LINUXOR.SK ... open source notes ...

SOLUTIONz

category: solutionz · date: 2026-10-02 · updated: 2026-10-03

A Solution is one complete system that I designed, built and ran, written up from the original design documents and working notes. The notes and howtos elsewhere on this site each answer one question; a Solution shows how the answers fit together when the thing has to stay up.

Every Solution is told the same way: why it was built, how it was designed, how each part was configured, and how it was operated. The configuration files are not pasted into the articles. Each one is a document of its own, commented, and linked from the article that explains it.

The Solutions

SolutionBuiltWhat it is
HashiCorp Vault2021-2024Secrets management for a multi-tenant service platform: three Vault clusters on Integrated Storage, Transit auto-unseal, HAProxy and Keepalived, AppRole, audit logging, snapshots to object storage
NetApp MetroCluster2017-2019Primary storage for a management infrastructure in two sites: fabric-attached MetroCluster of FAS8200 pairs, Brocade fabrics and ATTO bridges, NFS for KVM, volume encryption, Active Directory logins, Unified Manager, Tiebreaker, upgrades and troubleshooting
Email system on Postfix2017-2019Mail for the servers, applications and appliances of a management infrastructure in two sites: an SMTP pair behind a Keepalived address, senders authorized by Active Directory groups, a Bash content filter that encrypts every message with S/MIME or PGP/MIME, relays to the internet, mailboxes on Dovecot and Roundcube webmail
Proxy with SSL interception2018-2019Internet access for the servers of a management infrastructure in two datacenters: one Squid forward proxy per datacenter on RHEL 7.5 with two interfaces behind firewalld zones that drop by default, rich rules for the proxy port, Ansible and monitoring, SSL interception with peek, splice and bump under a self-signed CA renewed every year, the SELinux module it needed, and a client that refused the intercepted certificates
Balabit SCB2017-2018Privileged session control for a management infrastructure in two sites: a high-availability pair of Balabit Shell Control Box appliances per site in non-transparent mode, connections per partner and protocol to jump servers chosen in the username, Active Directory logins, audit trails encrypted, timestamped and signed under the appliance's own CA, backups and archives over NFS, IPMI, and the upgrades and support cases of the first year
Oracle RAC 11g on SUSE Linux2016A two-node Oracle RAC database on Hyper-V virtual machines: SUSE Linux Enterprise Server 11 prepared for Oracle, shared iSCSI disks through udev rules and ASMLib, Grid Infrastructure and Oracle Database 11.2.0.4, a Knot DNS server for the cluster names, Symantec Backup Exec for the nodes and the database, and the two problems that held the installation up
Linux Storage2013 (and 2010)A Fibre Channel SAN for Linux hosts: an HP 3PAR array behind two Cisco MDS 9124e blade switches, VSANs for datacenter and DMZ, FC aliases, single-initiator zoning and port security, the HBA and LUN inventory of a Linux host through sysfs and systool, SCSI bus rescans, and older notes on the IBM/LSI RDAC multipath driver in front of two DS5300 arrays

How to read one

Start at the Solution's own page. It lists the articles in the order the system was built, and every configuration file with the article that explains it. Each configuration file is shown as it ran, and followed by a section that checks it against the current release of the software. Where the two differ, the file stays as it was and the section says what to do today.