!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

374 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.115 Servers

Load older messages


SenderMessageTime
18 Oct 2025
@hexa:lossy.networkhexa (signing key rotation when)all alias records are servfail on some gandi pop reachable from Southern Europe and the Middle East and South America19:11:23
@vcunat:matrix.orgvcunatDo we really need ALIAS records in there?19:13:58
@vcunat:matrix.orgvcunatSurely there's a solution which works for static A+AAAA?19:14:17
@vcunat:matrix.orgvcunat(even if perhaps the first redirect is slightly slower than with an ALIAS)19:14:37
@hexa:lossy.networkhexa (signing key rotation when)netlify does geodns, so the alias record was so that people would get a local pop19:16:46
@hexa:lossy.networkhexa (signing key rotation when)do we need it? no19:16:56
@hexa:lossy.networkhexa (signing key rotation when)is it better than not having it? yes19:17:06
@vcunat:matrix.orgvcunatAah, I thought the normal practice is that you get http-redirected to www.19:17:41
@vcunat:matrix.orgvcunat(and there you can have CNAME)19:17:49
@hexa:lossy.networkhexa (signing key rotation when)yeah, ideally19:17:56
@hexa:lossy.networkhexa (signing key rotation when)but that is not the case on nixos.org19:18:00
@vcunat:matrix.orgvcunatbut I'm somewhat out of touch from the web world.19:18:04
@hexa:lossy.networkhexa (signing key rotation when)and I'm not keen on changing that, because it'll fck with search results, no?19:18:13
@vcunat:matrix.orgvcunatI see now. But don't tell me that netlify is relying on ALIAS so heavily.19:18:22
@vcunat:matrix.orgvcunatI mean, it's completely unstandardized.19:18:28
@hexa:lossy.networkhexa (signing key rotation when)they only give us a hostname19:18:37
@hexa:lossy.networkhexa (signing key rotation when)no stable IP addresses19:18:42
@hexa:lossy.networkhexa (signing key rotation when)we hosted DNS until earlier this year19:19:06
@hexa:lossy.networkhexa (signing key rotation when)which is how that ✨️ magic ✨️ just worked19:19:26
@hexa:lossy.networkhexa (signing key rotation when)but alas nixos-homepage was using that account with unscoped api tokens and pull_request_target and lol no19:20:19
@vcunat:matrix.orgvcunat🤔 I guess Netlify prefer that you have DNS with them as well.19:20:41
@hexa:lossy.networkhexa (signing key rotation when)Redacted or Malformed Event19:20:50
@vcunat:matrix.orgvcunatThey seem to offer a static IP, but given that we don't redirect... https://docs.netlify.com/manage/domains/configure-domains/configure-external-dns/#configure-an-apex-domain19:20:55
@vcunat:matrix.orgvcunatAnd I see no option for HTTPS records to salvage at least some clients.19:21:22
@vcunat:matrix.orgvcunatYeah, I don't know. Not great.19:21:42
@hexa:lossy.networkhexa (signing key rotation when)I did recreate the nixos.org origin record a while ago, but that didn't change anything19:25:08
@vcunat:matrix.orgvcunatAnd a ticket at Gandi has been created, surely.19:26:32
@vcunat:matrix.orgvcunat(I'm out of ideas for shorter-term mitigations. Static IP would surely make it slow for half of the world, unless we switch to www. redirects which would probably be a larger change.)19:31:05
@vcunat:matrix.orgvcunat* (I'm out of ideas for shorter-term mitigations. Static IP would surely make it slow for half of the world, unless we switch to www. redirects which would perhaps be a larger change.)19:32:14
@hexa:lossy.networkhexa (signing key rotation when)5h ago19:33:09

Show newer messages


Back to Room ListRoom Version: 6