snix/ops
Florian Klink 6666d38584 fix(ops/meta01): fix http listener port, restrict tcp
The config seems a bit underdocumented, but this is what gets it to
listen on 4722 for http.

While we have firewall rules in place, we don't want this to listen on
*:$randomPort, for tcp but just have it disabled.

This doesn't seem to be possible right now, due to a bug in viper, but
we can at least restrict it to listen to localhost only for TCP.

Change-Id: I94d379b8820fd32dc1d75082d3a7fb078f93e4ec
Reviewed-on: https://cl.snix.dev/c/snix/+/30523
Autosubmit: Florian Klink <flokli@flokli.de>
Tested-by: besadii
Reviewed-by: Ryan Lahfa <ryan@lahfa.xyz>
2025-05-16 09:15:26 +00:00
..
besadii doc(ops/besadii): update docstring 2025-05-02 01:11:06 +00:00
buildkite feat(*): initialize new Snix infrastructure 2025-03-17 17:15:07 +00:00
buildkite-api-proxy feat(ops/buildkite-api-proxy): init 2025-05-03 22:36:42 +00:00
dashboards fix(treewide): add missing final newlines 2025-03-21 13:33:32 +00:00
dns feat(ops/dns): manage snix.{store,systems} in DO 2025-05-12 14:39:47 +00:00
gerrit-autosubmit chore(ops/gerrit-autosubmit): clean up warnings & clippy lints 2024-01-03 20:28:56 +00:00
gerrit-tvl fix(ops/gerrit-tvl): query buildkite-status endpoint and re-enable 2025-05-03 22:49:43 +00:00
hcloud fix(ops): delete email config for now 2025-03-18 21:52:06 +00:00
hetzner-s3 feat(*): initialize new Snix infrastructure 2025-03-17 17:15:07 +00:00
keycloak feat(ops/keycloak): configure Buildkite SAML 2025-05-05 12:36:30 +00:00
machines fix(ops/meta01): fix http listener port, restrict tcp 2025-05-16 09:15:26 +00:00
modules feat(ops/meta01): deploy irccat 2025-05-15 14:31:42 +00:00
pipelines fix(ops): add +x for /nix/var/nix/gcroots 2025-03-23 15:02:22 +00:00
secrets feat(ops/meta01): deploy irccat 2025-05-15 14:31:42 +00:00
users refactor(ops): use ops.users for ssh keys consistently 2025-03-20 12:21:44 +00:00
nixos.nix refactor(ops/machines/snix-cache): use new snix.store domain 2025-05-07 21:03:57 +00:00