diff options
| -rw-r--r-- | flake.lock | 66 | ||||
| -rw-r--r-- | flake.nix | 4 | ||||
| -rw-r--r-- | hm/soft/nixvim/nixvim.nix | 4 | ||||
| -rw-r--r-- | hosts/bibus-lab/configuration.nix | 5 | ||||
| -rw-r--r-- | hosts/thinkpad/configuration.nix | 1 | ||||
| -rw-r--r-- | hosts/thinkpad/home.nix | 1 | ||||
| -rw-r--r-- | os/core/networking.nix | 19 | ||||
| -rw-r--r-- | os/srv/dns.nix | 36 | ||||
| -rw-r--r-- | os/srv/monero.nix | 36 | ||||
| -rw-r--r-- | os/srv/nginx.nix | 18 |
10 files changed, 121 insertions, 69 deletions
@@ -306,11 +306,11 @@ ] }, "locked": { - "lastModified": 1779043781, - "narHash": "sha256-7YoRc6jOuQUI0yv3qBHFhc60G/RG0LwVsKkN90UkPn4=", + "lastModified": 1781478132, + "narHash": "sha256-XGKD/DId5Eont4ytPV7LfGvykDRalMWx4pbkRVUNzxY=", "owner": "Mjoyufull", "repo": "fsel", - "rev": "6b6ae52e3a2c254007e8a2c332a8d5de99428ba5", + "rev": "8a12d4f35e78297f3e2d55e026185710bff38338", "type": "github" }, "original": { @@ -374,11 +374,11 @@ ] }, "locked": { - "lastModified": 1781189114, - "narHash": "sha256-5inaamLgUMWy+MOBE9ChF9QAF1o/74LFuHkI0W/9rqc=", + "lastModified": 1781497404, + "narHash": "sha256-9GAF8sSsnkyCVCWkomXR0T+zdSxyUlfPt6neQidimdg=", "owner": "nix-community", "repo": "home-manager", - "rev": "486595d2cf49cfcd649b58a284fa11ac0e34da22", + "rev": "1285cd3d6882a9847f2d56ed5541b3350c8a6162", "type": "github" }, "original": { @@ -417,11 +417,11 @@ "spectrum": "spectrum" }, "locked": { - "lastModified": 1780588968, - "narHash": "sha256-zQk+GqLO+T9taIl1UUt3swvaOksWJxL7PL8K0+Fc/Hs=", + "lastModified": 1781389237, + "narHash": "sha256-Ne1/E5XNUq0gleaQz0vW5R4xf/0h/uEZ+bOW1aNjeQk=", "owner": "microvm-nix", "repo": "microvm.nix", - "rev": "4d3fb17437944ea57eef2b9e6108ca777b1209ca", + "rev": "6ad601df0a07d9855c5e8f9b81135ecaf7c287eb", "type": "github" }, "original": { @@ -514,11 +514,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1781038035, - "narHash": "sha256-X+uFuOQVWiouzl7eSV5JUgg4CAbv779QgEqOxIo6Gls=", + "lastModified": 1781234038, + "narHash": "sha256-jo4a47qDgsx1F1i0MtHZl12FfzqKJOES25vbm0ZUxeI=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "27982962e1dee4994b05d2b0b4a29f8de2529a55", + "rev": "eb5789cba8d37802d330df5a13c691622c83121f", "type": "github" }, "original": { @@ -589,11 +589,11 @@ ] }, "locked": { - "lastModified": 1781101699, - "narHash": "sha256-5erzbe5hgJufkqBr3KCYElX4nW+xfJJrFDOvweWZR3w=", + "lastModified": 1781301671, + "narHash": "sha256-rq6WOopxq3U2AGEWO80o9LIJDYcYIdgw6jyl+y+19w8=", "owner": "simple-nixos-mailserver", "repo": "nixos-mailserver", - "rev": "d59fcaeef8144328b8801f987f1a3af7ca6aec41", + "rev": "661ec59a97ccee13a63f79280b282eb6f7d3f817", "type": "gitlab" }, "original": { @@ -681,11 +681,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1780749050, - "narHash": "sha256-3av0pIjlOWQ6rDbNOmpUSvbNnJkGORQKKjb4LtCZsIY=", + "lastModified": 1781074563, + "narHash": "sha256-md8WlXOlfnIeHeOScMTTHFyf2d6iaTwPl2apR5EQ3P4=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "a799d3e3886da994fa307f817a6bc705ae538eeb", + "rev": "9ae611a455b90cf061d8f332b977e387bda8e1ca", "type": "github" }, "original": { @@ -734,11 +734,11 @@ "systems": "systems_2" }, "locked": { - "lastModified": 1781034432, - "narHash": "sha256-+UuS36un3lXLtKsGCYQnOn51hDhB+dZ1SHoHXClnV/0=", + "lastModified": 1781496494, + "narHash": "sha256-SfOg25O4vI7jVl4hwxiLAgsa0oiu2K1SPoDtRT3ECNc=", "owner": "nix-community", "repo": "nixvim", - "rev": "e9fbbd56eab78751ba4c166c31a1667042528ced", + "rev": "586286af54a314a24566811ce44eb9f380696e6e", "type": "github" }, "original": { @@ -759,11 +759,11 @@ "systems": "systems_3" }, "locked": { - "lastModified": 1781204315, - "narHash": "sha256-0mEWVih7Aq2tdyZwHL91tZMsIitFIocGMvtfaenOSPc=", + "lastModified": 1781468924, + "narHash": "sha256-lohnpykCw/3ABFIyMw3SjKQe+Je3iiH/ZHAl/HOS00s=", "owner": "NotAShelf", "repo": "nvf", - "rev": "5727a5b9a76f6540d93a26cfc96c6ec2b47fa4f3", + "rev": "d55e51c3f75b94f49445a9efb73aab722df1cf4d", "type": "github" }, "original": { @@ -945,11 +945,11 @@ "rust-overlay": "rust-overlay" }, "locked": { - "lastModified": 1781157699, - "narHash": "sha256-3wCm5AnfEOqEvx1acTB5j4Wn5+8lDQ6nWAz6r/Er2ag=", + "lastModified": 1781448218, + "narHash": "sha256-fpJcWeYy15/p1Ku22H8DbOUYQVmnYBFOMA4sgul2j88=", "owner": "gabm", "repo": "Satty", - "rev": "9dde65caaf515636a9cdcf5abece0413de465605", + "rev": "7f6e489da286519a59b37fcd110680a62f7b2aa8", "type": "github" }, "original": { @@ -1169,11 +1169,11 @@ "xwayland-satellite-unstable": { "flake": false, "locked": { - "lastModified": 1779745227, - "narHash": "sha256-yqY7RtEJGJiENzR0GwL6q69tSAy6xAAmAcLuIhLjPf8=", + "lastModified": 1781226823, + "narHash": "sha256-28696iIw8uE0ZUyFTtzhEM8xMh85clCYypMxkvUi+sc=", "owner": "Supreeeme", "repo": "xwayland-satellite", - "rev": "5d1efbc9dc3ab1c10160b656e0247f3325daf0f2", + "rev": "8575d0ef55d70f9b4c46b6bffb3accf912217e1e", "type": "github" }, "original": { @@ -1191,11 +1191,11 @@ "rust-overlay": "rust-overlay_2" }, "locked": { - "lastModified": 1781181862, - "narHash": "sha256-EBeyydl9ekGp/98VyF4ciFS3zNkspWhJiTG/+UWyHQ4=", + "lastModified": 1781438303, + "narHash": "sha256-cBw2N3U0hoZO33s24Z/022AthIJtTnZk1jwgnxObfBY=", "owner": "sxyazi", "repo": "yazi", - "rev": "9b920ed2e3ebc126cf8ba3e51acfc5be8b8cbf56", + "rev": "f1e93d7f528b22fdeaf66b198c73e32a7040a90c", "type": "github" }, "original": { @@ -3,13 +3,13 @@ inputs = { nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; - nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-25.11"; + nixpkgs-stable.url = "github:NixOS/nixpkgs/nixos-26.11"; # Hardware and gaming nixos-hardware.url = "github:NixOS/nixos-hardware/master"; nixos-mailserver = { - url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.05"; + url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.11"; inputs.nixpkgs.follows = "nixpkgs"; }; diff --git a/hm/soft/nixvim/nixvim.nix b/hm/soft/nixvim/nixvim.nix index 7013c27..6f689b3 100644 --- a/hm/soft/nixvim/nixvim.nix +++ b/hm/soft/nixvim/nixvim.nix @@ -14,7 +14,7 @@ in config = lib.mkIf cfg.enable { programs.nixvim = { - diagnostics.virtual_text = false; + # diagnostics.virtual_text = false; enable = true; vimAlias = true; @@ -179,7 +179,7 @@ in neoscroll.enable = true; bufferline.enable = true; web-devicons.enable = true; - lsp-kind.enable = true; + # lsp-kind.enable = true; blink-cmp = { enable = true; diff --git a/hosts/bibus-lab/configuration.nix b/hosts/bibus-lab/configuration.nix index 13e1a3b..bace2f6 100644 --- a/hosts/bibus-lab/configuration.nix +++ b/hosts/bibus-lab/configuration.nix @@ -1,6 +1,6 @@ -{ inputs, username, ... }: +{ inputs, ... }: { - system.stateVersion = "26.05"; + system.stateVersion = "26.11"; imports = [ inputs.disko.nixosModules.disko @@ -10,5 +10,4 @@ ]; hardware.facter.reportPath = ./facter.json; - } diff --git a/hosts/thinkpad/configuration.nix b/hosts/thinkpad/configuration.nix index fd8e727..6f3e85a 100644 --- a/hosts/thinkpad/configuration.nix +++ b/hosts/thinkpad/configuration.nix @@ -80,7 +80,6 @@ }; moonlight.enable = true; virtualization.kvm.enable = true; - kdeconnect.enable = true; nix-helper.enable = true; monero.wallet.enable = true; sops.enable = true; diff --git a/hosts/thinkpad/home.nix b/hosts/thinkpad/home.nix index 26cb32e..f0b3ecc 100644 --- a/hosts/thinkpad/home.nix +++ b/hosts/thinkpad/home.nix @@ -55,7 +55,6 @@ chat.enable = true; onlyoffice.enable = true; obsidian.enable = true; - spicetify.enable = true; torrent.enable = true; yt-dlp.enable = true; }; diff --git a/os/core/networking.nix b/os/core/networking.nix index d50d899..6cfe4ad 100644 --- a/os/core/networking.nix +++ b/os/core/networking.nix @@ -11,6 +11,25 @@ in options.os.core.network = { enable = lib.mkEnableOption "system-wide networking setup"; + ips = lib.mkOption { + type = lib.types.attrsOf lib.types.str; + default = { + router = "10.0.0.1"; + host = "10.0.0.2"; + vm1-opnsense = "10.0.0.3"; + vm2-gateway = "10.0.0.4"; + vm3-monitor = "10.0.0.5"; + vm4-media = "10.0.0.6"; + vm5-sandbox = "10.0.0.7"; + vm6-storage = "10.0.0.8"; + vm7-web = "10.0.0.9"; + vm8-mail = "10.0.0.10"; + vm9-relays = "10.0.0.11"; + vm10-mc = "10.0.0.12"; + }; + description = "Central registry of static IP allocations for the cluster."; + }; + profile = lib.mkOption { type = lib.types.enum [ "client" diff --git a/os/srv/dns.nix b/os/srv/dns.nix index f0c50a6..2da4c66 100644 --- a/os/srv/dns.nix +++ b/os/srv/dns.nix @@ -1,10 +1,22 @@ -{ config, lib, ... }: +{ + config, + lib, + masterDomain, + securityTemplates, + ... +}: let cfg = config.os.srv.dns; unboundPort = 5335; in { - options.os.srv.dns.enable = lib.mkEnableOption "enables dns scanning"; + options.os.srv.dns = { + enable = lib.mkEnableOption "enables dns scanning"; + adguardProxyConfig = lib.mkOption { + type = lib.types.attrs; + default = { }; + }; + }; config = lib.mkIf cfg.enable { services.unbound = { enable = true; @@ -63,11 +75,17 @@ in config.os.core.network.wg.ip config.os.core.network.hs.ip ]; + rewrites = [ + { + domain = "router.local"; + answer = config.os.core.network.ips.vm1-opnsense; + } + ]; port = 53; upstream_dns = [ "127.0.0.1:${toString unboundPort}" ]; bootstrap_dns = [ "9.9.9.9" ]; cache_size = 536870912; - # anonymize_client_ip = true; + anonymize_client_ip = true; }; filtering = { @@ -239,6 +257,18 @@ in }; }; + os.srv.dns.adguardProxyConfig = { + "adguard.${masterDomain}" = { + enableACME = true; + forceSSL = true; + + locations."/" = { + proxyPass = "http://${config.os.core.network.ips.vm2-gateway}:3000"; + extraConfig = securityTemplates.restrictToInternal; + }; + }; + }; + networking.firewall = { allowedUDPPorts = [ 53 ]; allowedTCPPorts = [ 53 ]; diff --git a/os/srv/monero.nix b/os/srv/monero.nix index 4e74432..f00413d 100644 --- a/os/srv/monero.nix +++ b/os/srv/monero.nix @@ -12,7 +12,13 @@ in { options.os.srv.monero = { wallet.enable = lib.mkEnableOption "enables the monero wallet"; - service.enable = lib.mkEnableOption "enables hosting a monero node"; + service = { + enable = lib.mkEnableOption "enables hosting a monero node"; + proxyConfig = lib.mkOption { + type = lib.types.attrs; + default = { }; + }; + }; }; config = lib.mkMerge [ @@ -22,10 +28,6 @@ in (lib.mkIf cfg.service.enable { assertions = [ { - assertion = config.os.srv.nginx.enable; - message = "Hosting a Monero node requires nginx for proxying"; - } - { assertion = config.os.srv.sops.enable; message = "Required for password secure password storing"; } @@ -55,19 +57,21 @@ in }; }; - services.nginx.virtualHosts."xmr.${masterDomain}" = { - enableACME = true; - forceSSL = true; + os.srv.monero.service.proxyConfig = { + "xmr.${masterDomain}" = { + enableACME = true; + forceSSL = true; - locations."/" = { - proxyPass = "http://127.0.0.1:18081"; - extraConfig = '' - proxy_read_timeout 600s; - proxy_send_timeout 600s; - client_max_body_size 50m; + locations."/" = { + proxyPass = "http://${config.os.core.network.ips.vm9-relays}:18081"; + extraConfig = '' + proxy_read_timeout 600s; + proxy_send_timeout 600s; + client_max_body_size 50m; - ${securityTemplates.restrictToInternal} - ''; + ${securityTemplates.restrictToInternal} + ''; + }; }; }; diff --git a/os/srv/nginx.nix b/os/srv/nginx.nix index 6159e25..a38b703 100644 --- a/os/srv/nginx.nix +++ b/os/srv/nginx.nix @@ -42,14 +42,16 @@ in recommendedTlsSettings = true; recommendedOptimisation = true; recommendedGzipSettings = true; - virtualHosts = { - default = { - serverName = "_"; - default = true; - rejectSSL = true; - locations."/".return = "444"; - }; - }; + virtualHosts = lib.mkMerge [ + { + "_" = { + default = true; + rejectSSL = true; + locations."/".return = "444"; + }; + } + config.os.srv.monero.proxyConfig + ]; }; security.acme = { |
