Declarative NixOS configuration for mura.dev
Find a file
2026-10-05 12:16:18 +02:00
docs docs: require DNS-only Forgejo SSH endpoint 2026-10-05 11:38:56 +02:00
hosts/mura server: enable cross-region Forgejo backups 2026-10-05 11:25:08 +02:00
modules forgejo: hide pronouns profile settings 2026-10-05 12:16:18 +02:00
patches forgejo: hide pronouns profile settings 2026-10-05 12:16:18 +02:00
secrets server: enable cross-region Forgejo backups 2026-10-05 11:25:08 +02:00
.gitignore server: use stable disk labels on Linode 2026-10-05 10:56:13 +02:00
.sops.yaml server: add NixOS Linode configuration 2026-10-05 09:36:37 +02:00
flake.lock server: add NixOS Linode configuration 2026-10-05 09:36:37 +02:00
flake.nix server: enable cross-region Forgejo backups 2026-10-05 11:25:08 +02:00
README.md server: add NixOS Linode configuration 2026-10-05 09:36:37 +02:00

mura-server

Declarative NixOS configuration for the Linode serving:

The host is pinned to NixOS 26.05. Forgejo Actions and cross-region Restic backups are deliberately staged off until their scoped external credentials have been created.

Validate

nix fmt -- --check .
nix flake check -L
nix build .#nixosConfigurations.mura.config.system.build.toplevel

Install and operate

The encrypted file secrets/server.yaml is safe to commit. Its age private keys and the generated recovery credentials are not. The bootstrap copy is at ~/.local/share/mura-server/ on the installation workstation and must be placed in a password manager or other recovery escrow before the workstation copy is removed.

Normal deployments run from this directory:

nixos-rebuild switch \
  --flake .#mura \
  --target-host user@139.162.188.37 \
  --use-remote-sudo

Every deployment must keep a working LISH session available until SSH, nginx, Forgejo, and the rollback generation have been verified.