Putting a PBX in Docker Did Not Remove the Networking
Containerizing a SIP service added another address and NAT boundary, which made port publishing, advertised addresses and RTP ranges more important rather than less important.
Containerizing a SIP service added another address and NAT boundary, which made port publishing, advertised addresses and RTP ranges more important rather than less important.
A production-engineering deep dive into thermals on a 2014 mac mini are a production signal, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
A topology view should consume routing state rather than infer a gateway from labels or layout.
A production-engineering deep dive into linux psi changed how i think about saturation, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
Free-space graphs can remain green while a workload creates huge numbers of tiny files and consumes the available inode table.
Some periods looked acceptable in average CPU and RAM graphs while interactive services still felt slow.
Swap is sometimes treated as a direct replacement for RAM, but memory moved to storage has to be read back when active work needs it again. Swap creates room while introducing a time cost.
A production-engineering deep dive into disk throughput is not disk latency, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
`dig` gave me a way to separate resolver configuration, authoritative answers, record types and response timing instead of reducing DNS to 'name works' or 'name fails'.
Repeated sudo failures may be operator error, expired credentials or suspicious privilege-escalation attempts, and they often happen outside application logs.
The strictest-looking file mode is not automatically the safest usable mode when a non-root service must read the key.
Ubuntu 18.04 was a good excuse to stop relying on desktop network icons and start reading interface state, routes, sockets and DNS configuration directly from the system.
Dashboards improved once I stopped collecting attractive metrics and started collecting evidence for specific failure modes.
A few megabytes of swap on an old Linux host did not automatically mean an incident, especially after long uptime.
A production-engineering deep dive into why i monitor memavailable instead of “free ram”, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
I can send SSH packets over the tailnet without asking Tailscale to become the SSH authentication system.
A load average of four means something very different on a two-core system than on an eight-core system.
A protected parent directory can block a perfectly readable child file because directory execute controls traversal.
The host looked busy enough that a simple percentage could easily become the whole diagnosis, but Linux memory reclaim makes that misleading.
On Linux, a high used-memory number does not automatically mean the system is under pressure. Cache consumes memory too and can often be reclaimed. A full-looking memory graph and work actually stalling for memory are different events.
One reason I like Linux is that its parts can be followed. Behind a command, you can trace processes, files, permissions, and network relationships. You do not need to understand everything at once for the larger system to start opening up.
Container networking stopped feeling magical when I separated host routing, bridge interfaces, NAT and the application socket.
Service state, bind failures and restart loops often explained a broken PBX before I needed to inspect a single SIP packet.
A production-engineering deep dive into load average without cpu count is almost meaningless, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
Stopping a service now, preventing automatic startup at boot, and making the service impossible to start are different operational intentions. systemd's stop, disable, and mask reflect those distinctions.
A production-engineering deep dive into clock synchronization is an availability dependency, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
Once I started reading Linux routes as prefix decisions instead of interface settings, multi-interface hosts and lab gateways became much easier to debug.
A production-engineering deep dive into monitoring tcp retransmission on a server that also runs voip, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
A production-engineering deep dive into swap usage alone is a bad memory alert, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
A useful home lab does not need enterprise hardware. A spare PC, a small switch and a few isolated network experiments are enough to learn a lot about real interfaces, routes and services.
Before opening a full packet capture, sngrep gave me a quick view of call legs, response codes and dialog timing directly on the server.
A production-engineering deep dive into disk full and inodes full are two different outages, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
A file can have the right contents and still be unusable when directory traversal or group permissions are wrong.
A device at high utilization can be handling work efficiently, while a lower-utilization device can still be returning slow requests.
The verifier proves classes of memory and control-flow safety. It does not prove that returning the wrong XDP action, updating the wrong map, or attaching at the wrong hook will preserve network connectivity.
The host can show modest megabytes per second while applications still wait because each storage request takes too long.
Moving from local console access to SSH keys changed the lab from a collection of machines into something I could actually operate and troubleshoot remotely.
The host can report high CPU usage even when the useful question is whether time is going to user work, system work, steal, or I/O wait.
A service can be allowed through one protected directory without being allowed to inspect the directory itself.
Stopping only the shell does not necessarily stop pg_dump, tar or helper processes that the shell launched.
On a headless Linux box, tcpdump was faster than moving captures around blindly. A narrow capture at the right interface often answered the question immediately.
A rising established-connection count can represent normal load, a leak, slow clients or a downstream dependency holding sockets open.
Joining a machine is easy; making its identity, hostname, access and role predictable is the part that matters later.
On a headless PBX, a narrow tcpdump capture often answered the important question faster than a full GUI trace: did the signaling or media packet actually reach the server?
A production-engineering deep dive into page cache is not a memory leak, grounded in the 2014 Mac mini hserver observability stack and its accepted runtime evidence.
CPU percentage alone did not reveal when the kernel was spending more work scheduling tasks or servicing device activity.