aboutsummaryrefslogtreecommitdiff
path: root/cluster/prod/app/garage
Commit message (Collapse)AuthorAgeFilesLines
* prod: garage: Enable on-demand-tls check for *.garage S3 endpointBaptiste Jonglez2024-06-081-0/+1
| | | | | | | | | | | | | | We were hitting Let's Encrypt rate limits because we were generating thousands of non-sense certificates like "foo.bar.baz.garage.deuxfleurs.fr" See https://crt.sh Subdomains of garage.deuxfleurs.fr only make sense when accessing buckets through S3 with vhost-style, so let's enable the on-demand-tls check to make sure that the bucket exists in Garage. In the long term, we might want to have a wildcard certificate for this usage, or simply stop supporting vhost-style S3 access.
* garage: harmonize staging and prod (checks, services)Baptiste Jonglez2024-06-081-37/+36
|
* hotfix garageQuentin Dufour2024-05-171-1/+1
|
* prod: garage v1.0.0-rc1Alex Auvolat2024-04-012-1/+3
|
* garage: update to v0.9.2 finalAlex Auvolat2024-03-011-1/+1
|
* prod: update to garage 0.9.2-rc1Alex Auvolat2024-02-291-1/+1
|
* prod: update diplonat and make garage restart on template changes againAlex Auvolat2024-01-171-1/+1
| | | | | | | Diplonat update prevents unnecessary flapping of autodiscovered ip addresses, which was the cause of useless restarts of the garage daemon. But in principle we want Garage to be restarted if the ipv6 address changes as it indicates changes in the network.
* Revert "Revert "garage prod: use dynamically determined ipv6 addresses""Baptiste Jonglez2023-12-191-2/+11
| | | | | | Quentin's fix seems to work fine. This reverts commit e5f3b6ef0abe3ac67b652b4ece74c933e2c1b554.
* Revert "garage prod: use dynamically determined ipv6 addresses"Baptiste Jonglez2023-12-191-11/+2
| | | | | | | | | | | | | | This partially reverts commit 47e982b29d41e8b271100b9961b6766e96e009b1. This leads to invalid config: Dec 19 08:23:09 courgette 25f10ae4271c[781]: 2023-12-19T07:23:09.087813Z INFO garage::server: Loading configuration... Dec 19 08:23:09 courgette 25f10ae4271c[781]: Error: TOML decode error: TOML parse error at line 16, column 17 Dec 19 08:23:09 courgette 25f10ae4271c[781]: | Dec 19 08:23:09 courgette 25f10ae4271c[781]: 16 | rpc_bind_addr = "[<no value>]:3901" Dec 19 08:23:09 courgette 25f10ae4271c[781]: | ^^^^^^^^^^^^^^^^^^^ Dec 19 08:23:09 courgette 25f10ae4271c[781]: invalid socket address syntax Dec 19 08:23:09 courgette 25f10ae4271c[781]:
* stop reloading config fileQuentin Dufour2023-12-191-0/+1
|
* garage prod: use dynamically determined ipv6 addressesAlex Auvolat2023-12-132-4/+13
|
* Move garage's redirections to a dedicated serviceQuentin Dufour2023-12-041-3/+17
| | | | | | Reason: - do not slow down the garage web endpoint - required now that we map domain name to a garage bucket
* add degrowthQuentin Dufour2023-12-041-0/+1
|
* tricot updateQuentin Dufour2023-12-011-0/+1
|
* add some redirectionsQuentin Dufour2023-11-291-0/+2
|
* màj garage prodAlex Auvolat2023-10-161-3/+3
|
* remove default HTTP CSP, put your CSP in your HTMLQuentin Dufour2023-10-031-1/+0
|
* prod: remove all apps from orion, add some missing in scorpioAlex Auvolat2023-09-041-1/+1
|
* prod garage: add health check using admin api's '/health'Alex Auvolat2023-08-271-35/+64
|
* final cspQuentin Dufour2023-07-231-2/+1
|
* Simpler IPv6 config for GarageQuentin Dufour2023-07-231-4/+2
|
* linesQuentin Dufour2023-07-231-0/+2
|
* make specifying an ipv6 fully optionnalAlex Auvolat2023-04-211-2/+4
|
* update garage and let it use more ramAlex Auvolat2023-03-161-1/+2
|
* TODOs in deuxfleurs.nix because the old world is maybe mixing with the newAdrien2023-03-151-1/+1
|
* prod: garage v0.8.1Alex Auvolat2023-03-061-1/+1
|
* prod: deploy d53Alex Auvolat2023-01-042-98/+1
|
* Migrate prod cluster secrets to new formatAlex Auvolat2022-12-254-3/+14
|
* prod: enable site load balancing in tricotAlex Auvolat2022-12-061-0/+3
|
* Upgrade to garage v0.8.0-rc2Quentin Dufour2022-11-163-17/+79
|
* Deploy garage on bespinMaximilien Richer2022-10-161-1/+1
|
* Split garage deployments in 2 categoriesQuentin Dufour2022-10-082-6/+83
| | | | | - The ones that will receive some traffic from tricot - The ones "only for storage" that will not receive traffic from tricot
* Force Garage to use ipv6 connectivityAlex Auvolat2022-09-152-20/+2
|
* Update LDAP configurationQuentin Dufour2022-08-311-1/+1
|
* Remove garage files at bad location, add basic telemetryAlex Auvolat2022-08-254-1/+24
|
* Deploy MatrixQuentin Dufour2022-08-251-1/+6
|
* Reconfigure services to use correct tricot url, TLS failsAlex Auvolat2022-08-243-0/+156