Tidbits
Short notes from real work. No product pitch.
ssh-agent as a systemd user service
With gnome-keyring and i3, Ed25519 keys can misbehave. Running ssh-agent as a user service is a reliable fix.
Put this in ~/.config/systemd/user/ssh-agent.service:
[Unit]
Description=OpenSSH private key agent
IgnoreOnIsolate=true
[Service]
Type=forking
Environment=SSH_AUTH_SOCK=%t/ssh-agent.socket
ExecStart=/usr/bin/ssh-agent -a $SSH_AUTH_SOCK
ExecStartPost=/usr/bin/systemctl --user set-environment SSH_AUTH_SOCK=${SSH_AUTH_SOCK}
[Install]
WantedBy=default.target
Enable and start:
systemctl --user enable ssh-agent.service
systemctl --user start ssh-agent.service
In .bashrc or .profile:
eval $(systemctl --user show-environment | grep SSH_AUTH_SOCK)
export SSH_AUTH_SOCK
Then use ssh-add as usual.
MariaDB Galera Cluster SST
When a node will not join, check the joiner and donor logs. A common failure is rsync SST timing out on large datasets. Switch SST to mariabackup.
Install mariadb-backup. On the joiner (Debian-style paths):
# 20-galera.conf
[mysqld]
wsrep_sst_method="mariabackup"
wsrep_sst_donor="node1.mariadb.cluster"
# 50-server.conf
[mariadb]
wsrep_sst_auth = mariabackup:CHANGE_ME
On the donor, create the user and grant the needed privileges, or set wsrep_sst_auth globally. Restart the joiner and confirm SST with mariabackup.
Logstash grok patterns for sssd
sssd logs are awkward to ship natively. One approach: rsyslog already on the host, then Logstash with a pre-match, an sssd block, and custom grok patterns — no Filebeat on every machine.
Example project: opentokix/logstash-sssd.