aboutsummaryrefslogtreecommitdiff
path: root/modules/services/nixos
diff options
context:
space:
mode:
authorCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-07-15 12:03:58 -0500
committerCollin Williams <96917990+bluedragon1221@users.noreply.github.com>2026-07-15 12:03:58 -0500
commitd2aecd69c17fa64305c07333686576152432993d (patch)
tree2f52c7808a6cbd57ef60284947d3728a38cfab34 /modules/services/nixos
parentf5ef0cf848e65d4fea2be8dee7bc1c72ad67046f (diff)
changes.
Diffstat (limited to 'modules/services/nixos')
-rw-r--r--modules/services/nixos/default.nix1
-rw-r--r--modules/services/nixos/glance.nix145
-rw-r--r--modules/services/nixos/openssh.nix96
-rw-r--r--modules/services/nixos/qbittorrent.nix2
4 files changed, 175 insertions, 69 deletions
diff --git a/modules/services/nixos/default.nix b/modules/services/nixos/default.nix
index 68ed3ee..65315cf 100644
--- a/modules/services/nixos/default.nix
+++ b/modules/services/nixos/default.nix
@@ -8,6 +8,7 @@
./cgit
./ganyupload
./jta
+ ./glance.nix
./minecraft.nix
./ngircd.nix
diff --git a/modules/services/nixos/glance.nix b/modules/services/nixos/glance.nix
new file mode 100644
index 0000000..1396562
--- /dev/null
+++ b/modules/services/nixos/glance.nix
@@ -0,0 +1,145 @@
+{
+ pkgs,
+ config,
+ lib,
+ ...
+}: let
+ cfg = config.collinux.services.glance;
+
+ pure = x: [x];
+
+ settings = {
+ server = {
+ inherit (cfg) port;
+ proxied = true;
+ host = "127.0.0.1";
+ assets-path = "/var/lib/glance";
+ };
+
+ branding.hide-footer = true;
+ pages = pure {
+ name = "Dashboard";
+ width = "slim";
+ hide-desktop-navigation = true;
+ center-vertically = true;
+ columns = pure {
+ size = "full";
+ widgets = [
+ {
+ type = "search";
+ autofocus = true;
+ search-engine = "duckduckgo";
+ bangs = [
+ {
+ title = "GitHub";
+ shortcut = "gh";
+ url = "https://github.com/search?q={QUERY}&type=repositories";
+ }
+ {
+ title = "I'm Feeling Lucky";
+ shortcut = "!";
+ url = "https://www.google.com/search?q={QUERY}&btnI=&sourceid=navclient&gfns=1";
+ }
+ {
+ title = "YouTube Music";
+ shortcut = "ytm";
+ url = "https://music.youtube.com/search?q={QUERY}";
+ }
+ {
+ title = "Google AI Mode";
+ shortcut = "ai";
+ url = "https://www.google.com/search?udm=50&q={QUERY}";
+ }
+ ];
+ }
+ {
+ type = "server-stats";
+ servers = pure {
+ type = "local";
+ name = "Ganymede";
+ hide-mountpoints-by-default = true;
+ mountpoints = {
+ "/".hide = false;
+ "/media".hide = false;
+ };
+ };
+ }
+ {
+ type = "monitor";
+ cache = "1m";
+ title = "Services";
+ sites = [
+ {
+ title = "stats";
+ url = "https://stats.ganymede";
+ icon = "mdi:poll";
+ }
+ {
+ title = "btop";
+ url = "https://btop.ganymede";
+ icon = "si:htop";
+ }
+ {
+ title = "git";
+ url = "https://git.ganymede";
+ icon = "si:git";
+ }
+ {
+ title = "bittorrent";
+ url = "https://bittorrent.ganymede";
+ icon = "si:qbittorrent";
+ }
+ {
+ title = "website";
+ url = "https://williamsfam.us.com";
+ icon = "mdi:web";
+ }
+ ];
+ }
+ ];
+ };
+ };
+ };
+
+ settingsFile = (pkgs.formats.yaml {}).generate "config.yml" settings;
+in {
+ config = lib.mkIf cfg.enable {
+ users.groups."glance" = {};
+ users.users."glance" = {
+ isSystemUser = true;
+ group = "glance";
+
+ home = "/var/lib/glance";
+ createHome = true;
+ };
+
+ systemd.services."glance" = {
+ restartIfChanged = true;
+ wants = ["network-online.target"];
+ after = ["network-online.target"];
+
+ serviceConfig = {
+ User = "glance";
+ Type = "simple";
+
+ ReadWritePaths = "/var/lib/glance";
+ WorkingDirectory = "/var/lib/glance";
+ ExecStart = "${pkgs.glance}/bin/glance -config ${settingsFile}";
+
+ NoNewPrivileges = true;
+ PrivateTmp = true;
+ ProtectSystem = "strict";
+ ProtectHome = true;
+ ProtectKernelTunables = true;
+ ProtectKernelModules = true;
+ ProtectControlGroups = true;
+ };
+ };
+
+ services.caddy.virtualHosts."home.ganymede".extraConfig = ''
+ tls internal
+
+ reverse_proxy 127.0.0.1:${toString cfg.port}
+ '';
+ };
+}
diff --git a/modules/services/nixos/openssh.nix b/modules/services/nixos/openssh.nix
index 98f8b87..1d7834b 100644
--- a/modules/services/nixos/openssh.nix
+++ b/modules/services/nixos/openssh.nix
@@ -1,94 +1,54 @@
{
config,
lib,
- pkgs,
hosts,
...
}: let
cfg = config.collinux.services.sshd;
+
+ pure = x: [x];
+
+ authorizedKeys =
+ hosts
+ |> builtins.mapAttrs (_: data: data.user_pubkey or null)
+ |> builtins.attrValues
+ |> builtins.filter (x: x != null);
in {
config = lib.mkIf cfg.enable {
- networking.firewall.allowedTCPPorts = lib.optional cfg.public cfg.port;
-
services.openssh = {
enable = true;
allowSFTP = true;
- hostKeys = [
- {
- path = "/etc/ssh/ssh_host_ed25519_key";
- type = "ed25519";
- }
- ];
+ hostKeys = pure {
+ path = "/etc/ssh/ssh_host_ed25519_key";
+ type = "ed25519";
+ };
- listenAddresses = [
- {
- addr =
- if cfg.public
- then "0.0.0.0"
- else "127.0.0.1";
- port = cfg.port;
- }
- ];
+ listenAddresses = pure {
+ addr = "0.0.0.0";
+ port = cfg.port;
+ };
- # Lock down everything by default
settings = {
- PermitRootLogin = "no";
+ PermitRootLogin =
+ if cfg.conf.rootLogin
+ then "yes"
+ else "no";
+
PasswordAuthentication = false;
- PubkeyAuthentication = false;
KbdInteractiveAuthentication = false;
- AllowAgentForwarding = false;
+ PubkeyAuthentication = true;
};
-
- extraConfig = lib.concatStringsSep "\n" [
- "Match LocalPort ${toString cfg.port}"
- (
- if cfg.conf.otp
- then ''
- ChallengeResponseAuthentication yes
- PubkeyAuthentication yes
- KbdInteractiveAuthentication yes
- AuthenticationMethods publickey,keyboard-interactive:pam
- ''
- else ''
- PubkeyAuthentication yes
- AuthenticationMethods publickey
- ''
- )
- (lib.optionalString cfg.conf.rootLogin "PermitRootLogin yes")
- ];
- };
-
- security.pam.services = lib.optionalAttrs cfg.conf.otp {
- login.googleAuthenticator.enable = true;
-
- sshd.text = ''
- account required pam_unix.so
-
- auth required ${pkgs.google-authenticator}/lib/security/pam_google_authenticator.so nullok no_increment_hotp
- auth sufficient pam_permit.so
-
- session required pam_env.so conffile=/etc/pam/environment readenv=0
- session required pam_unix.so
- session required pam_loginuid.so
- session optional ${pkgs.systemd}/lib/security/pam_systemd.so
- '';
};
- users.users = let
- k.openssh.authorizedKeys.keys =
- hosts
- |> builtins.mapAttrs (_: data: data.user_pubkey or null)
- |> builtins.attrValues
- |> builtins.filter (x: x != null);
- in {
- ${config.collinux.user.name} = k;
- "root" = lib.mkIf cfg.conf.rootLogin k;
+ users.users = {
+ ${config.collinux.user.name}.openssh.authorizedKeys.keys = authorizedKeys;
+ root.openssh.authorizedKeys.keys = lib.mkIf cfg.conf.rootLogin authorizedKeys;
};
- systemd.services."openssh" = {
- after = lib.mkAfter ["network-online.target"];
- wants = lib.mkAfter ["network-online.target"];
+ systemd.services.openssh = {
+ after = ["network-online.target"];
+ wants = ["network-online.target"];
};
};
}
diff --git a/modules/services/nixos/qbittorrent.nix b/modules/services/nixos/qbittorrent.nix
index bb0fab7..cc147b1 100644
--- a/modules/services/nixos/qbittorrent.nix
+++ b/modules/services/nixos/qbittorrent.nix
@@ -23,7 +23,7 @@ in {
services.caddy.virtualHosts."bittorrent.ganymede".extraConfig = ''
tls internal
- reverse_proxy ${toString cfg.port}
+ reverse_proxy 127.0.0.1:${toString cfg.port}
'';
};
}