home-server-config/secrets/README.md

1.3 KiB

Secrets

Encrypted with sops using the host's age key.

First-time setup on the server

  1. Generate an age key for the host:
    sudo mkdir -p /var/lib/sops-nix
    sudo age-keygen -o /var/lib/sops-nix/key.txt
    sudo chmod 600 /var/lib/sops-nix/key.txt
    
  2. Read the public key:
    sudo grep "public key" /var/lib/sops-nix/key.txt
    
  3. On a workstation, put that public key into .sops.yaml at the repository root and encrypt the required secret files.

Shared Borg backup credentials

borgbackup.yaml contains private-key and passphrase. The resulting secrets are shared by the TIDE and yisroelbaum.com backup jobs.

Forgejo

forgejo.yaml contains forgejo-mailer-user and forgejo-mailer-passwd. The host passes these secret paths to the yisroelbaum-web module.

TIDE

Create tide.yaml from tide.yaml.example and encrypt it with sops. It must contain admin-password, mail-key, and secret-key. The encrypted file is committed; the example contains placeholders only.

Rabbi Gerzi

Create rabbi-gerzi.env as a SOPS-encrypted dotenv file with:

APP_KEY=base64:...
RABBI_GERZI_INITIAL_ADMIN_EMAIL=...
RABBI_GERZI_INITIAL_ADMIN_PASSWORD=...

The host passes this environment file to the Rabbi Gerzi service through the yisroelbaum-web module.