Tags: JakeHillion/nixos
Tags
sundown: retire the legacy-full-access Nebula group sundown is the first host to drop the broad legacy-full-access group as part of splitting Nebula access into per-service cert groups. It only serves Tang inbound, and every path it initiates (irisd peer cache, etcd, journald upload) is already covered by the fleet-wide irisd-client, etcd-client, and journal-client groups from ogygia.nix/defaults.nix. Removing the group leaves sundown with no host-level groups, matching fanboy. Its cert was re-signed for the new spec. Test plan: - nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel' - CI - Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work
sundown: retire the legacy-full-access Nebula group sundown is the first host to drop the broad legacy-full-access group as part of splitting Nebula access into per-service cert groups. It only serves Tang inbound, and every path it initiates (irisd peer cache, etcd, journald upload) is already covered by the fleet-wide irisd-client, etcd-client, and journal-client groups from ogygia.nix/defaults.nix. Removing the group leaves sundown with no host-level groups, matching fanboy. Its cert was re-signed for the new spec. Test plan: - nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel' - CI - Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work
sundown: retire the legacy-full-access Nebula group sundown is the first host to drop the broad legacy-full-access group as part of splitting Nebula access into per-service cert groups. It only serves Tang inbound, and every path it initiates (irisd peer cache, etcd, journald upload) is already covered by the fleet-wide irisd-client, etcd-client, and journal-client groups from ogygia.nix/defaults.nix. Removing the group leaves sundown with no host-level groups, matching fanboy. Its cert was re-signed for the new spec. Test plan: - nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel' - CI - Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work
chore(deps): update ghcr.io/chia-network/chia docker tag to v2.7.2
sundown: retire the legacy-full-access Nebula group sundown is the first host to drop the broad legacy-full-access group as part of splitting Nebula access into per-service cert groups. It only serves Tang inbound, and every path it initiates (irisd peer cache, etcd, journald upload) is already covered by the fleet-wide irisd-client, etcd-client, and journal-client groups from ogygia.nix/defaults.nix. Removing the group leaves sundown with no host-level groups, matching fanboy. Its cert was re-signed for the new spec. Test plan: - nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel' - CI - Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work
sundown: retire the legacy-full-access Nebula group sundown is the first host to drop the broad legacy-full-access group as part of splitting Nebula access into per-service cert groups. It only serves Tang inbound, and every path it initiates (irisd peer cache, etcd, journald upload) is already covered by the fleet-wide irisd-client, etcd-client, and journal-client groups from ogygia.nix/defaults.nix. Removing the group leaves sundown with no host-level groups, matching fanboy. Its cert was re-signed for the new spec. Test plan: - nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel' - CI - Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work
sundown: retire the legacy-full-access Nebula group sundown is the first host to drop the broad legacy-full-access group as part of splitting Nebula access into per-service cert groups. It only serves Tang inbound, and every path it initiates (irisd peer cache, etcd, journald upload) is already covered by the fleet-wide irisd-client, etcd-client, and journal-client groups from ogygia.nix/defaults.nix. Removing the group leaves sundown with no host-level groups, matching fanboy. Its cert was re-signed for the new spec. Test plan: - nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel' - CI - Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work
sundown: retire the legacy-full-access Nebula group sundown is the first host to drop the broad legacy-full-access group as part of splitting Nebula access into per-service cert groups. It only serves Tang inbound, and every path it initiates (irisd peer cache, etcd, journald upload) is already covered by the fleet-wide irisd-client, etcd-client, and journal-client groups from ogygia.nix/defaults.nix. Removing the group leaves sundown with no host-level groups, matching fanboy. Its cert was re-signed for the new spec. Test plan: - nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel' - CI - Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work
chore(deps): update ghcr.io/chia-network/chia docker tag to v2.7.2
sundown: retire the legacy-full-access Nebula group sundown is the first host to drop the broad legacy-full-access group as part of splitting Nebula access into per-service cert groups. It only serves Tang inbound, and every path it initiates (irisd peer cache, etcd, journald upload) is already covered by the fleet-wide irisd-client, etcd-client, and journal-client groups from ogygia.nix/defaults.nix. Removing the group leaves sundown with no host-level groups, matching fanboy. Its cert was re-signed for the new spec. Test plan: - nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel' - CI - Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work
PreviousNext