Page MenuHomeDevCentral
Feed Advanced Search

Yesterday

dereckson added a comment to T2067: Deploy an OpenBSD server.

Why not port encrypt to FreeBSD?

Wed, Sep 10, 22:57 · Servers
dereckson added a comment to T2081: Deploy Snuffleupagus.

Support for PHP 8.4 is still there.

Wed, Sep 10, 22:56 · PHP 8.x support, Product evaluation, Servers, Alkane
dereckson closed T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship as Resolved by committing rOPSe5ec87dfe258: Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:51 · Servers
dereckson closed D3658: Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:51
dereckson committed rOPSe5ec87dfe258: Allow systemd-hostnamed to create socket when called from Varlink (authored by dereckson).
Allow systemd-hostnamed to create socket when called from Varlink
Wed, Sep 10, 22:51
dereckson accepted D3658: Allow systemd-hostnamed to create socket when called from Varlink.

Deployed on Dwellers, works like a charm.

Wed, Sep 10, 22:51
dereckson updated the diff for D3658: Allow systemd-hostnamed to create socket when called from Varlink.

Allow to remove the socket too

Wed, Sep 10, 22:40
dereckson planned changes to D3658: Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:34
dereckson closed T2115: Update Dwellers packages as Resolved.

Uninstalled certbot.
Pruned old Python 3 dependencies.
Updated EPEL repo to epel-release-10-6
Updated packages
Reinstalled certbot, now running under Python 3.12 too.

Wed, Sep 10, 22:30 · Servers
dereckson added a comment to T2115: Update Dwellers packages.

Just for information, working on T2113, I've first updated the packages non related to that conflict, so I had fresh packages for both systemd and selinux config.

Wed, Sep 10, 22:24 · Servers
dereckson added a comment to T2122: Package starship for EPEL.

https://snapcraft.io/starship - last update: 27 April 2023 - latest/edge

Wed, Sep 10, 22:10 · Servers
dereckson retitled D3658: Allow systemd-hostnamed to create socket when called from Varlink from Allow systemd-hostnamed to create socket when started by snap starinstalled with snap to Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:07
dereckson added a revision to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship: D3658: Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:06 · Servers
dereckson requested review of D3658: Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:06
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Was looking to offer a fix upstream, like read hostname from /proc/sys/kernel/hostname on Linux, but then I've realised this is an interaction issue with snap, starship, systemd and SELinux.

Wed, Sep 10, 22:03 · Servers
dereckson triaged T2122: Package starship for EPEL as Low priority.
Wed, Sep 10, 22:00 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Decreasing priority, as it only occurs with Starship.

Wed, Sep 10, 21:12 · Servers
dereckson renamed T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship from systemd-hostnamed service can't be launched - SELinux blocks it to systemd-hostnamed service can't be launched - SELinux blocks it - starship.
Wed, Sep 10, 21:11 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Normal behavior observed with the policy:

Wed, Sep 10, 21:10 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Still an error with last packages versions.

Wed, Sep 10, 21:09 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

audit2allow policy

Wed, Sep 10, 21:01 · Servers
dereckson updated the summary of D3657: Renew Vault intermediate authority certificate.
Wed, Sep 10, 19:43
dereckson added a comment to T2103: Upgrade servers to FreeBSD 14.3.

Bumping for 14.3, are still going on, it makes sense to target latest version

Wed, Sep 10, 19:41 · Servers
dereckson renamed T2103: Upgrade servers to FreeBSD 14.3 from Upgrade servers to FreeBSD 14.2 to Upgrade servers to FreeBSD 14.3.
Wed, Sep 10, 19:41 · Servers
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault HTTPS certificate automatically to Renew Vault web server certificate automatically.
Wed, Sep 10, 19:38 · security, Servers
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault HTTP certificate automatically to Renew Vault HTTPS certificate automatically.
Wed, Sep 10, 19:38 · security, Servers
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault certificate to Renew Vault HTTP certificate automatically.
Wed, Sep 10, 19:38 · security, Servers
dereckson updated the diff for D3657: Renew Vault intermediate authority certificate.

shellcheck

Wed, Sep 10, 19:36
dereckson requested review of D3657: Renew Vault intermediate authority certificate.
Wed, Sep 10, 19:34
dereckson added a revision to T2112: Renew Vault web server certificate automatically: D3657: Renew Vault intermediate authority certificate.
Wed, Sep 10, 19:34 · security, Servers
dereckson added a comment to T2112: Renew Vault web server certificate automatically.

First step is to create a script to renew all needed certificates:

Wed, Sep 10, 19:31 · security, Servers
dereckson renamed T2117: Unexpected reboot of docker-002 from Unexpeted reboot of docker-002 to Unexpected reboot of docker-002.
Wed, Sep 10, 19:28 · Nasqueron Operations Squad
dereckson closed T2111: Bump dependencies for API servers log PHP version, a subtask of T2015: Migrate remaining sites from ysul to Alkane, as Resolved.
Wed, Sep 10, 19:05 · Alkane
dereckson closed T2111: Bump dependencies for API servers log PHP version as Resolved.

Updated to PHPUnit 12.

Wed, Sep 10, 19:05 · Monitoring and reporting, Nasqueron API
dereckson closed D3656: Bump dependencies.
Wed, Sep 10, 19:04
dereckson committed rAPISRVLOGSd24ccd361b67: Bump dependencies (authored by dereckson).
Bump dependencies
Wed, Sep 10, 19:04
dereckson added a revision to T2111: Bump dependencies for API servers log PHP version: D3635: Bump dependencies.
Wed, Sep 10, 19:04 · Monitoring and reporting, Nasqueron API
dereckson added a task to D3635: Bump dependencies: T2111: Bump dependencies for API servers log PHP version.
Wed, Sep 10, 19:04
dereckson accepted D3656: Bump dependencies.
Wed, Sep 10, 19:03
dereckson added a revision to T2111: Bump dependencies for API servers log PHP version: D3656: Bump dependencies.
Wed, Sep 10, 19:03 · Monitoring and reporting, Nasqueron API
dereckson requested review of D3656: Bump dependencies.
Wed, Sep 10, 19:03
dereckson closed T2116: Drop of OCSP Service as Resolved.
Wed, Sep 10, 19:01 · Servers, Nasqueron Operations Squad
dereckson added a comment to T2116: Drop of OCSP Service.

Applied to Hervil, was missing there.

Wed, Sep 10, 19:01 · Servers, Nasqueron Operations Squad
dereckson closed D3638: Prune OCSP nginx configuration.
Wed, Sep 10, 18:59
dereckson committed rOPSac58e606182d: Prune OCSP nginx configuration (authored by dereckson).
Prune OCSP nginx configuration
Wed, Sep 10, 18:59
dereckson committed rOPS60c7955e1c0e: Allow to discover IPv6 gateway for Online servers (authored by dereckson).
Allow to discover IPv6 gateway for Online servers
Wed, Sep 10, 18:56
dereckson closed D3651: Allow to discover IPv6 gateway for Online servers.
Wed, Sep 10, 18:56
dereckson added a comment to D3655: Enable TCP Fast Open on FreeBSD for role dns.

Applied to dns-001

Wed, Sep 10, 18:55
dereckson closed D3655: Enable TCP Fast Open on FreeBSD for role dns.
Wed, Sep 10, 18:54
dereckson committed rOPS0df5b8cc669a: Enable TCP Fast Open on FreeBSD for role dns (authored by dereckson).
Enable TCP Fast Open on FreeBSD for role dns
Wed, Sep 10, 18:54
dereckson committed rQVR12ac9fc4c928: Allow to remove steerable saddle easily (authored by dereckson).
Allow to remove steerable saddle easily
Wed, Sep 10, 18:51