aboutsummaryrefslogtreecommitdiff
path: root/secrets/secrets.nix (unfollow)
Commit message (Collapse)AuthorFilesLines
2025-08-14add keycloak for OAuth, runbooks, and finish forgejo setupFranck Cuny1-0/+8
2025-08-12rekey some secrets and deleted unused onesFranck Cuny1-9/+4
2025-08-12delete LLM related stuff for nowFranck Cuny1-6/+0
2025-08-10setup wireguard tunnel between the VM and DO hostsFranck Cuny1-0/+5
2025-08-10manage a DigitalOcean virtual machine with nixosFranck Cuny1-0/+10
Add a new machine on DigitalOcean and provision it using terraform + nixos-anywhere. This takes care of bringing the machine up on nixos completely, and use a static SSH host key in order to configure wireguard at the same time.
2025-08-09add the SSH key for the remote builderFranck Cuny1-0/+7
All the secrets were rekeyed.
2025-07-25add a module for mounting CIFS volumesFranck Cuny1-0/+4
The new module is for NAS clients, where we specify the server and the paths to mount locally. We add a new secret to have the username of the `nas' user. We mount the backups volume from the NAS under `/data/backups` on the VM.
2025-07-06add secrets and configurations for cloudflaredFranck Cuny1-0/+9
2025-06-30backup the VM to Google Cloud StorageFranck Cuny1-0/+11
For now we only backup git repositories.
2025-06-12remove one of my keys from the secretsFranck Cuny1-6/+3
2025-06-12use a dedicated SSH key for agenixFranck Cuny1-3/+10
The key is still stored in 1password, and we add a script to synchronize the key to the host. The existing keys have been rekeyed with the new key.
2025-06-08use agenix to manage some secretsFranck Cuny1-0/+9
I have some secrets that I want to manage for my user without having to rely on 1password, and ensure proper rotation everywhere when needed. For now we only have two secrets (one for `llm` and another one is the API key for anthropic for Emacs). Will document the process better in the near future.
2024-12-28remove secrets and agenix since nothing uses themFranck Cuny1-12/+0
2024-12-19switch to the newer version of nixfmtFranck Cuny1-6/+8
`nixfmt-rfc-style' replaces `nixfmt-classic'. It's actively maintained, but also changes the style, so this commit touches all the files in the repository.
2024-12-19use treefmt to format all the filesFranck Cuny1-6/+1
2024-12-15run `ddns-updater' on `vm-synology'Franck Cuny1-1/+4
It has a small UI and the configuration with the secrets is managed with `agenix'.
2024-12-14use agenix to manage secrets in the repositoryFranck Cuny1-0/+12