Thursday, March 9, 2017
I am a terrible blogger.. that is all
My first inclination is to leave it and learn from it, if anything it makes me laugh.
Wednesday, July 29, 2015
Fighting with Java SSL and Confluence
The Error:
Connection test failed. Response from the server:
ldaps.example.com:636; nested exception is javax.naming.CommunicationException: ldaps.example.com:636 [Root exception is javax.net.ssl.SSLHandshakeException: java.security.cert.CertificateException: No subject alternative names matching IP address 172.0.0.20 found]
Some notes:
* Does not happen when using java 1.8.0_45 (Java 8 u45)
* I ran into problem when using java 1.8.0_51 (Java 8 u51)
* Running Atlassian Confluence 5.8.4 on EL6
Updates To Follow:
Monday, January 5, 2015
What do you mean "it's in production"?
What do you mean "it's in production"?
Short Story:
To many groups use the word "production" and that word changes meaning and risk depending on the group in question.Long Story:
Our usage of the term "production" leads to some issues as it changes context based on audience. Operations can look at "production" as a matter of state where as Development may see it as a function or environment. To confuse matters worse Ops may also refer to it as an environment given it's history of working with Dev.An example of the issue is demonstrated by a common statement.
Jane: I show server prodX is down, whats going on?Jane may be reasonably confused by Johns statement. What does John mean by the server is not in production?
John: It's ok server prodX is not in production.
- "prodX" is not in the production environment. (Maybe the node name is mislabeled or misunderstood.)
- "prodX" is in the production environment but is not in a production state.
- "prodX" is is not in a production state and is not in a production environment.
This also applies to the simple statement.
The code has been deployed to production.This could mean:
- The code is servicing customer requests.
- The code is located in the production environment.
- It is servicing customer requests.
- It is not servicing customer requests.
- The code is not in a production environment but it is taking requests.
From an Ops perspective there are three options for any given service outage:
- SEV1/2/3: Drop everything (Severity determines response time)
- SEV4: Don't wake me I will get it when get in.
- REQ#: Nothing is broke you should send in a request.
Operations service response for State \ Environment
Not Active \ Non-Prod => REQ#
Not Active \ Prod => SEV4
Active \ Non-Prod => SEV4
Active \ Prod => SEV1/2/3
Developers on the other hand have a near reverse perspective.
- P1: Project is in active development.
- P2: Project is waiting on resources.
- SEV#: Help to make sure the application keeps working. There are constraints on what we can do.
Developers response for State \ Environment
Not Active \ Non-Prod => P2
Not Active \ Prod => P1
Active \ Non-Prod => P1
Active \ Prod => SEV#
In the case of "Not Active \ Prod" and "Active \ Non-Prod" the Ops teams will give low priority for supporting resources to the Development teams. This can impact speed of delivery of fixes and features to production but it conflicts with Ops immediate role of keeping things working. Likewise because the hands of the Dev teams are usually tied in "Active \ Prod" environments the Dev teams are slow to help seeing that it is Ops job to control those environments, even though it is the previous chain of work that feeds production.
How does DevOps resolve this issue?
There are two issues with understanding "what is production".- How do you deal with scope and work priority?
- How do you deal with semantics?
How do you deal with scope and work priority?
In some ways DevOps flips the priory of both Dev and Ops. The problem area is what gets DevOps focus and it is where Developers and Operations must meet. The mission for each group stays the same, however structure needs to be added to have the groups work together in those contentious areas.The Ops team needs to understand the work of the Dev's. They need to see the features and be active in understanding why a function is monitored or not monitored, what is the impact of a missing function, and what are the business drivers for a service. All of those things help in determining risk which Ops deals with regularly. The Ops team doesn't change how they respond to SLA's for Prod and Non-Prod but they should work with the Developers on seeing what is happening in those space.
Devs need visibility into what Ops is doing and dealing with. From a service perspective they need access to logs, monitors, and trends which should all be jointly reviewed by Ops and Dev as it may directly impact Dev's mission. Both groups need to create a constant feed back loop that helps push each team to better work quality and ultimately better service for the business.
How do you deal with semantics?
The issue of semantics is difficult. That "Sami Language of Norway, Sweden, and Finland have a 180+ snow and ice related words. This is needed because the distinctions are important. The more I see of companies dealing with this issue the more I think the same of ITSM and DevOps. However I do not now what that word should be or how it should be structured as both state and environment are important to IT, but both had different context for different groups.Thursday, September 4, 2014
Learned something new on my way to testing https posts
$ sudo nc -l 80 < resp_200.txtThe file "resp_200.txt" simply has a a line "HTTP 200 OK". Netcat will open port 80 and respond to what ever connects to it with the text from that resp_200.txt file. It will dump output to the screen with the http post it received. Nice way to test your post. Ah but what do you do when you are sending a post to HTTPS?
OpenSSL can be used to provide some netcat type functionality. You can see a detailed view of this from Wsec "USING OPENSSL AS A NETCAT REPLACEMENT".
Quick how to is:
Create self signed cert
$ sudo openssl req -x509 -nodes -days 365 -newkey rsa:1024 -keyout mycert.pem -out mycert.pem
Now use openssl to make a listener on port 443
$ sudo openssl s_server -accept 443 -cert mycert.pem
In my case I'm using Ruby to post to https similar to this example on Stackoverflow but with HTTPS instead of HTTP.
After you post you will see a bunch of text showing you the HTTP post information you sent.
This is a nice way to test your post code before you start hitting your production site.
Friday, August 8, 2014
Time to look at Ansible
I am not sure I agree with Ansible's design concept. The marriage of configuration management and ad-hoc execution is prone to problems. Puppet Labs and R.I.Pienaar, creator of Mcollective, take a pretty strong stance of trying to avoid execution of scripts or code because some crazy things can happen. It's not so bad when it's one or two systems but when you do something on hundreds and they run into the problem that could be an issue.
The nice thing about automation is it enables you to do good things faster across many more systems.
The problem with automation is it enables you to do bad things faster across many more systems.
Both Puppet and Ansible are declarative in nature, so they do not require the item to change only that the item "becomes" a finished state. However given Ansible's "push" philosophy it is also looking for "immediate consistency". This may work for small deployments but in larger systems this becomes problematic as I can break everything from the start. Puppet follows the "eventual consistency" model which when properly accounted for leads to large scale services that deploy as opposed to small scale ones that for whatever reason will not get to the state you want when you think you want it. It also gives me an idio-second to change something back because I broke the first 5 nodes that checked in and not all 100.
Ansible does have a "pull" option which does allow for "eventual consistency" but this begs the question of "why have another configuration management system?". Which then just brings us back to what does Ansible give me that Puppet does not? At this point it gives me the ability to run ad-hoc command execution across multiple systems. Puppet already gives me configuration management and Mcollective gives me safer orchestration.
After trying Ansible out I may change my mind and there is nothing that fundamentally says you cannot use both tools. Ansible being agent-less has it's advantages. However puppet agent has saved me from my stupidity when I broke SSH and OpenSSL. It was nice to have Puppet correct my screw up after locking everyone out of SSH. I could see where it would be nice to have Ansible save me when I inevitably break Puppet doing something silly.
UPDATE: 2014-08-11T19:33-50
Ansible allows you to --ask-sudo-pass to prompt for your sudo password on the systems. This means that as long as your user has sudo rights to run the command in question you can do what you like. Not sure how --ask-sudo-pass stores your password though?
Thursday, July 24, 2014
Too many or too few STEM degrees?
In my opinion geography plays a huge part in many people's reason to stay. Some of this depends on specialty but for the most part the coasts are looking to decrease their cost and trying to find degrees in other locations. However there are many cases where people simple do not want to move to the coasts. People with STEM degrees are not stupid generally weigh the benefits of moving to California, Texas, or New York / DC.
I have had several colleagues choose to move to the east or west coast. Some who have even moved back after a stent because they simile didn't like something about those places. There is also the cost of living that can change drastically. Trying finding 10 acres or 5 acres of land near San Francisco, Seattle, or New York. You won't not with out having a sizable commute. You can do that in the Midwest (well not Chicago) and to some degree in Texas, but even Texas is starting to show strain due to traffic. As much as I complain about traffic in Kansas City it is nothing compared to Texas, San Francisco, New York, or Seattle.
I have seen a number of tech workers wishing to be able to work remotely. This has strong pull to many but it is a new paradigm that many companies are not equipped culturally or technically to handle. However that is changing. I have seen startups and some large name places coming to understand that they can do work remotely and this will remove the geographic issue to some extent. In the past I have told several companies that I would love to work with them but I am in no position or have no desire to move to their city / state.
This of course has it's own trade offs. Companies in the Midwest are just now realizing the career options that companies like Google, Linkedin, Facebook, or Amazon offer to STEM employees. Otherwise they have been traditional limited in advancement options and frankly most people I know that are successful in STEM are generally drive to want to advance.
In short STEM will see better utilization when geography is removed from the equation as geographic markets play a huge role in the decision to move to the various STEM "meccas" in the US.
Monday, June 23, 2014
RedHat Subscription model and why OEL is easier.
I often work on keeping our repository of various Linux distributions available for my job. Tool's like cobblerd are a great help in this effort. By having our repositories readily available and being able to automate much of our deployment makes deploying Ubuntu, CentOS, and OEL systems a snap. I can have a new system built from scratch in less than 30 minutes and I can do many of them in parallel. (NOTE to self, really really need to start looking at RAZOR)
Now this is all fine and dandy but there is something missing from this setup, Redhat or (RHEL). Why you ask? RHEL repositories require you to be subscribed to them in order to get the updates. You cannot mirror them like you can mirror Ubuntu, CentOS, or OEL. If you want to have a local mirror you are ardently encouraged to use Satellite server. Which is great until you start figuring out the cost of having the privilege of mirroring Redhat's package services. There are other problems with this process, mainly that the mechanics of registering a license on a server with Redhat is an automation headache. It is very possible that I am missing something in this process but frankly I do not see anything that allows this to be automated because I have about 6 billion licensing combinations to go with. (Yes, that is an exaggeration because this is a rant). The astute among you will think well, Redhat has come up with using the answers file to make this process work automatically... Please note this requires Satellite.
Satellite sucks.
"But why do you think Satellite is so bad?". First the cost of Satellite is something like $10K. This isn't much for an enterprise and you would be right, it is not. I have no problem with the cost of the server itself, but wait their is more. $10K gets you the server but you need another subscription for each server you have managed by it. It's not a little bit either. Last quote I had was close to $200 to $250. I hope price has changed and I know the advent of the virtual machine and having RHEL be your Hypbervisor has mucked with how things are but really? $200 per server + $10K for Satellite + Hardware needed to run it locally + Subscription = I can pay for a good Sysadmin and do it all with CentOS or Ubuntu or Debian. This has not even touched on it's usability or lack their of. Redhat would do well to hire a UI designer and process engineer to stream line the workflow for managing it's systems.
I want to like Redhat. I really really do but OEL hosts the current repo for you to mirror. It's licenses are cheaper and it's basically the same as RHEL. Yes, Redhat made it first and Oracle just added their secret sauce for Oracle stuff but OEL is like CentOS but with support. Oracle's Linux engineers are some decent guys and I find them fairly easy to work with. (Oracle, your application support sucks. Sucks so bad I would probably only call support if I was drunk. Regretfully I don't drink so it makes your support process very hard.)
Redhat has great people but they really need to figure out this pricing and licensing/subscription game. As it stands now it is more pain than it is worth using.
Thursday, November 29, 2012
Dell XPS 15 with Ubuntu
So Sputnik has done something that I have been dying for, they have looked at getting the Dell touch pads working sanely. They have pretty much accomplished this with the XPS13. However the XPS13 is a small laptop. Great portability and power for it's size but frankly not something I would consider a work horse like my Dell E6420. I like the larger screen and tend to have a lot going on in various windows and work spaces. For single minded tasks the XPS13 is great and works great for running two terminals side by side but doesn't fit my needs. So I am tackling the XPS15 (L521x).
Meet the Dell XPS 15:
The XPS15 is a rather powerful slim laptop. It has various configurations for purchase of which I have the high end Enterprise version but I am ordering a high end small business lappy as well due to my needs with VMs. In short more cores better option than faster cores.
NOTE: If you look at the Dell website you have to be careful as the XPS 15 is listed under large business and small business both of which have different processor options. The large enterprise version offers the i5-3320M and i7-3520M where as the small business version has the i5-3120M and i7-3612QM. (See comparison at ark.intel.com) There is also the consumer/home version is the XPS 15Z so make sure you look at all locations when you are looking for the one you want.
Overall Anandtech has done a nice write up on the small business version and I would suggest giving it a read.
Ubuntu and XPS 15.
Ubuntu 12.04 "Precise Pangolin" installed with out a hitch. Recognized wireless right away and had no issues with the Intel 4000 gpu. Working with the Nvidia GeForce GT 640M gpu was a littl more involved but I will get to that in a moment. Overall the Ubuntu install was flawless, fast, and free from major issues like I have experienced before. That said there were some small issues that were quickly remedied by having the right drivers.
One big issue that you will probably notice right away is that the track pad is on ludicras speed. It took some steady slow fingers to go through some menu's. The track pad issue was resolved thanks to Project Sputnik mentioned earlier. The XPS 13 and 15 essentially use the same mouse drivers so I added the ppa for Sputnik and this made the track pad much more resonable. The pad does take some getting used to as it is a full click pad and does away with the middle button. Depending on you mouse settings you may need to use one finger clicks to do left click and two finger click to do right click. Oh and almost forgot, two finger scrolling works both vertically and horizontally This was a feature lacking on my E6420 that could only do vertical scrolling with two fingers.
Your next major hurdle, and it is time consuming, is dealing with Nvidia's Optimus technology. I was a little ticked at first about having to work with it and that the bios doesn't let you disable it like previous version did. However the technology has progressed and so has Linux thus making Optimus viable and helpful. What is Optimus you ask? "Optimus" allows non-3d intense apps to run on the local gpu while programs needing more power can use the Nvidia card. Thus power demand decreases based on usage. It also helps for Linux because most the Intel graphic drivers just work, especially when adding external monitors.
To get Optimus to run in Linux you currently need an application called "Bumblebee" which adds Optimus support to Linux. Ultimately Bumblebee will be included in the kernel but until then it is a separate project. Once installed there are some configuration things that need to be done all of which are covered in "Bumblebee's" documentation/FAQ for how to install it. Once in place you should be able to run "$ optirun {command} " and that application will render using the Nvidia card instead of the Intel 4000.
One gotcha I ran into is that you essentially have to remove "bumblebee" and install it again should the kernel change. Hopefully that will all be taken care of in future versions.
Pain Point and Deal Breakers
There is some setup that you need to do to get Ubuntu to run correctly on the XPS15. It is a little more than what you would do with E6420, however it is doable and once done the system works well and I had few issues. However, the two issues I did run into are show stoppers.
While typing I would often send the mouse flying or inadvertently click on something. After using the XPS15 for some time I switched back to my E6420 only to suddenly realize why I had such issue. The XPS15 essentially centers the larger trackpad on the "H" key thus shifting the normal location over and with the added size means it is constantly near my palm. If you use proper typing techniques with the home keys then hitting the 6,7,y,h has the strong potential of hitting the trackpad and causing an inadvertent click. The "disable as you type" feature helps some but not enough.
The second issue is with the heat generation. This comes in two forms; cpu and gpu, both caused by pushing the graphic's capabilities of the system even slightly. Minecraft and League of Legends work well on my E6420 but slaughtered the XPS15 due to heat. The only fixes I found for this was a firmware updated that essentially clocks the GPU down which invalidates any reason to purchase such hardware.
Conclusion
On paper this system has great CPU, GPU, and memory capabilities. Regretfully it doesn't survive the real world which is to bad because I really wanted to like this laptop, but given the track pad placement and heat issue I will have to wait till the next model from Dell to see if the correct the issues.
Friday, February 17, 2012
Dell? a software company? Frankly I'm torn.
ZDNet's Glenn ODonnel tells us "Suddenly, Dell is a Software Company!"
About two weeks ago, Dell announced it formed a new software group. In itself, this is not necessarily big news, but what gets us excited about Dell’s potential to finally become a serious software player lies in the man they hired to lead this new group. The new President of Dell Software Group is none other than John Swainson, the same guy who rescued CA from the brink of collapse and turned it into a truly good software company. When John left CA, it was the best it had been in its entire history. It continues to be a strong company because he built it to endure.
I cannot say I am surprised at Dell's move. Dell wishes to compete with HP who competes with IBM and Oracle all of whom have vast software and service portfolio's. Not to mention the hardware business is become more and more of a commodity market. Only the high end systems offers good margins and that seems to get smaller and smaller.
On the one had this move will be a good move for Dell, John Swainson has a good track record and has Gleen pointed out if Dell's culture is compatible what what John brings then it could be very successful. On the other hand I have to ask is this really a good move for the customers? One thing I have liked about Dell is they have been the most vendor agnostic. IBM is network agnostic as is Oracle but HP has been trying to claim the entire hardware stack for a while which has put pressure on Dell to do likewise. I think IBM and Oracle have been wise to stay out of the network space but both are heavy in the storage market. Cisco has entered the server market but honestly I have not seen anything from them that has been very compelling. Only thing I do see between HP and Cisco is that their building of the stack has just lead to a proprietary stack.
Personally I have not been happy with the hardware stack all in one vendor approach. It seems to be an "all eggs in one basket" approach. I am not saying this doesn't work, but I question how good it is for the industry as a whole and for customers in-particular. HP pushes their stack hard. Yes they will work with you if you bring up another solution but it is generally a HP first mentality. Oracle seems to be moving to the "we are the only one" route. IBM seems to be the most willing to work with people and build good hardware stack, but IBM has a problem with the image (true or not) of being costly. So Dell has played and good role in value and service. Frankly their equipment hardware is as good or better than HP servers. Dell's DCS team is a great boom but I wish they were a little more public with what they do as they have great solutions that might actually fit other people but no-knows that is going on behind their closed doors. (BTW, I really like the concept behind the C6100 and C5000 are great. Just wish acquisition cost would come down more.)
Building out more software solutions for Dell may be seen as a good competitive strategy when comparing Dell to HP but I can see where one time business partners are now software rivals. We saw the same thing happen between HP and Cisco which in turn changed things between Dell and Cisco. HP started making more advanced 10G switch gear and made their "VirtualConnect" which offered something more than Cisco offered for the HP Blade Enclosures. Soon we find out that Cisco is going to make their own server hardware and blade enclosure and the only "Cisco" blade-switch you can have for your C7000 is the Cisco 3120, 3020. None of which have 10G connectivity to the blade. Your only option is to use 10G pass=through to a Cisco switch. You have a similar situation with Dell.
In the end if Dell can show the same customer service with software that it does with it's hardware and do a good job with implementation then I see them doing well in this new initiative. But it still begs the question is this good for customer and the industry or are we starting to hedge towards more proprietary hardware stacks?
Wednesday, November 16, 2011
Fall of the Admin / Rise of the Architect?
A cohort and I engaged in a rather interesting conversation regarding the future of the "sys admin". In short the contention was made that the sys admin will dwindle with the rise of "cloud computing" and IaaS, PaaS and SaaS. With the rise of the various "as a service" platforms coming out I can not help but wonder what will become of my vaunted profesion? Will all the companies start moving away from having local sys admin's to take care of their various it tools? Will I be part of a dieing breed going the way of the big iron Unix admins?
Personally I'm not fully convinced they will go away. No doubt that the sys admin of today will be come a slightly different animal be he Linux or Windows admin. Linux and Unix admins have always been part code/script monkey. Really good Windows admins have as well but the advent of Windows power shell is causing the Windows admins to put on their coding hat and join their *nix cousins. Automation and scale will be the future for anyone who wants to learn this craft.
Typically sys admin's are used to working between 50 to 200 systems. However this all varies by application and number of supported applications. Some companies have dedicated appliation administrators or analyst where as some leave this to the role of their sys admins. The more apps an admin has to support the less number of overall systems. Now go look at a XaaS site like Amazon EC2, Google, Facebook, or Salesforce. Admin's at these places typically support a handfull of applications and hundreds if not thousands of servers. Frankly I dream of being able to work supporting 1000+:1 environment. (Currently I'm at 180+:1). XaaS is very much the future and one day I can see that most companies will either have private clouds because they don't trust 3rd parties but many companies will shift that way as they have a huge cost and headache saving benifit. But the question remains what happens to the admin?
The US Bureau of Labor and Statistics expects employment of Sys Admins to rise 23% between 2008 and 2018. What is not addressed is the number of people going into this field. I only have anictotal evidence at the moment but demand for Sys Admin's seems to have increased. Coastal regions are looking to the US interior for employees because they cannot find enough in their area. Cloud start ups are looking for admin's to build, manage and repair their systems and business are still not fully onboard with operating in the "cloud". Don't get me wrong cloud addoption is ever increasing it seams but I the applications that are hosted as part of SaaS is still not close to it's saturation point as SaaS is still to new for the typically conservative corporations to adopt it.
The demand for sys admins is only eclipsed by the demand for cloud developers. But even here the admin plays a critical role is supporting all those developers. No infrastructure, no app, no revenue.
XaaS also brings about a change in the tasks of the admin. The commoditization of the infrastructure, deployment, and user management of systems starts freeing the admins to do some rather fun higher level activities like actual architecture of the systems and environment or tackling truly difficult problems. Over all I think this is good, but it does lead me to wonder how we grow from Jr. Sys Admin to Systems Architect? If the environment that a typical Jr. admin cuts his teeth on and develops his skills to be an Sr. Admin or Architect is commoditized then how does he get the necessary expertise to become and Architect? That level of work requires knowing some of the more mundane tasks in order to see the trees and the forest of any system. With out that level of detailed knowledge it becomes more difficult to know the details of a system. Then again look what language abstraction has done programming. I'd submit that the number of people who actually code in Assembly language is very small and could possibly fit on a small cruise ship. Most software developers are using C, Java, Python, Ruby, PHP, or some other high level language. So maybe that really won't be an issue but I frankly don't know. As an admin you need to know how to manage one system before you can manage tens, hundreds, or thousands of them, so I hope we are not painting our selves into an experience corner.
Over all I think the change that the System Admin field is seeing with the commoditization of infrastructure is a good thing. It will mean changes for the role as we know it, but ultimately I think this will work out well. The number of admin's being produced is still lower than the demand for them thus keeping wages high even when taking into account the operational efficiencies that modern admins are reaching. My main concern is how we train up the next generation of admin's so they can work with the new demands that essentially call more experienced systems knowledge that can be scaled.
Friday, September 30, 2011
No Killer Linux desktop apps!? Why is that even relevant?
As much as Miguel has a point it goes much broader than he realizes. It's not just Linux as Mac and Windows are going to hit the same problem for different reason. The 80% to 90% of computer users don't need the desktop. Killer apps or not their consumption habits are going to change and the PC will revert to niche areas. The killer app they do use (Internet and productivity software) are going mobile.
Get a good tablet with keyboard (bluetooth, usb, whatever) and suddenly the non-niche market has no need for the desktop. The PC of old will essentially be used by power users (gamers, programmers, developers, etc). Office apps will be in the "Cloud" or at least not needing a huge desktop to do the work. All the tablet needs is productivity software and the ability to connect to one to two larger displays and it will have wiped out the business PC as the productivity platform. All those office workers can start their spreadsheet or power point in a meeting and complete it at their desk on dual monitor goodness and not skip a beat. I have one Linux Admin in my office who has already said if he could get a ClusterSSH and a good shell client on his iPad he would have no need for a desktop.
Miguel's complaint about he Gnome/KDE and various windows manager's is frankly irrelevant to most people. If anything the Linux field needs to start thinking about next display technology and how it can jump in on the up and coming computer input technologies beyond the current multi touch. (Think of that computer desk from "The Island").
Apps come and go. They are what bring people to the computer platform but form factors also impact their usage. The power in a tablet computer is sufficient for the majority of people's needs. We are just waiting for the productivity apps to catch on and for the tablet designers to realize how the can supplant the desktop PC. Yes, niche players will always go for their desktop of choice but most of them will probably have a productivity device (Laptop/Tablet/Mobile device) on hand as well.
Wednesday, June 15, 2011
I use Linux in a corporate environment and proxy support sucks.
My workstation currently runs Ubuntu 11.04. I had been running with Fedora 13 then 14 but frankly Fedora is not that user friendly for a desktop. SELinux borderlines on the insane if you use it and mildly annoying if you put it in passive mode. Yes, you could disable SELinux which is what many people do but as many times as you have to log in as root to do something useful it really seems counter productive. Ubuntu/Debian's sudo setup is far superior in this regard. And in my opinion APT is far easier to work with than YUM. Just managing repositories seems faster. Which takes me back to my previous issue, proxies.
Proxies, simply put, need help in Linux. Proxies are a standard in the corporate world. Which should tell you why it so important. When Chrome first came out it relied on the OS proxy settings which caused problems if you were needing to authenticate to the proxy. It was quickly updated and partially resolved the issue but authentication is still a bear. Some pages may prompt you several times to authenticate, others my only prompt you once. Not that this is due to the application. Firefox is prone to the multi-authentication issue where as Chrome will prompt once and your good for that session... most of the time. Other apps are not so forgiving or feature rich. Banshee authenticates with basic auth. Many productivity apps depend entirely on the OS provide proxy config but they don't even utilize it fully as many will ignore the authentication piece and just time out.
Now some apps will allow you to save your password. GREAT! However corporate password policy may not be so nice. If you have to change your password every 30 to 45 days trying to remember which app stored your password can be hazardous to your login attempt. I used to have Thunderbird remember my proxy password and this worked great until the password changed. Add to it I was in a rush and opened up multiple applications all failing their initial authentication and wham! "Your account is locked out".
With my head bowed I schlepped over to the domain admin, as my account can only be reset by a Domain admin, and requested they reset my password. After a long story as to why my account was locked I was greeted with typical Windows Admin jest of getting a real OS. To which I counter "They won't get me a UNIX work station" and then walk back to my desk to type in the new password.
What makes things more frustrating is that the Linux proxy tool gives you the option to put in your username and password for the proxy. However it rarely if ever works. Add to that I don't know how secure it is. I'd love to have the Linux proxy tool updated so that it worked with authentication proxies, stored your password securely, or just used your local authentication. I think this alone would help the corporate adoption rate, or at least make my life a little easier.
Friday, April 29, 2011
Microsoft $5.2 billion VS Apple's $5.99 billion
Wednesday, March 9, 2011
Apotheker and future of HP
Over all I hope the best for HP. Hurd helped the money line but only helped in bringing down the business. The HP employee's started to remind me of Sprint folks because they didn't know when the axe would fall. Mark Hurd took to acquiring new things but cut off that which made HP great, namely it's people. If Apotheker's rehtoric can be believed then he is at least looking to bring back HP's innovative spirit. Which they will need. Dell has been making inroads in the server space, and personally I like Dell enclosures and servers better than HP's. We have notorious firmware issues with HP, where as our Dell systems don't have to be patched unless something is broke. HP Blade's are a different beast.
NOTE: Word to the wise, if you buy an C7000 fill the bays and then don't touch it if at all possible. Otherwise a firmware update on one blade may cause you to have to update everything on the other blades and the enclosure.
On the software end Oracle and HP have been beating on each other for a while but HP is falling behind. Frankly I think HP needs to capitalize on Oracle's bad blood in the FOSS community. Apotheker would be wise to encourage HP to back the disgruntled players in MySQL and the Java space.
In the end only time will tell. Apotheker has said he has learned from his mistakes and SAP and "The one thing I've learned is to try to manage my temper better and get rid of cynics sooner." (see "Apotheker seeks to save hp's lost soul with software").
Sunday, November 21, 2010
Inventory, Data, and the Unicorn.
- How many systems do you have?
- How many are deployed and how many in inventory?
- What OS are deployed?
- What is the break down by manufacture?
- What is the warranty on the systems?
- Who is responsible for the systems?
- How much is the equipment worth?
Take the gbic for example. You will most likely use it in one system and probably purchased it with that switch. However three years later the switch has lived it's glorious life and is being decommissioned. However it's 10Gb gbic is still good and you need it for another machine. Now you may quite reasonably think you can just take it and move it to another system. It's still a usable part and can fix a problem you currently have. Finance on the other had has different ideas. For them the gbic may still have monetary value and still be considered a capital good. It's where abouts has impact on them and they only have record of the equipment it was first purchased with. The equipment you are putting it in has a value in their records. By you moving that gbic from equipment A to equipment B you have now devalued A and increased the value of B. Your little equipment move no longer seems so simple.
Quote: "Captain, we're receiving two hundred and eighty-five thousand hails" -- Lt. Wesley Crusher (Parallels)
Quote: Now I will believe that there are unicorns...--William Shakespeare--(The Tempest)
Monday, October 19, 2009
The importants of logs.
But how does this all fit in with "Tech". Simple, it's evaluation time and I must sit back and recount what in the name of St. Torvalds did I do this year? Logs, diary's, journals all things I used to shun and now something I'm glad my manager wants us to do. This process becomes a lot easier when I look back and see what I have done at work. I may have to start one at home as well so I know what I did there. If anything it will be helpful to the historians who look back on my life and see that even though I lived in extraordinary times I was still just a normal guy.
But enough of that, how does logging help you? Well unless you have a photographic memory and instant recall of information your going to forget what you did, when you did it, and why you did it. Here is an anecdote to help with my case.
I was writing a file compression utility to help with about a terrabyte of data on an sftp server. I have to admit I was being a little lazy having previously worked on the code the day before I made an undocumented change. It was a smart change but upon looking at it the day after and forgetting why I made it I was confronted with the problem "What in was I thinking when I did this?". Fortunately the code was still being developed and my test environment was easy to duplicate. I say "fortunately because when I started working on it the next day I changed something that started putting my compressed files into a folder that was not self incrementing. Oops!
If I had made the notes I should have I wouldn't have had a self writing compression script that went on forever over writing it's data. My change from the day before was a smart one and kept this from happening and now I had broke it by undoing my brilliance.
- What you did the day before had a good reason.
- Log what you did and the process behind it or you will surly cause your self double the work.
Friday, September 11, 2009
Ultra-low PUE??? KC Mares seems to know so.
Now, you ask, how did we get to a PUE of 1.05? Let me hopefully answer a few of your questions: 1) yes, based on annual hourly site weather data; 2) all three have densities of 400-500 watts/sf; 3) all three are roughly Tier III to Tier III+, so all have roughly N+1 (I explain a little more below); 4) all three are in climates that exceed 90F in summer; 5) none use a body of water to transfer heat (i.e. lake, river, etc); 6) all are roughly 10 MWs of IT load, so pretty normal size; 7) all operate within TC9.9 recommended ranges except for a few hours a year within the allowable range; and most importantly,Google has reported 1.2 and 1.10 but if KC is right then they could possibly do even better. That all said I look forward to seeing if the test of time bears it out. That is one problem I have with PUE. At this point it is all theory and short term testing. At least as far as I have seen.all have construction budgets equal to or LESS than standard data center construction. Oh, and one more thing: even though each of these sites have some renewable energy generation, this is not counted in the PUE to reduce it; I don’t believe that is in the spirit of the metric.
The question "Did all the IT load really NEED to be on UPS? " has some very interesting ideas. Yes, it comes down to risk but it is a very serious question that should be asked. In most cases the UPS is simply there to carry your load long enough to transfer power to the generator. Well why do you need both of your power supplies on the UPS for the preparation of a 15 minute power outage? Why have two when one would carry you through that time?
Of course you could point out "well what if your power supply on a critical server fails while your load is being transfered?" To which you must ask, "how 'critical' is this system and if it is that super critical why is it not clustered and have a failover server as well? Or do you like your single points of failure on one piece of hardware?"
I shall ponder this more. As they say the more direct you can get your power to the equipment the less power you lose. That cuts out one big middle man. Not sure APC would be all that happy...
Wednesday, July 1, 2009
Revolutionary may be an understatement. Meet Gaikai.
Gaikai is claming you can play pretty much any game online, anyware. Could be a PC title or console title. Bandwidth is a necissary part of the equation but they try to keep it down in the 1 MB range. They showed World of Warcraft, EVE, Mario Cart, and some others but this is just crazy given the implications.
- The distribution channel has shifted from by the game in the store, to downloading it online, to now buy your account and start playing. No install, no patching, it is there and ready for you.
- Store fronts may be a little pissed.
- Operating system is neutral. This is a major deal for Mac and Linux folks as this runs in their browser.
- Huge win for the game providor as they don't have to code for specific hardware. As they manage the hardware themselves they can do the upgrade and patching themselves. No worries about the customer screwing it up.
- Piracy is pretty much mute. No pay, no account, no access.
- What about saved game data? Or game allowed addon's? World of Warcraft, for example, has addons you can put on. Is there some upload mechanism to put them on your account?
- Can you change screen size?
- Is there anyway to have the game play while not connected to the network?
- Would there be an extra fee for the service on top of the game price or is it all rolled into one?
- What does the server foot print look like to host a game and it's users? In the case of games like WoW are you having 10, 20, 30 users connected to a client server that then in turn connect to the Game server?
- Game retail stores are not going to like this setup as they are essenteally cut out of the service.
- How much is Gaikai talking to the telecommunication industry to help spread broadband service to cover all of America?
Monday, June 8, 2009
Well duh! Most blogs are greated on a whim.
The oped goes on giving various examples of blogs come and gone and quite frankly are we supprised by this? Many people rant for a short time and then fade due to hopelessness or just shear lack of comments back. I've done varous searches for obsure topics and found hundreds of blogs with people who have limited feedback, bad spelling (I'm included in that one.), what turned out to be a shameless attempt to use Google adsence to make a buck.
I know I have personally started several blogs and somethings life just gets to busy to blog. Add in new technologies like Twitter and micro blogging and it makes since that typical blogs do not seem as active. Personally if I find myself posting a blog that is less than a paragraph then why bother? Twitter allows for the micro comments that make it much easier for people to give a comment with out using up lots of time.
Speaking of time, I think I've said enough. Blogging will stay for some time but look for many to persue micro-blogging.
Thursday, May 14, 2009
What does a toaster and a HP DL360g5 have in common?
Today one of the SysAdmins came to me with the woeful tale of not being able to PXE boot a DL360 so he could load an OS on it. After using iLO to look at the system remotely we see that the system never sees any drives. So off we go on a short walk to the data center and see what is going on. It should be noted that iLO gave no health warnings. It was all peachy keen save hard drives not showing up.
We arrive in the data center, plug in the monitor and see that yes the drives are not showing up. The lack of blinking lights on the drives should have been our first clue but we skipped that step as it is rarely that two out of two drives fail. But we were obviosly wrong.
First I pulled out the drive on bay one and all was well. Then I pulled out drive number 2.

Well that is a sure sign of a problem. So I pulled the DL360g5 from the rack and took it to my desk. Fortunately we had another server on hand so the Admin was able to get back to work rebuilding his system. I took the system back to my desk and started to crack it open so as to see what other damage there might be.
Here is a view of the burned out fan.

And the burned drive controller.

It was fun talking to the support people and explaining that "no it was not in a fire or struck by lightning. It caused a fire or electrical arc". The engineer that will be coming out to document it kind of laughed when his boss told him they actually have a procedure for this but it is rarely used.
To be fair to HP this is the first I've ever heard of a server actually starting the fire. We have around 100 DL360's in service and this is the only one that we have had this happen to. I like the DL360 line and wish I could get the DL360g6 as they have are using the new Intel® Xeon® processor 5500 and have a huge energy savings. However I will be interested to see what the HP engineer says when he comes to look at the system.
UPDATE:
I have some more photos for when we moved the fans out of the way.
First up some melted fans.

And here is a series of shots for the drive controller.



Cannot wait to hear back from the HP Engineers to see what the failure was.