Merge branch 'main' of gh:greg-hellings/nixos-config

This commit is contained in:
Greg Hellings
2024-06-20 14:36:01 -05:00
47 changed files with 1607 additions and 343 deletions
+21
View File
@@ -0,0 +1,21 @@
{
fsid = "749bf0ea-acf5-4a5e-b33e-9a057455c06b";
clusterName = "home";
initialMonitors = [ {
hostname = "myself.thehellings.lan";
ipAddress = "10.42.1.6";
} {
hostname = "jeremiah.thehellings.lan";
ipAddress = "10.42.1.8";
} {
hostname = "hosea.thehellings.lan";
ipAddress = "10.42.1.7";
} ];
mdsNodes = [ {
hostname = "jeremiah.thehellings.lan";
ipAddress = "10.42.1.8";
} ];
publicNetworks = [ "10.42.0.0/16" ];
clusterNetworks = [ "10.201.0.0/16" ];
adminKeyring = ../secrets/home.client.admin.keyring;
}
Generated
+209 -204
View File
@@ -10,11 +10,11 @@
"systems": "systems"
},
"locked": {
"lastModified": 1707830867,
"narHash": "sha256-PAdwm5QqdlwIqGrfzzvzZubM+FXtilekQ/FA0cI49/o=",
"lastModified": 1712079060,
"narHash": "sha256-/JdiT9t+zzjChc5qQiF+jhrVhRt8figYH29rZO7pFe4=",
"owner": "ryantm",
"repo": "agenix",
"rev": "8cb01a0e717311680e0cbca06a76cbceba6f3ed6",
"rev": "1381a759b205dff7a6818733118d02253340fd5e",
"type": "github"
},
"original": {
@@ -52,11 +52,11 @@
]
},
"locked": {
"lastModified": 1705915768,
"narHash": "sha256-+Jlz8OAqkOwJlioac9wtpsCnjgGYUhvLpgJR/5tP9po=",
"lastModified": 1717976995,
"narHash": "sha256-u3HBinyIyUvL1+N816bODpJmSQdgn0Mbb8BprFw7kqo=",
"owner": "lnl7",
"repo": "nix-darwin",
"rev": "1e706ef323de76236eb183d7784f3bd57255ec0b",
"rev": "315aa649ba307704db0b16c92f097a08a65ec955",
"type": "github"
},
"original": {
@@ -66,7 +66,43 @@
"type": "github"
}
},
"devshell": {
"inputs": {
"flake-utils": "flake-utils_2",
"nixpkgs": [
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1717408969,
"narHash": "sha256-Q0OEFqe35fZbbRPPRdrjTUUChKVhhWXz3T9ZSKmaoVY=",
"owner": "numtide",
"repo": "devshell",
"rev": "1ebbe68d57457c8cae98145410b164b5477761f4",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "devshell",
"type": "github"
}
},
"flake-compat": {
"locked": {
"lastModified": 1696426674,
"narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=",
"rev": "0f9255e01c2351cc7d116c072cb317785dd33b33",
"revCount": 57,
"type": "tarball",
"url": "https://api.flakehub.com/f/pinned/edolstra/flake-compat/1.0.1/018afb31-abd1-7bff-a5e4-cff7e18efb7a/source.tar.gz"
},
"original": {
"type": "tarball",
"url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz"
}
},
"flake-compat_2": {
"flake": false,
"locked": {
"lastModified": 1696426674,
@@ -82,16 +118,53 @@
"type": "github"
}
},
"flake-compat_3": {
"flake": false,
"locked": {
"lastModified": 1696426674,
"narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "0f9255e01c2351cc7d116c072cb317785dd33b33",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-parts": {
"inputs": {
"nixpkgs-lib": [
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1717285511,
"narHash": "sha256-iKzJcpdXih14qYVcZ9QC9XuZYnPc6T8YImb6dX166kw=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "2a55567fcf15b1b1c7ed712a2c6fadaec7412ea8",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"flake-utils": {
"inputs": {
"systems": "systems_2"
},
"locked": {
"lastModified": 1694529238,
"narHash": "sha256-zsNZZGTGnMOf9YpHKJqMSsa0dXbfmxeoJ7xHlrt+xmY=",
"lastModified": 1710146030,
"narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "ff7b65b44d01cf9ba6a71320833626af21126384",
"rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a",
"type": "github"
},
"original": {
@@ -105,11 +178,11 @@
"systems": "systems_3"
},
"locked": {
"lastModified": 1705309234,
"narHash": "sha256-uNRRNRKmJyCRC/8y1RqBkqWBLM034y4qN7EprSdmgyA=",
"lastModified": 1701680307,
"narHash": "sha256-kAuep2h5ajznlPMD9rnQyffWG8EM/C73lejGofXvdM8=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "1ef2e671c3b0c19053962c07dbda38332dcebf26",
"rev": "4022d587cbbfd70fe950c1e2083a02621806a725",
"type": "github"
},
"original": {
@@ -123,11 +196,11 @@
"systems": "systems_4"
},
"locked": {
"lastModified": 1705309234,
"narHash": "sha256-uNRRNRKmJyCRC/8y1RqBkqWBLM034y4qN7EprSdmgyA=",
"lastModified": 1710146030,
"narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "1ef2e671c3b0c19053962c07dbda38332dcebf26",
"rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a",
"type": "github"
},
"original": {
@@ -136,22 +209,52 @@
"type": "github"
}
},
"haumea": {
"git-hooks": {
"inputs": {
"nixpkgs": "nixpkgs"
"flake-compat": "flake-compat_2",
"gitignore": "gitignore",
"nixpkgs": [
"nixvim",
"nixpkgs"
],
"nixpkgs-stable": [
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1685133229,
"narHash": "sha256-FePm/Gi9PBSNwiDFq3N+DWdfxFq0UKsVVTJS3cQPn94=",
"owner": "nix-community",
"repo": "haumea",
"rev": "34dd58385092a23018748b50f9b23de6266dffc2",
"lastModified": 1717664902,
"narHash": "sha256-7XfBuLULizXjXfBYy/VV+SpYMHreNRHk9nKMsm1bgb4=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "cc4d466cb1254af050ff7bdf47f6d404a7c646d1",
"type": "github"
},
"original": {
"owner": "nix-community",
"ref": "v0.2.2",
"repo": "haumea",
"owner": "cachix",
"repo": "git-hooks.nix",
"type": "github"
}
},
"gitignore": {
"inputs": {
"nixpkgs": [
"nixvim",
"git-hooks",
"nixpkgs"
]
},
"locked": {
"lastModified": 1709087332,
"narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=",
"owner": "hercules-ci",
"repo": "gitignore.nix",
"rev": "637db329424fd7e46cf4185293b9cc8c88c95394",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "gitignore.nix",
"type": "github"
}
},
@@ -162,16 +265,16 @@
]
},
"locked": {
"lastModified": 1705659542,
"narHash": "sha256-WA3xVfAk1AYmFdwghT7mt/erYpsU6JPu9mdTEP/e9HQ=",
"lastModified": 1717527182,
"narHash": "sha256-vWSkg6AMok1UUQiSYVdGMOXKD2cDFnajITiSi0Zjd1A=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "10cd9c53115061aa6a0a90aad0b0dde6a999cdb9",
"rev": "845a5c4c073f74105022533907703441e0464bc3",
"type": "github"
},
"original": {
"owner": "nix-community",
"ref": "release-23.11",
"ref": "release-24.05",
"repo": "home-manager",
"type": "github"
}
@@ -183,11 +286,11 @@
]
},
"locked": {
"lastModified": 1706798041,
"narHash": "sha256-BbvuF4CsVRBGRP8P+R+JUilojk0M60D7hzqE0bEvJBQ=",
"lastModified": 1717931644,
"narHash": "sha256-Sz8Wh9cAiD5FhL8UWvZxBfnvxETSCVZlqWSYWaCPyu0=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "4d53427bce7bf3d17e699252fd84dc7468afc46e",
"rev": "3d65009effd77cb0d6e7520b68b039836a7606cf",
"type": "github"
},
"original": {
@@ -221,16 +324,16 @@
"home-manager_2": {
"inputs": {
"nixpkgs": [
"nixneovim",
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1705535278,
"narHash": "sha256-V5+XKfNbiY0bLKLQlH+AXyhHttEL7XcZBH9iSbxxexA=",
"lastModified": 1717525419,
"narHash": "sha256-5z2422pzWnPXHgq2ms8lcCfttM0dz+hg+x1pCcNkAws=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "b84191db127c16a92cbdf7f7b9969d58bb456699",
"rev": "a7117efb3725e6197dd95424136f79147aa35e5b",
"type": "github"
},
"original": {
@@ -239,51 +342,34 @@
"type": "github"
}
},
"nix-flake-tests": {
"locked": {
"lastModified": 1677844186,
"narHash": "sha256-ErJZ/Gs1rxh561CJeWP5bohA2IcTq1rDneu1WT6CVII=",
"owner": "antifuchs",
"repo": "nix-flake-tests",
"rev": "bbd9216bd0f6495bb961a8eb8392b7ef55c67afb",
"type": "github"
},
"original": {
"owner": "antifuchs",
"repo": "nix-flake-tests",
"type": "github"
}
},
"nix-github-actions": {
"nix-darwin": {
"inputs": {
"nixpkgs": [
"nixneovim",
"nixneovimplugins",
"poetry2nix",
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1688870561,
"narHash": "sha256-4UYkifnPEw1nAzqqPOTL2MvWtm3sNGw1UTYTalkTcGY=",
"owner": "nix-community",
"repo": "nix-github-actions",
"rev": "165b1650b753316aa7f1787f3005a8d2da0f5301",
"lastModified": 1716993688,
"narHash": "sha256-vo5k2wQekfeoq/2aleQkBN41dQiQHNTniZeVONWiWLs=",
"owner": "lnl7",
"repo": "nix-darwin",
"rev": "c0d5b8c54d6828516c97f6be9f2d00c63a363df4",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nix-github-actions",
"owner": "lnl7",
"repo": "nix-darwin",
"type": "github"
}
},
"nix23_05": {
"locked": {
"lastModified": 1702759837,
"narHash": "sha256-u3XeJVRe/Q975nwFE+6ALEwypMKJEELMJKDAhSKyq3M=",
"lastModified": 1704290814,
"narHash": "sha256-LWvKHp7kGxk/GEtlrGYV68qIvPHkU9iToomNFGagixU=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "b2566f4f897ac6224e094b167d9488d03e157f28",
"rev": "70bdadeb94ffc8806c0570eb5c2695ad29f0e421",
"type": "github"
},
"original": {
@@ -293,83 +379,17 @@
"type": "github"
}
},
"nixneovim": {
"inputs": {
"flake-utils": "flake-utils_2",
"haumea": "haumea",
"home-manager": "home-manager_2",
"nix-flake-tests": "nix-flake-tests",
"nixneovimplugins": "nixneovimplugins",
"nixpkgs": "nixpkgs_2",
"nmd": "nmd",
"nmt": "nmt"
},
"locked": {
"lastModified": 1705702328,
"narHash": "sha256-yDPcAUzGlQ4e7JKHVligTUpXcB2X18QNOrA5pzmeus0=",
"owner": "NixNeovim",
"repo": "NixNeovim",
"rev": "30e3b1854039a16d8fd08a1ed3f5aaf6c114060e",
"type": "github"
},
"original": {
"owner": "NixNeovim",
"repo": "NixNeovim",
"type": "github"
}
},
"nixneovimplugins": {
"inputs": {
"flake-utils": [
"nixneovim",
"flake-utils"
],
"nixpkgs": [
"nixneovim",
"nixpkgs"
],
"poetry2nix": "poetry2nix"
},
"locked": {
"lastModified": 1705344848,
"narHash": "sha256-Ns//Yrqug/OmupDUS4ue1tTvv4/UmLtY9oI6dIeWcMM=",
"owner": "nixneovim",
"repo": "nixneovimplugins",
"rev": "1054b77f33b54727082fb17170ce91d121b8a496",
"type": "github"
},
"original": {
"owner": "nixneovim",
"repo": "nixneovimplugins",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1681001314,
"narHash": "sha256-5sDnCLdrKZqxLPK4KA8+f4A3YKO/u6ElpMILvX0g72c=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "367c0e1086a4eb4502b24d872cea2c7acdd557f4",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixpkgs.lib",
"type": "github"
}
},
"nixpkgs_2": {
"locked": {
"lastModified": 1705496572,
"narHash": "sha256-rPIe9G5EBLXdBdn9ilGc0nq082lzQd0xGGe092R/5QE=",
"owner": "nixos",
"lastModified": 1717786204,
"narHash": "sha256-4q0s6m0GUcN7q+Y2DqD27iLvbcd1G50T2lv08kKxkSI=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "842d9d80cfd4560648c785f8a4e6f3b096790e19",
"rev": "051f920625ab5aabe37c920346e3e69d7d34400e",
"type": "github"
},
"original": {
"owner": "nixos",
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
@@ -377,27 +397,27 @@
},
"nixstable": {
"locked": {
"lastModified": 1708831307,
"narHash": "sha256-0iL/DuGjiUeck1zEaL+aIe2WvA3/cVhp/SlmTcOZXH4=",
"lastModified": 1717952948,
"narHash": "sha256-mJi4/gjiwQlSaxjA6AusXBN/6rQRaPCycR7bd8fydnQ=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "5bf1cadb72ab4e77cb0b700dab76bcdaf88f706b",
"rev": "2819fffa7fa42156680f0d282c60d81e8fb185b7",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-23.11",
"ref": "nixos-24.05",
"repo": "nixpkgs",
"type": "github"
}
},
"nixunstable": {
"locked": {
"lastModified": 1709961763,
"narHash": "sha256-6H95HGJHhEZtyYA3rIQpvamMKAGoa8Yh2rFV29QnuGw=",
"lastModified": 1717786204,
"narHash": "sha256-4q0s6m0GUcN7q+Y2DqD27iLvbcd1G50T2lv08kKxkSI=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "3030f185ba6a4bf4f18b87f345f104e6a6961f34",
"rev": "051f920625ab5aabe37c920346e3e69d7d34400e",
"type": "github"
},
"original": {
@@ -407,46 +427,38 @@
"type": "github"
}
},
"nmd": {
"flake": false,
"locked": {
"lastModified": 1672949361,
"narHash": "sha256-WWg1kbilAb3sA+RoJtSYfAZvyYu1Nk79ocHaerwbQxQ=",
"owner": "~rycee",
"repo": "nmd",
"rev": "fb9cf8e991487c6923f3c654b8ae51b6f0f205ce",
"type": "sourcehut"
"nixvim": {
"inputs": {
"devshell": "devshell",
"flake-compat": "flake-compat",
"flake-parts": "flake-parts",
"git-hooks": "git-hooks",
"home-manager": "home-manager_2",
"nix-darwin": "nix-darwin",
"nixpkgs": "nixpkgs",
"treefmt-nix": "treefmt-nix"
},
"original": {
"owner": "~rycee",
"repo": "nmd",
"rev": "fb9cf8e991487c6923f3c654b8ae51b6f0f205ce",
"type": "sourcehut"
}
},
"nmt": {
"flake": false,
"locked": {
"lastModified": 1694274695,
"narHash": "sha256-PufoLMSuBYkga8hTqYf/cIQzSuy2lfFj+cdKcp2nLEI=",
"owner": "jooooscha",
"repo": "nmt",
"rev": "29595267923b4a6ce766ff0d85afaa930842b88d",
"lastModified": 1718028681,
"narHash": "sha256-C27X1vnsxKaKd1dCUU/u3LU+3DiA3Jo/ApvDiDNPIrI=",
"owner": "nix-community",
"repo": "nixvim",
"rev": "33a32c94176feebd3ff5259ce418b989b428d5ae",
"type": "github"
},
"original": {
"owner": "jooooscha",
"repo": "nmt",
"owner": "nix-community",
"repo": "nixvim",
"type": "github"
}
},
"nurpkgs": {
"locked": {
"lastModified": 1706910257,
"narHash": "sha256-w0EN3LJS+4HlkTBb3rgImSWCkzNdFWxsIbgsYpKh09E=",
"lastModified": 1718026702,
"narHash": "sha256-B62vRJYFK7x5pJKDvXCIRgKcAS9K/KwoTBYAECfb81A=",
"owner": "nix-community",
"repo": "NUR",
"rev": "96b0e9d38890afb8e4af6d6a556ee27e79fd6e22",
"rev": "f7e5fe023ea5742a1db039b6ba17f717ef24cc0f",
"type": "github"
},
"original": {
@@ -455,34 +467,6 @@
"type": "github"
}
},
"poetry2nix": {
"inputs": {
"flake-utils": [
"nixneovim",
"nixneovimplugins",
"flake-utils"
],
"nix-github-actions": "nix-github-actions",
"nixpkgs": [
"nixneovim",
"nixneovimplugins",
"nixpkgs"
]
},
"locked": {
"lastModified": 1689849924,
"narHash": "sha256-d259Z2S7CS7Na04qQNQ6LYQILuI7cf4Rpe76qc4mz40=",
"owner": "nix-community",
"repo": "poetry2nix",
"rev": "1d7eda9336f336392d24e9602be5cb9be7ae405c",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "poetry2nix",
"type": "github"
}
},
"root": {
"inputs": {
"agenix": "agenix",
@@ -491,9 +475,9 @@
"hm": "hm",
"hmunstable": "hmunstable",
"nix23_05": "nix23_05",
"nixneovim": "nixneovim",
"nixstable": "nixstable",
"nixunstable": "nixunstable",
"nixvim": "nixvim",
"nurpkgs": "nurpkgs",
"wsl": "wsl"
}
@@ -558,20 +542,41 @@
"type": "github"
}
},
"treefmt-nix": {
"inputs": {
"nixpkgs": [
"nixvim",
"nixpkgs"
]
},
"locked": {
"lastModified": 1717850719,
"narHash": "sha256-npYqVg+Wk4oxnWrnVG7416fpfrlRhp/lQ6wQ4DHI8YE=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "4fc1c45a5f50169f9f29f6a98a438fb910b834ed",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "treefmt-nix",
"type": "github"
}
},
"wsl": {
"inputs": {
"flake-compat": "flake-compat",
"flake-compat": "flake-compat_3",
"flake-utils": "flake-utils_3",
"nixpkgs": [
"nixunstable"
]
},
"locked": {
"lastModified": 1709211223,
"narHash": "sha256-1cjd+yXbTlnCwNwEDjn289rJ2f0er5M8pOig4PxniEM=",
"lastModified": 1713528946,
"narHash": "sha256-IBQta+xrEaI2S5UmYrXcgV7Tu7rGLQu2V3TeJseLPSg=",
"owner": "nix-community",
"repo": "NixOS-WSL",
"rev": "3257ad7f173b0314c8a42fec450fa6556495b97c",
"rev": "63c1247e12f269396ed2df8cdec3aed1f0f3928c",
"type": "github"
},
"original": {
+4 -5
View File
@@ -15,16 +15,16 @@
};
flake-utils.url = "github:numtide/flake-utils";
hm = {
url = "github:nix-community/home-manager/release-23.11";
url = "github:nix-community/home-manager/release-24.05";
inputs.nixpkgs.follows = "nixstable";
};
hmunstable = {
url = "github:nix-community/home-manager/master";
inputs.nixpkgs.follows = "nixstable";
};
nixneovim.url = "github:NixNeovim/NixNeovim";
nixvim.url = "github:nix-community/nixvim";
nix23_05.url = "github:NixOS/nixpkgs/nixos-23.05";
nixstable.url = "github:nixos/nixpkgs/nixos-23.11";
nixstable.url = "github:nixos/nixpkgs/nixos-24.05";
nixunstable.url = "github:nixos/nixpkgs/nixos-unstable";
nurpkgs.url = "github:nix-community/NUR";
wsl = {
@@ -39,10 +39,10 @@
flake-utils,
hm,
hmunstable,
nixneovim,
nix23_05,
nixstable,
nixunstable,
nixvim,
nurpkgs,
wsl,
@@ -58,7 +58,6 @@
agenix.overlays.default
pkg-sets
local_overlay
nixneovim.overlays.default
nurpkgs.overlay
];
+15 -10
View File
@@ -5,30 +5,35 @@
{
imports =
[ (modulesPath + "/profiles/qemu-guest.nix")
[ (modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "sr_mod" "virtio_blk" ];
boot.initrd.availableKernelModules = [ "xhci_pci" "thunderbolt" "nvme" "uas" "sd_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/disk/by-uuid/a13f941e-4985-47ab-a8c6-374a627c5ce1";
fsType = "ext4";
{ device = "/dev/disk/by-uuid/607b933f-2967-4652-b478-4d8e9aa38a0d";
fsType = "btrfs";
options = [ "subvol=@" ];
};
swapDevices =
[ { device = "/dev/disk/by-uuid/ac4557de-1ad5-4d3c-b9f4-5ec50dbf76f1"; }
];
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/B31C-C1F4";
fsType = "vfat";
};
swapDevices = [ ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.ens18.useDHCP = lib.mkDefault true;
# networking.interfaces.ens19.useDHCP = lib.mkDefault true;
# networking.interfaces.enp0s13f0u1.useDHCP = lib.mkDefault true;
# networking.interfaces.wlp170s0.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
+4 -1
View File
@@ -3,9 +3,12 @@
host ? "most",
...}:
let
system = pkgs.system;
in
{
imports = [
inputs.nixneovim.nixosModules.default
inputs.nixvim.homeManagerModules.default
./modules
./ansible.nix
./bash.nix
+6
View File
@@ -0,0 +1,6 @@
{ pkgs, config, ... }:
{
greg.gnome = true;
greg.gui = true;
}
+1 -2
View File
@@ -5,7 +5,6 @@ let
djangorestframework
django-rapyd-modernauth
environs
#itg-django-utils
mysqlclient
pyyaml
ruamel-yaml
@@ -20,8 +19,8 @@ in {
home = {
packages = with pkgs; [
aacs
ansible
bitwarden-cli
bruno
direnv
home-manager
insomnia
+2 -2
View File
@@ -14,7 +14,7 @@ let
vars = {
MOZ_ENABLE_WAYLAND = "1";
XDG_CURRENT_DESKTOP = "sway";
XDG_CURRENT_DESKTOP = "GNOME";
};
in {
options.greg.gui = lib.mkEnableOption "Enable GUI programs";
@@ -69,7 +69,7 @@ in {
};
extensions = with pkgs.nur.repos.rycee.firefox-addons; [
bitwarden
bypass-paywalls-clean
#bypass-paywalls-clean
gsconnect
foxyproxy-standard
multi-account-containers
+1
View File
@@ -5,3 +5,4 @@ ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINnRc/kBhxcjpUtiRQY+BXnSObdp0jFL1395wAQxJip7
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAl6DJVrPSujvJSAEA5Q8tRrzfJs/c6DMwqwQEUFffIR greg@myself
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGrqJQvDspLi1vXQRJ/Z5kN/F8jCBHvaXjo+5zLuIYjR greg@hosea
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIYIiecdyM9c7tXgR96983K3wqiJeQRMbrzGIF8Wy6uO greg@jeremiah
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC189EnvWjNUp3xSzPMAtw85oQEsvP1tQR1TK640nLx6 greg@exodus
+28 -23
View File
@@ -27,20 +27,18 @@ in
pyright
];
programs.nixneovim = {
programs.nixvim = {
enable = true;
colorscheme = "gruvbox";
colorschemes.gruvbox.enable = true;
globals = {
indent_guides_enable_on_vim_startup = 1;
nix_recommended_style = 0;
NERDTreeIgnore = [
"\\.pyc$"
"\\.pyo$"
"\\.o$"
"\\.class$"
];
netrw_liststyle = 3;
netrw_browse_split = 4;
netrw_altv = 1;
netrw_winsize = 25;
};
options = {
opts = {
background = "dark";
backup = false;
copyindent = true;
@@ -68,22 +66,30 @@ in
wrap = false;
writebackup = false;
};
mappings = {
normalVisualOp = {
"<F2>" = ''"<Esc>:BufExplorer<CR>"'';
"<F4>" = ''"<Esc>:NERDTreeToggle<CR>"'';
"<F6>" = ''"<Esc>:Files<CR>"'';
"<C-j>" = ''"<C-w>j<C-w><CR>"'';
"<C-k>" = ''"<C-w>k<C-w><CR>"'';
"<C-h>" = ''"<C-w>h<C-w><CR>"'';
"<C-l>" = ''"<C-w>l<C-w><CR>"'';
"<C-o>" = ''":GFiles?<CR>"'';
};
};
keymaps = let
winMove = key: { mode = "n"; key = "<C-${key}>"; action = "<C-w>${key}<C-w><CR>"; };
in [ {
mode = "n";
key = "<C-e>";
action = "<Esc>:BufExplorer<CR>";
} {
mode = "n";
key = "<C-t>";
action = "<Esc>:Lex<CR>";
} {
mode = "n";
key = "<C-o>";
action = "<Esc>:GFiles?<CR>";
}
(winMove "h")
(winMove "j")
(winMove "k")
(winMove "l")
];
plugins = {
airline = {
enable = true;
theme = "gruvbox";
settings.theme = "gruvbox";
};
gitgutter.enable = true;
fugitive.enable = true;
@@ -94,7 +100,6 @@ in
extraPlugins = with pkgs.vimPlugins; [
bufexplorer
gruvbox
nerdtree
nvim-cmp
packer-nvim
+2 -1
View File
@@ -11,15 +11,16 @@
enable = true;
package = pkgs.vscodium;
extensions = with pkgs.vscode-extensions; [
arrterian.nix-env-selector
asvetliakov.vscode-neovim
bungcip.better-toml
golang.go
jnoortheen.nix-ide
mkhl.direnv
ms-python.python
vscjava.vscode-java-test
vscjava.vscode-java-dependency
vscjava.vscode-java-debug
vscodevim.vim
];
};
}
+9 -9
View File
@@ -5,18 +5,10 @@
enable = true;
sessionVariables = {
TIMEFORMAT = "%3Uu %3Ss %3lR %P%%";
CLICOLOR = 1;
LSCOLORS = "ExGxBxDxCxEgEdxbxgxcxd";
EDITOR = "${pkgs.vim}/bin/vim";
# Tells vox where to find virtualenvs
VIRTUALENV_HOME = "${config.home.homeDirectory}/venv/";
# vte_new_tab_cwd causes new Terminal tabs to open in the
# same CWD as the current tab
PROMPT = "{vte_new_tab_cwd}{env_name}{BOLD_GREEN}{user}@{hostname}{BOLD_BLUE} {short_cwd}{branch_color}{curr_branch: {}}{RESET} {BOLD_BLUE}{prompt_end}{RESET} ";
SWORD_PATH = "${config.home.homeDirectory}/.sword/";
OS_CLOUD = "default";
MAVEN_OPTS = " -Dmaven.wagon.http.ssl.insecure=true";
LESS_TERMCAP_mb = "\\033[01;31m"; # begin blinking
LESS_TERMCAP_md = "\\033[01;31m"; # begin bold
LESS_TERMCAP_me = "\\033[0m"; # end mode
@@ -24,6 +16,15 @@
LESS_TERMCAP_se = "\\033[0m"; # end standout-mode
LESS_TERMCAP_us = "\\033[00;36m"; # begin underline
LESS_TERMCAP_ue = "\\033[0m"; # end underline
LIBMYSQL_ENABLE_CLEARTEXT_PLUGIN = "1";
LSCOLORS = "ExGxBxDxCxEgEdxbxgxcxd";
MAVEN_OPTS = " -Dmaven.wagon.http.ssl.insecure=true";
OS_CLOUD = "default";
PROMPT = "{vte_new_tab_cwd}{env_name}{BOLD_GREEN}{user}@{hostname}{BOLD_BLUE} {short_cwd}{branch_color}{curr_branch: {}}{RESET} {BOLD_BLUE}{prompt_end}{RESET} ";
SWORD_PATH = "${config.home.homeDirectory}/.sword/";
TIMEFORMAT = "%3Uu %3Ss %3lR %P%%";
# Tells vox where to find virtualenvs
VIRTUALENV_HOME = "${config.home.homeDirectory}/venv/";
COMPASS_SKIP_ORIGIN_CHECK = "True";
@@ -41,7 +42,6 @@
cci = "compass workspace run src/python3/uc/tools:circleci-checks";
ccover = "compass workspace cover --extra-cmd-args=\"--test_output=errors\"";
cexec = "compass workspace exec";
cfetch = "compass workspace exec bazel run src/go/compass.com/tools/circleci_results_cache/fetch/cmd/fetch:fetch";
cgh = "$GH_CONFIG_DIR=\"${config.home.homeDirectory}/.config/gh/compass\" gh";
cpip = "compass workspace run src/python3/uc/tools:run_pip_compile";
crun = "compass workspace run";
+21
View File
@@ -1,5 +1,25 @@
# vim: set ft=python :
def bw_unlock():
"""Unlocks the BitWarden CLI and adds the resulting session code to the
current environment variables. Also returns the code for them."""
if "BW_SESSION" in ${...}:
return $BW_SESSION
result = $(bw unlock)
while "BW_SESSION" not in result:
result = $(bw unlock)
lines = result.split("\n")
l = [k for k in lines if 'BW_SESSION="' in k][0]
left, right = l.split("=", 1)
token = right[1:-1]
$BW_SESSION = token
return token
def _cfetch(args):
bw_unlock()
$CIRCLECI_CLI_TOKEN=$(bw get password CircleCI)
compass workspace exec bazel run src/go/compass.com/tools/circleci_results_cache/fetch/cmd/fetch:fetch
def _rebuild(args):
system = uname()
if system.sysname == 'Darwin':
@@ -48,6 +68,7 @@ def _bake(args):
git clone src:greg/copier-templates.git ~/.copier-templates
copier copy @(str(templates / args[0])) .
aliases['cfetch'] = _cfetch
aliases['bake'] = _bake
aliases['rebuild'] = _rebuild
aliases['yaml2json'] = _yaml2json
+1
View File
@@ -39,6 +39,7 @@ let
};
in {
genesis = machine { name = "genesis"; };
exodus = unstable { name = "exodus"; };
jude = unstable { name = "jude"; };
icdm-root = unstable { name = "icdm-root"; };
linode = machine { name = "linode"; };
+20
View File
@@ -0,0 +1,20 @@
{ pkgs, config, ... }:
{
imports = [
./hardware-configuration.nix
../jude/printing.nix
];
boot.loader = {
systemd-boot.enable = true;
efi.canTouchEfiVariables = true;
};
networking.hostName = "exodus";
greg = {
home = true;
gnome.enable = true;
tailscale.enable = true;
};
}
+39
View File
@@ -0,0 +1,39 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "xhci_pci" "thunderbolt" "nvme" "uas" "sd_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/disk/by-uuid/607b933f-2967-4652-b478-4d8e9aa38a0d";
fsType = "btrfs";
options = [ "subvol=@" ];
};
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/B31C-C1F4";
fsType = "vfat";
};
swapDevices = [ ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.enp0s13f0u1.useDHCP = lib.mkDefault true;
# networking.interfaces.wlp170s0.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
+4 -2
View File
@@ -8,9 +8,10 @@
10.42.1.2 opnsense router opnsense.thehellings.lan router.thehellings.lan
10.42.1.3 printer.thehellings.lan
10.42.1.4 chronicles chronicles.thehellings.lan nas.thehellings.lan
10.42.1.5 genesis genesis.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan speedtest.thehellings.lan nixcache.thehellings.lan gitcache.thehellings.lan s3.thehellings.lan
10.42.1.5 genesis genesis.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan speedtest.thehellings.lan nixcache.thehellings.lan gitcache.thehellings.lan
10.42.1.6 isaiah isaiah.thehellings.lan
10.42.1.7 hosea hosea.thehellings.lan
10.42.1.7 hosea hosea.thehellings.lan s3.thehellings.lan
10.42.1.8 jeremiah jeremiah.thehellings.lan
10.42.1.12 tv
10.42.100.6 isaiahbmc isaiahbmc.thehellings.lan
@@ -24,6 +25,7 @@
100.84.183.79 myself.home myself.shire-zebra.ts.net
100.78.226.76 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan
100.68.203.1 hosea.home hosea.shire-zebra.ts.net
100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net
# Dev hosts
10.42.101.1 icdm.lan wiki.icdm.lan *.icdm.lan
+10 -10
View File
@@ -137,24 +137,24 @@ in {
# Static IPs for things in the IOT range
"b4:b0:24:9a:02:4a,192.168.66.5" # LD125
"98:da:c4:20:f3:64,192.168.66.6"
"98:da:c4:20:f3:64,192.168.66.6" # Dining room light
"54:af:97:c1:dc:b9,192.168.66.25" # Master bedroom Kasa switch
"f0:03:8c:b3:b0:f6,192.168.66.55" # Roomba
"4c:a1:61:05:cd:52,192.168.66.61" # Rainbird
"48:d6:d5:5d:81:21,192.168.66.65" # Google Home
"6c:29:90:3e:e2:02,192.168.66.66" # wiz
"28:87:ba:0e:ca:da,192.168.66.74" # KS200M switch
"28:87:ba:0e:c9:fd,192.168.66.75"
"54:af:97:c2:0f:a1,192.168.66.76"
"28:87:ba:0e:ca:da,192.168.66.74" #
"28:87:ba:0e:c9:fd,192.168.66.75" # Master closet
"54:af:97:c2:0f:a1,192.168.66.76" # Master toilet
"54:af:97:83:ed:33,192.168.66.80"
"98:da:c4:77:80:18,192.168.66.84"
"98:da:c4:21:1b:2e,192.168.66.85"
"0c:80:63:41:6e:0f,192.168.66.90"
"0c:80:63:41:6c:5d,192.168.66.98" # HS200 switch
"98:da:c4:77:80:18,192.168.66.84" # Kitchen lights
"98:da:c4:21:1b:2e,192.168.66.85" # Living Room lights
"0c:80:63:41:6e:0f,192.168.66.90" # Front porch
"0c:80:63:41:6c:5d,192.168.66.98" # House number
"ac:84:c6:5e:4b:28,192.168.66.100"
"98:da:c4:77:7f:4d,192.168.66.102"
"98:da:c4:77:7f:4d,192.168.66.102" # Office lights
"8c:85:80:1c:f9:d1,192.168.66.104"
"98:da:c4:77:82:7b,192.168.66.105"
"98:da:c4:77:82:7b,192.168.66.105" # Parlor lamp
"0c:80:63:41:74:73,192.168.66.106" # Front hall light switch
"98:da:c4:20:ea:db,192.168.66.107" # Parlor light switch
"8c:49:62:aa:58:60,192.168.66.108" # Roku, HiHandsome
+33
View File
@@ -0,0 +1,33 @@
{ config, ... }:
let
publicIp = (builtins.elemAt config.networking.interfaces.enp68s0.ipv4.addresses 0).address;
sanIp = (builtins.elemAt config.networking.interfaces.enp67s0.ipv4.addresses 0).address;
vip = (builtins.elemAt config.networking.interfaces.enp68s0.ipv4.addresses 1).address;
hostname = config.networking.hostName;
baseConfig = import ../../ceph/home.nix;
in {
services.ceph-benaco = baseConfig // {
enable = true;
monitor = {
enable = true;
initialKeyring = ../../secrets/home.mon.keyring;
nodeName = hostname;
bindAddr = publicIp;
advertisedPublicAddr = vip;
};
osdBindAddr = publicIp;
osdAdvertisedPublicAddr = publicIp;
osds = {
osd1 = {
enable = true;
bootstrapKeyring = ../../secrets/home.osd-bootstrap.keyring;
id = 1;
uuid = "c13bd2b1-cfc7-4966-8da5-d92356e87e06";
blockDevice = "/dev/sda";
blockDeviceUdevRuleMatcher = ''KERNEL=="sda"'';
clusterAddress = sanIp;
};
};
};
}
+56 -12
View File
@@ -1,22 +1,66 @@
# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{ config, pkgs, ... }:
{
imports =
[ # Include the results of the hardware scan.
./hardware-configuration.nix
];
imports =
[ # Include the results of the hardware scan.
./ceph.nix
./hardware-configuration.nix
];
# Bootloader.
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
# Bootloader.
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
networking.hostName = "jeremiah"; # Define your hostname.
greg = {
networking = {
hostName = "jeremiah"; # Define your hostname.
useDHCP = false;
defaultGateway = {
address = " 10.42.1.1";
interface = "enp68s0";
};
interfaces = {
enp68s0 = {
ipv4.addresses = [ {
address = "10.42.1.8";
prefixLength = 16;
} {
address = "10.42.100.1";
prefixLength = 16;
} ];
};
enp67s0 = {
ipv4.addresses = [ {
address = "10.201.1.2";
prefixLength = 16;
} ];
};
};
nameservers = [
"10.42.1.5"
];
};
greg = {
home = true;
tailscale.enable = true;
};
tailscale.enable = true;
};
environment.systemPackages = with pkgs; [
btrfs-progs
];
fileSystems = {
"/nix" = {
fsType = "btrfs";
options = [ "subvol=nix" ];
device = "/dev/nvme0n1p1";
};
"/var" = {
fsType = "btrfs";
options = [ "subvol=var" ];
device = "/dev/nvme0n1p1";
};
};
}
+3 -2
View File
@@ -32,8 +32,8 @@
greg = {
tailscale.enable = true;
sway.enable = false;
gnome.enable = false;
kde.enable = true;
gnome.enable = true;
kde.enable = false;
};
boot.extraModulePackages = [ config.boot.kernelPackages.v4l2loopback ];
@@ -68,6 +68,7 @@
oathToolkit
synology-drive-client
terraform
usbutils
vagrant
ventoy
]
+28 -17
View File
@@ -1,4 +1,4 @@
{ pkgs, ... }:
{ pkgs, config, ... }:
{
environment.systemPackages = with pkgs; [
@@ -6,11 +6,11 @@
guestfs-tools
libguestfs
OVMFFull
ovftool
packer
virt-manager
vmware-workstation
vmfs-tools
xorriso
];
# Give my user access to the libvirtd process
@@ -28,8 +28,6 @@
enableExtensionPack = true;
};
vmware.host.enable = false;
waydroid.enable = false;
lxd.enable = false;
};
@@ -39,20 +37,33 @@
boot.extraModprobeConfig = "options kvm_amd nested=1";
systemd.services = {
vbox = {
gitlab-runner = {
conflicts = [ "libvirtd.service" ];
serviceConfig = {
Type = "oneshot";
RemainAfterExit = "yes";
ExecStart = [
"rmmod kvm_amd"
"rmmod kvm"
];
ExecStop = [
"rmmod vboxnetflt"
"rmmod vboxnetadp"
"rmmod vboxdrv"
];
preStart = builtins.concatStringsSep "\n" [
"${pkgs.kmod}/bin/modprobe vboxnetflt vboxdrv"
"${pkgs.kmod}/bin/modprobe vboxnetadp"
];
postStop = "${pkgs.kmod}/bin/rmmod vboxnetflt vboxnetadp vboxdrv";
wantedBy = pkgs.lib.mkForce [];
serviceConfig.User = "root";
};
libvirtd = {
preStart = "${pkgs.kmod}/bin/modprobe kvm_amd";
postStop = "${pkgs.kmod}/bin/rmmod kvm_amd kvm";
};
};
age.secrets.runner-reg.file = ../../secrets/gitlab/myself-vbox-runner-reg.age;
services.gitlab-runner = {
enable = true;
settings.concurrent = 5;
services.vbox = {
executor = "shell";
limit = 5;
registrationConfigFile = config.age.secrets.runner-reg.path;
environmentVariables = {
EFI_DIR = "${pkgs.OVMF.fd}/FV/";
};
};
};
+37 -1
View File
@@ -1,4 +1,4 @@
{ pkgs, lib, ... }:
{ pkgs, lib, config, ... }:
{
imports = [
@@ -26,6 +26,7 @@
];
networking = {
networkmanager.enable = lib.mkForce false;
hostName = "linode";
domain = "thehellings.com";
nameservers = [
@@ -33,6 +34,41 @@
];
};
age.secrets.runner-deployer = {
file = ../../secrets/gitlab/linode-deployer-runner-reg.age;
owner = "gitlab-runner";
};
services.gitlab-runner = {
enable = true;
services.deployer = {
executor = "shell";
registrationConfigFile = config.age.secrets.runner-deployer.path;
};
};
users.users.gitlab-runner = {
isSystemUser = true;
group = "gitlab-runner";
};
users.groups.gitlab-runner = {};
systemd.services."gitlab-runner".serviceConfig = {
DynamicUser = lib.mkForce false;
User = "gitlab-runner";
};
security.sudo.extraRules = [{
users = [ "gitlab-runner" ];
commands = [{
command = "/run/current-system/sw/bin/systemctl";
options = [ "NOPASSWD" ];
} {
command = "/run/current-system/sw/bin/podman";
options = [ "NOPASSWD" ];
}];
}];
environment.systemPackages = with pkgs; [
bind
graphviz
+6 -6
View File
@@ -2,6 +2,7 @@
let
srcDomain = "src.thehellings.com";
sshPort = 2222;
in {
greg.proxies."${srcDomain}" = {
target = "http://git.thehellings.lan";
@@ -19,6 +20,8 @@ in {
extraConfig = "client_max_body_size 250m;";
};
networking.firewall.allowedTCPPorts = [ sshPort ];
services.haproxy = {
enable = true;
config = builtins.concatStringsSep "\n" [
@@ -31,14 +34,11 @@ in {
" timeout client 500s"
" timeout server 1h"
"frontend gitsshd"
" bind *:2222"
" default_backend gitssh"
"listen gitsshd"
" bind *:${toString sshPort}"
" timeout client 1h"
"backend gitssh"
" mode tcp"
" server git-thehellings-lan git.thehellings.lan:2222"
" server git-thehellings-lan git.thehellings.lan:22"
];
};
}
+1 -1
View File
@@ -25,7 +25,7 @@
enableACME = true;
};
greg.backup.jobs.nextcloud = {
greg.backup.jobs.nextcloud-bkup = {
src = "/var/lib/nextcloud";
dest = "nextcloud-backup";
user = "nextcloud";
+2 -1
View File
@@ -23,7 +23,8 @@ in
virtualisation.oci-containers = {
backend = "podman";
containers."homepage" = {
image = "ghcr.io/greg-hellings/homepage:latest";
# needs explicit port to match what gitlab-runner sees when pulling
image = "registry.thehellings.com:443/greg/homepage/gregs-homepage:latest";
ports = [ "${homepage}:80" ];
};
};
+5
View File
@@ -1,8 +1,13 @@
{ config, pkgs, lib, ... }:
{
environment.systemPackages = [
pkgs.upgrade-pg-cluster
];
services.postgresql = {
enable = true;
package = pkgs.postgresql_15;
checkConfig = true;
ensureDatabases = [
"nextcloud"
+44
View File
@@ -13,6 +13,19 @@ in {
gitlab-jws = cfg "jws";
gitlab-key = cfg "key";
gitlab-cert = cfg "cert";
minio_access_key_id = {
file = ../../secrets/minio_access_key_id.age;
owner = "gitlab";
group = "gitlab";
mode = "0444";
};
minio_secret_access_key = {
file = ../../secrets/minio_secret_access_key.age;
owner = "gitlab";
group = "gitlab";
mode = "0444";
};
};
networking.firewall.allowedTCPPorts = [ 80 registryPort ];
@@ -86,6 +99,34 @@ in {
dbFile = config.age.secrets.gitlab-db.path;
jwsFile = config.age.secrets.gitlab-jws.path;
};
extraConfig = {
object_store = {
enabled = true;
proxy_download = false; # Tell them to reach out to object storage themselves!
connection = {
provider = "AWS";
endpoint = "http://s3.thehellings.lan:9000";
region = "us-east-1";
aws_access_key_id = { _secret = config.age.secrets.minio_access_key_id.path; };
aws_secret_access_key = { _secret = config.age.secrets.minio_secret_access_key.path; };
path_style = true; # True for MinIO
aws_signature_version = 2;
};
#storage_options = ...;
objects = builtins.listToAttrs ( builtins.map (x: lib.attrsets.nameValuePair x { bucket = "gitlab-${builtins.replaceStrings [ "_" ] [ "-" ] x}"; }) [
"artifacts"
"ci_secure_files"
"dependency_proxy"
"external_diffs"
"lfs"
"packages"
"pages"
"terraform_state"
"uploads"
]);
};
};
};
nginx.virtualHosts."gitlab.shire-zebra.ts.net" = {
@@ -147,6 +188,9 @@ in {
"network.target"
"network-online.target"
];
preStart = ''
sleep 5 # tailscaled is up before it's ACTUALLY up... try waiting?
'';
};
system.stateVersion = lib.mkForce "24.05";
}
+9
View File
@@ -33,6 +33,15 @@
ipv4.addresses = [ {
address = "10.42.1.6";
prefixLength = 16;
} {
address = "10.42.100.1";
prefixLength = 16;
} ];
};
interfaces.enp39s0 = {
ipv4.addresses = [ {
address = "10.201.1.1";
prefixLength = 24;
} ];
};
nameservers = [
+5 -4
View File
@@ -65,6 +65,7 @@ in {
config = ((import ./container-runner.nix) {
inherit inputs overlays;
name = "shell";
extra.virtualisation.podman.enable = true;
});
};
@@ -96,13 +97,13 @@ in {
"koalaman/shellcheck:*"
"registry.gitlab.com/gitlab-org/*"
"registry.thehellings.com/*"
"gitlab.shire-zebra.ts.net:5000/*:*"
"registry.thehellings.com/*/*/*:*"
"gitlab.shire-zebra.ts.net:5000/*/*/*:*"
];
dockerAllowedServices = [
"docker:*"
"registry.thehellings.com/*"
"gitlab.shire-zebra.ts.net:5000/*:*"
"registry.thehellings.com/*/*/*:*"
"gitlab.shire-zebra.ts.net:5000/*/*/*:*"
];
dockerPrivileged = true;
dockerVolumes = [
+7 -7
View File
@@ -1,4 +1,7 @@
{ pkgs, ... }:
{ pkgs, lib, ... }:
let
notDarwin = (! pkgs.stdenv.isDarwin);
in
{
# Enable flakes
nix = {
@@ -15,8 +18,7 @@
keep-derivations = true;
min-free = (toString (1024 * 1024 * 1024) );
max-free = (toString (5 * 1024 * 1024 * 1024) );
substituters = [
"http://nixcache.home"
substituters = (if notDarwin then [ "http://nixcache.home" ] else []) ++ [
"https://cache.garnix.io"
"https://ai.cachix.org"
];
@@ -32,8 +34,7 @@
};
# Base packages that need to be in all my hosts
environment.systemPackages = with pkgs; (
[
environment.systemPackages = with pkgs; [
agenix
android-file-transfer
bitwarden-cli
@@ -56,6 +57,5 @@
transcrypt
unzip
wget
]
);
];
}
+848 -1
View File
@@ -1,2 +1,849 @@
# This is a good source for a Ceph dealio
# https://gist.github.com/nh2/13425a1f18b4c1ce82edb63c10b163c9
# https://gist.github.com0/nh2/13425a1f18b4c1ce82edb63c10b163c9
{ config, lib, pkgs, ... }:
with lib;
let
cfg = config.services.ceph-benaco;
commaSep = builtins.concatStringsSep ",";
ensureUnitExists = c': name: let
unitName = (builtins.elemAt (builtins.split "\\." name) 0);
in if c'.systemd.services ? unitName
then name
else name;# "Unable to locate ${name} at ${commaSep (builtins.attrNames c')}";
in
{
###### interface
options = {
services.ceph-benaco = {
enable = mkEnableOption "Ceph distributed filesystem";
package = mkOption {
type = types.package;
default = pkgs.ceph;
defaultText = literalExpression "pkgs.ceph-benaco";
description = "Ceph package to use.";
};
fsid = mkOption {
type = types.str;
description = "Unique cluster identifier.";
};
clusterName = mkOption {
type = types.str;
description = "Cluster name.";
default = "ceph";
};
initialMonitors = mkOption {
type = types.listOf (types.submodule {
options = {
hostname = mkOption {
type = types.str;
description = "Initial monitor hostname.";
};
ipAddress = mkOption {
type = types.str;
description = "Initial monitor IP address.";
};
};
});
description = "Initial monitors.";
};
mdsNodes = mkOption {
type = types.listOf (types.submodule {
options = {
hostname = mkOption {
type = types.str;
description = "MDS hostname.";
};
ipAddress = mkOption {
type = types.str;
description = "MDS IP address.";
};
};
});
description = "MDS nodes.";
};
publicNetworks = mkOption {
type = types.listOf types.str;
description = "Public network(s) of the cluster.";
};
clusterNetworks = mkOption {
type = types.listOf types.str;
description = "Cluster backend networks for OSD sync";
};
adminKeyring = mkOption {
type = types.path;
description = "Ceph admin keyring to install on the machine.";
};
monitor = {
enable = mkEnableOption "Activate a Ceph monitor on this machine.";
initialKeyring = mkOption {
type = types.path;
description = "Keyring file to use when initializing a new monitor";
example = "/path/to/ceph.mon.keyring";
};
nodeName = mkOption {
type = types.str;
description = "Ceph monitor node name.";
example = "node1";
};
bindAddr = mkOption {
type = types.str;
description = "IP address that the OSDs shall bind to.";
example = "10.0.0.1";
};
advertisedPublicAddr = mkOption {
type = types.str;
description = "IP address that the monitor shall advertise.";
example = "10.0.0.1";
};
};
manager = {
enable = mkEnableOption "Activate a Ceph manager on this machine.";
nodeName = mkOption {
type = types.str;
description = "Ceph manager node name.";
example = "node1";
};
};
osdBindAddr = mkOption {
type = types.str;
description = "IP address that the OSDs shall bind to.";
example = "10.0.0.1";
};
osdAdvertisedPublicAddr = mkOption {
type = types.str;
description = "IP address that the OSDs shall advertise.";
example = "10.0.0.1";
};
osds = mkOption {
default = {};
example = {
osd1 = {
enable = true;
bootstrapKeyring = "/path/to/ceph.client.bootstrap-osd.keyring";
id = 1;
uuid = "11111111-1111-1111-1111-111111111111";
blockDevice = "/dev/sdb";
blockDeviceUdevRuleMatcher = ''KERNEL=="sdb"'';
clusterAddress = "10.1.0.1";
};
osd2 = {
enable = true;
bootstrapKeyring = "/path/to/ceph.client.bootstrap-osd.keyring";
id = 2;
uuid = "22222222-2222-2222-2222-222222222222";
blockDevice = "/dev/sdc";
blockDeviceUdevRuleMatcher = ''KERNEL=="sdc"'';
clusterAddress = "10.1.0.2";
};
};
description = ''
This option allows you to define multiple Ceph OSDs.
A common idiom is to use one OSD per physical hard drive.
Note that the OSD names given as attributes of this key
are NOT what ceph calls OSD IDs (instead, those are defined
by the 'services.ceph-benaco.osds.*.id' fields).
Instead, the name is an identifier local and unique to the
current machine only, used only to name the systemd service
for that OSD.
'';
type = types.attrsOf (types.submodule {
options = {
enable = mkEnableOption "Activate a Ceph OSD on this machine.";
bootstrapKeyring = mkOption {
type = types.path;
description = "Ceph OSD bootstrap keyring.";
example = "/path/to/ceph.client.bootstrap-osd.keyring";
};
id = mkOption {
type = types.int;
description = "The ID of this OSD. Must be unique in the Ceph cluster.";
example = 1;
};
uuid = mkOption {
type = types.str;
description = "The UUID of this OSD. Must be unique in the Ceph cluster.";
example = "abcdef12-abcd-1234-abcd-1234567890ab";
};
systemdExtraRequiresAfter = mkOption {
type = types.listOf types.str;
default = [];
description = ''
Add the specified systemd units to the "requires" and "after"
lists of the systemd service of this OSD.
Useful, for example, to decrypt the underlying block devices with LUKS first.
NixOS modules allow override those lists from outside, but for that
the names of the systemd services for the OSDs need to be known;
this option is a convenience to not have to know them from outside.
'';
example = "decrypt-my-disk.service";
};
skipZap = mkOption {
type = types.bool;
default = false;
description = ''
Whether to skip the zapping of the the OSD device on initial OSD
installation.
Skipping is needed because <command>ceph-volume</command> cannot
zap device-mapper devices:
<link xlink:href="https://tracker.ceph.com/issues/24504" />
In that case you need to wipe the device manually.
In the common case of placing the OSD on a cryptsetup LUKS device
(which is a device-mapper device), re-creating the encryption
from scratch with a new key zaps anything anyway, in which case
zapping can be skipped here.
'';
};
blockDevice = mkOption {
type = types.str;
description = "The block device used to store the OSD.";
example = "/dev/sdb";
};
blockDeviceUdevRuleMatcher = mkOption {
type = types.str;
description = ''
An udev rule matcher matching the block device used to store the OSD.
Will be spliced into the udev rule that is
used to set access permissions to the ceph user via an udev rule.
This is a matcher instead of just a device name to allow flexibility:
Normal disks can be easily matched with <code>KERNEL=="sda1"</code>, but
device-mapper may not; for example, decrypted cryptsetup LUKS devices
have a less useful <code>KERNEL=="dm-4"</code> and may better be matched
using <code>ENV{DM_NAME}=="mydisk-decrypted"</code>.
'';
example = ''KERNEL=="sdb"'';
};
dbBlockDevice = mkOption {
type = types.nullOr types.str;
default = null;
description = ''
The block device used to store the OSD's BlueStore DB device.
Put this on a faster device than <option>blockDevice</option> to improve performance.
See <link xlink:href="http://docs.ceph.com/docs/master/rados/configuration/bluestore-config-ref/" />
for details.
'';
example = "/dev/sdc";
};
dbBlockDeviceUdevRuleMatcher = mkOption {
type = types.nullOr types.str;
default = null;
description = ''
Like <option>blockDeviceUdevRuleMatcher</option> but for the
<option>dbBlockDevice</option>.
'';
example = ''KERNEL=="sdc"'';
};
clusterAddress = mkOption {
type = types.nullOr types.str;
default = null;
description = ''
The IP address on the dedicated cluster network that
is used by the backend communication for OSD communication.
'';
example = "10.1.0.1f";
};
};
});
};
mds = {
enable = mkEnableOption "Activate a Ceph MDS on this machine.";
nodeName = mkOption {
type = types.str;
description = "Ceph MDS node name.";
example = "node1";
};
listenAddr = mkOption {
type = types.str;
description = "IP address that the MDS shall advertise.";
example = "10.0.0.1";
};
};
extraConfig = mkOption {
type = types.str;
default = "";
description = ''
Additional ceph.conf settings.
See the sample file for inspiration:
<link xlink:href="https://github.com/ceph/ceph/blob/master/src/sample.ceph.conf" />
'';
};
};
};
###### implementation
config = let
monDir = "/var/lib/ceph/mon/${cfg.clusterName}-${cfg.monitor.nodeName}";
mgrDir = "/var/lib/ceph/mgr/${cfg.clusterName}-${cfg.manager.nodeName}";
mdsDir = "/var/lib/ceph/mds/${cfg.clusterName}-${cfg.mds.nodeName}";
# File permissions for things that are on locations wiped at start
# (e.g. /run or its /var/run symlink).
ensureTransientCephDirs = ''
install -m 770 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/run/ceph
'';
# File permissions from cluster deployed with ceph-deploy.
ensureCephDirs = ''
install -m 3770 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/log/ceph
install -m 770 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/run/ceph
install -m 750 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph
install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/mon
install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/mgr
install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/osd
'';
# Utilities called by Ceph device health scraping, see:
# https://docs.ceph.com/en/latest/rados/operations/devices/#enabling-monitoring
# As per https://github.com/ceph/ceph-container/pull/1490/commits/c49e821599965ae92a88b2c78077ee03c4405895,
# both the OSDs and the `mon` need this.
# Ceph calls these utilities with `sudo`. That requires sudoers entries.
# Sudoers entries require absolute path; that exact (nix store) path needs to
# be used by Ceph, so it needs to be given to the systemd unit via `path`.
# This is why we pair each `sudoersExtraRule` with the `package` to put onto
# that `path`.
#
# Entries are based on:
# https://github.com/ceph/ceph/blob/a2f5a3c1dbfa4dce41e25da4f029a8fdb8c8d864/sudoers.d/ceph-smartctl
cephMonitoringSudoersCommandsAndPackages = [
{
package = pkgs.smartmontools;
sudoersExtraRule = { # entry for `security.sudo.extraRules`
users = [ config.users.users.ceph.name ];
commands = [{
command = "${lib.getBin pkgs.smartmontools}/bin/smartctl -x --json=o /dev/*";
options = [ "NOPASSWD" ];
}];
};
}
{
package = pkgs.nvme-cli;
sudoersExtraRule = { # entry for `security.sudo.extraRules`
users = [ config.users.users.ceph.name ];
commands = [{
command = "${lib.getBin pkgs.nvme-cli}/bin/nvme * smart-log-add --json /dev/*";
options = [ "NOPASSWD" ];
}];
};
}
];
cephDeviceHealthMonitoringPathsOrPackages = with pkgs; [
# Contains `sudo`. Ceph wraps this around the other health check programs.
# Cannot use `pkgs.sudo` because that one is not SUID, see:
# https://discourse.nixos.org/t/sudo-uid-issues/9133
"/run/wrappers" # `systemd.services.<name>.path` adds the `bin/` subdir of this
] ++ map ({ package, ... }: package) cephMonitoringSudoersCommandsAndPackages;
makeCephOsdSetupSystemdService = localOsdServiceName: osdConfig:
let
osdExistenceFile = "/var/lib/ceph/osd/.${toString osdConfig.id}.${osdConfig.uuid}.nix-existence";
in
mkIf osdConfig.enable {
description = "Initialize Ceph OSD";
requires = osdConfig.systemdExtraRequiresAfter;
after = osdConfig.systemdExtraRequiresAfter;
path = with pkgs; [
# The following are currently missing in Ceph's wrapping, see https://github.com/NixOS/nixpkgs/issues/147801#issue-1065600852
util-linux # for `lsblk`
lvm2 # for `lvs`
];
# TODO Use `udevadm trigger --settle` instead of the separate `udevadm settle`
# once that feature is available to us with systemd >= 238;
# see https://github.com/systemd/systemd/commit/792cc203a67edb201073351f5c766fce3d5eab45
preStart = ''
set -x
${ensureCephDirs}
install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/bootstrap-osd
# `install` is not atomic, see
# https://lists.gnu.org/archive/html/bug-coreutils/2010-02/msg00243.html
# so use `mktemp` + `mv` to make it atomic.
TMPFILE=$(mktemp --tmpdir=/var/lib/ceph/bootstrap-osd/)
install -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} ${osdConfig.bootstrapKeyring} "$TMPFILE"
mv "$TMPFILE" /var/lib/ceph/bootstrap-osd/ceph.keyring
# Trigger udev rules for permissions of block devices and wait for them to settle.
udevadm trigger --name-match=${osdConfig.blockDevice}
'' + lib.optionalString (osdConfig.dbBlockDevice != null) ''
udevadm trigger --name-match=${osdConfig.dbBlockDevice}
'' +
''
udevadm settle
'' + (optionalString (!osdConfig.skipZap) (
''
# Zap OSD block devices, otherwise `ceph-osd` below will try to fsck if there's some old
# ceph data on the block device (see https://tracker.ceph.com/issues/24099).
${cfg.package}/bin/ceph-volume lvm zap ${osdConfig.blockDevice}
'' + lib.optionalString (osdConfig.dbBlockDevice != null) ''
${cfg.package}/bin/ceph-volume lvm zap ${osdConfig.dbBlockDevice}
''
));
script = ''
set -euo pipefail
set -x
until [ -f /etc/ceph/${cfg.clusterName}.client.admin.keyring ]
do
sleep 1
done
OSD_SECRET=$(${cfg.package}/bin/ceph-authtool --gen-print-key)
echo "{\"cephx_secret\": \"$OSD_SECRET\"}" | \
${cfg.package}/bin/ceph osd new ${osdConfig.uuid} ${toString osdConfig.id} -i - \
-n client.bootstrap-osd -k ${osdConfig.bootstrapKeyring}
mkdir -p /var/lib/ceph/osd/${cfg.clusterName}-${toString osdConfig.id}
ln -s ${osdConfig.blockDevice} /var/lib/ceph/osd/${cfg.clusterName}-${toString osdConfig.id}/block
'' + lib.optionalString (osdConfig.dbBlockDevice != null) ''
ln -s ${osdConfig.dbBlockDevice} /var/lib/ceph/osd/${cfg.clusterName}-${toString osdConfig.id}/block.db
'' +
''
${cfg.package}/bin/ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${toString osdConfig.id}/keyring \
--name osd.${toString osdConfig.id} --add-key $OSD_SECRET
${cfg.package}/bin/ceph-osd -i ${toString osdConfig.id} --mkfs --osd-uuid ${osdConfig.uuid} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} --osd-objectstore bluestore
touch ${osdExistenceFile}
'';
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
PermissionsStartOnly = true; # only run the script as ceph, preStart as root
User = config.users.users.ceph.name;
Group = config.users.groups.ceph.name;
};
unitConfig = {
ConditionPathExists = "!${osdExistenceFile}";
};
};
makeCephOsdSystemdService = localOsdServiceName: osdConfig: mkIf osdConfig.enable {
description = "Ceph OSD";
# Note we do not have to add `osdConfig.systemdExtraRequiresAfter` here because
# that's already a dependency of our dependency `ceph-osd-setup-*`.
requires = [
(ensureUnitExists config "ceph-osd-setup-${localOsdServiceName}.service")
];
requiredBy = [ "multi-user.target" ];
after = [
"network.target"
"local-fs.target"
"time-sync.target"
(ensureUnitExists config "ceph-osd-setup-${localOsdServiceName}.service")
];
wants = [
"network.target"
"local-fs.target"
"time-sync.target"
];
path = [
# TODO: use wrapProgram in the ceph package for this in the future
pkgs.getopt
]
++ cephDeviceHealthMonitoringPathsOrPackages
;
restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ];
preStart = ''
${ensureTransientCephDirs}
${lib.getLib cfg.package}/libexec/ceph/ceph-osd-prestart.sh --cluster ${cfg.clusterName} --id ${toString osdConfig.id}
'';
serviceConfig = let
clusterIpArg = lib.optionalString (osdConfig.clusterAddress != null) "--cluster_addr=${osdConfig.clusterAddress}";
in {
LimitNOFILE="1048576";
LimitNPROC="1048576";
ExecStart=''
${cfg.package}/bin/ceph-osd -f --cluster ${cfg.clusterName} --id ${toString osdConfig.id} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} "--public_bind_addr=${cfg.osdBindAddr}" "--public_addr=${cfg.osdAdvertisedPublicAddr}" "${clusterIpArg}"
'';
ExecReload=''
${pkgs.coreutils}/bin/kill -HUP $MAINPID
'';
Restart="on-failure";
ProtectHome="true";
ProtectSystem="full";
PrivateTmp="true";
TasksMax="infinity";
# StartLimitBurst="3";
};
# startLimitIntervalSec = 30 * 60;
};
in mkIf cfg.enable {
environment.systemPackages = [ cfg.package ];
networking.firewall = {
allowedTCPPorts = [
# Ceph outside of VPN because it is very data heavy and causes packet loss.
# We enable msgr-v2 only because that allows its own on-wire encryption.
3300 # ceph msgr-v2
];
allowedTCPPortRanges = [
{ from = 6800; to = 7300; } # https://docs.ceph.com/en/pacific/rados/configuration/network-config-ref/
];
};
# Reminder of how `ceph.conf` works:
#
# * Ceph upstream docs now recommend to use underscores instead of spaces.
# * Options in more specific sections like `[mon]` override those in less
# specific sections like `[global]`. But all options can be written into all sections,
# and an option has the same name, no matter in which section it is written.
# Thus, put options in `[global]`, and only use a diffent section
# if you want to override an option you've set in `global`.
#
# Sample: https://github.com/ceph/ceph/blob/master/src/sample.ceph.conf
environment.etc."ceph/${cfg.clusterName}.conf".text =
''
[global]
fsid = ${cfg.fsid}
mon_initial_members = ${commaSep (map (mon: mon.hostname) cfg.initialMonitors)}
mon_host = ${commaSep (map (mon: mon.ipAddress) cfg.initialMonitors)}
# Ceph clusters go into WARN health mode, until
# the following setting is made strict by setting it to `false`:
# See: https://docs.ceph.com/en/latest/security/CVE-2021-20288/#recommendations
# As of writing, this setting is not documented outside of the CVE note :(
#
# While for new clusters the warning no longer seems to appear, it still
# appears in our existing clusters unless this option is set, see:
# https://tracker.ceph.com/issues/53751#note-7
auth_allow_insecure_global_id_reclaim = false
# Disable dirfrag prefetch on MDS restart to prevent out-of-memory after
# many files were opened.
# Note this option has no effect on Ceph < 15, because it doesn't exist there.
# TODO: Remove this once we're on a Ceph version that includes this default,
# see https://github.com/ceph/ceph/pull/44667.
# This is assuming that the commit fixes existing clusters, see
# https://github.com/ceph/ceph/pull/44667#issuecomment-1036103397
# If it doesn't this can only be removed once we have no existing
# cluster with the old default.
mds_oft_prefetch_dirfrags = false
# Disable sleep between HDD recovery operations, otherwise recovery
# will take forever when small objects (e.g. CephFS files) are on HDD.
# See https://tracker.ceph.com/issues/23595#note-12
osd_recovery_sleep_hdd = 0.0
# Increase scrub intervals by 4x.
# Since we store many small files on HDD, and scrubbing apparently
# iterates over all objects
# we have no chance to scrub at the default intervals.
#
# (This was written when we had 400M files across 30 HDDs.)
# Change this back once we have reduced our number of files per disk.
osd_scrub_min_interval = 345600
osd_scrub_max_interval = 2419200
osd_deep_scrub_interval = 2419200
public_network = ${commaSep cfg.publicNetworks}
cluster_network = ${commaSep cfg.clusterNetworks}
auth_cluster_required = cephx
auth_service_required = cephx
auth_client_required = cephx
# Enforce on-wire transport encryption.
ms_cluster_mode = secure
ms_service_mode = secure
ms_client_mode = secure
${cfg.extraConfig}
'';
environment.etc."ceph/${cfg.clusterName}.client.admin.keyring" = {
source = cfg.adminKeyring;
mode = "0600";
# Make ceph own this keyring so that it can use it to get keys for its daemons.
user = "ceph";
group = "ceph";
};
users.users.ceph = {
isNormalUser = false;
isSystemUser = true;
# TODO: Legacy UID / GID chosen from before we configured the UID declaratively.
# In the future, we whould change this whole module to use
# `config.ids.uids.ceph`, like the upstream nixpkgs Ceph module does.
# Switching away from `nogroup` would also be good as described there.
# For both cases, we'll have to `chown` all relevant existing files on
# deployments, such as `/var/lib/ceph`, and log files.
uid = 1001;
group = config.users.groups.nogroup.name;
};
users.groups.ceph = {
# TODO: Same TODO as above for the `uid`.
gid = 499;
};
# Allow ceph daemons (which run as user ceph) to collect device health metrics.
security.sudo.extraRules =
map ({ sudoersExtraRule, ... }: sudoersExtraRule) cephMonitoringSudoersCommandsAndPackages;
# The udevadm trigger/settle in `makeCephOsdSetupSystemdService` waits for these rules rule to be applied.
services.udev.extraRules =
lib.concatStringsSep "\n" (
lib.mapAttrsToList (_localOsdServiceName: osdConfig:
''
SUBSYSTEM=="block", ${osdConfig.blockDeviceUdevRuleMatcher}, OWNER="${config.users.users.ceph.name}", GROUP="${config.users.groups.ceph.name}", MODE="0660"
''
+ lib.optionalString (osdConfig.dbBlockDeviceUdevRuleMatcher != null) (
''
SUBSYSTEM=="block", ${osdConfig.dbBlockDeviceUdevRuleMatcher}, OWNER="${config.users.users.ceph.name}", GROUP="${config.users.groups.ceph.name}", MODE="0660"
''
)
) cfg.osds
);
systemd.services = {
ceph-mon-setup = mkIf cfg.monitor.enable {
description = "Initialize ceph monitor";
preStart = ensureCephDirs;
script = let
# `--addv` seems currently required to get msgr-v2 working, see:
# https://tracker.ceph.com/issues/53751#note-11
monmapNodes = builtins.concatStringsSep " " (lib.concatMap (mon: [ "--addv" mon.hostname "[v2:${mon.ipAddress}:3300,v1:${mon.ipAddress}:6789]" ]) cfg.initialMonitors);
# Monitors cannot simply be changed in config, one has to update the monmap, see note [replacing-ceph-monmap-ips-for-existing-cluster]
in ''
set -euo pipefail
rm -rf "${monDir}" # Start from scratch.
echo "Initializing monitor."
MONMAP_DIR=`mktemp -d`
${cfg.package}/bin/monmaptool --create ${monmapNodes} --fsid ${cfg.fsid} "$MONMAP_DIR/monmap"
${cfg.package}/bin/ceph-mon --cluster ${cfg.clusterName} --mkfs -i ${cfg.monitor.nodeName} --monmap "$MONMAP_DIR/monmap" --keyring ${cfg.monitor.initialKeyring}
rm -r "$MONMAP_DIR"
touch ${monDir}/done
'';
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
PermissionsStartOnly = true; # only run the script as ceph
User = config.users.users.ceph.name;
Group = config.users.groups.ceph.name;
};
unitConfig = {
ConditionPathExists = "!${monDir}/done";
};
};
ceph-mon = mkIf cfg.monitor.enable {
description = "Ceph monitor";
requires = [ (ensureUnitExists config "ceph-mon-setup.service") ];
requiredBy = [ "multi-user.target" ];
after = [ "network.target" "local-fs.target" "time-sync.target" (ensureUnitExists config "ceph-mon-setup.service") ];
wants = [ "network.target" "local-fs.target" "time-sync.target" ];
restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ];
path = cephDeviceHealthMonitoringPathsOrPackages;
preStart = ensureTransientCephDirs;
serviceConfig = {
LimitNOFILE="1048576";
LimitNPROC="1048576";
ExecStart=''
${cfg.package}/bin/ceph-mon -f --cluster ${cfg.clusterName} --id ${cfg.monitor.nodeName} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} "--public_bind_addr=${cfg.monitor.bindAddr}" "--public_addr=${cfg.monitor.advertisedPublicAddr}"
'';
ExecReload=''
${pkgs.coreutils}/bin/kill -HUP $MAINPID
'';
PrivateDevices="yes";
ProtectHome="true";
ProtectSystem="full";
PrivateTmp="true";
TasksMax="infinity";
Restart="on-failure";
# StartLimitBurst="5";
RestartSec="10";
};
# startLimitIntervalSec = 30 * 60;
};
ceph-mgr-setup = mkIf cfg.manager.enable {
description = "Initialize Ceph manager";
preStart = ensureCephDirs;
script = ''
set -euo pipefail
mkdir -p ${mgrDir}
until [ -f /etc/ceph/${cfg.clusterName}.client.admin.keyring ]
do
sleep 1
done
${cfg.package}/bin/ceph auth get-or-create mgr.${cfg.manager.nodeName} mon 'allow profile mgr' mds 'allow *' osd 'allow *' -o ${mgrDir}/keyring
touch "${mgrDir}/.nix_done"
'';
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
PermissionsStartOnly = true; # only run the script as ceph
User = config.users.users.ceph.name;
Group = config.users.groups.ceph.name;
};
unitConfig = {
ConditionPathExists = "!${mgrDir}/.nix_done";
};
};
ceph-mgr = mkIf cfg.manager.enable {
description = "Ceph manager";
requires = [ (ensureUnitExists config "ceph-mgr-setup.service") ];
requiredBy = [ "multi-user.target" ];
after = [ "network.target" "local-fs.target" "time-sync.target" (ensureUnitExists config "ceph-mgr-setup.service") ];
wants = [ "network.target" "local-fs.target" "time-sync.target" ];
restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ];
preStart = ensureTransientCephDirs;
serviceConfig = {
LimitNOFILE="1048576";
LimitNPROC="1048576";
ExecStart=''
${cfg.package}/bin/ceph-mgr -f --cluster ${cfg.clusterName} --id ${cfg.manager.nodeName} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name}
'';
ExecReload=''
${pkgs.coreutils}/bin/kill -HUP $MAINPID
'';
Restart="on-failure";
RestartSec=10;
# StartLimitBurst="3";
};
# startLimitIntervalSec = 30 * 60;
};
ceph-mds-setup = mkIf cfg.mds.enable {
description = "Initialize Ceph MDS";
preStart = ensureCephDirs;
script = ''
set -euo pipefail
mkdir -p ${mdsDir}
until [ -f /etc/ceph/${cfg.clusterName}.client.admin.keyring ]
do
sleep 1
done
${cfg.package}/bin/ceph auth get-or-create mds.${cfg.mds.nodeName} osd 'allow rwx' mds 'allow' mon 'allow profile mds' -o ${mdsDir}/keyring
touch "${mdsDir}/.nix_done"
'';
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
PermissionsStartOnly = true; # only run the script as ceph
User = config.users.users.ceph.name;
Group = config.users.groups.ceph.name;
};
unitConfig = {
ConditionPathExists = "!${mdsDir}/.nix_done";
};
};
ceph-mds = mkIf cfg.mds.enable {
description = "Ceph MDS";
requires = [ (ensureUnitExists config "ceph-mds-setup.service") ];
requiredBy = [ "multi-user.target" ];
after = [ "network.target" "local-fs.target" "time-sync.target" (ensureUnitExists config "ceph-mds-setup.service") ];
wants = [ "network.target" "local-fs.target" "time-sync.target" ];
restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ];
preStart = ensureTransientCephDirs;
serviceConfig = {
LimitNOFILE="1048576";
LimitNPROC="1048576";
ExecStart=''
${cfg.package}/bin/ceph-mds -f --cluster ${cfg.clusterName} --id ${cfg.mds.nodeName} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} "--public_addr=${cfg.mds.listenAddr}"
'';
ExecReload=''
${pkgs.coreutils}/bin/kill -HUP $MAINPID
'';
Restart="on-failure";
# StartLimitBurst="3";
};
# startLimitIntervalSec = 30 * 60;
};
}
# Make one OSD service for each configured OSD.
// lib.mapAttrs' (localOsdServiceName: osdConfig: nameValuePair "ceph-osd-setup-${localOsdServiceName}" (makeCephOsdSetupSystemdService localOsdServiceName osdConfig)) cfg.osds
// lib.mapAttrs' (localOsdServiceName: osdConfig: nameValuePair "ceph-osd-${localOsdServiceName}" (makeCephOsdSystemdService localOsdServiceName osdConfig)) cfg.osds;
};
}
+1
View File
@@ -4,6 +4,7 @@
imports = [
../baseline.nix
./backup.nix
./ceph.nix
./container.nix
./db.nix
./gnome.nix
+3 -2
View File
@@ -13,13 +13,14 @@ in with lib; {
services = {
accounts-daemon.enable = true;
# Trackpad support
libinput.enable = true;
xserver = {
enable = true;
displayManager.gdm.enable = true;
desktopManager.gnome.enable = true;
xkb.layout = "us";
# Trackpad support
libinput.enable = true;
};
udev.packages = with pkgs; [
+8 -8
View File
@@ -13,16 +13,10 @@ in with lib; {
services = {
xserver = {
enable = true;
displayManager = {
defaultSession = "plasma";
sddm.enable = true;
};
xkb.layout = "us";
# Trackpad support
libinput.enable = true;
} // (optionalAttrs (builtins.hasAttr "plasma6" options.services.xserver.desktopManager) {
desktopManager.plasma6.enable = true;
});
};
pipewire = {
enable = true;
@@ -30,7 +24,13 @@ in with lib; {
alsa.support32Bit = true;
pulse.enable = true;
};
};
} // (optionalAttrs (builtins.hasAttr "plasma6" options.services.xserver.desktopManager) {
desktopManager.plasma6.enable = true;
displayManager = {
defaultSession = "plasma";
sddm.enable = true;
};
});
programs.dconf.enable = true;
programs.sway.enable = true; # Gives us Wayland
+3 -10
View File
@@ -40,10 +40,6 @@ in rec {
xonsh-apipenv = cp ./xonsh-apipenv.nix {};
xonsh-direnv = cp ./xonsh-direnv.nix {};
xontrib-vox = cp ./xonsh-vox.nix {};
home-assistant-chip-core = python-prev.home-assistant-chip-core.override {
openssl_1_1 = final.openssl;
};
})
];
@@ -87,14 +83,11 @@ in rec {
};
pipenv-ivr = prev.callPackage ./pipenv.nix { };
xonsh = prev.xonsh.overridePythonAttrs (old: rec{
python3 = final.gregpy;
propagatedBuildInputs = with final.gregpy.pkgs; old.propagatedBuildInputs ++ [
responses
ruamel-yaml
xonsh = (prev.xonsh.override {
extraPackages = (ps: with ps; [
xonsh-apipenv
xonsh-direnv
xontrib-vox
];
]);
});
}
+2 -2
View File
@@ -1,8 +1,8 @@
{ postgresql_15, postgresql_14, writeScriptBin, ... }:
let
newPostgres = postgresql_15;
oldPostgres = postgresql_14;
newPostgres = postgresql_16;
oldPostgres = postgresql_15;
in writeScriptBin "upgrade-pg-cluster" ''
set -eux
systemctl stop postgresql
@@ -0,0 +1,27 @@
age-encryption.org/v1
-> ssh-ed25519 oyEmTw lC+4KBNMMM5fHkFBRa/tJT+jFZeN+mw5/8yrdojjVB0
YwL7HD2UJ14F/hqbCAQU6KYqUzshv+0c8GHs+ZvAp4Q
-> ssh-ed25519 mOmPfg nUi8aarXOdi1x5PvO15/U1hM6I4quLD7eVQGZrN8OW8
aPTW1RJ9USImY2zMSL6g9PVwZ9T+7JgOLExnpYKZt9Y
-> ssh-ed25519 YJiRbw kEJIPA5pyp8mp1tS+EX7YGwxssQ3RYpR7KOpubCa3n0
p7uz1Zhm3WiR2rYWTnR4WaAwwPL71ILSmul0VadddJQ
-> ssh-ed25519 aY2AXA GZnDdhRihahe0WCfhx7urPRXn+XWMwUGiU+mC4qaXBM
QGqQVWLLSb0TII1gF4rHjqqOGMogmEEy9/PoE5wB0CM
-> ssh-ed25519 xNtnoA tfCFZUkCqvOJ0etchpciY2FfvoX0Y1wW7IU8I2u6pBw
gqi1YjkYY5Q1wd3UL7bYVFUCSK51V3ggeFcmIhdnug4
-> ssh-ed25519 Nl/5yA fvgVFAiODubImv5HKKvk9BTrw4abIq1Xi1WC+CxupV4
Flg0H5pNbfKmyDH1NRBwyzDjQK2v8Z+RJrR2Br3aSa0
-> ssh-ed25519 GdLgCQ CRzrCRlcBKiLa7ghPfbfrwz08RYH55zRIdPKyXc2jkE
43Sd7ERicIqrgn0Di7yQ43qJsYbtgeE99DvOj0AzA6A
-> ssh-ed25519 tOH/HQ pzx7DaPLmk070Zz5yi9BIYGajCKba6/j5CjsQcuHLkg
4XSP61C4oovtYIvTioZaiB0MoP5/kkk/4a7TWxs0wEQ
-> ssh-ed25519 FpzvfQ xJpLuQ3NhiVT7PNm5/NngiwV8cm1wYlBjlPsKOcV2nM
nV9Jx/eIz6MIa217sntxrp2HmkbJsN0hseUgp7iqzSg
-> ssh-ed25519 kdPvzQ v3TYNmF/9DHD1eKdFblwpfyBh78+jBaiP0H62JJnQF4
vYQkEzhLmFMiG3TdoSfB/Xa7g6wYzYB2K2jyO/X67Yo
-> ssh-ed25519 onmXpg iNwyY2pwpwupeu3ZN1ALWl2Z6EJZpqHDFK+IQp8EGHo
ez+cR4a8i2nJkiko23wflNomrpaoMYDR3fWHrMZHe5M
-> ssh-ed25519 CnhD0g fU6TSuG9ZEEUxQE9CJLg9wu71IryXpJpb5NXCqdOBiw
GXPNWmn/SHBOHwBVOGLCfEYkUSF+JkalLKbbBxF4aTE
--- Zk7n2mzoAnSuC6CdpPH+LGeGVcRPJL4zMt6d+Q2Eipw
æ¯ôΧ‚%d29úß>#␍£æÅp ÐvLj‘ç¿Èß×}³õõ[îæ`žR¿ yno¥ÏŠ‘•0»Nsyh¤&7NÀ¨À¢Â×°žÉ<àaV¦oÍ·î”øùÏWäoÓyÉ«þ% Obà’Œ#6ïÊ¿R–
Binary file not shown.
Binary file not shown.
+6
View File
@@ -0,0 +1,6 @@
[client.admin]
key = AQBojDlmfnc8MBAAkr+PXbSewmq4OooESo2X1A==
caps mds = "allow *"
caps mgr = "allow *"
caps mon = "allow *"
caps osd = "allow *"
View File
+13
View File
@@ -0,0 +1,13 @@
[mon.]
key = AQAUijlm7emnJBAAKsHT1+2EzYRQxKsL4KwwkQ==
caps mon = "allow *"
[client.admin]
key = AQBojDlmfnc8MBAAkr+PXbSewmq4OooESo2X1A==
caps mds = "allow *"
caps mgr = "allow *"
caps mon = "allow *"
caps osd = "allow *"
[client.bootstrap-osd]
key = AQDvJDpm4BDlIhAAXISJWnrOtNDk0FqhSX0/YQ==
caps mgr = "allow r"
caps mon = "profile bootstrap-osd"
+4
View File
@@ -0,0 +1,4 @@
[client.bootstrap-osd]
key = AQDvJDpm4BDlIhAAXISJWnrOtNDk0FqhSX0/YQ==
caps mgr = "allow r"
caps mon = "profile bootstrap-osd"
+28
View File
@@ -0,0 +1,28 @@
age-encryption.org/v1
-> ssh-ed25519 oyEmTw hf1hKhiFfX6yMQ1qcMrDwwIaNd2HfW+n9GnbqbE/Rh4
wq11rHPGL3fbljB29TGjXrNyJHgLOCCZsSz4zYWM4vg
-> ssh-ed25519 mOmPfg 9jL8idaEmiGayJIxk/1EFHFJbIx7M0M+fMI/TWeoWhw
Ql66dcWE1WRCLuoTFXGiLqzohHYBIjSdigWMribJJyA
-> ssh-ed25519 YJiRbw /1BFGrfrte3CivJUS/GvSHMwkN8GzkPKhaYnFwtnFDs
qlLfYrSe/Z0BlxLIp5n9KAmHcE4IZYAAmIWRlStwq0Y
-> ssh-ed25519 aY2AXA SRklz9w4e5Jwl7XufavpBsHeablN5VG9uYH+iFUVwVA
UHPOD9dqEzg6XV3uKfvMgY0ChSeTxXt85kRI04YWSz0
-> ssh-ed25519 xNtnoA IaaP0EB/jO3SI3t/xRdQ3lwNoUEwbnfiMLozmCm/WHg
3rNnvts8o+nC5sl5CIRqVmGVRXNJ66YY1cW7kQOfWtI
-> ssh-ed25519 Nl/5yA cKrmmqXsTo0+fca2yYkverutncYCwk520aeBAGaHXwQ
4xWBcM/dSZlXLhhjMxp80msywQU25weHTz046KwljKk
-> ssh-ed25519 GdLgCQ ZfvLrLUWu4xxFYONerRZM5p9uxvT9szo1V0TJON6rSc
NbB1zDiCuV1zHLre0uA5dvBEHxIUauz42xk/oCvczlA
-> ssh-ed25519 tOH/HQ 1Y20TH6y2I4Qm8w0Nzu5iC+K3ZUiaIL7PemZBZVPliE
1i1PVvXPT7cWdfmr1zs68WOc1UfaIT7dTRcrc+jXMs0
-> ssh-ed25519 FpzvfQ ZhVpLDqkN/nlXqtuF+GRQlSrxg0sf5w+6+ZG2DdPE0w
qo/WhjlAs1GrQycXsZHJ4UNcF5cXeErjhPBxDRHFhYU
-> ssh-ed25519 kdPvzQ 9zXqF+TL09+CiiQmFBN4Ot/c6uD4u0OEYXWJPaFRSxY
DPVcP9vxZj/6kXRc0OgBprgJKwfL9NB9EIXYJyqah7o
-> ssh-ed25519 onmXpg Gs0MOWzCOYIRhBPfZyL5Z1TdPqMNIq3wXIlq2DYbBWI
yUzy442MRbdWty9RDsaY5O4Wchvd7LEAuGnGa8fCOxA
-> ssh-ed25519 CnhD0g 6tT8mA7uhnmzCpNTogvn17sO8zTW0exFeixIgvAyAyk
ytGcHx7w5rz+c2gJ1FVdhLXG2O38JChCCNqSttwxzsI
--- 4i0TkrK0RTDthPFfeHDd2ibgqaTKIBurUlyqpokWi6o
áË#¹=ïäOF¯‰hìòp.ÃúŽú*‹˜efìó
ÇQúÆ
+27
View File
@@ -0,0 +1,27 @@
age-encryption.org/v1
-> ssh-ed25519 oyEmTw K64YZ3oV6Y6Yo8MS94zi0kCYnFawmOJSjBITRG7AeiQ
9OJyljEKIx1s1PfIdMvtzw+2cXS5pXjkgAipYLiDjyw
-> ssh-ed25519 mOmPfg Hsh9HGdGSWnXznjR4mkiMkbKUOXcaCQFIO08EB5/Ekc
MdAvpPaplb5sZ1E1Oht4PK4AtqXZyPSMugyTMpfhPm0
-> ssh-ed25519 YJiRbw DlHantLuhX38Y2AB6Cz7KER10XSmGGyRGqJXCvGHDT8
ZwqPXgKnC5wirlIg+KCHA6TDhN0Sy4S+UFJDlruiooQ
-> ssh-ed25519 aY2AXA AQ9DBDsEyu9zEF8gKnfraumaYhp3BCAR86r/ILJ6IWE
T6JnZHXwUbccwsPJHTv+hFcVk2mCR2XLmb9T1eZnuZo
-> ssh-ed25519 xNtnoA t0uPYr6snRzOb2PzPz5TmjCfk3VsnE4SUiaNMMyEHU4
a431i8PRHPIlIrguN20bgkhwKU7JlmvbTGxxn50TCLE
-> ssh-ed25519 Nl/5yA sleAnnThOoNzRWNMh1IGzp3ZZATBofTENSxiBK9joUw
TRUyZFIJXFejD3HVkVVBVel3lzQ4VJosYw/Dlvei0hs
-> ssh-ed25519 GdLgCQ lFiwpazUJUnR43dvdLp1Zunl/DuQw+HmRo95OaCfcxk
jJ/Q46ePulw0jEGW8zEd7IWWXu16XkeOkoFlohh+xl4
-> ssh-ed25519 tOH/HQ 7BMLfACpO9nFjLbk7wkn1d2UQUJCBy2HDvaDrQ8tfls
kx5Uhf4hpOa4SMgkHsooIJ7yOKAXVcN27GRkGJHGFGg
-> ssh-ed25519 FpzvfQ PzqPPe2QOHMi8Qe0itydR6i+lIVwrV+uAQxMBHlicjo
WN2nq3X9g1cfEAes4VcvwZgRCOCOg7BaHloibSEyVrA
-> ssh-ed25519 kdPvzQ KxmqKQtYW8IkpWIdf+I59v7AUZKT/3FSZYLVIDQofz4
5DQ4dwCYhFKZKo3fluQPa6skzz6CrdICTzS3FRzccnk
-> ssh-ed25519 onmXpg s/bWvEbtSGEzCJm8NVpCGjedkM8x3ghfOacNfvlJ+10
vcEoWg6QnoXoV3DU0Kyc6ZZRWbXE/pPYWCl2keEzoeU
-> ssh-ed25519 CnhD0g Lrb+HkK0iCFpSRfsJm+tdROGJIfnEayteY1Ja4l2lUQ
YzqwdSAmF5ksx9BpUJk/aIz2xenaAacwxRxZGcyVXSQ
--- J031VMz/nwgAAOpEKSqxKKZ8wOOrONpkptB5RA1lzMQ
"y(4“0Ê!edxh‰ÉßH£‰±,ÕRkÐùVˆÚhnPÑÒ0ä¼EÅuëEŽÍ®
+4
View File
@@ -60,9 +60,13 @@ in
"gitlab/myself-vbox-runner-reg.age".publicKeys = everyone;
"gitlab/myself-podman-runner-reg.age".publicKeys = everyone;
"gitlab/myself-shell-runner-reg.age".publicKeys = everyone;
"gitlab/linode-deployer-runner-reg.age".publicKeys = everyone;
"gitlab/docker-auth.age".publicKeys = everyone;
"acme_password.age".publicKeys = everyone;
"ca/intermediate_key.age".publicKeys = everyone;
"ca/root_key.age".publicKeys = everyone;
"minio_secret_access_key.age".publicKeys = everyone;
"minio_access_key_id.age".publicKeys = everyone;
}