Point web-repo flake inputs and deploy SSH config at code.randogoth.com instead of Codeberg

This commit is contained in:
randogoth 2026-07-23 13:00:36 +02:00
parent 34b91012e5
commit 699bfb01c1
5 changed files with 34 additions and 38 deletions

View file

@ -19,7 +19,7 @@ SSH into the server and run nixos-rebuild there — do not build locally:
ssh tobias@194.68.44.28 'cd /etc/nixos && sudo git pull && sudo nixos-rebuild switch --flake /etc/nixos#bucur'
```
The server pulls from Codeberg (`codeberg.org:randogoth/bucur`) using the deploy key in `secrets/bucur.yaml`.
The server pulls from Forgejo (`code.randogoth.com:randogoth/bucur`) using the deploy key in `secrets/bucur.yaml`. (Note: the live server's `/etc/nixos` checkout still has its own `origin` pointed at Codeberg until that's updated directly on the server — see the deploy migration notes.)
## Adding secrets

40
flake.lock generated
View file

@ -9,11 +9,11 @@
"rev": "e357155471eb78a543aaa57195707bac3c34ea3d",
"revCount": 18,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/flux.vision.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git"
},
"original": {
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/flux.vision.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git"
}
},
"geoblog_plugin": {
@ -25,11 +25,11 @@
"rev": "840d907235d1a81b8ebfa0345f5e848452d69d60",
"revCount": 2,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/geoblog-plugin.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git"
},
"original": {
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/geoblog-plugin.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git"
}
},
"jirorian": {
@ -48,11 +48,11 @@
"rev": "b5bcef3d0a2938b5bd2dead4707b113bf78bb469",
"revCount": 5,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/jirorian.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/jirorian.git"
},
"original": {
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/jirorian.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/jirorian.git"
}
},
"nfc_web": {
@ -64,11 +64,11 @@
"rev": "6bd590bcd113b6159edcdf8beaf66629ea7aa8dc",
"revCount": 71,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/nfc-web.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git"
},
"original": {
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/nfc-web.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git"
}
},
"nixpkgs": {
@ -115,13 +115,13 @@
"rev": "97a0507dabb61d59075c19c95ee3aa78499b3959",
"revCount": 96,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/xfay.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/xfay.git"
},
"original": {
"dir": "server/oberon",
"ref": "main",
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/xfay.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/xfay.git"
}
},
"praxis": {
@ -133,11 +133,11 @@
"rev": "dda2c101079b7d7e6563aa40edc1057ada710a9f",
"revCount": 1,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/praxis.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/praxis.git"
},
"original": {
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/praxis.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/praxis.git"
}
},
"pyproject-build-systems": {
@ -215,11 +215,11 @@
"rev": "36bfce14b41942eda24bd763b8f6613141a55a1f",
"revCount": 227,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/scopesessions.org.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git"
},
"original": {
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/scopesessions.org.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git"
}
},
"sops-nix": {
@ -251,11 +251,11 @@
"rev": "15f372399d900ff71afe2c9b8bf969e54a4b7688",
"revCount": 438,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/sublunar.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.git"
},
"original": {
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/sublunar.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.git"
}
},
"sublunar_almanac": {
@ -267,11 +267,11 @@
"rev": "c10e0a0bf27a685b8c00c6ed986f0616b7b7ba3d",
"revCount": 84,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/sublunar.almanac.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git"
},
"original": {
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/sublunar.almanac.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git"
}
},
"uv2nix": {
@ -308,11 +308,11 @@
"rev": "4bd3c78d97b9995c3ac5d9b66a04e53470762aa2",
"revCount": 21,
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/zonetoast.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git"
},
"original": {
"type": "git",
"url": "ssh://git@codeberg.org/randogoth/zonetoast.git"
"url": "ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git"
}
}
},

View file

@ -9,25 +9,25 @@
sublunar.url = "git+ssh://git@code.randogoth.com:2222/randogoth/sublunar.git";
sublunar.flake = false;
flux_vision.url = "git+ssh://git@codeberg.org/randogoth/flux.vision.git";
flux_vision.url = "git+ssh://git@code.randogoth.com:2222/randogoth/flux.vision.git";
flux_vision.flake = false;
nfc_web.url = "git+ssh://git@codeberg.org/randogoth/nfc-web.git";
nfc_web.url = "git+ssh://git@code.randogoth.com:2222/randogoth/nfc-web.git";
nfc_web.flake = false;
scopesessions.url = "git+ssh://git@codeberg.org/randogoth/scopesessions.org.git";
scopesessions.url = "git+ssh://git@code.randogoth.com:2222/randogoth/scopesessions.org.git";
scopesessions.flake = false;
sublunar_almanac.url = "git+ssh://git@codeberg.org/randogoth/sublunar.almanac.git";
sublunar_almanac.url = "git+ssh://git@code.randogoth.com:2222/randogoth/sublunar.almanac.git";
sublunar_almanac.flake = false;
praxis.url = "git+ssh://git@codeberg.org/randogoth/praxis.git";
praxis.url = "git+ssh://git@code.randogoth.com:2222/randogoth/praxis.git";
praxis.flake = false;
geoblog_plugin.url = "git+ssh://git@codeberg.org/randogoth/geoblog-plugin.git";
geoblog_plugin.url = "git+ssh://git@code.randogoth.com:2222/randogoth/geoblog-plugin.git";
geoblog_plugin.flake = false;
zonetoast.url = "git+ssh://git@codeberg.org/randogoth/zonetoast.git";
zonetoast.url = "git+ssh://git@code.randogoth.com:2222/randogoth/zonetoast.git";
zonetoast.flake = false;
jirorian.url = "git+ssh://git@code.randogoth.com:2222/randogoth/jirorian.git";

View file

@ -32,10 +32,10 @@ in
};
};
# System-wide SSH client config so root (the nix daemon) can fetch the private
# Forgejo flake inputs, mirroring the Codeberg block in webhook-deploy.nix.
# Reuses the existing /etc/ssh/codeberg_id_ed25519 deploy key (its public half
# is registered on the randogoth Forgejo account).
# System-wide SSH client config so root (the nix daemon) can fetch this
# Forgejo's own flake inputs. Reuses the existing /etc/ssh/codeberg_id_ed25519
# deploy key (its public half is registered on the randogoth Forgejo account) —
# the same key all other flake inputs migrated off Codeberg now use too.
programs.ssh.extraConfig = ''
Host ${domain}
Port 2222

View file

@ -58,12 +58,8 @@ in
mode = "0400";
};
# System-wide SSH client config so root can reach Codeberg via the deploy key.
programs.ssh.extraConfig = ''
Host codeberg.org
IdentityFile /etc/ssh/codeberg_id_ed25519
StrictHostKeyChecking accept-new
'';
# All flake inputs pulled here now live on code.randogoth.com; the SSH
# client config for that host (same deploy key) is set up in forgejo.nix.
systemd.services = lib.listToAttrs
(map (site: lib.nameValuePair "update-${site.name}" {