1.1 KiB
1.1 KiB
yisroelbaum.com web stack
This flake owns the production NixOS configuration for the web services under
yisroelbaum.com:
- the MyResume package at
yisroelbaum.com; - Jellyfin at
jellyfin.yisroelbaum.com; - Forgejo at
git.yisroelbaum.com, including its Borg backup; - nginx and per-host ACME certificates for those endpoints.
The importing host remains responsible for provisioning secrets. Import
nixosModules.yisroelbaum-web or nixosModules.default, then pass the
resulting runtime paths:
services.yisroelbaum-web = {
enable = true;
secretFiles = {
borgPassphrase = "/run/secrets/borg-passphrase";
borgPrivateKey = "/run/secrets/borg-private-key";
forgejoMailerUser = "/run/secrets/forgejo-mailer-user";
forgejoMailerPassword = "/run/secrets/forgejo-mailer-password";
};
};
Run the checks with:
nix flake check
First deployment
This repository is hosted by the Forgejo instance that it configures. For the initial migration, publish and push this flake while the old host configuration is still active. Only then add the remote flake input to the host configuration and update its lock file.