27 May 2024 |
adamcstephens | yeah, agreed. i figured the sudo exec showed it should work | 15:27:18 |
adamcstephens | now you have me doubting it :) | 15:27:27 |
hexa | sudo is unconstrained root access | 15:29:08 |
hexa | if your incus systemd units don't have hardening (CapabilityBoundingSet in this case), then all is well | 15:29:41 |
adamcstephens | they don't | 15:38:27 |
28 May 2024 |
hexa | # incus launch images:nixos/unstable nixos -c security.secureboot=false
Launching nixos
Error: Failed instance creation: Failed creating instance record: Unknown configuration key: security.secureboot
| 11:54:50 |
hexa | on 6.0.0 🤔 | 11:54:57 |
hexa | missing --vm flag in wiki example, fixed | 11:57:20 |
adamcstephens | thanks for fixing | 13:06:45 |
hexa | online migration with zfs is working fine | 14:11:58 |
hexa | loving the remote cli acccess to the cluster | 14:12:09 |
hexa | a bit annoying that it is stuck with a single node | 14:14:54 |
hexa | Download image.png | 14:25:02 |
hexa | the capitalization is off | 14:25:12 |
adamcstephens | hmm, i'm not sure where that comes from | 14:39:18 |
adamcstephens | In reply to @hexa:lossy.network a bit annoying that it is stuck with a single node what does this mean? | 14:39:26 |
hexa | so you can set up your local CLI to use remotes | 14:41:38 |
hexa | * so, you can set up your local CLI to control remote clusters over the HTTP API | 14:42:51 |
hexa | incus config trust add foo prints a token | 14:43:06 |
hexa | and you can configure that with incus remote add somecluster <token> | 14:43:19 |
hexa | and then incus remote switch somecluster | 14:43:26 |
hexa | but this isn't somecluster , it is somehostofsomecluster only | 14:43:40 |
adamcstephens | ahh, so the remote isn't cluster aware | 14:43:56 |
hexa | yeah | 14:44:02 |
hexa | the keying probably is | 14:44:04 |
hexa | but the CLI isn't smart enough to failover to other cluster members | 14:44:17 |
adamcstephens | yeah that's a shame. so you'd have to add all the nodes individually and target them | 14:46:16 |
hexa | and switch projects as needed 🙂 | 14:46:26 |
adamcstephens | what kind of environment are you trying to replace? | 14:48:36 |
adamcstephens | vmware? | 14:48:39 |