pub.solar infrastructure, mostly in nix and terraform
Find a file
Benjamin Yule Bädorf ad1ea4a49e
forgejo: run internal ssh server on port 22
The system-wide SSH server was hidden behind a wireguard proxy for
security reasons, but since forgejo was using it, git pushes and pulls
got broken for people without wireguard access.

These config changes make sure forgejo starts its built-in SSH server
on port 22, which is then allowed to be accessed from the open internet
in the firewall config.
2024-04-05 15:05:28 +02:00
.forgejo/workflows fix(ci): avoid nix trying to use GH access-token 2023-12-14 00:40:38 +01:00
docs docs: how to update mediawiki wiki.pub.solar 2024-01-08 14:54:25 +01:00
hosts forgejo: run internal ssh server on port 22 2024-04-05 15:05:28 +02:00
lib treewide: apply nixpkgs-fmt 2024-01-27 20:29:30 +01:00
logins logins/wireguard: move teutat3s wireguard device 2024-04-05 11:09:31 +00:00
modules forgejo: run internal ssh server on port 22 2024-04-05 15:05:28 +02:00
overlays chore: update flake inputs 2024-03-05 21:39:19 +01:00
secrets wireguard: add basic keys 2024-04-05 11:09:31 +00:00
terraform feat: init tmate-ssh-server 2024-02-07 19:01:36 +01:00
.envrc Add dev shell 2023-10-28 12:38:14 +02:00
.git-blame-ignore-revs feat: add .git-blame-ignore-revs file 2024-01-28 00:32:41 +01:00
.gitignore fix: add result to gitignore 2023-12-14 00:40:37 +01:00
flake.lock chore: update flake inputs 2024-04-04 18:49:09 +02:00
flake.nix wireguard: initial commit 2024-04-05 11:09:31 +00:00
README.md docs: fix typo in README 2023-11-18 23:17:28 +01:00

The pub.solar infrastructure

This repository contains almost all of the configuration for the whole pub.solar infrastructure. Our goal is to have everything, from host configurations to Terraform DNS in this repository.

The architecture we are working towards is a vast simplification of what it was before: one dedicated Hetzner server running NixOS with all services. Offsite backups go to several different locations with restic.

Contributing

If you'd like to contribute, it makes sense to talk to the crew on Matrix via #hakken. We can help figuring out how things work and can make sure your ideas fit the pub.solar philosophy. Of course popping a pull request is always celebrated.

To start, see how to get a development shell.