My plan for #CD refactoring for #ZeroHR:
https://github.com/numtide/system-manager/tree/main — allows to configure non-NixOS systemd declaratively using Nix programming language.
https://github.com/serokell/deploy-rs — allows to do non-privileged deploys using #nix flakes. Works on non-NixOS linuxes via home-manager.
https://github.com/getsops/sops — for secret management capability, integratable with deploy-rs[1].
[1]: https://samleathers.com/posts/2022-02-11-my-new-network-and-sops.html