summaryrefslogtreecommitdiff
path: root/configuration.nix
diff options
context:
space:
mode:
authorMica White <botahamec@outlook.com>2026-09-27 18:27:28 -0400
committerMica White <botahamec@outlook.com>2026-09-27 18:27:28 -0400
commitedcbe20b15ec8b09cd1ceac8bf5bfb23bec47172 (patch)
tree6d8da5eeb03c68b06036a66ca806a6cd909df614 /configuration.nix
Initial commit
Diffstat (limited to 'configuration.nix')
-rw-r--r--configuration.nix340
1 files changed, 340 insertions, 0 deletions
diff --git a/configuration.nix b/configuration.nix
new file mode 100644
index 0000000..a4d316c
--- /dev/null
+++ b/configuration.nix
@@ -0,0 +1,340 @@
+{ config, pkgs, ... }: {
+ imports = [
+ ./hardware-configuration.nix
+ ];
+
+ environment.sessionVariables = {
+ NH_FLAKE = "/etc/nixos";
+ EDITOR = "hx";
+ VISUAL = "hx";
+ };
+ environment.systemPackages = with pkgs; [
+ helix
+ nixd
+ btop
+ sops
+ age
+ dust
+ nh
+ ];
+
+ services.fail2ban.enable = true;
+
+ security.acme = {
+ acceptTerms = true;
+ defaults.email = "botahamec@outlook.com";
+ certs."altahamec.dev" = {
+ webroot = "/var/lib/acme/challenges-altahamec";
+ email = "botahamec@outlook.com";
+ group = "nginx";
+ extraDomainNames = [ "www.altahamec.dev" ];
+ };
+ certs."botahamec.dev" = {
+ webroot = "/var/lib/acme/challenges-botahamec";
+ email = "botahamec@outlook.com";
+ group = "nginx";
+ extraDomainNames = [ "www.botahamec.dev" ];
+ };
+ };
+
+ programs.mosh.enable = true;
+ services.openssh = {
+ enable = true;
+ settings = {
+ PermitRootLogin = "no";
+ PasswordAuthentication = false;
+ KbdInteractiveAuthentication = false;
+ };
+ };
+
+ services.vaultwarden = {
+ enable = true;
+ backupDir = "/var/local/vaultwarden/backup";
+ config = {
+ DOMAIN = "https://www.altahamec.dev/vault";
+ SIGNUPS_ALLOWED = false;
+
+ ROCKET_ADDRESS = "127.0.0.1";
+ ROCKET_PORT = 8222;
+ ROCKET_LOG = "critical";
+ };
+ };
+
+ services.copyparty = {
+ enable = true;
+ user = "syncthing";
+ settings = {
+ e2dsa = true;
+ e2ts = true;
+ shr = "/shares";
+ rss = true;
+ ftp = 3921;
+ no-robots = true;
+ rp-loc = "/copyparty";
+ };
+ accounts = {
+ botahamec.passwordFile = config.sops.secrets."myPassword".path;
+ guest.passwordFile = config.sops.secrets."guestPassword".path;
+ };
+ volumes."/" = {
+ path = "/var/lib/syncthing";
+ access.A = [ "botahamec" ];
+ access.r = [ "guest" ];
+ };
+ };
+
+ services.radicale = {
+ enable = true;
+ settings = {
+ server.hosts = [ "0.0.0.0:5232" ];
+ auth = {
+ type = "htpasswd";
+ htpasswd_filename = config.sops.secrets."radicaleAuth".path;
+ };
+ };
+ };
+
+ programs.git = {
+ enable = true;
+ config.init.defaultBranch = "main";
+ };
+ services.cgit."foo" = {
+ enable = true;
+ nginx.location = "/cgit/";
+ nginx.virtualHost = "botahamec.dev";
+ gitHttpBackend.enable = true;
+ gitHttpBackend.checkExportOkFiles = false;
+ scanPath = "/var/lib/git-server/";
+ group = "git";
+ settings = {
+ enable-tree-linenumbers = false;
+ enable-html-serving = true;
+ enable-http-clone = true;
+ clone-url = "https://botahamec.dev/cgit/$CGIT_REPO_URL";
+ remove-suffix = true;
+ css = "/cgit/cgit.css";
+ logo = "/cgit/cgit.png";
+ js = "/cgit/cgit.js";
+ # readme = "main:README.md";
+ # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh";
+ # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py";
+ # source-filter = "${pkgs.cgit-arborium}/bin/cgit-syntax-highlight";
+ };
+ };
+ # services.cgit."bar" = {
+ # enable = true;
+ # nginx.location = "/cgit/";
+ # nginx.virtualHost = "altahamec.dev";
+ # gitHttpBackend.enable = true;
+ # gitHttpBackend.checkExportOkFiles = false;
+ # scanPath = "/var/lib/git-server/";
+ # group = "git";
+ # settings = {
+ # enable-tree-linenumbers = false;
+ # enable-html-serving = true;
+ # enable-http-clone = true;
+ # clone-url = "https://altahamec.dev/cgit/$CGIT_REPO_URL";
+ # remove-suffix = true;
+ # css = "/cgit/cgit.css";
+ # logo = "/cgit/cgit.png";
+ # js = "/cgit/cgit.js";
+ # # readme = "main:README.md";
+ # # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh";
+ # # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py";
+ # };
+ # };
+
+ services.syncthing = {
+ enable = true;
+ openDefaultPorts = true;
+ };
+
+ sops = {
+ defaultSopsFile = ./secrets.yaml;
+ defaultSopsFormat = "yaml";
+ age.keyFile = "/home/botahamec/.config/sops/age/keys.txt";
+ secrets = {
+ "myPassword" = {
+ owner = "syncthing";
+ mode = "0640";
+ };
+ "guestPassword" = {
+ owner = "syncthing";
+ mode = "0640";
+ };
+ "radicaleAuth" = {
+ owner = "radicale";
+ mode = "0640";
+ };
+ };
+ };
+
+ users.users.nginx.extraGroups = [ "acme" "git" ];
+ services.nginx = {
+ enable = true;
+ recommendedOptimisation = true;
+ recommendedBrotliSettings = true;
+ recommendedGzipSettings = true;
+ recommendedProxySettings = true;
+ recommendedTlsSettings = true;
+ virtualHosts = let config = {useACMEHost, acmeRoot, serverAliases}: {
+ addSSL = true;
+ inherit useACMEHost;
+ inherit serverAliases;
+ inherit acmeRoot;
+ locations."/vault/" = {
+ proxyPass = "http://127.0.0.1:8222";
+ recommendedProxySettings = true;
+ proxyWebsockets = true;
+ };
+ locations."/syncthing/" = {
+ proxyWebsockets = true;
+ recommendedProxySettings = true;
+ extraConfig = ''
+ proxy_pass http://127.0.0.1:8384/;
+
+ proxy_read_timeout 600s;
+ proxy_send_timeout 600s;
+ '';
+ };
+ locations."/copyparty/" = {
+ proxyPass = "http://127.0.0.1:3923";
+ recommendedProxySettings = true;
+ proxyWebsockets = true;
+ extraConfig = ''
+ # disable buffering
+ proxy_buffering off;
+ proxy_request_buffering off;
+ # improve download speed from 600 to 1500MiB/s;
+ proxy_buffers 32 8k;
+ proxy_buffer_size 16k;
+ proxy_busy_buffers_size 24k;
+ '';
+ };
+ locations."/dav/" = {
+ proxyPass = "http://127.0.0.1:5232";
+ extraConfig = ''
+ proxy_set_header X-Script-Name /dav;
+ proxy_pass_header Authorization;
+ '';
+ };
+ # locations."/cgit\." = {
+ # root = "${pkgs.cgit}/cgit/";
+ # };
+ # locations."~ ^(/cgit/.*/(INFO/refs|HEAD|objects/info/.*|git-(upload|receive)-pack))$" = {
+ # extraConfig = ''
+ # include ${pkgs.nginx}/conf/fastcgi_params;
+ # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend;
+ # fastcgi_param GIT_PROJECT_ROOT /srv/git;
+ # fastcgi_param GIT_HTTP_EXPORT_ALL "";
+ # fastcgi_pass unix:/run/fcgiwrap.sock;
+ # '';
+ # };
+ # locations."@cgit" = {
+ # extraConfig = ''
+ # include fastcgi_params;
+ # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend;
+ # fastcgi_param PATH_INFO $uri;
+ # fastcgi_param QUERY_STRING $args;
+ # fastcgi_param HTTP_HOST $server_name;
+ # fastcgi_pass unix:/run/fcgiwrap.socket;
+ # '';
+ # };
+ locations."/" = {
+ root = "/var/www/botahamec.dev";
+ index = "index.html";
+ tryFiles = "$uri /blog/$uri /blog/$uri.html $uri.html $uri/ =404";
+ };
+ }; in {
+ "altahamec.dev" = config {
+ useACMEHost = "altahamec.dev";
+ serverAliases = ["www.altahamec.dev"];
+ acmeRoot = "/var/lib/acme/challenges-altahamec";
+ };
+ "botahamec.dev" = config {
+ useACMEHost = "botahamec.dev";
+ serverAliases = ["www.botahamec.dev"];
+ acmeRoot = "/var/lib/acme/challenges-botahamec";
+ };
+ };
+ };
+
+ # Workaround for https://github.com/NixOS/nix/issues/8502
+ services.logrotate.checkConfig = false;
+
+ networking.hostName = "botahamec-sh";
+ networking.firewall.allowedTCPPorts = [ 22 80 443 3921 ];
+
+ time.timeZone = "America/New_York";
+ i18n.defaultLocale = "en_US.UTF-8";
+ console.keyMap = "us";
+
+ security.sudo.wheelNeedsPassword = false;
+ users.groups.git = {};
+ users.users = {
+ root.hashedPassword = "!";
+ botahamec = {
+ isNormalUser = true;
+ extraGroups = ["wheel"];
+ openssh.authorizedKeys.keys = [
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1"
+ ];
+ };
+ git = {
+ isSystemUser = true;
+ group = "git";
+ home = "/var/lib/git-server";
+ homeMode = "755";
+ createHome = true;
+ shell = "${pkgs.bash}/bin/bash";
+ openssh.authorizedKeys.keys = [
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINWcpi4SrCv2VKRAwBCa4CN7zaVOKfrhEZHf+blndGF8"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFWQ1MW4lfCShJ2C5f0WjKXbgsqAu5oxVexIymZSDJAz"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOdsY6akjlI9IL2nLw8A7s1IbDlz19eLMLU+HZguFPxx"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHBEYjq0+cbiTLbgS3v/LyISLL7CG82fj4yCyqdS2sW6"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKf97P0HlHHudrQuzO/yysIQxZZdEhhnvaclE8ABzNm0"
+ ];
+ };
+ radicale = {
+ extraGroups = [ "syncthing" ];
+ };
+ };
+
+ boot.tmp.cleanOnBoot = true;
+ zramSwap.enable = true;
+
+ system.stateVersion = "26.05";
+ system.autoUpgrade = {
+ enable = true;
+ dates = "daily";
+ flake = "path:///etc/nixos";
+ };
+ systemd.services.nixos-upgrade = {
+ after = [ "flake-update.service" ];
+ requires = [ "flake-update.service" ];
+ };
+ systemd.services.flake-update = {
+ description = "Update flake inputs";
+ unitConfig = {
+ StartLimitIntervalSec = 300;
+ StartLimitBurst = 5;
+ };
+ serviceConfig = {
+ ExecStartPre = "${pkgs.networkmanager}/bin/nm-online";
+ ExecStart = "${pkgs.nix}/bin/nix flake update --flake /etc/nixos";
+ Restart = "on-failure";
+ RestartSec = "30";
+ Type = "oneshot";
+ };
+ path = with pkgs; [ nix git host networkmanager ];
+ };
+
+ nix.package = pkgs.lixPackageSets.stable.lix;
+ nix.gc.automatic = true;
+ nix.gc.dates = "daily";
+ nix.gc.options = "--delete-older-than 1d";
+ nix.settings.auto-optimise-store = true;
+ nix.settings.experimental-features = [ "nix-command" "flakes" ];
+ nix.settings.trusted-users = [ "root" "botahamec" "@wheel" ];
+}