!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

468 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.147 Servers

Load older messages


SenderMessageTime
27 Jun 2026
@wamserma:nixos.devwamsermatlog sounds nice. + publishing a hash in a few different places as RoT?12:10:16
@emilazy:matrix.orgemilytbh Merkle tree certs is what would be ideal, but that'd be a whole thing to teach Nix about12:10:16
@emilazy:matrix.orgemilyyou can do better than that12:10:27
@emilazy:matrix.orgemilyhttps://witness-network.org/12:10:38
@emilazy:matrix.orgemilyespecially with WebPKI adopting MTCs with tlogs as the source of truth for certs there's a lot of nice things happening12:11:19
@wamserma:nixos.devwamsermadid someone mention SLSA yet?12:13:09
@hexa:lossy.networkhexa (signing key rotation when)yes, tooon in 202212:13:58
@hexa:lossy.networkhexa (signing key rotation when)Redacted or Malformed Event12:14:03
@hexa:lossy.networkhexa (signing key rotation when)Redacted or Malformed Event12:14:09
@wamserma:nixos.devwamserma(just being snarky, going full SLSA would be leaping instead of taking this in reasonable steps)12:15:26
@hexa:lossy.networkhexa (signing key rotation when)given that this rom is lossy12:15:43
@hexa:lossy.networkhexa (signing key rotation when)Redacted or Malformed Event12:15:49
@hexa:lossy.networkhexa (signing key rotation when)y'all should schedule a meeting and discuss options12:15:58
@hexa:lossy.networkhexa (signing key rotation when)and come back with a protocol12:16:03
@wamserma:nixos.devwamsermai can offer this as a thesis topic :)12:20:24
@vcunat:matrix.orgvcunatThe GC issues need deploying some updates on the builders (as well), right?13:14:51
@joerg:thalheim.ioMic92 hexa (signing key rotation when): did this presumably? Because the branch is merged. 13:17:58
@vcunat:matrix.orgvcunat

A quick check didn't seem that way:

[root@elated-minsky:~]# ls -l /run/current-system
lrwxrwxrwx 1 root root 93 Jun 27 00:00 /run/current-system -> /nix/store/hy3xflm3y9ckb8zrdv73gb63xgmycw3g-nixos-system-elated-minsky-26.05.20260621.c1613e5
13:18:38
@joerg:thalheim.ioMic92Okay, feel free to update.13:19:02
@hexa:lossy.networkhexa (signing key rotation when)I did update the builders with the patched nix package13:19:25
@hexa:lossy.networkhexa (signing key rotation when)before I merged13:19:30
@joerg:thalheim.ioMic92Grafana looks good now13:19:48
@hexa:lossy.networkhexa (signing key rotation when)and I do rebase all PRs before redeploying, to prevent rollbacsk13:20:02
@vcunat:matrix.orgvcunat 🤔 I thought such updates would change timestamps of /run/current-system and /nix/var/nix/profiles/system 13:25:01
@vcunat:matrix.orgvcunat *

I did update the builders with the patched nix package

🤔 I thought such updates would change timestamps of /run/current-system and /nix/var/nix/profiles/system

13:25:21
@vcunat:matrix.orgvcunat(unless you did it earlier than in the last 13h.13:26:22
@vcunat:matrix.orgvcunat* (unless you did it earlier than in the last 13h)13:26:25
@vcunat:matrix.orgvcunat* (unless you did it earlier than in the last 13h; my point is to understand this better)13:29:10
@vcunat:matrix.orgvcunat* (unless you did it earlier than in the last 13h; my main point is to understand this better)13:29:16
@hexa:lossy.networkhexa (signing key rotation when)certainly not13:31:48

Show newer messages


Back to Room ListRoom Version: 6