From 699bfb01c1a32b6a3b6c2e4225786093519f30e4 Mon Sep 17 00:00:00 2001 From: randogoth Date: Thu, 23 Jul 2026 13:00:36 +0200 Subject: [PATCH] Point web-repo flake inputs and deploy SSH config at code.randogoth.com instead of Codeberg --- deploy.md | 2 +- flake.lock | 40 ++++++++++++++--------------- flake.nix | 14 +++++----- modules/services/forgejo.nix | 8 +++--- modules/services/webhook-deploy.nix | 8 ++---- 5 files changed, 34 insertions(+), 38 deletions(-) diff --git a/deploy.md b/deploy.md index 591936c..a63e71d 100644 --- a/deploy.md +++ b/deploy.md @@ -19,7 +19,7 @@ SSH into the server and run nixos-rebuild there — do not build locally: ssh tobias@194.68.44.28 'cd /etc/nixos && sudo git pull && sudo nixos-rebuild switch --flake /etc/nixos#bucur' ``` -The server pulls from Codeberg (`codeberg.org:randogoth/bucur`) using the deploy key in `secrets/bucur.yaml`. +The server pulls from Forgejo (`code.randogoth.com:randogoth/bucur`) using the deploy key in `secrets/bucur.yaml`. (Note: the live server's `/etc/nixos` checkout still has its own `origin` pointed at Codeberg until that's updated directly on the server — see the deploy migration notes.) ## Adding secrets diff --git a/flake.lock b/flake.lock index d29e7d5..91b75c7 100644 --- a/flake.lock +++ b/flake.lock @@ -9,11 +9,11 @@ "rev": "e357155471eb78a543aaa57195707bac3c34ea3d", "revCount": 18, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/flux.vision.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git" }, "original": { "type": "git", - "url": "ssh://git@codeberg.org/randogoth/flux.vision.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git" } }, "geoblog_plugin": { @@ -25,11 +25,11 @@ "rev": "840d907235d1a81b8ebfa0345f5e848452d69d60", "revCount": 2, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/geoblog-plugin.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git" }, "original": { "type": "git", - "url": "ssh://git@codeberg.org/randogoth/geoblog-plugin.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git" } }, "jirorian": { @@ -48,11 +48,11 @@ "rev": "b5bcef3d0a2938b5bd2dead4707b113bf78bb469", "revCount": 5, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/jirorian.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/jirorian.git" }, "original": { "type": "git", - "url": "ssh://git@codeberg.org/randogoth/jirorian.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/jirorian.git" } }, "nfc_web": { @@ -64,11 +64,11 @@ "rev": "6bd590bcd113b6159edcdf8beaf66629ea7aa8dc", "revCount": 71, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/nfc-web.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git" }, "original": { "type": "git", - "url": "ssh://git@codeberg.org/randogoth/nfc-web.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git" } }, "nixpkgs": { @@ -115,13 +115,13 @@ "rev": "97a0507dabb61d59075c19c95ee3aa78499b3959", "revCount": 96, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/xfay.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/xfay.git" }, "original": { "dir": "server/oberon", "ref": "main", "type": "git", - "url": "ssh://git@codeberg.org/randogoth/xfay.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/xfay.git" } }, "praxis": { @@ -133,11 +133,11 @@ "rev": "dda2c101079b7d7e6563aa40edc1057ada710a9f", "revCount": 1, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/praxis.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/praxis.git" }, "original": { "type": "git", - "url": "ssh://git@codeberg.org/randogoth/praxis.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/praxis.git" } }, "pyproject-build-systems": { @@ -215,11 +215,11 @@ "rev": "36bfce14b41942eda24bd763b8f6613141a55a1f", "revCount": 227, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/scopesessions.org.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git" }, "original": { "type": "git", - "url": "ssh://git@codeberg.org/randogoth/scopesessions.org.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git" } }, "sops-nix": { @@ -251,11 +251,11 @@ "rev": "15f372399d900ff71afe2c9b8bf969e54a4b7688", "revCount": 438, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/sublunar.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.git" }, "original": { "type": "git", - "url": "ssh://git@codeberg.org/randogoth/sublunar.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.git" } }, "sublunar_almanac": { @@ -267,11 +267,11 @@ "rev": "c10e0a0bf27a685b8c00c6ed986f0616b7b7ba3d", "revCount": 84, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/sublunar.almanac.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git" }, "original": { "type": "git", - "url": "ssh://git@codeberg.org/randogoth/sublunar.almanac.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git" } }, "uv2nix": { @@ -308,11 +308,11 @@ "rev": "4bd3c78d97b9995c3ac5d9b66a04e53470762aa2", "revCount": 21, "type": "git", - "url": "ssh://git@codeberg.org/randogoth/zonetoast.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git" }, "original": { "type": "git", - "url": "ssh://git@codeberg.org/randogoth/zonetoast.git" + "url": "ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git" } } }, diff --git a/flake.nix b/flake.nix index b9c29f3..ccc635a 100644 --- a/flake.nix +++ b/flake.nix @@ -9,25 +9,25 @@ sublunar.url = "git+ssh://git@code.randogoth.com:2222/randogoth/sublunar.git"; sublunar.flake = false; - flux_vision.url = "git+ssh://git@codeberg.org/randogoth/flux.vision.git"; + flux_vision.url = "git+ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git"; flux_vision.flake = false; - nfc_web.url = "git+ssh://git@codeberg.org/randogoth/nfc-web.git"; + nfc_web.url = "git+ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git"; nfc_web.flake = false; - scopesessions.url = "git+ssh://git@codeberg.org/randogoth/scopesessions.org.git"; + scopesessions.url = "git+ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git"; scopesessions.flake = false; - sublunar_almanac.url = "git+ssh://git@codeberg.org/randogoth/sublunar.almanac.git"; + sublunar_almanac.url = "git+ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git"; sublunar_almanac.flake = false; - praxis.url = "git+ssh://git@codeberg.org/randogoth/praxis.git"; + praxis.url = "git+ssh://git@code.randogoth.com:2222/randogoth/praxis.git"; praxis.flake = false; - geoblog_plugin.url = "git+ssh://git@codeberg.org/randogoth/geoblog-plugin.git"; + geoblog_plugin.url = "git+ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git"; geoblog_plugin.flake = false; - zonetoast.url = "git+ssh://git@codeberg.org/randogoth/zonetoast.git"; + zonetoast.url = "git+ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git"; zonetoast.flake = false; jirorian.url = "git+ssh://git@code.randogoth.com:2222/randogoth/jirorian.git"; diff --git a/modules/services/forgejo.nix b/modules/services/forgejo.nix index 88cb287..0e2757c 100644 --- a/modules/services/forgejo.nix +++ b/modules/services/forgejo.nix @@ -32,10 +32,10 @@ in }; }; - # System-wide SSH client config so root (the nix daemon) can fetch the private - # Forgejo flake inputs, mirroring the Codeberg block in webhook-deploy.nix. - # Reuses the existing /etc/ssh/codeberg_id_ed25519 deploy key (its public half - # is registered on the randogoth Forgejo account). + # System-wide SSH client config so root (the nix daemon) can fetch this + # Forgejo's own flake inputs. Reuses the existing /etc/ssh/codeberg_id_ed25519 + # deploy key (its public half is registered on the randogoth Forgejo account) — + # the same key all other flake inputs migrated off Codeberg now use too. programs.ssh.extraConfig = '' Host ${domain} Port 2222 diff --git a/modules/services/webhook-deploy.nix b/modules/services/webhook-deploy.nix index 6c5bca6..0ba90c2 100644 --- a/modules/services/webhook-deploy.nix +++ b/modules/services/webhook-deploy.nix @@ -58,12 +58,8 @@ in mode = "0400"; }; - # System-wide SSH client config so root can reach Codeberg via the deploy key. - programs.ssh.extraConfig = '' - Host codeberg.org - IdentityFile /etc/ssh/codeberg_id_ed25519 - StrictHostKeyChecking accept-new - ''; + # All flake inputs pulled here now live on code.randogoth.com; the SSH + # client config for that host (same deploy key) is set up in forgejo.nix. systemd.services = lib.listToAttrs (map (site: lib.nameValuePair "update-${site.name}" {