!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

386 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.120 Servers

Load older messages


SenderMessageTime
18 Oct 2025
@hexa:lossy.networkhexano stable IP addresses19:18:42
@hexa:lossy.networkhexawe hosted DNS until earlier this year19:19:06
@hexa:lossy.networkhexawhich is how that ✨️ magic ✨️ just worked19:19:26
@hexa:lossy.networkhexabut alas nixos-homepage was using that account with unscoped api tokens and pull_request_target and lol no19:20:19
@vcunat:matrix.orgVladimír Čunát🤔 I guess Netlify prefer that you have DNS with them as well.19:20:41
@hexa:lossy.networkhexaRedacted or Malformed Event19:20:50
@vcunat:matrix.orgVladimír ČunátThey seem to offer a static IP, but given that we don't redirect... https://docs.netlify.com/manage/domains/configure-domains/configure-external-dns/#configure-an-apex-domain19:20:55
@vcunat:matrix.orgVladimír ČunátAnd I see no option for HTTPS records to salvage at least some clients.19:21:22
@vcunat:matrix.orgVladimír ČunátYeah, I don't know. Not great.19:21:42
@hexa:lossy.networkhexaI did recreate the nixos.org origin record a while ago, but that didn't change anything19:25:08
@vcunat:matrix.orgVladimír ČunátAnd a ticket at Gandi has been created, surely.19:26:32
@vcunat:matrix.orgVladimír Čunát(I'm out of ideas for shorter-term mitigations. Static IP would surely make it slow for half of the world, unless we switch to www. redirects which would probably be a larger change.)19:31:05
@vcunat:matrix.orgVladimír Čunát* (I'm out of ideas for shorter-term mitigations. Static IP would surely make it slow for half of the world, unless we switch to www. redirects which would perhaps be a larger change.)19:32:14
@hexa:lossy.networkhexa5h ago19:33:09
@hexa:lossy.networkhexanetlify has a single IPv4 adress we can point nixos.org to19:33:27
@raitobezarius:matrix.orgraitobezariusI did mention it to Gandi people I was IRL few hours ago19:34:01
@raitobezarius:matrix.orgraitobezarius(who might escalate it internally)19:34:10
@vcunat:matrix.orgVladimír Čunát🤔 though if the IP was anycasted, it might not be so bad.19:34:12
@vcunat:matrix.orgVladimír Čunát Heh, we go against Netlify's strong recommendations with the www.
https://docs.netlify.com/manage/domains/manage-domains/manage-multiple-domains/#apex-domains-and-www-subdomains
19:36:06
@hexa:lossy.networkhexayeah, the single IP address is an anycasted aws address19:36:09
@vcunat:matrix.orgVladimír ČunátSo perhaps that for now?19:36:41
@hexa:lossy.networkhexawhat I suggested here19:37:02
@vcunat:matrix.orgVladimír ČunátSounds OK to try for me.19:37:23
@vcunat:matrix.orgVladimír ČunátThough it would be nice to confirm experimentally that the site remains usable from at least two different continents.19:37:52
@vcunat:matrix.orgVladimír Čunát And consider defaulting to www. for medium term? (Maybe it's easy to switch in Netlify, but I have no idea really.) 19:38:13
@vcunat:matrix.orgVladimír Čunát * And consider defaulting to www. for medium term? (Maybe it's easy to switch in Netlify, but I have no idea really and it surely can have implications.) 19:38:24
@vcunat:matrix.orgVladimír Čunát * And consider defaulting to www. for medium term? (Maybe it's easy to switch in Netlify, but I have no idea really and it surely can have nontrivial implications.) 19:38:30
@vcunat:matrix.orgVladimír ČunátIf you do, please use somewhat short TTL for now.19:39:27
@vcunat:matrix.orgVladimír Čunát* If you/we do, please use somewhat short TTL for now.19:39:48
@vcunat:matrix.orgVladimír ČunátSo that it's still possible to switch fast.19:40:06

Show newer messages


Back to Room ListRoom Version: 6