Linux+ Break Room · Case 10
The séance
Every ghost from every case, summoned at once. No hints this time.
The house has one job tonight: the beacon, a little web service, must answer at http://10.66.6.10:8080. It doesn't. Something else answers the door instead, and it keeps coming back. The beacon's service won't even load. Its disk is full of something that isn't data. Its config shows a secret to anyone who looks. It has more power than it should. A health check swears everything is fine. And even when all that is fixed, the door still won't open. You've met every one of these ghosts before. Name them all.
⚠️ This case needs sudo
- Play it on a practice VM (a free Ubuntu VM, a spare Pi, a lab node), not a machine you care about.
- Everything happens on a pretend address,
10.66.6.10, on a dummy cardghost10that only this machine can reach. Your real network, SSH and firewall are left alone. - It creates a user
beacon, two services, a cron file, a sudoers file, a tiny RAM disk, two nftables tables (one of them is only a guard that keeps other machines out) and a health script.--cleanremoves all of it. - The spoilers are at the bottom of the script. Read the top for safety, then stop.
- Rebooted in the middle? Run the script again: the pretend card and the tiny disk don't survive a reboot.
Get the case
Rule 4: read it before you run it, less breakroom-mission-10.sh. The top of the file lists everything it creates and how --clean removes it.
curl -O https://arunnetworkingpro.com/labs/breakroom-mission-10.sh
sudo bash breakroom-mission-10.sh
At any point, ask the house how many ghosts are left:
sudo bash breakroom-mission-10.sh --check
The séance
Light the beacon
curl -s --max-time 5 http://10.66.6.10:8080
beacon-healthMake the beacon answer with The beacon is lit., as the beacon user, with its secret kept private, no spare powers, room on its disk, nothing squatting on its port, and a health check that tells the truth. Use --check to see how many spirits remain.
Hint
No hints for the séance. Only a reminder of the tools you've already used: ss, systemctl, journalctl, df, ls -la, sudo -l -U, /etc/cron.d, nft list ruleset, and your own eyes on every script. One warning: never nft flush ruleset, which wipes your real firewall too. Delete only what's broken.
✅ How you know you won
sudo bash breakroom-mission-10.sh --check says Verdict: 7/7. Every spirit named, every one of them Linux. The seance is over.
Answer key (no peeking until you've tried)
1: breakroom-10-candle.service squats on port 8080, and /etc/cron.d/breakroom-10 relights it every minute (Case 05 + 09). 2: the beacon unit's ExecStart=usr/bin/python3 isn't absolute (Case 02). 3: /var/lib/breakroom-10 is a 1 MB disk filled by the hidden .ectoplasm, so the beacon dies with No space left on device (Case 03). 4: /etc/breakroom-10/beacon.conf is 644 and holds a secret: chown root:beacon, chmod 640 (Case 01). 5: /etc/sudoers.d/breakroom-10 gives beacon NOPASSWD: ALL (Case 04). 6: nftables table inet breakroom10 drops port 8080 to 10.66.6.10 (Case 05). 7: beacon-health ignores curl and always exits 0 (Case 08); e.g. curl -sf --max-time 5 http://10.66.6.10:8080/ | grep -q 'beacon is lit' || exit 1.
💥 Let it haunt you again
Run the script again. The haunting starts over, fresh:
sudo bash breakroom-mission-10.shNow do it without the hints. And when you're done for good: sudo bash breakroom-mission-10.sh --clean.
🧠 The ghost, explained
Verdict: not a ghost. Seven small, ordinary problems (one of them with a helper), stacked so that each one hid the next. That's what real outages look like.
Fix one thing, then look again. Every time a ghost left, the error changed. That's progress, not failure. The unit wouldn't load, then it wouldn't start, then it started but nobody could reach it.
Symptoms lie; evidence doesn't. "It doesn't answer" had four different causes here. ss said who owned the port, journalctl said why the service died, df said the disk was full, and nft list ruleset said who closed the door.
You've now touched every corner of the exam. Permissions, services, storage, users, security, boot, automation and troubleshooting. Run any case again without hints, and time yourself. That's the best practice test there is.
← Case 09 · All cases · Stuck, or found a better way? Email me
🎉 Got it, thank you!
Your comment just landed in my inbox. I read every one, and I'll reply by email.
🤔 That didn't go through
Something in the form looked off. Check your name, email and comment and try again, or just email me.
🐢 Whoa, slow down
That's a lot of comments in a short time, so the box is taking a breather. Try again later, or email me.
😴 The comment box is napping
My server is taking a quick break, so your comment couldn't be sent. Sorry! Please email me instead.
💬 Leave a comment
Stuck, found a better way, or just built it and want to brag? Tell me. It comes straight to my inbox (nothing is posted publicly), and I'll reply by email.
Your email is only used to reply to you. Never shared, never added to any list.