SOLUTIONz
A Solution is one complete system that I designed, built and ran, written up from the original design documents and working notes. The notes and howtos elsewhere on this site each answer one question; a Solution shows how the answers fit together when the thing has to stay up.
Every Solution is told the same way: why it was built, how it was designed, how each part was configured, and how it was operated. The configuration files are not pasted into the articles. Each one is a document of its own, commented, and linked from the article that explains it.
The Solutions
| Solution | Built | What it is |
|---|---|---|
| HashiCorp Vault | 2021-2024 | Secrets management for a multi-tenant service platform: three Vault clusters on Integrated Storage, Transit auto-unseal, HAProxy and Keepalived, AppRole, audit logging, snapshots to object storage |
| NetApp MetroCluster | 2017-2019 | Primary storage for a management infrastructure in two sites: fabric-attached MetroCluster of FAS8200 pairs, Brocade fabrics and ATTO bridges, NFS for KVM, volume encryption, Active Directory logins, Unified Manager, Tiebreaker, upgrades and troubleshooting |
| Email system on Postfix | 2017-2019 | Mail for the servers, applications and appliances of a management infrastructure in two sites: an SMTP pair behind a Keepalived address, senders authorized by Active Directory groups, a Bash content filter that encrypts every message with S/MIME or PGP/MIME, relays to the internet, mailboxes on Dovecot and Roundcube webmail |
How to read one
Start at the Solution's own page. It lists the articles in the order the system was built, and every configuration file with the article that explains it.
Each configuration file is shown as it ran, and followed by a section that checks it against the current release of the software. Where the two differ, the file stays as it was and the section says what to do today.