Fleet integration: deploy sovrn from ~/projects/servers

closed
#ae42c89 opened by agent Oct 6

All hosts are now deployed from one Colmena fleet in ~/projects/servers (plan: ~/projects/servers/docs/fleet-migration-plan.md, Phase 4). It composes several projects on one machine; infra.mymood.at (netcup) already runs moods there and will also run sovrn’s metrics box and backup relay. sovrn exports NixOS modules; the fleet owns hosts, inventory, disk, boot, network and deploys.

Decisions (2026-10-06, user): - Every deployment comes from the servers repo. sovrn’s Justfile.nix and Justfile keep dev/test/build recipes; host recipes become stubs that call just -f ../servers/Justfile … or print where things live. - Rotate the fleet OIDC key and OAuth attestation key first (3418287 recorded both leaking to a terminal; nothing uses them yet).

Work: 1. Rotate sovrn/shared/oidc-key.pem and sovrn/shared/oauth-attestation.key (go run ./cmd/gensecrets into a temp dir, encrypt into the store, remove the temp dir). Check nothing outside the store pins the old public halves. 2. Options instead of specialArgs: fleet → sovrn.fleet (defaults from nix/fleet.nix); host.name → config.networking.fqdn; host.pdsOriginSuffix → sovrn.cell.pdsOriginSuffix. (moods also had a fleet specialArg with a different meaning, so both can’t coexist on one host.) 3. Hostnames as options: sovrn.metrics.hostname (infra.sovrn.at), sovrn.relay.hostname (mxb.eu.sovrn.at). The shared box’s own name is infra.mymood.at. 4. Prefix Colmena key attributes sovrn- (file names unchanged); replace the hard-coded *-key.service names in roles/metrics.nix with a .unit attribute; metrics and relay must fit on one host. 5. services.caddy.email → mkDefault (one value per host). 6. Export nixosModules.services, .metrics, .cell (.relay, .telemetryEdge as they land), each bringing the overlay. 7. Roles come from the fleet’s hosts.json, not hostname regexes. 8. Per-role host-secret generators exposed from the flake for the fleet’s gen-host-secrets. 9. Host recipes in Justfile.nix (new-host, known-hosts, deploy, gen-host-secrets, check-secrets, ci-staging) become stubs.

Done when the VM tests (cell, stalwart, metrics) and stalwart-plan pass, the fleet evaluates sovrn roles, and the keys are rotated.

2 Comments

agent a4e64d2 Oct 6

Done (2026-10-06), pending your review

  1. Keys rotated: new sovrn/shared/oidc-key.pem and oauth-attestation.key (gensecrets); leaked copies renamed *.age.leaked-2026-10-06 in the store. Details on 3418287. 2–6. sovrn (wwzzsxmw): nix/modules/options.nix (sovrn.fleet = fleet.nix + overrides, sovrn.cell.hostname / pdsOriginSuffix, sovrn.metrics.hostname) replaces the fleet/host specialArgs in the cell/metrics roles, cell edge and secrets; nix/modules/services.nix split from base.nix; Colmena key attributes/units prefixed sovrn- with a .unit attribute (files unchanged); Caddy email mkDefault; flake exports nixosModules.services, .metrics, .cell.
  2. Roles now come from the fleet’s hosts.json (sovrn-cell, sovrn-metrics).
  3. apps.gen-secret (nix/scripts/gen-secret.sh) holds the per-host generators; the fleet’s just gen-host-secrets calls it.
  4. Justfile.nix host recipes forward to the fleet (loyrlypn); just -f Justfile.nix fleet explains the layout; deploy keeps the uncommitted-UI-assets guard.

Before this, the uncommitted cell data plane work (63eb0d9) was given its own change, oxswkpoq “cell data plane on NixOS (63eb0d9, pending review)”; go test and all checks passed on it.

Verified: checks.cell / stalwart / metrics and stalwart-plan pass. The options move leaves the test nodes’ systems identical apart from the order of tmpfiles rules. In the fleet (evaluated, nothing deployed): moods + sovrn-metrics on infra.mymood.at merge cleanly; a throwaway sovrn-cell host evaluates, with hostname and PDS suffix from the inventory; sovrn-cell next to another role fails the exclusive assertion; DRY=1 just gen-host-secrets for mx99 lists exactly the missing values.

Open for later phases: the relay module export (b45a76f), telemetry edge (a6edca3).

agent a2e5412 Oct 8

Closing (user, 2026-10-08): done. sovrn is deployed only from the fleet (~/projects/servers); roles from the inventory; keys rotated; host recipes are stubs forwarding to the fleet.