refactor: rename vps host -> neptun (solar-system theme)

git-mv hosts/vps->neptun, secrets/vps.yaml->neptun.yaml; update flake, .sops.yaml
rules, hostName, sops paths, README/CLAUDE. Off-repo host key dir renamed too.
This commit is contained in:
erik
2026-07-14 13:32:44 +02:00
parent 19c65e1921
commit ac05d948b6
11 changed files with 18 additions and 18 deletions
+3 -3
View File
@@ -11,7 +11,7 @@ keys:
# per-host keys — derived from each box's pre-generated SSH host key # per-host keys — derived from each box's pre-generated SSH host key
# (ssh-to-age). The host decrypts at runtime using /etc/ssh/ssh_host_ed25519_key. # (ssh-to-age). The host decrypts at runtime using /etc/ssh/ssh_host_ed25519_key.
- &jupiter age1zak7glavmg4026p2389fyqe769vqm4jrryknuqckgqq4merz5f7q44rkkt - &jupiter age1zak7glavmg4026p2389fyqe769vqm4jrryknuqckgqq4merz5f7q44rkkt
- &vps age1hp72xyx2cnd05937e4eww95g5kdtn0wsf9j2nypw330pa69gfdxqn0lpkp - &neptun age1hp72xyx2cnd05937e4eww95g5kdtn0wsf9j2nypw330pa69gfdxqn0lpkp
# mercury (rpi) uses a dedicated age key (SD image, no ssh-host-key delivery); # mercury (rpi) uses a dedicated age key (SD image, no ssh-host-key delivery);
# the private key is dropped on its boot partition after flashing. # the private key is dropped on its boot partition after flashing.
- &mercury age1cpty7zrgnn6l97upq00w5wa8zcvnkxkdt2jvhlj97jh83exure4slha43t - &mercury age1cpty7zrgnn6l97upq00w5wa8zcvnkxkdt2jvhlj97jh83exure4slha43t
@@ -21,9 +21,9 @@ creation_rules:
- path_regex: secrets/jupiter\.yaml$ - path_regex: secrets/jupiter\.yaml$
key_groups: key_groups:
- age: [ *admin, *jupiter ] - age: [ *admin, *jupiter ]
- path_regex: secrets/vps\.yaml$ - path_regex: secrets/neptun\.yaml$
key_groups: key_groups:
- age: [ *admin, *vps ] - age: [ *admin, *neptun ]
- path_regex: secrets/mercury\.yaml$ - path_regex: secrets/mercury\.yaml$
key_groups: key_groups:
- age: [ *admin, *mercury ] - age: [ *admin, *mercury ]
+3 -3
View File
@@ -3,7 +3,7 @@
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository. This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
Flake-based NixOS config for a homelab. Hosts: **jupiter** (ZimaBlade NAS, x86_64), Flake-based NixOS config for a homelab. Hosts: **jupiter** (ZimaBlade NAS, x86_64),
**vps** (netcup public reverse proxy + tailnet node, x86_64), **mercury** (Raspberry **neptun** (netcup public reverse proxy + tailnet node, x86_64), **mercury** (Raspberry
Pi 3B+ DNS/DHCP, aarch64). See `README.md` for the full install/deploy walkthrough. Pi 3B+ DNS/DHCP, aarch64). See `README.md` for the full install/deploy walkthrough.
## Layout ## Layout
@@ -21,7 +21,7 @@ scripts/edit_secrets
A host = `common.nix` + the `services/*` modules it imports + its `hosts/<h>/configuration.nix`. A host = `common.nix` + the `services/*` modules it imports + its `hosts/<h>/configuration.nix`.
`services/` modules are engine-agnostic and shared across hosts (e.g. `tailscale.nix`, `services/` modules are engine-agnostic and shared across hosts (e.g. `tailscale.nix`,
`caddy.nix` used by jupiter and vps). `caddy.nix` used by jupiter and neptun).
## Commands ## Commands
@@ -59,7 +59,7 @@ nix build .#nixosConfigurations.jupiter-vbox.config.system.build.virtualBoxOVA
- Each `secrets/<host>.yaml` is encrypted to the **admin** key (edit) + that **host's** - Each `secrets/<host>.yaml` is encrypted to the **admin** key (edit) + that **host's**
key (runtime decrypt); rules in `.sops.yaml`. Private keys live OFF-repo: key (runtime decrypt); rules in `.sops.yaml`. Private keys live OFF-repo:
`~/.config/sops/age/keys.txt` (admin), `~/.config/homelab/<host>/` (host keys). `~/.config/sops/age/keys.txt` (admin), `~/.config/homelab/<host>/` (host keys).
- jupiter/vps decrypt with their **ssh host key** (`ssh-to-age` recipient), shipped at - jupiter/neptun decrypt with their **ssh host key** (`ssh-to-age` recipient), shipped at
install via `nixos-anywhere --extra-files`. install via `nixos-anywhere --extra-files`.
- mercury (SD image, no `--extra-files`) uses a **dedicated age key** at - mercury (SD image, no `--extra-files`) uses a **dedicated age key** at
`/var/lib/sops-nix/age.txt``./scripts/deploy flash` writes it to the ext4 root partition. `/var/lib/sops-nix/age.txt``./scripts/deploy flash` writes it to the ext4 root partition.
+5 -5
View File
@@ -5,7 +5,7 @@ Flake-based NixOS config. Host: `jupiter` (ZimaBlade, NAS + services).
## Structure ## Structure
``` ```
flake.nix # inputs + nixosConfigurations (jupiter, vps, kexec, ...) flake.nix # inputs + nixosConfigurations (jupiter, neptun, kexec, ...)
common.nix # shared base: user, ssh, nix, firewall, timezone common.nix # shared base: user, ssh, nix, firewall, timezone
services/ # one reusable module per service services/ # one reusable module per service
samba.nix avahi.nix audiobookshelf.nix containers.nix caddy.nix tailscale.nix samba.nix avahi.nix audiobookshelf.nix containers.nix caddy.nix tailscale.nix
@@ -16,9 +16,9 @@ hosts/
hardware-configuration.nix hardware-configuration.nix
secrets.nix # sops-nix wiring secrets.nix # sops-nix wiring
vm.nix # VirtualBox test image (jupiter-vbox) vm.nix # VirtualBox test image (jupiter-vbox)
vps/ # netcup public reverse proxy + tailnet node neptun/ # netcup public reverse proxy + tailnet node
configuration.nix disk-config.nix hardware-configuration.nix secrets.nix configuration.nix disk-config.nix hardware-configuration.nix secrets.nix
secrets/ # age-encrypted sops files (jupiter.yaml, vps.yaml) secrets/ # age-encrypted sops files (jupiter.yaml, neptun.yaml)
scripts/ # deploy, edit_secrets scripts/ # deploy, edit_secrets
``` ```
@@ -86,13 +86,13 @@ All arguments mandatory — no default host, no default config.
./deploy switch <config> <host> # rebuild + activate on a running host ./deploy switch <config> <host> # rebuild + activate on a running host
./deploy boot|test <config> <host> # stage for next boot / activate without boot entry ./deploy boot|test <config> <host> # stage for next boot / activate without boot entry
``` ```
`<config>` is a `nixosConfigurations` name (`jupiter`, `vps`). Its pre-generated `<config>` is a `nixosConfigurations` name (`jupiter`, `neptun`). Its pre-generated
SSH host key lives at `~/.config/homelab/<config>/ssh_host_ed25519_key`. SSH host key lives at `~/.config/homelab/<config>/ssh_host_ed25519_key`.
Examples: Examples:
``` ```
./deploy switch jupiter jupiter.sol ./deploy switch jupiter jupiter.sol
./deploy install vps 159.195.64.117 ./deploy install neptun 159.195.64.117
``` ```
Rollback: `nixos-rebuild switch --rollback` on the host, or pick a prior Rollback: `nixos-rebuild switch --rollback` on the host, or pick a prior
generation at boot. generation at boot.
+1 -1
View File
@@ -1,7 +1,7 @@
{ pkgs, ... }: { pkgs, ... }:
# Shared base for all hosts: user, SSH hardening, nix settings, packages. # Shared base for all hosts: user, SSH hardening, nix settings, packages.
# (jupiter still carries its own copy in services.nix; vps uses this.) # (jupiter still carries its own copy in services.nix; neptun uses this.)
{ {
# ---- User ---- # ---- User ----
users.users.darman = { users.users.darman = {
+2 -2
View File
@@ -36,13 +36,13 @@
}; };
# netcup VPS — public reverse proxy + tailnet node. # netcup VPS — public reverse proxy + tailnet node.
vps = nixpkgs.lib.nixosSystem { neptun = nixpkgs.lib.nixosSystem {
inherit system; inherit system;
specialArgs = { inherit inputs; }; specialArgs = { inherit inputs; };
modules = [ modules = [
disko.nixosModules.disko disko.nixosModules.disko
sops-nix.nixosModules.sops sops-nix.nixosModules.sops
./hosts/vps/configuration.nix ./hosts/neptun/configuration.nix
]; ];
}; };
@@ -18,7 +18,7 @@
# what nixos-generate-config detects in the installer. # what nixos-generate-config detects in the installer.
boot.initrd.availableKernelModules = [ "virtio_pci" "virtio_blk" "virtio_scsi" ]; boot.initrd.availableKernelModules = [ "virtio_pci" "virtio_blk" "virtio_scsi" ];
networking.hostName = "vps"; networking.hostName = "neptun";
# ---- Static networking (netcup) ---- # ---- Static networking (netcup) ----
# No LAN fallback: get this right or the box is unreachable (use netcup's # No LAN fallback: get this right or the box is unreachable (use netcup's
@@ -1,11 +1,11 @@
{ config, ... }: { config, ... }:
# sops-nix wiring for the VPS. Encrypted values live in ../../secrets/vps.yaml, # sops-nix wiring for neptun (netcup VPS). Encrypted values in ../../secrets/neptun.yaml,
# decrypted with the VPS's own SSH host key (recipient in ../../.sops.yaml). # decrypted with the VPS's own SSH host key (recipient in ../../.sops.yaml).
# The host key is pre-generated on the laptop and shipped at install # The host key is pre-generated on the laptop and shipped at install
# (nixos-anywhere --extra-files -> /etc/ssh/ssh_host_ed25519_key). # (nixos-anywhere --extra-files -> /etc/ssh/ssh_host_ed25519_key).
{ {
sops.defaultSopsFile = ../../secrets/vps.yaml; sops.defaultSopsFile = ../../secrets/neptun.yaml;
sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
sops.secrets.tailscale_authkey = { }; sops.secrets.tailscale_authkey = { };
+1 -1
View File
@@ -2,7 +2,7 @@
# Caddy reverse proxy — base enable + open the web ports. # Caddy reverse proxy — base enable + open the web ports.
# Each host adds its own `services.caddy.virtualHosts.<name>` (LAN names on # Each host adds its own `services.caddy.virtualHosts.<name>` (LAN names on
# jupiter, public domains with automatic HTTPS on the vps). # jupiter, public domains with automatic HTTPS on the neptun).
{ {
services.caddy.enable = true; services.caddy.enable = true;
networking.firewall.allowedTCPPorts = [ 80 443 ]; networking.firewall.allowedTCPPorts = [ 80 443 ];