Add authentication to applications and secure services with minimum fuss. No need to deal with storing users or authenticating users. It's all available out of the box.
You'll even get advanced features such as User Federation, Identity Brokering and Social Login.
For more details go to about and documentation, and don't forget to try Keycloak. It's easy by design!
Setting up and bootstrapping the zone catalog feature. The requierments are:
- a running knot dns server verion >= 3.0
- configured remote, acl and key sections for a primary/secondary zone transfer setup
Assumptions:
- nsp.domain.tld is the primary nameserver.
- ns1.domain.tld is the secondary nameserver
- There exist valid remote, acl and key configurations for this hosts on the other side
- special catalog zone is name "zone.catalog"
-
Create a zone template for the zones, which will be created on this zone catalog feature
- For the primary nameserver:
- id: "catalog-zone-template"
...
notify: ns1
acl: ns1
...- For the secondary nameserver:
- id: "catalog-zone-template"
...
notify: nsp
acl: nsp
... -
Create the special catalog zone for this feature
- For the primary nameserver:
zone:
- domain: "zone.catalog."
...
notify: ns1
acl: ns1
catalog-role: "interpret"
catalog-template: "catalog-zone-template"- For the secondary nameserver:
zone:
- domain: "zone.catalog."
...
notify: nsp
acl: nsp
catalog-role: "interpret"
catalog-template: "catalog-zone-template" -
Create the content for the special catalog zone. We need to have at least a SOA, NS and TXT resource record:
cat<<EOT | su -c "/usr/bin/knotc" knot
zone-begin zone.catalog
zone-set zone.catalog @ 60 NS nsp.REDACTED.DOM.
zone-set zone.catalog @ 60 SOA nsp.REDACTED.DOM. hostmaster.REDACTED.DOM. 1 16384 2048 1048576 2560
zone-set zone.catalog version 0 TXT "2"
zone-commit zone.catalog
EOT -
Create on the primary nameserver member zone in the special catalog zone.
- Create an unique id for the first member zone:
ZUID="id-$RANDOM-$RANDOM" # generate a random id string
# ZUID="id-$(pwgen -AB 8 1)" # or other method of generating a random id string- And create this zone with the knotc command as user knot:
NEWDOMAIN="my-first-domain.invalid"
cat<<EOT | su -c "/usr/bin/knotc" knot
zone-begin zone.catalog
zone-set zone.catalog id-${ZUID}.zones 0 IN PTR ${NEWDOMAIN%.}.
zone-commit zone.catalog
EOT- The easy thing to oversee is ".zones" part in the in the PTR resource record.
-
Last step: Setup the new domain content.
NEWDOMAIN="my-first-domain.invalid"
cat<<EOZ | su -c /usr/bin/knotc knot
zone-begin ${NEWDOMAIN%.}
zone-set ${NEWDOMAIN%.} @ 60 SOA nshp.REDACTED.DOM. hostmaster.REDACTED.DOM. 1 16384 2048 1048576 2560
zone-set ${NEWDOMAIN%.} @ 60 NS nshp.REDACTED.DOM.
zone-commit ${NEWDOMAIN%.}
EOZ -
Check this new domain content on your secondary nameserver:
NEWDOMAIN="my-first-domain.invalid"
su -c "/usr/bin/knotc zone-read ${NEWDOMAIN%.}." knot
The Pigeonhole project provides Sieve support as a plugin for Dovecot's Local Delivery Agent (LDA) and also for its LMTP service. The plugin implements a Sieve interpreter, which filters incoming messages using a script specified in the Sieve language (RFC 5228). The Sieve script is provided by the user and, using that Sieve script, the user can customize how incoming messages are handled. Messages can be delivered to specific folders, forwarded, rejected, discarded, etc.
Heute läuft der Server mit Ubuntu 20.04. Darauf laufen keine LXC/LXD Container mehr. Stattdessen läuft jetzt Kubernetes darauf. Zu Beginn nutzte ich für die Installation von Kubernetes Kubespray ein, das Standard-Kubernetes war allerdings deutlich zu fett. Größtes Manko war, dass das etcd verdammt viel auf die SSD geschrieben hat und ich regelmäßig bei jedem Upgrade das Setup kaputt gespielt habe. Für den Privatgebrauch ergab das so daher keinen Sinn.
Mittlerweile setze ich auf das vergleichsweise schlanke k3s.io. Das braucht im Heimbetrieb deutlich weniger Leistung und erledigt trotzdem das, was ich brauche. Statt etcd setzt es auf sqlite und statt Docker auf containerd.
Wayland is the next-generation display server for Unix-like systems, designed and built by the alumni of the venerable Xorg server, and is the best way to get your application windows onto your user's screens. Readers who have worked with X11 in the past will be pleasantly surprised by Wayland's improvements, and those who are new to graphics on Unix will find it a flexible and powerful system for building graphical applications and desktops.
This book will help you establish a firm understanding of the concepts, design, and implementation of Wayland, and equip you with the tools to build your own Wayland client and server applications. Over the course of your reading, we'll build a mental model of Wayland and establish the rationale that went into its design. Within these pages you should find many "aha!" moments as the intuitive design choices of Wayland become clear, which should help to keep the pages turning. Welcome to the future of open source graphics!
Notice: this is a draft. Chapters 1-10 are more or less complete, but may be updated later. Chapters 11 forward in large part remain to be written.
TODO
- Expand on resource lifetimes and avoiding race conditions in chapter 2.4
- Move linux-dmabuf details to the appendix, add note about wl_drm & mesa
- Rewrite the introduction text
- Add example code for interactive move, to demonstrate the use of serials
- Use — instead of - where appropriate
- Prepare PDFs and EPUBs
Mit ein paar kleinen Eingriffen in die Jitsi-Meet-Konfiguration könnt ihr die Leistung optimieren. Insbesondere Video-Konferenzen mit mehreren Teilnehmern profitieren von den Einstellungen.
Öffnet dazu die config.js-Datei von Jitsi Meet:
Like many people, I recently have been re-discovering the XMPP messaging protocol and ended up running my own server. In fact, this blog is essentially a result of that effort, though it functions independently from the XMPP service.
Repository with copies of my XMPP server configuration for public interest / investigation.
Notes on this setup
- Database backend: PostgreSQL
- Admin web interface and API are disabled
- In-Band registration and web registration are enabled
- Captchas enabled
- Nginx is used as HTTP / Websocket Proxy
- Port 5223 used as TLS port for "XMPP over TLS" feature (Port 443 is forwarded to 5223)
YunoHost is a server operating system aiming to make self-hosting accessible to everyone. • YunoHost
YunoHost is a server operating system aiming to make self-hosting accessible to everyone.
Algo VPN is a set of Ansible scripts that simplify the setup of a personal IPSEC and Wireguard VPN. It uses the most secure defaults available, works with common cloud providers, and does not require client software on most devices. See our release announcement for more information.
Because The join domain account is often visible in your deployment answer file (unattend.xml of sysprep.inf) during the WinPE phase, it is important that this specific account does not have any more permission, than the bare minimum.. I often experience that a domain admin account is used for this job, which is a huge security breach. When i ask why this is, the answer is normally “ we can not find the information on how to create an account with only join domain rights”.
Warning: This post is long. While working through this massive server upgrade/migration process, tears were shed, many cuss words were said, along with a general feeling of frustration, which ultimately culminated into extreme happiness once the migration was completed. The scale and complexity of the implementation factor into the length of this post, and I’ll share my thought process on how this was executed, so here goes.
Quassel IRC is a modern, cross-platform, distributed IRC client, meaning that one (or multiple) client(s) can attach to and detach from a central core -- much like the popular combination of screen and a text-based IRC client such as WeeChat, but graphical. In addition to this unique feature, we aim to bring a pleasurable, comfortable chatting experience to all major platforms (including Linux®, Windows®, and MacOS X® as well as Android smartphones), making communication with your peers not only convenient, but also ubiquitous available.
And the best of all: It's free - as in beer and as in speech, since we distribute Quassel under the GPL, and you are welcome to download and see for yourself!
The self-hosted web IRC client
Always connected.
Pleroma is a free, federated social networking server built on open protocols. It is compatible with GNU Social, Mastodon, and many other ActivityPub and OStatus implementations.
The project consists of several components: Pleroma is the server implementation, and comes bundled with PleromaFE, the default frontend. Other useful utilities are also provided, such as an ActivityPub relay.
We use PostgreSQL extensively at Braintree, and it backs many of our highly available services (including our main payments API).
We are constantly building and refining our products, and this often means evolving our database schema. In general, PostgreSQL is great at this, and we can make many different types of schema changes without downtime. There are some gotchas, however, that this post will cover.
We’ve spent the last two years automating and improving our migration process to address key issues we were having — manual intervention, backwards compatibility, correctness, and performance. This post dives into the problems we ran into and highlights some learnings and tools we made along the way.