bucur/deploy.md

1.4 KiB

Deploying bucur

Connect

SSH via Tailscale (preferred) or direct IP:

ssh tobias@bucur          # via Tailscale
ssh tobias@194.68.44.28   # direct

User tobias has passwordless sudo (wheel group).

Deploy

SSH into the server and run nixos-rebuild there — do not build locally:

ssh tobias@194.68.44.28 'cd /etc/nixos && sudo git pull && sudo nixos-rebuild switch --flake /etc/nixos#bucur'

The server pulls from Forgejo (code.randogoth.com:randogoth/bucur) using the deploy key in secrets/bucur.yaml. (Note: the live server's /etc/nixos checkout still has its own origin pointed at Codeberg until that's updated directly on the server — see the deploy migration notes.)

Adding secrets

Edit secrets/bucur.yaml with sops (age key at secrets/age/keys.txt):

SOPS_AGE_KEY_FILE=secrets/age/keys.txt nix run nixpkgs#sops -- secrets/bucur.yaml

Reference the new secret in the relevant module via config.sops.secrets.<name>.path.

Manual service ops

# Check a service
ssh tobias@194.68.44.28 'sudo journalctl -fu <service>'

# Trigger the daily database backup
ssh tobias@194.68.44.28 'sudo systemctl start borgbackup-job-databases'

# List backup archives
ssh tobias@194.68.44.28 'sudo bash -c "BORG_RSH=\"ssh -i /run/secrets/borg_ssh_key\" BORG_PASSPHRASE=\$(cat /run/secrets/borg_passphrase) borg list ssh://snh7mkwh@snh7mkwh.repo.borgbase.com/./repo"'