!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

105 Members
Another day, another cert renewal45 Servers

Load older messages


SenderMessageTime
26 Feb 2025
@m1cr0man:m1cr0man.comm1cr0man
In reply to @k900:0upti.me
Aaand eval failed
Out of interest, Why did the eval fail on the way I had it?
08:49:55
@k900:0upti.meK900 ⚡️ You were missing the acme attrset 08:50:24
@k900:0upti.meK900 ⚡️ So they ended up as just nixos.tests.http-01 08:50:32
@k900:0upti.meK900 ⚡️ Instead of nixos.tests.acme.http-01 08:50:37
@m1cr0man:m1cr0man.comm1cr0manOh right I thought it was referencing by value. Didn't think the path had to be mirrored08:51:29
@k900:0upti.meK900 ⚡️Yeah it's referencing paths kind of within itself08:51:51
@k900:0upti.meK900 ⚡️It's a pretty cursed setup08:51:55
@m1cr0man:m1cr0man.comm1cr0man
In reply to @k900:0upti.me
https://hydra.nixos.org/build/291163302
The eval time improvement is a nice win too. Looks like the old suite took 9+ minutes. The new http01-builtin took 2 minutes, and dns01 took 1 minute
08:53:34
27 Feb 2025
@wjjunyor:matrix.orgw changed their display name from w to w - out for 🚬.18:34:07
@wjjunyor:matrix.orgw changed their display name from w - out for 🚬 to w.19:25:29
28 Mar 2025
@nakibrayane:matrix.orgRayane Nakib (ريّان نقيب) changed their display name from Rayane Nakib (ريان نقيب) to Rayane Nakib (ريّان نقيب).22:52:02
1 Apr 2025
@sandro:supersandro.deSandro 🐧 changed their display name from Sandro 🐧 to Sandro 🐧 [c3d2].13:57:36
@sandro:supersandro.deSandro 🐧 changed their display name from Sandro 🐧 [c3d2] to Sandro 🐧.13:59:16
4 Apr 2025
@qbit:tapenet.orgqbit left the room.15:55:33
5 Apr 2025
@tinybronca:sibnsk.netunderpantsgnome removed their display name underpantsgnome.15:53:09
@tinybronca:sibnsk.netunderpantsgnome left the room.15:56:20
19 Apr 2025
@hexa:lossy.networkhexaok, so bummer22:48:50
@hexa:lossy.networkhexaenabling ARI caused lego to keep waiting22:49:54
@hexa:lossy.networkhexa
2025/04/19 22:39:09 [INFO] [music.lossy.network] acme: renewalInfo endpoint indicates that renewal is needed
2025/04/19 22:39:09 [INFO] [music.lossy.network] Sleeping 21h43m27.656213001s until renewal time 2025-04-20 20:22:37.463135258 +0000 UTC
22:49:56
@hexa:lossy.networkhexabut that resulted in nginx not starting up22:50:03
@hexa:lossy.networkhexabecause it depends on all the acme-${domain}.service units22:50:28
@emilazy:matrix.orgemilyhm, I thought we were going to set it to just not wait?22:52:10
@hexa:lossy.networkhexaand we did not set it to anything in nixpkgs22:54:08
@hexa:lossy.networkhexabut I set it to something on my private infra22:54:16
@emilazy:matrix.orgemilyright23:00:12
@emilazy:matrix.orgemilyI think the current format will only work well when set to not wait at all23:00:19
@emilazy:matrix.orgemily(which should be fine as the cron job runs often anyway, though we might want to bump it)23:00:29
21 Apr 2025
@m1cr0man:m1cr0man.comm1cr0manThere was some talk about bumping it when they announced the lower lifetime certs. Wouldn't be the worst thing to do.19:18:58
22 Apr 2025
@hexa:lossy.networkhexanow 47 days was announced to be the next shorter lifespan23:08:50
@hexa:lossy.networkhexaand I don't think it warrants trying more than daily for 7-14 days23:09:13

Show newer messages


Back to Room ListRoom Version: 6