!VhzbGHamdfMiGxpXyg:robins.wtf

NixOS LXC

36 Members
lxc, lxd, incus discussions related to NixOS15 Servers

Load older messages


SenderMessageTime
28 Jan 2025
@adam:robins.wtfadamcstephensThat's probably in the magical stgraber not-public land21:19:57
@adam:robins.wtfadamcstephensI'll open an issue and see if he can fix it21:20:25
@adam:robins.wtfadamcstephenshttps://github.com/lxc/lxc-ci/issues/86521:22:03
@adam:robins.wtfadamcstephens for the other error, we can set i18n.defaultLocale = "C.UTF-8"; in the image, or add locales 21:22:32
@adam:robins.wtfadamcstephensi haven't dug into why they're missing, but these images try to strip out a bunch of stuff to keep them small21:22:54
29 Jan 2025
@adam:robins.wtfadamcstephens since you reminded me of lxc-ci yesterday, I removed 24.05 hexa :) 16:29:27
@hexa:lossy.networkhexa!!!!!!16:29:38
@hexa:lossy.networkhexaonly slightly EOL 😄 16:30:57
@adam:robins.wtfadamcstephensslightly16:31:22
@adam:robins.wtfadamcstephensi'll try and set a reminder for myself next time16:31:40
@hexa:lossy.networkhexamaybe add it to the release wiki16:33:19
@hexa:lossy.networkhexaso you get poked by release managers16:33:23
@adam:robins.wtfadamcstephenshttps://github.com/NixOS/release-wiki/pull/9818:03:02
31 Jan 2025
@hexa:lossy.networkhexaanyone here reverse proxying incus webui to :443?12:18:52
@hexa:lossy.networkhexaI would assume that for client certificate auth to keep working I need to let incus terminate the TLS session12:19:15
@adam:robins.wtfadamcstephens I haven’t tried that but sounds right 13:41:07
@hexa:lossy.networkhexaso either nginx stream or haproxy13:43:33
@adam:robins.wtfadamcstephens I would assume traefik could do it too, if that’s an option for you 13:48:10
@adam:robins.wtfadamcstephens It has TLS pass through  13:48:24
@hexa:lossy.networkhexahm, I think i need to set the cluster certificate13:49:08
@hexa:lossy.networkhexa
root@incus1:~# incus cluster update-cert --help
Description:
  Update cluster certificate with PEM certificate and key read from input files.

Usage:
  incus cluster update-certificate [<remote>:] <cert.crt> <cert.key> [flags]
13:49:18
@hexa:lossy.networkhexato slide in something from Letsencrypt13:49:30
@hexa:lossy.networkhexabut that seems like one cert for the whole cluster, which is a bit wild 😄 13:50:05
@hexa:lossy.networkhexa hm, but there is both a cluster.key and a server.key 13:55:52
@hexa:lossy.networkhexawondering which one gets used for the webui13:56:03
@hexa:lossy.networkhexa ok, looks like cluster.crt is what is sent over https 13:56:46
@hexa:lossy.networkhexa * ok, looks like cluster.crt is what is used for https 13:56:54
@adam:robins.wtfadamcstephensare you finally rolling out at work?15:44:15
@hexa:lossy.networkhexaI did15:44:34
@hexa:lossy.networkhexawas stuck on a faulty ESI-LAG config that required a reboot to clear15:45:13

Show newer messages


Back to Room ListRoom Version: 10