Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

make HSM configuration more robust to unintended large billings

未关闭
#201 0 条评论 0 个 reaction 已指派 1 人 在 GitHub 查看

维护者通常 1 天内回复

@hellais 已经在做这个了。

开始于 2025年3月14日。

评估

这个 Issue 还没有评估数据。

描述

In January 2025 we forgot the HSM modules running in AWS and as a result incurred in 1.6k USD unexpected fees for CloudHSM and in February 2.2k USD.

Going forward we should put things in place to prevent this. Currently this is all reliant on going through the HSM procedure properly and not skipping the last step:

1. Run the command:

create-hsms.sh

wait for the tokens to be created (this will take several minutes).

2. If it’s the first time you are doing signing, ensure that /home/ubuntu/.hsmcredentials constains the username and password to access the code signing key in the format HSM_PASSWORD=”USERNAME:PASSWORD”
You can now sign exe binaries using:

sign-windows-exe.sh [unsigned.exe] [signed.exe]

3. Once you are done be sure to terminate all the running HSMs using:

delete-hsms.sh

We should evaluate having:

  • Monitoring that checks the HSM tokens are not running for more than some amount of time and if so sends us a notification
  • Automatically terminate the HSM tokens (running delete-hsms.sh) after some amount of inactivity
主要语言
HCL
星标
4
派生
15
平均合并
3 天 1 小时
30 天内合并 PR
9

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

ooni/devops 的其他 Issue

查看 ooni/devops 的全部 Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。