When /tmp fills a 1‑GB VPS in 15 minutes – how a simple tmpfs mount stops crashes

A 1‑GB VPS that dies in 15 minutes: the /tmp overflow problem

When a 1‑GB VPS runs a handful of services that write temporary files—apt‑get, pip, Docker, or even a simple web server—the /tmp directory can fill up faster than you think. Once the filesystem is full, many processes abort, the kernel starts killing tasks, and the machine can become unresponsive. The fix is surprisingly simple: mount /tmp as a tmpfs so it lives in RAM instead of on the disk.

[Read More]

How to use journalctl to pinpoint why a scheduled rsync job stalls during authentication

rsync scheduled jobs that stall on authentication: a journalctl‑first approach

When an rsync job launched by a systemd timer stops at the authentication step, the first place to look is the journal. The logs contain every attempt to open a connection, every key exchange, and every error message that the ssh daemon emits. With the right filters you can turn a vague “stalled” symptom into a concrete failure reason.

1. Know the unit that runs your rsync

Most modern distributions ship a template unit [email protected] that is started by a timer such as [email protected]. The instance name encodes the target host, e.g. [email protected]. Check the status:

[Read More]

When systemd‑resolved ignores /etc/hosts entries for local subdomains

Why /etc/hosts still matters

Even with systemd‑resolved becoming the default in most modern distros, that old /etc/hosts file is still the fastest way to pin a name to an IP on a single box or a tiny LAN. I’ve seen people drop the file entirely, thinking DNS is always the answer, and then run into a maze of “host not found” errors. The culprit? systemd‑resolved quietly skipping some /etc/hosts entries—especially the ones that look like subdomains of a local domain.

[Read More]

How to Fix Permission‑Denied Errors When Mounting Host Paths in Rootless Podman Containers

Why “Permission‑Denied” Pops Up When You Bind‑Mount in Rootless Podman

Rootless Podman runs containers as an unprivileged user. That’s great for security, but it also means the container’s view of the host filesystem is filtered through the user‑namespace mapping. When you try to bind‑mount a host path that the container’s UID/GID can’t access, the mount silently fails and the container reports a permission‑denied error. The problem is not the mount itself; it’s the mismatch between the host’s ownership/SELinux context and the container’s user namespace.

[Read More]

Granting Group Write Access on a Shared /srv/web Directory Using ACLs Without Changing File Ownership

The /srv/web directory is usually the spot where you keep static assets, CMS themes, or a shared workspace for a handful of developers. In most setups the files are owned by root or a dedicated web user, but the team still needs to edit or upload content without juggling ownerships. That’s where Access Control Lists (ACLs) come in handy: they let you grant a specific group write rights while keeping the original ownership hierarchy intact.

[Read More]

Hardening a Home Assistant Docker Container with User Namespaces and Read‑Only Volumes

I only have the opening paragraph of the article. To rewrite it while keeping all the commands, links, and the final TAGS line intact, I’ll need the complete draft. Could you paste the rest of the article (or at least the sections that follow the “Enable user namespaces” heading)? Once I have the full text, I can apply the style and technical preservation rules you specified.