Commit Graph

37 Commits

Author SHA1 Message Date
h7x4 630cbe2e78 WIP: temmie/userweb: inject users from passwd into httpd sandbox 2026-05-29 23:23:29 +09:00
Vegard Bieker Matthey c59c00f3fc gluttony: setup bluemap 2026-05-25 03:20:21 +02:00
Felix Albrigtsen f433ae1e15 ustetind: remove from sops
rg -. to the rescue
2026-05-22 10:01:15 +02:00
Vegard Bieker Matthey 9c93f15569 change agekey for ildkule and update keys
update keys
2026-05-21 17:27:11 +02:00
Daniel Olsen 11d1f8b442 bakke: the owls sick motorbike 2026-05-08 03:07:09 +02:00
Daniel Olsen 45f10be9b4 secrets: delete skrott 2026-05-08 03:01:11 +02:00
h7x4 683e4b2dbc lupine-3: update sops key 2026-04-19 01:26:12 +09:00
h7x4 8a9e92c706 lupine-5: update sops key 2026-04-19 00:38:24 +09:00
h7x4 a399f23785 lupine-{1,2,4}: update sops keys 2026-04-18 23:58:43 +09:00
Vegard Bieker Matthey b5fecc94a7 hosts: add skrot
Co-authored-by: System administrator <root@skrot.pvv.ntnu.no>
Reviewed-on: https://git.pvv.ntnu.no/Drift/pvv-nixos-config/pulls/124
Co-authored-by: Vegard Bieker Matthey <VegardMatthey@protonmail.com>
Co-committed-by: Vegard Bieker Matthey <VegardMatthey@protonmail.com>
2026-02-14 18:53:54 +01:00
Vegard Bieker Matthey 35907be4f2 update sops keys for skrott 2026-02-07 22:17:09 +01:00
h7x4 210f74dc59 secrets: sops updatekeys 2026-02-08 05:19:26 +09:00
h7x4 0f355046de .sops.yaml: add skrott 2026-01-26 13:53:16 +09:00
Vegard Bieker Matthey 1a62eee464 add vegardbm to sops.yaml 2026-01-16 07:36:43 +01:00
h7x4 5e18855c7c skrott: register sops with dibbler db url 2026-01-12 02:32:21 +09:00
h7x4 c66e04dd26 .sops.yaml: remove remains of jokum 2025-12-22 15:08:39 +09:00
felixalb 0491df32f7 Init bakke (!87)
New backup server just dropped!
This server is awfully slow, and the mdraid setup is awfully slow, and I doubt that this will be a good experience, but we now have a backup server again?

- Tried Disko and nixos-anywhere
- Tried using mdraid
- Found that md is ancient and bad
- Found that disko is 100% extra steps, and a lot more complicated and noisy than just formatting your disks yourself
- Found that systemd-boot doesn't support mdraid
- Found that we probably don't need to mirror the boot partition :)
- Found that old hardware is slow
- Found that old hardware can have poor support for iPXE with UEFI, and might do weird BIOS stuff on you when you least expect it
- Reaffirmed that zfs is love

Current disk layout:
- mdraid for boot/root disk
    - 4TB WD Red with 500MiB ESP with systemd-boot, Remaining mdraid - Old?
    - 4TB WD Red with 500MiB Unused partition, Remaining mdraid - Old?
- zfs pool "tank" for the actual backup data
    - 8TB Toshiba MG08 - New
    - 8TB Exos 7E10 - New

TODO:

- Document the death of Toriel on the wiki
- Document Bakke on the wiki
  - ... describing the poco loco disk layout
- Start backing stuff up
  - Restic? Borg? Rsync?
  - Make backup retention policy and zfs snapshot system
  - Document backup procedures

Reviewed-on: https://git.pvv.ntnu.no/Drift/pvv-nixos-config/pulls/87
Co-authored-by: Felix Albrigtsen <felix@albrigtsen.it>
Co-committed-by: Felix Albrigtsen <felix@albrigtsen.it>
2025-12-22 04:08:30 +01:00
Daniel Olsen 938e916025 update bicep key 2025-12-02 01:51:40 +01:00
Daniel Olsen d9a9fcfef1 danio has a new sops key 2025-12-02 01:40:54 +01:00
Albert 043099eb37 hosts/lupine: init
Co-authored-by: h7x4 <h7x4@nani.wtf>
2025-07-30 20:30:28 +02:00
h7x4 08b010cb93 kommode/sops: init 2025-03-16 14:04:09 +01:00
Øystein Tveit 1f85208587 hosts/ustetind: set up gitea-runners 2024-12-09 22:24:54 +01:00
Peder Bergebakken Sundt 9dbf5d56f5 fix whitespacing issues 2024-08-04 04:37:23 +02:00
Peder Bergebakken Sundt b52de48455 sops: add pederbs 2024-08-04 01:24:54 +02:00
felixalb 55e8f01d1d Upgrade ildkule (!36)
This PR is made while moving Ildkule from PVE on joshua, to Openstack on stack.it.ntnu.no.

- The main monitoring dashboard is moved from https://ildkule.pvv.ntnu.no to https://grafana.pvv.ntnu.no.
- A new service is added: uptime-kuma on https://uptime.pvv.ntnu.no.
- The (hardware) configuration for ildkule is updated to fit the new virtualization environment, boot loader, network interfaces, etc.
- Metrics exporters on other hosts should be updated to allow connections from the new host

As this is the first proper server running on openstack, and therefore outside our main IP range, we might discover challenges in our network structure. For example, the database servers usually only allow connections from this range, so Ildkule can no longer access it. This should be explored, documented and/or fixed as we move more services.

Reviewed-on: https://git.pvv.ntnu.no/Drift/pvv-nixos-config/pulls/36
Co-authored-by: Felix Albrigtsen <felix@albrigtsen.it>
Co-committed-by: Felix Albrigtsen <felix@albrigtsen.it>
2024-04-21 23:36:25 +02:00
Daniel Olsen fe4dd21acb add eirikwit to sops 2024-03-16 22:38:16 +01:00
Felix Albrigtsen 8ccf9e9298 Update keys and re-enable web services 2023-05-21 02:29:14 +02:00
Daniel Olsen ee73a964be move matrix to bicep 2023-05-08 03:38:59 +02:00
Daniel Olsen bddd7e438d update jokum sops secrets 2023-03-26 13:14:55 +02:00
h7x4 796155481f Add host bekkalokk
`bekkalokk` is a new machine, meant to host web services and eventually
miscellaneous services.
2023-01-29 01:51:35 +01:00
h7x4 5d50a9807e sops: reencrypt jokum secrets with felixalb keys 2023-01-22 00:47:22 +01:00
Felix Albrigtsen 92280cd3d3 Merge remote-tracking branch 'origin/main' into prometheus-stack 2023-01-14 22:49:21 +01:00
Felix Albrigtsen c84af91c2c Add ildkule host keys 2022-12-20 18:11:32 +01:00
Daniel Olsen d52a7295b5 sops: shamir secret setting does nothing 2022-12-18 10:58:00 +01:00
Daniel Olsen 57ff1fa17a Add oysteikt to secrets 2022-12-18 00:05:26 +01:00
felixalb 6b1f0eb090 Add host ildkule 2022-12-17 21:51:43 +01:00
Daniel Olsen 3ed65c6cfa Add sops for secret management 2022-12-07 10:16:07 +01:00