2026-02-16T11:03:05 Hello folks (kudos related) can you please look into https://gitlab.infra.opensuse.org/infra/salt/-/merge_requests/2711 (also see my comment about 0 sized certs) 2026-02-16T11:32:45 > 2026-02-07 20:19:40 acidsys LubosKocman: we use acls for this, in salt/profile/dehydrated/target.sls there is a crtkey_acl macro already for some other services using their own user/group 2026-02-16T11:37:11 your extra long message does not make it here (because heisenbridge is broken since forever) 2026-02-16T11:38:41 it's filtered on the firewall, you can there is a "chain network_vpn" in salt/files/nftables/asgard/zones/1102_os-odin.nft .. if you let me know what port/service on the machine you want to access from VPN I can implement it for you 2026-02-16T11:48:15 so the 3000 and 5555 (prisma admin) 2026-02-16T11:48:43 but the 3000 is also the port that we set up reverse proxy to point at, I hope that is okay 2026-02-16T11:51:32 Oky will use ACL for the certs. Thanks sir! 2026-02-16T11:51:40 btw what about the 0 size? 2026-02-16T12:18:27 cert deployment has failed so far.. already came up in monitoring alerts but I did not get to check yet, will try later 2026-02-16T12:50:16 thank you very much sir Georg! 2026-02-16T20:41:06 Is the mail server working? I didn't receive ~140 emails from the build service 2026-02-16T22:14:50 https://paste.opensuse.org/pastes/4cef409aa0cb ← it's slow but I'm getting the missing messages