Compare commits
3 commits
5406f8c991
...
0d1f3fc78c
| Author | SHA1 | Date | |
|---|---|---|---|
| 0d1f3fc78c | |||
| 0bece42016 | |||
| 92d6e4bad7 |
8 changed files with 75 additions and 169 deletions
|
|
@ -6,3 +6,7 @@ nixos-rebuild switch --flake .#nixos \
|
||||||
--sudo --ask-sudo-password
|
--sudo --ask-sudo-password
|
||||||
```
|
```
|
||||||
|
|
||||||
|
The main public services under `yisroelbaum.com` are provided by the
|
||||||
|
`yisroelbaum-web` flake input. Rabbi Gerzi is imported directly from its own
|
||||||
|
flake so its application module remains independently owned. This repository
|
||||||
|
owns the machine configuration and provisions runtime secrets for both.
|
||||||
|
|
|
||||||
|
|
@ -1,8 +1,5 @@
|
||||||
{
|
{
|
||||||
config,
|
|
||||||
pkgs,
|
pkgs,
|
||||||
domainName,
|
|
||||||
resume,
|
|
||||||
...
|
...
|
||||||
}:
|
}:
|
||||||
{
|
{
|
||||||
|
|
@ -10,7 +7,6 @@
|
||||||
[ # Include the results of the hardware scan.
|
[ # Include the results of the hardware scan.
|
||||||
./hardware-configuration.nix
|
./hardware-configuration.nix
|
||||||
./borgbackup.nix
|
./borgbackup.nix
|
||||||
./forgejo.nix
|
|
||||||
./boot.nix
|
./boot.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
|
@ -99,46 +95,6 @@
|
||||||
# Install firefox.
|
# Install firefox.
|
||||||
programs.firefox.enable = true;
|
programs.firefox.enable = true;
|
||||||
|
|
||||||
users.users.nginx.extraGroups = [ "acme" ];
|
|
||||||
services.nginx = {
|
|
||||||
enable = true;
|
|
||||||
virtualHosts = {
|
|
||||||
"${domainName}" = {
|
|
||||||
forceSSL = true;
|
|
||||||
enableACME = true;
|
|
||||||
locations = {
|
|
||||||
"/" = {
|
|
||||||
root = "${resume.packages.x86_64-linux.default}";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
"jellyfin.${domainName}" = {
|
|
||||||
forceSSL = true;
|
|
||||||
enableACME = true;
|
|
||||||
locations = {
|
|
||||||
"/" = {
|
|
||||||
proxyPass = "http://localhost:8096";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
security.acme = {
|
|
||||||
defaults.webroot = "/var/lib/acme/acme-challenge/";
|
|
||||||
acceptTerms = true;
|
|
||||||
defaults.email = "yisroel.d.baum@gmail.com";
|
|
||||||
certs = {
|
|
||||||
"${domainName}" = {
|
|
||||||
domain = "*.${domainName}";
|
|
||||||
webroot = "/var/lib/acme/acme-challenge/";
|
|
||||||
group = config.services.nginx.group;
|
|
||||||
reloadServices = [
|
|
||||||
"nginx"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
# Allow unfree packages
|
# Allow unfree packages
|
||||||
nixpkgs.config.allowUnfree = true;
|
nixpkgs.config.allowUnfree = true;
|
||||||
|
|
||||||
|
|
@ -159,10 +115,6 @@
|
||||||
# enableSSHSupport = true;
|
# enableSSHSupport = true;
|
||||||
# };
|
# };
|
||||||
|
|
||||||
services.jellyfin = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
|
|
||||||
# List services that you want to enable:
|
# List services that you want to enable:
|
||||||
services.dnsmasq = {
|
services.dnsmasq = {
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
|
||||||
34
flake.lock
generated
34
flake.lock
generated
|
|
@ -44,11 +44,11 @@
|
||||||
"utils": "utils"
|
"utils": "utils"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1783365146,
|
"lastModified": 1785613642,
|
||||||
"narHash": "sha256-glQYGvVU2renata14CZqKmAINrbZqVud/BBqimr4QHM=",
|
"narHash": "sha256-WFG0BXn6XHhdf5O2EC0KOvCpzkknx5pPwTME1NNPLhw=",
|
||||||
"ref": "refs/heads/master",
|
"ref": "refs/heads/master",
|
||||||
"rev": "04aad89124c4d4c6347fd741f76ca163941292b9",
|
"rev": "1cf3de423a932da611c715df7a6196d969b25e80",
|
||||||
"revCount": 375,
|
"revCount": 388,
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "https://git.yisroelbaum.com/yisroelbaum/Rabbi_Gerzi"
|
"url": "https://git.yisroelbaum.com/yisroelbaum/Rabbi_Gerzi"
|
||||||
},
|
},
|
||||||
|
|
@ -60,6 +60,7 @@
|
||||||
"resume": {
|
"resume": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
|
"yisroelbaum-web",
|
||||||
"nixpkgs"
|
"nixpkgs"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
|
@ -82,9 +83,9 @@
|
||||||
"home-manager": "home-manager",
|
"home-manager": "home-manager",
|
||||||
"nixpkgs": "nixpkgs",
|
"nixpkgs": "nixpkgs",
|
||||||
"rabbi-gerzi": "rabbi-gerzi",
|
"rabbi-gerzi": "rabbi-gerzi",
|
||||||
"resume": "resume",
|
|
||||||
"sops-nix": "sops-nix",
|
"sops-nix": "sops-nix",
|
||||||
"tide": "tide"
|
"tide": "tide",
|
||||||
|
"yisroelbaum-web": "yisroelbaum-web"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"sops-nix": {
|
"sops-nix": {
|
||||||
|
|
@ -159,6 +160,27 @@
|
||||||
"repo": "flake-utils",
|
"repo": "flake-utils",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
|
},
|
||||||
|
"yisroelbaum-web": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"nixpkgs"
|
||||||
|
],
|
||||||
|
"resume": "resume"
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1785611752,
|
||||||
|
"narHash": "sha256-AC7EilGHueXmYK9gu+/EOw8wfL+Hv0bbjgKuBMvbPvA=",
|
||||||
|
"ref": "refs/heads/master",
|
||||||
|
"rev": "4a489e90f3af8d6eeb0ab0658c6e932253eaedc3",
|
||||||
|
"revCount": 3,
|
||||||
|
"type": "git",
|
||||||
|
"url": "https://git.yisroelbaum.com/yisroelbaum/yisroelbaum-web"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"type": "git",
|
||||||
|
"url": "https://git.yisroelbaum.com/yisroelbaum/yisroelbaum-web"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"root": "root",
|
"root": "root",
|
||||||
|
|
|
||||||
10
flake.nix
10
flake.nix
|
|
@ -16,8 +16,8 @@
|
||||||
url = "git+https://git.yisroelbaum.com/yisroelbaum/TIDE";
|
url = "git+https://git.yisroelbaum.com/yisroelbaum/TIDE";
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
};
|
};
|
||||||
resume = {
|
yisroelbaum-web = {
|
||||||
url = "git+https://git.yisroelbaum.com/yisroelbaum/MyResume";
|
url = "git+https://git.yisroelbaum.com/yisroelbaum/yisroelbaum-web";
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
};
|
};
|
||||||
rabbi-gerzi = {
|
rabbi-gerzi = {
|
||||||
|
|
@ -33,23 +33,24 @@
|
||||||
home-manager,
|
home-manager,
|
||||||
sops-nix,
|
sops-nix,
|
||||||
tide,
|
tide,
|
||||||
resume,
|
yisroelbaum-web,
|
||||||
rabbi-gerzi,
|
rabbi-gerzi,
|
||||||
...
|
...
|
||||||
}:
|
}:
|
||||||
let
|
let
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
domainName = "yisroelbaum.com";
|
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
nixosConfigurations.nixos = nixpkgs.lib.nixosSystem {
|
nixosConfigurations.nixos = nixpkgs.lib.nixosSystem {
|
||||||
modules = [
|
modules = [
|
||||||
./configuration.nix
|
./configuration.nix
|
||||||
./tide.nix
|
./tide.nix
|
||||||
|
./yisroelbaum-web.nix
|
||||||
./rabbi-gerzi.nix
|
./rabbi-gerzi.nix
|
||||||
home-manager.nixosModules.home-manager
|
home-manager.nixosModules.home-manager
|
||||||
sops-nix.nixosModules.sops
|
sops-nix.nixosModules.sops
|
||||||
tide.nixosModules.tide
|
tide.nixosModules.tide
|
||||||
|
yisroelbaum-web.nixosModules.default
|
||||||
rabbi-gerzi.nixosModules.default
|
rabbi-gerzi.nixosModules.default
|
||||||
{
|
{
|
||||||
home-manager.useGlobalPkgs = true;
|
home-manager.useGlobalPkgs = true;
|
||||||
|
|
@ -57,7 +58,6 @@
|
||||||
home-manager.users.yisroel = ./home-manager/home.nix;
|
home-manager.users.yisroel = ./home-manager/home.nix;
|
||||||
}
|
}
|
||||||
];
|
];
|
||||||
specialArgs = { inherit domainName resume; };
|
|
||||||
};
|
};
|
||||||
devShells."${system}".default =
|
devShells."${system}".default =
|
||||||
let
|
let
|
||||||
|
|
|
||||||
107
forgejo.nix
107
forgejo.nix
|
|
@ -1,107 +0,0 @@
|
||||||
{
|
|
||||||
domainName,
|
|
||||||
config,
|
|
||||||
pkgs,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
{
|
|
||||||
services = {
|
|
||||||
forgejo = {
|
|
||||||
enable = true;
|
|
||||||
settings = {
|
|
||||||
server = {
|
|
||||||
ROOT_URL = "https://git.${domainName}/";
|
|
||||||
PROTOCOL = "http";
|
|
||||||
HTTP_ADDR = "127.0.0.1";
|
|
||||||
HTTP_PORT = 3000;
|
|
||||||
DOMAIN = "git.${domainName}";
|
|
||||||
SSH_PORT = 2222;
|
|
||||||
START_SSH_SERVER = true;
|
|
||||||
};
|
|
||||||
session.COOKIE_SECURE = true;
|
|
||||||
service.DISABLE_REGISTRATION = true;
|
|
||||||
mailer = {
|
|
||||||
ENABLED = true;
|
|
||||||
SMTP_ADDR = "in-v3.mailjet.com";
|
|
||||||
SMTP_PORT = 587;
|
|
||||||
FROM = "me@${domainName}";
|
|
||||||
# USER and PASSWD come from secrets below
|
|
||||||
};
|
|
||||||
};
|
|
||||||
secrets.mailer.USER = config.sops.secrets."forgejo-mailer-user".path;
|
|
||||||
secrets.mailer.PASSWD = config.sops.secrets."forgejo-mailer-passwd".path;
|
|
||||||
};
|
|
||||||
nginx.virtualHosts."git.${domainName}" = {
|
|
||||||
forceSSL = true;
|
|
||||||
enableACME = true;
|
|
||||||
extraConfig = ''
|
|
||||||
client_max_body_size 512M;
|
|
||||||
'';
|
|
||||||
locations = {
|
|
||||||
"/" = {
|
|
||||||
proxyPass = "http://127.0.0.1:3000";
|
|
||||||
recommendedProxySettings = false;
|
|
||||||
extraConfig = ''
|
|
||||||
proxy_set_header Host $host;
|
|
||||||
proxy_set_header X-Real-IP $remote_addr;
|
|
||||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
||||||
proxy_set_header X-Forwarded-Proto $scheme;
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
borgbackup.jobs.forgejo = {
|
|
||||||
paths = [ config.services.forgejo.stateDir ];
|
|
||||||
repo = "ssh://n5lniyfd@n5lniyfd.repo.borgbase.com/./repo";
|
|
||||||
user = "root";
|
|
||||||
group = "root";
|
|
||||||
encryption = {
|
|
||||||
mode = "repokey-blake2";
|
|
||||||
passCommand = "${pkgs.coreutils}/bin/cat ${config.sops.secrets."borg-passphrase".path}";
|
|
||||||
};
|
|
||||||
doInit = true;
|
|
||||||
compression = "auto,zstd";
|
|
||||||
startAt = "*-*-* 03:15:00";
|
|
||||||
persistentTimer = true;
|
|
||||||
prune.keep = {
|
|
||||||
daily = 7;
|
|
||||||
weekly = 4;
|
|
||||||
monthly = 6;
|
|
||||||
};
|
|
||||||
environment.BORG_RSH = "ssh -i ${config.sops.secrets."borg-private-key".path} -o IdentitiesOnly=yes -o BatchMode=yes -o StrictHostKeyChecking=accept-new -o UserKnownHostsFile=/root/.config/borg/known_hosts";
|
|
||||||
preHook = ''
|
|
||||||
forgejoWasActive=/root/.cache/borg/forgejo-was-active
|
|
||||||
if ${pkgs.systemd}/bin/systemctl is-active --quiet forgejo.service; then
|
|
||||||
touch "$forgejoWasActive"
|
|
||||||
${pkgs.systemd}/bin/systemctl stop forgejo.service
|
|
||||||
else
|
|
||||||
rm -f "$forgejoWasActive"
|
|
||||||
fi
|
|
||||||
'';
|
|
||||||
postHook = ''
|
|
||||||
forgejoWasActive=/root/.cache/borg/forgejo-was-active
|
|
||||||
if [ -e "$forgejoWasActive" ]; then
|
|
||||||
${pkgs.systemd}/bin/systemctl start forgejo.service
|
|
||||||
rm -f "$forgejoWasActive"
|
|
||||||
fi
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
systemd.services.borgbackup-job-forgejo = {
|
|
||||||
after = [
|
|
||||||
"sops-install-secrets.service"
|
|
||||||
"network-online.target"
|
|
||||||
];
|
|
||||||
wants = [ "network-online.target" ];
|
|
||||||
};
|
|
||||||
|
|
||||||
sops.secrets."forgejo-mailer-user" = {
|
|
||||||
sopsFile = ./secrets/forgejo.yaml;
|
|
||||||
mode = "0400";
|
|
||||||
};
|
|
||||||
sops.secrets."forgejo-mailer-passwd" = {
|
|
||||||
sopsFile = ./secrets/forgejo.yaml;
|
|
||||||
mode = "0400";
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
@ -1,20 +1,19 @@
|
||||||
{
|
{
|
||||||
config,
|
config,
|
||||||
domainName,
|
|
||||||
...
|
...
|
||||||
}:
|
}:
|
||||||
{
|
{
|
||||||
services.rabbi-gerzi = {
|
services.rabbi-gerzi = {
|
||||||
enable = true;
|
enable = true;
|
||||||
frontend = {
|
frontend = {
|
||||||
hostName = "rabbigerzi.${domainName}";
|
hostName = "rabbigerzi.yisroelbaum.com";
|
||||||
nginx = {
|
nginx = {
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
enableACME = true;
|
enableACME = true;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
backend = {
|
backend = {
|
||||||
hostName = "rabbigerziapi.${domainName}";
|
hostName = "rabbigerziapi.yisroelbaum.com";
|
||||||
environmentFile = config.sops.secrets."rabbi-gerzi-env".path;
|
environmentFile = config.sops.secrets."rabbi-gerzi-env".path;
|
||||||
nginx = {
|
nginx = {
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
|
|
|
||||||
|
|
@ -18,6 +18,17 @@ host's age key.
|
||||||
3. On a workstation, put that public key into `.sops.yaml` at the repository
|
3. On a workstation, put that public key into `.sops.yaml` at the repository
|
||||||
root and encrypt the required secret files.
|
root and encrypt the required secret files.
|
||||||
|
|
||||||
|
## Shared Borg backup credentials
|
||||||
|
|
||||||
|
`borgbackup.yaml` contains `private-key` and `passphrase`. The resulting
|
||||||
|
secrets are shared by the TIDE and yisroelbaum.com backup jobs.
|
||||||
|
|
||||||
|
## Forgejo
|
||||||
|
|
||||||
|
`forgejo.yaml` contains `forgejo-mailer-user` and
|
||||||
|
`forgejo-mailer-passwd`. The host passes these secret paths to the
|
||||||
|
`yisroelbaum-web` module.
|
||||||
|
|
||||||
## TIDE
|
## TIDE
|
||||||
|
|
||||||
Create `tide.yaml` from `tide.yaml.example` and encrypt it with sops. It must
|
Create `tide.yaml` from `tide.yaml.example` and encrypt it with sops. It must
|
||||||
|
|
@ -33,3 +44,5 @@ APP_KEY=base64:...
|
||||||
RABBI_GERZI_INITIAL_ADMIN_EMAIL=...
|
RABBI_GERZI_INITIAL_ADMIN_EMAIL=...
|
||||||
RABBI_GERZI_INITIAL_ADMIN_PASSWORD=...
|
RABBI_GERZI_INITIAL_ADMIN_PASSWORD=...
|
||||||
```
|
```
|
||||||
|
|
||||||
|
The host passes this environment file directly to the Rabbi Gerzi module.
|
||||||
|
|
|
||||||
23
yisroelbaum-web.nix
Normal file
23
yisroelbaum-web.nix
Normal file
|
|
@ -0,0 +1,23 @@
|
||||||
|
{ config, ... }:
|
||||||
|
{
|
||||||
|
services.yisroelbaum-web = {
|
||||||
|
enable = true;
|
||||||
|
secretFiles = {
|
||||||
|
borgPassphrase = config.sops.secrets."borg-passphrase".path;
|
||||||
|
borgPrivateKey = config.sops.secrets."borg-private-key".path;
|
||||||
|
forgejoMailerUser = config.sops.secrets."forgejo-mailer-user".path;
|
||||||
|
forgejoMailerPassword = config.sops.secrets."forgejo-mailer-passwd".path;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
sops.secrets = {
|
||||||
|
"forgejo-mailer-user" = {
|
||||||
|
sopsFile = ./secrets/forgejo.yaml;
|
||||||
|
mode = "0400";
|
||||||
|
};
|
||||||
|
"forgejo-mailer-passwd" = {
|
||||||
|
sopsFile = ./secrets/forgejo.yaml;
|
||||||
|
mode = "0400";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
Loading…
Add table
Add a link
Reference in a new issue