!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

352 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.109 Servers

Load older messages


SenderMessageTime
2 Jul 2025
@zimbatm:numtide.comJonas Chevalier emily: Personally I'd be interested in knowing how much bandwidth my personal infra, and Numtide are using. I would be interesting to me. I'm wondering if other people would like to have this facility too. 13:57:20
@zimbatm:numtide.comJonas ChevalierIt could also be useful to know which org to approach and ask if they would be willing to install loca caches / reverse proxies to reduce the load.13:59:29
@vcunat:matrix.orgvcunatI'd expect the last bit to be covered by Fastly, but who knows.14:15:12
@zimbatm:numtide.comJonas ChevalierWe can already identify orgs with public IP ranges / AS as those appror in the fastly logs.14:31:00
@ners:nixos.devners
In reply to @emilazy:matrix.org
most organizations with that kind of need are probably using their own caching proxy if they're using the central cache at all, surely?
AFAIK, the caches I know, such as Cachix and Attic, will not cache locally things that are available in the global cache.
16:27:14
@zimbatm:numtide.comJonas ChevalierI'm expecting GitHub Action runners to use most of the traffic16:37:14
@tom:dragar.deTom
In reply to @ners:nixos.dev
AFAIK, the caches I know, such as Cachix and Attic, will not cache locally things that are available in the global cache.
For attic: you can disable the upload filter and then it's only a question of having the priorities configured correctly to primarily use your cache.
16:48:50
3 Jul 2025
@k900:0upti.meK900https://hydra.nixos.org/build/301602245 might be stuck07:36:40
@k900:0upti.meK900Yeah definitely stuck07:57:41
@k900:0upti.meK900I'll just start a new eval instead07:57:58
4 Jul 2025
@dgrig:erethon.comdgrigWhat's the proper procedure for me to request I get write access to Grafana so I can upload a dashboard for the tracker.security.nixos.org service? The dashboard in question is https://github.com/Nix-Security-WG/nix-security-tracker/blob/main/contrib/grafana-dashboard.json if it's easier for someone else to import it.11:35:26
@dgrig:erethon.comdgrig* What's the proper procedure for me to request I get write access to Grafana so I can upload a dashboard for the tracker.security.nixos.org service? GitHub issue? The dashboard in question is https://github.com/Nix-Security-WG/nix-security-tracker/blob/main/contrib/grafana-dashboard.json if it's easier for someone else to import it.11:35:43
@k900:0upti.meK900https://grafana.nixos.org/d/beo2uotj65lvkb/nix-security-tracker?orgId=1&from=now-6h&to=now&timezone=browser&var-Instance11:36:40
@k900:0upti.meK900The metrics don't exist though11:36:44
@k900:0upti.meK900Are those actually being scraped/pushed from anywhere?11:37:35
@dgrig:erethon.comdgrigNot yet, PR incoming for this11:40:07
5 Jul 2025
@sinan:sinanmohd.comsinan changed their profile picture.04:04:36
7 Jul 2025
@julien:ligi.frZempashi joined the room.20:55:53
8 Jul 2025
@julien:ligi.frZempashi removed their profile picture.15:54:47
@janne:hess.oooJanne joined the room.21:22:48
@janne.hess:helsinki-systems.de@janne.hess:helsinki-systems.de left the room.21:22:57
10 Jul 2025
@shock-wave:matrix.orgshock-wave joined the room.11:23:18
@shock-wave:matrix.orgshock-waveHi, I have been told that this chatroom is the right place to be with seek help with issues pertaining to the nixos discourse. I have been trying to log in to my account but I havent saved/remembered the password. The last time I logged in was 3 months ago. However when I try to recover my password or login with link sent to the email address, I dont receive anything. I have also tried to make a new account with a new email address but I dont seem to receive emails to that either. The account isnt banned(at least not overtly). I was wondering if someone could help me with this issue or tell me what the issue is. Thanks in advance.11:40:27
@ctheune:matrix.flyingcircus.ioChristian TheuneI can check if you DM me the email address you are using. (Room: let me know if I should verify this request further to avoid information leakage wrt potential social engineering.)11:54:37
@shock-wave:matrix.orgshock-wavewill do and understandable if you want a second opinion, I can also provide more info if needed.11:56:15
@hexa:lossy.networkhexa (signing key rotation when)infra call in 15m and I'd invite you to try lasuite-meet over here https://meet.cccda.de/rdt-xpjb-mav15:46:04
@hexa:lossy.networkhexa (signing key rotation when)* infra call in 15m and I invite you to try lasuite-meet over here https://meet.cccda.de/rdt-xpjb-mav15:46:18
@arianvp:matrix.orgArian

So we were a bit puzzled during the call.

It seems that even without my changes to cache NARs more aggressively, currently 404s are not cached even though fastly by default caches 404s.

Or at leasts x-cache-hits response header is always 0 for 404s whilst for all other paths we do get hits.

i.e. if you fetch a non-existent narinfo we always get a x-cache-hits: 0 back

So it feels like something is misconfigured today?

Or is maybe the synthetic response object that we have resetting those headers?

https://github.com/NixOS/infra/blob/main/terraform/cache.tf#L233-L240

I wonder if we need to move from cache_condition to request_condition here or something?

16:59:18
@arianvp:matrix.orgArian but yeh for me curl -v https://cache.nixos.org/non-existent.narinfo always reports a x-cache-hits: 0 which doesn't sound correct 17:00:44
@arianvp:matrix.orgArianOr does it? is that the desired behaviour?17:00:59

Show newer messages


Back to Room ListRoom Version: 6