Fleet integration: deploy sovrn from ~/projects/servers
closedAll hosts are now deployed from one Colmena fleet in ~/projects/servers (plan: ~/projects/servers/docs/fleet-migration-plan.md, Phase 4). It composes several projects on one machine; infra.mymood.at (netcup) already runs moods there and will also run sovrn’s metrics box and backup relay. sovrn exports NixOS modules; the fleet owns hosts, inventory, disk, boot, network and deploys.
Decisions (2026-10-06, user):
- Every deployment comes from the servers repo. sovrn’s Justfile.nix and Justfile keep dev/test/build recipes; host recipes become stubs that call just -f ../servers/Justfile … or print where things live.
- Rotate the fleet OIDC key and OAuth attestation key first (3418287 recorded both leaking to a terminal; nothing uses them yet).
Work:
1. Rotate sovrn/shared/oidc-key.pem and sovrn/shared/oauth-attestation.key (go run ./cmd/gensecrets into a temp dir, encrypt into the store, remove the temp dir). Check nothing outside the store pins the old public halves.
2. Options instead of specialArgs: fleet → sovrn.fleet (defaults from nix/fleet.nix); host.name → config.networking.fqdn; host.pdsOriginSuffix → sovrn.cell.pdsOriginSuffix. (moods also had a fleet specialArg with a different meaning, so both can’t coexist on one host.)
3. Hostnames as options: sovrn.metrics.hostname (infra.sovrn.at), sovrn.relay.hostname (mxb.eu.sovrn.at). The shared box’s own name is infra.mymood.at.
4. Prefix Colmena key attributes sovrn- (file names unchanged); replace the hard-coded *-key.service names in roles/metrics.nix with a .unit attribute; metrics and relay must fit on one host.
5. services.caddy.email → mkDefault (one value per host).
6. Export nixosModules.services, .metrics, .cell (.relay, .telemetryEdge as they land), each bringing the overlay.
7. Roles come from the fleet’s hosts.json, not hostname regexes.
8. Per-role host-secret generators exposed from the flake for the fleet’s gen-host-secrets.
9. Host recipes in Justfile.nix (new-host, known-hosts, deploy, gen-host-secrets, check-secrets, ci-staging) become stubs.
Done when the VM tests (cell, stalwart, metrics) and stalwart-plan pass, the fleet evaluates sovrn roles, and the keys are rotated.
2 Comments
Done (2026-10-06), pending your review
sovrn/shared/oidc-key.pemandoauth-attestation.key(gensecrets); leaked copies renamed*.age.leaked-2026-10-06in the store. Details on 3418287. 2–6. sovrn (wwzzsxmw):nix/modules/options.nix(sovrn.fleet= fleet.nix + overrides,sovrn.cell.hostname/pdsOriginSuffix,sovrn.metrics.hostname) replaces thefleet/hostspecialArgs in the cell/metrics roles, cell edge and secrets;nix/modules/services.nixsplit from base.nix; Colmena key attributes/units prefixedsovrn-with a.unitattribute (files unchanged); Caddy emailmkDefault; flake exportsnixosModules.services,.metrics,.cell.sovrn-cell,sovrn-metrics).apps.gen-secret(nix/scripts/gen-secret.sh) holds the per-host generators; the fleet’sjust gen-host-secretscalls it.Justfile.nixhost recipes forward to the fleet (loyrlypn);just -f Justfile.nix fleetexplains the layout;deploykeeps the uncommitted-UI-assets guard.Before this, the uncommitted cell data plane work (63eb0d9) was given its own change,
oxswkpoq“cell data plane on NixOS (63eb0d9, pending review)”; go test and all checks passed on it.Verified: checks.cell / stalwart / metrics and stalwart-plan pass. The options move leaves the test nodes’ systems identical apart from the order of tmpfiles rules. In the fleet (evaluated, nothing deployed): moods + sovrn-metrics on infra.mymood.at merge cleanly; a throwaway sovrn-cell host evaluates, with hostname and PDS suffix from the inventory; sovrn-cell next to another role fails the exclusive assertion;
DRY=1 just gen-host-secretsfor mx99 lists exactly the missing values.Open for later phases: the relay module export (b45a76f), telemetry edge (a6edca3).
Closing (user, 2026-10-08): done. sovrn is deployed only from the fleet (~/projects/servers); roles from the inventory; keys rotated; host recipes are stubs forwarding to the fleet.