Tidbits

Short notes from real work. No product pitch.

ssh-agent as a systemd user service

With gnome-keyring and i3, Ed25519 keys can misbehave. Running ssh-agent as a user service is a reliable fix.

Put this in ~/.config/systemd/user/ssh-agent.service:

[Unit]
Description=OpenSSH private key agent
IgnoreOnIsolate=true

[Service]
Type=forking
Environment=SSH_AUTH_SOCK=%t/ssh-agent.socket
ExecStart=/usr/bin/ssh-agent -a $SSH_AUTH_SOCK
ExecStartPost=/usr/bin/systemctl --user set-environment SSH_AUTH_SOCK=${SSH_AUTH_SOCK}

[Install]
WantedBy=default.target

Enable and start:

systemctl --user enable ssh-agent.service
systemctl --user start ssh-agent.service

In .bashrc or .profile:

eval $(systemctl --user show-environment | grep SSH_AUTH_SOCK)
export SSH_AUTH_SOCK

Then use ssh-add as usual.

MariaDB Galera Cluster SST

When a node will not join, check the joiner and donor logs. A common failure is rsync SST timing out on large datasets. Switch SST to mariabackup.

Install mariadb-backup. On the joiner (Debian-style paths):

# 20-galera.conf
[mysqld]
wsrep_sst_method="mariabackup"
wsrep_sst_donor="node1.mariadb.cluster"

# 50-server.conf
[mariadb]
wsrep_sst_auth = mariabackup:CHANGE_ME

On the donor, create the user and grant the needed privileges, or set wsrep_sst_auth globally. Restart the joiner and confirm SST with mariabackup.

Logstash grok patterns for sssd

sssd logs are awkward to ship natively. One approach: rsyslog already on the host, then Logstash with a pre-match, an sssd block, and custom grok patterns — no Filebeat on every machine.

Example project: opentokix/logstash-sssd.