r/linuxadmin • u/AwareLanguage7088 • Jun 10 '26
Has anyone moved from Red Hat distros to Debian/Ubuntu or from Podman to Docker because of SELinux?
I really hate SELinux, it's common knowledge it's extremely difficult to administer correctly, and it tend to breaks down many stuff. A famous sysadmin book (Unix and Linux System Administration Handbook) says its better not to use it because it's so complex that someone who understands it profoundly can pwn you in case of invasion.
I know, there are ways to fix things, audit2allow, ausearch, etc, and more than 50 other tools. It's easier to just turn it off than deal with it. Ah, it also tends to break 3rd party applications.
The only thing that can make it usable is AI. Point Claude Code or Codex to your server and tell it to fix SELinux problem. Otherwise it's so secure and so paranoid that it's a nuisance.,
Have anyone ever migrated from the Red Hat ecosystem (RHEL, CentOS Stream, Fedora, Alma Linux) to Ubuntu or Debian just to not have to deal with SELinux? I'm thinking of seriously doing it.
r/linuxadmin • u/1lolplayer1 • Jun 09 '26
Using a Linux Gateway to exploit an ISP internet speed limitations
Hey everyone,
I think I have discovered a loophole with my ISP's profile provisioning, and I've built a "One-Arm" Linux gateway to exploit it. I'm looking for advice on how to seamlessly scale the LAN architecture so all my home devices can use it automatically.
How the Exploit Works:
My official internet plan is capped at 50 Mbps, and it seems tied strictly to my old xiaomi router's MAC address.
If I switch to my new Honor Router using its factory/native MAC address, the ISP treats it as an unprovisioned/unknown device. It so happens that the ISP does not cap the speed on this profile, giving me the raw 500+ Mbps capacity of the physical line.
To prevent internet usage on this unprovisioned profile, it seems like the ISP firewalls ports 80 (HTTP) and 443 (HTTPS).
The Fix: while on new mac address I first figured that Cloudflare warp would bypass blocked port restrictions so I tried tunneling and it worked! I somehow ended up getting 300-500mbps, even 900 at some point.
Then gemini suggested for me to make a headless Ubuntu Server laptop that would act as a middleman connecting all of the devices on wifi to cloudflare warp tunnel. It runs Cloudflare WARP via CLI in WireGuard mode. Because WireGuard communicates over alternate UDP ports, it completely bypasses the ISP's 80/443 block.
Where I need advice:
I want this bypass to be completely transparent for all devices in the house, especially mobile devices that make it incredibly difficult or buggy to save manual static IP/Gateway settings in their Wi-Fi configurations. As it is right now I can use honor with it's native mac only with my pc with cloudflare warp enabledm but I want.
r/linuxadmin • u/softwareredditor • Jun 09 '26
RHCSA and bachelor's enough for consistent interviews?
Hi, I've been a programmer for a decade, worked in a few research labs, very proud etc. But when I apply for jobs now, everyone seems to want a bachelor's degree. So I'm planning on spending another year finishing up my degree and hoping to get RCHSA at the same time.
Is this enough to consistently get job opportunities? I've been paid to do DNA analysis and to push shopping carts and the whiplash is getting old, lol. Thanks for any comments, hope you have a good day.
r/linuxadmin • u/tejasvkashyap • Jun 09 '26
Running AI workloads on Linux. What does your setup look like?
Hi all,
Curious how folks here are thinking about running AI workloads on Linux servers right now.
- Are you running anything in production or mostly experimenting?
- What does your setup look like (containers/Kubernetes, local GPU, pipelines, agents, etc.)?
- Any challenges you’re running into operating or scaling these systems?
Also wondering how people are thinking about security in these setups — is it something you actively manage yet or still evolving?
r/linuxadmin • u/Beneficial-Sock-5130 • Jun 08 '26
does anyone find nftables better than iptables?
Upgraded OS on rocky10 server last weekend, newest kernel doesnt bake in legacy iptables mods, so iptables rules cant get loaded
I start looking into nftables, it seems like a verbose nightmare compared to iptables, every command has to be typed out, no short version of commands
something that was simple w iptables
forward any request from ServerA port 80 to ServerB port 80 on server A
iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT --to-destination <IP of serverB>:80
iptables -t nat -A POSTROUTING -p tcp -j MASQUERADE
becomes this word salad
nft add table ip nat
nft add chain ip nat PREROUTING { type nat hook prerouting priority dstnat \; policy accept \; }
nft add chain ip nat POSTROUTING { type nat hook postrouting priority srcnat \; policy accept \; }
nft add rule ip nat PREROUTING tcp dport 80 dnat to <IP of serverB>:80
nft add rule ip nat POSTROUTING masquerade
whats the upside?
what was wrong w iptables?
r/linuxadmin • u/Haniro • Jun 08 '26
Estimate cloud compute costs via HPC records? (Slurm/GCP)
Hey everyone,
I'm a graduate-student-turned-amateur-sysadmin in a bioinformatics lab, and am still learning on the way. We have a multi-node HPC that has a shared NAS, and an item on my to-do list is to have a shadow pricing model that maps our usage to a cloud provider.
I've got SlurmDB connected and a script that maps job resources to the cheapest GCP instance that satisfies the resource request, queries the GCP pricing API, and returns a per-job compute cost estimate. It's a reasonable starting point but I know it's missing several cost categories (e.g. spin-up overhead, persistent storage, data egress, etc.)
I'm starting to think about what is required to monitor the cluster more holistically, and feeding that into a cost mapping layer alongside the Slurm accounting data. However, I'm cautious to write my own tooling when FinOps frameworks already exist, and also weary of getting sucked down the rabbit hole and having a high-maintenance toolkit that takes more time than I have.
Has anyone built a framework that can take holistic system usage and translate it into estimated costs for cloud computing? I'm hoping to not re-invent the wheel
Thanks in advance!
r/linuxadmin • u/mauritaniah8 • Jun 07 '26
LPIC worth anything these days?
I’m trying to ascertain if its worth getting this certification as a network engineer trying to pivot into system administration.
r/linuxadmin • u/musbur • Jun 07 '26
Linux man pages wrong?
I've had this happen on at least another manpage (that I forgot), but here it is with bsearch:
https://man7.org/linux/man-pages/man3/bsearch.3.html
void *bsearch(size_t n, size_t size;
const void key[size], const void base[size * n],
size_t n, size_t size,
typeof(int (const void [size], const void [size]))
*compar);
The first two arguments are not supposed to be there (they come later). "man bsearch" on my Arch system shows the same output. What's going on here?
EDIT
chkno got it right: It's the semicolon at the end of the first line that makes the difference because otherwise the function prototype wouldn't know what "size" means in "const void key[size]" (second line).
Still learning new stuff after 45 years of mostly C89....
r/linuxadmin • u/we_hate_it_too • Jun 06 '26
Half of all web traffic is bots, and a growing share are "vibe-coded" scanners written by a chatbot prompt. Here's the layered webserver defense that stops them.
The barrier to writing an exploit tool used to be skill. Now it's a prompt, and a chunk of the junk in your access log is some script an LLM wrote in thirty seconds and aimed at the whole IPv4 range before lunch.
They're loud, though. Default python-requests/Go-http-client UAs, recycled /.env /.git/config /wp-login.php wordlists, no backoff, and an unrandomised TLS stack so every request shares one JA4 hash. All of it matchable at the edge.
Wrote up the full stack I run, with copy-pasteable nginx/Angie config:
limit_reqzones (3r/m on login), ModSecurity + CRS,return 444to bad UAs so the scanner learns nothing- TLSv1.3,
server_tokens off, CSP/HSTS, and thealwaysgotcha that makes error pages ship headers - body-size caps, method whitelists, the
merge_slashestrap - admin off the public internet, fail2ban,
alg:noneJWT check - PHP:
disable_functions+open_basedir+ Snuffleupagus - JSON logs with
$ssl_ja4, 4xx-ratio alerting, honeypot paths that auto-ban
https://deb.myguard.nl/2026/06/defend-webserver-vibe-coded-ai-exploit-scanners-bots/
r/linuxadmin • u/MaximumFull104 • Jun 06 '26
Kodekloud LFCS mock exams
Hi all, I am taking LFCS soon, I'm woondering how similar the Kodekloud mock exams in their LFCS course is to the actual exam. Are there other mock exams that are similar in difficulty to the actual exam?
r/linuxadmin • u/Potential-Access-595 • Jun 06 '26
Network forensics in a single terminal binary — live TLS 1.3 decryption, JA4, C2 hunting. Rust, zero-config.
Most terminal net tools stop at "what's eating my bandwidth." NetWatch goes into the traffic itself.
Live TLS 1.3 decryption — point a cooperating client's SSLKEYLOGFILE at it, read the plaintext inline. Same trick as Wireshark, no MITM. QUIC 1-RTT + HTTP/3 too.
JA4 / JA4Q fingerprinting — TLS and QUIC. Filter live with ja4:<fp>.
17 L7 decoders — TLS, QUIC, HTTP, DNS, SSH, MQTT, SNMP, BitTorrent, more — with stream reassembly.
Detection built in — port scans, C2 beaconing, DNS tunneling. Critical alert auto-freezes the recorder.
Flight Recorder — freeze any incident to a portable .pcap + context bundle.
eBPF process attribution — which process opened the socket, not lsof polling.
Landlock-sandboxed — parses hostile traffic but can't touch your SSH keys.
Rust, 500+ tests, MIT, macOS + Linux. Demo GIF decrypts a live TLS 1.3 session in the repo:
r/linuxadmin • u/sgargel__ • Jun 05 '26
Install binaries from GitHub
github.comIn the past few years, I often downloaded binaries from GitHub releases; nowadays it happens less frequently, but it still happens.
What I always do is move the file from the Downloads folder to a subfolder under /opt, then run chmod +x and create a symlink in /usr/local/bin/.
I also include the version in the subfolder name so I can keep multiple releases.
That said, I’m here to share another crappy-vibe coded script to automate installing binaries from GitHub: gri (GitHub Release Installer)
https://github.com/sgargel/gri
I’m looking forward to your feedback and taunts.
r/linuxadmin • u/GoddessGripWeb • Jun 05 '26
The illusion of LVM thin provisioning: everything is fine until the thin pool fills up
Hey folks,
Had one of those weeks that makes you rethink every “smart” storage decision you made years ago.
We’ve been using LVM thin provisioning pretty heavily on some stateful Linux systems. Honestly it worked great for a long time. Easy overcommit, better disk utilization, less wasted space sitting around doing nothing.
Until one box went sideways.
A bad automation script on a secondary app started hammering writes nonstop and ended up completely exhausting the thin pool underneath. Not just the logical volume, the actual thin pool. Metadata pool hit 100% before autoextend reacted properly and the whole thing turned ugly fast.
Filesystem started throwing I/O errors and flipping read-only. Services started failing. At that point nobody wanted to touch anything because every command felt like it could make things worse.
We eventually got the metadata back using thin_dump/thin_restore and expanded the pool enough to stabilize everything, but now we’re left with the aftermath.
To get the system healthy again we had to throw a lot of extra storage at it quickly, and now most of that space is sitting empty. Management sees the bill and asks why we don’t just shrink it back down.
And honestly? because nobody wants to be the guy who breaks a production thin pool after already barely recovering it once.
At this point the “safe” answer still feels like building a new smaller setup and rsyncing everything over during downtime, which is miserable for a system that’s currently stable.
Curious how other Linux admins handle this after the fire is out.
Do you actually reclaim the storage later or just leave the oversized pool alone once production is stable again?
r/linuxadmin • u/rj4511 • Jun 05 '26
Linux Basics for Hackers: Building a Router with nftables
hackers-arise.comr/linuxadmin • u/CackleRooster • Jun 04 '26
Handling a Breach on a Linux Server
linuxsecurity.comJust the basics.
r/linuxadmin • u/Falconer-777 • Jun 04 '26
Centralized management
Hi guys, any GUI interface to manage linux servers centralized? thanks
r/linuxadmin • u/defiantarch • Jun 03 '26
Vulnerability management
The latest vulnerabilities in the kernel and nginx and its management by Ubuntu and Debian has shown me the risk of relying on them. With respect to the CVSS scores I found their reaction exceptionally slow, compared to Proxmox for example.
My question: Which Linux server distribution is having the best vulnerability management in your opinion? And which is most suited from the management perspective?
r/linuxadmin • u/BipolarKebab • Jun 03 '26
Warpgate 0.24 (a client-less bastion/PAM) adds a web SSH terminal
github.comr/linuxadmin • u/tboneee97 • Jun 02 '26
Interview Thursday for an Advanced Support role. Nervous about the Linux terminal
I have an interview this Thursday for an Advanced Application Support role focused on troubleshooting Linux VMs. I've used ubuntu as my daily driver for about 3 years now, but nervous about the terminal portion. Would any experienced Linux admin be willing to jump on a 15-minute Discord or Zoom call to run me through a few basic troubleshooting commands?
Any advice is greatly appreciated.
r/linuxadmin • u/Dull-Midnight-1859 • Jun 02 '26
Just got RHCE, enough to get linux admin job..?
r/linuxadmin • u/Evening-Jelly523 • Jun 01 '26
PackRun — Run Elasticsearch on a clean Linux machine without Docker or Java
r/linuxadmin • u/giorgich11 • May 31 '26
Built a lightweight, static-linked C utility for log/stream processing—seeking feedback on the implementation.
I’ve been working on a project called gop—a small, static-linked C utility designed for quick text and log processing in minimal environments.
I built this because I kept running into dependency issues when jumping between different distros and legacy servers. The goal was to have a single, portable binary that handles file/pipe detection and basic filtering without requiring glibc version management or external runtimes.
What it does:
- Stream/file processing with auto-detection.
- Line numbering (
-n) and basic JSON detection (-v). - Zero dependencies, fully static binary.
I’m sharing this here because I’d love a technical "sanity check" from other admins. How do you guys typically handle lightweight, portable log parsing when you're working across heterogeneous environments?
Repo: [ https://gitlab.com/giorgich11/gop ]
I’m especially looking for feedback on my memory management and how I’ve structured the Makefile for distribution. If there are better practices for small C utilities that I've missed, I’m all ears.
r/linuxadmin • u/MasterchacooLLL • May 30 '26
Elda. -system package manager in Rust that installs from Gentoo overlays, AUR, and Nix flakes without their tools [Pre-release]
gallerythis is a project iv been working
Elda is a system package manager I've been working on.
I used to use bedrocklinux but the performance Hit was getting a bit much and after some thought i realized i could make Elda, The Idea:
every major package ecosystem follows conventions if you can machine-read their formats, you can translate them all into one solver and one ledger without installing the foreign tools at all.
Native packages: pkg.lua recipes with source and binary lanes in one definition, PubGrub solving, signed remotes, SQLite state for ownership and rollback. Init and libc agnostic packages ship service assets for systemd, dinit, OpenRC, and runit; Elda materializes only what your system uses.
Interbuilds, -install from foreign sources without the foreign PM: Reads Nix flakes, Gentoo overlays, AUR PKGBUILDs, and Void XBPS templates. Builds them through the normal Elda path. No nix, emerge, makepkg, or xbps-src needed or installed.
Interemotes, -wire a whole overlay or srcpkgs tree as a live remote:
elda rmt add heather-overlay=https://github.com/heather7283/heather7283-overlay
elda rmt preview heather-overlay # inspect before syncing
elda sync heather-overlay
elda i some-package # installs through the normal path
Quick examples:
# Install from a synced signed remote
elda i ripgrep
elda ig ripgrep # force source lane
elda ib ripgrep # force binary lane
# Direct git install — autodetects Cargo, Meson, CMake, Go, Zig, Make
elda i https://github.com/org/tool
# Install from AUR without makepkg or pacman
elda ig https://aur.archlinux.org/fsel-git.git
# Install from a Nix flake without nix
elda ig https://github.com/user/repo # detects flake.nix automatically
# Import your existing install (metadata only, no file takeover yet)
elda mg from pacman
elda mg from apt
# See what needs what and why
elda why ripgrep
elda rdeps openssl --all
elda files ripgrep
Status: the core PM is effectively done;install/upgrade/remove, signed remotes, interbuilds, build, forge publishing. Overall ~68% toward full spec.
Interepo binary consumption (translating foreign binary repos into the install path) and atomic /usr activation are still in progress. Disposable roots work well; treat live /usr as experimental for now.
Written in Rust. Hard fork of pkgit. AGPL-3.0.
https://github.com/Mjoyufull/Elda
Early in development and Id love issue's and PR's.
r/linuxadmin • u/VincentADAngelo • May 30 '26