<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Debian on Kohanyi News</title><link>https://kohanyi.net/tags/debian/</link><description>Recent content in Debian on Kohanyi News</description><generator>Hugo</generator><language>en-us</language><copyright>&lt;a href="https://creativecommons.org/licenses/by-sa/4.0/" target="_blank" rel="noopener"&gt;CC BY-SA 4.0&lt;/a&gt;</copyright><lastBuildDate>Wed, 19 Aug 2026 10:30:00 +0000</lastBuildDate><atom:link href="https://kohanyi.net/tags/debian/index.xml" rel="self" type="application/rss+xml"/><item><title>Linux rc.local on Modern Systemd (Debian 13)</title><link>https://kohanyi.net/posts/2026/08/linux-rc.local-on-modern-systemd-debian-13/</link><pubDate>Wed, 19 Aug 2026 10:30:00 +0000</pubDate><guid>https://kohanyi.net/posts/2026/08/linux-rc.local-on-modern-systemd-debian-13/</guid><description>&lt;p&gt;If you miss the old &lt;code&gt;/etc/rc.local&lt;/code&gt; from the SysV days &amp;ndash; it still&#10;works on modern systemd systems. You just need to enable it manually.&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="create-the-systemd-service-unit"&gt;Create the systemd service unit&lt;/h2&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo nano /etc/systemd/system/rc-local.service&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Paste this:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-ini" data-lang="ini"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;[Unit]&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;Description&lt;/span&gt;&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;/etc/rc.local&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;ConditionPathExists&lt;/span&gt;&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;/etc/rc.local&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;[Service]&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;Type&lt;/span&gt;&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;forking&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;ExecStart&lt;/span&gt;&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;/etc/rc.local start&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;TimeoutSec&lt;/span&gt;&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;0&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;StandardOutput&lt;/span&gt;&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;tty&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;RemainAfterExit&lt;/span&gt;&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;yes&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;SysVStartPriority&lt;/span&gt;&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;99&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#66d9ef"&gt;[Install]&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;WantedBy&lt;/span&gt;&lt;span style="color:#f92672"&gt;=&lt;/span&gt;&lt;span style="color:#e6db74"&gt;multi-user.target&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="create-rclocal"&gt;Create rc.local&lt;/h2&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo nano /etc/rc.local&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Paste this:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#!/bin/sh -e&#10;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# rc.local&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# This script is executed at the end of each multiuser runlevel.&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Make sure that the script will &amp;#34;exit 0&amp;#34; on success or any other&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# value on error.&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# In order to enable or disable this script just change the execution&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# bits.&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;#&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# By default this script does nothing.&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;exit &lt;span style="color:#ae81ff"&gt;0&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="enable-and-test"&gt;Enable and test&lt;/h2&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo chmod +x /etc/rc.local&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo systemctl enable rc-local&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo systemctl start rc-local.service&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo systemctl status rc-local.service&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;hr&gt;&#10;&lt;h2 id="notes"&gt;Notes&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Any commands placed before &lt;code&gt;exit 0&lt;/code&gt; will run at the end of every&#10;multiuser boot. Useful for old habits, kernel tweaks, or hardware&#10;init that doesn&amp;rsquo;t have a proper systemd service yet.&lt;/li&gt;&#10;&lt;li&gt;This works on Debian 13 Trixie. Also works on Ubuntu 18.04+,&#10;RHEL 7+, and most modern distros.&lt;/li&gt;&#10;&lt;/ul&gt;</description></item><item><title>Setting Up Serial Console Access on a Linux Server</title><link>https://kohanyi.net/posts/2026/08/setting-up-serial-console-access-on-a-linux-server/</link><pubDate>Wed, 19 Aug 2026 10:00:00 +0000</pubDate><guid>https://kohanyi.net/posts/2026/08/setting-up-serial-console-access-on-a-linux-server/</guid><description>&lt;p&gt;If your server has a virtual serial port &amp;ndash; like HP iLO, Dell iDRAC,&#10;or any BMC that exposes a serial console over SSH &amp;ndash; this gets you&#10;keyboard-in-the-face access before the network stack is even up.&lt;/p&gt;&#10;&lt;p&gt;Useful for debugging boot issues, GRUB recovery, or just not having to&#10;walk to the machine room.&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="find-your-serial-port"&gt;Find your serial port&lt;/h2&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo dmesg | grep tty&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Look for something like &lt;code&gt;ttyS0&lt;/code&gt;, &lt;code&gt;ttyS1&lt;/code&gt;, etc. On many systems:&lt;/p&gt;</description></item><item><title>Debian with Encrypted Root and Automatic Unlock via Tang + Clevis</title><link>https://kohanyi.net/posts/2026/08/debian-with-encrypted-root-and-automatic-unlock-via-tang--clevis/</link><pubDate>Wed, 19 Aug 2026 09:30:00 +0000</pubDate><guid>https://kohanyi.net/posts/2026/08/debian-with-encrypted-root-and-automatic-unlock-via-tang--clevis/</guid><description>&lt;p&gt;A recipe for installing Debian with a LUKS-encrypted root filesystem and&#10;configuring it to unlock automatically at boot using Tang and Clevis&#10;(Network-Bound Disk Encryption).&lt;/p&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; This process will nuke all data on the drives you&#10;target. Back up anything you want to keep before you start.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;This works on plain ext4 on LUKS (Part 1 below) and on&#10;&lt;a href="https://kohanyi.net/posts/2026/08/debian-13-with-encrypted-zfs-root-zfs-on-luks/"&gt;ZFS on LUKS&lt;/a&gt;&#10;equally &amp;ndash; Clevis binds to the LUKS layer regardless of what is on top.&lt;/p&gt;</description></item><item><title>Debian 13 with Encrypted ZFS Root (ZFS on LUKS)</title><link>https://kohanyi.net/posts/2026/08/debian-13-with-encrypted-zfs-root-zfs-on-luks/</link><pubDate>Wed, 19 Aug 2026 09:00:00 +0000</pubDate><guid>https://kohanyi.net/posts/2026/08/debian-13-with-encrypted-zfs-root-zfs-on-luks/</guid><description>&lt;p&gt;A step-by-step recipe for installing Debian 13 (Trixie) with a fully encrypted root filesystem using ZFS on top of LUKS.&lt;/p&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; This process will nuke all data on the drives you target. Back up anything you want to keep before you start.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;p&gt;This gives you the integrity and snapshot features of ZFS, with the whole disk encrypted at rest. I use this on my home servers and VPS instances.&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="prerequisites"&gt;Prerequisites&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Debian 13 &lt;strong&gt;Live&lt;/strong&gt; ISO (the standard live image, not the netinst)&lt;/li&gt;&#10;&lt;li&gt;Two disks for a mirror, or one disk if you are starting small&lt;/li&gt;&#10;&lt;li&gt;UEFI boot (recommended for modern systems)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="why-not-just-zfs-native-encryption"&gt;Why not just ZFS native encryption?&lt;/h2&gt;&#10;&lt;p&gt;ZFS native encryption (zencrypt) exists and works. But LUKS gives you a battle-tested crypto layer that GRUB, initramfs, and every Linux tool understand natively. Combined with ZFS on top, you get the best of both worlds.&lt;/p&gt;</description></item></channel></rss>