!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

105 Members
Another day, another cert renewal46 Servers

Load older messages


SenderMessageTime
22 Feb 2025
@thinkchaos:matrix.orgThinkChaosI'm looking into the ACME account registration as part of the setup, and did the ACME change locally, the part I'm unsure about and need to investigate more is that creating the account as part of the setup service means the setup requires the internet, and being offline will block the self signed services from starting I think we can have a service per account instead of relying on the single setup one, but it's bringing back more complexity, so not sure how I feel about it yet22:35:31
@thinkchaos:matrix.orgThinkChaos* I'm looking into the ACME account registration as part of the setup, and did the ACME change locally, the part I'm unsure about and need to investigate more is that creating the account as part of the setup service means the setup requires an internet connection, and being offline will block the self signed services from starting since they depend on the setup. I think we can have a service per account instead of relying on the single setup one, but it's bringing back more complexity, so not sure how I feel about it yet22:36:14
@thinkchaos:matrix.orgThinkChaos* I'm looking into the ACME account registration as part of the setup, and did the ACME change locally, the part I'm unsure about and need to investigate more is that creating the account as part of the setup service means the setup requires an internet connection, and being offline will block the self signed services from starting since they depend on the setup. I think we can have a service per account instead of relying on the single setup one, but it's bringing back more complexity, so not sure how I feel about it yet, need to see if it's still an improvement over the locking.22:37:03
@thinkchaos:matrix.orgThinkChaos* I'm looking into the ACME account registration as part of the setup, and did the ACME change locally, the part I'm unsure about and need to investigate more is that creating the account as part of the setup service means the setup requires an internet connection, and being offline will block the self signed services from starting since they depend on the setup. I think we can have a service per account instead of relying on the single setup one, but it's bringing back more complexity, so not sure how I feel about it yet, need to see if it's still an improvement over the leader/follower certs.22:37:48
@thinkchaos:matrix.orgThinkChaos* I'm looking into the ACME account registration as part of the setup, and did the lego change locally, the part I'm unsure about and need to investigate more is that creating the account as part of the setup service means the setup requires an internet connection, and being offline will block the self signed services from starting since they depend on the setup. I think we can have a service per account instead of relying on the single setup one, but it's bringing back more complexity, so not sure how I feel about it yet, need to see if it's still an improvement over the leader/follower certs.22:41:49
@m1cr0man:m1cr0man.comm1cr0manAh yeah that's frustrating. It would indeed mean more services, and additionally slower initial renewals (since you would have to get an account then renew, whereas the current situation would create account + renew in one lego call).23:08:46
@m1cr0man:m1cr0man.comm1cr0manDid I mess something up trying to test the test suite rewrite PR, or is there actually no x86_64-linux builders available on ofborg right now?23:15:59
23 Feb 2025
@emilazy:matrix.orgemily there are no x86_64-linux builders available on ofborg right now 02:12:26
25 Feb 2025
@k900:0upti.meK900 (Old)So how are we doing on the test rewrite?10:48:00
@k900:0upti.meK900 (Old)I just had to bonk it a third time10:48:06
@emilazy:matrix.orgemilyI thought there was a PR up13:32:57
@emilazy:matrix.orgemilyhttps://github.com/NixOS/nixpkgs/pull/37870513:33:10
@thinkchaos:matrix.orgThinkChaosThat PR depends on this one: https://github.com/NixOS/nixpkgs/pull/355087 Both are ready to merge as far as I'm concerned16:22:19
26 Feb 2025
@k900:0upti.meK900 (Old)Merged those07:29:25
@k900:0upti.meK900 (Old)OK I'm tilted07:46:15
@k900:0upti.meK900 (Old)0/507:46:20
@k900:0upti.meK900 (Old)On the old tests07:46:25
@k900:0upti.meK900 (Old)I'll just start a new eval with the tests fixed07:46:38
@k900:0upti.meK900 (Old)Aaand eval failed07:48:17
@k900:0upti.meK900 (Old)Ugh07:48:19
@k900:0upti.meK900 (Old)Fixing...07:48:26
@k900:0upti.meK900 (Old)FIxened07:53:15
@k900:0upti.meK900 (Old)https://hydra.nixos.org/build/29116330207:58:45
@k900:0upti.meK900 (Old)First successful test07:58:50
@arianvp:matrix.orgArianExciting 08:30:14
@m1cr0man:m1cr0man.comm1cr0man
In reply to @k900:0upti.me
Aaand eval failed
Out of interest, Why did the eval fail on the way I had it?
08:49:55
@k900:0upti.meK900 (Old) You were missing the acme attrset 08:50:24
@k900:0upti.meK900 (Old) So they ended up as just nixos.tests.http-01 08:50:32
@k900:0upti.meK900 (Old) Instead of nixos.tests.acme.http-01 08:50:37
@m1cr0man:m1cr0man.comm1cr0manOh right I thought it was referencing by value. Didn't think the path had to be mirrored08:51:29

Show newer messages


Back to Room ListRoom Version: 6