aboutsummaryrefslogtreecommitdiffstats
path: root/modules/by-name
diff options
context:
space:
mode:
Diffstat (limited to '')
-rw-r--r--modules/by-name/ba/back/module.nix121
-rw-r--r--modules/by-name/co/constants/module.nix43
-rw-r--r--modules/by-name/et/etesync/secret_file.age17
-rw-r--r--modules/by-name/ni/nix-sync/hosts.nix48
-rw-r--r--modules/by-name/ni/nix-sync/module.nix70
-rw-r--r--modules/by-name/pe/peertube/secrets/general.age15
-rw-r--r--modules/by-name/pe/peertube/secrets/smtp.age16
-rw-r--r--modules/by-name/re/redlib/module.nix44
-rw-r--r--modules/vhack/co/coredump/module.nix (renamed from modules/by-name/co/coredump/module.nix)0
-rw-r--r--modules/vhack/dh/dhcpcd/module.nix (renamed from modules/by-name/dh/dhcpcd/module.nix)0
-rw-r--r--modules/vhack/di/disko/module.nix (renamed from modules/by-name/di/disko/module.nix)0
-rw-r--r--modules/vhack/et/etesync/module.nix (renamed from modules/by-name/et/etesync/module.nix)26
-rw-r--r--modules/vhack/fa/fail2ban/module.nix (renamed from modules/by-name/fa/fail2ban/module.nix)0
-rw-r--r--modules/vhack/gi/git-server/css.nix (renamed from modules/by-name/gi/git-server/css.nix)0
-rw-r--r--modules/vhack/gi/git-server/module.nix (renamed from modules/by-name/gi/git-server/module.nix)11
-rw-r--r--modules/vhack/im/impermanence/module.nix (renamed from modules/by-name/im/impermanence/module.nix)0
-rw-r--r--modules/vhack/ng/nginx/module.nix (renamed from modules/by-name/ng/nginx/module.nix)57
-rw-r--r--modules/vhack/ni/nix-sync/internal_module.nix (renamed from modules/by-name/ni/nix-sync/internal_module.nix)0
-rw-r--r--modules/vhack/ns/nscd/module.nix (renamed from modules/by-name/ns/nscd/module.nix)0
-rw-r--r--modules/vhack/oo/oomd/module.nix (renamed from modules/by-name/oo/oomd/module.nix)0
-rw-r--r--modules/vhack/op/openssh/module.nix (renamed from modules/by-name/op/openssh/module.nix)0
-rw-r--r--modules/vhack/pe/peertube/module.nix (renamed from modules/by-name/pe/peertube/module.nix)29
-rw-r--r--modules/vhack/po/postgresql/module.nix (renamed from modules/by-name/po/postgresql/module.nix)0
-rw-r--r--modules/vhack/re/resolvconf/module.nix (renamed from modules/by-name/re/resolvconf/module.nix)0
-rw-r--r--modules/vhack/ru/rust-motd/module.nix (renamed from modules/by-name/ru/rust-motd/module.nix)32
-rw-r--r--modules/vhack/us/users/module.nix (renamed from modules/by-name/us/users/module.nix)30
26 files changed, 104 insertions, 455 deletions
diff --git a/modules/by-name/ba/back/module.nix b/modules/by-name/ba/back/module.nix
deleted file mode 100644
index 520acdb..0000000
--- a/modules/by-name/ba/back/module.nix
+++ /dev/null
@@ -1,121 +0,0 @@
-{
- config,
- lib,
- vhackPackages,
- pkgs,
- ...
-}: let
- cfg = config.vhack.back;
-
- mkConfigFile = repoPath: domain:
- (pkgs.formats.json {}).generate "config.json"
- {
- inherit (cfg) source_code_repository_url;
- repository_path = repoPath;
- root_url = "https://${domain}";
- };
-
- mkUnit = repoPath: port: domain: {
- description = "Back service for ${repoPath}";
- wants = ["network-online.target"];
- after = ["network-online.target"];
- wantedBy = ["default.target"];
-
- environment = {
- ROCKET_PORT = builtins.toString port;
- };
-
- serviceConfig = {
- ExecStart = "${lib.getExe vhackPackages.back} ${mkConfigFile repoPath domain}";
-
- # Ensure that the service can read the repository
- # FIXME(@bpeetz): This has the implied assumption, that all the exposed git
- # repositories are readable for the git group. This should not be necessary. <2024-12-23>
- User = "git";
- Group = "git";
-
- DynamicUser = true;
- Restart = "always";
-
- # Sandboxing
- ProtectSystem = "strict";
- ProtectHome = true;
- PrivateTmp = true;
- PrivateDevices = true;
- ProtectHostname = true;
- ProtectClock = true;
- ProtectKernelTunables = true;
- ProtectKernelModules = true;
- ProtectKernelLogs = true;
- ProtectControlGroups = true;
- RestrictAddressFamilies = ["AF_UNIX" "AF_INET" "AF_INET6"];
- RestrictNamespaces = true;
- LockPersonality = true;
- MemoryDenyWriteExecute = true;
- RestrictRealtime = true;
- RestrictSUIDSGID = true;
- RemoveIPC = true;
- PrivateMounts = true;
- # System Call Filtering
- SystemCallArchitectures = "native";
- SystemCallFilter = ["~@cpu-emulation @debug @keyring @mount @obsolete @privileged @setuid"];
- };
- };
-
- mkVirtalHost = port: {
- locations."/".proxyPass = "http://127.0.0.1:${builtins.toString port}";
-
- enableACME = true;
- forceSSL = true;
- };
-
- services =
- lib.mapAttrs' (gitPath: config: {
- name = builtins.replaceStrings ["/"] ["_"] "back-${config.domain}";
- value = mkUnit gitPath config.port config.domain;
- })
- cfg.repositories;
-
- virtualHosts =
- lib.mapAttrs' (gitPath: config: {
- name = config.domain;
- value = mkVirtalHost config.port;
- })
- cfg.repositories;
-in {
- options.vhack.back = {
- enable = lib.mkEnableOption "Back issue tracker (inspired by tvix's panettone)";
-
- source_code_repository_url = lib.mkOption {
- description = "The url to the source code of this instance of back";
- default = "https://git.foss-syndicate.org/vhack.eu/nixos-server/tree/pkgs/by-name/ba/back";
- type = lib.types.str;
- };
-
- repositories = lib.mkOption {
- description = "An attibute set of repos to launch `back` services for.";
- type = lib.types.attrsOf (lib.types.submodule {
- options = {
- enable = (lib.mkEnableOption "`back` for this repository.") // {default = true;};
- domain = lib.mkOption {
- type = lib.types.str;
- description = "The domain to host this `back` instance on.";
- };
- port = lib.mkOption {
- type = lib.types.port;
-
- # TODO: This _should_ be an implementation detail, but I've no real approach to
- # automatically generate them without encountering weird bugs. <2024-12-23>
- description = "The port to use for this back instance. This must be unique.";
- };
- };
- });
- default = {};
- };
- };
-
- config = lib.mkIf cfg.enable {
- systemd = {inherit services;};
- services.nginx = {inherit virtualHosts;};
- };
-}
diff --git a/modules/by-name/co/constants/module.nix b/modules/by-name/co/constants/module.nix
deleted file mode 100644
index a28ea0c..0000000
--- a/modules/by-name/co/constants/module.nix
+++ /dev/null
@@ -1,43 +0,0 @@
-# This file is inspired by the `nixos/modules/misc/ids.nix`
-# file in nixpkgs.
-{lib, ...}: {
- options.vhack.constants = {
- ids.uids = lib.mkOption {
- internal = true;
- description = ''
- The user IDs used in the vhack.eu nixos config.
- '';
- type = lib.types.attrsOf lib.types.int;
- };
- ids.gids = lib.mkOption {
- internal = true;
- description = ''
- The group IDs used in the vhack.eu nixos config.
- '';
- type = lib.types.attrsOf lib.types.int;
- };
- };
-
- config.vhack.constants = {
- ids.uids = {
- acme = 328;
- dhcpcd = 329;
- nscd = 330;
- sshd = 331;
- systemd-oom = 332;
-
- # As per the NixOS file, the uids should not be greater or equal to 400;
- };
- ids.gids = {
- acme = 328;
- dhcpcd = 329;
- nscd = 330;
- sshd = 331;
- systemd-oom = 332;
- resolvconf = 333; # This group is not matched to an user?
- systemd-coredump = 151; # matches systemd-coredump user
-
- # The gid should match the uid. Thus should not be >= 400;
- };
- };
-}
diff --git a/modules/by-name/et/etesync/secret_file.age b/modules/by-name/et/etesync/secret_file.age
deleted file mode 100644
index 8d8e3c2..0000000
--- a/modules/by-name/et/etesync/secret_file.age
+++ /dev/null
@@ -1,17 +0,0 @@
------BEGIN AGE ENCRYPTED FILE-----
-YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA0UiswNDhQNWpsaFZUQTdY
-U3F2TFlrSzhMbmRBWEIyTGQ2VGVramdPTDI4CjRGSnlqUm5rWWJ2Vk5neE56azdt
-WitpbXlPWngxSGtEalBKWkRZdHF5QjQKLT4gWDI1NTE5IDRSSW1jcHhocjBIM0tM
-ZjRxNUhZWkhkd1c5aVlucTMxTTVhSHRIMHMyU0EKbWlQZ0xKRXUvOWluSkZQRWdp
-UjNMQWR3MHNwbUVYbm4vSGJQOGtrb2ZxVQotPiBzc2gtZWQyNTUxOSBPRDhUNGcg
-SEpCY1JWZm5yMG1lL3QwUERPVUFqRWo5ZVJEb1JqNGVLS3pXVkhaYk1SYwpjb3dW
-UWcrMkdmYTlvckFOYmsvcGwvY1dvc1oxY1FaY2p4eURCK3BIR044Ci0+ICgreWhl
-KG9RLWdyZWFzZSAobEpLXVEgNVA3IGQKekx5YVFkeFRBUlJiUis2cFVyWlBPNncK
-LS0tIFJxa0hDZUIyYm5uYlhiZjRnNHRLNTRrRW01d1hCL2dCZnByL1M2SkFyQXMK
-gsR7erKGQrBhXlcnR73PbnC+PzOQlsBOg6a6DosGyixbnEgZ4DfyeK5Ep1oPB81Q
-zcS9AV7h+8NlpmVM4G+0JCIC8I3TTCEQyOPwiu+GVXr4GYy/3stg+pK1htkt2V2M
-WraPl//K3kvFln1KRt5lbsVXLX8SYZS4UJDzK25oJElwdNuqXHqwMkTmXjEgnbvS
-pjgaNak5ooxHiZfCtzismLx5iL+P/+oohegUPvW16fQTq/eKp3mIjeBZmrWNnTuL
-/xlhk0vp0+jS3+TqgGWSwAAqoCp/+TewUZ9f+GhU0/pkU3HP4+tx35rKN2wxerQj
-nMbQ8SphigUeMpc501oDRw6X5ZAasoww
------END AGE ENCRYPTED FILE-----
diff --git a/modules/by-name/ni/nix-sync/hosts.nix b/modules/by-name/ni/nix-sync/hosts.nix
deleted file mode 100644
index 98dbbf1..0000000
--- a/modules/by-name/ni/nix-sync/hosts.nix
+++ /dev/null
@@ -1,48 +0,0 @@
-{...}: let
- extraWkdSettings = {
- locations."/.well-known/openpgpkey/hu/".extraConfig = ''
- default_type application/octet-stream;
-
- # Came from: https://www.uriports.com/blog/setting-up-openpgp-web-key-directory/
- # No idea if it is actually necessary
- # add_header Access-Control-Allow-Origin * always;
- '';
- };
-in [
- {
- domain = "vhack.eu";
- url = "https://codeberg.org/vhack.eu/website.git";
- }
- {
- domain = "b-peetz.de";
- url = "https://codeberg.org/bpeetz/b-peetz.de.git";
- }
-
- # Trinitrix
- {
- domain = "trinitrix.vhack.eu";
- url = "https://codeberg.org/trinitrix/website.git";
- }
-
- # WKD
- {
- domain = "openpgpkey.b-peetz.de";
- url = "https://codeberg.org/vhack.eu/gpg_wkd.git";
- extraSettings = extraWkdSettings;
- }
- {
- domain = "openpgpkey.s-schoeffel.de";
- url = "https://codeberg.org/vhack.eu/gpg_wkd.git";
- extraSettings = extraWkdSettings;
- }
- {
- domain = "openpgpkey.sils.li";
- url = "https://codeberg.org/vhack.eu/gpg_wkd.git";
- extraSettings = extraWkdSettings;
- }
- {
- domain = "openpgpkey.vhack.eu";
- url = "https://codeberg.org/vhack.eu/gpg_wkd.git";
- extraSettings = extraWkdSettings;
- }
-]
diff --git a/modules/by-name/ni/nix-sync/module.nix b/modules/by-name/ni/nix-sync/module.nix
deleted file mode 100644
index de096b9..0000000
--- a/modules/by-name/ni/nix-sync/module.nix
+++ /dev/null
@@ -1,70 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.nix-sync;
-
- mkNixSyncRepository = {
- domain,
- root ? "",
- url,
- extraSettings ? {},
- }: {
- name = "${domain}";
- value = {
- path = "/etc/nginx/websites/${domain}/${root}";
- uri = "${url}";
- inherit extraSettings;
- };
- };
- nixSyncRepositories = builtins.listToAttrs (builtins.map mkNixSyncRepository domains);
-
- mkVirtHost = {
- domain,
- root ? "",
- url,
- extraSettings ? {},
- }: {
- name = "${domain}";
- value =
- lib.recursiveUpdate {
- forceSSL = true;
- enableACME = true;
- root = "/etc/nginx/websites/${domain}/${root}";
- }
- extraSettings;
- };
- virtHosts = builtins.listToAttrs (builtins.map mkVirtHost domains);
-
- domains = import ./hosts.nix {};
-in {
- imports = [
- ./internal_module.nix
- ];
-
- options.vhack.nix-sync = {
- enable = lib.mkEnableOption ''
- a website git ops solution.
- '';
- };
-
- config = lib.mkIf cfg.enable {
- vhack.persist.directories = [
- {
- directory = "/var/lib/nix-sync";
- user = "nix-sync";
- group = "nix-sync";
- mode = "0700";
- }
- ];
-
- services.nix-sync = {
- enable = true;
- repositories = nixSyncRepositories;
- };
-
- vhack.nginx.enable = true;
- services.nginx.virtualHosts = virtHosts;
- };
-}
diff --git a/modules/by-name/pe/peertube/secrets/general.age b/modules/by-name/pe/peertube/secrets/general.age
deleted file mode 100644
index 854ab1a..0000000
--- a/modules/by-name/pe/peertube/secrets/general.age
+++ /dev/null
@@ -1,15 +0,0 @@
------BEGIN AGE ENCRYPTED FILE-----
-YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBlNjR4TDVUZmY2Y0hYT2hk
-YmtPcFIxSXplNWF4M0V1Kzh2b2VoSTFCK0dzCmpwT2tDa3FpR082V2pyelBoS05o
-RmlWRVdNdVhZbkRVUEVnaDlPdlN1bDAKLT4gWDI1NTE5IFlvaTFPc2JHcWczbEJy
-eVZDS2NaUzBvbnpadk5ySVFxRTlNVXhrd2N0a3MKanJ0NEZWaTg3dE5Cbm9uNHNS
-ZCs2dmU4RkFZOHNyNlJKa0cyd2VqSlFPQQotPiBzc2gtZWQyNTUxOSBPRDhUNGcg
-NXhFSHdWUk1sbEUyb3FTdGpIaHlyTUJlMnlzNXBEY2lzTXpuM09WVDBrOApmM05W
-d1VBSGlhMmlDYlhZS1hSdlJBUVkrVWs0bTJseS9BUmZGY1l5K0NBCi0+IEQkNi1l
-LWdyZWFzZSAhIUlaOnNsZCAsUVRVKiBfRig2KGg+NSA6CmI0Q0N0cmlFbnNGSFZQ
-WThEV0RHS0V2NTVaZnIyK2tUQXZTOHdsRkhyRlExdCtOeHRML2hFNDNxd08xQjlG
-V3oKMThoQnF4Y3FDU3hMZjhwRUNvVWRRR3I4c1k5QnhJS1dRR2dod0EKLS0tIEZT
-dHhnVXdHV3QzYThXWFJQL2szeTZ4SWM4czZYQWxJOFFIVjBZSnJ0K00KH8WdXv68
-rjAqo5RoWu91aVg5Bl2HKuiFbaGcnlkiMPZ9wGfpq4mpCc/yc4NTa6HhkaI5tA61
-PjKurnkiLXywcdyUTPuaykk+wANynLucbwfq/Mv3aLcG01soh+dFNKZV/g==
------END AGE ENCRYPTED FILE-----
diff --git a/modules/by-name/pe/peertube/secrets/smtp.age b/modules/by-name/pe/peertube/secrets/smtp.age
deleted file mode 100644
index 1979ea7..0000000
--- a/modules/by-name/pe/peertube/secrets/smtp.age
+++ /dev/null
@@ -1,16 +0,0 @@
------BEGIN AGE ENCRYPTED FILE-----
-YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBtU05NMDN0Q2MrVGEraHpH
-Tkwyd0NuVEQwcjljd0NUNUpsSER0V0RldWxNCjlnRHZWNmprVDYxQm90Q3pFVHR5
-enJyUTZhSVdUL1I1aC9Ya2NkMElQaFUKLT4gWDI1NTE5IHprWjRDZVlMK3Rmd1A5
-K0pZRVBIYldsOW0wQXp4SmJzM1pXdzAvZVpiWEUKd1cwR2ZNZTh6WXhQNGZBVmdN
-VWpxZGxPZXJBT1dqUFd1aU4xaHAxckZLcwotPiBzc2gtZWQyNTUxOSBPRDhUNGcg
-akdaS3I3VHplOENIZDg5TSt2SmRCSGpjaUZoUHVYTFJRR2wzc1RHYWNnVQpFN1Ew
-MTZDNGNyKzB1aEdTMHpKaWlFLzE0blJpZ3RhOTZReTNucUp6SEdZCi0+IHloQSUq
-LWdyZWFzZQo5VitXYjNxck5FbnkwYlBvUyt6R2ROVG9JOWtQNGJma1ZYd29oVlFx
-blFzSytWNDA4d3lqWE9JTUVreCs2Wi92ClZCdFgwYmRmc1VsU0NhTVR4b2dtZkpK
-ZTU2M24zVjd0UTRrelFXYnFEZwotLS0gT2ZlRGJsZWNPcEwxK2drdDhVSndDV3Fj
-SENsN2piWWEzSFI2OW8xbk12cwrFU4dzHxb5M3miGDpWLh3XbwzsrqWlFWLLu0Ht
-SDvqJGrwAPsnVn4YLSG42q1BodYfcQVvVwqRCVbkubEUDcecDTdaYDvjaS3tmDZW
-u5Nabp1ujYuIewOEZ8w41napS0C553qq0mL5sYZH1C23ViW81va4X1XOJTCnmbz6
-lbh+lK8ZbZz3cer49nR8OHTtpjA9hrf4Pf/W2nMR+0exy4zDYw==
------END AGE ENCRYPTED FILE-----
diff --git a/modules/by-name/re/redlib/module.nix b/modules/by-name/re/redlib/module.nix
deleted file mode 100644
index 2b20c66..0000000
--- a/modules/by-name/re/redlib/module.nix
+++ /dev/null
@@ -1,44 +0,0 @@
-{
- config,
- pkgsUnstable,
- lib,
- ...
-}: let
- domain = "redlib.vhack.eu";
-
- cfg = config.vhack.redlib;
-in {
- options.vhack.redlib = {
- enable = lib.mkEnableOption ''
- the redlib reddit frontend
- '';
- };
-
- config = lib.mkIf cfg.enable {
- services.redlib = {
- enable = true;
- package = pkgsUnstable.redlib;
- port = 8080;
- address = "127.0.0.1";
- openFirewall = false;
- };
-
- services.nginx = {
- enable = true;
- virtualHosts.${domain} = {
- locations."/".proxyPass = "http://127.0.0.1:${toString config.services.redlib.port}";
-
- enableACME = true;
- forceSSL = true;
- };
-
- # TODO: Remove this at a certain point. <2024-12-19>
- virtualHosts."libreddit.vhack.eu" = {
- locations."/".return = "301 https://${domain}";
-
- forceSSL = true;
- enableACME = true;
- };
- };
- };
-}
diff --git a/modules/by-name/co/coredump/module.nix b/modules/vhack/co/coredump/module.nix
index ce28ed9..ce28ed9 100644
--- a/modules/by-name/co/coredump/module.nix
+++ b/modules/vhack/co/coredump/module.nix
diff --git a/modules/by-name/dh/dhcpcd/module.nix b/modules/vhack/dh/dhcpcd/module.nix
index 0e35af3..0e35af3 100644
--- a/modules/by-name/dh/dhcpcd/module.nix
+++ b/modules/vhack/dh/dhcpcd/module.nix
diff --git a/modules/by-name/di/disko/module.nix b/modules/vhack/di/disko/module.nix
index b4fc3c8..b4fc3c8 100644
--- a/modules/by-name/di/disko/module.nix
+++ b/modules/vhack/di/disko/module.nix
diff --git a/modules/by-name/et/etesync/module.nix b/modules/vhack/et/etesync/module.nix
index 0f6c565..4dc8575 100644
--- a/modules/by-name/et/etesync/module.nix
+++ b/modules/vhack/et/etesync/module.nix
@@ -9,6 +9,10 @@ in {
enable = lib.mkEnableOption ''
a secure, end-to-end encrypted, and privacy respecting sync for your contacts, calendars, tasks and notes.
'';
+ secretFile = lib.mkOption {
+ type = lib.types.path;
+ description = "The age encrypted globale etebase secretfile passed to agenix";
+ };
};
config = lib.mkIf cfg.enable {
@@ -25,13 +29,13 @@ in {
};
age.secrets.etebase-server = {
- file = ./secret_file.age;
+ file = cfg.secretFile;
mode = "700";
owner = "etebase-server";
group = "etebase-server";
};
- environment.persistence."/srv".directories = [
+ vhack.persist.directories = [
{
directory = "/var/lib/etebase-server";
user = "etebase-server";
@@ -41,26 +45,14 @@ in {
];
services.nginx = {
- enable = true;
- recommendedTlsSettings = true;
- recommendedOptimisation = true;
- recommendedGzipSettings = true;
- recommendedProxySettings = true;
-
virtualHosts = {
"etebase.vhack.eu" = {
- enableACME = true;
- forceSSL = true;
-
locations = {
# TODO: Maybe fix permissions to use pregenerated static files which would
# improve performance.
#"/static" = {
# root = config.services.etebase-server.settings.global.static_root;
#};
- "/" = {
- proxyPass = "http://127.0.0.1:${builtins.toString config.services.etebase-server.port}";
- };
};
serverAliases = [
"dav.vhack.eu"
@@ -68,5 +60,11 @@ in {
};
};
};
+ vhack.anubis.instances."etebase.vhack.eu".target = "http://127.0.0.1:${builtins.toString config.services.etebase-server.port}";
+
+ users = {
+ users.etebase-server.uid = config.vhack.constants.ids.uids.etebase-server;
+ groups.etebase-server.gid = config.vhack.constants.ids.gids.etebase-server;
+ };
};
}
diff --git a/modules/by-name/fa/fail2ban/module.nix b/modules/vhack/fa/fail2ban/module.nix
index c619ef9..c619ef9 100644
--- a/modules/by-name/fa/fail2ban/module.nix
+++ b/modules/vhack/fa/fail2ban/module.nix
diff --git a/modules/by-name/gi/git-server/css.nix b/modules/vhack/gi/git-server/css.nix
index 7d0ad06..7d0ad06 100644
--- a/modules/by-name/gi/git-server/css.nix
+++ b/modules/vhack/gi/git-server/css.nix
diff --git a/modules/by-name/gi/git-server/module.nix b/modules/vhack/gi/git-server/module.nix
index db35897..3e2c848 100644
--- a/modules/by-name/gi/git-server/module.nix
+++ b/modules/vhack/gi/git-server/module.nix
@@ -8,8 +8,7 @@
cgitCss = import ./css.nix {
inherit pkgs;
- cgitPkg =
- config.services.cgit."${cfg.domain}".package;
+ cgitPkg = config.services.cgit."${cfg.domain}".package;
};
in {
options.vhack.git-server = {
@@ -84,10 +83,16 @@ in {
cgit."${cfg.domain}" = {
enable = true;
- package = pkgs.cgit-pink;
+ package = pkgs.cgit;
scanPath = "${config.services.gitolite.dataDir}/repositories";
user = "git";
group = "git";
+
+ # Don't bypass `cgit` when performing a http only clone.
+ # This is slightly slower, but we don't need to worry about the access
+ # restrictions also being by-passed.
+ gitHttpBackend.enable = false;
+
settings = {
branch-sort = "age";
diff --git a/modules/by-name/im/impermanence/module.nix b/modules/vhack/im/impermanence/module.nix
index 1c916e2..1c916e2 100644
--- a/modules/by-name/im/impermanence/module.nix
+++ b/modules/vhack/im/impermanence/module.nix
diff --git a/modules/by-name/ng/nginx/module.nix b/modules/vhack/ng/nginx/module.nix
index 39919c9..1317d4d 100644
--- a/modules/by-name/ng/nginx/module.nix
+++ b/modules/vhack/ng/nginx/module.nix
@@ -6,7 +6,7 @@
mkRedirect = _: value: {
forceSSL = true;
enableACME = true;
- locations."/".return = "301 ${value}";
+ locations."/".return = "301 ${value}$request_uri";
};
redirects = builtins.mapAttrs mkRedirect cfg.redirects;
@@ -18,15 +18,6 @@ in {
a default nginx config.
'';
- selfsign = lib.mkOption {
- type = lib.types.bool;
- default = false;
- description = ''
- Whether to selfsign the acme certificates. This should only
- really be useful for tests.
- '';
- };
-
redirects = lib.mkOption {
type = lib.types.attrsOf lib.types.str;
default = {};
@@ -39,12 +30,33 @@ in {
};
config = lib.mkIf cfg.enable {
- vhack.persist.directories = [
- "/var/lib/acme"
- ];
+ vhack = {
+ persist.directories = [
+ "/var/lib/acme"
+ ];
+
+ monitoring.prometheus = {
+ sources = [
+ {
+ name = "nginx";
+ target = "127.0.0.1:${toString config.services.prometheus.exporters.nginx.port}";
+ }
+ ];
+ };
+ };
+
+ services.prometheus.exporters.nginx = {
+ enable = true;
+ port = 9111;
+ listenAddress = "127.0.0.1";
+ scrapeUri = "http://localhost:80/nginx_status";
+ };
users = {
- users.acme.uid = config.vhack.constants.ids.uids.acme;
+ users.acme = {
+ uid = config.vhack.constants.ids.uids.acme;
+ group = "acme";
+ };
groups.acme.gid = config.vhack.constants.ids.gids.acme;
};
@@ -53,10 +65,6 @@ in {
defaults = {
email = "admin@vhack.eu";
webroot = "/var/lib/acme/acme-challenge";
-
- # Avoid spamming the acme server, if we run in a test, and only really want self-signed
- # certificates
- server = lib.mkIf cfg.selfsign "https://127.0.0.1";
};
};
@@ -65,16 +73,11 @@ in {
};
services.nginx = {
enable = true;
- virtualHosts = redirects;
- # FIXME(@bpeetz): Migrate to a host. <2024-12-25>
- # {
- # "gallery.s-schoeffel.de" = {
- # forceSSL = true;
- # enableACME = true;
- # root = "/srv/gallery.s-schoeffel.de";
- # };
- # }
+ # Enable the status page for the prometheus exporter.
+ statusPage = lib.mkIf config.services.prometheus.enable true;
+
+ virtualHosts = redirects;
};
};
}
diff --git a/modules/by-name/ni/nix-sync/internal_module.nix b/modules/vhack/ni/nix-sync/internal_module.nix
index 4e28586..4e28586 100644
--- a/modules/by-name/ni/nix-sync/internal_module.nix
+++ b/modules/vhack/ni/nix-sync/internal_module.nix
diff --git a/modules/by-name/ns/nscd/module.nix b/modules/vhack/ns/nscd/module.nix
index 428ae3b..428ae3b 100644
--- a/modules/by-name/ns/nscd/module.nix
+++ b/modules/vhack/ns/nscd/module.nix
diff --git a/modules/by-name/oo/oomd/module.nix b/modules/vhack/oo/oomd/module.nix
index 3b39236..3b39236 100644
--- a/modules/by-name/oo/oomd/module.nix
+++ b/modules/vhack/oo/oomd/module.nix
diff --git a/modules/by-name/op/openssh/module.nix b/modules/vhack/op/openssh/module.nix
index 83aeadf..83aeadf 100644
--- a/modules/by-name/op/openssh/module.nix
+++ b/modules/vhack/op/openssh/module.nix
diff --git a/modules/by-name/pe/peertube/module.nix b/modules/vhack/pe/peertube/module.nix
index 29d1d07..e65e0b5 100644
--- a/modules/by-name/pe/peertube/module.nix
+++ b/modules/vhack/pe/peertube/module.nix
@@ -1,7 +1,6 @@
{
config,
lib,
- pkgs,
...
}: let
cfg = config.vhack.peertube;
@@ -10,6 +9,14 @@ in {
enable = lib.mkEnableOption ''
the peertube video platform.
'';
+ peertubeGeneral = lib.mkOption {
+ type = lib.types.path;
+ description = "The age encrypted general secret file passed to agenix";
+ };
+ smtpPasswordFile = lib.mkOption {
+ type = lib.types.path;
+ description = "The age encrypted smtp password file passed to agenix";
+ };
};
config = lib.mkIf cfg.enable {
@@ -22,7 +29,7 @@ in {
listenWeb = 443;
smtp = {
- createLocally = true;
+ createLocally = false;
passwordFile = "${config.age.secrets.peertubeSmtp.path}";
};
database = {
@@ -66,10 +73,8 @@ in {
smtp = let
emailAddress = "peertube@vhack.eu";
in {
- sendmail = "${pkgs.postfix}/bin/sendmail";
-
- transport = "sendmail";
- hostname = "server1.vhack.eu";
+ transport = "smtp";
+ hostname = "mail.foss-syndicate.org";
port = 587;
username = emailAddress;
tls = true;
@@ -88,20 +93,20 @@ in {
age.secrets = {
peertubeGeneral = {
- file = ./secrets/general.age;
+ file = cfg.peertubeGeneral;
mode = "700";
owner = "peertube";
group = "peertube";
};
peertubeSmtp = {
- file = ./secrets/smtp.age;
+ file = cfg.smtpPasswordFile;
mode = "700";
owner = "peertube";
group = "peertube";
};
};
- environment.persistence."/srv".directories = [
+ vhack.persist.directories = [
{
directory = "/var/lib/peertube";
user = "peertube";
@@ -109,5 +114,11 @@ in {
mode = "0700";
}
];
+ users = {
+ users.peertube.uid = config.vhack.constants.ids.uids.peertube;
+ groups.peertube.gid = config.vhack.constants.ids.gids.peertube;
+ users.redis-peertube.uid = config.vhack.constants.ids.uids.redis-peertube;
+ groups.redis-peertube.gid = config.vhack.constants.ids.gids.redis-peertube;
+ };
};
}
diff --git a/modules/by-name/po/postgresql/module.nix b/modules/vhack/po/postgresql/module.nix
index 319c3ac..319c3ac 100644
--- a/modules/by-name/po/postgresql/module.nix
+++ b/modules/vhack/po/postgresql/module.nix
diff --git a/modules/by-name/re/resolvconf/module.nix b/modules/vhack/re/resolvconf/module.nix
index ff99696..ff99696 100644
--- a/modules/by-name/re/resolvconf/module.nix
+++ b/modules/vhack/re/resolvconf/module.nix
diff --git a/modules/by-name/ru/rust-motd/module.nix b/modules/vhack/ru/rust-motd/module.nix
index a6998f4..bf23843 100644
--- a/modules/by-name/ru/rust-motd/module.nix
+++ b/modules/vhack/ru/rust-motd/module.nix
@@ -19,6 +19,13 @@
|| v.openssh.authorizedKeys.keyFiles != []
);
userList = builtins.mapAttrs (n: v: 2) (lib.filterAttrs pred config.users.users);
+
+ bannerFile =
+ pkgs.runCommandLocal "banner-file" {
+ nativeBuildInputs = [pkgs.figlet];
+ } ''
+ echo "${config.system.name}" | figlet -f slant > "$out"
+ '';
in {
options.vhack.rust-motd = {
enable = lib.mkEnableOption "rust-motd";
@@ -49,25 +56,22 @@ in {
banner = {
color = "red";
- command = "${pkgs.hostname}/bin/hostname | ${pkgs.figlet}/bin/figlet -f slant";
- # if you don't want a dependency on figlet, you can generate your
- # banner however you want, put it in a file, and then use something like:
- # command = "cat banner.txt"
+ # Avoid some runtime dependencies.
+ command = "cat ${bannerFile}";
+ };
+
+ cg_stats = {
+ state_file = "/var/lib/rust-motd/cg_stats_state";
+ threshold = 0.02; # When to start generating output for a cgroup
+ };
+ load_avg = {
+ format = "Load (1, 5, 15 min.): {one:.02}, {five:.02}, {fifteen:.02}";
};
uptime = {
prefix = "Uptime:";
};
- # ssl_certificates = {
- # sort_method = "manual";
- #
- # certs = {
- # "server1.vhack.eu" = "/var/lib/acme/server1.vhack.eu/cert.pem";
- # "vhack.eu" = "/var/lib/acme/vhack.eu/cert.pem";
- # };
- # };
-
filesystems = {
root = "/";
persistent = "/srv";
@@ -79,7 +83,7 @@ in {
swap_pos = "beside"; # or "below" or "none"
};
- fail2_ban = {
+ fail_2_ban = {
jails = ["sshd"]; #, "anotherjail"]
};
diff --git a/modules/by-name/us/users/module.nix b/modules/vhack/us/users/module.nix
index a197b13..e029130 100644
--- a/modules/by-name/us/users/module.nix
+++ b/modules/vhack/us/users/module.nix
@@ -27,20 +27,22 @@
};
};
- extraUsers = lib.listToAttrs (builtins.map mkUser [
- {
- name = "soispha";
- password = "$y$jFT$3.8XmUyukZvpExMUxDZkI.$IVrJgm8ysNDF/0vDD2kF6w73ozXgr1LMVRNN4Bq7pv1";
- sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIME4ZVa+IoZf6T3U08JG93i6QIAJ4amm7mkBzO14JSkz cardno:000F_18F83532";
- uid = 1000;
- }
- {
- name = "sils";
- password = "$y$jFT$KpFnahVCE9JbE.5P3us8o.$ZzSxCusWqe3sL7b6DLgOXNNUf114tiiptM6T8lDxtKC";
- sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAe4o1PM6VasT3KZNl5NYvgkkBrPOg36dqsywd10FztS openpgp:0x21D20D6A";
- uid = 1001;
- }
- ]);
+ extraUsers = lib.listToAttrs (
+ builtins.map mkUser [
+ {
+ name = "soispha";
+ password = "$y$jFT$3.8XmUyukZvpExMUxDZkI.$IVrJgm8ysNDF/0vDD2kF6w73ozXgr1LMVRNN4Bq7pv1";
+ sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIME4ZVa+IoZf6T3U08JG93i6QIAJ4amm7mkBzO14JSkz cardno:000F_18F83532";
+ uid = 1000;
+ }
+ {
+ name = "jaki";
+ password = "$y$jFT$KpFnahVCE9JbE.5P3us8o.$ZzSxCusWqe3sL7b6DLgOXNNUf114tiiptM6T8lDxtKC";
+ sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILn7Oumr5IYtTTIKRFvDnofGXXiDLBQE9jVF+7UE+4G5 vhack.eu";
+ uid = 1001;
+ }
+ ]
+ );
in {
options.vhack.users = {
enable = lib.mkEnableOption "user setup";