6.1 KiB
Service Management Solutions [⚙️]
This section documents my solutions to service management scenarios, including systemd services, process management, and service configuration.
Scenario Tags
| Tag | Description |
|---|---|
| [v1-S3] | Service and Security Management - Practice Scenarios v1 |
| [v2-S3] | Process and Service Management - Practice Scenarios v2 |
| [v3-S9] | Service Management and Monitoring - Practice Scenarios v3 |
Scenario: [v1-S3] Web Server Configuration
Original Problem
[To be filled with actual scenario]
Environment
- OS Version: RHEL/Rocky Linux
- Initial State: [Initial service state]
- Required Outcome: [Desired service configuration]
Solution Steps
-
Install and Enable Service
# Install service sudo dnf install httpd # Enable and start service sudo systemctl enable --now httpd[Explanation of installation]
-
Configure Service
# Configuration commands sudo vi /etc/httpd/conf/httpd.conf[Explanation of configuration]
-
Manage Service State
# Restart service sudo systemctl restart httpd # Check status sudo systemctl status httpd[Explanation of management]
Verification
# Check service status
systemctl status httpd
# Check port listening
ss -tunlp | grep httpd
# Test service
curl localhost
Key Learnings
- Understanding of systemd
- Service configuration best practices
- Troubleshooting methodology
Skills Demonstrated
- Service Management
- Process Control
- Log Analysis
- Security Configuration
Scenario: [v1-S3] Time Synchronization and Security Configuration
Original Problem
- Configure chronyd to sync with time server 'time.example.com'
- Configure firewall to allow HTTP (port 80) and HTTPS (port 443)
- Create an SELinux policy to allow Apache to listen on port 8080
- Configure SSH to disable root login and only allow key-based authentication
- Set up a cron job to run system updates every Sunday at 2 AM
Environment
- OS Version: RHEL/Rocky Linux
- Initial State: Default installation without time sync or security configurations
- Required Outcome: Properly configured time synchronization, firewall, SELinux, SSH, and automated updates
Solution Steps
-
Configure chronyd to sync with time server 'time.example.com'
# Install chrony sudo dnf install chrony # Configure chronyd to sync with time server 'time.example.com' sudo vi /etc/chrony.conf # Add the following line to the file server time.example.com iburst # Save and exit :wq # Enable and start service sudo systemctl enable chronyd sudo systemctl start chronyd sudo systemctl status chronydThe output should show the chrony service enabled and running
-
Configure firewall to allow HTTP (port 80) and HTTPS (port 443)
# Install firewalld sudo dnf install firewalld # Enable and start firewalld sudo systemctl enable --now firewalld # Configure firewall to allow HTTP (port 80) and HTTPS (port 443) sudo firewall-cmd --add-service=http --permanent sudo firewall-cmd --add-service=https --permanentThe output should show the firewall rules added
-
Create an SELinux policy to allow Apache to listen on port 8080
# Install policycoreutils sudo dnf install policycoreutils # Create an SELinux policy to allow Apache to listen on port 8080 sudo semanage port -a -t http_port_t -p tcp 8080The output should show the SELinux policy created
-
Configure SSH to disable root login and only allow key-based authentication
# Configure SSH to disable root login and only allow key-based authentication sudo vi /etc/ssh/sshd_config # Disable root login PermitRootLogin no # Allow key-based authentication PubkeyAuthentication yes # Save and exit :wq # Restart SSH service sudo systemctl restart sshdThe output should show the SSH configuration updated
-
Set up a cron job to run system updates every Sunday at 2 AM
# Set up a cron job to run system updates every Sunday at 2 AM sudo crontab -e # Add the following line to the file 0 2 * * 0 sudo dnf update # Save and exit :wq # Check status of cron service sudo systemctl status cronThe output should show the cron job added
Verification
# Check chrony status
sudo systemctl status chronyd
# Check firewall status
sudo firewall-cmd --list-all
# Check SELinux status
sudo getenforce
# Check SSH status
sudo systemctl status sshd
# Check cron status
sudo systemctl status cron
Key Learnings
- Understanding of systemd
- Understanding of SELinux
- Understanding of SSH
- Understanding of cron
- Understanding of firewall
- Understanding of time synchronization
Skills Demonstrated
- Service Management
- SELinux Management
- SSH Configuration
- Cron Job Management
- Firewall Configuration
- Time Synchronization
Scenario: [v2-S3] Process and Service Management
Original Problem
From Practice Scenarios v2, Scenario 3:
- Configure system to start in graphical.target
- Set up Apache web server to start at boot
- Create a systemd service for a custom application
- Configure process nice levels for specific applications
- Set up logging rotation for application logs
- Configure journald for persistent logging
Environment
- OS Version: [To be filled]
- Initial State: [To be filled]
- Required Outcome: [To be filled]
Solution Steps
[Your solution will be added here]
Scenario: [v3-S9] Service Management and Monitoring
Original Problem
From Practice Scenarios v3, Scenario 9:
- Configure systemd services with:
- Dependencies
- Custom environment files
- Restart policies
- Set up service monitoring with:
- Custom status checks
- Email notifications
- Automatic recovery
- Implement logging with:
- Remote syslog
- Custom journald configuration
- Log forwarding
Environment
- OS Version: [To be filled]
- Initial State: [To be filled]
- Required Outcome: [To be filled]
Solution Steps
[Your solution will be added here]