blob: a4d316c1ea7949dc8ccf10c278d91c06f43a41e4 (
plain)
{ config, pkgs, ... }: {
imports = [
./hardware-configuration.nix
];
environment.sessionVariables = {
NH_FLAKE = "/etc/nixos";
EDITOR = "hx";
VISUAL = "hx";
};
environment.systemPackages = with pkgs; [
helix
nixd
btop
sops
age
dust
nh
];
services.fail2ban.enable = true;
security.acme = {
acceptTerms = true;
defaults.email = "botahamec@outlook.com";
certs."altahamec.dev" = {
webroot = "/var/lib/acme/challenges-altahamec";
email = "botahamec@outlook.com";
group = "nginx";
extraDomainNames = [ "www.altahamec.dev" ];
};
certs."botahamec.dev" = {
webroot = "/var/lib/acme/challenges-botahamec";
email = "botahamec@outlook.com";
group = "nginx";
extraDomainNames = [ "www.botahamec.dev" ];
};
};
programs.mosh.enable = true;
services.openssh = {
enable = true;
settings = {
PermitRootLogin = "no";
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
};
};
services.vaultwarden = {
enable = true;
backupDir = "/var/local/vaultwarden/backup";
config = {
DOMAIN = "https://www.altahamec.dev/vault";
SIGNUPS_ALLOWED = false;
ROCKET_ADDRESS = "127.0.0.1";
ROCKET_PORT = 8222;
ROCKET_LOG = "critical";
};
};
services.copyparty = {
enable = true;
user = "syncthing";
settings = {
e2dsa = true;
e2ts = true;
shr = "/shares";
rss = true;
ftp = 3921;
no-robots = true;
rp-loc = "/copyparty";
};
accounts = {
botahamec.passwordFile = config.sops.secrets."myPassword".path;
guest.passwordFile = config.sops.secrets."guestPassword".path;
};
volumes."/" = {
path = "/var/lib/syncthing";
access.A = [ "botahamec" ];
access.r = [ "guest" ];
};
};
services.radicale = {
enable = true;
settings = {
server.hosts = [ "0.0.0.0:5232" ];
auth = {
type = "htpasswd";
htpasswd_filename = config.sops.secrets."radicaleAuth".path;
};
};
};
programs.git = {
enable = true;
config.init.defaultBranch = "main";
};
services.cgit."foo" = {
enable = true;
nginx.location = "/cgit/";
nginx.virtualHost = "botahamec.dev";
gitHttpBackend.enable = true;
gitHttpBackend.checkExportOkFiles = false;
scanPath = "/var/lib/git-server/";
group = "git";
settings = {
enable-tree-linenumbers = false;
enable-html-serving = true;
enable-http-clone = true;
clone-url = "https://botahamec.dev/cgit/$CGIT_REPO_URL";
remove-suffix = true;
css = "/cgit/cgit.css";
logo = "/cgit/cgit.png";
js = "/cgit/cgit.js";
# readme = "main:README.md";
# about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh";
# source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py";
# source-filter = "${pkgs.cgit-arborium}/bin/cgit-syntax-highlight";
};
};
# services.cgit."bar" = {
# enable = true;
# nginx.location = "/cgit/";
# nginx.virtualHost = "altahamec.dev";
# gitHttpBackend.enable = true;
# gitHttpBackend.checkExportOkFiles = false;
# scanPath = "/var/lib/git-server/";
# group = "git";
# settings = {
# enable-tree-linenumbers = false;
# enable-html-serving = true;
# enable-http-clone = true;
# clone-url = "https://altahamec.dev/cgit/$CGIT_REPO_URL";
# remove-suffix = true;
# css = "/cgit/cgit.css";
# logo = "/cgit/cgit.png";
# js = "/cgit/cgit.js";
# # readme = "main:README.md";
# # about-filter = "${pkgs.cgit}/lib/cgit/filters/about-formatting.sh";
# # source-filter = "${pkgs.cgit}/lib/cgit/filters/syntax-highlighting.py";
# };
# };
services.syncthing = {
enable = true;
openDefaultPorts = true;
};
sops = {
defaultSopsFile = ./secrets.yaml;
defaultSopsFormat = "yaml";
age.keyFile = "/home/botahamec/.config/sops/age/keys.txt";
secrets = {
"myPassword" = {
owner = "syncthing";
mode = "0640";
};
"guestPassword" = {
owner = "syncthing";
mode = "0640";
};
"radicaleAuth" = {
owner = "radicale";
mode = "0640";
};
};
};
users.users.nginx.extraGroups = [ "acme" "git" ];
services.nginx = {
enable = true;
recommendedOptimisation = true;
recommendedBrotliSettings = true;
recommendedGzipSettings = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
virtualHosts = let config = {useACMEHost, acmeRoot, serverAliases}: {
addSSL = true;
inherit useACMEHost;
inherit serverAliases;
inherit acmeRoot;
locations."/vault/" = {
proxyPass = "http://127.0.0.1:8222";
recommendedProxySettings = true;
proxyWebsockets = true;
};
locations."/syncthing/" = {
proxyWebsockets = true;
recommendedProxySettings = true;
extraConfig = ''
proxy_pass http://127.0.0.1:8384/;
proxy_read_timeout 600s;
proxy_send_timeout 600s;
'';
};
locations."/copyparty/" = {
proxyPass = "http://127.0.0.1:3923";
recommendedProxySettings = true;
proxyWebsockets = true;
extraConfig = ''
# disable buffering
proxy_buffering off;
proxy_request_buffering off;
# improve download speed from 600 to 1500MiB/s;
proxy_buffers 32 8k;
proxy_buffer_size 16k;
proxy_busy_buffers_size 24k;
'';
};
locations."/dav/" = {
proxyPass = "http://127.0.0.1:5232";
extraConfig = ''
proxy_set_header X-Script-Name /dav;
proxy_pass_header Authorization;
'';
};
# locations."/cgit\." = {
# root = "${pkgs.cgit}/cgit/";
# };
# locations."~ ^(/cgit/.*/(INFO/refs|HEAD|objects/info/.*|git-(upload|receive)-pack))$" = {
# extraConfig = ''
# include ${pkgs.nginx}/conf/fastcgi_params;
# fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend;
# fastcgi_param GIT_PROJECT_ROOT /srv/git;
# fastcgi_param GIT_HTTP_EXPORT_ALL "";
# fastcgi_pass unix:/run/fcgiwrap.sock;
# '';
# };
# locations."@cgit" = {
# extraConfig = ''
# include fastcgi_params;
# fastcgi_param SCRIPT_FILENAME ${pkgs.git}/libexec/git-core/git-http-backend;
# fastcgi_param PATH_INFO $uri;
# fastcgi_param QUERY_STRING $args;
# fastcgi_param HTTP_HOST $server_name;
# fastcgi_pass unix:/run/fcgiwrap.socket;
# '';
# };
locations."/" = {
root = "/var/www/botahamec.dev";
index = "index.html";
tryFiles = "$uri /blog/$uri /blog/$uri.html $uri.html $uri/ =404";
};
}; in {
"altahamec.dev" = config {
useACMEHost = "altahamec.dev";
serverAliases = ["www.altahamec.dev"];
acmeRoot = "/var/lib/acme/challenges-altahamec";
};
"botahamec.dev" = config {
useACMEHost = "botahamec.dev";
serverAliases = ["www.botahamec.dev"];
acmeRoot = "/var/lib/acme/challenges-botahamec";
};
};
};
# Workaround for https://github.com/NixOS/nix/issues/8502
services.logrotate.checkConfig = false;
networking.hostName = "botahamec-sh";
networking.firewall.allowedTCPPorts = [ 22 80 443 3921 ];
time.timeZone = "America/New_York";
i18n.defaultLocale = "en_US.UTF-8";
console.keyMap = "us";
security.sudo.wheelNeedsPassword = false;
users.groups.git = {};
users.users = {
root.hashedPassword = "!";
botahamec = {
isNormalUser = true;
extraGroups = ["wheel"];
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1"
];
};
git = {
isSystemUser = true;
group = "git";
home = "/var/lib/git-server";
homeMode = "755";
createHome = true;
shell = "${pkgs.bash}/bin/bash";
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID6jrOMQYc96U7x3dV53g/OBjzOH5CPSX9YJ1EBUMMRM botahamec@Hydrogen3.1"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINWcpi4SrCv2VKRAwBCa4CN7zaVOKfrhEZHf+blndGF8"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFWQ1MW4lfCShJ2C5f0WjKXbgsqAu5oxVexIymZSDJAz"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOdsY6akjlI9IL2nLw8A7s1IbDlz19eLMLU+HZguFPxx"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHBEYjq0+cbiTLbgS3v/LyISLL7CG82fj4yCyqdS2sW6"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKf97P0HlHHudrQuzO/yysIQxZZdEhhnvaclE8ABzNm0"
];
};
radicale = {
extraGroups = [ "syncthing" ];
};
};
boot.tmp.cleanOnBoot = true;
zramSwap.enable = true;
system.stateVersion = "26.05";
system.autoUpgrade = {
enable = true;
dates = "daily";
flake = "path:///etc/nixos";
};
systemd.services.nixos-upgrade = {
after = [ "flake-update.service" ];
requires = [ "flake-update.service" ];
};
systemd.services.flake-update = {
description = "Update flake inputs";
unitConfig = {
StartLimitIntervalSec = 300;
StartLimitBurst = 5;
};
serviceConfig = {
ExecStartPre = "${pkgs.networkmanager}/bin/nm-online";
ExecStart = "${pkgs.nix}/bin/nix flake update --flake /etc/nixos";
Restart = "on-failure";
RestartSec = "30";
Type = "oneshot";
};
path = with pkgs; [ nix git host networkmanager ];
};
nix.package = pkgs.lixPackageSets.stable.lix;
nix.gc.automatic = true;
nix.gc.dates = "daily";
nix.gc.options = "--delete-older-than 1d";
nix.settings.auto-optimise-store = true;
nix.settings.experimental-features = [ "nix-command" "flakes" ];
nix.settings.trusted-users = [ "root" "botahamec" "@wheel" ];
}
|