diff --git a/README.md b/README.md index 697ed3e..3386fb2 100644 --- a/README.md +++ b/README.md @@ -1,258 +1,34 @@ # Kieran's Dots -![nix rebuild with flake update](.github/images/nix-update.webp) +![fastfetch on my main systems](https://l4.dunkirk.sh/i/O3-dLGix6Cd9.webp) > [!CAUTION] > These dots are highly prone to change / breakage. > -> ~~I am not a nix os expert (this is my first time touching nix), so I'm not sure if this will work or not. I'm just trying to get my dots up on github.~~ +> ~I am not a nix os expert (this is my first time touching nix), so I'm not sure if this will work or not. I'm just trying to get my dots up on github :3 > > After `591` days of these dots being in constant operation, many many rebuilds, and `776` commits these dots have been rock solid and I have no complaints. -## The layout - -``` -~/dots -├── .github/workflows # CI/CD (deploy-rs + per-service reusable workflow) -├── dots # config files symlinked by home-manager -│ └── wallpapers -├── machines -│ ├── atalanta # macOS M4 (nix-darwin) -│ ├── ember # dell r210 server (basement) -│ ├── iso # NixOS installer ISO (x86_64 + aarch64) -│ ├── moonlark # framework 13 (dead) -│ ├── nest # shared tilde server (home-manager only) -│ ├── prattle # lenovo thinkstation p300 (xeon, 32GB, ZFS mirror) -│ ├── tacyon # rpi 5 -│ └── terebithia # oracle cloud aarch64 (main server) -├── modules -│ ├── lib -│ │ └── mkService.nix # service factory (see Deployment section) -│ ├── home # home-manager modules -│ │ ├── aesthetics # theming and wallpapers -│ │ ├── apps # app configs (ghostty, helix, git, ssh, etc.) -│ │ ├── system # shell, environment -│ │ └── wm/hyprland -│ └── nixos # nixos modules -│ ├── apps # system-level app configs -│ ├── services # self-hosted services (mkService-based + custom) -│ │ ├── restic # backup system with CLI -│ │ └── bore # tunnel proxy -│ └── system # pam, wifi -├── packages # custom nix packages -└── secrets # agenix-encrypted secrets -``` - -## Installation - -> [!WARNING] -> Also to note that this configuration will **not** work if you do not change any of the [secrets](./secrets) since they are encrypted. - -You could install a NixOS machine, use the home-manager instructions, or use nix-darwin for macOS. - -### macOS with nix-darwin - -For macOS machines, you can use nix-darwin: - -1. Install Nix using the determinate systems installer: - -```bash -curl -fsSL https://install.determinate.systems/nix | sh -s -- install -``` - -2. Clone the repository: +## Documentation -```bash -git clone git@github.com:taciturnaxolotl/dots.git -cd dots -``` +Semi up-to-date documentation lives in the [mdbook](https://dots.dunkirk.sh) but the most reliable docs are just the config itself. Uptime stats are served at [infra.dunkirk.sh](https://infra.dunkirk.sh). -3. Apply the configuration: +### Quick start ```bash +# macOS darwin-rebuild switch --flake .#atalanta -``` - -### Home Manager - -Install nix via the determinate systems installer - -```bash -curl -fsSL https://install.determinate.systems/nix | sh -s -- install --determinate -``` - -then copy ssh keys and chmod them -```bash -scp .ssh/id_rsa* nest:/home/kierank/.ssh/ -ssh nest chmod 600 ~/.ssh/id_rsa* -``` - -and then clone the repo - -```bash -git clone git@github.com:taciturnaxolotl/dots.git -cd dots -``` +# NixOS (local) +nixos-rebuild switch --flake .#terebithia -and execute the machine profile - -```bash -nix-shell -p home-manager -home-manager switch --flake .#nest -``` - -setup atuin and import previous shell history - -```bash -atuin login -atuin import +# Remote deploy (from dev shell) +nix develop +deploy .#terebithia ``` -### NixOS - -> These instructions have been validated by installing on my friend's machine ([`Nat2-Dev/dots`](https://github.com/Nat2-Dev/dots)) - -#### Using nixos-anywhere (Recommended for remote installations) - > [!WARNING] -> This only currently works with `prattle` and `terebithia` as they have the proper disko configs setup. - -For remote installations (like Oracle Cloud), use [nixos-anywhere](https://github.com/nix-community/nixos-anywhere): - -```bash -nix run github:nix-community/nixos-anywhere -- \ - --flake .#prattle \ - --generate-hardware-config nixos-facter ./machines/prattle/facter.json \ - --build-on-remote \ - root@ -``` - -Replace `prattle` with your machine configuration and `` with your target machine's IP. - -> [!NOTE] -> Make sure your SSH key is in the target machine's `authorized_keys` and the machine configuration has the correct network settings. The `--generate-hardware-config nixos-facter` flag will generate a comprehensive hardware report using [nixos-facter](https://github.com/numtide/nixos-facter) instead of the traditional `nixos-generate-config`. - -#### Using the install script - -```bash -curl -L https://raw.githubusercontent.com/taciturnaxolotl/dots/main/install.sh -o install.sh -chmod +x install.sh -./install.sh -``` - -#### Post-install - -After first boot, log in with user `kierank` and the default password, then change it immediately: - -```bash -passwd kierank -``` - -Move the config to your home directory and symlink: - -```bash -sudo mv /etc/nixos ~/dots -sudo ln -s ~/dots /etc/nixos -sudo chown -R $(id -un):users ~/dots -``` - -Set up [atuin](https://atuin.sh/) for shell history sync: - -```bash -atuin login -atuin sync -``` - -## Deployment - -Two deploy paths: **infrastructure** (NixOS config changes in this repo) and **application code** (per-service repos). - -### Infrastructure - -Pushing to `main` here triggers `.github/workflows/deploy.yaml` which runs `deploy-rs` over Tailscale to rebuild NixOS on the target machine. - -```sh -# manual deploy -nix run 'github:serokell/deploy-rs' -- --remote-build --ssh-user kierank . -``` - -### Application code - -Each service repo has a minimal workflow calling the reusable `.github/workflows/deploy-service.yml`. On push to `main`: - -1. Connects to Tailscale (`tag:deploy`) -2. SSHes as the **service user** (e.g., `cachet@terebithia`) via Tailscale SSH -3. Snapshots the SQLite DB (if `db_path` is provided) -4. `git pull` + `bun install --frozen-lockfile` + `sudo systemctl restart` -5. Health check (HTTP URL or systemd status fallback) -6. Auto-rollback on failure (restores DB snapshot + reverts to previous commit) - -Per-app workflow — copy and change the `with:` values: - -```yaml -name: Deploy -on: - push: - branches: [main] - workflow_dispatch: -jobs: - deploy: - uses: taciturnaxolotl/dots/.github/workflows/deploy-service.yml@main - with: - service: cachet - health_url: https://cachet.dunkirk.sh/health - db_path: /var/lib/cachet/data/cachet.db - secrets: - TS_OAUTH_CLIENT_ID: ${{ secrets.TS_OAUTH_CLIENT_ID }} - TS_OAUTH_SECRET: ${{ secrets.TS_OAUTH_SECRET }} -``` - -Omit `health_url` to fall back to `systemctl is-active`. Omit `db_path` for stateless services. - -### mkService - -`modules/lib/mkService.nix` standardizes service modules. A call to `mkService { ... }` provides: - -- Systemd service with initial git clone (subsequent deploys via GitHub Actions) -- Caddy reverse proxy with TLS via Cloudflare DNS and optional rate limiting -- Data declarations (`sqlite`, `postgres`, `files`) that feed into automatic backups -- Dedicated system user with sudo for restart/stop/start (enables per-user Tailscale ACLs) -- Port conflict detection, security hardening, agenix secrets - -Adding a new service: create a module in `modules/nixos/services/`, enable it in `machines/terebithia/default.nix`, and add a deploy workflow to the app repo. See `modules/nixos/services/cachet.nix` for a minimal example. - -### Secrets (agenix) - -Secrets are encrypted in `secrets/*.age` and declared in `secrets/secrets.nix`. Referenced as `config.age.secrets..path` — decrypted at activation time to `/run/agenix/`. - -```sh -cd secrets && agenix -e myapp.age # create/edit a secret -``` - -## Backups - -Services are automatically backed up nightly using restic to Backblaze B2. Backup targets are auto-discovered from `data.sqlite`/`data.postgres`/`data.files` declarations in mkService modules. - -The `atelier-backup` CLI provides an interactive TUI for managing backups: - -```bash -sudo atelier-backup # Interactive menu -sudo atelier-backup status # Show backup status -sudo atelier-backup restore # Restore wizard -sudo atelier-backup dr # Disaster recovery -``` - -See [modules/nixos/services/restic/README.md](modules/nixos/services/restic/README.md) for setup and usage. - -## some odd things - -for helix if you want the grammar to work you must run the following as per [this helix discussion](https://github.com/helix-editor/helix/discussions/10035#discussioncomment-13852637) - -```bash -hx -g fetch -hx -g build -``` +> This configuration will **not** work without changing the [secrets](./secrets) since they are encrypted with agenix. ## Screenshots @@ -262,6 +38,7 @@ hx -g build **Last updated: 2024-12-27** +![nix rebuild with flake update](.github/images/nix-update.webp) ![the github page of this repo](.github/images/github.webp) ![nautilus file manager](.github/images/nautilus.webp) ![neofetch](.github/images/neofetch.webp) @@ -293,7 +70,7 @@ Thanks a bunch to the following people for their dots, configs, and general insp - [setting up the proper portals](https://github.com/NixOS/nixpkgs/issues/274554) - [tuigreet setup](https://github.com/sjcobb2022/nixos-config/blob/29077cee1fc82c5296908f0594e28276dacbe0b0/hosts/common/optional/greetd.nix) -## 📜 License +## License The code is licensed under `MIT`! That means MIT allows for free use, modification, and distribution of the software, requiring only that the original copyright notice and disclaimer are included in copies. All artwork and images are copyright reserved but may be used with proper attribution to the authors. diff --git a/docs/src/README.md b/docs/src/README.md index 5453c82..a531cd1 100644 --- a/docs/src/README.md +++ b/docs/src/README.md @@ -1,47 +1,14 @@ # dunkirk.sh -Kieran's opinionated NixOS infrastructure — declarative server config, self-hosted services, and automated deployments. +Kieran's opinionated NixOS infrastructure. Declarative server config, self-hosted services, automated deployments. -## Layout +For machine inventory, apply commands, repo layout, and conventions see [AGENTS.md](https://github.com/taciturnaxolotl/dots/blob/main/AGENTS.md). -``` -~/dots -├── .github/workflows # CI/CD (deploy-rs + per-service reusable workflow) -├── dots # config files symlinked by home-manager -│ └── wallpapers -├── machines -│ ├── atalanta # macOS M4 (nix-darwin) -│ ├── ember # dell r210 server (basement) -│ ├── moonlark # framework 13 (dead) -│ ├── nest # shared tilde server (home-manager only) -│ ├── prattle # oracle cloud x86_64 -│ ├── tacyon # rpi 5 -│ └── terebithia # oracle cloud aarch64 (main server) -├── modules -│ ├── lib -│ │ └── mkService.nix # service factory (see Deployment section) -│ ├── home # home-manager modules -│ │ ├── aesthetics # theming and wallpapers -│ │ ├── apps # app configs (ghostty, helix, git, ssh, etc.) -│ │ ├── system # shell, environment -│ │ └── wm/hyprland -│ └── nixos # nixos modules -│ ├── apps # system-level app configs -│ ├── services # self-hosted services (mkService-based + custom) -│ │ ├── restic # backup system with CLI -│ │ └── bore # tunnel proxy -│ └── system # pam, wifi -├── packages # custom nix packages -└── secrets # agenix-encrypted secrets -``` +- [Installation](./installation.md) — getting started on macOS, NixOS, or home-manager +- [Deployment](./deployment.md) — CI/CD workflows for infrastructure and application code +- [Services](./services/README.md) — architecture overview and service documentation +- [Secrets](./secrets.md) — agenix workflow +- [mkService](./mkservice.md) — the service factory reference +- [Modules](./modules/README.md) — custom NixOS and home-manager modules -## Machines - -| Name | Platform | Role | -|------|----------|------| -| **terebithia** | Oracle Cloud aarch64 | Main server — runs all services | -| **prattle** | Oracle Cloud x86_64 | Secondary server | -| **atalanta** | macOS M4 | Development laptop (nix-darwin) | -| **ember** | Dell R210 | Basement server | -| **tacyon** | Raspberry Pi 5 | Edge device | -| **nest** | Shared tilde | Home-manager only | +Live status at [infra.dunkirk.sh](https://infra.dunkirk.sh). Machine manifest: `nix eval --json .#services-manifest`. diff --git a/docs/src/SUMMARY.md b/docs/src/SUMMARY.md index a8147fe..389d411 100644 --- a/docs/src/SUMMARY.md +++ b/docs/src/SUMMARY.md @@ -5,13 +5,12 @@ - [Installation](./installation.md) - [Deployment](./deployment.md) - [Services](./services/README.md) - - [control](./services/control.md) + - [bore](./services/bore.md) - [cedarlogic](./services/cedarlogic.md) + - [control](./services/control.md) - [emojibot](./services/emojibot.md) - [herald](./services/herald.md) - [knot-sync](./services/knot-sync.md) - - [bore](./services/bore.md) -- [Backups](./backups.md) - [Secrets](./secrets.md) - [Modules](./modules/README.md) - [tuigreet](./modules/tuigreet.md) diff --git a/docs/src/backups.md b/docs/src/backups.md deleted file mode 100644 index 61d29d7..0000000 --- a/docs/src/backups.md +++ /dev/null @@ -1,71 +0,0 @@ -# Backups - -Services are automatically backed up nightly using restic to Backblaze B2. Backup targets are auto-discovered from `data.sqlite`/`data.postgres`/`data.files` declarations in mkService modules. - -## Schedule - -- **Time:** 02:00 AM daily -- **Random delay:** 0–2 hours (spreads load across services) -- **Retention:** 3 snapshots, 7 daily, 5 weekly, 12 monthly - -## CLI - -The `atelier-backup` command provides an interactive TUI: - -```bash -sudo atelier-backup # Interactive menu -sudo atelier-backup status # Show backup status for all services -sudo atelier-backup list # Browse snapshots -sudo atelier-backup backup # Trigger manual backup -sudo atelier-backup restore # Interactive restore wizard -sudo atelier-backup dr # Disaster recovery mode -``` - -## Service integration - -### Automatic (mkService) - -Services using `mkService` with `data.*` declarations get automatic backup: - -```nix -mkService { - name = "myapp"; - extraConfig = cfg: { - atelier.services.myapp.data = { - sqlite = "${cfg.dataDir}/data/app.db"; # Auto WAL checkpoint + stop/start - files = [ "${cfg.dataDir}/uploads" ]; # Just backed up, no hooks - }; - }; -} -``` - -The backup system automatically checkpoints SQLite WAL, stops the service during backup, and restarts after completion. - -### Manual registration - -For services not using `mkService`: - -```nix -atelier.backup.services.myservice = { - paths = [ "/var/lib/myservice" ]; - exclude = [ "*.log" "cache/*" ]; - preBackup = "systemctl stop myservice"; - postBackup = "systemctl start myservice"; -}; -``` - -## Disaster recovery - -On a fresh NixOS install: - -1. Rebuild from flake: `nixos-rebuild switch --flake .#hostname` -2. Run: `sudo atelier-backup dr` -3. All services restored from latest snapshots - -## Setup - -1. Create a B2 bucket and application key -2. Create agenix secrets for `restic/password`, `restic/env`, `restic/repo` -3. Enable: `atelier.backup.enable = true;` - -See [modules/nixos/services/restic/README.md](https://github.com/taciturnaxolotl/dots/blob/main/modules/nixos/services/restic/README.md) for full setup details. diff --git a/docs/src/deployment.md b/docs/src/deployment.md index 0e402b4..eada972 100644 --- a/docs/src/deployment.md +++ b/docs/src/deployment.md @@ -7,10 +7,17 @@ Two deploy paths: **infrastructure** (NixOS config changes) and **application co Pushing to `main` triggers `.github/workflows/deploy.yaml` which runs `deploy-rs` over Tailscale to rebuild NixOS on the target machine. ```sh -# manual deploy -nix run 'github:serokell/deploy-rs' -- --remote-build --ssh-user kierank . +# From the dev shell (preferred) +nix develop +deploy .#terebithia +deploy .#prattle + +# Manual one-off +nix run 'github:serokell/deploy-rs' -- --remote-build --ssh-user kierank .#terebithia ``` +Builds happen on the target machine (`--remote-build`), so CI only needs Nix and network access. + ## Application Code Each service repo has a minimal workflow calling the reusable `.github/workflows/deploy-service.yml`. On push to `main`: @@ -22,7 +29,7 @@ Each service repo has a minimal workflow calling the reusable `.github/workflows 5. Health check (HTTP URL or systemd status fallback) 6. Auto-rollback on failure (restores DB snapshot + reverts to previous commit) -Per-app workflow — copy and change the `with:` values: +Per-app workflow. Copy and change the `with:` values: ```yaml name: Deploy @@ -44,24 +51,11 @@ jobs: Omit `health_url` to fall back to `systemctl is-active`. Omit `db_path` for stateless services. -## mkService - -`modules/lib/mkService.nix` standardizes service modules. A call to `mkService { ... }` provides: - -- Systemd service with initial git clone (subsequent deploys via GitHub Actions) -- Caddy reverse proxy with TLS via Cloudflare DNS and optional rate limiting -- Data declarations (`sqlite`, `postgres`, `files`) that feed into automatic backups -- Dedicated system user with sudo for restart/stop/start (enables per-user Tailscale ACLs) -- Port conflict detection, security hardening, agenix secrets - -### Adding a new service - -1. Create a module in `modules/nixos/services/` -2. Enable it in `machines/terebithia/default.nix` -3. Add a deploy workflow to the app repo - -See `modules/nixos/services/cachet.nix` for a minimal example. +## Adding a new service -## Machine health checks +1. Create a module in `modules/nixos/services/` using [mkService](./mkservice.md) or a custom module +2. Register secrets in `secrets/secrets.nix` and encrypt with agenix +3. Enable in the target machine's `default.nix` +4. Add a deploy workflow to the app repo (if it has one) -Machines with Tailscale enabled automatically expose their hostname for reachability checks in the services manifest via `atelier.machine.tailscaleHost`. This defaults to `networking.hostName` when `services.tailscale.enable` is true. +See `modules/nixos/services/cachet.nix` for a minimal mkService example. diff --git a/docs/src/modules/README.md b/docs/src/modules/README.md index 37326fe..f2745b7 100644 --- a/docs/src/modules/README.md +++ b/docs/src/modules/README.md @@ -2,21 +2,32 @@ Custom NixOS and home-manager modules under the `atelier.*` namespace. These wrap and extend upstream packages with opinionated defaults and structured configuration. -## NixOS modules - -| Module | Namespace | Description | -|--------|-----------|-------------| -| [tuigreet](./tuigreet.md) | `atelier.apps.tuigreet` | Login greeter with 30+ typed options | -| [wifi](./wifi.md) | `atelier.network.wifi` | Declarative Wi-Fi profiles with eduroam support | -| authentication | `atelier.authentication` | Fingerprint + PAM stack (fprintd, polkit, gnome-keyring) | - -## Home-manager modules - -| Module | Namespace | Description | -|--------|-----------|-------------| -| [shell](./shell.md) | `atelier.shell` | Zsh + oh-my-posh + Tangled workflow tooling | -| [ssh](./ssh.md) | `atelier.ssh` | SSH config with zmx persistent sessions | -| [helix](./helix.md) | `atelier.apps.helix` | Evil-helix with 15+ LSPs, wakatime, harper | -| [bore (client)](./bore-client.md) | `atelier.bore` | Tunnel client CLI for the bore server | -| [pbnj](./pbnj.md) | `atelier.pbnj` | Pastebin CLI with language detection | -| [wut](./wut.md) | `atelier.shell.wut` | Git worktree manager | +All modules live under `modules/nixos/` and `modules/home/`. Machines using `import-tree` automatically discover every `.nix` file in those trees. Modules only activate when their `enable` option is set to `true`. + +## Documented modules + +These have detailed option references and examples: + +### NixOS + +- [tuigreet](./tuigreet.md) — login greeter (`atelier.apps.tuigreet`) +- [wifi](./wifi.md) — declarative Wi-Fi profiles with eduroam (`atelier.network.wifi`) + +### Home-manager + +- [shell](./shell.md) — zsh + oh-my-posh + Tangled tooling (`atelier.shell`) +- [ssh](./ssh.md) — SSH config with zmx persistent sessions (`atelier.ssh`) +- [helix](./helix.md) — evil-helix with LSPs, wakatime, harper (`atelier.apps.helix`) +- [bore (client)](./bore-client.md) — tunnel client CLI (`atelier.bore`) +- [pbnj](./pbnj.md) — pastebin CLI (`atelier.pbnj`) +- [wut](./wut.md) — git worktree manager (`atelier.shell.wut`) + +## Other modules + +Many more modules exist without dedicated doc pages. Browse the source: + +- `modules/home/apps/` — ghostty, alacritty, git, jj, qutebrowser, spotify, halloy, irssi, tofi +- `modules/home/aesthetics/` — theming (Catppuccin), wallpapers +- `modules/home/wm/` — hyprland, yabai/skhd +- `modules/nixos/system/` — authentication, machine metadata +- `modules/nixos/services/` — 20+ service modules (see [Services](../services/README.md)) diff --git a/docs/src/services/README.md b/docs/src/services/README.md index 6538bde..db4eaf2 100644 --- a/docs/src/services/README.md +++ b/docs/src/services/README.md @@ -1,75 +1,21 @@ # Services -Services are grouped by machine in the services manifest. Machines with Tailscale enabled automatically expose their hostname for reachability checks via `atelier.machine.tailscaleHost`. +All services run behind Caddy with Cloudflare DNS TLS. Most use the [mkService](../mkservice.md) factory which provides systemd units, dedicated users, reverse proxy, backup integration, and port conflict detection. -## Machines +## Live status -| Machine | Platform | Tailscale | -|---------|----------|-----------| -| terebithia | Oracle Cloud aarch64 | `terebithia` | -| moonlark | — | — | -| prattle | — | — | +- **Dashboard:** [infra.dunkirk.sh](https://infra.dunkirk.sh) +- **Machine manifest:** `nix eval --json .#services-manifest` or [`/services.json`](../services.json) -## terebithia +## Service documentation -All services run behind Caddy with Cloudflare DNS TLS. +These services have detailed option references and architecture notes: -### mkService-based +- [bore](./bore.md) — HTTP/TCP/UDP tunnel proxy with optional OAuth +- [cedarlogic](./cedarlogic.md) — circuit simulator with WebSocket collaboration +- [control](./control.md) — admin dashboard for Caddy feature toggles +- [emojibot](./emojibot.md) — multi-instance Slack emoji management +- [herald](./herald.md) — git SSH hosting with email via SMTP/DKIM +- [knot-sync](./knot-sync.md) — mirrors Tangled knot repos to GitHub on cron -| Service | Domain | Port | Runtime | Description | -|---------|--------|------|---------|-------------| -| cachet | cachet.dunkirk.sh | 3000 | bun | Slack emoji/profile cache | -| hn-alerts | hn.dunkirk.sh | 3001 | bun | Hacker News monitoring | -| indiko | indiko.dunkirk.sh | 3003 | bun | IndieAuth/OAuth2 server | -| l4 | l4.dunkirk.sh | 3004 | bun | Image CDN — Slack image optimizer | -| canvas-mcp | canvas.dunkirk.sh | 3006 | bun | Canvas MCP server | -| control | control.dunkirk.sh | 3010 | bun | Admin dashboard for Caddy toggles | -| traverse | traverse.dunkirk.sh | 4173 | bun | Code walkthrough diagram server | -| cedarlogic | cedarlogic.dunkirk.sh | 3100 | custom | Circuit simulator | - -### Multi-instance - -| Service | Domain | Port | Description | -|---------|--------|------|-------------| -| emojibot-hackclub | hc.emojibot.dunkirk.sh | 3002 | Emojibot for Hack Club | -| emojibot-df1317 | df.emojibot.dunkirk.sh | 3005 | Emojibot for df1317 | - -### Custom / external - -| Service | Domain | Description | -|---------|--------|-------------| -| bore (frps) | bore.dunkirk.sh | HTTP/TCP/UDP tunnel proxy | -| herald | herald.dunkirk.sh | Git SSH hosting + email | -| knot | knot.dunkirk.sh | Tangled git hosting | -| spindle | spindle.dunkirk.sh | Tangled CI | -| n8n | n8n.dunkirk.sh | Workflow automation | - -## Services manifest - -The manifest is now grouped by machine. Evaluate with: - -```sh -nix eval --json .#services-manifest -``` - -Output shape: - -```json -{ - "terebithia": { - "hostname": "terebithia", - "tailscale_host": "terebithia", - "services": [{ "name": "cachet", "health_url": "https://cachet.dunkirk.sh/health", ... }] - } -} -``` - -## Architecture - -Each mkService module provides: - -- **Systemd service** — initial git clone for scaffolding, subsequent deploys via GitHub Actions -- **Caddy reverse proxy** — TLS via Cloudflare DNS challenge, optional rate limiting -- **Data declarations** — `sqlite`, `postgres`, `files` feed into automatic backups -- **Dedicated user** — sudo for restart/stop/start, per-user Tailscale SSH ACLs -- **Port conflict detection** — assertions prevent two services binding the same port +For all other services, check the manifest or the module source in `modules/nixos/services/`. diff --git a/packages/docs.nix b/packages/docs.nix index b54995a..efae077 100644 --- a/packages/docs.nix +++ b/packages/docs.nix @@ -1,6 +1,5 @@ { stdenvNoCC, - lib, mdbook, nixdoc, fetchurl,