<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Technical — LowEndSpirit</title>
        <link>https://staging.lowendspirit.com/index.php?p=/</link>
        <pubDate>Mon, 20 Jul 2026 21:06:06 +0000</pubDate>
        <language>en</language>
            <description>Technical — LowEndSpirit</description>
    <atom:link href="https://staging.lowendspirit.com/index.php?p=/categories/technical/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>Post some YABS bench here</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/592/post-some-yabs-bench-here</link>
        <pubDate>Fri, 07 Feb 2020 12:25:41 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>cybertech</dc:creator>
        <guid isPermaLink="false">592@/index.php?p=/discussions</guid>
        <description><![CDATA[<p></p><div>

<h1><strong>Welcome to OCD Benchmarking Thread</strong></h1>

<p><em>Only in here, benchmark walks. The rest is talk.</em><br />
</p></div>

<hr />

<p>When sharing/posting YABS results, please use the proper code tag/formatting (&#96;&#96;) just so that the results are displayed neatly.</p>

<p>In addition to the above, it would be very much appreciated if you were to include details such as the Provider, Plan, Location and Price. Other details like date of purchase can be included as well, or just indicate if it's a deal bought on a special occasion, i.e., Black Friday, Cyber Monday, Independence Day etc.</p>

<p>If you're posting results of a custom built machine, or something locally of your own, it would be nice if you could share details of your build and/or hardware - just to serve as an "FYI" for the community members.</p>

<p>Here's an example of the format you can use to share your YABS results:</p>

<div>  <p>ShockHosting SSD-KVM-2GB - Piscataway NJ US - $29.99/year (4th of July Deal)</p>

<pre><code># ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
#              Yet-Another-Bench-Script              #
#                     v2022-06-11                    #
# https://github.com/masonr/yet-another-bench-script #
# ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #

Mon 04 Jul 2022 04:28:07 PM EDT

Basic System Information:
---------------------------------
Uptime     : 0 days, 0 hours, 6 minutes
Processor  : Intel(R) Xeon(R) Gold 5315Y CPU @ 3.20GHz
CPU cores  : 1 @ 3199.998 MHz
AES-NI     : ✔ Enabled
VM-x/AMD-V : ✔ Enabled
RAM        : 1.9 GiB
Swap       : 975.0 MiB
Disk       : 28.4 GiB
Distro     : Debian GNU/Linux 11 (bullseye)
Kernel     : 5.10.0-15-amd64

fio Disk Speed Tests (Mixed R/W 50/50):
---------------------------------
Block Size | 4k            (IOPS) | 64k           (IOPS)
  ------   | ---            ----  | ----           ----
Read       | 264.91 MB/s  (66.2k) | 3.46 GB/s    (54.1k)
Write      | 265.61 MB/s  (66.4k) | 3.48 GB/s    (54.4k)
Total      | 530.52 MB/s (132.6k) | 6.95 GB/s   (108.6k)
           |                      |
Block Size | 512k          (IOPS) | 1m            (IOPS)
  ------   | ---            ----  | ----           ----
Read       | 9.32 GB/s    (18.2k) | 7.95 GB/s     (7.7k)
Write      | 9.82 GB/s    (19.1k) | 8.48 GB/s     (8.2k)
Total      | 19.15 GB/s   (37.4k) | 16.44 GB/s   (16.0k)

iperf3 Network Speed Tests (IPv4):
---------------------------------
Provider        | Location (Link)           | Send Speed      | Recv Speed
                |                           |                 |
Clouvider       | London, UK (10G)          | 828 Mbits/sec   | 469 Mbits/sec
Online.net      | Paris, FR (10G)           | 882 Mbits/sec   | 262 Mbits/sec
Hybula          | The Netherlands (40G)     | 882 Mbits/sec   | 823 Mbits/sec
Uztelecom       | Tashkent, UZ (10G)        | 577 Mbits/sec   | 307 Mbits/sec
Clouvider       | NYC, NY, US (10G)         | 940 Mbits/sec   | 939 Mbits/sec
Clouvider       | Dallas, TX, US (10G)      | 746 Mbits/sec   | 155 Mbits/sec
Clouvider       | Los Angeles, CA, US (10G) | 796 Mbits/sec   | 619 Mbits/sec

iperf3 Network Speed Tests (IPv6):
---------------------------------
Provider        | Location (Link)           | Send Speed      | Recv Speed
                |                           |                 |
Clouvider       | London, UK (10G)          | 705 Mbits/sec   | 435 Mbits/sec
Online.net      | Paris, FR (10G)           | 823 Mbits/sec   | 431 Mbits/sec
Hybula          | The Netherlands (40G)     | 714 Mbits/sec   | 725 Mbits/sec
Uztelecom       | Tashkent, UZ (10G)        | 676 Mbits/sec   | 410 Mbits/sec
Clouvider       | NYC, NY, US (10G)         | 926 Mbits/sec   | 926 Mbits/sec
Clouvider       | Dallas, TX, US (10G)      | 904 Mbits/sec   | 775 Mbits/sec
Clouvider       | Los Angeles, CA, US (10G) | 885 Mbits/sec   | 632 Mbits/sec

Geekbench 5 Benchmark Test:
---------------------------------
Test            | Value
                |
Single Core     | 1036
Multi Core      | 1005
Full Test       | https://browser.geekbench.com/v5/cpu/15825267
</code></pre></div>

<p>Thank you and happy YABS-ing! <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/heart.png" title="&lt;3" alt="&lt;3" height="18" /></p>

<p></p><hr />
]]>
        </description>
    </item>
    <item>
        <title>Comprehensive Speedtest Script | network-speed.xyz | Share your bench</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5812/comprehensive-speedtest-script-network-speed-xyz-share-your-bench</link>
        <pubDate>Wed, 26 Apr 2023 20:05:36 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>sh97</dc:creator>
        <guid isPermaLink="false">5812@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Hi All,<br />
I present to you yet another damn speed test script. I understand there are many speed test scripts out there, but ... well I did it anyway. I've been working on this for a couple of months now and feel it is ready for public use now.<br />
I built this on top of Teddysuns bench.sh - adding my code and removing unnecessary stuff.</p>

<p>All information can be found on <a rel="nofollow" href="https://network-speed.xyz/" title="https://network-speed.xyz/">https://network-speed.xyz/</a></p>

<p><strong>Test Locations</strong><br />
* North America<br />
* South America<br />
* Europe<br />
* Asia<br />
* Africa<br />
* GCC Middle East<br />
* India<br />
* China<br />
* Iran<br />
* More coming soon!</p>

<p><strong>Usage</strong><br />
For Global Test</p>

<pre><code>wget -qO- network-speed.xyz | bash
</code></pre>

<p>For Regional Test</p>

<pre><code>curl -sL network-speed.xyz | bash -s -- -r region_name
</code></pre>

<p>region_name = na, sa, eu, asia, Africa, middle-east, india, china, iran</p>

<p><strong>Global Test Sample Output</strong></p>

<pre><code>---------------------------- network-speed.xyz ----------------------------
      A simple script to test network performance using speedtest-cli
---------------------------------------------------------------------------
 Version            : v2023.04.25
 Global Speedtest   : wget -qO- network-speed.xyz | bash
 Region Speedtest   : wget -qO- network-speed.xyz | bash -s -- -r &lt;region&gt;
---------------------------------------------------------------------------
 Basic System Info
---------------------------------------------------------------------------
 CPU Model          : AMD Ryzen 9 3900X 12-Core Processor
 CPU Cores          : 1 @ 3800.000 MHz
 CPU Cache          : 512 KB
 AES-NI             : ✔ Enabled
 VM-x/AMD-V         : ✔ Enabled
 Total Disk         : 24.3 GB (6.9 GB Used)
 Total RAM          : 1.1 GB (210.2 MB Used)
 System uptime      : 4 days, 12 hour 38 min
 Load average       : 0.07, 0.04, 0.03
 OS                 : Ubuntu 20.04.6 LTS
 Arch               : x86_64 (64 Bit)
 Kernel             : 5.4.0-147-generic
 Virtualization     : KVM
---------------------------------------------------------------------------
 Basic Network Info
---------------------------------------------------------------------------
 Primary Network    : IPv4
 ISP                : Alibaba.com LLC
 ASN                : AS35913 DediPath
 Host               : Zenlayer Inc, Virtual Machine Solutions LLC
 Location           : Seattle, Washington-WA, United States
---------------------------------------------------------------------------
 Speedtest.net (Region: GLOBAL)
---------------------------------------------------------------------------
 Location         Latency     Loss    DL Speed       UP Speed       Server

 ISP: DediPath

 Nearest          39.10 ms    0.0%    874.86 Mbps    773.67 Mbps    Ideatek Telcom - Wichita, KS

 Kochi, IN        279.63 ms   0.0%    505.94 Mbps    252.15 Mbps    Asianet Broadband - Cochin
 Bangalore, IN    251.37 ms   0.3%    645.52 Mbps    269.74 Mbps    Bharti Airtel Ltd - Bangalore
 Chennai, IN      230.78 ms   N/A     551.27 Mbps    354.59 Mbps    Jio - Chennai
 Mumbai, IN       289.37 ms   0.3%    366.12 Mbps    116.30 Mbps    i3D.net - Mumbai
 Delhi, IN        267.42 ms   0.0%    596.24 Mbps    159.85 Mbps    Tata Play Fiber - New Delhi

 Los Angeles, US  28.41 ms    0.0%    884.35 Mbps    533.28 Mbps    ReliableSite Hosting - Los Angeles, CA
 Dallas, US       53.31 ms    0.0%    774.85 Mbps    452.48 Mbps    Hivelocity - Dallas, TX
 New York, US     80.01 ms    0.0%    315.54 Mbps    797.42 Mbps    Clouvider Ltd - New York, NY
 Seattle, US      2.37 ms     N/A     938.03 Mbps    935.63 Mbps    Comcast - Seattle, WA
 Miami, US        89.86 ms    0.0%    823.65 Mbps    660.29 Mbps    AT&amp;T - Miami, FL
 Toronto, CA      66.14 ms    0.0%    724.23 Mbps    618.85 Mbps    Rogers - Toronto, ON

 Paris, FR        158.80 ms   0.0%    675.62 Mbps    553.16 Mbps    ORANGE FRANCE - Paris
 Amsterdam, NL    157.07 ms   0.0%    3.55 Mbps      460.41 Mbps    Clouvider Ltd - Amsterdam
 Warsaw, PL       178.59 ms   0.0%    717.62 Mbps    411.57 Mbps    UPC Polska - Warszawa
 London, UK       146.49 ms   0.0%    857.45 Mbps    37.09 Mbps     VeloxServ Communications - London
 Frankfurt, DE    173.11 ms   0.0%    797.18 Mbps    407.43 Mbps    23M GmbH - Frankfurt Am Main

 Dubai, AE        281.79 ms   0.0%    517.34 Mbps    291.43 Mbps    du - Dubai
 Fujairah, AE     247.51 ms   0.0%    543.98 Mbps    296.35 Mbps    ETISALAT-UAE - Fujairah
 Jeddah, KSA      211.72 ms   0.0%    621.52 Mbps    407.56 Mbps    Saudi Telecom Company

 Shanghai, CU-CN  200.57 ms   0.0%    688.99 Mbps    307.36 Mbps    China Unicom 5G - ShangHai
 Nanjing, CT-CN   168.96 ms   0.3%    659.64 Mbps    461.14 Mbps    China Telecom JiangSu 5G - Nanjing
 Hong Kong, HKG   157.84 ms   N/A     787.04 Mbps    297.71 Mbps    STC - Hong Kong
 Singapore, SG    174.90 ms   0.0%    700.25 Mbps    343.45 Mbps    i3D.net - Singapore
 Jakarta, ID      244.22 ms   0.0%    412.39 Mbps    172.91 Mbps    PT Indosat Tbk - Jakarta
 Tokyo, JP        111.60 ms   N/A     645.79 Mbps    433.46 Mbps    fdcservers.net - Tokyo
---------------------------------------------------------------------------
 Avg DL Speed       : 639.57 Mbps
 Avg UL Speed       : 415.59 Mbps

 Total DL Data      : 21.90 GB
 Total UL Data      : 14.15 GB
 Total Data         : 36.05 GB
---------------------------------------------------------------------------
 Duration           : 13 min 5 sec
 System Time        : 27/04/2023 - 01:10:33 IST
 Total Script Runs  : 1063
---------------------------------------------------------------------------
 Result             : https://cdn1.frocdn.ch/JrA3CugVFKYukMj.txt
---------------------------------------------------------------------------
root@us9-virmach-seattle:~#
</code></pre>

<p><strong>Regional Test Sample Output</strong><br />
NA: <a href="https://cdn1.frocdn.ch/o0jvHlZr9cUQSa2.txt" rel="nofollow">https://cdn1.frocdn.ch/o0jvHlZr9cUQSa2.txt</a><br />
SA: <a href="https://cdn1.frocdn.ch/t31SkeDTWhuwbHH.txt" rel="nofollow">https://cdn1.frocdn.ch/t31SkeDTWhuwbHH.txt</a><br />
EU: <a href="https://cdn1.frocdn.ch/UzgzCEzBqFzAOVf.txt" rel="nofollow">https://cdn1.frocdn.ch/UzgzCEzBqFzAOVf.txt</a><br />
Asia: <a href="https://rentry.co/q7qvg" rel="nofollow">https://rentry.co/q7qvg</a><br />
GCC: <a href="https://cdn1.frocdn.ch/5F5jacWigHcsMQu.txt" rel="nofollow">https://cdn1.frocdn.ch/5F5jacWigHcsMQu.txt</a><br />
India: <a href="https://rentry.co/q7qvg" rel="nofollow">https://rentry.co/q7qvg</a><br />
China: <a href="https://pastebin.com/4ZiB92m4" rel="nofollow">https://pastebin.com/4ZiB92m4</a><br />
Iran: <a href="https://pastebin.com/LuFsGM6H" rel="nofollow">https://pastebin.com/LuFsGM6H</a></p>

<p>Of course, I am actively developing and updating this regularly, so any feedbacks and suggestions are welcome!</p>
]]>
        </description>
    </item>
    <item>
        <title>yammdb - just another .mmdb</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5876/yammdb-just-another-mmdb</link>
        <pubDate>Fri, 05 May 2023 21:18:22 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Neoon</dc:creator>
        <guid isPermaLink="false">5876@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Hey,</p>

<p>Today I wanted to present you, yammdb.<br />
Which is another, different, geodatabase, based on real measurements.</p>

<p>You can find it here: <a href="https://github.com/Ne00n/yammdb" rel="nofollow">https://github.com/Ne00n/yammdb</a><br />
The Database is build weekly, on fridays.</p>

<p>As long the buildserver doesn't blow up.<br />
The primary use case for me is to compare existing geo data, maybe someone of you will find it useful.</p>

<p>If you have any ideas and feedback, please lemme know.</p>

<p>Enjoy.</p>
]]>
        </description>
    </item>
    <item>
        <title>systemd-nspawn</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5996/systemd-nspawn</link>
        <pubDate>Mon, 05 Jun 2023 02:55:42 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Not_Oles</dc:creator>
        <guid isPermaLink="false">5996@/index.php?p=/discussions</guid>
        <description><![CDATA[<p><img src="https://lowendspirit.com/uploads/editor/4j/fi9mqwkfl8gy.png" alt="" title="" /></p>

<p>Today I first heard about systemd-nspawn when andrewstuart <a rel="nofollow" href="https://news.ycombinator.com/item?id=36190040">mentioned it on HN.</a></p>

<p>Doesn't look like there has been much mention of nspawn here on LES, but there is a <a rel="nofollow" href="https://wiki.debian.org/nspawn">Debian wiki page</a> and an <a rel="nofollow" href="https://wiki.archlinux.org/title/systemd-nspawn">Arch wiki page.</a> There is a man page on <a rel="nofollow" href="https://www.freedesktop.org/software/systemd/man/systemd-nspawn.html">FreeDesktop.org.</a></p>

<p>Quoting from the Arch wiki: "systemd-nspawn may be used to run a command or OS in a light-weight namespace container. . . . systemd-nspawn is a simpler tool to configure than LXC or Libvirt." Hmm, simple configuration sounds pretty good!</p>

<p>There seems to be an <a rel="nofollow" href="https://hub.nspawn.org/faq/">nspawn.org website,</a> which talks about a wrapper script for easier install, and there is a <a rel="nofollow" href="https://github.com/nspawn/nspawn/blob/master/nspawn">Github repo as well.</a></p>

<p>Might a server with a bunch of nspawn containers create an <em>easily configured</em> Low End Empire? 💰</p>

<p>Does anybody here have experience using nspawn?</p>
]]>
        </description>
    </item>
    <item>
        <title>dnscry.pt - Public DNSCrypt resolvers hosted by LowEnd providers</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5502/dnscry-pt-public-dnscrypt-resolvers-hosted-by-lowend-providers</link>
        <pubDate>Sat, 18 Feb 2023 15:06:31 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Brueggus</dc:creator>
        <guid isPermaLink="false">5502@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Some of you may remember my <a rel="nofollow" href="https://lowendspirit.com/discussion/4484/brueggus-vps-flea-market/p1">VPS flea market</a> which became a bit messy eventually. I was nonetheless able to get rid of some of my idlers, others were canceled since then but I'm still sitting on a pile of them.</p>

<p>In December, I decided to turn some of them into something useful (hopefully...) for the community and <a rel="nofollow" href="https://www.dnscry.pt/">dnscry.pt</a> was born:</p>

<p></p><div><img src="https://www.dnscry.pt/media/images/logo.png" alt="" /><br /><br />
<strong>Public DNSCrypt resolvers hosted by LowEnd providers</strong></div>

<p>Most of the servers have been taken from my collection of idlers, but I'd like to give a shout-out to <a href="https://staging.lowendspirit.com/index.php?p=/profile/Kuroit" rel="nofollow">@Kuroit</a> and <a href="https://staging.lowendspirit.com/index.php?p=/profile/terrahost" rel="nofollow">@terrahost</a> who are generously sponsoring three servers for the project.</p>

<p>In a nutshell, DNSCrypt is a protocol which encrypt and authenticates your DNS requests, so that a third party (like your ISP) can no longer tinker with them. You have to run a DNSCrypt client like <a rel="nofollow" href="https://github.com/DNSCrypt/dnscrypt-proxy">dnscrypt-proxy</a> locally or in your network and point your DNS requests there instead of towards your Wi-Fi router or public resolvers like Google's 8.8.8.8. Your DNSCrypt client will take care of the encryption and forward your requests to a public DNSCrypt resolver (like one of those I run for dnscry.pt).</p>

<p>None of the resolvers do any filtering of any kind. I don't store any logs of your requests. All I do is collect metrics using Munin.</p>

<p>If you're interested in giving it a try, further instructions can be found <a rel="nofollow" href="https://www.dnscry.pt/get-started/">here</a>. There's also <a rel="nofollow" href="https://www.dnscry.pt/public-resolvers/">a list of all resolvers</a>.</p>

<p><small>Singapore may appear offline from time to time but is doing fine for local traffic. Intercontinental traffic is going through Cogent and their lines appear to be <a rel="nofollow" href="https://img.brueggus.de/files/25f7ad7a095684/2b603a32.png">congested af</a>. I'm monitoring all resolvers from a server hosted in Jacksonville, FL.</small></p>

<p>If you're using dnscrypt-proxy, you don't have to handpick resolvers near your location. Instead, use the <a rel="nofollow" href="https://www.dnscry.pt/resolvers.md">auto-generated resolver list</a>. Configuration instructions can be found in the file header or in the "Get Started" guide on the website.</p>

<p>I hope this is useful for some of you. I'm using DNSCrypt for years and have switched to my resolver list recently.</p>

<p>Let me know if you have any feedback or questions. I'm also open for suggestions for new locations. <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":smile:" alt=":smile:" height="18" /></p>
]]>
        </description>
    </item>
    <item>
        <title>TCP reset alert</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5989/tcp-reset-alert</link>
        <pubDate>Sat, 03 Jun 2023 07:26:46 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>hostaspace</dc:creator>
        <guid isPermaLink="false">5989@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Hello LES fellow's,<br />
I am getting TCP reset alert from one of my VDS which is currently idle and running Ubuntu 22.04LTS hosted by advinservers.com ( <a href="https://staging.lowendspirit.com/index.php?p=/profile/advin" rel="nofollow">@advin</a> ). <br />
I'm not concerned but I get this same alert few times before also. Just curious  <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/open_mouth.png" title=":o" alt=":o" height="18" />  to know what that mean is it a port scan or what. <br />
I am not running anything as yet used few times before as a middleman relay  <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/wink.png" title=";)" alt=";)" height="18" />  vps just for some large zip extraction and file transfers using rclone from Russian &amp; European region to my other servers. Afterward reinstall upgrade the OS and leave it Idle.</p>

<p>Alert Info<br />
Node: 12-eu-adv<br />
Chart ID: ipv4.tcphandshake<br />
Type: System<br />
Component: Network<br />
Class: Errors<br />
Check every: 10 seconds<br />
10s_ipv4_tcp_resets_sent<br />
Triggered 6/2/23 15:02:55   0.0322 tcp resets/s<br />
Alert Description- average number of sent TCP RESETS over the last 10 seconds. This can indicate a port scan, or that a service running on this host has crashed.</p>

<p><img src="https://cdn1.frocdn.ch/07zn7MPwJGb5nFh.png" alt="" title="" /></p>

<p><img src="https://cdn1.frocdn.ch/HHCO5TUEnr8zIzW.png" alt="" title="" /></p>
]]>
        </description>
    </item>
    <item>
        <title>Unassigned LAN IP leads to server suspension because of spoofing</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5980/unassigned-lan-ip-leads-to-server-suspension-because-of-spoofing</link>
        <pubDate>Wed, 31 May 2023 08:44:44 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>sgheghele</dc:creator>
        <guid isPermaLink="false">5980@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Can you educate me on something I was not aware of?</p>

<p>I added a LAN IP address to my WireGuard server like this:</p>

<p>ip addr add 10.10.10.123/32 dev wg0</p>

<p>I happened not to use this IP for anything. The IP was pingable when connected to WireGuard, the server would respond.</p>

<p>The hosting provider suspended my server because of IP spoofing, that someone had been using that unassigned IP to spoof my public IP.</p>

<p>This was fixed easily, but now I have questions.</p>

<p>How is that possible? Given that there was no breach, it means that the unassigned LAN IP could be somehow used to act as the external IP?</p>
]]>
        </description>
    </item>
    <item>
        <title>Server Load Average.</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5958/server-load-average</link>
        <pubDate>Thu, 25 May 2023 06:46:25 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>hostaspace</dc:creator>
        <guid isPermaLink="false">5958@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Hello to all LES fellow..<br />
I manage my server from almost two years and learned many thing but till now i didn't understand how to read that server load average thing. I use netdata.cloud for the same as a noob <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/confused.png" title=":/" alt=":/" height="18" /><br />
Can anyone explain about the server load average and how to read the same.</p>

<p>Below i attached the ss of current server load.<br />
<img src="https://cdn1.frocdn.ch/UEpy3O3ps047pUL.png" alt="" title="" /></p>
]]>
        </description>
    </item>
    <item>
        <title>NetBSD Not Quite Installed On Hetzner EX101</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5928/netbsd-not-quite-installed-on-hetzner-ex101</link>
        <pubDate>Wed, 17 May 2023 01:46:49 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Not_Oles</dc:creator>
        <guid isPermaLink="false">5928@/index.php?p=/discussions</guid>
        <description><![CDATA[<p><a rel="nofollow" href="https://netbsd.org/">NetBSD</a> has a <a rel="nofollow" href="http://nycdn.netbsd.org/pub/NetBSD-daily/HEAD/202305131120Z/amd64/installation/cdrom/">serial, non-video installer</a> which seems to work with qemu inside tmux inside Hetzner's rescue system:</p>

<pre><code>root@rescue ~ # cat start-install 
qemu-system-x86_64 \
    -enable-kvm \
    -nographic \
    -cpu host \
    -boot once=d \
    -cdrom ./boot-com.iso \
    -m 4096 \
    -drive file=/dev/nvme0n1,format=raw,media=disk,if=virtio \
    -drive file=/dev/nvme1n1,format=raw,media=disk,if=virtio 
root@rescue ~ # 
</code></pre>

<p>One downloads from the above linked page the SHA512 file and the boot-com.iso file, checks the SHA512, and runs something like the above qemu-command. A prerequisite might be having used Hetzner installimage to put a non-RAID install on the server so that the rescue system's qemu will see /dev/nvme* devices instead of /dev/md*.</p>

<p>After running through the install sequence and rebooting inside qemu inside tmux, the system seemed to come up from the NVMe drive.</p>

<p>After <code>shutdown -h now</code> inside NetBSD and then Ctrl-b, x, y to get out of tmux and then rebooting to get out of the Hetzner Rescue System, the server seemed to come up! It responded to IPv4 ping, but <code>ssh root@fsn.metalvps.com</code> gave me <code>ssh: connect to host fsn.metalvps.com port 22: Network is unreachable</code>.</p>

<p>Re-enabling the Hetzner rescue system and restarting qemu, NetBSD booted again from the NVMe disk (same qemu command as above, but with the following two lines removed).</p>

<pre><code>     -boot once=d \
    -cdrom ./boot-com.iso \
</code></pre>

<p>Eventually I may figure out why the live, booted-from-metal server could respond to ping but ssh wouldn't work. It's been more than 20 years since I last used NetBSD, so I've forgotten everything. <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":)" alt=":)" height="18" /></p>

<p>Why didn't I use Hetzner's <a rel="nofollow" href="https://docs.hetzner.com/robot/dedicated-server/maintainance/kvm-console/">free KVM console</a> option? Well, if qemu works, I don't have to bother Hetzner's support guys to have them attach and then remove the KVM.</p>

<p>Thanks to the <a rel="nofollow" href="https://depenguin.me/">depenguin.me guys</a> for helpful hints.</p>

<p>Here's <code>ps aux</code> output from the rebooted server running inside qemu. Notice that there are fewer processes than contemporary Linux.</p>

<pre><code>fsn# date -u; ps aux
Tue May 16 23:57:19 UTC 2023
USER     PID %CPU %MEM   VSZ   RSS TTY   STAT STARTED    TIME COMMAND
root       0  0.0  0.8     0 33688 ?     DKl  11:30PM 0:00.32 [system]
root       1  0.0  0.0 11944  1660 ?     Is   11:30PM 0:00.00 init 
postfix  328  0.0  0.1 21456  4900 ?     I    11:30PM 0:00.01 pickup -l -t unix
postfix  329  0.0  0.1 21504  4968 ?     I    11:30PM 0:00.00 qmgr -l -t unix -
root     331  0.0  0.0 13360  1488 ?     Is   11:30PM 0:00.00 /usr/sbin/inetd -
root     339  0.0  0.0 12212  1740 ?     Is   11:30PM 0:00.00 /usr/sbin/cron 
root     351  0.0  0.1 18408  2676 ?     S    11:30PM 0:00.03 ntpd: asynchronou
root     829  0.0  0.1 18036  2476 ?     Ss   11:30PM 0:00.03 /usr/sbin/syslogd
root    1313  0.0  0.0 11768  1416 ?     Is   11:30PM 0:00.00 /usr/sbin/powerd 
root    1442  0.0  0.4 18272 17824 ?     Ss   11:30PM 0:00.14 /usr/sbin/ntpd -p
root    1532  0.0  0.1 23044  3200 ?     Is   11:30PM 0:00.00 sshd: /usr/sbin/s
root    1821  0.0  0.1 21528  2876 ?     Is   11:30PM 0:00.01 /usr/libexec/post
root     306  0.0  0.0 12076  1720 tty00 O+   11:57PM 0:00.00 ps -aux 
root     335  0.0  0.1 12584  2228 tty00 S    11:31PM 0:00.07 -sh 
root     347  0.0  0.3 24872 10492 tty00 Is   11:30PM 0:00.09 login 
root     348  0.0  0.0 11860  1684 ttyE1 Is+  11:30PM 0:00.00 /usr/libexec/gett
root    2013  0.0  0.0 11856  1684 ttyE2 Is+  11:30PM 0:00.00 /usr/libexec/gett
root    1118  0.0  0.0 11856  1680 ttyE3 Is+  11:30PM 0:00.00 /usr/libexec/gett
fsn# 
</code></pre>

<p>Here's <code>dmesg</code> output from the rebooted server running inside qemu.</p>

<pre><code>fsn# dmesg | cat -n                                                                                                                                        
     1  [     1.000000] Copyright (c) 1996, 1997, 1998, 1999, 2000, 2001, 2002, 2003,                                                                      
     2  [     1.000000]     2004, 2005, 2006, 2007, 2008, 2009, 2010, 2011, 2012, 2013,                                                                    
     3  [     1.000000]     2014, 2015, 2016, 2017, 2018, 2019, 2020, 2021, 2022, 2023                                                                     
     4  [     1.000000]     The NetBSD Foundation, Inc.  All rights reserved.                                                                              
     5  [     1.000000] Copyright (c) 1982, 1986, 1989, 1991, 1993                                                                                         
     6  [     1.000000]     The Regents of the University of California.  All rights reserved.                                                             
     7                                                                                                                                                     
     8  [     1.000000] NetBSD 10.99.4 (GENERIC) #0: Sat May 13 11:19:19 UTC 2023                                                                          
     9  [     1.000000]         mkrepro@mkrepro.NetBSD.org:/usr/src/sys/arch/amd64/compile/GENERIC                                                         
    10  [     1.000000] total memory = 4095 MB                                                                                                             
    11  [     1.000000] avail memory = 3935 MB                                                                                                             
    12  [     1.000000] timecounter: Timecounters tick every 10.000 msec                                                                                   
    13  [     1.000000] Kernelized RAIDframe activated                                                                                                     
    14  [     1.000000] timecounter: Timecounter "i8254" frequency 1193182 Hz quality 100                                                                  
    15  [     1.000004] mainbus0 (root)                                                                                                                    
    16  [     1.000004] ACPI: RSDP 0x00000000000F5AF0 000014 (v00 BOCHS )                                                                                  
    17  [     1.000004] ACPI: RSDT 0x00000000BFFE1550 000034 (v01 BOCHS  BXPCRSDT 00000001 BXPC 00000001)                                                  
    18  [     1.000004] ACPI: FACP 0x00000000BFFE1404 000074 (v01 BOCHS  BXPCFACP 00000001 BXPC 00000001)                                                  
    19  [     1.000004] ACPI: DSDT 0x00000000BFFE0040 0013C4 (v01 BOCHS  BXPCDSDT 00000001 BXPC 00000001)                                                  
    20  [     1.000004] ACPI: FACS 0x00000000BFFE0000 000040                                                                                               
    21  [     1.000004] ACPI: APIC 0x00000000BFFE1478 000078 (v01 BOCHS  BXPCAPIC 00000001 BXPC 00000001)                                                  
    22  [     1.000004] ACPI: HPET 0x00000000BFFE14F0 000038 (v01 BOCHS  BXPCHPET 00000001 BXPC 00000001)                                                  
    23  [     1.000004] ACPI: WAET 0x00000000BFFE1528 000028 (v01 BOCHS  BXPCWAET 00000001 BXPC 00000001)                                                  
    24  [     1.000004] ACPI: 1 ACPI AML tables successfully acquired and loaded                                                                           
    25  [     1.000004] ioapic0 at mainbus0 apid 0: pa 0xfec00000, version 0x11, 24 pins                                                                   
    26  [     1.000004] cpu0 at mainbus0 apid 0                                                                                                            
    27  [     1.000004] cpu0: Use lfence to serialize rdtsc                                                                                                
    28  [     1.000004] cpu0: 13th Gen Intel(R) Core(TM) i9-13900, id 0xb0671
    29  [     1.000004] cpu0: node 0, package 0, core 0, smt 0
    30  [     1.000004] acpi0 at mainbus0: Intel ACPICA 20221020
    31  [     1.000004] acpi0: X/RSDT: OemId &lt;BOCHS ,BXPCRSDT,00000001&gt;, AslId &lt;BXPC,00000001&gt;
    31  [     1.000004] acpi0: X/RSDT: OemId &lt;BOCHS ,BXPCRSDT,00000001&gt;, AslId &lt;BXPC,00000001&gt;                                                     [76/526]
    32  [     1.000004] LNKS: ACPI: Found matching pin for 0.1.INTA at func 3: 9                                                                           
    33  [     1.000004] LNKC: ACPI: Found matching pin for 0.3.INTA at func 0: 11                                                                          
    34  [     1.000004] LNKD: ACPI: Found matching pin for 0.4.INTA at func 0: 11                                                                          
    35  [     1.000004] LNKA: ACPI: Found matching pin for 0.5.INTA at func 0: 10                                                                          
    36  [     1.000004] acpi0: SCI interrupting at int 9                                                                                                   
    37  [     1.000004] acpi0: fixed power button present                                                                                                  
    38  [     1.000004] timecounter: Timecounter "ACPI-Fast" frequency 3579545 Hz quality 1000                                                             
    39  [     1.046041] hpet0 at acpi0: high precision event timer (mem 0xfed00000-0xfed00400)                                                             
    40  [     1.046041] timecounter: Timecounter "hpet0" frequency 100000000 Hz quality 2000                                                               
    41  [     1.046619] pckbc1 at acpi0 (KBD, PNP0303) (kbd port): io 0x60,0x64 irq 1                                                                      
    42  [     1.046619] pckbc2 at acpi0 (MOU, PNP0F13) (aux port): irq 12                                                                                  
    43  [     1.046619] fdc0 at acpi0 (FDC0, PNP0700): io 0x3f2-0x3f5,0x3f7 irq 6 drq 2                                                                    
    44  [     1.046619] lpt0 at acpi0 (LPT1, PNP0400-1): io 0x378-0x37f irq 7                                                                              
    45  [     1.046619] com0 at acpi0 (COM1, PNP0501-1): io 0x3f8-0x3ff irq 4                                                                              
    46  [     1.046619] com0: ns16550a, 16-byte FIFO                                                                                                       
    47  [     1.046619] com0: console                                                                                                                      
    48  [     1.046619] qemufwcfg0 at acpi0 (FWCF, QEMU0002): io 0x510-0x51b                                                                               
    49  [     1.046619] qemufwcfg0: &lt;QEMU&gt;                                                                                                                 
    50  [     1.046619] ACPI: Enabled 2 GPEs in block 00 to 0F                                                                                             
    51  [     1.046619] pckbd0 at pckbc1 (kbd slot)                                                                                                        
    52  [     1.046619] pckbc1: using irq 1 for kbd slot                                                                                                   
    53  [     1.046619] wskbd0 at pckbd0 mux 1                                                                                                             
    54  [     1.046619] pms0 at pckbc1 (aux slot)                                                                                                          
    55  [     1.046619] pckbc1: using irq 12 for aux slot                                                                                                  
    56  [     1.046619] wsmouse0 at pms0 mux 0                                                                                                             
    57  [     1.046619] pci0 at mainbus0 bus 0: configuration mode 1                                                                                       
    58  [     1.046619] pci0: i/o space, memory space enabled, rd/line, rd/mult, wr/inv ok                                                                 
    59  [     1.046619] pchb0 at pci0 dev 0 function 0: Intel 82441FX (PMC) PCI and Memory Controller (rev. 0x02)                                          
    60  [     1.046619] pcib0 at pci0 dev 1 function 0: Intel 82371SB (PIIX3) PCI-ISA Bridge (rev. 0x00)                                                   
    61  [     1.046619] piixide0 at pci0 dev 1 function 1: Intel 82371SB IDE Interface (PIIX3) (rev. 0x00)                                                 
    62  [     1.046619] piixide0: bus-master DMA support present                                                                                           
    63  [     1.046619] piixide0: primary channel wired to compatibility mode                                                                              
    64  [     1.046619] piixide0: primary channel interrupting at ioapic0 pin 14                                                                           
    65  [     1.046619] atabus0 at piixide0 channel 0                                                                                                      
    66  [     1.046619] piixide0: secondary channel wired to compatibility mode                                                                            
    67  [     1.046619] piixide0: secondary channel interrupting at ioapic0 pin 15                                                                         
    68  [     1.046619] atabus1 at piixide0 channel 1 
    69  [     1.046619] piixpm0 at pci0 dev 1 function 3: Intel 82371AB (PIIX4) Power Management Controller (rev. 0x03)                            [38/526]
    70  [     1.046619] timecounter: Timecounter "piixpm0" frequency 3579545 Hz quality 1000                                                               
    71  [     1.046619] piixpm0: 24-bit timer                                                                                                              
    72  [     1.046619] piixpm0: interrupting at ioapic0 pin 9                                                                                             
    73  [     1.046619] iic0 at piixpm0 port 0: I2C bus                                                                                                    
    74  [     1.046619] vga0 at pci0 dev 2 function 0: vendor 1234 product 1111 (rev. 0x02)                                                                
    75  [     1.046619] wsdisplay0 at vga0 kbdmux 1                                                                                                        
    76  [     1.046619] wsmux1: connecting to wsdisplay0                                                                                                   
    77  [     1.046619] wskbd0: connecting to wsdisplay0                                                                                                   
    78  [     1.046619] drm at vga0 not configured                                                                                                         
    79  [     1.046619] wm0 at pci0 dev 3 function 0, 64-bit DMA: Intel i82540EM 1000BASE-T Ethernet (rev. 0x03)                                           
    80  [     1.046619] wm0: interrupting at ioapic0 pin 11                                                                                                
    81  [     1.046619] wm0: 32-bit 33MHz PCI bus                                                                                                          
    82  [     1.046619] wm0: 64 words (6 address bits) MicroWire EEPROM                                                                                    
    83  [     1.046619] wm0: Ethernet address 52:54:00:12:34:56                                                                                            
    84  [     1.046619] wm0: 0x200002&lt;LOCK_EECD,WOL&gt;                                                                                                       
    85  [     1.046619] makphy0 at wm0 phy 1: Marvell 88E1011 Gigabit PHY, rev. 0                                                                          
    86  [     1.046619] makphy0: Failed to access EADR. Are you an emulator?                                                                               
    87  [     1.046619] makphy0: Failed to read EXTSR. Are you an emulator?. Regard as 1000BASE-T.                                                         
    88  [     1.046619] makphy0: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, 1000baseT, 1000baseT-FDX, auto                                            
    89  [     1.046619] virtio0 at pci0 dev 4 function 0                                                                                                   
    90  [     1.046619] virtio0: block device (id 2, rev. 0x00)                                                                                            
    91  [     1.046619] ld0 at virtio0: features: 0x10000a54&lt;INDIRECT_DESC,CONFIG_WCE,FLUSH,BLK_SIZE,GEOMETRY,SEG_MAX&gt;                                     
    92  [     1.046619] virtio0: allocated 1060864 byte for virtqueue 0 for I/O request, size 256                                                          
    93  [     1.046619] virtio0: using 1048576 byte (65536 entries) indirect descriptors                                                                   
    94  [     1.046619] virtio0: config interrupting at msix0 vec 0                                                                                        
    95  [     1.046619] virtio0: queues interrupting at msix0 vec 1                                                                                        
    96  [     1.046619] ld0: 1788 GB, 16383 cyl, 16 head, 63 sec, 512 bytes/sect x 3750748848 sectors                                                      
    97  [     1.046619] virtio1 at pci0 dev 5 function 0                                                                                                   
    98  [     1.046619] virtio1: block device (id 2, rev. 0x00)                                                                                            
    99  [     1.046619] ld1 at virtio1: features: 0x10000a54&lt;INDIRECT_DESC,CONFIG_WCE,FLUSH,BLK_SIZE,GEOMETRY,SEG_MAX&gt;                                     
   100  [     1.046619] virtio1: allocated 1060864 byte for virtqueue 0 for I/O request, size 256                                                          
   101  [     1.046619] virtio1: using 1048576 byte (65536 entries) indirect descriptors                                                                   
   102  [     1.046619] virtio1: config interrupting at msix1 vec 0                                                                                        
   103  [     1.046619] virtio1: queues interrupting at msix1 vec 1                                                                                        
   104  [     1.046619] ld1: 1788 GB, 16383 cyl, 16 head, 63 sec, 512 bytes/sect x 3750748848 sectors                                                      
   105  [     1.046619] isa0 at pcib0                                                                                                                      
   106  [     1.046619] attimer0 at isa0 port 0x40-0x43 
   107  [     1.046619] pcppi0 at isa0 port 0x61
   108  [     1.046619] spkr0 at pcppi0: PC Speaker
   109  [     1.046619] wsbell at spkr0 not configured
   110  [     1.046619] midi0 at pcppi0: PC speaker
   111  [     1.046619] sysbeep0 at pcppi0
   112  [     1.046619] attimer0: attached to pcppi0
   113  [     1.046619] acpicpu0 at cpu0: ACPI CPU
   114  [     1.046619] acpicpu0: C1: HLT, lat   0 us, pow     0 mW
   115  [     1.046619] vmt0 at cpu0
   116  [     1.046619] vmt0: UUID: 00000000-0000-0000-0000-000000000000
   117  [     1.046619] vmware: open failed, eax=0xffffffff, ecx=0x1e, edx=0x5658
   118  [     1.046619] vmt0: autoconfiguration error: failed to open backdoor RPC channel (TCLO protocol)
   119  [     1.046619] timecounter: Timecounter "clockinterrupt" frequency 100 Hz quality 0
   120  [     1.046619] fd0 at fdc0 drive 0: 1.44MB, 80 cyl, 2 head, 18 sec
   121  [     1.046619] ld1: GPT GUID: 7ac59b06-d775-499c-b672-f71133e62986
   122  [     1.046619] ld0: GPT GUID: 868d363e-b930-4142-944f-e70905997bdb
   123  [     1.046619] IPsec: Initialized Security Association Processing.
   124  [     1.046619] dk0 at ld1: "be45d1a2-c15f-4fa9-a36b-db22ab2e15e0", 524288 blocks at 4096, type: msdos
   125  [     1.046619] dk1 at ld1: "c6fc5a64-7669-464c-8578-77c52a1ebe6c", 1048576 blocks at 528384, type: &lt;unknown&gt;
   126  [     1.046619] dk2 at ld1: "24fde94d-ca86-46bd-8358-93c1ac2f8b9e", 3749171855 blocks at 1576960, type: &lt;unknown&gt;
   127  [     1.046619] dk3 at ld0: "02a153e5-14e1-45f0-8e65-d55f5f7da62c", 3742359552 blocks at 2048, type: ffs
   128  [     1.046619] dk4 at ld0: "981d2b55-1018-4fc9-9f3c-5847d6751eb7", 8387215 blocks at 3742361600, type: swap
   129  [     5.005793] atapibus0 at atabus1: 2 targets
   130  [     5.015571] cd0 at atapibus0 drive 0: &lt;QEMU DVD-ROM, QM00003, 2.5+&gt; cdrom removable
   131  [     5.015571] cd0: 32-bit data port
   132  [     5.015571] cd0: drive supports PIO mode 4, DMA mode 2, Ultra-DMA mode 5 (Ultra/100)
   133  [     5.015571] cd0(piixide0:1:0): using PIO mode 4, DMA mode 2 (using DMA)
   134  [     5.015571] swwdog0: software watchdog initialized
   135  [     5.025557] WARNING: 1 error while detecting hardware; check system log.
   136  [     5.025557] boot device: ld0
   137  [     5.025557] root on dk3 dumps on dk4
   138  [     5.025557] root file system type: ffs
   139  [     5.025557] kern.module.path=/stand/amd64/10.99.4/modules
   140  [    10.485560] wsdisplay0: screen 1 added (80x25, vt100 emulation)
   141  [    10.485560] wsdisplay0: screen 2 added (80x25, vt100 emulation)
   142  [    10.485560] wsdisplay0: screen 3 added (80x25, vt100 emulation)
   143  [    10.485560] wsdisplay0: screen 4 added (80x25, vt100 emulation)
fsn# 
</code></pre>
]]>
        </description>
    </item>
    <item>
        <title>Distrobox: Use any Linux distribution inside your terminal | Hacker News</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5923/distrobox-use-any-linux-distribution-inside-your-terminal-hacker-news</link>
        <pubDate>Mon, 15 May 2023 19:11:53 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Not_Oles</dc:creator>
        <guid isPermaLink="false">5923@/index.php?p=/discussions</guid>
        <description><![CDATA[<p><a href="https://news.ycombinator.com/item?id=35939240" rel="nofollow">https://news.ycombinator.com/item?id=35939240</a></p>

<p><a href="https://github.com/89luca89/distrobox" rel="nofollow">https://github.com/89luca89/distrobox</a></p>

<p>I glanced at this last night. I haven't read much of it, and I haven't tried it. I never heard of it, or its antecedent mentioned in the README.md file.</p>

<p>Could this, or something else like it, be the basis of a super fast, distro agnostic, shared server?</p>

<p>Thanks! Friendly greetings! <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":)" alt=":)" height="18" /></p>
]]>
        </description>
    </item>
    <item>
        <title>EPYC + Plex or Jellyfin or Emby</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5913/epyc-plex-or-jellyfin-or-emby</link>
        <pubDate>Fri, 12 May 2023 21:58:20 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>hornet</dc:creator>
        <guid isPermaLink="false">5913@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>My only server play has been with Intel hardware, apart from a <strong>long</strong> time ago with 100-series Opterons.  I am scheming on changing my setup, and I was wondering what EPYC CPUs can do compared to the Intel boys.  I definitely am not interested in trashing either one -I was just wondering what your experiences were like.  If you have used EPYC processors for such, what was the configuration?  vCPU? How many cores? On your (home?) network?  Rented? And so forth...</p>

<p>Thanks!</p>
]]>
        </description>
    </item>
    <item>
        <title>The Great Firewall thread</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5853/the-great-firewall-thread</link>
        <pubDate>Thu, 04 May 2023 01:32:47 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>System</dc:creator>
        <guid isPermaLink="false">5853@/index.php?p=/discussions</guid>
        <description><![CDATA[This discussion was created from comments split from: <a rel="nofollow" href="/discussion/5754/free-metalvps-intel-i9-13900-traditional-shell-account-make-your-own-vpses/">Free MetalVPS Intel i9-13900 Traditional Shell Account! Make Your Own VPSes!</a>.]]>
        </description>
    </item>
    <item>
        <title>So is our future going to be bun.js or deno.js 2? Or something else?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5807/so-is-our-future-going-to-be-bun-js-or-deno-js-2-or-something-else</link>
        <pubDate>Tue, 25 Apr 2023 20:14:39 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Not_Oles</dc:creator>
        <guid isPermaLink="false">5807@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Hello!</p>

<p>So is our future going to be bun.js or deno.js 2? Or something else?</p>

<p>I've had this question in my sig for a few days. I'm still wondering what the answer is. I'm not trying to push any particular perspective. I'm just . . . wondering. What do you think?</p>

<p>Best!</p>

<p>Tom</p>
]]>
        </description>
    </item>
    <item>
        <title>Does anyone have experience with SSD based Ceph?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5832/does-anyone-have-experience-with-ssd-based-ceph</link>
        <pubDate>Mon, 01 May 2023 07:41:32 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>RapToN</dc:creator>
        <guid isPermaLink="false">5832@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>In the last year we have migrated all HDD based vServers to a Ceph storage and are excited about the possibilities and the performance the system offers. <br />
Now I would like to migrate our SSD vServer to a Ceph based storage and I am facing some questions that I have answered myself with the HDD based system through many tests. But that cost a lot of time and money, which I only accepted because I also wanted to familiarize myself intensively with Ceph before I start running customers here.</p>

<p>Which SSDs do you use in your Ceph storage?<br />
How important is the RAM speed (I could imagine that this plays an upscale role with SSDs)?<br />
Any good or negative experiences you can share?</p>

<p>I would be extremely happy if a lively exchange of experiences and opinions takes place here, without anyone attacking anyone else.</p>

<p>Thanks a lot for your support.</p>
]]>
        </description>
    </item>
    <item>
        <title>What's the best server hardware deal at the moment?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5808/whats-the-best-server-hardware-deal-at-the-moment</link>
        <pubDate>Wed, 26 Apr 2023 01:45:28 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Not_Oles</dc:creator>
        <guid isPermaLink="false">5808@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Over <a rel="nofollow" href="https://lowendspirit.com/discussion/comment/136971/#Comment_136971">there,</a> in my MetalVPS thread, <a href="https://staging.lowendspirit.com/index.php?p=/profile/somik" rel="nofollow">@somik</a> said:</p>

<blockquote><div>
  <p>Now with falling price of server grade hardware, it's cheaper to buy. . . .</p>
</div></blockquote>

<p>Are server prices really falling?</p>

<p>What's the current cost of a great deal to buy a server in the US + colo? Something with server grade hardware, but otherwise somewhat like the i9-13900 I have from Hetzner (64 GB DDR5 ECC, 2 x 1.92 TB NVMe Gen 4, 1 Gbps unlimited) for € 89.00/month?</p>

<p>I don't have a server in the US at the moment. A US location with good connections to Asia would be nice.</p>
]]>
        </description>
    </item>
    <item>
        <title>OpenVZ 7 node IPv6 issue after update</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5824/openvz-7-node-ipv6-issue-after-update</link>
        <pubDate>Sat, 29 Apr 2023 09:34:12 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Abdullah</dc:creator>
        <guid isPermaLink="false">5824@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>I am wondering anyone here still using OpenVZ 7 sees the new IPv6 related issues after upgrading to version 3.10.0-1160.80.1.vz7.191.4</p>

<p>Initially when installing container IPv6 works fine, but randomly dies after a while on some of the containers. <br />
From container -</p>

<p>Some containers have working IPv6 , some don't.</p>

<p>The host node is unaffected by this issue:</p>

<pre>
[root@dro2-nld ~]# ping6 google.com
PING google.com(ams15s41-in-x0e.1e100.net (2a00:1450:400e:802::200e)) 56 data bytes
64 bytes from ams16s21-in-x0e.1e100.net (2a00:1450:400e:802::200e): icmp_seq=1 ttl=120 time=4.74 ms
64 bytes from ams16s21-in-x0e.1e100.net (2a00:1450:400e:802::200e): icmp_seq=2 ttl=120 time=2.78 ms
64 bytes from ams16s21-in-x0e.1e100.net (2a00:1450:400e:802::200e): icmp_seq=3 ttl=120 time=3.04 ms
64 bytes from ams16s21-in-x0e.1e100.net (2a00:1450:400e:802::200e): icmp_seq=4 ttl=120 time=2.73 ms
64 bytes from ams16s21-in-x0e.1e100.net (2a00:1450:400e:802::200e): icmp_seq=5 ttl=120 time=2.82 ms
^C
--- google.com ping statistics ---
5 packets transmitted, 5 received, 0% packet loss, time 4005ms
rtt min/avg/max/mdev = 2.734/3.225/4.742/0.767 ms
</pre>

<p><br /></p>

<p><br /></p>

<p>Checking it further ,</p>

<p>I made a test VM and assigned it IPv6 '2001:41d0:a:28b6:7cbb:0000:0000:0001'</p>

<p>Tried pinging the address and it was not reachable globally <a href="https://prnt.sc/vmRGmN2P0UDZ" rel="nofollow">https://prnt.sc/vmRGmN2P0UDZ</a></p>

<p>I added that IPv6 address to the host node network interface<br />
<code>ip -6 addr add 2001:41d0:a:28b6:7cbb:0000:0000:0001/80 dev br0</code></p>

<p>It responds to pings now <a href="https://prnt.sc/CdgToWos2TFZ" rel="nofollow">https://prnt.sc/CdgToWos2TFZ</a></p>

<p><br /></p>

<p>I removed the IPv6 address from the host node network interface  <code>ip -6 addr del 2001:41d0:a:28b6:7cbb:0000:0000:0001/80 dev br0</code></p>

<p>It still responds to ping fine <a href="https://prnt.sc/3prDDpT7I_z7" rel="nofollow">https://prnt.sc/3prDDpT7I_z7</a></p>

<p>The container has working IPv6 connectivity now</p>

<pre>
root@test:/# ping6 google.com
PING google.com(par21s20-in-x0e.1e100.net (2a00:1450:4007:818::200e)) 56 data bytes
64 bytes from par21s20-in-x0e.1e100.net (2a00:1450:4007:818::200e): icmp_seq=1 ttl=115 time=4.69 ms
64 bytes from par21s20-in-x0e.1e100.net (2a00:1450:4007:818::200e): icmp_seq=2 ttl=115 time=4.64 ms
64 bytes from par21s20-in-x0e.1e100.net (2a00:1450:4007:818::200e): icmp_seq=3 ttl=115 time=4.79 ms
^C
--- google.com ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 5ms
rtt min/avg/max/mdev = 4.637/4.703/4.785/0.100 ms
</pre>

<p><br /></p>

<p>This issue did not exist in previous openvz versions and appeared after the upgrade.</p>

<p>Any idea what is causing this ? I think using <a rel="nofollow" href="https://github.com/yoursunny/ndpresponder" title="ndpresponder">ndpresponder</a> will resolve this issue, but I haven't figured how to configure it yet.</p>
]]>
        </description>
    </item>
    <item>
        <title>[NEWS] Intel i219-LM Had Only Been Running At ~60% Of Maximum Speed Due To Linux Driver Bug</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5798/news-intel-i219-lm-had-only-been-running-at-60-of-maximum-speed-due-to-linux-driver-bug</link>
        <pubDate>Mon, 24 Apr 2023 14:59:48 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>ralf</dc:creator>
        <guid isPermaLink="false">5798@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Interesting reading about this today: <a href="https://www.phoronix.com/news/Intel-i219-LM-Linux-60p-Fix" rel="nofollow">https://www.phoronix.com/news/Intel-i219-LM-Linux-60p-Fix</a></p>

<p>I recognised the chipset name and when I checked my Hetzner box (i9-9900k), sure enough it had one of these. However, whenever I've done a YABS, I did get around 900Mbps, so not entirely sure what's going on here. I'm using debian 11 which has kernel 5.10.0, so in theory this regression should have been evident on my system.</p>
]]>
        </description>
    </item>
    <item>
        <title>How to create your own .mmdb for gdnsd or any other nameserver</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5791/how-to-create-your-own-mmdb-for-gdnsd-or-any-other-nameserver</link>
        <pubDate>Fri, 21 Apr 2023 15:55:21 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Neoon</dc:creator>
        <guid isPermaLink="false">5791@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Hey,</p>

<p>Simple Tutorial to create your own .mmdb for gdnsd.</p>

<p>You need a .mmdb writer, I suggest coded in python3, but there is also one in Perl and Go, depending on what you prefer.</p>

<p>Python3 writer can be found here:<br />
<a href="https://github.com/vimt/MaxMind-DB-Writer-python" rel="nofollow">https://github.com/vimt/MaxMind-DB-Writer-python</a><br />
<a href="https://github.com/maxmind/mmdbwriter" rel="nofollow">https://github.com/maxmind/mmdbwriter</a> (Go)<br />
<a href="https://github.com/maxmind/MaxMind-DB-Writer-perl" rel="nofollow">https://github.com/maxmind/MaxMind-DB-Writer-perl</a> (Perl)</p>

<p>I slightly needed to modify it, because of the data type, gdnsd strictly validates the geo cordinates.<br />
<a href="https://github.com/Ne00n/MaxMind-DB-Writer-python" rel="nofollow">https://github.com/Ne00n/MaxMind-DB-Writer-python</a></p>

<p>After Installing, you can build your own, .mmdb, that works out of the box with gdnsd.</p>

<pre><code>from netaddr import IPNetwork, IPSet
from mmdb_writer import MMDBWriter
import geoip2.database

writer = MMDBWriter(4, 'GeoIP2-City', languages=['EN'], description="Mah own .mmdb")
subnets = ["1.1.1.0/24","8.8.8.0/24"]
writer.insert_network(IPSet(subnets), {'location':{"latitude":1.11,"longitude":2.22}})
writer.to_db_file('geo.mmdb')

reader = geoip2.database.Reader("geo.mmdb")

response = reader.city("1.1.1.1")
print(response.location.latitude,response.location.longitude)

response = reader.city("8.8.8.8")
print(response.location.latitude,response.location.longitude)
</code></pre>

<p>Will return.</p>

<pre><code>1.11 2.22
1.11 2.22
</code></pre>

<p>Put the geo.mmdb into /etc/gdnsd/geoip<br />
Example gdnsd config for that setup.</p>

<pre><code>plugins =&gt; { geoip =&gt; {
  maps =&gt; {
    prod =&gt; {
      geoip2_db =&gt; geo.mmdb,
      datacenters =&gt; [1,2,3],
      auto_dc_coords =&gt; {
       1 =&gt; [ 52.22, 21.01 ],
       2 =&gt; [ 1.35, 103.81 ],
       3 =&gt; [ 40.71, -74 ],
      }
    }
  },
  resources =&gt; {
    prod_www =&gt; {
      map =&gt; prod
      service_types =&gt; up
      dcmap =&gt; {
       1 =&gt; 1.1.1.1,
       2 =&gt; 2.2.2.2,
       3 =&gt; 3.3.3.3,
      }
    }
  }
}}
</code></pre>

<p>You can install gdnsd simply with apt-get.<br />
gdnsd is not available for Ubuntu 22.04, however for 20.04, 23.04, Debian 10, Debian 11 and Debian 12.</p>

<p>Given the low memory usage and good performance by gdnsd, you can even run this with a fat .mmdb on low end boxes, like I do.</p>

<p>Enjoy.</p>
]]>
        </description>
    </item>
    <item>
        <title>Cloudflare Access wildcard logic change</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5695/cloudflare-access-wildcard-logic-change</link>
        <pubDate>Thu, 30 Mar 2023 07:01:21 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>bikegremlin</dc:creator>
        <guid isPermaLink="false">5695@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>In case you are using Cloudflare Zero Trust with wildcards, and have missed this note from the company:</p>

<blockquote><div>
  <p>You are receiving this email because your account has an Access Application with a wildcard definition that will begin to cover more URL combinations. We are updating our wildcard behavior in Cloudflare Access for wildcards at the end of a path not following a slash character (e.g. example.com/text*). If no action is taken before April 20th, 2023, an Access login screen will be presented for additional path combinations.</p>
  
  <p><strong>Current</strong> Access Application behavior<br />
  <code>example.com/alpha*</code> will cover <code>example.com/alpha</code> and <code>example.com/alpha/one</code> but not <code>example.com/alphabet</code>.</p>
  
  <p>Change impact<br />
  After April 20th, 2023 at 20:00 UTC, <strong>all three path combinations will be covered by Access</strong>. If you would like to exempt specific paths from Access, a Bypass policy can be configured.</p>
  
  <p>How to identify impacted Access Applications<br />
  To identify which Access Applications will be impacted by this change, please open the Zero Trust Dashboard, navigate to Access→Applications and search for the * character. This will highlight any applications that may require modification.</p>
</div></blockquote>

<p>I consider this to be the logical way the wildcard should work - as it should have been from the start.</p>

<p>I've updated my <a rel="nofollow" href="https://io.bikegremlin.com/30705/cloudflare-zero-trust-tutorial/#3" title="Cloudflare Zero Trust article">Cloudflare Zero Trust article</a> - as this wildcard function was one of my complaints.</p>
]]>
        </description>
    </item>
    <item>
        <title>first time attempt ipv6 from router to pfsense</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5659/first-time-attempt-ipv6-from-router-to-pfsense</link>
        <pubDate>Fri, 24 Mar 2023 00:16:49 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>xyphos10</dc:creator>
        <guid isPermaLink="false">5659@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Hello everyone,</p>

<p>Just wanted to get some input with my attempt and configuring native ISP ipv6 on my network. So for an overview of how things are setup, my ISP gives me a Cable Modem which has a static ipv4 and /64 ipv6 which feeds a pfsense and from there everything else. They do not allow me to put the modem in bridged mode.</p>

<p>lets use fd00:0824:2273:a::/64 as stand in for the public ipv6.</p>

<p>If I assign fd00:0824:2273:a::1 to the modem and fd00:0824:2273:a::2 to pfsense on WAN side. How can I go about make all clients on pfsense LAN side have an ipv6.</p>

<p>I have attempted using ULA on LAN side and then using NPt but it does not work. As soon as traffic gets to pfsense it stop. (Yes I have all appropriate pfsense rules and have verified in the logs that it is not simply being blocked)</p>

<p>I have attempted breaking down the /64 into 2 /65 and use 1 for wan and 1 for lan but no luck.</p>

<p>Is there a simpler way of doing this that I am just overlooking? I appreciate any help.</p>
]]>
        </description>
    </item>
    <item>
        <title>Get public IP from bash</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5581/get-public-ip-from-bash</link>
        <pubDate>Sun, 05 Mar 2023 02:45:20 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>itsdeadjim</dc:creator>
        <guid isPermaLink="false">5581@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>In case anyone finds this useful, sometimes I need to get my public IP from bash or scripts and I use api.myip.com, only because it's easy to remember.</p>

<p>But more and more often lately, some IPs are blocked there and get http errors,  so I bought a cheap domain and I woke up a $3/year <a href="https://staging.lowendspirit.com/index.php?p=/profile/natvps_uk" rel="nofollow">@natvps_uk</a> from idling, and..</p>

<p><code>wget -4 -qO- myip.cam</code><br />
or for ipv6<br />
<code>wget -6 -qO- myip.cam</code></p>

<p>(or <code>curl -4L myip.cam</code> if curl is your thing)</p>
]]>
        </description>
    </item>
    <item>
        <title>How To Secure A Linux Server</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5377/how-to-secure-a-linux-server</link>
        <pubDate>Mon, 30 Jan 2023 21:58:29 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>loay</dc:creator>
        <guid isPermaLink="false">5377@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>An evolving how-to guide for securing a Linux server.</p>

<p><a href="https://github.com/imthenachoman/How-To-Secure-A-Linux-Server" rel="nofollow">https://github.com/imthenachoman/How-To-Secure-A-Linux-Server</a></p>
]]>
        </description>
    </item>
    <item>
        <title>Is Chroot Still Useful In 2023?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5542/is-chroot-still-useful-in-2023</link>
        <pubDate>Fri, 24 Feb 2023 22:42:35 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Not_Oles</dc:creator>
        <guid isPermaLink="false">5542@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Does anybody here use chroot nowadays?</p>

<p>With KVM and LXC and other virtualization technologies being very popular now, chroot might not seem needed very often any more. Nevertheless, I had a lot of fun last night making a chroot environment.</p>

<p>With <a rel="nofollow" href="https://en.wikipedia.org/wiki/Debian-Installer#debootstrap">debootstrap,</a> the chroot was super fast and easy to set up. It seems to work okay, has network access, I can ssh in, etc.</p>

<p><a rel="nofollow" href="https://en.wikipedia.org/wiki/Chroot">Wikipedia's chroot article</a> tells the very interesting history of chroot, beginning with its introduction in v7 Unix in 1979. The linked Wikipedia article also contains an interesting section on the <a rel="nofollow" href="https://en.wikipedia.org/wiki/Chroot#Limitations">limitations of chroot.</a> However, the limitations might not be especially significant for every use case.</p>

<p>Is it too crazy to imagine that chroot still might be very useful today? For example, if all one needs is a quick test of something? As another example, <a rel="nofollow" href="https://www.hetzner.com/">Hetzner</a> uses chroot in <a rel="nofollow" href="https://docs.hetzner.com/robot/dedicated-server/operating-systems/installimage">Installimage,</a> which is one of Hetzner's methods to install Operating Systems on dedicated servers.</p>

<p>Here, from Installimage, are lines 9 through 27 of <a rel="nofollow" href="https://github.com/hetzneronline/installimage/blob/master/chroot.functions.sh">chroot.functions.sh,</a> where <code>execute_chroot_command()</code> is defined:</p>

<pre><code>execute_chroot_command_wo_debug() {
  local dirs=(/{dev,dev/pts,dev/shm,proc,run,sys})
  for dir in "${dirs[@]}"; do
    mkdir -p "$FOLD/hdd/$dir"
    mount --bind "$dir" "$FOLD/hdd/$dir"
  done
  unshare -f -p chroot "$FOLD/hdd" /usr/bin/env bash -c "$@"
  local r=$?
  for ((i=${#dirs[@]}-1; i&gt;=0; i--)); do
    until umount "$FOLD/hdd/${dirs[i]}"; do :; done
  done
  return $r
}

execute_chroot_command() {
  debug "# chroot: $*"
  execute_chroot_command_wo_debug "$@" |&amp; debugoutput
  return "${PIPESTATUS[0]}"
}
</code></pre>

<p>Please see also <a rel="nofollow" href="https://github.com/hetzneronline/installimage/blob/master/functions.sh">Installimage's functions.sh</a> where <code>execute_chroot_command()</code> appears 14 times.</p>

<p>I hope to learn more about the <a rel="nofollow" href="https://docs.kernel.org/userspace-api/unshare.html">unshare system call,</a> which Installimage uses in the function execute_chroot_command_wo_debug(), and which <a rel="nofollow" href="https://en.wikipedia.org/wiki/Linux_namespaces#Syscalls">"allows a process (or thread) to disassociate parts of its execution context that are currently being shared with other processes (or threads)."</a></p>

<p>People here at LES are invited to teach and learn together with me on <a rel="nofollow" href="https://metalvps.com">MetalVPS.</a> If you think you might like a MetalVPS account, please check the current offer at <a rel="nofollow" href="https://lowendspirit.com/discussion/5481/free-debian-sid-intel-i9-12900k-shell-accounts-from-metalvps">Free Debian Sid Intel i9-12900K Shell Accounts from MetalVPS!</a></p>

<p>I wonder how many people here still use chroot? And, besides Installimage, what are other current uses of chroot these days?</p>

<p>Friendly greetings! <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":)" alt=":)" height="18" /></p>
]]>
        </description>
    </item>
    <item>
        <title>[Solved] Proxmox Alpine Linux LXC Container IPv6 Network Failure</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5395/solved-proxmox-alpine-linux-lxc-container-ipv6-network-failure</link>
        <pubDate>Thu, 02 Feb 2023 22:04:43 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Not_Oles</dc:creator>
        <guid isPermaLink="false">5395@/index.php?p=/discussions</guid>
        <description><![CDATA[<h2><strong>Can We Solve This IPv6 Networking Problem?</strong></h2>

<p>Our server is an i9-9900K at <a rel="nofollow" href="https://www.hetzner.com">Hetzner.</a> Eight <a rel="nofollow" href="https://linuxcontainers.org/">LXC</a> containers are running various Linux distributions on <a rel="nofollow" href="https://proxmox.com">Proxmox-VE 7.3.</a> Everything  seems to work great! . . . Except inside one <a rel="nofollow" href="https://www.alpinelinux.org/">Alpine Linux</a> container. Somehow, IPv6 doesn't work from within this one container. Nevertheless, IPv6 ping to the container somehow seems to work from the Proxmox node. Amazingly, ping also works to the container even from the <a rel="nofollow" href="https://en.wikipedia.org/wiki/Wide_area_network">Wide Area Network (WAN).</a></p>

<p>How could such strangeness happen? Let's investigate!</p>

<h2><strong>A Closer Look At The Problem</strong></h2>

<p>The network configuration for all the containers was added individually by hand in the Proxmox GUI. Proxmox numbers LXC containers beginning with the number "100". The containers are IPv6 only. Each container was given a <a rel="nofollow" href="https://en.wikipedia.org/wiki/IP_address#:~:text=Persistent%20configuration%20is%20also%20known,using%20a%20dynamic%20IP%20address.">static IPv6 address</a> ending with the container's Proxmox container number.</p>

<p>The container with the IPv6 network problem is number 102. An example of the working containers is number 106. Number 106 was chosen for comparison because both container 102 and container 106 were built from the same Alpine Linux LXC image. The other working containers are Ubuntu and Debian.</p>

<p>Alpine Linux seems less likely to be causing the IPv6 network failure because container 106, also built from the Alpine image, is functioning just fine. So let's look directly at the misbehaving container, number 102.</p>

<p>Container 102 can ping localhost.</p>

<pre><code>root@Proxmox-VE ~ # lxc-attach -n 102
~ # ping6 -c 2 localhost
PING localhost (::1): 56 data bytes
64 bytes from ::1: seq=0 ttl=64 time=0.024 ms
64 bytes from ::1: seq=1 ttl=64 time=0.036 ms

--- localhost ping statistics ---
2 packets transmitted, 2 packets received, 0% packet loss
round-trip min/avg/max = 0.024/0.030/0.036 ms
~ # 
</code></pre>

<p>Container 102 also responds to ping from external WAN.</p>

<pre><code>[opc@instance-20220717-1620 ~]$ ping -c 2 2a01:4f8:121:24cc::102
PING 2a01:4f8:121:24cc::102(2a01:4f8:121:24cc::102) 56 data bytes
64 bytes from 2a01:4f8:121:24cc::102: icmp_seq=1 ttl=51 time=154 ms
64 bytes from 2a01:4f8:121:24cc::102: icmp_seq=2 ttl=51 time=154 ms

--- 2a01:4f8:121:24cc::102 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 153.966/154.042/154.118/0.076 ms
[opc@instance-20220717-1620 ~]$ 
</code></pre>

<p>However, from inside container 102, it can't ping its DNS servers, or the WAN.</p>

<pre><code>root@Proxmox-VE ~ # lxc-attach -n 102
~ # cat /etc/resolv.conf
# --- BEGIN PVE ---
search metalvps.com
nameserver 2a01:4ff:ff00::add:2
nameserver 2001:470:20::2
# --- END PVE ---
~ # ping6 -c 2 2a01:4ff:ff00::add:2
PING 2a01:4ff:ff00::add:2 (2a01:4ff:ff00::add:2): 56 data bytes

--- 2a01:4ff:ff00::add:2 ping statistics ---
2 packets transmitted, 0 packets received, 100% packet loss
~ # ping6 -c 2 2001:470:20::2
PING 2001:470:20::2 (2001:470:20::2): 56 data bytes

--- 2001:470:20::2 ping statistics ---
2 packets transmitted, 0 packets received, 100% packet loss
~ # ping6 -c 2 metalvps.com
ping6: bad address 'metalvps.com'
~ # ping6 -c 2 ipv6.google.com
ping6: bad address 'ipv6.google.com'
~ # exit
</code></pre>

<p>By contrast, from inside working container 106, we can ping both the DNS servers and the WAN.</p>

<pre><code>root@Proxmox-VE ~ # lxc-attach -n 106
~ # cat /etc/resolv.conf
# --- BEGIN PVE ---
search metalvps.com
nameserver 2a01:4ff:ff00::add:2
nameserver 2001:470:20::2
# --- END PVE ---
~ # ping6 -c 2 2a01:4ff:ff00::add:2
PING 2a01:4ff:ff00::add:2 (2a01:4ff:ff00::add:2): 56 data bytes
64 bytes from 2a01:4ff:ff00::add:2: seq=0 ttl=61 time=0.446 ms
64 bytes from 2a01:4ff:ff00::add:2: seq=1 ttl=61 time=0.274 ms

--- 2a01:4ff:ff00::add:2 ping statistics ---
2 packets transmitted, 2 packets received, 0% packet loss
round-trip min/avg/max = 0.274/0.360/0.446 ms
~ # ping6 -c 2 2001:470:20::2
PING 2001:470:20::2 (2001:470:20::2): 56 data bytes
64 bytes from 2001:470:20::2: seq=0 ttl=57 time=18.516 ms
64 bytes from 2001:470:20::2: seq=1 ttl=57 time=18.552 ms

--- 2001:470:20::2 ping statistics ---
2 packets transmitted, 2 packets received, 0% packet loss
round-trip min/avg/max = 18.516/18.534/18.552 ms
~ # ping6 -c 2 metalvps.com
PING metalvps.com (2603:c020:3:a9a9::250): 56 data bytes
64 bytes from 2603:c020:3:a9a9::250: seq=0 ttl=49 time=151.895 ms
64 bytes from 2603:c020:3:a9a9::250: seq=1 ttl=49 time=151.856 ms

--- metalvps.com ping statistics ---
2 packets transmitted, 2 packets received, 0% packet loss
round-trip min/avg/max = 151.856/151.875/151.895 ms
~ # ping6 -c 2 ipv6.google.com
PING ipv6.google.com (2a00:1450:4001:830::200e): 56 data bytes
64 bytes from 2a00:1450:4001:830::200e: seq=0 ttl=118 time=5.477 ms
64 bytes from 2a00:1450:4001:830::200e: seq=1 ttl=118 time=5.611 ms

--- ipv6.google.com ping statistics ---
2 packets transmitted, 2 packets received, 0% packet loss
round-trip min/avg/max = 5.477/5.544/5.611 ms
~ # 
</code></pre>

<h2><strong>Could The Firewall Cause This Problem?</strong></h2>

<p>The problem with container 102 probably is not a firewall drop egress issue because there aren't any egress rules in the container's zone and the default egress policy is ACCEPT. Also, the container's internal IPv6 egress problem still happens if container 102's firewall zone is set entirely off.</p>

<h2><strong>The <code>ip</code> Command</strong></h2>

<p>The <code>ip</code> command from the <a rel="nofollow" href="https://github.com/shemminger/iproute2">iproute2 suite</a> provides much information about Linux networking. As the <a rel="nofollow" href="https://man7.org/linux/man-pages/man8/ip.8.html">ip(8) man page</a> explains, we can use <code>ip</code> in the following syntax: <code>ip [OPTIONS] OBJECT { COMMAND | help }</code>. In other words, to use <code>ip</code> we need to specify three items: an OPTION, an OBJECT, and a COMMAND.</p>

<p>For IPv4, the usual OPTION is nothing because <code>ip</code> defaults to IPv4. But, if we wish to specify the IPv4 OPTION explicitly, the option could be specified as "-family inet". The IPv4 OPTION can be abbreviated to "ip -f inet" or just "ip -4".</p>

<p>For IPv6, we use the OPTION "ip -family inet6". The IPv6 OPTION can be abbreviated to "ip -f inet6" or just "ip -6".</p>

<p>The OBJECT can be, for example, "link", "address", or "route". A "link" is a hardware or virtualized interface connecting our machine to a network. The "address" is the numerical IP address or addresses we assigned to our link. The "route" is the IP address where the kernel should send network packets initiated by programs running on our machine. "link", "address", and "route" can be abbreviated as "l", "a", and "r", respectively. Longer abbreviations also work. For example, "addr" commonly is used as an abbreviation for "address".</p>

<p>Frequently, when something happens involving networking, it can be very helpful to check the output of the <code>ip</code> command. Let's look with the <code>ip</code> command and see what we can find!</p>

<h2><strong>The Error Message</strong></h2>

<p>Checking the output of the <code>ip -family inet6 address show</code> command inside container 102 reveals "tentative dadfailed" as follows.</p>

<pre><code>root@Proxmox-VE ~ # lxc-attach -n 102
~ # ip -f inet6 addr show
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 state UNKNOWN qlen 1000
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: eth0@if45: &lt;BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN&gt; mtu 1500 state UP qlen 1000
    inet6 2a01:4f8:121:24cc::102/64 scope global tentative dadfailed 
       valid_lft forever preferred_lft forever
    inet6 fe80::d8dd:65ff:fe45:70f2/64 scope link 
       valid_lft forever preferred_lft forever
~ # exit
root@Proxmox-VE ~ # 
</code></pre>

<p>Output of the same command from inside container 106 where networking works fine does not include "tentative dadfailed."</p>

<pre><code>root@Proxmox-VE ~ # lxc-attach -n 106
~ # ip -f inet6 addr show
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 state UNKNOWN qlen 1000
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: eth0@if28: &lt;BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN&gt; mtu 1500 state UP qlen 1000
    inet6 2a01:4f8:121:24cc::106/64 scope global 
       valid_lft forever preferred_lft forever
    inet6 fe80::64ce:78ff:fe85:15fd/64 scope link 
       valid_lft forever preferred_lft forever
~ # 
</code></pre>

<h2><strong>Dadfailed</strong></h2>

<p>Some quick googling found a page called <a rel="nofollow" href="https://blog.tankywoo.com/2013/09/27/ipv6-dadfailed-problem.html">IPv6 'dadfailed' Problem.</a>  The problem there involved reassigning an address previously assigned to another machine which failed without the address being deleted. However, down toward the bottom of the page, we find key information: the "dad" in "dadfailed" is "Duplicate Address Detection."</p>

<h2><strong>No Mistake With Container 102's Creation</strong></h2>

<p>But, even after reading about Duplicate Address Detection, I still did not immediately find the solution. I was puzzled about how, like the dadfailed page that Google showed me, some machine possibly could be down but with its address still present on my clean, new server with all its containers working fine except for this single itty bitty networking issue inside one container. Nothing was down. All the containers had their own addresses, and all the containers successfully started and continued running.</p>

<p>I kept looking and looking for some mistake I somehow might have made while setting up container 102. I checked and recheckd the screenshots that recorded container 102's creation. But everything looked okay!</p>

<p><img src="https://lowendspirit.com/uploads/editor/zo/uq2w7zhstjyi.png" alt="" title="" /></p>

<p><img src="https://lowendspirit.com/uploads/editor/gk/pb2vpmuj9ckg.png" alt="" title="" /></p>

<h2><strong>Asking For Help</strong></h2>

<p>Next I talked with a well known hosting provider about what was happening. I also wrote up a LES post asking for help with the puzzling  issue. It was starting to get late by the time I finished drafting the LES post. I decided to sleep. I deferred posting to LES Help until the next morning.</p>

<p>When I woke up, however, the idea was in my mind that possibly I mistakenly also had assigned the 102 address to another container. Such a mistake didn't seem likely, though, because there were only 8 containers, and the container numbers, 100, 101, 102, 103, 104, 105, 106, and 107 seemed understandable. I decided to check all the other containers besides 102 to make sure no additional container inadvertently and duplicatively also had been assigned the 102 address.</p>

<h2><strong>Checking All The Containers</strong></h2>

<ul>
<li><strong>Container 100</strong></li>
</ul>

<p>First I checked container 100. Container 100 was the test container that had been checked by <a href="https://staging.lowendspirit.com/index.php?p=/profile/yoursunny" rel="nofollow">@yoursunny</a> and found to be <a rel="nofollow" href="https://lowendspirit.com/discussion/comment/122229/#Comment_122229">"very strong."</a> Container 100 seemed to have been assigned the correct IP address ending in 100.</p>

<ul>
<li><strong>Container 101</strong></li>
</ul>

<p>Uh! Oh! Here it is! Container 101 got the 102 address!!</p>

<p><img src="https://lowendspirit.com/uploads/editor/oo/3dgabiigl86j.png" alt="" title="" /></p>

<p><img src="https://lowendspirit.com/uploads/editor/tm/q6vjyxdc2ve3.png" alt="" title="" /></p>

<h2><strong>How Did The Error Happen?</strong></h2>

<p>Container 101 was the second container that was created. Obviously it should have an IP address ending with 2, right? Well, not when the first address ended with 0. <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":)" alt=":)" height="18" /></p>

<h2><strong>What About The Node And WAN Responses To Ping?</strong></h2>

<p>How could container 102 respond to a ping from external WAN while seeming unable to initiate a ping to an external WAN destination? Container 101 already had been created with the 102 address. So, the ping responses came from container 101.</p>

<h2>How Do We Fix container 102?</h2>

<p>All that's needed to fix container 102 is to change its address to any that is not already in use. I tried the 101 address, and that address immediately worked fine. <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":)" alt=":)" height="18" /></p>

<h2>More Information About Dadfailed</h2>

<p>The <code>ip</code> command has a <a rel="nofollow" href="https://man7.org/linux/man-pages/man8/ip.8.html">manual page</a> which doesn't mention dadfailed. However, the <code>ip</code> man page refers to the <a rel="nofollow" href="https://man7.org/linux/man-pages/man8/ip-address.8.html"><code>ip-address</code></a> man page, which does mention dadfailed as an addition to the <code>ip address show</code> command.</p>

<pre><code>   ip address show - look at protocol addresses

        [ . . . ]

       dadfailed
              (IPv6 only) only list addresses which have failed duplicate ad‐
              dress detection.

       -dadfailed
              (IPv6 only) only list addresses which have not failed duplicate
              address detection.
</code></pre>

<p>For example, inside the Linux container on my Chromebook:</p>

<pre><code>chronos@penguin:~/log$ ip -6 address show dadfailed
chronos@penguin:~/log$ ip -6 address show -dadfailed
1: lo: &lt;LOOPBACK,UP,LOWER_UP&gt; mtu 65536 state UNKNOWN qlen 1000
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
5: eth0@if6: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt; mtu 1500 state UP qlen 1000
    inet6 fe80::216:3eff:fe43:22fb/64 scope link 
       valid_lft forever preferred_lft forever
chronos@penguin:~/log$ 
</code></pre>

<h2>Dadfailed In The RFCs</h2>

<p>Duplicate Address Detection failure is discussed in <a rel="nofollow" href="https://www.rfc-editor.org/rfc/rfc4862#section-5.4.5">section 5.4.5 of RFC 4862</a> which says:</p>

<blockquote><div>
  <p>5.4.5.  When Duplicate Address Detection Fails</p>
  
  <p>A tentative address that is determined to be a duplicate as described above MUST NOT be assigned to an interface, and the node SHOULD log a system management error.</p>
</div></blockquote>

<p>Further discussion of Duplicate Address Detection occurs in <a rel="nofollow" href="https://www.rfc-editor.org/rfc/rfc4862#appendix-A">Appendix A of RFC 4862</a> and in <a rel="nofollow" href="https://www.rfc-editor.org/rfc/rfc7527">RFC 7527 Enhanced Duplicate Address Detection.</a></p>

<h2>Dadfailed In The Logs</h2>

<p>Indeed, the node did log a system management failure just as RFC 4862 said it should:</p>

<pre><code>root@Proxmox-VE /var/log # zcat messages.2.gz | grep "duplicate address"
Jan 10 03:01:27 Proxmox-VE kernel: [97048.519242] IPv6: eth0: IPv6 duplicate address 2a01:4f8:121:24cc::102 used by 92:17:7a:22:c1:e2 detected!
[ . . . ]
Jan 13 06:44:36 Proxmox-VE kernel: [  141.636572] IPv6: eth0: IPv6 duplicate address 2a01:4f8:121:24cc::102 used by 92:17:7a:22:c1:e2 detected!
root@Proxmox-VE /var/log # 
</code></pre>

<h2>Source Code</h2>

<p>Recently I started to look at C source code. I don't know hardly anything about C, so looking at source code always is an adventure.</p>

<p>Above, we previously saw the <code>ip</code> command  print the following "dadfailed" output:</p>

<pre><code>~ # ip -f inet6 addr show
  [ . . . ]
2: eth0@if45: &lt;BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN&gt; mtu 1500 state UP qlen 1000
    inet6 2a01:4f8:121:24cc::102/64 scope global tentative dadfailed 
       valid_lft forever preferred_lft forever
  [ . . . ]
</code></pre>

<p>Can we find the source code which printed the dadfailed error? Finding the printing code sounds simple enough. Probably the printing code is nowhere near as complicated as the code which checked for and found the dadfailed error, right?</p>

<p>We saw the dadfailed error notification inside an Alpine container. Possibly that error notification came from iproute2 code running inside Busybox inside the Alpine container. Nevertheless, let's start by imagining how we might get the iproute2 source code that Proxmox itself uses. I'm unsure the method here gets the sources correctly, but we can try. First come the Proxmox sources, which seem to include the Debian sources, and then we get what might be the upstream sources.</p>

<pre><code>root@Proxmox-VE ~ # git clone git://git.proxmox.com/git/iproute2.git
Cloning into 'iproute2'...
remote: Enumerating objects: 187, done.
remote: Total 187 (delta 0), reused 0 (delta 0), pack-reused 187
Receiving objects: 100% (187/187), 11.25 MiB | 88.63 MiB/s, done.
Resolving deltas: 100% (83/83), done.
root@Proxmox-VE ~ # 
cd iproute2/
root@Proxmox-VE ~/iproute2 # ls
debian  iproute2  Makefile  README
root@Proxmox-VE ~/iproute2 # cat README 
We compile our own package to make sure we always have the
latest version and bug fixes.
root@Proxmox-VE ~/iproute2 # ls debian/
changelog  copyright          iproute2-doc.examples  iproute2.links     README.Debian  source
compat     doc                iproute2-doc.install   iproute2.manpages  README.source
control    iproute2-doc.docs  iproute2.install       patches            rules
root@Proxmox-VE ~/iproute2 # ls iproute2/ #The iproute2/iproute2 directory is empty.
root@Proxmox-VE ~/iproute2 # git clone git://git.kernel.org/pub/scm/network/iproute2/iproute2.git
Cloning into 'iproute2'...
remote: Enumerating objects: 313, done.
remote: Counting objects: 100% (313/313), done.
remote: Compressing objects: 100% (289/289), done.
remote: Total 33973 (delta 60), reused 37 (delta 20), pack-reused 33660
Receiving objects: 100% (33973/33973), 8.34 MiB | 42.06 MiB/s, done.
Resolving deltas: 100% (25490/25490), done.
root@Proxmox-VE ~/iproute2 # 
</code></pre>

<p>Let's look inside the iproute2/iproute2 directory and then inside the iproute2/iproute2/ip directory.</p>

<pre><code>root@Proxmox-VE ~/iproute2 # cd iproute2/
root@Proxmox-VE ~/iproute2/iproute2 # ls
bash-completion  COPYING  doc       genl     lib       misc   README        tc         vdpa
bridge           dcb      etc       include  Makefile  netem  README.devel  testsuite
configure        devlink  examples  ip       man       rdma   schema        tipc
root@Proxmox-VE ~/iproute2/iproute2 # cd ip
root@Proxmox-VE ~/iproute2/iproute2/ip # ls
ila_common.h           iplink.c            iplink_vlan.c    ipprefix.c          link_vti.c
ip6tunnel.c            iplink_can.c        iplink_vrf.c     iproute.c           link_xfrm.c
ipaddress.c            iplink_dsa.c        iplink_vxcan.c   iproute_lwtunnel.c  Makefile
ipaddrlabel.c          iplink_dummy.c      iplink_vxlan.c   iprule.c            nh_common.h
ip.c                   iplink_geneve.c     iplink_wwan.c    ipseg6.c            routel
ip_common.h            iplink_gtp.c        iplink_xdp.c     ipstats.c           rtm_map.c
ipfou.c                iplink_hsr.c        iplink_xstats.c  iptoken.c           rtmon.c
ipila.c                iplink_ifb.c        ipmacsec.c       iptunnel.c          static-syms.c
ipioam6.c              iplink_ipoib.c      ipmaddr.c        iptuntap.c          tcp_metrics.c
ipl2tp.c               iplink_ipvlan.c     ipmonitor.c      ipvrf.c             tunnel.c
iplink_amt.c           iplink_macvlan.c    ipmptcp.c        ipxfrm.c            tunnel.h
iplink_bareudp.c       iplink_netdevsim.c  ipmroute.c       link_gre6.c         xfrm.h
iplink_batadv.c        iplink_nlmon.c      ipneigh.c        link_gre.c          xfrm_monitor.c
iplink_bond.c          iplink_rmnet.c      ipnetconf.c      link_ip6tnl.c       xfrm_policy.c
iplink_bond_slave.c    iplink_team.c       ipnetns.c        link_iptnl.c        xfrm_state.c
iplink_bridge.c        iplink_vcan.c       ipnexthop.c      link_veth.c
iplink_bridge_slave.c  iplink_virt_wifi.c  ipntable.c       link_vti6.c
root@Proxmox-VE ~/iproute2/iproute2/ip # 
</code></pre>

<p>It was the address OBJECT which drew our interest, so let's look at <a rel="nofollow" href="https://git.kernel.org/pub/scm/network/iproute2/iproute2.git/tree/ip/ipaddress.c">ipaddress.c.</a></p>

<pre><code>root@Proxmox-VE ~/iproute2/iproute2/ip # cat -n ipaddress.c | grep dadfailed
    68                  "           [-]tentative | [-]deprecated | [-]dadfailed | temporary |\n"
  1411          { .name = "dadfailed",          .mask = IFA_F_DADFAILED,        .readonly = true,      .v6only = true},
root@Proxmox-VE ~/iproute2/iproute2/ip # 
</code></pre>

<p>Line 68 seems to be part of the error message which is printed when <code>ip</code> doesn't understand the arguments given to it on the command line.</p>

<p>If we back up from line 1411 to line 1400, we can see the comment reproduced here, just below. Also, a little further down, at lines 1451 and 1452, there's code involving both "print" and "name." I'm guessing that maybe lines 1451 and 1452 <em>might</em> be responsible for printing "tentative" and "dadfailed."</p>

<pre><code>  1400  /* Mapping from argument to address flag mask and attributes */
  1401  static const struct ifa_flag_data_t {
  [ . . . ]
  1411          { .name = "dadfailed",          .mask = IFA_F_DADFAILED,        .readonly = tru
e,       .v6only = true},
  [ . . . ]
  1414          { .name = "tentative",          .mask = IFA_F_TENTATIVE,        .readonly = tru
e,       .v6only = true},
  [ . . . ]
  1451                                  print_string(PRINT_FP, NULL,
  1452                                               "%s ", flag_data-&gt;name);
</code></pre>

<p>Finally, glancing at the Busybox <code>ip</code> command, the relevant source code seems to be <a rel="nofollow" href="https://git.busybox.net/busybox/tree/networking/ip.c">ip.c.</a> The usage message for <code>ip address show</code> is on lines 139 to 149.</p>

<pre><code>139  //usage:#define ipaddr_trivial_usage
140  //usage:       "add|del IFADDR dev IFACE | show|flush [dev IFACE] [to PREFIX]"
141  //usage:#define ipaddr_full_usage "\n\n"
142  //usage:       "ipaddr add|change|replace|delete dev IFACE [CONFFLAG-LIST] IFADDR\n"
143  //usage:       "   IFADDR := PREFIX | ADDR peer PREFIX [broadcast ADDR|+|-]\n"
144  //usage:       "       [anycast ADDR] [label STRING] [scope SCOPE]\n"
145  //usage:       "   PREFIX := ADDR[/MASK]\n"
146  //usage:       "   SCOPE := [host|link|global|NUMBER]\n"
147  //usage:       "   CONFFLAG-LIST := [CONFFLAG-LIST] CONFFLAG\n"
148  //usage:       "   CONFFLAG := [noprefixroute]\n"
149  //usage:       "ipaddr show|flush [dev IFACE] [scope SCOPE] [to PREFIX] [label PATTERN]"
</code></pre>

<p>There is more on lines 341 to 347.</p>

<pre><code>341  #if ENABLE_IPADDR
342  int ipaddr_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
343  int ipaddr_main(int argc UNUSED_PARAM, char **argv)
344  {
345     return ip_do(do_ipaddr, argv);
346  }
347  #endif
</code></pre>

<p><code>ip_do</code> is defined on lines 334 to 338.</p>

<pre><code>334  static int ip_do(ip_func_ptr_t ip_func, char **argv)
335  {
336     argv = ip_parse_common_args(argv + 1);
337     return ip_func(argv);
338  }
</code></pre>

<p>Hopefully I soon will be able to understand more about how the iproute2 and Busybox code works to print the dadfailed error. Probably someone here at LES will be kind enough to provide some hints! Thanks very much! It is a lot of fun to learn a little about dadfailed! <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":)" alt=":)" height="18" /></p>
]]>
        </description>
    </item>
    <item>
        <title>Best way to install Nextcloud</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5394/best-way-to-install-nextcloud</link>
        <pubDate>Thu, 02 Feb 2023 20:16:16 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>imok</dc:creator>
        <guid isPermaLink="false">5394@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>I'm thinking about installing Nextcloud to manage my photos and some documents.</p>

<p>Do you recommend using the PHP installer or Docker? I don't know that much about Docker, but shouldn't be that hard.</p>

<p>What's the best method to install, maintain and highly possible migrate later?</p>
]]>
        </description>
    </item>
    <item>
        <title>Has anyone seen weirdness with proxmox guests using 100% CPU for no reason?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5267/has-anyone-seen-weirdness-with-proxmox-guests-using-100-cpu-for-no-reason</link>
        <pubDate>Mon, 16 Jan 2023 10:13:33 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>ralf</dc:creator>
        <guid isPermaLink="false">5267@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>So, bit of a weird question this, and not really sure I've got enough information to go on, but thought I'd ask anyway...</p>

<p>So, my two dedis are running manually set-up VMs, that I've set up using virsh and made my own script to create cloud-init configs, etc. Neither of these machines ever seem to have any problems with the VMs.</p>

<p>But when I upgraded my home network to use fibre, I decided to get one of those multi-port NUCs, and run pfSense (FreeBSD) virtualised on the free version of proxmox, which was set up with pretty much the default configuration, and following the guide from STH. This pfSense instance has been 100% reliable, never had any downtime with it.</p>

<p>But I also decided to make use of the spare capacity with a couple of smaller VMs, the main one being an extra borg backup destination for my most critical VMs from the dedis, but also a couple of ancillary ones that get very little use e.g. a proxy to a site that requires a whitelisted IP, so it uses wireguard to make a tunnel to one of my dedis, and an SSH jump host into my home network (that the borg clients use).</p>

<p>Now, all of these VMs have very little use, and so I don't often notice when they have issues (apart from borg which would trigger an email when the client fails to backup), so I don't know exactly when they fail, but sometimes after a couple of weeks of not really doing much, the CPU on these instances will suddenly jump to 100% and the machine won't respond to pings or input on the (serial) console. Interestingly, it's usually not borg that this happens to, but the really idle machines that are basically just forwarding things.</p>

<p>Anyway, when this happens, it seems like it's using 100% CPU, but it seems like the linux kernel itself isn't even running as it doesn't even respond to pings. The only solution is to connect to the proxmox interface, and force a stop/reset. The safer reboot/shutdown options are ignored, and because that just sends an ACPI event to the client.</p>

<p>Today, this just happened while I happened to the borg instance while I was able to jump on the proxmox interface to examine it, and it looks like the load suddenly jumped up while extra disk space was being allocated to the VM (proxmox seems to use these LVM sparse / lite volumes, which is the main difference between the instances on my dedis which are all allocated space using a pre-allocated volume group).</p>

<p>Now, the graphs only seem to have minute accuracy, but first jump in disk allocation corresponded to the start of the CPU spike from 0% to 50% (which is understandable as the borg server was actually doing something) and spike in network traffic, a minute later CPU hits 90% and traffic increases more, and another minute later, CPU is still 90%, traffic hits it maximum and the disk allocation increases again. The next minute, CPU is stuck at 100%, and network traffic is negligible (presumably ssh retrying to connect), and zero the minute after that.</p>

<p>So now my theory is that maybe this random proxmox thing is being triggered whenever a LVM lite allocation is increased, maybe because of logging, log rotation, or something else. Mostly, I'm concluding this as I've changed everything about the virtual hardware on these machines, so no matter what disk type, video card type, network card type, they all seem to end up like this stuck CPU state at some random point. Of course, it <em>could</em> just be a genuine hardware issue, but the fact that the pfsense instance has been rock solid (only rebooted once in the 7 months I've been using this setup, and that was because I moved the router to a new location and had to unplug it) makes me think there's some weirdness with proxmox itself...</p>

<p>There's no real reason for proxmox to be trying to use sparse LVM volumes anyway, as I've only allocated about half my 500G SSD to VMs, but it was the default setting when I set it up, so I left it alone.</p>

<p>Has anyone else seen weirdness like this in proxmox before? Or just as valid feedback, do most people just use the sparse LVM allocation and have no issues at all?</p>
]]>
        </description>
    </item>
    <item>
        <title>Share some Monster Benches</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/426/share-some-monster-benches</link>
        <pubDate>Tue, 31 Dec 2019 09:53:14 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>cybertech</dc:creator>
        <guid isPermaLink="false">426@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Let's start off with the beast:</p>

<pre><code>---------------------------------------------------------------------------   
OS           : CentOS 7.7.1908 (64 Bit)
 Virt/Kernel  : KVM / 5.4.5-1.el7.elrepo.x86_64
 CPU Model    : AMD Ryzen 7 3700X 8-Core Processor
 CPU Cores    : 2 @ 3593.248 MHz x86_64 512 KB Cache
 CPU Flags    : AES-NI Enabled &amp; VM-x/AMD-V Disabled
 Load Average : 0.00, 0.00, 0.00
 Total Space  : 18G (13G ~67% used)
 Total RAM    : 1990 MB (679 MB + 912 MB Buff in use)
 Total SWAP   : 2047 MB (0 MB in use)
 Uptime       : 11 days 7:18
---------------------------------------------------------------------------
 ASN &amp; ISP    : AS24940, Hetzner Online GmbH
 Organization :
 Location     : Falkenstein, Germany / DE
 Region       : Saxony
---------------------------------------------------------------------------

 ## Geekbench v4 CPU Benchmark:

  Single Core : 5170  (EXCELLENT)
   Multi Core : 9023

 ## IO Test

 CPU Speed:
    bzip2     : 136 MB/s
   sha256     :   1.4 GB/s
   md5sum     : 658 MB/s

 RAM Speed:
   Avg. write : 3072.0 MB/s
   Avg. read  : 8908.8 MB/s

 Disk Speed:
   1st run    : 1.7 GB/s
   2nd run    : 2.4 GB/s
   3rd run    : 2.4 GB/s
   -----------------------
   Average    : 2218.7 MB/s

 ## Global Speedtest

 Location                       Upload           Download         Ping
---------------------------------------------------------------------------
 Speedtest.net                  901.30 Mbit/s    878.05 Mbit/s    3.25 ms
 USA, New York (AT&amp;T)           144.94 Mbit/s    125.09 Mbit/s   103.261 ms
 USA, Chicago (Windstream)      187.46 Mbit/s    110.34 Mbit/s   101.268 ms
 USA, Dallas (Frontier)         152.66 Mbit/s    168.53 Mbit/s   124.391 ms
 USA, Miami (Frontier)          168.47 Mbit/s    161.24 Mbit/s   113.602 ms
 USA, Los Angeles (Spectrum)    131.42 Mbit/s    148.38 Mbit/s   151.154 ms
 UK, London (Community Fibre)   580.25 Mbit/s    536.88 Mbit/s    19.524 ms
 France, Lyon (SFR)             510.47 Mbit/s    343.03 Mbit/s    19.664 ms
 Germany, Berlin (DNS:NET)      595.07 Mbit/s    649.75 Mbit/s    18.254 ms
 Spain, Madrid (MasMovil)       470.36 Mbit/s    508.52 Mbit/s    29.368 ms
 Italy, Rome (Unidata)          350.80 Mbit/s    363.33 Mbit/s    47.221 ms
 Israel, Haifa (013Netvision)   284.63 Mbit/s    292.39 Mbit/s    58.202 ms
 India, New Delhi (GIGATEL)     136.84 Mbit/s    285.17 Mbit/s   132.552 ms
 Singapore (FirstMedia)         39.11 Mbit/s     36.78 Mbit/s    170.950 ms
 Japan, Tsukuba (SoftEther)     18.34 Mbit/s     60.18 Mbit/s    250.445 ms
 Australia, Sydney (Yes Optus)  19.22 Mbit/s     16.35 Mbit/s    291.932 ms
 RSA, Randburg (Cool Ideas)     84.76 Mbit/s     219.46 Mbit/s   188.881 ms
 Brazil, Sao Paulo (Criare)     79.18 Mbit/s     206.16 Mbit/s   192.480 ms
---------------------------------------------------------------------------

 Finished in : 9 min 16 sec
</code></pre>
]]>
        </description>
    </item>
    <item>
        <title>Storing Grafana Loki log data in a Google Cloud Storage bucket</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5117/storing-grafana-loki-log-data-in-a-google-cloud-storage-bucket</link>
        <pubDate>Sun, 25 Dec 2022 18:44:43 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>vitobotta</dc:creator>
        <guid isPermaLink="false">5117@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>In case anyone is interested, I wrote a post on how I got Loki to store logs in a GCS bucket instead of persistent volumes, so I can store unlimited amounts of logs indefinitely.</p>

<p><a href="https://vitobotta.com/2022/12/25/storing-grafana-loki-log-data-in-a-google-cloud-storage-bucket/" rel="nofollow">https://vitobotta.com/2022/12/25/storing-grafana-loki-log-data-in-a-google-cloud-storage-bucket/</a></p>

<p>Happy holidays!</p>
]]>
        </description>
    </item>
    <item>
        <title>[HOWTO] Setup AMD iGPU passthrough with VirtFusion</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5084/howto-setup-amd-igpu-passthrough-with-virtfusion</link>
        <pubDate>Sun, 18 Dec 2022 23:45:56 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>webcraft</dc:creator>
        <guid isPermaLink="false">5084@/index.php?p=/discussions</guid>
        <description><![CDATA[<h1>iGPU passthrough with VirtFusion</h1>

<p>I've spend quite a lot of time setting up iGPU passthrough with an AMD processor. It was super easy with Intel's iGPU (VT-d) but not that easy with a Ryzen APU. Also thanks a lot for <a href="https://staging.lowendspirit.com/index.php?p=/profile/VirtFusion" rel="nofollow">@VirtFusion</a> for your efforts to implement such functionalities. In general this works quite similar with an external GPU or any other PCIe device, you just need to regroup the iommo-groups.</p>

<h1>Guide</h1>

<h2>Enable IOMMU in Motherboard UEFI</h2>

<p>As a first step, make sure that iommo is enabled in your motherboard's uefi. It should be really enabled and not in auto mode because I noticed that for some motherboards (e.g. MSI) auto doesn't work for some reason but enabled does.</p>

<h2>Install OS and VirtFusion</h2>

<p>Perform an installation from ISO without desktop environment (in theory you can use it along with a desktop programm but this will install packages which interfer with our setup). Install VirtFusion and configure networking and everything as described in their docs. Do not create a VM however. Also install <code>pciutils</code> which might not be part of a default installation but we'll need it later.</p>

<h2>Server setup</h2>

<p>Now comes the actual part of the passthrough procedure.<br />
The hypervisor may not load any drivers that activate the iGPU because the iGPU can only be accessed by one driver per startup. We need to tell the hypervisor kernel to not load any video modules by appending the following to the line <code>GRUB_CMDLINE_LINUX_DEFAULT=</code>:</p>

<pre><code># nano /etc/default/grub

amd_iommu=on initcall_blacklist=sysfb_init video=simplefb:off video=vesafb:off video=efifb:off video=vesa:off disable_vga=1 textonly vfio_iommu_type1.allow_unsafe_interrupts=1 kvm.ignore_msrs=1 modprobe.blacklist=amdgpu,snd_hda_intel
</code></pre>

<p>Not all those flags might be necessary but they usually don't have any negative effects if they're set though they're not needed.<br />
In a next step we need to load vfio drivers which are used as passthrough drivers that host the iGPU as device in the virtual machine later.</p>

<p>DEBIAN</p>

<pre><code> # nano /etc/modules

 vfio
 vfio_iommu_type1
 vfio_pci
 vfio_virqfd
</code></pre>

<p>RHEL</p>

<pre><code> # vi /etc/modules-load.d/vfio-pci.conf

 vfio
 vfio_iommu_type1
 vfio-pci
 vfio_virqfd
</code></pre>

<p>Then we need to tell vfio which devices it should pass through. You can look up the device IDs of the iommo-group through pciutils with <code>lscpi -nnv</code>. Note that you have to list the IDs of all devices of the iommo-group to be passed on even if you don't use the sound device for instance.</p>

<pre><code># nano /etc/modprobe.d/vfio.conf

options vfio-pci ids=1002:1863,1002:1864
</code></pre>

<p>Then we update the grup config to reflect the new settings and restart the server:</p>

<pre><code>update-grub2 (RHEL: grub2-mkconfig -o /boot/grub2/grub.cfg)
update-initramfs -u -k all
reboot now
</code></pre>

<p>To verify you were successfull, run <code>lspci -nnv</code> and scroll down until you find your VGA compatible device and Audio device. If it says <code>Kernel driver in use: vfio-pci</code> you're all set.</p>

<h2>VirtFusion setup</h2>

<p>After having configured the hypervisor, it's time to create our first virtual machine in VirtFusion and configure it to use the iGPU through the previously created vfio virtual-devices.<br />
It may work with seabios (VirtFusion: "SMBIOS") and i440FX (VirtFusion: "PC") but only on compatibility layer hence we use Q35 (which supports PCIe and not only PCI like i440FX) and UEFI (because the vbios, see below, will be available for UEFI only on modern systems).<br />
<img src="https://lowendspirit.com/uploads/editor/5s/yco3jg71es5f.jpg" alt="" title="" /></p>

<p>The environmental variables of the virtual machine are now configured to work with vfio and an optional modern vbios. You can extract the vbios from the bios file of your motherboard vendor with e.g. GPU-Z. I've stored my vbios of the APU in this example at <code>/usr/share/kvm/vbios-cezanne.bin</code>.<br />
In order to make libvirt create the hostdevice for us, we need to configure it in the corresponding fields in VirtFusion. For compatibility reasons you can hide the kvm status but this isn't mendatory. Make sure to adapt the iommu-group number and the functions id to the one of your config. You get the values with <code>lscpi -nnv</code>.</p>

<pre><code>&lt;hostdev mode="subsystem" type="pci" managed="yes"&gt;
    &lt;driver name="vfio"/&gt;
    &lt;source&gt;
        &lt;address type="pci" domain="0x0000" bus="0x20" slot="0x00" function="0x0"/&gt;
    &lt;/source&gt;
    &lt;address type="pci" domain="0x0000" bus="0x00" slot="0x8" function="0x0"/&gt;
    &lt;rom bar="on" file="/usr/share/kvm/vbios-cezanne.bin"/&gt;
&lt;/hostdev&gt;
</code></pre>

<p><img src="https://lowendspirit.com/uploads/editor/nv/psojd1d1xem8.jpg" alt="" title="" /></p>

<p>Enable the custom elements you've filled out and update the config. Then restart the virtual machine.<br />
Do not assign a PCIe device (in this case the iGPU) to more than one virtual machine at a time or you'll get permission errors from vfio or driver errors.<br />
<strong>That's it.</strong> I hope this guide is helpful to you.</p>
]]>
        </description>
    </item>
    <item>
        <title>Regarding questions about KVM guest agent</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5056/regarding-questions-about-kvm-guest-agent</link>
        <pubDate>Mon, 12 Dec 2022 10:50:07 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>System</dc:creator>
        <guid isPermaLink="false">5056@/index.php?p=/discussions</guid>
        <description><![CDATA[This discussion was created from comments split from: <a rel="nofollow" href="/discussion/5039/take-by-storm/">Take By Storm</a>.]]>
        </description>
    </item>
    <item>
        <title>Blesta DirectAdmin module problem - SOLVED</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5015/blesta-directadmin-module-problem-solved</link>
        <pubDate>Mon, 05 Dec 2022 11:25:26 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>bikegremlin</dc:creator>
        <guid isPermaLink="false">5015@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Last time I used the DirectAdmin module was about a year ago or so. It used to work.</p>

<p>Now, I have been able to configure the cPanel module, and it works fine.<br />
However, I'm not able to get the DirectAdmin module to load the created user packages (as shown in the attached screenshot).</p>

<p>I've tried disabling the SSL option in the module configuration - and that didn't help. <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/frown.png" title=":(" alt=":(" height="18" /></p>

<p>I have double checked the server hostname and login credentials - they work outside of Blesta with no problems.</p>

<p>PHP 7.4<br />
Blesta: 5.5.3<br />
Module: DirectAdmin 2.15.0</p>

<p>I suspect it's related to Blesta. Maybe it's just the interface. I've tried to get it to work now with MyW hosting, HostMantis, and with MXroute DA reseller.</p>

<p>Maybe DA did something during one of the updates. Maybe it's Blesta. Of course, it could always be some mistake on my part, but Google, Blesta, DirectAdmin (and MXroute for that matter) tutorials dosc and info aren't helping.  <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/frown.png" title=":(" alt=":(" height="18" /></p>

<p>Here's a screenshot of the problem:<br />
<img src="https://lowendspirit.com/uploads/editor/1m/faf91uwd4koq.png" alt="" title="" /></p>

<p>I have also tried removing the Group, as well as choosing the "Any" option for the group. No help.</p>
]]>
        </description>
    </item>
    <item>
        <title>Set up VPS for incoming email only - best practices?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/5012/set-up-vps-for-incoming-email-only-best-practices</link>
        <pubDate>Sun, 04 Dec 2022 22:01:21 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>JDMcPea</dc:creator>
        <guid isPermaLink="false">5012@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Looking for the best way to enable incoming only email on a low end/low resource VPS. Daily emails received will likely be below 50 average.</p>

<p>Have searched online for tutorials but no luck finding something I can use. A common suggestion is just to set up a regular email server and block port for outgoing emails but am looking for the lightest weight solution.</p>

<p>Plan on using Thunderbird from home PC to view and archive and it's already set up with reputable third party for sending email. I should be able enable Dovecot, Postflix, Fetchmail, Qmail, Procmail Mail Filter, SpamAssasin Mail filter, and ClamAV with a couple mouse clicks in control panel, as needed.</p>

<p>If anyone is using a VPS for incoming mail only please let me know what worked best for you, what settings you use, and what I should avoid. If anyone knows of any good tutorials for doing this geared toward less experienced users would appreciate the info.</p>
]]>
        </description>
    </item>
    <item>
        <title>Subdomains and website database</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/4992/subdomains-and-website-database</link>
        <pubDate>Fri, 02 Dec 2022 01:43:01 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>JDMcPea</dc:creator>
        <guid isPermaLink="false">4992@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>I've got an eCommerce site that I plan on adding a blog and a photo gallery to on the same VPS. Same domain.</p>

<p>So the store would be mysite.com and blog would be blog.mysite.com and gallery would be gallery.mysite.com.</p>

<p>In a case like this is it best to use the same database for all three?  And just use prefixes like bl_ and ga_ for the blog and gallery database tables?  The database for the store currently does not use prefixes.</p>

<p>Any reason to use/not use subdomains?</p>

<p>Advice, tips, suggestions appreciated.</p>
]]>
        </description>
    </item>
    <item>
        <title>Selling a 15 GB download?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/4866/selling-a-15-gb-download</link>
        <pubDate>Thu, 10 Nov 2022 19:58:30 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>bikegremlin</dc:creator>
        <guid isPermaLink="false">4866@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Our (Serbian) government has some really shitty software.<br />
Everyone who runs a company, or has anything to do with the government (taxes etc.) has to use it.</p>

<p>It runs properly only on Windows 10, and is a real hassle to configure.</p>

<p>I managed to make a VirtualBox machine that is installed, configured and ready to work (unactivated Win10, so anyone can activate it with their own Win key).</p>

<p>It's a 50 GB instance, that gets 7z-ed to a 13.5 GB file.</p>

<p>Now, how can I distribute it?<br />
I wouldn't mind charging for it (I suppose any infrastructure for it would cost money, for bandwidth if nothing else).<br />
But I wouldn't mind sharing it for free if there are no costs for me.</p>

<p>I expect a relatively steep rise of downloads, that will taper off to a low number of downloads over time.<br />
A few thousands in total, I suppose (maybe more, maybe less).</p>

<p>Of course, it's possible that no one will download it, ever - lol.  <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":)" alt=":)" height="18" /></p>
]]>
        </description>
    </item>
    <item>
        <title>What are some useful commands that you discovered or learnt on the terminal?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/4844/what-are-some-useful-commands-that-you-discovered-or-learnt-on-the-terminal</link>
        <pubDate>Mon, 07 Nov 2022 11:41:38 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>evnix</dc:creator>
        <guid isPermaLink="false">4844@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>as for me, it has been,</p>

<p>history | grep searchTerm</p>

<p>ctrl+a and ctrl+e move to the beginning or end of the line.</p>

<p>also, installing fzf was a massive productivity booster while doing things like ctrl+r (<a rel="nofollow" href="https://www.youtube.com/watch?v=qgG5Jhi_Els" title="https://www.youtube.com/watch?v=qgG5Jhi_Els">https://www.youtube.com/watch?v=qgG5Jhi_Els</a>)</p>

<p><strong>Update:</strong></p>

<p>I 'll use the comments below to write a summary article here, these might be more useful than random commands on the web as these are likely heavily used by the community here.</p>

<p>search through history:</p>

<p><code>history | grep searchTerm</code></p>

<p>Install <code>fzf</code> to introduce partial/fuzzy search for history, files etc.</p>

<p><code>ctrl+a</code> and <code>ctrl+e</code> move to the beginning or end of the line.</p>

<p><code>ctrl+LEFT|RIGHT arrow</code> to jump words</p>

<p><code>CTRL+L</code> clear screen</p>

<p><code>TAB</code> for autocomplete</p>

<p><code>fdupes -Sr .</code> FDUPES is a program for identifying duplicate files residing<br />
within specified directories.</p>

<p><code>jdupes</code> a faster fdupes</p>

<p><code>ncdu</code>  to work out where all the storage space went</p>

<p><code>tldr &lt;command&gt;</code> an easy to read manpage</p>

<p><code>last reboot</code> Shows reboot history</p>

<p><code>findmnt -l</code> list all mounts</p>

<p><code>iftop</code> realtime bandwidth monitoring</p>

<p><code>iostat -m 10</code> report to better balance the input/output load between physical disks</p>

<p><code>ss -tupan</code> socket statistics.</p>

<p><code>scp localFilePath user@remote:/remote/file/path</code> remote file transfer.</p>

<p><code>nload</code> - shows per interface network usage live on a graph on your terminal.</p>

<p><strong>Cool Stuff:</strong></p>

<pre><code>telnet 2001:7b8:666:ffff::1:42
</code></pre>

<p>Won't tell you what it is, but it is safe.</p>

<pre><code>ani-cli animename episode
</code></pre>

<p>watch anime on the terminal</p>

<p><code>apt-get install sl sl</code><br />
cures bad habit of mistyping ls</p>

<p><strong>Combinations:</strong></p>

<pre><code>zfs send -w tank/dana@snap1 | ssh host2 zfs recv newtank/dana
</code></pre>

<p>ZFS send and recv.</p>

<pre><code>du -k ./* | sort -nr | cut -f2 | xargs -d '\n' du -sh | less
</code></pre>

<p>useful for debugging diskspace</p>

<pre><code>ls -a; uptime; exit
</code></pre>

<p><code>ps -C sshd o user,pid,comm,lstart</code> as alternative to <code>who</code></p>

<p>On a tmux session, open multiple panes, then do this:<br />
<code>Ctrl+B, Shift+;</code></p>

<p>Then type: <code>setw sync on</code> All panes will now type the same thing</p>

<p>type <code>setw sync off</code> to turn it off again.</p>

<p>*sh aliases: <a href="https://tldp.org/LDP/abs/html/aliases.html" rel="nofollow">https://tldp.org/LDP/abs/html/aliases.html</a></p>

<p><strong>external Tools:</strong><br />
<a href="https://doublecmd.sourceforge.io/" rel="nofollow">https://doublecmd.sourceforge.io/</a><br />
<a href="https://github.com/junegunn/fzf" rel="nofollow">https://github.com/junegunn/fzf</a><br />
<a href="https://github.com/nvbn/thefuck" rel="nofollow">https://github.com/nvbn/thefuck</a> - auto corrects last command<br />
<a href="https://github.com/kellyjonbrazil/jc" rel="nofollow">https://github.com/kellyjonbrazil/jc</a> - terminal output as json<br />
<a href="http://www.figlet.org/" rel="nofollow">http://www.figlet.org/</a> - text to ascii<br />
<a href="https://books.goalkicker.com/BashBook/" rel="nofollow">https://books.goalkicker.com/BashBook/</a> - there are other good books there</p>

<p>Contributors: <a href="https://staging.lowendspirit.com/index.php?p=/profile/jperkins" rel="nofollow">@jperkins</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/typicalGta" rel="nofollow">@typicalGta</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/xleet" rel="nofollow">@xleet</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/ralf" rel="nofollow">@ralf</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/CamoYoshi" rel="nofollow">@CamoYoshi</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/Neoon" rel="nofollow">@Neoon</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/ehab" rel="nofollow">@ehab</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/legendary" rel="nofollow">@legendary</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/hornet" rel="nofollow">@hornet</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/shallow" rel="nofollow">@shallow</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/Ympker" rel="nofollow">@Ympker</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/Encoders" rel="nofollow">@Encoders</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/iansss" rel="nofollow">@iansss</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/Mumbly" rel="nofollow">@Mumbly</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/msatt" rel="nofollow">@msatt</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/cold" rel="nofollow">@cold</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/Calin" rel="nofollow">@Calin</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/g4m3r" rel="nofollow">@g4m3r</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/havoc" rel="nofollow">@havoc</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/vyas" rel="nofollow">@vyas</a> <a href="https://staging.lowendspirit.com/index.php?p=/profile/TheDP" rel="nofollow">@TheDP</a></p>

<p>Thanks for all the contributions <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":smile:" alt=":smile:" height="18" /></p>
]]>
        </description>
    </item>
    <item>
        <title>How to setup a correct subdomain for email hosting?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/4855/how-to-setup-a-correct-subdomain-for-email-hosting</link>
        <pubDate>Wed, 09 Nov 2022 10:46:55 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>frakass</dc:creator>
        <guid isPermaLink="false">4855@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Last day I won a domain auction from LET for which I setup a mail hosting using the subdomain "mail.crypt.pw". Here is the guide:<br />
<a href="https://notes.199903.xyz/how-to-setup-subdomain-on-xyamail-hosting" rel="nofollow">https://notes.199903.xyz/how-to-setup-subdomain-on-xyamail-hosting</a></p>

<p>Simply to say we should have four DNS records setup correctly to make the email hosting work as expected. Though this guide is using the mail hosting by ourselves, but the theory is almost the same for every provider. Thanks. <img src="https://staging.lowendspirit.com/plugins/emojiextender/emoji/twitter/smile.png" title=":)" alt=":)" height="18" /></p>
]]>
        </description>
    </item>
    <item>
        <title>Adguard - DNS Amplification Issues - HELP ( SOS )</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/2892/adguard-dns-amplification-issues-help-sos</link>
        <pubDate>Sat, 08 May 2021 13:10:24 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>deepak_leb</dc:creator>
        <guid isPermaLink="false">2892@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Dear Les-bians,</p>

<p>Greeting, Hope Everyone is safe and sound in good shape.<br />
\</p>

<p>Well, Recently I installed a  Adguard + Wireguard on a VPS Server. To my suprise am getting New Spam Clients from China and Some other Countries.</p>

<p>Especaillay pizzaseo .com&amp; other clients.</p>

<p>So, kindly say how to stop these, and let me get to know that what i have messed up.</p>
]]>
        </description>
    </item>
    <item>
        <title>Linux Mint 19.3 Refuses to Boot With AMDGPU Drivers (will displays blank screen) Tried Lots!</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/4724/linux-mint-19-3-refuses-to-boot-with-amdgpu-drivers-will-displays-blank-screen-tried-lots</link>
        <pubDate>Mon, 17 Oct 2022 22:50:45 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>Havy</dc:creator>
        <guid isPermaLink="false">4724@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>I really don't get it at all. <strong>Tried everything</strong> from changing between kernels, Updating ASUS PRIME's Firmware to the LATEST, SSDs and EVEN installing Linux Mint 21 (after updating everything of course with same results!).</p>

<p>If it doesn't boots into software drivers (Compatibility/Advanced) I can't boot it.</p>

<p>Here is my paste.gg for the two times I tried booting it <a href="https://paste.gg/p/anonymous/8416287828884071877cb928529861b8" rel="nofollow">https://paste.gg/p/anonymous/8416287828884071877cb928529861b8</a></p>

<p>Is anybody able to help me troubleshoot this further on what this might be coming from??</p>
]]>
        </description>
    </item>
    <item>
        <title>Any providers which enable enclaves on VPS ?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/4703/any-providers-which-enable-enclaves-on-vps</link>
        <pubDate>Wed, 12 Oct 2022 21:28:50 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>erk</dc:creator>
        <guid isPermaLink="false">4703@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>It seems that from a hardware level, enclaves are supported on typical hardware</p>

<ul>
<li>E5-2680 should have SGX under KVM</li>
<li>EPYC 7543P seems like there is SEV support for KVM</li>
</ul>

<p>Informally on a small number of hosts I haven't seen these enabled...<br />
Is there a reason that these are usually disabled ?<br />
Is it just too much of a niche feature for it to be set in Proxmox?</p>
]]>
        </description>
    </item>
    <item>
        <title>Options for sharing accumulated VPS storage space as a single volume?</title>
        <link>https://staging.lowendspirit.com/index.php?p=/discussion/4630/options-for-sharing-accumulated-vps-storage-space-as-a-single-volume</link>
        <pubDate>Sat, 24 Sep 2022 22:18:12 +0000</pubDate>
        <category>Technical</category>
        <dc:creator>wankel</dc:creator>
        <guid isPermaLink="false">4630@/index.php?p=/discussions</guid>
        <description><![CDATA[<p>Hi all,</p>

<p>One way or another I ended up with a <em>very reasonable</em> (quite sure it's still single digits) number of VPN's. Most of them got more storage space than needed, but a couple could use some more space.</p>

<p>Is there a 'best' way to create some JBOD-like storage on one of my VPS out of left over bits of other VPS's?</p>

<p>I love SSHFS and use it to bolt all kinds of things together. It gives separate directories for each mount point, so with 5 VPS's that have 2 GB left, I can create 5 separate directories on the 6th server. Is there a way to homogenize those into a single 10 GB directory or volume?</p>

<p>I hardly have any experience with NFS or iSCSI, I think those won't be happy with the relatively high latency between hosts. Would an open source S3 storage framework work? Would Ceph or Gluster give what I look for?</p>

<p>The storage is mostly needed for Nextcloud. It doesn't need to be very fast. All VPS's run Debian.</p>
]]>
        </description>
    </item>
   </channel>
</rss>
