| 2 Feb 2023 |
m1cr0man | Yep | 15:19:25 |
hexa | https://hydra.nixos.org/build/207980199 acme 😄 | 17:44:04 |
hexa | https://hydra.nixos.org/log/lbyjk7n05hk7s9mhccrh4h1jzs470lkl-vm-test-run-acme.drv | 17:44:29 |
hexa | restarting | 17:44:32 |
K900 | Saved the log to https://termbin.com/nrjp | 17:45:03 |
hexa | thanks | 17:45:23 |
hexa | probably as helpful as ever | 17:45:32 |
raitobezarius | In reply to @winterqt:nixos.dev m1cr0man: Would you say the best way to guide users wrt DynamicUser services and permissions would be to have them set SupplementalGroups to whatever owns the given cert? I personally do that | 17:58:55 |
Winter (she/her) | In reply to@hexa:lossy.network probably as helpful as ever you'd be right :) ``` | 22:42:18 |
Winter (she/her) | In reply to@hexa:lossy.network probably as helpful as ever * you'd be right :) webserver: waiting for unit acme-finished-http.example.test.target
Test "Can request certificate with Lego's built in web server" failed with error: "unit "acme-finished-http.example.test.target" is inactive and there are no pending jobs" | 22:42:21 |
hexa | In reply to @raitobezarius:matrix.org I personally do that alternatively LoadCredentials=, but generally SupplementaryGroups= | 22:43:20 |
hexa | hey and what about TemporaryFilesystem= and BindPath= | 22:46:40 |
hexa | * hey and what about TemporaryFilesystem= and BindPaths= | 22:46:55 |
hexa | choices! | 22:47:04 |
hexa | * hey and what about TemporaryFilesystem= and BindReadOnlyPaths= | 22:47:58 |