Keithp.com/ blogs/ rebuild

?tag "fd.o" Rebuilding the Freedesktop.org Server Complex

Ok, so it’s really only two machines at present, but we have big plans.

As Daniel described in some detail, the machine was compromised and we’ve spent the last week rebuilding it. But, I wanted to describe our current setup and what we’d like to see in the near future.

The worst effect of the breakin was to disable all of our services, from web to email and even CVS. That’s clearly not acceptable, and I think we can expect future security issues with our vast collection of random web services. This points to the usual solution — use separate boxes for separate services. Based on conversations with other people running similar sites, I think we need:

We’ve got three machines available at present:

We’ve stuck in a budget request for another “real” server. If that happens we can use that for CVS. It would be nice to get another small server for mail or ldap so that we could avoid using the dual opteron box; it’s a desktop machine and isn’t likely to be as reliable as we’d like to see.

X.org is also looking into building another site; I imagine we’ll be able to piggy-back on that effort and mirror the fd.o content whereever x.org lands.