LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise
User Name
Password
Linux - Enterprise This forum is for all items relating to using Linux in the Enterprise.

Notices


Reply
  Search this Thread
Old 07-15-2016, 08:58 AM   #1
jsdomingo
LQ Newbie
 
Registered: Feb 2016
Posts: 18

Rep: Reputation: Disabled
Revamp Infrastructure


Hi everyone,

I recently transitioned to the Linux (RHEL/CentOS) environment roughly 9-ish months ago and have learned so much since then but still consider myself a total newbie. This is my first Linux Administration role and I've never seen other infrastructures compared to what I've been dealing with. Our host/user base is also roughly about 20ish and I'd like to be prepared when that grows in the future.

Currently I feel as if the current infrastructure, that I inherited, isn't setup properly and I'd like everyone's opinion on my thoughts about improving it.

Here is how we have things setup:

RHEL Server (NFS Share): This host has been setup with the CentOS/RHEL kickstarts for NFS deployment and also Open Source Puppet for applying the necessary post imaging configurations.

RHEL Workstation (Sync? Local Repo): This host was setup with downloading RHEL/CentOS packages weekly and have our workstation hosts pointed to it for updates by using reposync. Unfortunately, there isn't a RHEL Server VM spun up setup like this host (yet) and all of our RHEL Servers are being pointed directly to RHN. Our local site requires the hosts to point to a local repo so that it can be managed. The reason why I have yet to stand up another RHEL Server VM for reposync is explained below.

My thought was to purchase Red Hat Satellite Server and utilize the Puppet Enterprise
(https://access.redhat.com/articles/s...pet-enterprise) integration so this way we can just get rid of the jury-rigged repo VM. Our RHEL machines also aren't subscribed since they're just pulling updates from the local repo.
 
Old 07-18-2016, 12:42 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Where you must use RHEL (for whatever reasons, client contract, compliance etc, etc) you first need to fix Licensing and then using Satellite + Puppet does make sense. For those machines that haven't such requirements transitioning to CentOS + Spacewalk (OSS Satellite) may be an option. And not that it's ready right now I believe but also look ahead at what Red Hat has on offer for the future (CloudForms + Foreman vs Katello).
 
Old 07-18-2016, 06:16 AM   #3
jsdomingo
LQ Newbie
 
Registered: Feb 2016
Posts: 18

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by unSpawn View Post
Where you must use RHEL (for whatever reasons, client contract, compliance etc, etc) you first need to fix Licensing and then using Satellite + Puppet does make sense. For those machines that haven't such requirements transitioning to CentOS + Spacewalk (OSS Satellite) may be an option. And not that it's ready right now I believe but also look ahead at what Red Hat has on offer for the future (CloudForms + Foreman vs Katello).
Thank you for your response. Just as you said, for reasons (DoD), we only have RHSS and PE approved or else I would setup CentOS + Spacewalk. Good to know about the CloudForms + Foreman vs Katello, I'll play with those at home to get my feet wet.
 
Old 07-18-2016, 09:43 AM   #4
JockVSJock
Senior Member
 
Registered: Jan 2004
Posts: 1,420
Blog Entries: 4

Rep: Reputation: 164Reputation: 164
Quote:
Originally Posted by jsdomingo View Post
Thank you for your response. Just as you said, for reasons (DoD), we only have RHSS and PE approved or else I would setup CentOS + Spacewalk. Good to know about the CloudForms + Foreman vs Katello, I'll play with those at home to get my feet wet.
I'm curious about your DoD site. Since I work DoD too, and we don't allow any of our DoD RHEL Servers to go out to RH Network directly. We have a Red Hat Satellite, disconnected, where we do all of the patching from. So I'm wondering why it is setup this way?

Also for NFS, it is against the STIGs to run this, so I shut all of that down and use scp to move files right now.
 
Old 07-18-2016, 09:50 AM   #5
jsdomingo
LQ Newbie
 
Registered: Feb 2016
Posts: 18

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by JockVSJock View Post
I'm curious about your DoD site. Since I work DoD too, and we don't allow any of our DoD RHEL Servers to go out to RH Network directly. We have a Red Hat Satellite, disconnected, where we do all of the patching from. So I'm wondering why it is setup this way?

Also for NFS, it is against the STIGs to run this, so I shut all of that down and use scp to move files right now.
That's interesting, from what I gathered, no regular workstations are allowed to connect directly to RHN just as you said unless it's through a local repo or RHSS. We just went though the new accreditation process with DISA and I don't recall seeing anything saying this wasn't allowed. Could you clarify as to which portion you meant as being setup "this way"?

The STIGs don't specifically say to not use NFS (unless I missed a STIG ID), they say that if you are using it, you need certain options in place such as "nosuid" and "nodev" (list goes on).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
infrastructure henryjames Linux - Newbie 2 06-07-2016 08:27 AM
KDE3 series revamp (trinity) as seen on Porteus live for 13.x series SCerovec Slackware 22 01-26-2012 11:49 AM
Oolite models and textures revamp in progress Simon Bridge Linux - Games 0 05-17-2009 02:55 AM
LXer: BBC Web TV revamp: Linux and Apple are in LXer Syndicated Linux News 0 02-02-2007 09:21 PM

LinuxQuestions.org > Forums > Enterprise Linux Forums > Linux - Enterprise

All times are GMT -5. The time now is 05:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration