Commit graph

1318 commits

Author SHA1 Message Date
bors[bot]
09a8509ab8
Merge
451: roles/security: update build04 r=Mic92 a=zowoq



Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2023-02-24 09:13:46 +00:00
zowoq
ce9562fa52 roles/security: update build04
follow up from dfc0db1caf
2023-02-24 18:19:30 +10:00
bors[bot]
9a8a3da024
Merge
450: gitignore .direnv in terraform dir r=Mic92 a=Mic92



Co-authored-by: Jörg Thalheim <joerg@thalheim.io>
2023-02-24 07:54:03 +00:00
Jörg Thalheim
f5a1b89672 gitignore .direnv in terraform dir 2023-02-24 08:53:30 +01:00
bors[bot]
0e4de72cb9
Merge
449: build04: rebuild machine r=Mic92 a=Mic92



Co-authored-by: Jörg Thalheim <joerg@thalheim.io>
2023-02-24 07:52:17 +00:00
Jörg Thalheim
14da49635f build04: fix flake attribute passwd to nixos-anywhere 2023-02-24 08:51:51 +01:00
Jörg Thalheim
7c4c6015a1 add envrc to terraform 2023-02-24 08:45:43 +01:00
Jörg Thalheim
dfc0db1caf build04: update age keys + ip address 2023-02-24 08:43:19 +01:00
Jörg Thalheim
1633958886 build04 increase from 512mb to 1Gib 2023-02-24 08:21:18 +01:00
Jörg Thalheim
aa85dbe59c build04: update install instruction 2023-02-24 08:21:09 +01:00
bors[bot]
9ea7fc756d
Merge
448: flake.lock: Update r=zowoq a=nix-infra-bot



Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2023-02-24 04:34:54 +00:00
github-actions[bot]
135d57e13a flake.lock: Update
Flake lock file updates:

• Updated input 'disko':
    'github:nix-community/disko/fafcaaefa3bd8ece07804b8110a5f0e43db60ae2' (2023-02-17)
  → 'github:nix-community/disko/8fddb2fd721365fa77ff68b709539639d4dc65d7' (2023-02-23)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/efc59894b1ba73cb745676616c56c780383d6788' (2023-02-19)
  → 'github:NixOS/nixpkgs/3d566e183b71fec07b6d466375190f9e79b1e735' (2023-02-22)
• Updated input 'sops-nix':
    'github:Mic92/sops-nix/1da7257baa1d6801c45d9d3dedae7ce79c0e6498' (2023-02-19)
  → 'github:Mic92/sops-nix/2c5828439d718a6cddd9a511997d9ac7626a4aff' (2023-02-21)
• Updated input 'srvos':
    'github:numtide/srvos/fbc606b9b0ac9a19b0519a990373d68acc4065bf' (2023-02-20)
  → 'github:numtide/srvos/bbc55aaa74bf831c09e70ec01d18634de8b965c9' (2023-02-23)
2023-02-24 03:03:30 +00:00
bors[bot]
9d0033e43e
Merge
447: hound: update r=zowoq a=zowoq



Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2023-02-23 23:14:27 +00:00
zowoq
de535b314c hound: update 2023-02-24 09:08:19 +10:00
bors[bot]
11fff5ea23
Merge
427: terraform: pin terraform and providers in separate flake r=zowoq a=zowoq



Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2023-02-23 22:32:54 +00:00
bors[bot]
1168c25c9b
Merge
446: docs: update Gandi logo r=zowoq a=nlewo



Co-authored-by: Antoine Eiche <lewo@abesis.fr>
2023-02-23 22:18:23 +00:00
Antoine Eiche
ea46d17581 docs: update Gandi logo 2023-02-23 17:17:26 +01:00
zowoq
f09e14935b terraform: pin terraform and providers in separate flake 2023-02-21 12:22:51 +10:00
bors[bot]
0d958270b6
Merge
444: flake.lock: Update r=zowoq a=nix-infra-bot



Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2023-02-20 03:31:50 +00:00
github-actions[bot]
d9474ff8d0 flake.lock: Update
Flake lock file updates:

• Updated input 'disko':
    'github:nix-community/disko/9afae0ba3685656cbe1910b33fad758dd483137f' (2023-02-14)
  → 'github:nix-community/disko/fafcaaefa3bd8ece07804b8110a5f0e43db60ae2' (2023-02-17)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/4987c7aacdeeed0b08fcd12ab1c5813b683be7d6' (2023-02-16)
  → 'github:NixOS/nixpkgs/efc59894b1ba73cb745676616c56c780383d6788' (2023-02-19)
• Updated input 'sops-nix':
    'github:Mic92/sops-nix/c5dab21d8706afc7ceb05c23d4244dcb48d6aade' (2023-02-12)
  → 'github:Mic92/sops-nix/1da7257baa1d6801c45d9d3dedae7ce79c0e6498' (2023-02-19)
• Updated input 'sops-nix/nixpkgs-stable':
    'github:NixOS/nixpkgs/d863ca850a06d91365c01620dcac342574ecf46f' (2023-02-12)
  → 'github:NixOS/nixpkgs/f27a4e2f6a3a23b843ca1c736e6043fb8b99acc1' (2023-02-19)
• Updated input 'srvos':
    'github:numtide/srvos/84fa35705a36d64c6467ac44b2f763137d2780a9' (2023-02-16)
  → 'github:numtide/srvos/fbc606b9b0ac9a19b0519a990373d68acc4065bf' (2023-02-20)
2023-02-20 03:11:24 +00:00
bors[bot]
f11040c0fb
Merge
441: flake.lock: Update r=zowoq a=nix-infra-bot



Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2023-02-17 23:19:05 +00:00
github-actions[bot]
1cb8de4c03 flake.lock: Update
Flake lock file updates:

• Updated input 'disko':
    'github:nix-community/disko/9b78d9668ead8d3c7e09d4bcdb68dc7947eb91e3' (2023-02-09)
  → 'github:nix-community/disko/9afae0ba3685656cbe1910b33fad758dd483137f' (2023-02-14)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/f8e875671f248c21a49a7f914117c28135d4c588' (2023-02-10)
  → 'github:NixOS/nixpkgs/4987c7aacdeeed0b08fcd12ab1c5813b683be7d6' (2023-02-16)
• Updated input 'sops-nix':
    'github:Mic92/sops-nix/8fec29b009c19538e68d5d814ec74e04f662fbd1' (2023-02-08)
  → 'github:Mic92/sops-nix/c5dab21d8706afc7ceb05c23d4244dcb48d6aade' (2023-02-12)
• Updated input 'sops-nix/nixpkgs-stable':
    'github:NixOS/nixpkgs/e32c33811815ca4a535a16faf1c83eeb4493145b' (2023-02-05)
  → 'github:NixOS/nixpkgs/d863ca850a06d91365c01620dcac342574ecf46f' (2023-02-12)
• Updated input 'srvos':
    'github:numtide/srvos/f9c21e31ef5a80aaa6b606d9a91e94e0fbc548d5' (2023-02-09)
  → 'github:numtide/srvos/84fa35705a36d64c6467ac44b2f763137d2780a9' (2023-02-16)
• Updated input 'treefmt-nix':
    'github:numtide/treefmt-nix/e9033eca3d7139fd499f310023ddc3bb5abff515' (2023-02-09)
  → 'github:numtide/treefmt-nix/819dd7f076832838bba238eceef9a3dbfc63f5d0' (2023-02-11)
2023-02-17 03:11:54 +00:00
bors[bot]
b8fa094a8d
Merge
439: .github/labeler.yml: add `sops secrets` label r=zimbatm a=zowoq



Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2023-02-16 15:38:22 +00:00
bors[bot]
404bb3dcf5
Merge
438: terraform: use Gandi for email r=zimbatm a=zimbatm



Co-authored-by: zimbatm <zimbatm@zimbatm.com>
2023-02-16 15:34:06 +00:00
zimbatm
8741b30043
terraform: use Gandi for email
Fix the DNS records so we can use the email forwarding service from
Gandi.
2023-02-16 16:33:39 +01:00
zowoq
a860c3a5ae .github/labeler.yml: add sops secrets label
useful to see if these files are touched to avoid merge conflicts
2023-02-16 21:04:31 +10:00
bors[bot]
ea1e01d3e0
Merge
436: remove outdated secrets r=zowoq a=zowoq



Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2023-02-16 11:00:33 +00:00
bors[bot]
e6112e5c44
Merge
437: update nixpkgs-update r=zowoq a=ryantm



Co-authored-by: Ryan Mulligan <ryan@ryantm.com>
2023-02-16 04:15:56 +00:00
Ryan Mulligan
fc5a7c5e49 update nixpkgs-update 2023-02-15 19:09:57 -08:00
zowoq
9dd9597e8b terraform: removed outdated secrets 2023-02-15 13:05:53 +10:00
zowoq
fad4356a85 roles/hercules-ci: removed outdated secrets 2023-02-15 12:59:10 +10:00
zowoq
125277a6bf build03: remove outdated secrets 2023-02-15 12:59:10 +10:00
bors[bot]
3cedcb98b6
Merge
418: use gandi for our domains r=zimbatm a=zimbatm



Co-authored-by: zimbatm <zimbatm@zimbatm.com>
2023-02-11 16:08:30 +00:00
zimbatm
9bae446a1a
use gandi for our domains 2023-02-11 17:00:31 +01:00
zimbatm
e62b523dcf
bump nixpkgs
Get the latest nixos-unstable that includes
https://github.com/NixOS/nixpkgs/pull/214956
2023-02-11 16:41:38 +01:00
bors[bot]
098674ea21
Merge
435: flake.lock: Update r=nix-infra-bot a=nix-infra-bot



Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2023-02-10 03:13:44 +00:00
github-actions[bot]
d272da408a flake.lock: Update
Flake lock file updates:

• Updated input 'disko':
    'github:nix-community/disko/b1a4ecb8ca5f9e5850514cc9ceef3c8aa2e97d6f' (2023-02-06)
  → 'github:nix-community/disko/9b78d9668ead8d3c7e09d4bcdb68dc7947eb91e3' (2023-02-09)
• Updated input 'flake-parts':
    'github:hercules-ci/flake-parts/bf53492df08f3178ce85e0c9df8ed8d03c030c9f' (2023-02-01)
  → 'github:hercules-ci/flake-parts/47478a4a003e745402acf63be7f9a092d51b83d7' (2023-02-09)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/977c06339c40c917e31478e91eece8195cf59b4b' (2023-02-05)
  → 'github:NixOS/nixpkgs/1991c407592877730c8414f128bd7ef8960f7dfe' (2023-02-09)
• Updated input 'nur-update':
    'github:nix-community/nur-update/4f538df8aa3fa35dfcd7643f4747b4791c2bbfba' (2023-01-24)
  → 'github:nix-community/nur-update/2611c6b34a38318c3f9ac769b5cc577975da825d' (2023-02-06)
• Updated input 'sops-nix':
    'github:Mic92/sops-nix/4d16c18787ba8ff80c1ff8db25c5ca56f68ceed3' (2023-02-05)
  → 'github:Mic92/sops-nix/8fec29b009c19538e68d5d814ec74e04f662fbd1' (2023-02-08)
• Updated input 'srvos':
    'github:numtide/srvos/2d566a2cfebc7409edd96448a8ff45b6a283e7bf' (2023-02-06)
  → 'github:numtide/srvos/f9c21e31ef5a80aaa6b606d9a91e94e0fbc548d5' (2023-02-09)
• Updated input 'treefmt-nix':
    'github:numtide/treefmt-nix/70e03145e26c2f3199f4320ecd9fd343f1129c60' (2023-02-05)
  → 'github:numtide/treefmt-nix/e9033eca3d7139fd499f310023ddc3bb5abff515' (2023-02-09)
2023-02-10 03:13:26 +00:00
bors[bot]
15057e7161
Merge
434: tasks.py: add ssh-to-age to shell and update comments r=Mic92 a=zowoq



Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2023-02-07 08:38:53 +00:00
zowoq
16962b3a09 tasks.py: add ssh-to-age to shell and update comments 2023-02-07 12:22:46 +10:00
bors[bot]
a6fb3a5457
Merge
433: build(deps): bump cachix/install-nix-action from 18 to 19 r=Mic92 a=dependabot[bot]



Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2023-02-06 21:15:58 +00:00
zowoq
2789ef0946 .github/workflows: remove GITHUB_TOKEN
now set by default
2023-02-07 07:05:11 +10:00
dependabot[bot]
9af145a926
build(deps): bump cachix/install-nix-action from 18 to 19
Bumps [cachix/install-nix-action](https://github.com/cachix/install-nix-action) from 18 to 19.
- [Release notes](https://github.com/cachix/install-nix-action/releases)
- [Commits](https://github.com/cachix/install-nix-action/compare/v18...v19)

---
updated-dependencies:
- dependency-name: cachix/install-nix-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-02-06 21:00:55 +00:00
bors[bot]
91ed604439
Merge
431: flake: `treefmt-nix` follow nixpkgs r=zimbatm a=zowoq



Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2023-02-06 09:12:02 +00:00
zowoq
fb8df7f054 flake: treefmt-nix follow nixpkgs
Flake lock file updates:

• Updated input 'treefmt-nix/nixpkgs':
    'github:nixos/nixpkgs/0591d6b57bfeb55dfeec99a671843337bc2c3323' (2023-02-04)
  → follows 'nixpkgs'
2023-02-06 14:43:20 +10:00
bors[bot]
e61a7a2707
Merge
430: flake.lock: Update r=nix-infra-bot a=nix-infra-bot



Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2023-02-06 02:56:55 +00:00
github-actions[bot]
6b92a84f32 flake.lock: Update
Flake lock file updates:

• Updated input 'disko':
    'github:nix-community/disko/c0c93e75d9949e1f1a6bfb393ecd26115ccb2a69' (2023-02-02)
  → 'github:nix-community/disko/b1a4ecb8ca5f9e5850514cc9ceef3c8aa2e97d6f' (2023-02-06)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/a0acf943cc65d56e6708c6a63731473a5752dedb' (2023-02-02)
  → 'github:NixOS/nixpkgs/977c06339c40c917e31478e91eece8195cf59b4b' (2023-02-05)
• Updated input 'sops-nix':
    'github:Mic92/sops-nix/a81ce6c961480b3b93498507074000c589bd9d60' (2023-02-01)
  → 'github:Mic92/sops-nix/4d16c18787ba8ff80c1ff8db25c5ca56f68ceed3' (2023-02-05)
• Updated input 'sops-nix/nixpkgs-stable':
    'github:NixOS/nixpkgs/a3a1400571e3b9ccc270c2e8d36194cf05aab6ce' (2023-02-01)
  → 'github:NixOS/nixpkgs/e32c33811815ca4a535a16faf1c83eeb4493145b' (2023-02-05)
• Updated input 'srvos':
    'github:numtide/srvos/238361f0494d56ae33b14f39e72ba68babf338db' (2023-02-02)
  → 'github:numtide/srvos/2d566a2cfebc7409edd96448a8ff45b6a283e7bf' (2023-02-06)
• Updated input 'treefmt-nix':
    'github:numtide/treefmt-nix/7b8b3f20d91ebafc0a4b885e92b8c164a0cccfec' (2023-02-02)
  → 'github:numtide/treefmt-nix/70e03145e26c2f3199f4320ecd9fd343f1129c60' (2023-02-05)
• Added input 'treefmt-nix/nixpkgs':
    'github:nixos/nixpkgs/0591d6b57bfeb55dfeec99a671843337bc2c3323' (2023-02-04)
2023-02-06 02:56:37 +00:00
bors[bot]
93f5e67d28
Merge
429: users: remove admins after quorum changes r=zowoq a=zowoq



Co-authored-by: zowoq <59103226+zowoq@users.noreply.github.com>
2023-02-05 00:37:34 +00:00
bors[bot]
62a2e7a550
Merge
428: flake.lock: Update r=zowoq a=nix-infra-bot



Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2023-02-03 08:20:43 +00:00
zowoq
3af85714fb users: remove admins after quorum changes
moved to roles/builder/users as trusted to keep access to the community builder

follow up to 232ff1eee5
2023-02-03 17:10:58 +10:00
github-actions[bot]
d5b4f2cbe0 flake.lock: Update
Flake lock file updates:

• Updated input 'disko':
    'github:nix-community/disko/aa26c0ce0d0ed8129cb404abafb75a9ece0e1af1' (2023-01-28)
  → 'github:nix-community/disko/c0c93e75d9949e1f1a6bfb393ecd26115ccb2a69' (2023-02-02)
• Updated input 'flake-parts':
    'github:hercules-ci/flake-parts/7c7a8bce3dffe71203dcd4276504d1cb49dfe05f' (2023-01-26)
  → 'github:hercules-ci/flake-parts/bf53492df08f3178ce85e0c9df8ed8d03c030c9f' (2023-02-01)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/bea4062a62e18615421e8f4ce7bc339529f1c106' (2023-01-29)
  → 'github:NixOS/nixpkgs/a0acf943cc65d56e6708c6a63731473a5752dedb' (2023-02-02)
• Updated input 'sops-nix':
    'github:Mic92/sops-nix/b6ab3c61e2ca5e07d1f4eb1b67304e2670ea230c' (2023-01-24)
  → 'github:Mic92/sops-nix/a81ce6c961480b3b93498507074000c589bd9d60' (2023-02-01)
• Updated input 'sops-nix/nixpkgs-stable':
    'github:NixOS/nixpkgs/918b760070bb8f48cb511300fcd7e02e13058a2e' (2023-01-22)
  → 'github:NixOS/nixpkgs/a3a1400571e3b9ccc270c2e8d36194cf05aab6ce' (2023-02-01)
• Updated input 'srvos':
    'github:numtide/srvos/d494d87d80474312eca0a0c3ebe36f69a0bd9173' (2023-01-30)
  → 'github:numtide/srvos/238361f0494d56ae33b14f39e72ba68babf338db' (2023-02-02)
• Updated input 'treefmt-nix':
    'github:numtide/treefmt-nix/d5ed9a1e6793f99b2e179d5dec9639e48ef22db7' (2023-01-23)
  → 'github:numtide/treefmt-nix/7b8b3f20d91ebafc0a4b885e92b8c164a0cccfec' (2023-02-02)
2023-02-03 03:03:56 +00:00