No description
Find a file
2026-08-01 22:15:52 +03:00
nix remove Rabbi Gerzi ownership 2026-08-01 22:15:52 +03:00
.gitignore add yisroelbaum web stack module 2026-07-31 11:17:25 +03:00
flake.lock remove Rabbi Gerzi ownership 2026-08-01 22:15:52 +03:00
flake.nix remove Rabbi Gerzi ownership 2026-08-01 22:15:52 +03:00
README.md remove Rabbi Gerzi ownership 2026-08-01 22:15:52 +03:00

yisroelbaum.com web stack

This flake owns the production NixOS configuration for the web services under yisroelbaum.com:

  • the MyResume package at yisroelbaum.com;
  • Jellyfin at jellyfin.yisroelbaum.com;
  • Forgejo at git.yisroelbaum.com, including its Borg backup;
  • nginx and per-host ACME certificates for those endpoints.

The importing host remains responsible for provisioning secrets. Import nixosModules.yisroelbaum-web or nixosModules.default, then pass the resulting runtime paths:

services.yisroelbaum-web = {
  enable = true;
  secretFiles = {
    borgPassphrase = "/run/secrets/borg-passphrase";
    borgPrivateKey = "/run/secrets/borg-private-key";
    forgejoMailerUser = "/run/secrets/forgejo-mailer-user";
    forgejoMailerPassword = "/run/secrets/forgejo-mailer-password";
  };
};

Run the checks with:

nix flake check

First deployment

This repository is hosted by the Forgejo instance that it configures. For the initial migration, publish and push this flake while the old host configuration is still active. Only then add the remote flake input to the host configuration and update its lock file.