diff --git a/_sources/generated.json b/_sources/generated.json index b85add2..7d4188b 100644 --- a/_sources/generated.json +++ b/_sources/generated.json @@ -407,6 +407,26 @@ }, "version": "1be6c3bde64da46d4c369135479118e62690d3d5" }, + "slopview": { + "cargoLock": null, + "date": "2026-04-25", + "extract": null, + "name": "slopview", + "passthru": null, + "pinned": false, + "src": { + "deepClone": false, + "fetchSubmodules": false, + "leaveDotGit": false, + "name": null, + "rev": "0966b6b0488d9ec48af788ac6a9f7cf1bc968305", + "sha256": "sha256-rritHO9NbZAiO2X8gN1nVqK085KoswgrIPbt+WvyqR8=", + "sparseCheckout": [], + "type": "git", + "url": "https://tangled.org/@ptr.pet/slopview" + }, + "version": "0966b6b0488d9ec48af788ac6a9f7cf1bc968305" + }, "stylix": { "cargoLock": null, "date": "2026-04-03", diff --git a/_sources/generated.nix b/_sources/generated.nix index ceb9057..a963b9c 100644 --- a/_sources/generated.nix +++ b/_sources/generated.nix @@ -270,6 +270,20 @@ }; date = "2026-04-20"; }; + slopview = { + pname = "slopview"; + version = "0966b6b0488d9ec48af788ac6a9f7cf1bc968305"; + src = fetchgit { + url = "https://tangled.org/@ptr.pet/slopview"; + rev = "0966b6b0488d9ec48af788ac6a9f7cf1bc968305"; + fetchSubmodules = false; + deepClone = false; + leaveDotGit = false; + sparseCheckout = [ ]; + sha256 = "sha256-rritHO9NbZAiO2X8gN1nVqK085KoswgrIPbt+WvyqR8="; + }; + date = "2026-04-25"; + }; stylix = { pname = "stylix"; version = "6d0502ef7447090abf8b00362b5cda8ac64595b4"; diff --git a/dns/dnsconfig.js b/dns/dnsconfig.js index 4add803..b808347 100644 --- a/dns/dnsconfig.js +++ b/dns/dnsconfig.js @@ -95,7 +95,7 @@ D( "klbr.net", REG_NONE, DnsProvider(DSP_PRIMARY), - TRIMOUNTS(["api.compare.plc", "api.spool"]), + TRIMOUNTS(["api.compare.plc", "api.spool", "bsky"]), DZWONEK("vpn"), VOLSINII(["plc", "relay"]), TXT("@", "data endpoint for services and projects that fall under klbr.net."), diff --git a/hosts/chernobog/modules/network.nix b/hosts/chernobog/modules/network.nix index 7c41f88..47ffd42 100644 --- a/hosts/chernobog/modules/network.nix +++ b/hosts/chernobog/modules/network.nix @@ -2,4 +2,7 @@ imports = [ ../../../modules/network/dns/systemd.nix ]; networking.useDHCP = true; + + # networking.firewall.enable = true; + # networking.firewall.allowedTCPPorts = [22]; } diff --git a/hosts/chernobog/modules/tailscale.nix b/hosts/chernobog/modules/tailscale.nix index 7687ed1..0e255a3 100644 --- a/hosts/chernobog/modules/tailscale.nix +++ b/hosts/chernobog/modules/tailscale.nix @@ -1,5 +1,6 @@ -{ config, ... }: +{ lib, ... }: { imports = [ ../../../modules/network/tailscale.nix ]; networking.firewall.checkReversePath = "loose"; + services.tailscale.extraUpFlags = lib.mkForce ["--ssh"]; } diff --git a/hosts/dzwonek/modules/headscale.nix/acl.nix b/hosts/dzwonek/modules/headscale.nix/acl.nix index 02c17d5..82a9b19 100644 --- a/hosts/dzwonek/modules/headscale.nix/acl.nix +++ b/hosts/dzwonek/modules/headscale.nix/acl.nix @@ -27,6 +27,23 @@ let }; }; }; + sshRuleType = t.submodule { + options = { + action = l.mkOption { + type = t.enum [ "accept" ]; + default = "accept"; + }; + users = l.mkOption { + type = t.listOf t.str; + }; + src = l.mkOption { + type = t.listOf t.str; + }; + dst = l.mkOption { + type = t.listOf t.str; + }; + }; + }; in { options = { @@ -47,6 +64,10 @@ in type = t.listOf ruleType; default = [ ]; }; + sshRules = l.mkOption { + type = t.listOf sshRuleType; + default = []; + }; }; }; @@ -58,6 +79,7 @@ in tagOwners = l.mapAttrs' (k: v: l.nameValuePair "tag:${k}" v) cfg.tagOwners; hosts = cfg.hosts; acls = l.map (rule: if rule.proto == null then l.removeAttrs rule [ "proto" ] else rule) cfg.rules; + ssh = cfg.sshRules; } ); in diff --git a/hosts/dzwonek/modules/headscale.nix/default.nix b/hosts/dzwonek/modules/headscale.nix/default.nix index 49f828e..6cdde1d 100644 --- a/hosts/dzwonek/modules/headscale.nix/default.nix +++ b/hosts/dzwonek/modules/headscale.nix/default.nix @@ -29,6 +29,13 @@ in chernobog = "100.64.0.6"; trimounts = "100.64.0.1"; }; + sshRules = [ + { + src = ["autogroup:member"]; + dst = ["autogroup:self"]; + users = ["autogroup:nonroot"]; + } + ]; rules = lib.mkBefore [ { src = [ "group:admin" ]; @@ -50,8 +57,8 @@ in dst = [ "chernobog:*" ]; } { - src = [ admin ]; - dst = [ "${admin}:*" ]; + src = ["autogroup:member"]; + dst = ["autogroup:self:*"]; } { src = [ diff --git a/hosts/trimounts/modules/slopview.nix b/hosts/trimounts/modules/slopview.nix new file mode 100644 index 0000000..79e3e5a --- /dev/null +++ b/hosts/trimounts/modules/slopview.nix @@ -0,0 +1,43 @@ +{ terra, ... }: +let + port = 8000; + + rootDomain = "klbr.net"; + domain = "bsky.${rootDomain}"; +in { + # users.users.slopview = { + # isSystemUser = true; + # group = "slopview"; + # }; + # users.groups.slopview = {}; + + # systemd.services.slopview = { + # description = "slopview"; + # wantedBy = ["multi-user.target"]; + # after = ["network.target"]; + + # environment = { + # PORT = toString port; + # SEED_ACCOUNT = "did:plc:dfl62fgb7wtjj3fcbb72naae"; + # }; + + # serviceConfig = rec { + # ExecStart = "${terra.slopview}/bin/appview"; + # User = "slopview"; + # Group = "slopview"; + # StateDirectory = "slopview"; + # WorkingDirectory = "%S/${StateDirectory}"; + # Restart = "on-failure"; + # RestartSec = "5s"; + # }; + # }; + + security.acme.certs.${rootDomain}.extraDomainNames = [domain]; + services.nginx.virtualHosts.${domain} = { + useACMEHost = rootDomain; + forceSSL = true; + quic = true; + kTLS = true; + locations."/".proxyPass = "http://chernobog:${toString port}"; + }; +} diff --git a/nvfetcher.toml b/nvfetcher.toml index f621a93..573d187 100644 --- a/nvfetcher.toml +++ b/nvfetcher.toml @@ -70,6 +70,10 @@ fetch.git = "https://tangled.org/@ptr.pet/compare-plc" src.git = "https://tangled.org/@ptr.pet/random.wisp.place" fetch.git = "https://tangled.org/@ptr.pet/random.wisp.place" +[slopview] +src.git = "https://tangled.org/@ptr.pet/slopview" +fetch.git = "https://tangled.org/@ptr.pet/slopview" + ## TANGLED ## [tangled] diff --git a/pkgs-set/pkgs/slopview.nix b/pkgs-set/pkgs/slopview.nix new file mode 100644 index 0000000..8dfed2d --- /dev/null +++ b/pkgs-set/pkgs/slopview.nix @@ -0,0 +1 @@ +{inputs, callPackage, ...}: callPackage inputs.slopview {}