Declarative NixOS configuration for mura.dev
- Nix 100%
| docs | ||
| hosts/mura | ||
| modules | ||
| patches | ||
| secrets | ||
| .gitignore | ||
| .sops.yaml | ||
| flake.lock | ||
| flake.nix | ||
| README.md | ||
mura-server
Declarative NixOS configuration for the Linode serving:
- https://mura.dev from the pinned
mura-os/mura.devstatic tree. - https://git.mura.dev from Forgejo behind nginx.
- Git over the system OpenSSH daemon as
forgejo@git.mura.dev.
The host is pinned to NixOS 26.05. Forgejo Actions and cross-region Restic backups are deliberately staged off until their scoped external credentials have been created.
Validate
nix fmt -- --check .
nix flake check -L
nix build .#nixosConfigurations.mura.config.system.build.toplevel
Install and operate
The encrypted file secrets/server.yaml is safe to commit. Its age private
keys and the generated recovery credentials are not. The bootstrap copy is at
~/.local/share/mura-server/ on the installation workstation and must be
placed in a password manager or other recovery escrow before the workstation
copy is removed.
Normal deployments run from this directory:
nixos-rebuild switch \
--flake .#mura \
--target-host user@139.162.188.37 \
--use-remote-sudo
Every deployment must keep a working LISH session available until SSH, nginx, Forgejo, and the rollback generation have been verified.