Compare commits

...

3 Commits

Author SHA1 Message Date
oysteikt 9a837d210d bicep/postgres: log connections/disconnections
Build topology graph / evals (push) Successful in 3m23s
Eval nix flake / evals (push) Successful in 8m59s
2026-07-21 16:39:25 +09:00
oysteikt d3c9fabbc2 base/irqbalance: only start on multi-socket machines 2026-07-21 16:38:38 +09:00
oysteikt 950b163869 bicep/postgresql: use scram-sha-256 as default password algorithm 2026-07-21 16:32:49 +09:00
2 changed files with 30 additions and 2 deletions
+20 -2
View File
@@ -1,4 +1,22 @@
{ ... }:
{ config, pkgs, lib, ... }:
let
cfg = config.services.irqbalance;
in
{
services.irqbalance.enable = true;
}
# irqbalance only has meaningful work to do on multi-socket machines, so
# skip starting it pointlessly everywhere else.
systemd.services.irqbalance.serviceConfig.ExecCondition = let
isMultiSocket = pkgs.writeShellApplication {
name = "irqbalance-is-multi-socket";
runtimeInputs = [ pkgs.coreutils ];
text = ''
sockets=$(cat /sys/devices/system/cpu/cpu*/topology/physical_package_id | sort -u | wc -l)
[ "$sockets" -gt 1 ]
'';
};
in lib.mkIf cfg.enable [
(lib.getExe isMultiSocket)
];
}
@@ -14,6 +14,7 @@ in
extensions = ps: with ps; [ pg_repack ];
enableTCPIP = true;
# NOTE: md5 accepts both md5 and scram-sha-256
authentication = ''
host all all ${values.ipv4-space} md5
host all all ${values.ipv6-space} md5
@@ -76,6 +77,15 @@ in
maintenance_io_concurrency = 100;
wal_recycle = true;
# -------------------------------- #
# Authentication
password_encryption = "scram-sha-256";
# Logging
log_connections = "authorization";
log_disconnections = true;
# SSL
ssl = true;
ssl_cert_file = "/run/credentials/postgresql.service/cert";