Difference between revisions of "Syscom Todo"

From CSCWiki
Jump to navigation Jump to search
Line 2: Line 2:
  
 
==General==
 
==General==
* Prepare MEF request for `sodium-benzoate` upgrades/replacement.
+
* Prepare for `sodium-benzoate` upgrades/replacement.
* Prepare MEF request for drives for cobalamin.
+
** new-mirror has like 30 disk shelves so we can just do a live sync on the 2TB disks and then insert the 4TB ones
* Make roundcube use webauth, or else make webauth not tell you not to log into roundcube.
 
 
* Establish remote syslog
 
* Establish remote syslog
 
* Get UPS monitoring working across multiple systems
 
* Get UPS monitoring working across multiple systems
 
* `/users` backups
 
* `/users` backups
 
* Disaster recovery plan
 
* Disaster recovery plan
* Put backup containers onto cobalamin
+
* Put backup containers onto cobalamin (auth2)
 
* Get an IP/KVM for the machine room which doesn't suck?
 
* Get an IP/KVM for the machine room which doesn't suck?
 
* Update the wiki.
 
* Update the wiki.
* Get stuff for natural-flavours & install (e45lee)
 
 
* Sort through keyboards in the office
 
* Sort through keyboards in the office
* Fix the webcam counter (jj2baile)
+
* Clean up wiki vandalism
* mounting USB sticks - special permissions required, can they be relaxed?
+
* Fix debian.csclub, aka our personal Debian repo which serves the CEO package
* clean up wiki vandalism
+
** Fix ceo versioning, which seems to be different on every machine it's installed on...
* make uploading videos less painful
 
* fix debian.csclub
 
 
* Fix audio auth: audio is both a system group and an LDAP group and this has bad consequences for audio authorization
 
* Fix audio auth: audio is both a system group and an LDAP group and this has bad consequences for audio authorization
 +
* Centralized repo for various configs: NFS, PAM auth with kerb, /etc/hosts/, LDAP and Kerb5, routing/interfaces files
 +
** LDAP login is currently broken on glomag, it is password with root only
 +
** Private subnet routing is broken on every machine ''except'' corn-syrup (see 'ethcrazy')
 +
* Update hosts list (10.15.134.WTF?)
  
 
==When in the Machine Room==
 
==When in the Machine Room==
* Rotate CPUs in `hfcs` to see if it's the CPU or the socket that's causing NMI issues.
 
 
* Set up binaerpilot.
 
* Set up binaerpilot.
 
* Make sure that the IPMI/console connections are correct, up-to-date, and working.
 
* Make sure that the IPMI/console connections are correct, up-to-date, and working.
* Add "DO NO TURN ON" label to phlogiston
 
 
* Fix psilodump's and aspartame's IPs and routing
 
* Fix psilodump's and aspartame's IPs and routing
 
** psilodump should not be routable outside aspartame. This is currently accomplished by fuckery. This *should* be fixed to use the net.ipv4.conf.all.arp_filter sysctl.
 
** psilodump should not be routable outside aspartame. This is currently accomplished by fuckery. This *should* be fixed to use the net.ipv4.conf.all.arp_filter sysctl.
 
* Look into expanding /scratch and using RAID using spare disks in the office.
 
* Look into expanding /scratch and using RAID using spare disks in the office.
* Decommission denardo
 
  
 
==Science Machine Room==
 
==Science Machine Room==
* Setup Cobalamin (space has already been set aside for us)
+
* Set up remote syslog2

Revision as of 12:44, 15 July 2015

These are things that syscom should do eventually:

General

  • Prepare for `sodium-benzoate` upgrades/replacement.
    • new-mirror has like 30 disk shelves so we can just do a live sync on the 2TB disks and then insert the 4TB ones
  • Establish remote syslog
  • Get UPS monitoring working across multiple systems
  • `/users` backups
  • Disaster recovery plan
  • Put backup containers onto cobalamin (auth2)
  • Get an IP/KVM for the machine room which doesn't suck?
  • Update the wiki.
  • Sort through keyboards in the office
  • Clean up wiki vandalism
  • Fix debian.csclub, aka our personal Debian repo which serves the CEO package
    • Fix ceo versioning, which seems to be different on every machine it's installed on...
  • Fix audio auth: audio is both a system group and an LDAP group and this has bad consequences for audio authorization
  • Centralized repo for various configs: NFS, PAM auth with kerb, /etc/hosts/, LDAP and Kerb5, routing/interfaces files
    • LDAP login is currently broken on glomag, it is password with root only
    • Private subnet routing is broken on every machine except corn-syrup (see 'ethcrazy')
  • Update hosts list (10.15.134.WTF?)

When in the Machine Room

  • Set up binaerpilot.
  • Make sure that the IPMI/console connections are correct, up-to-date, and working.
  • Fix psilodump's and aspartame's IPs and routing
    • psilodump should not be routable outside aspartame. This is currently accomplished by fuckery. This *should* be fixed to use the net.ipv4.conf.all.arp_filter sysctl.
  • Look into expanding /scratch and using RAID using spare disks in the office.

Science Machine Room

  • Set up remote syslog2