From 7b9a5eb561948521ac4669074cc746a0f848ed23 Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Thu, 8 Jan 2026 22:33:36 -0600 Subject: headscale --- modules/services/nixos/selfhost/default.nix | 1 + modules/services/nixos/selfhost/headscale.nix | 55 +++++++++++++++++++++++++++ modules/services/options.nix | 32 +++++++++++----- 3 files changed, 78 insertions(+), 10 deletions(-) create mode 100644 modules/services/nixos/selfhost/headscale.nix (limited to 'modules/services') diff --git a/modules/services/nixos/selfhost/default.nix b/modules/services/nixos/selfhost/default.nix index 876586d..de1078b 100644 --- a/modules/services/nixos/selfhost/default.nix +++ b/modules/services/nixos/selfhost/default.nix @@ -2,6 +2,7 @@ imports = [ ./adguard.nix ./forgejo.nix + ./headscale.nix ./caddy.nix ]; } diff --git a/modules/services/nixos/selfhost/headscale.nix b/modules/services/nixos/selfhost/headscale.nix new file mode 100644 index 0000000..9319691 --- /dev/null +++ b/modules/services/nixos/selfhost/headscale.nix @@ -0,0 +1,55 @@ +{ + config, + pkgs, + lib, + ... +}: let + cfg = config.collinux.services.selfhost.headscale; + + acl_file = (pkgs.formats.json {}).generate "acl.json" { + ssh = { + src = ["*"]; + dst = ["*"]; + users = ["autogroup:nonroot" "root"]; + action = "accept"; + }; + }; +in + lib.mkIf cfg.enable { + services.headscale = { + enable = true; + address = cfg.bind_host; + port = cfg.port; + settings = { + server_url = cfg.root_url; + + database.type = "sqlite"; + + dns = { + magic_dns = true; + base_domain = "collinux.tailnet"; + override_local_dns = true; + nameservers.global = ["9.9.9.9" "149.112.112.112" "2620:fe::fe" "2620:fe::9"]; + }; + + policy.path = "${acl_file}"; + + prefixes = { + "v4" = "100.100.0.0/16"; + allocation = "random"; + }; + + # leave tls for caddy to worry about + tls_cert_path = null; + tls_key_path = null; + + logtail.enabled = false; + }; + }; + + services.caddy.virtualHosts.${cfg.root_url}.extraConfig = lib.mkIf config.collinux.services.selfhost.caddy.enable '' + reverse_proxy localhost:8080 + ''; + + environment.systemPackages = [pkgs.headscale]; + } diff --git a/modules/services/options.nix b/modules/services/options.nix index f42dd12..2084c45 100644 --- a/modules/services/options.nix +++ b/modules/services/options.nix @@ -31,8 +31,20 @@ in { default = null; }; }; - tailscale.enable = mkEnableOption "tailscale"; - sshd.enable = mkEnableOption "OpenSSH server"; + tailscale = { + enable = mkEnableOption "tailscale"; + tailnet = mkOption { + type = lib.types.str; + default = "tail7cca06.ts.net"; + }; + }; + sshd = { + enable = mkEnableOption "OpenSSH server"; + bind_host = mkOption { + type = ip_addr; + default = "0.0.0.0"; + }; + }; }; audio = { enable = mkEnableOption "pipewire + wireplumber"; @@ -54,21 +66,17 @@ in { enable = mkEnableOption ""; bind_host = mkOption { type = ip_addr; - default = - if config.collinux.services.networking.tailscale.enable - then "100.69.160.89" - else "0.0.0.0"; + default = "0.0.0.0"; }; port = mkOption { type = lib.types.port; default = default_port; }; - root_url = mkOption { type = lib.types.str; - default = - if config.collinux.services.networking.tailscale.enable - then "https://${service_name}.tail7cca06.ts.net" + default = with config.collinux.services.networking.tailscale; + if enable + then "https://${service_name}.${tailnet}" else null; }; }; @@ -81,6 +89,10 @@ in { service_name = "forgejo"; default_port = 8010; }; + headscale = selfhostOptions { + service_name = "headscale"; + default_port = 8080; + }; caddy = { enable = mkEnableOption "caddy https server"; envFile = mkOption { -- cgit v1.3.1 From 547d6dc4731b04a240048b0b95c0ea12e0d1f6bd Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Fri, 9 Jan 2026 20:36:36 -0600 Subject: lots of changes, including revamp of network services boot chain on mercury --- flake.lock | 57 +++++++++++++++++++++++++- flake.nix | 5 +++ hosts/ganymede/caddy-env.age | 11 ++--- hosts/ganymede/caddy.nix | 6 --- hosts/ganymede/config.nix | 18 +++++--- hosts/ganymede/minecraft.nix | 10 ++--- hosts/ganymede/nixos.nix | 28 ++++++++++++- hosts/ganymede/tsnsrv-authkey.age | 7 ++++ hosts/mercury/hjem.nix | 1 + modules/services/nixos/bluetooth.nix | 12 ++++++ modules/services/nixos/networking/default.nix | 3 +- modules/services/nixos/networking/networkd.nix | 6 +++ modules/services/nixos/selfhost/adguard.nix | 3 +- modules/services/nixos/selfhost/forgejo.nix | 7 +++- modules/services/nixos/selfhost/headscale.nix | 25 ++++++++--- modules/services/nixos/ssh.nix | 14 +++++++ modules/services/nixos/tailscale.nix | 6 +++ modules/services/options.nix | 4 +- secrets.nix | 1 + 19 files changed, 188 insertions(+), 36 deletions(-) create mode 100644 hosts/ganymede/tsnsrv-authkey.age (limited to 'modules/services') diff --git a/flake.lock b/flake.lock index 63739b2..b4d9b39 100644 --- a/flake.lock +++ b/flake.lock @@ -150,6 +150,24 @@ "type": "github" } }, + "flake-parts": { + "inputs": { + "nixpkgs-lib": "nixpkgs-lib" + }, + "locked": { + "lastModified": 1765835352, + "narHash": "sha256-XswHlK/Qtjasvhd1nOa1e8MgZ8GS//jBoTqWtrS1Giw=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "a34fae9c08a15ad73f295041fec82323541400a9", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, "gitignore": { "inputs": { "nixpkgs": [ @@ -283,6 +301,21 @@ "type": "github" } }, + "nixpkgs-lib": { + "locked": { + "lastModified": 1765674936, + "narHash": "sha256-k00uTP4JNfmejrCLJOwdObYC9jHRrr/5M/a/8L2EIdo=", + "owner": "nix-community", + "repo": "nixpkgs.lib", + "rev": "2075416fcb47225d9b68ac469a5c4801a9c4dd85", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs.lib", + "type": "github" + } + }, "pre-commit": { "inputs": { "flake-compat": "flake-compat_2", @@ -316,7 +349,8 @@ "lanzaboote": "lanzaboote", "nixos-facter-modules": "nixos-facter-modules", "nixpkgs": "nixpkgs", - "tmux-tsunami": "tmux-tsunami" + "tmux-tsunami": "tmux-tsunami", + "tsnsrv": "tsnsrv" } }, "rust-overlay": { @@ -451,6 +485,27 @@ "type": "github" } }, + "tsnsrv": { + "inputs": { + "flake-parts": "flake-parts", + "nixpkgs": [ + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1767001347, + "narHash": "sha256-uRm4oWMFUBSmXgofOngMWIyA/yUmLlon6f3XoFTWvBA=", + "owner": "boinkor-net", + "repo": "tsnsrv", + "rev": "8f3fbf69e1517612c0fde9be27522e12c2ddc238", + "type": "github" + }, + "original": { + "owner": "boinkor-net", + "repo": "tsnsrv", + "type": "github" + } + }, "utils": { "inputs": { "systems": "systems_2" diff --git a/flake.nix b/flake.nix index 6958a06..6f71eb4 100644 --- a/flake.nix +++ b/flake.nix @@ -37,6 +37,11 @@ url = "github:MrOtherGuy/firefox-csshacks"; flake = false; }; + + tsnsrv = { + url = "github:boinkor-net/tsnsrv"; + inputs.nixpkgs.follows = "nixpkgs"; + }; }; outputs = inputs: let diff --git a/hosts/ganymede/caddy-env.age b/hosts/ganymede/caddy-env.age index 79d7b91..ecfc05a 100644 --- a/hosts/ganymede/caddy-env.age +++ b/hosts/ganymede/caddy-env.age @@ -1,6 +1,7 @@ age-encryption.org/v1 --> ssh-ed25519 Jg4yWQ cVxgS8Sy6bB9lQVeDBQVhmCaD437YxPAZduSzFA6WHE -KV9ZrAEH3z8cT0IeaIfkqMYhU/4LS2St0ySK030Ie1c ---- pUeKTMwZf3FARqVLl9TARgItjcr1O82hUKaZ9YtjFRM -a_v1BRgʫ*+r֘0}ܨd`˟ϞJ<3hi1|Gjl3!7r 3Xp=d`71ݻѲhFW5/2̞?[HZ - Sd:FCGq%-#W~Wz_XF)ZS~MhCF!C)N*ٟ -R \ No newline at end of file +-> ssh-ed25519 Jg4yWQ t4jtOOcuC4v735Yi4FzdDnvjQFNYVgzMluuH7H3oxx4 +qLKbZ3wA3kk7UXqwUJN2HH+6Wr3qgzINNwLx+dbgsIg +--- im4dvpbhdvB7fwa8QJ7clFZ+5aVIaXld/gPlhUalc14 +>u4BECQD:3kkKļc}}}mK)HM3v}ܣI9Ikxr1s?"8Д>J{uafϚ}.3Oa9m2- @C0b X|]:9`WX1ba|W2=l]Cw U&~"0 ! +6 +MFίp D˅+q `-R6/L 4 \ No newline at end of file diff --git a/hosts/ganymede/caddy.nix b/hosts/ganymede/caddy.nix index e6f18ab..6ad32cf 100644 --- a/hosts/ganymede/caddy.nix +++ b/hosts/ganymede/caddy.nix @@ -19,12 +19,6 @@ } ''; - virtualHosts."https://web.tail7cca06.ts.net".extraConfig = '' - bind tailscale/web - root * /var/www - file_server - ''; - virtualHosts."https://williamsfam.us.com".extraConfig = '' root * /var/www file_server diff --git a/hosts/ganymede/config.nix b/hosts/ganymede/config.nix index c2b312f..3adf620 100644 --- a/hosts/ganymede/config.nix +++ b/hosts/ganymede/config.nix @@ -1,5 +1,5 @@ {config, ...}: let - tailscaleIP = "100.69.180.89"; + tailscaleIP = "100.100.218.182"; in { collinux = { user.name = "collin"; @@ -7,6 +7,7 @@ in { secrets = { "williams-psk".file = ./williams-psk.age; "caddy-env".file = ./caddy-env.age; + "tsnsrv-authkey".file = ./tsnsrv-authkey.age; }; terminal = { @@ -33,7 +34,10 @@ in { gateway = "192.168.50.1"; }; }; - tailscale.enable = true; + tailscale = { + enable = true; + tailnet = "collinux.tailnet"; + }; sshd = { enable = true; bind_host = tailscaleIP; @@ -41,10 +45,12 @@ in { }; selfhost = { - adguard = { - enable = true; - bind_host = tailscaleIP; - }; + magic_caddy.enable = false; + + # adguard = { + # enable = true; + # bind_host = tailscaleIP; + # }; forgejo = { enable = true; bind_host = tailscaleIP; diff --git a/hosts/ganymede/minecraft.nix b/hosts/ganymede/minecraft.nix index cff5de2..c244868 100644 --- a/hosts/ganymede/minecraft.nix +++ b/hosts/ganymede/minecraft.nix @@ -1,6 +1,6 @@ {config, ...}: { networking.firewall.allowedUDPPorts = [19132]; - virtualisation.oci-containers.backend = "podman"; + virtualisation.oci-containers.backend = "docker"; virtualisation.oci-containers.containers."Minecraft" = { environment = { @@ -9,16 +9,14 @@ SERVER_NAME = "YServer"; TZ = config.time.timeZone; - VERSION = "1.21.81.2"; - CONTENT_LOG_FILE_ENABLED = "true"; + VERSION = "1.21.131.1"; + CONTENT_LOG_FILE_ENABLED = "false"; ALLOW_CHEATS = "false"; DIFFICULTY = "1"; }; image = "itzg/minecraft-bedrock-server"; ports = ["0.0.0.0:19132:19132/udp"]; - volumes = ["/srv/minecraft/:/data"]; - - podman.sdnotify = "conmon"; # avoid nasty errors about healthcheck (idk, the service runs fine) + volumes = ["/var/lib/minecraft/:/data"]; }; } diff --git a/hosts/ganymede/nixos.nix b/hosts/ganymede/nixos.nix index 863032f..ce30973 100644 --- a/hosts/ganymede/nixos.nix +++ b/hosts/ganymede/nixos.nix @@ -1,8 +1,16 @@ -{inputs, ...}: { +{ + config, + lib, + inputs, + ... +}: { imports = [ inputs.disko.nixosModules.disko + inputs.tsnsrv.nixosModules.default ./disks.nix + ./minecraft.nix + ./iwlwifi.nix ./caddy.nix ]; @@ -15,6 +23,24 @@ networkConfig.DHCP = "yes"; }; + services.openssh.settings.PasswordAuthentication = lib.mkForce true; + + # services.tsnsrv = { + # enable = true; + # defaults = { + # authKeyPath = config.collinux.secrets."tsnsrv-authkey".path; + # ephemeral = true; + # loginServerUrl = "https://williamsfam.us.com"; + # }; + + # services = { + # "adguard" = { + # listenAddr = ":80"; + # toURL = "http://localhost:8001"; + # }; + # }; + # }; + nixpkgs.hostPlatform = "x86_64-linux"; system.stateVersion = "25.05"; } diff --git a/hosts/ganymede/tsnsrv-authkey.age b/hosts/ganymede/tsnsrv-authkey.age new file mode 100644 index 0000000..d0e6eb1 --- /dev/null +++ b/hosts/ganymede/tsnsrv-authkey.age @@ -0,0 +1,7 @@ +age-encryption.org/v1 +-> ssh-ed25519 Jg4yWQ NYO6CUksU6appmdib7CER3YYbcKoyn0wmB4YGTCeTE0 +tizx14UdvQftYrkDa3iXQYDp6JPWHfjDmFwjr11FBxQ +-> ssh-ed25519 azBilg 3PYXHVdB2y2Y42ijOiv8LJ9c4WmeB5ivEPcehfS3Wns +tP/xCHzd31DydF5aCn1tJGudanXLl+DIPod7KFtglXQ +--- nbch7DRt1CYKBqzE9CeUIJgTMKIUCEA/CXVQZjkywfI +~}H <42)U{QK3%G^FW3GJy 1 \ No newline at end of file diff --git a/hosts/mercury/hjem.nix b/hosts/mercury/hjem.nix index 1db654f..6eba4c9 100644 --- a/hosts/mercury/hjem.nix +++ b/hosts/mercury/hjem.nix @@ -6,6 +6,7 @@ kdePackages.kleopatra mpv musescore + zed-editor # experimenting kew # music player prismlauncher diff --git a/modules/services/nixos/bluetooth.nix b/modules/services/nixos/bluetooth.nix index a86b5b3..bdcaa00 100644 --- a/modules/services/nixos/bluetooth.nix +++ b/modules/services/nixos/bluetooth.nix @@ -12,6 +12,18 @@ in powerOnBoot = true; }; + # hardening (down to 2.1 OK) + systemd.services."bluetooth".serviceConfig = { + IPAddressDeny = "any"; + ProtectHostname = true; + ProtectKernelTunables = lib.mkForce true; + ProtectKernelLogs = true; + ProtectKernelModules = lib.mkForce true; + RestrictAddressFamilies = ["AF_UNIX" "AF_BLUETOOTH"]; + ProtectClock = true; + ProcSubset = "pid"; + }; + environment.systemPackages = [ (lib.mkIf cfg.blueman.enable pkgs.blueman) (lib.mkIf cfg.bluetuith.enable pkgs.bluetuith) diff --git a/modules/services/nixos/networking/default.nix b/modules/services/nixos/networking/default.nix index 2667849..62b9146 100644 --- a/modules/services/nixos/networking/default.nix +++ b/modules/services/nixos/networking/default.nix @@ -11,6 +11,7 @@ services.resolved = { enable = true; dnsovertls = "opportunistic"; + dnssec = "allow-downgrade"; fallbackDns = [ "9.9.9.9#dns.quad9.net" "149.112.112.112#dns.quad9.net" @@ -21,6 +22,4 @@ extraConfig = "MulticastDNS=no"; }; networking.resolvconf.enable = false; - - systemd.network.wait-online.enable = false; } diff --git a/modules/services/nixos/networking/networkd.nix b/modules/services/nixos/networking/networkd.nix index 9a11129..470bcec 100644 --- a/modules/services/nixos/networking/networkd.nix +++ b/modules/services/nixos/networking/networkd.nix @@ -25,6 +25,12 @@ in systemd.network = { enable = true; + + wait-online = { + enable = true; + ignoredInterfaces = ["docker0"]; + }; + networks."11-static-lan" = { name = "wl*"; diff --git a/modules/services/nixos/selfhost/adguard.nix b/modules/services/nixos/selfhost/adguard.nix index c5e93ee..73c6caf 100644 --- a/modules/services/nixos/selfhost/adguard.nix +++ b/modules/services/nixos/selfhost/adguard.nix @@ -32,7 +32,8 @@ in DNSStubListener=no ''; - services.caddy = lib.mkIf config.collinux.services.selfhost.caddy.enable { + services.caddy = lib.mkIf (config.collinux.services.selfhost.caddy.enable + && config.collinux.services.selfhost.magic_caddy.enable) { virtualHosts.${cfg.root_url}.extraConfig = '' ${ if config.collinux.services.networking.tailscale.enable diff --git a/modules/services/nixos/selfhost/forgejo.nix b/modules/services/nixos/selfhost/forgejo.nix index b1a6095..e499e64 100644 --- a/modules/services/nixos/selfhost/forgejo.nix +++ b/modules/services/nixos/selfhost/forgejo.nix @@ -36,7 +36,12 @@ in }; }; - services.caddy = lib.mkIf config.collinux.services.selfhost.caddy.enable { + systemd.services."forgejo" = lib.mkIf config.collinux.services.networking.networkd.enable { + after = lib.mkAfter ["network-online.target"]; + wants = lib.mkAfter ["network-online.target"]; + }; + + services.caddy = lib.mkIf (config.collinux.services.selfhost.caddy.enable && config.collinux.services.selfhost.magic_caddy.enable) { virtualHosts.${cfg.root_url}.extraConfig = '' ${ if config.collinux.services.networking.tailscale.enable diff --git a/modules/services/nixos/selfhost/headscale.nix b/modules/services/nixos/selfhost/headscale.nix index 9319691..9989742 100644 --- a/modules/services/nixos/selfhost/headscale.nix +++ b/modules/services/nixos/selfhost/headscale.nix @@ -7,12 +7,14 @@ cfg = config.collinux.services.selfhost.headscale; acl_file = (pkgs.formats.json {}).generate "acl.json" { - ssh = { - src = ["*"]; - dst = ["*"]; - users = ["autogroup:nonroot" "root"]; - action = "accept"; - }; + ssh = [ + { + src = ["collin@"]; + dst = ["collin@"]; + users = ["autogroup:nonroot" "root"]; + action = "accept"; + } + ]; }; in lib.mkIf cfg.enable { @@ -47,6 +49,17 @@ in }; }; + # make sure headscale can start before tailscale + systemd.services."headscale" = lib.mkIf config.collinux.services.networking.tailscale.enable { + after = lib.mkForce ["network.target"]; + before = lib.mkForce ["headscale.target"]; + wants = lib.mkForce ["network.target" "headscale.target"]; + }; + + systemd.targets."headscale" = { + description = "Target represents headscale is running. started by headscale.service"; + }; + services.caddy.virtualHosts.${cfg.root_url}.extraConfig = lib.mkIf config.collinux.services.selfhost.caddy.enable '' reverse_proxy localhost:8080 ''; diff --git a/modules/services/nixos/ssh.nix b/modules/services/nixos/ssh.nix index 2867d10..cfe7883 100644 --- a/modules/services/nixos/ssh.nix +++ b/modules/services/nixos/ssh.nix @@ -8,18 +8,32 @@ in { config = lib.mkIf cfg.enable { services.openssh = { enable = true; + openFirewall = false; hostKeys = [ { path = "/etc/ssh/ssh_host_ed25519_key"; type = "ed25519"; } ]; + + listenAddresses = [ + { + addr = cfg.bind_host; + port = 22; + } + ]; + settings = { PermitRootLogin = "prohibit-password"; PasswordAuthentication = false; }; }; + systemd.services."openssh" = lib.mkIf config.collinux.services.networking.networkd.enable { + after = lib.mkAfter ["network-online.target"]; + wants = lib.mkAfter ["network-online.target"]; + }; + services.tailscale.extraSetFlags = lib.optional config.services.tailscale.enable "--ssh=true"; }; } diff --git a/modules/services/nixos/tailscale.nix b/modules/services/nixos/tailscale.nix index f39fc27..6af3c1c 100644 --- a/modules/services/nixos/tailscale.nix +++ b/modules/services/nixos/tailscale.nix @@ -18,5 +18,11 @@ in allowedUDPPorts = [config.services.tailscale.port]; }; + # don't start tailscale until after headscale starts + systemd.services."tailscaled" = lib.mkIf config.collinux.services.selfhost.headscale.enable { + wants = lib.mkForce ["network.target" "headscale.target"]; + after = lib.mkForce ["network.target" "headscale.target"]; + }; + environment.systemPackages = [pkgs.tailscale]; } diff --git a/modules/services/options.nix b/modules/services/options.nix index 2084c45..8be7c42 100644 --- a/modules/services/options.nix +++ b/modules/services/options.nix @@ -76,11 +76,13 @@ in { type = lib.types.str; default = with config.collinux.services.networking.tailscale; if enable - then "https://${service_name}.${tailnet}" + then "http://${service_name}.${tailnet}" else null; }; }; in { + magic_caddy.enable = mkEnableOption "Automatically create caddy configurations for services"; + adguard = selfhostOptions { service_name = "adguard"; default_port = 8001; diff --git a/secrets.nix b/secrets.nix index 3dc8491..d0a5ffb 100644 --- a/secrets.nix +++ b/secrets.nix @@ -5,6 +5,7 @@ let ganymede = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINlr+53UmlGVP1blkdNl6NFqn1w2umFJyjH1EVUPKIy9"; in { "caddy-env.age".publicKeys = [ganymede]; + "tsnsrv-authkey.age".publicKeys = [ganymede mercury]; "williams-psk.age".publicKeys = [ganymede]; "github-ssh-key.age".publicKeys = [mercury jupiter]; } -- cgit v1.3.1 From c7e9ff3c853755cd3b0e8bc7443d55d222a06f80 Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Sun, 11 Jan 2026 08:03:03 -0600 Subject: clean up services/networking config even more --- hosts/ganymede/config.nix | 25 +++++++++++----------- modules/services/nixos/networking/default.nix | 17 +-------------- modules/services/nixos/networking/networkd.nix | 1 + modules/services/nixos/networking/resolved.nix | 17 +++++++++++++++ modules/services/nixos/selfhost/adguard.nix | 13 ++++++------ modules/services/nixos/selfhost/forgejo.nix | 10 ++++----- modules/services/nixos/selfhost/headscale.nix | 17 ++++++++++----- modules/services/options.nix | 29 ++++++++++++++++---------- 8 files changed, 73 insertions(+), 56 deletions(-) create mode 100644 modules/services/nixos/networking/resolved.nix (limited to 'modules/services') diff --git a/hosts/ganymede/config.nix b/hosts/ganymede/config.nix index 3adf620..0d3f15e 100644 --- a/hosts/ganymede/config.nix +++ b/hosts/ganymede/config.nix @@ -5,7 +5,10 @@ in { user.name = "collin"; secrets = { - "williams-psk".file = ./williams-psk.age; + "williams-psk" = { + file = ./williams-psk.age; + owner = "wpa_supplicant"; + }; "caddy-env".file = ./caddy-env.age; "tsnsrv-authkey".file = ./tsnsrv-authkey.age; }; @@ -40,28 +43,26 @@ in { }; sshd = { enable = true; - bind_host = tailscaleIP; + bind_host = "0.0.0.0"; }; }; selfhost = { - magic_caddy.enable = false; + caddy = { + enable = true; + envFile = config.collinux.secrets."caddy-env".path; + }; - # adguard = { - # enable = true; - # bind_host = tailscaleIP; - # }; forgejo = { enable = true; bind_host = tailscaleIP; + root_url = "ganymede.collinux.tailnet:8010"; }; + headscale = { enable = true; - root_url = "https://headscale.williamsfam.us.com"; - }; - caddy = { - enable = true; - envFile = config.collinux.secrets."caddy-env".path; + root_url = "headscale.williamsfam.us.com"; + caddy.enable = true; }; }; }; diff --git a/modules/services/nixos/networking/default.nix b/modules/services/nixos/networking/default.nix index 62b9146..9fa56da 100644 --- a/modules/services/nixos/networking/default.nix +++ b/modules/services/nixos/networking/default.nix @@ -3,23 +3,8 @@ ./iwd.nix ./networkmanager.nix ./networkd.nix + ./resolved.nix ]; networking.firewall.enable = true; - - # DNS - services.resolved = { - enable = true; - dnsovertls = "opportunistic"; - dnssec = "allow-downgrade"; - fallbackDns = [ - "9.9.9.9#dns.quad9.net" - "149.112.112.112#dns.quad9.net" - ]; - - # disable extra stuff - llmnr = "false"; - extraConfig = "MulticastDNS=no"; - }; - networking.resolvconf.enable = false; } diff --git a/modules/services/nixos/networking/networkd.nix b/modules/services/nixos/networking/networkd.nix index 470bcec..920b93f 100644 --- a/modules/services/nixos/networking/networkd.nix +++ b/modules/services/nixos/networking/networkd.nix @@ -29,6 +29,7 @@ in wait-online = { enable = true; ignoredInterfaces = ["docker0"]; + anyInterface = true; }; networks."11-static-lan" = { diff --git a/modules/services/nixos/networking/resolved.nix b/modules/services/nixos/networking/resolved.nix new file mode 100644 index 0000000..b552095 --- /dev/null +++ b/modules/services/nixos/networking/resolved.nix @@ -0,0 +1,17 @@ +{ + networking.resolvconf.enable = false; + + services.resolved = { + enable = true; + dnsovertls = "opportunistic"; + dnssec = "allow-downgrade"; + fallbackDns = [ + "9.9.9.9#dns.quad9.net" + "149.112.112.112#dns.quad9.net" + ]; + + # disable extra stuff + llmnr = "false"; + extraConfig = "MulticastDNS=no"; + }; +} diff --git a/modules/services/nixos/selfhost/adguard.nix b/modules/services/nixos/selfhost/adguard.nix index 73c6caf..69fb8a4 100644 --- a/modules/services/nixos/selfhost/adguard.nix +++ b/modules/services/nixos/selfhost/adguard.nix @@ -32,17 +32,16 @@ in DNSStubListener=no ''; - services.caddy = lib.mkIf (config.collinux.services.selfhost.caddy.enable - && config.collinux.services.selfhost.magic_caddy.enable) { + services.tailscale.extraSetFlags = lib.optional config.collinux.services.networking.tailscale.enable "--accept-dns=false"; # would create an infinite loop of dns lookups + + services.caddy = lib.mkIf cfg.caddy.enable { virtualHosts.${cfg.root_url}.extraConfig = '' ${ - if config.collinux.services.networking.tailscale.enable - then "bind tailscale/adguard" + if cfg.caddy.bind_tailscale + then "bind tailscale/${cfg.service_name}" else "" } - reverse_proxy localhost:${toString cfg.port} + reverse_proxy ${cfg.bind_host}:${toString cfg.port} ''; }; - - services.tailscale.extraSetFlags = lib.optional config.collinux.services.networking.tailscale.enable "--accept-dns=false"; # would create an infinite loop of dns lookups } diff --git a/modules/services/nixos/selfhost/forgejo.nix b/modules/services/nixos/selfhost/forgejo.nix index e499e64..4571dca 100644 --- a/modules/services/nixos/selfhost/forgejo.nix +++ b/modules/services/nixos/selfhost/forgejo.nix @@ -8,7 +8,7 @@ in lib.mkIf cfg.enable { services.forgejo = { enable = true; - database.type = "postgres"; + database.type = "sqlite3"; settings = { server = { DOMAIN = "localhost"; @@ -41,14 +41,14 @@ in wants = lib.mkAfter ["network-online.target"]; }; - services.caddy = lib.mkIf (config.collinux.services.selfhost.caddy.enable && config.collinux.services.selfhost.magic_caddy.enable) { + services.caddy = lib.mkIf cfg.caddy.enable { virtualHosts.${cfg.root_url}.extraConfig = '' ${ - if config.collinux.services.networking.tailscale.enable - then "bind tailscale/forgejo" + if cfg.caddy.bind_tailscale + then "bind tailscale/${cfg.service_name}" else "" } - reverse_proxy localhost:${toString cfg.port} + reverse_proxy ${cfg.bind_host}:${toString cfg.port} ''; }; } diff --git a/modules/services/nixos/selfhost/headscale.nix b/modules/services/nixos/selfhost/headscale.nix index 9989742..2bdcca1 100644 --- a/modules/services/nixos/selfhost/headscale.nix +++ b/modules/services/nixos/selfhost/headscale.nix @@ -23,7 +23,7 @@ in address = cfg.bind_host; port = cfg.port; settings = { - server_url = cfg.root_url; + server_url = "https://${cfg.root_url}"; database.type = "sqlite"; @@ -60,9 +60,16 @@ in description = "Target represents headscale is running. started by headscale.service"; }; - services.caddy.virtualHosts.${cfg.root_url}.extraConfig = lib.mkIf config.collinux.services.selfhost.caddy.enable '' - reverse_proxy localhost:8080 - ''; - environment.systemPackages = [pkgs.headscale]; + + services.caddy = lib.mkIf cfg.caddy.enable { + virtualHosts.${cfg.root_url}.extraConfig = '' + ${ + if cfg.caddy.bind_tailscale + then "bind tailscale/${cfg.service_name}" + else "" + } + reverse_proxy ${cfg.bind_host}:${toString cfg.port} + ''; + }; } diff --git a/modules/services/options.nix b/modules/services/options.nix index 8be7c42..df8bc52 100644 --- a/modules/services/options.nix +++ b/modules/services/options.nix @@ -17,7 +17,7 @@ in { networkmanager.enable = mkEnableOption "heavier wifi daemon"; networkd = { - enable = mkEnableOption "set static IP (systemd-networkd)"; + enable = mkEnableOption "use systemd-networkd"; ssid = mkOption {type = lib.types.str;}; pskFile = mkOption {type = lib.types.str;}; @@ -61,9 +61,13 @@ in { selfhostOptions = { service_name, default_port ? null, - ... }: { - enable = mkEnableOption ""; + enable = mkEnableOption "${service_name} selfhosted service"; + + service_name = mkOption { + type = lib.types.str; + }; + bind_host = mkOption { type = ip_addr; default = "0.0.0.0"; @@ -72,29 +76,32 @@ in { type = lib.types.port; default = default_port; }; + root_url = mkOption { - type = lib.types.str; - default = with config.collinux.services.networking.tailscale; - if enable - then "http://${service_name}.${tailnet}" - else null; + type = lib.types.nullOr lib.types.str; + }; + + caddy = { + enable = mkEnableOption "Automatically create caddy configurations for this service"; + bind_tailscale = mkEnableOption "Bind the service to {service_name}.{tailnet}"; }; }; in { - magic_caddy.enable = mkEnableOption "Automatically create caddy configurations for services"; - adguard = selfhostOptions { service_name = "adguard"; default_port = 8001; }; + forgejo = selfhostOptions { service_name = "forgejo"; default_port = 8010; }; + headscale = selfhostOptions { service_name = "headscale"; default_port = 8080; }; + caddy = { enable = mkEnableOption "caddy https server"; envFile = mkOption { @@ -109,7 +116,7 @@ in { assertions = [ { assertion = with config.collinux.services.networking; (iwd.enable && !networkmanager.enable && !networkd.enable) || (!iwd.enable && networkmanager.enable && !networkd.enable) || (!iwd.enable && !networkmanager.enable && networkd.enable); - message = "only one networking method (iwd, networkmanager, static) can be active"; + message = "only one networking method (iwd, networkmanager, networkd) can be active"; } ]; }; -- cgit v1.3.1 From 32a7e59b93a9c3748cd6aeca3d4fc9dadf8e0f59 Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Sun, 11 Jan 2026 08:03:58 -0600 Subject: move various configs into modules where they belong --- hosts/ganymede/nixos.nix | 23 ++--------------------- hosts/jupiter/config.nix | 5 +---- hosts/jupiter/nixos.nix | 15 +-------------- hosts/mercury/config.nix | 28 ++++++++++++---------------- hosts/mercury/hjem.nix | 1 - hosts/mercury/nixos.nix | 11 +++++------ modules/desktop/nixos/fonts.nix | 3 +-- modules/nix/nixos/default.nix | 10 +++++----- modules/services/nixos/audio.nix | 5 +++-- modules/services/options.nix | 8 +++----- modules/user/nixos/default.nix | 3 +-- 11 files changed, 34 insertions(+), 78 deletions(-) (limited to 'modules/services') diff --git a/hosts/ganymede/nixos.nix b/hosts/ganymede/nixos.nix index ce30973..9dc6dec 100644 --- a/hosts/ganymede/nixos.nix +++ b/hosts/ganymede/nixos.nix @@ -1,6 +1,5 @@ { config, - lib, inputs, ... }: { @@ -23,24 +22,6 @@ networkConfig.DHCP = "yes"; }; - services.openssh.settings.PasswordAuthentication = lib.mkForce true; - - # services.tsnsrv = { - # enable = true; - # defaults = { - # authKeyPath = config.collinux.secrets."tsnsrv-authkey".path; - # ephemeral = true; - # loginServerUrl = "https://williamsfam.us.com"; - # }; - - # services = { - # "adguard" = { - # listenAddr = ":80"; - # toURL = "http://localhost:8001"; - # }; - # }; - # }; - - nixpkgs.hostPlatform = "x86_64-linux"; - system.stateVersion = "25.05"; + # i broke something and this fixes it + environment.etc."systemd/resolved.conf.d/10-dns.conf".text = config.environment.etc."systemd/resolved.conf".text; } diff --git a/hosts/jupiter/config.nix b/hosts/jupiter/config.nix index a0c1583..decaa61 100644 --- a/hosts/jupiter/config.nix +++ b/hosts/jupiter/config.nix @@ -57,10 +57,7 @@ sshd.enable = true; }; - audio = { - enable = true; - pulse.enable = true; - }; + audio.enable = true; bluetooth.enable = true; }; diff --git a/hosts/jupiter/nixos.nix b/hosts/jupiter/nixos.nix index e39328a..80ab0f4 100644 --- a/hosts/jupiter/nixos.nix +++ b/hosts/jupiter/nixos.nix @@ -1,21 +1,8 @@ -{ - inputs, - pkgs, - ... -}: { +{inputs, ...}: { imports = [ ./disks.nix inputs.nixos-facter-modules.nixosModules.facter ]; - boot.blacklistedKernelModules = ["snd_seq_dummy"]; - - systemd.network.wait-online.enable = false; # fix for weird wifi issue - - fonts.packages = [pkgs.nerd-fonts.iosevka]; - facter.reportPath = ./facter.json; - time.timeZone = "America/Chicago"; - nixpkgs.hostPlatform = "x86_64-linux"; - system.stateVersion = "25.05"; } diff --git a/hosts/mercury/config.nix b/hosts/mercury/config.nix index 9ee29d0..3fb4753 100644 --- a/hosts/mercury/config.nix +++ b/hosts/mercury/config.nix @@ -1,20 +1,19 @@ -{pkgs, ...}: { +{ collinux = { theme = "catppuccin"; user.name = "collin"; desktop = { wallpaper = ./wallpaper.jpg; - - # gtk.enable = true; - + gtk.enable = true; greetd.enable = true; wm = { - # sway.enable = true; niri.enable = true; - components.fuzzel.enable = true; - components.dunst.enable = true; + components = { + fuzzel.enable = true; + dunst.enable = true; + }; }; programs = { @@ -43,26 +42,23 @@ shells.bash.enable = true; # for nix-shells programs = { - lazygit.enable = true; starship.enable = true; - fzf.enable = true; bat.enable = true; eza.enable = true; + helix = { + enable = true; + hardMode = true; + }; + lazygit.enable = true; + nh.enable = true; git = { enable = true; userName = "Collin Williams"; userEmail = "96917990+bluedragon1221@users.noreply.github.com"; installKey = true; }; - - nh.enable = true; - - helix = { - enable = true; - hardMode = true; - }; }; }; diff --git a/hosts/mercury/hjem.nix b/hosts/mercury/hjem.nix index 6eba4c9..1db654f 100644 --- a/hosts/mercury/hjem.nix +++ b/hosts/mercury/hjem.nix @@ -6,7 +6,6 @@ kdePackages.kleopatra mpv musescore - zed-editor # experimenting kew # music player prismlauncher diff --git a/hosts/mercury/nixos.nix b/hosts/mercury/nixos.nix index 558ae60..631a537 100644 --- a/hosts/mercury/nixos.nix +++ b/hosts/mercury/nixos.nix @@ -12,10 +12,11 @@ inputs.lanzaboote.nixosModules.lanzaboote ]; - systemd.services.systemd-udev-settle.enable = false; - networking.interfaces.wlp2s0.useDHCP = false; - - services.sshd.enable = true; + services.syncthing = { + enable = true; + user = "collin"; + dataDir = "/home/collin/.local/syncthing"; + }; facter.reportPath = ./facter.json; @@ -25,6 +26,4 @@ allowedUDPPorts = [445]; allowedTCPPorts = [8000]; }; - - system.stateVersion = "25.05"; } diff --git a/modules/desktop/nixos/fonts.nix b/modules/desktop/nixos/fonts.nix index 3f10d92..5ac17ec 100644 --- a/modules/desktop/nixos/fonts.nix +++ b/modules/desktop/nixos/fonts.nix @@ -1,8 +1,7 @@ {pkgs, ...}: { fonts = { enableDefaultPackages = false; - # fontDir.enable = true; fontconfig.enable = true; - packages = [pkgs.nerd-fonts.iosevka pkgs.ibm-plex]; # for terminal (blackbox or foot) + packages = [pkgs.nerd-fonts.iosevka pkgs.ibm-plex]; # for terminal (blackbox or foot or ghostty) }; } diff --git a/modules/nix/nixos/default.nix b/modules/nix/nixos/default.nix index 7116371..c817859 100644 --- a/modules/nix/nixos/default.nix +++ b/modules/nix/nixos/default.nix @@ -1,12 +1,9 @@ { - inputs, config, pkgs, ... }: { nix = { - # package = inputs.determinate.packages.${pkgs.system}.default; - gc.automatic = false; # use nh cleaner instead # Make builds run with low priority so my system stays responsive @@ -27,9 +24,12 @@ programs.nh = { enable = true; - flake = "/home/collin/nixos"; + flake = "/home/${config.collinux.user.name}/nixos"; clean.enable = true; }; - hjem.users."${config.collinux.user.name}".packages = [pkgs.cached-nix-shell]; + environment.systemPackages = [pkgs.cached-nix-shell]; + + nixpkgs.hostPlatform = "x86_64-linux"; + system.stateVersion = "25.05"; } diff --git a/modules/services/nixos/audio.nix b/modules/services/nixos/audio.nix index 93f8289..8f2f23e 100644 --- a/modules/services/nixos/audio.nix +++ b/modules/services/nixos/audio.nix @@ -12,9 +12,10 @@ in enable = true; wireplumber.enable = true; alsa.enable = true; - - pulse.enable = cfg.pulse.enable; + pulse.enable = false; }; + boot.blacklistedKernelModules = ["snd_seq_dummy"]; # remove extraneous alsa midi devices + environment.systemPackages = [pkgs.pwvucontrol]; } diff --git a/modules/services/options.nix b/modules/services/options.nix index df8bc52..16bf5ac 100644 --- a/modules/services/options.nix +++ b/modules/services/options.nix @@ -46,11 +46,9 @@ in { }; }; }; - audio = { - enable = mkEnableOption "pipewire + wireplumber"; - pulse.enable = mkEnableOption "pipewire-pulse"; - # some config to make audio work with wine (TODO for jupiter) - }; + + audio.enable = mkEnableOption "pipewire + wireplumber"; + bluetooth = { enable = mkEnableOption "bluetooth"; blueman.enable = mkEnableOption "graphical bluetooth manager"; diff --git a/modules/user/nixos/default.nix b/modules/user/nixos/default.nix index b14e52d..0b0ae41 100644 --- a/modules/user/nixos/default.nix +++ b/modules/user/nixos/default.nix @@ -1,13 +1,12 @@ { config, - hostname, lib, ... }: let cfg = config.collinux.user; in { users = { - mutableUsers = true; + mutableUsers = true; # system passwords stored mutably users."${cfg.name}" = { isNormalUser = true; -- cgit v1.3.1 From dbc5cb478c7fad1c1750421486252f0a5d98ef9c Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Sun, 11 Jan 2026 13:36:45 -0600 Subject: now there's docs --- flake.lock | 59 ++++------------------- flake.nix | 15 ++++-- lib/lib.nix | 14 ++++-- lib/nix-furnace/mkSystem.nix | 82 ++++++++++++++++++++----------- modules/boot/options.nix | 9 ++-- modules/desktop/options.nix | 112 +++++++++++++++++++++++-------------------- modules/options.nix | 3 ++ modules/secrets/options.nix | 10 +++- modules/services/options.nix | 43 ++++++++++++----- modules/terminal/options.nix | 10 ++-- modules/user/options.nix | 2 + 11 files changed, 197 insertions(+), 162 deletions(-) (limited to 'modules/services') diff --git a/flake.lock b/flake.lock index 5832b7a..dae6702 100644 --- a/flake.lock +++ b/flake.lock @@ -150,24 +150,6 @@ "type": "github" } }, - "flake-parts": { - "inputs": { - "nixpkgs-lib": "nixpkgs-lib" - }, - "locked": { - "lastModified": 1765835352, - "narHash": "sha256-XswHlK/Qtjasvhd1nOa1e8MgZ8GS//jBoTqWtrS1Giw=", - "owner": "hercules-ci", - "repo": "flake-parts", - "rev": "a34fae9c08a15ad73f295041fec82323541400a9", - "type": "github" - }, - "original": { - "owner": "hercules-ci", - "repo": "flake-parts", - "type": "github" - } - }, "gitignore": { "inputs": { "nixpkgs": [ @@ -323,18 +305,18 @@ "type": "github" } }, - "nixpkgs-lib": { + "nmd": { "locked": { - "lastModified": 1765674936, - "narHash": "sha256-k00uTP4JNfmejrCLJOwdObYC9jHRrr/5M/a/8L2EIdo=", - "owner": "nix-community", - "repo": "nixpkgs.lib", - "rev": "2075416fcb47225d9b68ac469a5c4801a9c4dd85", + "lastModified": 1759339018, + "narHash": "sha256-13x2gvgnnr3cJ5qp7zz7ZnUSrg0DF/sU9KiwZkML6J0=", + "owner": "gvolpe", + "repo": "nmd", + "rev": "5ecbe493e22de649e79c8e51dc5e92659940e081", "type": "github" }, "original": { - "owner": "nix-community", - "repo": "nixpkgs.lib", + "owner": "gvolpe", + "repo": "nmd", "type": "github" } }, @@ -371,8 +353,8 @@ "lanzaboote": "lanzaboote", "nixos-facter-modules": "nixos-facter-modules", "nixpkgs": "nixpkgs", - "tmux-tsunami": "tmux-tsunami", - "tsnsrv": "tsnsrv" + "nmd": "nmd", + "tmux-tsunami": "tmux-tsunami" } }, "rust-overlay": { @@ -507,27 +489,6 @@ "type": "github" } }, - "tsnsrv": { - "inputs": { - "flake-parts": "flake-parts", - "nixpkgs": [ - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1767001347, - "narHash": "sha256-uRm4oWMFUBSmXgofOngMWIyA/yUmLlon6f3XoFTWvBA=", - "owner": "boinkor-net", - "repo": "tsnsrv", - "rev": "8f3fbf69e1517612c0fde9be27522e12c2ddc238", - "type": "github" - }, - "original": { - "owner": "boinkor-net", - "repo": "tsnsrv", - "type": "github" - } - }, "utils": { "inputs": { "systems": "systems_2" diff --git a/flake.nix b/flake.nix index 6f71eb4..35afadd 100644 --- a/flake.nix +++ b/flake.nix @@ -38,14 +38,13 @@ flake = false; }; - tsnsrv = { - url = "github:boinkor-net/tsnsrv"; - inputs.nixpkgs.follows = "nixpkgs"; - }; + nmd.url = "github:gvolpe/nmd"; }; outputs = inputs: let - inherit (import ./lib/nix-furnace/mkSystem.nix) mkNixosSystem; + inherit (import ./lib/nix-furnace/mkSystem.nix) mkNixosSystem genDocs; + + buildPkgs = import inputs.nixpkgs {system = "x86_64-linux";}; in rec { nixosConfigurations."mercury" = mkNixosSystem { inherit inputs; @@ -63,6 +62,12 @@ username = "collin"; }; + packages."x86_64-linux".docs = buildPkgs.callPackage genDocs { + inherit inputs; + pkgs = buildPkgs; + hostname = "mercury"; + }; + deploy.nodes."ganymede" = { hostname = "ganymede"; sshUser = "root"; diff --git a/lib/lib.nix b/lib/lib.nix index 00cc334..56f0dfd 100644 --- a/lib/lib.nix +++ b/lib/lib.nix @@ -32,15 +32,21 @@ let config, }: let inherit (lib) mkOption mkEnableOption; - mkProgramOption = name: { - enable = mkEnableOption "whether to enable ${name}"; - theme = mkOption { + + mkThemeOption = name: + mkOption { + description = "Pre-made theme for ${name}"; type = lib.types.enum ["catppuccin" "adwaita" "kanagawa"]; default = config.collinux.theme; + defaultText = "config.collinux.theme"; }; + + mkProgramOption = name: { + enable = mkEnableOption "whether to enable ${name}"; + theme = mkThemeOption name; }; in { - inherit mkProgramOption; + inherit mkProgramOption mkThemeOption; }; in { inherit globimport; diff --git a/lib/nix-furnace/mkSystem.nix b/lib/nix-furnace/mkSystem.nix index 85f952c..2766082 100644 --- a/lib/nix-furnace/mkSystem.nix +++ b/lib/nix-furnace/mkSystem.nix @@ -4,6 +4,32 @@ let listModules = getSubdirs ../../modules; + nixosModules = hostname: + [ + ../../modules/options.nix + ../../hosts/${hostname}/config.nix + (lazyImport ../../hosts/${hostname}/nixos.nix) + ] + ++ (listModules + |> (builtins.map (modName: [ + (lazyImport ../../modules/${modName}/options.nix) + (lazyImport ../../modules/${modName}/nixos/default.nix) + ])) + |> my-lib.flatten); + + hjemModules = hostname: + [ + ../../modules/options.nix + ../../hosts/${hostname}/config.nix + (lazyImport ../../hosts/${hostname}/hjem.nix) + ] + ++ (listModules + |> (builtins.map (modName: [ + (lazyImport ../../modules/${modName}/options.nix) + (lazyImport ../../modules/${modName}/hjem/default.nix) + ])) + |> my-lib.flatten); + mkNixosSystem = { inputs, hostname, @@ -17,20 +43,7 @@ let ../../hosts/${hostname}/config.nix # Nixos-sided modules - { - imports = - [ - ../../modules/options.nix - ../../hosts/${hostname}/config.nix - (lazyImport ../../hosts/${hostname}/nixos.nix) - ] - ++ (listModules - |> (builtins.map (modName: [ - (lazyImport ../../modules/${modName}/options.nix) - (lazyImport ../../modules/${modName}/nixos/default.nix) - ])) - |> my-lib.flatten); - } + {imports = nixosModules hostname;} # Hjem-sided modules { @@ -38,18 +51,7 @@ let inputs.hjem.nixosModules.hjem ]; hjem = { - extraModules = - [ - ../../modules/options.nix - ../../hosts/${hostname}/config.nix - (lazyImport ../../hosts/${hostname}/hjem.nix) - ] - ++ (listModules - |> (builtins.map (modName: [ - (lazyImport ../../modules/${modName}/options.nix) - (lazyImport ../../modules/${modName}/hjem/default.nix) - ])) - |> my-lib.flatten); + extraModules = hjemModules hostname; specialArgs = {inherit inputs my-lib;}; users.${username} = { enable = true; @@ -60,6 +62,32 @@ let } ]; }; + + genDocs = { + lib, + pkgs, + inputs, + hostname, + ... + }: let + eval = lib.evalModules { + modules = listModules |> (builtins.map (m: (lazyImport ../../modules/${m}/options.nix))); + specialArgs = { + inherit my-lib pkgs; + }; + check = false; + }; + + optionsDoc = pkgs.nixosOptionsDoc { + inherit (eval) options; + }; + in + pkgs.runCommand "options-doc.md" { + buildInputs = [pkgs.pandoc]; + } '' + mkdir -p $out + cat ${optionsDoc.optionsCommonMark} | pandoc -t html -o - | tee $out/index.html + ''; in { - inherit mkNixosSystem; + inherit mkNixosSystem genDocs; } diff --git a/modules/boot/options.nix b/modules/boot/options.nix index 2f670f9..9e85570 100644 --- a/modules/boot/options.nix +++ b/modules/boot/options.nix @@ -1,9 +1,11 @@ { + my-lib, config, lib, ... }: let - inherit (lib) mkOption mkEnableOption types; + inherit (lib) mkOption mkEnableOption; + inherit (my-lib.options {inherit lib config;}) mkThemeOption; in { options = { collinux.boot = { @@ -15,10 +17,7 @@ in { }; plymouth = { enable = mkEnableOption "plymouth bootsplash"; - theme = mkOption { - type = types.enum ["catppuccin" "adwaita"]; - default = config.collinux.theme; - }; + theme = mkThemeOption "plymouth"; }; secureBoot.enable = mkEnableOption "lanzaboote"; }; diff --git a/modules/desktop/options.nix b/modules/desktop/options.nix index 1067d0b..e59ed68 100644 --- a/modules/desktop/options.nix +++ b/modules/desktop/options.nix @@ -6,7 +6,7 @@ ... }: let inherit (lib) mkOption mkEnableOption types; - inherit (my-lib.options {inherit lib config;}) mkProgramOption; + inherit (my-lib.options {inherit lib config;}) mkProgramOption mkThemeOption; in { options = { collinux.desktop = { @@ -17,12 +17,14 @@ in { wallpaper_cmd = mkOption { type = types.str; default = "${lib.getExe pkgs.wbg} -s ${config.collinux.desktop.wallpaper}"; + internal = true; }; greetd = { enable = mkEnableOption "greetd greeter"; command = mkOption { type = lib.types.str; + internal = true; default = let cfg = config.collinux.desktop; in @@ -40,7 +42,6 @@ in { niri.enable = mkEnableOption "niri"; components = { - # waybar = mkProgramOption "waybar"; dunst = mkProgramOption "dunst"; fuzzel = mkProgramOption "fuzzel"; }; @@ -49,54 +50,63 @@ in { gtk = { enable = mkEnableOption "gtk theming"; - theme = mkOption { - type = types.enum ["catppuccin" "adwaita" "kanagawa"]; - default = config.collinux.theme; - }; - cursor_data = { - package = mkOption { - type = lib.types.package; - default = - if (config.collinux.desktop.gtk.theme == "catppuccin") - then pkgs.catppuccin-cursors.mochaDark - else if (config.collinux.desktop.gtk.theme == "adwaita") - then pkgs.vanilla-dmz - else null; - }; - name = mkOption { - type = lib.types.str; - default = - if (config.collinux.desktop.gtk.theme == "catppuccin") - then "catppuccin-mocha-dark-cursors" - else if (config.collinux.desktop.gtk.theme == "adwaita") - then "Vanilla-DMZ" - else null; + theme = mkThemeOption "gtk"; + + cursor_data = mkOption { + internal = true; + type = lib.types.submodule { + package = mkOption { + internal = true; + type = lib.types.package; + }; + name = mkOption { + internal = true; + type = lib.types.str; + }; }; + default = + if config.collinux.desktop.gtk.theme == "catppuccin" + then { + name = "catppuccin-mocha-dark-cursors"; + package = pkgs.catppuccin-cursors.mochaDark; + } + else if config.collinux.gtk.theme == "adwaita" + then { + name = "Vanilla-DMZ"; + package = pkgs.vanilla-dmz; + } + else null; }; - theme_data = { - package = mkOption { - type = lib.types.package; - default = - if (config.collinux.desktop.gtk.theme == "catppuccin") - then - (pkgs.catppuccin-gtk.override { - variant = "mocha"; - accents = ["blue"]; - size = "standard"; - }) - else if (config.collinux.desktop.gtk.theme == "adwaita") - then pkgs.adw-gtk3 - else ""; - }; - name = mkOption { - type = lib.types.str; - default = - if (config.collinux.desktop.gtk.theme == "catppuccin") - then "catppuccin-mocha-blue-standard" - else if (config.collinux.desktop.gtk.theme == "adwaita") - then "adw-gtk3" - else ""; + + theme_data = mkOption { + internal = true; + type = lib.types.submodule { + package = mkOption { + internal = true; + type = lib.types.package; + }; + name = mkOption { + internal = true; + type = lib.types.str; + }; }; + + default = + if config.collinux.desktop.gtk.theme == "catppuccin" + then { + package = pkgs.catppuccin-gtk.override { + variant = "mocha"; + accents = ["blue"]; + size = "standard"; + }; + name = "catppuccin-mocha-blue-standard"; + } + else if config.collinux.desktop.gtk.theme == "adwaita" + then { + package = pkgs.adw-gtk3; + name = "adw-gtk3"; + } + else null; }; }; @@ -106,11 +116,9 @@ in { profileName = mkOption { type = types.str; default = config.collinux.user.name; + internal = true; }; - theme = mkOption { - type = types.enum ["none" "catppuccin" "adwaita" "kanagawa"]; - default = config.collinux.theme; - }; + theme = mkThemeOption "firefox"; extensions.zotero.enable = mkOption { description = "install Zotero Connector for Firefox"; default = config.collinux.desktop.programs.research.enable; @@ -122,7 +130,7 @@ in { ghostty.enable = mkEnableOption "ghostty"; alacritty.enable = mkEnableOption "alacritty"; - research.enable = mkEnableOption "zathura, Xournal++, Zotero, Zotero Connector"; + research.enable = mkEnableOption "zathura, Xournal++, Zotero"; }; }; }; diff --git a/modules/options.nix b/modules/options.nix index 65de32e..8ecf1d7 100644 --- a/modules/options.nix +++ b/modules/options.nix @@ -7,15 +7,18 @@ in { options = { collinux.theme = mkOption { + description = "System-wide theme"; type = types.enum ["catppuccin" "adwaita" "kanagawa"]; }; collinux.palette = let colorOption = lib.mkOption { type = lib.types.strMatching "^([0-9a-fA-F]{6}|[0-9a-fA-F]{3})$"; + internal = true; }; in lib.mkOption { + internal = true; type = lib.types.submodule { options = { base00 = colorOption; diff --git a/modules/secrets/options.nix b/modules/secrets/options.nix index de15f50..fa53d6f 100644 --- a/modules/secrets/options.nix +++ b/modules/secrets/options.nix @@ -3,25 +3,33 @@ in { options = { collinux.secrets = lib.mkOption { + description = "Atribute set of secrets"; type = lib.types.attrsOf ( lib.types.submodule ({config, ...}: { options = { name = mkOption { type = lib.types.str; default = config._module.args.name; + internal = true; + }; + file = mkOption { + description = "Name of the file in the /run/secrets.d"; + type = lib.types.path; }; - file = mkOption {type = lib.types.path;}; mode = mkOption { + description = "Permissions mode of the decrypted secret in a format understood by chmod"; type = lib.types.str; default = "0400"; }; owner = mkOption { + description = "Owner of the decrypted secret file"; type = lib.types.str; default = "0"; }; path = mkOption { type = lib.types.str; default = "/run/secrets.d/${config.name}"; + description = "Path where the decrypted secret is installed"; }; }; }) diff --git a/modules/services/options.nix b/modules/services/options.nix index 16bf5ac..231c949 100644 --- a/modules/services/options.nix +++ b/modules/services/options.nix @@ -18,36 +18,47 @@ in { networkd = { enable = mkEnableOption "use systemd-networkd"; - ssid = mkOption {type = lib.types.str;}; - pskFile = mkOption {type = lib.types.str;}; + ssid = mkOption { + description = "SSID for this network"; + type = lib.types.str; + }; + pskFile = mkOption { + description = "Absolute path to a file containing the pre-shared key for this network"; + type = lib.types.str; + example = "/run/secrets.d/wifi-psk"; + }; static = lib.mkOption { + description = "Set a static IP address for this device on this network. Set to null to use DHCP"; type = lib.types.nullOr (lib.types.submodule { options = { - ip = mkOption {type = ip_addr_cidr;}; - gateway = mkOption {type = ip_addr;}; + ip = mkOption { + description = "IP address"; + type = ip_addr_cidr; + }; + gateway = mkOption { + description = "default gateway"; + type = ip_addr; + }; }; }); default = null; }; }; - tailscale = { - enable = mkEnableOption "tailscale"; - tailnet = mkOption { - type = lib.types.str; - default = "tail7cca06.ts.net"; - }; - }; + + tailscale.enable = mkEnableOption "tailscale"; + sshd = { enable = mkEnableOption "OpenSSH server"; bind_host = mkOption { + description = "The IP address on which OpenSSH will listen for incomming connections. The default, `0.0.0.0`, means 'all interfaces'"; type = ip_addr; default = "0.0.0.0"; }; }; }; - audio.enable = mkEnableOption "pipewire + wireplumber"; + audio.enable = mkEnableOption "pipewire and wireplumber"; bluetooth = { enable = mkEnableOption "bluetooth"; @@ -64,24 +75,28 @@ in { service_name = mkOption { type = lib.types.str; + internal = true; }; bind_host = mkOption { + description = "The IP address on which ${service_name} will listen for incoming connections. The default, `0.0.0.0`, means 'all interfaces'"; type = ip_addr; default = "0.0.0.0"; }; port = mkOption { + description = "The port on which ${service_name} will listen for incomming connections"; type = lib.types.port; default = default_port; }; root_url = mkOption { + description = "The final url that this service will be hosted on. Required for caddy, otherwise optional"; type = lib.types.nullOr lib.types.str; }; caddy = { enable = mkEnableOption "Automatically create caddy configurations for this service"; - bind_tailscale = mkEnableOption "Bind the service to {service_name}.{tailnet}"; + bind_tailscale = mkEnableOption "Bind the service to ${service_name}.{tailnet}"; }; }; in { @@ -103,7 +118,9 @@ in { caddy = { enable = mkEnableOption "caddy https server"; envFile = mkOption { + description = "Absolute path to file that contains environment variables for caddy operations"; type = lib.types.str; + example = "/run/secrets.d/caddy-env"; }; }; }; diff --git a/modules/terminal/options.nix b/modules/terminal/options.nix index 25e0eb4..8207be3 100644 --- a/modules/terminal/options.nix +++ b/modules/terminal/options.nix @@ -6,7 +6,7 @@ ... }: let inherit (lib) mkOption mkEnableOption types; - inherit (my-lib.options {inherit lib config;}) mkProgramOption; + inherit (my-lib.options {inherit lib config;}) mkProgramOption mkThemeOption; in { options = { collinux.terminal = { @@ -37,10 +37,11 @@ in { git = { enable = mkEnableOption "git"; userName = mkOption { + description = "Public name uses for git"; type = types.str; - default = config.collinux.user.name; }; userEmail = mkOption { + description = "Public email used for git"; type = types.str; }; installKey = mkEnableOption "automatically install github authentication key"; @@ -48,10 +49,7 @@ in { helix = { enable = mkEnableOption "helix text editor"; - theme = mkOption { - type = lib.types.enum ["catppuccin" "adwaita" "kanagawa"]; - default = config.collinux.theme; - }; + theme = mkThemeOption "helix"; hardMode = mkOption { type = types.bool; description = "Disable arrow keys and mouse"; diff --git a/modules/user/options.nix b/modules/user/options.nix index 1024494..d805bf9 100644 --- a/modules/user/options.nix +++ b/modules/user/options.nix @@ -4,9 +4,11 @@ in { options = { collinux.user = { name = mkOption { + description = "Name for the sole user of this system"; type = types.str; }; isAdmin = mkOption { + description = "Whether this user is an admin"; type = types.bool; default = true; }; -- cgit v1.3.1 From 5c4484e206087b0be5723b0f79728fdeb1af7f82 Mon Sep 17 00:00:00 2001 From: Collin Williams <96917990+bluedragon1221@users.noreply.github.com> Date: Sun, 18 Jan 2026 07:04:18 -0600 Subject: make tailscale start at the right time --- modules/services/nixos/tailscale.nix | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) (limited to 'modules/services') diff --git a/modules/services/nixos/tailscale.nix b/modules/services/nixos/tailscale.nix index 6af3c1c..50e35d3 100644 --- a/modules/services/nixos/tailscale.nix +++ b/modules/services/nixos/tailscale.nix @@ -19,10 +19,16 @@ in }; # don't start tailscale until after headscale starts - systemd.services."tailscaled" = lib.mkIf config.collinux.services.selfhost.headscale.enable { - wants = lib.mkForce ["network.target" "headscale.target"]; - after = lib.mkForce ["network.target" "headscale.target"]; - }; + systemd.services."tailscaled" = + if config.collinux.services.selfhost.headscale.enable + then { + wants = lib.mkForce ["network.target" "headscale.target"]; + after = lib.mkForce ["network.target" "headscale.target"]; + } + else { + wants = lib.mkForce ["network.target"]; + after = lib.mkForce ["network.target"]; + }; environment.systemPackages = [pkgs.tailscale]; } -- cgit v1.3.1