diff --git a/flake.lock b/flake.lock index 54c2fc1..262d1a8 100644 --- a/flake.lock +++ b/flake.lock @@ -213,11 +213,11 @@ ] }, "locked": { - "lastModified": 1778954430, - "narHash": "sha256-oaNyOr05lblaQdtbkbN1wO0b2KLIL2O1LkmwDgdQp4I=", + "lastModified": 1779027260, + "narHash": "sha256-ZbgWWFQmSyM3HQ31nAZk2hJ7OSeNr9uRFHL8jCifY9M=", "owner": "nix-community", "repo": "home-manager", - "rev": "26aaab785b0bab4af60a2c42b22760fa906ef22a", + "rev": "bcb774cfc3268120cd61808629f9aa7dad3750a2", "type": "github" }, "original": { @@ -476,11 +476,11 @@ "systems": "systems" }, "locked": { - "lastModified": 1778906310, - "narHash": "sha256-LqASEJRtLuKRBJd9051T1KMAEaYvsVrc6m64jhD6xbw=", + "lastModified": 1779023681, + "narHash": "sha256-K7RLGyiK3J6wHr/JDxXdlGF0+0DEsdBf1w9mXjSyL8I=", "owner": "nix-community", "repo": "nixvim", - "rev": "06cace835d7ee727852ac789e3dcd42fc2fd360e", + "rev": "0d05726bfb060f6559f6d64c1d427f3663dba178", "type": "github" }, "original": { diff --git a/modules/core/nix.nix b/modules/core/nix.nix index 7156471..2defcc6 100644 --- a/modules/core/nix.nix +++ b/modules/core/nix.nix @@ -1,6 +1,7 @@ -{ ... }: +{ pkgs, ... }: { nix = { + package = pkgs.lixPackageSets.stable.lix; gc = { automatic = true; dates = "daily"; diff --git a/modules/core/packages.nix b/modules/core/packages.nix index 5db9f3c..1f4322d 100644 --- a/modules/core/packages.nix +++ b/modules/core/packages.nix @@ -3,6 +3,12 @@ nixpkgs.overlays = [ inputs.niri.overlays.niri (final: prev: { + inherit (prev.lixPackageSets.stable) + nixpkgs-review + nix-eval-jobs + nix-fast-build + colmena + ; electron = final.electron-bin; libime-jyutping = final.callPackage ../../pkgs/libime-jyutping { }; musescore = prev.musescore.overrideAttrs (oldAttrs: { diff --git a/modules/server/piped.nix b/modules/server/piped.nix index 1ef5873..04e9cc9 100644 --- a/modules/server/piped.nix +++ b/modules/server/piped.nix @@ -21,102 +21,104 @@ let localAddress = "192.168.30.2"; in { - /*containers.piped = { - inherit localAddress; - autoStart = true; - privateNetwork = true; - hostAddress = "192.168.30.1"; - config = - { ... }: - { - imports = [ - inputs.piped.nixosModules.default - ]; + /* + containers.piped = { + inherit localAddress; + autoStart = true; + privateNetwork = true; + hostAddress = "192.168.30.1"; + config = + { ... }: + { + imports = [ + inputs.piped.nixosModules.default + ]; - networking = { - useHostResolvConf = false; - firewall = { - checkReversePath = "loose"; - enable = true; - allowedTCPPorts = [ - proxy.port - frontend.port - api.port - ]; + networking = { + useHostResolvConf = false; + firewall = { + checkReversePath = "loose"; + enable = true; + allowedTCPPorts = [ + proxy.port + frontend.port + api.port + ]; + }; + nameservers = config.networking.nameservers; }; - nameservers = config.networking.nameservers; - }; - services = { - resolved = { - enable = true; - settings.Resolve = { - DNSSEC = "true"; - DNSOverTLS = "true"; - Domains = [ "~." ]; - FallbackDns = [ ]; + services = { + resolved = { + enable = true; + settings.Resolve = { + DNSSEC = "true"; + DNSOverTLS = "true"; + Domains = [ "~." ]; + FallbackDns = [ ]; + }; }; - }; - postgresql = { - package = pkgs.postgresql_17; - authentication = pkgs.lib.mkOverride 10 '' - local all all trust - host all all 127.0.0.1/32 trust - ''; - }; + postgresql = { + package = pkgs.postgresql_17; + authentication = pkgs.lib.mkOverride 10 '' + local all all trust + host all all 127.0.0.1/32 trust + ''; + }; - piped-proxy = { - enable = true; - listenAddress = "${localAddress}:${toString proxy.port}"; - }; - piped-backend = { - enable = true; - settings = { - COMPROMISED_PASSWORD_CHECK = "true"; - HOST = localAddress; - PORT = api.port; - API_URL = "https://${api.fqdn}"; - FRONTEND_URL = "https://${frontend.fqdn}"; - PROXY_PART = "https://${proxy.fqdn}"; + piped-proxy = { + enable = true; + listenAddress = "${localAddress}:${toString proxy.port}"; + }; + piped-backend = { + enable = true; + settings = { + COMPROMISED_PASSWORD_CHECK = "true"; + HOST = localAddress; + PORT = api.port; + API_URL = "https://${api.fqdn}"; + FRONTEND_URL = "https://${frontend.fqdn}"; + PROXY_PART = "https://${proxy.fqdn}"; + }; + }; + piped-frontend = { + enable = true; + listenHost = localAddress; + listenPort = frontend.port; + publicFrontendUrl = "https://${frontend.fqdn}"; + publicBackendUrl = "https://${api.fqdn}"; }; }; - piped-frontend = { - enable = true; - listenHost = localAddress; - listenPort = frontend.port; - publicFrontendUrl = "https://${frontend.fqdn}"; - publicBackendUrl = "https://${api.fqdn}"; - }; - }; - system.stateVersion = "26.05"; - }; - }; + system.stateVersion = "26.05"; + }; + }; - forest.nginxHosts = [ - (lib.mkIf config.containers.piped.autoStart { - "${proxy.fqdn}" = { - onlySSL = true; - http2 = true; - sslCertificate = config.sops.secrets."ssl/cert".path; - sslCertificateKey = config.sops.secrets."ssl/key".path; - locations."/".proxyPass = "http://${localAddress}:${toString proxy.port}"; - }; - "${frontend.fqdn}" = { - onlySSL = true; - http2 = true; - sslCertificate = config.sops.secrets."ssl/cert".path; - sslCertificateKey = config.sops.secrets."ssl/key".path; - locations."/".proxyPass = "http://${localAddress}:${toString frontend.port}"; - }; - "${api.fqdn}" = { - onlySSL = true; - http2 = true; - sslCertificate = config.sops.secrets."ssl/cert".path; - sslCertificateKey = config.sops.secrets."ssl/key".path; - locations."/".proxyPass = "http://${localAddress}:${toString api.port}"; - }; - }) - ];*/ + forest.nginxHosts = [ + (lib.mkIf config.containers.piped.autoStart { + "${proxy.fqdn}" = { + onlySSL = true; + http2 = true; + sslCertificate = config.sops.secrets."ssl/cert".path; + sslCertificateKey = config.sops.secrets."ssl/key".path; + locations."/".proxyPass = "http://${localAddress}:${toString proxy.port}"; + }; + "${frontend.fqdn}" = { + onlySSL = true; + http2 = true; + sslCertificate = config.sops.secrets."ssl/cert".path; + sslCertificateKey = config.sops.secrets."ssl/key".path; + locations."/".proxyPass = "http://${localAddress}:${toString frontend.port}"; + }; + "${api.fqdn}" = { + onlySSL = true; + http2 = true; + sslCertificate = config.sops.secrets."ssl/cert".path; + sslCertificateKey = config.sops.secrets."ssl/key".path; + locations."/".proxyPass = "http://${localAddress}:${toString api.port}"; + }; + }) + ]; + */ }