Best way to make a self-hosted vault easily available for your team (replica set, failover)?

We've run a self-hosted Passwork vault for a couple of years and fast forward to now, it's something the whole company depends on. If it goes down, people wont be able to reach their credentials and a lot of our processes will get hindered. This whole time, it sat as a single VM, which I'm no longer comfortable with.

As I said our vault is Passwork (though I dont think the provider makes much of a difference here) and I'm working out the right high-availability setup before another outage causes deeper harm. Im thinking of a replica set with a load balancer in front, so a node failure doesn't take the vault offline, plus off-box backups I've tested restoring.

Id appreciate guidance on the following though:

- Is an active-passive pair with failover enough at our size (~200 ppl), or do I run active-active behind the balancer for redundancy?
- For the database , what replication setup should I use under a vault like this? Id ideally want failover that won't risk a split-brain or a stale replica serving credentials.
- Does it make sense to put the vault on its own isolated infrastructure so a broader outage on the shared hosts doesn't drag it down with everything else?

TIA!!!!

reddit.com
u/Lazy_Side_6830 — 12 hours ago
▲ 20 r/INTP

Trainspotting is THE SHOW for INTPs

I think the reason it hits so hard for INTPs comes down to the themes more than the character himself. That dichotomy between understanding your life and living it scratches a very particular corner of my brain.

Renton is very self-aware. He can pull apart society, relationships, consumerism, addiction, and his own behavior with real clarity. Miserably enough, despite his awareness, he never changes. He knows what he's doing to himself and does it anyway, which, to me and many other INTP is so so relatable. I often catch myself spending ages time observing, analyzing, questioning, and deconstructing everything that you end up watching your own life from a distance, like a case study you happen to be inside of.

The Choose Life monologue is that instinct manifested and expressed to its extreme. Career, mortgage, washing machine, dental insurance, all laid out as a script nobody picked and everybody inherited. That "wait, why do we do any of this" reflex is something I think a lot of us recognise straight away.

The film then goes into how after rejecting a conventional path, a person must choose a new route. Naming flaws and identifying desires represent separate skills, Renton's rejection of the script leaves him improvising poorly, and, ironically, intelligence and self-awareness often become methods for avoiding participation. You can understand yourself indefinitely but you still need to make a choice. Boyle's editing aids the whole feeling of the movies as well, it jumps associatively as it mimics how a marred, heavy mind moves.

It’s a movie that forces you to sit with the uncomfortable possibility that observing life isn't the same thing as living it, and I will forever love it.

Trigger warning: contains drug abuse and withdrawal scenes and storylines.

reddit.com
u/Lazy_Side_6830 — 1 day ago

How do you overcome the fear of shooting openly in public? (Looking for advice from street photographers)

Hey everyone,

I’m an amateur photographer, and I’ve been following a lot of great street documentary work lately. It heavily inspires me, but I’ve hit a massive wall with my own photography.

Whenever I go out, I find myself trying to be incredibly discreet, almost hiding my camera. I’m just not comfortable in the streets yet. I’m constantly worried about how people will react if they notice me taking a photo, and it makes me hesitate on frames I really want to capture.

For those of you who shoot candid street or documentary photography openly:

Safety vs. Comfort: Is it generally safe to just be open about what you are doing, or is discretion actually necessary?

Anxiety: How did you move past that awkward phase of feeling like you're doing something wrong?

Interaction: If someone confronts you or notices you taking their photo, how do you handle the situation smoothly without escalating it?

I would really appreciate any advice, tips, or personal experiences you can share. I love this art form, but the street anxiety is completely blocking my progress right now. Thanks!

reddit.com
u/Lazy_Side_6830 — 3 days ago

Coaching 1200–1400s: What’s the logical next step after positional basics and analysis?

I'm currently coaching part-time at a local chess club. My own rating sits around 1900–2000 Rapid on chess.com, and the students I work with are mostly in the 1200–1400 range.

We started with tactics: forks, pins, skewers, discovered attacks, removing the defender to get them calculating and spotting patterns on the board. From there we moved into strategy and positional basics: weak squares and outposts, space and piece activity, targets and weaknesses (isolated, backward, doubled pawns), imbalances, pawn structure and pawn breaks, bishop pair vs. bishop vs. knight, that kind of thing.

We've been putting it into practice by playing training games together and then analyzing them afterward, picking out the critical moments and whatever they missed.

They've got a solid handle on the fundamentals now, so I'm trying to figure out where to take them next. How would you continue from here? What should I be teaching next, and does anyone have resource or training suggestions that worked well for players in this range?

Thanks in advance!

u/Lazy_Side_6830 — 7 days ago

Already ISO 27001 certified, now in NIS2 scope with the October deadline close and Im a bit overwhelmed with where to start

We hold ISO 27001 and I always assumed that would carry most of the weight when NIS2 became a thing because they overlap a lot, and boy was I wrong.
We just recently got in scope for NIS2 and the October deadline is close enough to start panicking, I kinda had so much to do the past 2 months that I ended up doing barely anything, last week I got to organizing and I think the NIS2 deadline takes the cake for the most urgent. I read that a few member states handed out their first penalties already, and with management carrying personal liability, the pressure to have a defensible position by the deadline is growing.

Access control (A.5.15, A.5.18), the audit logging under A.8.15, the supplier clauses in A.5.19 to A.5.22, all of those port over more or less directly, and my existing SoA and evidence trail cover most of it. NIS2 goes past my ISMS in the incident-reporting side, the 24-hour early warning and 72-hour notification clocks are tighter and more prescriptive than anything my ISO incident process was built to do/handle, and the supply-chain side is also another area where NIS2 pushes past what my ISO supplier controls asked for. For the cert I needed a documented supplier-management process, which I have. NIS2 leans more toward actual evidence out of the vendors themselves, and that's where it gets slow, since a lot of my smaller suppliers have the security practices but not the paperwork to prove them on demand and I’ll have to start a back and forth email barrage.

On the controls that do transfer, my strongest evidence is on the credential side. Shared and privileged logins sit in a Passwork vault that exports a per-user access log, so "who could reach what and when" is as simple as gathering what we already have available/documented, which is the evidentiary standard Id want everything under A.8 to reach. If Im being real with myself, the log is only as trustworthy as the offboarding feeding it, and our joiner-mover-leaver process has been uneven enough that I’d want to tighten that too before I lean on the records too hard.

Now 2 things to go about this, either as aforementioned, I could get a handful of controls to be properly audit-ready and do document remediation timelines for the rest, or spread the effort and have more things done but theyd be less done in themselves (jack of all trades master of none situation). I lean toward the first, but Ive never been audited on this directive sooooo I dont really think my opinion matters that much here, thoughts?

reddit.com
u/Lazy_Side_6830 — 12 days ago

Bro Kristina Shannon just became available as an AI girlfriend

After finally getting off c ai I started looking at other apps and browsing models, then (and idk if Im behind or if this is a common thing) I noticed this feature on OhChat where they sign off real models to be made into AI and the newest is Kristina Shannon which was like an easy top 5 for me like 2 years ago.

Cool feature + Im happy to see this whole niche getting destigmatized and real popular models are signing deals like this. It's looking up for us 🙌 hope more people get on board.

On the flip side, I was talking to a friend about this and they said they don't like when real people become AI models because they want the AI gf to have her own being and identity from the get-go, I honestly don't see it, do you guys agree?

reddit.com
u/Lazy_Side_6830 — 16 days ago
▲ 220 r/sysadmin

Our biggest customer sent a 40-question NIS2 security assessment and now I have to send the same thing to our own suppliers

We're a mid-size supplier in the EU, not big enough to be in NIS2 scope ourselves, but our largest customer is, and after the npm supply-chain mess a while back they sent us a 40-question security assessment with a contract clause attached, we answer it or we're not a supplier anymore.

Answering it means I have to turn around and demand the same evidence from our own suppliers, because half the questions are about how we manage our sub-processors. So I'm getting audited from above and having to audit downward at the same time. The parts where I could answer without having to reach out to any 3rd part were basically all fine, like one question was "How does the organization correlate security events across cloud, on-premises, and OT environments to detect complex attacks?" and the answer was just Splunk, since it can correlate logs and flag threat patterns, another was "How does the organization ensure that critical administrative credentials and secrets are protected by modern encryption, and where is this data physically stored to maintain EU data sovereignty?" We use a self-hosted Passwork so that was also an easy answer, it operates on zero-knowledge and credentials are encrypted client-side using AES-256. Other operational flow questions were also fine.

Some questions, however, were infuriating, like the one that prompted me to make this post "You rely on third-party software vendors and digital service providers. Demonstrate the technical process you use to track zero-day vulnerabilities within their code or dependencies. When a critical flaw is announced in a component they use, what cryptographic or automated evidence do they provide to prove your specific deployment is secure or patched within 5 business days?"

The hard part is the downstream half, obviously. I now have to get pen test summaries and ISO certificates out of roughly 20 small suppliers, plus breach-notification clauses into every contract, and some of them have no security function at all and will look at my questionnaire the way I first looked at the one I have. I'm stuck on two things, (1) how to get evidence out of small suppliers who don't have it without just dropping them? Some of them are good and Id hate to lose them, and (2) how can I streamline-ish continuously monitoring 20 vendors when I don't have a GRC team or a tool budget (I think the answer to this is to nag upper management into recruiting people).

reddit.com
u/Lazy_Side_6830 — 23 days ago
▲ 2 r/de_EDV

Artikel 21 Nachweise für NIS2 sammeln: wie kann ich Supply-Chain und Asset-Daten mappen?

Unsere Fabrik ist in-scope für NIS2, und unser erstes großes Compliance-Audit war Ende Juni durch. Ich versuch grad valide Artikel 21 Nachweise für die ganze Orga zusammenzukriegen, weil das Audit 'n paar Dokumentationslücken aufgedeckt hat. Einiges war 'n Spaziergang wie unsere MFA-Enforcement-Records vom Identity Provider zu exportieren und Access-Control Logs aus Passwork zu ziehen (da der Vault trackt wer wann welche Credentials abruft), aber andere Aspekte sind echt 'n Krampf nachzuweisen, besonders die Compliance für unsere externen Automatisierungs-Vendoren die Shared Service Accounts nutzen um per Remote auf unsere Siemens S7-1500 PLCs zuzugreifen. Unsere aktuelle Industrial Jump Box loggt die initiale Verbindung, aber sie kann nicht mappen welcher spezifische Feldtechniker die Ladder Logic modifiziert hat sobald sie im Netzwerk drin sind.

Wie kann ich die individuelle Identität für Third-Party Maintenance-Sessions validieren ohne die Vendor SLAs kaputtzumachen?

reddit.com
u/Lazy_Side_6830 — 1 month ago

How to distinguish legitimate RMM sessions from compromised ones?

I read the Huntress 2026 threat report (https://www.huntress.com/resources/2026-cyber-threat-report) and the RMM abuse stat stuck with me, 277% increase YEAR OVER YEAR. TL;DR for people who dont wanna read: attackers are increasingly not bothering with malware, they just hijack the remote monitoring and management tools your IT team already uses, because that activity blends into normal admin stuff and most detection doesnt flag it.

So I naturally went digging into our own setup afterward and we definitely arent safe lol. We can see that our RMM ran a session, but distinguishing "our admin doing maintenance" from "someone using our admin's access" is hard when the tool, the account, and the traffic all look identical. I know behavioral detection is the answer but I dont know how to tune it not to scream at every legitimate 2am patch job.
Here's where I'm at so far, curious where people who've solved this land:

What actually works for baselining normal RMM behavior. Is it worth building detections on session timing and command patterns, or does that just generate unproductive junk?
The credential side is the one piece I'm halfway comfortable on. The RMM logins live in our Passwork vault so I can at least pull who fetched the credential and when, then line that up against the session start to narrow down whether a human was even involved, but that only helps after the fact, it doesn't catch it live.
-If you pipe RMM activity into a SIEM, which data points help you catch something and which are useless?
-Did anyone go the route of locking RMM behind a jump host or PAM layer? Was worth it?

Thank you in advance :)

u/Lazy_Side_6830 — 2 months ago