audit-pt1 #94
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "audit-pt1"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
split build offload from deploy -
nixbldRemote+nixbldKeyserved both roles, meaning every host held a private key that was root everywherebuilderuser (non-wheel,trusted-users) onbrigidonly - acceptsbuilderKeyforssh-ngbuild connectionsdeployeruser (wheel, passwordless sudo) replacesnixbldRemotefleet-wide - accepts freshdeployerKeybuilderKeysecret scoped to non-builder hosts only (outbound tobrigid);deployerKeylives exclusively in the runner's~/.ssh/id_ed25519ceremony/01-gen-keys.sh+ceremony/02-update-sops.shwalk through key generation + sops rotation; oldnixbldKeystays in sops until first successful deploy, thensops editit outstale
nix-configurationspaths fixed - repo renamed topantheona while back, several things missed itnh.flake,nixdserver settings (4 expr paths invscode.nix),ishtarborg backup pathbrigid.nixgetsspecialArgs = { inherit inputs self; }- silent with nostatic/brigid/today, confusing crash the moment one appearsborg failure alerting wired up - there's already been one silent-failure incident and nothing was catching repeats
borg-alert.service(oneshot, curl toathenasmtp over WG) added toborgbackup.nix;onFailureon every jobathenaalready trusts the full internal/48inmynetworks+ rspamdlocal_addrsdocs/added to.gitignore- fable audit report lives there, not meant to be trackedleft for later:
nixbldKeyremoval post-deploy, per-host age keys (audit #.1), second WG hub onminervaif a public port materializes