Page MenuHomeDevCentral
Feed Advanced Search

Oct 16 2024

dereckson added a revision to T1858: Ensure salt-minion is up at boot time: D3091: Enable Salt minion server on FreeBSD nodes.
Oct 16 2024, 18:44 · Salt, Servers, Operations sprints (Ignite Alkane Propulsion)

Oct 14 2024

dereckson added a comment to T2039: Automate Poudriere deployment.

Poudriere seems stable for ports development.

Oct 14 2024, 00:34 · Servers
dereckson added a comment to T1991: Context has again been lost on /var/log/www.

Same thing for Dwellers:

Oct 14 2024, 00:23 · upstream, Regression, Servers, Salt
dereckson updated the task description for T2044: Upgrade FreeBSD servers still on 14.0 to 14.1.
Oct 14 2024, 00:01 · Servers

Oct 13 2024

dereckson updated the task description for T2044: Upgrade FreeBSD servers still on 14.0 to 14.1.
Oct 13 2024, 23:59 · Servers
dereckson added a revision to T1853: Setup IPv6 connectivity on web-001: D3519: Use prefixlen 56 for OVH IPv6.
Oct 13 2024, 23:52 · IPv6, Operations sprints (Ignite Alkane Propulsion), Alkane, Servers, User-Dereckson
dereckson added a comment to T2044: Upgrade FreeBSD servers still on 14.0 to 14.1.

Issues with web-001

Oct 13 2024, 20:32 · Servers
dereckson merged task T1981: Upgrade to FreeBSD 14.1 into T2044: Upgrade FreeBSD servers still on 14.0 to 14.1.
Oct 13 2024, 20:30 · Servers
dereckson merged T1981: Upgrade to FreeBSD 14.1 into T2044: Upgrade FreeBSD servers still on 14.0 to 14.1.
Oct 13 2024, 20:30 · Servers
dereckson closed T2054: Support IPv6 on web-001 as Resolved.

We can use this OVH IP, it's stable enough now.

Oct 13 2024, 12:45 · Alkane, Servers, IPv6
dereckson claimed T2054: Support IPv6 on web-001.

DNS records have been updated:

Oct 13 2024, 12:43 · Alkane, Servers, IPv6
dereckson updated the task description for T2054: Support IPv6 on web-001.
Oct 13 2024, 12:43 · Alkane, Servers, IPv6
dereckson closed T1904: Update WindRiver information as Resolved by committing rHOMEbbd0d7e90ef5: Update information from WindRiver.
Oct 13 2024, 12:20 · Servers
dereckson added a revision to T2017: Install WindRiver replacement server: D3516: Update information from WindRiver.
Oct 13 2024, 12:20 · Servers
dereckson added a revision to T1904: Update WindRiver information: D3516: Update information from WindRiver.
Oct 13 2024, 12:20 · Servers
dereckson added a subtask for T2054: Support IPv6 on web-001: T1243: Deploy Varnish.
Oct 13 2024, 12:17 · Alkane, Servers, IPv6
dereckson added a parent task for T1243: Deploy Varnish: T2054: Support IPv6 on web-001.
Oct 13 2024, 12:17 · Servers
dereckson updated the task description for T1243: Deploy Varnish.
Oct 13 2024, 12:17 · Servers
dereckson added a comment to T1243: Deploy Varnish.

2001:470:1f13:9e1:0:cac:7e:1 (cac:7e for cache, cac:7e:1 for cache #1).

Oct 13 2024, 12:16 · Servers
dereckson added projects to T2054: Support IPv6 on web-001: Servers, Alkane.
Oct 13 2024, 12:15 · Alkane, Servers, IPv6
dereckson renamed T1243: Deploy Varnish from Deploy Varnish on webserver-legacy to Deploy Varnish.
Oct 13 2024, 12:09 · Servers
dereckson closed T1742: Fix network unit for Ysul as Wontfix.

During WindRiver reprovisioning, the network unit behaved correctly.

Oct 13 2024, 12:07 · Salt, Servers
dereckson moved T169: Ensure /root/setup-network.service is installed and works correctly on Dwellers from Backlog to Servers on the IPv6 board.
Oct 13 2024, 12:04 · IPv6, Drake network, Servers
dereckson moved T1735: Investigate why IPv6 connections fail to Dwellers port 443 from Backlog to Servers on the IPv6 board.
Oct 13 2024, 12:04 · IPv6, Servers
dereckson moved T1169: Postfix on ysul.nasqueron.org doesn't listen on IPv6 from Backlog to Apps on the IPv6 board.
Oct 13 2024, 12:04 · Operations sprints (Ignite Alkane Propulsion), Servers, IPv6
dereckson moved T1861: Configure static IPv6 on WindRiver from Backlog to Knowledge sharing is needed on the IPv6 board.
Oct 13 2024, 12:04 · security, Servers, IPv6
dereckson added a comment to T1861: Configure static IPv6 on WindRiver.

So, to get routing back:

Oct 13 2024, 12:03 · security, Servers, IPv6
dereckson added a revision to T2017: Install WindRiver replacement server: D3515: Update gateway for IPv6 routing on WindRiver.
Oct 13 2024, 11:58 · Servers
dereckson added a comment to P363 dhclient6 negociation.

To make it works:

Oct 13 2024, 11:31 · Servers
dereckson added a comment to P363 dhclient6 negociation.

igb0 is the right target interface

Oct 13 2024, 11:10 · Servers
dereckson created P363 dhclient6 negociation.
Oct 13 2024, 11:08 · Servers

Oct 12 2024

dereckson added a comment to T2019: Supersede portsnap by a Git repository.

Salt deployment of /usr/ports as Git repository done.

Oct 12 2024, 21:40 · Servers
dereckson updated the task description for T2017: Install WindRiver replacement server.
Oct 12 2024, 21:38 · Servers
dereckson moved T2044: Upgrade FreeBSD servers still on 14.0 to 14.1 from Backlog to Working on on the Servers board.
Oct 12 2024, 21:36 · Servers
dereckson added a comment to T2044: Upgrade FreeBSD servers still on 14.0 to 14.1.

Taking db-B-001 and web-001.

Oct 12 2024, 21:32 · Servers
dereckson moved T1850: Move packages from Ysul to WindRiver from Backlog - Alkane/Webservers to Working on on the Operations sprints (Ignite Alkane Propulsion) board.
Oct 12 2024, 10:22 · Operations sprints (Ignite Alkane Propulsion), Alkane, Servers
dereckson moved T1599: Install TLS wildcard certificates for nginx fallback vhost from Backlog to Backlog - Alkane/Webservers on the Operations sprints (Ignite Alkane Propulsion) board.
Oct 12 2024, 10:22 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson moved T1765: SELinux context is missing for /etc/nginx configuration files from Backlog - Docker to Backlog - Alkane/Webservers on the Operations sprints (Ignite Alkane Propulsion) board.
Oct 12 2024, 10:21 · Operations sprints (Ignite Alkane Propulsion), Salt, security, Nasqueron Docker deployment squad, Servers
dereckson moved T1610: Deploy Jitsi Meet instance from Working on to Backlog - Docker on the Operations sprints (Ignite Alkane Propulsion) board.
Oct 12 2024, 10:20 · Operations sprints (Ignite Alkane Propulsion), Wolfplex migration, XMPP, Nasqueron Docker deployment squad, Servers, Product evaluation
dereckson moved T503: Provide a way to generate the first login a password, or at account creation from Backlog to Nasqueron Operations SIG on the discussion board.
Oct 12 2024, 10:19 · discussion, Servers
dereckson edited projects for T503: Provide a way to generate the first login a password, or at account creation, added: discussion; removed Dæghrefn.

Removing TC2 as not used anymore for accounts creation.

Oct 12 2024, 10:18 · discussion, Servers
dereckson added a comment to T503: Provide a way to generate the first login a password, or at account creation.

This is still an issue for accounts created with Salt.

Oct 12 2024, 10:18 · discussion, Servers
dereckson closed T619: Allow to control from TC2 the Docker engine as Wontfix.

Not sure of the current benefit to use TC2.

Oct 12 2024, 10:16 · Operations sprints (Operations sprint 1), security, Nasqueron Docker deployment squad, Servers, Dæghrefn
dereckson moved T1325: Consolidate webserver roles from Backlog to Backlog - Alkane/Webservers on the Operations sprints (Ignite Alkane Propulsion) board.
Oct 12 2024, 10:11 · Operations sprints (Ignite Alkane Propulsion), Technical debt, Salt, Servers
dereckson edited projects for T1325: Consolidate webserver roles, added: Operations sprints (Ignite Alkane Propulsion); removed Operations sprints (The Dreadnought will produce new officers).
Oct 12 2024, 10:11 · Operations sprints (Ignite Alkane Propulsion), Technical debt, Salt, Servers
dereckson added a comment to T1325: Consolidate webserver roles.

Consolidation recent works occurred at T1828 to further unify nginx configurations.

Oct 12 2024, 10:11 · Operations sprints (Ignite Alkane Propulsion), Technical debt, Salt, Servers
dereckson moved T1620: Decide if we keep staging repository from Backlog to Nasqueron Operations SIG on the discussion board.
Oct 12 2024, 10:04 · discussion, documentation, Salt, Operations sprints (Consolidate them all), Servers
dereckson added a project to T1620: Decide if we keep staging repository: discussion.
Oct 12 2024, 10:04 · discussion, documentation, Salt, Operations sprints (Consolidate them all), Servers
dereckson updated subscribers of T1620: Decide if we keep staging repository.
Oct 12 2024, 10:04 · discussion, documentation, Salt, Operations sprints (Consolidate them all), Servers
dereckson added a comment to T1620: Decide if we keep staging repository.

Some context about this staging repository:

Oct 12 2024, 10:04 · discussion, documentation, Salt, Operations sprints (Consolidate them all), Servers
dereckson added a comment to T1600: Automate staging commit craft.

[Moved to T1620]

Oct 12 2024, 10:01 · documentation, good-first-issue, Salt, Operations sprints (Consolidate them all), Servers
dereckson moved T1602: Provision ACME DNS credentials for core domains on each servers from Backlog to Backlog - Alkane/Webservers on the Operations sprints (Ignite Alkane Propulsion) board.
Oct 12 2024, 09:48 · Operations sprints (Ignite Alkane Propulsion), security, Servers
dereckson edited projects for T1602: Provision ACME DNS credentials for core domains on each servers, added: Operations sprints (Ignite Alkane Propulsion); removed Operations sprints (Consolidate them all).
Oct 12 2024, 09:47 · Operations sprints (Ignite Alkane Propulsion), security, Servers
dereckson moved T1602: Provision ACME DNS credentials for core domains on each servers from Pending review to Not for this sprint on the Operations sprints (Consolidate them all) board.
Oct 12 2024, 09:47 · Operations sprints (Ignite Alkane Propulsion), security, Servers
dereckson added a comment to T1602: Provision ACME DNS credentials for core domains on each servers.

This is still needed for acme.sh if we want to provision different *.nasqueron.org certificates on different servers.

Oct 12 2024, 09:47 · Operations sprints (Ignite Alkane Propulsion), security, Servers
dereckson moved T2043: Switch to acme.sh instead of certbot from Backlog to Working on on the Operations sprints (Ignite Alkane Propulsion) board.
Oct 12 2024, 09:45 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson added a project to T2043: Switch to acme.sh instead of certbot: Operations sprints (Ignite Alkane Propulsion).
Oct 12 2024, 09:45 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson added a comment to T1599: Install TLS wildcard certificates for nginx fallback vhost.

Really blocked by T1602 if we want to have this on any server without copying private keys around.

Oct 12 2024, 09:45 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson removed a subtask for T2043: Switch to acme.sh instead of certbot: T1599: Install TLS wildcard certificates for nginx fallback vhost.
Oct 12 2024, 09:44 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson edited parent tasks for T1599: Install TLS wildcard certificates for nginx fallback vhost, added: T1602: Provision ACME DNS credentials for core domains on each servers; removed: T2043: Switch to acme.sh instead of certbot.
Oct 12 2024, 09:44 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson added a subtask for T1602: Provision ACME DNS credentials for core domains on each servers: T1599: Install TLS wildcard certificates for nginx fallback vhost.
Oct 12 2024, 09:44 · Operations sprints (Ignite Alkane Propulsion), security, Servers
dereckson added a parent task for T1599: Install TLS wildcard certificates for nginx fallback vhost: T2043: Switch to acme.sh instead of certbot.
Oct 12 2024, 09:44 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson added a subtask for T2043: Switch to acme.sh instead of certbot: T1599: Install TLS wildcard certificates for nginx fallback vhost.
Oct 12 2024, 09:44 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson edited projects for T1599: Install TLS wildcard certificates for nginx fallback vhost, added: Operations sprints (Ignite Alkane Propulsion); removed Operations sprints (Consolidate them all).
Oct 12 2024, 09:43 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson closed T1341: Document what to do if php-fpm lost pid files as Resolved.
Oct 12 2024, 09:40 · PHP 8.x support, Operations sprints (Consolidate them all), documentation, PHP 7 deployment, Servers
dereckson added a revision to T1341: Document what to do if php-fpm lost pid files: D3512: Prune new rc service name php_fpm.
Oct 12 2024, 09:39 · PHP 8.x support, Operations sprints (Consolidate them all), documentation, PHP 7 deployment, Servers
dereckson triaged T1341: Document what to do if php-fpm lost pid files as Normal priority.

The problem is somewhat fixed by two things:

Oct 12 2024, 09:36 · PHP 8.x support, Operations sprints (Consolidate them all), documentation, PHP 7 deployment, Servers
dereckson closed T1563: Declare MKV as video format in nginx configuration as Wontfix.

That's an issue for Chrome to report upstream.

Oct 12 2024, 09:26 · Operations sprints (Consolidate them all), Servers, Salt
dereckson moved T2037: Provide roll on devserver role from New port to Port published on the freebsd-port-wanted board.
Oct 12 2024, 09:14 · Servers, freebsd-port-wanted
dereckson moved T2046: Deploy Medusa on devserver role from New port to Port published on the freebsd-port-wanted board.
Oct 12 2024, 09:14 · upstream, freebsd-port-wanted, Vault, Servers
dereckson added a revision to T2046: Deploy Medusa on devserver role: D3508: Publish alkane, roll, phpfpm_exporter, medusa and salt-tower.
Oct 12 2024, 07:49 · upstream, freebsd-port-wanted, Vault, Servers
dereckson added a revision to T2037: Provide roll on devserver role: D3508: Publish alkane, roll, phpfpm_exporter, medusa and salt-tower.
Oct 12 2024, 07:49 · Servers, freebsd-port-wanted

Oct 10 2024

dereckson added a revision to T2039: Automate Poudriere deployment: D3504: Scrape ccache metrics.
Oct 10 2024, 22:02 · Servers

Oct 9 2024

dereckson closed T2048: Setup reverse DNS for 195.154.30.15 as Resolved.

Local cache is OK.

Oct 9 2024, 18:47 · Servers
dereckson lowered the priority of T2051: Can't renew TLS certificates verified through HTTP on docker engines from High to Normal.
Oct 9 2024, 18:45 · security, Nasqueron Docker deployment squad, Servers
dereckson updated the task description for T2051: Can't renew TLS certificates verified through HTTP on docker engines.
Oct 9 2024, 18:45 · security, Nasqueron Docker deployment squad, Servers
dereckson added a comment to T2051: Can't renew TLS certificates verified through HTTP on docker engines.

Salt SELinux module issue

Oct 9 2024, 18:45 · security, Nasqueron Docker deployment squad, Servers
dereckson updated the task description for T2051: Can't renew TLS certificates verified through HTTP on docker engines.
Oct 9 2024, 18:07 · security, Nasqueron Docker deployment squad, Servers
dereckson added a revision to T2051: Can't renew TLS certificates verified through HTTP on docker engines: D3501: Allow nginx to read /.well-known/acme-challenge.
Oct 9 2024, 17:48 · security, Nasqueron Docker deployment squad, Servers
dereckson moved T2051: Can't renew TLS certificates verified through HTTP on docker engines from Backlog to Pending review on the Servers board.
Oct 9 2024, 17:43 · security, Nasqueron Docker deployment squad, Servers
dereckson moved T2051: Can't renew TLS certificates verified through HTTP on docker engines from Backlog to Working on on the Nasqueron Docker deployment squad board.

SELinux context was the default for anything created under /var, which we didn't allow and aren't interested to allow for nginx.

Oct 9 2024, 17:43 · security, Nasqueron Docker deployment squad, Servers
dereckson triaged T2051: Can't renew TLS certificates verified through HTTP on docker engines as High priority.
Oct 9 2024, 16:02 · security, Nasqueron Docker deployment squad, Servers
dereckson created T2051: Can't renew TLS certificates verified through HTTP on docker engines.
Oct 9 2024, 16:01 · security, Nasqueron Docker deployment squad, Servers

Oct 8 2024

dereckson moved T1676: Serve Zed on webserver-alkane from In progress to Backlog on the User-Dereckson board.
Oct 8 2024, 00:46 · User-Dereckson, Servers, PHP 8.x support, Zed
dereckson moved T1937: Update FreeBSD packages Nasqueron repository from Backlog to Pending review on the Servers board.
Oct 8 2024, 00:46 · Servers, User-Dereckson
dereckson moved T1937: Update FreeBSD packages Nasqueron repository from Backlog to Code review / Peering on the User-Dereckson board.
Oct 8 2024, 00:46 · Servers, User-Dereckson
dereckson moved T1681: Publish schema.nasqueron.org from Next to Backlog on the User-Dereckson board.
Oct 8 2024, 00:45 · Schemas, Salt, User-Dereckson, Servers
dereckson moved T2049: Release api-exec from Backlog to Next on the User-Dereckson board.
Oct 8 2024, 00:45 · Nasqueron API, User-Dereckson, Servers
dereckson moved T2049: Release api-exec from Backlog to New ideas on the Nasqueron API board.
Oct 8 2024, 00:44 · Nasqueron API, User-Dereckson, Servers
dereckson added a project to T2049: Release api-exec: Nasqueron API.
Oct 8 2024, 00:44 · Nasqueron API, User-Dereckson, Servers
dereckson triaged T2049: Release api-exec as Low priority.
Oct 8 2024, 00:44 · Nasqueron API, User-Dereckson, Servers
dereckson moved T2039: Automate Poudriere deployment from Backlog to Pending review on the Servers board.
Oct 8 2024, 00:32 · Servers
dereckson triaged T2043: Switch to acme.sh instead of certbot as High priority.
Oct 8 2024, 00:15 · Operations sprints (Ignite Alkane Propulsion), Servers
dereckson added a comment to T2048: Setup reverse DNS for 195.154.30.15.

Authoritative DNS

Oct 8 2024, 00:15 · Servers
dereckson added a revision to T2037: Provide roll on devserver role: D3499: Install vault-medusa and roll on devserver role.
Oct 8 2024, 00:11 · Servers, freebsd-port-wanted
dereckson added a revision to T2046: Deploy Medusa on devserver role: D3499: Install vault-medusa and roll on devserver role.
Oct 8 2024, 00:11 · upstream, freebsd-port-wanted, Vault, Servers
dereckson added a revision to T1937: Update FreeBSD packages Nasqueron repository : D3498: Support several ABI for FreeBSD packages repository.
Oct 8 2024, 00:05 · Servers, User-Dereckson

Oct 7 2024

dereckson added a revision to T1850: Move packages from Ysul to WindRiver: D3497: Serve packages.nasqueron.org from WindRiver.
Oct 7 2024, 23:26 · Operations sprints (Ignite Alkane Propulsion), Alkane, Servers
dereckson added a comment to T1850: Move packages from Ysul to WindRiver.

DNS change

Oct 7 2024, 23:20 · Operations sprints (Ignite Alkane Propulsion), Alkane, Servers
dereckson added a comment to T1850: Move packages from Ysul to WindRiver.

For RHEL 8, we probably only need docker-processes, but roles/paas-docker/devel refers dive too.

Oct 7 2024, 22:49 · Operations sprints (Ignite Alkane Propulsion), Alkane, Servers