Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file added docs/assets/fonts/ibm-plex-mono-100-italic.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-100.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-200-italic.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-200.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-300-italic.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-300.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-400-italic.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-400.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-500-italic.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-500.woff2
Binary file not shown.
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-600.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-700-italic.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-mono-700.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-sans-italic.woff2
Binary file not shown.
Binary file added docs/assets/fonts/ibm-plex-sans.woff2
Binary file not shown.
2 changes: 1 addition & 1 deletion docs/staff-docs/archive/znc.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ to connect to the bouncer from your desktop client, irssi, phone, etc.
It's handy to avoid constantly disconnecting/reconnecting from IRC. It will
also store messages you've missed and replay them when you log in.

It's useful along with [OCF's IRC server](../../user-docs/contact/irc.md).
It's useful along with [OCF's IRC server](../../user-docs/contact/chat.md).

## Installing ZNC on your staff VM

Expand Down
6 changes: 3 additions & 3 deletions docs/staff-docs/get-involved/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ We hold two meetings each week during the fall and spring semesters. If you're
new to the OCF, we recommend you attend our [General
Meetings](staff-meetings.md). If you're curious about the larger technical and
administrative decisions we make, you can also listen in on our [Board of
Directors](/bod/) meetings.
Directors](../../bod/index.md) meetings.

### Linux SysAdmin DeCal

Expand All @@ -48,7 +48,7 @@ say you’re interested in joining staff and we’ll let you in.

### Starter Tasks

The [Starter Tasks](starter-tasks) page in our documentation contains a variety of intermediate-difficulty exercises that are another great way to get some practice working with OCF infrastructure.
The [Starter Tasks](starter-tasks/index.md) page in our documentation contains a variety of intermediate-difficulty exercises that are another great way to get some practice working with OCF infrastructure.

### Contribute

Expand Down Expand Up @@ -105,7 +105,7 @@ attending staff hours can serve multiple purposes:
**I wasn’t able to make the first/second/nth meeting of the semester, can I
still join?**

Yes! You can join at any meeting at any time. If you’re worried about what you’ve missed, you can ask a veteran staffer to bring you up to speed or review the [BoD minutes](/bod/) for that week.
Yes! You can join at any meeting at any time. If you’re worried about what you’ve missed, you can ask a veteran staffer to bring you up to speed or review the [BoD minutes](../../bod/index.md) for that week.

**What if I can’t physically be present at weekly meetings?**

Expand Down
10 changes: 5 additions & 5 deletions docs/staff-docs/get-involved/starter-tasks/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ All of [our servers](https://www.ocf.berkeley.edu/docs/staff/backend/servers/) r
them over the command line. There are a lot of online resources about using the
Linux command line, so if you're confused about something, try Googling it!

You can also connect to [our ssh server](../../../user-docs/services/shell/)
You can also connect to [our ssh server](../../../user-docs/services/shell/index.md)
(`ssh.ocf.berkeley.edu`) using your own SSH client.

If you want to get more comfortable, try completing [lab
Expand Down Expand Up @@ -56,10 +56,10 @@ OCF staff use a collection of scripts when interacting with the campus
community. For example, before creating an account for a student organization,
we make sure the person requesting the account is listed as a signatory for that
group. Staff members use the
[`signat`](https://ocf.io/docs/staff/scripts/signat) command to perform this
[`signat`](../../scripts/signat.md) command to perform this
check.

1. [Log into koi](../../procedures/ssh-koi.md).
1. [Log into koi](../../infrastructure/nix-hosts/login-servers.md).
2. Use the `signat` command to list the signatories for the Open Computing
Facility or another student organization of your choice. Hint: if you are not
sure how to use the `signat` command, try running `signat --help`. This trick
Expand All @@ -79,7 +79,7 @@ website](https://www.ocf.berkeley.edu/~ckuehl/).
[ocflib][ocflib] is a Python library we maintain which is installed on every OCF
host. For this exercise, you won’t need to make modifications to ocflib.

1. [Log into koi](../../procedures/ssh-koi.md) and start an
1. [Log into koi](../../infrastructure/nix-hosts/login-servers.md) and start an
IPython3 shell (the `ipython3` command).
2. To make sure things are working:
1. Run `import ocflib.lab.staff_hours` to import utilities relating to
Expand Down Expand Up @@ -114,7 +114,7 @@ add your name to [the list of everyone who's completed this task](completed.md).
1. Log into [GitHub](https://github.com). If your [OCF email](../../../user-docs/services/mail.md) (`<OCF username>@ocf.berkeley.edu`) is not connected to your
account, [add it to your account emails](https://github.com/settings/emails).
2. Create your personal [fork][github-fork] of [ocfweb][ocfweb].
3. [Log into koi](../../procedures/ssh-koi.md).
3. [Log into koi](../../infrastructure/nix-hosts/login-servers.md).
4. Optional: For easier authentication to GitHub, [generate an SSH
key][github-ssh-keygen] and [add it to your GitHub account][github-add-key].
Note: the `xclip` commands will probably not work. Instead, just run `cat
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
title: Internal Firewalls
---

While the [external firewall](external-firewall.md) regulates network
While the [external firewall](../external-firewall.md) regulates network
traffic to the OCF from outside the OCF network, internal firewalls are
responsible for regulating network traffic between different machines within the
OCF.
Expand Down
2 changes: 1 addition & 1 deletion docs/staff-docs/infrastructure/debian-hosts/libvirt.md
Original file line number Diff line number Diff line change
Expand Up @@ -139,7 +139,7 @@ and for vCPUs:

### How do I edit my VM's disk size?

There's [a full guide for this in the docs](../procedures/live-resize.md)
There's [a full guide for this in the docs](live-resize.md)
with step-by-step instructions for how to live-resize your VM to have _more_
disk size. However, if you'd instead like to _shrink_ a partition on-line, see
[this Unix SE answer](https://unix.stackexchange.com/a/227318). It's much more
Expand Down
2 changes: 1 addition & 1 deletion docs/staff-docs/infrastructure/hpc/add-hpc-users.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
title: Adding Users to the HPC Cluster
---

Access to the OCF's HPC [cluster](../../user-docs/services/hpc/index.md) is controlled by means
Access to the OCF's HPC [cluster](../../../user-docs/services/hpc/index.md) is controlled by means
of an LDAP group named `ocfhpc`. If a user requests access to the cluster and
meets the basic access criteria, namely that they have specified what they
want to use the cluster for, simply run the following commands to add the user
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Configuration (Transpire)

[Transpire](https://github.com/ocf/transpire) (/tɹænˈspaɪ̯ɚ/) is a Kubernetes config generation tool designed by and for the Open Computing Facility. If you're wondering why we wanted to build our own thing, check out the [History](/doc/history-wxYwTlBgfS) document.
[Transpire](https://github.com/ocf/transpire) (/tɹænˈspaɪ̯ɚ/) is a Kubernetes config generation tool designed by and for the Open Computing Facility. If you're wondering why we wanted to build our own thing, check out the [History](transpire-history.md) document.

## Design Goals

Expand Down Expand Up @@ -60,4 +60,4 @@ Transpire is still currently very unstable, and the API changes quite frequently

:::

You'll need to clone the OCF's [transpire root repository](http://github.com/ocf/transpire/) and run transpire commands from there, even if you're making changes to another app (like docs). We're working on fixing this.
You'll need to clone the OCF's [transpire root repository](http://github.com/ocf/transpire/) and run transpire commands from there, even if you're making changes to another app (like docs). We're working on fixing this.
6 changes: 3 additions & 3 deletions docs/staff-docs/infrastructure/kubernetes/secrets/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ OCF's convention is to put the contents of the `V1Secret` in Vault at the path
}
```

The easier way to do this is to create a `V1Secret`, and let [transpire](/doc/configuration-transpire-uJ5GHrW9cg) automatically transform it into a `VaultSecret`. If the secret can be automatically generated (i.e. it's a random string) you can write some Python to generate it, and then push the generated secret to Vault with `transpire secret push <module>`.
The easier way to do this is to create a `V1Secret`, and let [transpire](../configuration-transpire/index.md) automatically transform it into a `VaultSecret`. If the secret can be automatically generated (i.e. it's a random string) you can write some Python to generate it, and then push the generated secret to Vault with `transpire secret push <module>`.

```python
from transpire.resources import Secret
Expand Down Expand Up @@ -57,8 +57,8 @@ The annotations to use are [documented on the Hashicorp website](https://develop

Vault may have an engine that specifically supports your use-case (e.x. databases). If this is the case, configure Vault via OCF Terraform to support your use case. Instructions are provided in the [Vault documentation](https://developer.hashicorp.com/vault).

Generic secret provisioning to non-Kubernetes infrastructure is currently out of scope, and is explicitly not recommended for anything that sits underneath Kubernetes because it will create dependency loops. For example, [NixOS](/doc/nixos-linux-systems-Mh8Ugu5kdY) should use a different secret management solution.
Generic secret provisioning to non-Kubernetes infrastructure is currently out of scope, and is explicitly not recommended for anything that sits underneath Kubernetes because it will create dependency loops. For example, [NixOS](../../nix-hosts/index.md) should use a different secret management solution.

## Configuration

As mentioned earlier, the only thing you should be doing from the Vault web interface is managing secrets. To configure Vault itself, you should write Terraform.
As mentioned earlier, the only thing you should be doing from the Vault web interface is managing secrets. To configure Vault itself, you should write Terraform.
Original file line number Diff line number Diff line change
Expand Up @@ -31,4 +31,4 @@ If you're using `rbd-nvme` you probably want to go fast. For databases, make sur

## Data Durability

All Persistent Volumes are backed up to the OCF backup server unless they have the label `velero.io/exclude-from-backup: true`. These backups are then periodically replicated offsite in Fremont, CA. For more details on the backup strategy, see [Backups (Velero)](/doc/backups-velero-xVMmUZgO2s).
All Persistent Volumes are backed up to the OCF backup server unless they have the label `velero.io/exclude-from-backup: true`. These backups are then periodically replicated offsite in Fremont, CA. For more details on the backup strategy, see [Backups (Velero)](../backups-velero.md).
Original file line number Diff line number Diff line change
Expand Up @@ -31,4 +31,4 @@ We have not tried to optimize CephFS for performance. There is likely a lot of h

## Data Durability

All Persistent Volumes are backed up to the OCF backup server unless they have the label `velero.io/exclude-from-backup: true`. These backups are then periodically replicated offsite in Fremont, CA. For more details on the backup strategy, see [Backups (Velero)](/doc/backups-velero-xVMmUZgO2s).
All Persistent Volumes are backed up to the OCF backup server unless they have the label `velero.io/exclude-from-backup: true`. These backups are then periodically replicated offsite in Fremont, CA. For more details on the backup strategy, see [Backups (Velero)](../backups-velero.md).
2 changes: 1 addition & 1 deletion docs/staff-docs/infrastructure/mail/vhost.md
Original file line number Diff line number Diff line change
Expand Up @@ -47,5 +47,5 @@ clients to send as a vhost address. (See `/etc/pam.d/smtp` and

## How do I add mail hosting to a group?

See [here](../config-vhost/).
See [here](config-vhost.md).

2 changes: 1 addition & 1 deletion docs/staff-docs/infrastructure/nix-hosts/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,4 +33,4 @@ To install Nix, follow the instructions at https://zero-to-nix.com/start/install

## Old Linux Systems (Puppet)

We used to use [Puppet](/doc/puppet-4chWqU6Eqx). Actually we still do use puppet, and most of our legacy infrastructure is on it. See the link in the first sentence for more information!
We used to use [Puppet](../debian-hosts/puppet.md). Actually we still do use puppet, and most of our legacy infrastructure is on it. See the link in the first sentence for more information!
2 changes: 1 addition & 1 deletion docs/staff-docs/infrastructure/nix-hosts/njha-nix-guide.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ Next you should install a copy of the OS. If you have spare hardware lying aroun
* NixOS Options: <https://search.nixos.org/options>
* NixOS Packages: [https://search.nixos.org/packages](https://search.nixos.org/packages?)

It's a good idea to either install Nix locally (see [Nix on your Computer](/doc/nix-on-your-computer-r7pLkYWNML) for installation instructions) or use your NixOS install to play around with Nix more.
It's a good idea to either [install Nix locally](https://zero-to-nix.com/start/install) or use your NixOS install to play around with Nix more.

## Step 3. Nix Course

Expand Down
6 changes: 3 additions & 3 deletions docs/staff-docs/infrastructure/printing/printhost.md
Original file line number Diff line number Diff line change
Expand Up @@ -177,7 +177,7 @@ and emails users in the case a job fails.
After printing a document from a desktop, lab visitors are notified when pages
are subtracted from their quota by a little popup notification. This is done by
a short daemon script, [notify script][notify], which starts upon login and
runs the [paper command](../scripts/paper.md) every minute to see if the
runs the [paper command](../../scripts/paper.md) every minute to see if the
quota has changed.

In the future, it would be nice to have a more robust notification system where
Expand All @@ -194,9 +194,9 @@ current user.

## See also

- [Printing maintenance](../procedures/printing.md)
- [Printing maintenance](maintenance.md)
- The [ocf\_printhost][ocf_printhost] Puppet class # TODO update
- The [paper](../scripts/paper.md) command
- The [paper](../../scripts/paper.md) command
- [CUPS documentation at Samba][cups-samba] (for Windows users, but has general
CUPS info as well)

Expand Down
2 changes: 1 addition & 1 deletion docs/staff-docs/infrastructure/prometheus.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ Additionally, we don't receive email alerts for staff VMs. Monitoring for the ne

Alerts can be viewed at [prometheus.ocf.berkeley.edu/alerts](https://prometheus.ocf.berkeley.edu/alerts). They are configured at [this folder][prometheus-puppet] in the Puppet configs.

Alerts can additionally be configured using the [alert manager](prometheus.ocf.berkeley.edu/alertmanager). Alertmanager handles notifications for alerts via communication through email. Alerts can be inhibited or silenced. Alertmanager documentation can be found [here](https://prometheus.io/docs/alerting/alertmanager/).
Alerts can additionally be configured using the [alert manager](https://prometheus.ocf.berkeley.edu/alertmanager). Alertmanager handles notifications for alerts via communication through email. Alerts can be inhibited or silenced. Alertmanager documentation can be found [here](https://prometheus.io/docs/alerting/alertmanager/).

Alerts are currently under development and may not be fully comprehensive.

Expand Down
2 changes: 1 addition & 1 deletion docs/staff-docs/infrastructure/switch.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@ Port Channel Port-Channel7:

More details can be found on the EOS guide online, in the [Port Channel section][lacp-guide].

LACP also needs to be configured on the [host side](../procedures/setting-up-lacp.md).
LACP also needs to be configured on the [host side](debian-hosts/setting-up-lacp.md).

[primary-switch]: https://www.arista.com/assets/data/pdf/Datasheets/7050SX-128_64_Datasheet.pdf
[secondary-switch]: https://www.arista.com/assets/data/pdf/Datasheets/7048T-A_DataSheet.pdf
Expand Down
2 changes: 1 addition & 1 deletion docs/staff-docs/policies/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ read and be aware of these policies.

* [Staff policy](staff-policy.md)
* [Keycard policy](keycard.md)
* The [restarting services procedure](../procedures/restarting-services.md)
* The [restarting services procedure](../infrastructure/debian-hosts/restarting-services.md)

OCF staff should also familiarize themselves with the
[University's IT Policies](https://security.berkeley.edu/policy/policy-catalog).
Expand Down
2 changes: 1 addition & 1 deletion docs/staff-docs/scripts/economode.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ title: "economode: turn economode on/off on the printers"
By default our printers print with the Economode setting off. If you need to save toner, you can use the `economode` script to turn Economode on.

You'll need the printer password, whose location can be found in the
[private docs](../private/index.md).
[private docs](../private.md).

## Usage

Expand Down
2 changes: 1 addition & 1 deletion docs/staff-docs/scripts/signat.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ it also gives all the information needed to create group accounts with
up UIDs and OIDs in OCF [LDAP](../infrastructure/ldap.md) and names in the
university's [LDAP directory service][berkeleyldap].

[ocflib]: github.com/ocf/ocflib
[ocflib]: https://github.com/ocf/ocflib
[callinkapi]: https://studentgroupservice.sait-west.berkeley.edu/service.asmx
[berkeleyldap]: https://wikihub.berkeley.edu/display/calnet/LDAP+Directory+Service

Expand Down
36 changes: 18 additions & 18 deletions docs/stylesheets/extra.css
Original file line number Diff line number Diff line change
Expand Up @@ -3,111 +3,111 @@
font-family: 'IBM Plex Mono';
font-style: normal;
font-weight: 100;
src: url('assets/ibm-plex-mono-100.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-100.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: italic;
font-weight: 100;
src: url('assets/ibm-plex-mono-100-italic.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-100-italic.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: normal;
font-weight: 200;
src: url('assets/ibm-plex-mono-200.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-200.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: italic;
font-weight: 200;
src: url('assets/ibm-plex-mono-200-italic.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-200-italic.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: normal;
font-weight: 300;
src: url('assets/ibm-plex-mono-300.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-300.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: italic;
font-weight: 300;
src: url('assets/ibm-plex-mono-300-italic.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-300-italic.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: normal;
font-weight: 400;
src: url('assets/ibm-plex-mono-400.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-400.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: italic;
font-weight: 400;
src: url('assets/ibm-plex-mono-400-italic.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-400-italic.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: normal;
font-weight: 500;
src: url('assets/ibm-plex-mono-500.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-500.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: italic;
font-weight: 500;
src: url('assets/ibm-plex-mono-500-italic.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-500-italic.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: normal;
font-weight: 600;
src: url('assets/ibm-plex-mono-600.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-600.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: italic;
font-weight: 600;
src: url('assets/ibm-plex-mono-600-italic.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-600-italic.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: normal;
font-weight: 700;
src: url('assets/ibm-plex-mono-700.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-700.woff2') format('woff2');
}

@font-face {
font-display: swap;
font-family: 'IBM Plex Mono';
font-style: italic;
font-weight: 700;
src: url('assets/ibm-plex-mono-700-italic.woff2') format('woff2');
src: url('../assets/fonts/ibm-plex-mono-700-italic.woff2') format('woff2');
}


Expand All @@ -117,8 +117,8 @@
font-style: normal;
font-weight: 100 900;
font-stretch: 75% 100%;
src: url('assets/ibm-plex-sans.woff2') format('woff2 supports variations'),
url('assets/ibm-plex-sans.woff2') format('woff2-variations');
src: url('../assets/fonts/ibm-plex-sans.woff2') format('woff2 supports variations'),
url('../assets/fonts/ibm-plex-sans.woff2') format('woff2-variations');
}

@font-face {
Expand All @@ -127,8 +127,8 @@
font-style: italic;
font-weight: 100 900;
font-stretch: 75% 100%;
src: url('assets/ibm-plex-sans-italic.woff2') format('woff2 supports variations'),
url('assets/ibm-plex-sans-italic.woff2') format('woff2-variations');
src: url('../assets/fonts/ibm-plex-sans-italic.woff2') format('woff2 supports variations'),
url('../assets/fonts/ibm-plex-sans-italic.woff2') format('woff2-variations');
}

:root {
Expand Down
Loading
Loading