Skip to content

Tags: JakeHillion/nixos

Tags

nextboot/sundown.st.neb.jakehillion.me

Toggle nextboot/sundown.st.neb.jakehillion.me's commit message
sundown: retire the legacy-full-access Nebula group

sundown is the first host to drop the broad legacy-full-access group as
part of splitting Nebula access into per-service cert groups. It only
serves Tang inbound, and every path it initiates (irisd peer cache, etcd,
journald upload) is already covered by the fleet-wide irisd-client,
etcd-client, and journal-client groups from ogygia.nix/defaults.nix.

Removing the group leaves sundown with no host-level groups, matching
fanboy. Its cert was re-signed for the new spec.

Test plan:
- nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel'
- CI
- Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work

nextboot/stinger.pop.neb.jakehillion.me

Toggle nextboot/stinger.pop.neb.jakehillion.me's commit message
sundown: retire the legacy-full-access Nebula group

sundown is the first host to drop the broad legacy-full-access group as
part of splitting Nebula access into per-service cert groups. It only
serves Tang inbound, and every path it initiates (irisd peer cache, etcd,
journald upload) is already covered by the fleet-wide irisd-client,
etcd-client, and journal-client groups from ogygia.nix/defaults.nix.

Removing the group leaves sundown with no host-level groups, matching
fanboy. Its cert was re-signed for the new spec.

Test plan:
- nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel'
- CI
- Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work

nextboot/slider.pop.neb.jakehillion.me

Toggle nextboot/slider.pop.neb.jakehillion.me's commit message
sundown: retire the legacy-full-access Nebula group

sundown is the first host to drop the broad legacy-full-access group as
part of splitting Nebula access into per-service cert groups. It only
serves Tang inbound, and every path it initiates (irisd peer cache, etcd,
journald upload) is already covered by the fleet-wide irisd-client,
etcd-client, and journal-client groups from ogygia.nix/defaults.nix.

Removing the group leaves sundown with no host-level groups, matching
fanboy. Its cert was re-signed for the new spec.

Test plan:
- nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel'
- CI
- Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work

nextboot/phoenix.st.neb.jakehillion.me

Toggle nextboot/phoenix.st.neb.jakehillion.me's commit message
chore(deps): update ghcr.io/chia-network/chia docker tag to v2.7.2

nextboot/maverick.cx.neb.jakehillion.me

Toggle nextboot/maverick.cx.neb.jakehillion.me's commit message
sundown: retire the legacy-full-access Nebula group

sundown is the first host to drop the broad legacy-full-access group as
part of splitting Nebula access into per-service cert groups. It only
serves Tang inbound, and every path it initiates (irisd peer cache, etcd,
journald upload) is already covered by the fleet-wide irisd-client,
etcd-client, and journal-client groups from ogygia.nix/defaults.nix.

Removing the group leaves sundown with no host-level groups, matching
fanboy. Its cert was re-signed for the new spec.

Test plan:
- nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel'
- CI
- Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work

nextboot/li.pop.neb.jakehillion.me

Toggle nextboot/li.pop.neb.jakehillion.me's commit message
sundown: retire the legacy-full-access Nebula group

sundown is the first host to drop the broad legacy-full-access group as
part of splitting Nebula access into per-service cert groups. It only
serves Tang inbound, and every path it initiates (irisd peer cache, etcd,
journald upload) is already covered by the fleet-wide irisd-client,
etcd-client, and journal-client groups from ogygia.nix/defaults.nix.

Removing the group leaves sundown with no host-level groups, matching
fanboy. Its cert was re-signed for the new spec.

Test plan:
- nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel'
- CI
- Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work

nextboot/cyclone.gw.neb.jakehillion.me

Toggle nextboot/cyclone.gw.neb.jakehillion.me's commit message
sundown: retire the legacy-full-access Nebula group

sundown is the first host to drop the broad legacy-full-access group as
part of splitting Nebula access into per-service cert groups. It only
serves Tang inbound, and every path it initiates (irisd peer cache, etcd,
journald upload) is already covered by the fleet-wide irisd-client,
etcd-client, and journal-client groups from ogygia.nix/defaults.nix.

Removing the group leaves sundown with no host-level groups, matching
fanboy. Its cert was re-signed for the new spec.

Test plan:
- nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel'
- CI
- Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work

nextboot/boron.cx.neb.jakehillion.me

Toggle nextboot/boron.cx.neb.jakehillion.me's commit message
sundown: retire the legacy-full-access Nebula group

sundown is the first host to drop the broad legacy-full-access group as
part of splitting Nebula access into per-service cert groups. It only
serves Tang inbound, and every path it initiates (irisd peer cache, etcd,
journald upload) is already covered by the fleet-wide irisd-client,
etcd-client, and journal-client groups from ogygia.nix/defaults.nix.

Removing the group leaves sundown with no host-level groups, matching
fanboy. Its cert was re-signed for the new spec.

Test plan:
- nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel'
- CI
- Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work

nextboot/bob.lt.neb.jakehillion.me

Toggle nextboot/bob.lt.neb.jakehillion.me's commit message
chore(deps): update ghcr.io/chia-network/chia docker tag to v2.7.2

current/sundown.st.neb.jakehillion.me

Toggle current/sundown.st.neb.jakehillion.me's commit message
sundown: retire the legacy-full-access Nebula group

sundown is the first host to drop the broad legacy-full-access group as
part of splitting Nebula access into per-service cert groups. It only
serves Tang inbound, and every path it initiates (irisd peer cache, etcd,
journald upload) is already covered by the fleet-wide irisd-client,
etcd-client, and journal-client groups from ogygia.nix/defaults.nix.

Removing the group leaves sundown with no host-level groups, matching
fanboy. Its cert was re-signed for the new spec.

Test plan:
- nix build '.#nixosConfigurations."sundown.st.neb.jakehillion.me".config.system.build.toplevel'
- CI
- Deploy, then verify SSH in/out, Prometheus/journal presence, ogygia auto-update, and Tang unlock still work