# ๐Ÿ“„ ะ•ะดะธะฝั‹ะน ั„ะฐะนะป ัะฐะนั‚ะฐ SysAdmin Blog ะ’ะพั‚ ะฟะพะปะฝั‹ะน HTML-ั„ะฐะนะป ัะพ ะฒัะตะผ ัะฐะนั‚ะพะผ (27 ัั‚ั€ะฐะฝะธั† ะฒ ะพะดะฝะพะผ ั„ะฐะนะปะต). ะกะพั…ั€ะฐะฝะธั‚ะต ะตะณะพ ะบะฐะบ `sysadmin-blog.html` ะธ ะพั‚ะบั€ะพะนั‚ะต ะฒ ะฑั€ะฐัƒะทะตั€ะต. ```html James Morrison โ€” SysAdmin Blog | Helsinki, Finland
๐Ÿ“ Helsinki, Finland

Keeping Servers Alive,
One Terminal at a Time

Senior Systems Administrator sharing battle-tested knowledge on Linux, DevOps, cloud infrastructure, and cybersecurity. No fluff โ€” just real solutions.

james@helsinki:~
$ whoami
james_morrison
$ cat /etc/role
Senior Systems Administrator | DevOps Engineer
$ uptime
14 years of production experience
$ echo $PASSION
200+
Articles Published
14
Years Experience
500+
Servers Managed
99.9%
Uptime Record

Latest Articles

Deep dives into systems administration, security, and infrastructure automation.

๐Ÿง

Linux Server Hardening: A Complete 2026 Guide

Essential steps to secure your Linux servers against modern threats, from SSH configuration to kernel parameters.

Read More โ†’
๐Ÿณ

Docker Security Best Practices for Production

How to run containers securely in production environments with proper isolation and image scanning.

Read More โ†’
โ˜ธ๏ธ

Kubernetes for SysAdmins: Practical Guide

A systems administrator's perspective on managing Kubernetes clusters in production.

Read More โ†’
View All Articles โ†’

What I Do

Comprehensive infrastructure solutions for businesses of all sizes.

๐Ÿ–ฅ๏ธ

Linux Administration

Expert management of RHEL, Ubuntu, Debian, and CentOS systems. Performance tuning, patch management, and high availability configurations.

โš™๏ธ

DevOps & Automation

CI/CD pipelines with GitLab CI and Jenkins. Infrastructure as Code using Ansible, Terraform, and cloud-native tooling.

๐Ÿ”’

Cybersecurity

Security audits, firewall configurations, intrusion detection, incident response, and compliance with GDPR and ISO 27001.

All Services โ†’

Need Infrastructure Expertise?

Whether you need a server audit, migration planning, or ongoing administration โ€” let's talk.

Get in Touch โ†’

Hello, I'm James Morrison

I'm a Senior Systems Administrator and DevOps Engineer based in Helsinki, Finland. For over 14 years, I've been managing, securing, and automating infrastructure for companies ranging from Finnish startups to multinational enterprises.

My journey started with a curiosity about how the internet works, which led me to my first Linux server at age 16. Since then, I've managed hundreds of servers, built CI/CD pipelines processing thousands of deployments, and responded to more 3 AM incidents than I care to count.

This blog is my way of giving back to the community that helped me grow. Every article here is based on real production experience โ€” no theoretical fluff.

~/about_me.sh
#!/bin/bash
NAME="James Morrison"
ROLE="Senior Systems Administrator"
LOCATION="Helsinki, Finland ๐Ÿ‡ซ๐Ÿ‡ฎ"
EXPERIENCE="14+ years"
CERTS=("RHCE" "AWS SA Pro" "CKA" "CompTIA Security+")
COFFEE_PER_DAY=4
# Still learning, still breaking things (in staging)

Technical Skills

Linux (RHEL, Ubuntu, Debian)98%
Docker & Kubernetes92%
Ansible / Terraform90%
AWS / Azure / GCP88%
Networking & Firewalls94%
CI/CD (GitLab, Jenkins)91%
Python / Bash Scripting87%
Monitoring (Prometheus, Grafana)89%

Certifications

  • ๐Ÿ† Red Hat Certified Engineer (RHCE)
  • ๐Ÿ† AWS Solutions Architect Professional
  • ๐Ÿ† Certified Kubernetes Administrator (CKA)
  • ๐Ÿ† CompTIA Security+
  • ๐Ÿ† HashiCorp Terraform Associate

Career Timeline

Senior Systems Administrator

2021 โ€” Present

Leading infrastructure team at a Finnish fintech company. Managing hybrid cloud environments across AWS and on-premise data centers.

DevOps Engineer

2018 โ€” 2021

Built CI/CD pipelines, containerized microservices, and implemented Infrastructure as Code for a Helsinki-based SaaS company.

Systems Administrator

2015 โ€” 2018

Managed 200+ Linux servers, implemented monitoring with Nagios/Zabbix, and led migration from physical to virtual infrastructure.

Junior SysAdmin / Help Desk

2012 โ€” 2015

Started in IT support, quickly moved to server administration. First exposure to enterprise Linux environments and networking.

๐Ÿง

Linux Server Hardening: A Complete 2026 Guide

Essential steps to secure your Linux servers against modern threats.

Read More โ†’
๐Ÿณ

Docker Security Best Practices for Production

Run containers securely with proper isolation and image scanning.

Read More โ†’
โ˜ธ๏ธ

Kubernetes for SysAdmins: Practical Guide

A sysadmin's perspective on managing K8s clusters in production.

Read More โ†’
๐Ÿค–

Ansible Automation: From Zero to Production

Automate server provisioning and configuration management with Ansible.

Read More โ†’
๐Ÿ“ก

Network Monitoring with Prometheus & Grafana

Build a comprehensive monitoring stack for your infrastructure.

Read More โ†’
๐Ÿ’พ

Backup Strategies That Actually Work

Implement the 3-2-1 rule and automate your backup workflows.

Read More โ†’
๐Ÿงฑ

Firewall Setup with iptables and nftables

Configure robust firewall rules to protect your servers.

Read More โ†’
๐ŸŒ

DNS Management: Bind, PowerDNS & Cloud DNS

Master DNS configuration for reliability and performance.

Read More โ†’
๐Ÿ”„

CI/CD Pipelines: GitLab CI vs Jenkins

Compare and build effective continuous integration and delivery pipelines.

Read More โ†’
Browse by Category โ†’
๐Ÿ–ฅ๏ธ

Linux Server Administration

Full lifecycle management of RHEL, Ubuntu, and Debian servers. Includes patch management, performance tuning, and 24/7 monitoring setup.

โš™๏ธ

DevOps & CI/CD

Design and implement CI/CD pipelines using GitLab CI, Jenkins, and GitHub Actions. Automate testing, building, and deployment workflows.

๐Ÿ”’

Security Audits

Comprehensive security assessments including penetration testing, vulnerability scanning, firewall review, and compliance checks (GDPR, ISO 27001).

โ˜๏ธ

Cloud Migration

Plan and execute migrations to AWS, Azure, or GCP. Includes architecture design, cost optimization, and hybrid cloud setups.

๐Ÿณ

Container Orchestration

Kubernetes cluster setup, management, and optimization. Docker containerization strategies and microservices architecture consulting.

๐Ÿ“Š

Monitoring & Observability

Implement comprehensive monitoring with Prometheus, Grafana, ELK Stack, and custom alerting. Never miss a critical issue again.

Request a Quote โ†’

๐Ÿฆ Fintech Platform Migration

Migrated a monolithic application to microservices on Kubernetes. Reduced deployment time from 4 hours to 8 minutes. Handled 50+ services across 3 availability zones.

๐Ÿฅ Healthcare Data Platform

Designed GDPR-compliant infrastructure for a Finnish healthcare company. Implemented end-to-end encryption, audit logging, and disaster recovery with RPO < 1 hour.

๐Ÿ›’ E-Commerce Scaling

Built auto-scaling infrastructure handling 10x traffic spikes during Black Friday. Implemented CDN, database read replicas, and Redis caching layer.

๐Ÿญ IoT Fleet Management

Managed infrastructure for 10,000+ IoT devices. Built MQTT broker clusters, time-series database pipelines, and real-time alerting systems.

CategoryToolUse Case
EditorsNeovim, VS CodeConfiguration files, scripting, documentation
Terminaltmux, AlacrittySession management, GPU-accelerated terminal
MonitoringPrometheus, Grafana, ZabbixMetrics collection, dashboards, alerting
LoggingELK Stack, LokiCentralized log aggregation and search
AutomationAnsible, Terraform, PackerConfiguration management, IaC, image building
ContainersDocker, Podman, KubernetesContainerization and orchestration
CI/CDGitLab CI, Jenkins, ArgoCDContinuous integration and deployment
NetworkingWireshark, nmap, tcpdumpNetwork analysis and troubleshooting
SecurityOpenSCAP, Lynis, Fail2BanSecurity scanning and intrusion prevention
CloudAWS CLI, az CLI, gcloudMulti-cloud management
๐Ÿ“š

Books

UNIX and Linux System Administration Handbook by Nemeth et al. โ€” The bible of sysadmin work.

The Phoenix Project by Gene Kim โ€” Understanding DevOps through narrative.

Site Reliability Engineering by Google โ€” How to run production systems.

๐ŸŽ“

Certifications Path

1. CompTIA Linux+ โ†’ 2. RHCSA โ†’ 3. RHCE โ†’ 4. AWS SA Associate โ†’ 5. CKA โ†’ 6. AWS SA Professional. This path gives you a well-rounded foundation.

๐Ÿ”—

Communities

r/sysadmin, r/linuxadmin, Hacker News, Linux Foundation forums, local Finnish Linux user groups (FLUG). Networking is as important as networking.

What Linux distributions do you specialize in? +
I primarily work with RHEL/Rocky Linux for enterprise environments, Ubuntu for cloud and container workloads, and Debian for stable infrastructure. I also have experience with SUSE and Arch Linux.
Do you offer remote consulting? +
Yes! While I'm based in Helsinki, I work with clients globally. Most of my consulting is done remotely via secure SSH sessions, video calls, and collaborative documentation.
How often do you publish new articles? +
I aim to publish 2-3 articles per week. Topics are based on real production challenges I encounter, community questions, and emerging technologies in the sysadmin space.
Can you help with GDPR compliance for infrastructure? +
Absolutely. Being based in Finland, GDPR compliance is part of my daily work. I can help with data encryption, access controls, audit logging, and data residency requirements for EU-based infrastructure.
What is your typical response time for consulting? +
For ongoing retainer clients, I offer 1-hour response time during business hours (EET). For emergency situations, I provide 24/7 on-call availability with a 15-minute response SLA.
Do you work with startups or only enterprises? +
I work with both! Startups often need help building their infrastructure right from the start, while enterprises need optimization and migration. I tailor my approach to each client's size and budget.

Send a Message

Contact Info

๐Ÿ“ Location: Helsinki, Finland

๐Ÿ“ง Email: james@jamesmorrison.fi

๐Ÿ• Timezone: EET (UTC+2) / EEST (UTC+3)

๐Ÿ’ผ Availability: Open for consulting

contact.sh
$ echo "Let's build something reliable."
Let's build something reliable.
$ gpg --fingerprint james@jamesmorrison.fi
# PGP key available on request

1. Introduction

Welcome to jamesmorrison.fi. This Privacy Policy explains how James Morrison ("I", "me") collects, uses, and protects your personal data when you visit this website, in compliance with the EU General Data Protection Regulation (GDPR).

2. Data Controller

James Morrison, Helsinki, Finland. Contact: james@jamesmorrison.fi

3. Data We Collect

  • Contact forms: Name, email, and message content when you voluntarily submit them.
  • Server logs: IP addresses, browser type, and access timestamps for security purposes.
  • Cookies: Minimal cookies for site functionality. No tracking cookies are used.

4. Legal Basis

Data processing is based on your consent (contact forms) and legitimate interest (security logs), as defined by GDPR Articles 6(1)(a) and 6(1)(f).

5. Data Retention

Contact form data is retained for up to 12 months. Server logs are automatically purged after 30 days.

6. Your Rights

Under GDPR, you have the right to access, rectify, erase, and port your personal data. Contact me at james@jamesmorrison.fi to exercise these rights.

7. Contact

For any privacy-related questions, email james@jamesmorrison.fi.

1. Acceptance of Terms

By accessing and using jamesmorrison.fi, you agree to be bound by these Terms of Service. If you do not agree, please do not use this website.

2. Content

All articles, tutorials, and code examples on this blog are provided for informational purposes. While I strive for accuracy, I cannot guarantee that all information is error-free or applicable to your specific environment.

3. Code Examples

Any code provided in articles is offered "as is" without warranty. Always test in a staging environment before applying to production systems.

4. Intellectual Property

All content on this website is the intellectual property of James Morrison unless otherwise stated. You may share links to articles but may not reproduce content without permission.

5. Liability

I am not liable for any damages arising from the use of information, code, or advice provided on this website.

6. Governing Law

These terms are governed by the laws of Finland. Any disputes shall be resolved in the courts of Helsinki.

Why Server Hardening Matters

In 2026, automated scanning bots find newly provisioned servers within minutes. Without proper hardening, your server will be compromised before you finish reading this article. Here is a comprehensive checklist based on years of production experience.

1. Keep Everything Updated

The most basic yet most overlooked security measure. Enable automatic security updates:

# Ubuntu/Debian
sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades

# RHEL/Rocky
sudo dnf install dnf-automatic
sudo systemctl enable --now dnf-automatic-install.timer

2. SSH Hardening

SSH is the primary attack vector. Configure these in /etc/ssh/sshd_config:

PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
AllowUsers admin deployer
ClientAliveInterval 300
ClientAliveCountMax 2

3. Firewall Configuration

Use nftables (successor to iptables) to implement a default-deny policy. Only open ports you absolutely need.

4. Kernel Hardening with sysctl

# /etc/sysctl.d/99-hardening.conf
net.ipv4.ip_forward = 0
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
kernel.randomize_va_space = 2

5. File System Security

Security is not a product, but a process. โ€” Bruce Schneier

6. Audit and Logging

Enable auditd for comprehensive system auditing. Forward logs to a centralized SIEM. Monitor failed login attempts, privilege escalation, and file changes.

Conclusion

Hardening is an ongoing process, not a one-time task. Regularly review your configurations, stay updated on CVEs, and practice incident response before you need it.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

The Container Security Landscape

Containers share the host kernel, making security configuration critical. A misconfigured container can lead to full host compromise.

1. Use Minimal Base Images

# Bad
FROM ubuntu:latest

# Good
FROM alpine:3.19
# or even better
FROM scratch

Smaller images have fewer vulnerabilities. Use distroless images when possible.

2. Run as Non-Root

RUN addgroup -S appgroup && adduser -S appuser -G appgroup
USER appuser

3. Image Scanning

Integrate Trivy or Grype into your CI/CD pipeline. Never deploy images with critical vulnerabilities.

4. Docker Security Options

docker run \
  --read-only \
  --tmpfs /tmp \
  --security-opt no-new-privileges:true \
  --cap-drop ALL \
  --cap-add NET_BIND_SERVICE \
  myapp:latest

5. Network Segmentation

Create custom Docker networks. Never expose containers directly to the internet without a reverse proxy.

6. Secrets Management

Never hardcode secrets in Dockerfiles or images. Use Docker secrets, Vault, or environment-specific secret injection.

A container is only as secure as its configuration.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

Why SysAdmins Need Kubernetes

Kubernetes has become the de facto standard for container orchestration. As a sysadmin, understanding K8s is no longer optional โ€” it is essential.

1. Cluster Architecture

Understand the control plane (API server, etcd, scheduler, controller manager) and worker nodes (kubelet, kube-proxy, container runtime).

2. Essential kubectl Commands

kubectl get nodes -o wide
kubectl get pods --all-namespaces
kubectl describe pod <pod-name>
kubectl logs -f <pod-name>
kubectl exec -it <pod-name> -- /bin/sh

3. Resource Management

Always set resource requests and limits. Without them, a single pod can starve the entire node.

4. RBAC

Implement Role-Based Access Control from day one. Follow least privilege โ€” no one needs cluster-admin except break-glass accounts.

5. Monitoring with Prometheus Operator

Deploy the kube-prometheus-stack for out-of-the-box monitoring of your cluster metrics, pod health, and node utilization.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

Why Ansible?

Ansible is agentless, uses YAML for playbooks, and has a massive module ecosystem. It is the perfect starting point for infrastructure automation.

1. Installation and Setup

pip install ansible
mkdir ~/ansible && cd ~/ansible
echo "[webservers]\nweb1.example.com\nweb2.example.com" > inventory

2. Your First Playbook

---
- name: Configure web servers
  hosts: webservers
  become: yes
  tasks:
    - name: Install nginx
      apt:
        name: nginx
        state: present
        update_cache: yes
    - name: Start nginx
      service:
        name: nginx
        state: started
        enabled: yes

3. Roles and Directory Structure

Organize complex automation with Ansible roles. Each role has tasks, handlers, templates, and variables.

4. Ansible Vault for Secrets

ansible-vault create secrets.yml
ansible-vault edit secrets.yml
ansible-playbook site.yml --ask-vault-pass

5. Best Practices

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

The Monitoring Trinity

Effective monitoring requires metrics collection (Prometheus), visualization (Grafana), and alerting (Alertmanager). Together, they form the foundation of observability.

1. Installing Prometheus

wget https://github.com/prometheus/prometheus/releases/download/v2.53.0/prometheus-2.53.0.linux-amd64.tar.gz
tar xvfz prometheus-*.tar.gz
cd prometheus-*/
./prometheus --config.file=prometheus.yml

2. Node Exporter for System Metrics

Deploy node_exporter on every server to collect CPU, memory, disk, and network metrics automatically.

3. Grafana Dashboards

Import community dashboards (ID 1860 for Node Exporter) and customize them. Set up data sources and create custom panels.

4. Alerting Rules

groups:
  - name: infrastructure
    rules:
      - alert: HighCPU
        expr: 100 - (avg by(instance) (rate(node_cpu_seconds_total{mode="idle"}[5m])) * 100) > 80
        for: 5m
        labels:
          severity: warning
        annotations:
          summary: "High CPU on {{ $labels.instance }}"

5. Best Practices

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

The 3-2-1 Rule

Keep 3 copies of your data, on 2 different media types, with 1 copy offsite. This is the gold standard of backup strategy.

1. rsync for File Backups

rsync -avz --delete \
  --exclude=".cache" \
  /var/www/ \
  backup@remote:/backups/www/

2. Database Backups

# PostgreSQL
pg_dump -Fc mydb > /backups/mydb_$(date +%Y%m%d).dump

# MySQL
mysqldump --single-transaction mydb | gzip > /backups/mydb.sql.gz

3. Automated Backup Scripts

Create cron jobs with proper error handling, notification, and rotation. Always test your restore process โ€” an untested backup is not a backup.

4. Offsite Storage

Use AWS S3 with lifecycle policies, Backblaze B2, or a secondary data center. Encrypt all offsite backups with GPG or age.

There are two types of people: those who have lost data and those who will.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

Default Deny Philosophy

Start with a default deny policy and only open what is necessary. This is the foundation of firewall security.

1. nftables Basics

#!/usr/sbin/nft -f
flush ruleset

table inet filter {
  chain input {
    type filter hook input priority 0; policy drop;
    ct state established,related accept
    iif lo accept
    tcp dport 22 accept
    tcp dport {80, 443} accept
  }
  chain forward {
    type filter hook forward priority 0; policy drop;
  }
  chain output {
    type filter hook output priority 0; policy accept;
  }
}

2. Rate Limiting

Protect against brute force attacks by rate-limiting SSH connections. Combine with fail2ban for IP-based blocking.

3. Logging Dropped Packets

Add logging rules before your drop rules to troubleshoot connectivity issues without compromising security.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

DNS is the Backbone

When DNS breaks, everything breaks. Understanding DNS management is a core sysadmin skill.

1. DNS Record Types

A, AAAA, CNAME, MX, TXT, SRV, NS, SOA โ€” know them all and when to use each one.

2. Running Your Own DNS

# BIND9 zone file example
$TTL 86400
@   IN  SOA  ns1.example.com. admin.example.com. (
        2026062001  ; Serial
        3600        ; Refresh
        900         ; Retry
        604800      ; Expire
        86400 )     ; Minimum
    IN  NS   ns1.example.com.
    IN  NS   ns2.example.com.
    IN  A    93.184.216.34

3. DNSSEC

Enable DNSSEC to prevent DNS spoofing attacks. Most cloud DNS providers support it natively.

4. Monitoring DNS

Monitor resolution times, check for propagation issues, and set up alerts for record changes.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

The CI/CD Imperative

Manual deployments are a liability. Automated pipelines reduce errors, increase velocity, and provide audit trails.

1. GitLab CI Example

stages:
  - test
  - build
  - deploy

test:
  stage: test
  script:
    - npm test
    - npm run lint

build:
  stage: build
  script:
    - docker build -t myapp:$CI_COMMIT_SHA .
    - docker push registry.example.com/myapp:$CI_COMMIT_SHA

deploy_prod:
  stage: deploy
  script:
    - kubectl set image deployment/myapp myapp=myapp:$CI_COMMIT_SHA
  only:
    - main

2. Jenkins vs GitLab CI

GitLab CI is more integrated and uses YAML configuration. Jenkins is more flexible with plugins but requires more maintenance. Choose based on your team size and needs.

3. Pipeline Security

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

Migration is Not Just Copy-Paste

A poorly planned migration can cause hours of downtime and data loss. This playbook covers the systematic approach I use for every migration.

Phase 1: Assessment

Phase 2: Preparation

Set up the target environment. Mirror configurations using Ansible playbooks. Test with non-production data first.

Phase 3: Data Sync

# Initial sync
rsync -avz /data/ target:/data/

# Final sync (during maintenance window)
rsync -avz --delete /data/ target:/data/

Phase 4: Cutover

DNS TTL reduction, final data sync, service switchover, and verification. Have a rollback plan ready.

The best migration is one that users never notice.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

Cloud is Not Just Someone Else Computer

Cloud infrastructure requires different thinking than traditional data centers. Embrace elasticity, automation, and managed services.

1. Multi-AZ Architecture

Deploy across multiple Availability Zones for high availability. Use load balancers to distribute traffic and handle zone failures gracefully.

2. Infrastructure as Code

# Terraform example
resource "aws_instance" "web" {
  ami           = "ami-0c55b159cbfafe1f0"
  instance_type = "t3.micro"

  tags = {
    Name        = "web-server"
    Environment = "production"
    ManagedBy   = "terraform"
  }
}

3. Cost Optimization

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

SSH is Your Front Door

SSH is the most targeted service on any server. Going beyond basic key authentication is essential for production environments.

1. Certificate-Based Authentication

Instead of managing individual public keys, use an SSH CA to sign certificates. This simplifies key management at scale.

2. SSH Bastion Hosts

Never expose SSH directly to the internet. Use a bastion/jump host as the single entry point with MFA.

3. SSH Configuration Hardening

# /etc/ssh/sshd_config
KexAlgorithms curve25519-sha256@libssh.org,diffie-hellman-group16-sha512
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com
MACs hmac-sha2-512-etm@openssh.com
HostKeyAlgorithms ssh-ed25519,rsa-sha2-512

4. SSH Agent Forwarding Alternatives

Avoid agent forwarding (it is a security risk). Use ProxyJump instead for multi-hop connections.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

Databases Are Not Just for DBAs

As a sysadmin, you need to handle database backups, replication, performance tuning, and basic troubleshooting.

1. PostgreSQL Performance Tuning

# postgresql.conf key parameters
shared_buffers = 25% of RAM
effective_cache_size = 75% of RAM
work_mem = 64MB
maintenance_work_mem = 512MB
max_connections = 200
wal_level = replica

2. Automated Backups

Use pg_basebackup for physical backups and pg_dump for logical backups. Always test restores.

3. Replication

Set up streaming replication for high availability. Monitor replication lag and automate failover with Patroni.

4. Connection Pooling

Use PgBouncer to manage database connections efficiently and prevent connection exhaustion.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

Why Centralized Logging?

When troubleshooting across 100 servers, SSH-ing into each one to grep logs is not an option. Centralized logging is essential.

1. ELK Stack Components

2. Lightweight Alternative: Loki + Promtail

# promtail config
scrape_configs:
  - job_name: system
    static_configs:
      - targets: [localhost]
        labels:
          job: varlogs
          __path__: /var/log/*.log

3. Log Retention Policies

Define retention based on compliance requirements. GDPR requires you to justify how long you keep logs containing personal data.

4. Alerting on Log Patterns

Create alerts for error spikes, security events, and application anomalies using Kibana alerts or ElastAlert.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’

Incidents Will Happen

The question is not if, but when. Having a structured incident response process reduces MTTR (Mean Time to Resolution) and minimizes damage.

1. The Incident Response Lifecycle

2. Communication During Incidents

Establish clear communication channels. Use a war room (Slack channel, Zoom call). Assign roles: Incident Commander, Communications Lead, Technical Lead.

3. Post-Mortem Template

# Incident Post-Mortem
## Summary
What happened in 2-3 sentences.

## Timeline
- HH:MM - Alert triggered
- HH:MM - Investigation started
- HH:MM - Root cause identified
- HH:MM - Fix deployed
- HH:MM - Services restored

## Root Cause
Technical explanation.

## Action Items
- [ ] Fix the bug
- [ ] Add monitoring
- [ ] Update runbook
Every incident is a learning opportunity. Blameless post-mortems build better systems.

Enjoyed this article?

Subscribe to get more sysadmin tips and tutorials delivered to your inbox.

Get in Touch โ†’
``` ---