!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

349 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.108 Servers

Load older messages


SenderMessageTime
20 Jun 2025
@infinisil:matrix.orginfinisil hexa (signing key rotation when): Can you PM me the email list of the moderation team members? This is for https://github.com/NixOS/infra/pull/748 20:21:10
@hexa:lossy.networkhexa (signing key rotation when)for what purpose?20:21:34
@infinisil:matrix.orginfinisilI need to give them a freescout account, which needs an email20:21:58
@hexa:lossy.networkhexa (signing key rotation when)^20:22:06
@hexa:lossy.networkhexa (signing key rotation when)for that exact reason20:22:10
@hexa:lossy.networkhexa (signing key rotation when)this should not have gone into production without proper login infrastructure20:22:22
@infinisil:matrix.orginfinisilThat doesn't work either way20:22:28
@hexa:lossy.networkhexa (signing key rotation when)why not?20:22:38
@infinisil:matrix.orginfinisil hexa (signing key rotation when): I added it in https://github.com/NixOS/infra/issues/700#issue-3098140041 20:23:15
@hexa:lossy.networkhexa (signing key rotation when)https://github.com/NixOS/infra/blob/main/build/pluto/prometheus/alertmanager.nix#L79-L8420:23:28
@hexa:lossy.networkhexa (signing key rotation when)we can absolute tie oidc in with github teams20:23:36
@hexa:lossy.networkhexa (signing key rotation when)we are already doing that for infra20:23:44
@infinisil:matrix.orginfinisilFreescout supports OIDC?20:24:07
@hexa:lossy.networkhexa (signing key rotation when)https://freescout.net/module/oauth-login/20:24:22
@infinisil:matrix.orginfinisilI see no mention of OIDC20:24:36
@infinisil:matrix.orginfinisilI don't really know OIDC though, so tell me if I'm wrong ๐Ÿ˜…20:25:17
@hexa:lossy.networkhexa (signing key rotation when)you are very likely wrong ๐Ÿ™‚ 20:25:33
@hexa:lossy.networkhexa (signing key rotation when)https://github.com/dexidp/dex#connectors20:25:40
@emilazy:matrix.orgemilyOIDC is based on top of OAuth20:25:47
@infinisil:matrix.orginfinisilI see!20:26:12
@emilazy:matrix.orgemily(but I don't know if the OIDC identity layer on top is relevant to any of the considerations here)20:26:25
@emilazy:matrix.orgemily(it looks kind of like they're just using OAuth as an imprecise term for OIDC actually)20:27:21
@hexa:lossy.networkhexa (signing key rotation when)the question is just if the plugin can map groups20:27:24
@hexa:lossy.networkhexa (signing key rotation when)

Keep in mind that this is the general OAuth authentication plugin and it will not allow to adjust users access based on userโ€™s GitHub organization.

20:28:22
@infinisil:matrix.orginfinisilI don't think it makes sense to insist on OIDC now when we haven't done that for the mailing list in the past. The moderation team email is working in freescout, I just need to onboard everybody who got mails forwarded to their personal email before20:28:24
@hexa:lossy.networkhexa (signing key rotation when)ah, that is what freescout says themselves20:28:27
@hexa:lossy.networkhexa (signing key rotation when)but that is more likely a limitation they have20:28:34
@hexa:lossy.networkhexa (signing key rotation when)I absolutely dislike passing emails around in principle, but here we go20:29:28
@hexa:lossy.networkhexa (signing key rotation when)* I absolutely dislike passing email addresses around in principle, but here we go20:29:45
@infinisil:matrix.orginfinisilThanks!20:30:33

Show newer messages


Back to Room ListRoom Version: 6