@NotRealZeyad said:
Why when I connect it says potential security breach
Cause the server was wiped and OS was reinstalled, so the server signature changed. Yes, your data is gone. No, you are requried to keep own backups.
@Nubuki said:
I agree with the formulation of rules based on what is allowed and what isn't, a telegram chat group, the open source restrictions (though I'm not really sure how to approach that).
The server itself is free and open to people. So having a small limitations like only open source is a good thing. You can always get a server from hetzner and do what you want on it
@Nubuki said:
Also isn't there a way to limit the amount of cpu/ amount of time a large amount of CPU can be used by a shared user?
No, because he isn't using any panels. So there is no monitoring going on. Only limitations are number of cores and max amount of RAM, which @Not_Oles isn't willing to enforce.
I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.
@NotRealZeyad said:
Why when I connect it says potential security breach
Cause the server was wiped and OS was reinstalled, so the server signature changed. Yes, your data is gone. No, you are requried to keep own backups.
@Nubuki said:
I agree with the formulation of rules based on what is allowed and what isn't, a telegram chat group, the open source restrictions (though I'm not really sure how to approach that).
The server itself is free and open to people. So having a small limitations like only open source is a good thing. You can always get a server from hetzner and do what you want on it
@Nubuki said:
Also isn't there a way to limit the amount of cpu/ amount of time a large amount of CPU can be used by a shared user?
No, because he isn't using any panels. So there is no monitoring going on. Only limitations are number of cores and max amount of RAM, which @Not_Oles isn't willing to enforce.
@NotRealZeyad said:
Why when I connect it says potential security breach
Cause the server was wiped and OS was reinstalled, so the server signature changed. Yes, your data is gone. No, you are requried to keep own backups.
@Nubuki said:
I agree with the formulation of rules based on what is allowed and what isn't, a telegram chat group, the open source restrictions (though I'm not really sure how to approach that).
The server itself is free and open to people. So having a small limitations like only open source is a good thing. You can always get a server from hetzner and do what you want on it
@Nubuki said:
Also isn't there a way to limit the amount of cpu/ amount of time a large amount of CPU can be used by a shared user?
No, because he isn't using any panels. So there is no monitoring going on. Only limitations are number of cores and max amount of RAM, which @Not_Oles isn't willing to enforce.
Thanks
FYI, you can always just click the tanks button bellow the username instead of a comment to just say thanks. Ofcourse it's ok to comment if you have some other comments or questions
I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.
Yep, postponing membership is necessary. It takes time to implement security measures and observe and consider users. In short, I believe there is no rush to open membership.🤔
@NotRealZeyad said:
Why when I connect it says potential security breach
Cause the server was wiped and OS was reinstalled, so the server signature changed. Yes, your data is gone. No, you are requried to keep own backups.
@Nubuki said:
I agree with the formulation of rules based on what is allowed and what isn't, a telegram chat group, the open source restrictions (though I'm not really sure how to approach that).
The server itself is free and open to people. So having a small limitations like only open source is a good thing. You can always get a server from hetzner and do what you want on it
I'm actually not disputing this,
In case it wasn't really clear I just wasn't clear if open Source here meant running only Linux kvms , running open source code and what not.
Can you maybe elaborate what count as open source and what doesn't?
@Nubuki said:
Also isn't there a way to limit the amount of cpu/ amount of time a large amount of CPU can be used by a shared user?
No, because he isn't using any panels. So there is no monitoring going on. Only limitations are number of cores and max amount of RAM, which @Not_Oles isn't willing to enforce.
I assumed that @Not_Oles could have done so by using cpulimit on the QEMU executable, ensure that a login shell is run with nice so that the child processes will inherit the nice value, or limit with cgroups and or probably create a bash script that checks if a process hogging CPU has run for too long.
It's done that way in those rootless tilde servers (I think)
@Nubuki said:
I agree with the formulation of rules based on what is allowed and what isn't, a telegram chat group, the open source restrictions (though I'm not really sure how to approach that).
The server itself is free and open to people. So having a small limitations like only open source is a good thing. You can always get a server from hetzner and do what you want on it
I'm actually not disputing this,
In case it wasn't really clear I just wasn't clear if open Source here meant running only Linux kvms , running open source code and what not.
Can you maybe elaborate what count as open source and what doesn't?
Anything where the source code is readily available to anyone looking for it is open source. Yes, linux is opensource. Almost all projects on github is also considered opensource.
Windows is not open source as you dont have access to the source code.
If you have any specific software in mind, google for it whether it is open source or not.
Ofcourse you can negotiate final terms with Not_OIes if you need something specific?
@Nubuki said:
I assumed that @Not_Oles could have done so by using cpulimit on the QEMU executable, ensure that a login shell is run with nice so that the child processes will inherit the nice value, or limit with cgroups and or probably create a bash script that checks if a process hogging CPU has run for too long.
It's done that way in those rootless tilde servers (I think)
Sorry, that all passed way over my head
Maybe you can explain it in simpler terms (or a step by step guide) to @Not_Oles ?
I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.
@somik said: So what kind of verification do you suggest? If telegram is out, whatsapp and discord follows it. Only social media with "followers" are now considered, but given that you can "buy" followers, doubt it is a good way either...
I think setting up a Telegram group is just a preliminary verification, and we do not expect it to be the sole means of verifying users. What I have in mind is to gradually deepen our understanding of users through chatting, and finally decide whether to let them use it through anonymous voting.
Users who have contributed to this node and ctively helped others are eligible to enter the KVM group, while those who have provided necessary identity proof materials on the basis of their contributions are eligible to enter the sudo group. Whether they can ultimately qualify depends on the results of anonymous voting.
@somik said: So what kind of verification do you suggest? If telegram is out, whatsapp and discord follows it. Only social media with "followers" are now considered, but given that you can "buy" followers, doubt it is a good way either...
I think setting up a Telegram group is just a preliminary verification, and we do not expect it to be the sole means of verifying users. What I have in mind is to gradually deepen our understanding of users through chatting, and finally decide whether to let them use it through anonymous voting.
Users who have contributed to this node and ctively helped others are eligible to enter the KVM group, while those who have provided necessary identity proof materials on the basis of their contributions are eligible to enter the sudo group. Whether they can ultimately qualify depends on the results of anonymous voting.
The issue with voting is that once a certain group becomes the majority, they can influence the outcome. Lets say there are 20 users on the server. In that list, 5 users belongs to the "abuse" group. Then when a new "abuser" joins, those 5 can all vote "yes" and they will only need 33% of the remaining people to vote yes to get the new abuser in. Once that happens, this can go until they become the majority.
Thus, in this case, I think that instead of voting, leave the decision making to @Not_Oles as in the end, it is him who is paying for the server and it is him who have to face Hetzner when abuse gets reported. What do you think?
I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.
Whoah, I posted a thing on page 2, not interested in a free account but wondering how you'd be dealing with abuse, after 20 pages shits going down really quick, so around a month, i guess.
in the previous pages, there's already a post that mentions doing stages of verification to get more privileges or move to a more 'important' server, but imo if you really want to cut the headache, do what hetzner did: verify them using idenfy
another option is to do a similar thing like freeshell (verify using postcards, don't forget to make a nice blog with those scans; i'm sure it's interesting to get in touch with LESbians), they provided free accounts for years, albeit with no root access, but you can request to install stuff. still, it proves that they managed to handle the abuse issues.
on the other hand, I found it interesting that Tom still treats his free vps members like humans (it's really admirable), if i were him, I'd already used my custom kernel to log every user's activity (shell command history is just a small portion of it), and treat them like pieces of data that 'somehow' behave like sentient programs.
goddamn that sounds like a psycho, but if I were giving away free stuff, i'd highly desire more interesting results instead of having to deal with abuse nonsense.
Fuck this 24/7 internet spew of trivia and celebrity bullshit.
@Encoders said:
another option is to do a similar thing like freeshell (verify using postcards, don't forget to make a nice blog with those scans; i'm sure it's interesting to get in touch with LESbians), they provided free accounts for years, albeit with no root access, but you can request to install stuff. still, it proves that they managed to handle the abuse issues.
Woa, wasn't even thinking that as a option... freeshell looks interesting too!
@Encoders said:
on the other hand, I found it interesting that Tom still treats his free vps members like humans (it's really admirable), if i were him, I'd already used my custom kernel to log every user's activity (shell command history is just a small portion of it), and treat them like pieces of data that 'somehow' behave like sentient programs.
You and me both. Follow what the big corporations do. If it works for them, thats more then proof enough that it works
I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.
Hello @Not_Oles
Could you add my ssh key again? ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdxnYG6YQ7yl/JpMl1v2+NS9fnaf+NiWWyWLsC7PUcg
Can i also ask you about the vms (if they are allowed or no?) simply whats not allowed real quick if you can.
@somik said: So what kind of verification do you suggest? If telegram is out, whatsapp and discord follows it. Only social media with "followers" are now considered, but given that you can "buy" followers, doubt it is a good way either...
I think setting up a Telegram group is just a preliminary verification, and we do not expect it to be the sole means of verifying users. What I have in mind is to gradually deepen our understanding of users through chatting, and finally decide whether to let them use it through anonymous voting.
Users who have contributed to this node and ctively helped others are eligible to enter the KVM group, while those who have provided necessary identity proof materials on the basis of their contributions are eligible to enter the sudo group. Whether they can ultimately qualify depends on the results of anonymous voting.
The issue with voting is that once a certain group becomes the majority, they can influence the outcome. Lets say there are 20 users on the server. In that list, 5 users belongs to the "abuse" group. Then when a new "abuser" joins, those 5 can all vote "yes" and they will only need 33% of the remaining people to vote yes to get the new abuser in. Once that happens, this can go until they become the majority.总之
Thus, in this case, I think that instead of voting, leave the decision making to @Not_Oles as in the end, it is him who is paying for the server and it is him who have to face Hetzner when abuse gets reported. What do you think?
You are always able to consider things thoughtfully and thoroughly❤️. Needless to say,the decision-making power should be in @Not_Oles's hands, and when reporting abusive behavior, one must face Hetzner, which is natural.
Sorry to @Not_Oles🥺,My intention is not to ignore his opinions, but rather to reduce his workload on one hand (It may be too exhausting for him to reassess and approve them one by one alone.……), and on the other hand, those who are approved through collective voting may develop a sense of collective identity and belonging, thereby reducing the likelihood of abuse.
However, I did not consider that the actual number of people participating may not be many, perhaps around a few dozen ? In a group of this size, @Not_Oles's workload may still be manageable (I don't know what he would think🤣), and each person's vote is crucial. If abusers form alliances, it could make things uncontrollable.😱
An anonymous voting scheme may be more effective in groups of several hundred or thousand people, but here, let's forget about it. I agree with your plan!👍
@NodeSeek用户123 said:
Sorry to @Not_Oles🥺,My intention is not to ignore his opinions, but rather to reduce his workload on one hand (It may be too exhausting for him to reassess and approve them one by one alone.……), and on the other hand, those who are approved through collective voting may develop a sense of collective identity and belonging, thereby reducing the likelihood of abuse.
Don't worry, we all know you have his best interest in mind and we are all racking our brains to reduce it as much as possible. Afterall, it is no fun to be fighting on all fronts.
@NodeSeek用户123 said:
However, I did not consider that the actual number of people participating may not be many, perhaps around a few dozen ? In a group of this size, @Not_Oles's workload may still be manageable (I don't know what he would think🤣), and each person's vote is crucial. If abusers form alliances, it could make things uncontrollable.😱
An anonymous voting scheme may be more effective in groups of several hundred or thousand people, but here, let's forget about it. I agree with your plan!👍
I agree with you that if there are hundreds or thousands of people, it makes sense to vote. But since there might not even be 100 people, it wont make sense in the beginning.
I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.
@Nubuki said:
I agree with the formulation of rules based on what is allowed and what isn't, a telegram chat group, the open source restrictions (though I'm not really sure how to approach that).
The server itself is free and open to people. So having a small limitations like only open source is a good thing. You can always get a server from hetzner and do what you want on it
I'm actually not disputing this,
In case it wasn't really clear I just wasn't clear if open Source here meant running only Linux kvms , running open source code and what not.
Can you maybe elaborate what count as open source and what doesn't?
Anything where the source code is readily available to anyone looking for it is open source. Yes, linux is opensource. Almost all projects on github is also considered opensource.
Windows is not open source as you dont have access to the source code.
If you have any specific software in mind, google for it whether it is open source or not.
Ofcourse you can negotiate final terms with Not_OIes if you need something specific?
@Nubuki said:
I assumed that @Not_Oles could have done so by using cpulimit on the QEMU executable, ensure that a login shell is run with nice so that the child processes will inherit the nice value, or limit with cgroups and or probably create a bash script that checks if a process hogging CPU has run for too long.
It's done that way in those rootless tilde servers (I think)
Sorry, that all passed way over my head
Maybe you can explain it in simpler terms (or a step by step guide) to @Not_Oles ?
Okay! I'll wait till he starts responding to replies then ask him
@Nubuki said:
I agree with the formulation of rules based on what is allowed and what isn't, a telegram chat group, the open source restrictions (though I'm not really sure how to approach that).
The server itself is free and open to people. So having a small limitations like only open source is a good thing. You can always get a server from hetzner and do what you want on it
I'm actually not disputing this,
In case it wasn't really clear I just wasn't clear if open Source here meant running only Linux kvms , running open source code and what not.
Can you maybe elaborate what count as open source and what doesn't?
Anything where the source code is readily available to anyone looking for it is open source. Yes, linux is opensource. Almost all projects on github is also considered opensource.
Windows is not open source as you dont have access to the source code.
If you have any specific software in mind, google for it whether it is open source or not.
Ofcourse you can negotiate final terms with Not_OIes if you need something specific?
@Nubuki said:
I assumed that @Not_Oles could have done so by using cpulimit on the QEMU executable, ensure that a login shell is run with nice so that the child processes will inherit the nice value, or limit with cgroups and or probably create a bash script that checks if a process hogging CPU has run for too long.
It's done that way in those rootless tilde servers (I think)
Sorry, that all passed way over my head
Maybe you can explain it in simpler terms (or a step by step guide) to @Not_Oles ?
Okay! I'll wait till he starts responding to replies then ask him
nice is old enough that I know about it. I think I might know what you mean by cpulimit too. I might understand a little about child process inheritance.
Would it be too crazy to imagine that you might want to share a bit about what exactly it is you have been doing on the server and about how you have been doing it? Thanks!
Something really interesting has happened! I have been stuck trying to figure out some ideal system for Neighbor application filtering. You guys have been very kindly helping me. But, unexpectedly, while we all were stuck, one guy quietly provided his identity information by a method that he selected and then asked me if his method was okay. I was interested and impressed that one guy simply and quietly went ahead and did the needful. I'm deliberately not providing details because I don't want to risk compromising his privacy any more than minimally necessary.
All the great ideas about community voting on new applicants and complex systems of user monitoring are great for a large community. But I'm just one guy with extra server capacity on one or a couple of servers.
I've been tasting the Low End market for awhile now. I've seen some really great guys fade away! I'm still here. For my own needs I easily could go to the Cloud. But, that wouldn't be metal, would it? Servers are getting more and more expensive. For a while longer I can enjoy using maybe 1% or 2% my i9-13900's capacity. It's great with me if a few nice folks come aboard alongside. 💖 But it's just a single clueless™ guy's thing.
@RtedPro said:
Hello @Not_Oles
Could you add my ssh key again? ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdxnYG6YQ7yl/JpMl1v2+NS9fnaf+NiWWyWLsC7PUcg
Want to provide identity information?
Can i also ask you about the vms (if they are allowed or no?) simply whats not allowed real quick if you can.
I don't want to have a bunch of rules about what is and isn't allowed. Right now I'm thinking about asking guys to run only open source software and not automatically adding new Neighbors to the kvm group.
Have a good day! Thanks for your continuing interest!
@Encoders said:
Whoah, I posted a thing on page 2, not interested in a free account but wondering how you'd be dealing with abuse, after 20 pages shits going down really quick, so around a month, i guess.
in the previous pages, there's already a post that mentions doing stages of verification to get more privileges or move to a more 'important' server, but imo if you really want to cut the headache, do what hetzner did: verify them using idenfy
another option is to do a similar thing like freeshell (verify using postcards, don't forget to make a nice blog with those scans; i'm sure it's interesting to get in touch with LESbians), they provided free accounts for years, albeit with no root access, but you can request to install stuff. still, it proves that they managed to handle the abuse issues.
on the other hand, I found it interesting that Tom still treats his free vps members like humans (it's really admirable), if i were him, I'd already used my custom kernel to log every user's activity (shell command history is just a small portion of it), and treat them like pieces of data that 'somehow' behave like sentient programs.
goddamn that sounds like a psycho, but if I were giving away free stuff, i'd highly desire more interesting results instead of having to deal with abuse nonsense.
Yeah, nice guy that runs ctrl-c.club. I kinda took another quick look over there a couple days ago. Also sdf.org. And thc.org. I should take a look at freeshell. Been years!
I found it interesting that Tom still treats his free vps members like humans (it's really admirable)
You made my day! Thank you! I'm gonna add this to the green links at the bottom of my LES ad OPs!
my custom kernel
Is it Open Source? May we please have a link! Wink!
@somik said: So what kind of verification do you suggest? If telegram is out, whatsapp and discord follows it. Only social media with "followers" are now considered, but given that you can "buy" followers, doubt it is a good way either...
I think setting up a Telegram group is just a preliminary verification, and we do not expect it to be the sole means of verifying users. What I have in mind is to gradually deepen our understanding of users through chatting, and finally decide whether to let them use it through anonymous voting.
Users who have contributed to this node and ctively helped others are eligible to enter the KVM group, while those who have provided necessary identity proof materials on the basis of their contributions are eligible to enter the sudo group. Whether they can ultimately qualify depends on the results of anonymous voting.
Nothing against Telegram, but, for what it's worth, I've been using Signal App. And PMs here, plus the email address on my profile.
I posted earlier today about how small MetalVPS is. I want MetalVPS to feel free and unlimited. I want MetalVPS to be simple.
Neighbors from certain countries may have to overcome increased challenges to providing identity verification. These neighbors need additional support. But, how?
@Nubuki said: In case it wasn't really clear I just wasn't clear if open Source here meant running only Linux kvms , running open source code and what not.
Can you maybe elaborate what count as open source and what doesn't?
Maybe something more or less like:
If the executable is present on the server we all should be able to see the source code. We also ought to be able to see and modify and share any compiler or intermediate tool that was used to create the executable as well as any low level executable (assembly or machine language) that's present on the server. If we can't see, modify, and share the source, the code isn't "Open Source."
@somik said: @Not_Oles forgot to mention, but please ensure that apache is not running as "root". It should be running as user "www-data" and group "www-data", otherwise certain scripts can be used to get shell access to the server as root user.
Do not enable cgi-bin or perl scripts for apache for the same reason.
What's running now is the default which came out of apt-get install apache2. Root didn't start apache2, apt seems to start stuff. Does the following look right?
@RtedPro said:
Hello @Not_Oles
Could you add my ssh key again? ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdxnYG6YQ7yl/JpMl1v2+NS9fnaf+NiWWyWLsC7PUcg
Want to provide identity information?
Can i also ask you about the vms (if they are allowed or no?) simply whats not allowed real quick if you can.
I don't want to have a bunch of rules about what is and isn't allowed. Right now I'm thinking about asking guys to run only open source software and not automatically adding new Neighbors to the kvm group.
Have a good day! Thanks for your continuing interest!
@Not_Oles said:
Neighbors from certain countries may have to overcome increased challenges to providing identity verification. These neighbors need additional support. But, how?
I like the post card idea! Think of it as writing to a pen pal.
I am sure you'll be delighted to receive post cards from different places as well.
Unless you will get into trouble for writing to a pen pal outside of the country... Which i don't think is the case for most people wishing to use MetalVPS.
@Not_Oles said:
Hmm. The following might not seem right. Any user can run the apache2 command?
Yes, any user can run any service on any port >=1024. To bind to a low-numbered port, such as 80 (HTTP) or 443 (HTTPS) requires root privileges. A non-root user will override the default configuration file path, otherwise it'll default to the one in /etc which will fail because they can't bind to the port.
nice is old enough that I know about it. I think I might know what you mean by cpulimit too. I might understand a little about child process inheritance.
I see great then
Would it be too crazy to imagine that you might want to share a bit about what exactly it is you have been doing on the server and about how you have been doing it? Thanks!
Best wishes!
Tom
Well I have been encoding videos 😑
Basically it's more of archiving though
A telegram bot is deployed, I forward a video to the bot on tg, bot compresses it and uploads the compressed file to my drive or returns the file on telegram
Basically it's more of archiving though
A telegram bot is deployed, I forward a video to the bot on tg, bot compresses it and uploads the compressed file to my drive or returns the file on telegram
Can one do this with Open Source software exclusively?
@Not_Oles said:
Hmm. The following might not seem right. Any user can run the apache2 command?
Yes, any user can run any service on any port >=1024. To bind to a low-numbered port, such as 80 (HTTP) or 443 (HTTPS) requires root privileges. A non-root user will override the default configuration file path, otherwise it'll default to the one in /etc which will fail because they can't bind to the port.
How does a "non-root user . . . override the default configuration file path?" Is it by making an alternate configuration and pointing Apache to the alternate configuration, or perhaps by specifying the configuration through command line options? Hmm. I probably should Google this before posting. Bad boy!
No issue that process 6892 is running as root? Why?
@RtedPro said:
Hello @Not_Oles
Could you add my ssh key again? ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdxnYG6YQ7yl/JpMl1v2+NS9fnaf+NiWWyWLsC7PUcg
Want to provide identity information?
Can i also ask you about the vms (if they are allowed or no?) simply whats not allowed real quick if you can.
I don't want to have a bunch of rules about what is and isn't allowed. Right now I'm thinking about asking guys to run only open source software and not automatically adding new Neighbors to the kvm group.
Have a good day! Thanks for your continuing interest!
Hi @RtedPro! The proposed identity information types are specified explicitly in the public draft of the upcoming new MetalVPS ad. If you have time, could you please take a look and tell me how the draft could be improved? Best! Tom
@Not_Oles said:
Hmm. The following might not seem right. Any user can run the apache2 command?
Yes, any user can run any service on any port >=1024. To bind to a low-numbered port, such as 80 (HTTP) or 443 (HTTPS) requires root privileges. A non-root user will override the default configuration file path, otherwise it'll default to the one in /etc which will fail because they can't bind to the port.
How does a "non-root user . . . override the default configuration file path?" Is it by making an alternate configuration and pointing Apache to the alternate configuration,
Yes, -f config_file defaults to /etc/apache2/apache2.conf
or perhaps by specifying the configuration through command line options?
There are far too many for that! The config file includes a whole load of other files too.
No issue that process 6892 is running as root? Why?
I'm guessing that's for when it needs to re-read the config files and possibly needs to bind to a new port.
I believe the startup is somewhat complicated - worker processes are created that setuid(www-data) to protect against vulnerabilities. Then the config file is read and the worker processes communicate with the original root process to say what ports need to be listened on. The root process creates these as it has permission, and these are then shared with the worker processes to accept() and process the incoming requests.
Basically it's more of archiving though
A telegram bot is deployed, I forward a video to the bot on tg, bot compresses it and uploads the compressed file to my drive or returns the file on telegram
Can one do this with Open Source software exclusively?
Yup everything is run using Python and the repository is public the dependencies like ffmpeg (which is actually used in encoding) is open source too
Basically it's more of archiving though
A telegram bot is deployed, I forward a video to the bot on tg, bot compresses it and uploads the compressed file to my drive or returns the file on telegram
Can one do this with Open Source software exclusively?
Yup everything is run using Python and the repository is public the dependencies like ffmpeg (which is actually used in encoding) is open source too
Excellent! If you have time, can you post an example or a link? Thanks!
Basically it's more of archiving though
A telegram bot is deployed, I forward a video to the bot on tg, bot compresses it and uploads the compressed file to my drive or returns the file on telegram
Can one do this with Open Source software exclusively?
Yup everything is run using Python and the repository is public the dependencies like ffmpeg (which is actually used in encoding) is open source too
Excellent! If you have time, can you post an example or a link? Thanks!
Basically it's more of archiving though
A telegram bot is deployed, I forward a video to the bot on tg, bot compresses it and uploads the compressed file to my drive or returns the file on telegram
Can one do this with Open Source software exclusively?
Yup everything is run using Python and the repository is public the dependencies like ffmpeg (which is actually used in encoding) is open source too
Excellent! If you have time, can you post an example or a link? Thanks!
Thanks! I took a quick look at the README.md. Sometime, when you have a chance, could you please link to an example video? Sorry, I've never used Telegram, and so I have no idea what kinds of videos would be forwarded to Telegram. And you say that the Telegram bot compresses the video file. Does "forwarded" plus "bot compression" mean something akin to posting the video? Thanks!
@Not_Oles said:
New Terms of Service for MetalVPS Neighbors might include:
Run open source software only?
I'm OK with this actually.
No transfer of account or sub-accounts?
Surely this is a must.
kvm group membership deferred?
I don't think this is actually a good idea, this may make people lost interest in MetalVPS. Maybe just limit them to use not more than 8GB RAM and 4 CPU cores. Or maybe limit it to people who has verified their identity by using any method.
sudo group membership deferred?
I'm OK with no sudo access, at least I still need to use KVM
New Benefits for MetalVPS Neighbors might include:
Shared hosting, maybe /home/neighbor/www/ is served?
@Not_Oles said:
Hmm. The following might not seem right. Any user can run the apache2 command?
Yes, any user can run any service on any port >=1024. To bind to a low-numbered port, such as 80 (HTTP) or 443 (HTTPS) requires root privileges. A non-root user will override the default configuration file path, otherwise it'll default to the one in /etc which will fail because they can't bind to the port.
How does a "non-root user . . . override the default configuration file path?" Is it by making an alternate configuration and pointing Apache to the alternate configuration,
Yes, -f config_file defaults to /etc/apache2/apache2.conf
or perhaps by specifying the configuration through command line options?
There are far too many for that! The config file includes a whole load of other files too.
No issue that process 6892 is running as root? Why?
I'm guessing that's for when it needs to re-read the config files and possibly needs to bind to a new port.
I believe the startup is somewhat complicated - worker processes are created that setuid(www-data) to protect against vulnerabilities. Then the config file is read and the worker processes communicate with the original root process to say what ports need to be listened on. The root process creates these as it has permission, and these are then shared with the worker processes to accept() and process the incoming requests.
The config file /etc/apache2/apache2.conf should contain the default user and group
User www-data
Group www-data
If it is something different, change and restart apache2
I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.
@Not_Oles said:
Hmm. The following might not seem right. Any user can run the apache2 command?
Yes, any user can run any service on any port >=1024. To bind to a low-numbered port, such as 80 (HTTP) or 443 (HTTPS) requires root privileges. A non-root user will override the default configuration file path, otherwise it'll default to the one in /etc which will fail because they can't bind to the port.
How does a "non-root user . . . override the default configuration file path?" Is it by making an alternate configuration and pointing Apache to the alternate configuration,
Yes, -f config_file defaults to /etc/apache2/apache2.conf
or perhaps by specifying the configuration through command line options?
There are far too many for that! The config file includes a whole load of other files too.
No issue that process 6892 is running as root? Why?
I'm guessing that's for when it needs to re-read the config files and possibly needs to bind to a new port.
I believe the startup is somewhat complicated - worker processes are created that setuid(www-data) to protect against vulnerabilities. Then the config file is read and the worker processes communicate with the original root process to say what ports need to be listened on. The root process creates these as it has permission, and these are then shared with the worker processes to accept() and process the incoming requests.
The config file /etc/apache2/apache2.conf should contain the default user and group
User www-data
Group www-data
If it is something different, change and restart apache2
Thanks so much @somik! Your help is greatly appreciated!
root@fsn ~ # cat /etc/apache2/apache2.conf
[ . . . ]
# These need to be set in /etc/apache2/envvars
User ${APACHE_RUN_USER}
Group ${APACHE_RUN_GROUP}
[ . . . ]
root@fsn ~ # cat /etc/apache2/envvars
[ . . . ]
export APACHE_RUN_USER=www-data
export APACHE_RUN_GROUP=www-data
[ . . . ]
root@fsn ~ #
It's interesting to read the comments in /etc/apache2/apache2.conf ("Apache 2 web server configuration in Debian is quite different to upstream's. . . .") and /etc/apache2/envvars (". . . there is no sane way to get the parsed apache2 config in scripts. . . .")
@Not_Oles said:
Hmm. The following might not seem right. Any user can run the apache2 command?
Yes, any user can run any service on any port >=1024. To bind to a low-numbered port, such as 80 (HTTP) or 443 (HTTPS) requires root privileges. A non-root user will override the default configuration file path, otherwise it'll default to the one in /etc which will fail because they can't bind to the port.
How does a "non-root user . . . override the default configuration file path?" Is it by making an alternate configuration and pointing Apache to the alternate configuration,
Yes, -f config_file defaults to /etc/apache2/apache2.conf
or perhaps by specifying the configuration through command line options?
There are far too many for that! The config file includes a whole load of other files too.
No issue that process 6892 is running as root? Why?
I'm guessing that's for when it needs to re-read the config files and possibly needs to bind to a new port.
I believe the startup is somewhat complicated - worker processes are created that setuid(www-data) to protect against vulnerabilities. Then the config file is read and the worker processes communicate with the original root process to say what ports need to be listened on. The root process creates these as it has permission, and these are then shared with the worker processes to accept() and process the incoming requests.
The config file /etc/apache2/apache2.conf should contain the default user and group
User www-data
Group www-data
If it is something different, change and restart apache2
Thanks so much @somik! Your help is greatly appreciated!
root@fsn ~ # cat /etc/apache2/apache2.conf
[ . . . ]
# These need to be set in /etc/apache2/envvars
User ${APACHE_RUN_USER}
Group ${APACHE_RUN_GROUP}
[ . . . ]
root@fsn ~ # cat /etc/apache2/envvars
[ . . . ]
export APACHE_RUN_USER=www-data
export APACHE_RUN_GROUP=www-data
[ . . . ]
root@fsn ~ #
It's interesting to read the comments in /etc/apache2/apache2.conf ("Apache 2 web server configuration in Debian is quite different to upstream's. . . .") and /etc/apache2/envvars (". . . there is no sane way to get the parsed apache2 config in scripts. . . .")
Ya, i was worried about that... Maybe someone here with more knowledge about apache2 on debian can help...
I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.
@Not_Oles said:
What is the program you want to run inside Qemu-KVM?
How could you run your program directly on the metal so that Qemu-KVM would not be needed?
For now I'm not sure yet. Probably something that runs inside Linux and is interesting for me.
To run the program directly sometimes I may need sudo because of dependecies issues.
@Not_Oles said:
What is the program you want to run inside Qemu-KVM?
How could you run your program directly on the metal so that Qemu-KVM would not be needed?
For now I'm not sure yet. Probably something that runs inside Linux and is interesting for me.
To run the program directly sometimes I may need sudo because of dependecies issues.
Seems reasonable. . . .
The i9-13900 isn't really ready yet, but I will make an account for you. kvm group and sudo group 🔜
The i9-9900K is turned off, which seems a shame. Could you please let me know which one of the following distros you would like?
AlmaLinux 8.7 base
Arch Linux latest minimal
CentOS 7.9 minimal
CentOS Stream 8 base
Debian 10 base
Debian 10 LAMP
Debian 11 base
Rocky Linux 8.7 base
Ubuntu 18.04.5 LTS minimal
Ubuntu 18.04.5 LTS Nextcloud
Ubuntu 20.04.3 (HWE) LTS minimal
Ubuntu 20.04.3 LTS base
Ubuntu 22.04.1 LTS base
Thanks! Best wishes and welcome, again, to MetalVPS.
@Not_Oles said:
What is the program you want to run inside Qemu-KVM?
How could you run your program directly on the metal so that Qemu-KVM would not be needed?
For now I'm not sure yet. Probably something that runs inside Linux and is interesting for me.
To run the program directly sometimes I may need sudo because of dependecies issues.
Fyi, you can still run the program on LXC containers inside metalVPS without KVM or sudo access. That brings me to the question, is KVM group membership required for LXC or should there be a seperate LXC group membership?
I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.
Thanks for your message. kvm is "not right away." If that's okay, how do you want to verify your identity? Send
Name
Address
Email
Phone number
Scan of government ID
to the email address on my LES profile? Send by LES PM? Another way?
Best wishes!
Tom
Create me an account using the previous SSH key btw
Hi @iamvinh123! As a result of the port scan that Hetzner caught, MetalVPS has an identity requirement now. How do you want to verify your identity? You could send
Name
Address
Email
Phone number
Scan of government ID
to the email address on my LES profile? Or send by LES PM? Or maybe you prefer another way?
Thanks for your message. kvm is "not right away." If that's okay, how do you want to verify your identity? Send
Name
Address
Email
Phone number
Scan of government ID
to the email address on my LES profile? Send by LES PM? Another way?
Best wishes!
Tom
Create me an account using the previous SSH key btw
Hi @iamvinh123! As a result of the port scan that Hetzner caught, MetalVPS has an identity requirement now. How do you want to verify your identity? You could send
Name
Address
Email
Phone number
Scan of government ID
to the email address on my LES profile? Or send by LES PM? Or maybe you prefer another way?
Thanks! Best!
Tom
Hmmmm, I would prefer the another way as I'm 13 yo old
yo = years
Thanks for your message. kvm is "not right away." If that's okay, how do you want to verify your identity? Send
Name
Address
Email
Phone number
Scan of government ID
to the email address on my LES profile? Send by LES PM? Another way?
Best wishes!
Tom
Create me an account using the previous SSH key btw
Hi @iamvinh123! As a result of the port scan that Hetzner caught, MetalVPS has an identity requirement now. How do you want to verify your identity? You could send
Name
Address
Email
Phone number
Scan of government ID
to the email address on my LES profile? Or send by LES PM? Or maybe you prefer another way?
Thanks! Best!
Tom
Hmmmm, I would prefer the another way as I'm 13 yo old
yo = years
Comments
Cause the server was wiped and OS was reinstalled, so the server signature changed. Yes, your data is gone. No, you are requried to keep own backups.
The server itself is free and open to people. So having a small limitations like only open source is a good thing. You can always get a server from hetzner and do what you want on it
No, because he isn't using any panels. So there is no monitoring going on. Only limitations are number of cores and max amount of RAM, which @Not_Oles isn't willing to enforce.
Thanks
@Not_Oles Can you put back m account? AAAAC3NzaC1lZDI1NTE5AAAAIBUp/JhS4fx3Ht9SSaZaeC/OGP9vGwZ31j+Kwakh
VDxR
FYI, you can always just click the tanks button bellow the username instead of a comment to just say thanks. Ofcourse it's ok to comment if you have some other comments or questions
I am personally willing to accept this.
But I would like to know how to implement it.
I strongly agree with this point.
sudo group membership deferred?
Yep, postponing membership is necessary. It takes time to implement security measures and observe and consider users. In short, I believe there is no rush to open membership.🤔
I'm actually not disputing this,
In case it wasn't really clear I just wasn't clear if open Source here meant running only Linux kvms , running open source code and what not.
Can you maybe elaborate what count as open source and what doesn't?
I assumed that @Not_Oles could have done so by using cpulimit on the QEMU executable, ensure that a login shell is run with nice so that the child processes will inherit the nice value, or limit with cgroups and or probably create a bash script that checks if a process hogging CPU has run for too long.
It's done that way in those rootless tilde servers (I think)
Teehee!
Anything where the source code is readily available to anyone looking for it is open source. Yes, linux is opensource. Almost all projects on github is also considered opensource.
Windows is not open source as you dont have access to the source code.
If you have any specific software in mind, google for it whether it is open source or not.
Ofcourse you can negotiate final terms with Not_OIes if you need something specific?
Sorry, that all passed way over my head
Maybe you can explain it in simpler terms (or a step by step guide) to @Not_Oles ?
I think setting up a Telegram group is just a preliminary verification, and we do not expect it to be the sole means of verifying users. What I have in mind is to gradually deepen our understanding of users through chatting, and finally decide whether to let them use it through anonymous voting.
Users who have contributed to this node and ctively helped others are eligible to enter the KVM group, while those who have provided necessary identity proof materials on the basis of their contributions are eligible to enter the sudo group. Whether they can ultimately qualify depends on the results of anonymous voting.
The issue with voting is that once a certain group becomes the majority, they can influence the outcome. Lets say there are 20 users on the server. In that list, 5 users belongs to the "abuse" group. Then when a new "abuser" joins, those 5 can all vote "yes" and they will only need 33% of the remaining people to vote yes to get the new abuser in. Once that happens, this can go until they become the majority.
Thus, in this case, I think that instead of voting, leave the decision making to @Not_Oles as in the end, it is him who is paying for the server and it is him who have to face Hetzner when abuse gets reported. What do you think?
Whoah, I posted a thing on page 2, not interested in a free account but wondering how you'd be dealing with abuse, after 20 pages shits going down really quick, so around a month, i guess.
in the previous pages, there's already a post that mentions doing stages of verification to get more privileges or move to a more 'important' server, but imo if you really want to cut the headache, do what hetzner did: verify them using idenfy
another option is to do a similar thing like freeshell (verify using postcards, don't forget to make a nice blog with those scans; i'm sure it's interesting to get in touch with LESbians), they provided free accounts for years, albeit with no root access, but you can request to install stuff. still, it proves that they managed to handle the abuse issues.
on the other hand, I found it interesting that Tom still treats his free vps members like humans (it's really admirable), if i were him, I'd already used my custom kernel to log every user's activity (shell command history is just a small portion of it), and treat them like pieces of data that 'somehow' behave like sentient programs.
goddamn that sounds like a psycho, but if I were giving away free stuff, i'd highly desire more interesting results instead of having to deal with abuse nonsense.
Fuck this 24/7 internet spew of trivia and celebrity bullshit.
Woa, wasn't even thinking that as a option... freeshell looks interesting too!
You and me both. Follow what the big corporations do. If it works for them, thats more then proof enough that it works
Hello @Not_Oles
Could you add my ssh key again? ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdxnYG6YQ7yl/JpMl1v2+NS9fnaf+NiWWyWLsC7PUcg
Can i also ask you about the vms (if they are allowed or no?) simply whats not allowed real quick if you can.
You are always able to consider things thoughtfully and thoroughly❤️. Needless to say,the decision-making power should be in @Not_Oles's hands, and when reporting abusive behavior, one must face Hetzner, which is natural.
Sorry to @Not_Oles🥺,My intention is not to ignore his opinions, but rather to reduce his workload on one hand (It may be too exhausting for him to reassess and approve them one by one alone.……), and on the other hand, those who are approved through collective voting may develop a sense of collective identity and belonging, thereby reducing the likelihood of abuse.
However, I did not consider that the actual number of people participating may not be many, perhaps around a few dozen ? In a group of this size, @Not_Oles's workload may still be manageable (I don't know what he would think🤣), and each person's vote is crucial. If abusers form alliances, it could make things uncontrollable.😱
An anonymous voting scheme may be more effective in groups of several hundred or thousand people, but here, let's forget about it. I agree with your plan!👍
Don't worry, we all know you have his best interest in mind and we are all racking our brains to reduce it as much as possible. Afterall, it is no fun to be fighting on all fronts.
I agree with you that if there are hundreds or thousands of people, it makes sense to vote. But since there might not even be 100 people, it wont make sense in the beginning.
Okay! I'll wait till he starts responding to replies then ask him
Teehee!
Hi @Nubuki!
niceis old enough that I know about it.cpulimittoo. I might understand a little about child process inheritance.Would it be too crazy to imagine that you might want to share a bit about what exactly it is you have been doing on the server and about how you have been doing it?
Thanks!
Best wishes!
Tom
Guys!
Something really interesting has happened! I have been stuck trying to figure out some ideal system for Neighbor application filtering. You guys have been very kindly helping me. But, unexpectedly, while we all were stuck, one guy quietly provided his identity information by a method that he selected and then asked me if his method was okay. I was interested and impressed that one guy simply and quietly went ahead and did the needful. I'm deliberately not providing details because I don't want to risk compromising his privacy any more than minimally necessary.
All the great ideas about community voting on new applicants and complex systems of user monitoring are great for a large community. But I'm just one guy with extra server capacity on one or a couple of servers.
I've been tasting the Low End market for awhile now. I've seen some really great guys fade away! I'm still here. For my own needs I easily could go to the Cloud. But, that wouldn't be metal, would it? Servers are getting more and more expensive. For a while longer I can enjoy using maybe 1% or 2% my i9-13900's capacity. It's great with me if a few nice folks come aboard alongside. 💖 But it's just a single clueless™ guy's thing.
Best wishes!
Tom
Want to provide identity information?
I don't want to have a bunch of rules about what is and isn't allowed. Right now I'm thinking about asking guys to run only open source software and not automatically adding new Neighbors to the kvm group.
Have a good day! Thanks for your continuing interest!
I didn't know about Idenfy or that Hetzner might use idenfy. Thanks for telling us!
Yeah, nice guy that runs ctrl-c.club. I kinda took another quick look over there a couple days ago. Also sdf.org. And thc.org. I should take a look at freeshell. Been years!
You made my day! Thank you! I'm gonna add this to the green links at the bottom of my LES ad OPs!
Is it Open Source?
May we please have a link!
Wink! 
Nothing against Telegram, but, for what it's worth, I've been using Signal App. And PMs here, plus the email address on my profile.
I posted earlier today about how small MetalVPS is. I want MetalVPS to feel free and unlimited. I want MetalVPS to be simple.
Neighbors from certain countries may have to overcome increased challenges to providing identity verification. These neighbors need additional support. But, how?
Maybe something more or less like:
If the executable is present on the server we all should be able to see the source code.
We also ought to be able to see and modify and share any compiler or intermediate tool that was used to create the executable as well as any low level executable (assembly or machine language) that's present on the server. If we can't see, modify, and share the source, the code isn't "Open Source."
Um, approximately.
What's running now is the default which came out of
apt-get install apache2. Root didn't start apache2, apt seems to start stuff. Does the following look right?Hmm. The following might not seem right. Any user can run the
apache2command?Thanks!
@yqua
Hello @Not_Oles
What identify information?
I like the post card idea! Think of it as writing to a pen pal.
I am sure you'll be delighted to receive post cards from different places as well.
Unless you will get into trouble for writing to a pen pal outside of the country... Which i don't think is the case for most people wishing to use MetalVPS.
DM us for private tracker invite.
Yes, any user can run any service on any port >=1024. To bind to a low-numbered port, such as 80 (HTTP) or 443 (HTTPS) requires root privileges. A non-root user will override the default configuration file path, otherwise it'll default to the one in /etc which will fail because they can't bind to the port.
I see great then
Well I have been encoding videos 😑
Basically it's more of archiving though
A telegram bot is deployed, I forward a video to the bot on tg, bot compresses it and uploads the compressed file to my drive or returns the file on telegram
Teehee!
Can one do this with Open Source software exclusively?
How does a "non-root user . . . override the default configuration file path?" Is it by making an alternate configuration and pointing Apache to the alternate configuration, or perhaps by specifying the configuration through command line options? Hmm. I probably should Google this before posting. Bad boy!
No issue that process 6892 is running as root? Why?
Thanks!!!
Hi @RtedPro! The proposed identity information types are specified explicitly in the public draft of the upcoming new MetalVPS ad. If you have time, could you please take a look and tell me how the draft could be improved? Best! Tom
Yes,
-f config_filedefaults to/etc/apache2/apache2.confThere are far too many for that! The config file includes a whole load of other files too.
I'm guessing that's for when it needs to re-read the config files and possibly needs to bind to a new port.
I believe the startup is somewhat complicated - worker processes are created that
setuid(www-data)to protect against vulnerabilities. Then the config file is read and the worker processes communicate with the original root process to say what ports need to be listened on. The root process creates these as it has permission, and these are then shared with the worker processes toaccept()and process the incoming requests.Yup everything is run using Python and the repository is public the dependencies like ffmpeg (which is actually used in encoding) is open source too
Teehee!
Excellent! If you have time, can you post an example or a link? Thanks!
Okay Here!
Teehee!
Thanks! I took a quick look at the README.md. Sometime, when you have a chance, could you please link to an example video? Sorry, I've never used Telegram, and so I have no idea what kinds of videos would be forwarded to Telegram. And you say that the Telegram bot compresses the video file. Does "forwarded" plus "bot compression" mean something akin to posting the video?
Thanks!
I'm OK with this actually.
Surely this is a must.
I don't think this is actually a good idea, this may make people lost interest in MetalVPS. Maybe just limit them to use not more than 8GB RAM and 4 CPU cores. Or maybe limit it to people who has verified their identity by using any method.
I'm OK with no sudo access, at least I still need to use KVM
This looks like a great idea!
Thanks for your helpful comment!
What is the program you want to run inside Qemu-KVM?
How could you run your program directly on the metal so that Qemu-KVM would not be needed?
The config file
/etc/apache2/apache2.confshould contain the default user and groupIf it is something different, change and restart apache2
Thanks so much @somik! Your help is greatly appreciated!
However
Nevertheless
It's interesting to read the comments in /etc/apache2/apache2.conf ("Apache 2 web server configuration in Debian is quite different to upstream's. . . .") and /etc/apache2/envvars (". . . there is no sane way to get the parsed apache2 config in scripts. . . .")
Ya, i was worried about that... Maybe someone here with more knowledge about apache2 on debian can help...
Hi, I want to create a NAT kvm with IPv6; then I want to establish an ip6tnl between two different IPv6 KVMs. Can I join this party?
Here is my pub key
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGXNzoL4Y7b+LDxR9tdR5jGzc7Vce0a15U3mdM/dnP77For now I'm not sure yet. Probably something that runs inside Linux and is interesting for me.
To run the program directly sometimes I may need sudo because of dependecies issues.
Seems reasonable. . . .
The i9-13900 isn't really ready yet, but I will make an account for you. kvm group and sudo group 🔜
The i9-9900K is turned off, which seems a shame. Could you please let me know which one of the following distros you would like?
Thanks! Best wishes and welcome, again, to MetalVPS.
Fyi, you can still run the program on LXC containers inside metalVPS without KVM or sudo access. That brings me to the question, is KVM group membership required for LXC or should there be a seperate LXC group membership?
Hi @dwight!
Thanks for your message. kvm is "not right away." If that's okay, how do you want to verify your identity? Send
Name
Address
Email
Phone number
Scan of government ID
to the email address on my LES profile? Send by LES PM? Another way?
Best wishes!
Tom
Create me an account using the previous SSH key btw
I think usually, but not always. For example, an unprivileged LXC user can't mount file systems.
kvm group membership is not required for LXC. The user needs to be in /etc/subuid, /etc/subgid, and /etc/lxc/lxc-usernet. Please see https://linuxcontainers.org/lxc/getting-started/ .
Maybe what @itsmepaddi and what @dwight want to do could be done with LXC containers. @itsmepaddi @dwight Have you guys tried LXC yet?
Best wishes!
BTW = by the way
Hi @iamvinh123! As a result of the port scan that Hetzner caught, MetalVPS has an identity requirement now. How do you want to verify your identity? You could send
Name
Address
Email
Phone number
Scan of government ID
to the email address on my LES profile? Or send by LES PM? Or maybe you prefer another way?
Thanks!
Best! 
Tom
Hmmmm, I would prefer the another way as I'm 13 yo old
yo = years
Since I'm from Vietnam, I don't have any gov ID