Page MenuHomeDevCentral
Feed Advanced Search

Fri, Apr 3

dereckson added a parent task for T2293: viperserv.nasqueron.org IP on WindRiver was missing after reboot: T2296: Bind correctly to proper IPv6.
Fri, Apr 3, 18:15 · Salt, Servers, Dæghrefn
dereckson added a comment to T2296: Bind correctly to proper IPv6.

Ideal configuration is vhost6 + IP address.

Fri, Apr 3, 18:14 · IPv6, Dæghrefn
dereckson updated the diff for D4041: Remove network_utils.can_directly_be_discovered.

-ipaddress

Fri, Apr 3, 18:08
dereckson requested review of D4041: Remove network_utils.can_directly_be_discovered.
Fri, Apr 3, 18:08
dereckson added a comment to D4039: Don't use keyword add to declare an IPv6 alias on FreeBSD.
WindRiver
$ salt-call --local state.apply roles/core/network/ipv6
local:
----------
          ID: /etc/rc.conf.d/netif/ipv6_igb0
    Function: file.managed
      Result: True
     Comment: File /etc/rc.conf.d/netif/ipv6_igb0 updated
     Started: 18:02:28.820428
    Duration: 14.352 ms
     Changes:   
              ----------
              diff:
                  --- 
                  +++ 
                  @@ -14,5 +14,5 @@
                   #   </auto-generated>
Fri, Apr 3, 18:03
dereckson added a comment to D4040: Simplify IPv6 routing for FreeBSD.
WindRiver
$ salt-call --local state.apply roles/core/network/ipv6 
local:
----------
          ID: /etc/rc.conf.d/netif/ipv6_igb0
    Function: file.managed
      Result: True
     Comment: File /etc/rc.conf.d/netif/ipv6_igb0 is in the correct state
     Started: 17:54:13.510501
    Duration: 19.632 ms
     Changes:   
----------
          ID: /etc/rc.conf.d/routing/ipv6
    Function: file.managed
      Result: True
     Comment: File /etc/rc.conf.d/routing/ipv6 updated
     Started: 17:54:13.530295
    Duration: 11.486 ms
     Changes:   
              ----------
              diff:
                  --- 
                  +++ 
                  @@ -14,6 +14,4 @@
                   #   </auto-generated>
Fri, Apr 3, 18:00
dereckson requested review of D4040: Simplify IPv6 routing for FreeBSD.
Fri, Apr 3, 17:59
dereckson added a revision to T2295: IPv6 route should include interface on FreeBSD: D4040: Simplify IPv6 routing for FreeBSD.
Fri, Apr 3, 17:59 · Salt, IPv6, Dæghrefn
dereckson renamed T2293: viperserv.nasqueron.org IP on WindRiver was missing after reboot from Add viperserv.nasqueron.org IP on WindRiver to viperserv.nasqueron.org IP on WindRiver was missing after reboot.
Fri, Apr 3, 17:47 · Salt, Servers, Dæghrefn
dereckson moved T2292: Create syslog configuration for CARP from Backlog to Working on on the Servers board.
Fri, Apr 3, 17:44 · Servers, Secure HA tunnels
dereckson triaged T2296: Bind correctly to proper IPv6 as Normal priority.
Fri, Apr 3, 17:42 · IPv6, Dæghrefn
dereckson moved T2295: IPv6 route should include interface on FreeBSD from Backlog to Bugs on the Dæghrefn board.
Fri, Apr 3, 17:41 · Salt, IPv6, Dæghrefn
dereckson updated the test plan for D4039: Don't use keyword add to declare an IPv6 alias on FreeBSD.
Fri, Apr 3, 17:40
dereckson requested review of D4039: Don't use keyword add to declare an IPv6 alias on FreeBSD.
Fri, Apr 3, 17:39
dereckson added a revision to T2293: viperserv.nasqueron.org IP on WindRiver was missing after reboot: D4039: Don't use keyword add to declare an IPv6 alias on FreeBSD.
Fri, Apr 3, 17:39 · Salt, Servers, Dæghrefn
dereckson moved T2293: viperserv.nasqueron.org IP on WindRiver was missing after reboot from Backlog to Servers config on the Salt board.
Fri, Apr 3, 17:37 · Salt, Servers, Dæghrefn
dereckson added a project to T2293: viperserv.nasqueron.org IP on WindRiver was missing after reboot: Salt.
Fri, Apr 3, 17:37 · Salt, Servers, Dæghrefn
dereckson moved T2295: IPv6 route should include interface on FreeBSD from Backlog to Servers config on the Salt board.
Fri, Apr 3, 17:37 · Salt, IPv6, Dæghrefn
dereckson triaged T2295: IPv6 route should include interface on FreeBSD as High priority.
Fri, Apr 3, 17:37 · Salt, IPv6, Dæghrefn
dereckson added a comment to T2225: Reboot WindRiver.

I've started a list of the points to check at https://agora.nasqueron.org/WindRiver#To_check_after_reboot

Fri, Apr 3, 17:20 · Servers
dereckson added a comment to T2293: viperserv.nasqueron.org IP on WindRiver was missing after reboot.
Fri, Apr 3, 17:08 · Salt, Servers, Dæghrefn
dereckson triaged T2294: Can't connect to Salt from WindRiver as High priority.
Fri, Apr 3, 17:03 · Servers, Salt
dereckson reopened T2225: Reboot WindRiver as "Open".

Server was rebooted without .35 IP.

Fri, Apr 3, 16:54 · Servers
dereckson updated the task description for T2293: viperserv.nasqueron.org IP on WindRiver was missing after reboot.
Fri, Apr 3, 16:47 · Salt, Servers, Dæghrefn
dereckson triaged T2293: viperserv.nasqueron.org IP on WindRiver was missing after reboot as High priority.
Fri, Apr 3, 16:45 · Salt, Servers, Dæghrefn
dereckson requested review of D4038: Redirect properly Wolfplex domains without www.
Fri, Apr 3, 16:41
dereckson requested review of D4037: Publish AAAA record for WindRiver.
Fri, Apr 3, 16:39

Tue, Mar 31

dereckson retitled D4035: Remove IntraNought gateway from new routers from Remove IntraNought gateway from new routers to Remove IntraNought gateway from new routers.
Tue, Mar 31, 22:33
dereckson retitled D4035: Remove IntraNought gateway from new routers from Remove IntraBought gateway from new routers to Remove IntraNought gateway from new routers.
Tue, Mar 31, 22:24
dereckson retitled D4035: Remove IntraNought gateway from new routers from Removing gateway 172.27.27.1 from Intranought on router-002 and router-003 to Remove IntraBought gateway from new routers.
Tue, Mar 31, 22:23
dereckson added a comment to D4035: Remove IntraNought gateway from new routers.

OK with pillarize too?

Tue, Mar 31, 22:18
dereckson accepted D4035: Remove IntraNought gateway from new routers.

OK with pillarize too?

Tue, Mar 31, 22:16
dereckson added inline comments to D4034: Add debug scripts for Vault, OVH, and VIP assignment.
Tue, Mar 31, 21:31
dereckson requested changes to D4033: Attach OVH VIP to the CARP MASTER MAC.

If we're going to flood /var/log/messages with carp debug information, perhaps should we create a separate log topic, but that can be another change. I've created T2292.

Tue, Mar 31, 21:17
dereckson triaged T2292: Create syslog configuration for CARP as Normal priority.
Tue, Mar 31, 21:16 · Servers, Secure HA tunnels

Mon, Mar 30

dereckson added inline comments to D3988: Configure strongSwan as IPsec implementation.
Mon, Mar 30, 17:20

Sun, Mar 29

dereckson added inline comments to D4026: Deploy or rotate Vault secrets.
Sun, Mar 29, 20:29
dereckson accepted D4031: Generate secretsmith Vault configuration for routers via Salt.
Sun, Mar 29, 20:28
dereckson added a revision to T2276: Automate CARP VIP MAC reassignment using devd and OVH API: D4031: Generate secretsmith Vault configuration for routers via Salt.
Sun, Mar 29, 20:27 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson updated the summary of D4031: Generate secretsmith Vault configuration for routers via Salt.
Sun, Mar 29, 20:27

Wed, Mar 25

dereckson moved T1939: Implement blue/green deployment or immutable artefacts for router-001 from Backlog to IntraNought / GRE tunnels on the Drake network board.
Wed, Mar 25, 12:49 · Servers, Drake network
dereckson moved T2096: WindRiver Route to Drake private network Ignored from Backlog to IntraNought / GRE tunnels on the Drake network board.
Wed, Mar 25, 12:49 · Drake network, Servers
dereckson moved T2167: Implement Common Address Redundancy Protocol (CARP) from Backlog to IntraNought / GRE tunnels on the Drake network board.
Wed, Mar 25, 12:49 · Servers, Drake network, Workshop
dereckson moved T2276: Automate CARP VIP MAC reassignment using devd and OVH API from Backlog to IntraNought / GRE tunnels on the Drake network board.
Wed, Mar 25, 12:49 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson moved T2290: Installation of CARP switch Python dependencies via Salt from Backlog to IntraNought / GRE tunnels on the Drake network board.
Wed, Mar 25, 12:49 · Python package, Drake network, Servers, Secure HA tunnels
dereckson closed D4020: Install GNU findutils.
Wed, Mar 25, 11:32
dereckson committed rOPS0564e79c0fe6: Install GNU findutils (authored by dereckson).
Install GNU findutils
Wed, Mar 25, 11:32
dereckson added a parent task for T2291: Configure explicitly php-fpm pool in nginx Docker image: T1294: Dockerize tools.nasqueron.org.
Wed, Mar 25, 11:24 · Nasqueron Tools, Docker images
dereckson added a subtask for T1294: Dockerize tools.nasqueron.org: T2291: Configure explicitly php-fpm pool in nginx Docker image.
Wed, Mar 25, 11:24 · Operations sprints (Consolidate them all), Docker images, Nasqueron Tools, Servers
dereckson moved T2291: Configure explicitly php-fpm pool in nginx Docker image from Backlog to Infra / DevOps on the Nasqueron Tools board.
Wed, Mar 25, 11:23 · Nasqueron Tools, Docker images
dereckson moved T2291: Configure explicitly php-fpm pool in nginx Docker image from Backlog to Need Dockerfile or config on the Docker images board.
Wed, Mar 25, 11:23 · Nasqueron Tools, Docker images
dereckson updated the task description for T2291: Configure explicitly php-fpm pool in nginx Docker image.
Wed, Mar 25, 11:22 · Nasqueron Tools, Docker images
dereckson triaged T2291: Configure explicitly php-fpm pool in nginx Docker image as High priority.
Wed, Mar 25, 11:20 · Nasqueron Tools, Docker images
dereckson added a comment to T1294: Dockerize tools.nasqueron.org.

Two actions to fix:

Wed, Mar 25, 11:14 · Operations sprints (Consolidate them all), Docker images, Nasqueron Tools, Servers
dereckson added a comment to T1294: Dockerize tools.nasqueron.org.

The nginx configuration doesn't seem the same for the Docker container and the development site:

Wed, Mar 25, 10:44 · Operations sprints (Consolidate them all), Docker images, Nasqueron Tools, Servers
dereckson moved T1294: Dockerize tools.nasqueron.org from Live on tools. to Infra / DevOps on the Nasqueron Tools board.
Wed, Mar 25, 10:31 · Operations sprints (Consolidate them all), Docker images, Nasqueron Tools, Servers
dereckson moved T1982: Upgrade from Python 3.9 to Python 3.11+ from Backlog to Let's Encrypt - legacy on the TLS certificates board.
Wed, Mar 25, 09:33 · TLS certificates, Servers
dereckson moved T1599: Install TLS wildcard certificates for nginx fallback vhost from Backlog to Let's Encrypt - acme.sh on the TLS certificates board.
Wed, Mar 25, 09:32 · TLS certificates, Operations sprints (Ignite Alkane Propulsion), Servers
dereckson moved T1167: Restart nginx on Ysul when renew certificates from Backlog to Let's Encrypt - legacy on the TLS certificates board.
Wed, Mar 25, 09:32 · TLS certificates, Wolfplex migration, Servers, User-Dereckson
dereckson moved T1966: Automate certificates renewal for Vault from Backlog to Vault / Nasqueron PKI on the TLS certificates board.
Wed, Mar 25, 09:32 · TLS certificates, Vault
dereckson moved T1513: Propagate certificate to Openfire server from Backlog to Let's Encrypt - acme.sh on the TLS certificates board.
Wed, Mar 25, 09:32 · TLS certificates, XMPP, security, Servers
dereckson moved T1602: Provision ACME DNS credentials for core domains on each servers from Backlog to Let's Encrypt - acme.sh on the TLS certificates board.
Wed, Mar 25, 09:31 · TLS certificates, Operations sprints (Ignite Alkane Propulsion), security, Servers
dereckson moved T1505: Automate Let's Encrypt TLS certificates management for every server from Backlog to Let's Encrypt - legacy on the TLS certificates board.
Wed, Mar 25, 09:31 · TLS certificates, Servers
dereckson moved T1342: Let's encrypt on Debian use logrotate from Backlog to Let's Encrypt - legacy on the TLS certificates board.
Wed, Mar 25, 09:31 · TLS certificates, security, Servers, Eglide, Salt
dereckson moved T2043: Switch to acme.sh instead of certbot from Backlog to Let's Encrypt - acme.sh on the TLS certificates board.
Wed, Mar 25, 09:31 · TLS certificates, Operations sprints (Ignite Alkane Propulsion), Servers
dereckson moved T2062: Native TLS support from Backlog to Applications on the TLS certificates board.
Wed, Mar 25, 09:31 · TLS certificates, wurf
dereckson moved T2112: Renew Vault web server certificate automatically from Backlog to Let's Encrypt - acme.sh on the TLS certificates board.
Wed, Mar 25, 09:31 · TLS certificates, security, Servers
dereckson moved T2155: Review rotation for acme.sh logs from Backlog to Let's Encrypt - acme.sh on the TLS certificates board.
Wed, Mar 25, 09:30 · TLS certificates, Restricted Project, security, Servers
dereckson moved T2196: Reload of dovecot and postfix when certif renew from Backlog to Let's Encrypt - acme.sh on the TLS certificates board.
Wed, Mar 25, 09:30 · TLS certificates, Restricted Project, good-first-issue, Nasqueron Operations Squad, Mail
dereckson requested review of D4030: Sort more DevCentral projects in Notifications Center.
Wed, Mar 25, 08:53
dereckson set the image for TLS certificates to F25014448: profile.
Wed, Mar 25, 08:31
dereckson created TLS certificates.
Wed, Mar 25, 08:30
dereckson accepted D4029: Allow role router to access ops/secrets/network/router/vault.
Wed, Mar 25, 08:23

Tue, Mar 24

dereckson accepted D4027: Install dependencies to register MAC address to ISP.
Tue, Mar 24, 17:58
dereckson created P397 rg packages_prefixes.
Tue, Mar 24, 17:18
dereckson added inline comments to D4027: Install dependencies to register MAC address to ISP.
Tue, Mar 24, 17:12
dereckson renamed T2290: Installation of CARP switch Python dependencies via Salt from Installation of CARP switch Python dependencies via Salt to Installation of CARP switch Python dependencies via Salt.
Tue, Mar 24, 15:29 · Python package, Drake network, Servers, Secure HA tunnels
dereckson added projects to T2290: Installation of CARP switch Python dependencies via Salt: Secure HA tunnels, Servers, Drake network.
Tue, Mar 24, 15:29 · Python package, Drake network, Servers, Secure HA tunnels
dereckson renamed T2290: Installation of CARP switch Python dependencies via Salt from Installation of Python dependencies via Salt to Installation of CARP switch Python dependencies via Salt.
Tue, Mar 24, 15:28 · Python package, Drake network, Servers, Secure HA tunnels
dereckson renamed T2290: Installation of CARP switch Python dependencies via Salt from Installation of secretsmith and ovh via Salt to Installation of Python dependencies via Salt.
Tue, Mar 24, 15:27 · Python package, Drake network, Servers, Secure HA tunnels
dereckson added a subtask for T2276: Automate CARP VIP MAC reassignment using devd and OVH API: T2290: Installation of CARP switch Python dependencies via Salt.
Tue, Mar 24, 15:27 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson added a parent task for T2290: Installation of CARP switch Python dependencies via Salt: T2276: Automate CARP VIP MAC reassignment using devd and OVH API.
Tue, Mar 24, 15:27 · Python package, Drake network, Servers, Secure HA tunnels
dereckson updated the test plan for D4027: Install dependencies to register MAC address to ISP.
Tue, Mar 24, 13:59
dereckson retitled D4027: Install dependencies to register MAC address to ISP from Install ovh and secretsmith via Salt to Install dependencies to register MAC address to ISP.
Tue, Mar 24, 13:42
dereckson added a revision to T2276: Automate CARP VIP MAC reassignment using devd and OVH API: D4027: Install dependencies to register MAC address to ISP.
Tue, Mar 24, 13:42 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson requested review of D4028: Update Black style.
Tue, Mar 24, 12:48

Mon, Mar 23

dereckson added inline comments to D4027: Install dependencies to register MAC address to ISP.
Mon, Mar 23, 20:51
dereckson added a comment to D2084: Usee Docker pillar information in nginx config.

I've asked upstream for advice how to resolve pillar for another server than the current node @ https://groups.google.com/g/salt-tower/c/XEKg2CEiZrU

Mon, Mar 23, 17:06
dereckson planned changes to D2084: Usee Docker pillar information in nginx config.

The output is really useful to avoid to manually repeat the ports.

Mon, Mar 23, 16:37
dereckson updated the diff for D2084: Usee Docker pillar information in nginx config.

Rebased. Fixed pillar handling.

Mon, Mar 23, 16:32
dereckson added a comment to D4026: Deploy or rotate Vault secrets.

Note: we're deploying a third secret for CARP routers scripts. If we've already that code merged, we'll need to append a line to deploy that state too.

Mon, Mar 23, 14:26
dereckson added a comment to D4026: Deploy or rotate Vault secrets.

Note: we're deploying a third secret for CARP routers scripts. If we've already that code merged, we'll need to append a line to deploy that state too.

Mon, Mar 23, 14:21
dereckson updated the summary of D2084: Usee Docker pillar information in nginx config.
Mon, Mar 23, 14:16
dereckson added a comment to D2084: Usee Docker pillar information in nginx config.

Next: try salt web-001 paas_docker.get_upstreams

Mon, Mar 23, 14:12
dereckson added inline comments to D3988: Configure strongSwan as IPsec implementation.
Mon, Mar 23, 14:08
dereckson retitled D2084: Usee Docker pillar information in nginx config from WIP: Use Docker pillar information in nginx config to Usee Docker pillar information in nginx config.
Mon, Mar 23, 14:04
dereckson updated the diff for D2084: Usee Docker pillar information in nginx config.

Rebased against current main for Alkane.

Mon, Mar 23, 14:04
dereckson moved T2289: https://infra.nasqueron.org/cd/dashboard without trailing slash doesn't serve CSS from Backlog to Next on the Servers board.
Mon, Mar 23, 14:01 · Jenkins, Tommy, Servers, Alkane
dereckson triaged T2289: https://infra.nasqueron.org/cd/dashboard without trailing slash doesn't serve CSS as Normal priority.
Mon, Mar 23, 14:00 · Jenkins, Tommy, Servers, Alkane
dereckson added a comment to D2084: Usee Docker pillar information in nginx config.

This change is interesting and should be rebased.

Mon, Mar 23, 13:34