!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

86 Members
Another day, another cert renewal39 Servers

Load older messages


SenderMessageTime
21 Jan 2023
@hexa:lossy.networkhexanah, looks like that completed21:47:17
22 Jan 2023
@k900:0upti.meK900It got oomkilled I think 08:00:24
@k900:0upti.meK900So I just restarted it08:00:29
@m1cr0man:m1cr0man.comm1cr0man
In reply to @hexa:lossy.network

(finished: must succeed: curl --data '{"host": "acme.test", "addresses": ["192.168.1.1"]}' http://192.168.1.3:8055/add-a, in 0.24 seconds)
client # curl: (7) Failed to connect to acme.test port 15000 after 88 ms: Couldn't connect to server
client # curl: (7) Failed to connect to acme.test port 15000 after 88 ms: Couldn't connect to server

Yeah that looks fine
18:53:19
@m1cr0man:m1cr0man.comm1cr0manI suppose OOMkill could be the culprit actually.. this test starts like 4 vms iirc. Client/dnsserver/webserver/acme server. I don't imagine many other tests have as many VMs18:54:50
@hexa:lossy.networkhexamaybe allocate more memory for the test19:34:30
@hexa:lossy.networkhexa * maybe allocate more memory for the test then19:34:36
@m1cr0man:m1cr0man.comm1cr0manis that possible?22:06:26
31 Jan 2023
@winterqt:nixos.devWinter (she/her)
In reply to @m1cr0man:m1cr0man.com
is that possible?
virtualisation.memorySize, bytes. (default is 1024.)
00:53:58
@m1cr0man:m1cr0man.comm1cr0manDoes that increase the ram for each node or for the encapsulating VM running the suite?01:03:30
@winterqt:nixos.devWinter (she/her)
In reply to @m1cr0man:m1cr0man.com
Does that increase the ram for each node or for the encapsulating VM running the suite?
There's no encapsulating VM. Each node is run as its own VM.
01:07:43
@m1cr0man:m1cr0man.comm1cr0manRight I see, see I think the issue is that whatever the test suite is running on is running out of ram.01:08:21
@winterqt:nixos.devWinter (she/her)let me poke the operator of that specific machine01:09:01
@m1cr0man:m1cr0man.comm1cr0manI already did that 103-run test a while ago and it was grand so I don't think the nodes are running out01:09:12
@m1cr0man:m1cr0man.comm1cr0manAlright thanks 🙂 lmk if there's something obvious 01:09:37
@winterqt:nixos.devWinter (she/her)poked them in #infra:nixos.org01:09:57
@m1cr0man:m1cr0man.comm1cr0manActually is there system performance dashboards we can correlate against test failure?01:09:59
@winterqt:nixos.devWinter (she/her)https://monitoring.nixos.org/grafana/ might have something01:10:41
@m1cr0man:m1cr0man.comm1cr0manCool I'll check that out tomorrow01:11:05
2 Feb 2023
@winterqt:nixos.devWinter (she/her) m1cr0man: Would you say the best way to guide users wrt DynamicUser services and permissions would be to have them set SupplementalGroups to whatever owns the given cert? 15:18:49
@m1cr0man:m1cr0man.comm1cr0manYep15:19:25
@hexa:lossy.networkhexahttps://hydra.nixos.org/build/207980199 acme 😄17:44:04
@hexa:lossy.networkhexahttps://hydra.nixos.org/log/lbyjk7n05hk7s9mhccrh4h1jzs470lkl-vm-test-run-acme.drv17:44:29
@hexa:lossy.networkhexarestarting17:44:32
@k900:0upti.meK900Saved the log to https://termbin.com/nrjp17:45:03
@hexa:lossy.networkhexathanks17:45:23
@hexa:lossy.networkhexaprobably as helpful as ever17:45:32
@raitobezarius:matrix.orgraitobezarius
In reply to @winterqt:nixos.dev
m1cr0man: Would you say the best way to guide users wrt DynamicUser services and permissions would be to have them set SupplementalGroups to whatever owns the given cert?
I personally do that
17:58:55
@winterqt:nixos.devWinter (she/her)
In reply to@hexa:lossy.network
probably as helpful as ever

you'd be right :)

```

22:42:18
@winterqt:nixos.devWinter (she/her)
In reply to@hexa:lossy.network
probably as helpful as ever
*

you'd be right :)

webserver: waiting for unit acme-finished-http.example.test.target
Test "Can request certificate with Lego's built in web server" failed with error: "unit "acme-finished-http.example.test.target" is inactive and there are no pending jobs"
22:42:21

Show newer messages


Back to Room ListRoom Version: 6