feat(hosts): make config multi-host and add vps host

Parametrize networking, users, and containers modules under
myNetworking/myUsers/myContainers so both hosts share the same logic
instead of duplicating it, and split desktop/server module imports
into modules/profiles/. Adds hosts/vps (not installed yet, hardware
config and bootloader device are placeholders) to run Traefik,
Headscale, Headplane, and Gitea via a combined Docker Compose stack.

Wires up agenix for secrets and migrates miku-homelab's WireGuard
private key off a plain filesystem path into an encrypted
secrets/miku-homelab-wg.age. The vps side of that tunnel still needs
its own key generated and encrypted after install.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
emmatherockandClaude Sonnet 5 committed 2026-08-12 00:07:55 -03:00
1 parent 26bfa56268
commit 42e60a3bb5
13 files changed
+695 -184

No files matched your search

+20
View File
@@ -0,0 +1,20 @@
let
# Emma's personal SSH keys (same ones authorized in modules/system/users.nix),
# so secrets can be edited/re-keyed from her own workstations.
emma-main-pc = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA8vfwM5g9RJXqHtqTgNqsYg9SxSm+UMvFqTjBoAsLJ6 emmatherock@MAIN-PC";
emma-s21-plus = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIpTslcK0yQ6k+h8foNl17wVRyJUfEGzq7f1h3014WNB s21 plus";
# Host SSH host keys, used by agenix at runtime to decrypt (via the default
# age.identityPaths, which points at services.openssh host keys).
miku-homelab = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH7zsQdzX7RHRd2plwrTKJR89uwR2YfzBm1n+HkcYEbb root@NixOS";
# TODO: replace with the real vps SSH host key once the host is installed
# (e.g. via `ssh-keyscan` or by reading /etc/ssh/ssh_host_ed25519_key.pub on
# the vps itself), then re-key any vps secrets that were encrypted without it.
vps = "ssh-ed25519 REPLACE_ME_AFTER_VPS_INSTALL";
admins = [ emma-main-pc emma-s21-plus ];
in
{
"miku-homelab-wg.age".publicKeys = admins ++ [ miku-homelab ];
}