This tag identifies security issue.
Details
Yesterday
Cohort 1. Users with access only to nasqueron-dev-docker but not to ops.
A. Keep access - currently maintaining PHP images.
A. Keep access
Sat, Aug 15
Jul 4 2026
- Updated to Debian 12, then 13
- /usr merge process done manually, with the help of statically compiled busybox
- reinstalled libwebp6_0.6.1-2.1+deb11u2_amd64.deb to avoid to update PHP
Currently runs under Debian 11, target would be Debian 13.
Jul 2 2026
Jun 14 2026
Our Salt state core/sshd does not set PubkeyAcceptedAlgorithms, so ssh-rsa (SHA-1) is blocked by default — this has been the case since OpenSSH 8.8 (released 2021-09-26, see https://www.openssh.com/txt/release-8.8).
Apr 22 2026
The error occured is (T2315) :
Apr 3 2026
Mar 25 2026
Mar 23 2026
With Salt, sudo files content are now managed from rOPS.
Mar 22 2026
Next: configure DNS records
Mar 21 2026
Will need to be revisited when we switch to acme.sh.
Mar 20 2026
Feb 5 2026
Patched it live.
Feb 3 2026
Nov 10 2025
Bruteforce attack scenario possible, so we're only interested by usernames defined in users.sls, not by "root" (can't login by SSH) or generic accounts like "docker" (doesn't exist):
