move yisroelbaum web stack into module

This commit is contained in:
Yisroel Baum 2026-07-31 11:30:25 +03:00
parent 5406f8c991
commit 92d6e4bad7
Signed by: yisroelbaum
GPG key ID: 0FA60884F75520A9
8 changed files with 81 additions and 204 deletions

View file

@ -6,3 +6,7 @@ nixos-rebuild switch --flake .#nixos \
--sudo --ask-sudo-password --sudo --ask-sudo-password
``` ```
The public services under `yisroelbaum.com` are provided by the
`yisroelbaum-web` flake input. This repository owns the machine configuration
and provisions the runtime secrets passed to that module from
`yisroelbaum-web.nix`.

View file

@ -1,8 +1,5 @@
{ {
config,
pkgs, pkgs,
domainName,
resume,
... ...
}: }:
{ {
@ -10,7 +7,6 @@
[ # Include the results of the hardware scan. [ # Include the results of the hardware scan.
./hardware-configuration.nix ./hardware-configuration.nix
./borgbackup.nix ./borgbackup.nix
./forgejo.nix
./boot.nix ./boot.nix
]; ];
@ -99,46 +95,6 @@
# Install firefox. # Install firefox.
programs.firefox.enable = true; programs.firefox.enable = true;
users.users.nginx.extraGroups = [ "acme" ];
services.nginx = {
enable = true;
virtualHosts = {
"${domainName}" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
root = "${resume.packages.x86_64-linux.default}";
};
};
};
"jellyfin.${domainName}" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://localhost:8096";
};
};
};
};
};
security.acme = {
defaults.webroot = "/var/lib/acme/acme-challenge/";
acceptTerms = true;
defaults.email = "yisroel.d.baum@gmail.com";
certs = {
"${domainName}" = {
domain = "*.${domainName}";
webroot = "/var/lib/acme/acme-challenge/";
group = config.services.nginx.group;
reloadServices = [
"nginx"
];
};
};
};
# Allow unfree packages # Allow unfree packages
nixpkgs.config.allowUnfree = true; nixpkgs.config.allowUnfree = true;
@ -159,10 +115,6 @@
# enableSSHSupport = true; # enableSSHSupport = true;
# }; # };
services.jellyfin = {
enable = true;
};
# List services that you want to enable: # List services that you want to enable:
services.dnsmasq = { services.dnsmasq = {
enable = true; enable = true;

29
flake.lock generated
View file

@ -39,6 +39,7 @@
"rabbi-gerzi": { "rabbi-gerzi": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
"yisroelbaum-web",
"nixpkgs" "nixpkgs"
], ],
"utils": "utils" "utils": "utils"
@ -60,6 +61,7 @@
"resume": { "resume": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
"yisroelbaum-web",
"nixpkgs" "nixpkgs"
] ]
}, },
@ -81,10 +83,9 @@
"inputs": { "inputs": {
"home-manager": "home-manager", "home-manager": "home-manager",
"nixpkgs": "nixpkgs", "nixpkgs": "nixpkgs",
"rabbi-gerzi": "rabbi-gerzi",
"resume": "resume",
"sops-nix": "sops-nix", "sops-nix": "sops-nix",
"tide": "tide" "tide": "tide",
"yisroelbaum-web": "yisroelbaum-web"
} }
}, },
"sops-nix": { "sops-nix": {
@ -159,6 +160,28 @@
"repo": "flake-utils", "repo": "flake-utils",
"type": "github" "type": "github"
} }
},
"yisroelbaum-web": {
"inputs": {
"nixpkgs": [
"nixpkgs"
],
"rabbi-gerzi": "rabbi-gerzi",
"resume": "resume"
},
"locked": {
"lastModified": 1785486508,
"narHash": "sha256-ERBDLfvLBz91IBMJeagoTfXzeldUjhekF8jqiuHCeGw=",
"ref": "refs/heads/master",
"rev": "b09be84f730937f9556263fc995753e873e31ac0",
"revCount": 2,
"type": "git",
"url": "https://git.yisroelbaum.com/yisroelbaum/yisroelbaum-web"
},
"original": {
"type": "git",
"url": "https://git.yisroelbaum.com/yisroelbaum/yisroelbaum-web"
}
} }
}, },
"root": "root", "root": "root",

View file

@ -16,12 +16,8 @@
url = "git+https://git.yisroelbaum.com/yisroelbaum/TIDE"; url = "git+https://git.yisroelbaum.com/yisroelbaum/TIDE";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
resume = { yisroelbaum-web = {
url = "git+https://git.yisroelbaum.com/yisroelbaum/MyResume"; url = "git+https://git.yisroelbaum.com/yisroelbaum/yisroelbaum-web";
inputs.nixpkgs.follows = "nixpkgs";
};
rabbi-gerzi = {
url = "git+https://git.yisroelbaum.com/yisroelbaum/Rabbi_Gerzi";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
}; };
@ -33,31 +29,28 @@
home-manager, home-manager,
sops-nix, sops-nix,
tide, tide,
resume, yisroelbaum-web,
rabbi-gerzi,
... ...
}: }:
let let
system = "x86_64-linux"; system = "x86_64-linux";
domainName = "yisroelbaum.com";
in in
{ {
nixosConfigurations.nixos = nixpkgs.lib.nixosSystem { nixosConfigurations.nixos = nixpkgs.lib.nixosSystem {
modules = [ modules = [
./configuration.nix ./configuration.nix
./tide.nix ./tide.nix
./rabbi-gerzi.nix ./yisroelbaum-web.nix
home-manager.nixosModules.home-manager home-manager.nixosModules.home-manager
sops-nix.nixosModules.sops sops-nix.nixosModules.sops
tide.nixosModules.tide tide.nixosModules.tide
rabbi-gerzi.nixosModules.default yisroelbaum-web.nixosModules.default
{ {
home-manager.useGlobalPkgs = true; home-manager.useGlobalPkgs = true;
home-manager.useUserPackages = true; home-manager.useUserPackages = true;
home-manager.users.yisroel = ./home-manager/home.nix; home-manager.users.yisroel = ./home-manager/home.nix;
} }
]; ];
specialArgs = { inherit domainName resume; };
}; };
devShells."${system}".default = devShells."${system}".default =
let let

View file

@ -1,107 +0,0 @@
{
domainName,
config,
pkgs,
...
}:
{
services = {
forgejo = {
enable = true;
settings = {
server = {
ROOT_URL = "https://git.${domainName}/";
PROTOCOL = "http";
HTTP_ADDR = "127.0.0.1";
HTTP_PORT = 3000;
DOMAIN = "git.${domainName}";
SSH_PORT = 2222;
START_SSH_SERVER = true;
};
session.COOKIE_SECURE = true;
service.DISABLE_REGISTRATION = true;
mailer = {
ENABLED = true;
SMTP_ADDR = "in-v3.mailjet.com";
SMTP_PORT = 587;
FROM = "me@${domainName}";
# USER and PASSWD come from secrets below
};
};
secrets.mailer.USER = config.sops.secrets."forgejo-mailer-user".path;
secrets.mailer.PASSWD = config.sops.secrets."forgejo-mailer-passwd".path;
};
nginx.virtualHosts."git.${domainName}" = {
forceSSL = true;
enableACME = true;
extraConfig = ''
client_max_body_size 512M;
'';
locations = {
"/" = {
proxyPass = "http://127.0.0.1:3000";
recommendedProxySettings = false;
extraConfig = ''
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
'';
};
};
};
borgbackup.jobs.forgejo = {
paths = [ config.services.forgejo.stateDir ];
repo = "ssh://n5lniyfd@n5lniyfd.repo.borgbase.com/./repo";
user = "root";
group = "root";
encryption = {
mode = "repokey-blake2";
passCommand = "${pkgs.coreutils}/bin/cat ${config.sops.secrets."borg-passphrase".path}";
};
doInit = true;
compression = "auto,zstd";
startAt = "*-*-* 03:15:00";
persistentTimer = true;
prune.keep = {
daily = 7;
weekly = 4;
monthly = 6;
};
environment.BORG_RSH = "ssh -i ${config.sops.secrets."borg-private-key".path} -o IdentitiesOnly=yes -o BatchMode=yes -o StrictHostKeyChecking=accept-new -o UserKnownHostsFile=/root/.config/borg/known_hosts";
preHook = ''
forgejoWasActive=/root/.cache/borg/forgejo-was-active
if ${pkgs.systemd}/bin/systemctl is-active --quiet forgejo.service; then
touch "$forgejoWasActive"
${pkgs.systemd}/bin/systemctl stop forgejo.service
else
rm -f "$forgejoWasActive"
fi
'';
postHook = ''
forgejoWasActive=/root/.cache/borg/forgejo-was-active
if [ -e "$forgejoWasActive" ]; then
${pkgs.systemd}/bin/systemctl start forgejo.service
rm -f "$forgejoWasActive"
fi
'';
};
};
systemd.services.borgbackup-job-forgejo = {
after = [
"sops-install-secrets.service"
"network-online.target"
];
wants = [ "network-online.target" ];
};
sops.secrets."forgejo-mailer-user" = {
sopsFile = ./secrets/forgejo.yaml;
mode = "0400";
};
sops.secrets."forgejo-mailer-passwd" = {
sopsFile = ./secrets/forgejo.yaml;
mode = "0400";
};
}

View file

@ -1,34 +0,0 @@
{
config,
domainName,
...
}:
{
services.rabbi-gerzi = {
enable = true;
frontend = {
hostName = "rabbigerzi.${domainName}";
nginx = {
forceSSL = true;
enableACME = true;
};
};
backend = {
hostName = "rabbigerziapi.${domainName}";
environmentFile = config.sops.secrets."rabbi-gerzi-env".path;
nginx = {
forceSSL = true;
enableACME = true;
};
};
};
sops.secrets."rabbi-gerzi-env" = {
sopsFile = ./secrets/rabbi-gerzi.env;
format = "dotenv";
key = "";
mode = "0400";
owner = config.services.rabbi-gerzi.user;
group = config.services.rabbi-gerzi.group;
};
}

View file

@ -18,6 +18,17 @@ host's age key.
3. On a workstation, put that public key into `.sops.yaml` at the repository 3. On a workstation, put that public key into `.sops.yaml` at the repository
root and encrypt the required secret files. root and encrypt the required secret files.
## Shared Borg backup credentials
`borgbackup.yaml` contains `private-key` and `passphrase`. The resulting
secrets are shared by the TIDE and yisroelbaum.com backup jobs.
## Forgejo
`forgejo.yaml` contains `forgejo-mailer-user` and
`forgejo-mailer-passwd`. The host passes these secret paths to the
`yisroelbaum-web` module.
## TIDE ## TIDE
Create `tide.yaml` from `tide.yaml.example` and encrypt it with sops. It must Create `tide.yaml` from `tide.yaml.example` and encrypt it with sops. It must
@ -33,3 +44,6 @@ APP_KEY=base64:...
RABBI_GERZI_INITIAL_ADMIN_EMAIL=... RABBI_GERZI_INITIAL_ADMIN_EMAIL=...
RABBI_GERZI_INITIAL_ADMIN_PASSWORD=... RABBI_GERZI_INITIAL_ADMIN_PASSWORD=...
``` ```
The host passes this environment file to the Rabbi Gerzi service through the
`yisroelbaum-web` module.

32
yisroelbaum-web.nix Normal file
View file

@ -0,0 +1,32 @@
{ config, ... }:
{
services.yisroelbaum-web = {
enable = true;
secretFiles = {
borgPassphrase = config.sops.secrets."borg-passphrase".path;
borgPrivateKey = config.sops.secrets."borg-private-key".path;
forgejoMailerUser = config.sops.secrets."forgejo-mailer-user".path;
forgejoMailerPassword = config.sops.secrets."forgejo-mailer-passwd".path;
rabbiGerziEnvironment = config.sops.secrets."rabbi-gerzi-env".path;
};
};
sops.secrets = {
"forgejo-mailer-user" = {
sopsFile = ./secrets/forgejo.yaml;
mode = "0400";
};
"forgejo-mailer-passwd" = {
sopsFile = ./secrets/forgejo.yaml;
mode = "0400";
};
"rabbi-gerzi-env" = {
sopsFile = ./secrets/rabbi-gerzi.env;
format = "dotenv";
key = "";
mode = "0400";
owner = config.services.rabbi-gerzi.user;
group = config.services.rabbi-gerzi.group;
};
};
}