Page MenuHomeDevCentral
Feed Advanced Search

Jul 5 2024

dereckson added a comment to T1930: Postfix Provisioning.

Queries from https://gist.github.com/barryo/8918488 have been checked against PostgreSQL mail database and works like a charm.

Jul 5 2024, 19:50 · Mail, Restricted Project, Servers
dereckson added a comment to T1931: Dovecot Provisioning.

Adapted from https://gist.github.com/barryo/8918488:

Jul 5 2024, 19:50 · Mail, Restricted Project, Servers
dereckson closed T1974: Update windu SSH key as Resolved by committing rOPS3defdf4a54a8: Update SSH key for windu.
Jul 5 2024, 18:54 · security, Servers
dereckson added projects to T1974: Update windu SSH key: Servers, security.
Jul 5 2024, 18:47 · security, Servers
DorianWinty added a comment to T1475: Provision a mail server.

Due to various problems with vimbadmin,
we will provision mailbox ourself with salt

Jul 5 2024, 17:44 · Mail, Restricted Project, Servers

Jul 4 2024

DorianWinty added a subtask for T1932: ViMbAdmin Provisioning: T1973: ViMbAdmin Security Issue.
Jul 4 2024, 19:47 · Mail, Restricted Project, Servers

Jul 3 2024

DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3352: Install PHP dependencies for ViMbAdmin.
Jul 3 2024, 16:35 · Mail, Restricted Project, Servers

Jul 2 2024

dereckson added a comment to T1972: Update WindRiver to FreeBSD 14.1.

pefs module has been rebuilt, /opt/python ruamel yaml clib fix updated

Jul 2 2024, 20:30 · Servers
dereckson closed T1972: Update WindRiver to FreeBSD 14.1 as Resolved.
Jul 2 2024, 20:29 · Servers

Jul 1 2024

dereckson added a comment to T1972: Update WindRiver to FreeBSD 14.1.

Userland ready for update, rebooting server to new kernel

Jul 1 2024, 19:50 · Servers
dereckson triaged T1972: Update WindRiver to FreeBSD 14.1 as Normal priority.
Jul 1 2024, 19:50 · Servers

Jun 28 2024

dereckson added a revision to T752: Salt configuration for White Rabbit: D3347: Fix tests for RabbitMQ password hash.
Jun 28 2024, 17:59 · Salt, Servers, Nasqueron Docker deployment squad

Jun 24 2024

DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3343: Init alkane and webserver-content to install VimbAdmin.
Jun 24 2024, 18:46 · Mail, Restricted Project, Servers
DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3342: Deploy webserver roles on hervil.
Jun 24 2024, 18:17 · Mail, Restricted Project, Servers
DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3341: Allow Hervil to access to DB-A-001 for ViMbAdmin.
Jun 24 2024, 18:12 · Mail, Restricted Project, Servers
DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3340: Allow permanent static UIDs for webserver accounts.
Jun 24 2024, 17:48 · Mail, Restricted Project, Servers

Jun 19 2024

dereckson added a comment to T1932: ViMbAdmin Provisioning.

misssing php-gettext extention
(installed by myself)

Jun 19 2024, 19:18 · Mail, Restricted Project, Servers

Jun 17 2024

DorianWinty reopened T1932: ViMbAdmin Provisioning as "Open".

misssing php-gettext extention
(installed by myself)

Jun 17 2024, 18:30 · Mail, Restricted Project, Servers
DorianWinty reopened T1932: ViMbAdmin Provisioning, a subtask of T1475: Provision a mail server, as Open.
Jun 17 2024, 18:30 · Mail, Restricted Project, Servers

Jun 16 2024

DorianWinty closed T1932: ViMbAdmin Provisioning, a subtask of T1475: Provision a mail server, as Wontfix.
Jun 16 2024, 19:21 · Mail, Restricted Project, Servers
DorianWinty closed T1932: ViMbAdmin Provisioning as Wontfix.

vimbadmin not maintained anymore

Jun 16 2024, 19:21 · Mail, Restricted Project, Servers
DorianWinty added a subtask for T1475: Provision a mail server: T1970: Configure Mailbox thugh salt.
Jun 16 2024, 16:15 · Mail, Restricted Project, Servers
DorianWinty added a comment to T1475: Provision a mail server.

Due to various problems with vimbadmin,
we will provision mailbox ourself with salt

Jun 16 2024, 16:15 · Mail, Restricted Project, Servers

Jun 12 2024

dereckson closed T1968: No environment for Alkane service on hervil as Resolved by committing rALKa1f78abc247a: Allow PATH in rc service environment.
Jun 12 2024, 23:54 · Alkane, Servers
dereckson added a revision to T1968: No environment for Alkane service on hervil: D3333: Allow PATH in rc service environment.
Jun 12 2024, 23:53 · Alkane, Servers
dereckson triaged T1968: No environment for Alkane service on hervil as High priority.
Jun 12 2024, 21:16 · Alkane, Servers

Jun 9 2024

DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3326: Deploy ViMbAdmin web application.
Jun 9 2024, 20:36 · Mail, Restricted Project, Servers
dereckson added a revision to T1950: Deploy PHP 8.3: D3327: Bump PHP version to 8.2 on shellserver and devserver roles.
Jun 9 2024, 15:32 · Servers, PHP 8.x support
dereckson added a comment to T1950: Deploy PHP 8.3.

As a follow-up, for shellserver and webserver-alkane roles, we need to bump s/php82/php83 for main package name.

Jun 9 2024, 15:19 · Servers, PHP 8.x support
DorianWinty moved T1932: ViMbAdmin Provisioning from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jun 9 2024, 12:04 · Mail, Restricted Project, Servers

Jun 8 2024

DorianWinty updated the task description for T1932: ViMbAdmin Provisioning.
Jun 8 2024, 20:53 · Mail, Restricted Project, Servers
DorianWinty updated the task description for T1932: ViMbAdmin Provisioning.
Jun 8 2024, 20:52 · Mail, Restricted Project, Servers

Jun 2 2024

dereckson added a comment to P352 Renew Vault certificates automation - renew.py.
  • pprint isn't used anymore
  • need to run black
  • description needs to be updated
  • TTL can be much shorter if we automate this procedure
Jun 2 2024, 22:43 · Servers, Vault
dereckson added a comment to P351 Renew Vault certificates automation - renew.sh.

sudo kill -1 $(cat /var/run/vault.pid)

Error management should be done to check if that pids exist or return an error code.

Jun 2 2024, 22:40 · Servers, Vault
dereckson added a comment to P351 Renew Vault certificates automation - renew.sh.

Needs hvac and pyyaml as packages to be installed on the server, Complector doesn't currently have hvac, only pyyaml.

Jun 2 2024, 22:38 · Servers, Vault
dereckson created P352 Renew Vault certificates automation - renew.py.
Jun 2 2024, 22:35 · Servers, Vault
dereckson created P351 Renew Vault certificates automation - renew.sh.
Jun 2 2024, 22:34 · Servers, Vault
dereckson triaged T1965: Decommission CloudHugger as Low priority.
Jun 2 2024, 22:29 · Servers
DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3322: Add pdo_pgsql for the container.
Jun 2 2024, 16:06 · Mail, Restricted Project, Servers
DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3323: Allow ViMbAdmin PostgreSQL connection.
Jun 2 2024, 16:05 · Mail, Restricted Project, Servers
DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3324: Refresh permissions for ViMbAdmin.
Jun 2 2024, 16:05 · Mail, Restricted Project, Servers
DorianWinty added a revision to T1932: ViMbAdmin Provisioning: D3320: WIP: configure ViMbAdmin.
Jun 2 2024, 16:04 · Mail, Restricted Project, Servers
DorianWinty updated the task description for T1932: ViMbAdmin Provisioning.
Jun 2 2024, 14:37 · Mail, Restricted Project, Servers
DorianWinty updated the task description for T1932: ViMbAdmin Provisioning.
Jun 2 2024, 14:30 · Mail, Restricted Project, Servers
DorianWinty updated the task description for T1932: ViMbAdmin Provisioning.
Jun 2 2024, 14:23 · Mail, Restricted Project, Servers

Apr 18 2024

DorianWinty created T1963: Server outage: infra.nasqueron.org.
Apr 18 2024, 18:34 · Servers

Mar 28 2024

dereckson lowered the priority of T1960: Unknown domains are currently served by windriver server vhost from High to Normal.

Decreasing priority as we tested a page successfully on WindRiver.

Mar 28 2024, 23:43 · Servers

Mar 8 2024

dereckson added a comment to T1960: Unknown domains are currently served by windriver server vhost.

Currently, the responsibility seems to be to the nginx unit in the main webserver role, not on webserver-core:

Mar 8 2024, 00:27 · Servers
dereckson added a comment to T1960: Unknown domains are currently served by windriver server vhost.

000-fallback.conf exists on WindRiver but as an empty file, so without any server block

Mar 8 2024, 00:21 · Servers
dereckson triaged T1960: Unknown domains are currently served by windriver server vhost as High priority.
Mar 8 2024, 00:20 · Servers

Feb 24 2024

dereckson added a comment to T1950: Deploy PHP 8.3.

Did you know? Debian Sid still has 8.2 in the core repo.

Feb 24 2024, 20:21 · Servers, PHP 8.x support

Feb 17 2024

dereckson closed T1953: sshd-otp returns fatal error recv_rexec_state: parse config: incomplete message as Resolved.
Ysul
$ /usr/local/etc/rc.d/sshd-otp restart
Performing sanity check on sshd_otp configuration.
Stopping sshd_otp.
Waiting for PIDS: 1331.
Performing sanity check on sshd_otp configuration.
Starting sshd_otp.
Feb 17 2024, 14:50 · security, Servers
dereckson created T1953: sshd-otp returns fatal error recv_rexec_state: parse config: incomplete message.
Feb 17 2024, 14:50 · security, Servers

Feb 4 2024

dereckson added a revision to T437: Recreate NextCloud installation: D3312: Create datacube directory for NextCloud.
Feb 4 2024, 01:11 · Servers

Feb 3 2024

dereckson added a comment to T437: Recreate NextCloud installation.

Next steps:

Feb 3 2024, 23:16 · Servers
dereckson added a revision to T437: Recreate NextCloud installation: D3309: Serve NextCloud on drive.nasqueron.org for Nginx.
Feb 3 2024, 23:14 · Servers

Feb 2 2024

dereckson added a revision to T437: Recreate NextCloud installation: D3308: Install NextCloud on saas-nextcloud role.
Feb 2 2024, 02:04 · Servers
dereckson added a revision to T1950: Deploy PHP 8.3: D3307: Set PHP 8.3 as default version on FreeBSD servers.
Feb 2 2024, 02:02 · Servers, PHP 8.x support
dereckson added a revision to T437: Recreate NextCloud installation: D3306: Run maintenance operations for NextCloud.
Feb 2 2024, 01:27 · Servers
dereckson added a revision to T437: Recreate NextCloud installation: D3305: Configure NextCloud php-fpm pool.
Feb 2 2024, 01:13 · Servers
dereckson added a revision to T437: Recreate NextCloud installation: D3304: Increase memory limit for PHP processes.
Feb 2 2024, 01:04 · Servers
dereckson added a comment to T437: Recreate NextCloud installation.

Consolidating datacube volumes:

Feb 2 2024, 00:33 · Servers
dereckson lowered the priority of T437: Recreate NextCloud installation from Normal to Low.

I've asked on a brainstorming channel if someone is interested we take at Online some RPN storage, I didn't receive any answer, so I get nobody is looking for a solution to store a lot of Gb of documents here, hence the priority decrease.

Feb 2 2024, 00:23 · Servers
dereckson claimed T437: Recreate NextCloud installation.
Feb 2 2024, 00:12 · Servers

Feb 1 2024

dereckson added a comment to T1950: Deploy PHP 8.3.

Done for WindRiver, our current development server.

Feb 1 2024, 00:37 · Servers, PHP 8.x support
dereckson triaged T1950: Deploy PHP 8.3 as Normal priority.
Feb 1 2024, 00:21 · Servers, PHP 8.x support

Jan 18 2024

dereckson triaged T1947: nginx resolver defined at 127.0.0.1 doesn't work on Docker engines as Normal priority.
Jan 18 2024, 01:17 · Nasqueron Docker deployment squad, Servers, Salt
dereckson created T1947: nginx resolver defined at 127.0.0.1 doesn't work on Docker engines.
Jan 18 2024, 01:17 · Nasqueron Docker deployment squad, Servers, Salt

Jan 16 2024

dereckson moved T1529: Evaluate ml-workspace and ml-hub from Backlog to Nope / later on the Product evaluation board.
Jan 16 2024, 01:04 · Product evaluation, Servers

Jan 15 2024

dereckson added a comment to T1877: Evaluate Alcali - Salt front-end.

Alcali is still alive.

Jan 15 2024, 21:50 · security, Salt, Servers, Product evaluation
dereckson moved T1944: Ensure portsnap is available where we use ports from Backlog to Servers config on the Salt board.
Jan 15 2024, 21:50 · Salt, Servers
dereckson triaged T1944: Ensure portsnap is available where we use ports as Normal priority.
Jan 15 2024, 21:50 · Salt, Servers
dereckson added a revision to T1888: Add XML support on db-A PostgreSQL: D3290: Ensure PostgreSQL port is still up-to-date on FreeBSD.
Jan 15 2024, 21:37 · upstream, DBA, Servers
dereckson added a revision to T1943: Orbeon Forms trigger an error after application is submit: D3290: Ensure PostgreSQL port is still up-to-date on FreeBSD.
Jan 15 2024, 21:37 · Servers, Nasqueron Docker deployment squad, Launch community
dereckson closed T1943: Orbeon Forms trigger an error after application is submit as Resolved.
Jan 15 2024, 00:21 · Servers, Nasqueron Docker deployment squad, Launch community
dereckson closed T1888: Add XML support on db-A PostgreSQL, a subtask of T1943: Orbeon Forms trigger an error after application is submit, as Resolved.
Jan 15 2024, 00:21 · Servers, Nasqueron Docker deployment squad, Launch community
dereckson closed T1888: Add XML support on db-A PostgreSQL as Resolved.
Jan 15 2024, 00:21 · upstream, DBA, Servers
dereckson added a revision to T1888: Add XML support on db-A PostgreSQL: D3287: Fix PostgreSQL 15 build instructions.
Jan 15 2024, 00:19 · upstream, DBA, Servers
dereckson added a comment to T1888: Add XML support on db-A PostgreSQL.

I've added documentation to https://agora.nasqueron.org/Operations_grimoire/FreeBSD#PostgreSQL without real conviction.

Jan 15 2024, 00:16 · upstream, DBA, Servers
dereckson lowered the priority of T1943: Orbeon Forms trigger an error after application is submit from High to Normal.

Fixed. Form works again.

Jan 15 2024, 00:13 · Servers, Nasqueron Docker deployment squad, Launch community
dereckson moved T1943: Orbeon Forms trigger an error after application is submit from Backlog to Working on on the Nasqueron Docker deployment squad board.
Jan 15 2024, 00:06 · Servers, Nasqueron Docker deployment squad, Launch community
dereckson moved T1943: Orbeon Forms trigger an error after application is submit from Backlog to Working on on the Servers board.

I'm rebuilding PostgreSQL 15.4 with XML support on db-A-001.

Jan 15 2024, 00:06 · Servers, Nasqueron Docker deployment squad, Launch community

Jan 14 2024

dereckson added a subtask for T1943: Orbeon Forms trigger an error after application is submit: T1888: Add XML support on db-A PostgreSQL.
Jan 14 2024, 23:19 · Servers, Nasqueron Docker deployment squad, Launch community
dereckson added a parent task for T1888: Add XML support on db-A PostgreSQL: T1943: Orbeon Forms trigger an error after application is submit.
Jan 14 2024, 23:19 · upstream, DBA, Servers
dereckson added a comment to T1943: Orbeon Forms trigger an error after application is submit.

Jan 14 23:13:52 db-A-001 postgres[35351]: [7-1] 2024-01-14 23:13:52.659 UTC [35351] ERROR: unsupported XML feature

Jan 14 2024, 23:19 · Servers, Nasqueron Docker deployment squad, Launch community
dereckson reopened T1888: Add XML support on db-A PostgreSQL as "Open".

When upgraded to FreeBSD 14, we lost this.

Jan 14 2024, 23:18 · upstream, DBA, Servers
dereckson updated subscribers of T1943: Orbeon Forms trigger an error after application is submit.

When clicking to Save Progress:

Jan 14 2024, 23:17 · Servers, Nasqueron Docker deployment squad, Launch community
dereckson updated the task description for T1943: Orbeon Forms trigger an error after application is submit.
Jan 14 2024, 22:55 · Servers, Nasqueron Docker deployment squad, Launch community
dereckson triaged T1943: Orbeon Forms trigger an error after application is submit as High priority.
Jan 14 2024, 22:55 · Servers, Nasqueron Docker deployment squad, Launch community

Jan 10 2024

dereckson updated the task description for T1938: Non open-source infrastructure software policy.
Jan 10 2024, 22:30 · discussion, Servers
dereckson added a comment to T1938: Non open-source infrastructure software policy.

Added RHEL question.

Jan 10 2024, 22:23 · discussion, Servers
dereckson updated the task description for T1938: Non open-source infrastructure software policy.
Jan 10 2024, 22:23 · discussion, Servers
dereckson lowered the priority of T1939: Implement blue/green deployment or immutable artefacts for router-001 from Normal to Low.
Jan 10 2024, 22:11 · Servers, Drake network
dereckson added a comment to T1939: Implement blue/green deployment or immutable artefacts for router-001.

router-001 update would cut network connections between Ysul, WindRiver, CloudHugger and IntraNought VMs.

I think that's actually acceptable, as production services can reach web-001/db-*/ directly through their dedicated network card.

Impact:

  • IRC bots wouldn't be able to reach MySQL or Vault as they're still on Ysul
  • Services still on Ysul can't reach
  • Development servers can't reach production services, or Dwellers

Another issue is we lose connections to all those machines, as router-001 is used to route traffic to them.

Probably best to ship router-002 under FreeBSD 14 so we can prepare to minimize this impact if we need more hypervisors in the future.

Jan 10 2024, 22:10 · Servers, Drake network
dereckson updated the task description for T1939: Implement blue/green deployment or immutable artefacts for router-001.
Jan 10 2024, 22:10 · Servers, Drake network
dereckson closed T1924: Upgrade servers to FreeBSD 14 as Resolved.

router-001 is out of scope as long as T1939 is implemented

Jan 10 2024, 22:09 · Servers
dereckson triaged T1939: Implement blue/green deployment or immutable artefacts for router-001 as Normal priority.
Jan 10 2024, 22:08 · Servers, Drake network

Jan 7 2024

dereckson added a comment to T1924: Upgrade servers to FreeBSD 14.

router-001 update would cut network connections between Ysul, WindRiver, CloudHugger and IntraNought VMs.

Jan 7 2024, 18:01 · Servers
dereckson updated the task description for T1924: Upgrade servers to FreeBSD 14.
Jan 7 2024, 17:46 · Servers
dereckson added a revision to T1924: Upgrade servers to FreeBSD 14: D3264: Bump FreeBSD version in MOTD.
Jan 7 2024, 16:20 · Servers