pull down to refresh

Started a blog about practical digital sovereignty. Self-hosting, homelab, Linux, that kind of thing. This is the first post.

Short version: I was tired of setting up the same Linux desktop by hand, so a coding agent now writes the machine's NixOS config. It has never logged into the laptop though. It works from a container with no route to the machine and pushes branches to my Forgejo with a token that can't merge. I review the diff and apply it myself. If it breaks something, the previous generation is still in the boot menu.

Basically the same trust model as holding your own keys. Don't ask the agent to behave, make the dangerous action impossible.

There's a second post up too, about self-hosting email. Happy to answer questions about either setup.

Secrets need care.

Integrate sops - also available on nixpkgs. I run this myself combined with Hashicorp Vault and Keycloak, which is probably overkill for your setup, but you can easily run it with gpg or age too.

reply

Thanks. I've bumped into it already and it's definitely something I want to explore.

I have big plans for my homelab and infra I manage. With NixOS, I fell in love with having things declarative, so the plan is gitops with flux and k3s. Also more topics to write about.

reply

truly end-to-end secure automated provisioning was still a pain in the butt with k3s last time I tried (early this year) but that's mostly because cousin k8s is bloated and they try to simplify it (and then take insecure shortcuts.) I haven't done true manual provisioning since terraform was launched so I'm always holding things against what I have, which is painful at times haha.

Maybe now that some more projects have matured, the time has come to look at it again.

reply

I'll go through it for the first time soon myself. Excited to see how it goes.

reply

This is the greatest unlock for Linux and probably most of Open source. AI plus open source. Feels like a whole new technology stack

reply
34 sats \ 1 reply \ @LightOfBitcoin 24 Sep -130 sats

Honestly, I like the idea of letting the agent do the boring stuff without giving it the keys to the machine.