Compare commits

..
Author SHA1 Message Date
notplantsandClaude Fable 5.1 62a927c552 sops: the combined cc-ci host's ssh host key is a recipient (secrets submodule bumped)
continuous-integration/drone/push Build is failing
cc-ci-secrets now encrypts to the new host (195.201.88.249) via its own
ssh-host-key-derived age identity, like the canonical cc-ci did, so the
off-box master recovery key no longer has to live on that box —
/var/lib/sops-nix/key.txt there holds the host-derived identity instead.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FqkQq3CDmFWcQ7u1LzoyRz
2026-09-07 21:30:49 +00:00
3 changed files with 67 additions and 72 deletions
+2
View File
@@ -5,10 +5,12 @@
# /srv/cc-ci/.sops/master-age.txt (never in this repo). Lets us re-key if cc-ci is lost. # /srv/cc-ci/.sops/master-age.txt (never in this repo). Lets us re-key if cc-ci is lost.
keys: keys:
- &host age1h90utdztfc23kx8ewrtrtk80mnddvrf8pg4ppej55rwwwupzhfvqhmp3qa - &host age1h90utdztfc23kx8ewrtrtk80mnddvrf8pg4ppej55rwwwupzhfvqhmp3qa
- &host2 age1tmvgpgc822ezqgxg4x8h6ndph6j9hwpgjpg364zn7lw3t5h694rq5730wa
- &master age1cmk26t9e30ls8594s8txgmf2exenydmntfxqpcd3qdqm3ru2lpnqpdkdz9 - &master age1cmk26t9e30ls8594s8txgmf2exenydmntfxqpcd3qdqm3ru2lpnqpdkdz9
creation_rules: creation_rules:
- path_regex: secrets/.*\.(yaml|json|env)$ - path_regex: secrets/.*\.(yaml|json|env)$
key_groups: key_groups:
- age: - age:
- *host - *host
- *host2
- *master - *master
+7 -14
View File
@@ -60,24 +60,18 @@ in
environment.etc."acme-dns/lego.env".source = legoEnvironment; environment.etc."acme-dns/lego.env".source = legoEnvironment;
# The staging order has completed successfully. This marker permits the
# production ACME post-run hook to hand a renewed certificate to Traefik.
systemd.tmpfiles.rules = [
"f /var/lib/ci-certs/acme-production-enabled 0600 root root -"
];
networking.firewall = { networking.firewall = {
allowedTCPPorts = [ 53 ]; allowedTCPPorts = [ 53 ];
allowedUDPPorts = [ 53 ]; allowedUDPPorts = [ 53 ];
}; };
systemd.services.acme-dns = {
# One `systemd` attrset (statix W20): the tmpfiles marker, the acme-dns daemon and the
# traefik handoff oneshot.
systemd = {
# The staging order has completed successfully. This marker permits the
# production ACME post-run hook to hand a renewed certificate to Traefik.
tmpfiles.rules = [
"f /var/lib/ci-certs/acme-production-enabled 0600 root root -"
];
services.acme-dns = {
description = "Restricted authoritative DNS for cc-ci ACME DNS-01"; description = "Restricted authoritative DNS for cc-ci ACME DNS-01";
wantedBy = [ "multi-user.target" ]; wantedBy = [ "multi-user.target" ];
after = [ "network-online.target" ]; after = [ "network-online.target" ];
@@ -106,7 +100,7 @@ in
# Traefik consumes its wildcard as immutable Swarm secrets, so a renewed # Traefik consumes its wildcard as immutable Swarm secrets, so a renewed
# host certificate must be copied and reconciled rather than merely reloaded. # host certificate must be copied and reconciled rather than merely reloaded.
# This service is started only by the production-mode ACME postRun hook. # This service is started only by the production-mode ACME postRun hook.
services.cc-ci-acme-traefik-handoff = { systemd.services.cc-ci-acme-traefik-handoff = {
description = "Install renewed cc-ci wildcard into Traefik Swarm secrets"; description = "Install renewed cc-ci wildcard into Traefik Swarm secrets";
after = [ "docker.service" "deploy-proxy.service" ]; after = [ "docker.service" "deploy-proxy.service" ];
requires = [ "docker.service" ]; requires = [ "docker.service" ];
@@ -140,7 +134,6 @@ in
while IFS= read -r stale; do docker secret rm "$stale" || true; done while IFS= read -r stale; do docker secret rm "$stale" || true; done
''; '';
}; };
};
security.acme = { security.acme = {
acceptTerms = true; acceptTerms = true;
+1 -1
Submodule secrets updated: 2ce5f86c02...638c28dae8