No description
Find a file
2026-07-31 11:28:28 +03:00
nix add yisroelbaum web stack module 2026-07-31 11:17:25 +03:00
.gitignore add yisroelbaum web stack module 2026-07-31 11:17:25 +03:00
flake.lock preserve deployed Rabbi Gerzi revision 2026-07-31 11:28:28 +03:00
flake.nix add yisroelbaum web stack module 2026-07-31 11:17:25 +03:00
README.md add yisroelbaum web stack module 2026-07-31 11:17:25 +03:00

yisroelbaum.com web stack

This flake owns the production NixOS configuration for the web services under yisroelbaum.com:

  • the MyResume package at yisroelbaum.com;
  • Jellyfin at jellyfin.yisroelbaum.com;
  • Forgejo at git.yisroelbaum.com, including its Borg backup;
  • Rabbi Gerzi at rabbigerzi.yisroelbaum.com and rabbigerziapi.yisroelbaum.com;
  • nginx and per-host ACME certificates for those endpoints.

The importing host remains responsible for provisioning secrets. Import nixosModules.yisroelbaum-web or nixosModules.default, then pass the resulting runtime paths:

services.yisroelbaum-web = {
  enable = true;
  secretFiles = {
    borgPassphrase = "/run/secrets/borg-passphrase";
    borgPrivateKey = "/run/secrets/borg-private-key";
    forgejoMailerUser = "/run/secrets/forgejo-mailer-user";
    forgejoMailerPassword = "/run/secrets/forgejo-mailer-password";
    rabbiGerziEnvironment = "/run/secrets/rabbi-gerzi.env";
  };
};

Run the checks with:

nix flake check

First deployment

This repository is hosted by the Forgejo instance that it configures. For the initial migration, publish and push this flake while the old host configuration is still active. Only then add the remote flake input to the host configuration and update its lock file.