Files
ngit-grasp/nix/example-configuration.nix
DanConwayDev 22bbd48537 docs(deploy): add host-specific production paths
The production guide was NixOS-only despite presenting itself as the general deployment entry point, and its examples referenced an unavailable GitHub source and a hardening control the module does not set.

Turn the entry point into an environment chooser, preserve the corrected NixOS material in its own guide, add a hardened generic systemd unit and repeatable Linux installation, document the preferred unprivileged Proxmox layout, and update repository navigation and architecture references.

Each path assumes the shared deployment contract from the container change. Kubernetes automation, remote host mutation, and changes to the existing NixOS module are deliberately excluded.

Validated the canonical Git remote with git ls-remote, parsed and scored the systemd unit with systemd-analyze, checked all new deployment-guide links, removed trailing whitespace, scanned the staged diff for key-shaped nsec values, and ran git diff --check.
2026-08-20 19:38:04 +00:00

140 lines
4.5 KiB
Nix

# Example NixOS configurations using ngit-grasp module
#
# Usage:
# 1. Add to your server's flake.nix inputs:
# inputs.ngit-grasp.url =
# "git+https://gitnostr.com/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git";
#
# 2. Import the module in your configuration:
# imports = [ inputs.ngit-grasp.nixosModules.default ];
#
# 3. Configure one or more instances (examples below)
{ inputs, ... }:
{
imports = [ inputs.ngit-grasp.nixosModules.default ];
# ============================================================================
# EXAMPLE 1: Single Instance Configuration
# ============================================================================
services.ngit-grasp.production = {
enable = true;
domain = "ngit.danconwaydev.com";
# Network
bindAddress = "127.0.0.1";
port = 8082;
# Trust forwarding headers only from the loopback Caddy connection.
# Keep this empty if ngit-grasp is directly exposed.
trustedProxyCidrs = [ "127.0.0.1/32" ];
# Storage
dataDir = "/persistent/ngit-danconwaydev-com-ngit-grasp";
# Identity
relayName = "DanConwayDev's ngit-grasp";
relayDescription =
"personal instance of ngit-grasp, a Rust GRASP implementation with proactive sync";
# Option 1: Use a runtime secret file (recommended). The module loads it
# as a systemd credential, keeping the nsec out of the process command line.
relayOwnerNsecFile = "/run/agenix/ngit-grasp-relay-owner-nsec";
# Option 2: Inline nsec (less secure, ends up in nix store)
# relayOwnerNsec = "nsec1...";
# Option 3: Auto-generate (default if neither above is set)
# ngit-grasp will create .relay-owner.nsec in dataDir automatically
# Sync
syncBootstrapRelayUrl = "wss://relay.ngit.dev";
# Metrics
metricsEnabled = true;
# Logging
logLevel = "info"; # Options: trace, debug, info, warn, error
};
# Caddy reverse proxy for production instance
services.caddy.virtualHosts."ngit.danconwaydev.com" = {
extraConfig = ''
reverse_proxy 127.0.0.1:8082 {
# Caddy manages X-Forwarded-For automatically.
header_up X-Real-IP {remote_host}
}
'';
};
# ============================================================================
# EXAMPLE 2: Multiple Instances on Same Server
# ============================================================================
# Uncomment to run multiple instances:
# # Production instance
# services.ngit-grasp.prod = {
# enable = true;
# domain = "ngit.example.com";
# port = 8082;
# dataDir = "/persistent/ngit-production";
# relayName = "Production GRASP Relay";
# syncBootstrapRelayUrl = "wss://relay.ngit.dev";
# logLevel = "info";
# };
#
# # Testing/staging instance
# services.ngit-grasp.staging = {
# enable = true;
# domain = "ngit-staging.example.com";
# port = 8083;
# dataDir = "/persistent/ngit-staging";
# relayName = "Staging GRASP Relay";
# syncBootstrapRelayUrl = "wss://relay.ngit.dev";
# logLevel = "debug"; # More verbose logging for testing
# };
#
# # Development instance with in-memory database
# services.ngit-grasp.dev = {
# enable = true;
# domain = "localhost";
# bindAddress = "127.0.0.1";
# port = 8084;
# dataDir = "/tmp/ngit-dev";
# databaseBackend = "memory"; # No persistence
# relayName = "Development GRASP Relay";
# metricsEnabled = false;
# logLevel = "trace"; # Maximum verbosity for debugging
# };
#
# # Caddy configuration for multiple instances
# services.caddy.virtualHosts = {
# "ngit.example.com" = {
# extraConfig = "reverse_proxy 127.0.0.1:8082";
# };
# "ngit-staging.example.com" = {
# extraConfig = "reverse_proxy 127.0.0.1:8083";
# };
# };
# ============================================================================
# NOTES
# ============================================================================
# Instance names (e.g., "production", "prod", "staging") can be anything.
# They are used for:
# - systemd service names: ngit-grasp-<name>
# - default user names: ngit-grasp-<name>
# - default data directories: /var/lib/ngit-grasp-<name>
# Systemd service management:
# systemctl status ngit-grasp-production
# systemctl restart ngit-grasp-staging
# journalctl -u ngit-grasp-prod -f
# Each instance runs as a separate user but shares the same group by default.
# You can customize user/group per instance if needed.
}