!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

377 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.116 Servers

Load older messages


SenderMessageTime
18 Oct 2025
@hexa:lossy.networkhexado we need it? no19:16:56
@hexa:lossy.networkhexais it better than not having it? yes19:17:06
@vcunat:matrix.orgVladimír ČunátAah, I thought the normal practice is that you get http-redirected to www.19:17:41
@vcunat:matrix.orgVladimír Čunát(and there you can have CNAME)19:17:49
@hexa:lossy.networkhexayeah, ideally19:17:56
@hexa:lossy.networkhexabut that is not the case on nixos.org19:18:00
@vcunat:matrix.orgVladimír Čunátbut I'm somewhat out of touch from the web world.19:18:04
@hexa:lossy.networkhexaand I'm not keen on changing that, because it'll fck with search results, no?19:18:13
@vcunat:matrix.orgVladimír ČunátI see now. But don't tell me that netlify is relying on ALIAS so heavily.19:18:22
@vcunat:matrix.orgVladimír ČunátI mean, it's completely unstandardized.19:18:28
@hexa:lossy.networkhexathey only give us a hostname19:18:37
@hexa:lossy.networkhexano stable IP addresses19:18:42
@hexa:lossy.networkhexawe hosted DNS until earlier this year19:19:06
@hexa:lossy.networkhexawhich is how that ✨️ magic ✨️ just worked19:19:26
@hexa:lossy.networkhexabut alas nixos-homepage was using that account with unscoped api tokens and pull_request_target and lol no19:20:19
@vcunat:matrix.orgVladimír Čunát🤔 I guess Netlify prefer that you have DNS with them as well.19:20:41
@hexa:lossy.networkhexaRedacted or Malformed Event19:20:50
@vcunat:matrix.orgVladimír ČunátThey seem to offer a static IP, but given that we don't redirect... https://docs.netlify.com/manage/domains/configure-domains/configure-external-dns/#configure-an-apex-domain19:20:55
@vcunat:matrix.orgVladimír ČunátAnd I see no option for HTTPS records to salvage at least some clients.19:21:22
@vcunat:matrix.orgVladimír ČunátYeah, I don't know. Not great.19:21:42
@hexa:lossy.networkhexaI did recreate the nixos.org origin record a while ago, but that didn't change anything19:25:08
@vcunat:matrix.orgVladimír ČunátAnd a ticket at Gandi has been created, surely.19:26:32
@vcunat:matrix.orgVladimír Čunát(I'm out of ideas for shorter-term mitigations. Static IP would surely make it slow for half of the world, unless we switch to www. redirects which would probably be a larger change.)19:31:05
@vcunat:matrix.orgVladimír Čunát* (I'm out of ideas for shorter-term mitigations. Static IP would surely make it slow for half of the world, unless we switch to www. redirects which would perhaps be a larger change.)19:32:14
@hexa:lossy.networkhexa5h ago19:33:09
@hexa:lossy.networkhexanetlify has a single IPv4 adress we can point nixos.org to19:33:27
@raitobezarius:matrix.orgraitobezariusI did mention it to Gandi people I was IRL few hours ago19:34:01
@raitobezarius:matrix.orgraitobezarius(who might escalate it internally)19:34:10
@vcunat:matrix.orgVladimír Čunát🤔 though if the IP was anycasted, it might not be so bad.19:34:12
@vcunat:matrix.orgVladimír Čunát Heh, we go against Netlify's strong recommendations with the www.
https://docs.netlify.com/manage/domains/manage-domains/manage-multiple-domains/#apex-domains-and-www-subdomains
19:36:06

Show newer messages


Back to Room ListRoom Version: 6