!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

374 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.115 Servers

Load older messages


SenderMessageTime
18 Oct 2025
@hexa:lossy.networkhexa (signing key rotation when)netlify has a single IPv4 adress we can point nixos.org to19:33:27
@raitobezarius:matrix.orgraitobezariusI did mention it to Gandi people I was IRL few hours ago19:34:01
@raitobezarius:matrix.orgraitobezarius(who might escalate it internally)19:34:10
@vcunat:matrix.orgvcunat🤔 though if the IP was anycasted, it might not be so bad.19:34:12
@vcunat:matrix.orgvcunat Heh, we go against Netlify's strong recommendations with the www.
https://docs.netlify.com/manage/domains/manage-domains/manage-multiple-domains/#apex-domains-and-www-subdomains
19:36:06
@hexa:lossy.networkhexa (signing key rotation when)yeah, the single IP address is an anycasted aws address19:36:09
@vcunat:matrix.orgvcunatSo perhaps that for now?19:36:41
@hexa:lossy.networkhexa (signing key rotation when)what I suggested here19:37:02
@vcunat:matrix.orgvcunatSounds OK to try for me.19:37:23
@vcunat:matrix.orgvcunatThough it would be nice to confirm experimentally that the site remains usable from at least two different continents.19:37:52
@vcunat:matrix.orgvcunat And consider defaulting to www. for medium term? (Maybe it's easy to switch in Netlify, but I have no idea really.) 19:38:13
@vcunat:matrix.orgvcunat * And consider defaulting to www. for medium term? (Maybe it's easy to switch in Netlify, but I have no idea really and it surely can have implications.) 19:38:24
@vcunat:matrix.orgvcunat * And consider defaulting to www. for medium term? (Maybe it's easy to switch in Netlify, but I have no idea really and it surely can have nontrivial implications.) 19:38:30
@vcunat:matrix.orgvcunatIf you do, please use somewhat short TTL for now.19:39:27
@vcunat:matrix.orgvcunat* If you/we do, please use somewhat short TTL for now.19:39:48
@vcunat:matrix.orgvcunatSo that it's still possible to switch fast.19:40:06
@hexa:lossy.networkhexa (signing key rotation when)default ttl is 1h19:41:45
@hexa:lossy.networkhexa (signing key rotation when)that's reasonably short imo19:41:49
@vcunat:matrix.orgvcunatWell... the Netlify records get returned with 80s to me.19:50:02
@vcunat:matrix.orgvcunatOr 120 now, say www.nixos.org.19:50:21
@vcunat:matrix.orgvcunatI meant it like - if the static record turns out horrible, it's nice to be able to revert within minutes.19:51:16
@vcunat:matrix.orgvcunat(and performance benefit of TTLs above several minutes seem rather low in practice, from what I've heard)19:51:59
@vcunat:matrix.orgvcunat* (and performance benefit of TTLs above several minutes seem rather low in practice, from what I've heard, except maybe stuff like DNSKEYs and nameserver records)19:52:23
@vcunat:matrix.orgvcunatI see it switched now. And pretty snappy clicking around the web, from here in .cz at least.19:56:38
@hexa:lossy.networkhexa (signing key rotation when)ideally we'd have something that we can put behind fastly22:30:14
@hexa:lossy.networkhexa (signing key rotation when)because fastly does give us ip addresses22:30:20
20 Oct 2025
@felix.schroeter:scs.ems.host@felix.schroeter:scs.ems.host changed their display name from Felix Schröter to Felix Schröter (🌄 27.10. – 09.11.).08:34:10
@felix.schroeter:scs.ems.host@felix.schroeter:scs.ems.host left the room.09:44:53
21 Oct 2025
@echobc:matrix.org@echobc:matrix.org joined the room.18:10:42
@mjolnir:nixos.orgNixOS Moderation Bot banned @echobc:matrix.org@echobc:matrix.org (<no reason supplied>).18:10:45

Show newer messages


Back to Room ListRoom Version: 6