# Posts

> Practical notes on infrastructure, operations, and everyday tooling.

---

LLMS index: [llms.txt](/en/llms.txt)

---

Section pages:

- [fixing memory leaks in python services: diagnostics and dump collection](/en/posts/python-memory-leaks-diagnostics/)
- [SSH key best practices](/en/posts/post/)
- [kubectl cheatsheet: essential commands for Kubernetes](/en/posts/kubectl-cheatsheet/)
- [Creating User and Role in Kubernetes and Binding Them via RBAC](/en/posts/k8s-user-role-rbac/)
- [Git Tag: Marking Releases and Bookmarks in History](/en/posts/git-tag/)
- [Deploying with a post-receive Git Hook](/en/posts/git-hook-post-receive-dlya-deploya/)
- [ulimit and systemd LimitNOFILE — why ulimit -n inside a unit doesn't stick](/en/posts/ulimit-i-systemd-limitnofile/)
- [coredumpctl: Finding a Binary Crash](/en/posts/coredumpctl-naiti-padenie-binarya/)
- [curl --resolve and SNI: Testing Virtual Hosts Without /etc/hosts](/en/posts/curl-resolve-i-sni/)
- [Docker logs and journald: choosing a logging driver](/en/posts/docker-logs-i-journald/)
- [scp — Secure Copy Over SSH](/en/posts/scp/)
- [Sudoers: NOPASSWD Without Holes](/en/posts/sudoers-nopasswd-bez-dyr/)
- [ThinLinc: Remote Access to Linux Desktops](/en/posts/thinlinc/)
- [Chrony Instead of ntpd](/en/posts/chrony-vmesto-ntpd/)
- [fail2ban: SSH Jail Configuration](/en/posts/fail2ban-jail-dlya-sshd/)
- [journalctl: filters and follow](/en/posts/journalctl-filtry-i-follow/)
- [nftables: Basic Rule Set](/en/posts/nftables-bazovyi-nabor-pravil/)
- [Debian — The Swiss Army Knife of Linux](/en/posts/debian-swiss-army-knife-linux/)
- [pipx: Isolated Python CLI Tools Without the Mess](/en/posts/pipx/)
- [uv — Fast Python Package Manager](/en/posts/uv-python-package-manager/)
- [logrotate for Custom Daemons](/en/posts/logrotate-custom-daemons/)
- [Rsync: Backing Up a Directory Over SSH](/en/posts/rsync-ssh-backup/)
- [Setting Up Your Own SSH Bastion Server](/en/posts/ssh-bastion-server/)
- [tmux on Prod After Screen](/en/posts/tmux-after-screen/)
- [bpftrace: one-liners that replace strace in production](/en/posts/bpftrace-one-liners-replace-strace/)
- [ip: Network Setup and Diagnostics in CLI](/en/posts/ip-command-network-cli/)
- [nslookup and drill: DNS resolution in terminal](/en/posts/nslookup-drill-dns-resolution/)
- [journalctl: Filtering and Formatting systemd Logs](/en/posts/journalctl-filtering-formatting/)
- [OpenSSL: TLS Certificate Verification and Parsing in CLI](/en/posts/openssl-check-tls-certificates/)
- [ProxyJump and bastion hosts via ~/.ssh/config](/en/posts/ssh-proxyjump-bastion-config/)
- [auditd: file access and syscall logging](/en/posts/auditd-file-syscall-logging/)
- [logrotate: automatic log rotation and archiving](/en/posts/logrotate-auto-rotation/)
- [sshd_config: baseline for a test stand](/en/posts/sshd-config-baseline/)
- [systemd-run: Run Services Without Unit Files](/en/posts/systemd-run-transient-services/)
- [curl: HTTP Debugging in CLI](/en/posts/curl-http-debugging-cli/)
- [ethtool: network interface diagnostics and tuning](/en/posts/ethtool-diagnosis-tuning-network-interface/)
- [lsof: which processes listen on port and hold file](/en/posts/lsof-port-file-processes/)
- [mc — MinIO Client S3 CLI](/en/posts/minio-mc-s3-client-usage/)
- [nftables: Modern Linux Firewall](/en/posts/nftables-modern-firewall-linux/)
- [ss: socket statistics instead of deprecated netstat](/en/posts/ss-replace-netstat/)
- [SSH Config: Wildcards and Dynamic Variable Substitution](/en/posts/ssh-config-wildcards-dynamic-variables/)
- [strace: System Call Tracing for Diagnosing Hangs and Leaks](/en/posts/strace-syscall-troubleshooting/)
- [tcpdump and tshark: Packet Capture in CLI](/en/posts/tcpdump-tshark-cli-packet-capture/)
- [CasaOS: Web Dashboard for Home Lab](/en/posts/casaos-home-lab/)
- [cockpit-ufw-module: Uncomplicated Firewall in Cockpit](/en/posts/cockpit-ufw-module/)
- [Creating a Custom Systemd Service](/en/posts/custom-systemd-service/)
- [kubectl whoami and Service Account Permission Checks](/en/posts/kubectl-whoami-check-sa-rights/)
- [ngrep: grep for Network Packets in Real Time](/en/posts/ngrep-setevoy-grep/)
- [socat: Forwarding Unix Sockets Over TCP](/en/posts/socat-unix-socket-tcp-forwarding/)
- [SSH Escape Sequences: Reviving a Frozen Terminal](/en/posts/ssh-escape-sequences-frozen-terminal/)
- [What is Self-Hosted and Why It's So Popular](/en/posts/what-is-self-hosted/)
- [cockpit-modules: web panels for day-to-day operations](/en/posts/cockpit-modules/)
- [dig: DNS Query Debugging in CLI](/en/posts/dig-dns-cli-debugging/)
- [MkDocs: Project Documentation from Markdown](/en/posts/mkdocs-quick-start/)
- [Squid: Internet Forwarding to Remote VM](/en/posts/squid-proxy-remote-vm/)
- [SSH certificates instead of authorized_keys](/en/posts/ssh-certificates-instead-of-authorized-keys/)
- [systemd-timer: scheduling instead of cron](/en/posts/systemd-timer-scheduling/)
- [Cron setup: a practical walkthrough](/en/posts/cron-setup/)
- [GNU Screen: sessions that survive an SSH drop](/en/posts/gnu-screen/)
- [Kafka: Cluster Health Check](/en/posts/kafka-cluster-health-check/)
- [kind: Local Kubernetes in Docker](/en/posts/kind-local-kubernetes-in-docker/)
- [Too many authentication failures: SSH ran out of tries](/en/posts/ssh-too-many-authentication-failures/)
- [Trusting a custom CA: system store, browsers, and CLI](/en/posts/trust-custom-ca/)
- [ssh-connection-manager: a TUI for hosts in ~/.ssh/config](/en/posts/ssh-connection-manager/)
