summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authoradikro <adikro@disroot.org>2026-06-29 00:31:26 +0200
committeradikro <adikro@disroot.org>2026-06-29 00:31:26 +0200
commit8a820cacee1ff07ae7397d053b26e66f7086a4a4 (patch)
tree23153683130799babd4e5ed1a39068c52fa7d588
parent9b8f9a4bf5e13efe49ec101f127d0df3d7bb3cf3 (diff)
updated some stuff, added persistanceHEADmain
-rw-r--r--flake.lock99
-rw-r--r--flake.nix5
-rw-r--r--hosts/bibus-lab/disko.nix11
-rw-r--r--hosts/desktop/configuration.nix2
-rw-r--r--hosts/desktop/home.nix1
-rw-r--r--os/core/default.nix1
-rw-r--r--os/core/networking.nix25
-rw-r--r--os/core/persistance.nix50
-rw-r--r--os/core/users.nix2
-rw-r--r--os/core/zfs.nix (renamed from os/srv/zfs.nix)6
-rw-r--r--os/srv/avahi.nix41
-rw-r--r--os/srv/backup.nix3
-rw-r--r--os/srv/crowdsec.nix74
-rw-r--r--os/srv/default.nix1
-rw-r--r--os/srv/dns.nix13
-rw-r--r--os/srv/gaming.nix31
-rw-r--r--os/srv/lldap.nix11
-rw-r--r--os/srv/monero.nix32
-rw-r--r--os/srv/simplex.nix13
-rw-r--r--os/srv/ssh.nix69
-rw-r--r--os/vms/microvms.nix3
21 files changed, 307 insertions, 186 deletions
diff --git a/flake.lock b/flake.lock
index 0bbd8f4..ced4b22 100644
--- a/flake.lock
+++ b/flake.lock
@@ -374,11 +374,11 @@
]
},
"locked": {
- "lastModified": 1782423922,
- "narHash": "sha256-qPNd6lUohHP5gcJhqQ7rLV87RwIx0xYR2A4Frb9Zjc4=",
+ "lastModified": 1782657028,
+ "narHash": "sha256-PHTCpYZCMzJYS3phhywqRAZphKVr2zjvlGYa+H20ZZ4=",
"owner": "nix-community",
"repo": "home-manager",
- "rev": "5d320ab301cfaaca7d32514f13815d19d109f5f4",
+ "rev": "4ad9aaae70c9aaab504127f926c0fa9cfbc2b365",
"type": "github"
},
"original": {
@@ -391,6 +391,27 @@
"home-manager_2": {
"inputs": {
"nixpkgs": [
+ "impermanence",
+ "nixpkgs"
+ ]
+ },
+ "locked": {
+ "lastModified": 1768598210,
+ "narHash": "sha256-kkgA32s/f4jaa4UG+2f8C225Qvclxnqs76mf8zvTVPg=",
+ "owner": "nix-community",
+ "repo": "home-manager",
+ "rev": "c47b2cc64a629f8e075de52e4742de688f930dc6",
+ "type": "github"
+ },
+ "original": {
+ "owner": "nix-community",
+ "repo": "home-manager",
+ "type": "github"
+ }
+ },
+ "home-manager_3": {
+ "inputs": {
+ "nixpkgs": [
"otter-launcher",
"nixpkgs"
]
@@ -409,6 +430,27 @@
"type": "github"
}
},
+ "impermanence": {
+ "inputs": {
+ "home-manager": "home-manager_2",
+ "nixpkgs": [
+ "nixpkgs"
+ ]
+ },
+ "locked": {
+ "lastModified": 1769548169,
+ "narHash": "sha256-03+JxvzmfwRu+5JafM0DLbxgHttOQZkUtDWBmeUkN8Y=",
+ "owner": "nix-community",
+ "repo": "impermanence",
+ "rev": "7b1d382faf603b6d264f58627330f9faa5cba149",
+ "type": "github"
+ },
+ "original": {
+ "owner": "nix-community",
+ "repo": "impermanence",
+ "type": "github"
+ }
+ },
"microvm": {
"inputs": {
"nixpkgs": [
@@ -492,11 +534,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
},
"locked": {
- "lastModified": 1782333733,
- "narHash": "sha256-QYrNYMNPKErRgNlxWwk0cjNKftnq6WzSs84pcZnUskM=",
+ "lastModified": 1782592242,
+ "narHash": "sha256-kgINba6Ilpj3rdTi2BeKlQBs6ZxTdu3Gb49U5gDUVhg=",
"owner": "sodiboo",
"repo": "niri-flake",
- "rev": "a6351044a3d69877d1c23be54971d18f8531c930",
+ "rev": "9e26dfe0fb8d61475b6f9e8d63477fe92509f1db",
"type": "github"
},
"original": {
@@ -543,11 +585,11 @@
"nixpkgs": "nixpkgs_2"
},
"locked": {
- "lastModified": 1782379505,
- "narHash": "sha256-zPvPiU+a7pqtH47xrtZLNRABJKpOjfZQclDbcvNtH+I=",
+ "lastModified": 1782562157,
+ "narHash": "sha256-a7+T6QSeowynwZ1ZJJbP8T8ntAytvrui8kFGJmIZt2c=",
"owner": "NixOS",
"repo": "nixos-hardware",
- "rev": "603d3afd1b6145bd66e97ae38a34d91c95df70cf",
+ "rev": "a9cf7546a938c737b079e738de73934a13de9784",
"type": "github"
},
"original": {
@@ -614,11 +656,11 @@
},
"nixpkgs-stable": {
"locked": {
- "lastModified": 1782188297,
- "narHash": "sha256-imdcA5fgbHK259bhHlyiiSr7bMY1AZ6onOWDdAcydc4=",
+ "lastModified": 1782498288,
+ "narHash": "sha256-8/X3yyTXiE82b38n32ItbOqfWOVBl+gKa8fILyZfR4Q=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "9a1a7dbb18f0eb31c49b031babb8def7eab0af54",
+ "rev": "3cac626ec5e3703e835f227687e88aa9e2f25701",
"type": "github"
},
"original": {
@@ -630,11 +672,11 @@
},
"nixpkgs-stable_2": {
"locked": {
- "lastModified": 1782233679,
- "narHash": "sha256-QyuGP5+QOtmXpy4i2X4DhBVBaySBdDKQEhqKcphcp34=",
+ "lastModified": 1782535326,
+ "narHash": "sha256-ZeRxu4yn6shd3SNF5ZUQb4r7BaVo1zBKMjRhfoNSBmw=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "667d5cf1c59585031d743c78b394b0a647537c35",
+ "rev": "714a5f8c4ead6b31148d829288440ed033ccc041",
"type": "github"
},
"original": {
@@ -659,11 +701,11 @@
},
"nixpkgs_3": {
"locked": {
- "lastModified": 1781577229,
- "narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=",
+ "lastModified": 1782467914,
+ "narHash": "sha256-pGvFkM8N0xEkIIXDe5YYfbEAvHrk4IxBrjB/x8OomhE=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f",
+ "rev": "e73de5be04e0eff4190a1432b946d469c794e7b4",
"type": "github"
},
"original": {
@@ -722,11 +764,11 @@
"systems": "systems_3"
},
"locked": {
- "lastModified": 1782369036,
- "narHash": "sha256-jxbvrIvE+NklSd6HPNSdEhGr8RvwNj4b7Gd5tgEXwSQ=",
+ "lastModified": 1782660650,
+ "narHash": "sha256-d4Ndt82q9bhL+iKFr1reufZyE/MTdULzN3kEkXsNG88=",
"owner": "NotAShelf",
"repo": "nvf",
- "rev": "096045d0e927bf7064989e9181a89b47c1b8779c",
+ "rev": "18d2d23191250c7f597d85da07d860eb05f9e1be",
"type": "github"
},
"original": {
@@ -785,7 +827,7 @@
"otter-launcher": {
"inputs": {
"flake-parts": "flake-parts_3",
- "home-manager": "home-manager_2",
+ "home-manager": "home-manager_3",
"nixpkgs": [
"nixpkgs"
],
@@ -810,6 +852,7 @@
"disko": "disko",
"fsel": "fsel",
"home-manager": "home-manager",
+ "impermanence": "impermanence",
"microvm": "microvm",
"niri": "niri",
"nixos-hardware": "nixos-hardware",
@@ -909,11 +952,11 @@
"rust-overlay": "rust-overlay"
},
"locked": {
- "lastModified": 1782333283,
- "narHash": "sha256-57ycRZHQkootKokT5VDSVZIyeGGaq05G7i2iqh1NApI=",
+ "lastModified": 1782542860,
+ "narHash": "sha256-79L/yxMuJHS+Dfpt7y4wXvgNJILux0jv6mnVFxanqKc=",
"owner": "gabm",
"repo": "Satty",
- "rev": "26848045f3565cb05f6c18ad9e0d8ca5b3a7e1c1",
+ "rev": "ff0c0d350d233f446c868e7ca4c13cfb67d0c43d",
"type": "github"
},
"original": {
@@ -1155,11 +1198,11 @@
"rust-overlay": "rust-overlay_2"
},
"locked": {
- "lastModified": 1782458355,
- "narHash": "sha256-qa+ReXlH0m+5SZrmUKWK3xAri4qE45M8FcmM4L7VC5s=",
+ "lastModified": 1782583823,
+ "narHash": "sha256-S52dg5T6iRjuED2e0bxzWeVM1Einbz5rJbB5wcruop4=",
"owner": "sxyazi",
"repo": "yazi",
- "rev": "bf1274315dbcef858b46a55f212cfa34b916c3d3",
+ "rev": "21550a7eb5086ba34f8eabf8aaab85f601d34a74",
"type": "github"
},
"original": {
diff --git a/flake.nix b/flake.nix
index f925335..7e6ca6e 100644
--- a/flake.nix
+++ b/flake.nix
@@ -8,6 +8,11 @@
# Hardware and gaming
nixos-hardware.url = "github:NixOS/nixos-hardware/master";
+ impermanence = {
+ url = "github:nix-community/impermanence";
+ inputs.nixpkgs.follows = "nixpkgs";
+ };
+
nixos-mailserver = {
# url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.05";
url = "gitlab:simple-nixos-mailserver/nixos-mailserver/main";
diff --git a/hosts/bibus-lab/disko.nix b/hosts/bibus-lab/disko.nix
index 6ca17b9..203ec95 100644
--- a/hosts/bibus-lab/disko.nix
+++ b/hosts/bibus-lab/disko.nix
@@ -85,9 +85,6 @@
"rpool" = {
type = "zfs_fs";
options = {
- encryption = "on";
- keyformat = "passphrase";
- keylocation = "prompt";
mountpoint = "none";
compression = "zstd";
atime = "off";
@@ -107,6 +104,11 @@
type = "zfs_fs";
mountpoint = "/home";
};
+ "rpool/persist" = {
+ type = "zfs_fs";
+ mountpoint = "/persist";
+ options.mountpoint = "legacy";
+ };
"rpool/log" = {
type = "zfs_fs";
mountpoint = "/var/log";
@@ -190,9 +192,6 @@
type = "zfs_fs";
mountpoint = "none";
options = {
- encryption = "on";
- keyformat = "passphrase";
- keylocation = "prompt";
compression = "zstd";
atime = "off";
};
diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix
index 7e78c91..b910f8f 100644
--- a/hosts/desktop/configuration.nix
+++ b/hosts/desktop/configuration.nix
@@ -22,7 +22,7 @@
};
drivers = {
enable = true;
- kernel = "zen";
+ # kernel = "zen";
cpu = "amd";
graphics = {
enable = true;
diff --git a/hosts/desktop/home.nix b/hosts/desktop/home.nix
index 38f1469..374b007 100644
--- a/hosts/desktop/home.nix
+++ b/hosts/desktop/home.nix
@@ -98,5 +98,6 @@
gimp
stow
antigravity-cli
+ libnotify
];
}
diff --git a/os/core/default.nix b/os/core/default.nix
index 1146f2d..963436b 100644
--- a/os/core/default.nix
+++ b/os/core/default.nix
@@ -17,6 +17,7 @@ in
./security.nix
./storage.nix
./users.nix
+ ./zfs.nix
];
options.os.core = {
diff --git a/os/core/networking.nix b/os/core/networking.nix
index b94b540..9e4c329 100644
--- a/os/core/networking.nix
+++ b/os/core/networking.nix
@@ -20,20 +20,21 @@ in
ips = lib.mkOption {
type = lib.types.attrsOf lib.types.str;
- default = rec {
- router = opnsense-vm;
- host = "10.0.0.2";
+ default = {
+ bare-metal = "10.0.0.2";
opnsense-vm = "10.0.0.1";
gateway-vm = "10.0.0.3";
- databse-vm = "10.0.0.4";
- monitor-vm = "10.0.0.5";
- media-vm = "10.0.0.6";
- sandbox-vm = "10.0.0.7";
- storage-vm = "10.0.0.8";
- web-vm = "10.0.0.9";
- mail-vm = "10.0.0.10";
- relay-vm = "10.0.0.11";
- gameserver-vm = "10.0.0.12";
+ auth-vm = "10.0.0.4";
+ database-vm = "10.0.0.5";
+ monitor-vm = "10.0.0.6";
+ media-vm = "10.0.0.7";
+ torrent-vm = "10.0.0.8";
+ storage-vm = "10.0.0.9";
+ web-vm = "10.0.0.10";
+ comm-vm = "10.0.0.11";
+ mail-vm = "10.0.0.12";
+ relay-vm = "10.0.0.13";
+ gameserver-vm = "10.0.0.14";
};
description = "Central registry of static IP allocations for the cluster.";
};
diff --git a/os/core/persistance.nix b/os/core/persistance.nix
new file mode 100644
index 0000000..89f3702
--- /dev/null
+++ b/os/core/persistance.nix
@@ -0,0 +1,50 @@
+{
+ config,
+ lib,
+ inputs,
+ ...
+}:
+let
+ cfg = config.os.srv.persistance;
+in
+{
+ imports = [ inputs.impermanence.nixosModules.impermanence ];
+
+ options.os.srv.persistance.enable = lib.mkEnableOption "enables persistance drive maintnance";
+ config = lib.mkMerge [
+ (lib.mkIf cfg.enable {
+ environment.persistence."/persist" = {
+ hideMounts = true;
+ directories = [
+ "/var/lib/nixos"
+ "/var/lib/systemd"
+ "/var/lib/microvm"
+ ];
+ files = [
+ "/etc/machine-id"
+ ];
+ };
+ })
+ (lib.mkIf (cfg.enable && config.os.srv.ssh.server.enable) {
+ environment.persistence."/persist" = {
+ files = [
+ "/etc/ssh/ssh_host_ed25519_key"
+ "/etc/ssh/ssh_host_ed25519_key.pub"
+ ];
+ };
+ })
+ (lib.mkIf (cfg.enable && config.os.srv.crowdsec.agent.enable) {
+ environment.persistence."/persist" = lib.mkIf cfg.agent.enable {
+ hideMounts = true;
+ directories = [
+ {
+ directory = "/var/lib/crowdsec";
+ user = "crowdsec";
+ group = "crowdsec";
+ mode = "0750";
+ }
+ ];
+ };
+ })
+ ];
+}
diff --git a/os/core/users.nix b/os/core/users.nix
index 494406b..ff45a99 100644
--- a/os/core/users.nix
+++ b/os/core/users.nix
@@ -43,7 +43,7 @@ in
"render"
])
(lib.mkIf (config.os.core.network.enable or false) [ "networkmanager" ])
- (lib.mkIf (config.os.srv.virtualization.enable or false) [ "libvirtd" ])
+ (lib.mkIf (config.os.srv.virtualization.kvm.enable or false) [ "libvirtd" ])
(lib.mkIf (config.os.srv.docker.enable or false) [ "docker" ])
];
};
diff --git a/os/srv/zfs.nix b/os/core/zfs.nix
index 3bfd2de..771644d 100644
--- a/os/srv/zfs.nix
+++ b/os/core/zfs.nix
@@ -21,8 +21,8 @@ in
boot = {
kernelParams = [ "zfs.zfs_arc_max=${toString (32 * 1024 * 1024 * 1024)}" ];
zfs = {
- requestEncryptionCredentials = [ "zroot" ];
- useKeyringForCredentials = true;
+ # requestEncryptionCredentials = [ "zroot" ];
+ # useKeyringForCredentials = true;
extraPools = [ "tank" ];
};
supportedFilesystems = [ "zfs" ];
@@ -37,7 +37,6 @@ in
flags = "-k -p --utc";
};
zed = {
- enableCustomScripts = true;
settings = {
ZED_DEBUG_LOG = "/var/log/zed.debug.log";
@@ -56,5 +55,6 @@ in
};
systemd.services.zfs-zed.serviceConfig.EnvironmentFile = config.sops.secrets."ntfy/zed".path;
networking.hostId = "4e3e22e1";
+
};
}
diff --git a/os/srv/avahi.nix b/os/srv/avahi.nix
new file mode 100644
index 0000000..f14b33a
--- /dev/null
+++ b/os/srv/avahi.nix
@@ -0,0 +1,41 @@
+{ config, lib, ... }:
+let
+ cfg = config.os.srv.avahi;
+in
+{
+ options.os.srv.avahi.enable = lib.mkEnableOption "enables avahis";
+ config = lib.mkIf cfg.enable {
+ services.avahi = {
+ enable = true;
+ ipv4 = true;
+
+ publish = {
+ enable = true;
+ addresses = true;
+ workstation = true;
+ };
+
+ nssmdns4 = true;
+
+ extraServiceFiles = {
+ nfs = ''
+ <?xml version="1.0" standalone='no'?>
+ <!DOCTYPE service-group SYSTEM "avahi-service.dtd">
+ <service-group>
+ <name replace-wildcards="yes">NFS Share on %h</name>
+ <service>
+ <type>_nfs._tcp</type>
+ <port>2049</port>
+ <txt-record>path=/data/vault</txt-record>
+ </service>
+ <service>
+ <type>_nfs._tcp</type>
+ <port>2049</port>
+ <txt-record>path=/data/media</txt-record>
+ </service>
+ </service-group>
+ '';
+ };
+ };
+ };
+}
diff --git a/os/srv/backup.nix b/os/srv/backup.nix
index 3d1d583..e7c07f9 100644
--- a/os/srv/backup.nix
+++ b/os/srv/backup.nix
@@ -58,7 +58,8 @@ in
syncoid = {
enable = true;
commonArgs = [
- "-w"
+ "-c"
+ "-p"
"--delete-target-snapshots"
"--use-hold"
"--no-sync-snap"
diff --git a/os/srv/crowdsec.nix b/os/srv/crowdsec.nix
index 71818bd..c3df81b 100644
--- a/os/srv/crowdsec.nix
+++ b/os/srv/crowdsec.nix
@@ -1,4 +1,9 @@
-{ config, lib, ... }:
+{
+ config,
+ lib,
+ masterDomain,
+ ...
+}:
let
cfg = config.os.srv.security.crowdsec;
in
@@ -22,14 +27,71 @@ in
}
];
+ sops = {
+ secrets."crowdsec/env" = {
+ owner = "crowdsec";
+ group = "crowdsec";
+ restartUnits = [ "crowdsec.service" ];
+ };
+
+ templates."local_api_credentials.yaml" = {
+ owner = "crowdsec";
+ group = "crowdsec";
+ restartUnits = [ "crowdsec.service" ];
+ content = ''
+ url: http://${config.os.core.network.ips.gateway-vm}:8080
+ login: ${config.networking.hostName}
+ password: ${config.sops.placeholder."crowdsec/client_password"}
+ '';
+ };
+ };
+
+ systemd.services.crowdsec.serviceConfig.EnvironmentFile = config.sops.secrets."crowdsec/env".path;
+
services.crowdsec = {
enable = true;
autoUpdateService = true;
- openFirewall = cfg.aggregator.enable;
+ openFirewall = true;
settings = {
- api.server.enable = cfg.aggregator.enable;
+ common = {
+ compress_logs = true;
+ log_format = "json";
+ };
+ prometheus = {
+ enabled = true;
+ level = "full";
+ listen_addr = "0.0.0.0";
+ listen_port = 6060;
+ };
+ db_config = {
+ type = "postgresql";
+ host = config.os.core.network.ips.database-vm;
+ port = 5432;
+ db_name = "crowdsec";
+ user = "crowdsec";
+ password = "$CROWDSEC_DB_PASSWORD";
+ sslmode = "require";
+ };
+
+ api = {
+ server = {
+ enable = cfg.aggregator.enable;
+ listen_uri = "0.0.0.0:8080";
+ trusted_ips = [
+ "127.0.0.1"
+ "10.0.0.0/24"
+ ];
+
+ auto_registration = {
+ enabled = cfg.aggregator.enable;
+ token = "$CROWDSEC_REGISTER_TOKEN";
+ allowed_ranges = [ "10.0.0.0/24" ];
+ };
+ };
+ client.credentials_path = config.sops.templates."local_api_credentials.yaml".path;
+ };
lapi.client.api_url = "http://${config.os.core.network.ips.gateway-vm}:8080";
};
@@ -82,11 +144,11 @@ in
name = "ntfy_alerts";
type = "http";
method = "POST";
- #TODO add ntfy sops thing
- url = "https://ntfy.sh/your_secret_topic_here";
+ url = "https://ntfy.${masterDomain}/crowdsec-alerts";
headers = {
Title = "CrowdSec Alert on Bibus-Lab";
Priority = "high";
+ Authorization = "$NTFY_AUTH_TOKEN";
};
format = ''
{{range .}} {{.Alert.Message}} (Scenario: {{.Alert.Scenario}}) from IP {{.Alert.Source.IP}} {{end}}
@@ -105,8 +167,8 @@ in
settings = {
mode = "nftables";
update_frequency = "10s";
-
api_url = "http://${config.os.core.network.ips.gateway-vm}:8080";
+ api_key = lib.mkIf cfg.aggregator.enable "$CROWDSEC_LOCAL_BOUNCER_KEY";
};
};
diff --git a/os/srv/default.nix b/os/srv/default.nix
index 073067d..c89d029 100644
--- a/os/srv/default.nix
+++ b/os/srv/default.nix
@@ -44,6 +44,5 @@
./virtualization.nix
./wireguard.nix
./yggdrasil.nix
- ./zfs.nix
];
}
diff --git a/os/srv/dns.nix b/os/srv/dns.nix
index 2da4c66..b8a973f 100644
--- a/os/srv/dns.nix
+++ b/os/srv/dns.nix
@@ -77,12 +77,21 @@ in
];
rewrites = [
{
- domain = "router.local";
- answer = config.os.core.network.ips.vm1-opnsense;
+ domain = "router.lan";
+ answer = config.os.core.network.ips.opnsense-vm;
+ }
+ {
+ domain = "nas.lan";
+ answer = config.os.core.network.ips.bare-metal;
+ }
+ {
+ domain = "ldap.${masterDomain}";
+ answer = config.os.core.network.ips.gateway-vm;
}
];
port = 53;
upstream_dns = [ "127.0.0.1:${toString unboundPort}" ];
+ fallback_dns = [ "9.9.9.9" ];
bootstrap_dns = [ "9.9.9.9" ];
cache_size = 536870912;
anonymize_client_ip = true;
diff --git a/os/srv/gaming.nix b/os/srv/gaming.nix
index 730dcd2..b9b6766 100644
--- a/os/srv/gaming.nix
+++ b/os/srv/gaming.nix
@@ -103,35 +103,10 @@ in
}
(lib.mkIf cfg.steam.enableSls {
+ environment.systemPackages = [
+ inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped
+ ];
home-manager.users.${username} = {
- imports = [ inputs.sls-steam.homeModules.sls-steam ];
-
- services.sls-steam.config = {
- PlayNotOwnedGames = true;
- DisableFamilyShareLock = true;
- SafeMode = false;
- AdditionalApps = [
- 2483190
- 4439260
- 4439270
- 4439280
- 4439300
- 4439750
- 4439790
- 4439800
- 4439810
- 4439820
- 4439830
- 4440380
- 4444140
- 4444150
- 4520350
- 4520360
- 4562050
- ];
- };
- home.packages = [ inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped ];
-
xdg.desktopEntries = {
steam = {
name = "Steam";
diff --git a/os/srv/lldap.nix b/os/srv/lldap.nix
index 1463ab6..6755dfe 100644
--- a/os/srv/lldap.nix
+++ b/os/srv/lldap.nix
@@ -2,7 +2,6 @@
config,
lib,
masterDomain,
- securityTemplates,
...
}:
let
@@ -49,16 +48,6 @@ in
environmentFile = config.sops.secrets."lldap/env_file".path;
};
- os.cluster.nginxProxies."lldap.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
-
- locations."/" = {
- proxyPass = "http://${config.os.core.network.ips.gateway-vm}:17170";
- extraConfig = securityTemplates.restrictToInternal;
- };
- };
-
networking.firewall.extraInputRules = ''
ip saddr 10.0.0.0/24 tcp dport 3890 accept
'';
diff --git a/os/srv/monero.nix b/os/srv/monero.nix
index 6b50e1d..eb21abc 100644
--- a/os/srv/monero.nix
+++ b/os/srv/monero.nix
@@ -81,24 +81,24 @@ in
};
services.tor = lib.mkIf cfg.service.tor.enable {
- onionServices."xmr-rpc" = {
- to = [
- {
- port = 18081;
- address = config.os.core.network.ips.vm9-relays;
- }
- ];
- };
+ # onionServices."xmr-rpc" = {
+ # to = [
+ # {
+ # port = 18081;
+ # address = config.os.core.network.ips.relay-vm;
+ # }
+ # ];
+ # };
};
services.i2pd = lib.mkIf cfg.service.i2p.enable {
- tunnels.server."xmr-rpc" = {
- port = 18081;
- address = config.os.core.network.ips.vm9-relays;
- keys = "xmr-rpc-key.dat";
- inbound.length = 3;
- outbound.length = 3;
- };
+ # tunnels.server."xmr-rpc" = {
+ # port = 18081;
+ # address = config.os.core.network.ips.relay-vm;
+ # keys = "xmr-rpc-key.dat";
+ # inbound.length = 3;
+ # outbound.length = 3;
+ # };
};
os.cluster.nginxProxies."xmr.${masterDomain}" = {
@@ -106,7 +106,7 @@ in
forceSSL = true;
locations."/" = {
- proxyPass = "http://${config.os.core.network.ips.vm9-relays}:18081";
+ proxyPass = "http://${config.os.core.network.ips.relay-vm}:18081";
extraConfig = ''
proxy_read_timeout 600s;
proxy_send_timeout 600s;
diff --git a/os/srv/simplex.nix b/os/srv/simplex.nix
index 51b9577..ca22192 100644
--- a/os/srv/simplex.nix
+++ b/os/srv/simplex.nix
@@ -73,19 +73,6 @@ in
};
};
- services.nginx = {
- streamConfig = ''
- server {
- listen 5223;
- proxy_pass 127.0.0.1:${toString internalSmpPort};
- }
- server {
- listen 5224;
- proxy_pass 127.0.0.1:${toString internalXftpPort};
- }
- '';
- };
-
systemd.tmpfiles.rules = [
"d /var/lib/simplex/smp/config 0755 root root -"
"d /var/lib/simplex/smp/logs 0755 root root -"
diff --git a/os/srv/ssh.nix b/os/srv/ssh.nix
index d36df00..63b2034 100644
--- a/os/srv/ssh.nix
+++ b/os/srv/ssh.nix
@@ -10,11 +10,7 @@ let
in
{
options.os.srv.ssh = {
- server = {
- enable = lib.mkEnableOption "enables the ssh server module";
- enableInitrd = lib.mkEnableOption "enables ssh access during initrd";
- microvm.enable = lib.mkEnableOption "enables ssh for microvms";
- };
+ server.enable = lib.mkEnableOption "enables the ssh server module";
client = {
enable = lib.mkEnableOption "enables the ssh client module";
createAliases = lib.mkEnableOption "enables system-wide SSH shortcuts";
@@ -32,19 +28,19 @@ in
addr = "127.0.0.1";
port = 22;
}
- {
- addr = config.os.core.network.lan.ip;
- port = 22;
- }
- {
- addr = config.os.core.network.wg.ip;
- port = 22;
- }
- {
- addr = config.os.core.network.hs.ip;
- port = 22;
- }
- ];
+ ]
+ ++ lib.optional (config.os.core.network ? lan.ip) {
+ addr = config.os.core.network.lan.ip;
+ port = 22;
+ }
+ ++ lib.optional (config.os.core.network ? wg.ip) {
+ addr = config.os.core.network.wg.ip;
+ port = 22;
+ }
+ ++ lib.optional (config.os.core.network ? hs.ip) {
+ addr = config.os.core.network.hs.ip;
+ port = 22;
+ };
hostKeys = [
{
path = "/etc/ssh/ssh_host_ed25519_key";
@@ -54,7 +50,7 @@ in
settings = {
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
- PermitRootLogin = if cfg.server.microvm.enable then "prohibit-password" else "no";
+ PermitRootLogin = "no";
PubkeyAcceptedAlgorithms = "ssh-ed25519";
};
@@ -69,41 +65,6 @@ in
);
})
- (lib.mkIf (cfg.server.enable && cfg.server.microvm.enable) {
- users.users.root.openssh.authorizedKeys.keys = [
- "${keys.main} adikro@disroot.org"
- ];
- })
-
- (lib.mkIf (cfg.server.enable && cfg.server.enableInitrd) {
- assertions = [
- {
- assertion = config.os.srv.sops.enable;
- message = "required for storing the ssh key";
- }
- ];
- sops.secrets."initrd_ssh_key" = {
- path = "/etc/secrets/initrd/ssh_host_ed25519_key";
- };
- boot = {
- initrd = {
- secrets = {
- "/etc/secrets/initrd/ssh_host_ed25519_key" = config.sops.secrets.initrd_ssh_key.path;
- };
- network = {
- enable = true;
- ssh = {
- enable = true;
- port = 2222;
- authorizedKeys = [ "${keys.main}" ];
- hostKeys = [ "/etc/secrets/initrd/ssh_host_ed25519_key" ];
- };
- };
- };
- kernelParams = [ "ip=dhcp" ];
- };
- })
-
(lib.mkIf cfg.client.enable {
programs.ssh.startAgent = true;
services.gnome.gcr-ssh-agent.enable = false;
diff --git a/os/vms/microvms.nix b/os/vms/microvms.nix
index 0a24c60..e2e1a0f 100644
--- a/os/vms/microvms.nix
+++ b/os/vms/microvms.nix
@@ -23,9 +23,6 @@ in
};
config = lib.mkMerge [
- (lib.mkIf cfg.enable {
- })
-
(lib.mkIf cfg.net-core.enable {
microvm.vms.net-core = {
autostart = true;