!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

104 Members
Another day, another cert renewal44 Servers

Load older messages


SenderMessageTime
9 Jul 2025
@ctheune:matrix.flyingcircus.ioChristian TheuneFrom my experience, this kind of dependencies quickly leads to an operational nightmare when something goes unexpectedly wrong. Designing for a "everything is sunny in california" environment doesn't resonate very well with me. Especially because the complexity is getting so high that making predictions about reliability and not forgetting some corner case is becoming impossible.07:14:07
@ctheune:matrix.flyingcircus.ioChristian TheuneIMHO the overall design would be much better off if we ripped out the "no self signed certificates" knob ... 07:14:41
@ctheune:matrix.flyingcircus.ioChristian Theune This will let us have a single straight path in the dependencies to ensure servers come up somehow and then let users deal with partial degradations instead of complete failure that then becomes impossible to fix because of opposing dependencies. 07:15:46
@ctheune:matrix.flyingcircus.ioChristian Theune m1cr0man: Just to make sure: I completely agree with the tradeoffs you mention regrading community needs. I've read through the original PR that introduces the knob (https://github.com/NixOS/nixpkgs/pull/15562) and I see that it was kind of a given to use a knob - this has been 9 years ago and I think we were in a state of expansion on ACME capabilities back then. From todays perspective I don't see a strong reason to support turning it off as it's such a core case of people using HTTP-01... 07:27:33
@ctheune:matrix.flyingcircus.ioChristian Theuneoooh, and the management of ownership/permissions in the .lego/ directory is inconsistent. it partially wants 600 for the files (and verifies that in a test) but then again the setup script broadly sets them back to 64009:33:41
@ctheune:matrix.flyingcircus.ioChristian Theunebut the tests never saw that due to selective permission checking.09:33:56
@ctheune:matrix.flyingcircus.ioChristian TheuneI'd say keeping the files consistently on 640 with the right group is fine ... ?09:34:14
@ctheune:matrix.flyingcircus.ioChristian Theunenot sure why we'd go to the extra lengths of having them 600 and 640 ... 09:34:27
@m1cr0man:m1cr0man.comm1cr0manWhere is it inconsistent exactly? I don't remember all the permissions checks19:43:33
@m1cr0man:m1cr0man.comm1cr0manSure, I'm sold :) 19:47:44
@alina:catgirl.cloud@alina:catgirl.cloud changed their profile picture.21:01:28
@alina:catgirl.cloud@alina:catgirl.cloud changed their display name from alina to alina arielle amelie🏳️‍⚧️🐾.21:02:13
10 Jul 2025
@ctheune:matrix.flyingcircus.ioChristian Theunefinally ... i got all tests working. one last cleanup regarding the lock handling, but then I should be ready for more eyes ... 09:39:08
@ctheune:matrix.flyingcircus.ioChristian Theune alright ... m1cr0man emily if you'd like to take a look https://github.com/NixOS/nixpkgs/pull/422076 is now ready. it's a lot more changes than I anticipated and I really tried my best to keep it down. 12:43:41
@ctheune:matrix.flyingcircus.ioChristian Theune hexa: if you have oppinions, then I'm all ear, too. 12:43:59
@ctheune:matrix.flyingcircus.ioChristian Theune Arian: and you taking another look is of course appreciated as well 12:44:17
@emilazy:matrix.orgemily busy today and I'm sure m1cr0man will be more thorough than myself but I'll see if I can find time to take a quick look over the weekend 14:16:11
@emilazy:matrix.orgemilyfrankly the module has grown so big that I find it hard to keep track of everything to review changes14:16:28
@emilazy:matrix.orgemilythough I'd be very happy to review PRs that reduce the number of lines :D14:16:51
@ctheune:matrix.flyingcircus.ioChristian TheuneUnderstood. Overall it's a few more lines but I think the module itself is same length or shorter, but overall simpler. There's some places that could be DRY'd but at n=3 I'm still wary of early abstraction. Most new lines are in tests, I think.19:53:42
14 Jul 2025
@m1cr0man:m1cr0man.comm1cr0manI have been reviewing the change bit by bit for the last few days. Haven't had much time to sit down continuously. About 70% done07:34:45
@ctheune:matrix.flyingcircus.ioChristian Theunethanks! i know it's a big one ... 07:35:27
@ctheune:matrix.flyingcircus.ioChristian Theunei'll be on vacation starting from thursday - no pressure, but don't expect a reply between thursday and august 5h. i'll pick this up afterwards if need be.07:35:55
@hexa:lossy.networkhexacurrently otherwise occupied with … mail.23:12:17
@hexa:lossy.networkhexa* currently otherwise occupied with … mail stuff.23:12:20
15 Jul 2025
@m1cr0man:m1cr0man.comm1cr0manI'm on vacation until a similar time at EOM, so that works out :) I'll try and drop the review before my holiday00:00:08
@ctheune:matrix.flyingcircus.ioChristian Theune🙂06:13:53
24 Jul 2025
@blocklisted:matrix.orgblocklisted joined the room.10:10:53
28 Jul 2025
@hashbangcore:matrix.orgJohn joined the room.08:01:26
4 Aug 2025
@m1cr0man:m1cr0man.comm1cr0man Christian Theune: Just sent the review there. Sorry it took so long, I was on call the week before my holiday and was way too mentally exhausted to look at more code. 14:43:09

Show newer messages


Back to Room ListRoom Version: 6