!UKDpaKNNsBpOPfLWfX:zhaofeng.li

Colmena

289 Members
A simple, stateless NixOS deployment tool - https://github.com/zhaofengli/colmena97 Servers

Load older messages


SenderMessageTime
3 May 2023
@hexa:lossy.networkhexaI use a ControlMaster socket for ssh13:38:31
@hexa:lossy.networkhexaand when I am already logged into the host I13:38:48
@hexa:lossy.networkhexa * and when I am already logged into the host I'm deploying to, colmena gets stuck at "Pushing system closure" and "Activation system profiile"13:39:18
@hexa:lossy.networkhexa * and when I am already logged into the host I'm deploying to, colmena gets stuck at "Pushing system closure" and "Activation system profile"13:39:20
@hexa:lossy.networkhexafeels like it wants to disconnect/reconnect the ssh connection multiple times13:43:17
@whentze:matrix.orgWanja HentzeI've seen colmena hang forever at pushing when using proxyjumps14:05:10
@whentze:matrix.orgWanja Hentzeseemed to happen only sporadically and only when using ssh-ng14:05:25
@whentze:matrix.orgWanja Hentzedoes your problem happen *always* or just once in a while?14:05:49
@hexa:lossy.networkhexait is highly reproducible14:33:42
@hexa:lossy.networkhexaiterated on a module, so I did 10+ deploys in a row14:33:56
@hexa:lossy.networkhexagot stuck every time I was logged in, tailing the journal14:34:06
@me:indeednotjames.comemilydo you have a lot of deployment keys? jumphost?14:34:30
@hexa:lossy.networkhexano jumphosts, strict key matching14:34:52
@me:indeednotjames.comemilysshd logs? do you use a lot of deployment keys that need to be uploaded each apply? (--no-keys maybe?)14:36:33
@hexa:lossy.networkhexaI don't use pre-activation keys14:39:56
@oddlama:matrix.orgoddlamaI've also been using control sockets, and I always keep a connection to the target open in the background before running colmena. But I don't have these issues.15:36:52
@oddlama:matrix.orgoddlamaI remember running into something like that once or twice though, but since it never occurred again I attributed it to a fluke15:37:17
@linus:schreibt.jetzt@linus:schreibt.jetzt

hexa: connection limit? I have

        extraConfig = ''
          Match All
            MaxSessions 100
        '';

on my services.openssh

15:37:56
@linus:schreibt.jetzt@linus:schreibt.jetzt *

hexa: session limit? I have

        extraConfig = ''
          Match All
            MaxSessions 100
        '';

on my services.openssh

15:38:03
@hexa:lossy.networkhexanop16:22:57
4 May 2023
@treed:zenithia.nettreed joined the room.07:08:04
5 May 2023
@philipp:woelfel.ca@philipp:woelfel.ca joined the room.23:38:17
14 May 2023
@julian:nekover.se@julian:nekover.se joined the room.23:20:58
16 May 2023
@boozedog:matrix.orgDavid A. Buser (boozedog) joined the room.11:37:46
18 May 2023
@ibizaman:matrix.orgibizaman joined the room.06:48:01
@ibizaman:matrix.orgibizamanHi all. I wanted to support this great tool and I wrote a blog post which covers deploying to a Raspberry PI (really, any supported ARM device) using colmena. http://ibizaman.github.io/posts/2023-05-12-install-nixos-on-a-raspberry-pi.html All feedback is appreciated.06:51:32
@yuri:nekover.se@yuri:nekover.se joined the room.19:31:49
@yuri:nekover.se@yuri:nekover.se

hi, I'm new to Nix and want to use Colmena to setup a remote host. This works fine, but what I don't understand is when I specify a user with "targetUser" in the "deployment" set who is member of the wheel group and "security.sudo.wheelNeedsPassword" is set to "false", I still need to add the user to "nix.settings.trusted-users" for it to work.
Otherwise I get the error

[ERROR]   stderr) error: cannot add path '/nix/store/6nh78ndmjdqg19ni7gmngp3cpjsf9ykm-system-path' because it lacks a valid signature

when running "colmena apply".
Does anyone know why that is?

21:25:54
@zhaofeng:zhaofeng.liZhaofeng Li It's because it copies the closure with nix-copy-closure using the targetUser 21:52:59
@zhaofeng:zhaofeng.liZhaofeng LiThe behavior is indeed pretty counterintuitive when privilegeEscalationCommand is a thing but isn't used at that stage21:53:56

Show newer messages


Back to Room ListRoom Version: 6