Page MenuHomeDevCentral

ServersFolder
ActivePublic

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

Anything related to the Nasqueron server infrastructure at IaaS or PaaS levels.

Recent Activity

Sun, Sep 14

dereckson moved T1580: Deploy ACME-specific DNS server from DNS Server / KnotDNS to AcmeDNS on the DNS board.
Sun, Sep 14, 23:11 · Operations sprints (Consolidate them all), DNS, security, Servers
dereckson moved T2021: Can't renew certificate with acme DNS plugin under Python 3.11 from Backlog to AcmeDNS on the DNS board.
Sun, Sep 14, 23:11 · DNS, Servers
dereckson moved T1580: Deploy ACME-specific DNS server from Backlog to DNS Server / KnotDNS on the DNS board.
Sun, Sep 14, 23:10 · Operations sprints (Consolidate them all), DNS, security, Servers
dereckson moved T1928: Serve CAA DNS records from Backlog to DNS records on the DNS board.
Sun, Sep 14, 23:10 · Servers, DNS, security
dereckson moved T761: Automate to create subdomains DNS records from Backlog to DNS Server / KnotDNS on the DNS board.
Sun, Sep 14, 23:09 · DNS, Servers
dereckson moved T1269: Update SSHFP records for ysul from Backlog to DNS records on the DNS board.
Sun, Sep 14, 23:09 · DNS, Operations sprints (The Dreadnought will produce new officers), Servers
dereckson moved T1925: No SRV record found for the repo 'Nasqueron' from Backlog to DNS records on the DNS board.
Sun, Sep 14, 23:09 · DNS, Servers
dereckson closed T2021: Can't renew certificate with acme DNS plugin under Python 3.11 as Resolved.

Not spot anymore. Python 3.11 is used on every FreeBSD systems now.

Sun, Sep 14, 23:09 · DNS, Servers
dereckson added a comment to T761: Automate to create subdomains DNS records.

Closing as a duplicate, as with T1217 task, automation is there:

  • new records can be submitted as a commit against zone file
  • new zones can be added by creating a new file and pillar entry
Sun, Sep 14, 23:08 · DNS, Servers
dereckson merged task T761: Automate to create subdomains DNS records into T1217: Host our DNS servers.
Sun, Sep 14, 23:06 · DNS, Servers
dereckson merged T761: Automate to create subdomains DNS records into T1217: Host our DNS servers.
Sun, Sep 14, 23:06 · DNS, Servers
dereckson moved T1218: Provision primary DNS server from Backlog to DNS Server / KnotDNS on the DNS board.
Sun, Sep 14, 23:05 · Restricted Project, DNS, Servers
dereckson moved T1217: Host our DNS servers from Backlog to DNS Server / KnotDNS on the DNS board.
Sun, Sep 14, 23:05 · DNS, Servers
dereckson added a project to T1217: Host our DNS servers: DNS.
Sun, Sep 14, 23:05 · DNS, Servers
dereckson closed T1219: Provision secondary DNS server, a subtask of T1217: Host our DNS servers, as Wontfix.
Sun, Sep 14, 23:04 · DNS, Servers
dereckson closed T1219: Provision secondary DNS server as Wontfix.

Per T2105, current solution is to use an external provider (Hurricane Electric?) to host our secondary zone.

Sun, Sep 14, 23:04 · DNS, Servers
dereckson moved T1219: Provision secondary DNS server from Backlog to DNS Server / KnotDNS on the DNS board.
Sun, Sep 14, 23:02 · DNS, Servers
dereckson moved T2014: Serve https://nasqueron.org from web-001 from Backlog to DNS records on the DNS board.
Sun, Sep 14, 23:02 · Alkane, DNS, Servers
dereckson moved T2105: Use HE as secondary DNS server from Backlog to DNS Server / KnotDNS on the DNS board.
Sun, Sep 14, 23:02 · DNS, Servers
dereckson moved T1610: Deploy Jitsi Meet instance from Current focus to Backlog on the Product evaluation board.
Sun, Sep 14, 22:14 · Operations sprints (Ignite Alkane Propulsion), Wolfplex migration, XMPP, Nasqueron Docker deployment squad, Servers, Product evaluation
dereckson renamed T2125: Review Vault policies from vault_secrets_by_role from Review Vault policies to Review Vault policies from vault_secrets_by_role.
Sun, Sep 14, 00:58 · Nasqueron Docker deployment squad, Servers
dereckson triaged T2125: Review Vault policies from vault_secrets_by_role as High priority.
Sun, Sep 14, 00:57 · Nasqueron Docker deployment squad, Servers

Fri, Sep 12

dereckson moved T2123: Fix tests for operations repository from Backlog to Ops on the Technical debt board.
Fri, Sep 12, 17:51 · Technical debt, Servers
dereckson moved T2123: Fix tests for operations repository from Backlog to Pending review on the Servers board.
Fri, Sep 12, 17:51 · Technical debt, Servers
dereckson added a comment to T2123: Fix tests for operations repository.

Tests fix commits will be aggregated in datacube T2123-improve-tests-suite branch, so we can have a look of what's remaining to fix.

Fri, Sep 12, 17:50 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3665: Prune unused webserver-content index generator.
Fri, Sep 12, 17:46 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3664: Deploy the monitoring Vault policy.
Fri, Sep 12, 17:19 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3663: Fix node.resolve_network tests.
Fri, Sep 12, 17:15 · Technical debt, Servers

Thu, Sep 11

dereckson added a revision to T2123: Fix tests for operations repository: D3662: Read flatter docker_networks pillar.
Thu, Sep 11, 23:56 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3661: Avoid unittest deprecated aliases.
Thu, Sep 11, 23:09 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3660: Fix docker_containers app_port/host test.
Thu, Sep 11, 22:58 · Technical debt, Servers
dereckson added a comment to T2123: Fix tests for operations repository.

Tests commits will be aggregates in datacube T2123-improve-tests-suite branch, so we can have a look of what's remaining to fix.

Thu, Sep 11, 22:18 · Technical debt, Servers
dereckson added a revision to T2123: Fix tests for operations repository: D3659: Handle ssh_keys_by_forest and everywhere_tasks in pillar users test.
Thu, Sep 11, 22:16 · Technical debt, Servers
dereckson updated subscribers of T2123: Fix tests for operations repository.

Going to take this, as I wrote the tests suite, @DorianWinty will review.

Thu, Sep 11, 22:15 · Technical debt, Servers
dereckson triaged T2123: Fix tests for operations repository as High priority.
Thu, Sep 11, 22:15 · Technical debt, Servers

Wed, Sep 10

dereckson added a comment to T2067: Deploy an OpenBSD server.

Why not port encrypt to FreeBSD?

Wed, Sep 10, 22:57 · Servers
dereckson added a comment to T2081: Deploy Snuffleupagus.

Support for PHP 8.4 is still there.

Wed, Sep 10, 22:56 · PHP 8.x support, Product evaluation, Servers, Alkane
dereckson closed T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship as Resolved by committing rOPSe5ec87dfe258: Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:51 · Servers
dereckson closed T2115: Update Dwellers packages as Resolved.

Uninstalled certbot.
Pruned old Python 3 dependencies.
Updated EPEL repo to epel-release-10-6
Updated packages
Reinstalled certbot, now running under Python 3.12 too.

Wed, Sep 10, 22:30 · Servers
dereckson added a comment to T2115: Update Dwellers packages.

Just for information, working on T2113, I've first updated the packages non related to that conflict, so I had fresh packages for both systemd and selinux config.

Wed, Sep 10, 22:24 · Servers
dereckson added a comment to T2122: Package starship for EPEL.

https://snapcraft.io/starship - last update: 27 April 2023 - latest/edge

Wed, Sep 10, 22:10 · Servers
dereckson added a revision to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship: D3658: Allow systemd-hostnamed to create socket when called from Varlink.
Wed, Sep 10, 22:06 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Was looking to offer a fix upstream, like read hostname from /proc/sys/kernel/hostname on Linux, but then I've realised this is an interaction issue with snap, starship, systemd and SELinux.

Wed, Sep 10, 22:03 · Servers
dereckson triaged T2122: Package starship for EPEL as Low priority.
Wed, Sep 10, 22:00 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Decreasing priority, as it only occurs with Starship.

Wed, Sep 10, 21:12 · Servers
dereckson renamed T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship from systemd-hostnamed service can't be launched - SELinux blocks it to systemd-hostnamed service can't be launched - SELinux blocks it - starship.
Wed, Sep 10, 21:11 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Normal behavior observed with the policy:

Wed, Sep 10, 21:10 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

Still an error with last packages versions.

Wed, Sep 10, 21:09 · Servers
dereckson added a comment to T2113: systemd-hostnamed service can't be launched - SELinux blocks it - starship.

audit2allow policy

Wed, Sep 10, 21:01 · Servers
dereckson added a comment to T2103: Upgrade servers to FreeBSD 14.3.

Bumping for 14.3, are still going on, it makes sense to target latest version

Wed, Sep 10, 19:41 · Servers