diff --git a/flake.lock b/flake.lock index e3f2fb5..433fe44 100644 --- a/flake.lock +++ b/flake.lock @@ -23,28 +23,6 @@ "type": "github" } }, - "btc": { - "inputs": { - "extra-container": "extra-container", - "flake-utils": "flake-utils", - "nixpkgs": "nixpkgs", - "nixpkgs-unstable": "nixpkgs-unstable" - }, - "locked": { - "lastModified": 1763988628, - "narHash": "sha256-ss6OdixftoK6Mttp7MLAo4ROxT1OCvfHP8JLsVmuhc0=", - "owner": "fort-nix", - "repo": "nix-bitcoin", - "rev": "f1ebb5d2cd10a6fd4b94e370ceec9a7b7a6e3cd7", - "type": "github" - }, - "original": { - "owner": "fort-nix", - "ref": "release", - "repo": "nix-bitcoin", - "type": "github" - } - }, "buildbot": { "inputs": { "flake-parts": "flake-parts", @@ -70,10 +48,10 @@ }, "charts": { "inputs": { - "flake-utils": "flake-utils_2", + "flake-utils": "flake-utils", "haumea": "haumea", "nix-kube-generators": "nix-kube-generators", - "nixpkgs": "nixpkgs_2", + "nixpkgs": "nixpkgs", "poetry2nix": "poetry2nix" }, "locked": { @@ -93,9 +71,9 @@ "colmena": { "inputs": { "flake-compat": "flake-compat", - "flake-utils": "flake-utils_4", + "flake-utils": "flake-utils_3", "nix-github-actions": "nix-github-actions_2", - "nixpkgs": "nixpkgs_3", + "nixpkgs": "nixpkgs_2", "stable": "stable" }, "locked": { @@ -155,32 +133,6 @@ "type": "github" } }, - "extra-container": { - "inputs": { - "flake-utils": [ - "btc", - "flake-utils" - ], - "nixpkgs": [ - "btc", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1734005403, - "narHash": "sha256-vgh3TqfkFdnPxREBedw4MQehIDc3N8YyxBOB45n+AvU=", - "owner": "erikarvstedt", - "repo": "extra-container", - "rev": "f4de6c329b306a9d3a9798a30e060c166f781baa", - "type": "github" - }, - "original": { - "owner": "erikarvstedt", - "ref": "0.13", - "repo": "extra-container", - "type": "github" - } - }, "flake-compat": { "flake": false, "locked": { @@ -322,32 +274,14 @@ "type": "github" }, "original": { - "owner": "numtide", - "repo": "flake-utils", - "type": "github" + "id": "flake-utils", + "type": "indirect" } }, "flake-utils_2": { "inputs": { "systems": "systems_3" }, - "locked": { - "lastModified": 1731533236, - "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=", - "owner": "numtide", - "repo": "flake-utils", - "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b", - "type": "github" - }, - "original": { - "id": "flake-utils", - "type": "indirect" - } - }, - "flake-utils_3": { - "inputs": { - "systems": "systems_4" - }, "locked": { "lastModified": 1726560853, "narHash": "sha256-X6rJYSESBVr3hBoH0WbKE5KvhPU5bloyZ2L4K60/fPQ=", @@ -362,7 +296,7 @@ "type": "github" } }, - "flake-utils_4": { + "flake-utils_3": { "locked": { "lastModified": 1659877975, "narHash": "sha256-zllb8aq3YO3h8B/U0/J1WBgAL8EX5yWf5pMj3G0NAmc=", @@ -577,16 +511,16 @@ }, "nixpkgs": { "locked": { - "lastModified": 1763622513, - "narHash": "sha256-1jQnuyu82FpiSxowrF/iFK6Toh9BYprfDqfs4BB+19M=", + "lastModified": 1739020877, + "narHash": "sha256-mIvECo/NNdJJ/bXjNqIh8yeoSjVLAuDuTUzAo7dzs8Y=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "c58bc7f5459328e4afac201c5c4feb7c818d604b", + "rev": "a79cfe0ebd24952b580b1cf08cd906354996d547", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-25.05", + "ref": "nixos-unstable", "repo": "nixpkgs", "type": "github" } @@ -637,22 +571,6 @@ } }, "nixpkgs-unstable": { - "locked": { - "lastModified": 1763618868, - "narHash": "sha256-v5afmLjn/uyD9EQuPBn7nZuaZVV9r+JerayK/4wvdWA=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "a8d610af3f1a5fb71e23e08434d8d61a466fc942", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixpkgs-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs-unstable_2": { "locked": { "lastModified": 1761114652, "narHash": "sha256-f/QCJM/YhrV/lavyCVz8iU3rlZun6d+dAiC3H+CDle4=", @@ -668,22 +586,6 @@ } }, "nixpkgs_2": { - "locked": { - "lastModified": 1739020877, - "narHash": "sha256-mIvECo/NNdJJ/bXjNqIh8yeoSjVLAuDuTUzAo7dzs8Y=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "a79cfe0ebd24952b580b1cf08cd906354996d547", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "nixos-unstable", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_3": { "locked": { "lastModified": 1750134718, "narHash": "sha256-v263g4GbxXv87hMXMCpjkIxd/viIF7p3JpJrwgKdNiI=", @@ -699,7 +601,7 @@ "type": "github" } }, - "nixpkgs_4": { + "nixpkgs_3": { "locked": { "lastModified": 1765779637, "narHash": "sha256-KJ2wa/BLSrTqDjbfyNx70ov/HdgNBCBBSQP3BIzKnv4=", @@ -715,7 +617,7 @@ "type": "github" } }, - "nixpkgs_5": { + "nixpkgs_4": { "locked": { "lastModified": 1759770925, "narHash": "sha256-CZwkCtzTNclqlhuwDsVtGoRumTpqCUK0xSnFIMgd8ls=", @@ -753,7 +655,7 @@ "nixpkgs": [ "nixunstable" ], - "systems": "systems_6" + "systems": "systems_5" }, "locked": { "lastModified": 1765929769, @@ -773,7 +675,7 @@ "nurpkgs": { "inputs": { "flake-parts": "flake-parts_4", - "nixpkgs": "nixpkgs_4" + "nixpkgs": "nixpkgs_3" }, "locked": { "lastModified": 1765924577, @@ -791,13 +693,13 @@ }, "poetry2nix": { "inputs": { - "flake-utils": "flake-utils_3", + "flake-utils": "flake-utils_2", "nix-github-actions": "nix-github-actions", "nixpkgs": [ "charts", "nixpkgs" ], - "systems": "systems_5", + "systems": "systems_4", "treefmt-nix": "treefmt-nix_2" }, "locked": { @@ -819,7 +721,7 @@ "flake-compat": "flake-compat_2", "nixpkgs-libvncserver": "nixpkgs-libvncserver", "nixpkgs-stable": "nixpkgs-stable", - "nixpkgs-unstable": "nixpkgs-unstable_2", + "nixpkgs-unstable": "nixpkgs-unstable", "utils": "utils" }, "locked": { @@ -839,7 +741,6 @@ "root": { "inputs": { "agenix": "agenix", - "btc": "btc", "buildbot": "buildbot", "charts": "charts", "colmena": "colmena", @@ -962,21 +863,6 @@ "type": "github" } }, - "systems_7": { - "locked": { - "lastModified": 1681028828, - "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=", - "owner": "nix-systems", - "repo": "default", - "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e", - "type": "github" - }, - "original": { - "owner": "nix-systems", - "repo": "default", - "type": "github" - } - }, "treefmt-nix": { "inputs": { "nixpkgs": [ @@ -1022,7 +908,7 @@ }, "utils": { "inputs": { - "systems": "systems_7" + "systems": "systems_6" }, "locked": { "lastModified": 1731533236, @@ -1040,7 +926,7 @@ }, "vsext": { "inputs": { - "nixpkgs": "nixpkgs_5" + "nixpkgs": "nixpkgs_4" }, "locked": { "lastModified": 1766109760, diff --git a/flake.nix b/flake.nix index 5089e83..718f916 100644 --- a/flake.nix +++ b/flake.nix @@ -9,9 +9,6 @@ url = "github:ryantm/agenix"; inputs.nixpkgs.follows = "nixunstable"; }; - btc = { - url = "github:fort-nix/nix-bitcoin/release"; - }; buildbot = { url = "github:nix-community/buildbot-nix"; inputs.nixpkgs.follows = "nixunstable"; diff --git a/hosts/default.nix b/hosts/default.nix index 8b84551..dbe50cd 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -22,6 +22,9 @@ let inherit metadata top; }; modules = [ + { + nixpkgs.hostPlatform = system; + } # Imported ones top.agenix.nixosModules.default hm.nixosModules.home-manager diff --git a/hosts/hosea/bitcoin.nix b/hosts/hosea/bitcoin.nix deleted file mode 100644 index 8b25efc..0000000 --- a/hosts/hosea/bitcoin.nix +++ /dev/null @@ -1,86 +0,0 @@ -{ config, pkgs, ... }: - -let - ip = "100.68.203.1"; -in -{ - nix-bitcoin = { - generateSecrets = true; - operator = { - enable = true; - name = "greg"; - }; - useVersionLockedPkgs = true; # Use the exact versions of packages from upstream - }; - - networking.firewall.allowedTCPPorts = with config.services; [ - bitcoind.port - bitcoind.rpc.port - lnd.restPort - lnd.port - mempool.frontend.port - rtl.port - ]; - - greg.backup.jobs = { - clightning = { - src = config.services.clightning.replication.local.directory; - dest = "hosea-clightning"; - }; - }; - - services = { - backups = { - enable = true; - frequency = "hourly"; - }; - bitcoind = { - enable = true; - address = "0.0.0.0"; - dataDir = "/chain/bitcoind"; - listen = true; - rpc = { - address = ip; - allowip = [ "100.1.1.1/8" ]; - }; - }; - clightning = { - enable = true; - address = ip; - port = 9736; - replication = { - enable = true; - local.directory = "/var/backup/clightning"; - encrypt = false; - }; - }; - electrs = { - enable = true; - address = ip; - }; - lnd = { - enable = true; - address = ip; - lndconnect.enable = true; - }; - mempool = { - enable = true; - frontend = { - enable = true; - address = ip; - }; - }; - rtl = { - enable = true; - address = ip; - dataDir = "/chain/rtl"; - extraCurrency = "USD"; - nodes = { - clightning.enable = true; - lnd.enable = true; - }; - }; - }; - - environment.systemPackages = with pkgs; [ ]; -} diff --git a/hosts/hosea/default.nix b/hosts/hosea/default.nix index c512d7c..4db5e7c 100644 --- a/hosts/hosea/default.nix +++ b/hosts/hosea/default.nix @@ -5,7 +5,6 @@ { config, pkgs, - top, ... }: let @@ -18,8 +17,6 @@ in imports = [ # Include the results of the hardware scan. ./hardware-configuration.nix - top.btc.nixosModules.default - ./bitcoin.nix ]; # Bootloader @@ -90,6 +87,13 @@ in }; services = { + albyhub = { + enable = true; + openFirewall = true; + settings = { + workDir = "/chain/alby"; + }; + }; jellyfin = { enable = true; openFirewall = true; diff --git a/modules/nixos/albyhub.nix b/modules/nixos/albyhub.nix new file mode 100644 index 0000000..bb331d1 --- /dev/null +++ b/modules/nixos/albyhub.nix @@ -0,0 +1,109 @@ +{ + config, + lib, + pkgs, + ... +}: +let + inherit (lib) types; + cfg = config.services.albyhub; +in +{ + options = { + services.albyhub = { + enable = lib.mkEnableOption "Enable the Alby Hub service"; + + group = lib.mkOption { + type = types.str; + default = "albyhub"; + description = "Group to add user to, and give process permissions for"; + }; + + openFirewall = lib.mkOption { + type = types.bool; + default = false; + description = "Automatically open firewall access for this service."; + }; + + package = lib.mkPackageOption pkgs "albyhub" { }; + + user = lib.mkOption { + type = types.str; + default = "albyhub"; + description = "User to run the service as"; + }; + + settings = { + database = lib.mkOption { + type = types.str; + default = "${cfg.workDir}/database.db"; + description = "Either a path to the SQLite database location or a Postgres URI"; + }; + + logLevel = lib.mkOption { + type = types.int; + default = 4; + description = "Higher integers are more verbose logging. Default is 4, which is info"; + }; + + port = lib.mkOption { + type = types.int; + default = 8080; + description = "Port for the service to listen on"; + }; + + relay = lib.mkOption { + type = types.listOf types.str; + default = [ "wss://relay.getalby.com/v1" ]; + description = "List of relays for Albyhub to connect to."; + }; + + workDir = lib.mkOption { + type = types.str; + default = "/var/lib/albyhub"; + description = "Work directory for Alby Hub"; + }; + }; + }; + }; + + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = cfg.settings.port > 0 && cfg.settings.port <= 65535; + message = "Alby hub port must be an integer between 1 and 65535"; + } + ]; + + networking.firewall.allowedTCPPorts = lib.mkIf cfg.openFirewall [ cfg.settings.port ]; + + systemd.services.albyhub = { + after = [ "network-online.target" ]; + environment = { + LOG_LEVEL = builtins.toString cfg.settings.logLevel; + PORT = builtins.toString cfg.settings.port; + RELAY = builtins.concatStringsSep "," cfg.settings.relay; + WORK_DIR = cfg.settings.workDir; + }; + requiredBy = [ "multi-user.target" ]; + script = "${lib.getExe cfg.package}"; + wants = [ "network-online.target" ]; + + serviceConfig = { + DynamicUser = true; + Group = cfg.group; + ReadWritePaths = cfg.settings.workDir; + Restart = "always"; + User = cfg.user; + }; + }; + + users = { + groups.${cfg.group} = { }; + users.${cfg.user} = { + isSystemUser = true; + group = cfg.group; + }; + }; + }; +} diff --git a/modules/nixos/default.nix b/modules/nixos/default.nix index ec850ae..2a4945b 100644 --- a/modules/nixos/default.nix +++ b/modules/nixos/default.nix @@ -4,6 +4,7 @@ { imports = [ + ./albyhub.nix ./backup.nix ./ceph.nix ./db.nix diff --git a/network.json b/network.json index dbba128..97908b3 100644 --- a/network.json +++ b/network.json @@ -41,6 +41,9 @@ "iso": { "system": "x86_64-linux" }, + "ivr": { + "system": "aarc64-darwin" + }, "jeremiah": { "builder": true, "ip": "10.42.1.8",