Merge branch 'main' of gh:greg-hellings/nixos-config

This commit is contained in:
Greg Hellings
2022-06-12 00:32:14 -05:00
9 changed files with 51 additions and 30 deletions
+2
View File
@@ -42,6 +42,8 @@ in {
molcol = "molecule -c ../../tests/molecule.yml"; molcol = "molecule -c ../../tests/molecule.yml";
pa = "cd ~/src/packaging"; pa = "cd ~/src/packaging";
dirflake = "nix flake new -t github:nix-community/nix-direnv"; dirflake = "nix flake new -t github:nix-community/nix-direnv";
tsup = "tailscale up";
tspub = "tailscale up --exit-node=linode";
}; };
configHeader = '' configHeader = ''
+1
View File
@@ -10,6 +10,7 @@
]; ];
greg.home = false; greg.home = false;
greg.linode.enable = true; greg.linode.enable = true;
greg.tailscale.enable = true;
networking.hostName = "linode"; networking.hostName = "linode";
networking.domain = "thehellings.com"; networking.domain = "thehellings.com";
} }
-4
View File
@@ -30,8 +30,4 @@
enable = true; enable = true;
devices = [ "nas" ]; devices = [ "nas" ];
}; };
services.cron.systemCronJobs = [
"59 2 * * * root chmod -R a+r ${config.services.syncthing.folders.nextcloud-backup.path} && find ${config.services.syncthing.folders.nextcloud-backup.path} -type d -exec chmod a+x '{}' \\;"
];
} }
+2 -1
View File
@@ -5,7 +5,7 @@ in
{ {
security.acme = { security.acme = {
acceptTerms = true; acceptTerms = true;
email = "greg.hellings@gmail.com"; defaults.email = "greg.hellings@gmail.com";
}; };
services.nginx = { services.nginx = {
@@ -30,5 +30,6 @@ in
greg.proxies."thehellings.com" = { greg.proxies."thehellings.com" = {
target = "http://${homepage}/"; target = "http://${homepage}/";
ssl = true; ssl = true;
genAliases = false;
}; };
} }
+2 -6
View File
@@ -31,10 +31,10 @@ root root postgres
services.logrotate = { services.logrotate = {
enable = true; enable = true;
paths = { settings = {
postgres = { postgres = {
enable = true; enable = true;
path = "${config.services.postgresqlBackup.location}/*.gz"; files = "${config.services.postgresqlBackup.location}/*.gz";
}; };
}; };
}; };
@@ -44,8 +44,4 @@ root root postgres
enable = true; enable = true;
devices = [ "nas" ]; devices = [ "nas" ];
}; };
services.cron.systemCronJobs = [
"59 2 * * * root chmod -R a+r ${config.services.postgresqlBackup.location} && find ${config.services.postgresqlBackup.location} -type d -exec chmod a+x '{}' \\;"
];
} }
+22 -18
View File
@@ -74,26 +74,30 @@ return 200 '${builtins.toJSON client}';
services.matrix-synapse = { services.matrix-synapse = {
enable = true; enable = true;
database_name = "synapse";
database_user = "matrix-synapse";
# Identify ourselves as the root of our own domain # Identify ourselves as the root of our own domain
server_name = "thehellings.com"; settings = {
#registration_shared_secret = "B9EoPr2WV9hzwc7uL2Sx1JmvCeKDEOGCpB0uginQcQtEH4wzRtkSIdo7lltrjSQa"; database.args = {
# Bind a single listener to localhost only, disable SSL/TLS, and put user = "matrix-synapse";
# it behind an nginx proxy database = "synapse";
listeners = [ { };
port = 8448; server_name = "thehellings.com";
bind_address = "127.0.0.1"; #registration_shared_secret = "B9EoPr2WV9hzwc7uL2Sx1JmvCeKDEOGCpB0uginQcQtEH4wzRtkSIdo7lltrjSQa";
type = "http"; # Offload SSL/TLS to Nginx # Bind a single listener to localhost only, disable SSL/TLS, and put
tls = false; # it behind an nginx proxy
resources = [ { listeners = [ {
names = [ "client" "federation" ]; port = 8448;
compress = false; # Offload compressiong to Nginx bind_addresses = ["127.0.0.1"];
type = "http"; # Offload SSL/TLS to Nginx
tls = false;
resources = [ {
names = [ "client" "federation" ];
compress = false; # Offload compressiong to Nginx
} ];
} ]; } ];
} ]; app_service_config_files = [
app_service_config_files = [ "/etc/${fbRegistrationFile}"
"/etc/${fbRegistrationFile}" ];
]; };
}; };
# Open networking ports for the server # Open networking ports for the server
+1
View File
@@ -7,6 +7,7 @@
./linode.nix ./linode.nix
./proxy.nix ./proxy.nix
./rpi4.nix ./rpi4.nix
./tailscale.nix
./xprograms.nix ./xprograms.nix
]; ];
} }
+7 -1
View File
@@ -16,7 +16,7 @@ proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade; proxy_set_header Connection $connection_upgrade;
''; '';
}; };
serverAliases = [ "${alias name}" ]; serverAliases = lib.mkIf dest.genAliases [ "${alias name}" ];
}; };
in with lib; { in with lib; {
@@ -40,6 +40,12 @@ in with lib; {
{ name, config, options, ... }: { name, config, options, ... }:
{ {
options = { options = {
genAliases = mkOption {
type = types.bool;
description = "Whether to auto-generate short alias name";
default = true;
};
target = mkOption { target = mkOption {
type = types.str; type = types.str;
description = ''The destination that is being proxied.''; description = ''The destination that is being proxied.'';
+14
View File
@@ -0,0 +1,14 @@
{ lib, config, ... }:
let
cfg = config.greg.tailscale;
in {
options = {
greg.tailscale.enable = lib.mkEnableOption "Enable Tailscale";
};
config = lib.mkIf cfg.enable {
services.tailscale.enable = true;
networking.firewall.checkReversePath = "loose";
};
}