From 118c19c872bc379208b27a8245288efb6a84cef7 Mon Sep 17 00:00:00 2001 From: Anirudh Oppiliappan Date: Wed, 23 Jul 2025 13:26:52 +0300 Subject: [PATCH] setup pds host Signed-off-by: Anirudh Oppiliappan --- .gitignore | 1 + flake.lock | 12 ++++---- flake.nix | 28 +++++++++++++++++- hosts/pds/configuration.nix | 57 ++++++++++++++++++++++++++++++++++++ hosts/pds/disk-config.nix | 56 +++++++++++++++++++++++++++++++++++ hosts/pds/services/nginx.nix | 35 ++++++++++++++++++++++ hosts/pds/services/pds.nix | 13 ++++++++ 7 files changed, 195 insertions(+), 7 deletions(-) create mode 100644 .gitignore create mode 100644 hosts/pds/configuration.nix create mode 100644 hosts/pds/disk-config.nix create mode 100644 hosts/pds/services/nginx.nix create mode 100644 hosts/pds/services/pds.nix diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..4c49bd7 --- /dev/null +++ b/.gitignore @@ -0,0 +1 @@ +.env diff --git a/flake.lock b/flake.lock index 25e3c77..517d622 100644 --- a/flake.lock +++ b/flake.lock @@ -288,16 +288,16 @@ "sqlite-lib-src": "sqlite-lib-src" }, "locked": { - "lastModified": 1751974352, - "narHash": "sha256-VUvvyMpgpWNuL+TezoT9knv6sO5B5yzJSdMHZ3BNlKE=", - "ref": "push-ksrsmmytwuul", - "rev": "f278504076c0178397ac733eeeb095ba7ad76550", - "revCount": 887, + "lastModified": 1752245231, + "narHash": "sha256-paYg0gHQCN2poSo6EgNDqRKG0NV3kUcAyTgeMP2TkXM=", + "ref": "master", + "rev": "ac5359ba6ccb77f8aef3d32483fa1e0e58f46985", + "revCount": 923, "type": "git", "url": "https://tangled.sh/@tangled.sh/core" }, "original": { - "ref": "push-ksrsmmytwuul", + "ref": "master", "type": "git", "url": "https://tangled.sh/@tangled.sh/core" } diff --git a/flake.nix b/flake.nix index 93aa1c3..35b58b0 100644 --- a/flake.nix +++ b/flake.nix @@ -2,7 +2,7 @@ description = "nix infra for tangled"; inputs = { nixpkgs.url = "github:nixos/nixpkgs?ref=nixos-unstable"; - tangled.url = "git+https://tangled.sh/@tangled.sh/core?ref=push-ksrsmmytwuul"; + tangled.url = "git+https://tangled.sh/@tangled.sh/core?ref=master"; colmena.url = "github:zhaofengli/colmena/release-0.4.x"; disko = { url = "github:nix-community/disko"; @@ -27,6 +27,14 @@ ./hosts/nixery/configuration.nix ]; }; + nixosConfigurations.pds = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + disko.nixosModules.disko + ./hosts/pds/configuration.nix + ]; + }; + colmenaHive = colmena.lib.makeHive { meta = { nixpkgs = nixpkgs.legacyPackages.x86_64-linux; @@ -43,6 +51,24 @@ pkgs.curl ]; }; + pds = { pkgs, ... }: { + deployment = { + targetHost = "tngl.sh"; + targetPort = 22; + targetUser = "tangler"; + buildOnTarget = true; + }; + nixpkgs.system = "x86_64-linux"; + + imports = [ + disko.nixosModules.disko + ./hosts/pds/configuration.nix + ./hosts/pds/services/nginx.nix + ./hosts/pds/services/pds.nix + ]; + time.timeZone = "Europe/Helsinki"; + }; + nixery = { pkgs, ... }: { deployment = { targetHost = "nixery.tangled.sh"; diff --git a/hosts/pds/configuration.nix b/hosts/pds/configuration.nix new file mode 100644 index 0000000..ea6a7fd --- /dev/null +++ b/hosts/pds/configuration.nix @@ -0,0 +1,57 @@ +{ modulesPath +, lib +, pkgs +, ... +} @ args: +{ + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + (modulesPath + "/profiles/qemu-guest.nix") + ./disk-config.nix + ]; + boot.loader.grub = { + # no need to set devices, disko will add all devices that have a EF02 partition to the list already + # devices = [ ]; + efiSupport = true; + efiInstallAsRemovable = true; + }; + + networking.hostName = "pds"; + services = { + openssh.enable = true; + }; + + + nix = { + extraOptions = '' + experimental-features = nix-command flakes ca-derivations + warn-dirty = false + keep-outputs = false + ''; + }; + + environment.systemPackages = map lib.lowPrio [ + pkgs.curl + pkgs.gitMinimal + ]; + + users.users.tangler = { + extraGroups = [ "networkmanager" "wheel" ]; + openssh.authorizedKeys.keys = args.commonArgs.sshKeys; + isNormalUser = true; + }; + + security.sudo.extraRules = [ + { + users = [ "tangler" ]; + commands = [ + { + command = "ALL"; + options = [ "NOPASSWD" ]; + } + ]; + } + ]; + + system.stateVersion = "25.05"; +} diff --git a/hosts/pds/disk-config.nix b/hosts/pds/disk-config.nix new file mode 100644 index 0000000..88e17e5 --- /dev/null +++ b/hosts/pds/disk-config.nix @@ -0,0 +1,56 @@ +# Example to create a bios compatible gpt partition +{ lib, ... }: +{ + disko.devices = { + disk.disk1 = { + device = lib.mkDefault "/dev/vda"; + type = "disk"; + content = { + type = "gpt"; + partitions = { + boot = { + name = "boot"; + size = "1M"; + type = "EF02"; + }; + esp = { + name = "ESP"; + size = "500M"; + type = "EF00"; + content = { + type = "filesystem"; + format = "vfat"; + mountpoint = "/boot"; + }; + }; + root = { + name = "root"; + size = "100%"; + content = { + type = "lvm_pv"; + vg = "pool"; + }; + }; + }; + }; + }; + lvm_vg = { + pool = { + type = "lvm_vg"; + lvs = { + root = { + size = "100%FREE"; + content = { + type = "filesystem"; + format = "ext4"; + mountpoint = "/"; + mountOptions = [ + "defaults" + ]; + }; + }; + }; + }; + }; + }; +} diff --git a/hosts/pds/services/nginx.nix b/hosts/pds/services/nginx.nix new file mode 100644 index 0000000..1680fea --- /dev/null +++ b/hosts/pds/services/nginx.nix @@ -0,0 +1,35 @@ +{ + services.nginx = { + enable = true; + virtualHosts."tngl.sh" = { + forceSSL = true; + enableACME = true; + + # match exact root + locations."= /" = { + extraConfig = '' + return 301 https://tangled.sh; + ''; + }; + + # match all other paths + locations."/" = { + proxyPass = "http://localhost:3000"; + extraConfig = '' + proxy_set_header Host $host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection "upgrade"; + ''; + }; + }; + }; + + security.acme = { + acceptTerms = true; + defaults.email = "anirudh@tangled.sh"; + }; + networking.firewall.allowedTCPPorts = [ 80 443 ]; +} diff --git a/hosts/pds/services/pds.nix b/hosts/pds/services/pds.nix new file mode 100644 index 0000000..ee2a572 --- /dev/null +++ b/hosts/pds/services/pds.nix @@ -0,0 +1,13 @@ +{ + services.pds = { + enable = true; + settings = { + PDS_HOSTNAME = "tngl.sh"; + PDS_PORT = 3000; + PDS_HOST = "127.0.0.1"; + }; + environmentFiles = [ + "/var/secrets/pds.env" + ]; + }; +} -- 2.51.2