feat(hosts): make config multi-host and add vps host
Parametrize networking, users, and containers modules under myNetworking/myUsers/myContainers so both hosts share the same logic instead of duplicating it, and split desktop/server module imports into modules/profiles/. Adds hosts/vps (not installed yet, hardware config and bootloader device are placeholders) to run Traefik, Headscale, Headplane, and Gitea via a combined Docker Compose stack. Wires up agenix for secrets and migrates miku-homelab's WireGuard private key off a plain filesystem path into an encrypted secrets/miku-homelab-wg.age. The vps side of that tunnel still needs its own key generated and encrypted after install. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
26bfa56268
commit
42e60a3bb5
13 files changed
+695
-184
No files matched your search
@@ -0,0 +1,9 @@
|
||||
age-encryption.org/v1
|
||||
-> ssh-ed25519 IW6ZLQ fGdkbwV5VE8c5ueKCr/q3Agl9cKnqzmpPUGQsOTMqVU
|
||||
ZvXNujDfCWxuprM/2k7FR7aeNcpwU+cAd9H+ZByYOkE
|
||||
-> ssh-ed25519 h0IYxQ 3PzwNp8Sn8eeYBNMBKOJ+hoH9uxVlgV0RtqsPdZNtnM
|
||||
WDLCfjfmKsj3u0GL+luYLwwXit98RLbgwMBNzp+x24U
|
||||
-> ssh-ed25519 4D7N4w 3ndiKKCZSJoZNpn1HElFnyPOx8DeFJPm9iAMQdtm4SM
|
||||
KqX/oScwxOhOqHM1Z+uoXWMRZrCpl5ax6BuHiy6puwc
|
||||
--- CEVnIJUTA60ffvNCDrodud14KIfucXHub+tl7tXX/N4
|
||||
ÅШb³ú_zj(Ãö…s>îãF¼x£UßãFعÝÓÛñS·ˆ`†ŸOdÙ…N‰lÛFã%š LfÇ—FfÞ‡#ê6ò‘ðÎ
|
||||
@@ -0,0 +1,20 @@
|
||||
let
|
||||
# Emma's personal SSH keys (same ones authorized in modules/system/users.nix),
|
||||
# so secrets can be edited/re-keyed from her own workstations.
|
||||
emma-main-pc = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA8vfwM5g9RJXqHtqTgNqsYg9SxSm+UMvFqTjBoAsLJ6 emmatherock@MAIN-PC";
|
||||
emma-s21-plus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIpTslcK0yQ6k+h8foNl17wVRyJUfEGzq7f1h3014WNB s21 plus";
|
||||
|
||||
# Host SSH host keys, used by agenix at runtime to decrypt (via the default
|
||||
# age.identityPaths, which points at services.openssh host keys).
|
||||
miku-homelab = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH7zsQdzX7RHRd2plwrTKJR89uwR2YfzBm1n+HkcYEbb root@NixOS";
|
||||
|
||||
# TODO: replace with the real vps SSH host key once the host is installed
|
||||
# (e.g. via `ssh-keyscan` or by reading /etc/ssh/ssh_host_ed25519_key.pub on
|
||||
# the vps itself), then re-key any vps secrets that were encrypted without it.
|
||||
vps = "ssh-ed25519 REPLACE_ME_AFTER_VPS_INSTALL";
|
||||
|
||||
admins = [ emma-main-pc emma-s21-plus ];
|
||||
in
|
||||
{
|
||||
"miku-homelab-wg.age".publicKeys = admins ++ [ miku-homelab ];
|
||||
}
|
||||
Reference in new issue
Block a user