!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

103 Members
Another day, another cert renewal46 Servers

Load older messages


SenderMessageTime
8 Nov 2024
@k900:0upti.meK900 ⚡️It doesn't 23:37:24
@m1cr0man:m1cr0man.comm1cr0manI could do something really smart and find the webserver that serves port 80 and only mark the HTTP-01 certs as requiring that webserver as necessary. Infact, that's not even a big stretch given the existing complexity 🙃23:52:17
9 Nov 2024
@emilazy:matrix.orgemilycan we just integrate this into the web server modules?04:40:42
@emilazy:matrix.orgemily they support useACMEHost etc., could the logic be there? 04:40:54
@emilazy:matrix.orgemilyI really don't want to see more magic04:40:59
@k900:0upti.meK900 ⚡️
In reply to@emilazy:matrix.org
they support useACMEHost etc., could the logic be there?
It should be there, yeah
06:30:17
@k900:0upti.meK900 ⚡️I guess I can just make the test wait for the server to start for now06:30:31
@k900:0upti.meK900 ⚡️OK so06:50:27
@k900:0upti.meK900 ⚡️https://github.com/NixOS/nixpkgs/pull/35462906:50:27
@k900:0upti.meK900 ⚡️ I added a commit that makes it work for now 06:50:34
@k900:0upti.meK900 ⚡️
webserver # [  426.884702] (es-start)[2816]: acme-lockfiles.service: Changing to the requested working directory failed: Permission denied
webserver # [  426.934208] (es-start)[2816]: acme-lockfiles.service: Failed at step CHDIR spawning /nix/store/n24xs3nmndyyivq3q5w52f7aqlb06hqh-unit-script-acme-lockfiles-start/bin/acme-lockfiles-start: Permission denied
08:03:11
@k900:0upti.meK900 ⚡️You fucking what08:03:13
@k900:0upti.meK900 ⚡️https://hydra.nixos.org/build/278094707/log08:05:12
@k900:0upti.meK900 ⚡️Also this thing08:05:13
@k900:0upti.meK900 ⚡️What is even happening anymore08:05:18
@k900:0upti.meK900 ⚡️OK looks like that machine is just hella overloaded08:06:32
@m1cr0man:m1cr0man.comm1cr0manLooking into that ^ The acme-lockfiles.service is configured in a less than stellar manner. Working directory is /run/acme, but it is managed by tmpfiles instead of RuntimeDirectory, despite being RemainAfterExit (so the runtime dir should not get deleted). Gonna fix all of this now.21:06:42
@k900:0upti.meK900 ⚡️https://hydra.nixos.org/eval/180987321:57:20
@k900:0upti.meK900 ⚡️More ordering nonsense 21:57:24
@k900:0upti.meK900 ⚡️If anyone wants to look into it 21:57:30
@k900:0upti.meK900 ⚡️It's funny how adding more synchronization uncovers more and more weird behaviors 21:58:31
@k900:0upti.meK900 ⚡️ Just because tests that used to insta-fail on slow machines don't anymore 21:58:43
@m1cr0man:m1cr0man.comm1cr0manDid I miss it? Looks like it passed22:20:42
@k900:0upti.meK900 ⚡️I restarted it 22:21:12
@k900:0upti.meK900 ⚡️Without really thinking 22:21:43
@k900:0upti.meK900 ⚡️My bad 22:21:44
@m1cr0man:m1cr0man.comm1cr0manNo worries. What was the gist of it?22:24:00
@k900:0upti.meK900 ⚡️Two different failures 22:24:33
@k900:0upti.meK900 ⚡️On aarch64 and x86_6422:24:41
@k900:0upti.meK900 ⚡️Did not look closely 22:24:44

Show newer messages


Back to Room ListRoom Version: 6