ixIqNVSiwTGMmcS0EajFHKi01Z8ShWkE2b5iow4gjZnTsgxzaKiKc4NQlSi6cTKQZe+RN6JiO2CD 0pusYL7lJP7ms+3qDdz4B/efBQnm63IHyz+nuvZO89dN9J08gjqo+uMxL55IrDbr17vPrVtdseIr g4RiZl/RYAKiwHZbs/OvO8EpnXPGzAD3ruteIAG6Q2HwrY0fgWXHKlPl+/qN3oduo7HnXjgUOPBh HF2+PUmFe0192+R3JZCi7LsOwq+ajZ01e9LFR6D0/SRxLhWo5upGcQ4pGhqMbF7a6UalX0R9NcKi TOv+cEsVr9fmZP+nW9nA8m5C0hZ6LT3UbKFTJ/bpPbz1KfgX/7KSiovTqmL6qbU7OXOgKNS8bkgp UJacmqwjSzI3WvLzFr3OSnC5wKQpRm8bUlUdzgGhiI2JEwQPeejfRlNM77PpXRa50yTUX0kSoBsm URT46FyitdIastU8ZtqwX/ZI6XY4Ym20I2RWgXo4zq4crNBHfMmLq1r7rRrh5t9/S/dElzwEAAA= }}} == gitea == nginx configs {{{ /etc/nginx/conf.d/almalinux.conf server { listen 80; listen [::]:80; server_name mirror.thighhighs.top; root /usr/share/nginx/html; location /almalinux/mirrorlist { alias /persist/almalinux_mirrorlists ; autoindex on; } location /almalinux { alias /persist/almalinux_repos ; autoindex on; } "/etc/nginx/conf.d/gitea.conf" server { listen 80; listen [::]:80; server_name git.thighhighs.top; root /usr/share/nginx/html; location / { client_max_body_size 512M; proxy_pass http://localhost:3000; proxy_set_header Connection $http_connection; proxy_set_header Upgrade $http_upgrade; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } } }}} Run gitea as a service: {{{ "gitea.service" # THIS FILE IS MANAGED BY ANSIBLE. MANUAL CHANGES MAY BE DESTROYED. # vim: syntax=systemd [Unit] Description=containerised Gitea After=docker.service persist-gitea.mount Requires=docker.service persist-gitea.mount [Service] Environment=USER_UID=2000 Environment=USER_GID=2000 Environment=HTTP_PORT=3000 Environment=SSH_PORT=2222 Environment='GITEA_IMAGE=docker.io/gitea/gitea:1.23.4' ExecStart=docker run --rm --name="gitea" -e USER_UID=${USER_UID} -e USER_GID=${USER_GID} -p ${HTTP_PORT}:3000 -p ${SSH_PORT}:22 -v /persist/gitea/data:/data -v /etc/timezone:/etc/timezone:ro -v /etc/localtime:/etc/localtime:ro ${GITEA_IMAGE} Restart=on-failure RestartSec=10s [Install] WantedBy=multi-user.target }}} And filesystem mounts: {{{ "persist-almalinux_repos.mount" [Unit] Description=Filesystem for Almalinux dnf repos Requires=iscsi.service [Mount] What=/dev/disk/by-uuid/7f55bc8f-ebd1-4159-8572-6332539f7f13 Where=/persist/almalinux_repos Type=xfs Options=noatime,_netdev TimeoutSec=20 [Install] WantedBy=default.target "persist-gitea.mount" [Unit] Description=Filesystem for gitea data Requires=iscsi.service [Mount] What=/dev/disk/by-uuid/c1ef0078-ed22-4a08-9e5b-24aa5b815d5e Where=/persist/gitea Type=xfs Options=noatime,_netdev TimeoutSec=20 [Install] WantedBy=default.target }}} == Local almalinux mirror == {{{ sync-alma-mirror-from-upstream.service # THIS FILE IS MANAGED BY ANSIBLE. MANUAL CHANGES MAY BE DESTROYED. # vim: syntax=systemd [Unit] Description=rsync the AlmaLinux package mirror After=persist-almalinux_repos.mount Requires=persist-almalinux_repos.mount [Service] Type=oneshot Nice=19 IOSchedulingClass=2 IOSchedulingPriority=7 ExecStart=/usr/bin/rsync -rlptvSH --bwlimit=80m --exclude=.~tmp~ --delete-delay --delay-updates rsync://rsync.repo.almalinux.org/almalinux/ /persist/almalinux_repos/ Restart=on-failure RestartSec=5min "sync-alma-mirror-from-upstream.timer" # THIS FILE IS MANAGED BY ANSIBLE. MANUAL CHANGES MAY BE DESTROYED. # vim: syntax=systemd [Unit] Description=AlmaLinux repo rsync Requires=persist-almalinux_repos.mount After=persist-almalinux_repos.mount [Timer] OnBootSec=30min OnUnitInactiveSec=13h RandomizedDelaySec=10m [Install] WantedBy=timers.target }}} {{{ [root@krolik system]# base64 /persist/mirrorlists.tar.gz H4sIAAAAAAAAA+3X3WqDMBwFcK/3FF702nyoCdvd9gK96AOMbMgUdAlJCj7+or0YK5vWLjhmzw+K YgPRnv+BairrGueJajvVNu/H/rlrrNW2DRcdSaKggSzL8RicH8dzVshCMh6WhXWslDlL0jLO9tOO ziubponV2k+tm/v+nzKT+d9nZYQZuDz/nHIZrjPBc4r81zCfvzLGeVupLvP9db/AELAoih/zZzT/ mj8P4yKTlEZ+1m/deP619+aBkFPoma+bt3r4uMxr8zkU4yA8GnMYB4HsXpSrlH2tiXbk7q8fAX5h vv9D1tpdXf7kkv7T8/7zvED/17Cg/09hEPYHlH9T5vtf9d6q1fsvBPq/hgX9Pw0C+r8pM/2Pssf4 /iflgvd/wYf//zxMXZQbmHLj/QcAAAAAAAAAAACAbfoAVea3QwAoAAA= }}} ansible is done, now setup nginx with it to serve the repo == iscsi notes == basti attaches iscsi LUNs from fenny so it doesn't need much local storage. {{{ [root@krolik iscsi]# tree . ├── ifaces ├── isns ├── nodes │ └── iqn.2011-08.com.asustor:fs6812x-437849.krolik │ └── 192.168.32.18,3260,1 │ └── default ├── send_targets │ └── fenny.thighhighs.top,3260 │ ├── iqn.2011-08.com.asustor:fs6812x-437849.krolik,192.168.32.18,3260,1,default -> /var/lib/iscsi/nodes/iqn.2011-08.com.asustor:fs6812x-437849.krolik/192.168.32.18,3260,1 │ └── st_config ├── slp └── static [root@basti ~]# iscsiadm -m discovery -t sendtargets -p fenny.thighhighs.top 192.168.32.18:3260,1 iqn.2011-08.com.asustor:fs6812x-437849..basti [root@basti ~]# iscsiadm -m node -T iqn.2011-08.com.asustor:fs6812x-437849..basti -l Login to [iface: default, target: iqn.2011-08.com.asustor:fs6812x-437849..basti, portal: 192.168.32.18,3260] successful. [root@basti ~]# lsscsi [1:0:0:0] disk ATA NGFF 2280 512GB 3A0 /dev/sda [2:0:0:0] disk ASUSTOR iSCSI Storage 380 /dev/sdb [2:0:0:1] disk ASUSTOR iSCSI Storage 380 /dev/sdc [root@basti ~]# iscsiadm -m node -L automatic }}}