Point web-repo flake inputs and deploy SSH config at code.randogoth.com instead of Codeberg

This commit is contained in:
randogoth 2026-07-23 13:00:36 +02:00
parent 34b91012e5
commit 699bfb01c1
5 changed files with 34 additions and 38 deletions

View file

@ -19,7 +19,7 @@ SSH into the server and run nixos-rebuild there — do not build locally:
ssh tobias@194.68.44.28 'cd /etc/nixos && sudo git pull && sudo nixos-rebuild switch --flake /etc/nixos#bucur' ssh tobias@194.68.44.28 'cd /etc/nixos && sudo git pull && sudo nixos-rebuild switch --flake /etc/nixos#bucur'
``` ```
The server pulls from Codeberg (`codeberg.org:randogoth/bucur`) using the deploy key in `secrets/bucur.yaml`. The server pulls from Forgejo (`code.randogoth.com:randogoth/bucur`) using the deploy key in `secrets/bucur.yaml`. (Note: the live server's `/etc/nixos` checkout still has its own `origin` pointed at Codeberg until that's updated directly on the server — see the deploy migration notes.)
## Adding secrets ## Adding secrets

40
flake.lock generated
View file

@ -9,11 +9,11 @@
"rev": "e357155471eb78a543aaa57195707bac3c34ea3d", "rev": "e357155471eb78a543aaa57195707bac3c34ea3d",
"revCount": 18, "revCount": 18,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/flux.vision.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git"
}, },
"original": { "original": {
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/flux.vision.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git"
} }
}, },
"geoblog_plugin": { "geoblog_plugin": {
@ -25,11 +25,11 @@
"rev": "840d907235d1a81b8ebfa0345f5e848452d69d60", "rev": "840d907235d1a81b8ebfa0345f5e848452d69d60",
"revCount": 2, "revCount": 2,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/geoblog-plugin.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git"
}, },
"original": { "original": {
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/geoblog-plugin.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git"
} }
}, },
"jirorian": { "jirorian": {
@ -48,11 +48,11 @@
"rev": "b5bcef3d0a2938b5bd2dead4707b113bf78bb469", "rev": "b5bcef3d0a2938b5bd2dead4707b113bf78bb469",
"revCount": 5, "revCount": 5,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/jirorian.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/jirorian.git"
}, },
"original": { "original": {
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/jirorian.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/jirorian.git"
} }
}, },
"nfc_web": { "nfc_web": {
@ -64,11 +64,11 @@
"rev": "6bd590bcd113b6159edcdf8beaf66629ea7aa8dc", "rev": "6bd590bcd113b6159edcdf8beaf66629ea7aa8dc",
"revCount": 71, "revCount": 71,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/nfc-web.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git"
}, },
"original": { "original": {
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/nfc-web.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git"
} }
}, },
"nixpkgs": { "nixpkgs": {
@ -115,13 +115,13 @@
"rev": "97a0507dabb61d59075c19c95ee3aa78499b3959", "rev": "97a0507dabb61d59075c19c95ee3aa78499b3959",
"revCount": 96, "revCount": 96,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/xfay.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/xfay.git"
}, },
"original": { "original": {
"dir": "server/oberon", "dir": "server/oberon",
"ref": "main", "ref": "main",
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/xfay.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/xfay.git"
} }
}, },
"praxis": { "praxis": {
@ -133,11 +133,11 @@
"rev": "dda2c101079b7d7e6563aa40edc1057ada710a9f", "rev": "dda2c101079b7d7e6563aa40edc1057ada710a9f",
"revCount": 1, "revCount": 1,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/praxis.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/praxis.git"
}, },
"original": { "original": {
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/praxis.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/praxis.git"
} }
}, },
"pyproject-build-systems": { "pyproject-build-systems": {
@ -215,11 +215,11 @@
"rev": "36bfce14b41942eda24bd763b8f6613141a55a1f", "rev": "36bfce14b41942eda24bd763b8f6613141a55a1f",
"revCount": 227, "revCount": 227,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/scopesessions.org.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git"
}, },
"original": { "original": {
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/scopesessions.org.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git"
} }
}, },
"sops-nix": { "sops-nix": {
@ -251,11 +251,11 @@
"rev": "15f372399d900ff71afe2c9b8bf969e54a4b7688", "rev": "15f372399d900ff71afe2c9b8bf969e54a4b7688",
"revCount": 438, "revCount": 438,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/sublunar.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.git"
}, },
"original": { "original": {
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/sublunar.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.git"
} }
}, },
"sublunar_almanac": { "sublunar_almanac": {
@ -267,11 +267,11 @@
"rev": "c10e0a0bf27a685b8c00c6ed986f0616b7b7ba3d", "rev": "c10e0a0bf27a685b8c00c6ed986f0616b7b7ba3d",
"revCount": 84, "revCount": 84,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/sublunar.almanac.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git"
}, },
"original": { "original": {
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/sublunar.almanac.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git"
} }
}, },
"uv2nix": { "uv2nix": {
@ -308,11 +308,11 @@
"rev": "4bd3c78d97b9995c3ac5d9b66a04e53470762aa2", "rev": "4bd3c78d97b9995c3ac5d9b66a04e53470762aa2",
"revCount": 21, "revCount": 21,
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/zonetoast.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git"
}, },
"original": { "original": {
"type": "git", "type": "git",
"url": "ssh://git@codeberg.org/randogoth/zonetoast.git" "url": "ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git"
} }
} }
}, },

View file

@ -9,25 +9,25 @@
sublunar.url = "git+ssh://git@code.randogoth.com:2222/randogoth/sublunar.git"; sublunar.url = "git+ssh://git@code.randogoth.com:2222/randogoth/sublunar.git";
sublunar.flake = false; sublunar.flake = false;
flux_vision.url = "git+ssh://git@codeberg.org/randogoth/flux.vision.git"; flux_vision.url = "git+ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git";
flux_vision.flake = false; flux_vision.flake = false;
nfc_web.url = "git+ssh://git@codeberg.org/randogoth/nfc-web.git"; nfc_web.url = "git+ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git";
nfc_web.flake = false; nfc_web.flake = false;
scopesessions.url = "git+ssh://git@codeberg.org/randogoth/scopesessions.org.git"; scopesessions.url = "git+ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git";
scopesessions.flake = false; scopesessions.flake = false;
sublunar_almanac.url = "git+ssh://git@codeberg.org/randogoth/sublunar.almanac.git"; sublunar_almanac.url = "git+ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git";
sublunar_almanac.flake = false; sublunar_almanac.flake = false;
praxis.url = "git+ssh://git@codeberg.org/randogoth/praxis.git"; praxis.url = "git+ssh://git@code.randogoth.com:2222/randogoth/praxis.git";
praxis.flake = false; praxis.flake = false;
geoblog_plugin.url = "git+ssh://git@codeberg.org/randogoth/geoblog-plugin.git"; geoblog_plugin.url = "git+ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git";
geoblog_plugin.flake = false; geoblog_plugin.flake = false;
zonetoast.url = "git+ssh://git@codeberg.org/randogoth/zonetoast.git"; zonetoast.url = "git+ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git";
zonetoast.flake = false; zonetoast.flake = false;
jirorian.url = "git+ssh://git@code.randogoth.com:2222/randogoth/jirorian.git"; jirorian.url = "git+ssh://git@code.randogoth.com:2222/randogoth/jirorian.git";

View file

@ -32,10 +32,10 @@ in
}; };
}; };
# System-wide SSH client config so root (the nix daemon) can fetch the private # System-wide SSH client config so root (the nix daemon) can fetch this
# Forgejo flake inputs, mirroring the Codeberg block in webhook-deploy.nix. # Forgejo's own flake inputs. Reuses the existing /etc/ssh/codeberg_id_ed25519
# Reuses the existing /etc/ssh/codeberg_id_ed25519 deploy key (its public half # deploy key (its public half is registered on the randogoth Forgejo account) —
# is registered on the randogoth Forgejo account). # the same key all other flake inputs migrated off Codeberg now use too.
programs.ssh.extraConfig = '' programs.ssh.extraConfig = ''
Host ${domain} Host ${domain}
Port 2222 Port 2222

View file

@ -58,12 +58,8 @@ in
mode = "0400"; mode = "0400";
}; };
# System-wide SSH client config so root can reach Codeberg via the deploy key. # All flake inputs pulled here now live on code.randogoth.com; the SSH
programs.ssh.extraConfig = '' # client config for that host (same deploy key) is set up in forgejo.nix.
Host codeberg.org
IdentityFile /etc/ssh/codeberg_id_ed25519
StrictHostKeyChecking accept-new
'';
systemd.services = lib.listToAttrs systemd.services = lib.listToAttrs
(map (site: lib.nameValuePair "update-${site.name}" { (map (site: lib.nameValuePair "update-${site.name}" {