!coeAONBrWyDJnYMbMi:nixos.org

NixOS System Operations

588 Members
About system administration for running NixOS systems in production. Declaratively manage your operations. | Room recommendations: #networking:nixos.org156 Servers

Load older messages


SenderMessageTime
25 Jan 2025
@scrumplex:duckhub.ioScrumplex👀 Thank you for lending me your pair of eyes 😅14:38:04
28 Jan 2025
@syxal:syxal.io@syxal:syxal.io left the room.09:35:04
@adam:robins.wtfadamcstephensLet Encrypt is ending expiration emails. Since I rely on this in case automation is failing unexpectedly, I'd like an alternative. Any suggestions for something self hosted you like?19:21:14
@magic_rb:matrix.redalder.orgmagic_rbopenssl in a cron job with some regex? /partial s19:21:55
@adam:robins.wtfadamcstephenssure, i could script something19:22:45
@adam:robins.wtfadamcstephensthough i wouldn't probably use openssl cli for it :)19:23:06
@magic_rb:matrix.redalder.orgmagic_rb https://github.com/serokell/serokell.nix/blob/master/modules/acme-sh.nix im using this for automatic renewal 19:23:46
@dgrig:erethon.comdgrighttps://github.com/prometheus/blackbox_exporter is what's commonly used (but it assumes you have prometheus already and alertmanager setup)19:23:47
@magic_rb:matrix.redalder.orgmagic_rb Well, my own fork in my dotfiles 19:23:54
@adam:robins.wtfadamcstephensi don't need the renewal itself. just monitoring of installed certs19:37:43
@k900:0upti.meK900 blackbox-exporter can do that 19:38:02
@k900:0upti.meK900But you do need a working LGTM stack for it to be nice19:38:16
@k900:0upti.meK900Unless you're willing to raw dog Prometheus I guess 19:38:31
@adam:robins.wtfadamcstephensi converted to alloy recently which has a blackbox exporter19:39:18
@adam:robins.wtfadamcstephensso i have a working LGM setup. no T because I'm not generating that many traces yet :)19:40:48
@k900:0upti.meK900Then yeah it just has a metric for certificate expiration date 19:41:10
@adam:robins.wtfadamcstephensthanks. i'll use that then19:41:28
@adam:robins.wtfadamcstephensthough i may write a custom setup to expose an RSS feed instead. :)19:42:14
@adam:robins.wtfadamcstephensanybody switch to 7 day certs yet?19:42:26
@k900:0upti.meK900Can lego even do those yet? 19:42:53
@k900:0upti.meK900I have not checked 19:42:59
@adam:robins.wtfadamcstephensi haven't either.19:43:18
@adam:robins.wtfadamcstephens sorry, they're six day 19:43:22
@hexa:lossy.networkhexaplease report back once you know 🙂 20:18:46
@adam:robins.wtfadamcstephensi don't see anything, so i went back to the LE blog opst20:39:35
@adam:robins.wtfadamcstephens* i don't see anything, so i went back to the LE blog post20:39:37
@adam:robins.wtfadamcstephens

Around April we will enable short-lived certificates for a small set of early adopting subscribers. We hope to make short-lived certificates generally available by the end of 2025.

20:39:41
@adam:robins.wtfadamcstephenslooks like the support we're going to want are "profiles" https://letsencrypt.org/2025/01/09/acme-profiles/20:40:18
29 Jan 2025
@alexb:homeserver.ballmerlabs.netalexb joined the room.04:33:55
@oxapentane:matrix.orgoxa moved -> 0xa:oxapentane.com changed their profile picture.22:14:21

Show newer messages


Back to Room ListRoom Version: 10