!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

418 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.128 Servers

Load older messages


SenderMessageTime
29 May 2026
@raitobezarius:matrix.orgraitobezariusalso Keycloak has proper forced PKCE, DPoP and will probably have transaction tokens21:19:27
@raitobezarius:matrix.orgraitobezariusif i could put the keycloak ui on my screenlocker, i would21:19:46
@raitobezarius:matrix.orgraitobezariuskeycloak can log oidc tokens21:26:04
@hexa:lossy.networkhexa (signing key rotation when)fine21:31:58
@hexa:lossy.networkhexa (signing key rotation when)I don't care too strongly anyhow21:32:10
@hexa:lossy.networkhexa (signing key rotation when) nobody ever got fired for running keycloak 21:33:26
30 May 2026
@pyrox:pyrox.devdish [Fox/It/She]
In reply to @hexa:lossy.network
Question is: Keycloak vs Authentik

neither >:3 /jk

but i ran authentik for a while and its very complicated and heavyweight feeling so its not my preferred. no experience with keycloak so idk how it is in that regard

00:00:01
@pyrox:pyrox.devdish [Fox/It/She] also authentik can feel slow at times >.> 00:00:14
@hexa:lossy.networkhexa (signing key rotation when)keycloak is a java enterprise app :p00:02:24
@bart:bartoostveen.nlBartAnd Authentik is a beefy Django + Go app :p00:12:53
@hexa:lossy.networkhexa (signing key rotation when)If in doubt, I'd rather debug python and go over java00:26:49
@hexa:lossy.networkhexa (signing key rotation when)Redacted or Malformed Event00:26:55
@bart:bartoostveen.nlBartoh definitely00:46:47
@bart:bartoostveen.nlBartand authentik docs are way better than keycloak as well00:47:29
@pyrox:pyrox.devdish [Fox/It/She]
In reply to @hexa:lossy.network
keycloak is a java enterprise app :p
JVM can be fast 🤷‍♀️
01:54:31
@hexa:lossy.networkhexa (signing key rotation when)but annoying to debug01:54:41
@hexa:lossy.networkhexa (signing key rotation when)and not easy to patch01:54:49
@pyrox:pyrox.devdish [Fox/It/She]oh absolutely01:54:51
@hexa:lossy.networkhexa (signing key rotation when)we just fetch something pre-built in nixpkgs and tada.wav01:55:32
@leona:leona.isleonaI try self compiling keycloak for a while … maybe soon lol (it’s awful)07:38:02
@ma27:nicht-so.sexyma27you forget the RUst part in 2026.5 that's surprisingly annoying to package (almost done with it as well, then I'll open my promised PR :p) ;-)08:38:27
@sternenseemann:systemli.orgsternikeycloak had massive issues with GitHub logins when you had (some) emails marked as private, probably wise to check whether that’s fixed if GH backed logins are needed09:14:36
@raitobezarius:matrix.orgraitobezariusIt was fixed09:27:41
@bart:bartoostveen.nlBart oh no 😭 09:54:45
@bart:bartoostveen.nlBartI did not know09:54:50
@bart:bartoostveen.nlBartIt seems like Hydra is having troubles uploading artifacts to S310:56:10
@bart:bartoostveen.nlBartimage.png
Download image.png
10:56:10
@hexa:lossy.networkhexa (signing key rotation when)regularly10:56:54
@bart:bartoostveen.nlBartI noticed this because status.nixos.org is almost entirely red 😭10:57:17
@hexa:lossy.networkhexa (signing key rotation when)I think that's because somone abort non-current builds10:57:53

Show newer messages


Back to Room ListRoom Version: 6