@hadret@fosstodon.org

He/Him. System Administrator, #UNIX (#AIX, #FreeBSD, #Solaris, #SmartOS / #Illumos) and #Linux (#Debian, #Gentoo) lover ❤️ Working #remote from #Berlin 🇩🇪, originates from Poland 🇵🇱 Painfully casual #gamer (#PC, #3DS, #Switch) 🎮 #Anime & #manga fan 🇯🇵 Skeptic, vegetarian and friend of animals 🐈 Dad & hunbando 👨‍👩‍👧‍👦

Infra Engineer @ https://Ghost.org 👻 Nonsensical opinions are my own, all the rest was probably stolen.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

jerry, to random
@jerry@infosec.exchange avatar

On the upside, adding an additional app server to Infosec.exchange US has nearly eliminated the lags that I had been seeing, but on the downside, I am STILL seeing the media upload issue where nginx helpfully swaps all servers mid-upload, resulting in an error 500/503 🤬

hadret,
@hadret@fosstodon.org avatar

@jerry Do you share your nginx config anywhere by chance? Would love to have a peek 👀

jerry, to random
@jerry@infosec.exchange avatar

I also ran into a really odd iptables problem... when I meshed in the second app server node using wireguard, my egress filter rule was blocking outbound traffic on both hosts. After some fiddling, out of frustration, I flushed the rules out of iptables on both hosts - so no rules. And... iptables was still blocking the outbound traffic. I ended up having to reboot each host - and once I did that, things worked ok. Has anyone seen iptables go into zombie mode before?

hadret,
@hadret@fosstodon.org avatar

@jerry Yep, happened to me as well, number of times

jerry, to random
@jerry@infosec.exchange avatar

Things on infosec.exchange were getting a little bit sluggish, and I've had complaints about media processing taking a long time so I added another app server for the US region. In the past, that has caused media uploads for some people to just fail outright because the reverse proxy hops the upload from one app server to another - and the other has no idea what to do with the last half of a file. I am hopeful I've got that problem ironed out in the nginx config, but would be interested in knowing if anyone runs into that...

hadret,
@hadret@fosstodon.org avatar

@jerry ip_hash?

hadret,
@hadret@fosstodon.org avatar

@jerry That’s interesting — ideally ip_hash should suffice, but I guess with a really slow connection it could still reach the timeout? An edge case for sure, fingers crossed it will work out 🤞🏻

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • Ask_kbincafe
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines