Thursday, March 9, 2017

I am a terrible blogger.. that is all

I really am terrible at blogging. Apparently I have ignored my blog for over the year. Now I am just debating should I delete it all or pick it up again...

My first inclination is to leave it and learn from it, if anything it makes me laugh.

Wednesday, July 29, 2015

Fighting with Java SSL and Confluence

The Error:

Connection test failed. Response from the server:
ldaps.example.com:636; nested exception is javax.naming.CommunicationException: ldaps.example.com:636 [Root exception is javax.net.ssl.SSLHandshakeException: java.security.cert.CertificateException: No subject alternative names matching IP address 172.0.0.20 found]

Some notes:
* Does not happen when using java 1.8.0_45 (Java 8 u45)
* I ran into problem when using java 1.8.0_51 (Java 8 u51)
* Running Atlassian Confluence 5.8.4 on EL6

Updates To Follow:




Monday, January 5, 2015

What do you mean "it's in production"?

What do you mean "it's in production"?

Short Story: 

To many groups use the word "production" and that word changes meaning and risk depending on the group in question.

Long Story:

Our usage of the term "production" leads to some issues as it changes context based on audience. Operations can look at "production" as a matter of state where as Development may see it as a function or environment. To confuse matters worse Ops may also refer to it as an environment given it's history of working with Dev.

An example of the issue is demonstrated by a common statement.
Jane: I show server prodX is down, whats going on?
John: It's ok server prodX is not in production.
Jane may be reasonably confused by Johns statement. What does John mean by the server is not in production?


  1. "prodX" is not in the production environment. (Maybe the node name is mislabeled or misunderstood.)
  2. "prodX" is in the production environment but is not in a production state.
  3. "prodX" is is not in a production state and is not in a production environment. 

This also applies to the simple statement.
The code has been deployed to production.
This could mean:

  1. The code is servicing customer requests.
  2. The code is located in the production environment.
    1. It is servicing customer requests.
    2. It is not servicing customer requests.
  3. The code is not in a production environment but it is taking requests.

From an Ops perspective there are three options for any given service outage:

  • SEV1/2/3: Drop everything (Severity determines response time)
  • SEV4: Don't wake me I will get it when get in.
  • REQ#: Nothing is broke you should send in a request.

Operations service response for State \ Environment
Not Active \ Non-Prod => REQ#
Not Active \ Prod => SEV4
Active \ Non-Prod => SEV4
Active \ Prod => SEV1/2/3

Developers on the other hand have a near reverse perspective.

  • P1: Project is in active development.
  • P2: Project is waiting on resources.
  • SEV#: Help to make sure the application keeps working. There are constraints on what we can do.

Developers response for State \ Environment
Not Active \ Non-Prod => P2
Not Active \ Prod => P1
Active \ Non-Prod => P1
Active \ Prod => SEV#

When you merge the views you will see that there is a conflict for Not Active \ Prod, Active Non-Prod, and Active \ Prod.
In the case of "Not Active \ Prod" and "Active \ Non-Prod" the Ops teams will give low priority for supporting resources to the Development teams. This can impact speed of delivery of fixes and features to production but it conflicts with Ops immediate role of keeping things working. Likewise because the hands of the Dev teams are usually tied in "Active \ Prod" environments the Dev teams are slow to help seeing that it is Ops job to control those environments, even though it is the previous chain of work that feeds production.

How does DevOps resolve this issue?

There are two issues with understanding "what is production".

  • How do you deal with scope and work priority?
  • How do you deal with semantics?

How do you deal with scope and work priority?

In some ways DevOps flips the priory of both Dev and Ops. The problem area is what gets DevOps focus and it is where Developers and Operations must meet. The mission for each group stays the same, however structure needs to be added to have the groups work together in those contentious areas.
The Ops team needs to understand the work of the Dev's. They need to see the features and be active in understanding why a function is monitored or not monitored, what is the impact of a missing function, and what are the business drivers for a service. All of those things help in determining risk which Ops deals with regularly. The Ops team doesn't change how they respond to SLA's for Prod and Non-Prod but they should work with the Developers on seeing what is happening in those space.
Devs need visibility into what Ops is doing and dealing with. From a service perspective they need access to logs, monitors, and trends which should all be jointly reviewed by Ops and Dev as it may directly impact Dev's mission. Both groups need to create a constant feed back loop that helps push each team to better work quality and ultimately better service for the business.

How do you deal with semantics?

The issue of semantics is difficult. That "Sami Language of Norway, Sweden, and Finland have a 180+ snow and ice related words. This is needed because the distinctions are important. The more I see of companies dealing with this issue the more I think the same of ITSM and DevOps. However I do not now what that word should be or how it should be structured as both state and environment are important to IT, but both had different context for different groups.

Thursday, September 4, 2014

Learned something new on my way to testing https posts

This is a quick post for testing https posts. If you were doing something simple and just sending http posts then you could use netcat (nc) with something like
$ sudo nc -l 80 < resp_200.txt
The file "resp_200.txt" simply has a a line "HTTP 200 OK". Netcat will open port 80 and respond to what ever connects to it with the text from that resp_200.txt file. It will dump output to the screen with the http post it received. Nice way to test your post. Ah but what do you do when you are sending a post to HTTPS?

OpenSSL can be used to provide some netcat type functionality. You can see a detailed view of this from Wsec "USING OPENSSL AS A NETCAT REPLACEMENT".

Quick how to is:

Create self signed cert
$  sudo openssl req -x509 -nodes -days 365 -newkey rsa:1024 -keyout mycert.pem -out mycert.pem

Now use openssl to make a listener on port 443

$ sudo openssl s_server -accept 443 -cert mycert.pem

In my case I'm using Ruby to post to https similar to this example on Stackoverflow but with HTTPS instead of HTTP.

After you post you will see a bunch of text showing you the HTTP post information you sent.

This is a nice way to test your post code before you start hitting your production site.

Friday, August 8, 2014

Time to look at Ansible

I find it time I take a look at Ansible. From the ad-hoc perspective it seems to fit in nicely and probably works a little better than my "batchcmd" bash script I use to run commands across a list of hosts.

I am not sure I agree with Ansible's design concept. The marriage of configuration management and ad-hoc execution is prone to problems. Puppet Labs and R.I.Pienaar, creator of Mcollective, take a pretty strong stance of trying to avoid execution of scripts or code because some crazy things can happen. It's not so bad when it's one or two systems but when you do something on hundreds and they run into the problem that could be an issue.

The nice thing about automation is it enables you to do good things faster across many more systems.
The problem with automation is it enables you to do bad things faster across many more systems.

Both Puppet and Ansible are declarative in nature, so they do not require the item to change only that the item "becomes" a finished state. However given Ansible's "push" philosophy it is also looking for "immediate consistency". This may work for small deployments but in larger systems this becomes problematic as I can break everything from the start. Puppet follows the "eventual consistency" model which when properly accounted for leads to large scale services that deploy as opposed to small scale ones that for whatever reason will not get to the state you want when you think you want it. It also gives me an idio-second to change something back because I broke the first 5 nodes that checked in and not all 100.

Ansible does have a "pull" option which does allow for "eventual consistency" but this begs the question of "why have another configuration management system?". Which then just brings us back to what does Ansible give me that Puppet does not? At this point it gives me the ability to run ad-hoc command execution across multiple systems. Puppet already gives me configuration management and Mcollective gives me safer orchestration.

After trying Ansible out I may change my mind and there is nothing that fundamentally says you cannot use both tools. Ansible being agent-less has it's advantages. However puppet agent has saved me from my stupidity when I broke SSH and OpenSSL. It was nice to have Puppet correct my screw up after locking everyone out of SSH. I could see where it would be nice to have Ansible save me when I inevitably break Puppet doing something silly.

UPDATE: 2014-08-11T19:33-50
Ansible allows you to --ask-sudo-pass to prompt for your sudo password on the systems. This means that as long as your user has sudo rights to run the command in question you can do what you like. Not sure how --ask-sudo-pass stores your password though?

Thursday, July 24, 2014

Too many or too few STEM degrees?

Are there too many or too few STEM degrees and are they being utilized correctly? Infoworld's Patrick Thibodeau and Sharon Machlis note that "For 74 percent, STEM degrees lead to non-STEM jobs"

In my opinion geography plays a huge part in many people's reason to stay. Some of this depends on specialty but for the most part the coasts are looking to decrease their cost and trying to find degrees in other locations. However there are many cases where people simple do not want to move to the coasts. People with STEM degrees are not stupid generally weigh the benefits of moving to California, Texas, or New York / DC.

I have had several colleagues choose to move to the east or west coast. Some who have even moved back after a stent because they simile didn't like something about those places. There is also the cost of living that can change drastically. Trying finding 10 acres or 5 acres of land near San Francisco, Seattle, or New York. You won't not with out having a sizable commute. You can do that in the Midwest (well not Chicago) and to some degree in Texas, but even Texas is starting to show strain due to traffic. As much as I complain about traffic in Kansas City it is nothing compared to Texas, San Francisco, New York, or Seattle.

I have seen a number of tech workers wishing to be able to work remotely. This has strong pull to many but it is a new paradigm that many companies are not equipped culturally or technically to handle. However that is changing. I have seen startups and some large name places coming to understand that they can do work remotely and this will remove the geographic issue to some extent. In the past I have told several companies that I would love to work with them but I am in no position or have no desire to move to their city / state.

This of course has it's own trade offs. Companies in the Midwest are just now realizing the career options that companies like Google, Linkedin, Facebook, or Amazon offer to STEM employees. Otherwise they have been traditional limited in advancement options and frankly most people I know that are successful in STEM are generally drive to want to advance.

In short STEM will see better utilization when geography is removed from the equation as geographic markets play a huge role in the decision to move to the various STEM "meccas" in the US.

Monday, June 23, 2014

RedHat Subscription model and why OEL is easier.

DISCLAIMER: Some colleagues got me started on this rant, and make no mistake this is a "rant", so I fully intend to blame them for this lengthy deluge of vehemently worded information.

I often work on keeping our repository of various Linux distributions available for my job. Tool's like cobblerd are a great help in this effort. By having our repositories readily available and being able to automate much of our deployment makes deploying Ubuntu, CentOS, and OEL systems a snap. I can have a new system built from scratch in less than 30 minutes and I can do many of them in parallel. (NOTE to self, really really need to start looking at RAZOR)

Now this is all fine and dandy but there is something missing from this setup, Redhat or (RHEL). Why you ask? RHEL repositories require you to be subscribed to them in order to get the updates. You cannot mirror them like you can mirror Ubuntu, CentOS, or OEL. If you want to have a local mirror you are ardently encouraged to use Satellite server. Which is great until you start figuring out the cost of having the privilege of mirroring Redhat's package services. There are other problems with this process, mainly that the mechanics of registering a license on a server with Redhat is an automation headache. It is very possible that I am missing something in this process but frankly I do not see anything that allows this to be automated because I have about 6 billion licensing combinations to go with. (Yes, that is an exaggeration because this is a rant). The astute among you will think well, Redhat has come up with using the answers file to make this process work automatically... Please note this requires Satellite.
Satellite sucks.

"But why do you think Satellite is so bad?". First the cost of Satellite is something like $10K. This isn't much for an enterprise and you would be right, it is not. I have no problem with the cost of the server itself, but wait their is more. $10K gets you the server but you need another subscription for each server you have managed by it. It's not a little bit either. Last quote I had was close to $200 to $250. I hope price has changed and I know the advent of the virtual machine and having RHEL be your Hypbervisor has mucked with how things are but really? $200 per server + $10K for Satellite + Hardware needed to run it locally + Subscription = I can pay for a good Sysadmin and do it all with CentOS or Ubuntu or Debian. This has not even touched on it's usability or lack their of. Redhat would do well to hire a UI designer and process engineer to stream line the workflow for managing it's systems.

I want to like Redhat. I really really do but OEL hosts the current repo for you to mirror. It's licenses are cheaper and it's basically the same as RHEL. Yes, Redhat made it first and Oracle just added their secret sauce for Oracle stuff but OEL is like CentOS but with support. Oracle's Linux engineers are some decent guys and I find them fairly easy to work with. (Oracle, your application support sucks. Sucks so bad I would probably only call support if I was drunk. Regretfully I don't drink so it makes your support process very hard.)

Redhat has great people but they really need to figure out this pricing and licensing/subscription game. As it stands now it is more pain than it is worth using.


Thursday, November 29, 2012

Dell XPS 15 with Ubuntu

There are some exciting things going on at Dell and Canonical. Project Sputnik is going well and one of my comrades at work is thoroughly enjoying his Dell XPS 13 with Ubuntu 12.04 on it. As he says "it just works". He's not a big fan of Unity but he's getting old and questions change (^_^ love you man!). I don't mind Unity. It's getting better but that is a discussion for another time.

So Sputnik has done something that I have been dying for, they have looked at getting the Dell touch pads working sanely. They have pretty much accomplished this with the XPS13. However the XPS13 is a small laptop. Great portability and power for it's size but frankly not something I would consider a work horse like my Dell E6420. I like the larger screen and tend to have a lot going on in various windows and work spaces. For single minded tasks the XPS13 is great and works great for running two terminals side by side but doesn't fit my needs. So I am tackling the XPS15 (L521x).

Meet the Dell XPS 15:
The XPS15 is a rather powerful slim laptop. It has various configurations for purchase of which I have the high end Enterprise version but I am ordering a high end small business lappy as well due to my needs with VMs. In short more cores better option than faster cores.
NOTE: If you look at the Dell website you have to be careful as the XPS 15 is listed under large business and small business both of which have different processor options. The large enterprise version offers the i5-3320M and i7-3520M where as the small business version has the i5-3120M and i7-3612QM. (See comparison at ark.intel.com) There is also the consumer/home version is the XPS 15Z so make sure you look at all locations when you are looking for the one you want.
Overall Anandtech has done a nice write up on the small business version and I would suggest giving it a read.

Ubuntu and XPS 15.
Ubuntu 12.04 "Precise Pangolin" installed with out a hitch. Recognized wireless right away and had no issues with the Intel 4000 gpu. Working with the Nvidia GeForce GT 640M gpu was a littl more involved but I will get to that in a moment. Overall the Ubuntu install was flawless, fast, and free from major issues like I have experienced before. That said there were some small issues that were quickly remedied by having the right drivers.

One big issue that you will probably notice right away is that the track pad is on ludicras speed. It took some steady slow fingers to go through some menu's. The track pad issue was resolved thanks to Project Sputnik mentioned earlier. The XPS 13 and 15 essentially use the same mouse drivers so I added the ppa for Sputnik and this made the track pad much more resonable. The pad does take some getting used to as it is a full click pad and does away with the middle button. Depending on you mouse settings you may need to use one finger clicks to do left click and two finger click to do right click. Oh and almost forgot, two finger scrolling works both vertically and horizontally  This was a feature lacking on my E6420 that could only do vertical scrolling with two fingers.

Your next major hurdle, and it is time consuming, is dealing with Nvidia's Optimus technology. I was a little ticked at first about having to work with it and that the bios doesn't let you disable it like previous version did. However the technology has progressed and so has Linux thus making Optimus viable and helpful. What is Optimus you ask? "Optimus" allows non-3d intense apps to run on the local gpu while programs needing more power can use the Nvidia card. Thus power demand decreases based on usage. It also helps for Linux because most the Intel graphic drivers just work, especially when adding external monitors.

To get Optimus to run in Linux you currently need an application called "Bumblebee" which adds Optimus support to Linux. Ultimately Bumblebee will be included in the kernel but until then it is a separate project. Once installed there are some configuration things that need to be done all of which are covered in "Bumblebee's" documentation/FAQ for how to install it. Once in place you should be able to run "$ optirun {command} " and that application will render using the Nvidia card instead of the Intel 4000.

One gotcha I ran into is that you essentially have to remove "bumblebee" and install it again should the kernel change. Hopefully that will all be taken care of in future versions.

Pain Point and Deal Breakers
There is some setup that you need to do to get Ubuntu to run correctly on the XPS15. It is a little more than what you would do with E6420, however it is doable and once done the system works well and I had few issues. However, the two issues I did run into are show stoppers.

While typing I would often send the mouse flying or inadvertently click on something. After using the XPS15 for some time I switched back to my E6420 only to suddenly realize why I had such issue. The XPS15 essentially centers the larger trackpad on the "H" key thus shifting the normal location over and with the added size means it is constantly near my palm. If you use proper typing techniques with the home keys then hitting the 6,7,y,h has the strong potential of hitting the trackpad and causing an inadvertent click. The "disable as you type" feature helps some but not enough.

The second issue is with the heat generation. This comes in two forms; cpu and gpu, both caused by pushing the graphic's capabilities of the system even slightly. Minecraft and League of Legends work well on my E6420 but slaughtered the XPS15 due to heat. The only fixes I found for this was a firmware updated that essentially clocks the GPU down which invalidates any reason to purchase such hardware.

Conclusion
On paper this system has great CPU, GPU, and memory capabilities. Regretfully it doesn't survive the real world which is to bad because I really wanted to like this laptop, but given the track pad placement and heat issue I will have to wait till the next model from Dell to see if the correct the issues.

Friday, February 17, 2012

Dell? a software company? Frankly I'm torn.

ZDNet's Glenn ODonnel tells us "Suddenly, Dell is a Software Company!"

About two weeks ago, Dell announced it formed a new software group. In itself, this is not necessarily big news, but what gets us excited about Dell’s potential to finally become a serious software player lies in the man they hired to lead this new group. The new President of Dell Software Group is none other than John Swainson, the same guy who rescued CA from the brink of collapse and turned it into a truly good software company. When John left CA, it was the best it had been in its entire history. It continues to be a strong company because he built it to endure.

I cannot say I am surprised at Dell's move. Dell wishes to compete with HP who competes with IBM and Oracle all of whom have vast software and service portfolio's. Not to mention the hardware business is become more and more of a commodity market. Only the high end systems offers good margins and that seems to get smaller and smaller.

On the one had this move will be a good move for Dell, John Swainson has a good track record and has Gleen pointed out if Dell's culture is compatible what what John brings then it could be very successful. On the other hand I have to ask is this really a good move for the customers? One thing I have liked about Dell is they have been the most vendor agnostic. IBM is network agnostic as is Oracle but HP has been trying to claim the entire hardware stack for a while which has put pressure on Dell to do likewise. I think IBM and Oracle have been wise to stay out of the network space but both are heavy in the storage market. Cisco has entered the server market but honestly I have not seen anything from them that has been very compelling. Only thing I do see between HP and Cisco is that their building of the stack has just lead to a proprietary stack.

Personally I have not been happy with the hardware stack all in one vendor approach. It seems to be an "all eggs in one basket" approach. I am not saying this doesn't work, but I question how good it is for the industry as a whole and for customers in-particular. HP pushes their stack hard. Yes they will work with you if you bring up another solution but it is generally a HP first mentality. Oracle seems to be moving to the "we are the only one" route. IBM seems to be the most willing to work with people and build good hardware stack, but IBM has a problem with the image (true or not) of being costly. So Dell has played and good role in value and service. Frankly their equipment hardware is as good or better than HP servers. Dell's DCS team is a great boom but I wish they were a little more public with what they do as they have great solutions that might actually fit other people but no-knows that is going on behind their closed doors. (BTW, I really like the concept behind the C6100 and C5000 are great. Just wish acquisition cost would come down more.)

Building out more software solutions for Dell may be seen as a good competitive strategy when comparing Dell to HP but I can see where one time business partners are now software rivals. We saw the same thing happen between HP and Cisco which in turn changed things between Dell and Cisco. HP started making more advanced 10G switch gear and made their "VirtualConnect" which offered something more than Cisco offered for the HP Blade Enclosures. Soon we find out that Cisco is going to make their own server hardware and blade enclosure and the only "Cisco" blade-switch you can have for your C7000 is the Cisco 3120, 3020. None of which have 10G connectivity to the blade. Your only option is to use 10G pass=through to a Cisco switch. You have a similar situation with Dell.

In the end if Dell can show the same customer service with software that it does with it's hardware and do a good job with implementation then I see them doing well in this new initiative. But it still begs the question is this good for customer and the industry or are we starting to hedge towards more proprietary hardware stacks?

Wednesday, November 16, 2011

Fall of the Admin / Rise of the Architect?

A cohort and I engaged in a rather interesting conversation regarding the future of the "sys admin". In short the contention was made that the sys admin will dwindle with the rise of "cloud computing" and IaaS, PaaS and SaaS. With the rise of the various "as a service" platforms coming out I can not help but wonder what will become of my vaunted profesion? Will all the companies start moving away from having local sys admin's to take care of their various it tools? Will I be part of a dieing breed going the way of the big iron Unix admins?

Personally I'm not fully convinced they will go away. No doubt that the sys admin of today will be come a slightly different animal be he Linux or Windows admin. Linux and Unix admins have always been part code/script monkey. Really good Windows admins have as well but the advent of Windows power shell is causing the Windows admins to put on their coding hat and join their *nix cousins. Automation and scale will be the future for anyone who wants to learn this craft.

Typically sys admin's are used to working between 50 to 200 systems. However this all varies by application and number of supported applications. Some companies have dedicated appliation administrators or analyst where as some leave this to the role of their sys admins. The more apps an admin has to support the less number of overall systems. Now go look at a XaaS site like Amazon EC2, Google, Facebook, or Salesforce. Admin's at these places typically support a handfull of applications and hundreds if not thousands of servers. Frankly I dream of being able to work supporting 1000+:1 environment. (Currently I'm at 180+:1). XaaS is very much the future and one day I can see that most companies will either have private clouds because they don't trust 3rd parties but many companies will shift that way as they have a huge cost and headache saving benifit. But the question remains what happens to the admin?

The US Bureau of Labor and Statistics expects employment of Sys Admins to rise 23% between 2008 and 2018. What is not addressed is the number of people going into this field. I only have anictotal evidence at the moment but demand for Sys Admin's seems to have increased. Coastal regions are looking to the US interior for employees because they cannot find enough in their area. Cloud start ups are looking for admin's to build, manage and repair their systems and business are still not fully onboard with operating in the "cloud". Don't get me wrong cloud addoption is ever increasing it seams but I the applications that are hosted as part of SaaS is still not close to it's saturation point as SaaS is still to new for the typically conservative corporations to adopt it. 

The demand for sys admins is only eclipsed by the demand for cloud developers. But even here the admin plays a critical role is supporting all those developers. No infrastructure, no app, no revenue. 

XaaS also brings about a change in the tasks of the admin. The commoditization of the infrastructure, deployment, and user management of systems starts freeing the admins to do some rather fun higher level activities like actual architecture of the systems and environment or tackling truly difficult problems. Over all I think this is good, but it does lead me to wonder how we grow from Jr. Sys Admin to Systems Architect? If the environment that a typical Jr. admin cuts his teeth on and develops his skills to be an Sr. Admin or Architect is commoditized then how does he get the necessary expertise to become and Architect? That level of work requires knowing some of the more mundane tasks in order to see the trees and the forest of any system.  With out that level of detailed knowledge it becomes more difficult to know the details of a system. Then again look what language abstraction has done programming. I'd submit that the number of people who actually code in Assembly language is very small and could possibly fit on a small cruise ship. Most software developers are using C, Java, Python, Ruby, PHP, or some other high level language. So maybe that really won't be an issue but I frankly don't know. As an admin you need to know how to manage one system before you can manage tens, hundreds, or thousands of them, so I hope we are not painting our selves into an experience corner.

Over all I think the change that the System Admin field is seeing with the commoditization of infrastructure is a good thing. It will mean changes for the role as we know it, but ultimately I think this will work out well. The number of admin's being produced is still lower than the demand for them thus keeping wages high even when taking into account the operational efficiencies that modern admins are reaching. My main concern is how we train up the next generation of admin's so they can work with the new demands that essentially call more experienced systems knowledge that can be scaled. 

Friday, September 30, 2011

No Killer Linux desktop apps!? Why is that even relevant?

Miguel de Icaza, creator of the Gnome Desktop, is a little down on the Linux Desktop. I cannot say I really disagree with his assessment. All the "great" desktop apps for Linux are really niche apps or apps that are cross platform. Chrome, Firefox, Thunderbird, even LibreOffice are all cross platform so their's nothing there that says Linux only. As a SysAdmin I would cry without ClusterSSH but that is really something for the SysAdmin niche. Adobe's PhotoShop works on Mac OS X and Windows but it is also a niche app (and rumor has it runs fine under Wine) that will be used by graphic designers, not Joe and Jane Smith.

As much as Miguel has a point it goes much broader than he realizes. It's not just Linux as Mac and Windows are going to hit the same problem for different reason. The 80% to 90% of computer users don't need the desktop. Killer apps or not their consumption habits are going to change and the PC will revert to niche areas. The killer app they do use (Internet and productivity software) are going mobile.

Get a good tablet with keyboard (bluetooth, usb, whatever) and suddenly the non-niche market has no need for the desktop. The PC of old will essentially be used by power users (gamers, programmers, developers, etc). Office apps will be in the "Cloud" or at least not needing a huge desktop to do the work. All the tablet needs is productivity software and the ability to connect to one to two larger displays and it will have wiped out the business PC as the productivity platform. All those office workers can start their spreadsheet or power point in a meeting and complete it at their desk on dual monitor goodness and not skip a beat. I have one Linux Admin in my office who has already said if he could get a ClusterSSH and a good shell client on his iPad he would have no need for a desktop.

Miguel's complaint about he Gnome/KDE and various windows manager's is frankly irrelevant to most people. If anything the Linux field needs to start thinking about next display technology and how it can jump in on the up and coming computer input technologies beyond the current multi touch. (Think of that computer desk from "The Island").
Apps come and go. They are what bring people to the computer platform but form factors also impact their usage. The power in a tablet computer is sufficient for the majority of people's needs. We are just waiting for the productivity apps to catch on and for the tablet designers to realize how the can supplant the desktop PC. Yes, niche players will always go for their desktop of choice but most of them will probably have a productivity device (Laptop/Tablet/Mobile device) on hand as well.

Wednesday, June 15, 2011

I use Linux in a corporate environment and proxy support sucks.

I have two work stations, a Windows XP desktop and Linux workstation. The bulk of my day to day work is done from the workstation. This does not come without some pitfalls. My most aggravating being proxy server authentication. Windows NTLM and it's ability to pass along your authentication is rather nice and simplifies your world. Linux on the other hand can be a little daunting at times.

My workstation currently runs Ubuntu 11.04. I had been running with Fedora 13 then 14 but frankly Fedora is not that user friendly for a desktop. SELinux borderlines on the insane if you use it and mildly annoying if you put it in passive mode. Yes, you could disable SELinux which is what many people do but as many times as you have to log in as root to do something useful it really seems counter productive. Ubuntu/Debian's sudo setup is far superior in this regard. And in my opinion APT is far easier to work with than YUM. Just managing repositories seems faster. Which takes me back to my previous issue, proxies.

Proxies, simply put, need help in Linux. Proxies are a standard in the corporate world. Which should tell you why it so important. When Chrome first came out it relied on the OS proxy settings which caused problems if you were needing to authenticate to the proxy. It was quickly updated and partially resolved the issue but authentication is still a bear. Some pages may prompt you several times to authenticate, others my only prompt you once. Not that this is due to the application. Firefox is prone to the multi-authentication issue where as Chrome will prompt once and your good for that session... most of the time. Other apps are not so forgiving or feature rich. Banshee authenticates with basic auth. Many productivity apps depend entirely on the OS provide proxy config but they don't even utilize it fully as many will ignore the authentication piece and just time out.

Now some apps will allow you to save your password. GREAT! However corporate password policy may not be so nice. If you have to change your password every 30 to 45 days trying to remember which app stored your password can be hazardous to your login attempt. I used to have Thunderbird remember my proxy password and this worked great until the password changed. Add to it I was in a rush and opened up multiple applications all failing their initial authentication and wham! "Your account is locked out".

With my head bowed I schlepped over to the domain admin, as my account can only be reset by a Domain admin, and requested they reset my password. After a long story as to why my account was locked I was greeted with typical Windows Admin jest of getting a real OS. To which I counter "They won't get me a UNIX work station" and then walk back to my desk to type in the new password.

What makes things more frustrating is that the Linux proxy tool gives you the option to put in your username and password for the proxy. However it rarely if ever works. Add to that I don't know how secure it is. I'd love to have the Linux proxy tool updated so that it worked with authentication proxies, stored your password securely, or just used your local authentication. I think this alone would help the corporate adoption rate, or at least make my life a little easier.

Friday, April 29, 2011

Microsoft $5.2 billion VS Apple's $5.99 billion

The Wall Street Journal documents Microsoft 3Q Net Jumps 31%, But Windows Decline Dims Outlook - WSJ.com

Short answer, Microsoft did better than it has been but not enough to beat out it's rival Apple. Which is funny given how Microsoft bailed out Apple back 1997. Some theorize that without Gates, Microsoft is just moving on to a the slow death. Apple suffered without Steve Jobs for several years and look what happened when he returned!

Ars commented on the same story yesterday and the comments section went the way of the troll. But there were some good points made. One, Apple is a hardware company not a software company like Microsoft. Yes, they do have some software but they have dominated with their hardware and they have capitalized on the App Store which is a constant stream of revenue for Apple, to the tune of almost $2 billion. That's a huge sum for something that requires relatively little effort on Apples part. Microsoft has nothing to compare/compete with the App Store.

Microsoft is trying it's hand at the mobile game but lets be real. The hardware part is nothing compared to the application end and Apple gets a nice slice from every pie that goes through their store.

Apple gets 30% of every dollar that goes through the app store and that is almost free money. Add in the price of the phone, and what Apple gets for kick backs from the phone providers and you make lots of money. Microsoft doesn't compete. Apple has mobile providers nearly frothing at the mouth to get access, where as Microsoft is "meh, I guess we can carrier your OS."

My personal opinion is the Microsoft VS Apple is a bad comparison. They do have some overlap but they both compete in vastly different areas. I'd be more interested to see analysis on the Android impact as Android of today is the PC of yesteryear and Apple lost that battle in the 80's and 90's.

Android is not making more money than Apple but it has captured market share. Microsoft is not significant in the phone market, but Google is and Android VS iPhone is a far more realistic comparison.



Wednesday, March 9, 2011

Apotheker and future of HP

On November 1st, 2010 Léo Apotheker took the reigns of HP. The man has some big plans; webOS on every HP, increase HP's software profile, and bring back innovation that Mark Hurd chucked. But not all is sunny in HP land, today Bloombergs Carol Hymowitz and Douglas MacMillan note Apotheker's involvement in some shady dealings regarding HP's Board.

Over all I hope the best for HP. Hurd helped the money line but only helped in bringing down the business. The HP employee's started to remind me of Sprint folks because they didn't know when the axe would fall. Mark Hurd took to acquiring new things but cut off that which made HP great, namely it's people. If Apotheker's rehtoric can be believed then he is at least looking to bring back HP's innovative spirit. Which they will need. Dell has been making inroads in the server space, and personally I like Dell enclosures and servers better than HP's. We have notorious firmware issues with HP, where as our Dell systems don't have to be patched unless something is broke. HP Blade's are a different beast.

NOTE: Word to the wise, if you buy an C7000 fill the bays and then don't touch it if at all possible. Otherwise a firmware update on one blade may cause you to have to update everything on the other blades and the enclosure.

On the software end Oracle and HP have been beating on each other for a while but HP is falling behind. Frankly I think HP needs to capitalize on Oracle's bad blood in the FOSS community. Apotheker would be wise to encourage HP to back the disgruntled players in MySQL and the Java space.

In the end only time will tell. Apotheker has said he has learned from his mistakes and SAP and  "The one thing I've learned is to try to manage my temper better and get rid of cynics sooner." (see "Apotheker seeks to save hp's lost soul with software").


Sunday, November 21, 2010

Inventory, Data, and the Unicorn.

Managing the data center inventory for a large corporation is no small task. There are many questions that have been asked, are asked, and will be asked regarding the equipment and many times the person asking questions will throw you a curve. Some common questions that should be easy to answer are:
  • How many systems do you have?
  • How many are deployed and how many in inventory?
  • What OS are deployed?
  • What is the break down by manufacture?
  • What is the warranty on the systems?
  • Who is responsible for the systems?
  • How much is the equipment worth?
Now there are many more but these are very common and something any inventory system should be able to answer.

So what is missing from this? It has been my experience that there is the once a year or maybe even twice a year question that gets asked. This question seems to change every year so it's a little hard to predict exactly what they will ask for this year. One year Finance may ask about the value of equipment? Next year they may ask what is the value and depreciation of the equipment? Other years they may just ask for the list of equipment and the purchase order they came in on?

Now you might reasonably ask, "Why are they asking me, they sign the PO and track the orders don't they?" Well first smack your self and realize you don't think like a Finance person. They have pieces of information, not all information. In many cases they lack the expertise to know the difference between a Linksys router you use in the branch office and the Cisco 4000 you use at your HQ. They simply know how much they cost and when it was purchased. Add to this they may have some arbitrary amount that they consider to be a capital asset where as the usage you may have for an item is a little more laissez-faire.

Take the gbic for example. You will most likely use it in one system and probably purchased it with that switch. However three years later the switch has lived it's glorious life and is being decommissioned. However it's 10Gb gbic is still good and you need it for another machine.  Now you may quite reasonably think you can just take it and move it to another system. It's still a usable part and can fix a problem you currently have. Finance on the other had has different ideas. For them the gbic may still have monetary value and still be considered a capital good. It's where abouts has impact on them and they only have record of the equipment it was first purchased with. The equipment you are putting it in has a value in their records. By you moving that gbic from equipment A to equipment B you have now devalued A and increased the value of B. Your little equipment move no longer seems so simple.

Finance isn't the only group with this problem. Your operations team has a set of information they want to know. Managers have information they want and there may be other teams that need information. In my organization Network and System's used to be all together but now they are distinct groups. Each group's has different bits of information they want to tie to an asset and that is where all the fun begins.

Incoming!
Quote: "Captain, we're receiving two hundred and eighty-five thousand hails" -- Lt. Wesley Crusher (Parallels)

For ever group their could be 5 requests. Each of the 5 requests may require data from 5 different places. 5x5x5 = 125 Unique queries. In short that is a lot of data to juggle. That of course is a low number considering I have already provided more than five questions earlier. Add in the variants on those questions and new questions and your query begins to sprawl. So what are you to do?

ITIL offers us some hope in the Change Management Database (CMDB), however it is my understanding that many people confuse a CMDB for being the holder of all good information in all it's glory. Truth is ITIL calls for federating the data in large data sets. To put it simply there is to much data for one system to adequately hold it all. Instead you need to link multiple databases where the CMDB contains some data but not all data.

This is done so as to simplify the data for it's respective members. The idea being that Finance has a record of it's data and can easily go out and gather additional information from other systems, either by finding it in the CMDB or the CMDB telling them where they can find more data. Meanwhile the Service Desk can retrieve information from different information pools in the same manor. The Service Desk may not care how much the equipment cost and it's depreciation rate but they may care about when it was purchased and received.

Great in Theory
Quote: Now I will believe that there are unicorns...
--William Shakespeare--
(The Tempest)

A federated database that tells you where everything is, everything you wanted to know and things you didn't want to know, why this is a grand idea! And then I woke up. I have seen many vendors attempt to make this grandiose dream of data jubilee come true but I have never seen such a wonder. HP, IBM, they get pretty close, if you are an HP and IBM shop and drink their kool-aid you can come very close to this dream, but we are not a pure HP, IBM, Dell, Oracle, ACME, shop. Many places are not bound to one vendor and their in lies the problem. How does one federate what so many applications keep hidden?

I would like to think that the Open Source Community can tackle this but I'm not sure if the heart or even the thought is there. Various asset tools try to gather information regarding hardware but you still run into the same issue of linking data with Finance and Service Desk applications (or other groups for that matter). You need to have your data accessible and as it stands every vendor has their own idea of accessible. Where is the W3 of data interoperability? Where is the IEEE of data transport?

I'll tell you where! It's right next to the unicorn and the pink elephant.





Monday, October 19, 2009

The importants of logs.

I'm a history buff... Well kind of. I don't have the date recollection that many do but I love history. It's easy to look through history and see villains and heroes, or just normal people living through extraordinary times. You can look through the diaries of John and Abigail Adams and see two brilliant people who in the middle of one of the greatest changes in history still have normal life events happening. It lets you know that John Adams, though brilliant, was still a man. Sure he was better educated then most today and don't get me started on Ben Franklin, but needless to say he was a self made man who people should look at and not say "well he was a genius so of course things worked well for him" and instead realize he was a genius who made something of his life.

But how does this all fit in with "Tech". Simple, it's evaluation time and I must sit back and recount what in the name of St. Torvalds did I do this year? Logs, diary's, journals all things I used to shun and now something I'm glad my manager wants us to do. This process becomes a lot easier when I look back and see what I have done at work. I may have to start one at home as well so I know what I did there. If anything it will be helpful to the historians who look back on my life and see that even though I lived in extraordinary times I was still just a normal guy.

But enough of that, how does logging help you? Well unless you have a photographic memory and instant recall of information your going to forget what you did, when you did it, and why you did it. Here is an anecdote to help with my case.

I was writing a file compression utility to help with about a terrabyte of data on an sftp server. I have to admit I was being a little lazy having previously worked on the code the day before I made an undocumented change. It was a smart change but upon looking at it the day after and forgetting why I made it I was confronted with the problem "What in was I thinking when I did this?". Fortunately the code was still being developed and my test environment was easy to duplicate. I say "fortunately because when I started working on it the next day I changed something that started putting my compressed files into a folder that was not self incrementing. Oops!

If I had made the notes I should have I wouldn't have had a self writing compression script that went on forever over writing it's data. My change from the day before was a smart one and kept this from happening and now I had broke it by undoing my brilliance.

So two lessons.
  1. What you did the day before had a good reason.
  2. Log what you did and the process behind it or you will surly cause your self double the work.
Logs, notes, journals, all are things that can help use deal with the massive amounts of data we ingest and create. Unfortunately they are also time consuming. But is that time lost for making the notes a good counter to time lost with breaking something? That all depends. Set processes have notes made and should be easy to back track and see were a step was skipped/missed. Thus you are covered. It's the undocumented process that bite you and can throw off an entire day.

There is also those points in your career where you have to sit and wonder "What did I do this year?" and in most case you remember one or two big projects but and remember the last couple of projects at the end of the year but forget all that happened in the beginning.

Just like a server logs it's events, log your own. You may not be a John Adams and partake in a world changing revolution, but you might just save your brain from being taxed on what you did with your life.







Friday, September 11, 2009

Ultra-low PUE??? KC Mares seems to know so.

KC Mares of MegaWatt Consulting has managed to get some really low PUE with today's technology. Color me sceptical but KC says his math is holding up up.

Now, you ask, how did we get to a PUE of 1.05? Let me hopefully answer a few of your questions: 1) yes, based on annual hourly site weather data; 2) all three have densities of 400-500 watts/sf; 3) all three are roughly Tier III to Tier III+, so all have roughly N+1 (I explain a little more below); 4) all three are in climates that exceed 90F in summer; 5) none use a body of water to transfer heat (i.e. lake, river, etc); 6) all are roughly 10 MWs of IT load, so pretty normal size; 7) all operate within TC9.9 recommended ranges except for a few hours a year within the  allowable range; and most importantly, 8) all have construction budgets equal to or LESS than standard data center construction. Oh, and one more thing: even though each of these sites have some renewable energy generation, this is not counted in the PUE to reduce it; I don’t believe that is in the spirit of the metric.
Google has reported 1.2 and 1.10 but if KC is right then they could possibly do even better. That all said I look forward to seeing if the test of time bears it out. That is one problem I have with PUE. At this point it is all theory and short term testing. At least as far as I have seen.

The question "Did all the IT load really NEED to be on UPS? " has some very interesting ideas. Yes, it comes down to risk but it is a very serious question that should be asked. In most cases the UPS is simply there to carry your load long enough to transfer power to the generator. Well why do you need both of your power supplies on the UPS for the preparation of a 15 minute power outage? Why have two when one would carry you through that time?

Of course you could point out "well what if your power supply on a critical server fails while your load is being transfered?" To which you must ask, "how 'critical' is this system and if it is that super critical why is it not clustered and have a failover server as well? Or do you like your single points of failure on one piece of hardware?"

I shall ponder this more. As they say the more direct you can get your power to the equipment the less power you lose. That cuts out one big middle man. Not sure APC would be all that happy...





Wednesday, July 1, 2009

Revolutionary may be an understatement. Meet Gaikai.

This just popped up on Slashdot and frankly to say it is Revolutionary is an understatement. Gaikai is seeking to allow high quality games to run on the cloud and free you the gamer from where you play it. I was sceptical at first but after seeing the video I am thoroughly impressed.

Gaikai is claming you can play pretty much any game online, anyware. Could be a PC title or console title. Bandwidth is a necissary part of the equation but they try to keep it down in the 1 MB range. They showed World of Warcraft, EVE, Mario Cart, and some others but this is just crazy given the implications.

  • The distribution channel has shifted from by the game in the store, to downloading it online, to now buy your account and start playing. No install, no patching, it is there and ready for you.
  • Store fronts may be a little pissed.
  • Operating system is neutral. This is a major deal for Mac and Linux folks as this runs in their browser.
  • Huge win for the game providor as they don't have to code for specific hardware. As they manage the hardware themselves they can do the upgrade and patching themselves. No worries about the customer screwing it up.
  • Piracy is pretty much mute. No pay, no account, no access.
That all said I do have some questions:
  • What about saved game data? Or game allowed addon's? World of Warcraft, for example, has addons you can put on. Is there some upload mechanism to put them on your account?
  • Can you change screen size?
  • Is there anyway to have the game play while not connected to the network?
  • Would there be an extra fee for the service on top of the game price or is it all rolled into one?
  • What does the server foot print look like to host a game and it's users? In the case of games like WoW are you having 10, 20, 30 users connected to a client server that then in turn connect to the Game server?
  • Game retail stores are not going to like this setup as they are essenteally cut out of the service.
  • How much is Gaikai talking to the telecommunication industry to help spread broadband service to cover all of America?
Hopefully we will see good things from this advancement in gaming. So far it is looking good.





Monday, June 8, 2009

Well duh! Most blogs are greated on a whim.

My beloved Slashdot has directed me to a NYTimes article by Douglas Quenqua (Published June 5, 2009). Douglas points to a 2008 survey by the Technorati that essentially states many (95%) of blogs go unattended. Left to the void of time and soon forgotten only to show up in usless google searches...

The oped goes on giving various examples of blogs come and gone and quite frankly are we supprised by this? Many people rant for a short time and then fade due to hopelessness or just shear lack of comments back. I've done varous searches for obsure topics and found hundreds of blogs with people who have limited feedback, bad spelling (I'm included in that one.), what turned out to be a shameless attempt to use Google adsence to make a buck.

I know I have personally started several blogs and somethings life just gets to busy to blog. Add in new technologies like Twitter and micro blogging and it makes since that typical blogs do not seem as active. Personally if I find myself posting a blog that is less than a paragraph then why bother? Twitter allows for the micro comments that make it much easier for people to give a comment with out using up lots of time.

Speaking of time, I think I've said enough. Blogging will stay for some time but look for many to persue micro-blogging.

UPDATE: 2009.06.09

John Scalzi has a different take on NYT's article. In "The New York Times: We May Slide Into Irrelevancy But At Least We Update Daily" notes that the NYT has a slight grudge with the new media and is a decade late on noting that blogs come and go. 

Well I agree that the old media simply missed the boat when it comes to the net. The old school newpapers were religated to irreliveance with Craig's List, eBay, blogs, and twitter. The cable news stations are doing a little better with addapting to the changing times but in many respects news print is dead in. This isn't to say that some papers havin't figured it out but many of the old hats will pass in the sands of time becoming afterthoughts or historical footnotes.

Thursday, May 14, 2009

What does a toaster and a HP DL360g5 have in common?

Why both can melt plastic very well.

Today one of the SysAdmins came to me with the woeful tale of not being able to PXE boot a DL360 so he could load an OS on it. After using iLO to look at the system remotely we see that the system never sees any drives. So off we go on a short walk to the data center and see what is going on. It should be noted that iLO gave no health warnings. It was all peachy keen save hard drives not showing up.

We arrive in the data center, plug in the monitor and see that yes the drives are not showing up.  The lack of blinking lights on the drives should have been our first clue but we skipped that step as it is rarely that two out of two drives fail. But we were obviosly wrong.

First I pulled out the drive on bay one and all was well. Then I pulled out drive number 2.



Well that is a sure sign of a problem. So I pulled the DL360g5 from the rack and took it to my desk. Fortunately we had another server on hand so the Admin was able to get back to work rebuilding his system. I took the system back to my desk and started to crack it open so as to see what other damage there might be.

Here is a view of the burned out fan.


And the burned drive controller.



It was fun talking to the support people and explaining that "no it was not in a fire or struck by lightning. It caused a fire or electrical arc". The engineer that will be coming out to document it kind of laughed when his boss told him they actually have a procedure for this but it is rarely used.

To be fair to HP this is the first I've ever heard of a server actually starting the fire. We have around 100 DL360's in service and this is the only one that we have had this happen to. I like the DL360 line and wish I could get the DL360g6 as they have are using the new Intel® Xeon® processor 5500 and have a huge energy savings. However I will be interested to see what the HP engineer says when he comes to look at the system.

UPDATE:

I have some more photos for when we moved the fans out of the way.

First up some melted fans.

And here is a series of shots for the drive controller.







Cannot wait to hear back from the HP Engineers to see what the failure was.