From 11d05469368ecfe533c7720e7f5b624f2f8f19fc Mon Sep 17 00:00:00 2001 From: adikro Date: Sat, 7 Mar 2026 22:27:05 +0100 Subject: ... --- .sops.yaml | 12 --- flake.lock | 157 ++++++++++++++------------------------- flake.nix | 17 +---- hm/conf/xdg-dirs.nix | 14 +--- hm/env/niri/binds.nix | 58 ++++++++++----- hm/env/niri/niri.nix | 63 ++++++++++++++-- hm/soft/media.nix | 45 +---------- hm/soft/nixcord.nix | 2 +- hm/soft/obsidian.nix | 2 +- hm/soft/sioyek.nix | 18 +++++ hm/soft/soft.nix | 2 +- hm/soft/vpn.nix | 20 ----- hosts/desktop/configuration.nix | 13 +++- hosts/desktop/home.nix | 2 +- hosts/thinkpad/configuration.nix | 26 +++++-- hosts/thinkpad/disko.nix | 1 - hosts/thinkpad/home.nix | 1 + os/core/audio.nix | 21 +----- os/core/bootloader.nix | 36 --------- os/core/networking.nix | 12 ++- os/core/security.nix | 18 ++--- os/core/ssh.nix | 6 -- os/srv/i2p.nix | 32 ++++++++ os/srv/ollama.nix | 15 ++-- os/srv/sops.nix | 15 ++-- os/srv/srv.nix | 2 + os/srv/syncthing.nix | 47 +++++++----- os/srv/vpn.nix | 49 ++++++++++++ secrets/common.yaml | 13 +++- secrets/oci.yaml | 57 -------------- 30 files changed, 360 insertions(+), 416 deletions(-) create mode 100644 hm/soft/sioyek.nix delete mode 100644 hm/soft/vpn.nix create mode 100644 os/srv/i2p.nix create mode 100644 os/srv/vpn.nix delete mode 100644 secrets/oci.yaml diff --git a/.sops.yaml b/.sops.yaml index fcce3e5..e7cce03 100644 --- a/.sops.yaml +++ b/.sops.yaml @@ -4,7 +4,6 @@ keys: - &host_thinkpad - &host_pendrive age1sx8ut0arwlrp7n7qvlaele8mq93pyvzc0ddetlk47cnyx935gcusdceq9q - &host_laptop age1m4u7n6mt5d3jv39lf4aedr9gqu3khl4sahuqx5n5h7v48gkyc9zqkp9qs8 - - &host_oci creation_rules: - path_regex: .*secrets/common\.yaml$ @@ -16,14 +15,3 @@ creation_rules: - *host_laptop pgp: - *admin_gpg - - - path_regex: .*secrets/oci\.yaml$ - key_groups: - - age: - - *host_szpont - - *host_thinkpad - - *host_pendrive - - *host_laptop - - *host_oci - pgp: - - *admin_gpg diff --git a/flake.lock b/flake.lock index dd7651c..58d69fe 100644 --- a/flake.lock +++ b/flake.lock @@ -59,11 +59,11 @@ ] }, "locked": { - "lastModified": 1769996383, - "narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=", + "lastModified": 1772408722, + "narHash": "sha256-rHuJtdcOjK7rAHpHphUb1iCvgkU3GpfvicLMwwnfMT0=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "57928607ea566b5db3ad13af0e57e921e6b12381", + "rev": "f20dc5d9b8027381c474144ecabc9034d6a839a3", "type": "github" }, "original": { @@ -77,11 +77,11 @@ "nixpkgs-lib": "nixpkgs-lib" }, "locked": { - "lastModified": 1769996383, - "narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=", + "lastModified": 1772408722, + "narHash": "sha256-rHuJtdcOjK7rAHpHphUb1iCvgkU3GpfvicLMwwnfMT0=", "owner": "hercules-ci", "repo": "flake-parts", - "rev": "57928607ea566b5db3ad13af0e57e921e6b12381", + "rev": "f20dc5d9b8027381c474144ecabc9034d6a839a3", "type": "github" }, "original": { @@ -111,27 +111,6 @@ "type": "github" } }, - "flake-parts_4": { - "inputs": { - "nixpkgs-lib": [ - "nur", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1733312601, - "narHash": "sha256-4pDvzqnegAfRkPwO3wmwBhVi/Sye1mzps0zHWYnP88c=", - "owner": "hercules-ci", - "repo": "flake-parts", - "rev": "205b12d8b7cd4802fbcb8e8ef6a0f1408781a4f9", - "type": "github" - }, - "original": { - "owner": "hercules-ci", - "repo": "flake-parts", - "type": "github" - } - }, "flake-utils": { "inputs": { "systems": "systems_3" @@ -157,11 +136,11 @@ ] }, "locked": { - "lastModified": 1772380461, - "narHash": "sha256-O3ukj3Bb3V0Tiy/4LUfLlBpWypJ9P0JeUgsKl2nmZZY=", + "lastModified": 1772845525, + "narHash": "sha256-Dp5Ir2u4jJDGCgeMRviHvEQDe+U37hMxp6RSNOoMMPc=", "owner": "nix-community", "repo": "home-manager", - "rev": "f140aa04d7d14f8a50ab27f3691b5766b17ae961", + "rev": "27b93804fbef1544cb07718d3f0a451f4c4cd6c0", "type": "github" }, "original": { @@ -196,11 +175,11 @@ ] }, "locked": { - "lastModified": 1772323514, - "narHash": "sha256-aWy20stlI6cl+UM1Ds8j4NSEfWTCp/VWW+SqQy+DOM8=", + "lastModified": 1772842024, + "narHash": "sha256-rP+FjAOPqvAJO+hhVSEP3lxkrP6txFgM5O9QOo9Xekc=", "owner": "nix-community", "repo": "neovim-nightly-overlay", - "rev": "744c005b53bd588a82b3662f82c791eecf4710ad", + "rev": "fb3e5603c475739c421d3e941c608bc20986ef18", "type": "github" }, "original": { @@ -212,11 +191,11 @@ "neovim-src": { "flake": false, "locked": { - "lastModified": 1772319592, - "narHash": "sha256-Bp+pAkfjSdUWV/giJFT9Gbp0wecQ+H4Kbh4+XfyOj5s=", + "lastModified": 1772822087, + "narHash": "sha256-uaecQjyj20yqMHcNNAnJzTsgi3rjDfx2mh9bD9TNPks=", "owner": "neovim", "repo": "neovim", - "rev": "8a79e3398a347248f067abe0c09097416fbf9cae", + "rev": "34a59e30dbe23bab59bc6b39a4b235c5b2862e60", "type": "github" }, "original": { @@ -237,11 +216,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1772320432, - "narHash": "sha256-d6Wm7/+6iNtgdcp6mxayEBhjWisi1aj84Ob7VyEAW9Y=", + "lastModified": 1772884214, + "narHash": "sha256-nl1U1E9Kk9ZmxWdqcwBuFaljxknbrwq8/bY+utQSajk=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "557374f9cd3649ab27b2621ae8117bec59969645", + "rev": "3fc5b3670ef77356173ca5f1fa5015e01204bc33", "type": "github" }, "original": { @@ -270,11 +249,11 @@ "niri-unstable": { "flake": false, "locked": { - "lastModified": 1772207631, - "narHash": "sha256-Jkkg+KqshFO3CbTszVVpkKN2AOObYz+wMsM3ONo1z5g=", + "lastModified": 1772873827, + "narHash": "sha256-T1igKylw0ZX8+yws4dWbkrSc+hZ1bmsM+Tjs4lxMYgo=", "owner": "YaLTeR", "repo": "niri", - "rev": "e708f546153f74acf33eb183b3b2992587a701e5", + "rev": "8f75d171b6017ed34043b1255ec4ffc374bf6ab0", "type": "github" }, "original": { @@ -292,11 +271,11 @@ ] }, "locked": { - "lastModified": 1772266502, - "narHash": "sha256-HBO3W1ooO9UwmxwwwFflnbCrAVHhaxpB8YnxFGPvOsY=", + "lastModified": 1772891434, + "narHash": "sha256-+MUN+5lOvWS6T4pvIZBGL4AKJkflLXGgVRYTlNeZEiE=", "owner": "KaylorBen", "repo": "nixcord", - "rev": "e805e50f0cc8b9f2d950dc81cd9ee1c986899eaf", + "rev": "fc63af2dbc92cdcfeb6c650d986280057b0f135c", "type": "github" }, "original": { @@ -323,11 +302,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1772198003, - "narHash": "sha256-I45esRSssFtJ8p/gLHUZ1OUaaTaVLluNkABkk6arQwE=", + "lastModified": 1772773019, + "narHash": "sha256-E1bxHxNKfDoQUuvriG71+f+s/NT0qWkImXsYZNFFfCs=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "dd9b079222d43e1943b6ebd802f04fd959dc8e61", + "rev": "aca4d95fce4914b3892661bcb80b8087293536c6", "type": "github" }, "original": { @@ -339,11 +318,11 @@ }, "nixpkgs-lib": { "locked": { - "lastModified": 1769909678, - "narHash": "sha256-cBEymOf4/o3FD5AZnzC3J9hLbiZ+QDT/KDuyHXVJOpM=", + "lastModified": 1772328832, + "narHash": "sha256-e+/T/pmEkLP6BHhYjx6GmwP5ivonQQn0bJdH9YrRB+Q=", "owner": "nix-community", "repo": "nixpkgs.lib", - "rev": "72716169fe93074c333e8d0173151350670b824c", + "rev": "c185c7a5e5dd8f9add5b2f8ebeff00888b070742", "type": "github" }, "original": { @@ -354,11 +333,11 @@ }, "nixpkgs-stable": { "locked": { - "lastModified": 1772047000, - "narHash": "sha256-7DaQVv4R97cii/Qdfy4tmDZMB2xxtyIvNGSwXBBhSmo=", + "lastModified": 1772822230, + "narHash": "sha256-yf3iYLGbGVlIthlQIk5/4/EQDZNNEmuqKZkQssMljuw=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "1267bb4920d0fc06ea916734c11b0bf004bbe17e", + "rev": "71caefce12ba78d84fe618cf61644dce01cf3a96", "type": "github" }, "original": { @@ -393,11 +372,11 @@ "systems": "systems" }, "locked": { - "lastModified": 1771135771, - "narHash": "sha256-wyvBIhDuyCRyjB3yPg77qoyxrlgQtBR1rVW3c9knV3E=", + "lastModified": 1772402258, + "narHash": "sha256-3DmCFOdmbkFML1/G9gj8Wb+rCCZFPOQtNoMCpqOF8SA=", "owner": "nix-community", "repo": "nixvim", - "rev": "ed0424f0b08d303a7348f52f7850ad1b2704f9ba", + "rev": "21ae25e13b01d3b4cdc750b5f9e7bad68b150c10", "type": "github" }, "original": { @@ -406,27 +385,6 @@ "type": "github" } }, - "nur": { - "inputs": { - "flake-parts": "flake-parts_4", - "nixpkgs": [ - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1772382471, - "narHash": "sha256-n+4KTzFpt66Qaw+N1qtL9/tTlvcW4X3jdREBMKK2mfM=", - "owner": "nix-community", - "repo": "NUR", - "rev": "9c70f0aceae49f327988e432d1c5111be102f69c", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "NUR", - "type": "github" - } - }, "root": { "inputs": { "disko": "disko", @@ -438,7 +396,6 @@ "nixos-hardware": "nixos-hardware", "nixpkgs": "nixpkgs", "nixvim": "nixvim", - "nur": "nur", "satty": "satty", "sops-nix": "sops-nix", "spicetify-nix": "spicetify-nix", @@ -472,11 +429,11 @@ ] }, "locked": { - "lastModified": 1769091129, - "narHash": "sha256-Jj/vIHjiu4OdDIrDXZ3xOPCJrMZZKzhE2UIVXV/NYzY=", + "lastModified": 1772420823, + "narHash": "sha256-q3oVwz1Rx41D1D+F6vg41kpOkk3Zi3KwnkHEZp7DCGs=", "owner": "oxalica", "repo": "rust-overlay", - "rev": "131e22d6a6d54ab72aeef6a5a661ab7005b4c596", + "rev": "458eea8d905c609e9d889423e6b8a1c7bc2f792c", "type": "github" }, "original": { @@ -493,11 +450,11 @@ "rust-overlay": "rust-overlay" }, "locked": { - "lastModified": 1771828319, - "narHash": "sha256-ZWayNzcfhCEzc4XFPKwutazN/+ZIt9s3tQ7RSbK7X1M=", + "lastModified": 1772431585, + "narHash": "sha256-HbI9f8Ejyf9Dz1LcM8r7hS5UkOJt+sekedsGkD/q26w=", "owner": "gabm", "repo": "Satty", - "rev": "2833499810b391c1e64a85b38455b86acb173458", + "rev": "6005a58641f9c3ce5536cf397e9796abe2b8fba1", "type": "github" }, "original": { @@ -513,11 +470,11 @@ ] }, "locked": { - "lastModified": 1772340640, - "narHash": "sha256-1nq7+Kt5IUBD8Hu3nptVPbMf+22rNJoHT0t9L1X+GKA=", + "lastModified": 1772495394, + "narHash": "sha256-hmIvE/slLKEFKNEJz27IZ8BKlAaZDcjIHmkZ7GCEjfw=", "owner": "Mic92", "repo": "sops-nix", - "rev": "dec4d8eac700dcd2fe3c020857d3ee220ec147f1", + "rev": "1d9b98a29a45abe9c4d3174bd36de9f28755e3ff", "type": "github" }, "original": { @@ -534,11 +491,11 @@ "systems": "systems_2" }, "locked": { - "lastModified": 1771737804, - "narHash": "sha256-7wn9qbzIQQgH8tnq4VwzuWEqEWpekuymlLyhY3vM/j8=", + "lastModified": 1772494187, + "narHash": "sha256-6ksgNAFXVK+Cg/6ww7bB2nJUPZlnS75UwZC7G+L03EE=", "owner": "Gerg-L", "repo": "spicetify-nix", - "rev": "6dd43010ac2458cc56a6ac5250349b9217a7a2ae", + "rev": "915ab06b046d05613041780c575c62a32fe67cea", "type": "github" }, "original": { @@ -600,11 +557,11 @@ ] }, "locked": { - "lastModified": 1772288942, - "narHash": "sha256-tWpp3YCvPZB5a2yffLQ0YUwSunXULDk0yUD1lOAUXBM=", + "lastModified": 1772901987, + "narHash": "sha256-FdfUDo6FNozvXoeGGDutp9A++0sjG0xNhz//o+A9j5w=", "owner": "Alexays", "repo": "Waybar", - "rev": "31b373b9849091ab95aa8cf31c606e87da95e608", + "rev": "e425423648ea620627a0ba0c9c81173af18c0254", "type": "github" }, "original": { @@ -633,11 +590,11 @@ "xwayland-satellite-unstable": { "flake": false, "locked": { - "lastModified": 1771787042, - "narHash": "sha256-7bM6Y4KldhKnfopSALF8XALxcX7ehkomXH9sPl4MXp0=", + "lastModified": 1772429643, + "narHash": "sha256-M+bAeCCcjBnVk6w/4dIVvXvpJwOKnXjwi/lDbaN6Yws=", "owner": "Supreeeme", "repo": "xwayland-satellite", - "rev": "33c344fee50504089a447a8fef5878cf4f6215fc", + "rev": "10f985b84cdbcc3bbf35b3e7e43d1b2a84fa9ce2", "type": "github" }, "original": { @@ -655,11 +612,11 @@ "rust-overlay": "rust-overlay_2" }, "locked": { - "lastModified": 1772254863, - "narHash": "sha256-w6RJF9uCx5Wt/ASC9sMiuod7nqYhJB0Z+t2pT/iSrzg=", + "lastModified": 1772869527, + "narHash": "sha256-U0E3U2Iu3JeQFbTQ+vclG2jZMoJl+rJdEa68I8qk4Eg=", "owner": "sxyazi", "repo": "yazi", - "rev": "3cdc3ecb70c13da9325b8333dca8514a53bcbdc3", + "rev": "741f84e22b2c360366c685724d45cbec6d90b480", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index 8f4e2fb..bb957f7 100644 --- a/flake.nix +++ b/flake.nix @@ -9,11 +9,6 @@ nixos-hardware.url = "github:NixOS/nixos-hardware/master"; - nur = { - url = "github:nix-community/NUR"; - inputs.nixpkgs.follows = "nixpkgs"; - }; - sops-nix = { url = "github:Mic92/sops-nix"; inputs.nixpkgs.follows = "nixpkgs"; @@ -71,18 +66,8 @@ }; outputs = - { - self, - nixpkgs, - nur, - ... - }@inputs: + { self, nixpkgs, ... }@inputs: let - system = "x86_64-linux"; - pkgs = import nixpkgs { - inherit system; - overlays = [ nur.overlays.default ]; - }; scripts = import ./scripts; mkHost = { diff --git a/hm/conf/xdg-dirs.nix b/hm/conf/xdg-dirs.nix index ba5b063..3a37e6a 100644 --- a/hm/conf/xdg-dirs.nix +++ b/hm/conf/xdg-dirs.nix @@ -18,7 +18,7 @@ in createDirectories = true; download = "${config.home.homeDirectory}/dl"; - documents = "${config.home.homeDirectory}/docs"; + documents = "${config.home.homeDirectory}/dc"; pictures = "${toString cfg.storagePath}/pics"; videos = "${toString cfg.storagePath}/vids"; @@ -29,7 +29,7 @@ in templates = null; extraConfig = { - PROJECTS = "${config.home.homeDirectory}/proj"; + DEV = "${config.home.homeDirectory}/dv"; GAMES = "${config.home.homeDirectory}/games"; storage = "${toString cfg.storagePath}"; SS = "${toString cfg.storagePath}/pics/ss"; @@ -39,15 +39,5 @@ in ARCHIVE = "${toString cfg.storagePath}/archive"; }; }; - home.sessionVariables = { - PROJECTS = "${config.home.homeDirectory}/proj"; - GAMES = "${config.home.homeDirectory}/games"; - storage = "${toString cfg.storagePath}"; - SS = "${toString cfg.storagePath}/pics/ss"; - CLIPS = "${toString cfg.storagePath}/vids/clips"; - MOVIES = "${toString cfg.storagePath}/movies"; - ANIME = "${toString cfg.storagePath}/anime"; - ARCHIVE = "${toString cfg.storagePath}/archive"; - }; }; } diff --git a/hm/env/niri/binds.nix b/hm/env/niri/binds.nix index 0dc4ea5..a84d5f5 100644 --- a/hm/env/niri/binds.nix +++ b/hm/env/niri/binds.nix @@ -22,9 +22,6 @@ in XF86AudioMute.action = spawn "sh" "-c" "wpctl set-mute @DEFAULT_AUDIO_SINK@ toggle && wpctl set-mute @DEFAULT_AUDIO_SOURCE@ toggle"; - XF86Tools.action = - spawn "sh" "-c" - "wpctl set-mute @DEFAULT_AUDIO_SINK@ toggle && wpctl set-mute @DEFAULT_AUDIO_SOURCE@ toggle"; # Media Control XF86AudioPlay.action = playerctl "play-pause"; @@ -36,26 +33,46 @@ in XF86MonBrightnessDown.action = spawn "light" "-U" "10"; # --- Applications --- - "Mod+Return".action = spawn "foot"; + "Mod+Return".action = spawn "footclient"; "Mod+D".action = spawn "fuzzel"; - "Mod+C".action = spawn "qalculate-gtk"; "Mod+Shift+D".action = spawn "sh" "-c" "cliphist list | fuzzel --dmenu | cliphist decode | wl-copy"; "Super+Return".action = spawn "sh" "-c" "OBS_WEBSOCKET_URL=$(cat ${obsPass}) obs-cmd replay save"; + "Super+C".action = spawn "qalculate-gtk"; + "Super+D".action = spawn "equibop"; + "Super+B".action = spawn "librewolf"; + "Super+S".action = spawn "spotify"; + "Super+E".action = spawn "thunar"; + # --- Navigation: Columns & Workspaces --- - "Mod+H".action = focus-column-left; - "Mod+L".action = focus-column-right; - "Mod+J".action = focus-workspace-down; - "Mod+K".action = focus-workspace-up; + "Mod+H".action = focus-column-or-monitor-left; + "Mod+L".action = focus-column-or-monitor-right; + "Mod+J".action = focus-window-or-workspace-down; + "Mod+K".action = focus-window-or-workspace-up; + + "Super+H".action = focus-monitor-left; + "Super+L".action = focus-monitor-right; + "Super+Shift+H".action = move-column-left-or-to-monitor-left; + "Super+Shift+L".action = move-column-right-or-to-monitor-right; "Mod+WheelScrollDown".action = focus-column-right; "Mod+WheelScrollUp".action = focus-column-left; - "Super+WheelScrollDown".action = focus-workspace-down; - "Super+WheelScrollUp".action = focus-workspace-up; + "Super+WheelScrollDown".action = focus-window-or-workspace-down; + "Super+WheelScrollUp".action = focus-window-or-workspace-up; - # --- Navigation: Monitors --- - "Super+H".action = focus-monitor-left; - "Super+L".action = focus-monitor-right; + "Mod+Tab" = { + action = + spawn "sh" "-c" + "niri msg action focus-column-right; niri msg action move-column-to-last; niri msg action focus-window-previous"; + repeat = false; + }; + + XF86Tools = { + action = + spawn "sh" "-c" + "niri msg action set-dynamic-cast-window --id $(niri msg --json pick-window | ${pkgs.jq}/bin/jq .id)"; + repeat = false; + }; # --- Window Management --- "Mod+Shift+Q".action = close-window; @@ -66,15 +83,13 @@ in }; # Moving Windows/Columns - "Mod+Shift+H".action = move-column-left; - "Mod+Shift+L".action = move-column-right; + "Mod+Shift+H".action = move-column-left-or-to-monitor-left; + "Mod+Shift+L".action = move-column-right-or-to-monitor-right; "Mod+Shift+J".action = move-window-down-or-to-workspace-down; "Mod+Shift+K".action = move-window-up-or-to-workspace-up; - "Super+Shift+H".action = move-column-to-monitor-left; - "Super+Shift+L".action = move-column-to-monitor-right; - "Mod+Shift+WheelScrollDown".action = move-column-right; "Mod+Shift+WheelScrollUp".action = move-column-left; + "Mod+Shift+WheelScrollDown".action = move-column-right; "Super+Shift+WheelScrollDown".action = move-window-down-or-to-workspace-down; "Super+Shift+WheelScrollUp".action = move-window-up-or-to-workspace-up; @@ -86,13 +101,13 @@ in XF86Launch5.action = consume-or-expel-window-right; XF86Launch6.action = consume-or-expel-window-left; + XF86Launch7.action = switch-preset-column-width; # --- Layout & Sizing --- "Mod+F".action = maximize-column; "Mod+Shift+F".action = fullscreen-window; "Mod+W".action = toggle-column-tabbed-display; "Mod+R".action = switch-preset-column-width; - XF86Launch7.action = switch-preset-column-width; "Mod+Shift+R".action = reset-window-height; "Mod+Minus".action = set-column-width "-10%"; @@ -124,6 +139,9 @@ in ''; repeat = false; }; + + "Mod+grave".action.focus-workspace = 0; + "Mod+Shift+grave".action.move-column-to-workspace = 0; } // (builtins.listToAttrs ( builtins.concatMap ( diff --git a/hm/env/niri/niri.nix b/hm/env/niri/niri.nix index f8e1542..2274259 100644 --- a/hm/env/niri/niri.nix +++ b/hm/env/niri/niri.nix @@ -57,13 +57,12 @@ in }; layout = { empty-workspace-above-first = true; - border = { - width = 2; - # active = ; - }; + border.enable = false; focus-ring = { - width = 2; - # active = ; + enable = true; + width = 3; + active.color = "#7fc8ff"; + inactive.color = "#505050"; }; preset-column-widths = [ { proportion = 1. / 3.; } @@ -84,17 +83,65 @@ in window-rules = [ { matches = [ - { app-id = "Bitwarden"; } + { app-id = "^Bitwarden$"; } + { app-id = "^org\\.keepassxc\\.KeePassXC$"; } ]; block-out-from = "screen-capture"; } + { + matches = [ + { + app-id = "steam"; + title = "^notificationtoasts_\\d+_desktop$"; + } + ]; + default-floating-position = { + x = 10; + y = 10; + relative-to = "bottom-right"; + }; + } + { + matches = [ { is-window-cast-target = true; } ]; + + focus-ring.active.color = "#f38ba8"; + shadow = { + enable = true; + color = "#7d0d2d70"; + }; + } + { + matches = [ { app-id = "^qalculate-gtk$"; } ]; + open-floating = true; + + # Use default-window-height instead of default-floating-height + default-window-height.fixed = 537; + default-column-width.fixed = 802; + + default-floating-position = { + relative-to = "right"; + x = 100; + y = 0; + }; + } + { + matches = [ { app-id = "^sober$"; } ]; + open-fullscreen = true; + } + ]; + layer-rules = [ + { + matches = [ + { namespace = "^notifications$"; } + ]; + block-out-from = "screencast"; + } ]; gestures.hot-corners.enable = false; spawn-at-startup = [ { command = [ "obs" - "--disable-missing-files-check" "--startreplaybuffer" ]; } diff --git a/hm/soft/media.nix b/hm/soft/media.nix index 72ddc64..de70715 100644 --- a/hm/soft/media.nix +++ b/hm/soft/media.nix @@ -10,56 +10,15 @@ in { options.hm.soft.media.enable = lib.mkEnableOption "media cli tools"; config = lib.mkIf cfg.enable { - programs.zathura = { - enable = true; - package = pkgs.zathura.override { - plugins = with pkgs.zathuraPkgs; [ - zathura_pdf_mupdf - zathura_cb - ]; - }; - options = { - selection-clipboard = "clipboard"; - - incremental-search = true; - highlight-active-color = "#fabd2f"; - highlight-color = "#fe8019"; - - recolor = true; - recolor-keephue = true; - - default-bg = "#282828"; - default-fg = "#ebdbb2"; - recolor-lightcolor = "#282828"; - recolor-darkcolor = "#ebdbb2"; - - render-loading = false; - scroll-step = 50; - statusbar-h-padding = 10; - statusbar-v-padding = 10; - }; - - mappings = { - "u" = "scroll half-up"; - "d" = "scroll half-down"; - "D" = "toggle_page_mode"; - "r" = "reload"; - "R" = "rotate"; - "K" = "zoom in"; - "J" = "zoom out"; - "i" = "recolor"; - }; - }; home.packages = with pkgs; [ - (callPackage ./czkawka-v11.nix { }) - + czkawka nsxiv pinta ffmpeg imagemagick mediainfo sox - syncplay-nogui + syncplay ]; }; } diff --git a/hm/soft/nixcord.nix b/hm/soft/nixcord.nix index 112a82b..8e5ae12 100644 --- a/hm/soft/nixcord.nix +++ b/hm/soft/nixcord.nix @@ -24,7 +24,7 @@ in autoscroll.enable = true; vencord.enable = false; - equicord.enable = true; + # equicord.enable = true; }; equibop = { enable = true; diff --git a/hm/soft/obsidian.nix b/hm/soft/obsidian.nix index a840726..38093fa 100644 --- a/hm/soft/obsidian.nix +++ b/hm/soft/obsidian.nix @@ -1,4 +1,4 @@ -{ config, lib, pkgs, ... }: +{ config, lib, ... }: let cfg = config.hm.soft.obsidian; in diff --git a/hm/soft/sioyek.nix b/hm/soft/sioyek.nix new file mode 100644 index 0000000..6b2650d --- /dev/null +++ b/hm/soft/sioyek.nix @@ -0,0 +1,18 @@ +{ config, lib, ... }: +let + cfg = config.hm.soft.sioyek; +in +{ + options.hm.soft.sioyek.enable = lib.mkEnableOption "enables sioyek pdf reader"; + config = lib.mkIf cfg.enable { + programs.sioyek = { + enable = true; + config = { + + }; + bindings = { + + }; + }; + }; +} diff --git a/hm/soft/soft.nix b/hm/soft/soft.nix index 0d74669..f6a9a69 100644 --- a/hm/soft/soft.nix +++ b/hm/soft/soft.nix @@ -13,7 +13,7 @@ ./onlyoffice.nix ./spicetify.nix ./torrent.nix - ./vpn.nix ./yt-dlp.nix + ./sioyek.nix ]; } diff --git a/hm/soft/vpn.nix b/hm/soft/vpn.nix deleted file mode 100644 index 47bd959..0000000 --- a/hm/soft/vpn.nix +++ /dev/null @@ -1,20 +0,0 @@ -{ config, lib, pkgs, ... }: -let - cfg = config.hm.soft.vpn; -in -{ - options.hm.soft.vpn = { - protonvpn.enable = lib.mkEnableOption "protonvpn"; - mullvad.enable = lib.mkEnableOption "mullvad vpn"; - }; - config = lib.mkMerge [ - (lib.mkIf cfg.mullvad.enable { - programs.mullvad-vpn = { - enable = true; - }; - }) - (lib.mkIf cfg.protonvpn.enable { - home.packages = [ pkgs.protonvpn-gui ]; - }) - ]; -} diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix index fc1c334..69c95da 100644 --- a/hosts/desktop/configuration.nix +++ b/hosts/desktop/configuration.nix @@ -62,6 +62,7 @@ users.enable = true; }; srv = { + i2p.enable = true; files = { enable = true; localsend.enable = true; @@ -80,6 +81,7 @@ monero.enable = true; sops.enable = true; syncthing.enable = true; + vpn.enable = true; }; wm = { enable = true; @@ -107,13 +109,22 @@ ]; }; + services.hardware.openrgb = { + enable = true; + motherboard = "amd"; + package = pkgs.openrgb-with-all-plugins; + }; + boot = { + kernelParams = [ + "video=DP-1:2560x1440@240" + "video=DP-2:1920x1080@144" + ]; kernelModules = [ "nct6687" "binder_linux" "ashem_linux" ]; - # kernelParams = [ "video=DP-1:2560x1440@240" ]; extraModulePackages = [ config.boot.kernelPackages.nct6687d ]; diff --git a/hosts/desktop/home.nix b/hosts/desktop/home.nix index 196617b..9ca7073 100644 --- a/hosts/desktop/home.nix +++ b/hosts/desktop/home.nix @@ -43,6 +43,7 @@ starship.enable = true; }; soft = { + sioyek.enable = true; browser = { librewolf.enable = true; brave.enable = true; @@ -55,7 +56,6 @@ obsidian.enable = true; spicetify.enable = true; torrent.enable = true; - vpn.protonvpn.enable = true; yt-dlp.enable = true; }; }; diff --git a/hosts/thinkpad/configuration.nix b/hosts/thinkpad/configuration.nix index 56a21b3..f9d3f6c 100644 --- a/hosts/thinkpad/configuration.nix +++ b/hosts/thinkpad/configuration.nix @@ -19,19 +19,14 @@ os = { core = { allowUnfree.enable = true; + flatpak.enable = true; audio.enable = true; bootloader = { type = "grub"; + efi = false; timeout = 0; luks.enable = true; - grub = { - device = "/dev/nvme0n1"; - signing = { - enable = true; - keyId = "3D95543550A5A23A"; - }; - }; }; drivers = { enable = true; @@ -62,6 +57,7 @@ }; srv = { bluetooth.enable = true; + i2p.enable = true; files = { enable = true; localsend.enable = true; @@ -78,12 +74,26 @@ nix-helper.enable = true; monero.enable = true; sops.enable = true; + syncthing.enable = true; + vpn.enable = true; }; wm = { enable = true; niri.enable = true; }; }; + boot = { + kernelParams = [ "iomem=relaxed" ]; + initrd = { + secrets = { + "/etc/cryptsetup-keys.d/root.key" = "/etc/cryptsetup-keys.d/root.key"; + }; + luks.devices."crypted" = { + device = "/dev/nvme0n1p2"; + keyFile = "/etc/cryptsetup-keys.d/root.key"; + allowDiscards = true; + }; + }; + }; services.thinkfan.enable = true; - boot.kernelParams = [ "iomem=relaxed" ]; } diff --git a/hosts/thinkpad/disko.nix b/hosts/thinkpad/disko.nix index 9816f7f..3ab76f4 100644 --- a/hosts/thinkpad/disko.nix +++ b/hosts/thinkpad/disko.nix @@ -16,7 +16,6 @@ content = { type = "luks"; name = "crypted"; - keyFile = "/boot/root.key"; extraFormatArgs = [ "--type luks2" "--pbkdf argon2id" diff --git a/hosts/thinkpad/home.nix b/hosts/thinkpad/home.nix index 3a8215d..b121ae2 100644 --- a/hosts/thinkpad/home.nix +++ b/hosts/thinkpad/home.nix @@ -40,6 +40,7 @@ starship.enable = true; }; soft = { + sioyek.enable = true; browser.librewolf.enable = true; email.thunderbird.enable = true; media.enable = true; diff --git a/os/core/audio.nix b/os/core/audio.nix index 5b9607c..e677a90 100644 --- a/os/core/audio.nix +++ b/os/core/audio.nix @@ -25,20 +25,6 @@ in alsa.support32Bit = true; jack.enable = true; wireplumber.enable = true; - - # wireplumber.extraConfig."10-force-input-awake" = { - # "monitor.alsa.rules" = [ - # { - # matches = [ - # { "node.name" = "~alsa_input.*HyperX.*"; } - # { "node.name" = "~alsa_output.*HyperX.*"; } - # ]; - # actions.update-props = { - # "session.suspend-on-idle" = false; - # }; - # } - # ]; - # }; }; playerctld.enable = true; spotifyd.enable = true; @@ -50,14 +36,9 @@ in hardware.enableAllFirmware = true; environment.systemPackages = with pkgs; [ - helvum + crosspipe alsa-utils ]; - - # boot.kernelParams = [ "usbcore.autosuspend=-1" ]; - # boot.extraModprobeConfig = '' - # options snd-usb-audio power_save=0 - # ''; }) (lib.mkIf cfg.disable-devices.enable { diff --git a/os/core/bootloader.nix b/os/core/bootloader.nix index aae167e..6eca320 100644 --- a/os/core/bootloader.nix +++ b/os/core/bootloader.nix @@ -48,13 +48,6 @@ in default = 0; description = "Index of the default boot entry"; }; - signing = { - enable = lib.mkEnableOption "GPG signing for Libreboot/GRUB"; - keyId = lib.mkOption { - type = lib.types.str; - description = "The GPG Key ID used to sign the boot files"; - }; - }; }; luks.enable = lib.mkEnableOption "LUKS encryption support"; @@ -104,36 +97,7 @@ in default = cfg.grub.defaultEntry; enableCryptodisk = cfg.luks.enable; copyKernels = true; - - extraConfig = lib.mkIf cfg.grub.signing.enable '' - set check_signatures=enforce - terminal_input console - terminal_output console - ''; - - extraInstallCommands = lib.mkIf cfg.grub.signing.enable '' - echo "Signing with keys from ${gpgHome}" - - SIGN_CMD="${pkgs.gnupg}/bin/gpg --homedir ${gpgHome} --detach-sign --batch --yes --default-key ${cfg.grub.signing.keyId}" - - $SIGN_CMD /boot/grub/grub.cfg - - for f in /boot/nixos/*; do - if [[ "$f" != *.sig ]]; then - $SIGN_CMD "$f" - fi - done - ''; }; - environment.systemPackages = lib.optional cfg.grub.signing.enable pkgs.gnupg; }) - { - assertions = [ - { - assertion = cfg.grub.signing.enable -> cfg.grub.signing.keyId != ""; - message = "Bootloader signing is enabled but os.core.bootloader.grub.signing.keyId is not set."; - } - ]; - } ]; } diff --git a/os/core/networking.nix b/os/core/networking.nix index 4835cb8..d3021e4 100644 --- a/os/core/networking.nix +++ b/os/core/networking.nix @@ -6,18 +6,22 @@ in options.os.core.network.enable = lib.mkEnableOption "system-wide networking setup"; config = lib.mkIf cfg.enable { networking = { - useDHCP = lib.mkDefault true; networkmanager = { enable = true; - wifi.macAddress = "stable-ssid"; - ethernet.macAddress = "stable-ssid"; + wifi = { + macAddress = "random"; + backend = "iwd"; + }; + ethernet.macAddress = "random"; + dns = "systemd-resolved"; }; firewall = { - enable = true; + enable = false; allowedTCPPorts = [ ]; allowedUDPPorts = [ ]; }; }; + services.resolved.enable = true; systemd.services."NetworkManager-wait-online".enable = false; }; } diff --git a/os/core/security.nix b/os/core/security.nix index bc2c41c..f1c41c2 100644 --- a/os/core/security.nix +++ b/os/core/security.nix @@ -21,21 +21,15 @@ in rtkit.enable = true; }; - # systemd.user.services.polkit-gnome-authentication-agent-1 = { - # description = "gnome-polkit-authentication-agent-1"; - # wantedBy = [ "graphical-session.target" ]; - # serviceConfig = { - # Type = "simple"; - # ExecStart = "${pkgs.polkit_gnome}/libexec/polkit-gnome-authentication-agent-1"; - # Restart = "on-failure"; - # RestartSec = 1; - # TimeoutStopSec = 10; - # }; - # }; - environment.systemPackages = with pkgs; [ veracrypt + bitwarden-desktop + keyguard + + keepassxc + keepassxc-go + git-credential-keepassxc ]; }; } diff --git a/os/core/ssh.nix b/os/core/ssh.nix index d41c116..a0cb1f4 100644 --- a/os/core/ssh.nix +++ b/os/core/ssh.nix @@ -12,12 +12,6 @@ in options.os.core.ssh.enable = lib.mkEnableOption "enables ssh server setup"; config = lib.mkIf cfg.enable { - environment.systemPackages = [ pkgs.rclone ]; - services.tailscale = { - enable = true; - openFirewall = true; - }; - services.openssh = { enable = true; settings = { diff --git a/os/srv/i2p.nix b/os/srv/i2p.nix new file mode 100644 index 0000000..8850795 --- /dev/null +++ b/os/srv/i2p.nix @@ -0,0 +1,32 @@ +{ + config, + lib, + ... +}: +let + cfg = config.os.srv.i2p; +in +{ + options.os.srv.i2p.enable = lib.mkEnableOption "enables i2pd"; + + config = lib.mkIf cfg.enable { + services.i2pd = { + enable = true; + upnp.enable = true; + bandwidth = 1024; + ssu2 = { + enable = true; + # published = true; + }; + reseed.verify = true; + # proto = { + # socksProxy = { + # enable = true; + # port = 4445; + # }; + # i2pControl.enable = true; + # }; + yggdrasil.enable = true; + }; + }; +} diff --git a/os/srv/ollama.nix b/os/srv/ollama.nix index 7a9bc78..3afc684 100644 --- a/os/srv/ollama.nix +++ b/os/srv/ollama.nix @@ -1,4 +1,9 @@ -{ config, lib, pkgs, ... }: +{ + config, + lib, + pkgs, + ... +}: let cfg = config.os.srv.ollama; in @@ -14,15 +19,9 @@ in services.ollama = { enable = true; package = pkgs.ollama-rocm; - + rocmOverrideGfx = "12.0.1"; user = "ollama"; models = "/models"; - - syncModels = true; - loadModels = [ - "deepseek-r1:14b" - "qwen3:14b" - ]; }; }; } diff --git a/os/srv/sops.nix b/os/srv/sops.nix index 40f9c74..fecb9df 100644 --- a/os/srv/sops.nix +++ b/os/srv/sops.nix @@ -23,17 +23,18 @@ in age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; secrets = { - "syncthing/gui_password" = { - owner = username; - sopsFile = ../../secrets/oci.yaml; + "syncthing/gui_password".owner = username; + "syncthing/encryption/game-saves".owner = username; + "syncthing/encryption/keepass".owner = username; + "vpn/warp_private_key" = { + owner = "root"; + group = "networkmanager"; + mode = "0400"; + restartUnits = [ "NetworkManager.service" ]; }; "obs/websocket_password".owner = username; root_password.neededForUsers = true; user_password.neededForUsers = true; - oracler_password = { - neededForUsers = true; - sopsFile = ../../secrets/oci.yaml; - }; }; }; diff --git a/os/srv/srv.nix b/os/srv/srv.nix index 8ee895b..4edd742 100644 --- a/os/srv/srv.nix +++ b/os/srv/srv.nix @@ -12,5 +12,7 @@ ./ollama.nix ./kdeconnect.nix ./monero.nix + ./vpn.nix + ./i2p.nix ]; } diff --git a/os/srv/syncthing.nix b/os/srv/syncthing.nix index 332bb54..b350428 100644 --- a/os/srv/syncthing.nix +++ b/os/srv/syncthing.nix @@ -6,39 +6,34 @@ }: let cfg = config.os.srv.syncthing; + syncDirs = lib.mapAttrsToList (_: folder: folder.path) config.services.syncthing.settings.folders; in { options.os.srv.syncthing.enable = lib.mkEnableOption "enables syncthing syncing"; config = lib.mkIf cfg.enable { + systemd.tmpfiles.rules = map (path: "d ${path} 0755 ${username} users -") syncDirs; + services.syncthing = { enable = true; - user = "${username}"; + user = username; dataDir = "/home/${username}/.local/share/syncthing"; configDir = "/home/${username}/.config/syncthing"; - guiPasswordFile = "/run/secrets/syncthing/gui_password"; + guiPasswordFile = config.sops.secrets."syncthing/gui_password".path; settings = { - devices = { - "desktop" = { - id = "YGMWGOB-LTJUDM7-CY25MAF-NPE7J4J-KYRNPB5-ZHD5DBI-VNRAXI6-LIP2DQP"; - }; - "laptop" = { - id = ""; - }; - "thinkpad" = { - id = ""; - }; - }; + devices."oci".id = "DQXGVDC-KGPM6RK-5NDEBJJ-R7PEWYZ-N6Z3WFZ-TSVJG5X-235SHG4-4BEJNQJ"; + folders = { "game-saves" = { path = "/home/${username}/.saves"; - id = "shared-saves-v1"; + id = "game-saves"; devices = [ - "desktop" - "laptop" - "thinkpad" + { + name = "oci"; + encryptionPasswordFile = config.sops.secrets."syncthing/encryption/game-saves".path; + compression = "always"; + } ]; - versioning = { type = "staggered"; params = { @@ -47,6 +42,22 @@ in }; }; }; + + "keepass" = { + path = "/home/${username}/.keepass"; + id = "keepass"; + devices = [ + { + name = "oci"; + encryptionPasswordFile = config.sops.secrets."syncthing/encryption/keepass".path; + compression = "metadata"; + } + ]; + versioning = { + type = "simple"; + params.keep = "10"; + }; + }; }; }; }; diff --git a/os/srv/vpn.nix b/os/srv/vpn.nix new file mode 100644 index 0000000..28c7a9e --- /dev/null +++ b/os/srv/vpn.nix @@ -0,0 +1,49 @@ +{ + config, + lib, + pkgs, + ... +}: +let + cfg = config.os.srv.vpn; + netCfg = config.os.core.network; +in +{ + options.os.srv.vpn.enable = lib.mkEnableOption "enables vpn stuff"; + + config = lib.mkIf (cfg.enable && netCfg.enable) { + networking.networkmanager.ensureProfiles = { + environmentFiles = [ config.sops.secrets."vpn/warp_private_key".path ]; + profiles.cloudflare-warp = { + connection = { + id = "cloudflare-warp"; + type = "wireguard"; + interface-name = "wg0"; + autoconnect = false; + }; + wireguard = { + mtu = 1200; + private-key = "$WG_KEY"; + }; + "wireguard-peer.bmXOC+F1FxEMF9dyiK2H5/1SUtzH0JuVo51h2wPfgyo=" = { + endpoint = "engage.cloudflareclient.com:2408"; + allowed-ips = "0.0.0.0/0;::/0;"; + }; + ipv4 = { + method = "manual"; + address1 = "172.16.0.2/32"; + dns = "1.1.1.1;1.0.0.1;"; + }; + ipv6 = { + method = "manual"; + address1 = "2606:4700:110:84c7:36c4:e444:5efb:b108/128"; + dns = "2606:4700:4700::1111;2606:4700:4700::1001;"; + }; + }; + }; + environment.systemPackages = with pkgs; [ + wgcf + wireguard-tools + ]; + }; +} diff --git a/secrets/common.yaml b/secrets/common.yaml index 90da196..48c31db 100644 --- a/secrets/common.yaml +++ b/secrets/common.yaml @@ -2,6 +2,13 @@ user_password: ENC[AES256_GCM,data:lPSKNpHWQYQZvLFmK1NIqvcDTsXWe8lMnBuqATtkyQjjs root_password: ENC[AES256_GCM,data:F2M3P5JTpP9bnO494jnLA/Hs2ndQRYhgN9Z9LiEgTYYQPvMdi0DGI5dN6rh+5Dhm0a9eqGSOpU+4rWYX6cXOp+Um2exKr0O8YQ==,iv:WZtTsAMhg+qzE66/v2DUsG50Voc3vJF+1X19LNNsG3Q=,tag:cpQu7W/SMfilYxnbsgi/RQ==,type:str] obs: websocket_password: ENC[AES256_GCM,data:JkKC2b6Hs2orWJ3MN9hk6W2V2vH2A/FCdxuI13fwwOrcA1E8HaMH,iv:IvMrKDxWMxkCBAHEy9mLDd3JS1Pie3XuESXr7gp6D/E=,tag:6yfqG7Dv2ElPFCMKZX2dvg==,type:str] +vpn: + warp_private_key: ENC[AES256_GCM,data:4+adbMc4syo46oQmPpQ5Flw1zZt575qjKw9kUsRrD/M+MMstT6PifWTkwQSDWQx7lzgy,iv:s9hsaa67uSDuXQHVefxBWQ0+8MHc8fG63pP189tkHHs=,tag:JRdUN/p17z4TDz9cV0nvWA==,type:str] +syncthing: + gui_password: ENC[AES256_GCM,data:l1qUM6MfrCTnv2LlFeRDy4o4eYQbLBzfI5C9BgcmVGQNnwjT5HWCXQqY54XHfhlPuSXO4bZs7u8JcKbQFW/+Pg==,iv:IIBWrmgX8nhP6B7WkZisEK1zmvMBqNYCg4eHgJX68Ak=,tag:1DggOF7x60nvz9gS9Ou29g==,type:str] + encryption: + game-saves: ENC[AES256_GCM,data:67kubvePq/KYxJKJkNR8gBEf3VGczFkJE469XSYvBg/a4HfAAmdJuL2kfv62zEXVVb5BXx7NK1Xr5s+81AEaZw==,iv:1ERuh9X8IX/+XM22rreNUzt+i4CcJhVhS+IM210Z6dU=,tag:iSkTHHUF/WosX94JqJAjiQ==,type:str] + keepass: ENC[AES256_GCM,data:OLU0tYB9TTKZ5V1Mzj5FDE9YdCpj0ajJaoxzqd7HtTmaBqETjs7CjYriq7kCOgSEVBtwzek/NA1vetwuMQhI8Q==,iv:P9aBZCIbj23aOvuMBtAjAZ2L+0lUT5Xjk7XRikbc9u0=,tag:xnWUxctkKVTUOV0AtpnTug==,type:str] sops: age: - recipient: age1s39d4mdrjhkf8cy8eea02p836r7s875fj8f7w3z4ld2stmaac49qd075ww @@ -31,8 +38,8 @@ sops: VTZMMDhCcUtCaFRDcWtBbTRvaXF4amsK7mbW8KsfTrHZkdGbORVgIfCfgTZfgOcQ Q4ejje7WzbEhPVUKeYkbe5cmrA2AhxcLGURPZhZfNihBuKzj/TX+/Q== -----END AGE ENCRYPTED FILE----- - lastmodified: "2026-03-01T13:38:59Z" - mac: ENC[AES256_GCM,data:KOrDWFJM60kwUVPhC1GrnsI4UN5rpKfpRMRzXYNCtWIa8SsY5JhktMNcldVN5WvaXO1x3Q2N2nF1i3S45ByFUcAahnWwVEFKIfgVt6BfgKLlcXSGvYOxhqA4wWC7zYI8PlPvLmTKET/1fqFa2KrFTiZsPwFNPmASdIy94//Mluc=,iv:8qkTr9mg/4E8qfAhSLgGtCXahLyoy71lyVmNc65QvKg=,tag:tFoJkmC+igSX/NfObYIQig==,type:str] + lastmodified: "2026-03-06T22:04:13Z" + mac: ENC[AES256_GCM,data:LuJ93avw8+YwfEMo4jYaWuPR+FJHkJIuBNfXLm39aO/7z5YHzZt7Dg4V08IM1zhVdSBtIl/cw4PYBnp8/rKMpdx5XsmOGJ2l8i1JrQk1XckouQIWXodG4SoLBHxoCQ0vlnythlVptBlNK9yCDqynQs6xtZwO1nmOFSGPagsCDcw=,iv:V9RYOAVqgXA1zHTInFQKwixW0sO0CEGUo63SlCyoxeE=,tag:4BC8hAyVVKkSwpWdtfqJ0A==,type:str] pgp: - created_at: "2026-02-13T17:46:13Z" enc: |- @@ -55,4 +62,4 @@ sops: -----END PGP MESSAGE----- fp: EF69F2FB25C8B5A66918EA91A38ACEAB9656CD94 unencrypted_suffix: _unencrypted - version: 3.12.0 + version: 3.12.1 diff --git a/secrets/oci.yaml b/secrets/oci.yaml deleted file mode 100644 index 2cb83cf..0000000 --- a/secrets/oci.yaml +++ /dev/null @@ -1,57 +0,0 @@ -oracler_password: ENC[AES256_GCM,data:rzf38LcMsRcklYBC2lcKvEt4Zj1oqiRFkuAR+iOPo376bH0kmu+fQIZFrSRG3Nsc4BGLTmoCGizL7CMGqIbE/xuC9HFitQ9CUg==,iv:9zHJbNv/O9dB25XAMptzkUowQWvrnmzs08ipjjfrKmE=,tag:QFYDFLiT2eth1Qu/qLO4ww==,type:str] -syncthing: - gui_password: ENC[AES256_GCM,data:7Gn8HXDA4EcQMXSza7fWPkW7kmhAKs053dXJ0+GSyCryH+iL2BtzMBuGyzCWC19wuce8UC6mKFNGvN/UXJVQM2G+N2iNTTveA7l5BidB9et8K5y9mOiiJnKFh14FSdyTgF/JSJXiwB5hpmmNMALRRftmc6LFYl7NzuBoCuYPAMw=,iv:VaxfT1W6nKAVsg9FOwZXrAsDDFjpp+TkYtA+cmSV4Hc=,tag:AstVeaue+MxAB77ixDXAFQ==,type:str] -sops: - age: - - recipient: age1s39d4mdrjhkf8cy8eea02p836r7s875fj8f7w3z4ld2stmaac49qd075ww - enc: | - -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBwMTZYc1grOVZsd1ZCT0Rs - ZkgrTUFPWG83aEJTY3I2UWV6NjkzV1dLOUM0CnhuYUNNb3FiNCtmVy9SSGtxNkhs - NW56eU5pYXdUWDFTOVNSUHpYYTY3K0UKLS0tIHU1bHpjc094WWw0SXo2SjRJZGZm - bm1DdmdBR0Nja3Fvcmx1b21UaW5sNXcKZyT0t3vnWfrnc/Qwn7RyICWHEM/91uKu - wLD0Jdj8+cwSV5YMUyH5vGWAryDUUYnm3vMgvI8/Beq0w1PqRvYnng== - -----END AGE ENCRYPTED FILE----- - - recipient: age1sx8ut0arwlrp7n7qvlaele8mq93pyvzc0ddetlk47cnyx935gcusdceq9q - enc: | - -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBKcVFpK0FCeVFDb0RYbVN4 - K0puNUNPTTkrc1hBRDFnM3JqRlhWUk4yMmlRClBtTjBuNHFHWFNob1dwZWkvOU45 - d0ljVXpJSWs2OTdTRit4eUNzQ0F5ekUKLS0tIEFVVVdwMWE2ZEg3QmpMVzJUZUlT - WW85cWdxZ1ROVWhCNzNaMGVjV0k0blEKP9Ux8+moowwbMDbbo69ZzahoDjKVQor8 - i2Qkh4h2vNHxTKbR7XUBdlbdCgQpKxYsrA7lKeMb9+wfh25ey3k90g== - -----END AGE ENCRYPTED FILE----- - - recipient: age1m4u7n6mt5d3jv39lf4aedr9gqu3khl4sahuqx5n5h7v48gkyc9zqkp9qs8 - enc: | - -----BEGIN AGE ENCRYPTED FILE----- - YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA3NUtMUDBlb3UzOXBKZktu - U2FWczNiWGpKTERkOWNzeThMdmgrVmIyaGtnCnNtUHhaNEJIekVOaHgzeDZ5bTFO - T0JXVHJrVi9leFNaZEZnVW1YVEVsNkUKLS0tIEZDV01GTUVHR1BLSUo2aXZUQTZa - YlcvSzc5aU8rZjBHVUwvb3gwS29ocXMKTusHPeGGMigfgDoDGL54lmHl/GSSjc3n - VCx4h1bOCHmx4drkjEnOJBHd1FBYtnaUhAnojfFTQsTViErvamRLKw== - -----END AGE ENCRYPTED FILE----- - lastmodified: "2026-02-15T19:28:43Z" - mac: ENC[AES256_GCM,data:aMEACyF/DATSBd9e1MhnGbYaeI33HD48b+ylnNPfmhjpv5BUYj587hO8T7AJgVi36QpDP6kLAn95dFTfKiAaUBnJf4LB9A9RGmeYtMPbutwhJIFzeYn+OUISvLGZujTLg+pFMgvGyhe3pQh+jopbhlf4xorrkv+7OxUYuP0HhU4=,iv:gIqC0zqceJdcXkEQffHf5gupl/oTtfHQzEO7EGusWAo=,tag:8pwTrSmVQJ2oliF/i+7T7Q==,type:str] - pgp: - - created_at: "2026-02-15T19:28:19Z" - enc: |- - -----BEGIN PGP MESSAGE----- - - hQIMA/mKtLqB941HAQ/9Hqgbj6ZgQv2LMApnJMuR1ssHLxu7qBWXkM05JjDS0lMs - uBRmA40dln/rtiXujLAw9c4ChD14vcUOR/DLxkKb5QZmMVff3XdVDnNqVYh9tOqT - Rf223PVhvZBaUDYj8rB2jCI8Nx9HJMl8A1bknUg4CuBmukveDluOvSxSlKeqAx1g - vOh2f8i9zgv4cwEcjgWVK7zdD74OSfszOdGUOK/F0wCpqLF45N5TXPaxU7+GPYUX - QT3MudGzYVuiAsSDFbz5uJf4TJ3Hc6SH0isbGFtn9pdgKNTbKLV4/b+9stfb2wzK - Kbv6uWlnhygrjrGExysmfiROhamBeyXS71FXxgT5Rg9BzscjSenlBrEi+SigOj8P - nFwqAfQ8cKPfQe3WZBUP6AN9KsNUFYUXBtvQB7TexW2TBJ+j8I5JE5H8v6gDrOHs - gUSNN+Ly1uyLynnDi10rJf5PhzOCVt6Rs2w2ZUGpIgM8zztxb+FDnlELz+I1R7ei - sOmdYYotyIzPJVfKghoBf6aZckoYNsLpu3puau7I+r3RzTRmv8w+XiTM/eiJXDy4 - HjJdjSUa3VNnuIy2JNYi7wS22h+WgPAfOx+K2YlHiGGukCknMu9IM9ybwGONskDa - Lyo7FB+gHg8aucKlQANPIM02AgLRztkUkXN5alaHD5KWeht6J7V4CLf5S/zBC5bS - XgEgv3JyvyAdHmrN+xeLGcwCjngrpiPXJAp3ZkcWlUhRkEAFZeovCsbwlQcELo7s - JdxMIUKUSZah8JFN90oyt4rmtdehJeurm+7a6g6c2JCGJaHT/lNHf7YED7v2q5s= - =GCLy - -----END PGP MESSAGE----- - fp: EF69F2FB25C8B5A66918EA91A38ACEAB9656CD94 - unencrypted_suffix: _unencrypted - version: 3.11.0 -- cgit v1.3