aboutsummaryrefslogtreecommitdiffstats
path: root/modules/by-name
diff options
context:
space:
mode:
Diffstat (limited to 'modules/by-name')
-rw-r--r--modules/by-name/ba/back/module.nix121
-rw-r--r--modules/by-name/ba/backup/module.nix91
-rw-r--r--modules/by-name/co/constants/module.nix68
-rw-r--r--modules/by-name/co/coredump/module.nix18
-rw-r--r--modules/by-name/dh/dhcpcd/module.nix18
-rw-r--r--modules/by-name/di/disko/module.nix78
-rw-r--r--modules/by-name/et/etesync/module.nix80
-rw-r--r--modules/by-name/fa/fail2ban/module.nix58
-rw-r--r--modules/by-name/ga/gallery/module.nix22
-rw-r--r--modules/by-name/gi/git-server/css.nix119
-rw-r--r--modules/by-name/gi/git-server/module.nix188
-rw-r--r--modules/by-name/im/impermanence/module.nix30
-rw-r--r--modules/by-name/in/invidious-router/module.nix70
-rw-r--r--modules/by-name/ma/mail/module.nix167
-rw-r--r--modules/by-name/ma/mastodon/module.nix123
-rw-r--r--modules/by-name/ma/mastodon/patches/0001-feat-treewide-Increase-character-limit-to-5000-in-me.patch40
-rw-r--r--modules/by-name/ma/matrix/module.nix171
-rw-r--r--modules/by-name/mi/miniflux/module.nix55
-rw-r--r--modules/by-name/mu/murmur/module.nix80
-rw-r--r--modules/by-name/ng/nginx/module.nix71
-rw-r--r--modules/by-name/ni/nix-sync/internal_module.nix299
-rw-r--r--modules/by-name/ni/nix-sync/module.nix104
-rw-r--r--modules/by-name/ni/nixconfig/module.nix28
-rw-r--r--modules/by-name/ns/nscd/module.nix25
-rw-r--r--modules/by-name/oo/oomd/module.nix19
-rw-r--r--modules/by-name/op/openssh/module.nix60
-rw-r--r--modules/by-name/pe/peertube/module.nix124
-rw-r--r--modules/by-name/po/postgresql/module.nix19
-rw-r--r--modules/by-name/re/redlib/module.nix44
-rw-r--r--modules/by-name/re/resolvconf/module.nix16
-rw-r--r--modules/by-name/ru/rust-motd/module.nix92
-rw-r--r--modules/by-name/us/users/module.nix82
32 files changed, 0 insertions, 2580 deletions
diff --git a/modules/by-name/ba/back/module.nix b/modules/by-name/ba/back/module.nix
deleted file mode 100644
index 520acdb..0000000
--- a/modules/by-name/ba/back/module.nix
+++ /dev/null
@@ -1,121 +0,0 @@
-{
- config,
- lib,
- vhackPackages,
- pkgs,
- ...
-}: let
- cfg = config.vhack.back;
-
- mkConfigFile = repoPath: domain:
- (pkgs.formats.json {}).generate "config.json"
- {
- inherit (cfg) source_code_repository_url;
- repository_path = repoPath;
- root_url = "https://${domain}";
- };
-
- mkUnit = repoPath: port: domain: {
- description = "Back service for ${repoPath}";
- wants = ["network-online.target"];
- after = ["network-online.target"];
- wantedBy = ["default.target"];
-
- environment = {
- ROCKET_PORT = builtins.toString port;
- };
-
- serviceConfig = {
- ExecStart = "${lib.getExe vhackPackages.back} ${mkConfigFile repoPath domain}";
-
- # Ensure that the service can read the repository
- # FIXME(@bpeetz): This has the implied assumption, that all the exposed git
- # repositories are readable for the git group. This should not be necessary. <2024-12-23>
- User = "git";
- Group = "git";
-
- DynamicUser = true;
- Restart = "always";
-
- # Sandboxing
- ProtectSystem = "strict";
- ProtectHome = true;
- PrivateTmp = true;
- PrivateDevices = true;
- ProtectHostname = true;
- ProtectClock = true;
- ProtectKernelTunables = true;
- ProtectKernelModules = true;
- ProtectKernelLogs = true;
- ProtectControlGroups = true;
- RestrictAddressFamilies = ["AF_UNIX" "AF_INET" "AF_INET6"];
- RestrictNamespaces = true;
- LockPersonality = true;
- MemoryDenyWriteExecute = true;
- RestrictRealtime = true;
- RestrictSUIDSGID = true;
- RemoveIPC = true;
- PrivateMounts = true;
- # System Call Filtering
- SystemCallArchitectures = "native";
- SystemCallFilter = ["~@cpu-emulation @debug @keyring @mount @obsolete @privileged @setuid"];
- };
- };
-
- mkVirtalHost = port: {
- locations."/".proxyPass = "http://127.0.0.1:${builtins.toString port}";
-
- enableACME = true;
- forceSSL = true;
- };
-
- services =
- lib.mapAttrs' (gitPath: config: {
- name = builtins.replaceStrings ["/"] ["_"] "back-${config.domain}";
- value = mkUnit gitPath config.port config.domain;
- })
- cfg.repositories;
-
- virtualHosts =
- lib.mapAttrs' (gitPath: config: {
- name = config.domain;
- value = mkVirtalHost config.port;
- })
- cfg.repositories;
-in {
- options.vhack.back = {
- enable = lib.mkEnableOption "Back issue tracker (inspired by tvix's panettone)";
-
- source_code_repository_url = lib.mkOption {
- description = "The url to the source code of this instance of back";
- default = "https://git.foss-syndicate.org/vhack.eu/nixos-server/tree/pkgs/by-name/ba/back";
- type = lib.types.str;
- };
-
- repositories = lib.mkOption {
- description = "An attibute set of repos to launch `back` services for.";
- type = lib.types.attrsOf (lib.types.submodule {
- options = {
- enable = (lib.mkEnableOption "`back` for this repository.") // {default = true;};
- domain = lib.mkOption {
- type = lib.types.str;
- description = "The domain to host this `back` instance on.";
- };
- port = lib.mkOption {
- type = lib.types.port;
-
- # TODO: This _should_ be an implementation detail, but I've no real approach to
- # automatically generate them without encountering weird bugs. <2024-12-23>
- description = "The port to use for this back instance. This must be unique.";
- };
- };
- });
- default = {};
- };
- };
-
- config = lib.mkIf cfg.enable {
- systemd = {inherit services;};
- services.nginx = {inherit virtualHosts;};
- };
-}
diff --git a/modules/by-name/ba/backup/module.nix b/modules/by-name/ba/backup/module.nix
deleted file mode 100644
index 856a1c3..0000000
--- a/modules/by-name/ba/backup/module.nix
+++ /dev/null
@@ -1,91 +0,0 @@
-{
- config,
- pkgs,
- lib,
- ...
-}: let
- cfg = config.vhack.backup;
- snapshots = "/srv/snapshots";
- postgresUser = "postgres";
-in {
- options.vhack.backup = {
- enable = lib.mkEnableOption "backups with restic";
- user = lib.mkOption {
- type = lib.types.str;
- description = "The storagebox-user to use";
- example = "u384702-sub2";
- };
- privateSshKey = lib.mkOption {
- type = lib.types.path;
- description = "The age-encrypted ssh-key, passed to agenix";
- };
- privatePassword = lib.mkOption {
- type = lib.types.path;
- description = "The age-encrypted restic password, passed to agenix";
- };
- };
- config = lib.mkIf cfg.enable {
- vhack.persist.directories = [
- {
- directory = "/root/.ssh";
- user = "root";
- group = "root";
- mode = "0700";
- }
- ];
- age.secrets = {
- resticpass = {
- file = cfg.privatePassword;
- mode = "0700";
- owner = "root";
- group = "root";
- };
- resticssh = {
- file = cfg.privateSshKey;
- mode = "0700";
- owner = "root";
- group = "root";
- };
- };
- services.restic.backups = {
- storagebox = {
- initialize = true;
- backupPrepareCommand = ''
- ${pkgs.sudo}/bin/sudo -u ${postgresUser} ${pkgs.postgresql}/bin/pg_dumpall --clean --if-exists --quote-all-identifiers > /srv/db_backup.sql
-
- [ -d /srv/snapshots ] || ${pkgs.btrfs-progs}/bin/btrfs subvolume create /srv/snapshots;
- [ -d /srv/snapshots/srv ] && ${pkgs.btrfs-progs}/bin/btrfs subvolume delete /srv/snapshots/srv;
- ${pkgs.btrfs-progs}/bin/btrfs subvolume snapshot -r /srv /srv/snapshots/srv;
-
- # dump() {
- # # compression:
- # # pg_dump -F t -v "$1" | xz -z -9 -e -T0 > "db_$1.tar.xz"
- # pg_dump -v "$1" > "db_$1.tar.xz"
- # }
- # # List all databases, and dump each of them in its own file
- # # psql --list --csv | while read -r line; do echo "$line" | grep ','; done | while IFS=, read -r name _; do echo "$name"; done | sed '1d' | while read -r db_name; do dump "$db_name"; done
- '';
- paths = [
- snapshots
- ];
- exclude = [
- ".snapshots"
- "/var/lib/postgresql" # included in the db dump
- ];
- extraBackupArgs = [
- "--verbose" # spam log
- ];
- passwordFile = config.age.secrets.resticpass.path;
- extraOptions = [
- "rclone.program='ssh -p 23 ${cfg.user}@${cfg.user}.your-storagebox.de -i ${config.age.secrets.resticssh.path}'"
- ];
- repository = "rclone: "; # There is only one repository served
- timerConfig = {
- Requires = "network-online.target";
- OnCalendar = "daily";
- Persistent = true;
- };
- };
- };
- };
-}
diff --git a/modules/by-name/co/constants/module.nix b/modules/by-name/co/constants/module.nix
deleted file mode 100644
index fed14d3..0000000
--- a/modules/by-name/co/constants/module.nix
+++ /dev/null
@@ -1,68 +0,0 @@
-# This file is inspired by the `nixos/modules/misc/ids.nix`
-# file in nixpkgs.
-{lib, ...}: {
- options.vhack.constants = {
- ids.uids = lib.mkOption {
- internal = true;
- description = ''
- The user IDs used in the vhack.eu nixos config.
- '';
- type = lib.types.attrsOf lib.types.int;
- };
- ids.gids = lib.mkOption {
- internal = true;
- description = ''
- The group IDs used in the vhack.eu nixos config.
- '';
- type = lib.types.attrsOf lib.types.int;
- };
- };
-
- config.vhack.constants = {
- ids.uids = {
- acme = 328;
- dhcpcd = 329;
- nscd = 330;
- sshd = 331;
- systemd-oom = 332;
- nix-sync = 334;
- redis-peertube = 990;
- peertube = 992; # TODO Sort correctly
- mastodon = 996;
- redis-mastodon = 991;
- matrix-synapse = 224;
- mautrix-whatsapp = 225;
- knot-resolver = 997;
- redis-rspamd = 989;
- rspamd = 225;
- opendkim = 221;
- virtualMail = 5000;
- etebase-server = 998;
-
- # As per the NixOS file, the uids should not be greater or equal to 400;
- };
- ids.gids = {
- acme = 328;
- dhcpcd = 329;
- nscd = 330;
- sshd = 331;
- systemd-oom = 332;
- resolvconf = 333; # This group is not matched to an user?
- nix-sync = 334;
- systemd-coredump = 151; # matches systemd-coredump user
- redis-peertube = 990;
- peertube = 992;
- mastodon = 996;
- redis-mastodon = 991;
- matrix-synapse = 224;
- knot-resolver = 997;
- redis-rspamd = 989;
- rspamd = 225;
- opendkim = 221;
- virtualMail = 5000;
- etebase-server = 998;
-
- # The gid should match the uid. Thus should not be >= 400;
- };
- };
-}
diff --git a/modules/by-name/co/coredump/module.nix b/modules/by-name/co/coredump/module.nix
deleted file mode 100644
index ce28ed9..0000000
--- a/modules/by-name/co/coredump/module.nix
+++ /dev/null
@@ -1,18 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.systemd.coredump;
-in {
- options.vhack.systemd.coredump = {
- # NOTE(@bpeetz): Enabled by default, because that is what NixOS also does. <2024-12-25>
- enable = (lib.mkEnableOption "oomd") // {default = true;};
- };
-
- config = lib.mkIf cfg.enable {
- users = {
- groups.systemd-coredump.gid = config.vhack.constants.ids.gids.systemd-coredump;
- };
- };
-}
diff --git a/modules/by-name/dh/dhcpcd/module.nix b/modules/by-name/dh/dhcpcd/module.nix
deleted file mode 100644
index 0e35af3..0000000
--- a/modules/by-name/dh/dhcpcd/module.nix
+++ /dev/null
@@ -1,18 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.dhcpcd;
-in {
- options.vhack.dhcpcd = {
- enable = (lib.mkEnableOption "dhcpcd") // {default = config.networking.dhcpcd.enable;};
- };
-
- config = lib.mkIf cfg.enable {
- users = {
- users.dhcpcd.uid = config.vhack.constants.ids.uids.dhcpcd;
- groups.dhcpcd.gid = config.vhack.constants.ids.gids.dhcpcd;
- };
- };
-}
diff --git a/modules/by-name/di/disko/module.nix b/modules/by-name/di/disko/module.nix
deleted file mode 100644
index b4fc3c8..0000000
--- a/modules/by-name/di/disko/module.nix
+++ /dev/null
@@ -1,78 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.disko;
-
- defaultMountOptions = ["compress-force=zstd:15" "noatime"];
-in {
- options.vhack.disko = {
- enable = lib.mkEnableOption "disk configuration via disko";
-
- disk = lib.mkOption {
- type = lib.types.path;
- example = "/dev/disk/by-id/ata-WDC_WD10SDRW-11A0XS0_WD-WXP2A901KJN5";
- description = "Path to the main disk";
- };
- };
-
- config = lib.mkIf cfg.enable {
- disko.devices = {
- disk.main = {
- type = "disk";
- device = cfg.disk;
-
- content = {
- type = "gpt";
- partitions = {
- boot = {
- size = "1M";
- type = "EF02"; # for grub MBR
- };
- root = {
- size = "100%";
- content = {
- type = "btrfs";
- extraArgs = ["-f" "--label nixos"]; # f: Override existing partitions
-
- subvolumes = {
- "/nix" = {
- mountpoint = "/nix";
- mountOptions = defaultMountOptions;
- };
- "/srv" = {
- mountpoint = "/srv";
- mountOptions = defaultMountOptions;
- };
- "/srv/.snapshots" = {
- mountpoint = "/srv/.snapshots";
- mountOptions = defaultMountOptions;
- };
- "/boot" = {
- mountpoint = "/boot";
- mountOptions = defaultMountOptions;
- };
- };
- };
- };
- };
- };
- };
-
- nodev."/" = {
- fsType = "tmpfs";
- mountOptions = ["defaults" "size=6G" "mode=755"];
- };
- };
-
- fileSystems = {
- "/srv" = {
- neededForBoot = true;
- };
- "/boot" = {
- neededForBoot = true;
- };
- };
- };
-}
diff --git a/modules/by-name/et/etesync/module.nix b/modules/by-name/et/etesync/module.nix
deleted file mode 100644
index bcabc8a..0000000
--- a/modules/by-name/et/etesync/module.nix
+++ /dev/null
@@ -1,80 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.etesync;
-in {
- options.vhack.etesync = {
- enable = lib.mkEnableOption ''
- a secure, end-to-end encrypted, and privacy respecting sync for your contacts, calendars, tasks and notes.
- '';
- secretFile = lib.mkOption {
- type = lib.types.path;
- description = "The age encrypted globale etebase secretfile passed to agenix";
- };
- };
-
- config = lib.mkIf cfg.enable {
- services.etebase-server = {
- enable = true;
- port = 8001;
- settings = {
- global.secret_file = "${config.age.secrets.etebase-server.path}";
- allowed_hosts = {
- allowed_host1 = "etebase.vhack.eu";
- allowed_host2 = "dav.vhack.eu";
- };
- };
- };
-
- age.secrets.etebase-server = {
- file = cfg.secretFile;
- mode = "700";
- owner = "etebase-server";
- group = "etebase-server";
- };
-
- vhack.persist.directories = [
- {
- directory = "/var/lib/etebase-server";
- user = "etebase-server";
- group = "etebase-server";
- mode = "0700";
- }
- ];
-
- services.nginx = {
- enable = true;
- recommendedTlsSettings = true;
- recommendedOptimisation = true;
- recommendedGzipSettings = true;
- recommendedProxySettings = true;
-
- virtualHosts = {
- "etebase.vhack.eu" = {
- enableACME = true;
- forceSSL = true;
-
- locations = {
- # TODO: Maybe fix permissions to use pregenerated static files which would
- # improve performance.
- #"/static" = {
- # root = config.services.etebase-server.settings.global.static_root;
- #};
- "/" = {
- proxyPass = "http://127.0.0.1:${builtins.toString config.services.etebase-server.port}";
- };
- };
- serverAliases = [
- "dav.vhack.eu"
- ];
- };
- };
- };
- users = {
- users.etebase-server.uid = config.vhack.constants.ids.uids.etebase-server;
- groups.etebase-server.gid = config.vhack.constants.ids.gids.etebase-server;
- };
- };
-}
diff --git a/modules/by-name/fa/fail2ban/module.nix b/modules/by-name/fa/fail2ban/module.nix
deleted file mode 100644
index c619ef9..0000000
--- a/modules/by-name/fa/fail2ban/module.nix
+++ /dev/null
@@ -1,58 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.fail2ban;
-in {
- options.vhack.fail2ban = {
- enable = lib.mkEnableOption "fail2ban";
- };
-
- config = lib.mkIf cfg.enable {
- vhack.persist.directories = [
- {
- directory = "/var/lib/fail2ban";
- # TODO: Fail2ban should probably run under a dedicated `fail2ban` user. <2024-12-25>
- user = "root";
- group = "root";
- mode = "0700";
- }
- ];
-
- services.fail2ban = {
- enable = true;
- maxretry = 7; # ban after 7 failures
- daemonSettings = {
- Definition = {
- logtarget = "SYSLOG";
- socket = "/run/fail2ban/fail2ban.sock";
- pidfile = "/run/fail2ban/fail2ban.pid";
- dbfile = "/var/lib/fail2ban/db.sqlite3";
- };
- };
- bantime-increment = {
- enable = true;
- rndtime = "8m";
- overalljails = true;
- multipliers = "2 4 16 128 256";
- maxtime = "72h";
- };
- jails = {
- dovecot = ''
- # block IPs which failed to log-in
- # aggressive mode add blocking for aborted connections
- enabled = true
- filter = dovecot[mode=aggressive]
- maxretry = 2
- '';
- postfix = ''
- enabled = true
- filter = postfix[mode=aggressive]
- findtime = 600
- maxretry = 3
- '';
- };
- };
- };
-}
diff --git a/modules/by-name/ga/gallery/module.nix b/modules/by-name/ga/gallery/module.nix
deleted file mode 100644
index a5237e6..0000000
--- a/modules/by-name/ga/gallery/module.nix
+++ /dev/null
@@ -1,22 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.sils.gallery;
-in {
- options.sils.gallery = {
- enable = lib.mkEnableOption "a stateful static gallery site";
- domain = lib.mkOption {
- type = lib.types.str;
- };
- };
- config = lib.mkIf cfg.enable {
- vhack.nginx.enable = true;
- services.nginx.virtualHosts."${cfg.domain}" = {
- forceSSL = true;
- enableACME = true;
- root = "/srv/${cfg.domain}";
- };
- };
-}
diff --git a/modules/by-name/gi/git-server/css.nix b/modules/by-name/gi/git-server/css.nix
deleted file mode 100644
index 7d0ad06..0000000
--- a/modules/by-name/gi/git-server/css.nix
+++ /dev/null
@@ -1,119 +0,0 @@
-{
- cgitPkg,
- pkgs,
-}: let
- /*
- Adapted from `https://git.qyliss.net/nixlib/sys/atuin.nix`, originally distributed under
- the MIT license.
- */
- cgitCss =
- pkgs.runCommand "cgit-extra.css" {
- licenseHeader = ''
- /*
- * This program is free software: you can redistribute it and/or modify
- * it under the terms of the GNU General Public License v2 as published
- * by the Free Software Foundation.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- * GNU General Public License for more details.
- *
- * See <https://www.gnu.org/licenses/>.
- */
-
- '';
-
- # Adapted from
- # <https://git.causal.agency/src/plain/www/git.causal.agency/custom.css>,
- # distributed as a Larger Work under a Secondary License,
- # as permitted by the terms of the
- # Mozilla Public License Version 2.0.
- extraCss = ''
- * { line-height: 1.25em; }
-
- article {
- font-family: sans-serif;
- max-width: 70ch;
- margin-left: auto;
- margin-right: auto;
- }
-
- div#cgit {
- margin: auto;
- font-family: monospace;
- -moz-tab-size: 4;
- tab-size: 4;
- display: table;
- }
-
- div#cgit table#header {
- margin-left: auto;
- margin-right: auto;
- }
- div#cgit table#header td.logo {
- display: none;
- }
- div#cgit table#header td.main {
- font-size: 1em;
- font-weight: bold;
- }
- div#cgit table#header td.sub {
- border-top: none;
- }
- div#cgit table.tabs {
- margin-left: auto;
- margin-right: auto;
- border-bottom: none;
- }
- div#cgit div.content {
- border-bottom: none;
- min-width: 108ch;
- }
- div#cgit div.content div#summary {
- display: table;
- margin-left: auto;
- margin-right: auto;
- }
- div#cgit div.notes {
- border: none;
- background: transparent;
- padding: 0;
- }
- div#cgit table.list {
- margin-left: auto;
- margin-right: auto;
- }
- div#cgit table.list th a {
- color: inherit;
- }
- div#cgit table.list tr:nth-child(even) {
- background: inherit;
- }
- div#cgit table.list tr:hover {
- background: inherit;
- }
- div#cgit table.list tr.nohover-highlight:hover:nth-child(even) {
- background: inherit;
- }
- div#cgit div.footer {
- font-size: 1em;
- margin-top: 0;
- }
-
- div#cgit table.blob td.linenumbers:nth-last-child(3) {
- display: none;
- }
-
- div#cgit table.blob td.linenumbers a:target {
- color: goldenrod;
- text-decoration: underline;
- outline: none;
- }
- '';
- passAsFile = ["licenseHeader" "extraCss"];
- } ''
- cat $licenseHeaderPath ${cgitPkg}/cgit/cgit.css $extraCssPath > $out
- '';
-in
- cgitCss
diff --git a/modules/by-name/gi/git-server/module.nix b/modules/by-name/gi/git-server/module.nix
deleted file mode 100644
index db35897..0000000
--- a/modules/by-name/gi/git-server/module.nix
+++ /dev/null
@@ -1,188 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}: let
- cfg = config.vhack.git-server;
-
- cgitCss = import ./css.nix {
- inherit pkgs;
- cgitPkg =
- config.services.cgit."${cfg.domain}".package;
- };
-in {
- options.vhack.git-server = {
- enable = lib.mkEnableOption ''
- a lightweight git-server, realised with cgit and gitolite.
- '';
-
- domain = lib.mkOption {
- type = lib.types.str;
- default = "git.vhack.eu";
- description = ''
- The domain this git instance will run under.
- '';
- };
-
- gitolite = {
- adminPubkey = lib.mkOption {
- description = ''
- The initial key to use for gitolite. This will only be used for the initial
- clone of the `gitolite-admin` repository.
- '';
- type = lib.types.str;
- default = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAe4o1PM6VasT3KZNl5NYvgkkBrPOg36dqsywd10FztS openpgp:0x21D20D6A";
- };
- };
- };
-
- config = lib.mkIf cfg.enable {
- programs.git = {
- enable = true;
- config = {
- init = {
- defaultBranch = "main";
- };
- };
- };
-
- # Needed for the nginx proxy and the virtual host
- vhack = {
- nginx.enable = true;
- persist.directories = [
- {
- directory = "/var/lib/gitolite";
- user = "git";
- group = "git";
- mode = "0755";
- }
- ];
- };
-
- services = {
- gitolite = {
- inherit (cfg.gitolite) adminPubkey;
- enable = true;
- dataDir = "/var/lib/gitolite";
- user = "git";
- group = "git";
- extraGitoliteRc = ''
- $RC{UMASK} = 0027; # Enable group access, important for cgit.
-
- # Enable modifing git variables (for cgit.owner and such things)
- # These must be enable in the gitolite-admin repo (option user-configs = ...)
- push( @{$RC{ENABLE}}, 'config' );
- push( @{$RC{ENABLE}}, 'git-config' );
-
- push( @{$RC{ENABLE}}, 'expand-deny-messages' );
- push( @{$RC{ENABLE}}, 'Motd' );
-
- push( @{$RC{ENABLE}}, 'cgit' );
- '';
- };
-
- cgit."${cfg.domain}" = {
- enable = true;
- package = pkgs.cgit-pink;
- scanPath = "${config.services.gitolite.dataDir}/repositories";
- user = "git";
- group = "git";
- settings = {
- branch-sort = "age";
-
- # Allow users to download a repo checkout with these compression formats
- snapshots = ["tar.gz" "zip"];
- # The template used to generate the clone url for https clone.
- clone-url = [
- "https://${cfg.domain}/$CGIT_REPO_URL"
- "ssh://git@${cfg.domain}/$CGIT_REPO_URL"
- ];
- enable-http-clone = true;
-
- # TODO: We might want to add an logo and readme here <2024-07-31>
- # logo = "<url>";
- # root-readme = "/some/readme/file"
- root-desc = "The cgit instance of ${cfg.domain}!";
- root-title = "${
- lib.strings.toUpper (builtins.substring 0 1 cfg.domain) + builtins.substring 1 (builtins.stringLength cfg.domain) cfg.domain
- } cgit instace";
-
- # Set the default maximum statistics period. Valid values are "week",
- # "month", "quarter" and "year".
- max-stats = "week";
-
- readme = [
- ":README.md"
- ":readme.md"
- ":README.mkd"
- ":readme.mkd"
- ":README.rst"
- ":readme.rst"
- ":README.html"
- ":readme.html"
- ":README.htm"
- ":readme.htm"
- ":README.txt"
- ":readme.txt"
- ":README"
- ":readme"
- ":INSTALL.md"
- ":install.md"
- ":INSTALL.mkd"
- ":install.mkd"
- ":INSTALL.rst"
- ":install.rst"
- ":INSTALL.html"
- ":install.html"
- ":INSTALL.htm"
- ":install.htm"
- ":INSTALL.txt"
- ":install.txt"
- ":INSTALL"
- ":install"
- ];
-
- enable-blame = true;
- enable-commit-graph = true;
- enable-subject-links = true;
- enable-follow-links = true;
- enable-index-links = true;
- enable-index-owner = true;
-
- # NOTE: This allows cgit to take configuration from the bare git repositories:
- # All `repo.<key>` can be set by setting `cgit.<key>` in the git config. E.g.:
- # setting the owner (i.e. `repo.owner`) would be done by setting the
- # `cgit.owner` config. All repo options are outline in the cgitrc (5) man page.
- enable-git-config = true;
-
- # Remove the `.git` suffix from scanned repositories (this must be set _before_ `scan-path`)
- remove-suffix = true;
-
- css = "/custom_cgit.css";
-
- # This is a number of path elements to treat as section.
- # `-1` means that we treat the last element as name, all others as sections
- section-from-path = -1;
-
- project-list = "${config.services.gitolite.dataDir}/projects.list";
-
- # TODO: We might want to use the kernel.org `libravatar.lua` email-filter <2024-07-31>
- source-filter = "${config.services.cgit."${cfg.domain}".package}/lib/cgit/filters/syntax-highlighting.py";
- about-filter = "${config.services.cgit."${cfg.domain}".package}/lib/cgit/filters/about-formatting.sh";
- };
- };
-
- nginx.virtualHosts."${cfg.domain}" = {
- enableACME = true;
- forceSSL = true;
-
- locations = {
- "= /custom_cgit.css" = {
- alias = cgitCss.outPath;
- };
- };
- };
- };
- };
-}
diff --git a/modules/by-name/im/impermanence/module.nix b/modules/by-name/im/impermanence/module.nix
deleted file mode 100644
index 1c916e2..0000000
--- a/modules/by-name/im/impermanence/module.nix
+++ /dev/null
@@ -1,30 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.persist;
-in {
- options.vhack.persist = {
- enable = lib.mkEnableOption "impermanence";
-
- directories = lib.mkOption {
- description = "The list of directories to persist";
- type = lib.types.listOf (lib.types.coercedTo lib.types.str (d: {directory = d;}) (lib.types.attrsOf lib.types.anything));
- };
- };
-
- config = lib.mkIf cfg.enable {
- environment.persistence."/srv" = {
- hideMounts = true;
- directories =
- [
- "/etc/nixos"
- ]
- ++ cfg.directories;
- files = [
- "/etc/machine-id"
- ];
- };
- };
-}
diff --git a/modules/by-name/in/invidious-router/module.nix b/modules/by-name/in/invidious-router/module.nix
deleted file mode 100644
index f85a06c..0000000
--- a/modules/by-name/in/invidious-router/module.nix
+++ /dev/null
@@ -1,70 +0,0 @@
-{
- config,
- lib,
- pkgsUnstable,
- ...
-}: let
- cfg = config.vhack.invidious-router;
-in {
- options.vhack.invidious-router = {
- enable = lib.mkEnableOption "invidious-router";
- domain = lib.mkOption {
- type = lib.types.str;
- description = "The domain invidious-router should be served on";
- };
- extraDomains = lib.mkOption {
- type = lib.types.listOf lib.types.str;
- default = [];
- description = "Addtional domains invidious-router should be served on";
- };
- };
- config = lib.mkIf cfg.enable {
- services.invidious-router = {
- enable = true;
- package = pkgsUnstable.invidious-router;
- settings = {
- app = {
- listen = "127.0.0.1:8050";
- enable_youtube_fallback = false;
- reload_instance_list_interval = "60s";
- not_available_message = ''
- No available invidious instance found!
- [link]View this video on YouTube[/link], a proprietary
- platform that collects and uses your data without respecting
- your privacy.
- '';
- };
- api = {
- enabled = true;
- url = "https://api.invidious.io/instances.json";
- filter_regions = false;
- allowed_regions = [
- "AT"
- "DE"
- "CH"
- ];
- };
- healthcheck = {
- path = "/watch?v=uSvJaYxRoB4";
- allowed_status_codes = [
- 200
- ];
- timeout = "1s";
- interval = "10s";
- filter_by_response_time = {
- enabled = true;
- qty_of_top_results = 4;
- };
- minimum_ratio = 0.2;
- remove_no_ratio = false;
- text_not_present = "YouTube is currently trying to block Invidious instances";
- };
- };
- nginx = {
- enable = true;
- inherit (cfg) domain extraDomains;
- };
- };
- vhack.nginx.enable = true;
- };
-}
diff --git a/modules/by-name/ma/mail/module.nix b/modules/by-name/ma/mail/module.nix
deleted file mode 100644
index 55f2fb8..0000000
--- a/modules/by-name/ma/mail/module.nix
+++ /dev/null
@@ -1,167 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.mail;
- all_admins = [
- "sils@vhack.eu"
- "soispha@vhack.eu"
- "nightingale@vhack.eu"
- ];
-in {
- options.vhack.mail = {
- enable = lib.mkEnableOption "sophisticated mail setup with simple-nixos-mailserver";
- fqdn = lib.mkOption {
- type = lib.types.str;
- description = "The fqdn mailserver should be served on.";
- };
- };
-
- config = lib.mkIf cfg.enable {
- vhack.persist.directories = [
- {
- directory = "/var/lib/mail/backup";
- user = "virtualMail";
- group = "virtualMail";
- mode = "0700";
- }
- {
- directory = "/var/lib/mail/sieve";
- user = "virtualMail";
- group = "virtualMail";
- mode = "0700";
- }
- {
- directory = "/var/lib/mail/vmail";
- user = "virtualMail";
- group = "virtualMail";
- mode = "0700";
- }
- {
- directory = "/var/lib/mail/dkim";
- user = "opendkim";
- group = "opendkim";
- mode = "0700";
- }
- {
- directory = "/var/lib/postfix/data";
- user = "postfix";
- group = "postfix";
- mode = "0700";
- }
- {
- directory = "/var/lib/postfix/queue";
- user = "postfix";
- group = "postfix";
- mode = "0700";
- }
- {
- directory = "/var/lib/rspamd";
- user = "rspamd";
- group = "rspamd";
- mode = "0700";
- }
- ];
- vhack.nginx.enable = true;
- security.acme.certs = {
- "${cfg.fqdn}" = {
- domain = cfg.fqdn;
- };
- };
- mailserver = {
- enable = true;
- inherit (cfg) fqdn;
-
- useFsLayout = true;
-
- extraVirtualAliases = {
- "abuse@vhack.eu" = all_admins;
- "postmaster@vhack.eu" = all_admins;
- "admin@vhack.eu" = all_admins;
- };
-
- mailDirectory = "/var/lib/mail/vmail";
- dkimKeyDirectory = "/var/lib/mail/dkim";
- sieveDirectory = "/var/lib/mail/sieve";
- backup.snapshotRoot = "/var/lib/mail/backup";
-
- enableImap = false;
- enableImapSsl = true;
- enablePop3 = false;
- enablePop3Ssl = true;
- # SMTP
- enableSubmission = false;
- enableSubmissionSsl = true;
- openFirewall = true;
-
- keyFile = "/var/lib/acme/${cfg.fqdn}/key.pem";
- certificateScheme = "acme";
- certificateFile = "/var/lib/acme/${cfg.fqdn}/fullchain.pem";
-
- domains = [
- "vhack.eu"
-
- "s-schoeffel.de"
- "b-peetz.de"
-
- "sils.li"
- "nightingale.sils.li"
- "sils.sils.li"
- ];
-
- loginAccounts = {
- "sils@vhack.eu" = {
- hashedPassword = "$2b$05$RW/Svgk7iGxvP5W7ZwUZ1e.a3fj4fteevb2MtfFYYD0d1DQ17y9Fm";
- };
- "soispha@vhack.eu" = {
- hashedPassword = "$2b$05$XX36sJuHNbTFvi8DFldscOeQBHahluSkiUqD9QGzQaET7NJusSuQW";
- };
-
- "benedikt.peetz@b-peetz.de" = {
- hashedPassword = "$2b$05$MfET8utot2OolPZNASqoDe4VXNoG2chnEWhdfQ2E92mit0TvI2gBy";
- aliases = ["@b-peetz.de"];
- };
- "silas.schoeffel@s-schoeffel.de" = {
- hashedPassword = "$2b$05$Qb8rl7ncpCcTbsSdsduJBuOITp8RTD6sfOTjuxJsVtD9vjAYY9n8e";
- aliases = ["@s-schoeffel.de"];
- };
-
- "nightingale@vhack.eu" = {
- hashedPassword = "$2b$05$nDKVVq1EktKXWqGFhnOLP.plLovXFyvWSuptK9GIkxA5DScKFx6YS";
- aliases = [
- "@nightingale.sils.li"
- ];
- };
- "sils@sils.li" = {
- hashedPassword = "$2b$05$Ebzh2ZhuWkz1p4tqJ172IejNZg10FtCxPDY4k6umYrpirXg7ezIRq";
- aliases = [
- "@sils.sils.li"
- "@sils.li"
- ];
- };
-
- # Mail-Account used by hosted software
- "mastodon@vhack.eu" = {
- hashedPassword = "$2b$05$pSby3x2p3cHg0FyAE8IiJ.nYUqtAIR10JA8HNpHwMAiLXqc.ltSK.";
- };
- "peertube@vhack.eu" = {
- hashedPassword = "$y$j9T$hyWQ8Awd2Xrc6qsK.2hwE1$LxACfaeW.yHGbkQL95dWtID9.zXL/aMwT6lp.yU/0g0";
- };
- };
- };
-
- users = {
- users = {
- knot-resolver.uid = config.vhack.constants.ids.uids.knot-resolver;
- redis-rspamd.uid = config.vhack.constants.ids.uids.redis-rspamd;
- rspamd.uid = config.vhack.constants.ids.uids.rspamd;
- };
- groups = {
- knot-resolver.gid = lib.mkForce config.vhack.constants.ids.gids.knot-resolver;
- redis-rspamd.gid = config.vhack.constants.ids.gids.redis-rspamd;
- rspamd.gid = config.vhack.constants.ids.gids.rspamd;
- };
- };
- };
-}
diff --git a/modules/by-name/ma/mastodon/module.nix b/modules/by-name/ma/mastodon/module.nix
deleted file mode 100644
index 895428d..0000000
--- a/modules/by-name/ma/mastodon/module.nix
+++ /dev/null
@@ -1,123 +0,0 @@
-{
- config,
- pkgs,
- lib,
- ...
-}: let
- emailAddress = "mastodon@vhack.eu";
- applyPatches = pkg:
- pkg.overrideAttrs (attrs: {
- patches = (attrs.patches or []) ++ [./patches/0001-feat-treewide-Increase-character-limit-to-5000-in-me.patch];
- });
- cfg = config.vhack.mastodon;
-in {
- options.vhack.mastodon = {
- enable = lib.mkEnableOption "a mastodon instance";
- domain = lib.mkOption {
- type = lib.types.str;
- description = "The Domain mastodon should be served on";
- example = "mastodon.vhack.eu";
- };
- enableTLD = lib.mkEnableOption "using the tld as handle, configured via
- webfinger (note: this requires the tld to point to the same server as domain)";
- tld = lib.mkOption {
- type = lib.types.nullOr lib.types.str;
- default = null;
- example = "vhack.eu";
- };
- mailPwFile = lib.mkOption {
- type = lib.types.path;
- description = "The age encrypted mail password file passed to agenix";
- };
- };
- config = lib.mkIf cfg.enable {
- age.secrets.mastodonMail = {
- file = cfg.mailPwFile;
- mode = "700";
- owner = "mastodon";
- group = "mastodon";
- };
- vhack.persist.directories = [
- {
- directory = "/var/lib/mastodon";
- user = "mastodon";
- group = "mastodon";
- mode = "0700";
- }
- ];
-
- vhack.postgresql.enable = true;
- services.mastodon = {
- enable = true;
-
- package = applyPatches pkgs.mastodon;
-
- # Unstable Mastodon package, used if
- # security updates aren't backported.
- #package = applyPatches pkgs-unstable.mastodon;
-
- localDomain =
- if cfg.enableTLD
- then cfg.tld
- else cfg.domain;
- smtp = {
- authenticate = true;
- createLocally = false;
- fromAddress = emailAddress;
- user = emailAddress;
- host = "mail.foss-syndicate.org";
- passwordFile = config.age.secrets.mastodonMail.path;
- };
- streamingProcesses = 3; # Number of Cores - 1
- extraConfig = {
- WEB_DOMAIN = cfg.domain;
- EMAIL_DOMAIN_ALLOWLIST = "vhack.eu|sils.li";
- };
- };
-
- vhack.nginx.enable = true;
- services.nginx = {
- enable = true;
- recommendedProxySettings = true; # required for redirections to work
- virtualHosts = {
- "${cfg.domain}" = {
- root = "${config.services.mastodon.package}/public/";
- # mastodon only supports https, but you can override this if you offload tls elsewhere.
- forceSSL = true;
- enableACME = true;
-
- locations = {
- "/system/".alias = "/var/lib/mastodon/public-system/";
- "/".tryFiles = "$uri @proxy";
- "@proxy" = {
- proxyPass = "http://unix:/run/mastodon-web/web.socket";
- proxyWebsockets = true;
- };
- "/api/v1/streaming/" = {
- proxyPass = "http://unix:/run/mastodon-streaming/streaming.socket";
- proxyWebsockets = true;
- };
- };
- };
- "${cfg.tld}" =
- if cfg.enableTLD
- then {
- locations."/.well-known/webfinger".return = "301 https://${cfg.domain}$request_uri";
- }
- else {};
- };
- };
-
- users = {
- users.mastodon.uid = config.vhack.constants.ids.uids.mastodon;
- users.redis-mastodon.uid = config.vhack.constants.ids.uids.redis-mastodon;
- groups.redis-mastodon.gid = config.vhack.constants.ids.gids.redis-mastodon;
- groups.mastodon = {
- gid = config.vhack.constants.ids.gids.mastodon;
- members = [
- config.services.nginx.user
- ];
- };
- };
- };
-}
diff --git a/modules/by-name/ma/mastodon/patches/0001-feat-treewide-Increase-character-limit-to-5000-in-me.patch b/modules/by-name/ma/mastodon/patches/0001-feat-treewide-Increase-character-limit-to-5000-in-me.patch
deleted file mode 100644
index 35dc809..0000000
--- a/modules/by-name/ma/mastodon/patches/0001-feat-treewide-Increase-character-limit-to-5000-in-me.patch
+++ /dev/null
@@ -1,40 +0,0 @@
-From ab67426c53d343eee349de501767ecbbf5d211ad Mon Sep 17 00:00:00 2001
-From: Benedikt Peetz <benedikt.peetz@b-peetz.de>
-Date: Sat, 21 Dec 2024 20:07:11 +0100
-Subject: [PATCH] feat(treewide): Increase character limit to 5000 in messages
-
-The default of 500 was just not enough.
----
- .../features/compose/containers/compose_form_container.js | 2 +-
- app/validators/status_length_validator.rb | 2 +-
- 2 files changed, 2 insertions(+), 2 deletions(-)
-
-diff --git a/app/javascript/mastodon/features/compose/containers/compose_form_container.js b/app/javascript/mastodon/features/compose/containers/compose_form_container.js
-index bda2edba6..76ac65bf3 100644
---- a/app/javascript/mastodon/features/compose/containers/compose_form_container.js
-+++ b/app/javascript/mastodon/features/compose/containers/compose_form_container.js
-@@ -28,7 +28,7 @@ const mapStateToProps = state => ({
- anyMedia: state.getIn(['compose', 'media_attachments']).size > 0,
- isInReply: state.getIn(['compose', 'in_reply_to']) !== null,
- lang: state.getIn(['compose', 'language']),
-- maxChars: state.getIn(['server', 'server', 'configuration', 'statuses', 'max_characters'], 500),
-+ maxChars: state.getIn(['server', 'server', 'configuration', 'statuses', 'max_characters'], 5000),
- });
-
- const mapDispatchToProps = (dispatch) => ({
-diff --git a/app/validators/status_length_validator.rb b/app/validators/status_length_validator.rb
-index dc841ded3..9cb1ec94b 100644
---- a/app/validators/status_length_validator.rb
-+++ b/app/validators/status_length_validator.rb
-@@ -1,7 +1,7 @@
- # frozen_string_literal: true
-
- class StatusLengthValidator < ActiveModel::Validator
-- MAX_CHARS = 500
-+ MAX_CHARS = 5000
- URL_PLACEHOLDER_CHARS = 23
- URL_PLACEHOLDER = 'x' * 23
-
---
-2.47.0
-
diff --git a/modules/by-name/ma/matrix/module.nix b/modules/by-name/ma/matrix/module.nix
deleted file mode 100644
index 4b730da..0000000
--- a/modules/by-name/ma/matrix/module.nix
+++ /dev/null
@@ -1,171 +0,0 @@
-{
- config,
- pkgs,
- lib,
- ...
-}: let
- cfg = config.vhack.matrix;
- clientConfig."m.homeserver".base_url = "https://${cfg.fqdn}";
- serverConfig."m.server" = "${cfg.fqdn}:443";
- mkWellKnown = data: ''
- add_header Content-Type application/json;
- add_header Access-Control-Allow-Origin *;
- return 200 '${builtins.toJSON data}';
- '';
-in {
- options.vhack.matrix = {
- enable = lib.mkEnableOption "matrix setup based on synapse";
- fqdn = lib.mkOption {
- type = lib.types.str;
- description = "The FQDN on which matrix-synapse should be served.";
- example = "matrix.vhack.eu";
- };
- url = lib.mkOption {
- type = lib.types.str;
- description = "The url the matrix-server should be known under.";
- };
- sharedSecretFile = lib.mkOption {
- type = lib.types.path;
- description = "The age encrypted shared secret file for synapse, passed to agenix";
- };
- };
- config = lib.mkIf cfg.enable {
- age.secrets.matrix-synapse_registration_shared_secret = {
- file = cfg.sharedSecretFile;
- mode = "700";
- owner = "matrix-synapse";
- group = "matrix-synapse";
- };
- networking.firewall.allowedTCPPorts = [80 443];
-
- vhack.persist.directories = [
- {
- directory = "/var/lib/matrix";
- user = "matrix-synapse";
- group = "matrix-synapse";
- mode = "0700";
- }
- {
- directory = "/var/lib/mautrix-whatsapp";
- user = "mautrix-whatsapp";
- group = "matrix-synapse";
- mode = "0750";
- }
- ];
- systemd.tmpfiles.rules = [
- "d /etc/matrix 0755 matrix-synapse matrix-synapse"
- ];
-
- vhack.postgresql.enable = true;
- vhack.nginx.enable = true;
-
- services = {
- postgresql = {
- enable = true;
- initialScript = pkgs.writeText "synapse-init.sql" ''
- --Matrix:
- CREATE ROLE "matrix-synapse" WITH LOGIN PASSWORD 'synapse';
- CREATE DATABASE "matrix-synapse" WITH OWNER "matrix-synapse"
- TEMPLATE template0
- LC_COLLATE = "C"
- LC_CTYPE = "C";
-
- --Whatsapp-bridge:
- CREATE ROLE "mautrix-whatsapp" WITH LOGIN PASSWORD 'whatsapp';
- CREATE DATABASE "mautrix-whatsapp" WITH OWNER "mautrix-whatsapp"
- TEMPLATE template0
- LC_COLLATE = "C"
- LC_CTYPE = "C";
- '';
- };
-
- nginx = {
- enable = true;
- recommendedTlsSettings = true;
- recommendedOptimisation = true;
- recommendedGzipSettings = true;
- recommendedProxySettings = true;
- virtualHosts = {
- "${cfg.url}" = {
- enableACME = true;
- forceSSL = true;
- locations = {
- "/.well-known/matrix/server".extraConfig = mkWellKnown serverConfig;
- "/.well-known/matrix/client".extraConfig = mkWellKnown clientConfig;
- };
- };
- "${cfg.fqdn}" = {
- enableACME = true;
- forceSSL = true;
- locations = {
- "/".return = "404";
- "/_matrix".proxyPass = "http://[::1]:8008";
- "/_synapse/client".proxyPass = "http://[::1]:8008";
- };
- };
- };
- };
-
- mautrix-whatsapp = {
- # FIXME(@bpeetz): This was disabled because `mautrix-whatsapp` dependends on libolm.
- # Re-enable it, when this has changed. <2024-09-06>
- enable = false;
- settings = {
- appservice = {
- database = {
- type = "postgres";
- uri = "postgres:///mautrix-whatsapp?host=/run/postgresql";
- };
- whatsapp = {
- # TODO: See https://github.com/tulir/whatsmeow/blob/efc632c008604016ddde63bfcfca8de4e5304da9/binary/proto/def.proto#L43-L64 for a list.
- # This also determines the WhatsApp icon
- browser_name = "unknown";
- };
- };
- homeserver.address = "https://${cfg.fqdn}";
- bridge.permissions = {
- "@soispha:vhack.eu" = "admin";
- "@sils:vhack.eu" = "admin";
- "@nightingale:vhack.eu" = "admin";
- };
- };
- };
-
- matrix-synapse = {
- enable = true;
- dataDir = "/var/lib/matrix";
- configFile = "/etc/matrix/matrix.conf";
- settings = {
- media_store_path = "/var/lib/matrix/media_store";
- registration_shared_secret_path = "${config.age.secrets.matrix-synapse_registration_shared_secret.path}";
- server_name = cfg.url;
- listeners = [
- {
- port = 8008;
- bind_addresses = ["::1"];
- type = "http";
- tls = false;
- x_forwarded = true;
- resources = [
- {
- names = ["client" "federation"];
- compress = true;
- }
- ];
- }
- ];
- };
- };
- };
- users = {
- users = {
- matrix-synapse.uid = config.vhack.constants.ids.uids.matrix-synapse;
- mautrix-whatsapp = {
- uid = config.vhack.constants.ids.uids.mautrix-whatsapp;
- group = "matrix-synapse";
- };
- };
- groups.matrix-synapse.gid = config.vhack.constants.ids.gids.matrix-synapse;
- };
- };
-}
diff --git a/modules/by-name/mi/miniflux/module.nix b/modules/by-name/mi/miniflux/module.nix
deleted file mode 100644
index 0075bca..0000000
--- a/modules/by-name/mi/miniflux/module.nix
+++ /dev/null
@@ -1,55 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.miniflux;
-in {
- options.vhack.miniflux = {
- enable = lib.mkEnableOption "miniflux, an simple web rss reading software";
- domain = lib.mkOption {
- type = lib.types.str;
- description = "The primary domain miniflux should be served on";
- };
- extraDomains = lib.mkOption {
- type = lib.types.listOf lib.types.str;
- description = "Additional domains to serve miniflux on";
- default = [];
- };
- adminCredentialsFile = lib.mkOption {
- type = lib.types.path;
- description = "The age encrypted admin credentials file passed to agenix";
- };
- };
- config = lib.mkIf cfg.enable {
- age.secrets = {
- minifluxAdmin = {
- file = cfg.adminCredentialsFile;
- mode = "700";
- owner = "root";
- group = "root";
- };
- };
- services.miniflux = {
- enable = true;
- config = {
- LISTEN_ADDR = "127.0.0.1:5892";
- };
- adminCredentialsFile = config.age.secrets.minifluxAdmin.path;
- };
-
- vhack = {
- nginx.enable = true;
- postgresql.enable = true;
- };
- services.nginx = {
- virtualHosts.${cfg.domain} = {
- locations."/".proxyPass = "http://${config.services.miniflux.config.LISTEN_ADDR}";
-
- enableACME = true;
- forceSSL = true;
- serverAliases = cfg.extraDomains;
- };
- };
- };
-}
diff --git a/modules/by-name/mu/murmur/module.nix b/modules/by-name/mu/murmur/module.nix
deleted file mode 100644
index 5cc6f7d..0000000
--- a/modules/by-name/mu/murmur/module.nix
+++ /dev/null
@@ -1,80 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.murmur;
-in {
- options.vhack.murmur = {
- enable = lib.mkEnableOption "murmur, a mumble server software";
- murmurStore = lib.mkOption {
- type = lib.types.str;
- default = "/var/lib/murmur";
- description = "The location of murmurs data dir.";
- };
- host = lib.mkOption {
- type = lib.types.str;
- description = "The domain murmur should be served on.";
- example = "mumble.vhack.eu";
- };
- url = lib.mkOption {
- type = lib.types.str;
- description = "The url this instance should be registered under. Note that
- this is not the domain mumur is served on";
- example = "vhack.eu";
- };
- name = lib.mkOption {
- type = lib.types.str;
- description = "The name this instance should be registered under.";
- example = "vhack";
- };
- };
- config = lib.mkIf cfg.enable {
- vhack.persist.directories = [
- {
- directory = cfg.murmurStore;
- user = "murmur";
- group = "murmur";
- mode = "0700";
- }
- ];
-
- services.murmur = {
- enable = true;
- openFirewall = true;
- welcometext = ''
- <b>You never get a second chance to make a first impression</b><br>
-
- The entire team of [name of the company] is thrilled to welcome you on board. We hope you’ll do some amazing work here!
- '';
- sslKey = "${cfg.murmurStore}/key.pem";
- sslCert = "${cfg.murmurStore}/fullchain.pem";
-
- registerUrl = cfg.url;
- registerName = cfg.name;
- registerHostname = cfg.host;
- hostName = cfg.host;
- clientCertRequired = true;
- bandwidth = 7200000;
- };
-
- security.acme.certs.murmur = {
- domain = cfg.host;
- postRun =
- /*
- bash
- */
- ''
- set -x
- rm "${cfg.murmurStore}/key.pem"
- rm "${cfg.murmurStore}/fullchain.pem"
-
- cp key.pem "${cfg.murmurStore}";
- cp fullchain.pem "${cfg.murmurStore}";
-
- chown murmur:murmur "${cfg.murmurStore}/key.pem"
- chown murmur:murmur "${cfg.murmurStore}/fullchain.pem"
- '';
- };
- };
-}
diff --git a/modules/by-name/ng/nginx/module.nix b/modules/by-name/ng/nginx/module.nix
deleted file mode 100644
index 27b0302..0000000
--- a/modules/by-name/ng/nginx/module.nix
+++ /dev/null
@@ -1,71 +0,0 @@
-{
- lib,
- config,
- ...
-}: let
- mkRedirect = _: value: {
- forceSSL = true;
- enableACME = true;
- locations."/".return = "301 ${value}";
- };
-
- redirects = builtins.mapAttrs mkRedirect cfg.redirects;
-
- cfg = config.vhack.nginx;
-in {
- options.vhack.nginx = {
- enable = lib.mkEnableOption ''
- a default nginx config.
- '';
-
- selfsign = lib.mkOption {
- type = lib.types.bool;
- default = false;
- description = ''
- Whether to selfsign the acme certificates. This should only
- really be useful for tests.
- '';
- };
-
- redirects = lib.mkOption {
- type = lib.types.attrsOf lib.types.str;
- default = {};
- description = ''
- An attrset of redirects to add.
- The keys are the domain that should than be redirected to the url specified as
- value.
- '';
- };
- };
-
- config = lib.mkIf cfg.enable {
- vhack.persist.directories = [
- "/var/lib/acme"
- ];
-
- users = {
- users.acme.uid = config.vhack.constants.ids.uids.acme;
- groups.acme.gid = config.vhack.constants.ids.gids.acme;
- };
-
- security.acme = {
- acceptTerms = true;
- defaults = {
- email = "admin@vhack.eu";
- webroot = "/var/lib/acme/acme-challenge";
-
- # Avoid spamming the acme server, if we run in a test, and only really want self-signed
- # certificates
- server = lib.mkIf cfg.selfsign "https://127.0.0.1";
- };
- };
-
- networking.firewall = {
- allowedTCPPorts = [80 443];
- };
- services.nginx = {
- enable = true;
- virtualHosts = redirects;
- };
- };
-}
diff --git a/modules/by-name/ni/nix-sync/internal_module.nix b/modules/by-name/ni/nix-sync/internal_module.nix
deleted file mode 100644
index 4e28586..0000000
--- a/modules/by-name/ni/nix-sync/internal_module.nix
+++ /dev/null
@@ -1,299 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}: let
- cfg = config.services.nix-sync;
- esa = lib.strings.escapeShellArg;
-
- mkTimer = name: repo: {
- description = "Nix sync ${name} timer";
- wantedBy = ["timers.target"];
- timerConfig = {
- OnUnitActiveSec = repo.interval;
- };
- wants = ["network-online.target"];
- after = ["network-online.target"];
- };
-
- parents = path: let
- split_path = builtins.split "/" path;
- filename = builtins.elemAt split_path (builtins.length split_path - 1);
- path_build =
- lib.strings.removeSuffix "/" (builtins.replaceStrings [filename] [""] path);
- final_path =
- if filename == ""
- then parents path_build
- else path_build;
- in
- final_path;
-
- mkUnit = name: repo: let
- optionalPathSeparator =
- if lib.strings.hasPrefix "/" repo.path
- then ""
- else "/";
- /*
- * `ln` tries to create a symlink in the directory, if the target ends with a '/',
- * thus remove it.
- */
- repoPath = lib.strings.removeSuffix "/" repo.path;
-
- repoCachePath = cfg.cachePath + optionalPathSeparator + repo.path;
- execStartScript = pkgs.writeScript "nix-sync-exec" ''
- #! /usr/bin/env dash
- export XDG_CACHE_HOME="$CACHE_DIRECTORY";
- cd ${esa repoCachePath};
-
- git fetch
- origin="$(git rev-parse @{u})";
- branch="$(git rev-parse @)";
-
- if ! [ "$origin" = "$branch" ]; then
- git pull --rebase;
-
- out_paths=$(mktemp);
- nix build . --print-out-paths --experimental-features 'nix-command flakes' > "$out_paths";
- [ "$(wc -l < "$out_paths")" -gt 1 ] && { echo "To many out-paths"; exit 1; }
- out_path="$(cat "$out_paths")";
- rm ${esa repoPath};
- ln -s "$out_path" ${esa repoPath};
- rm "$out_paths";
- fi
- '';
- execStartPreScript = ''
- export XDG_CACHE_HOME="$CACHE_DIRECTORY";
-
- if ! [ -d ${esa repoCachePath}/.git ]; then
- mkdir --parents ${esa repoCachePath};
- git clone ${esa repo.uri} ${esa repoCachePath};
-
- out_paths=$(mktemp);
- nix build ${esa repoCachePath} --print-out-paths --experimental-features 'nix-command flakes' > "$out_paths";
- [ "$(wc -l < "$out_paths")" -gt 1 ] && { echo "To many out-paths"; exit 1; }
- out_path="$(cat "$out_paths")";
- ln -s "$out_path" ${esa repoPath};
- rm "$out_paths";
- fi
-
- if ! [ -L ${esa repoPath} ]; then
- cd ${esa repoCachePath};
-
- git pull --rebase;
-
- out_paths=$(mktemp);
- nix build . --print-out-paths --experimental-features 'nix-command flakes' > "$out_paths";
- [ "$(wc -l < "$out_paths")" -gt 1 ] && { echo "To many out-paths"; exit 1; }
- out_path="$(cat "$out_paths")";
-
- if [ -d ${esa repoPath} ]; then
- rm -d ${esa repoPath};
- else
- mkdir --parents "$(dirname ${esa repoPath})";
- fi
- [ -e ${esa repoPath} ] && rm ${esa repoPath};
-
- ln -s "$out_path" ${esa repoPath};
- rm "$out_paths";
- fi
- '';
- in {
- description = "Nix Sync ${name}";
- wantedBy = ["default.target"];
- after = ["network.target"];
- path = with pkgs; [openssh git nix mktemp coreutils dash];
- preStart = execStartPreScript;
-
- serviceConfig = {
- TimeoutSec = 0;
- ExecStart = execStartScript;
- Restart = "on-abort";
- # User and group
- User = cfg.user;
- Group = cfg.group;
- # Runtime directory and mode
- RuntimeDirectory = "nix-sync";
- RuntimeDirectoryMode = "0750";
- # Cache directory and mode
- CacheDirectory = "nix-sync";
- CacheDirectoryMode = "0750";
- # Logs directory and mode
- LogsDirectory = "nix-sync";
- LogsDirectoryMode = "0750";
- # Proc filesystem
- ProcSubset = "all";
- ProtectProc = "invisible";
- # New file permissions
- UMask = "0027"; # 0640 / 0750
- # Capabilities
- AmbientCapabilities = ["CAP_CHOWN"];
- CapabilityBoundingSet = ["CAP_CHOWN"];
- # Security
- NoNewPrivileges = true;
- # Sandboxing (sorted by occurrence in https://www.freedesktop.org/software/systemd/man/systemd.exec.html)
- ReadWritePaths = ["${esa (parents repo.path)}" "-${esa (parents repoCachePath)}" "-${esa cfg.cachePath}"];
- ReadOnlyPaths = ["/nix"]; # TODO: Should be irrelevant, as we have ProtectSystem=Strict <2024-06-01>
- ProtectSystem = "strict";
- ProtectHome = true;
- PrivateTmp = true;
- PrivateDevices = true;
- ProtectHostname = true;
- ProtectClock = true;
- ProtectKernelTunables = true;
- ProtectKernelModules = true;
- ProtectKernelLogs = true;
- ProtectControlGroups = true;
- RestrictAddressFamilies = ["AF_UNIX" "AF_INET" "AF_INET6"];
- RestrictNamespaces = true;
- LockPersonality = true;
- MemoryDenyWriteExecute = true;
- RestrictRealtime = true;
- RestrictSUIDSGID = true;
- RemoveIPC = true;
- PrivateMounts = true;
- # System Call Filtering
- SystemCallArchitectures = "native";
- SystemCallFilter = ["~@cpu-emulation @debug @keyring @mount @obsolete @privileged @setuid"];
- };
- };
-
- services =
- lib.mapAttrs' (name: repo: {
- name = "nix-sync-${name}";
- value = mkUnit name repo;
- })
- cfg.repositories;
- timers =
- lib.mapAttrs' (name: repo: {
- name = "nix-sync-${name}";
- value = mkTimer name repo;
- })
- cfg.repositories;
-
- # generate the websites directory, so systemd can mount it read write
- generatedDirectories =
- lib.mapAttrsToList (
- _: repo: "d ${esa (parents repo.path)} 0755 ${cfg.user} ${cfg.group}"
- )
- cfg.repositories;
-
- repositoryType = lib.types.submodule ({name, ...}: {
- options = {
- name = lib.mkOption {
- internal = true;
- default = name;
- type = lib.types.str;
- description = "The name that should be given to this unit.";
- };
-
- path = lib.mkOption {
- type = lib.types.str;
- description = "The path at which to sync the repository";
- };
-
- uri = lib.mkOption {
- type = lib.types.str;
- example = "ssh://user@example.com:/~[user]/path/to/repo.git";
- description = ''
- The URI of the remote to be synchronized. This is only used in the
- event that the directory does not already exist. See
- <link xlink:href="https://git-scm.com/docs/git-clone#_git_urls"/>
- for the supported URIs.
- '';
- };
-
- extraSettings = lib.mkOption {
- type = lib.types.attrsOf lib.types.anything;
- example = lib.literalExpression ''
- {
- locations."/.well-known/openpgpkey/hu/" = {
- extraConfig = \'\'
- default_type application/octet-stream;
-
- add_header Access-Control-Allow-Origin * always;
- \'\';
- };
- }
- '';
- description = ''
- Extra config to add the the nginx virtual host.
- '';
- };
-
- interval = lib.mkOption {
- type = lib.types.int;
- default = 500;
- description = ''
- The interval, specified in seconds, at which the synchronization will
- be triggered.
- '';
- };
- };
- });
-in {
- options = {
- services.nix-sync = {
- enable = lib.mkEnableOption "nix-sync services";
-
- user = lib.mkOption {
- type = lib.types.str;
- default = "nix-sync";
- description = lib.mdDoc "User account under which nix-sync units runs.";
- };
-
- group = lib.mkOption {
- type = lib.types.str;
- default = "nix-sync";
- description = lib.mdDoc "Group account under which nix-sync units runs.";
- };
-
- cachePath = lib.mkOption {
- type = lib.types.str;
- default = "/var/lib/nix-sync";
- description = lib.mdDoc ''
- Where to cache git directories. Should not end with a slash ("/")
- '';
- };
-
- repositories = lib.mkOption {
- type = with lib.types; attrsOf repositoryType;
- description = ''
- The repositories that should be synchronized.
- '';
- };
- };
- };
-
- config = lib.mkIf cfg.enable {
- assertions = [
- {
- assertion = !lib.strings.hasSuffix "/" cfg.cachePath;
- message = "Your cachePath ('${cfg.cachePath}') ends with a slash ('/'), please use: '${lib.strings.removeSuffix "/" cfg.cachePath}'.";
- }
- ];
- systemd = {
- tmpfiles.rules =
- generatedDirectories;
-
- inherit services timers;
- };
- users.users =
- if cfg.user == "nix-sync"
- then {
- nix-sync = {
- group = "${cfg.group}";
- isSystemUser = true;
- };
- }
- else lib.warnIf (cfg.user != "nix-sync") "The user (${cfg.user}) is not \"nix-sync\", thus you are responible for generating it.";
- users.groups =
- if cfg.group == "nix-sync"
- then {
- nix-sync = {
- members = ["${cfg.user}"];
- };
- }
- else lib.warnIf (cfg.group != "nix-sync") "The group (${cfg.group}) is not \"nix-sync\", thus you are responible for generating it.";
- };
-}
diff --git a/modules/by-name/ni/nix-sync/module.nix b/modules/by-name/ni/nix-sync/module.nix
deleted file mode 100644
index 1413920..0000000
--- a/modules/by-name/ni/nix-sync/module.nix
+++ /dev/null
@@ -1,104 +0,0 @@
-{
- config,
- lib,
- modulesPath,
- ...
-}: let
- cfg = config.vhack.nix-sync;
-
- mkNixSyncRepository = {
- domain,
- repositoryUrl,
- extraSettings,
- }: {
- name = "${domain}";
- value = {
- path = "/etc/nginx/websites/${domain}";
- uri = "${repositoryUrl}";
- inherit extraSettings;
- };
- };
- nixSyncRepositories = builtins.listToAttrs (builtins.map mkNixSyncRepository cfg.domains);
-
- mkVirtHost = {
- domain,
- repositoryUrl,
- extraSettings,
- }: {
- name = "${domain}";
- value =
- lib.recursiveUpdate {
- forceSSL = true;
- enableACME = true;
- root = "/etc/nginx/websites/${domain}";
- }
- extraSettings;
- };
- virtHosts = builtins.listToAttrs (builtins.map mkVirtHost cfg.domains);
-in {
- imports = [
- ./internal_module.nix
- ];
-
- options.vhack.nix-sync = {
- enable = lib.mkEnableOption ''
- a website git ops solution.
- '';
-
- domains = lib.mkOption {
- type = lib.types.listOf (lib.types.submodule {
- options = {
- domain = lib.mkOption {
- type = lib.types.str;
- example = "b-peetz.de";
- description = ''
- The fully qualified domain to use as base of this website.
- '';
- };
- repositoryUrl = lib.mkOption {
- type = lib.types.str;
- example = "b-peetz.de";
- description = ''
- The url used for the source git repository, which is deployed at this domain.
- '';
- };
- extraSettings = lib.mkOption {
- type =
- lib.types.submodule (import (modulesPath + "/services/web-servers/nginx/vhost-options.nix") {inherit config lib;});
- example = {
- locations."/.well-known/openpgpkey/hu/".extraConfig = "default_type application/octet-stream";
- };
- default = {};
- description = ''
- Extra configuration to add to the nginx virtual host.
- '';
- };
- };
- });
- };
- };
-
- config = lib.mkIf cfg.enable {
- vhack.persist.directories = [
- {
- directory = "/var/lib/nix-sync";
- user = "nix-sync";
- group = "nix-sync";
- mode = "0700";
- }
- ];
-
- services.nix-sync = {
- enable = true;
- repositories = nixSyncRepositories;
- };
-
- vhack.nginx.enable = true;
- services.nginx.virtualHosts = virtHosts;
-
- users = {
- users.nix-sync.uid = config.vhack.constants.ids.uids.nix-sync;
- groups.nix-sync.gid = config.vhack.constants.ids.gids.nix-sync;
- };
- };
-}
diff --git a/modules/by-name/ni/nixconfig/module.nix b/modules/by-name/ni/nixconfig/module.nix
deleted file mode 100644
index a5bf950..0000000
--- a/modules/by-name/ni/nixconfig/module.nix
+++ /dev/null
@@ -1,28 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.nixconfig;
-in {
- options.vhack.nixconfig = {
- enable = lib.mkEnableOption "sophisticated nix settings";
- };
- config = lib.mkIf cfg.enable {
- nix = {
- # gc = {
- # automatic = true;
- # dates = "daily";
- # options = "--delete-older-than 3";
- # };
- settings = {
- auto-optimise-store = true;
- experimental-features = ["nix-command" "flakes"];
- trusted-users = [
- "root"
- "@wheel"
- ];
- };
- };
- };
-}
diff --git a/modules/by-name/ns/nscd/module.nix b/modules/by-name/ns/nscd/module.nix
deleted file mode 100644
index 428ae3b..0000000
--- a/modules/by-name/ns/nscd/module.nix
+++ /dev/null
@@ -1,25 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.nscd;
-in {
- options.vhack.nscd = {
- # NOTE(@bpeetz): This is enabled by default in NixOS.
- # Because of this reason:
- # > Whether to enable the Name Service Cache Daemon. Disabling this is
- # > strongly discouraged, as this effectively disables NSS Lookups from
- # > all non-glibc NSS modules, including the ones provided by systemd.
- #
- # As such we should also always enable it. <2024-12-25>
- enable = (lib.mkEnableOption "nscd") // {default = true;};
- };
-
- config = lib.mkIf cfg.enable {
- users = {
- users.nscd.uid = config.vhack.constants.ids.uids.nscd;
- groups.nscd.gid = config.vhack.constants.ids.gids.nscd;
- };
- };
-}
diff --git a/modules/by-name/oo/oomd/module.nix b/modules/by-name/oo/oomd/module.nix
deleted file mode 100644
index 3b39236..0000000
--- a/modules/by-name/oo/oomd/module.nix
+++ /dev/null
@@ -1,19 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.systemd.oomd;
-in {
- options.vhack.systemd.oomd = {
- # NOTE(@bpeetz): Enabled by default, because that is what NixOS also does. <2024-12-25>
- enable = (lib.mkEnableOption "oomd") // {default = true;};
- };
-
- config = lib.mkIf cfg.enable {
- users = {
- users.systemd-oom.uid = config.vhack.constants.ids.uids.systemd-oom;
- groups.systemd-oom.gid = config.vhack.constants.ids.gids.systemd-oom;
- };
- };
-}
diff --git a/modules/by-name/op/openssh/module.nix b/modules/by-name/op/openssh/module.nix
deleted file mode 100644
index 83aeadf..0000000
--- a/modules/by-name/op/openssh/module.nix
+++ /dev/null
@@ -1,60 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.openssh;
-in {
- options.vhack.openssh = {
- enable = lib.mkEnableOption ''
- a sane openssh implementation.
- '';
- };
-
- config = lib.mkIf cfg.enable {
- /*
- FIXME(@bpeetz):
- This results in a boot error, as the `/var/lib/sshd` directory
- is only mounted _after_ the stage 2 init and with it the system
- activation. `agenix` needs the sshd hostkey however to decrypt the
- secrets and thus we have to ensure that this directory is mounted
- _before_ the system activation. Alas the only way I see to achieve
- that is to store the ssh hostkey directly on /srv, which is mounted
- before (it's marked as 'neededForBoot' after all).
-
- It should be possible to achieve this with impermanence however,
- as `/var/log` is mounted in the stage 1 init; The problem is that
- I have no idea _why_ only this is mounted and nothing else.
-
-
- vhack.persist.directories = [
- {
- directory = "/var/lib/sshd";
- user = "root";
- group = "root";
- mode = "0755";
- }
- ];
- */
-
- users = {
- users.sshd.uid = config.vhack.constants.ids.uids.sshd;
- groups.sshd.gid = config.vhack.constants.ids.gids.sshd;
- };
-
- services.openssh = {
- enable = true;
- settings.PasswordAuthentication = false;
- hostKeys = [
- {
- # FIXME: Remove the dependency on `/srv` this workaround.
- # See the explanation for using `/srv` above.
- path = "/srv/var/lib/sshd/ssh_host_ed25519_key";
-
- rounds = 1000;
- type = "ed25519";
- }
- ];
- };
- };
-}
diff --git a/modules/by-name/pe/peertube/module.nix b/modules/by-name/pe/peertube/module.nix
deleted file mode 100644
index e65e0b5..0000000
--- a/modules/by-name/pe/peertube/module.nix
+++ /dev/null
@@ -1,124 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.peertube;
-in {
- options.vhack.peertube = {
- enable = lib.mkEnableOption ''
- the peertube video platform.
- '';
- peertubeGeneral = lib.mkOption {
- type = lib.types.path;
- description = "The age encrypted general secret file passed to agenix";
- };
- smtpPasswordFile = lib.mkOption {
- type = lib.types.path;
- description = "The age encrypted smtp password file passed to agenix";
- };
- };
-
- config = lib.mkIf cfg.enable {
- services.peertube = {
- enable = true;
-
- configureNginx = true;
- localDomain = "peertube.vhack.eu";
- enableWebHttps = true;
- listenWeb = 443;
-
- smtp = {
- createLocally = false;
- passwordFile = "${config.age.secrets.peertubeSmtp.path}";
- };
- database = {
- createLocally = true;
- };
- redis = {
- enableUnixSocket = true;
- createLocally = true;
- };
-
- secrets.secretsFile = "${config.age.secrets.peertubeGeneral.path}";
-
- settings = {
- signup = {
- enabled = true;
-
- limit = 10; # When the limit is reached, registrations are disabled. -1 == unlimited
-
- minimum_age = 18; # Used to configure the signup form
-
- # Users fill a form to register so moderators can accept/reject the registration
- requires_approval = true;
- requires_email_verification = true;
- };
- user = {
- video_quota = "10GB";
- video_quota_daily = "2GB";
- };
- auto_blacklist = {
- videos = {
- of_users = {
- enabled = true;
- };
- };
- };
- listen.hostname = "127.0.0.1";
- instance.name = "PeerTube at Vhack.eu";
-
- admin.email = "admin@vhack.eu";
-
- smtp = let
- emailAddress = "peertube@vhack.eu";
- in {
- transport = "smtp";
- hostname = "mail.foss-syndicate.org";
- port = 587;
- username = emailAddress;
- tls = true;
- disable_starttls = true;
- from_address = emailAddress;
- };
- };
- };
-
- # The `configureNginx` option does not do this for some reason
- # TODO(@bpeetz): Find out why <2024-06-27>
- services.nginx.virtualHosts."${config.services.peertube.localDomain}" = {
- enableACME = true;
- forceSSL = true;
- };
-
- age.secrets = {
- peertubeGeneral = {
- file = cfg.peertubeGeneral;
- mode = "700";
- owner = "peertube";
- group = "peertube";
- };
- peertubeSmtp = {
- file = cfg.smtpPasswordFile;
- mode = "700";
- owner = "peertube";
- group = "peertube";
- };
- };
-
- vhack.persist.directories = [
- {
- directory = "/var/lib/peertube";
- user = "peertube";
- group = "peertube";
- mode = "0700";
- }
- ];
- users = {
- users.peertube.uid = config.vhack.constants.ids.uids.peertube;
- groups.peertube.gid = config.vhack.constants.ids.gids.peertube;
- users.redis-peertube.uid = config.vhack.constants.ids.uids.redis-peertube;
- groups.redis-peertube.gid = config.vhack.constants.ids.gids.redis-peertube;
- };
- };
-}
diff --git a/modules/by-name/po/postgresql/module.nix b/modules/by-name/po/postgresql/module.nix
deleted file mode 100644
index 319c3ac..0000000
--- a/modules/by-name/po/postgresql/module.nix
+++ /dev/null
@@ -1,19 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.postgresql;
-in {
- options.vhack.postgresql = {
- enable = lib.mkEnableOption "postgresql";
- };
-
- config = lib.mkIf cfg.enable {
- vhack.persist.directories = [
- "/var/lib/postgresql"
- ];
-
- services.postgresql.enable = true;
- };
-}
diff --git a/modules/by-name/re/redlib/module.nix b/modules/by-name/re/redlib/module.nix
deleted file mode 100644
index 2b20c66..0000000
--- a/modules/by-name/re/redlib/module.nix
+++ /dev/null
@@ -1,44 +0,0 @@
-{
- config,
- pkgsUnstable,
- lib,
- ...
-}: let
- domain = "redlib.vhack.eu";
-
- cfg = config.vhack.redlib;
-in {
- options.vhack.redlib = {
- enable = lib.mkEnableOption ''
- the redlib reddit frontend
- '';
- };
-
- config = lib.mkIf cfg.enable {
- services.redlib = {
- enable = true;
- package = pkgsUnstable.redlib;
- port = 8080;
- address = "127.0.0.1";
- openFirewall = false;
- };
-
- services.nginx = {
- enable = true;
- virtualHosts.${domain} = {
- locations."/".proxyPass = "http://127.0.0.1:${toString config.services.redlib.port}";
-
- enableACME = true;
- forceSSL = true;
- };
-
- # TODO: Remove this at a certain point. <2024-12-19>
- virtualHosts."libreddit.vhack.eu" = {
- locations."/".return = "301 https://${domain}";
-
- forceSSL = true;
- enableACME = true;
- };
- };
- };
-}
diff --git a/modules/by-name/re/resolvconf/module.nix b/modules/by-name/re/resolvconf/module.nix
deleted file mode 100644
index ff99696..0000000
--- a/modules/by-name/re/resolvconf/module.nix
+++ /dev/null
@@ -1,16 +0,0 @@
-{
- config,
- lib,
- ...
-}: let
- cfg = config.vhack.resolvconf;
-in {
- options.vhack.resolvconf = {
- # NOTE(@bpeetz): This condition is taken directly from NixOS. <2024-12-25>
- enable = lib.mkEnableOption "resolvconf" // {default = !(config.environment.etc ? "resolv.conf");};
- };
-
- config = lib.mkIf cfg.enable {
- users.groups.resolvconf.gid = config.vhack.constants.ids.gids.resolvconf;
- };
-}
diff --git a/modules/by-name/ru/rust-motd/module.nix b/modules/by-name/ru/rust-motd/module.nix
deleted file mode 100644
index a6998f4..0000000
--- a/modules/by-name/ru/rust-motd/module.nix
+++ /dev/null
@@ -1,92 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}: let
- cfg = config.vhack.rust-motd;
-
- # List all users that can login
- pred = n: v: (
- false # <- just here for neat formatting
- || v.initialHashedPassword != null
- || v.initialPassword != null
- || v.hashedPassword != null
- || v.hashedPasswordFile != null
- || v.password != null
- || v.passwordFile != null
- || v.openssh.authorizedKeys.keys != []
- || v.openssh.authorizedKeys.keyFiles != []
- );
- userList = builtins.mapAttrs (n: v: 2) (lib.filterAttrs pred config.users.users);
-in {
- options.vhack.rust-motd = {
- enable = lib.mkEnableOption "rust-motd";
- };
-
- config = lib.mkIf cfg.enable {
- systemd.services.rust-motd = {
- path = with pkgs; [
- bash
- fail2ban # Needed for rust-motd fail2ban integration
- ];
- };
-
- programs.rust-motd = {
- enable = true;
- enableMotdInSSHD = true;
- refreshInterval = "*:0/5"; # 0/5 means: hour 0 AND all hour wich match (0 + 5 * x) (is the same as: 0, 5, 10, 15, 20)
-
- # An example is here: https://raw.githubusercontent.com/rust-motd/rust-motd/refs/heads/main/example_config.toml
- settings = {
- global = {
- progress_full_character = "=";
- progress_empty_character = "-";
- progress_prefix = "[";
- progress_suffix = "]";
- time_format = "%Y-%m-%d %H:%M:%S";
- };
-
- banner = {
- color = "red";
- command = "${pkgs.hostname}/bin/hostname | ${pkgs.figlet}/bin/figlet -f slant";
- # if you don't want a dependency on figlet, you can generate your
- # banner however you want, put it in a file, and then use something like:
- # command = "cat banner.txt"
- };
-
- uptime = {
- prefix = "Uptime:";
- };
-
- # ssl_certificates = {
- # sort_method = "manual";
- #
- # certs = {
- # "server1.vhack.eu" = "/var/lib/acme/server1.vhack.eu/cert.pem";
- # "vhack.eu" = "/var/lib/acme/vhack.eu/cert.pem";
- # };
- # };
-
- filesystems = {
- root = "/";
- persistent = "/srv";
- store = "/nix";
- boot = "/boot";
- };
-
- memory = {
- swap_pos = "beside"; # or "below" or "none"
- };
-
- fail2_ban = {
- jails = ["sshd"]; #, "anotherjail"]
- };
-
- last_login = userList;
-
- last_run = {};
- };
- };
- };
-}
diff --git a/modules/by-name/us/users/module.nix b/modules/by-name/us/users/module.nix
deleted file mode 100644
index a197b13..0000000
--- a/modules/by-name/us/users/module.nix
+++ /dev/null
@@ -1,82 +0,0 @@
-{
- config,
- lib,
- pkgs,
- ...
-}: let
- cfg = config.vhack.users;
-
- mkUser = {
- name,
- password,
- uid,
- sshKey,
- }: {
- inherit name;
- value = {
- inherit name uid;
- isNormalUser = true;
- home = "/home/${name}";
- hashedPassword = password;
- extraGroups = [
- "wheel"
- ];
- openssh.authorizedKeys.keys = [
- sshKey
- ];
- };
- };
-
- extraUsers = lib.listToAttrs (builtins.map mkUser [
- {
- name = "soispha";
- password = "$y$jFT$3.8XmUyukZvpExMUxDZkI.$IVrJgm8ysNDF/0vDD2kF6w73ozXgr1LMVRNN4Bq7pv1";
- sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIME4ZVa+IoZf6T3U08JG93i6QIAJ4amm7mkBzO14JSkz cardno:000F_18F83532";
- uid = 1000;
- }
- {
- name = "sils";
- password = "$y$jFT$KpFnahVCE9JbE.5P3us8o.$ZzSxCusWqe3sL7b6DLgOXNNUf114tiiptM6T8lDxtKC";
- sshKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAe4o1PM6VasT3KZNl5NYvgkkBrPOg36dqsywd10FztS openpgp:0x21D20D6A";
- uid = 1001;
- }
- ]);
-in {
- options.vhack.users = {
- enable = lib.mkEnableOption "user setup";
- };
-
- config = lib.mkIf cfg.enable {
- users = {
- mutableUsers = false;
- defaultUserShell = pkgs.bashInteractive;
-
- users =
- {
- root = {
- hashedPassword = lib.mkForce null; # to lock root
- openssh.authorizedKeys.keys = lib.mkForce [];
- };
- }
- // extraUsers;
-
- # TODO(@bpeetz): Is this still relevant?
- # If it is, it should be moved to a separate module. <2024-12-24>
- # nixremote = {
- # name = "nixremote";
- # isNormalUser = true;
- # createHome = true;
- # home = "/home/nixremote";
- # uid = 1003;
- # group = "nixremote";
- # openssh.authorizedKeys.keys = [
- # "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCbSWqFzb+WTq2JVoRGoTkCkP7AM3bNY91bsUBeoQQc8gKAWuqCrpAOmr2Q2QMaTTGEOM0CsWfWLs3ZYtynHmc7wIFc4T/sUloV+dB9oSCmOk5ePxtj8+gpPK35Ja+ug5zmXsaI4s+n9mEbuuEjn33MxDYCUzAI+aWvWe68u/j+FM3u9c3Ta009rotajjSZ/cmIltgNLsG1rnAZRpwmLVg5UL4cb9um54o/NLYFd2KAekQFVbwUQDzzqriZhWmzkfhnznBMDblf9R1xvZ18Lqv3JF21shdaR43NW1wtuntBvAdsVYK2VUEbj+3MxTkK0aQ/E9SHMtH8MRE4oxU74TeTWfIhuSZk9/wekzSNMkHP3ReFC6B9xCMYa+ZqaTaGSWLQi78AQDeM2F9rAfp3hQzyRa7T7qKlgbae/hEb07xZglqmG7eml9vPSt4AHv5Y176Q95NiiWduGoLQOmjvSBMU9/KEGrGKyLfGH1Wa2EOfPxKKcvcHW0Xi9PlPiuP0nYk= root@thinklappi"
- # ];
- # };
- # };
- # groups.nixremote = {
- # gid = 1004;
- # };
- };
- };
-}