2 ms·
Firstly, a nice checklist. Easy actionable steps, repeatable, and pretty much most of what you need. Secondly, you are about 4-5 hours away from learning puppe
by josephkern 14y ago
Firstly, a nice checklist. Easy actionable steps, repeatable, and pretty much most of what you need.
Secondly, you are about 4-5 hours away from learning puppet (or Chef) and making this checklist into actual code.
Thirdly, you now have a checklist of items that you can use in a job interview if you get the oppertunity to gain a new-hire or an intern.
Lastly, good on you for submitting this to a peer-review on HN. We can be a picky lot.
TL;DR Checklists are a good first step for building a proper config management system.
- laumars 14y agoWe can be picky, but with good reason as security is an exact science and a costly one to get wrong. There's so much conflicting and out right bad advice posted online these days that sometimes it takes a picky community to help clarify the best practices. For what it's worth, some of the advice given in that article was worth mentioning (eg fail2ban, it's a great tool). But the shared account suggestion was the complete opposite of how you should be managing user accounts as you lose audit trails. And for that comment alone, I'd recommend people read that article with a degree of scepticism before rushing onto any boxes they might administrate. That article has generated a lot of good discussion though. So even if just indirectly, it's been a valuable contribution to HN.
- josephkern 14y agoPicky is good! We never grow without constructive critisim. And a community of practice may yeild better results than an individual (at least for simple things). > I'd recommend people read that article with a degree of scepticism before rushing onto any boxes they might administrate. Agreed. But the same could be said of everything; hackers and engineers, empiricists both. Some of the advice in the article would seem apporpriate to someone who had never worked with another senior engineer. No fault of the OP. System engineering and security are as much a learned craft as a science; a dialectic between sand castles (if you will).