48 lines
1.3 KiB
Markdown
48 lines
1.3 KiB
Markdown
# Secrets
|
|
|
|
Encrypted with [sops](https://github.com/getsops/sops) using the
|
|
host's age key.
|
|
|
|
## First-time setup on the server
|
|
|
|
1. Generate an age key for the host:
|
|
```
|
|
sudo mkdir -p /var/lib/sops-nix
|
|
sudo age-keygen -o /var/lib/sops-nix/key.txt
|
|
sudo chmod 600 /var/lib/sops-nix/key.txt
|
|
```
|
|
2. Read the public key:
|
|
```
|
|
sudo grep "public key" /var/lib/sops-nix/key.txt
|
|
```
|
|
3. On a workstation, put that public key into `.sops.yaml` at the repository
|
|
root and encrypt the required secret files.
|
|
|
|
## Shared Borg backup credentials
|
|
|
|
`borgbackup.yaml` contains `private-key` and `passphrase`. The resulting
|
|
secrets are shared by the TIDE and yisroelbaum.com backup jobs.
|
|
|
|
## Forgejo
|
|
|
|
`forgejo.yaml` contains `forgejo-mailer-user` and
|
|
`forgejo-mailer-passwd`. The host passes these secret paths to the
|
|
`yisroelbaum-web` module.
|
|
|
|
## TIDE
|
|
|
|
Create `tide.yaml` from `tide.yaml.example` and encrypt it with sops. It must
|
|
contain `admin-password`, `mail-key`, and `secret-key`. The encrypted file is
|
|
committed; the example contains placeholders only.
|
|
|
|
## Rabbi Gerzi
|
|
|
|
Create `rabbi-gerzi.env` as a SOPS-encrypted dotenv file with:
|
|
|
|
```dotenv
|
|
APP_KEY=base64:...
|
|
RABBI_GERZI_INITIAL_ADMIN_EMAIL=...
|
|
RABBI_GERZI_INITIAL_ADMIN_PASSWORD=...
|
|
```
|
|
|
|
The host passes this environment file directly to the Rabbi Gerzi module.
|