nix: export the CI server as nixosModules.cc-ci-server
continuous-integration/drone/push Build is failing

The whole server (every service module, the harness tooling, sops wiring,
acme-dns) becomes one reusable module, nix/modules/default.nix, so another
flake can run cc-ci on a host it defines. First consumer: the
cc-ci-orchestrator repo's `#cc-ci` host, which runs the CI server and the
orchestrator together on one Hetzner machine.

Two things the modules hard-coded become options (nix/modules/options.nix):
- cc-ci.publicIPv4 — acme-dns's listen address and ns-acme glue record.
- cc-ci.sopsFile — the secrets.yaml path; defaults to the secrets/ submodule,
  but a consumer that imports cc-ci as a plain input (no private submodule)
  points it at the deployed --recursive checkout and sops-nix reads it at
  activation (validateSopsFiles off for that case).

The standalone host (nix/hosts/cc-ci-hetzner) now only carries hardware,
networking and identity and imports the module via the flake. Verified: the
`#cc-ci` system derivation is byte-identical before and after
(/nix/store/ckp1244bz86fz3qbx81n5kx60c1lak3m-…531670d.drv on both).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
This commit is contained in:
2026-09-07 19:56:58 +00:00
co-authored by Claude Fable 5.1
parent 769fd29dcf
commit 9b99f81f5f
6 changed files with 118 additions and 40 deletions
+8 -1
View File
@@ -6,8 +6,15 @@
# off-box master recovery key).
{ config, ... }:
{
imports = [ ./options.nix ];
sops = {
defaultSopsFile = ../../secrets/secrets.yaml;
# See options.nix: the submodule path by default; an absolute host path on a combined host
# that imports cc-ci as a flake input without the private submodule.
defaultSopsFile = config.cc-ci.sopsFile;
# sops-nix validates store-path sops files at build time. An absolute (string) path is read
# at activation instead, so validation has to be off for that case.
validateSopsFiles = builtins.isPath config.cc-ci.sopsFile;
# Decrypt using the host's SSH host key (converted to an age identity by sops-nix).
age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
# Phase-1c: also accept a bootstrap age key at a fixed path — THE one out-of-band secret,