From 5eee8ea67cd763df2ae439fb8ba92aa24e480c92 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 22 Jul 2024 13:50:46 -0500 Subject: [PATCH 1/3] Add usbutils to default --- modules/nixos/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/nixos/default.nix b/modules/nixos/default.nix index 1e42e83..d32bb6a 100644 --- a/modules/nixos/default.nix +++ b/modules/nixos/default.nix @@ -24,6 +24,7 @@ efibootmgr psmisc lshw + usbutils ]; system.stateVersion = "24.05"; From fb45b77e27f7b7e2ed3fa226990d158617f53b49 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 22 Jul 2024 13:58:55 -0500 Subject: [PATCH 2/3] Remove several genesis services Remove Nginx proxy Remove mounting of LUN --- hosts/genesis/networking.nix | 40 ------------------------------------ overlays/default.nix | 2 +- 2 files changed, 1 insertion(+), 41 deletions(-) diff --git a/hosts/genesis/networking.nix b/hosts/genesis/networking.nix index 6366008..86fcf34 100644 --- a/hosts/genesis/networking.nix +++ b/hosts/genesis/networking.nix @@ -75,10 +75,6 @@ in { fsType = "nfs"; options = [ "ro" ]; }; - "/proxy" = { - device = "/dev/vdb1"; - fsType = "btrfs"; - }; }; services = { @@ -187,42 +183,6 @@ in { "jellyfin.home".target = "http://localhost:8096/"; }; - services = { - nginx.virtualHosts."nixcache.thehellings.lan" = { - serverName = "nixcache.thehellings.lan"; - serverAliases = [ "nixcache" "nixcache.home" ]; - root = "/proxy"; - locations = { - "~ ^/nix-cache-info" = { - proxyPass = "https://cache.nixos.org"; - root = "/proxy/nixpkgs/nix-cache-info/store"; - recommendedProxySettings = false; - extraConfig = '' - error_log /var/log/nginx/proxy.log debug; - proxy_store on; - proxy_store_access user:rw group:rw all:r; - proxy_temp_path /proxy/nixpkgs/nix-cache-info/temp; - proxy_pass_request_headers on; - proxy_set_header Host "cache.nixos.org"; - ''; - }; - "~^/nar/.+$" = { - proxyPass = "https://cache.nixos.org"; - root = "/proxy/nixpkgs/nar/store"; - recommendedProxySettings = false; - extraConfig = '' - proxy_store on; - proxy_store_access user:rw group:rw all:r; - proxy_temp_path /proxy/nixpkgs/nar/temp; - proxy_pass_request_headers on; - proxy_set_header Host "cache.nixos.org"; - ''; - }; - }; - }; - }; - systemd.services.nginx.serviceConfig.ReadWritePaths = [ "/proxy" ]; - environment.systemPackages = with pkgs; [ bind curl # Used by dnsmasq fetching diff --git a/overlays/default.nix b/overlays/default.nix index ce58c26..926b646 100644 --- a/overlays/default.nix +++ b/overlays/default.nix @@ -83,7 +83,7 @@ in rec { }; pipenv-ivr = prev.callPackage ./pipenv.nix { }; - myxonsh = (prev.xonsh-unwrapped.passthru.wrapper.override { + myxonsh = (prev.unstable.xonsh-unwrapped.passthru.wrapper.override { extraPackages = (ps: with ps; [ xonsh-apipenv xonsh-direnv From b4a0561ed62e26097cdb6d957f9dc590eb3367c7 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Mon, 22 Jul 2024 14:40:10 -0500 Subject: [PATCH 3/3] Simplify Hosea Remove the Hosea gitlab runner service Remove extra Hosea supports for the runner service Setup S3 on Hosea, again, as an exposed service --- hosts/hosea/default.nix | 69 ----------------------------------------- hosts/hosea/minio.nix | 3 ++ modules/baseline.nix | 2 +- 3 files changed, 4 insertions(+), 70 deletions(-) diff --git a/hosts/hosea/default.nix b/hosts/hosea/default.nix index 1ed4a13..9a37af7 100644 --- a/hosts/hosea/default.nix +++ b/hosts/hosea/default.nix @@ -57,74 +57,5 @@ in layout = "us"; variant = ""; }; - gitlab-runner = { - enable = true; - settings.concurrent = 1; - services = { - shell = { - executor = "shell"; - limit = 5; - registrationConfigFile = config.age.secrets.runner-reg.path; - environmentVariables = { - EFI_DIR = "${pkgs.OVMF.fd}/FV/"; - STORAGE_URL = "http://minio-01.thehellings.lan:9000"; - }; - }; - }; - }; }; - - ##################################################################################### - #################### Virtualbox Runner ############################################## - ##################################################################################### - age.secrets.runner-reg.file = ../../secrets/gitlab/myself-vbox-runner-reg.age; - virtualisation.virtualbox.host = { - enable = true; - enableExtensionPack = true; - enableHardening = false; - headless = true; - }; - - systemd.services."gitlab-runner" = { - after = [ - "network.target" - "network-online.target" - "systemd-resolved.service" - ]; - # Moved here from myself/Isaiah, so technically unnecessary now - conflicts = [ - "container@gitlab-runner-qemu.service" - ]; - wants = [ - "network-online.target" - "systemd-resolved.service" - ]; - preStart = builtins.concatStringsSep "\n" [ - "${pkgs.kmod}/bin/modprobe vboxdrv" - "${pkgs.kmod}/bin/modprobe vboxnetadp" - "${pkgs.kmod}/bin/modprobe vboxnetflt" - ]; - postStop = "${pkgs.kmod}/bin/rmmod vboxnetadp vboxnetflt vboxdrv"; - serviceConfig = { - DevicePolicy = lib.mkForce "auto"; - User = "root"; - DynamicUser = lib.mkForce false; - }; - }; - environment.systemPackages = with pkgs; [ - curl - gawk - git - p7zip - packer - pup - gregpy - shellcheck - unzip - xorriso - vagrant - wget - ]; - - networking.firewall.allowedTCPPorts = [ 18083 ]; # Should be interface for vboxweb } diff --git a/hosts/hosea/minio.nix b/hosts/hosea/minio.nix index 65a042a..12f3c99 100644 --- a/hosts/hosea/minio.nix +++ b/hosts/hosea/minio.nix @@ -10,6 +10,7 @@ in { }; networking.firewall.allowedTCPPorts = [ + 80 minioPort minioConsolePort ]; @@ -23,6 +24,8 @@ in { browser = true; }; + greg.proxies."s3.thehellings.lan".target = "http://127.0.0.1:${toString minioPort}"; + environment.systemPackages = with pkgs; [ minio-client ]; diff --git a/modules/baseline.nix b/modules/baseline.nix index c1455c8..449602e 100644 --- a/modules/baseline.nix +++ b/modules/baseline.nix @@ -18,7 +18,7 @@ in keep-derivations = true; min-free = (toString (1024 * 1024 * 1024) ); max-free = (toString (5 * 1024 * 1024 * 1024) ); - substituters = (if notDarwin then [ "http://nixcache.home" ] else []) ++ [ + substituters = [ "https://cache.garnix.io" "https://ai.cachix.org" ];