Re: Finding new home for our builds and other security sensitive stuff

2022-03-07 Thread Ross Vandegrift
On Mon, Mar 07, 2022 at 06:28:15PM +0100, Bastian Blank wrote: > On Mon, Mar 07, 2022 at 07:38:50AM -0800, Noah Meyerhans wrote: > > On Mon, Mar 07, 2022 at 12:11:37PM +0100, Bastian Blank wrote: > > > I was talking about a Vault for our secrets. That's the priority now. > > At the moment, yes,

Re: Finding new home for our builds and other security sensitive stuff

2022-03-07 Thread Bastian Blank
On Mon, Mar 07, 2022 at 07:38:50AM -0800, Noah Meyerhans wrote: > On Mon, Mar 07, 2022 at 12:11:37PM +0100, Bastian Blank wrote: > > I was talking about a Vault for our secrets. That's the priority now. > At the moment, yes, but earlier in the thread was discussion of needing > ~50 GB of storage

Re: Finding new home for our builds and other security sensitive stuff

2022-03-07 Thread Noah Meyerhans
On Mon, Mar 07, 2022 at 12:11:37PM +0100, Bastian Blank wrote: > On Sun, Mar 06, 2022 at 04:40:24PM -0800, Noah Meyerhans wrote: > > Are you not satisfied that the salsa issues have been addressed with the > > latest maintenance? We are now running a current Gitlab release, at > > least. > > I

Re: Finding new home for our builds and other security sensitive stuff

2022-03-07 Thread Bastian Blank
On Sun, Mar 06, 2022 at 04:40:24PM -0800, Noah Meyerhans wrote: > Are you not satisfied that the salsa issues have been addressed with the > latest maintenance? We are now running a current Gitlab release, at > least. I was talking about a Vault for our secrets. That's the priority now. But

Re: Finding new home for our builds and other security sensitive stuff

2022-03-06 Thread Noah Meyerhans
On Sun, Mar 06, 2022 at 05:46:41PM +0100, Bastian Blank wrote: > > > Yeah. That just reduces the possibilities to the large platforms. > > I agree this is a downside. But we wouldn't be forever locked into a > > plaform - it's easy to migrate to consul (and probably raft, but I've > > never

Re: Finding new home for our builds and other security sensitive stuff

2022-03-06 Thread Bastian Blank
Hi On Mon, Feb 28, 2022 at 08:25:21AM -0800, Ross Vandegrift wrote: > On Mon, Feb 28, 2022 at 01:07:37PM +0100, Bastian Blank wrote: > > Yeah. That just reduces the possibilities to the large platforms. > I agree this is a downside. But we wouldn't be forever locked into a > plaform - it's easy

Re: Finding new home for our builds and other security sensitive stuff

2022-02-28 Thread Ross Vandegrift
On Mon, Feb 28, 2022 at 01:07:37PM +0100, Bastian Blank wrote: > On Sun, Feb 27, 2022 at 09:41:47PM -0800, Ross Vandegrift wrote: > > > We use Hashicorp Vault in my company, and we are very happy of it. It > > > works > > > well, it's safe, and has many good options. So I support the idea. > > +1

Re: Finding new home for our builds and other security sensitive stuff

2022-02-28 Thread Bastian Blank
On Sun, Feb 27, 2022 at 09:41:47PM -0800, Ross Vandegrift wrote: > > We use Hashicorp Vault in my company, and we are very happy of it. It works > > well, it's safe, and has many good options. So I support the idea. > +1 - we should talk more about how this would look. I have some thoughts. > We

Re: Finding new home for our builds and other security sensitive stuff

2022-02-28 Thread Thomas Goirand
On 2/28/22 06:41, Ross Vandegrift wrote: Thanks! Bastian, do you remember how much artifact storage we use? IIRC, it's surprisingly large. salsa is still down at the moment, so I'm unable to check. I'm not sure what you mean by "large". These days, we setup servers with 12x18TB each, 6

Re: Finding new home for our builds and other security sensitive stuff

2022-02-27 Thread Ross Vandegrift
On Sun, Feb 27, 2022 at 04:14:03PM +0100, Thomas Goirand wrote: > On 2/27/22 14:09, Bastian Blank wrote: > > Sadly the problems regarding Salsa did just gain a new level. For those > > who don't follow debian-private or the monthly meetings of the Cloud > > team, this is the short version: > > >

Re: Finding new home for our builds and other security sensitive stuff

2022-02-27 Thread Thomas Goirand
Hi Bastian, On 2/27/22 14:09, Bastian Blank wrote: Hi Sadly the problems regarding Salsa did just gain a new level. For those who don't follow debian-private or the monthly meetings of the Cloud team, this is the short version: - The instance was not updated for any of the last nine upstream

Finding new home for our builds and other security sensitive stuff

2022-02-27 Thread Bastian Blank
Hi Sadly the problems regarding Salsa did just gain a new level. For those who don't follow debian-private or the monthly meetings of the Cloud team, this is the short version: - The instance was not updated for any of the last nine upstream releases, it is now seven months out of upstream