diff options
| author | Collin Williams <96917990+bluedragon1221@users.noreply.github.com> | 2026-07-29 06:54:49 -0500 |
|---|---|---|
| committer | Collin Williams <96917990+bluedragon1221@users.noreply.github.com> | 2026-07-29 06:54:49 -0500 |
| commit | e29dd8a2283399b7e046937340509d5aec4b52ba (patch) | |
| tree | aa679e70fe55cb620698ab1695eadf23f8a2cdba | |
| parent | d2aecd69c17fa64305c07333686576152432993d (diff) | |
changes
30 files changed, 332 insertions, 398 deletions
@@ -26,11 +26,11 @@ "betterfox": { "flake": false, "locked": { - "lastModified": 1777825377, - "narHash": "sha256-4d4S0DAqCjQFHoACAUSpltPqYrs83ZecuBU+m/x7xvM=", + "lastModified": 1783031216, + "narHash": "sha256-nLkaxpbAMifWxx/RJvuaDpjndzKFPTvAO8o9gR47HtU=", "owner": "yokoffing", "repo": "Betterfox", - "rev": "392c62a03c0d63e323a9aae55bc9aff87454db16", + "rev": "8e415d1633f10fe0192d9c938e4ca2628eeec9f9", "type": "github" }, "original": { @@ -47,11 +47,11 @@ ] }, "locked": { - "lastModified": 1778874672, - "narHash": "sha256-lL5SXrufwxu9sthDnTCieH8gskhOv5KOGj2wXx2xCsw=", + "lastModified": 1785084545, + "narHash": "sha256-avpzdMZu2+bz7lAE5lyYx5O9y/RTcQTiIkQH4iZqWx0=", "owner": "9001", "repo": "copyparty", - "rev": "3b53a228b0e07912766d8dbf88b1dd01da57e2c5", + "rev": "b6abc33fb31d81cd803c2f239a1328e8cab2555c", "type": "github" }, "original": { @@ -62,11 +62,11 @@ }, "crane": { "locked": { - "lastModified": 1778106249, - "narHash": "sha256-cM/AuKy5tMhwOOQIbha8ZRRMHVfNf7cv2aljIw+qoCg=", + "lastModified": 1784407669, + "narHash": "sha256-gcFMcRjw0ZSn380Rx2QLlU1goUQeSrKX/DF12omI6+o=", "owner": "ipetkov", "repo": "crane", - "rev": "6d015ea29630b7ad2402841386da2cb617a470a7", + "rev": "1316b7d278ad77a16aec024b71d971366e123bec", "type": "github" }, "original": { @@ -104,11 +104,11 @@ ] }, "locked": { - "lastModified": 1778958912, - "narHash": "sha256-6pvS9rIF9mZRj1ENwu9fDLHeG1JFDTCpRyy6vJhXkTA=", + "lastModified": 1781152676, + "narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=", "owner": "nix-community", "repo": "disko", - "rev": "6e8dc7aa0e65fce67c76e18227a13a7d529f2cdf", + "rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1", "type": "github" }, "original": { @@ -120,11 +120,11 @@ "firefox-csshacks": { "flake": false, "locked": { - "lastModified": 1778816467, - "narHash": "sha256-RuZ0ihlTNu3chVVYd5JZX7xrRl2+jtLmucAKROKFD3s=", + "lastModified": 1784803587, + "narHash": "sha256-irQ+LUoN9NQWHOuV89mGQeedyAQOjiqDpig5v2Or928=", "owner": "MrOtherGuy", "repo": "firefox-csshacks", - "rev": "1f477a50cf7a2996a0dbd7656c877f22df5bf968", + "rev": "52e47afe74182b4a31d6e2a229e687daa3916c7e", "type": "github" }, "original": { @@ -152,11 +152,11 @@ "flake-registry": { "flake": false, "locked": { - "lastModified": 1763556067, - "narHash": "sha256-q2jzJQdsJMpD3dbuNphQJgwx6XeGPonWOp43U0nY7o0=", + "lastModified": 1782548455, + "narHash": "sha256-Jjp/ZivVqZCLptwlSuwU8n0a8b8PXJqabxpSG7KRNuI=", "owner": "NixOS", "repo": "flake-registry", - "rev": "cb70c9306b44501de412649c356dee503a25f119", + "rev": "10bd3d9e8eefb4725e346eddd3a505aa0aacf01b", "type": "github" }, "original": { @@ -183,11 +183,11 @@ "fx-autoconfig": { "flake": false, "locked": { - "lastModified": 1777913309, - "narHash": "sha256-czNgt62fofg3hXw7F4wXSv/+ZAsGtO6bg3sUOiUXcu4=", + "lastModified": 1784800794, + "narHash": "sha256-bpOt/fD8zZiKbb2sRQHl7eobuGklY9c2QI/jmYi9WE4=", "owner": "MrOtherGuy", "repo": "fx-autoconfig", - "rev": "d469a80f12e286c0e937d8b93c01dfc2d55dca8f", + "rev": "dfdab5684faffc112b76ccb1d8cab7f75da0102c", "type": "github" }, "original": { @@ -199,7 +199,7 @@ "geolite-db": { "flake": false, "locked": { - "narHash": "sha256-uA7ExafgNl03y3PW+dbm79iUncMDn62eUmMjCr2guZA=", + "narHash": "sha256-5eN2/D67TBIgV5dMW9YkfLSxFU+3cpr9y/Jmye95S9k=", "type": "file", "url": "https://github.com/P3TERX/GeoLite.mmdb/releases/latest/download/GeoLite2-City.mmdb" }, @@ -208,41 +208,18 @@ "url": "https://github.com/P3TERX/GeoLite.mmdb/releases/latest/download/GeoLite2-City.mmdb" } }, - "gitignore": { - "inputs": { - "nixpkgs": [ - "lanzaboote", - "pre-commit", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1709087332, - "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", - "owner": "hercules-ci", - "repo": "gitignore.nix", - "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", - "type": "github" - }, - "original": { - "owner": "hercules-ci", - "repo": "gitignore.nix", - "type": "github" - } - }, "hjem": { "inputs": { - "nix-darwin": "nix-darwin", "nixpkgs": [ "nixpkgs" ] }, "locked": { - "lastModified": 1779044379, - "narHash": "sha256-DHV1vpUers1TbZxIuEGz4VENShZ/EXefiTXd79QIhs4=", + "lastModified": 1784896036, + "narHash": "sha256-EAadJywc5P9CSIB7212S5jpQX48aTfYUbsJeAIbQaVI=", "owner": "feel-co", "repo": "hjem", - "rev": "4a2fd57f9e5d22cd3ef4c4230d245da159ab8dce", + "rev": "08d2b170a74a102c230c9651d8989fe6b39dfad8", "type": "github" }, "original": { @@ -282,11 +259,11 @@ "rust-overlay": "rust-overlay" }, "locked": { - "lastModified": 1778702031, - "narHash": "sha256-HJ4e4IQz7TJ1wDmEnkowXCM6SYXF9sfYg8nmUYHCnpI=", + "lastModified": 1784568171, + "narHash": "sha256-t17AqLEhPG6m27ipkp8mJd8Ug0XkdANFDVsgyIFBZcQ=", "owner": "nix-community", "repo": "lanzaboote", - "rev": "f11608843ca4fa95049c096ec0a50c93b41080b8", + "rev": "f4b0aef3dba28677a5ca4b3416827aade60b5a0b", "type": "github" }, "original": { @@ -295,27 +272,6 @@ "type": "github" } }, - "nix-darwin": { - "inputs": { - "nixpkgs": [ - "hjem", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1777780666, - "narHash": "sha256-8wURyQMdDkGUarSTKOGdCuFfYiwa3HbzwscUfn3STDE=", - "owner": "nix-darwin", - "repo": "nix-darwin", - "rev": "8c62fba0854ba15c8917aed18894dbccb48a3777", - "type": "github" - }, - "original": { - "owner": "nix-darwin", - "repo": "nix-darwin", - "type": "github" - } - }, "nix-index-database": { "inputs": { "nixpkgs": [ @@ -323,11 +279,11 @@ ] }, "locked": { - "lastModified": 1778999127, - "narHash": "sha256-V5GquqJvAqwFTcpN6hxKSQAtwuJFRUEHmyNKbeaTQDg=", + "lastModified": 1785046085, + "narHash": "sha256-UiK+mmZJuLWQVhJ5b2wDzogIYWAesyRm6LA3h3Ulh3Y=", "owner": "nix-community", "repo": "nix-index-database", - "rev": "f680e0d3c1dbefe298c423691662e238496890f2", + "rev": "11665045df8b9938ef811a3bfdc65cffb02b4b70", "type": "github" }, "original": { @@ -368,11 +324,11 @@ }, "nixpkgs": { "locked": { - "lastModified": 1778869304, - "narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=", + "lastModified": 1784796856, + "narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "d233902339c02a9c334e7e593de68855ad26c4cb", + "rev": "e2587caef70cea85dd97d7daab492899902dbf5d", "type": "github" }, "original": { @@ -385,23 +341,22 @@ "pre-commit": { "inputs": { "flake-compat": "flake-compat", - "gitignore": "gitignore", "nixpkgs": [ "lanzaboote", "nixpkgs" ] }, "locked": { - "lastModified": 1776796298, - "narHash": "sha256-PcRvlWayisPSjd0UcRQbhG8Oqw78AcPE6x872cPRHN8=", + "lastModified": 1784288435, + "narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=", "owner": "cachix", - "repo": "pre-commit-hooks.nix", - "rev": "3cfd774b0a530725a077e17354fbdb87ea1c4aad", + "repo": "git-hooks.nix", + "rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9", "type": "github" }, "original": { "owner": "cachix", - "repo": "pre-commit-hooks.nix", + "repo": "git-hooks.nix", "type": "github" } }, @@ -432,11 +387,11 @@ ] }, "locked": { - "lastModified": 1778383025, - "narHash": "sha256-UK7s2LJS1YwIMFL7PSaNJvLXT9pyRgm7X+HNPgMXiEE=", + "lastModified": 1784438913, + "narHash": "sha256-NYF7ZM5ip0u+w1pBFDpIGEbrbgN/wpnLFAmBkWkYMXw=", "owner": "oxalica", "repo": "rust-overlay", - "rev": "4568a557ca325ff81fb354382d4a9968daa1001a", + "rev": "afacd6819d3765a05814ee8e3de74c77d42ac799", "type": "github" }, "original": { diff --git a/hosts/ganymede/caddy.nix b/hosts/ganymede/caddy.nix index 3a805f4..08a779b 100644 --- a/hosts/ganymede/caddy.nix +++ b/hosts/ganymede/caddy.nix @@ -9,7 +9,7 @@ "github.com/tailscale/caddy-tailscale@v0.0.0-20251204171825-f070d146dd61" "github.com/caddy-dns/porkbun@v0.3.1" ]; - hash = "sha256-FrAI7Fpz3bXclmKcizBMv/VI1hTAWT6DQnj7S09MwNY="; + hash = "sha256-3BRyQ/fqPUemW1KqwyvkO1LeZB7PyBMIL/5a2u1mqqU="; }); globalConfig = '' @@ -19,22 +19,25 @@ } ''; - virtualHosts."lindsey.williamsfam.us.com".extraConfig = '' - redir https://williams-ryan-lindsey.blogspot.com permanent - ''; + virtualHosts = { + "lindsey.williamsfam.us.com".extraConfig = '' + redir https://williams-ryan-lindsey.blogspot.com permanent + ''; - virtualHosts."daniel.williamsfam.us.com".extraConfig = '' - root * /media/public/www/daniel - file_server - ''; + "daniel.williamsfam.us.com".extraConfig = '' + root * /media/public/www/daniel + file_server + ''; - # virtualHosts."collin.williamsfam.us.com".extraConfig = '' - # root * /med - # ''; + "williamsfam.us.com".extraConfig = '' + root * /media/public/www/root + file_server + ''; + }; + }; - virtualHosts."williamsfam.us.com".extraConfig = '' - root * /media/public/www/root - file_server - ''; + collinux.services.glance.homelabServices."website" = { + url = "https://williamsfam.us.com"; + icon = "mdi:web"; }; } diff --git a/hosts/ganymede/config.nix b/hosts/ganymede/config.nix index 0858106..ed397ef 100644 --- a/hosts/ganymede/config.nix +++ b/hosts/ganymede/config.nix @@ -29,6 +29,7 @@ }; system.network = { + dns.areYouAServer = true; static = { ip = "192.168.50.2/24"; gateway = "192.168.50.1"; @@ -41,58 +42,35 @@ }; services = { - sshd = { - enable = true; - public = true; - - conf.rootLogin = true; - }; - - minecraft = { - enable = true; - port = 19132; # standard - public = true; - }; - - ngircd = { - enable = true; - port = 6667; # standard - public = true; - }; + sshd.enable = true; # :22 + minecraft.enable = true; # :19132 + ngircd.enable = true; # :6667 jta = { enable = true; port = 8072; - publicUrl = "jta.williamsfam.us.com"; - }; - ganyupload = { - enable = true; - port = 8073; - publicUrl = "upld.williamsfam.us.com"; }; goaccess = { enable = true; port = 7890; - privateUrl = "stats.ganymede"; }; btopweb = { enable = true; port = 8017; - privateUrl = "btop.ganymede"; }; qbittorrent = { enable = true; port = 8076; - privateUrl = "bittorrent.ganymede"; - }; - cgit = { - enable = true; - privateUrl = "git.ganymede"; }; + cgit.enable = true; glance = { enable = true; port = 8081; }; + filebrowser = { + enable = true; + port = 8082; + }; caddy = { enable = true; diff --git a/hosts/ganymede/nixos.nix b/hosts/ganymede/nixos.nix index d913df7..873cd2f 100644 --- a/hosts/ganymede/nixos.nix +++ b/hosts/ganymede/nixos.nix @@ -28,7 +28,4 @@ services.caddy.virtualHosts."jta.williamsfam.us.com".logFormat = lib.mkForce '' output file /var/log/caddy/access-williamsfam.us.com.log ''; - - # i broke something and this fixes it - environment.etc."systemd/resolved.conf.d/10-dns.conf".text = config.environment.etc."systemd/resolved.conf".text; } diff --git a/hosts/ganymede/wireguard.nix b/hosts/ganymede/wireguard.nix index a1be5f7..de7afb5 100644 --- a/hosts/ganymede/wireguard.nix +++ b/hosts/ganymede/wireguard.nix @@ -6,19 +6,13 @@ }: { environment.systemPackages = [pkgs.wireguard-tools]; - services.dnsmasq = { - enable = true; - settings = { - port = 5353; - local = "/ganymede/"; - address = "/.ganymede/10.100.0.1"; - listen-address = ["127.0.0.1" "10.100.0.1"]; - }; - }; - boot.kernel.sysctl."net.ipv4.ip_forward" = 1; - networking.firewall.allowedUDPPorts = [51820 5353]; + networking.firewall = { + allowedUDPPorts = [51820]; + trustedInterfaces = ["wg0"]; # bypass firewall inside wireguard + }; + systemd.network.netdevs."50-wg0" = { netdevConfig = { Kind = "wireguard"; @@ -43,15 +37,9 @@ systemd.network.networks."wg0" = { matchConfig.Name = "wg0"; address = ["${hosts.ganymede.wg_ip}/24"]; - dns = ["127.0.0.1:5353"]; - domains = ["~ganymede"]; networkConfig = { IPMasquerade = "ipv4"; IPv4Forwarding = true; }; - extraConfig = '' - DNSOverTLS=no - DNSSEC=no - ''; }; } diff --git a/hosts/mercury/wireguard.nix b/hosts/mercury/wireguard.nix index 268cdc6..627e649 100644 --- a/hosts/mercury/wireguard.nix +++ b/hosts/mercury/wireguard.nix @@ -6,21 +6,6 @@ }: { environment.systemPackages = [pkgs.wireguard-tools]; - networking.firewall.interfaces."wg0" = { - allowedTCPPortRanges = [ - { - from = 1714; - to = 1764; - } - ]; - allowedUDPPortRanges = [ - { - from = 1714; - to = 1764; - } - ]; - }; - systemd.network.netdevs."10-wg" = { netdevConfig = { Kind = "wireguard"; @@ -43,7 +28,7 @@ matchConfig.Name = "wg0"; address = ["${hosts.mercury.wg_ip}/24"]; DHCP = "no"; - dns = ["${hosts.ganymede.wg_ip}:5353"]; + dns = [hosts.ganymede.wg_ip]; domains = ["~ganymede"]; networkConfig.IPv6AcceptRA = false; extraConfig = '' diff --git a/modules/desktop/nixos/fonts.nix b/modules/desktop/nixos/fonts.nix index e740bf1..6a33629 100644 --- a/modules/desktop/nixos/fonts.nix +++ b/modules/desktop/nixos/fonts.nix @@ -2,6 +2,6 @@ fonts = { enableDefaultPackages = false; fontconfig.enable = true; - packages = [pkgs.nerd-fonts.iosevka pkgs.ibm-plex pkgs.liberation_ttf pkgs.rubik]; # for terminal (blackbox or foot or ghostty) + packages = with pkgs; [nerd-fonts.iosevka ibm-plex liberation_ttf rubik]; }; } diff --git a/modules/system/nixos/networking/default.nix b/modules/networking/nixos/default.nix index f6baaac..f869670 100644 --- a/modules/system/nixos/networking/default.nix +++ b/modules/networking/nixos/default.nix @@ -1,7 +1,7 @@ { imports = [ ./resolved.nix - + ./unbound.nix ./networkd.nix ./iwd.nix ./wpasupplicant.nix @@ -14,14 +14,9 @@ }; # Disable default networking stuff + resolvconf.enable = false; dhcpcd.enable = false; useDHCP = false; networkmanager.enable = false; }; - - boot.kernel.sysctl = { - # disable all ipv6 - "net.ipv6.conf.all.disable_ipv6" = 1; - "net.ipv6.conf.default.disable_ipv6" = 1; - }; } diff --git a/modules/system/nixos/networking/iwd.nix b/modules/networking/nixos/iwd.nix index 0c5bdfa..0c5bdfa 100644 --- a/modules/system/nixos/networking/iwd.nix +++ b/modules/networking/nixos/iwd.nix diff --git a/modules/system/nixos/networking/networkd.nix b/modules/networking/nixos/networkd.nix index 2c7f580..2c7f580 100644 --- a/modules/system/nixos/networking/networkd.nix +++ b/modules/networking/nixos/networkd.nix diff --git a/modules/networking/nixos/resolved.nix b/modules/networking/nixos/resolved.nix new file mode 100644 index 0000000..01e75e2 --- /dev/null +++ b/modules/networking/nixos/resolved.nix @@ -0,0 +1,24 @@ +{ + config, + lib, + ... +}: let + cfg = config.collinux.system.network.dns; +in + lib.mkIf (!cfg.areYouAServer) { + networking.nameservers = [ + "9.9.9.9#dns.quad9.net" + "149.112.112.112#dns.quad9.net" + ]; + + services.resolved = { + enable = true; + settings.Resolve = { + DNSOverTLS = true; + DNSSEC = "allow-downgrade"; + + LLMNR = false; + MulticastDNS = false; + }; + }; + } diff --git a/modules/networking/nixos/unbound.nix b/modules/networking/nixos/unbound.nix new file mode 100644 index 0000000..b8b1e0b --- /dev/null +++ b/modules/networking/nixos/unbound.nix @@ -0,0 +1,30 @@ +{ + config, + lib, + ... +}: let + cfg = config.collinux.system.network.dns; +in + lib.mkIf cfg.areYouAServer { + networking = { + nameservers = ["127.0.0.1"]; + resolvconf.enable = lib.mkForce true; # we disabled this earlier + }; + services.resolved.enable = false; + + services.unbound = { + enable = true; + settings.server = { + interface = ["0.0.0.0"]; + port = 53; + access-control = [ + "127.0.0.0/8 allow" + "10.100.0.0/24 allow" + "0.0.0.0/0 refuse" + ]; + + local-zone = [''"ganymede." redirect'']; + local-data = [''"ganymede. IN A 10.100.0.1"'']; + }; + }; + } diff --git a/modules/system/nixos/networking/wpasupplicant.nix b/modules/networking/nixos/wpasupplicant.nix index 8314095..8314095 100644 --- a/modules/system/nixos/networking/wpasupplicant.nix +++ b/modules/networking/nixos/wpasupplicant.nix diff --git a/modules/networking/options.nix b/modules/networking/options.nix new file mode 100644 index 0000000..cc4864b --- /dev/null +++ b/modules/networking/options.nix @@ -0,0 +1,58 @@ +{ + lib, + my-lib, + ... +}: let + inherit (my-lib.netTypes {inherit lib;}) ipAddr ipAddrCidr; + inherit (lib) mkOption mkEnableOption; +in { + options.collinux.system.network = { + dns.areYouAServer = mkEnableOption "Set up unbound with the *.ganymede resolver and disable resolved stub"; + + static = lib.mkOption { + description = "Set a static IP address for this device on this network. Leave unset to use DHCP"; + type = lib.types.nullOr (lib.types.submodule { + options = { + ip = mkOption { + description = "IP address"; + type = ipAddrCidr; + }; + gateway = mkOption { + description = "default gateway"; + type = ipAddr; + }; + }; + }); + default = null; + }; + + wireless = { + static = lib.mkOption { + description = "Set a preconfigured SSID and PSK for the wireless config"; + type = lib.types.nullOr (lib.types.submodule { + options = { + ssid = mkOption { + description = "SSID for this network"; + type = lib.types.str; + }; + pskFile = mkOption { + description = "Absolute path to a file containing the pre-shared key for this network in the form `psk:<wifi psk>`"; + type = lib.types.str; + example = "/run/secrets.d/wifi-psk"; + }; + }; + }); + default = null; + }; + dynamic = mkEnableOption "Enable dynamically joining wireless networks with iwd"; + }; + + wireguard = { + enable = mkEnableOption "Whether to enable Wireguard on this device"; + # peers = lib.types.listOf (lib.types.submodule { + # options = { + # }; + # }); + }; + }; +} diff --git a/modules/services/nixos/btopweb.nix b/modules/services/nixos/btopweb.nix index d8f4598..75498a9 100644 --- a/modules/services/nixos/btopweb.nix +++ b/modules/services/nixos/btopweb.nix @@ -33,7 +33,7 @@ in { User = "btopweb"; Type = "simple"; - ExecStart = ''${pkgs.ttyd}/bin/ttyd -W -i ${cfg.listenAddr} -p ${toString cfg.port} -t renderType=canvas -t fontSize=16 ${pkgs.btop}/bin/btop -c ${btopSettings}''; + ExecStart = ''${lib.getExe pkgs.ttyd} -W -i 127.0.0.1 -p ${toString cfg.port} -t renderType=canvas -t fontSize=16 ${pkgs.btop}/bin/btop -c ${btopSettings}''; }; }; @@ -41,5 +41,10 @@ in { tls internal reverse_proxy 127.0.0.1:${toString cfg.port} ''; + + collinux.services.glance.homelabServices."btop" = { + url = "https://btop.ganymede"; + icon = "si:htop"; + }; }; } diff --git a/modules/services/nixos/caddy.nix b/modules/services/nixos/caddy.nix index b61a3c6..4b41c76 100644 --- a/modules/services/nixos/caddy.nix +++ b/modules/services/nixos/caddy.nix @@ -7,8 +7,10 @@ cfg = config.collinux.services.caddy; in lib.mkIf cfg.enable { + users.users."caddy".extraGroups = ["fileserver"]; networking.firewall.allowedTCPPorts = [80 443]; - environment.systemPackages = with pkgs; [nss.tools]; # required for caddy https stuff + environment.systemPackages = [pkgs.nss.tools]; # required for caddy https stuff + services.caddy = { enable = true; environmentFile = cfg.envFile; diff --git a/modules/services/nixos/cgit/default.nix b/modules/services/nixos/cgit/default.nix index 2a78607..4f0a7ba 100644 --- a/modules/services/nixos/cgit/default.nix +++ b/modules/services/nixos/cgit/default.nix @@ -96,5 +96,10 @@ in { } } ''; + + collinux.services.glance.homelabServices."git" = { + url = "https://git.ganymede"; + icon = "si:git"; + }; }; } diff --git a/modules/services/nixos/default.nix b/modules/services/nixos/default.nix index 65315cf..fa74cf6 100644 --- a/modules/services/nixos/default.nix +++ b/modules/services/nixos/default.nix @@ -9,6 +9,7 @@ ./ganyupload ./jta ./glance.nix + ./filebrowser.nix ./minecraft.nix ./ngircd.nix diff --git a/modules/services/nixos/filebrowser.nix b/modules/services/nixos/filebrowser.nix new file mode 100644 index 0000000..df0d536 --- /dev/null +++ b/modules/services/nixos/filebrowser.nix @@ -0,0 +1,52 @@ +{ + lib, + pkgs, + config, + ... +}: let + cfg = config.collinux.services.filebrowser; +in + lib.mkIf cfg.enable { + users.groups."dufs" = {}; + users.users."dufs" = { + isSystemUser = true; + group = "dufs"; + extraGroups = ["fileserver"]; + }; + + systemd.services."dufs" = { + description = "dufs file server"; + restartIfChanged = true; + wants = ["network-online.target"]; + after = ["network-online.target"]; + wantedBy = ["multi-user.target"]; + + serviceConfig = { + # ExecStart = "${pkgs.dufs}/bin/dufs /media --port ${toString cfg.port}"; + ExecStart = "${lib.getExe pkgs.dufs} /media --bind /run/dufs/dufs.sock"; + + RuntimeDirectory = "dufs"; # /run/dufs + + User = "dufs"; + Group = "dufs"; + + # Hardening + ProtectSystem = "strict"; + ProtectHome = true; + PrivateTmp = true; + NoNewPrivileges = true; + + Restart = "on-failure"; + }; + }; + + services.caddy.virtualHosts."files.ganymede".extraConfig = '' + tls internal + reverse_proxy unix//run/dufs/dufs.sock + ''; + + collinux.services.glance.homelabServices."files" = { + url = "https://files.ganymede"; + icon = "si:folder"; + }; + } diff --git a/modules/services/nixos/glance.nix b/modules/services/nixos/glance.nix index 1396562..38e5e1d 100644 --- a/modules/services/nixos/glance.nix +++ b/modules/services/nixos/glance.nix @@ -8,6 +8,8 @@ pure = x: [x]; + servicesLinks = builtins.attrValues cfg.homelabServices; + settings = { server = { inherit (cfg) port; @@ -68,33 +70,7 @@ type = "monitor"; cache = "1m"; title = "Services"; - sites = [ - { - title = "stats"; - url = "https://stats.ganymede"; - icon = "mdi:poll"; - } - { - title = "btop"; - url = "https://btop.ganymede"; - icon = "si:htop"; - } - { - title = "git"; - url = "https://git.ganymede"; - icon = "si:git"; - } - { - title = "bittorrent"; - url = "https://bittorrent.ganymede"; - icon = "si:qbittorrent"; - } - { - title = "website"; - url = "https://williamsfam.us.com"; - icon = "mdi:web"; - } - ]; + sites = servicesLinks; } ]; }; @@ -117,6 +93,7 @@ in { restartIfChanged = true; wants = ["network-online.target"]; after = ["network-online.target"]; + wantedBy = ["multi-user.target"]; serviceConfig = { User = "glance"; @@ -138,7 +115,6 @@ in { services.caddy.virtualHosts."home.ganymede".extraConfig = '' tls internal - reverse_proxy 127.0.0.1:${toString cfg.port} ''; }; diff --git a/modules/services/nixos/goaccess.nix b/modules/services/nixos/goaccess.nix index b77f370..288428d 100644 --- a/modules/services/nixos/goaccess.nix +++ b/modules/services/nixos/goaccess.nix @@ -16,7 +16,7 @@ ws-url = "wss://stats.ganymede:443/ws"; port = cfg.port; - addr = cfg.listenAddr; + addr = "127.0.0.1"; real-time-html = "true"; output = "/var/www/goaccess/index.html"; @@ -80,5 +80,10 @@ in { reverse_proxy /ws 127.0.0.1:${toString cfg.port} ''; + + collinux.services.glance.homelabServices."stats" = { + url = "https://stats.ganymede"; + icon = "mdi:poll"; + }; }; } diff --git a/modules/services/nixos/minecraft.nix b/modules/services/nixos/minecraft.nix index 45af606..0209549 100644 --- a/modules/services/nixos/minecraft.nix +++ b/modules/services/nixos/minecraft.nix @@ -6,7 +6,7 @@ cfg = config.collinux.services.minecraft; in lib.mkIf cfg.enable { - networking.firewall.allowedUDPPorts = lib.optional cfg.public cfg.port; + networking.firewall.allowedUDPPorts = [cfg.port]; virtualisation.oci-containers.containers."Minecraft" = { environment = { @@ -23,11 +23,7 @@ in }; image = "itzg/minecraft-bedrock-server"; ports = [ - "${ - if cfg.public - then "0.0.0.0" - else "127.0.0.1" - }:${toString cfg.port}:19132/udp" + "0.0.0.0:${toString cfg.port}:19132/udp" ]; volumes = ["/var/lib/minecraft/:/data"]; diff --git a/modules/services/nixos/ngircd.nix b/modules/services/nixos/ngircd.nix index ac93f06..d06a497 100644 --- a/modules/services/nixos/ngircd.nix +++ b/modules/services/nixos/ngircd.nix @@ -6,7 +6,7 @@ cfg = config.collinux.services.ngircd; in lib.mkIf cfg.enable { - networking.firewall.allowedTCPPorts = lib.optional cfg.public cfg.port; + networking.firewall.allowedTCPPorts = [cfg.port]; services.ngircd = { enable = true; @@ -16,11 +16,7 @@ in Info = Ganymede IRC Chat AdminInfo1 = Collin - Listen = ${ - if cfg.public - then "0.0.0.0" - else "127.0.0.1" - } + Listen = 0.0.0.0 Ports = ${toString cfg.port} [Channel] diff --git a/modules/services/nixos/openssh.nix b/modules/services/nixos/openssh.nix index 1d7834b..4826369 100644 --- a/modules/services/nixos/openssh.nix +++ b/modules/services/nixos/openssh.nix @@ -5,7 +5,6 @@ ... }: let cfg = config.collinux.services.sshd; - pure = x: [x]; authorizedKeys = @@ -30,11 +29,7 @@ in { }; settings = { - PermitRootLogin = - if cfg.conf.rootLogin - then "yes" - else "no"; - + PermitRootLogin = "yes"; PasswordAuthentication = false; KbdInteractiveAuthentication = false; PubkeyAuthentication = true; @@ -43,7 +38,7 @@ in { users.users = { ${config.collinux.user.name}.openssh.authorizedKeys.keys = authorizedKeys; - root.openssh.authorizedKeys.keys = lib.mkIf cfg.conf.rootLogin authorizedKeys; + root.openssh.authorizedKeys.keys = authorizedKeys; }; systemd.services.openssh = { diff --git a/modules/services/nixos/qbittorrent.nix b/modules/services/nixos/qbittorrent.nix index cc147b1..fe2831a 100644 --- a/modules/services/nixos/qbittorrent.nix +++ b/modules/services/nixos/qbittorrent.nix @@ -11,8 +11,10 @@ in { extraGroups = ["fileserver"]; # torrent files go to /media/library }; - networking.firewall.allowedTCPPorts = [49252]; - networking.firewall.allowedUDPPorts = [49252]; + networking.firewall = { + allowedTCPPorts = [49252]; + allowedUDPPorts = [49252]; + }; services.qbittorrent = { enable = true; @@ -25,5 +27,10 @@ in { tls internal reverse_proxy 127.0.0.1:${toString cfg.port} ''; + + collinux.services.glance.homelabServices."bittorrent" = { + url = "https://bittorrent.ganymede"; + icon = "si:qbittorrent"; + }; }; } diff --git a/modules/services/options.nix b/modules/services/options.nix index 7dbaa2c..0e033be 100644 --- a/modules/services/options.nix +++ b/modules/services/options.nix @@ -1,117 +1,62 @@ -{ - lib, - my-lib, - ... -}: let +{lib, ...}: let inherit (lib) mkOption mkEnableOption types; - inherit (my-lib.netTypes {inherit lib;}) ipAddr; - # A helper function to generate the submodule - webserviceOptions = { - service_name, - reverse_proxy ? true, - }: - { - enable = mkEnableOption "${service_name} selfhosted service"; - listenAddr = mkOption { - description = "The IP address on which ${service_name} will listen for incoming connections"; - type = ipAddr; - default = "127.0.0.1"; - }; - privateUrl = mkOption { - description = "Internal .local name for the service. Don't put the protocol (https://) in the string"; - type = lib.types.nullOr lib.types.str; - default = null; - }; - publicUrl = mkOption { - description = "Public website on which the service will be hosted. Don't put the protocol (https://) in the string"; - type = lib.types.nullOr lib.types.str; - default = null; - }; - } - // ( - if reverse_proxy - then { - reverseProxy = mkOption { - internal = true; - type = lib.types.bool; - default = true; - }; - port = mkOption { - description = "The port on which ${service_name} will listen for incomming connections"; - type = lib.types.port; - }; - } - else { - manualCaddyConfig = mkOption { - description = "Configuration to describe this service in caddy, since reverse_proxy = false."; - type = lib.types.str; - }; - } - ); + basicService = { + desc, + default_port ? null, + }: { + enable = mkEnableOption desc; + port = mkOption { + type = lib.types.port; + default = default_port; + }; + }; in { options.collinux.services = { - sshd = { - enable = mkEnableOption "OpenSSH server"; - port = mkOption { - description = "Port to run on"; - type = lib.types.port; - default = 22; - }; - public = mkEnableOption "whether to make this service accessable over the internet"; - - conf = { - otp = mkEnableOption "Whether to require TOTP (Google Authenticator) 2fa codes to login"; - rootLogin = mkEnableOption "Whether to allow root login"; - }; + sshd = basicService { + desc = "OpenSSH server"; + default_port = 22; }; - minecraft = { - enable = mkEnableOption "Minecraft bedrock server"; - port = mkOption { - description = "port to run on"; - type = lib.types.port; - default = 19132; - }; - public = mkEnableOption "whether to make this service accessable over the internet"; - }; - ngircd = { - enable = mkEnableOption "ngircd IRC server"; - port = mkOption { - type = lib.types.port; - default = 6667; - }; + jta = basicService {desc = "personal project";}; + ganyupload = basicService {desc = "anonymous file uploads";}; + btopweb = basicService {desc = "btop accessable in a browser tab";}; - public = mkEnableOption "whether to make this service accessable over the internet"; - }; + forgejo = basicService {desc = "Self-hosted git forge";}; + qbittorrent = basicService {desc = "webui for qBittorrent";}; + goaccess = basicService {desc = "webserver stats from caddy logs";}; + filebrowser = basicService {desc = "dufs file browser";}; + cgit.enable = mkEnableOption "cgit git webui"; - jta = webserviceOptions { - service_name = "jta"; - }; - ganyupload = webserviceOptions { - service_name = "ganyupload"; - }; - forgejo = webserviceOptions { - service_name = "forgejo"; - }; - btopweb = webserviceOptions { - service_name = "btopweb"; - }; - goaccess = webserviceOptions { - service_name = "goaccess"; - }; - glance = { - enable = mkEnableOption "Glance homepage"; - port = lib.mkOption { - type = lib.types.port; + glance = + (basicService {desc = "Glance homepage";}) + // { + homelabServices = lib.mkOption { + type = lib.types.attrsOf (lib.types.submodule ({config, ...}: { + options = { + title = lib.mkOption { + type = lib.types.str; + default = config._module.args.name; + }; + url = lib.mkOption { + type = lib.types.str; + }; + icon = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + }; + }; + })); + }; }; + + minecraft = basicService { + desc = "Minecraft bedrock server"; + default_port = 19132; }; - cgit = webserviceOptions { - service_name = "cgit"; - reverse_proxy = false; - }; - qbittorrent = webserviceOptions { - service_name = "qbittorrent"; + ngircd = basicService { + desc = "ngircd IRC server"; + default_port = 6667; }; caddy = { diff --git a/modules/system/nixos/boot.nix b/modules/system/nixos/boot.nix index 50d66fe..aefc6da 100644 --- a/modules/system/nixos/boot.nix +++ b/modules/system/nixos/boot.nix @@ -74,10 +74,7 @@ in { }; }); - system.etc.overlay = { - enable = true; - mutable = true; # necessary for installing secrets into etc - }; + system.etc.overlay.enable = true; system.nixos-init.enable = true; # store journald logs in memory diff --git a/modules/system/nixos/default.nix b/modules/system/nixos/default.nix index 035c5be..baacaa0 100644 --- a/modules/system/nixos/default.nix +++ b/modules/system/nixos/default.nix @@ -1,6 +1,5 @@ { imports = [ - ./networking ./boot.nix ./audio.nix ./bluetooth.nix diff --git a/modules/system/nixos/networking/resolved.nix b/modules/system/nixos/networking/resolved.nix deleted file mode 100644 index e49e004..0000000 --- a/modules/system/nixos/networking/resolved.nix +++ /dev/null @@ -1,19 +0,0 @@ -{config, ...}: { - networking.resolvconf.enable = false; - - networking.nameservers = [ - "9.9.9.9#dns.quad9.net" - "149.112.112.112#dns.quad9.net" - ]; - - services.resolved = { - enable = true; - settings.Resolve = { - DNSOverTLS = true; - DNSSEC = "allow-downgrade"; - - LLMNR = false; - MulticastDNS = false; - }; - }; -} diff --git a/modules/system/options.nix b/modules/system/options.nix index a6db575..cbc8cd1 100644 --- a/modules/system/options.nix +++ b/modules/system/options.nix @@ -5,7 +5,6 @@ ... }: let inherit (lib) mkOption mkEnableOption; - inherit (my-lib.netTypes {inherit lib;}) ipAddr ipAddrCidr; inherit (my-lib.options {inherit lib config;}) mkThemeOption; in { options.collinux.system = { @@ -26,46 +25,6 @@ in { secureBoot.enable = mkEnableOption "lanzaboote"; }; - network = { - static = lib.mkOption { - description = "Set a static IP address for this device on this network. Leave unset to use DHCP"; - type = lib.types.nullOr (lib.types.submodule { - options = { - ip = mkOption { - description = "IP address"; - type = ipAddrCidr; - }; - gateway = mkOption { - description = "default gateway"; - type = ipAddr; - }; - }; - }); - default = null; - }; - - wireless = { - static = lib.mkOption { - description = "Set a preconfigured SSID and PSK for the wireless config"; - type = lib.types.nullOr (lib.types.submodule { - options = { - ssid = mkOption { - description = "SSID for this network"; - type = lib.types.str; - }; - pskFile = mkOption { - description = "Absolute path to a file containing the pre-shared key for this network in the form `psk:<wifi psk>`"; - type = lib.types.str; - example = "/run/secrets.d/wifi-psk"; - }; - }; - }); - default = null; - }; - dynamic = lib.mkEnableOption "Enable dynamically joining wireless networks with iwd"; - }; - }; - audio.enable = mkEnableOption "pipewire and wireplumber"; bluetooth.enable = mkEnableOption "bluetooth"; printing.enable = mkEnableOption "cups printing server"; |
