Can you install your own software when being an IT system admin

vim and nano are essential.Remember you might be learning for the Red Hat cert , but commands like nano and vim are universal , and are used in all linux distro's.

Not to mention vim syntax is used inside many other tools.
 
A system admin cannot install random software on the server without the company's approval.

1. It could cause licensing issues and fines.
2. It can allow for hacking into the server
3. It can take up resources meant for other tasks, which can slow down business productivity
4. Any outing can cause business to loose money, this will most likely get you fired.

So no, you cant randomly install software which you think may be good, it has to go through architecture, then testing and certification, and so on. If you go ahead and just do it, they may happily fire you for putting their business at risk.

We had someone install photoshop on a desktop without licensing, Adobe that checks our environment for licensing scanned that it was installed for 9 years. We got slapped with R35k per year x 9.

The staff member was fired, and the loss incurred was deducted off his pension.

Of course they can, if they have the permissions to do so.

Policy <> Ability to do things.

And 99% of the time nobody is going to blink or have such a drama as per your example even if policy says otherwise.

A desktop user installing Adobe (why do they have an administrator account?) is not the same as an IT person installing a tool on a Linux server, not on any level.
 
Cockpit has a web UI. It's a key part of the main enterprise product.
not familiar with this,i dont think its in the study guides.this cert is already difficult and i do not want to lay extra stress with this program, rather gonna stick to the rules and follow the path.Got a week left then i am done.After that do the course over again.I then will look into that
 
Can you? Sure you can.

You can also disable the firewall and enable iis among many other things.
 
A system admin cannot install random software on the server without the company's approval.

1. It could cause licensing issues and fines.
2. It can allow for hacking into the server
3. It can take up resources meant for other tasks, which can slow down business productivity
4. Any outing can cause business to loose money, this will most likely get you fired.

So no, you cant randomly install software which you think may be good, it has to go through architecture, then testing and certification, and so on. If you go ahead and just do it, they may happily fire you for putting their business at risk.

We had someone install photoshop on a desktop without licensing, Adobe that checks our environment for licensing scanned that it was installed for 9 years. We got slapped with R35k per year x 9.

The staff member was fired, and the loss incurred was deducted off his pension.

stop being a Karen now.Its generally assumed that if you are a systems admin , you know what you are doing.You will do what you need to get the job done.
 
A desktop user installing Adobe (why do they have an administrator account?) is not the same as an IT person installing a tool on a Linux server, not on any level.
Reading this and thought exactly the same. They should really relook their company policies and what users are allowed to install what

End users compared with your sys admin or infrastructure engineers, like comparing apples with dragonfruit never mind pears.
 
Reading this and thought exactly the same. They should really relook their company policies and what users are allowed to install what

End users compared with your sys admin or infrastructure engineers, like comparing apples with dragonfruit never mind pears.

Yeah find it hilarious how someone as a Linux admin apparently “cannot” install software as and when they please, but every end user has full admin rights to install whatever they want and then allegedly got fired for it.

Pull the other one please.
 
ok so i was thinking if something could be better why would they deny it.
your installed software might come with libraries or dependencies that replaces older libraries that might be needed for you companies software to run properly. So I think they would like to know how you'll fix it or roll back if that happens. Usually discussed as part of change management meetings.
Of course, if your companies software is containerized, then it might not be an big issue.
 
Last edited:
Usually discussed as part of change management meetings.

And here is the crux. Making a change to production servers requires approval by both IT and business which normally means it’s been tested and signed off as compatible. During change management your change will get selected by business if it’s installed on production and you have to have the required processes in place otherwise it gets rejected right then and there. Install it without a change request in place and you’re looking at disciplinary hearings.

I see 2 very different type of IT environments arguing in this thread.
 
your installed software might come with libraries or dependencies that replaces older libraries that might be needed for you companies software to run properly. So I think they would like to know how you'll fix it or roll back if that happens. Usually discussed as part of change management meetings.
Of course, if your companies software is containerized, then it might not be an big issue.

Precisely, it's a very big blanket statement that doesn't apply to all companies nor all software, depending on scale and implementation of systems.

Many (I would say most) companies don't even have change management in place (whether wilfully or unknowingly) or this kind of thing doesn't even come across the radar for them.

Some run on-premises systems with massive independencies like you mention, other run individual app on their own systems in the cloud and others still containerise it all across cloud and on-prem and the approach will be entirely different for each of them.

I worked as a Linux Admin in a Managed Services capacity in my previous role across hundreds of customers and not even once did I need to get approval or follow a change management process to install anything on those systems across HP-UX, CentOS, SunOS, Red Hat etc etc all over the world.

On the flip side 15-20 years ago I needed to have weekly meetings about this kak and log tickets to get actual permissions because it was all locked down and impossible to move and get your job done. Ironically those were all Windows systems back then.

Every business is going to be vastly different.
 
And here is the crux. Making a change to production servers requires approval by both IT and business which normally means it’s been tested and signed off as compatible. During change management your change will get selected by business if it’s installed on production and you have to have the required processes in place otherwise it gets rejected right then and there. Install it without a change request in place and you’re looking at disciplinary hearings.

I see 2 very different type of IT environments arguing in this thread.

That's only where extreme Change Management is a thing and it seems the assumption is made that this is always the case where I would argue Change Management is actually less and less prevalent in the modern world of being agile and moving faster.

Again, it's very dependant on what kind of business and what kind of operations are in play and then also how they are structured and how risk is managed.

An IT admin needing to install a tool to make their life easier is not worthy of a change request. Especially not if something has gone wrong and it's a case of high priority troubleshooting.

I usually get called when the **** has hit the fan and it would be impossible for me to get my work done in a timely manner and adhere to SLA's etc if I first needed to ask permission and get a change process completed. Revenue loss at any given time far outweighs any change management bullshit, which most of the time is just fabricated job creation anyway.
 
That's only where extreme Change Management is a thing and it seems the assumption is made that this is always the case where I would argue Change Management is actually less and less prevalent in the modern world of being agile and moving faster.

Again, it's very dependant on what kind of business and what kind of operations are in play and then also how they are structured and how risk is managed.

An IT admin needing to install a tool to make their life easier is not worthy of a change request. Especially not if something has gone wrong and it's a case of high priority troubleshooting.

I usually get called when the **** has hit the fan and it would be impossible for me to get my work done in a timely manner and adhere to SLA's etc if I first needed to ask permission and get a change process completed. Revenue loss at any given time far outweighs any change management bullshit, which most of the time is just fabricated job creation anyway.
So in bold what you mean is there is no need for it as you are the highest on the pyramid and making life easier and more productive does not require one to submit a ticket,but wait why would the main IT guy submit a ticket when he is the one that receives it.If you the senior sysadmin nothing can stop you right.
 
So in bold what you mean is there is no need for it as you are the highest on the pyramid and making life easier and more productive does not require one to submit a ticket,but wait why would the main IT guy submit a ticket when he is the one that receives it.If you the senior sysadmin nothing can stop you right.

Not at all, this is applicable across the board for anyone in my team and other similar positions in the business.

The risk mitigation was done when we employed people who knew what they were doing, it’s entirely unnecessary to babysit professionals and just slows them down.

Results are based on outcomes, not how many bullshit tickets you logged that weren’t necessary in the first place.

Trust your people.

Staging and test environments also exist for a reason. Nothing that goes into Production would be a surprise.

But note I’m speaking specifically in the context of your original questions here. Someone installing a free tool inside a Linux environment to facilitate them working better is a non-event with zero impact and I’ve got enough monitoring in place to detect and alert on something truly dodgy.

Someone upgrading a database or migrating a server is a whole different story that requires a maintenance window and communications to stakeholders etc as it has business impact.

Also, even the top tier engineer needs someone else to accept their changes, otherwise the entire system is flawed.
 
Last edited:
It seems very complicated and sometimes confusing.I have not worked in an IT environment and cant wait to experience this.Been to long in the automotive industry .
 
It took me 5 hours of intense research and testing and practical session just to mount a usb flash drive with iso on and transfer it to proxmox server to make a redhat vm,I have not made the vm yet.Gawd damn proxmox.I was getting error after error for hours.I need to know is proxmox a good idea for homelab or is there an easy way .
The error i was getting just happend after load shedding kicked in with the pc.I forgot to turn it off.I had to reinstall proxmox 3 times ffs.
UPDATE:
I do have another problem centos stream 9 gives kernal panic when installing it as vm in proxmox,I visit the proxmox forum and many people having this issue.There are fixes but they not working for me.Anyone got other ideas thanks
 
Last edited:
It took me 5 hours of intense research and testing and practical session just to mount a usb flash drive with iso on and transfer it to proxmox server to make a redhat vm,I have not made the vm yet.Gawd damn proxmox.I was getting error after error for hours.I need to know is proxmox a good idea for homelab or is there an easy way .
The error i was getting just happend after load shedding kicked in with the pc.I forgot to turn it off.I had to reinstall proxmox 3 times ffs.
UPDATE:
I do have another problem centos stream 9 gives kernal panic when installing it as vm in proxmox,I visit the proxmox forum and many people having this issue.There are fixes but they not working for me.Anyone got other ideas thanks
My responce on a previous thread about Proxmox - https://mybroadband.co.za/forum/thr...ice-ha-plex-sonarr-etc.1255390/#post-31824990
 
My opinion based on my own experience in this space:

These distros like Proxmox, TrueNAS (especially TrueNAS), pfsense (most professional of these bunch) are on a whole different level.
Their release philosophy and their standards are incredible low.
This is part of the reason the large cloud providers have become so popular.

Breaking releases are waved away like "well it's free".
That is fundamentally the problem with their approach to software development.
They are actually doing this as a day job and they are actually getting paid.

But because they are "giving it away for free", they feel entitled to a very low quality bar.

If I said some of the things these guys say publicly I'd lose my job.
The professionalism is just not there.

But note I’m speaking specifically in the context of your original questions here. Someone installing a free tool inside a Linux environment to facilitate them working better is a non-event with zero impact and I’ve got enough monitoring in place to detect and alert on something truly dodgy.
FWIW I work for a fairly large cloud provider and we moved to humans not allowed in terms of anything that is production quite a few years ago.
Our deployments have been hands off now for years.
The servers are constantly rotated (automatically) and software redeployed (automatically). (ie. the entire VM is replaced and moves between machines, etc.)
It exercises the path pretty well and avoids nasty surprises from "special servers" suddenly dying and being a mission to replace.

To make sure we can unblock people from fixing things if it goes really bad we have a break glass mechanism.
You can ssh to a host by breaking glass which sets off a lot of alarms and logs a transcript of what you are doing.
Systems with higher confidentially levels (ie. stores customer data like CC info, and so on) don't typically have a break-glass or has several additional restrictions for break glass for obvious reasons.

But overall in our world where we have millions of servers, the data has shown again and again that having people do things on servers is a bad thing, no matter how accomplished, professional, well intentioned or educated the individual believes they are. It doesn't work.
Not if you care about your customers and providing them with a stable product.

A desktop user installing Adobe (why do they have an administrator account?) is not the same as an IT person installing a tool on a Linux server, not on any level.
My opinion again but:

What's good for the Adobe installer on their company issued laptop, is good for an "IT admin", "dev ops eng.", etc.

We've actually gone completely the opposite. Everyone has admin rights on their computers (except if it is shared like call centers). Because it drastically reduces friction for "getting it done". Instead we assume zero trust. Treat each individual laptop/desktop/etc. as compromised and zero trust.

The opposite is building a walled garden which is inherently incredible fragile.

LastPass has gone through some epic hack attempts and it shows the fragility IMO of this walled garden approach.
They allowed some of the "super engineers" access to incredible sensitive databases and that person became a target of a long game.
Compromising that single individual brought down their walled garden.

This is true of any system or individual that is protected by a walled garden, at some point the wall is going to get compromised. A good engineer recognizes that it can never be completely secure, a bad "engineer" insists on more restrictions and lockdowns. It is the same as a dictator attempting to hold on to their power. Eventually it comes crashing down.

Ofc. the zero trust model is not perfect either, but it is inherently built on the concept of free will = bad stuff gonna happen. Which more accurately reflects our reality.

If humans really do need access to insane things like a database with every users passwords database, I suspect the CIA is onto something there with SCIF approach.
 
Top
Sign up to the MyBroadband newsletter
X