summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--flake.lock811
-rw-r--r--flake.nix164
-rw-r--r--hosts/bibus-lab/configuration.nix13
-rw-r--r--hosts/bibus-lab/disko.nix249
-rw-r--r--hosts/desktop/1119
-rw-r--r--hosts/desktop/hardware-configuration.nix71
-rw-r--r--modules/audio.nix96
-rw-r--r--modules/bluetooth.nix (renamed from os/srv/bluetooth.nix)0
-rw-r--r--modules/bootloader.nix (renamed from os/core/bootloader.nix)0
-rw-r--r--modules/compat.nix (renamed from os/srv/compat.nix)0
-rw-r--r--modules/drivers.nix (renamed from os/core/drivers.nix)0
-rw-r--r--modules/files.nix (renamed from os/srv/files.nix)0
-rw-r--r--modules/fonts.nix (renamed from os/core/fonts.nix)14
-rw-r--r--modules/gaming.nix (renamed from os/srv/gaming.nix)0
-rw-r--r--modules/greet.nix (renamed from os/core/greet.nix)0
-rw-r--r--modules/i2p.nix (renamed from os/srv/i2p.nix)0
-rw-r--r--modules/localization.nix (renamed from os/core/localization.nix)0
-rw-r--r--modules/memory.nix (renamed from os/core/memory.nix)0
-rw-r--r--modules/monero.nix (renamed from os/srv/monero.nix)0
-rw-r--r--modules/networking.nix (renamed from os/core/networking.nix)0
-rw-r--r--modules/niri.nix (renamed from os/wm/niri.nix)0
-rw-r--r--modules/nix-helper.nix (renamed from os/srv/nix-helper.nix)0
-rw-r--r--modules/omnisearch.nix (renamed from os/srv/omnisearch.nix)0
-rw-r--r--modules/persistance.nix (renamed from os/core/persistance.nix)0
-rw-r--r--modules/power.nix (renamed from os/core/power.nix)0
-rw-r--r--modules/security.nix (renamed from os/core/security.nix)0
-rw-r--r--modules/sops.nix (renamed from os/srv/sops.nix)0
-rw-r--r--modules/ssh.nix (renamed from os/srv/ssh.nix)0
-rw-r--r--modules/storage.nix (renamed from os/core/storage.nix)0
-rw-r--r--modules/syncthing.nix (renamed from os/srv/syncthing.nix)0
-rw-r--r--modules/tor.nix (renamed from os/srv/tor.nix)0
-rw-r--r--modules/users.nix (renamed from os/core/users.nix)0
-rw-r--r--modules/virtualization.nix (renamed from os/srv/virtualization.nix)0
-rw-r--r--os/core/audio.nix146
-rw-r--r--os/core/default.nix36
-rw-r--r--os/core/home-manager.nix44
-rw-r--r--os/core/zfs.nix60
-rw-r--r--os/default.nix9
-rw-r--r--os/srv/authelia.nix179
-rw-r--r--os/srv/avahi.nix41
-rw-r--r--os/srv/backup.nix97
-rw-r--r--os/srv/clamav.nix21
-rw-r--r--os/srv/cluster.nix16
-rw-r--r--os/srv/crowdsec.nix181
-rw-r--r--os/srv/default.nix48
-rw-r--r--os/srv/dns.nix286
-rw-r--r--os/srv/grafana.nix109
-rw-r--r--os/srv/headscale.nix76
-rw-r--r--os/srv/kea.nix58
-rw-r--r--os/srv/lldap.nix55
-rw-r--r--os/srv/loki.nix62
-rw-r--r--os/srv/mailserver.nix59
-rw-r--r--os/srv/netdata.nix43
-rw-r--r--os/srv/nfs.nix26
-rw-r--r--os/srv/nginx.nix75
-rw-r--r--os/srv/ntfy.nix59
-rw-r--r--os/srv/ntopng.nix43
-rw-r--r--os/srv/oci.nix36
-rw-r--r--os/srv/postgres.nix72
-rw-r--r--os/srv/prometheus.nix75
-rw-r--r--os/srv/redis.nix37
-rw-r--r--os/srv/restic.nix12
-rw-r--r--os/srv/scrutiny.nix35
-rw-r--r--os/srv/simplex.nix129
-rw-r--r--os/srv/sunshine.nix42
-rw-r--r--os/srv/tailscale.nix19
-rw-r--r--os/srv/ups.nix35
-rw-r--r--os/srv/uptime-kuma.nix41
-rw-r--r--os/srv/vector.nix79
-rw-r--r--os/srv/wireguard.nix152
-rw-r--r--os/srv/yggdrasil.nix44
-rw-r--r--os/vms/microvms.nix37
-rw-r--r--os/vms/net-core.nix30
-rw-r--r--os/vms/opnsense.nix95
-rw-r--r--os/wm/default.nix37
75 files changed, 243 insertions, 4130 deletions
diff --git a/flake.lock b/flake.lock
index ced4b22..c5ffb4d 100644
--- a/flake.lock
+++ b/flake.lock
@@ -18,22 +18,6 @@
"url": "https://git.bwaaa.monster/beaker"
}
},
- "blobs": {
- "flake": false,
- "locked": {
- "lastModified": 1604995301,
- "narHash": "sha256-wcLzgLec6SGJA8fx1OEN1yV/Py5b+U5iyYpksUY/yLw=",
- "owner": "simple-nixos-mailserver",
- "repo": "blobs",
- "rev": "2cccdf1ca48316f2cfd1c9a0017e8de5a7156265",
- "type": "gitlab"
- },
- "original": {
- "owner": "simple-nixos-mailserver",
- "repo": "blobs",
- "type": "gitlab"
- }
- },
"disko": {
"inputs": {
"nixpkgs": [
@@ -58,33 +42,10 @@
"fenix": {
"inputs": {
"nixpkgs": [
- "fsel",
- "naersk",
- "nixpkgs"
- ],
- "rust-analyzer-src": "rust-analyzer-src"
- },
- "locked": {
- "lastModified": 1752475459,
- "narHash": "sha256-z6QEu4ZFuHiqdOPbYss4/Q8B0BFhacR8ts6jO/F/aOU=",
- "owner": "nix-community",
- "repo": "fenix",
- "rev": "bf0d6f70f4c9a9cf8845f992105652173f4b617f",
- "type": "github"
- },
- "original": {
- "owner": "nix-community",
- "repo": "fenix",
- "type": "github"
- }
- },
- "fenix_2": {
- "inputs": {
- "nixpkgs": [
"openmw-nix",
"nixpkgs"
],
- "rust-analyzer-src": "rust-analyzer-src_2"
+ "rust-analyzer-src": "rust-analyzer-src"
},
"locked": {
"lastModified": 1759560021,
@@ -103,38 +64,6 @@
"flake-compat": {
"flake": false,
"locked": {
- "lastModified": 1767039857,
- "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
- "owner": "NixOS",
- "repo": "flake-compat",
- "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
- "type": "github"
- },
- "original": {
- "owner": "NixOS",
- "repo": "flake-compat",
- "type": "github"
- }
- },
- "flake-compat_2": {
- "flake": false,
- "locked": {
- "lastModified": 1777699697,
- "narHash": "sha256-Eg9b/rq/ECYwNwEXs5i9wHyhxNI0JrYx2srdI2uZMaQ=",
- "ref": "refs/heads/main",
- "rev": "382052b74656a369c5408822af3f2501e9b1af81",
- "revCount": 94,
- "type": "git",
- "url": "https://git.lix.systems/lix-project/flake-compat.git"
- },
- "original": {
- "type": "git",
- "url": "https://git.lix.systems/lix-project/flake-compat.git"
- }
- },
- "flake-compat_3": {
- "flake": false,
- "locked": {
"lastModified": 1650374568,
"narHash": "sha256-Z+s0J8/r907g149rllvwhb4pKi8Wam5ij0st8PwAh+E=",
"owner": "edolstra",
@@ -148,35 +77,16 @@
"type": "github"
}
},
- "flake-compat_4": {
- "flake": false,
- "locked": {
- "lastModified": 1767039857,
- "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
- "owner": "edolstra",
- "repo": "flake-compat",
- "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
- "type": "github"
- },
- "original": {
- "owner": "edolstra",
- "repo": "flake-compat",
- "type": "github"
- }
- },
"flake-parts": {
"inputs": {
- "nixpkgs-lib": [
- "nixvim",
- "nixpkgs"
- ]
+ "nixpkgs-lib": "nixpkgs-lib"
},
"locked": {
- "lastModified": 1778716662,
- "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=",
+ "lastModified": 1782949081,
+ "narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
"owner": "hercules-ci",
"repo": "flake-parts",
- "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb",
+ "rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
"type": "github"
},
"original": {
@@ -187,28 +97,7 @@
},
"flake-parts_2": {
"inputs": {
- "nixpkgs-lib": [
- "nvf",
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1778716662,
- "narHash": "sha256-m1Yf0wZ8j1OHjTc2UwHwyQRSnNeSgLJOd7q5Y45hzi4=",
- "owner": "hercules-ci",
- "repo": "flake-parts",
- "rev": "f7c1a2d347e4c52d5fb8d10cb4d94b5884e546fb",
- "type": "github"
- },
- "original": {
- "owner": "hercules-ci",
- "repo": "flake-parts",
- "type": "github"
- }
- },
- "flake-parts_3": {
- "inputs": {
- "nixpkgs-lib": "nixpkgs-lib"
+ "nixpkgs-lib": "nixpkgs-lib_2"
},
"locked": {
"lastModified": 1768135262,
@@ -229,11 +118,11 @@
"systems": "systems"
},
"locked": {
- "lastModified": 1731533236,
- "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
+ "lastModified": 1694529238,
+ "narHash": "sha256-zsNZZGTGnMOf9YpHKJqMSsa0dXbfmxeoJ7xHlrt+xmY=",
"owner": "numtide",
"repo": "flake-utils",
- "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
+ "rev": "ff7b65b44d01cf9ba6a71320833626af21126384",
"type": "github"
},
"original": {
@@ -244,7 +133,7 @@
},
"flake-utils-plus": {
"inputs": {
- "flake-utils": "flake-utils_2"
+ "flake-utils": "flake-utils"
},
"locked": {
"lastModified": 1715533576,
@@ -261,136 +150,29 @@
"type": "github"
}
},
- "flake-utils_2": {
+ "hjem": {
"inputs": {
- "systems": "systems_4"
- },
- "locked": {
- "lastModified": 1694529238,
- "narHash": "sha256-zsNZZGTGnMOf9YpHKJqMSsa0dXbfmxeoJ7xHlrt+xmY=",
- "owner": "numtide",
- "repo": "flake-utils",
- "rev": "ff7b65b44d01cf9ba6a71320833626af21126384",
- "type": "github"
- },
- "original": {
- "owner": "numtide",
- "repo": "flake-utils",
- "type": "github"
- }
- },
- "flake-utils_3": {
- "inputs": {
- "systems": "systems_6"
- },
- "locked": {
- "lastModified": 1731533236,
- "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
- "owner": "numtide",
- "repo": "flake-utils",
- "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
- "type": "github"
- },
- "original": {
- "owner": "numtide",
- "repo": "flake-utils",
- "type": "github"
- }
- },
- "fsel": {
- "inputs": {
- "flake-utils": "flake-utils",
- "naersk": "naersk",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
- "lastModified": 1781478132,
- "narHash": "sha256-XGKD/DId5Eont4ytPV7LfGvykDRalMWx4pbkRVUNzxY=",
- "owner": "Mjoyufull",
- "repo": "fsel",
- "rev": "8a12d4f35e78297f3e2d55e026185710bff38338",
+ "lastModified": 1784896036,
+ "narHash": "sha256-EAadJywc5P9CSIB7212S5jpQX48aTfYUbsJeAIbQaVI=",
+ "owner": "feel-co",
+ "repo": "hjem",
+ "rev": "08d2b170a74a102c230c9651d8989fe6b39dfad8",
"type": "github"
},
"original": {
- "owner": "Mjoyufull",
- "repo": "fsel",
- "type": "github"
- }
- },
- "git-hooks": {
- "inputs": {
- "flake-compat": [
- "nixos-mailserver",
- "flake-compat"
- ],
- "gitignore": "gitignore",
- "nixpkgs": [
- "nixos-mailserver",
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1778507602,
- "narHash": "sha256-kTwur1wV+01SdqskVMSo6JMEpg71ps3HpbFY2GsflKs=",
- "owner": "cachix",
- "repo": "git-hooks.nix",
- "rev": "61ab0e80d9c7ab14c256b5b453d8b3fb0189ba0a",
- "type": "github"
- },
- "original": {
- "owner": "cachix",
- "repo": "git-hooks.nix",
- "type": "github"
- }
- },
- "gitignore": {
- "inputs": {
- "nixpkgs": [
- "nixos-mailserver",
- "git-hooks",
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1709087332,
- "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=",
- "owner": "hercules-ci",
- "repo": "gitignore.nix",
- "rev": "637db329424fd7e46cf4185293b9cc8c88c95394",
- "type": "github"
- },
- "original": {
- "owner": "hercules-ci",
- "repo": "gitignore.nix",
+ "owner": "feel-co",
+ "repo": "hjem",
"type": "github"
}
},
"home-manager": {
"inputs": {
"nixpkgs": [
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1782657028,
- "narHash": "sha256-PHTCpYZCMzJYS3phhywqRAZphKVr2zjvlGYa+H20ZZ4=",
- "owner": "nix-community",
- "repo": "home-manager",
- "rev": "4ad9aaae70c9aaab504127f926c0fa9cfbc2b365",
- "type": "github"
- },
- "original": {
- "owner": "nix-community",
- "ref": "master",
- "repo": "home-manager",
- "type": "github"
- }
- },
- "home-manager_2": {
- "inputs": {
- "nixpkgs": [
"impermanence",
"nixpkgs"
]
@@ -409,7 +191,7 @@
"type": "github"
}
},
- "home-manager_3": {
+ "home-manager_2": {
"inputs": {
"nixpkgs": [
"otter-launcher",
@@ -432,7 +214,7 @@
},
"impermanence": {
"inputs": {
- "home-manager": "home-manager_2",
+ "home-manager": "home-manager",
"nixpkgs": [
"nixpkgs"
]
@@ -451,42 +233,6 @@
"type": "github"
}
},
- "microvm": {
- "inputs": {
- "nixpkgs": [
- "nixpkgs"
- ],
- "spectrum": "spectrum"
- },
- "locked": {
- "lastModified": 1782324740,
- "narHash": "sha256-EpaYlgijQUv8nvbhMStQEFoO7aDWxJmVTOlsoHWqHpg=",
- "owner": "microvm-nix",
- "repo": "microvm.nix",
- "rev": "49a3e9fe33d33f189d24dafca36096766faa60ad",
- "type": "github"
- },
- "original": {
- "owner": "microvm-nix",
- "repo": "microvm.nix",
- "type": "github"
- }
- },
- "mnw": {
- "locked": {
- "lastModified": 1780772958,
- "narHash": "sha256-VKKe8r4pwCGWZ3Yr9CPN129R4S3CKLSrlYqdYz3vKpM=",
- "owner": "Gerg-L",
- "repo": "mnw",
- "rev": "0871dbf63a53610c95db04439ed8ea4d6ec9c160",
- "type": "github"
- },
- "original": {
- "owner": "Gerg-L",
- "repo": "mnw",
- "type": "github"
- }
- },
"mygui": {
"locked": {
"lastModified": 1716480759,
@@ -503,93 +249,16 @@
"type": "github"
}
},
- "naersk": {
- "inputs": {
- "fenix": "fenix",
- "nixpkgs": "nixpkgs"
- },
- "locked": {
- "lastModified": 1776200608,
- "narHash": "sha256-broZ6RFQr4Fv0wT73gGmzNX14A43TmTFF8g4wDKlNss=",
- "owner": "nix-community",
- "repo": "naersk",
- "rev": "8b23250ab45c2a38cd91031aee26478ca4d0a28e",
- "type": "github"
- },
- "original": {
- "owner": "nix-community",
- "repo": "naersk",
- "type": "github"
- }
- },
- "niri": {
- "inputs": {
- "niri-stable": "niri-stable",
- "niri-unstable": "niri-unstable",
- "nixpkgs": [
- "nixpkgs"
- ],
- "nixpkgs-stable": "nixpkgs-stable",
- "xwayland-satellite-stable": "xwayland-satellite-stable",
- "xwayland-satellite-unstable": "xwayland-satellite-unstable"
- },
- "locked": {
- "lastModified": 1782592242,
- "narHash": "sha256-kgINba6Ilpj3rdTi2BeKlQBs6ZxTdu3Gb49U5gDUVhg=",
- "owner": "sodiboo",
- "repo": "niri-flake",
- "rev": "9e26dfe0fb8d61475b6f9e8d63477fe92509f1db",
- "type": "github"
- },
- "original": {
- "owner": "sodiboo",
- "repo": "niri-flake",
- "type": "github"
- }
- },
- "niri-stable": {
- "flake": false,
- "locked": {
- "lastModified": 1756556321,
- "narHash": "sha256-RLD89dfjN0RVO86C/Mot0T7aduCygPGaYbog566F0Qo=",
- "owner": "YaLTeR",
- "repo": "niri",
- "rev": "01be0e65f4eb91a9cd624ac0b76aaeab765c7294",
- "type": "github"
- },
- "original": {
- "owner": "YaLTeR",
- "ref": "v25.08",
- "repo": "niri",
- "type": "github"
- }
- },
- "niri-unstable": {
- "flake": false,
- "locked": {
- "lastModified": 1781781064,
- "narHash": "sha256-Ii/koEm/sRyg65qbAQWqEgboSEIhdH0EL4KglAc14p0=",
- "owner": "YaLTeR",
- "repo": "niri",
- "rev": "49fc6117fd6c043adaa2ead316b82db5ed735d36",
- "type": "github"
- },
- "original": {
- "owner": "YaLTeR",
- "repo": "niri",
- "type": "github"
- }
- },
"nixos-hardware": {
"inputs": {
- "nixpkgs": "nixpkgs_2"
+ "nixpkgs": "nixpkgs"
},
"locked": {
- "lastModified": 1782562157,
- "narHash": "sha256-a7+T6QSeowynwZ1ZJJbP8T8ntAytvrui8kFGJmIZt2c=",
+ "lastModified": 1784723954,
+ "narHash": "sha256-1CfD8ZUjCkTgjsneLZ/lxCHhgDfqxxE7/GX0MmsgiqA=",
"owner": "NixOS",
"repo": "nixos-hardware",
- "rev": "a9cf7546a938c737b079e738de73934a13de9784",
+ "rev": "a017f5b72210026af5b3ac5949f08d94380a6fbd",
"type": "github"
},
"original": {
@@ -599,47 +268,35 @@
"type": "github"
}
},
- "nixos-mailserver": {
- "inputs": {
- "blobs": "blobs",
- "flake-compat": "flake-compat",
- "git-hooks": "git-hooks",
- "nixpkgs": [
- "nixpkgs"
- ]
- },
+ "nixpkgs": {
"locked": {
- "lastModified": 1781892035,
- "narHash": "sha256-e46EhlHo0jupcYCLE4QJRitd3+y+RgIQYNcfcCdLbKg=",
- "owner": "simple-nixos-mailserver",
- "repo": "nixos-mailserver",
- "rev": "c37fd9c40877450716692b6478e6dda330dfc46a",
- "type": "gitlab"
+ "lastModified": 1767892417,
+ "narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=",
+ "rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba",
+ "type": "tarball",
+ "url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz"
},
"original": {
- "owner": "simple-nixos-mailserver",
- "ref": "main",
- "repo": "nixos-mailserver",
- "type": "gitlab"
+ "type": "tarball",
+ "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
}
},
- "nixpkgs": {
+ "nixpkgs-lib": {
"locked": {
- "lastModified": 1752077645,
- "narHash": "sha256-HM791ZQtXV93xtCY+ZxG1REzhQenSQO020cu6rHtAPk=",
- "owner": "NixOS",
- "repo": "nixpkgs",
- "rev": "be9e214982e20b8310878ac2baa063a961c1bdf6",
+ "lastModified": 1782614948,
+ "narHash": "sha256-ePjCwr1sNm9NYUqywL7QfK3JnlS015msC+eBu2zKlp8=",
+ "owner": "nix-community",
+ "repo": "nixpkgs.lib",
+ "rev": "db3f255737b94216eb71cce308e2912cf6bc2d7c",
"type": "github"
},
"original": {
- "owner": "NixOS",
- "ref": "nixpkgs-unstable",
- "repo": "nixpkgs",
+ "owner": "nix-community",
+ "repo": "nixpkgs.lib",
"type": "github"
}
},
- "nixpkgs-lib": {
+ "nixpkgs-lib_2": {
"locked": {
"lastModified": 1765674936,
"narHash": "sha256-k00uTP4JNfmejrCLJOwdObYC9jHRrr/5M/a/8L2EIdo=",
@@ -656,27 +313,11 @@
},
"nixpkgs-stable": {
"locked": {
- "lastModified": 1782498288,
- "narHash": "sha256-8/X3yyTXiE82b38n32ItbOqfWOVBl+gKa8fILyZfR4Q=",
+ "lastModified": 1784856561,
+ "narHash": "sha256-J+Bx1Z6Oeoj2FgnBhRMKyUhhtDoOpTgXYaVLZpDjW4A=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "3cac626ec5e3703e835f227687e88aa9e2f25701",
- "type": "github"
- },
- "original": {
- "owner": "NixOS",
- "ref": "nixos-25.11",
- "repo": "nixpkgs",
- "type": "github"
- }
- },
- "nixpkgs-stable_2": {
- "locked": {
- "lastModified": 1782535326,
- "narHash": "sha256-ZeRxu4yn6shd3SNF5ZUQb4r7BaVo1zBKMjRhfoNSBmw=",
- "owner": "NixOS",
- "repo": "nixpkgs",
- "rev": "714a5f8c4ead6b31148d829288440ed033ccc041",
+ "rev": "597283ad8aa0b331c788e97c4c262d58877074ef",
"type": "github"
},
"original": {
@@ -688,24 +329,11 @@
},
"nixpkgs_2": {
"locked": {
- "lastModified": 1767892417,
- "narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=",
- "rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba",
- "type": "tarball",
- "url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz"
- },
- "original": {
- "type": "tarball",
- "url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
- }
- },
- "nixpkgs_3": {
- "locked": {
- "lastModified": 1782467914,
- "narHash": "sha256-pGvFkM8N0xEkIIXDe5YYfbEAvHrk4IxBrjB/x8OomhE=",
+ "lastModified": 1784796856,
+ "narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "e73de5be04e0eff4190a1432b946d469c794e7b4",
+ "rev": "e2587caef70cea85dd97d7daab492899902dbf5d",
"type": "github"
},
"original": {
@@ -715,87 +343,38 @@
"type": "github"
}
},
- "nixpkgs_4": {
+ "nixpkgs_3": {
"locked": {
- "lastModified": 1744536153,
- "narHash": "sha256-awS2zRgF4uTwrOKwwiJcByDzDOdo3Q1rPZbiHQg/N38=",
+ "lastModified": 1773734432,
+ "narHash": "sha256-IF5ppUWh6gHGHYDbtVUyhwy/i7D261P7fWD1bPefOsw=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "18dd725c29603f582cf1900e0d25f9f1063dbf11",
+ "rev": "cda48547b432e8d3b18b4180ba07473762ec8558",
"type": "github"
},
"original": {
"owner": "NixOS",
- "ref": "nixpkgs-unstable",
+ "ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
- "nixvim": {
- "inputs": {
- "flake-parts": "flake-parts",
- "nixpkgs": [
- "nixpkgs"
- ],
- "systems": "systems_2"
- },
- "locked": {
- "lastModified": 1782254890,
- "narHash": "sha256-kjsEECqhpPnJWqhooXp6tWh2qGQftCPAo2G1GvZtKdw=",
- "owner": "nix-community",
- "repo": "nixvim",
- "rev": "dbf9550dba8448b03e11d58e5695d6c44a464554",
- "type": "github"
- },
- "original": {
- "owner": "nix-community",
- "repo": "nixvim",
- "type": "github"
- }
- },
- "nvf": {
- "inputs": {
- "flake-compat": "flake-compat_2",
- "flake-parts": "flake-parts_2",
- "mnw": "mnw",
- "nixpkgs": [
- "nixpkgs"
- ],
- "systems": "systems_3"
- },
- "locked": {
- "lastModified": 1782660650,
- "narHash": "sha256-d4Ndt82q9bhL+iKFr1reufZyE/MTdULzN3kEkXsNG88=",
- "owner": "NotAShelf",
- "repo": "nvf",
- "rev": "18d2d23191250c7f597d85da07d860eb05f9e1be",
- "type": "github"
- },
- "original": {
- "owner": "NotAShelf",
- "repo": "nvf",
- "type": "github"
- }
- },
"omnisearch": {
"inputs": {
"beaker-src": "beaker-src",
- "nixpkgs": [
- "nixpkgs"
- ]
+ "nixpkgs": "nixpkgs_3"
},
"locked": {
- "lastModified": 1778546173,
- "narHash": "sha256-nhSXc+jaOYlDGr5beX+LMcw0BeA5SdWH28aCrV1QMPg=",
+ "lastModified": 1783357409,
+ "narHash": "sha256-eolp0Msb3ACNatbenEJftjFlUoh/RfZDizv3GdetEsM=",
"ref": "refs/heads/master",
- "rev": "24f9909badd4e7aa1f3aeef717b93e9b71c20a4e",
- "revCount": 123,
+ "rev": "9c68a8ae6fb32f8a1660da392b9985a4ab3e7cb4",
+ "revCount": 135,
"shallow": false,
"type": "git",
"url": "https://git.bwaaa.monster/omnisearch"
},
"original": {
- "rev": "24f9909badd4e7aa1f3aeef717b93e9b71c20a4e",
"shallow": false,
"type": "git",
"url": "https://git.bwaaa.monster/omnisearch"
@@ -803,7 +382,7 @@
},
"openmw-nix": {
"inputs": {
- "fenix": "fenix_2",
+ "fenix": "fenix",
"mygui": "mygui",
"nixpkgs": [
"nixpkgs"
@@ -826,19 +405,19 @@
},
"otter-launcher": {
"inputs": {
- "flake-parts": "flake-parts_3",
- "home-manager": "home-manager_3",
+ "flake-parts": "flake-parts_2",
+ "home-manager": "home-manager_2",
"nixpkgs": [
"nixpkgs"
],
- "systems": "systems_5"
+ "systems": "systems_2"
},
"locked": {
- "lastModified": 1780973227,
- "narHash": "sha256-vlNT2248Oxg3++bk8ZkozsU4wDbxOkh6dl3GeoBmmXE=",
+ "lastModified": 1783875707,
+ "narHash": "sha256-Ryg3PqFcGydelQpgPF0j8GMaXaGDrNTSesEy6fDw/eg=",
"owner": "kuokuo123",
"repo": "otter-launcher",
- "rev": "764a38d1de308da3268222692652a0a85bb71eee",
+ "rev": "242e5da4f0acc0b4301be7b4546f5afb3e4b23d6",
"type": "github"
},
"original": {
@@ -850,47 +429,22 @@
"root": {
"inputs": {
"disko": "disko",
- "fsel": "fsel",
- "home-manager": "home-manager",
+ "flake-parts": "flake-parts",
+ "hjem": "hjem",
"impermanence": "impermanence",
- "microvm": "microvm",
- "niri": "niri",
"nixos-hardware": "nixos-hardware",
- "nixos-mailserver": "nixos-mailserver",
- "nixpkgs": "nixpkgs_3",
- "nixpkgs-stable": "nixpkgs-stable_2",
- "nixvim": "nixvim",
- "nvf": "nvf",
+ "nixpkgs": "nixpkgs_2",
+ "nixpkgs-stable": "nixpkgs-stable",
"omnisearch": "omnisearch",
"openmw-nix": "openmw-nix",
"otter-launcher": "otter-launcher",
- "satty": "satty",
"sls-steam": "sls-steam",
- "sops-nix": "sops-nix",
- "waybar": "waybar",
- "yazi": "yazi"
+ "sops-nix": "sops-nix"
}
},
"rust-analyzer-src": {
"flake": false,
"locked": {
- "lastModified": 1752428706,
- "narHash": "sha256-EJcdxw3aXfP8Ex1Nm3s0awyH9egQvB2Gu+QEnJn2Sfg=",
- "owner": "rust-lang",
- "repo": "rust-analyzer",
- "rev": "591e3b7624be97e4443ea7b5542c191311aa141d",
- "type": "github"
- },
- "original": {
- "owner": "rust-lang",
- "ref": "nightly",
- "repo": "rust-analyzer",
- "type": "github"
- }
- },
- "rust-analyzer-src_2": {
- "flake": false,
- "locked": {
"lastModified": 1759301569,
"narHash": "sha256-7StxDed3v2fAWLkl+Hse9FlpjT7Dk7Cn/4vxTFyEhIg=",
"owner": "rust-lang",
@@ -905,66 +459,6 @@
"type": "github"
}
},
- "rust-overlay": {
- "inputs": {
- "nixpkgs": "nixpkgs_4"
- },
- "locked": {
- "lastModified": 1748140821,
- "narHash": "sha256-GZcjWLQtDifSYMd1ueLDmuVTcQQdD5mONIBTqABooOk=",
- "owner": "oxalica",
- "repo": "rust-overlay",
- "rev": "476b2ba7dc99ddbf70b1f45357dbbdbdbdfb4422",
- "type": "github"
- },
- "original": {
- "owner": "oxalica",
- "repo": "rust-overlay",
- "type": "github"
- }
- },
- "rust-overlay_2": {
- "inputs": {
- "nixpkgs": [
- "yazi",
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1779851998,
- "narHash": "sha256-UkkMh3bX9QW4Luqkm98nUaOqKWrU6i65mUnph3WeSSw=",
- "owner": "oxalica",
- "repo": "rust-overlay",
- "rev": "6cddd512fa2bf7231f098d3a2f92f6e4cff71e0a",
- "type": "github"
- },
- "original": {
- "owner": "oxalica",
- "repo": "rust-overlay",
- "type": "github"
- }
- },
- "satty": {
- "inputs": {
- "nixpkgs": [
- "nixpkgs"
- ],
- "rust-overlay": "rust-overlay"
- },
- "locked": {
- "lastModified": 1782542860,
- "narHash": "sha256-79L/yxMuJHS+Dfpt7y4wXvgNJILux0jv6mnVFxanqKc=",
- "owner": "gabm",
- "repo": "Satty",
- "rev": "ff0c0d350d233f446c868e7ca4c13cfb67d0c43d",
- "type": "github"
- },
- "original": {
- "owner": "gabm",
- "repo": "Satty",
- "type": "github"
- }
- },
"sls-steam": {
"inputs": {
"nixpkgs": [
@@ -972,11 +466,11 @@
]
},
"locked": {
- "lastModified": 1782389855,
- "narHash": "sha256-LhalI4N/bv20fvi0ag+f6ESWLS5VbOdzJKLoEGnJDMk=",
+ "lastModified": 1785003674,
+ "narHash": "sha256-XZ0VVFYOBudkEtnfnLoSu0dfXt2ENDQMk5QT7J8f9/w=",
"owner": "AceSLS",
"repo": "SLSsteam",
- "rev": "ceb07e711cc0e831b2851236b46629827f87bbc4",
+ "rev": "9927612e5d0acb43f9ff6818fcfbbbadedfdd818",
"type": "github"
},
"original": {
@@ -987,7 +481,7 @@
},
"snowfall-lib": {
"inputs": {
- "flake-compat": "flake-compat_3",
+ "flake-compat": "flake-compat",
"flake-utils-plus": "flake-utils-plus",
"nixpkgs": [
"openmw-nix",
@@ -1015,11 +509,11 @@
]
},
"locked": {
- "lastModified": 1782165805,
- "narHash": "sha256-478kKQBvK6SYTOdN2h9jhKJv94nbXRbFMfuL1WshErg=",
+ "lastModified": 1783174389,
+ "narHash": "sha256-aCWC8ngycU7OdJrU2+Je3qf+1a2ykuBvpPhZT/9tXMc=",
"owner": "Mic92",
"repo": "sops-nix",
- "rev": "56b24064fdcaedca53553b1a6d607fd23b613a24",
+ "rev": "f1406619a3884cd5c47992a70b8b35c9c0fcb4c9",
"type": "github"
},
"original": {
@@ -1028,22 +522,6 @@
"type": "github"
}
},
- "spectrum": {
- "flake": false,
- "locked": {
- "lastModified": 1778940603,
- "narHash": "sha256-voSM8dZNlaOWN3kbYFky+FNY6fFQOEw0xF+ZMpZKkCQ=",
- "ref": "refs/heads/main",
- "rev": "367dd227f539267eae2b62770b4c17b88ac8c1f1",
- "revCount": 1265,
- "type": "git",
- "url": "https://spectrum-os.org/git/spectrum"
- },
- "original": {
- "type": "git",
- "url": "https://spectrum-os.org/git/spectrum"
- }
- },
"systems": {
"locked": {
"lastModified": 1681028828,
@@ -1061,52 +539,6 @@
},
"systems_2": {
"locked": {
- "lastModified": 1774449309,
- "narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
- "owner": "nix-systems",
- "repo": "default",
- "rev": "c29398b59d2048c4ab79345812849c9bd15e9150",
- "type": "github"
- },
- "original": {
- "owner": "nix-systems",
- "ref": "future-26.11",
- "repo": "default",
- "type": "github"
- }
- },
- "systems_3": {
- "locked": {
- "lastModified": 1681028828,
- "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
- "owner": "nix-systems",
- "repo": "default",
- "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
- "type": "github"
- },
- "original": {
- "owner": "nix-systems",
- "repo": "default",
- "type": "github"
- }
- },
- "systems_4": {
- "locked": {
- "lastModified": 1681028828,
- "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
- "owner": "nix-systems",
- "repo": "default",
- "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
- "type": "github"
- },
- "original": {
- "owner": "nix-systems",
- "repo": "default",
- "type": "github"
- }
- },
- "systems_5": {
- "locked": {
"lastModified": 1689347949,
"narHash": "sha256-12tWmuL2zgBgZkdoB6qXZsgJEH9LR3oUgpaQq2RbI80=",
"owner": "nix-systems",
@@ -1119,97 +551,6 @@
"repo": "default-linux",
"type": "github"
}
- },
- "systems_6": {
- "locked": {
- "lastModified": 1681028828,
- "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
- "owner": "nix-systems",
- "repo": "default",
- "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
- "type": "github"
- },
- "original": {
- "owner": "nix-systems",
- "repo": "default",
- "type": "github"
- }
- },
- "waybar": {
- "inputs": {
- "flake-compat": "flake-compat_4",
- "nixpkgs": [
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1777929458,
- "narHash": "sha256-51R3mIt8cLNvh/X5qe9vOqeJCj0U9KRyemVE5y+OhiU=",
- "owner": "Alexays",
- "repo": "Waybar",
- "rev": "05945748dccce28bf96d26d8f64a9e69a8dd49ba",
- "type": "github"
- },
- "original": {
- "owner": "Alexays",
- "repo": "Waybar",
- "type": "github"
- }
- },
- "xwayland-satellite-stable": {
- "flake": false,
- "locked": {
- "lastModified": 1755491097,
- "narHash": "sha256-m+9tUfsmBeF2Gn4HWa6vSITZ4Gz1eA1F5Kh62B0N4oE=",
- "owner": "Supreeeme",
- "repo": "xwayland-satellite",
- "rev": "388d291e82ffbc73be18169d39470f340707edaa",
- "type": "github"
- },
- "original": {
- "owner": "Supreeeme",
- "ref": "v0.7",
- "repo": "xwayland-satellite",
- "type": "github"
- }
- },
- "xwayland-satellite-unstable": {
- "flake": false,
- "locked": {
- "lastModified": 1781226823,
- "narHash": "sha256-28696iIw8uE0ZUyFTtzhEM8xMh85clCYypMxkvUi+sc=",
- "owner": "Supreeeme",
- "repo": "xwayland-satellite",
- "rev": "8575d0ef55d70f9b4c46b6bffb3accf912217e1e",
- "type": "github"
- },
- "original": {
- "owner": "Supreeeme",
- "repo": "xwayland-satellite",
- "type": "github"
- }
- },
- "yazi": {
- "inputs": {
- "flake-utils": "flake-utils_3",
- "nixpkgs": [
- "nixpkgs"
- ],
- "rust-overlay": "rust-overlay_2"
- },
- "locked": {
- "lastModified": 1782583823,
- "narHash": "sha256-S52dg5T6iRjuED2e0bxzWeVM1Einbz5rJbB5wcruop4=",
- "owner": "sxyazi",
- "repo": "yazi",
- "rev": "21550a7eb5086ba34f8eabf8aaab85f601d34a74",
- "type": "github"
- },
- "original": {
- "owner": "sxyazi",
- "repo": "yazi",
- "type": "github"
- }
}
},
"root": "root",
diff --git a/flake.nix b/flake.nix
index 7e6ca6e..c6b85d8 100644
--- a/flake.nix
+++ b/flake.nix
@@ -5,22 +5,17 @@
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-26.05";
- # Hardware and gaming
- nixos-hardware.url = "github:NixOS/nixos-hardware/master";
+ flake-parts.url = "github:hercules-ci/flake-parts";
- impermanence = {
- url = "github:nix-community/impermanence";
- inputs.nixpkgs.follows = "nixpkgs";
- };
+ nixos-hardware.url = "github:NixOS/nixos-hardware/master";
- nixos-mailserver = {
- # url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.05";
- url = "gitlab:simple-nixos-mailserver/nixos-mailserver/main";
+ hjem = {
+ url = "github:feel-co/hjem";
inputs.nixpkgs.follows = "nixpkgs";
};
- microvm = {
- url = "github:microvm-nix/microvm.nix";
+ impermanence = {
+ url = "github:nix-community/impermanence";
inputs.nixpkgs.follows = "nixpkgs";
};
@@ -34,117 +29,86 @@
inputs.nixpkgs.follows = "nixpkgs";
};
- # System Utilities
sops-nix = {
url = "github:Mic92/sops-nix";
inputs.nixpkgs.follows = "nixpkgs";
};
- home-manager = {
- url = "github:nix-community/home-manager/master";
- inputs.nixpkgs.follows = "nixpkgs";
- };
-
disko = {
url = "github:nix-community/disko/latest";
inputs.nixpkgs.follows = "nixpkgs";
};
- # UI and apps
- niri = {
- url = "github:sodiboo/niri-flake";
- inputs.nixpkgs.follows = "nixpkgs";
- };
-
- waybar = {
- url = "github:Alexays/Waybar";
- inputs.nixpkgs.follows = "nixpkgs";
- };
-
- yazi = {
- url = "github:sxyazi/yazi";
- inputs.nixpkgs.follows = "nixpkgs";
- };
-
- satty = {
- url = "github:gabm/Satty";
- inputs.nixpkgs.follows = "nixpkgs";
- };
-
- # Other
omnisearch = {
- url = "git+https://git.bwaaa.monster/omnisearch?shallow=0&rev=24f9909badd4e7aa1f3aeef717b93e9b71c20a4e";
- inputs.nixpkgs.follows = "nixpkgs";
+ url = "git+https://git.bwaaa.monster/omnisearch?shallow=0";
+ # inputs.nixpkgs.follows = "nixpkgs";
};
otter-launcher = {
url = "github:kuokuo123/otter-launcher";
inputs.nixpkgs.follows = "nixpkgs";
};
+ };
- fsel = {
- url = "github:Mjoyufull/fsel";
- inputs.nixpkgs.follows = "nixpkgs";
- };
+ outputs =
+ inputs@{ flake-parts, ... }:
+ flake-parts.lib.mkFlake { inherit inputs; } {
- nixvim = {
- url = "github:nix-community/nixvim";
- inputs.nixpkgs.follows = "nixpkgs";
- };
+ imports = [
+ (inputs.flake-parts.lib.importTree ./modules)
+ ];
- nvf = {
- url = "github:NotAShelf/nvf";
- inputs.nixpkgs.follows = "nixpkgs";
- };
- };
+ perSystem = { pkgs, ... }: {
+ formatter = pkgs.nixfmt-rfc-style;
+ };
- outputs =
- {
- self,
- nixpkgs,
- nixpkgs-stable,
- ...
- }@inputs:
- let
- unstablePkgs = import nixpkgs { };
- stablePkgs = import nixpkgs-stable { };
- mkHost =
- {
- hostname,
- user ? "adam",
- isStable ? false,
- path ? ./hosts/${hostname}/configuration.nix,
- }:
- nixpkgs.lib.nixosSystem {
- specialArgs = {
- inherit inputs;
- username = user;
- pkgs-unstable = unstablePkgs;
- pkgs-stable = stablePkgs;
- masterDomain = "bibus.top";
- };
- modules = [
- path
- { networking.hostName = hostname; }
- ];
- };
- in
- {
- nixosConfigurations = {
- szpont = mkHost {
- hostname = "szpont";
- path = ./hosts/desktop/configuration.nix;
- };
- thinkpad = mkHost { hostname = "thinkpad"; };
- pendrive = mkHost {
- hostname = "pendrive";
- user = "user";
- };
- bibus-lab = mkHost {
- hostname = "bibus-lab";
- user = "opc";
- isStable = true;
+ flake = {
+ nixosModules.default = {
+ imports = [ inputs.hjem.nixosModules.default ];
};
+
+ nixosConfigurations =
+ let
+ mkHost =
+ {
+ hostname,
+ user ? "adam",
+ pkgsInput ? inputs.nixpkgs,
+ path ? ./hosts/${hostname}/configuration.nix,
+ }:
+ pkgsInput.lib.nixosSystem {
+ specialArgs = {
+ inherit inputs;
+ username = user;
+ pkgs-unstable = import inputs.nixpkgs {
+ system = "x86_64-linux";
+ config.allowUnfree = true;
+ };
+ pkgs-stable = import inputs.nixpkgs-stable {
+ system = "x86_64-linux";
+ config.allowUnfree = true;
+ };
+ };
+ modules = [
+ inputs.hjem.nixosModules.default
+ inputs.disko.nixosModules.disko
+ inputs.impermanence.nixosModules.impermanence
+ inputs.sops-nix.nixosModules.sops
+
+ path
+ { networking.hostName = hostname; }
+ ];
+ };
+ in
+ {
+ szpont = mkHost { hostname = "szpont"; };
+ thinkpad = mkHost { hostname = "thinkpad"; };
+ pendrive = mkHost {
+ hostname = "pendrive";
+ user = "user";
+ pkgsInput = inputs.nixpkgs-stable;
+ };
+ };
};
};
}
diff --git a/hosts/bibus-lab/configuration.nix b/hosts/bibus-lab/configuration.nix
deleted file mode 100644
index bace2f6..0000000
--- a/hosts/bibus-lab/configuration.nix
+++ /dev/null
@@ -1,13 +0,0 @@
-{ inputs, ... }:
-{
- system.stateVersion = "26.11";
-
- imports = [
- inputs.disko.nixosModules.disko
- ./disko.nix
-
- ../../os/default.nix
- ];
-
- hardware.facter.reportPath = ./facter.json;
-}
diff --git a/hosts/bibus-lab/disko.nix b/hosts/bibus-lab/disko.nix
deleted file mode 100644
index 203ec95..0000000
--- a/hosts/bibus-lab/disko.nix
+++ /dev/null
@@ -1,249 +0,0 @@
-{
- disko.devices = {
- main = {
- type = "disk";
- # TODO fill id
- device = "/dev/disk/by-id/CHANGEME";
- content = {
- type = "gpt";
- partitions = {
- ESP = {
- size = "2G";
- type = "EF00";
- content = {
- type = "filesystem";
- format = "vfat";
- mountpoint = "/boot";
- };
- };
- zfs = {
- size = "100%";
- content = {
- type = "zfs";
- pool = "zroot";
- };
- };
- };
- };
- };
- hdd1 = {
- type = "disk";
- # TODO fill id
- device = "/dev/disk/by-id/CHANGEME";
- content = {
- type = "gpt";
- partitions = {
- zfs = {
- size = "100%";
- content = {
- type = "zfs";
- pool = "tank";
- };
- };
- };
- };
- };
- hdd2 = {
- type = "disk";
- # TODO fill id
- device = "/dev/disk/by-id/CHANGEME";
- content = {
- type = "gpt";
- partitions = {
- zfs = {
- size = "100%";
- content = {
- type = "zfs";
- pool = "tank";
- };
- };
- };
- };
- };
- hdd3 = {
- type = "disk";
- # TODO fill id
- device = "/dev/disk/by-id/CHANGEME";
- content = {
- type = "gpt";
- partitions = {
- zfs = {
- size = "100%";
- content = {
- type = "zfs";
- pool = "tank";
- };
- };
- };
- };
- };
- zpool = {
- zroot = {
- type = "zpool";
- rootTmpfs = true;
- datasets = {
- "rpool" = {
- type = "zfs_fs";
- options = {
- mountpoint = "none";
- compression = "zstd";
- atime = "off";
- };
- };
- "rpool/root" = {
- type = "zfs_fs";
- mountpoint = "/";
- options.mountpoint = "legacy";
- };
- "rpool/nix" = {
- type = "zfs_fs";
- mountpoint = "/nix";
- options.mountpoint = "legacy";
- };
- "rpool/home" = {
- type = "zfs_fs";
- mountpoint = "/home";
- };
- "rpool/persist" = {
- type = "zfs_fs";
- mountpoint = "/persist";
- options.mountpoint = "legacy";
- };
- "rpool/log" = {
- type = "zfs_fs";
- mountpoint = "/var/log";
- options.mountpoint = "legacy";
- };
- "rpool/var" = {
- type = "zfs_fs";
- options.mountpoint = "none";
- };
- "rpool/var/acme" = {
- type = "zfs_fs";
- mountpoint = "/var/lib/acme";
- };
- "rpool/containers" = {
- type = "zfs_fs";
- mountpoint = "/var/lib/containers";
- };
- "rpool/appdata" = {
- type = "zfs_fs";
- options.mountpoint = "none";
- };
- "rpool/appdata/cfg" = {
- type = "zfs_fs";
- mountpoint = "/var/lib/appdata/cfg";
- };
- "rpool/appdata/db" = {
- type = "zfs_fs";
- mountpoint = "/var/lib/appdata/db";
- options.canmount = "off";
- };
- "rpool/appdata/db/postgres" = {
- type = "zfs_fs";
- mountpoint = "/var/lib/appdata/db/postgres";
- options = {
- recordsize = "8K";
- logbias = "latency";
- };
- };
- "rpool/appdata/db/couchdb" = {
- type = "zfs_fs";
- mountpoint = "/var/lib/appdata/db/couchdb";
- options.recordsize = "64K";
- };
- "rpool/appdata/db/redis" = {
- type = "zfs_fs";
- mountpoint = "/var/lib/appdata/db/redis";
- options = {
- recordsize = "128K";
- compression = "lz4";
- };
- };
- "rpool/appdata/monero" = {
- type = "zfs_fs";
- mountpoint = "/var/lib/monero";
- options = {
- compression = "off";
- recordsize = "8K";
- };
- };
- "rpool/appdata/mail" = {
- type = "zfs_fs";
- mountpoint = "/var/vmail";
- options = {
- atime = "on";
- recordsize = "64K";
- };
- };
- "rpool/appdata/games" = {
- type = "zfs_fs";
- mountpoint = "/var/lib/games";
- options.recordsize = "64K";
- };
- };
- };
- tank = {
- type = "zpool";
- mode = "raidz1";
-
- datasets = {
- "ztank" = {
- type = "zfs_fs";
- mountpoint = "none";
- options = {
- compression = "zstd";
- atime = "off";
- };
- };
- "ztank/media" = {
- type = "zfs_fs";
- mountpoint = "/data/media";
- options = {
- compression = "none";
- recordsize = "1M";
- };
- };
- "ztank/vault" = {
- type = "zfs_fs";
- mountpoint = "/data/vault";
- options.xattr = "sa";
- };
- "ztank/seafile" = {
- type = "zfs_fs";
- mountpoint = "none";
- options.recordsize = "128K";
- };
- "ztank/seafile/personal" = {
- type = "zfs_fs";
- mountpoint = "/data/seafile/personal";
- };
- "ztank/seafile/shared" = {
- type = "zfs_fs";
- mountpoint = "/data/seafile/shared";
- refquota = "1T";
- };
- "ztank/dl" = {
- type = "zfs_fs";
- options.mountpoint = "none";
- };
- "ztank/dl/active" = {
- type = "zfs_fs";
- mountpoint = "/data/dl/active";
- options.recordsize = "16K";
- };
- "ztank/dl/complete" = {
- type = "zfs_fs";
- mountpoint = "/data/dl/complete";
- options.recordsize = "1M";
- };
- "ztank/backup" = {
- type = "zfs_fs";
- mountpoint = "/data/backup";
- options.recordsize = "1M";
- };
- };
- };
- };
- };
-}
diff --git a/hosts/desktop/1 b/hosts/desktop/1
deleted file mode 100644
index 088098d..0000000
--- a/hosts/desktop/1
+++ /dev/null
@@ -1,119 +0,0 @@
-{ config, username, ... }:
-{
- system.stateVersion = "25.05";
-
- imports = [
- ./hardware-configuration.nix
- ../../os/default.nix
- ];
-
- os = {
- core = {
- allowUnfree.enable = true;
- flatpak.enable = true;
-
- audio = {
- enable = true;
- disable-devices.enable = true;
- };
- bootloader = {
- type = "systemd-boot";
- timeout = 0;
- };
- drivers = {
- enable = true;
- kernel = "zen";
- cpu = "amd";
- graphics = {
- enable = true;
- amdgpu.enable = true;
- };
- };
- fonts.enable = true;
- greet.enable = true;
- home-manager = {
- enable = true;
- users.${username}.path = ./home.nix;
- };
- locale.enable = true;
- memory = {
- zram.enable = true;
- swapfile = {
- enable = true;
- size = 16;
- };
- };
- network.enable = true;
- security = {
- enable = true;
- sandboxing.enable = true;
- };
- storage.enable = true;
- users.enable = true;
- };
- srv = {
- bluetooth.enable = true;
- tailscale.enable = true;
- ssh = {
- server.enable = true;
- client = {
- enable = true;
- createAliases = true;
- };
- enableSigning = true;
- };
- firewall.enable = true;
- yggdrasil.enable = true;
- i2p.enable = true;
- tor = {
- enable = true;
- enableBrowser = true;
- };
- files = {
- enable = true;
- localsend.enable = true;
- krusader.enable = true;
- };
- gaming = {
- enable = true;
- steam = {
- enable = true;
- enableSls = true;
- };
- vr.enable = true;
- };
- sunshine.enable = true;
- virtualization.kvm.enable = true;
- nix-helper.enable = true;
- monero.wallet.enable = true;
- sops.enable = true;
- syncthing = {
- enable = true;
- activeFolders = [
- "openmw-config"
- "openmw-mods"
- "game-saves"
- "keepass"
- "sync"
- "music"
- ];
- };
- omnisearch.enable = true;
- };
- wm = {
- enable = true;
- niri.enable = true;
- };
- };
-
- boot = {
- kernelModules = [
- "nct6687"
- "binder_linux"
- "ashem_linux"
- ];
- extraModulePackages = [
- config.boot.kernelPackages.nct6687d
- ];
- };
-}
diff --git a/hosts/desktop/hardware-configuration.nix b/hosts/desktop/hardware-configuration.nix
deleted file mode 100644
index 6685e8e..0000000
--- a/hosts/desktop/hardware-configuration.nix
+++ /dev/null
@@ -1,71 +0,0 @@
-# Do not modify this file! It was generated by ‘nixos-generate-config’
-# and may be overwritten by future invocations. Please make changes
-# to /etc/nixos/configuration.nix instead.
-{
- config,
- lib,
- pkgs,
- modulesPath,
- ...
-}:
-
-{
- imports = [
- (modulesPath + "/installer/scan/not-detected.nix")
- ];
-
- boot.initrd.availableKernelModules = [
- "nvme"
- "ahci"
- "xhci_pci"
- "usbhid"
- "usb_storage"
- "sd_mod"
- ];
- boot.initrd.kernelModules = [ ];
- boot.kernelModules = [ "kvm-amd" ];
- boot.extraModulePackages = [ ];
-
- fileSystems."/" = {
- device = "/dev/disk/by-uuid/aa9c6208-2cc3-413c-a52a-5e0fdf93e748";
- fsType = "btrfs";
- options = [ "noatime" ];
- };
-
- fileSystems."/boot" = {
- device = "/dev/disk/by-uuid/A687-03D4";
- fsType = "vfat";
- options = [
- "fmask=0022"
- "dmask=0022"
- ];
- };
-
- fileSystems."/home" = {
- device = "/dev/disk/by-uuid/694036da-fc6e-4c7c-8765-7b90fb9a04c8";
- fsType = "btrfs";
- options = [ "noatime" ];
- };
-
- fileSystems."/storage" = {
- device = "/dev/disk/by-uuid/c0dc7c4d-1800-4c84-a04c-5ea7f5e86c4b";
- fsType = "ext4";
- options = [
- "nofail"
- "noatime"
- ];
- };
-
- swapDevices = [ ];
-
- # Enables DHCP on each ethernet and wireless interface. In case of scripted networking
- # (the default) this is the recommended approach. When using systemd-networkd it's
- # still possible to use this option, but it's recommended to use it in conjunction
- # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
- networking.useDHCP = lib.mkDefault true;
- # networking.interfaces.enp14s0.useDHCP = lib.mkDefault true;
- # networking.interfaces.wlp15s0.useDHCP = lib.mkDefault true;
-
- nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
- hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
-}
diff --git a/modules/audio.nix b/modules/audio.nix
new file mode 100644
index 0000000..e926076
--- /dev/null
+++ b/modules/audio.nix
@@ -0,0 +1,96 @@
+{
+ flake.nixosModules.audio = { config, lib, pkgs, ... }:
+ let
+ cfg = config.os.core.audio;
+ in
+ {
+ options.os.core.audio = {
+ enable = lib.mkEnableOption "audio support";
+ disable-devices.enable = lib.mkEnableOption "disables some random devices cluttering up";
+ noise-cancellation.enable = lib.mkEnableOption "RNNoise background noise cancellation";
+ };
+
+ config = lib.mkMerge [
+ (lib.mkIf cfg.enable {
+ services.pulseaudio.enable = false;
+ security.rtkit.enable = true;
+
+ services.pipewire = {
+ enable = true;
+ audio.enable = true;
+ pulse.enable = true;
+ alsa = {
+ enable = true;
+ support32Bit = true;
+ };
+ jack.enable = true;
+
+ wireplumber = {
+ enable = true;
+ extraConfig."99-lock-microphone-gain"."pulse.rules" = [{
+ matches = [ { "application.name" = "~*cord*"; } ];
+ actions.quirks = [ "no-source-volume" ];
+ }];
+ };
+ };
+ services.playerctld.enable = true;
+
+ environment.systemPackages = with pkgs; [
+ crosspipe
+ pulsemixer
+ pavucontrol
+ alsa-utils
+ ];
+ })
+
+ (lib.mkIf cfg.disable-devices.enable {
+ services.pipewire.wireplumber.extraConfig = {
+ "99-disable-devices"."monitor.alsa.rules" = [{
+ matches = [
+ { "device.name" = "~alsa_card.pci-0000_03_00.1*"; }
+ { "device.description" = "~USB Audio*"; }
+ ];
+ actions.update-props."device.disabled" = true;
+ }];
+ };
+ })
+
+ (lib.mkIf cfg.noise-cancellation.enable {
+ services.pipewire.extraConfig.pipewire."99-rnnoise" = {
+ "context.modules" = [
+ {
+ name = "libpipewire-module-filter-chain";
+ args = {
+ "node.description" = "Noise Canceling Source";
+ "media.name" = "Noise Canceling Source";
+ "filter.graph".nodes = [
+ {
+ type = "ladspa";
+ name = "rnnoise";
+ plugin = "${pkgs.rnnoise-plugin}/lib/ladspa/librnnoise_ladspa.so";
+ label = "noise_suppressor_mono";
+ control = {
+ "VAD Threshold (%)" = 50.0;
+ "VAD Grace Period (ms)" = 200.0;
+ "Retroactive VAD Grace Period (ms)" = 0.0;
+ };
+ }
+ ];
+ "capture.props" = {
+ "node.name" = "effect_input.rnnoise";
+ "node.passive" = true;
+ "audio.position" = [ "MONO" ];
+ };
+ "playback.props" = {
+ "node.name" = "effect_output.rnnoise";
+ "media.class" = "Audio/Source";
+ "audio.position" = [ "MONO" ];
+ };
+ };
+ }
+ ];
+ };
+ })
+ ];
+ };
+}
diff --git a/os/srv/bluetooth.nix b/modules/bluetooth.nix
index 1705db6..1705db6 100644
--- a/os/srv/bluetooth.nix
+++ b/modules/bluetooth.nix
diff --git a/os/core/bootloader.nix b/modules/bootloader.nix
index e8dfc11..e8dfc11 100644
--- a/os/core/bootloader.nix
+++ b/modules/bootloader.nix
diff --git a/os/srv/compat.nix b/modules/compat.nix
index 1ea6105..1ea6105 100644
--- a/os/srv/compat.nix
+++ b/modules/compat.nix
diff --git a/os/core/drivers.nix b/modules/drivers.nix
index 6e74e98..6e74e98 100644
--- a/os/core/drivers.nix
+++ b/modules/drivers.nix
diff --git a/os/srv/files.nix b/modules/files.nix
index 777a394..777a394 100644
--- a/os/srv/files.nix
+++ b/modules/files.nix
diff --git a/os/core/fonts.nix b/modules/fonts.nix
index ee61591..344ff63 100644
--- a/os/core/fonts.nix
+++ b/modules/fonts.nix
@@ -11,18 +11,18 @@ in
options.os.core.fonts.enable = lib.mkEnableOption "system-wide font and console configuration";
config = lib.mkIf cfg.enable {
- console = {
- keyMap = "pl";
- earlySetup = true;
- font = "ter-v32n";
- packages = with pkgs; [ terminus_font ];
- };
+ # console = {
+ # keyMap = "pl";
+ # earlySetup = true;
+ # font = "ter-v32n";
+ # packages = with pkgs; [ terminus_font ];
+ # };
fonts.packages = with pkgs; [
- terminus_font
nerd-fonts.jetbrains-mono
nerd-fonts.fira-mono
nerd-fonts.fira-code
+
noto-fonts
noto-fonts-cjk-sans
noto-fonts-cjk-serif
diff --git a/os/srv/gaming.nix b/modules/gaming.nix
index b9b6766..b9b6766 100644
--- a/os/srv/gaming.nix
+++ b/modules/gaming.nix
diff --git a/os/core/greet.nix b/modules/greet.nix
index 1c01b68..1c01b68 100644
--- a/os/core/greet.nix
+++ b/modules/greet.nix
diff --git a/os/srv/i2p.nix b/modules/i2p.nix
index 5e36c20..5e36c20 100644
--- a/os/srv/i2p.nix
+++ b/modules/i2p.nix
diff --git a/os/core/localization.nix b/modules/localization.nix
index 49933fa..49933fa 100644
--- a/os/core/localization.nix
+++ b/modules/localization.nix
diff --git a/os/core/memory.nix b/modules/memory.nix
index b20ec8a..b20ec8a 100644
--- a/os/core/memory.nix
+++ b/modules/memory.nix
diff --git a/os/srv/monero.nix b/modules/monero.nix
index eb21abc..eb21abc 100644
--- a/os/srv/monero.nix
+++ b/modules/monero.nix
diff --git a/os/core/networking.nix b/modules/networking.nix
index 9e4c329..9e4c329 100644
--- a/os/core/networking.nix
+++ b/modules/networking.nix
diff --git a/os/wm/niri.nix b/modules/niri.nix
index 58d27af..58d27af 100644
--- a/os/wm/niri.nix
+++ b/modules/niri.nix
diff --git a/os/srv/nix-helper.nix b/modules/nix-helper.nix
index 5e5e133..5e5e133 100644
--- a/os/srv/nix-helper.nix
+++ b/modules/nix-helper.nix
diff --git a/os/srv/omnisearch.nix b/modules/omnisearch.nix
index ac36184..ac36184 100644
--- a/os/srv/omnisearch.nix
+++ b/modules/omnisearch.nix
diff --git a/os/core/persistance.nix b/modules/persistance.nix
index 89f3702..89f3702 100644
--- a/os/core/persistance.nix
+++ b/modules/persistance.nix
diff --git a/os/core/power.nix b/modules/power.nix
index b3dbf91..b3dbf91 100644
--- a/os/core/power.nix
+++ b/modules/power.nix
diff --git a/os/core/security.nix b/modules/security.nix
index 33aa919..33aa919 100644
--- a/os/core/security.nix
+++ b/modules/security.nix
diff --git a/os/srv/sops.nix b/modules/sops.nix
index 3ca2d16..3ca2d16 100644
--- a/os/srv/sops.nix
+++ b/modules/sops.nix
diff --git a/os/srv/ssh.nix b/modules/ssh.nix
index 63b2034..63b2034 100644
--- a/os/srv/ssh.nix
+++ b/modules/ssh.nix
diff --git a/os/core/storage.nix b/modules/storage.nix
index 8527bac..8527bac 100644
--- a/os/core/storage.nix
+++ b/modules/storage.nix
diff --git a/os/srv/syncthing.nix b/modules/syncthing.nix
index 0c5e53e..0c5e53e 100644
--- a/os/srv/syncthing.nix
+++ b/modules/syncthing.nix
diff --git a/os/srv/tor.nix b/modules/tor.nix
index 8777fba..8777fba 100644
--- a/os/srv/tor.nix
+++ b/modules/tor.nix
diff --git a/os/core/users.nix b/modules/users.nix
index ff45a99..ff45a99 100644
--- a/os/core/users.nix
+++ b/modules/users.nix
diff --git a/os/srv/virtualization.nix b/modules/virtualization.nix
index 8ff9f3f..8ff9f3f 100644
--- a/os/srv/virtualization.nix
+++ b/modules/virtualization.nix
diff --git a/os/core/audio.nix b/os/core/audio.nix
deleted file mode 100644
index a7fb5db..0000000
--- a/os/core/audio.nix
+++ /dev/null
@@ -1,146 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}:
-let
- cfg = config.os.core.audio;
- toggleMuteNotify = pkgs.writeShellScriptBin "toggle-mute-notify" ''
- IS_MUTED=$(${pkgs.wireplumber}/bin/wpctl get-volume @DEFAULT_AUDIO_SOURCE@ | grep -c "MUTED")
-
- if [ "$IS_MUTED" -eq 1 ]; then
- ${pkgs.libnotify}/bin/notify-send -a "MuteIndicator" -t 0 -u critical "Microphone Muted" "Mic is currently OFF"
- else
- ${pkgs.mako}/bin/makoctl dismiss -a "MuteIndicator"
- fi
- '';
-in
-{
- options.os.core.audio = {
- enable = lib.mkEnableOption "audio support";
- disable-devices.enable = lib.mkEnableOption "disables some random devices cluttering up";
- };
-
- config = lib.mkMerge [
- (lib.mkIf cfg.enable {
- services.pulseaudio.enable = false;
- security.rtkit.enable = true;
-
- services = {
- pipewire = {
- enable = true;
- audio.enable = true;
- pulse.enable = true;
- alsa = {
- enable = true;
- support32Bit = true;
- };
- jack.enable = true;
- wireplumber = {
- enable = true;
- extraConfig = {
- "99-lock-microphone-gain" = {
- "pulse.rules" = [
- {
- matches = [
- { "application.name" = "~*cord*"; }
- ];
- actions = {
- quirks = [ "no-source-volume" ];
- };
- }
- ];
- };
- "99-disable-suspend" = {
- "monitor.alsa.rules" = [
- {
- matches = [
- { "node.name" = "~alsa_input.*"; }
- { "node.name" = "~alsa_output.*"; }
- ];
- actions.update-props = {
- "session.suspend-timeout-seconds" = 0;
- };
- }
- ];
- };
- "10-bluetooth-policy" = {
- "wireplumber.profiles" = {
- "main" = {
- "policy.bluetooth" = "enabled";
- };
- };
- "monitor.bluez.properties" = {
- "bluez5.roles" = [
- "a2dp_sink"
- "a2dp_source"
- "bap_sink"
- "bap_source"
- "hfp_hf"
- "hsp_hs"
- ];
- "bluez5.codecs" = [
- "sbc"
- "sbc_xq"
- "aac"
- "ldac"
- "aptx"
- "aptx_hd"
- ];
- };
- };
- };
- };
- };
- playerctld.enable = true;
- };
-
- systemd.user.services.pipewire-quantum = {
- description = "Set strict low-latency PipeWire quantum";
- after = [ "wireplumber.service" ];
- bindsTo = [ "pipewire.service" ];
- wantedBy = [ "wireplumber.service" ];
- serviceConfig = {
- Type = "oneshot";
- ExecStart = [
- "${pkgs.pipewire}/bin/pw-metadata -n settings 0 clock.quantum 512"
- "${pkgs.pipewire}/bin/pw-metadata -n settings 0 clock.min-quantum 512"
- ];
- };
- };
-
- programs.noisetorch.enable = true;
-
- systemd.user.services.pipewire-pulse = {
- serviceConfig = {
- Environment = [ "LADSPA_PATH=/tmp" ];
- };
- };
-
- environment.systemPackages = with pkgs; [
- toggleMuteNotify
- pulsemixer
- pavucontrol
- crosspipe
- alsa-utils
- ];
- })
-
- (lib.mkIf cfg.disable-devices.enable {
- services.pipewire.wireplumber.extraConfig = {
- "99-disable-useless-devices"."monitor.alsa.rules" = [
- {
- matches = [
- { "device.name" = "~alsa_card.pci-0000_03_00.1*"; }
- { "device.description" = "~USB Audio*"; }
- ];
- actions.update-props = {
- "device.disabled" = true;
- };
- }
- ];
- };
- })
- ];
-}
diff --git a/os/core/default.nix b/os/core/default.nix
deleted file mode 100644
index 963436b..0000000
--- a/os/core/default.nix
+++ /dev/null
@@ -1,36 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.core;
-in
-{
- imports = [
- ./audio.nix
- ./bootloader.nix
- ./drivers.nix
- ./fonts.nix
- ./greet.nix
- ./home-manager.nix
- ./localization.nix
- ./memory.nix
- ./networking.nix
- ./power.nix
- ./security.nix
- ./storage.nix
- ./users.nix
- ./zfs.nix
- ];
-
- options.os.core = {
- allowUnfree.enable = lib.mkEnableOption "unfree software";
- flatpak.enable = lib.mkEnableOption "Flatpak support";
- };
-
- config = lib.mkMerge [
- (lib.mkIf cfg.allowUnfree.enable {
- nixpkgs.config.allowUnfree = true;
- })
- (lib.mkIf cfg.flatpak.enable {
- services.flatpak.enable = true;
- })
- ];
-}
diff --git a/os/core/home-manager.nix b/os/core/home-manager.nix
deleted file mode 100644
index 63f3dfd..0000000
--- a/os/core/home-manager.nix
+++ /dev/null
@@ -1,44 +0,0 @@
-{
- inputs,
- config,
- lib,
- username,
- ...
-}:
-let
- cfg = config.os.core.home-manager;
-in
-{
- imports = [ inputs.home-manager.nixosModules.home-manager ];
-
- options.os.core.home-manager = {
- enable = lib.mkEnableOption "home Manager configuration";
-
- users = lib.mkOption {
- default = { };
- description = "Attribute set of users and their home-manager configurations";
- type = lib.types.attrsOf (
- lib.types.submodule {
- options = {
- path = lib.mkOption {
- type = lib.types.path;
- description = "Path to the user's home.nix file";
- };
- };
- }
- );
- };
- };
- config = lib.mkIf cfg.enable {
- home-manager = {
- extraSpecialArgs = { inherit inputs username; };
- useGlobalPkgs = true;
- useUserPackages = true;
- backupFileExtension = "bak";
-
- users = lib.mapAttrs (name: userCfg: {
- imports = [ userCfg.path ];
- }) cfg.users;
- };
- };
-}
diff --git a/os/core/zfs.nix b/os/core/zfs.nix
deleted file mode 100644
index 771644d..0000000
--- a/os/core/zfs.nix
+++ /dev/null
@@ -1,60 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.zfs;
-in
-{
- options.os.srv.zfs.enable = lib.mkEnableOption "enables zfs drive maintnance";
- config = lib.mkIf cfg.enable {
- assertions = [
- {
- assertion = config.os.core.drivers.kernel == "zfs";
- message = "ZFS requires the zfs supported kernel";
- }
- {
- assertion = config.os.srv.sops.enable;
- message = "required for storing the ntfy token";
- }
- ];
-
- sops.secrets."ntfy/zed".neededForUsers = false;
-
- boot = {
- kernelParams = [ "zfs.zfs_arc_max=${toString (32 * 1024 * 1024 * 1024)}" ];
- zfs = {
- # requestEncryptionCredentials = [ "zroot" ];
- # useKeyringForCredentials = true;
- extraPools = [ "tank" ];
- };
- supportedFilesystems = [ "zfs" ];
- initrd.supportedFilesystems = [ "zfs" ];
- };
- services.zfs = {
- expandOnBoot = "all";
- autoScrub.enable = true;
- trim.enable = true;
- autoSnapshot = {
- enable = true;
- flags = "-k -p --utc";
- };
- zed = {
- settings = {
- ZED_DEBUG_LOG = "/var/log/zed.debug.log";
-
- ZED_NOTIFY_INTERVAL_SECS = 3600;
- ZED_NOTIFY_VERBOSE = 0;
-
- ZED_USE_ENCLOSURE_LEDS = 1;
- ZED_SCRUB_AFTER_RESILVER = 1;
- ZED_POWER_OFF_ENCLOSURE_SLOT_ON_FAULT = 1;
- ZED_POWER_OFF_ENCLOSURE_SLOT_ON_DEADMAN = 1;
-
- ZED_NTFY_TOPIC = "zed-alerts-bibus-lab";
- ZED_NTFY_URL = "http://${config.os.core.network.ips.monitor-vm}:8085";
- };
- };
- };
- systemd.services.zfs-zed.serviceConfig.EnvironmentFile = config.sops.secrets."ntfy/zed".path;
- networking.hostId = "4e3e22e1";
-
- };
-}
diff --git a/os/default.nix b/os/default.nix
deleted file mode 100644
index 5c55a8f..0000000
--- a/os/default.nix
+++ /dev/null
@@ -1,9 +0,0 @@
-{ ... }:
-{
- imports = [
- ./core/default.nix
- ./srv/default.nix
- ./wm/default.nix
- ./vms/microvms.nix
- ];
-}
diff --git a/os/srv/authelia.nix b/os/srv/authelia.nix
deleted file mode 100644
index 2c42b0a..0000000
--- a/os/srv/authelia.nix
+++ /dev/null
@@ -1,179 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- securityTemplates,
- ...
-}:
-let
- cfg = config.os.srv.authelia;
- computedBaseDN = lib.concatStringsSep "," (
- map (domainPart: "dc=${domainPart}") (lib.splitString "." masterDomain)
- );
-in
-{
- options.os.srv.authelia.enable =
- lib.mkEnableOption "enables authelia authentication gateway instance";
-
- config = lib.mkIf cfg.enable {
- assertions = [
- {
- assertion = config.os.srv.sops.enable;
- message = "sops must be enabled for secure cryptographic token storage";
- }
- {
- assertion = config.os.core.network.enableFirewall;
- message = "Requires firewall";
- }
- ];
-
- sops.secrets = {
- "authelia/jwt_secret" = {
- owner = "authelia-main";
- group = "authelia-main";
- restartUnits = [ "authelia-main.service" ];
- };
- "authelia/session_secret" = {
- owner = "authelia-main";
- group = "authelia-main";
- restartUnits = [ "authelia-main.service" ];
- };
- "authelia/encryption_key" = {
- owner = "authelia-main";
- group = "authelia-main";
- restartUnits = [ "authelia-main.service" ];
- };
-
- "authelia/oidc_hmac" = {
- owner = "authelia-main";
- group = "authelia-main";
- restartUnits = [ "authelia-main.service" ];
- };
- "authelia/oidc_private_key" = {
- owner = "authelia-main";
- group = "authelia-main";
- restartUnits = [ "authelia-main.service" ];
- };
-
- "postgres/authelia_password" = {
- owner = "authelia-main";
- group = "authelia-main";
- restartUnits = [ "authelia-main.service" ];
- };
- "redis/password" = {
- owner = "authelia-main";
- group = "authelia-main";
- restartUnits = [ "authelia-main.service" ];
- };
- };
-
- services.authelia.instances.main = {
- enable = true;
-
- secrets = {
- jwtSecretFile = config.sops.secrets."authelia/jwt_secret".path;
- sessionSecretFile = config.sops.secrets."authelia/session_secret".path;
- storageEncryptionKeyFile = config.sops.secrets."authelia/encryption_key".path;
-
- oidcHmacSecretFile = config.sops.secrets."authelia/oidc_hmac".path;
- oidcIssuerPrivateKeyFile = config.sops.secrets."authelia/oidc_private_key".path;
- };
-
- settings = {
- theme = "dark";
- default_2fa_method = "totp";
-
- log = {
- level = "info";
- format = "json";
- path = "/var/log/authelia/authelia.log";
- keep_stdout = true;
- };
-
- server.address = "tcp://127.0.0.1:9091";
-
- telemetry.metrics = {
- enabled = true;
- address = "tcp://127.0.0.1:9959";
- };
-
- storage = {
- postgres = {
- host = config.os.core.network.ips.database-vm;
- port = 5432;
- database = "authelia";
- username = "authelia";
- timeout = "5s";
- schema = "public";
- };
- };
-
- session = {
- name = "authelia_session";
- expiration = "1h";
- inactivity = "15m";
- remember_me = "1M";
- provider = {
- redis = {
- host = config.os.core.network.ips.database-vm;
- port = 6379;
- database = 0;
- timeout = "5s";
- };
- };
- };
-
- authentication_backend = {
- ldap = {
- address = "ldap://${config.os.core.network.ips.gateway-vm}:3890";
- implementation = "lldap";
- base_dn = computedBaseDN;
- user = "uid=authelia,ou=people,${computedBaseDN}";
- };
- };
-
- identity_providers = {
- oidc = {
- cors.allowed_origins = map (domain: "https://${domain}") (
- builtins.attrNames config.os.cluster.nginxProxies
- );
-
- clients = config.os.cluster.oidcClients;
- };
- };
-
- access_control = {
- default_policy = "deny";
- rules = [
- {
- domain = "auth.${masterDomain}";
- policy = "bypass";
- }
- ]
- ++ config.os.cluster.autheliaRules;
- };
-
- session.domain = masterDomain;
- };
-
- environmentVariables = {
- AUTHELIA_AUTHENTICATION_BACKEND_LDAP_PASSWORD_FILE = config.sops.secrets."lldap/password".path;
- AUTHELIA_SESSION_REDIS_PASSWORD_FILE = config.sops.secrets."redis/password".path;
- AUTHELIA_STORAGE_POSTGRES_PASSWORD_FILE = config.sops.secrets."postreg/authelia_password".path;
- };
- };
-
- os.cluster.nginxProxies."auth.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
- locations."/" = {
- proxyPass = "http://${config.os.core.network.ips.gateway-vm}:9091";
- extraConfig = securityTemplates.restrictToInternal;
- };
- };
-
- networking.firewall.extraInputRules = ''
- ip saddr ${config.os.core.network.ips.monitor-vm} tcp dport 9959 accept
- '';
- };
-}
diff --git a/os/srv/avahi.nix b/os/srv/avahi.nix
deleted file mode 100644
index f14b33a..0000000
--- a/os/srv/avahi.nix
+++ /dev/null
@@ -1,41 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.avahi;
-in
-{
- options.os.srv.avahi.enable = lib.mkEnableOption "enables avahis";
- config = lib.mkIf cfg.enable {
- services.avahi = {
- enable = true;
- ipv4 = true;
-
- publish = {
- enable = true;
- addresses = true;
- workstation = true;
- };
-
- nssmdns4 = true;
-
- extraServiceFiles = {
- nfs = ''
- <?xml version="1.0" standalone='no'?>
- <!DOCTYPE service-group SYSTEM "avahi-service.dtd">
- <service-group>
- <name replace-wildcards="yes">NFS Share on %h</name>
- <service>
- <type>_nfs._tcp</type>
- <port>2049</port>
- <txt-record>path=/data/vault</txt-record>
- </service>
- <service>
- <type>_nfs._tcp</type>
- <port>2049</port>
- <txt-record>path=/data/media</txt-record>
- </service>
- </service-group>
- '';
- };
- };
- };
-}
diff --git a/os/srv/backup.nix b/os/srv/backup.nix
deleted file mode 100644
index e7c07f9..0000000
--- a/os/srv/backup.nix
+++ /dev/null
@@ -1,97 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}:
-let
- cfg = config.os.srv.replication;
- pgLockScript = pkgs.writeScriptBin "pg-lock" ''
- #!/bin/sh
- microvm -s database-vm -- sudo -u postgres psql -c "SELECT pg_backup_start('sanoid_snap');"
- '';
-
- pgUnlockScript = pkgs.writeScriptBin "pg-unlock" ''
- #!/bin/sh
- microvm -s database-vm -- sudo -u postgres psql -c "SELECT pg_backup_stop();"
- '';
-in
-{
- options.os.srv.replication.enable = lib.mkEnableOption "enables replications";
- config = lib.mkIf cfg.enable {
- services = {
- sanoid = {
- enable = true;
- templates.production = {
- autosnap = true;
- autoprune = true;
- hourly = 24;
- daily = 7;
- weekly = 4;
- monthly = 3;
- };
- datasets = {
- "zroot/rpool/appdata/db/postgres" = {
- useTemplate = [ "production" ];
-
- pre_snapshot_script = "${pgLockScript}/bin/pg-lock";
- post_snapshot_script = "${pgUnlockScript}/bin/pg-unlock";
- no_inconsistent_snapshot = true;
- force_post_snapshot_script = true;
- script_timeout = 30;
- };
-
- "zroot/rpool/appdata/db/redis".useTemplate = [ "production" ];
-
- "zroot/rpool/appdata/db/couchdb".useTemplate = [ "production" ];
-
- "zroot/rpool/appdata/cfg".useTemplate = [ "production" ];
-
- "zroot/rpool/appdata/games".useTemplate = [ "production" ];
-
- "zroot/rpool/appdata/mail".useTemplate = [ "production" ];
-
- "zroot/rpool/containers".useTemplate = [ "production" ];
- };
- };
-
- syncoid = {
- enable = true;
- commonArgs = [
- "-c"
- "-p"
- "--delete-target-snapshots"
- "--use-hold"
- "--no-sync-snap"
- ];
- commands = {
- "sync-databases" = {
- source = "zroot/rpool/appdata/db";
- target = "tank/ztank/backup/nvme/db";
- recursive = true;
- };
-
- "sync-config" = {
- source = "zroot/rpool/appdata/cfg";
- target = "tank/ztank/backup/nvme/cfg";
- };
-
- "sync-games" = {
- source = "zroot/rpool/appdata/games";
- target = "tank/ztank/backup/nvme/games";
- };
-
- "sync-mail" = {
- source = "zroot/rpool/appdata/mail";
- target = "tank/ztank/backup/nvme/mail";
- };
-
- "sync-docker" = {
- source = "zroot/rpool/containers";
- target = "tank/ztank/backup/nvme/containers";
- };
- };
- };
- };
- };
-}
diff --git a/os/srv/clamav.nix b/os/srv/clamav.nix
deleted file mode 100644
index d2dc49f..0000000
--- a/os/srv/clamav.nix
+++ /dev/null
@@ -1,21 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.clamav;
-in
-{
- options.os.srv.clamav.enable = lib.mkEnableOption "enables clamav scanning";
- config = lib.mkIf cfg.enable {
- services.clamav = {
- daemon = {
- enable = true;
- settings = {
- MaxThreads = 20;
- MaxQueue = 100;
- };
- };
- scanner.enable = true;
- updater.enable = true;
- fangfrisch.enable = true;
- };
- };
-}
diff --git a/os/srv/cluster.nix b/os/srv/cluster.nix
deleted file mode 100644
index 6e54ee2..0000000
--- a/os/srv/cluster.nix
+++ /dev/null
@@ -1,16 +0,0 @@
-{ lib, ... }: {
- options.os.cluster = {
- nginxProxies = lib.mkOption {
- type = lib.types.attrsOf lib.types.attrs;
- default = { };
- };
- autheliaRules = lib.mkOption {
- type = lib.types.listOf lib.types.attrs;
- default = [ ];
- };
- oidcClients = lib.mkOption {
- type = lib.types.listOf lib.types.attrs;
- default = [ ];
- };
- };
-}
diff --git a/os/srv/crowdsec.nix b/os/srv/crowdsec.nix
deleted file mode 100644
index c3df81b..0000000
--- a/os/srv/crowdsec.nix
+++ /dev/null
@@ -1,181 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- ...
-}:
-let
- cfg = config.os.srv.security.crowdsec;
-in
-{
- options.os.srv.security.crowdsec = {
- enable = lib.mkEnableOption "enables CrowdSec collaborative intrusion prevention";
-
- aggregator.enable = lib.mkEnableOption "this node acting as a central LAPI aggregator for the network";
- agent.enable = lib.mkEnableOption "local log parsing and threat intelligence generation on this node";
- };
-
- config = lib.mkIf cfg.enable {
- assertions = [
- {
- assertion = config.networking.nftables.enable;
- message = "CrowdSec requires networking.nftables to be enabled for blocking.";
- }
- {
- assertion = cfg.agent.enable || cfg.aggregator.enable;
- message = "You must enable at least one CrowdSec role: 'agent.enable' or 'aggregator.enable'.";
- }
- ];
-
- sops = {
- secrets."crowdsec/env" = {
- owner = "crowdsec";
- group = "crowdsec";
- restartUnits = [ "crowdsec.service" ];
- };
-
- templates."local_api_credentials.yaml" = {
- owner = "crowdsec";
- group = "crowdsec";
- restartUnits = [ "crowdsec.service" ];
- content = ''
- url: http://${config.os.core.network.ips.gateway-vm}:8080
- login: ${config.networking.hostName}
- password: ${config.sops.placeholder."crowdsec/client_password"}
- '';
- };
- };
-
- systemd.services.crowdsec.serviceConfig.EnvironmentFile = config.sops.secrets."crowdsec/env".path;
-
- services.crowdsec = {
- enable = true;
- autoUpdateService = true;
-
- openFirewall = true;
-
- settings = {
- common = {
- compress_logs = true;
- log_format = "json";
- };
- prometheus = {
- enabled = true;
- level = "full";
- listen_addr = "0.0.0.0";
- listen_port = 6060;
- };
- db_config = {
- type = "postgresql";
- host = config.os.core.network.ips.database-vm;
- port = 5432;
- db_name = "crowdsec";
- user = "crowdsec";
- password = "$CROWDSEC_DB_PASSWORD";
- sslmode = "require";
- };
-
- api = {
- server = {
- enable = cfg.aggregator.enable;
- listen_uri = "0.0.0.0:8080";
- trusted_ips = [
- "127.0.0.1"
- "10.0.0.0/24"
- ];
-
- auto_registration = {
- enabled = cfg.aggregator.enable;
- token = "$CROWDSEC_REGISTER_TOKEN";
- allowed_ranges = [ "10.0.0.0/24" ];
- };
- };
- client.credentials_path = config.sops.templates."local_api_credentials.yaml".path;
- };
- lapi.client.api_url = "http://${config.os.core.network.ips.gateway-vm}:8080";
- };
-
- hub = lib.mkIf cfg.agent.enable {
- collections = [
- "crowdsecurity/linux"
- "crowdsecurity/nginx"
- "crowdsecurity/authelia"
- "crowdsecurity/sshd"
- ];
- };
-
- localConfig = {
- acquisitions = lib.mkIf cfg.agent.enable [
- {
- source = "journalctl";
- journalctl_filter = [ "_SYSTEMD_UNIT=sshd.service" ];
- labels.type = "syslog";
- }
- {
- source = "file";
- filenames = [ "/var/log/nginx/*.log" ];
- labels.type = "nginx";
- }
- {
- source = "file";
- filenames = [ "/var/log/authelia/authelia.log" ];
- labels.type = "authelia";
- }
- ];
-
- parsers.s02Enrich = lib.mkIf cfg.agent.enable [
- {
- name = "myips/whitelist";
- description = "Prevent local address ranges from triggering bans";
- whitelist = {
- reason = "Internal private subnets";
- cidr = [
- "10.0.0.0/24"
- "10.1.0.0/24"
- "10.3.0.0/24"
- "10.4.0.0/24"
- ];
- };
- }
- ];
-
- notifications = lib.mkIf cfg.aggregator.enable [
- {
- name = "ntfy_alerts";
- type = "http";
- method = "POST";
- url = "https://ntfy.${masterDomain}/crowdsec-alerts";
- headers = {
- Title = "CrowdSec Alert on Bibus-Lab";
- Priority = "high";
- Authorization = "$NTFY_AUTH_TOKEN";
- };
- format = ''
- {{range .}} {{.Alert.Message}} (Scenario: {{.Alert.Scenario}}) from IP {{.Alert.Source.IP}} {{end}}
- '';
- log_level = "info";
- }
- ];
- };
- };
-
- services.crowdsec-firewall-bouncer = {
- enable = true;
-
- registerBouncer.enable = cfg.aggregator.enable;
-
- settings = {
- mode = "nftables";
- update_frequency = "10s";
- api_url = "http://${config.os.core.network.ips.gateway-vm}:8080";
- api_key = lib.mkIf cfg.aggregator.enable "$CROWDSEC_LOCAL_BOUNCER_KEY";
- };
- };
-
- users.users.crowdsec.extraGroups = lib.mkIf cfg.agent.enable [
- "systemd-journal"
- "nginx"
- "authelia-main"
- ];
- };
-}
diff --git a/os/srv/default.nix b/os/srv/default.nix
deleted file mode 100644
index c89d029..0000000
--- a/os/srv/default.nix
+++ /dev/null
@@ -1,48 +0,0 @@
-{ ... }:
-{
- imports = [
- ./authelia.nix
- ./backup.nix
- ./bluetooth.nix
- ./clamav.nix
- ./cluster.nix
- ./compat.nix
- ./crowdsec.nix
- ./dns.nix
- ./files.nix
- ./gaming.nix
- ./grafana.nix
- ./headscale.nix
- ./i2p.nix
- ./kea.nix
- ./lldap.nix
- ./loki.nix
- ./mailserver.nix
- ./monero.nix
- ./netdata.nix
- ./nfs.nix
- ./nginx.nix
- ./nix-helper.nix
- ./ntfy.nix
- ./ntopng.nix
- ./oci.nix
- ./omnisearch.nix
- ./postgres.nix
- ./prometheus.nix
- ./redis.nix
- ./scrutiny.nix
- ./simplex.nix
- ./sops.nix
- ./ssh.nix
- ./sunshine.nix
- ./syncthing.nix
- ./tailscale.nix
- ./tor.nix
- ./ups.nix
- ./uptime-kuma.nix
- ./vector.nix
- ./virtualization.nix
- ./wireguard.nix
- ./yggdrasil.nix
- ];
-}
diff --git a/os/srv/dns.nix b/os/srv/dns.nix
deleted file mode 100644
index b8a973f..0000000
--- a/os/srv/dns.nix
+++ /dev/null
@@ -1,286 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- securityTemplates,
- ...
-}:
-let
- cfg = config.os.srv.dns;
- unboundPort = 5335;
-in
-{
- options.os.srv.dns = {
- enable = lib.mkEnableOption "enables dns scanning";
- adguardProxyConfig = lib.mkOption {
- type = lib.types.attrs;
- default = { };
- };
- };
- config = lib.mkIf cfg.enable {
- services.unbound = {
- enable = true;
- settings = {
- server = {
- interface = [ "127.0.0.1" ];
- port = unboundPort;
-
- do-ip4 = true;
- do-ip6 = false;
- do-udp = true;
- do-tcp = true;
-
- num-threads = 4;
- msg-cache-slabs = 4;
- rrset-cache-slabs = 4;
- infra-cache-slabs = 4;
- key-cache-slabs = 4;
-
- msg-cache-size = "256m";
- rrset-cache-size = "512m";
- infra-cache-numhosts = 20000;
-
- so-rcvbuf = "8m";
- so-sndbuf = "8m";
- so-reuseport = true;
-
- qname-minimisation = true;
- prefetch = true;
- prefetch-key = true;
- harden-glue = true;
- harden-dnssec-stripped = true;
- hide-identity = true;
- hide-version = true;
- use-caps-for-id = false; # might try this later
- edns-buffer-size = 1232;
-
- access-control = [
- "127.0.0.0/8 allow"
- "0.0.0.0/0 deny"
- ];
- };
- };
- };
-
- services.adguardhome = {
- enable = true;
- mutableSettings = true;
-
- settings = {
- http.address = "0.0.0.0:3000";
- dns = {
- bind_hosts = [
- "127.0.0.1"
- config.os.core.network.lan.ip
- config.os.core.network.wg.ip
- config.os.core.network.hs.ip
- ];
- rewrites = [
- {
- domain = "router.lan";
- answer = config.os.core.network.ips.opnsense-vm;
- }
- {
- domain = "nas.lan";
- answer = config.os.core.network.ips.bare-metal;
- }
- {
- domain = "ldap.${masterDomain}";
- answer = config.os.core.network.ips.gateway-vm;
- }
- ];
- port = 53;
- upstream_dns = [ "127.0.0.1:${toString unboundPort}" ];
- fallback_dns = [ "9.9.9.9" ];
- bootstrap_dns = [ "9.9.9.9" ];
- cache_size = 536870912;
- anonymize_client_ip = true;
- };
-
- filtering = {
- filtering_enabled = true;
- interval = 24;
- };
- filters = [
- {
- enabled = true;
- name = "Black Mirror Blocklist";
- url = "https://raw.githubusercontent.com/T145/black-mirror/refs/heads/master/dist/ADGUARD_SOURCES.txt";
- }
- {
- enabled = true;
- name = "Scam Blocklist by DurableNapkin";
- url = "https://raw.githubusercontent.com/durablenapkin/scamblocklist/master/adguard.txt";
- }
- {
- enabled = true;
- name = "Neo Dev Host Blocklist";
- url = "https://raw.githubusercontent.com/neodevpro/neodevhost/master/adblocker";
- }
- {
- enabled = true;
- name = "hBlock Blocklist";
- url = "https://hblock.molinero.dev/hosts_adblock.txt";
- }
- {
- enabled = true;
- name = "OISD Big Blocklist";
- url = "https://big.oisd.nl";
- }
- {
- enabled = true;
- name = "StevenBlack Unified";
- url = "https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts";
- }
- {
- enabled = true;
- name = "StevenBlack Fakenews";
- url = "https://raw.githubusercontent.com/StevenBlack/hosts/master/alternates/fakenews-only/hosts";
- }
- {
- enabled = true;
- name = "StevenBlack Gambling";
- url = "https://raw.githubusercontent.com/StevenBlack/hosts/master/alternates/gambling-only/hosts";
- }
-
- #-----------------------------------------------------------------------------
-
- # HaGeZi's Blocklists
-
- {
- enabled = true;
- name = "HaGeZi's Ultimate Blocklist";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/ultimate.txt";
- }
- {
- enabled = false; # Added but disabled Pro++ as a fallback if Ultimate proves to be too aggressive
- name = "HaGeZi's Pro++ DNS Blocklist";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/pro.plus.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Fake DNS Blocklist";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/fake.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Threat Intelligence Feeds DNS Blocklist";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/tif.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Dynamic DNS Blocklsit";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/dyndns.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Badware Hoster Blocklist";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/hoster.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's URL Shortener Blocklist";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/urlshortener.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's DNS Rebind Protection";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adguard/dns-rebind-protection.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Gambling DNS Blocklist";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/gambling.txt";
- }
-
- #-----------------------------------------------------------------------------
-
- # NEWLY REGISTERED DOMAINS / ENTROPY DGAs
-
- {
- enabled = true;
- name = "HaGeZi's Newly Registered Domains 7 days ago to yesterday";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/nrd7.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Newly Registered Domains 14 days ago to 8 days ago";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/nrd14-8.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Newly Registered Domains 21 days ago to 15 days ago";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/nrd21-15.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Newly Registered Domains 28 days ago to 12 days ago";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/nrd28-22.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Newly Registered Domains 35 days ago to 29 days ago";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/nrd35-29.txt";
- }
- {
- enabled = true;
- name = "HaGeZi's Newly Registered High Entropy Domains";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/dga30.txt";
- }
-
- #-----------------------------------------------------------------------------
-
- # DNS BYPASS BLOCKLISTS
-
- {
- enabled = true;
- name = "HaGeZi's DNS Bypass Blocklist";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/doh-vpn-proxy-bypass.txt";
- }
- {
- enabled = true;
- name = "DNS HTTPS Blocklist";
- url = "https://raw.githubusercontent.com/Bryantdl7/pihole-blocklists/main/dns-https-block.txt";
- }
-
- #-----------------------------------------------------------------------------
-
- # NSFW DNS BLOCKLISTS
-
- {
- enabled = true;
- name = "HaGeZi's NSFW DNS Blocklist";
- url = "https://raw.githubusercontent.com/hagezi/dns-blocklists/main/adblock/nsfw.txt";
- }
- {
- enabled = true;
- name = "oisd NSFW";
- url = "https://nsfw.oisd.nl";
- }
- {
- enabled = true;
- name = "StevenBlack NSFW Blocklist";
- url = "https://raw.githubusercontent.com/StevenBlack/hosts/master/alternates/porn-only/hosts";
- }
- ];
- };
- };
-
- os.srv.dns.adguardProxyConfig = {
- "adguard.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
-
- locations."/" = {
- proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000";
- extraConfig = securityTemplates.restrictToInternal;
- };
- };
- };
-
- networking.firewall = {
- allowedUDPPorts = [ 53 ];
- allowedTCPPorts = [ 53 ];
- };
- };
-}
diff --git a/os/srv/grafana.nix b/os/srv/grafana.nix
deleted file mode 100644
index 5428818..0000000
--- a/os/srv/grafana.nix
+++ /dev/null
@@ -1,109 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- securityTemplates,
- ...
-}:
-let
- cfg = config.os.srv.grafana;
-in
-{
- options.os.srv.grafana = {
- enable = lib.mkEnableOption "enables grafana";
- proxyConfig = lib.mkOption {
- type = lib.types.attrs;
- default = { };
- };
- };
- config = lib.mkIf cfg.enable {
- services.grafana = {
- enable = true;
- openFirewall = true;
-
- # Might use later
- # declarativePlugins = [ ];
-
- settings = {
- server = {
- protocol = "http";
- http_port = 3000;
- http_addr = "0.0.0.0";
- domain = "grafana.${masterDomain}";
- root_url = "https://grafana.${masterDomain}";
- enforceDomain = true;
- enable_gzip = true;
- };
- database = {
- wal = true;
- };
- security = {
- admin_user = "opc";
- # TODO: Generate password to use in sops-nix
- # admin_password = "sops"
- admin_email = "adikro@disroot.org";
- # TODO generate secret key and put it in sops-nix
- # secret_key = "sops";
- disable_gravatar = true;
- cookie_secure = true;
- cookie_samesite = "lax";
- # security
- allow_embedding = false;
- strict_transport_security = true;
-
- disable_initial_admin_creation = false;
- disable_brute_force_login_protection = false;
- };
- # TODO setup mailing
- # smtp = { enabled = true; };
- analytics.feedback_links_enabled = false;
- };
- provision = {
- enable = true;
- datasources.settings = {
- prune = true;
-
- datasources = [
- {
- name = "Prometheus";
- type = "prometheus";
- url = "http://127.0.0.1:9090";
- access = "proxy";
- isDefault = true;
- editable = false;
- }
- {
- name = "Loki";
- type = "loki";
- url = "http://127.0.0.1:3100";
- access = "proxy";
- editable = false;
- }
- ];
- };
- };
- # dashboards.settings = {
- # providers = [
- # {
- # name = "default";
- # type = "file";
- # options.path = "/var/lib/grafana/dashboards";
- # }
- # ];
- # };
- };
-
- os.srv.grafana.proxyConfig = {
- "grafana.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
-
- locations."/" = {
- proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000";
- proxyWebsockets = true;
- extraConfig = securityTemplates.restrictToInternal;
- };
- };
- };
- };
-}
diff --git a/os/srv/headscale.nix b/os/srv/headscale.nix
deleted file mode 100644
index 01fc06c..0000000
--- a/os/srv/headscale.nix
+++ /dev/null
@@ -1,76 +0,0 @@
-{
- config,
- lib,
- pkgs,
- masterDomain,
- ...
-}:
-let
- cfg = config.os.srv.headscale;
- aclPolicy = pkgs.writeText "headscale-policy.json" (
- builtins.toJSON {
- groups = {
- "group:admin" = [ "your-device-name" ];
- "group:friends" = [ "friend-device-name" ];
- };
-
- hosts = {
- "server" = "10.4.0.1";
- };
-
- acls = [
- {
- action = "accept";
- src = [ "group:admin" ];
- dst = [ "*:*" ];
- }
-
- {
- action = "accept";
- src = [ "group:friends" ];
- dst = [
- "server:18080"
- "server:18081"
- "server:25565"
- ];
- }
- ];
- }
- );
-in
-{
- options.os.srv.headscale.enable = lib.mkEnableOption "enables headscales";
-
- config = lib.mkIf cfg.enable {
- services.headscale = {
- enable = true;
- address = "127.0.0.1";
- port = 8080;
-
- settings = {
- server_url = "https://vpn.${masterDomain}";
-
- policy.path = "${aclPolicy}";
-
- dns = {
- magic_dns = true;
- base_domain = "vpn";
- nameservers = [ config.os.core.network.ips.vm2-gateway ];
- };
-
- ip_prefixes = [
- "10.4.0.0/16"
- ];
- };
- };
-
- services.nginx.virtualHosts."vpn.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
- locations."/" = {
- proxyPass = "http://127.0.0.1:8080";
- proxyWebsockets = true;
- };
- };
- };
-}
diff --git a/os/srv/kea.nix b/os/srv/kea.nix
deleted file mode 100644
index 168590e..0000000
--- a/os/srv/kea.nix
+++ /dev/null
@@ -1,58 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.kea;
-in
-{
- options.os.srv.kea.enable = lib.mkEnableOption "enables kea dhcp server";
- config = lib.mkIf cfg.enable {
- services.kea.dhcp4 = {
- enable = true;
- settings = {
- interfaces-config = {
- # To be used in a VM
- interfaces = [ "eth0" ];
- dhcp-socket-type = "udp";
- };
-
- lease-database = {
- type = "memfile";
- persist = true;
- name = "/var/lib/kea/dhcp4.leases";
- };
-
- subnet4 = [
- {
- id = 1;
- subnet = "10.1.0.0/24";
- pools = [ { pool = "10.1.0.50 - 10.1.0.250"; } ];
- option-data = [
- {
- name = "routers";
- data = "10.1.0.1";
- }
- {
- name = "domain-name-servers";
- data = "10.0.0.3";
- }
- ];
- }
- {
- id = 2;
- subnet = "10.2.0.0/24";
- pools = [ { pool = "10.2.0.50 - 10.2.0.250"; } ];
- option-data = [
- {
- name = "routers";
- data = "10.2.0.1";
- }
- {
- name = "domain-name-servers";
- data = "10.0.0.3";
- }
- ];
- }
- ];
- };
- };
- };
-}
diff --git a/os/srv/lldap.nix b/os/srv/lldap.nix
deleted file mode 100644
index 6755dfe..0000000
--- a/os/srv/lldap.nix
+++ /dev/null
@@ -1,55 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- ...
-}:
-let
- cfg = config.os.srv.lldap;
- computedBaseDN = lib.concatStringsSep "," (
- map (domainPart: "dc=${domainPart}") (lib.splitString "." masterDomain)
- );
-in
-{
- options.os.srv.lldap.enable = lib.mkEnableOption "enables lldap scanning";
- config = lib.mkIf cfg.enable {
- assertions = [
- {
- assertion = config.os.srv.sops.enable;
- message = "Required for password secure password storing";
- }
- {
- assertion = config.os.core.network.enableFirewall;
- message = "Requires firewall";
- }
- ];
-
- sops.secrets = {
- "lldap/password" = {
- owner = "lldap";
- group = "lldap";
- };
- "lldap/env_file" = {
- owner = "lldap";
- group = "lldap";
- };
- };
-
- services.lldap = {
- enable = true;
- settings = {
- ldap_base_dn = computedBaseDN;
- http_host = "127.0.0.1";
- http_url = "https://lldap.${masterDomain}";
- ldap_user_email = "adikro@disroot.org";
- ldap_user_pass_file = config.sops.secrets."lldap/password".path;
- silenceForceUserPassResetWarning = true;
- };
- environmentFile = config.sops.secrets."lldap/env_file".path;
- };
-
- networking.firewall.extraInputRules = ''
- ip saddr 10.0.0.0/24 tcp dport 3890 accept
- '';
- };
-}
diff --git a/os/srv/loki.nix b/os/srv/loki.nix
deleted file mode 100644
index 84b94d8..0000000
--- a/os/srv/loki.nix
+++ /dev/null
@@ -1,62 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.loki;
-in
-{
- options.os.srv.loki.enable = lib.mkEnableOption "enables loki";
- config = lib.mkIf cfg.enable {
- services.loki = {
- enable = true;
- configuration = {
- server = {
- http_listen_address = "0.0.0.0";
- http_compress_responses = true;
- };
-
- common = {
- instance_addr = "127.0.0.1";
- path_prefix = "/var/lib/loki";
- replication_factor = 1;
-
- storage.filesystem = {
- chunks_directory = "/var/lib/loki/chunks";
- rules_directory = "/var/lib/loki/rules";
- };
- };
-
- schema_config.configs = [
- {
- from = "2026-01-01";
- store = "tsdb";
- object_store = "filesystem";
- schema = "v13";
- index = {
- prefix = "loki_index_";
- period = "24h";
- };
- }
- ];
-
- ingester.wal.enabled = true;
-
- limits_config = {
- max_entries_limit_per_query = 10000;
- reject_old_samples_max_age = "720h";
- retention_period = "90d";
- volume_enabled = true;
- };
-
- compactor = {
- enabled = true;
- retention_enabled = true;
- retention_delete_delay = "1h";
- compactor_window = "168h";
- };
-
- querier.query_timeout = "5m";
- query_range.out_of_order_time_shifting = "5m";
- analytics.reporting_enabled = false;
- };
- };
- };
-}
diff --git a/os/srv/mailserver.nix b/os/srv/mailserver.nix
deleted file mode 100644
index 7bcd008..0000000
--- a/os/srv/mailserver.nix
+++ /dev/null
@@ -1,59 +0,0 @@
-{
- config,
- lib,
- inputs,
- masterDomain,
- ...
-}:
-let
- cfg = config.os.srv.mailserver;
-in
-{
- options.os.srv.mailserver.enable = lib.mkEnableOption "enables mailserver scanning";
- imports = [ inputs.nixos-mailserver.nixosModules.mailserver ];
- config = lib.mkIf cfg.enable {
- assertions = [
- {
- assertion = config.os.srv.sops.enable;
- message = "Required for password secure password storing";
- }
- {
- assertion = config.os.srv.lldap.enable;
- message = "required for user accounts";
- }
- ];
- mailserver = {
- enable = true;
- fqdn = "mail.${masterDomain}";
- domains = [ masterDomain ];
-
- # TODO setup ldap
- ldap = {
- enable = true;
- uris = [ "ldap://127.0.0.1:3890" ];
- base = "ou=people,dc=yourdomain,dc=com";
-
- bind = {
- dn = "uid=mail-service,ou=people,dc=yourdomain,dc=com";
- passwordFile = "/var/src/secrets/ldap-mail-password";
- };
-
- attributes = {
- username = "uid";
- mail = "mail";
- password = "userPassword";
- uuid = "entryUUID";
- };
-
- dovecot = {
- userFilter = "(|(mail=%{user})(uid=%{user}))";
- passFilter = "(uid=%{user})";
- };
-
- postfix = {
- filter = "(mail=%s)";
- };
- };
- };
- };
-}
diff --git a/os/srv/netdata.nix b/os/srv/netdata.nix
deleted file mode 100644
index a7b4300..0000000
--- a/os/srv/netdata.nix
+++ /dev/null
@@ -1,43 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- securityTemplates,
- ...
-}:
-let
- cfg = config.os.srv.netdata;
-in
-{
- options.os.srv.netdata = {
- enable = lib.mkEnableOption "enables netdata monitoring";
- proxyConfig = lib.mkOption {
- type = lib.types.attrs;
- default = { };
- };
- };
-
- config = lib.mkIf cfg.enable {
- services.netdata = {
- enable = true;
- config.web."bind to" = "127.0.0.1";
-
- python = {
- enable = true;
- recommendedPythonPackages = true;
- };
- };
-
- os.srv.netdata.proxyConfig = {
- "netdata.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
-
- locations."/" = {
- proxyPass = "http://${config.os.core.network.ips.host}:19999";
- extraConfig = securityTemplates.restrictToInternal;
- };
- };
- };
- };
-}
diff --git a/os/srv/nfs.nix b/os/srv/nfs.nix
deleted file mode 100644
index 07f331e..0000000
--- a/os/srv/nfs.nix
+++ /dev/null
@@ -1,26 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.nfs;
-in
-{
- options.os.srv.nfs.enable = lib.mkEnableOption "enables nfs drive sharing";
- config = lib.mkIf cfg.enable {
- services.nfs.server = {
- enable = true;
- nproc = 4; # Lowered due to low traffic for a home server
- createMountPoints = true;
-
- exports = ''
- /data/media 10.1.0.0/24(rw,all_squash,anonuid=1000,anongid=100,async,insecure,no_subtree_check) \
- 10.3.0.0/24(rw,all_squash,anonuid=1000,anongid=100,async,insecure,no_subtree_check) \
- 10.4.0.0/24(rw,all_squash,anonuid=1000,anongid=100,async,insecure,no_subtree_check)
-
- /data/vault 10.1.0.0/24(rw,all_squash,anonuid=1000,anongid=100,async,insecure,no_subtree_check) \
- 10.3.0.0/24(rw,all_squash,anonuid=1000,anongid=100,async,insecure,no_subtree_check) \
- 10.4.0.0/24(rw,all_squash,anonuid=1000,anongid=100,async,insecure,no_subtree_check)
- '';
- };
-
- networking.firewall.allowedTCPPorts = [ 2049 ];
- };
-}
diff --git a/os/srv/nginx.nix b/os/srv/nginx.nix
deleted file mode 100644
index 2194ecb..0000000
--- a/os/srv/nginx.nix
+++ /dev/null
@@ -1,75 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}:
-
-let
- cfg = config.os.srv.nginx;
-in
-{
- options.os.srv.nginx = {
- enable = lib.mkEnableOption "the NGINX reverse proxy service";
-
- openFirewall = lib.mkOption {
- type = lib.types.bool;
- default = true;
- description = "Whether to open ports 80 and 443 in the firewall.";
- };
- };
-
- config = lib.mkMerge [
- {
- _module.args.securityTemplates.restrictToInternal = ''
- allow 127.0.0.1;
- allow ::1;
-
- allow ${config.os.core.network.lan.range};
- allow 10.1.0.0/24;
- allow ${config.os.core.network.wg.range};
- allow ${config.os.core.network.hs.range};
-
- deny all;
- '';
- }
-
- (lib.mkIf cfg.enable {
- services.nginx = {
- enable = true;
- package = pkgs.nginx.override { openssl = pkgs.libressl; };
-
- recommendedProxySettings = true;
- recommendedTlsSettings = true;
- recommendedOptimisation = true;
- recommendedGzipSettings = true;
- virtualHosts = lib.mkMerge [
- {
- "_" = {
- default = true;
- rejectSSL = true;
- locations."/".return = "444";
- };
- }
- config.os.cluster.nginxProxies
- ];
- };
-
- security.acme = {
- acceptTerms = true;
- defaults.email = "adikro@disroot.org";
- };
-
- users.users.nginx.extraGroups = [ "acme" ];
-
- networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [
- 80
- 443
- ];
-
- systemd.tmpfiles.rules = [
- "d /var/log/nginx 0750 nginx adm -"
- ];
- })
- ];
-}
diff --git a/os/srv/ntfy.nix b/os/srv/ntfy.nix
deleted file mode 100644
index 1417c81..0000000
--- a/os/srv/ntfy.nix
+++ /dev/null
@@ -1,59 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- ...
-}:
-let
- cfg = config.os.srv.ntfy;
-in
-{
- options.os.srv.ntfy = {
- enable = lib.mkEnableOption "enables ntfy";
- proxyConfig = lib.mkOption {
- type = lib.types.attrs;
- default = { };
- };
- };
- config = lib.mkIf cfg.enable {
- services.ntfy-sh = {
- enable = true;
- settings = {
- base-url = "https://ntfy.${masterDomain}";
-
- listen-http = "127.0.0.1:2586";
-
- cache-file = "/var/lib/ntfy/cache.db";
- cache-duration = "72h";
-
- attachment-cache-dir = "/var/lib/ntfy/attachments";
- attachment-total-size-limit = "5G";
- attachment-file-size-limit = "15M";
- attachment-expiry-duration = "3h";
-
- behind-proxy = true;
- };
- };
-
- os.srv.ntfy.proxyConfig = {
- "uptime-kuma.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
-
- locations."/" = {
- proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3001";
- extraConfig = ''
- proxy_set_header Connection "";
- proxy_connect_timeout 1m;
- proxy_send_timeout 1m;
- proxy_read_timeout 24h;
-
- proxy_buffering off;
- proxy_request_buffering off;
- chunked_transfer_encoding on;
- '';
- };
- };
- };
- };
-}
diff --git a/os/srv/ntopng.nix b/os/srv/ntopng.nix
deleted file mode 100644
index 692fe2c..0000000
--- a/os/srv/ntopng.nix
+++ /dev/null
@@ -1,43 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- securityTemplates,
- ...
-}:
-let
- cfg = config.os.srv.ntopng;
-in
-{
- options.os.srv.ntopng = {
- enable = lib.mkEnableOption "enables ntopng monitoring";
- proxyConfig = lib.mkOption {
- type = lib.types.attrs;
- default = { };
- };
- };
- config = lib.mkIf cfg.enable {
- services.ntopng = {
- enable = true;
- extraConfig = "--packet-fanout 'cluster' -g 2 -m '192.168.0.0/16,10.0.0.0/8' -X 50000 --community";
-
- # TODO fill interfaces
- interfaces = [
- "" # WAN Interface
- "" # LAN Interface
- "" # Virtual Bridge
- ];
- };
- os.srv.ntopng.proxyConfig = {
- "ntopng.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
-
- locations."/" = {
- proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000";
- extraConfig = securityTemplates.restrictToInternal;
- };
- };
- };
- };
-}
diff --git a/os/srv/oci.nix b/os/srv/oci.nix
deleted file mode 100644
index ea680fd..0000000
--- a/os/srv/oci.nix
+++ /dev/null
@@ -1,36 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}:
-let
- cfg = config.os.srv.oci;
-in
-{
- options.os.srv.oci.enable = lib.mkEnableOption "OCI container support via Podman";
- config = lib.mkIf cfg.enable {
- virtualisation = {
- containers = {
- enable = true;
- storage.settings.driver = "zfs";
- };
- podman = {
- enable = true;
- dockerCompat = true;
- defaultNetwork.settings.dns_enabled = true;
- autoPrune = {
- enable = true;
- dates = "weekly";
- flags = [ "--all" ];
- };
- };
- oci-containers.backend = "podman";
- };
-
- environment.systemPackages = with pkgs; [
- podman-tui
- podman-compose
- ];
- };
-}
diff --git a/os/srv/postgres.nix b/os/srv/postgres.nix
deleted file mode 100644
index f669f63..0000000
--- a/os/srv/postgres.nix
+++ /dev/null
@@ -1,72 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}:
-let
- cfg = config.os.srv.postgres;
-in
-{
- options.os.srv.postgres.enable = lib.mkEnableOption "";
- config = lib.mkIf cfg.enable {
- assertions = [
- {
- assertion = config.os.srv.sops.enable;
- message = "Required for password secure password storing";
- }
- {
- assertion = config.os.core.network.enableFirewall;
- message = "Requires firewall";
- }
- ];
-
- sops.secrets."postgres/authelia_password" = {
- owner = "postgres";
- group = "postgres";
- restartUnits = [ "postgresql.service" ];
- };
-
- services.postgresql = {
- enable = true;
- package = pkgs.postgresql_18;
-
- extraPlugins = [ config.services.postgresql.package.pkgs.pgvector ];
-
- settings = {
- listen_addresses = config.os.core.network.ips.database-vm;
-
- max_connections = 100;
- shared_buffers = "256MB";
- work_mem = "4MB";
- };
-
- ensureDatabases = [ "authelia" ];
- ensureUsers = [
- {
- name = "authelia";
- ensureDBOwnership = true;
- }
- ];
-
- initialScript = pkgs.writeText "init-postgres-passwords.sql" ''
- CREATE USER authelia;
- ALTER USER authelia WITH PASSWORD 'scram-sha-256';
- '';
-
- authentication = pkgs.lib.mkForce ''
- local all all trust
- host all all 10.0.0.0/24 scram-sha-256
- '';
- };
-
- systemd.services.postgresql.postStart = lib.mkAfter ''
- PASS=$(cat ${config.sops.secrets."postgres/authelia_password".path})
- ${config.services.postgresql.package}/bin/psql -tAc "ALTER USER authelia WITH PASSWORD '$PASS';"
- '';
-
- networking.firewall.extraInputRules = ''
- ip saddr 10.0.0.0/24 tcp dport 5432 accept
- '';
- };
-}
diff --git a/os/srv/prometheus.nix b/os/srv/prometheus.nix
deleted file mode 100644
index 5b133be..0000000
--- a/os/srv/prometheus.nix
+++ /dev/null
@@ -1,75 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- ...
-}:
-let
- cfg = config.os.srv.prometheus;
-in
-{
- options.os.srv.prometheus.enable = lib.mkEnableOption "enables prometheus";
- config = lib.mkIf cfg.enable {
- services.prometheus = {
- enable = true;
- port = 9090;
-
- scrapeConfigs = [
- {
- job_name = "prometheus";
- static_configs = [ { targets = [ "127.0.0.1:9090" ]; } ];
- }
- {
- job_name = "node-hardware";
- static_configs = [ { targets = [ "127.0.0.1:9100" ]; } ];
- }
- {
- job_name = "node_exporter";
- static_configs = [ { targets = [ "127.0.0.1:9100" ]; } ];
- }
- {
- job_name = "bare_metal_host_netdata";
- scheme = "https";
- metrics_path = "/api/v1/allmetrics";
- params = {
- format = [ "prometheus" ];
- };
- static_configs = [
- { targets = [ "netdata.${masterDomain}" ]; }
- ];
- }
- {
- job_name = "uptime_kuma";
- metrics_path = "/metrics";
- static_configs = [ { targets = [ "127.0.0.1:3001" ]; } ];
- }
- {
- job_name = "network-latency";
- static_configs = [ { targets = [ "127.0.0.1:9374" ]; } ];
- }
- ];
- exporters = {
- node = {
- enable = true;
- enableCollectors = [ "systemd" ];
- port = 9100;
- };
-
- smokeping = {
- enable = true;
- listenAddress = "127.0.0.1";
-
- hosts = [
- "10.0.0.1" # Personal Router
- "192.168.0.1" # ISP Modem Box
- "84.116.254.69" # First ISP Hop
- "185.182.244.39" # Regional Katowice Hub
- "1.1.1.1" # Cloudflare DNS
- "8.8.8.8" # Google DNS
- "130.162.223.123" # OCI Instance
- ];
- };
- };
- };
- };
-}
diff --git a/os/srv/redis.nix b/os/srv/redis.nix
deleted file mode 100644
index a51f9db..0000000
--- a/os/srv/redis.nix
+++ /dev/null
@@ -1,37 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.redis;
-in
-{
- options.os.srv.redis.enable = lib.mkEnableOption "";
- config = lib.mkIf cfg.enable {
- assertions = [
- {
- assertion = config.os.srv.sops.enable;
- message = "Required for password secure password storing";
- }
- {
- assertion = config.os.core.network.enableFirewall;
- message = "Requires firewall";
- }
- ];
-
- sops.secrets."redis/password" = {
- owner = "redis-main";
- restartUnits = [ "redis-servers-main.service" ];
- };
-
- services.redis.servers."main" = {
- enable = true;
- bind = config.os.core.network.ips.database-vm;
- port = 6379;
-
- requirePassFile = config.sops.secrets."redis/password".path;
- };
-
- networking.firewall.extraInputRules = ''
- ip saddr 10.0.0.0/24 tcp dport 6379 accept
- '';
-
- };
-}
diff --git a/os/srv/restic.nix b/os/srv/restic.nix
deleted file mode 100644
index fb2bd19..0000000
--- a/os/srv/restic.nix
+++ /dev/null
@@ -1,12 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.restic;
-in
-{
- options.os.srv.restic.enable = lib.mkEnableOption "enables restic backups";
-
- config = lib.mkIf cfg.enable {
- assertions = [
- ];
- };
-}
diff --git a/os/srv/scrutiny.nix b/os/srv/scrutiny.nix
deleted file mode 100644
index ffe8c39..0000000
--- a/os/srv/scrutiny.nix
+++ /dev/null
@@ -1,35 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- securityTemplates,
- ...
-}:
-let
- cfg = config.os.srv.scrutiny;
-in
-{
- options.os.srv.scrutiny.enable = lib.mkEnableOption "enables scrutiny monitoring";
- config = lib.mkIf cfg.enable {
- services.scrutiny = {
- enable = true;
- settings.web.listen.host = "127.0.0.1";
-
- collector = {
- enable = true;
- schedule = "hourly";
- settings.host.id = "bibus-lab";
- };
- };
-
- services.nginx.virtualHosts."scrutiny.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
-
- locations."/" = {
- proxyPass = "http://127.0.0.1:8080";
- extraConfig = securityTemplates.restrictToInternal;
- };
- };
- };
-}
diff --git a/os/srv/simplex.nix b/os/srv/simplex.nix
deleted file mode 100644
index ca22192..0000000
--- a/os/srv/simplex.nix
+++ /dev/null
@@ -1,129 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- ...
-}:
-let
- cfg = config.os.srv.simplex;
- internalSmpPort = 5223;
- internalXftpPort = 5224;
-in
-{
- options.os.srv.simplex = {
- enable = lib.mkEnableOption "enables SimpleX SMP and XFTP containers via Podman";
- tor.enable = lib.mkEnableOption "enables Tor hidden services for SimpleX";
- };
-
- config = lib.mkIf cfg.enable (
- lib.mkMerge [
- {
- assertions = [
- {
- assertion = config.os.srv.oci.enable;
- message = "SimpleX requires os.srv.oci to be enabled to run containers.";
- }
- {
- assertion = config.os.srv.nginx.enable;
- message = "SimpleX requires os.srv.nginx to be enabled for clearnet proxying.";
- }
- {
- assertion = config.os.srv.sops.enable;
- message = "SimpleX requires sops for managing container passwords securely.";
- }
- ];
-
- sops.secrets."simplex/smp-env" = { };
- sops.secrets."simplex/xftp-env" = { };
-
- virtualisation.oci-containers.containers = {
- simplex-smp = {
- image = "simplexchat/smp-server:latest";
- ports = [ "127.0.0.1:${toString internalSmpPort}:5223" ];
-
- environment = {
- ADDR = "smp.${masterDomain}";
- CONFIG_DIR = "/etc/opt/simplex";
- };
-
- environmentFiles = [ config.sops.secrets."simplex/smp-env".path ];
-
- volumes = [
- "/var/lib/simplex/smp/config:/etc/opt/simplex:rw"
- "/var/lib/simplex/smp/logs:/var/opt/simplex:rw"
- "/var/lib/simplex/certs:/certificates:ro"
- ];
- };
-
- simplex-xftp = {
- image = "simplexchat/xftp-server:latest";
- ports = [ "127.0.0.1:${toString internalXftpPort}:443" ];
-
- environment = {
- ADDR = "xftp.${masterDomain}";
- QUOTA = "10gb";
- };
-
- environemntFiles = [ config.sops.secrets."simplex/xftp-env".path ];
- volumes = [
- "/var/lib/simplex/xftp/config:/etc/opt/simplex-xftp:rw"
- "/var/lib/simplex/xftp/logs:/var/opt/simplex-xftp:rw"
- "/var/lib/simplex/xftp/files:/srv/xftp:rw"
- ];
- };
- };
-
- systemd.tmpfiles.rules = [
- "d /var/lib/simplex/smp/config 0755 root root -"
- "d /var/lib/simplex/smp/logs 0755 root root -"
- "d /var/lib/simplex/rsa_certs 0755 root root -"
-
- "d /var/lib/simplex/xftp/config 0755 root root -"
- "d /var/lib/simplex/xftp/logs 0755 root root -"
- "d /var/lib/simplex/xftp/files 0755 root root -"
- ];
-
- networking.firewall.allowedTCPPorts = [
- 5223
- 5224
- ];
- }
-
- (lib.mkIf cfg.tor.enable {
- assertions = [
- {
- assertion = config.os.srv.tor.enable;
- message = "SimpleX Tor support requires os.srv.tor to be enabled.";
- }
- ];
-
- services.tor.relay.onionServices = {
- simplex-smp = {
- version = 3;
- map = [
- {
- port = 5223;
- target = {
- addr = "127.0.0.1";
- port = internalSmpPort;
- };
- }
- ];
- };
- simplex-xftp = {
- version = 3;
- map = [
- {
- port = 5224;
- target = {
- addr = "127.0.0.1";
- port = internalXftpPort;
- };
- }
- ];
- };
- };
- })
- ]
- );
-}
diff --git a/os/srv/sunshine.nix b/os/srv/sunshine.nix
deleted file mode 100644
index a347568..0000000
--- a/os/srv/sunshine.nix
+++ /dev/null
@@ -1,42 +0,0 @@
-{
- config,
- lib,
- pkgs,
- username,
- ...
-}:
-let
- cfgSunshine = config.os.srv.sunshine;
- cfgMoonlight = config.os.srv.moonlight;
-in
-{
- options.os.srv = {
- sunshine.enable = lib.mkEnableOption "enables sunshine streaming server";
- moonlight.enable = lib.mkEnableOption "enables moonlight streaming client";
- };
-
- config = lib.mkMerge [
- (lib.mkIf cfgSunshine.enable {
- services.sunshine = {
- enable = true;
- capSysAdmin = true;
- openFirewall = true;
- autoStart = false;
- };
-
- hardware.uinput.enable = true;
-
- users.users.${username}.extraGroups = [
- "video"
- "input"
- "render"
- ];
- })
-
- (lib.mkIf cfgMoonlight.enable {
- environment.systemPackages = [
- pkgs.moonlight-qt
- ];
- })
- ];
-}
diff --git a/os/srv/tailscale.nix b/os/srv/tailscale.nix
deleted file mode 100644
index 5c8d72e..0000000
--- a/os/srv/tailscale.nix
+++ /dev/null
@@ -1,19 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.tailscale;
-in
-{
- options.os.srv.tailscale.enable = lib.mkEnableOption "enables tailscale vpn";
-
- config = lib.mkIf cfg.enable {
- services.tailscale = {
- enable = true;
- openFirewall = true;
- useRoutingFeatures = "client";
- };
- networking.firewall = {
- trustedInterfaces = [ "tailscale0" ];
- checkReversePath = "loose";
- };
- };
-}
diff --git a/os/srv/ups.nix b/os/srv/ups.nix
deleted file mode 100644
index 260f346..0000000
--- a/os/srv/ups.nix
+++ /dev/null
@@ -1,35 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.ups;
-in
-{
- options.os.srv.ups.enable = lib.mkEnableOption "enables smooth shutdown on power loss";
- config = lib.mkIf cfg.enable {
- power.ups = {
- enable = true;
- mode = "standalone";
-
- ups.main = {
- driver = "usbhid-ups";
- port = "auto";
- description = "Main Server UPS";
- };
- users.upsmon = {
- # TODO make password
- passwordFile = "sops";
- upsmon = "master";
- };
- upsmon.monitor.main = {
- system = "main@localhost";
- user = "upsmon";
- # TODO password
- passwordFile = "sops";
- type = "master";
- };
- # settings = {
- # MINSUPPLIES = 1;
- # POWERDOWNFLAG = "/run/killpower";
- # };
- };
- };
-}
diff --git a/os/srv/uptime-kuma.nix b/os/srv/uptime-kuma.nix
deleted file mode 100644
index 7bf8dd0..0000000
--- a/os/srv/uptime-kuma.nix
+++ /dev/null
@@ -1,41 +0,0 @@
-{
- config,
- lib,
- masterDomain,
- securityTemplates,
- ...
-}:
-let
- cfg = config.os.srv.uptime-kuma;
-in
-{
- options.os.srv.uptime-kuma = {
- enable = lib.mkEnableOption "enables uptime-kuma";
- proxyConfig = lib.mkOption {
- type = lib.types.attrs;
- default = { };
- };
- };
- config = lib.mkIf cfg.enable {
- services.uptime-kuma = {
- enable = true;
- appriseSupport = true;
- settings = {
- HOST = "127.0.0.1";
- UPTIME_KUMA_DB_TYPE = "sqlite";
- };
- };
-
- os.srv.uptime-kuma.proxyConfig = {
- "uptime-kuma.${masterDomain}" = {
- enableACME = true;
- forceSSL = true;
-
- locations."/" = {
- proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3001";
- extraConfig = securityTemplates.restrictToInternal;
- };
- };
- };
- };
-}
diff --git a/os/srv/vector.nix b/os/srv/vector.nix
deleted file mode 100644
index a216a19..0000000
--- a/os/srv/vector.nix
+++ /dev/null
@@ -1,79 +0,0 @@
-{ config, lib, ... }:
-let
- cfg = config.os.srv.vector;
-in
-{
- options.os.srv.vector = {
- enable = lib.mkEnableOption "Vector observability data framework";
- agent.enable = lib.mkEnableOption "local client daemon to pull journals & stream upstream";
- aggregator.enable = lib.mkEnableOption "central receiver role to bundle, parse, and push to Loki";
- };
-
- config = lib.mkIf cfg.enable {
- services.vector = {
- enable = true;
- journaldAccess = lib.mkIf cfg.agent.enable true;
- validateConfig = true;
-
- settings = lib.mkMerge [
- (lib.mkIf cfg.agent.enable {
- sources.systemd_journal = {
- type = "journald";
- exclude_units = [ "vector.service" ];
- };
-
- transforms.filter_logs = {
- type = "filter";
- inputs = [ "systemd_journal" ];
- condition = ''.status != "debug" && .status != "trace"'';
- };
-
- sinks.to_aggregator = {
- type = "vector";
- inputs = [ "filter_logs" ];
- address = "${config.os.core.network.ips.vm3-monitor}:9000";
- };
- })
-
- (lib.mkIf cfg.aggregator.enable {
- sources.upstream_agents = {
- type = "vector";
- address = "0.0.0.0:9000";
- version = "2";
- };
-
- sources.opnsense_syslog = {
- type = "syslog";
- address = "${cfg.aggregator.listenAddress}:5140";
- mode = "udp";
- };
-
- sinks.loki_backend = {
- type = "loki";
- inputs = [
- "upstream_agents"
- "opnsense_syslog"
- ];
- endpoint = "http://127.0.0.1:3100";
- labels = {
- host = "{{ host }}";
- unit = "{{`{{_SYSTEMD_UNIT}}`}}";
- source_type = "{{ type }}";
- };
- buffer = {
- type = "disk";
- max_size = 5 * (1024 * 1024 * 1024);
- when_full = "block";
- };
- };
- encoding.codec = "json";
- })
- ];
- };
-
- networking.firewall = lib.mkIf cfg.aggregator.enable {
- allowedTCPPorts = [ 9000 ];
- allowedUDPPorts = [ 5140 ];
- };
- };
-}
diff --git a/os/srv/wireguard.nix b/os/srv/wireguard.nix
deleted file mode 100644
index c758174..0000000
--- a/os/srv/wireguard.nix
+++ /dev/null
@@ -1,152 +0,0 @@
-{
- config,
- lib,
- hostname,
- masterDomain,
- ...
-}:
-let
- cfg = config.os.srv.wireguard;
-in
-{
- options.os.srv.wireguard = {
- enable = lib.mkEnableOption "enables wireguard vpn";
-
- role = lib.mkOption {
- type = lib.types.enum [
- "server"
- "client"
- ];
- default = "client";
- description = "where the machine is accepting connections or connecting";
- };
-
- server = {
- externalInterface = lib.mkOption {
- type = lib.types.str;
- default = "eth0";
- description = "The public WAN interface of the server";
- };
- publicKey = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- description = "The public key of your primary WireGuard server node.";
- };
-
- peers = lib.mkOption {
- type = lib.types.listOf (
- lib.types.submodule {
- options = {
- name = lib.mkOption { type = lib.types.str; };
- publicKey = lib.mkOption { type = lib.types.str; };
- };
- }
- );
- default = [ ];
- description = "List of client peers authorized to connect to this server";
- };
- };
-
- client = {
- index = lib.mkOption {
- type = lib.types.nullOr lib.types.int;
- default = null;
- description = "The assigned host index number for the client IP address";
- };
-
- routeAllTraffic = lib.mkOption {
- type = lib.types.bool;
- default = false;
- description = "Routes 100% of your internet traffic through the server when active";
- };
- };
- };
-
- config = lib.mkIf cfg.enable (
- lib.mkMerge [
- {
- assertions = [
- {
- assertion = config.os.srv.sops.enable;
- message = "required for wg private key";
- }
- ];
-
- sops.secrets."wg_private_key/${hostname}" = {
- owner = "root";
- group = "root";
- mode = "0600";
- };
- }
-
- (lib.mkIf (cfg.role == "server") {
- assertions = [
- {
- assertion = config.os.srv.firewall.enable;
- message = "required for opening ports and passthrough";
- }
- ];
- boot.kernel.sysctl."net.ipv4.ip_forward" = 1;
- networking.firewall.allowedUDPPorts = [ 51280 ];
-
- networking.nftables = {
- tables.wg-nat = {
- family = "inet";
- content = ''
- chain forward {
- type filter hook forward priority 0; policy accept;
- iifname "wg0" accept
- oifname "wg0" accept
- }
- chain postrouting {
- type nat hook postrouting priority 100; policy accept;
- oifname "${cfg.server.externalInterface}" masquerade
- }
- '';
- };
- };
-
- networking.wireguard.interfaces.wg0 = {
- ips = [ "10.3.0.1/24" ];
- listenPort = 51280;
- privateKeyFile = config.sops.secrets."wg_private_key/${hostname}".path;
-
- peers = lib.imap1 (i: peer: {
- publicKey = peer.publicKey;
- allowedIPs = [ "10.3.0.${toString (i + 1)}/32" ];
- persistentKeepalive = 25;
- }) cfg.server.peers;
- };
- })
-
- (lib.mkIf (cfg.role == "client") {
- assertions = [
- {
- assertion = cfg.client.index != null;
- message = "WireGuard client role requires a valid 'client.index' integer designation.";
- }
- ];
-
- networking.nameservers = [
- config.os.core.network.ips.vm2-gateway
- "9.9.9.9"
- ];
-
- networking.wireguard.interfaces.wg0 = {
- ips = [ "10.3.0.${toString cfg.client.index + 1}/24" ];
- privateKeyFile = config.sops.secrets."wg_private_key/${hostname}".path;
-
- peers = [
- {
- publicKey = cfg.server.publicKey;
- endpoint = "${masterDomain}:51280";
- persistentKeepalive = 25;
-
- allowedIPs = if cfg.client.routeAllTraffic then [ "0.0.0.0/0" ] else [ "10.255.0.0/16" ];
- }
- ];
- };
- })
- ]
- );
-}
diff --git a/os/srv/yggdrasil.nix b/os/srv/yggdrasil.nix
deleted file mode 100644
index 6fe91af..0000000
--- a/os/srv/yggdrasil.nix
+++ /dev/null
@@ -1,44 +0,0 @@
-{
- config,
- lib,
- ...
-}:
-let
- cfg = config.os.srv.yggdrasil;
-in
-{
- options.os.srv.yggdrasil.enable = lib.mkEnableOption "enables yggdrasil";
-
- config = lib.mkIf cfg.enable {
- services = {
- yggdrasil = {
- enable = true;
- openMulticastPort = true;
-
- settings = {
- # PrivateKeyPath = config.sops.secrets."yggdrasil-private-key".path;
- IfName = "ygg0";
- NodeInfoPrivacy = true;
- Peers = [
- "tcp://ip6.fvm.mywire.org:8080?key=000000000143db657d1d6f80b5066dd109a4cb31f7dc6cb5d56050fffb014217"
- "tcp://ygg1.mk16.de:1337?key=0000000087ee9949eeab56bd430ee8f324cad55abf3993ed9b9be63ce693e18a"
- "tcp://62.210.85.80:39565"
-
- "tls://ygg1.mk16.de:1338?key=0000000087ee9949eeab56bd430ee8f324cad55abf3993ed9b9be63ce693e18a"
- "tls://103.109.234.106:443?key=000000035621c71b5610434589df051aed2688510f904ae79860668dc0fbf182"
- "tls://s2.i2pd.xyz:39575"
-
- "quic://ygg1.mk16.de:1339?key=0000000087ee9949eeab56bd430ee8f324cad55abf3993ed9b9be63ce693e18a"
- "quic://ygg6.mk16.de:1339?key=0000005e5ced06fd4d465bc651c5deb6d70cbe82d36efb68c0450268eaaa5384"
- "quic://[2a0b:4142:e9e::2]:65535"
- ];
- Listen = [
- "tls://0.0.0.0:0"
- "tcp://[::]:9001"
- ];
- };
- };
- yggdrasil-jumper.enable = true;
- };
- };
-}
diff --git a/os/vms/microvms.nix b/os/vms/microvms.nix
deleted file mode 100644
index e2e1a0f..0000000
--- a/os/vms/microvms.nix
+++ /dev/null
@@ -1,37 +0,0 @@
-{
- config,
- lib,
- inputs,
- ...
-}:
-let
- cfg = config.os.vms;
- sharedSecrets = [
- {
- tag = "shared-secrets";
- proto = "virtiofs";
- source = "/etc/nixos/secrets";
- mountPoint = "/etc/nixos/secrets";
- }
- ];
-in
-{
- imports = [ inputs.microvm.nixosModules.host ];
-
- options.os.vms = {
- net-core.enable = lib.mkEnableOption "enables the net-core virtual machine";
- };
-
- config = lib.mkMerge [
- (lib.mkIf cfg.net-core.enable {
- microvm.vms.net-core = {
- autostart = true;
- config = {
- imports = [ ../vms/net-core.nix ];
- microvm.shares = sharedSecrets;
- };
- };
- })
-
- ];
-}
diff --git a/os/vms/net-core.nix b/os/vms/net-core.nix
deleted file mode 100644
index a9a1c47..0000000
--- a/os/vms/net-core.nix
+++ /dev/null
@@ -1,30 +0,0 @@
-{ pkgs, inputs, ... }:
-{
- system.stateVersion = "26.11";
-
- imports = [
- inputs.microvm.nixosModules.microvm
- ../core/default.nix
- ];
-
- os = {
- core = {
- allowUnfree.enable = true;
- locale.enable = true;
- };
- srv = {
- ssh = {
- server = {
- enable = true;
- microvm = true;
- };
- };
- firewall.enable = true;
- sops.enable = true;
- };
- };
-
- networking.hostName = "net-core";
-
- environment.systemPackages = [ pkgs.vis ];
-}
diff --git a/os/vms/opnsense.nix b/os/vms/opnsense.nix
deleted file mode 100644
index b9f2978..0000000
--- a/os/vms/opnsense.nix
+++ /dev/null
@@ -1,95 +0,0 @@
-{
- config,
- lib,
- inputs,
- ...
-}:
-let
- cfg = config.os.srv.opnsense;
- makePciArgs =
- ids:
- builtins.concatLists (
- map (id: [
- "-device"
- "vfio-pci,host=${id},rombar=0"
- ]) ids
- );
-in
-{
- imports = [ inputs.microvm.nixosModules.host ];
-
- options.os.srv.opnsense = {
- enable = lib.mkEnableOption "enables an opnsense microvm";
-
- pciIDs = lib.mkOption {
- type = lib.types.listOf lib.types.str;
- default = [ ];
- example = [
- "03:00.0"
- "03:00.1"
- ];
- description = "List of PCI bus addresses to pass through directly to OPNsense.";
- };
-
- vendorIDs = lib.mkOption {
- type = lib.types.listOf lib.types.str;
- default = [ ];
- example = [ "8086:1563" ];
- description = "List of Vendor:Device IDs to bind explicitly to the vfio-pci driver.";
- };
-
- imagePath = lib.mkOption {
- type = lib.types.path;
- default = /var/lib/microvm/images/opnsense.qcow2;
- description = "Path to the OPNsense qcow2 drive image block.";
- };
- };
-
- config = lib.mkIf cfg.enable {
- boot = {
- kernelParams = [
- "intel_iommu=on"
- "iommu=pt"
- ];
- kernelModules = [
- "vfio_pci"
- "vfio"
- "vfio_iommu_type1"
- ];
- extraModprobeConfig = ''
- options vfio-pci ids=${lib.concatStringsSep "," (lib.unique cfg.vendorIDs)}
- '';
- };
-
- microvm.vms.opnsense = {
- autostart = true;
- config = {
- imports = [ inputs.microvm.nixosModules.microvm ];
-
- networking.hostName = "opnsense";
-
- microvm = {
- vcpu = 4;
- mem = 4096;
- hypervisor = "qemu";
-
- interfaces = [
- {
- type = "bridge";
- id = "vtnet0";
- bridge = "br-srv";
- }
- ];
-
- qemu.extraArgs = [
- "-machine"
- "q35,accel=kvm,kernel-irqchip=on"
- "-cpu"
- "host,migratable=off,+invtsc"
- ]
- ++ (makePciArgs cfg.pciIDs);
- };
- };
- };
- };
-}
diff --git a/os/wm/default.nix b/os/wm/default.nix
deleted file mode 100644
index a470171..0000000
--- a/os/wm/default.nix
+++ /dev/null
@@ -1,37 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}:
-let
- cfg = config.os.wm;
-in
-{
- imports = [ ./niri.nix ];
-
- options.os.wm.enable = lib.mkEnableOption "enables shared wm features";
-
- config = lib.mkIf cfg.enable {
- services.dbus.enable = true;
-
- xdg.portal = {
- enable = true;
- xdgOpenUsePortal = true;
-
- extraPortals = [
- pkgs.xdg-desktop-portal-gnome
- pkgs.xdg-desktop-portal-gtk
- ];
-
- config = {
- common.default = [ "gtk" ];
- niri = {
- "org.freedesktop.impl.portal.ScreenCast" = [ "gnome" ];
- "org.freedesktop.impl.portal.Screenshot" = [ "gnome" ];
- "default" = [ "gtk" ];
- };
- };
- };
- };
-}