!PbtOpdWBSRFbEZRLIf:numtide.com

Nix Community Projects

655 Members
Meta discussions related to https://nix-community.org. (For project specific discussions use github issues or projects own matrix channel). Need help from an admin? Open an issue on https://github.com/nix-community/infra/issues165 Servers

Load older messages


SenderMessageTime
16 Mar 2023
@brian:bmcgee.ie@brian:bmcgee.ieWhich is why I figure it makes sense to have a nix-community bot profile rather than creating one for each repo potentially13:41:48
@brian:bmcgee.ie@brian:bmcgee.iewith an org wide bot gpg key that can be dropped in if you need signed commits13:42:08
@joerg:thalheim.ioMic92Well, than this bot also would need to be a contributor potentially. But maybe not.13:42:20
@joerg:thalheim.ioMic92If we had to give than each repo also a github token, this would be not so nice from a security perspective since than every user could potentially use this. But I guess this might be not needed.13:43:01
@joerg:thalheim.ioMic92We would only have per project gpg keys13:43:45
@brian:bmcgee.ie@brian:bmcgee.ieI think that makes sense. Isolates the key to a project, but a common github profile for the bot13:44:24
@brian:bmcgee.ie@brian:bmcgee.ieif you need a key ask an admin to drop in a new gpg key on the bot account and then add that as a repo secret13:44:48
@brian:bmcgee.ie@brian:bmcgee.ie?13:44:57
@joerg:thalheim.ioMic92I would probably automate this away with the terraform github provider.13:45:34
@joerg:thalheim.ioMic92if this is a feature there.13:45:44
@joerg:thalheim.ioMic92so that people would make a PR.13:45:54
@brian:bmcgee.ie@brian:bmcgee.ieeven better13:46:04
@joerg:thalheim.ioMic92https://registry.terraform.io/providers/integrations/github/latest/docs/resources/user_gpg_key13:46:17
@joerg:thalheim.ioMic92That' looks easy enough.13:46:27
@joerg:thalheim.ioMic92make an issue here please: https://github.com/nix-community/infra/issues13:46:49
@brian:bmcgee.ie@brian:bmcgee.ieis there already a terraform setup for managing nix-community infra?13:46:51
@brian:bmcgee.ie@brian:bmcgee.ieAh cool13:46:54
@joerg:thalheim.ioMic92yes, we have that for dns stuff13:47:03
@brian:bmcgee.ie@brian:bmcgee.iehttps://github.com/nix-community/infra/issues/48213:53:18
@joerg:thalheim.ioMic92 BMG: mhm. One issue still. When we have one bot with multiple private keys than each private key would be still recognized as valid... 13:56:09
@brian:bmcgee.ie@brian:bmcgee.ie🤔13:57:04
@joerg:thalheim.ioMic92So that means that if ethereum.nix commits could be still signed from a different's project gnupg keys.13:57:44
@joerg:thalheim.ioMic92We don't do a lot of background checks if someone wants to join this org.13:58:40
@brian:bmcgee.ie@brian:bmcgee.ieI can just create a dedicated github bot profile for now until this has had more time to shake out in the issue. 13:58:45
@brian:bmcgee.ie@brian:bmcgee.ieUpdated the issue with your concerns14:01:13
17 Mar 2023
@figsoda:matrix.orgfigsodado the hercules agents support recursive nix?15:06:37
@joerg:thalheim.ioMic92 figsoda: at minium we would need to enable it in the nix build, I guess? Feel free to make a PR: https://github.com/nix-community/infra/blob/692240395447dc57594a39da42af2353e95041a3/roles/nix-daemon.nix#L7 18:24:21
20 Mar 2023
@adis:blad.isadisbladis
In reply to @figsoda:matrix.org
do the hercules agents support recursive nix?
We don't have recursive nix enabled
05:34:18
@lotte:chir.rs@lotte:chir.rs changed their profile picture.21:08:28
21 Mar 2023
@raitobezarius:matrix.orgraitobezarius Winter (she/her): sorry to bother you, do you know if the darwin build box had his changes redeployed? 12:52:32

Show newer messages


Back to Room ListRoom Version: 6