!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

99 Members
Another day, another cert renewal40 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
1 Dec 2022
@hexa:lossy.networkhexa changed their display name from hexa to hexa (22.11 now).13:08:34
@hexa:lossy.networkhexa changed their display name from hexa (22.11 now) to hexa.14:38:23
7 Dec 2022
@qbit:tapenet.org@qbit:tapenet.org joined the room.17:54:45
@me:linj.techlinj joined the room.21:36:54
@me:linj.techlinjRedacted or Malformed Event21:39:52
@me:linj.techlinj * I use acme module with caddy to do http01 challenge, so the cert's group is set to caddy and its owner is acme. Is there a way to let a systemd dynamic service read that cert?21:40:12
@me:linj.techlinj * I use acme module with caddy to do http01 challenge, so the cert's group is set to caddy and its owner is acme. What is the way to let a systemd dynamic service read that cert with minimal permission given to it?21:45:17
13 Dec 2022
@k900:0upti.meK900https://hydra.nixos.org/build/20191409608:43:07
@k900:0upti.meK900The test is failing again08:43:13
@m1cr0man:m1cr0man.comm1cr0manRight. I'm gonna write a script to run it 1000 times and capture the failures :P I have no clue why it's failing. I already did a pass on it a while ago when it failed far more frequently (like maybe a year ago now), so there must be some other race condition going on10:20:20
@k900:0upti.meK900I think it's trying to hit the webserver before the webserver is actually up10:20:51
@m1cr0man:m1cr0man.comm1cr0manyeah which it shouldn't be doing, I have appropriate port checks and retry logic but that seems to be insufficient10:21:57

Show newer messages


Back to Room ListRoom Version: 6