diff options
| author | adikro <adikro@disroot.org> | 2026-06-17 00:28:00 +0200 |
|---|---|---|
| committer | adikro <adikro@disroot.org> | 2026-06-17 00:28:00 +0200 |
| commit | 630da5d0639cada53e26a03f579df0a7bac3b17a (patch) | |
| tree | 73edd6ea30331d807413d548f9559d89acc38a82 | |
| parent | ce7fb7ddd3267291a8d692cc6381dad606288aa5 (diff) | |
librewolf manual compilation issue
| -rw-r--r-- | flake.lock | 92 | ||||
| -rw-r--r-- | flake.nix | 7 | ||||
| -rw-r--r-- | hm/soft/nixvim/nixvim.nix | 1 | ||||
| -rw-r--r-- | hosts/desktop/1 | 119 | ||||
| -rw-r--r-- | hosts/desktop/configuration.nix | 4 | ||||
| -rw-r--r-- | os/core/drivers.nix | 1 | ||||
| -rw-r--r-- | os/srv/default.nix | 8 | ||||
| -rw-r--r-- | os/srv/fail2ban.nix | 69 | ||||
| -rw-r--r-- | os/srv/gaming.nix | 20 | ||||
| -rw-r--r-- | os/srv/grafana.nix | 54 | ||||
| -rw-r--r-- | os/srv/loki.nix | 57 | ||||
| -rw-r--r-- | os/srv/netdata.nix | 34 | ||||
| -rw-r--r-- | os/srv/ntfy.nix | 59 | ||||
| -rw-r--r-- | os/srv/ntopng.nix | 35 | ||||
| -rw-r--r-- | os/srv/prometheus.nix | 75 | ||||
| -rw-r--r-- | os/srv/scrutiny.nix | 35 | ||||
| -rw-r--r-- | os/srv/uptime-kuma.nix | 41 |
17 files changed, 578 insertions, 133 deletions
@@ -374,11 +374,11 @@ ] }, "locked": { - "lastModified": 1781497404, - "narHash": "sha256-9GAF8sSsnkyCVCWkomXR0T+zdSxyUlfPt6neQidimdg=", + "lastModified": 1781642113, + "narHash": "sha256-mAR7KTS9rjreTcXCNqfCbN96mnhJO8lDQq1vl7GviBQ=", "owner": "nix-community", "repo": "home-manager", - "rev": "1285cd3d6882a9847f2d56ed5541b3350c8a6162", + "rev": "df4e0465717a2d34f05b8ccd967275aaf3ceaa01", "type": "github" }, "original": { @@ -514,11 +514,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1781234038, - "narHash": "sha256-jo4a47qDgsx1F1i0MtHZl12FfzqKJOES25vbm0ZUxeI=", + "lastModified": 1781610921, + "narHash": "sha256-PXyfDFGyW+UYteu3uHJgp49sFHRU16iocf5K2ltqn3M=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "eb5789cba8d37802d330df5a13c691622c83121f", + "rev": "e5857dc58304b3d5bbac6340820f7d4450688538", "type": "github" }, "original": { @@ -547,11 +547,11 @@ "niri-unstable": { "flake": false, "locked": { - "lastModified": 1780938415, - "narHash": "sha256-QHyIMGSbCQW8d5qbOrMsm6gem10bO3Au2YLa3alJfHo=", + "lastModified": 1781588278, + "narHash": "sha256-Fw/Zo0hwgn9ulgY5duQy51WHtqpNoLjNDZYLdEI1SS4=", "owner": "YaLTeR", "repo": "niri", - "rev": "6f1a2c5f0e8274223d4204b1f8d6f7f91538967e", + "rev": "fdb6d85fc78355762bcf3cf71fe4037681a766f9", "type": "github" }, "original": { @@ -565,11 +565,11 @@ "nixpkgs": "nixpkgs_2" }, "locked": { - "lastModified": 1781168557, - "narHash": "sha256-LOnLQ2tpYF9gqIDDr3+j3DbpJJr/QCH6zPRT2GzEUOE=", + "lastModified": 1781622756, + "narHash": "sha256-JrPh4M6S7aPsEE9tOENuZrxC6o2szSLlK+t4+nLke9s=", "owner": "NixOS", "repo": "nixos-hardware", - "rev": "6358ff76821101c178e3ab4919a62799bfe3652e", + "rev": "08018c72174a4df5657f8d94178ac69fb9c243e5", "type": "github" }, "original": { @@ -589,16 +589,16 @@ ] }, "locked": { - "lastModified": 1781301671, - "narHash": "sha256-rq6WOopxq3U2AGEWO80o9LIJDYcYIdgw6jyl+y+19w8=", + "lastModified": 1781300555, + "narHash": "sha256-anhcFNgXdTEe1KPBAHvxLxDzjEbrt+YZ2O4tfq3WiRA=", "owner": "simple-nixos-mailserver", "repo": "nixos-mailserver", - "rev": "661ec59a97ccee13a63f79280b282eb6f7d3f817", + "rev": "51726d7b7fd94aa69829fd42749a803914cbf3b7", "type": "gitlab" }, "original": { "owner": "simple-nixos-mailserver", - "ref": "nixos-26.05", + "ref": "main", "repo": "nixos-mailserver", "type": "gitlab" } @@ -636,11 +636,11 @@ }, "nixpkgs-stable": { "locked": { - "lastModified": 1780952837, - "narHash": "sha256-Fwd1+spDtQ0hDyBwme6ufG3n4mY0UrjjFdYHv+G/Hds=", + "lastModified": 1781509190, + "narHash": "sha256-uJZs9Di8I6ciTp6jiojj0HzlNpBkud8ax5aT/O5aJkw=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "e820eb4a444b46a19b2e03e8dfd2359439ff30fe", + "rev": "d6df3513510aa548c83868fd22bfddd0a8c0a0d4", "type": "github" }, "original": { @@ -652,16 +652,16 @@ }, "nixpkgs-stable_2": { "locked": { - "lastModified": 1780952837, - "narHash": "sha256-Fwd1+spDtQ0hDyBwme6ufG3n4mY0UrjjFdYHv+G/Hds=", + "lastModified": 1781216227, + "narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "e820eb4a444b46a19b2e03e8dfd2359439ff30fe", + "rev": "a0374025a863d007d98e3297f6aa46cc3141c2f0", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-25.11", + "ref": "nixos-26.05", "repo": "nixpkgs", "type": "github" } @@ -681,11 +681,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1781074563, - "narHash": "sha256-md8WlXOlfnIeHeOScMTTHFyf2d6iaTwPl2apR5EQ3P4=", + "lastModified": 1781577229, + "narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "9ae611a455b90cf061d8f332b977e387bda8e1ca", + "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f", "type": "github" }, "original": { @@ -697,22 +697,6 @@ }, "nixpkgs_4": { "locked": { - "lastModified": 1780336545, - "narHash": "sha256-vhVhuXzFrIOfcssC/9hDHx7MHzDKjF3keHuREOQqQiQ=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "4df1b885d76a54e1aa1a318f8d16fd6005b6401f", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixpkgs-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_5": { - "locked": { "lastModified": 1744536153, "narHash": "sha256-awS2zRgF4uTwrOKwwiJcByDzDOdo3Q1rPZbiHQg/N38=", "owner": "NixOS", @@ -730,15 +714,17 @@ "nixvim": { "inputs": { "flake-parts": "flake-parts", - "nixpkgs": "nixpkgs_4", + "nixpkgs": [ + "nixpkgs" + ], "systems": "systems_2" }, "locked": { - "lastModified": 1781496494, - "narHash": "sha256-SfOg25O4vI7jVl4hwxiLAgsa0oiu2K1SPoDtRT3ECNc=", + "lastModified": 1781637822, + "narHash": "sha256-6Fwwt8BBGF5rqwGPhj/9ZMyyjXeJQzeHHJQfPuqJP3I=", "owner": "nix-community", "repo": "nixvim", - "rev": "586286af54a314a24566811ce44eb9f380696e6e", + "rev": "d43c763fd9fae0912bdb4103cd842f26fea5b0ed", "type": "github" }, "original": { @@ -759,11 +745,11 @@ "systems": "systems_3" }, "locked": { - "lastModified": 1781468924, - "narHash": "sha256-lohnpykCw/3ABFIyMw3SjKQe+Je3iiH/ZHAl/HOS00s=", + "lastModified": 1781534482, + "narHash": "sha256-d3UIqXuigQhsc7amQkZ7F+SWnaJFAxIROE2f2X+pzUs=", "owner": "NotAShelf", "repo": "nvf", - "rev": "d55e51c3f75b94f49445a9efb73aab722df1cf4d", + "rev": "63d8fc82d652c23419a837e2b2934dd4bead04f3", "type": "github" }, "original": { @@ -900,7 +886,7 @@ }, "rust-overlay": { "inputs": { - "nixpkgs": "nixpkgs_5" + "nixpkgs": "nixpkgs_4" }, "locked": { "lastModified": 1748140821, @@ -945,11 +931,11 @@ "rust-overlay": "rust-overlay" }, "locked": { - "lastModified": 1781448218, - "narHash": "sha256-fpJcWeYy15/p1Ku22H8DbOUYQVmnYBFOMA4sgul2j88=", + "lastModified": 1781585488, + "narHash": "sha256-NrD3WYckzuQ2oH4t5td4TWzzUtTF0SVrrIhKdU9IgLM=", "owner": "gabm", "repo": "Satty", - "rev": "7f6e489da286519a59b37fcd110680a62f7b2aa8", + "rev": "1199a4417000b14105cf61e0b4ee2189a00796b4", "type": "github" }, "original": { @@ -3,13 +3,14 @@ inputs = { nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; - nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-26.11"; + nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-26.05"; # Hardware and gaming nixos-hardware.url = "github:NixOS/nixos-hardware/master"; nixos-mailserver = { - url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.11"; + # url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.05"; + url = "gitlab:simple-nixos-mailserver/nixos-mailserver/main"; inputs.nixpkgs.follows = "nixpkgs"; }; @@ -84,7 +85,7 @@ nixvim = { url = "github:nix-community/nixvim"; - # inputs.nixpkgs.follows = "nixpkgs"; + inputs.nixpkgs.follows = "nixpkgs"; }; nvf = { diff --git a/hm/soft/nixvim/nixvim.nix b/hm/soft/nixvim/nixvim.nix index 6f689b3..8f36cdf 100644 --- a/hm/soft/nixvim/nixvim.nix +++ b/hm/soft/nixvim/nixvim.nix @@ -16,6 +16,7 @@ in programs.nixvim = { # diagnostics.virtual_text = false; enable = true; + nixpkgs.source = inputs.nixpkgs; vimAlias = true; defaultEditor = true; diff --git a/hosts/desktop/1 b/hosts/desktop/1 new file mode 100644 index 0000000..088098d --- /dev/null +++ b/hosts/desktop/1 @@ -0,0 +1,119 @@ +{ config, username, ... }: +{ + system.stateVersion = "25.05"; + + imports = [ + ./hardware-configuration.nix + ../../os/default.nix + ]; + + os = { + core = { + allowUnfree.enable = true; + flatpak.enable = true; + + audio = { + enable = true; + disable-devices.enable = true; + }; + bootloader = { + type = "systemd-boot"; + timeout = 0; + }; + drivers = { + enable = true; + kernel = "zen"; + cpu = "amd"; + graphics = { + enable = true; + amdgpu.enable = true; + }; + }; + fonts.enable = true; + greet.enable = true; + home-manager = { + enable = true; + users.${username}.path = ./home.nix; + }; + locale.enable = true; + memory = { + zram.enable = true; + swapfile = { + enable = true; + size = 16; + }; + }; + network.enable = true; + security = { + enable = true; + sandboxing.enable = true; + }; + storage.enable = true; + users.enable = true; + }; + srv = { + bluetooth.enable = true; + tailscale.enable = true; + ssh = { + server.enable = true; + client = { + enable = true; + createAliases = true; + }; + enableSigning = true; + }; + firewall.enable = true; + yggdrasil.enable = true; + i2p.enable = true; + tor = { + enable = true; + enableBrowser = true; + }; + files = { + enable = true; + localsend.enable = true; + krusader.enable = true; + }; + gaming = { + enable = true; + steam = { + enable = true; + enableSls = true; + }; + vr.enable = true; + }; + sunshine.enable = true; + virtualization.kvm.enable = true; + nix-helper.enable = true; + monero.wallet.enable = true; + sops.enable = true; + syncthing = { + enable = true; + activeFolders = [ + "openmw-config" + "openmw-mods" + "game-saves" + "keepass" + "sync" + "music" + ]; + }; + omnisearch.enable = true; + }; + wm = { + enable = true; + niri.enable = true; + }; + }; + + boot = { + kernelModules = [ + "nct6687" + "binder_linux" + "ashem_linux" + ]; + extraModulePackages = [ + config.boot.kernelPackages.nct6687d + ]; + }; +} diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix index 088098d..d14cc88 100644 --- a/hosts/desktop/configuration.nix +++ b/hosts/desktop/configuration.nix @@ -116,4 +116,8 @@ config.boot.kernelPackages.nct6687d ]; }; + nixpkgs.config.permittedInsecurePackages = [ + "librewolf-151.0.2-1" + "librewolf-unwrapped-151.0.2-1" + ]; } diff --git a/os/core/drivers.nix b/os/core/drivers.nix index e6e2814..6e74e98 100644 --- a/os/core/drivers.nix +++ b/os/core/drivers.nix @@ -2,7 +2,6 @@ config, lib, pkgs, - inputs, ... }: let diff --git a/os/srv/default.nix b/os/srv/default.nix index 5729e10..a808328 100644 --- a/os/srv/default.nix +++ b/os/srv/default.nix @@ -8,22 +8,27 @@ ./compat.nix ./crowdsec.nix ./dns.nix - ./fail2ban.nix ./files.nix ./firewall.nix ./gaming.nix + ./grafana.nix ./headscale.nix ./i2p.nix ./kea.nix ./lldap.nix + ./loki.nix ./mailserver.nix ./monero.nix + ./netdata.nix ./nfs.nix ./nginx.nix ./nix-helper.nix + ./ntfy.nix ./ntopng.nix ./oci.nix ./omnisearch.nix + ./prometheus.nix + ./scrutiny.nix ./simplex.nix ./sops.nix ./ssh.nix @@ -32,6 +37,7 @@ ./tailscale.nix ./tor.nix ./ups.nix + ./uptime-kuma.nix ./virtualization.nix ./wireguard.nix ./yggdrasil.nix diff --git a/os/srv/fail2ban.nix b/os/srv/fail2ban.nix deleted file mode 100644 index 9b51ceb..0000000 --- a/os/srv/fail2ban.nix +++ /dev/null @@ -1,69 +0,0 @@ -{ config, lib, ... }: - -let - cfg = config.os.srv.fail2ban; -in -{ - options.os.srv.fail2ban = { - enable = lib.mkEnableOption "the NGINX reverse proxy service"; - nginxJails.enable = lib.mkEnableOption "enables Nginx basic-auth and botsearch jails" // { - default = true; - }; - }; - - config = lib.mkIf cfg.enable { - assertions = [ - { - assertion = config.networking.firewall.enable || config.networking.nftables.enable; - message = "Fail2ban requires the NixOS firewall or nftables to be enabled to block IPs."; - } - { - assertion = cfg.nginxJails.enable -> config.os.srv.nginx.enable; - message = "Fail2ban Nginx jails require your custom Nginx service to be enabled."; - } - ]; - - services.fail2ban = { - enable = true; - - bantime = "24h"; - # findtime = "10m"; - maxretry = 5; - - banaction = "nftables-multiport"; - - ignoreIP = [ "10.0.0.0/16" ]; - - jails = lib.mkMerge [ - { - sshd = { - enabled = true; - settings = { - maxretry = 3; - }; - }; - } - - (lib.mkIf cfg.nginxJails.enable { - nginx-http-auth = { - enabled = true; - settings = { - port = "http,https"; - filter = "nginx-http-auth"; - maxretry = 5; - }; - }; - - nginx-botsearch = { - enabled = true; - settings = { - port = "http,https"; - filter = "nginx-botsearch"; - maxretry = 3; - }; - }; - }) - ]; - }; - }; -} diff --git a/os/srv/gaming.nix b/os/srv/gaming.nix index 7e9099d..36f2db5 100644 --- a/os/srv/gaming.nix +++ b/os/srv/gaming.nix @@ -106,8 +106,28 @@ in imports = [ inputs.sls-steam.homeModules.sls-steam ]; services.sls-steam.config = { + PlayNotOwnedGames = true; DisableFamilyShareLock = true; SafeMode = false; + AdditionalApps = [ + 2483190 + 4439260 + 4439270 + 4439280 + 4439300 + 4439750 + 4439790 + 4439800 + 4439810 + 4439820 + 4439830 + 4440380 + 4444140 + 4444150 + 4520350 + 4520360 + 4562050 + ]; }; home.packages = [ inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped ]; diff --git a/os/srv/grafana.nix b/os/srv/grafana.nix new file mode 100644 index 0000000..3e1333b --- /dev/null +++ b/os/srv/grafana.nix @@ -0,0 +1,54 @@ +{ + config, + lib, + masterDomain, + securityTemplates, + ... +}: +let + cfg = config.os.srv.grafana; +in +{ + options.os.srv.grafana = { + enable = lib.mkEnableOption "enables grafana"; + proxyConfig = lib.mkOption { + type = lib.types.attrs; + default = { }; + }; + }; + config = lib.mkIf cfg.enable { + services.grafana = { + enable = true; + settings.server = { + http_addr = "127.0.0.1"; + http_port = 3000; + }; + provision = { + enable = true; + datasources.settings.datasources = [ + { + name = "Prometheus"; + type = "prometheus"; + url = "http://127.0.0.1:9090"; + } + { + name = "Loki"; + type = "loki"; + url = "http://127.0.0.1:3100"; + } + ]; + }; + }; + os.srv.grafana.proxyConfig = { + "grafana.${masterDomain}" = { + enableACME = true; + forceSSL = true; + + locations."/" = { + proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000"; + extraConfig = securityTemplates.restrictToInternal; + }; + }; + }; + }; +} diff --git a/os/srv/loki.nix b/os/srv/loki.nix new file mode 100644 index 0000000..2388432 --- /dev/null +++ b/os/srv/loki.nix @@ -0,0 +1,57 @@ +{ + config, + lib, + pkgs, + ... +}: +let + cfg = config.os.srv.loki; +in +{ + options.os.srv.loki.enable = lib.mkEnableOption "enables loki"; + config = lib.mkIf cfg.enable { + services.loki = { + enable = true; + configFile = pkgs.writeText "loki-config.yaml" ( + builtins.toJSON { + auth_enabled = false; + server = { + http_listen_port = 3100; + }; + common = { + ring = { + kvstore = { + store = "inmemory"; + }; + }; + instance_interface_names = [ "lo" ]; + }; + ingester = { + lifecycler = { + address = "127.0.0.1"; + }; + }; + storage_config = { + filesystem = { + directory = "/var/lib/loki/chunks"; + }; + }; + schema_config = { + configs = [ + { + from = "2020-10-24"; + store = "tsdb"; + object_store = "filesystem"; + schema = "v13"; + index = { + prefix = "index_"; + period = "24h"; + }; + } + ]; + }; + } + ); + }; + }; +} diff --git a/os/srv/netdata.nix b/os/srv/netdata.nix new file mode 100644 index 0000000..87854d4 --- /dev/null +++ b/os/srv/netdata.nix @@ -0,0 +1,34 @@ +{ + config, + lib, + masterDomain, + securityTemplates, + ... +}: +let + cfg = config.os.srv.netdata; +in +{ + options.os.srv.netdata.enable = lib.mkEnableOption "enables netdata monitoring"; + config = lib.mkIf cfg.enable { + services.netdata = { + enable = true; + config.web."bind to" = "127.0.0.1"; + + python = { + enable = true; + recommendedPythonPackages = true; + }; + }; + + services.nginx.virtualHosts."netdata.${masterDomain}" = { + enableACME = true; + forceSSL = true; + + locations."/" = { + proxyPass = "http://127.0.0.1:19999"; + extraConfig = securityTemplates.restrictToInternal; + }; + }; + }; +} diff --git a/os/srv/ntfy.nix b/os/srv/ntfy.nix new file mode 100644 index 0000000..1417c81 --- /dev/null +++ b/os/srv/ntfy.nix @@ -0,0 +1,59 @@ +{ + config, + lib, + masterDomain, + ... +}: +let + cfg = config.os.srv.ntfy; +in +{ + options.os.srv.ntfy = { + enable = lib.mkEnableOption "enables ntfy"; + proxyConfig = lib.mkOption { + type = lib.types.attrs; + default = { }; + }; + }; + config = lib.mkIf cfg.enable { + services.ntfy-sh = { + enable = true; + settings = { + base-url = "https://ntfy.${masterDomain}"; + + listen-http = "127.0.0.1:2586"; + + cache-file = "/var/lib/ntfy/cache.db"; + cache-duration = "72h"; + + attachment-cache-dir = "/var/lib/ntfy/attachments"; + attachment-total-size-limit = "5G"; + attachment-file-size-limit = "15M"; + attachment-expiry-duration = "3h"; + + behind-proxy = true; + }; + }; + + os.srv.ntfy.proxyConfig = { + "uptime-kuma.${masterDomain}" = { + enableACME = true; + forceSSL = true; + + locations."/" = { + proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3001"; + extraConfig = '' + proxy_set_header Connection ""; + proxy_connect_timeout 1m; + proxy_send_timeout 1m; + proxy_read_timeout 24h; + + proxy_buffering off; + proxy_request_buffering off; + chunked_transfer_encoding on; + ''; + }; + }; + }; + }; +} diff --git a/os/srv/ntopng.nix b/os/srv/ntopng.nix index 3c11534..692fe2c 100644 --- a/os/srv/ntopng.nix +++ b/os/srv/ntopng.nix @@ -1,20 +1,43 @@ -{ config, lib, ... }: +{ + config, + lib, + masterDomain, + securityTemplates, + ... +}: let cfg = config.os.srv.ntopng; in { - options.os.srv.ntopng.enable = lib.mkEnableOption "enables ntopng monitoring"; + options.os.srv.ntopng = { + enable = lib.mkEnableOption "enables ntopng monitoring"; + proxyConfig = lib.mkOption { + type = lib.types.attrs; + default = { }; + }; + }; config = lib.mkIf cfg.enable { services.ntopng = { enable = true; - httpPort = 3000; - extraConfig = "--packet-fanout"; + extraConfig = "--packet-fanout 'cluster' -g 2 -m '192.168.0.0/16,10.0.0.0/8' -X 50000 --community"; # TODO fill interfaces interfaces = [ - "" - "" + "" # WAN Interface + "" # LAN Interface + "" # Virtual Bridge ]; }; + os.srv.ntopng.proxyConfig = { + "ntopng.${masterDomain}" = { + enableACME = true; + forceSSL = true; + + locations."/" = { + proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000"; + extraConfig = securityTemplates.restrictToInternal; + }; + }; + }; }; } diff --git a/os/srv/prometheus.nix b/os/srv/prometheus.nix new file mode 100644 index 0000000..afccef4 --- /dev/null +++ b/os/srv/prometheus.nix @@ -0,0 +1,75 @@ +{ config, lib, ... }: +let + cfg = config.os.srv.prometheus; +in +{ + options.os.srv.prometheus.enable = lib.mkEnableOption "enables prometheus"; + config = lib.mkIf cfg.enable { + services.prometheus = { + enable = true; + port = 9090; + + alertmanagers = [ + { + static_configs = [ { targets = [ "127.0.0.1:9093" ]; } ]; + } + ]; + + scrapeConfigs = [ + { + job_name = "prometheus"; + static_configs = [ { targets = [ "127.0.0.1:9090" ]; } ]; + } + { + job_name = "node_exporter"; + static_configs = [ { targets = [ "127.0.0.1:9100" ]; } ]; + } + { + job_name = "uptime_kuma"; + metrics_path = "/metrics"; + static_configs = [ { targets = [ "127.0.0.1:3001" ]; } ]; + } + ]; + exporters = { + node = { + enable = true; + enableCollectors = [ "systemd" ]; + port = 9100; + }; + + alertmanager = { + enable = true; + port = 9093; + configuration = { + route = { + receiver = "default-receiver"; + group_by = [ "alertname" ]; + }; + receivers = [ + { + name = "default-receiver"; + } + ]; + }; + }; + + smokeping = { + enable = true; + listenAddress = "127.0.0.1"; + + pingInterval = "1s"; + + hosts = [ + "10.0.0.1" # Personal Router + "192.168.0.1" # ISP Modem Box + "84.116.254.69" # First ISP Hop + "185.182.244.39" # Regional Katowice Hub + "1.1.1.1" # Cloudflare DNS + "8.8.8.8" # Google DNS + "130.162.223.123" # OCI Instance + ]; + }; + }; + }; + }; +} diff --git a/os/srv/scrutiny.nix b/os/srv/scrutiny.nix new file mode 100644 index 0000000..ffe8c39 --- /dev/null +++ b/os/srv/scrutiny.nix @@ -0,0 +1,35 @@ +{ + config, + lib, + masterDomain, + securityTemplates, + ... +}: +let + cfg = config.os.srv.scrutiny; +in +{ + options.os.srv.scrutiny.enable = lib.mkEnableOption "enables scrutiny monitoring"; + config = lib.mkIf cfg.enable { + services.scrutiny = { + enable = true; + settings.web.listen.host = "127.0.0.1"; + + collector = { + enable = true; + schedule = "hourly"; + settings.host.id = "bibus-lab"; + }; + }; + + services.nginx.virtualHosts."scrutiny.${masterDomain}" = { + enableACME = true; + forceSSL = true; + + locations."/" = { + proxyPass = "http://127.0.0.1:8080"; + extraConfig = securityTemplates.restrictToInternal; + }; + }; + }; +} diff --git a/os/srv/uptime-kuma.nix b/os/srv/uptime-kuma.nix new file mode 100644 index 0000000..7bf8dd0 --- /dev/null +++ b/os/srv/uptime-kuma.nix @@ -0,0 +1,41 @@ +{ + config, + lib, + masterDomain, + securityTemplates, + ... +}: +let + cfg = config.os.srv.uptime-kuma; +in +{ + options.os.srv.uptime-kuma = { + enable = lib.mkEnableOption "enables uptime-kuma"; + proxyConfig = lib.mkOption { + type = lib.types.attrs; + default = { }; + }; + }; + config = lib.mkIf cfg.enable { + services.uptime-kuma = { + enable = true; + appriseSupport = true; + settings = { + HOST = "127.0.0.1"; + UPTIME_KUMA_DB_TYPE = "sqlite"; + }; + }; + + os.srv.uptime-kuma.proxyConfig = { + "uptime-kuma.${masterDomain}" = { + enableACME = true; + forceSSL = true; + + locations."/" = { + proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3001"; + extraConfig = securityTemplates.restrictToInternal; + }; + }; + }; + }; +} |
