Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Postmortem & rebuild server #59

Open
2 of 7 tasks
bjacobel opened this issue Oct 1, 2015 · 0 comments
Open
2 of 7 tasks

Postmortem & rebuild server #59

bjacobel opened this issue Oct 1, 2015 · 0 comments

Comments

@bjacobel
Copy link
Contributor

bjacobel commented Oct 1, 2015

[DigitalOcean] New Ticket # 767564 : Networking disabled: citadel

Hi there,

We are sorry to report that we have detected what appears to be a large flood of traffic from one or more of your servers that is disrupting the normal traffic flow for other users.

I got owned again :( early signs point to unsecured Elasticsearch -- right before New Relic cut out there was a huge CPU spike caused by some process I don't recognize running under the elasticsearch user.

  • Find out how they got in
  • find out how to stop it from happening again
  • Get rid of the droplet
  • Spin up new server (Could be an opportunity to switch to AWS)
  • reconnect DNS
  • rebuild server (bright side: good full test of Ansible)
  • bonus: Get elasticsearch off the server and switch to Amazon's new hosted ES
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

1 participant