!coeAONBrWyDJnYMbMi:nixos.org

NixOS System Operations

549 Members
About system administration for running NixOS systems in production. Declaratively manage your operations. | Room recommendations: #networking:nixos.org146 Servers

Load older messages


SenderMessageTime
26 Feb 2025
@magic_rb:matrix.redalder.orgmagic_rbI only allow ssh over wireguard period20:28:33
@dgrig:erethon.comdgrig(waiting for a new circuit after a restart can be a bit annoying if you're trying to ssh right after a restart in my opinion)20:28:36
@scrumplex:duckhub.ioScrumplexAnother way to reduce ssh bot noise is to limit sshd to listen on IPv6 only20:50:50
@sigmasquadron:matrix.orgFernando Rodrigues
In reply to @magic_rb:matrix.redalder.org
I only allow ssh over wireguard period
ssh over wireguard is so nice
21:36:06
@hexa:lossy.networkhexayeah, much nicer than just using ssh over internet21:38:07
@hexa:lossy.networkhexa * yeah, much nicer than just using ssh over internet \s 21:38:09
@hexa:lossy.networkhexato be clear, I have a wireguard/babel mesh, so I can ssh over a routed connection of private addresses21:38:39
@sigmasquadron:matrix.orgFernando Rodrigues
In reply to @hexa:lossy.network
yeah, much nicer than just using ssh over internet \s
i mean, unironically yes.
21:38:43
@hexa:lossy.networkhexabut now imagine a git host21:38:49
@sigmasquadron:matrix.orgFernando RodriguesI don't see the issue?21:39:11
@hexa:lossy.networkhexagit+ssh21:39:19
@hexa:lossy.networkhexa* git+ssh://21:39:30
@sigmasquadron:matrix.orgFernando RodriguesSure, just change the IP from whatever it was before to the wireguard address.21:39:43
@sigmasquadron:matrix.orgFernando Rodriguesditto with a domain21:39:50
@hexa:lossy.networkhexaa custom port is too cumbersome, means everyone needs to maintain ssh configs etc.21:39:50
@hexa:lossy.networkhexapublic git access over ssh21:40:04
@hexa:lossy.networkhexaforgejo21:40:07
@hexa:lossy.networkhexagitlab21:40:09
@sigmasquadron:matrix.orgFernando Rodriguesah, yes. forgejo.21:40:26
@sigmasquadron:matrix.orgFernando Rodriguescurrently i use a nginx stream to proxy ssh connections over a wireguard tunnel to a forgejo host21:40:55
@hexa:lossy.networkhexanginx stream is a fancy word for saying "socat"21:41:10
@sigmasquadron:matrix.orgFernando Rodriguesyes21:41:16
@dgrig:erethon.comdgrig(gitlab automatically adds the ssh port in the UI when copying the git clone command iirc, but agreed it can be a pita)21:43:12
@hexa:lossy.networkhexachanging the ssh port means everyone needs to adapt on every machine for every application using it21:47:42
@hexa:lossy.networkhexathat's not worth the hassle21:47:48
27 Feb 2025
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.17:11:06
@flare:matrix.darkc0de.oneflareeh22:54:41
@flare:matrix.darkc0de.oneflarefor personal uses it has worked for me that approach22:54:53
1 Mar 2025
@77a5a1:matrix.org@77a5a1:matrix.org

Hello, could someone help me with this error?

error: a 'x86_64-linux' with features {gccarch-raptorlake} is required to build '/nix/store/x0zfxhzq9xh2s3f02qhzxwgi17fglk8h-bootstrap-stage0-glibc-bootstrapFiles.drv', but I am a 'x86_64-linux' with features {benchmark, big-parallel, kvm, nixos-test}

21:53:29
@77a5a1:matrix.org@77a5a1:matrix.org
cat /etc/nixos/configuration.nix 
{ config, pkgs, lib, ... }:
{
  nix.settings.system-features = [ "gccarch-raptorlake" "benchmark" "big-parallel" "kvm" "nixos-test" ];
  nixpkgs.hostPlatform = { gcc.arch = "raptorlake"; gcc.tune = "raptorlake"; system = "x86_64-linux"; };

21:54:00

Show newer messages


Back to Room ListRoom Version: 10