home-server-config/secrets/README.md

49 lines
1.3 KiB
Markdown

# Secrets
Encrypted with [sops](https://github.com/getsops/sops) using the
host's age key.
## First-time setup on the server
1. Generate an age key for the host:
```
sudo mkdir -p /var/lib/sops-nix
sudo age-keygen -o /var/lib/sops-nix/key.txt
sudo chmod 600 /var/lib/sops-nix/key.txt
```
2. Read the public key:
```
sudo grep "public key" /var/lib/sops-nix/key.txt
```
3. On a workstation, put that public key into `.sops.yaml` at the repository
root and encrypt the required secret files.
## Shared Borg backup credentials
`borgbackup.yaml` contains `private-key` and `passphrase`. The resulting
secrets are shared by the TIDE and yisroelbaum.com backup jobs.
## Forgejo
`forgejo.yaml` contains `forgejo-mailer-user` and
`forgejo-mailer-passwd`. The host passes these secret paths to the
`yisroelbaum-web` module.
## TIDE
Create `tide.yaml` from `tide.yaml.example` and encrypt it with sops. It must
contain `admin-password`, `mail-key`, and `secret-key`. The encrypted file is
committed; the example contains placeholders only.
## Rabbi Gerzi
Create `rabbi-gerzi.env` as a SOPS-encrypted dotenv file with:
```dotenv
APP_KEY=base64:...
RABBI_GERZI_INITIAL_ADMIN_EMAIL=...
RABBI_GERZI_INITIAL_ADMIN_PASSWORD=...
```
The host passes this environment file to the Rabbi Gerzi service through the
`yisroelbaum-web` module.