|
Size: 11295
Comment: add all the rebuild notes from 2026-05-18
|
← Revision 6 as of 2026-09-08 15:09:52 ⇥
Size: 11307
Comment: link to neru
|
| Deletions are marked like this. | Additions are marked like this. |
| Line 88: | Line 88: |
| We're now using neru to serve TFTP and HTTP for PXE boot, no need to have a whole linux machine dedicated to it. Slightly harder to maintain, but should be more bulletproof and doesn't need as much maintenance. A USB stick hosts the bootloader and configs for TFTP, and we run nginx in a container to serve netinstall images from the same directory (`/usb1p1/srv/`) | We're now using [[servers/neru]] to serve TFTP and HTTP for PXE boot, no need to have a whole linux machine dedicated to it. Slightly harder to maintain, but should be more bulletproof and doesn't need as much maintenance. A USB stick hosts the bootloader and configs for TFTP, and we run nginx in a container to serve netinstall images from the same directory (`/usb1p1/srv/`) |
basti
This is going to be a higher-security network services host, mostly to host LDAP and maybe some associated services.
- Maxtang MAX-N100-A5 Mini PC (Intel N100, 4x E-cores, 16gb RAM)
- Intel N100, 6MB cache, up to 3.4GHz
- 1x SODIMM slot, DDR4
- 2x 1gb NIC ports
- M2 2280 slot for PCIe 3.0 4x NVME/SATA
- M2 2280 slot for PCIe 3.0 1x NVME
- M2 2230 slot for wifi and bluetooth
- 2x HDMI 2.0, 1x USB 2.0, 3x USB 3.2, 1x audio jack
- 120x120x36mm
- Internal PSU draws 1.5A from mains, producing ~45W DC power
- Box specs
- Colour: grey
- Memory: 16gb
- Storage: 512gb
- PN: GM0MAXN100001005
- SN: DT2024120402001
AlmaLinux 9.5
- LAN MACs
enp1s0: e8:ff:1e:d5:60:7a (this is the primary NIC, despite having a higher MAC address)
enp2s0: e8:ff:1e:d5:60:79
- located at home
Contents
Build notes
This is a mix of notes from the previous provisioning, plus what I did when I renamed her from krolik to basti. I did this build around 2026-05-18
Build a clean Alma10 system than add FreeIPA to it.
rename krolik to basti
basti 300 IN A 192.168.53.10
Prepare network
This will live in a new VLAN, attached to hoshino, with firewalling eventually added.
Prepare hoshino:
- Prepare bridge
- VLAN 20, INFRA
- Bridge VLAN on bridge1 (ports Et1-6)
- Untagged on port 5,6 (amaris, basti)
- Create interface-VLAN
- name VLAN20_INFRA
- on bridge1
- Add an IP address on the VLAN
- 192.168.53.1/24
- network 192.168.53.0
- on interface VLAN20_INFRA
- Prep DHCP server on hoshino for the build, create the Network
- address 192.168.53.0/24
- gateway 192.168.53.1
- mask 24
- DNS server 8.8.8.8
- domain thighhighs.top
- next server 192.168.1.25
- boot file name grub/grubx64-improved.efi
- Create an IP pool for it
- name: INFRA
- addresses: 192.168.53.10-192.168.53.30
- next pool: none
- Create a DHCP Server for the segment
- name: infra
- interface: VLAN20_INFRA
- address pool: INFRA
- Update DHCP lease for basti to give correct address
- address: 192.168.53.10
MAC: E8:FF:1E:D5:60:7A
- server: infra
Boot it up and hope it works!
Do firewalling on hoshino:
- We can't use in/out ports because it's part of the bridge, and we don't want to enable ip-firewalling on the bridge because it'll slow it down, so we'll just use src/dst IPs for now.
- Google this error for details: "in-bridge-port matcher not possible when bridge use-ip-firewall is disabled"
OS imaging
We're now using servers/neru to serve TFTP and HTTP for PXE boot, no need to have a whole linux machine dedicated to it. Slightly harder to maintain, but should be more bulletproof and doesn't need as much maintenance. A USB stick hosts the bootloader and configs for TFTP, and we run nginx in a container to serve netinstall images from the same directory (/usb1p1/srv/)
Editing kickstart configs is kinda a pain in the arse now because you can't just run vim on the device, but you can edit remotely via an SSHFS mount.
What do we want to even install here anyway?
- FreeIPA?
dnf install mtr traceroute
FreeIPA
Start on the QSG: https://www.freeipa.org/page/Quick_Start_Guide
TBC
MikroDash
This is kinda nice.
Run it like this:
docker run -d -p 3081:3081 -v /persist/mikrodash:/data --name mikrodash --restart=unless-stopped ghcr.io/secops-7/mikrodash:latest
Configure targets:
[root@krolik mikrodash]# gzip -c routers.json | base64 H4sICNo3A2oAA3JvdXRlcnMuanNvbgDF1ltv4jgUB/D3+RSor4yLHTu+rLQPhALlVsqtBVb7YMc2 yQAJjZPSYbTffUM7nZGg81oURUJ/J1asn87h/POlUvlR3pXKVayv/qpcMa6VJ30fIB0qQHwDAafS AmGUolyYUFN59fXtjY1UZnN8CVVAJTKbWCbvS1Hq8uPKW3qdR/EqOt7uOk937w/t0uz4EGce/5nk G1cGVm6c+Z10EmfCIjMnK4UzWSK3x/hqG6+zVEsX/dpaOrdPs9cjPdT8vpOWFPfVb/Pk4Z6ShLJD PTn0p4f5rL/rIFhLn9ei9eCNMxXU8ySIxJO8X03h3+/7aWNlsck79rihyRGI3e9jxMlqKrOVeT0x un693hfV/ibdJwO1Ox4MQQh/5bPdeSq1Nrp+3Acxxn1BfOb7yC8X//t6KmUQxhJpD3CMSiljFFBG UVBuwSjmoWFSnUnhUmor17HM8/TU6j2/rJZp8Wo+yehhXa1NXxrhfTeAtzcLOAxYrxfdwG74lDeD +8Zg8eA13XY4W6SL2M512A3/pBWZDH0GFqWUEP4hlmWlJTIEGK0QIJhgwD0tAdYYhyH2yhKzZ1ik xLJZnMfylAoJ7xpRXn47+WSeKpXjaTdRqrfYPYvZBKu+o5o/PfrkpmnxobOr19qzKBHjajDruVEY w+Vjdb+Lkv2leYQHOfE+5KGUWe5hAUzoa0C0gEDx8lfZ8wzkSgjqmTMe/9j1UhfFyVkp/YwvW0m4 wdeQpGgl57TbG6/atdbIo6vAb7JuVxV3tVW4R8VyOfQhXXBe53wIp3Vqxo+Di1MxTr2P2x71CLU0 ZCBEygIiSQiUZzDwNCdaCko5Om97tKRax65scKdSb+lloVrzJmtnm+Cmmc98R+cz23P5rivCYVDX z9Hev9vb1iIu0uloLLsLkwV37RUXgbv94x/UJ0H5EJcX/BBKCOt7mkngUVtCcU4BV0aC0CossZVY GH0GxUoomcXulOmYXRZp7Xs89OBkMnEParcRNd3YZ4vHzdLF9emIPUdMey8t/nTYsnVzPNhHi5ci qdan4+XFkRDChLAPkbhRhFtYjnsY0nKICClQmGpgBefYMmOJD8+Q+LGazHkpmQvXke7PcNBOo6n2 sm/17+auZ5pNGBXFbIQKMxrn45g9y27e3tjddms7kxeewFXUGLnOxYkIxPxjIoaYUFz5APuwHB1o OT9IKiTgmkiNLYSInxOJkigxWXFqdMwuizTeF41ogwRCSZK4u2CVrft5z63NujMJbv2iP3gK1rWw cIHfY3nn2+1jbam/D4Z5zi+OxAQVr/Pdl3//B0z/kIQ5DQAA [root@krolik mikrodash]# gzip -c settings.json | base64 H4sICMC2CWoAA3NldHRpbmdzLmpzb24AZZJPc9owEMXv+RSMz4XaTuLYnemhgaZxC0wG1DY9ru31 n0FIHkmGMJ1+90rYxnIYLub3Vm9X+/T3ZjJxBG8UimculfNp4niRP/OCcBaGM8/5MOgvXBg9fPAj ixIqNVSiwTGMmcS0EajFHKi01Z8ShWkE2b5iow4gjZnTsgxzaKiKc4NQlSi6cTKQZe+RN6JiO2CD 0pusYL7lJP7ms+3qDdz4B/efBQnm63IHyz+nuvZO89dN9J08gjqo+uMxL55IrDbr17vPrVtdseIr g4RiZl/RYAKiwHZbs/OvO8EpnXPGzAD3ruteIAG6Q2HwrY0fgWXHKlPl+/qN3oduo7HnXjgUOPBh HF2+PUmFe0192+R3JZCi7LsOwq+ajZ01e9LFR6D0/SRxLhWo5upGcQ4pGhqMbF7a6UalX0R9NcKi TOv+cEsVr9fmZP+nW9nA8m5C0hZ6LT3UbKFTJ/bpPbz1KfgX/7KSiovTqmL6qbU7OXOgKNS8bkgp UJacmqwjSzI3WvLzFr3OSnC5wKQpRm8bUlUdzgGhiI2JEwQPeejfRlNM77PpXRa50yTUX0kSoBsm URT46FyitdIastU8ZtqwX/ZI6XY4Ym20I2RWgXo4zq4crNBHfMmLq1r7rRrh5t9/S/dElzwEAAA=
gitea
nginx configs
/etc/nginx/conf.d/almalinux.conf
server {
listen 80;
listen [::]:80;
server_name mirror.thighhighs.top;
root /usr/share/nginx/html;
location /almalinux/mirrorlist {
alias /persist/almalinux_mirrorlists ;
autoindex on;
}
location /almalinux {
alias /persist/almalinux_repos ;
autoindex on;
}
"/etc/nginx/conf.d/gitea.conf"
server {
listen 80;
listen [::]:80;
server_name git.thighhighs.top;
root /usr/share/nginx/html;
location / {
client_max_body_size 512M;
proxy_pass http://localhost:3000;
proxy_set_header Connection $http_connection;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}Run gitea as a service:
"gitea.service"
# THIS FILE IS MANAGED BY ANSIBLE. MANUAL CHANGES MAY BE DESTROYED.
# vim: syntax=systemd
[Unit]
Description=containerised Gitea
After=docker.service persist-gitea.mount
Requires=docker.service persist-gitea.mount
[Service]
Environment=USER_UID=2000
Environment=USER_GID=2000
Environment=HTTP_PORT=3000
Environment=SSH_PORT=2222
Environment='GITEA_IMAGE=docker.io/gitea/gitea:1.23.4'
ExecStart=docker run --rm --name="gitea" -e USER_UID=${USER_UID} -e USER_GID=${USER_GID} -p ${HTTP_PORT}:3000 -p ${SSH_PORT}:22 -v /persist/gitea/data:/data -v /etc/timezone:/etc/timezone:ro -v /etc/localtime:/etc/localtime:ro ${GITEA_IMAGE}
Restart=on-failure
RestartSec=10s
[Install]
WantedBy=multi-user.targetAnd filesystem mounts:
"persist-almalinux_repos.mount" [Unit] Description=Filesystem for Almalinux dnf repos Requires=iscsi.service [Mount] What=/dev/disk/by-uuid/7f55bc8f-ebd1-4159-8572-6332539f7f13 Where=/persist/almalinux_repos Type=xfs Options=noatime,_netdev TimeoutSec=20 [Install] WantedBy=default.target "persist-gitea.mount" [Unit] Description=Filesystem for gitea data Requires=iscsi.service [Mount] What=/dev/disk/by-uuid/c1ef0078-ed22-4a08-9e5b-24aa5b815d5e Where=/persist/gitea Type=xfs Options=noatime,_netdev TimeoutSec=20 [Install] WantedBy=default.target
Local almalinux mirror
sync-alma-mirror-from-upstream.service # THIS FILE IS MANAGED BY ANSIBLE. MANUAL CHANGES MAY BE DESTROYED. # vim: syntax=systemd [Unit] Description=rsync the AlmaLinux package mirror After=persist-almalinux_repos.mount Requires=persist-almalinux_repos.mount [Service] Type=oneshot Nice=19 IOSchedulingClass=2 IOSchedulingPriority=7 ExecStart=/usr/bin/rsync -rlptvSH --bwlimit=80m --exclude=.~tmp~ --delete-delay --delay-updates rsync://rsync.repo.almalinux.org/almalinux/ /persist/almalinux_repos/ Restart=on-failure RestartSec=5min "sync-alma-mirror-from-upstream.timer" # THIS FILE IS MANAGED BY ANSIBLE. MANUAL CHANGES MAY BE DESTROYED. # vim: syntax=systemd [Unit] Description=AlmaLinux repo rsync Requires=persist-almalinux_repos.mount After=persist-almalinux_repos.mount [Timer] OnBootSec=30min OnUnitInactiveSec=13h RandomizedDelaySec=10m [Install] WantedBy=timers.target
[root@krolik system]# base64 /persist/mirrorlists.tar.gz H4sIAAAAAAAAA+3X3WqDMBwFcK/3FF702nyoCdvd9gK96AOMbMgUdAlJCj7+or0YK5vWLjhmzw+K YgPRnv+BairrGueJajvVNu/H/rlrrNW2DRcdSaKggSzL8RicH8dzVshCMh6WhXWslDlL0jLO9tOO ziubponV2k+tm/v+nzKT+d9nZYQZuDz/nHIZrjPBc4r81zCfvzLGeVupLvP9db/AELAoih/zZzT/ mj8P4yKTlEZ+1m/deP619+aBkFPoma+bt3r4uMxr8zkU4yA8GnMYB4HsXpSrlH2tiXbk7q8fAX5h vv9D1tpdXf7kkv7T8/7zvED/17Cg/09hEPYHlH9T5vtf9d6q1fsvBPq/hgX9Pw0C+r8pM/2Pssf4 /iflgvd/wYf//zxMXZQbmHLj/QcAAAAAAAAAAACAbfoAVea3QwAoAAA=
ansible is done, now setup nginx with it to serve the repo
iscsi notes
basti attaches iscsi LUNs from fenny so it doesn't need much local storage.
[root@krolik iscsi]# tree . ├── ifaces ├── isns ├── nodes │ └── iqn.2011-08.com.asustor:fs6812x-437849.krolik │ └── 192.168.32.18,3260,1 │ └── default ├── send_targets │ └── fenny.thighhighs.top,3260 │ ├── iqn.2011-08.com.asustor:fs6812x-437849.krolik,192.168.32.18,3260,1,default -> /var/lib/iscsi/nodes/iqn.2011-08.com.asustor:fs6812x-437849.krolik/192.168.32.18,3260,1 │ └── st_config ├── slp └── static [root@basti ~]# iscsiadm -m discovery -t sendtargets -p fenny.thighhighs.top 192.168.32.18:3260,1 iqn.2011-08.com.asustor:fs6812x-437849..basti [root@basti ~]# iscsiadm -m node -T iqn.2011-08.com.asustor:fs6812x-437849..basti -l Login to [iface: default, target: iqn.2011-08.com.asustor:fs6812x-437849..basti, portal: 192.168.32.18,3260] successful. [root@basti ~]# lsscsi [1:0:0:0] disk ATA NGFF 2280 512GB 3A0 /dev/sda [2:0:0:0] disk ASUSTOR iSCSI Storage 380 /dev/sdb [2:0:0:1] disk ASUSTOR iSCSI Storage 380 /dev/sdc [root@basti ~]# iscsiadm -m node -L automatic