F-Droid Devs

112 Members
F-Droid development discussion only | Use #fdroid:f-droid.org for general, app- and repo-related matters | Meeting every Thursday at 11:30 UTC | This channel is publicly logged at https://view.matrix.org/alias/%23fdroid-dev:f-droid.org22 Servers

Load older messages


SenderMessageTime
5 Jun 2020
@eighthave:matrix.org_hc1GB is the max site size19:00:43
@freenode_cdesai:matrix.orgcdesaijust adding files to a git repo could work too.19:00:49
@eighthave:matrix.org_hcyeah, there's a 10GB limit for git repos19:01:12
@eighthave:matrix.org_hcnot easily viewable though19:01:22
@eighthave:matrix.org_hcso the max snippet size is 50MB! https://docs.gitlab.com/ee/administration/snippets/19:02:16
@freenode_cdesai:matrix.orgcdesaicould compress the logs if put in the git repo19:02:34
@eighthave:matrix.org_hcI agree it would be nice to have the build logs in gitlab-ci, but it seems we would have to give up so much to have that19:02:52
@eighthave:matrix.org_hcsnippets are easy to post via the API19:03:16
@eighthave:matrix.org_hc one liner with curl, or very simple in python 19:03:26
@eighthave:matrix.org_hcoh 50MB is the default size, I wonder what gitlab.com uses19:04:08
@bubu:bubu1.euBubu
In reply to @freenode_cdesai:matrix.org
you don't have a central resource with ssh access to your infra.
gitlab ci coordinator don't have access to your infra
19:05:12
@bubu:bubu1.euBubuthe runner polls for jobs19:05:24
@bubu:bubu1.euBubuand executes them in docker containers19:05:32
@eighthave:matrix.org_hcgitlab.com could feed arbitrary jobs to your runner19:05:54
@bubu:bubu1.euBubuyes19:06:06
@bubu:bubu1.euBububut gitlab.com already has full project acess across the board19:06:35
@bubu:bubu1.euBubuthe runner isn't doing anything else19:06:41
@bubu:bubu1.euBubuWe can host our own gitlab19:07:24
@eighthave:matrix.org_hcright except for they cannot add commits to master, then remove them without anyone being able to notice19:07:37
@eighthave:matrix.org_hcgit gives us that19:07:46
@bubu:bubu1.euBubuIt's pretty easy, but the network effect of eveyone having to sign up there is super bad :(19:07:53
@freenode_cdesai:matrix.orgcdesai it'd also be an additional thing to maintain / admin / update 19:08:16
@bubu:bubu1.euBubu
In reply to @eighthave:matrix.org
right except for they cannot add commits to master, then remove them without anyone being able to notice
It sure can?
19:08:43
@eighthave:matrix.org_hcI would not like to have to defend a gitlab box like that19:08:49
@eighthave:matrix.org_hcso like push commit with exploit, then remove it to hide tracks19:12:46
@eighthave:matrix.org_hcif no one downloads it, then yes, they can19:12:47
@eighthave:matrix.org_hcgitlab.com could send a job to a runner without any log of it or public record. only the runner would see it. if its an exploit, then they remove the trace of that job from the runner19:12:48
@eighthave:matrix.org_hcthat's standard exploit practice19:12:49
@eighthave:matrix.org_hcthat just gave me an idea: we should have a box that just constantly mirrors master on all our git repos as a monitor19:12:50
@eighthave:matrix.org_hcif expploiter pushes a commit to master, then someone downloads it, then the exploiter cannot make that commit go away19:13:05

Show newer messages


Back to Room ListRoom Version: 1