diff --git a/flake.lock b/flake.lock index 48bde4f..27b21f4 100644 --- a/flake.lock +++ b/flake.lock @@ -166,11 +166,11 @@ "cachyos-kernel": { "flake": false, "locked": { - "lastModified": 1781767284, - "narHash": "sha256-cjIw6fLHT1shDREFkhsMeZeRAYO7z+cnauxmpUkSdp4=", + "lastModified": 1781883168, + "narHash": "sha256-raAojJGk0aWdscfFn/9ikZ6V5oUuAZcAz5kjAZ2QN3E=", "owner": "CachyOS", "repo": "linux-cachyos", - "rev": "d9b3cd77b1aa6fd4dc4baa3d876a598f884f5472", + "rev": "daed450e9b1a4fadfef68fb4fa5e2f3391fedb34", "type": "github" }, "original": { @@ -182,11 +182,11 @@ "cachyos-kernel-patches": { "flake": false, "locked": { - "lastModified": 1781605133, - "narHash": "sha256-lmxxhcZt3qSHPS3ETDeN2OIZqC4yIa3uVpMXuIR+8Rc=", + "lastModified": 1781953785, + "narHash": "sha256-YgEE1a5QdKd47AfRoU5G8nm0gGzeCuPN2emupNDMQcc=", "owner": "CachyOS", "repo": "kernel-patches", - "rev": "3d40b72fc3c40581269f9e7a12433950f2fd6d95", + "rev": "e8e9d325eea25f5664e045787c19baac661828de", "type": "github" }, "original": { @@ -213,11 +213,11 @@ }, "crane": { "locked": { - "lastModified": 1780532242, - "narHash": "sha256-D+BsdpxmtUwtqGoY0IXPhHgTlmqgcZKCEo1oMyn7ep0=", + "lastModified": 1781825982, + "narHash": "sha256-SlXKwIRIhrOSAcTjCB3ftPLzJWZStQIPS7J1FlZPnKk=", "owner": "ipetkov", "repo": "crane", - "rev": "59a82a1222dd3b2080b5cc52a1a2e8d5f1b77f37", + "rev": "469fd08d0bcf6926321fa973c6777fbc87785dd7", "type": "github" }, "original": { @@ -666,11 +666,11 @@ ] }, "locked": { - "lastModified": 1781906751, - "narHash": "sha256-6Ld1PqmptFtFKblE+SynhRgyBApUWcmrISetWqWHeeo=", + "lastModified": 1782103446, + "narHash": "sha256-+vMR3KPBVoY9nJrQI9qje5H1vmv51dJgMYkUuYimtJg=", "owner": "nix-community", "repo": "home-manager", - "rev": "37f21dfa5d27e71b75bacd9418b156f9265e312e", + "rev": "d8dac1f668fd861369571be3678ec75b1573e7e3", "type": "github" }, "original": { @@ -1087,15 +1087,16 @@ ] }, "locked": { - "lastModified": 1781649287, - "narHash": "sha256-ycG9a7svaV/zF9G03waY7BqUcNQn2HODMN/lXy3C7Zc=", + "lastModified": 1782141370, + "narHash": "sha256-hqijVSEETttmo8Okql9/LG0Ua34hdciKW1a5zzlj8mU=", "owner": "nix-community", "repo": "lanzaboote", - "rev": "001e560fffc8f0235e9db20ebeb4ccde0ade1caf", + "rev": "7c9a54a7f87b4539ddbd8bda09a8a5f5f9361aa9", "type": "github" }, "original": { "owner": "nix-community", + "ref": "v1.1.0", "repo": "lanzaboote", "type": "github" } @@ -1193,11 +1194,11 @@ "nixpkgs": "nixpkgs_5" }, "locked": { - "lastModified": 1781811723, - "narHash": "sha256-o0Y3TIykOACq7nwwoSzeQOhQhheI7P4x0PvHtUsoXPY=", + "lastModified": 1782068713, + "narHash": "sha256-Vujeg1QyOCnEMCNV1U7aFDllD0w2lEl8c0uJyKM+cOI=", "owner": "xddxdd", "repo": "nix-cachyos-kernel", - "rev": "26da04e24aef2993ea256917be42d18f83ce8e8b", + "rev": "756ed060ca6adcdf3e65371e3725b89c58a1354d", "type": "github" }, "original": { @@ -1251,11 +1252,11 @@ ] }, "locked": { - "lastModified": 1781422160, - "narHash": "sha256-W7S8O86bVrw2gaomEwkHStOzmPpnFIHQ6lS4Q2HffJ0=", + "lastModified": 1782030356, + "narHash": "sha256-h4WpMr455AfRub0FXBaon6Vcpe0waUyJ4GivIW6oyd4=", "owner": "nix-community", "repo": "nix-index-database", - "rev": "854d04e2368fb2e9c328a36b3c0a04cd713bfae1", + "rev": "3017088b49efd404f78e3b104f553b97e4af786b", "type": "github" }, "original": { @@ -1477,11 +1478,11 @@ }, "nixpkgs_5": { "locked": { - "lastModified": 1781793837, - "narHash": "sha256-T9/Q/A5B/Q1hC65fdwCz0aKVN7u1MDXGQXMKgoMQ1Hw=", + "lastModified": 1782014548, + "narHash": "sha256-zYKx9xcbPvk4zOzkny3w2/AkuKhJqGwRD+piA3urkx8=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "05eced6879632fc2f62fec56f2e33269157984ef", + "rev": "72349305fb839e27697873de7a4ce3a98c378f48", "type": "github" }, "original": { @@ -1553,11 +1554,11 @@ "treefmt-nix": "treefmt-nix" }, "locked": { - "lastModified": 1781404532, - "narHash": "sha256-ciNbueiFN7YcHct3k+n4dWbGkgzZVudMpfr4/5Nm96Q=", + "lastModified": 1782009525, + "narHash": "sha256-VKFj+Lt3jTg93ONWFLKieH/QQnXstsqs4hwpQj0nqZ0=", "owner": "noctalia-dev", "repo": "noctalia-qs", - "rev": "d52844d40a697e47fea7bc0f1ec68aae9108ddf2", + "rev": "fc1bdab9adccd3f67fad09e7f6094707eb8c2bfc", "type": "github" }, "original": { @@ -1576,11 +1577,11 @@ ] }, "locked": { - "lastModified": 1781930652, - "narHash": "sha256-7VPaBziWHi8dJeiG9lrwunOC6rkhmgTsbUQVHCab6+U=", + "lastModified": 1782133810, + "narHash": "sha256-037T8qwCrig4A5X8JaIa+9gxoifWA91TGhbwzmvpY1g=", "owner": "nix-community", "repo": "NUR", - "rev": "6b4d2c6477c8e23f7ac33040849a4c1c9ad633fc", + "rev": "797063acfe02907eff9e65da527cbc4ccf8703c8", "type": "github" }, "original": { @@ -1657,11 +1658,11 @@ ] }, "locked": { - "lastModified": 1778507602, - "narHash": "sha256-kTwur1wV+01SdqskVMSo6JMEpg71ps3HpbFY2GsflKs=", + "lastModified": 1781733627, + "narHash": "sha256-U3yTuGBnmXvXoQI3qkpfEDsn9RovQPAjN7ndRco+3u0=", "owner": "cachix", "repo": "pre-commit-hooks.nix", - "rev": "61ab0e80d9c7ab14c256b5b453d8b3fb0189ba0a", + "rev": "3bbec39bc90eadfa031e6f3b77272f3f60803e39", "type": "github" }, "original": { @@ -1805,11 +1806,11 @@ ] }, "locked": { - "lastModified": 1780547341, - "narHash": "sha256-Gq8KNx5A7hBB3uGJaj6eQfLDIz5YdLu92gqBcvHvoUo=", + "lastModified": 1781943681, + "narHash": "sha256-NFHmA7H47adqiyp+0iEOyZOQhmigDqA/NBAlf4imB6U=", "owner": "Mic92", "repo": "sops-nix", - "rev": "9ed65852b6257fbeae4355bc24ecfea307ca759a", + "rev": "420f8d2e9882911f65cfac15cc706f639ba96cca", "type": "github" }, "original": { @@ -1826,11 +1827,11 @@ "systems": "systems_8" }, "locked": { - "lastModified": 1781425310, - "narHash": "sha256-GTBka4Df/ZOacmisI/DI2LICyNChEqn/giah83LucdM=", + "lastModified": 1782031037, + "narHash": "sha256-a7oWSyS7SN81UOqVt481yIEMDsMpaJ7GNdV6Eaz5Yqg=", "owner": "Gerg-L", "repo": "spicetify-nix", - "rev": "aeaf7c81a45d3761da61cb05bfc370ac6d1b0441", + "rev": "9cb27462cfd20edac174353f1e95bc03aa888863", "type": "github" }, "original": { @@ -1863,11 +1864,11 @@ "tinted-zed": "tinted-zed" }, "locked": { - "lastModified": 1781018772, - "narHash": "sha256-C+cGIUaC6dqfwTbI+BwCd572PbESGA3WYxR1sLTqxkY=", + "lastModified": 1781997134, + "narHash": "sha256-muBZG4O/agq/ljgHr6c3AsobIWgODAS6vf50xIS7o+Q=", "owner": "danth", "repo": "stylix", - "rev": "a378e4c09031fb15a4d65da88aa628f71fc52f6b", + "rev": "a6a493119e492e15874caf6f7f8c7e572e64c655", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index 6c82749..1b8f4c3 100644 --- a/flake.nix +++ b/flake.nix @@ -38,7 +38,7 @@ }; import-tree.url = "github:vic/import-tree"; lanzaboote = { - url = "github:nix-community/lanzaboote"; + url = "github:nix-community/lanzaboote?ref=v1.1.0"; inputs = { nixpkgs.follows = "nixpkgs"; rust-overlay.follows = "tuigreet/rust-overlay"; diff --git a/modules/hosts/euclid/default.nix b/modules/hosts/euclid/default.nix index e687c38..7692c78 100644 --- a/modules/hosts/euclid/default.nix +++ b/modules/hosts/euclid/default.nix @@ -1,7 +1,9 @@ {self, ...}: { flake.modules.nixos.euclid = { + # keep-sorted start config, pkgs, + # keep-sorted end ... }: { imports = with self.modules.nixos; [ @@ -10,6 +12,7 @@ # Services # keep-sorted start + apprise authentik cloudbeaver crowdsec-server @@ -76,13 +79,6 @@ networking.hosts = { "10.100.0.1" = ["euclid.wg"]; }; - networking.firewall.interfaces.wg0.allowedTCPPorts = [ - # keep-sorted start numeric=yes - 3000 - 3306 - 5432 - # keep-sorted end - ]; users.users.${config.services.crowdsec.user}.extraGroups = ["podman"]; diff --git a/modules/hosts/laptop/default.nix b/modules/hosts/laptop/default.nix index 3912b5d..e135f97 100644 --- a/modules/hosts/laptop/default.nix +++ b/modules/hosts/laptop/default.nix @@ -16,7 +16,7 @@ # Services # keep-sorted start - scx + scx-loader tlp wifi # keep-sorted end diff --git a/modules/nix/lanzaboote.nix b/modules/nix/lanzaboote.nix index f179710..5fca80a 100644 --- a/modules/nix/lanzaboote.nix +++ b/modules/nix/lanzaboote.nix @@ -1,6 +1,6 @@ { flake-file.inputs.lanzaboote = { - url = "github:nix-community/lanzaboote"; + url = "github:nix-community/lanzaboote?ref=v1.1.0"; inputs = { nixpkgs.follows = "nixpkgs"; rust-overlay.follows = "tuigreet/rust-overlay"; diff --git a/modules/programs/gui/zen/preferences.nix b/modules/programs/gui/zen/preferences.nix index 7cc426d..b783daa 100644 --- a/modules/programs/gui/zen/preferences.nix +++ b/modules/programs/gui/zen/preferences.nix @@ -17,7 +17,13 @@ types # keep-sorted end ; - inherit (vars) countryCode; + inherit + (vars) + # keep-sorted start + countryCode + groundDomain + # keep-sorted end + ; in { options.programs.zen-browser.profiles = mkOption { type = types.attrsOf (types.submodule { @@ -329,6 +335,8 @@ # keep-sorted end }; + identity.sync.tokenserver.uri = "https://firefox-sync.${groundDomain}/1.0/sync/1.5"; + image = { # keep-sorted start block=yes newline_separated=yes cache.size = 10485760; diff --git a/modules/services/apprise.nix b/modules/services/apprise.nix new file mode 100644 index 0000000..abaf2cd --- /dev/null +++ b/modules/services/apprise.nix @@ -0,0 +1,50 @@ +{ + flake.modules.nixos.apprise = { + virtualisation.oci-containers.containers.apprise = { + hostname = "apprise"; + image = "caronc/apprise:latest"; + + environment = { + APPRISE_ADMIN = "y"; + APPRISE_STATEFUL_MODE = "simple"; + APPRISE_WORKER_COUNT = "1"; + APPRISE_WORKER_MAX_REQUESTS = "200"; + }; + + extraOptions = [ + "--network=host" + "--tmpfs=/tmp" + "--user=1000:1000" + + # Health check. + "--health-cmd=curl -fsSo /dev/null http://127.0.0.1:8000/ || exit 1" + "--health-interval=60s" + "--health-retries=5" + "--health-start-period=30s" + "--health-timeout=5s" + ]; + + volumes = [ + # keep-sorted start + "/var/lib/apprise/attach:/attach" + "/var/lib/apprise/config:/config" + "/var/lib/apprise/plugin:/plugin" + # keep-sorted end + ]; + }; + + networking.firewall.extraInputRules = '' + # Allow containers to reach host Apprise API. + iifname "podman*" tcp dport 8000 accept + ''; + + systemd.tmpfiles.rules = [ + # keep-sorted start + "d /var/lib/apprise 0750 1000 1000 -" + "d /var/lib/apprise/attach 0750 1000 1000 -" + "d /var/lib/apprise/config 0750 1000 1000 -" + "d /var/lib/apprise/plugin 0750 1000 1000 -" + # keep-sorted end + ]; + }; +} diff --git a/modules/services/dockhand.nix b/modules/services/dockhand.nix index 14af4fd..4f6ecfa 100644 --- a/modules/services/dockhand.nix +++ b/modules/services/dockhand.nix @@ -39,6 +39,8 @@ volumes = ["/var/lib/dockhand:/app/data"]; }; + networking.firewall.interfaces.wg0.allowedTCPPorts = [3000]; + systemd = { tmpfiles.rules = ["d /var/lib/dockhand 0750 1001 1001 -"]; diff --git a/modules/services/gotify.nix b/modules/services/gotify.nix index 2163f7d..83c9fb2 100644 --- a/modules/services/gotify.nix +++ b/modules/services/gotify.nix @@ -43,6 +43,7 @@ GOTIFY_OIDC_ENABLED = "true"; GOTIFY_OIDC_ISSUER = "https://authentik.${groundDomain}/application/o/gotify/"; + GOTIFY_OIDC_LINK_BY_USERNAME = "true"; GOTIFY_OIDC_REDIRECTURL = "https://gotify.${groundDomain}/auth/oidc/callback"; GOTIFY_DATABASE_DIALECT = "postgres"; @@ -61,6 +62,11 @@ }; }; + networking.firewall.extraInputRules = '' + # Allow containers to reach host Gotify. + iifname "podman*" tcp dport 44407 accept + ''; + systemd.services.gotify-server = { after = [ # keep-sorted start diff --git a/modules/services/hawser.nix b/modules/services/hawser.nix index 96e7fe6..9babc04 100644 --- a/modules/services/hawser.nix +++ b/modules/services/hawser.nix @@ -36,7 +36,9 @@ image = "ghcr.io/finsys/hawser:latest"; extraOptions = [ + "--cgroupns=host" "--network=host" + "--pid=host" # Health check. "--health-cmd=wget -q --spider http://[::1]:2376/_hawser/health || exit 1" diff --git a/modules/services/mysql.nix b/modules/services/mysql.nix index 48fd185..fa4a2d1 100644 --- a/modules/services/mysql.nix +++ b/modules/services/mysql.nix @@ -37,6 +37,15 @@ compressionLevel = 3; }; + networking.firewall = { + interfaces.wg0.allowedTCPPorts = [3306]; + + extraInputRules = '' + # Allow containers to reach host MariaDB. + iifname "podman*" tcp dport 3306 accept + ''; + }; + systemd.services.mysql-admin = { # keep-sorted start block=yes newline_separated=yes after = [ diff --git a/modules/services/podman.nix b/modules/services/podman.nix index 6904b37..30f8b4f 100644 --- a/modules/services/podman.nix +++ b/modules/services/podman.nix @@ -50,16 +50,13 @@ }; }; + environment.systemPackages = [pkgs.podman-compose]; + networking.firewall.extraInputRules = '' iifname "podman*" udp dport 53 accept iifname "podman*" tcp dport 53 accept - - # Allow containers to reach host Gotify. - iifname "podman*" tcp dport 44407 accept ''; - environment.systemPackages = [pkgs.podman-compose]; - users.users.${username}.extraGroups = ["podman"]; }; } diff --git a/modules/services/postgres.nix b/modules/services/postgres.nix index 8e94b07..a218705 100644 --- a/modules/services/postgres.nix +++ b/modules/services/postgres.nix @@ -85,6 +85,8 @@ compressionLevel = 3; }; + networking.firewall.interfaces.wg0.allowedTCPPorts = [5432]; + systemd.services.postgres-admin = { # keep-sorted start block=yes newline_separated=yes after = [ diff --git a/modules/services/scx-loader.nix b/modules/services/scx-loader.nix new file mode 100644 index 0000000..50f41c1 --- /dev/null +++ b/modules/services/scx-loader.nix @@ -0,0 +1,15 @@ +{ + flake.modules.nixos.scx = {pkgs, ...}: { + services.scx-loader = { + enable = true; + schedsPackages = pkgs.scx.rustscheds; + + config = { + default_sched = "scx_lavd"; + default_mode = "Auto"; + + scheds.scx_lavd.auto_mode = ["--autopower"]; + }; + }; + }; +} diff --git a/modules/services/scx.nix b/modules/services/scx.nix deleted file mode 100644 index 109075a..0000000 --- a/modules/services/scx.nix +++ /dev/null @@ -1,12 +0,0 @@ -{ - flake.modules.nixos.scx = {pkgs, ...}: { - services.scx = { - enable = true; - - # Use the rust scheds package with lavd and autopower tuning. - package = pkgs.scx.rustscheds; - scheduler = "scx_lavd"; - extraArgs = ["--autopower"]; - }; - }; -} diff --git a/modules/services/traefik.nix b/modules/services/traefik.nix index c18840d..d483a84 100644 --- a/modules/services/traefik.nix +++ b/modules/services/traefik.nix @@ -151,6 +151,13 @@ routers = { # keep-sorted start block=yes newline_separated=yes + apprise = { + entryPoints = ["websecure"]; + middlewares = ["authentik@file"]; + rule = "Host(`apprise.${groundDomain}`)"; + service = "apprise"; + }; + authentik = { entryPoints = ["websecure"]; rule = "Host(`authentik.${groundDomain}`)"; @@ -194,6 +201,10 @@ services = { # keep-sorted start block=yes newline_separated=yes + apprise.loadBalancer.servers = [ + {url = "http://127.0.0.1:8000";} + ]; + authentik-outpost.loadBalancer.servers = [ {url = "http://[::1]:9005/outpost.goauthentik.io";} ];