emily 10cdf9408d
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
feat: enable request-level logging for bandwidth/traffic incident tracing
Triggered by investigating a several-hour >10Mbps traffic spike to
linode. HAProxy's own IPAccounting confirmed ~121GB moved over ~19.6h
before it crash-looped, but with 'option httplog' commented out and no
per-backend request logs, there was no way to attribute that traffic
to a specific backend, host, or client.

- linode: enable HAProxy httplog + defaults 'log global' (was
  commented out) so every proxied HTTP request is now logged with
  timing/status/bytes.
- linode: add a haproxy 'stats' listener on 127.0.0.1:8404 for live
  per-backend/per-server connection and byte counters.
- linode: route nginx (Nextcloud's local vhost) access logs to
  journald via syslog, since the read-only monitoring account has no
  access to /var/log/nginx/*.
- linode: enable vnstat for historical per-interface bandwidth
  tracking (5-min granularity) so a reported 'traffic was high for N
  hours' can be confirmed/timestamped immediately instead of
  reconstructed after the fact from journal timestamps.
- k3s manifests: enable Traefik access logging (JSON) — this is the
  ingress layer HAProxy forwards :80 traffic to (git/matrix/immich),
  and lacked any per-request visibility.
- hosts/baseline.nix (fleet-wide): add a journald rate limit
  (2000 lines / 30s per unit). Found live while investigating that
  uptime-kuma on 'kuma' was logging a Prometheus label-validation
  error on every monitor beat (~100k lines/hour), which was itself
  degrading journalctl responsiveness on that host during the
  cross-host traffic scan.

Related but not otherwise addressed here: Nebula relay/handshake
churn on kuma's tunnel and the etcd read-latency warnings seen on
isaiah/zeke around the same incident window — noted for a future
investigation, not fixed by this PR.
2026-08-09 16:15:35 -05:00
2026-07-26 21:36:46 -05:00
2026-07-07 14:16:27 -05:00
2026-05-19 23:47:42 -05:00
2026-08-05 22:57:58 -05:00
2025-12-17 23:28:53 -06:00
2023-03-18 06:19:56 +00:00
2025-12-08 05:53:17 -06:00
2025-12-28 22:00:05 -06:00
2026-08-01 14:38:01 -05:00
2026-08-05 22:57:58 -05:00
2026-05-19 02:40:33 -05:00
2026-05-13 08:06:57 -05:00

This is a unified repo to contain my personal configurations for NixOS machines.

How To Use This

Go through the normal process to setup a NixOS system during installation.

  1. Boot from an appropriate medium
  2. Parition the drives
  3. Mount them
  4. Before you generate out the configuration, clone this repoistory to your /etc/nixos folder
  5. Run the configuration generator. It should only genreate the hardware-configuration.nix file, which this repo gitignores
  6. Create a folder and file with the machine name in hosts/<machine>/default.nix
  7. Add hosts/default.nix an appropriate entry for the machine you are building
  8. Create a file home/hosts/<machine>/default.nix with the new machine name as well

Adding new hosts

To add a new host, create a folder in the directory hosts/ that matches the name of the target system. Each host must contain, minimally, a default.nix file that serves as the basis of configuring that host.

Test build a VM for your system

  • nom build ".#nixosConfigurations.<host>.config.system.build.vm
  • export QEMU_NET_OPTS="hostfwd=tcp::2221-:22" to export the SSH port
  • ./result/bin/run-<host>-vm
S
Description
No description provided
Readme
30 MiB
Languages
Nix 86.5%
Go 4.4%
Vim Script 3%
Xonsh 2%
Lua 1.6%
Other 2.5%