From 8a820cacee1ff07ae7397d053b26e66f7086a4a4 Mon Sep 17 00:00:00 2001 From: adikro Date: Mon, 29 Jun 2026 00:31:26 +0200 Subject: updated some stuff, added persistance --- flake.lock | 99 +++++++++++++++++++++++++++++------------ flake.nix | 5 +++ hosts/bibus-lab/disko.nix | 11 +++-- hosts/desktop/configuration.nix | 2 +- hosts/desktop/home.nix | 1 + os/core/default.nix | 1 + os/core/networking.nix | 25 ++++++----- os/core/persistance.nix | 50 +++++++++++++++++++++ os/core/users.nix | 2 +- os/core/zfs.nix | 60 +++++++++++++++++++++++++ os/srv/avahi.nix | 41 +++++++++++++++++ os/srv/backup.nix | 3 +- os/srv/crowdsec.nix | 74 +++++++++++++++++++++++++++--- os/srv/default.nix | 1 - os/srv/dns.nix | 13 +++++- os/srv/gaming.nix | 31 ++----------- os/srv/lldap.nix | 11 ----- os/srv/monero.nix | 32 ++++++------- os/srv/simplex.nix | 13 ------ os/srv/ssh.nix | 69 +++++++--------------------- os/srv/zfs.nix | 60 ------------------------- os/vms/microvms.nix | 3 -- 22 files changed, 364 insertions(+), 243 deletions(-) create mode 100644 os/core/persistance.nix create mode 100644 os/core/zfs.nix create mode 100644 os/srv/avahi.nix delete mode 100644 os/srv/zfs.nix diff --git a/flake.lock b/flake.lock index 0bbd8f4..ced4b22 100644 --- a/flake.lock +++ b/flake.lock @@ -374,11 +374,11 @@ ] }, "locked": { - "lastModified": 1782423922, - "narHash": "sha256-qPNd6lUohHP5gcJhqQ7rLV87RwIx0xYR2A4Frb9Zjc4=", + "lastModified": 1782657028, + "narHash": "sha256-PHTCpYZCMzJYS3phhywqRAZphKVr2zjvlGYa+H20ZZ4=", "owner": "nix-community", "repo": "home-manager", - "rev": "5d320ab301cfaaca7d32514f13815d19d109f5f4", + "rev": "4ad9aaae70c9aaab504127f926c0fa9cfbc2b365", "type": "github" }, "original": { @@ -389,6 +389,27 @@ } }, "home-manager_2": { + "inputs": { + "nixpkgs": [ + "impermanence", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1768598210, + "narHash": "sha256-kkgA32s/f4jaa4UG+2f8C225Qvclxnqs76mf8zvTVPg=", + "owner": "nix-community", + "repo": "home-manager", + "rev": "c47b2cc64a629f8e075de52e4742de688f930dc6", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "home-manager", + "type": "github" + } + }, + "home-manager_3": { "inputs": { "nixpkgs": [ "otter-launcher", @@ -409,6 +430,27 @@ "type": "github" } }, + "impermanence": { + "inputs": { + "home-manager": "home-manager_2", + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1769548169, + "narHash": "sha256-03+JxvzmfwRu+5JafM0DLbxgHttOQZkUtDWBmeUkN8Y=", + "owner": "nix-community", + "repo": "impermanence", + "rev": "7b1d382faf603b6d264f58627330f9faa5cba149", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "impermanence", + "type": "github" + } + }, "microvm": { "inputs": { "nixpkgs": [ @@ -492,11 +534,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1782333733, - "narHash": "sha256-QYrNYMNPKErRgNlxWwk0cjNKftnq6WzSs84pcZnUskM=", + "lastModified": 1782592242, + "narHash": "sha256-kgINba6Ilpj3rdTi2BeKlQBs6ZxTdu3Gb49U5gDUVhg=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "a6351044a3d69877d1c23be54971d18f8531c930", + "rev": "9e26dfe0fb8d61475b6f9e8d63477fe92509f1db", "type": "github" }, "original": { @@ -543,11 +585,11 @@ "nixpkgs": "nixpkgs_2" }, "locked": { - "lastModified": 1782379505, - "narHash": "sha256-zPvPiU+a7pqtH47xrtZLNRABJKpOjfZQclDbcvNtH+I=", + "lastModified": 1782562157, + "narHash": "sha256-a7+T6QSeowynwZ1ZJJbP8T8ntAytvrui8kFGJmIZt2c=", "owner": "NixOS", "repo": "nixos-hardware", - "rev": "603d3afd1b6145bd66e97ae38a34d91c95df70cf", + "rev": "a9cf7546a938c737b079e738de73934a13de9784", "type": "github" }, "original": { @@ -614,11 +656,11 @@ }, "nixpkgs-stable": { "locked": { - "lastModified": 1782188297, - "narHash": "sha256-imdcA5fgbHK259bhHlyiiSr7bMY1AZ6onOWDdAcydc4=", + "lastModified": 1782498288, + "narHash": "sha256-8/X3yyTXiE82b38n32ItbOqfWOVBl+gKa8fILyZfR4Q=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "9a1a7dbb18f0eb31c49b031babb8def7eab0af54", + "rev": "3cac626ec5e3703e835f227687e88aa9e2f25701", "type": "github" }, "original": { @@ -630,11 +672,11 @@ }, "nixpkgs-stable_2": { "locked": { - "lastModified": 1782233679, - "narHash": "sha256-QyuGP5+QOtmXpy4i2X4DhBVBaySBdDKQEhqKcphcp34=", + "lastModified": 1782535326, + "narHash": "sha256-ZeRxu4yn6shd3SNF5ZUQb4r7BaVo1zBKMjRhfoNSBmw=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "667d5cf1c59585031d743c78b394b0a647537c35", + "rev": "714a5f8c4ead6b31148d829288440ed033ccc041", "type": "github" }, "original": { @@ -659,11 +701,11 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1781577229, - "narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=", + "lastModified": 1782467914, + "narHash": "sha256-pGvFkM8N0xEkIIXDe5YYfbEAvHrk4IxBrjB/x8OomhE=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f", + "rev": "e73de5be04e0eff4190a1432b946d469c794e7b4", "type": "github" }, "original": { @@ -722,11 +764,11 @@ "systems": "systems_3" }, "locked": { - "lastModified": 1782369036, - "narHash": "sha256-jxbvrIvE+NklSd6HPNSdEhGr8RvwNj4b7Gd5tgEXwSQ=", + "lastModified": 1782660650, + "narHash": "sha256-d4Ndt82q9bhL+iKFr1reufZyE/MTdULzN3kEkXsNG88=", "owner": "NotAShelf", "repo": "nvf", - "rev": "096045d0e927bf7064989e9181a89b47c1b8779c", + "rev": "18d2d23191250c7f597d85da07d860eb05f9e1be", "type": "github" }, "original": { @@ -785,7 +827,7 @@ "otter-launcher": { "inputs": { "flake-parts": "flake-parts_3", - "home-manager": "home-manager_2", + "home-manager": "home-manager_3", "nixpkgs": [ "nixpkgs" ], @@ -810,6 +852,7 @@ "disko": "disko", "fsel": "fsel", "home-manager": "home-manager", + "impermanence": "impermanence", "microvm": "microvm", "niri": "niri", "nixos-hardware": "nixos-hardware", @@ -909,11 +952,11 @@ "rust-overlay": "rust-overlay" }, "locked": { - "lastModified": 1782333283, - "narHash": "sha256-57ycRZHQkootKokT5VDSVZIyeGGaq05G7i2iqh1NApI=", + "lastModified": 1782542860, + "narHash": "sha256-79L/yxMuJHS+Dfpt7y4wXvgNJILux0jv6mnVFxanqKc=", "owner": "gabm", "repo": "Satty", - "rev": "26848045f3565cb05f6c18ad9e0d8ca5b3a7e1c1", + "rev": "ff0c0d350d233f446c868e7ca4c13cfb67d0c43d", "type": "github" }, "original": { @@ -1155,11 +1198,11 @@ "rust-overlay": "rust-overlay_2" }, "locked": { - "lastModified": 1782458355, - "narHash": "sha256-qa+ReXlH0m+5SZrmUKWK3xAri4qE45M8FcmM4L7VC5s=", + "lastModified": 1782583823, + "narHash": "sha256-S52dg5T6iRjuED2e0bxzWeVM1Einbz5rJbB5wcruop4=", "owner": "sxyazi", "repo": "yazi", - "rev": "bf1274315dbcef858b46a55f212cfa34b916c3d3", + "rev": "21550a7eb5086ba34f8eabf8aaab85f601d34a74", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index f925335..7e6ca6e 100644 --- a/flake.nix +++ b/flake.nix @@ -8,6 +8,11 @@ # Hardware and gaming nixos-hardware.url = "github:NixOS/nixos-hardware/master"; + impermanence = { + url = "github:nix-community/impermanence"; + inputs.nixpkgs.follows = "nixpkgs"; + }; + nixos-mailserver = { # url = "gitlab:simple-nixos-mailserver/nixos-mailserver/nixos-26.05"; url = "gitlab:simple-nixos-mailserver/nixos-mailserver/main"; diff --git a/hosts/bibus-lab/disko.nix b/hosts/bibus-lab/disko.nix index 6ca17b9..203ec95 100644 --- a/hosts/bibus-lab/disko.nix +++ b/hosts/bibus-lab/disko.nix @@ -85,9 +85,6 @@ "rpool" = { type = "zfs_fs"; options = { - encryption = "on"; - keyformat = "passphrase"; - keylocation = "prompt"; mountpoint = "none"; compression = "zstd"; atime = "off"; @@ -107,6 +104,11 @@ type = "zfs_fs"; mountpoint = "/home"; }; + "rpool/persist" = { + type = "zfs_fs"; + mountpoint = "/persist"; + options.mountpoint = "legacy"; + }; "rpool/log" = { type = "zfs_fs"; mountpoint = "/var/log"; @@ -190,9 +192,6 @@ type = "zfs_fs"; mountpoint = "none"; options = { - encryption = "on"; - keyformat = "passphrase"; - keylocation = "prompt"; compression = "zstd"; atime = "off"; }; diff --git a/hosts/desktop/configuration.nix b/hosts/desktop/configuration.nix index 7e78c91..b910f8f 100644 --- a/hosts/desktop/configuration.nix +++ b/hosts/desktop/configuration.nix @@ -22,7 +22,7 @@ }; drivers = { enable = true; - kernel = "zen"; + # kernel = "zen"; cpu = "amd"; graphics = { enable = true; diff --git a/hosts/desktop/home.nix b/hosts/desktop/home.nix index 38f1469..374b007 100644 --- a/hosts/desktop/home.nix +++ b/hosts/desktop/home.nix @@ -98,5 +98,6 @@ gimp stow antigravity-cli + libnotify ]; } diff --git a/os/core/default.nix b/os/core/default.nix index 1146f2d..963436b 100644 --- a/os/core/default.nix +++ b/os/core/default.nix @@ -17,6 +17,7 @@ in ./security.nix ./storage.nix ./users.nix + ./zfs.nix ]; options.os.core = { diff --git a/os/core/networking.nix b/os/core/networking.nix index b94b540..9e4c329 100644 --- a/os/core/networking.nix +++ b/os/core/networking.nix @@ -20,20 +20,21 @@ in ips = lib.mkOption { type = lib.types.attrsOf lib.types.str; - default = rec { - router = opnsense-vm; - host = "10.0.0.2"; + default = { + bare-metal = "10.0.0.2"; opnsense-vm = "10.0.0.1"; gateway-vm = "10.0.0.3"; - databse-vm = "10.0.0.4"; - monitor-vm = "10.0.0.5"; - media-vm = "10.0.0.6"; - sandbox-vm = "10.0.0.7"; - storage-vm = "10.0.0.8"; - web-vm = "10.0.0.9"; - mail-vm = "10.0.0.10"; - relay-vm = "10.0.0.11"; - gameserver-vm = "10.0.0.12"; + auth-vm = "10.0.0.4"; + database-vm = "10.0.0.5"; + monitor-vm = "10.0.0.6"; + media-vm = "10.0.0.7"; + torrent-vm = "10.0.0.8"; + storage-vm = "10.0.0.9"; + web-vm = "10.0.0.10"; + comm-vm = "10.0.0.11"; + mail-vm = "10.0.0.12"; + relay-vm = "10.0.0.13"; + gameserver-vm = "10.0.0.14"; }; description = "Central registry of static IP allocations for the cluster."; }; diff --git a/os/core/persistance.nix b/os/core/persistance.nix new file mode 100644 index 0000000..89f3702 --- /dev/null +++ b/os/core/persistance.nix @@ -0,0 +1,50 @@ +{ + config, + lib, + inputs, + ... +}: +let + cfg = config.os.srv.persistance; +in +{ + imports = [ inputs.impermanence.nixosModules.impermanence ]; + + options.os.srv.persistance.enable = lib.mkEnableOption "enables persistance drive maintnance"; + config = lib.mkMerge [ + (lib.mkIf cfg.enable { + environment.persistence."/persist" = { + hideMounts = true; + directories = [ + "/var/lib/nixos" + "/var/lib/systemd" + "/var/lib/microvm" + ]; + files = [ + "/etc/machine-id" + ]; + }; + }) + (lib.mkIf (cfg.enable && config.os.srv.ssh.server.enable) { + environment.persistence."/persist" = { + files = [ + "/etc/ssh/ssh_host_ed25519_key" + "/etc/ssh/ssh_host_ed25519_key.pub" + ]; + }; + }) + (lib.mkIf (cfg.enable && config.os.srv.crowdsec.agent.enable) { + environment.persistence."/persist" = lib.mkIf cfg.agent.enable { + hideMounts = true; + directories = [ + { + directory = "/var/lib/crowdsec"; + user = "crowdsec"; + group = "crowdsec"; + mode = "0750"; + } + ]; + }; + }) + ]; +} diff --git a/os/core/users.nix b/os/core/users.nix index 494406b..ff45a99 100644 --- a/os/core/users.nix +++ b/os/core/users.nix @@ -43,7 +43,7 @@ in "render" ]) (lib.mkIf (config.os.core.network.enable or false) [ "networkmanager" ]) - (lib.mkIf (config.os.srv.virtualization.enable or false) [ "libvirtd" ]) + (lib.mkIf (config.os.srv.virtualization.kvm.enable or false) [ "libvirtd" ]) (lib.mkIf (config.os.srv.docker.enable or false) [ "docker" ]) ]; }; diff --git a/os/core/zfs.nix b/os/core/zfs.nix new file mode 100644 index 0000000..771644d --- /dev/null +++ b/os/core/zfs.nix @@ -0,0 +1,60 @@ +{ config, lib, ... }: +let + cfg = config.os.srv.zfs; +in +{ + options.os.srv.zfs.enable = lib.mkEnableOption "enables zfs drive maintnance"; + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = config.os.core.drivers.kernel == "zfs"; + message = "ZFS requires the zfs supported kernel"; + } + { + assertion = config.os.srv.sops.enable; + message = "required for storing the ntfy token"; + } + ]; + + sops.secrets."ntfy/zed".neededForUsers = false; + + boot = { + kernelParams = [ "zfs.zfs_arc_max=${toString (32 * 1024 * 1024 * 1024)}" ]; + zfs = { + # requestEncryptionCredentials = [ "zroot" ]; + # useKeyringForCredentials = true; + extraPools = [ "tank" ]; + }; + supportedFilesystems = [ "zfs" ]; + initrd.supportedFilesystems = [ "zfs" ]; + }; + services.zfs = { + expandOnBoot = "all"; + autoScrub.enable = true; + trim.enable = true; + autoSnapshot = { + enable = true; + flags = "-k -p --utc"; + }; + zed = { + settings = { + ZED_DEBUG_LOG = "/var/log/zed.debug.log"; + + ZED_NOTIFY_INTERVAL_SECS = 3600; + ZED_NOTIFY_VERBOSE = 0; + + ZED_USE_ENCLOSURE_LEDS = 1; + ZED_SCRUB_AFTER_RESILVER = 1; + ZED_POWER_OFF_ENCLOSURE_SLOT_ON_FAULT = 1; + ZED_POWER_OFF_ENCLOSURE_SLOT_ON_DEADMAN = 1; + + ZED_NTFY_TOPIC = "zed-alerts-bibus-lab"; + ZED_NTFY_URL = "http://${config.os.core.network.ips.monitor-vm}:8085"; + }; + }; + }; + systemd.services.zfs-zed.serviceConfig.EnvironmentFile = config.sops.secrets."ntfy/zed".path; + networking.hostId = "4e3e22e1"; + + }; +} diff --git a/os/srv/avahi.nix b/os/srv/avahi.nix new file mode 100644 index 0000000..f14b33a --- /dev/null +++ b/os/srv/avahi.nix @@ -0,0 +1,41 @@ +{ config, lib, ... }: +let + cfg = config.os.srv.avahi; +in +{ + options.os.srv.avahi.enable = lib.mkEnableOption "enables avahis"; + config = lib.mkIf cfg.enable { + services.avahi = { + enable = true; + ipv4 = true; + + publish = { + enable = true; + addresses = true; + workstation = true; + }; + + nssmdns4 = true; + + extraServiceFiles = { + nfs = '' + + + + NFS Share on %h + + _nfs._tcp + 2049 + path=/data/vault + + + _nfs._tcp + 2049 + path=/data/media + + + ''; + }; + }; + }; +} diff --git a/os/srv/backup.nix b/os/srv/backup.nix index 3d1d583..e7c07f9 100644 --- a/os/srv/backup.nix +++ b/os/srv/backup.nix @@ -58,7 +58,8 @@ in syncoid = { enable = true; commonArgs = [ - "-w" + "-c" + "-p" "--delete-target-snapshots" "--use-hold" "--no-sync-snap" diff --git a/os/srv/crowdsec.nix b/os/srv/crowdsec.nix index 71818bd..c3df81b 100644 --- a/os/srv/crowdsec.nix +++ b/os/srv/crowdsec.nix @@ -1,4 +1,9 @@ -{ config, lib, ... }: +{ + config, + lib, + masterDomain, + ... +}: let cfg = config.os.srv.security.crowdsec; in @@ -22,14 +27,71 @@ in } ]; + sops = { + secrets."crowdsec/env" = { + owner = "crowdsec"; + group = "crowdsec"; + restartUnits = [ "crowdsec.service" ]; + }; + + templates."local_api_credentials.yaml" = { + owner = "crowdsec"; + group = "crowdsec"; + restartUnits = [ "crowdsec.service" ]; + content = '' + url: http://${config.os.core.network.ips.gateway-vm}:8080 + login: ${config.networking.hostName} + password: ${config.sops.placeholder."crowdsec/client_password"} + ''; + }; + }; + + systemd.services.crowdsec.serviceConfig.EnvironmentFile = config.sops.secrets."crowdsec/env".path; + services.crowdsec = { enable = true; autoUpdateService = true; - openFirewall = cfg.aggregator.enable; + openFirewall = true; settings = { - api.server.enable = cfg.aggregator.enable; + common = { + compress_logs = true; + log_format = "json"; + }; + prometheus = { + enabled = true; + level = "full"; + listen_addr = "0.0.0.0"; + listen_port = 6060; + }; + db_config = { + type = "postgresql"; + host = config.os.core.network.ips.database-vm; + port = 5432; + db_name = "crowdsec"; + user = "crowdsec"; + password = "$CROWDSEC_DB_PASSWORD"; + sslmode = "require"; + }; + + api = { + server = { + enable = cfg.aggregator.enable; + listen_uri = "0.0.0.0:8080"; + trusted_ips = [ + "127.0.0.1" + "10.0.0.0/24" + ]; + + auto_registration = { + enabled = cfg.aggregator.enable; + token = "$CROWDSEC_REGISTER_TOKEN"; + allowed_ranges = [ "10.0.0.0/24" ]; + }; + }; + client.credentials_path = config.sops.templates."local_api_credentials.yaml".path; + }; lapi.client.api_url = "http://${config.os.core.network.ips.gateway-vm}:8080"; }; @@ -82,11 +144,11 @@ in name = "ntfy_alerts"; type = "http"; method = "POST"; - #TODO add ntfy sops thing - url = "https://ntfy.sh/your_secret_topic_here"; + url = "https://ntfy.${masterDomain}/crowdsec-alerts"; headers = { Title = "CrowdSec Alert on Bibus-Lab"; Priority = "high"; + Authorization = "$NTFY_AUTH_TOKEN"; }; format = '' {{range .}} {{.Alert.Message}} (Scenario: {{.Alert.Scenario}}) from IP {{.Alert.Source.IP}} {{end}} @@ -105,8 +167,8 @@ in settings = { mode = "nftables"; update_frequency = "10s"; - api_url = "http://${config.os.core.network.ips.gateway-vm}:8080"; + api_key = lib.mkIf cfg.aggregator.enable "$CROWDSEC_LOCAL_BOUNCER_KEY"; }; }; diff --git a/os/srv/default.nix b/os/srv/default.nix index 073067d..c89d029 100644 --- a/os/srv/default.nix +++ b/os/srv/default.nix @@ -44,6 +44,5 @@ ./virtualization.nix ./wireguard.nix ./yggdrasil.nix - ./zfs.nix ]; } diff --git a/os/srv/dns.nix b/os/srv/dns.nix index 2da4c66..b8a973f 100644 --- a/os/srv/dns.nix +++ b/os/srv/dns.nix @@ -77,12 +77,21 @@ in ]; rewrites = [ { - domain = "router.local"; - answer = config.os.core.network.ips.vm1-opnsense; + domain = "router.lan"; + answer = config.os.core.network.ips.opnsense-vm; + } + { + domain = "nas.lan"; + answer = config.os.core.network.ips.bare-metal; + } + { + domain = "ldap.${masterDomain}"; + answer = config.os.core.network.ips.gateway-vm; } ]; port = 53; upstream_dns = [ "127.0.0.1:${toString unboundPort}" ]; + fallback_dns = [ "9.9.9.9" ]; bootstrap_dns = [ "9.9.9.9" ]; cache_size = 536870912; anonymize_client_ip = true; diff --git a/os/srv/gaming.nix b/os/srv/gaming.nix index 730dcd2..b9b6766 100644 --- a/os/srv/gaming.nix +++ b/os/srv/gaming.nix @@ -103,35 +103,10 @@ in } (lib.mkIf cfg.steam.enableSls { + environment.systemPackages = [ + inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped + ]; home-manager.users.${username} = { - imports = [ inputs.sls-steam.homeModules.sls-steam ]; - - services.sls-steam.config = { - PlayNotOwnedGames = true; - DisableFamilyShareLock = true; - SafeMode = false; - AdditionalApps = [ - 2483190 - 4439260 - 4439270 - 4439280 - 4439300 - 4439750 - 4439790 - 4439800 - 4439810 - 4439820 - 4439830 - 4440380 - 4444140 - 4444150 - 4520350 - 4520360 - 4562050 - ]; - }; - home.packages = [ inputs.sls-steam.packages.${pkgs.stdenv.hostPlatform.system}.wrapped ]; - xdg.desktopEntries = { steam = { name = "Steam"; diff --git a/os/srv/lldap.nix b/os/srv/lldap.nix index 1463ab6..6755dfe 100644 --- a/os/srv/lldap.nix +++ b/os/srv/lldap.nix @@ -2,7 +2,6 @@ config, lib, masterDomain, - securityTemplates, ... }: let @@ -49,16 +48,6 @@ in environmentFile = config.sops.secrets."lldap/env_file".path; }; - os.cluster.nginxProxies."lldap.${masterDomain}" = { - enableACME = true; - forceSSL = true; - - locations."/" = { - proxyPass = "http://${config.os.core.network.ips.gateway-vm}:17170"; - extraConfig = securityTemplates.restrictToInternal; - }; - }; - networking.firewall.extraInputRules = '' ip saddr 10.0.0.0/24 tcp dport 3890 accept ''; diff --git a/os/srv/monero.nix b/os/srv/monero.nix index 6b50e1d..eb21abc 100644 --- a/os/srv/monero.nix +++ b/os/srv/monero.nix @@ -81,24 +81,24 @@ in }; services.tor = lib.mkIf cfg.service.tor.enable { - onionServices."xmr-rpc" = { - to = [ - { - port = 18081; - address = config.os.core.network.ips.vm9-relays; - } - ]; - }; + # onionServices."xmr-rpc" = { + # to = [ + # { + # port = 18081; + # address = config.os.core.network.ips.relay-vm; + # } + # ]; + # }; }; services.i2pd = lib.mkIf cfg.service.i2p.enable { - tunnels.server."xmr-rpc" = { - port = 18081; - address = config.os.core.network.ips.vm9-relays; - keys = "xmr-rpc-key.dat"; - inbound.length = 3; - outbound.length = 3; - }; + # tunnels.server."xmr-rpc" = { + # port = 18081; + # address = config.os.core.network.ips.relay-vm; + # keys = "xmr-rpc-key.dat"; + # inbound.length = 3; + # outbound.length = 3; + # }; }; os.cluster.nginxProxies."xmr.${masterDomain}" = { @@ -106,7 +106,7 @@ in forceSSL = true; locations."/" = { - proxyPass = "http://${config.os.core.network.ips.vm9-relays}:18081"; + proxyPass = "http://${config.os.core.network.ips.relay-vm}:18081"; extraConfig = '' proxy_read_timeout 600s; proxy_send_timeout 600s; diff --git a/os/srv/simplex.nix b/os/srv/simplex.nix index 51b9577..ca22192 100644 --- a/os/srv/simplex.nix +++ b/os/srv/simplex.nix @@ -73,19 +73,6 @@ in }; }; - services.nginx = { - streamConfig = '' - server { - listen 5223; - proxy_pass 127.0.0.1:${toString internalSmpPort}; - } - server { - listen 5224; - proxy_pass 127.0.0.1:${toString internalXftpPort}; - } - ''; - }; - systemd.tmpfiles.rules = [ "d /var/lib/simplex/smp/config 0755 root root -" "d /var/lib/simplex/smp/logs 0755 root root -" diff --git a/os/srv/ssh.nix b/os/srv/ssh.nix index d36df00..63b2034 100644 --- a/os/srv/ssh.nix +++ b/os/srv/ssh.nix @@ -10,11 +10,7 @@ let in { options.os.srv.ssh = { - server = { - enable = lib.mkEnableOption "enables the ssh server module"; - enableInitrd = lib.mkEnableOption "enables ssh access during initrd"; - microvm.enable = lib.mkEnableOption "enables ssh for microvms"; - }; + server.enable = lib.mkEnableOption "enables the ssh server module"; client = { enable = lib.mkEnableOption "enables the ssh client module"; createAliases = lib.mkEnableOption "enables system-wide SSH shortcuts"; @@ -32,19 +28,19 @@ in addr = "127.0.0.1"; port = 22; } - { - addr = config.os.core.network.lan.ip; - port = 22; - } - { - addr = config.os.core.network.wg.ip; - port = 22; - } - { - addr = config.os.core.network.hs.ip; - port = 22; - } - ]; + ] + ++ lib.optional (config.os.core.network ? lan.ip) { + addr = config.os.core.network.lan.ip; + port = 22; + } + ++ lib.optional (config.os.core.network ? wg.ip) { + addr = config.os.core.network.wg.ip; + port = 22; + } + ++ lib.optional (config.os.core.network ? hs.ip) { + addr = config.os.core.network.hs.ip; + port = 22; + }; hostKeys = [ { path = "/etc/ssh/ssh_host_ed25519_key"; @@ -54,7 +50,7 @@ in settings = { PasswordAuthentication = false; KbdInteractiveAuthentication = false; - PermitRootLogin = if cfg.server.microvm.enable then "prohibit-password" else "no"; + PermitRootLogin = "no"; PubkeyAcceptedAlgorithms = "ssh-ed25519"; }; @@ -69,41 +65,6 @@ in ); }) - (lib.mkIf (cfg.server.enable && cfg.server.microvm.enable) { - users.users.root.openssh.authorizedKeys.keys = [ - "${keys.main} adikro@disroot.org" - ]; - }) - - (lib.mkIf (cfg.server.enable && cfg.server.enableInitrd) { - assertions = [ - { - assertion = config.os.srv.sops.enable; - message = "required for storing the ssh key"; - } - ]; - sops.secrets."initrd_ssh_key" = { - path = "/etc/secrets/initrd/ssh_host_ed25519_key"; - }; - boot = { - initrd = { - secrets = { - "/etc/secrets/initrd/ssh_host_ed25519_key" = config.sops.secrets.initrd_ssh_key.path; - }; - network = { - enable = true; - ssh = { - enable = true; - port = 2222; - authorizedKeys = [ "${keys.main}" ]; - hostKeys = [ "/etc/secrets/initrd/ssh_host_ed25519_key" ]; - }; - }; - }; - kernelParams = [ "ip=dhcp" ]; - }; - }) - (lib.mkIf cfg.client.enable { programs.ssh.startAgent = true; services.gnome.gcr-ssh-agent.enable = false; diff --git a/os/srv/zfs.nix b/os/srv/zfs.nix deleted file mode 100644 index 3bfd2de..0000000 --- a/os/srv/zfs.nix +++ /dev/null @@ -1,60 +0,0 @@ -{ config, lib, ... }: -let - cfg = config.os.srv.zfs; -in -{ - options.os.srv.zfs.enable = lib.mkEnableOption "enables zfs drive maintnance"; - config = lib.mkIf cfg.enable { - assertions = [ - { - assertion = config.os.core.drivers.kernel == "zfs"; - message = "ZFS requires the zfs supported kernel"; - } - { - assertion = config.os.srv.sops.enable; - message = "required for storing the ntfy token"; - } - ]; - - sops.secrets."ntfy/zed".neededForUsers = false; - - boot = { - kernelParams = [ "zfs.zfs_arc_max=${toString (32 * 1024 * 1024 * 1024)}" ]; - zfs = { - requestEncryptionCredentials = [ "zroot" ]; - useKeyringForCredentials = true; - extraPools = [ "tank" ]; - }; - supportedFilesystems = [ "zfs" ]; - initrd.supportedFilesystems = [ "zfs" ]; - }; - services.zfs = { - expandOnBoot = "all"; - autoScrub.enable = true; - trim.enable = true; - autoSnapshot = { - enable = true; - flags = "-k -p --utc"; - }; - zed = { - enableCustomScripts = true; - settings = { - ZED_DEBUG_LOG = "/var/log/zed.debug.log"; - - ZED_NOTIFY_INTERVAL_SECS = 3600; - ZED_NOTIFY_VERBOSE = 0; - - ZED_USE_ENCLOSURE_LEDS = 1; - ZED_SCRUB_AFTER_RESILVER = 1; - ZED_POWER_OFF_ENCLOSURE_SLOT_ON_FAULT = 1; - ZED_POWER_OFF_ENCLOSURE_SLOT_ON_DEADMAN = 1; - - ZED_NTFY_TOPIC = "zed-alerts-bibus-lab"; - ZED_NTFY_URL = "http://${config.os.core.network.ips.monitor-vm}:8085"; - }; - }; - }; - systemd.services.zfs-zed.serviceConfig.EnvironmentFile = config.sops.secrets."ntfy/zed".path; - networking.hostId = "4e3e22e1"; - }; -} diff --git a/os/vms/microvms.nix b/os/vms/microvms.nix index 0a24c60..e2e1a0f 100644 --- a/os/vms/microvms.nix +++ b/os/vms/microvms.nix @@ -23,9 +23,6 @@ in }; config = lib.mkMerge [ - (lib.mkIf cfg.enable { - }) - (lib.mkIf cfg.net-core.enable { microvm.vms.net-core = { autostart = true; -- cgit v1.3