aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-07-29 06:54:49 -0500
committerCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-07-29 06:54:49 -0500
commite29dd8a2283399b7e046937340509d5aec4b52ba (patch)
treeaa679e70fe55cb620698ab1695eadf23f8a2cdba
parentd2aecd69c17fa64305c07333686576152432993d (diff)
changes
-rw-r--r--flake.lock129
-rw-r--r--hosts/ganymede/caddy.nix33
-rw-r--r--hosts/ganymede/config.nix40
-rw-r--r--hosts/ganymede/nixos.nix3
-rw-r--r--hosts/ganymede/wireguard.nix22
-rw-r--r--hosts/mercury/wireguard.nix17
-rw-r--r--modules/desktop/nixos/fonts.nix2
-rw-r--r--modules/networking/nixos/default.nix (renamed from modules/system/nixos/networking/default.nix)9
-rw-r--r--modules/networking/nixos/iwd.nix (renamed from modules/system/nixos/networking/iwd.nix)0
-rw-r--r--modules/networking/nixos/networkd.nix (renamed from modules/system/nixos/networking/networkd.nix)0
-rw-r--r--modules/networking/nixos/resolved.nix24
-rw-r--r--modules/networking/nixos/unbound.nix30
-rw-r--r--modules/networking/nixos/wpasupplicant.nix (renamed from modules/system/nixos/networking/wpasupplicant.nix)0
-rw-r--r--modules/networking/options.nix58
-rw-r--r--modules/services/nixos/btopweb.nix7
-rw-r--r--modules/services/nixos/caddy.nix4
-rw-r--r--modules/services/nixos/cgit/default.nix5
-rw-r--r--modules/services/nixos/default.nix1
-rw-r--r--modules/services/nixos/filebrowser.nix52
-rw-r--r--modules/services/nixos/glance.nix32
-rw-r--r--modules/services/nixos/goaccess.nix7
-rw-r--r--modules/services/nixos/minecraft.nix8
-rw-r--r--modules/services/nixos/ngircd.nix8
-rw-r--r--modules/services/nixos/openssh.nix9
-rw-r--r--modules/services/nixos/qbittorrent.nix11
-rw-r--r--modules/services/options.nix153
-rw-r--r--modules/system/nixos/boot.nix5
-rw-r--r--modules/system/nixos/default.nix1
-rw-r--r--modules/system/nixos/networking/resolved.nix19
-rw-r--r--modules/system/options.nix41
30 files changed, 332 insertions, 398 deletions
diff --git a/flake.lock b/flake.lock
index b644039..b0bd35a 100644
--- a/flake.lock
+++ b/flake.lock
@@ -26,11 +26,11 @@
"betterfox": {
"flake": false,
"locked": {
- "lastModified": 1777825377,
- "narHash": "sha256-4d4S0DAqCjQFHoACAUSpltPqYrs83ZecuBU+m/x7xvM=",
+ "lastModified": 1783031216,
+ "narHash": "sha256-nLkaxpbAMifWxx/RJvuaDpjndzKFPTvAO8o9gR47HtU=",
"owner": "yokoffing",
"repo": "Betterfox",
- "rev": "392c62a03c0d63e323a9aae55bc9aff87454db16",
+ "rev": "8e415d1633f10fe0192d9c938e4ca2628eeec9f9",
"type": "github"
},
"original": {
@@ -47,11 +47,11 @@
]
},
"locked": {
- "lastModified": 1778874672,
- "narHash": "sha256-lL5SXrufwxu9sthDnTCieH8gskhOv5KOGj2wXx2xCsw=",
+ "lastModified": 1785084545,
+ "narHash": "sha256-avpzdMZu2+bz7lAE5lyYx5O9y/RTcQTiIkQH4iZqWx0=",
"owner": "9001",
"repo": "copyparty",
- "rev": "3b53a228b0e07912766d8dbf88b1dd01da57e2c5",
+ "rev": "b6abc33fb31d81cd803c2f239a1328e8cab2555c",
"type": "github"
},
"original": {
@@ -62,11 +62,11 @@
},
"crane": {
"locked": {
- "lastModified": 1778106249,
- "narHash": "sha256-cM/AuKy5tMhwOOQIbha8ZRRMHVfNf7cv2aljIw+qoCg=",
+ "lastModified": 1784407669,
+ "narHash": "sha256-gcFMcRjw0ZSn380Rx2QLlU1goUQeSrKX/DF12omI6+o=",
"owner": "ipetkov",
"repo": "crane",
- "rev": "6d015ea29630b7ad2402841386da2cb617a470a7",
+ "rev": "1316b7d278ad77a16aec024b71d971366e123bec",
"type": "github"
},
"original": {
@@ -104,11 +104,11 @@
]
},
"locked": {
- "lastModified": 1778958912,
- "narHash": "sha256-6pvS9rIF9mZRj1ENwu9fDLHeG1JFDTCpRyy6vJhXkTA=",
+ "lastModified": 1781152676,
+ "narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
"owner": "nix-community",
"repo": "disko",
- "rev": "6e8dc7aa0e65fce67c76e18227a13a7d529f2cdf",
+ "rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
"type": "github"
},
"original": {
@@ -120,11 +120,11 @@
"firefox-csshacks": {
"flake": false,
"locked": {
- "lastModified": 1778816467,
- "narHash": "sha256-RuZ0ihlTNu3chVVYd5JZX7xrRl2+jtLmucAKROKFD3s=",
+ "lastModified": 1784803587,
+ "narHash": "sha256-irQ+LUoN9NQWHOuV89mGQeedyAQOjiqDpig5v2Or928=",
"owner": "MrOtherGuy",
"repo": "firefox-csshacks",
- "rev": "1f477a50cf7a2996a0dbd7656c877f22df5bf968",
+ "rev": "52e47afe74182b4a31d6e2a229e687daa3916c7e",
"type": "github"
},
"original": {
@@ -152,11 +152,11 @@
"flake-registry": {
"flake": false,
"locked": {
- "lastModified": 1763556067,
- "narHash": "sha256-q2jzJQdsJMpD3dbuNphQJgwx6XeGPonWOp43U0nY7o0=",
+ "lastModified": 1782548455,
+ "narHash": "sha256-Jjp/ZivVqZCLptwlSuwU8n0a8b8PXJqabxpSG7KRNuI=",
"owner": "NixOS",
"repo": "flake-registry",
- "rev": "cb70c9306b44501de412649c356dee503a25f119",
+ "rev": "10bd3d9e8eefb4725e346eddd3a505aa0aacf01b",
"type": "github"
},
"original": {
@@ -183,11 +183,11 @@
"fx-autoconfig": {
"flake": false,
"locked": {
- "lastModified": 1777913309,
- "narHash": "sha256-czNgt62fofg3hXw7F4wXSv/+ZAsGtO6bg3sUOiUXcu4=",
+ "lastModified": 1784800794,
+ "narHash": "sha256-bpOt/fD8zZiKbb2sRQHl7eobuGklY9c2QI/jmYi9WE4=",
"owner": "MrOtherGuy",
"repo": "fx-autoconfig",
- "rev": "d469a80f12e286c0e937d8b93c01dfc2d55dca8f",
+ "rev": "dfdab5684faffc112b76ccb1d8cab7f75da0102c",
"type": "github"
},
"original": {
@@ -199,7 +199,7 @@
"geolite-db": {
"flake": false,
"locked": {
- "narHash": "sha256-uA7ExafgNl03y3PW+dbm79iUncMDn62eUmMjCr2guZA=",
+ "narHash": "sha256-5eN2/D67TBIgV5dMW9YkfLSxFU+3cpr9y/Jmye95S9k=",
"type": "file",
"url": "https://github.com/P3TERX/GeoLite.mmdb/releases/latest/download/GeoLite2-City.mmdb"
},
@@ -208,41 +208,18 @@
"url": "https://github.com/P3TERX/GeoLite.mmdb/releases/latest/download/GeoLite2-City.mmdb"
}
},
- "gitignore": {
- "inputs": {
- "nixpkgs": [
- "lanzaboote",
- "pre-commit",
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1709087332,
- "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=",
- "owner": "hercules-ci",
- "repo": "gitignore.nix",
- "rev": "637db329424fd7e46cf4185293b9cc8c88c95394",
- "type": "github"
- },
- "original": {
- "owner": "hercules-ci",
- "repo": "gitignore.nix",
- "type": "github"
- }
- },
"hjem": {
"inputs": {
- "nix-darwin": "nix-darwin",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
- "lastModified": 1779044379,
- "narHash": "sha256-DHV1vpUers1TbZxIuEGz4VENShZ/EXefiTXd79QIhs4=",
+ "lastModified": 1784896036,
+ "narHash": "sha256-EAadJywc5P9CSIB7212S5jpQX48aTfYUbsJeAIbQaVI=",
"owner": "feel-co",
"repo": "hjem",
- "rev": "4a2fd57f9e5d22cd3ef4c4230d245da159ab8dce",
+ "rev": "08d2b170a74a102c230c9651d8989fe6b39dfad8",
"type": "github"
},
"original": {
@@ -282,11 +259,11 @@
"rust-overlay": "rust-overlay"
},
"locked": {
- "lastModified": 1778702031,
- "narHash": "sha256-HJ4e4IQz7TJ1wDmEnkowXCM6SYXF9sfYg8nmUYHCnpI=",
+ "lastModified": 1784568171,
+ "narHash": "sha256-t17AqLEhPG6m27ipkp8mJd8Ug0XkdANFDVsgyIFBZcQ=",
"owner": "nix-community",
"repo": "lanzaboote",
- "rev": "f11608843ca4fa95049c096ec0a50c93b41080b8",
+ "rev": "f4b0aef3dba28677a5ca4b3416827aade60b5a0b",
"type": "github"
},
"original": {
@@ -295,27 +272,6 @@
"type": "github"
}
},
- "nix-darwin": {
- "inputs": {
- "nixpkgs": [
- "hjem",
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1777780666,
- "narHash": "sha256-8wURyQMdDkGUarSTKOGdCuFfYiwa3HbzwscUfn3STDE=",
- "owner": "nix-darwin",
- "repo": "nix-darwin",
- "rev": "8c62fba0854ba15c8917aed18894dbccb48a3777",
- "type": "github"
- },
- "original": {
- "owner": "nix-darwin",
- "repo": "nix-darwin",
- "type": "github"
- }
- },
"nix-index-database": {
"inputs": {
"nixpkgs": [
@@ -323,11 +279,11 @@
]
},
"locked": {
- "lastModified": 1778999127,
- "narHash": "sha256-V5GquqJvAqwFTcpN6hxKSQAtwuJFRUEHmyNKbeaTQDg=",
+ "lastModified": 1785046085,
+ "narHash": "sha256-UiK+mmZJuLWQVhJ5b2wDzogIYWAesyRm6LA3h3Ulh3Y=",
"owner": "nix-community",
"repo": "nix-index-database",
- "rev": "f680e0d3c1dbefe298c423691662e238496890f2",
+ "rev": "11665045df8b9938ef811a3bfdc65cffb02b4b70",
"type": "github"
},
"original": {
@@ -368,11 +324,11 @@
},
"nixpkgs": {
"locked": {
- "lastModified": 1778869304,
- "narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
+ "lastModified": 1784796856,
+ "narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "d233902339c02a9c334e7e593de68855ad26c4cb",
+ "rev": "e2587caef70cea85dd97d7daab492899902dbf5d",
"type": "github"
},
"original": {
@@ -385,23 +341,22 @@
"pre-commit": {
"inputs": {
"flake-compat": "flake-compat",
- "gitignore": "gitignore",
"nixpkgs": [
"lanzaboote",
"nixpkgs"
]
},
"locked": {
- "lastModified": 1776796298,
- "narHash": "sha256-PcRvlWayisPSjd0UcRQbhG8Oqw78AcPE6x872cPRHN8=",
+ "lastModified": 1784288435,
+ "narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=",
"owner": "cachix",
- "repo": "pre-commit-hooks.nix",
- "rev": "3cfd774b0a530725a077e17354fbdb87ea1c4aad",
+ "repo": "git-hooks.nix",
+ "rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9",
"type": "github"
},
"original": {
"owner": "cachix",
- "repo": "pre-commit-hooks.nix",
+ "repo": "git-hooks.nix",
"type": "github"
}
},
@@ -432,11 +387,11 @@
]
},
"locked": {
- "lastModified": 1778383025,
- "narHash": "sha256-UK7s2LJS1YwIMFL7PSaNJvLXT9pyRgm7X+HNPgMXiEE=",
+ "lastModified": 1784438913,
+ "narHash": "sha256-NYF7ZM5ip0u+w1pBFDpIGEbrbgN/wpnLFAmBkWkYMXw=",
"owner": "oxalica",
"repo": "rust-overlay",
- "rev": "4568a557ca325ff81fb354382d4a9968daa1001a",
+ "rev": "afacd6819d3765a05814ee8e3de74c77d42ac799",
"type": "github"
},
"original": {
diff --git a/hosts/ganymede/caddy.nix b/hosts/ganymede/caddy.nix
index 3a805f4..08a779b 100644
--- a/hosts/ganymede/caddy.nix
+++ b/hosts/ganymede/caddy.nix
@@ -9,7 +9,7 @@
"github.com/tailscale/caddy-tailscale@v0.0.0-20251204171825-f070d146dd61"
"github.com/caddy-dns/porkbun@v0.3.1"
];
- hash = "sha256-FrAI7Fpz3bXclmKcizBMv/VI1hTAWT6DQnj7S09MwNY=";
+ hash = "sha256-3BRyQ/fqPUemW1KqwyvkO1LeZB7PyBMIL/5a2u1mqqU=";
});
globalConfig = ''
@@ -19,22 +19,25 @@
}
'';
- virtualHosts."lindsey.williamsfam.us.com".extraConfig = ''
- redir https://williams-ryan-lindsey.blogspot.com permanent
- '';
+ virtualHosts = {
+ "lindsey.williamsfam.us.com".extraConfig = ''
+ redir https://williams-ryan-lindsey.blogspot.com permanent
+ '';
- virtualHosts."daniel.williamsfam.us.com".extraConfig = ''
- root * /media/public/www/daniel
- file_server
- '';
+ "daniel.williamsfam.us.com".extraConfig = ''
+ root * /media/public/www/daniel
+ file_server
+ '';
- # virtualHosts."collin.williamsfam.us.com".extraConfig = ''
- # root * /med
- # '';
+ "williamsfam.us.com".extraConfig = ''
+ root * /media/public/www/root
+ file_server
+ '';
+ };
+ };
- virtualHosts."williamsfam.us.com".extraConfig = ''
- root * /media/public/www/root
- file_server
- '';
+ collinux.services.glance.homelabServices."website" = {
+ url = "https://williamsfam.us.com";
+ icon = "mdi:web";
};
}
diff --git a/hosts/ganymede/config.nix b/hosts/ganymede/config.nix
index 0858106..ed397ef 100644
--- a/hosts/ganymede/config.nix
+++ b/hosts/ganymede/config.nix
@@ -29,6 +29,7 @@
};
system.network = {
+ dns.areYouAServer = true;
static = {
ip = "192.168.50.2/24";
gateway = "192.168.50.1";
@@ -41,58 +42,35 @@
};
services = {
- sshd = {
- enable = true;
- public = true;
-
- conf.rootLogin = true;
- };
-
- minecraft = {
- enable = true;
- port = 19132; # standard
- public = true;
- };
-
- ngircd = {
- enable = true;
- port = 6667; # standard
- public = true;
- };
+ sshd.enable = true; # :22
+ minecraft.enable = true; # :19132
+ ngircd.enable = true; # :6667
jta = {
enable = true;
port = 8072;
- publicUrl = "jta.williamsfam.us.com";
- };
- ganyupload = {
- enable = true;
- port = 8073;
- publicUrl = "upld.williamsfam.us.com";
};
goaccess = {
enable = true;
port = 7890;
- privateUrl = "stats.ganymede";
};
btopweb = {
enable = true;
port = 8017;
- privateUrl = "btop.ganymede";
};
qbittorrent = {
enable = true;
port = 8076;
- privateUrl = "bittorrent.ganymede";
- };
- cgit = {
- enable = true;
- privateUrl = "git.ganymede";
};
+ cgit.enable = true;
glance = {
enable = true;
port = 8081;
};
+ filebrowser = {
+ enable = true;
+ port = 8082;
+ };
caddy = {
enable = true;
diff --git a/hosts/ganymede/nixos.nix b/hosts/ganymede/nixos.nix
index d913df7..873cd2f 100644
--- a/hosts/ganymede/nixos.nix
+++ b/hosts/ganymede/nixos.nix
@@ -28,7 +28,4 @@
services.caddy.virtualHosts."jta.williamsfam.us.com".logFormat = lib.mkForce ''
output file /var/log/caddy/access-williamsfam.us.com.log
'';
-
- # i broke something and this fixes it
- environment.etc."systemd/resolved.conf.d/10-dns.conf".text = config.environment.etc."systemd/resolved.conf".text;
}
diff --git a/hosts/ganymede/wireguard.nix b/hosts/ganymede/wireguard.nix
index a1be5f7..de7afb5 100644
--- a/hosts/ganymede/wireguard.nix
+++ b/hosts/ganymede/wireguard.nix
@@ -6,19 +6,13 @@
}: {
environment.systemPackages = [pkgs.wireguard-tools];
- services.dnsmasq = {
- enable = true;
- settings = {
- port = 5353;
- local = "/ganymede/";
- address = "/.ganymede/10.100.0.1";
- listen-address = ["127.0.0.1" "10.100.0.1"];
- };
- };
-
boot.kernel.sysctl."net.ipv4.ip_forward" = 1;
- networking.firewall.allowedUDPPorts = [51820 5353];
+ networking.firewall = {
+ allowedUDPPorts = [51820];
+ trustedInterfaces = ["wg0"]; # bypass firewall inside wireguard
+ };
+
systemd.network.netdevs."50-wg0" = {
netdevConfig = {
Kind = "wireguard";
@@ -43,15 +37,9 @@
systemd.network.networks."wg0" = {
matchConfig.Name = "wg0";
address = ["${hosts.ganymede.wg_ip}/24"];
- dns = ["127.0.0.1:5353"];
- domains = ["~ganymede"];
networkConfig = {
IPMasquerade = "ipv4";
IPv4Forwarding = true;
};
- extraConfig = ''
- DNSOverTLS=no
- DNSSEC=no
- '';
};
}
diff --git a/hosts/mercury/wireguard.nix b/hosts/mercury/wireguard.nix
index 268cdc6..627e649 100644
--- a/hosts/mercury/wireguard.nix
+++ b/hosts/mercury/wireguard.nix
@@ -6,21 +6,6 @@
}: {
environment.systemPackages = [pkgs.wireguard-tools];
- networking.firewall.interfaces."wg0" = {
- allowedTCPPortRanges = [
- {
- from = 1714;
- to = 1764;
- }
- ];
- allowedUDPPortRanges = [
- {
- from = 1714;
- to = 1764;
- }
- ];
- };
-
systemd.network.netdevs."10-wg" = {
netdevConfig = {
Kind = "wireguard";
@@ -43,7 +28,7 @@
matchConfig.Name = "wg0";
address = ["${hosts.mercury.wg_ip}/24"];
DHCP = "no";
- dns = ["${hosts.ganymede.wg_ip}:5353"];
+ dns = [hosts.ganymede.wg_ip];
domains = ["~ganymede"];
networkConfig.IPv6AcceptRA = false;
extraConfig = ''
diff --git a/modules/desktop/nixos/fonts.nix b/modules/desktop/nixos/fonts.nix
index e740bf1..6a33629 100644
--- a/modules/desktop/nixos/fonts.nix
+++ b/modules/desktop/nixos/fonts.nix
@@ -2,6 +2,6 @@
fonts = {
enableDefaultPackages = false;
fontconfig.enable = true;
- packages = [pkgs.nerd-fonts.iosevka pkgs.ibm-plex pkgs.liberation_ttf pkgs.rubik]; # for terminal (blackbox or foot or ghostty)
+ packages = with pkgs; [nerd-fonts.iosevka ibm-plex liberation_ttf rubik];
};
}
diff --git a/modules/system/nixos/networking/default.nix b/modules/networking/nixos/default.nix
index f6baaac..f869670 100644
--- a/modules/system/nixos/networking/default.nix
+++ b/modules/networking/nixos/default.nix
@@ -1,7 +1,7 @@
{
imports = [
./resolved.nix
-
+ ./unbound.nix
./networkd.nix
./iwd.nix
./wpasupplicant.nix
@@ -14,14 +14,9 @@
};
# Disable default networking stuff
+ resolvconf.enable = false;
dhcpcd.enable = false;
useDHCP = false;
networkmanager.enable = false;
};
-
- boot.kernel.sysctl = {
- # disable all ipv6
- "net.ipv6.conf.all.disable_ipv6" = 1;
- "net.ipv6.conf.default.disable_ipv6" = 1;
- };
}
diff --git a/modules/system/nixos/networking/iwd.nix b/modules/networking/nixos/iwd.nix
index 0c5bdfa..0c5bdfa 100644
--- a/modules/system/nixos/networking/iwd.nix
+++ b/modules/networking/nixos/iwd.nix
diff --git a/modules/system/nixos/networking/networkd.nix b/modules/networking/nixos/networkd.nix
index 2c7f580..2c7f580 100644
--- a/modules/system/nixos/networking/networkd.nix
+++ b/modules/networking/nixos/networkd.nix
diff --git a/modules/networking/nixos/resolved.nix b/modules/networking/nixos/resolved.nix
new file mode 100644
index 0000000..01e75e2
--- /dev/null
+++ b/modules/networking/nixos/resolved.nix
@@ -0,0 +1,24 @@
+{
+ config,
+ lib,
+ ...
+}: let
+ cfg = config.collinux.system.network.dns;
+in
+ lib.mkIf (!cfg.areYouAServer) {
+ networking.nameservers = [
+ "9.9.9.9#dns.quad9.net"
+ "149.112.112.112#dns.quad9.net"
+ ];
+
+ services.resolved = {
+ enable = true;
+ settings.Resolve = {
+ DNSOverTLS = true;
+ DNSSEC = "allow-downgrade";
+
+ LLMNR = false;
+ MulticastDNS = false;
+ };
+ };
+ }
diff --git a/modules/networking/nixos/unbound.nix b/modules/networking/nixos/unbound.nix
new file mode 100644
index 0000000..b8b1e0b
--- /dev/null
+++ b/modules/networking/nixos/unbound.nix
@@ -0,0 +1,30 @@
+{
+ config,
+ lib,
+ ...
+}: let
+ cfg = config.collinux.system.network.dns;
+in
+ lib.mkIf cfg.areYouAServer {
+ networking = {
+ nameservers = ["127.0.0.1"];
+ resolvconf.enable = lib.mkForce true; # we disabled this earlier
+ };
+ services.resolved.enable = false;
+
+ services.unbound = {
+ enable = true;
+ settings.server = {
+ interface = ["0.0.0.0"];
+ port = 53;
+ access-control = [
+ "127.0.0.0/8 allow"
+ "10.100.0.0/24 allow"
+ "0.0.0.0/0 refuse"
+ ];
+
+ local-zone = [''"ganymede." redirect''];
+ local-data = [''"ganymede. IN A 10.100.0.1"''];
+ };
+ };
+ }
diff --git a/modules/system/nixos/networking/wpasupplicant.nix b/modules/networking/nixos/wpasupplicant.nix
index 8314095..8314095 100644
--- a/modules/system/nixos/networking/wpasupplicant.nix
+++ b/modules/networking/nixos/wpasupplicant.nix
diff --git a/modules/networking/options.nix b/modules/networking/options.nix
new file mode 100644
index 0000000..cc4864b
--- /dev/null
+++ b/modules/networking/options.nix
@@ -0,0 +1,58 @@
+{
+ lib,
+ my-lib,
+ ...
+}: let
+ inherit (my-lib.netTypes {inherit lib;}) ipAddr ipAddrCidr;
+ inherit (lib) mkOption mkEnableOption;
+in {
+ options.collinux.system.network = {
+ dns.areYouAServer = mkEnableOption "Set up unbound with the *.ganymede resolver and disable resolved stub";
+
+ static = lib.mkOption {
+ description = "Set a static IP address for this device on this network. Leave unset to use DHCP";
+ type = lib.types.nullOr (lib.types.submodule {
+ options = {
+ ip = mkOption {
+ description = "IP address";
+ type = ipAddrCidr;
+ };
+ gateway = mkOption {
+ description = "default gateway";
+ type = ipAddr;
+ };
+ };
+ });
+ default = null;
+ };
+
+ wireless = {
+ static = lib.mkOption {
+ description = "Set a preconfigured SSID and PSK for the wireless config";
+ type = lib.types.nullOr (lib.types.submodule {
+ options = {
+ ssid = mkOption {
+ description = "SSID for this network";
+ type = lib.types.str;
+ };
+ pskFile = mkOption {
+ description = "Absolute path to a file containing the pre-shared key for this network in the form `psk:<wifi psk>`";
+ type = lib.types.str;
+ example = "/run/secrets.d/wifi-psk";
+ };
+ };
+ });
+ default = null;
+ };
+ dynamic = mkEnableOption "Enable dynamically joining wireless networks with iwd";
+ };
+
+ wireguard = {
+ enable = mkEnableOption "Whether to enable Wireguard on this device";
+ # peers = lib.types.listOf (lib.types.submodule {
+ # options = {
+ # };
+ # });
+ };
+ };
+}
diff --git a/modules/services/nixos/btopweb.nix b/modules/services/nixos/btopweb.nix
index d8f4598..75498a9 100644
--- a/modules/services/nixos/btopweb.nix
+++ b/modules/services/nixos/btopweb.nix
@@ -33,7 +33,7 @@ in {
User = "btopweb";
Type = "simple";
- ExecStart = ''${pkgs.ttyd}/bin/ttyd -W -i ${cfg.listenAddr} -p ${toString cfg.port} -t renderType=canvas -t fontSize=16 ${pkgs.btop}/bin/btop -c ${btopSettings}'';
+ ExecStart = ''${lib.getExe pkgs.ttyd} -W -i 127.0.0.1 -p ${toString cfg.port} -t renderType=canvas -t fontSize=16 ${pkgs.btop}/bin/btop -c ${btopSettings}'';
};
};
@@ -41,5 +41,10 @@ in {
tls internal
reverse_proxy 127.0.0.1:${toString cfg.port}
'';
+
+ collinux.services.glance.homelabServices."btop" = {
+ url = "https://btop.ganymede";
+ icon = "si:htop";
+ };
};
}
diff --git a/modules/services/nixos/caddy.nix b/modules/services/nixos/caddy.nix
index b61a3c6..4b41c76 100644
--- a/modules/services/nixos/caddy.nix
+++ b/modules/services/nixos/caddy.nix
@@ -7,8 +7,10 @@
cfg = config.collinux.services.caddy;
in
lib.mkIf cfg.enable {
+ users.users."caddy".extraGroups = ["fileserver"];
networking.firewall.allowedTCPPorts = [80 443];
- environment.systemPackages = with pkgs; [nss.tools]; # required for caddy https stuff
+ environment.systemPackages = [pkgs.nss.tools]; # required for caddy https stuff
+
services.caddy = {
enable = true;
environmentFile = cfg.envFile;
diff --git a/modules/services/nixos/cgit/default.nix b/modules/services/nixos/cgit/default.nix
index 2a78607..4f0a7ba 100644
--- a/modules/services/nixos/cgit/default.nix
+++ b/modules/services/nixos/cgit/default.nix
@@ -96,5 +96,10 @@ in {
}
}
'';
+
+ collinux.services.glance.homelabServices."git" = {
+ url = "https://git.ganymede";
+ icon = "si:git";
+ };
};
}
diff --git a/modules/services/nixos/default.nix b/modules/services/nixos/default.nix
index 65315cf..fa74cf6 100644
--- a/modules/services/nixos/default.nix
+++ b/modules/services/nixos/default.nix
@@ -9,6 +9,7 @@
./ganyupload
./jta
./glance.nix
+ ./filebrowser.nix
./minecraft.nix
./ngircd.nix
diff --git a/modules/services/nixos/filebrowser.nix b/modules/services/nixos/filebrowser.nix
new file mode 100644
index 0000000..df0d536
--- /dev/null
+++ b/modules/services/nixos/filebrowser.nix
@@ -0,0 +1,52 @@
+{
+ lib,
+ pkgs,
+ config,
+ ...
+}: let
+ cfg = config.collinux.services.filebrowser;
+in
+ lib.mkIf cfg.enable {
+ users.groups."dufs" = {};
+ users.users."dufs" = {
+ isSystemUser = true;
+ group = "dufs";
+ extraGroups = ["fileserver"];
+ };
+
+ systemd.services."dufs" = {
+ description = "dufs file server";
+ restartIfChanged = true;
+ wants = ["network-online.target"];
+ after = ["network-online.target"];
+ wantedBy = ["multi-user.target"];
+
+ serviceConfig = {
+ # ExecStart = "${pkgs.dufs}/bin/dufs /media --port ${toString cfg.port}";
+ ExecStart = "${lib.getExe pkgs.dufs} /media --bind /run/dufs/dufs.sock";
+
+ RuntimeDirectory = "dufs"; # /run/dufs
+
+ User = "dufs";
+ Group = "dufs";
+
+ # Hardening
+ ProtectSystem = "strict";
+ ProtectHome = true;
+ PrivateTmp = true;
+ NoNewPrivileges = true;
+
+ Restart = "on-failure";
+ };
+ };
+
+ services.caddy.virtualHosts."files.ganymede".extraConfig = ''
+ tls internal
+ reverse_proxy unix//run/dufs/dufs.sock
+ '';
+
+ collinux.services.glance.homelabServices."files" = {
+ url = "https://files.ganymede";
+ icon = "si:folder";
+ };
+ }
diff --git a/modules/services/nixos/glance.nix b/modules/services/nixos/glance.nix
index 1396562..38e5e1d 100644
--- a/modules/services/nixos/glance.nix
+++ b/modules/services/nixos/glance.nix
@@ -8,6 +8,8 @@
pure = x: [x];
+ servicesLinks = builtins.attrValues cfg.homelabServices;
+
settings = {
server = {
inherit (cfg) port;
@@ -68,33 +70,7 @@
type = "monitor";
cache = "1m";
title = "Services";
- sites = [
- {
- title = "stats";
- url = "https://stats.ganymede";
- icon = "mdi:poll";
- }
- {
- title = "btop";
- url = "https://btop.ganymede";
- icon = "si:htop";
- }
- {
- title = "git";
- url = "https://git.ganymede";
- icon = "si:git";
- }
- {
- title = "bittorrent";
- url = "https://bittorrent.ganymede";
- icon = "si:qbittorrent";
- }
- {
- title = "website";
- url = "https://williamsfam.us.com";
- icon = "mdi:web";
- }
- ];
+ sites = servicesLinks;
}
];
};
@@ -117,6 +93,7 @@ in {
restartIfChanged = true;
wants = ["network-online.target"];
after = ["network-online.target"];
+ wantedBy = ["multi-user.target"];
serviceConfig = {
User = "glance";
@@ -138,7 +115,6 @@ in {
services.caddy.virtualHosts."home.ganymede".extraConfig = ''
tls internal
-
reverse_proxy 127.0.0.1:${toString cfg.port}
'';
};
diff --git a/modules/services/nixos/goaccess.nix b/modules/services/nixos/goaccess.nix
index b77f370..288428d 100644
--- a/modules/services/nixos/goaccess.nix
+++ b/modules/services/nixos/goaccess.nix
@@ -16,7 +16,7 @@
ws-url = "wss://stats.ganymede:443/ws";
port = cfg.port;
- addr = cfg.listenAddr;
+ addr = "127.0.0.1";
real-time-html = "true";
output = "/var/www/goaccess/index.html";
@@ -80,5 +80,10 @@ in {
reverse_proxy /ws 127.0.0.1:${toString cfg.port}
'';
+
+ collinux.services.glance.homelabServices."stats" = {
+ url = "https://stats.ganymede";
+ icon = "mdi:poll";
+ };
};
}
diff --git a/modules/services/nixos/minecraft.nix b/modules/services/nixos/minecraft.nix
index 45af606..0209549 100644
--- a/modules/services/nixos/minecraft.nix
+++ b/modules/services/nixos/minecraft.nix
@@ -6,7 +6,7 @@
cfg = config.collinux.services.minecraft;
in
lib.mkIf cfg.enable {
- networking.firewall.allowedUDPPorts = lib.optional cfg.public cfg.port;
+ networking.firewall.allowedUDPPorts = [cfg.port];
virtualisation.oci-containers.containers."Minecraft" = {
environment = {
@@ -23,11 +23,7 @@ in
};
image = "itzg/minecraft-bedrock-server";
ports = [
- "${
- if cfg.public
- then "0.0.0.0"
- else "127.0.0.1"
- }:${toString cfg.port}:19132/udp"
+ "0.0.0.0:${toString cfg.port}:19132/udp"
];
volumes = ["/var/lib/minecraft/:/data"];
diff --git a/modules/services/nixos/ngircd.nix b/modules/services/nixos/ngircd.nix
index ac93f06..d06a497 100644
--- a/modules/services/nixos/ngircd.nix
+++ b/modules/services/nixos/ngircd.nix
@@ -6,7 +6,7 @@
cfg = config.collinux.services.ngircd;
in
lib.mkIf cfg.enable {
- networking.firewall.allowedTCPPorts = lib.optional cfg.public cfg.port;
+ networking.firewall.allowedTCPPorts = [cfg.port];
services.ngircd = {
enable = true;
@@ -16,11 +16,7 @@ in
Info = Ganymede IRC Chat
AdminInfo1 = Collin
- Listen = ${
- if cfg.public
- then "0.0.0.0"
- else "127.0.0.1"
- }
+ Listen = 0.0.0.0
Ports = ${toString cfg.port}
[Channel]
diff --git a/modules/services/nixos/openssh.nix b/modules/services/nixos/openssh.nix
index 1d7834b..4826369 100644
--- a/modules/services/nixos/openssh.nix
+++ b/modules/services/nixos/openssh.nix
@@ -5,7 +5,6 @@
...
}: let
cfg = config.collinux.services.sshd;
-
pure = x: [x];
authorizedKeys =
@@ -30,11 +29,7 @@ in {
};
settings = {
- PermitRootLogin =
- if cfg.conf.rootLogin
- then "yes"
- else "no";
-
+ PermitRootLogin = "yes";
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
PubkeyAuthentication = true;
@@ -43,7 +38,7 @@ in {
users.users = {
${config.collinux.user.name}.openssh.authorizedKeys.keys = authorizedKeys;
- root.openssh.authorizedKeys.keys = lib.mkIf cfg.conf.rootLogin authorizedKeys;
+ root.openssh.authorizedKeys.keys = authorizedKeys;
};
systemd.services.openssh = {
diff --git a/modules/services/nixos/qbittorrent.nix b/modules/services/nixos/qbittorrent.nix
index cc147b1..fe2831a 100644
--- a/modules/services/nixos/qbittorrent.nix
+++ b/modules/services/nixos/qbittorrent.nix
@@ -11,8 +11,10 @@ in {
extraGroups = ["fileserver"]; # torrent files go to /media/library
};
- networking.firewall.allowedTCPPorts = [49252];
- networking.firewall.allowedUDPPorts = [49252];
+ networking.firewall = {
+ allowedTCPPorts = [49252];
+ allowedUDPPorts = [49252];
+ };
services.qbittorrent = {
enable = true;
@@ -25,5 +27,10 @@ in {
tls internal
reverse_proxy 127.0.0.1:${toString cfg.port}
'';
+
+ collinux.services.glance.homelabServices."bittorrent" = {
+ url = "https://bittorrent.ganymede";
+ icon = "si:qbittorrent";
+ };
};
}
diff --git a/modules/services/options.nix b/modules/services/options.nix
index 7dbaa2c..0e033be 100644
--- a/modules/services/options.nix
+++ b/modules/services/options.nix
@@ -1,117 +1,62 @@
-{
- lib,
- my-lib,
- ...
-}: let
+{lib, ...}: let
inherit (lib) mkOption mkEnableOption types;
- inherit (my-lib.netTypes {inherit lib;}) ipAddr;
- # A helper function to generate the submodule
- webserviceOptions = {
- service_name,
- reverse_proxy ? true,
- }:
- {
- enable = mkEnableOption "${service_name} selfhosted service";
- listenAddr = mkOption {
- description = "The IP address on which ${service_name} will listen for incoming connections";
- type = ipAddr;
- default = "127.0.0.1";
- };
- privateUrl = mkOption {
- description = "Internal .local name for the service. Don't put the protocol (https://) in the string";
- type = lib.types.nullOr lib.types.str;
- default = null;
- };
- publicUrl = mkOption {
- description = "Public website on which the service will be hosted. Don't put the protocol (https://) in the string";
- type = lib.types.nullOr lib.types.str;
- default = null;
- };
- }
- // (
- if reverse_proxy
- then {
- reverseProxy = mkOption {
- internal = true;
- type = lib.types.bool;
- default = true;
- };
- port = mkOption {
- description = "The port on which ${service_name} will listen for incomming connections";
- type = lib.types.port;
- };
- }
- else {
- manualCaddyConfig = mkOption {
- description = "Configuration to describe this service in caddy, since reverse_proxy = false.";
- type = lib.types.str;
- };
- }
- );
+ basicService = {
+ desc,
+ default_port ? null,
+ }: {
+ enable = mkEnableOption desc;
+ port = mkOption {
+ type = lib.types.port;
+ default = default_port;
+ };
+ };
in {
options.collinux.services = {
- sshd = {
- enable = mkEnableOption "OpenSSH server";
- port = mkOption {
- description = "Port to run on";
- type = lib.types.port;
- default = 22;
- };
- public = mkEnableOption "whether to make this service accessable over the internet";
-
- conf = {
- otp = mkEnableOption "Whether to require TOTP (Google Authenticator) 2fa codes to login";
- rootLogin = mkEnableOption "Whether to allow root login";
- };
+ sshd = basicService {
+ desc = "OpenSSH server";
+ default_port = 22;
};
- minecraft = {
- enable = mkEnableOption "Minecraft bedrock server";
- port = mkOption {
- description = "port to run on";
- type = lib.types.port;
- default = 19132;
- };
- public = mkEnableOption "whether to make this service accessable over the internet";
- };
- ngircd = {
- enable = mkEnableOption "ngircd IRC server";
- port = mkOption {
- type = lib.types.port;
- default = 6667;
- };
+ jta = basicService {desc = "personal project";};
+ ganyupload = basicService {desc = "anonymous file uploads";};
+ btopweb = basicService {desc = "btop accessable in a browser tab";};
- public = mkEnableOption "whether to make this service accessable over the internet";
- };
+ forgejo = basicService {desc = "Self-hosted git forge";};
+ qbittorrent = basicService {desc = "webui for qBittorrent";};
+ goaccess = basicService {desc = "webserver stats from caddy logs";};
+ filebrowser = basicService {desc = "dufs file browser";};
+ cgit.enable = mkEnableOption "cgit git webui";
- jta = webserviceOptions {
- service_name = "jta";
- };
- ganyupload = webserviceOptions {
- service_name = "ganyupload";
- };
- forgejo = webserviceOptions {
- service_name = "forgejo";
- };
- btopweb = webserviceOptions {
- service_name = "btopweb";
- };
- goaccess = webserviceOptions {
- service_name = "goaccess";
- };
- glance = {
- enable = mkEnableOption "Glance homepage";
- port = lib.mkOption {
- type = lib.types.port;
+ glance =
+ (basicService {desc = "Glance homepage";})
+ // {
+ homelabServices = lib.mkOption {
+ type = lib.types.attrsOf (lib.types.submodule ({config, ...}: {
+ options = {
+ title = lib.mkOption {
+ type = lib.types.str;
+ default = config._module.args.name;
+ };
+ url = lib.mkOption {
+ type = lib.types.str;
+ };
+ icon = lib.mkOption {
+ type = lib.types.nullOr lib.types.str;
+ default = null;
+ };
+ };
+ }));
+ };
};
+
+ minecraft = basicService {
+ desc = "Minecraft bedrock server";
+ default_port = 19132;
};
- cgit = webserviceOptions {
- service_name = "cgit";
- reverse_proxy = false;
- };
- qbittorrent = webserviceOptions {
- service_name = "qbittorrent";
+ ngircd = basicService {
+ desc = "ngircd IRC server";
+ default_port = 6667;
};
caddy = {
diff --git a/modules/system/nixos/boot.nix b/modules/system/nixos/boot.nix
index 50d66fe..aefc6da 100644
--- a/modules/system/nixos/boot.nix
+++ b/modules/system/nixos/boot.nix
@@ -74,10 +74,7 @@ in {
};
});
- system.etc.overlay = {
- enable = true;
- mutable = true; # necessary for installing secrets into etc
- };
+ system.etc.overlay.enable = true;
system.nixos-init.enable = true;
# store journald logs in memory
diff --git a/modules/system/nixos/default.nix b/modules/system/nixos/default.nix
index 035c5be..baacaa0 100644
--- a/modules/system/nixos/default.nix
+++ b/modules/system/nixos/default.nix
@@ -1,6 +1,5 @@
{
imports = [
- ./networking
./boot.nix
./audio.nix
./bluetooth.nix
diff --git a/modules/system/nixos/networking/resolved.nix b/modules/system/nixos/networking/resolved.nix
deleted file mode 100644
index e49e004..0000000
--- a/modules/system/nixos/networking/resolved.nix
+++ /dev/null
@@ -1,19 +0,0 @@
-{config, ...}: {
- networking.resolvconf.enable = false;
-
- networking.nameservers = [
- "9.9.9.9#dns.quad9.net"
- "149.112.112.112#dns.quad9.net"
- ];
-
- services.resolved = {
- enable = true;
- settings.Resolve = {
- DNSOverTLS = true;
- DNSSEC = "allow-downgrade";
-
- LLMNR = false;
- MulticastDNS = false;
- };
- };
-}
diff --git a/modules/system/options.nix b/modules/system/options.nix
index a6db575..cbc8cd1 100644
--- a/modules/system/options.nix
+++ b/modules/system/options.nix
@@ -5,7 +5,6 @@
...
}: let
inherit (lib) mkOption mkEnableOption;
- inherit (my-lib.netTypes {inherit lib;}) ipAddr ipAddrCidr;
inherit (my-lib.options {inherit lib config;}) mkThemeOption;
in {
options.collinux.system = {
@@ -26,46 +25,6 @@ in {
secureBoot.enable = mkEnableOption "lanzaboote";
};
- network = {
- static = lib.mkOption {
- description = "Set a static IP address for this device on this network. Leave unset to use DHCP";
- type = lib.types.nullOr (lib.types.submodule {
- options = {
- ip = mkOption {
- description = "IP address";
- type = ipAddrCidr;
- };
- gateway = mkOption {
- description = "default gateway";
- type = ipAddr;
- };
- };
- });
- default = null;
- };
-
- wireless = {
- static = lib.mkOption {
- description = "Set a preconfigured SSID and PSK for the wireless config";
- type = lib.types.nullOr (lib.types.submodule {
- options = {
- ssid = mkOption {
- description = "SSID for this network";
- type = lib.types.str;
- };
- pskFile = mkOption {
- description = "Absolute path to a file containing the pre-shared key for this network in the form `psk:<wifi psk>`";
- type = lib.types.str;
- example = "/run/secrets.d/wifi-psk";
- };
- };
- });
- default = null;
- };
- dynamic = lib.mkEnableOption "Enable dynamically joining wireless networks with iwd";
- };
- };
-
audio.enable = mkEnableOption "pipewire and wireplumber";
bluetooth.enable = mkEnableOption "bluetooth";
printing.enable = mkEnableOption "cups printing server";