Search This Blog

Showing posts with label configuration management. Show all posts
Showing posts with label configuration management. Show all posts

Wednesday, August 29, 2012

How to control and manage you cloud servers from a bastion server

The idea is very simple. We would like to have one (or more) server that belongs to our cloud account and use it only to execute and orchestrate various execution tasks. A diagram below is showing the concept. From the machine you have to ssh to your bastion (1) and then from it you can run any further tasks (2).



An hardened servers should be used as a bastion host. This server will provide the following functions:

  • Act as a secure gateway into the cloud environment 
  • You should configure all other server to accept connections from this server only
  • From bastion you can lunch tasks that will perform further actions on the other cloud servers

Problem

How to run ssh or scp command over ssh that is initiated by the client and need to be executed from a bastion host on other cloud server.

Solution

This relatively long script written in python that uses paramiko module demonstrates the idea. It can be definitely extended and improved but you get the idea I hope :).

Wednesday, November 4, 2009

Configuration Management and DB2 parameters

Configuration Management is one of the most important thing in problem and incident management. Even in a simple situation when our db server with important db's will totally demanded we will need some "secured", high tuned parameters for db, application or for the operating system.

To be able to collect this db parameters we can write some simple script which will do this for us. The most important thing in this script that we need to thing about are: looking and deadlock situation in the db.

For IBM db2 we can use following peace of code in Perl, which will use "uncommitted lock" during the connection with db to get the db parameters:
446: $id= getpwnam("$user_name");
447: @tmp=getpwuid($id);
448: $home_dir=$tmp[7];
449: $cmd="db2 change isolation to ur ; " .
"
db2 connect to $db_name ; " .
"db2 list tables for all show detail; db2 connect reset"
;
450:
451: @tmp=`sudo su - $user_name -c "$cmd" 2>&1`;
The complete script can be found there db2-cfg-info.pl