!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

115 Members
Another day, another cert renewal47 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
11 May 2025
@netpleb:matrix.orgnetplebregardless, thank you all here for your help!02:47:58
@netpleb:matrix.orgnetpleb *

I am not sure of what the root cause is (I am not an expert in this stuff and had to learn a bunch about systemd-network to even get this far), but all I know is that once I finally whittled it down to the smallest possible config that still worked correctly and then removed the LinkLocalAddressing = "no" line (thereby reverting to the default "yes" behavior), the container all of a sudden would timeout trying to reach wait-online (thereby triggering the original issue I was having).

Who knows. I am just happy it finally works! Now the container boots typically 11 seconds (including checking certs and such) instead of the multiple minutes it was taking before.

02:48:56
@netpleb:matrix.orgnetpleb *

I am not sure of what the root cause is (I am not an expert in this stuff and had to learn a bunch about systemd-network to even get this far), but all I know is that once I finally whittled it down to the smallest possible config that still worked correctly and then removed the LinkLocalAddressing = "no" line (thereby reverting to the default "yes" behavior), the container all of a sudden would timeout trying to reach wait-online, thereby triggering the original issue I was having.

Who knows though. I am just happy it finally works! Now the container boots typically 11 seconds (including checking certs and such) instead of the multiple minutes it was taking before.

02:49:18
15 May 2025
@m1cr0man:m1cr0man.comm1cr0manAny chance of seeing this one merged soonish? https://github.com/NixOS/nixpkgs/pull/37633420:30:23
16 May 2025
@hexa:lossy.networkhexa m1cr0man: in principle yes, but shouldn't the assert look at more options to to check domain && keyType || csr? 09:16:10
@hexa:lossy.networkhexa * m1cr0man: in principle yes, but shouldn't the assert look at more options to check domain && keyType || csr? 09:16:27
@hexa:lossy.networkhexabecause right now they're silently unused when a csr get configuredt09:17:04
@hexa:lossy.networkhexahm, domain is the key in the attrset, so maybe not09:25:17
@hexa:lossy.networkhexaand keyType always has a default09:25:21
@hexa:lossy.networkhexaso yeah, no09:25:26
@hexa:lossy.networkhexaalso can the acme team please just dissolve?09:26:41
@hexa:lossy.networkhexait is clearly m1cr0man who reviews everything09:27:43
@hexa:lossy.networkhexaand then someone active in this room merging the thing09:27:53
@hexa:lossy.networkhexa aanderse, Arian please reconsider your ACME team membership 09:28:17
@hexa:lossy.networkhexaalso https://github.com/orgs/NixOS/teams/acme has no maintainer role set09:33:38
@hexa:lossy.networkhexa m1cr0man: ask in #org_owners:nixos.org to for that role 09:33:59

Show newer messages


Back to Room ListRoom Version: 6