home.social

#ansible — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ansible, aggregated by home.social.

  1. CW: AI

    Out of curiosity, I have asked Claude to rewrite a tiny little SSH wrapper from Python to Go and Rust to check performance.

    Results:
    * Python = 20ms
    * Go = 3ms
    * Rust = 1.5ms

    It's totally useless if you have Mitogen because it opens the SSH connection once but if you don't, every single ms counts.

    #ssh #python #go #rust #ansible #ai

  2. CW: AI

    Out of curiosity, I have asked Claude to rewrite a tiny little SSH wrapper from Python to Go and Rust to check performance.

    Results:
    * Python = 20ms
    * Go = 3ms
    * Rust = 1.5ms

    It's totally useless if you have Mitogen because it opens the SSH connection once but if you don't, every single ms counts.

  3. CW: AI

    Out of curiosity, I have asked Claude to rewrite a tiny little SSH wrapper from Python to Go and Rust to check performance.

    Results:
    * Python = 20ms
    * Go = 3ms
    * Rust = 1.5ms

    It's totally useless if you have Mitogen because it opens the SSH connection once but if you don't, every single ms counts.

    #ssh #python #go #rust #ansible #ai

  4. CW: AI

    Out of curiosity, I have asked Claude to rewrite a tiny little SSH wrapper from Python to Go and Rust to check performance.

    Results:
    * Python = 20ms
    * Go = 3ms
    * Rust = 1.5ms

    It's totally useless if you have Mitogen because it opens the SSH connection once but if you don't, every single ms counts.

    #ssh #python #go #rust #ansible #ai

  5. CW: AI

    Out of curiosity, I have asked Claude to rewrite a tiny little SSH wrapper from Python to Go and Rust to check performance.

    Results:
    * Python = 20ms
    * Go = 3ms
    * Rust = 1.5ms

    It's totally useless if you have Mitogen because it opens the SSH connection once but if you don't, every single ms counts.

    #ssh #python #go #rust #ansible #ai

  6. I've tested Mitogen for Ansible. Now I can't tell Ansible is bad at loops anymore. It's bad at handling SSH connections by default. I feel like it runs at the speed of light now!

    mitogen.networkgenomics.com/an

    #ansible #mitogen #ssh #automation

  7. I have spent the last two days debugging why my SSH connection didn't go through The Bastion. I have automated everything with terraform so no human mistake. Network flows, user, private key, correct "from" list in the ingress key. In the end, the connection doesn't even reach the bastion. It silently dies in the wrapper in between. And of course, there is no explicit error that could have saved me hours of work. It's not lost because everything is automated now, but this is frustrating.

    When I checked the repo, there are multiple issues and pull requests to review now. So it's time to put my maintainer hat on and get things done!

    github.com/ovh/the-bastion-ans

    #ansible #bastion #ssh

  8. I have spent the last two days debugging why my SSH connection didn't go through The Bastion. I have automated everything with terraform so no human mistake. Network flows, user, private key, correct "from" list in the ingress key. In the end, the connection doesn't even reach the bastion. It silently dies in the wrapper in between. And of course, there is no explicit error that could have saved me hours of work. It's not lost because everything is automated now, but this is frustrating.

    When I checked the repo, there are multiple issues and pull requests to review now. So it's time to put my maintainer hat on and get things done!

    github.com/ovh/the-bastion-ans

  9. I have spent the last two days debugging why my SSH connection didn't go through The Bastion. I have automated everything with terraform so no human mistake. Network flows, user, private key, correct "from" list in the ingress key. In the end, the connection doesn't even reach the bastion. It silently dies in the wrapper in between. And of course, there is no explicit error that could have saved me hours of work. It's not lost because everything is automated now, but this is frustrating.

    When I checked the repo, there are multiple issues and pull requests to review now. So it's time to put my maintainer hat on and get things done!

    github.com/ovh/the-bastion-ans

    #ansible #bastion #ssh

  10. I have spent the last two days debugging why my SSH connection didn't go through The Bastion. I have automated everything with terraform so no human mistake. Network flows, user, private key, correct "from" list in the ingress key. In the end, the connection doesn't even reach the bastion. It silently dies in the wrapper in between. And of course, there is no explicit error that could have saved me hours of work. It's not lost because everything is automated now, but this is frustrating.

    When I checked the repo, there are multiple issues and pull requests to review now. So it's time to put my maintainer hat on and get things done!

    github.com/ovh/the-bastion-ans

    #ansible #bastion #ssh

  11. I have spent the last two days debugging why my SSH connection didn't go through The Bastion. I have automated everything with terraform so no human mistake. Network flows, user, private key, correct "from" list in the ingress key. In the end, the connection doesn't even reach the bastion. It silently dies in the wrapper in between. And of course, there is no explicit error that could have saved me hours of work. It's not lost because everything is automated now, but this is frustrating.

    When I checked the repo, there are multiple issues and pull requests to review now. So it's time to put my maintainer hat on and get things done!

    github.com/ovh/the-bastion-ans

    #ansible #bastion #ssh

  12. ADR-05: Ansible für die gesamte Konfiguration; ansible-vault für Geheimnisse

    StatusAngenommenEntschiedenSobald ein Host von hand existierteBezugAusnahme korrigiert durch ADR-10

    Kontext:Ein System, das durch Eintippen von Befehlen entstanden ist, existiert nur so lange, wie sich die tippende

    behindtheconsole.com/2026/09/0

    #Projekt #SystemArchitektur #ADR #ansible #Systemarchitektur #BTC

  13. ADR-05: Ansible für die gesamte Konfiguration; ansible-vault für Geheimnisse

    StatusAngenommenEntschiedenSobald ein Host von hand existierteBezugAusnahme korrigiert durch ADR-10

    Kontext:Ein System, das durch Eintippen von Befehlen entstanden ist, existiert nur so lange, wie sich die tippende

    behindtheconsole.com/2026/09/0

    #Projekt #SystemArchitektur #ADR #ansible #Systemarchitektur #BTC

  14. ADR-05: Ansible für die gesamte Konfiguration; ansible-vault für Geheimnisse

    StatusAngenommenEntschiedenSobald ein Host von hand existierteBezugAusnahme korrigiert durch ADR-10

    Kontext:Ein System, das durch Eintippen von Befehlen entstanden ist, existiert nur so lange, wie sich die tippende

    behindtheconsole.com/2026/09/0

    #Projekt #SystemArchitektur #ADR #ansible #Systemarchitektur #BTC

  15. ADR-05: Ansible für die gesamte Konfiguration; ansible-vault für Geheimnisse

    StatusAngenommenEntschiedenSobald ein Host von hand existierteBezugAusnahme korrigiert durch ADR-10

    Kontext:Ein System, das durch Eintippen von Befehlen entstanden ist, existiert nur so lange, wie sich die tippende

    behindtheconsole.com/2026/09/0

    #Projekt #SystemArchitektur #ADR #ansible #Systemarchitektur #BTC

  16. ADR-05: Ansible für die gesamte Konfiguration; ansible-vault für Geheimnisse

    StatusAngenommenEntschiedenSobald ein Host von hand existierteBezugAusnahme korrigiert durch ADR-10

    Kontext:Ein System, das durch Eintippen von Befehlen entstanden ist, existiert nur so lange, wie sich die tippende

    behindtheconsole.com/2026/09/0

    #Projekt #SystemArchitektur #ADR #ansible #Systemarchitektur #BTC

  17. Spaß mit cowsay und lolcat 😊

    Für den Admin-Kollegen tat sich eine neue Welt auf.

    Und meine Ansible-Playbooks sahen noch nie so fancy aus.

    #Linux #Ansible #Terminal #CLI #sysadmin #cowsay #lolcat

  18. Основы Ansible — как автоматизировать конфигурации и деплой

    В статье — разбор основ Ansible: как писать идемпотентные плейбуки, не класть продакшен сухими прогонами и встроить Ansible в CI/CD. Разбираю структуру ролей, работу с динамическим инвентарём, секретами и типовые грабли новичков. Две наглядные схемы, реальный кейс из боевой практики и набор правил, которые делают автоматизацию предсказуемой и безопасной. Читать разбор

    habr.com/ru/companies/otus/art

    #Ansible #автоматизация_конфигураций #деплой #GitLab_CI #Jenkins #playbook #инфраструктура #ansiblevault #DevOpsпрактики

  19. VMmanager, управление инфраструктурой через VMmanager API и Ansible

    Привет, Хабр! Статья будет посвящена любимому мной IaC. Чтобы ввести в курс дела, кратко расскажу про VMmanager и текущую реализацию продукта. Затронем варианты, как можно работать с VMmanager с подходом Infrastructure as Code, а основная часть — про развертывание платформы VMmanager и управление виртуальными машинами в ней с помощью Ansible.

    habr.com/ru/companies/ispsyste

    #vmmanager #виртуализация #ansible #infrastructureasacode #pyhton #програмиирование #инфраструктура

  20. Спускаясь с облаков в ад: развёртывание Kubernetes на Astra Linux. Часть 1

    За годы работы с Kubernetes у нас было множество различных задач: от самых типовых развёртываний до крайне специфичных конфигураций и установок. Однако недавно в наших стенах решалась задача, которая заставила нас проявить творческий подход, выйти за рамки Kubernetes и даже немного сжульничать. Всем привет, на связи Пётр. Сегодня мы рассмотрим автоматическое развёртывание ванильного Kubernetes на Astra Linux через Kubespray + Helm. Давайте разворачивать

    habr.com/ru/companies/nixys/ar

    #astralinux #kubernetes #helm #ansible #kubespray #linux #devops #automatization #tutorial #infrastructureasacode

  21. Покрываем плэйбуками ansible IaC в части предоставления доступа

    Итак мы уже научились быстро поднимать инфраструктуру с помощью IaC, завели кучу репозиторриев и готовы восстановить исковерканную или сломанную инфраструктуру в части готовности сервисов. В качесте следующего этапа можно рассмотреть предоставление доступов к ресурсам и документирование предоставления таких доступов. Такой подход позволит не только быстро находить на каком основании Вася дропнул табличку на проде, но и ускорить предоставление доступов и сократить количество ошибок.

    habr.com/ru/articles/808687/

    #ansible #ansible_roles #iac #infrastructureasacode #infrastructure_as_code

  22. Ansible + Grafana Loki: Настраиваем отправку уведомлении в чат после логина на сервер по SSH

    Не задумывались ли вы когда-нибудь над тем, чтобы знать о каждом входе на ваши сервера? Меня охватила такая же паранойя: а вдруг, когда я сплю, на мой сервер заходит домовой и творит там ужасы? Хотя логин на наши сервера и запрещен по паролю, а SSH-ключи есть только у меня, в любом случае это вызывает большие опасения. В этой статье мы развёрнем через Terraform несколько серверов в Yandex.Cloud, а затем при помощи Ansible настроим необходимый софт на каждом сервере. У нас будет основной сервер c Loki (система агрегирования логов) и Grafana (инструмент для визуализации данных), на серверах, которые мы хотим отслеживать, будет установлен Promtail (агент для сбора и отправки логов). Мы разберёмся с тем, как отслеживать входы на сервер, а затем в удобном формате отправлять об этом уведомления в чат с помощью вышеуказанных сервисов.

    habr.com/ru/articles/795855/

    #мониторинг #grafana #loki #promtail #защита_серверов #ansible #terraform #iac #infrastructureasacode #логирование

  23. Hashicorp Vault — собираем непрямую репликацию через ведро

    Hashicorp Vault - прекрасный продукт для централизованного хранения всех паролей и других секретов компании. При этом, многие знают, что удобная ключница - это идеальный способ потерять все ключи одновременно. Когда я работал в крупном телекоме, то DRP-протоколы с восстановлением данных учитывали даже запрет на сбор более двух Хранителей Ключей в одном месте. Чисто на случай очень неудачного корпоратива с совместным полетом на воздушном шаре, дегустацией домашних грибов или другими подобными факторами. Короче, если вы внедряете подобную систему, то вам надо очень внимательно подходить не только к вопросам эксплуатации, но и резервного копирования и восстановления. Сегодня я не буду глубоко касаться темы организации правильного хранения фрагментов ключей Шамира. Вместо этого, я попробую рассказать о том, как развернуть с нуля отказоустойчивый кластер Hashicorp Vault в community edition. Для этого поднимем основной и тестовый кластер Vault в нескольких регионах и датацентрах. Тестовый кластер у нас одновременно будет служить и резервным в рамках процедуры DRP. Чтобы было совсем интересно, настроим процесс таким образом, чтобы тестовый кластер был односторонней репликой продуктивного с отставанием в несколько суток. Разумеется, все развертывание мы будем проводить в парадигме Infrastructure-as-a-code с Terraform и Ansible в качестве основных инструментов. Сейчас расскажу, когда это может пригодиться и какими ansible-модулями можно для этого воспользоваться. Сразу предупреждаю - это будет лонгрид, так как я не люблю разбивать на кучу мелких постов единый туториал.

    habr.com/ru/companies/wiseops/

    #hashicorp #hashicorp_vault #ansible #terraform #iac #infrastructureasacode #безопасность #мы_все_немного_параноики #tutorial

  24. Geräteinitiative und #Linux
    linux-bildung.at/2023/03/gerae

    Interessanter Bericht zum zentralen Verwalten von 142 Stück #refurbished HP #Elitebook 840 G4 von der Firma #AfB (Arbeit für Behinderte) in einer #Schule. Sieht nach durchdachtem Konzept aus. 🤓

    #ansible #PXE #MDM

  25. Über #Ansible #automatisieren das #Zabbix #postgresql auf einem #debian mit separater #datenbank überwacht, brauchte gerade folgendes Wissen:

    * Eigenheiten von Zabbix
    * Eigenheiten des #zabbix_agent2
    * Eigenheiten der Maintainer von Zabbix für die debian pakete.
    * Eigenheiten … Configurationsstruktur der Distro Maintainer
    * Eigenheiten … Ansible community.zabbix repo
    * #YAML
    * #jinja2

    Und ich glaube das war es, mehr musste ich dafür heute nicht weiter, sehr gut kennen. o.O
    Ps. Ja, tat weh.