summaryrefslogtreecommitdiff
path: root/configuration.nix
blob: 15d08a36a4ca68cb3bb978f01a5903c9a02ae6cd (plain)
{ config, pkgs, ... }: {
  imports = [
    ./hardware-configuration.nix    
  ];

  environment.sessionVariables = {
    NH_FLAKE = "/etc/nixos";
    EDITOR = "hx";
    VISUAL = "hx";
  };
  environment.systemPackages = with pkgs; [
    helix
    nixd
    btop
    sops
    age
    dust
    nh
  ];

  services.fail2ban.enable = true;

  security.acme = {
    acceptTerms = true;
    defaults.email = "botahamec@outlook.com";
    certs."altahamec.dev" = {
      webroot = "/var/lib/acme/challenges-altahamec";
      email = "botahamec@outlook.com";
      group = "nginx";
      extraDomainNames = [ "www.altahamec.dev" ];
    };
    certs."botahamec.dev" = {
      webroot = "/var/lib/acme/challenges-botahamec";
      email = "botahamec@outlook.com";
      group = "nginx";
      extraDomainNames = [ "www.botahamec.dev" ];
    };
  };

  programs.mosh.enable = true;
  services.openssh = {
    enable = true;
    settings = {
      PermitRootLogin = "no";
      PasswordAuthentication = false;
      KbdInteractiveAuthentication = false;
    };
  };

  services.vaultwarden = {
    enable = true;
    backupDir = "/var/local/vaultwarden/backup";
    config = {
      DOMAIN = "https://www.altahamec.dev/vault";
      SIGNUPS_ALLOWED = false;

      ROCKET_ADDRESS = "127.0.0.1";
      ROCKET_PORT = 8222;
      ROCKET_LOG = "critical";
    };
  };

  services.copyparty = {
    enable = true;
    user = "syncthing";
    settings = {
      e2dsa = true;
      e2ts = true;
      shr = "/shares";
      rss = true;
      ftp = 3921;
      no-robots = true;
      rp-loc = "/copyparty";
    };
    accounts = {
      botahamec.passwordFile = config.sops.secrets."myPassword".path;
      guest.passwordFile = config.sops.secrets."guestPassword".path;
    };
    volumes."/" = {
      path = "/var/lib/syncthing";
      access.A = [ "botahamec" ];
      access.r = [ "guest" ];
    };
  };

  services.radicale = {
    enable = true;
    settings = {
      server.hosts = [ "0.0.0.0:5232" ];
      auth = {
        type = "htpasswd";
        htpasswd_filename = config.sops.secrets."radicaleAuth".path;
      };
    };
  };

  programs.git = {
    enable = true;
    config.init.defaultBranch = "main";
  };
  services.cgit."foo" = {
    enable = true;
    nginx.location = "/cgit/";
    nginx.virtualHost = "botahamec.dev";
    gitHttpBackend.enable = true;
    gitHttpBackend.checkExportOkFiles = false;
    scanPath = "/var/lib/git-server/";
    group = "git";
    settings = {
      enable-tree-linenumbers = false;
      enable-html-serving = true;
      enable-http-clone = true;
      clone-url = "https://botahamec.dev/cgit/$CGIT_REPO_URL";
      remove-suffix = true;
      css = "/cgit/cgit.css";
      logo = "/cgit/cgit.png";
      js = "/cgit/cgit.js";
      # readme = "main:README.md";
      # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh";
      # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py";
      # source-filter = "${pkgs.cgit-arborium}/bin/cgit-syntax-highlight";
    };
  };
  # services.cgit."bar" = {
  #   enable = true;
  #   nginx.location = "/cgit/";
  #   nginx.virtualHost = "altahamec.dev";
  #   gitHttpBackend.enable = true;
  #   gitHttpBackend.checkExportOkFiles = false;
  #   scanPath = "/var/lib/git-server/";
  #   group = "git";
  #   settings = {
  #     enable-tree-linenumbers = false;
  #     enable-html-serving = true;
  #     enable-http-clone = true;
  #     clone-url = "https://altahamec.dev/cgit/$CGIT_REPO_URL";
  #     remove-suffix = true;
  #     css = "/cgit/cgit.css";
  #     logo = "/cgit/cgit.png";
  #     js = "/cgit/cgit.js";
  #     # readme = "main:README.md";
  #     # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh";
  #     # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py";
  #   };
  # };
  
  services.syncthing = {
    enable = true;
    openDefaultPorts = true;
  };

  sops = {
    defaultSopsFile = ./secrets.yaml;
    defaultSopsFormat = "yaml";
    age.keyFile = "/home/botahamec/.config/sops/age/keys.txt";
    secrets = {
      "myPassword" = {
        owner = "syncthing";
        mode = "0640";
      };
      "guestPassword" = {
        owner = "syncthing";
        mode = "0640";
      };
      "radicaleAuth" = {
        owner = "radicale";
        mode = "0640";
      };
    };
  };

  users.users.nginx.extraGroups = [ "acme" "git" ];
  services.nginx = {
    enable = true;
    recommendedOptimisation = true;
    recommendedBrotliSettings = true;
    recommendedGzipSettings = true;
    recommendedProxySettings = true;
    recommendedTlsSettings = true;
    virtualHosts = let config = {useACMEHost, acmeRoot, serverAliases}: {
      addSSL = true;
      inherit useACMEHost;
      inherit serverAliases;
      inherit acmeRoot;
      locations."/vault/" = {
        proxyPass = "http://127.0.0.1:8222";
        recommendedProxySettings = true;
        proxyWebsockets = true;
      };
      locations."/syncthing/" = {
        proxyWebsockets = true;
        recommendedProxySettings = true;
        extraConfig = ''
            proxy_pass              http://127.0.0.1:8384/;

            proxy_read_timeout      600s;
            proxy_send_timeout      600s;
          '';
      };
      locations."/copyparty/" = {
        proxyPass = "http://127.0.0.1:3923";
        recommendedProxySettings = true;
        proxyWebsockets = true;
        extraConfig = ''
            # disable buffering
            proxy_buffering         off;
            proxy_request_buffering off;
            # improve download speed from 600 to 1500MiB/s;
            proxy_buffers           32 8k;
            proxy_buffer_size       16k;
            proxy_busy_buffers_size 24k;
          '';
      };
      locations."/dav/" = {
        proxyPass = "http://127.0.0.1:5232";
        extraConfig = ''
          proxy_set_header X-Script-Name /dav;
          proxy_pass_header Authorization;
        '';
      };
      # locations."/cgit\." = {
      #   root = "${pkgs.cgit}/cgit/";
      # };
      # locations."~ ^(/cgit/.*/(INFO/refs|HEAD|objects/info/.*|git-(upload|receive)-pack))$" = {
      #   extraConfig = ''
      #     include ${pkgs.nginx}/conf/fastcgi_params;
      #     fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend;
      #     fastcgi_param GIT_PROJECT_ROOT /srv/git;
      #     fastcgi_param GIT_HTTP_EXPORT_ALL "";
      #     fastcgi_pass unix:/run/fcgiwrap.sock;
      #   '';
      # };
      # locations."@cgit" = {
      #   extraConfig = ''
      #     include fastcgi_params;
      #     fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend;
      #     fastcgi_param PATH_INFO $uri;
      #     fastcgi_param QUERY_STRING $args;
      #     fastcgi_param HTTP_HOST $server_name;
      #     fastcgi_pass unix:/run/fcgiwrap.socket;
      #   '';
      # };
      locations."/" = {
        root = "/var/www/botahamec.dev";
        index = "index.html";
        tryFiles = "$uri /blog/$uri /blog/$uri.html $uri.html $uri/ =404";
      };
    }; in {
      "altahamec.dev" = config {
        useACMEHost = "altahamec.dev";
        serverAliases = ["www.altahamec.dev"];
        acmeRoot = "/var/lib/acme/challenges-altahamec";
      };
      "botahamec.dev" = config {
        useACMEHost = "botahamec.dev";
        serverAliases = ["www.botahamec.dev"];
        acmeRoot = "/var/lib/acme/challenges-botahamec";
      };
    };
  };

  # Workaround for https://github.com/NixOS/nix/issues/8502
  services.logrotate.checkConfig = false;

  networking.hostName = "botahamec-sh";
  networking.firewall.allowedTCPPorts = [ 22 80 443 3921 ];

  time.timeZone = "America/New_York";
  i18n.defaultLocale = "en_US.UTF-8";
  console.keyMap = "us";

  security.sudo.wheelNeedsPassword = false;
  users.groups.git = {};
  users.users = {
    root.hashedPassword = "!";
    botahamec = {
      isNormalUser = true;
      extraGroups = ["wheel"];
      openssh.authorizedKeys.keys = [
        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1"
      ];
    };
    git = {
      isSystemUser = true;
      group = "git";
      home = "/var/lib/git-server";
      homeMode = "755";
      createHome = true;
      shell = "${pkgs.bash}/bin/bash";
      openssh.authorizedKeys.keys = [
        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1"
        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINWcpi4SrCv2VKRAwBCa4CN7zaVOKfrhEZHf+blndGF8"
        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFWQ1MW4lfCShJ2C5f0WjKXbgsqAu5oxVexIymZSDJAz"
        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOdsY6akjlI9IL2nLw8A7s1IbDlz19eLMLU+HZguFPxx"
        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHBEYjq0+cbiTLbgS3v/LyISLL7CG82fj4yCyqdS2sW6"
        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKf97P0HlHHudrQuzO/yysIQxZZdEhhnvaclE8ABzNm0"
        "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICkVyhHW6Me4IAd8m37mPn6mjWOxjffrZWtP9Oq0peSj"
      ];
    };
    radicale = {
      extraGroups = [ "syncthing" ];
    };
  };

  boot.tmp.cleanOnBoot = true;
  zramSwap.enable = true;

  system.stateVersion = "26.05";
  system.autoUpgrade = {
    enable = true;
    dates = "daily";
    flake = "path:///etc/nixos";
  };
  systemd.services.nixos-upgrade = {
    after = [ "flake-update.service" ];
    requires = [ "flake-update.service" ];
  };
  systemd.services.flake-update = {
    description = "Update flake inputs";
    unitConfig = {
      StartLimitIntervalSec = 300;
      StartLimitBurst = 5;
    };
    serviceConfig = {
      ExecStartPre = "${pkgs.networkmanager}/bin/nm-online";
      ExecStart = "${pkgs.nix}/bin/nix flake update --flake /etc/nixos";
      Restart = "on-failure";
      RestartSec = "30";
      Type = "oneshot";
    };
    path = with pkgs; [ nix git host networkmanager ];
  };

  nix.package = pkgs.lixPackageSets.stable.lix;
  nix.gc.automatic = true;
  nix.gc.dates = "daily";
  nix.gc.options = "--delete-older-than 1d";
  nix.settings.auto-optimise-store = true;
  nix.settings.experimental-features = [ "nix-command" "flakes" ];
  nix.settings.trusted-users = [ "root" "botahamec" "@wheel" ];
}