Files
it-knowledge/src/solutions/service-management.md
T

6.1 KiB

Service Management Solutions [⚙️]

This section documents my solutions to service management scenarios, including systemd services, process management, and service configuration.

Scenario Tags

Tag Description
[v1-S3] Service and Security Management - Practice Scenarios v1
[v2-S3] Process and Service Management - Practice Scenarios v2
[v3-S9] Service Management and Monitoring - Practice Scenarios v3

Scenario: [v1-S3] Web Server Configuration

Original Problem

[To be filled with actual scenario]

Environment

  • OS Version: RHEL/Rocky Linux
  • Initial State: [Initial service state]
  • Required Outcome: [Desired service configuration]

Solution Steps

  1. Install and Enable Service

    # Install service
    sudo dnf install httpd
    
    # Enable and start service
    sudo systemctl enable --now httpd
    

    [Explanation of installation]

  2. Configure Service

    # Configuration commands
    sudo vi /etc/httpd/conf/httpd.conf
    

    [Explanation of configuration]

  3. Manage Service State

    # Restart service
    sudo systemctl restart httpd
    
    # Check status
    sudo systemctl status httpd
    

    [Explanation of management]

Verification

# Check service status
systemctl status httpd

# Check port listening
ss -tunlp | grep httpd

# Test service
curl localhost

Key Learnings

  • Understanding of systemd
  • Service configuration best practices
  • Troubleshooting methodology

Skills Demonstrated

  • Service Management
  • Process Control
  • Log Analysis
  • Security Configuration


Scenario: [v1-S3] Time Synchronization and Security Configuration

Original Problem

  • Configure chronyd to sync with time server 'time.example.com'
  • Configure firewall to allow HTTP (port 80) and HTTPS (port 443)
  • Create an SELinux policy to allow Apache to listen on port 8080
  • Configure SSH to disable root login and only allow key-based authentication
  • Set up a cron job to run system updates every Sunday at 2 AM

Environment

  • OS Version: RHEL/Rocky Linux
  • Initial State: Default installation without time sync or security configurations
  • Required Outcome: Properly configured time synchronization, firewall, SELinux, SSH, and automated updates

Solution Steps

  1. Configure chronyd to sync with time server 'time.example.com'

    # Install chrony
    sudo dnf install chrony
    
    # Configure chronyd to sync with time server 'time.example.com'
    sudo vi /etc/chrony.conf
    
    # Add the following line to the file
    server time.example.com iburst
    
    # Save and exit
    :wq
    
    # Enable and start service
    sudo systemctl enable chronyd
    sudo systemctl start chronyd
    sudo systemctl status chronyd
    

    The output should show the chrony service enabled and running

  2. Configure firewall to allow HTTP (port 80) and HTTPS (port 443)

    # Install firewalld
    sudo dnf install firewalld
    
    # Enable and start firewalld
    sudo systemctl enable --now firewalld
    
    # Configure firewall to allow HTTP (port 80) and HTTPS (port 443)
    sudo firewall-cmd --add-service=http --permanent
    sudo firewall-cmd --add-service=https --permanent
    

    The output should show the firewall rules added

  3. Create an SELinux policy to allow Apache to listen on port 8080

    # Install policycoreutils
    sudo dnf install policycoreutils
    
    # Create an SELinux policy to allow Apache to listen on port 8080
    sudo semanage port -a -t http_port_t -p tcp 8080
    

    The output should show the SELinux policy created

  4. Configure SSH to disable root login and only allow key-based authentication

    # Configure SSH to disable root login and only allow key-based authentication
    sudo vi /etc/ssh/sshd_config
    
    # Disable root login
    PermitRootLogin no
    
    # Allow key-based authentication
    PubkeyAuthentication yes
    
    # Save and exit
    :wq
    
    # Restart SSH service
    sudo systemctl restart sshd
    

    The output should show the SSH configuration updated

  5. Set up a cron job to run system updates every Sunday at 2 AM

    # Set up a cron job to run system updates every Sunday at 2 AM
    sudo crontab -e
    
    # Add the following line to the file
    0 2 * * 0 sudo dnf update
    
    # Save and exit
    :wq
    
    # Check status of cron service
    sudo systemctl status cron
    

    The output should show the cron job added

Verification

# Check chrony status
sudo systemctl status chronyd

# Check firewall status
sudo firewall-cmd --list-all

# Check SELinux status
sudo getenforce

# Check SSH status
sudo systemctl status sshd

# Check cron status
sudo systemctl status cron

Key Learnings

  • Understanding of systemd
  • Understanding of SELinux
  • Understanding of SSH
  • Understanding of cron
  • Understanding of firewall
  • Understanding of time synchronization

Skills Demonstrated

  • Service Management
  • SELinux Management
  • SSH Configuration
  • Cron Job Management
  • Firewall Configuration
  • Time Synchronization

Scenario: [v2-S3] Process and Service Management

Original Problem

From Practice Scenarios v2, Scenario 3:

  1. Configure system to start in graphical.target
  2. Set up Apache web server to start at boot
  3. Create a systemd service for a custom application
  4. Configure process nice levels for specific applications
  5. Set up logging rotation for application logs
  6. Configure journald for persistent logging

Environment

  • OS Version: [To be filled]
  • Initial State: [To be filled]
  • Required Outcome: [To be filled]

Solution Steps

[Your solution will be added here]

Scenario: [v3-S9] Service Management and Monitoring

Original Problem

From Practice Scenarios v3, Scenario 9:

  1. Configure systemd services with:
    • Dependencies
    • Custom environment files
    • Restart policies
  2. Set up service monitoring with:
    • Custom status checks
    • Email notifications
    • Automatic recovery
  3. Implement logging with:
    • Remote syslog
    • Custom journald configuration
    • Log forwarding

Environment

  • OS Version: [To be filled]
  • Initial State: [To be filled]
  • Required Outcome: [To be filled]

Solution Steps

[Your solution will be added here]