Syscom Todo: Difference between revisions

From CSCWiki
Jump to navigation Jump to search
No edit summary
Line 2: Line 2:


==General==
==General==
* Prepare MEF request for `sodium-benzoate` upgrades/replacement.
* Prepare for `sodium-benzoate` upgrades/replacement.
** new-mirror has like 30 disk shelves so we can just do a live sync on the 2TB disks and then insert the 4TB ones
* Prepare MEF request for drives for cobalamin.
* Make roundcube use webauth, or else make webauth not tell you not to log into roundcube.
* Establish remote syslog
* Establish remote syslog
* Get UPS monitoring working across multiple systems
* Get UPS monitoring working across multiple systems
* `/users` backups
* `/users` backups
* Disaster recovery plan
* Disaster recovery plan
* Put backup containers onto cobalamin
* Put backup containers onto cobalamin (auth2)
* Get an IP/KVM for the machine room which doesn't suck?
* Get an IP/KVM for the machine room which doesn't suck?
* Update the wiki.
* Update the wiki.
* Get stuff for natural-flavours & install (e45lee)
* Sort through keyboards in the office
* Sort through keyboards in the office
* Clean up wiki vandalism
* Fix the webcam counter (jj2baile)
* Fix debian.csclub, aka our personal Debian repo which serves the CEO package
* mounting USB sticks - special permissions required, can they be relaxed?
** Fix ceo versioning, which seems to be different on every machine it's installed on...
* clean up wiki vandalism
* make uploading videos less painful
* fix debian.csclub
* Fix audio auth: audio is both a system group and an LDAP group and this has bad consequences for audio authorization
* Fix audio auth: audio is both a system group and an LDAP group and this has bad consequences for audio authorization
* Centralized repo for various configs: NFS, PAM auth with kerb, /etc/hosts/, LDAP and Kerb5, routing/interfaces files
** LDAP login is currently broken on glomag, it is password with root only
** Private subnet routing is broken on every machine ''except'' corn-syrup (see 'ethcrazy')
* Update hosts list (10.15.134.WTF?)


==When in the Machine Room==
==When in the Machine Room==
* Rotate CPUs in `hfcs` to see if it's the CPU or the socket that's causing NMI issues.
* Set up binaerpilot.
* Set up binaerpilot.
* Make sure that the IPMI/console connections are correct, up-to-date, and working.
* Make sure that the IPMI/console connections are correct, up-to-date, and working.
* Add "DO NO TURN ON" label to phlogiston
* Fix psilodump's and aspartame's IPs and routing
* Fix psilodump's and aspartame's IPs and routing
** psilodump should not be routable outside aspartame. This is currently accomplished by fuckery. This *should* be fixed to use the net.ipv4.conf.all.arp_filter sysctl.
** psilodump should not be routable outside aspartame. This is currently accomplished by fuckery. This *should* be fixed to use the net.ipv4.conf.all.arp_filter sysctl.
* Look into expanding /scratch and using RAID using spare disks in the office.
* Look into expanding /scratch and using RAID using spare disks in the office.
* Decommission denardo


==Science Machine Room==
==Science Machine Room==
* Set up remote syslog2
* Setup Cobalamin (space has already been set aside for us)

Revision as of 12:44, 15 July 2015

These are things that syscom should do eventually:

General

  • Prepare for `sodium-benzoate` upgrades/replacement.
    • new-mirror has like 30 disk shelves so we can just do a live sync on the 2TB disks and then insert the 4TB ones
  • Establish remote syslog
  • Get UPS monitoring working across multiple systems
  • `/users` backups
  • Disaster recovery plan
  • Put backup containers onto cobalamin (auth2)
  • Get an IP/KVM for the machine room which doesn't suck?
  • Update the wiki.
  • Sort through keyboards in the office
  • Clean up wiki vandalism
  • Fix debian.csclub, aka our personal Debian repo which serves the CEO package
    • Fix ceo versioning, which seems to be different on every machine it's installed on...
  • Fix audio auth: audio is both a system group and an LDAP group and this has bad consequences for audio authorization
  • Centralized repo for various configs: NFS, PAM auth with kerb, /etc/hosts/, LDAP and Kerb5, routing/interfaces files
    • LDAP login is currently broken on glomag, it is password with root only
    • Private subnet routing is broken on every machine except corn-syrup (see 'ethcrazy')
  • Update hosts list (10.15.134.WTF?)

When in the Machine Room

  • Set up binaerpilot.
  • Make sure that the IPMI/console connections are correct, up-to-date, and working.
  • Fix psilodump's and aspartame's IPs and routing
    • psilodump should not be routable outside aspartame. This is currently accomplished by fuckery. This *should* be fixed to use the net.ipv4.conf.all.arp_filter sysctl.
  • Look into expanding /scratch and using RAID using spare disks in the office.

Science Machine Room

  • Set up remote syslog2