Merge branch 'main' of 10.42.4.3:greg/nixos-config

This commit is contained in:
Greg Hellings
2025-06-05 13:25:38 -05:00
73 changed files with 14236 additions and 426 deletions
+2
View File
@@ -5,3 +5,5 @@ result
# On home-manager only installs, this is built into the same dir
# where I am storing my repo
nix.conf
manifests/postgres/charts
manifests/external-secrets/charts
+13
View File
@@ -21,3 +21,16 @@ default:
job: "Evaluate for builds"
variables:
PARENT_PIPELINE_ID: $CI_PIPELINE_ID
"Build image":
stage: build
parallel:
matrix:
- IMG:
- img-bitwarden
script:
- nix run "nixpkgs#podman" login -u "$CI_REGISTRY_USER" -p "$CI_REGISTRY_PASSWORD" "$CI_REGISTRY"
- nix build ".#${IMG}"
- nix run "nixpkgs#podman" load -i result
- nix run "nixpkgs#podman" tag "localhost/${IMG}:latest" "$CI_REGISTRY/greg/ci-images/${IMG}:latest"
- nix run "nixpkgs#podman" push "$CI_REGISTRY/greg/ci-images/${IMG}:latest"
+7
View File
@@ -0,0 +1,7 @@
{
"languages": {
"YAML": {
"tab_size": 2
}
}
}
Generated
+31 -49
View File
@@ -93,11 +93,11 @@
]
},
"locked": {
"lastModified": 1747820204,
"narHash": "sha256-oY/mH8K1LOd+YbO58sw9ORtOdTxy3rR9lvTzOJKVUtA=",
"lastModified": 1747964474,
"narHash": "sha256-i73u8NLiqewGy0iIriH4XizatLnAojXxzrBqHJEz49E=",
"owner": "lnl7",
"repo": "nix-darwin",
"rev": "e2676937faf868111dcea6a4a9cf4b6549907c9d",
"rev": "93562b65cf68612a544779c9f77536f9dff01096",
"type": "github"
},
"original": {
@@ -165,22 +165,6 @@
}
},
"flake-compat_3": {
"flake": false,
"locked": {
"lastModified": 1696426674,
"narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "0f9255e01c2351cc7d116c072cb317785dd33b33",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_4": {
"flake": false,
"locked": {
"lastModified": 1733328505,
@@ -315,11 +299,11 @@
"systems": "systems_6"
},
"locked": {
"lastModified": 1710146030,
"narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=",
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
@@ -356,11 +340,11 @@
]
},
"locked": {
"lastModified": 1747834438,
"narHash": "sha256-AHJt79W8wADzur2htCx1U8FtEk4XjvrHb9/3iDfNedI=",
"lastModified": 1747955385,
"narHash": "sha256-AKoBFaEGN02tGvBlkwVIDOGXouHvrTTfOUcvBDGxkxQ=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "6c2eb1e24cd0e76d88bdd633ef4c50d6286586e0",
"rev": "a868570581f0dbdef7e33c8c9bb34b735dfcbacf",
"type": "github"
},
"original": {
@@ -441,11 +425,11 @@
},
"nix-hardware": {
"locked": {
"lastModified": 1747723695,
"narHash": "sha256-lSXzv33yv1O9r9Ai1MtYFDX3OKhWsZMn/5FFb4Rni/k=",
"lastModified": 1747900541,
"narHash": "sha256-dn64Pg9xLETjblwZs9Euu/SsjW80pd6lr5qSiyLY1pg=",
"owner": "nixos",
"repo": "nixos-hardware",
"rev": "6ac6ec6fcb410e15a60ef5ec94b8a2b35b5dd282",
"rev": "11f2d9ea49c3e964315215d6baa73a8d42672f06",
"type": "github"
},
"original": {
@@ -632,17 +616,17 @@
},
"nixpkgs_5": {
"locked": {
"lastModified": 1713805509,
"narHash": "sha256-YgSEan4CcrjivCNO5ZNzhg7/8ViLkZ4CB/GrGBVSudo=",
"lastModified": 1744868846,
"narHash": "sha256-5RJTdUHDmj12Qsv7XOhuospjAjATNiTMElplWnJE9Hs=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "1e1dc66fe68972a76679644a5577828b6a7e8be4",
"rev": "ebe4301cbd8f81c4f8d3244b3632338bbeb6d49c",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"rev": "ebe4301cbd8f81c4f8d3244b3632338bbeb6d49c",
"type": "github"
}
},
@@ -672,11 +656,11 @@
"systems": "systems_4"
},
"locked": {
"lastModified": 1747845951,
"narHash": "sha256-wTmZS30RIM6ELx9JFH5XSI5bjI4GzjtpodjHTSZBY3g=",
"lastModified": 1747945641,
"narHash": "sha256-Ts16c+kptbC3YDwPcB/NqXFVMHPNYKeFD7LkiawbWCU=",
"owner": "nix-community",
"repo": "nixvim",
"rev": "7e3a0f4e97c0906a276a860975888db96106b75e",
"rev": "46fd0b184cbc5f1bdc5a8325cb973fc54e49ab68",
"type": "github"
},
"original": {
@@ -693,11 +677,11 @@
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1747844583,
"narHash": "sha256-zbwqs9a2mh0Q7i3ZPjEGipbYHoTOHh31IRlYm97B1Ec=",
"lastModified": 1747973449,
"narHash": "sha256-e+DaBDI6xzd7KW+1u3jHhEzdF2Ajx5hP0bF2CFiS/F8=",
"owner": "nix-community",
"repo": "NUR",
"rev": "b9b668b91302e0ee12aaa0114c4a8ae8096871f3",
"rev": "e4fcae418dde38789f3f59ea07ad289a4b9bcffe",
"type": "github"
},
"original": {
@@ -917,28 +901,26 @@
},
"vsext": {
"inputs": {
"flake-compat": "flake-compat_3",
"flake-utils": "flake-utils_3",
"nixpkgs": "nixpkgs_5"
},
"locked": {
"lastModified": 1739984805,
"narHash": "sha256-cX3UzBy65e2CafN6a6WJr3aXQm4gvYD+Ym1epuY600k=",
"owner": "greg-hellings",
"lastModified": 1747965670,
"narHash": "sha256-O91kjsTL7xccgTQr2KITmGhhLTpX9zh+oRvvV8ScOrg=",
"owner": "nix-community",
"repo": "nix-vscode-extensions",
"rev": "f5671be9dec0adee120e30436d6450abea4ced42",
"rev": "d3099346fa5e9e33d0989a4e6afc3e8dedd25311",
"type": "github"
},
"original": {
"owner": "greg-hellings",
"ref": "fix-json",
"owner": "nix-community",
"repo": "nix-vscode-extensions",
"type": "github"
}
},
"wsl": {
"inputs": {
"flake-compat": "flake-compat_4",
"flake-compat": "flake-compat_3",
"nixpkgs": [
"nixunstable"
]
@@ -966,11 +948,11 @@
"patched-nixpkgs": "patched-nixpkgs"
},
"locked": {
"lastModified": 1747467107,
"narHash": "sha256-IIewGkpjoV6zSJNgxsL7p+wij/Q7RpDAlf0OVggK/ME=",
"lastModified": 1747989907,
"narHash": "sha256-91ddFyGUJNgyiJw1GYD04sbENGp9IuqtuUWHwbL/RVU=",
"owner": "HPsaucii",
"repo": "zed-editor-flake",
"rev": "50b08c64d1abed4318b8289ec3f62b64b4f34231",
"rev": "aa6440225e5aa225f242bb38235fba185665a616",
"type": "github"
},
"original": {
+1 -1
View File
@@ -45,7 +45,7 @@
};
nixunstable.url = "github:nixos/nixpkgs/nixos-unstable";
nurpkgs.url = "github:nix-community/NUR";
vsext.url = "github:greg-hellings/nix-vscode-extensions/fix-json";
vsext.url = "github:nix-community/nix-vscode-extensions";
wsl = {
url = "github:nix-community/NixOS-WSL";
inputs.nixpkgs.follows = "nixunstable";
+4 -8
View File
@@ -7,14 +7,10 @@ def bw_unlock():
current environment variables. Also returns the code for them."""
if "BW_SESSION" in ${...}:
return $BW_SESSION
result = $(bw unlock)
while "BW_SESSION" not in result:
result = $(bw unlock)
lines = result.split("\n")
l = [k for k in lines if 'BW_SESSION="' in k][0]
left, right = l.split("=", 1)
token = right[1:-1]
$BW_SESSION = token
result = !(bw unlock --raw)
while result.returncode != 0:
result = !(bw unlock --raw)
$BW_SESSION = result.output.strip()
return token
def vpn(con, bwname):
+13
View File
@@ -211,6 +211,10 @@
}
];
}
{
name = "PGAdmin4";
url = "http://pgadmin.kubernetes/";
}
{
name = "Password Hash";
url = "https://unix4lyfe.org/crypt/";
@@ -238,6 +242,15 @@
}
];
}
{
name = "Docs";
bookmarks = [
{
name = "CloudNative PG";
url = "https://cloudnative-pg.io/documentation/1.26/";
}
];
}
];
}
]
+2
View File
@@ -55,4 +55,6 @@
virtualisation = {
oci-containers.backend = "podman";
};
users.users.greg.extraGroups = [ "podman" ];
}
-75
View File
@@ -1,75 +0,0 @@
{
pkgs,
config,
lib,
...
}:
let
address = (builtins.elemAt config.networking.interfaces.ens18.ipv4.addresses 0).address;
root_ca = pkgs.writeText "root_ca.crt" (builtins.readFile ../../ca/root_ca.crt);
intermediate_ca = pkgs.writeText "intermediate_ca.crt" (
builtins.readFile ../../ca/intermediate_ca.crt
);
in
{
age.secrets.acme_password = {
file = ../../secrets/acme_password.age;
};
age.secrets.intermediate_ca_key = {
file = ../../secrets/ca/intermediate_key.age;
};
age.secrets.root_ca_key.file = ../../secrets/ca/root_key.age;
systemd.services.step-ca.serviceConfig.Environment = lib.mkForce [
"STEPDEBUG=1"
"HOME=%S/step-ca"
];
services.step-ca = {
inherit address;
enable = false;
intermediatePasswordFile = config.age.secrets.acme_password.path;
openFirewall = true;
port = 8443;
settings = {
root = root_ca;
federatedRoots = null;
cert = intermediate_ca;
key = config.age.secrets.intermediate_ca_key.path;
dnsNames = [
"10.42.1.5"
"acme.thehellings.lan"
];
logger.format = "text";
db = {
type = "badgerv2";
dataSource = "/var/lib/step-ca/db";
badgerFileLoadingMode = "";
};
authority.provisioners = [
{
type = "JWK";
name = "greg@thehellings.com";
key = {
use = "sig";
kty = "EC";
kid = "1GOpOttYLZtx7XiG79ZycbGcG4ptL0czfohK35SZOEI";
crv = "P-256";
alg = "ES256";
x = "YEWVj5CCoqWQXWqmL0UuORlFY9IEOLcg1jpG1o-wGx4";
y = "MEpqnJp60VV-SpFtb6m8U-VAYut7R_PKFm07xl7MjBk";
};
encryptedKey = "eyJhbGciOiJQQkVTMi1IUzI1NitBMTI4S1ciLCJjdHkiOiJqd2sranNvbiIsImVuYyI6IkEyNTZHQ00iLCJwMmMiOjYwMDAwMCwicDJzIjoieWdfb0lfbWgwbHhPRXdjUTBsd0FnUSJ9.ivdQUFEhs2U8PUBYr8AhQl3hHdb4spF4jvXgqY_hiVgpjB-z3Nn9Uw.u7vrNht_3WD1G97q.mbydlpAQxjtKLkOmmDOUczqscRDPqrUyoPJ1uqXcJDH3vs4KiYlrKRcFLjPy9sWzEL1iIrqjwf3U-3AAx1KNAg7frs2D__MGfOO-U5SdQDVJVAND7KpWOJGJVSb0xioCA6-8ldlP_REqu4ENmkkdw0_6Is2b0p7ZFKqke_fqOOs7osqFAfbMb_WzEWrACLn5A5-Teh2rpEgR-z9zipN6MSEqE6VIQ2BXuv70aHWhslNe1MK1OgTYm9CqA47EMYvQ7HQLPDZAbP56WK84yJLktoXMmnkaKeTtvER0dh4ufyjJHBhecnEranbR5rHc_jV8_qvyWhlqbCrOU_8bWrk.a9SH_q3GKIUsOUSRWkDxQg";
}
];
tls = {
cipherSuites = [
"TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
];
minVersion = 1.2;
maxVersion = 1.3;
renegotiation = false;
};
};
};
}
-17
View File
@@ -7,12 +7,10 @@
let
dashy_port = "8080";
speedtest_port = "19472";
uptime_kuma_port = "4000";
in
{
imports = [
# Include the results of the hardware scan.
./acme.nix
./hardware-configuration.nix
./home-assistant.nix
./networking.nix
@@ -25,7 +23,6 @@ in
"speed.home".target = "http://localhost:${speedtest_port}";
"speedtest.thehellings.lan".target = "http://localhost:${speedtest_port}";
"dashy.home".target = "http://localhost:${dashy_port}";
"uptime.home".target = "http://localhost:${uptime_kuma_port}";
};
};
@@ -36,14 +33,6 @@ in
useOSProber = true;
};
#boot.loader = {
# systemd-boot.enable = true;
# efi = {
# canTouchEfiVariables = true;
# efiSysMountPoint = "/boot/efi";
# };
#};
environment.systemPackages = with pkgs; [
awscli2
create_ssl
@@ -139,12 +128,6 @@ in
];
};
};
uptime-kuma = {
enable = true;
settings = {
PORT = uptime_kuma_port;
};
};
};
virtualisation.oci-containers.containers = {
+4 -2
View File
@@ -13,6 +13,8 @@
10.42.1.7 hosea hosea.thehellings.lan
10.42.1.8 jeremiah jeremiah.thehellings.lan minio-02.thehellings.lan
10.42.1.9 ivr ivr.thehellings.lan
10.42.1.10 jude jude.thehellings.lan
10.42.1.11 jude1 jude1.thehellings.lan
10.42.1.12 tv
# VMs
@@ -30,8 +32,8 @@
100.88.91.27 genesis.home smart.home zwave.home nixcache.home gitcache.home dashy.home uptime.home speed.home
100.91.131.66 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan
100.68.203.1 hosea.home hosea.shire-zebra.ts.net
100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net
100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net
100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes postgres.kubernetes
100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes
100.90.74.19 jude.home
100.115.57.8 linode.home
100.65.5.38 matrix.home matrix.shire-zebra.ts.net
+8
View File
@@ -101,6 +101,14 @@
hw-address = "c8:5e:a9:54:9e:c6"; # IVR laptop Wi-Fi
ip-address = "10.42.1.9";
}
{
hw-address = "c8:4b:d6:ca:20:8f";
ip-address = "10.42.1.10"; # Jude - but maybe through the monitor?
}
{
hw-address = "04:7c:16:d5:60:6f";
ip-address = "10.42.1.11"; # Jude - but straight in the motherboard
}
########################################
# VM servers #
+3 -32
View File
@@ -11,9 +11,7 @@
];
age.secrets = {
runner-reg.file = ../../secrets/gitlab/isaiah-podman-runner-reg.age;
docker-auth.file = ../../secrets/gitlab/docker-auth.age;
runner-qemu.file = ../../secrets/gitlab/isaiah-qemu-runner-reg.age;
runner-reg.file = ../../secrets/gitlab/kubernetes-k3s-local.age;
};
boot = {
@@ -83,31 +81,9 @@
concurrent = 5;
};
services = {
default = {
executor = "docker";
kubernetes = {
authenticationTokenConfigFile = config.age.secrets.runner-reg.path;
dockerImage = "gitlab.shire-zebra.ts.net:5000/greg/ci-images/fedora:latest";
dockerAllowedImages = [
"alpine:*"
"debian:*"
"docker:*"
"fedora:*"
"python:*"
"ubuntu:*"
"registry.gitlab.com/gitlab-org/*"
"registry.thehellings.com/*/*/*:*"
"gitlab.shire-zebra.ts.net:5000/*/*/*:*"
];
dockerAllowedServices = [
"docker:*"
"registry.thehellings.com/*/*/*:*"
"gitlab.shire-zebra.ts.net:5000/*/*/*:*"
];
dockerPrivileged = true;
dockerVolumes = [
"/certs/client"
"/cache"
];
executor = "shell";
};
};
};
@@ -118,11 +94,6 @@
};
};
systemd.services.gitlab-runner = {
after = [ "network-online.target" ];
requires = [ "network-online.target" ];
};
virtualisation = {
libvirtd = {
enable = true;
+1 -1
View File
@@ -106,7 +106,7 @@ in
#####################################################################################
#################### Virtualbox Runner ##############################################
#####################################################################################
age.secrets.runner-reg.file = ../../secrets/gitlab/jeremiah-runner-reg.age;
age.secrets.runner-reg.file = ../../secrets/gitlab/nixos-qemu-shell.age;
services = {
gitlab-runner = {
+34 -2
View File
@@ -93,7 +93,32 @@
hostName = "jude";
networkmanager.enable = lib.mkForce true;
enableIPv6 = false;
interfaces.enp12s0.useDHCP = true;
useDHCP = false;
interfaces = {
# This seems to be direct mother board interface
enp12s0.useDHCP = true;
#enp12s0.ipv4.addresses = [
#{
#address = "10.42.1.11";
#prefixLength = 16;
#}
#];
# This seems to be the one that comes through the monitor hookup
enp14s0u1u2.ipv4.addresses = [
{
address = "10.42.1.10";
prefixLength = 16;
}
];
};
defaultGateway = {
address = "10.42.1.1";
interface = "enp14s0u1u2";
};
nameservers = [
"10.42.1.5"
"10.42.1.1"
];
firewall = {
enable = false;
allowedTCPPorts = [ 21000 ];
@@ -118,7 +143,14 @@
# Let's do a sound thing
services = {
k3s.extraFlags = [ "--tls-san 10.42.0.6" ];
k3s.extraFlags =
let
ip = (builtins.head config.networking.interfaces.enp14s0u1u2.ipv4.addresses).address;
in
[
"--tls-san ${ip}"
#"--bind-address ${ip}"
];
pipewire = {
enable = true;
alsa.enable = true;
+49 -18
View File
@@ -6,6 +6,10 @@
}:
let
environmentVariables = {
EFI_DIR = "${pkgs.OVMF.fd}/FV/";
STORAGE_URL = "s3.thehellings.lan:9000";
};
passthru = [
"1002:164e" # Raphael - embedded GPU
"1002:1640" # Rembrandt - Audio
@@ -14,9 +18,46 @@ let
];
in
{
greg.vmdev.enable = true;
specialisation = {
vbox.configuration = {
age.secrets.runner-reg.file = ../../secrets/gitlab/isaiah-vbox-runner-reg.age;
greg = {
podman.enable = lib.mkForce false;
vmdev.enable = lib.mkForce false;
};
users.extraGroups.vboxusers.members = [ "greg" ];
virtualisation = {
virtualbox.host = {
enable = true;
enableExtensionPack = true;
};
};
services.gitlab-runner.services = lib.mkForce {
vbox = {
inherit environmentVariables;
authenticationTokenConfigFile = config.age.secrets.vbox.path;
executor = "shell";
limit = 5;
};
};
systemd.services.gitlab-runner = {
serviceConfig = {
DevicePolicy = lib.mkForce "auto";
User = "root";
DynamicUser = lib.mkForce false;
};
};
};
};
age.secrets = {
qemu.file = ../../secrets/gitlab/nixos-qemu-shell.age;
vbox.file = ../../secrets/gitlab/nixos-vbox-shell.age;
};
# These options enable sharing of the GPU with the VM
boot = {
@@ -39,33 +80,23 @@ in
("vfio-pci.ids=" + (lib.concatStringsSep "," passthru))
];
};
greg.vmdev.enable = true;
hardware.graphics.enable = true;
services.gitlab-runner = {
enable = true;
settings.concurrent = 5;
services.vbox = {
services.qemu = {
inherit environmentVariables;
executor = "shell";
limit = 5;
authenticationTokenConfigFile = config.age.secrets.runner-reg.path;
environmentVariables = {
EFI_DIR = "${pkgs.OVMF.fd}/FV/";
};
authenticationTokenConfigFile = config.age.secrets.qemu.path;
};
};
systemd.services = {
gitlab-runner = {
conflicts = [ "libvirtd.service" ];
preStart = builtins.concatStringsSep "\n" [
"${pkgs.kmod}/bin/modprobe vboxnetflt vboxdrv"
"${pkgs.kmod}/bin/modprobe vboxnetadp"
];
postStop = "${pkgs.kmod}/bin/rmmod vboxnetflt vboxnetadp vboxdrv";
wantedBy = pkgs.lib.mkForce [ ];
serviceConfig.User = "root";
};
"libvirt-nosleep@" = {
description = "Prevent sleep while %i is running";
serviceConfig = {
+10 -2
View File
@@ -14,7 +14,6 @@ in
"${domain}" = {
enableACME = true;
forceSSL = true;
# This is needed so that servers contacting hellings.com can find
# the actual application server at matrix.thehellings.com
locations."= /.well-known/matrix/server".extraConfig =
@@ -51,11 +50,20 @@ in
enableACME = true;
forceSSL = true;
extraConfig = ''
error_log /var/log/nginx/debug.log debug;
'';
# Not the appropriate place for the chat client
locations =
(builtins.listToAttrs (
builtins.map
(val: lib.nameValuePair "/_${val}" { proxyPass = "http://matrix.shire-zebra.ts.net:8448"; })
(
val:
lib.nameValuePair "/_${val}" {
proxyPass = "http://matrix.kubernetes";
}
)
[
"matrix"
"synapse"
+9 -5
View File
@@ -2,11 +2,11 @@
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{ config, pkgs, ... }:
{ pkgs, ... }:
{
imports =
[ # Include the results of the hardware scan.
imports = [
# Include the results of the hardware scan.
./hardware-configuration.nix
];
@@ -16,7 +16,9 @@
efi.canTouchEfiVariables = true;
};
environment.systemPackages = with pkgs; [
environment.systemPackages =
with pkgs;
[
];
greg = {
@@ -43,6 +45,8 @@
nameservers = [ "10.42.1.5" ];
};
services.qemuGuest.enable = true;
system.stateVersion = "24.11"; # Did you read the comment?
# Define a user account. Don't forget to set a password with passwd.
@@ -50,6 +54,6 @@
isNormalUser = true;
description = "Greg Hellings";
extraGroups = [ "wheel" ];
packages = with pkgs; [];
packages = with pkgs; [ ];
};
}
@@ -1,27 +1,42 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
lib,
modulesPath,
...
}:
{
imports =
[ (modulesPath + "/profiles/qemu-guest.nix")
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [ "uhci_hcd" "ehci_pci" "ahci" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
boot.initrd.availableKernelModules = [
"uhci_hcd"
"ehci_pci"
"ahci"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb";
fileSystems."/" = {
device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb";
fsType = "ext4";
};
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/7115-EFA6";
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/7115-EFA6";
fsType = "vfat";
options = [ "fmask=0077" "dmask=0077" ];
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
+10 -5
View File
@@ -15,8 +15,8 @@ let
containerIp = "192.168.200.2";
in
{
imports =
[ # Include the results of the hardware scan.
imports = [
# Include the results of the hardware scan.
./hardware-configuration.nix
];
@@ -36,6 +36,9 @@ in
gitlab-jws = cfg "jws";
gitlab-key = cfg "key";
gitlab-cert = cfg "cert";
gitlab-salt = cfg "salt";
gitlab-primary-key = cfg "primary-key";
gitlab-deterministic-key = cfg "deterministic-key";
minio_access_key_id = {
file = ../../secrets/minio_access_key_id.age;
@@ -79,7 +82,6 @@ in
tailscale.enable = true;
};
networking = {
hostName = "vm-gitlab"; # Define your hostname.
firewall.allowedTCPPorts = [
@@ -134,10 +136,13 @@ in
externalPort = 443;
};
secrets = {
secretFile = config.age.secrets.gitlab-secret.path;
otpFile = config.age.secrets.gitlab-otp.path;
activeRecordDeterministicKeyFile = config.age.secrets.gitlab-deterministic-key.path;
activeRecordPrimaryKeyFile = config.age.secrets.gitlab-primary-key.path;
activeRecordSaltFile = config.age.secrets.gitlab-salt.path;
dbFile = config.age.secrets.gitlab-db.path;
jwsFile = config.age.secrets.gitlab-jws.path;
otpFile = config.age.secrets.gitlab-otp.path;
secretFile = config.age.secrets.gitlab-secret.path;
};
extraConfig = {
+24 -9
View File
@@ -1,18 +1,30 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
lib,
modulesPath,
...
}:
{
imports =
[ (modulesPath + "/profiles/qemu-guest.nix")
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
# Bootloader.
boot = {
extraModulePackages = [ ];
initrd = {
availableKernelModules = [ "uhci_hcd" "ehci_pci" "ahci" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
availableKernelModules = [
"uhci_hcd"
"ehci_pci"
"ahci"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
kernelModules = [ ];
};
loader = {
@@ -21,15 +33,18 @@
};
};
fileSystems."/" =
{ device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb";
fileSystems."/" = {
device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb";
fsType = "ext4";
};
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/7115-EFA6";
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/7115-EFA6";
fsType = "vfat";
options = [ "fmask=0077" "dmask=0077" ];
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
+24 -9
View File
@@ -1,27 +1,42 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
lib,
modulesPath,
...
}:
{
imports =
[ (modulesPath + "/profiles/qemu-guest.nix")
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [ "uhci_hcd" "ehci_pci" "ahci" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
boot.initrd.availableKernelModules = [
"uhci_hcd"
"ehci_pci"
"ahci"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb";
fileSystems."/" = {
device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb";
fsType = "ext4";
};
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/7115-EFA6";
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/7115-EFA6";
fsType = "vfat";
options = [ "fmask=0077" "dmask=0077" ];
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
+33
View File
@@ -0,0 +1,33 @@
Stands up my personal infrastructure in a Kubernetes environment.
# First Thing First
In order to properly get things up and going, you will need to create a secret to allow
the external secrets to log into BitWarden Password Manager. For obvious reasont this
cannot be safely added to this repository. As such, it is suggested you create this
manually.
```bash
kubectl create namespace bitwarden
kubectl create secret generic bitwarden-cli --namespace bitwarden --from-literal=BW_USERNAME=my_username --from-literal=BW_PASSWORD=my_password
# Alternative to the preceding line if you don't want the data in your shell history
kubectl create secret generic bitwarden-cli --namespace bitwarden --from-file=./BW_USERNAME.txt --from-file=./BW_PASSWORD.txt
# And yet an entirely other option, if I'm logged into my own systems
sudo cat /run/agenix/bw_secret | kubectl apply -f -
```
# Now Configure Cluster Services
To apply this you need to install kubectl, kustomize, and helm. It can then by applied
by simply invoking the command:
```bash
# Working directory is assumed to be the manifests directory
./apply.sh
```
Once the basic cluster stuff is setup, you can just apply this directory with
```bash
kubectl apply -k .
```
+14
View File
@@ -0,0 +1,14 @@
#!/usr/bin/env bash
# Get the directory where the script is located
SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )"
# Change to the script directory
cd "$SCRIPT_DIR"
kubectl apply -k namespaces
kubectl apply -f helm/flux.yaml
sleep 5
kubectl apply -k helm
sleep 5
kubectl apply .
+45
View File
@@ -0,0 +1,45 @@
---
apiVersion: external-secrets.io/v1
kind: ClusterSecretStore
metadata:
name: bitwarden-login
spec:
provider:
webhook:
url: "http://bitwarden-cli.bitwarden.svc.cluster.local:8087/object/item/{{ .remoteRef.key }}"
headers:
Content-Type: application/json
result:
jsonPath: "$.data.login.{{ .remoteRef.property }}"
---
apiVersion: external-secrets.io/v1
kind: ClusterSecretStore
metadata:
name: bitwarden-fields
spec:
provider:
webhook:
url: "http://bitwarden-cli.bitwarden.svc.cluster.local:8087/object/item/{{ .remoteRef.key }}"
result:
jsonPath: '$.data.fields[?@.name=="{{ .remoteRef.property }}"].value'
---
apiVersion: external-secrets.io/v1
kind: ClusterSecretStore
metadata:
name: bitwarden-notes
spec:
provider:
webhook:
url: "http://bitwarden-cli.bitwarden.svc.cluster.local:8087/object/item/{{ .remoteRef.key }}"
result:
jsonPath: "$.data.notes"
---
apiVersion: external-secrets.io/v1
kind: ClusterSecretStore
metadata:
name: bitwarden-attachments
spec:
provider:
webhook:
url: "http://bitwarden-cli.bitwarden.svc.cluster.local:8087/object/attachment/{{ .remoteRef.property }}?itemid={{ .remoteRef.key }}"
result: {}
+70
View File
@@ -0,0 +1,70 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: bitwarden-cli
labels:
app.kubernetes.io/instance: bitwarden-cli
app.kubernetes.io/name: bitwarden-cli
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app.kubernetes.io/name: bitwarden-cli
app.kubernetes.io/instance: bitwarden-cli
template:
metadata:
labels:
app.kubernetes.io/name: bitwarden-cli
app.kubernetes.io/instance: bitwarden-cli
spec:
containers:
- name: bitwarden-cli
image: "registry.thehellings.com/greg/nixos-config/img-bitwarden:latest"
imagePullPolicy: Always
env:
- name: BW_CLIENTID
valueFrom:
secretKeyRef:
name: bitwarden-cli
key: BW_CLIENTID
- name: BW_CLIENTSECRET
valueFrom:
secretKeyRef:
name: bitwarden-cli
key: BW_CLIENTSECRET
- name: BW_PASSWORD
valueFrom:
secretKeyRef:
name: bitwarden-cli
key: BW_PASSWORD
ports:
- name: http
containerPort: 8087
protocol: TCP
livenessProbe:
exec:
command:
- wget
- -q
- http://127.0.0.1:8087/sync?force=true
- --post-data=''
initialDelaySeconds: 20
failureThreshold: 3
timeoutSeconds: 10
periodSeconds: 120
readinessProbe:
tcpSocket:
port: 8087
initialDelaySeconds: 20
failureThreshold: 3
timeoutSeconds: 1
periodSeconds: 10
startupProbe:
tcpSocket:
port: 8087
initialDelaySeconds: 10
failureThreshold: 30
timeoutSeconds: 1
periodSeconds: 5
+6
View File
@@ -0,0 +1,6 @@
namespace: bitwarden
resources:
- deployment.yaml
- service.yaml
- cluster-stores.yaml
+18
View File
@@ -0,0 +1,18 @@
apiVersion: v1
kind: Service
metadata:
name: bitwarden-cli
labels:
app.kubernetes.io/instance: bitwarden-cli
app.kubernetes.io/name: bitwarden-cli
annotations:
spec:
type: ClusterIP
ports:
- port: 8087
targetPort: http
protocol: TCP
name: http
selector:
app.kubernetes.io/name: bitwarden-cli
app.kubernetes.io/instance: bitwarden-cli
+39
View File
@@ -0,0 +1,39 @@
apiVersion: traefik.io/v1alpha1
kind: MiddlewareTCP
metadata:
name: local-hosts-only
namespace: db
spec:
ipAllowList:
sourceRange:
- 127.0.0.1/32 # Localhost, obviously
- 10.42.0.0/16 # My internal net
- 10.211.0.0/16 # Kubernetes IPs
# Tailscale hosts
- 100.119.228.115 # chronicles
- 100.88.91.27 # dns?
- 100.80.99.48 # exodus
- 100.88.91.27 # genesis
- 100.91.131.66 # gitlab
- 100.68.203.1 # hosea
- 100.84.183.79 # isaiah
- 100.102.186.39 # jeremiah
- 100.90.74.19 # jude
- 100.115.57.8 # linode
- 100.65.5.38 # matrix
- 100.127.55.22 # jellyfin
---
apiVersion: traefik.io/v1alpha1
kind: IngressRouteTCP
metadata:
name: ingress-route-postgres
namespace: db
spec:
entryPoints:
- postgres
routes:
- match: HostSNI(`*`)
priority: 10
services:
- name: postgres-rw
port: 5432
+8
View File
@@ -0,0 +1,8 @@
namespace: db
resources:
- postgres-cluster.yaml
- postgres-gitlab.yaml
- postgres-pgadmin.yaml
- postgres-matrix.yaml
- ingress.yaml
+58
View File
@@ -0,0 +1,58 @@
apiVersion: postgresql.cnpg.io/v1
kind: Cluster
metadata:
name: postgres
spec:
instances: 3
storage:
size: 10Gi
primaryUpdateStrategy: unsupervised
managed:
roles:
- name: gitlab
ensure: present
comment: Gitlab user
login: true
superuser: false
passwordSecret:
name: postgres-user-gitlab
- name: pgadmin
ensure: present
comment: PG Admin user
login: true
superuser: true
passwordSecret:
name: postgres-user-pgadmin
- name: matrix
ensure: present
comment: Matrix DB user
login: true
superuser: false
passwordSecret:
name: postgres-user-matrix
backup:
retentionPolicy: "30d"
barmanObjectStore:
destinationPath: "s3://k3sbackup/postgres"
endpointURL: "http://s3.thehellings.lan:9000/"
s3Credentials:
accessKeyId:
name: k3sbackup
key: username
secretAccessKey:
name: k3sbackup
key: password
wal:
compression: gzip
---
apiVersion: postgresql.cnpg.io/v1
kind: ScheduledBackup
metadata:
name: postgres-backup
spec:
immediate: true # Create one when this is added to the cluster
schedule: "0 0 0 * * *" # Midnight, nightly
backupOwnerReference: self
cluster:
name: postgres
+9
View File
@@ -0,0 +1,9 @@
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: database-gitlab
spec:
name: gitlab
owner: gitlab
cluster:
name: postgres
+9
View File
@@ -0,0 +1,9 @@
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: database-matrix
spec:
name: matrix
owner: matrix
cluster:
name: postgres
+107
View File
@@ -0,0 +1,107 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: config-pgadmin
data:
servers.json: |
{
"Servers": {
"1": {
"Name": "Postgres",
"Group": "Servers",
"Port": 5432,
"Username": "pgadmin",
"Host": "postgres-rw",
"SSLMode": "allow",
"MaintenanceDB": "postgres"
}
}
}
---
apiVersion: v1
kind: Service
metadata:
name: service-pgadmin
spec:
ports:
- protocol: TCP
port: 80
targetPort: http
selector:
app: pgadmin
type: ClusterIP
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: pgadmin
spec:
serviceName: service-pgadmin
podManagementPolicy: Parallel
replicas: 1
updateStrategy:
type: RollingUpdate
selector:
matchLabels:
app: pgadmin
template:
metadata:
labels:
app: pgadmin
spec:
terminationGracePeriodSeconds: 10
containers:
- name: pgadmin
image: "dpage/pgadmin4:9.3"
imagePullPolicy: Always
env:
- name: PGADMIN_DEFAULT_EMAIL
value: greg@thehellings.com
- name: PGADMIN_DEFAULT_PASSWORD
valueFrom:
secretKeyRef:
name: postgres-user-pgadmin
key: password
- name: PGADMIN_SERVER_JSON_FILE
value: /config-pgadmin-vol/servers.json
ports:
- name: http
containerPort: 80
protocol: TCP
volumeMounts:
- name: config-pgadmin-vol
mountPath: /config-pgadmin-vol/
readOnly: true
- name: pgadmin-data
mountPath: /var/lib/pgadmin
volumes:
- name: config-pgadmin-vol
configMap:
name: config-pgadmin
volumeClaimTemplates:
- metadata:
name: pgadmin-data
spec:
accessModes: ["ReadWriteOnce"]
resources:
requests:
storage: 3Gi
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: ingress-pgadmin
annotations:
ingressClassName: traefik
spec:
rules:
- host: pgadmin.kubernetes
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: service-pgadmin
port:
number: 80
+33
View File
@@ -0,0 +1,33 @@
apiVersion: v1
kind: Namespace
metadata:
name: cnpg-system
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: cloudnative-pg
namespace: cnpg-system
spec:
interval: "24h"
url: "https://cloudnative-pg.github.io/charts/"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cnpg
namespace: cnpg-system
spec:
interval: 10m
chart:
spec:
chart: cloudnative-pg
version: "0.23.2"
sourceRef:
kind: HelmRepository
name: cloudnative-pg
interval: "1h"
values:
crds:
create: true
includeCRDs: true
+33
View File
@@ -0,0 +1,33 @@
apiVersion: v1
kind: Namespace
metadata:
name: external-secrets
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: external-secrets
namespace: external-secrets
spec:
interval: "24h"
url: "https://charts.external-secrets.io/"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: external-secrets
namespace: external-secrets
spec:
interval: 10m
chart:
spec:
chart: external-secrets
version: "0.17.0"
sourceRef:
kind: HelmRepository
name: external-secrets
interval: "1h"
values:
crds:
create: true
includeCRDs: true
File diff suppressed because it is too large Load Diff
+5
View File
@@ -0,0 +1,5 @@
resources:
- flux.yaml
- traefik.yaml
- external-secrets.yaml
- cloudnative-pg.yaml
+22
View File
@@ -0,0 +1,22 @@
apiVersion: "helm.cattle.io/v1"
kind: "HelmChartConfig"
metadata:
name: "traefik"
namespace: "kube-system"
spec:
valuesContent: |-
additionalArguments:
- "--entryPoints.postgres.address=:5432/tcp"
- "--api.dashboard=true"
- "--api.insecure=true"
- "--log.level=DEBUG"
ports:
postgres:
expose:
default: true
port: 5432
exposedPort: 5432
protocol: TCP
traefik:
expose:
default: true
+7
View File
@@ -0,0 +1,7 @@
resources:
- namespaces
- helm
- bitwarden
- secrets
- databases
- matrix
+189
View File
@@ -0,0 +1,189 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: dendrite-config
spec:
data:
- &secret
secretKey: username
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef: &remoteRef
key: 36d1046b-727e-4e09-a391-b2e90171d3d0
property: username
- <<: *secret
secretKey: password
remoteRef:
<<: *remoteRef
property: password
- secretKey: matrix_pem
sourceRef:
storeRef:
name: bitwarden-notes
kind: ClusterSecretStore
remoteRef:
key: 6de3500c-7c6e-4419-b4f5-b2ea0018ff28
target:
name: dendrite-config
deletionPolicy: Delete
template:
engineVersion: v2
data:
matrix.pem: "{{ .matrix_pem }}"
dendrite.yaml: |
version: 2
global:
server_name: thehellings.com
key_id: ed25519:auto
private_key: /etc/dendrite/matrix.pem
database:
connection_string: "postgres://{{ .username | urlquery }}:{{ .password | urlquery }}@postgres-rw.db.svc.cluster.local/matrix?sslmode=disable"
max_open_conns: 90
max_idle_conns: 2
conn_max_lifetime: -1
well_known_server_name: "http://matrix.thehellings.com"
well_known_client_name: "http://matrix.thehellings.com"
well_known_sliding_sync_proxy: ""
disable_federation: false
presence:
enable_inbound: false
enable_outbound: false
trusted_third_party_id_servers:
- matrix.org
- vector.im
jetstream:
storage_path: /var/dendrite
addresses: []
topic_prefix: Dendrite
in_memory: false
disable_tls_validation: true
credentials_path: ""
metrics:
enabled: false
basic_auth:
username: metrics
password: metrics
sentry:
enabled: false
dsn: ""
environment: ""
dns_cache:
enabled: false
cache_size: 256
cache_lifetime: 5m0s
server_notices:
enabled: true
local_part: _server
display_name: Server Alert
avatar_url: ""
room_name: Server Alert
report_stats:
enabled: false
endpoint: https://panopticon.matrix.org/push
cache:
max_size_estimated: 1073741824
max_age: 1h0m0s
app_service_api:
disable_tls_validation: false
legacy_auth: false
legacy_paths: false
config_files: []
client_api:
registration_disabled: true
registration_requires_token: false
registration_shared_secret: ""
guests_disabled: false
enable_registration_captcha: false
recaptcha_api_js_url: ""
recaptcha_sitekey_class: ""
recaptcha_form_field: ""
recaptcha_public_key: ""
recaptcha_private_key: ""
recaptcha_bypass_secret: ""
recaptcha_siteverify_api: ""
turn:
turn_user_lifetime: ""
turn_uris: []
turn_shared_secret: ""
turn_username: ""
turn_password: ""
rate_limiting:
enabled: true
threshold: 5
cooloff_ms: 500
exempt_user_ids: []
federation_api:
send_max_retries: 16
enable_relays: false
p2p_retries_until_assumed_offline: 1
disable_tls_validation: false
disable_http_keepalives: false
key_perspectives:
- server_name: matrix.org
keys:
- key_id: ed25519:auto
public_key: Noi6WqcDj0QmPxCNQqgezwTlBKrfqehY1u2FyWP9uYw
- key_id: ed25519:a_RXGa
public_key: l8Hft5qXKn1vfHrg3p4+W8gELQVo8N13JkluMfmn2sQ
prefer_direct_fetch: false
deny_networks:
- 127.0.0.1/8
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
- 100.64.0.0/10
- 169.254.0.0/16
- ::1/128
- fe80::/64
- fc00::/7
allow_networks:
- 0.0.0.0/0
key_server: {}
media_api:
base_path: /var/dendrite/media
max_file_size_bytes: 10485760
dynamic_thumbnails: false
max_thumbnail_generators: 10
thumbnail_sizes:
- width: 32
height: 32
method: crop
- width: 96
height: 96
method: crop
- width: 640
height: 480
method: scale
room_server:
default_room_version: "10"
sync_api:
real_ip_header: ""
search:
enabled: false
index_path: /var/dendrite/searchindex
in_memory: false
language: en
user_api:
bcrypt_cost: 10
openid_token_lifetime_ms: 3600000
push_gateway_disable_tls_validation: false
auto_join_rooms: []
worker_count: 8
relay_api: {}
mscs:
mscs: []
tracing:
enabled: false
jaeger:
serviceName: ""
disabled: false
rpc_metrics: false
traceid_128bit: false
tags: []
sampler: null
reporter: null
headers: null
baggage_restrictions: null
throttler: null
+29
View File
@@ -0,0 +1,29 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: dendrite
labels:
app: dendrite
spec:
replicas: 1
selector:
matchLabels:
app: dendrite
template:
metadata:
labels:
app: dendrite
spec:
containers:
- name: dendrite
image: ghcr.io/element-hq/dendrite-monolith:latest
ports:
- containerPort: 8008
name: http
volumeMounts:
- name: config-volume
mountPath: /etc/dendrite
volumes:
- name: config-volume
secret:
secretName: dendrite-config
+21
View File
@@ -0,0 +1,21 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: dendrite-ingress
annotations:
ingressClassName: traefik
spec:
rules:
- &host
host: matrix.kubernetes
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: dendrite
port:
number: 8008
- <<: *host
host: matrix.thehellings.com
+7
View File
@@ -0,0 +1,7 @@
namespace: matrix
resources:
- dendrite-config.yaml
- deployment.yaml
- service.yaml
- ingress.yaml
+14
View File
@@ -0,0 +1,14 @@
apiVersion: v1
kind: Service
metadata:
name: dendrite
labels:
app: dendrite
spec:
selector:
app: dendrite
ports:
- port: 8008
targetPort: http
protocol: TCP
type: ClusterIP
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: bitwarden
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: db
+4
View File
@@ -0,0 +1,4 @@
resources:
- bitwarden.yaml
- db.yaml
- matrix.yaml
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: matrix
+11
View File
@@ -0,0 +1,11 @@
#!/usr/bin/env bash
# Get the directory where the script is located
SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )"
# Change to the script directory
cd "$SCRIPT_DIR"
kubectl delete -k .
kustomize build postgres --enable-helm | kubectl delete -f -
kubectl delete -k namespaces
+33
View File
@@ -0,0 +1,33 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: k3sbackup
namespace: db
spec:
target:
name: k3sbackup
deletionPolicy: Delete
template:
type: Opaque
data:
username: |-
{{ .username }}
password: |-
{{ .password }}
data:
- secretKey: username
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 685b29c6-9264-4e60-ba4a-b2ea005a5d7b
property: username
- secretKey: password
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 685b29c6-9264-4e60-ba4a-b2ea005a5d7b
property: password
+5
View File
@@ -0,0 +1,5 @@
resources:
- postgres-user-gitlab.yaml
- postgres-user-pgadmin.yaml
- postgres-user-matrix.yaml
- k3sbackup.yaml
@@ -0,0 +1,33 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: postgres-user-gitlab
namespace: db
spec:
target:
name: postgres-user-gitlab
deletionPolicy: Delete
template:
type: Opaque
data:
username: |-
{{ .username }}
password: |-
{{ .password }}
data:
- secretKey: username
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57
property: username
- secretKey: password
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57
property: password
@@ -0,0 +1,33 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: postgres-user-matrix
namespace: db
spec:
target:
name: postgres-user-matrix
deletionPolicy: Delete
template:
type: Opaque
data:
username: |-
{{ .username }}
password: |-
{{ .password }}
data:
- secretKey: username
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 36d1046b-727e-4e09-a391-b2e90171d3d0
property: username
- secretKey: password
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 36d1046b-727e-4e09-a391-b2e90171d3d0
property: password
@@ -0,0 +1,33 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: postgres-user-pgadmin
namespace: db
spec:
target:
name: postgres-user-pgadmin
deletionPolicy: Delete
template:
type: Opaque
data:
username: |-
{{ .username }}
password: |-
{{ .password }}
data:
- secretKey: username
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: f333d637-1667-499d-b9a0-b2e9012bd8b7
property: username
- secretKey: password
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: f333d637-1667-499d-b9a0-b2e9012bd8b7
property: password
+23 -2
View File
@@ -1,4 +1,9 @@
{ config, lib, ... }:
{
config,
lib,
pkgs,
...
}:
let
cfg = config.greg.kubernetes;
in
@@ -15,11 +20,26 @@ in
};
config = lib.mkIf cfg.enable {
age.secrets.kubernetesToken.file = ../../secrets/kubernetes/kubernetesToken.age;
age.secrets = {
bw_secret.file = ../../secrets/kubernetes/bw_secret.age;
dendrite_key.file = ../../secrets/dendrite_key.age;
kubernetesToken.file = ../../secrets/kubernetes/kubernetesToken.age;
};
environment.systemPackages = [
pkgs.fluxcd
pkgs.kubectl-cnpg
pkgs.kubernetes-helm
pkgs.kustomize
pkgs.k9s
];
networking.firewall = {
allowedTCPPorts =
[
80
443
5432
6443
]
++ (
@@ -43,6 +63,7 @@ in
"--service-cidr=10.221.0.0/16"
"--write-kubeconfig-mode 0640"
"--write-kubeconfig-group kubeconfig"
"--resolv-conf=/etc/resolv.conf"
"--tls-san ${config.networking.hostName}.home"
"--tls-san ${config.networking.hostName}.thehellings.lan"
"--tls-san ${config.networking.hostName}.shire-zebra.ts.net"
-28
View File
@@ -58,36 +58,8 @@ with lib;
};
};
};
virtualbox.host = {
enable = true;
enableExtensionPack = true;
};
};
# Configuration for vbox user performance
users.extraGroups.vboxusers.members = [ cfg.user ];
boot.extraModprobeConfig = "options kvm_${cfg.system} nested=1";
# Configure the services more
systemd.services = {
libvirtd = {
preStart = "${pkgs.kmod}/bin/modprobe kvm_${cfg.system}";
postStop = "${pkgs.kmod}/bin/rmmod kvm_${cfg.system} kvm";
conflicts = [ "vbox.service" ];
#overrideStrategy = "asDropin";
};
vbox = {
preStart = "${pkgs.kmod}/bin/modprobe vboxdrv vboxnetadp vboxnetflt";
postStop = "${pkgs.kmod}/bin/rmmod vboxnetadp vboxnetflt vboxdrv";
script = "echo Started";
conflicts = [ "libvirtd.service" ];
unitConfig = {
Type = "oneshot";
RemainAfterExit = "yes";
};
};
};
};
}
+1
View File
@@ -14,6 +14,7 @@ in
hms = c ./hms { };
inject-darwin = c ./inject-darwin.nix { };
inject = c ./inject.nix { };
img-bitwarden = c ./img-bitwarden.nix { };
qemu-hook = c ./qemu-hook.nix { };
setup-ssh = c ./setup-ssh { };
upgrade-pg-cluster = c ./upgrade-pg-cluster.nix { };
+44
View File
@@ -0,0 +1,44 @@
{
bitwarden-cli,
cacert,
dockerTools,
lib,
writeShellApplication,
...
}:
dockerTools.buildLayeredImage {
name = "img-bitwarden";
tag = "latest";
contents = [
dockerTools.binSh
dockerTools.caCertificates
];
config = {
Cmd = [
(lib.getExe (writeShellApplication {
name = "bitwarden-cli-entrypoint.sh";
runtimeInputs = [ bitwarden-cli ];
text = ''
set -ex
# Uncomment if you need to hit a custom host
#bw config server ''${BW_HOST}
echo "Using apikey to log in"
bw login --apikey --raw
BW_SESSION="$(bw unlock --passwordenv BW_PASSWORD --raw)"
export BW_SESSION
echo 'Running "bw serve" on port 8087'
bw serve --hostname all --port 8087
'';
}))
];
Env = [
"CURL_CA_BUNDLE=${cacert}/etc/ssl/certs/ca-bundle.crt"
];
ExposedPorts = {
"8087/tcp" = { };
};
};
}
Binary file not shown.
+39
View File
@@ -0,0 +1,39 @@
age-encryption.org/v1
-> ssh-ed25519 64uajw pGArtr7GB1lyaooKK46PBygPCtdQmFfEpk1rA0molCA
8ssJyIFriGAp9BQCYMyTf+S2HmMeOC1UH2QXqbqBFLQ
-> ssh-ed25519 oyEmTw AZbFjT/AjhDQOVHQYiZAKwZyUZar5uMiM2r2B3IpN3A
FQ3cu6l6KZbHB6vSatiLWV/ntDoc1zVT4/QUinPVZCc
-> ssh-ed25519 mOmPfg Ru0AM8rjvVpn3PjWp7KPf/wtdBAphHfpNJ9bbZZVdmM
sphzkfNpy3GiLSXo5U9ct8t55tLGE+Lt2MVglsMCu/E
-> ssh-ed25519 YJiRbw UuAcR0LT/TWfWI1Ba8cm6iv/aYY+eADglTwPBAyjP1Q
NxxO5o0G+PQZBRTC1pdAFNr28+ijKUEXAZJDsbF2sLg
-> ssh-ed25519 aY2AXA 4Y8xviHTR9/fjycJHzcHLzN1txHl1+bGHG099CNnDm4
Y9IQVYf5KQ1qDdFwPKpWxsCwdy46OYRlYCncvEMHXO0
-> ssh-ed25519 xNtnoA CWVPYtuxcHQLtSd9cWLs7yuPgAuaY1hRGMesA+HhGCE
5LFGLF5uRxHkbSp0WenWH5pBpEDNr269GmTOrSA5F90
-> ssh-ed25519 AQhf1g bjCjRVRxIWGPIbXg6QvNwXjiXajyuwMXbLu/3EDxp3Y
zHlX3WzfAccjVyksrzsdWfVsx2ia2oXBdTWLGroP1BA
-> ssh-ed25519 B8wa7Q zr+NOkU1OAJPvpN/MXECQAowUKWIbnNLJJsGeGUydww
+we1cguTwDROfIAJJYrExz9Towmr18JXVY3oRkpv14w
-> ssh-ed25519 8UnW5Q QjneH4f6Oly7tnAMLiLMwUIjAsaSi5ZFoC8TQG6GkmY
kspnipzqALYSiT1jJRhF1yZecxbkXv70vlBKMUxBPZw
-> ssh-ed25519 0/WsKg Ep9gDq0DtcGbdQh/PrYe+iBv6OSeLPWxICjXbKjFJnE
2g526leouu0mRQBJSebsQ2h/3UF2fqQe6P8PnSLEhWA
-> ssh-ed25519 Nl/5yA ki1Df4IbjbBJsBuu0i7mlCDkIcp/238uCzTq2xxo3SU
0KPSkglgV55rtv0cJ0ZHxXXrrd/kFWPieM1RSSz+KKU
-> ssh-ed25519 GdLgCQ L+YIJXArLcYoRNBOEgSrpM0fNQHWTZn3AKmuue9s1Hs
Y7dOqUW2+/6DTVHfitXWPRQTn8dAXFaO848XhiarYYI
-> ssh-ed25519 tOH/HQ rohrw+mCT7L76YNfHG2kZ//3+0BvLE5adIv4iDCYPXo
7VsJeUR655/7Rl5+aT3OUK1iUHL2xaz88VblWxyzDbk
-> ssh-ed25519 FpzvfQ v8DOcm6/7afe7hqJLs4yS9QsoaKrtmft1nUbVMIQbiY
zPtH/T7vUG0TYAImLK4a4i8ta/n4Iu5qUIHNzj4AExk
-> ssh-ed25519 kdPvzQ TVIyKHig7iMyCx25roaLgF+wbm8r/FdDmYzsn47mQFY
7FGAj3og7JONhSZFjywwoc41lGSaUvJb2BaFjc7Ymlw
-> ssh-ed25519 onmXpg yr5rUSP7BVin9iRa8dbhsqkhzMNBgk03kSj0ne+9cxw
5fYMGMVh4lxXuZzNIOUhXj9B43RIEzI2mCy9urSSEng
-> ssh-ed25519 CnhD0g 7hvSFju7gEZ3z/wh7vYErWG545rqx2Vw+uoOk/QplEs
UOPP23HMYyJ5w/3qbtEmHZU36F8kwiCVBsaZHTeOJgk
-> ssh-ed25519 4ep2UA SSi6Na4Zkz15jv9AIQV9UW0xr2YFmoT5s96Fz0X0nmk
BoSwO6G8pMUt/N8RRLdVxzmQsn6RK655j27shIV5xq8
--- FsKrB9/IGIe8BxDxJDSnAnm84SoJAPZFawQjoAUTbUE
…¤ú¦\86IrwN[]¬å$é`uù8BÞ„HŽûÖƒ.§ñÓa‚#Â|³b¡Ëi—Ò®*é›>KpÈØÏq
Binary file not shown.
@@ -1,42 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 64uajw eV9Zpp4/hT0/yqmxioNHFm4k8vcIYxUcut7IoDDyuA8
f3UHC6bPtweXnJ6htSbHI9aGoFOekxSyP83jB8AXLJ4
-> ssh-ed25519 oyEmTw ncaobB5Yo3geYqqqGbgQAbL0ReboWV1Kd1VoaoUIqR8
qgHrn4ecZ4/T1dBncpcXpx0+hQNS2RDxTD0w7UW7dQ0
-> ssh-ed25519 mOmPfg v0q7ExwR8khGaySaCBmWa2J6cte4kbzcJ/kzM63oFXI
vheRD95qqHoYHLKZwpajbavOECr0sM5o/P2aN9l7MU8
-> ssh-ed25519 YJiRbw ZUwjcDh2BgTiuZtg7HB7z3CDcaSWI6p00CdwSynM1Qo
Dj9E36auKUDim3+8Jyo8eOl7QD0JiGAyKJwGibiZRTg
-> ssh-ed25519 aY2AXA 3OAFXfKEa17oKIvaLlqMIUt5ymogo/TjkNQq7a76tl0
VVunUS5pgcRb6iarZKT1EpTV1fNJqR9GdMsoLOva1zI
-> ssh-ed25519 xNtnoA Z9j4Y7Wf8vT5tJ87HEaYnjnklRrneHCo37pYUJ69bgc
0ZugVGxDqUT9Deq1Jf7f0mYnX3/mEYSgbgoburorUcc
-> ssh-ed25519 AQhf1g cNcndnaIgUJh6J7+tgXey7MpYzOUoAp1p7TfAqmimEs
UkDmgozd1WjYh2EmL9gEKP/WLnG/ZuPRLttxKGLvBWA
-> ssh-ed25519 B8wa7Q 9emGk7ySc9cqV5MWP4FMUgaokxsiaefV3BJLmQfIT3A
HcAfVurlttw8XECe3hl9LtcKsLypZZORKdzib6wUGJA
-> ssh-ed25519 8UnW5Q U6vSV1xCzXM2pI730y7xPQOYeN6MP/cwv1C7kFE52lA
L9shhjUH1RBYkPr6VO/iZ5FhAAZ2fQm0ap3FyodYcfE
-> ssh-ed25519 0/WsKg cAfTjIjq2NMz1mQVZ7Rzv2n+Uliv9STfX7Qk9Ixr8X8
rFlWd+QGDPGnDRnI4zZEK/QvNrQgZPqRq8Ta1ZNXIbg
-> ssh-ed25519 Nl/5yA asEF9vNOohQbne7nsuWo0mjne7JETHTGgXCPp5520m4
fo745n2zSyLWcadThr53CPizcCw3IRs6MPdGoTz94oQ
-> ssh-ed25519 GdLgCQ mUZSVAOzecIr1H8ekf/rrt6LLVxKZG5M3humVl22bww
CuJcm8Qy6TfH6HFJxlfFoOgl2K+4p4bpFSfmEb83wJI
-> ssh-ed25519 tOH/HQ AtfEqYQ0aZMT11xRDBNS7vb55weHU4uIV/ztb8JmyCA
esNanLRi1FBWG7v27615uo5CxGW6yvqe/Je/nJ/UVwo
-> ssh-ed25519 FpzvfQ MgdTAyCUMNTOOnYD7H0U60IxnOKRUbMO9yfKP1PArgc
/9ia4l8hI+yXb3N1sxTMBhEkkO0BTQRbG4IaGNZuUBs
-> ssh-ed25519 kdPvzQ BZGH7Uuor0zXWb7HrzFTKkU9bmZtj6hTYlqggv8EV18
p+Ix6dd5HqwVoZnliwvr18Tw7LMX/rLHBsyJeOR1Y4Q
-> ssh-ed25519 onmXpg zJHDidsIEBbTLWH4EwHdd0kxpp2TKOIMYTTkn30pWWs
ZcoRMNxoJDi1w+ISUw3fRTOi3+NyuCgqVE7k8//UdUs
-> ssh-ed25519 CnhD0g 6PMqxrnXVVPavFvgyEEgaj99G8GImfaQIZS6wIs5RQs
1z1plGxfj+Y1WWP46SkArNgHvK3izF3I3UGuLyGG+sA
-> ssh-ed25519 4ep2UA +9czZVUs3NAJkZ/E8UDTsk1r95clfNzWkVxcBSNbfS4
WQ5ZsO2mXPmWz71dX1K0ZJsEbVv4R0QfCSBPPWZ+cSQ
--- xEB5l1RXMXTk7nVXGag3x+jbkLAWzhAlR8CYtiOsfno
óéKâKÂÆ·û4Ž­Ñk÷5:Κ…x§6žS§ ú™¡;v}ðŸ6ÔCTg␍‚¬>õG ©Ëe1TZKÝB‹È§4ŽÏϤ7 ”9-ýDs>öÁ‡âxå¿1læ (³=3¡½è§»ú÷»áD²ê>;ÚùDþ¢
ã’gÝkø\7«ïSu¨:|³û²;>"n…w”  oM{×{3␍{ˆ<™Dcÿ #óðwùvu¡v²¯³ŒX΋Å(¼¥$ $WßÂô¶dvÞKÎv”–Sã _Ų»² 7çÇ:›ùÁSê?Ö ´­ s'޵ÕÖ¬ód[´(Vˆü¦»¹žÙíÂ=ëÝÆw½Þ1"iý÷pØyýú¢ˆ¢³Ò`ˆ)w·Ù'©wUØ
·4—v,é8sŒëÿW¨šà•5سÏMy¹åüƒQ"w–ö„ë«c£Í€F*Um=ÅœYä¿A EÍúºg
Vþt™À^•r¼c.±–>HB ú„AÁn¸éeÂõG«pç(Úñ¤à*3(ŒB %jt_!T»°GÒõáÜûËÀ½ÈóTž€¯␍ªèo‚¨–œ4pkìäåÍ– ôT‚rÁ␍Iø¶Ò±)*.è“!RŒ]Hï9vè
-40
View File
@@ -1,40 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 64uajw Owu2iq5FOcCnfmc7WkPZjpje4+l/Y9JpadTmc8ChxW4
kpN4BikG6+7GCSplNVFDrQtc0hKpVf7MGeLBdEtxvY4
-> ssh-ed25519 oyEmTw e0Irdtmkgx3pHkJKZ0M2wzfVmE+b/tsQ+a1mZTtW8XM
sjJNMwLtamfVYpM5nxvcTVverm41U3xpwTYQ63Q/N84
-> ssh-ed25519 mOmPfg On+SiDGuqOceWJOF8XZNWVHlseoJ7SWmrv2L7NXsjXQ
83KaBly8y4n8L9vclbojrKMTI71uuyvYgey0b9cxy4g
-> ssh-ed25519 YJiRbw vdtkHgNYQsmiSqEQMAstt1mUIDQV8ZYd/zm6BJYpFGo
zFXmTVzZbPJTdM/hRPVXaIj0JSl9OuWY3Rb91/y0dBc
-> ssh-ed25519 aY2AXA 9wbue2xbS4RCxt9Qv75oPDxc4ccCPdSnlRG758OGW0k
/5vK7IO8KafpczgAqtPx2wppxa6moy1/Lvnfxn5H02s
-> ssh-ed25519 xNtnoA aVFWpqxsXmmzd8qGM2ZKM8PjYutfaYm/ZRgjMeCR9j8
+xBg6M9RnnlsA1Ahb4gZOywOnWr+3bs3bRTYFVIKr38
-> ssh-ed25519 AQhf1g 7uTLGKz6PRaEypfKxVhHladHaTOxXzLDCwSaguVpEU0
ruCZuzyZB2MzO8On2JYae3jycom0sTDoY8Bkh4ruQyo
-> ssh-ed25519 B8wa7Q gxEB1ehbBnd4hcHWhSXKzXUfC8Nvkhis3c8FXtbfaQA
jHfJtyqB2kt0GqaRPtLc3gIcjh/YGhfgvGzXw3rm9DA
-> ssh-ed25519 8UnW5Q wJF80kCk+LgGpYPTreA3iTwY/QrhR/rLagNyWKerGzw
eZnYt6N7Trr3J1WGB0Nv3zHJTnML+n+iNkvzdL3jm4w
-> ssh-ed25519 0/WsKg bcN7gFP1Vm0MpWWuPW795gD8Q1E3xLr1CMycggtSqRA
6m1NXOBG/Wyz21hCRrj/VbfmhX7QzI8ekAQ+XXnyy38
-> ssh-ed25519 Nl/5yA PoO47KPvS1RXL3QA7PjQDdxL/Z5oYTPivx/gMBXOBWE
yTw7f+qbRyerQQ7JR6DqgkfKDTajkanhMlEmQIV0kCI
-> ssh-ed25519 GdLgCQ gI8fo4YpyT/qIEZPn3XIa4R+38ICcTIG1BdTMP+iUH8
RbU4uOP6RMQZ+DRKrEcZN+GwjLzjq+2pUdk9xm3Xlr4
-> ssh-ed25519 tOH/HQ mIrauZ8OfOElsomdivvcdgpsSSDPPjrlJ/YQmnf5g18
Mq/vcFQ2mGIPVB0uZS/qtO13WMTcs4CLRwl4YWrreJg
-> ssh-ed25519 FpzvfQ lC5aVnyJYH6t/PDDnQQNRqwOX4shQS3Ys1aOWfQ8sw4
xgdHax+M3voH8OquVY0SqmSoODJCCVrWZJL1bPFlsp4
-> ssh-ed25519 kdPvzQ kHJVlbRYWqubO9xDybSQ1awWZW/OZRp76z/Hmny5dQY
B1n6XLWZ2KBfzN0qniNBMKdZM40fjDogKkpHfEEQnW4
-> ssh-ed25519 onmXpg fHjrAjDy5Ce/hg1WNJc7IWEk8IxYXdR6h2asJ+1Uajs
VxVISuHeVJ6NKTmGLNY7AbyGgdOVPIZoWkGNH8C7xJ0
-> ssh-ed25519 CnhD0g +JqkpM0pFRZiaNP49Y8IPDo9w5KqahsqJYugsYmIe3Y
M44lsxcLqBh6AW/sf8zMcOg2euOqOytmOTtFtfMFHHc
-> ssh-ed25519 4ep2UA QvvgFgNihOAnItEV5W/MWkPOjrFALbTrQQf6PMO3CWw
rLJIh6PomyyT/nJXdi2WRIpzZymNqWQ4QuHp2olJI0M
--- m9Xw9hvo+ZLlW8pe2/YdH5rqL0cUFPcTicrExwC7DGQ
¯…ÀÜ6è²`ç@{XhçÅ ®Âœ10à–¶= ½éý÷ìëËÏÏR’LÜÿòw]Ðûhxõþã£ú6¾’ÐéûÉÛ\íÑ÷ƒ1Ò¨)Ô¼yo­¥ƒi¤úžgê)nÛY␍-÷މ ­ågàëý„¬ˆcˆŽ:#ìqÀ¬(‰_‘6²I|,§éºôé­žHB>Êö˜á)K¿B5²Ô‹L¯æœ­³yâ†ÖÑlUêekvZ␍Ç)•‚¼Ô=Bƒ”N¼”þ̨wØÇ¬“0y[ëÖÝÕƒãð*òí‘ð'W”éê—¯‡mG¢úgè ‰Í
¹±ÌBU¼¹¥âYkÙ¦ó™#…R!]µ š"gt^N¦Ÿ úþq€ƒ+šPadÁwÿÞ$0޳Ä%*wi(T0ªÈ ?^ìß÷Ÿ$S‡¦˜Bx7¢ u­¬çÙÙêýä0ÊÉJBFãX'”@dj6<eo™éÒ&´œú°®”¬-`™ŸöÀ^}» ¹ Ä.ttLTÿRDZGË&Øè|Î*óS¶U¬\DÉÑÝaL¦U¾Ü¯í",ûÛTҷ̰-¢=èç-•8ŸVL.o(>·‚¬äÙÌPx¯åPnqmaö51
Binary file not shown.
-44
View File
@@ -1,44 +0,0 @@
age-encryption.org/v1
-> ssh-ed25519 64uajw zaw1VrAOKf7WH+2V4MPaJ2NGfdRq2TPYV5LW10niQwI
yt3kmG5Pi13ALMjusVxuydh/j6xMLNJP5hLp/ePKxcs
-> ssh-ed25519 oyEmTw a9q3TpbESuMSh2ut7D/JfgA4KV0e8c6/JQySA1uh3Wk
haasKx1ZqqMf4tP1upDtgw7LOIw7J1D699Dl75LQ8IQ
-> ssh-ed25519 mOmPfg YDmQILepyMgtgVzriyRWks2QZpvt8zCsAhlrZI1Fl0o
scnIfvhOAVAHh31EIBqmFBNbqXleJ2pcFPuMjDEnZ/w
-> ssh-ed25519 YJiRbw O6Ar5fSR+6OTZ/MMACKg+SOIRV4NtmMJ3MPexY/fAHs
sBGDGkW5vfZcyQ/Hv/5xdAlOz1hYGRWMcO7tgDrNlG4
-> ssh-ed25519 aY2AXA oE4aRUnvlKUkrXkLxqdlmSeTblfk9uTWGzoMU/D22EE
XaRuO3ORNgb0LRZKzRj0sMpJDFzyzhDIuXBYs/OxxWw
-> ssh-ed25519 xNtnoA TLM/kPHULyiUEymgksLHLVhhCT5rIMRc9etjkINaE0c
JdDX25lXPXStWwoSWp1/WmgMeb3SDI8Z/OyiGyVF6mI
-> ssh-ed25519 AQhf1g pNMD0U938a14qqiMUFxTw8073SNF25IDJfjXGm7q9Ss
Yuf5Z6AoHW9uj5hOWSc5eirqP+xH9wbuwknqh2JW4K0
-> ssh-ed25519 B8wa7Q KXIt7sQKcZpSnKbs30fT5ybgBwFghhmM/Ov8OjQsfxE
BtZysD+2DVUcivWXnJdlW4Y2pLCoXLF7jP4IGj12Xo8
-> ssh-ed25519 8UnW5Q nLn5gfsYNAxDl8GatHyEyQMhpy+A5XvykowBYlVbPQ8
w+XlgXrE0KcfDWZC+ya0tnyDXshDw582B803CItqLFc
-> ssh-ed25519 0/WsKg TbGuq0eETh1mVmsqtqkvhCiXAliz5WS7iqQ+OY01nXY
GTXIQZf44Sjg4mVxQtD7+VOSx1eAOIr0gBxhAjMXK5U
-> ssh-ed25519 Nl/5yA fjC2SY379C5o9jBUetLXQApy00YVEa4A7Jr61yoCI0U
/350ThLM1JCvg1E8kJib2ESP9nXRUI5QqTTun0QQtO4
-> ssh-ed25519 GdLgCQ H7g+SuknwgOy8PDEwK8UqrNG82ZoLisCSSFTxaNS1EU
JVd1nDmgTSZ6oLdnp29Qlor39RHZN1q+hPEJl1RSw5s
-> ssh-ed25519 tOH/HQ PFuIUIqN8K9GoLsLOIdRHaFj5KclCuwGoRSoyH9WRHQ
fkQNV36OpzgiufqmTyJYHsNlfa6THDrDzvVyaVVrtzI
-> ssh-ed25519 FpzvfQ +HL0H1U9HYiMuyVjd9hosnTntjV3Bf8N/KhdfbZSgV4
rd7CNDUSU5GYRVfuPy8aEVNdWAv1DektrVb+JES5vTk
-> ssh-ed25519 kdPvzQ EsizsHpgHDbBWwDnRgPmSMy2Cmpvqpjd2wriSiW+xxg
tGd9x8NQMMLaqYDFKWWfJvvdPyTS63OZOZGWqvfj1+I
-> ssh-ed25519 onmXpg u4zMl21Un8YqsRaH4STYGbI53K364RJ9fMDCKmUcbCY
XHtAV9Z9jpPPVYGOPq7/jS0ZiTy4E9As2Dv4fAJUSVM
-> ssh-ed25519 CnhD0g 4VejzPLVJcGXdLQBY6/Fb4PKtrzvRpMltKBMjMM4UFk
4IwAQAJxOZA3EYa816SbQeM61y2yV23fIDPe7w2wGUw
-> ssh-ed25519 4ep2UA PTIWvjuv8m66h8E6+QZJKxEmZ4RyoI4qwiMMrYhVDS4
/28djh64HqyGhdOKzwFEseIH8BYGljkcQScV6rBx/Yk
--- UINMhgQK2hWVetzQg4cNYxksN4G+pOKGqvZ+Jl4Zl/k
]á·Mƒ>;¹I9Z~/P*Tîö5sñÒ58 åW–ùŽ”¤K
g
¡Ó7™ú<ôÀ&ËŽvªöL„³kQ=-“ÿµ³0aRôIã•Ekæ}lµ‡ýœxAJâÈ}–Jä`Ü
/TÄl”Pv\SõûÎì|tÿžAH„‰ÑºGÝá‘Ý{Pü‘@:3%HmÍ×c¹?d$ö€”­µJ.C3ð‘ÖLõ©zZŒì’ÌÚ× qÀzNžEÕ‡‘¼Â¸
ȹeü¸v7A o…¥>euòsuÇ9êrào~ˆXyñVU^È6-ïÊŸ±‹„2ÍÝJÄ ,&ËF^Âìan—}3ªe¦bsÉÅy_^2&á{§–r “Î=Úq”ía<L-§N ²à¦É‘Ù2YFŒ2Ü–Æ.ôèù”ßFá(ðØ …Èow*bøq"§ø,»e£‘@±è õwfĤ:zÈ(êý[
añnݯG–¢_à¼Â"+.z÷? ß0À' X6OŒ¾ªôÐÑ»Á¾ò7Vôv;\ g
Binary file not shown.
Binary file not shown.
+39
View File
@@ -0,0 +1,39 @@
age-encryption.org/v1
-> ssh-ed25519 64uajw 65up4NePHDRo97ryHxOcL/ZulVqH6bE8o0HRwKaS/zI
c4XtvR4EeZ8G4iT7sEj9prfvAoDDMnp8dUF2JSc/qPU
-> ssh-ed25519 oyEmTw QiQFAuLBYBQmiJ8TAGagLqfDFktf4mwsOhmJ7ZBIM0s
fdpvwfAKAWJUrFcGNA5NmH14Weixfp8NUqoPA/mw+4I
-> ssh-ed25519 mOmPfg dPYBhH6jodNFeTNTMwPuEq46i7DzKq67tMlYWkw3+T8
Z4Uh0YhUL8KWqUCmr/AFILazC7v9L2poNC7IUbE6Uu8
-> ssh-ed25519 YJiRbw RvWUVFSFOvz7q5mNBg1FoYLi1jbpMPvImUlJSy5zBTQ
nNuNQnN/RhtFUOsbezo8LP8ceY/yqFSYDCo7igujiqM
-> ssh-ed25519 aY2AXA LbCZXvEeHWVtlvecusaJVdRSUjsCONHhD2ADA73FGy8
4zNv08Z7vvS1c2/BOdL0JxAX/Y+kU4q/WWlfxmA6fVk
-> ssh-ed25519 xNtnoA fZVGgBdLb47UmapPENDK6nxICXx+KeIEhBQ3UKIi7HM
dTJO+0qXtgpzjCe6K4+FQa0nynH5qEXebyERRQEBDzE
-> ssh-ed25519 AQhf1g 8Srs6GErqaEibInARo/dzXwXdNqNTFBk/kgPyXGlEAM
K0Ol9j/Uxw1up7xEapKwtoTAc2ZgoHuqKiHFcdrM4IY
-> ssh-ed25519 B8wa7Q PZekZdp5Dj84fnRopshQYTZu7ue8A92PMfMqGMyPIUk
Y6WvNhXo2nQI/nmI2gGdO9XCjjafpAai+fEGeYSGCHA
-> ssh-ed25519 8UnW5Q AsNtL1dQUNeKHaatp/85nVUe1jLL5WsviNpKXQEBqkY
z/9Q/DJQqVGNYHHJ3fU/EFPfTREZSJMxxlm6fhVGpME
-> ssh-ed25519 0/WsKg 4TV+ryC7wbPQGTnU7TzuwCJz+iZEluBFAlnk23deA0U
h9JoILNlSPX+dePFjSYM8vvetXINWAJ+DIXcStM+D6M
-> ssh-ed25519 Nl/5yA uw7SLz+XPRnHb5ux2mp1VEL/cwnMFMhc86UnglcwARI
k7lt+0yFMqAcepklurzW0MoB+yr3HL9DLTa+1+PPETg
-> ssh-ed25519 GdLgCQ t5aY2s4XfLnlmAjB5k8UpEy2iMm2K8NFeowDyP9nliY
+x0yKD0pDecGPnU/ijJ7WRUm/UNoQu4EX4/azB9Og6Y
-> ssh-ed25519 tOH/HQ Cc06HO0i/Yy65bNTREl2r0qd8sM+vhLyVxB7Pm8pemY
qy1juC+a7BjtMZ2XoFvfCkIEI8ihTCs9ThAkTSvEsVg
-> ssh-ed25519 FpzvfQ MdxHv8FxO4tRbiup4k6N4JUFtnofB6WJ8xn8KTUSjyM
Mx+0cPM5bq/qJxKXSmzneL/Pg5CBiO7bjHjyFT05exw
-> ssh-ed25519 kdPvzQ Tww+Oh8cQV9/qUw+2FWpRJTljjsbFB7T93xrRJcFGwo
lGyd6FuQ3Y68pVn/aZCCtxVEoc9gn5Nc42peuFy68dk
-> ssh-ed25519 onmXpg asPPNt+wiRFWgaBaie0voK4Yw5R8t8r5I3t6qujAsx0
oa8Em8djkwbKYUQkPvZ3YMvvM2x9NEtm/f6Y7PoWmmo
-> ssh-ed25519 CnhD0g lfXt1ZIhVWv84cvAykGjO44OvVny+U1Rju+17gx6qR0
7StUFJgr+8zVr9OAmtgQk+UoBaQ8LqIUmttqlXdpX+s
-> ssh-ed25519 4ep2UA ued9/iPni10UpRf/RM0wesnRfp+lpoO99831MoShxnk
k5t8fmGnoCkHskZdvw1fYyCdns7BZsPUaLlJ6WzQgHc
--- HaCc7eAoVLgJf982a8aRJPadwoZ9WAQ2jH1+j5Z2w8Y
Ø÷!Mø¤CuÊ¥õX?„l=?˳êé[ÍÕþ(¹üMªNµÆßqh^"·Ž›…`#A4&qhšßE¢
+39
View File
@@ -0,0 +1,39 @@
age-encryption.org/v1
-> ssh-ed25519 64uajw RdFMAWftlhzUEqoxui6a0IBxI7KxrU6C5uQeJwhUAzg
UO611nUdfsLfG+LRhPVkX+BaVM2NoTB571nDdy7nn6E
-> ssh-ed25519 oyEmTw 3zfLtPD8rpTSaVSMQCOSp38S9fywd6e+V0e9v9JGgwU
qjaK+z7HDjmLdViDNjCj6rm3bNjc0xrrUVlwupkXd5w
-> ssh-ed25519 mOmPfg weCYfjyuqqPcEVNM7+rqE/x5ZL8Mifp+obzMULqZgWU
0HTPHd8Hq8qJOfVzP/kczVQYaXKJykT9KCK9Rn6r/nI
-> ssh-ed25519 YJiRbw 0ARXvdUzE670xRni7RRnyVhzFURTyoQ1GTNtfY+MWU8
jlt7BMNJ/AwOOIkIDAyiFyy8FV5PYlcqwB6MOLSZce4
-> ssh-ed25519 aY2AXA CyalC9EQJFdNCl+BNLKrt8KKZBPnaPzH3t25F9otkEM
m3mig+c7SvWuxUIorZcVfzIqualwTC+xJBDKvB+zCcU
-> ssh-ed25519 xNtnoA 3n7J6GMt64Z9+0M89QTmZaeJ2/A7JdMl7TfC2nUt+xQ
wk6G2SZL9VTzFlyIzc/EulzzG5P9EG9M1652aapvT+Q
-> ssh-ed25519 AQhf1g ksxGPi6mYEhc1X2waHMXkTFgnB6lpKWKUeyMxFOnMkM
Jj6fEbw52O3I9wUyk9of+NSJmNZC1U4+7UF98ChEbQI
-> ssh-ed25519 B8wa7Q yMYUdu6A9dEmiAgYveyxSKoUL5XkmMdnyOIwherXzyc
4n87yY0czhQib32cxQ8XH6tepRIzjmE7ewWCRaY0Dpg
-> ssh-ed25519 8UnW5Q PLN3cqCd4t1m4bNbRjFNAs5k2hwTUxRV02DPgpZ75Uk
tRwglJ5sPoJzp9Je5xEXlYM2kbUUd+xwawZIBYKZKZk
-> ssh-ed25519 0/WsKg V0GKvQ3KdATmhVHlXyL95Lb1bZ7uTBMHH+1DloQwaWA
UDb0UWGNzjY7K7qNqhU88+ViGoP7msG73sxmiTwaKgQ
-> ssh-ed25519 Nl/5yA eyZT6r909dv5ClBxUhCflv1676VV1uQALhsrHJycRQY
0AkXJLRwKURIXPhnM8VnUVkBl9Oq4LUHTs4n7Ai0X0w
-> ssh-ed25519 GdLgCQ bIMe/3XDR7HCZOzxG+n8ud5bzMMDrZSPCDoPnbX7clg
XGRkbM1xkZzhaCa2frDhWAZkJ0RAlbBx7IcJrCzhXWc
-> ssh-ed25519 tOH/HQ 42VvN/DyV1VjbK0sI3/AWGCByXw+W/atfLUjlEIkyCs
f2DijeqBQss3f44fFIDC5M3SXRRpm3Cl0iaLLOyAD68
-> ssh-ed25519 FpzvfQ iRQ1JgNvo6mpRIn4HiF3dOul/ZhzQbjP8MCID8sFY2k
SL9kRpWY1SigL2MVhy99hB3ACCHIPTK/IMIH98epch0
-> ssh-ed25519 kdPvzQ gleTd+wfxQgl4IcQDqw5SmdRQvOV5MRHtSh1XeXz3wY
5fGWJak3xivrRJS+dfiUWc15KaVTIXe8xlLhr+lgIR4
-> ssh-ed25519 onmXpg SU/B3Y0ddUAUNDPwSeAqaG1ICihEQRglorF1143KC1s
Qm6GGzluTIvEVnXTbl3z0LcrzxXpdN5hOksc03giazY
-> ssh-ed25519 CnhD0g GVlnY0nuxGqWn3y7CPIk3p5P/bJ2ovt/DCpsemTwnRw
vleILr9u6erKyzgofdIZuVShrilviX0New95Xw3+0pM
-> ssh-ed25519 4ep2UA xSlFMYDkUBAzs+xaJJr29rbaC4L88ARUG6zq8v82cng
C/i6coQ1Eg1Kka6sDXFnV7bMTekcKJOf6Q0gc6scFJA
--- sx1TUDKIOIimdMTVBePkZzcfpJnvHddO1itsV7adTSo
¼ñ8¼Z4bÉ‘Le× @B¹'Æ Œj§O©áÂiþZÛ•’pùŽŽI[!o8ÔÉ›ÙÔc<Г眗®PÞ½
Binary file not shown.
+8 -6
View File
@@ -83,6 +83,7 @@ in
"dendrite.age".publicKeys = everyone;
"dendrite_key.age".publicKeys = everyone;
"gitlab/secret.age".publicKeys = everyone;
"gitlab/otp.age".publicKeys = everyone;
"gitlab/db.age".publicKeys = everyone;
@@ -91,13 +92,13 @@ in
# Then pipe the resulting files to agenix -e <foo>
"gitlab/key.age".publicKeys = everyone;
"gitlab/cert.age".publicKeys = everyone;
"gitlab/jeremiah-runner-reg.age".publicKeys = everyone;
"gitlab/isaiah-qemu-runner-reg.age".publicKeys = everyone;
"gitlab/isaiah-vbox-runner-reg.age".publicKeys = everyone;
"gitlab/isaiah-podman-runner-reg.age".publicKeys = everyone;
"gitlab/isaiah-shell-runner-reg.age".publicKeys = everyone;
"gitlab/salt.age".publicKeys = everyone;
"gitlab/primary-key.age".publicKeys = everyone;
"gitlab/deterministic-key.age".publicKeys = everyone;
"gitlab/nixos-qemu-shell.age".publicKeys = everyone;
"gitlab/nixos-vbox-shell.age".publicKeys = everyone;
"gitlab/kubernetes-k3s-local.age".publicKeys = everyone;
"gitlab/linode-deployer-runner-reg.age".publicKeys = everyone;
"gitlab/docker-auth.age".publicKeys = everyone;
"acme_password.age".publicKeys = everyone;
"ca/intermediate_key.age".publicKeys = everyone;
@@ -106,6 +107,7 @@ in
"minio_secret_access_key.age".publicKeys = everyone;
"minio_access_key_id.age".publicKeys = everyone;
"kubernetes/bw_secret.age".publicKeys = everyone;
"kubernetes/kubernetesToken.age".publicKeys = [
isaiah
jeremiah