From edcbe20b15ec8b09cd1ceac8bf5bfb23bec47172 Mon Sep 17 00:00:00 2001 From: Mica White Date: Sun, 27 Sep 2026 18:27:28 -0400 Subject: Initial commit --- configuration.nix | 340 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 340 insertions(+) create mode 100644 configuration.nix (limited to 'configuration.nix') diff --git a/configuration.nix b/configuration.nix new file mode 100644 index 0000000..a4d316c --- /dev/null +++ b/configuration.nix @@ -0,0 +1,340 @@ +{ config, pkgs, ... }: { + imports = [ + ./hardware-configuration.nix + ]; + + environment.sessionVariables = { + NH_FLAKE = "/etc/nixos"; + EDITOR = "hx"; + VISUAL = "hx"; + }; + environment.systemPackages = with pkgs; [ + helix + nixd + btop + sops + age + dust + nh + ]; + + services.fail2ban.enable = true; + + security.acme = { + acceptTerms = true; + defaults.email = "botahamec@outlook.com"; + certs."altahamec.dev" = { + webroot = "/var/lib/acme/challenges-altahamec"; + email = "botahamec@outlook.com"; + group = "nginx"; + extraDomainNames = [ "www.altahamec.dev" ]; + }; + certs."botahamec.dev" = { + webroot = "/var/lib/acme/challenges-botahamec"; + email = "botahamec@outlook.com"; + group = "nginx"; + extraDomainNames = [ "www.botahamec.dev" ]; + }; + }; + + programs.mosh.enable = true; + services.openssh = { + enable = true; + settings = { + PermitRootLogin = "no"; + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + }; + }; + + services.vaultwarden = { + enable = true; + backupDir = "/var/local/vaultwarden/backup"; + config = { + DOMAIN = "https://www.altahamec.dev/vault"; + SIGNUPS_ALLOWED = false; + + ROCKET_ADDRESS = "127.0.0.1"; + ROCKET_PORT = 8222; + ROCKET_LOG = "critical"; + }; + }; + + services.copyparty = { + enable = true; + user = "syncthing"; + settings = { + e2dsa = true; + e2ts = true; + shr = "/shares"; + rss = true; + ftp = 3921; + no-robots = true; + rp-loc = "/copyparty"; + }; + accounts = { + botahamec.passwordFile = config.sops.secrets."myPassword".path; + guest.passwordFile = config.sops.secrets."guestPassword".path; + }; + volumes."/" = { + path = "/var/lib/syncthing"; + access.A = [ "botahamec" ]; + access.r = [ "guest" ]; + }; + }; + + services.radicale = { + enable = true; + settings = { + server.hosts = [ "0.0.0.0:5232" ]; + auth = { + type = "htpasswd"; + htpasswd_filename = config.sops.secrets."radicaleAuth".path; + }; + }; + }; + + programs.git = { + enable = true; + config.init.defaultBranch = "main"; + }; + services.cgit."foo" = { + enable = true; + nginx.location = "/cgit/"; + nginx.virtualHost = "botahamec.dev"; + gitHttpBackend.enable = true; + gitHttpBackend.checkExportOkFiles = false; + scanPath = "/var/lib/git-server/"; + group = "git"; + settings = { + enable-tree-linenumbers = false; + enable-html-serving = true; + enable-http-clone = true; + clone-url = "https://botahamec.dev/cgit/$CGIT_REPO_URL"; + remove-suffix = true; + css = "/cgit/cgit.css"; + logo = "/cgit/cgit.png"; + js = "/cgit/cgit.js"; + # readme = "main:README.md"; + # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh"; + # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py"; + # source-filter = "${pkgs.cgit-arborium}/bin/cgit-syntax-highlight"; + }; + }; + # services.cgit."bar" = { + # enable = true; + # nginx.location = "/cgit/"; + # nginx.virtualHost = "altahamec.dev"; + # gitHttpBackend.enable = true; + # gitHttpBackend.checkExportOkFiles = false; + # scanPath = "/var/lib/git-server/"; + # group = "git"; + # settings = { + # enable-tree-linenumbers = false; + # enable-html-serving = true; + # enable-http-clone = true; + # clone-url = "https://altahamec.dev/cgit/$CGIT_REPO_URL"; + # remove-suffix = true; + # css = "/cgit/cgit.css"; + # logo = "/cgit/cgit.png"; + # js = "/cgit/cgit.js"; + # # readme = "main:README.md"; + # # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh"; + # # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py"; + # }; + # }; + + services.syncthing = { + enable = true; + openDefaultPorts = true; + }; + + sops = { + defaultSopsFile = ./secrets.yaml; + defaultSopsFormat = "yaml"; + age.keyFile = "/home/botahamec/.config/sops/age/keys.txt"; + secrets = { + "myPassword" = { + owner = "syncthing"; + mode = "0640"; + }; + "guestPassword" = { + owner = "syncthing"; + mode = "0640"; + }; + "radicaleAuth" = { + owner = "radicale"; + mode = "0640"; + }; + }; + }; + + users.users.nginx.extraGroups = [ "acme" "git" ]; + services.nginx = { + enable = true; + recommendedOptimisation = true; + recommendedBrotliSettings = true; + recommendedGzipSettings = true; + recommendedProxySettings = true; + recommendedTlsSettings = true; + virtualHosts = let config = {useACMEHost, acmeRoot, serverAliases}: { + addSSL = true; + inherit useACMEHost; + inherit serverAliases; + inherit acmeRoot; + locations."/vault/" = { + proxyPass = "http://127.0.0.1:8222"; + recommendedProxySettings = true; + proxyWebsockets = true; + }; + locations."/syncthing/" = { + proxyWebsockets = true; + recommendedProxySettings = true; + extraConfig = '' + proxy_pass http://127.0.0.1:8384/; + + proxy_read_timeout 600s; + proxy_send_timeout 600s; + ''; + }; + locations."/copyparty/" = { + proxyPass = "http://127.0.0.1:3923"; + recommendedProxySettings = true; + proxyWebsockets = true; + extraConfig = '' + # disable buffering + proxy_buffering off; + proxy_request_buffering off; + # improve download speed from 600 to 1500MiB/s; + proxy_buffers 32 8k; + proxy_buffer_size 16k; + proxy_busy_buffers_size 24k; + ''; + }; + locations."/dav/" = { + proxyPass = "http://127.0.0.1:5232"; + extraConfig = '' + proxy_set_header X-Script-Name /dav; + proxy_pass_header Authorization; + ''; + }; + # locations."/cgit\." = { + # root = "${pkgs.cgit}/cgit/"; + # }; + # locations."~ ^(/cgit/.*/(INFO/refs|HEAD|objects/info/.*|git-(upload|receive)-pack))$" = { + # extraConfig = '' + # include ${pkgs.nginx}/conf/fastcgi_params; + # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend; + # fastcgi_param GIT_PROJECT_ROOT /srv/git; + # fastcgi_param GIT_HTTP_EXPORT_ALL ""; + # fastcgi_pass unix:/run/fcgiwrap.sock; + # ''; + # }; + # locations."@cgit" = { + # extraConfig = '' + # include fastcgi_params; + # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend; + # fastcgi_param PATH_INFO $uri; + # fastcgi_param QUERY_STRING $args; + # fastcgi_param HTTP_HOST $server_name; + # fastcgi_pass unix:/run/fcgiwrap.socket; + # ''; + # }; + locations."/" = { + root = "/var/www/botahamec.dev"; + index = "index.html"; + tryFiles = "$uri /blog/$uri /blog/$uri.html $uri.html $uri/ =404"; + }; + }; in { + "altahamec.dev" = config { + useACMEHost = "altahamec.dev"; + serverAliases = ["www.altahamec.dev"]; + acmeRoot = "/var/lib/acme/challenges-altahamec"; + }; + "botahamec.dev" = config { + useACMEHost = "botahamec.dev"; + serverAliases = ["www.botahamec.dev"]; + acmeRoot = "/var/lib/acme/challenges-botahamec"; + }; + }; + }; + + # Workaround for https://github.com/NixOS/nix/issues/8502 + services.logrotate.checkConfig = false; + + networking.hostName = "botahamec-sh"; + networking.firewall.allowedTCPPorts = [ 22 80 443 3921 ]; + + time.timeZone = "America/New_York"; + i18n.defaultLocale = "en_US.UTF-8"; + console.keyMap = "us"; + + security.sudo.wheelNeedsPassword = false; + users.groups.git = {}; + users.users = { + root.hashedPassword = "!"; + botahamec = { + isNormalUser = true; + extraGroups = ["wheel"]; + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1" + ]; + }; + git = { + isSystemUser = true; + group = "git"; + home = "/var/lib/git-server"; + homeMode = "755"; + createHome = true; + shell = "${pkgs.bash}/bin/bash"; + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINWcpi4SrCv2VKRAwBCa4CN7zaVOKfrhEZHf+blndGF8" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFWQ1MW4lfCShJ2C5f0WjKXbgsqAu5oxVexIymZSDJAz" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOdsY6akjlI9IL2nLw8A7s1IbDlz19eLMLU+HZguFPxx" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHBEYjq0+cbiTLbgS3v/LyISLL7CG82fj4yCyqdS2sW6" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKf97P0HlHHudrQuzO/yysIQxZZdEhhnvaclE8ABzNm0" + ]; + }; + radicale = { + extraGroups = [ "syncthing" ]; + }; + }; + + boot.tmp.cleanOnBoot = true; + zramSwap.enable = true; + + system.stateVersion = "26.05"; + system.autoUpgrade = { + enable = true; + dates = "daily"; + flake = "path:///etc/nixos"; + }; + systemd.services.nixos-upgrade = { + after = [ "flake-update.service" ]; + requires = [ "flake-update.service" ]; + }; + systemd.services.flake-update = { + description = "Update flake inputs"; + unitConfig = { + StartLimitIntervalSec = 300; + StartLimitBurst = 5; + }; + serviceConfig = { + ExecStartPre = "${pkgs.networkmanager}/bin/nm-online"; + ExecStart = "${pkgs.nix}/bin/nix flake update --flake /etc/nixos"; + Restart = "on-failure"; + RestartSec = "30"; + Type = "oneshot"; + }; + path = with pkgs; [ nix git host networkmanager ]; + }; + + nix.package = pkgs.lixPackageSets.stable.lix; + nix.gc.automatic = true; + nix.gc.dates = "daily"; + nix.gc.options = "--delete-older-than 1d"; + nix.settings.auto-optimise-store = true; + nix.settings.experimental-features = [ "nix-command" "flakes" ]; + nix.settings.trusted-users = [ "root" "botahamec" "@wheel" ]; +} -- cgit v1.3.1