Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
LochNessMonster
Feb 3, 2005

I need about three fitty


Methanar posted:


the hyphens control white space. In particular the final -%} removed a newline character after the line itself. What that meant was the document separator was no longer on its own line and rendered to

secretName: cilium-etcd-secrets---

Somehow, the effect of this isn't that you have an invalid manifest you're trying to post to k8s, but the following document after the bad document separator is just ignored. So for 7 months we had this time bomb that just blew up today


I imagine that was a nice wtf moment. The fact that it didn’t break the yaml is hilarious as just sneezing at a yaml file breaks it already.

Adbot
ADBOT LOVES YOU

nielsm
Jun 1, 2009



Zero VGS posted:

That's a good idea, maybe I can get away with just a big passive copper 1U heatsink and mounting it vertically. It's just a router so I'm not sure how much heat that CPU can truly dump out.

But it's a P4, I'm sure it can pump out lots of heat.

Antigravitas
Dec 8, 2019

Die Rettung fuer die Landwirte:
I've been blocked by other stuff and not wanting to take up even more plates to spin I decided to look at some long-standing annoyance with a local disk of mine and that path lead me to the hdparm manpage.

I just have to quote from it because I love all the ways it spells out how much you can gently caress yourself with that tool.

quote:

This is EXTREMELY DANGEROUS and will very likely cause massive loss of data. DO NOT USE THIS COMMAND.
[...]
VERY DANGEROUS, DON'T EVEN THINK ABOUT USING IT.
[...]
This command is EXTREMELY DANGEROUS and could destroy both the drive and all data on it. DO NOT USE THIS COMMAND.
[...]
Under rare circumstances, such failures can result in massive filesystem corruption.
[...]
Do NOT play with this without grokking the driver source code first.
[...]
Use with extreme caution! This feature includes zero protection for the unwary, and an unsuccessful outcome may result in severe filesystem corruption!
[...]
To change the current max (VERY DANGEROUS, DATA LOSS IS EXTREMELY LIKELY), [...]
[...]
Enable/disable the power-on in standby feature, if supported by the drive. VERY DANGEROUS.
[...]
EXCEPTIONALLY DANGEROUS. DO NOT USE THIS OPTION!! Tells the drive firmware to discard unneeded data sectors [...] EXCEPTIONALLY DANGEROUS. DO NOT USE THIS OPTION!!
[...]
Perform a device reset (DANGEROUS). Do NOT use this option.
(original formatting)

And it goes on, almost everything is absolutely plastered with nauseatingly dire warnings :allears:

Completely justified of course, hdparm can send some hilariously destructive commands to a device, but it makes for an interesting read.

I found the option I wanted though, and now my spinning rust bulk storage drive is quieter than before, without data loss :eng101:.

devmd01
Mar 7, 2006

Elektronik
Supersonik
Took today and next Friday off, because why the hell not? I have a ridiculous amount of PTO hours in the bank so might as well use them. Gonna take the kids on a hike, should be a nice day for it.

Bonzo
Mar 11, 2004

Just like Mama used to make it!
My wife does not have an as much PTO as I do so I usually end up doing 4 day work weeks toward the end of November all the way until Jan 1st.

uhhhhahhhhohahhh
Oct 9, 2012
I apparently love working so much I took zero time off last year. We lose our annual leave if we don't use it by the end of the tax year so I took ever Monday and Tuesday off from the beginning of January until the end of March. Them first weeks when you're back to doing 5 days :negative:

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Bonzo posted:

My wife does not have an as much PTO as I do so I usually end up doing 4 day work weeks toward the end of November all the way until Jan 1st.

My wife is WFH so there's no way I'm using PTO and getting stuck at home with her all day

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Bob Morales posted:

My wife is WFH so there's no way I'm using PTO and getting stuck at home with her all day

You can use vacation and sit in a park eating sandwiches. Bring a Switch.

12 rats tied together
Sep 7, 2006

Methanar posted:


Somehow, the effect of this isn't that you have an invalid manifest you're trying to post to k8s, but the following document after the bad document separator is just ignored. So for 7 months we had this time bomb that just blew up today

I cant reproduce this, chucking the document separator on a SecretVolumeSource just complains that my secret-name--- secret doesn't exist and can't be found.

This is probably some dumb helm bullshit. Using whitespace control without a comment explicitly describing why is also definitely a warning flag imo.

e: that you have a helm template with 4 digits of LoC is half hilarious and half terrifying. What a terrible loving job that must be.

MJP
Jun 17, 2007

Are you looking at me Senpai?

Grimey Drawer
Folks who work in nonprofits - what has your experience been like working with infosec teams? Is it basically "here's the output from Dome9/the pentest/%securitytool%, go fix it, no exceptions, don't even ask", or will they at least hear you out if applying a fix will break something critical and you have X and Y compensating/detective controls in place?

Sickening
Jul 16, 2007

Black summer was the best summer.

MJP posted:

Folks who work in nonprofits - what has your experience been like working with infosec teams? Is it basically "here's the output from Dome9/the pentest/%securitytool%, go fix it, no exceptions, don't even ask", or will they at least hear you out if applying a fix will break something critical and you have X and Y compensating/detective controls in place?

This is going to differ from org to org. Generally a security team with absolute authority are just creating unnecessary risk themselves.

SolusLunes
Oct 10, 2011

I now have several regrets.

:barf:

MJP posted:

Folks who work in nonprofits - what has your experience been like working with infosec teams? Is it basically "here's the output from Dome9/the pentest/%securitytool%, go fix it, no exceptions, don't even ask", or will they at least hear you out if applying a fix will break something critical and you have X and Y compensating/detective controls in place?

Risk of breaking something, especially if that probability is 1, is still a risk that infosec guys should take into account. SOMETIMES you do have to say "go fix it no exceptions" but that's generally pretty rare- the only time I've had to do that at this current job was to patch the MS DNS servers because of their wormable vulnerability. Which hadn't been patched in seven months. STOP FIGHTING ME ON PATCHING GODDAMNIT, PATCHING NEEDS TO HAPPEN

Neddy Seagoon
Oct 12, 2012

"Hi Everybody!"

GreenNight posted:

You can use vacation and sit in a park eating sandwiches. Bring a Switch.

While normally that sounds like a great afternoon, you're forgetting we're all in a pandemic. Especially if they're in the USA. If you're not actively exercising outdoors or running an errand, stay home and don't potentially spread or contract COVID-19.

Matt Zerella
Oct 7, 2002

Norris'es are back baby. It's good again. Awoouu (fox Howl)

Neddy Seagoon posted:

While normally that sounds like a great afternoon, you're forgetting we're all in a pandemic. Especially if they're in the USA. If you're not actively exercising outdoors or running an errand, stay home and don't potentially spread or contract COVID-19.

If you're socially distancing, wearing a mask when unable to, and taking the right precautions then it's no more of a risk than running an errand. I'm in no way saying it's completely safe but if people want to responsibly go out then they can. As long as its not something goddamned stupid like going to indoor dining or some poo poo like that.

I'm in NYC, plenty of people are going to Central Park or wherever and doing it responsibly.

Collateral Damage
Jun 13, 2009

SolusLunes posted:

STOP FIGHTING ME ON PATCHING GODDAMNIT, PATCHING NEEDS TO HAPPEN
Love it when system owners keep refusing any proposed service window by saying their system is business critical and they can't afford downtime, then get angry when they realize they're three major versions behind on the software.

Methanar
Sep 26, 2013

by the sex ghost

12 rats tied together posted:

I cant reproduce this, chucking the document separator on a SecretVolumeSource just complains that my secret-name--- secret doesn't exist and can't be found.

This is probably some dumb helm bullshit. Using whitespace control without a comment explicitly describing why is also definitely a warning flag imo.

e: that you have a helm template with 4 digits of LoC is half hilarious and half terrifying. What a terrible loving job that must be.

In our defense, its not our helm template. We just use dump the upstream cilium chart which apparently is the one to have this bug.

code:
helm fetch cilium/cilium --version "${CILIUM_VERSION}" --untar
helm template cilium \
   --namespace kube-system \
   --set agent.keepDeprecatedLabels=true \
   --set global.etcd.enabled=true \
   --set global.etcd.managed=true \
   --set global.etcd.clusterDomain="cluster.local" \
   --set global.prometheus.enabled=true \
   --set global.prometheus.serviceMonitor.enabled=true \
   > "${ROOT_DIR}/roles/cni/cilium/files/cilium.yaml"

    - name: Install Cilium
      command: >-
        {{ bin_dir }}/kubectl apply -f {{ kube_config_dir }}/cilium.yaml
Looks like I was actually mistaken by saying its the subsequent yaml docs after the bad document separator that doesn't apply: the document containing `secret-name---` doesn't apply, but doesn't error either.

tldr it was discovered by getting a page after our cluster autoscaler failed to bring up a node. Cilium didn't start because we had just done the 1.8 upgrade yesterday and I guess something changed between 1.6 and 1.8 around who enumerates nodes: cilium agent or the operator. >1.8 the operator does it, that's what the error message and rbac diff was implying anyway. Dumb decision imo to couple app logic to the operator, but fine. With the broken yaml templating we just haven't been updating the cilium operator invisibly since january so it was way behind. Walking through our steps again we eventually noticed that hey the operator isn't updating even though there is definitely a definition for it in what we k apply. Then we found the bad templating.

Methanar fucked around with this message at 18:01 on Jul 24, 2020

devmd01
Mar 7, 2006

Elektronik
Supersonik
We were....severely behind on patches when I took over, they would only approve critical security patches because That One Time a Microsoft Patch broke something Six Years Ago. Rebuilt wsus, changed the patching process to “if it shows up in wsus as needed, it gets approved,” and hammered everyone into compliance with a monthly patching cycle. It took six months of patching to get everything rolled out, since I didn’t want to go whole hog with all of them at once.

There have been a couple of times here and there where we skipped monthly patching, but that was primarily due to a very high level of risk due to a bug or known issue in that month’s patch set

Hiro Protagonist
Oct 25, 2010

Last of the freelance hackers and
Greatest swordfighter in the world
I just got my first IT job, working at a tier 1 help desk. I'd been studying for Net+, but I figured this would be a helpful experience that would get a foot in the door of the industry, considering I just got my A+ in June. That said, I'm extremely nervous. I feel like all you ever hear from help desk jobs is how awful they are. It'll probably be a temporary thing for me, and I'll still study for the rest of the CompTIA trifecta, but I still worry I'm going to instantly hate it.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Neddy Seagoon posted:

While normally that sounds like a great afternoon, you're forgetting we're all in a pandemic. Especially if they're in the USA. If you're not actively exercising outdoors or running an errand, stay home and don't potentially spread or contract COVID-19.

You can sit in a park alone and be OK.

Plus we're all hosed. I'm in Wisconsin and there were 100+ people at an outdoor soccer game 1 mile from my house and no one had masks or were social distancing.

Defenestrategy
Oct 24, 2010

Hiro Protagonist posted:

I just got my first IT job, working at a tier 1 help desk. I'd been studying for Net+, but I figured this would be a helpful experience that would get a foot in the door of the industry, considering I just got my A+ in June. That said, I'm extremely nervous. I feel like all you ever hear from help desk jobs is how awful they are. It'll probably be a temporary thing for me, and I'll still study for the rest of the CompTIA trifecta, but I still worry I'm going to instantly hate it.

Honestly, helpdesk's awfulness is overblown I feel and depends on the company you're working at. I've done helpdesk at places where if I was paid more it'd be down right pleasant, but I've found that a lot of IT dudes get into IT without having people skills or at least the ability to fake them and do the "UGH I HATE PEOPLE" schtick while working in what is primarily a service oriented occupation.


edit: Certainly as a permanent career choice its probably lovely just on the pay ceiling basis, but as a place to get some money and study for certs it certainly beats digging ditches by a long shot.

edit2: I feel that smaller company(less than 100 people) help desk might be the golden job for entry level dudes, because you end up doing everything instead of just being "did you restart your computer?" guy so you end up getting a ton of experience in various different places.

Defenestrategy fucked around with this message at 17:47 on Jul 24, 2020

Thanks Ants
May 21, 2004

#essereFerrari


Hiro Protagonist posted:

I just got my first IT job, working at a tier 1 help desk. I'd been studying for Net+, but I figured this would be a helpful experience that would get a foot in the door of the industry, considering I just got my A+ in June. That said, I'm extremely nervous. I feel like all you ever hear from help desk jobs is how awful they are. It'll probably be a temporary thing for me, and I'll still study for the rest of the CompTIA trifecta, but I still worry I'm going to instantly hate it.

Eh, everybody has to eat some amount of poo poo and do helpdesk at the start of their careers. It's a ton easier than being an apprentice to a tradesperson.

The Fool
Oct 16, 2003


Title change to 'Cloud Engineer' and 20% raise approved. Waiting to find out if takes effect at the beginning of the next year or if it can happen earlier than that.

Schadenboner
Aug 15, 2011

by Shine
I mean, bitching about help desk also a performative/shared-experience thing?

Methanar
Sep 26, 2013

by the sex ghost

The Fool posted:

Title change to 'Cloud Engineer' and 20% raise approved. Waiting to find out if takes effect at the beginning of the next year or if it can happen earlier than that.

:getin:

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Collateral Damage posted:

Love it when system owners keep refusing any proposed service window by saying their system is business critical and they can't afford downtime, then get angry when they realize they're three major versions behind on the software.

I finally get to update some wireless equipment that's been up for 560 days.

Bonzo
Mar 11, 2004

Just like Mama used to make it!
There is a special place in Hell for sales folk that wait until the end of the call to ask questions about items already covered, and then make us go over my 30 min because they where not paying attention at all.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Bonzo posted:

There is a special place in Hell for sales folk that wait until the end of the call to ask questions about items already covered, and then make us go over my 30 min because they where not paying attention at all.

FTFY

Antioch
Apr 18, 2003

Bob Morales posted:

I finally get to update some wireless equipment that's been up for 560 days.

The poorly planned and implemented HyperV servers I inherited when starting this job have an uptime approaching 1500 days. They're 7 years old, which means they've been up for more than half their lives.

I'm really looking forward to migrating everything to a proper esxi cluster in a couple months and then accidentally dropping these R320s down a flight of stairs, or off a roof, or into the river. As the old joke goes, it'll be A Dell, Rolling in the Deep.

22 Eargesplitten
Oct 10, 2010



Holy poo poo that might have been my best ever phone interview, hit it off super well with the hiring manager, he appreciated the tangents I can't stop myself from going off on when I'm excited about the topic, and he said he expects his employees to work no more than 40 hours a week. I shouldn't get so attached to a potential job before the technical interview, but it sounds absolutely amazing.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

22 Eargesplitten posted:

Holy poo poo that might have been my best ever phone interview, hit it off super well with the hiring manager, he appreciated the tangents I can't stop myself from going off on when I'm excited about the topic, and he said he expects his employees to work no more than 40 hours a week. I shouldn't get so attached to a potential job before the technical interview, but it sounds absolutely amazing.

Hopefully you won't get ghosted.

LochNessMonster
Feb 3, 2005

I need about three fitty


22 Eargesplitten posted:

Holy poo poo that might have been my best ever phone interview, hit it off super well with the hiring manager, he appreciated the tangents I can't stop myself from going off on when I'm excited about the topic, and he said he expects his employees to work no more than 40 hours a week. I shouldn't get so attached to a potential job before the technical interview, but it sounds absolutely amazing.

Awesome, hope you get an offer.

Thomamelas
Mar 11, 2009

Thanatosian posted:

We're switching vendors for some documents we provide to our customers online. Our previous vendor provided the documents as individual .pdf files that we import into our document management system using an index file with metadata that includes the file name. The new vendor provides a single PDF with metadata and the number of pages per document (think csv with customernumber,customername,documentdate,#ofpages). I've seen a PDF Command Line tool called PDFtk before; is anyone familiar with that or another open-source/proprietary command line PDF tool? I haven't worked with one before, and it's hard to pick out scams from legitimate software when you're just Googling.

I'm not a programmer, but I'm okay with scripting (Powershell, batch, SQL), I wanted to take a run at it. We requested a professional services quote from the document manager software manager, and they quoted $26,000; we're small enough that that is probably prohibitive, and if I can solve it well with a script, it's at least some brownie points. I'd want to break up the PDF based on the number of pages in the original index file, and generate a new index file with the metadata and replace the number of pages with a filename for the new individualized .pdf file. Is the $26,000 reasonable for that? Seems high to me, but I know that sometimes seemingly simple problems that are actually pretty difficult to resolve programming-wise.

I know this is a bit late, but I've used the PSWritePDF powershell module to split some PDFs. It seemed to work okay.

22 Eargesplitten
Oct 10, 2010



GreenNight posted:

Hopefully you won't get ghosted.

It's always possible, but he did say he was going to pass along the go-ahead to the HR manager, I guess she does all the interview scheduling.

Ham Equity
Apr 16, 2013

i hosted a great goon meet and all i got was this lousy avatar
Grimey Drawer

Thomamelas posted:

I know this is a bit late, but I've used the PSWritePDF powershell module to split some PDFs. It seemed to work okay.

Not late at all, I'm on vacation haven't been in the office since I posted that.

bull3964
Nov 18, 2000

DO YOU HEAR THAT? THAT'S THE SOUND OF ME PATTING MYSELF ON THE BACK.


Not that it matters to me since I'm remote regardless, but just got word that corporate will not be reopening the office in 2020.

Methanar
Sep 26, 2013

by the sex ghost

bull3964 posted:

Not that it matters to me since I'm remote regardless, but just got word that corporate will not be reopening the office in 2020.

RIP commercial real estate market

Docjowles
Apr 9, 2009

Bob Morales posted:

I finally get to update some wireless equipment that's been up for 560 days.

I didn’t save a screenshot because I’m a dummy but last year I got to decomm a bunch of switches that had been up continuously for like 7 years. It was the out of band management network at our lovely colo and only accessible over VPN but not exactly ideal lol.

The hardware was loving ancient Brocade garbage that I think was end of life when my old boss originally bought and deployed it second hand from god knows where. Don’t have to reboot equipment for security patching if the vendor doesn’t still publish updates! Checkmate, infosec dweebs :smug:

It felt real good to throw those all in the metaphorical dumpster.

Bonzo
Mar 11, 2004

Just like Mama used to make it!

Methanar posted:

RIP commercial real estate market

Nah is just means the lovely MSPs will have nicer offices now since the prices will be down.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Our company told us to expect everyone to be back in the office at some point, just not sure when. SO DONT GET USED TO WFH pretty much.

Adbot
ADBOT LOVES YOU

uhhhhahhhhohahhh
Oct 9, 2012
They made us do individual covid risk assessments and I threw on mine I wanted permanent work from home and they tentatively accepted it. I say tentatively because I think I'll be the first permanent WFH employee out of about ~5k staff and they have zero policies or processes written up for it.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply