When To Update TrueNAS Scale & What Happened to TrueCharts?

Lawrence Systems
14 Jul 202409:12

Summary

TLDRLa mise à jour 24.4.2 de TrueNAS SCALE a été publiée le 9 juillet 2024. Cette version corrective aborde notamment la vulnérabilité CVE-2024-6387 dans SSH, un problème majeur qui nécessite une correction. Bien que ce ne soit pas une version majeure, il est recommandé de mettre à jour rapidement, mais il est raisonnable d'attendre quelques jours pour s'assurer de la stabilité. La fin de TrueCharts est également abordée, avec des conseils pour migrer vos données et applications vers des alternatives. L'auteur exprime son enthousiasme pour le support Docker natif à venir dans TrueNAS SCALE.

Takeaways

  • 😀 La version 24.4.2 de TrueNAS SCALE est sortie le 9 juillet 2024 et a été mise à jour sans incident.
  • 🔒 Il est recommandé de garder son système TrueNAS SCALE à jour, en particulier après une version majeure.
  • 🐞 La mise à jour 24.4.2 inclut un correctif important pour une vulnérabilité dans SSH, CVE-2024-6387, connue sous le nom de 'Regran'.
  • 📅 Il est conseillé d'attendre quelques jours après la sortie d'une nouvelle version avant de la mettre en place, surtout pour les systèmes de production.
  • 📈 La communauté TrueNAS SCALE est active dans la recherche de bogues et la contribution au projet open source.
  • 📊 Les mises à jour de TrueNAS SCALE sont fréquemment basées sur les retours des utilisateurs et les corrections des problèmes connus.
  • 📚 True charts, un projet associé, a été abandonné et son catalogue supprimé, ce qui signifie qu'il n'y aura plus de mises à jour pour les utilisateurs.
  • 🚧 L'auteur du script n'a jamais recommandé True charts en raison de problèmes passés et d'instructions contradictoires.
  • 🗂️ Il est important de sauvegarder et de migrer les données correctement, en utilisant l'option 'host path' pour éviter de perdre des informations.
  • 🐳 TrueNAS SCALE prévoit de prendre en charge nativement Docker, offrant ainsi une méthode préférée et documentée pour exécuter des applications.

Q & A

  • Quelle est la date de sortie de la version 24.4.2 de TrueNAS SCALE ?

    -La version 24.4.2 de TrueNAS SCALE a été publiée le 9 juillet 2024.

  • Pourquoi la mise à jour de la version 24.4.2 est-elle importante ?

    -La mise à jour est importante car elle inclut un correctif pour une vulnérabilité dans SSH, CVE 2024 6387, également connue sous le nom de 'regran', qui est exploitable principalement dans les compilations i386.

  • Quelle est la différence entre une mise à jour majeure et une mise à jour de point pour TrueNAS SCALE ?

    -Une mise à jour de point, comme la version 24.4.2, ne contient généralement que des correctifs de bugs et des améliorations mineures, tandis qu'une mise à jour majeure apporte de nouvelles fonctionnalités et des changements plus significatifs.

  • Combien de temps faut-il généralement attendre avant de mettre à jour son système TrueNAS SCALE ?

    -Il est recommandé d'attendre au moins quelques jours après la sortie d'une mise à jour pour s'assurer qu'aucun problème majeur n'a été signalé, bien que cela puisse varier en fonction des besoins et des priorités de chaque utilisateur.

  • Pourquoi l'orateur n'a-t-il pas recommandé True Charts auparavant ?

    -L'orateur n'a pas recommandé True Charts en raison des nombreux changements cassants et des problèmes de gestion de l'espace de stockage qui ont conduit à des pertes de données chez les utilisateurs.

  • Que signifie la fin de True Charts pour les utilisateurs ?

    -La fin de True Charts signifie que les utilisateurs ne pourront plus recevoir de mises à jour ni de soutien pour ce projet. Ils devront exporter leurs données et trouver une alternative pour la gestion de leurs applications.

  • Quelle est la position de l'orateur sur l'utilisation de Docker avec TrueNAS SCALE ?

    -L'orateur est enthousiaste à propos de l'ajout du support Docker dans TrueNAS SCALE, car il estime que cela simplifie les choses, est bien documenté et est une solution populaire et durable dans le domaine de la virtualisation.

  • Quels sont les conseils de l'orateur pour ceux qui utilisent True Charts ?

    -L'orateur conseille aux utilisateurs de True Charts d'exporter leurs données et de préparer un plan B, car le support pour True Charts n'est plus disponible et les applications ne recevront plus de mises à jour.

  • Quelle est la recommandation de l'orateur concernant la migration des applications et des données ?

    -L'orateur recommande aux utilisateurs de True Charts de migrer leurs applications et de gérer leurs données en utilisant l'option 'host path' pour faciliter la migration et la récupération des données.

  • Quelle est l'attitude de l'orateur envers les projets open source et la communauté ?

    -L'orateur semble apprécier les efforts des développeurs open source et encourage une approche constructive et collaborative pour améliorer les projets, plutôt que de les critiquer de manière négative.

Outlines

00:00

💻 Mise à jour réussie de Traefik Scale 24.4.2

La mise à jour 24.4.2 de Traefik Scale a été publiée le 9 juillet 2024 et, jusqu'à présent, aucune panne n'a été signalée, ce qui indique que la mise à jour s'est bien passée. Il est important de garder son système à jour, surtout après une mise à jour majeure. L'auteur discute de la fréquence à laquelle les utilisateurs devraient mettre à jour leur système, soulignant qu'attendre trop longtemps peut poser des problèmes. Il est également question de la fin de True Charts, qui a cessé de fonctionner, et de la recommandation de migrer vers des alternatives plus stables.

05:00

🗂️ Fin de True Charts et anticipation de la prise en charge de Docker native

True Charts a été abandonné et son catalogue supprimé, ce qui a entraîné des discussions animées dans la communauté. L'auteur critique l'attitude de True Charts envers la communauté open source et les utilisateurs de Traefik Scale. Il recommande aux utilisateurs de True Charts de migrer leurs applications et de sauvegarder leurs données. L'auteur exprime également son enthousiasme pour l'ajout de la prise en charge de Docker native dans Traefik Scale, une fonctionnalité qui est prévue pour être ajoutée à l'avenir.

Mindmap

Keywords

💡tras scale

Tras scale fait référence à un système de gestion de conteneurs qui permet de déployer et de gérer des applications dans des environnements distribués. Dans le script, l'auteur mentionne la mise à jour de cette plateforme, indiquant qu'il s'agit d'une version mineure plutôt qu'une version majeure, ce qui suggère des améliorations et des correctifs de bogues plutôt que de changements radicaux.

💡mise à jour

La mise à jour est le processus d'application de nouvelles versions de logiciels pour améliorer les fonctionnalités, réparer les bogues ou améliorer la sécurité. Le script discute de la fréquence à laquelle les utilisateurs devraient mettre à jour leur système, soulignant l'importance de ne pas attendre trop longtemps après la sortie d'une nouvelle version.

💡CVE 2024 6387

CVE (Common Vulnerabilities and Exposures) est un identifiant unique attribué à une vulnérabilité spécifique dans un logiciel. CVE 2024 6387 est mentionné comme une vulnérabilité dans SSH (Secure Shell), un protocole utilisé pour la gestion sécurisée des systèmes à distance. Le script met en évidence l'importance de cette vulnérabilité et la nécessité de la corriger.

💡i386 et x64

i386 et x64 sont des architectures de processeurs. Le script mentionne que la vulnérabilité CVE 2024 6387 est plus exploitable dans les compilations i386 que dans les compilations x64, qui est la base de la plupart des systèmes d'exploitation modernes. Cela indique la portée et la gravité de la vulnérabilité.

💡open source

Le terme open source fait référence à des logiciels dont le code source est disponible au public et peut être modifié et amélioré par quiconque. Le script souligne que Chast est un projet open source, ce qui signifie que les mises à jour sont basées sur les contributions de la communauté et les rapports de bogues des utilisateurs.

💡release candidate

Un candidat à la version (release candidate) est une version préliminaire d'un logiciel qui est prête pour la publication finale, mais qui est testée avant la mise en production. L'auteur mentionne qu'il aime tester les release candidates, ce qui montre son engagement envers la participation à la communauté open source.

💡True charts

True charts est mentionné comme un projet abandonné dans le script. Il s'agissait d'un ensemble de chart Helm pour Tras scale, qui a été supprimé par les développeurs, ce qui a entraîné la fin de son utilisation. Cela montre les risques associés à l'utilisation de projets qui ne sont pas maintenus activement.

💡migration

La migration fait référence au processus de transition d'une version d'un logiciel à une autre, souvent plus récente. Le script discute de la migration des versions de Tras scale, soulignant l'importance de suivre les bonnes pratiques de migration pour s'assurer que le passage à la nouvelle version est fluide et sans problèmes.

💡Docker

Docker est une plateforme de virtualisation à niveau de conteneur qui permet de développer, de déployer et de gérer des applications dans des environnements isolés appelés conteneurs. Le script mentionne l'ajout du support Docker dans Tras scale, ce qui est considéré comme une avancée positive pour la simplicité, la documentation et la stabilité à long terme.

💡forum

Un forum est un lieu en ligne où les personnes peuvent discuter et partager des informations sur des sujets spécifiques. Le script mentionne les forums comme un moyen préférable de communication par rapport à Discord, soulignant l'importance de la rechercheabilité et de l'indexation des discussions pour la communauté.

Highlights

Traefik 24.4.2 was released on July 9th, 2024, and the speaker's systems updated successfully without any issues.

The speaker emphasizes the importance of keeping Traefik systems up to date and suggests updating to at least version 24.

The release of Traefik 24.4.2 was a point release, not a major one, indicating incremental improvements and bug fixes.

CVE 2024 6387, also known as 'regran', is a vulnerability in SSH that Traefik 24.4.2 addresses, highlighting the importance of the update.

The speaker recommends updating Traefik soon after a major release but advises caution and waiting for a few days to ensure stability.

TrueCharts has ended, and the speaker discusses the implications for those who were using it with Traefik.

The speaker critiques TrueCharts for its lack of control over breaking changes and storage path issues, which led to data loss for some users.

The speaker discusses the community's reaction to TrueCharts' end and the drama surrounding it on Reddit and Discord.

Traefik's native Docker support is on the roadmap, which the speaker is excited about as it promises simpler and well-documented setups.

The speaker provides advice on how to migrate apps and retrieve data in light of TrueCharts' discontinuation.

The speaker encourages setting up applications with host path to ensure data integrity and ease of migration.

The speaker anticipates a slow transition from TrueCharts to Docker due to Docker's popularity and stability.

The speaker invites viewers to subscribe and engage in discussions on Traefik and related topics on their forums.

Transcripts

play00:00

tras scale 24.4.2 was released on July

play00:04

9th of 2024 today is July 14th and all

play00:07

my systems updated none of them caught

play00:09

fire so I'm going to say it worked

play00:11

pretty well but that's not too

play00:12

surprising this was a point release not

play00:14

a major release but there's a few things

play00:15

I want to cover in this video first I

play00:17

want to be clear that you should keep

play00:19

your true system up to date I did have a

play00:22

good conversation with someone who

play00:23

reached out and said hey when should I

play00:25

update my chass I'm still on like the 23

play00:28

version and I'm like you should at least

play00:29

be on 24 and I can understand when the

play00:32

major release is first release waiting

play00:34

but I wouldn't wait too long so we're

play00:36

going to talk a little bit about how

play00:37

long you should wait we're also going to

play00:39

talk about true charts because that has

play00:41

now ended so if you're using true charts

play00:43

or you're here because you're wondering

play00:44

why true charts quit working yeah that

play00:47

era is over and we'll talk about that as

play00:49

well so let's get

play00:50

[Music]

play00:55

started now we can start here with the

play00:58

24.4.2 change law

play01:00

I think one of the big reasons for

play01:01

pushing this out was of course the first

play01:03

thing listed here cve 2024 6387 also

play01:07

known as regran believe it's how you

play01:09

pronounced that this is the

play01:10

vulnerability found in SSH it is

play01:13

exploitable more so in the i386

play01:16

compilations versus the x64 which is

play01:18

going to be what your shance is based on

play01:20

but still any bug in SSH because SSH is

play01:22

that ubiquitous control plane we all use

play01:25

for managing our systems therefore any

play01:27

problems found within it are a big deal

play01:29

deal matter of fact the last time we had

play01:31

this big of a deal found on SSH was all

play01:33

the way back in 2006 which actually this

play01:36

is the same bug it's a accidental

play01:38

regression back to that previous bug

play01:40

from 18 years ago in SSH so that does

play01:43

need to be patched I do highly recommend

play01:45

it the rest of the details are lots of

play01:48

little stuff you know why not throw the

play01:49

new Colonel version in here fix some of

play01:51

the other bug complaints that you find

play01:53

and there's always bug complaints people

play01:55

always are finding issues in edge cases

play01:58

and they inform the developers they Open

play02:00

tickets and that's how the ecosystem

play02:02

improves Chast is an open source project

play02:04

that puts out the updates that are done

play02:07

as best to the developers knowledge but

play02:09

it always does rely on users finding

play02:12

those edge cases that inform the

play02:14

developers of things that need to be

play02:15

fixed and changed there's a bunch of

play02:16

little things as I noted that are fixed

play02:17

here but when should you update well for

play02:20

me I like checking out the release

play02:21

candidate but that's me I like engaging

play02:24

with them I like helping get this

play02:25

product out I like testing the new

play02:27

features and that's fine for my non

play02:29

production system because I have

play02:31

production and non-production Jance

play02:32

systems well even what I may call

play02:34

non-production still does produce my

play02:36

videos and I will update those as well

play02:38

sometimes cuz hey I like to live on the

play02:40

edge a little bit but for those of you

play02:41

looking for a more stable release cycle

play02:44

when should you update maybe not on day

play02:47

one that's a fair way to look at it and

play02:50

I say that because if you look at

play02:51

something like the

play02:53

24041 change log you'll notice and we'll

play02:56

expand this real quick May 29th and this

play02:58

one was released on May 28th so waiting

play03:01

a couple days probably reasonable I

play03:04

generally even on client systems I don't

play03:07

think even waiting a week is too big of

play03:10

a deal provided there's not any major

play03:12

egregious problem that can't be

play03:14

mitigated Because by the way you could

play03:16

just turn off SSH for example if you

play03:17

needed to mitigate it until a production

play03:20

downtime window could be found so it's

play03:22

not like hair on fire as I noted but

play03:24

it's say maybe if you want to turn it

play03:26

off if there was some reason to

play03:27

facilitate it or if there was another

play03:28

bug found that was quite major maybe

play03:31

figure out ways to lock it off and

play03:32

mitigate it and then wait and schedule

play03:34

that maintenance downtime but generally

play03:36

waiting more than even a week I don't

play03:38

see the reason for most of the major

play03:40

problems are found there's a lot of

play03:41

people not just myself many in the

play03:43

community of course that jump right on

play03:45

these starting in the release candidates

play03:47

going into the releases and we start

play03:49

debugging right away because we want to

play03:50

see the project get better and if you're

play03:52

just one of the people who want to wait

play03:54

because you have other priorities and I

play03:55

completely understand that hey waiting a

play03:57

week seems reasonable maybe two I

play03:59

wouldn't wait a year though that is

play04:01

where I see people getting a little far

play04:03

off track and maybe outside of the

play04:05

migration path now that's all listed

play04:06

here how you migrate these and the

play04:08

different versions you can do but don't

play04:10

let these get too far behind because

play04:12

skipping ahead uh is a little bit harder

play04:14

then because you want to make sure

play04:16

you're updating 2204 to 2212 to 2302

play04:20

they have the migration path all listed

play04:22

right here in documentation or if you're

play04:24

on shes core and you want to know what

play04:25

version updates to it core 13061 can be

play04:29

updated to the latest uh they should

play04:31

probably fix this to say

play04:33

24.02 now so that's definitely a path by

play04:36

which you can migrate on here now let's

play04:38

talk a little bit about true charts

play04:40

tress scale failed to sync true charts

play04:42

catalog well this didn't take long to

play04:45

track down the problem they've deleted

play04:47

the true charts catalog they've

play04:48

abandoned the project they have well

play04:51

completely eliminated and I never

play04:53

recommended true charts I was always a

play04:54

little hesitant and there's a Reddit

play04:57

post we'll talk about as well where they

play05:00

grab a screenshot of what was posted in

play05:02

their Discord because for some reason

play05:03

they don't like forums they think

play05:04

discords are forums and Discord is not a

play05:07

great place for forums it's because it's

play05:08

not searchable or indexed and it's a

play05:10

proprietary system so I'll stop ranting

play05:12

there it's why we had to have a

play05:14

screenshot and then post it over in

play05:16

Reddit and in the trass forums about

play05:18

they have now decided it's gone this is

play05:21

a lot of debate back and forth and

play05:23

there's clearly a lot of heated

play05:24

discussions and I'll leave links to this

play05:26

if you want to dive into the drama but

play05:28

one of the things I never OD about true

play05:30

charts and this right here is kind of

play05:34

like a weird adversarial instruction

play05:37

what I mean by that is all guides under

play05:39

this section are made for tras scale we

play05:40

do not control anything made by a

play05:42

systems no matter how good or bad it is

play05:44

more specifically we have no control at

play05:46

all over the following and they talk

play05:47

about some of the problems because there

play05:48

was always a lot of breaking changes

play05:50

which is why I didn't recommend it as

play05:52

well as the issue of them wanting to use

play05:55

the storage as opposed to host path

play05:57

which made it confusing to people not

play05:59

knowing where their data is and as

play06:01

someone who runs forums myself

play06:02

participate in the community and does

play06:04

Consulting we ran into lots of people

play06:06

losing data because they didn't

play06:07

understand where it was saving the data

play06:09

when you follow the instructions just

play06:10

setting it up and letting it control

play06:12

your storage as opposed to being

play06:14

implicit with the host path but one more

play06:16

thing I want to point out and I had to

play06:18

use the Wayback W machine for this

play06:20

important must read and this is how it

play06:22

used to read before they changed it this

play06:24

is my first more or less introduction to

play06:26

True charts and it really kind of turned

play06:28

me off to the project all guides under

play06:30

the section are made for True N scale we

play06:31

do not control anything made by I

play06:33

systems familiar statement No matter how

play06:35

great or shitty it is I thought this was

play06:37

a weird way to say I want to help this

play06:40

product but it's garbage I don't it's

play06:42

not my problem it's garbage and I

play06:43

thought that's just like a weird

play06:44

attitude to come in with and it was kind

play06:47

of well if you read the Reddit drama

play06:49

that is posted in there and some of the

play06:51

drama going on in her Discord I just

play06:53

don't think they're probably the best

play06:55

for the open source Community this type

play06:57

of attitude just you know I don't really

play06:59

get I am not adversarial with the people

play07:02

at I ex systems I do like the fact that

play07:04

they're going to Docker but I think they

play07:05

put a lot of hard work and effort into

play07:07

it and I've never just dunked on them I

play07:08

like it as a product doesn't mean I

play07:10

think it's perfect but I have a nice

play07:12

civil discussion I don't just call their

play07:14

product garbage and then use it and like

play07:16

I said this is a weird relationship they

play07:18

seem to have with them and I just said

play07:20

you know I'm going to stay away from

play07:21

this and that's why I've not done or

play07:23

taken the time to do any videos on true

play07:24

charts which actually worked out quite

play07:26

well because well it's gone now now I

play07:28

have links to everything I mentioned

play07:29

down below if you feel like reading more

play07:32

uh but if you're wondering if there's a

play07:33

way to migrate your apps or get your

play07:36

data out hopefully you have taken the

play07:39

time to set it up properly with host

play07:40

pass because I have recommend that even

play07:42

for people using any of the applications

play07:44

and IX systems to set it that way so you

play07:46

can figure out a way to migrate your

play07:48

data if the apps are working they should

play07:49

remain working but they are no longer

play07:51

going to get updates or anything related

play07:53

to True charts so export your data

play07:55

figure out your plan B and yes they are

play07:58

coming and I'm excited for this with

play08:00

Native Docker support that is on the

play08:02

road map now for TR ascale that's pretty

play08:04

exciting I'm looking forward to that

play08:06

because that is a preferred method in my

play08:08

opinion because it's simpler it's well

play08:10

documented I don't think docker's going

play08:12

anywhere it's a little bit too popular

play08:13

if you will be that I don't think this

play08:15

is going to be one of those things that

play08:16

get deprecated and we're all left and

play08:18

alert I think we'll watch a slow erosion

play08:20

over over time and we'll switch to

play08:22

something else sometime far into future

play08:23

but that future is not now today Docker

play08:26

works great we've talked about it a few

play08:28

times on this channel and you can

play08:30

certainly find many other channels and

play08:31

many other writeups on how to set Docker

play08:33

things up which is going to really

play08:34

expand the options for running

play08:36

applications on trath so I'm excited and

play08:39

looking forward to that future as always

play08:41

like And subscribe to see more content

play08:42

from this channel leave your thoughts

play08:44

and comments down below head over to my

play08:45

forums forums. laen systems.com if you

play08:48

want to have a more in-depth discussion

play08:49

about this or other topics and thanks

play08:54

[Music]

Rate This

5.0 / 5 (0 votes)

Étiquettes Connexes
TrueNAS SCALEMise à jourSécurité SSHTrue ChartsStockageOpen SourceMise à jour systèmeDocker SupportCommunityTutoriel