Skip to content

Conversation

rgaiacs
Copy link
Collaborator

@rgaiacs rgaiacs commented Mar 31, 2025

Closes #3264

@rgaiacs rgaiacs self-assigned this Mar 31, 2025
@rgaiacs rgaiacs force-pushed the 3264-new-gesis-server branch from db4e8b2 to 1d9b1ef Compare April 2, 2025 15:39

# We share the registry with 2i2c
registry:
enabled: false
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This still needs to be enabled. What we'll share is the backing object store that the registry talks to, so the storage that the registry uses will be the same. But we still need a registry to serve them from here. So this config should match exactly what's in the hetzner-2i2c one (including secrets) so it can use the same storage backend but run its own server.

@rgaiacs
Copy link
Collaborator Author

rgaiacs commented Apr 3, 2025

@rgaiacs and @arnim have access to the new GESIS Server at Hetzner Online GmbH. K3s is configured in the new GESIS Server at Hetzner Online GmbH.

@yuvipanda
Copy link
Contributor

Can you invite me to the project as well?

@rgaiacs
Copy link
Collaborator Author

rgaiacs commented Apr 3, 2025

@yuvipanda I want to invite you to the project but GESIS IT did not even added me or @arnim to the project. The IP of the server is 78.46.233.119.

@yuvipanda
Copy link
Contributor

Ah! Is that something they'd be willing to do? I think it's important for us to have access there, for two reasons:

  1. Hetzner sends out network abuse reports for us to deal with, and we must deal with them. I'm guessing GESIS IT doesn't wanna do that, nor can they realistically
  2. Need access to the console for setting up additional disks (For DIND) as well as firewall rules

@rgaiacs
Copy link
Collaborator Author

rgaiacs commented Apr 3, 2025

I think it's important for us to have access there, for two reasons

I agree with you. @arnim and I explained the reasons. But the person that assisted us today to get the server running could not make the decision regarding giving us access to the dashboard.

@rgaiacs
Copy link
Collaborator Author

rgaiacs commented Apr 3, 2025

Need access to the console for setting up additional disks (For DIND) as well as firewall rules

We mirror the configuration of the server provided by 2i2c that you configured.

@yuvipanda
Copy link
Contributor

I've added DNS records for gesis.mybinder.org and *.gesis.mybinder.org to 78.46.233.119. Hopefully that unblocks you, @rgaiacs.

Hetzner's network abuse policy is that we must respond and take action often within 48 or 72h, or they will simply stop all network traffic to the server. So, I think we must have project access before we can take this into rotation.

@rgaiacs rgaiacs force-pushed the 3264-new-gesis-server branch from 617b4e3 to b6e58b4 Compare April 3, 2025 19:53
@rgaiacs rgaiacs changed the title DRAFT: Configure new GESIS Server at Hetzner Online GmbH Configure new GESIS Server at Hetzner Online GmbH Apr 3, 2025
@rgaiacs
Copy link
Collaborator Author

rgaiacs commented Apr 3, 2025

This PR will only configure the server. In another PR we will add the server to the federation. I'm merging this as it only changes the files in the GESIS namespace.

@rgaiacs rgaiacs merged commit 3428e54 into jupyterhub:main Apr 3, 2025
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

New GESIS Server at Hetzner Online GmbH
2 participants