!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

126 Members
Another day, another cert renewal55 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
3 Jun 2024
@stephank:stephank.nlStéphanBy no means a good attempt, but I hacked away on this: https://github.com/NixOS/nixpkgs/compare/master...stephank:nixpkgs:fix-acme?w=108:48:56
@stephank:stephank.nlStéphanI just have no idea how to test it08:49:04
@stephank:stephank.nlStéphanI reused the fixperms service, because I was worried about bind mounts. I'm not sure if bind mounts are preserved from ExecStartPre to ExecStart, or if they are recreated correctly when the underlying directory changed.08:50:13
@stephank:stephank.nlStéphan Now that I think about it, maybe a simple -e or -d check won't work because the $newHash directory will always be created via BindPaths? 08:51:01
@stephank:stephank.nlStéphanLooks like it's always created: https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#BindPaths=08:51:59
@stephank:stephank.nlStéphanOh wait, the fixperms / migration service doesn't use BindPaths. So what I cooked up there may work.08:55:41
@arianvp:matrix.orgArianWe have quite an extensive NixOS test which we could change. But doing NixOS tests for "transitions" is always a bit tricky 09:22:26
@arianvp:matrix.orgArian Stéphan: dont this based on stateVersion wont work 09:24:03
@arianvp:matrix.orgArian * Stéphan: doing this based on stateVersion wont work I think 09:24:23

Show newer messages


Back to Room ListRoom Version: 6