diff options
Diffstat (limited to 'hosts')
| -rw-r--r-- | hosts/ganymede/caddy.nix | 2 | ||||
| -rw-r--r-- | hosts/ganymede/config.nix | 69 | ||||
| -rw-r--r-- | hosts/ganymede/nixos.nix | 5 | ||||
| -rw-r--r-- | hosts/ganymede/secrets/wireguard-pk.age | 11 | ||||
| -rw-r--r-- | hosts/ganymede/secrets/wireguard-privkey.age | 8 | ||||
| -rw-r--r-- | hosts/mercury/ai.nix | 8 | ||||
| -rw-r--r-- | hosts/mercury/config.nix | 23 | ||||
| -rw-r--r-- | hosts/mercury/disks.nix | 12 | ||||
| -rw-r--r-- | hosts/mercury/hjem.nix | 6 | ||||
| -rw-r--r-- | hosts/mercury/nixos.nix | 86 | ||||
| -rw-r--r-- | hosts/mercury/secrets/ts-key.age | bin | 0 -> 274 bytes | |||
| -rw-r--r-- | hosts/mercury/secrets/wireguard-privkey.age | 6 |
12 files changed, 91 insertions, 145 deletions
diff --git a/hosts/ganymede/caddy.nix b/hosts/ganymede/caddy.nix index d10910c..a03fcdc 100644 --- a/hosts/ganymede/caddy.nix +++ b/hosts/ganymede/caddy.nix @@ -9,7 +9,7 @@ "github.com/tailscale/caddy-tailscale@v0.0.0-20251204171825-f070d146dd61" "github.com/caddy-dns/porkbun@v0.3.1" ]; - hash = "sha256-n0HVlpCkJITyEPc+ml7zCcYw9gy3r1YAXertd6zc2o0="; + hash = "sha256-FrAI7Fpz3bXclmKcizBMv/VI1hTAWT6DQnj7S09MwNY="; }); globalConfig = '' diff --git a/hosts/ganymede/config.nix b/hosts/ganymede/config.nix index 94d67ec..47b7f49 100644 --- a/hosts/ganymede/config.nix +++ b/hosts/ganymede/config.nix @@ -9,19 +9,6 @@ }; "caddy-env".file = ./secrets/caddy-env.age; - - # "collin-copyparty-password" = { - # file = ./secrets/collin-copyparty-password.age; - # owner = "copyparty"; - # }; - "collin-forgejo-password" = { - file = ./secrets/collin-forgejo-password.age; - owner = "forgejo"; - }; - "wireguard-pk" = { - file = ./secrets/wireguard-pk.age; - owner = "systemd-network"; - }; }; terminal = { @@ -41,6 +28,7 @@ ip = "192.168.50.2/24"; gateway = "192.168.50.1"; }; + wireless.static = { ssid = "williams"; pskFile = config.collinux.secrets."williams-psk".path; @@ -50,58 +38,45 @@ services = { sshd = { enable = true; - port = 22; - listenAddr = "0.0.0.0"; - rootLogin = true; - }; + public = true; - goaccess = { - enable = true; - privateUrl = "stats.ganymede"; - }; - btopweb = { - enable = true; - privateUrl = "btop.ganymede"; - }; - - cgit = { - enable = true; - privateUrl = "git.ganymede"; + conf.rootLogin = true; }; minecraft = { enable = true; - listenAddr = "0.0.0.0"; + public = true; }; - ngircd.enable = true; - - qbittorrent = { + ngircd = { enable = true; - privateUrl = "bittorrent.ganymede"; + public = true; }; - # copyparty = { - # enable = true; - # listenAddr = "0.0.0.0"; - # publicUrl = "up.williamsfam.us.com"; - # privateUrl = "files.ganymede"; - - # users.collin = { - # isAdmin = true; - # passwordFile = config.collinux.secrets."collin-copyparty-password".path; - # hasPublicDir = true; - # }; - # }; jta = { enable = true; publicUrl = "jta.williamsfam.us.com"; }; - ganyupload = { enable = true; publicUrl = "upld.williamsfam.us.com"; }; + goaccess = { + enable = true; + privateUrl = "stats.ganymede"; + }; + btopweb = { + enable = true; + privateUrl = "btop.ganymede"; + }; + qbittorrent = { + enable = true; + privateUrl = "bittorrent.ganymede"; + }; + cgit = { + enable = true; + privateUrl = "git.ganymede"; + }; caddy = { enable = true; diff --git a/hosts/ganymede/nixos.nix b/hosts/ganymede/nixos.nix index 415509a..77e3ad5 100644 --- a/hosts/ganymede/nixos.nix +++ b/hosts/ganymede/nixos.nix @@ -16,6 +16,11 @@ facter.reportPath = ./facter.json; + environment.systemPackages = [ + pkgs.python313 + pkgs.net-tools + ]; + # backup usb teather configuration systemd.network.networks."80-usb-teather" = { name = "enp0s20f0u2"; diff --git a/hosts/ganymede/secrets/wireguard-pk.age b/hosts/ganymede/secrets/wireguard-pk.age deleted file mode 100644 index c8e365a..0000000 --- a/hosts/ganymede/secrets/wireguard-pk.age +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN AGE ENCRYPTED FILE----- -YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNzaC1lZDI1NTE5IEpnNHlXUSBxZlFt -bWR5NFJ1N0FBMkc2eThudnI1TnQ2WFNzK2NsVzdtaVgzQXRYNFhzCkJXTGUzSU5E -U05jYnEvQXVwZEhIU1FMamt3bUM4UnB3bmNEZWQzZDlBSXcKLT4gc09lRVkkfTQt -Z3JlYXNlIHMgSHYsVTZxOzgKWVJHbG1Ua3NONE9QYjVCNEQzOXQrNlZXRTBKQ3JW -elpKeGwvYVgrOVVMRStrUGl0ay9HYmNOcW8xZFJER2tXWApPcUZxY2I5aDBoMVBO -bmNxWE9YakZqL2h2dlFVYVdra0JrZjMKLS0tIGJWQlRmaVREL242aVdudFVOZTd4 -V1BnTnM3aTdGY1lUcm81VUVkd1QzcFUKMMrCSdf0J/xuvhvpktJO/GbpBp8ZnXue -S0TTS/s3zCx8wCT70j/C6alX1CeMX+RpJwiba5BpvTuphGrgrMjMtA0oYDCRZzeQ -1EtdX+A= ------END AGE ENCRYPTED FILE----- diff --git a/hosts/ganymede/secrets/wireguard-privkey.age b/hosts/ganymede/secrets/wireguard-privkey.age new file mode 100644 index 0000000..ee9130d --- /dev/null +++ b/hosts/ganymede/secrets/wireguard-privkey.age @@ -0,0 +1,8 @@ +age-encryption.org/v1 +-> ssh-ed25519 azBilg tvscfH96l4w2AkLjaczmtAJ3CKeU1mEPJWT82tR2HiY +F83pJqPj+qlFw4nb+ANCMJ7lOufSMluDIeWbaYvJkEU +-> ssh-ed25519 Jg4yWQ SXz2kA4FODscXLqsNsCjuqKqBUXSkEx5SIpSdjGKpQU +mVg50RgaBauKlTCyHUYDTPZYnDJkppOthhMC+MAsiiE +--- dlTzxZODPVxlkdRP3HRJSK6BU3yEHrs1fo/sudC6EKo +dEV!Axr?z(YKمSukst]<o( +>Mjzψ\D\Bs./2=
\ No newline at end of file diff --git a/hosts/mercury/ai.nix b/hosts/mercury/ai.nix deleted file mode 100644 index 4615838..0000000 --- a/hosts/mercury/ai.nix +++ /dev/null @@ -1,8 +0,0 @@ -{pkgs, ...}: { - services.ollama.enable = true; - # environment.systemPackages = [pkgs.mcphost]; - - hjem.users."collin".files.".config/fish/conf.d/ollama.fish".text = '' - set -gx OLLAMA_NOHISTORY 1 - ''; -} diff --git a/hosts/mercury/config.nix b/hosts/mercury/config.nix index 852c393..b9882f6 100644 --- a/hosts/mercury/config.nix +++ b/hosts/mercury/config.nix @@ -1,13 +1,16 @@ -{ +{config, ...}: { collinux = { - theme = "catppuccin"; + theme = "adwaita"; secrets = {}; user.useRun0 = true; desktop = { - wallpaper = ./wallpapers/abstract-swirls.jpg; + wallpaper = + if (config.collinux.theme == "catppuccin") + then ./wallpapers/abstract-swirls.jpg + else ./wallpapers/hintergrund2.png; gtk.enable = true; qt.enable = true; @@ -23,14 +26,13 @@ components = { fuzzel.enable = true; dunst.enable = true; - # tofi.enable = true; }; }; programs = { firefox = { enable = true; - extensions.zotero.enable = false; + extensions.foxyproxy.enable = true; }; foot.enable = true; @@ -44,9 +46,7 @@ secureBoot.enable = true; }; - network = { - wireless.dynamic = true; - }; + network.wireless.dynamic = true; audio.enable = true; bluetooth.enable = true; @@ -54,8 +54,10 @@ }; terminal = { - shells.fish.enable = true; - shells.bash.enable = true; # for nix-shells + shells = { + fish.enable = true; + bash.enable = true; # for nix-shells + }; programs = { starship.enable = true; @@ -63,6 +65,7 @@ bat.enable = true; eza.enable = true; broot.enable = true; + tmux.enable = true; helix = { enable = true; hardMode = true; diff --git a/hosts/mercury/disks.nix b/hosts/mercury/disks.nix index 60187b1..7ef2d0d 100644 --- a/hosts/mercury/disks.nix +++ b/hosts/mercury/disks.nix @@ -3,17 +3,25 @@ device = "/dev/disk/by-uuid/3d80a86b-3268-4209-a833-b531b8bc0ebc"; fsType = "ext4"; }; - fileSystems."/boot" = { device = "/dev/disk/by-uuid/45A4-2E5B"; fsType = "vfat"; options = ["fmask=0022" "dmask=0022"]; }; - + swapDevices = [ + { + device = "/dev/disk/by-label/swap"; + priority = 10; + } + ]; zramSwap = { enable = true; priority = 100; algorithm = "lz4"; memoryPercent = 50; }; + + boot.kernelParams = [ + "resume=LABEL=swap" + ]; } diff --git a/hosts/mercury/hjem.nix b/hosts/mercury/hjem.nix index 6ecbb8e..3625e7b 100644 --- a/hosts/mercury/hjem.nix +++ b/hosts/mercury/hjem.nix @@ -1,9 +1,12 @@ {pkgs, ...}: { packages = with pkgs; [ - # obsidian anki libreoffice-qt musescore + (pkgs.callPackage ../../pkgs/obsidian.nix {}) + + lmms # (?) + eq10q prismlauncher mpv @@ -12,7 +15,6 @@ opencode (pkgs.callPackage ../../pkgs/yo {}) - (pkgs.callPackage ../../pkgs/yokey {}) captive-browser # https://words.filippo.io/captive-browser (pkgs.makeDesktopItem { diff --git a/hosts/mercury/nixos.nix b/hosts/mercury/nixos.nix index a47375a..9a89fca 100644 --- a/hosts/mercury/nixos.nix +++ b/hosts/mercury/nixos.nix @@ -11,20 +11,17 @@ inputs.nixos-facter-modules.nixosModules.facter inputs.lanzaboote.nixosModules.lanzaboote ]; - facter.reportPath = ./facter.json; + services.dbus.implementation = "broker"; environment.defaultPackages = lib.mkForce []; # im not a noob - services.syncthing = { - enable = true; - user = "collin"; - dataDir = "/home/collin/.local/syncthing"; - }; - programs.kdeconnect.enable = true; - - security.soteria.enable = true; + programs.ssh.extraConfig = '' + Host ganymede + HostName williamsfam.us.com + Port 22 + ''; virtualisation.podman = { enable = true; @@ -45,66 +42,34 @@ } ]; }; - - services.jupyter = { + virtualisation.waydroid = { + package = pkgs.waydroid-nftables; enable = true; - ip = "127.0.0.1"; - port = 8888; - - user = "collin"; # to access my files - - package = pkgs.python313Packages.jupyter; - command = "jupyter lab --ServerApp.token='' --ServerApp.password=''"; - password = ""; - - notebookDir = "~/brain/notes/schoolyear2025/physics"; - - kernels = { - python3 = let - python = pkgs.python313.withPackages (ps: - with ps; [ - numpy - pandas - matplotlib - sympy - ipywidgets - ipydatagrid - ipykernel - ]); - in { - language = "python"; - displayName = "Python (Physics)"; - argv = ["${python}/bin/python" "-m" "ipykernel_launcher" "-f" "{connection_file}"]; - }; - }; }; + programs.kdeconnect.enable = true; + + services.autossh.sessions = [ + { + name = "ganymede"; + user = "collin"; + monitoringPort = 20000; + extraArguments = "-N -D 9090 collin@ganymede"; + } + ]; + boot.supportedFilesystems."fuse.sshfs" = true; fileSystems."/home/collin/ganymede" = { device = "collin@ganymede:/media"; fsType = "fuse.sshfs"; options = [ "identityfile=/home/collin/.ssh/id_ed25519" "idmap=user" - "x-systemd.automount" #< mount the filesystem automatically on first access - "allow_other" #< don't restrict access to only the user which `mount`s it (because that's probably systemd who mounts it, not you) - "user" #< allow manual `mount`ing, as ordinary user. + "x-systemd.automount" # mount the filesystem automatically on first access + "allow_other" # don't restrict access to only the user which `mount`s it (because that's probably systemd who mounts it, not you) + "user" # allow manual `mount`ing, as ordinary user. ]; }; - boot.supportedFilesystems."fuse.sshfs" = true; - services.autossh.sessions = [ - { - name = "ganymede"; - user = "collin"; - monitoringPort = 20000; - extraArguments = "-N -D 9090 collin@williamsfam.us.com"; - } - ]; - programs.ssh.extraConfig = '' - Host ganymede - HostName williamsfam.us.com - Port 22 - ''; security.pki.certificates = [ '' -----BEGIN CERTIFICATE----- @@ -120,11 +85,4 @@ -----END CERTIFICATE----- '' ]; - - programs.firefox.policies.ExtensionSettings = { - "foxyproxy@eric.h.jung" = { - installation_mode = "force_installed"; - install_url = "https://addons.mozilla.org/firefox/downloads/latest/foxyproxy-standard/latest.xpi"; - }; - }; } diff --git a/hosts/mercury/secrets/ts-key.age b/hosts/mercury/secrets/ts-key.age Binary files differnew file mode 100644 index 0000000..57454fe --- /dev/null +++ b/hosts/mercury/secrets/ts-key.age diff --git a/hosts/mercury/secrets/wireguard-privkey.age b/hosts/mercury/secrets/wireguard-privkey.age new file mode 100644 index 0000000..614778d --- /dev/null +++ b/hosts/mercury/secrets/wireguard-privkey.age @@ -0,0 +1,6 @@ +age-encryption.org/v1 +-> ssh-ed25519 azBilg GS1BNOAVj8aZPePeR4teX45zKAyCMVOBvE+GNUGCX3I +rEzBojvbakMsQCKXROwbynFTxmlcPROD7DBsl/wzfO4 +--- ESZvgbmZ3UrE6CymN/Haej2rE+FrS13SCqZZX+gcsPw + 6T݈%]K2 + J-{;@ؠ`+E2GLF*-a$`gAmp
\ No newline at end of file |
