From 0989eb88bdb0026d1e90026cc546a2dff8067ed9 Mon Sep 17 00:00:00 2001 From: Gregory Hellings Date: Wed, 6 Apr 2022 09:21:50 -0500 Subject: [PATCH] 2maccabees setup DNS setup with dnsmasq DHCP setup with dnsmasq Home Assistant setup --- .gitignore | 2 + base.nix | 48 +++++++++++++++ configuration.nix | 14 +++++ hosts/2maccabees/default.nix | 13 ++++ hosts/2maccabees/dnsmasq.nix | 65 ++++++++++++++++++++ hosts/2maccabees/home-assistant.nix | 94 +++++++++++++++++++++++++++++ hosts/2maccabees/networking.nix | 44 ++++++++++++++ profiles/gnome.nix | 27 +++++++++ profiles/home.nix | 5 ++ profiles/rpi4.nix | 32 ++++++++++ 10 files changed, 344 insertions(+) create mode 100644 .gitignore create mode 100644 base.nix create mode 100644 configuration.nix create mode 100644 hosts/2maccabees/default.nix create mode 100644 hosts/2maccabees/dnsmasq.nix create mode 100644 hosts/2maccabees/home-assistant.nix create mode 100644 hosts/2maccabees/networking.nix create mode 100644 profiles/gnome.nix create mode 100644 profiles/home.nix create mode 100644 profiles/rpi4.nix diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..51c610f --- /dev/null +++ b/.gitignore @@ -0,0 +1,2 @@ +host +hardware-configuration.nix diff --git a/base.nix b/base.nix new file mode 100644 index 0000000..3738e29 --- /dev/null +++ b/base.nix @@ -0,0 +1,48 @@ +{ config, pkgs, ... }: + +{ + # I am a fan of network manager, myself + networking.networkmanager.enable = true; + + # Define a user account. Don't forget to set a password with ‘passwd’. + users.users.greg = { + isNormalUser = true; + extraGroups = [ "wheel" "networkmanager" ]; # Enable ‘sudo’ for the user. + openssh.authorizedKeys.keys = [ + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQDLQRq55JKqLifX+31kEXyuoB8gfM+5thAlgR7XLPvvdu6g2a5cCWyozQ1I2oGbPRfJtzcJ5ifM7Ii2PuqAj3MdYFLHBEDOhIpBBWme9Ts2YB9HJ4NorBvB4zEfJd0Q7k2MmylyeBOwdwGz3bVqPRDcJbxWFMDHqr33FEs6SXdfyAQ5SvhWGARI84qz8zUUdOp6M4e3aIGO3cx1gA+YzYQ4FbUtL8+m1NFO8VoNFMZBMf5q0iF/SgEu5bmGWUCePia6DvfeBFQ2/y4Y7WmOj980WE+JmFTkIvmGruMYeGI8FuDQ2JIIIcehddy9bQbPF4VlGnTFsHqJYVRUUWc+vH1cPNMn01oB8s27ogf9e1lyhIN+cZOgp/jDt4eXcO4Wr04uwj7CI6m+d8iMQOa5Jv0hmNgqqiwOMVBlKeo0FCxlovzwvn/Lia9WZ74JqM6JwLCD8SZ0oFgiSIHOTHrQhr7iaCmj7X/0ey7VR8FnCrpeAJpG+ELTfWGshF1d9QR2zW7u4EsXTDLiuOmdJ+/KxwMvjMcWdlg2+Qch6SwulTQRxWaED2IWJo+YiAql8eaiVXu/eZJGLoiskGFZnONoLrzIT4pSjakPlrSpn/M/GkP1pDpaMkr24OhJsGpJNEU3F1ZcOMqy2iJzIxlPmU8Xg0I/OrnbJplpaXeRCqnmouJUJhWkaPzawaVyW7dtvprLWcpQtUgTRet18WLyOrLKlq1jwvNRMTPKUJ2IFJMpk2pNEP6bdiUxyMa4vrRIEU2p1zsYSUJpCRLtccZ/i/+yAqwnTA2L5TdAORi9nD2uCdM/Ljz52V3A14QapS6oqcoWx2soWKgnsbVXoG8DxmUTpll77Ze9t7Y5216SMInWuOu0vstP8ZcgFmWsiBgIYIuLA58abWHMxgD251phYidua6R3Gtkf8J/kYqTR1P6eJF1bt5efEg7FD2aL1QQZsYJo3CRNz7yVe1XqMdPbfe2mFXQVF9TDX5x6r9Ir3d0KiEmTlBdByz8nSyPJ8IQxC58NT4LNVQs3p2XH2Zcf6B4JOBSmV4NNBnLseFobsxniWjkWwZigED/D2iu3OXuuhmskCbw0hKy2rBcKffaSNMioVqYIiYNfKlMlSvAacQKqc/1HCpqgX8PwAcSgNSLy4K7/gIrTHmjY+g+CH7onzatWzkLo+0vsZRa/D/qwhhK2CU2FeU07mhnWxWuzqpJuqVaAwDTaEforK7nQUtAOFAZZP6qGhIoqsynYt4THb+QORb3QYfaP0PVgQwXfVU5Q8eUQFZ8A+siPtOASFjDumsIbseB5VzkF+UhvdseJwkX2+4pVFu8eHFDyvArYsHeGK6fBcQGJFQc2jSs6doIP9HD9IO2R ghelling@unknown38BAF87CD102" + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDv26EhyBZS9E5bcuZDHHkh/oeyINHXlsD3OEL1UjZekIsiHoMv2QHYq99cYO/CsTVGcZj4ZTOKxrQQ069Cm1II76nXJP9mb3+jip5QAE/zYSWfxi3SgQum95qmkQsx9mxeKFi4NfUU9qN9vpmJkn0hrvYWg8vU98bcYmkx4RtGW6EgZJed3347EtHshTqq3UfAbj3ErSQdCbEqgNOjokzGWmcx16HyyO5HoQj2FP7PGQmArzMz0V76BRsnpg97CoPKkoWoGk+P13BCWWXR9GCa2PbJ9uprzPa6Ib4+i9RJPdeSkUiLlFi6rBTHaZUT9WUIEaqNSq3bbu1bIqMXkifPeDw7m+TMfOBT8MUBciJaPlPTgXuz3T4kCHBI041hIt+/VqryGtxnT45IavyUaN3JWYntDbpG3eEW4N9IB2oGWuC/XuTJrsUaNpLPpApUKuozxhsFELBRepU+j+Wn4kgJJl8hy0n+WL63ZUee+/F23C7UNXoOc/wU3KbpxO6ipsTSkTzhZpQF2LOuA3JUs5t9ZaiCJ2P9r8axHiphCRcIYSbcCo3pZupf1eTDSXm+x9/UB2sfzErNEH4SdakoSdAi8jG8WhPVOs3BrIXjVBjvyBLeOH86EzBGR/Ba8X6MWoEW9Oau1C3P/z65VH8RHpvPvp6axlMynyVI1ygt5uheuQ== gregory.hellings@C02G48H8MD6R" + ]; + }; + + # Enable the OpenSSH daemon for remote control + services.openssh.enable = true; + + # Base packages that need to be in all my hosts + environment.systemPackages = with pkgs; [ + vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. + wget + git + home-manager + python3 + tmux + ]; + + i18n.defaultLocale = "en_US.UTF-8"; + + console = { + font = "Lat2-Terminus16"; + keyMap = "us"; + }; + + # Keep freespace available, at a minimum + nix.extraOptions = '' + min-free = ${toString (1024 * 1024 * 1024) } + max-free = ${toString (5 * 1024 * 1024 * 1024) } + ''; + # Use hardlinking instead of copying when possible + nix.autoOptimiseStore = true; + + # The set of default values, which allow syou to keep system defaults set + # to a predictable value as you upgrade the system + system.stateVersion = "21.11"; +} diff --git a/configuration.nix b/configuration.nix new file mode 100644 index 0000000..fe109b7 --- /dev/null +++ b/configuration.nix @@ -0,0 +1,14 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page +# and in the NixOS manual (accessible by running ‘nixos-help’). + +{ config, pkgs, ... }: + +{ + imports = + [ # Include the results of the hardware scan. + ./hardware-configuration.nix + ./base.nix + ./host/default.nix + ]; +} diff --git a/hosts/2maccabees/default.nix b/hosts/2maccabees/default.nix new file mode 100644 index 0000000..0b429fe --- /dev/null +++ b/hosts/2maccabees/default.nix @@ -0,0 +1,13 @@ +{ config, pkgs, ... }: + +{ + imports = [ + ./networking.nix + ./dnsmasq.nix + ./home-assistant.nix + ../profiles/rpi4.nix + ../profiles/home.nix + ]; + networking.hostName = "2maccabees"; + networking.domain = "home.thehellings.com"; +} diff --git a/hosts/2maccabees/dnsmasq.nix b/hosts/2maccabees/dnsmasq.nix new file mode 100644 index 0000000..efe0a0c --- /dev/null +++ b/hosts/2maccabees/dnsmasq.nix @@ -0,0 +1,65 @@ +{ config, pkgs, ... }: + +let + extraHosts = builtins.concatStringsSep "\n" [ + "10.42.0.1 switch" + "10.42.1.1 router" + "10.42.1.2 dns smart" + "10.42.1.3 printer" + "10.42.1.4 chronicles" + "10.42.1.12 tv" + ]; + + extraConfig = builtins.concatStringsSep "\n" [ + "expand-hosts" + "domain=thehellings.lan" + "log-dhcp" + "log-queries" + "addn-hosts=/etc/adblock_hosts" + +# "dhcp-range=eth0,10.42.0.1,10.42.1.255,255.255.0.0,static" + "dhcp-range=eth0,10.42.2.1,10.42.2.255,255.255.0.0,12h" + "dhcp-option=eth0,option:router,10.42.1.1" + "dhcp-option=eth0,option:dns-server,10.42.1.2" + "dhcp-option=eth0,option:domain-search,thehellings.lan" + + "dhcp-range=vlan66@eth0,192.168.66.3,192.168.66.150,255.255.255.0,12h" + "dhcp-option=vlan66@eth0,option:router,192.168.66.1" + "dhcp-option=vlan66@eth0,option:dns-server,192.168.66.2" + + "dhcp-range=vlan67@eth0,192.168.67.3,192.168.67.150,12h" + "dhcp-option=vlan67@eth0,option:router,192.168.67.1" + "dhcp-option=vlan67@eth0,option:dns-server,192.168.67.2" + ]; +in +{ + # Enable the service with its own configuration + services.dnsmasq = { + enable = true; + # Public AdGuard DNS servers + servers = [ + "94.140.14.14" + "94.140.15.15" + ]; + extraConfig = "${extraConfig}"; + }; + environment.systemPackages = [ pkgs.curl ]; + + # Regularly update DNS block list + services.cron = { + enable = true; + systemCronJobs = [ + "* * * * * root ( ${pkgs.curl}/bin/curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts && systemctl restart dnsmasq ) 2>&1 > /var/log/adblock.log" + ]; + }; + + # Allow traffic through + networking.firewall = { + enable = true; + allowedTCPPorts = [ 53 ]; + allowedUDPPorts = [ 53 67 ]; + }; + + # Custom host addition + networking.extraHosts = "${extraHosts}"; +} diff --git a/hosts/2maccabees/home-assistant.nix b/hosts/2maccabees/home-assistant.nix new file mode 100644 index 0000000..438ae4d --- /dev/null +++ b/hosts/2maccabees/home-assistant.nix @@ -0,0 +1,94 @@ +{ config, pkgs, ... }: + +let + #unstable-src = builtins.fetchTarball "https://github.com/NixOS/nixpkgs/archive/nixos-unstable.tar.gz"; + #unstable = import unstable-src {}; + unstable = import {}; +in +{ + #services.home-assistant = { + # enable = true; + # applyDefaultConfig = true; + # configWritable = true; + # configDir = "/var/lib/hass"; + # config = { + # default_config = {}; + # met = {}; + # frontend = {}; + # http = { + # use_x_forwarded_for = true; + # trusted_proxies = [ "127.0.0.1" "::1" ]; + # }; + # "map" = {}; + # cloud = {}; + # mobile_app = {}; + # }; + + # package = (unstable.home-assistant.override { + # extraComponents = [ + # "accuweather" + # "cast" + # "cloud" + # "default_config" + # "esphome" + # "google" + # "google_assistant" + # "roomba" + # "synology_dsm" + # "tplink" + # "wiz" + # "zwave_js" + # ]; + # extraPackages = py: with unstable.python39Packages; [ + # ifaddr + # ]; + # }).overrideAttrs (oldAttrs: { + # doInstallCheck = false; + # }); + # openFirewall = true; + #}; + + virtualisation.podman.enable = true; + + virtualisation.oci-containers = { + backend = "podman"; + containers."home-assistant" = { + image = "ghcr.io/home-assistant/home-assistant:stable"; + ports = [ "127.0.0.1:8123:8123" ]; + volumes = [ "/var/lib/hass:/config" ]; + extraOptions = [ + "--network" "podman" + "--network" "podman66:ip=192.168.66.193" + ]; + }; + }; + + #systemd.services.podman66 = { + #wantedBy = [ "podman-home-assistant.service" ]; + #serviceConfig = { + #Type = "oneshot"; + #ExecStart = '' + #${pkgs.podman}/bin/podman network create -d macvlan -o parent=vlan66 --subnet 192.168.66.0/24 --ip-range 192.168.66.192/26 --gateway 192.168.66.1 podman66 || true + #''; + #}; + #}; + + services.nginx = { + enable= true; + virtualHosts."smart.thehellings.lan".locations."/" = { + proxyPass = "http://127.0.0.1:8123"; + extraConfig = '' + proxy_set_header Host $host; + proxy_http_version 1.1; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header Upgrade $http_upgrade; + proxy_set_header Connection $connection_upgrade; + ''; + }; + }; + + networking.firewall = { + enable = true; + allowedTCPPorts = [ 80 8123 ]; + }; +} diff --git a/hosts/2maccabees/networking.nix b/hosts/2maccabees/networking.nix new file mode 100644 index 0000000..24e336d --- /dev/null +++ b/hosts/2maccabees/networking.nix @@ -0,0 +1,44 @@ +{ config, ... }: + +{ + networking = { + # This value is deprecated, you now set it per interface + useDHCP = false; + defaultGateway = "10.42.1.1"; + nameservers = [ "127.0.0.1" ]; + interfaces = { + eth0.ipv4.addresses = [ { + address = "10.42.1.2"; + prefixLength = 16; + } ]; + wlan0.useDHCP = true; + + vlan66.ipv4.addresses = [ { + address = "192.168.66.2"; + prefixLength = 24; + } ]; + + vlan67.ipv4.addresses = [ { + address = "192.168.67.2"; + prefixLength = 24; + } ]; + }; + + vlans = { + vlan66 = { + id = 66; + interface = "eth0"; + }; + vlan67 = { + id = 67; + interface = "eth0"; + }; + }; + }; + + # Open ports in the firewall. + # networking.firewall.allowedTCPPorts = [ ... ]; + # networking.firewall.allowedUDPPorts = [ ... ]; + # Or disable the firewall altogether. + # networking.firewall.enable = false; +} diff --git a/profiles/gnome.nix b/profiles/gnome.nix new file mode 100644 index 0000000..d2fc077 --- /dev/null +++ b/profiles/gnome.nix @@ -0,0 +1,27 @@ +{ config, pkgs, ... }: + +{ + # Sets up a basic Gnome installation + services.xserver = { + enable = true; + displayManager = { + gdm.enable = true; + gnome.enable = true; + }; + layout = "us"; + # Trackpad support + libinput.enable = true; + }; + + programs.dconf.enable = true; + + # Enable some Gnome plugins that I like + environment.systemPackages = with pkgs; [ + gnome3.adwaita-icon-theme + gnomeExtensions.appindicator + ]; + + services.udev.packages = with pkgs; [ + gnome3.gnome-settings-daemon + ]; +} diff --git a/profiles/home.nix b/profiles/home.nix new file mode 100644 index 0000000..295a451 --- /dev/null +++ b/profiles/home.nix @@ -0,0 +1,5 @@ +{ config, ... }: + +{ + time.timeZone = "America/Chicago"; +} diff --git a/profiles/rpi4.nix b/profiles/rpi4.nix new file mode 100644 index 0000000..3cdeb28 --- /dev/null +++ b/profiles/rpi4.nix @@ -0,0 +1,32 @@ +# Base configurations for Raspberry Pi 4s +{ config, pkgs, ... }: + +{ + boot = { + # This prevents us from having to compile our own kernel + kernelPackages = pkgs.linuxPackages_rpi4; + kernelParams = [ + "8250.nr_uarts=1" + "console=ttyAMA0,115200" + "console=tty1" + "cma=128M" + ]; + + loader = { + raspberryPi = { + enable = true; + version = 4; + }; + + # Use the extlinux boot loader. (NixOS wants to enable GRUB by default) + grub.enable = false; + + # Enables the generation of /boot/extlinux/extlinux.conf + #generic-extlinux-compatible.enable = true; + }; + }; + + environment.systemPackages = with pkgs; [ + raspberrypifw + ]; +}