r/linuxadmin • • 2h ago

Rusty on Linux, moving from test automation into DevOps. Is a Linux cert (LFCS/RHCSA/Linux+) worth it, or should I just get the hours in?

7 Upvotes

I've been in the industry about 14 years, mostly test automation, and I'm moving toward DevOps/platform engineering. Day to day I work with GitLab CI/CD, Terraform, Helm/Kubernetes deployments, and some AWS. I'm currently leading a migration of a large number of services onto Kubernetes.

The problem is that I work at a .NET/Windows shop, so I've barely touched Linux in years. I took a basic self-check recently (systemctl/journalctl, finding what's on a port, disk usage, apt, file ownership) and did badly. I knew roughly which tool to reach for but not the actual commands.

My employer pays for certs. My current plan is KCNA, then CKA, Terraform Associate, and AWS Solutions Architect Associate. I wasn't planning on a Linux cert, just a refresher course plus using WSL daily and running a homelab.

Questions:

  1. Is LFCS, RHCSA, or Linux+ worth adding for someone aiming at cloud/platform roles, or does CKA cover the "can use Linux" signal well enough?
  2. If one is worth it, which, and would you do it before or after CKA?
  3. For those who came from a Windows-heavy background, what got your Linux skills to stick when your job didn't require it?
  4. How much Linux do you really use in a platform role, compared with what the certs test?

Not looking for reassurance, honest takes welcome.


r/linuxadmin • • 2h ago

ex200 simulador - prepara tu examen RHCSA

4 Upvotes

hola!...si estás preparando tu examen EX200 para Red Hat System Administrator, aquí te dejo rhcsa-sim, un simulador del examen con ejercicios de prueba para que practiques en una VM(no en tu host, por seguridad).
Está probado en almalinux10 pero no debería haber diferencias con RH10.

Es un proyecto opensource así que bienvenida las colaboraciones.

https://github.com/xilen0x/rhcsa-simulator/tree/main


r/linuxadmin • • 1h ago

Crashing after running yum update. On XCP-NG

Thumbnail
• Upvotes

r/linuxadmin • • 10h ago

Super best resource to prep for RHCSA (RHEL-10)

Thumbnail
0 Upvotes

r/linuxadmin • • 20h ago

GitLab patched a CVSS 9.9 sandbox escape in the self-hosted AI Gateway (CVE-2026-90970): what the patch notice does and doesn't say

0 Upvotes

Based on GitLab's own patch release notice from October 2 (docs.gitlab.com), plus Security Affairs, BleepingComputer and The Hacker News coverage, here is the architectural impact.

What is confirmed by GitLab: an authenticated user with Duo Agent Platform access can submit a crafted flow configuration, escape the prompt template sandbox, and run arbitrary commands on a self-hosted AI Gateway. CVSS vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Affected: 18.1.6 before 19.2.4, 19.3 before 19.3.2, 19.4 before 19.4.1. GitLab-hosted gateways were fixed before the announcement.

What is not confirmed: exploitation in the wild (none reported as of Oct 3), the template engine, and whether a workaround exists. The Hacker News notes no workaround and no fixed version below 19.2.4 in the advisory.

The design question I keep coming back to: the gateway sits between GitLab and your model backends, and user-authored flow configs are processed on that host. What does your gateway container have mounted and what can it reach on the network?

For people running Duo Self-Hosted: who has Duo Agent Platform access in your org, and do you review flow configs before they hit the gateway?

Background on a similar failure class (AI workflow tool, code validation): https://www.techgines.com/post/langflow-ssrf-vulnerability-cve-2026-12944 Full write-up: https://www.techgines.com/post/gitlab-ai-gateway-vulnerability-cve-2026-90970


r/linuxadmin • • 2d ago

Title: diskwatch 0.5.8: terminal disk diagnostics

Post image
32 Upvotes

diskwatch is a read-only TUI for seeing what your disks are doing. Eight tabs: devices, volumes, filesystems, I/O, SMART, hot files, insights. Single host, nothing to configure.

What's new:

- Windows support, with live per-disk I/O metrics

- Hot Files shows which process is writing to each path

- A config file, and you choose the Hot Files roots

- Adjustable refresh speed

- Arrow keys switch tabs everywhere

- An armv5te build, tested on an Iomega ix2-dl NAS

- Follows your terminal's palette

Written in Rust, MIT licensed. Windows is the newest part, so bug reports from Windows users are the most useful right now.

https://github.com/matthart1983/diskwatch


r/linuxadmin • • 2d ago

X11 - RHEL 10.2 - ISOLATED Passthrough

4 Upvotes

Hoping someone can help me out with an issue I've been having for a long while.

I'm running RHEL 10.2 Gnome 49, trying to use an X application inside of a podman container with a custom network.

"podman network create --internal pod_dev"

I pass in all the environment variables and files that I know and what AI also says i need. I can not for the life of me get the x application to display.

It works in fedora 44, and Ubuntu, but RHEL 10 is kicking my butt.. if i do --net=host is am able to get the x application to work, but I have to have the container have its own IP.

And advice at all is appreciated, I've probably spent over 100 hours trying different combinations of flags and ways to run.


r/linuxadmin • • 2d ago

Zammad zero-days (CVE-2026-102489/102490) behind the DIVD breach: what's confirmed, what the vendor disputes

0 Upvotes

Based on the case files DIVD published (DIVD-2026-00014 and -00015) and Zammad's own forum statement from Oct 1, here is where things stand.

DIVD says first access was Sept 21. The chain is a session hijack leading to RCE as the zammad user (CVE-2026-102489, 6.3.0 to 6.5.4) plus a local escalation to root (CVE-2026-102490). CISA put both in KEV on Oct 2.

Where sources disagree: Zammad says 102489 is only exploitable on 6.5 and older (EOL), hardened in 7.2.0, and that DIVD gave it no details on 102490. DIVD's own page is inconsistent on the 102490 range ("all versions" vs 1.5.0 to 7.1.0-alpha). The AI-agent attribution is DIVD's reading of its logs; no full logs or model name published.

What I'd do: upgrade to 7.2.0, copy the logs first, run DIVD's IoC script (read it first), segment the helpdesk.

Question for people running self-hosted helpdesks: do you treat ticketing as tier-0 (same segment rules as your IdP and mail gateway), and what does your credential rotation look like if the box is rooted?

https://www.techgines.com/post/zammad-zero-day-cve-2026-102489


r/linuxadmin • • 3d ago

Is there any way to know whether a vulnerable library is actually loaded in a running process, without instrumenting the app?

29 Upvotes

Trying to work out what's technically possible here versus what's marketing, and this sub tends to be good at that distinction.

The situation: a container image has a CVE in, say, a compression library six levels deep in the dependency tree. The scanner flags it because the package is on disk. What I want to know is whether the running process has actually mapped that library, or whether it's just sitting in the filesystem never being opened.

What I understand so far:

  • For dynamically linked stuff you can read /proc/<pid>/maps and see what's actually mapped. That seems definitive for "is this .so loaded right now".
  • For statically linked or vendored code that doesn't help at all, since there's no separate object to observe.
  • For interpreted languages (our case is mostly Python and Node) the module is loaded by the runtime, so you'd need to either introspect the interpreter or watch the file opens. So my questions:
  • Is watching openat/mmap at the kernel level actually a reliable proxy for "this code is in use", or does it produce garbage because package managers, health checks and startup scans touch everything?
  • For Python/Node specifically, does anyone do this without an in-process agent? I really don't want a language agent in every service.
  • Is there a meaningful difference between "loaded" and "the vulnerable function was called"? Because those feel like very different claims and I suspect products blur them. Not asking what to buy, asking what's actually detectable from outside the process.

r/linuxadmin • • 2d ago

LFCS practice

8 Upvotes

Hi everyone,

I’m currently preparing for the LFCS exam and I’m interested in hearing which hands-on learning resources you would recommend.

At the moment, I’m taking Mumshad’s course and working through the included exercises.

I’m already aware of Killer.sh, but the 36-hour access period isn’t really enough for me.

Do you know of anything similar to Killer.sh that offers good hands-on exercises specifically for the LFCS exam? Maybe a GitHub repository or something similar?

Thanks for your help!


r/linuxadmin • • 2d ago

Turn any Linux edge node into a cryptographically verifiable security enclave

Thumbnail github.com
0 Upvotes

yo so i did a thing,

I built a lightweight, modular edge defense tool called Micro-SOC (souljha213/micro-soc) to see if I could run a self-contained security enclave entirely out of volatile memory without relying on heavy enterprise agents.

Here is a breakdown of how it's structured:

RAM Cloaking: Shifts operational states and active logs straight into /dev/shm to keep disk footprints clean.

Process Masking: Disguises execution identity under low-level kernel worker names ([kworker/u4:3]).

Verifiable Forensics: Uses a local Merkle-linked chain (ledger.chain) for tamper-evident logging.

TUI Interface (stos): Built a real-time terminal cockpit using Textual to monitor swarm health, metrics, and mesh connections locally.

Would love to hear technical feedback or critiques on how you guys approach stealth logging and edge isolation.


r/linuxadmin • • 3d ago

Do control panels keep junior admins from learning Linux?

51 Upvotes

My junior admins is quick with the panel, but when a firewall rule broke SSH yesterday he didn't know how to check ufw from a shell. I use BeAdmin myself and have nothing against panels, but I learned iptables by breaking it with no GUI around, and I'm not sure he'll ever get that practice.

Have you seen this with people who started on panels, or am I just being an old man about it?


r/linuxadmin • • 2d ago

FortiMail CVE-2026-104286: unauth file write, exploited, patches not out yet. What's in Fortinet's IoC list

2 Upvotes

Based on Fortinet's PSIRT advisory FG-IR-26-175 (published Oct 1) and BleepingComputer's reporting, here is the architectural impact.

Fortinet describes path traversal (CWE-22) plus NULL byte handling (CWE-158) in the GUI, giving unauthenticated arbitrary file write. Affected: 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, 7.2.0-7.2.9. Fixes (8.0.2, 7.6.7, 7.4.9) are marked upcoming, and 7.2 gets a branch-migration answer. Workaround is config system encryption ibe / set status disable, or remove internet access to the management interface.

The IoCs include an added /data/etc/ld.so.preload and /data/lib/liblog.so, and a sample log of an archive account pointing at a remote IP. Fortinet doesn't explain the write-to-execution step. Some CVE feeds also list 7.0 as affected while the advisory doesn't, so I'd verify that one.

Question for people running FortiMail or similar gateways: do you keep the management GUI off any internet-routable interface by policy, or does it depend on who deployed it? And for those who rely on IBE, what breaks when you disable it?

Background on the same class of problem: https://www.techgines.com/post/fortimail-zero-day-cve-2026-104286


r/linuxadmin • • 2d ago

LayerSmith — a self-hosted container image builder, with air-gap exports

0 Upvotes

I've been working on LayerSmith, an open-source web UI for building container images with Docker or Podman.

You pick a Linux distribution and what you need the image for — development, Linux admin, network tools, Ansible, Kubernetes, OpenShift, or a custom setup. It handles distro-specific packages and shows you the generated Containerfile before building. You can also edit it, import an existing Dockerfile, or add your own packages, files and scripts.

A big part of the project is making images easier to carry into air-gapped environments: pinned base images, recorded build details, and export bundles containing the image, checksums and installation instructions.

We've recently added LLM training and fine-tuning profiles too, including LoRA/QLoRA, advanced PyTorch training and LLaMA-Factory. These use hash-locked dependencies and run offline checks after building, including a small CPU training test. Model weights and datasets are brought separately.

Curious how others handle building and maintaining images for disconnected environments, and what parts of that workflow are still a pain.

https://github.com/r0lfi/layersmith


r/linuxadmin • • 3d ago

VictoriaLogs for log indexing?

6 Upvotes

has anyone used victorialogs? Im currently using Graylog v7, local single instance on 5TB disk

using filebeat to ship logs to GL indexer

wondering how victorialogs performs comparatively. Anyone used it at all or have any feedback?

Thanks


r/linuxadmin • • 3d ago

Mirroring Repository

3 Upvotes

I am wanting to mirror a Debian repository onto my work network. Will be managing about 2500 machines running the exact same software on each. These are all servers running a containered player showing advertising on digital displays.

I have never mirrored a repo before, so I am curious, should I use apt-mirror, aptly, or something different?

The containers are Incus and have Debian as the base as well.

EDIT- looks like apt-mirror can be crossed off as it has not been updated in several years.


r/linuxadmin • • 3d ago

Cisco SD-WAN Manager CVE-2026-76504: auth bypass via URI encoding, exploited, no workaround

5 Upvotes

Based on Cisco's own advisory (cisco-sa-sdwan-webauth-xr8beuuU, published Sept 30), here's the architectural impact.

The flaw is in the Manager's API session authentication: improper handling of URI encoding lets a request skip an auth rule and land as admin. CVSS 9.8, all configurations affected, and Cisco PSIRT says it's seen exploitation. Cisco's IOC example is a POST to /%6a_security_check, but the advisory says any one encoded character works. Cisco says the bug was found while resolving a TAC case, and published no actor or victim details.

Hunting per Cisco: serviceproxy-access.log for j_security_check from unknown IPs, and vmanage-server.log for those requests against viptela-reserved- users. Cisco notes these can appear in normal operation, so baseline first.

Question for people running on-prem Managers: how are you restricting Manager reachability today, and did the May/June SD-WAN fixes change your exposure model at all? I'm curious whether anyone terminates the Manager behind a reverse proxy that normalizes paths.

https://www.techgines.com/post/cisco-sd-wan-manager-authentication-bypass-cve-2026-76504

Background from our earlier SD-WAN piece: https://www.techgines.com/post/cve-2026-20182-the-cvss-10-0-flaw-that-hands-attackers-the-keys-to-your-entire-sd-wan-fabric


r/linuxadmin • • 4d ago

how to learn project based learning the right way?

7 Upvotes

So guys, i am learning system administration from the past 3 months. i am mostly done with the foundational part and i am feeling confident that i should start learning by doing projects. i am thinking about building a homelab and setting up things.

so, i pick up a project idea ( for example, setting up a web server), and i want to do that. but i don't know what to do (i do know, but vaguely. the details are missing)? so i think about looking up online for the steps to do it. but then i find myself thinking if am walking into tutorial hell.

i don't know what to do, because i find both advices kind of conflicting. how to do project based learning as a beginner without looking into guided projects in a way that it does make it into tutorial hell? is the guided project way the way we are supposed to learn? if so, then why do people advice not to lookup tutorials?


r/linuxadmin • • 4d ago

how much time during a typical workday is spent on testing, troubleshooting snd doing root-cause analysis for an l1/l2/l3 engineer?

4 Upvotes

Hi i wanted to ask - for an L1/L2 engineer roughly how much time during a typical workday is spent on testing, troubleshooting snd doing root-cause analysis, and identifying and documenting issues?

And if required do these engineers also dive deep into software if required or do they just stay at the infra level?

I am trying to apply for l1 and l2 level roles and freelance opportunities and right now building case studies showing my abilitiy to identify, doing root cause analysis and document my findings of communjty problems like wordpress server issues , nginx , apache , openlightspeed forum issues.

Do you think this is worth it for bulding my portfolio?


r/linuxadmin • • 5d ago

Passed LFCS!!

39 Upvotes

LFG. Very happy with my score too (88%!!), I was so nervous for this exam, happy to have gotten my first Linux cert. RHCSA next 🫡


r/linuxadmin • • 5d ago

Kiteworks asked customers to shut down servers on a federal tip. No CVE, no IOCs. What do you do with that?

12 Upvotes

Based on the press release Kiteworks published Sep 25 (updated Sep 27), plus reporting from SecurityWeek, Sophos CTU, TechCrunch and Cybersecurity Dive: the vendor got a warning from federal intelligence authorities and told self-managed customers to power down. Kiteworks-hosted systems were shut down by the vendor. The advisory was lifted Sep 27, and Kiteworks says nothing was compromised and every known vulnerability is addressed in 9.5.1.

Two things bother me. The window length is reported inconsistently (6h vs 9h). And SecurityWeek's Advanced Forms detail rests on one customer email, while TechCrunch quotes Kiteworks saying it couldn't rule out other access routes.

With no CVE and no IOCs, my baseline check is the running version, whether Advanced Forms is enabled, auth and admin logs from before the window, and unexpected egress from the appliance.

For those who run MFT: what's your runbook when a vendor says "turn it off tonight" and gives you nothing to hunt for?

https://www.techgines.com/post/kiteworks-shutdown-advisory


r/linuxadmin • • 5d ago

Inspecting a built runtime with an ephemeral SSH instance

0 Upvotes

Render’s ephemeral SSH mode starts a temporary instance from the service’s latest build. Disclosure: I work at Render.

This gives a different diagnostic target from ordinary SSH. render ssh SERVICE --ephemeral puts the shell on a new instance that receives no production traffic and does not run the service’s start command. That makes it useful for checking installed packages, compiled assets, file layout, or a one-off command against the built runtime without using a live process. It is not a replica of the running service: startup is skipped and there is no request traffic, so process state, sockets, and live heap behavior still require live-instance diagnostics.

Isolation from production compute does not make external systems read-only. Before mutating anything, inspect which environment variables and network resources the shell can reach; if production credentials are present, treat them as live and prefer read-only commands unless mutation is intentional.

The instance is removed when SSH disconnects or after 24 hours. It requires a compatible paid service with at least one successful deploy; distroless images cannot offer shell access. CLI 2.20+ supports --plan when the diagnostic needs a different compute size. For work that should outlive a shell session, the SSH documentation points to a one-off job instead.


r/linuxadmin • • 5d ago

wiki.linux-server-admin.com legit?

Thumbnail
0 Upvotes

r/linuxadmin • • 6d ago

WebKVM - A lightweight, web-based management UI for Libvirt and QEMU/KVM written in Go (15-30MB idle RAM)

Thumbnail gallery
16 Upvotes

r/linuxadmin • • 6d ago

Roadmap to becoming Linux Admin?

Thumbnail
3 Upvotes