!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

387 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.120 Servers

Load older messages


SenderMessageTime
18 Mar 2025
@flokli:matrix.orgflokliso we only have cloudtrail for the last 90 days, unclear why it was deleted/by whom14:26:29
@flokli:matrix.orgflokliI mean, afaik it has only been parsing s3 access logs and put them into another parquet file, which can be redone14:27:10
@flokli:matrix.orgflokliIf we decide to spin it back up, we're saving 16$ per month…14:28:36
@zimbatm:numtide.comJonas Chevalierimage.png
Download image.png
15:00:28
@zimbatm:numtide.comJonas Chevalierit seems to be running from AWS' perspective15:00:40
@zimbatm:numtide.comJonas Chevalierlocated in us-east-1 in account 08043313656115:01:04
@zimbatm:numtide.comJonas Chevalier* located in us-east-1 in account 080433136561 (different account)15:01:17
@hexa:lossy.networkhexahuh15:05:15
@vcunat:matrix.orgVladimír ČunátRedacted or Malformed Event15:08:38
@flokli:matrix.orgfloklioh ok, so no idea what's been deleted in the other account then15:37:30
@flokli:matrix.orgflokliis there a way get a serial console or figure out why it's not responding?15:37:54
@zimbatm:numtide.comJonas Chevalierit looks like ICMP is filtered out, but SSH up to the password prompt is working for me17:09:14
@edef1c:matrix.orgedefyes17:09:25
@edef1c:matrix.orgedefbecause i restored the SSH inbound rules basically just now17:09:38
@edef1c:matrix.orgedefsomeone made the public-ssh group essentially completely inert17:11:15
@edef1c:matrix.orgedef* someone made the public-ssh security group essentially completely inert17:11:22
@edef1c:matrix.orgedef* something made the public-ssh security group essentially completely inert17:11:38
@zimbatm:numtide.comJonas Chevalieroh alright. I also added ICMP to the SG just now. I'll let you cook :)17:12:55
@edef1c:matrix.orgedefi'm okay with no ICMP tbh, i assume it allows related / PMTU ICMP17:14:24
@hexa:lossy.networkhexaI'm super pro ICMP17:16:30
@hexa:lossy.networkhexablocking it is not helpful and just causes confusion17:16:42
@edef1c:matrix.orgedefworks for me, i have no strong opinion17:16:51
@vcunat:matrix.orgVladimír ČunátMissing PMTU could be problematic.17:34:56
@edef1c:matrix.orgedefi would assume the AWS firewall is stateful enough to recognise that as related traffic, but idk17:35:22
19 Mar 2025
@hexa:lossy.networkhexa Mic92: did you by any chance rollback pluto? 13:28:13
@hexa:lossy.networkhexathere were prometheus changes deployed that are gone now13:28:55
@joerg:thalheim.ioMic92 hexa (signing key rotation when): could me. 13:44:09
@joerg:thalheim.ioMic92could be13:44:12
@hexa:lossy.networkhexaok13:44:25
@joerg:thalheim.ioMic92Re-deploy right now13:44:40

Show newer messages


Back to Room ListRoom Version: 6