!coeAONBrWyDJnYMbMi:nixos.org

NixOS System Operations

569 Members
About system administration for running NixOS systems in production. Declaratively manage your operations. | Room recommendations: #networking:nixos.org155 Servers

Load older messages


SenderMessageTime
25 Jan 2025
@k900:0upti.meK900It's /var/lib/postgresql14:37:36
@scrumplex:duckhub.ioScrumplex👀 Thank you for lending me your pair of eyes 😅14:38:04
28 Jan 2025
@syxal:syxal.io@syxal:syxal.io left the room.09:35:04
@adam:robins.wtf@adam:robins.wtfLet Encrypt is ending expiration emails. Since I rely on this in case automation is failing unexpectedly, I'd like an alternative. Any suggestions for something self hosted you like?19:21:14
@magic_rb:matrix.redalder.orgmagic_rbopenssl in a cron job with some regex? /partial s19:21:55
@adam:robins.wtf@adam:robins.wtfsure, i could script something19:22:45
@adam:robins.wtf@adam:robins.wtfthough i wouldn't probably use openssl cli for it :)19:23:06
@magic_rb:matrix.redalder.orgmagic_rb https://github.com/serokell/serokell.nix/blob/master/modules/acme-sh.nix im using this for automatic renewal 19:23:46
@dgrig:erethon.comdgrighttps://github.com/prometheus/blackbox_exporter is what's commonly used (but it assumes you have prometheus already and alertmanager setup)19:23:47
@magic_rb:matrix.redalder.orgmagic_rb Well, my own fork in my dotfiles 19:23:54
@adam:robins.wtf@adam:robins.wtfi don't need the renewal itself. just monitoring of installed certs19:37:43
@k900:0upti.meK900 blackbox-exporter can do that 19:38:02
@k900:0upti.meK900But you do need a working LGTM stack for it to be nice19:38:16
@k900:0upti.meK900Unless you're willing to raw dog Prometheus I guess 19:38:31
@adam:robins.wtf@adam:robins.wtfi converted to alloy recently which has a blackbox exporter19:39:18
@adam:robins.wtf@adam:robins.wtfso i have a working LGM setup. no T because I'm not generating that many traces yet :)19:40:48
@k900:0upti.meK900Then yeah it just has a metric for certificate expiration date 19:41:10
@adam:robins.wtf@adam:robins.wtfthanks. i'll use that then19:41:28
@adam:robins.wtf@adam:robins.wtfthough i may write a custom setup to expose an RSS feed instead. :)19:42:14
@adam:robins.wtf@adam:robins.wtfanybody switch to 7 day certs yet?19:42:26
@k900:0upti.meK900Can lego even do those yet? 19:42:53
@k900:0upti.meK900I have not checked 19:42:59
@adam:robins.wtf@adam:robins.wtfi haven't either.19:43:18
@adam:robins.wtf@adam:robins.wtf sorry, they're six day 19:43:22
@hexa:lossy.networkhexaplease report back once you know 🙂 20:18:46
@adam:robins.wtf@adam:robins.wtfi don't see anything, so i went back to the LE blog opst20:39:35
@adam:robins.wtf@adam:robins.wtf* i don't see anything, so i went back to the LE blog post20:39:37
@adam:robins.wtf@adam:robins.wtf

Around April we will enable short-lived certificates for a small set of early adopting subscribers. We hope to make short-lived certificates generally available by the end of 2025.

20:39:41
@adam:robins.wtf@adam:robins.wtflooks like the support we're going to want are "profiles" https://letsencrypt.org/2025/01/09/acme-profiles/20:40:18
29 Jan 2025
@alexb:homeserver.ballmerlabs.netalexb joined the room.04:33:55

Show newer messages


Back to Room ListRoom Version: 10