Welcome to ShieldedBytes, where cybersecurity meets clarity. This blog offers practical insights, best practices, and in-depth discussions to help you navigate the ever-evolving digital landscape securely.

Explore topics like data protection, network defense, secure coding, and more—all tailored for professionals seeking reliable, actionable advice.

Start exploring, stay informed, and take control of your digital security.

When /usr Shows 100 % Used but df Says Space Is Fine: Spotting Inode Exhaustion

Why Inode Exhaustion Happens

On a busy server you’ll often see df still showing plenty of space, but df -i screaming 100 % inode usage on a mount like /usr. The kernel will happily refuse to create any more files, even though there’s room on disk. The culprit is usually a deluge of tiny files—think logs, temp data, or a mis‑configured service that never cleans up.

Spotting the Problem Quickly

# Space vs. inodes
df -h /usr
df -i /usr

If the first command reports 20 GB free but the second is 100 % used, you’ve hit an inode shortage. Now find the directory that’s eating them.

[Read More]

When /tmp fills a 1‑GB VPS in 15 minutes – how a simple tmpfs mount stops crashes

A 1‑GB VPS that dies in 15 minutes: the /tmp overflow problem

When a 1‑GB VPS runs a handful of services that write temporary files—apt‑get, pip, Docker, or even a simple web server—the /tmp directory can fill up faster than you think. Once the filesystem is full, many processes abort, the kernel starts killing tasks, and the machine can become unresponsive. The fix is surprisingly simple: mount /tmp as a tmpfs so it lives in RAM instead of on the disk.

[Read More]

How to use journalctl to pinpoint why a scheduled rsync job stalls during authentication

rsync scheduled jobs that stall on authentication: a journalctl‑first approach

When an rsync job launched by a systemd timer stops at the authentication step, the first place to look is the journal. The logs contain every attempt to open a connection, every key exchange, and every error message that the ssh daemon emits. With the right filters you can turn a vague “stalled” symptom into a concrete failure reason.

1. Know the unit that runs your rsync

Most modern distributions ship a template unit [email protected] that is started by a timer such as [email protected]. The instance name encodes the target host, e.g. [email protected]. Check the status:

[Read More]

Fixing GNOME’s broken audio output after an ALSA upgrade

GNOME audio stops after an ALSA upgrade – how to diagnose and fix

When a distro bumps the ALSA stack, the first thing that usually goes wrong is the desktop audio. In GNOME you’ll see “no audio” or a muted‑looking volume slider that actually reports a non‑zero level. The root cause is a mismatch between the kernel‑level ALSA driver and the user‑space libraries that PipeWire (the default audio server in GNOME 45+) talks to. Below is a practical, step‑by‑step walk‑through that covers the most common culprits, how to confirm them, and how to fix the issue without rolling back the whole upgrade.

[Read More]

When systemd‑resolved ignores /etc/hosts entries for local subdomains

Why /etc/hosts still matters

Even with systemd‑resolved becoming the default in most modern distros, that old /etc/hosts file is still the fastest way to pin a name to an IP on a single box or a tiny LAN. I’ve seen people drop the file entirely, thinking DNS is always the answer, and then run into a maze of “host not found” errors. The culprit? systemd‑resolved quietly skipping some /etc/hosts entries—especially the ones that look like subdomains of a local domain.

[Read More]

How to Fix Permission‑Denied Errors When Mounting Host Paths in Rootless Podman Containers

Why “Permission‑Denied” Pops Up When You Bind‑Mount in Rootless Podman

Rootless Podman runs containers as an unprivileged user. That’s great for security, but it also means the container’s view of the host filesystem is filtered through the user‑namespace mapping. When you try to bind‑mount a host path that the container’s UID/GID can’t access, the mount silently fails and the container reports a permission‑denied error. The problem is not the mount itself; it’s the mismatch between the host’s ownership/SELinux context and the container’s user namespace.

[Read More]

When initramfs drops into emergency mode after a kernel upgrade: how to recover the root partition on Ubuntu 24.04

After a kernel upgrade, Ubuntu 24.04 can sometimes drop straight into emergency mode if the initramfs can’t mount the root filesystem. The prompt usually looks like:

Emergency mode
You are in emergency mode. The root filesystem is mounted read‑only.

Below is a practical walk‑through of the most common culprits and how to bring the root back online without compromising security.

Why emergency mode happens

  • UUID mismatch – The kernel’s root= parameter points at a UUID that no longer exists (think LVM snapshot churn or a fresh partition).
  • Missing drivers – The initramfs was rebuilt without the modules needed for your storage controller or filesystem.
  • Secure‑boot hiccups – A signed kernel gets rejected because the firmware can’t find the signing key or the initramfs isn’t signed.
  • Filesystem corruption – Bad blocks or a half‑finished update can stop the kernel from mounting the root.

The emergency shell gives you a minimal environment with the root filesystem mounted read‑only, which is perfect for debugging without risking further damage.

[Read More]

Granting Group Write Access on a Shared /srv/web Directory Using ACLs Without Changing File Ownership

The /srv/web directory is usually the spot where you keep static assets, CMS themes, or a shared workspace for a handful of developers. In most setups the files are owned by root or a dedicated web user, but the team still needs to edit or upload content without juggling ownerships. That’s where Access Control Lists (ACLs) come in handy: they let you grant a specific group write rights while keeping the original ownership hierarchy intact.

[Read More]