| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2025-07-15 | [0] akashi: use the staging branch of Deployment channel | Marek Paśnikowski | |
| Akashi system needs to have fan control enabled and customized. By default, the firmware fails to adequately cool the computer which results in thermal throttling. ----- The goal is to have the laptop fan run at full throttle at all times, regardless of CPU temeperature. ----- [ ] Enable fan control in thinkpad_acpi module. [ ] Set fan speed to full throttle. ----- This commit configures a custom guix configuration for Akashi system in order to set up a testing loop with a staging branch. Additional modules need to be imported in order to facilitate this change. ----- Akashi system will now pull the staging branch of Deployment channel during updates. | |||
| 2025-07-08 | mcdowell: switch default-guix-channel | Marek Paśnikowski | |
| The (sovereign channels) defines a new, simpler guix channel. | |||
| 2025-07-08 | mcdowell: use staging branches of sovereign and deployment channels | Marek Paśnikowski | |
| 2025-07-07 | systems: standardise label creation | Marek Paśnikowski | |
| All operating-system records are configured to prepend default labels with respective host names. ----- Some minor adaptations had to performed. | |||
| 2025-06-30 | aisaka: point the test subdomain to the schron subdomain | Marek Paśnikowski | |
| The purpose of the test subdomain is to try out changes in nginx configuration. As such, directories should not be created for the sake of the test subdomain. Instead, the test subdomain should point to a subdomain currently needing testing. | |||
| 2025-06-29 | aisaka: correct target of the schron subdomain | Marek Paśnikowski | |
| 2025-06-27 | aisaka: apply the new client certificate to schronca | Marek Paśnikowski | |
| 2025-06-27 | aisaka: test a new client certificate | Marek Paśnikowski | |
| 2025-06-27 | systems/aisaka: install openssl | Marek Paśnikowski | |
| The root user need access to openssl command in order to manipulate ca secrets. | |||
| 2025-06-26 | aisaka: improve layout of system | Marek Paśnikowski | |
| No functional changes are introduced. This is purely visual improvement. | |||
| 2025-06-20 | aisaka: ultimately fix the efi-directory target | Marek Paśnikowski | |
| 2025-06-20 | aisaka: use the standard home-environment-service of uid1000 | Marek Paśnikowski | |
| The current system configuration of aisaka uses an old custom home environment from before a unified one was developed. As it is no longer useful, the (home-services) procedure definition is removed from the module. | |||
| 2025-06-18 | aisaka: fix grub-efi target | Marek Paśnikowski | |
| 2025-06-18 | systems: fix mount points for efi partition | Marek Paśnikowski | |
| 2025-06-18 | systems: stop importing dead modules | Marek Paśnikowski | |
| 2025-06-17 | systems: update sudoers-file to use the definition in sovereign repository | Marek Paśnikowski | |
| 2025-06-16 | systems: fix the EFI partition mount point | Marek Paśnikowski | |
| 2025-06-14 | ayase: remove unused import of module (suweren services) | Marek Paśnikowski | |
| 2025-06-07 | ayase: use the name/home-environment variable for home services | Marek Paśnikowski | |
| 2025-06-07 | ayase: trim services list | Marek Paśnikowski | |
| 2025-06-02 | aisaka: point the schron subdomain to the test directory | Marek Paśnikowski | |
| 2025-06-02 | aisaka: certify the schron subdomain | Marek Paśnikowski | |
| 2025-06-01 | aisaka: update dns serial number | Marek Paśnikowski | |
| 2025-06-01 | aisaka: set up the schron subdomain | Marek Paśnikowski | |
| 2025-05-29 | aisaka: use a Let’s Encrypt certificate for the test subdomain | Marek Paśnikowski | |
| The prototype of the client certificate authentication is suboptimal. The use of a private certificate authority for server authentication causes unnecessary security warnings when loading the subdomain with an unauthenticated browser. Any browser in its default configuration has no right to understand the private certificate authority used for the client and server certificates. It is possible to mix Let’s Encrypt certificates with a private certificate authority to implement the authentication. None of the previously found client authentication guides mentioned that server authentication can use an authority chain different to client authentication. This change takes advantage of this separation of concerns by using a Let’s Encrypt certificate for the test subdomain server, while keeping the private certificate for client authentication. | |||
| 2025-05-17 | aisaka: expose nonguix repository | Marek Paśnikowski | |
| 2025-05-13 | aisaka: limit the publicly visible repositories to only Guix channels | Marek Paśnikowski | |
| 2025-05-12 | Revert "aisaka: uninstall cgit and simplify gitolite" | Marek Paśnikowski | |
| This reverts commit ba64ebfe587f05c734f24ace507d22629d350cd8. | |||
| 2025-05-12 | aisaka: redefine operating-system* | Marek Paśnikowski | |
| 2025-05-12 | aisaka: fix gitolite-service-type import | Marek Paśnikowski | |
| 2025-05-12 | aisaka: uninstall cgit and simplify gitolite | Marek Paśnikowski | |
| 2025-05-11 | aisaka: iterate client authentication | Marek Paśnikowski | |
| 2025-05-11 | aisaka: add proxy_set_headers for test.marekpasnikowski.pl | Marek Paśnikowski | |
| 2025-05-11 | aisaka: configure NGINX client authentication according to DataCadamia | Marek Paśnikowski | |
| 2025-05-03 | aisaka: configure client certificate check on test subdomain | Marek Paśnikowski | |
| 2025-05-03 | mcdowell: install openssh service | Marek Paśnikowski | |
| 2025-03-15 | systems: use the nonguix definition of initrd | Marek Paśnikowski | |
| The indirect bindings force the Sovereign channel to unnecessarily depend on Nonguix. | |||
| 2025-03-15 | systems: use the nonguix definition of kernel directly | Marek Paśnikowski | |
| The indirect bindings force the Sovereign channel to unnecessarily depend on Nonguix. | |||
| 2025-03-14 | import systems to deployment channel | Marek Paśnikowski | |
