Remove sops & add acs service

This commit is contained in:
2026-07-07 05:03:18 +01:00
parent 343ab84f42
commit 2d21314705
7 changed files with 40 additions and 65 deletions
+29 -9
View File
@@ -12,6 +12,11 @@
networking.hostName = "syedm";
nix.settings.experimental-features = [
"nix-command"
"flakes"
];
# Configure network connections interactively with nmcli or nmtui.
networking.networkmanager.enable = true;
@@ -47,7 +52,7 @@
# List packages installed in system profile.
# You can use https://search.nixos.org/ to find more packages (and options).
environment.systemPackages = with pkgs; [
sops
nodejs
age
eza
yazi
@@ -60,13 +65,6 @@
git
];
# Secrets file
sops.age.keyFile = "/home/me/.config/sops/age/keys.txt";
sops.secrets."main.env" = {
sopsFile = ../secrets/main.env;
format = "dotenv";
};
# Enable the OpenSSH daemon.
services.openssh.enable = true;
@@ -78,6 +76,9 @@
virtualHosts."git.syedm.dev".extraConfig = ''
reverse_proxy localhost:3000
'';
virtualHosts."acs.syedm.dev".extraConfig = ''
reverse_proxy localhost:3709
'';
};
services.gitea = {
@@ -100,7 +101,26 @@
session.COOKIE_SECURE = true;
log.LEVEL = "Info";
};
lfs.enable = true;
};
systemd.services.msjd = {
description = "Msjd";
after = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
serviceConfig = {
WorkingDirectory = "/home/me/main/msjd";
ExecStart = "${pkgs.nodejs}/bin/node index.mjs";
User = "me";
Restart = "always";
RestartSec = 3;
Environment = [
"NODE_ENV=production"
"PORT=3709"
];
};
};
# Open ports in the firewall.
+1 -36
View File
@@ -16,44 +16,9 @@
"type": "github"
}
},
"nixpkgs_2": {
"locked": {
"lastModified": 1775888245,
"narHash": "sha256-nwASzrRDD1JBEu/o8ekKYEXm/oJW6EMCzCRdrwcLe90=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "13043924aaa7375ce482ebe2494338e058282925",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"root": {
"inputs": {
"nixpkgs": "nixpkgs",
"sops-nix": "sops-nix"
}
},
"sops-nix": {
"inputs": {
"nixpkgs": "nixpkgs_2"
},
"locked": {
"lastModified": 1782165805,
"narHash": "sha256-478kKQBvK6SYTOdN2h9jhKJv94nbXRbFMfuL1WshErg=",
"owner": "Mic92",
"repo": "sops-nix",
"rev": "56b24064fdcaedca53553b1a6d607fd23b613a24",
"type": "github"
},
"original": {
"owner": "Mic92",
"repo": "sops-nix",
"type": "github"
"nixpkgs": "nixpkgs"
}
}
},
+2 -4
View File
@@ -1,10 +1,9 @@
{
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
sops-nix.url = "github:Mic92/sops-nix";
};
outputs = inputs@{ self, nixpkgs, sops-nix, ... }:
outputs = inputs@{ self, nixpkgs, ... }:
let
system = "x86_64-linux";
in {
@@ -13,8 +12,7 @@
modules = [
./configuration.nix
sops-nix.nixosModules.sops
./flakes/cloudflare-ddns.nix
# ./flakes/cloudflare-ddns.nix ! to be readded when fixed secret management
];
};
};