Commit Graph

521 Commits (main)

Author SHA1 Message Date
stuebinm 17149be4bd update inputs 1 week ago
stuebinm 920ea9e8d4 flake updates & mattermost 8.1.5 → 8.1.6 2 weeks ago
stuebinm f03a582345 updates: mattermost 8.1.4 → 8.1.5 3 weeks ago
stuebinm 641c59092c fix a mistake in flake outputs
`nix run ...` should run websites; I broke this earlier.
4 weeks ago
stuebinm b5855fe379 unpin nix-hexchen
bug which broke things in 448ea1b831
got fixed upstream.
4 weeks ago
Raphael Weniger 0f19d712cb Removed <del>-tag at link 4 weeks ago
stuebinm 448ea1b831 updates, but pin older nix-hexchen 4 weeks ago
stuebinm ea5a77703e updates
general updates of flake input & mattermost minor version bump (8.1.3 → 8.1.4)
1 month ago
stuebinm 8186160c1b update nixpkgs 1 month ago
stuebinm e03bf84d3a mattermost: jump ESR versions 7.8.x → 8.1.3
package definition adjusted by comparing to the current version in
2 months ago
stuebinm a4288d77ce update
(inputs & mattermost security release)
2 months ago
stuebinm 3ce4b83464 update inputs 2 months ago
stuebinm 9e7929ab5f fix auamost

fish doesn't find jq if it's not in environment.systemPackages, dunno why.
2 months ago
stuebinm a8f7ee667d downgrade nextcloud module
whoops, forgot to commit this bit in the remove-unstable commit, and
lack energy to go back & amend & rebase
2 months ago
stuebinm eae84263f5 less verbose container definitions
move some options (the nopersist & container profiles + allowUnfree
packages) into the evalConfig used for containers, so we don't have to
repeat ourselves as much.

also removed some no-longer-needed specialArgs.

also made thelounge work with nopersist, which for some reason it didn't
use before.
2 months ago
stuebinm 6586f0c552 remove unstable
this downgrades vaultwarden back to what's in stable; this was the last
thing we used from unstable, so remove that as well.
2 months ago
stuebinm f9d7496af7 various absurd fixes 2 months ago
stuebinm a17cd69a52 keep using the old uffd's pythonPackages, lol 2 months ago
stuebinm 54fe6bfce7 Revert "new uffd packaging"
This reverts commit 90f4971e88, and resets
the uffd version to the one we are already using, in hopes of making the
update slightly less painfull (haha).
2 months ago
stuebinm 17ead057f4 update inputs 2 months ago
stuebinm 3407e873ef new uffd packaging 2 months ago
stuebinm 4b40d665fe update inputs
this now no longer needs to be built with allow_broken; tracktrain's
packaging now includes an override to remove the marked-broken state.
2 months ago
stuebinm 6529cb79a0 update inputs 2 months ago
stuebinm 72ca5b2888 initial work for 23.05
in theory this might be ready to deploy. Potential hazards & things to
know when actually doing so:

 1. the mysql version used by mattermost was updated (the old uses an
    openssl which is marked insecure). Might have to migrate a database
 2. lots of settings now use RFC 42-style settings, which might contain
    new typos
 3. this updates uffd (& changes the patches we apply). Since version
    dependencies of uffd are basically "whatever debian has" we have
    never bothered to match them, but afaik have also never updated uffd
    since the initial deploy some years ago. No guarantee it still
 4. tracktrain depends on haskellPackages.conferer-warp, which is
    currently marked broken. There is no reason for this (it builds
    fine). Until fixed upstream, build with NIXPKGS_ALLOW_BROKEN=1.
    cf.; waiting for a
    merge of haskell-updates into 23.05
2 months ago
stuebinm 74654f2fc0 websites: rooms on libera → 2 months ago
stuebinm 4fb06c3e10 mattermost 7.8.10 → 7.8.11
(another security update)
2 months ago
stuebinm d7d15f4b0b websites: chats are on for now 3 months ago
stuebinm c18215f356 mattermost 7.8.8 → 7.8.10 3 months ago
stuebinm 6a4ff47443 mattermost 7.8.7 → 7.8.8 4 months ago
stuebinm 109aada070 mattermost 7.8.5 → 7.8.7 5 months ago
Moira 2d542e9167 remove 6 months ago
stuebinm d8e937a91d mattermost: 7.1.8 → 7.8.5 6 months ago
stuebinm 57b6eac7c2 tracktrain: upstream is slow in updating gtfs, use our own
note: I am author of both the file now under /persist/containers/tracktrain
& the upstream one at, but don't have direct access to the
wordpress instance running there, and no one who does has yet uploaded
the new file.
7 months ago
stuebinm e5d57ebec9 sops/tracktrain: fix a missed non-declarative secret 7 months ago
stuebinm 6a51e74c73 enable receiving mail on mattermost@
otherwise we apparently cause feedback loops? pfft.
7 months ago
stuebinm 5bd2c5ab4c remove apparently unnecessary nextcloud config 7 months ago
stuebinm 3099798468 remove apparently unnessary mattermost lib.mkForce 7 months ago
stuebinm b5d4f76a1d rotate octycs's ssh key 7 months ago
stuebinm 003f2f7e44 move all on-disk secrets into sops
this only concerns secrets which are in a raw file. Some of our
services (e.g. nextclouds) keeps secrets in its database; these remain

Not yet deployed because of shitty train internet.
7 months ago
stuebinm 0d75469590 rotate zauberberg's ssh key 7 months ago
stuebinm 49fa2325f3 sops-nix proof of concept
this is currently deployed and appears to be working. please everyone
have a look at it & then decide if we want to use this for the other
secrets as well.
7 months ago
stuebinm a3689d1c76 mattermost: 7.1.7 → 7.1.8
this is a security update, see
for more.
8 months ago
stuebinm eda184ee48 netbox: remove python override workaround
this is currently unused anyways, but in case we ever do need it again, has removed the need for
the weird override workaround.
8 months ago
stuebinm 8d9df0e20e mattermost: 7.1.4 → 7.1.7
apparently the 7.1.x series is now old enough that even though it
does still get security fixes, the mattermost team no longer mentions
this on their blog, so we missed out on a couple. fun!
8 months ago
stuebinm fb3c1b0a96 symlink haccfiles into /etc/haccfiles
 - we will no longer get confused about which state is currently deployed
 - deploys get slower, since it has to uploads the entire haccfiles each time
8 months ago
stuebinm b30df7ea6d unbreak tracktrain css 9 months ago
stuebinm 26f3f98a9c update inputs 9 months ago
Moira f91ea850bc
mail: reenable recieving mail on noreply@
because mail providers are sending out abuse mails for fbls they're
causing *shrung*
9 months ago
stuebinm a6d21f4fd9 make working on websites nicer
(since every time we have to change anything on these I get annoyed at
having to remember how to build these. Now you can just use `nix run`!)
9 months ago
stuebinm 7fd1c9ff80 remove the default.nix file
(why did we keep this around? in any case, it's broken)
9 months ago