Baptiste Jonglez
7e88a88e04
prod: garage: Enable on-demand-tls check for *.garage S3 endpoint
...
We were hitting Let's Encrypt rate limits because we were generating
thousands of non-sense certificates like "foo.bar.baz.garage.deuxfleurs.fr"
See https://crt.sh
Subdomains of garage.deuxfleurs.fr only make sense when accessing buckets
through S3 with vhost-style, so let's enable the on-demand-tls check to
make sure that the bucket exists in Garage.
In the long term, we might want to have a wildcard certificate for this
usage, or simply stop supporting vhost-style S3 access.
2024-06-08 17:14:48 +02:00
Baptiste Jonglez
9fc22d72d4
garage: harmonize staging and prod (checks, services)
2024-06-08 16:43:18 +02:00
Baptiste Jonglez
cbb0093f2c
staging: garage: Handle *.garage.staging for vhost-style S3 and add on-demand TLS checks
2024-06-08 16:35:35 +02:00
Baptiste Jonglez
d4fb14347d
staging: Upgrade tricot for on-demand TLS checks
2024-06-08 16:34:16 +02:00
Baptiste Jonglez
bdc7376df4
staging: make tricot config closer to prod
2024-05-30 23:47:38 +02:00
Baptiste Jonglez
22dba1f35c
staging: enable IPv4 diplonat (UPnP) for corrin site
2024-05-30 23:42:48 +02:00
Baptiste Jonglez
7c174d6746
Revert "staging: disable allocation of grafana on piranha"
...
piranha is accessible on a more reliable network now.
2024-05-30 21:33:32 +02:00
Baptiste Jonglez
02bdc5a0c0
Move piranha to new network
2024-05-30 10:12:48 +02:00
726f4b2f32
Merge pull request 'cluster(prod): Add dathomir site' ( #25 ) from KokaKiwi/nixcfg:add-dathomir into main
...
Reviewed-on: #25
Reviewed-by: maximilien <me@mricher.fr>
2024-05-26 21:04:01 +00:00
37a2f781eb
prod(cluster/dathomir): Open more SSH ports
2024-05-26 23:00:39 +02:00
435cbeebfb
cluster(prod): Add oseille
2024-05-26 18:24:28 +02:00
3776734e50
style: Fix spacetab in cluster/prod/ssh_config
2024-05-26 17:04:33 +02:00
57628b508e
cluster(prod): Add io
2024-05-26 17:04:18 +02:00
3e0df95fe9
use diplonat autodiscovery to set ip addr
2024-05-18 15:45:00 +02:00
602c003e1e
update neptune IP address
2024-05-18 15:27:48 +02:00
e746768de1
hotfix garage
2024-05-17 20:29:05 +02:00
a513690004
cluster(prod): Add dathomir site and onion node
2024-05-15 11:50:49 +02:00
f55891ba21
migration Cryptpad sur Courgette (Neptune) depuis Abricot (Scorpio), avec reconfiguration des backups
2024-05-12 22:02:22 +02:00
9a6935ac90
ajout Boris en admin sur Cryptpad
2024-05-12 20:35:04 +02:00
Armaël Guéneau
3b777ddeb6
Move emails from ananas (in scorpio) to celeri (in neptune)
2024-05-12 17:09:05 +02:00
Armaël Guéneau
ca59237057
staging: disable allocation of grafana on piranha
...
piranha does not seem to be available from the outside world currently
2024-05-01 00:44:09 +02:00
28b58b3776
ajout max et vincent en admin cryptpad
2024-04-30 10:10:40 +02:00
Baptiste Jonglez
7db40a8dcf
Fix coturn that was failing with newer Nomad/Docker
...
Coturn was failing to start with the following error:
failed to create task for container: failed to create shim task: OCI
runtime create failed: runc create failed: unable to start container
process: exec: "/usr/local/bin/docker-entrypoint.sh": permission denied:
unknown
It seems to be caused by the recent NixOS update.
Either because Docker/runc is now more strict when checking if the
entrypoint is executable [1]
And/or because Nomad may mount the secrets directory with "noexec" [2].
In any case, the "local" directory [2] looks more appropriate, because
it's shared with the task while not being accessible to other tasks.
[1] https://github.com/opencontainers/runc/issues/3715
[2] https://developer.hashicorp.com/nomad/docs/concepts/filesystem
2024-04-28 18:01:52 +02:00
Baptiste Jonglez
c56ce9134c
Update woodpecker to latest 2.4.1
2024-04-28 13:31:15 +02:00
1d40a3c7c0
Merge pull request 'Update Woodpecker to v2.4.0' ( #24 ) from tixie/nixcfg:update-woodpecker-2.4.0 into main
...
Reviewed-on: #24
2024-04-28 11:25:06 +00:00
Baptiste Jonglez
5dc7c3132b
Fix link in CI setup doc
2024-04-28 13:23:54 +02:00
Armaël Guéneau
6307f7e62f
caribou: update ipv6 address after ISP change
2024-04-26 18:00:56 +02:00
e6bac83e02
Tricot ulimit
2024-04-25 09:13:06 +02:00
22fbadef2e
update woodpecker-agent to 2.4.0
2024-04-24 22:20:20 +02:00
43189a5fc2
update woodpecker-server to 2.4.0
2024-04-24 22:20:06 +02:00
ff7462b2c7
prod: update nomad to 1.6
2024-04-20 12:29:26 +02:00
972fc4ea7c
prod: nixos 23.11 and nomad 1.5
2024-04-20 10:58:36 +02:00
444306aa54
prod: allow woodpecker on neptune now with good ipv6
2024-04-20 10:20:04 +02:00
c6a1bb341f
prod: update nixos to 23.05
2024-04-20 10:09:55 +02:00
eddc95c5df
prod: update ip config for Free ISP at Neptune
2024-04-20 09:37:24 +02:00
fb871fd350
staging: accept nomad bsl license
2024-04-19 08:54:11 +02:00
27df86a7e5
fix pad when not in neptune, and allow android7 email to move to bespin
2024-04-19 08:53:48 +02:00
d817ad7b15
Merge branch 'poil'
2024-04-18 19:36:32 +02:00
1871f7bbff
ajout de Jill & Trinity en admins de CryptPad
2024-04-18 19:36:07 +02:00
18e73b18f3
Merge pull request 'cluster/prod(app): Upgrade CryptPad to 2024.3.0' ( #23 ) from KokaKiwi/nixcfg:crytptpad-upgrade-1 into main
...
Reviewed-on: #23
2024-04-18 17:35:36 +00:00
a817d764d3
déplacement du service cryptpad concombre -> abricot
2024-04-18 19:07:08 +02:00
9111997f84
cluster/prod(app): Add new CryptPad build files
2024-04-18 18:56:19 +02:00
d41e10bd25
cluster/prod(app): Upgrade CryptPad to 2024.3.0
2024-04-18 18:45:07 +02:00
718a23b74b
cluster/prod: Add kokakiwi to adminAccounts
2024-04-18 17:57:24 +02:00
96ead9a597
prod: garage v1.0.0-rc1
2024-04-01 20:11:24 +02:00
6152dc18d6
remove notice message for moderation
2024-03-29 15:48:21 +01:00
1a1ad0a8ad
staging: garage v1.0 rc1
2024-03-28 17:17:21 +01:00
5b89004c0f
staging: deploy garage 0.10 beta + fix monitoring
2024-03-28 11:56:51 +01:00
e4708a325d
add trinity.fr.eu.org to DKIM
2024-03-24 13:42:47 +00:00
05dcd1c6a6
Courderec.re domain in the DKIM table
2024-03-24 14:23:47 +01:00