Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | feat(modules/nginx): Modularise the redirects and migrate them to server2 | Benedikt Peetz | 2024-12-25 |
| | | | | | | The redirects always have an implicit dependency on the DNS config of the running host. As such, simply stating them for all host is never a possibility and setting them per host the only viable option. | ||
* | fix(modules/nix-sync/internal): Fix syntax errors in shell-script | Benedikt Peetz | 2024-12-25 |
| | |||
* | fix(modules/dhcpcd): Also set uid/gid for the `dhcpcd` user | Benedikt Peetz | 2024-12-25 |
| | | | | | Otherwise, this user's/group's owned files/directories could change when a new user is added or removed, as we do not persist `/var/lib/nixos`. | ||
* | build(flake.nix): Re-add `ragenix` to the devShell | Benedikt Peetz | 2024-12-25 |
| | |||
* | refactor(hosts): Use a `by-name` structure and construct all host depended ↵ | Benedikt Peetz | 2024-12-25 |
| | | | | | | values This allows us to outsource the host-handling from the `flake.nix` file. | ||
* | fix(treewide): Add constant uids and gids to each user and group | Benedikt Peetz | 2024-12-25 |
| | | | | This allows us to avoid persisting `/var/lib/nixos`. | ||
* | docs(CONTRIBUTING.md): Remove | Benedikt Peetz | 2024-12-25 |
| | | | | | | | | The information is currently out-dated, was never really up-to-date and as such will not provide anything useful to new contributors. We should probably try to write it again at some point when our workflow has moved more from cathedral to bazaar. | ||
* | refactor(system/services/fail2ban): Migrate to `by-name` | Benedikt Peetz | 2024-12-25 |
| | | | | | | Additionally, I've changed to owner of the `/var/lib/fail2ban` directory to `root:root` as the main `fail2ban` service also runs under `root` and a `fail2ban` user is never created. | ||
* | refactor(system/services/rust-motd): Migrate to `by-name` | Benedikt Peetz | 2024-12-25 |
| | |||
* | fix(modules/impermanence): Don't always persist `/var/log` and `/var/lib/nixos` | Benedikt Peetz | 2024-12-25 |
| | | | | | | | | | | Persisting them, without marking the `/srv` containing fs as `neededForBoot` will result in a kernel panic in the init (because `impermanence` tries to mount these directories and fails as `/srv` is still missing.) Thus, each host, that sets `/srv` to `neededForBoot` should add these directories to `vhack.persist.directories`. | ||
* | fix(system): Remove out-dated imports | Benedikt Peetz | 2024-12-25 |
| | | | | Both of these modules have been moved to `by-name` | ||
* | refactor(system/users): Migrate to `by-name` | Benedikt Peetz | 2024-12-25 |
| | |||
* | fix(modules/git-server): Use `vhack.persist` for data-directories | Benedikt Peetz | 2024-12-25 |
| | | | | | This avoids having to create them manually on the server and is, overall just generally a better way to solve this problem. | ||
* | fix(modules/back): Use correct source-code environment variable | Benedikt Peetz | 2024-12-25 |
| | |||
* | build(scripts/deploy): Init | Benedikt Peetz | 2024-12-25 |
| | | | | | This documents the commands used for the first deployment (i.e., with a full, disko-driven, disk formatting step). | ||
* | build(scripts/mk_network_config): Init | Benedikt Peetz | 2024-12-25 |
| | | | | | | | This has been taken directly from `nixos-infect` (which rather under-maintained, sadly). Currently, it is extremely useful to generate the `networking.nix` config for new hosts. | ||
* | refactor(modules/impermanence): Migrate to by-name while distributing mods | Benedikt Peetz | 2024-12-24 |
| | |||
* | fix(modules/back): Set now needed source code URL environment variable | Benedikt Peetz | 2024-12-24 |
| | |||
* | docs(pkgs/back): Document useful environment variables | Benedikt Peetz | 2024-12-24 |
| | |||
* | feat(pkgs/back): Add a link to the source code | Benedikt Peetz | 2024-12-24 |
| | | | | | This is required by the AGPL license and should probably also be done, because we do not have a reason to hide or obfuscate the code. | ||
* | feat(hosts/server1): Configure back for the `nixos-server` repo | Benedikt Peetz | 2024-12-24 |
| | |||
* | feat(tests/back): Init | Benedikt Peetz | 2024-12-24 |
| | |||
* | feat(modules/back): Init | Benedikt Peetz | 2024-12-24 |
| | |||
* | build(scripts/test_interactive): Fix typo in variable name | Benedikt Peetz | 2024-12-24 |
| | |||
* | fix(modules/nix-sync/internal): Use correct command grouping syntax | Benedikt Peetz | 2024-12-24 |
| | | | | | | Commands in parentheses (i.e., `()`) are _subshells_ and `exit`ting from these will not result in an `exit` of the actually _shell_. Thus, we use want simple command grouping and use the correct syntax for that. | ||
* | build(pkgs/back): Apply source filtering | Benedikt Peetz | 2024-12-24 |
| | | | | | This avoids useless rebuilds, just because files like the `README.md` changed. | ||
* | docs(pkgs/back): Add note about needed write access | Benedikt Peetz | 2024-12-24 |
| | |||
* | fix(pkgs/back): Set `meta.mainProgram` | Benedikt Peetz | 2024-12-24 |
| | |||
* | fix(modules/disko): Actually honor `cfg.enable` | Benedikt Peetz | 2024-12-24 |
| | |||
* | test(scripts/lint_missing_tests.sh): Remove | Benedikt Peetz | 2024-12-23 |
| | | | | | This functionality is now available via the `coImport` feature in the `mkByName` `nixLib` function. | ||
* | style(treewide): Format | Benedikt Peetz | 2024-12-23 |
| | |||
* | build(flake): Use treefmt as nix formatter | Benedikt Peetz | 2024-12-23 |
| | | | | | This allows us to also keep markdown and other documents, that aren't nix, formatted. | ||
* | feat(pkgs): Hook up to the flake and add needed infrastructure | Benedikt Peetz | 2024-12-23 |
| | |||
* | feat(pkgs/back): Init | Benedikt Peetz | 2024-12-23 |
| | | | | | Other options, for example `git-bug webui --read-only` is just to bugged to be useful. | ||
* | fix(modules/disko): Remove deprecated legacy type and migrate to `by-name` | Benedikt Peetz | 2024-12-21 |
| | |||
* | fix(system/services/mastodon): Update char patch to v4.3 | Benedikt Peetz | 2024-12-21 |
| | |||
* | fix(modules/redlib): Change subdomain to `redlib` | Benedikt Peetz | 2024-12-20 |
| | | | | | | The old `libreddit` subdomain still has redirection to avoid this being a breaking change. But keeping the old subdomain is rather weird considering their new name. | ||
* | refactor(system/services/libreddit): Migrate to `by-name` | Benedikt Peetz | 2024-12-20 |
| | | | | This also includes a rename into `redlib` because of upstream changes. | ||
* | refactor({modules,test}): Migrate to a `by-name` structure | Benedikt Peetz | 2024-12-20 |
| | |||
* | fix(treewide): Update to nixos release 24.11 | Benedikt Peetz | 2024-12-19 |
| | |||
* | build(system/services/taskserver/certs/generate): Convert to `nix-shell` | Benedikt Peetz | 2024-12-19 |
| | | | | Lix does not support the newer `nix shell` shebang. | ||
* | fix(system/services/invidious-router): remove_no_ratio = false | Silas Schöffel | 2024-12-06 |
| | |||
* | fix(system/services/libreddit): Use unstable `redlib` version | Benedikt Peetz | 2024-11-16 |
| | | | | | The current stable version has a bug with regard to parsing the current reddit json responses. | ||
* | build(flake.lock): Update | Benedikt Peetz | 2024-11-16 |
| | |||
* | docs(system/services/matrix): Fix typos in comment | Benedikt Peetz | 2024-11-03 |
| | |||
* | build(flake): Update | Benedikt Peetz | 2024-11-03 |
| | |||
* | feat(taskserver/certs/ca.certs.pem): Regenerate certificate | Benedikt Peetz | 2024-10-05 |
| | |||
* | refactor(taskserver/certs): Format scripts and allow selecting which certs ↵ | Benedikt Peetz | 2024-10-05 |
| | | | | to generate | ||
* | chore(taskserver/certs/ca.key.pem.gpg): reencrypt with new keys as recipients | Silas Schöffel | 2024-10-05 |
| | |||
* | fix(system/services/invidious-router): Use the unstable pkg | Benedikt Peetz | 2024-10-04 |
| | | | | | This has been updated to provide a means to send the user to YouTube, if no invidious instances are available. |