RSSAmplifier

Blog

(Fabio Alessandro Locati|Fale)'s blog

Recent content on (Fabio Alessandro Locati|Fale)'s blog

fale.ioRSS feed ↗243 posts

Latest posts

Red Hat EX467 exam

Last Friday, I renewed my Red Hat Certified Specialist in Managing Automation with Ansible Automation Platform (EX467) certification. As I’m already a Red Hat Certified Architect and have passed this same exam about three years ago , I wasn’t too worried about it. The exam still focuses on leveraging the Ansible Automation Platform in enterprise environments rather than writing Ansible…

On Podman 6 and weeding out legacy

Podman 6.0 was released yesterday. This is a fairly big and important release, since they removed the support for cgroups v1, iptables, CNI, slirp4netns, and BoltDB. All features that depend on those dependencies have not been dropped; they are only supporting the modern replacements that have been available and the defaults for a while. In fact, they are now provided by cgroups v2, nftables,…

Btrfs scare

Last weekend, I updated and rebooted the system, but it did not come back online. Checking with IPMI revealed that the ata-2 disk was not responding to the operating system, preventing a clean mount of the Btrfs filesystem and halting the system from completing the boot sequence. My Btrfs array is composed of 6 SSD disks, all with different ages, except for the first two, which arrived together at…

Fedora 44 released

Three days ago, the Fedora project released Fedora 44. This release was delayed a couple of times due to an issue with the NVIDIA driver and installer. Since neither of those was relevant to me, I was not blocked by that. I appreciate that Fedora caters to many different kinds of users and use cases, and therefore, there might be delays for reasons that do not affect me. I’ve used Fedora 44…

On the value of an automation platform

Over the last 20+ years in IT, I’ve seen automation evolve from a nice-to-have to a non-negotiable part of how organizations operate. Every company I’ve worked with has some form of automation. The problem is that, in many cases, what they have is not an automation strategy but rather a collection of individual scripts, cron jobs, and one-off solutions that were built to solve…

On the importance of thought leadership

Over the last 20+ years in IT, I’ve been lucky enough to work across many roles and industries. In that time, I’ve always found that the work we do, and that we’re measured against, is only one side of the story. The other side, and often the most important one, is the work we share: the ideas, the rationale, the reasoning, the reflections that shape how others think. That is…

Red Hat Certified Specialist in Containers

Yesterday, I passed the Red Hat EX188 exam , which allowed me to renew my Red Hat Certified Specialist in Containers certification. I had a very good memory of this exam from the last time I took it, so I was happy to go through it again. Different from last time, I did encounter some difficulties with the last exercise, which was a little surprising to me, since the last time I found it testing…

KNX with HTTP API

After a few years of experimenting, I moved forward with a full electrical system rewiring in my house earlier this year, opting for a KNX-based design. One of the aspects I really like about KNX is that it is a brand-agnostic protocol, which makes it very easy to find any kind of object compatible with it. Another aspect that KNX has, different from many other options, is that it is it bus based.…

Red Hat EX374 exam

Earlier this month, I sat the Red Hat EX374 exam to renew my Red Hat Certified Specialist in Developing Automation with Ansible Automation Platform certification. As I’m already a Red Hat Certified Architect and have passed this same exam a couple of years ago, I wasn’t too worried about it. Still, it is always interesting to see how exams evolve. When I registered for the exam, I quickly checked…

AWS SSA-C03 exam

Three years passed from the last AWS exam I took, and my AWS certifications were due for renewal. The first thing I checked was the exam code, which I had taken three years ago. It turns out that last time I took the SAA-C03 , and this time I would also have taken the same exam. This time around, I considered doing the SAP-C02 instead, but, given the very limited time, I decided on the SAA-C03 .

Moving out of AWS

For years, I hosted this blog and several other services on AWS. AWS is powerful, but it is also expensive and deeply entropic. It often feels like every problem on AWS has three different services as possible solutions. Each service has its own setup, and keeping track of everything just gets harder over time. For personal infrastructure, the financial and cognitive cost simply stopped being…

Red Hat EX457 exam

Last week, I renewed my Red Hat Certified Specialist in Ansible Network Automation (EX457) certification. As I’m already a Red Hat Certified Architect and have passed this same exam a couple of years ago, I wasn’t too worried about it. Still, it is always interesting to see how exams evolve. Since I did not remember the kind of content that was there last time, I read the objectives…

Google Professional Cloud Architect

At this point, it has become kind of a ritual for me: renewing my Google Professional Architect Certification during the summer months. This time around, I renewed it slightly earlier than usual, which is today instead of the second half of August, as I did two years back . Knowing the usual difficulties I have with scheduling the Google Cloud certification renewal exam, I started very early and,…

On your providers business models

When buying a service, you’re not just buying what’s on the label. You’re buying into someone else’s business model. This aspect is now becoming even more relevant, considering that many times, when buying a product, you are also buying a service with it since there are more and more hybrid products. If you don’t understand how your provider is structured and how it…

Upcoming Events: CEC, Flock, and DevConf.cz

In the coming couple of weeks I’ll be heading to the Common Europe Congress (CEC2025), Flock 2025, and DevConf.cz 2025, some of the best community-driven events in the ecosystem. If you’re around, let’s catch up and share stories over coffee! Common Europe Congress 2025 (Gothenburg, June 2–4) The Common Europe Congress is the largest educational convention for IBM Power users in…

Route traffic across Podman networks with Traefik

If you’ve followed my posts over the years, you know I prefer clean solutions to less clean ones for my home lab (more to come on this!). Over the past year, I settled on a pattern that gives me the isolation of Kubernetes Namespaces without any of its weight: one private Podman network per application, plus Traefik in a shared “DMZ” network that terminates TLS and forwards…

Fedora on Scaleway Dedibox with bootc

For a while now, I’ve been looking into optimizing and reorganizing some of the infrastructure that powers my self-hosting services. After evaluating a few alternatives, Scaleway’s Dedibox lineup caught my attention: it is a European company with good hardware and decent pricing. However, as with every good solution, it is not perfect. Scaleway does not provide Fedora as an OS option…

On photographing physical keys

Every one of us probably has some physical keys in our pocket or purse right now. This familiarity with this common object might make us forget about how the security of those objects actually works. I see pictures of keys shared very often in groups or on social media. Sometimes this happens because a set of keys has been found somewhere, and the person uploading the picture is trying to help…

Upcoming Events: CentOS Connect, FOSDEM, and CfgMgmtCamp

The next few days are shaping up to be packed with open-source goodness! I’ll be heading to CentOS Connect, FOSDEM, and CfgMgmtCamp, three of the best events in the ecosystem. These conferences always include a great mix of technical talks, hallway conversations, and spontaneous meetups with friends—both old and new. If you’re around, let’s catch up! CentOS Connect (Brussels,…

A bad year for open source databases

Although the definitions of Open Source are related to specific software characteristics (i.e., the license), the reality is much more complex. Open-source is way more related to a social contract that the software’s creator and its users morally sign than the definition might lead you to believe. This social contract’s key aspect concerns the software’s current license and the…

Hyperscalers are not serious about Service Level Agreements (SLA)

I often talk with people about Service Level Agreements (SLAs) in public cloud contexts, and I discover that their idea of what those SLAs are is often distorted. I believe SLAs need to be approached with a healthy dose of skepticism. In reality, they often provide little meaningful recourse when things go awry. There are two big issues, in my opinion, with the SLA provided by many companies,…

Nebula VPN split configuration

We have had Nebula VPN within the Fedora repositories for a couple of years. A couple of months ago, I changed the default systemd service unit. More specifically, this is the change: -ExecStart=/usr/bin/nebula -config /etc/nebula/config.yml +ExecStart=/usr/bin/nebula -config /etc/nebula Although the change is only a few characters, this change allows for a much more flexible use of Nebula. Before…

On being the cheapest cloud

Recently, I heard a pitch from a public cloud company. Among other characteristics, a key aspect they stressed is that they are the cheapest cloud. This aspect struck me. Not because I believe it is or is not, but because I’ve heard many companies pitch themselves as the cheapest cloud over the years. I asked the CTO if they were foreseeing consistent and planned cuts in the pricing every…

On Out of Office emails

This summer, I found myself multiple times reading out-of-office emails. Actually, this is not a new phenomenon: it has happened every summer since I started working. Obviously, it also happens outside the summer, but it is far easier to notice it during the summer. I think the majority of people should not configure an out-of-office replyer. By recipient Many people might write to you and receive…

On software versioning schema

Last month, the Ansible Forum had a discussion about potential changes that might be implemented in AWX. One aspect that immediately hit me was the decision to move from SemVer to CalVer . More specifically, what struck me was the focus on this change in the initial post and in the comments. Since it took me a while to formulate a whole reasoning behind my perspective, I created this blog post to…

Red Hat Certified Specialist in Services Management and Automation - EX358 Exam

I took the EX358 exam a few years back and therefore it recently expired. Since the exam is still available, I decided to take it again to renew my Red Hat Certified Specialist in Services Management and Automation certification and, therefore, extend my Red Hat Certified Architect certification. This time around, I had the impression that the exam had changed quite a bit from the last time I took…

Perform backups with Systemd

Many strategies can be employed to build resilience in IT systems. Personally, I think one of the most critical yet overlooked ones - both in personal and corporate settings - is backups. I recently had to back up a folder containing the state of a service running on a Fedora machine. As often happens, an interesting aspect of this service is that the backups are consistent and, therefore,…

Forward all your traffic with RedSocks

VPNs can be used in different ways based on the desired objective. If the goal is to reach some specific web pages served only within a network, using a proxy will probably do the trick. Another common use for VPNs is to ensure the confidentiality of data transferred between a remote system and a safe site. In this case, we might want to ensure that all traffic from the remote system reaches the…

Use Dante to proxy web traffic

A while ago, I posted about using SSH to proxy traffic within a Nebula network context. In the last few months, I changed my implementation because SSH required some steps and accesses that I was not fully happy with. In the previous iteration, I was using SSH as a SOCKS proxy. The problem, though, is that I need to set up the connection every time and use my SSH credentials, so it becomes…

Please stop using VPN services for privacy!

For many years, VPN companies have advertised their VPNs as a necessary tool for all people who want to preserve their privacy. For the same amount of time, I tried to explain to the people that this view made no sense if not for those company’s sales. As an example, Onavo , a Meta subsidiary, used to advertise its services, highlighting that, among other advantages, using their product…

Build and publish multi-arch containers with Quay and GitHub Actions

When I deploy a system, I always try to automate it fully. There are many reasons for this, one of which is that, in this way, the automation becomes the documentation for the system itself. Another reason that drives me to automate everything is my preference for clean systems. Another consequence of this preference I have is that in the last few years, I’ve moved many systems to a Fedora…

Share volumes between Podman Systemd services

Since the merge of Quadlet in Podman, I’ve been moving multiple services to Podman Systemd services. I find them to be easy to create, manage, and automate. I recently migrated a complex system to Podman Systemd, where multiple processes write in a folder, and one process reads the folder’s content. Before the migration, everything worked properly since all the processes were running…

On the nature of the right to privacy

In the last month, Meta has started to give their European users a choice between an account for their services paid in data or one paid in Euros. Today, noyb has filed a GDPR complaint against Meta over this behavior. Noyb has very good points to sustain their filing, but I don’t want to delve too much into those since those are very well explained in their press release. I think there is a…

Fedora CoreOS on Hetzner Dedicated server

Over the last few years, I’ve moved many of my systems to Immutable versions of Fedora. One of the last systems still missing was my Hetzner Dedicated server. The blocking part for me was that Hetzner is not offering any Fedora or Immutable options. However, Hetzner provides the Rescue System, which is a Debian system, so it is possible to leverage it! After rebooting in Rescue mode: Go to…

Google Professional Cloud Architect

As it happens every couple of years, my Google Cloud Certifications were up for renewal at the end of August. I started to look for possible exam dates at the beginning of June since it is possible to renew Google Cloud exams only from the 60th day before the expiration to the 30th day after the expiration date. Since the system informed me that I was outside the 60-day window, I assumed I had to…

Practical Ansible - Second Edition

Ansible empowers you to automate a myriad of tasks, including software provisioning, configuration management, infrastructure deployment, and application rollouts. It can be used as a deployment tool as well as an orchestration tool. While Ansible provides simple yet powerful features to automate multi-layer environments using agentless communication, it can also solve other critical IT…

Use per-host SSH key pairs on AWX and Ansible Automation Controller

One of the aspects that I have always loved about Ansible is that it integrates very nicely with the rest of the system where it is running. For example, you can easily configure all the SSH configurations directly by changing the ~/.ssh/config file. I’ve seen multiple cases where the SSH configuration file needs to be tweaked. A case that comes up occasionally is an environment configured…

Red Hat Certified Specialist in Managing Automation with Ansible Automation Platform

A few weeks ago, I passed the Red Hat EX467 exam , which allowed me to become Red Hat Certified Specialist in Managing Automation with Ansible Automation Platform. As of today, this is the newest Red Hat exam on Ansible. You can notice this from the version of Ansible Automated Platform that this exam uses: 2.2. An aspect that is already clear by looking at the objective is that this exam is…

Implement WebFinger with AWS CloudFront and AWS Lambda

This website is hosted on AWS S3 and uses AWS CloudFront as CDN. I use a couple of AWS Lambda@Edge functions to make AWS CloudFront a little brighter. When I decided to self-host a Fediverse instance, it became immediately evident that I would have to set up WebFinger on my domain to be able to use my root domain as the account domain. There is documentation on the web on how to set up WebFinger,…

Why do Kubernetes Control Planes have an odd number of members?

The single most frequent question I get asked about Kubernetes is regarding the number of Control Plane nodes. Sometimes it is out of curiosity for the “unusual number”; other times, it is plainly confrontational since the person would prefer a different number, which usually is 2. The first thing to understand is that there are a couple of reasons to choose a certain number of…

Fedora on Pine64 ROCKPro64

Recently, I was looking for a couple of Single Board Computers (SBCs) for a project I’m working on. Given the characteristics I was looking for, there were not many options; in the end, I opted for the ROCKPro64 by Pine64. Once I received the SBC, I immediately tried to put Fedora on it. The process proved slightly more complex than I was expecting since I assumed that U-Boot (or some other…

EU EDPB vs. Irish DPC vs. Meta Platforms

The Irish Data Protection Commission (DPC) has evaluated the legality of Facebook’s (now Meta Platforms) data transfer for over 10 years. In those 10 years, we have seen the Irish DPC trying to avoid ruling on the matter multiple times and the European Data Protection Board (EDPB) forcing them to do it. We now have a final ruling on the matter, which is unfavorable to Meta. In fact, in…

Manage Podman containers with Systemd and Quadlet

Until a few months ago, the only option to start containers from Systemd was to create a Systemd unit which called podman (or docker ) with the run sub-command. Podman was also providing podman generate systemd to easily create such Systemd file. This has now changed. From version 4.4 of Podman, in addition to the mentioned method, it is possible to use Quadlet to simplify the execution of…

Fedora Sericea and Sway Spin released!

With Fedora 38 officially released , Sericea and Sway Spin have also been officially released! In the last month, I’ve been working on those variants’ presence on the Fedora website. Now both variants have their page on the Fedora Website respectively at Sericea and Sway Spin . If you have any questions, reach the Sway SIG in the following ways: Sway SIG mailing list . Sway SIG Matrix…

GitHub Actions and containers

GitHub Actions allows the use of containers with different Operating Systems. Although, it does not mean that everything is seamless when you are using them. I’ve discovered this the hard way! Below are my findings and the process I followed to make the GitHub Action pipeline work properly with containers. It all started with the addition of a new tool in the pipeline, which was not…

Fedora Sericea and Sway Spin beta

The Fedora Project released Fedora 38 beta images. The Fedora Sway Spin and the Fedora Sericea ones are in the long list of released images! This is a critical point in the release of those Fedora artifacts based on Sway since it is the first time it has been possible to test them for the wider public. Although the Fedora Project has been creating Sway artifacts for a couple of months, those were…

MACCHIATObin boot on serial port

I bought a MACCHIATObin Single Shot a few months ago with the idea of creating a NAS out of it. The results have been very good and, to begin in an easy way, I decided to install Fedora 37 Server Edition. Now that I’ve decided exactly what I want out of it, I reinstalled Fedora and started from scratch with exactly what I wanted. I decided to install Fedora 37 IoT, which is an rpm-ostree…

Red Hat Certified Specialist in Containers

Last week, I completed the Red Hat EX188 exam , which allowed me to become Red Hat Certified Specialist in Containers. I think that Red Hat has been able to improve the quality of its exams over time. Newer exams tend to have better explanations of the required tasks. It could also be that this feeling is partially due to my increasing familiarity with those kinds of exercises. This exam is very…

Podman ports and firewalld

A few weeks ago, I was doing a security check on one of my machines to ensure that everything was secure when I noticed that there were some ports open that I was surprised to find out. The way I discovered those ports was by checking some ports with netcat ( nc -zv IP_ADDRESS PORT ). I was expecting those ports to be closed, and I got surprised when netcat claimed to be able to connect to them.

Fedora Sway artifacts approved by FESCo

Back in August, I asked for suggestions for a name for an os-tree-based Fedora version with Sway. Although I’ve not posted anything more on the topic, the work went forward. We have asked Fedora Council to approve the naming, to FESCo for the approval for the change to Fedora, and to RelEng support to merge our work in the Fedora workstream. A couple of weeks ago, the Fedora Council approved…