!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

86 Members
Another day, another cert renewal39 Servers

Load older messages


SenderMessageTime
16 Aug 2023
@hexa:lossy.networkhexa
In reply to @hexa:lossy.network
saved to https://gist.github.com/mweinelt/0bf207904ea0a32e30f0aadd3e0b1bba
should be this
21:44:19
17 Aug 2023
@k900:0upti.meK900
In reply to@m1cr0man:m1cr0man.com
weird did you grab the logs before that by any chance?
Yep what @hexa linked
05:38:50
@k900:0upti.meK900It flakes like that every once in a while05:38:58
18 Aug 2023
@k900:0upti.meK900New flake: https://hydra.nixos.org/build/231859621/nixlog/56/tail05:59:02
@thomaslepoix:matrix.orgthomaslepoix joined the room.07:23:23
@zeorin:matrix.orgXandor Schiefer joined the room.09:17:13
@m1cr0man:m1cr0man.comm1cr0manthat one I'm aware off - I need to wrap that curl in some retries18:52:40
19 Aug 2023
@k900:0upti.meK900
In reply to@k900:0upti.me
New flake: https://hydra.nixos.org/build/231859621/nixlog/56/tail
-small hit this again
07:27:04
@k900:0upti.meK900I kicked it but you know07:27:08
@m1cr0man:m1cr0man.comm1cr0manGod damn acme tests18:46:57
@m1cr0man:m1cr0man.comm1cr0manI'm gonna fix that add-a right now18:47:02
@cel:pussy.accountants@cel:pussy.accountants left the room.18:56:00
@m1cr0man:m1cr0man.comm1cr0manhere we go https://github.com/NixOS/nixpkgs/pull/25026021:43:25
22 Aug 2023
@m1cr0man:m1cr0man.comm1cr0man Any comments from people on the locking PRs? Discussion here. Would appreciate an arbiter/voting on the preferred solution. 18:21:42
@raitobezarius:matrix.orgraitobezariusPersonally, I'd prefer to see this solved in systemd19:32:27
@raitobezarius:matrix.orgraitobezariusAnd used in NixOS19:32:29
@raitobezarius:matrix.orgraitobezariusRather than solved in NixOS19:32:32
@raitobezarius:matrix.orgraitobezariusAs you said it, we have too much complexity in our NixOS module19:32:54
@raitobezarius:matrix.orgraitobezariusBecause we don't have enough good primitives for this19:32:59
@raitobezarius:matrix.orgraitobezariussystemd is in the good position to create the right primitive19:33:05
@raitobezarius:matrix.orgraitobezariusMeanwhile, an official patch can be blessed19:33:12
@raitobezarius:matrix.orgraitobezariusAnd can be applied to nixpkgs19:33:17
@raitobezarius:matrix.orgraitobezariushttps://github.com/systemd/systemd/issues/2807519:33:38
@raitobezarius:matrix.orgraitobezariusAs the OP is interacting here, I'd just encourage to push through19:33:49
@raitobezarius:matrix.orgraitobezariusAnd coordinate with NixOS systemd folks if help is needed19:33:56
@raitobezarius:matrix.orgraitobezariusIt's not like anyway we don't need that feature for something else than ACME19:35:56
@raitobezarius:matrix.orgraitobezariusSo I wish we don't see hacks to generalize this behavior everywhere19:36:03
@m1cr0man:m1cr0man.comm1cr0manI do agree this should be solved upsream. I don't know if you clicked in but the "competing" PR (my one) is a pure systemd + nix implementation with arguably less overheads.20:26:48
@m1cr0man:m1cr0man.comm1cr0manIt's annoying to add more complexity but personally I am trying to keep the diff and unique code low where possible. Both lego and systemd could do with upstreamed features to help us out. For example, if lego had an "offline ok" flag for checking renewal that would remove all the openssl shenanigans. I did plan to upstream that at one point but just never had the time20:29:25
30 Aug 2023
@ajs124:ajs124.deajs124 joined the room.17:38:15

Show newer messages


Back to Room ListRoom Version: 6