freiburg.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Ein Mastodon-Server für Freiburg und Umland betrieben durch den Verein freiburg.social e.V.: https://wir.freiburg.social

Server stats:

535
active users

#sops

0 posts0 participants0 posts today
Dan ⁂<p>finally found some time to play with <a href="https://beoriginal.social/tags/SOPS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOPS</span></a> (<a href="https://getsops.io/docs/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">getsops.io/docs/</span><span class="invisible"></span></a>) and migrated a project to it. seems like a good replacement and optimization for our current secrets sharing workflow. also super useful that it works with both <a href="https://beoriginal.social/tags/PGP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PGP</span></a>/ <a href="https://beoriginal.social/tags/GPG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GPG</span></a> and <a href="https://beoriginal.social/tags/age" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>age</span></a> keys</p>
Eddie Roger<p>After a few nights and weekends of mashing keys, I have figured the right order to bring up a <a href="https://hachyderm.io/tags/nixos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nixos</span></a> instance built for <a href="https://hachyderm.io/tags/proxmox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>proxmox</span></a>, provision it with <a href="https://hachyderm.io/tags/colmena" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>colmena</span></a>, shove secrets on it with <a href="https://hachyderm.io/tags/sops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sops</span></a>, bring up a docker container, and get it on my <span class="h-card" translate="no"><a href="https://hachyderm.io/@tailscale" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>tailscale</span></a></span> <a href="https://hachyderm.io/tags/tailnet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tailnet</span></a>. I don’t know how many times I nearly gave up, but it paid off, and I’m thrilled. </p><p>Now to do it again.</p>
David Guillot<p>📣 New <a href="https://social.tchncs.de/tags/webdev" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>webdev</span></a> related blog post here, introducing my take on what a <a href="https://social.tchncs.de/tags/Django" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Django</span></a> project template could be for an advanced usage. Obviously <a href="https://social.tchncs.de/tags/astraluv" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>astraluv</span></a> is there, but also <a href="https://social.tchncs.de/tags/justsystems" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>justsystems</span></a> , <a href="https://social.tchncs.de/tags/esbuild" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>esbuild</span></a> , and... <a href="https://social.tchncs.de/tags/SOPS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOPS</span></a> 🔐 </p><p>It's very early stage so please tell me what do you think about it 🙏</p><p><a href="https://david.guillot.me/en/posts/tech/proposal-for-a-django-project-template/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">david.guillot.me/en/posts/tech</span><span class="invisible">/proposal-for-a-django-project-template/</span></a></p>
Lennart J. Kurzweg 🇪🇺<p>For all the <a href="https://ieji.de/tags/sops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sops</span></a> <a href="https://ieji.de/tags/nix" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nix</span></a> enjoyers out there, Where do you keep your <a href="https://ieji.de/tags/AGE" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AGE</span></a> key? Does it just live on your drive? Do you use something like a <a href="https://ieji.de/tags/yubikey" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>yubikey</span></a>? Because boot strapping the key with sops obviously doesn't work</p><p><a href="https://ieji.de/tags/nixos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>nixos</span></a> <a href="https://ieji.de/tags/homemanager" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>homemanager</span></a> <a href="https://ieji.de/tags/sopsnix" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sopsnix</span></a></p>
Lennart J. Kurzweg 🇪🇺<p>Learning how to create <a href="https://ieji.de/tags/ssh" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ssh</span></a> keys from my <a href="https://ieji.de/tags/gpg" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>gpg</span></a> <a href="https://ieji.de/tags/pgp" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pgp</span></a> keys so that I can use <a href="https://ieji.de/tags/age" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>age</span></a> for <a href="https://ieji.de/tags/sops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sops</span></a> <a href="https://ieji.de/tags/sops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sops</span></a>-nix so I don't have to enter my email password manually if I even were to nuke my system </p><p><a href="https://ieji.de/tags/NixOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NixOS</span></a> <a href="https://ieji.de/tags/homemanager" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>homemanager</span></a> <a href="https://ieji.de/tags/cryptograpy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cryptograpy</span></a></p>
Heinlein Support<p>👉 Egal ob Zugriffskontrolle oder Notfallwiederherstellung, ob Datensicherung in der Cloud oder im Rechenzentrum – Schlomo Schapiro von der Tektit Consulting GmbH zeigt im Vortrag auf der Secure <a href="https://social.heinlein-support.de/tags/Linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Linux</span></a> Administration Conference, wie sich Herausforderungen rund um betriebliche Geheimnisse in modernen IT-Infrastrukturen lösen lassen. </p><p>Sein Werkzeug der Wahl: Mozilla <a href="https://social.heinlein-support.de/tags/SOPS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOPS</span></a> (Secrets OPerationS). </p><p>🎟️ Jetzt Tickets für die SLAC vom 6.-8.5.24 in Berlin sichern &amp; mehr erfahren:</p><p><a href="https://www.slac-2024.de" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="">slac-2024.de</span><span class="invisible"></span></a></p>
NFDI4Microbiota<p>You can still join us online for the <a href="https://nfdi.social/tags/NFDI4Microbiota" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NFDI4Microbiota</span></a> Knowledge Base Sprint on 15 -16th February! Find more details on the program <a href="https://t1p.de/hnks4" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="">t1p.de/hnks4</span><span class="invisible"></span></a> Topics are e.g. <a href="https://nfdi.social/tags/metadata" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>metadata</span></a>, reproducible data analysis, <a href="https://nfdi.social/tags/SOPs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOPs</span></a>, Research data management. ZOOM meeting ID:&nbsp;889 8299 1488, Passcode:&nbsp;033653</p>
Paula Gentle on Friendica<p>Meine erste Zertifikatserneuerung in der immer noch frischen Kubernetes-Infrastruktur verlief zumindest unfallfrei. Nennt mich Captain SOPS!</p><p><a href="https://libranet.de/search?tag=k8s" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>k8s</span></a> <a href="https://libranet.de/search?tag=SOPS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SOPS</span></a> <a href="https://libranet.de/search?tag=EinmalMitProfis" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EinmalMitProfis</span></a></p>
Karsten<p>Is someone here familiar with <a href="https://chaos.social/tags/sops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sops</span></a> and has experience with multiple encrypt/decrypt methods? We are using vault which leaves us unable to decrypt when the vault is down. Is it possible to add an <a href="https://chaos.social/tags/age" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>age</span></a> recipient as backup "decryptor"? I know multiple pgp keys work. <a href="https://chaos.social/tags/devops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>devops</span></a></p>
Sebastian Mangelsdorf<p><a href="https://metalhead.club/tags/introduction" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>introduction</span></a> time<br>I live near <a href="https://metalhead.club/tags/hamburg" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hamburg</span></a>, build and maintain <a href="https://metalhead.club/tags/privatecloud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privatecloud</span></a> installations based on <a href="https://metalhead.club/tags/openshift" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>openshift</span></a> and I'm always eager to automate stuff - <a href="https://metalhead.club/tags/sysadmin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sysadmin</span></a> for live, technical stuff just makes me happy.</p><p>Loving games, books, good discussions and real world riddles. And of course: music, rock and a bit of metal.</p><p>Technical Stuff running in the lab:<br><a href="https://metalhead.club/tags/proxmox" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>proxmox</span></a> <br><a href="https://metalhead.club/tags/k3s" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>k3s</span></a><br><a href="https://metalhead.club/tags/sops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sops</span></a><br><a href="https://metalhead.club/tags/fluxcd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fluxcd</span></a> <br><a href="https://metalhead.club/tags/metallb" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>metallb</span></a> <br><a href="https://metalhead.club/tags/traefik" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>traefik</span></a> <br><a href="https://metalhead.club/tags/longhorn" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>longhorn</span></a><br><a href="https://metalhead.club/tags/prometheus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>prometheus</span></a><br><a href="https://metalhead.club/tags/thanos" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>thanos</span></a> <br><a href="https://metalhead.club/tags/loki" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>loki</span></a> <br><a href="https://metalhead.club/tags/alloy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>alloy</span></a> <br><a href="https://metalhead.club/tags/grafana" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>grafana</span></a> <br><a href="https://metalhead.club/tags/tekton" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tekton</span></a> <br><a href="https://metalhead.club/tags/mosquitto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mosquitto</span></a> <br><a href="https://metalhead.club/tags/homeassistant" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>homeassistant</span></a> <br><a href="https://metalhead.club/tags/jellyfin" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>jellyfin</span></a> <br><a href="https://metalhead.club/tags/wikijs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>wikijs</span></a> <br><a href="https://metalhead.club/tags/keycloak" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>keycloak</span></a> <br><a href="https://metalhead.club/tags/forgejo" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>forgejo</span></a><br><a href="https://metalhead.club/tags/openshift" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>openshift</span></a></p>
nieebel<p><span class="h-card"><a href="https://fosstodon.org/@nalum" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nalum</span></a></span> <a href="https://digitalcourage.social/tags/fluxcd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fluxcd</span></a> v2 + <a href="https://digitalcourage.social/tags/Mozilla" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mozilla</span></a> <a href="https://digitalcourage.social/tags/sops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sops</span></a> + <a href="https://digitalcourage.social/tags/Vault" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Vault</span></a> is nice! I prefer it over <a href="https://digitalcourage.social/tags/argoCD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>argoCD</span></a> (I heard that AWS moved away from argo to flux).</p><p>For managing k8s resources I prefer simple and small controllers written in Go listening only to small subset of resources instead of what <a href="https://digitalcourage.social/tags/kyverno" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>kyverno</span></a> is doing: intercepting every kubernetes api server traffic, which might be a bottleneck or a single point of failure, which I would avoid. But not sure, have not much experience with it. </p><p>I use mostly <a href="https://digitalcourage.social/tags/kubebuilder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>kubebuilder</span></a> code generators which I prefer over Operator Framework. Only unit-testing with the K8s fake client is not possible to an extend I would expect...<br>So we try to get more integration tests in our pipeline via ephemeral Kind/minikube/... clusters via <a href="https://digitalcourage.social/tags/prow" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>prow</span></a> - which is not that straight forward...</p>