2maccabees setup
DNS setup with dnsmasq DHCP setup with dnsmasq Home Assistant setup
This commit is contained in:
@@ -0,0 +1,2 @@
|
||||
host
|
||||
hardware-configuration.nix
|
||||
@@ -0,0 +1,48 @@
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
{
|
||||
# I am a fan of network manager, myself
|
||||
networking.networkmanager.enable = true;
|
||||
|
||||
# Define a user account. Don't forget to set a password with ‘passwd’.
|
||||
users.users.greg = {
|
||||
isNormalUser = true;
|
||||
extraGroups = [ "wheel" "networkmanager" ]; # Enable ‘sudo’ for the user.
|
||||
openssh.authorizedKeys.keys = [
|
||||
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQDLQRq55JKqLifX+31kEXyuoB8gfM+5thAlgR7XLPvvdu6g2a5cCWyozQ1I2oGbPRfJtzcJ5ifM7Ii2PuqAj3MdYFLHBEDOhIpBBWme9Ts2YB9HJ4NorBvB4zEfJd0Q7k2MmylyeBOwdwGz3bVqPRDcJbxWFMDHqr33FEs6SXdfyAQ5SvhWGARI84qz8zUUdOp6M4e3aIGO3cx1gA+YzYQ4FbUtL8+m1NFO8VoNFMZBMf5q0iF/SgEu5bmGWUCePia6DvfeBFQ2/y4Y7WmOj980WE+JmFTkIvmGruMYeGI8FuDQ2JIIIcehddy9bQbPF4VlGnTFsHqJYVRUUWc+vH1cPNMn01oB8s27ogf9e1lyhIN+cZOgp/jDt4eXcO4Wr04uwj7CI6m+d8iMQOa5Jv0hmNgqqiwOMVBlKeo0FCxlovzwvn/Lia9WZ74JqM6JwLCD8SZ0oFgiSIHOTHrQhr7iaCmj7X/0ey7VR8FnCrpeAJpG+ELTfWGshF1d9QR2zW7u4EsXTDLiuOmdJ+/KxwMvjMcWdlg2+Qch6SwulTQRxWaED2IWJo+YiAql8eaiVXu/eZJGLoiskGFZnONoLrzIT4pSjakPlrSpn/M/GkP1pDpaMkr24OhJsGpJNEU3F1ZcOMqy2iJzIxlPmU8Xg0I/OrnbJplpaXeRCqnmouJUJhWkaPzawaVyW7dtvprLWcpQtUgTRet18WLyOrLKlq1jwvNRMTPKUJ2IFJMpk2pNEP6bdiUxyMa4vrRIEU2p1zsYSUJpCRLtccZ/i/+yAqwnTA2L5TdAORi9nD2uCdM/Ljz52V3A14QapS6oqcoWx2soWKgnsbVXoG8DxmUTpll77Ze9t7Y5216SMInWuOu0vstP8ZcgFmWsiBgIYIuLA58abWHMxgD251phYidua6R3Gtkf8J/kYqTR1P6eJF1bt5efEg7FD2aL1QQZsYJo3CRNz7yVe1XqMdPbfe2mFXQVF9TDX5x6r9Ir3d0KiEmTlBdByz8nSyPJ8IQxC58NT4LNVQs3p2XH2Zcf6B4JOBSmV4NNBnLseFobsxniWjkWwZigED/D2iu3OXuuhmskCbw0hKy2rBcKffaSNMioVqYIiYNfKlMlSvAacQKqc/1HCpqgX8PwAcSgNSLy4K7/gIrTHmjY+g+CH7onzatWzkLo+0vsZRa/D/qwhhK2CU2FeU07mhnWxWuzqpJuqVaAwDTaEforK7nQUtAOFAZZP6qGhIoqsynYt4THb+QORb3QYfaP0PVgQwXfVU5Q8eUQFZ8A+siPtOASFjDumsIbseB5VzkF+UhvdseJwkX2+4pVFu8eHFDyvArYsHeGK6fBcQGJFQc2jSs6doIP9HD9IO2R ghelling@unknown38BAF87CD102"
|
||||
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDv26EhyBZS9E5bcuZDHHkh/oeyINHXlsD3OEL1UjZekIsiHoMv2QHYq99cYO/CsTVGcZj4ZTOKxrQQ069Cm1II76nXJP9mb3+jip5QAE/zYSWfxi3SgQum95qmkQsx9mxeKFi4NfUU9qN9vpmJkn0hrvYWg8vU98bcYmkx4RtGW6EgZJed3347EtHshTqq3UfAbj3ErSQdCbEqgNOjokzGWmcx16HyyO5HoQj2FP7PGQmArzMz0V76BRsnpg97CoPKkoWoGk+P13BCWWXR9GCa2PbJ9uprzPa6Ib4+i9RJPdeSkUiLlFi6rBTHaZUT9WUIEaqNSq3bbu1bIqMXkifPeDw7m+TMfOBT8MUBciJaPlPTgXuz3T4kCHBI041hIt+/VqryGtxnT45IavyUaN3JWYntDbpG3eEW4N9IB2oGWuC/XuTJrsUaNpLPpApUKuozxhsFELBRepU+j+Wn4kgJJl8hy0n+WL63ZUee+/F23C7UNXoOc/wU3KbpxO6ipsTSkTzhZpQF2LOuA3JUs5t9ZaiCJ2P9r8axHiphCRcIYSbcCo3pZupf1eTDSXm+x9/UB2sfzErNEH4SdakoSdAi8jG8WhPVOs3BrIXjVBjvyBLeOH86EzBGR/Ba8X6MWoEW9Oau1C3P/z65VH8RHpvPvp6axlMynyVI1ygt5uheuQ== gregory.hellings@C02G48H8MD6R"
|
||||
];
|
||||
};
|
||||
|
||||
# Enable the OpenSSH daemon for remote control
|
||||
services.openssh.enable = true;
|
||||
|
||||
# Base packages that need to be in all my hosts
|
||||
environment.systemPackages = with pkgs; [
|
||||
vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default.
|
||||
wget
|
||||
git
|
||||
home-manager
|
||||
python3
|
||||
tmux
|
||||
];
|
||||
|
||||
i18n.defaultLocale = "en_US.UTF-8";
|
||||
|
||||
console = {
|
||||
font = "Lat2-Terminus16";
|
||||
keyMap = "us";
|
||||
};
|
||||
|
||||
# Keep freespace available, at a minimum
|
||||
nix.extraOptions = ''
|
||||
min-free = ${toString (1024 * 1024 * 1024) }
|
||||
max-free = ${toString (5 * 1024 * 1024 * 1024) }
|
||||
'';
|
||||
# Use hardlinking instead of copying when possible
|
||||
nix.autoOptimiseStore = true;
|
||||
|
||||
# The set of default values, which allow syou to keep system defaults set
|
||||
# to a predictable value as you upgrade the system
|
||||
system.stateVersion = "21.11";
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
# Edit this configuration file to define what should be installed on
|
||||
# your system. Help is available in the configuration.nix(5) man page
|
||||
# and in the NixOS manual (accessible by running ‘nixos-help’).
|
||||
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
{
|
||||
imports =
|
||||
[ # Include the results of the hardware scan.
|
||||
./hardware-configuration.nix
|
||||
./base.nix
|
||||
./host/default.nix
|
||||
];
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
{
|
||||
imports = [
|
||||
./networking.nix
|
||||
./dnsmasq.nix
|
||||
./home-assistant.nix
|
||||
../profiles/rpi4.nix
|
||||
../profiles/home.nix
|
||||
];
|
||||
networking.hostName = "2maccabees";
|
||||
networking.domain = "home.thehellings.com";
|
||||
}
|
||||
@@ -0,0 +1,65 @@
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
let
|
||||
extraHosts = builtins.concatStringsSep "\n" [
|
||||
"10.42.0.1 switch"
|
||||
"10.42.1.1 router"
|
||||
"10.42.1.2 dns smart"
|
||||
"10.42.1.3 printer"
|
||||
"10.42.1.4 chronicles"
|
||||
"10.42.1.12 tv"
|
||||
];
|
||||
|
||||
extraConfig = builtins.concatStringsSep "\n" [
|
||||
"expand-hosts"
|
||||
"domain=thehellings.lan"
|
||||
"log-dhcp"
|
||||
"log-queries"
|
||||
"addn-hosts=/etc/adblock_hosts"
|
||||
|
||||
# "dhcp-range=eth0,10.42.0.1,10.42.1.255,255.255.0.0,static"
|
||||
"dhcp-range=eth0,10.42.2.1,10.42.2.255,255.255.0.0,12h"
|
||||
"dhcp-option=eth0,option:router,10.42.1.1"
|
||||
"dhcp-option=eth0,option:dns-server,10.42.1.2"
|
||||
"dhcp-option=eth0,option:domain-search,thehellings.lan"
|
||||
|
||||
"dhcp-range=vlan66@eth0,192.168.66.3,192.168.66.150,255.255.255.0,12h"
|
||||
"dhcp-option=vlan66@eth0,option:router,192.168.66.1"
|
||||
"dhcp-option=vlan66@eth0,option:dns-server,192.168.66.2"
|
||||
|
||||
"dhcp-range=vlan67@eth0,192.168.67.3,192.168.67.150,12h"
|
||||
"dhcp-option=vlan67@eth0,option:router,192.168.67.1"
|
||||
"dhcp-option=vlan67@eth0,option:dns-server,192.168.67.2"
|
||||
];
|
||||
in
|
||||
{
|
||||
# Enable the service with its own configuration
|
||||
services.dnsmasq = {
|
||||
enable = true;
|
||||
# Public AdGuard DNS servers
|
||||
servers = [
|
||||
"94.140.14.14"
|
||||
"94.140.15.15"
|
||||
];
|
||||
extraConfig = "${extraConfig}";
|
||||
};
|
||||
environment.systemPackages = [ pkgs.curl ];
|
||||
|
||||
# Regularly update DNS block list
|
||||
services.cron = {
|
||||
enable = true;
|
||||
systemCronJobs = [
|
||||
"* * * * * root ( ${pkgs.curl}/bin/curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts && systemctl restart dnsmasq ) 2>&1 > /var/log/adblock.log"
|
||||
];
|
||||
};
|
||||
|
||||
# Allow traffic through
|
||||
networking.firewall = {
|
||||
enable = true;
|
||||
allowedTCPPorts = [ 53 ];
|
||||
allowedUDPPorts = [ 53 67 ];
|
||||
};
|
||||
|
||||
# Custom host addition
|
||||
networking.extraHosts = "${extraHosts}";
|
||||
}
|
||||
@@ -0,0 +1,94 @@
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
let
|
||||
#unstable-src = builtins.fetchTarball "https://github.com/NixOS/nixpkgs/archive/nixos-unstable.tar.gz";
|
||||
#unstable = import unstable-src {};
|
||||
unstable = import <nixos-unstable> {};
|
||||
in
|
||||
{
|
||||
#services.home-assistant = {
|
||||
# enable = true;
|
||||
# applyDefaultConfig = true;
|
||||
# configWritable = true;
|
||||
# configDir = "/var/lib/hass";
|
||||
# config = {
|
||||
# default_config = {};
|
||||
# met = {};
|
||||
# frontend = {};
|
||||
# http = {
|
||||
# use_x_forwarded_for = true;
|
||||
# trusted_proxies = [ "127.0.0.1" "::1" ];
|
||||
# };
|
||||
# "map" = {};
|
||||
# cloud = {};
|
||||
# mobile_app = {};
|
||||
# };
|
||||
|
||||
# package = (unstable.home-assistant.override {
|
||||
# extraComponents = [
|
||||
# "accuweather"
|
||||
# "cast"
|
||||
# "cloud"
|
||||
# "default_config"
|
||||
# "esphome"
|
||||
# "google"
|
||||
# "google_assistant"
|
||||
# "roomba"
|
||||
# "synology_dsm"
|
||||
# "tplink"
|
||||
# "wiz"
|
||||
# "zwave_js"
|
||||
# ];
|
||||
# extraPackages = py: with unstable.python39Packages; [
|
||||
# ifaddr
|
||||
# ];
|
||||
# }).overrideAttrs (oldAttrs: {
|
||||
# doInstallCheck = false;
|
||||
# });
|
||||
# openFirewall = true;
|
||||
#};
|
||||
|
||||
virtualisation.podman.enable = true;
|
||||
|
||||
virtualisation.oci-containers = {
|
||||
backend = "podman";
|
||||
containers."home-assistant" = {
|
||||
image = "ghcr.io/home-assistant/home-assistant:stable";
|
||||
ports = [ "127.0.0.1:8123:8123" ];
|
||||
volumes = [ "/var/lib/hass:/config" ];
|
||||
extraOptions = [
|
||||
"--network" "podman"
|
||||
"--network" "podman66:ip=192.168.66.193"
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
#systemd.services.podman66 = {
|
||||
#wantedBy = [ "podman-home-assistant.service" ];
|
||||
#serviceConfig = {
|
||||
#Type = "oneshot";
|
||||
#ExecStart = ''
|
||||
#${pkgs.podman}/bin/podman network create -d macvlan -o parent=vlan66 --subnet 192.168.66.0/24 --ip-range 192.168.66.192/26 --gateway 192.168.66.1 podman66 || true
|
||||
#'';
|
||||
#};
|
||||
#};
|
||||
|
||||
services.nginx = {
|
||||
enable= true;
|
||||
virtualHosts."smart.thehellings.lan".locations."/" = {
|
||||
proxyPass = "http://127.0.0.1:8123";
|
||||
extraConfig = ''
|
||||
proxy_set_header Host $host;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection $connection_upgrade;
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
networking.firewall = {
|
||||
enable = true;
|
||||
allowedTCPPorts = [ 80 8123 ];
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,44 @@
|
||||
{ config, ... }:
|
||||
|
||||
{
|
||||
networking = {
|
||||
# This value is deprecated, you now set it per interface
|
||||
useDHCP = false;
|
||||
defaultGateway = "10.42.1.1";
|
||||
nameservers = [ "127.0.0.1" ];
|
||||
interfaces = {
|
||||
eth0.ipv4.addresses = [ {
|
||||
address = "10.42.1.2";
|
||||
prefixLength = 16;
|
||||
} ];
|
||||
wlan0.useDHCP = true;
|
||||
|
||||
vlan66.ipv4.addresses = [ {
|
||||
address = "192.168.66.2";
|
||||
prefixLength = 24;
|
||||
} ];
|
||||
|
||||
vlan67.ipv4.addresses = [ {
|
||||
address = "192.168.67.2";
|
||||
prefixLength = 24;
|
||||
} ];
|
||||
};
|
||||
|
||||
vlans = {
|
||||
vlan66 = {
|
||||
id = 66;
|
||||
interface = "eth0";
|
||||
};
|
||||
vlan67 = {
|
||||
id = 67;
|
||||
interface = "eth0";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
# Open ports in the firewall.
|
||||
# networking.firewall.allowedTCPPorts = [ ... ];
|
||||
# networking.firewall.allowedUDPPorts = [ ... ];
|
||||
# Or disable the firewall altogether.
|
||||
# networking.firewall.enable = false;
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
{
|
||||
# Sets up a basic Gnome installation
|
||||
services.xserver = {
|
||||
enable = true;
|
||||
displayManager = {
|
||||
gdm.enable = true;
|
||||
gnome.enable = true;
|
||||
};
|
||||
layout = "us";
|
||||
# Trackpad support
|
||||
libinput.enable = true;
|
||||
};
|
||||
|
||||
programs.dconf.enable = true;
|
||||
|
||||
# Enable some Gnome plugins that I like
|
||||
environment.systemPackages = with pkgs; [
|
||||
gnome3.adwaita-icon-theme
|
||||
gnomeExtensions.appindicator
|
||||
];
|
||||
|
||||
services.udev.packages = with pkgs; [
|
||||
gnome3.gnome-settings-daemon
|
||||
];
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
{ config, ... }:
|
||||
|
||||
{
|
||||
time.timeZone = "America/Chicago";
|
||||
}
|
||||
@@ -0,0 +1,32 @@
|
||||
# Base configurations for Raspberry Pi 4s
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
{
|
||||
boot = {
|
||||
# This prevents us from having to compile our own kernel
|
||||
kernelPackages = pkgs.linuxPackages_rpi4;
|
||||
kernelParams = [
|
||||
"8250.nr_uarts=1"
|
||||
"console=ttyAMA0,115200"
|
||||
"console=tty1"
|
||||
"cma=128M"
|
||||
];
|
||||
|
||||
loader = {
|
||||
raspberryPi = {
|
||||
enable = true;
|
||||
version = 4;
|
||||
};
|
||||
|
||||
# Use the extlinux boot loader. (NixOS wants to enable GRUB by default)
|
||||
grub.enable = false;
|
||||
|
||||
# Enables the generation of /boot/extlinux/extlinux.conf
|
||||
#generic-extlinux-compatible.enable = true;
|
||||
};
|
||||
};
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
raspberrypifw
|
||||
];
|
||||
}
|
||||
Reference in New Issue
Block a user