HTTP and websocket on the same port and domain behind reverse proxy
I wanted to try Node-Red and have installed it on my Ubuntu server. This server runs an apache reverse proxy but I can't get it to work right. If I create a virtualhost for the HTTP connection I can access my Node-Red interface just fine, but it doesn't show me any activity such as online MQTT servers or debug messages. After some googling I found out this is because it also uses websockets and those ha ...

Jenkinsfile - Build only if change in a specific subdirectory, how to manage post action
Basically, we're doing trunk development here, and got tons of services under the same directory.

I have a Jenkins job that is triggered through GitHub webhook, and that will do some actions only if there's a change in a specific directory of that repo :

pipeline {
        agent any
        stages {
                stage('Building') {
                when { changeset "subdirectory/*"}
Active Directory Users and Computers delegated user cannot create user accounts
Windows Server 2016 Active Directory under an Organizational Unit (OU), I created a user which was delegated control to be able to create, delete and manage users, and passwords.

I logged in with this user account, but the options is missing, for example NEW TAB where one can create new users, OU's, printers etc.

If I supply administrator credentials, still signed in as this same user, I can create  ...

Transfer 200GB from client using Google Cloud
I have a client who wishes to transfer 200GB of sensitive data to us. I would like them to upload this data to a GCloud bucket.

What is the best way to set up an external user to have access to a single new bucket and be able to upload?

Open VSwitch - Connect two virtual networks through two physical networks
I managed to setup the following network configuration :


  • HOST1 and HOST2 are two physical machines running Debian OS.
  • They have both two network cards (eth0 and eth1), each of them connected to two physically separated network and with different subnets.
  • OVS BR1 is an open vswitch bridge (one in each host)
  • VMx are virtual machines using vethvmx ovs port in the bridge of the host machine.
  • OVS BR1 are co ...
Nginx Pagespeed Module: What is "Ngx_pagespeed Slow write operation on file /usr/share/nginx/ngx_pagespeed_cache..." in error logs and how to fix?
I am running an Ubuntu 20.04 LEMP server with the pagespeed module for Nginx in a business environment. In my /var/log/nginx/error.log I am seeing the following error:

[ngx_pagespeed] Slow write operation on file /usr/share/nginx/ngx_pagespeed_cache/v3/,3A/,,.tempqfKyZe: 61.512ms; configure SlowFileLatencyUs ...
Can I use OpenStack Rocky with a neoverse-n1?
Situation: For now, I'm stuck on OpenStack Rocky on Ubuntu 18.04.6 and I have some beefy Neoverse-n1 hardware (aarch64, 64-core, 1TB memory) to integrate. Can I accomplish this with on my current OS cluster, or is this futile?

# qemu-system-aarch64 --version
QEMU emulator version 2.11.1(Debian 1:2.11+dfsg-1ubuntu7.41)
Copyright (c) 2003-2017 Fabrice Bellard and the QEMU Project developers
# virsh --versi ...
Issue with SoftEther VPN Server / Client
We have to Locations, Germany and Sweden. We are Trying to Join AD Domains Together. The Software we are Using is SoftEther VPN Server and VPN Client. One is Windows Server 2012 Std (No R2) for Resources until September and the other is 2022 21H2. If we connect the Two Together. We receive a Timeout. I've Already Checked the Firewall. No Results. Image is from Germany (Main Location). Cascade is not an  ...

Linux netfilter NAT based on SNI?
I am trying to do SNI proxying to a subnet on a router while keeping the src IP.

Background: I have a router doing DNAT to do port-forwarding for many application ports, and it is connected to a subnet (using a VPN actually) with different backends. For protocols that do NOT have something like HTTP Host or TLS SNI that can be routed to different IPs based on the request, I simply uses DNAT with  ...

port forward with openVPN to access local machine remotely
I have an OpenVPN server set up on my AWS Linux instance and I can successfully use the OpenVPN client to connect to the server using an .ovpn configuration file. My question is how can I set up port forwarding to access web servers hosted on my local machine using myAwsPublicIp:openedPort without having to set up forwarding rules on my router. I already tried opening the port on my AWS firewall r ...

AWX SSH connection not establishing when running playbook
I am trying to run my first playbook. Running AWX on CentOS8,trying to connect to remote device using SSH. On my remote device I have run ssh-genkey on my device and added the .pub key to authorized_keys file. I have also taken the .pub private key and created a credentials machine type and added the private key. Username and password are blank. I can only connect using root user to my remote device ent ...

PROXMOX multiport NIC, multiple /24 private networks, multiple VMs; networking setup
I am trying to get networking setup on my proxmox server and have the following setup:

vmbr0: gw:
bridged to eno1
2 VMs on this network:

vmbr1: gw: none
bridged to eno4
1 VM on this network

I can ping/surf from machines setup on the vmbr0 network.

I can ping the router from vmb ...

Nginx error logs: what does "pagespeed: rollback gzip, explicit configuration in /etc/nginx/nginx.conf:151" mean, and how can I fix it to use brotli?
I am running an Ubuntu 20.04 LEMP server with the pagespeed and brotli module for Nginx. In my /var/log/nginx/error.log I am seeing the following error:

2023/02/23 07:34:49 [info] 1553667#1553667: [ngx_pagespeed] No threading detected. Own threads: 1 Rewrite, 1 Expensive Rewrite.
2023/02/23 07:34:49 [info] 1553667#1553667: pagespeed: rollback gzip, explicit configuration in /etc/nginx/nginx. ...
How to manage app versions with AWS ElasticBeanstalk Docker platform
So I have successfully launched an app and an environment in AWS ElasticBeanstalk, using private image repository. I can build and push new versions of my app to the repository, and then run eb deploy to have it pull and update the EC2 instances. Great!

But how can I manage versions? What if I want to rollback to some previous version of the app? In the current setup there's only really one image in the ...

Cloud-init installing packages on Debian with contrib sources
I need to install some zfs packages on Debian instances using cloud-init. One of the packages needs the contrib sources. I can get it to update the sources list, but the packages fail to install. If I remove the contrib source lists, some packages install, just not the ones that need contrib. Kind of a catch 22. Has anyone had success installing zfs and all prerequisites using cloud-init?

Here  ...

Nginx reverse proxy only specific sub directory and pass through everything else
I have development situation where i have a domain with multiple services:

On this service there are multiple project as subdirectories

  • <- landing page
  • <- rest api server
  • <- my app

So is it possible (and how) to setup nginx and hosts file to reverse proxy only ...

Normal traffic stalls, wireguard traffic through same server works fine
I have a weird networking issue, possibly due to problems at my ISP or with my router (an Eero 6), which manifests itself in the following way. On a machine X connected by wire to the router R, requests to certain web sites stall (sometimes the ssh handshake completes, sometimes not, but it always stops there).

This machine X also acts as a wireguard server, and the router R forwards connections  ...

Does Nginx aio work with linux?
We have a VOD service and we are using nginx as webserver.

Our system doesn't use nginx-vod-module instead it just has all the small m4s files for a dash stream.

I came across this article(Thread Pools in NGINX Boost Performance 9x) by Valentin Bartenev.

It says that enabling aio in nginx might be a good solution for reducing io wait and load.

but it says:

A good example here is FreeBSD. Unfortuna ...

what the meaning of "logpath = %(nginx_error_log)s" in fail2ban jail log path?
I am running fail2ban on Ubuntu 20.04 server, and am looking over some of the default jails. In [nginx-http-auth] the default log path shows as logpath = %(nginx_error_log)s. What exactly does %(nginx_error_log)s mean in fail2ban, and how does it articulate a log path for nginx logs in fail2ban? The same question goes for the default [sshd] jail log path and backend which has:

logpath = %(sshd_log)s ...
CSF has port 22 listed for TCP_IN, what is blocking certain IPs?
I went through my whole csf config, and unless I'm missing something it's not treated or listed any differently than port 80, although it blocks all IPs that are not white listed. Port 80 will allow any IP address regardless.

Is blocking IPs for port 22 hardcoded into csf? I'm trying to understand. I've read that CSF blocks everything by default, but then how is port 80 open to every IP without s ...

Impact of KrbTgtFullPAC Signature (CVE-2022-37967) patches
I am a bit concerned about the Windows November 2022 patches that introduced signing of the PAC-Field in Kerberostickets.

  1. There is a RegKey(“KrbtgtFullPacSignature”) that, if set to auditmode, accept and log all unsigned tickets. Since January, we have enabled this key on all of our DCs, but nothing is logged on our DCs, even though we have some Server 2008 and Windows 7 systems, which should not ...
How to ssh through the gitlab subdomain URL
From this question I'd like to ask more of it

Solved the problem that I need to open the port on the cloud service. Now the next problem is how do I clone using the URL instead of the host machine IP. Example :

ssh git@x.x.x.x -p 6022

x.x.x.x is the hos ...

GCP: Api Gateway failing to redirect to an url made from a private dns
I have a vm instance at IP I created two url representing this service by two different ways, and I inject it in the Gateway configuration file. is a url created by service. Given an IP, you get a public url is a url made from a DNS Zone, with A -> The good IP

The gateway works perfectly with the public nip addres ...

aws efs describe-access-points no filters?
When I run

aws efs describe-access-points --query 'AccessPoints[*].[AccessPointId]' --output table

I get back 5 different ID's.

There does not appear to be any filter options like there are for other resources.

aws efs describe-access-points --filters "Name=AccessPoints.Name,Values=media" --query 'AccessPoints[*].[AccessPointId]' --output table

usage: aws [options] <command> <subcommand&gt ...
Why does Terraform want to fully delete aws_iam_policy_document?
I don't understand why Terraform wants to remove the json policy. In other cases, when the data will be read during the apply, the plan shows the json policy being removed and added in the same plan, but it is not happening, Terraform is just removing it.

This is the policy:

data "aws_iam_policy_document" "my_policy" {
  statement {
    sid = "S3"
    effect = "Allow"
    actions = ["s3:*"]
    resour ...
STONITH Block Device daemon (SBD) actions based on conditions
Is there any detailed description how SBD reacts to various conditions/issues? sbd(8) is not very detailed I would say. I can't read the source which is here:

AH01114: HTTP: failed to make connection to backend: localhost
I know some of you might think that its a little bit off topic here, but am not sure whether its fault of server OR fault of my config file, so...

I made React.js project , but it needs server side rendering, So now I have to migrate from CRA to next.js . the problem: I have to upload my website on apache web server, from what I gathered from google, I need installed node.js and pm2 (latest versi ...

React App with Nginx reverse proxy not displaying /swagger ; /redoc
So I've been trying to set up Swagger to work on /swagger/, it was working fine until we switched to a domain. I'm not that experienced with nginx and it's reverse proxy. I will share my settings, if anyone could help. It actually opens the page, but it's all white, same goes with /redoc/ (Redis).


events {
worker_connections 768;
multi_accept       on;

http {

large_client_header_buffers ...
HDP cluster + journal nodes get out of Sync
we have HDP cluster version 2.6.5

when we look on name-node logs we can see the following warning

2023-02-20 15:56:37,731 INFO  namenode.FileJournalManager ( - Finalizing edits file /hadoop/hdfs/journal/hdfsha/current/edits_inprogress_0000000193594484455 -> /hadoop/hdfs/journal/hdfsha/current/edits_0000000193594484455-0000000193594600017
2023-02-20 ...
ssh server show message after login successful
I have one debian ssh server question , I want to display a message after successful login I have used motd, but the localhost will display it. I don’t want the local machine to display it. I only want to display it after a specific user successfully logs in to ssh.

