41 lines
1.3 KiB
Markdown
41 lines
1.3 KiB
Markdown
# yisroelbaum.com web stack
|
|
|
|
This flake owns the production NixOS configuration for the web services under
|
|
`yisroelbaum.com`:
|
|
|
|
- the MyResume package at `yisroelbaum.com`;
|
|
- Jellyfin at `jellyfin.yisroelbaum.com`;
|
|
- Forgejo at `git.yisroelbaum.com`, including its Borg backup;
|
|
- Rabbi Gerzi at `rabbigerzi.yisroelbaum.com` and
|
|
`rabbigerziapi.yisroelbaum.com`;
|
|
- nginx and per-host ACME certificates for those endpoints.
|
|
|
|
The importing host remains responsible for provisioning secrets. Import
|
|
`nixosModules.yisroelbaum-web` or `nixosModules.default`, then pass the
|
|
resulting runtime paths:
|
|
|
|
```nix
|
|
services.yisroelbaum-web = {
|
|
enable = true;
|
|
secretFiles = {
|
|
borgPassphrase = "/run/secrets/borg-passphrase";
|
|
borgPrivateKey = "/run/secrets/borg-private-key";
|
|
forgejoMailerUser = "/run/secrets/forgejo-mailer-user";
|
|
forgejoMailerPassword = "/run/secrets/forgejo-mailer-password";
|
|
rabbiGerziEnvironment = "/run/secrets/rabbi-gerzi.env";
|
|
};
|
|
};
|
|
```
|
|
|
|
Run the checks with:
|
|
|
|
```shell
|
|
nix flake check
|
|
```
|
|
|
|
## First deployment
|
|
|
|
This repository is hosted by the Forgejo instance that it configures. For the
|
|
initial migration, publish and push this flake while the old host configuration
|
|
is still active. Only then add the remote flake input to the host configuration
|
|
and update its lock file.
|