!RROtHmAaQIkiJzJZZE:nixos.org

NixOS Infrastructure

417 Members
Next Infra call: 2024-07-11, 18:00 CEST (UTC+2) | Infra operational issues backlog: https://github.com/orgs/NixOS/projects/52 | See #infra-alerts:nixos.org for real time alerts from Prometheus.130 Servers

Load older messages


SenderMessageTime
14 May 2026
@hexa:lossy.networkhexa
hetzner@intense-heron.mac.nixos.org |  3:28  up 48 days,  8:07, 0 users, load averages: 15.91 14.71 11.59
customer@eager-heisenberg.mac.nixos.org |  1:28  up 28 days, 13:38, 1 user, load averages: 7.24 8.43 8.04
customer@kind-lumiere.mac.nixos.org |  1:28  up 40 days,  9:47, 1 user, load averages: 4.58 6.38 6.41
hetzner@growing-jennet.mac.nixos.org |  3:28  up 20 days, 22:27, 0 users, load averages: 5.80 8.05 9.15
hetzner@enormous-catfish.mac.nixos.org |  3:28  up 40 days,  9:54, 0 users, load averages: 5.01 7.72 7.86
hetzner@sweeping-filly.mac.nixos.org |  3:28  up 40 days,  9:59, 0 users, load averages: 3.97 5.49 6.28
hetzner@maximum-snail.mac.nixos.org |  3:28  up 40 days,  9:55, 0 users, load averages: 8.13 7.53 7.29
root@norwegian-blue.mac.nixos.org |  3:28  up 2 days, 16:39, 1 user, load averages: 2.55 4.79 5.16
01:28:53
@tjni:matrix.org@tjni:matrix.org left the room.04:57:49
@vcunat:matrix.orgVladimír Čunát

Channels are blocked.

remote: Personal access tokens (classic) are forbidden from accessing this repository.

https://github.com/NixOS/org/issues/247#issuecomment-4447783439

09:38:48
@emilazy:matrix.orgemilyI did ping infra team on that issue weeks ago after doing a brief review myself 😅13:32:02
@emilazy:matrix.orgemilywe should probably roll back for now until the uses can be fixed13:32:15
@emilazy:matrix.orgemilythe channel scripts should be using a GitHub app like CI/rfc39/etc. do, most likely13:33:40
@emilazy:matrix.orgemilyIIRC it looked to me like the channel scripts used an SSH key for the Git push btw, what is the token in question used for?13:53:32
@vcunat:matrix.orgVladimír ČunátWell, I did not know this stuff. Just tried to diagnose the issue quickly.14:22:55
@vcunat:matrix.orgVladimír Čunát

Which pointed me to

GIT_DIR=$dir git config credential.helper 'store --file=${config.age.secrets.hydra-mirror-git-credentials.path}'
14:37:47
@hexa:lossy.networkhexathis is easily fixed14:50:56
@hexa:lossy.networkhexawe'll go for an ssh key this time, I think14:56:06
@emilazy:matrix.orgemilyyeah, making it use an app is probably good for the long term to scope the permissions further but SSH key will at least restrict it down to Git ops15:14:48
@emilazy:matrix.orgemilysorry for missing that when looking through the infra repo15:15:18
@emilazy:matrix.orgemilyI'll look through the other reports in more detail later15:16:28
@emilazy:matrix.orgemilybut I guess this was the only thing noticed for official infra?15:16:38
@hexa:lossy.networkhexaI didn't check, because I assumed you did15:18:12
@hexa:lossy.networkhexabut no biggie15:18:15
@hexa:lossy.networkhexaI'll check the rest of infra in a bit15:18:30
@emilazy:matrix.orgemilyI did15:28:51
@emilazy:matrix.orgemilyI listed my findings in the original issue15:29:03
@emilazy:matrix.orgemilybut pinged because it seemed possible I missed something since I'm not super savvy with the infra repo and don't have access to the secrets to see what format they take15:29:33
@emilazy:matrix.orgemilythe secret had Hydra in the name and I checked that the Hydra code was doing it right (with other Hydra secrets I guess). didn't correlate it with the channel scripts that looked like they'd just be using an SSH key15:30:35
@hexa:lossy.networkhexainfra call in 30m15:31:24
@hexa:lossy.networkhexano worries, emily15:31:49
@hexa:lossy.networkhexahttps://github.com/NixOS/infra/pull/103315:33:55
@hexa:lossy.networkhexaat least the git* secrets look clean15:45:48
@hexa:lossy.networkhexathey're not random pats15:46:00
@hexa:lossy.networkhexahttps://meet.cccda.de/nix-osin-fra15:53:25
@hexa:lossy.networkhexa We enabled Intelligent Tiering on the cache.nixos.org S3 bucket. The idea is that we'll save money by moving older objects to lower storing tiers "intelligently". We'll check back in a month to evaluate the update cost structure. 16:47:51
@hexa:lossy.networkhexaRedacted or Malformed Event16:48:01

Show newer messages


Back to Room ListRoom Version: 6