Commit Graph
960656 Commits
Author SHA1 Message Date
0x2BandFliegendeWurst 58a2e2f971 jwtcat: init at 0-unstable-2022-10-15 2026-07-22 08:42:21 +02:00
0x2BandFliegendeWurst b14f8fbb74 maintainers: add _0x2B-bin 2026-07-22 08:42:13 +02:00
Edward TjörnhammarandGitHub 50f05917b3 nixos/nvidia: add dc_580 and dc_590 drivers (#496834) 2026-03-08 21:43:15 +00:00
Edward Tjörnhammar 680f6c90b1 nixos/nvidia: add dc_580 and dc_590 drivers 2026-03-08 22:36:26 +01:00
Gaétan LepageandGitHub 48b474784c bbot: add websockets to pythonRelaxDeps and add maintainer (#498006) 2026-03-08 21:29:49 +00:00
Fabian AffolterandGitHub 9fd3b01b11 havn: 0.3.4 -> 0.3.5 (#498007) 2026-03-08 21:27:05 +00:00
JoandGitHub 6736df9e64 noto-fonts: 2026.02.01 -> 2026.03.01 (#496143) 2026-03-08 21:16:45 +00:00
dotlambdaandGitHub 85132a06e0 python3Packages.pyportainer: 1.0.31 -> 1.0.33 (#498002) 2026-03-08 21:01:34 +00:00
SandroandGitHub bca938be22 stirling-pdf: 2.4.5 -> 2.6.0; nixos/stirling-pdf: add timhae as maintainer (#496929) 2026-03-08 20:48:54 +00:00
YtandGitHub fbbeeda6c0 python3Packages.weaviate-client: 4.20.1 -> 4.20.3 (#497887) 2026-03-08 20:41:26 +00:00
YtandGitHub ab2d232bec python3Packages.obstore: init at 0.9.1 (#450944) 2026-03-08 20:39:34 +00:00
Gaétan LepageandGitHub 47f872cd26 ansible: 2.20.0 -> 2.20.3 (#493762) 2026-03-08 20:31:17 +00:00
K900andGitHub 67b085ee30 livekit: 1.9.11 -> 1.9.12 (#496986) 2026-03-08 20:29:18 +00:00
SandroandGitHub 51b963af40 archisteamfarm: 6.3.2.3 -> 6.3.3.3 (#496692) 2026-03-08 20:18:13 +00:00
SandroandGitHub 3c746adeeb coredns: 1.14.1 -> 1.14.2 (#497951) 2026-03-08 20:15:40 +00:00
nixpkgs-ci[bot]andGitHub 4e6e27823a source-meta-json-schema: 14.7.1 -> 14.13.4 (#490493) 2026-03-08 20:14:31 +00:00
Matthieu CoudronandGitHub c34ce1ed0d neovim: rework provider code generation (#495392) 2026-03-08 20:04:35 +00:00
JennyandGitHub 604270fe77 librenms: 25.12.0 -> 26.2.0 (#497777) 2026-03-08 20:01:10 +00:00
YurekaandGitHub 112cdc0c44 irrd: 4.5.0 -> 4.5.1 (#497968) 2026-03-08 19:57:23 +00:00
Robert Sliwinski ef8e8232e9 bbot: Add robsliwi as maintainer 2026-03-08 20:56:53 +01:00
Robert Sliwinski c665740dbb bbot: add websockets to pythonRelaxDeps 2026-03-08 20:55:46 +01:00
R. Ryantm 008e145c69 havn: 0.3.4 -> 0.3.5 2026-03-08 19:53:56 +00:00
Cosima NeidahlandGitHub 6a7aef3079 mkcal: 0.7.30 -> 0.7.31 (#497648) 2026-03-08 19:53:33 +00:00
SandroandGitHub 49eb059788 karakeep: changing cache dir location away from nix store (#416531) 2026-03-08 19:49:25 +00:00
Yureka 24ad083da8 irrd: 4.5.0 -> 4.5.1
Diff: https://github.com/irrdnet/irrd/compare/v4.5.0...v4.5.1

Changelog: https://irrd.readthedocs.io/en/v4.5.1/releases/
2026-03-08 20:46:14 +01:00
Yureka 5c6d0eefa9 irrd: fix build
The new ariadne version 0.29+ removed functions used by irrd
2026-03-08 20:46:14 +01:00
R. Ryantm 63066fe248 python3Packages.pyportainer: 1.0.31 -> 1.0.33 2026-03-08 19:44:16 +00:00
Robert Sliwinski 8a453ec3b4 ansible: use finalAttrs instead of rec
See https://github.com/NixOS/nixpkgs/issues/315337
2026-03-08 20:42:50 +01:00
nixpkgs-ci[bot]andGitHub fcc709bc9e tinyauth: 5.0.1 -> 5.0.2 (#497986) 2026-03-08 19:19:40 +00:00
Marcus RambergandGitHub 283bb24fce pocket-id: 2.3.0 -> 2.4.0 (#497928) 2026-03-08 19:19:14 +00:00
Maximilian BoschandGitHub b8893e2c6b nixos/grafana: update instructions on secret rotation (#497976) 2026-03-08 19:10:14 +00:00
Luna NovaandGitHub a1a5d8812b twemoji-color-font-src: svgo from main package set instead of nodePackages alias (#497988) 2026-03-08 19:09:30 +00:00
Luna Nova 8ba3e73c4c twemoji-color-font-src: svgo from main package set instead of nodePackages alias
Fixes: 1f47317b58 ("twemoji-color-font-src: init at 15.1.0")
2026-03-08 11:51:34 -07:00
Cosima NeidahlandGitHub c583bccdf5 vgmtools: 0.1-unstable-2026-02-23 -> 0.1-unstable-2026-02-26 (#496785) 2026-03-08 18:47:56 +00:00
R. Ryantm ffc8f9a345 tinyauth: 5.0.1 -> 5.0.2 2026-03-08 18:47:08 +00:00
Doron BeharandGitHub 9507db197b imapfilter: 2.8.3 -> 2.8.4 (#497890) 2026-03-08 18:37:54 +00:00
Cosima NeidahlandGitHub 4c086ad81f lomiri.biometryd: 0.3.3 -> 0.4.0 (#495196) 2026-03-08 18:33:46 +00:00
nixpkgs-ci[bot]andGitHub e9b5a97133 firecracker: 1.14.1 -> 1.14.2 (#496788) 2026-03-08 18:28:14 +00:00
nixpkgs-ci[bot]andGitHub d009985cb6 vault: 1.21.2 -> 1.21.4 (#491550) 2026-03-08 18:28:12 +00:00
Doron BeharandGitHub d68c78c388 python3Packages.plotpy: 2.8.3 -> 2.8.4 (#496944) 2026-03-08 18:27:49 +00:00
Doron BeharandGitHub 29975dd468 mnxdom: init at 3.0 (#492826) 2026-03-08 18:26:12 +00:00
Doron BeharandGitHub a9732f7487 nixos/taskchampion-sync-server: use DynamicUser after 26.05 (#494338) 2026-03-08 18:25:26 +00:00
Doron BeharandGitHub b48f52a2d9 octavePackages: Run autoreconf hook on compiled sources (#496611) 2026-03-08 18:18:10 +00:00
Anton TetovandSandro Jäckel ce751b2e38 karakeep: changing cache dir location away from nix store 2026-03-08 19:13:09 +01:00
nixpkgs-ci[bot]andGitHub f3f83f3659 kine: 0.14.12 -> 0.14.13 (#497418) 2026-03-08 18:06:28 +00:00
nixpkgs-ci[bot]andGitHub 80f5fa4ac6 infrastructure-agent: 1.72.6 -> 1.72.7 (#497343) 2026-03-08 18:06:27 +00:00
Gaétan LepageandGitHub 657c3f4b98 python3Packages.moyopy: 0.7.7 -> 0.7.9 (#497971) 2026-03-08 18:04:21 +00:00
Maximilian Bosch ec7dc46bfc nixos/grafana: update instructions on secret rotation
Closes #495278

Turns out that the documentation about secrets[1] is actually a little
misleading and I let myself fool by it: the rotation is about moving
to envelope-based encryption, i.e. a way where a key is generated and
stored in the DB that is encrypted with `secret_key` and used to
decrypt actual secrets.

In fact, there's no official way to rotate this on a running instance.
The reason this wasn't noticed so far is because I'd expect most people
to

* use provisioning to set up their datasources (or)
* talk to a local Prometheus (or else) API that is exposed on the
  machine only and thus no authentication is needed if you trust that
  machine enough.

On top, the encryption is unauthenticated so only changing secret_key
appears to work, but uses gibberish as password for authentication
against data-sources.

So effectively there are two ways to migrate (short of a fresh setup):

* keep the old secret and call it a day. IMHO this is fine if the setup
  is e.g. a single-node machine where both the secret and the DB are on
  the same file-system, in the same data-dir and protected by the same
  permissions.

* use a 3rd-party rotation tool[2]. I ensured by hand on a test-instance
  that following the instructions works and you end up with a freshly
  generated secret_key that you need to deploy. With that key deployed,
  the credentials still decrypt to the same plaintext.

[1] https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-database-encryption/#envelope-encryption
[2] https://github.com/erooke/grafana-secretkey-rotation-tool/tree/d9dc788902fa5185e15cb15ce6129f7237ab6138
2026-03-08 19:00:21 +01:00
Gaétan LepageandGitHub df6c2ecdae presenterm: Drop Sixel dependency (#491385) 2026-03-08 17:53:02 +00:00
R. Ryantm d7e66ca8c2 python3Packages.moyopy: 0.7.7 -> 0.7.9 2026-03-08 17:48:01 +00:00