| 18 Oct 2025 |
hexa (signing key rotation when) | which is how that ✨️ magic ✨️ just worked | 19:19:26 |
hexa (signing key rotation when) | but alas nixos-homepage was using that account with unscoped api tokens and pull_request_target and lol no | 19:20:19 |
vcunat | 🤔 I guess Netlify prefer that you have DNS with them as well. | 19:20:41 |
hexa (signing key rotation when) | Redacted or Malformed Event | 19:20:50 |
vcunat | They seem to offer a static IP, but given that we don't redirect...
https://docs.netlify.com/manage/domains/configure-domains/configure-external-dns/#configure-an-apex-domain | 19:20:55 |
vcunat | And I see no option for HTTPS records to salvage at least some clients. | 19:21:22 |
vcunat | Yeah, I don't know. Not great. | 19:21:42 |
hexa (signing key rotation when) | I did recreate the nixos.org origin record a while ago, but that didn't change anything | 19:25:08 |
vcunat | And a ticket at Gandi has been created, surely. | 19:26:32 |
vcunat | (I'm out of ideas for shorter-term mitigations. Static IP would surely make it slow for half of the world, unless we switch to www. redirects which would probably be a larger change.) | 19:31:05 |
vcunat | * (I'm out of ideas for shorter-term mitigations. Static IP would surely make it slow for half of the world, unless we switch to www. redirects which would perhaps be a larger change.) | 19:32:14 |
hexa (signing key rotation when) | 5h ago | 19:33:09 |
hexa (signing key rotation when) | netlify has a single IPv4 adress we can point nixos.org to | 19:33:27 |