{ config, pkgs, ... }: { imports = [ ./hardware-configuration.nix ]; environment.sessionVariables = { NH_FLAKE = "/etc/nixos"; EDITOR = "hx"; VISUAL = "hx"; }; environment.systemPackages = with pkgs; [ helix nixd btop sops age dust nh codeberg-cli ]; services.fail2ban.enable = true; security.acme = { acceptTerms = true; defaults.email = "botahamec@outlook.com"; certs."altahamec.dev" = { webroot = "/var/lib/acme/challenges-altahamec"; email = "botahamec@outlook.com"; group = "nginx"; extraDomainNames = [ "www.altahamec.dev" ]; }; certs."botahamec.dev" = { webroot = "/var/lib/acme/challenges-botahamec"; email = "botahamec@outlook.com"; group = "nginx"; extraDomainNames = [ "www.botahamec.dev" ]; }; }; programs.mosh.enable = true; services.openssh = { enable = true; settings = { PermitRootLogin = "no"; PasswordAuthentication = false; KbdInteractiveAuthentication = false; }; }; services.vaultwarden = { enable = true; backupDir = "/var/local/vaultwarden/backup"; config = { DOMAIN = "https://www.altahamec.dev/vault"; SIGNUPS_ALLOWED = false; ROCKET_ADDRESS = "127.0.0.1"; ROCKET_PORT = 8222; ROCKET_LOG = "critical"; }; }; services.copyparty = { enable = true; user = "syncthing"; settings = { e2dsa = true; e2ts = true; shr = "/shares"; rss = true; ftp = 3921; no-robots = true; rp-loc = "/copyparty"; }; accounts = { botahamec.passwordFile = config.sops.secrets."myPassword".path; guest.passwordFile = config.sops.secrets."guestPassword".path; }; volumes."/" = { path = "/var/lib/syncthing"; access.A = [ "botahamec" ]; access.r = [ "guest" ]; }; }; services.radicale = { enable = true; settings = { server.hosts = [ "0.0.0.0:5232" ]; auth = { type = "htpasswd"; htpasswd_filename = config.sops.secrets."radicaleAuth".path; }; }; }; programs.git = { enable = true; config.init.defaultBranch = "main"; }; services.cgit."foo" = { enable = true; nginx.location = "/cgit/"; nginx.virtualHost = "botahamec.dev"; gitHttpBackend.enable = true; gitHttpBackend.checkExportOkFiles = false; scanPath = "/var/lib/git-server/"; group = "git"; settings = { enable-tree-linenumbers = false; enable-html-serving = true; enable-http-clone = true; clone-url = "https://botahamec.dev/cgit/$CGIT_REPO_URL"; remove-suffix = true; css = "/cgit/cgit.css"; logo = "/cgit/cgit.png"; js = "/cgit/cgit.js"; # readme = "main:README.md"; # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh"; # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py"; # source-filter = "${pkgs.cgit-arborium}/bin/cgit-syntax-highlight"; }; }; # services.cgit."bar" = { # enable = true; # nginx.location = "/cgit/"; # nginx.virtualHost = "altahamec.dev"; # gitHttpBackend.enable = true; # gitHttpBackend.checkExportOkFiles = false; # scanPath = "/var/lib/git-server/"; # group = "git"; # settings = { # enable-tree-linenumbers = false; # enable-html-serving = true; # enable-http-clone = true; # clone-url = "https://altahamec.dev/cgit/$CGIT_REPO_URL"; # remove-suffix = true; # css = "/cgit/cgit.css"; # logo = "/cgit/cgit.png"; # js = "/cgit/cgit.js"; # # readme = "main:README.md"; # # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh"; # # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py"; # }; # }; services.syncthing = { enable = true; openDefaultPorts = true; }; sops = { defaultSopsFile = ./secrets.yaml; defaultSopsFormat = "yaml"; age.keyFile = "/home/botahamec/.config/sops/age/keys.txt"; secrets = { "myPassword" = { owner = "syncthing"; mode = "0640"; }; "guestPassword" = { owner = "syncthing"; mode = "0640"; }; "radicaleAuth" = { owner = "radicale"; mode = "0640"; }; }; }; users.users.nginx.extraGroups = [ "acme" "git" ]; services.nginx = { enable = true; recommendedOptimisation = true; recommendedBrotliSettings = true; recommendedGzipSettings = true; recommendedProxySettings = true; recommendedTlsSettings = true; virtualHosts = let config = {useACMEHost, acmeRoot, serverAliases}: { addSSL = true; inherit useACMEHost; inherit serverAliases; inherit acmeRoot; locations."/vault/" = { proxyPass = "http://127.0.0.1:8222"; recommendedProxySettings = true; proxyWebsockets = true; }; locations."/syncthing/" = { proxyWebsockets = true; recommendedProxySettings = true; extraConfig = '' proxy_pass http://127.0.0.1:8384/; proxy_read_timeout 600s; proxy_send_timeout 600s; ''; }; locations."/copyparty/" = { proxyPass = "http://127.0.0.1:3923"; recommendedProxySettings = true; proxyWebsockets = true; extraConfig = '' # disable buffering proxy_buffering off; proxy_request_buffering off; # improve download speed from 600 to 1500MiB/s; proxy_buffers 32 8k; proxy_buffer_size 16k; proxy_busy_buffers_size 24k; ''; }; locations."/dav/" = { proxyPass = "http://127.0.0.1:5232"; extraConfig = '' proxy_set_header X-Script-Name /dav; proxy_pass_header Authorization; ''; }; # locations."/cgit\." = { # root = "${pkgs.cgit}/cgit/"; # }; # locations."~ ^(/cgit/.*/(INFO/refs|HEAD|objects/info/.*|git-(upload|receive)-pack))$" = { # extraConfig = '' # include ${pkgs.nginx}/conf/fastcgi_params; # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend; # fastcgi_param GIT_PROJECT_ROOT /srv/git; # fastcgi_param GIT_HTTP_EXPORT_ALL ""; # fastcgi_pass unix:/run/fcgiwrap.sock; # ''; # }; # locations."@cgit" = { # extraConfig = '' # include fastcgi_params; # fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend; # fastcgi_param PATH_INFO $uri; # fastcgi_param QUERY_STRING $args; # fastcgi_param HTTP_HOST $server_name; # fastcgi_pass unix:/run/fcgiwrap.socket; # ''; # }; locations."/" = { root = "/var/www/botahamec.dev"; index = "index.html"; tryFiles = "$uri /blog/$uri /blog/$uri.html $uri.html $uri/ =404"; }; }; in { "altahamec.dev" = config { useACMEHost = "altahamec.dev"; serverAliases = ["www.altahamec.dev"]; acmeRoot = "/var/lib/acme/challenges-altahamec"; }; "botahamec.dev" = config { useACMEHost = "botahamec.dev"; serverAliases = ["www.botahamec.dev"]; acmeRoot = "/var/lib/acme/challenges-botahamec"; }; }; }; # Workaround for https://github.com/NixOS/nix/issues/8502 services.logrotate.checkConfig = false; networking.hostName = "botahamec-sh"; networking.firewall.allowedTCPPorts = [ 22 80 443 3921 ]; time.timeZone = "America/New_York"; i18n.defaultLocale = "en_US.UTF-8"; console.keyMap = "us"; security.sudo.wheelNeedsPassword = false; users.groups.git = {}; users.users = { root.hashedPassword = "!"; botahamec = { isNormalUser = true; extraGroups = ["wheel"]; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1" ]; }; git = { isSystemUser = true; group = "git"; home = "/var/lib/git-server"; homeMode = "755"; createHome = true; shell = "${pkgs.bash}/bin/bash"; openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINWcpi4SrCv2VKRAwBCa4CN7zaVOKfrhEZHf+blndGF8" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFWQ1MW4lfCShJ2C5f0WjKXbgsqAu5oxVexIymZSDJAz" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOdsY6akjlI9IL2nLw8A7s1IbDlz19eLMLU+HZguFPxx" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHBEYjq0+cbiTLbgS3v/LyISLL7CG82fj4yCyqdS2sW6" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKf97P0HlHHudrQuzO/yysIQxZZdEhhnvaclE8ABzNm0" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICkVyhHW6Me4IAd8m37mPn6mjWOxjffrZWtP9Oq0peSj" ]; }; radicale = { extraGroups = [ "syncthing" ]; }; }; boot.tmp.cleanOnBoot = true; zramSwap.enable = true; system.stateVersion = "26.05"; system.autoUpgrade = { enable = true; dates = "daily"; flake = "path:///etc/nixos"; }; systemd.services.nixos-upgrade = { after = [ "flake-update.service" ]; requires = [ "flake-update.service" ]; }; systemd.services.flake-update = { description = "Update flake inputs"; unitConfig = { StartLimitIntervalSec = 300; StartLimitBurst = 5; }; serviceConfig = { ExecStartPre = "${pkgs.networkmanager}/bin/nm-online"; ExecStart = "${pkgs.nix}/bin/nix flake update --flake /etc/nixos"; Restart = "on-failure"; RestartSec = "30"; Type = "oneshot"; }; path = with pkgs; [ nix git host networkmanager ]; }; nix.package = pkgs.lixPackageSets.stable.lix; nix.gc.automatic = true; nix.gc.dates = "daily"; nix.gc.options = "--delete-older-than 1d"; nix.settings.auto-optimise-store = true; nix.settings.experimental-features = [ "nix-command" "flakes" ]; nix.settings.trusted-users = [ "root" "botahamec" "@wheel" ]; }