Tobserver/secrets
Tobias Ostner 5753bf9e33 Remove checker service (#9)
## Summary

- Remove the checker NixOS module, including its systemd service, system user/group, SOPS secret declaration, and nginx virtual host.
- Remove the checker flake input and its now-unreachable lock-file dependency graph.

## Validation

- `tobserver-agent check` — passed all formatting, whitespace, no-build flake, strict NixOS assertion/systemd unit, secret-policy, and Gitleaks checks.
- Focused Nix evaluation confirmed the checker service, user, nginx virtual host, and SOPS secret declaration are absent; `flake.lock` no longer contains the checker input.

## Risks and limitations

- Deployment will stop exposing the checker service and nginx virtual host, but existing runtime state, a mutable system user, DNS records, ACME data, and the encrypted checker secret may remain until a human removes them if desired.

## Manual follow-up

- Review and merge this pull request in Codeberg.
- Deploy manually on Tobserver after merge.
- After deployment, verify the checker unit and virtual host are absent; optionally clean up checker DNS, runtime state, user, ACME data, and the encrypted secret through the appropriate human-managed process.

Reviewed-on: https://codeberg.org/oibot/Tobserver/pulls/9
2026-07-28 13:30:17 +02:00
..
.sops.yaml Setup sops 2026-04-11 18:52:36 +02:00
nextcloud-mail.json Setup sops 2026-04-11 18:52:36 +02:00
tobserver.yaml Remove checker service (#9) 2026-07-28 13:30:17 +02:00