<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Sysadmin on yequari.com</title>
		<link>https://yequari.com/tags/sysadmin/</link>
		<description>Recent content in Sysadmin on yequari.com</description>
		<generator>Hugo</generator>
		<language>en-us</language>
		
		
		
		
			<lastBuildDate>Mon, 05 Oct 2026 12:33:54 -0700</lastBuildDate>
		
			<atom:link href="https://yequari.com/tags/sysadmin/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Nginx notes</title>
				<link>https://yequari.com/notes/nginx/</link>
				<pubDate>Mon, 05 Oct 2026 11:59:00 -0700</pubDate>
				<guid>https://yequari.com/notes/nginx/</guid>
				<description>&lt;p&gt;Enable an available site&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;sudo ln -s /etc/nginx/sites-available/your_site.conf /etc/nginx/sites-enabled/&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Test config&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;sudo nginx -t&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reload nginx&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;sudo systemctl reload nginx&#xA;&lt;/code&gt;&lt;/pre&gt;</description>
			</item>
			<item>
				<title>Postgresql Notes</title>
				<link>https://yequari.com/notes/postgresql/</link>
				<pubDate>Mon, 05 Oct 2026 11:59:00 -0700</pubDate>
				<guid>https://yequari.com/notes/postgresql/</guid>
				<description>&lt;h1 id=&#34;configure-connections&#34;&gt;Configure connections&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Configure listen addresses in &lt;code&gt;/etc/postgresql/17/main/postgresql.conf&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;Configure what addresses can access which databases with which users in &lt;code&gt;/etc/postgresql/17/main/pg_hba.conf&lt;/code&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;create-a-user-and-a-database-owned-by-them&#34;&gt;Create a user and a database owned by them&lt;/h1&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;psql&#xA;CREATE USER username WITH PASSWORD &amp;#39;password&amp;#39;;&#xA;CREATE DATABASE dbname OWNER owneruser;&#xA;GRANT ALL PRIVILEGES ON DATABASE dbname TO username;&#xA;\c dbname&#xA;GRANT ALL ON SCHEMA public TO username;&#xA;&#xA;# for Discourse&#xA;CREATE EXTENSION hstore;&#xA;CREATE EXTENSION pg_trgm;&#xA;CREATE EXTENSION unaccent;&#xA;CREATE EXTENSION vector;&#xA;&#xA;# temporarily add superuser to restore user&#xA;ALTER USER username WITH SUPERUSER;&#xA;ALTER USER username WITH NOSUPERUSER;&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&#34;connect-via-psql&#34;&gt;Connect via &lt;code&gt;psql&lt;/code&gt;&lt;/h1&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;psql -h host -p port -U username -d dbname&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&#34;migrate-data-directory&#34;&gt;Migrate data directory&lt;/h1&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Stop postgresql service&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;cp -a source_data_directory destination_data_directory&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;`chown -R postgres_user /destination_data_directory&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;export PGDATA=destination_data_directory&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;Changing data directory to &lt;code&gt;destination_data_directory&lt;/code&gt; within &lt;code&gt;postgresql.conf&lt;/code&gt;&lt;/li&gt;&#xA;&lt;li&gt;pg_ctl start&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
			</item>
			<item>
				<title>Server Administration Basics</title>
				<link>https://yequari.com/notes/server-administration-basics/</link>
				<pubDate>Mon, 05 Oct 2026 11:59:00 -0700</pubDate>
				<guid>https://yequari.com/notes/server-administration-basics/</guid>
				<description>&lt;p&gt;These are the first steps I do to setup a brand new server&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;TODO: Provide explanations for what all this actually does and why you should do it.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;h1 id=&#34;add-user&#34;&gt;Add user&lt;/h1&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;useradd -m yequari&#xA;passwd yequari&#xA;usermod -aG sudo yequari&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&#34;copy-ssh-key&#34;&gt;Copy SSH key&lt;/h1&gt;&#xA;&lt;p&gt;Assuming you are currently root, trying to set up SSH on your new user&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;mkdir /home/yequari/.ssh&#xA;echo &amp;lt;pubkey&amp;gt; &amp;gt;&amp;gt; /home/yequari/.ssh/authorized_keys&#xA;chown -R yequari:yequari /home/yequari/.ssh&#xA;chmod 0700 /home/yequari/.ssh&#xA;chmod 0600 /home/yequari/.ssh/authorized_keys&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&#34;disable-password-auth&#34;&gt;Disable Password Auth&lt;/h1&gt;&#xA;&lt;p&gt;Edit &lt;code&gt;/etc/ssh/sshd_config&lt;/code&gt;&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;PasswordAuthenticaion no&#xA;KbdInteractiveAuthentication no&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Restart ssh service&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;sudo systemctl restart ssh.service&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&#34;install-fail2ban-and-ufw&#34;&gt;Install fail2ban and ufw&lt;/h1&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;sudo apt install fail2ban ufw&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;h1 id=&#34;set-up-firewall&#34;&gt;Set up firewall&lt;/h1&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;sudo ufw default deny incoming&#xA;sudo ufw default allow outgoing&#xA;sudo ufw allow 22/tcp&#xA;sudo ufw allow 80/tcp&#xA;sudo ufw allow 443/tcp&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;To allow connection to port from only specific hosts&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;sudo ufw allow from &amp;lt;host_ip&amp;gt; to any port &amp;lt;port#&amp;gt;&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;See &#xA;&#xA;&#xA;&lt;a href=&#34;https://www.digitalocean.com/community/tutorials/how-to-setup-a-firewall-with-ufw-on-an-ubuntu-and-debian-cloud-server&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;&#xA;  DigitalOcean Community&lt;svg width=&#34;14px&#34; height=&#34;14px&#34; viewBox=&#34;0 0 24 24&#34; fill=&#34;none&#34; stroke=&#34;currentColor&#34; stroke-width=&#34;2&#34; stroke-linecap=&#34;round&#34; stroke-linejoin=&#34;round&#34;&gt;&#xA;&lt;path d=&#34;M18 13v6a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V8a2 2 0 0 1 2-2h6&#34;&gt;&lt;/path&gt;&#xA;&lt;polyline points=&#34;15 3 21 3 21 9&#34;&gt;&lt;/polyline&gt;&#xA;&lt;line x1=&#34;10&#34; y1=&#34;14&#34; x2=&#34;21&#34; y2=&#34;3&#34;&gt;&lt;/line&gt;&#xA;&lt;/svg&gt;&lt;/a&gt;&#xA; for more &lt;code&gt;ufw&lt;/code&gt; tips&lt;/p&gt;&#xA;</description>
			</item>
			<item>
				<title>Example Systemd Service</title>
				<link>https://yequari.com/notes/systemd-example/</link>
				<pubDate>Mon, 06 May 2024 00:00:00 -0700</pubDate>
				<guid>https://yequari.com/notes/systemd-example/</guid>
				<description>&lt;p&gt;System units go in &lt;code&gt;/etc/systemd/system&lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;User units go in &lt;code&gt;$HOME/.config/systemd/user&lt;/code&gt;&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;[Unit]  &#xA;Description=Webring test service &#xA;After=network.target&#xA;StartLimitIntervalSec=0&#xA;&#xA;[Service]  &#xA;Type=simple&#xA;Restart=always&#xA;RestartSec=1&#xA;WorkingDir=/code/webring&#xA;ExecStart=/code/webring/webring --dsn /code/webring/webring.db --addr :8000&#xA;  &#xA;[Install]  &#xA;WantedBy=multi-user.target&#xA;&lt;/code&gt;&lt;/pre&gt;</description>
			</item>
	</channel>
</rss>
