diff --git a/ceph/home.nix b/ceph/home.nix new file mode 100644 index 0000000..124937b --- /dev/null +++ b/ceph/home.nix @@ -0,0 +1,21 @@ +{ + fsid = "749bf0ea-acf5-4a5e-b33e-9a057455c06b"; + clusterName = "home"; + initialMonitors = [ { + hostname = "myself.thehellings.lan"; + ipAddress = "10.42.1.6"; + } { + hostname = "jeremiah.thehellings.lan"; + ipAddress = "10.42.1.8"; + } { + hostname = "hosea.thehellings.lan"; + ipAddress = "10.42.1.7"; + } ]; + mdsNodes = [ { + hostname = "jeremiah.thehellings.lan"; + ipAddress = "10.42.1.8"; + } ]; + publicNetworks = [ "10.42.0.0/16" ]; + clusterNetworks = [ "10.201.0.0/16" ]; + adminKeyring = ../secrets/home.client.admin.keyring; +} diff --git a/flake.lock b/flake.lock index 67c2120..5ef373b 100644 --- a/flake.lock +++ b/flake.lock @@ -10,11 +10,11 @@ "systems": "systems" }, "locked": { - "lastModified": 1707830867, - "narHash": "sha256-PAdwm5QqdlwIqGrfzzvzZubM+FXtilekQ/FA0cI49/o=", + "lastModified": 1712079060, + "narHash": "sha256-/JdiT9t+zzjChc5qQiF+jhrVhRt8figYH29rZO7pFe4=", "owner": "ryantm", "repo": "agenix", - "rev": "8cb01a0e717311680e0cbca06a76cbceba6f3ed6", + "rev": "1381a759b205dff7a6818733118d02253340fd5e", "type": "github" }, "original": { @@ -52,11 +52,11 @@ ] }, "locked": { - "lastModified": 1705915768, - "narHash": "sha256-+Jlz8OAqkOwJlioac9wtpsCnjgGYUhvLpgJR/5tP9po=", + "lastModified": 1717976995, + "narHash": "sha256-u3HBinyIyUvL1+N816bODpJmSQdgn0Mbb8BprFw7kqo=", "owner": "lnl7", "repo": "nix-darwin", - "rev": "1e706ef323de76236eb183d7784f3bd57255ec0b", + "rev": "315aa649ba307704db0b16c92f097a08a65ec955", "type": "github" }, "original": { @@ -66,7 +66,43 @@ "type": "github" } }, + "devshell": { + "inputs": { + "flake-utils": "flake-utils_2", + "nixpkgs": [ + "nixvim", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1717408969, + "narHash": "sha256-Q0OEFqe35fZbbRPPRdrjTUUChKVhhWXz3T9ZSKmaoVY=", + "owner": "numtide", + "repo": "devshell", + "rev": "1ebbe68d57457c8cae98145410b164b5477761f4", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "devshell", + "type": "github" + } + }, "flake-compat": { + "locked": { + "lastModified": 1696426674, + "narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=", + "rev": "0f9255e01c2351cc7d116c072cb317785dd33b33", + "revCount": 57, + "type": "tarball", + "url": "https://api.flakehub.com/f/pinned/edolstra/flake-compat/1.0.1/018afb31-abd1-7bff-a5e4-cff7e18efb7a/source.tar.gz" + }, + "original": { + "type": "tarball", + "url": "https://flakehub.com/f/edolstra/flake-compat/1.tar.gz" + } + }, + "flake-compat_2": { "flake": false, "locked": { "lastModified": 1696426674, @@ -82,16 +118,53 @@ "type": "github" } }, + "flake-compat_3": { + "flake": false, + "locked": { + "lastModified": 1696426674, + "narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=", + "owner": "edolstra", + "repo": "flake-compat", + "rev": "0f9255e01c2351cc7d116c072cb317785dd33b33", + "type": "github" + }, + "original": { + "owner": "edolstra", + "repo": "flake-compat", + "type": "github" + } + }, + "flake-parts": { + "inputs": { + "nixpkgs-lib": [ + "nixvim", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1717285511, + "narHash": "sha256-iKzJcpdXih14qYVcZ9QC9XuZYnPc6T8YImb6dX166kw=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "2a55567fcf15b1b1c7ed712a2c6fadaec7412ea8", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, "flake-utils": { "inputs": { "systems": "systems_2" }, "locked": { - "lastModified": 1694529238, - "narHash": "sha256-zsNZZGTGnMOf9YpHKJqMSsa0dXbfmxeoJ7xHlrt+xmY=", + "lastModified": 1710146030, + "narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=", "owner": "numtide", "repo": "flake-utils", - "rev": "ff7b65b44d01cf9ba6a71320833626af21126384", + "rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a", "type": "github" }, "original": { @@ -105,11 +178,11 @@ "systems": "systems_3" }, "locked": { - "lastModified": 1705309234, - "narHash": "sha256-uNRRNRKmJyCRC/8y1RqBkqWBLM034y4qN7EprSdmgyA=", + "lastModified": 1701680307, + "narHash": "sha256-kAuep2h5ajznlPMD9rnQyffWG8EM/C73lejGofXvdM8=", "owner": "numtide", "repo": "flake-utils", - "rev": "1ef2e671c3b0c19053962c07dbda38332dcebf26", + "rev": "4022d587cbbfd70fe950c1e2083a02621806a725", "type": "github" }, "original": { @@ -123,11 +196,11 @@ "systems": "systems_4" }, "locked": { - "lastModified": 1705309234, - "narHash": "sha256-uNRRNRKmJyCRC/8y1RqBkqWBLM034y4qN7EprSdmgyA=", + "lastModified": 1710146030, + "narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=", "owner": "numtide", "repo": "flake-utils", - "rev": "1ef2e671c3b0c19053962c07dbda38332dcebf26", + "rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a", "type": "github" }, "original": { @@ -136,22 +209,52 @@ "type": "github" } }, - "haumea": { + "git-hooks": { "inputs": { - "nixpkgs": "nixpkgs" + "flake-compat": "flake-compat_2", + "gitignore": "gitignore", + "nixpkgs": [ + "nixvim", + "nixpkgs" + ], + "nixpkgs-stable": [ + "nixvim", + "nixpkgs" + ] }, "locked": { - "lastModified": 1685133229, - "narHash": "sha256-FePm/Gi9PBSNwiDFq3N+DWdfxFq0UKsVVTJS3cQPn94=", - "owner": "nix-community", - "repo": "haumea", - "rev": "34dd58385092a23018748b50f9b23de6266dffc2", + "lastModified": 1717664902, + "narHash": "sha256-7XfBuLULizXjXfBYy/VV+SpYMHreNRHk9nKMsm1bgb4=", + "owner": "cachix", + "repo": "git-hooks.nix", + "rev": "cc4d466cb1254af050ff7bdf47f6d404a7c646d1", "type": "github" }, "original": { - "owner": "nix-community", - "ref": "v0.2.2", - "repo": "haumea", + "owner": "cachix", + "repo": "git-hooks.nix", + "type": "github" + } + }, + "gitignore": { + "inputs": { + "nixpkgs": [ + "nixvim", + "git-hooks", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1709087332, + "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", + "owner": "hercules-ci", + "repo": "gitignore.nix", + "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "gitignore.nix", "type": "github" } }, @@ -162,16 +265,16 @@ ] }, "locked": { - "lastModified": 1705659542, - "narHash": "sha256-WA3xVfAk1AYmFdwghT7mt/erYpsU6JPu9mdTEP/e9HQ=", + "lastModified": 1717527182, + "narHash": "sha256-vWSkg6AMok1UUQiSYVdGMOXKD2cDFnajITiSi0Zjd1A=", "owner": "nix-community", "repo": "home-manager", - "rev": "10cd9c53115061aa6a0a90aad0b0dde6a999cdb9", + "rev": "845a5c4c073f74105022533907703441e0464bc3", "type": "github" }, "original": { "owner": "nix-community", - "ref": "release-23.11", + "ref": "release-24.05", "repo": "home-manager", "type": "github" } @@ -183,11 +286,11 @@ ] }, "locked": { - "lastModified": 1706798041, - "narHash": "sha256-BbvuF4CsVRBGRP8P+R+JUilojk0M60D7hzqE0bEvJBQ=", + "lastModified": 1717931644, + "narHash": "sha256-Sz8Wh9cAiD5FhL8UWvZxBfnvxETSCVZlqWSYWaCPyu0=", "owner": "nix-community", "repo": "home-manager", - "rev": "4d53427bce7bf3d17e699252fd84dc7468afc46e", + "rev": "3d65009effd77cb0d6e7520b68b039836a7606cf", "type": "github" }, "original": { @@ -221,16 +324,16 @@ "home-manager_2": { "inputs": { "nixpkgs": [ - "nixneovim", + "nixvim", "nixpkgs" ] }, "locked": { - "lastModified": 1705535278, - "narHash": "sha256-V5+XKfNbiY0bLKLQlH+AXyhHttEL7XcZBH9iSbxxexA=", + "lastModified": 1717525419, + "narHash": "sha256-5z2422pzWnPXHgq2ms8lcCfttM0dz+hg+x1pCcNkAws=", "owner": "nix-community", "repo": "home-manager", - "rev": "b84191db127c16a92cbdf7f7b9969d58bb456699", + "rev": "a7117efb3725e6197dd95424136f79147aa35e5b", "type": "github" }, "original": { @@ -239,51 +342,34 @@ "type": "github" } }, - "nix-flake-tests": { - "locked": { - "lastModified": 1677844186, - "narHash": "sha256-ErJZ/Gs1rxh561CJeWP5bohA2IcTq1rDneu1WT6CVII=", - "owner": "antifuchs", - "repo": "nix-flake-tests", - "rev": "bbd9216bd0f6495bb961a8eb8392b7ef55c67afb", - "type": "github" - }, - "original": { - "owner": "antifuchs", - "repo": "nix-flake-tests", - "type": "github" - } - }, - "nix-github-actions": { + "nix-darwin": { "inputs": { "nixpkgs": [ - "nixneovim", - "nixneovimplugins", - "poetry2nix", + "nixvim", "nixpkgs" ] }, "locked": { - "lastModified": 1688870561, - "narHash": "sha256-4UYkifnPEw1nAzqqPOTL2MvWtm3sNGw1UTYTalkTcGY=", - "owner": "nix-community", - "repo": "nix-github-actions", - "rev": "165b1650b753316aa7f1787f3005a8d2da0f5301", + "lastModified": 1716993688, + "narHash": "sha256-vo5k2wQekfeoq/2aleQkBN41dQiQHNTniZeVONWiWLs=", + "owner": "lnl7", + "repo": "nix-darwin", + "rev": "c0d5b8c54d6828516c97f6be9f2d00c63a363df4", "type": "github" }, "original": { - "owner": "nix-community", - "repo": "nix-github-actions", + "owner": "lnl7", + "repo": "nix-darwin", "type": "github" } }, "nix23_05": { "locked": { - "lastModified": 1702759837, - "narHash": "sha256-u3XeJVRe/Q975nwFE+6ALEwypMKJEELMJKDAhSKyq3M=", + "lastModified": 1704290814, + "narHash": "sha256-LWvKHp7kGxk/GEtlrGYV68qIvPHkU9iToomNFGagixU=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "b2566f4f897ac6224e094b167d9488d03e157f28", + "rev": "70bdadeb94ffc8806c0570eb5c2695ad29f0e421", "type": "github" }, "original": { @@ -293,83 +379,17 @@ "type": "github" } }, - "nixneovim": { - "inputs": { - "flake-utils": "flake-utils_2", - "haumea": "haumea", - "home-manager": "home-manager_2", - "nix-flake-tests": "nix-flake-tests", - "nixneovimplugins": "nixneovimplugins", - "nixpkgs": "nixpkgs_2", - "nmd": "nmd", - "nmt": "nmt" - }, - "locked": { - "lastModified": 1705702328, - "narHash": "sha256-yDPcAUzGlQ4e7JKHVligTUpXcB2X18QNOrA5pzmeus0=", - "owner": "NixNeovim", - "repo": "NixNeovim", - "rev": "30e3b1854039a16d8fd08a1ed3f5aaf6c114060e", - "type": "github" - }, - "original": { - "owner": "NixNeovim", - "repo": "NixNeovim", - "type": "github" - } - }, - "nixneovimplugins": { - "inputs": { - "flake-utils": [ - "nixneovim", - "flake-utils" - ], - "nixpkgs": [ - "nixneovim", - "nixpkgs" - ], - "poetry2nix": "poetry2nix" - }, - "locked": { - "lastModified": 1705344848, - "narHash": "sha256-Ns//Yrqug/OmupDUS4ue1tTvv4/UmLtY9oI6dIeWcMM=", - "owner": "nixneovim", - "repo": "nixneovimplugins", - "rev": "1054b77f33b54727082fb17170ce91d121b8a496", - "type": "github" - }, - "original": { - "owner": "nixneovim", - "repo": "nixneovimplugins", - "type": "github" - } - }, "nixpkgs": { "locked": { - "lastModified": 1681001314, - "narHash": "sha256-5sDnCLdrKZqxLPK4KA8+f4A3YKO/u6ElpMILvX0g72c=", - "owner": "nix-community", - "repo": "nixpkgs.lib", - "rev": "367c0e1086a4eb4502b24d872cea2c7acdd557f4", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "nixpkgs.lib", - "type": "github" - } - }, - "nixpkgs_2": { - "locked": { - "lastModified": 1705496572, - "narHash": "sha256-rPIe9G5EBLXdBdn9ilGc0nq082lzQd0xGGe092R/5QE=", - "owner": "nixos", + "lastModified": 1717786204, + "narHash": "sha256-4q0s6m0GUcN7q+Y2DqD27iLvbcd1G50T2lv08kKxkSI=", + "owner": "NixOS", "repo": "nixpkgs", - "rev": "842d9d80cfd4560648c785f8a4e6f3b096790e19", + "rev": "051f920625ab5aabe37c920346e3e69d7d34400e", "type": "github" }, "original": { - "owner": "nixos", + "owner": "NixOS", "ref": "nixos-unstable", "repo": "nixpkgs", "type": "github" @@ -377,27 +397,27 @@ }, "nixstable": { "locked": { - "lastModified": 1708831307, - "narHash": "sha256-0iL/DuGjiUeck1zEaL+aIe2WvA3/cVhp/SlmTcOZXH4=", + "lastModified": 1717952948, + "narHash": "sha256-mJi4/gjiwQlSaxjA6AusXBN/6rQRaPCycR7bd8fydnQ=", "owner": "nixos", "repo": "nixpkgs", - "rev": "5bf1cadb72ab4e77cb0b700dab76bcdaf88f706b", + "rev": "2819fffa7fa42156680f0d282c60d81e8fb185b7", "type": "github" }, "original": { "owner": "nixos", - "ref": "nixos-23.11", + "ref": "nixos-24.05", "repo": "nixpkgs", "type": "github" } }, "nixunstable": { "locked": { - "lastModified": 1709961763, - "narHash": "sha256-6H95HGJHhEZtyYA3rIQpvamMKAGoa8Yh2rFV29QnuGw=", + "lastModified": 1717786204, + "narHash": "sha256-4q0s6m0GUcN7q+Y2DqD27iLvbcd1G50T2lv08kKxkSI=", "owner": "nixos", "repo": "nixpkgs", - "rev": "3030f185ba6a4bf4f18b87f345f104e6a6961f34", + "rev": "051f920625ab5aabe37c920346e3e69d7d34400e", "type": "github" }, "original": { @@ -407,46 +427,38 @@ "type": "github" } }, - "nmd": { - "flake": false, - "locked": { - "lastModified": 1672949361, - "narHash": "sha256-WWg1kbilAb3sA+RoJtSYfAZvyYu1Nk79ocHaerwbQxQ=", - "owner": "~rycee", - "repo": "nmd", - "rev": "fb9cf8e991487c6923f3c654b8ae51b6f0f205ce", - "type": "sourcehut" + "nixvim": { + "inputs": { + "devshell": "devshell", + "flake-compat": "flake-compat", + "flake-parts": "flake-parts", + "git-hooks": "git-hooks", + "home-manager": "home-manager_2", + "nix-darwin": "nix-darwin", + "nixpkgs": "nixpkgs", + "treefmt-nix": "treefmt-nix" }, - "original": { - "owner": "~rycee", - "repo": "nmd", - "rev": "fb9cf8e991487c6923f3c654b8ae51b6f0f205ce", - "type": "sourcehut" - } - }, - "nmt": { - "flake": false, "locked": { - "lastModified": 1694274695, - "narHash": "sha256-PufoLMSuBYkga8hTqYf/cIQzSuy2lfFj+cdKcp2nLEI=", - "owner": "jooooscha", - "repo": "nmt", - "rev": "29595267923b4a6ce766ff0d85afaa930842b88d", + "lastModified": 1718028681, + "narHash": "sha256-C27X1vnsxKaKd1dCUU/u3LU+3DiA3Jo/ApvDiDNPIrI=", + "owner": "nix-community", + "repo": "nixvim", + "rev": "33a32c94176feebd3ff5259ce418b989b428d5ae", "type": "github" }, "original": { - "owner": "jooooscha", - "repo": "nmt", + "owner": "nix-community", + "repo": "nixvim", "type": "github" } }, "nurpkgs": { "locked": { - "lastModified": 1706910257, - "narHash": "sha256-w0EN3LJS+4HlkTBb3rgImSWCkzNdFWxsIbgsYpKh09E=", + "lastModified": 1718026702, + "narHash": "sha256-B62vRJYFK7x5pJKDvXCIRgKcAS9K/KwoTBYAECfb81A=", "owner": "nix-community", "repo": "NUR", - "rev": "96b0e9d38890afb8e4af6d6a556ee27e79fd6e22", + "rev": "f7e5fe023ea5742a1db039b6ba17f717ef24cc0f", "type": "github" }, "original": { @@ -455,34 +467,6 @@ "type": "github" } }, - "poetry2nix": { - "inputs": { - "flake-utils": [ - "nixneovim", - "nixneovimplugins", - "flake-utils" - ], - "nix-github-actions": "nix-github-actions", - "nixpkgs": [ - "nixneovim", - "nixneovimplugins", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1689849924, - "narHash": "sha256-d259Z2S7CS7Na04qQNQ6LYQILuI7cf4Rpe76qc4mz40=", - "owner": "nix-community", - "repo": "poetry2nix", - "rev": "1d7eda9336f336392d24e9602be5cb9be7ae405c", - "type": "github" - }, - "original": { - "owner": "nix-community", - "repo": "poetry2nix", - "type": "github" - } - }, "root": { "inputs": { "agenix": "agenix", @@ -491,9 +475,9 @@ "hm": "hm", "hmunstable": "hmunstable", "nix23_05": "nix23_05", - "nixneovim": "nixneovim", "nixstable": "nixstable", "nixunstable": "nixunstable", + "nixvim": "nixvim", "nurpkgs": "nurpkgs", "wsl": "wsl" } @@ -558,20 +542,41 @@ "type": "github" } }, + "treefmt-nix": { + "inputs": { + "nixpkgs": [ + "nixvim", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1717850719, + "narHash": "sha256-npYqVg+Wk4oxnWrnVG7416fpfrlRhp/lQ6wQ4DHI8YE=", + "owner": "numtide", + "repo": "treefmt-nix", + "rev": "4fc1c45a5f50169f9f29f6a98a438fb910b834ed", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "treefmt-nix", + "type": "github" + } + }, "wsl": { "inputs": { - "flake-compat": "flake-compat", + "flake-compat": "flake-compat_3", "flake-utils": "flake-utils_3", "nixpkgs": [ "nixunstable" ] }, "locked": { - "lastModified": 1709211223, - "narHash": "sha256-1cjd+yXbTlnCwNwEDjn289rJ2f0er5M8pOig4PxniEM=", + "lastModified": 1713528946, + "narHash": "sha256-IBQta+xrEaI2S5UmYrXcgV7Tu7rGLQu2V3TeJseLPSg=", "owner": "nix-community", "repo": "NixOS-WSL", - "rev": "3257ad7f173b0314c8a42fec450fa6556495b97c", + "rev": "63c1247e12f269396ed2df8cdec3aed1f0f3928c", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index 148529a..a0dfed2 100644 --- a/flake.nix +++ b/flake.nix @@ -15,16 +15,16 @@ }; flake-utils.url = "github:numtide/flake-utils"; hm = { - url = "github:nix-community/home-manager/release-23.11"; + url = "github:nix-community/home-manager/release-24.05"; inputs.nixpkgs.follows = "nixstable"; }; hmunstable = { url = "github:nix-community/home-manager/master"; inputs.nixpkgs.follows = "nixstable"; }; - nixneovim.url = "github:NixNeovim/NixNeovim"; + nixvim.url = "github:nix-community/nixvim"; nix23_05.url = "github:NixOS/nixpkgs/nixos-23.05"; - nixstable.url = "github:nixos/nixpkgs/nixos-23.11"; + nixstable.url = "github:nixos/nixpkgs/nixos-24.05"; nixunstable.url = "github:nixos/nixpkgs/nixos-unstable"; nurpkgs.url = "github:nix-community/NUR"; wsl = { @@ -39,10 +39,10 @@ flake-utils, hm, hmunstable, - nixneovim, nix23_05, nixstable, nixunstable, + nixvim, nurpkgs, wsl, @@ -58,7 +58,6 @@ agenix.overlays.default pkg-sets local_overlay - nixneovim.overlays.default nurpkgs.overlay ]; diff --git a/hardware-configuration.nix b/hardware-configuration.nix index 41686e2..dbb261b 100644 --- a/hardware-configuration.nix +++ b/hardware-configuration.nix @@ -5,30 +5,35 @@ { imports = - [ (modulesPath + "/profiles/qemu-guest.nix") + [ (modulesPath + "/installer/scan/not-detected.nix") ]; - boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "sr_mod" "virtio_blk" ]; + boot.initrd.availableKernelModules = [ "xhci_pci" "thunderbolt" "nvme" "uas" "sd_mod" ]; boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; boot.extraModulePackages = [ ]; fileSystems."/" = - { device = "/dev/disk/by-uuid/a13f941e-4985-47ab-a8c6-374a627c5ce1"; - fsType = "ext4"; + { device = "/dev/disk/by-uuid/607b933f-2967-4652-b478-4d8e9aa38a0d"; + fsType = "btrfs"; + options = [ "subvol=@" ]; }; - swapDevices = - [ { device = "/dev/disk/by-uuid/ac4557de-1ad5-4d3c-b9f4-5ec50dbf76f1"; } - ]; + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/B31C-C1F4"; + fsType = "vfat"; + }; + + swapDevices = [ ]; # Enables DHCP on each ethernet and wireless interface. In case of scripted networking # (the default) this is the recommended approach. When using systemd-networkd it's # still possible to use this option, but it's recommended to use it in conjunction # with explicit per-interface declarations with `networking.interfaces..useDHCP`. networking.useDHCP = lib.mkDefault true; - # networking.interfaces.ens18.useDHCP = lib.mkDefault true; - # networking.interfaces.ens19.useDHCP = lib.mkDefault true; + # networking.interfaces.enp0s13f0u1.useDHCP = lib.mkDefault true; + # networking.interfaces.wlp170s0.useDHCP = lib.mkDefault true; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; } diff --git a/home/home.nix b/home/home.nix index 12527fa..f35e327 100644 --- a/home/home.nix +++ b/home/home.nix @@ -3,9 +3,12 @@ host ? "most", ...}: +let + system = pkgs.system; +in { imports = [ - inputs.nixneovim.nixosModules.default + inputs.nixvim.homeManagerModules.default ./modules ./ansible.nix ./bash.nix diff --git a/home/hosts/exodus/default.nix b/home/hosts/exodus/default.nix new file mode 100644 index 0000000..665f951 --- /dev/null +++ b/home/hosts/exodus/default.nix @@ -0,0 +1,6 @@ +{ pkgs, config, ... }: + +{ + greg.gnome = true; + greg.gui = true; +} diff --git a/home/hosts/ivr/default.nix b/home/hosts/ivr/default.nix index 276c973..9f38b22 100644 --- a/home/hosts/ivr/default.nix +++ b/home/hosts/ivr/default.nix @@ -5,7 +5,6 @@ let djangorestframework django-rapyd-modernauth environs - #itg-django-utils mysqlclient pyyaml ruamel-yaml @@ -20,8 +19,8 @@ in { home = { packages = with pkgs; [ aacs + ansible bitwarden-cli - bruno direnv home-manager insomnia diff --git a/home/modules/gui.nix b/home/modules/gui.nix index ca87db7..0d2e7ec 100644 --- a/home/modules/gui.nix +++ b/home/modules/gui.nix @@ -14,7 +14,7 @@ let vars = { MOZ_ENABLE_WAYLAND = "1"; - XDG_CURRENT_DESKTOP = "sway"; + XDG_CURRENT_DESKTOP = "GNOME"; }; in { options.greg.gui = lib.mkEnableOption "Enable GUI programs"; @@ -69,7 +69,7 @@ in { }; extensions = with pkgs.nur.repos.rycee.firefox-addons; [ bitwarden - bypass-paywalls-clean + #bypass-paywalls-clean gsconnect foxyproxy-standard multi-account-containers diff --git a/home/ssh/authorized_keys b/home/ssh/authorized_keys index 4f434cd..fe893a6 100644 --- a/home/ssh/authorized_keys +++ b/home/ssh/authorized_keys @@ -5,3 +5,4 @@ ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINnRc/kBhxcjpUtiRQY+BXnSObdp0jFL1395wAQxJip7 ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAl6DJVrPSujvJSAEA5Q8tRrzfJs/c6DMwqwQEUFffIR greg@myself ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGrqJQvDspLi1vXQRJ/Z5kN/F8jCBHvaXjo+5zLuIYjR greg@hosea ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIYIiecdyM9c7tXgR96983K3wqiJeQRMbrzGIF8Wy6uO greg@jeremiah +ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC189EnvWjNUp3xSzPMAtw85oQEsvP1tQR1TK640nLx6 greg@exodus diff --git a/home/vim.nix b/home/vim.nix index 8c20638..4524ede 100644 --- a/home/vim.nix +++ b/home/vim.nix @@ -27,20 +27,18 @@ in pyright ]; - programs.nixneovim = { + programs.nixvim = { enable = true; - colorscheme = "gruvbox"; + colorschemes.gruvbox.enable = true; globals = { indent_guides_enable_on_vim_startup = 1; nix_recommended_style = 0; - NERDTreeIgnore = [ - "\\.pyc$" - "\\.pyo$" - "\\.o$" - "\\.class$" - ]; + netrw_liststyle = 3; + netrw_browse_split = 4; + netrw_altv = 1; + netrw_winsize = 25; }; - options = { + opts = { background = "dark"; backup = false; copyindent = true; @@ -68,22 +66,30 @@ in wrap = false; writebackup = false; }; - mappings = { - normalVisualOp = { - "" = ''":BufExplorer"''; - "" = ''":NERDTreeToggle"''; - "" = ''":Files"''; - "" = ''"j"''; - "" = ''"k"''; - "" = ''"h"''; - "" = ''"l"''; - "" = ''":GFiles?"''; - }; - }; + keymaps = let + winMove = key: { mode = "n"; key = ""; action = "${key}"; }; + in [ { + mode = "n"; + key = ""; + action = ":BufExplorer"; + } { + mode = "n"; + key = ""; + action = ":Lex"; + } { + mode = "n"; + key = ""; + action = ":GFiles?"; + } + (winMove "h") + (winMove "j") + (winMove "k") + (winMove "l") + ]; plugins = { airline = { enable = true; - theme = "gruvbox"; + settings.theme = "gruvbox"; }; gitgutter.enable = true; fugitive.enable = true; @@ -94,7 +100,6 @@ in extraPlugins = with pkgs.vimPlugins; [ bufexplorer gruvbox - nerdtree nvim-cmp packer-nvim diff --git a/home/vscodium.nix b/home/vscodium.nix index 589c30d..2f9fed4 100644 --- a/home/vscodium.nix +++ b/home/vscodium.nix @@ -11,15 +11,16 @@ enable = true; package = pkgs.vscodium; extensions = with pkgs.vscode-extensions; [ + arrterian.nix-env-selector asvetliakov.vscode-neovim bungcip.better-toml golang.go + jnoortheen.nix-ide mkhl.direnv ms-python.python vscjava.vscode-java-test vscjava.vscode-java-dependency vscjava.vscode-java-debug - vscodevim.vim ]; }; } diff --git a/home/xonsh.nix b/home/xonsh.nix index 411ef8e..10cb5c6 100644 --- a/home/xonsh.nix +++ b/home/xonsh.nix @@ -5,18 +5,10 @@ enable = true; sessionVariables = { - TIMEFORMAT = "%3Uu %3Ss %3lR %P%%"; CLICOLOR = 1; - LSCOLORS = "ExGxBxDxCxEgEdxbxgxcxd"; EDITOR = "${pkgs.vim}/bin/vim"; - # Tells vox where to find virtualenvs - VIRTUALENV_HOME = "${config.home.homeDirectory}/venv/"; # vte_new_tab_cwd causes new Terminal tabs to open in the # same CWD as the current tab - PROMPT = "{vte_new_tab_cwd}{env_name}{BOLD_GREEN}{user}@{hostname}{BOLD_BLUE} {short_cwd}{branch_color}{curr_branch: {}}{RESET} {BOLD_BLUE}{prompt_end}{RESET} "; - SWORD_PATH = "${config.home.homeDirectory}/.sword/"; - OS_CLOUD = "default"; - MAVEN_OPTS = " -Dmaven.wagon.http.ssl.insecure=true"; LESS_TERMCAP_mb = "\\033[01;31m"; # begin blinking LESS_TERMCAP_md = "\\033[01;31m"; # begin bold LESS_TERMCAP_me = "\\033[0m"; # end mode @@ -24,6 +16,15 @@ LESS_TERMCAP_se = "\\033[0m"; # end standout-mode LESS_TERMCAP_us = "\\033[00;36m"; # begin underline LESS_TERMCAP_ue = "\\033[0m"; # end underline + LIBMYSQL_ENABLE_CLEARTEXT_PLUGIN = "1"; + LSCOLORS = "ExGxBxDxCxEgEdxbxgxcxd"; + MAVEN_OPTS = " -Dmaven.wagon.http.ssl.insecure=true"; + OS_CLOUD = "default"; + PROMPT = "{vte_new_tab_cwd}{env_name}{BOLD_GREEN}{user}@{hostname}{BOLD_BLUE} {short_cwd}{branch_color}{curr_branch: {}}{RESET} {BOLD_BLUE}{prompt_end}{RESET} "; + SWORD_PATH = "${config.home.homeDirectory}/.sword/"; + TIMEFORMAT = "%3Uu %3Ss %3lR %P%%"; + # Tells vox where to find virtualenvs + VIRTUALENV_HOME = "${config.home.homeDirectory}/venv/"; COMPASS_SKIP_ORIGIN_CHECK = "True"; @@ -41,7 +42,6 @@ cci = "compass workspace run src/python3/uc/tools:circleci-checks"; ccover = "compass workspace cover --extra-cmd-args=\"--test_output=errors\""; cexec = "compass workspace exec"; - cfetch = "compass workspace exec bazel run src/go/compass.com/tools/circleci_results_cache/fetch/cmd/fetch:fetch"; cgh = "$GH_CONFIG_DIR=\"${config.home.homeDirectory}/.config/gh/compass\" gh"; cpip = "compass workspace run src/python3/uc/tools:run_pip_compile"; crun = "compass workspace run"; diff --git a/home/xonsh_footer.xsh b/home/xonsh_footer.xsh index 8554b2d..019831e 100644 --- a/home/xonsh_footer.xsh +++ b/home/xonsh_footer.xsh @@ -1,5 +1,25 @@ # vim: set ft=python : +def bw_unlock(): + """Unlocks the BitWarden CLI and adds the resulting session code to the + current environment variables. Also returns the code for them.""" + if "BW_SESSION" in ${...}: + return $BW_SESSION + result = $(bw unlock) + while "BW_SESSION" not in result: + result = $(bw unlock) + lines = result.split("\n") + l = [k for k in lines if 'BW_SESSION="' in k][0] + left, right = l.split("=", 1) + token = right[1:-1] + $BW_SESSION = token + return token + +def _cfetch(args): + bw_unlock() + $CIRCLECI_CLI_TOKEN=$(bw get password CircleCI) + compass workspace exec bazel run src/go/compass.com/tools/circleci_results_cache/fetch/cmd/fetch:fetch + def _rebuild(args): system = uname() if system.sysname == 'Darwin': @@ -48,6 +68,7 @@ def _bake(args): git clone src:greg/copier-templates.git ~/.copier-templates copier copy @(str(templates / args[0])) . +aliases['cfetch'] = _cfetch aliases['bake'] = _bake aliases['rebuild'] = _rebuild aliases['yaml2json'] = _yaml2json diff --git a/hosts/default.nix b/hosts/default.nix index edb844c..77d9903 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -39,6 +39,7 @@ let }; in { genesis = machine { name = "genesis"; }; + exodus = unstable { name = "exodus"; }; jude = unstable { name = "jude"; }; icdm-root = unstable { name = "icdm-root"; }; linode = machine { name = "linode"; }; diff --git a/hosts/exodus/default.nix b/hosts/exodus/default.nix new file mode 100644 index 0000000..fe06c2a --- /dev/null +++ b/hosts/exodus/default.nix @@ -0,0 +1,20 @@ +{ pkgs, config, ... }: + +{ + imports = [ + ./hardware-configuration.nix + ../jude/printing.nix + ]; + + boot.loader = { + systemd-boot.enable = true; + efi.canTouchEfiVariables = true; + }; + + networking.hostName = "exodus"; + greg = { + home = true; + gnome.enable = true; + tailscale.enable = true; + }; +} diff --git a/hosts/exodus/hardware-configuration.nix b/hosts/exodus/hardware-configuration.nix new file mode 100644 index 0000000..dbb261b --- /dev/null +++ b/hosts/exodus/hardware-configuration.nix @@ -0,0 +1,39 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "thunderbolt" "nvme" "uas" "sd_mod" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/607b933f-2967-4652-b478-4d8e9aa38a0d"; + fsType = "btrfs"; + options = [ "subvol=@" ]; + }; + + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/B31C-C1F4"; + fsType = "vfat"; + }; + + swapDevices = [ ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.enp0s13f0u1.useDHCP = lib.mkDefault true; + # networking.interfaces.wlp170s0.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/hosts/genesis/net/hosts b/hosts/genesis/net/hosts index 53a3406..60a6519 100644 --- a/hosts/genesis/net/hosts +++ b/hosts/genesis/net/hosts @@ -8,9 +8,10 @@ 10.42.1.2 opnsense router opnsense.thehellings.lan router.thehellings.lan 10.42.1.3 printer.thehellings.lan 10.42.1.4 chronicles chronicles.thehellings.lan nas.thehellings.lan -10.42.1.5 genesis genesis.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan speedtest.thehellings.lan nixcache.thehellings.lan gitcache.thehellings.lan s3.thehellings.lan +10.42.1.5 genesis genesis.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan speedtest.thehellings.lan nixcache.thehellings.lan gitcache.thehellings.lan 10.42.1.6 isaiah isaiah.thehellings.lan -10.42.1.7 hosea hosea.thehellings.lan +10.42.1.7 hosea hosea.thehellings.lan s3.thehellings.lan +10.42.1.8 jeremiah jeremiah.thehellings.lan 10.42.1.12 tv 10.42.100.6 isaiahbmc isaiahbmc.thehellings.lan @@ -24,6 +25,7 @@ 100.84.183.79 myself.home myself.shire-zebra.ts.net 100.78.226.76 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan 100.68.203.1 hosea.home hosea.shire-zebra.ts.net +100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net # Dev hosts 10.42.101.1 icdm.lan wiki.icdm.lan *.icdm.lan diff --git a/hosts/genesis/networking.nix b/hosts/genesis/networking.nix index dc87163..6366008 100644 --- a/hosts/genesis/networking.nix +++ b/hosts/genesis/networking.nix @@ -137,24 +137,24 @@ in { # Static IPs for things in the IOT range "b4:b0:24:9a:02:4a,192.168.66.5" # LD125 - "98:da:c4:20:f3:64,192.168.66.6" + "98:da:c4:20:f3:64,192.168.66.6" # Dining room light "54:af:97:c1:dc:b9,192.168.66.25" # Master bedroom Kasa switch "f0:03:8c:b3:b0:f6,192.168.66.55" # Roomba "4c:a1:61:05:cd:52,192.168.66.61" # Rainbird "48:d6:d5:5d:81:21,192.168.66.65" # Google Home "6c:29:90:3e:e2:02,192.168.66.66" # wiz - "28:87:ba:0e:ca:da,192.168.66.74" # KS200M switch - "28:87:ba:0e:c9:fd,192.168.66.75" - "54:af:97:c2:0f:a1,192.168.66.76" + "28:87:ba:0e:ca:da,192.168.66.74" # + "28:87:ba:0e:c9:fd,192.168.66.75" # Master closet + "54:af:97:c2:0f:a1,192.168.66.76" # Master toilet "54:af:97:83:ed:33,192.168.66.80" - "98:da:c4:77:80:18,192.168.66.84" - "98:da:c4:21:1b:2e,192.168.66.85" - "0c:80:63:41:6e:0f,192.168.66.90" - "0c:80:63:41:6c:5d,192.168.66.98" # HS200 switch + "98:da:c4:77:80:18,192.168.66.84" # Kitchen lights + "98:da:c4:21:1b:2e,192.168.66.85" # Living Room lights + "0c:80:63:41:6e:0f,192.168.66.90" # Front porch + "0c:80:63:41:6c:5d,192.168.66.98" # House number "ac:84:c6:5e:4b:28,192.168.66.100" - "98:da:c4:77:7f:4d,192.168.66.102" + "98:da:c4:77:7f:4d,192.168.66.102" # Office lights "8c:85:80:1c:f9:d1,192.168.66.104" - "98:da:c4:77:82:7b,192.168.66.105" + "98:da:c4:77:82:7b,192.168.66.105" # Parlor lamp "0c:80:63:41:74:73,192.168.66.106" # Front hall light switch "98:da:c4:20:ea:db,192.168.66.107" # Parlor light switch "8c:49:62:aa:58:60,192.168.66.108" # Roku, HiHandsome diff --git a/hosts/jeremiah/ceph.nix b/hosts/jeremiah/ceph.nix new file mode 100644 index 0000000..7648761 --- /dev/null +++ b/hosts/jeremiah/ceph.nix @@ -0,0 +1,33 @@ +{ config, ... }: + +let + publicIp = (builtins.elemAt config.networking.interfaces.enp68s0.ipv4.addresses 0).address; + sanIp = (builtins.elemAt config.networking.interfaces.enp67s0.ipv4.addresses 0).address; + vip = (builtins.elemAt config.networking.interfaces.enp68s0.ipv4.addresses 1).address; + hostname = config.networking.hostName; + baseConfig = import ../../ceph/home.nix; +in { + services.ceph-benaco = baseConfig // { + enable = true; + monitor = { + enable = true; + initialKeyring = ../../secrets/home.mon.keyring; + nodeName = hostname; + bindAddr = publicIp; + advertisedPublicAddr = vip; + }; + osdBindAddr = publicIp; + osdAdvertisedPublicAddr = publicIp; + osds = { + osd1 = { + enable = true; + bootstrapKeyring = ../../secrets/home.osd-bootstrap.keyring; + id = 1; + uuid = "c13bd2b1-cfc7-4966-8da5-d92356e87e06"; + blockDevice = "/dev/sda"; + blockDeviceUdevRuleMatcher = ''KERNEL=="sda"''; + clusterAddress = sanIp; + }; + }; + }; +} diff --git a/hosts/jeremiah/default.nix b/hosts/jeremiah/default.nix index 0b465a7..c992675 100644 --- a/hosts/jeremiah/default.nix +++ b/hosts/jeremiah/default.nix @@ -1,22 +1,66 @@ # Edit this configuration file to define what should be installed on -# your system. Help is available in the configuration.nix(5) man page +# your system. Help is available in the configuration.nix(5) man page # and in the NixOS manual (accessible by running ‘nixos-help’). { config, pkgs, ... }: { - imports = - [ # Include the results of the hardware scan. - ./hardware-configuration.nix - ]; + imports = + [ # Include the results of the hardware scan. + ./ceph.nix + ./hardware-configuration.nix + ]; - # Bootloader. - boot.loader.systemd-boot.enable = true; - boot.loader.efi.canTouchEfiVariables = true; + # Bootloader. + boot.loader.systemd-boot.enable = true; + boot.loader.efi.canTouchEfiVariables = true; - networking.hostName = "jeremiah"; # Define your hostname. - greg = { + networking = { + hostName = "jeremiah"; # Define your hostname. + useDHCP = false; + defaultGateway = { + address = " 10.42.1.1"; + interface = "enp68s0"; + }; + interfaces = { + enp68s0 = { + ipv4.addresses = [ { + address = "10.42.1.8"; + prefixLength = 16; + } { + address = "10.42.100.1"; + prefixLength = 16; + } ]; + }; + enp67s0 = { + ipv4.addresses = [ { + address = "10.201.1.2"; + prefixLength = 16; + } ]; + }; + }; + nameservers = [ + "10.42.1.5" + ]; + }; + greg = { home = true; - tailscale.enable = true; - }; + tailscale.enable = true; + }; + environment.systemPackages = with pkgs; [ + btrfs-progs + ]; + + fileSystems = { + "/nix" = { + fsType = "btrfs"; + options = [ "subvol=nix" ]; + device = "/dev/nvme0n1p1"; + }; + "/var" = { + fsType = "btrfs"; + options = [ "subvol=var" ]; + device = "/dev/nvme0n1p1"; + }; + }; } diff --git a/hosts/jude/default.nix b/hosts/jude/default.nix index ce86564..1b3dac2 100644 --- a/hosts/jude/default.nix +++ b/hosts/jude/default.nix @@ -32,8 +32,8 @@ greg = { tailscale.enable = true; sway.enable = false; - gnome.enable = false; - kde.enable = true; + gnome.enable = true; + kde.enable = false; }; boot.extraModulePackages = [ config.boot.kernelPackages.v4l2loopback ]; @@ -68,6 +68,7 @@ oathToolkit synology-drive-client terraform + usbutils vagrant ventoy ] diff --git a/hosts/jude/virt.nix b/hosts/jude/virt.nix index 6fcaefd..4cd286d 100644 --- a/hosts/jude/virt.nix +++ b/hosts/jude/virt.nix @@ -1,4 +1,4 @@ -{ pkgs, ... }: +{ pkgs, config, ... }: { environment.systemPackages = with pkgs; [ @@ -6,11 +6,11 @@ guestfs-tools libguestfs OVMFFull - ovftool packer virt-manager vmware-workstation vmfs-tools + xorriso ]; # Give my user access to the libvirtd process @@ -28,8 +28,6 @@ enableExtensionPack = true; }; - vmware.host.enable = false; - waydroid.enable = false; lxd.enable = false; }; @@ -39,20 +37,33 @@ boot.extraModprobeConfig = "options kvm_amd nested=1"; systemd.services = { - vbox = { + gitlab-runner = { conflicts = [ "libvirtd.service" ]; - serviceConfig = { - Type = "oneshot"; - RemainAfterExit = "yes"; - ExecStart = [ - "rmmod kvm_amd" - "rmmod kvm" - ]; - ExecStop = [ - "rmmod vboxnetflt" - "rmmod vboxnetadp" - "rmmod vboxdrv" - ]; + preStart = builtins.concatStringsSep "\n" [ + "${pkgs.kmod}/bin/modprobe vboxnetflt vboxdrv" + "${pkgs.kmod}/bin/modprobe vboxnetadp" + ]; + postStop = "${pkgs.kmod}/bin/rmmod vboxnetflt vboxnetadp vboxdrv"; + wantedBy = pkgs.lib.mkForce []; + serviceConfig.User = "root"; + }; + libvirtd = { + preStart = "${pkgs.kmod}/bin/modprobe kvm_amd"; + postStop = "${pkgs.kmod}/bin/rmmod kvm_amd kvm"; + }; + }; + + age.secrets.runner-reg.file = ../../secrets/gitlab/myself-vbox-runner-reg.age; + + services.gitlab-runner = { + enable = true; + settings.concurrent = 5; + services.vbox = { + executor = "shell"; + limit = 5; + registrationConfigFile = config.age.secrets.runner-reg.path; + environmentVariables = { + EFI_DIR = "${pkgs.OVMF.fd}/FV/"; }; }; }; diff --git a/hosts/linode/default.nix b/hosts/linode/default.nix index b443e07..8493590 100644 --- a/hosts/linode/default.nix +++ b/hosts/linode/default.nix @@ -1,4 +1,4 @@ -{ pkgs, lib, ... }: +{ pkgs, lib, config, ... }: { imports = [ @@ -26,6 +26,7 @@ ]; networking = { + networkmanager.enable = lib.mkForce false; hostName = "linode"; domain = "thehellings.com"; nameservers = [ @@ -33,6 +34,41 @@ ]; }; + age.secrets.runner-deployer = { + file = ../../secrets/gitlab/linode-deployer-runner-reg.age; + owner = "gitlab-runner"; + }; + + services.gitlab-runner = { + enable = true; + services.deployer = { + executor = "shell"; + registrationConfigFile = config.age.secrets.runner-deployer.path; + }; + }; + + users.users.gitlab-runner = { + isSystemUser = true; + group = "gitlab-runner"; + }; + users.groups.gitlab-runner = {}; + + systemd.services."gitlab-runner".serviceConfig = { + DynamicUser = lib.mkForce false; + User = "gitlab-runner"; + }; + + security.sudo.extraRules = [{ + users = [ "gitlab-runner" ]; + commands = [{ + command = "/run/current-system/sw/bin/systemctl"; + options = [ "NOPASSWD" ]; + } { + command = "/run/current-system/sw/bin/podman"; + options = [ "NOPASSWD" ]; + }]; + }]; + environment.systemPackages = with pkgs; [ bind graphviz diff --git a/hosts/linode/git.nix b/hosts/linode/git.nix index e475d94..d393ac3 100644 --- a/hosts/linode/git.nix +++ b/hosts/linode/git.nix @@ -2,6 +2,7 @@ let srcDomain = "src.thehellings.com"; + sshPort = 2222; in { greg.proxies."${srcDomain}" = { target = "http://git.thehellings.lan"; @@ -19,6 +20,8 @@ in { extraConfig = "client_max_body_size 250m;"; }; + networking.firewall.allowedTCPPorts = [ sshPort ]; + services.haproxy = { enable = true; config = builtins.concatStringsSep "\n" [ @@ -31,14 +34,11 @@ in { " timeout client 500s" " timeout server 1h" - "frontend gitsshd" - " bind *:2222" - " default_backend gitssh" + "listen gitsshd" + " bind *:${toString sshPort}" " timeout client 1h" - - "backend gitssh" " mode tcp" - " server git-thehellings-lan git.thehellings.lan:2222" + " server git-thehellings-lan git.thehellings.lan:22" ]; }; } diff --git a/hosts/linode/nextcloud.nix b/hosts/linode/nextcloud.nix index 7a4f5eb..2431006 100644 --- a/hosts/linode/nextcloud.nix +++ b/hosts/linode/nextcloud.nix @@ -25,7 +25,7 @@ enableACME = true; }; - greg.backup.jobs.nextcloud = { + greg.backup.jobs.nextcloud-bkup = { src = "/var/lib/nextcloud"; dest = "nextcloud-backup"; user = "nextcloud"; diff --git a/hosts/linode/nginx.nix b/hosts/linode/nginx.nix index dc7c4de..2f46ce3 100644 --- a/hosts/linode/nginx.nix +++ b/hosts/linode/nginx.nix @@ -23,7 +23,8 @@ in virtualisation.oci-containers = { backend = "podman"; containers."homepage" = { - image = "ghcr.io/greg-hellings/homepage:latest"; + # needs explicit port to match what gitlab-runner sees when pulling + image = "registry.thehellings.com:443/greg/homepage/gregs-homepage:latest"; ports = [ "${homepage}:80" ]; }; }; diff --git a/hosts/linode/postgres.nix b/hosts/linode/postgres.nix index 447ad1c..edd035c 100644 --- a/hosts/linode/postgres.nix +++ b/hosts/linode/postgres.nix @@ -1,8 +1,13 @@ { config, pkgs, lib, ... }: { + environment.systemPackages = [ + pkgs.upgrade-pg-cluster + ]; + services.postgresql = { enable = true; + package = pkgs.postgresql_15; checkConfig = true; ensureDatabases = [ "nextcloud" diff --git a/hosts/myself/container-git.nix b/hosts/myself/container-git.nix index 9635979..3309365 100644 --- a/hosts/myself/container-git.nix +++ b/hosts/myself/container-git.nix @@ -13,6 +13,19 @@ in { gitlab-jws = cfg "jws"; gitlab-key = cfg "key"; gitlab-cert = cfg "cert"; + + minio_access_key_id = { + file = ../../secrets/minio_access_key_id.age; + owner = "gitlab"; + group = "gitlab"; + mode = "0444"; + }; + minio_secret_access_key = { + file = ../../secrets/minio_secret_access_key.age; + owner = "gitlab"; + group = "gitlab"; + mode = "0444"; + }; }; networking.firewall.allowedTCPPorts = [ 80 registryPort ]; @@ -86,6 +99,34 @@ in { dbFile = config.age.secrets.gitlab-db.path; jwsFile = config.age.secrets.gitlab-jws.path; }; + + extraConfig = { + object_store = { + enabled = true; + proxy_download = false; # Tell them to reach out to object storage themselves! + connection = { + provider = "AWS"; + endpoint = "http://s3.thehellings.lan:9000"; + region = "us-east-1"; + aws_access_key_id = { _secret = config.age.secrets.minio_access_key_id.path; }; + aws_secret_access_key = { _secret = config.age.secrets.minio_secret_access_key.path; }; + path_style = true; # True for MinIO + aws_signature_version = 2; + }; + #storage_options = ...; + objects = builtins.listToAttrs ( builtins.map (x: lib.attrsets.nameValuePair x { bucket = "gitlab-${builtins.replaceStrings [ "_" ] [ "-" ] x}"; }) [ + "artifacts" + "ci_secure_files" + "dependency_proxy" + "external_diffs" + "lfs" + "packages" + "pages" + "terraform_state" + "uploads" + ]); + }; + }; }; nginx.virtualHosts."gitlab.shire-zebra.ts.net" = { @@ -147,6 +188,9 @@ in { "network.target" "network-online.target" ]; + preStart = '' + sleep 5 # tailscaled is up before it's ACTUALLY up... try waiting? + ''; }; system.stateVersion = lib.mkForce "24.05"; } diff --git a/hosts/myself/default.nix b/hosts/myself/default.nix index 113ec8b..bf31c63 100644 --- a/hosts/myself/default.nix +++ b/hosts/myself/default.nix @@ -33,6 +33,15 @@ ipv4.addresses = [ { address = "10.42.1.6"; prefixLength = 16; + } { + address = "10.42.100.1"; + prefixLength = 16; + } ]; + }; + interfaces.enp39s0 = { + ipv4.addresses = [ { + address = "10.201.1.1"; + prefixLength = 24; } ]; }; nameservers = [ diff --git a/hosts/myself/git.nix b/hosts/myself/git.nix index 2e8c634..a9c7d63 100644 --- a/hosts/myself/git.nix +++ b/hosts/myself/git.nix @@ -65,6 +65,7 @@ in { config = ((import ./container-runner.nix) { inherit inputs overlays; name = "shell"; + extra.virtualisation.podman.enable = true; }); }; @@ -96,13 +97,13 @@ in { "koalaman/shellcheck:*" "registry.gitlab.com/gitlab-org/*" - "registry.thehellings.com/*" - "gitlab.shire-zebra.ts.net:5000/*:*" + "registry.thehellings.com/*/*/*:*" + "gitlab.shire-zebra.ts.net:5000/*/*/*:*" ]; dockerAllowedServices = [ "docker:*" - "registry.thehellings.com/*" - "gitlab.shire-zebra.ts.net:5000/*:*" + "registry.thehellings.com/*/*/*:*" + "gitlab.shire-zebra.ts.net:5000/*/*/*:*" ]; dockerPrivileged = true; dockerVolumes = [ diff --git a/modules/baseline.nix b/modules/baseline.nix index af48974..c1455c8 100644 --- a/modules/baseline.nix +++ b/modules/baseline.nix @@ -1,4 +1,7 @@ -{ pkgs, ... }: +{ pkgs, lib, ... }: +let + notDarwin = (! pkgs.stdenv.isDarwin); +in { # Enable flakes nix = { @@ -15,8 +18,7 @@ keep-derivations = true; min-free = (toString (1024 * 1024 * 1024) ); max-free = (toString (5 * 1024 * 1024 * 1024) ); - substituters = [ - "http://nixcache.home" + substituters = (if notDarwin then [ "http://nixcache.home" ] else []) ++ [ "https://cache.garnix.io" "https://ai.cachix.org" ]; @@ -32,8 +34,7 @@ }; # Base packages that need to be in all my hosts - environment.systemPackages = with pkgs; ( - [ + environment.systemPackages = with pkgs; [ agenix android-file-transfer bitwarden-cli @@ -56,6 +57,5 @@ transcrypt unzip wget - ] - ); + ]; } diff --git a/modules/nixos/ceph.nix b/modules/nixos/ceph.nix index 95a14e0..87e2c58 100644 --- a/modules/nixos/ceph.nix +++ b/modules/nixos/ceph.nix @@ -1,2 +1,849 @@ # This is a good source for a Ceph dealio -# https://gist.github.com/nh2/13425a1f18b4c1ce82edb63c10b163c9 +# https://gist.github.com0/nh2/13425a1f18b4c1ce82edb63c10b163c9 +{ config, lib, pkgs, ... }: + +with lib; + +let + cfg = config.services.ceph-benaco; + commaSep = builtins.concatStringsSep ","; + + ensureUnitExists = c': name: let + unitName = (builtins.elemAt (builtins.split "\\." name) 0); + in if c'.systemd.services ? unitName + then name + else name;# "Unable to locate ${name} at ${commaSep (builtins.attrNames c')}"; +in + +{ + + ###### interface + + options = { + + services.ceph-benaco = { + + enable = mkEnableOption "Ceph distributed filesystem"; + + package = mkOption { + type = types.package; + default = pkgs.ceph; + defaultText = literalExpression "pkgs.ceph-benaco"; + description = "Ceph package to use."; + }; + + fsid = mkOption { + type = types.str; + description = "Unique cluster identifier."; + }; + + clusterName = mkOption { + type = types.str; + description = "Cluster name."; + default = "ceph"; + }; + + initialMonitors = mkOption { + type = types.listOf (types.submodule { + options = { + hostname = mkOption { + type = types.str; + description = "Initial monitor hostname."; + }; + + ipAddress = mkOption { + type = types.str; + description = "Initial monitor IP address."; + }; + }; + }); + description = "Initial monitors."; + }; + + mdsNodes = mkOption { + type = types.listOf (types.submodule { + options = { + hostname = mkOption { + type = types.str; + description = "MDS hostname."; + }; + + ipAddress = mkOption { + type = types.str; + description = "MDS IP address."; + }; + }; + }); + description = "MDS nodes."; + }; + + publicNetworks = mkOption { + type = types.listOf types.str; + description = "Public network(s) of the cluster."; + }; + + clusterNetworks = mkOption { + type = types.listOf types.str; + description = "Cluster backend networks for OSD sync"; + }; + + adminKeyring = mkOption { + type = types.path; + description = "Ceph admin keyring to install on the machine."; + }; + + monitor = { + enable = mkEnableOption "Activate a Ceph monitor on this machine."; + + initialKeyring = mkOption { + type = types.path; + description = "Keyring file to use when initializing a new monitor"; + example = "/path/to/ceph.mon.keyring"; + }; + + nodeName = mkOption { + type = types.str; + description = "Ceph monitor node name."; + example = "node1"; + }; + + bindAddr = mkOption { + type = types.str; + description = "IP address that the OSDs shall bind to."; + example = "10.0.0.1"; + }; + + advertisedPublicAddr = mkOption { + type = types.str; + description = "IP address that the monitor shall advertise."; + example = "10.0.0.1"; + }; + }; + + manager = { + enable = mkEnableOption "Activate a Ceph manager on this machine."; + + nodeName = mkOption { + type = types.str; + description = "Ceph manager node name."; + example = "node1"; + }; + }; + + osdBindAddr = mkOption { + type = types.str; + description = "IP address that the OSDs shall bind to."; + example = "10.0.0.1"; + }; + + osdAdvertisedPublicAddr = mkOption { + type = types.str; + description = "IP address that the OSDs shall advertise."; + example = "10.0.0.1"; + }; + + osds = mkOption { + default = {}; + example = { + osd1 = { + enable = true; + bootstrapKeyring = "/path/to/ceph.client.bootstrap-osd.keyring"; + id = 1; + uuid = "11111111-1111-1111-1111-111111111111"; + blockDevice = "/dev/sdb"; + blockDeviceUdevRuleMatcher = ''KERNEL=="sdb"''; + clusterAddress = "10.1.0.1"; + }; + osd2 = { + enable = true; + bootstrapKeyring = "/path/to/ceph.client.bootstrap-osd.keyring"; + id = 2; + uuid = "22222222-2222-2222-2222-222222222222"; + blockDevice = "/dev/sdc"; + blockDeviceUdevRuleMatcher = ''KERNEL=="sdc"''; + clusterAddress = "10.1.0.2"; + }; + }; + description = '' + This option allows you to define multiple Ceph OSDs. + A common idiom is to use one OSD per physical hard drive. + + Note that the OSD names given as attributes of this key + are NOT what ceph calls OSD IDs (instead, those are defined + by the 'services.ceph-benaco.osds.*.id' fields). + Instead, the name is an identifier local and unique to the + current machine only, used only to name the systemd service + for that OSD. + ''; + type = types.attrsOf (types.submodule { + options = { + + enable = mkEnableOption "Activate a Ceph OSD on this machine."; + + bootstrapKeyring = mkOption { + type = types.path; + description = "Ceph OSD bootstrap keyring."; + example = "/path/to/ceph.client.bootstrap-osd.keyring"; + }; + + id = mkOption { + type = types.int; + description = "The ID of this OSD. Must be unique in the Ceph cluster."; + example = 1; + }; + + uuid = mkOption { + type = types.str; + description = "The UUID of this OSD. Must be unique in the Ceph cluster."; + example = "abcdef12-abcd-1234-abcd-1234567890ab"; + }; + + systemdExtraRequiresAfter = mkOption { + type = types.listOf types.str; + default = []; + description = '' + Add the specified systemd units to the "requires" and "after" + lists of the systemd service of this OSD. + + Useful, for example, to decrypt the underlying block devices with LUKS first. + + NixOS modules allow override those lists from outside, but for that + the names of the systemd services for the OSDs need to be known; + this option is a convenience to not have to know them from outside. + ''; + example = "decrypt-my-disk.service"; + }; + + skipZap = mkOption { + type = types.bool; + default = false; + description = '' + Whether to skip the zapping of the the OSD device on initial OSD + installation. + + Skipping is needed because ceph-volume cannot + zap device-mapper devices: + + + In that case you need to wipe the device manually. + + In the common case of placing the OSD on a cryptsetup LUKS device + (which is a device-mapper device), re-creating the encryption + from scratch with a new key zaps anything anyway, in which case + zapping can be skipped here. + ''; + }; + + blockDevice = mkOption { + type = types.str; + description = "The block device used to store the OSD."; + example = "/dev/sdb"; + }; + + blockDeviceUdevRuleMatcher = mkOption { + type = types.str; + description = '' + An udev rule matcher matching the block device used to store the OSD. + Will be spliced into the udev rule that is + used to set access permissions to the ceph user via an udev rule. + + This is a matcher instead of just a device name to allow flexibility: + Normal disks can be easily matched with KERNEL=="sda1", but + device-mapper may not; for example, decrypted cryptsetup LUKS devices + have a less useful KERNEL=="dm-4" and may better be matched + using ENV{DM_NAME}=="mydisk-decrypted". + ''; + example = ''KERNEL=="sdb"''; + }; + + dbBlockDevice = mkOption { + type = types.nullOr types.str; + default = null; + description = '' + The block device used to store the OSD's BlueStore DB device. + + Put this on a faster device than to improve performance. + + See + for details. + ''; + example = "/dev/sdc"; + }; + + dbBlockDeviceUdevRuleMatcher = mkOption { + type = types.nullOr types.str; + default = null; + description = '' + Like but for the + . + ''; + example = ''KERNEL=="sdc"''; + }; + + clusterAddress = mkOption { + type = types.nullOr types.str; + default = null; + description = '' + The IP address on the dedicated cluster network that + is used by the backend communication for OSD communication. + ''; + example = "10.1.0.1f"; + }; + + }; + }); + }; + + mds = { + enable = mkEnableOption "Activate a Ceph MDS on this machine."; + + nodeName = mkOption { + type = types.str; + description = "Ceph MDS node name."; + example = "node1"; + }; + + listenAddr = mkOption { + type = types.str; + description = "IP address that the MDS shall advertise."; + example = "10.0.0.1"; + }; + }; + + extraConfig = mkOption { + type = types.str; + default = ""; + description = '' + Additional ceph.conf settings. + + See the sample file for inspiration: + + ''; + }; + }; + }; + + ###### implementation + + config = let + monDir = "/var/lib/ceph/mon/${cfg.clusterName}-${cfg.monitor.nodeName}"; + mgrDir = "/var/lib/ceph/mgr/${cfg.clusterName}-${cfg.manager.nodeName}"; + mdsDir = "/var/lib/ceph/mds/${cfg.clusterName}-${cfg.mds.nodeName}"; + + # File permissions for things that are on locations wiped at start + # (e.g. /run or its /var/run symlink). + ensureTransientCephDirs = '' + install -m 770 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/run/ceph + ''; + + # File permissions from cluster deployed with ceph-deploy. + ensureCephDirs = '' + install -m 3770 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/log/ceph + install -m 770 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/run/ceph + install -m 750 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph + install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/mon + install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/mgr + install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/osd + ''; + + # Utilities called by Ceph device health scraping, see: + # https://docs.ceph.com/en/latest/rados/operations/devices/#enabling-monitoring + # As per https://github.com/ceph/ceph-container/pull/1490/commits/c49e821599965ae92a88b2c78077ee03c4405895, + # both the OSDs and the `mon` need this. + # Ceph calls these utilities with `sudo`. That requires sudoers entries. + # Sudoers entries require absolute path; that exact (nix store) path needs to + # be used by Ceph, so it needs to be given to the systemd unit via `path`. + # This is why we pair each `sudoersExtraRule` with the `package` to put onto + # that `path`. + # + # Entries are based on: + # https://github.com/ceph/ceph/blob/a2f5a3c1dbfa4dce41e25da4f029a8fdb8c8d864/sudoers.d/ceph-smartctl + cephMonitoringSudoersCommandsAndPackages = [ + { + package = pkgs.smartmontools; + sudoersExtraRule = { # entry for `security.sudo.extraRules` + users = [ config.users.users.ceph.name ]; + commands = [{ + command = "${lib.getBin pkgs.smartmontools}/bin/smartctl -x --json=o /dev/*"; + options = [ "NOPASSWD" ]; + }]; + }; + } + { + package = pkgs.nvme-cli; + sudoersExtraRule = { # entry for `security.sudo.extraRules` + users = [ config.users.users.ceph.name ]; + commands = [{ + command = "${lib.getBin pkgs.nvme-cli}/bin/nvme * smart-log-add --json /dev/*"; + options = [ "NOPASSWD" ]; + }]; + }; + } + ]; + + cephDeviceHealthMonitoringPathsOrPackages = with pkgs; [ + # Contains `sudo`. Ceph wraps this around the other health check programs. + # Cannot use `pkgs.sudo` because that one is not SUID, see: + # https://discourse.nixos.org/t/sudo-uid-issues/9133 + "/run/wrappers" # `systemd.services..path` adds the `bin/` subdir of this + ] ++ map ({ package, ... }: package) cephMonitoringSudoersCommandsAndPackages; + + makeCephOsdSetupSystemdService = localOsdServiceName: osdConfig: + let + osdExistenceFile = "/var/lib/ceph/osd/.${toString osdConfig.id}.${osdConfig.uuid}.nix-existence"; + in + mkIf osdConfig.enable { + description = "Initialize Ceph OSD"; + + requires = osdConfig.systemdExtraRequiresAfter; + after = osdConfig.systemdExtraRequiresAfter; + + path = with pkgs; [ + # The following are currently missing in Ceph's wrapping, see https://github.com/NixOS/nixpkgs/issues/147801#issue-1065600852 + util-linux # for `lsblk` + lvm2 # for `lvs` + ]; + + # TODO Use `udevadm trigger --settle` instead of the separate `udevadm settle` + # once that feature is available to us with systemd >= 238; + # see https://github.com/systemd/systemd/commit/792cc203a67edb201073351f5c766fce3d5eab45 + preStart = '' + set -x + ${ensureCephDirs} + install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/bootstrap-osd + # `install` is not atomic, see + # https://lists.gnu.org/archive/html/bug-coreutils/2010-02/msg00243.html + # so use `mktemp` + `mv` to make it atomic. + TMPFILE=$(mktemp --tmpdir=/var/lib/ceph/bootstrap-osd/) + install -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} ${osdConfig.bootstrapKeyring} "$TMPFILE" + mv "$TMPFILE" /var/lib/ceph/bootstrap-osd/ceph.keyring + + # Trigger udev rules for permissions of block devices and wait for them to settle. + udevadm trigger --name-match=${osdConfig.blockDevice} + '' + lib.optionalString (osdConfig.dbBlockDevice != null) '' + udevadm trigger --name-match=${osdConfig.dbBlockDevice} + '' + + '' + udevadm settle + '' + (optionalString (!osdConfig.skipZap) ( + '' + # Zap OSD block devices, otherwise `ceph-osd` below will try to fsck if there's some old + # ceph data on the block device (see https://tracker.ceph.com/issues/24099). + ${cfg.package}/bin/ceph-volume lvm zap ${osdConfig.blockDevice} + '' + lib.optionalString (osdConfig.dbBlockDevice != null) '' + ${cfg.package}/bin/ceph-volume lvm zap ${osdConfig.dbBlockDevice} + '' + )); + + script = '' + set -euo pipefail + set -x + until [ -f /etc/ceph/${cfg.clusterName}.client.admin.keyring ] + do + sleep 1 + done + + OSD_SECRET=$(${cfg.package}/bin/ceph-authtool --gen-print-key) + echo "{\"cephx_secret\": \"$OSD_SECRET\"}" | \ + ${cfg.package}/bin/ceph osd new ${osdConfig.uuid} ${toString osdConfig.id} -i - \ + -n client.bootstrap-osd -k ${osdConfig.bootstrapKeyring} + mkdir -p /var/lib/ceph/osd/${cfg.clusterName}-${toString osdConfig.id} + + ln -s ${osdConfig.blockDevice} /var/lib/ceph/osd/${cfg.clusterName}-${toString osdConfig.id}/block + '' + lib.optionalString (osdConfig.dbBlockDevice != null) '' + ln -s ${osdConfig.dbBlockDevice} /var/lib/ceph/osd/${cfg.clusterName}-${toString osdConfig.id}/block.db + '' + + '' + + ${cfg.package}/bin/ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${toString osdConfig.id}/keyring \ + --name osd.${toString osdConfig.id} --add-key $OSD_SECRET + + ${cfg.package}/bin/ceph-osd -i ${toString osdConfig.id} --mkfs --osd-uuid ${osdConfig.uuid} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} --osd-objectstore bluestore + touch ${osdExistenceFile} + ''; + + serviceConfig = { + Type = "oneshot"; + RemainAfterExit = true; + PermissionsStartOnly = true; # only run the script as ceph, preStart as root + User = config.users.users.ceph.name; + Group = config.users.groups.ceph.name; + }; + unitConfig = { + ConditionPathExists = "!${osdExistenceFile}"; + }; + }; + + makeCephOsdSystemdService = localOsdServiceName: osdConfig: mkIf osdConfig.enable { + description = "Ceph OSD"; + + # Note we do not have to add `osdConfig.systemdExtraRequiresAfter` here because + # that's already a dependency of our dependency `ceph-osd-setup-*`. + requires = [ + (ensureUnitExists config "ceph-osd-setup-${localOsdServiceName}.service") + ]; + requiredBy = [ "multi-user.target" ]; + after = [ + "network.target" + "local-fs.target" + "time-sync.target" + (ensureUnitExists config "ceph-osd-setup-${localOsdServiceName}.service") + ]; + wants = [ + "network.target" + "local-fs.target" + "time-sync.target" + ]; + + path = [ + # TODO: use wrapProgram in the ceph package for this in the future + pkgs.getopt + ] + ++ cephDeviceHealthMonitoringPathsOrPackages + ; + + restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ]; + + preStart = '' + ${ensureTransientCephDirs} + ${lib.getLib cfg.package}/libexec/ceph/ceph-osd-prestart.sh --cluster ${cfg.clusterName} --id ${toString osdConfig.id} + ''; + + serviceConfig = let + clusterIpArg = lib.optionalString (osdConfig.clusterAddress != null) "--cluster_addr=${osdConfig.clusterAddress}"; + in { + LimitNOFILE="1048576"; + LimitNPROC="1048576"; + + ExecStart='' + ${cfg.package}/bin/ceph-osd -f --cluster ${cfg.clusterName} --id ${toString osdConfig.id} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} "--public_bind_addr=${cfg.osdBindAddr}" "--public_addr=${cfg.osdAdvertisedPublicAddr}" "${clusterIpArg}" + ''; + ExecReload='' + ${pkgs.coreutils}/bin/kill -HUP $MAINPID + ''; + Restart="on-failure"; + ProtectHome="true"; + ProtectSystem="full"; + PrivateTmp="true"; + TasksMax="infinity"; + # StartLimitBurst="3"; + }; + # startLimitIntervalSec = 30 * 60; + }; + + in mkIf cfg.enable { + environment.systemPackages = [ cfg.package ]; + + networking.firewall = { + allowedTCPPorts = [ + # Ceph outside of VPN because it is very data heavy and causes packet loss. + # We enable msgr-v2 only because that allows its own on-wire encryption. + 3300 # ceph msgr-v2 + ]; + allowedTCPPortRanges = [ + { from = 6800; to = 7300; } # https://docs.ceph.com/en/pacific/rados/configuration/network-config-ref/ + ]; + }; + + # Reminder of how `ceph.conf` works: + # + # * Ceph upstream docs now recommend to use underscores instead of spaces. + # * Options in more specific sections like `[mon]` override those in less + # specific sections like `[global]`. But all options can be written into all sections, + # and an option has the same name, no matter in which section it is written. + # Thus, put options in `[global]`, and only use a diffent section + # if you want to override an option you've set in `global`. + # + # Sample: https://github.com/ceph/ceph/blob/master/src/sample.ceph.conf + environment.etc."ceph/${cfg.clusterName}.conf".text = + '' + [global] + fsid = ${cfg.fsid} + mon_initial_members = ${commaSep (map (mon: mon.hostname) cfg.initialMonitors)} + mon_host = ${commaSep (map (mon: mon.ipAddress) cfg.initialMonitors)} + + # Ceph clusters go into WARN health mode, until + # the following setting is made strict by setting it to `false`: + # See: https://docs.ceph.com/en/latest/security/CVE-2021-20288/#recommendations + # As of writing, this setting is not documented outside of the CVE note :( + # + # While for new clusters the warning no longer seems to appear, it still + # appears in our existing clusters unless this option is set, see: + # https://tracker.ceph.com/issues/53751#note-7 + auth_allow_insecure_global_id_reclaim = false + + # Disable dirfrag prefetch on MDS restart to prevent out-of-memory after + # many files were opened. + # Note this option has no effect on Ceph < 15, because it doesn't exist there. + # TODO: Remove this once we're on a Ceph version that includes this default, + # see https://github.com/ceph/ceph/pull/44667. + # This is assuming that the commit fixes existing clusters, see + # https://github.com/ceph/ceph/pull/44667#issuecomment-1036103397 + # If it doesn't this can only be removed once we have no existing + # cluster with the old default. + mds_oft_prefetch_dirfrags = false + + # Disable sleep between HDD recovery operations, otherwise recovery + # will take forever when small objects (e.g. CephFS files) are on HDD. + # See https://tracker.ceph.com/issues/23595#note-12 + osd_recovery_sleep_hdd = 0.0 + + # Increase scrub intervals by 4x. + # Since we store many small files on HDD, and scrubbing apparently + # iterates over all objects + # we have no chance to scrub at the default intervals. + # + # (This was written when we had 400M files across 30 HDDs.) + # Change this back once we have reduced our number of files per disk. + osd_scrub_min_interval = 345600 + osd_scrub_max_interval = 2419200 + osd_deep_scrub_interval = 2419200 + + public_network = ${commaSep cfg.publicNetworks} + cluster_network = ${commaSep cfg.clusterNetworks} + auth_cluster_required = cephx + auth_service_required = cephx + auth_client_required = cephx + + # Enforce on-wire transport encryption. + ms_cluster_mode = secure + ms_service_mode = secure + ms_client_mode = secure + + ${cfg.extraConfig} + ''; + + environment.etc."ceph/${cfg.clusterName}.client.admin.keyring" = { + source = cfg.adminKeyring; + mode = "0600"; + # Make ceph own this keyring so that it can use it to get keys for its daemons. + user = "ceph"; + group = "ceph"; + }; + + users.users.ceph = { + isNormalUser = false; + isSystemUser = true; + # TODO: Legacy UID / GID chosen from before we configured the UID declaratively. + # In the future, we whould change this whole module to use + # `config.ids.uids.ceph`, like the upstream nixpkgs Ceph module does. + # Switching away from `nogroup` would also be good as described there. + # For both cases, we'll have to `chown` all relevant existing files on + # deployments, such as `/var/lib/ceph`, and log files. + uid = 1001; + group = config.users.groups.nogroup.name; + }; + users.groups.ceph = { + # TODO: Same TODO as above for the `uid`. + gid = 499; + }; + + # Allow ceph daemons (which run as user ceph) to collect device health metrics. + security.sudo.extraRules = + map ({ sudoersExtraRule, ... }: sudoersExtraRule) cephMonitoringSudoersCommandsAndPackages; + + # The udevadm trigger/settle in `makeCephOsdSetupSystemdService` waits for these rules rule to be applied. + services.udev.extraRules = + lib.concatStringsSep "\n" ( + lib.mapAttrsToList (_localOsdServiceName: osdConfig: + '' + SUBSYSTEM=="block", ${osdConfig.blockDeviceUdevRuleMatcher}, OWNER="${config.users.users.ceph.name}", GROUP="${config.users.groups.ceph.name}", MODE="0660" + '' + + lib.optionalString (osdConfig.dbBlockDeviceUdevRuleMatcher != null) ( + '' + SUBSYSTEM=="block", ${osdConfig.dbBlockDeviceUdevRuleMatcher}, OWNER="${config.users.users.ceph.name}", GROUP="${config.users.groups.ceph.name}", MODE="0660" + '' + ) + ) cfg.osds + ); + + systemd.services = { + + ceph-mon-setup = mkIf cfg.monitor.enable { + description = "Initialize ceph monitor"; + + preStart = ensureCephDirs; + + script = let + # `--addv` seems currently required to get msgr-v2 working, see: + # https://tracker.ceph.com/issues/53751#note-11 + monmapNodes = builtins.concatStringsSep " " (lib.concatMap (mon: [ "--addv" mon.hostname "[v2:${mon.ipAddress}:3300,v1:${mon.ipAddress}:6789]" ]) cfg.initialMonitors); + # Monitors cannot simply be changed in config, one has to update the monmap, see note [replacing-ceph-monmap-ips-for-existing-cluster] + in '' + set -euo pipefail + rm -rf "${monDir}" # Start from scratch. + echo "Initializing monitor." + MONMAP_DIR=`mktemp -d` + ${cfg.package}/bin/monmaptool --create ${monmapNodes} --fsid ${cfg.fsid} "$MONMAP_DIR/monmap" + ${cfg.package}/bin/ceph-mon --cluster ${cfg.clusterName} --mkfs -i ${cfg.monitor.nodeName} --monmap "$MONMAP_DIR/monmap" --keyring ${cfg.monitor.initialKeyring} + rm -r "$MONMAP_DIR" + touch ${monDir}/done + ''; + + serviceConfig = { + Type = "oneshot"; + RemainAfterExit = true; + PermissionsStartOnly = true; # only run the script as ceph + User = config.users.users.ceph.name; + Group = config.users.groups.ceph.name; + }; + unitConfig = { + ConditionPathExists = "!${monDir}/done"; + }; + }; + + ceph-mon = mkIf cfg.monitor.enable { + description = "Ceph monitor"; + + requires = [ (ensureUnitExists config "ceph-mon-setup.service") ]; + requiredBy = [ "multi-user.target" ]; + after = [ "network.target" "local-fs.target" "time-sync.target" (ensureUnitExists config "ceph-mon-setup.service") ]; + wants = [ "network.target" "local-fs.target" "time-sync.target" ]; + + restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ]; + + path = cephDeviceHealthMonitoringPathsOrPackages; + + preStart = ensureTransientCephDirs; + + serviceConfig = { + LimitNOFILE="1048576"; + LimitNPROC="1048576"; + ExecStart='' + ${cfg.package}/bin/ceph-mon -f --cluster ${cfg.clusterName} --id ${cfg.monitor.nodeName} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} "--public_bind_addr=${cfg.monitor.bindAddr}" "--public_addr=${cfg.monitor.advertisedPublicAddr}" + ''; + ExecReload='' + ${pkgs.coreutils}/bin/kill -HUP $MAINPID + ''; + PrivateDevices="yes"; + ProtectHome="true"; + ProtectSystem="full"; + PrivateTmp="true"; + TasksMax="infinity"; + Restart="on-failure"; + # StartLimitBurst="5"; + RestartSec="10"; + }; + # startLimitIntervalSec = 30 * 60; + }; + + ceph-mgr-setup = mkIf cfg.manager.enable { + description = "Initialize Ceph manager"; + + preStart = ensureCephDirs; + + script = '' + set -euo pipefail + mkdir -p ${mgrDir} + until [ -f /etc/ceph/${cfg.clusterName}.client.admin.keyring ] + do + sleep 1 + done + ${cfg.package}/bin/ceph auth get-or-create mgr.${cfg.manager.nodeName} mon 'allow profile mgr' mds 'allow *' osd 'allow *' -o ${mgrDir}/keyring + touch "${mgrDir}/.nix_done" + ''; + + serviceConfig = { + Type = "oneshot"; + RemainAfterExit = true; + PermissionsStartOnly = true; # only run the script as ceph + User = config.users.users.ceph.name; + Group = config.users.groups.ceph.name; + }; + unitConfig = { + ConditionPathExists = "!${mgrDir}/.nix_done"; + }; + }; + + ceph-mgr = mkIf cfg.manager.enable { + description = "Ceph manager"; + + requires = [ (ensureUnitExists config "ceph-mgr-setup.service") ]; + requiredBy = [ "multi-user.target" ]; + after = [ "network.target" "local-fs.target" "time-sync.target" (ensureUnitExists config "ceph-mgr-setup.service") ]; + wants = [ "network.target" "local-fs.target" "time-sync.target" ]; + + restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ]; + + preStart = ensureTransientCephDirs; + + serviceConfig = { + LimitNOFILE="1048576"; + LimitNPROC="1048576"; + + ExecStart='' + ${cfg.package}/bin/ceph-mgr -f --cluster ${cfg.clusterName} --id ${cfg.manager.nodeName} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} + ''; + ExecReload='' + ${pkgs.coreutils}/bin/kill -HUP $MAINPID + ''; + Restart="on-failure"; + RestartSec=10; + # StartLimitBurst="3"; + }; + # startLimitIntervalSec = 30 * 60; + }; + + ceph-mds-setup = mkIf cfg.mds.enable { + description = "Initialize Ceph MDS"; + + preStart = ensureCephDirs; + + script = '' + set -euo pipefail + mkdir -p ${mdsDir} + until [ -f /etc/ceph/${cfg.clusterName}.client.admin.keyring ] + do + sleep 1 + done + ${cfg.package}/bin/ceph auth get-or-create mds.${cfg.mds.nodeName} osd 'allow rwx' mds 'allow' mon 'allow profile mds' -o ${mdsDir}/keyring + touch "${mdsDir}/.nix_done" + ''; + + serviceConfig = { + Type = "oneshot"; + RemainAfterExit = true; + PermissionsStartOnly = true; # only run the script as ceph + User = config.users.users.ceph.name; + Group = config.users.groups.ceph.name; + }; + unitConfig = { + ConditionPathExists = "!${mdsDir}/.nix_done"; + }; + }; + + ceph-mds = mkIf cfg.mds.enable { + description = "Ceph MDS"; + + requires = [ (ensureUnitExists config "ceph-mds-setup.service") ]; + requiredBy = [ "multi-user.target" ]; + after = [ "network.target" "local-fs.target" "time-sync.target" (ensureUnitExists config "ceph-mds-setup.service") ]; + wants = [ "network.target" "local-fs.target" "time-sync.target" ]; + + restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ]; + + preStart = ensureTransientCephDirs; + + serviceConfig = { + LimitNOFILE="1048576"; + LimitNPROC="1048576"; + + ExecStart='' + ${cfg.package}/bin/ceph-mds -f --cluster ${cfg.clusterName} --id ${cfg.mds.nodeName} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} "--public_addr=${cfg.mds.listenAddr}" + ''; + ExecReload='' + ${pkgs.coreutils}/bin/kill -HUP $MAINPID + ''; + Restart="on-failure"; + # StartLimitBurst="3"; + }; + # startLimitIntervalSec = 30 * 60; + }; + + } + # Make one OSD service for each configured OSD. + // lib.mapAttrs' (localOsdServiceName: osdConfig: nameValuePair "ceph-osd-setup-${localOsdServiceName}" (makeCephOsdSetupSystemdService localOsdServiceName osdConfig)) cfg.osds + // lib.mapAttrs' (localOsdServiceName: osdConfig: nameValuePair "ceph-osd-${localOsdServiceName}" (makeCephOsdSystemdService localOsdServiceName osdConfig)) cfg.osds; + }; +} + diff --git a/modules/nixos/default.nix b/modules/nixos/default.nix index a2584f6..1e42e83 100644 --- a/modules/nixos/default.nix +++ b/modules/nixos/default.nix @@ -4,6 +4,7 @@ imports = [ ../baseline.nix ./backup.nix + ./ceph.nix ./container.nix ./db.nix ./gnome.nix diff --git a/modules/nixos/gnome.nix b/modules/nixos/gnome.nix index e820feb..e127bc0 100644 --- a/modules/nixos/gnome.nix +++ b/modules/nixos/gnome.nix @@ -13,13 +13,14 @@ in with lib; { services = { accounts-daemon.enable = true; + # Trackpad support + libinput.enable = true; + xserver = { enable = true; displayManager.gdm.enable = true; desktopManager.gnome.enable = true; xkb.layout = "us"; - # Trackpad support - libinput.enable = true; }; udev.packages = with pkgs; [ diff --git a/modules/nixos/kde.nix b/modules/nixos/kde.nix index 050f09e..685edb8 100644 --- a/modules/nixos/kde.nix +++ b/modules/nixos/kde.nix @@ -13,16 +13,10 @@ in with lib; { services = { xserver = { enable = true; - displayManager = { - defaultSession = "plasma"; - sddm.enable = true; - }; xkb.layout = "us"; # Trackpad support libinput.enable = true; - } // (optionalAttrs (builtins.hasAttr "plasma6" options.services.xserver.desktopManager) { - desktopManager.plasma6.enable = true; - }); + }; pipewire = { enable = true; @@ -30,7 +24,13 @@ in with lib; { alsa.support32Bit = true; pulse.enable = true; }; - }; + } // (optionalAttrs (builtins.hasAttr "plasma6" options.services.xserver.desktopManager) { + desktopManager.plasma6.enable = true; + displayManager = { + defaultSession = "plasma"; + sddm.enable = true; + }; + }); programs.dconf.enable = true; programs.sway.enable = true; # Gives us Wayland diff --git a/overlays/default.nix b/overlays/default.nix index 648d8cf..74258a4 100644 --- a/overlays/default.nix +++ b/overlays/default.nix @@ -40,10 +40,6 @@ in rec { xonsh-apipenv = cp ./xonsh-apipenv.nix {}; xonsh-direnv = cp ./xonsh-direnv.nix {}; xontrib-vox = cp ./xonsh-vox.nix {}; - - home-assistant-chip-core = python-prev.home-assistant-chip-core.override { - openssl_1_1 = final.openssl; - }; }) ]; @@ -87,14 +83,11 @@ in rec { }; pipenv-ivr = prev.callPackage ./pipenv.nix { }; - xonsh = prev.xonsh.overridePythonAttrs (old: rec{ - python3 = final.gregpy; - propagatedBuildInputs = with final.gregpy.pkgs; old.propagatedBuildInputs ++ [ - responses - ruamel-yaml + xonsh = (prev.xonsh.override { + extraPackages = (ps: with ps; [ xonsh-apipenv xonsh-direnv xontrib-vox - ]; + ]); }); } diff --git a/overlays/upgrade-pg-cluster.nix b/overlays/upgrade-pg-cluster.nix index a22e36e..80b7c87 100644 --- a/overlays/upgrade-pg-cluster.nix +++ b/overlays/upgrade-pg-cluster.nix @@ -1,8 +1,8 @@ { postgresql_15, postgresql_14, writeScriptBin, ... }: let - newPostgres = postgresql_15; - oldPostgres = postgresql_14; + newPostgres = postgresql_16; + oldPostgres = postgresql_15; in writeScriptBin "upgrade-pg-cluster" '' set -eux systemctl stop postgresql diff --git a/secrets/gitlab/linode-deployer-runner-reg.age b/secrets/gitlab/linode-deployer-runner-reg.age new file mode 100644 index 0000000..7734518 --- /dev/null +++ b/secrets/gitlab/linode-deployer-runner-reg.age @@ -0,0 +1,27 @@ +age-encryption.org/v1 +-> ssh-ed25519 oyEmTw lC+4KBNMMM5fHkFBRa/tJT+jFZeN+mw5/8yrdojjVB0 +YwL7HD2UJ14F/hqbCAQU6KYqUzshv+0c8GHs+ZvAp4Q +-> ssh-ed25519 mOmPfg nUi8aarXOdi1x5PvO15/U1hM6I4quLD7eVQGZrN8OW8 +aPTW1RJ9USImY2zMSL6g9PVwZ9T+7JgOLExnpYKZt9Y +-> ssh-ed25519 YJiRbw kEJIPA5pyp8mp1tS+EX7YGwxssQ3RYpR7KOpubCa3n0 +p7uz1Zhm3WiR2rYWTnR4WaAwwPL71ILSmul0VadddJQ +-> ssh-ed25519 aY2AXA GZnDdhRihahe0WCfhx7urPRXn+XWMwUGiU+mC4qaXBM +QGqQVWLLSb0TII1gF4rHjqqOGMogmEEy9/PoE5wB0CM +-> ssh-ed25519 xNtnoA tfCFZUkCqvOJ0etchpciY2FfvoX0Y1wW7IU8I2u6pBw +gqi1YjkYY5Q1wd3UL7bYVFUCSK51V3ggeFcmIhdnug4 +-> ssh-ed25519 Nl/5yA fvgVFAiODubImv5HKKvk9BTrw4abIq1Xi1WC+CxupV4 +Flg0H5pNbfKmyDH1NRBwyzDjQK2v8Z+RJrR2Br3aSa0 +-> ssh-ed25519 GdLgCQ CRzrCRlcBKiLa7ghPfbfrwz08RYH55zRIdPKyXc2jkE +43Sd7ERicIqrgn0Di7yQ43qJsYbtgeE99DvOj0AzA6A +-> ssh-ed25519 tOH/HQ pzx7DaPLmk070Zz5yi9BIYGajCKba6/j5CjsQcuHLkg +4XSP61C4oovtYIvTioZaiB0MoP5/kkk/4a7TWxs0wEQ +-> ssh-ed25519 FpzvfQ xJpLuQ3NhiVT7PNm5/NngiwV8cm1wYlBjlPsKOcV2nM +nV9Jx/eIz6MIa217sntxrp2HmkbJsN0hseUgp7iqzSg +-> ssh-ed25519 kdPvzQ v3TYNmF/9DHD1eKdFblwpfyBh78+jBaiP0H62JJnQF4 +vYQkEzhLmFMiG3TdoSfB/Xa7g6wYzYB2K2jyO/X67Yo +-> ssh-ed25519 onmXpg iNwyY2pwpwupeu3ZN1ALWl2Z6EJZpqHDFK+IQp8EGHo +ez+cR4a8i2nJkiko23wflNomrpaoMYDR3fWHrMZHe5M +-> ssh-ed25519 CnhD0g fU6TSuG9ZEEUxQE9CJLg9wu71IryXpJpb5NXCqdOBiw +GXPNWmn/SHBOHwBVOGLCfEYkUSF+JkalLKbbBxF4aTE +--- Zk7n2mzoAnSuC6CdpPH+LGeGVcRPJL4zMt6d+Q2Eipw +Χ%d29># p vLj}[`R ynoϊ0Nsyh&7Nװ ssh-ed25519 oyEmTw hf1hKhiFfX6yMQ1qcMrDwwIaNd2HfW+n9GnbqbE/Rh4 +wq11rHPGL3fbljB29TGjXrNyJHgLOCCZsSz4zYWM4vg +-> ssh-ed25519 mOmPfg 9jL8idaEmiGayJIxk/1EFHFJbIx7M0M+fMI/TWeoWhw +Ql66dcWE1WRCLuoTFXGiLqzohHYBIjSdigWMribJJyA +-> ssh-ed25519 YJiRbw /1BFGrfrte3CivJUS/GvSHMwkN8GzkPKhaYnFwtnFDs +qlLfYrSe/Z0BlxLIp5n9KAmHcE4IZYAAmIWRlStwq0Y +-> ssh-ed25519 aY2AXA SRklz9w4e5Jwl7XufavpBsHeablN5VG9uYH+iFUVwVA +UHPOD9dqEzg6XV3uKfvMgY0ChSeTxXt85kRI04YWSz0 +-> ssh-ed25519 xNtnoA IaaP0EB/jO3SI3t/xRdQ3lwNoUEwbnfiMLozmCm/WHg +3rNnvts8o+nC5sl5CIRqVmGVRXNJ66YY1cW7kQOfWtI +-> ssh-ed25519 Nl/5yA cKrmmqXsTo0+fca2yYkverutncYCwk520aeBAGaHXwQ +4xWBcM/dSZlXLhhjMxp80msywQU25weHTz046KwljKk +-> ssh-ed25519 GdLgCQ ZfvLrLUWu4xxFYONerRZM5p9uxvT9szo1V0TJON6rSc +NbB1zDiCuV1zHLre0uA5dvBEHxIUauz42xk/oCvczlA +-> ssh-ed25519 tOH/HQ 1Y20TH6y2I4Qm8w0Nzu5iC+K3ZUiaIL7PemZBZVPliE +1i1PVvXPT7cWdfmr1zs68WOc1UfaIT7dTRcrc+jXMs0 +-> ssh-ed25519 FpzvfQ ZhVpLDqkN/nlXqtuF+GRQlSrxg0sf5w+6+ZG2DdPE0w +qo/WhjlAs1GrQycXsZHJ4UNcF5cXeErjhPBxDRHFhYU +-> ssh-ed25519 kdPvzQ 9zXqF+TL09+CiiQmFBN4Ot/c6uD4u0OEYXWJPaFRSxY +DPVcP9vxZj/6kXRc0OgBprgJKwfL9NB9EIXYJyqah7o +-> ssh-ed25519 onmXpg Gs0MOWzCOYIRhBPfZyL5Z1TdPqMNIq3wXIlq2DYbBWI +yUzy442MRbdWty9RDsaY5O4Wchvd7LEAuGnGa8fCOxA +-> ssh-ed25519 CnhD0g 6tT8mA7uhnmzCpNTogvn17sO8zTW0exFeixIgvAyAyk +ytGcHx7w5rz+c2gJ1FVdhLXG2O38JChCCNqSttwxzsI +--- 4i0TkrK0RTDthPFfeHDd2ibgqaTKIBurUlyqpokWi6o +#=OFhp.*ef +Q \ No newline at end of file diff --git a/secrets/minio_secret_access_key.age b/secrets/minio_secret_access_key.age new file mode 100644 index 0000000..fb330d3 --- /dev/null +++ b/secrets/minio_secret_access_key.age @@ -0,0 +1,27 @@ +age-encryption.org/v1 +-> ssh-ed25519 oyEmTw K64YZ3oV6Y6Yo8MS94zi0kCYnFawmOJSjBITRG7AeiQ +9OJyljEKIx1s1PfIdMvtzw+2cXS5pXjkgAipYLiDjyw +-> ssh-ed25519 mOmPfg Hsh9HGdGSWnXznjR4mkiMkbKUOXcaCQFIO08EB5/Ekc +MdAvpPaplb5sZ1E1Oht4PK4AtqXZyPSMugyTMpfhPm0 +-> ssh-ed25519 YJiRbw DlHantLuhX38Y2AB6Cz7KER10XSmGGyRGqJXCvGHDT8 +ZwqPXgKnC5wirlIg+KCHA6TDhN0Sy4S+UFJDlruiooQ +-> ssh-ed25519 aY2AXA AQ9DBDsEyu9zEF8gKnfraumaYhp3BCAR86r/ILJ6IWE +T6JnZHXwUbccwsPJHTv+hFcVk2mCR2XLmb9T1eZnuZo +-> ssh-ed25519 xNtnoA t0uPYr6snRzOb2PzPz5TmjCfk3VsnE4SUiaNMMyEHU4 +a431i8PRHPIlIrguN20bgkhwKU7JlmvbTGxxn50TCLE +-> ssh-ed25519 Nl/5yA sleAnnThOoNzRWNMh1IGzp3ZZATBofTENSxiBK9joUw +TRUyZFIJXFejD3HVkVVBVel3lzQ4VJosYw/Dlvei0hs +-> ssh-ed25519 GdLgCQ lFiwpazUJUnR43dvdLp1Zunl/DuQw+HmRo95OaCfcxk +jJ/Q46ePulw0jEGW8zEd7IWWXu16XkeOkoFlohh+xl4 +-> ssh-ed25519 tOH/HQ 7BMLfACpO9nFjLbk7wkn1d2UQUJCBy2HDvaDrQ8tfls +kx5Uhf4hpOa4SMgkHsooIJ7yOKAXVcN27GRkGJHGFGg +-> ssh-ed25519 FpzvfQ PzqPPe2QOHMi8Qe0itydR6i+lIVwrV+uAQxMBHlicjo +WN2nq3X9g1cfEAes4VcvwZgRCOCOg7BaHloibSEyVrA +-> ssh-ed25519 kdPvzQ KxmqKQtYW8IkpWIdf+I59v7AUZKT/3FSZYLVIDQofz4 +5DQ4dwCYhFKZKo3fluQPa6skzz6CrdICTzS3FRzccnk +-> ssh-ed25519 onmXpg s/bWvEbtSGEzCJm8NVpCGjedkM8x3ghfOacNfvlJ+10 +vcEoWg6QnoXoV3DU0Kyc6ZZRWbXE/pPYWCl2keEzoeU +-> ssh-ed25519 CnhD0g Lrb+HkK0iCFpSRfsJm+tdROGJIfnEayteY1Ja4l2lUQ +YzqwdSAmF5ksx9BpUJk/aIz2xenaAacwxRxZGcyVXSQ +--- J031VMz/nwgAAOpEKSqxKKZ8wOOrONpkptB5RA1lzMQ +"y(40!edxhH,RkVhnP0EuEͮ \ No newline at end of file diff --git a/secrets/secrets.nix b/secrets/secrets.nix index ac70882..bbc3f45 100644 --- a/secrets/secrets.nix +++ b/secrets/secrets.nix @@ -60,9 +60,13 @@ in "gitlab/myself-vbox-runner-reg.age".publicKeys = everyone; "gitlab/myself-podman-runner-reg.age".publicKeys = everyone; "gitlab/myself-shell-runner-reg.age".publicKeys = everyone; + "gitlab/linode-deployer-runner-reg.age".publicKeys = everyone; "gitlab/docker-auth.age".publicKeys = everyone; "acme_password.age".publicKeys = everyone; "ca/intermediate_key.age".publicKeys = everyone; "ca/root_key.age".publicKeys = everyone; + + "minio_secret_access_key.age".publicKeys = everyone; + "minio_access_key_id.age".publicKeys = everyone; }