diff options
Diffstat (limited to '')
| -rw-r--r-- | modules/by-name/ba/back/module.nix | 121 | ||||
| -rw-r--r-- | modules/by-name/co/constants/module.nix | 43 | ||||
| -rw-r--r-- | modules/by-name/et/etesync/secret_file.age | 17 | ||||
| -rw-r--r-- | modules/by-name/ni/nix-sync/hosts.nix | 48 | ||||
| -rw-r--r-- | modules/by-name/ni/nix-sync/module.nix | 70 | ||||
| -rw-r--r-- | modules/by-name/pe/peertube/secrets/general.age | 15 | ||||
| -rw-r--r-- | modules/by-name/pe/peertube/secrets/smtp.age | 16 | ||||
| -rw-r--r-- | modules/by-name/re/redlib/module.nix | 44 | ||||
| -rw-r--r-- | modules/vhack/co/coredump/module.nix (renamed from modules/by-name/co/coredump/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/dh/dhcpcd/module.nix (renamed from modules/by-name/dh/dhcpcd/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/di/disko/module.nix (renamed from modules/by-name/di/disko/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/et/etesync/module.nix (renamed from modules/by-name/et/etesync/module.nix) | 26 | ||||
| -rw-r--r-- | modules/vhack/fa/fail2ban/module.nix (renamed from modules/by-name/fa/fail2ban/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/gi/git-server/css.nix (renamed from modules/by-name/gi/git-server/css.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/gi/git-server/module.nix (renamed from modules/by-name/gi/git-server/module.nix) | 11 | ||||
| -rw-r--r-- | modules/vhack/im/impermanence/module.nix (renamed from modules/by-name/im/impermanence/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/ng/nginx/module.nix (renamed from modules/by-name/ng/nginx/module.nix) | 57 | ||||
| -rw-r--r-- | modules/vhack/ni/nix-sync/internal_module.nix (renamed from modules/by-name/ni/nix-sync/internal_module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/ns/nscd/module.nix (renamed from modules/by-name/ns/nscd/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/oo/oomd/module.nix (renamed from modules/by-name/oo/oomd/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/op/openssh/module.nix (renamed from modules/by-name/op/openssh/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/pe/peertube/module.nix (renamed from modules/by-name/pe/peertube/module.nix) | 29 | ||||
| -rw-r--r-- | modules/vhack/po/postgresql/module.nix (renamed from modules/by-name/po/postgresql/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/re/resolvconf/module.nix (renamed from modules/by-name/re/resolvconf/module.nix) | 0 | ||||
| -rw-r--r-- | modules/vhack/ru/rust-motd/module.nix (renamed from modules/by-name/ru/rust-motd/module.nix) | 32 | ||||
| -rw-r--r-- | modules/vhack/us/users/module.nix (renamed from modules/by-name/us/users/module.nix) | 30 |
26 files changed, 104 insertions, 455 deletions
diff --git a/modules/by-name/ba/back/module.nix b/modules/by-name/ba/back/module.nix deleted file mode 100644 index 520acdb..0000000 --- a/modules/by-name/ba/back/module.nix +++ /dev/null @@ -1,121 +0,0 @@ -{ - config, - lib, - vhackPackages, - pkgs, - ... -}: let - cfg = config.vhack.back; - - mkConfigFile = repoPath: domain: - (pkgs.formats.json {}).generate "config.json" - { - inherit (cfg) source_code_repository_url; - repository_path = repoPath; - root_url = "https://${domain}"; - }; - - mkUnit = repoPath: port: domain: { - description = "Back service for ${repoPath}"; - wants = ["network-online.target"]; - after = ["network-online.target"]; - wantedBy = ["default.target"]; - - environment = { - ROCKET_PORT = builtins.toString port; - }; - - serviceConfig = { - ExecStart = "${lib.getExe vhackPackages.back} ${mkConfigFile repoPath domain}"; - - # Ensure that the service can read the repository - # FIXME(@bpeetz): This has the implied assumption, that all the exposed git - # repositories are readable for the git group. This should not be necessary. <2024-12-23> - User = "git"; - Group = "git"; - - DynamicUser = true; - Restart = "always"; - - # Sandboxing - ProtectSystem = "strict"; - ProtectHome = true; - PrivateTmp = true; - PrivateDevices = true; - ProtectHostname = true; - ProtectClock = true; - ProtectKernelTunables = true; - ProtectKernelModules = true; - ProtectKernelLogs = true; - ProtectControlGroups = true; - RestrictAddressFamilies = ["AF_UNIX" "AF_INET" "AF_INET6"]; - RestrictNamespaces = true; - LockPersonality = true; - MemoryDenyWriteExecute = true; - RestrictRealtime = true; - RestrictSUIDSGID = true; - RemoveIPC = true; - PrivateMounts = true; - # System Call Filtering - SystemCallArchitectures = "native"; - SystemCallFilter = ["~@cpu-emulation @debug @keyring @mount @obsolete @privileged @setuid"]; - }; - }; - - mkVirtalHost = port: { - locations."/".proxyPass = "http://127.0.0.1:${builtins.toString port}"; - - enableACME = true; - forceSSL = true; - }; - - services = - lib.mapAttrs' (gitPath: config: { - name = builtins.replaceStrings ["/"] ["_"] "back-${config.domain}"; - value = mkUnit gitPath config.port config.domain; - }) - cfg.repositories; - - virtualHosts = - lib.mapAttrs' (gitPath: config: { - name = config.domain; - value = mkVirtalHost config.port; - }) - cfg.repositories; -in { - options.vhack.back = { - enable = lib.mkEnableOption "Back issue tracker (inspired by tvix's panettone)"; - - source_code_repository_url = lib.mkOption { - description = "The url to the source code of this instance of back"; - default = "https://git.foss-syndicate.org/vhack.eu/nixos-server/tree/pkgs/by-name/ba/back"; - type = lib.types.str; - }; - - repositories = lib.mkOption { - description = "An attibute set of repos to launch `back` services for."; - type = lib.types.attrsOf (lib.types.submodule { - options = { - enable = (lib.mkEnableOption "`back` for this repository.") // {default = true;}; - domain = lib.mkOption { - type = lib.types.str; - description = "The domain to host this `back` instance on."; - }; - port = lib.mkOption { - type = lib.types.port; - - # TODO: This _should_ be an implementation detail, but I've no real approach to - # automatically generate them without encountering weird bugs. <2024-12-23> - description = "The port to use for this back instance. This must be unique."; - }; - }; - }); - default = {}; - }; - }; - - config = lib.mkIf cfg.enable { - systemd = {inherit services;}; - services.nginx = {inherit virtualHosts;}; - }; -} diff --git a/modules/by-name/co/constants/module.nix b/modules/by-name/co/constants/module.nix deleted file mode 100644 index a28ea0c..0000000 --- a/modules/by-name/co/constants/module.nix +++ /dev/null @@ -1,43 +0,0 @@ -# This file is inspired by the `nixos/modules/misc/ids.nix` -# file in nixpkgs. -{lib, ...}: { - options.vhack.constants = { - ids.uids = lib.mkOption { - internal = true; - description = '' - The user IDs used in the vhack.eu nixos config. - ''; - type = lib.types.attrsOf lib.types.int; - }; - ids.gids = lib.mkOption { - internal = true; - description = '' - The group IDs used in the vhack.eu nixos config. - ''; - type = lib.types.attrsOf lib.types.int; - }; - }; - - config.vhack.constants = { - ids.uids = { - acme = 328; - dhcpcd = 329; - nscd = 330; - sshd = 331; - systemd-oom = 332; - - # As per the NixOS file, the uids should not be greater or equal to 400; - }; - ids.gids = { - acme = 328; - dhcpcd = 329; - nscd = 330; - sshd = 331; - systemd-oom = 332; - resolvconf = 333; # This group is not matched to an user? - systemd-coredump = 151; # matches systemd-coredump user - - # The gid should match the uid. Thus should not be >= 400; - }; - }; -} diff --git a/modules/by-name/et/etesync/secret_file.age b/modules/by-name/et/etesync/secret_file.age deleted file mode 100644 index 8d8e3c2..0000000 --- a/modules/by-name/et/etesync/secret_file.age +++ /dev/null @@ -1,17 +0,0 @@ ------BEGIN AGE ENCRYPTED FILE----- -YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA0UiswNDhQNWpsaFZUQTdY -U3F2TFlrSzhMbmRBWEIyTGQ2VGVramdPTDI4CjRGSnlqUm5rWWJ2Vk5neE56azdt -WitpbXlPWngxSGtEalBKWkRZdHF5QjQKLT4gWDI1NTE5IDRSSW1jcHhocjBIM0tM -ZjRxNUhZWkhkd1c5aVlucTMxTTVhSHRIMHMyU0EKbWlQZ0xKRXUvOWluSkZQRWdp -UjNMQWR3MHNwbUVYbm4vSGJQOGtrb2ZxVQotPiBzc2gtZWQyNTUxOSBPRDhUNGcg -SEpCY1JWZm5yMG1lL3QwUERPVUFqRWo5ZVJEb1JqNGVLS3pXVkhaYk1SYwpjb3dW -UWcrMkdmYTlvckFOYmsvcGwvY1dvc1oxY1FaY2p4eURCK3BIR044Ci0+ICgreWhl -KG9RLWdyZWFzZSAobEpLXVEgNVA3IGQKekx5YVFkeFRBUlJiUis2cFVyWlBPNncK -LS0tIFJxa0hDZUIyYm5uYlhiZjRnNHRLNTRrRW01d1hCL2dCZnByL1M2SkFyQXMK -gsR7erKGQrBhXlcnR73PbnC+PzOQlsBOg6a6DosGyixbnEgZ4DfyeK5Ep1oPB81Q -zcS9AV7h+8NlpmVM4G+0JCIC8I3TTCEQyOPwiu+GVXr4GYy/3stg+pK1htkt2V2M -WraPl//K3kvFln1KRt5lbsVXLX8SYZS4UJDzK25oJElwdNuqXHqwMkTmXjEgnbvS -pjgaNak5ooxHiZfCtzismLx5iL+P/+oohegUPvW16fQTq/eKp3mIjeBZmrWNnTuL -/xlhk0vp0+jS3+TqgGWSwAAqoCp/+TewUZ9f+GhU0/pkU3HP4+tx35rKN2wxerQj -nMbQ8SphigUeMpc501oDRw6X5ZAasoww ------END AGE ENCRYPTED FILE----- diff --git a/modules/by-name/ni/nix-sync/hosts.nix b/modules/by-name/ni/nix-sync/hosts.nix deleted file mode 100644 index 98dbbf1..0000000 --- a/modules/by-name/ni/nix-sync/hosts.nix +++ /dev/null @@ -1,48 +0,0 @@ -{...}: let - extraWkdSettings = { - locations."/.well-known/openpgpkey/hu/".extraConfig = '' - default_type application/octet-stream; - - # Came from: https://www.uriports.com/blog/setting-up-openpgp-web-key-directory/ - # No idea if it is actually necessary - # add_header Access-Control-Allow-Origin * always; - ''; - }; -in [ - { - domain = "vhack.eu"; - url = "https://codeberg.org/vhack.eu/website.git"; - } - { - domain = "b-peetz.de"; - url = "https://codeberg.org/bpeetz/b-peetz.de.git"; - } - - # Trinitrix - { - domain = "trinitrix.vhack.eu"; - url = "https://codeberg.org/trinitrix/website.git"; - } - - # WKD - { - domain = "openpgpkey.b-peetz.de"; - url = "https://codeberg.org/vhack.eu/gpg_wkd.git"; - extraSettings = extraWkdSettings; - } - { - domain = "openpgpkey.s-schoeffel.de"; - url = "https://codeberg.org/vhack.eu/gpg_wkd.git"; - extraSettings = extraWkdSettings; - } - { - domain = "openpgpkey.sils.li"; - url = "https://codeberg.org/vhack.eu/gpg_wkd.git"; - extraSettings = extraWkdSettings; - } - { - domain = "openpgpkey.vhack.eu"; - url = "https://codeberg.org/vhack.eu/gpg_wkd.git"; - extraSettings = extraWkdSettings; - } -] diff --git a/modules/by-name/ni/nix-sync/module.nix b/modules/by-name/ni/nix-sync/module.nix deleted file mode 100644 index de096b9..0000000 --- a/modules/by-name/ni/nix-sync/module.nix +++ /dev/null @@ -1,70 +0,0 @@ -{ - config, - lib, - ... -}: let - cfg = config.vhack.nix-sync; - - mkNixSyncRepository = { - domain, - root ? "", - url, - extraSettings ? {}, - }: { - name = "${domain}"; - value = { - path = "/etc/nginx/websites/${domain}/${root}"; - uri = "${url}"; - inherit extraSettings; - }; - }; - nixSyncRepositories = builtins.listToAttrs (builtins.map mkNixSyncRepository domains); - - mkVirtHost = { - domain, - root ? "", - url, - extraSettings ? {}, - }: { - name = "${domain}"; - value = - lib.recursiveUpdate { - forceSSL = true; - enableACME = true; - root = "/etc/nginx/websites/${domain}/${root}"; - } - extraSettings; - }; - virtHosts = builtins.listToAttrs (builtins.map mkVirtHost domains); - - domains = import ./hosts.nix {}; -in { - imports = [ - ./internal_module.nix - ]; - - options.vhack.nix-sync = { - enable = lib.mkEnableOption '' - a website git ops solution. - ''; - }; - - config = lib.mkIf cfg.enable { - vhack.persist.directories = [ - { - directory = "/var/lib/nix-sync"; - user = "nix-sync"; - group = "nix-sync"; - mode = "0700"; - } - ]; - - services.nix-sync = { - enable = true; - repositories = nixSyncRepositories; - }; - - vhack.nginx.enable = true; - services.nginx.virtualHosts = virtHosts; - }; -} diff --git a/modules/by-name/pe/peertube/secrets/general.age b/modules/by-name/pe/peertube/secrets/general.age deleted file mode 100644 index 854ab1a..0000000 --- a/modules/by-name/pe/peertube/secrets/general.age +++ /dev/null @@ -1,15 +0,0 @@ ------BEGIN AGE ENCRYPTED FILE----- -YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBlNjR4TDVUZmY2Y0hYT2hk -YmtPcFIxSXplNWF4M0V1Kzh2b2VoSTFCK0dzCmpwT2tDa3FpR082V2pyelBoS05o -RmlWRVdNdVhZbkRVUEVnaDlPdlN1bDAKLT4gWDI1NTE5IFlvaTFPc2JHcWczbEJy -eVZDS2NaUzBvbnpadk5ySVFxRTlNVXhrd2N0a3MKanJ0NEZWaTg3dE5Cbm9uNHNS -ZCs2dmU4RkFZOHNyNlJKa0cyd2VqSlFPQQotPiBzc2gtZWQyNTUxOSBPRDhUNGcg -NXhFSHdWUk1sbEUyb3FTdGpIaHlyTUJlMnlzNXBEY2lzTXpuM09WVDBrOApmM05W -d1VBSGlhMmlDYlhZS1hSdlJBUVkrVWs0bTJseS9BUmZGY1l5K0NBCi0+IEQkNi1l -LWdyZWFzZSAhIUlaOnNsZCAsUVRVKiBfRig2KGg+NSA6CmI0Q0N0cmlFbnNGSFZQ -WThEV0RHS0V2NTVaZnIyK2tUQXZTOHdsRkhyRlExdCtOeHRML2hFNDNxd08xQjlG -V3oKMThoQnF4Y3FDU3hMZjhwRUNvVWRRR3I4c1k5QnhJS1dRR2dod0EKLS0tIEZT -dHhnVXdHV3QzYThXWFJQL2szeTZ4SWM4czZYQWxJOFFIVjBZSnJ0K00KH8WdXv68 -rjAqo5RoWu91aVg5Bl2HKuiFbaGcnlkiMPZ9wGfpq4mpCc/yc4NTa6HhkaI5tA61 -PjKurnkiLXywcdyUTPuaykk+wANynLucbwfq/Mv3aLcG01soh+dFNKZV/g== ------END AGE ENCRYPTED FILE----- diff --git a/modules/by-name/pe/peertube/secrets/smtp.age b/modules/by-name/pe/peertube/secrets/smtp.age deleted file mode 100644 index 1979ea7..0000000 --- a/modules/by-name/pe/peertube/secrets/smtp.age +++ /dev/null @@ -1,16 +0,0 @@ ------BEGIN AGE ENCRYPTED FILE----- -YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBtU05NMDN0Q2MrVGEraHpH -Tkwyd0NuVEQwcjljd0NUNUpsSER0V0RldWxNCjlnRHZWNmprVDYxQm90Q3pFVHR5 -enJyUTZhSVdUL1I1aC9Ya2NkMElQaFUKLT4gWDI1NTE5IHprWjRDZVlMK3Rmd1A5 -K0pZRVBIYldsOW0wQXp4SmJzM1pXdzAvZVpiWEUKd1cwR2ZNZTh6WXhQNGZBVmdN -VWpxZGxPZXJBT1dqUFd1aU4xaHAxckZLcwotPiBzc2gtZWQyNTUxOSBPRDhUNGcg -akdaS3I3VHplOENIZDg5TSt2SmRCSGpjaUZoUHVYTFJRR2wzc1RHYWNnVQpFN1Ew -MTZDNGNyKzB1aEdTMHpKaWlFLzE0blJpZ3RhOTZReTNucUp6SEdZCi0+IHloQSUq -LWdyZWFzZQo5VitXYjNxck5FbnkwYlBvUyt6R2ROVG9JOWtQNGJma1ZYd29oVlFx -blFzSytWNDA4d3lqWE9JTUVreCs2Wi92ClZCdFgwYmRmc1VsU0NhTVR4b2dtZkpK -ZTU2M24zVjd0UTRrelFXYnFEZwotLS0gT2ZlRGJsZWNPcEwxK2drdDhVSndDV3Fj -SENsN2piWWEzSFI2OW8xbk12cwrFU4dzHxb5M3miGDpWLh3XbwzsrqWlFWLLu0Ht -SDvqJGrwAPsnVn4YLSG42q1BodYfcQVvVwqRCVbkubEUDcecDTdaYDvjaS3tmDZW -u5Nabp1ujYuIewOEZ8w41napS0C553qq0mL5sYZH1C23ViW81va4X1XOJTCnmbz6 -lbh+lK8ZbZz3cer49nR8OHTtpjA9hrf4Pf/W2nMR+0exy4zDYw== ------END AGE ENCRYPTED FILE----- diff --git a/modules/by-name/re/redlib/module.nix b/modules/by-name/re/redlib/module.nix deleted file mode 100644 index 2b20c66..0000000 --- a/modules/by-name/re/redlib/module.nix +++ /dev/null @@ -1,44 +0,0 @@ -{ - config, - pkgsUnstable, - lib, - ... -}: let - domain = "redlib.vhack.eu"; - - cfg = config.vhack.redlib; -in { - options.vhack.redlib = { - enable = lib.mkEnableOption '' - the redlib reddit frontend - ''; - }; - - config = lib.mkIf cfg.enable { - services.redlib = { - enable = true; - package = pkgsUnstable.redlib; - port = 8080; - address = "127.0.0.1"; - openFirewall = false; - }; - - services.nginx = { - enable = true; - virtualHosts.${domain} = { - locations."/".proxyPass = "http://127.0.0.1:${toString config.services.redlib.port}"; - - enableACME = true; - forceSSL = true; - }; - - # TODO: Remove this at a certain point. <2024-12-19> - virtualHosts."libreddit.vhack.eu" = { - locations."/".return = "301 https://${domain}"; - - forceSSL = true; - enableACME = true; - }; - }; - }; -} diff --git a/modules/by-name/co/coredump/module.nix b/modules/vhack/co/coredump/module.nix index ce28ed9..ce28ed9 100644 --- a/modules/by-name/co/coredump/module.nix +++ b/modules/vhack/co/coredump/module.nix diff --git a/modules/by-name/dh/dhcpcd/module.nix b/modules/vhack/dh/dhcpcd/module.nix index 0e35af3..0e35af3 100644 --- a/modules/by-name/dh/dhcpcd/module.nix +++ b/modules/vhack/dh/dhcpcd/module.nix diff --git a/modules/by-name/di/disko/module.nix b/modules/vhack/di/disko/module.nix index b4fc3c8..b4fc3c8 100644 --- a/modules/by-name/di/disko/module.nix +++ b/modules/vhack/di/disko/module.nix diff --git a/modules/by-name/et/etesync/module.nix b/modules/vhack/et/etesync/module.nix index 0f6c565..4dc8575 100644 --- a/modules/by-name/et/etesync/module.nix +++ b/modules/vhack/et/etesync/module.nix @@ -9,6 +9,10 @@ in { enable = lib.mkEnableOption '' a secure, end-to-end encrypted, and privacy respecting sync for your contacts, calendars, tasks and notes. ''; + secretFile = lib.mkOption { + type = lib.types.path; + description = "The age encrypted globale etebase secretfile passed to agenix"; + }; }; config = lib.mkIf cfg.enable { @@ -25,13 +29,13 @@ in { }; age.secrets.etebase-server = { - file = ./secret_file.age; + file = cfg.secretFile; mode = "700"; owner = "etebase-server"; group = "etebase-server"; }; - environment.persistence."/srv".directories = [ + vhack.persist.directories = [ { directory = "/var/lib/etebase-server"; user = "etebase-server"; @@ -41,26 +45,14 @@ in { ]; services.nginx = { - enable = true; - recommendedTlsSettings = true; - recommendedOptimisation = true; - recommendedGzipSettings = true; - recommendedProxySettings = true; - virtualHosts = { "etebase.vhack.eu" = { - enableACME = true; - forceSSL = true; - locations = { # TODO: Maybe fix permissions to use pregenerated static files which would # improve performance. #"/static" = { # root = config.services.etebase-server.settings.global.static_root; #}; - "/" = { - proxyPass = "http://127.0.0.1:${builtins.toString config.services.etebase-server.port}"; - }; }; serverAliases = [ "dav.vhack.eu" @@ -68,5 +60,11 @@ in { }; }; }; + vhack.anubis.instances."etebase.vhack.eu".target = "http://127.0.0.1:${builtins.toString config.services.etebase-server.port}"; + + users = { + users.etebase-server.uid = config.vhack.constants.ids.uids.etebase-server; + groups.etebase-server.gid = config.vhack.constants.ids.gids.etebase-server; + }; }; } diff --git a/modules/by-name/fa/fail2ban/module.nix b/modules/vhack/fa/fail2ban/module.nix index c619ef9..c619ef9 100644 --- a/modules/by-name/fa/fail2ban/module.nix +++ b/modules/vhack/fa/fail2ban/module.nix diff --git a/modules/by-name/gi/git-server/css.nix b/modules/vhack/gi/git-server/css.nix index 7d0ad06..7d0ad06 100644 --- a/modules/by-name/gi/git-server/css.nix +++ b/modules/vhack/gi/git-server/css.nix diff --git a/modules/by-name/gi/git-server/module.nix b/modules/vhack/gi/git-server/module.nix index db35897..3e2c848 100644 --- a/modules/by-name/gi/git-server/module.nix +++ b/modules/vhack/gi/git-server/module.nix @@ -8,8 +8,7 @@ cgitCss = import ./css.nix { inherit pkgs; - cgitPkg = - config.services.cgit."${cfg.domain}".package; + cgitPkg = config.services.cgit."${cfg.domain}".package; }; in { options.vhack.git-server = { @@ -84,10 +83,16 @@ in { cgit."${cfg.domain}" = { enable = true; - package = pkgs.cgit-pink; + package = pkgs.cgit; scanPath = "${config.services.gitolite.dataDir}/repositories"; user = "git"; group = "git"; + + # Don't bypass `cgit` when performing a http only clone. + # This is slightly slower, but we don't need to worry about the access + # restrictions also being by-passed. + gitHttpBackend.enable = false; + settings = { branch-sort = "age"; diff --git a/modules/by-name/im/impermanence/module.nix b/modules/vhack/im/impermanence/module.nix index 1c916e2..1c916e2 100644 --- a/modules/by-name/im/impermanence/module.nix +++ b/modules/vhack/im/impermanence/module.nix diff --git a/modules/by-name/ng/nginx/module.nix b/modules/vhack/ng/nginx/module.nix index 39919c9..1317d4d 100644 --- a/modules/by-name/ng/nginx/module.nix +++ b/modules/vhack/ng/nginx/module.nix @@ -6,7 +6,7 @@ mkRedirect = _: value: { forceSSL = true; enableACME = true; - locations."/".return = "301 ${value}"; + locations."/".return = "301 ${value}$request_uri"; }; redirects = builtins.mapAttrs mkRedirect cfg.redirects; @@ -18,15 +18,6 @@ in { a default nginx config. ''; - selfsign = lib.mkOption { - type = lib.types.bool; - default = false; - description = '' - Whether to selfsign the acme certificates. This should only - really be useful for tests. - ''; - }; - redirects = lib.mkOption { type = lib.types.attrsOf lib.types.str; default = {}; @@ -39,12 +30,33 @@ in { }; config = lib.mkIf cfg.enable { - vhack.persist.directories = [ - "/var/lib/acme" - ]; + vhack = { + persist.directories = [ + "/var/lib/acme" + ]; + + monitoring.prometheus = { + sources = [ + { + name = "nginx"; + target = "127.0.0.1:${toString config.services.prometheus.exporters.nginx.port}"; + } + ]; + }; + }; + + services.prometheus.exporters.nginx = { + enable = true; + port = 9111; + listenAddress = "127.0.0.1"; + scrapeUri = "http://localhost:80/nginx_status"; + }; users = { - users.acme.uid = config.vhack.constants.ids.uids.acme; + users.acme = { + uid = config.vhack.constants.ids.uids.acme; + group = "acme"; + }; groups.acme.gid = config.vhack.constants.ids.gids.acme; }; @@ -53,10 +65,6 @@ in { defaults = { email = "admin@vhack.eu"; webroot = "/var/lib/acme/acme-challenge"; - - # Avoid spamming the acme server, if we run in a test, and only really want self-signed - # certificates - server = lib.mkIf cfg.selfsign "https://127.0.0.1"; }; }; @@ -65,16 +73,11 @@ in { }; services.nginx = { enable = true; - virtualHosts = redirects; - # FIXME(@bpeetz): Migrate to a host. <2024-12-25> - # { - # "gallery.s-schoeffel.de" = { - # forceSSL = true; - # enableACME = true; - # root = "/srv/gallery.s-schoeffel.de"; - # }; - # } + # Enable the status page for the prometheus exporter. + statusPage = lib.mkIf config.services.prometheus.enable true; + + virtualHosts = redirects; }; }; } diff --git a/modules/by-name/ni/nix-sync/internal_module.nix b/modules/vhack/ni/nix-sync/internal_module.nix index 4e28586..4e28586 100644 --- a/modules/by-name/ni/nix-sync/internal_module.nix +++ b/modules/vhack/ni/nix-sync/internal_module.nix diff --git a/modules/by-name/ns/nscd/module.nix b/modules/vhack/ns/nscd/module.nix index 428ae3b..428ae3b 100644 --- a/modules/by-name/ns/nscd/module.nix +++ b/modules/vhack/ns/nscd/module.nix diff --git a/modules/by-name/oo/oomd/module.nix b/modules/vhack/oo/oomd/module.nix index 3b39236..3b39236 100644 --- a/modules/by-name/oo/oomd/module.nix +++ b/modules/vhack/oo/oomd/module.nix diff --git a/modules/by-name/op/openssh/module.nix b/modules/vhack/op/openssh/module.nix index 83aeadf..83aeadf 100644 --- a/modules/by-name/op/openssh/module.nix +++ b/modules/vhack/op/openssh/module.nix diff --git a/modules/by-name/pe/peertube/module.nix b/modules/vhack/pe/peertube/module.nix index 29d1d07..e65e0b5 100644 --- a/modules/by-name/pe/peertube/module.nix +++ b/modules/vhack/pe/peertube/module.nix @@ -1,7 +1,6 @@ { config, lib, - pkgs, ... }: let cfg = config.vhack.peertube; @@ -10,6 +9,14 @@ in { enable = lib.mkEnableOption '' the peertube video platform. ''; + peertubeGeneral = lib.mkOption { + type = lib.types.path; + description = "The age encrypted general secret file passed to agenix"; + }; + smtpPasswordFile = lib.mkOption { + type = lib.types.path; + description = "The age encrypted smtp password file passed to agenix"; + }; }; config = lib.mkIf cfg.enable { @@ -22,7 +29,7 @@ in { listenWeb = 443; smtp = { - createLocally = true; + createLocally = false; passwordFile = "${config.age.secrets.peertubeSmtp.path}"; }; database = { @@ -66,10 +73,8 @@ in { smtp = let emailAddress = "peertube@vhack.eu"; in { - sendmail = "${pkgs.postfix}/bin/sendmail"; - - transport = "sendmail"; - hostname = "server1.vhack.eu"; + transport = "smtp"; + hostname = "mail.foss-syndicate.org"; port = 587; username = emailAddress; tls = true; @@ -88,20 +93,20 @@ in { age.secrets = { peertubeGeneral = { - file = ./secrets/general.age; + file = cfg.peertubeGeneral; mode = "700"; owner = "peertube"; group = "peertube"; }; peertubeSmtp = { - file = ./secrets/smtp.age; + file = cfg.smtpPasswordFile; mode = "700"; owner = "peertube"; group = "peertube"; }; }; - environment.persistence."/srv".directories = [ + vhack.persist.directories = [ { directory = "/var/lib/peertube"; user = "peertube"; @@ -109,5 +114,11 @@ in { mode = "0700"; } ]; + users = { + users.peertube.uid = config.vhack.constants.ids.uids.peertube; + groups.peertube.gid = config.vhack.constants.ids.gids.peertube; + users.redis-peertube.uid = config.vhack.constants.ids.uids.redis-peertube; + groups.redis-peertube.gid = config.vhack.constants.ids.gids.redis-peertube; + }; }; } diff --git a/modules/by-name/po/postgresql/module.nix b/modules/vhack/po/postgresql/module.nix index 319c3ac..319c3ac 100644 --- a/modules/by-name/po/postgresql/module.nix +++ b/modules/vhack/po/postgresql/module.nix diff --git a/modules/by-name/re/resolvconf/module.nix b/modules/vhack/re/resolvconf/module.nix index ff99696..ff99696 100644 --- a/modules/by-name/re/resolvconf/module.nix +++ b/modules/vhack/re/resolvconf/module.nix diff --git a/modules/by-name/ru/rust-motd/module.nix b/modules/vhack/ru/rust-motd/module.nix index a6998f4..bf23843 100644 --- a/modules/by-name/ru/rust-motd/module.nix +++ b/modules/vhack/ru/rust-motd/module.nix @@ -19,6 +19,13 @@ || v.openssh.authorizedKeys.keyFiles != [] ); userList = builtins.mapAttrs (n: v: 2) (lib.filterAttrs pred config.users.users); + + bannerFile = + pkgs.runCommandLocal "banner-file" { + nativeBuildInputs = [pkgs.figlet]; + } '' + echo "${config.system.name}" | figlet -f slant > "$out" + ''; in { options.vhack.rust-motd = { enable = lib.mkEnableOption "rust-motd"; @@ -49,25 +56,22 @@ in { banner = { color = "red"; - command = "${pkgs.hostname}/bin/hostname | ${pkgs.figlet}/bin/figlet -f slant"; - # if you don't want a dependency on figlet, you can generate your - # banner however you want, put it in a file, and then use something like: - # command = "cat banner.txt" + # Avoid some runtime dependencies. + command = "cat ${bannerFile}"; + }; + + cg_stats = { + state_file = "/var/lib/rust-motd/cg_stats_state"; + threshold = 0.02; # When to start generating output for a cgroup + }; + load_avg = { + format = "Load (1, 5, 15 min.): {one:.02}, {five:.02}, {fifteen:.02}"; }; uptime = { prefix = "Uptime:"; }; - # ssl_certificates = { - # sort_method = "manual"; - # - # certs = { - # "server1.vhack.eu" = "/var/lib/acme/server1.vhack.eu/cert.pem"; - # "vhack.eu" = "/var/lib/acme/vhack.eu/cert.pem"; - # }; - # }; - filesystems = { root = "/"; persistent = "/srv"; @@ -79,7 +83,7 @@ in { swap_pos = "beside"; # or "below" or "none" }; - fail2_ban = { + fail_2_ban = { jails = ["sshd"]; #, "anotherjail"] }; diff --git a/modules/by-name/us/users/module.nix b/modules/vhack/us/users/module.nix index a197b13..e029130 100644 --- a/modules/by-name/us/users/module.nix +++ b/modules/vhack/us/users/module.nix @@ -27,20 +27,22 @@ }; }; - extraUsers = lib.listToAttrs (builtins.map mkUser [ - { - name = "soispha"; - password = "$y$jFT$3.8XmUyukZvpExMUxDZkI.$IVrJgm8ysNDF/0vDD2kF6w73ozXgr1LMVRNN4Bq7pv1"; - sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIME4ZVa+IoZf6T3U08JG93i6QIAJ4amm7mkBzO14JSkz cardno:000F_18F83532"; - uid = 1000; - } - { - name = "sils"; - password = "$y$jFT$KpFnahVCE9JbE.5P3us8o.$ZzSxCusWqe3sL7b6DLgOXNNUf114tiiptM6T8lDxtKC"; - sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAe4o1PM6VasT3KZNl5NYvgkkBrPOg36dqsywd10FztS openpgp:0x21D20D6A"; - uid = 1001; - } - ]); + extraUsers = lib.listToAttrs ( + builtins.map mkUser [ + { + name = "soispha"; + password = "$y$jFT$3.8XmUyukZvpExMUxDZkI.$IVrJgm8ysNDF/0vDD2kF6w73ozXgr1LMVRNN4Bq7pv1"; + sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIME4ZVa+IoZf6T3U08JG93i6QIAJ4amm7mkBzO14JSkz cardno:000F_18F83532"; + uid = 1000; + } + { + name = "jaki"; + password = "$y$jFT$KpFnahVCE9JbE.5P3us8o.$ZzSxCusWqe3sL7b6DLgOXNNUf114tiiptM6T8lDxtKC"; + sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILn7Oumr5IYtTTIKRFvDnofGXXiDLBQE9jVF+7UE+4G5 vhack.eu"; + uid = 1001; + } + ] + ); in { options.vhack.users = { enable = lib.mkEnableOption "user setup"; |
