Compare commits

...

3 commits

Author SHA1 Message Date
0d1f3fc78c
update rabbi gerzi 2026-08-01 22:55:25 +03:00
0bece42016
import Rabbi Gerzi directly 2026-08-01 22:19:59 +03:00
92d6e4bad7
move yisroelbaum web stack into module 2026-07-31 11:30:25 +03:00
8 changed files with 75 additions and 169 deletions

View file

@ -6,3 +6,7 @@ nixos-rebuild switch --flake .#nixos \
--sudo --ask-sudo-password --sudo --ask-sudo-password
``` ```
The main public services under `yisroelbaum.com` are provided by the
`yisroelbaum-web` flake input. Rabbi Gerzi is imported directly from its own
flake so its application module remains independently owned. This repository
owns the machine configuration and provisions runtime secrets for both.

View file

@ -1,8 +1,5 @@
{ {
config,
pkgs, pkgs,
domainName,
resume,
... ...
}: }:
{ {
@ -10,7 +7,6 @@
[ # Include the results of the hardware scan. [ # Include the results of the hardware scan.
./hardware-configuration.nix ./hardware-configuration.nix
./borgbackup.nix ./borgbackup.nix
./forgejo.nix
./boot.nix ./boot.nix
]; ];
@ -99,46 +95,6 @@
# Install firefox. # Install firefox.
programs.firefox.enable = true; programs.firefox.enable = true;
users.users.nginx.extraGroups = [ "acme" ];
services.nginx = {
enable = true;
virtualHosts = {
"${domainName}" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
root = "${resume.packages.x86_64-linux.default}";
};
};
};
"jellyfin.${domainName}" = {
forceSSL = true;
enableACME = true;
locations = {
"/" = {
proxyPass = "http://localhost:8096";
};
};
};
};
};
security.acme = {
defaults.webroot = "/var/lib/acme/acme-challenge/";
acceptTerms = true;
defaults.email = "yisroel.d.baum@gmail.com";
certs = {
"${domainName}" = {
domain = "*.${domainName}";
webroot = "/var/lib/acme/acme-challenge/";
group = config.services.nginx.group;
reloadServices = [
"nginx"
];
};
};
};
# Allow unfree packages # Allow unfree packages
nixpkgs.config.allowUnfree = true; nixpkgs.config.allowUnfree = true;
@ -159,10 +115,6 @@
# enableSSHSupport = true; # enableSSHSupport = true;
# }; # };
services.jellyfin = {
enable = true;
};
# List services that you want to enable: # List services that you want to enable:
services.dnsmasq = { services.dnsmasq = {
enable = true; enable = true;

34
flake.lock generated
View file

@ -44,11 +44,11 @@
"utils": "utils" "utils": "utils"
}, },
"locked": { "locked": {
"lastModified": 1783365146, "lastModified": 1785613642,
"narHash": "sha256-glQYGvVU2renata14CZqKmAINrbZqVud/BBqimr4QHM=", "narHash": "sha256-WFG0BXn6XHhdf5O2EC0KOvCpzkknx5pPwTME1NNPLhw=",
"ref": "refs/heads/master", "ref": "refs/heads/master",
"rev": "04aad89124c4d4c6347fd741f76ca163941292b9", "rev": "1cf3de423a932da611c715df7a6196d969b25e80",
"revCount": 375, "revCount": 388,
"type": "git", "type": "git",
"url": "https://git.yisroelbaum.com/yisroelbaum/Rabbi_Gerzi" "url": "https://git.yisroelbaum.com/yisroelbaum/Rabbi_Gerzi"
}, },
@ -60,6 +60,7 @@
"resume": { "resume": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
"yisroelbaum-web",
"nixpkgs" "nixpkgs"
] ]
}, },
@ -82,9 +83,9 @@
"home-manager": "home-manager", "home-manager": "home-manager",
"nixpkgs": "nixpkgs", "nixpkgs": "nixpkgs",
"rabbi-gerzi": "rabbi-gerzi", "rabbi-gerzi": "rabbi-gerzi",
"resume": "resume",
"sops-nix": "sops-nix", "sops-nix": "sops-nix",
"tide": "tide" "tide": "tide",
"yisroelbaum-web": "yisroelbaum-web"
} }
}, },
"sops-nix": { "sops-nix": {
@ -159,6 +160,27 @@
"repo": "flake-utils", "repo": "flake-utils",
"type": "github" "type": "github"
} }
},
"yisroelbaum-web": {
"inputs": {
"nixpkgs": [
"nixpkgs"
],
"resume": "resume"
},
"locked": {
"lastModified": 1785611752,
"narHash": "sha256-AC7EilGHueXmYK9gu+/EOw8wfL+Hv0bbjgKuBMvbPvA=",
"ref": "refs/heads/master",
"rev": "4a489e90f3af8d6eeb0ab0658c6e932253eaedc3",
"revCount": 3,
"type": "git",
"url": "https://git.yisroelbaum.com/yisroelbaum/yisroelbaum-web"
},
"original": {
"type": "git",
"url": "https://git.yisroelbaum.com/yisroelbaum/yisroelbaum-web"
}
} }
}, },
"root": "root", "root": "root",

View file

@ -16,8 +16,8 @@
url = "git+https://git.yisroelbaum.com/yisroelbaum/TIDE"; url = "git+https://git.yisroelbaum.com/yisroelbaum/TIDE";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
resume = { yisroelbaum-web = {
url = "git+https://git.yisroelbaum.com/yisroelbaum/MyResume"; url = "git+https://git.yisroelbaum.com/yisroelbaum/yisroelbaum-web";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
rabbi-gerzi = { rabbi-gerzi = {
@ -33,23 +33,24 @@
home-manager, home-manager,
sops-nix, sops-nix,
tide, tide,
resume, yisroelbaum-web,
rabbi-gerzi, rabbi-gerzi,
... ...
}: }:
let let
system = "x86_64-linux"; system = "x86_64-linux";
domainName = "yisroelbaum.com";
in in
{ {
nixosConfigurations.nixos = nixpkgs.lib.nixosSystem { nixosConfigurations.nixos = nixpkgs.lib.nixosSystem {
modules = [ modules = [
./configuration.nix ./configuration.nix
./tide.nix ./tide.nix
./yisroelbaum-web.nix
./rabbi-gerzi.nix ./rabbi-gerzi.nix
home-manager.nixosModules.home-manager home-manager.nixosModules.home-manager
sops-nix.nixosModules.sops sops-nix.nixosModules.sops
tide.nixosModules.tide tide.nixosModules.tide
yisroelbaum-web.nixosModules.default
rabbi-gerzi.nixosModules.default rabbi-gerzi.nixosModules.default
{ {
home-manager.useGlobalPkgs = true; home-manager.useGlobalPkgs = true;
@ -57,7 +58,6 @@
home-manager.users.yisroel = ./home-manager/home.nix; home-manager.users.yisroel = ./home-manager/home.nix;
} }
]; ];
specialArgs = { inherit domainName resume; };
}; };
devShells."${system}".default = devShells."${system}".default =
let let

View file

@ -1,107 +0,0 @@
{
domainName,
config,
pkgs,
...
}:
{
services = {
forgejo = {
enable = true;
settings = {
server = {
ROOT_URL = "https://git.${domainName}/";
PROTOCOL = "http";
HTTP_ADDR = "127.0.0.1";
HTTP_PORT = 3000;
DOMAIN = "git.${domainName}";
SSH_PORT = 2222;
START_SSH_SERVER = true;
};
session.COOKIE_SECURE = true;
service.DISABLE_REGISTRATION = true;
mailer = {
ENABLED = true;
SMTP_ADDR = "in-v3.mailjet.com";
SMTP_PORT = 587;
FROM = "me@${domainName}";
# USER and PASSWD come from secrets below
};
};
secrets.mailer.USER = config.sops.secrets."forgejo-mailer-user".path;
secrets.mailer.PASSWD = config.sops.secrets."forgejo-mailer-passwd".path;
};
nginx.virtualHosts."git.${domainName}" = {
forceSSL = true;
enableACME = true;
extraConfig = ''
client_max_body_size 512M;
'';
locations = {
"/" = {
proxyPass = "http://127.0.0.1:3000";
recommendedProxySettings = false;
extraConfig = ''
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
'';
};
};
};
borgbackup.jobs.forgejo = {
paths = [ config.services.forgejo.stateDir ];
repo = "ssh://n5lniyfd@n5lniyfd.repo.borgbase.com/./repo";
user = "root";
group = "root";
encryption = {
mode = "repokey-blake2";
passCommand = "${pkgs.coreutils}/bin/cat ${config.sops.secrets."borg-passphrase".path}";
};
doInit = true;
compression = "auto,zstd";
startAt = "*-*-* 03:15:00";
persistentTimer = true;
prune.keep = {
daily = 7;
weekly = 4;
monthly = 6;
};
environment.BORG_RSH = "ssh -i ${config.sops.secrets."borg-private-key".path} -o IdentitiesOnly=yes -o BatchMode=yes -o StrictHostKeyChecking=accept-new -o UserKnownHostsFile=/root/.config/borg/known_hosts";
preHook = ''
forgejoWasActive=/root/.cache/borg/forgejo-was-active
if ${pkgs.systemd}/bin/systemctl is-active --quiet forgejo.service; then
touch "$forgejoWasActive"
${pkgs.systemd}/bin/systemctl stop forgejo.service
else
rm -f "$forgejoWasActive"
fi
'';
postHook = ''
forgejoWasActive=/root/.cache/borg/forgejo-was-active
if [ -e "$forgejoWasActive" ]; then
${pkgs.systemd}/bin/systemctl start forgejo.service
rm -f "$forgejoWasActive"
fi
'';
};
};
systemd.services.borgbackup-job-forgejo = {
after = [
"sops-install-secrets.service"
"network-online.target"
];
wants = [ "network-online.target" ];
};
sops.secrets."forgejo-mailer-user" = {
sopsFile = ./secrets/forgejo.yaml;
mode = "0400";
};
sops.secrets."forgejo-mailer-passwd" = {
sopsFile = ./secrets/forgejo.yaml;
mode = "0400";
};
}

View file

@ -1,20 +1,19 @@
{ {
config, config,
domainName,
... ...
}: }:
{ {
services.rabbi-gerzi = { services.rabbi-gerzi = {
enable = true; enable = true;
frontend = { frontend = {
hostName = "rabbigerzi.${domainName}"; hostName = "rabbigerzi.yisroelbaum.com";
nginx = { nginx = {
forceSSL = true; forceSSL = true;
enableACME = true; enableACME = true;
}; };
}; };
backend = { backend = {
hostName = "rabbigerziapi.${domainName}"; hostName = "rabbigerziapi.yisroelbaum.com";
environmentFile = config.sops.secrets."rabbi-gerzi-env".path; environmentFile = config.sops.secrets."rabbi-gerzi-env".path;
nginx = { nginx = {
forceSSL = true; forceSSL = true;

View file

@ -18,6 +18,17 @@ host's age key.
3. On a workstation, put that public key into `.sops.yaml` at the repository 3. On a workstation, put that public key into `.sops.yaml` at the repository
root and encrypt the required secret files. root and encrypt the required secret files.
## Shared Borg backup credentials
`borgbackup.yaml` contains `private-key` and `passphrase`. The resulting
secrets are shared by the TIDE and yisroelbaum.com backup jobs.
## Forgejo
`forgejo.yaml` contains `forgejo-mailer-user` and
`forgejo-mailer-passwd`. The host passes these secret paths to the
`yisroelbaum-web` module.
## TIDE ## TIDE
Create `tide.yaml` from `tide.yaml.example` and encrypt it with sops. It must Create `tide.yaml` from `tide.yaml.example` and encrypt it with sops. It must
@ -33,3 +44,5 @@ APP_KEY=base64:...
RABBI_GERZI_INITIAL_ADMIN_EMAIL=... RABBI_GERZI_INITIAL_ADMIN_EMAIL=...
RABBI_GERZI_INITIAL_ADMIN_PASSWORD=... RABBI_GERZI_INITIAL_ADMIN_PASSWORD=...
``` ```
The host passes this environment file directly to the Rabbi Gerzi module.

23
yisroelbaum-web.nix Normal file
View file

@ -0,0 +1,23 @@
{ config, ... }:
{
services.yisroelbaum-web = {
enable = true;
secretFiles = {
borgPassphrase = config.sops.secrets."borg-passphrase".path;
borgPrivateKey = config.sops.secrets."borg-private-key".path;
forgejoMailerUser = config.sops.secrets."forgejo-mailer-user".path;
forgejoMailerPassword = config.sops.secrets."forgejo-mailer-passwd".path;
};
};
sops.secrets = {
"forgejo-mailer-user" = {
sopsFile = ./secrets/forgejo.yaml;
mode = "0400";
};
"forgejo-mailer-passwd" = {
sopsFile = ./secrets/forgejo.yaml;
mode = "0400";
};
};
}