No description
  • Nix 67.3%
  • Python 18.7%
  • Shell 9.8%
  • HCL 2.6%
  • HTML 0.7%
  • Other 0.9%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Kiara Grouwstra 11b02de9a0
Some checks failed
checks-api-deploy-env-apex / api-deploy-env-apex (push) Successful in 4s
checks-core-docs / core-docs (push) Successful in 10s
dispatch-sentinel / dispatch-sentinel (push) Successful in 8s
devShells-default / core-default (push) Successful in 25s
nix-unit-components / components (push) Successful in 23s
checks-core-treefmt / core-treefmt (push) Successful in 31s
checks-panel-docs / panel-docs (push) Successful in 29s
checks-api-schema-parity / api-schema-parity (push) Successful in 32s
checks-treefmt / treefmt (push) Successful in 36s
publish-panel / publish-panel (push) Successful in 31s
nix-unit-contracts / contracts (push) Successful in 28s
publish-asyncapi / publish-asyncapi (push) Successful in 33s
checks-deployment-tf-hosts / deployment-tf-hosts (push) Successful in 46s
publish-dns-hosting-provider / publish (push) Successful in 51s
deploy-incus / deploy (push) Successful in 58s
checks-deployment-nixos-hosts / deployment-nixos-hosts (push) Successful in 1m1s
checks-integrations-octodns-bind / integrations-octodns-bind (push) Successful in 59s
publish-swagger / publish-swagger (push) Successful in 47s
nix-unit-render / render (push) Successful in 40s
nixosConfigurations-operator / operator-valkey (push) Successful in 20s
nix-unit-effects / effects (push) Successful in 49s
nixosConfigurations-operator / operator-pixelfed (push) Successful in 24s
devShells-default / root-default (push) Successful in 59s
nix-unit-lib / lib (push) Successful in 53s
nixosConfigurations-dev / dev-forgejo (push) Successful in 1m56s
nixosConfigurations-dev / dev-dev2 (push) Successful in 2m23s
nixosConfigurations-dev / dev-dev3 (push) Successful in 2m45s
nixosConfigurations-hosting-provider / hosting-provider-api (push) Successful in 2m44s
nixosConfigurations-dev / dev-fediversity-ci (push) Successful in 2m44s
checks-integrations-publish-records / integrations-publish-records (push) Successful in 2m59s
nixosConfigurations-hosting-provider / hosting-provider-otel-collector (push) Successful in 3m3s
nixosConfigurations-hosting-provider / hosting-provider-panel (push) Successful in 3m3s
nixosConfigurations-operator / operator-smtp (push) Successful in 2m35s
nixosConfigurations-hosting-provider / hosting-provider-smtp (push) Successful in 3m1s
nixosConfigurations-hosting-provider / hosting-provider-postgresql (push) Successful in 3m2s
checks-deployment-verdict-spawn / deployment-verdict-spawn (push) Successful in 3m7s
nixosConfigurations-operator / operator-mastodon (push) Successful in 2m41s
checks-deployment-tf-hosts-bootstrap / deployment-tf-hosts-bootstrap (push) Successful in 3m43s
nixosConfigurations-hosting-provider / hosting-provider-authelia (push) Successful in 4m33s
deploy-dev2 / deploy (push) Successful in 4m58s
nix-unit-setups / setups (push) Successful in 5m1s
nixosConfigurations-hosting-provider / hosting-provider-bind (push) Successful in 5m22s
checks-deployment-tf-incus-operator / deployment-tf-incus-operator (push) Successful in 5m31s
nixosConfigurations-hosting-provider / hosting-provider-garage (push) Successful in 5m42s
nixosConfigurations-hosting-provider / hosting-provider-spire (push) Successful in 5m33s
nixosConfigurations-hosting-provider / hosting-provider-lldap (push) Successful in 5m43s
nixosConfigurations-operator / operator-authelia (push) Successful in 5m27s
checks-deployment-verdict-chain / deployment-verdict-chain (push) Successful in 6m0s
nixosConfigurations-hypervisor / hypervisor-incus (push) Successful in 5m29s
nixosConfigurations-hosting-provider / hosting-provider-windmill (push) Successful in 5m30s
publish-core / publish-core (push) Successful in 5m59s
nixosConfigurations-hosting-provider / hosting-provider-netbox (push) Successful in 5m58s
flake-show-panel / flake-show-panel (push) Successful in 6m11s
deploy-hosting-provider / deploy (push) Successful in 6m5s
checks-deployment-verdict-failed / deployment-verdict-failed (push) Successful in 6m21s
checks-deployment-tf-incus-hosts / deployment-tf-incus-hosts (push) Successful in 7m24s
checks-integrations-publish-records-named / integrations-publish-records-named (push) Successful in 7m2s
checks-apps-tf / apps-tf (push) Successful in 8m43s
nixosConfigurations-dev / dev-dev4 (push) Successful in 8m59s
checks-deployment-verdict-loop / deployment-verdict-loop (push) Failing after 9m29s
deploy-fediversity-ci / deploy (push) Successful in 9m53s
checks-integrations-apex-key-mint / integrations-apex-key-mint (push) Successful in 10m25s
nixosConfigurations-hosting-provider / hosting-provider-telemetry (push) Successful in 10m4s
deploy-dev4 / deploy (push) Successful in 10m37s
nixosConfigurations-hosting-provider / hosting-provider-terraform-backend (push) Successful in 10m4s
nixosConfigurations-hosting-provider / hosting-provider-valkey (push) Successful in 10m3s
deploy-forgejo / deploy (push) Successful in 10m39s
nixosConfigurations-hosting-provider / hosting-provider-openbao (push) Successful in 10m26s
nixosConfigurations-operator / operator-lldap (push) Successful in 10m17s
flake-show-core / flake-show-core (push) Successful in 10m55s
nixosConfigurations-operator / operator-peertube (push) Successful in 10m15s
checks-deployment-ssh-hosts / deployment-ssh-hosts (push) Successful in 11m0s
nix-unit-testers / testers (push) Successful in 10m29s
deploy-dev3 / deploy (push) Successful in 11m10s
flake-show-api / flake-show-api (push) Successful in 11m11s
Nix flake completeness check / _complete (push) Successful in 11m20s
checks-deployment-ssh-recovery / deployment-ssh-recovery (push) Successful in 11m33s
flake-show-root / flake-show-root (push) Successful in 11m31s
nix-unit-resources / resources (push) Successful in 11m36s
checks-integrations-spire-incus / integrations-spire-incus (push) Successful in 15m43s
checks-apps-api / apps-api (push) Successful in 21m28s
checks-apps-panel / apps-panel (push) Successful in 22m39s
checks-apps-tf-incus / apps-tf-incus (push) Successful in 24m10s
Merge pull request 'dns: publish the operator deployment's own mail records' (#1756) from kiara/fediversity:operator-mail-records into main
Reviewed-on: #1756
2026-09-11 11:29:38 +02:00
.forgejo ci: give nix-unit-setups a tier its evaluation fits, and share that evaluation 2026-09-10 09:12:23 +02:00
api tests: let the drain assertion read the whole journal 2026-09-10 22:10:19 +02:00
core dns: publish the operator deployment's own mail records 2026-09-11 10:50:41 +02:00
examples docs: name the check paths and the core layout as they are 2026-09-04 20:23:49 +02:00
keys secrets: document the rekey/rotate lifecycle, and correct both READMEs 2026-08-28 15:26:24 +02:00
nix openbao-agent: converge a rendered secret's owner at agent start 2026-09-10 19:06:20 +02:00
notes operator: register an operator's domain through the openprovider_domain resource 2026-09-07 11:42:49 +02:00
npins npins: pin the openprovider fork at the gateway retry 2026-09-08 11:47:04 +02:00
panel ci: root the npins sources on the runner hosts and move the eval-only checks to ram-2g 2026-09-09 00:40:08 +02:00
.envrc Move formatting over to treefmt (#1012) 2026-06-04 19:37:21 +02:00
.gitignore octodns: drop a __pycache__ committed by accident 2026-08-19 22:25:27 +02:00
default.nix ci: root the npins sources on the runner hosts and move the eval-only checks to ram-2g 2026-09-09 00:40:08 +02:00
flake.lock use data model (#597) 2026-03-02 20:01:06 +01:00
flake.nix flakes: instantiate each entrypoint once per system 2026-08-12 21:43:02 +02:00
LICENSE Initial commit 2024-10-02 12:13:02 +02:00
README.md npins: record why each non-release pin exists and when it can go 2026-09-06 14:39:09 +02:00
ruff.toml panel: drop the api-client wrappers no view calls 2026-09-06 13:26:43 +02:00
shell.nix promote nix-module-form + nix-docs-lib to org repos (#1200) 2026-07-12 19:06:14 +02:00
treefmt.nix dns: add a third registrar, in the EU, that takes the key rather than the digest 2026-09-04 14:36:30 +02:00
ty.toml Merge pull request 'panel: small sweeps over views, the api-client facade, ty scope and ruff' (#1695) from kiara/fediversity:panel-small-sweeps into main 2026-09-06 14:32:30 +02:00

The Fediversity project

This repository contains all the code and code-related files having to do with the Fediversity project.

Goals

Decentralise the operational responsibility for social media. Enable a more robust market of hosting providers, by making it easy to migrate operations and data to different providers.

Note that Fediversity is not about self-hosting. There already exist solutions for self-hosting, but they're not suitable for what we're trying to do. The ones we're aware of require substantial technical knowledge and time commitment by system-operators, especially for scaling to thousands of users. Not everyone has the expertise and time to run their own server.

Status: in development

see our:

Interactions

To reach these goals, we aim to implement the following interactions between actors (depicted with rounded corners) and system components (see the glossary, depicted with rectangles).

Concepts

The actors involved and the vocabulary this project uses are documented at https://core.pages.git.fediversity.eu/concepts.html.

Development

All the code made for this project is freely licenced under EUPL. This means, anyone can use the work here to learn from it or change it according to their needs. You can even read up on development proceedings.

Contact the project team if you have questions or suggestions, or if you're interested in using Fediversity software for your operations:

Content of this repository

Most of the directories in this repository have their own README going into more details as to what they are for. As an overview:

  • keys/ contains the public keys of the contributors to this project as well as the systems that we administrate.

  • panel/ contains the code of our front-end.

  • core/ contains source code handling deployments.

Documentation sites

Each component's rendered docs are published on push to main under pages.git.fediversity.eu (see notes/git-pages.md):

  • core -- the core NixOS options/module and library docs.
  • panel -- the Django front-end docs.
  • api -- the API docs, plus its wire surface as Swagger UI (HTTP) and AsyncAPI (Centrifugo pub/sub).

Entrypoints

Rather than one monolithic root flake, each top-level component owns its own entrypoint (a flake.nix + default.nix following the transparent-wrapper pattern), and consumers address it directly:

  • core/ -- the shared library leaf (data model, resources, effects, components, setups) plus the pure render combinator that turns a groups set into the orchestration surface: nixosConfigurations, the <group>-<effect>-<machine> deployment packages/apps/devShells, legacyPackages, core-docs, the core-scoped formatter and the default dev shell. core/default.nix runs render with its in-tree frontend-free groups, so ./core#... exposes a default deploy family out of the box.
  • api/, panel/ -- each leaf owns its packages, checks, formatter and devShells. Addressed as ./api#..., etc. (The nix-module-form widget the panel embeds lives in its own org repo, consumed here via an npins pin. npins/README.md records, for each pin that is a fork, a branch or a non-vendor source, why it is one and when it can go.)
  • the repo root (./) stays thin, retaining only what is inherently root-anchored (see below).

Enumerating attributes cheaply

nix flake show forces every leaf on the surface to report its type, name and meta.description, and the deploy family is ~1400 attributes wide per entrypoint. When all you need is the list of names, ask for the attrset spine instead:

nix eval --json ./core#packages.x86_64-linux --apply builtins.attrNames

This is what nix-flake-check.sh uses to walk the surface. For the deployment family specifically, nix build ./core#api-deployments yields the same { attribute, machine } records the api's detect-at-submit guard reads, as JSON, and core/docs/md/flake-attributes-intro.md documents the <group>-<effect>-<machine>[-<verb>] grammar the names follow, so a name can usually be constructed rather than looked up.

When you do run nix flake show, note that its eval cache is keyed on the flake's locked-ref fingerprint: a dirty working tree has no rev and so no fingerprint, and --impure disables the cache outright. Committing first is what makes a repeated nix flake show free.

Why the root entrypoint cannot be removed

Two concerns force a repo-root flake to survive; both are documented inline in default.nix:

  1. The deploying-vs-deployed boundary. The generated deploy configuration.nix bakes (import repoRoot {}).boundary.<system> and resolves the operator config through boundary.<system>.deploymentPlan, whose caller is imported as import (repoRoot + "/${caller}") args. Those caller strings span several trees, and hosts-common.nix / the deployment constants.nix anchor root-path at the repo root, so ./. there must remain the repo root.
  2. The infra / cross-cutting checks. core/checks/default.nix aggregates checks that cross core/, nix/contracts and multiple leaves, and resist a clean per-leaf split (shared runNixOSTest overlay, requiredMemory passthru, repo-root caller paths), so the root retains them as its checks output.

The root also owns the one repo-wide concern that must scan the whole tree: the pre-commit hook (git-hooks treefmt + trim-trailing-whitespace, src = ./.). Per-leaf treefmt checks cover each leaf's own languages; the repo-wide hook is the backstop so no file falls between leaf scopes.

The out-of-tree npins / flake-mode caveat

Each entrypoint reads its dependencies via sources ? import ../npins, reaching the single npins/ directory at the repo root -- there is no per-leaf npins copy. In flake mode (./core#...) Nix copies each flake's own subtree to the store, so ../npins is only reachable because npins/ is git-tracked at the root; flake mode ignores untracked files. Two consequences:

  • New leaf files (flake.nix, flake.lock) must be tracked with git add (or git add -N) before a flake-mode eval sees them, otherwise ../npins (and the leaf itself) resolves against an incomplete tree and fails with a 'npins' is too short to be a valid store path error.
  • The leaf flakes are system-scoped and guard builtins.currentSystem (see core/default.nix), but CI evals still pass --impure so currentSystem is available in pure flake eval. Path-mode (import ./core {} / nix-build ./core -A ...) reaches ../npins unconditionally and yields drvPaths identical to flake mode.

Usage

Loading the nix shell should install a pre-commit hook.