From 81cfd091fd410706000b501bcddaf891a8120e89 Mon Sep 17 00:00:00 2001 From: Seongmin Lee Date: Tue, 15 Sep 2026 20:44:23 +0900 Subject: [PATCH] add mock PDS Signed-off-by: Seongmin Lee --- flake.lock | 35 +++++++++++++++- flake.nix | 6 ++- hosts/mock-eu-1/services/mock-hydrant.nix | 3 ++ hosts/mock-eu-1/services/mock-pds.nix | 14 +++++++ hosts/mock-eu-1/services/nginx.nix | 50 +++++++++++++++++++++++ 5 files changed, 106 insertions(+), 2 deletions(-) create mode 100644 hosts/mock-eu-1/services/mock-hydrant.nix create mode 100644 hosts/mock-eu-1/services/mock-pds.nix create mode 100644 hosts/mock-eu-1/services/nginx.nix diff --git a/flake.lock b/flake.lock index 4a45c81..bffb083 100644 --- a/flake.lock +++ b/flake.lock @@ -804,6 +804,19 @@ "type": "github" } }, + "nixpkgs_7": { + "locked": { + "lastModified": 1789370336, + "narHash": "sha256-obwZbWHP7htCIoq2Z0g/uTMcEgN6yqcMNIcOMe6P2qI=", + "rev": "c7def046b9a883d46974757852106483d741586f", + "type": "tarball", + "url": "https://releases.nixos.org/nixpkgs/nixpkgs-26.11pre1073483.c7def046b9a8/nixexprs.tar.xz" + }, + "original": { + "type": "tarball", + "url": "https://channels.nixos.org/nixpkgs-unstable/nixexprs.tar.xz" + } + }, "root": { "inputs": { "asn-alibaba": "asn-alibaba", @@ -820,7 +833,8 @@ "tangled": "tangled", "tangled-lexicons": "tangled-lexicons", "tangled-ozone": "tangled-ozone", - "tangled-svfe": "tangled-svfe" + "tangled-svfe": "tangled-svfe", + "tranquil-pds": "tranquil-pds" } }, "rust-analyzer-src": { @@ -1108,6 +1122,25 @@ "type": "git", "url": "https://tangled.org/tangled.org/core" } + }, + "tranquil-pds": { + "inputs": { + "nixpkgs": "nixpkgs_7" + }, + "locked": { + "lastModified": 1789456344, + "narHash": "sha256-3q/CtOUgaaSWy1rDYhmMYN2J1oJVryWYq5OJ2PQcuD0=", + "ref": "liar", + "rev": "38b0519716ee60f042427fc456d4288b3dfdf09d", + "revCount": 494, + "type": "git", + "url": "https://tangled.org/boltless.me/tranquil-pds" + }, + "original": { + "ref": "liar", + "type": "git", + "url": "https://tangled.org/boltless.me/tranquil-pds" + } } }, "root": "root", diff --git a/flake.nix b/flake.nix index 3e0ae75..ea4411e 100644 --- a/flake.nix +++ b/flake.nix @@ -18,6 +18,7 @@ flake = false; }; tangled-ozone.url = "git+https://tangled.org/oppi.li/ozone?ref=customized"; + tranquil-pds.url = "git+https://tangled.org/boltless.me/tranquil-pds?ref=liar"; colmena.url = "github:zhaofengli/colmena/release-0.4.x"; cloudflare-ips-v4 = { url = "file+https://www.cloudflare.com/ips-v4"; @@ -69,6 +70,7 @@ hydrant-fork, atlogin, tangled-ozone, + tranquil-pds, ... }: let lib = nixpkgs.lib; @@ -138,7 +140,9 @@ mock-eu-1 = { modules = [ ./modules/hyd-node/hydrant.nix - ./modules/hyd-node/nginx.nix + tranquil-pds.nixosModules.tranquil-pds + ./hosts/mock-eu-1/services/mock-pds.nix + ./hosts/mock-eu-1/services/nginx.nix ]; specialArgs.hydrant-src = hydrant-fork; target = "35.228.210.244"; diff --git a/hosts/mock-eu-1/services/mock-hydrant.nix b/hosts/mock-eu-1/services/mock-hydrant.nix new file mode 100644 index 0000000..a1a108e --- /dev/null +++ b/hosts/mock-eu-1/services/mock-hydrant.nix @@ -0,0 +1,3 @@ +{ +# run mock hydrant (hydrant that blindly trusts specific PDS) +} diff --git a/hosts/mock-eu-1/services/mock-pds.nix b/hosts/mock-eu-1/services/mock-pds.nix new file mode 100644 index 0000000..5d1fb5e --- /dev/null +++ b/hosts/mock-eu-1/services/mock-pds.nix @@ -0,0 +1,14 @@ +{...}: { + services.tranquil-pds = { + enable = true; + database.createLocally = true; + # JWT_SECRET, DPOP_SECRET, MASTER_KEY, MOCK_ACCOUNT_PASSWORD. Created + # out-of-band; nothing here puts them in the world-readable nix store. + environmentFiles = ["/etc/secrets/tranquil-pds.env"]; + settings.server = { + hostname = "pds.mock.tangled.org"; + invite_code_required = false; + disable_account_verification_gate = true; + }; + }; +} diff --git a/hosts/mock-eu-1/services/nginx.nix b/hosts/mock-eu-1/services/nginx.nix new file mode 100644 index 0000000..73f532d --- /dev/null +++ b/hosts/mock-eu-1/services/nginx.nix @@ -0,0 +1,50 @@ +{...}: { + services.nginx = { + enable = true; + virtualHosts = { + "pds.mock.tangled.org" = { + forceSSL = true; + enableACME = true; + locations."/" = { + proxyPass = "http://127.0.0.1:3000"; + proxyWebsockets = true; + extraConfig = '' + # subscribeRepos is a long-lived stream; the 60s default kills it. + proxy_read_timeout 86400; + proxy_send_timeout 86400; + client_max_body_size 0; + ''; + }; + }; + + hydrant = { + default = true; + # Opening 80/443 for ACME would otherwise make this a public endpoint. + # It stays reachable over the tailnet only, as before. + extraConfig = '' + allow 100.64.0.0/10; + allow fd7a:115c:a1e0::/48; + deny all; + ''; + locations."/" = { + proxyPass = "http://127.0.0.1:13010"; + proxyWebsockets = true; + extraConfig = '' + proxy_read_timeout 86400; + proxy_send_timeout 86400; + ''; + }; + }; + }; + }; + + security.acme = { + acceptTerms = true; + defaults.email = "seongmin@tangled.org"; + }; + + networking.firewall.allowedTCPPorts = [80 443]; + # Redundant while 80 is open globally above; kept so the tailnet path + # survives if the public ports ever go away. + networking.firewall.interfaces."tailscale0".allowedTCPPorts = [80]; +} -- 2.51.2