summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authoradikro <adikro@disroot.org>2026-06-15 13:49:27 +0200
committeradikro <adikro@disroot.org>2026-06-15 13:49:27 +0200
commitce7fb7ddd3267291a8d692cc6381dad606288aa5 (patch)
tree5b3ab65c22713de2b084682e6f560af8877d1987
parent1eba5398fd09f98bd11cbf8c3b80f20bb9ce1f2d (diff)
revamped proxy configs
-rw-r--r--flake.lock66
-rw-r--r--flake.nix4
-rw-r--r--hm/soft/nixvim/nixvim.nix4
-rw-r--r--hosts/bibus-lab/configuration.nix5
-rw-r--r--hosts/thinkpad/configuration.nix1
-rw-r--r--hosts/thinkpad/home.nix1
-rw-r--r--os/core/networking.nix19
-rw-r--r--os/srv/dns.nix36
-rw-r--r--os/srv/monero.nix36
-rw-r--r--os/srv/nginx.nix18
10 files changed, 121 insertions, 69 deletions
diff --git a/flake.lock b/flake.lock
index d1387eb..6583254 100644
--- a/flake.lock
+++ b/flake.lock
@@ -306,11 +306,11 @@
]
},
"locked": {
- "lastModified": 1779043781,
- "narHash": "sha256-7YoRc6jOuQUI0yv3qBHFhc60G/RG0LwVsKkN90UkPn4=",
+ "lastModified": 1781478132,
+ "narHash": "sha256-XGKD/DId5Eont4ytPV7LfGvykDRalMWx4pbkRVUNzxY=",
"owner": "Mjoyufull",
"repo": "fsel",
- "rev": "6b6ae52e3a2c254007e8a2c332a8d5de99428ba5",
+ "rev": "8a12d4f35e78297f3e2d55e026185710bff38338",
"type": "github"
},
"original": {
@@ -374,11 +374,11 @@
]
},
"locked": {
- "lastModified": 1781189114,
- "narHash": "sha256-5inaamLgUMWy+MOBE9ChF9QAF1o/74LFuHkI0W/9rqc=",
+ "lastModified": 1781497404,
+ "narHash": "sha256-9GAF8sSsnkyCVCWkomXR0T+zdSxyUlfPt6neQidimdg=",
"owner": "nix-community",
"repo": "home-manager",
- "rev": "486595d2cf49cfcd649b58a284fa11ac0e34da22",
+ "rev": "1285cd3d6882a9847f2d56ed5541b3350c8a6162",
"type": "github"
},
"original": {
@@ -417,11 +417,11 @@
"spectrum": "spectrum"
},
"locked": {
- "lastModified": 1780588968,
- "narHash": "sha256-zQk+GqLO+T9taIl1UUt3swvaOksWJxL7PL8K0+Fc/Hs=",
+ "lastModified": 1781389237,
+ "narHash": "sha256-Ne1/E5XNUq0gleaQz0vW5R4xf/0h/uEZ+bOW1aNjeQk=",
"owner": "microvm-nix",
"repo": "microvm.nix",
- "rev": "4d3fb17437944ea57eef2b9e6108ca777b1209ca",
+ "rev": "6ad601df0a07d9855c5e8f9b81135ecaf7c287eb",
"type": "github"
},
"original": {
@@ -514,11 +514,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
},
"locked": {
- "lastModified": 1781038035,
- "narHash": "sha256-X+uFuOQVWiouzl7eSV5JUgg4CAbv779QgEqOxIo6Gls=",
+ "lastModified": 1781234038,
+ "narHash": "sha256-jo4a47qDgsx1F1i0MtHZl12FfzqKJOES25vbm0ZUxeI=",
"owner": "sodiboo",
"repo": "niri-flake",
- "rev": "27982962e1dee4994b05d2b0b4a29f8de2529a55",
+ "rev": "eb5789cba8d37802d330df5a13c691622c83121f",
"type": "github"
},
"original": {
@@ -589,11 +589,11 @@
]
},
"locked": {
- "lastModified": 1781101699,
- "narHash": "sha256-5erzbe5hgJufkqBr3KCYElX4nW+xfJJrFDOvweWZR3w=",
+ "lastModified": 1781301671,
+ "narHash": "sha256-rq6WOopxq3U2AGEWO80o9LIJDYcYIdgw6jyl+y+19w8=",
"owner": "simple-nixos-mailserver",
"repo": "nixos-mailserver",
- "rev": "d59fcaeef8144328b8801f987f1a3af7ca6aec41",
+ "rev": "661ec59a97ccee13a63f79280b282eb6f7d3f817",
"type": "gitlab"
},
"original": {
@@ -681,11 +681,11 @@
},
"nixpkgs_3": {
"locked": {
- "lastModified": 1780749050,
- "narHash": "sha256-3av0pIjlOWQ6rDbNOmpUSvbNnJkGORQKKjb4LtCZsIY=",
+ "lastModified": 1781074563,
+ "narHash": "sha256-md8WlXOlfnIeHeOScMTTHFyf2d6iaTwPl2apR5EQ3P4=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "a799d3e3886da994fa307f817a6bc705ae538eeb",
+ "rev": "9ae611a455b90cf061d8f332b977e387bda8e1ca",
"type": "github"
},
"original": {
@@ -734,11 +734,11 @@
"systems": "systems_2"
},
"locked": {
- "lastModified": 1781034432,
- "narHash": "sha256-+UuS36un3lXLtKsGCYQnOn51hDhB+dZ1SHoHXClnV/0=",
+ "lastModified": 1781496494,
+ "narHash": "sha256-SfOg25O4vI7jVl4hwxiLAgsa0oiu2K1SPoDtRT3ECNc=",
"owner": "nix-community",
"repo": "nixvim",
- "rev": "e9fbbd56eab78751ba4c166c31a1667042528ced",
+ "rev": "586286af54a314a24566811ce44eb9f380696e6e",
"type": "github"
},
"original": {
@@ -759,11 +759,11 @@
"systems": "systems_3"
},
"locked": {
- "lastModified": 1781204315,
- "narHash": "sha256-0mEWVih7Aq2tdyZwHL91tZMsIitFIocGMvtfaenOSPc=",
+ "lastModified": 1781468924,
+ "narHash": "sha256-lohnpykCw/3ABFIyMw3SjKQe+Je3iiH/ZHAl/HOS00s=",
"owner": "NotAShelf",
"repo": "nvf",
- "rev": "5727a5b9a76f6540d93a26cfc96c6ec2b47fa4f3",
+ "rev": "d55e51c3f75b94f49445a9efb73aab722df1cf4d",
"type": "github"
},
"original": {
@@ -945,11 +945,11 @@
"rust-overlay": "rust-overlay"
},
"locked": {
- "lastModified": 1781157699,
- "narHash": "sha256-3wCm5AnfEOqEvx1acTB5j4Wn5+8lDQ6nWAz6r/Er2ag=",
+ "lastModified": 1781448218,
+ "narHash": "sha256-fpJcWeYy15/p1Ku22H8DbOUYQVmnYBFOMA4sgul2j88=",
"owner": "gabm",
"repo": "Satty",
- "rev": "9dde65caaf515636a9cdcf5abece0413de465605",
+ "rev": "7f6e489da286519a59b37fcd110680a62f7b2aa8",
"type": "github"
},
"original": {
@@ -1169,11 +1169,11 @@
"xwayland-satellite-unstable": {
"flake": false,
"locked": {
- "lastModified": 1779745227,
- "narHash": "sha256-yqY7RtEJGJiENzR0GwL6q69tSAy6xAAmAcLuIhLjPf8=",
+ "lastModified": 1781226823,
+ "narHash": "sha256-28696iIw8uE0ZUyFTtzhEM8xMh85clCYypMxkvUi+sc=",
"owner": "Supreeeme",
"repo": "xwayland-satellite",
- "rev": "5d1efbc9dc3ab1c10160b656e0247f3325daf0f2",
+ "rev": "8575d0ef55d70f9b4c46b6bffb3accf912217e1e",
"type": "github"
},
"original": {
@@ -1191,11 +1191,11 @@
"rust-overlay": "rust-overlay_2"
},
"locked": {
- "lastModified": 1781181862,
- "narHash": "sha256-EBeyydl9ekGp/98VyF4ciFS3zNkspWhJiTG/+UWyHQ4=",
+ "lastModified": 1781438303,
+ "narHash": "sha256-cBw2N3U0hoZO33s24Z/022AthIJtTnZk1jwgnxObfBY=",
"owner": "sxyazi",
"repo": "yazi",
- "rev": "9b920ed2e3ebc126cf8ba3e51acfc5be8b8cbf56",
+ "rev": "f1e93d7f528b22fdeaf66b198c73e32a7040a90c",
"type": "github"
},
"original": {
diff --git a/flake.nix b/flake.nix
index 9a1f0b6..8fcf3f3 100644
--- a/flake.nix
+++ b/flake.nix
@@ -3,13 +3,13 @@
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
- nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-25.11";
+ nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-26.11";
# Hardware and gaming
nixos-hardware.url = "github:NixOS/nixos-hardware/master";
nixos-mailserver = {
- url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.05";
+ url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.11";
inputs.nixpkgs.follows = "nixpkgs";
};
diff --git a/hm/soft/nixvim/nixvim.nix b/hm/soft/nixvim/nixvim.nix
index 7013c27..6f689b3 100644
--- a/hm/soft/nixvim/nixvim.nix
+++ b/hm/soft/nixvim/nixvim.nix
@@ -14,7 +14,7 @@ in
config = lib.mkIf cfg.enable {
programs.nixvim = {
- diagnostics.virtual_text = false;
+ # diagnostics.virtual_text = false;
enable = true;
vimAlias = true;
@@ -179,7 +179,7 @@ in
neoscroll.enable = true;
bufferline.enable = true;
web-devicons.enable = true;
- lsp-kind.enable = true;
+ # lsp-kind.enable = true;
blink-cmp = {
enable = true;
diff --git a/hosts/bibus-lab/configuration.nix b/hosts/bibus-lab/configuration.nix
index 13e1a3b..bace2f6 100644
--- a/hosts/bibus-lab/configuration.nix
+++ b/hosts/bibus-lab/configuration.nix
@@ -1,6 +1,6 @@
-{ inputs, username, ... }:
+{ inputs, ... }:
{
- system.stateVersion = "26.05";
+ system.stateVersion = "26.11";
imports = [
inputs.disko.nixosModules.disko
@@ -10,5 +10,4 @@
];
hardware.facter.reportPath = ./facter.json;
-
}
diff --git a/hosts/thinkpad/configuration.nix b/hosts/thinkpad/configuration.nix
index fd8e727..6f3e85a 100644
--- a/hosts/thinkpad/configuration.nix
+++ b/hosts/thinkpad/configuration.nix
@@ -80,7 +80,6 @@
};
moonlight.enable = true;
virtualization.kvm.enable = true;
- kdeconnect.enable = true;
nix-helper.enable = true;
monero.wallet.enable = true;
sops.enable = true;
diff --git a/hosts/thinkpad/home.nix b/hosts/thinkpad/home.nix
index 26cb32e..f0b3ecc 100644
--- a/hosts/thinkpad/home.nix
+++ b/hosts/thinkpad/home.nix
@@ -55,7 +55,6 @@
chat.enable = true;
onlyoffice.enable = true;
obsidian.enable = true;
- spicetify.enable = true;
torrent.enable = true;
yt-dlp.enable = true;
};
diff --git a/os/core/networking.nix b/os/core/networking.nix
index d50d899..6cfe4ad 100644
--- a/os/core/networking.nix
+++ b/os/core/networking.nix
@@ -11,6 +11,25 @@ in
options.os.core.network = {
enable = lib.mkEnableOption "system-wide networking setup";
+ ips = lib.mkOption {
+ type = lib.types.attrsOf lib.types.str;
+ default = {
+ router = "10.0.0.1";
+ host = "10.0.0.2";
+ vm1-opnsense = "10.0.0.3";
+ vm2-gateway = "10.0.0.4";
+ vm3-monitor = "10.0.0.5";
+ vm4-media = "10.0.0.6";
+ vm5-sandbox = "10.0.0.7";
+ vm6-storage = "10.0.0.8";
+ vm7-web = "10.0.0.9";
+ vm8-mail = "10.0.0.10";
+ vm9-relays = "10.0.0.11";
+ vm10-mc = "10.0.0.12";
+ };
+ description = "Central registry of static IP allocations for the cluster.";
+ };
+
profile = lib.mkOption {
type = lib.types.enum [
"client"
diff --git a/os/srv/dns.nix b/os/srv/dns.nix
index f0c50a6..2da4c66 100644
--- a/os/srv/dns.nix
+++ b/os/srv/dns.nix
@@ -1,10 +1,22 @@
-{ config, lib, ... }:
+{
+ config,
+ lib,
+ masterDomain,
+ securityTemplates,
+ ...
+}:
let
cfg = config.os.srv.dns;
unboundPort = 5335;
in
{
- options.os.srv.dns.enable = lib.mkEnableOption "enables dns scanning";
+ options.os.srv.dns = {
+ enable = lib.mkEnableOption "enables dns scanning";
+ adguardProxyConfig = lib.mkOption {
+ type = lib.types.attrs;
+ default = { };
+ };
+ };
config = lib.mkIf cfg.enable {
services.unbound = {
enable = true;
@@ -63,11 +75,17 @@ in
config.os.core.network.wg.ip
config.os.core.network.hs.ip
];
+ rewrites = [
+ {
+ domain = "router.local";
+ answer = config.os.core.network.ips.vm1-opnsense;
+ }
+ ];
port = 53;
upstream_dns = [ "127.0.0.1:${toString unboundPort}" ];
bootstrap_dns = [ "9.9.9.9" ];
cache_size = 536870912;
- # anonymize_client_ip = true;
+ anonymize_client_ip = true;
};
filtering = {
@@ -239,6 +257,18 @@ in
};
};
+ os.srv.dns.adguardProxyConfig = {
+ "adguard.${masterDomain}" = {
+ enableACME = true;
+ forceSSL = true;
+
+ locations."/" = {
+ proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000";
+ extraConfig = securityTemplates.restrictToInternal;
+ };
+ };
+ };
+
networking.firewall = {
allowedUDPPorts = [ 53 ];
allowedTCPPorts = [ 53 ];
diff --git a/os/srv/monero.nix b/os/srv/monero.nix
index 4e74432..f00413d 100644
--- a/os/srv/monero.nix
+++ b/os/srv/monero.nix
@@ -12,7 +12,13 @@ in
{
options.os.srv.monero = {
wallet.enable = lib.mkEnableOption "enables the monero wallet";
- service.enable = lib.mkEnableOption "enables hosting a monero node";
+ service = {
+ enable = lib.mkEnableOption "enables hosting a monero node";
+ proxyConfig = lib.mkOption {
+ type = lib.types.attrs;
+ default = { };
+ };
+ };
};
config = lib.mkMerge [
@@ -22,10 +28,6 @@ in
(lib.mkIf cfg.service.enable {
assertions = [
{
- assertion = config.os.srv.nginx.enable;
- message = "Hosting a Monero node requires nginx for proxying";
- }
- {
assertion = config.os.srv.sops.enable;
message = "Required for password secure password storing";
}
@@ -55,19 +57,21 @@ in
};
};
- services.nginx.virtualHosts."xmr.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
+ os.srv.monero.service.proxyConfig = {
+ "xmr.${masterDomain}" = {
+ enableACME = true;
+ forceSSL = true;
- locations."/" = {
- proxyPass = "http://127.0.0.1:18081";
- extraConfig = ''
- proxy_read_timeout 600s;
- proxy_send_timeout 600s;
- client_max_body_size 50m;
+ locations."/" = {
+ proxyPass = "http://${config.os.core.network.ips.vm9-relays}:18081";
+ extraConfig = ''
+ proxy_read_timeout 600s;
+ proxy_send_timeout 600s;
+ client_max_body_size 50m;
- ${securityTemplates.restrictToInternal}
- '';
+ ${securityTemplates.restrictToInternal}
+ '';
+ };
};
};
diff --git a/os/srv/nginx.nix b/os/srv/nginx.nix
index 6159e25..a38b703 100644
--- a/os/srv/nginx.nix
+++ b/os/srv/nginx.nix
@@ -42,14 +42,16 @@ in
recommendedTlsSettings = true;
recommendedOptimisation = true;
recommendedGzipSettings = true;
- virtualHosts = {
- default = {
- serverName = "_";
- default = true;
- rejectSSL = true;
- locations."/".return = "444";
- };
- };
+ virtualHosts = lib.mkMerge [
+ {
+ "_" = {
+ default = true;
+ rejectSSL = true;
+ locations."/".return = "444";
+ };
+ }
+ config.os.srv.monero.proxyConfig
+ ];
};
security.acme = {