!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

103 Members
Another day, another cert renewal44 Servers

Load older messages


SenderMessageTime
17 Oct 2022
@winterqt:nixos.devWinter (she/her)though that's definitely an issue i considered, and maybe there's some race condition or something11:11:53
@winterqt:nixos.devWinter (she/her)
In reply to @hexa:lossy.network
do you have a setup with non-persistent mountpoints?
what do you mean by that? (probably not, but want to clarify what you mean)
11:12:09
@hexa:lossy.networkhexayeah, the wording is weird11:12:17
@hexa:lossy.networkhexauhm, erase your darlings blogpost11:12:22
@hexa:lossy.networkhexalike data below / is not persistent, but instead tmpfs or zfs with rollbacks to a clean state11:12:47
@hexa:lossy.networkhexaI'm wondering whether some state that tracks whether a timer has execute is not being persisted11:13:26
@hexa:lossy.networkhexaand with Persist=yes it thinks it has to rerun everytime11:13:35
@winterqt:nixos.devWinter (she/her)it's bring persisted11:20:29
@winterqt:nixos.devWinter (she/her)that's the stamp file i'm talking about11:20:42
@winterqt:nixos.devWinter (she/her)
In reply to @winterqt:nixos.dev
It gets recreated as expected, gonna reboot again. I assume it won't be updated.
here i show that my path is being persisted correctly, but systemd isn't stamping the file at boot after that initial creation
11:21:49
@winterqt:nixos.devWinter (she/her)maybe it's nginx depending on the renewal target 🤔11:35:40
@winterqt:nixos.devWinter (she/her)that would make sense lmfao11:40:35
19 Oct 2022
@m1cr0man:m1cr0man.comm1cr0manDepending on the renewal target in nginx shouldn't be triggering the timer? Unless, the timer is aware of when the unit last ran? Maybe I'm wrong though.22:57:28
20 Oct 2022
@hjulle:matrix.orghjulle joined the room.12:04:33
24 Oct 2022
@andreas.schraegle:helsinki-systems.deAndreas Schräglethe acme nixos test broke recently https://hydra.nixos.org/job/nixos/trunk-combined/nixos.tests.acme.x86_64-linux / https://hydra.nixos.org/log/hv4qwbrhmnxf6h0fq70m8lxy5an0xf89-vm-test-run-acme.drv logs indicate minica being denied a system call, if I'm not reading them wrong. any ideas why this might be happening?08:30:55
@arianvp:matrix.orgArianodd08:32:13
@arianvp:matrix.orgArianseems both minica and lego dumped core08:33:26
@arianvp:matrix.orgArianthis is really odd. maybe the go package broke?08:34:10
@arianvp:matrix.orgArianaaah wait08:34:45
@arianvp:matrix.orgArianWe have a whitelist of syscalls here: 08:35:15
@arianvp:matrix.orgArianhttps://github.com/NixOS/nixpkgs/blob/master/nixos/modules/security/acme/default.nix#L63-L7008:35:16
@arianvp:matrix.orgArianso maybe lego and minica are doing new syscalls that aren't in this list08:35:27
@arianvp:matrix.orgArianlego seems to be calling setrlimit (which tbh is a weird thing for a process to do themselves) and idk if that one is allowed by default08:36:04
@arianvp:matrix.orgArianminica stacktrace is very... uninformative08:36:14
@arianvp:matrix.orgAriananyhow this means that the acme module is properly broken. this is a release blocker08:36:44
@arianvp:matrix.orgArian Andreas Schrägle: could you please open an issue so we can add it to the release blocker list? 08:37:07
@andreas.schraegle:helsinki-systems.deAndreas Schrägle
In reply to @arianvp:matrix.org
Andreas Schrägle: could you please open an issue so we can add it to the release blocker list?
does this not block the (non -small) channel anyways?
08:38:39
@arianvp:matrix.orgArianidk if this VM test is in the list. 08:38:57
@arianvp:matrix.orgArianif it is then we're good :)08:39:00
@andreas.schraegle:helsinki-systems.deAndreas Schräglelooks like it isn't. I'll open an issue.08:41:04

Show newer messages


Back to Room ListRoom Version: 6