!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

418 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.128 Servers

Load older messages


SenderMessageTime
14 May 2026
@vcunat:matrix.orgvcunatWell, I did not know this stuff. Just tried to diagnose the issue quickly.14:22:55
@vcunat:matrix.orgvcunat

Which pointed me to

GIT_DIR=$dir git config credential.helper 'store --file=${config.age.secrets.hydra-mirror-git-credentials.path}'
14:37:47
@hexa:lossy.networkhexa (signing key rotation when)this is easily fixed14:50:56
@hexa:lossy.networkhexa (signing key rotation when)we'll go for an ssh key this time, I think14:56:06
@emilazy:matrix.orgemilyyeah, making it use an app is probably good for the long term to scope the permissions further but SSH key will at least restrict it down to Git ops15:14:48
@emilazy:matrix.orgemilysorry for missing that when looking through the infra repo15:15:18
@emilazy:matrix.orgemilyI'll look through the other reports in more detail later15:16:28
@emilazy:matrix.orgemilybut I guess this was the only thing noticed for official infra?15:16:38
@hexa:lossy.networkhexa (signing key rotation when)I didn't check, because I assumed you did15:18:12
@hexa:lossy.networkhexa (signing key rotation when)but no biggie15:18:15
@hexa:lossy.networkhexa (signing key rotation when)I'll check the rest of infra in a bit15:18:30
@emilazy:matrix.orgemilyI did15:28:51
@emilazy:matrix.orgemilyI listed my findings in the original issue15:29:03
@emilazy:matrix.orgemilybut pinged because it seemed possible I missed something since I'm not super savvy with the infra repo and don't have access to the secrets to see what format they take15:29:33
@emilazy:matrix.orgemilythe secret had Hydra in the name and I checked that the Hydra code was doing it right (with other Hydra secrets I guess). didn't correlate it with the channel scripts that looked like they'd just be using an SSH key15:30:35
@hexa:lossy.networkhexa (signing key rotation when)infra call in 30m15:31:24
@hexa:lossy.networkhexa (signing key rotation when)no worries, emily15:31:49
@hexa:lossy.networkhexa (signing key rotation when)https://github.com/NixOS/infra/pull/103315:33:55
@hexa:lossy.networkhexa (signing key rotation when)at least the git* secrets look clean15:45:48
@hexa:lossy.networkhexa (signing key rotation when)they're not random pats15:46:00
@hexa:lossy.networkhexa (signing key rotation when)https://meet.cccda.de/nix-osin-fra15:53:25
@hexa:lossy.networkhexa (signing key rotation when) We enabled Intelligent Tiering on the cache.nixos.org S3 bucket. The idea is that we'll save money by moving older objects to lower storing tiers "intelligently". We'll check back in a month to evaluate the update cost structure. 16:47:51
@hexa:lossy.networkhexa (signing key rotation when)Redacted or Malformed Event16:48:01
@hexa:lossy.networkhexa (signing key rotation when)
 $ git remote update origin >&2
Fetching origin
From https://github.com/NixOS/nixpkgs
 * [new branch]                backport-518430-to-release-25.11 -> origin/backport-518430-to-release-25.11
   7f1371b3a6db..3054723ea2b1  master         -> origin/master
   625b14ada4b3..aa8faea6d577  python-updates -> origin/python-updates
   fbc1b6e6d1ad..503504ad2d36  release-25.11  -> origin/release-25.11
   997d0d965a30..0b1741a3bf36  staging        -> origin/staging
   e81ce22cc447..2a7e5c6f1f46  staging-next   -> origin/staging-next
   ec5490bc79b6..2a49f0d42ca9  staging-nixos  -> origin/staging-nixos
 $ git push origin 54a8ef403e0b27e1eed0298f92e8d3cb863c968a:refs/heads/nixos-25.11-small >&2
fatal: could not read Username for 'https://github.com': No such device or address
Command failed with code (128) errno (0).
22:38:38
@hexa:lossy.networkhexa (signing key rotation when)welp22:38:45
@hexa:lossy.networkhexa (signing key rotation when)https://seashells.io/v/TrBcrEvC22:40:30
@hexa:lossy.networkhexa (signing key rotation when)ok, we're good22:41:36
15 May 2026
@hexa:lossy.networkhexa (signing key rotation when)in 2 minutes10:22:54
@hexa:lossy.networkhexa (signing key rotation when) gabyx doesn't look like it reproduces 10:26:44
@hexa:lossy.networkhexa (signing key rotation when)https://photon.codes/blog/we-found-a-ticking-time-bomb-in-macos-tcp-networking 🤷10:27:29

Show newer messages


Back to Room ListRoom Version: 6