explainshell.com

VN:F [1.9.22_1171]
Rating: 6.0/10 (1 vote cast)

Match linux command-line arguments to view their help text.

stackshare.io

VN:F [1.9.22_1171]
Rating: 8.0/10 (1 vote cast)

Dev / Production stacks for all to see. Handy tool to see what software is trending today.

aws.amazon.com

VN:F [1.9.22_1171]
Rating: 7.7/10 (3 votes cast)

Amazons’s cloud computing & web hosting service.

Amazon Timestream for InfluxDB Now Supports Advanced Metrics

27 March 2026 @ 10:48 pm

Amazon Timestream for InfluxDB now offers Advanced Metrics, providing comprehensive visibility into your database performance and health. This new capability automatically publishes detailed operational metrics from your Timestream for InfluxDB 2 instances directly to Amazon CloudWatch, enabling real-time monitoring and alerting without requiring additional configuration or instrumentation for both Single-AZ and Multi-AZ Timestream for InfluxDB 2 databases. With Advanced Metrics, customers can track critical database performance indicators, set up custom dashboards, and configure automated alerts based on predefined thresholds. This enhanced observability helps DevOps teams quickly identify potential issues, optimize database performance, and ensure high availability for time-series applications by providing deeper insights into resource utilization, query performance, and system health across their InfluxDB 2 environments. Amazon Timestream for InfluxDB Advanced M

Amazon CloudWatch Logs now supports data protection, OpenSearch PPL and OpenSearch SQL for the Infrequent Access ingestion class

27 March 2026 @ 8:00 pm

Amazon CloudWatch Logs now supports expanded analytics and data protection capabilities for the Infrequent Access (Logs IA) ingestion class, including support for data protection, OpenSearch’s Piped Processing Language (PPL) and OpenSearch SQL. These enhancements make it easier for customers to perform flexible analytics and protect sensitive data while cost-effectively consolidating all your logs natively on AWS, making Logs IA ideal for ad-hoc troubleshooting and forensic analysis on infrequently accessed logs. Logs IA is a cost-effective ingestion class for consolidating logs that are queried occasionally, such as forensic investigations. Logs IA currently offers log analytics with Logs Insights Query Language, export to S3, and encryption with a lower ingestion price per GB compared to the Standard log class. With today’s launch, customers can now use OpenSearch SQL and OpenSearch PPL queries to perform advanced analytics. In addition, data protection allows customer

AWS Lambda supports up to 32 GB of memory and 16 vCPUs for Lambda Managed Instances

27 March 2026 @ 4:00 pm

AWS Lambda now supports up to 32 GB of memory and 16 vCPUs for functions running on Lambda Managed Instances, enabling customers to run compute-intensive workloads such as large-scale data processing, media transcoding, and scientific simulations without managing any infrastructure. Customers can also configure the memory-to-vCPU ratio — 2:1, 4:1, or 8:1 — to match the resource profile of their workload. Lambda Managed Instances lets you run Lambda functions on managed Amazon EC2 instances with built-in routing, load balancing, and auto-scaling, giving you access to specialized compute configurations including the latest-generation processors and high-bandwidth networking, with no operational overhead. Customers building compute-intensive applications such as data processing pipelines, high-throughput API backends, and batch computation workloads require substantial memory and CPU resources to process large datasets, serve low-latency responses at scale, and run complex

AWS Management Console now supports settings to control service and Region visibility

27 March 2026 @ 3:00 pm

Today, AWS announces the general availability of Visible services and Visible Regions account settings in the AWS Management Console. These settings allow you to customize which services and regions appear in the Management Console for authorized users in your account, helping your users easily identify what is available to them and simplifying navigation. You can configure these settings in the AWS Management Console under Unified Settings in the Account Settings tab. You can also configure these setting programmatically via User Experience Customization (UXC) in AWS Command Line Interface (CLI), AWS Software Development Kits (SDKs), AWS Cloud Development Kit (CDK), or AWS CloudFormation. The Visible services and Visible Regions settings are available in AWS Commercial Regions at no additional cost. Visit the AWS User Experience Customization documentation page and

Amazon GameLift Servers expands instance support with next-generation EC2 instance families

27 March 2026 @ 9:00 am

Amazon GameLift Servers now supports Amazon EC2 5th through 8th generation instances, offering enhanced price-performance, efficiency, and flexibility for game server hosting. This update allows developers to leverage the latest advancements in EC2 compute, memory, and networking across three main instance families: General Purpose (M-series): Balanced CPU, memory, and networking for a wide range of game workloads. Compute Optimized (C-series): High-performance compute instances with a 2:1 memory ratio, ideal for CPU-intensive game servers. Memory Optimized (R-Series): Optimized for high-memory workloads with an 8:1 memory ratio, supporting complex simulations and large player sessions. Each new EC2 generation brings significant improvements: 5th Gen: Proven reliability with Intel processors with balanced performance 6th Gen: Includes AWS Graviton2 ARM-based options alongside Intel and AMD var

AWS HealthImaging announces study-level fine-grained access control

27 March 2026 @ 7:00 am

AWS HealthImaging now supports fine-grained access control, enabling organizations to securely manage access to medical imaging data at the DICOM study and series levels. Medical imaging workflows are typically organized around DICOM studies, which are stored in AWS HealthImaging as one or more image set resources. Now customers can easily grant users access to all image sets for a set of DICOM Studies or Series with easy-to-maintain IAM policies. Customers can now grant permissions for DICOMweb APIs using DICOM Study Instance UIDs and Series Instance UIDs directly in their IAM policies, eliminating the need to list individual image set ARNs. Customers can now create dynamic, temporary access grants using AWS Security Token Service (STS) session policies with low-latency authentication. This capability provides enhanced protection for Protected Health Information (PHI) by scoping access grants to specific Studies or Series rather than entire data stores. This launch better s

Amazon EC2 High Memory U7i instances now available in Europe (Milan)

26 March 2026 @ 10:30 pm

Amazon EC2 High Memory U7i-8TB instances (u7i-8tb.112xlarge) and U7i-12TB instances (u7i-12tb.224xlarge) are now available in AWS Europe (Milan). U7i instances are part of AWS 7th generation and are powered by custom fourth generation Intel Xeon Scalable Processors (Sapphire Rapids). U7i-8tb instances offer 8TiB of DDR5 memory, and U7i-12tb instances offer 12TiB of DDR5 memory, enabling customers to scale transaction processing throughput in a fast-growing data environment. U7i-8tb instances deliver 448 vCPUs; U7i-12tb instances deliver 896 vCPUs. Both instances support up to 100 Gbps of Amazon EBS bandwidth for faster data loading and backups, 100 Gbps of network bandwidth, and ENA Express. U7i instances are ideal for customers using mission-critical in-memory databases like SAP HANA, Oracle, and SQL Server. To learn more about U7i instances, visit the High Memory instances page.

AWS Step Functions adds 28 new service integrations, including Amazon Bedrock AgentCore

26 March 2026 @ 10:00 pm

AWS Step Functions expands its AWS SDK integrations with 28 additional services and over 1,100 new API actions across new and existing AWS services, including Amazon Bedrock AgentCore and Amazon S3 Vectors. This expansion enables you to orchestrate a broader set of AWS services directly from your workflows without writing integration code. AWS Step Functions is a visual workflow service capable of orchestrating over 220 AWS services to help customers build distributed applications at scale. With the Amazon Bedrock AgentCore service integration, you can invoke AI agent runtimes with built-in retries, run multiple agents in parallel using Map states, and automate agent provisioning workflows that create, update, and tear down agent infrastructure as workflow steps. This expansion also includes Amazon S3 Vectors for automating document ingestion pipelines that populate knowledge bases for AI applications. It also a

Palmyra Vision 7B from Writer now available on Amazon Bedrock

26 March 2026 @ 8:38 pm

Amazon Bedrock is a fully managed service that offers a choice of high-performing foundation models from leading AI companies via a single API. Starting today, customers can use Palmyra Vision 7B from Writer on Amazon Bedrock to build generative AI applications that interpret and generate text from images. With Palmyra Vision 7B on Bedrock, customers can build generative AI applications for visual understanding tasks without managing inference infrastructure. The model has been trained on PixMo, a dataset of 1 million high-quality image-text pairs, and excels in visual question answering and image-text comprehension for enterprise applications. It enables visual understanding tasks such as document analysis, chart interpretation, and image-based question answering. Palmyra Vision 7B can extract handwritten text, classify objects and colors, interpret plots and dashboards, and answer natural-language questions about image content. Typical applications include a

Amazon SageMaker Studio launches support for Kiro and Cursor IDEs as remote IDEs

26 March 2026 @ 7:53 pm

Today, AWS announces the ability to remotely connect from Kiro and Cursor IDEs to Amazon SageMaker Studio. This new capability allows data scientists, ML engineers, and developers to leverage their Kiro and Cursor setup - including its spec-driven development, conversational coding, and automated feature generation capabilities - while accessing the scalable compute resources of Amazon SageMaker Studio. By connecting Kiro and Cursor to SageMaker Studio using the AWS Toolkit extension, you can eliminate context switching between your local IDE and cloud infrastructure, maintaining your existing agentic development workflows within a single environment for all your AWS analytics and AI/ML services. SageMaker Studio, offers a broad set of fully managed cloud interactive development environments (IDE), including JupyterLab and Code Editor based on Code-OSS (Open-Source Software), and VS Code IDE as remote IDE. Starting today, you can also use your customized local Kiro and Curs

networkworld.com

VN:F [1.9.22_1171]
Rating: 6.0/10 (1 vote cast)

Information, intelligence and insight for Network and IT Executives.

European Commission data stolen in a cyberattack on the infrastructure hosting its web sites

27 March 2026 @ 9:18 pm

The European Commission is continuing to investigate the theft of data from its cloud infrastructure earlier this week. On Thursday, the Commission revealed there had been an attack on its Europa.eu platform, offering few details, then, on Friday, security news site Bleeping Computer reported that the attack had involved the compromise of an account or accounts on Amazon Web Services (AWS). Th

Equinix launches AI platform to simplify control of distributed AI resources

27 March 2026 @ 7:25 pm

An age-old problem for enterprise IT managers has always been data sprawl. However, in the era of AI, where data is needed from every potential source available, scale in data sprawl become unmanageable. Existing architectures weren’t designed for distributing processing, which is part and parcel of AI training. Data center provider Equinix says it has the solution:  The Distributed AI Hub powered by Equinix Fabric Intelligence. The

Return of the PTT: Poste Italiane looks to snap up telco TIM

27 March 2026 @ 4:42 pm

During a wave of privatization in the 1980s and 90s, there was a separation of postal services and telecoms throughout Europe as governments looked to tap into the liberalization of telecoms markets by breaking up their national PTTs — government agencies with a monopoly on operating postal, telephone, and telegraph services. Now, for one country at least, it’s back to square one: Poste Italiane is ready to snap up Italian telecoms provider TIM in a deal worth €10.8 billion. Postal services have been hit badly over the past few decades: The

Networking terms and definitions

27 March 2026 @ 2:09 pm

To find a brief definition of the networking term you are looking for user your browser’s “Find” feature then follow links to a fuller explanation. Abstraction interface (SAI) An abstraction interface (SAI) is an API designed to allow network software (such as an operating system) to control the hardware of a network switch. Traditionally, if you bought a switch from a specific vendor, you had to use its software to run it. If you wanted to switch hardware, you had to redo management system. SAI c

Intel: Latest news and insights

26 March 2026 @ 9:08 pm

More processor coverage on Network World:AMD news and insights | Nvidia news and insights Intel is hoping for a turnaround under its new CEO, Lip-BuTan. Intel’s Q1 2025 revenue was $12.7 billion, flat year-over-year. While revenue for its client computing group dropped 8%, the data center and AI segment showed an 8% increase, dr

Network jobs watch: Hiring, skills and certification trends

26 March 2026 @ 6:09 pm

Network and infrastructure roles continue to shift as enterprises adopt technologies such as AI-driven network operations, multicloud networking, zero trust network access (ZTNA), and SD-WAN. Here’s a recap of some of the latest industry research, hiring s

Data center poaching adds to staffing crisis

26 March 2026 @ 6:07 pm

Poaching talent has become a default response to the data center staffing crunch, but new findings from Uptime Institute suggest the strategy is unsustainable. Nearly half of operators (46%) report difficulty finding qualified candidates, according to Uptime Intelligence, the institute’s research and analysis practice. In addition, 37% struggle to keep the staff they already have—despite escalating efforts to buy experience from competitors rather than build it in-house. Roughly 25% of staff are being hired away by competitors (doing data center work), and 12% are being hired away by non-competitors (doing non-data center wor

Arm shifts course, moves into silicon business

26 March 2026 @ 5:28 pm

For 36 years, Arm Holdings made CPU designs and licensed them to anyone who wanted them, who then designed and made their own custom modifications. But that is changing. Arm has announced its expansion into production of silicon products for the first time in the company’s history. The company’s first product is the Arm AGI CPU, an Arm-designed CPU purpose built for AI data centers, with Meta as its first customer. “AI has fundamentally redefined how computing is built and deployed. Agentic computing is accelerating that change,” said

AI’s need for speed, optical connectivity in focus at OFC 2026

26 March 2026 @ 5:13 pm

The need for high-throughput and energy-efficient optical infrastructure, driven by AI demands, was a recurring theme at this month’s Optical Fiber Communications (OFC) conference in Los Angeles. The so-called opticalization of the network, where fiber replaces copper and optical connectivity becomes imperative, is critical in the AI era, according to OFC 2026 participants and industry watchers. “The excitement across the ecosystem was palpable, as AI drives significant demand for connectivity solutions across scale-up, scale-out, and scale-across domains,” wrote

The optical imperative and Nokia’s vision to close the AI gap

26 March 2026 @ 1:58 pm

While all eyes were on Nvidia GTC last week, there was another event happening with implications for the evolution of AI. The Optical Fiber Communications (OFC) conference took place in Los Angeles and addressed the desperate hunt for more capacity. For years, the networking industry has operated on a comfortable four-year innovation cycle. But as generative AI transitions from a boardroom initiative to physical infrastructure, that timeline has been accelerated. During the OFC 2026 event, Nokia held a press and analyst event to announce a number of new products th

forensicswiki.org

VN:F [1.9.22_1171]
Rating: 8.0/10 (1 vote cast)

Computer forensic tools and techniques used by investigators

cyberciti.biz

VN:F [1.9.22_1171]
Rating: 6.0/10 (2 votes cast)

online community of new and seasoned Linux / Unix sysadmins.

Unable to load the feed. Please try again later.

heartinternet.co.uk

VN:F [1.9.22_1171]
Rating: 8.3/10 (3 votes cast)

Hosting packages for an initial web presence

SSL Certificates are changing. Here’s what you need to know.

17 March 2026 @ 10:12 am

The rules around SSL certificates are changing across the whole internet. The good news is that for most customers, very little will change on your side. This is an industry-wide... The post SSL Certificates are changing. Here’s what you need to know. appeared first on Heart Internet.

Hosting VPS Linux vs Windows VPS

9 March 2026 @ 3:03 pm

The post Hosting VPS Linux vs Windows VPS appeared first on Heart Internet.

Domain Name Transfer Checklist: Everything You Need to Know

3 March 2026 @ 2:56 pm

The post Domain Name Transfer Checklist: Everything You Need to Know appeared first on Heart Internet.

Heart Internet Win Gapstars Innovation Award 2026

23 February 2026 @ 11:57 am

We’re incredibly proud to celebrate our Site Reliability Engineering team, who have won the Gapstars Innovation Award for their outstanding work improving platform stability, security, and visibility across our shared... The post Heart Internet Win Gapstars Innovation Award 2026 appeared first on Heart Internet.

A/B Testing Explained: A Practical Guide To Better Results | Part 1

20 February 2026 @ 8:32 am

If you want to improve your website you probably need to do A/B testing, otherwise known as split testing. Instead of guessing, A/B testing allows you to experiment more scientifically.... The post A/B Testing Explained: A Practical Guide To Better Results | Part 1 appeared first on Heart Internet.

How to enable two-factor authentication (2FA) on your Heart Internet account

28 January 2026 @ 12:37 pm

Account security matters, and switching on two-factor authentication (2FA) is a quick win. 2FA adds a second check during the sign-in process, so even if someone compromises your password, they still can’t get in.  To enable 2FA:  Step 1: Open your... The post How to enable two-factor authentication (2FA) on your Heart Internet account appeared first on Heart Internet.

How to Choose the Perfect Domain Name for Your Business

9 July 2025 @ 9:30 am

Get Your Name Right – The Internet Never Forgets Choosing a domain name might sound simple – until you realise it’s the online equivalent of naming your child. No pressure.... The post How to Choose the Perfect Domain Name for Your Business appeared first on Heart Internet.

What is a VPS? And is it Time You Got One?

25 June 2025 @ 9:30 am

Discover what a VPS server is, how VPS hosting works, and why it’s ideal for small businesses. Learn the benefits and explore VPS plans with Heart Internet. The post What is a VPS? And is it Time You Got One? appeared first on Heart Internet.

We’re Now Certified by the Green Web Foundation

11 June 2025 @ 9:30 am

💚 Hosting that works hard, treads lightly.   Big news: Heart Internet is now officially listed with the Green Web Foundation. That means our hosting services are recognised as being... The post We’re Now Certified by the Green Web Foundation appeared first on Heart Internet.

What is Web Hosting and Why Does Your Business Need It?

6 May 2025 @ 4:54 pm

Without web hosting, your website would not be visible or accessible to users! It is crucial to host your website with a website hosting service to ensure that your business... The post What is Web Hosting and Why Does Your Business Need It? appeared first on Heart Internet.

serverfault.com

VN:F [1.9.22_1171]
Rating: 6.0/10 (1 vote cast)

Common Server issues – FAQs and answers from those in the know

File stuck in php-fpm opcache?

28 March 2026 @ 2:17 pm

I had a php file I was unable to update. The server was constantly returning an old version of the file. After deleting the file I got 404, but restoring the file again returned an old version of the file. All other files I tested worked as expected. Copying the file to a new file name worked as expected. Just that one file wouldn't update. After calling opcache_reset it started working. So it seems the cache was not correctly invalidated for that one file on change. This is scary. Why would this happen? How can I prevent this from happening again, besides disabling opcache? I found this other example of it happening to someone (though it doesn't specify it happening to just one file): Why Does PHP-FPM sometimes get stuck serving old files?

Trigger scripts via dovecot imapsieve without actually touching the read-only mailbox

27 March 2026 @ 11:15 pm

Configuring a Sieve script to run after IMAP flag changes like so: [..] dovecot_config_version = 2.4.0 protocol imap { mail_plugins { acl = yes imap_acl = yes imap_sieve = yes } } sieve_plugins { sieve_imapsieve = yes } sieve_script script_name { cause = flag driver = file name = script_name # content does not matter, empty file sufficient path = /etc/dovecot/file-name.sieve type = after } [..] In conjunction with an ACL of lookup/read/write/write-seen (no insert/post!) on a mailbox gives me errors like this.. on each and every flag IMAP change: imap(redacted@example)<123> Error: sieve: Execution of script 'script_name/file-name' failed with unsuccessful implicit keep Is there a more proper (not relying on dovecot hand

Apache redirect all ports from subdomain to back end server

27 March 2026 @ 4:20 pm

I have multiple servers with different services. I have Apache on a publicly accessible server, pointing different subdomains to different servers (*.example.com, *.serv1.example.com, *.serv2.example.com). One problem that is when I go to serv1.example.com:5320, it goes to example.com:5320. Here is the Apache server config: <VirtualHost *:80> ServerName serv1.example.com ServerAlias *.serv1.example.com ProxyPreserveHost On ProxyPass / http://100.10.20.30/ ProxyPassReverse / http://100.10.20.30/ </VirtualHost> I tried using <VirtualHost *:*> but that didn't route traffic through in general. The back end servers are also running nginx, so that I could give them their own subdomains, and the main server is running Ubuntu with the backend servers running Arch linux. Any help would be much appreciated.

How to configure dovecot to handle one specific user special?

27 March 2026 @ 1:13 pm

My dovecot setup looks like this: # 2.4.2 (0962ed2104): /etc/dovecot/dovecot.conf # Pigeonhole version 2.4.2 (767418c3) # OS: Linux 6.12.0-160000.25-default x86_64 # Hostname: eagle # 9 default setting changes since version 2.4.0 dovecot_config_version = 2.4.0 dovecot_storage_version = 2.4.0 listen = * protocols = imap lmtp ssl = required protocol imap { imap_idle_notify_interval = 60 secs mail_max_userip_connections = 10 } ssl_server { cert_file = /etc/dovecot/certs/cert.pem key_file = /etc/dovecot/certs/privkey.pem } namespace inbox { mail_driver = mbox mail_inbox_path = /var/mail/%{user} mail_path = ~/Mail inbox = yes separator = / } mbox { read_locks = fcntl write_locks = fcntl } passdb pam { service_name = dovecot } userdb passwd { use_worker = yes } service imap-login { inet_listener imap { } inet_listener imaps { port = 993 ssl = yes } } namespace inbox { inbox = yes separator = / mailbox Drafts { special_use

Email from Google to Microsoft 365 fails, but no error messages

27 March 2026 @ 12:55 pm

Due to a migration process, I need to adjust our inbound mail configuration to transition to exchange online. The old configuration Config A MX 10 mymail-1.mydomain.com. MX 20 mymail-2.mydomain.com. The currently desired configuration is something like Config B MX 5 mydomain.mail.protection.outlook.com. MX 10 mymail-1.mydomain.com. MX 20 mymail-2.mydomain.com. After enabling this, everything seemd to work fine: As expected, almost all incoming mails entered via Exchange Online, every now and then some incoming mail used the fallback or even the fallback of the fallback. There was but one(?) exception that did not work: Mails coming from Google customers. From what I can assess from my side, Google perhaps tried to go via the Microsoft route and failed, but never tried the fallback or second fallback. Even after several hours, neither did the mail arrive her

Puppet fails with Cannot allocate memory - fork(2) on Debian Trixie VMs (Ganeti) unless RAM is increased to 8 GB

27 March 2026 @ 3:59 am

I am facing a memory-related issue on Debian Trixie VMs running on Ganeti. These VMs are used exclusively as PostgreSQL database servers. The same Puppet configuration works fine on Debian Bullseye and Bookworm, but consistently fails on Trixie. Environment Hypervisor: Ganeti Guest OS: Debian Trixie VM RAM: 4 GB (fails), works only at 8 GB Workload: PostgreSQL + Puppet agent Puppet version: Puppet 7 PostgreSQL version: 14 Problem When running Puppet (runpuppet), I get multiple failures like: Error: Could not evaluate: Cannot allocate memory - fork(2) Error: Could not prefetch mount provider 'parsed': Cannot allocate memory - fork(2) Error: Could not prefetch sysctl provider 'augeas': Cannot allocate memory - fork(2) Example full output: Error: /Stage[main]/Ssh/Exec[/bin/systemctl enable systemd-networkd-wait-online.service]: Could not evaluate: Cannot allocate memory - fork(2) Error: /Stage[main]/Profiles::Monitor

The configured disk size and the size provided by the service do not match

26 March 2026 @ 6:04 pm

enter image description here My boot disk is 40GB, but my server's actual disk space is only 30GB. enter image description here

Postfix with SMTP: "From" error

26 March 2026 @ 2:39 pm

I am running a Debian server which hosts two different web applications running on apache2 that both need to be able to send emails from specific email addresses. Those addresses are actual email accounts from my provider with my domain name, so I am trying to implement SMTP with postfix. In order to test I am trying to send this email using sendmail in CLI: email.txt: From: [email protected] Subject: test test test test sendmail [email protected] < ./email.txt However it doesn't work. Here's what /var/log/mail has to say about it (I trimmed the timestamps for readability): postfix/pickup[1130256]: 075FC37CE43: uid=0 from=<root> postfix/cleanup[1133097]: 075FC37CE43: message-id=<20260326142453.075FC37CE43@myhostname> postfix/qmgr[1130257]: 075FC37CE43: from=<root@myhostname>, size=272, nrcpt=1 (queue active) postfix/smtp[1133100]: 075FC37CE43: to=<[email protected]>, relay=send

Regarding using HAPROXY with proxy protocol to secure database

26 March 2026 @ 12:30 pm

I read this blog: https://www.haproxy.com/blog/using-haproxy-with-the-proxy-protocol-to-better-secure-your-database but am confused as the author uses some addresses to indicate the problem and different addresses within the solution. If someone could provide a little clarity about it. We have 4 percona (MYSQL) servers: 2 in datacentre A and 2 in datacentre B. The user entry point is via haproxy, where we have 1 in both datacentres It looks to me like the author suggests that every possible source for access on the client side would need to be added to the database: mysql> CREATE USER 'haproxy'@'192.168.122.64'; which, I assume would have to be both source user and host. But what if there are multiple users on each host? How to cater for DHCP hosts? Would we have to then have global wildcards declare

OpenLDAP conditional sudo based on server tag

26 March 2026 @ 8:00 am

I want to setup a conditional sudo access rule to a host. I understand adding a sudo schema, and then adding a user to group that gives sudo powers. But I want to distinguish somehow hosts by custom ldap groups, and allow users sudo access if they belong to same ldap group too. Example picture: ldap setup wish Imagine Host1 belongs to groupA, and Host2 belongs to groupB. I would like to add Alice to groupA and to groupSudo - so she can execute sudo commands on Host1, while she would not have sudo access on host2, but she can still login there as simple user. Similarly I want to assign Bob to groupB and groupSudo - that would give him sudo only on Host2. And Cynthia to all 3 groups so that she gets sudo everywhere. I'm struggling to finding this solution though. I did find a solution where I would restrict Alice login to Host2 entirely, by configuring sssd to not allow logins if not in groupB. H

poundhost.com

VN:F [1.9.22_1171]
Rating: 6.7/10 (3 votes cast)

Cheap dedicated server hosting

tagadab.com

VN:F [1.9.22_1171]
Rating: 8.0/10 (1 vote cast)

Cheap developer VPS hosting from £10