Skip to content

Commit 7e6db42

Browse files
stackptrclaude
andauthored
feat: centralize PostgreSQL on glyph (#359)
* feat: centralize PostgreSQL on glyph Move PostgreSQL from spore to glyph so all databases are on the host with the best hardware (i7-13700K, NVMe, ZFS). This also fixes the atticd SQLite connection pool timeout under concurrent CI pushes by switching to PostgreSQL. - Add PostgreSQL 16 on glyph with atticd and pocketid databases - Switch atticd from SQLite to PostgreSQL - Add databaseURL and localDatabase options to rc.web.auth module - Configure pocket-id on spore to connect to glyph via Tailscale - Disable PostgreSQL on spore - Move database backups from spore to glyph Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: remove owner/group from attic-credentials secret atticd uses DynamicUser so the atticd user doesn't exist during activation when agenix decrypts secrets. Default to root:root — systemd reads the EnvironmentFile as root before dropping privileges. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: use lib in spore backup module to satisfy statix and NixOS args Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix: update Attic cache public key after PostgreSQL migration The signing keypair was regenerated when the cache was recreated on the new PostgreSQL backend. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * refactor: remove redundant postgresql dependency from atticd The atticd NixOS module already detects local PostgreSQL from the database URL (checks for /run/postgresql) and adds the systemd after/requires dependencies automatically. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * refactor: remove unused db.nix and backup.nix from spore PostgreSQL and database backups have moved to glyph. These files were left as stubs and are no longer needed. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
1 parent 733436c commit 7e6db42

11 files changed

Lines changed: 66 additions & 58 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ jobs:
3131
github_access_token: ${{ secrets.GITHUB_TOKEN }}
3232
extra_nix_config: |
3333
extra-substituters = https://cache.zx.dev/main
34-
extra-trusted-public-keys = main:sbkS1Xz6P4g66iyttRGj/o8aPODE6bVG9oKT98/ULKI=
34+
extra-trusted-public-keys = main:mu0jkxdJTGWC3djDSEQb3rvZgqlhA8WVMulcTo5IW6c=
3535
- name: Configure Attic cache
3636
run: |
3737
nix profile install --inputs-from . attic#attic-client

‎flake.nix‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -122,7 +122,7 @@
122122
"https://cache.zx.dev/main"
123123
];
124124
extra-trusted-public-keys = [
125-
"main:sbkS1Xz6P4g66iyttRGj/o8aPODE6bVG9oKT98/ULKI="
125+
"main:mu0jkxdJTGWC3djDSEQb3rvZgqlhA8WVMulcTo5IW6c="
126126
];
127127
};
128128
};

‎hosts/glyph/services/attic.nix‎

Lines changed: 2 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,5 @@
11
{config, ...}: {
2-
age.secrets.attic-credentials = {
3-
file = ./../secrets/attic-credentials.age;
4-
mode = "440";
5-
owner = "atticd";
6-
group = "atticd";
7-
};
2+
age.secrets.attic-credentials.file = ./../secrets/attic-credentials.age;
83

94
services.atticd = {
105
enable = true;
@@ -13,7 +8,7 @@
138
settings = {
149
listen = "[::]:8199";
1510

16-
database.url = "sqlite:///var/lib/atticd/server.db?mode=rwc";
11+
database.url = "postgresql:///atticd?host=/run/postgresql";
1712

1813
storage = {
1914
type = "local";
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,9 @@
1-
{
2-
config,
3-
pkgs,
4-
...
5-
}: {
1+
{pkgs, ...}: {
62
services.postgresql = {
73
enable = true;
84
package = pkgs.postgresql_16;
95
enableTCPIP = true;
106
authentication = pkgs.lib.mkOverride 10 ''
11-
# Any user can connect to any database via Unix socket, local loopback,
12-
# or Tailscale
137
local all all trust
148
host all all 127.0.0.1/32 trust
159
host all all 100.64.0.0/10 trust
@@ -18,5 +12,21 @@
1812
port = 5432;
1913
max_connections = 150;
2014
};
15+
ensureDatabases = ["atticd" "pocketid"];
16+
ensureUsers = [
17+
{
18+
name = "atticd";
19+
ensureDBOwnership = true;
20+
}
21+
{
22+
name = "pocketid";
23+
ensureDBOwnership = true;
24+
}
25+
];
26+
};
27+
28+
services.postgresqlBackup = {
29+
enable = true;
30+
databases = ["atticd" "pocketid"];
2131
};
2232
}

‎hosts/glyph/services/default.nix‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,7 @@
55
}: {
66
imports = [
77
./attic.nix
8+
./db.nix
89
./avahi.nix
910
./dns.nix
1011
./filebrowser.nix
@@ -85,7 +86,7 @@
8586
rc.backup = {
8687
enable = true;
8788
paths = [
88-
"/var/lib/atticd/server.db"
89+
config.services.postgresqlBackup.location
8990
"/var/lib/basic-memory"
9091
"/var/lib/open-webui"
9192
"/var/lib/roon-server/backup"

‎hosts/spore/backup.nix‎

Lines changed: 0 additions & 8 deletions
This file was deleted.

‎hosts/spore/default.nix‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,6 @@
99
(modulesPath + "/installer/scan/not-detected.nix")
1010
(modulesPath + "/profiles/qemu-guest.nix")
1111
./disk-config.nix
12-
./backup.nix
1312
./services
1413
];
1514

‎hosts/spore/services/default.nix‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,6 @@
44
...
55
}: {
66
imports = [
7-
./db.nix
87
./grafana.nix
98
./homepage-dashboard.nix
109
./mastodon.nix

‎hosts/spore/services/mastodon.nix‎

Lines changed: 2 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ in {
4848
configureNginx = true;
4949
database = {
5050
createLocally = false;
51-
host = "127.0.0.1";
51+
host = "glyph.rove-duck.ts.net";
5252
port = 5432;
5353
user = "mastodon";
5454
passwordFile = "/dev/null"; # Not needed
@@ -84,19 +84,7 @@ in {
8484
];
8585
};
8686

87-
services.postgresql = lib.mkIf enable {
88-
ensureUsers = [
89-
{
90-
name = "mastodon";
91-
ensureDBOwnership = true;
92-
}
93-
];
94-
ensureDatabases = ["mastodon"];
95-
};
96-
services.postgresqlBackup = {
97-
#inherit enable;
98-
databases = ["mastodon"];
99-
};
87+
# Database managed on glyph when re-enabled
10088
services.redis.servers.mastodon = {
10189
inherit enable;
10290
port = 31637;

‎hosts/spore/services/web/auth.nix‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,8 @@
2222
host = "id.zx.dev";
2323
useACMEHost = "zx.dev";
2424
encryptionKeyFile = config.age.secrets.pocket-id-encryption-key.path;
25+
databaseURL = "postgres://pocketid@glyph.rove-duck.ts.net/pocketid";
26+
localDatabase = false;
2527
};
2628
authProxy = {
2729
host = "oauth.zx.dev";

0 commit comments

Comments
 (0)