Page MenuHomeDevCentral

ServersFolder
ActivePublic

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

Anything related to the Nasqueron server infrastructure at IaaS or PaaS levels.

Recent Activity

Today

dereckson renamed T2125: Review Vault policies from vault_secrets_by_role from Review Vault policies to Review Vault policies from vault_secrets_by_role.
Sun, Sep 14, 00:58 · Nasqueron Docker deployment squad, Servers
dereckson triaged T2125: Review Vault policies from vault_secrets_by_role as High priority.
Sun, Sep 14, 00:57 · Nasqueron Docker deployment squad, Servers

Fri, Sep 12

dereckson moved T2123: Fix tests for operations repository from Backlog to Ops on the Technical debt board.
Fri, Sep 12, 17:51 · Technical debt, Servers
dereckson moved T2123: Fix tests for operations repository from Backlog to Pending review on the Servers board.
Fri, Sep 12, 17:51 · Technical debt, Servers
dereckson added a comment to T2123: Fix tests for operations repository.

Tests fix commits will be aggregated in datacube T2123-improve-tests-suite branch, so we can have a look of what's remaining to fix.

Fri, Sep 12, 17:50 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3665: Prune unused webserver-content index generator.
Fri, Sep 12, 17:46 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3664: Deploy the monitoring Vault policy.
Fri, Sep 12, 17:19 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3663: Fix node.resolve_network tests.
Fri, Sep 12, 17:15 · Technical debt, Servers

Thu, Sep 11

dereckson added a revision to T2123: Fix tests for operations repository: D3662: Read flatter docker_networks pillar.
Thu, Sep 11, 23:56 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3661: Avoid unittest deprecated aliases.
Thu, Sep 11, 23:09 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3660: Fix docker_containers app_port/host test.
Thu, Sep 11, 22:58 · Technical debt, Servers
dereckson added a comment to T2123: Fix tests for operations repository.

Tests commits will be aggregates in datacube T2123-improve-tests-suite branch, so we can have a look of what's remaining to fix.

Thu, Sep 11, 22:18 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3659: Handle ssh_keys_by_forest and everywhere_tasks in pillar users test.
Thu, Sep 11, 22:16 · Technical debt, Servers
dereckson updated subscribers of T2123: Fix tests for operations repository.

Going to take this, as I wrote the tests suite, @DorianWinty will review.

Thu, Sep 11, 22:15 · Technical debt, Servers
dereckson triaged T2123: Fix tests for operations repository as High priority.
Thu, Sep 11, 22:15 · Technical debt, Servers

Wed, Sep 10

dereckson added a comment to T2067: Deploy an OpenBSD server.

Why not port encrypt to FreeBSD?

Wed, Sep 10, 22:57 · Servers
dereckson added a comment to T2081: Deploy Snuffleupagus.

Support for PHP 8.4 is still there.

Wed, Sep 10, 22:56 · PHP 8.x support, Product evaluation, Servers, Alkane
dereckson closed T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship as Resolved by committing rOPSe5ec87dfe258: Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:51 · Servers
dereckson closed T2115: Update Dwellers packages as Resolved.

Uninstalled certbot.
Pruned old Python 3 dependencies.
Updated EPEL repo to epel-release-10-6
Updated packages
Reinstalled certbot, now running under Python 3.12 too.

Wed, Sep 10, 22:30 · Servers
dereckson added a comment to T2115: Update Dwellers packages.

Just for information, working on T2113, I've first updated the packages non related to that conflict, so I had fresh packages for both systemd and selinux config.

Wed, Sep 10, 22:24 · Servers
dereckson added a comment to T2122: Package starship for EPEL.

https://snapcraft.io/starship - last update: 27 April 2023 - latest/edge

Wed, Sep 10, 22:10 · Servers
dereckson added a revision to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship: D3658: Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:06 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Was looking to offer a fix upstream, like read hostname from /proc/sys/kernel/hostname on Linux, but then I've realised this is an interaction issue with snap, starship, systemd and SELinux.

Wed, Sep 10, 22:03 · Servers
dereckson triaged T2122: Package starship for EPEL as Low priority.
Wed, Sep 10, 22:00 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Decreasing priority, as it only occurs with Starship.

Wed, Sep 10, 21:12 · Servers
dereckson renamed T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship from systemd-hostnamed service can't be launched - SELinux blocks it to systemd-hostnamed service can't be launched - SELinux blocks it - starship.
Wed, Sep 10, 21:11 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Normal behavior observed with the policy:

Wed, Sep 10, 21:10 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Still an error with last packages versions.

Wed, Sep 10, 21:09 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

audit2allow policy

Wed, Sep 10, 21:01 · Servers
dereckson added a comment to T2103: Upgrade servers to FreeBSD 14.3.

Bumping for 14.3, are still going on, it makes sense to target latest version

Wed, Sep 10, 19:41 · Servers
dereckson renamed T2103: Upgrade servers to FreeBSD 14.3 from Upgrade servers to FreeBSD 14.2 to Upgrade servers to FreeBSD 14.3.
Wed, Sep 10, 19:41 · Servers
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault HTTPS certificate automatically to Renew Vault web server certificate automatically.
Wed, Sep 10, 19:38 · security, Servers
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault HTTP certificate automatically to Renew Vault HTTPS certificate automatically.
Wed, Sep 10, 19:38 · security, Servers
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault certificate to Renew Vault HTTP certificate automatically.
Wed, Sep 10, 19:38 · security, Servers
dereckson added a revision to T2112: Renew Vault web server certificate automatically: D3657: Renew Vault intermediate authority certificate.
Wed, Sep 10, 19:34 · security, Servers
dereckson added a comment to T2112: Renew Vault web server certificate automatically.

First step is to create a script to renew all needed certificates:

Wed, Sep 10, 19:31 · security, Servers
dereckson closed T2116: Drop of OCSP Service as Resolved.
Wed, Sep 10, 19:01 · Servers, Nasqueron Operations Squad
dereckson added a comment to T2116: Drop of OCSP Service.

Applied to Hervil, was missing there.

Wed, Sep 10, 19:01 · Servers, Nasqueron Operations Squad

Tue, Sep 2

DorianWinty added a revision to T1217: Host our DNS servers: D3654: Define nasqueron.org DNS zone.
Tue, Sep 2, 20:41 · Servers
DorianWinty added a revision to T1217: Host our DNS servers: D3652: Define testdom for ook.space to test on windriver dns.
Tue, Sep 2, 17:52 · Servers
dereckson edited P372 DNS - Raw AXFR output - nasqueron.org.
Tue, Sep 2, 17:03 · DNS, Servers

Sun, Aug 31

dereckson closed T2120: Don't allow infinite grow of MariaDB binary log as Resolved by committing rOPS9e78009934a7: Sets the MariaDB binary log expiration.
Sun, Aug 31, 15:48 · DBA, Servers
dereckson added a comment to T2017: Install WindRiver replacement server.

Find more easily the gateway

Sun, Aug 31, 15:31 · Servers

Jul 27 2025

dereckson added a revision to T2120: Don't allow infinite grow of MariaDB binary log: D3645: Sets the MariaDB binary log expiration.
Jul 27 2025, 15:51 · DBA, Servers
dereckson added a comment to T2120: Don't allow infinite grow of MariaDB binary log.

For reference, the configuration contains max_binlog_size = 1000M. This only affects the maximal size of ONE log file, but it can create as many as needed.

Jul 27 2025, 15:47 · DBA, Servers
dereckson added a comment to T2120: Don't allow infinite grow of MariaDB binary log.

For dbserver-mysql role, configuration is located at roles/dbserver-mysql/mysql-server/files/conf.d/server.cnf

Jul 27 2025, 15:45 · DBA, Servers
dereckson triaged T2120: Don't allow infinite grow of MariaDB binary log as High priority.
Jul 27 2025, 15:40 · DBA, Servers

Jun 12 2025

DorianWinty added a revision to T1217: Host our DNS servers: D3641: Get public IPV6 from servers.
Jun 12 2025, 19:06 · Servers

Jun 11 2025

DorianWinty added a revision to T1217: Host our DNS servers: D3640: Deploy KnotDNS on dns server.
Jun 11 2025, 17:37 · Servers

Jun 3 2025

dereckson closed T2118: Load pefs module automatically on devserver role on boot as Resolved by committing rOPS5f9cc5dbd472: Load pefs module at boot time.
Jun 3 2025, 18:38 · Servers