Skip to content

Commit a39d64f

Browse files
authored
Merge pull request #692 from genebean/hermes-social-summerizer
Deploy social-reader-mcp (HermesSocialSummerizer) to nixnuc
2 parents ea4bc64 + 31fe9a6 commit a39d64f

6 files changed

Lines changed: 104 additions & 3 deletions

File tree

flake.lock

Lines changed: 21 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

flake.nix

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,6 +43,11 @@
4343
flake = false;
4444
};
4545

46+
hermes-social-summerizer = {
47+
url = "github:genebean/HermesSocialSummerizer";
48+
inputs.nixpkgs.follows = "nixpkgs";
49+
};
50+
4651
# Manages things in home directory
4752
home-manager = {
4853
url = "github:nix-community/home-manager/release-26.05";
@@ -199,6 +204,7 @@
199204
hostname = "nixnuc";
200205
additionalModules = [
201206
inputs.cup-collector.nixosModules.default
207+
inputs.hermes-social-summerizer.nixosModules.default
202208
inputs.private-flake.nixosModules.private.nixnuc
203209
inputs.ytdlfin.nixosModules.default
204210
];

modules/hosts/nixos/nixnuc/default.nix

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@ in
2121
./cup-collector.nix
2222
./monitoring-stack.nix
2323
./ports.nix
24+
./social-reader-mcp.nix
2425
./zfs-datasets.nix
2526
../../../shared/nixos/lets-encrypt.nix
2627
../../../shared/nixos/restic.nix

modules/hosts/nixos/nixnuc/ports.nix

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -76,6 +76,12 @@
7676
openFirewall = true;
7777
};
7878

79+
# Firewalled TCP services continued
80+
social-reader-mcp = {
81+
port = 8787;
82+
openFirewall = true;
83+
};
84+
7985
# Internal-only TCP services (proxied via nginx, not firewalled)
8086
pocket-id = {
8187
port = 1411;

modules/hosts/nixos/nixnuc/secrets.yaml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ nginx_basic_auth: ENC[AES256_GCM,data:9qy8ccV9yWOrQtagf4D4fTp4v8GuY5ORxsE8hUv/vK
1818
pocketid_encryption_key: ENC[AES256_GCM,data:N/V1XHU4NZOL02KJL6kqec9NyJl1UQI4q626j7apFxfz/LMXNavQQ8eKDtrY,iv:ukJAEWKq3SX1iU8qXhxEAGVlovY5N8FTwdShgMQ+zig=,tag:U9eWbhaPySsYlyhS+dEoQQ==,type:str]
1919
psitransfer_dot_env: ENC[AES256_GCM,data:bhvU0AOCjecZ62BtLw4H1DdkLeatI+uUl6L7UkdDRkBF3sayO45Z1eR4q60tflXucyTGhT8WgKFz53I+C2dn265wzojIRc3Xr4TBLyWpfJ7/dct40SckgUiRvOnrefiriWQ=,iv:DGMhDkzgeupzzTJnCdVWDPUSo2wxI3MAypKQwVfHExE=,tag:KbteGqrkqgj2XB1lvlk/yQ==,type:str]
2020
pinchflat_dot_env: ENC[AES256_GCM,data:8DLiFXThG5PGJ0ymW5bMVy5A8dM=,iv:BGkVvxaNwFIMSaA3F6h4ZsgkC9tm1lohA0lg2pgZhpw=,tag:qQNrluP5exdKG3NXgQHM8g==,type:str]
21+
social_reader_mcp_env: ENC[AES256_GCM,data:w+jujihm4bAAF8+dZ6pXOZD6arAdvhlj8e7IKrSJA0yMeIWQDjfsIiemoYwb1P7CHFsf9F9g5LvtwcWf2uo0yFOHoB/GdGVhnO8M87J90IoFfNYLsMCUhxNQagPBvDpe6BpwWGab+vU19zKtzEAWHwV5w04Osp3h75J7GHsaeXxpCS5cNcFvZpOy6fEXo9Z3hscQZ36PMCnqaVUjPA2fgqYXyB0UOpkSbbYyMyeZeMQM2jzwtg==,iv:+f9MZbiFI7x8zdA3n18Hiq9AOrWzfmpIRywbhyWKgTw=,tag:K/nyvcmUguvW5IFYkrs3mw==,type:str]
2122
tandoor_db_pass: ENC[AES256_GCM,data:X0unx5jquLsUXadbF6xLjjeGY+f8Ec4kdc15JQ==,iv:XptlJHfAkF+3jbgJTqxhVReYjuVVdk3NzfPepP78DRI=,tag:3RG5P9QGCJ/fjdxWpY1xWA==,type:str]
2223
tandoor_secret_key: ENC[AES256_GCM,data:aSQRdtWUZQzy5rvQBPAvYFvwTqyu16UGrvUayxqi2WdsTOfqOyxQ7ywNEy/g/qPqSbwM,iv:kbct/gvfYhU6GOhkomY80o/Sx5mr9FY9SAFJGNrj3Ow=,tag:v+LKQ9UM5nzzd77By7TnGg==,type:str]
2324
ytdlfin-env: ENC[AES256_GCM,data:X33y2zqG7XRhUX0F7YoT8clGoOzTuBKTaKbyZ5/2UmFJfg5xxRYieelRwKxAw/FvZoMEHRaugXYfHinCjOvRT6+Zgk5BOiV1f4TvRInTAIrMq8ApFlYvsUS7rS6q1g9Q5/h/gmOmEaa400+7Aml4fuHUaIEJG3OBGQEdZc97pLLsfmBAG+uYxxom6+msXJ494Ua1cnfbsjcvVReJiIa1TjRH3BN8LrJY42UEv4QSGFhyJKEpNtJre3t+,iv:4pyijslimg8SKBt1EzuwFGxxAy3nDYk9razfEbfj+EE=,tag:blmVpDS1GDx/7kQEDVLkJg==,type:str]
@@ -32,7 +33,7 @@ sops:
3233
PF025X9U+yG2oIopwXEVBkxcD70eyuJn3OqH0xoVLBkbhNM9i8LHrA==
3334
-----END AGE ENCRYPTED FILE-----
3435
recipient: age1g24zhwvgenpc4wqejt63thvgd4rn5x9n7nnwwme7dm83nfqpp93se2vmq4
35-
lastmodified: "2026-06-13T23:53:00Z"
36-
mac: ENC[AES256_GCM,data:flcQgdp3x15cy/SY8FwF3LWJy54l4Si/mW3dXhjFWCBO/qPoceAqgFSRKnZsNxtJYZWP3n43gqpMLQQXk7667VoDC/YDrAZRZVbdQXakXmxZzASBki2BX6iT2JQ1+VDeo4tpK5WGH3aL6uhzwtw1a3GQEGkysV/D1Vb7mXv7U6A=,iv:dTofpuoxJabzw34L+Wm6VszRkVGTr19lCblwbE0umdI=,tag:+AR2ndMOwDgl3QPWUYZhpQ==,type:str]
36+
lastmodified: "2026-07-16T02:52:27Z"
37+
mac: ENC[AES256_GCM,data:ozer784MBv/26PxUK4cFdyvD+7psTJpgneibsAzCykKvY7Sf0R3x0TpbE68kq1UCLDFNdXlgz1DRHZwR51qELl+diQJKFAqYH6agjniUUHHP2B5oAx4Fny6nxhmjXAOndcwKzYuN8pYay6/MotNTH25v29jdqZXZvK3M61McT1E=,iv:jNS2wz1kUJfIS/w+N/h3gSlvWLLfWBJHWJN/TBvUu5Y=,tag:eapj96F2DNPhXJ0DyBN1Rw==,type:str]
3738
unencrypted_suffix: _unencrypted
38-
version: 3.13.1
39+
version: 3.13.2
Lines changed: 66 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,66 @@
1+
{
2+
config,
3+
...
4+
}:
5+
{
6+
services.social-reader-mcp = {
7+
enable = true;
8+
9+
bluesky = [
10+
{
11+
appPasswordEnv = "BSKY_PERSONAL_APP_PW";
12+
handle = "genebean.bsky.social";
13+
id = "personal";
14+
}
15+
];
16+
17+
http = {
18+
enable = true;
19+
20+
bindAddress = "0.0.0.0";
21+
environmentFile = config.sops.secrets.social_reader_mcp_env.path;
22+
# Bind on all interfaces — LAN-only access, no nginx proxy in front.
23+
# The bearer token (SOCIAL_READER_MCP_HTTP_TOKEN in environmentFile)
24+
# is the sole auth mechanism.
25+
port = config.genebean.ports.social-reader-mcp.port;
26+
};
27+
28+
mastodon = [
29+
{
30+
accessTokenEnv = "MASTODON_MAIN_TOKEN";
31+
id = "main";
32+
instanceUrl = "https://fosstodon.org";
33+
}
34+
];
35+
36+
nostr = [
37+
{
38+
id = "main";
39+
npub = "npub1mwsk3ly4lk7efdqqjm62dkc699kqapwyyvdley3xljjm0lxruh9qzvu46p";
40+
relays = [
41+
"wss://nostr.data.haus"
42+
"wss://relay.primal.net"
43+
"wss://relay.damus.io"
44+
];
45+
}
46+
];
47+
48+
user = "social-reader-mcp";
49+
};
50+
51+
# Dedicated system user — required so sops can assign ownership of the
52+
# EnvironmentFile and tmpfiles can create the cursor-state directory with
53+
# a known, persistent owner (DynamicUser doesn't work here for that reason).
54+
sops.secrets.social_reader_mcp_env = {
55+
owner = "social-reader-mcp";
56+
restartUnits = [ "social-reader-mcp-http.service" ];
57+
};
58+
59+
users = {
60+
groups.social-reader-mcp = { };
61+
users.social-reader-mcp = {
62+
group = "social-reader-mcp";
63+
isSystemUser = true;
64+
};
65+
};
66+
}

0 commit comments

Comments
 (0)