!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

373 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.114 Servers

Load older messages


SenderMessageTime
20 Jun 2025
@hexa:lossy.networkhexa (signing key rotation when)you are very likely wrong ๐Ÿ™‚ 20:25:33
@hexa:lossy.networkhexa (signing key rotation when)https://github.com/dexidp/dex#connectors20:25:40
@emilazy:matrix.orgemilyOIDC is based on top of OAuth20:25:47
@infinisil:matrix.orginfinisilI see!20:26:12
@emilazy:matrix.orgemily(but I don't know if the OIDC identity layer on top is relevant to any of the considerations here)20:26:25
@emilazy:matrix.orgemily(it looks kind of like they're just using OAuth as an imprecise term for OIDC actually)20:27:21
@hexa:lossy.networkhexa (signing key rotation when)the question is just if the plugin can map groups20:27:24
@hexa:lossy.networkhexa (signing key rotation when)

Keep in mind that this is the general OAuth authentication plugin and it will not allow to adjust users access based on userโ€™s GitHub organization.

20:28:22
@infinisil:matrix.orginfinisilI don't think it makes sense to insist on OIDC now when we haven't done that for the mailing list in the past. The moderation team email is working in freescout, I just need to onboard everybody who got mails forwarded to their personal email before20:28:24
@hexa:lossy.networkhexa (signing key rotation when)ah, that is what freescout says themselves20:28:27
@hexa:lossy.networkhexa (signing key rotation when)but that is more likely a limitation they have20:28:34
@hexa:lossy.networkhexa (signing key rotation when)I absolutely dislike passing emails around in principle, but here we go20:29:28
@hexa:lossy.networkhexa (signing key rotation when)* I absolutely dislike passing email addresses around in principle, but here we go20:29:45
@infinisil:matrix.orginfinisilThanks!20:30:33
@infinisil:matrix.orginfinisil What I'd like to see in the future is everybody having a <githubUser>@member.nixos.org email address, with some criteria for getting one of those 20:31:00
@hexa:lossy.networkhexa (signing key rotation when)we should really roll our own IDM before we go for such a thing20:32:12
@emma:rory.gay@emma:rory.gayso, i change my github username, what now?20:33:32
@infinisil:matrix.orginfinisilI guess we would want to alias then20:34:03
@infinisil:matrix.orginfinisil <githubId>@member.nixos.org is more stable but less usable :P 20:34:31
@emma:rory.gay@emma:rory.gayand even then, in the end i'd just end up never reading those emails most likely lol20:35:17
@emma:rory.gay@emma:rory.gayif it forwards to my regular email, sure20:35:39
@emilazy:matrix.orgemilyemail provider isn't a fun game to be in, you end up in the critical path of people's accounts etc.20:36:41
@emilazy:matrix.orgemilyand people expect addresses to live forever20:36:48
@hexa:lossy.networkhexa (signing key rotation when)though this one only needs to last as long as the project is alive ๐Ÿ˜› 20:37:17
@emilazy:matrix.orgemilyand deliverability issues on both ends, etc. (applies even for project accounts too but at least the support burden is limited there)20:37:28
@hexa:lossy.networkhexa (signing key rotation when)tbh, I'd prefer actual login accounts to the forwarding situation we are now in20:37:52
@hexa:lossy.networkhexa (signing key rotation when)(or that we are now slowly moving away from towards freescout)20:38:19
@infinisil:matrix.orginfinisilCan recommend so far20:41:12
21 Jun 2025
@mjoerg:nixos.devMartin Joerg joined the room.06:51:09
@k900:0upti.meK900 @vcunat I'm pretty sure t4b is dead: https://hydra.nixos.org/build/301012833 12:41:33

Show newer messages


Back to Room ListRoom Version: 6