!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

373 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.114 Servers

Load older messages


SenderMessageTime
2 Jun 2025
@hexa:lossy.networkhexa (signing key rotation when)see https://manage.fastly.com/network/subscriptions20:50:51
@arianvp:matrix.orgArianhaving to choose between TLS1.3 and Ipv6 is wild20:51:18
@hexa:lossy.networkhexa (signing key rotation when)hm, no … that's not it20:51:20
@hexa:lossy.networkhexa (signing key rotation when)https://manage.fastly.com/network/tls-configurations20:51:31
@arianvp:matrix.orgArianOkay that’s one mystery down. But why is half our traffic HTTP 1.1?20:51:39
@hexa:lossy.networkhexa (signing key rotation when)that is surprising to me20:52:08
@arianvp:matrix.orgArianhttps://manage.fastly.com/observability/dashboard/system/overview/details/Tb10gX/7mNUQGZO6YxAd2jpokgWxS?mode=historic&view=data20:53:15
@hexa:lossy.networkhexa (signing key rotation when)oh, I confused h1/h2 with tls11/1220:54:39
@hexa:lossy.networkhexa (signing key rotation when)and while we offer tls11/12 all clients use tls1220:54:50
@hexa:lossy.networkhexa (signing key rotation when)* oh, I misremembered the numbers for tls11/12 as h1/h220:55:11
@hexa:lossy.networkhexa (signing key rotation when)so one thing we could add is a https record with alpn information20:55:34
@hexa:lossy.networkhexa (signing key rotation when)and see if that makes a dent, though I would be surprised if it did20:55:54
@emilazy:matrix.orgemilydoes Nix itself speak h2?20:58:23
@hexa:lossy.networkhexa (signing key rotation when)I would hope so, since it relies on curl20:58:43
@arianvp:matrix.orgArian

Yes. it has been speaking H2 for ages

https://github.com/NixOS/nix/blob/e72f19eb28189c9aaaa051423d3c35c93a591fad/src/libstore/filetransfer.cc#L353-L357

unless you disable it explicitly in the config

20:58:56
@arianvp:matrix.orgArianbut this would mean half our users opted out of using it? that seems odd to me20:59:18
@hexa:lossy.networkhexa (signing key rotation when)unlikely20:59:28
@k900:0upti.meK900There's also corporate proxies 20:59:38
@edef1c:matrix.orgedefsplit it out by user agent20:59:39
@k900:0upti.meK900And DPI bullshit 20:59:42
@edef1c:matrix.orgedefand maybe origin AS20:59:55
@hexa:lossy.networkhexa (signing key rotation when)at least the dashboard does not seem to offer that granularity21:00:51
@hexa:lossy.networkhexa (signing key rotation when)* at least their dashboard does not seem to offer that granularity21:00:58
@edef1c:matrix.orgedefokay, maybe after i've had coffee21:01:10
@edef1c:matrix.orgedefuser agent should be in the dash i think21:01:16
@edef1c:matrix.orgedefAS i might have used my own tools for21:01:27
@hexa:lossy.networkhexa (signing key rotation when)lots of observability features are on a trial period21:01:53
@edef1c:matrix.orgedefi suspect if you filter down to eyeball networks and split by user agent it's actually gonna be much more clear21:02:06
@arianvp:matrix.orgArianaren’t we sending fastly logs to S3?21:04:57
@hexa:lossy.networkhexa (signing key rotation when)wasn't that the bits that eelco tried to migrate from his workstation to infra?21:05:32

Show newer messages


Back to Room ListRoom Version: 6