# cc-ci on Hetzner Cloud — the canonical STANDALONE CI-server host. # Hardware + networking + host identity only; every cc-ci service comes from the shared # `nixosModules.cc-ci-server` module (nix/modules/default.nix), which flake.nix adds to this # host. The same module builds the combined CI-server + orchestrator host declared in # recipe-maintainers/cc-ci-orchestrator (`#cc-ci`), which is where cc-ci is moving (2026-09). # # To apply after `terraform apply` + nixos-infect: # git clone --recursive https://git.autonomic.zone/recipe-maintainers/cc-ci.git /etc/cc-ci # install -m600 /var/lib/sops-nix/key.txt # nixos-rebuild switch --flake 'git+file:///etc/cc-ci?submodules=1#cc-ci' { pkgs, ... }: { imports = [ ./hardware.nix ./networking.nix ]; # This host's public address: acme-dns listens on it and publishes it as the ns-acme glue. cc-ci.publicIPv4 = "91.98.47.73"; # Built from a --recursive clone, so the sops file is the default (the secrets/ submodule). # Tailscale — keeps the orchestrator→cc-ci access path unchanged (direct peer). # On the Hetzner host the auth key is also seeded via /etc/ts-auth-key. services.tailscale = { enable = true; authKeyFile = "/etc/ts-auth-key"; extraUpFlags = [ "--hostname=cc-ci" ]; }; # SSH — allow root login over tailscale (same as Incus host). services.openssh = { enable = true; settings.PermitRootLogin = "yes"; }; # Root SSH authorized keys — preserved across nixos-rebuild switches. # 2026-09-28: synced to the live /root/.ssh/authorized_keys on cc-ci (which had drifted: # several keys had been added manually and would have been wiped by the next rebuild). # Claude-sandbox keys removed at operator request; new `nptest` and # `notplants-orchestrator` keys added. users.users.root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGZGp/DQTFuD1GvsyTzCVBUTmoWqcb5T+Z7zZo5nYLXO" "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDhgo41nt8/L+Cr0PKd8jQK45mw/A+h041j6LQ8JWZisEVaQOzr6s9rxPL8VT5ML4P3/4bMblzdDiXWlJxymcb+yk5S5TnVrMavzHEDhWHwEvTRMe6xNTmsU6cmmhRw7PJqqQ+0GTlQalu3I4jkC0kTF7kuPwduUOgUuSpJqxvDTwYiXoyVnOQHAIygh+BmQvYUz0PBfQgIhgcbYmGZ++T0DnMzdGFzW2UB/iy5mymnpmbaZCgLy0w8AoDE+0YLtUc4gwTXc183nvqO1i7LQr+3jBYkv5ZthCCc52vXFHDSw9xZ5ohsOrBvoi5foRbqinmU5/t0aTK7SSrat7xXm/odIOyS+S7PJyeEcsXN6d5zdxbabAy5vLfodEaKGZd4rqQeDCxOTPAS/BlrBV/EV714n4E+fSOAllAuMBO4IibJM/gLJrh2Dql3co50QW9HEDeSC7iqp2lxRBDxvUs3rIEzy7o4HSN8chqBUK1bbBY6B17fuNHIpBAw4akRVVvPnVM= trav@trav480sweet" "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC6jrKj7iZUNRLBTZG0vZM1D/BXtARhhB4+GrvpyuqmPb9iw2ifT9YqRUwgyGrOW9U6nIAR9yFnfp9+FkyhEKWByqEBbe/zYKlGLRGjfsIdDdW29QQ3hvmqNyboCkXLxZGat93poYhnoomqicmGD/xST4s0OUhcK9E494lUmenlD9dcMZW1aKpJ+9O4Dq6A7nk2z1e4KFcZdrZDI2Hgg+gfEdsKZQqd/R3Mls/eVKpzhfv3Y8BiNoHssUChVf8IGESqTOBOR7Dk7FsU5Z2ZcnQ1coxY7VlBn4fPjTWmz/Ac0jLqgcpCLpNyQzFPDVMYZKYrPVoqBeKVhN5YnfwR5OVP8YsakT/obLwC43sx/esXfjhVGcsRoGpiLOfazzNw/eC8s6FlS8cesOubEM37a7F25z4UEG3d487oM7EjQ39gBCCj/KRgUimCKMWsm6yIas4OSctBWEAo/NhZp0gwulSRxleW6eJCNNwzOmWjdzYIVWoVP0EIeM95Tq8PVUN7gpc= aadil@t480" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMyHSi12R0+HCVBz7+d9fyOBnoJi8Nsj5D7vQ9UQO8a5" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJVlfoLBPseQ9fA9534KmRg2KWcksKZGzAJIpHJ2JpsI mfowler.email@protonmail.com" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHOcLo0YBa0UYi7i/l8K/Y/7cF2OclmDqSTlAsHM0dOS notplants-orchestrator-ed25519" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMniNzAzuI527bfk/EipqFILFayUCwYXDoZ3R7+QgYq6" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKmGDZC6wrOQNJAW5PPDpxgEXXrcsnIU4b3QJLtq05RQ cc-ci-loops-to-root@cc-ci" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIONhAh8/jjH8v8AOZIlzL8yyNyb5VihefIEkaHschoJy nptest" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHIa8iunWtA4mqLKV6MuiTo3RkVj2ucsk3gLL4ArMEPO notplants-orchestrator" ]; # Firewall — Hetzner has a public IP, so open 80+443 for Traefik. # Tailscale interface is trusted (no port restrictions for orchestrator access). # Plan §6: v1 keeps the sops wildcard cert; evaluate ACME-on-public-IP as follow-up. networking.firewall = { enable = true; trustedInterfaces = [ "tailscale0" ]; allowedTCPPorts = [ 22 80 443 ]; }; # The recipe-test tool set (ccciRuntimeTools) is installed by the cc-ci-server module; the ssh # client is a host-only addition (not part of the recipe-test tool set). environment.systemPackages = [ pkgs.openssh ]; system.stateVersion = "24.11"; }