I’m beautiful and tough like a diamond…or beef jerky in a ball gown.

– Titus Andromedon

  • 105 Posts
  • 237 Comments
Joined 1 year ago
cake
Cake day: July 15th, 2025

help-circle











  • Twice a year I fill in as DBA when our lady graybeard Oracle DBA takes vacation. This month is one of those times. Yay me.

    For my org, it’s just the massive in-house developed line-of-business application that’s tightly coupled to Oracle that keeps us chained to it. It’s technical debt from top to bottom, and has been accumulating steadily since the early 2010s, but no one seems willing to start replacing it.

    The new projects typically go with Postgres, MariaDB, or if all else fails, MSSQL. But the Oracle monster in the closet isn’t likely to leave any time soon.









  • Security is pretty minimal, not gonna lie.

    There’s a 50 GB LUKS partition that stays locked unless I’m actively using it. It’s got backup copies of my important/critical documents and password manager exports but the rest of it is just media and doesn’t really merit encryption.

    All applications have local accounts but I’m not using LDAP or any kind of SSO like I am with my main stack.

    At home, I keep the firewall disabled on the interface configured as “WAN” so I can access its services directly via their hostname (I point its wildcard DNS record to its local “WAN” IP) but do enable firewall when I’m using it on an untrusted network. Granted, I have to manually remember to do that, so that’s kind of a security risk if I forget. Generally, though, when I’m using it remotely, it’s using my secondary phone as a USB-tethered uplink so even if I leave its internal services exposed to WAN, the NAT from the phone blocks that. One of my goals, eventually, is to automate some of the firewall rules depending on where I’m using it.


  • I addressed that in a few ways:

    1. I bought a quality SD card to start with. A 1 TB card is a lot of eggs in one basket so I wasn’t about to cheap out on that part.
    2. The board has 32 GB of eMMC which is where the OS is installed
    3. There are very few writes to the SD card during normal operation (after initially loading content onto it). Running data (DBs, caches, log dirs, etc) for most applications is stored on the eMMC rather than the SD card or in some cases written to tmpfs (logs).
    4. The subset of content I loaded onto this from my main media server was all chosen because it has the most re-watch potential, so re-loading close to a TB of media isn’t something that’s going to happen too often. The largest write it sees is the semi-annual refresh of the full ~130 GB Wikipedia ZIM dump, but I may push that back to once a year. I’ve only updated it twice so far.
    5. Armbian assumes it’s going to run from SD card and does a pretty good job about minimizing the number of writes. Logs are all written to zram and only occasionally written to disk, it has no swap file, etc. If those are good enough to keep an SD card happy, they should keep an eMMC even happier.

    Basically, I tried my best to configure the SD card so that in day to day use it’s WORM (write once, read many) without actually going so far as mounting it read only. The data that gets synced daily from my main servers is incremental and usually has few changes.

    I’ve had PIs running for years without issue with the SD card mounted read only and retired them from service before the SD cards ever started showing issues. My Meshtastic EAS Alerter project is using one of those Pi Zero W2’s I retired from an older project and its 6 year old SD card.

    This is actually the second iteration. Originally I attached a 1 TB SSD via a USB->NVMe enclosure. That worked, but also made the unit sprawl which was something I wanted to trim down in the final version. It worked but had random glitches and instability that I initially chalked up to the board and/or Armbian. I didn’t realize it was EMI from the Wi-Fi coming in through the USB cable until after I switched to the 1 TB SD card. That’s why I added some ghetto shielding to the power cable for lack of having ferrite beads on hand lol.

    Should the SD card prove problematic over time, I can always go back to the USB->NVMe solution and lose its “keychain” form factor.

       /_\  _ _ _ __ | |__(_)__ _ _ _  
      / _ \| '_| '  \| '_ \ / _` | ' \ 
     /_/ \_\_| |_|_|_|_.__/_\__,_|_||_|
                                       
     v25.11.2 for BananaPi BPI-M4-Zero running Armbian Linux 6.12.58-current-sunxi64
    
     Packages:     Ubuntu stable (noble)
     Updates:      Kernel upgrade enabled and 52 packages available for upgrade 
     WiFi AP:      SSID: (BananaAP), channel 6 (2437 MHz), width: 20 MHz, center1: 2437 MHz
     IPv4:         (LAN) 192.168.5.1, 10.10.10.15 (WAN) 192.168.1.12
     Containers:   postgres_postgres_1
    
     Performance:  
    
     Load:         4%           	 Uptime:       18 weeks, 22 hours, 49 minutes	 Local users:  2           	
     Memory usage: 45% of 3.83G  	 Zram usage:    74% of 1.91G  	
     CPU temp:     63°C           	 Usage of /:   35% of 29G    	
     RX today:     6 GiB