Hi,
Around 1432Z IPv6 connectivity to all hosts was lost, and VPSes on
kwak.bitfolk.com became unreachable (both IPv4 and v6).
Subsequent investigation has revealed that kwak.bitfolk.com was
unexpectedly power cycled and returned in a configuration that had
no networking.
IPv6 connectivity was restored at around 1503Z and VPSes hosted on
kwak.bitfolk.com are now in the process of being booted again.
If you are unable to reach your VPS, and it is hosted on
kwak.bitfolk.com¹, please log in to your Xen Shell and look at its
console to see what is happening:
https://tools.bitfolk.com/wiki/Xen_Shell
There is a high possibility that the VPS is still booting, is
performing a filesystem check, or has failed to boot because of some
configuration problem local to your VPS.
If you have ruled all of those out then please do send a support
ticket to support(a)bitfolk.com. For those of you with Nagios
monitoring set up I will be watching to make sure any alerts
recover where that is within my power.
To follow:
- How kwak came to be power cycled
- Why it didn't boot with networking enabled
- Why IPv6 broke for everyone even though it should have failed over
to another router.
Cheers,
Andy
¹ If you don't know, you can find out which piece of hardware your
VPS is hosted on as follows:
https://bitfolk.com/customer_information.html#toc_3_Which_piece_of_actual_h…
--
http://bitfolk.com/ -- No-nonsense VPS hosting
Please consider the environment before reading this e-mail.
— John Levine
Hi,
You may be aware of the "free LWN for a year" offer:
https://tools.bitfolk.com/wiki/Free_LWN_subscriptions
The current set of subscriptions are up for renewal on 28th November
and I don't intend to renew them. Therefore those of you currently
using them are going to need to pay for an account if you wish to
continue using LWN as a subscriber after that point.
The reason for this is that for the last couple of years it's
actually been quite hard to give these away to new customers, and
it's not something I want to just keep giving away to the same
people.
I think something like an electronic subscription to Linux Voice may
be more desirable, and that's something I'm willing to explore if
they implement an institution subscription system. That is an idea
I've heard them mention in passing but I'm not sure it will ever
happen as although I think it might be a better fit for BitFolk
customers, it's hard to imagine it being that popular amongst
institutions.
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
Hi,
Due to what I believe is a software bug in the version of Xen
hypervisor running on urquell.bitfolk.com, it has become impossible
to boot some VPSes.
This will require a reboot to recover from, so I intend to perform a
clean shut down and boot again at 0100Z Friday 9th May (2am tonight
UK time). This is necessary in order to regain manageability.
At the same time I will apply updates that should fix the problem.
Customers on urquell should expect to see a clean shutdown followed
by a boot again. I should expect the outage to take no more than 30
minutes.
Apologies for the disruption and short notice this has entailed.
urquell currently has an uptime of 1166 days.
If you are unsure which piece of hardware your VPS currently resides
on, you can work it out in a number of ways. Please see:
https://bitfolk.com/customer_information.html#toc_3_Which_piece_of_actual_h…http://is.gd/16wUTV
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
Hi,
Last night I added Ubuntu 14.04.x LTS (Trusty Tahr) to the
self-installer. It appears to work fine in my limited tests.
If you intend to make use of it just do a self-install by the usual
procedure:
https://tools.bitfolk.com/wiki/Using_the_self-serve_net_installer
I am not yet aware of any customers who have upgraded to 14.04
though so while I do not expect any issues, you may want to
exercise some caution.
Upgrades from the previous LTS (12.04.x LTS) are of course supported
by Ubuntu and I know of no reason why that also would not work, but
again I am not yet aware of any customer who has done one.
Installers for:
11.04 (Natty Narwhal)
11.10 (Oneiric Ocelot)
13.04 (Raring Ringtail)
were removed as these distributions are now EOL for security
updates.
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
Hi,
I've seen a bunch of scans for this exploit across my hosts, and
have already heard of some hosts compromised by it:
http://seclists.org/fulldisclosure/2014/Apr/240
So if you run Nagios NRPE, please make sure to:
- Firewall it off appropriately
- Use its config options for restricting who can talk to it
- Disable client specification of command arguments if possible
- Upgrade to a fixed version
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
Hello,
If you've been reading tech news in the last 24 hours then you're
probably aware of "heartbleed", but if not then you will want to
have a read of:
http://heartbleed.com/
and take appropriate action.
If you trust this site you can use it to check if your HTTPS server
is vulnerable or not:
http://filippo.io/Heartbleed/
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
Hi,
As you may know, we have supported UK Direct Debit payments for
quite some time:
https://tools.bitfolk.com/wiki/Direct_Debit
It works well.
At the moment it's only available to customers with a UK bank
account though.
GoCardless are trialling their SEPA Direct Debits platform at the
moment, which would allow customers in countries that use the Euro
to also use the same Direct Debit payment method.
In order to judge whether this is a priority to work on I would be
most grateful if anyone who would be interested in switching to this
payment method would:
1. Visit:
https://tools.bitfolk.com/redmine/issues/123
2. Log in to it (usual BitFolk account credentials)
3. Vote it up.
Thanks!
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
"I'd be happy to buy all variations of sex to ensure I got what I wanted."
— Gary Coates (talking about cabling)
Hello,
Here's some information that those of you using your VPSes to handle
email may be interested in:
https://github.com/antibodyMX/communicado
If you're not interested in receiving such emails from Communicado
then the information there should help you, and please do consider
contributing to the effort if you're able.
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting
Hi,
As you may be aware, massive distributed denial of service attacks
have been mounted over the last couple of weeks by sending forged
administrative queries to public NTP servers.
A favourite query in use is "monlist", which results in a constant
stream of data being returned from the NTP server to the victim
host.
While we have no evidence that any BitFolk VPS has so far been used
in such an attack, we are going to take some pre-emptive action to
minimise the risk.
As there is no need to allow these administrative queries from the
entire Internet, we now require these to be disabled by default and
only allowed from specified trusted hosts. This has always been the
configuration provided to you on provisioning of your VPS, so only
those who have changed their ntpd configuration would have
re-enabled administrative queries.
Disabling administrative queries is normally achieved by using the
"noquery" option in the "restrict" lines. This setting does not
disallow time synchronisation.
For more information please see:
https://tools.bitfolk.com/wiki/Securing_NTP
Cheers,
Andy
--
http://bitfolk.com/ -- No-nonsense VPS hosting