| 12 Jan 2026 |
hexa | yeah, implemented … I think | 01:18:32 |
emily | I was just thinking we could run it much more often with no randomization if it's getting an ARI time from the CA | 01:28:59 |
emily | because then the CA does its own load balancing across renewal times | 01:29:15 |
emily | I implemented the skew back before ARI was a thing | 01:29:47 |
hexa | https://github.com/NixOS/nixpkgs/pull/479209 | 01:50:33 |
hexa | I wish we could do something similar for the timer intervall | 01:51:24 |
Tom | is there that much harm in just runniung it more often as the new default? | 01:53:10 |
Tom | * is there that much harm in just running it more often as the new default? | 01:53:40 |
hexa | we're a multiplier, so yes it matters | 01:56:59 |
Tom | from my understanding the check on whether to proceed with the renewal is done locally. So it would "only" affect local resources from my understanding? | 02:04:35 |
hexa | Redacted or Malformed Event | 02:05:05 |
hexa | * only while above validMinDays | 02:05:10 |
hexa | * we only fail if above valid min days | 02:05:24 |
hexa | Redacted or Malformed Event | 02:05:28 |
hexa | we run renew always, but only fail if below validMinDays | 02:06:02 |
hexa | if is_expiration_skippable out/full.pem; then
echo 1>&2 "nixos-acme: Ignoring failed renewal because expiration isn't within the coming ${toString data.validMinDays} days"
else
# High number to avoid Systemd reserved codes.
exit 11
| 02:06:31 |
hexa | that's this logic | 02:06:33 |
hexa | * if ! lego ${renewOpts} --days ${toString data.validMinDays}; then
if is_expiration_skippable out/full.pem; then
echo 1>&2 "nixos-acme: Ignoring failed renewal because expiration isn't within the coming ${toString data.validMinDays} days"
else
# High number to avoid Systemd reserved codes.
exit 11
| 02:06:46 |
Tom | ah, okay | 02:07:36 |
hexa | Tom: feel free to test https://github.com/NixOS/nixpkgs/pull/479212 | 02:12:04 |
| 26 May 2021 |
| @grahamc:nixos.org set the history visibility to "world_readable". | 20:36:34 |
| @grahamc:nixos.org changed the room name to "" from "". | 20:36:34 |
| Server Stats Discoverer (traveler bot) joined the room. | 20:36:42 |
| @grahamc:nixos.org invited m1cr0man. | 20:36:47 |
| @grahamc:nixos.orgchanged room power levels. | 20:36:52 |
| m1cr0man joined the room. | 20:37:09 |
| Dandellion joined the room. | 20:38:19 |
| emily joined the room. | 20:43:31 |
| hexa joined the room. | 20:44:30 |
| m1cr0man set the room topic to "Another day, another cert renewal". | 20:46:02 |