home.social

#snippet — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #snippet, aggregated by home.social.

fetched live
  1. Hardening Apache for PCI DSS? Enforce TLS 1.2+, disable SSLv3/TLS 1.0/1.1, set strong ciphers, and enable HSTS. Here's the config for Ubuntu 22.04/Debian 12. #pci #snippet #ValtersIT

    valtersit.com/vault/pci-dss-tl

  2. Hardening Apache for PCI DSS? Enforce TLS 1.2+, disable SSLv3/TLS 1.0/1.1, set strong ciphers, and enable HSTS. Here's the config for Ubuntu 22.04/Debian 12. #pci #snippet #ValtersIT

    valtersit.com/vault/pci-dss-tl

  3. Stop manually checking iDRAC health. This RACADM snippet configures SNMP trap forwarding for system, storage, and fan alerts to a remote receiver. Works on RHEL 8/9, Ubuntu 22.04, Debian 12, iDRAC7+. #idrac #snippet #alerts

    valtersit.com/vault/configure-

  4. Stop manually checking iDRAC health. This RACADM snippet configures SNMP trap forwarding for system, storage, and fan alerts to a remote receiver. Works on RHEL 8/9, Ubuntu 22.04, Debian 12, iDRAC7+. #idrac #snippet #alerts

    valtersit.com/vault/configure-

  5. Achieve zero-downtime rolling updates with Docker Compose healthchecks. Configure healthcheck directives for readiness, use depends_on with condition: service_healthy, and deploy.update_config with order: start-first. Works on Docker Compose v2.20+, Docker v24+, Ubuntu 22.04, Debian 12. #docker #snippet #zero-downtime #healthcheck #ValtersIT

    valtersit.com/vault/zerodownti

  6. Achieve zero-downtime rolling updates with Docker Compose healthchecks. Configure healthcheck directives for readiness, use depends_on with condition: service_healthy, and deploy.update_config with order: start-first. Works on Docker Compose v2.20+, Docker v24+, Ubuntu 22.04, Debian 12. #docker #snippet #zero-downtime #healthcheck #ValtersIT

    valtersit.com/vault/zerodownti

  7. Control primary component selection in Galera Cluster with node weight configuration. Use pc.weight in wsrep_provider_options to assign higher votes to preferred nodes. During a network partition, the group with the highest total weight wins quorum. #mysql #snippet #node-weight

    valtersit.com/vault/galera-clu

  8. Control primary component selection in Galera Cluster with node weight configuration. Use pc.weight in wsrep_provider_options to assign higher votes to preferred nodes. During a network partition, the group with the highest total weight wins quorum. #mysql #snippet #node-weight

    valtersit.com/vault/galera-clu

  9. Bash’s `read -s` disables terminal echo via `stty -echo`, reads input, then restores it. Store credentials in a variable cleared after use, and use them only in a subshell to prevent leakage. Secure credential injection for POSIX shells. #bash #snippet #security

    valtersit.com/vault/bash-secur

  10. Bash’s `read -s` disables terminal echo via `stty -echo`, reads input, then restores it. Store credentials in a variable cleared after use, and use them only in a subshell to prevent leakage. Secure credential injection for POSIX shells. #bash #snippet #security

    valtersit.com/vault/bash-secur

  11. Need to bulk reset AD user passwords from a CSV? This PowerShell snippet processes each user, handles errors, logs success/failure, and forces password change at next logon. Works on Windows Server 2016-2022. #windows #snippet #powershell

    valtersit.com/vault/bulk-reset

  12. Need to bulk reset AD user passwords from a CSV? This PowerShell snippet processes each user, handles errors, logs success/failure, and forces password change at next logon. Works on Windows Server 2016-2022. #windows #snippet #powershell

    valtersit.com/vault/bulk-reset

  13. Monitor your Shodan API rate limits with a simple curl to /api-info. Extract credits, query limits, and scan limits via jq. Works on Linux and macOS. Full snippet: #shodan #snippet #api-rate-limits

    valtersit.com/vault/shodan-api

  14. Monitor your Shodan API rate limits with a simple curl to /api-info. Extract credits, query limits, and scan limits via jq. Works on Linux and macOS. Full snippet: #shodan #snippet #api-rate-limits

    valtersit.com/vault/shodan-api

  15. Automate compliance fixes: use OpenSCAP's generate-fix to create a Bash remediation script from XCCDF scan results. Maps failed rules to benchmark fixes for RHEL 8/9, CentOS 8, Fedora 36+. #remediation #snippet #openscap

    valtersit.com/vault/remediatio

  16. Automate compliance fixes: use OpenSCAP's generate-fix to create a Bash remediation script from XCCDF scan results. Maps failed rules to benchmark fixes for RHEL 8/9, CentOS 8, Fedora 36+. #remediation #snippet #openscap

    valtersit.com/vault/remediatio

  17. Need to cap CPU on a legacy system without cgroups? cpulimit attaches to a PID and sends SIGSTOP/SIGCONT at microsecond intervals to enforce a percentage limit. Works on CentOS 7, Ubuntu 20.04, Debian 11. #linux #snippet #cpu-throttling

    valtersit.com/vault/limit-proc

  18. Need 90th, 95th & 99th percentiles over sliding 1-hour windows for CPU metrics? This Flux script uses window() and quantile() with t-digest for efficient approximate computation. #flux #snippet #percentile

    valtersit.com/vault/flux-query

  19. Use InfluxDB as an annotation source in Grafana to overlay events like deployments on your graphs. This Flux query maps event data from a measurement into the required _time, title, and text columns, using a host tag matched to a dashboard variable. #grafana #snippet #annotations

    valtersit.com/vault/grafana-an

  20. Stop namespace conflicts in Helm. Use .Release.Namespace to dynamically scope resources to the release’s namespace. Works with Helm 3.x on Kubernetes 1.19+. No more cross-namespace clashes. #helm #snippet #kubernetes

    valtersit.com/vault/helm-chart

  21. Secure your container data: Mount host directories as read-only using Docker volumes. The `:ro` flag enforces kernel-level write protection, preventing container processes from altering the host filesystem. Essential for security. #docker #snippet #volumes #read-only #ValtersIT

    valtersit.com/vault/mount-host

  22. Keep Lynis audit logs under control with automated rotation and compression. This snippet configures logrotate to rotate logs weekly, gzip them, and retain 4 weeks of history — preventing disk exhaustion on Ubuntu 22.04, Debian 12, RHEL 9, or CentOS Stream 9. Essential for frequent scans. #lynis #snippet #logrotate

    valtersit.com/vault/lynis-audi

  23. I often get frustrated when copy-pasting commands from a website into my Nushell terminal, especially with those line-escaping backslashes...

    Here is a little snippet I found to solve that issue.

    Read more on my blog: moskitohero.com/post/2026-07-1

    #nushell #bash #shell #snippet

  24. I often get frustrated when copy-pasting commands from a website into my Nushell terminal, especially with those line-escaping backslashes...

    Here is a little snippet I found to solve that issue.

    Read more on my blog: moskitohero.com/post/2026-07-1

    #nushell #bash #shell #snippet

  25. I often get frustrated when copy-pasting commands from a website into my Nushell terminal, especially with those line-escaping backslashes...

    Here is a little snippet I found to solve that issue.

    Read more on my blog: moskitohero.com/post/2026-07-1

    #nushell #bash #shell #snippet

  26. I often get frustrated when copy-pasting commands from a website into my Nushell terminal, especially with those line-escaping backslashes...

    Here is a little snippet I found to solve that issue.

    Read more on my blog: moskitohero.com/post/2026-07-1

    #nushell #bash #shell #snippet

  27. Configure iDRAC for encrypted SNMP v3 traps: racadm sets trap destination, enables alerts, and configures auth/privacy protocols. iDRAC firmware generates traps from Dell MIBs on temperature, power, fan events.

    #idrac #snippet #snmp

    valtersit.com/vault/monitor-id

  28. Enforce HTTPS for all S3 data access with this AWS CLI policy, meeting ISO 27001 A.13.2.3 on secure communications. Uses aws:SecureTransport condition to deny non-TLS requests. Scopable to specific principals.
    #iso #snippet #awss3

    valtersit.com/vault/aws-s3-buc

  29. Analyze per-process page faults with `ps` and `/proc/[pid]/stat`. Track major faults (disk I/O) vs minor faults (cache) via kernel's `task_struct`. Compute delta over time to spot high-impact processes. Production-ready for Ubuntu 22.04, Debian 12, RHEL 8. #linux #snippet #page-fault #major-fault #ValtersIT

    valtersit.com/vault/perprocess

  30. Monitor ZeroTier with Prometheus: Export peer counts, health & bandwidth stats via ZeroTier JSON API, scraped by node_exporter textfile collector. Script queries /status and /network/[ID] endpoints, outputs gauge metrics. Works on Ubuntu 22.04, Debian 12. #zerotier #prometheus #snippet

    valtersit.com/vault/zerotier-w

  31. Calculate P99 latency from structured logs in Loki using LogQL. This query filters for `duration_ms` fields, then applies `quantile_over_time(0.99, [5m])` via the t-digest algorithm for efficient approximation. Works with Loki v2.6+ and LogQL v2.0+. Full guide at #loki #snippet #latency #p99 #ValtersIT

    valtersit.com/vault/logql-quer

  32. Monitor USB insertion events to detect data exfiltration. Use wevtutil to query System log for Event ID 20001 from Microsoft-Windows-Kernel-PnP, filtering for 'USB\VID_' hardware IDs. Outputs timestamps, device description, and serial number. #windows #snippet #usb-monitoring #dlp #ValtersIT

    valtersit.com/vault/monitor-us

  33. Monitor USB insertion events to detect data exfiltration. Use wevtutil to query System log for Event ID 20001 from Microsoft-Windows-Kernel-PnP, filtering for 'USB\VID_' hardware IDs. Outputs timestamps, device description, and serial number. #windows #snippet #usb-monitoring #dlp #ValtersIT

    valtersit.com/vault/monitor-us

  34. Monitor USB insertion events to detect data exfiltration. Use wevtutil to query System log for Event ID 20001 from Microsoft-Windows-Kernel-PnP, filtering for 'USB\VID_' hardware IDs. Outputs timestamps, device description, and serial number. #windows #snippet #usb-monitoring #dlp #ValtersIT

    valtersit.com/vault/monitor-us

  35. Monitor USB insertion events to detect data exfiltration. Use wevtutil to query System log for Event ID 20001 from Microsoft-Windows-Kernel-PnP, filtering for 'USB\VID_' hardware IDs. Outputs timestamps, device description, and serial number. #windows #snippet #usb-monitoring #dlp #ValtersIT

    valtersit.com/vault/monitor-us

  36. Monitor USB insertion events to detect data exfiltration. Use wevtutil to query System log for Event ID 20001 from Microsoft-Windows-Kernel-PnP, filtering for 'USB\VID_' hardware IDs. Outputs timestamps, device description, and serial number. #windows #snippet #usb-monitoring #dlp #ValtersIT

    valtersit.com/vault/monitor-us

  37. Deploy stateful Workers with Durable Objects using `wrangler deploy --bind`. Achieve strongly consistent state across requests via a single global coordinator with SQLite-based persistence. Automatic failover included. #cloudflare #durable-objects #snippet

    valtersit.com/vault/integrate-

  38. Zero-downtime deployments with Fabric: This snippet implements blue-green swapping by checking a symlink, deploying to the inactive environment, and running health checks via c.run(). Perfect for Ubuntu/Debian. #fabric #snippet #blue-green

    valtersit.com/vault/rolling-de

  39. Migrate Terraform state from local to S3 without re-importing resources. Use `terraform state mv` combined with a backend migration to rename and transition state files seamlessly. Works on Linux, macOS, Windows (Terraform 0.12+). Details: #terraform #snippet #state-migration #s3 #ValtersIT

    valtersit.com/vault/migrate-te

  40. Can't trust a scan from within an infected OS. This snippet triggers Windows Defender Offline Scan via WinRE, booting into a minimal PE environment with updated signatures to catch persistent, hidden malware. Windows 10/11, Server 2016+. #windows #snippet #offline-scan #winre #ValtersIT

    valtersit.com/vault/offline-sc

  41. Protect your VLAN configs! Backup vlan.dat on Cisco IOS/IOS-XE switches with `copy flash:vlan.dat flash:vlan-backup.dat`. Restore via `copy flash:vlan-backup.dat flash:vlan.dat` and reload. Essential for disaster recovery or cloning setups. #cisco #snippet #ValtersIT

    valtersit.com/vault/vlan-datab

  42. Need to route multiple subnets through a single IPSec tunnel on VyOS 1.4? This snippet shows how to configure multiple traffic selectors (TS) with strongSwan and XFRM for efficient site-to-site connections. #vyos #snippet #ipsec #traffic-selector #ValtersIT

    valtersit.com/vault/ipsec-tunn

  43. Streamline your LLMNR poisoning workflow: Use Responder's -o and -F flags to output NTLMv1 hashes in Hashcat-compatible format for offline cracking with mode 5500. Works on Kali, Ubuntu, Parrot. #responder #snippet #hashcat #llmnr #ValtersIT

    valtersit.com/vault/llmnr-pois

  44. SCAP drift detection via timestamp-based differential scanning: compare current scan start-time to baseline ARF using oscap info. If delta > 24h, full scan; else quick OVAL delta check. Works on RHEL 8, Ubuntu 22.04, Debian 12. #openscap #snippet #drift

    valtersit.com/vault/scap-times

  45. Deploy the Tailscale Kubernetes operator with Helm, then expose services directly via Tailscale ingress — no load balancer needed. Create a ProxyClass for tags, annotate your service, and get per-pod node connectivity. Kubernetes 1.24+, Helm 3.8+. #kubernetes #snippet #operator

    valtersit.com/vault/tailscale-

  46. Deploy the Tailscale Kubernetes operator with Helm, then expose services directly via Tailscale ingress — no load balancer needed. Create a ProxyClass for tags, annotate your service, and get per-pod node connectivity. Kubernetes 1.24+, Helm 3.8+. #kubernetes #snippet #operator

    valtersit.com/vault/tailscale-

  47. Deploy the Tailscale Kubernetes operator with Helm, then expose services directly via Tailscale ingress — no load balancer needed. Create a ProxyClass for tags, annotate your service, and get per-pod node connectivity. Kubernetes 1.24+, Helm 3.8+. #kubernetes #snippet #operator

    valtersit.com/vault/tailscale-

  48. Exploit Heartbleed (CVE-2014-0160) with OpenSSL s_client: send a malformed heartbeat request with oversized payload length to extract up to 64KB of heap memory. Use -no_ssl3 -no_tls1 for TLS 1.0/1.1, -msg to capture leaked data. #cve #snippet #heartbleed #cve-2014-0160 #ValtersIT

    valtersit.com/vault/heartbleed

  49. une solution qui me convient en attendant de dépasser le seuil de flemme :

    ```
    nb ls --limit 10 --excerpt 5 --pager --paths --sort --reverse
    ```

    #snippet

  50. une solution qui me convient en attendant de dépasser le seuil de flemme :

    ```
    nb ls --limit 10 --excerpt 5 --pager --paths --sort --reverse
    ```

    #snippet

  51. une solution qui me convient en attendant de dépasser le seuil de flemme :

    ```
    nb ls --limit 10 --excerpt 5 --pager --paths --sort --reverse
    ```

    #snippet

  52. une solution qui me convient en attendant de dépasser le seuil de flemme :

    ```
    nb ls --limit 10 --excerpt 5 --pager --paths --sort --reverse
    ```

    #snippet

  53. Alien verse 1 not full
    Call me
    This year
    This summer
    A new world
    A new order
    A new leader
    New original ep by fend otw check out the lead singles "cody" & "alien" soon droping more singles
    Stay tuned
    Yt channel: youtube.com/@fffend?si=7QgpCwV
    Keep up if you want
    Unknown L*sers
    #music #art #snippet #checkout #design #song #newmusic #undergroundmusic #newartist

  54. Alien verse 1 not full
    Call me
    This year
    This summer
    A new world
    A new order
    A new leader
    New original ep by fend otw check out the lead singles "cody" & "alien" soon droping more singles
    Stay tuned
    Yt channel: youtube.com/@fffend?si=7QgpCwV
    Keep up if you want
    Unknown L*sers
    #music #art #snippet #checkout #design #song #newmusic #undergroundmusic #newartist

  55. Alien verse 1 not full
    Call me
    This year
    This summer
    A new world
    A new order
    A new leader
    New original ep by fend otw check out the lead singles "cody" & "alien" soon droping more singles
    Stay tuned
    Yt channel: youtube.com/@fffend?si=7QgpCwV
    Keep up if you want
    Unknown L*sers
    #music #art #snippet #checkout #design #song #newmusic #undergroundmusic #newartist