!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

105 Members
Another day, another cert renewal43 Servers

Load older messages


SenderMessageTime
29 Jan 2025
@k900:0upti.meK900 ⚡️It seems like it's just correlated with machine loa07:50:57
@k900:0upti.meK900 ⚡️* It seems like it's just correlated with machine load07:50:58
@arianvp:matrix.orgArian:((13:02:12
@arianvp:matrix.orgArianNuclear option: do we wanna disable the tests on at least unstable for now?13:02:26
@arianvp:matrix.orgArianI feel bad for this being a channel blocker 13:02:32
@k900:0upti.meK900 ⚡️I don't think we should13:19:47
@k900:0upti.meK900 ⚡️ If it actually breaks, we'll get a bunch of people offline 13:20:02
@k900:0upti.meK900 ⚡️I'm fine kicking it every now and then to make sure that doesn't happen 13:20:22
@m1cr0man:m1cr0man.comm1cr0man I nearly have the test suite rewritten - working on webserver test isolation now. It will be a lot more reliable, and we can disable tests piecemeal instead of disabling the whole suite if it gets flakey again. 17:28:03
@k900:0upti.meK900 ⚡️❤️18:03:25
@m1cr0man:m1cr0man.comm1cr0manAre you KIDDING me? There's an option on pebble that sets a percentage failure for cert validation? https://github.com/letsencrypt/pebble?tab=readme-ov-file#invalid-anti-replay-nonce-errors19:04:31
@m1cr0man:m1cr0man.comm1cr0manIt's been in there for 8 years apparently 🫠 probably not the source of the main problems but still, I've disabled it19:07:39
@k900:0upti.meK900 ⚡️Uhh19:13:13
@k900:0upti.meK900 ⚡️I think that's a good thing actually?19:13:17
@k900:0upti.meK900 ⚡️It seems useful to verify lego behaves correctly in that case19:13:30
@m1cr0man:m1cr0man.comm1cr0manThis has been a decision from the get-go: We are not testing lego, we are testing the Nix module. I have 0 interest in testing behaviour of lego outside of standard operation.20:16:47
2 Feb 2025
@m1cr0man:m1cr0man.comm1cr0manhttps://github.com/NixOS/nixpkgs/issues/374792#issuecomment-262920372702:07:22
6 Feb 2025
@jeff:ocjtech.usJeff changed their profile picture.06:10:06
15 Feb 2025
@benjb83:matrix.orgBenjB83 joined the room.10:19:26
@benjb83:matrix.orgBenjB83 changed their display name from Benjamín Buske to BenjB83.10:43:22
16 Feb 2025
@thinkchaos:matrix.orgThinkChaos I'm looking at what can be done to create the ACME account separately of fetching a cert again because of the impending Revert "nixos/nginx: not "before" ACME certs using DNS validation".
m1cr0man Have you already brought up adding a lego sub-command that only creates the account with them?
That looks like something I can try to contribute there, so I'm curious if there's relevant discussion I didn't find.
22:13:39
@m1cr0man:m1cr0man.comm1cr0manI haven't reached out to lego about that specifically. It would be a nice thing to have for sure22:43:14
@m1cr0man:m1cr0man.comm1cr0manWe could then add it to the setup service22:43:23
@thinkchaos:matrix.orgThinkChaosOk, I'll look into it more22:43:59
@thinkchaos:matrix.orgThinkChaosExactly, the goal behind it is to simplify the unit dependencies22:44:34
17 Feb 2025
@hexa:lossy.networkhexaI don't think we currently support ACME Renwal Info (ARI), because don't execute lego when the certificate is not yet outdated16:55:13
@hexa:lossy.networkhexahttps://github.com/go-acme/lego/pull/191216:55:14
@emilazy:matrix.orgemilyI thought we execute lego like every 24 hours16:56:10
@hexa:lossy.networkhexaLE are currently sending out mail to their subscribers with recommendations16:56:11
@emilazy:matrix.orgemilydid that get conditionalized?16:56:15

Show newer messages


Back to Room ListRoom Version: 6