diff options
| author | adikro <adikro@disroot.org> | 2026-05-23 21:32:00 +0200 |
|---|---|---|
| committer | adikro <adikro@disroot.org> | 2026-05-23 21:32:00 +0200 |
| commit | c7abbc56562f9745d9d1bb29f3c0d4874425e92c (patch) | |
| tree | 2e652540993b69b0d33260902b85ea1c2207d3f6 | |
| parent | c6b6a3e6c702834eac2b633db2ed4c397b4ae113 (diff) | |
updates
| -rw-r--r-- | flake.lock | 106 | ||||
| -rw-r--r-- | hm/soft/chat.nix | 1 | ||||
| -rw-r--r-- | hm/soft/nixvim/nixvim.nix | 41 | ||||
| -rw-r--r-- | hosts/desktop/configuration.nix | 22 | ||||
| -rw-r--r-- | hosts/desktop/home.nix | 2 | ||||
| -rw-r--r-- | hosts/thinkpad/configuration.nix | 1 | ||||
| -rw-r--r-- | hosts/thinkpad/home.nix | 1 | ||||
| -rw-r--r-- | os/srv/authelia.nix | 55 | ||||
| -rw-r--r-- | os/srv/default.nix | 4 | ||||
| -rw-r--r-- | os/srv/firewall.nix | 10 | ||||
| -rw-r--r-- | os/srv/gaming.nix | 6 | ||||
| -rw-r--r-- | os/srv/lldap.nix | 24 | ||||
| -rw-r--r-- | os/srv/nginx.nix | 25 | ||||
| -rw-r--r-- | os/srv/nix-helper.nix | 6 | ||||
| -rw-r--r-- | os/srv/ntopng.nix | 20 | ||||
| -rw-r--r-- | os/srv/ssh.nix | 111 | ||||
| -rw-r--r-- | os/srv/syncthing.nix | 194 | ||||
| -rw-r--r-- | os/srv/vpn.nix | 49 | ||||
| -rw-r--r-- | os/srv/wireguard.nix | 146 |
19 files changed, 542 insertions, 282 deletions
@@ -87,11 +87,11 @@ "flake-compat": { "flake": false, "locked": { - "lastModified": 1751685974, - "narHash": "sha256-NKw96t+BgHIYzHUjkTK95FqYRVKB8DHpVhefWSz/kTw=", + "lastModified": 1777699697, + "narHash": "sha256-Eg9b/rq/ECYwNwEXs5i9wHyhxNI0JrYx2srdI2uZMaQ=", "ref": "refs/heads/main", - "rev": "549f2762aebeff29a2e5ece7a7dc0f955281a1d1", - "revCount": 92, + "rev": "382052b74656a369c5408822af3f2501e9b1af81", + "revCount": 94, "type": "git", "url": "https://git.lix.systems/lix-project/flake-compat.git" }, @@ -161,11 +161,11 @@ ] }, "locked": { - "lastModified": 1769996383, - "narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=", + "lastModified": 1778716662, + "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "57928607ea566b5db3ad13af0e57e921e6b12381", + "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb", "type": "github" }, "original": { @@ -294,11 +294,11 @@ ] }, "locked": { - "lastModified": 1779103424, - "narHash": "sha256-hBYJz5jnRDjACPrwdD064zwMW+s5bdNlG/lNQipLhgM=", + "lastModified": 1779507042, + "narHash": "sha256-7wOwi8B6D0BYsieZCnHZZj2sNUzgJhLoIVSfkwB7lxQ=", "owner": "nix-community", "repo": "home-manager", - "rev": "dd71501fb7005264feb4de78444a2e1518cd4f66", + "rev": "509ed3c603349a9d43de9e2ae6613baea6bd5b34", "type": "github" }, "original": { @@ -337,11 +337,11 @@ "spectrum": "spectrum" }, "locked": { - "lastModified": 1779043402, - "narHash": "sha256-1dH6yiwEck1n3oz5TDUV5TGbwNqu46eNTVHbhFO2U5k=", + "lastModified": 1779300350, + "narHash": "sha256-slQySSmaIewOxdZXF0/g0GSiVg7vJy209Yjs7fDNms8=", "owner": "microvm-nix", "repo": "microvm.nix", - "rev": "77024c22f4ddf509137fc732094888d1ffe631e2", + "rev": "9755fd345bd64d1c75ba12b63089c926dd5d886e", "type": "github" }, "original": { @@ -352,11 +352,11 @@ }, "mnw": { "locked": { - "lastModified": 1777828893, - "narHash": "sha256-gVWVnmyNr74BVKfhMMZDWkhx2699dhmZ2g0W8TTHtkk=", + "lastModified": 1778541201, + "narHash": "sha256-n0twkzWexzjsoDycOTvvQNuGEdg62UiNHYcFCduYpKI=", "owner": "Gerg-L", "repo": "mnw", - "rev": "c1c0b544bfabe6669b5a6a0383ccb475fe60258b", + "rev": "1a3573fc9d2486738fe0b2cacc5cd10dd5f3a445", "type": "github" }, "original": { @@ -408,16 +408,16 @@ ] }, "locked": { - "lastModified": 1776882296, - "narHash": "sha256-DWZozXwMsgvUqfVlL1mQ8dOxW7GJ/8CdyaDN+1niZRg=", + "lastModified": 1779233504, + "narHash": "sha256-YIKEyzh0NFQlD0O92LQQNMoVCDwV8yw1Xz0Iu+4ZC5U=", "owner": "feel-co", "repo": "ndg", - "rev": "ab7d78d4884b3a34968cf9fa3d16c0c1246d5c6e", + "rev": "86f6644411a64d5413711895b7cf6e0e1be465b6", "type": "github" }, "original": { "owner": "feel-co", - "ref": "refs/tags/v2.6.0", + "ref": "refs/tags/v2.8.0", "repo": "ndg", "type": "github" } @@ -434,11 +434,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1778942403, - "narHash": "sha256-SPCWvqeVySTNUgX/shARpRl5fi/NnkObUgDGR/Aco4c=", + "lastModified": 1779477998, + "narHash": "sha256-acWBiLVnoEmabvXQEfzuL9h0h+jhdzNcoCsJfpj1/88=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "daefca3370581223fedc24d0101c4915a3689f9e", + "rev": "1209504f60d88fa5bea843471c19aedb87f7e1e2", "type": "github" }, "original": { @@ -467,11 +467,11 @@ "niri-unstable": { "flake": false, "locked": { - "lastModified": 1778858756, - "narHash": "sha256-9VvAHNoi2wd0fxLfJOPChZMS7l6rhCtAJmpd59Hv5rw=", + "lastModified": 1779374863, + "narHash": "sha256-qKWgJ2MUODpg+b8tOwWMdMKREvs8TdGBz63SHaQZCeA=", "owner": "YaLTeR", "repo": "niri", - "rev": "cd5ac3e5e04bb5a11276d3c755fa25242818e05f", + "rev": "4294948cf1c70c50e938383c2c865d7ca455ac7e", "type": "github" }, "original": { @@ -487,11 +487,11 @@ ] }, "locked": { - "lastModified": 1778999476, - "narHash": "sha256-Zs4Y8kPVsSLHVI7aOYXnZC55LhFOKqE+mf19dBBUiWw=", + "lastModified": 1779519816, + "narHash": "sha256-3WPfrkP9Idr0ex2BLqy6WsuXLR93D0JdcRSh/YE/9qs=", "owner": "powerofthe69", "repo": "nix-gaming-edge", - "rev": "3d3ab84d554b50cf915a49766df6c3eb90436b5c", + "rev": "a8126c9e7ed0b1f169cd1870f1a69a6169982a9a", "type": "github" }, "original": { @@ -502,11 +502,11 @@ }, "nixos-hardware": { "locked": { - "lastModified": 1779099457, - "narHash": "sha256-u73aVD/lUmmT3JV+kPDztl7zPwQKd0eobD1AbJltaGs=", + "lastModified": 1779258371, + "narHash": "sha256-j1iZsLy6oFApqR1oiDmHhvkwxXqcNi0aoSJj643LuwU=", "owner": "NixOS", "repo": "nixos-hardware", - "rev": "8792fab9d4a6454a9201675f01326f827ce35ead", + "rev": "c97bc4d15bd3473dd095e8e8ba57330ab1943a77", "type": "github" }, "original": { @@ -549,11 +549,11 @@ }, "nixpkgs-stable": { "locked": { - "lastModified": 1778737229, - "narHash": "sha256-6xWoytx8jFW4PF1GjRm/i/53trbpKGfz6zjzQGBr4cI=", + "lastModified": 1779102034, + "narHash": "sha256-vZJZjLo513IeI8hjzHFc6TDezUd4uCE2Eq4SNO3DNNg=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "d7a713c0b7e47c908258e71cba7a2d77cc8d71d5", + "rev": "687f05a9184cad4eaf905c48b63649e3a86f5433", "type": "github" }, "original": { @@ -565,11 +565,11 @@ }, "nixpkgs-stable_2": { "locked": { - "lastModified": 1778737229, - "narHash": "sha256-6xWoytx8jFW4PF1GjRm/i/53trbpKGfz6zjzQGBr4cI=", + "lastModified": 1779102034, + "narHash": "sha256-vZJZjLo513IeI8hjzHFc6TDezUd4uCE2Eq4SNO3DNNg=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "d7a713c0b7e47c908258e71cba7a2d77cc8d71d5", + "rev": "687f05a9184cad4eaf905c48b63649e3a86f5433", "type": "github" }, "original": { @@ -581,11 +581,11 @@ }, "nixpkgs_2": { "locked": { - "lastModified": 1778869304, - "narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=", + "lastModified": 1779357205, + "narHash": "sha256-cCO8aTqss5x9Ky8GWkpY0Hy5fyTZEbtifSUV8QjSzic=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "d233902339c02a9c334e7e593de68855ad26c4cb", + "rev": "f83fc3c307e74bc5fd5adb7eb6b8b13ffd2a36e1", "type": "github" }, "original": { @@ -620,11 +620,11 @@ "systems": "systems_2" }, "locked": { - "lastModified": 1779092748, - "narHash": "sha256-NliK7JRrPh44IbVwoLi/s7dleSfwoGXgu69d1PjhYdw=", + "lastModified": 1779554657, + "narHash": "sha256-qjLcUp7DBpmSUL+nVjLymp2nEvAzeKKoAVDCRgZYxFk=", "owner": "nix-community", "repo": "nixvim", - "rev": "2e60ad952a9f4b0a1c275a79a1a44c8e3a088789", + "rev": "1a380f12453ba97ad8cc9c60f223afb1cb8bace8", "type": "github" }, "original": { @@ -645,11 +645,11 @@ "systems": "systems_3" }, "locked": { - "lastModified": 1779018518, - "narHash": "sha256-RUmjcuxbaa8UKsd5rUO5bqDe9YxGBDLXd4tFFBi351E=", + "lastModified": 1779461836, + "narHash": "sha256-iV6reLT7o1XfofI+mLuFZl7TdDXzsnniXge6aFXjjrc=", "owner": "NotAShelf", "repo": "nvf", - "rev": "cd45295f9c65ca81f323155660ba83d427bd0154", + "rev": "21849b62be17c6657accbf4e0c9e1afe57e27ea3", "type": "github" }, "original": { @@ -714,11 +714,11 @@ "systems": "systems_5" }, "locked": { - "lastModified": 1779026498, - "narHash": "sha256-oQw4/UqDpE/K0lkc+zFXdWsNKps9p0rZg6ybMwVDhsM=", + "lastModified": 1779154764, + "narHash": "sha256-D3wp7vR3+ktTNJ54rUWHIK6Y5tGeNXDD4FBO785wl0E=", "owner": "kuokuo123", "repo": "otter-launcher", - "rev": "380ceb9d2cf9b02854fbd3be39177e5e151fae6c", + "rev": "b1c2c0992403f52dff1f5754cc250ee6e121e342", "type": "github" }, "original": { @@ -1113,11 +1113,11 @@ "rust-overlay": "rust-overlay_2" }, "locked": { - "lastModified": 1778801438, - "narHash": "sha256-TtawbMZ+tgKAiDpkJJw7m2OLOJHUbRZB0xLDXBxTPck=", + "lastModified": 1779505360, + "narHash": "sha256-V9emUCEpW4lf73LreHeCpdH48R4GCmeEVE7za8V+QM0=", "owner": "sxyazi", "repo": "yazi", - "rev": "3f5cc47a4852cbffbd8536507ae7499d3da1f0b7", + "rev": "d9cd1907d91927a36efe7296eee2a7d8975230f8", "type": "github" }, "original": { diff --git a/hm/soft/chat.nix b/hm/soft/chat.nix index d7f0020..b886656 100644 --- a/hm/soft/chat.nix +++ b/hm/soft/chat.nix @@ -11,6 +11,7 @@ in options.hm.soft.chat.enable = lib.mkEnableOption "chatting apps"; config = lib.mkIf cfg.enable { home.packages = with pkgs; [ + telegram-desktop simplex-chat-desktop signal-desktop equibop diff --git a/hm/soft/nixvim/nixvim.nix b/hm/soft/nixvim/nixvim.nix index efd348e..7013c27 100644 --- a/hm/soft/nixvim/nixvim.nix +++ b/hm/soft/nixvim/nixvim.nix @@ -24,6 +24,17 @@ in globals.mapleader = " "; + autoCmd = [ + { + event = [ "BufWritePost" ]; + pattern = [ "*/dotfiles/waybar/.config/waybar/*" ]; + callback.__raw = '' + function() + vim.fn.jobstart({ "systemctl", "--user", "restart", "waybar.service" }) + end + ''; + } + ]; clipboard = { providers.wl-copy.enable = true; register = "unnamedplus"; @@ -61,12 +72,6 @@ in } { mode = "n"; - key = "<leader>gs"; - action = "<cmd>Neogit<CR>"; - options.desc = "Neogit Status"; - } - { - mode = "n"; key = "<leader>ff"; action = "<cmd>Telescope find_files<CR>"; options.desc = "Find Files"; @@ -109,30 +114,6 @@ in } { mode = "n"; - key = "<leader>ma"; - action = "<cmd>MCpattern<CR>"; - options.desc = "Select all matches of pattern"; - } - { - mode = "n"; - key = "<leader>ha"; - action = ''<cmd>lua require("harpoon.mark").add_file()<CR>''; - options.desc = "Harpoon: Mark File"; - } - { - mode = "n"; - key = "<leader>hh"; - action = ''<cmd>lua require("harpoon.ui").toggle_quick_menu()<CR>''; - options.desc = "Harpoon: Show Menu"; - } - { - mode = "n"; - key = "<leader>xx"; - action = "<cmd>Trouble diagnostics toggle<CR>"; - options.desc = "Toggle Trouble (Diagnostics)"; - } - { - mode = "n"; key = "<leader>p"; action = "<cmd>Telescope yank_history<CR>"; options.desc = "Open Yank History"; diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix index 0f0f63e..adfb5a3 100644 --- a/hosts/desktop/configuration.nix +++ b/hosts/desktop/configuration.nix @@ -54,7 +54,14 @@ srv = { bluetooth.enable = true; tailscale.enable = true; - ssh.enable = true; + ssh = { + server.enable = true; + client = { + enable = true; + createAliases = true; + }; + enableSigning = true; + }; firewall.enable = true; yggdrasil.enable = true; i2p.enable = true; @@ -81,9 +88,18 @@ nix-helper.enable = true; monero.wallet.enable = true; sops.enable = true; - syncthing.enable = true; + syncthing = { + enable = true; + activeFolders = [ + "openmw-config" + "openmw-mods" + "game-saves" + "keepass" + "sync" + "music" + ]; + }; omnisearch.enable = true; - vpn.enable = true; }; wm = { enable = true; diff --git a/hosts/desktop/home.nix b/hosts/desktop/home.nix index 5a4f373..cdce283 100644 --- a/hosts/desktop/home.nix +++ b/hosts/desktop/home.nix @@ -94,6 +94,8 @@ }; home.packages = with pkgs; [ + cosmic-files + feishin tmux gimp stow diff --git a/hosts/thinkpad/configuration.nix b/hosts/thinkpad/configuration.nix index 0fe2945..9f27ac0 100644 --- a/hosts/thinkpad/configuration.nix +++ b/hosts/thinkpad/configuration.nix @@ -79,7 +79,6 @@ monero.wallet.enable = true; sops.enable = true; syncthing.enable = true; - vpn.enable = true; }; wm = { enable = true; diff --git a/hosts/thinkpad/home.nix b/hosts/thinkpad/home.nix index 8676adc..9b6dd95 100644 --- a/hosts/thinkpad/home.nix +++ b/hosts/thinkpad/home.nix @@ -64,6 +64,5 @@ home.packages = with pkgs; [ stow gimp - telegram-desktop ]; } diff --git a/os/srv/authelia.nix b/os/srv/authelia.nix new file mode 100644 index 0000000..a7a8c19 --- /dev/null +++ b/os/srv/authelia.nix @@ -0,0 +1,55 @@ +{ + config, + lib, + masterDomain, + ... +}: +let + cfg = config.os.srv.authelia; +in +{ + options.os.srv.authelia.enable = lib.mkEnableOption "enables authelia scanning"; + options.os.services.authelia.extraRules = lib.mkOption { + type = lib.types.listOf lib.types.attrs; + default = [ ]; + description = "Additional access control rules to be appended to Authelia."; + }; + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = config.os.srv.sops.enable; + message = "Required for password secure password storing"; + } + ]; + services.authelia.instances.main = { + enable = true; + secrets = { + jwtSecretFile = config.sops.secrets."authelia/jwt_secret".path; + storageEncryptionKeyFile = config.sops.secrets."authelia/encryptionKey".path; + }; + settings = { + theme = "dark"; + authentication_backend = { + ldap = { + address = "ldap://127.0.0.1:3890"; + implementation = "lldap"; + base_dn = "dc=example,dc=com"; + user = "uid=authelia,ou=people,dc=example,dc=com"; + password_file = config.sops.secrets."lldap/bind_password".path; + }; + }; + access_control = { + default_policy = "deny"; + rules = [ + { + domain = "auth.${masterDomain}"; + policy = "bypass"; + } + ] + ++ config.os.services.authelia.extraRules; + }; + session.domain = masterDomain; + }; + }; + }; +} diff --git a/os/srv/default.nix b/os/srv/default.nix index d42fdb9..9bba42b 100644 --- a/os/srv/default.nix +++ b/os/srv/default.nix @@ -2,6 +2,7 @@ { imports = [ ./aide.nix + ./authelia.nix ./backup.nix ./bluetooth.nix ./clamav.nix @@ -13,10 +14,12 @@ ./gaming.nix ./i2p.nix ./kdeconnect.nix + ./lldap.nix ./monero.nix ./nfs.nix ./nginx.nix ./nix-helper.nix + ./ntopng.nix ./oci.nix ./omnisearch.nix ./opnsense.nix @@ -28,7 +31,6 @@ ./tailscale.nix ./tor.nix ./virtualization.nix - ./vpn.nix ./wireguard.nix ./yggdrasil.nix ./zfs.nix diff --git a/os/srv/firewall.nix b/os/srv/firewall.nix index 9242007..bc06ffe 100644 --- a/os/srv/firewall.nix +++ b/os/srv/firewall.nix @@ -4,19 +4,13 @@ let in { options.os.srv.firewall = { - enable = lib.mkEnableOption "enables the firewall"; + enable = lib.mkEnableOption "enables the nixos firewall and nftables"; }; config = lib.mkIf cfg.enable { networking = { + firewall.enable = true; nftables.enable = true; - - firewall = { - enable = true; - - allowedTCPPorts = [ ]; - allowedUDPPorts = [ ]; - }; }; }; } diff --git a/os/srv/gaming.nix b/os/srv/gaming.nix index 1e3e9cd..28e309a 100644 --- a/os/srv/gaming.nix +++ b/os/srv/gaming.nix @@ -107,9 +107,9 @@ in home.packages = [ inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped ]; xdg.desktopEntries = { - "SLSsteam" = { - name = "SLSsteam"; - comment = "Library modification for Steam"; + steam = { + name = "Steam"; + comment = "Library modified Steam client"; exec = "${ lib.getExe' inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped "SLSsteam" } %U"; diff --git a/os/srv/lldap.nix b/os/srv/lldap.nix new file mode 100644 index 0000000..1cf43e4 --- /dev/null +++ b/os/srv/lldap.nix @@ -0,0 +1,24 @@ +{ config, lib, ... }: +let + cfg = config.os.srv.lldap; +in +{ + options.os.srv.lldap.enable = lib.mkEnableOption "enables lldap scanning"; + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = config.os.srv.sops.enable; + message = "Required for password secure password storing"; + } + ]; + services.lldap = { + enable = true; + settings = { + ldap_base_dn = "dc=example,dc=com"; + ldap_port = 3890; + http_port = 17170; + }; + environmentFile = config.sops.secrets."lldap/env".path; + }; + }; +} diff --git a/os/srv/nginx.nix b/os/srv/nginx.nix index b0c01a7..f0207b3 100644 --- a/os/srv/nginx.nix +++ b/os/srv/nginx.nix @@ -1,4 +1,9 @@ -{ config, lib, ... }: +{ + config, + lib, + pkgs, + ... +}: let cfg = config.os.srv.nginx; @@ -17,14 +22,30 @@ in config = lib.mkIf cfg.enable { services.nginx = { enable = true; + package = pkgs.nginx.override { openssl = pkgs.libressl; }; recommendedProxySettings = true; recommendedTlsSettings = true; recommendedOptimisation = true; recommendedGzipSettings = true; + virtualHosts = { + default = { + serverName = "_"; + default = true; + rejectSSL = true; + locations."/".return = "444"; + }; + }; + }; + + security.acme = { + acceptTerms = true; + defaults.email = "adikro@disroot.org"; }; - networking.firewall.allowedTCPPorts = lib.mkOptional cfg.openFirewall [ + # users.users.nginx.extraGroups = [ "acme" ]; + + networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [ 80 443 ]; diff --git a/os/srv/nix-helper.nix b/os/srv/nix-helper.nix index 5e5e133..9734043 100644 --- a/os/srv/nix-helper.nix +++ b/os/srv/nix-helper.nix @@ -2,7 +2,6 @@ config, lib, pkgs, - username, ... }: let @@ -12,10 +11,7 @@ in options.os.srv.nix-helper.enable = lib.mkEnableOption "enables nix-helper"; config = lib.mkIf cfg.enable { nix.settings = { - trusted-users = [ - "root" - "${username}" - ]; + allowed-users = [ "@users" ]; experimental-features = [ "nix-command" "flakes" diff --git a/os/srv/ntopng.nix b/os/srv/ntopng.nix new file mode 100644 index 0000000..3c11534 --- /dev/null +++ b/os/srv/ntopng.nix @@ -0,0 +1,20 @@ +{ config, lib, ... }: +let + cfg = config.os.srv.ntopng; +in +{ + options.os.srv.ntopng.enable = lib.mkEnableOption "enables ntopng monitoring"; + config = lib.mkIf cfg.enable { + services.ntopng = { + enable = true; + httpPort = 3000; + extraConfig = "--packet-fanout"; + + # TODO fill interfaces + interfaces = [ + "" + "" + ]; + }; + }; +} diff --git a/os/srv/ssh.nix b/os/srv/ssh.nix index 089fb32..2c7a4ac 100644 --- a/os/srv/ssh.nix +++ b/os/srv/ssh.nix @@ -6,50 +6,85 @@ }: let cfg = config.os.srv.ssh; - keys = { - main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC610CJfgc3yII7MpLVqzEzQGa8Tsm+dih+CTXHXTnv4"; - oci = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCgWmRbNTP/kcaZ8JNV1boVTZ/FQVV4qP/9eTKL9buzDvz9HJdgyWmbCiVZicNSert31IRdWOF/wm1sFjZ48nSkGDHbrnc//MPSdHULTx+kMES/NW9SZwwpaquFIJClrObysxrFYBAqweD+DJ3bp451WIymBs7lRBMNKPgoHBpJ5WN2CfIQjl60Jqnli7ML5seCsrquPEemcMPr1TFPmrFCbirzgDVkzCLL5kOowSD2uprtSA08fFm/pZ6nZh6KTQaEgPO4zR9tK+NQ46oCynWwBTI7JOPB4/LtIOiC5TjEUrkXZ/sJzpCBiNPYSRI8RWnAD0N/uVFJ4EYPUKLO2C/d"; - }; + keys.main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC610CJfgc3yII7MpLVqzEzQGa8Tsm+dih+CTXHXTnv4"; in { - options.os.srv.ssh.enable = lib.mkEnableOption "enables ssh server setup"; - - config = lib.mkIf cfg.enable { - services.openssh = { - enable = true; - settings = { - PasswordAuthentication = false; - KbdInteractiveAuthentication = false; - }; + options.os.srv.ssh = { + server = { + enable = lib.mkEnableOption "enables the ssh server module"; + enableWireguard = lib.mkEnableOption "only allows connections from wireguard"; }; + client = { + enable = lib.mkEnableOption "enables the ssh client module"; + createAliases = lib.mkEnableOption "enables system-wide SSH shortcuts"; + }; + enableSigning = lib.mkEnableOption "enables signing git commits with ssh keys"; + }; - programs.ssh.startAgent = true; - services.gnome.gcr-ssh-agent.enable = false; - - users.users.${username}.openssh.authorizedKeys.keys = [ "${keys.main} adikro@disroot.org" ]; - - environment.etc."ssh/allowed_signers".text = "adikro@disroot.org ${keys.main}"; - home-manager.users.${username} = { - programs.ssh = { + config = lib.mkMerge [ + (lib.mkIf cfg.server.enable { + services.openssh = { enable = true; - enableDefaultConfig = false; - matchBlocks = { - "github.com codeberg.org" = { - identityFile = "~/.ssh/main_id_ed25519.pub"; - identitiesOnly = true; - user = "git"; - }; - "oci" = { - hostname = "130.162.223.123"; - user = "opc"; - }; + hostKeys = [ + { + path = "/etc/ssh/ssh_host_ed25519_key"; + type = "ed25519"; + } + ]; + settings = { + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + PermitRootLogin = "no"; + + PubkeyAcceptedAlgorithms = "ssh-ed25519"; }; }; - home.file = { - ".ssh/main_id_ed25519.pub".text = keys.main; - ".ssh/oci.pub".text = keys.oci; - }; - }; - }; + + users.users.${username}.openssh.authorizedKeys.keys = [ + "${keys.main} adikro@disroot.org" + ]; + }) + (lib.mkIf (cfg.server.enable && cfg.server.enableWireguard) { + services.openssh.listenAddresses = [ + { + addr = "10.255.0.1"; + } + ]; + }) + + (lib.mkIf cfg.client.enable { + programs.ssh.startAgent = true; + services.gnome.gcr-ssh-agent.enable = false; + }) + + (lib.mkIf (cfg.client.enable && cfg.client.createAliases) { + programs.ssh.extraConfig = '' + Host github.com codeberg.org + IdentityFile /home/${username}/.ssh/main_id_ed25519.pub + IdentitiesOnly yes + User git + + Host oci + HostName 130.162.223.123 + User opc + + Host bibus + HostName bibus.top + User opc + + Host bibus-local + HostName 10.255.0.1 + user opc + ''; + systemd.tmpfiles.rules = [ + "d /home/${username}/.ssh 0700 ${username} users - -" + "f /home/${username}/.ssh/main_id_ed25519.pub 0644 ${username} users - ${keys.main}" + ]; + }) + + (lib.mkIf cfg.enableSigning { + environment.etc."ssh/allowed_signers".text = "adikro@disroot.org ${keys.main}"; + }) + ]; } diff --git a/os/srv/syncthing.nix b/os/srv/syncthing.nix index 28806f1..bcbf665 100644 --- a/os/srv/syncthing.nix +++ b/os/srv/syncthing.nix @@ -6,10 +6,116 @@ }: let cfg = config.os.srv.syncthing; - syncDirs = lib.mapAttrsToList (_: folder: folder.path) config.services.syncthing.settings.folders; + allFolders = { + "openmw-config" = { + path = "/home/${username}/.config/openmw"; + id = "openmw-config"; + devices = [ "oci" ]; + versioning = { + type = "simple"; + params.keep = "3"; + }; + ignorePatterns = [ + "settings.cfg" + "*.log" + ]; + }; + + "openmw-mods" = { + path = "/home/${username}/games/openmw"; + id = "openmw-mods"; + devices = [ "oci" ]; + versioning = { + type = "trashcan"; + params.cleanoutDays = "7"; + }; + }; + + "game-saves" = { + path = "/home/${username}/.saves"; + id = "game-saves"; + devices = [ "oci" ]; + versioning = { + type = "staggered"; + params = { + cleanInterval = "3600"; + maxAge = "2592000"; + }; + }; + }; + + "keepass" = { + path = "/home/${username}/.keepass"; + id = "keepass"; + devices = [ + { + name = "oci"; + encryptionPasswordFile = config.sops.secrets."syncthing/encryption/keepass".path; + } + ]; + versioning = { + type = "staggered"; + params = { + cleanInterval = "3600"; + maxAge = "31536000"; + }; + }; + }; + + "sync" = { + path = "/home/${username}/sync"; + id = "sync"; + devices = [ + { + name = "oci"; + encryptionPasswordFile = config.sops.secrets."syncthing/encryption/sync".path; + } + ]; + versioning = { + type = "staggered"; + params = { + cleanInterval = "3600"; + maxAge = "15552000"; + }; + }; + }; + + "music" = { + path = "/storage/music"; + id = "music"; + devices = [ "oci" ]; + versioning = { + type = "trashcan"; + params.cleanoutDays = "14"; + }; + }; + }; + activeFoldersSet = lib.filterAttrs (name: _: builtins.elem name cfg.activeFolders) allFolders; + + syncDirs = lib.mapAttrsToList (_: folder: folder.path) activeFoldersSet; in { - options.os.srv.syncthing.enable = lib.mkEnableOption "enables syncthing syncing"; + options.os.srv.syncthing = { + enable = lib.mkEnableOption "enables syncthing syncing"; + + activeFolders = lib.mkOption { + type = lib.types.listOf ( + lib.types.enum [ + "openmw-config" + "openmw-mods" + "game-saves" + "keepass" + "sync" + "music" + ] + ); + default = [ + "keepass" + "sync" + ]; + description = "List of Syncthing folders to enable and sync on this specific machine."; + }; + }; config = lib.mkIf cfg.enable { systemd.tmpfiles.rules = map (path: "d ${path} 0755 ${username} users -") syncDirs; @@ -23,89 +129,7 @@ in settings = { devices."oci".id = "DQXGVDC-KGPM6RK-5NDEBJJ-R7PEWYZ-N6Z3WFZ-TSVJG5X-235SHG4-4BEJNQJ"; - folders = { - "openmw-config" = { - path = "/home/${username}/.config/openmw"; - id = "openmw-config"; - devices = [ - { - name = "oci"; - encryptionPasswordFile = config.sops.secrets."syncthing/encryption/openmw-config".path; - } - ]; - versioning = { - type = "simple"; - params.keep = "3"; - }; - ignorePatterns = [ - "settings.cfg" - "*.log" - ]; - }; - - "openmw-mods" = { - path = "/home/${username}/games/openmw"; - id = "openmw-mods"; - devices = [ - { - name = "oci"; - encryptionPasswordFile = config.sops.secrets."syncthing/encryption/openmw-mods".path; - } - ]; - versioning = { - type = "trashcan"; - params.cleanoutDays = "7"; - }; - }; - - "game-saves" = { - path = "/home/${username}/.saves"; - id = "game-saves"; - devices = [ - { - name = "oci"; - encryptionPasswordFile = config.sops.secrets."syncthing/encryption/game-saves".path; - } - ]; - versioning = { - type = "staggered"; - params = { - cleanInterval = "3600"; - maxAge = "2592000"; - }; - }; - }; - - "keepass" = { - path = "/home/${username}/.keepass"; - id = "keepass"; - devices = [ - { - name = "oci"; - encryptionPasswordFile = config.sops.secrets."syncthing/encryption/keepass".path; - } - ]; - versioning = { - type = "simple"; - params.keep = "10"; - }; - }; - - "sync" = { - path = "/home/${username}/sync"; - id = "sync"; - devices = [ - { - name = "oci"; - encryptionPasswordFile = config.sops.secrets."syncthing/encryption/sync".path; - } - ]; - versioning = { - type = "simple"; - params.keep = "3"; - }; - }; - }; + folders = activeFoldersSet; }; }; }; diff --git a/os/srv/vpn.nix b/os/srv/vpn.nix deleted file mode 100644 index 28c7a9e..0000000 --- a/os/srv/vpn.nix +++ /dev/null @@ -1,49 +0,0 @@ -{ - config, - lib, - pkgs, - ... -}: -let - cfg = config.os.srv.vpn; - netCfg = config.os.core.network; -in -{ - options.os.srv.vpn.enable = lib.mkEnableOption "enables vpn stuff"; - - config = lib.mkIf (cfg.enable && netCfg.enable) { - networking.networkmanager.ensureProfiles = { - environmentFiles = [ config.sops.secrets."vpn/warp_private_key".path ]; - profiles.cloudflare-warp = { - connection = { - id = "cloudflare-warp"; - type = "wireguard"; - interface-name = "wg0"; - autoconnect = false; - }; - wireguard = { - mtu = 1200; - private-key = "$WG_KEY"; - }; - "wireguard-peer.bmXOC+F1FxEMF9dyiK2H5/1SUtzH0JuVo51h2wPfgyo=" = { - endpoint = "engage.cloudflareclient.com:2408"; - allowed-ips = "0.0.0.0/0;::/0;"; - }; - ipv4 = { - method = "manual"; - address1 = "172.16.0.2/32"; - dns = "1.1.1.1;1.0.0.1;"; - }; - ipv6 = { - method = "manual"; - address1 = "2606:4700:110:84c7:36c4:e444:5efb:b108/128"; - dns = "2606:4700:4700::1111;2606:4700:4700::1001;"; - }; - }; - }; - environment.systemPackages = with pkgs; [ - wgcf - wireguard-tools - ]; - }; -} diff --git a/os/srv/wireguard.nix b/os/srv/wireguard.nix index 4b9dbc4..15675a4 100644 --- a/os/srv/wireguard.nix +++ b/os/srv/wireguard.nix @@ -1,9 +1,149 @@ -{ config, lib, ... }: +{ + config, + lib, + hostname, + masterDomain, + ... +}: let cfg = config.os.srv.wireguard; in { - options.os.srv.wireguard.enable = lib.mkEnableOption "enables wireguard vpn"; - config = lib.mkIf cfg.enable { + options.os.srv.wireguard = { + enable = lib.mkEnableOption "enables wireguard vpn"; + + role = lib.mkOption { + type = lib.types.enum [ + "server" + "client" + ]; + default = "client"; + description = "where the machine is accepting connections or connecting"; + }; + + server = { + externalInterface = lib.mkOption { + type = lib.types.str; + default = "eth0"; + description = "The public WAN interface of the server"; + }; + + peers = lib.mkOption { + type = lib.types.listOf ( + lib.types.submodule { + options = { + name = lib.mkOption { type = lib.types.str; }; + publicKey = lib.mkOption { type = lib.types.str; }; + }; + } + ); + default = [ ]; + description = "List of client peers authorized to connect to this server"; + }; + }; + + client = { + index = lib.mkOption { + type = lib.types.nullOr lib.types.int; + default = null; + description = "The assigned host index number for the client IP address"; + }; + + routeAllTraffic = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Routes 100% of your internet traffic through the server when active"; + }; + }; }; + + config = lib.mkIf cfg.enable ( + lib.mkMerge [ + { + assertions = [ + { + assertion = config.os.srv.sops.enable; + message = "required for wg private key"; + } + ]; + + sops.secrets."wg_private_key/${hostname}" = { + owner = "root"; + group = "root"; + mode = "0600"; + }; + } + + (lib.mkIf (cfg.role == "server") { + assertions = [ + { + assertion = config.os.srv.firewall.enable; + message = "required for opening ports and passthrough"; + } + ]; + boot.kernel.sysctl."net.ipv4.ip_forward" = 1; + networking.firewall.allowedUDPPorts = [ 51280 ]; + + networking.nftables = { + tables.wg-nat = { + family = "inet"; + content = '' + chain forward { + type filter hook forward priority 0; policy accept; + iifname "wg0" accept + oifname "wg0" accept + } + + chain postrouting { + type nat hook postrouting priority 100; policy accept; + iifname "wg0" oifname "${cfg.server.externalInterface}" masquerade + } + ''; + }; + }; + + networking.wireguard.interfaces.wg0 = { + ips = [ "10.255.1.1/16" ]; + listenPort = 51280; + privateKeyFile = config.sops.secrets."wg_private_key/${hostname}".path; + + peers = lib.imap1 (i: peer: { + publicKey = peer.publicKey; + allowedIPs = [ "10.255.0.${toString i}/32" ]; + persistentKeepalive = 25; + }) cfg.server.peers; + }; + }) + + (lib.mkIf (cfg.role == "client") { + assertions = [ + { + assertion = cfg.client.index != null; + message = "WireGuard client role requires a valid 'client.index' integer designation."; + } + ]; + + networking.nameservers = [ + "10.255.1.1" + "9.9.9.9" + ]; + + networking.wireguard.interfaces.wg0 = { + ips = [ "10.255.0.${toString cfg.client.index}/16" ]; + privateKeyFile = config.sops.secrets."wg_private_key/${hostname}".path; + + peers = [ + { + # TODO get the server public key + publicKey = ""; + endpoint = "${masterDomain}:51280"; + persistentKeepalive = 25; + + allowedIPs = if cfg.client.routeAllTraffic then [ "0.0.0.0/0" ] else [ "10.255.0.0/16" ]; + } + ]; + }; + }) + ] + ); } |
