Commit Graph

  • d57ca21e06 add sqlite-analyzer to attestation servers Daniel Micay 2024-03-08 11:54:02 -0500
  • e9d90bf88b lsof replaced with lsfd Daniel Micay 2024-03-06 16:17:59 -0500
  • c8d359af57 disable mkinitcpio fallback image Daniel Micay 2024-03-04 13:13:58 -0500
  • 8591cb9354 raise 2.grapheneos.network journal size to 2G Daniel Micay 2024-03-03 15:45:04 -0500
  • 14174e90f4 nginx-rotate-session-ticket-keys: drop unnecessary time sync Daniel Micay 2024-03-03 09:57:30 -0500
  • fb8775bb85 use checksum-based rsync Daniel Micay 2024-03-03 09:53:39 -0500
  • d8b70fce4f raise journal size for high log volume servers Daniel Micay 2024-03-01 10:05:39 -0500
  • 16e3df0c39 raise max log size for OVH network instances Daniel Micay 2024-02-29 11:32:28 -0500
  • 67a71a5cd3 count: drop 3rd gen Pixels Daniel Micay 2024-02-24 19:19:41 -0500
  • 23207e99bf replace 4.releases.grapheneos.org server Daniel Micay 2024-02-24 10:34:52 -0500
  • c9cceb3bc0 explicit set XFS allocation group count Daniel Micay 2024-02-24 10:28:10 -0500
  • e0d5ff2fb2 enable deploy-initial script Daniel Micay 2024-02-24 10:22:19 -0500
  • b185e04a2c update install image to 2024.02.01 Daniel Micay 2024-02-24 10:21:24 -0500
  • 0899b7e984 update python dependencies Daniel Micay 2024-02-23 13:04:36 -0500
  • 827324d15d stop generating unused en_US.UTF-8 locale Daniel Micay 2024-02-15 13:56:13 -0500
  • 5b25870f96 enable reboot on systemd crash caught systemd Daniel Micay 2024-02-13 13:07:42 -0500
  • 2e7058e9c4 replace certbot log rotation with logrotate Daniel Micay 2024-02-13 11:56:53 -0500
  • e81e9feef3 replace MaxRetentionSec to stop excessive rotation Daniel Micay 2024-02-13 11:16:17 -0500
  • d39937fc6c disable currently unused energy aware scheduling Daniel Micay 2024-02-12 16:13:28 -0500
  • bd9a3d97d7 update python dependencies Daniel Micay 2024-02-08 15:08:09 -0500
  • 81307b3bb9 add authorized_keys to gitignore Daniel Micay 2024-02-03 17:48:56 -0500
  • 86d582ba2b add stripped down initial deployment script Daniel Micay 2024-02-03 17:47:41 -0500
  • 154811ab1e add uptime to dns stats Daniel Micay 2024-02-03 17:30:22 -0500
  • 963921413e add 8th generation Pixels to count script Daniel Micay 2024-02-02 14:42:28 -0500
  • a010e02c52 use leaner format for update log output Daniel Micay 2024-02-02 07:26:36 -0500
  • 6989905361 add updatedb drop-in unit to pacreport exclusions Daniel Micay 2024-02-01 18:00:35 -0500
  • d583da0a65 disable sending console output to unused ttyS0 Daniel Micay 2024-02-01 16:39:15 -0500
  • 2fe25c5218 grub: remove extra space Daniel Micay 2024-01-31 21:28:14 -0500
  • 69c7803b31 update python dependencies Daniel Micay 2024-01-30 14:37:31 -0500
  • 4371062b71 add sshpass on mail.grapheneos.org Daniel Micay 2024-01-26 00:41:51 -0500
  • 50de6d59c0 switch main domain for ECDSA mail server cert Daniel Micay 2024-01-25 12:55:57 -0500
  • 88eba9a5fe update copyright notice Daniel Micay 2024-01-25 01:57:18 -0500
  • a5fa9f930f update certbot-ocsp-fetcher Daniel Micay 2024-01-25 01:23:49 -0500
  • 0e3521564c replace mail.grapheneos.org server Daniel Micay 2024-01-24 22:53:09 -0500
  • da98484270 replace attestation.app server Daniel Micay 2024-01-23 19:05:20 -0500
  • 7213c1745a replace 2.grapheneos.org and 2.grapheneos.network Daniel Micay 2024-01-22 01:39:38 -0500
  • 4714b0bdb9 replace discuss.grapheneos.org server Daniel Micay 2024-01-20 23:36:30 -0500
  • 6a0481714f replace 0.grapheneos.org and 0.grapheneos.network Daniel Micay 2024-01-20 00:59:00 -0500
  • 8d1782161f stop sending external ADoT queries through unbound Daniel Micay 2024-01-19 13:44:47 -0500
  • 5ed0c02e99 nftables: extend notrack rules for ADoT changes Daniel Micay 2024-01-19 12:51:35 -0500
  • a954a4a024 use clean syntax for IPv6 address Daniel Micay 2024-01-18 08:44:02 -0500
  • d22b380520 replace ns1.grapheneos.org server Daniel Micay 2024-01-18 08:19:33 -0500
  • d44a316624 disable 32-bit support via kernel line Daniel Micay 2024-01-03 11:01:36 -0500
  • dd9d6ff2a5 disable unused multipath TCP Daniel Micay 2024-01-03 10:52:27 -0500
  • d0e6159220 filter irrelevant module output Daniel Micay 2024-01-03 10:18:15 -0500
  • e581aeafb5 use idle CPU scheduling mode for updatedb Daniel Micay 2024-01-03 10:09:44 -0500
  • ae0373cc38 simplify log fetching Daniel Micay 2023-12-24 20:21:06 -0500
  • 15a2fa132f disable services on IPv6 for discussion forum Daniel Micay 2023-12-22 17:45:10 -0500
  • 8bfec062dc switch to nodejs 20 LTS branch Daniel Micay 2023-12-21 20:07:00 -0500
  • 99973b1ca2 add mmdblookup to servers using geoip2 Daniel Micay 2023-12-21 09:49:36 -0500
  • 5a7110bee4 add geoip2 packages for discuss.grapheneos.org Daniel Micay 2023-12-21 09:46:53 -0500
  • 5cef4a2aa6 allow geoipupdate internet access for discuss Daniel Micay 2023-12-21 09:44:05 -0500
  • dc4101f3de update systemd configuration files Daniel Micay 2023-12-07 12:33:59 -0500
  • 8708b133e5 update python dependencies Daniel Micay 2023-12-03 23:52:09 -0500
  • c1a826278e add widevineprovisioning.grapheneos.org Daniel Micay 2023-12-02 02:16:42 -0500
  • d99ca0a43f switch to development release of matterbridge Daniel Micay 2023-12-02 02:16:24 -0500
  • bed640859d update python dependencies Daniel Micay 2023-11-20 22:43:56 -0500
  • f9bd8e2476 switch domain order for nameserver certbot setup Daniel Micay 2023-11-05 01:33:56 -0500
  • ebd0c7d8d0 add staging nameserver certbot setup Daniel Micay 2023-11-05 01:32:44 -0500
  • 38bb002a01 add authenticated DNS-over-TLS to nameservers Daniel Micay 2023-11-04 22:16:56 -0400
  • 3a92693611 move PowerDNS webserver to localhost port 81 Daniel Micay 2023-11-04 22:50:37 -0400
  • c959f8bc5b drop jdk-openjdk from attestation servers Daniel Micay 2023-11-04 16:31:03 -0400
  • a10afab253 update Python dependencies Daniel Micay 2023-10-24 14:16:54 -0400
  • 9aba6192e7 unbound: block dns rebinding Orazio 2023-10-04 13:39:59 +0200
  • cfc189742e
    unbound: block dns rebinding Orazio 2023-10-04 13:39:59 +0200
  • cb0007f816 update python dependencies Daniel Micay 2023-10-03 11:39:02 -0400
  • a4af9e2faf add ephemeral-trees directory to pacreport Daniel Micay 2023-10-01 09:04:41 -0400
  • c29206dff6 update python dependencies Daniel Micay 2023-10-01 08:41:06 -0400
  • ffff417df9 mastodon package now declares proper dependencies Daniel Micay 2023-09-24 22:18:30 -0400
  • 1f7ea042fe expand host variable declarations Daniel Micay 2023-09-18 03:29:23 -0400
  • 15f1cbcd02 nginx: drop ExecStart override Daniel Micay 2023-09-18 02:41:59 -0400
  • eeaaf12886
    Typo fix Tommy 2023-09-07 19:57:24 -0700
  • 4a985cbe29
    Typo fix Tommy 2023-09-07 19:56:43 -0700
  • 1bc32489f1
    Use curve secp384r1 Tommy 2023-09-07 19:51:41 -0700
  • 90411f367c update OCSP cache path for certbot-renew.service Daniel Micay 2023-09-02 15:07:28 -0400
  • 067b42213f update ocsp cache path for certbot deploy hook Daniel Micay 2023-08-21 03:20:50 -0400
  • adec4b9bda certbot: drop absolute path for deploy hook Daniel Micay 2023-08-21 03:15:44 -0400
  • a92156528a add nftables dscp counter config to guide Daniel Micay 2023-08-19 00:46:21 -0400
  • 104c1857d9 add vconsole.conf to pacreport.conf Daniel Micay 2023-08-19 00:37:04 -0400
  • 14da5949f2 add fstrim/xfs_fsr configuration to pacreport.conf Daniel Micay 2023-08-19 00:33:56 -0400
  • 5a86b91909 update pip-compile command Daniel Micay 2023-08-19 00:27:56 -0400
  • 9419af1bd6 use af21 for unbound DoT traffic Daniel Micay 2023-08-19 00:17:06 -0400
  • e1af23a478 add attestation service config for email Daniel Micay 2023-08-18 23:57:44 -0400
  • 343d1fdb2f add mtr package Daniel Micay 2023-08-16 22:55:53 -0400
  • b88d0d5c96 raise ssh background traffic priority to af11 Daniel Micay 2023-08-14 23:31:22 -0400
  • ae2fc9244b support drop-in configurations for ssh configs Daniel Micay 2023-08-11 11:36:08 -0400
  • 894f150a62 use CAKE no-split-gso for release servers Daniel Micay 2023-08-06 23:18:53 -0400
  • 4160e5a6b7 chrony: mark traffic as EF Daniel Micay 2023-08-04 16:51:12 -0400
  • 2f56bae4a5 use consistent naming for system drop-in configs Daniel Micay 2023-08-04 14:45:15 -0400
  • e56add4330 run fstrim daily instead of weekly Daniel Micay 2023-08-04 14:38:41 -0400
  • b67d037a5e add xfs_fsr service run before fstrim service Daniel Micay 2023-08-03 13:45:11 -0400
  • 124897ccba update systemd/system.conf Daniel Micay 2023-08-01 18:06:28 -0400
  • 7a95f6bfb4 update systemd/networkd.conf Daniel Micay 2023-08-01 18:05:09 -0400
  • 2703b7a378 add pv package Daniel Micay 2023-07-28 23:24:40 -0400
  • 53b46f6166 set correct subnet mask for BuyVM main IP Daniel Micay 2023-07-28 00:12:05 -0400
  • 5e07ae005b use idle scheduling for fstrim.service Daniel Micay 2023-07-26 13:01:17 -0400
  • 0e37437f0c update python dependencies Daniel Micay 2023-07-26 03:41:24 -0400
  • 39c15372a2 add ioping package Daniel Micay 2023-07-26 03:40:57 -0400
  • e3b8692914 add buyvm and ovh hosts arrays Daniel Micay 2023-07-24 21:31:24 -0400
  • 1173060c25 ssh: switch to AES256-GCM to use AES-NI Daniel Micay 2023-07-22 16:32:52 -0400