summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authoradikro <adikro@disroot.org>2026-06-21 22:37:42 +0200
committeradikro <adikro@disroot.org>2026-06-21 22:37:42 +0200
commit30f34740891096471b5663704fbbd9bf67ebe885 (patch)
treee454527368c67be4aeb81bc15ac3a0b6cc424f67
parent630da5d0639cada53e26a03f579df0a7bac3b17a (diff)
updates and pinning omnisearch
-rw-r--r--flake.lock84
-rw-r--r--flake.nix3
-rw-r--r--hm/soft/browser.nix4
-rw-r--r--hosts/desktop/configuration.nix10
-rw-r--r--hosts/desktop/home.nix1
-rw-r--r--os/core/networking.nix78
-rw-r--r--os/srv/default.nix1
-rw-r--r--os/srv/firewall.nix16
-rw-r--r--os/srv/grafana.nix85
-rw-r--r--os/srv/loki.nix93
-rw-r--r--os/srv/netdata.nix23
-rw-r--r--os/srv/nginx.nix1
-rw-r--r--os/srv/prometheus.nix50
-rw-r--r--os/srv/vector.nix79
-rw-r--r--os/vms/net-core.nix6
15 files changed, 340 insertions, 194 deletions
diff --git a/flake.lock b/flake.lock
index a6b0dff..481872c 100644
--- a/flake.lock
+++ b/flake.lock
@@ -374,11 +374,11 @@
]
},
"locked": {
- "lastModified": 1781642113,
- "narHash": "sha256-mAR7KTS9rjreTcXCNqfCbN96mnhJO8lDQq1vl7GviBQ=",
+ "lastModified": 1782051614,
+ "narHash": "sha256-xBRAhYLEXcjp8hM2tkkTTLb6PWU7VDxDoogl25g7Ezs=",
"owner": "nix-community",
"repo": "home-manager",
- "rev": "df4e0465717a2d34f05b8ccd967275aaf3ceaa01",
+ "rev": "d1ccd0721ec599866622665f3651e19e6e2d4c6a",
"type": "github"
},
"original": {
@@ -417,11 +417,11 @@
"spectrum": "spectrum"
},
"locked": {
- "lastModified": 1781389237,
- "narHash": "sha256-Ne1/E5XNUq0gleaQz0vW5R4xf/0h/uEZ+bOW1aNjeQk=",
+ "lastModified": 1781738058,
+ "narHash": "sha256-wgKY6pbZbFpBXae+8bjvJtW1Z9qekZergGly44n2qZw=",
"owner": "microvm-nix",
"repo": "microvm.nix",
- "rev": "6ad601df0a07d9855c5e8f9b81135ecaf7c287eb",
+ "rev": "225b35c204e29efb5bbe9b55b1a38b07b3fca2af",
"type": "github"
},
"original": {
@@ -480,28 +480,6 @@
"type": "github"
}
},
- "ndg": {
- "inputs": {
- "nixpkgs": [
- "nvf",
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1779233504,
- "narHash": "sha256-YIKEyzh0NFQlD0O92LQQNMoVCDwV8yw1Xz0Iu+4ZC5U=",
- "owner": "feel-co",
- "repo": "ndg",
- "rev": "86f6644411a64d5413711895b7cf6e0e1be465b6",
- "type": "github"
- },
- "original": {
- "owner": "feel-co",
- "ref": "refs/tags/v2.8.0",
- "repo": "ndg",
- "type": "github"
- }
- },
"niri": {
"inputs": {
"niri-stable": "niri-stable",
@@ -514,11 +492,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
},
"locked": {
- "lastModified": 1781610921,
- "narHash": "sha256-PXyfDFGyW+UYteu3uHJgp49sFHRU16iocf5K2ltqn3M=",
+ "lastModified": 1781795508,
+ "narHash": "sha256-VKrApQ3WCkEe9D8DbaeFjGqLAh7zqYGYjbQYtY5ikxc=",
"owner": "sodiboo",
"repo": "niri-flake",
- "rev": "e5857dc58304b3d5bbac6340820f7d4450688538",
+ "rev": "493ce1e33e72f86312584f331c8cf52b3432ec99",
"type": "github"
},
"original": {
@@ -547,11 +525,11 @@
"niri-unstable": {
"flake": false,
"locked": {
- "lastModified": 1781588278,
- "narHash": "sha256-Fw/Zo0hwgn9ulgY5duQy51WHtqpNoLjNDZYLdEI1SS4=",
+ "lastModified": 1781781064,
+ "narHash": "sha256-Ii/koEm/sRyg65qbAQWqEgboSEIhdH0EL4KglAc14p0=",
"owner": "YaLTeR",
"repo": "niri",
- "rev": "fdb6d85fc78355762bcf3cf71fe4037681a766f9",
+ "rev": "49fc6117fd6c043adaa2ead316b82db5ed735d36",
"type": "github"
},
"original": {
@@ -589,11 +567,11 @@
]
},
"locked": {
- "lastModified": 1781300555,
- "narHash": "sha256-anhcFNgXdTEe1KPBAHvxLxDzjEbrt+YZ2O4tfq3WiRA=",
+ "lastModified": 1781892035,
+ "narHash": "sha256-e46EhlHo0jupcYCLE4QJRitd3+y+RgIQYNcfcCdLbKg=",
"owner": "simple-nixos-mailserver",
"repo": "nixos-mailserver",
- "rev": "51726d7b7fd94aa69829fd42749a803914cbf3b7",
+ "rev": "c37fd9c40877450716692b6478e6dda330dfc46a",
"type": "gitlab"
},
"original": {
@@ -720,11 +698,11 @@
"systems": "systems_2"
},
"locked": {
- "lastModified": 1781637822,
- "narHash": "sha256-6Fwwt8BBGF5rqwGPhj/9ZMyyjXeJQzeHHJQfPuqJP3I=",
+ "lastModified": 1782062554,
+ "narHash": "sha256-v2J6/S33H2ms6jz3qr6in0UUlGFqUW46+iB3hMJDuD4=",
"owner": "nix-community",
"repo": "nixvim",
- "rev": "d43c763fd9fae0912bdb4103cd842f26fea5b0ed",
+ "rev": "b3e7b2d2e568f29becae04217242ed18a90febc4",
"type": "github"
},
"original": {
@@ -738,18 +716,17 @@
"flake-compat": "flake-compat_2",
"flake-parts": "flake-parts_2",
"mnw": "mnw",
- "ndg": "ndg",
"nixpkgs": [
"nixpkgs"
],
"systems": "systems_3"
},
"locked": {
- "lastModified": 1781534482,
- "narHash": "sha256-d3UIqXuigQhsc7amQkZ7F+SWnaJFAxIROE2f2X+pzUs=",
+ "lastModified": 1781997110,
+ "narHash": "sha256-6D6xtYN5t1kZGNd69eMZsRBkgX5Df1roErn/kFR1C+A=",
"owner": "NotAShelf",
"repo": "nvf",
- "rev": "63d8fc82d652c23419a837e2b2934dd4bead04f3",
+ "rev": "320f60b97075a58d38b90fc5e39f478421dbd38a",
"type": "github"
},
"original": {
@@ -776,6 +753,7 @@
"url": "https://git.bwaaa.monster/omnisearch"
},
"original": {
+ "rev": "24f9909badd4e7aa1f3aeef717b93e9b71c20a4e",
"shallow": false,
"type": "git",
"url": "https://git.bwaaa.monster/omnisearch"
@@ -931,11 +909,11 @@
"rust-overlay": "rust-overlay"
},
"locked": {
- "lastModified": 1781585488,
- "narHash": "sha256-NrD3WYckzuQ2oH4t5td4TWzzUtTF0SVrrIhKdU9IgLM=",
+ "lastModified": 1781902199,
+ "narHash": "sha256-VD/bm9ZinziQdfUZDeTXd4H+T+TQ5WHwWXK9FpOniUs=",
"owner": "gabm",
"repo": "Satty",
- "rev": "1199a4417000b14105cf61e0b4ee2189a00796b4",
+ "rev": "32b2be3618a5617b196942b8fc023f998b44beca",
"type": "github"
},
"original": {
@@ -994,11 +972,11 @@
]
},
"locked": {
- "lastModified": 1780547341,
- "narHash": "sha256-Gq8KNx5A7hBB3uGJaj6eQfLDIz5YdLu92gqBcvHvoUo=",
+ "lastModified": 1781943681,
+ "narHash": "sha256-NFHmA7H47adqiyp+0iEOyZOQhmigDqA/NBAlf4imB6U=",
"owner": "Mic92",
"repo": "sops-nix",
- "rev": "9ed65852b6257fbeae4355bc24ecfea307ca759a",
+ "rev": "420f8d2e9882911f65cfac15cc706f639ba96cca",
"type": "github"
},
"original": {
@@ -1177,11 +1155,11 @@
"rust-overlay": "rust-overlay_2"
},
"locked": {
- "lastModified": 1781438303,
- "narHash": "sha256-cBw2N3U0hoZO33s24Z/022AthIJtTnZk1jwgnxObfBY=",
+ "lastModified": 1781971032,
+ "narHash": "sha256-lxliQTpjaN1iF2ntK2gJ4UO55HM4w47Hcqwe6gBo85o=",
"owner": "sxyazi",
"repo": "yazi",
- "rev": "f1e93d7f528b22fdeaf66b198c73e32a7040a90c",
+ "rev": "4f45ddb514c3db558da0c5fffabaaa44f18cc18e",
"type": "github"
},
"original": {
diff --git a/flake.nix b/flake.nix
index 7ea91e0..f925335 100644
--- a/flake.nix
+++ b/flake.nix
@@ -68,8 +68,7 @@
# Other
omnisearch = {
- # url = "git+https://git.bwaaa.monster/omnisearch";
- url = "git+https://git.bwaaa.monster/omnisearch?shallow=0";
+ url = "git+https://git.bwaaa.monster/omnisearch?shallow=0&rev=24f9909badd4e7aa1f3aeef717b93e9b71c20a4e";
inputs.nixpkgs.follows = "nixpkgs";
};
diff --git a/hm/soft/browser.nix b/hm/soft/browser.nix
index b53804e..1a87fe4 100644
--- a/hm/soft/browser.nix
+++ b/hm/soft/browser.nix
@@ -1,16 +1,20 @@
{
config,
lib,
+ inputs,
+ pkgs,
...
}:
let
cfg = config.hm.soft.browser;
+ pkgs-stable = import inputs.nixpkgs-stable { inherit (pkgs) system; };
in
{
options.hm.soft.browser.librewolf.enable = lib.mkEnableOption "Enables the librewolf browser";
config = lib.mkIf cfg.librewolf.enable {
programs.librewolf = {
enable = true;
+ package = pkgs-stable.librewolf;
# policies = {
# DisableTelemetry = true;
# DisableFirefoxStudies = true;
diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix
index d14cc88..7e78c91 100644
--- a/hosts/desktop/configuration.nix
+++ b/hosts/desktop/configuration.nix
@@ -43,7 +43,10 @@
size = 16;
};
};
- network.enable = true;
+ network = {
+ enable = true;
+ enableFirewall = true;
+ };
security = {
enable = true;
sandboxing.enable = true;
@@ -62,7 +65,6 @@
};
enableSigning = true;
};
- firewall.enable = true;
yggdrasil.enable = true;
i2p.enable = true;
tor = {
@@ -116,8 +118,4 @@
config.boot.kernelPackages.nct6687d
];
};
- nixpkgs.config.permittedInsecurePackages = [
- "librewolf-151.0.2-1"
- "librewolf-unwrapped-151.0.2-1"
- ];
}
diff --git a/hosts/desktop/home.nix b/hosts/desktop/home.nix
index e4461cd..38f1469 100644
--- a/hosts/desktop/home.nix
+++ b/hosts/desktop/home.nix
@@ -97,5 +97,6 @@
tmux
gimp
stow
+ antigravity-cli
];
}
diff --git a/os/core/networking.nix b/os/core/networking.nix
index 6cfe4ad..638ecd4 100644
--- a/os/core/networking.nix
+++ b/os/core/networking.nix
@@ -10,22 +10,29 @@ in
{
options.os.core.network = {
enable = lib.mkEnableOption "system-wide networking setup";
+ enableFirewall = lib.mkEnableOption "integrated zero-trust nftables firewall layers";
+
+ isVM = lib.mkOption {
+ type = lib.types.bool;
+ default = false;
+ description = "Set to true if this configuration is running inside a guest VM. Set to false for the bare-metal host.";
+ };
ips = lib.mkOption {
type = lib.types.attrsOf lib.types.str;
- default = {
- router = "10.0.0.1";
+ default = rec {
+ router = vm1-opnsense;
host = "10.0.0.2";
- vm1-opnsense = "10.0.0.3";
- vm2-gateway = "10.0.0.4";
- vm3-monitor = "10.0.0.5";
- vm4-media = "10.0.0.6";
- vm5-sandbox = "10.0.0.7";
- vm6-storage = "10.0.0.8";
- vm7-web = "10.0.0.9";
- vm8-mail = "10.0.0.10";
- vm9-relays = "10.0.0.11";
- vm10-mc = "10.0.0.12";
+ vm1-opnsense = "10.0.0.1";
+ vm2-gateway = "10.0.0.3";
+ vm3-monitor = "10.0.0.4";
+ vm4-media = "10.0.0.5";
+ vm5-sandbox = "10.0.0.6";
+ vm6-storage = "10.0.0.7";
+ vm7-web = "10.0.0.8";
+ vm8-mail = "10.0.0.9";
+ vm9-relays = "10.0.0.10";
+ vm10-mc = "10.0.0.11";
};
description = "Central registry of static IP allocations for the cluster.";
};
@@ -50,7 +57,7 @@ in
};
range = lib.mkOption {
type = lib.types.str;
- default = "10.0.0.0/8";
+ default = "10.0.0.0/24";
description = "The broader subnet block representing the physical home network.";
};
};
@@ -116,6 +123,13 @@ in
];
})
+ (lib.mkIf (cfg.profile == "client" && cfg.enableFirewall) {
+ networking = {
+ firewall.enable = true;
+ nftables.enable = true;
+ };
+ })
+
(lib.mkIf (cfg.profile == "server") {
networking = {
useNetworkd = true;
@@ -123,24 +137,48 @@ in
};
systemd.network = {
enable = true;
+ wait-online.enable = lib.mkIf (!cfg.isVM) false;
- netdevs."10-br-srv" = {
- netdevConfig = {
- Name = "br-srv";
- Kind = "bridge";
+ netdevs = lib.mkIf (!cfg.isVM) {
+ "10-br-srv" = {
+ netdevConfig = {
+ Name = "br-srv";
+ Kind = "bridge";
+ };
};
};
networks."20-host-management" = {
- matchConfig.Name = "br-srv";
- address = [ "10.0.0.2/24" ];
- gateway = [ "10.0.0.1" ];
+ matchConfig.Name = if cfg.isVM then "eth0" else "br-srv";
+ address = [ "${cfg.lan.ip}/24" ];
+ gateway = [ cfg.ips.router ];
networkConfig.LinkLocalAddressing = "no";
};
};
boot.kernel.sysctl = {
"net.ipv4.ip_nonlocal_bind" = 1;
+ "net.ipv4.ip_forward" = 1;
};
})
+ (lib.mkIf
+ (
+ cfg.profile == "server"
+ && cfg.enableFirewall
+ && cfg.isVM
+ && config.networking.hostName != "vm2-gateway"
+ )
+ {
+ networking.nftables.enable = true;
+ networking.firewall = {
+ enable = true;
+ extraCommands = ''
+ nft add table ip nat 2>/dev/null || true
+ nft flush table ip nat
+ nft add chain ip nat PREROUTING { type nat hook prerouting priority dstnat \; }
+ nft add rule ip nat PREROUTING ip saddr ${cfg.ips.vm2-gateway} ip daddr ${cfg.lan.ip} redirect
+ '';
+ };
+ }
+ )
]
);
}
diff --git a/os/srv/default.nix b/os/srv/default.nix
index a808328..34aa179 100644
--- a/os/srv/default.nix
+++ b/os/srv/default.nix
@@ -9,7 +9,6 @@
./crowdsec.nix
./dns.nix
./files.nix
- ./firewall.nix
./gaming.nix
./grafana.nix
./headscale.nix
diff --git a/os/srv/firewall.nix b/os/srv/firewall.nix
deleted file mode 100644
index bc06ffe..0000000
--- a/os/srv/firewall.nix
+++ /dev/null
@@ -1,16 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.firewall;
-in
-{
- options.os.srv.firewall = {
- enable = lib.mkEnableOption "enables the nixos firewall and nftables";
- };
-
- config = lib.mkIf cfg.enable {
- networking = {
- firewall.enable = true;
- nftables.enable = true;
- };
- };
-}
diff --git a/os/srv/grafana.nix b/os/srv/grafana.nix
index 3e1333b..5428818 100644
--- a/os/srv/grafana.nix
+++ b/os/srv/grafana.nix
@@ -19,26 +19,80 @@ in
config = lib.mkIf cfg.enable {
services.grafana = {
enable = true;
- settings.server = {
- http_addr = "127.0.0.1";
- http_port = 3000;
+ openFirewall = true;
+
+ # Might use later
+ # declarativePlugins = [ ];
+
+ settings = {
+ server = {
+ protocol = "http";
+ http_port = 3000;
+ http_addr = "0.0.0.0";
+ domain = "grafana.${masterDomain}";
+ root_url = "https://grafana.${masterDomain}";
+ enforceDomain = true;
+ enable_gzip = true;
+ };
+ database = {
+ wal = true;
+ };
+ security = {
+ admin_user = "opc";
+ # TODO: Generate password to use in sops-nix
+ # admin_password = "sops"
+ admin_email = "adikro@disroot.org";
+ # TODO generate secret key and put it in sops-nix
+ # secret_key = "sops";
+ disable_gravatar = true;
+ cookie_secure = true;
+ cookie_samesite = "lax";
+ # security
+ allow_embedding = false;
+ strict_transport_security = true;
+
+ disable_initial_admin_creation = false;
+ disable_brute_force_login_protection = false;
+ };
+ # TODO setup mailing
+ # smtp = { enabled = true; };
+ analytics.feedback_links_enabled = false;
};
provision = {
enable = true;
- datasources.settings.datasources = [
- {
- name = "Prometheus";
- type = "prometheus";
- url = "http://127.0.0.1:9090";
- }
- {
- name = "Loki";
- type = "loki";
- url = "http://127.0.0.1:3100";
- }
- ];
+ datasources.settings = {
+ prune = true;
+
+ datasources = [
+ {
+ name = "Prometheus";
+ type = "prometheus";
+ url = "http://127.0.0.1:9090";
+ access = "proxy";
+ isDefault = true;
+ editable = false;
+ }
+ {
+ name = "Loki";
+ type = "loki";
+ url = "http://127.0.0.1:3100";
+ access = "proxy";
+ editable = false;
+ }
+ ];
+ };
};
+ # dashboards.settings = {
+ # providers = [
+ # {
+ # name = "default";
+ # type = "file";
+ # options.path = "/var/lib/grafana/dashboards";
+ # }
+ # ];
+ # };
};
+
os.srv.grafana.proxyConfig = {
"grafana.${masterDomain}" = {
enableACME = true;
@@ -46,6 +100,7 @@ in
locations."/" = {
proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000";
+ proxyWebsockets = true;
extraConfig = securityTemplates.restrictToInternal;
};
};
diff --git a/os/srv/loki.nix b/os/srv/loki.nix
index 2388432..84b94d8 100644
--- a/os/srv/loki.nix
+++ b/os/srv/loki.nix
@@ -1,9 +1,4 @@
-{
- config,
- lib,
- pkgs,
- ...
-}:
+{ config, lib, ... }:
let
cfg = config.os.srv.loki;
in
@@ -12,46 +7,56 @@ in
config = lib.mkIf cfg.enable {
services.loki = {
enable = true;
- configFile = pkgs.writeText "loki-config.yaml" (
- builtins.toJSON {
- auth_enabled = false;
- server = {
- http_listen_port = 3100;
- };
- common = {
- ring = {
- kvstore = {
- store = "inmemory";
- };
- };
- instance_interface_names = [ "lo" ];
+ configuration = {
+ server = {
+ http_listen_address = "0.0.0.0";
+ http_compress_responses = true;
+ };
+
+ common = {
+ instance_addr = "127.0.0.1";
+ path_prefix = "/var/lib/loki";
+ replication_factor = 1;
+
+ storage.filesystem = {
+ chunks_directory = "/var/lib/loki/chunks";
+ rules_directory = "/var/lib/loki/rules";
};
- ingester = {
- lifecycler = {
- address = "127.0.0.1";
+ };
+
+ schema_config.configs = [
+ {
+ from = "2026-01-01";
+ store = "tsdb";
+ object_store = "filesystem";
+ schema = "v13";
+ index = {
+ prefix = "loki_index_";
+ period = "24h";
};
- };
- storage_config = {
- filesystem = {
- directory = "/var/lib/loki/chunks";
- };
- };
- schema_config = {
- configs = [
- {
- from = "2020-10-24";
- store = "tsdb";
- object_store = "filesystem";
- schema = "v13";
- index = {
- prefix = "index_";
- period = "24h";
- };
- }
- ];
- };
- }
- );
+ }
+ ];
+
+ ingester.wal.enabled = true;
+
+ limits_config = {
+ max_entries_limit_per_query = 10000;
+ reject_old_samples_max_age = "720h";
+ retention_period = "90d";
+ volume_enabled = true;
+ };
+
+ compactor = {
+ enabled = true;
+ retention_enabled = true;
+ retention_delete_delay = "1h";
+ compactor_window = "168h";
+ };
+
+ querier.query_timeout = "5m";
+ query_range.out_of_order_time_shifting = "5m";
+ analytics.reporting_enabled = false;
+ };
};
};
}
diff --git a/os/srv/netdata.nix b/os/srv/netdata.nix
index 87854d4..a7b4300 100644
--- a/os/srv/netdata.nix
+++ b/os/srv/netdata.nix
@@ -9,7 +9,14 @@ let
cfg = config.os.srv.netdata;
in
{
- options.os.srv.netdata.enable = lib.mkEnableOption "enables netdata monitoring";
+ options.os.srv.netdata = {
+ enable = lib.mkEnableOption "enables netdata monitoring";
+ proxyConfig = lib.mkOption {
+ type = lib.types.attrs;
+ default = { };
+ };
+ };
+
config = lib.mkIf cfg.enable {
services.netdata = {
enable = true;
@@ -21,13 +28,15 @@ in
};
};
- services.nginx.virtualHosts."netdata.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
+ os.srv.netdata.proxyConfig = {
+ "netdata.${masterDomain}" = {
+ enableACME = true;
+ forceSSL = true;
- locations."/" = {
- proxyPass = "http://127.0.0.1:19999";
- extraConfig = securityTemplates.restrictToInternal;
+ locations."/" = {
+ proxyPass = "http://${config.os.core.network.ips.host}:19999";
+ extraConfig = securityTemplates.restrictToInternal;
+ };
};
};
};
diff --git a/os/srv/nginx.nix b/os/srv/nginx.nix
index a38b703..5161920 100644
--- a/os/srv/nginx.nix
+++ b/os/srv/nginx.nix
@@ -26,6 +26,7 @@ in
allow ::1;
allow ${config.os.core.network.lan.range};
+ allow 10.1.0.0/24;
allow ${config.os.core.network.wg.range};
allow ${config.os.core.network.hs.range};
diff --git a/os/srv/prometheus.nix b/os/srv/prometheus.nix
index afccef4..5b133be 100644
--- a/os/srv/prometheus.nix
+++ b/os/srv/prometheus.nix
@@ -1,4 +1,9 @@
-{ config, lib, ... }:
+{
+ config,
+ lib,
+ masterDomain,
+ ...
+}:
let
cfg = config.os.srv.prometheus;
in
@@ -9,26 +14,39 @@ in
enable = true;
port = 9090;
- alertmanagers = [
- {
- static_configs = [ { targets = [ "127.0.0.1:9093" ]; } ];
- }
- ];
-
scrapeConfigs = [
{
job_name = "prometheus";
static_configs = [ { targets = [ "127.0.0.1:9090" ]; } ];
}
{
+ job_name = "node-hardware";
+ static_configs = [ { targets = [ "127.0.0.1:9100" ]; } ];
+ }
+ {
job_name = "node_exporter";
static_configs = [ { targets = [ "127.0.0.1:9100" ]; } ];
}
{
+ job_name = "bare_metal_host_netdata";
+ scheme = "https";
+ metrics_path = "/api/v1/allmetrics";
+ params = {
+ format = [ "prometheus" ];
+ };
+ static_configs = [
+ { targets = [ "netdata.${masterDomain}" ]; }
+ ];
+ }
+ {
job_name = "uptime_kuma";
metrics_path = "/metrics";
static_configs = [ { targets = [ "127.0.0.1:3001" ]; } ];
}
+ {
+ job_name = "network-latency";
+ static_configs = [ { targets = [ "127.0.0.1:9374" ]; } ];
+ }
];
exporters = {
node = {
@@ -37,28 +55,10 @@ in
port = 9100;
};
- alertmanager = {
- enable = true;
- port = 9093;
- configuration = {
- route = {
- receiver = "default-receiver";
- group_by = [ "alertname" ];
- };
- receivers = [
- {
- name = "default-receiver";
- }
- ];
- };
- };
-
smokeping = {
enable = true;
listenAddress = "127.0.0.1";
- pingInterval = "1s";
-
hosts = [
"10.0.0.1" # Personal Router
"192.168.0.1" # ISP Modem Box
diff --git a/os/srv/vector.nix b/os/srv/vector.nix
new file mode 100644
index 0000000..a216a19
--- /dev/null
+++ b/os/srv/vector.nix
@@ -0,0 +1,79 @@
+{ config, lib, ... }:
+let
+ cfg = config.os.srv.vector;
+in
+{
+ options.os.srv.vector = {
+ enable = lib.mkEnableOption "Vector observability data framework";
+ agent.enable = lib.mkEnableOption "local client daemon to pull journals & stream upstream";
+ aggregator.enable = lib.mkEnableOption "central receiver role to bundle, parse, and push to Loki";
+ };
+
+ config = lib.mkIf cfg.enable {
+ services.vector = {
+ enable = true;
+ journaldAccess = lib.mkIf cfg.agent.enable true;
+ validateConfig = true;
+
+ settings = lib.mkMerge [
+ (lib.mkIf cfg.agent.enable {
+ sources.systemd_journal = {
+ type = "journald";
+ exclude_units = [ "vector.service" ];
+ };
+
+ transforms.filter_logs = {
+ type = "filter";
+ inputs = [ "systemd_journal" ];
+ condition = ''.status != "debug" && .status != "trace"'';
+ };
+
+ sinks.to_aggregator = {
+ type = "vector";
+ inputs = [ "filter_logs" ];
+ address = "${config.os.core.network.ips.vm3-monitor}:9000";
+ };
+ })
+
+ (lib.mkIf cfg.aggregator.enable {
+ sources.upstream_agents = {
+ type = "vector";
+ address = "0.0.0.0:9000";
+ version = "2";
+ };
+
+ sources.opnsense_syslog = {
+ type = "syslog";
+ address = "${cfg.aggregator.listenAddress}:5140";
+ mode = "udp";
+ };
+
+ sinks.loki_backend = {
+ type = "loki";
+ inputs = [
+ "upstream_agents"
+ "opnsense_syslog"
+ ];
+ endpoint = "http://127.0.0.1:3100";
+ labels = {
+ host = "{{ host }}";
+ unit = "{{`{{_SYSTEMD_UNIT}}`}}";
+ source_type = "{{ type }}";
+ };
+ buffer = {
+ type = "disk";
+ max_size = 5 * (1024 * 1024 * 1024);
+ when_full = "block";
+ };
+ };
+ encoding.codec = "json";
+ })
+ ];
+ };
+
+ networking.firewall = lib.mkIf cfg.aggregator.enable {
+ allowedTCPPorts = [ 9000 ];
+ allowedUDPPorts = [ 5140 ];
+ };
+ };
+}
diff --git a/os/vms/net-core.nix b/os/vms/net-core.nix
index 392aaf5..a9a1c47 100644
--- a/os/vms/net-core.nix
+++ b/os/vms/net-core.nix
@@ -1,8 +1,4 @@
-{
- pkgs,
- inputs,
- ...
-}:
+{ pkgs, inputs, ... }:
{
system.stateVersion = "26.11";