Files
ngit-grasp/deploy/systemd/ngit-grasp.env.example
T
DanConwayDev 22bbd48537 docs(deploy): add host-specific production paths
The production guide was NixOS-only despite presenting itself as the general deployment entry point, and its examples referenced an unavailable GitHub source and a hardening control the module does not set.

Turn the entry point into an environment chooser, preserve the corrected NixOS material in its own guide, add a hardened generic systemd unit and repeatable Linux installation, document the preferred unprivileged Proxmox layout, and update repository navigation and architecture references.

Each path assumes the shared deployment contract from the container change. Kubernetes automation, remote host mutation, and changes to the existing NixOS module are deliberately excluded.

Validated the canonical Git remote with git ls-remote, parsed and scored the systemd unit with systemd-analyze, checked all new deployment-guide links, removed trailing whitespace, scanned the staged diff for key-shaped nsec values, and ran git diff --check.
2026-08-20 19:38:04 +00:00

16 lines
565 B
Bash

# Required canonical public hostname, without a scheme or path.
NGIT_DOMAIN=ngit.example.com
NGIT_BASE_PATH=/
NGIT_BIND_ADDRESS=127.0.0.1:7334
NGIT_GIT_DATA_PATH=/var/lib/ngit-grasp/git
NGIT_RELAY_DATA_PATH=/var/lib/ngit-grasp/relay
NGIT_DATABASE_BACKEND=lmdb
NGIT_LOG_LEVEL=info
# Optional initial relay. Sync discovers additional relays automatically.
# NGIT_SYNC_BOOTSTRAP_RELAY_URL=wss://relay.ngit.dev
# Prefer /var/lib/ngit-grasp/.relay-owner.nsec or a systemd credential over an
# environment secret. Never put NGIT_RELAY_OWNER_NSEC in this example file.