diff --git a/infra/domains.tf b/infra/domains.tf index f4873fa..102e778 100644 --- a/infra/domains.tf +++ b/infra/domains.tf @@ -10,8 +10,8 @@ resource "ovh_domain_zone_record" "rss" { zone = "srebrna.space" subdomain = "rss" fieldtype = "CNAME" - target = "heimdall.hauleth.dev." - ttl = 3600 + target = "mimir.hauleth.dev." + ttl = 300 } resource "ovh_domain_zone_record" "heimdall_a" { @@ -32,12 +32,30 @@ resource "ovh_domain_zone_record" "heimdall_aaaa" { ttl = 3600 } +resource "ovh_domain_zone_record" "mimir_a" { + for_each = toset(local.mimir.ipv4) + zone = "hauleth.dev" + subdomain = "mimir" + fieldtype = "A" + target = each.value + ttl = 3600 +} + +resource "ovh_domain_zone_record" "mimir_aaaa" { + for_each = toset(local.mimir.ipv6) + zone = "hauleth.dev" + subdomain = "mimir" + fieldtype = "AAAA" + target = each.value + ttl = 3600 +} + resource "ovh_domain_zone_record" "irc" { zone = "hauleth.dev" subdomain = "irc" fieldtype = "CNAME" - target = "heimdall.hauleth.dev." - ttl = 3600 + target = "mimir.hauleth.dev." + ttl = 300 } resource "ovh_domain_zone_record" "atproto" { @@ -60,16 +78,16 @@ resource "ovh_domain_zone_record" "git" { zone = "hauleth.dev" subdomain = "git" fieldtype = "CNAME" - target = "heimdall.hauleth.dev." - ttl = 3600 + target = "mimir.hauleth.dev." + ttl = 300 } resource "ovh_domain_zone_record" "tangled_knot" { zone = "hauleth.dev" subdomain = "knot" fieldtype = "CNAME" - target = "heimdall.hauleth.dev." - ttl = 3600 + target = "mimir.hauleth.dev." + ttl = 300 } module "blog" { @@ -83,7 +101,7 @@ module "hauleth_mail" { source = "./modules/email" zone = "hauleth.dev" - ipv4 = local.heimdall.ipv4 - ipv6 = local.heimdall.ipv6 + ipv4 = local.mimir.ipv4 + ipv6 = local.mimir.ipv6 dkim = "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwL3BpNVzsqrplHL7/cooPhEwExaNPMtDZ+pz7U1gehTnsMp+mVdBYQwmm/Nm/5KgvBOdhc4YFvNGeVLIV7JwegxrSPeYtic9G/Nd8niH5L/iF1NALzH6udlKedtRxAFweQooYhn14SbNEt4cUCyNScE5W8CS28759xOnqFwSxFoAppCyAXP74+jwg0dtpxFf+wgvAUtEYrHhX2mxthXe87F/m26eA8ktjLyL9mqhcAW5uXZ02kaVA4lyKwvdTambe/HfSKrHe54WZ7VWZwNwt+BLGlLTmaIl/ghpyX2kLmqbfJgX7xecMOxYovxs97j93eQFwlfPTWYFefU5tBBrqQIDAQAB" } diff --git a/infra/modules/email/zones.tf b/infra/modules/email/zones.tf index edcb437..9919e14 100644 --- a/infra/modules/email/zones.tf +++ b/infra/modules/email/zones.tf @@ -4,7 +4,7 @@ resource "ovh_domain_zone_record" "a" { subdomain = var.subdomain fieldtype = "A" target = each.value - ttl = 3600 + ttl = 300 } resource "ovh_domain_zone_record" "aaaa" { @@ -13,7 +13,7 @@ resource "ovh_domain_zone_record" "aaaa" { subdomain = var.subdomain fieldtype = "AAAA" target = each.value - ttl = 3600 + ttl = 300 } resource "ovh_domain_zone_record" "dkim" { @@ -21,7 +21,7 @@ resource "ovh_domain_zone_record" "dkim" { subdomain = "default._domainkey" fieldtype = "TXT" target = "v=DKIM1; k=rsa; p=${var.dkim}" - ttl = 3600 + ttl = 300 } resource "ovh_domain_zone_record" "spf" { @@ -29,7 +29,7 @@ resource "ovh_domain_zone_record" "spf" { subdomain = "" fieldtype = "SPF" target = "v=spf1 mx ${join(" ", [for ip in var.ipv4 : format("ip4:%s", ip)])} ${join(" ", [for ip in var.ipv6 : format("ip6:%s", ip)])} ~all" - ttl = 3600 + ttl = 300 } resource "ovh_domain_zone_record" "mx" { @@ -37,7 +37,7 @@ resource "ovh_domain_zone_record" "mx" { subdomain = "" fieldtype = "MX" target = "10 ${var.subdomain}.${var.zone}." - ttl = 3600 + ttl = 300 } resource "ovh_domain_zone_record" "dmarc" { @@ -45,5 +45,5 @@ resource "ovh_domain_zone_record" "dmarc" { subdomain = "_dmarc" fieldtype = "TXT" target = "v=DMARC1; p=none; rua=mailto:postmaster@${var.zone}; ruf=mailto:postmaster@${var.zone}" - ttl = 3600 + ttl = 300 } diff --git a/modules/monitoring.nix b/modules/beszel-agent.nix similarity index 51% rename from modules/monitoring.nix rename to modules/beszel-agent.nix index 7736040..343f6d3 100644 --- a/modules/monitoring.nix +++ b/modules/beszel-agent.nix @@ -9,18 +9,6 @@ hostName = "${config.networking.hostName}.${config.networking.domain}"; unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system}; in { - logs.services = ["beszel"]; - - services.beszel.hub = { - enable = true; - package = unstable.beszel; - - environment = { - APP_URL = "https://heimdall.hauleth.dev"; - SHARE_ALL_SYSTEMS = "true"; - }; - }; - users.users.beszel-agent = { isSystemUser = true; group = "beszel-agent"; @@ -32,9 +20,6 @@ in { enable = true; package = unstable.beszel; environment = { - TOKEN = "3f7eba65-dc6c-4ed5-9783-ae5afda0d521"; - KEY = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOmUyxo6q7CghxjI+M6rKWzVll/LY02KwSskTN/pRXEh"; - HUB_URL = "localhost:${toString config.services.beszel.hub.port}"; # LISTEN = "/run/beszel-agent/agent.sock"; SERVICE_PATTERNS = lib.strings.concatStringsSep "," [ "beszel-agent" @@ -60,24 +45,4 @@ in { Group = "beszel-agent"; }; }; - - # Expose service via Nginx - services.nginx = { - statusPage = true; - - virtualHosts.${hostName} = { - forceSSL = true; - enableACME = true; - - locations."/" = { - proxyPass = "http://localhost:${toString config.services.beszel.hub.port}"; - extraConfig = '' - proxy_read_timeout 360s; - proxy_http_version 1.1; - proxy_set_header Upgrade $http_upgrade; - proxy_set_header Connection "upgrade"; - ''; - }; - }; - }; } diff --git a/modules/beszel-hub.nix b/modules/beszel-hub.nix new file mode 100644 index 0000000..9f12ea0 --- /dev/null +++ b/modules/beszel-hub.nix @@ -0,0 +1,43 @@ +{ + config, + pkgs, + lib, + secrets, + inputs, + ... +}: let + hostName = "${config.networking.hostName}.${config.networking.domain}"; + unstable = inputs.nixpkgs-unstable.legacyPackages.${pkgs.stdenv.hostPlatform.system}; +in { + logs.services = ["beszel"]; + + services.beszel.hub = { + enable = true; + package = unstable.beszel; + + environment = { + APP_URL = "https://${hostName}"; + SHARE_ALL_SYSTEMS = "true"; + }; + }; + + # Expose service via Nginx + services.nginx = { + statusPage = true; + + virtualHosts.${hostName} = { + forceSSL = true; + enableACME = true; + + locations."/" = { + proxyPass = "http://localhost:${toString config.services.beszel.hub.port}"; + extraConfig = '' + proxy_read_timeout 360s; + proxy_http_version 1.1; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + ''; + }; + }; + }; +} diff --git a/modules/common/default.nix b/modules/common/default.nix index 9aa1576..0372596 100644 --- a/modules/common/default.nix +++ b/modules/common/default.nix @@ -77,6 +77,8 @@ services.polkit.rssh = true; }; + boot.kernelParams = ["ia32_emulation=off"]; + security.polkit = { enable = true; # debug = true; diff --git a/modules/common/hardening.nix b/modules/common/hardening.nix index 123a1ed..46f3e3d 100644 --- a/modules/common/hardening.nix +++ b/modules/common/hardening.nix @@ -120,17 +120,4 @@ in { })); })); }; - - config = { - systemd.services.postgresql = { - harden = { - enable = true; - ipSockets = true; - }; - - serviceConfig = { - PrivateUsers = false; - }; - }; - }; } diff --git a/modules/mail/module.nix b/modules/mail/module.nix index e9c87a8..928dd71 100644 --- a/modules/mail/module.nix +++ b/modules/mail/module.nix @@ -179,6 +179,9 @@ in { serviceConfig = { ExecStart = "${cfg.package}/bin/stalwart --config=${configFile}"; + User = "stalwart-mail"; + Group = "stalwart-mail"; + # Base from template resources/systemd/stalwart-mail.service Type = "simple"; LimitNOFILE = 65536; @@ -190,7 +193,6 @@ in { StandardError = "journal"; SyslogIdentifier = "stalwart"; - DynamicUser = true; StateDirectory = "stalwart"; CacheDirectory = "stalwart"; diff --git a/modules/postgres.nix b/modules/postgres.nix index 80cdc79..3c952d5 100644 --- a/modules/postgres.nix +++ b/modules/postgres.nix @@ -2,6 +2,7 @@ logs.services = [ "postgresql" ]; services.postgresql = { + # enable = true; package = pkgs.postgresql_17; settings = { @@ -28,4 +29,15 @@ max_parallel_workers = 8; }; }; + + systemd.services.postgresql = { + harden = { + enable = true; + ipSockets = true; + }; + + serviceConfig = { + PrivateUsers = false; + }; + }; } diff --git a/servers/heimdall/default.nix b/servers/heimdall/default.nix index 5c1698e..8509f72 100644 --- a/servers/heimdall/default.nix +++ b/servers/heimdall/default.nix @@ -31,14 +31,14 @@ in { imports = with inputs.self.nixosModules; [ ovh backup - postgres - rss - irc-bouncer - monitoring - mail - pastebin + # postgres + # rss + # irc-bouncer + # monitoring + # mail + # pastebin tailscale logs - git + # git ]; } diff --git a/servers/mimir/default.nix b/servers/mimir/default.nix new file mode 100644 index 0000000..2d4e29e --- /dev/null +++ b/servers/mimir/default.nix @@ -0,0 +1,87 @@ +{inputs, ...}: let + ipv6Prefix = "2001:41d0:0601:1100"; + prefixLength = 128; + ipv6Address = "${ipv6Prefix}::178f"; + ipv6Gateway = "${ipv6Prefix}::0001"; +in { + networking.hostName = "mimir"; + networking.domain = "hauleth.dev"; + + # networking.useDHCP = false; + networking.interfaces.ens3 = { + ipv6.addresses = [ + { + address = ipv6Address; + inherit prefixLength; + } + ]; + + ipv6.routes = [ + { + address = ipv6Gateway; + inherit prefixLength; + } + ]; + }; + + networking.defaultGateway6 = { + address = ipv6Gateway; + interface = "ens3"; + }; + + boot.loader.grub = { + # no need to set devices, disko will add all devices that have a EF02 partition to the list already + # devices = [ ]; + efiSupport = true; + efiInstallAsRemovable = true; + }; + + environment.persistence."/persist" = { + enable = true; + hideMounts = true; + + directories = [ + "/var/backup" + "/var/log" + "/var/lib" + + "/home" + ]; + + files = [ + "/etc/machine-id" + "/etc/ssh/ssh_host_ed25519_key" + "/etc/ssh/ssh_host_ed25519_key.pub" + "/etc/ssh/ssh_host_rsa_key" + "/etc/ssh/ssh_host_rsa_key.pub" + ]; + }; + + networking.firewall.allowedTCPPorts = [2222]; + + services.beszel.agent.environment = { + TOKEN = "8c42e760-da30-429b-852c-3e26ca20d90b"; + KEY = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOmUyxo6q7CghxjI+M6rKWzVll/LY02KwSskTN/pRXEh"; + HUB_URL = "https://heimdall.hauleth.dev"; + # DISABLE_SSH = "true"; + LISTEN = "45876"; + }; + + imports = with inputs.self.nixosModules; [ + inputs.impermanence.nixosModules.impermanence + inputs.disko.nixosModules.disko + ./hardware.nix + ./disks.nix + backup + postgres + rss + irc-bouncer + beszel-hub + beszel-agent + mail + # pastebin + tailscale + logs + git + ]; +} diff --git a/servers/mimir/disks.nix b/servers/mimir/disks.nix new file mode 100644 index 0000000..b92de6e --- /dev/null +++ b/servers/mimir/disks.nix @@ -0,0 +1,72 @@ +{lib, ...}: { + disko.devices = { + disk.main = { + device = lib.mkDefault "/dev/sda"; + type = "disk"; + content = { + type = "gpt"; + partitions = { + boot = { + name = "boot"; + size = "1M"; + type = "EF02"; + }; + + ESP = { + priority = 1; + name = "ESP"; + start = "1M"; + end = "512M"; + type = "EF00"; + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + mountOptions = [ "defaults" ]; + }; + }; + + root = { + size = "100%"; + content = { + type = "btrfs"; + extraArgs = [ "-f" ]; + + subvolumes = { + "@root" = { + mountpoint = "/"; + mountOptions = [ + "compress=zstd" + "noatime" + ]; + }; + "@nix" = { + mountpoint = "/nix"; + mountOptions = [ + "compress=zstd" + "noatime" + ]; + }; + + "@persist" = { + mountpoint = "/persist"; + mountOptions = [ + "compress=zstd" + "noatime" + ]; + }; + + "@swap" = { + mountpoint = "/.swap"; + swap.swapfile.size = "12G"; + }; + }; + }; + }; + }; + }; + }; + }; + + fileSystems."/persist".neededForBoot = true; +} diff --git a/servers/mimir/hardware.nix b/servers/mimir/hardware.nix new file mode 100644 index 0000000..1c084da --- /dev/null +++ b/servers/mimir/hardware.nix @@ -0,0 +1,17 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +}