Re: DPN: Debian System Administrators, What do you do?

Paul Wise <[email protected]>
Newsgroups gmane.linux.debian.devel.publicity,gmane.linux.debian.devel.www
Organization Debian
Message-ID <[email protected]>
On Tue, 2015-02-24 at 22:09 +0800, Paul Wise wrote:

> I'm working on a response to this, we'll discuss it and reply when done.

Hopefully the information below is useful, if there is anything more we
would suggest doing an interview, perhaps at DebConf.

The Debian System Administration (DSA) team is delegated to manage the
infrastructure of the Debian project, including machines, core services
and relationships with donors of equipment, services and hosting.

In practice, a nine person team gets to work through a deluge of email,
cron output, monitoring notifications, bouncing Debian member mail,
hoster/vendor notifications, spam, weird mail, misdirected questions,
hardware that fails to reboot, dying hardware, sick hardware, serial
consoles, disk replacements, hardware donations, hardware purchasing,
hardware sponsors, hosting sponsors, guest account requests, group
member changes, inter-release compatibility issues, service admin
prodding, security updates, inter-team co-ordination and much more.

Our tools of the trade include Debian stable (and some backports),
hardware capable of running amd64 VMs, entropy keys, ganeti, puppet,
icinga, munin, ikiwiki, git, postgresql, apache, openldap, gnupg,
openssh, bacula, ferm, sudo and a bunch of homegrown scripts.

We are interested in automation, reliability, speed, privacy, security,
resilience, longevity and try to balance these for the benefit of the
Debian project, members, users, derivatives and the wider world.

As we have a lot to deal with, we mostly leave the actual running of
services to service admins but provide general guidance as well as
specific guidance on a case-by-case basis.

https://wiki.debian.org/ServicesHosting#Recommended_practices_for_Debian_services

A recent achievement was modifying the update-ca-certificates code to
allow for multiple X.509 certificate stores and adding puppet bits to
ensure the 3 certificate stores we wanted are consistent between hosts. 

https://lists.debian.org/debian-services-admin/2014/12/msg00000.html

An ongoing project is to replace our current old LDAP web/mail frontend
with a new one based on Django.

https://wiki.debian.org/Teams/DSA/UserdirLdapRewrite

If anyone would like to reduce our workload, please take a look at and
fix the various bugs that we have filed.

https://bugs.debian.org/cgi-bin/[email protected]

-- 
bye,
pabs

https://wiki.debian.org/PaulWise
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCgAGBQJU7cQ3AAoJEDEWul6f+mmjE8YP/1Hwaapx+OHS3bnQCuDfIClp
SA/5WcmLtXB70KeLm3VA2kjw9esY+5KHZU55r0/i1mY7ykxdMRGqNnk2slJLCBW8
RO2Xgyog8h+pa/oz1OerXyXOjivDzDtTOzhs6rcdh68apyU2DjIes5kKBQWWcRiC
LELix2hABNnQtstlk/BrcR8A2wnHKbwkV2Yf5p3BtvCJ5m2g2S1a78KR+epgarkQ
jmgK+gqH23StIjKDhCSHmN5n/DLZspgoXB8iToERs8TcOy6syKoA/42tXpTnSDzv
ZE+U9aWFTYJqU3Au17s7fNAbix7cz7E3X4VICafWu9ZEKEj/0M8v5seFuoQR1dvF
EmhMwO3/jLXN7O6tcnN0RYqQGp7O94L1kDc5KqD/cx3d0ZxAPDRJZ0ISpb5VQu7W
UZUrDSbXHoy6+eZGzjzi8KfLuVQ1s9x3+yo3rcbq+C7Whz3THSMRsxLZTwy8Ej0H
8jP3HrTOQ9MdhHsD0FNKHWe35utG2jeUOhsJ8PR5tGmt50B1XjuDmzzJU9xQdaFu
7XVaHJ/OOczcLrZQ/Pr9UtC+LdH8Ylf+R6in6uacQQNUduBHOmxEdEPvHnFztTMd
noC2B6WRyP1TNoDbaZr7q7y7wk25UqBABJliVaeWjIOtZPPsCPrkXxGTKEVFTfGe
TXfjATmZJzGpxFDbqfJ3
=zkMt
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.