!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

918 Members
Declaratively manage your switching, routing, wireless, tunneling and more.276 Servers

Load older messages


SenderMessageTime
21 Aug 2021
@6aa4fd:tchncs.de6aa4fda data center with only a /64? what a joke03:00:11
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneWell, it's just a business connection.03:00:22
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneBT (British Telecom)03:00:27
@6aa4fd:tchncs.de6aa4fdthat is like a v4 network with only one vlan03:00:30
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneYup :D03:00:35
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneHorrible.03:00:36
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneand the network administrator is a BOFH03:00:54
@6aa4fd:tchncs.de6aa4fddo they just use Mac based firewalling?03:01:01
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneNot sure about the firewall details, it's a free for all.03:01:18
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zonehttps://youtu.be/GE94BJg3U1Q03:01:26
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneThis video should explain it.03:01:28
@6aa4fd:tchncs.de6aa4fd
In reply to @matthewcroughan:defenestrate.it
Not sure about the firewall details, it's a free for all.
time to get ya shit out brotha
03:06:05
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneI'm not that paranoid really.03:06:16
@6aa4fd:tchncs.de6aa4fdanyways good luck with the tunnel, ping me if it hisses03:06:37
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneA NixOS machine is a pretty good and secure internet facing base.03:06:39
@6aa4fd:tchncs.de6aa4fdsure unless they get any user with read access03:07:00
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneOnly two users on the machine. Me and the other Administrator.03:07:31
@6aa4fd:tchncs.de6aa4fduntil we have granular store permissions its pretty dicey as production03:07:37
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneTwo users with a shell, and ssh access, ssh keys only.03:07:47
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zone
In reply to @6aa4fd:tchncs.de
until we have granular store permissions its pretty dicey as production
How do you figure? What does the store have to do with it?
03:08:08
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneNothing sensitive is in the nix store.03:08:19
@6aa4fd:tchncs.de6aa4fdyeah well if you don't expose anything but ssh, back ports are the only thing that matters, its not exactly a conpetjtkve field03:08:26
@6aa4fd:tchncs.de6aa4fdwell sure but a shit load of services you configure with the nix store do have write-sensitive information in the store03:09:10
@6aa4fd:tchncs.de6aa4fdso not actually true, though it would be nice03:09:28
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneThe nix store is not world writable.03:09:29
@6aa4fd:tchncs.de6aa4fdread-sensitive, sorry03:09:40
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneI disagree, what are you thinking of?03:09:51
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneI mean, you can put it there yourself, but you'd be mad to.03:10:00
@6aa4fd:tchncs.de6aa4fdso do you use environment variables instead03:10:18
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneI use agenix which stores secrets encrypted in the store.03:10:36

Show newer messages


Back to Room ListRoom Version: 6