Point web-repo flake inputs and deploy SSH config at code.randogoth.com instead of Codeberg
This commit is contained in:
parent
34b91012e5
commit
699bfb01c1
5 changed files with 34 additions and 38 deletions
|
|
@ -19,7 +19,7 @@ SSH into the server and run nixos-rebuild there — do not build locally:
|
|||
ssh tobias@194.68.44.28 'cd /etc/nixos && sudo git pull && sudo nixos-rebuild switch --flake /etc/nixos#bucur'
|
||||
```
|
||||
|
||||
The server pulls from Codeberg (`codeberg.org:randogoth/bucur`) using the deploy key in `secrets/bucur.yaml`.
|
||||
The server pulls from Forgejo (`code.randogoth.com:randogoth/bucur`) using the deploy key in `secrets/bucur.yaml`. (Note: the live server's `/etc/nixos` checkout still has its own `origin` pointed at Codeberg until that's updated directly on the server — see the deploy migration notes.)
|
||||
|
||||
## Adding secrets
|
||||
|
||||
|
|
|
|||
40
flake.lock
generated
40
flake.lock
generated
|
|
@ -9,11 +9,11 @@
|
|||
"rev": "e357155471eb78a543aaa57195707bac3c34ea3d",
|
||||
"revCount": 18,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/flux.vision.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/flux.vision.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git"
|
||||
}
|
||||
},
|
||||
"geoblog_plugin": {
|
||||
|
|
@ -25,11 +25,11 @@
|
|||
"rev": "840d907235d1a81b8ebfa0345f5e848452d69d60",
|
||||
"revCount": 2,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/geoblog-plugin.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/geoblog-plugin.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git"
|
||||
}
|
||||
},
|
||||
"jirorian": {
|
||||
|
|
@ -48,11 +48,11 @@
|
|||
"rev": "b5bcef3d0a2938b5bd2dead4707b113bf78bb469",
|
||||
"revCount": 5,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/jirorian.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/jirorian.git"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/jirorian.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/jirorian.git"
|
||||
}
|
||||
},
|
||||
"nfc_web": {
|
||||
|
|
@ -64,11 +64,11 @@
|
|||
"rev": "6bd590bcd113b6159edcdf8beaf66629ea7aa8dc",
|
||||
"revCount": 71,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/nfc-web.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/nfc-web.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git"
|
||||
}
|
||||
},
|
||||
"nixpkgs": {
|
||||
|
|
@ -115,13 +115,13 @@
|
|||
"rev": "97a0507dabb61d59075c19c95ee3aa78499b3959",
|
||||
"revCount": 96,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/xfay.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/xfay.git"
|
||||
},
|
||||
"original": {
|
||||
"dir": "server/oberon",
|
||||
"ref": "main",
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/xfay.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/xfay.git"
|
||||
}
|
||||
},
|
||||
"praxis": {
|
||||
|
|
@ -133,11 +133,11 @@
|
|||
"rev": "dda2c101079b7d7e6563aa40edc1057ada710a9f",
|
||||
"revCount": 1,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/praxis.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/praxis.git"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/praxis.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/praxis.git"
|
||||
}
|
||||
},
|
||||
"pyproject-build-systems": {
|
||||
|
|
@ -215,11 +215,11 @@
|
|||
"rev": "36bfce14b41942eda24bd763b8f6613141a55a1f",
|
||||
"revCount": 227,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/scopesessions.org.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/scopesessions.org.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git"
|
||||
}
|
||||
},
|
||||
"sops-nix": {
|
||||
|
|
@ -251,11 +251,11 @@
|
|||
"rev": "15f372399d900ff71afe2c9b8bf969e54a4b7688",
|
||||
"revCount": 438,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/sublunar.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.git"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/sublunar.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.git"
|
||||
}
|
||||
},
|
||||
"sublunar_almanac": {
|
||||
|
|
@ -267,11 +267,11 @@
|
|||
"rev": "c10e0a0bf27a685b8c00c6ed986f0616b7b7ba3d",
|
||||
"revCount": 84,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/sublunar.almanac.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/sublunar.almanac.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git"
|
||||
}
|
||||
},
|
||||
"uv2nix": {
|
||||
|
|
@ -308,11 +308,11 @@
|
|||
"rev": "4bd3c78d97b9995c3ac5d9b66a04e53470762aa2",
|
||||
"revCount": 21,
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/zonetoast.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://git@codeberg.org/randogoth/zonetoast.git"
|
||||
"url": "ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git"
|
||||
}
|
||||
}
|
||||
},
|
||||
|
|
|
|||
14
flake.nix
14
flake.nix
|
|
@ -9,25 +9,25 @@
|
|||
sublunar.url = "git+ssh://git@code.randogoth.com:2222/randogoth/sublunar.git";
|
||||
sublunar.flake = false;
|
||||
|
||||
flux_vision.url = "git+ssh://git@codeberg.org/randogoth/flux.vision.git";
|
||||
flux_vision.url = "git+ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git";
|
||||
flux_vision.flake = false;
|
||||
|
||||
nfc_web.url = "git+ssh://git@codeberg.org/randogoth/nfc-web.git";
|
||||
nfc_web.url = "git+ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git";
|
||||
nfc_web.flake = false;
|
||||
|
||||
scopesessions.url = "git+ssh://git@codeberg.org/randogoth/scopesessions.org.git";
|
||||
scopesessions.url = "git+ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git";
|
||||
scopesessions.flake = false;
|
||||
|
||||
sublunar_almanac.url = "git+ssh://git@codeberg.org/randogoth/sublunar.almanac.git";
|
||||
sublunar_almanac.url = "git+ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git";
|
||||
sublunar_almanac.flake = false;
|
||||
|
||||
praxis.url = "git+ssh://git@codeberg.org/randogoth/praxis.git";
|
||||
praxis.url = "git+ssh://git@code.randogoth.com:2222/randogoth/praxis.git";
|
||||
praxis.flake = false;
|
||||
|
||||
geoblog_plugin.url = "git+ssh://git@codeberg.org/randogoth/geoblog-plugin.git";
|
||||
geoblog_plugin.url = "git+ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git";
|
||||
geoblog_plugin.flake = false;
|
||||
|
||||
zonetoast.url = "git+ssh://git@codeberg.org/randogoth/zonetoast.git";
|
||||
zonetoast.url = "git+ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git";
|
||||
zonetoast.flake = false;
|
||||
|
||||
jirorian.url = "git+ssh://git@code.randogoth.com:2222/randogoth/jirorian.git";
|
||||
|
|
|
|||
|
|
@ -32,10 +32,10 @@ in
|
|||
};
|
||||
};
|
||||
|
||||
# System-wide SSH client config so root (the nix daemon) can fetch the private
|
||||
# Forgejo flake inputs, mirroring the Codeberg block in webhook-deploy.nix.
|
||||
# Reuses the existing /etc/ssh/codeberg_id_ed25519 deploy key (its public half
|
||||
# is registered on the randogoth Forgejo account).
|
||||
# System-wide SSH client config so root (the nix daemon) can fetch this
|
||||
# Forgejo's own flake inputs. Reuses the existing /etc/ssh/codeberg_id_ed25519
|
||||
# deploy key (its public half is registered on the randogoth Forgejo account) —
|
||||
# the same key all other flake inputs migrated off Codeberg now use too.
|
||||
programs.ssh.extraConfig = ''
|
||||
Host ${domain}
|
||||
Port 2222
|
||||
|
|
|
|||
|
|
@ -58,12 +58,8 @@ in
|
|||
mode = "0400";
|
||||
};
|
||||
|
||||
# System-wide SSH client config so root can reach Codeberg via the deploy key.
|
||||
programs.ssh.extraConfig = ''
|
||||
Host codeberg.org
|
||||
IdentityFile /etc/ssh/codeberg_id_ed25519
|
||||
StrictHostKeyChecking accept-new
|
||||
'';
|
||||
# All flake inputs pulled here now live on code.randogoth.com; the SSH
|
||||
# client config for that host (same deploy key) is set up in forgejo.nix.
|
||||
|
||||
systemd.services = lib.listToAttrs
|
||||
(map (site: lib.nameValuePair "update-${site.name}" {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue