LFCS — Linux Foundation System Administrator
Configuring and Reading Addresses, Names and Routes
Goal
You write a static address configuration file, check the name resolution path segment by segment, and read sockets and routing to make a summary.
Why it matters
Steps 1–2 of this lab are exactly the procedure to prevent recurrence of an incident that actually killed a cluster in the author's homelab. When a DHCP lease renewal changed the control plane's address, it fell out of line with the certificate SAN and the apiserver could not start. What was learned then is that dhcp4: false alone is not "fixed". Because cloud-init regenerates the network configuration at every boot, you have to block that generation too, and only when you also do the DHCP reservation on the router as a set does the address become fixed.
The remaining steps are a process of getting the diagnostic order into your hands. The point where the results of getent and dig diverge is the problem segment, and the socket state from ss and the default route from ip route are the evidence that confirms "up to here it is normal". In this environment ping and iptables are blocked, so instead of checking reachability you train judging only from configuration files and observation tools.
Steps
- Write a netplan configuration in
/root/lfcs-net/01-static.yaml.network.versionis 2, the interface isenp3s0,dhcp4: false, the address is10.0.0.120/24, the default route isto: defaultandvia: 10.0.0.1, and the nameservers are10.0.0.1and1.1.1.1. - In
/root/lfcs-net/99-disable-network-config.cfg, write the content that turns off cloud-init's generation of network configuration. On a real server you would put this file under/etc/cloud/cloud.cfg.d/. - Add an entry to
/etc/hostswith the address10.0.0.120, the canonical namecp-1.homelab.internal, and the aliascp-1, and save the output ofgetent hosts cp-1to/root/lfcs-net/getent.txt. - In
/root/lfcs-net/resolv-summary.txt, write two lines based on/etc/resolv.conf:nameservers=<nameserver 줄 개수>andndots=<옵션 값 또는 none>(nameservers= followed by the number of nameserver lines, and ndots= followed by the option value or none). - Start one TCP listener on
127.0.0.1:8087, and put the local addresses of the sockets currently in LISTEN into/root/lfcs-net/listen.txt, one per line. - In
/root/lfcs-net/route.txt, write two lines:default_via=<기본 경로의 게이트웨이 또는 none>andprimary_iface=<기본 경로가 나가는 장치>(default_via= followed by the default route's gateway or none, and primary_iface= followed by the device the default route goes out through). - In
/root/lfcs-net/nsswitch.txt, write one line:hosts=<'/etc/nsswitch.conf' 의 hosts 행 값들>(hosts= followed by the values of the hosts line in '/etc/nsswitch.conf'). Separate the values with a single space. - In
/root/lfcs-net/firewall-plan.txt, write five rules in the format<동작> <프로토콜> <포트> <출발지>(action, protocol, port, source) in exactly the order below.
allow tcp 22 10.0.0.0/24
allow tcp 6443 10.0.0.0/24
allow tcp 80 0.0.0.0/0
allow tcp 443 0.0.0.0/0
deny any any 0.0.0.0/0
Notes
- You can make the listener by starting
python3 -m http.server 8087 --bind 127.0.0.1in the background. ss -ltnHshows only TCP sockets in LISTEN, without a header. The local address is the fourth column.getentgoes through the whole name service switch path, butdiglooks only at DNS. If their results differ, the culprit is not DNS.- A common mistake: if you put the default deny rule first, you cut your own connection before reaching the allow rules that follow.
netplan static address configuration
Write a netplan configuration in /root/lfcs-net/01-static.yaml. network.version is 2, the interface is enp3s0, dhcp4: false, the address is 10.0.0.120/24, the default route is to: default and via: 10.0.0.1, and the nameservers are 10.0.0.1 and 1.1.1.1.
netplan is YAML and the top-level key is network. Under the interface go the key that turns off DHCP, the address list, the route list, and the nameservers. Write the prefix length together with the address.
Turning off cloud-init network configuration
In /root/lfcs-net/99-disable-network-config.cfg, write the content that turns off cloud-init's generation of network configuration. On a real server you would put this file under /etc/cloud/cloud.cfg.d/.
One line is enough. Set the key that stops cloud-init from regenerating the network configuration to a disabled value.
The hosts entry and the getent check
Add an entry to /etc/hosts with the address 10.0.0.120, the canonical name cp-1.homelab.internal, and the alias cp-1, and save the output of getent hosts cp-1 to /root/lfcs-net/getent.txt.
One line of the hosts file is in the order address, canonical name, and then alias. For the check, use a tool that goes through the whole name service switch, not one that looks only at DNS.
Summarizing the resolver configuration
In /root/lfcs-net/resolv-summary.txt, write two lines based on /etc/resolv.conf: nameservers=<nameserver 줄 개수> and ndots=<옵션 값 또는 none> (nameservers= followed by the number of nameserver lines, and ndots= followed by the option value or none).
Count the number of lines that start with nameserver, and find the dot-count threshold in the options line. If that item is absent, write none.
Start a listener and make a socket list
Start one TCP listener on 127.0.0.1:8087, and put the local addresses of the sockets currently in LISTEN into /root/lfcs-net/listen.txt, one per line.
You can start a simple server with Python's built-in module, and there is an option that binds the address to loopback. If you use the option that extracts the socket list without a header, processing is easy.
Parsing the default route
In /root/lfcs-net/route.txt, write two lines: default_via=<기본 경로의 게이트웨이 또는 none> and primary_iface=<기본 경로가 나가는 장치> (default_via= followed by the default route's gateway or none, and primary_iface= followed by the device the default route goes out through).
There is a subcommand that shows only the default route. From the output, pull out the values after the keywords that indicate the next hop and the outgoing device.
Recording the name resolution order
In /root/lfcs-net/nsswitch.txt, write one line: hosts=<'/etc/nsswitch.conf' 의 hosts 행 값들> (hosts= followed by the values of the hosts line in '/etc/nsswitch.conf'). Separate the values with a single space.
Copy the values of the line that starts with hosts as they are, separated by a single space. This listing order is the query order.
Firewall rule design document
In /root/lfcs-net/firewall-plan.txt, write five rules in the format <동작> <프로토콜> <포트> <출발지> (action, protocol, port, source) in exactly the order below.
Rules are evaluated from the top. Open the management access port first and put the default deny at the very end so that you do not lock yourself out remotely.