summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authoradikro <adikro@disroot.org>2026-06-17 00:28:00 +0200
committeradikro <adikro@disroot.org>2026-06-17 00:28:00 +0200
commit630da5d0639cada53e26a03f579df0a7bac3b17a (patch)
tree73edd6ea30331d807413d548f9559d89acc38a82
parentce7fb7ddd3267291a8d692cc6381dad606288aa5 (diff)
librewolf manual compilation issue
-rw-r--r--flake.lock92
-rw-r--r--flake.nix7
-rw-r--r--hm/soft/nixvim/nixvim.nix1
-rw-r--r--hosts/desktop/1119
-rw-r--r--hosts/desktop/configuration.nix4
-rw-r--r--os/core/drivers.nix1
-rw-r--r--os/srv/default.nix8
-rw-r--r--os/srv/fail2ban.nix69
-rw-r--r--os/srv/gaming.nix20
-rw-r--r--os/srv/grafana.nix54
-rw-r--r--os/srv/loki.nix57
-rw-r--r--os/srv/netdata.nix34
-rw-r--r--os/srv/ntfy.nix59
-rw-r--r--os/srv/ntopng.nix35
-rw-r--r--os/srv/prometheus.nix75
-rw-r--r--os/srv/scrutiny.nix35
-rw-r--r--os/srv/uptime-kuma.nix41
17 files changed, 578 insertions, 133 deletions
diff --git a/flake.lock b/flake.lock
index 6583254..a6b0dff 100644
--- a/flake.lock
+++ b/flake.lock
@@ -374,11 +374,11 @@
]
},
"locked": {
- "lastModified": 1781497404,
- "narHash": "sha256-9GAF8sSsnkyCVCWkomXR0T+zdSxyUlfPt6neQidimdg=",
+ "lastModified": 1781642113,
+ "narHash": "sha256-mAR7KTS9rjreTcXCNqfCbN96mnhJO8lDQq1vl7GviBQ=",
"owner": "nix-community",
"repo": "home-manager",
- "rev": "1285cd3d6882a9847f2d56ed5541b3350c8a6162",
+ "rev": "df4e0465717a2d34f05b8ccd967275aaf3ceaa01",
"type": "github"
},
"original": {
@@ -514,11 +514,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
},
"locked": {
- "lastModified": 1781234038,
- "narHash": "sha256-jo4a47qDgsx1F1i0MtHZl12FfzqKJOES25vbm0ZUxeI=",
+ "lastModified": 1781610921,
+ "narHash": "sha256-PXyfDFGyW+UYteu3uHJgp49sFHRU16iocf5K2ltqn3M=",
"owner": "sodiboo",
"repo": "niri-flake",
- "rev": "eb5789cba8d37802d330df5a13c691622c83121f",
+ "rev": "e5857dc58304b3d5bbac6340820f7d4450688538",
"type": "github"
},
"original": {
@@ -547,11 +547,11 @@
"niri-unstable": {
"flake": false,
"locked": {
- "lastModified": 1780938415,
- "narHash": "sha256-QHyIMGSbCQW8d5qbOrMsm6gem10bO3Au2YLa3alJfHo=",
+ "lastModified": 1781588278,
+ "narHash": "sha256-Fw/Zo0hwgn9ulgY5duQy51WHtqpNoLjNDZYLdEI1SS4=",
"owner": "YaLTeR",
"repo": "niri",
- "rev": "6f1a2c5f0e8274223d4204b1f8d6f7f91538967e",
+ "rev": "fdb6d85fc78355762bcf3cf71fe4037681a766f9",
"type": "github"
},
"original": {
@@ -565,11 +565,11 @@
"nixpkgs": "nixpkgs_2"
},
"locked": {
- "lastModified": 1781168557,
- "narHash": "sha256-LOnLQ2tpYF9gqIDDr3+j3DbpJJr/QCH6zPRT2GzEUOE=",
+ "lastModified": 1781622756,
+ "narHash": "sha256-JrPh4M6S7aPsEE9tOENuZrxC6o2szSLlK+t4+nLke9s=",
"owner": "NixOS",
"repo": "nixos-hardware",
- "rev": "6358ff76821101c178e3ab4919a62799bfe3652e",
+ "rev": "08018c72174a4df5657f8d94178ac69fb9c243e5",
"type": "github"
},
"original": {
@@ -589,16 +589,16 @@
]
},
"locked": {
- "lastModified": 1781301671,
- "narHash": "sha256-rq6WOopxq3U2AGEWO80o9LIJDYcYIdgw6jyl+y+19w8=",
+ "lastModified": 1781300555,
+ "narHash": "sha256-anhcFNgXdTEe1KPBAHvxLxDzjEbrt+YZ2O4tfq3WiRA=",
"owner": "simple-nixos-mailserver",
"repo": "nixos-mailserver",
- "rev": "661ec59a97ccee13a63f79280b282eb6f7d3f817",
+ "rev": "51726d7b7fd94aa69829fd42749a803914cbf3b7",
"type": "gitlab"
},
"original": {
"owner": "simple-nixos-mailserver",
- "ref": "nixos-26.05",
+ "ref": "main",
"repo": "nixos-mailserver",
"type": "gitlab"
}
@@ -636,11 +636,11 @@
},
"nixpkgs-stable": {
"locked": {
- "lastModified": 1780952837,
- "narHash": "sha256-Fwd1+spDtQ0hDyBwme6ufG3n4mY0UrjjFdYHv+G/Hds=",
+ "lastModified": 1781509190,
+ "narHash": "sha256-uJZs9Di8I6ciTp6jiojj0HzlNpBkud8ax5aT/O5aJkw=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "e820eb4a444b46a19b2e03e8dfd2359439ff30fe",
+ "rev": "d6df3513510aa548c83868fd22bfddd0a8c0a0d4",
"type": "github"
},
"original": {
@@ -652,16 +652,16 @@
},
"nixpkgs-stable_2": {
"locked": {
- "lastModified": 1780952837,
- "narHash": "sha256-Fwd1+spDtQ0hDyBwme6ufG3n4mY0UrjjFdYHv+G/Hds=",
+ "lastModified": 1781216227,
+ "narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "e820eb4a444b46a19b2e03e8dfd2359439ff30fe",
+ "rev": "a0374025a863d007d98e3297f6aa46cc3141c2f0",
"type": "github"
},
"original": {
"owner": "NixOS",
- "ref": "nixos-25.11",
+ "ref": "nixos-26.05",
"repo": "nixpkgs",
"type": "github"
}
@@ -681,11 +681,11 @@
},
"nixpkgs_3": {
"locked": {
- "lastModified": 1781074563,
- "narHash": "sha256-md8WlXOlfnIeHeOScMTTHFyf2d6iaTwPl2apR5EQ3P4=",
+ "lastModified": 1781577229,
+ "narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "9ae611a455b90cf061d8f332b977e387bda8e1ca",
+ "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f",
"type": "github"
},
"original": {
@@ -697,22 +697,6 @@
},
"nixpkgs_4": {
"locked": {
- "lastModified": 1780336545,
- "narHash": "sha256-vhVhuXzFrIOfcssC/9hDHx7MHzDKjF3keHuREOQqQiQ=",
- "owner": "NixOS",
- "repo": "nixpkgs",
- "rev": "4df1b885d76a54e1aa1a318f8d16fd6005b6401f",
- "type": "github"
- },
- "original": {
- "owner": "NixOS",
- "ref": "nixpkgs-unstable",
- "repo": "nixpkgs",
- "type": "github"
- }
- },
- "nixpkgs_5": {
- "locked": {
"lastModified": 1744536153,
"narHash": "sha256-awS2zRgF4uTwrOKwwiJcByDzDOdo3Q1rPZbiHQg/N38=",
"owner": "NixOS",
@@ -730,15 +714,17 @@
"nixvim": {
"inputs": {
"flake-parts": "flake-parts",
- "nixpkgs": "nixpkgs_4",
+ "nixpkgs": [
+ "nixpkgs"
+ ],
"systems": "systems_2"
},
"locked": {
- "lastModified": 1781496494,
- "narHash": "sha256-SfOg25O4vI7jVl4hwxiLAgsa0oiu2K1SPoDtRT3ECNc=",
+ "lastModified": 1781637822,
+ "narHash": "sha256-6Fwwt8BBGF5rqwGPhj/9ZMyyjXeJQzeHHJQfPuqJP3I=",
"owner": "nix-community",
"repo": "nixvim",
- "rev": "586286af54a314a24566811ce44eb9f380696e6e",
+ "rev": "d43c763fd9fae0912bdb4103cd842f26fea5b0ed",
"type": "github"
},
"original": {
@@ -759,11 +745,11 @@
"systems": "systems_3"
},
"locked": {
- "lastModified": 1781468924,
- "narHash": "sha256-lohnpykCw/3ABFIyMw3SjKQe+Je3iiH/ZHAl/HOS00s=",
+ "lastModified": 1781534482,
+ "narHash": "sha256-d3UIqXuigQhsc7amQkZ7F+SWnaJFAxIROE2f2X+pzUs=",
"owner": "NotAShelf",
"repo": "nvf",
- "rev": "d55e51c3f75b94f49445a9efb73aab722df1cf4d",
+ "rev": "63d8fc82d652c23419a837e2b2934dd4bead04f3",
"type": "github"
},
"original": {
@@ -900,7 +886,7 @@
},
"rust-overlay": {
"inputs": {
- "nixpkgs": "nixpkgs_5"
+ "nixpkgs": "nixpkgs_4"
},
"locked": {
"lastModified": 1748140821,
@@ -945,11 +931,11 @@
"rust-overlay": "rust-overlay"
},
"locked": {
- "lastModified": 1781448218,
- "narHash": "sha256-fpJcWeYy15/p1Ku22H8DbOUYQVmnYBFOMA4sgul2j88=",
+ "lastModified": 1781585488,
+ "narHash": "sha256-NrD3WYckzuQ2oH4t5td4TWzzUtTF0SVrrIhKdU9IgLM=",
"owner": "gabm",
"repo": "Satty",
- "rev": "7f6e489da286519a59b37fcd110680a62f7b2aa8",
+ "rev": "1199a4417000b14105cf61e0b4ee2189a00796b4",
"type": "github"
},
"original": {
diff --git a/flake.nix b/flake.nix
index 8fcf3f3..7ea91e0 100644
--- a/flake.nix
+++ b/flake.nix
@@ -3,13 +3,14 @@
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
- nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-26.11";
+ nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-26.05";
# Hardware and gaming
nixos-hardware.url = "github:NixOS/nixos-hardware/master";
nixos-mailserver = {
- url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.11";
+ # url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.05";
+ url = "gitlab:simple-nixos-mailserver/nixos-mailserver/main";
inputs.nixpkgs.follows = "nixpkgs";
};
@@ -84,7 +85,7 @@
nixvim = {
url = "github:nix-community/nixvim";
- # inputs.nixpkgs.follows = "nixpkgs";
+ inputs.nixpkgs.follows = "nixpkgs";
};
nvf = {
diff --git a/hm/soft/nixvim/nixvim.nix b/hm/soft/nixvim/nixvim.nix
index 6f689b3..8f36cdf 100644
--- a/hm/soft/nixvim/nixvim.nix
+++ b/hm/soft/nixvim/nixvim.nix
@@ -16,6 +16,7 @@ in
programs.nixvim = {
# diagnostics.virtual_text = false;
enable = true;
+ nixpkgs.source = inputs.nixpkgs;
vimAlias = true;
defaultEditor = true;
diff --git a/hosts/desktop/1 b/hosts/desktop/1
new file mode 100644
index 0000000..088098d
--- /dev/null
+++ b/hosts/desktop/1
@@ -0,0 +1,119 @@
+{ config, username, ... }:
+{
+ system.stateVersion = "25.05";
+
+ imports = [
+ ./hardware-configuration.nix
+ ../../os/default.nix
+ ];
+
+ os = {
+ core = {
+ allowUnfree.enable = true;
+ flatpak.enable = true;
+
+ audio = {
+ enable = true;
+ disable-devices.enable = true;
+ };
+ bootloader = {
+ type = "systemd-boot";
+ timeout = 0;
+ };
+ drivers = {
+ enable = true;
+ kernel = "zen";
+ cpu = "amd";
+ graphics = {
+ enable = true;
+ amdgpu.enable = true;
+ };
+ };
+ fonts.enable = true;
+ greet.enable = true;
+ home-manager = {
+ enable = true;
+ users.${username}.path = ./home.nix;
+ };
+ locale.enable = true;
+ memory = {
+ zram.enable = true;
+ swapfile = {
+ enable = true;
+ size = 16;
+ };
+ };
+ network.enable = true;
+ security = {
+ enable = true;
+ sandboxing.enable = true;
+ };
+ storage.enable = true;
+ users.enable = true;
+ };
+ srv = {
+ bluetooth.enable = true;
+ tailscale.enable = true;
+ ssh = {
+ server.enable = true;
+ client = {
+ enable = true;
+ createAliases = true;
+ };
+ enableSigning = true;
+ };
+ firewall.enable = true;
+ yggdrasil.enable = true;
+ i2p.enable = true;
+ tor = {
+ enable = true;
+ enableBrowser = true;
+ };
+ files = {
+ enable = true;
+ localsend.enable = true;
+ krusader.enable = true;
+ };
+ gaming = {
+ enable = true;
+ steam = {
+ enable = true;
+ enableSls = true;
+ };
+ vr.enable = true;
+ };
+ sunshine.enable = true;
+ virtualization.kvm.enable = true;
+ nix-helper.enable = true;
+ monero.wallet.enable = true;
+ sops.enable = true;
+ syncthing = {
+ enable = true;
+ activeFolders = [
+ "openmw-config"
+ "openmw-mods"
+ "game-saves"
+ "keepass"
+ "sync"
+ "music"
+ ];
+ };
+ omnisearch.enable = true;
+ };
+ wm = {
+ enable = true;
+ niri.enable = true;
+ };
+ };
+
+ boot = {
+ kernelModules = [
+ "nct6687"
+ "binder_linux"
+ "ashem_linux"
+ ];
+ extraModulePackages = [
+ config.boot.kernelPackages.nct6687d
+ ];
+ };
+}
diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix
index 088098d..d14cc88 100644
--- a/hosts/desktop/configuration.nix
+++ b/hosts/desktop/configuration.nix
@@ -116,4 +116,8 @@
config.boot.kernelPackages.nct6687d
];
};
+ nixpkgs.config.permittedInsecurePackages = [
+ "librewolf-151.0.2-1"
+ "librewolf-unwrapped-151.0.2-1"
+ ];
}
diff --git a/os/core/drivers.nix b/os/core/drivers.nix
index e6e2814..6e74e98 100644
--- a/os/core/drivers.nix
+++ b/os/core/drivers.nix
@@ -2,7 +2,6 @@
config,
lib,
pkgs,
- inputs,
...
}:
let
diff --git a/os/srv/default.nix b/os/srv/default.nix
index 5729e10..a808328 100644
--- a/os/srv/default.nix
+++ b/os/srv/default.nix
@@ -8,22 +8,27 @@
./compat.nix
./crowdsec.nix
./dns.nix
- ./fail2ban.nix
./files.nix
./firewall.nix
./gaming.nix
+ ./grafana.nix
./headscale.nix
./i2p.nix
./kea.nix
./lldap.nix
+ ./loki.nix
./mailserver.nix
./monero.nix
+ ./netdata.nix
./nfs.nix
./nginx.nix
./nix-helper.nix
+ ./ntfy.nix
./ntopng.nix
./oci.nix
./omnisearch.nix
+ ./prometheus.nix
+ ./scrutiny.nix
./simplex.nix
./sops.nix
./ssh.nix
@@ -32,6 +37,7 @@
./tailscale.nix
./tor.nix
./ups.nix
+ ./uptime-kuma.nix
./virtualization.nix
./wireguard.nix
./yggdrasil.nix
diff --git a/os/srv/fail2ban.nix b/os/srv/fail2ban.nix
deleted file mode 100644
index 9b51ceb..0000000
--- a/os/srv/fail2ban.nix
+++ /dev/null
@@ -1,69 +0,0 @@
-{ config, lib, ... }:
-
-let
- cfg = config.os.srv.fail2ban;
-in
-{
- options.os.srv.fail2ban = {
- enable = lib.mkEnableOption "the NGINX reverse proxy service";
- nginxJails.enable = lib.mkEnableOption "enables Nginx basic-auth and botsearch jails" // {
- default = true;
- };
- };
-
- config = lib.mkIf cfg.enable {
- assertions = [
- {
- assertion = config.networking.firewall.enable || config.networking.nftables.enable;
- message = "Fail2ban requires the NixOS firewall or nftables to be enabled to block IPs.";
- }
- {
- assertion = cfg.nginxJails.enable -> config.os.srv.nginx.enable;
- message = "Fail2ban Nginx jails require your custom Nginx service to be enabled.";
- }
- ];
-
- services.fail2ban = {
- enable = true;
-
- bantime = "24h";
- # findtime = "10m";
- maxretry = 5;
-
- banaction = "nftables-multiport";
-
- ignoreIP = [ "10.0.0.0/16" ];
-
- jails = lib.mkMerge [
- {
- sshd = {
- enabled = true;
- settings = {
- maxretry = 3;
- };
- };
- }
-
- (lib.mkIf cfg.nginxJails.enable {
- nginx-http-auth = {
- enabled = true;
- settings = {
- port = "http,https";
- filter = "nginx-http-auth";
- maxretry = 5;
- };
- };
-
- nginx-botsearch = {
- enabled = true;
- settings = {
- port = "http,https";
- filter = "nginx-botsearch";
- maxretry = 3;
- };
- };
- })
- ];
- };
- };
-}
diff --git a/os/srv/gaming.nix b/os/srv/gaming.nix
index 7e9099d..36f2db5 100644
--- a/os/srv/gaming.nix
+++ b/os/srv/gaming.nix
@@ -106,8 +106,28 @@ in
imports = [ inputs.sls-steam.homeModules.sls-steam ];
services.sls-steam.config = {
+ PlayNotOwnedGames = true;
DisableFamilyShareLock = true;
SafeMode = false;
+ AdditionalApps = [
+ 2483190
+ 4439260
+ 4439270
+ 4439280
+ 4439300
+ 4439750
+ 4439790
+ 4439800
+ 4439810
+ 4439820
+ 4439830
+ 4440380
+ 4444140
+ 4444150
+ 4520350
+ 4520360
+ 4562050
+ ];
};
home.packages = [ inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped ];
diff --git a/os/srv/grafana.nix b/os/srv/grafana.nix
new file mode 100644
index 0000000..3e1333b
--- /dev/null
+++ b/os/srv/grafana.nix
@@ -0,0 +1,54 @@
+{
+ config,
+ lib,
+ masterDomain,
+ securityTemplates,
+ ...
+}:
+let
+ cfg = config.os.srv.grafana;
+in
+{
+ options.os.srv.grafana = {
+ enable = lib.mkEnableOption "enables grafana";
+ proxyConfig = lib.mkOption {
+ type = lib.types.attrs;
+ default = { };
+ };
+ };
+ config = lib.mkIf cfg.enable {
+ services.grafana = {
+ enable = true;
+ settings.server = {
+ http_addr = "127.0.0.1";
+ http_port = 3000;
+ };
+ provision = {
+ enable = true;
+ datasources.settings.datasources = [
+ {
+ name = "Prometheus";
+ type = "prometheus";
+ url = "http://127.0.0.1:9090";
+ }
+ {
+ name = "Loki";
+ type = "loki";
+ url = "http://127.0.0.1:3100";
+ }
+ ];
+ };
+ };
+ os.srv.grafana.proxyConfig = {
+ "grafana.${masterDomain}" = {
+ enableACME = true;
+ forceSSL = true;
+
+ locations."/" = {
+ proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000";
+ extraConfig = securityTemplates.restrictToInternal;
+ };
+ };
+ };
+ };
+}
diff --git a/os/srv/loki.nix b/os/srv/loki.nix
new file mode 100644
index 0000000..2388432
--- /dev/null
+++ b/os/srv/loki.nix
@@ -0,0 +1,57 @@
+{
+ config,
+ lib,
+ pkgs,
+ ...
+}:
+let
+ cfg = config.os.srv.loki;
+in
+{
+ options.os.srv.loki.enable = lib.mkEnableOption "enables loki";
+ config = lib.mkIf cfg.enable {
+ services.loki = {
+ enable = true;
+ configFile = pkgs.writeText "loki-config.yaml" (
+ builtins.toJSON {
+ auth_enabled = false;
+ server = {
+ http_listen_port = 3100;
+ };
+ common = {
+ ring = {
+ kvstore = {
+ store = "inmemory";
+ };
+ };
+ instance_interface_names = [ "lo" ];
+ };
+ ingester = {
+ lifecycler = {
+ address = "127.0.0.1";
+ };
+ };
+ storage_config = {
+ filesystem = {
+ directory = "/var/lib/loki/chunks";
+ };
+ };
+ schema_config = {
+ configs = [
+ {
+ from = "2020-10-24";
+ store = "tsdb";
+ object_store = "filesystem";
+ schema = "v13";
+ index = {
+ prefix = "index_";
+ period = "24h";
+ };
+ }
+ ];
+ };
+ }
+ );
+ };
+ };
+}
diff --git a/os/srv/netdata.nix b/os/srv/netdata.nix
new file mode 100644
index 0000000..87854d4
--- /dev/null
+++ b/os/srv/netdata.nix
@@ -0,0 +1,34 @@
+{
+ config,
+ lib,
+ masterDomain,
+ securityTemplates,
+ ...
+}:
+let
+ cfg = config.os.srv.netdata;
+in
+{
+ options.os.srv.netdata.enable = lib.mkEnableOption "enables netdata monitoring";
+ config = lib.mkIf cfg.enable {
+ services.netdata = {
+ enable = true;
+ config.web."bind to" = "127.0.0.1";
+
+ python = {
+ enable = true;
+ recommendedPythonPackages = true;
+ };
+ };
+
+ services.nginx.virtualHosts."netdata.${masterDomain}" = {
+ enableACME = true;
+ forceSSL = true;
+
+ locations."/" = {
+ proxyPass = "http://127.0.0.1:19999";
+ extraConfig = securityTemplates.restrictToInternal;
+ };
+ };
+ };
+}
diff --git a/os/srv/ntfy.nix b/os/srv/ntfy.nix
new file mode 100644
index 0000000..1417c81
--- /dev/null
+++ b/os/srv/ntfy.nix
@@ -0,0 +1,59 @@
+{
+ config,
+ lib,
+ masterDomain,
+ ...
+}:
+let
+ cfg = config.os.srv.ntfy;
+in
+{
+ options.os.srv.ntfy = {
+ enable = lib.mkEnableOption "enables ntfy";
+ proxyConfig = lib.mkOption {
+ type = lib.types.attrs;
+ default = { };
+ };
+ };
+ config = lib.mkIf cfg.enable {
+ services.ntfy-sh = {
+ enable = true;
+ settings = {
+ base-url = "https://ntfy.${masterDomain}";
+
+ listen-http = "127.0.0.1:2586";
+
+ cache-file = "/var/lib/ntfy/cache.db";
+ cache-duration = "72h";
+
+ attachment-cache-dir = "/var/lib/ntfy/attachments";
+ attachment-total-size-limit = "5G";
+ attachment-file-size-limit = "15M";
+ attachment-expiry-duration = "3h";
+
+ behind-proxy = true;
+ };
+ };
+
+ os.srv.ntfy.proxyConfig = {
+ "uptime-kuma.${masterDomain}" = {
+ enableACME = true;
+ forceSSL = true;
+
+ locations."/" = {
+ proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3001";
+ extraConfig = ''
+ proxy_set_header Connection "";
+ proxy_connect_timeout 1m;
+ proxy_send_timeout 1m;
+ proxy_read_timeout 24h;
+
+ proxy_buffering off;
+ proxy_request_buffering off;
+ chunked_transfer_encoding on;
+ '';
+ };
+ };
+ };
+ };
+}
diff --git a/os/srv/ntopng.nix b/os/srv/ntopng.nix
index 3c11534..692fe2c 100644
--- a/os/srv/ntopng.nix
+++ b/os/srv/ntopng.nix
@@ -1,20 +1,43 @@
-{ config, lib, ... }:
+{
+ config,
+ lib,
+ masterDomain,
+ securityTemplates,
+ ...
+}:
let
cfg = config.os.srv.ntopng;
in
{
- options.os.srv.ntopng.enable = lib.mkEnableOption "enables ntopng monitoring";
+ options.os.srv.ntopng = {
+ enable = lib.mkEnableOption "enables ntopng monitoring";
+ proxyConfig = lib.mkOption {
+ type = lib.types.attrs;
+ default = { };
+ };
+ };
config = lib.mkIf cfg.enable {
services.ntopng = {
enable = true;
- httpPort = 3000;
- extraConfig = "--packet-fanout";
+ extraConfig = "--packet-fanout 'cluster' -g 2 -m '192.168.0.0/16,10.0.0.0/8' -X 50000 --community";
# TODO fill interfaces
interfaces = [
- ""
- ""
+ "" # WAN Interface
+ "" # LAN Interface
+ "" # Virtual Bridge
];
};
+ os.srv.ntopng.proxyConfig = {
+ "ntopng.${masterDomain}" = {
+ enableACME = true;
+ forceSSL = true;
+
+ locations."/" = {
+ proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000";
+ extraConfig = securityTemplates.restrictToInternal;
+ };
+ };
+ };
};
}
diff --git a/os/srv/prometheus.nix b/os/srv/prometheus.nix
new file mode 100644
index 0000000..afccef4
--- /dev/null
+++ b/os/srv/prometheus.nix
@@ -0,0 +1,75 @@
+{ config, lib, ... }:
+let
+ cfg = config.os.srv.prometheus;
+in
+{
+ options.os.srv.prometheus.enable = lib.mkEnableOption "enables prometheus";
+ config = lib.mkIf cfg.enable {
+ services.prometheus = {
+ enable = true;
+ port = 9090;
+
+ alertmanagers = [
+ {
+ static_configs = [ { targets = [ "127.0.0.1:9093" ]; } ];
+ }
+ ];
+
+ scrapeConfigs = [
+ {
+ job_name = "prometheus";
+ static_configs = [ { targets = [ "127.0.0.1:9090" ]; } ];
+ }
+ {
+ job_name = "node_exporter";
+ static_configs = [ { targets = [ "127.0.0.1:9100" ]; } ];
+ }
+ {
+ job_name = "uptime_kuma";
+ metrics_path = "/metrics";
+ static_configs = [ { targets = [ "127.0.0.1:3001" ]; } ];
+ }
+ ];
+ exporters = {
+ node = {
+ enable = true;
+ enableCollectors = [ "systemd" ];
+ port = 9100;
+ };
+
+ alertmanager = {
+ enable = true;
+ port = 9093;
+ configuration = {
+ route = {
+ receiver = "default-receiver";
+ group_by = [ "alertname" ];
+ };
+ receivers = [
+ {
+ name = "default-receiver";
+ }
+ ];
+ };
+ };
+
+ smokeping = {
+ enable = true;
+ listenAddress = "127.0.0.1";
+
+ pingInterval = "1s";
+
+ hosts = [
+ "10.0.0.1" # Personal Router
+ "192.168.0.1" # ISP Modem Box
+ "84.116.254.69" # First ISP Hop
+ "185.182.244.39" # Regional Katowice Hub
+ "1.1.1.1" # Cloudflare DNS
+ "8.8.8.8" # Google DNS
+ "130.162.223.123" # OCI Instance
+ ];
+ };
+ };
+ };
+ };
+}
diff --git a/os/srv/scrutiny.nix b/os/srv/scrutiny.nix
new file mode 100644
index 0000000..ffe8c39
--- /dev/null
+++ b/os/srv/scrutiny.nix
@@ -0,0 +1,35 @@
+{
+ config,
+ lib,
+ masterDomain,
+ securityTemplates,
+ ...
+}:
+let
+ cfg = config.os.srv.scrutiny;
+in
+{
+ options.os.srv.scrutiny.enable = lib.mkEnableOption "enables scrutiny monitoring";
+ config = lib.mkIf cfg.enable {
+ services.scrutiny = {
+ enable = true;
+ settings.web.listen.host = "127.0.0.1";
+
+ collector = {
+ enable = true;
+ schedule = "hourly";
+ settings.host.id = "bibus-lab";
+ };
+ };
+
+ services.nginx.virtualHosts."scrutiny.${masterDomain}" = {
+ enableACME = true;
+ forceSSL = true;
+
+ locations."/" = {
+ proxyPass = "http://127.0.0.1:8080";
+ extraConfig = securityTemplates.restrictToInternal;
+ };
+ };
+ };
+}
diff --git a/os/srv/uptime-kuma.nix b/os/srv/uptime-kuma.nix
new file mode 100644
index 0000000..7bf8dd0
--- /dev/null
+++ b/os/srv/uptime-kuma.nix
@@ -0,0 +1,41 @@
+{
+ config,
+ lib,
+ masterDomain,
+ securityTemplates,
+ ...
+}:
+let
+ cfg = config.os.srv.uptime-kuma;
+in
+{
+ options.os.srv.uptime-kuma = {
+ enable = lib.mkEnableOption "enables uptime-kuma";
+ proxyConfig = lib.mkOption {
+ type = lib.types.attrs;
+ default = { };
+ };
+ };
+ config = lib.mkIf cfg.enable {
+ services.uptime-kuma = {
+ enable = true;
+ appriseSupport = true;
+ settings = {
+ HOST = "127.0.0.1";
+ UPTIME_KUMA_DB_TYPE = "sqlite";
+ };
+ };
+
+ os.srv.uptime-kuma.proxyConfig = {
+ "uptime-kuma.${masterDomain}" = {
+ enableACME = true;
+ forceSSL = true;
+
+ locations."/" = {
+ proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3001";
+ extraConfig = securityTemplates.restrictToInternal;
+ };
+ };
+ };
+ };
+}