majorwiki/02-selfhosting/security
MajorLinux af14e36caf ClamAV fleet article: add DigitalOcean monitoring caveat for 1vCPU droplets
DO's hypervisor-level CPU metric doesn't know about nice/ionice — a
"polite" weekly clamscan on a 1 vCPU droplet still reads 100% utilization
and trips a default >85%/5m alert. Adds a new section explaining the
trade-off and providing the DO API recipe (PUT existing alert with
explicit entities, POST a new relaxed alert scoped to the small
droplet) plus when not to bother (2+ vCPU boxes won't trip).

Triggered by the 2026-05-10 teelia incident where the weekly cron fired
the fleet-wide CPU alert despite the cron script already wrapping
clamscan in nice 19 + ionice idle + cgroup memory limits.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-10 02:24:17 -04:00
..
ansible-unattended-upgrades-fleet.md wiki: audit fixes — broken links, wikilinks, frontmatter, stale content (66 files) 2026-04-02 11:16:29 -04:00
clamav-fleet-deployment.md ClamAV fleet article: add DigitalOcean monitoring caveat for 1vCPU droplets 2026-05-10 02:24:17 -04:00
fail2ban-apache-404-scanner-jail.md wiki: audit fixes — broken links, wikilinks, frontmatter, stale content (66 files) 2026-04-02 11:16:29 -04:00
fail2ban-apache-bad-request-jail.md Add 4 articles: nginx/apache bad-request jails, SSH fleet hardening, Watchtower localhost relay 2026-04-17 21:06:09 -04:00
fail2ban-apache-php-probe-jail.md wiki: add fail2ban jail for Apache PHP webshell probes 2026-04-13 10:17:24 -04:00
fail2ban-digest-mode-fleet.md wiki: update fail2ban digest + netdata docker health + 3 new articles 2026-05-02 14:58:07 -04:00
fail2ban-nginx-bad-request-jail.md Add 4 articles: nginx/apache bad-request jails, SSH fleet hardening, Watchtower localhost relay 2026-04-17 21:06:09 -04:00
fail2ban-wordpress-login-jail.md Add wiki article: Fail2ban WordPress login brute force jail 2026-04-02 16:04:13 -04:00
firewalld-fleet-hardening.md Add 5 wiki articles from 2026-04-17/18 work 2026-04-18 11:13:39 -04:00
linux-server-hardening-checklist.md wiki: audit fixes — broken links, wikilinks, frontmatter, stale content (66 files) 2026-04-02 11:16:29 -04:00
selinux-fail2ban-execmem-fix.md wiki: audit fixes — broken links, wikilinks, frontmatter, stale content (66 files) 2026-04-02 11:16:29 -04:00
ssh-hardening-ansible-fleet.md Add 4 articles: nginx/apache bad-request jails, SSH fleet hardening, Watchtower localhost relay 2026-04-17 21:06:09 -04:00
ufw-firewall-management.md Update UFW article: add web server ports lesson from tttpod outage 2026-04-03 03:57:27 -04:00
wp-fail2ban-logpath-debian-ubuntu.md wiki: update fail2ban digest + netdata docker health + 3 new articles 2026-05-02 14:58:07 -04:00