!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

393 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.121 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
5 Jan 2025
@hexa:lossy.networkhexalooking at curl, wget and most of all scrapy03:07:20
@hexa:lossy.networkhexawhen hydra-server gets busy we don't get any metrics any more from it03:07:47
@adam:robins.wtf@adam:robins.wtf Is it possible to put Hydra behind the Fastly cache 11:58:08
@adam:robins.wtf@adam:robins.wtf Would that help here? 11:58:26
@emilazy:matrix.orgemilymany pages seem too dynamic for that?14:03:07
@emilazy:matrix.orgemily(the expensive ones, I'd assume)14:03:12
@adam:robins.wtf@adam:robins.wtfyeah i guess it depends on what they're scraping14:55:50
@k900:0upti.meK900They're not scraping anything 14:57:51
@adam:robins.wtf@adam:robins.wtfthen what is happening? because hexa said "people who scrape hydra"15:01:08
@hexa:lossy.networkhexathere are gaps in our graphs on prometheus, and when that happens I also can't reach h.n.o.15:03:13
@hexa:lossy.networkhexaI browse the access.log, and yes, there are some high frequency scrapers in there15:03:33
@hexa:lossy.networkhexawe could probably evaluate access logs besser15:03:48
@hexa:lossy.networkhexa
Hits      h% Vis.     v% Tx. Amount Data
18111 20.20%    4  0.05% 763.06 MiB 2a01:4f9:3070:15e0::1  (pluto.nixos.org)
16250 18.13%    1  0.01%   1.69 GiB 99.245. (random rogers customer)
 4059  4.53%    1  0.01%   1.91 MiB 34.44 (google cloud)
 2683  2.99%    2  0.02%   2.00 MiB 81.200
15:06:18
@hexa:lossy.networkhexathis is the last 75.5h15:07:32
@hexa:lossy.networkhexaestimated from the prometheus scraper, who runs every 15s15:07:51
@hexa:lossy.networkhexa * 15:13:29
@raitobezarius:matrix.orgraitobezariusreaction has something to block on the L3 level the scrapers15:19:37
@raitobezarius:matrix.orgraitobezarius https://reaction.ppom.me/filters/ai-crawlers.html 15:20:39
@k900:0upti.meK900Oh sorry I meant Fastly 15:21:47
@adam:robins.wtf@adam:robins.wtfthat makes more sense :) 15:22:36
@adam:robins.wtf@adam:robins.wtfi didn't mean to imply fastly was scraping us. i was just wondering if we could leverage fastly to protect hydra15:22:55
@hexa:lossy.networkhexatbh, the hydra-server needs to be more robust16:29:19
@hexa:lossy.networkhexait can't just lock up16:29:24
@vcunat:matrix.orgVladimír ČunátMaybe we should separate the external-facing web somehow.16:31:53
@emilazy:matrix.orgemilythe web UI runs on the same machine that holds the signing key, right?16:33:26
@hexa:lossy.networkhexayes16:37:59
@emilazy:matrix.orgemilyscary16:39:16
@emilazy:matrix.orgemilysigning key rotation when16:39:28
@hexa:lossy.networkhexadifferent user16:39:33
@raitobezarius:matrix.orgraitobezariusthe power of unix perm isolation16:39:50

Show newer messages


Back to Room ListRoom Version: 6