diff options
| -rw-r--r-- | .sops.yaml | 7 | ||||
| -rw-r--r-- | configuration.nix | 340 | ||||
| -rw-r--r-- | flake.lock | 98 | ||||
| -rw-r--r-- | flake.nix | 35 | ||||
| -rw-r--r-- | hardware-configuration.nix | 9 | ||||
| -rw-r--r-- | secrets.yaml | 18 |
6 files changed, 507 insertions, 0 deletions
diff --git a/.sops.yaml b/.sops.yaml new file mode 100644 index 0000000..7935053 --- /dev/null +++ b/.sops.yaml @@ -0,0 +1,7 @@ +keys: + - &botahamec age13dgmrdrztllqp3qawvxwn5c3s6dcc660dkexlqhzz4hye00p7asql8c7cl +creation_rules: + - path_regex: secrets.yaml$ + key_groups: + - age: + - *botahamec diff --git a/configuration.nix b/configuration.nix new file mode 100644 index 0000000..a4d316c --- /dev/null +++ b/configuration.nix @@ -0,0 +1,340 @@ +{ config, pkgs, ... }: { + imports = [ + ./hardware-configuration.nix + ]; + + environment.sessionVariables = { + NH_FLAKE = "/etc/nixos"; + EDITOR = "hx"; + VISUAL = "hx"; + }; + environment.systemPackages = with pkgs; [ + helix + nixd + btop + sops + age + dust + nh + ]; + + services.fail2ban.enable = true; + + security.acme = { + acceptTerms = true; + defaults.email = "botahamec@outlook.com"; + certs."altahamec.dev" = { + webroot = "/var/lib/acme/challenges-altahamec"; + email = "botahamec@outlook.com"; + group = "nginx"; + extraDomainNames = [ "www.altahamec.dev" ]; + }; + certs."botahamec.dev" = { + webroot = "/var/lib/acme/challenges-botahamec"; + email = "botahamec@outlook.com"; + group = "nginx"; + extraDomainNames = [ "www.botahamec.dev" ]; + }; + }; + + programs.mosh.enable = true; + services.openssh = { + enable = true; + settings = { + PermitRootLogin = "no"; + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + }; + }; + + services.vaultwarden = { + enable = true; + backupDir = "/var/local/vaultwarden/backup"; + config = { + DOMAIN = "https://www.altahamec.dev/vault"; + SIGNUPS_ALLOWED = false; + + ROCKET_ADDRESS = "127.0.0.1"; + ROCKET_PORT = 8222; + ROCKET_LOG = "critical"; + }; + }; + + services.copyparty = { + enable = true; + user = "syncthing"; + settings = { + e2dsa = true; + e2ts = true; + shr = "/shares"; + rss = true; + ftp = 3921; + no-robots = true; + rp-loc = "/copyparty"; + }; + accounts = { + botahamec.passwordFile = config.sops.secrets."myPassword".path; + guest.passwordFile = config.sops.secrets."guestPassword".path; + }; + volumes."/" = { + path = "/var/lib/syncthing"; + access.A = [ "botahamec" ]; + access.r = [ "guest" ]; + }; + }; + + services.radicale = { + enable = true; + settings = { + server.hosts = [ "0.0.0.0:5232" ]; + auth = { + type = "htpasswd"; + htpasswd_filename = config.sops.secrets."radicaleAuth".path; + }; + }; + }; + + programs.git = { + enable = true; + config.init.defaultBranch = "main"; + }; + services.cgit."foo" = { + enable = true; + nginx.location = "/cgit/"; + nginx.virtualHost = "botahamec.dev"; + gitHttpBackend.enable = true; + gitHttpBackend.checkExportOkFiles = false; + scanPath = "/var/lib/git-server/"; + group = "git"; + settings = { + enable-tree-linenumbers = false; + enable-html-serving = true; + enable-http-clone = true; + clone-url = "https://botahamec.dev/cgit/$CGIT_REPO_URL"; + remove-suffix = true; + css = "/cgit/cgit.css"; + logo = "/cgit/cgit.png"; + js = "/cgit/cgit.js"; + # readme = "main:README.md"; + # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh"; + # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py"; + # source-filter = "${pkgs.cgit-arborium}/bin/cgit-syntax-highlight"; + }; + }; + # services.cgit."bar" = { + # enable = true; + # nginx.location = "/cgit/"; + # nginx.virtualHost = "altahamec.dev"; + # gitHttpBackend.enable = true; + # gitHttpBackend.checkExportOkFiles = false; + # scanPath = "/var/lib/git-server/"; + # group = "git"; + # settings = { + # enable-tree-linenumbers = false; + # enable-html-serving = true; + # enable-http-clone = true; + # clone-url = "https://altahamec.dev/cgit/$CGIT_REPO_URL"; + # remove-suffix = true; + # css = "/cgit/cgit.css"; + # logo = "/cgit/cgit.png"; + # js = "/cgit/cgit.js"; + # # readme = "main:README.md"; + # # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh"; + # # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py"; + # }; + # }; + + services.syncthing = { + enable = true; + openDefaultPorts = true; + }; + + sops = { + defaultSopsFile = ./secrets.yaml; + defaultSopsFormat = "yaml"; + age.keyFile = "/home/botahamec/.config/sops/age/keys.txt"; + secrets = { + "myPassword" = { + owner = "syncthing"; + mode = "0640"; + }; + "guestPassword" = { + owner = "syncthing"; + mode = "0640"; + }; + "radicaleAuth" = { + owner = "radicale"; + mode = "0640"; + }; + }; + }; + + users.users.nginx.extraGroups = [ "acme" "git" ]; + services.nginx = { + enable = true; + recommendedOptimisation = true; + recommendedBrotliSettings = true; + recommendedGzipSettings = true; + recommendedProxySettings = true; + recommendedTlsSettings = true; + virtualHosts = let config = {useACMEHost, acmeRoot, serverAliases}: { + addSSL = true; + inherit useACMEHost; + inherit serverAliases; + inherit acmeRoot; + locations."/vault/" = { + proxyPass = "http://127.0.0.1:8222"; + recommendedProxySettings = true; + proxyWebsockets = true; + }; + locations."/syncthing/" = { + proxyWebsockets = true; + recommendedProxySettings = true; + extraConfig = '' + proxy_pass http://127.0.0.1:8384/; + + proxy_read_timeout 600s; + proxy_send_timeout 600s; + ''; + }; + locations."/copyparty/" = { + proxyPass = "http://127.0.0.1:3923"; + recommendedProxySettings = true; + proxyWebsockets = true; + extraConfig = '' + # disable buffering + proxy_buffering off; + proxy_request_buffering off; + # improve download speed from 600 to 1500MiB/s; + proxy_buffers 32 8k; + proxy_buffer_size 16k; + proxy_busy_buffers_size 24k; + ''; + }; + locations."/dav/" = { + proxyPass = "http://127.0.0.1:5232"; + extraConfig = '' + proxy_set_header X-Script-Name /dav; + proxy_pass_header Authorization; + ''; + }; + # locations."/cgit\." = { + # root = "${pkgs.cgit}/cgit/"; + # }; + # locations."~ ^(/cgit/.*/(INFO/refs|HEAD|objects/info/.*|git-(upload|receive)-pack))$" = { + # extraConfig = '' + # include ${pkgs.nginx}/conf/fastcgi_params; + # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend; + # fastcgi_param GIT_PROJECT_ROOT /srv/git; + # fastcgi_param GIT_HTTP_EXPORT_ALL ""; + # fastcgi_pass unix:/run/fcgiwrap.sock; + # ''; + # }; + # locations."@cgit" = { + # extraConfig = '' + # include fastcgi_params; + # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend; + # fastcgi_param PATH_INFO $uri; + # fastcgi_param QUERY_STRING $args; + # fastcgi_param HTTP_HOST $server_name; + # fastcgi_pass unix:/run/fcgiwrap.socket; + # ''; + # }; + locations."/" = { + root = "/var/www/botahamec.dev"; + index = "index.html"; + tryFiles = "$uri /blog/$uri /blog/$uri.html $uri.html $uri/ =404"; + }; + }; in { + "altahamec.dev" = config { + useACMEHost = "altahamec.dev"; + serverAliases = ["www.altahamec.dev"]; + acmeRoot = "/var/lib/acme/challenges-altahamec"; + }; + "botahamec.dev" = config { + useACMEHost = "botahamec.dev"; + serverAliases = ["www.botahamec.dev"]; + acmeRoot = "/var/lib/acme/challenges-botahamec"; + }; + }; + }; + + # Workaround for https://github.com/NixOS/nix/issues/8502 + services.logrotate.checkConfig = false; + + networking.hostName = "botahamec-sh"; + networking.firewall.allowedTCPPorts = [ 22 80 443 3921 ]; + + time.timeZone = "America/New_York"; + i18n.defaultLocale = "en_US.UTF-8"; + console.keyMap = "us"; + + security.sudo.wheelNeedsPassword = false; + users.groups.git = {}; + users.users = { + root.hashedPassword = "!"; + botahamec = { + isNormalUser = true; + extraGroups = ["wheel"]; + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1" + ]; + }; + git = { + isSystemUser = true; + group = "git"; + home = "/var/lib/git-server"; + homeMode = "755"; + createHome = true; + shell = "${pkgs.bash}/bin/bash"; + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINWcpi4SrCv2VKRAwBCa4CN7zaVOKfrhEZHf+blndGF8" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFWQ1MW4lfCShJ2C5f0WjKXbgsqAu5oxVexIymZSDJAz" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOdsY6akjlI9IL2nLw8A7s1IbDlz19eLMLU+HZguFPxx" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHBEYjq0+cbiTLbgS3v/LyISLL7CG82fj4yCyqdS2sW6" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKf97P0HlHHudrQuzO/yysIQxZZdEhhnvaclE8ABzNm0" + ]; + }; + radicale = { + extraGroups = [ "syncthing" ]; + }; + }; + + boot.tmp.cleanOnBoot = true; + zramSwap.enable = true; + + system.stateVersion = "26.05"; + system.autoUpgrade = { + enable = true; + dates = "daily"; + flake = "path:///etc/nixos"; + }; + systemd.services.nixos-upgrade = { + after = [ "flake-update.service" ]; + requires = [ "flake-update.service" ]; + }; + systemd.services.flake-update = { + description = "Update flake inputs"; + unitConfig = { + StartLimitIntervalSec = 300; + StartLimitBurst = 5; + }; + serviceConfig = { + ExecStartPre = "${pkgs.networkmanager}/bin/nm-online"; + ExecStart = "${pkgs.nix}/bin/nix flake update --flake /etc/nixos"; + Restart = "on-failure"; + RestartSec = "30"; + Type = "oneshot"; + }; + path = with pkgs; [ nix git host networkmanager ]; + }; + + nix.package = pkgs.lixPackageSets.stable.lix; + nix.gc.automatic = true; + nix.gc.dates = "daily"; + nix.gc.options = "--delete-older-than 1d"; + nix.settings.auto-optimise-store = true; + nix.settings.experimental-features = [ "nix-command" "flakes" ]; + nix.settings.trusted-users = [ "root" "botahamec" "@wheel" ]; +} diff --git a/flake.lock b/flake.lock new file mode 100644 index 0000000..148e306 --- /dev/null +++ b/flake.lock @@ -0,0 +1,98 @@ +{ + "nodes": { + "copyparty": { + "inputs": { + "flake-utils": "flake-utils", + "nixpkgs": "nixpkgs" + }, + "locked": { + "lastModified": 1789682424, + "narHash": "sha256-b0/YFB7nUJ87N8x1QvmFAKn1+YOlIeWRx8fog//0n/E=", + "owner": "9001", + "repo": "copyparty", + "rev": "c688bb2e4684e21e30b430142708e08f6f60ab9e", + "type": "github" + }, + "original": { + "owner": "9001", + "repo": "copyparty", + "type": "github" + } + }, + "flake-utils": { + "locked": { + "lastModified": 1678901627, + "narHash": "sha256-U02riOqrKKzwjsxc/400XnElV+UtPUQWpANPlyazjH0=", + "owner": "numtide", + "repo": "flake-utils", + "rev": "93a2b84fc4b70d9e089d029deacc3583435c2ed6", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "flake-utils", + "type": "github" + } + }, + "nixpkgs": { + "locked": { + "lastModified": 1748162331, + "narHash": "sha256-rqc2RKYTxP3tbjA+PB3VMRQNnjesrT0pEofXQTrMsS8=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "7c43f080a7f28b2774f3b3f43234ca11661bf334", + "type": "github" + }, + "original": { + "id": "nixpkgs", + "ref": "nixos-25.05", + "type": "indirect" + } + }, + "nixpkgs_2": { + "locked": { + "lastModified": 1789542786, + "narHash": "sha256-ajQuqcxnj6RYnwCjA/9FTCnrdR2+BDzstE8UembXf60=", + "owner": "NixOS", + "repo": "nixpkgs", + "rev": "4c7870105e7f1fdf9c48688c8d7efc21abf0688a", + "type": "github" + }, + "original": { + "owner": "NixOS", + "ref": "nixos-26.05", + "repo": "nixpkgs", + "type": "github" + } + }, + "root": { + "inputs": { + "copyparty": "copyparty", + "nixpkgs": "nixpkgs_2", + "sops-nix": "sops-nix" + } + }, + "sops-nix": { + "inputs": { + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1789691124, + "narHash": "sha256-k+I+R6uwHX3VcJ7326qLV6vCahZUgsVl+i8sSU/Stxk=", + "owner": "Mic92", + "repo": "sops-nix", + "rev": "1e73e8f7176d65e1b55e324de099bbfff4b2c574", + "type": "github" + }, + "original": { + "owner": "Mic92", + "repo": "sops-nix", + "type": "github" + } + } + }, + "root": "root", + "version": 7 +} diff --git a/flake.nix b/flake.nix new file mode 100644 index 0000000..cbfe91c --- /dev/null +++ b/flake.nix @@ -0,0 +1,35 @@ +{ + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; + + copyparty.url = "github:9001/copyparty"; + sops-nix.url = "github:Mic92/sops-nix"; + sops-nix.inputs.nixpkgs.follows = "nixpkgs"; + }; + + outputs = { nixpkgs, sops-nix, copyparty, ... }: { + nixosConfigurations.botahamec-sh = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + copyparty.nixosModules.default + ({ pkgs, ... }: { + nixpkgs.overlays = [ copyparty.overlays.default ]; + environment.systemPackages = [ pkgs.copyparty ]; + }) + { + nixpkgs.overlays = [ + (final: prev: { + inherit (prev.lixPackageSets.stable) + nixpkgs-review + nix-eval-jobs + nix-fast-build + colmena; + }) + ]; + } + ./configuration.nix + sops-nix.nixosModules.sops + ]; + }; + }; +} diff --git a/hardware-configuration.nix b/hardware-configuration.nix new file mode 100644 index 0000000..5e7b44e --- /dev/null +++ b/hardware-configuration.nix @@ -0,0 +1,9 @@ +{ modulesPath, ... }: +{ + imports = [ (modulesPath + "/profiles/qemu-guest.nix") ]; + boot.loader.grub.device = "/dev/sda"; + boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "xen_blkfront" "vmw_pvscsi" ]; + boot.initrd.kernelModules = [ "nvme" ]; + fileSystems."/" = { device = "/dev/sda1"; fsType = "ext4"; }; + +} diff --git a/secrets.yaml b/secrets.yaml new file mode 100644 index 0000000..65eaaf8 --- /dev/null +++ b/secrets.yaml @@ -0,0 +1,18 @@ +myPassword: ENC[AES256_GCM,data:GaD6TkutNur8K5IAqg==,iv:6RlxP4/XNO5UZJfgUsu3s3kXHC1aJlbHkxj1eqhDLyM=,tag:LPvYaS9tsG/DKYBLDEOXpA==,type:str] +guestPassword: ENC[AES256_GCM,data:HtELb/UpQs0Q8q+pMEdE4js=,iv:iw/c2U/c7DzdHEdHNkrKwi/mt9zFqmip52EaQz4A9Cc=,tag:MoLYDtLAi3il/26dEeJCXQ==,type:str] +radicaleAuth: ENC[AES256_GCM,data:TVkutNEbiYsRrpXTPGfQyUgeWjEYEjg=,iv:gpi7o/T4TmScADVCpmTphutE3eGjrlWO35T93qdagKE=,tag:WNPUx0gmkdgBU+SMCky6sg==,type:str] +sops: + age: + - enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAra2tBYnI5bW0wSVU1UGZ6 + d25UNDVJc0NhTWh5OXFvNmhIdStCWXdZVVNZCnhYUVJxV0dNWFFtMHF3TDdza2th + ZUNMNkg2OS96MU9DYWVDemRGRFlLZGMKLS0tIEpFeFAvSFJOMUNwbFZpby9NZjY3 + MmVIZmJadFFvV3NWWUVZbDBvbVZkNWMKscpPTrNS51XNBO/8ksoGITFPqx8YorGg + vD5mndjwdSiME8yFaAnxhjFVOo1CVw7NNCeoyYu7oArkszztsBBxQQ== + -----END AGE ENCRYPTED FILE----- + recipient: age13dgmrdrztllqp3qawvxwn5c3s6dcc660dkexlqhzz4hye00p7asql8c7cl + lastmodified: "2026-09-25T02:00:43Z" + mac: ENC[AES256_GCM,data:z1qgAq9ntHvpC5Wpw1QaDb4ShU5Z1a036/+mXIizjn5V4eyE6SQV7niMez1i1/P0KhPLjTAY+GgN9k/xXDyDQue/tuYEyxrtnIX1HXpO0wnl2chAcfTRP4lb71dxOLdTfSvTENB6yse6ALcJ5uDQu1Nt4P0HWc9W2R9xpgaMxuI=,iv:DYX4LSW7FJCPdrhsTtFZV6730l3nNDfhSyiiuL2QQPs=,tag:53RVLfIbLVO3k8Ymcp5uzw==,type:str] + unencrypted_suffix: _unencrypted + version: 3.13.3 |
