Commit graph

229 commits

Author SHA1 Message Date
Max
5bd83ec5c1 cluster/services/monitoring: make grafana highly available 2023-06-04 22:48:58 +02:00
Max
1aebeef6a2 cluster/services/monitoring: make tempo datasource externally accessible 2023-06-03 01:04:37 +02:00
Max
a55fc7bb44 cluster/services/ipfs: configure public gateway address on node 2023-06-02 23:39:41 +02:00
Max
3e0684ffb5 cluster/services/ipfs: make gateway consul service public 2023-06-02 23:26:44 +02:00
Max
56d0d07d26 cluster/services/ipfs: add consul service for gateway 2023-06-02 22:53:54 +02:00
Max
70f67f6e71 cluster/services/irc: no DNS indirection 2023-06-02 21:58:00 +02:00
Max
d308f80ab5 cluster/services/websites: no DNS indirection 2023-06-02 21:05:14 +02:00
Max
d264751a9f cluster/services/ipfs: metrics via grafana-agent 2023-06-02 18:50:02 +02:00
Max
a714c37cec cluster/services/ipfs: split remote api, rework gateway 2023-06-02 18:34:15 +02:00
Max
4fb9373f1f cluster/services/ipfs: split io tweaks 2023-06-02 17:51:00 +02:00
Max
f41265ed00 cluster/services/ipfs: switch to cluster otlp trace endpoint 2023-06-02 17:38:12 +02:00
Max
d0ec0c4f82 cluster/services/monitoring: make tempo otlp receivers externally accessible 2023-06-02 17:35:53 +02:00
Max
98b2537482 cluster/services/patroni: enable metrics 2023-06-01 23:18:22 +02:00
Max
6fb3a543b8 cluster/services/consul: enable metrics 2023-06-01 22:36:57 +02:00
Max
4dbfb3b6ab cluster/services/monitoring: provision dashboards 2023-06-01 00:41:00 +02:00
Max
a4888920df cluster/services/monitoring: add some dashboards 2023-06-01 00:41:00 +02:00
Max
6624e2b7c7 cluster/services/monitoring: refactor 2023-05-27 14:18:02 +02:00
Max
9b5e44461e cluster/services/monitoring: add blackbox_exporter 2023-05-27 13:44:31 +02:00
Max
68ca309c93 cluster/services/monitoring: use grafana-agent integrated node_exporter 2023-05-26 17:36:23 +02:00
Max
6cff7460f6 cluster/services/monitoring: configure remote write url 2023-05-26 17:03:33 +02:00
Max
6ecd210130 cluster/services/monitoring: make Prometheus accessible in host mesh 2023-05-26 16:26:24 +02:00
Max
c4d2a13912 cluster/services/monitoring: remove Jitsi monitoring 2023-05-26 16:15:20 +02:00
Max
1945265362 cluster/services/monitoring: use grafana-agent for central logging 2023-05-26 15:02:28 +02:00
Max
f24d794215 cluster/services/ipfs: OTel sampling: 0.01 -> 0.50 2023-05-13 23:29:53 +02:00
Max
05bfdae17c cluster/services/monitoring: switch grafana to postgres 2023-05-13 16:42:40 +02:00
Max
09f40ffde5 VEGAS/monitoring: move to cluster 2023-05-13 16:42:40 +02:00
Max
8d8ea8edaa cluster/services/monitoring: enable systemd collector on node_exporter 2023-05-08 21:25:35 +02:00
Max
c5541eadb1 cluster/services/ipfs: allow access to DNS servers 2023-04-12 23:25:55 +02:00
Max
7d4b7470c8 treewide: re-encode secrets for prophet 2023-04-12 20:36:53 +02:00
Max
21e9cf9c53 cluster/services/certificates: install certs on prophet 2023-04-12 19:37:32 +02:00
Max
2adcd30e42 cluster/services/consul: enable agent on prophet 2023-04-12 19:36:26 +02:00
Max
2146597a06 cluster/services/patroni: enable dcs failsafe mode 2023-03-31 18:19:18 +02:00
Max
e8d350b9a3 cluster/services/hercules-ci-multi-agent: remove custom agent package 2023-03-31 16:03:03 +02:00
Max
29c37f7a54 cluster/services/patroni: use integrated consul service registration 2023-03-24 17:52:48 +01:00
Max
1b22ad2c01 cluster/services/hercules-ci-multi-agent: configure HCI effects secrets for private-void 2023-03-23 19:43:44 +01:00
Max
9d4026b2e3 cluster/services/dns: add checkmate and thunderskin to clients 2023-03-22 23:27:35 +01:00
Max
ae07af5a80 cluster/services/dns: client: use more DNS servers 2023-03-22 23:23:14 +01:00
Max
7985d891a0 cluster/services/dns: improve resiliency 2023-03-22 23:00:29 +01:00
Max
694bd7d712 cluster/services/wireguard: use hostLinks 2023-03-22 21:26:02 +01:00
Max
72636cfffb cluster/services/wireguard: remove extraPeers 2023-03-22 21:14:46 +01:00
Max
23b4929f5d cluster/services/patroni: run worker on thunderskin 2023-03-22 18:07:16 +01:00
Max
4a6e329391 cluster/services/acme-client: configure on thunderskin 2023-03-22 00:05:07 +01:00
Max
a0fa03ab05 cluster/services/wireguard: fix mesh config for thunderskin 2023-03-21 23:56:19 +01:00
Max
eaa164d6ab cluster/services/certificates: install internal wildcard cert on thunderskin 2023-03-21 23:55:22 +01:00
Max
faf9fca341 cluster/services/consul: run server agent on thunderskin 2023-03-21 23:51:35 +01:00
Max
769dcdac3f cluster/services/monitoring: monitor thunderskin 2023-03-21 23:51:02 +01:00
Max
3c6e5fae77 cluster/services/nginx: host on thunderskin 2023-03-21 23:49:49 +01:00
Max
5872083e56 cluster/services/websites: host on thunderskin 2023-03-21 23:44:38 +01:00
Max
8be3c9084c hosts/thunderskin: init 2023-03-20 20:03:20 +01:00
Max
1c27955577 cluster: use new hosts style 2023-03-11 19:48:30 +01:00
Max
be919cb2b3 treewide: pipe /modules through flake-parts 2023-03-11 19:48:30 +01:00
Max
9b71bd9a59 cluster/services/consul: add recursors 2023-03-06 21:52:29 +01:00
Max
ff09634883 cluster/services/dns: resolve via consul 2023-03-06 21:52:17 +01:00
Max
cfe4513627 cluster/services/dns: enable alias records 2023-03-06 21:10:22 +01:00
Max
a62db21de2 cluster/services/dns: enable Lua records 2023-03-06 18:28:55 +01:00
Max
789566e224 cluster/services/patroni: improve health checks 2023-03-06 18:05:04 +01:00
Max
5b0560752a cluster/services/consul: provide internal remote API access 2023-03-06 17:58:29 +01:00
Max
b56e484bd6 cluster/services/certificates: init, add internal wildcard cert 2023-03-06 16:52:52 +01:00
Max
2348b8f0f3 cluster/services/patroni: add a service health check for postgres itself 2023-03-06 16:45:49 +01:00
Max
4d6c88ce97 modules/consul-service-registry: allow binding multiple services to one systemd unit 2023-03-06 16:42:14 +01:00
Max
027d681ede cluster/services/dns: run authoritative nameserver on checkmate 2023-03-06 16:21:40 +01:00
Max
2b6b6964b7 cluster/services/dns: handle consul addr requests correctly 2023-03-06 00:49:44 +01:00
Max
63b9957926 cluster/services/websites: register with consul 2023-03-06 00:48:49 +01:00
Max
baf8fe481e cluster/services/patroni: register with consul 2023-03-06 00:28:15 +01:00
Max
363c54b0f6 cluster/services/irc: register with consul 2023-03-06 00:12:00 +01:00
Max
3be1bc9336 cluster/services/dns: register with consul 2023-03-05 23:50:50 +01:00
Max
8be69d13ad cluster/services/dns: forward consul domain 2023-03-05 22:16:06 +01:00
Max
b362ef59cf cluster/services/consul: use proper subdomain 2023-03-05 22:14:05 +01:00
Max
347cb9dfe7 cluster/services/consul: rename datacenter 2023-03-05 22:00:43 +01:00
Max
2a5094c284 cluster/services/dns: put coredns in front of powerdns 2023-03-05 22:00:18 +01:00
Max
59795e6fb1 cluster/services/dns: generify coredns config 2023-03-05 21:21:10 +01:00
Max
39134f74c3 cluster/services/patroni: switch to consul, remove etcd 2023-03-05 20:51:20 +01:00
Max
9a1fa4e418 cluster/services/consul: init 2023-03-05 20:39:15 +01:00
Max
b854cfdde4 cluster/services/acme-client: add checkmate to hosts 2023-03-01 22:45:23 +01:00
Max
ea12ce8b31 cluster/services/nginx: add checkmate to hosts 2023-03-01 22:40:16 +01:00
Max
5830db1c19 cluster/services/websites: add checkmate to hosts 2023-03-01 22:37:51 +01:00
Max
d3e71fc2cf cluster/services/monitoring: add checkmate to monitoring clients 2023-03-01 22:37:16 +01:00
Max
006ef68577 cluster/services/patroni: give etcd some more time to start 2023-03-01 21:52:06 +01:00
Max
cbd4f79a45 cluster/services/patroni: add checkmate to etcd nodes 2023-03-01 21:52:06 +01:00
Max
f6311ec7c4 cluster/services/wireguard: add checkmate to host mesh 2023-03-01 21:52:06 +01:00
Max
30e92d89c8 cluster/services/dns: give powerdns-admin some more time to start 2023-01-30 23:07:10 +01:00
Max
6d6664ce0b cluster/services/hercules-ci-multi-agent: cleanup 2023-01-08 22:34:52 +01:00
Max
90abb5792e cluster/services/hercules-ci-multi-agent: use our patched hercules-ci-agent 2023-01-08 22:34:52 +01:00
Max
930c533782 packages/powerdns-admin: patch to support new authlib, use server_metadata_url instead of manual configuration 2023-01-01 14:36:02 +01:00
Max
eb7bf281d7 cluster/services/hercules-ci-multi-agent: fix secrets 2022-11-23 17:32:31 +01:00
Max
677f49563b cluster/services/hercules-ci-multi-agent: add some more agents
- nixpak: prophet
- max: VEGAS, prophet
2022-11-23 17:12:30 +01:00
Max
1423a45b3a cluster/services/hercules-ci-multi-agent: init
obsoletes modules/hercules-ci-agent

Hercules CI orgs:
- private-void
- nixpak
2022-11-23 16:24:04 +01:00
Max
3c8bbf3bde cluster/services/ipfs: filter private addresses 2022-11-17 15:55:28 +01:00
Max
bafd0a0c83 cluster/services/ipfs: better routing 2022-11-15 23:39:46 +01:00
Max
70970765ac cluster/services/ipfs: fix Peering.Peers format 2022-11-14 00:49:38 +01:00
Max
f0aeeb78a1 cluster/services/ipfs: peer with other nodes 2022-11-14 00:01:09 +01:00
Max
5443c97e03 cluster/services/ipfs: enable QUIC 2022-11-13 23:44:12 +01:00
Max
c48af5a7a6 cluster/services/ipfs: use PL bootstrap nodes 2022-11-13 00:58:49 +01:00
Max
524a2560be cluster/services/ipfs: stop using pnet 2022-11-13 00:35:00 +01:00
Max
784be19d88 Revert "cluster/services/nginx: switch to OpenSSL 1.1 to mitigate a to-be-disclosed vulnerability"
This reverts commit 41448f0c23.
Fixed upstream: https://github.com/NixOS/nixpkgs/pull/199001
2022-11-02 20:50:05 +01:00
Max
41448f0c23 cluster/services/nginx: switch to OpenSSL 1.1 to mitigate a to-be-disclosed vulnerability 2022-10-31 18:42:09 +01:00
Max
d560d76028 cluster/services/nginx: init from host-specific modules 2022-10-31 18:14:39 +01:00
Max
64cdf850b9 cluster/services/ipfs: use custom IPFS service module 2022-10-22 16:28:02 +02:00
Max
0af4177b2a cluster/services/irc: specify ircOpers globally 2022-10-22 14:13:59 +02:00
Max
1def40063d cluster/services/irc: refactor with hostLinks 2022-10-22 14:12:37 +02:00
Max
fc2944edf2 cluster/services/ipfs: expose pinning service API cluster endpoint 2022-10-22 02:29:56 +02:00
Max
b56ba5f7eb cluster/services/ipfs: add ipfs-cluster 2022-10-22 01:19:14 +02:00
Max
41aad67a83 cluster/services/ipfs: init from modules/ipfs 2022-10-19 20:33:36 +02:00
Max
a80381fac1 cluster/services/patroni: auto-restart etcd 2022-10-18 23:06:34 +02:00
Max
142a640154 treewide: apply deadnix fixes 2022-10-17 14:54:48 +02:00
Max
dbbf2330fd treewide: apply statix fixes 2022-10-17 14:47:11 +02:00
Max
4c1fca0a20 cluster/services/irc: coerce keyfile properly 2022-09-23 22:06:45 +02:00
Max
456f7e230e cluster/services/irc: add persistent #general 2022-09-18 23:39:37 +02:00
Max
fc845158d8 cluster/services/irc: add oper configuration 2022-09-18 23:37:50 +02:00
Max
1ffd88cfe3 cluster/services/irc: add PAM configuration 2022-09-18 23:05:03 +02:00
Max
92c9f5d680 cluster/services/irc: init 2022-09-18 22:13:06 +02:00
Max
8962c1072e cleanup 2022-09-01 23:05:39 +02:00
Max
59671eb356 cluster/services/websites: host Excalidraw 2022-08-28 23:15:14 +02:00
Max
f881ff7ba6 cluster/services/patroni: make HAProxy provide postgresql.service via alias 2022-08-10 01:18:03 +02:00
Max
175d3c8b13 cluster/services/websites: init 2022-08-09 20:10:25 +02:00
Max
52459c42c1 cluster/services/acme-client: init 2022-08-07 21:06:17 +02:00
Max
cfd82880e4 cluster/services/dns: load API key directly 2022-08-07 20:59:16 +02:00
Max
0eed86421b cluster/services/dns: add resolver client config 2022-08-07 20:01:48 +02:00
Max
5356ba97c6 cluster/services/dns: init 2022-08-07 20:01:48 +02:00
Max
6b998f4ec2 cluster/services/patroni: allow any user to connect 2022-08-07 19:57:35 +02:00
Max
a14ba1235a cluster/services/patroni: init 2022-08-04 23:57:54 +02:00
Max
12fe9620e9 cluster/services/wireguard: expose meshNet in vars 2022-08-04 23:25:37 +02:00
Max
f5d5c3e538 cluster/services/wireguard: add external etcd node to mesh net 2022-08-04 23:25:16 +02:00
Max
8a7f929cc7 cluster/services/monitoring: adjust Jitsi monitoring 2022-08-04 13:53:32 +02:00
Max
70ee7d9ccf cluster/services/wireguard: add extra routes 2022-08-04 00:27:21 +02:00
Max
31d9afaef5 cluster/services/wireguard: trust interface 2022-08-04 00:13:59 +02:00
Max
c8beafd021 modules/monitoring: convert to cluster service 2022-08-03 23:36:11 +02:00
Max
1dae0738eb cluster/services/wireguard: init 2022-08-03 23:04:21 +02:00
Max
cf1dd21418 cluster: init 2022-08-03 23:04:19 +02:00