!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

385 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.120 Servers

Load older messages


SenderMessageTime
4 Jun 2025
@hexa:lossy.networkhexawe are using dex for alerts.nixos.org20:23:32
@hexa:lossy.networkhexa* we are using dex for alerts.nixos.org to bridge that gap20:24:45
@hexa:lossy.networkhexawith more services that we deploy we should probably run our own idm20:45:44
5 Jun 2025
@joerg:thalheim.ioMic92 hexa (signing key rotation when): I still see dangling terraform resources for netlify domains in terraform. Should I remove those? 11:23:40
@joerg:thalheim.ioMic92I mean removing the state otherwise, terraform apply will remove all our records11:24:10
@hexa:lossy.networkhexayeah, feel free12:37:15
@joerg:thalheim.ioMic92 hexa (signing key rotation when): finished my second fastly pr, in case you want to have a look 13:00:07
@joerg:thalheim.ioMic92https://github.com/NixOS/infra/pull/71813:00:10
6 Jun 2025
@arcayr:mischief.expertarcayr changed their profile picture.01:11:38
7 Jun 2025
@infinisil:matrix.orginfinisil

hexa (signing key rotation when): Recently the foundation board got a request to "unban" somebody's IP, they also linked to a post of them about it: https://sharkey.ghodawalaaman.xyz/notes/a8bh6usmk8

Is this something the infra team can look into? I can PM you the IP address

21:59:57
@sandro:supersandro.deSandropinging 52.74.232.59 also results in 100% packet loss for me22:09:25
@hexa:lossy.networkhexa
In reply to @infinisil:matrix.org

hexa (signing key rotation when): Recently the foundation board got a request to "unban" somebody's IP, they also linked to a post of them about it: https://sharkey.ghodawalaaman.xyz/notes/a8bh6usmk8

Is this something the infra team can look into? I can PM you the IP address

Thats hosted by netlify and I would be surprised if anyone was "banned"
22:17:56
@hexa:lossy.networkhexa
In reply to @sandro:supersandro.de
pinging 52.74.232.59 also results in 100% packet loss for me
"Security"
22:18:18
@infinisil:matrix.orginfinisilOh and yeah I also get full packet loss for nixos.org pings22:18:24
@infinisil:matrix.orginfinisilI guess there's no reason for it to respond to pings22:18:32
@edef1c:matrix.orgedefit might just not answer pings22:18:38
@hexa:lossy.networkhexaThats not a problem22:18:40
@edef1c:matrix.orgedefyeah22:18:41
@infinisil:matrix.orginfinisilAlright I'll answer with that. Can also tell them to join this room if there's other problems22:19:01
@infinisil:matrix.orginfinisil(although if they're actually blocked in some way they might not be able to :P)22:19:17
@edef1c:matrix.orgedefa lot of networking equipment also doesn't answer pings or punts them to low priority22:19:23
@edef1c:matrix.orgedefso ICMP pings are not inherently reliable tests of connectivity or latency22:19:47
@hexa:lossy.networkhexa
In reply to @infinisil:matrix.org
(although if they're actually blocked in some way they might not be able to :P)
Unlikely
22:20:22
@edef1c:matrix.orgedef(and i can confirm that nixos.org indeed does not answer ICMP pings, but does answer HTTPS)22:20:44
@hexa:lossy.networkhexaRelevant would he a traceroute (UDP or TCP) and a curl log22:21:08
@hexa:lossy.networkhexa * 22:21:16
@sandro:supersandro.deSandroMy providers routers drop exactly 50% of a normal mtr ping at hop 4 or 5 22:43:00
@sandro:supersandro.deSandronot 49.5, not 51.3, exactly 50.0%22:43:13
@hexa:lossy.networkhexaits because icmp echo requests leave the fast path and go to the control plane22:43:24
@hexa:lossy.networkhexathe control plane is not equipped to handle a huge number of packages, so rate limiting kicks in22:43:47

Show newer messages


Back to Room ListRoom Version: 6