Compare commits

..

No commits in common. "806b00f63473577de66d80655ff038853c13b2d1" and "468c95c7a167ed9be1d435c2dff84a8532e2546c" have entirely different histories.

17 changed files with 132 additions and 173 deletions

View file

@ -28,24 +28,24 @@
}; };
}; };
outputs = flakes @ { outputs =
self, flakes@{ self
nixpkgs, , nixpkgs
unstable, , unstable
home-manager, , home-manager
impermanence, , impermanence
flake-utils, , flake-utils
vpsadminos, , vpsadminos
homepage, , homepage
conduwuit, , conduwuit
mediawikiSkinCitizen, , mediawikiSkinCitizen
}: let }:
let
system = "x86_64-linux"; system = "x86_64-linux";
pkgs = importPkgs nixpkgs; pkgs = importPkgs nixpkgs;
importPkgs = flake: importPkgs = flake: import flake {
import flake {
inherit system; inherit system;
config = import ./pkgs/config nixpkgs.lib; config = import ./pkgs/config nixpkgs.lib;
@ -55,10 +55,11 @@
local = import ./pkgs; local = import ./pkgs;
in in
with pkgs.lib; { with pkgs.lib; {
formatter.${system} = pkgs.alejandra; formatter.${system} = pkgs.nixpkgs-fmt;
packages.${system} = pkgs.local; packages.${system} = pkgs.local;
overlays.default = final: prev: let overlays.default = final: prev:
let
locals = local { locals = local {
inherit final prev flakes; inherit final prev flakes;
}; };
@ -66,8 +67,7 @@
{ {
local = locals; local = locals;
unstable = importPkgs unstable; unstable = importPkgs unstable;
} } // locals.override;
// locals.override;
nixosConfigurations.vps = makeOverridable nixpkgs.lib.nixosSystem { nixosConfigurations.vps = makeOverridable nixpkgs.lib.nixosSystem {
inherit pkgs system; inherit pkgs system;
@ -80,3 +80,4 @@
}; };
}; };
} }

View file

@ -1,8 +1,4 @@
{ { final, prev, flakes }: {
final,
prev,
flakes,
}: {
homepage = flakes.homepage.packages.${final.system}.default; homepage = flakes.homepage.packages.${final.system}.default;
override = { }; override = { };

View file

@ -1,11 +1,6 @@
{ config, pkgs, lib, flakes, ... }:
with lib;
{ {
config,
pkgs,
lib,
flakes,
...
}:
with lib; {
imports = [ imports = [
flakes.vpsadminos.nixosConfigurations.container flakes.vpsadminos.nixosConfigurations.container
flakes.home-manager.nixosModules.home-manager flakes.home-manager.nixosModules.home-manager
@ -62,7 +57,7 @@ with lib; {
group = "fabian"; group = "fabian";
shell = pkgs.zsh; shell = pkgs.zsh;
extraGroups = [ "users" "wheel" "networkmanager" "dialout" "libvirtd" ]; extraGroups = [ "users" "wheel" "networkmanager" "dialout" "libvirtd" ];
openssh.authorizedKeys.keyFiles = [../pki/fabian.pub]; openssh.authorizedKeys.keyFiles = [ "${flakes.self}/pki/fabian.pub" ];
}; };
groups.fabian.gid = 1000; groups.fabian.gid = 1000;
}; };

View file

@ -1,9 +1,6 @@
{ lib, pkgs, ... }:
with lib;
{ {
lib,
pkgs,
...
}:
with lib; {
programs = { programs = {
zsh = { zsh = {
enable = true; enable = true;
@ -16,7 +13,8 @@ with lib; {
}; };
neovim.enable = true; neovim.enable = true;
}; };
home.packages = with pkgs; [ home.packages = with pkgs;
[
file file
htop htop
killall killall

View file

@ -1,11 +1,7 @@
{ config, pkgs, lib, flakes, ... }:
with lib;
{ {
config,
pkgs,
lib,
flakes,
...
}:
with lib; {
imports = [ imports = [
./cli.nix ./cli.nix
]; ];

View file

@ -1,10 +1,8 @@
{ lib, pkgs, ... }:
with lib;
{ {
lib,
pkgs,
...
}:
with lib; {
services = { services = {
nginx = { nginx = {
virtualHosts."send.posixlycorrect.com" = { virtualHosts."send.posixlycorrect.com" = {
enableACME = true; enableACME = true;
@ -16,6 +14,7 @@ with lib; {
locations."/" = { locations."/" = {
proxyPass = "http://127.0.0.1:8989"; proxyPass = "http://127.0.0.1:8989";
}; };
}; };
}; };

View file

@ -1,11 +1,6 @@
{ config, pkgs, lib, flakes, ... }:
with lib;
{ {
config,
pkgs,
lib,
flakes,
...
}:
with lib; {
imports = [ imports = [
./net.nix ./net.nix
./mediawiki.nix ./mediawiki.nix

View file

@ -1,9 +1,6 @@
{ config, lib, ... }:
with lib;
{ {
config,
lib,
...
}:
with lib; {
config = { config = {
environment.etc."fail2ban/filter.d/gitea.local".text = '' environment.etc."fail2ban/filter.d/gitea.local".text = ''
[Definition] [Definition]

View file

@ -1,10 +1,9 @@
{ lib, pkgs, ... }:
with lib;
{ {
lib,
pkgs,
...
}:
with lib; {
services = { services = {
nginx = { nginx = {
virtualHosts."stream.posixlycorrect.com" = { virtualHosts."stream.posixlycorrect.com" = {
enableACME = true; enableACME = true;

View file

@ -1,10 +1,9 @@
{ lib, pkgs, flakes, ... }:
with lib;
{ {
lib,
pkgs,
...
}:
with lib; {
services = { services = {
nginx = { nginx = {
virtualHosts."meet.posixlycorrect.com" = { virtualHosts."meet.posixlycorrect.com" = {
enableACME = true; enableACME = true;
@ -15,7 +14,7 @@ with lib; {
ssl_verify_depth 1; ssl_verify_depth 1;
ssl_verify_client on; ssl_verify_client on;
ssl_client_certificate ${../../pki/gatekeeper_ca.pem}; ssl_client_certificate ${flakes.self}/pki/gatekeeper_ca.pem;
if ($ssl_client_verify != "SUCCESS") { if ($ssl_client_verify != "SUCCESS") {
return 403; return 403;
} }
@ -23,6 +22,7 @@ with lib; {
}; };
}; };
jitsi-meet = { jitsi-meet = {
enable = true; enable = true;
hostName = "meet.posixlycorrect.com"; hostName = "meet.posixlycorrect.com";

View file

@ -1,9 +1,6 @@
{ lib, pkgs, ... }:
with lib;
{ {
lib,
pkgs,
...
}:
with lib; {
services = { services = {
nginx = { nginx = {
virtualHosts."status.posixlycorrect.com" = { virtualHosts."status.posixlycorrect.com" = {

View file

@ -1,14 +1,10 @@
{ { lib, pkgs, config, flakes, ... }:
lib, with lib;
pkgs, let
config,
flakes,
...
}:
with lib; let
subdomain = "matrix.posixlycorrect.com"; subdomain = "matrix.posixlycorrect.com";
baseUrl = "https://${subdomain}"; baseUrl = "https://${subdomain}";
in { in
{
# ver https://nixos.org/manual/nixos/stable/#module-services-matrix # ver https://nixos.org/manual/nixos/stable/#module-services-matrix
services = { services = {
matrix-conduit = { matrix-conduit = {
@ -27,7 +23,8 @@ in {
}; };
}; };
nginx.virtualHosts = let nginx.virtualHosts =
let
clientConfig."m.homeserver".base_url = baseUrl; clientConfig."m.homeserver".base_url = baseUrl;
serverConfig."m.server" = "${subdomain}:443"; serverConfig."m.server" = "${subdomain}:443";
mkWellKnown = data: '' mkWellKnown = data: ''
@ -35,7 +32,8 @@ in {
add_header Access-Control-Allow-Origin *; add_header Access-Control-Allow-Origin *;
return 200 '${builtins.toJSON data}'; return 200 '${builtins.toJSON data}';
''; '';
in { in
{
"posixlycorrect.com" = { "posixlycorrect.com" = {
locations."= /.well-known/matrix/server".extraConfig = mkWellKnown serverConfig; locations."= /.well-known/matrix/server".extraConfig = mkWellKnown serverConfig;
locations."= /.well-known/matrix/client".extraConfig = mkWellKnown clientConfig; locations."= /.well-known/matrix/client".extraConfig = mkWellKnown clientConfig;
@ -52,7 +50,10 @@ in {
''; '';
locations."/_matrix".proxyPass = "http://[::1]:6167"; locations."/_matrix".proxyPass = "http://[::1]:6167";
locations."/_synapse/client".proxyPass = "http://[::1]:6167"; locations."/_synapse/client".proxyPass = "http://[::1]:6167";
}; };
}; };
}; };
} }

View file

@ -1,10 +1,6 @@
{ lib, pkgs, flakes, ... }:
with lib;
{ {
lib,
pkgs,
flakes,
...
}:
with lib; {
services = { services = {
nginx = { nginx = {
virtualHosts."wiki.posixlycorrect.com" = { virtualHosts."wiki.posixlycorrect.com" = {

View file

@ -1,9 +1,6 @@
{ lib, pkgs, ... }:
with lib;
{ {
lib,
pkgs,
...
}:
with lib; {
users.groups = { users.groups = {
mailsenders = { mailsenders = {
members = [ "fabian" "mediawiki" ]; members = [ "fabian" "mediawiki" ];

View file

@ -1,9 +1,6 @@
{ lib, pkgs, ... }:
with lib;
{ {
lib,
pkgs,
...
}:
with lib; {
networking = { networking = {
nftables.enable = true; nftables.enable = true;
firewall = { firewall = {

View file

@ -1,9 +1,6 @@
{ config, lib, ... }:
with lib;
{ {
config,
lib,
...
}:
with lib; {
services = { services = {
nginx = { nginx = {
virtualHosts."vault.posixlycorrect.com" = { virtualHosts."vault.posixlycorrect.com" = {
@ -21,12 +18,10 @@ with lib; {
postgresql = { postgresql = {
ensureDatabases = [ "vaultwarden" ]; ensureDatabases = [ "vaultwarden" ];
ensureUsers = [ ensureUsers = [{
{
name = "vaultwarden"; name = "vaultwarden";
ensureDBOwnership = true; ensureDBOwnership = true;
} }];
];
}; };
vaultwarden = { vaultwarden = {