Compare commits

..
Author SHA1 Message Date
ahtlon c5e1667b16 [host builder] fix trusted-public-keys
Check flake syntax / flake-check (push) Successful in 23m23s
Hydra callback / on_pr (push) Skipped
Hydra callback / on_push (push) Skipped
turns out, the name is linked to the key and also not relevant to the substituter
2026-09-07 19:59:12 +02:00
ahtlon a6de2c394d Merge branch 'add_blackbox_metrics'
Check flake syntax / flake-check (push) Successful in 18m32s
2026-09-07 17:18:13 +02:00
ahtlon 8ee0a99ce7 [overwatch] blackbox: add more domains
Check flake syntax / flake-check (push) Successful in 12m17s
Hydra callback / on_pr (pull_request) Successful in 3m31s
Hydra callback / on_push (pull_request) Skipped
2026-09-07 16:59:01 +02:00
ahtlon 4c8253e8e3 [overwatch] enable and scrape metrics from hydra
Check flake syntax / flake-check (push) Successful in 10m15s
Hydra callback / on_pr (pull_request) Successful in 4m41s
Hydra callback / on_push (pull_request) Skipped
2026-09-04 18:21:39 +02:00
ahtlonandahtlon d50a9ddbbf [overwatch] add the blackbox exporter to monitor websites
Check flake syntax / flake-check (push) Successful in 12m9s
Hydra callback / on_pr (pull_request) Successful in 6m40s
Hydra callback / on_push (pull_request) Skipped
2026-09-01 21:02:37 +02:00
6 changed files with 164 additions and 30 deletions
Generated
+25 -25
View File
@@ -29,11 +29,11 @@
]
},
"locked": {
"lastModified": 1788076475,
"narHash": "sha256-sD4UyILWAhk7aexE3YpDOdb71ZEeL+1/+LV05XIWCBo=",
"lastModified": 1768143854,
"narHash": "sha256-E5/kyPz4zAZn/lZdvqlF83jMgCWNxmqYjjWuadngCbk=",
"owner": "kirelagin",
"repo": "dns.nix",
"rev": "4710a34f2c36e7a0d634d7ba8fe2499d75f012a2",
"rev": "a97cf4156e9f044fe4bed5be531061000dfabb07",
"type": "github"
},
"original": {
@@ -85,11 +85,11 @@
]
},
"locked": {
"lastModified": 1787377438,
"narHash": "sha256-Sxu1NLTD/Ern6hFGLlZmtKCSct3YQXZI/lls8RE1XeM=",
"lastModified": 1781319724,
"narHash": "sha256-ZGuxexEMo4Xv28KJ0dX/m/PHN4oZIOnxHZpNTyrvx4M=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "65258d5c65a250189fde2e35f490d15e064c4c62",
"rev": "8355f0a16b2dbb06a97959a918af5b239bbe05ae",
"type": "github"
},
"original": {
@@ -126,11 +126,11 @@
"spectrum": "spectrum"
},
"locked": {
"lastModified": 1788263502,
"narHash": "sha256-gyVqW5U9wy6A8voJNu6SiSYTKDplo/MDl31x7FszWlk=",
"lastModified": 1781389237,
"narHash": "sha256-Ne1/E5XNUq0gleaQz0vW5R4xf/0h/uEZ+bOW1aNjeQk=",
"owner": "astro",
"repo": "microvm.nix",
"rev": "974d315e504e666eac4920d712e3ff6804dc1502",
"rev": "6ad601df0a07d9855c5e8f9b81135ecaf7c287eb",
"type": "github"
},
"original": {
@@ -180,11 +180,11 @@
"nixpkgs": "nixpkgs_2"
},
"locked": {
"lastModified": 1788335262,
"narHash": "sha256-3jBEq8avfzlrsY4UpW4d5TOmm7ocseZfnitEJhqauyc=",
"lastModified": 1781622756,
"narHash": "sha256-JrPh4M6S7aPsEE9tOENuZrxC6o2szSLlK+t4+nLke9s=",
"owner": "NixOS",
"repo": "nixos-hardware",
"rev": "44d95795ee2d475b3d687325e26dcf4ca9104557",
"rev": "08018c72174a4df5657f8d94178ac69fb9c243e5",
"type": "github"
},
"original": {
@@ -212,11 +212,11 @@
},
"nixpkgs-unstable": {
"locked": {
"lastModified": 1788179007,
"narHash": "sha256-hn1oU2rue2SYK8dAr8+WNZWtbsz1S2W5mnHlSEuh3bo=",
"lastModified": 1781577229,
"narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "34ab99075ac4f7e40cf037eef32cb1c360bb85e9",
"rev": "567a49d1913ce81ac6e9582e3553dd90a955875f",
"type": "github"
},
"original": {
@@ -241,11 +241,11 @@
},
"nixpkgs_3": {
"locked": {
"lastModified": 1788187754,
"narHash": "sha256-bu1QxmXKmPuvBLN7bHP355OV9Qo13x9WCiRDH62CqRM=",
"lastModified": 1781216227,
"narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "5dfba6236110080a54247d6460bc2ff5dda939cc",
"rev": "a0374025a863d007d98e3297f6aa46cc3141c2f0",
"type": "github"
},
"original": {
@@ -280,11 +280,11 @@
]
},
"locked": {
"lastModified": 1788337237,
"narHash": "sha256-gkSH8VUtCo6hnysNmb9DbTuDepH2t5pv+QWjP75xKAk=",
"lastModified": 1780547341,
"narHash": "sha256-Gq8KNx5A7hBB3uGJaj6eQfLDIz5YdLu92gqBcvHvoUo=",
"owner": "Mic92",
"repo": "sops-nix",
"rev": "fbf759290e0cb0a98dfc813a4eb7d53ad1dacb57",
"rev": "9ed65852b6257fbeae4355bc24ecfea307ca759a",
"type": "github"
},
"original": {
@@ -296,11 +296,11 @@
"spectrum": {
"flake": false,
"locked": {
"lastModified": 1785761586,
"narHash": "sha256-MWOMVqJJERwjQGgRIv8d6rlEBqbLM3VZWxHkNKIIZNw=",
"lastModified": 1778940603,
"narHash": "sha256-voSM8dZNlaOWN3kbYFky+FNY6fFQOEw0xF+ZMpZKkCQ=",
"ref": "refs/heads/main",
"rev": "a7762d6f54b40560dd5255ce902e6e6a5d980fe9",
"revCount": 1416,
"rev": "367dd227f539267eae2b62770b4c17b88ac8c1f1",
"revCount": 1265,
"type": "git",
"url": "https://spectrum-os.org/git/spectrum"
},
+9 -1
View File
@@ -35,9 +35,17 @@
Include ${config.sops.secrets.gitea_token.path}
using_frontend_proxy 1
base_uri hydra.malobeo.org
<hydra_notify>
<prometheus>
listen_address = 0.0.0.0
port = 9199
</prometheus>
</hydra_notify>
queue_runner_metrics_address = 0.0.0.0:9198
'';
};
networking.firewall.allowedTCPPorts = [ 9199 9198 ];
systemd.services.hydra-manual-setup = {
description = "Create Admin User for Hydra";
serviceConfig.Type = "oneshot";
+1 -1
View File
@@ -32,7 +32,7 @@ rec {
];
trusted-public-keys = [
"cache.dynamicdiscord.de:DKueZicqi2NhJJXz9MYgUbiyobMs10fTyHCgAUibRP4="
"cache.malobeo.org:+eSv8F63uj94A0fvmdyPcDDH0qI3CYR91fsbA/eLFGw="
"albert:+eSv8F63uj94A0fvmdyPcDDH0qI3CYR91fsbA/eLFGw="
];
trusted-users = [ "root" "@wheel" ];
};
+78
View File
@@ -0,0 +1,78 @@
modules:
http_2xx:
prober: http
http:
preferred_ip_protocol: "ip4"
http_post_2xx:
prober: http
http:
method: POST
tcp_connect:
prober: tcp
pop3s_banner:
prober: tcp
tcp:
query_response:
- expect: "^+OK"
tls: true
tls_config:
insecure_skip_verify: false
grpc:
prober: grpc
grpc:
tls: true
preferred_ip_protocol: "ip4"
grpc_plain:
prober: grpc
grpc:
tls: false
service: "service1"
ssh_banner:
prober: tcp
tcp:
query_response:
- expect: "^SSH-2.0-"
- send: "SSH-2.0-blackbox-ssh-check"
ssh_banner_extract:
prober: tcp
timeout: 5s
tcp:
query_response:
- expect: "^SSH-2.0-([^ -]+)(?: (.*))?$"
labels:
- name: ssh_version
value: "${1}"
- name: ssh_comments
value: "${2}"
irc_banner:
prober: tcp
tcp:
query_response:
- send: "NICK prober"
- send: "USER prober prober prober :prober"
- expect: "PING :([^ ]+)"
send: "PONG ${1}"
- expect: "^:[^ ]+ 001"
icmp:
prober: icmp
icmp_ttl5:
prober: icmp
timeout: 5s
icmp:
ttl: 5
websocket:
prober: websocket
http_3xx:
prober: http
http:
preferred_ip_protocol: "ip4"
enable_http3: true
enable_http2: false
valid_http_versions: ["HTTP/3.0"]
postgresql:
prober: tcp
tcp:
query_response:
- send: !!binary AAAACATSFi8= # 0x00, 0x00, 0x00, 0x08, 0x04, 0xD2, 0x16, 0x2F - PostgreSQL SSLRequest
- expect_bytes: S # 0x53 - Reply will be 'S' if SSL is enabled, and 'N' if it is not.
- starttls: true
+51
View File
@@ -108,7 +108,58 @@ in
retentionTime = "1y";
port = 9001;
exporters.blackbox = {
enable = true;
configFile = ./blackbox.yaml;
};
scrapeConfigs = [
{
job_name = "blackbox-http";
metrics_path = "/probe";
params = {
module = ["http_2xx"];
};
static_configs = [{
targets = [
"https://malobeo.org"
"https://cloud.malobeo.org"
"https://antamap.malobeo.org"
"https://docs.malobeo.org"
"https://events.malobeo.org"
"https://hydra.malobeo.org"
"https://keys.malobeo.org"
"https://tasklist.malobeo.org"
"https://zines.malobeo.org"
];
}];
relabel_configs = [
{
source_labels = ["__address__"];
target_label = "__param_target";
}
{
source_labels = ["__param_target"];
target_label = "instance";
}
{
target_label = "__address__";
replacement = "127.0.0.1:9115";
}
];
}
{
job_name = "hydra";
static_configs = [{
targets = [ "${hosts.malobeo.hosts.albert.network.address}:9199" ];
}];
}
{
job_name = "hydra-queue-runner";
static_configs = [{
targets = [ "${hosts.malobeo.hosts.albert.network.address}:9198" ];
}];
}
{
job_name = "overwatch";
static_configs = [{
-3
View File
@@ -19,9 +19,7 @@ in
useDHCP = false;
};
disabledModules = [ "services/web-apps/pretalx.nix" ];
imports = [
"${inputs.nixpkgs-unstable}/nixos/modules/services/web-apps/pretalx.nix"
self.nixosModules.malobeo.metrics
self.nixosModules.malobeo.users
../modules/sshd.nix
@@ -80,7 +78,6 @@ in
config.sops.secrets.pretalx_smtp.path
];
settings = {
redis.session = false;
locale = {
language_code = "de";
};