Go to file
Dustin 647cdb8346 ssh-host-certs: Run sshca-cli from a container
Installing packages on the host system via `rpm-ostree` is _insanely_
slow, especially on Raspberry Pi devices.  The main reason I chose to go
that route for managing the SSH host certificates was to avoid having to
maintain the systemd units in multiple places.  I think the trade-off is
worth it, though; bringing up a new Raspberry Pi is significantly
faster, by 15+ minutes, if we do not have to wait for `rpm-ostree` at
all.
2024-01-17 20:30:34 -06:00
.gitattributes frigate: Enable Frigate+ integration 2023-09-21 22:29:51 -05:00
.gitignore flash: Clean up/add support for RPi 3 2023-10-04 20:50:30 -05:00
65-apex.rules gasket-driver: Install Coral EdgeTPU driver 2023-09-16 07:58:48 -05:00
Makefile mkvm: Add script to create FCOS VM 2024-01-06 20:49:31 -06:00
after-install.target packages: Add after-install target unit 2024-01-06 19:43:08 -06:00
butane-watch.sh meta: Add Makefile 2023-09-16 08:15:08 -05:00
collectd.yaml collectd: Start after install 2024-01-06 19:47:07 -06:00
common.yaml Switch from Step CA to SSHCA 2024-01-06 19:57:48 -06:00
datadisk-var.yaml k8s-amd64-n3: Add new K8s VM node 2024-01-06 20:46:25 -06:00
dch-repo.yaml Switch from Step CA to SSHCA 2024-01-06 19:57:48 -06:00
dch.repo Switch from Step CA to SSHCA 2024-01-06 19:57:48 -06:00
fetchcert.service fetchcert: Add script to fetch certs from K8s 2023-09-21 22:30:23 -05:00
fetchcert.sh fetchcert: Add script to fetch certs from K8s 2023-09-21 22:30:23 -05:00
fetchcert.timer fetchcert: Add script to fetch certs from K8s 2023-09-21 22:30:23 -05:00
fetchcert.yaml fetchcert: Add script to fetch certs from K8s 2023-09-21 22:30:23 -05:00
flash.zsh flash: Clean up/add support for RPi 3 2023-10-04 20:50:30 -05:00
frigate.container frigate: Disable systemd filesystem isolation 2023-09-21 22:29:51 -05:00
frigate.env.gpg frigate: Enable Frigate+ integration 2023-09-21 22:29:51 -05:00
frigate.nginx frigate: Configure nginx reverse proxy 2023-09-21 22:32:59 -05:00
frigate.sysusers frigate: Manage state dir with tmpfiles.d 2023-09-19 10:44:34 -05:00
frigate.tmpfiles frigate: Manage state dir with tmpfiles.d 2023-09-19 10:44:34 -05:00
frigate.token.gpg nvr1: Deploy nginx 2023-09-21 22:34:14 -05:00
frigate.yaml frigate: Configure nginx reverse proxy 2023-09-21 22:32:59 -05:00
gasket-driver.container gasket-driver: Install Coral EdgeTPU driver 2023-09-16 07:58:48 -05:00
gasket-driver.yaml gasket-driver: Install Coral EdgeTPU driver 2023-09-16 07:58:48 -05:00
install-packages.service packages: Fix service start on first boot 2024-01-06 19:41:07 -06:00
install-packages.sh packages: Add after-install target unit 2024-01-06 19:43:08 -06:00
k8s-aarch64-n0.yaml common: Add config shared by all hosts 2023-10-03 20:07:29 -05:00
k8s-aarch64-n1.yaml k8s-aarch6-n1: Add new Kubernetes node 2023-10-03 19:59:14 -05:00
k8s-amd64-n3.yaml k8s-amd64-n3: Add new K8s VM node 2024-01-06 20:46:25 -06:00
kubelet.yaml kubelet: Use install-packages service 2024-01-06 19:48:31 -06:00
local_exporter.config local_exporter: Exporter for Zincati metrics 2023-10-03 15:29:58 -05:00
local_exporter.container local_exporter: Start after network online 2024-01-06 19:49:41 -06:00
local_exporter.yaml local_exporter: Exporter for Zincati metrics 2023-10-03 15:29:58 -05:00
mkvm.sh mkvm: Add script to create FCOS VM 2024-01-06 20:49:31 -06:00
nginx.conf nginx: Fix configuration 2024-01-06 19:50:42 -06:00
nginx.container nginx: Fix configuration 2024-01-06 19:50:42 -06:00
nginx.yaml fetchcert: Add script to fetch certs from K8s 2023-09-21 22:30:23 -05:00
notify-shutdown.service notify-shutdown: Send a message on shutdown 2023-09-21 22:34:14 -05:00
notify-shutdown.yaml notify-shutdown: Send a message on shutdown 2023-09-21 22:34:14 -05:00
nvr1.yaml common: Add config shared by all hosts 2023-10-03 20:07:29 -05:00
packages.yaml packages: Add after-install target unit 2024-01-06 19:43:08 -06:00
ssh-host-cert-sign@.container ssh-host-certs: Run sshca-cli from a container 2024-01-17 20:30:34 -06:00
ssh-host-certs-renew.target ssh-host-certs: Run sshca-cli from a container 2024-01-17 20:30:34 -06:00
ssh-host-certs-renew.timer ssh-host-certs: Run sshca-cli from a container 2024-01-17 20:30:34 -06:00
ssh-host-certs.service ssh-host-certs: Run sshca-cli from a container 2024-01-17 20:30:34 -06:00
ssh-host-certs.yaml ssh-host-certs: Run sshca-cli from a container 2024-01-17 20:30:34 -06:00
sshkeys.yaml sshkeys: Trust certificates issued by the CA 2023-10-03 20:06:37 -05:00
zram.yaml zram: Configure swap-on-zram 2023-09-16 08:15:08 -05:00