diff --git a/common/base.nix b/common/base.nix new file mode 100644 index 0000000..c3cbcd3 --- /dev/null +++ b/common/base.nix @@ -0,0 +1,43 @@ +{ modulesPath, lib, pkgs, commonArgs, ... }: +{ + imports = [ + (modulesPath + "/installer/scan/not-detected.nix") + (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.loader.grub = { + efiSupport = true; + efiInstallAsRemovable = true; + }; + + services.openssh.enable = true; + + nix.extraOptions = '' + experimental-features = nix-command flakes ca-derivations + warn-dirty = false + keep-outputs = false + ''; + + environment.systemPackages = map lib.lowPrio [ + pkgs.curl + pkgs.gitMinimal + ]; + + users.users.tangler = { + extraGroups = [ "networkmanager" "wheel" ]; + openssh.authorizedKeys.keys = commonArgs.sshKeys; + isNormalUser = true; + }; + + security.sudo.extraRules = [ + { + users = [ "tangler" ]; + commands = [ + { + command = "ALL"; + options = [ "NOPASSWD" ]; + } + ]; + } + ]; +} diff --git a/common/tailscale.nix b/common/tailscale.nix new file mode 100644 index 0000000..d886410 --- /dev/null +++ b/common/tailscale.nix @@ -0,0 +1,3 @@ +{ + services.tailscale.enable = true; +} diff --git a/flake.nix b/flake.nix index 66e1615..0c4631b 100644 --- a/flake.nix +++ b/flake.nix @@ -20,38 +20,34 @@ outputs = { nixpkgs, disko, colmena, nixery-flake, tangled, atlogin, ... }: let + lib = nixpkgs.lib; system = "x86_64-linux"; commonArgs = import ./common/ssh.nix; - # Helper function to create nixosConfiguration + baseModules = [ + disko.nixosModules.disko + ./common/base.nix + ./common/tailscale.nix + ]; + mkHost = hostname: extraModules: - nixpkgs.lib.nixosSystem { + lib.nixosSystem { inherit system; specialArgs = { inherit commonArgs; }; - modules = [ - disko.nixosModules.disko - ./hosts/${hostname}/configuration.nix - ] ++ extraModules; + modules = baseModules ++ [ ./hosts/${hostname}/configuration.nix ] ++ extraModules; }; - # Helper function to create colmena host - mkColmenaHost = hostname: targetHost: targetPort: extraModules: - { - deployment = { - inherit targetHost; - inherit targetPort; - targetUser = "tangler"; - buildOnTarget = true; - }; - nixpkgs.system = system; - time.timeZone = "Europe/Helsinki"; - imports = [ - disko.nixosModules.disko - ./hosts/${hostname}/configuration.nix - ] ++ extraModules; + mkColmenaHost = hostname: targetHost: targetPort: extraModules: { + deployment = { + inherit targetHost targetPort; + targetUser = "tangler"; + buildOnTarget = true; }; + nixpkgs.system = system; + time.timeZone = "Europe/Helsinki"; + imports = baseModules ++ [ ./hosts/${hostname}/configuration.nix ] ++ extraModules; + }; - # Host configurations hosts = { appview = { modules = [ @@ -61,6 +57,7 @@ ./hosts/appview/services/litestream.nix ]; target = "95.111.205.38"; + port = 2222; }; pds = { @@ -116,39 +113,25 @@ }; in { - # nixos-anywhere and nixos-rebuild use these - nixosConfigurations = { - appview = mkHost "appview" hosts.appview.modules; - pds = mkHost "pds" hosts.pds.modules; - nixery = mkHost "nixery" hosts.nixery.modules; - spindle = mkHost "spindle" hosts.spindle.modules; - knot1 = mkHost "knot1" hosts.knot1.modules; - mirror = mkHost "mirror" hosts.mirror.modules; - }; + nixosConfigurations = lib.mapAttrs + (name: host: mkHost name host.modules) + hosts; - # colmena uses this - colmenaHive = colmena.lib.makeHive { - meta = { - nixpkgs = nixpkgs.legacyPackages.${system}; - specialArgs = { - inherit commonArgs; - nixery-pkgs = import nixery-flake.outPath { - pkgs = import nixpkgs { inherit system; }; + colmenaHive = colmena.lib.makeHive ( + { + meta = { + nixpkgs = nixpkgs.legacyPackages.${system}; + specialArgs = { + inherit commonArgs; + nixery-pkgs = import nixery-flake.outPath { + pkgs = import nixpkgs { inherit system; }; + }; + tangled-pkgs = tangled.packages.x86_64-linux; }; - tangled-pkgs = tangled.packages.x86_64-linux; }; - }; - - defaults = { pkgs, ... }: { - environment.systemPackages = [ pkgs.curl ]; - }; - - appview = mkColmenaHost "appview" hosts.appview.target 2222 hosts.appview.modules; - pds = mkColmenaHost "pds" hosts.pds.target 22 hosts.pds.modules; - nixery = mkColmenaHost "nixery" hosts.nixery.target 22 hosts.nixery.modules; - spindle = mkColmenaHost "spindle" hosts.spindle.target 22 hosts.spindle.modules; - knot1 = mkColmenaHost "knot1" hosts.knot1.target 22 hosts.knot1.modules; - mirror = mkColmenaHost "mirror" hosts.mirror.target 22 hosts.mirror.modules; - }; + } // lib.mapAttrs + (name: host: mkColmenaHost name host.target (host.port or 22) host.modules) + hosts + ); }; } diff --git a/hosts/appview/configuration.nix b/hosts/appview/configuration.nix index 1363c7b..bfee328 100644 --- a/hosts/appview/configuration.nix +++ b/hosts/appview/configuration.nix @@ -1,62 +1,7 @@ -{ modulesPath -, lib -, pkgs -, ... -} @ args: +{ ... }: { - imports = [ - (modulesPath + "/installer/scan/not-detected.nix") - (modulesPath + "/profiles/qemu-guest.nix") - ./disk-config.nix - ]; - boot.loader.grub = { - # no need to set devices, disko will add all devices that have a EF02 partition to the list already - # devices = [ ]; - efiSupport = true; - efiInstallAsRemovable = true; - }; - + imports = [ ./disk-config.nix ]; networking.hostName = "appview-arn"; - services = { - openssh.enable = true; - openssh.ports = [2222]; - }; - - # networking.extraHosts = '' - # 85.9.211.103 knot1.tangled.sh - # ''; - - - nix = { - extraOptions = '' - experimental-features = nix-command flakes ca-derivations - warn-dirty = false - keep-outputs = false - ''; - }; - - environment.systemPackages = map lib.lowPrio [ - pkgs.curl - pkgs.gitMinimal - ]; - - users.users.tangler = { - extraGroups = [ "networkmanager" "wheel" ]; - openssh.authorizedKeys.keys = args.commonArgs.sshKeys; - isNormalUser = true; - }; - - security.sudo.extraRules = [ - { - users = [ "tangler" ]; - commands = [ - { - command = "ALL"; - options = [ "NOPASSWD" ]; - } - ]; - } - ]; - + services.openssh.ports = [ 2222 ]; system.stateVersion = "25.05"; } diff --git a/hosts/appview/services/nginx.nix b/hosts/appview/services/nginx.nix index 57deb5e..20a7266 100644 --- a/hosts/appview/services/nginx.nix +++ b/hosts/appview/services/nginx.nix @@ -17,6 +17,7 @@ ~*CCBot 1; ~*anthropic-ai 1; ~*Claude-Web 1; + ~*meta-externalagent 1; } ''; diff --git a/hosts/knot1/configuration.nix b/hosts/knot1/configuration.nix index aa19380..3ec7dbd 100644 --- a/hosts/knot1/configuration.nix +++ b/hosts/knot1/configuration.nix @@ -1,45 +1,10 @@ -{ modulesPath -, lib -, pkgs -, ... -} @ args: +{ ... }: { - imports = [ - (modulesPath + "/installer/scan/not-detected.nix") - (modulesPath + "/profiles/qemu-guest.nix") - ./disk-config.nix - ]; - boot.loader.grub = { - # no need to set devices, disko will add all devices that have a EF02 partition to the list already - # devices = [ ]; - efiSupport = true; - efiInstallAsRemovable = true; - }; + imports = [ ./disk-config.nix ]; networking.hostName = "knot1-ams"; - services = { - openssh.enable = true; - }; - - - nix = { - extraOptions = '' - experimental-features = nix-command flakes ca-derivations - warn-dirty = false - keep-outputs = false - ''; - }; - - environment.systemPackages = map lib.lowPrio [ - pkgs.curl - pkgs.gitMinimal - ]; - users.users.tangler = { - extraGroups = [ "networkmanager" "wheel" "docker" ]; - openssh.authorizedKeys.keys = args.commonArgs.sshKeys; - isNormalUser = true; - }; + users.users.tangler.extraGroups = [ "docker" ]; users.users.git = { home = "/home/git"; @@ -50,17 +15,5 @@ users.groups.git = {}; - security.sudo.extraRules = [ - { - users = [ "tangler" ]; - commands = [ - { - command = "ALL"; - options = [ "NOPASSWD" ]; - } - ]; - } - ]; - system.stateVersion = "25.05"; } diff --git a/hosts/knot1/services/knot.nix b/hosts/knot1/services/knot.nix index 7954ce7..c149674 100644 --- a/hosts/knot1/services/knot.nix +++ b/hosts/knot1/services/knot.nix @@ -5,7 +5,7 @@ stateDir = "/home/git"; server = { listenAddr = "127.0.0.1:5555"; - owner = "did:plc:hwevmowznbiukdf6uk5dwrrq"; + owner = "did:plc:wshs7t2adsemcrrd4snkeqli"; hostname = "knot1.tangled.sh"; }; }; diff --git a/hosts/mirror/configuration.nix b/hosts/mirror/configuration.nix index e0a05c2..33f1740 100644 --- a/hosts/mirror/configuration.nix +++ b/hosts/mirror/configuration.nix @@ -1,54 +1,7 @@ -{ modulesPath -, lib -, pkgs -, ... -} @ args: +{ ... }: { - imports = [ - (modulesPath + "/installer/scan/not-detected.nix") - (modulesPath + "/profiles/qemu-guest.nix") - ./disk-config.nix - ]; - - boot.loader.grub = { - efiSupport = true; - efiInstallAsRemovable = true; - }; - + imports = [ ./disk-config.nix ]; networking.hostName = "mirror"; - - services.openssh.enable = true; - - nix = { - extraOptions = '' - experimental-features = nix-command flakes ca-derivations - warn-dirty = false - keep-outputs = false - ''; - }; - - environment.systemPackages = map lib.lowPrio [ - pkgs.curl - pkgs.gitMinimal - ]; - - users.users.tangler = { - extraGroups = [ "networkmanager" "wheel" ]; - openssh.authorizedKeys.keys = args.commonArgs.sshKeys; - isNormalUser = true; - }; - - security.sudo.extraRules = [ - { - users = [ "tangler" ]; - commands = [ - { - command = "ALL"; - options = [ "NOPASSWD" ]; - } - ]; - } - ]; - + networking.enableIPv6 = false; system.stateVersion = "25.05"; } diff --git a/hosts/nixery/configuration.nix b/hosts/nixery/configuration.nix index aad7c07..f553d21 100644 --- a/hosts/nixery/configuration.nix +++ b/hosts/nixery/configuration.nix @@ -1,77 +1,28 @@ -{ modulesPath -, lib -, pkgs -, ... -} @ args: +{ ... }: { - imports = [ - (modulesPath + "/installer/scan/not-detected.nix") - (modulesPath + "/profiles/qemu-guest.nix") - ./disk-config.nix - ]; - boot.loader.grub = { - # no need to set devices, disko will add all devices that have a EF02 partition to the list already - # devices = [ ]; - efiSupport = true; - efiInstallAsRemovable = true; - }; + imports = [ ./disk-config.nix ]; networking.hostName = "nixery"; - services = { - openssh.enable = true; - tangled.spindle = { - enable = true; - server = { - owner = "did:plc:wshs7t2adsemcrrd4snkeqli"; # @tangled.sh - hostname = "spindle.tangled.sh"; - listenAddr = "127.0.0.1:6555"; - queueSize = 100; - maxJobCount = 2; - secrets = { - provider = "openbao"; - }; - }; - pipelines = { - workflowTimeout = "15m"; - }; - }; - }; + + users.users.tangler.extraGroups = [ "docker" ]; virtualisation.docker = { enable = true; logDriver = "json-file"; }; - nix = { - extraOptions = '' - experimental-features = nix-command flakes ca-derivations - warn-dirty = false - keep-outputs = false - ''; - }; - - environment.systemPackages = map lib.lowPrio [ - pkgs.curl - pkgs.gitMinimal - ]; - - users.users.tangler = { - extraGroups = [ "networkmanager" "wheel" "docker" ]; - openssh.authorizedKeys.keys = args.commonArgs.sshKeys; - isNormalUser = true; + services.tangled.spindle = { + enable = true; + server = { + owner = "did:plc:wshs7t2adsemcrrd4snkeqli"; # @tangled.sh + hostname = "spindle.tangled.sh"; + listenAddr = "127.0.0.1:6555"; + queueSize = 100; + maxJobCount = 2; + secrets.provider = "openbao"; + }; + pipelines.workflowTimeout = "15m"; }; - security.sudo.extraRules = [ - { - users = [ "tangler" ]; - commands = [ - { - command = "ALL"; - options = [ "NOPASSWD" ]; - } - ]; - } - ]; - system.stateVersion = "25.05"; } diff --git a/hosts/pds/configuration.nix b/hosts/pds/configuration.nix index ea6a7fd..f51723c 100644 --- a/hosts/pds/configuration.nix +++ b/hosts/pds/configuration.nix @@ -1,57 +1,6 @@ -{ modulesPath -, lib -, pkgs -, ... -} @ args: +{ ... }: { - imports = [ - (modulesPath + "/installer/scan/not-detected.nix") - (modulesPath + "/profiles/qemu-guest.nix") - ./disk-config.nix - ]; - boot.loader.grub = { - # no need to set devices, disko will add all devices that have a EF02 partition to the list already - # devices = [ ]; - efiSupport = true; - efiInstallAsRemovable = true; - }; - + imports = [ ./disk-config.nix ]; networking.hostName = "pds"; - services = { - openssh.enable = true; - }; - - - nix = { - extraOptions = '' - experimental-features = nix-command flakes ca-derivations - warn-dirty = false - keep-outputs = false - ''; - }; - - environment.systemPackages = map lib.lowPrio [ - pkgs.curl - pkgs.gitMinimal - ]; - - users.users.tangler = { - extraGroups = [ "networkmanager" "wheel" ]; - openssh.authorizedKeys.keys = args.commonArgs.sshKeys; - isNormalUser = true; - }; - - security.sudo.extraRules = [ - { - users = [ "tangler" ]; - commands = [ - { - command = "ALL"; - options = [ "NOPASSWD" ]; - } - ]; - } - ]; - system.stateVersion = "25.05"; } diff --git a/hosts/spindle/configuration.nix b/hosts/spindle/configuration.nix index 103195b..f2005ac 100644 --- a/hosts/spindle/configuration.nix +++ b/hosts/spindle/configuration.nix @@ -1,57 +1,7 @@ -{ modulesPath -, lib -, pkgs -, ... -} @ args: +{ ... }: { - imports = [ - (modulesPath + "/installer/scan/not-detected.nix") - (modulesPath + "/profiles/qemu-guest.nix") - ./disk-config.nix - ]; - boot.loader.grub = { - # no need to set devices, disko will add all devices that have a EF02 partition to the list already - # devices = [ ]; - efiSupport = true; - efiInstallAsRemovable = true; - }; - + imports = [ ./disk-config.nix ]; networking.hostName = "spindle-waw"; - services = { - openssh.enable = true; - }; - - - nix = { - extraOptions = '' - experimental-features = nix-command flakes ca-derivations - warn-dirty = false - keep-outputs = false - ''; - }; - - environment.systemPackages = map lib.lowPrio [ - pkgs.curl - pkgs.gitMinimal - ]; - - users.users.tangler = { - extraGroups = [ "networkmanager" "wheel" "docker" ]; - openssh.authorizedKeys.keys = args.commonArgs.sshKeys; - isNormalUser = true; - }; - - security.sudo.extraRules = [ - { - users = [ "tangler" ]; - commands = [ - { - command = "ALL"; - options = [ "NOPASSWD" ]; - } - ]; - } - ]; - + users.users.tangler.extraGroups = [ "docker" ]; system.stateVersion = "25.05"; }