yisroelbaum-web/README.md

38 lines
1.1 KiB
Markdown

# yisroelbaum.com web stack
This flake owns the production NixOS configuration for the web services under
`yisroelbaum.com`:
- the MyResume package at `yisroelbaum.com`;
- Jellyfin at `jellyfin.yisroelbaum.com`;
- Forgejo at `git.yisroelbaum.com`, including its Borg backup;
- nginx and per-host ACME certificates for those endpoints.
The importing host remains responsible for provisioning secrets. Import
`nixosModules.yisroelbaum-web` or `nixosModules.default`, then pass the
resulting runtime paths:
```nix
services.yisroelbaum-web = {
enable = true;
secretFiles = {
borgPassphrase = "/run/secrets/borg-passphrase";
borgPrivateKey = "/run/secrets/borg-private-key";
forgejoMailerUser = "/run/secrets/forgejo-mailer-user";
forgejoMailerPassword = "/run/secrets/forgejo-mailer-password";
};
};
```
Run the checks with:
```shell
nix flake check
```
## First deployment
This repository is hosted by the Forgejo instance that it configures. For the
initial migration, publish and push this flake while the old host configuration
is still active. Only then add the remote flake input to the host configuration
and update its lock file.