Search results

  1. H

    Kanidm and LDAP InvalidAttribute

    Good day, Trying to get LDAP from kanidm https://kanidm.github.io/kanidm/master/integrations/ldap.html and seems that it doesn't have - lastname - firstname - enable - expire - comment as I'm getting (various times) these when trying to sync: TASK ERROR: ldap user search error...
  2. H

    [SOLVED] re-encrypt backups

    Good day, I have a case where the encryption keys had been compromised (failed partnership), and there are a specific set of backups I'd like to re-encrypt with a new encryption key. ie. decrypt the current backup sets, en re-write then with a new backup encryption key. Q1: That is not an...
  3. H

    [SOLVED] Installing/adding extra packages to Proxmox AIS ISO image (FRR + configs) #4

    Edit: xorisso solution I have this "use case" where the PVEs will have a meshed networking setup, ie. the transit/host/production network not connected to a switch/LAN/L2 with DHCP/PXE server somewhere broadcast domain reachable, but only PtPlinks in the cluster and up to the routers...
  4. H

    ZA mirror for downloads.proxmox.com ?

    Good day, ZANOG is busy setting up a community mirror for ZA (South Africa https://nog.net.za/mirrors/ ) Reason is the CDN sometimes resolves to NA, even when the fr.cdn.proxmox.com is the closer one, but still, EU traffic isn't always so nice and fast either and I'm also getting hit by the...
  5. H

    OVS IntPort equivalent for Linux bridge? (SDN bridges refers)

    I have needs to have multiple IPs/networks on the hypervisors, typically on different VLANs (like backups, corosyncing, ceph,etc. etc.) Having used OVS before, it is/was a charm to do similar, as you just add an OVSIntPort with the VLAN and IPs, and you are done. As the SDN is using Linux...
  6. H

    SDN - connecting PVE host/Ceph to VxLan/EVPN ? (meshed setup)

    Busy FAFOing with this in a totally meshed setup, and the use case is to have Ceph on that SDN created VxLan/EVPN vnets of it's own. Reason to NOT have it on the "public" network, but also to allow VMs (pointing fingers to K8s) that wants direct Ceph storage access on the access network, and in...
  7. H

    PVE8.1 - SDN (problematic) experiences and and other fun with IPv6 configurations

    Good day, I have new set of clusters to be deployed in environments where I do have needs for SDN (vxlan-evpn) and loopback routes for CEPH while preparing for IPv6 only networks. Though I did got it going at one stage (IPv4 only), there are still missing pieces/processes that I'm stumbling on...
  8. H

    Backing up of MinIO (S3 compatible)

    Anybody arund here doing actual backups of the MinIO storage? I've contemplated using PVE->PBS backups of the nodes (currently I deploy using LXCs) but I'm concerned w.r.t. the sequential nature of the node backups. Which then brings me to the rclone mount type backups, ie. mount the bucket...
  9. H

    Custom IPAM plugins - NIPAP

    Good day, is there perhaps a template/documentation/examples for implementing a custom IPAM for the ProxMox SDN side? I'm looking at https://spritelink.github.io/NIPAP/ for IPAM as we roll out the next steps of our network, so obviously the question comes in w.r.t. PVE not (yet) supporting...
  10. H

    [SOLVED] Devuan 4.0 template and tmux - UNprivileged container failure with non-root user

    Good day, I've been deploying Devuan 4.0 images (pve 7.4) the past 4 months, and had noticed `byobu` strangeness, but only this week it caused me problems that I had to get to the bottom of it. I've tried all the settings in the GUI panel for UNprivileged containers, and eventually...
  11. H

    custom pre/post-scripts/hooks for ACME renewals (not plugins, but firewall etc. related)

    I'm in need of executing a script to allow traffic through firewall and open port 80 inbound to the PVE (and next PBS), and then once done, close the ports etc. Is there a current way to do it in PVE 7.x ?
  12. H

    SSH public key validation error (500)

    I'm bumping my head against this problem where I need to add several keys for containers at creation time, but keep getting the above error on PVE 7.4 when doing it via the WebUI/GUI interface. What is the expression/criteria to match or make it work? Is it acctually supported? as it seems to...
  13. H

    [SOLVED] Verify single snapshot from CLI ?

    Good day, In the GUI I can select a specific Snapshot to verify, but I can't find an equivalent in the CLI commands? Reason: I've copied the datastore files from a to-be-decommisioned PBS to the new server over the network, but there had been some rsync errors, so I want to run over those with...
  14. H

    Replacing BORG with PBS? (Non-PVE backups)

    Good day, Using PBS and very happy with it, but I'm busy taking over infrastructure with a BorgBackup and I'm wondering about anybody else that did such a replacement of any tips-tricks-a-traps I need to be aware of and if it's a feasible choice, or not? Reason for doing it, would be to...
  15. H

    [SOLVED] vzdump failure with stopped LXC: .zfs/shares EOPNOTSUPP: Operation not supported on transport endpoint

    Good day, Busy cleaning up LXCs that I had shutdown, but seems to keep getting this error with the methods SNAPSHOT & STOPPED Backup works fine after starting the LXC, but want to backup the "downed" LXCs with the troubles/issues that could happen with starting these (if any)
  16. H

    Promtail (to Loki) for task logs?

    Good day, Anybody done promtail configs for getting task logs into Loki/etc. ?
  17. H

    systemtap compatible kernels?

    I've got a situation where I need to run something like systemtap to track especially DNS requests. Found this solution https://serverfault.com/questions/192893/how-i-can-identify-which-process-is-making-udp-traffic-on-linux/192920#192920 that would've be a "perfect" solution, but PVE kernels...
  18. H

    Synchronization over latency links - parallel fetches?

    I have a case where the latency for a cross continent synchronization, is being slowed down by the "small" requests from the pulling PBS. If I start up multiple synchronization jobs for multiple backups groups, I do get the full (expected) bandwidth, but when it's "stuck" on a single group's...
  19. H

    Secrets vault or similar to Instance metadata and user data (AWS IMDSv1/2)

    I'm starting to hit my head into the needs for something similar to AWS's IMDS (using IPs fd00:ec2::254 & 169.254.169.254) with something connected to a Vault (ala HAshiCorp's Vault) for secrets and automated secret sharing/etc. without the secrets/passwords being unencrypted in the VM/LXC...
  20. H

    FAI(me) .ISO for guests - with cloud-init suport?

    Good day I've stumbled on FAIme https://fai-project.org/FAIme/ which creates a "nice" ISO installer that mostly just work... except for the requirement/need of DHCP (not an option at present, unless you could advise a ISC KEA option/replacement with cost effective (for me) static host API...