Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

nixdev — Development & CI

Purpose

nixdev is the development and CI host. It runs the self-hosted development services: continuous integration, Coder workspace platform, workflow automation, a Docker registry, and a forgesync mirror job.

Entry Point

Architecture / Services / Scope

CI / Automation

  • Woodpecker CI: Self-hosted CI server + local Docker-backed agent, supporting GitHub and Codeberg forges. Served on its own vhost with a separate gRPC agent endpoint.
  • GitHub Actions runners: A pool of 10 self-hosted nixos-runner-* runners for the nix-config repo.

Workspaces

  • Coder: Self-hosted development workspaces, backed by the Docker daemon. Coder users are granted Docker access.

Workflow Automation

  • n8n: Workflow automation with task runners, backed by PostgreSQL and Redis on the Database Coordinator.

Registry & Mirroring

  • Docker Registry: Self-hosted OCI registry storing images on the Storage Coordinator, with htpasswd auth.
  • Forgesync: Mirrors repositories between Codeberg and GitHub on a daily schedule.

Secrets

Declared secrets

Secret keyPurpose
GITHUB_TOKENToken for the self-hosted runners
POSTGRES/N8N_PASSWORDn8n database password
POSTGRES/CODER_PASSWORDCoder database password
POSTGRES/WOODPECKER_PASSWORDWoodpecker database password
POSTGRES/WINDMILL_PASSWORDWindmill database password
REDIS_PASSWORDn8n Redis password
N8N/ENCRYPTION_KEYn8n encryption key
N8N/RUNNER_AUTH_TOKENn8n task runner auth
WOODPECKER/GRPC_SECRETWoodpecker gRPC secret
WOODPECKER/AGENT_SECRETWoodpecker agent secret
WOODPECKER/GITHUB_CLIENT / GITHUB_SECRETGitHub forge OAuth
WOODPECKER/CODEBERG_CLIENT / CODEBERG_SECRETCodeberg forge OAuth
REGISTRY/SECRETRegistry shared secret
REGISTRY/HTPASSWDRegistry auth htpasswd
REGISTRY/S3_ACCESS_KEY / S3_SECRET_KEYS3 storage credentials
FORGESYNC/SOURCE_TOKEN / TARGET_TOKEN / MIRROR_TOKENForgesync tokens

Operational Notes / Assumptions

  • Runs Docker with auto-pruning for workspaces and CI workloads.
  • Woodpecker, n8n, Coder, the registry, and CI are exposed through the IO Coordinator reverse proxy.
  • Databases are provided by the Database Coordinator; n8n and Woodpecker depend on the database availability target.

References