diff --git a/hosts/vulpes/core/secrets.nix b/hosts/vulpes/core/secrets.nix index 1ff8c86..bfdbb5c 100644 --- a/hosts/vulpes/core/secrets.nix +++ b/hosts/vulpes/core/secrets.nix @@ -59,15 +59,15 @@ in # Garage # garage_rpc_secret = { - group = "sand-garage"; + group = "vulpes-garage"; mode = "0440"; }; garage_admin_token = { - group = "sand-garage"; + group = "vulpes-garage"; mode = "0440"; }; garage_metrics_token = { - group = "sand-garage"; + group = "vulpes-garage"; mode = "0440"; }; # @@ -139,6 +139,20 @@ in # Acme # acme_environment_file = { }; + # + # niks3 + niks3_signing_key = { + owner = "niks3"; + }; + niks3_api_token = { + owner = "niks3"; + }; + niks3_access_key = { + owner = "niks3"; + }; + niks3_secret_access_key = { + owner = "niks3"; + }; }; }; } diff --git a/hosts/vulpes/infra/binary_cache.nix b/hosts/vulpes/infra/binary_cache.nix new file mode 100644 index 0000000..7d997c8 --- /dev/null +++ b/hosts/vulpes/infra/binary_cache.nix @@ -0,0 +1,30 @@ +{ args, config, ... }: { + imports = [ + args.pins.niks3.nixosModules.default + ]; + + services.niks3 = { + enable = true; + httpAddr = "127.0.0.1:5751"; + readProxy.enable = true; + + database = { + createLocally = false; + connectionString = "postgres:///niks3?user=niks3"; + }; + + s3 = { + endpoint = "s3.awoo.ren"; + bucket = "niks3"; + region = "vulpes"; + useSSL = true; + accessKeyFile = config.sops.secrets.niks3_access_key.path; + secretKeyFile = config.sops.secrets.niks3_secret_access_key.path; + }; + + apiTokenFile = config.sops.secrets.niks3_api_token.path; + signKeyFiles = [ config.sops.secrets.niks3_signing_key.path ]; + + cacheUrl = "https://nar.awoo.ren"; + }; +} diff --git a/hosts/vulpes/infra/db.nix b/hosts/vulpes/infra/db.nix index 6ffae52..7b94bab 100644 --- a/hosts/vulpes/infra/db.nix +++ b/hosts/vulpes/infra/db.nix @@ -96,6 +96,10 @@ in login = true; }; } + { + name = "niks3"; + ensureDBOwnership = true; + } ]; ensureDatabases = [ "roufpup" @@ -109,6 +113,7 @@ in "vaultwarden" "netbird" "grafana" + "niks3" ]; settings = { listen_addresses = "*"; @@ -132,6 +137,7 @@ in host netbird netbird 127.0.0.1/8 scram-sha-256 host netbird_events netbird 127.0.0.1/8 scram-sha-256 host grafana grafana 127.0.0.1/8 scram-sha-256 + local niks3 niks3 peer map=niks3 ''; }; diff --git a/hosts/vulpes/infra/dns.nix b/hosts/vulpes/infra/dns.nix index 2f70ed6..bdfbe4c 100644 --- a/hosts/vulpes/infra/dns.nix +++ b/hosts/vulpes/infra/dns.nix @@ -130,7 +130,7 @@ let webhook IN AAAA ${pm.net.ipv6.sand-archives.addr} ''; - fennie-eu_zonefile = pkgs.writeText "zone_fennie.eu" '' + fennie-eu_zonefile = pkgs.writeText "zone_fennie.eu" '' $ORIGIN fennie.eu. $TTL 5m @ IN SOA ns1.fennie.eu. pup.fennie.eu. ( @@ -151,6 +151,17 @@ let @ IN A ${pm.net.ipv4.sand-archives.addr} @ IN AAAA ${pm.net.ipv6.sand-archives.addr} + + ; Tuta + @ IN MX 10 mail.tutanota.de. + @ IN TXT "t-verify=97e66f193bf443f8573c288a2fd2de16" + @ IN TXT "v=spf1 include:spf.tutanota.de -all" + _dmarc IN TXT "v=DMARC1; p=quarantine; adkim=s" + s1._domainkey IN CNAME s1.domainkey.tutanota.de. + s2._domainkey IN CNAME s2.domainkey.tutanota.de. + _mta-sts IN CNAME mta-sts.tutanota.de. + mta-sts IN CNAME mta-sts.tutanota.de. + ''; in { diff --git a/hosts/vulpes/infra/ente.nix b/hosts/vulpes/infra/ente.nix index c0d5135..54ef087 100644 --- a/hosts/vulpes/infra/ente.nix +++ b/hosts/vulpes/infra/ente.nix @@ -49,7 +49,7 @@ let key._secret = secrets.ente_garage_key.path; secret._secret = secrets.ente_garage_secret.path; endpoint._secret = secrets.ente_garage_endpoint.path; - region = "sand-archives"; + region = "vulpes"; bucket = "ente"; }; }; diff --git a/hosts/vulpes/infra/proxy.nix b/hosts/vulpes/infra/proxy.nix index 79779e0..9d1886d 100644 --- a/hosts/vulpes/infra/proxy.nix +++ b/hosts/vulpes/infra/proxy.nix @@ -289,7 +289,7 @@ in }; "nar.awoo.ren" = { extraConfig = '' - reverse_proxy http://127.0.0.1:1090 + reverse_proxy http://127.0.0.1:5751 ''; }; "stream.awoo.ren" = { diff --git a/hosts/vulpes/infra/s3.nix b/hosts/vulpes/infra/s3.nix index 7811ba4..c031bd3 100644 --- a/hosts/vulpes/infra/s3.nix +++ b/hosts/vulpes/infra/s3.nix @@ -1,8 +1,8 @@ { pkgs, config, ... }: { - users.groups.sand-garage = { + users.groups.vulpes-garage = { gid = 400; - name = "sand-garage"; + name = "vulpes-garage"; }; services.garage = { @@ -14,7 +14,7 @@ allow_world_readable_secrets = true; s3_api = { - s3_region = "sand-archives"; + s3_region = "vulpes"; api_bind_addr = "[::]:3900"; }; @@ -25,7 +25,7 @@ s3_web = { bind_addr = "[::]:3902"; index = "index.html"; - root_domain = ".garage.killuaa.dev"; + root_domain = ".s3.awoo.ren"; }; admin = { api_bind_addr = "[::]:3903"; @@ -41,16 +41,10 @@ systemd.services = { garage = { serviceConfig = { - BindPaths = [ - "/mnt/hd1/garage:/var/lib/garage/data" - ]; SupplementaryGroups = [ - "sand-garage" + "vulpes-garage" ]; }; - unitConfig = { - RequiresMountsFor = "/mnt/hd1/garage"; - }; }; }; } diff --git a/hosts/work/default.nix b/hosts/work/default.nix index e94f3a4..4dd61e4 100644 --- a/hosts/work/default.nix +++ b/hosts/work/default.nix @@ -7,7 +7,7 @@ { imports = [ args.pins.nix-index.nixosModules.nix-index - # /home/roufpup/repos/fluxer/nix/module + /home/roufpup/repos/fluxer/nix/module ] ++ (args.pup_lib.module_imports ./core) ++ (args.pup_lib.module_imports ./users); @@ -15,7 +15,6 @@ time.timeZone = "Europe/Amsterdam"; i18n.defaultLocale = "en_US.UTF-8"; - # services.fluxer.settings.domain = "chat.awoo.ren"; environment = { enableAllTerminfo = true; @@ -74,10 +73,12 @@ ]; substituters = [ "https://nix-community.cachix.org" + "https://nar.awoo.ren" ]; trusted-public-keys = [ "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" + "niks3_signing_key:kdstBMlSYlFP9moCkee/hyZagOijEWfhkX+ghmW85R4=" ]; }; gc = { diff --git a/hosts/work/users/roufpup/default.nix b/hosts/work/users/roufpup/default.nix index 83fe8cb..40e9a4e 100644 --- a/hosts/work/users/roufpup/default.nix +++ b/hosts/work/users/roufpup/default.nix @@ -133,6 +133,7 @@ in umu-launcher erdtree openssl + awscli2 ] ++ [ #gui diff --git a/modules/priv b/modules/priv index ef46c60..f73809a 160000 --- a/modules/priv +++ b/modules/priv @@ -1 +1 @@ -Subproject commit ef46c60519e8cfb50a7e15ae938ee48378ec0526 +Subproject commit f73809ae36e743c9091112c1f1694217922cc3b4 diff --git a/npins/sources.json b/npins/sources.json index e2297cc..ebf023d 100644 --- a/npins/sources.json +++ b/npins/sources.json @@ -143,6 +143,19 @@ "url": "https://github.com/nix-community/lanzaboote/archive/0403b4b7e8b2612657f0053a4c315e6c43eee9e6.tar.gz", "hash": "sha256-4JLkQvN7/f77TyxXXtoEuUfovMqMLOgWpBaLMNX1dns=" }, + "niks3": { + "type": "Git", + "repository": { + "type": "GitHub", + "owner": "Mic92", + "repo": "niks3" + }, + "branch": "main", + "submodules": false, + "revision": "5869a1f0c05f518ee36e6648b6cf1c398060a046", + "url": "https://github.com/Mic92/niks3/archive/5869a1f0c05f518ee36e6648b6cf1c398060a046.tar.gz", + "hash": "sha256-RnFf7ntLWIjDjgeq+etV3ITEarY5B/fNKa8LPBFHJVs=" + }, "nix-index": { "type": "Git", "repository": {