summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--.sops.yaml7
-rw-r--r--configuration.nix340
-rw-r--r--flake.lock98
-rw-r--r--flake.nix35
-rw-r--r--hardware-configuration.nix9
-rw-r--r--secrets.yaml18
6 files changed, 507 insertions, 0 deletions
diff --git a/.sops.yaml b/.sops.yaml
new file mode 100644
index 0000000..7935053
--- /dev/null
+++ b/.sops.yaml
@@ -0,0 +1,7 @@
+keys:
+ - &botahamec age13dgmrdrztllqp3qawvxwn5c3s6dcc660dkexlqhzz4hye00p7asql8c7cl
+creation_rules:
+ - path_regex: secrets.yaml$
+ key_groups:
+ - age:
+ - *botahamec
diff --git a/configuration.nix b/configuration.nix
new file mode 100644
index 0000000..a4d316c
--- /dev/null
+++ b/configuration.nix
@@ -0,0 +1,340 @@
+{ config, pkgs, ... }: {
+ imports = [
+ ./hardware-configuration.nix
+ ];
+
+ environment.sessionVariables = {
+ NH_FLAKE = "/etc/nixos";
+ EDITOR = "hx";
+ VISUAL = "hx";
+ };
+ environment.systemPackages = with pkgs; [
+ helix
+ nixd
+ btop
+ sops
+ age
+ dust
+ nh
+ ];
+
+ services.fail2ban.enable = true;
+
+ security.acme = {
+ acceptTerms = true;
+ defaults.email = "botahamec@outlook.com";
+ certs."altahamec.dev" = {
+ webroot = "/var/lib/acme/challenges-altahamec";
+ email = "botahamec@outlook.com";
+ group = "nginx";
+ extraDomainNames = [ "www.altahamec.dev" ];
+ };
+ certs."botahamec.dev" = {
+ webroot = "/var/lib/acme/challenges-botahamec";
+ email = "botahamec@outlook.com";
+ group = "nginx";
+ extraDomainNames = [ "www.botahamec.dev" ];
+ };
+ };
+
+ programs.mosh.enable = true;
+ services.openssh = {
+ enable = true;
+ settings = {
+ PermitRootLogin = "no";
+ PasswordAuthentication = false;
+ KbdInteractiveAuthentication = false;
+ };
+ };
+
+ services.vaultwarden = {
+ enable = true;
+ backupDir = "/var/local/vaultwarden/backup";
+ config = {
+ DOMAIN = "https://www.altahamec.dev/vault";
+ SIGNUPS_ALLOWED = false;
+
+ ROCKET_ADDRESS = "127.0.0.1";
+ ROCKET_PORT = 8222;
+ ROCKET_LOG = "critical";
+ };
+ };
+
+ services.copyparty = {
+ enable = true;
+ user = "syncthing";
+ settings = {
+ e2dsa = true;
+ e2ts = true;
+ shr = "/shares";
+ rss = true;
+ ftp = 3921;
+ no-robots = true;
+ rp-loc = "/copyparty";
+ };
+ accounts = {
+ botahamec.passwordFile = config.sops.secrets."myPassword".path;
+ guest.passwordFile = config.sops.secrets."guestPassword".path;
+ };
+ volumes."/" = {
+ path = "/var/lib/syncthing";
+ access.A = [ "botahamec" ];
+ access.r = [ "guest" ];
+ };
+ };
+
+ services.radicale = {
+ enable = true;
+ settings = {
+ server.hosts = [ "0.0.0.0:5232" ];
+ auth = {
+ type = "htpasswd";
+ htpasswd_filename = config.sops.secrets."radicaleAuth".path;
+ };
+ };
+ };
+
+ programs.git = {
+ enable = true;
+ config.init.defaultBranch = "main";
+ };
+ services.cgit."foo" = {
+ enable = true;
+ nginx.location = "/cgit/";
+ nginx.virtualHost = "botahamec.dev";
+ gitHttpBackend.enable = true;
+ gitHttpBackend.checkExportOkFiles = false;
+ scanPath = "/var/lib/git-server/";
+ group = "git";
+ settings = {
+ enable-tree-linenumbers = false;
+ enable-html-serving = true;
+ enable-http-clone = true;
+ clone-url = "https://botahamec.dev/cgit/$CGIT_REPO_URL";
+ remove-suffix = true;
+ css = "/cgit/cgit.css";
+ logo = "/cgit/cgit.png";
+ js = "/cgit/cgit.js";
+ # readme = "main:README.md";
+ # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh";
+ # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py";
+ # source-filter = "${pkgs.cgit-arborium}/bin/cgit-syntax-highlight";
+ };
+ };
+ # services.cgit."bar" = {
+ # enable = true;
+ # nginx.location = "/cgit/";
+ # nginx.virtualHost = "altahamec.dev";
+ # gitHttpBackend.enable = true;
+ # gitHttpBackend.checkExportOkFiles = false;
+ # scanPath = "/var/lib/git-server/";
+ # group = "git";
+ # settings = {
+ # enable-tree-linenumbers = false;
+ # enable-html-serving = true;
+ # enable-http-clone = true;
+ # clone-url = "https://altahamec.dev/cgit/$CGIT_REPO_URL";
+ # remove-suffix = true;
+ # css = "/cgit/cgit.css";
+ # logo = "/cgit/cgit.png";
+ # js = "/cgit/cgit.js";
+ # # readme = "main:README.md";
+ # # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh";
+ # # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py";
+ # };
+ # };
+
+ services.syncthing = {
+ enable = true;
+ openDefaultPorts = true;
+ };
+
+ sops = {
+ defaultSopsFile = ./secrets.yaml;
+ defaultSopsFormat = "yaml";
+ age.keyFile = "/home/botahamec/.config/sops/age/keys.txt";
+ secrets = {
+ "myPassword" = {
+ owner = "syncthing";
+ mode = "0640";
+ };
+ "guestPassword" = {
+ owner = "syncthing";
+ mode = "0640";
+ };
+ "radicaleAuth" = {
+ owner = "radicale";
+ mode = "0640";
+ };
+ };
+ };
+
+ users.users.nginx.extraGroups = [ "acme" "git" ];
+ services.nginx = {
+ enable = true;
+ recommendedOptimisation = true;
+ recommendedBrotliSettings = true;
+ recommendedGzipSettings = true;
+ recommendedProxySettings = true;
+ recommendedTlsSettings = true;
+ virtualHosts = let config = {useACMEHost, acmeRoot, serverAliases}: {
+ addSSL = true;
+ inherit useACMEHost;
+ inherit serverAliases;
+ inherit acmeRoot;
+ locations."/vault/" = {
+ proxyPass = "http://127.0.0.1:8222";
+ recommendedProxySettings = true;
+ proxyWebsockets = true;
+ };
+ locations."/syncthing/" = {
+ proxyWebsockets = true;
+ recommendedProxySettings = true;
+ extraConfig = ''
+ proxy_pass http://127.0.0.1:8384/;
+
+ proxy_read_timeout 600s;
+ proxy_send_timeout 600s;
+ '';
+ };
+ locations."/copyparty/" = {
+ proxyPass = "http://127.0.0.1:3923";
+ recommendedProxySettings = true;
+ proxyWebsockets = true;
+ extraConfig = ''
+ # disable buffering
+ proxy_buffering off;
+ proxy_request_buffering off;
+ # improve download speed from 600 to 1500MiB/s;
+ proxy_buffers 32 8k;
+ proxy_buffer_size 16k;
+ proxy_busy_buffers_size 24k;
+ '';
+ };
+ locations."/dav/" = {
+ proxyPass = "http://127.0.0.1:5232";
+ extraConfig = ''
+ proxy_set_header X-Script-Name /dav;
+ proxy_pass_header Authorization;
+ '';
+ };
+ # locations."/cgit\." = {
+ # root = "${pkgs.cgit}/cgit/";
+ # };
+ # locations."~ ^(/cgit/.*/(INFO/refs|HEAD|objects/info/.*|git-(upload|receive)-pack))$" = {
+ # extraConfig = ''
+ # include ${pkgs.nginx}/conf/fastcgi_params;
+ # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend;
+ # fastcgi_param GIT_PROJECT_ROOT /srv/git;
+ # fastcgi_param GIT_HTTP_EXPORT_ALL "";
+ # fastcgi_pass unix:/run/fcgiwrap.sock;
+ # '';
+ # };
+ # locations."@cgit" = {
+ # extraConfig = ''
+ # include fastcgi_params;
+ # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend;
+ # fastcgi_param PATH_INFO $uri;
+ # fastcgi_param QUERY_STRING $args;
+ # fastcgi_param HTTP_HOST $server_name;
+ # fastcgi_pass unix:/run/fcgiwrap.socket;
+ # '';
+ # };
+ locations."/" = {
+ root = "/var/www/botahamec.dev";
+ index = "index.html";
+ tryFiles = "$uri /blog/$uri /blog/$uri.html $uri.html $uri/ =404";
+ };
+ }; in {
+ "altahamec.dev" = config {
+ useACMEHost = "altahamec.dev";
+ serverAliases = ["www.altahamec.dev"];
+ acmeRoot = "/var/lib/acme/challenges-altahamec";
+ };
+ "botahamec.dev" = config {
+ useACMEHost = "botahamec.dev";
+ serverAliases = ["www.botahamec.dev"];
+ acmeRoot = "/var/lib/acme/challenges-botahamec";
+ };
+ };
+ };
+
+ # Workaround for https://github.com/NixOS/nix/issues/8502
+ services.logrotate.checkConfig = false;
+
+ networking.hostName = "botahamec-sh";
+ networking.firewall.allowedTCPPorts = [ 22 80 443 3921 ];
+
+ time.timeZone = "America/New_York";
+ i18n.defaultLocale = "en_US.UTF-8";
+ console.keyMap = "us";
+
+ security.sudo.wheelNeedsPassword = false;
+ users.groups.git = {};
+ users.users = {
+ root.hashedPassword = "!";
+ botahamec = {
+ isNormalUser = true;
+ extraGroups = ["wheel"];
+ openssh.authorizedKeys.keys = [
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1"
+ ];
+ };
+ git = {
+ isSystemUser = true;
+ group = "git";
+ home = "/var/lib/git-server";
+ homeMode = "755";
+ createHome = true;
+ shell = "${pkgs.bash}/bin/bash";
+ openssh.authorizedKeys.keys = [
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINWcpi4SrCv2VKRAwBCa4CN7zaVOKfrhEZHf+blndGF8"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFWQ1MW4lfCShJ2C5f0WjKXbgsqAu5oxVexIymZSDJAz"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOdsY6akjlI9IL2nLw8A7s1IbDlz19eLMLU+HZguFPxx"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHBEYjq0+cbiTLbgS3v/LyISLL7CG82fj4yCyqdS2sW6"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKf97P0HlHHudrQuzO/yysIQxZZdEhhnvaclE8ABzNm0"
+ ];
+ };
+ radicale = {
+ extraGroups = [ "syncthing" ];
+ };
+ };
+
+ boot.tmp.cleanOnBoot = true;
+ zramSwap.enable = true;
+
+ system.stateVersion = "26.05";
+ system.autoUpgrade = {
+ enable = true;
+ dates = "daily";
+ flake = "path:///etc/nixos";
+ };
+ systemd.services.nixos-upgrade = {
+ after = [ "flake-update.service" ];
+ requires = [ "flake-update.service" ];
+ };
+ systemd.services.flake-update = {
+ description = "Update flake inputs";
+ unitConfig = {
+ StartLimitIntervalSec = 300;
+ StartLimitBurst = 5;
+ };
+ serviceConfig = {
+ ExecStartPre = "${pkgs.networkmanager}/bin/nm-online";
+ ExecStart = "${pkgs.nix}/bin/nix flake update --flake /etc/nixos";
+ Restart = "on-failure";
+ RestartSec = "30";
+ Type = "oneshot";
+ };
+ path = with pkgs; [ nix git host networkmanager ];
+ };
+
+ nix.package = pkgs.lixPackageSets.stable.lix;
+ nix.gc.automatic = true;
+ nix.gc.dates = "daily";
+ nix.gc.options = "--delete-older-than 1d";
+ nix.settings.auto-optimise-store = true;
+ nix.settings.experimental-features = [ "nix-command" "flakes" ];
+ nix.settings.trusted-users = [ "root" "botahamec" "@wheel" ];
+}
diff --git a/flake.lock b/flake.lock
new file mode 100644
index 0000000..148e306
--- /dev/null
+++ b/flake.lock
@@ -0,0 +1,98 @@
+{
+ "nodes": {
+ "copyparty": {
+ "inputs": {
+ "flake-utils": "flake-utils",
+ "nixpkgs": "nixpkgs"
+ },
+ "locked": {
+ "lastModified": 1789682424,
+ "narHash": "sha256-b0/YFB7nUJ87N8x1QvmFAKn1+YOlIeWRx8fog//0n/E=",
+ "owner": "9001",
+ "repo": "copyparty",
+ "rev": "c688bb2e4684e21e30b430142708e08f6f60ab9e",
+ "type": "github"
+ },
+ "original": {
+ "owner": "9001",
+ "repo": "copyparty",
+ "type": "github"
+ }
+ },
+ "flake-utils": {
+ "locked": {
+ "lastModified": 1678901627,
+ "narHash": "sha256-U02riOqrKKzwjsxc/400XnElV+UtPUQWpANPlyazjH0=",
+ "owner": "numtide",
+ "repo": "flake-utils",
+ "rev": "93a2b84fc4b70d9e089d029deacc3583435c2ed6",
+ "type": "github"
+ },
+ "original": {
+ "owner": "numtide",
+ "repo": "flake-utils",
+ "type": "github"
+ }
+ },
+ "nixpkgs": {
+ "locked": {
+ "lastModified": 1748162331,
+ "narHash": "sha256-rqc2RKYTxP3tbjA+PB3VMRQNnjesrT0pEofXQTrMsS8=",
+ "owner": "NixOS",
+ "repo": "nixpkgs",
+ "rev": "7c43f080a7f28b2774f3b3f43234ca11661bf334",
+ "type": "github"
+ },
+ "original": {
+ "id": "nixpkgs",
+ "ref": "nixos-25.05",
+ "type": "indirect"
+ }
+ },
+ "nixpkgs_2": {
+ "locked": {
+ "lastModified": 1789542786,
+ "narHash": "sha256-ajQuqcxnj6RYnwCjA/9FTCnrdR2+BDzstE8UembXf60=",
+ "owner": "NixOS",
+ "repo": "nixpkgs",
+ "rev": "4c7870105e7f1fdf9c48688c8d7efc21abf0688a",
+ "type": "github"
+ },
+ "original": {
+ "owner": "NixOS",
+ "ref": "nixos-26.05",
+ "repo": "nixpkgs",
+ "type": "github"
+ }
+ },
+ "root": {
+ "inputs": {
+ "copyparty": "copyparty",
+ "nixpkgs": "nixpkgs_2",
+ "sops-nix": "sops-nix"
+ }
+ },
+ "sops-nix": {
+ "inputs": {
+ "nixpkgs": [
+ "nixpkgs"
+ ]
+ },
+ "locked": {
+ "lastModified": 1789691124,
+ "narHash": "sha256-k+I+R6uwHX3VcJ7326qLV6vCahZUgsVl+i8sSU/Stxk=",
+ "owner": "Mic92",
+ "repo": "sops-nix",
+ "rev": "1e73e8f7176d65e1b55e324de099bbfff4b2c574",
+ "type": "github"
+ },
+ "original": {
+ "owner": "Mic92",
+ "repo": "sops-nix",
+ "type": "github"
+ }
+ }
+ },
+ "root": "root",
+ "version": 7
+}
diff --git a/flake.nix b/flake.nix
new file mode 100644
index 0000000..cbfe91c
--- /dev/null
+++ b/flake.nix
@@ -0,0 +1,35 @@
+{
+ inputs = {
+ nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
+
+ copyparty.url = "github:9001/copyparty";
+ sops-nix.url = "github:Mic92/sops-nix";
+ sops-nix.inputs.nixpkgs.follows = "nixpkgs";
+ };
+
+ outputs = { nixpkgs, sops-nix, copyparty, ... }: {
+ nixosConfigurations.botahamec-sh = nixpkgs.lib.nixosSystem {
+ system = "x86_64-linux";
+ modules = [
+ copyparty.nixosModules.default
+ ({ pkgs, ... }: {
+ nixpkgs.overlays = [ copyparty.overlays.default ];
+ environment.systemPackages = [ pkgs.copyparty ];
+ })
+ {
+ nixpkgs.overlays = [
+ (final: prev: {
+ inherit (prev.lixPackageSets.stable)
+ nixpkgs-review
+ nix-eval-jobs
+ nix-fast-build
+ colmena;
+ })
+ ];
+ }
+ ./configuration.nix
+ sops-nix.nixosModules.sops
+ ];
+ };
+ };
+}
diff --git a/hardware-configuration.nix b/hardware-configuration.nix
new file mode 100644
index 0000000..5e7b44e
--- /dev/null
+++ b/hardware-configuration.nix
@@ -0,0 +1,9 @@
+{ modulesPath, ... }:
+{
+ imports = [ (modulesPath + "/profiles/qemu-guest.nix") ];
+ boot.loader.grub.device = "/dev/sda";
+ boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "xen_blkfront" "vmw_pvscsi" ];
+ boot.initrd.kernelModules = [ "nvme" ];
+ fileSystems."/" = { device = "/dev/sda1"; fsType = "ext4"; };
+
+}
diff --git a/secrets.yaml b/secrets.yaml
new file mode 100644
index 0000000..65eaaf8
--- /dev/null
+++ b/secrets.yaml
@@ -0,0 +1,18 @@
+myPassword: ENC[AES256_GCM,data:GaD6TkutNur8K5IAqg==,iv:6RlxP4/XNO5UZJfgUsu3s3kXHC1aJlbHkxj1eqhDLyM=,tag:LPvYaS9tsG/DKYBLDEOXpA==,type:str]
+guestPassword: ENC[AES256_GCM,data:HtELb/UpQs0Q8q+pMEdE4js=,iv:iw/c2U/c7DzdHEdHNkrKwi/mt9zFqmip52EaQz4A9Cc=,tag:MoLYDtLAi3il/26dEeJCXQ==,type:str]
+radicaleAuth: ENC[AES256_GCM,data:TVkutNEbiYsRrpXTPGfQyUgeWjEYEjg=,iv:gpi7o/T4TmScADVCpmTphutE3eGjrlWO35T93qdagKE=,tag:WNPUx0gmkdgBU+SMCky6sg==,type:str]
+sops:
+ age:
+ - enc: |
+ -----BEGIN AGE ENCRYPTED FILE-----
+ YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAra2tBYnI5bW0wSVU1UGZ6
+ d25UNDVJc0NhTWh5OXFvNmhIdStCWXdZVVNZCnhYUVJxV0dNWFFtMHF3TDdza2th
+ ZUNMNkg2OS96MU9DYWVDemRGRFlLZGMKLS0tIEpFeFAvSFJOMUNwbFZpby9NZjY3
+ MmVIZmJadFFvV3NWWUVZbDBvbVZkNWMKscpPTrNS51XNBO/8ksoGITFPqx8YorGg
+ vD5mndjwdSiME8yFaAnxhjFVOo1CVw7NNCeoyYu7oArkszztsBBxQQ==
+ -----END AGE ENCRYPTED FILE-----
+ recipient: age13dgmrdrztllqp3qawvxwn5c3s6dcc660dkexlqhzz4hye00p7asql8c7cl
+ lastmodified: "2026-09-25T02:00:43Z"
+ mac: ENC[AES256_GCM,data:z1qgAq9ntHvpC5Wpw1QaDb4ShU5Z1a036/+mXIizjn5V4eyE6SQV7niMez1i1/P0KhPLjTAY+GgN9k/xXDyDQue/tuYEyxrtnIX1HXpO0wnl2chAcfTRP4lb71dxOLdTfSvTENB6yse6ALcJ5uDQu1Nt4P0HWc9W2R9xpgaMxuI=,iv:DYX4LSW7FJCPdrhsTtFZV6730l3nNDfhSyiiuL2QQPs=,tag:53RVLfIbLVO3k8Ymcp5uzw==,type:str]
+ unencrypted_suffix: _unencrypted
+ version: 3.13.3