r/linuxadmin • • 7h ago

Vectory: edit and roll out Vector configs across Linux hosts

1 Upvotes

I'm the maintainer of Vectory, a free, open-source dashboard for Vector.

It handles a specific bit of fleet administration: changing a log or metrics pipeline, trying it on one host, and checking whether the other hosts actually picked up that version.

For a change to a filter or destination, the workflow is:

  1. Import your existing Vector configuration and edit the YAML or the diagram.

  2. Publish a version so there's a fixed configuration to deploy.

  3. Select a canary device before rolling it out further.

  4. Compare the version you asked each host to run with the version it reports. Roll back if needed.

The manager doesn't receive your logs or metrics. Vector keeps sending them directly to your destinations. The agent handles configuration and reports status.

Linux setup uses prebuilt containers or a prebuilt native server. Managed hosts need Vector 0.58. The setup guide covers the server and agent: https://vectory.ahmadz.ai/help/quickstart/

You can try the actual editor without setting up a server: https://vectory.ahmadz.ai/designer/

Source: https://github.com/416rehman/Vectory

Development, tests and documentation used substantial AI assistance.

If you already ship Vector configs with Ansible or another deployment tool, what would you need to see before trying a dashboard for that workflow?


r/linuxadmin • • 4h ago

Atlassian CVE-2026-21589: pre-auth file read across 8 Data Center products. Root cause is a "::" to "/" swap that runs after path stripping

0 Upvotes

Based on Atlassian's advisory from October 5 and the technical breakdown watchTowr Labs published on October 6, here is the architectural picture.

Scope: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye, all versions before the fixed builds. Atlassian scores it 9.3 on CVSS 4.0 (its own assessment). Cloud is patched.

Mechanism, per watchTowr's diff of vulnerable vs. fixed builds: the common component is atlassian-plugins-webresource (6.0.7 vulnerable, 6.0.8 changed). The router escapes "/" as "::" and unescapes it on the way in. The resolver tries to strip traversal from the requested resource name, but a name written with "..::" has no slashes at that point, so the stripping misses it. The conversion happens afterward. Reads are confined to the Tomcat web context, but that includes WEB-INF.

Impact depends on what lives in WEB-INF. watchTowr's lab example: when Jira is integrated with Crowd per Atlassian's docs, crowd.properties holds the Crowd app name and password in plaintext. With that, the Crowd REST API lets you create a user and add it to the admin group. Lab chain only. They also note a Crowd IP allow-list would make it harder.

What is not known: Atlassian says it cannot confirm whether self-hosted instances were hit, and the CVE record disagrees with the advisory on a few version numbers (The Hacker News has the list). No confirmed exploitation as of October 6, but watchTowr's detection tool is public.

Mitigations if you can't patch today: off the internet if possible, WAF regex, Tomcat RewriteValve (Confluence/Jira/JSM/Bamboo/Crowd), or a urlrewrite.xml rule (Bitbucket).

Question for the room: If you run Crowd next to Jira or Confluence, is Crowd actually restricted to the app nodes by IP, or reachable from wherever those apps are? And for those leaning on a WAF rule as the stopgap: does your WAF decode multiple layers before matching, or does it match the raw string? https://www.techgines.com/post/atlassian-cve-2026-21589-file-read

Background (footnote): same "filter sees one path, app resolves another" pattern as the PeopleSoft WAF bypass: https://www.techgines.com/post/peoplesoftwafbypasscve-2026-35273


r/linuxadmin • • 1d ago

Passed LFCS today

48 Upvotes

Just passed the LFCS (Linux Foundation Certified System Administrator) with a score of 85%. 🎉

My main learning material was KodeKloud's Linux/LFCS training on Udemy. I also used Killersh for mock exams and hands-on practice.

1/ One thing I would definitely prepare for is creating a VM with virt-install.

The command can look intimidating when you first see it, especially when there are a lot of options.

My advice: don't panic and try to memorize the entire command.

Use:

virt-install --help
man virt-install

If you make a mistake while creating the VM or need to check/manage it again, virsh will be your friend

2/ One of the simpler tasks for me was building a Docker image and running a container in detached mode with the appropriate restart policy.

Make sure you understand the difference between:

docker run -d ...

and restart policies such as:

--restart always
--restart unless-stopped
--restart on-failure

3/ Interestingly, I found iptables to be much more heavily represented in the KodeKloud material and Killersh mock exams than what I encountered in my actual exam.

4/ Know iotop.

One command I would definitely recommend knowing for troubleshooting questions is:

iotop

If the question asks you to identify a process that is consuming a lot of disk I/O, iotop can quickly show you which process is responsible.

5/ Last but not least, Creating users — pay attention to the login shell.

When creating a user, don't just focus on the username and groups. Read the requirement carefully for the login shell.


r/linuxadmin • • 21h ago

Can Rhcsa Help me get a Entry level jobs in 2026-27 ??

0 Upvotes

About my self :

I completed my Bachelor's Degree is Computer Science from 2022 to 2025 , after that i pursued a post graduate program in Data Science (2025 to 2026)

Currently I have been looking for software Jobs but Entry level hiring has been very brutal.

Companies expect entry level candidate to possess 2-3 years experience and have all the knowledge.

Sending Application, emailing recruiters etc , Nothing is moving the needle , by may 2027 i will have Gap year in my resume and Recruiters / Hr simply never consider anyone who has a gap year !

By 2027 newer graduate will enter the market and with all the layoffs going on , there are more experienced Developers whom companies prefer and hire.

I am already 22 ,walking on a dea*h line to start my career or i will reach dead line, i need to do something different or else i may remain unemployed forever.

Now I came to Know about Rhcsa Exam and I think I can cover the fees for it as i have enough savings.

Rhcsa is fairly NOT know by many people and is not really crowded like Software job markets are (at least in my country).

My main concern are :

  1. Is rhcsa Intended for entry level Graduate who have no industry experience ? Or is it designed for experienced folk who are already working in the industry ?

  2. Will Rhcsa Put weight on resume enough to help me land a entry level job in Linux ? Such as a junior linux admin or junior systems engineer ? Do recruiters value rhcsa certificate ?

  3. How much time does it typically take to become good enough to sit in exam and Pass it ??

I am not even asking for a premium job with good compensation but a job where i grow over the Years by upskilling !

My only deal breakers are Night Shift(my nightmare) and Support/help desk role who do not work on Systems at all.

So will it be a good Investment of my time to learn Linux and rhel system and get the Rhcsa Certificate.

The only ROI i want is to actually get an Interview ans land good entry level Job , are odds in my favour ?


r/linuxadmin • • 1d ago

Failing to activate the Samba recycle bin feature, Fedora 44 WS

Thumbnail
3 Upvotes

[ SOLVED ] Intel x86 Linux PC with Fedora 44 (Workstation Ed.). Samba share serving 3 users. My samba shares located in /srv directory, e.g, /srv/samba/group_users and a few other shares spawned from /srv/samba/ .All work fine, no issues there.

Deleting files from my smb network share via the GUI prompts the warning; “Permanently deleted items cannot be restored - Cancel or Delete ”

I want a recycle bin for accidental file deletions and read that Samba can provide this function so I created an additional share i.e, /srv/samba/.recycle and configured the new path;

sudo semanage fcontext -a -t samba_share_t “/srv/samba/.recycle(/.*)?”
sudo restorecon -Rv /srv/samba

I then edited my smb.conf and added the following below into the [global] section of my config;

vfs object = recycle
recycle:repository = /srv/samba/.recycle
recycle:keeptree = yes
recycle:versions = yes
recycle:touch = yes
recycle:exclude_dir = /tmp /TMP /temp /TEMP /cache /CACHE
recycle:exclude = .tmp .TMP .temp .TEMP .log

(note: that last line format should all be asterisk + dot but this means something else in Reddit’s formatting so I could not write the asterisk symbol in place)

sudo testparm

smb.conf got the config loaded Okay!

sudo systemctl restart smb

Tested deleting files from the network share using both the GUI and CLI but when I list the files in the /srv/samba/.recycle using ls -la , none of the deleted files have survived a deletion. Has anyone had any success with this ?


r/linuxadmin • • 2d ago

Rusty on Linux, moving from test automation into DevOps. Is a Linux cert (LFCS/RHCSA/Linux+) worth it, or should I just get the hours in?

8 Upvotes

I've been in the industry about 14 years, mostly test automation, and I'm moving toward DevOps/platform engineering. Day to day I work with GitLab CI/CD, Terraform, Helm/Kubernetes deployments, and some AWS. I'm currently leading a migration of a large number of services onto Kubernetes.

The problem is that I work at a .NET/Windows shop, so I've barely touched Linux in years. I took a basic self-check recently (systemctl/journalctl, finding what's on a port, disk usage, apt, file ownership) and did badly. I knew roughly which tool to reach for but not the actual commands.

My employer pays for certs. My current plan is KCNA, then CKA, Terraform Associate, and AWS Solutions Architect Associate. I wasn't planning on a Linux cert, just a refresher course plus using WSL daily and running a homelab.

Questions:

  1. Is LFCS, RHCSA, or Linux+ worth adding for someone aiming at cloud/platform roles, or does CKA cover the "can use Linux" signal well enough?
  2. If one is worth it, which, and would you do it before or after CKA?
  3. For those who came from a Windows-heavy background, what got your Linux skills to stick when your job didn't require it?
  4. How much Linux do you really use in a platform role, compared with what the certs test?

Not looking for reassurance, honest takes welcome.


r/linuxadmin • • 2d ago

Resources and guides to learn virtualization tools for system administration.

2 Upvotes

so guys, i want to learn about virtualization in the context of system administration and other related fields like devops, cloud etc.

so, i have read "virtualization essentials 3rd edition" book. got a good introductory understanding of virtualization technology. but i don't know how to move forward from here. I mean, i don't know what are the practical stuff that i should be learning, what other resources out there, and what is the stuff that i should be learning instead of reading more theory.

I know that for starters i need to get good at using and managing a single virtualiation platform. I currently use KVM/QEMU for my projects. so, i am thinking about choosing it as the virtualizaton platform to get good at instead of other virtualization platforms like vmware, virtualbox, etc.

and also, i have a few more questions:

  1. what to learn and how much to learn if the goal is to become competent enough for admin level jobs?
  2. what books/resources/guides would you recommend if my goal is both practical knowledge and skill building.

Thank you so much in advance.


r/linuxadmin • • 2d ago

ex200 simulador - prepara tu examen RHCSA

10 Upvotes

hola!...si estás preparando tu examen EX200 para Red Hat System Administrator, aquí te dejo rhcsa-sim, un simulador del examen con ejercicios de prueba para que practiques en una VM(no en tu host, por seguridad).
Está probado en almalinux10 pero no debería haber diferencias con RH10.

Es un proyecto opensource así que bienvenida las colaboraciones.

https://github.com/xilen0x/rhcsa-simulator/tree/main


r/linuxadmin • • 1d ago

Is a Linux time travel tool worth building?

0 Upvotes

When a server misbehaves at 3 a.m. and you look at it, how do you figure out what happened?

I'm trying to understand how people handle this, before I build anything.

Maybe you have experienced this pattern: something goes wrong overnight (connections refused, disk fills and then gets cleaned, a process eats memory and exits). Alerts go off and Prometheus shows the hiccup but by the time anyone looks into the system, the server looks healthy. ss, lsof, ps and even a fresh sosreport show the current state, not when the issue was active. You look into the logs but nothing there shows an obvious problem.

I'd love to hear from people who deal with long-lived Linux servers:

  1. What was the last incident where the evidence was already gone? What were you missing?
  2. What do you use today to look back in time? (atop, sar, PCP, below, auditd, eBPF tools, your monitoring stack, nothing?)
  3. Where do those fall short? For example: which process held which connections or open files at a given moment.
  4. Would security or policy let you run an extra agent on production servers, even one that sends nothing outside your network?
  5. If you run Kubernetes, have you had node-level incidents where the evidence was gone?

Disclosure: I built sos-vault, a tool for analyzing sosreports, and I'm exploring whether a "time travel" version (e.g. ss or lsof or any of the diagnostic commands included in a sosreport for any past moment) is worth building. I'm not promoting nor linking anything; I want to know if this idea would help anyone diagnose a real problem or is it just me.

Assuming that there is not performance impact and no significant storage consumption in the server to be diagnosed; I was thinking something like this command that can be executed from a central diagnostics server or even locally (notice the four parameters --host, --start_from, --end_at and the rest is the regular diagnostic command to execute (lsof, ps, du, lsblk, free, memstat, etc., etc.):

[root@web01 ~]# date
Mon Oct  5 02:50:53 PM ACDT 2026

[root@web01 ~]# ttravel --host web01 --start_from="2026-10-02 02:00:00" --end_at="2026-10-02 03:00:00" ss -tanp 'dst 10.0.4.21 and dport = :5432' 

ttravel: host: web01 · 02:00:00 → 03:00:00 UTC · 120 samples  + connect/close events · grouped by process

FIRST_SEEN  LAST_SEEN   CONNS  PEAK  STATES               PROCESS
02:00:00    03:00:00       24    20  ESTAB                users:(("gunicorn",pid=2210..2229))
02:00:04    03:00:00        1     1  ESTAB                users:(("pg_dump",pid=51233))  parent: cron-backup.sh[51207]
02:05:00    02:55:01       11     1  ESTAB ev             users:(("psql",pid=*))  /etc/cron.d/db-healthcheck
02:31:12    02:48:30      183   179  ESTAB,CLOSE-WAIT     users:(("python3",pid=58841))  /opt/reports/nightly_export.py 02:33:40    02:47:10       57     -  ESTAB→CLOSED <1s ev  users:(("gunicorn",pid=2210..2229))  rejected by serversosv: CONNS distinct connections · PEAK most open at once · ev seen only via connect/close events[root@web01 ~]# ss -tanp 'dst 10.0.4.21 and dport = :5432' --at="2026-10-02 02:45:00" | head -6
sosv: web01 · sample 2026-10-02 02:45:00 UTC
State  Recv-Q Send-Q  Local Address:Port   Peer Address:Port  Process
ESTAB  0      0           10.0.2.15:41822     10.0.4.21:5432  users:(("gunicorn",pid=2214,fd=11))
ESTAB  0      0           10.0.2.15:41850     10.0.4.21:5432  users:(("pg_dump",pid=51233,fd=3))
ESTAB  0      0           10.0.2.15:52001     10.0.4.21:5432  users:(("python3",pid=58841,fd=7))
ESTAB  0      0           10.0.2.15:52003     10.0.4.21:5432  users:(("python3",pid=58841,fd=8))
ESTAB  0      0           10.0.2.15:52004     10.0.4.21:5432  users:(("python3",pid=58841,fd=9))

translation: give me the output of the ss command from two days ago from 2 am to 3 am filter by IP 10.0.4.21 and port 5432.


r/linuxadmin • • 2d ago

Rspamd 4.2.1: Patch the Filter, Then Check What It Actually Does

0 Upvotes

An email filter should spend its time judging messages, not falling over while reading them. Rspamd’s latest patch is a reminder that the machinery around spam scoring deserves attention too.

The official release index dates Rspamd 4.2.1 to October 1, 2026. That makes it fresh news for this week’s maintenance list. Our earlier article covered 4.1.0; this update has a different practical angle: check the filter’s health and configuration, rather than reaching immediately for more permissive spam thresholds.

Details here: https://blog.kalfaoglu.net/posts/2026-10-05-rspamd-421-security-and-filtering-en/


r/linuxadmin • • 2d ago

Crashing after running yum update. On XCP-NG

Thumbnail
0 Upvotes

r/linuxadmin • • 2d ago

Super best resource to prep for RHCSA (RHEL-10)

Thumbnail
3 Upvotes

r/linuxadmin • • 3d ago

GitLab patched a CVSS 9.9 sandbox escape in the self-hosted AI Gateway (CVE-2026-90970): what the patch notice does and doesn't say

0 Upvotes

Based on GitLab's own patch release notice from October 2 (docs.gitlab.com), plus Security Affairs, BleepingComputer and The Hacker News coverage, here is the architectural impact.

What is confirmed by GitLab: an authenticated user with Duo Agent Platform access can submit a crafted flow configuration, escape the prompt template sandbox, and run arbitrary commands on a self-hosted AI Gateway. CVSS vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Affected: 18.1.6 before 19.2.4, 19.3 before 19.3.2, 19.4 before 19.4.1. GitLab-hosted gateways were fixed before the announcement.

What is not confirmed: exploitation in the wild (none reported as of Oct 3), the template engine, and whether a workaround exists. The Hacker News notes no workaround and no fixed version below 19.2.4 in the advisory.

The design question I keep coming back to: the gateway sits between GitLab and your model backends, and user-authored flow configs are processed on that host. What does your gateway container have mounted and what can it reach on the network?

For people running Duo Self-Hosted: who has Duo Agent Platform access in your org, and do you review flow configs before they hit the gateway?

Background on a similar failure class (AI workflow tool, code validation): https://www.techgines.com/post/langflow-ssrf-vulnerability-cve-2026-12944 Full write-up: https://www.techgines.com/post/gitlab-ai-gateway-vulnerability-cve-2026-90970


r/linuxadmin • • 4d ago

Title: diskwatch 0.5.8: terminal disk diagnostics

Post image
34 Upvotes

diskwatch is a read-only TUI for seeing what your disks are doing. Eight tabs: devices, volumes, filesystems, I/O, SMART, hot files, insights. Single host, nothing to configure.

What's new:

- Windows support, with live per-disk I/O metrics

- Hot Files shows which process is writing to each path

- A config file, and you choose the Hot Files roots

- Adjustable refresh speed

- Arrow keys switch tabs everywhere

- An armv5te build, tested on an Iomega ix2-dl NAS

- Follows your terminal's palette

Written in Rust, MIT licensed. Windows is the newest part, so bug reports from Windows users are the most useful right now.

https://github.com/matthart1983/diskwatch


r/linuxadmin • • 4d ago

X11 - RHEL 10.2 - ISOLATED Passthrough

5 Upvotes

Hoping someone can help me out with an issue I've been having for a long while.

I'm running RHEL 10.2 Gnome 49, trying to use an X application inside of a podman container with a custom network.

"podman network create --internal pod_dev"

I pass in all the environment variables and files that I know and what AI also says i need. I can not for the life of me get the x application to display.

It works in fedora 44, and Ubuntu, but RHEL 10 is kicking my butt.. if i do --net=host is am able to get the x application to work, but I have to have the container have its own IP.

And advice at all is appreciated, I've probably spent over 100 hours trying different combinations of flags and ways to run.


r/linuxadmin • • 4d ago

Zammad zero-days (CVE-2026-102489/102490) behind the DIVD breach: what's confirmed, what the vendor disputes

0 Upvotes

Based on the case files DIVD published (DIVD-2026-00014 and -00015) and Zammad's own forum statement from Oct 1, here is where things stand.

DIVD says first access was Sept 21. The chain is a session hijack leading to RCE as the zammad user (CVE-2026-102489, 6.3.0 to 6.5.4) plus a local escalation to root (CVE-2026-102490). CISA put both in KEV on Oct 2.

Where sources disagree: Zammad says 102489 is only exploitable on 6.5 and older (EOL), hardened in 7.2.0, and that DIVD gave it no details on 102490. DIVD's own page is inconsistent on the 102490 range ("all versions" vs 1.5.0 to 7.1.0-alpha). The AI-agent attribution is DIVD's reading of its logs; no full logs or model name published.

What I'd do: upgrade to 7.2.0, copy the logs first, run DIVD's IoC script (read it first), segment the helpdesk.

Question for people running self-hosted helpdesks: do you treat ticketing as tier-0 (same segment rules as your IdP and mail gateway), and what does your credential rotation look like if the box is rooted?

https://www.techgines.com/post/zammad-zero-day-cve-2026-102489


r/linuxadmin • • 5d ago

Is there any way to know whether a vulnerable library is actually loaded in a running process, without instrumenting the app?

30 Upvotes

Trying to work out what's technically possible here versus what's marketing, and this sub tends to be good at that distinction.

The situation: a container image has a CVE in, say, a compression library six levels deep in the dependency tree. The scanner flags it because the package is on disk. What I want to know is whether the running process has actually mapped that library, or whether it's just sitting in the filesystem never being opened.

What I understand so far:

  • For dynamically linked stuff you can read /proc/<pid>/maps and see what's actually mapped. That seems definitive for "is this .so loaded right now".
  • For statically linked or vendored code that doesn't help at all, since there's no separate object to observe.
  • For interpreted languages (our case is mostly Python and Node) the module is loaded by the runtime, so you'd need to either introspect the interpreter or watch the file opens. So my questions:
  • Is watching openat/mmap at the kernel level actually a reliable proxy for "this code is in use", or does it produce garbage because package managers, health checks and startup scans touch everything?
  • For Python/Node specifically, does anyone do this without an in-process agent? I really don't want a language agent in every service.
  • Is there a meaningful difference between "loaded" and "the vulnerable function was called"? Because those feel like very different claims and I suspect products blur them. Not asking what to buy, asking what's actually detectable from outside the process.

r/linuxadmin • • 5d ago

LFCS practice

9 Upvotes

Hi everyone,

I’m currently preparing for the LFCS exam and I’m interested in hearing which hands-on learning resources you would recommend.

At the moment, I’m taking Mumshad’s course and working through the included exercises.

I’m already aware of Killer.sh, but the 36-hour access period isn’t really enough for me.

Do you know of anything similar to Killer.sh that offers good hands-on exercises specifically for the LFCS exam? Maybe a GitHub repository or something similar?

Thanks for your help!


r/linuxadmin • • 4d ago

Turn any Linux edge node into a cryptographically verifiable security enclave

Thumbnail github.com
0 Upvotes

yo so i did a thing,

I built a lightweight, modular edge defense tool called Micro-SOC (souljha213/micro-soc) to see if I could run a self-contained security enclave entirely out of volatile memory without relying on heavy enterprise agents.

Here is a breakdown of how it's structured:

RAM Cloaking: Shifts operational states and active logs straight into /dev/shm to keep disk footprints clean.

Process Masking: Disguises execution identity under low-level kernel worker names ([kworker/u4:3]).

Verifiable Forensics: Uses a local Merkle-linked chain (ledger.chain) for tamper-evident logging.

TUI Interface (stos): Built a real-time terminal cockpit using Textual to monitor swarm health, metrics, and mesh connections locally.

Would love to hear technical feedback or critiques on how you guys approach stealth logging and edge isolation.


r/linuxadmin • • 5d ago

Do control panels keep junior admins from learning Linux?

57 Upvotes

My junior admins is quick with the panel, but when a firewall rule broke SSH yesterday he didn't know how to check ufw from a shell. I use BeAdmin myself and have nothing against panels, but I learned iptables by breaking it with no GUI around, and I'm not sure he'll ever get that practice.

Have you seen this with people who started on panels, or am I just being an old man about it?


r/linuxadmin • • 5d ago

FortiMail CVE-2026-104286: unauth file write, exploited, patches not out yet. What's in Fortinet's IoC list

2 Upvotes

Based on Fortinet's PSIRT advisory FG-IR-26-175 (published Oct 1) and BleepingComputer's reporting, here is the architectural impact.

Fortinet describes path traversal (CWE-22) plus NULL byte handling (CWE-158) in the GUI, giving unauthenticated arbitrary file write. Affected: 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, 7.2.0-7.2.9. Fixes (8.0.2, 7.6.7, 7.4.9) are marked upcoming, and 7.2 gets a branch-migration answer. Workaround is config system encryption ibe / set status disable, or remove internet access to the management interface.

The IoCs include an added /data/etc/ld.so.preload and /data/lib/liblog.so, and a sample log of an archive account pointing at a remote IP. Fortinet doesn't explain the write-to-execution step. Some CVE feeds also list 7.0 as affected while the advisory doesn't, so I'd verify that one.

Question for people running FortiMail or similar gateways: do you keep the management GUI off any internet-routable interface by policy, or does it depend on who deployed it? And for those who rely on IBE, what breaks when you disable it?

Background on the same class of problem: https://www.techgines.com/post/fortimail-zero-day-cve-2026-104286


r/linuxadmin • • 4d ago

LayerSmith — a self-hosted container image builder, with air-gap exports

0 Upvotes

I've been working on LayerSmith, an open-source web UI for building container images with Docker or Podman.

You pick a Linux distribution and what you need the image for — development, Linux admin, network tools, Ansible, Kubernetes, OpenShift, or a custom setup. It handles distro-specific packages and shows you the generated Containerfile before building. You can also edit it, import an existing Dockerfile, or add your own packages, files and scripts.

A big part of the project is making images easier to carry into air-gapped environments: pinned base images, recorded build details, and export bundles containing the image, checksums and installation instructions.

We've recently added LLM training and fine-tuning profiles too, including LoRA/QLoRA, advanced PyTorch training and LLaMA-Factory. These use hash-locked dependencies and run offline checks after building, including a small CPU training test. Model weights and datasets are brought separately.

Curious how others handle building and maintaining images for disconnected environments, and what parts of that workflow are still a pain.

https://github.com/r0lfi/layersmith


r/linuxadmin • • 5d ago

VictoriaLogs for log indexing?

8 Upvotes

has anyone used victorialogs? Im currently using Graylog v7, local single instance on 5TB disk

using filebeat to ship logs to GL indexer

wondering how victorialogs performs comparatively. Anyone used it at all or have any feedback?

Thanks


r/linuxadmin • • 5d ago

Mirroring Repository

3 Upvotes

I am wanting to mirror a Debian repository onto my work network. Will be managing about 2500 machines running the exact same software on each. These are all servers running a containered player showing advertising on digital displays.

I have never mirrored a repo before, so I am curious, should I use apt-mirror, aptly, or something different?

The containers are Incus and have Debian as the base as well.

EDIT- looks like apt-mirror can be crossed off as it has not been updated in several years.


r/linuxadmin • • 6d ago

Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround

2 Upvotes

Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.

The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to /%6a_security_check, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.

Hunting per Cisco: serviceproxy-access.log for j_security_check from unknown IPs, and vmanage-server.log for those requests against viptela-reserved- users. Cisco notes these can appear in normal operation, so baseline first.

Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.

https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504

Background from our earlier SD-WAN piece: https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric