Dorothea
    • Create new note
    • Create a note from template
      • Sharing URL Link copied
      • /edit
      • View mode
        • Edit mode
        • View mode
        • Book mode
        • Slide mode
        Edit mode View mode Book mode Slide mode
      • Customize slides
      • Note Permission
      • Read
        • Only me
        • Signed-in users
        • Everyone
        Only me Signed-in users Everyone
      • Write
        • Only me
        • Signed-in users
        • Everyone
        Only me Signed-in users Everyone
      • Engagement control Commenting, Suggest edit, Emoji Reply
    • Invite by email
      Invitee

      This note has no invitees

    • Publish Note

      Share your work with the world Congratulations! 🎉 Your note is out in the world Publish Note

      Your note will be visible on your profile and discoverable by anyone.
      Your note is now live.
      This note is visible on your profile and discoverable online.
      Everyone on the web can find and read all notes of this public team.
      See published notes
      Unpublish note
      Please check the box to agree to the Community Guidelines.
      View profile
    • Commenting
      Permission
      Disabled Forbidden Owners Signed-in users Everyone
    • Enable
    • Permission
      • Forbidden
      • Owners
      • Signed-in users
      • Everyone
    • Suggest edit
      Permission
      Disabled Forbidden Owners Signed-in users Everyone
    • Enable
    • Permission
      • Forbidden
      • Owners
      • Signed-in users
    • Emoji Reply
    • Enable
    • Versions and GitHub Sync
    • Note settings
    • Note Insights New
    • Engagement control
    • Transfer ownership
    • Delete this note
    • Save as template
    • Insert from template
    • Import from
      • Dropbox
      • Google Drive
      • Gist
      • Clipboard
    • Export to
      • Dropbox
      • Google Drive
      • Gist
    • Download
      • Markdown
      • HTML
      • Raw HTML
Menu Note settings Note Insights Versions and GitHub Sync Sharing URL Create Help
Create Create new note Create a note from template
Menu
Options
Engagement control Transfer ownership Delete this note
Import from
Dropbox Google Drive Gist Clipboard
Export to
Dropbox Google Drive Gist
Download
Markdown HTML Raw HTML
Back
Sharing URL Link copied
/edit
View mode
  • Edit mode
  • View mode
  • Book mode
  • Slide mode
Edit mode View mode Book mode Slide mode
Customize slides
Note Permission
Read
Only me
  • Only me
  • Signed-in users
  • Everyone
Only me Signed-in users Everyone
Write
Only me
  • Only me
  • Signed-in users
  • Everyone
Only me Signed-in users Everyone
Engagement control Commenting, Suggest edit, Emoji Reply
  • Invite by email
    Invitee

    This note has no invitees

  • Publish Note

    Share your work with the world Congratulations! 🎉 Your note is out in the world Publish Note

    Your note will be visible on your profile and discoverable by anyone.
    Your note is now live.
    This note is visible on your profile and discoverable online.
    Everyone on the web can find and read all notes of this public team.
    See published notes
    Unpublish note
    Please check the box to agree to the Community Guidelines.
    View profile
    Engagement control
    Commenting
    Permission
    Disabled Forbidden Owners Signed-in users Everyone
    Enable
    Permission
    • Forbidden
    • Owners
    • Signed-in users
    • Everyone
    Suggest edit
    Permission
    Disabled Forbidden Owners Signed-in users Everyone
    Enable
    Permission
    • Forbidden
    • Owners
    • Signed-in users
    Emoji Reply
    Enable
    Import from Dropbox Google Drive Gist Clipboard
       Owned this note    Owned this note      
    Published Linked with GitHub
    • Any changes
      Be notified of any changes
    • Mention me
      Be notified of mention me
    • Unsubscribe
    # OSMF OPS meeting 2024-03-21 Thursday 21 March 2024, 19:00 London time, unless rescheduled [Time in your timezone](https://www.timeanddate.com/worldclock/fixedtime.html?msg=OSM+Foundation+OPS+meeting+-++Thursday+21+March+2024&iso=20240321T19&p1=136&ah=1) [Countdown](https://www.timeanddate.com/countdown/generic?p0=136&iso=20240321T19&msg=OSM%20Foundation%20OPS%20meeting%20-%20%20Thursday%2021%20March%202024) [Online calendar](https://framagenda.org/apps/calendar/p/fce4xrpFGx7fMxz8) [Subscription to future events](https://framagenda.org/remote.php/dav/public-calendars/fce4xrpFGx7fMxz8?export) Frequency of meetings: every two weeks, on Thursday at 19:00 London time, unless rescheduled. [Video room](https://osmvideo.cloud68.co/user/dor-x99-y3m) ## Participants * Hrvoje * Guillaume * Paul * Grant ----- ## New action items from this meeting * [2024-03-21](https://hackmd.io/pnBMmOtbQHmweS2XqC8E6g?both) Paul to document in the ticket https://github.com/openstreetmap/operations/issues/518 that we will go with Znuny [Topic: OTRS] * [2024-03-21](https://hackmd.io/pnBMmOtbQHmweS2XqC8E6g?both) Grant to reply to Equinix, restating the issue in a brief form to them. [Topic: Equinix] * [2024-03-21](https://hackmd.io/pnBMmOtbQHmweS2XqC8E6g?both) Paul to open an issue about large wiki pages. [Topic: Large wiki pages] ----- ## Reportage ### Action item: 2024-03-07 Grant to open tickets about not forwarding incoming spammy tickets to other email servers, where they get bounced * 2024-03-07 ''Initial wording: "Grant to open a ticket about running our own IMAP server, to describe the problem and sample cases" [Topic: Running our own IMAP server] Consensus seemed to be that running our own IMAP server is not a good idea. **Issue:** we're being blacklisted for being spammers and this is related to: * we're accepting and forwarding genuine spam. * we don't rewrite headers, failing the SPF sender policy framework and * our systems are seeing spam come from ourselves. **Suggestions:** * Give to members of working groups and other Foundation bodies an @osmfoundation.org address. * OTRS: email notifications regarding new OTRS messages not including the content of the messages anymore. ** This will not work for DWG, as sometimes they reply from emails. **Other points mentioned during discussion** * SPF - has been addressed. * we shouldn't be forwarding certain messages via email, they should be injected into APIs. **Decision: Open multiple tickets for the different issues. There is already one for the forwarding aspect but not for the incoming spam and OTRS aspect.** ----- ### Action item: 2024-03-07 Grant and Guillaume to discuss further about the redundancy of gateway / IPv6 "private subnet". Benefit / "Cost" [Topic: Redundancy of Gateway / IPv6 "private subnet"] There was a long discussion. * UCL is the blocker. * A lot of the traffic that we pass over VPN could be now encrypted over TLS. * The gateway usually runs on the oldest machine in the rack. ** Not high priority but could go wrong. **Suggestions:** * Create an issue and possibly park it. * Drop this issue. **In favour of dropping this issue:** * Work required: There are multiple changes required in Chef/monitoring/networking stack, for a marginal improvement. * Network management: We would move some of the network management out of software control into our network layer stack, which is not ideal. * Prioritisation: There are more important tasks. * We have data on the reliability of the current set-up and it has not failed in over a decade. * Having out of band access only works via IPv6 with unknown reliability, is a blocker. * If we can't use IPv6 on our out of band network because of some of the out of band hardware that we have, then we'd have to run another parallel network. * Preference to spend time on Nginx and different backends, than designing Ipv6, which may not work with some of our equipment. * Not convinced there is a problem. **In favour of keeping this issue:** * It is a single point of failure, even if it hasn't failed in the past. * Presenting the issues we have helps with fundraising. **Other points mentioned during discussion:** * If what we're trying to achieve cannot be described in a GitHub ticket, then the issue is not actionable. * A solution came presented and the way it should be implemented was dictated, causing annoyance. * Conflicting suggestions on addressing the issue. Attempts to raise the issue for discussion were redirected to creating a GitHub ticket, while when proposing to create a ticket, advice was to discuss it. # Agenda ## OTRS https://github.com/openstreetmap/operations/issues/518 Grant will show results of his tests **Options:** * OTOBO * Znuny **OTOBO** * Docker-crazy, doesn't support podman. * Introduces new features, including search and elastic indexing. * Only supports the installation method and their containers, like Discourse does. * Work: ** Requires manual work, as it uses different DSL. ** We would have to convert their docker compose to Podman pods. Adding podman support to Chef will be helpful elsewhere. ** We would need time investment every time we need an upgrade, like we do with Mediawiki (new and default plugins/configuration/variables). * Concern: There is danger of closing their repositories and making it commercial. * Version 10.1 and have patch releases. * You have to run elasticsearch and probably Memcached. **Znuny** * Features stay close to the original. * Migration: ** it requires stepped migrations between versions. ** is a bit more painful, one-off sunk cost, but packaged in Debian. * Implementation: Stays close to the original. Required stepped migration. Upgrade smooth. Looks and feels like OTRS. * Debian package doesn't seem to be updated much, but this might be because the maintainer hasn't bumped the version yet. Supports version 6.5 (7 is out). * Search: Doesn't use Elasticsearch - pretty close to OTRS. ** New search plugin API, which relies on Elasticsearch. Has many options, not very well described, English documentation. * They have a long term supported version. * Wikimedia and a lot of open source groups moved from OTRS to Znuny. **OTRS** * We have used it for over a decade. * Most OTRS functionality seems to be currently done in plugins. * We use it pretty much like any small ticketing system, with some templates for responses, groups and queues. Consensus seemed to be: go with Znuny, as it seems better, with a straightforward upgrade path. <u>Other points mentioned during discussion</u> * It's a one-way decision. * Anything to ask the users? **Action item: Paul to document in the ticket https://github.com/openstreetmap/operations/issues/518 that we will go with Znuny** ----- ## DDOS attack * Increased 403s in Prometheus An individual emailed us saying that they found a security vulnerability, and requested Bitcoins, while DDOSing us from 5000-6000 IP addresses, from probably exploited servers. There were a few other people that received an identical email, a month ago. A UK mobile number was listed on the email. **Measures taken for the DDOS attack** 1. Tom put-in mod_evasive for high-requests rates. It worked but we accidentally blocked some mappers. Now it is reasonably tuned, 50 requests/sec upped to 150 req/sec. 2. If one continues with high request rates, fail2ban picks it up and they get blocked for a longer period after a certain period. **Requests blocked:** * Most are abusive. * Minority: Mapping parties or people behind a single IP address, so further fine-tuning of mod_evasive might be needed. ** Data: 2 such requests today (1 with Rapid). **mod_evasive** * Third-party package, heavily unmaintained. * Is on either on all requests or on none. * Can specify number of requests per time frame. * Cannot set-up multiple time-periods. * Has an allow list feature ("DDOS white list""), which we don't use at the moment. Could add IP addresses, and these do not enter into the counter and the counter never overflows. ** Unmaintainable long term. **Alternatives to using mod_evasive** * Mod-security which we can define policies for fine-grained access control. ** Issue: it's complicated. * Nginx. ** Has a fairly good, granular rate limiter built into it: can rate limit per any URL or a combination of headers and URL's. ** Tom has been looking into it. <u>Suggestion</u>: Replace mod_evasive. <u>Other points mentioned during discussion</u> * iD: gives a retry button - if you click it immediately, you get blocked for another 60 sec. * Wondering if there is a bug in iD that causes many requests. * Hard to work-out the limit. * mod_evasive is picking legitimate abuse. * If the high-requests rate continues, then fail2ban picks it up and blocks you for a longer period. ----- ## Equinix <u>Suggestion</u>: Restate the issue to the salesperson in a brief form. <u>Other points mentioned during discussion</u> * We were informed in November and the price increase was effective in January. * Equinix Foundation is managing donations, either monetary or providing staff time, to charitable organisations. <u>Other options</u> * Grant emailed the Equinix Foundation and received a response with some pointers. * Contact the salesperson and ask them to approach Equinix Foundation . * Ask the community whether anyone who works for Equinix wants to put us forward to the Equinix foundation as a charitable organisation they'd like to support. ** Probably the best option. **Action items:** * **Grant to reply to Equinix, restating the issue in a brief form to them.** * **OPS to ask the community whether anyone who works for Equinix wants to put us forward to the Equinix foundation as a charitable organisation they'd like to support.** ----- ## Large wiki pages <u>Issues</u> * The length of big OSM wiki pages pushes the limits of what Mediawiki can handle. * We occasionally get blocked from Wiki Commons, as sometimes our traffic is considered abusive, causing indexing scripts to fail. * People listing thousands of relations on a single page. <u>About Wiki Commons</u> We've enabled Wiki Commons, which allows us to easily embed images from wiki Commons into our wiki. * Front end: Visiting the Map Features page generates 150+ requests to Wiki Commons, for downloading images stored there. * Back end: Certain indexing tasks call out to Wiki commons. <u>Map features page</u> https://wiki.openstreetmap.org/wiki/Map_features * Calls a plethora of templated functions, ~ 1000. * Whenever there's a wiki problem, it seems to be related to map features. * It probably is not a good experience to be shown this big page, e.g. to new people at a mapping party. * Takes several seconds to load (20'' during the meeting). * Pressing the "edit" button (not the "edit source" button) will crash your browser and there is a hard-coded limit in the current version of Mediawiki of 30''. * ~ 5000 transcludes in. <u>Suggestions</u> * Put limits on the page (e.g. requiring to break the page into subcategories) or to the number of embeds or their size. * Put a front-in cache to all Mediawiki instances. ** We had one and it became complex to manage and we removed it. ** Caching works best for logged out users, but as soon as you log in, then you being cached per user. * Add plugins that do caching. ** They are semi-supported. * Produce a static HTML page, instead of having the contents in a CMS system. * Open an issue. <u>Other points mentioned during discussion</u> * Mediawiki caching is for an infinite amount of time. Mediawiki is sending purges to clear it. Works for their architecture but only for them. * There is a function/category to show long pages. * Not a good experience to be shown such a long page at first mapping party. ** Being shown a big list of things that can be mapped, helps new mappers understand that OSM is not only about mapping streets. * Map features: Opening the "edit" not "edit source" will crash the browser. 20 sec to load.Hard-coded limit is 30 sec. There was a plan to move it to the Semantic wiki. **Action item: Paul to open an issue about large wiki pages.** Post meeting addition: https://github.com/openstreetmap/operations/issues/1046 ----- ### Editor policy Deferred. ----- ### Faffy status https://hardware.openstreetmap.org/servers/faffy.openstreetmap.org/ Development and “tool” server HPE ProLiant DL360 Gen10 <u>Current status</u> * querying any of the individual disks we get multiple gigs per second. * querying MDRAID we get less than a megasecond. * disk usage was ~ 99% <u>Issue could be related to</u> * hitting a kernel performance bug. * MDRAID NVMe issue. * the file system could have become massively fragmented, particularly in the directory indexes. <u>Suggestions</u> * Remove a disk, wipe it, secure erase it and then re-add it and check performance. * Rewrite a file with zeros - Grant tried this. <u>Grant has tried</u> * Upgraded bios. * Removed iLO card. * Removed power-cap. * Upgraded firmware. * Looked at kernel parameters related to tuning performance and schedulers. * e4fsck directory optimise. * Defragemented the file system. * Checked Raid6 system - no mismatches - check was very fast. Machine is a bit faster now, but not near the performance it should have. <u>Other points mentioned during discussion</u> * Haven't done test write performance per disk. * Bottleneck hard to decipher from metrics in Prometheus ----- ## Open Ops Tickets Review open, what needs policy and what needs someone to help with... https://github.com/openstreetmap/operations/issues https://github.com/orgs/openstreetmap/projects/1 https://github.com/orgs/openstreetmap/projects/1/views/2?filterQuery=-is%3Aclosed ## Action items * 2024-03-07 Grant to open tickets about not forwarding incoming spammy tickets to other email servers, where they get bounced. [Topic: email notifications getting marked as spam] * 2024-03-07 Grant and Guillaume to open a github issue about the redundancy of gateway / IPv6 "private subnet". Benefit / "Cost" [Topic: Redundancy of Gateway / IPv6 "private subnet"] * 2024-02-08 OWG to review the Editor policy during one of the next calls and possibly vote on it. [Editor Policy adding to OpenStreetMap.org] * 2023-11-30 Grant to revisit the "policy for purchasing" document, which currently is focused on specs, and add information such as the process for obtaining approval for purchases. [Reportage] Added info: Who Approves / Steps etc -> Grant to create GitHub ticket * 2023-11-30 OPS to review the issue of spam reports to ISPs in 6 months (May 2024) -> Grant to create GitHub ticket * 2023-05-18 Paul to start an open document listing goals for longer-term planning. [Topic: Longer-term planning] ## OPS pads for 2024 meetings * [2024-03-07](https://hackmd.io/ktAqRslLTFmAn8PuGnnVRA) - https://osmfoundation.org/wiki/Operations/Minutes/2024-03-07 * [2024-03-21](https://hackmd.io/pnBMmOtbQHmweS2XqC8E6g) * [2024-04-04](https://hackmd.io/O2KUiG9RQXSk9vMAgPA7Dw) * [2024-04-18](https://hackmd.io/_FT8I1sSRL2UNVDM94IbQA) * [2024-05-02](https://hackmd.io/6VQhtcbqRYKDSwx1i-fpWg) * [2024-05-16](https://hackmd.io/XFtol8teRoinL34n7h2bcA) * [2024-05-30](https://hackmd.io/IM0d3VWhTqWcY-FPwgXy-A) * [2024-06-13](https://hackmd.io/rDX4FuDfRa-0Trc0IKFJ5Q) * [2024-06-27](https://hackmd.io/Gxa-ukx6SuKKNlu7lokf6A) * [2024-07-11](https://hackmd.io/oU9CCUivSPyNUWrp7FP2tQ) * [2024-07-25](https://hackmd.io/iyFjUWl1RY6D_pevem8ciA) * [2024-08-08](https://hackmd.io/su12wMb9TR2kd1I5lLJ8vw) * [2024-08-22](https://hackmd.io/ky2mjfvdTnaJFk9K98TL_g) * [2024-09-05](https://hackmd.io/A15F6GBrTgKfcXQkaTzDiQ) * [2024-09-19](https://hackmd.io/yqkAQF6FT2OzmLqNR7I7_g) * [2024-10-03](https://hackmd.io/Bd98MgqETlyqM1YDoUkq6Q) * [2024-10-17](https://hackmd.io/wIMfTi0jSVi07XoCN3RFrg) * [2024-10-31](https://hackmd.io/dqE6-AIvSjmPU31IJ2MtCA) * [2024-11-14](https://hackmd.io/gru50cHsSvetMprTz7gJ7Q) * [2024-11-28](https://hackmd.io/mei-vI-bRmSxkWAfWX-jlw) * [2024-12-12](https://hackmd.io/PXNLnaX_R4OvqQWSyXzzHw) * [2024-12-26](https://hackmd.io/u3nFsnpQSpCitJL2xe5Hzg)

    Import from clipboard

    Paste your markdown or webpage here...

    Advanced permission required

    Your current role can only read. Ask the system administrator to acquire write and comment permission.

    This team is disabled

    Sorry, this team is disabled. You can't edit this note.

    This note is locked

    Sorry, only owner can edit this note.

    Reach the limit

    Sorry, you've reached the max length this note can be.
    Please reduce the content or divide it to more notes, thank you!

    Import from Gist

    Import from Snippet

    or

    Export to Snippet

    Are you sure?

    Do you really want to delete this note?
    All users will lose their connection.

    Create a note from template

    Create a note from template

    Oops...
    This template has been removed or transferred.
    Upgrade
    All
    • All
    • Team
    No template.

    Create a template

    Upgrade

    Delete template

    Do you really want to delete this template?
    Turn this template into a regular note and keep its content, versions, and comments.

    This page need refresh

    You have an incompatible client version.
    Refresh to update.
    New version available!
    See releases notes here
    Refresh to enjoy new features.
    Your user state has changed.
    Refresh to load new user state.

    Sign in

    Forgot password

    or

    By clicking below, you agree to our terms of service.

    Sign in via Facebook Sign in via Twitter Sign in via GitHub Sign in via Dropbox Sign in with Wallet
    Wallet ( )
    Connect another wallet

    New to HackMD? Sign up

    Help

    • English
    • 中文
    • Français
    • Deutsch
    • 日本語
    • Español
    • Català
    • Ελληνικά
    • Português
    • italiano
    • Türkçe
    • Русский
    • Nederlands
    • hrvatski jezik
    • język polski
    • Українська
    • हिन्दी
    • svenska
    • Esperanto
    • dansk

    Documents

    Help & Tutorial

    How to use Book mode

    Slide Example

    API Docs

    Edit in VSCode

    Install browser extension

    Contacts

    Feedback

    Discord

    Send us email

    Resources

    Releases

    Pricing

    Blog

    Policy

    Terms

    Privacy

    Cheatsheet

    Syntax Example Reference
    # Header Header 基本排版
    - Unordered List
    • Unordered List
    1. Ordered List
    1. Ordered List
    - [ ] Todo List
    • Todo List
    > Blockquote
    Blockquote
    **Bold font** Bold font
    *Italics font* Italics font
    ~~Strikethrough~~ Strikethrough
    19^th^ 19th
    H~2~O H2O
    ++Inserted text++ Inserted text
    ==Marked text== Marked text
    [link text](https:// "title") Link
    ![image alt](https:// "title") Image
    `Code` Code 在筆記中貼入程式碼
    ```javascript
    var i = 0;
    ```
    var i = 0;
    :smile: :smile: Emoji list
    {%youtube youtube_id %} Externals
    $L^aT_eX$ LaTeX
    :::info
    This is a alert area.
    :::

    This is a alert area.

    Versions and GitHub Sync
    Get Full History Access

    • Edit version name
    • Delete

    revision author avatar     named on  

    More Less

    Note content is identical to the latest version.
    Compare
      Choose a version
      No search result
      Version not found
    Sign in to link this note to GitHub
    Learn more
    This note is not linked with GitHub
     

    Feedback

    Submission failed, please try again

    Thanks for your support.

    On a scale of 0-10, how likely is it that you would recommend HackMD to your friends, family or business associates?

    Please give us some advice and help us improve HackMD.

     

    Thanks for your feedback

    Remove version name

    Do you want to remove this version name and description?

    Transfer ownership

    Transfer to
      Warning: is a public team. If you transfer note to this team, everyone on the web can find and read this note.

        Link with GitHub

        Please authorize HackMD on GitHub
        • Please sign in to GitHub and install the HackMD app on your GitHub repo.
        • HackMD links with GitHub through a GitHub App. You can choose which repo to install our App.
        Learn more  Sign in to GitHub

        Push the note to GitHub Push to GitHub Pull a file from GitHub

          Authorize again
         

        Choose which file to push to

        Select repo
        Refresh Authorize more repos
        Select branch
        Select file
        Select branch
        Choose version(s) to push
        • Save a new version and push
        • Choose from existing versions
        Include title and tags
        Available push count

        Pull from GitHub

         
        File from GitHub
        File from HackMD

        GitHub Link Settings

        File linked

        Linked by
        File path
        Last synced branch
        Available push count

        Danger Zone

        Unlink
        You will no longer receive notification when GitHub file changes after unlink.

        Syncing

        Push failed

        Push successfully