From 07112f1a4caac043e3cde5ecdf1b4df6e3ae89d6 Mon Sep 17 00:00:00 2001 From: Aner Zakobar Date: Sun, 26 Jul 2026 01:19:25 +0300 Subject: [PATCH] backup: 2026-07-26 01:19 --- homey.org | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/homey.org b/homey.org index 9f7ac58..2a9e8f4 100644 --- a/homey.org +++ b/homey.org @@ -92,10 +92,14 @@ Attic: writing ephemeral TOML config via =ExecStartPre= shell script to =/run/at First deployment of a new container pulls the image during =nixos-rebuild switch=, which can block the activation for several minutes (e.g. stirling-pdf ~2 GB image took ~6 min on Pi). This is expected — not a hang. +SSH lockout recovery: =/etc/ssh/authorized_keys.d/admin= is OVERWRITTEN on every boot by NixOS activation (from the current system generation's Nix store). Manual edits to that file do not survive a reboot. To recover without a valid key: pull SD card, mount root partition (label =NIXOS_SD=), write the new public key to =/home/admin/.ssh/authorized_keys= (permissions: =.ssh/= 700, =authorized_keys= 600, owner UID 1000). This file is NOT managed by activation and survives reboots. Remove it after deploying the updated NixOS config. + +Admin SSH key is GPG-backed via YubiKey. Current key: =~/.ssh/gpg-as-ssh.pub= (=openpgp:0x13E0C25D=, =cardno:29_109_265=). SSH client config uses =IdentityAgent ${XDG_RUNTIME_DIR}/gnupg/S.gpg-agent.ssh=. Old broken YubiKey was =cardno:24_758_470= — its private =[A]= subkey material was never exported (flash drive backup contains stubs only). + ** Key Files - =flake.nix= — module list, =mkHost= builder, =homeyConfig= specialArgs, =rpi4Headless= hardware snippet -- =hosts/pi-main/default.nix= — enabled services, static IP, WiFi, reliability hardening, Attic substituter config +- =hosts/pi-main/default.nix= — enabled services, static IP, WiFi, reliability hardening, Attic substituter config, admin SSH key - =shells/defaultShell.nix= — dev shell with =homey-deploy-rpi-main= and other helper commands - =modules/caddy.nix= — =virtualHosts= option, dual vhost generation, Authelia forward_auth snippet - =modules/services/authelia.nix= — access control rule rendering, =accessControlRules= option (unconditional) @@ -106,6 +110,8 @@ First deployment of a new container pulls the image during =nixos-rebuild switch - =modules/common.nix= — Nix settings, podman network creation, sops global config - =modules/storage.nix= — external HD mount, =extraDirs= option - =modules/backup.nix= — Restic, pre/post hooks, =extraPaths= option +- =scripts/ssh-with-gpg-key.sh= — emergency SSH via GPG key file; sets up ephemeral GNUPGHOME and uses =[A]= subkey + ** TODOs *** TODO Enable chunked uploads to ATTIC @@ -117,7 +123,7 @@ Should be able to do this #+begin_src toml [store] -# Enable the chunk‑aware upload handler +# Enable the chunk-aware upload handler enableChunkedUpload = true # Optional: limit the size of each chunk (default 10 MiB) maxChunkSize = 5_000_000 # 5 MiB per chunk