Posts
nslookup and drill: DNS resolution in terminal
The server won’t resolve a domain, but pings fly through. No familiar dig at hand — the BIOS is already loading a minimal busybox. Or on a host without …
ip: Network Setup and Diagnostics in CLI
When ifconfig returns nothing and configuring a route requires a separate command, that’s not a system bug. It’s iproute2 — the package that replaced net-tools …
bpftrace: one-liners that replace strace in production
strace halts a process on every syscall. On a live server at 2000 RPS, that means timeouts and alerts. bpftrace runs through eBPF in the kernel — tracing …
ProxyJump and bastion hosts via ~/.ssh/config
Sometimes a server sits in a private network with no public IP. The only entry point is a bastion host with a public address. Typing ssh -J user@bastion …
OpenSSL: TLS Certificate Verification and Parsing in CLI
Certificates expiring on prod at the worst moment — a familiar story. OpenSSL answers TLS certificate questions faster than any marketplace checker. Here are …
journalctl: Filtering and Formatting systemd Logs
Logs disappeared. Server rebooted, and the familiar less /var/log/syslog returns nothing. On modern distros with systemd, logs are collected by journald and …
systemd-run: Run Services Without Unit Files
Sometimes you need to run a process under systemd’s control without writing a unit file — maybe you’re in a container without systemd, on someone else’s …
sshd_config: baseline for a test stand
SSH access to a test stand often gets opened in a hurry, and then the logs fill with brute-force attempts. A baseline sshd_config that blocks common attack …
logrotate: automatic log rotation and archiving
Application logs fill up disk space within a week, and manually running rm *.log is a recipe for trouble. logrotate handles this automatically: it rotates, …
auditd: file access and syscall logging
Linux doesn’t write every access to /etc/shadow or every unlink call to syslog. For incident investigation and compliance this is critical. auditd solves this: …
nftables: Modern Linux Firewall
Warning Before changing nftables, make sure you have physical or console access to the server. A misconfigured input chain can block SSH and lock you out. …
mc — MinIO Client S3 CLI
S3-compatible object storage is the default choice for buckets, backups, and static assets. When AWS CLI feels excessive and the web console is too clunky, …