Skip to content

Tech

Technical guides from real engineering practice: installation, integration, automation, troubleshooting and production operation of modern Linux and open-source platforms. The articles connect concrete configuration with architecture, security, lifecycle, monitoring and operations.

  • FreeIPA sudo rule for delegated systemctl status sshd access

    FreeIPA sudo rules in practice: delegate commands without root passwords

    3 minutes read

    Practical guide for central FreeIPA sudo rules with user group, host group, command group, positive sudo test, negative checks and SSSD cache notes.

    : FreeIPA sudo rules in practice: delegate commands without root passwords
  • Thunderbird with a grommunio IMAP account after upgrading to grommunio 2026.06.2
    grommunio & Groupware

    grommunio native clients after Keycloak SSO

    7 minutes read

    Practical acceptance guide for Thunderbird, AutoConfig, AutoDiscover, EWS, EAS, Outlook boundaries and MFA after upgrading to grommunio 2026.06.2.

    : grommunio native clients after Keycloak SSO
  • grommunio Admin login with single sign-on button in the upgrade lab
    grommunio & Groupware,  Identity & Access,  Enterprise Linux

    grommunio 2026.06.2 Upgrade and Acceptance

    20 minutes read

    Practical guide: upgrade grommunio 2026.06.1 to 2026.06.2, handle Keycloak SSO, and accept the result with system, mail, discovery, MFA, browser and client checks.

    : grommunio 2026.06.2 Upgrade and Acceptance
  • Anonymized Proxmox VE cluster overview with multiple nodes and healthy Ceph status
    Proxmox & Virtualization

    Proxmox VE: Migrating CephX from AES to AES256K with Rook/OKD

    14 minutes read

    CephX key migration from AES to AES256K in Proxmox VE with external Rook/OKD, Ceph-CSI secrets and final cipher lockdown.

    : Proxmox VE: Migrating CephX from AES to AES256K with Rook/OKD
  • FreeIPA HBAC rule overview with disabled allow_all and custom SSH rule
    Identity & Access

    FreeIPA HBAC in practice

    5 minutes read

    Control SSH access by user group, host group and service and validate it with real SSH tests.

    : FreeIPA HBAC in practice
  • FreeIPA password policy overview with global_policy and policy-users
    Identity & Access

    FreeIPA password policies in practice

    6 minutes read

    Global and group policies, expiration, history, lockout, unlock and Linux client behavior in the lab.

    : FreeIPA password policies in practice
  • FreeIPA active users
    Identity & Access

    Managing FreeIPA users and groups

    4 minutes read

    Identity lifecycle, stage users, preserved users, groups, member managers and client evidence in the lab.

    : Managing FreeIPA users and groups
  • FreeIPA host overview with the enrolled client client01.example.test
    Identity & Access

    Connect Linux Clients to FreeIPA

    7 minutes read

    SSSD, Kerberos, central users, SSH, cache and recovery in a practical FreeIPA client lab.

    : Connect Linux Clients to FreeIPA
  • Cockpit storage view with the separate data disk.
    Enterprise Linux,  Linux Lifecycle Management

    Operate and harden SUSE Multi-Linux Manager 5.2 in production

    12 minutes read

    Operate SUSE Multi-Linux Manager 5.2 long-term: backup, restore, TLS, roles, monitoring, storage, channel sync, maintenance windows and handover.

    : Operate and harden SUSE Multi-Linux Manager 5.2 in production
  • System list with registered SLES 16 client.
    Enterprise Linux,  Linux Lifecycle Management

    SUSE Multi-Linux Manager 5.2: build reporting, inventory and subscription audit

    9 minutes read

    Reporting, inventory, CVE Audit and subscription matching in SUSE Multi-Linux Manager 5.2: turn managed systems into reliable operational information.

    : SUSE Multi-Linux Manager 5.2: build reporting, inventory and subscription audit