Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f981d6e7a0 | ||
|
|
5d9ca52386 | ||
|
|
ddc2499722 | ||
|
|
33eb968705 | ||
|
|
d01d0c4875 | ||
|
|
c26813c2b8 | ||
|
|
e9c5da2710 | ||
|
|
50cae2c29b | ||
|
|
c2e3686be1 | ||
|
|
a1ba8775f4 | ||
|
|
3d50e3d00c | ||
|
|
2adc19297b | ||
|
|
bf77664a3f | ||
|
|
00efceadb5 | ||
|
|
40d90d8ecc | ||
|
|
144fe5becd | ||
|
|
8b3bcaed14 | ||
|
|
c0d5244002 | ||
|
|
8b0206d19f | ||
|
|
f8b68f2432 | ||
|
|
a4a69c85b8 | ||
|
|
3226f6cc2c | ||
|
|
d60b5b6093 | ||
|
|
ca79ed7f98 | ||
|
|
abaa51335d | ||
|
|
f5fa620213
|
||
|
|
b8ef55faea
|
||
|
|
3635e27a5a
|
||
|
|
48387f85ea | ||
|
|
23122047f2 | ||
|
|
44604dbe01 |
@@ -1,5 +1,5 @@
|
|||||||
# Disks
|
# Disks
|
||||||
The disks module can be used by importing `inputs.self.nixosModules.malobeo.disko`
|
The disks module can be used by importing `inputs.malobeo.nixosModules.malobeo.disko`
|
||||||
|
|
||||||
|
|
||||||
#### `let cfg = malobeo.disks`
|
#### `let cfg = malobeo.disks`
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
# Gitea-tanslator
|
# Gitea-tanslator
|
||||||
The module can be used by importing `inputs.self.nixosModules.malobeo.gitea-translator`
|
The module can be used by importing `inputs.malobeo.nixosModules.malobeo.gitea-translator`
|
||||||
|
|
||||||
This module starts a python server that fetches the gitea pull request api and translates it to a file that hydra understands.
|
This module starts a python server that fetches the gitea pull request api and translates it to a file that hydra understands.
|
||||||
To use, just set the parameters of the gitea server, then send a GET request to either `http://${host}:${port}/` or `http://${host}:${port}/gitea-pulls-sorted.json`
|
To use, just set the parameters of the gitea server, then send a GET request to either `http://${host}:${port}/` or `http://${host}:${port}/gitea-pulls-sorted.json`
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
# Initrd-ssh
|
# Initrd-ssh
|
||||||
The initssh module can be used by importing `inputs.self.nixosModules.malobeo.initssh`
|
The initssh module can be used by importing `inputs.malobeo.nixosModules.malobeo.initssh`
|
||||||
|
|
||||||
#### `let cfg = malobeo.initssh`
|
#### `let cfg = malobeo.initssh`
|
||||||
|
|
||||||
@@ -26,4 +26,4 @@ Run ` lspci -k | grep -iA4 ethernet `
|
|||||||
` [ ] `
|
` [ ] `
|
||||||
|
|
||||||
*Example:*
|
*Example:*
|
||||||
`[ "r8169" ]`
|
`[ "r8169" ]`
|
||||||
|
|||||||
Generated
+124
-25
@@ -29,11 +29,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1768143854,
|
"lastModified": 1788076475,
|
||||||
"narHash": "sha256-E5/kyPz4zAZn/lZdvqlF83jMgCWNxmqYjjWuadngCbk=",
|
"narHash": "sha256-sD4UyILWAhk7aexE3YpDOdb71ZEeL+1/+LV05XIWCBo=",
|
||||||
"owner": "kirelagin",
|
"owner": "kirelagin",
|
||||||
"repo": "dns.nix",
|
"repo": "dns.nix",
|
||||||
"rev": "a97cf4156e9f044fe4bed5be531061000dfabb07",
|
"rev": "4710a34f2c36e7a0d634d7ba8fe2499d75f012a2",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -78,6 +78,29 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"gatekeeper": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"nixpkgs-unstable"
|
||||||
|
],
|
||||||
|
"pyproject-build-systems": "pyproject-build-systems",
|
||||||
|
"pyproject-nix": "pyproject-nix",
|
||||||
|
"uv2nix": "uv2nix"
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1786138873,
|
||||||
|
"narHash": "sha256-+G/hTquaK4AjYxNSJTpcZXUEKxFDv9lOn3x+lHHTWJw=",
|
||||||
|
"ref": "refs/heads/master",
|
||||||
|
"rev": "c5934d05c6f01c94c36221deb7ed4de03aa91ca1",
|
||||||
|
"revCount": 127,
|
||||||
|
"type": "git",
|
||||||
|
"url": "https://git.dynamicdiscord.de/malobeo/gatekeeper"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"type": "git",
|
||||||
|
"url": "https://git.dynamicdiscord.de/malobeo/gatekeeper"
|
||||||
|
}
|
||||||
|
},
|
||||||
"home-manager": {
|
"home-manager": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
@@ -85,11 +108,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781319724,
|
"lastModified": 1787377438,
|
||||||
"narHash": "sha256-ZGuxexEMo4Xv28KJ0dX/m/PHN4oZIOnxHZpNTyrvx4M=",
|
"narHash": "sha256-Sxu1NLTD/Ern6hFGLlZmtKCSct3YQXZI/lls8RE1XeM=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "home-manager",
|
"repo": "home-manager",
|
||||||
"rev": "8355f0a16b2dbb06a97959a918af5b239bbe05ae",
|
"rev": "65258d5c65a250189fde2e35f490d15e064c4c62",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -126,11 +149,11 @@
|
|||||||
"spectrum": "spectrum"
|
"spectrum": "spectrum"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781389237,
|
"lastModified": 1788263502,
|
||||||
"narHash": "sha256-Ne1/E5XNUq0gleaQz0vW5R4xf/0h/uEZ+bOW1aNjeQk=",
|
"narHash": "sha256-gyVqW5U9wy6A8voJNu6SiSYTKDplo/MDl31x7FszWlk=",
|
||||||
"owner": "astro",
|
"owner": "astro",
|
||||||
"repo": "microvm.nix",
|
"repo": "microvm.nix",
|
||||||
"rev": "6ad601df0a07d9855c5e8f9b81135ecaf7c287eb",
|
"rev": "974d315e504e666eac4920d712e3ff6804dc1502",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -180,11 +203,11 @@
|
|||||||
"nixpkgs": "nixpkgs_2"
|
"nixpkgs": "nixpkgs_2"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781622756,
|
"lastModified": 1788335262,
|
||||||
"narHash": "sha256-JrPh4M6S7aPsEE9tOENuZrxC6o2szSLlK+t4+nLke9s=",
|
"narHash": "sha256-3jBEq8avfzlrsY4UpW4d5TOmm7ocseZfnitEJhqauyc=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixos-hardware",
|
"repo": "nixos-hardware",
|
||||||
"rev": "08018c72174a4df5657f8d94178ac69fb9c243e5",
|
"rev": "44d95795ee2d475b3d687325e26dcf4ca9104557",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -212,11 +235,11 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs-unstable": {
|
"nixpkgs-unstable": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781577229,
|
"lastModified": 1788179007,
|
||||||
"narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=",
|
"narHash": "sha256-hn1oU2rue2SYK8dAr8+WNZWtbsz1S2W5mnHlSEuh3bo=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "567a49d1913ce81ac6e9582e3553dd90a955875f",
|
"rev": "34ab99075ac4f7e40cf037eef32cb1c360bb85e9",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -241,11 +264,11 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs_3": {
|
"nixpkgs_3": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781216227,
|
"lastModified": 1788187754,
|
||||||
"narHash": "sha256-9mUW6gNwoN2SWc/l0fW4svPNOulXLl8ijqKyeSOGgJE=",
|
"narHash": "sha256-bu1QxmXKmPuvBLN7bHP355OV9Qo13x9WCiRDH62CqRM=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "a0374025a863d007d98e3297f6aa46cc3141c2f0",
|
"rev": "5dfba6236110080a54247d6460bc2ff5dda939cc",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -255,11 +278,62 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"pyproject-build-systems": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"gatekeeper",
|
||||||
|
"nixpkgs"
|
||||||
|
],
|
||||||
|
"pyproject-nix": [
|
||||||
|
"gatekeeper",
|
||||||
|
"pyproject-nix"
|
||||||
|
],
|
||||||
|
"uv2nix": [
|
||||||
|
"gatekeeper",
|
||||||
|
"uv2nix"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1776659114,
|
||||||
|
"narHash": "sha256-qapCOQmR++yZSY43dzrp3wCrkOTLpod+ONtJWBk6iKU=",
|
||||||
|
"owner": "pyproject-nix",
|
||||||
|
"repo": "build-system-pkgs",
|
||||||
|
"rev": "ffaa2161dd5d63e0e94591f86b54fc239660fb2e",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "pyproject-nix",
|
||||||
|
"repo": "build-system-pkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"pyproject-nix": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"gatekeeper",
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1778901413,
|
||||||
|
"narHash": "sha256-GSKXTAnFqRAMlZkJrIPcQMYf+lpMr66K3i60mB9STvc=",
|
||||||
|
"owner": "pyproject-nix",
|
||||||
|
"repo": "pyproject.nix",
|
||||||
|
"rev": "a228447c3e179d477c1b6246ef3efa8cfe3c469a",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "pyproject-nix",
|
||||||
|
"repo": "pyproject.nix",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
"root": {
|
"root": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"disko": "disko",
|
"disko": "disko",
|
||||||
"dns": "dns",
|
"dns": "dns",
|
||||||
"ep3-bs": "ep3-bs",
|
"ep3-bs": "ep3-bs",
|
||||||
|
"gatekeeper": "gatekeeper",
|
||||||
"home-manager": "home-manager",
|
"home-manager": "home-manager",
|
||||||
"mfsync": "mfsync",
|
"mfsync": "mfsync",
|
||||||
"microvm": "microvm",
|
"microvm": "microvm",
|
||||||
@@ -280,11 +354,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1780547341,
|
"lastModified": 1788337237,
|
||||||
"narHash": "sha256-Gq8KNx5A7hBB3uGJaj6eQfLDIz5YdLu92gqBcvHvoUo=",
|
"narHash": "sha256-gkSH8VUtCo6hnysNmb9DbTuDepH2t5pv+QWjP75xKAk=",
|
||||||
"owner": "Mic92",
|
"owner": "Mic92",
|
||||||
"repo": "sops-nix",
|
"repo": "sops-nix",
|
||||||
"rev": "9ed65852b6257fbeae4355bc24ecfea307ca759a",
|
"rev": "fbf759290e0cb0a98dfc813a4eb7d53ad1dacb57",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -296,11 +370,11 @@
|
|||||||
"spectrum": {
|
"spectrum": {
|
||||||
"flake": false,
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1778940603,
|
"lastModified": 1785761586,
|
||||||
"narHash": "sha256-voSM8dZNlaOWN3kbYFky+FNY6fFQOEw0xF+ZMpZKkCQ=",
|
"narHash": "sha256-MWOMVqJJERwjQGgRIv8d6rlEBqbLM3VZWxHkNKIIZNw=",
|
||||||
"ref": "refs/heads/main",
|
"ref": "refs/heads/main",
|
||||||
"rev": "367dd227f539267eae2b62770b4c17b88ac8c1f1",
|
"rev": "a7762d6f54b40560dd5255ce902e6e6a5d980fe9",
|
||||||
"revCount": 1265,
|
"revCount": 1416,
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "https://spectrum-os.org/git/spectrum"
|
"url": "https://spectrum-os.org/git/spectrum"
|
||||||
},
|
},
|
||||||
@@ -461,6 +535,31 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"uv2nix": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"gatekeeper",
|
||||||
|
"nixpkgs"
|
||||||
|
],
|
||||||
|
"pyproject-nix": [
|
||||||
|
"gatekeeper",
|
||||||
|
"pyproject-nix"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1779269674,
|
||||||
|
"narHash": "sha256-P1LHCRdYpdtHAEzuEsNHrI6d9mVPl5a2fyFDZGHNVbI=",
|
||||||
|
"owner": "pyproject-nix",
|
||||||
|
"repo": "uv2nix",
|
||||||
|
"rev": "69aec536f6d1acc415ed2e20299312802aba98c6",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "pyproject-nix",
|
||||||
|
"repo": "uv2nix",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
"zineshop": {
|
"zineshop": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
|
|||||||
@@ -37,6 +37,11 @@
|
|||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
};
|
};
|
||||||
|
|
||||||
|
gatekeeper = {
|
||||||
|
url = "git+https://git.dynamicdiscord.de/malobeo/gatekeeper";
|
||||||
|
inputs.nixpkgs.follows = "nixpkgs-unstable";
|
||||||
|
};
|
||||||
|
|
||||||
nixos-generators = {
|
nixos-generators = {
|
||||||
url = "github:nix-community/nixos-generators";
|
url = "github:nix-community/nixos-generators";
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
|||||||
@@ -15,17 +15,18 @@ in
|
|||||||
sops.secrets.wg_private = {};
|
sops.secrets.wg_private = {};
|
||||||
|
|
||||||
imports =
|
imports =
|
||||||
[ # Include the results of the hardware scan.
|
[
|
||||||
|
inputs.malobeo.nixosModules.malobeo.vpn
|
||||||
|
inputs.malobeo.nixosModules.malobeo.initssh
|
||||||
|
inputs.malobeo.nixosModules.malobeo.disko
|
||||||
|
inputs.malobeo.nixosModules.malobeo.metrics
|
||||||
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
inputs.malobeo.nixosModules.malobeo.backup
|
||||||
|
|
||||||
#./hardware-configuration.nix
|
#./hardware-configuration.nix
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/minimal_tools.nix
|
../modules/minimal_tools.nix
|
||||||
../modules/autoupdate.nix
|
../modules/autoupdate.nix
|
||||||
inputs.self.nixosModules.malobeo.vpn
|
|
||||||
inputs.self.nixosModules.malobeo.initssh
|
|
||||||
inputs.self.nixosModules.malobeo.disko
|
|
||||||
inputs.self.nixosModules.malobeo.metrics
|
|
||||||
inputs.self.nixosModules.malobeo.users
|
|
||||||
inputs.self.nixosModules.malobeo.backup
|
|
||||||
./hydra.nix
|
./hydra.nix
|
||||||
./gitea_runner.nix
|
./gitea_runner.nix
|
||||||
];
|
];
|
||||||
|
|||||||
@@ -15,7 +15,7 @@
|
|||||||
|
|
||||||
imports =
|
imports =
|
||||||
[
|
[
|
||||||
inputs.self.nixosModules.malobeo.gitea-translator
|
inputs.malobeo.nixosModules.malobeo.gitea-translator
|
||||||
];
|
];
|
||||||
|
|
||||||
services.malobeo.gitea-translator = {
|
services.malobeo.gitea-translator = {
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ self, config, lib, pkgs, inputs, ... }:
|
{ config, lib, pkgs, inputs, ... }:
|
||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
|
|
||||||
@@ -22,7 +22,8 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
self.nixosModules.malobeo.users
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
|||||||
@@ -6,13 +6,14 @@ in
|
|||||||
{
|
{
|
||||||
imports =
|
imports =
|
||||||
[ # Include the results of the hardware scan.
|
[ # Include the results of the hardware scan.
|
||||||
|
inputs.malobeo.nixosModules.malobeo.disko
|
||||||
|
inputs.malobeo.nixosModules.malobeo.initssh
|
||||||
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
#./hardware-configuration.nix
|
#./hardware-configuration.nix
|
||||||
../modules/xserver.nix
|
../modules/xserver.nix
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/autoupdate.nix
|
../modules/autoupdate.nix
|
||||||
inputs.self.nixosModules.malobeo.disko
|
|
||||||
inputs.self.nixosModules.malobeo.initssh
|
|
||||||
inputs.self.nixosModules.malobeo.users
|
|
||||||
];
|
];
|
||||||
|
|
||||||
malobeo.autoUpdate = {
|
malobeo.autoUpdate = {
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ config, self, lib, pkgs, inputs, ... }:
|
{ config, lib, pkgs, inputs, ... }:
|
||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
|
|
||||||
@@ -17,14 +17,19 @@ with lib;
|
|||||||
];
|
];
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
self.nixosModules.malobeo.metrics
|
inputs.malobeo.nixosModules.malobeo.metrics
|
||||||
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
inputs.tasklist.nixosModules.malobeo-tasklist
|
inputs.tasklist.nixosModules.malobeo-tasklist
|
||||||
|
|
||||||
../modules/malobeo_user.nix
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/minimal_tools.nix
|
../modules/minimal_tools.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
malobeo.metrics = {
|
malobeo.metrics = {
|
||||||
enable = true;
|
enable = true;
|
||||||
enablePromtail = true;
|
enablePromtail = true;
|
||||||
|
|||||||
@@ -11,18 +11,19 @@ in
|
|||||||
sops.secrets.njala_api_key = {};
|
sops.secrets.njala_api_key = {};
|
||||||
|
|
||||||
imports =
|
imports =
|
||||||
[ # Include the results of the hardware scan.
|
[
|
||||||
|
inputs.malobeo.nixosModules.malobeo.vpn
|
||||||
|
inputs.malobeo.nixosModules.malobeo.initssh
|
||||||
|
inputs.malobeo.nixosModules.malobeo.disko
|
||||||
|
inputs.malobeo.nixosModules.malobeo.microvm
|
||||||
|
inputs.malobeo.nixosModules.malobeo.metrics
|
||||||
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
inputs.malobeo.nixosModules.malobeo.backup
|
||||||
|
|
||||||
#./hardware-configuration.nix
|
#./hardware-configuration.nix
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/minimal_tools.nix
|
../modules/minimal_tools.nix
|
||||||
../modules/autoupdate.nix
|
../modules/autoupdate.nix
|
||||||
inputs.self.nixosModules.malobeo.vpn
|
|
||||||
inputs.self.nixosModules.malobeo.initssh
|
|
||||||
inputs.self.nixosModules.malobeo.disko
|
|
||||||
inputs.self.nixosModules.malobeo.microvm
|
|
||||||
inputs.self.nixosModules.malobeo.metrics
|
|
||||||
inputs.self.nixosModules.malobeo.users
|
|
||||||
inputs.self.nixosModules.malobeo.backup
|
|
||||||
./dyndns.nix
|
./dyndns.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
@@ -192,7 +193,7 @@ in
|
|||||||
proxyPass = "http://${hosts.malobeo.hosts.nextcloud.network.address}";
|
proxyPass = "http://${hosts.malobeo.hosts.nextcloud.network.address}";
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
client_max_body_size ${inputs.self.nixosConfigurations.nextcloud.config.services.nextcloud.maxUploadSize};
|
client_max_body_size ${inputs.malobeo.nixosConfigurations.nextcloud.config.services.nextcloud.maxUploadSize};
|
||||||
client_body_timeout 3600s;
|
client_body_timeout 3600s;
|
||||||
send_timeout 3600s;
|
send_timeout 3600s;
|
||||||
fastcgi_buffers 64 4K;
|
fastcgi_buffers 64 4K;
|
||||||
@@ -207,7 +208,7 @@ in
|
|||||||
proxyPass = "http://${hosts.malobeo.hosts.nextcloud.network.address}";
|
proxyPass = "http://${hosts.malobeo.hosts.nextcloud.network.address}";
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
client_max_body_size ${inputs.self.nixosConfigurations.nextcloud.config.services.nextcloud.maxUploadSize};
|
client_max_body_size ${inputs.malobeo.nixosConfigurations.nextcloud.config.services.nextcloud.maxUploadSize};
|
||||||
client_body_timeout 3600s;
|
client_body_timeout 3600s;
|
||||||
send_timeout 3600s;
|
send_timeout 3600s;
|
||||||
fastcgi_buffers 64 4K;
|
fastcgi_buffers 64 4K;
|
||||||
@@ -315,14 +316,16 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
virtualHosts."www.rm16bleibt.org" = {
|
virtualHosts."rm16bleibt.org" = {
|
||||||
forceSSL = true;
|
forceSSL = true;
|
||||||
enableACME = true;
|
enableACME = true;
|
||||||
locations."/" = {
|
locations."/" = {
|
||||||
proxyPass = "http://${hosts.malobeo.hosts.wordpress.network.address}:80";
|
proxyPass = "http://${hosts.malobeo.hosts.wordpress.network.address}";
|
||||||
recommendedProxySettings = true;
|
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_set_header X-Forwarded-Host $host;
|
||||||
proxy_set_header X-Forwarded-Port 443;
|
proxy_set_header X-Forwarded-Port 443;
|
||||||
proxy_set_header X-Forwarded-Proto https;
|
proxy_set_header X-Forwarded-Proto https;
|
||||||
'';
|
'';
|
||||||
|
|||||||
@@ -12,7 +12,7 @@
|
|||||||
${pkgs.curl}/bin/curl --fail --silent --show-error "https://njal.la/update/?h=cloud.malobeo.org&k="$KEYCLOUD"&auto"
|
${pkgs.curl}/bin/curl --fail --silent --show-error "https://njal.la/update/?h=cloud.malobeo.org&k="$KEYCLOUD"&auto"
|
||||||
${pkgs.curl}/bin/curl --fail --silent --show-error "https://njal.la/update/?h=zines.malobeo.org&k="$KEYZINES"&auto"
|
${pkgs.curl}/bin/curl --fail --silent --show-error "https://njal.la/update/?h=zines.malobeo.org&k="$KEYZINES"&auto"
|
||||||
${pkgs.curl}/bin/curl --fail --silent --show-error "https://njal.la/update/?h=antamap.malobeo.org&k="$KEYANATAMAP"&auto"
|
${pkgs.curl}/bin/curl --fail --silent --show-error "https://njal.la/update/?h=antamap.malobeo.org&k="$KEYANATAMAP"&auto"
|
||||||
${pkgs.curl}/bin/curl --fail --silent --show-error "https://njal.la/update/?h=www.rm16bleibt.org&k="$KEYRM16"&auto"
|
${pkgs.curl}/bin/curl --fail --silent --show-error "https://njal.la/update/?h=rm16bleibt.org&k="$KEYRM16"&auto"
|
||||||
'';
|
'';
|
||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
Type = "oneshot";
|
Type = "oneshot";
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ shop_auth: ENC[AES256_GCM,data:0NDIRjmGwlSFls12sCb5OlgyGTCHpPQIjycEJGhYlZsWKhEYX
|
|||||||
njalacloud: ENC[AES256_GCM,data:sp79Ij1vd9pQZuPUR1phmw==,iv:AWKZoOfBA/n16pWQCfA0dZmH1KajCztnLvYItoZZbgA=,tag:BIUrobBoO96pxUz1sjIYIw==,type:str]
|
njalacloud: ENC[AES256_GCM,data:sp79Ij1vd9pQZuPUR1phmw==,iv:AWKZoOfBA/n16pWQCfA0dZmH1KajCztnLvYItoZZbgA=,tag:BIUrobBoO96pxUz1sjIYIw==,type:str]
|
||||||
njalazines: ENC[AES256_GCM,data:fnObUEnXYvdj9HtkZNzXVA==,iv:0Zj2n2we9w4fj/n7e1ayd9XgFEMAGCHk4QLTu1IlRnQ=,tag:zeOLAB0oE6XbxqdqhdRNxw==,type:str]
|
njalazines: ENC[AES256_GCM,data:fnObUEnXYvdj9HtkZNzXVA==,iv:0Zj2n2we9w4fj/n7e1ayd9XgFEMAGCHk4QLTu1IlRnQ=,tag:zeOLAB0oE6XbxqdqhdRNxw==,type:str]
|
||||||
njalaantamap: ENC[AES256_GCM,data:nUc+E7HNbW0EDclzNDV6+w==,iv:H8nqeuOrvvu8O8QhGWkBkYWAQXwkBehf/jU6u/grs1A=,tag:mqX6jn47DyeSuk8xzG0e/Q==,type:str]
|
njalaantamap: ENC[AES256_GCM,data:nUc+E7HNbW0EDclzNDV6+w==,iv:H8nqeuOrvvu8O8QhGWkBkYWAQXwkBehf/jU6u/grs1A=,tag:mqX6jn47DyeSuk8xzG0e/Q==,type:str]
|
||||||
|
njalarm16: ENC[AES256_GCM,data:Uo/TBNgyvH7EGSJb7ZQUBw==,iv:YDGjr9w9YceiDGJAtNIAPltxaR5pfpEYswu33WtAiQQ=,tag:PtlbcggOHgb1vIb7KBV0hg==,type:str]
|
||||||
njala_api_key: ENC[AES256_GCM,data:ohSVzQUvFjia/s9WceqnZCdLyk3N1Lm2BCBmXeBlkWD2dyrohKCnd9GiJ499IORpuYcOXyM=,iv:Uczk8op5mgqe8gefxgU9YuTqOsYvjzHCKvzA7GDsgio=,tag:XA7JRq/LsGkpHcQSO36Whg==,type:str]
|
njala_api_key: ENC[AES256_GCM,data:ohSVzQUvFjia/s9WceqnZCdLyk3N1Lm2BCBmXeBlkWD2dyrohKCnd9GiJ499IORpuYcOXyM=,iv:Uczk8op5mgqe8gefxgU9YuTqOsYvjzHCKvzA7GDsgio=,tag:XA7JRq/LsGkpHcQSO36Whg==,type:str]
|
||||||
sops:
|
sops:
|
||||||
age:
|
age:
|
||||||
@@ -25,8 +26,8 @@ sops:
|
|||||||
SKFx7MXcjFRLKS2Ij12V8ftjL3Uod6be5zoMibkxK19KmXY/514Jww==
|
SKFx7MXcjFRLKS2Ij12V8ftjL3Uod6be5zoMibkxK19KmXY/514Jww==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
recipient: age1ljpdczmg5ctqyeezn739hv589fwhssjjnuqf7276fqun6kc62v3qmhkd0c
|
recipient: age1ljpdczmg5ctqyeezn739hv589fwhssjjnuqf7276fqun6kc62v3qmhkd0c
|
||||||
lastmodified: "2026-08-28T12:19:14Z"
|
lastmodified: "2026-09-14T12:42:34Z"
|
||||||
mac: ENC[AES256_GCM,data:TnElCRaL/b238clfFVEq+Ot1lwg5MLMchCkmhi5PmADRn2exA42Zeq5v1M/IM5sHt4xEyFLn5R/88Y49DAfehRFwu6rddV+3lnFV40k2rWRtMfQOUXSrCd7lGxZdFbMU0eIXF5jaATFbcP0wO03FohNA69/u6kNsS0y0jK3vuLQ=,iv:xPeNXUIavVYFfAv1fs5TXCHXmvnXQDs4mJZMHOX7qG8=,tag:85hrBTKMh1ckTtXpOxj5lg==,type:str]
|
mac: ENC[AES256_GCM,data:cOv94thIsHzpsiYnJAP2R/RZIkkdr+NHQuO5jCMxWssFu5WcWzeXC9mbYe0RAhY0Hx+tUHJsEG5SQqRaudpbGH9aYLC+5jkVaURXSYd5FIv+I8aUrBsZtpVrE7NJwo+S3+PAgpOUCO4w0bBFsmAWvgpEQSWIcndnkZvvwF2GtrU=,iv:pupuBdJsZTLY246yanDPdgDlRm2oOZprERy3uNdY7E4=,tag:9c1IAKpXBb2KhI1N6M7hOA==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2025-02-11T18:32:49Z"
|
- created_at: "2025-02-11T18:32:49Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
|
|||||||
@@ -0,0 +1,93 @@
|
|||||||
|
{ config, pkgs, inputs, modulesPath, ... }:
|
||||||
|
|
||||||
|
let
|
||||||
|
sshKeys = import ../ssh_keys.nix;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
networking.hostName = "goldman"; # Define your hostname.
|
||||||
|
nixpkgs.hostPlatform = { system = "aarch64-linux"; };
|
||||||
|
|
||||||
|
imports =
|
||||||
|
[
|
||||||
|
inputs.gatekeeper.nixosModules.gatekeeper
|
||||||
|
../modules/malobeo_user.nix
|
||||||
|
#inputs.nixos-hardware.nixosModules.raspberry-pi-3
|
||||||
|
(modulesPath + "/profiles/minimal.nix")
|
||||||
|
#(modulesPath + "/installer/sd-card/sd-image.nix")
|
||||||
|
];
|
||||||
|
|
||||||
|
fileSystems."/" =
|
||||||
|
{ device = "/dev/disk/by-label/NIXOS_SD";
|
||||||
|
fsType = "ext4";
|
||||||
|
};
|
||||||
|
|
||||||
|
#Try to reduce size
|
||||||
|
documentation.man.enable = false;
|
||||||
|
documentation.nixos.enable = false;
|
||||||
|
|
||||||
|
services.openssh.enable = true;
|
||||||
|
services.openssh.ports = [ 22 ];
|
||||||
|
services.openssh.settings.PasswordAuthentication = false;
|
||||||
|
services.openssh.settings.PermitRootLogin = "prohibit-password";
|
||||||
|
users.users.root.openssh.authorizedKeys.keys = sshKeys.admins;
|
||||||
|
|
||||||
|
# Use the extlinux boot loader. (NixOS wants to enable GRUB by default)
|
||||||
|
boot.loader.grub.enable = false;
|
||||||
|
|
||||||
|
# Enables the generation of /boot/extlinux/extlinux.conf
|
||||||
|
boot.loader.generic-extlinux-compatible.enable = true;
|
||||||
|
|
||||||
|
networking.dhcpcd.enable = true;
|
||||||
|
|
||||||
|
# Set your time zone.
|
||||||
|
time.timeZone = "Europe/Berlin";
|
||||||
|
|
||||||
|
services.mosquitto = {
|
||||||
|
enable = true;
|
||||||
|
listeners = [{
|
||||||
|
acl = [ "pattern readwrite #" ];
|
||||||
|
omitPasswordAuth = true;
|
||||||
|
settings.allow_anonymous = true;
|
||||||
|
}];
|
||||||
|
};
|
||||||
|
|
||||||
|
services = {
|
||||||
|
gatekeeper = {
|
||||||
|
enable = true;
|
||||||
|
envFile = pkgs.writeText "env" ''
|
||||||
|
MIFARE_APP_MASTER_KEY="7b195adb892073c9e34ebe7e0ca28b2b"
|
||||||
|
MIFARE_ACL_READ_BASE_KEY="741a50f2b189cc9f151e0600f50a6e1a"
|
||||||
|
MIFARE_ACL_WRITE_BASE_KEY="f1aa99f81cca268de98d422ee0ccb65c"
|
||||||
|
SECRET_KEY="8b14d0b447bff7efa24d5019cc59a999786e31f6f865173bbd642bf18de5ad85"
|
||||||
|
MQTT_HOST = "localhost"
|
||||||
|
MQTT_PORT = "1883"
|
||||||
|
'';
|
||||||
|
mock = "False";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
htop
|
||||||
|
wget
|
||||||
|
git
|
||||||
|
pciutils
|
||||||
|
gpio-utils
|
||||||
|
nix-tree
|
||||||
|
lgpio
|
||||||
|
];
|
||||||
|
|
||||||
|
services.avahi = {
|
||||||
|
enable = true;
|
||||||
|
nssmdns4 = true;
|
||||||
|
publish = {
|
||||||
|
enable = true;
|
||||||
|
addresses = true;
|
||||||
|
userServices = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
networking.firewall.allowedTCPPorts = [ 80 443 1883];
|
||||||
|
|
||||||
|
system.stateVersion = "23.05";
|
||||||
|
}
|
||||||
|
|
||||||
@@ -77,6 +77,15 @@ in
|
|||||||
nameservers = [ "192.168.1.1" "1.1.1.1" ];
|
nameservers = [ "192.168.1.1" "1.1.1.1" ];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
goldman = {
|
||||||
|
type = "rpi";
|
||||||
|
network = {
|
||||||
|
local = true;
|
||||||
|
hostId = "16";
|
||||||
|
address = "192.168.1.106";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
durruti = {
|
durruti = {
|
||||||
type = "microvm";
|
type = "microvm";
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ self, config, lib, pkgs, inputs, ... }:
|
{ config, lib, pkgs, inputs, ... }:
|
||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
|
|
||||||
@@ -10,11 +10,17 @@ with lib;
|
|||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
inputs.malobeo.nixosModules.malobeo.metrics
|
inputs.malobeo.nixosModules.malobeo.metrics
|
||||||
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
../durruti/documentation.nix
|
../durruti/documentation.nix
|
||||||
../modules/malobeo_user.nix
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
malobeo.metrics = {
|
malobeo.metrics = {
|
||||||
enable = true;
|
enable = true;
|
||||||
enablePromtail = true;
|
enablePromtail = true;
|
||||||
|
|||||||
@@ -3,13 +3,14 @@
|
|||||||
{
|
{
|
||||||
imports =
|
imports =
|
||||||
[ # Include the results of the hardware scan.
|
[ # Include the results of the hardware scan.
|
||||||
|
inputs.malobeo.nixosModules.malobeo.printing
|
||||||
|
|
||||||
./hardware-configuration.nix
|
./hardware-configuration.nix
|
||||||
../modules/xserver.nix
|
../modules/xserver.nix
|
||||||
../modules/malobeo_user.nix
|
../modules/malobeo_user.nix
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/minimal_tools.nix
|
../modules/minimal_tools.nix
|
||||||
../modules/autoupdate.nix
|
../modules/autoupdate.nix
|
||||||
inputs.self.nixosModules.malobeo.printing
|
|
||||||
];
|
];
|
||||||
|
|
||||||
malobeo.autoUpdate = {
|
malobeo.autoUpdate = {
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ config, pkgs, ... }:
|
{ config, pkgs, inputs, ... }:
|
||||||
|
|
||||||
let
|
let
|
||||||
sshKeys = import ../ssh_keys.nix;
|
sshKeys = import ../ssh_keys.nix;
|
||||||
@@ -6,10 +6,16 @@ in
|
|||||||
{
|
{
|
||||||
imports =
|
imports =
|
||||||
[ # Include the results of the hardware scan.
|
[ # Include the results of the hardware scan.
|
||||||
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
./hardware_configuration.nix
|
./hardware_configuration.nix
|
||||||
../modules/malobeo_user.nix
|
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
sops.defaultSopsFile = ./secrets.yaml;
|
sops.defaultSopsFile = ./secrets.yaml;
|
||||||
sops.secrets.njala_api_key = {};
|
sops.secrets.njala_api_key = {};
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
{config, lib, pkgs, inputs, ...}:
|
{config, lib, pkgs, inputs, ...}:
|
||||||
let
|
let
|
||||||
cfg = config.malobeo.users;
|
cfg = config.malobeo.users;
|
||||||
sshKeys = import ( inputs.self + /machines/ssh_keys.nix);
|
sshKeys = import ( inputs.malobeo + /machines/ssh_keys.nix);
|
||||||
inherit (config.networking) hostName;
|
inherit (config.networking) hostName;
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -72,7 +72,7 @@ in
|
|||||||
mtu = 1340; #seems to be necessary to proxypass nginx traffic through vpn
|
mtu = 1340; #seems to be necessary to proxypass nginx traffic through vpn
|
||||||
address = [ "${myPeer.address}/24" ];
|
address = [ "${myPeer.address}/24" ];
|
||||||
autostart = cfg.autostart;
|
autostart = cfg.autostart;
|
||||||
dns = [peers.ns1.address];
|
#dns = [peers.ns1.address "1.1.1.1"]; #currently broken, see commit message
|
||||||
listenPort = mkIf (myPeer.role == "server") myPeer.listenPort;
|
listenPort = mkIf (myPeer.role == "server") myPeer.listenPort;
|
||||||
|
|
||||||
# This allows the wireguard server to route your traffic to the internet and hence be like a VPN
|
# This allows the wireguard server to route your traffic to the internet and hence be like a VPN
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ config, self, lib, pkgs, ... }:
|
{ config, lib, pkgs, inputs, ... }:
|
||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
|
|
||||||
@@ -20,13 +20,19 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
self.nixosModules.malobeo.metrics
|
inputs.malobeo.nixosModules.malobeo.metrics
|
||||||
../modules/malobeo_user.nix
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/minimal_tools.nix
|
../modules/minimal_tools.nix
|
||||||
../modules/autoupdate.nix
|
../modules/autoupdate.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
malobeo.metrics = {
|
malobeo.metrics = {
|
||||||
enable = true;
|
enable = true;
|
||||||
enablePromtail = true;
|
enablePromtail = true;
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ config, self, lib, inputs, pkgs, ... }:
|
{ config, lib, inputs, pkgs, ... }:
|
||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
with inputs;
|
with inputs;
|
||||||
@@ -13,18 +13,33 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
../modules/malobeo_user.nix
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
inputs.malobeo.nixosModules.malobeo.vpn
|
||||||
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/minimal_tools.nix
|
../modules/minimal_tools.nix
|
||||||
../modules/autoupdate.nix
|
../modules/autoupdate.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
networking.firewall = {
|
networking.firewall = {
|
||||||
enable = true;
|
enable = true;
|
||||||
allowedTCPPorts = [ 53 ];
|
allowedTCPPorts = [ 53 ];
|
||||||
allowedUDPPorts = [ 53 ];
|
allowedUDPPorts = [ 53 ];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
sops.defaultSopsFile = ./secrets.yaml;
|
||||||
|
sops.secrets.wg_private = {};
|
||||||
|
services.malobeo.vpn = {
|
||||||
|
enable = true;
|
||||||
|
name = "ns1";
|
||||||
|
privateKeyFile = config.sops.secrets.wg_private.path;
|
||||||
|
};
|
||||||
|
|
||||||
services.bind = {
|
services.bind = {
|
||||||
enable = true;
|
enable = true;
|
||||||
forwarders = [
|
forwarders = [
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ config, self, lib, pkgs, inputs, ... }:
|
{ config, lib, pkgs, inputs, ... }:
|
||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
|
|
||||||
@@ -7,11 +7,21 @@ let
|
|||||||
in
|
in
|
||||||
{
|
{
|
||||||
sops.defaultSopsFile = ./secrets.yaml;
|
sops.defaultSopsFile = ./secrets.yaml;
|
||||||
|
|
||||||
sops.secrets = {
|
sops.secrets = {
|
||||||
grafana_smtp = {
|
grafana_smtp = {
|
||||||
owner = "grafana";
|
owner = "grafana";
|
||||||
group = "grafana";
|
group = "grafana";
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# Contains private targets for blackbox monitoring
|
||||||
|
# It is used below in the blackbox-http-private0 job
|
||||||
|
# More of these can be created such as private1, private2, ...
|
||||||
|
private0_blackbox_config = {
|
||||||
|
owner = "prometheus";
|
||||||
|
group = "prometheus";
|
||||||
|
path = "/var/lib/prometheus2/private0.json";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
@@ -20,12 +30,18 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
self.nixosModules.malobeo.metrics
|
inputs.malobeo.nixosModules.malobeo.metrics
|
||||||
../modules/malobeo_user.nix
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
./printer_module.nix
|
./printer_module.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [ 80 3100 ];
|
networking.firewall.allowedTCPPorts = [ 80 3100 ];
|
||||||
|
|
||||||
malobeo.metrics = {
|
malobeo.metrics = {
|
||||||
@@ -108,6 +124,10 @@ in
|
|||||||
retentionTime = "1y";
|
retentionTime = "1y";
|
||||||
port = 9001;
|
port = 9001;
|
||||||
|
|
||||||
|
# We have to disable the checks since we use file_sd_configs provided through
|
||||||
|
# sops secrets. These are not available during buildtime which leads to errors during the check
|
||||||
|
checkConfig = false;
|
||||||
|
|
||||||
exporters.blackbox = {
|
exporters.blackbox = {
|
||||||
enable = true;
|
enable = true;
|
||||||
configFile = ./blackbox.yaml;
|
configFile = ./blackbox.yaml;
|
||||||
@@ -133,6 +153,35 @@ in
|
|||||||
"https://zines.malobeo.org"
|
"https://zines.malobeo.org"
|
||||||
];
|
];
|
||||||
}];
|
}];
|
||||||
|
|
||||||
|
relabel_configs = [
|
||||||
|
{
|
||||||
|
source_labels = ["__address__"];
|
||||||
|
target_label = "__param_target";
|
||||||
|
}
|
||||||
|
{
|
||||||
|
source_labels = ["__param_target"];
|
||||||
|
target_label = "instance";
|
||||||
|
}
|
||||||
|
{
|
||||||
|
target_label = "__address__";
|
||||||
|
replacement = "127.0.0.1:9115";
|
||||||
|
}
|
||||||
|
];
|
||||||
|
}
|
||||||
|
{
|
||||||
|
job_name = "blackbox-http-private0";
|
||||||
|
metrics_path = "/probe";
|
||||||
|
params = {
|
||||||
|
module = ["http_2xx"];
|
||||||
|
};
|
||||||
|
file_sd_configs = [
|
||||||
|
{
|
||||||
|
files = [
|
||||||
|
config.sops.secrets.private0_blackbox_config.path
|
||||||
|
];
|
||||||
|
}
|
||||||
|
];
|
||||||
relabel_configs = [
|
relabel_configs = [
|
||||||
{
|
{
|
||||||
source_labels = ["__address__"];
|
source_labels = ["__address__"];
|
||||||
|
|||||||
@@ -1,9 +1,9 @@
|
|||||||
grafana_admin: ENC[AES256_GCM,data:zO7Tfmo=,iv:xa456cUb14VjJPEKClqGJiYR7cSsjQPIld+O2E0YNM8=,tag:dFgGtqMYhg4uweoLZPu48Q==,type:str]
|
grafana_admin: ENC[AES256_GCM,data:zO7Tfmo=,iv:xa456cUb14VjJPEKClqGJiYR7cSsjQPIld+O2E0YNM8=,tag:dFgGtqMYhg4uweoLZPu48Q==,type:str]
|
||||||
grafana_smtp: ENC[AES256_GCM,data:xndLMw==,iv:0P4INbDD2/Teo8Dv6lIfLhXvNAkcneEDCeB5OAY25wI=,tag:ilE0Noleb+uL5gqF4bU70w==,type:str]
|
grafana_smtp: ENC[AES256_GCM,data:xndLMw==,iv:0P4INbDD2/Teo8Dv6lIfLhXvNAkcneEDCeB5OAY25wI=,tag:ilE0Noleb+uL5gqF4bU70w==,type:str]
|
||||||
|
private0_blackbox_config: ENC[AES256_GCM,data:Q7Ll0GFtCEgCKsq2rE4/qLZwo4F+8HAkWFDrc0zz7GvWR29q88rm6P3YqiGpuHo5nGoxanJPxV0ucNV4dA9CRuH6kx1B3WONUd97BSjSY0iVjVMtGhBVNdRGl3i9q9+vTsfXT7jEY5kmEQ1uUMjC+3h5r3J6s6JlVAwxdA==,iv:V4nOZYipocrZjZ9L7Kv/QZEftVwu4yIRoiff5H5Gl4M=,tag:5RCh2ra+5sBEbxLe604m8w==,type:str]
|
||||||
sops:
|
sops:
|
||||||
age:
|
age:
|
||||||
- recipient: age18jn5mrfs4gqrnv0e2sxsgh3kq4sgxx39hwr8z7mz9kt7wlgaasjqlr88ng
|
- enc: |
|
||||||
enc: |
|
|
||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBPMXlEbWlabzVUNlRkVFFC
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBPMXlEbWlabzVUNlRkVFFC
|
||||||
ZktpQUx2alRNN01qYmhFYnhMRDBkYmFRdzNnCi9YbjBDUlRhc1kwVjZWY0NGZERQ
|
ZktpQUx2alRNN01qYmhFYnhMRDBkYmFRdzNnCi9YbjBDUlRhc1kwVjZWY0NGZERQ
|
||||||
@@ -11,8 +11,8 @@ sops:
|
|||||||
eDFDVStZS0o0WVh4cmJPa2o3eWNseGMKc0ydK8/2Gzxe2IYG96saVosJTrRcWizR
|
eDFDVStZS0o0WVh4cmJPa2o3eWNseGMKc0ydK8/2Gzxe2IYG96saVosJTrRcWizR
|
||||||
lcMbsh8mKlVCt5Fx9EQOtj50ylOGk2h2Itk4uLYG4UAySDU/Aw3iQw==
|
lcMbsh8mKlVCt5Fx9EQOtj50ylOGk2h2Itk4uLYG4UAySDU/Aw3iQw==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
- recipient: age1ljpdczmg5ctqyeezn739hv589fwhssjjnuqf7276fqun6kc62v3qmhkd0c
|
recipient: age18jn5mrfs4gqrnv0e2sxsgh3kq4sgxx39hwr8z7mz9kt7wlgaasjqlr88ng
|
||||||
enc: |
|
- enc: |
|
||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB1QmsxNERCclRBeFo0WGZ1
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB1QmsxNERCclRBeFo0WGZ1
|
||||||
OGlHTGxDMURsWXdDRXpoUk10S0JpeGk2QURvCjBkaVFHTHo1eGtKbERPWmhNZEpL
|
OGlHTGxDMURsWXdDRXpoUk10S0JpeGk2QURvCjBkaVFHTHo1eGtKbERPWmhNZEpL
|
||||||
@@ -20,8 +20,9 @@ sops:
|
|||||||
QXZwTVd5NnNSdUxRSzNLMHk2SWYxVnMKZyZvZV5qhJj4KATFV2eh9aN9XMbSQL7i
|
QXZwTVd5NnNSdUxRSzNLMHk2SWYxVnMKZyZvZV5qhJj4KATFV2eh9aN9XMbSQL7i
|
||||||
kRGQI9y5ADv6UsLh/y+rWe0xF4BPOGF0xL8JUnHfTy/RsKfhB3aTYQ==
|
kRGQI9y5ADv6UsLh/y+rWe0xF4BPOGF0xL8JUnHfTy/RsKfhB3aTYQ==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
lastmodified: "2026-01-24T17:01:57Z"
|
recipient: age1ljpdczmg5ctqyeezn739hv589fwhssjjnuqf7276fqun6kc62v3qmhkd0c
|
||||||
mac: ENC[AES256_GCM,data:KySo9sJgOLBPtxQZ1gXY8aCmCHbn44aiLKiK1mGziKsBoPkBdEivCT7dDQ1tXQj9wz3gly6raS4FEmR6ikcbtAE2EN86cDLNuu9sSiW2OYiJRe5iZvet2veqtA00K7TtPZgAX+ccsUE5iy0W55bu+kpK3J8MPNy3LUK0EbSKW8I=,iv:7BQKCNyWe4azTelyKlV6XvvgPIrspVbwITyycsW/c44=,tag:1XbSxju44GCKcGw8Ln9iuQ==,type:str]
|
lastmodified: "2026-09-21T11:52:54Z"
|
||||||
|
mac: ENC[AES256_GCM,data:rgxYGqsksR8vTznjod8nB9sukqRpHTNuH1hdFCUr7HnE67fojNpz3WzOQvl8Su3JK+8Kj2fe9EodQT9VUkMiSywwSw30M9j3aaXlKj798PEIHDhJBWKhkMrQDyaTMla1Lrp5PuGHDdTQ/vmPNUyeQu3XitfcAma6SdX3e9w1J0s=,iv:Je5Fu9f7NPG/to5t+qOVMV195rwbITPy4JsOjouxiLU=,tag:BhlRWoreptzqYCe29/kXdg==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-01-24T17:01:26Z"
|
- created_at: "2026-01-24T17:01:26Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
@@ -62,4 +63,4 @@ sops:
|
|||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: aef8d6c7e4761fc297cda833df13aebb1011b5d4
|
fp: aef8d6c7e4761fc297cda833df13aebb1011b5d4
|
||||||
unencrypted_suffix: _unencrypted
|
unencrypted_suffix: _unencrypted
|
||||||
version: 3.11.0
|
version: 3.13.3
|
||||||
|
|||||||
@@ -1,9 +1,9 @@
|
|||||||
grafana_admin: ENC[AES256_GCM,data:c+ZnOyxSXrG4eiK8ETKHheadiSz98LLHYwxb,iv:Ut2qFD2p6OmKDWjLMjFxyISxzTdJpZpgIB7obW5bgkY=,tag:HdayzjXQ1Zc7w9ITLzKLxA==,type:str]
|
grafana_admin: ENC[AES256_GCM,data:c+ZnOyxSXrG4eiK8ETKHheadiSz98LLHYwxb,iv:Ut2qFD2p6OmKDWjLMjFxyISxzTdJpZpgIB7obW5bgkY=,tag:HdayzjXQ1Zc7w9ITLzKLxA==,type:str]
|
||||||
grafana_smtp: ENC[AES256_GCM,data:gOER9SzqRACIWe3PchyKguX3RdW6xhSZDzLd727CK1w=,iv:KDOyXGYGXnUu92hvt6eBqI8zeKP+JRDsF8Ir5X/9TDk=,tag:wRexcIJp8XEURKcZnHCRtQ==,type:str]
|
grafana_smtp: ENC[AES256_GCM,data:gOER9SzqRACIWe3PchyKguX3RdW6xhSZDzLd727CK1w=,iv:KDOyXGYGXnUu92hvt6eBqI8zeKP+JRDsF8Ir5X/9TDk=,tag:wRexcIJp8XEURKcZnHCRtQ==,type:str]
|
||||||
|
private0_blackbox_config: ENC[AES256_GCM,data:seiw3jvNucIn8NfmYkOt9hxr17OgmydCzTSOfpmDsdL0sD8ZZ4cty0vO63f+cPzU5uWKDYOwCmFL1Rg+vefJFoXGGIHi0hjd4JNAADW3TJ5YMu91fHoB+0ikQcKsRdD8vAs3PjteohlvjBh3IuhHLcIk6NeE09yqBcHpVHbU0/Q1HUVF7gpO/4LK0V2FmJ3HTiWvo4qZNa3T,iv:OJuiotdqVT8ASeKj4Pa8RLn7TGze2O8ICwVB3BmLybk=,tag:fynrBmQOphqzwprhx0MYlA==,type:str]
|
||||||
sops:
|
sops:
|
||||||
age:
|
age:
|
||||||
- recipient: age1ljpdczmg5ctqyeezn739hv589fwhssjjnuqf7276fqun6kc62v3qmhkd0c
|
- enc: |
|
||||||
enc: |
|
|
||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBWdVhpdTdJNnh5VCtmNHh5
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBWdVhpdTdJNnh5VCtmNHh5
|
||||||
M1ZTKzk1WlVYYmRWKzJxd1ZUTi9IMW1ta1VvCjVZQVQ1K1lFeC9QZkI2MGZXNk81
|
M1ZTKzk1WlVYYmRWKzJxd1ZUTi9IMW1ta1VvCjVZQVQ1K1lFeC9QZkI2MGZXNk81
|
||||||
@@ -11,8 +11,8 @@ sops:
|
|||||||
NmRNSit1TkRRbUFQNzUvYThUczAxRzAKvpDK4R7m/GpfOzM4nU5vSYDXZGUy4D+c
|
NmRNSit1TkRRbUFQNzUvYThUczAxRzAKvpDK4R7m/GpfOzM4nU5vSYDXZGUy4D+c
|
||||||
xouTxOguMdId8GiKb1AJnVv2q/YYdr2M9yA/FpKn7kBfuQw/Hrj1rg==
|
xouTxOguMdId8GiKb1AJnVv2q/YYdr2M9yA/FpKn7kBfuQw/Hrj1rg==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
- recipient: age1hq75x3dpnfqat9sgtfjf8lep49qvkdgza3xwp7ugft3kd74pdfnqfsmmdn
|
recipient: age1ljpdczmg5ctqyeezn739hv589fwhssjjnuqf7276fqun6kc62v3qmhkd0c
|
||||||
enc: |
|
- enc: |
|
||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA0bEhCQitwNVpYSHRJOEMr
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA0bEhCQitwNVpYSHRJOEMr
|
||||||
ZnZLQ3lELzdtREVpSHVGd3BHZ3p6WU9BK3lFCkFlYXNsa2JWZmZFVjRmK3BTejc1
|
ZnZLQ3lELzdtREVpSHVGd3BHZ3p6WU9BK3lFCkFlYXNsa2JWZmZFVjRmK3BTejc1
|
||||||
@@ -20,8 +20,9 @@ sops:
|
|||||||
VnRIYVVIZktISENseEVLVWlsenFhcVkKvj8i349iNX2YNL5G0w7F9IuW/5ZRP6Z7
|
VnRIYVVIZktISENseEVLVWlsenFhcVkKvj8i349iNX2YNL5G0w7F9IuW/5ZRP6Z7
|
||||||
XC8TrYzCSOEOXt5nMnZg2yQUJHi6Qq8Wu2e2KV7Cd9J8Q/39dRv2cg==
|
XC8TrYzCSOEOXt5nMnZg2yQUJHi6Qq8Wu2e2KV7Cd9J8Q/39dRv2cg==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
lastmodified: "2026-01-24T16:52:54Z"
|
recipient: age1hq75x3dpnfqat9sgtfjf8lep49qvkdgza3xwp7ugft3kd74pdfnqfsmmdn
|
||||||
mac: ENC[AES256_GCM,data:BoJwPldIVZf2NZALbeMTq6DvuBMwOwyvmr5UjsPvQrdbbzYjLTl5dplkhT6QRHPDCFDT4Ibd1UfJ8pQYRkGdO2EjlUyuk3hvAYdR+PUmVz8afFE07sNsGw2EDGVHmsFjUVHLT69YqXtGpVNTW6KjqYuRhz/Ik0wEZLxzDSiy86c=,iv:TQU0si/AYaMpShF4l3CzUN3qajQpE0ZWa7mLOqhRP00=,tag:Oyapkoo4+Q7x08m6RTXfcQ==,type:str]
|
lastmodified: "2026-09-21T11:52:44Z"
|
||||||
|
mac: ENC[AES256_GCM,data:5/3fCS1QFmy4kHDCDklR+EwY/VPcb73pOI+rxDj44qlrR+1aRni97ZxdnvlfERy/Hkgsbk5UIKkj9+xMTcCW6Dqp1/zLf1YIL/xF1JVBIxBCVfNxWeS5XDsC0rORwgGi+BuRT4AuRdg2gu1cPwpbyJifpupNl9sOcaFcoctZ4NU=,iv:d2OQk8AIgHyQDOevKeeXi4sQStJF5KMky2ySwxmJrQs=,tag:KIkBsJlaGze4i43OoiXSVg==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-01-24T18:05:47Z"
|
- created_at: "2026-01-24T18:05:47Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
@@ -62,4 +63,4 @@ sops:
|
|||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: aef8d6c7e4761fc297cda833df13aebb1011b5d4
|
fp: aef8d6c7e4761fc297cda833df13aebb1011b5d4
|
||||||
unencrypted_suffix: _unencrypted
|
unencrypted_suffix: _unencrypted
|
||||||
version: 3.11.0
|
version: 3.13.3
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ config, self, lib, pkgs, inputs, ... }:
|
{ config, lib, pkgs, inputs, ... }:
|
||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
|
|
||||||
@@ -19,9 +19,12 @@ in
|
|||||||
useDHCP = false;
|
useDHCP = false;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
disabledModules = [ "services/web-apps/pretalx.nix" ];
|
||||||
imports = [
|
imports = [
|
||||||
self.nixosModules.malobeo.metrics
|
inputs.malobeo.nixosModules.malobeo.metrics
|
||||||
self.nixosModules.malobeo.users
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
|
"${inputs.nixpkgs-unstable}/nixos/modules/services/web-apps/pretalx.nix"
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/minimal_tools.nix
|
../modules/minimal_tools.nix
|
||||||
../modules/autoupdate.nix
|
../modules/autoupdate.nix
|
||||||
@@ -35,6 +38,7 @@ in
|
|||||||
|
|
||||||
malobeo.users = {
|
malobeo.users = {
|
||||||
admin = true;
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
||||||
@@ -78,6 +82,7 @@ in
|
|||||||
config.sops.secrets.pretalx_smtp.path
|
config.sops.secrets.pretalx_smtp.path
|
||||||
];
|
];
|
||||||
settings = {
|
settings = {
|
||||||
|
redis.session = false;
|
||||||
locale = {
|
locale = {
|
||||||
language_code = "de";
|
language_code = "de";
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -6,13 +6,18 @@ in
|
|||||||
imports =
|
imports =
|
||||||
[ # Include the results of the hardware scan.
|
[ # Include the results of the hardware scan.
|
||||||
#./hardware-configuration.nix
|
#./hardware-configuration.nix
|
||||||
../modules/malobeo_user.nix
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
inputs.malobeo.nixosModules.malobeo.initssh
|
||||||
|
inputs.malobeo.nixosModules.malobeo.disko
|
||||||
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/minimal_tools.nix
|
../modules/minimal_tools.nix
|
||||||
inputs.self.nixosModules.malobeo.initssh
|
|
||||||
inputs.self.nixosModules.malobeo.disko
|
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
boot.initrd.systemd.enable = true;
|
boot.initrd.systemd.enable = true;
|
||||||
boot.loader.systemd-boot.enable = true;
|
boot.loader.systemd-boot.enable = true;
|
||||||
|
|||||||
@@ -9,10 +9,16 @@ with lib;
|
|||||||
};
|
};
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
../modules/malobeo_user.nix
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [ 80 ];
|
networking.firewall.allowedTCPPorts = [ 80 ];
|
||||||
|
|
||||||
services.nginx = {
|
services.nginx = {
|
||||||
|
|||||||
@@ -16,11 +16,17 @@ with lib;
|
|||||||
};
|
};
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
../modules/malobeo_user.nix
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
inputs.malobeo.nixosModules.malobeo.metrics
|
||||||
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
inputs.self.nixosModules.malobeo.metrics
|
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [ 80 ];
|
networking.firewall.allowedTCPPorts = [ 80 ];
|
||||||
|
|
||||||
malobeo.metrics = {
|
malobeo.metrics = {
|
||||||
|
|||||||
@@ -17,12 +17,18 @@ with lib;
|
|||||||
};
|
};
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
inputs.self.nixosModules.malobeo.vpn
|
inputs.malobeo.nixosModules.malobeo.vpn
|
||||||
../modules/malobeo_user.nix
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
../modules/minimal_tools.nix
|
../modules/minimal_tools.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
services.malobeo.vpn = {
|
services.malobeo.vpn = {
|
||||||
enable = true;
|
enable = true;
|
||||||
name = "vpn";
|
name = "vpn";
|
||||||
|
|||||||
@@ -23,7 +23,8 @@ in {
|
|||||||
};
|
};
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
inputs.self.nixosModules.malobeo.users
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
@@ -80,7 +81,7 @@ in {
|
|||||||
|
|
||||||
services.nginx = {
|
services.nginx = {
|
||||||
enable = true;
|
enable = true;
|
||||||
virtualHosts."rm16bleibt.org" = {
|
virtualHosts."_" = {
|
||||||
#serverName = "rm16bleibt.org";
|
#serverName = "rm16bleibt.org";
|
||||||
root = "/var/lib/wordpress/rm16bleibt.org";
|
root = "/var/lib/wordpress/rm16bleibt.org";
|
||||||
extraConfig = ''
|
extraConfig = ''
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ self, config, lib, pkgs, inputs, ... }:
|
{ config, lib, pkgs, inputs, ... }:
|
||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
|
|
||||||
@@ -11,11 +11,17 @@ with lib;
|
|||||||
imports = [
|
imports = [
|
||||||
inputs.malobeo.nixosModules.malobeo.metrics
|
inputs.malobeo.nixosModules.malobeo.metrics
|
||||||
inputs.malobeo.nixosModules.malobeo.printing
|
inputs.malobeo.nixosModules.malobeo.printing
|
||||||
|
inputs.malobeo.nixosModules.malobeo.users
|
||||||
inputs.zineshop.nixosModules.zineshop
|
inputs.zineshop.nixosModules.zineshop
|
||||||
../modules/malobeo_user.nix
|
|
||||||
../modules/sshd.nix
|
../modules/sshd.nix
|
||||||
];
|
];
|
||||||
|
|
||||||
|
malobeo.users = {
|
||||||
|
admin = true;
|
||||||
|
malobeo = false;
|
||||||
|
};
|
||||||
|
|
||||||
malobeo.metrics = {
|
malobeo.metrics = {
|
||||||
enable = true;
|
enable = true;
|
||||||
enablePromtail = true;
|
enablePromtail = true;
|
||||||
|
|||||||
Reference in New Issue
Block a user