ooni / ooni/devops

make HSM configuration more robust to unintended large billings

Open
#201 0 comments 0 reactions 1 assignee View on GitHub

@hellais is already working on this.

Since Mar 14, 2025.

Dominant language
HCL
Stars
4
Forks
15
Avg merge
1h 50m
Merged PRs (30d)
4

Description

In January 2025 we forgot the HSM modules running in AWS and as a result incurred in 1.6k USD unexpected fees for CloudHSM and in February 2.2k USD.

Going forward we should put things in place to prevent this. Currently this is all reliant on going through the HSM procedure properly and not skipping the last step:

1. Run the command:

create-hsms.sh

wait for the tokens to be created (this will take several minutes).

2. If it’s the first time you are doing signing, ensure that /home/ubuntu/.hsmcredentials constains the username and password to access the code signing key in the format HSM_PASSWORD=”USERNAME:PASSWORD”
You can now sign exe binaries using:

sign-windows-exe.sh [unsigned.exe] [signed.exe]

3. Once you are done be sure to terminate all the running HSMs using:

delete-hsms.sh

We should evaluate having:

  • Monitoring that checks the HSM tokens are not running for more than some amount of time and if so sends us a notification
  • Automatically terminate the HSM tokens (running delete-hsms.sh) after some amount of inactivity

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.