Page MenuHomeDevCentral
Feed All Stories

Mon, Mar 23

dereckson merged T1524: Monitor sudo files on servers into T2286: Detect configuration drift by computing difference between Salt states and deployed.
Mon, Mar 23, 09:09 · Salt
dereckson merged task T1524: Monitor sudo files on servers into T2286: Detect configuration drift by computing difference between Salt states and deployed.
Mon, Mar 23, 09:09 · Eglide, security, Servers
dereckson closed T1524: Monitor sudo files on servers as Wontfix.

With Salt, sudo files content are now managed from rOPS.

Mon, Mar 23, 09:09 · Eglide, security, Servers
dereckson triaged T2286: Detect configuration drift by computing difference between Salt states and deployed as High priority.
Mon, Mar 23, 09:09 · Salt
dereckson closed T1942: Allow Jenkins to trigger deployment through Salt as Wontfix.

Not a priority right now, as we use Alkane to trigger website deployments.

Mon, Mar 23, 08:59 · Continous integration and delivery, Salt
dereckson closed T1942: Allow Jenkins to trigger deployment through Salt, a subtask of T1750: Import FANTOIR database, as Wontfix.
Mon, Mar 23, 08:59 · Nasqueron Databases
dereckson closed T752: Salt configuration for White Rabbit as Resolved.
Mon, Mar 23, 08:58 · Salt, Servers, Nasqueron Docker deployment squad
dereckson added a comment to T1691: Allow to inspect Salt configuration.

See also T1784 to improve UX and URLs.

Mon, Mar 23, 08:58 · documentation, Salt, Servers
dereckson closed T2124: Update reports automatically on Agora as Resolved.
Mon, Mar 23, 08:54 · Servers, Agora
dereckson retitled D4026: Deploy or rotate Vault secrets from Once the AppRole have been created or updated in Vault by Terraform/OpenTofu, the relevant configuration files with AppRole credentials must be provisioned. to Deploy or rotate Vault secrets.
Mon, Mar 23, 08:44
dereckson requested review of D4026: Deploy or rotate Vault secrets.
Mon, Mar 23, 00:32
dereckson committed rOPS92ef1ec2e3d1: Block known datacenter ranges flooding Phabricator (authored by dereckson).
Block known datacenter ranges flooding Phabricator
Mon, Mar 23, 00:25
dereckson closed D3947: Block known datacenter ranges flooding Phabricator.
Mon, Mar 23, 00:25
dereckson closed D3984: Help to install Arcanist dependencies.
Mon, Mar 23, 00:22
dereckson committed rOPS7f3fde8da814: Help to install Arcanist dependencies (authored by dereckson).
Help to install Arcanist dependencies
Mon, Mar 23, 00:22
dereckson triaged T1744: Stream processing with Benthos as Wishlist priority.
Mon, Mar 23, 00:21 · Message queues, Monitoring and reporting, Elastic for infra, Servers, Product evaluation
dereckson added a comment to T1744: Stream processing with Benthos.

Software has been renamed to Redpanda Connect:

Mon, Mar 23, 00:21 · Message queues, Monitoring and reporting, Elastic for infra, Servers, Product evaluation
dereckson closed T1735: Investigate why IPv6 connections fail to Dwellers port 443 as Resolved.

Checked today, it works fine:

Mon, Mar 23, 00:08 · IPv6, Servers
dereckson updated the task description for T1784: Parse URL in JavaScript in infra.nasqueron.org/config.
Mon, Mar 23, 00:04 · good-first-issue, Salt, Servers
dereckson moved T1784: Parse URL in JavaScript in infra.nasqueron.org/config from Backlog to Dev on the good-first-issue board.
Mon, Mar 23, 00:01 · good-first-issue, Salt, Servers
dereckson added a project to T1784: Parse URL in JavaScript in infra.nasqueron.org/config: good-first-issue.
Mon, Mar 23, 00:01 · good-first-issue, Salt, Servers
dereckson triaged T1784: Parse URL in JavaScript in infra.nasqueron.org/config as Normal priority.
Mon, Mar 23, 00:00 · good-first-issue, Salt, Servers
dereckson triaged T1789: Opt-out Sentry Beacon (telemetry) as High priority.
Mon, Mar 23, 00:00 · privacy, Continous integration and delivery, Servers
dereckson triaged T2006: docker.errors.DockerException: Error while fetching server API version: Not supported URL scheme http+docker as Normal priority.
Mon, Mar 23, 00:00 · upstream, Nasqueron Docker deployment squad

Sun, Mar 22

dereckson triaged T2093: Move .browserlistrc file into a package.json section as Normal priority.
Sun, Mar 22, 23:59 · upsection
dereckson updated the task description for T2225: Reboot WindRiver.
Sun, Mar 22, 23:59 · Servers
dereckson triaged T2096: WindRiver Route to Drake private network Ignored as High priority.
Sun, Mar 22, 23:58 · Drake network, Servers
dereckson triaged T2107: j'aimerais avoir une présence permanente sur internet as Wishlist priority.
Sun, Mar 22, 23:58 · Eglide, security
dereckson closed D4019: Revert "Try to install Salt 3006.8 as test dependency".
Sun, Mar 22, 23:57
dereckson added a reverting change for D4001: Try to install Salt 3006.8 as test dependency: rOPSed41f887d991: Revert "Try to install Salt 3006.8 as test dependency".
Sun, Mar 22, 23:57
dereckson committed rOPSed41f887d991: Revert "Try to install Salt 3006.8 as test dependency" (authored by dereckson).
Revert "Try to install Salt 3006.8 as test dependency"
Sun, Mar 22, 23:57
dereckson added a reverting change for rOPSede81bc37383: Try to install Salt 3006.8 as test dependency: rOPSed41f887d991: Revert "Try to install Salt 3006.8 as test dependency".
Sun, Mar 22, 23:57
dereckson requested review of D4025: Prune OCSP artefact from Git ignore list.
Sun, Mar 22, 23:55
dereckson added a revision to T2116: Drop of OCSP Service: D4025: Prune OCSP artefact from Git ignore list.
Sun, Mar 22, 23:55 · TLS certificates, Servers, Nasqueron Operations Squad
dereckson updated the task description for T2276: Automate CARP VIP MAC reassignment using devd and OVH API.
Sun, Mar 22, 23:47 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson added a comment to T2276: Automate CARP VIP MAC reassignment using devd and OVH API.

Ah, that's now what we need, nice for the script!

Sun, Mar 22, 23:43 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson closed D4016: Provision Vault policy for routers.
Sun, Mar 22, 23:41
dereckson committed rOPS7c907320cee6: Provision Vault policy for routers (authored by dereckson).
Provision Vault policy for routers
Sun, Mar 22, 23:41
dereckson added a comment to D4016: Provision Vault policy for routers.
Log from Terraform apply (grep router)
vault_policy.router: Creating...
module.router_approle.vault_approle_auth_backend_role.this: Creating...
module.router_approle.vault_approle_auth_backend_role.this: Creation complete after 0s [id=auth/approle/role/router]
module.router_approle.data.vault_approle_auth_backend_role_id.this: Reading...
module.router_approle.data.vault_approle_auth_backend_role_id.this: Read complete after 0s [id=auth/approle/role/router/role-id]
module.router_approle.vault_approle_auth_backend_role_secret_id.this: Creating...
vault_policy.router: Creation complete after 0s [id=router]
module.router_approle.vault_approle_auth_backend_role_secret_id.this: Creation complete after 1s [id=backend=approle::role=router::accessor=...]
module.router_approle.vault_kv_secret_v2.this: Creating...
module.router_approle.vault_kv_secret_v2.this: Creation complete after 0s [id=ops/data/secrets/network/router/vault]
Sun, Mar 22, 23:20
yousra accepted D4019: Revert "Try to install Salt 3006.8 as test dependency".
Sun, Mar 22, 22:45
yousra added a comment to T2276: Automate CARP VIP MAC reassignment using devd and OVH API.

The file /usr/local/etc/devd/carp.conf :

Sun, Mar 22, 21:33 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
yousra accepted D4016: Provision Vault policy for routers.
Sun, Mar 22, 21:16
dereckson added a comment to T2276: Automate CARP VIP MAC reassignment using devd and OVH API.

You can directly use variables in the action to pass interface and state with $subsystem and $type

Sun, Mar 22, 21:13 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
yousra added a comment to T2276: Automate CARP VIP MAC reassignment using devd and OVH API.
notify 0 {
    match "system" "CARP";
    match "subsystem" "[0-9]+@[0-9a-z.]+";
    match "type" "(MASTER|BACKUP)";
    action "/usr/local/scripts/carp-test.sh";
};
Sun, Mar 22, 20:24 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson closed T1697: Troubleshoot Openfire Docker image as Wontfix.

Closed as inactive.

Sun, Mar 22, 20:23 · Support, Docker images
dereckson added a comment to T1861: Configure static IPv6 on WindRiver.

Next: configure DNS records

Sun, Mar 22, 19:08 · security, Servers, IPv6
dereckson moved T2030: Provide wheel Python package for ruamel.yaml.clib in /opt/python from Backlog to Servers config on the Salt board.
Sun, Mar 22, 19:08 · Salt, Servers
dereckson placed T2030: Provide wheel Python package for ruamel.yaml.clib in /opt/python up for grabs.

This method works well, Salt automation is welcome.

Sun, Mar 22, 19:07 · Salt, Servers
dereckson changed the visibility for T2143: Hash Tomcat credentials.
Sun, Mar 22, 19:04 · Servers, Nasqueron Docker deployment squad, security
dereckson shifted T2143: Hash Tomcat credentials from the Restricted Space space to the S1 Nasqueron space.
Sun, Mar 22, 19:03 · Servers, Nasqueron Docker deployment squad, security
dereckson closed T2143: Hash Tomcat credentials as Resolved.
Sun, Mar 22, 19:02 · Servers, Nasqueron Docker deployment squad, security
dereckson closed T1975: Allow ops to login to Vault as Resolved.

Solution is satisfactory and stable all summer long.

Sun, Mar 22, 18:56 · Salt, Vault
dereckson closed T2014: Serve https://nasqueron.org from web-001, a subtask of T1582: Implement XEP-0156, as Resolved.
Sun, Mar 22, 18:56 · good-first-issue, XMPP, Servers
dereckson closed T2014: Serve https://nasqueron.org from web-001 as Resolved.
Sun, Mar 22, 18:56 · Alkane, DNS, Servers
dereckson removed a revision from T2014: Serve https://nasqueron.org from web-001: D3439: Automate www. deployment through Alkane.
Sun, Mar 22, 18:55 · Alkane, DNS, Servers
dereckson removed a task from D3439: Automate www. deployment through Alkane: T2014: Serve https://nasqueron.org from web-001.
Sun, Mar 22, 18:55
dereckson updated the summary of D3439: Automate www. deployment through Alkane.
Sun, Mar 22, 18:55
dereckson closed T2017: Install WindRiver replacement server as Resolved.

We can consider we're done and handle the remaining as regular tasks.

Sun, Mar 22, 18:54 · Servers
dereckson updated the task description for T2031: Harmonize nginx includes.
Sun, Mar 22, 18:53 · Servers
dereckson closed T2103: Upgrade servers to FreeBSD 14.3 as Resolved.

All server has been upgraded to FreeBSD 15, excepted router-001, which will be decom when router-002/003 will be live.

Sun, Mar 22, 18:52 · Servers
dereckson added a project to T1767: Provision /etc/hosts: Secure HA tunnels.
Sun, Mar 22, 18:48 · Secure HA tunnels, Salt, Drake network
dereckson placed T1510: Create migration.mediawiki.test.ook.space up for grabs.
Sun, Mar 22, 18:41 · Mediawiki SaaS, Wikimedia, Servers
dereckson added a comment to T1510: Create migration.mediawiki.test.ook.space.

https://migration.mediawiki.test.ook.space/w/index.php reports an unknown wiki.

Sun, Mar 22, 18:40 · Mediawiki SaaS, Wikimedia, Servers
dereckson closed T1396: nginx autoindex pages aren't served as UTF-8 as Resolved.

Test URL: https://windriver.nasqueron.org/~dereckson/ops/T1396-nginx-autoindex/

Sun, Mar 22, 18:37 · Servers
dereckson updated the task description for T1396: nginx autoindex pages aren't served as UTF-8.
Sun, Mar 22, 18:36 · Servers
dereckson placed T1396: nginx autoindex pages aren't served as UTF-8 up for grabs.

[ Not working actively on this, also we'd need a repro URL. ]

Sun, Mar 22, 18:32 · Servers
dereckson placed T1131: Populate language codes up for grabs.

[ Not actively working on this, but please ping me if you need this. ]

Sun, Mar 22, 18:32 · Nasqueron Databases, Odderon
dereckson moved T1109: Switch all OAuth GitHub applications to Nasqueron organization accounts from Backlog to Infra on the Auth Grove board.
Sun, Mar 22, 18:30 · Auth Grove, User-Dereckson, security, Nasqueron Operations Squad
dereckson triaged T1109: Switch all OAuth GitHub applications to Nasqueron organization accounts as Normal priority.
Sun, Mar 22, 18:29 · Auth Grove, User-Dereckson, security, Nasqueron Operations Squad
dereckson updated the task description for T1423: Investigate OpenFaaS + Kong.
Sun, Mar 22, 18:28 · Nasqueron Docker deployment squad, Servers, Nasqueron API, Product evaluation
dereckson placed T1423: Investigate OpenFaaS + Kong up for grabs.

Not working on this for now, and the number of services in our API doesn't make that urgent.

Sun, Mar 22, 18:24 · Nasqueron Docker deployment squad, Servers, Nasqueron API, Product evaluation
dereckson placed T1513: Propagate certificate to Openfire server up for grabs.
Sun, Mar 22, 18:21 · TLS certificates, XMPP, security, Servers
dereckson triaged T1513: Propagate certificate to Openfire server as Normal priority.
Sun, Mar 22, 18:21 · TLS certificates, XMPP, security, Servers
dereckson updated the diff for D4024: Make available TeX fonts to all the system on devserver.

Not in misc anymore

Sun, Mar 22, 18:19
dereckson updated the diff for D4024: Make available TeX fonts to all the system on devserver.

Whitespace issues

Sun, Mar 22, 18:17
dereckson updated the diff for D4024: Make available TeX fonts to all the system on devserver.

Extract TeX live states to tex.sls for clarity. Fix symlink.

Sun, Mar 22, 18:16
dereckson created P394 fc-list | grep texmf when deployed with D4024.
Sun, Mar 22, 18:02
dereckson moved T1526: Make available TeX fonts to all the system on devserver from Backlog to Pending review on the Servers board.
Sun, Mar 22, 17:54 · Salt, Servers
dereckson added a revision to T1526: Make available TeX fonts to all the system on devserver: D4024: Make available TeX fonts to all the system on devserver.
Sun, Mar 22, 17:54 · Salt, Servers
dereckson requested review of D4024: Make available TeX fonts to all the system on devserver.
Sun, Mar 22, 17:54
dereckson added a comment to T2276: Automate CARP VIP MAC reassignment using devd and OVH API.

For all CARP external documentation, I think I've found the threshold where information is outdated in that man page:

Sun, Mar 22, 17:46 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson added a comment to T2276: Automate CARP VIP MAC reassignment using devd and OVH API.

According carp(4) (man carp) examples section, the name has changed.

Sun, Mar 22, 17:43 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
yousra added a comment to T2276: Automate CARP VIP MAC reassignment using devd and OVH API.

@dereckson I first tried to redefine the devd rule by matching specific IFNET event types such as LINK_UP, LINK_DOWN, UP and DOWN, but none of them were triggered during CARP state changes in my tests.

Sun, Mar 22, 17:11 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson added a comment to T1526: Make available TeX fonts to all the system on devserver.

Procedure still the same in current TeX Live Guide, updated the link.

Sun, Mar 22, 17:08 · Salt, Servers
dereckson triaged T1526: Make available TeX fonts to all the system on devserver as Normal priority.
Sun, Mar 22, 17:07 · Salt, Servers
dereckson updated the task description for T2285: Allow to run recent Node version on Jenkins CI and CD.
Sun, Mar 22, 17:03 · upsection, Docker images, Jenkins, ServPulse
dereckson updated the task description for T2285: Allow to run recent Node version on Jenkins CI and CD.
Sun, Mar 22, 17:02 · upsection, Docker images, Jenkins, ServPulse
dereckson moved T2285: Allow to run recent Node version on Jenkins CI and CD from 🧭 Dispatch to 🟣 BACKEND - DevOps/Infra on the ServPulse board.
Sun, Mar 22, 17:01 · upsection, Docker images, Jenkins, ServPulse
dereckson moved T2285: Allow to run recent Node version on Jenkins CI and CD from Backlog to Need Dockerfile or config on the Docker images board.
Sun, Mar 22, 17:01 · upsection, Docker images, Jenkins, ServPulse
dereckson moved T2285: Allow to run recent Node version on Jenkins CI and CD from Backlog / triage to Deployment on the upsection board.
Sun, Mar 22, 17:00 · upsection, Docker images, Jenkins, ServPulse
dereckson moved T2285: Allow to run recent Node version on Jenkins CI and CD from Backlog to Executor nodes / agents on the Jenkins board.
Sun, Mar 22, 17:00 · upsection, Docker images, Jenkins, ServPulse
dereckson triaged T2285: Allow to run recent Node version on Jenkins CI and CD as High priority.
Sun, Mar 22, 17:00 · upsection, Docker images, Jenkins, ServPulse
dereckson placed T2244: Configure Harbormaster build plan up for grabs.

[ Deassigning, as it needs some CI love first, to be able to run modern Node 24 on Jenkins ]

Sun, Mar 22, 16:53 · ServPulse
dereckson added a comment to T2276: Automate CARP VIP MAC reassignment using devd and OVH API.
notify 0 {
    match "system" "IFNET";
    match "subsystem" "vmx1";
    action "logger CARP state change detected";
};
Sun, Mar 22, 16:32 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
yousra added a comment to T2276: Automate CARP VIP MAC reassignment using devd and OVH API.

A dedicated devd file was placed in /usr/local/etc/devd because this directory is usually used for custom configurations added by administrators, while /etc/devd contains the default system rules from FreeBSD. It makes the setup cleaner, avoids mixing custom logic with system configuration, and makes future maintenance or upgrades easier.

Sun, Mar 22, 15:48 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
yousra updated the task description for T2276: Automate CARP VIP MAC reassignment using devd and OVH API.
Sun, Mar 22, 15:28 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
yousra updated the task description for T2276: Automate CARP VIP MAC reassignment using devd and OVH API.
Sun, Mar 22, 15:26 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
yousra updated the task description for T2276: Automate CARP VIP MAC reassignment using devd and OVH API.
Sun, Mar 22, 15:25 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
yousra updated the task description for T2276: Automate CARP VIP MAC reassignment using devd and OVH API.
Sun, Mar 22, 15:24 · Drake network, Servers, Monitoring and reporting, Secure HA tunnels
dereckson requested review of D4023: Provide a Docker image able to run tests.
Sun, Mar 22, 13:57