Chat Logs

  1. phalethhi
  2. phalethstill getting the same error when trying to start nevet https://paste.debian.net/plainh/dab58abd
  3. phalethpostgres is reachable from the app server https://paste.debian.net/plainh/0108da55 and I'm not sure if I should try postgres 17.9
  4. phalethit's very difficult to debug startup of this application since it leaves no clue if it can or cannot read environment variables on startup
  5. phalethafk
  6. phalethlooks like I should update gitea once gitea 1.25.5 is out and figure out how to build prometheus from source https://go.dev/blog/allocation-optimizations
  7. nevetAllocating on the Stack - The Go Programming Language
  8. phalethalso shame on google for not doing these optimizations much much earlier
  9. bluephaleth: yes, that's the error I got
  10. bluedreamreal: any idea how we can debug this?
  11. blueFeb 28 06:45:48 nevet java[55]: SQL State : 08001
  12. bluephaleth: are you sure the nevet container can see the app one, they're on the same network?
  13. blueCaused by: java.net.UnknownHostException: postgres:bfK7kP2fcyO7oUxN@192.168.1.105
  14. phalethoh it leaks password
  15. bot<discord:blue> yes
  16. phalethyeah, the nevet app can reach the db container, see the second paste
  17. blueoh, this is from the nevet app?
  18. phalethI think env vars are not being read
  19. phalethyeah, it's java
  20. blueare the env vars available in the container
  21. blue?
  22. phalethor is nevet not java? I don't know what this is then, was supposed to deploy the java app
  23. blueyes, nevet is kotlin, which is java
  24. phalethenv vars are set by systemd
  25. bluecan you do echo $DB_URL in the container?
  26. blueactually, I think I can enter the container myself and check
  27. bluece332a-nevet-srv
  28. blue?
  29. phalethno you cannot, cause env vars are set only for the systemd process that manages the kotlin or whatever app
  30. bluenevet.service?
  31. phalethwhich apps can normally read just fine, but not this one
  32. phalethyeah
  33. blueman I can't even use ping from inside the container
  34. bluethose images are really reduced :P
  35. phalethapt update
  36. phalethapt install iputils-ping
  37. bluethx
  38. phalethnp
  39. bluehm, looks fine indeed
  40. blueyup:
  41. blueroot@nevet:/etc/systemd/system# systemctl show nevet --property=Environment
  42. blueEnvironment=
  43. phalethanyway, normally applications should be self-discoverable, they should tell what you need to configure and error out if something is missing, but this is again some stuff hacked together that only runs on the developers machine
  44. phaleththe systemd property is called EnvironmentFile
  45. blueyes
  46. blueFeb 28 12:21:19 nevet java[892]: Build: ${git.commit.id.abbrev} (${git.branch}) ${git.build.time}
  47. bluebtw this line is also suspicious
  48. phalethI used a zip copy of the code to build the app
  49. bluephaleth: looks better, I removed username/password from the connection string, it kills java
  50. blueinstead, it loads them from the env vars
  51. bluenow there's some oauth2 issue
  52. blueFeb 28 12:24:37 nevet java[945]: Caused by: java.lang.IllegalStateException: Client id of registration 'google' must not be empty.
  53. blueHMMMMMM
  54. bluedreamreal: is this a hard requirement?
  55. phalethok, cool, I had no idea that was the problem and why I have to specify the credentials second time
  56. blueat least we're getting somewhere. but I think now we need dreamreal's help, and it's shabbat, he might be slow to respond
  57. blueit's actually better this way, phaleth. the password doesn't get leaked
  58. phalethyeah, I'll reset the password
  59. blueI'd still prefer if the jdbc connection string supported that, but it's ok
  60. blueapparently this is the officially documented for postgres jdbc: jdbc:postgresql://[REDACTED:url-credentials]@host:port/database
  61. blueah, sorry, I mean this:
  62. phalethI'd prefer jdbc making any sense in it's error messages
  63. bluejdbc:postgresql://host:port/database
  64. bluetrue
  65. phalethok
  66. blueapparently what also works are params
  67. bluejdbc:postgresql://host:port/database
  68. bluewith ?user=...&password=...
  69. phalethok, it run migrations
  70. blueit did?
  71. blueI can't tell, it's borked because there's no google client id
  72. bluebtw phaleth: https://github.com/primate-run/primate/issues/251
  73. nevetProposal: Add `AppFacade#env(key: string)` · Issue #251 · primate-run/primate
  74. phalethhere's the almost full log https://api.pastecode.io/anon/raw-snippet/rwoe5ynj?raw=inline&ticket=329e0fa6-7403-4e9a-adb3-d78889e19cb5
  75. nevetUntitled (rwoe5ynj) - PasteCode.io
  76. bluephaleth: meanwhile, could you change the deployment to come from https://gitea.repopack.app/blue/bytecode.news
  77. bluebecause this contains the primate app in apps/primate
  78. bluefor which we also need a container
  79. phalethyeah, I can try
  80. bluenice log, yes I get the same google error
  81. blueapparently it needsa GOOGLE_CLIENT_ID and _SECRET
  82. bluehttps://gitea.repopack.app/blue/bytecode.news/src/branch/master/.env.default
  83. bluethis isn't documented here yet
  84. bluephaleth: https://gitea.repopack.app/blue/bytecode.news/src/branch/master/docs/deployment.md
  85. blue`Nevet supports "Sign in with Google" and "Sign in with GitHub" via OIDC / OAuth2. Both are optional and independent -`
  86. bluehm
  87. bluemaybe this is a bug
  88. blueit should work without the GOOGLE_CLIENT_ID, but maybe the env variable has to be set? dunno
  89. blueyeah, I don't think it's optional
  90. bluespring picks it up automatically, and tries to configure it, hits empty string or missing property, dies
  91. phaleth"If `GOOGLE_CLIENT_ID` and `GITHUB_CLIENT_ID` are both empty, OIDC endpoints are not registered and the app runs OTP-only."
  92. blueyeah, that's simply not true in this case. or maybe we need to include those two env vars but set them to empty
  93. blueshould I try that?
  94. phalethnot sure if whatever reads those properties is that dumb, but null and empty is something different for sure
  95. phalethI mean env vars
  96. blueyeah, it's spring, and spring is a truckload of magic that no one understands
  97. blueI'm gonna try empty vars. but empty vars should be virtually the same as non-existent
  98. bluenope, still dying
  99. blueOMG
  100. bluechatgpt is telling me I need to "Move the Google registration into a profile:"
  101. bluebut then I'll need to rebuild the container
  102. phalethI can rebuild the container
  103. phalethbut I don't follow what chatccp is saying
  104. dreamrealYou should be able to put trash values in there, and I'm going to try to figure out how to make those things optional - it shouldn't be that hard to do - but the UI shoudl expect OIDC to be present, is the problem
  105. dreamrealbut you shouldn't have to rebuild a container to provide values to it, we need to be able to externalize them and put them in .env and docker just imports them
  106. phalethagreed
  107. phalethblue: I assume you can just rebase https://gitea.repopack.app/blue/bytecode.news ?
  108. bluephaleth: yes, once dreamreal fixes this google nonsense
  109. blueI don't know if I can just delete it from application.yml and it would work
  110. phalethok
  111. phalethlet's try getting the code from gitea then
  112. blueyes, it has the primate app under apps/primate, too
  113. blueI'm gonna sync my gh fork, then pull down stuff onto gitea
  114. blueomg
  115. phaleththere's a CLI called tea
  116. blueMerge branch 'jottinger:main' into master
  117. bluedid I tell you how much I hate GH?
  118. blueinstead of rebasing my branch, it does this nonsense
  119. bluemy fork*
  120. phalethall of these cli's are garbage
  121. phalethglab on top
  122. blueit's not a cli
  123. blueI went to gh, hit 'sync' fork
  124. phalethgh is github cli
  125. blueoh man
  126. bluegithub is such a garbage website
  127. blueoh man and I asked chatgpt and it spews total nonsense
  128. blueit claims rebase rewrites history. no it wouldn't, it wouldn't rewrite the upstream history, that's the poitn
  129. bluenvm, I'll do it myself
  130. bluegithub ui is nonsense
  131. phalethyeah, and I'll just download tar over https during the build, cannot be bothered figuring out something else
  132. bluephaleth: done
  133. bluegitea is rebased against the latest commmit + two primate app commits
  134. bluehttps://gitea.repopack.app/blue/bytecode.news
  135. blueonce he pushes out a fix, I can easily rebase again and push out to gitea
  136. bluewe need `ce332a-nevet-app` for primate, right?
  137. phalethfor primate?
  138. phalethno clue
  139. phalethI'll deploy the kotlin thing to that container
  140. blueyou want to put them in the same container?
  141. phalethoh, you always call everything app
  142. bluethe nevet java thingy is -srv
  143. phalethand that container name does not exist obviously, but I get it
  144. phalethyeah
  145. blueI was thinking you'd add -app for the primate app
  146. blueso specifically, for the code under apps/primate
  147. phalethyeah
  148. phalethI mean nah
  149. dreamrealokay, found it: creating an issue and I'm going to create a runtime profile so you can enable/disable OIDC with an invocation flag
  150. phalethlook at: sudo machinectl list
  151. phalethif everthing was an app that'd be a disaster
  152. bluece332a-nevet-db container systemd-nspawn debian 13 192.168.1.105…
  153. bluece332a-nevet-srv container systemd-nspawn debian 13 192.168.1.107…
  154. phalethit already is in other ways
  155. blueI was thinking you'd add ce332a-nevet-app for the primate app
  156. phalethI will add another container for primate, sure, but not gonna label it with -app
  157. bluesure, call it whatever you like
  158. dreamrealI'm gonna have a PR for this in a few minutes
  159. dreamrealSPRING_ACTIVE_PROFILES=oidc java -jar app-1.0.jar # this will require OIDC, ignore it otherwise
  160. phalethok
  161. dreamrealmain has been updated
  162. bluephaleth: it's on gitea
  163. dreamrealso: the *configuration* hasn't changed in .env but it won't try to use OIDC unless that profile is activated
  164. dreamrealI've got another issue for the UI to be able to introspect whether OIDC is enabled or not, but I haven't written anything for it yet
  165. blueah sorry dreamreal, I accidently pushed to upstream/master, let me delete it
  166. dreamrealhttps://github.com/jottinger/bytecode.news/issues/128
  167. phalethI will just put SPRING_ACTIVE_PROFILES=oidc into the env file
  168. dreamrealphaleth: do that ONLY IF YOU WANT OIDC enabled
  169. dreamrealif you don't, yeet it
  170. dreamrealthe default profile will not use OIDC
  171. phalethok, I'll get rid of it then
  172. dreamrealOIDC means configuring the google oauth tokens and setting up the github stuff
  173. blueok, I deleted it again
  174. dreamrealfor developers, that shouldn't be necessary unless they're specifically testing that path
  175. bluedreamreal: it's best if you changed my role on the original repo to readonly
  176. blueI'll keep accidently pushing master otherwise, but I don't need to
  177. phalethor just migrate github -> gitea, main -> master
  178. dreamrealyou're gonna love this, blue: github doesn't let me set it to readonly :D
  179. blueyeah that's what I did, but I accidently did `git push origin` and it pushed it to his repo
  180. dreamrealNot for a private repo, maybe
  181. blueor well, git push upstream, that was dumb
  182. phalethhmm, could set the main branch as protected or whatever github calls that
  183. blueI have upstream = his repo (jottinger/bytecode.news), origin (gitea) and then github (same fork, on github)
  184. dreamrealphaleth: doing that now
  185. blueI don't think I need github at all, but once I start sending him PRs, I don't know if I can do it from gitea
  186. dreamrealoh, damn you github
  187. dreamrealwon't apply to the repo because it's private
  188. dreamrealit might be good enough that it's time to move it, actually
  189. phalethheh
  190. dreamrealblue: what do you think? Nevet's exceeded the prior version enough to become IT?
  191. phalethI have no problem giving your access to our gitea
  192. dreamrealdear god no
  193. dreamrealI'm swimming in access as it is
  194. bluephaleth, he means moving it to a public github repo, I think. but why move it, dreamreal, why not just open up the repo?
  195. blueif you move it you lose all the issues
  196. dreamrealI was just gonna rename it and open it
  197. blueor do you mean with 'move', change from private to public?
  198. blueoh, gotcha
  199. dreamrealbut maybe opening it is enough
  200. phalethah, ok
  201. bluewell this limitation is ridiculous anyway
  202. dreamrealeverything is ridiculous, that's why we laugh
  203. blueno I mean, the way github cripples its features when your repo is private
  204. blueunder the guise of promoting FOSS. but it's exactly the opposite, they want you to pay
  205. blueprivate & public should get the same treatment, and premium features should cost either way
  206. blueanyway
  207. bluedon't open it up on my behalf
  208. blueI'll try to set up git to prevent me from accidently pushing master to upstream
  209. dreamrealso: any opinion on it being streampack vs bytecode.news?
  210. dreamrealdoeth the speaky-speaky things now, losers, or forever hold thy peace
  211. blueI don't have a specific opinion. but currently you're using three names and it's confusing, pick one and stick to it. if you already got the domain, then bytecode it is
  212. dreamrealwe're jews, names are transitory, be a jew :D
  213. blueya well
  214. dreamrealphaleth: any opinion? We have one vote for bytecode.news
  215. phalethsay it three times and you'll see
  216. dreamrealfor some reason it counts
  217. bluelol
  218. phalethreact-router react-router react-router, doesn't catch on
  219. dreamrealI have more votes than anyone else, so I win no matter what, but I'd like to hear from the el gallery anyway
  220. dreamrealbytecode.news three times isn't catchy either but that's fine
  221. blueI told him bytenews is better, but he won't listen
  222. dreamrealI actually like nevet but nevet's a specific instance, not THE PROJECT
  223. blueI'd personally get the domain bytenews.dev :P
  224. dreamrealphaleth: any opinion?
  225. dreamrealblue: I may have already gotten it
  226. dreamrealI don't remember
  227. phalethnevet should have ended with h, then it'd be cool like phaleth
  228. phalethwasted opportunity there
  229. dreamrealphaleth: only dorks' names end in h
  230. phalethheh
  231. * dreamreal used to use "Epesh" as a nick for YEARS
  232. dreamrealand in some communities Epesh is still remembered
  233. dreamrealblue: my hebrew is very very strong, as you see: mistranslit of efes
  234. blueyes I noticed. you also seemed to remember nevet means stream
  235. dreamrealI know, I know
  236. dreamrealI forget the first name we came up with
  237. dreamrealbut I like nevet
  238. bluethankfully, I'm here to correct you
  239. dreamrealI also like alit but I know a really cute lady named alit and that would be unseemly
  240. dreamrealI figured you deserved a chance to be right for once
  241. blueyeah that's a girl's name, nevet's a boy
  242. dreamrealmmm alit. If I'd been single I'd have seen her as a missed opportunity. Wonderful lady, though. Flighty, red hair, lithe... and a missile launch technician in the IDF :D
  243. blueyeah you don't wanna mess with that
  244. dreamrealnow a yoga instructor in sfarad
  245. bluehahahaha
  246. dreamrealoh if I'd been single I'd DEFINITELY have wanted to mess with that
  247. dreamrealI was not, plus I'm a professional, so there's no effin' way but biologically hell to the yes
  248. bluewell yeah, that's the problem isn't it
  249. dreamrealnot a problem. I love alit as a friend. There's no temptation there; she's just a hell of a person and I respect that.
  250. dreamrealphaleth: fine, you have no opinion
  251. dreamrealdealer's choice wins: I have voted as well
  252. blue heh
  253. phalethyeah, I'd say thanks for asking for an opinion, but I can't give any on something I have no clue about
  254. bluelol
  255. phalethbtw, before you open up the github repo to the world consider the following
  256. phalethsetup the copy of the repo somewhere else, and use the github repo as a mirror and continue using github only for issues and abandon PRs
  257. phalethand of couse setup an action/pipeline/whatever to push to github automatically
  258. phalethPRs on github can be disabled, not sure that's a paid feature
  259. blueit's been recently added, not paid
  260. dreamrealI don't want them disabled, I want them demanded
  261. dreamrealphaleth: that's certainly an option but no
  262. phalethyeah, right, the point of a mirror is to be read-only except for the action/pipeline from the other repo
  263. bluephaleth, did the oauth problem get solved?
  264. phalethnot yet, trying to find a place where to generate token in gitea
  265. dreamrealwhich oauth problem are you trying to solve?
  266. dreamrealand bytecode.news is now a public repo
  267. phalethoh, ok, what's the github url?
  268. dreamrealgithub.com/jottinger/bytecode.news
  269. phalethI think blue will want his stuff to be there, so I'll search for how to get the token from gitea
  270. phalethprivate access token I mean
  271. blueya
  272. phalethah, so it's under Settings -> Applications
  273. bluecool
  274. phalethlooks good now https://quickpaste.net/iWAoGlr/plain
  275. bluegood
  276. bluenow we need the primate app, no?
  277. bluecan you expose it under nevet.repopack.app?
  278. phalethsits at the top https://images4.imagebam.com/1a/5a/bf/ME1AZS3Y_o.png
  279. phalethtry if it's reachable at nevet.repopack.app
  280. phalethI actually have absolutely zero clue how to test that app
  281. phalethcurl maybe
  282. bluelet me add an index app
  283. phalethI guess it's not listening on port 80
  284. bluenope, it'd be the normal primate port at 6161
  285. bluedone
  286. phalethok, it's listening on 8080 but should I open that to the interwebz you mean?
  287. bluehttps://gitea.repopack.app/blue/bytecode.news/commit/9cbc244b72d5b46b0bf7a7c0fd465484d7ea9eb2
  288. bluethe java app is listening on 8080
  289. bluebut you only need to open the primate app
  290. phaleththe one which I didn't deploy yet
  291. blueyes
  292. bluethe primate app will send requests to the nevet api, internally, on the network
  293. bluebut only it will be exposed outside
  294. phalethok, makes sense
  295. blueso my ideal setup is, I have a script or something to pull & redeploy the nevet primate app / nevet itself, think we can do that?
  296. phalethno package-lock.json again, ok
  297. blueyes
  298. blueI don't do package-lock.jsons :P
  299. phalethI'll push the documentation once you tell me it works
  300. phalethand then you can automate, but hold on
  301. bluek
  302. phalethblue: https://quickpaste.net/fGq-nFg
  303. nevetQuickpaste
  304. phalethNode.js v25.7.0
  305. bluesweet
  306. dreamrealGah
  307. dreamrealurl list
  308. dreamrealurl ignore list
  309. nevetIgnored hosts include: x.com, twitter.com, paste.debian.net, pastebin.com, bpa.st, dpaste.com, and pastebin.org
  310. dreamrealurl ignore add quickpaste.net
  311. nevetAdded quickpaste.net to ignored hosts.
  312. blueFeb 28 15:08:48 nevet-primate node[75]: Error: Cannot find module '/app/build/server.js'
  313. bluewhat's that?
  314. bluenevet-prmt, is that the machine, phaleth?
  315. phalethwell I have no clue how to start it
  316. phalethyeah
  317. phalethit builds, prolly outputs a build dir
  318. phalethserver.js is what I'd expect
  319. blueyes
  320. bluehm
  321. phalethah, the build subdir got omitted
  322. blueyes
  323. bluethough even if I run `node server.ts`, it fails
  324. bluehm hm hm
  325. phalethserver.ts?
  326. phaleththink that will work on node, I guess it should
  327. blueserver.js
  328. bluesorry
  329. phalethok, well, let me rebuild
  330. blueso locally it works for me `node build/server.js`
  331. blueso when I'm automatically, I'm gonna overlay a .env file onto the build,
  332. bluewhen I'm automating it*
  333. bluethis is actually something I haven't explored yet, because .env files aren't usually baked into a build
  334. blueI'll just copy it into `build` after `npm run build` runs, in the Containerfile, I think
  335. phalethok, blue, it fails on some sort of assert https://quickpaste.net/7PWeP6l
  336. blueyeah that's what I can see locally
  337. blueor well, if I try to run it within the image
  338. bluemaybe a package.json is necessary
  339. bluelet me stub it
  340. phalethok, I gotta go out, I'll just push the documentation to gitea for you to see what I've done
  341. bluealrighty
  342. bluewelp, got it running on 6161
  343. bluenow I just need to adapt the haproxy config and reload the haproxy containre, no?
  344. blueah, you already have it
  345. bluesweet
  346. phalethcheck the provision repo the last commit - 0ac59c2a890370a11d1a246b6bff4072518228c4
  347. bluebefore you go, do you have any idea why nevet.repopack.app isn't working?
  348. bluethe app is running in the container at port 6161
  349. bluealso, thanks for the docs, I'll automate it into a script so I can easily redeploy
  350. phalethit's still repeatedly crashing with that error
  351. phalethneed to rebuild and restart as per instructions
  352. blueFeb 28 15:25:57 nevet-primate systemd[1]: Started nevet-primate.service - Primate Nevet Site.
  353. blueFeb 28 15:25:57 nevet-primate node[4114]: » app url http://localhost:6161
  354. bluethat's inside the ocntainer though
  355. bluehm, maybe localhost is false
  356. phalethtry this
  357. phalethjournalctl -n 150 -f -u nevet-primate
  358. blueya
  359. blueit contains old entries
  360. blueoh
  361. blueyou mean it keeps crashing?
  362. phalethyeah
  363. phalethif you are not sure then wipe out the container and try again
  364. bluethe last two lines though are
  365. blueFeb 28 15:25:57 nevet-primate systemd[1]: Started nevet-primate.service - Primate Nevet Site.
  366. blueFeb 28 15:25:57 nevet-primate node[4114]: » app url http://localhost:6161
  367. phalethweird
  368. phalethlet me ditch it
  369. blueif you recreate the container, you'll have the same problem
  370. blueyou need to copy over the original package.json, outside of build
  371. bluethis is a primate bug
  372. blueor an rcompat bug, doesn't matter, but you need a package.json somewhere because it uses that to find paths
  373. phalethI'm rebuilding with --no-cache
  374. phalethoh, ok
  375. blueoki, but make sure you copy `package.json` from the repo onto /app
  376. phalethinto /app and not /app/build?
  377. blueyes
  378. phalethweird
  379. blueit's something I need to fix, I don't know why it does on a production build where everything is self-contained
  380. bluewhy it does that*
  381. blueyou did everything right, it's a primate problem, but I can't fix it in primate quickly
  382. blueso for now copying the original package.json will solve it
  383. bluedreamreal: is there a reason java container is costing us 700mb of RAM?
  384. phalethit's running
  385. bluebut nevet.repopack.app is still not working?
  386. phalethit does
  387. blueweird, I get 503
  388. bluehttps://nevet.repopack.app is working for you?
  389. phaleth» app url http://localhost:6161
  390. phalethgotta configure it to listen to any address
  391. blueok, that would be 0.0.0.0
  392. phalethfrom the VM I get:
  393. phaleth$ curl -IL 192.168.1.108:6161
  394. phalethcurl: (7) Failed to connect to 192.168.1.108 port 6161 after 0 ms: Could not connect to server
  395. phalethanyway, you can do it blue, it's the same old same old, primate issues from now on :D
  396. bluealright
  397. bluelet me figure out how I can rebuild the machine
  398. blueheh, you're using an auth header
  399. bluesweet
  400. blueMerge pull request #136 from jottinger/feature/128-feature-discovery-endpoint