Imports the notplants-atproto module: Docker daemon (this host had none), a systemd unit running the project's docker-compose stack, and an nginx vhost proxying to it on 127.0.0.1:8731 with ACME and websocket support. Opens 80/443 publicly. Until now only 22 was open and everything else was tailnet-only, so this is a real change in exposure — nginx is now reachable from the internet. The existing oc.commoninternet.net vhost is untouched and stays bound to the tailscale IP. nix/atproto-likes.nix is a COPY; the canonical file lives in the project repo at /srv/project-orchestrator/projects/notplants-atproto/nix/. Pure evaluation forbids importing an absolute path outside the flake tree, so it has to be duplicated here — and a new file must be git-added or nix silently ignores it. ACME currently FAILS: *.commoninternet.net is a wildcard pointing at 143.244.213.108, so the HTTP-01 challenge is answered by that host (500). nginx serves a self-signed placeholder and starts fine. Fix is an explicit A record atproto.commoninternet.net -> 168.119.126.100, then `systemctl start acme-atproto.commoninternet.net.service`. Applied with nixos-rebuild switch; container healthy, TLS proxy and wss verified end to end. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SmEK2voMnBa23495aLk1Ce
cc-ci-orchestrator
⚠️ HISTORICAL. This README describes the retired Incus VM (
100.116.55.106). The orchestrator now runs on Hetzner — the live host config isnix/hosts/cc-ci-orchestrator-hetzner/configuration.nix. Seecc-ci-plan/plan-orchestrator-hetzner-migration.mdfor the current setup. Kept for history.
NixOS config for the cc-ci-orchestrator Incus VM (b1, project terraform-ci, tailnet
100.116.55.106) — the reboot-resilient host for the cc-ci Builder/Adversary loops + watchdog +
orchestrator session, moved off the unstable 905 MiB Pi.
See cc-ci-plan/plan-orchestrator-migration.md for the full migration.
Files
configuration.nix— the VM's NixOS config (channel-based,nixos-24.11). Deployed to/etc/nixos/configuration.nixon the VM. Provides: nix-ld (so the standalone Claude Code Bun binary runs), tmux/git/python/jq + tools, a 4 GB swapfile, direct ssh to cc-ci (the VM is a tailnet peer — no SOCKS proxy needed, unlike the Pi), an idempotentclaude-installoneshot, and thecc-ci-loopssupervisor service (defined, enabled in Phase D once the workspace is staged).
Deploy (until this is wired to a flake/auto-pull)
# copy configuration.nix to the VM, then:
ssh cc-ci-orchestrator 'nixos-rebuild switch' # or run detached: see below
Over the (currently flaky) Pi→VM link, run the rebuild detached on the VM so an ssh/proxy drop
doesn't abort it, e.g. systemd-run --unit=orch-rebuild --collect nixos-rebuild switch then poll
journalctl -u orch-rebuild.
Status
- Phase A: VM created (2 GB / 2 vCPU / 30 GB), on tailnet, ssh-able. ✅
- Phase B: this config (DRAFT) — nix-ld/claude validation pending on the VM.
- Operator step pending (Phase C):
claude auth loginon the VM (device-code; can't be scripted). - Secrets to stage (Phase C, out-of-band):
/srv/cc-ci/.testenv,~/.ssh/cc-ci-root-ed25519, Incus mTLS certs, the sops master age key.