Hosting services is much more fun when we can be sure that malfunction of a single disk won't shut down services and cause data loss. FreeBSD Handbook has a chapter about Creating a Mirror with Two New Disks, but it suggests some outdated practices such as legacy BIOS boot and MBR partitioning s...
I had a situation where zpool on external USB disk would not get imported automatically at boot time. but manual zpool import extwd worked fine. I guessed rc script which imports known zpools at boot time runs before USB disk gets attached, so I looked for mechanism which would trigger import on attach. In FreeBSD this can be done with devd - device state change daemon.
I have recently moved my MX server to a new IPv4 address. Admittedly, new IPv4 address is in quite bad neighbourhood, a residential /24 pool provided by ISP who doesn't filter outgoing SMTP by default. Most other IPv4 addresses in this pool have quite poor reputation, probably without their users even knowing their malware infested devices are being used to send spam. It took less than a week since I took over this new IPv4 for it to get dropped from most of lists such as spamhaus which actively monitor and list spamming IP addresses, delisting them automatically when spamming stops.
Having broadband access to the Internet is ubiquitous in most households in Europe. The setup usually comprises of a device provided by ISP (Internet Service Provider) - commonly known as router - which connects to ISP's infrastructure over fiber or coaxial cable, and provides Internet connectivity to devices on home LAN (Local Area Network) connected to it. A router usually provides a few LAN ports for plugging wired devices such as desktop computers, as well as WiFi network to which wireless devices such as laptops, tablets, mobile phones, and increasing number of other types of appliances connect by means of selecting provided WiFi network and typing in its password. Once connected, one can browse webpages, engage in social networking, send and receive emails, watch movies and listen to music on various streaming platforms, play online games, chat by means of text messages, audio or video calls, do online shopping or banking or any of other things that people usually do "on the Internet". Most people can't be bothered to try to understand actual mechanisms which give them access to the "Internet". Recently, however, I have noticed that more and more people around me begin to understand that Internet isn't just a thing they access and use. They start to intuitively feel that Internet is also accessing and using them, sometimes to their disadvantage, and they start to ask me how it does that and how can it be prevented. Answers to those questions exist, and are quite exact, but they require quite a bit of reading and understanding. The following article tries to explain most basic terminology of home networks.
Now that we have secured our FreeBSD system, as well as our data partitions - both UFS and ZFS - from unavailability caused by disk failures, we will prepare it for its role of jail host. This requires reconfiguration of services that bind to all available interfaces to bind to specific interfaces instead. Jail manpage's section about setting up the host environment gives general guidelines, but it mentions services which are usually not enabled by default on contemporary FreeBSD versions (sendmail, inetd and rpcbind), while it does not mention services which are (ssh, ntp and syslog). This article gives instruction on how to bind sshd, ntpd and syslogd to specific interfaces, as well on how to create additional loopback interface. Finally we will modify hosts file.
In two previous articles we installed FreeBSD onto mirrored pair of disks as well as additional mirror for UFS data partition. gmirror and UFS are mature technologies which are quite stable and efficient, but lack some functionalities expected from modern filesystems. That's where ZFS comes into play. According to FreeBSD Handbook, ZFS is an advanced file system designed to solve major problems found in previous storage subsystem software. More than a file system, ZFS is fundamentally different from traditional file systems. Combining the traditionally separate roles of volume manager and file system provides ZFS with unique advantages. This article assumes FreeBSD has already been installed onto mirrored pair of disks and UFS data partition has already been added. We will now add RAIDZ volume consisting of four SATA disks which can survive failure of one of the disks. Write performance will be increasing by configuring two NVMe disks for ZIL (ZFS Intention Log), while read performance will be increased by adding single NVMe disk for Cache.
In another article we installed FreeBSD onto mirrored pair of disks. We intentionally used fairly small but very fast nvme disks so that our FreeBSD setup works as fast as possible. However, we wouldn't be able to fit much services onto such small storage. Good news is we shouldn't. There are many reasons to put data on separate partition, or - even better - on separate disk(s). First and foremost, exhausting free space on / could crash complete system, while filling up /var could disable syslog functionality. On busy servers which need a lot of disk IOPS and bandwidth it is good to ensure that basic OS functionality won't be slowed down by greedy services from disk IOPS and bandwidth point of view. This article builds upon mentioned article and describes how to make anothergmirror volume from two SATA disks, format it as UFS and mount it under /ufsdata partition.