Grex Coop Conference

Item 227: Thinking is over rated.

Entered by trig on Thu Mar 6 20:08:10 2008:

Morning Grex0rs,

There is a real issue with the system's uptime. That's to say that at any one
time a user can come by and render the system helpless. To define helpless
i mean:

That the server is in a state that a ssh or telnet [root] connection via the
server's main [grex.org] ip address is not possible. This means a [human] user
has to go to the physical location in order to get the system on line.


There are various ways to cope, the fact a person [in this day and age] has
to phyically drive to the location of the hosted server [most likely a co-lo
shit hole] is plainly out dated and no longer a possble solution to your up
time. I don't promote taking a server down for any reason if that has no way
to get itself up [on line] quickly. Like it or not this is going to be a
training zone for some users. The server will suffer
down time.

I suggest that GREX0rs consider getting a remote ability outside of a standard
local ssh connection  based on the server open ip's. [open meaning ips that
anyone with a bit of looking can get.] A Remote capability is what is needed.
I am sure you have a ip range [some netid, gateway, useable range, broadcast
/whatever] for Grex that can be used to carve out an ip for the Remote
connection. Or maybey you have one static ip. I don't think that's the case.
I may be wrong.

However, if you have a range you surely can vlsm off /30 [1] ip address from
your useable range. I would suggest binding a KVM to that. Lantronic makes
a fairly robust yet cheap option. Let's not be hung up on product line. Lets
agree to: yes, we need this and secondly [with out a lot of arguements] fund
it and use it.

If your base server has attached to it a cd-rom [floppy would be nice] you
could do a one time trip to install the KVM, put a recovery cd into the cd-rom
and be gone. You will thenhave full access to your server at every point from
post, fail point, to server=online.

Will this stop the server from being taken down? hell no! It will allow you
a quick response to getting the server back online with out a HUMAN [oh, user]
driving there.

Thank you.


--  sorry the item before this had bad spacing.
12 responses total.

#1 of 12 by mcnally on Fri Mar 7 01:32:37 2008:

Since there's a copy of this in Agora, which is likely to get seen
by more people, I responded there.

I encourage others interested in responding to do likewise, and this
instance of the item can be frozen or retired, while the other one
can be linked into coop and staff as desired.


#2 of 12 by trig on Fri Mar 7 04:50:17 2008:

 
Thank you for your input, mcnally. 


#3 of 12 by maus on Fri Mar 7 04:59:22 2008:

This is entirely sensible. Another alternative is that if we are looking
at a new physical box (which has been discussed many times before and
then dropped), we should look at one that supports console-redirection,
such as Sun's ALOM, HP's RILO, Dell's DRAC, etc. Not having a way to
remotely manage it is hurting us. 

The only caveat is that the out-of-band management address becomes a
target for attack, and so would need to be fairly robust and secure. 


#4 of 12 by trig on Fri Mar 7 18:25:47 2008:

drac's are good but don't get fooled I have seem them be a bear to install
and often not as robust. However, just the fact the idea is being introduced
aloud to solve a real world issue is great. This should be a no brainer, the
idea is get a remote ability. Lets do a quick bit of research and suggest cost
effective remote console ideas and make this plan an action. 

Thank you for your insight and reply, maus.


#5 of 12 by cross on Sun Mar 9 03:22:37 2008:

There was talk amongst the board of getting a new system to replace the aging
hardware we are currenting running on.  I was going to look into it, but got
activated and am now so busy with USMC stuff that I don't have time for it.

Hmm, we really need to have another board meeting.


#6 of 12 by denise on Wed Mar 12 01:40:18 2008:

So who does the scheduling for board meetings; is there some sort of 
protocal? 


#7 of 12 by glenda on Wed Mar 12 05:10:38 2008:

I was just thinking the same sort of thing.  It is March already and I
don't think that there has been a board meeting since the new board was
elected.


#8 of 12 by cross on Sat Mar 15 22:49:17 2008:

I'm not sure there has been one since I went on active duty back in September.


#9 of 12 by tod on Sun Mar 16 20:09:25 2008:

re #6
Usually the president is supposted to ensure those functions are happening.


#10 of 12 by slynne on Wed Mar 26 23:45:09 2008:

There isnt a president at the moment. I was the president but my board
term expired. 


#11 of 12 by tsty on Wed Jul 2 10:45:42 2008:

so?? did you abdicate by clock?


#12 of 12 by slynne on Wed Jul 2 15:48:40 2008:

I was feeling burned out. I stuck it out until my term expired. I wasnt
doing an especially good job at the end anyways. 


There are no more items selected.

You have several choices: