> tail -f /var/log/production
yourgeek.it Infrastructure, security, and the things that break between the two.
In-depth writing on production infrastructure: Proxmox in production, Terraform on DigitalOcean, Linux hardening, open-source monitoring, running lean on small servers, and migrations off managed cloud. Written by people who ran physical servers before the cloud had a name.
// posts
- #networking#security#infrastructure#troubleshooting
Logs Full of Cloudflare IPs: Finding the Real Client
Your app sees the proxy, not the client. How trusted proxies, forwarded headers and origin isolation decide whether the IP in your logs is real.
read → - #security#infrastructure#networking
Your new server is already being attacked
A fresh server with no firewall: first SSH knock in 85 seconds, Postgres found in 18 minutes. What the logs showed, and how to close it from minute zero.
read → - #security#incident#infrastructure
A Fake sshd on a Production Node: Why SSH Needs Keys
A cryptominer, a swapped sshd binary and a server that had been online for seven years. What I learned about SSH passwords, keys and the fleet check.
read → - #security#human-factor#infrastructure
Security+ and CEH Courses, Without the Exams
I paid for two security courses in 2020 and never sat the exams. What they changed in how I build servers, run audits and read a CV.
read → - #incident#troubleshooting#infrastructure#human-factor
He Added a Code Snippet 20 Minutes Before a Demo
A webmaster added a code snippet to WordPress right before a demo and the site went down. A few minutes to fix, and a weekend it could have cost.
read → - #infrastructure#resilience#troubleshooting
A full stack on 1 GB of RAM
Ingress, SSO, database, mail server and API on 1 GB of RAM: what each one takes, the OOM nobody noticed, and why a small limit beats a big plan.
read → - #incident#human-factor#security#troubleshooting
Don't panic: the order matters more than the speed
Two incidents, one caused by an attacker and one by me: what panic pushes you to do, what it destroys, and the order of steps that beats it.
read → - #security#human-factor#incident#resilience
AI agent guardrails aren't a sandbox
Rule files and prompts are requests an AI agent can ignore. What actually limits the damage: scoped credentials, segregated networks, backups it can't reach.
read → - #incident#human-factor#troubleshooting
Fixing PCs teaches you to fix everything else
A burst water filter, a forgotten web server and a weekend lost to Teflon on brass: what IT troubleshooting teaches you, and where it stops working.
read → - #security#human-factor#messaging#phone
The Voice Was Fake: A €95M CEO Fraud at an Italian Bank
A fake WhatsApp from the group CEO, a cloned lawyer's voice, and €95M out of a bank treasury. No system was breached: the approval process was.
read → - #virtualization#resilience#incident#human-factor
Seven Years of Proxmox in Production, Without HA
Seven years on a 3-node Proxmox cluster with no HA, backups on the same SAN and one sysadmin: what held, what broke, and what I'd change today.
read → - #security#human-factor#email
The Seal Was Real: Revolut, PEC and the Human Factor
A genuine Italian government PEC mailbox, stolen credentials, 680 customers' data handed over. Why a trusted channel is not a trusted request.
read →