!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

97 Members
Another day, another cert renewal39 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
28 Mar 2025
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب) changed their display name from Rayane Nakib (ريان نقيب) to Rayane Nakib (ريّان نقيب).22:52:02
1 Apr 2025
@sandro:supersandro.deSandro 🐧 changed their display name from Sandro 🐧 to Sandro 🐧 [c3d2].13:57:36
@sandro:supersandro.deSandro 🐧 changed their display name from Sandro 🐧 [c3d2] to Sandro 🐧.13:59:16
4 Apr 2025
@qbit:tapenet.org@qbit:tapenet.org left the room.15:55:33
5 Apr 2025
@tinybronca:sibnsk.net@tinybronca:sibnsk.net removed their display name underpantsgnome.15:53:09
@tinybronca:sibnsk.net@tinybronca:sibnsk.net left the room.15:56:20
19 Apr 2025
@hexa:lossy.networkhexaok, so bummer22:48:50
@hexa:lossy.networkhexaenabling ARI caused lego to keep waiting22:49:54
@hexa:lossy.networkhexa
2025/04/19 22:39:09 [INFO] [music.lossy.network] acme: renewalInfo endpoint indicates that renewal is needed
2025/04/19 22:39:09 [INFO] [music.lossy.network] Sleeping 21h43m27.656213001s until renewal time 2025-04-20 20:22:37.463135258 +0000 UTC
22:49:56
@hexa:lossy.networkhexabut that resulted in nginx not starting up22:50:03
@hexa:lossy.networkhexabecause it depends on all the acme-${domain}.service units22:50:28
@emilazy:matrix.orgemilyhm, I thought we were going to set it to just not wait?22:52:10
@hexa:lossy.networkhexaand we did not set it to anything in nixpkgs22:54:08
@hexa:lossy.networkhexabut I set it to something on my private infra22:54:16
@emilazy:matrix.orgemilyright23:00:12
@emilazy:matrix.orgemilyI think the current format will only work well when set to not wait at all23:00:19
@emilazy:matrix.orgemily(which should be fine as the cron job runs often anyway, though we might want to bump it)23:00:29
21 Apr 2025
@m1cr0man:m1cr0man.comm1cr0manThere was some talk about bumping it when they announced the lower lifetime certs. Wouldn't be the worst thing to do.19:18:58
22 Apr 2025
@hexa:lossy.networkhexanow 47 days was announced to be the next shorter lifespan23:08:50
@hexa:lossy.networkhexaand I don't think it warrants trying more than daily for 7-14 days23:09:13
@hexa:lossy.networkhexa* and I don't think it warrants trying more than daily23:09:33
@hexa:lossy.networkhexafor 6 days that changes of course23:09:45
28 Apr 2025
@m1cr0man:m1cr0man.comm1cr0man https://github.com/NixOS/nixpkgs/pull/376334#pullrequestreview-2801003367 this is ready to go. I tested it too. 21:26:09
29 Apr 2025
@ygt:matrix.org@ygt:matrix.org left the room.23:42:45
5 May 2025
@netpleb:matrix.orgnetpleb

hi everyone, does anybody have a workaround that fixes this pesky dns resolution issue when acme.certs... and BIND are running in a declarative nixos container?

Could not create client: get directory at 'https://acme-v02.api.letsencrypt.org/directory': Get "https://acme-v02.api.letsencrypt.org/directory": GET https://acme-v02.api.letsencrypt.org/directory giving up after 6 attempt(s): Get "https://acme-v02.api.letsencrypt.org/directory": dial tcp: lookup acme-v02.api.letsencrypt.org: Temporary failure in name resolution
17:59:16
@netpleb:matrix.orgnetplebwhat seems to be happening is that acme is starting so early that the container is unable to route things yet. Maybe the host has not installed routes yet? but that somehow acme blocks until it times out.18:00:34

Show newer messages


Back to Room ListRoom Version: 6