No description
## Summary - Remove the checker NixOS module, including its systemd service, system user/group, SOPS secret declaration, and nginx virtual host. - Remove the checker flake input and its now-unreachable lock-file dependency graph. ## Validation - `tobserver-agent check` — passed all formatting, whitespace, no-build flake, strict NixOS assertion/systemd unit, secret-policy, and Gitleaks checks. - Focused Nix evaluation confirmed the checker service, user, nginx virtual host, and SOPS secret declaration are absent; `flake.lock` no longer contains the checker input. ## Risks and limitations - Deployment will stop exposing the checker service and nginx virtual host, but existing runtime state, a mutable system user, DNS records, ACME data, and the encrypted checker secret may remain until a human removes them if desired. ## Manual follow-up - Review and merge this pull request in Codeberg. - Deploy manually on Tobserver after merge. - After deployment, verify the checker unit and virtual host are absent; optionally clean up checker DNS, runtime state, user, ACME data, and the encrypted secret through the appropriate human-managed process. Reviewed-on: https://codeberg.org/oibot/Tobserver/pulls/9 |
||
|---|---|---|
| docs | ||
| modules | ||
| secrets | ||
| .gitignore | ||
| configuration.nix | ||
| flake.lock | ||
| flake.nix | ||
| hardware-configuration.nix | ||