Hi,
Thank you for attending the Sysadmin 101 workshop!
You can find the workshop slides here:
https://nycbug1.nycbug.org/sysadmin101/
And below the workshop notes.
Gus
# Sysadmin 101 notes - June 4th 2022
~67 people in the workshop
### Resources
Join the relay operator community:
- IRC channel: #tor-relays on irc.oftc.net
- Matrix channel: #tor-relays:matrix.org
- Having issues to get in touch? Check this page:
https://support.torproject.org/get-in-touch/irc-help/
- Mailing lists:
- Tor-relays:
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays
- Tor-announce:
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-announce
- Tor Relay documentation:
- Documentation: https://community.torproject.org/relay/
- Support: https://support.torproject.org/relay-operators/
- Training:
https://community.torproject.org/training/resources/tor-relay-workshop/
- Expectations:
https://gitlab.torproject.org/tpo/community/team/-/wikis/Expectations-for-Relay-Operators
- Social contract and code of conduct:
https://gitweb.torproject.org/community/policies.git/tree/
https://support.torproject.org https://community.torproject.org
https://forum.torproject.org
- Other resources
- slides: https://nycbug1.nycbug.org/
- survey stats
https://gitlab.torproject.org/tpo/community/relays/-/issues/36#note_2810037
- Running a relay isn't for everyone. If you're not comfortable
running your own relay, consider running a Snowflake or Donating
- Here to one of the many non-profits that run exit relays:
https://community.torproject.org/relay/community-resources/relay-associations/
- NSA "Tor stinks" url from the Guardian
https://commons.wikimedia.org/wiki/File:Tor_Stinks.pdf
- Metrics https://metrics.torproject.org/
### Q/A
- How many people signed up?
- 100+. With 60-70 attendees in practice.
- Tor log: there have been x users in the last 6 hours... What's the
algorithm for what a distinct tor user is? (torix)
- I believe bridges count it by IP address, rounded up to the next
multiple of 8. Your bridge also publishes these stats plus more in
its "extrainfo" descriptor, which you can find in
https://collector.torproject.org/recent/bridge-descriptors/extra-infos/
and maybe also in the stats/ directory in your DataDirectory.
- How much time (per week or month) and how many times, should you plan
to invest?
- Depends on what you're doing and how you're doing it.
- "My eyeballs are the first line of defense." Watching the Tor
logs, watching the system logs, can help you get more comfortable
with how things are going (and what they look like when things are going
fine).
- What are the regular monitoring or upkeep activities we should be
performing to not "set it and forget it"
- Log in regularly. Check for updates and if your box needs to be
rebooted. (Set an alarm or calendar event to log in and check.) If
using Debian/Ubuntu, enable UnattendedUpgrades.
- prometheus:
https://forum.torproject.net/t/suggestion-a-summary-page-of-relay-bridge-install-guides-in-one-place/2425/4?u=gus
- george is into "agentless monitoring"
- What are acceptable domains or communications approaches for listing
in ContactInfo? E.g. what about a duck address.
- Use any domain that you use for normal communication. Don't use an
address that you never check.
- Any contact info that you regularly check.
- DO NOT obfuscate your contact information! Maintainers already
burn a lot of time trying to decipher obfuscated contact info!
- (Some people are concerned about spam, and that's why they try to
obfuscate the address. But actually, spam isn't so bad these days;
or if it is for you, consider using a separate email address for your
contact info.)
- Is a relay that allows exits to port 53 but routes those queries to a
pihole considered a bad node that is tampering with traffic?
- Please no! Don't mess with exit traffic. Redirecting outgoing tcp
port 53 connections to somewhere else is going to break things.
- There have been cases where a DNS on a distinct machine increased
performance
- What is the best way to figure out if a bridge/IP got burned (i.e.
blocked in certain countries)? What should be rotation intervals?
- At the beginning of 2022, we added a new feature where we're
measuring reachability of bridges from inside Russia, and
annotating relay-search with the results.
- Check metrics.torproject.org, there will be indicators if your
bridge is blocked or not
- This "your bridge is blocked in Russia" feature is in-progress:
the user experience at the end is not intended to be "you have to
watch your metrics page and then go cycle your IP address manually". So
don't worry too much about reacting to the relay-search page