2025-06-10 14:28:46 -05:00
|
|
|
|
{
|
|
|
|
|
|
config,
|
|
|
|
|
|
lib,
|
|
|
|
|
|
overlays,
|
|
|
|
|
|
pkgs,
|
|
|
|
|
|
self,
|
|
|
|
|
|
...
|
|
|
|
|
|
}:
|
|
|
|
|
|
let
|
|
|
|
|
|
builderHosts =
|
|
|
|
|
|
if self != null then
|
|
|
|
|
|
(lib.attrNames (
|
|
|
|
|
|
lib.filterAttrs (_: v: v.config.greg.remote-builder.enable) self.nixosConfigurations
|
|
|
|
|
|
))
|
|
|
|
|
|
else
|
|
|
|
|
|
[ ];
|
|
|
|
|
|
in
|
|
|
|
|
|
{
|
|
|
|
|
|
imports = [
|
2025-06-10 15:05:09 -05:00
|
|
|
|
../modules/nix-conf.nix
|
2025-06-10 14:28:46 -05:00
|
|
|
|
];
|
|
|
|
|
|
|
|
|
|
|
|
console = {
|
|
|
|
|
|
font = "Lat2-Terminus16";
|
|
|
|
|
|
keyMap = "us";
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
environment.systemPackages = with pkgs; [
|
|
|
|
|
|
agenix
|
|
|
|
|
|
bitwarden-cli
|
|
|
|
|
|
bmon
|
|
|
|
|
|
btop
|
|
|
|
|
|
btrfs-progs
|
|
|
|
|
|
coreutils-full
|
|
|
|
|
|
diffutils
|
|
|
|
|
|
efibootmgr
|
|
|
|
|
|
findutils
|
|
|
|
|
|
file
|
2025-09-27 17:53:39 -05:00
|
|
|
|
gcc-tune
|
2025-06-10 14:28:46 -05:00
|
|
|
|
git
|
|
|
|
|
|
gnupatch
|
|
|
|
|
|
hms # My own home manager switcher
|
|
|
|
|
|
iperf
|
|
|
|
|
|
killall
|
|
|
|
|
|
nano
|
|
|
|
|
|
lshw
|
|
|
|
|
|
pciutils
|
|
|
|
|
|
psmisc
|
|
|
|
|
|
pwgen
|
|
|
|
|
|
unzip
|
|
|
|
|
|
usbutils
|
|
|
|
|
|
wget
|
|
|
|
|
|
xfsprogs
|
|
|
|
|
|
];
|
|
|
|
|
|
|
|
|
|
|
|
i18n.defaultLocale = "en_US.UTF-8";
|
|
|
|
|
|
|
|
|
|
|
|
nix = {
|
|
|
|
|
|
gc.dates = "weekly";
|
|
|
|
|
|
settings.auto-optimise-store = true;
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
nixpkgs.overlays = overlays;
|
|
|
|
|
|
|
|
|
|
|
|
# Network Manager pulls in too many deps
|
|
|
|
|
|
networking = {
|
|
|
|
|
|
search = [
|
|
|
|
|
|
"thehellings.lan"
|
|
|
|
|
|
"home"
|
|
|
|
|
|
];
|
|
|
|
|
|
networkmanager.enable = false;
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
programs = {
|
2025-12-02 15:05:46 -06:00
|
|
|
|
gnupg.agent.enable = true;
|
|
|
|
|
|
|
2025-06-10 14:28:46 -05:00
|
|
|
|
xonsh = {
|
|
|
|
|
|
enable = true;
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
ssh = {
|
|
|
|
|
|
extraConfig = builtins.concatStringsSep "\n" (
|
|
|
|
|
|
lib.map (x: ''
|
|
|
|
|
|
Host ${x}-builder
|
|
|
|
|
|
Hostname ${x}.home
|
|
|
|
|
|
User remote-builder-user
|
|
|
|
|
|
'') builderHosts
|
|
|
|
|
|
);
|
|
|
|
|
|
|
|
|
|
|
|
knownHosts = {
|
|
|
|
|
|
chronicles = {
|
|
|
|
|
|
extraHostNames = [
|
|
|
|
|
|
"chronicles.thehellings.lan"
|
|
|
|
|
|
"chronicles.home"
|
|
|
|
|
|
"nas"
|
|
|
|
|
|
"nas.thehellings.lan"
|
|
|
|
|
|
"nas.home"
|
|
|
|
|
|
];
|
|
|
|
|
|
publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEBecZUva9OnZuXLaBun6/1ITo5f9p0YMLPD+q0egLRS";
|
|
|
|
|
|
};
|
|
|
|
|
|
dns = {
|
|
|
|
|
|
extraHostNames = [
|
|
|
|
|
|
"dns"
|
|
|
|
|
|
"dns.me.ts"
|
|
|
|
|
|
"dns.home"
|
|
|
|
|
|
];
|
|
|
|
|
|
publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKRCXdhXWHEvw84V9JC5bAGovvj12DLVphcEnsTHDjxW";
|
|
|
|
|
|
};
|
|
|
|
|
|
"genesis" = {
|
|
|
|
|
|
extraHostNames = [
|
|
|
|
|
|
"genesis.shire-zebra.ts.net"
|
|
|
|
|
|
"genesis.home"
|
|
|
|
|
|
];
|
|
|
|
|
|
publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEI9jbTPmEWQ0F2bLYmnIOLmBnag1fkKxHRjz3X8lB/k";
|
|
|
|
|
|
};
|
|
|
|
|
|
"git" = {
|
|
|
|
|
|
extraHostNames = [
|
|
|
|
|
|
"git.home"
|
|
|
|
|
|
"git.thehellings.lan"
|
|
|
|
|
|
];
|
|
|
|
|
|
publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC7hesFWwlmSbWPJWUiF8fIppy5a83yXw84O0Ytz+Zyq";
|
|
|
|
|
|
};
|
|
|
|
|
|
hosea = {
|
|
|
|
|
|
extraHostNames = [
|
|
|
|
|
|
"hosea.home"
|
|
|
|
|
|
"hosea.thehellings.lan"
|
|
|
|
|
|
];
|
|
|
|
|
|
publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKLIwkTTXA56sUlUjEulXXZRvZy5H4a5ZwgKWLlpkQDz";
|
|
|
|
|
|
};
|
|
|
|
|
|
isaiah = {
|
|
|
|
|
|
extraHostNames = [
|
|
|
|
|
|
"isaiah.home"
|
|
|
|
|
|
"isaiah.thehellings.lan"
|
|
|
|
|
|
"isaiah-builder"
|
|
|
|
|
|
];
|
|
|
|
|
|
publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHleYKtfV4W1Z63Ysu9w5Rbglqlz4F92YcZoMkucoTNf";
|
|
|
|
|
|
};
|
|
|
|
|
|
jeremiah = {
|
|
|
|
|
|
extraHostNames = [
|
|
|
|
|
|
"jeremiah.home"
|
|
|
|
|
|
"jeremiah.thehellings.lan"
|
|
|
|
|
|
"jeremiah-builder"
|
|
|
|
|
|
];
|
|
|
|
|
|
publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOjQjXq9WYU2Ki27BR9WwJ4ZruS/lJXbjC1b0Q42Adi0";
|
|
|
|
|
|
};
|
2025-07-02 11:55:35 -05:00
|
|
|
|
zeke = {
|
2025-06-10 14:28:46 -05:00
|
|
|
|
extraHostNames = [
|
2025-07-02 11:55:35 -05:00
|
|
|
|
"zeke.home"
|
|
|
|
|
|
"zeke.thehellings.lan"
|
|
|
|
|
|
"zeke-builder"
|
2025-06-10 14:28:46 -05:00
|
|
|
|
];
|
|
|
|
|
|
publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOos0zQePsa+T6Z2dsKbPOvEdrBQ8a6mx3s7pN6ysCI0";
|
|
|
|
|
|
};
|
|
|
|
|
|
linode = {
|
|
|
|
|
|
extraHostNames = [
|
|
|
|
|
|
"linode.home"
|
|
|
|
|
|
"linode.thehellings.lan"
|
|
|
|
|
|
"thehellings.com"
|
|
|
|
|
|
];
|
|
|
|
|
|
publicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMv9Zud3kZOl86gtmkn+uj3D4kiXWDPtyUL02VVLNR4Q";
|
|
|
|
|
|
};
|
|
|
|
|
|
};
|
|
|
|
|
|
};
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
# Enable the OpenSSH daemon for remote control
|
|
|
|
|
|
services = {
|
2025-07-02 11:55:35 -05:00
|
|
|
|
locate.enable = true;
|
2025-06-10 14:28:46 -05:00
|
|
|
|
openssh = {
|
|
|
|
|
|
enable = true;
|
|
|
|
|
|
settings.X11Forwarding = true;
|
|
|
|
|
|
};
|
2025-11-20 23:08:52 -06:00
|
|
|
|
prometheus.exporters = {
|
|
|
|
|
|
node = {
|
|
|
|
|
|
enable = true;
|
2025-12-02 15:05:46 -06:00
|
|
|
|
enabledCollectors = [
|
|
|
|
|
|
"ethtool"
|
|
|
|
|
|
"logind"
|
|
|
|
|
|
"mountstats"
|
|
|
|
|
|
"systemd"
|
|
|
|
|
|
"tcpstat"
|
|
|
|
|
|
];
|
2025-11-20 23:08:52 -06:00
|
|
|
|
};
|
|
|
|
|
|
ping = {
|
|
|
|
|
|
enable = true;
|
|
|
|
|
|
settings = {
|
|
|
|
|
|
ping = {
|
|
|
|
|
|
interval = "10s";
|
|
|
|
|
|
timeout = "5s";
|
|
|
|
|
|
};
|
2025-12-02 15:05:46 -06:00
|
|
|
|
targets = [
|
|
|
|
|
|
"thehellings.com"
|
|
|
|
|
|
"genesis.shire-zebra.ts.net"
|
|
|
|
|
|
"www.google.com"
|
|
|
|
|
|
];
|
2025-11-20 23:08:52 -06:00
|
|
|
|
};
|
|
|
|
|
|
};
|
|
|
|
|
|
systemd.enable = true;
|
2025-11-19 22:43:10 -06:00
|
|
|
|
};
|
2025-06-10 14:28:46 -05:00
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
security.sudo.extraRules = [
|
|
|
|
|
|
{
|
|
|
|
|
|
users = [ "greg" ];
|
|
|
|
|
|
commands = [
|
|
|
|
|
|
{
|
|
|
|
|
|
command = "ALL";
|
|
|
|
|
|
options = [ "NOPASSWD" ];
|
|
|
|
|
|
}
|
|
|
|
|
|
];
|
|
|
|
|
|
}
|
|
|
|
|
|
];
|
|
|
|
|
|
|
|
|
|
|
|
# Define a user account. Don't forget to set a password with ‘passwd’.
|
|
|
|
|
|
users.users.greg = {
|
|
|
|
|
|
isNormalUser = true;
|
|
|
|
|
|
createHome = true;
|
|
|
|
|
|
extraGroups = [
|
|
|
|
|
|
"wheel"
|
|
|
|
|
|
]; # Enable ‘sudo’ for the user.
|
|
|
|
|
|
shell = config.programs.xonsh.package;
|
|
|
|
|
|
initialPassword = "password";
|
|
|
|
|
|
openssh.authorizedKeys.keys = lib.strings.splitString "\n" (
|
2025-06-10 21:48:12 -05:00
|
|
|
|
builtins.readFile ../home/ssh/authorized_keys
|
2025-06-10 14:28:46 -05:00
|
|
|
|
);
|
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
system.stateVersion = "24.11";
|
|
|
|
|
|
}
|