Mobil Mewah

Salah satu sumber Inspirasi.

Mobil Sport terbaik

Anda pasti bisa memilikinya.

Bermain dengan pesawat

Salah satu ide yang gila, Balapan di udara.

Bermain di angkasa

Apakah ini salah satu Goals dalam hidup anda? anda pasti bisa mencapainya

Thursday, 7 April 2022

Mount a Network share from Linux

 Most server are using some sort of NAS or remote storage. The simple path is using SMB or cifs on linux machine to access the network storage.

To enable , you need make sure install cifs tools.

# yum install cifs.tools

Then you will able to mount any NAS storage using SMB protocol.

Some caveat are the version difference implementation on cifs. As recently there are security concern on previous version of SMB especially version 1, now we have until SMB version 3.0 

Usually we want the mount will be available after server reboot, so we need to add it on /etc/fstab

Here are sample for centos 6.6

//192.168.1.215/moview /movies cifs username=movies,password=movies,netdev 0 0

And for centos 7.9 release

//192.168.1.215/moview /movies cifs username=movies,password=movies,vers=2.0,_netdev 0 0

If you need more control on the protocol, can look some options from the documentation 

$ man mount.cifs



Friday, 6 August 2021

Receive money in US

Recently i need to able to receive USD money transfer within USA. And why is that? So i can save more on the transfer fee and speed up the transaction. And anyone can do it with the technology nowdays with Web Technology and Mobile.

So i use Transfer Wise for my needs. With them i can open an account and can have a US bank account. So with that, anyone in the USA can transfer me money just like they transfer locally. 

I also can receive ACH transfer with the account, which is usable if you have a brokerage account in the USA. Everyone will have brokerage account in USA for stock investment right, if you follow my path here :).

The step quite easy with few steps and you will get an US account.

1. Register with them

2. Deposit minimum 20US$ via any channel like debit card, credit card, wire transfer, ACH.

3. Post your ID Verification and Selfie photo

4. Wait from their confirmation and you set to go.

Can wait to get Withdrawal from my brokerage account monthly from the Profit generated. yay..

You can get Free fee when you register with this link Wise Transfer Register


Wednesday, 26 August 2020

IIS on Windows Server Core

 Windows famous because of the GUI to make everything easier. But when you have  windows server core under your management without any documentation, this will make you wonder, why install windows server Core. Is more secure than windows server ?

We not talk about security now. What we are going to talk here is installation of SSL certificate which will be use by the Webservice.

Quite easy with some command, but the diligence to look for what command should you run is the aha moment.

Here i document my journey and the process to do it.

1. You will need other windows server GUI to be able manage the windows core server with GUI.

2. Install the certificate and the root using windows MMC, put on the trusted root certificate.

3. You have the .pfk certificate format to be installed on IIS. But you cannot do it via remote IIS console. its by design.

4. The way to install the pfk is copy your certificate to the core server, and run this :
    C:/> certutil -importpfk <Path to certificate file>
    If prompt for password, enter it and it will success.

5. The last part, change the binding using remote IIS console. Your new SSL certificate will be show up on the list of certificate.

Some notes, the IIS management service not run on the core server , you can start it by :

C:/> net start WMSVC

In my experience on this, really Microsoft windows try to be like Linux part, but it wont be the same. 

In Linux every config file is accessible by a text editor.

That's all for my experience. Hope help someone. 

And i did it !!!

Wednesday, 15 July 2020

Compile Erlang using Kerl with crypto module

When working with erlang, we can use old version to run our erlang app which are not yet upgraded.
This multiple erlang version run like python env if you come from python.

So in erlang we using Kerl which can switch to multiple erlang version at runtime. So here we go.

We are using Debian 10.x buster. Some prerequisite before able to finish are install the dev tools.

# apt-get install build-essential autoconf libncurses5-dev openssl libssl-dev fop xsltproc unixodbc-dev libz-dev

Then get the openssl version supported on your erlang version. Here i use 17.5.x release which require openssl-1.0.xx to compile properly with crypto module.



1 $ git clone git@github.com:openssl/openssl.git --branch OpenSSL_1_0_2-stable
2 $ cd openssl
3 $ mkdir __result
4 $ ./config --prefix="${HOME}/openssl" shared zlib -fPIC
5 $ make depend
6 $ make
7 $ make install INSTALL_PREFIX="/home/me/openssl/__result"


Then we can start the kerl compilation.

Get the kerl 

1 $ curl -0 https://raw.githubusercontent.com/kerl/kerl/master/kerl
2 $ chmod a+x kerl

Make the ssl available for kerl compiler

1 $ export KERL_CONFIGURE_OPTIONS="--with-ssl=/home/me/openssl-OpenSSL_1_0_2-stable/__result/home/me/openssl-OpenSSL_1_0_2-stable/openssl/"

2 $ mkdir .kerl
3 $ kerl build 17.5.3 17.5.3

This should be show which indicate SSL included.







 



Then continue with installation:

$ kerl install 17.5.3 ~/.kerl/17.5.3

To test run erlang.

$ . ~/.kerl/17.5.3/activate
$ erl
> crypto:start().

Should no error if install successfully.

And make that fault tolerant app with 0 downtime.


Thursday, 25 June 2020

panic cannot login to linux

Panic ! Thats what occurs when a critical systems you manage cannot login , but the service was running properly.

Recently i do some changes on the /etc/security/limits.conf and it make all lockout. No SSH can be done, but all the service was running properly.

To the rescue, we need to login to the systems and revert back changes, and to do that we need to go into single mode.

We do on Centos 7.x systems which is the grub boot loader is different than the old version.

So how to do it step by step, and no panic. 

  • Reboot your machine and immidiately go to rescue mode.
  • Chose one boot options and press "e" to change the entry
  • Look for below entry :
    linux16 /boot/vmlinuz-3.10.0-123.el7.x86_64 root=UUID=act2884249823928928392 ro  xxxxxx
  • Change the ro to below 
    rw init=/sysroot/bin/sh
  • Then continue the boot, press ctrl+x to do that. No worries, after finish you can reboot and the grub boot loader will be still the old one.
  • once boot to single mode you need to mount the filesystem. do
    # chroot /sysroot/
  • After this step you can revert back any settings you made to restore it to working state.
  • On our side, its /etc/security/limits.conf
  • After finish we can reboot the machine to production mode
    # reboot -f
That was no panic attack anymore if you know what you are doing.

Always make sure you have backup of the OS.
Or better way use Container these days. 


Thursday, 11 June 2020

Compiling GoLang application

When using Golang basic setup need to be done to able compile all application based on golang in github.
To do that install golang then set in your home directory.

let say /home/geek/go/

inside the folder create a src folder, and put all the go app you want to compile.

Then remember to set env variable GOPATH.

in ~/.bashrc set :

GOPATH = /home/geek/go

Example you have a killer-app download from github with go source code.
Put it inside /home/geek/go/src/killer-app/

Then do this :

$ cd /home/geek/go/src/killer-app/
$ go get ./...
$ go build

Then there will be a file created from the compile called killer-app 

Then profit.


Sunday, 7 June 2020

Stafull and Stateless widget in Flutter

In flutter we have 2 type of widget, Statefull and stateless. Difference are the stateless widget will never changes after it rendered. Meantime statefull widget can be change in the future after the widget rendered.

There are difference on how to use it. Because flutter using inheritance of the widget, we will always override some of the function / properties of the widget. There will be a lot of inheritance method in flutter.

Lets go for the stateless widget first. On the stateless widget, the one we override are the build function.
Below is the example code.

import 'package:flutter/material.dart';

void main() => runApp(MyApp());

class MyApp extends StatelessWidget {
  @override
  Widget build(BuildContext context) {
    return MaterialApp (
      title: 'Measures Converter' ,
      home: Scaffold(
        appBar: AppBar(
          title: Text('Measures Converter'),
        ),
        body: Center(
          child: Text('Measures Converter'),
        ),
      ),
    );
  }
}


And for statefull widget, we override the createState method.

import 'package:flutter/material.dart';

void
main() => runApp(MyApp());

class
MyAppState extends State<MyApp> {
@override
Widget build(BuildContext context) {
return MaterialApp (
title: 'Measures Converter' ,
home: Scaffold(
appBar: AppBar(
title: Text('Measures Converter'),
),
body: Center(
child: Text('Measures Converter'),
),
),
);
}
}

class MyApp extends StatefulWidget {
@override
MyAppState createState() => MyAppState();


}


Saturday, 6 June 2020

Basic Flutter Scaffolding

Flutter makes the development enjoyable and fast.

Here are some of the template for create a basic layout.

We create an app with App bar and a body.
import 'package:flutter/cupertino.dart';
import
"package:flutter/material.dart";

void
main() => runApp(MyApp());

class
MyApp extends StatelessWidget {
@override
Widget build(BuildContext context){
return MaterialApp(
title: 'My Work Timer',
theme: ThemeData(
primarySwatch: Colors.blueGrey,
),
home: Scaffold(
appBar: AppBar(
title: Text('My Killer App'),
),
body: Center(
child:
Text('My Killer APp'),
),
),
);
}
}


Mobile Development with Flutter

Nowdays, mobile development not need to be tricky and hard.

Old timers for mobile dev will use java fro android and object C for ios development, which means 2 code for 2 platform Android and IOS.

Other path was hybrid using web development technique which just load a Web view in the application, so developer can use Web development tools and style to develop mobile app.

Now, we have Google who develop Flutter on top of Dart which will make the Java slogan "code once run on any mobile platform (Android / IOS) but now with happiness.

All in flutter just a widget and tooling all free and available and it also beautifull on the app generated because the template also provided like Material Design or Cupertino for IOS.

My interest on Flutter become increasing and after watching some time on the progress of Flutter. Now as on my writing, Flutter version 2.7.0 is been used on my development tools.

You will have my Flutter blogging on their feature and also this will be my flutter docs on my joourney to flutter.

Hope you enjoy it.

Thursday, 28 May 2020

Securing your Web services using Nginx


If we have an API service and want to publish to public, better use a reverse proxy like nginx to handle all the dirty traffic trying to taken down your services.

With Nginx you will make your API server live prosper and not minding the dirty request which should not coming on your server if not using Nginx in front of it.

So lets do the Nginx configuration for securing your backend API server.



    add_header Cache-Control public;
    add_header X-frame-Options "DENY";
    add_header X-Xss-Protection "1; mode=block" always;
    add_header Content-Security-Policy-Report-Only "script-src https://skyway.shineapi.net";
    add_header X-Content-Type-Options "nosniff" always;
    add_header Strict-Transport-Security 'max-age=31536000;includeSubDomains;preload;' always;
    add_header Referrer-Policy no-referrer-when-downgrade;
 
   if ($http_referer = "") {  return 403; }


With above configuration, any request incoming your API will be handled by Nginx and protected by the header config which is web security standards for securing any web app in the wild.

For the explanation i will put on another blog post for details.


Thursday, 7 May 2020

Monitoring tools in the new age with Grafana

We know for old school monitoring tools are using Nagios, Cacti, CollectD. Well, that's what i use on my job to monitoring infrastructure.

No fancy graphic and display, no filter , only plain time range value with the monitored data.

Now, we see Grafana. I try grafana and its looks a like elastic kibana. Well, apparantly Grafana was a fork of Kibana 3.0 . Grafana is Free to use, but also have enterprise version which have support.

With grafana we can connect to multiple datastore. What i try was using prometheus, as it can be generate data also the TSDB it used. no need more DB for the storage.

Also we can also put our application metrics to prometheus to scrap and display it.

Now version 6.x , grafana have many plugin and chart template to be use.

It can also used for your monitoring dashboard to show alerts.

Alerts can be set using prometheus alert manager. all is there to be exploited.

Lets continue the journey with Grafana + prometheus + prometheus alert manager

Wednesday, 6 May 2020

Create a Services in linux box

In linux box, everything runs at startup is a service.

Service located on  /etc/systemd/system/servicename.service

Step to create a service are :
1. Create a service user account
2. Change ownership of config file to the service account
3. Create a service file to load when startup

Create service user account the secure way :


  • $ sudo useradd --no-create-home --shell /bin/false blackbox_exporter

Here are template for create a service and use the created user above.

[Unit]
Description=Blackbox Exporter
Wants=network-online.target
After=network-online.target

[Service]
User=blackbox_exporter
Group=blackbox_exporter
Type=simple
ExecStart=/usr/local/bin/blackbox_exporter --config.file /etc/blackbox_exporter/blackbox.yml

[Install]
WantedBy=multi-user.target
This will be inside the .service file.

Then we need to reload the daemon.

#systemctl daemon-reload

And service can run using below command :

#systemctl start service_name

To enable it do :

#systemctl enable service_name

Hope this helps

Thursday, 27 February 2020

Exchange server error 452-4-3-1-insufficient-system-resources


When Microsoft Exchange have problem cannot receive any email from other party, there will be a lot of things can be happened. But make sure you pin point the exact issue by looking at the server event logs for exchange. Also if possible to get the NDR report from the sending party so we can know exactly what exchange spit out when error happening. Usually a mature mail systems will have specific error so administrator can resolve the problem.


On this case, we get the error message from the sender which are 452-4-3-1-insufficient-system-resources. What we got from this was :
  1. Server is reachable
  2. SMTP service is up
  3. When complete the sending, it fail with insufficient system resources

On Exchange documentation, this error related to storage, so the situation was when exchange going to store the receive message to disk, its spit error because insufficient resources.

Microsoft Exchange Transport is rejecting message submissions because the available disk space has dropped below the configured threshold.The following resources are under pressure:
Queue database logging path (“C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\data\Queue\”) = 96% [High] [Normal=92% Medium=94% High=96%]

Physical memory load = 90% [limit is 94% to start dehydrating messages.]
The following components are disabled due to back pressure:
Inbound mail submission from Hub Transport servers
Inbound mail submission from the Internet
Mail submission from Pickup directory
Mail submission from Replay directory
Mail submission from Mailbox server
Content aggregation
The following resources are in normal state:
Queue database path (“C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\data\Queue\mail.que”) = 95% [Normal] [Normal=95% Medium=97% High=99%]
Version buckets = 0 [Normal] [Normal=80 Medium=120 High=200]
Private bytes = 14% [Normal] [Normal=71% Medium=73% High=75%]
Batch Point = 0 [Normal] [Normal=2000 Medium=4000 High=8000]
Submission Queue = 0 [Normal] [Normal=1000 Medium=2000 High=4000]
With Microsoft Exchange, it have a monitoring component which monitor available resources - Back Pressure, which is also tracking free space on a disk, where the Exchange Transport service queue are located.
Checking on the disk resources on servers, we have plenty disk 1.4TB with free 100GB of disk. This was strange.

Some behavior to note when the threshold limit exceeded, Exchange can  :

- Medium (90%) threshold - Stop receiving mail over SMTP from external senders (MAPI client e-mails are yet processed)
- High (99%) threshold - The mailflow stops to be processed completely

Dig down more on the event log, we found that the drive of Microsoft Exchange transport was because the available disk space has dropped below the configured threshold. And we read the documentation in Microsoft, it states that Microsoft Exchange transport service will need retain a min 10% free disk space where the transport Role folder resides.

So in this case the size of 1.4TB will need minimum 10% to be free, which are 140GB, and in this case not enough as it left only 100GB. This is by design to prevent disk full and Microsoft Exchange crash.

The solution to this was easy, just add more disk with expanding the drive, or just move transport role folder to another disk drive if you cannot expand it. After the disk size threshold surpassed, restart Microsoft exchange transport service and all will be running again.

If you want to move the transport queue to another disk , you can edit the config in exchange install located in 
$env:exchangeinstallpath\bin\EdgeTransport.exe.config  wiith the following changes

<add key=”QueueDatabasePath” value=”C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\data\Queue” />

<add key=”QueueDatabaseLoggingPath” value=”C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\data\Queue” />
When change the trasnport queue path, leave the content and just restart transport service as Exchange will recreate the folder automatically.

Note : Old directory can safely be removed

In my case, we just extend the disk without restart the servers.

Sunday, 12 January 2020

Squid delay pools setup

Squid can do bandwith management and separate speed access based on group.

Below example of setup :


########################################### define networks
acl all src 0.0.0.0/0.0.0.0
acl unlimited src "/etc/squid/unlimited.txt"
acl our_1mbps src "/etc/squid/our_1mbps.txt"
acl our_512kbps src "/etc/squid/our_512kbps.txt"
acl our_256kbps src "/etc/squid/our_256kbps.txt"


######### give access

http_access allow unlimited
http_access allow our_1mbps
http_access allow our_512kbps
http_access allow our_256kbps
http_access deny all


##### define delay pools

delay_pools 4
delay_class 1 2
delay_access 1 allow unlimited
delay_access 1 deny all
delay_parameters 1 -1/-1 -1/-1


delay_class 2 2
delay_access 2 allow our_1mbps
delay_access 2 deny all
delay_parameters 2 -1/-1 131072/131072

delay_class 3 2
delay_access 3 allow our_512kbps
delay_access 3 deny all
delay_parameters 3 -1/-1 65536/65536

delay_class 4 2
delay_access 4 allow our_256kbps
delay_access 4 deny all
delay_parameters 4 -1/-1 32785/32786

With above setup, clients will limited to the above bandwith.

Sunday, 7 July 2019

IT Asset Management Software

Do you have ever experience trouble in managing your Assets in your organizatoin, especially within the scope of IT Assets like PC, laptop, accessories, etc which related to day to day operation ?

Manual will be using spreadsheets application available. More advance are using a specialized software which manage your assets and logs where about the assets and status.

Come the rescue, Snipeit asset management. Its a software based asset management with full feature to manage your assets and also come as a free open source software. Of course with free meanings, you can do it all by yourself to make it works, besides your skill on translate the documentation to working application.

Here you need to know that Snipeit application is a :
1. PHP based application
2. Need a database to function properly, eg. Mariadb or Postgresql.
3. Multiuser applicatoin
4. Support LDAP integration for corporate environment.
5. Can run both on Linux / Windows server as a web services

With this information, you should know what basic prerequisite needed.

For my journey, i come to Snipeit because organization i work for need an asset management software to manage all operation related activity and keep track of the asset owned by organization. This will be a second step after doing manual labour works using spreadsheets.

What i recommend to setup are using High Availability setup for uninterupted service, as these are web service, its easy to do the High Availablility setup, especially the web service part.

What can we do are using this design :

User ---------   HA Proxy               --->   Snipeit App 01   ----->    |    Snipeit Database
                       Load Balancer        --->  Snipeit APP 02    ----->    |

With this setup, access from user are load balanced between Snipeit AP 01 and 02 to provide high availability and load balancing within the application.

Working Snipeit IT ASSET Management Systems
The software we used are :
1. Centos 7.x
2. HA Proxy
3. Nginx
4. PHP7.2
5. MariaDB 10
6. Memcached


Monday, 23 July 2018

keepalived issue with iptables

When talking about High Availability services, we can use keepalived to do a automatic failover between 2 host.

Keepalived is working like a charm by using a virtual ip. 1 Master elected for normal operation, and others as backup.
When master have issue, backup will take over the services.

Issue arise with configuration, where there is iptables entry to drop any vrrp traffic type. This was issue with the configuration.

To mitigate this, look for the config of keepalived.conf . change entry from :

vrrp_strict 

to become :

vrrp_accept

This entry will make keepalived will not use iptables.

Keepalived version we use was V1.3.5

Monday, 2 July 2018

Environment variable with ChicagoBoss

On Chicagoboss I need to have some configuration variable set in the main configuration. Just like my experience with Django framework on settings.py

In Chicagoboss, we can do it also and add our on config variable in the configuration file, which are boss.config.

These below are the part of the config we can custom :

%% APPLICATION CONFIGURATIONS

%% domains - A list of domains to serve the application on
%% static_prefix - The URL prefix of static assets
%% doc_prefix - The URL prefix for developer documentation
{ myapp, [
    {path, "../myapp"},
    {base_url, "/"},

    {dummy, true}
]}
So we can add the variable for our application with below settings :


%% APPLICATION CONFIGURATIONS

%% domains - A list of domains to serve the application on
%% static_prefix - The URL prefix of static assets
%% doc_prefix - The URL prefix for developer documentation
{ myapp, [
    {path, "../myapp"},
    {base_url, "/"},

    {dummy, true}.
    {mail_from, "justme@mydomain.com"},
    {api_key, "324298nvUYSCN298snk92442ps"}

]}
Now how we can use it on the application. We can use :

application:get_env(myapp, api_key).

If we want to print out on console :

io:fwrite("~p", [application:get_env(myapp, api_key)]).

And if we want to assign the variable to our local variable in the app we can use :

{ok, apikey} = application:get_env(myapp, api_key).

With this we can add as many as variable we need on the config.


Monday, 18 June 2018

Generate a list from atom and string

On Erlang, there is no string data type, but its a list of strings. So different with other language.
Also some function return an atom, which usually we need to combine it with our string. For example was the need to generate an sql query from an input parameter and our hard coded string.

Let say we generate a year from erlang fun, then from that year, we generate the month and data.
To do this properly are :

{{Year,_,_},_} = calendar:universal_time(),
Y1 = io_lib:format("~p-01-01",[Year]),
Y2 = lists:flatten(Y1),

Y2 result will be  "2018-06-18"


Hope this helps, as i look all around the google for this.

Wednesday, 13 June 2018

Posgresql reporting query

With PostgreSQL when doing with datetime for reporting, it realy help if the DB can aggregate your needed data rather than process it yourself.

I found this interesting and useful as i start needed query for reporting from my dataset.

For example i want to have a list of records which user register per month. With postgresql here is the query :

SELECT date_trunc('month', created_at),
       count(*)
FROM users
GROUP BY 1
ORDER BY 1 DESC;


With date_trunc PostgreqSQL do its magic and return you the needed data without doing a query per month. really not so effective query. To get per week activity :

with months as (
  select month
  from generate_series('2018-01-01'::date, now()::date, '1 month'::interval) month
)

SELECT months.month,
       count(pmactivitylogs.id)
FROM months,
left join pmactivitylogs on date_trunc('month', pmactivitylogs.created_at) = months.month

GROUP BY 1
ORDER BY 1 DESC;


We will get all the monthly count of records for our reporting.

For more details get the docs on postgresql web site.

Sunday, 29 April 2018

Using Centos 5.x repo after EOL

We know Centos 5.x already EOL , and no update given.
But we sometimes still use the version as upgrade will be broke our application usage.

So problem arise when we need to install application package in that version. The repo is moved from main url of the release, and moved to vault.centos.org . To able to install from your yum package manager , we need to update the yum base url.

Here are some command to fix it.

sed -i 's/enabled=1/enabled=0/' /etc/yum/pluginconf.d/fastestmirror.conf
sed -i 's/mirrorlist/#mirrorlist/' /etc/yum.repos.d/*.repo
sed -i 's|#baseurl=http://mirror.centos.org/centos/$releasever|baseurl=http://vault.centos.org/5.11|' /etc/yum.repos.d/*.repo

With above command, yum config updated and you will be able to install package from yum repo and download all the dependencies.

Beware as the app no longer supported and might introduce security issue.



Twitter Delicious Facebook Digg Stumbleupon Favorites More