<@pboy:fedora.im>
17:00:20
!startmeeting fedora-server
<@meetbot:fedora.im>
17:00:22
Meeting started at 2026-06-03 17:00:20 UTC
<@meetbot:fedora.im>
17:00:22
The Meeting name is 'fedora-server'
<@pboy:fedora.im>
17:00:29
!topic Roll Call
<@eseyman:fedora.im>
17:00:33
!hello
<@pboy:fedora.im>
17:00:37
!group members server-wg
<@zodbot:fedora.im>
17:00:43
Emmanuel Seyman: Emmanuel Seyman (eseyman) - he / him / his
<@zodbot:fedora.im>
17:00:48
Members of server-wg: Alexander Bokovoy, Adam Williamson, Paul Maconi, eseyman, jwhimpel, Kevin Fenzi, korora (@korora:fedora.im, @korora1981:matrix.org), mowest, ngompa (@conan_kudo:matrix.org, @ngompa:fedora.im, @pharaoh_atem:opensuse.org, @ngompa:kde.org, @ngompa:almalinux.im), Peter Boy, Stephen Gallagher
<@pboy:fedora.im>
17:01:06
Welcome to our weekly Server WG meeting.
<@eseyman:fedora.im>
17:01:14
Hello, Peter
<@pboy:fedora.im>
17:01:17
I'll post the agenda in 2-3 minutes.
<@pboy:fedora.im>
17:01:17
As usual, let's wait a moment for everybody to show up.
<@pboy:fedora.im>
17:01:25
Hi Emmanuel!°
<@brettweir:matrix.org>
17:01:53
Hello, I'm here but reduced capacity 😄
<@brettweir:matrix.org>
17:01:59
Mostly listening
<@pboy:fedora.im>
17:02:00
I guess we must hurry to coordinate our Flock contribs.
<@pboy:fedora.im>
17:02:22
Brett: You are topic 2
<@pboy:fedora.im>
17:04:51
Hm, I guess, we are going to miss our quorum today. But maybe, we should just start in style of an open discussion and see, how it goes.
<@pboy:fedora.im>
17:05:04
!topic Agenda
<@pboy:fedora.im>
17:05:13
!info Follow-up actions & announcements
<@pboy:fedora.im>
17:05:22
!info Server Ansible Support
<@pboy:fedora.im>
17:05:34
!info home server spin-off: preinstalled applications
<@pboy:fedora.im>
17:05:42
!info Open Floor
<@pboy:fedora.im>
17:05:56
Anything to add?
<@eseyman:fedora.im>
17:06:08
No, I'm good
<@pboy:fedora.im>
17:06:17
OK.
<@pboy:fedora.im>
17:06:25
!topic 1. Follow-up actions & announcements
<@pboy:fedora.im>
17:06:35
https://docs.fedoraproject.org/en-US/server-working-group/wg-minutes-2026/
<@pboy:fedora.im>
17:06:35
meetings overview:
<@pboy:fedora.im>
17:06:35
Regarding the action, see the list in our
<@pboy:fedora.im>
17:06:42
Current status is:
<@pboy:fedora.im>
17:06:53
<@pboy:fedora.im>
17:06:53
.
<@pboy:fedora.im>
17:06:53
eseyman writes an Ansible playbook that applies the official post-installation tasks.
<@pboy:fedora.im>
17:06:53
<@pboy:fedora.im>
17:06:53
2.
<@pboy:fedora.im>
17:06:53
Conan Kudo will fix Kiwi to set the right partition type of Linux LVM for the system partition on KVM guest and arm image.
<@pboy:fedora.im>
17:06:53
3.
<@pboy:fedora.im>
17:06:53
MatH will compose the existing ideas and proposals into a TOC proposal, perhaps already for next meeting
<@pboy:fedora.im>
17:06:53
<@pboy:fedora.im>
17:06:53
4.
<@pboy:fedora.im>
17:06:53
pboy will implement the Fedocal workarount for providing meeting location address
<@pboy:fedora.im>
17:06:53
<@pboy:fedora.im>
17:06:53
5.
<@pboy:fedora.im>
17:06:53
pboy will put together the originally planned way of Ansible support for pre-installed software in home server spin-off in the server matrix room.
<@pboy:fedora.im>
17:07:31
No announcements from me, otherwise.
<@eseyman:fedora.im>
17:07:45
FTR, step 1 is still ongoing
<@pboy:fedora.im>
17:08:53
Yeah, its more a reminder of the list, which is mostly burried in our wg docs. :-)
<@pboy:fedora.im>
17:09:06
OK, let's start.
<@pboy:fedora.im>
17:09:19
!topic 2. Server Ansible Support
<@pboy:fedora.im>
17:09:52
Brett wrote a contribution, mostly about home server spin-off, but may be relevant not only for that.
<@pboy:fedora.im>
17:10:02
https://codeberg.org/brettweir/fedora-home-server-guide/src/branch/main/docs/management.md
<@pboy:fedora.im>
17:10:23
Probably 5 mins to read??
<@brettweir:matrix.org>
17:10:40
Yeah I suppose so hehe
<@eseyman:fedora.im>
17:17:49
I've used Ansible for so long that I have difficulty putting myself in the shoes of someone starting out
<@pboy:fedora.im>
17:18:12
Yes, that's not easy, indeed.
<@pboy:fedora.im>
17:19:21
Regarding ssh key: In our Server doc we disable password ssh,too, but with the exception of ant least one user (or two) so you have a fall back solution, just in case something goes wrong with the keys.
<@pboy:fedora.im>
17:19:44
Or when you have to use a machine, where you don't have the keys.
<@theprogram:fedora.im>
17:19:56
!hi
<@zodbot:fedora.im>
17:19:58
MatH: Mat H (theprogram)
<@pboy:fedora.im>
17:20:35
Welcome MatH
<@brettweir:matrix.org>
17:21:11
I'm accustomed to password auth being fully disabled since a lot of cloud providers require it
<@theprogram:fedora.im>
17:21:15
Hello, I'm in Poznan now, had to talk to people
<@pboy:fedora.im>
17:21:45
That's on Polen, isn't?
<@pboy:fedora.im>
17:22:47
Brett: Yeah, and I'm use to always have a fallback solution, just in case. :-)
<@brettweir:matrix.org>
17:23:15
Not a bad plan
<@pboy:fedora.im>
17:23:17
And restrict is to one or two users seems save enough for me
<@pboy:fedora.im>
17:24:22
But with a home server, you will always have terminal access, so maybe you don't need a fallback for ssh. That's a big difference to prof. Server in a remote data center.
<@theprogram:fedora.im>
17:24:31
I think it is fine to have some password access for a home use case, as long as the user picks a good password
<@theprogram:fedora.im>
17:24:52
Start open and people friendly, add strict access rules later
<@brettweir:matrix.org>
17:24:52
Oh, yeah, you have physical machine access still
<@pboy:fedora.im>
17:25:20
In any case, we should shortly explain, why we recommend differently, if we do.
<@brettweir:matrix.org>
17:25:35
But yeah I'm not sure how far to go with hardening the server. I think I typically err on excessively paranoid and trying to avoid that
<@theprogram:fedora.im>
17:26:19
I would say not to go to far, but introduce those concepts in the second half, advnced section
<@theprogram:fedora.im>
17:26:30
Where you can go crazy on hardening.
<@theprogram:fedora.im>
17:27:34
A properly configured firewall, ssh keys and a root password is adequate for a home use case
<@brettweir:matrix.org>
17:28:20
One thing I'm definitely doing differently from usual is keeping the homelab on the same subnet so avahi works. My own home lab, the cluster has its own subnet 🤣
<@theprogram:fedora.im>
17:29:50
I've not used avahi, have to read up on that
<@pboy:fedora.im>
17:30:07
MatH: I think so, yes. Mostly your home server is behind a provider's router including firewall
<@brettweir:matrix.org>
17:30:24
The "homeserver.local" domain afaik
<@pboy:fedora.im>
17:31:29
Yes, but the router does a lot of securing your home lab network.
<@pboy:fedora.im>
17:31:41
So you may be a bit relaxed.
<@theprogram:fedora.im>
17:31:52
Yes, I run a router firewall and a fedora firewall
<@pboy:fedora.im>
17:32:40
Allthough, ssh will be your way to your home server from out of home, just in case you need it.
<@brettweir:matrix.org>
17:32:51
Need to add some firewall discussion to these docs too
<@brettweir:matrix.org>
17:33:33
I was thinking Tailscale, but I know others just open a port and it's fine. Or maybe use your router's OpenVPN?
<@theprogram:fedora.im>
17:33:34
can /will cockpit work from outside?
<@theprogram:fedora.im>
17:33:52
Headscale, tailscale is propriatarty freeware
<@pboy:fedora.im>
17:33:57
Cockpit works from outside via port forwarding
<@brettweir:matrix.org>
17:34:15
If you forward the port, but we'd want to lock that down more
<@brettweir:matrix.org>
17:34:32
Can add 2FA for cockpit login
<@theprogram:fedora.im>
17:34:39
Im an 'open the port' kind of guy
<@theprogram:fedora.im>
17:34:52
I dont think we can rely on openvpn compatibility on all routers
<@brettweir:matrix.org>
17:35:02
Yeah probably not
<@theprogram:fedora.im>
17:35:04
definately a good option
<@pboy:fedora.im>
17:35:49
The question is, how often you need ssh access to your server from outside? E.G. being at Flock and urgently need something?
<@pboy:fedora.im>
17:36:04
(Your forgot your slides. :-). )
<@korora:fedora.im>
17:36:29
!hi
<@zodbot:fedora.im>
17:36:30
Jocelyn Gould (UTC-4): Jocelyn Gould (korora) - she / her / hers
<@korora:fedora.im>
17:36:35
Sorry I'm late
<@eseyman:fedora.im>
17:36:52
hello, Jocelyn
<@theprogram:fedora.im>
17:37:09
As a regular traveller, if I could get my partner to help me set up a homelab at ... home ... than I could administrate it via SSH from whereever I am
<@brettweir:matrix.org>
17:37:32
Should I also do that? 🤣
<@brettweir:matrix.org>
17:37:36
!hi
<@zodbot:fedora.im>
17:37:39
Brett: Brett Weir (brettweir) - he / him / his
<@theprogram:fedora.im>
17:38:03
No denying you were here now!
<@pboy:fedora.im>
17:38:44
And if your laptop was stolen and you don't have a machine with the keys. You'll curse the keys. (I did it in February anyway)
<@brettweir:matrix.org>
17:38:44
Honestly the cockpit approach is probably great here. We don't need to open an SSH port since cockpit has a terminal
<@brettweir:matrix.org>
17:39:36
Can focus on locking down cockpit for remote access. Can still use SSH at home
<@jelle:archlinux.org>
17:39:58
There is some talk about passkey support for Cockpit but its a bit involved
<@pboy:fedora.im>
17:40:22
That would be great!
<@korora:fedora.im>
17:40:23
I routinely useb rsync for file transfers... that needs either the rsync daemon or ssh
<@jelle:archlinux.org>
17:40:44
issue here https://github.com/cockpit-project/cockpit/issues/20389
<@theprogram:fedora.im>
17:41:37
I guess we have to come to an agreed minimal standard, rather than what we individually use. And then make docs for that stuff we each love
<@brettweir:matrix.org>
17:43:07
Cockpit seems like a good baseline target because it is so uniquely Fedora
<@pboy:fedora.im>
17:43:16
I was actioned to briefly summarize my idea of using Ansible. In short: We deliver a complete playbook around roles with variables. The configuration by the user is limited to entering specific values for the variables. Ideally using a small configuration editor that we should develop for Cockpit.
<@theprogram:fedora.im>
17:43:20
Yes i like that
<@pboy:fedora.im>
17:43:49
I think, that's compatible with Bretts text so far.
<@eseyman:fedora.im>
17:43:58
That works for me
<@theprogram:fedora.im>
17:44:22
It's a great idea, but the scripting it is not in my ballpark
<@brettweir:matrix.org>
17:44:33
Yeah, I'm definitely leaning into just all ansible all the time (which admittedly is also very Fedora lol)
<@theprogram:fedora.im>
17:44:37
What would be the timeline on that Peter?
<@pboy:fedora.im>
17:45:18
That's a good question. I suppose, we have to start w/o Cockbit at first.
<@pboy:fedora.im>
17:45:26
I#
<@pboy:fedora.im>
17:46:08
I'm evaluating Cockpit support for small specific tasks. There is a special section in thje docs about that.
<@brettweir:matrix.org>
17:46:30
I don't think it needs to be a blocker. Can edit ansible configs in vim just fine lol
<@brettweir:matrix.org>
17:46:38
Would be a good addition though
<@pboy:fedora.im>
17:46:52
Yes, as a start anyway.
<@pboy:fedora.im>
17:47:32
The first task is to define the variable and get the scripting right.
<@pboy:fedora.im>
17:49:11
We have to keep in mind the intended difference to commercial NAS and fully web based solution. We want to be open, extendible (and a bit of empowering to digital sov...)
<@pboy:fedora.im>
17:49:22
Ansible is quie good for that.
<@pboy:fedora.im>
17:50:21
OK, I think, we can go on?
<@theprogram:fedora.im>
17:50:32
Commercial NSA is a minefield, really not a safe solution at all. A basic server, with a NAS solution is infinately better
<@theprogram:fedora.im>
17:51:03
RE the included software, I do not have that list yet. I am erring towards what Peter said last week - keep it minimal
<@brettweir:matrix.org>
17:51:08
Yeah I don't like locked down devices, though that's why I'm here
<@pboy:fedora.im>
17:51:17
!topic 3. home server spin-off: preinstalled applications
<@pboy:fedora.im>
17:51:52
Yes, i think we shoud start with minimal. But what is minimal?
<@theprogram:fedora.im>
17:52:13
I was too quick! Having software interpreted as protocols rather than 'apps' is one interpretation of minimal
<@theprogram:fedora.im>
17:52:49
Another interpretation is to only include things in Fedora's repos
<@theprogram:fedora.im>
17:53:08
Which cuts out a lot of what was suggested to us by people currently running their own home labs
<@pboy:fedora.im>
17:53:39
Yes, but at some point the stuff has to run, i.e. protocol or as an app. :-)
<@pboy:fedora.im>
17:54:07
Yes, we should stay with Fedora rpm, at least at first.
<@theprogram:fedora.im>
17:54:39
Perhaps Brett, Jocelyn and myself cap put aside an hour to kick that around in the next day or two?
<@theprogram:fedora.im>
17:54:53
Simply run through the list we have and tick or cross each item
<@theprogram:fedora.im>
17:55:06
Perhaps Brett, Jocelyn and myself can put aside an hour to kick that around in the next day or two?
<@pboy:fedora.im>
17:55:51
Well, maybe wi should limit us to 5-8 apps/protocols at first? We have to do all the Ansible tasks for each.
<@theprogram:fedora.im>
17:56:42
I am not skilled in Ansible, but CStrauf has offered to teach me - we started, so I dont understand how much effort that is
<@pboy:fedora.im>
17:56:57
proposed !action Brett, Jocelyn and MatH will put together a proposal from the current ideas and proposals.
<@pboy:fedora.im>
17:57:26
proposed !action Brett, Jocelyn and MatH will put together a proposal for the initial small set of apps from the current ideas and proposals.
<@theprogram:fedora.im>
17:58:04
And Emmanuel, do not mean to forget about you!
<@pboy:fedora.im>
17:59:01
Emmanuel ?? You too? or are you busy with Ansible post install?
<@brettweir:matrix.org>
17:59:13
That's sounds good, I need more time to muck about with things. I've comparing web servers too, it'll be good to discuss more
<@theprogram:fedora.im>
17:59:35
We will see , I will loop him in if he has any opinion
<@pboy:fedora.im>
17:59:46
OK.
<@pboy:fedora.im>
17:59:59
!action Brett, Jocelyn and MatH will put together a proposal for the initial small set of apps from the current ideas and proposals.
<@eseyman:fedora.im>
18:00:10
I'm quite busy with Perl packaging right now. If you can move forward without my help, I say go for it
<@pboy:fedora.im>
18:00:36
OK, let's proceed to the next topic.
<@pboy:fedora.im>
18:00:45
!topic 4. Open Floor
<@pboy:fedora.im>
18:01:16
The floor is open! For everything, for any question, what youj always wanted to ask but couldn't
<@theprogram:fedora.im>
18:01:33
How did you start tandem biking?
<@korora:fedora.im>
18:01:50
Why am I
<@theprogram:fedora.im>
18:02:01
Or... room for others question...
<@pboy:fedora.im>
18:02:13
My wife couldn't no longer bike by herself because of hipp issiues. So we came to a Tandem. :-)
<@theprogram:fedora.im>
18:02:29
The alternative to electric, power on!
<@pboy:fedora.im>
18:03:33
Yeah, the new tandem is electric. But it is too risky for my wile to use a single bike. Just in case she has to stop very quickly.
<@theprogram:fedora.im>
18:04:32
That would be quite a sight, a tandem at speed, I've not seen that before, they look super fun, one day when I settle down...
<@pboy:fedora.im>
18:04:47
It is fun !!!!
<@korora:fedora.im>
18:05:25
I've seen a quad tandem, non-electric at speed.... it's... impressi
<@korora:fedora.im>
18:05:29
I've seen a quad tandem, non-electric at speed.... it's... impressive
<@pboy:fedora.im>
18:05:33
You have a lot móre power, and the speed ....
<@pboy:fedora.im>
18:06:21
OK, I think we need to free up the room, just in case.
<@pboy:fedora.im>
18:06:48
Bye bye!! see you next week
<@brettweir:matrix.org>
18:06:52
Good chatting with you all!
<@pboy:fedora.im>
18:07:08
!endmeeting