summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authoradikro <adikro@disroot.org>2026-05-23 21:32:00 +0200
committeradikro <adikro@disroot.org>2026-05-23 21:32:00 +0200
commitc7abbc56562f9745d9d1bb29f3c0d4874425e92c (patch)
tree2e652540993b69b0d33260902b85ea1c2207d3f6
parentc6b6a3e6c702834eac2b633db2ed4c397b4ae113 (diff)
updates
-rw-r--r--flake.lock106
-rw-r--r--hm/soft/chat.nix1
-rw-r--r--hm/soft/nixvim/nixvim.nix41
-rw-r--r--hosts/desktop/configuration.nix22
-rw-r--r--hosts/desktop/home.nix2
-rw-r--r--hosts/thinkpad/configuration.nix1
-rw-r--r--hosts/thinkpad/home.nix1
-rw-r--r--os/srv/authelia.nix55
-rw-r--r--os/srv/default.nix4
-rw-r--r--os/srv/firewall.nix10
-rw-r--r--os/srv/gaming.nix6
-rw-r--r--os/srv/lldap.nix24
-rw-r--r--os/srv/nginx.nix25
-rw-r--r--os/srv/nix-helper.nix6
-rw-r--r--os/srv/ntopng.nix20
-rw-r--r--os/srv/ssh.nix111
-rw-r--r--os/srv/syncthing.nix194
-rw-r--r--os/srv/vpn.nix49
-rw-r--r--os/srv/wireguard.nix146
19 files changed, 542 insertions, 282 deletions
diff --git a/flake.lock b/flake.lock
index 1d7b54e..0409fb0 100644
--- a/flake.lock
+++ b/flake.lock
@@ -87,11 +87,11 @@
"flake-compat": {
"flake": false,
"locked": {
- "lastModified": 1751685974,
- "narHash": "sha256-NKw96t+BgHIYzHUjkTK95FqYRVKB8DHpVhefWSz/kTw=",
+ "lastModified": 1777699697,
+ "narHash": "sha256-Eg9b/rq/ECYwNwEXs5i9wHyhxNI0JrYx2srdI2uZMaQ=",
"ref": "refs/heads/main",
- "rev": "549f2762aebeff29a2e5ece7a7dc0f955281a1d1",
- "revCount": 92,
+ "rev": "382052b74656a369c5408822af3f2501e9b1af81",
+ "revCount": 94,
"type": "git",
"url": "https://git.lix.systems/lix-project/flake-compat.git"
},
@@ -161,11 +161,11 @@
]
},
"locked": {
- "lastModified": 1769996383,
- "narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=",
+ "lastModified": 1778716662,
+ "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=",
"owner": "hercules-ci",
"repo": "flake-parts",
- "rev": "57928607ea566b5db3ad13af0e57e921e6b12381",
+ "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb",
"type": "github"
},
"original": {
@@ -294,11 +294,11 @@
]
},
"locked": {
- "lastModified": 1779103424,
- "narHash": "sha256-hBYJz5jnRDjACPrwdD064zwMW+s5bdNlG/lNQipLhgM=",
+ "lastModified": 1779507042,
+ "narHash": "sha256-7wOwi8B6D0BYsieZCnHZZj2sNUzgJhLoIVSfkwB7lxQ=",
"owner": "nix-community",
"repo": "home-manager",
- "rev": "dd71501fb7005264feb4de78444a2e1518cd4f66",
+ "rev": "509ed3c603349a9d43de9e2ae6613baea6bd5b34",
"type": "github"
},
"original": {
@@ -337,11 +337,11 @@
"spectrum": "spectrum"
},
"locked": {
- "lastModified": 1779043402,
- "narHash": "sha256-1dH6yiwEck1n3oz5TDUV5TGbwNqu46eNTVHbhFO2U5k=",
+ "lastModified": 1779300350,
+ "narHash": "sha256-slQySSmaIewOxdZXF0/g0GSiVg7vJy209Yjs7fDNms8=",
"owner": "microvm-nix",
"repo": "microvm.nix",
- "rev": "77024c22f4ddf509137fc732094888d1ffe631e2",
+ "rev": "9755fd345bd64d1c75ba12b63089c926dd5d886e",
"type": "github"
},
"original": {
@@ -352,11 +352,11 @@
},
"mnw": {
"locked": {
- "lastModified": 1777828893,
- "narHash": "sha256-gVWVnmyNr74BVKfhMMZDWkhx2699dhmZ2g0W8TTHtkk=",
+ "lastModified": 1778541201,
+ "narHash": "sha256-n0twkzWexzjsoDycOTvvQNuGEdg62UiNHYcFCduYpKI=",
"owner": "Gerg-L",
"repo": "mnw",
- "rev": "c1c0b544bfabe6669b5a6a0383ccb475fe60258b",
+ "rev": "1a3573fc9d2486738fe0b2cacc5cd10dd5f3a445",
"type": "github"
},
"original": {
@@ -408,16 +408,16 @@
]
},
"locked": {
- "lastModified": 1776882296,
- "narHash": "sha256-DWZozXwMsgvUqfVlL1mQ8dOxW7GJ/8CdyaDN+1niZRg=",
+ "lastModified": 1779233504,
+ "narHash": "sha256-YIKEyzh0NFQlD0O92LQQNMoVCDwV8yw1Xz0Iu+4ZC5U=",
"owner": "feel-co",
"repo": "ndg",
- "rev": "ab7d78d4884b3a34968cf9fa3d16c0c1246d5c6e",
+ "rev": "86f6644411a64d5413711895b7cf6e0e1be465b6",
"type": "github"
},
"original": {
"owner": "feel-co",
- "ref": "refs/tags/v2.6.0",
+ "ref": "refs/tags/v2.8.0",
"repo": "ndg",
"type": "github"
}
@@ -434,11 +434,11 @@
"xwayland-satellite-unstable": "xwayland-satellite-unstable"
},
"locked": {
- "lastModified": 1778942403,
- "narHash": "sha256-SPCWvqeVySTNUgX/shARpRl5fi/NnkObUgDGR/Aco4c=",
+ "lastModified": 1779477998,
+ "narHash": "sha256-acWBiLVnoEmabvXQEfzuL9h0h+jhdzNcoCsJfpj1/88=",
"owner": "sodiboo",
"repo": "niri-flake",
- "rev": "daefca3370581223fedc24d0101c4915a3689f9e",
+ "rev": "1209504f60d88fa5bea843471c19aedb87f7e1e2",
"type": "github"
},
"original": {
@@ -467,11 +467,11 @@
"niri-unstable": {
"flake": false,
"locked": {
- "lastModified": 1778858756,
- "narHash": "sha256-9VvAHNoi2wd0fxLfJOPChZMS7l6rhCtAJmpd59Hv5rw=",
+ "lastModified": 1779374863,
+ "narHash": "sha256-qKWgJ2MUODpg+b8tOwWMdMKREvs8TdGBz63SHaQZCeA=",
"owner": "YaLTeR",
"repo": "niri",
- "rev": "cd5ac3e5e04bb5a11276d3c755fa25242818e05f",
+ "rev": "4294948cf1c70c50e938383c2c865d7ca455ac7e",
"type": "github"
},
"original": {
@@ -487,11 +487,11 @@
]
},
"locked": {
- "lastModified": 1778999476,
- "narHash": "sha256-Zs4Y8kPVsSLHVI7aOYXnZC55LhFOKqE+mf19dBBUiWw=",
+ "lastModified": 1779519816,
+ "narHash": "sha256-3WPfrkP9Idr0ex2BLqy6WsuXLR93D0JdcRSh/YE/9qs=",
"owner": "powerofthe69",
"repo": "nix-gaming-edge",
- "rev": "3d3ab84d554b50cf915a49766df6c3eb90436b5c",
+ "rev": "a8126c9e7ed0b1f169cd1870f1a69a6169982a9a",
"type": "github"
},
"original": {
@@ -502,11 +502,11 @@
},
"nixos-hardware": {
"locked": {
- "lastModified": 1779099457,
- "narHash": "sha256-u73aVD/lUmmT3JV+kPDztl7zPwQKd0eobD1AbJltaGs=",
+ "lastModified": 1779258371,
+ "narHash": "sha256-j1iZsLy6oFApqR1oiDmHhvkwxXqcNi0aoSJj643LuwU=",
"owner": "NixOS",
"repo": "nixos-hardware",
- "rev": "8792fab9d4a6454a9201675f01326f827ce35ead",
+ "rev": "c97bc4d15bd3473dd095e8e8ba57330ab1943a77",
"type": "github"
},
"original": {
@@ -549,11 +549,11 @@
},
"nixpkgs-stable": {
"locked": {
- "lastModified": 1778737229,
- "narHash": "sha256-6xWoytx8jFW4PF1GjRm/i/53trbpKGfz6zjzQGBr4cI=",
+ "lastModified": 1779102034,
+ "narHash": "sha256-vZJZjLo513IeI8hjzHFc6TDezUd4uCE2Eq4SNO3DNNg=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "d7a713c0b7e47c908258e71cba7a2d77cc8d71d5",
+ "rev": "687f05a9184cad4eaf905c48b63649e3a86f5433",
"type": "github"
},
"original": {
@@ -565,11 +565,11 @@
},
"nixpkgs-stable_2": {
"locked": {
- "lastModified": 1778737229,
- "narHash": "sha256-6xWoytx8jFW4PF1GjRm/i/53trbpKGfz6zjzQGBr4cI=",
+ "lastModified": 1779102034,
+ "narHash": "sha256-vZJZjLo513IeI8hjzHFc6TDezUd4uCE2Eq4SNO3DNNg=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "d7a713c0b7e47c908258e71cba7a2d77cc8d71d5",
+ "rev": "687f05a9184cad4eaf905c48b63649e3a86f5433",
"type": "github"
},
"original": {
@@ -581,11 +581,11 @@
},
"nixpkgs_2": {
"locked": {
- "lastModified": 1778869304,
- "narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
+ "lastModified": 1779357205,
+ "narHash": "sha256-cCO8aTqss5x9Ky8GWkpY0Hy5fyTZEbtifSUV8QjSzic=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "d233902339c02a9c334e7e593de68855ad26c4cb",
+ "rev": "f83fc3c307e74bc5fd5adb7eb6b8b13ffd2a36e1",
"type": "github"
},
"original": {
@@ -620,11 +620,11 @@
"systems": "systems_2"
},
"locked": {
- "lastModified": 1779092748,
- "narHash": "sha256-NliK7JRrPh44IbVwoLi/s7dleSfwoGXgu69d1PjhYdw=",
+ "lastModified": 1779554657,
+ "narHash": "sha256-qjLcUp7DBpmSUL+nVjLymp2nEvAzeKKoAVDCRgZYxFk=",
"owner": "nix-community",
"repo": "nixvim",
- "rev": "2e60ad952a9f4b0a1c275a79a1a44c8e3a088789",
+ "rev": "1a380f12453ba97ad8cc9c60f223afb1cb8bace8",
"type": "github"
},
"original": {
@@ -645,11 +645,11 @@
"systems": "systems_3"
},
"locked": {
- "lastModified": 1779018518,
- "narHash": "sha256-RUmjcuxbaa8UKsd5rUO5bqDe9YxGBDLXd4tFFBi351E=",
+ "lastModified": 1779461836,
+ "narHash": "sha256-iV6reLT7o1XfofI+mLuFZl7TdDXzsnniXge6aFXjjrc=",
"owner": "NotAShelf",
"repo": "nvf",
- "rev": "cd45295f9c65ca81f323155660ba83d427bd0154",
+ "rev": "21849b62be17c6657accbf4e0c9e1afe57e27ea3",
"type": "github"
},
"original": {
@@ -714,11 +714,11 @@
"systems": "systems_5"
},
"locked": {
- "lastModified": 1779026498,
- "narHash": "sha256-oQw4/UqDpE/K0lkc+zFXdWsNKps9p0rZg6ybMwVDhsM=",
+ "lastModified": 1779154764,
+ "narHash": "sha256-D3wp7vR3+ktTNJ54rUWHIK6Y5tGeNXDD4FBO785wl0E=",
"owner": "kuokuo123",
"repo": "otter-launcher",
- "rev": "380ceb9d2cf9b02854fbd3be39177e5e151fae6c",
+ "rev": "b1c2c0992403f52dff1f5754cc250ee6e121e342",
"type": "github"
},
"original": {
@@ -1113,11 +1113,11 @@
"rust-overlay": "rust-overlay_2"
},
"locked": {
- "lastModified": 1778801438,
- "narHash": "sha256-TtawbMZ+tgKAiDpkJJw7m2OLOJHUbRZB0xLDXBxTPck=",
+ "lastModified": 1779505360,
+ "narHash": "sha256-V9emUCEpW4lf73LreHeCpdH48R4GCmeEVE7za8V+QM0=",
"owner": "sxyazi",
"repo": "yazi",
- "rev": "3f5cc47a4852cbffbd8536507ae7499d3da1f0b7",
+ "rev": "d9cd1907d91927a36efe7296eee2a7d8975230f8",
"type": "github"
},
"original": {
diff --git a/hm/soft/chat.nix b/hm/soft/chat.nix
index d7f0020..b886656 100644
--- a/hm/soft/chat.nix
+++ b/hm/soft/chat.nix
@@ -11,6 +11,7 @@ in
options.hm.soft.chat.enable = lib.mkEnableOption "chatting apps";
config = lib.mkIf cfg.enable {
home.packages = with pkgs; [
+ telegram-desktop
simplex-chat-desktop
signal-desktop
equibop
diff --git a/hm/soft/nixvim/nixvim.nix b/hm/soft/nixvim/nixvim.nix
index efd348e..7013c27 100644
--- a/hm/soft/nixvim/nixvim.nix
+++ b/hm/soft/nixvim/nixvim.nix
@@ -24,6 +24,17 @@ in
globals.mapleader = " ";
+ autoCmd = [
+ {
+ event = [ "BufWritePost" ];
+ pattern = [ "*/dotfiles/waybar/.config/waybar/*" ];
+ callback.__raw = ''
+ function()
+ vim.fn.jobstart({ "systemctl", "--user", "restart", "waybar.service" })
+ end
+ '';
+ }
+ ];
clipboard = {
providers.wl-copy.enable = true;
register = "unnamedplus";
@@ -61,12 +72,6 @@ in
}
{
mode = "n";
- key = "<leader>gs";
- action = "<cmd>Neogit<CR>";
- options.desc = "Neogit Status";
- }
- {
- mode = "n";
key = "<leader>ff";
action = "<cmd>Telescope find_files<CR>";
options.desc = "Find Files";
@@ -109,30 +114,6 @@ in
}
{
mode = "n";
- key = "<leader>ma";
- action = "<cmd>MCpattern<CR>";
- options.desc = "Select all matches of pattern";
- }
- {
- mode = "n";
- key = "<leader>ha";
- action = ''<cmd>lua require("harpoon.mark").add_file()<CR>'';
- options.desc = "Harpoon: Mark File";
- }
- {
- mode = "n";
- key = "<leader>hh";
- action = ''<cmd>lua require("harpoon.ui").toggle_quick_menu()<CR>'';
- options.desc = "Harpoon: Show Menu";
- }
- {
- mode = "n";
- key = "<leader>xx";
- action = "<cmd>Trouble diagnostics toggle<CR>";
- options.desc = "Toggle Trouble (Diagnostics)";
- }
- {
- mode = "n";
key = "<leader>p";
action = "<cmd>Telescope yank_history<CR>";
options.desc = "Open Yank History";
diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix
index 0f0f63e..adfb5a3 100644
--- a/hosts/desktop/configuration.nix
+++ b/hosts/desktop/configuration.nix
@@ -54,7 +54,14 @@
srv = {
bluetooth.enable = true;
tailscale.enable = true;
- ssh.enable = true;
+ ssh = {
+ server.enable = true;
+ client = {
+ enable = true;
+ createAliases = true;
+ };
+ enableSigning = true;
+ };
firewall.enable = true;
yggdrasil.enable = true;
i2p.enable = true;
@@ -81,9 +88,18 @@
nix-helper.enable = true;
monero.wallet.enable = true;
sops.enable = true;
- syncthing.enable = true;
+ syncthing = {
+ enable = true;
+ activeFolders = [
+ "openmw-config"
+ "openmw-mods"
+ "game-saves"
+ "keepass"
+ "sync"
+ "music"
+ ];
+ };
omnisearch.enable = true;
- vpn.enable = true;
};
wm = {
enable = true;
diff --git a/hosts/desktop/home.nix b/hosts/desktop/home.nix
index 5a4f373..cdce283 100644
--- a/hosts/desktop/home.nix
+++ b/hosts/desktop/home.nix
@@ -94,6 +94,8 @@
};
home.packages = with pkgs; [
+ cosmic-files
+ feishin
tmux
gimp
stow
diff --git a/hosts/thinkpad/configuration.nix b/hosts/thinkpad/configuration.nix
index 0fe2945..9f27ac0 100644
--- a/hosts/thinkpad/configuration.nix
+++ b/hosts/thinkpad/configuration.nix
@@ -79,7 +79,6 @@
monero.wallet.enable = true;
sops.enable = true;
syncthing.enable = true;
- vpn.enable = true;
};
wm = {
enable = true;
diff --git a/hosts/thinkpad/home.nix b/hosts/thinkpad/home.nix
index 8676adc..9b6dd95 100644
--- a/hosts/thinkpad/home.nix
+++ b/hosts/thinkpad/home.nix
@@ -64,6 +64,5 @@
home.packages = with pkgs; [
stow
gimp
- telegram-desktop
];
}
diff --git a/os/srv/authelia.nix b/os/srv/authelia.nix
new file mode 100644
index 0000000..a7a8c19
--- /dev/null
+++ b/os/srv/authelia.nix
@@ -0,0 +1,55 @@
+{
+ config,
+ lib,
+ masterDomain,
+ ...
+}:
+let
+ cfg = config.os.srv.authelia;
+in
+{
+ options.os.srv.authelia.enable = lib.mkEnableOption "enables authelia scanning";
+ options.os.services.authelia.extraRules = lib.mkOption {
+ type = lib.types.listOf lib.types.attrs;
+ default = [ ];
+ description = "Additional access control rules to be appended to Authelia.";
+ };
+ config = lib.mkIf cfg.enable {
+ assertions = [
+ {
+ assertion = config.os.srv.sops.enable;
+ message = "Required for password secure password storing";
+ }
+ ];
+ services.authelia.instances.main = {
+ enable = true;
+ secrets = {
+ jwtSecretFile = config.sops.secrets."authelia/jwt_secret".path;
+ storageEncryptionKeyFile = config.sops.secrets."authelia/encryptionKey".path;
+ };
+ settings = {
+ theme = "dark";
+ authentication_backend = {
+ ldap = {
+ address = "ldap://127.0.0.1:3890";
+ implementation = "lldap";
+ base_dn = "dc=example,dc=com";
+ user = "uid=authelia,ou=people,dc=example,dc=com";
+ password_file = config.sops.secrets."lldap/bind_password".path;
+ };
+ };
+ access_control = {
+ default_policy = "deny";
+ rules = [
+ {
+ domain = "auth.${masterDomain}";
+ policy = "bypass";
+ }
+ ]
+ ++ config.os.services.authelia.extraRules;
+ };
+ session.domain = masterDomain;
+ };
+ };
+ };
+}
diff --git a/os/srv/default.nix b/os/srv/default.nix
index d42fdb9..9bba42b 100644
--- a/os/srv/default.nix
+++ b/os/srv/default.nix
@@ -2,6 +2,7 @@
{
imports = [
./aide.nix
+ ./authelia.nix
./backup.nix
./bluetooth.nix
./clamav.nix
@@ -13,10 +14,12 @@
./gaming.nix
./i2p.nix
./kdeconnect.nix
+ ./lldap.nix
./monero.nix
./nfs.nix
./nginx.nix
./nix-helper.nix
+ ./ntopng.nix
./oci.nix
./omnisearch.nix
./opnsense.nix
@@ -28,7 +31,6 @@
./tailscale.nix
./tor.nix
./virtualization.nix
- ./vpn.nix
./wireguard.nix
./yggdrasil.nix
./zfs.nix
diff --git a/os/srv/firewall.nix b/os/srv/firewall.nix
index 9242007..bc06ffe 100644
--- a/os/srv/firewall.nix
+++ b/os/srv/firewall.nix
@@ -4,19 +4,13 @@ let
in
{
options.os.srv.firewall = {
- enable = lib.mkEnableOption "enables the firewall";
+ enable = lib.mkEnableOption "enables the nixos firewall and nftables";
};
config = lib.mkIf cfg.enable {
networking = {
+ firewall.enable = true;
nftables.enable = true;
-
- firewall = {
- enable = true;
-
- allowedTCPPorts = [ ];
- allowedUDPPorts = [ ];
- };
};
};
}
diff --git a/os/srv/gaming.nix b/os/srv/gaming.nix
index 1e3e9cd..28e309a 100644
--- a/os/srv/gaming.nix
+++ b/os/srv/gaming.nix
@@ -107,9 +107,9 @@ in
home.packages = [ inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped ];
xdg.desktopEntries = {
- "SLSsteam" = {
- name = "SLSsteam";
- comment = "Library modification for Steam";
+ steam = {
+ name = "Steam";
+ comment = "Library modified Steam client";
exec = "${
lib.getExe' inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped "SLSsteam"
} %U";
diff --git a/os/srv/lldap.nix b/os/srv/lldap.nix
new file mode 100644
index 0000000..1cf43e4
--- /dev/null
+++ b/os/srv/lldap.nix
@@ -0,0 +1,24 @@
+{ config, lib, ... }:
+let
+ cfg = config.os.srv.lldap;
+in
+{
+ options.os.srv.lldap.enable = lib.mkEnableOption "enables lldap scanning";
+ config = lib.mkIf cfg.enable {
+ assertions = [
+ {
+ assertion = config.os.srv.sops.enable;
+ message = "Required for password secure password storing";
+ }
+ ];
+ services.lldap = {
+ enable = true;
+ settings = {
+ ldap_base_dn = "dc=example,dc=com";
+ ldap_port = 3890;
+ http_port = 17170;
+ };
+ environmentFile = config.sops.secrets."lldap/env".path;
+ };
+ };
+}
diff --git a/os/srv/nginx.nix b/os/srv/nginx.nix
index b0c01a7..f0207b3 100644
--- a/os/srv/nginx.nix
+++ b/os/srv/nginx.nix
@@ -1,4 +1,9 @@
-{ config, lib, ... }:
+{
+ config,
+ lib,
+ pkgs,
+ ...
+}:
let
cfg = config.os.srv.nginx;
@@ -17,14 +22,30 @@ in
config = lib.mkIf cfg.enable {
services.nginx = {
enable = true;
+ package = pkgs.nginx.override { openssl = pkgs.libressl; };
recommendedProxySettings = true;
recommendedTlsSettings = true;
recommendedOptimisation = true;
recommendedGzipSettings = true;
+ virtualHosts = {
+ default = {
+ serverName = "_";
+ default = true;
+ rejectSSL = true;
+ locations."/".return = "444";
+ };
+ };
+ };
+
+ security.acme = {
+ acceptTerms = true;
+ defaults.email = "adikro@disroot.org";
};
- networking.firewall.allowedTCPPorts = lib.mkOptional cfg.openFirewall [
+ # users.users.nginx.extraGroups = [ "acme" ];
+
+ networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [
80
443
];
diff --git a/os/srv/nix-helper.nix b/os/srv/nix-helper.nix
index 5e5e133..9734043 100644
--- a/os/srv/nix-helper.nix
+++ b/os/srv/nix-helper.nix
@@ -2,7 +2,6 @@
config,
lib,
pkgs,
- username,
...
}:
let
@@ -12,10 +11,7 @@ in
options.os.srv.nix-helper.enable = lib.mkEnableOption "enables nix-helper";
config = lib.mkIf cfg.enable {
nix.settings = {
- trusted-users = [
- "root"
- "${username}"
- ];
+ allowed-users = [ "@users" ];
experimental-features = [
"nix-command"
"flakes"
diff --git a/os/srv/ntopng.nix b/os/srv/ntopng.nix
new file mode 100644
index 0000000..3c11534
--- /dev/null
+++ b/os/srv/ntopng.nix
@@ -0,0 +1,20 @@
+{ config, lib, ... }:
+let
+ cfg = config.os.srv.ntopng;
+in
+{
+ options.os.srv.ntopng.enable = lib.mkEnableOption "enables ntopng monitoring";
+ config = lib.mkIf cfg.enable {
+ services.ntopng = {
+ enable = true;
+ httpPort = 3000;
+ extraConfig = "--packet-fanout";
+
+ # TODO fill interfaces
+ interfaces = [
+ ""
+ ""
+ ];
+ };
+ };
+}
diff --git a/os/srv/ssh.nix b/os/srv/ssh.nix
index 089fb32..2c7a4ac 100644
--- a/os/srv/ssh.nix
+++ b/os/srv/ssh.nix
@@ -6,50 +6,85 @@
}:
let
cfg = config.os.srv.ssh;
- keys = {
- main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC610CJfgc3yII7MpLVqzEzQGa8Tsm+dih+CTXHXTnv4";
- oci = "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCgWmRbNTP/kcaZ8JNV1boVTZ/FQVV4qP/9eTKL9buzDvz9HJdgyWmbCiVZicNSert31IRdWOF/wm1sFjZ48nSkGDHbrnc//MPSdHULTx+kMES/NW9SZwwpaquFIJClrObysxrFYBAqweD+DJ3bp451WIymBs7lRBMNKPgoHBpJ5WN2CfIQjl60Jqnli7ML5seCsrquPEemcMPr1TFPmrFCbirzgDVkzCLL5kOowSD2uprtSA08fFm/pZ6nZh6KTQaEgPO4zR9tK+NQ46oCynWwBTI7JOPB4/LtIOiC5TjEUrkXZ/sJzpCBiNPYSRI8RWnAD0N/uVFJ4EYPUKLO2C/d";
- };
+ keys.main = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC610CJfgc3yII7MpLVqzEzQGa8Tsm+dih+CTXHXTnv4";
in
{
- options.os.srv.ssh.enable = lib.mkEnableOption "enables ssh server setup";
-
- config = lib.mkIf cfg.enable {
- services.openssh = {
- enable = true;
- settings = {
- PasswordAuthentication = false;
- KbdInteractiveAuthentication = false;
- };
+ options.os.srv.ssh = {
+ server = {
+ enable = lib.mkEnableOption "enables the ssh server module";
+ enableWireguard = lib.mkEnableOption "only allows connections from wireguard";
};
+ client = {
+ enable = lib.mkEnableOption "enables the ssh client module";
+ createAliases = lib.mkEnableOption "enables system-wide SSH shortcuts";
+ };
+ enableSigning = lib.mkEnableOption "enables signing git commits with ssh keys";
+ };
- programs.ssh.startAgent = true;
- services.gnome.gcr-ssh-agent.enable = false;
-
- users.users.${username}.openssh.authorizedKeys.keys = [ "${keys.main} adikro@disroot.org" ];
-
- environment.etc."ssh/allowed_signers".text = "adikro@disroot.org ${keys.main}";
- home-manager.users.${username} = {
- programs.ssh = {
+ config = lib.mkMerge [
+ (lib.mkIf cfg.server.enable {
+ services.openssh = {
enable = true;
- enableDefaultConfig = false;
- matchBlocks = {
- "github.com codeberg.org" = {
- identityFile = "~/.ssh/main_id_ed25519.pub";
- identitiesOnly = true;
- user = "git";
- };
- "oci" = {
- hostname = "130.162.223.123";
- user = "opc";
- };
+ hostKeys = [
+ {
+ path = "/etc/ssh/ssh_host_ed25519_key";
+ type = "ed25519";
+ }
+ ];
+ settings = {
+ PasswordAuthentication = false;
+ KbdInteractiveAuthentication = false;
+ PermitRootLogin = "no";
+
+ PubkeyAcceptedAlgorithms = "ssh-ed25519";
};
};
- home.file = {
- ".ssh/main_id_ed25519.pub".text = keys.main;
- ".ssh/oci.pub".text = keys.oci;
- };
- };
- };
+
+ users.users.${username}.openssh.authorizedKeys.keys = [
+ "${keys.main} adikro@disroot.org"
+ ];
+ })
+ (lib.mkIf (cfg.server.enable && cfg.server.enableWireguard) {
+ services.openssh.listenAddresses = [
+ {
+ addr = "10.255.0.1";
+ }
+ ];
+ })
+
+ (lib.mkIf cfg.client.enable {
+ programs.ssh.startAgent = true;
+ services.gnome.gcr-ssh-agent.enable = false;
+ })
+
+ (lib.mkIf (cfg.client.enable && cfg.client.createAliases) {
+ programs.ssh.extraConfig = ''
+ Host github.com codeberg.org
+ IdentityFile /home/${username}/.ssh/main_id_ed25519.pub
+ IdentitiesOnly yes
+ User git
+
+ Host oci
+ HostName 130.162.223.123
+ User opc
+
+ Host bibus
+ HostName bibus.top
+ User opc
+
+ Host bibus-local
+ HostName 10.255.0.1
+ user opc
+ '';
+ systemd.tmpfiles.rules = [
+ "d /home/${username}/.ssh 0700 ${username} users - -"
+ "f /home/${username}/.ssh/main_id_ed25519.pub 0644 ${username} users - ${keys.main}"
+ ];
+ })
+
+ (lib.mkIf cfg.enableSigning {
+ environment.etc."ssh/allowed_signers".text = "adikro@disroot.org ${keys.main}";
+ })
+ ];
}
diff --git a/os/srv/syncthing.nix b/os/srv/syncthing.nix
index 28806f1..bcbf665 100644
--- a/os/srv/syncthing.nix
+++ b/os/srv/syncthing.nix
@@ -6,10 +6,116 @@
}:
let
cfg = config.os.srv.syncthing;
- syncDirs = lib.mapAttrsToList (_: folder: folder.path) config.services.syncthing.settings.folders;
+ allFolders = {
+ "openmw-config" = {
+ path = "/home/${username}/.config/openmw";
+ id = "openmw-config";
+ devices = [ "oci" ];
+ versioning = {
+ type = "simple";
+ params.keep = "3";
+ };
+ ignorePatterns = [
+ "settings.cfg"
+ "*.log"
+ ];
+ };
+
+ "openmw-mods" = {
+ path = "/home/${username}/games/openmw";
+ id = "openmw-mods";
+ devices = [ "oci" ];
+ versioning = {
+ type = "trashcan";
+ params.cleanoutDays = "7";
+ };
+ };
+
+ "game-saves" = {
+ path = "/home/${username}/.saves";
+ id = "game-saves";
+ devices = [ "oci" ];
+ versioning = {
+ type = "staggered";
+ params = {
+ cleanInterval = "3600";
+ maxAge = "2592000";
+ };
+ };
+ };
+
+ "keepass" = {
+ path = "/home/${username}/.keepass";
+ id = "keepass";
+ devices = [
+ {
+ name = "oci";
+ encryptionPasswordFile = config.sops.secrets."syncthing/encryption/keepass".path;
+ }
+ ];
+ versioning = {
+ type = "staggered";
+ params = {
+ cleanInterval = "3600";
+ maxAge = "31536000";
+ };
+ };
+ };
+
+ "sync" = {
+ path = "/home/${username}/sync";
+ id = "sync";
+ devices = [
+ {
+ name = "oci";
+ encryptionPasswordFile = config.sops.secrets."syncthing/encryption/sync".path;
+ }
+ ];
+ versioning = {
+ type = "staggered";
+ params = {
+ cleanInterval = "3600";
+ maxAge = "15552000";
+ };
+ };
+ };
+
+ "music" = {
+ path = "/storage/music";
+ id = "music";
+ devices = [ "oci" ];
+ versioning = {
+ type = "trashcan";
+ params.cleanoutDays = "14";
+ };
+ };
+ };
+ activeFoldersSet = lib.filterAttrs (name: _: builtins.elem name cfg.activeFolders) allFolders;
+
+ syncDirs = lib.mapAttrsToList (_: folder: folder.path) activeFoldersSet;
in
{
- options.os.srv.syncthing.enable = lib.mkEnableOption "enables syncthing syncing";
+ options.os.srv.syncthing = {
+ enable = lib.mkEnableOption "enables syncthing syncing";
+
+ activeFolders = lib.mkOption {
+ type = lib.types.listOf (
+ lib.types.enum [
+ "openmw-config"
+ "openmw-mods"
+ "game-saves"
+ "keepass"
+ "sync"
+ "music"
+ ]
+ );
+ default = [
+ "keepass"
+ "sync"
+ ];
+ description = "List of Syncthing folders to enable and sync on this specific machine.";
+ };
+ };
config = lib.mkIf cfg.enable {
systemd.tmpfiles.rules = map (path: "d ${path} 0755 ${username} users -") syncDirs;
@@ -23,89 +129,7 @@ in
settings = {
devices."oci".id = "DQXGVDC-KGPM6RK-5NDEBJJ-R7PEWYZ-N6Z3WFZ-TSVJG5X-235SHG4-4BEJNQJ";
- folders = {
- "openmw-config" = {
- path = "/home/${username}/.config/openmw";
- id = "openmw-config";
- devices = [
- {
- name = "oci";
- encryptionPasswordFile = config.sops.secrets."syncthing/encryption/openmw-config".path;
- }
- ];
- versioning = {
- type = "simple";
- params.keep = "3";
- };
- ignorePatterns = [
- "settings.cfg"
- "*.log"
- ];
- };
-
- "openmw-mods" = {
- path = "/home/${username}/games/openmw";
- id = "openmw-mods";
- devices = [
- {
- name = "oci";
- encryptionPasswordFile = config.sops.secrets."syncthing/encryption/openmw-mods".path;
- }
- ];
- versioning = {
- type = "trashcan";
- params.cleanoutDays = "7";
- };
- };
-
- "game-saves" = {
- path = "/home/${username}/.saves";
- id = "game-saves";
- devices = [
- {
- name = "oci";
- encryptionPasswordFile = config.sops.secrets."syncthing/encryption/game-saves".path;
- }
- ];
- versioning = {
- type = "staggered";
- params = {
- cleanInterval = "3600";
- maxAge = "2592000";
- };
- };
- };
-
- "keepass" = {
- path = "/home/${username}/.keepass";
- id = "keepass";
- devices = [
- {
- name = "oci";
- encryptionPasswordFile = config.sops.secrets."syncthing/encryption/keepass".path;
- }
- ];
- versioning = {
- type = "simple";
- params.keep = "10";
- };
- };
-
- "sync" = {
- path = "/home/${username}/sync";
- id = "sync";
- devices = [
- {
- name = "oci";
- encryptionPasswordFile = config.sops.secrets."syncthing/encryption/sync".path;
- }
- ];
- versioning = {
- type = "simple";
- params.keep = "3";
- };
- };
- };
+ folders = activeFoldersSet;
};
};
};
diff --git a/os/srv/vpn.nix b/os/srv/vpn.nix
deleted file mode 100644
index 28c7a9e..0000000
--- a/os/srv/vpn.nix
+++ /dev/null
@@ -1,49 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}:
-let
- cfg = config.os.srv.vpn;
- netCfg = config.os.core.network;
-in
-{
- options.os.srv.vpn.enable = lib.mkEnableOption "enables vpn stuff";
-
- config = lib.mkIf (cfg.enable && netCfg.enable) {
- networking.networkmanager.ensureProfiles = {
- environmentFiles = [ config.sops.secrets."vpn/warp_private_key".path ];
- profiles.cloudflare-warp = {
- connection = {
- id = "cloudflare-warp";
- type = "wireguard";
- interface-name = "wg0";
- autoconnect = false;
- };
- wireguard = {
- mtu = 1200;
- private-key = "$WG_KEY";
- };
- "wireguard-peer.bmXOC+F1FxEMF9dyiK2H5/1SUtzH0JuVo51h2wPfgyo=" = {
- endpoint = "engage.cloudflareclient.com:2408";
- allowed-ips = "0.0.0.0/0;::/0;";
- };
- ipv4 = {
- method = "manual";
- address1 = "172.16.0.2/32";
- dns = "1.1.1.1;1.0.0.1;";
- };
- ipv6 = {
- method = "manual";
- address1 = "2606:4700:110:84c7:36c4:e444:5efb:b108/128";
- dns = "2606:4700:4700::1111;2606:4700:4700::1001;";
- };
- };
- };
- environment.systemPackages = with pkgs; [
- wgcf
- wireguard-tools
- ];
- };
-}
diff --git a/os/srv/wireguard.nix b/os/srv/wireguard.nix
index 4b9dbc4..15675a4 100644
--- a/os/srv/wireguard.nix
+++ b/os/srv/wireguard.nix
@@ -1,9 +1,149 @@
-{ config, lib, ... }:
+{
+ config,
+ lib,
+ hostname,
+ masterDomain,
+ ...
+}:
let
cfg = config.os.srv.wireguard;
in
{
- options.os.srv.wireguard.enable = lib.mkEnableOption "enables wireguard vpn";
- config = lib.mkIf cfg.enable {
+ options.os.srv.wireguard = {
+ enable = lib.mkEnableOption "enables wireguard vpn";
+
+ role = lib.mkOption {
+ type = lib.types.enum [
+ "server"
+ "client"
+ ];
+ default = "client";
+ description = "where the machine is accepting connections or connecting";
+ };
+
+ server = {
+ externalInterface = lib.mkOption {
+ type = lib.types.str;
+ default = "eth0";
+ description = "The public WAN interface of the server";
+ };
+
+ peers = lib.mkOption {
+ type = lib.types.listOf (
+ lib.types.submodule {
+ options = {
+ name = lib.mkOption { type = lib.types.str; };
+ publicKey = lib.mkOption { type = lib.types.str; };
+ };
+ }
+ );
+ default = [ ];
+ description = "List of client peers authorized to connect to this server";
+ };
+ };
+
+ client = {
+ index = lib.mkOption {
+ type = lib.types.nullOr lib.types.int;
+ default = null;
+ description = "The assigned host index number for the client IP address";
+ };
+
+ routeAllTraffic = lib.mkOption {
+ type = lib.types.bool;
+ default = false;
+ description = "Routes 100% of your internet traffic through the server when active";
+ };
+ };
};
+
+ config = lib.mkIf cfg.enable (
+ lib.mkMerge [
+ {
+ assertions = [
+ {
+ assertion = config.os.srv.sops.enable;
+ message = "required for wg private key";
+ }
+ ];
+
+ sops.secrets."wg_private_key/${hostname}" = {
+ owner = "root";
+ group = "root";
+ mode = "0600";
+ };
+ }
+
+ (lib.mkIf (cfg.role == "server") {
+ assertions = [
+ {
+ assertion = config.os.srv.firewall.enable;
+ message = "required for opening ports and passthrough";
+ }
+ ];
+ boot.kernel.sysctl."net.ipv4.ip_forward" = 1;
+ networking.firewall.allowedUDPPorts = [ 51280 ];
+
+ networking.nftables = {
+ tables.wg-nat = {
+ family = "inet";
+ content = ''
+ chain forward {
+ type filter hook forward priority 0; policy accept;
+ iifname "wg0" accept
+ oifname "wg0" accept
+ }
+
+ chain postrouting {
+ type nat hook postrouting priority 100; policy accept;
+ iifname "wg0" oifname "${cfg.server.externalInterface}" masquerade
+ }
+ '';
+ };
+ };
+
+ networking.wireguard.interfaces.wg0 = {
+ ips = [ "10.255.1.1/16" ];
+ listenPort = 51280;
+ privateKeyFile = config.sops.secrets."wg_private_key/${hostname}".path;
+
+ peers = lib.imap1 (i: peer: {
+ publicKey = peer.publicKey;
+ allowedIPs = [ "10.255.0.${toString i}/32" ];
+ persistentKeepalive = 25;
+ }) cfg.server.peers;
+ };
+ })
+
+ (lib.mkIf (cfg.role == "client") {
+ assertions = [
+ {
+ assertion = cfg.client.index != null;
+ message = "WireGuard client role requires a valid 'client.index' integer designation.";
+ }
+ ];
+
+ networking.nameservers = [
+ "10.255.1.1"
+ "9.9.9.9"
+ ];
+
+ networking.wireguard.interfaces.wg0 = {
+ ips = [ "10.255.0.${toString cfg.client.index}/16" ];
+ privateKeyFile = config.sops.secrets."wg_private_key/${hostname}".path;
+
+ peers = [
+ {
+ # TODO get the server public key
+ publicKey = "";
+ endpoint = "${masterDomain}:51280";
+ persistentKeepalive = 25;
+
+ allowedIPs = if cfg.client.routeAllTraffic then [ "0.0.0.0/0" ] else [ "10.255.0.0/16" ];
+ }
+ ];
+ };
+ })
+ ]
+ );
}