NixOS agenix Secrets
A public-safe pattern for keeping real service credentials out of the repo while still fitting a rebuildable NixOS host.
Neat infrastructure for the home
Declarative service design, maintainable automation, and self-hosting patterns with less operational drift.
A public-safe pattern for keeping real service credentials out of the repo while still fitting a rebuildable NixOS host.
A rebuild-first pattern for adding one real service to a NixOS host with explicit state, env placeholders, validation, and backup scope.
A small NixOS baseline with flakes, key-only SSH, firewall defaults, fail2ban, and rebuild checks.