diff --git a/hosts/dzwonek/default.nix b/hosts/dzwonek/default.nix index 35f5908..ecb4781 100644 --- a/hosts/dzwonek/default.nix +++ b/hosts/dzwonek/default.nix @@ -16,7 +16,6 @@ ] ++ (tlib.importFolder (toString ./modules)); - environment.systemPackages = [ pkgs.curl pkgs.gitMinimal diff --git a/hosts/dzwonek/disk-config.nix b/hosts/dzwonek/disk-config.nix index 0bec6a4..143733b 100644 --- a/hosts/dzwonek/disk-config.nix +++ b/hosts/dzwonek/disk-config.nix @@ -51,4 +51,4 @@ }; }; }; -} \ No newline at end of file +} diff --git a/hosts/dzwonek/modules/hardware-configuration.nix b/hosts/dzwonek/modules/hardware-configuration.nix index 9a8ad1b..538e614 100644 --- a/hosts/dzwonek/modules/hardware-configuration.nix +++ b/hosts/dzwonek/modules/hardware-configuration.nix @@ -1,14 +1,26 @@ # Do not modify this file! It was generated by ‘nixos-generate-config’ # and may be overwritten by future invocations. Please make changes # to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: +{ + config, + lib, + pkgs, + modulesPath, + ... +}: { - imports = - [ (modulesPath + "/profiles/qemu-guest.nix") - ]; + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; - boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "sr_mod" "virtio_blk" ]; + boot.initrd.availableKernelModules = [ + "ata_piix" + "uhci_hcd" + "virtio_pci" + "sr_mod" + "virtio_blk" + ]; boot.initrd.kernelModules = [ ]; boot.kernelModules = [ ]; boot.extraModulePackages = [ ]; diff --git a/hosts/dzwonek/modules/headscale.nix/acl.nix b/hosts/dzwonek/modules/headscale.nix/acl.nix index f1e1501..02c17d5 100644 --- a/hosts/dzwonek/modules/headscale.nix/acl.nix +++ b/hosts/dzwonek/modules/headscale.nix/acl.nix @@ -1,4 +1,5 @@ -{config, lib, ...}: let +{ config, lib, ... }: +let l = lib // builtins; t = l.types; @@ -10,7 +11,12 @@ default = "accept"; }; proto = l.mkOption { - type = t.nullOr (t.enum ["tcp" "udp"]); + type = t.nullOr ( + t.enum [ + "tcp" + "udp" + ] + ); default = null; }; src = l.mkOption { @@ -21,45 +27,44 @@ }; }; }; -in { +in +{ options = { services.headscale.acl = { groups = l.mkOption { type = t.attrsOf (t.listOf t.str); - default = []; + default = [ ]; }; tagOwners = l.mkOption { type = t.attrsOf (t.listOf t.str); - default = []; + default = [ ]; }; hosts = l.mkOption { type = t.attrsOf t.str; - default = []; + default = [ ]; }; rules = l.mkOption { type = t.listOf ruleType; - default = []; + default = [ ]; }; }; }; - config = let - generated = l.toFile "policy.hujson" (l.toJSON { - groups = l.mapAttrs' (k: v: l.nameValuePair "group:${k}" v) cfg.groups; - tagOwners = l.mapAttrs' (k: v: l.nameValuePair "tag:${k}" v) cfg.tagOwners; - hosts = cfg.hosts; - acls = l.map - (rule: - if rule.proto == null - then l.removeAttrs rule ["proto"] - else rule - ) - cfg.rules; - }); - in { - services.headscale.settings.policy = { - mode = "file"; - path = generated; + config = + let + generated = l.toFile "policy.hujson" ( + l.toJSON { + groups = l.mapAttrs' (k: v: l.nameValuePair "group:${k}" v) cfg.groups; + tagOwners = l.mapAttrs' (k: v: l.nameValuePair "tag:${k}" v) cfg.tagOwners; + hosts = cfg.hosts; + acls = l.map (rule: if rule.proto == null then l.removeAttrs rule [ "proto" ] else rule) cfg.rules; + } + ); + in + { + services.headscale.settings.policy = { + mode = "file"; + path = generated; + }; }; - }; } diff --git a/hosts/dzwonek/modules/headscale.nix/default.nix b/hosts/dzwonek/modules/headscale.nix/default.nix index dabf8a6..c9830cb 100644 --- a/hosts/dzwonek/modules/headscale.nix/default.nix +++ b/hosts/dzwonek/modules/headscale.nix/default.nix @@ -4,7 +4,7 @@ let domain = "vpn.${rootDomain}"; in { - imports = [./acl.nix]; + imports = [ ./acl.nix ]; age.secrets.headscaleOidcSecret = { file = ../../../../secrets/headscaleOidcSecret.age; @@ -18,10 +18,10 @@ in address = "0.0.0.0"; port = 1111; acl = { - groups.admin = ["90008@gaze.systems"]; + groups.admin = [ "90008@gaze.systems" ]; tagOwners = { - private-infra = ["group:admin"]; - other-infra = ["group:admin"]; + private-infra = [ "group:admin" ]; + other-infra = [ "group:admin" ]; }; hosts = { chernobog = "100.64.0.9"; @@ -30,28 +30,34 @@ in }; rules = lib.mkBefore [ { - src = ["group:admin"]; - dst = ["tag:private-infra:*" "tag:other-infra:*"]; + src = [ "group:admin" ]; + dst = [ + "tag:private-infra:*" + "tag:other-infra:*" + ]; } { - src = ["tag:private-infra"]; - dst = ["tag:other-infra:*"]; + src = [ "tag:private-infra" ]; + dst = [ "tag:other-infra:*" ]; } { - src = ["wolumonde"]; - dst = ["chernobog:*"]; + src = [ "wolumonde" ]; + dst = [ "chernobog:*" ]; } { - src = ["90008@gaze.systems"]; - dst = ["90008@gaze.systems:*"]; + src = [ "90008@gaze.systems" ]; + dst = [ "90008@gaze.systems:*" ]; } { - src = ["90008@gaze.systems" "tag:private-infra"]; - dst = ["autogroup:internet:*"]; + src = [ + "90008@gaze.systems" + "tag:private-infra" + ]; + dst = [ "autogroup:internet:*" ]; } { - src = ["ellite@ellite.dev"]; - dst = ["chernobog:8463"]; + src = [ "ellite@ellite.dev" ]; + dst = [ "chernobog:8463" ]; } ]; }; @@ -76,7 +82,6 @@ in }; }; - # security.acme.certs.${rootDomain}.extraDomainNames = [domain]; services.nginx.virtualHosts.${domain} = { useACMEHost = domain; diff --git a/hosts/dzwonek/modules/nginx.nix b/hosts/dzwonek/modules/nginx.nix index 72f3df7..cdf8b7e 100644 --- a/hosts/dzwonek/modules/nginx.nix +++ b/hosts/dzwonek/modules/nginx.nix @@ -16,7 +16,10 @@ statusPage = true; }; - networking.firewall.allowedTCPPorts = [ 80 443 ]; + networking.firewall.allowedTCPPorts = [ + 80 + 443 + ]; # output json logs so we can consume them more easily services.nginx.appendHttpConfig = '' diff --git a/hosts/dzwonek/modules/tailscale.nix b/hosts/dzwonek/modules/tailscale.nix index 36c4b2a..2573b4d 100644 --- a/hosts/dzwonek/modules/tailscale.nix +++ b/hosts/dzwonek/modules/tailscale.nix @@ -1,6 +1,7 @@ -{config, ...}: { - imports = [../../../modules/network/tailscale.nix]; - +{ config, ... }: +{ + imports = [ ../../../modules/network/tailscale.nix ]; + # age.secrets.tailscaleAuthKey.file = ../../../secrets/tailscaleAuthKey.age; # services.tailscale.authKeyFile = config.age.secrets.tailscaleAuthKey.path; } diff --git a/hosts/volsinii/disk-config.nix b/hosts/volsinii/disk-config.nix index 01a4903..c3dbb8f 100644 --- a/hosts/volsinii/disk-config.nix +++ b/hosts/volsinii/disk-config.nix @@ -51,4 +51,4 @@ }; }; }; -} \ No newline at end of file +} diff --git a/hosts/volsinii/modules/hardware-configuration.nix b/hosts/volsinii/modules/hardware-configuration.nix index 749b8b2..6b33ab5 100644 --- a/hosts/volsinii/modules/hardware-configuration.nix +++ b/hosts/volsinii/modules/hardware-configuration.nix @@ -1,12 +1,22 @@ # Do not modify this file! It was generated by ‘nixos-generate-config’ # and may be overwritten by future invocations. Please make changes # to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: +{ + config, + lib, + pkgs, + modulesPath, + ... +}: { imports = [ ]; - boot.initrd.availableKernelModules = [ "ata_piix" "sr_mod" "xen_blkfront" ]; + boot.initrd.availableKernelModules = [ + "ata_piix" + "sr_mod" + "xen_blkfront" + ]; boot.initrd.kernelModules = [ ]; boot.kernelModules = [ ]; boot.extraModulePackages = [ ]; @@ -16,11 +26,12 @@ systemd.network.enable = true; systemd.network.wait-online.enable = false; systemd.network.networks."enX0" = { - matchConfig = { Name = "enX0"; }; - address = ["199.71.188.53/29"]; - gateway = ["199.71.188.49"]; + matchConfig = { + Name = "enX0"; + }; + address = [ "199.71.188.53/29" ]; + gateway = [ "199.71.188.49" ]; }; - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; } diff --git a/hosts/volsinii/modules/tailscale.nix b/hosts/volsinii/modules/tailscale.nix index 36c4b2a..2573b4d 100644 --- a/hosts/volsinii/modules/tailscale.nix +++ b/hosts/volsinii/modules/tailscale.nix @@ -1,6 +1,7 @@ -{config, ...}: { - imports = [../../../modules/network/tailscale.nix]; - +{ config, ... }: +{ + imports = [ ../../../modules/network/tailscale.nix ]; + # age.secrets.tailscaleAuthKey.file = ../../../secrets/tailscaleAuthKey.age; # services.tailscale.authKeyFile = config.age.secrets.tailscaleAuthKey.path; } diff --git a/hosts/wolumonde/modules/atproto.nix b/hosts/wolumonde/modules/atproto.nix index 8280a1d..3457f40 100644 --- a/hosts/wolumonde/modules/atproto.nix +++ b/hosts/wolumonde/modules/atproto.nix @@ -17,15 +17,17 @@ let }) files ); }; - mkHandleCfg = rootDomain: did: (mkWellKnownCfg { - "atproto-did" = pkgs.writeText "server" did; - }) - // { - useACMEHost = rootDomain; - forceSSL = true; - quic = true; - kTLS = true; - }; + mkHandleCfg = + rootDomain: did: + (mkWellKnownCfg { + "atproto-did" = pkgs.writeText "server" did; + }) + // { + useACMEHost = rootDomain; + forceSSL = true; + quic = true; + kTLS = true; + }; mkDidWebCfg = domain: { "${domain}" = (mkWellKnownCfg { @@ -44,7 +46,10 @@ let in { security.acme.certs."gaze.systems".extraDomainNames = [ - dawnDid guestbookDid "drew.gaze.systems" "test.gaze.systems" + dawnDid + guestbookDid + "drew.gaze.systems" + "test.gaze.systems" ]; services.nginx.virtualHosts = { "test.gaze.systems" = mkHandleCfg "gaze.systems" "did:web:dawn.gaze.systems"; diff --git a/hosts/wolumonde/modules/clickee-proxy.nix b/hosts/wolumonde/modules/clickee-proxy.nix index e97ca33..d3ef5c0 100644 --- a/hosts/wolumonde/modules/clickee-proxy.nix +++ b/hosts/wolumonde/modules/clickee-proxy.nix @@ -1,6 +1,8 @@ -{config, terra, ...}: let +{ config, terra, ... }: +let port = 7145; -in { +in +{ age.secrets.clickeeProxyConfig = { file = ../../../secrets/clickeeProxyConfig.age; }; diff --git a/hosts/wolumonde/modules/email.nix b/hosts/wolumonde/modules/email.nix index 8782b23..ab5b673 100644 --- a/hosts/wolumonde/modules/email.nix +++ b/hosts/wolumonde/modules/email.nix @@ -1,62 +1,65 @@ -{pkgs, ...}: { - security.acme.certs."ptr.pet".extraDomainNames = [ - "mta-sts.ptr.pet" - "autoconfig.ptr.pet" - "autodiscover.ptr.pet" - "test.ptr.pet" - ]; - services.nginx.virtualHosts."test.ptr.pet" = { - useACMEHost = "ptr.pet"; - quic = true; - kTLS = true; - forceSSL = true; +{ pkgs, ... }: +{ + security.acme.certs."ptr.pet".extraDomainNames = [ + "mta-sts.ptr.pet" + "autoconfig.ptr.pet" + "autodiscover.ptr.pet" + "test.ptr.pet" + ]; + services.nginx.virtualHosts."test.ptr.pet" = { + useACMEHost = "ptr.pet"; + quic = true; + kTLS = true; + forceSSL = true; + }; + services.nginx.virtualHosts."ptr.pet" = { + useACMEHost = "ptr.pet"; + quic = true; + kTLS = true; + forceSSL = true; + locations."/mail/config-v1.1.xml" = { + return = "301 https://autoconfig.migadu.com/mail/config-v1.1.xml"; }; - services.nginx.virtualHosts."ptr.pet" = { - useACMEHost = "ptr.pet"; - quic = true; - kTLS = true; - forceSSL = true; - locations."/mail/config-v1.1.xml" = { - return = "301 https://autoconfig.migadu.com/mail/config-v1.1.xml"; - }; - locations."/Autodiscover/Autodiscover.xml" = { - return = "301 https://autodiscover.migadu.com/Autodiscover/Autodiscover.xml"; - }; + locations."/Autodiscover/Autodiscover.xml" = { + return = "301 https://autodiscover.migadu.com/Autodiscover/Autodiscover.xml"; }; - services.nginx.virtualHosts."mta-sts.ptr.pet" = let - file = pkgs.writeText "mta-sts.txt" '' - version: STSv1 - mode: enforce - mx: aspmx1.migadu.com - mx: aspmx2.migadu.com - max_age: 31557600 - ''; - in { - useACMEHost = "ptr.pet"; - quic = true; - kTLS = true; - forceSSL = true; - locations."=/.well-known/mta-sts.txt".extraConfig = '' - alias ${file}; - default_type text/plain; - ''; + }; + services.nginx.virtualHosts."mta-sts.ptr.pet" = + let + file = pkgs.writeText "mta-sts.txt" '' + version: STSv1 + mode: enforce + mx: aspmx1.migadu.com + mx: aspmx2.migadu.com + max_age: 31557600 + ''; + in + { + useACMEHost = "ptr.pet"; + quic = true; + kTLS = true; + forceSSL = true; + locations."=/.well-known/mta-sts.txt".extraConfig = '' + alias ${file}; + default_type text/plain; + ''; }; - services.nginx.virtualHosts."autoconfig.ptr.pet" = { - useACMEHost = "ptr.pet"; - quic = true; - kTLS = true; - forceSSL = true; - locations."/" = { - return = "301 https://autoconfig.migadu.com$request_uri"; - }; + services.nginx.virtualHosts."autoconfig.ptr.pet" = { + useACMEHost = "ptr.pet"; + quic = true; + kTLS = true; + forceSSL = true; + locations."/" = { + return = "301 https://autoconfig.migadu.com$request_uri"; }; - services.nginx.virtualHosts."autodiscover.ptr.pet" = { - useACMEHost = "ptr.pet"; - quic = true; - kTLS = true; - forceSSL = true; - locations."/" = { - return = "301 https://autodiscover.migadu.com$request_uri"; - }; + }; + services.nginx.virtualHosts."autodiscover.ptr.pet" = { + useACMEHost = "ptr.pet"; + quic = true; + kTLS = true; + forceSSL = true; + locations."/" = { + return = "301 https://autodiscover.migadu.com$request_uri"; }; + }; } diff --git a/hosts/wolumonde/modules/forgejo.nix/default.nix b/hosts/wolumonde/modules/forgejo.nix/default.nix index de85efe..5d4cd18 100644 --- a/hosts/wolumonde/modules/forgejo.nix/default.nix +++ b/hosts/wolumonde/modules/forgejo.nix/default.nix @@ -54,7 +54,7 @@ in "public" ]; - security.acme.certs."gaze.systems".extraDomainNames = [forgejoCfg.server.DOMAIN]; + security.acme.certs."gaze.systems".extraDomainNames = [ forgejoCfg.server.DOMAIN ]; services.nginx.virtualHosts.${forgejoCfg.server.DOMAIN} = { useACMEHost = "gaze.systems"; forceSSL = true; diff --git a/hosts/wolumonde/modules/hedgedoc.nix b/hosts/wolumonde/modules/hedgedoc.nix index b3ede26..f3b7c7c 100644 --- a/hosts/wolumonde/modules/hedgedoc.nix +++ b/hosts/wolumonde/modules/hedgedoc.nix @@ -1,4 +1,5 @@ -{ config, ... }: let +{ config, ... }: +let cfg = config.services.hedgedoc.settings; in { @@ -16,13 +17,12 @@ in }; }; - security.acme.certs."gaze.systems".extraDomainNames = [cfg.domain]; + security.acme.certs."gaze.systems".extraDomainNames = [ cfg.domain ]; services.nginx.virtualHosts.${cfg.domain} = { useACMEHost = "gaze.systems"; forceSSL = true; quic = true; kTLS = true; - locations."/".proxyPass = - "http://${cfg.host}:${toString cfg.port}"; + locations."/".proxyPass = "http://${cfg.host}:${toString cfg.port}"; }; } diff --git a/hosts/wolumonde/modules/openbao.disabled/default.nix b/hosts/wolumonde/modules/openbao.disabled/default.nix index 903e406..2471e96 100644 --- a/hosts/wolumonde/modules/openbao.disabled/default.nix +++ b/hosts/wolumonde/modules/openbao.disabled/default.nix @@ -1,10 +1,12 @@ -{lib, config, ...}: let +{ lib, config, ... }: +let port = 5394; domain = "bao.${config.services.headscale.settings.dns.base_domain}"; cfg = config.services.openbao.settings; apiAddress = "127.0.0.1:${toString port}"; -in { - imports = [./spindle-proxy]; +in +{ + imports = [ ./spindle-proxy ]; services.openbao = { enable = true; diff --git a/hosts/wolumonde/modules/openbao.disabled/spindle-proxy/default.nix b/hosts/wolumonde/modules/openbao.disabled/spindle-proxy/default.nix index 1b3bc99..ce428df 100644 --- a/hosts/wolumonde/modules/openbao.disabled/spindle-proxy/default.nix +++ b/hosts/wolumonde/modules/openbao.disabled/spindle-proxy/default.nix @@ -1,24 +1,29 @@ -{ config, lib, pkgs, ... }: +{ + config, + lib, + pkgs, + ... +}: let port = 8945; secrets = config.age.secrets; cfgFile = pkgs.writeText "openbao-proxy-spindle-config.hcl" ( lib.replaceStrings - [ - "%role_id%" - "%secret_id%" - "%vault_address%" - "%listener_port%" - "%name%" - ] - [ - secrets.spindleOpenbaoRoleId.path - secrets.spindleOpenbaoSecretId.path - config.services.openbao.settings.api_addr - (toString port) - name - ] - (lib.fileContents ./config.hcl) + [ + "%role_id%" + "%secret_id%" + "%vault_address%" + "%listener_port%" + "%name%" + ] + [ + secrets.spindleOpenbaoRoleId.path + secrets.spindleOpenbaoSecretId.path + config.services.openbao.settings.api_addr + (toString port) + name + ] + (lib.fileContents ./config.hcl) ); domain = "spindle.bao.lan.gaze.systems"; name = "openbao-proxy-spindle"; @@ -42,7 +47,7 @@ in group = name; }; users.groups.${name} = { - members = [name]; + members = [ name ]; }; systemd.services.${name} = { @@ -58,24 +63,32 @@ in LimitNOFILE = "65536"; User = name; Group = name; - RuntimeDirectory=name; - RuntimeDirectoryMode=0700; - StateDirectory=name; - StateDirectoryMode=0700; - ProcSubset="pid"; - ProtectClock=true; - ProtectControlGroups=true; - ProtectHome=true; - ProtectHostname=true; - ProtectKernelLogs=true; - ProtectKernelModules=true; - ProtectKernelTunables=true; - ProtectProc="invisible"; - RestrictNamespaces=true; - RestrictRealtime=true; - RestrictAddressFamilies=["AF_INET" "AF_INET6" "AF_UNIX"]; - SystemCallArchitectures="native"; - SystemCallFilter=["@system-service" "@resources" "~@privileged"]; + RuntimeDirectory = name; + RuntimeDirectoryMode = 0700; + StateDirectory = name; + StateDirectoryMode = 0700; + ProcSubset = "pid"; + ProtectClock = true; + ProtectControlGroups = true; + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectProc = "invisible"; + RestrictNamespaces = true; + RestrictRealtime = true; + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + ]; + SystemCallArchitectures = "native"; + SystemCallFilter = [ + "@system-service" + "@resources" + "~@privileged" + ]; }; }; diff --git a/hosts/wolumonde/modules/perses.nix/default.nix b/hosts/wolumonde/modules/perses.nix/default.nix index d9f9907..346c7b1 100644 --- a/hosts/wolumonde/modules/perses.nix/default.nix +++ b/hosts/wolumonde/modules/perses.nix/default.nix @@ -66,8 +66,11 @@ in systemd.services.perses = { description = "perses"; - after = ["network.target" "pocket-id.service"]; - requires = ["pocket-id.service"]; + after = [ + "network.target" + "pocket-id.service" + ]; + requires = [ "pocket-id.service" ]; serviceConfig = { ExecStart = "${pkgs.perses}/bin/perses --config=${persesConfigYaml} --web.listen-address=:${toString port} --log.level=info"; EnvironmentFile = secrets.persesSecret.path; @@ -79,7 +82,7 @@ in cp -f ${./provision}/* ${provisioningFolder} ''; - security.acme.certs."gaze.systems".extraDomainNames = [domain]; + security.acme.certs."gaze.systems".extraDomainNames = [ domain ]; services.nginx.virtualHosts.${domain} = { useACMEHost = "gaze.systems"; # TODO: write a module to define vhosts for subdomains quic = true; diff --git a/hosts/wolumonde/modules/pocket-id.nix b/hosts/wolumonde/modules/pocket-id.nix index bb13739..e7420b4 100644 --- a/hosts/wolumonde/modules/pocket-id.nix +++ b/hosts/wolumonde/modules/pocket-id.nix @@ -13,7 +13,7 @@ in }; }; - security.acme.certs."gaze.systems".extraDomainNames = [domain]; + security.acme.certs."gaze.systems".extraDomainNames = [ domain ]; services.nginx.virtualHosts.${domain} = { useACMEHost = "gaze.systems"; diff --git a/hosts/wolumonde/modules/tailscale.nix b/hosts/wolumonde/modules/tailscale.nix index 053a8e0..361fbb4 100644 --- a/hosts/wolumonde/modules/tailscale.nix +++ b/hosts/wolumonde/modules/tailscale.nix @@ -1,7 +1,7 @@ { config, ... }: { - imports = [../../../modules/network/tailscale.nix]; - + imports = [ ../../../modules/network/tailscale.nix ]; + # age.secrets.tailscaleAuthKey.file = ../../../secrets/tailscaleAuthKey.age; # services.tailscale.authKeyFile = config.age.secrets.tailscaleAuthKey.path; diff --git a/hosts/wolumonde/modules/tangled.nix/default.nix b/hosts/wolumonde/modules/tangled.nix/default.nix index bbbb71b..0c4a114 100644 --- a/hosts/wolumonde/modules/tangled.nix/default.nix +++ b/hosts/wolumonde/modules/tangled.nix/default.nix @@ -1,3 +1,6 @@ { - imports = [./knot.nix ./spindle.nix]; + imports = [ + ./knot.nix + ./spindle.nix + ]; } diff --git a/hosts/wolumonde/modules/tangled.nix/knot.nix b/hosts/wolumonde/modules/tangled.nix/knot.nix index e808839..1318d7b 100644 --- a/hosts/wolumonde/modules/tangled.nix/knot.nix +++ b/hosts/wolumonde/modules/tangled.nix/knot.nix @@ -24,7 +24,7 @@ in }; }; - security.acme.certs."gaze.systems".extraDomainNames = [knotCfg.server.hostname]; + security.acme.certs."gaze.systems".extraDomainNames = [ knotCfg.server.hostname ]; services.nginx.virtualHosts.${knotCfg.server.hostname} = { useACMEHost = "gaze.systems"; diff --git a/hosts/wolumonde/modules/tangled.nix/spindle.nix b/hosts/wolumonde/modules/tangled.nix/spindle.nix index 311644d..37358ca 100644 --- a/hosts/wolumonde/modules/tangled.nix/spindle.nix +++ b/hosts/wolumonde/modules/tangled.nix/spindle.nix @@ -41,7 +41,7 @@ in }; }; - security.acme.certs."gaze.systems".extraDomainNames = [spindleCfg.server.hostname]; + security.acme.certs."gaze.systems".extraDomainNames = [ spindleCfg.server.hostname ]; services.nginx.virtualHosts.${spindleCfg.server.hostname} = { useACMEHost = "gaze.systems"; diff --git a/hosts/wolumonde/modules/webhook.disabled/default.nix b/hosts/wolumonde/modules/webhook.disabled/default.nix index 3d7a654..a9b472f 100644 --- a/hosts/wolumonde/modules/webhook.disabled/default.nix +++ b/hosts/wolumonde/modules/webhook.disabled/default.nix @@ -1,6 +1,8 @@ -{ config, tlib, ... }: let +{ config, tlib, ... }: +let domain = "webhook.gaze.systems"; -in { +in +{ imports = tlib.importFolder ./.; services.webhook = { @@ -15,7 +17,7 @@ in { group = "nginx"; }; - security.acme.certs."gaze.systems".extraDomainNames = [domain]; + security.acme.certs."gaze.systems".extraDomainNames = [ domain ]; services.nginx.virtualHosts.${domain} = { useACMEHost = "gaze.systems"; forceSSL = true; diff --git a/hosts/wolumonde/modules/webhook.disabled/deploy-wolumonde.nix b/hosts/wolumonde/modules/webhook.disabled/deploy-wolumonde.nix index a36ffee..433a02f 100644 --- a/hosts/wolumonde/modules/webhook.disabled/deploy-wolumonde.nix +++ b/hosts/wolumonde/modules/webhook.disabled/deploy-wolumonde.nix @@ -1,20 +1,21 @@ -{ pkgs, ... }: let +{ pkgs, ... }: +let port = toString 9000; -in { +in +{ services.webhook.hooks."deploy-wolumonde" = { execute-command = "${pkgs.curl}/bin/curl"; - pass-arguments-to-command = - builtins.map - (n: { - source = "string"; - name = n; - }) - [ "http://higashi:${port}/hooks/deploy-wolumonde" ]; + pass-arguments-to-command = builtins.map (n: { + source = "string"; + name = n; + }) [ "http://higashi:${port}/hooks/deploy-wolumonde" ]; }; - services.headscale.acl.rules = [{ - proto = "tcp"; - src = ["wolumonde"]; - dst = ["higashi:${port}"]; - }]; + services.headscale.acl.rules = [ + { + proto = "tcp"; + src = [ "wolumonde" ]; + dst = [ "higashi:${port}" ]; + } + ]; } diff --git a/users/dusk@devel.mobi/default.nix b/users/dusk@devel.mobi/default.nix index a8a38f7..12073ca 100644 --- a/users/dusk@devel.mobi/default.nix +++ b/users/dusk@devel.mobi/default.nix @@ -70,7 +70,10 @@ in enable = true; controlServer = "https://vpn.gaze.systems"; authKeyFile = config.age.secrets.tailscaleAuthKey.path; - extraUpFlags = [ "--advertise-exit-node=true" "--hostname=dusk-devel-mobi" ]; + extraUpFlags = [ + "--advertise-exit-node=true" + "--hostname=dusk-devel-mobi" + ]; }; programs = { diff --git a/users/modules/ssh/default.nix b/users/modules/ssh/default.nix index 7f49c57..e7c46af 100644 --- a/users/modules/ssh/default.nix +++ b/users/modules/ssh/default.nix @@ -3,16 +3,16 @@ enable = true; enableDefaultConfig = false; matchBlocks."*" = { - forwardAgent = false; - serverAliveInterval = 0; - serverAliveCountMax = 3; - compression = true; - hashKnownHosts = true; - addKeysToAgent = "yes"; - userKnownHostsFile = "~/.ssh/known_hosts"; - controlMaster = "no"; - controlPath = "~/.ssh/master-%r@%n:%p"; - controlPersist = "no"; + forwardAgent = false; + serverAliveInterval = 0; + serverAliveCountMax = 3; + compression = true; + hashKnownHosts = true; + addKeysToAgent = "yes"; + userKnownHostsFile = "~/.ssh/known_hosts"; + controlMaster = "no"; + controlPath = "~/.ssh/master-%r@%n:%p"; + controlPersist = "no"; }; # Only needed for darcs hub # extraConfig = ''