Normale Ansicht

VNC: Die fünf wichtigsten Elemente von Confidential AI

16. Juli 2024 um 06:12

Künstliche Intelligenz wird häufig als latente Gefahr für die Datensouveränität von Unternehmen beschrieben. Wer sich dieser Gefahr nicht aussetzen will, muss Strategien und Taktiken für den sicheren und zugleich produktiven Umgang mit KI entwickeln. VNC erklärt die wichtigsten Parameter von Confidential AI.

Quelle

62 Minuten für die Ewigkeit

22. Juli 2024 um 10:46

IT-Sicherheitsexperte Elmar Geese analysiert die gravierenden Folgen eines fehlerhaften CrowdStrike-Updates, das weltweit Schäden verursachte. Der Vorfall zeigt die Risiken zentralisierter digitaler Lieferketten und die Problematik von Sicherheitssoftware in kritischen Bereichen. Geese fordert bessere Haftung, Qualität und den Einsatz von Open-Source-Alternativen zur Vermeidung solcher Vorfälle.

Quelle

Wie wird im Ansible Automation Controller eine neue Inventory Source hinzugefügt?

22. Juli 2024 um 05:00

In diesem Überblick beschreibe ich am Beispiel der Proxmox inventory source, wie eine eigene Inventory Source im Ansible Automation Controller hinzugefügt werden kann.

Die folgenden Schritte wurden mit der Ansible Automation Platform 2.4 getestet. Die einzelnen Schritte sollten in gleicher Weise auch in Ansible AWX ausgeführt werden können.

Um diesem Text folgen zu können, werden Kenntnisse im Umgang mit Ansible und Git auf der Kommandozeile vorausgesetzt.

Der Text verweist, wo möglich, auf bestehende Dokumentation. Es handelt sich bei diesem Text nicht um ein klassisches Tutorial. Er dient mir als Gedächtnisstütze und mag euch eine Anregung sein, bzw. im besten Fall die Wissenslücken schließen, die sich mit der Dokumentation allein nicht schließen lassen.

Ausgangssituation

Abschnitt 18.4.5.1. Inventory sources im Automation Controller User Guide führt die in der Ansible Automation Platform (AAP) unterstützten Inventory Sources auf. Möchte man nun bspw. Proxmox Virtual Environment (PVE), Microsoft Active Directory oder Cisco DNA Center als Quelle für sein Inventar benutzen, wird man auf den ersten Blick nicht fündig.

Für das Beispiel in diesem Text werden Hosts aus der Bestandsliste eines PVE als Inventory Source hinzugefügt. Die dabei verwendete Vorgehensweise kann auch für andere Inventory Plugins verwendet werden. Die Entwicklung von Inventory Plugins ist jedoch nicht Gegenstand dieses Textes. Hierzu wird auf die Dokumentation unter „Developing dynamic inventory“ verwiesen.

Mein Kollege Steffen Scheib hat mir geholfen, das Proxmox-Plugin zu konfigurieren, wofür ich ihm an dieser Stelle nochmal ganz herzlich danke. Es liegt auf meiner Arbeitsstation als Ansible Project in folgender Verzeichnisstruktur vor:

]$ tree proxmox_inventory/
proxmox_inventory/
├── collections
│   └── requirements.yml
├── inventory
│   └── inventory.proxmox.yml
└── vault_password_file

3 directories, 3 files

Mit Ausnahme der Datei vault_password_file wurden alle Dateien und Verzeichnisse in Git aufgenommen. Ich verwende einen einfachen Git-Server in meiner Laborumgebung, auf welchen ich meine lokalen Repositorys pushe. Der Automation Controller synchronisiert das Projekt aus dem Git-Repo, um es als Inventory Source verfügbar zu machen.

Die Vorgehensweise im Überblick

  1. Ansible Credential für Source Control erstellen
  2. Ein Ansible Projekt hinzufügen
  3. Einen Custom Credential Type erstellen
  4. Ein Ansible Inventory hinzufügen

Ansible Credential für Source Control erstellen

Das Proxmox Inventory Plugin befindet sich in einem Git-Repository, auf welches mit SSH-Key-Authentifizierung zugegriffen werden kann. Damit auch der Automation Controller auf dieses Repository zugreifen kann, wird ein Credential vom Typ Source Control erstellt.

Beipsiel für einen Source Control Credential Typ im Ansible Automation Controller

Der SSH-Private-Key wurde von meinem Host hochgeladen und verschlüsselt im Automation Controller gespeichert. Der Key lässt sich in der GUI nicht wieder sichtbar machen, lediglich ersetzen.

Ein Ansible Projekt hinzufügen

Der Dokumentation folgend, wird ein Projekt hinzugefügt:

Beispiel einer ausgefüllten Maske im Automation Controller, zum Hinzufügen eines Projekts.

Wenn alles passt, wird das Projekt nach dem Speichern erfolgreich synchronisiert:

Dieses Projekt wird in einem späteren Schritt zur Erstellung des Inventory benötigt.

Einen Custom Credential Type erstellen

Bevor ich auf die Erstellung selbst eingehe, möchte ich kurz beschreiben, warum dieser Schritt notwendig ist.

Folgender Codeblock zeigt meine Datei inventory.proxmox.yml welche einige mit Ansible Vault verschlüsselte Werte enthält:

]$ cat inventory/inventory.proxmox.yml 
---
plugin: 'community.general.proxmox'
url: 'https://pve.example.com'
user: !vault |
          $ANSIBLE_VAULT;1.1;AES256
          30623661316338386633623162303036346562346238386162633263636164636338393532613565
          3332616265353962326139363533313261623739643765640a623032613034613139653162356266
          34646464323233313964663939643631313539353736313364333433643136306632633065633664
          3234346635396563350a656334353632643830353534386636306365656261356436613662623163
          31663535363264356537336531393731633164613733316537383433653334643433
token_id: !vault |
          $ANSIBLE_VAULT;1.1;AES256
          62356662336534646661353666356263363734666231643932393430336639363032303266636432
          3762343235633335613663393838343532326230353130380a616161313830373265306137346562
          61613662333764393565316362623838633332376366373161646237363163663039613863393439
          3165616664626633390a396465343430373837343662373634653634643138613131633034306432
          62623438366166353765366339323263393833396133653866343833663335663766
token_secret: !vault |
          $ANSIBLE_VAULT;1.1;AES256
          66386338643463373837666164396332306261366634396630306430663937613963346164636433
          3362396566343932393234353439383932316436396437380a336365393038373566383534623136
          30353332383464356664393666383664636536666531663463623232353136353636363366653431
          3234616531623537630a393530643437376363653438643036636436316636616265316361623661
          35313832613063633662363531346164306638373538393164373663633335333863646430663232
          6339343164633865636239356538326438333937366134613738

validate_certs: false

# fail if a variable is not resolvable
strict: true

# facts are required to retrieve proxmox_vmtype
want_facts: true

# only allow qemu VMs
filters:
  - "proxmox_vmtype == 'qemu'"

Auf der Kommandozeile meines Hosts kann ich den Inhalt des Dynamic Inventory wie folgt anzeigen lassen:

ansible-inventory -i inventory/inventory.proxmox.yml --list --vault-password-file vault_password_file

Die Datei vault_password_file befindet sich jedoch nicht im Git, da sie das Passwort im Klartext enthält. Aus diesem Grund möchte ich die Datei auch nicht auf dem Automation Controller ablegen. Irgendwie müssen auf dem Automation Controller jedoch Credentials hinterlegt werden, um die Ansible Vault encrypted_strings zu entschlüsseln. Die Lösung steckt in diesem Kommentar auf Github. Im Automation Controller User Guide gibt es dazu Chapter 11. Custom credential types.

Fertig sieht das dann so aus:

Quelle: https://github.com/ansible/awx/issues/4089#issuecomment-1632066592

Das Schlüssel-Wert-Paar secret: true stellt sicher, dass das Passwort verschlüsselt gespeichert wird. Es kann danach im Automation Controller nicht mehr im Klartext angezeigt werden. Nachdem der neue Credential Typ erstellt ist, kann dieser instanziiert werden:

Beispiel des neuen Custom Credential Typs ‚encrypted_vault_password‘

Das Vault Passwort wird in das entsprechende Formularfeld kopiert. Es ist standardmäßig nicht sichtbar und wird wie oben bereits erwähnt, verschlüsselt gespeichert. Mit diesem Credential verfügt der Automation Controller nun über die notwendigen Informationen, um das Proxmox Inventory auszulesen.

Ein Ansible Inventory hinzufügen

Zuerst wird ein Inventory nach Dokumentation erstellt. Anschließend wird diesem eine Inventory Source hinzugefügt.

Die Formularfelder sind dabei wie folgt zu befüllen:

  • Name: Kann frei vergeben werden
  • Source: Sourced from a Project
  • Credential: Hier wird das im vorangegangenen Schritt erstellte Credential ausgewählt
  • Project: Hier wird das in obigen Abschnitt erstellte Projekt ausgewählt
  • Inventory file: Kann in diesem Fall auf `/ (project root)` gesetzt werden
Eine Inventory Source mit Proxmox als Beispiel

Nach dem Speichern wird die Inventory Source durch Klick auf ‚Sync‘ synchronisiert:

In dieser Ansicht wurde die Inventory Source bereits erfolgreich synchronisiert

Und wir haben 17 Hosts in unserem Inventory:

Damit endet dieser kurze Überblick auch schon. Ich wünsche euch viel Freude bei der Inventarpflege.

Das sagt Deine Linux Distro über Dich aus

Von: MK
19. Juli 2024 um 16:30

Die Wahl der Linux-Distribution spiegelt oft die Persönlichkeit und Vorlieben eines Nutzers wider. Jede Distro hat ihre eigenen Stärken, Schwächen und Besonderheiten, die bestimmte Nutzertypen anziehen. Ubuntu-Nutzer sind Allrounder, die Zuverlässigkeit und Benutzerfreundlichkeit schätzen. Sie legen Wert auf eine große Community und Unterstützung durch Hersteller, sowie eine gute Balance zwischen Stabilität und aktuellen Updates. Linux […]

Der Beitrag Das sagt Deine Linux Distro über Dich aus erschien zuerst auf fosstopia.

Firefox und die Werbeindustrie - immer noch die beste Alternative?

19. Juli 2024 um 16:00

💾

In diesem Video zeigt Jean, ob Firefox nach dem Update immer noch zu benutzen ist und welchen Browser mit welchen Einstellungen er benutzt.
Wenn Du das Video unterstützen willst, dann gib bitte eine Bewertung ab, und schreibe einen Kommentar. Vielen Dank!

Welchen Browser nutzt Ihr? https://cloud.linuxguides.de/index.php/apps/forms/s/kFLdLT88QNZpGnQsgCTxGtLs


Links:
-------------------------------------
Artikel von Netzpolitik.org: https://netzpolitik.org/2024/privatsphaere-firefox-sammelt-jetzt-standardmaessig-daten-fuer-die-werbeindustrie/#netzpolitik-pw
Blogeintrag: Firefox auf Abwegen: https://www.kuketz-blog.de/firefox-auf-abwegen-welche-browser-alternative/
Passwörter mit KeePassXC: https://www.youtube.com/watch?v=kQzOQoIo9q8

Linux-Guides Merch*: https://linux-guides.myspreadshop.de/
Professioneller Linux Support*: https://www.linuxguides.de/linux-support/
Linux-Arbeitsplatz für KMU & Einzelpersonen*: https://www.linuxguides.de/linux-arbeitsplatz/
Linux Mint Kurs für Anwender*: https://www.linuxguides.de/kurs-linux-mint-fur-anwender/
Offizielle Webseite: https://www.linuxguides.de
Forum: https://forum.linuxguides.de/
Unterstützen: http://unterstuetzen.linuxguides.de
Mastodon: https://mastodon.social/@LinuxGuides
X: https://twitter.com/LinuxGuides
Instagram: https://www.instagram.com/linuxguides/
Kontakt: https://www.linuxguides.de/kontakt/

Inhaltsverzeichnis:
-------------------------------------
0:00 Begrüßung
0:34 Änderungen bei Firefox
1:12 Begründung von Mozilla
2:00 Standard-Einstellungen von Firefox
3:50 empfohlene Einstellungen bei Firefox
6:01 Browser-Alternativen
10:01 Chromium Einstellungen
13:46 Fazit
14:50 UMFRAGE und Verabschiedung


Haftungsausschluss:
-------------------------------------
Das Video dient lediglich zu Informationszwecken. Wir übernehmen keinerlei Haftung für in diesem Video gezeigte und / oder erklärte Handlungen. Es entsteht in keinem Moment Anspruch auf Schadensersatz oder ähnliches.

*) Werbung

EC cuts funding support for Free Software projects

18. Juli 2024 um 23:00

EC cuts funding support for Free Software projects

The Next Generation Internet initiative has supported Free Software projects with funding and technical assistance since 2018. Despite its proven success, the European Commission made the decision to cut this funding in the current draft for the Horizon Europe 2025 Work Programme. This decision highlights the larger problem of the lack of motivated and sustainable public funding for Free Software projects.

The Next Generation Internet (NGI) initiative has been a project of the European Commission’s (EC) Horizon Europe programme since 2018. It provides funding for scientific research and innovation that can improve the Internet as a platform, including for the development of Free Software. The FSFE has always been a part of this initiative as a consortium member in the NGI Zero (NGI0) sub-group, where we provide legal and licensing support to more than 400 Free Software projects funded by the initiative.

As the EC works on the future plans for Horizon Europe, the FSFE is disappointed to learn that NGI is no longer mentioned as part of the plans for the Horizon Europe funding drafts and work programmes for 2025. The lack of public funding to such crucial technologies negatively impacts not only Free Software but the whole future of the Internet.

A blow to the vast NGI ecosystem

NGI is structured to support a large number of organizations and individuals working on open digital technologies, through open calls and a cascade funding system. Through this system, the NGI allocates its budget to fund crucial open technologies of the Internet. Open assets include Free Software, Open Hardware, Open Data, Privacy Enhancing Technologies, AI, networking, and many more. Under the previous Horizon Europe Cluster 4 Work Programme, spanning from 2023-2025, €27 million have been allocated to these projects.

The FSFE has over the past years seen the wide array of Free Software projects funded by NGI, that support, in their mission, values that promote privacy, security, diversity in opinion and participation, as well as choice in the digital sphere, among others. These are values we view to support democratic participation online, and to enable users to better control their digital technology. NGI funding support was also crucial for the FSFE to develop better copyright and licensing practices for software projects, making compliance easier for everyone.

This cascade funding system is however not renewed in the current draft proposal for Horizon Europe 2025, which will have the unfortunate effect of depriving many Free Software projects (and other types of beneficial research and innovation projects) of vital funding. This has us worried about the future of many of these ongoing grassroots level Free Software (and other) projects.

Where did the funding go?

An impact study finds that NGI projects have been immensely positive in providing funding and technical support for a diverse range of open projects, and in fostering an internet ecosystem that respects digital rights, promotes sustainability, and upholds EU legislation and values. Indeed, in practical terms, the study also notes that from the over 1,000 projects that received funding, 57% offer “viable alternatives to existing market solutions”, and 74% continue to operate post-funding.

Given these positives achieved by the NGI initiative at large, it is disappointing and baffling to see the decision to discontinue funding for it. Without the Horizon Europe 2025 umbrella, NGI is now left without alternative funding, which will harm the Free Software ecosystem and therefore, EU innovation. The reasons for this shift in budget away from funding Free Software and the NGI initiative seems to be an allocation of more funds for AI, leaving internet infrastructure by the wayside. Meanwhile, the EC has thus far declined to comment to share its official reasoning for striking this funding from its budget.

The future of an open Internet needs public funding

Funding is an important component in nurturing new Free Software technologies, and often makes the difference for whether a Free Software project is able to survive, succeed, or fall into abandonware. This is a particular problem because large parts of our infrastructure are based on these projects, as they guarantee the necessary independence and resilience. Cancelling funding means curtailing our own autonomy. This debate once again demonstrates a fundamental problem: We need sustainable, secure, and dedicated funding for NGI and Free Software solutions that help Europe to control its technology.

With the EU attempting to create fairer and more competitive markets with the Digital Markets Act, boosting alternative business models that challenge large, monopolistic, and consolidated digital platforms (also known as “gatekeepers”) is essential. Free Software is key for achieving such ambitious objectives. Public money is therefore more important than ever to support Free Software alternatives in internet infrastructure. It is impossible to achieve Device Neutrality, and a free and open internet without the commitment of the public sector to maintain a vigorous and sustainable ecosystem of viable and real-life tested software alternatives that can disentrench gatekeepers.

We therefore call for these funds to be made available again immediately and for funding to be secured in the medium to long term. This is the only way to successfully drive the digitalisation of Europe forward.

What you can do to help

The budget decision is not yet official - so there is still a chance to allocate funds for NGI. It is therefore very important to contact Ursula von der Leyen (President EU Commission), DG Connect, to ask them to make the funds available.

Pressure is also needed from member states. Contact your National Contact Point (NCP) and persuade them to also advocate for the NGI funds to be made available.

Support FSFE

❌