1.3 KiB
1.3 KiB
Secrets
Encrypted with sops using the host's age key.
First-time setup on the server
- Generate an age key for the host:
sudo mkdir -p /var/lib/sops-nix sudo age-keygen -o /var/lib/sops-nix/key.txt sudo chmod 600 /var/lib/sops-nix/key.txt - Read the public key:
sudo grep "public key" /var/lib/sops-nix/key.txt - On a workstation, put that public key into
.sops.yamlat the repository root and encrypt the required secret files.
Shared Borg backup credentials
borgbackup.yaml contains private-key and passphrase. The resulting
secrets are shared by the TIDE and yisroelbaum.com backup jobs.
Forgejo
forgejo.yaml contains forgejo-mailer-user and
forgejo-mailer-passwd. The host passes these secret paths to the
yisroelbaum-web module.
TIDE
Create tide.yaml from tide.yaml.example and encrypt it with sops. It must
contain admin-password, mail-key, and secret-key. The encrypted file is
committed; the example contains placeholders only.
Rabbi Gerzi
Create rabbi-gerzi.env as a SOPS-encrypted dotenv file with:
APP_KEY=base64:...
RABBI_GERZI_INITIAL_ADMIN_EMAIL=...
RABBI_GERZI_INITIAL_ADMIN_PASSWORD=...
The host passes this environment file to the Rabbi Gerzi service through the
yisroelbaum-web module.