There’s a command line in the gofi post I wrote ten days ago that has been quietly bugging me ever since I hit publish:
gofips -H 10.20.30.1 -k --get > hosts.conf
Look at that -k. That’s me telling the tool “don’t bother checking the TLS certificate.” And the part you can’t see is worse: my UniFi admin username and password, sitting in environment variables. Both of those were compromises I made to get the thing working. Neither of them sat well.
Here’s a thing I’ve quietly hated for years: managing static IP assignments and DNS names for the little fleet of gear on my network. Every homelab has it — the Pi in the garage, the shop printer, the sensor node in the attic, the pool controller. You want them at known addresses with known names. And the “old-school” way to get that is to stand up a DHCP server and a DNS server and keep them in sync. Since my network has tens of BrightSign devices in addition to my hobby robotics devices, this becomes actual work.
Tl;dr: read the web instead of Linux for Networking Professionals. This book is a broad, shallow coverage that is probably more easily learned from web pages for free.
I’m revisiting why I don’t like MQTT, and what I am doing about it.
SSH tunnels are basically indistinguishable from magic.