Add Genesis

This commit is contained in:
Greg Hellings
2023-08-18 20:47:44 -05:00
parent 9c22f7414c
commit 64834c6f83
8 changed files with 355 additions and 1 deletions
+1
View File
@@ -4,3 +4,4 @@ ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQDUd5LQVl/spIfJ3mh/MERlCfSIHCh3jXnaNVnyHY2A
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQCoGGV3eD1oF0O62JZfCWNxmViRjRGQsfOhRkQfzQROkwDlFZ7S1+02fudD9t7mPtZE6dQ4yS2+6Q3NIfGW8NBbZAlWwsQ6PnrpuAhWpWc+ng/IDQd9CH/rBCt5bWSLL8AGHa4c+qde7iyoFGK0l9jXVD9wATBFQ274WTmPacVQVHmIAmJS6ISmR6vlq9eaDj1fX8wixao6WvzfwAUvXIs8nhPEfmtyu4T/1Eev9rVIxOw3ODQjk/E0VWV4Koeptsyc+V+j+XMyA91v8f20T4Uwe5LGnJHSQS0WavHnCMWHb1tzkmiKdaNCymoDUcUF2rywMYry7JN0kZo2mp2d7OzE/RP3bz/IsAI33+DwRlDYDNzgeLsLVmOJij61AtqBZque6WDcyCF8HN0ZaY0KJPOtNlN92+GUBRF/Faei0MXZ7wW2BZL5Bc7qnXc9USyhPNsm2vQ7LLhh/NtBGqB88+C+AidTTZ/xiIHKWZJXPkWLPRcK5cfaFqHFqcVMk4U+b0FYB95vYPKmjURlAZ6WrU6dNaNaMH9hJSE6/03is4hb4t8RCRiNaR41pEACDZbATjY0DInFn1LxxpUV66xfpOVg5hKm5ScIks3KxWJ8i3v4/cX7WvbDC/UzWb2UygpsqR7/1n5LV1SNPl+/qxFfdaOyZ8WVvx7DKGxkKfkPBgGwdpSthdv7BY+SC4sT9WXQAPGnvOIk6HwKhHjJYX7AIKK64ACfGZbjBC2gg7Ocl4HkgwpYYlUWLRJdJUhHOCi3VhPZDspYhw/UxPnUhYa8lxq5l7kgkks/tFe1qHOvPe3QRW6brg3EdJNkwtMrlrstW4/nph/KFqSshzNVDlEqTAnhE1cjbBZNmlHt1Un4ixcW1b8b86mE+472pSsIEfO8vxP26brQhxepJFZGOFv2vs3XDrrtn6IMJok4e+AQSCCY0kCcgfG5nMYXUoWpGyTpN/JLG0joJuhPWt58OaOzzKNPq2+rCVAbS7/UmDCqkwxjCywxOZRwluBsEWbZaLEdOwQOfIZQGwSDBM0hfHJJxMSaLN3rCe6VZb+c/5mFXUZ46L5mOGkRlO1TOEAe4jqawAQnuGaHN8mMWSw1gKM+UBXTKa0tBR6Aj/OSfPW0jU+mz/YzzJkzNnlRFiSrLxWvL4eXaBsMZvgKdpA41+E4JG8Vu+9D9KNGRnLASOCxRknV18MubZlEEyKby9A6TaKoPrz7GVQZP+36V9DtAJAza74nHSDNAQG/4w2BLOw9+VrDNdXwjMbgG+SN4f1K+e554OirtSMVB73VXjdwoH/FyX+7+dcUZRQ7V2n37jIVOE6CcuEPjzdnkvKSqBsdTO3Bt66+QtS9BwGHu5c01+Q7jvIl greg@nixos
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQDR4vmc5TiymSjMB7E+oYsiTxOg+2xwnLAILYjQKPA7dIvz/A/HW31R1aVVxNEgkHm8qeqmgE1bUysMMl128zvdKmwkMmq2uagx9hboyfCwOYRaQOtpS0dlgSllhM654vL9553t94sTuMIfNUiXBD3EV2Z5JJ1RteCkBTJjzmXQnV9he0xozBYOdGv35UGneQzAr7Pps9iK81mR4yW+vLcW3pAaPmDBbN7C6WFxqcEBWsaJZK0rLCTrQo+6B130XgH6gPgh4GyDaRmtRJl63yANiP/RfkDFTPKOh87slLLZaHJUe94P2CTZw0e9xSzWuzx71nBp9JhkoZkI9XD+AnbHIZ9X3twIADUf+D0fivzOH+Yzne0gNRFa+O4x8xd/xj8QeM+Rr1ATikBf/FRfyx+RzHgHS1ZyOKfIpQbrm44E8Smv7FzS5RcCfAScSn0npOqP0cilYjtDCEoeMVsx4XQy4+iYLOA/EaMICSz2PwQFG/KXe7NK30Cc5flq5qUiz8TX1Mzlxuro4qTktYSXZBs5YyEg3Za/hcqMV52kVn0W8S1DatHOL4TlRKYeKsg1hWNvtm2MRqJvWkqK9vNNL86Ew5D5hgXdCk+AiRzOhQxfprPYMea2Vx1Mkaq3VYHWmJBWc/m4aOKUSajhFu8KG7l8bc4IkgC+qQCYzr6pCUDlCaCEF1iQ3lItSkbJJmRBHKEOb85lsIJ/SZ0bhsMl8bc9z33zY+bwv2NezG/aKVGrny4ZTAI1BKkZN/60L0yzJihyKamEa442jjnvG1jzC2wEtd/0gCGWScfZsQWqDu97spbeq8jrc67U9xqlGTrWyyNsCW2lpu26cQWWRC8ufl5zBNRDFDSYKceBaJ2+sx1GPj3YYdJSlTt5JvxNyBg0BGfGqCTd0w4IXF3KP9IZRWWAKPaOZcil2MRZwYhWEd7p+CtKVAL93uW0sE+0C13+iFMnBUkFBJ2dZH+tWpywCRYcrVNvrBlsHe2XniwBwvQHUFgKaQAB8upFTK1xBWTh2S+CVyNed/fckAUrPDj4sI2NERGcyPC5Oi6r0fUPtcWvKRfA/yXx5A0iNWc6acTqd5wwSO3s8rOCjIwdczZmkmnjAf3UKhmtDnwRd9rbO5Hanom80re9Dk0W+z9E2+70b9iYvZ60pbw+cG4WqEQnr02RS8hKvU0CsYFoDMTzV4snqTKNrl0IeD+Fmjl7oDkcC4YQbZd2902qVL3WHHvW+p0WQ1B/rk8BPVRYVmrUQbqwPFCQlmTe3Zy+LpqbWYemhQJGVSiEiioVNCc7pHO6RyWLCoEQKwKHAoNleKtkG94hT/d0z+1RYpB/nbJ51BPihK5EMlXbw/Hu1SVaaDLOSL6p greg@mm
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINAX6pNx5mbwIa8X+GzktyNijfYmJUpgROFpRxSW9js0 greg@linode
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQCXP9nxL5Hg1R1AtT78zJl+ObCDZsnWWAqAYhTVjpRvYpiTbODvCf2IImvUsLGMdgo/xdSSzNqQcK6+KZVeNbvRSsw0ssWw7ggYnhw/yyv/KDZwnqXsppeucicnwpQNvts154yOqAvuuMaOYCTTQoOVvecDdgtA3svIpfxL3vVB/Mq/Ns/NwoE9XKz3NBYlWytqDcvSwR6Les7RzbMIs6axSfMVNwm9w41dG1NqDMteLjKlQ8bFfrtWXZ4QHKlnEWatOgJIzbP1hU91JvvzfypjleGuE9EBCSayqhu9PuxJ1/yxMJKSMaXUl8SoPMLsPNr1ZS5ZNjkNCvZK4fI+CqyAXtbgeSGKIKqZhg9z6/fR9SG0l3Gh3Prtw+AEuE+Xzb99Bi4IAe8lTaL+lw+z+CmsXR+kcJ4nnNrmf1fnDsI4l1EctVGb3Yt3tutV6GjB4mDjIYKwNBxuIx8hlugmZIy3oEUGrh85o5wnXlJQzmhszS4eas99dj1L5tj5dF4O/ED7SyQI5e7V9Pb5AgolcvLLXcFzDuy43oU8kWvQJMMvbEIFr6qPXWmp8MvrSTucRQCCzWJVudhrYhodXA56tRoJvFIRs0s12p/YXzsmJbKxPiVwLGOlCd2CqbdM2rCqN2LkUeOAQitb/8wv4njRKZ4lgqhjyXnBtoD2Nm/NmuIERoUY9J21dOhc2tg0zLvH120xVKa+WN5HVOOG9LyKl7koyc8nqdSDKFhcN4joYmnZKfyJUJzQIhiQayEfvWfTNJiNVkMIE2OqQ4O64s/7QzOHeHSMzY4TCO7+5bK9ecOqPxCDHLHhO0xVA3/w4FscRkObjkQ6zv3UCFJTSbr4YkdUIk8OtRR2KN9y9txrt/OS1l1DigVyuYUdz/L83+Y8E8d3l0hq/S1YLMwlkCbHE8hm0HxlLuyTA3OqXizRxNk7w4ku9OC4+nHrj03i2apNG0Z/ojcGsJxSBLhPGlPWbDJ2h7YL+lkDZFitdhBZHjIQKC2dNoretA8zEzNk48Pi829NFRuXqjSsq3iOJ1sXP/lMAZvdzbZOQ8CrH5SWb9GDeWR0uh76RXzKXvv5UTtu1PpYj/BHToApc8kUAxpUh3ypjt6bS7XLYtk74PEZHD3HXbpBYBnMNPUp2ecDw6rxpLxq3rnzROriX4Uvy0sOx8Q13ZgrZwxLeEWImlK9qQT4SYytGGxt4vwG0R2B8zS1xNiNC/B8jnBrK4GwnYSuJwNMrJ8vk1u9gn1pCj51RslBsldVzVB30jxNU74iD/WQGJudJrUAYkQ5EpArKZK0GQfaRXM6VzsvyLBA02CZJkeIU0jUc6Q1Nms+C8teKrP8+EKXONT/igsLXwfLMiR2CqVP greg@nixos
+9 -1
View File
@@ -36,7 +36,15 @@ let
] ++ extraMods;
};
in {
"2maccabees" = unstable { name = "2maccabees"; system = "aarch64-linux"; };
"2maccabees" = unstable {
system = "aarch64-linux";
name = "2maccabees";
};
genesis = unstable {
name = "genesis";
gnome = true;
gui = true;
};
jude = unstable {
name = "jude";
gnome = true;
+43
View File
@@ -0,0 +1,43 @@
# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{ config, pkgs, ... }:
{
imports =
[ # Include the results of the hardware scan.
./dnsmasq.nix
./hardware-configuration.nix
./home-assistant.nix
./networking.nix
./vhosts.nix
];
greg.home = true;
greg.gnome.enable = true;
# Bootloader.
boot.loader.systemd-boot.enable = true;
boot.loader.efi.canTouchEfiVariables = true;
boot.loader.efi.efiSysMountPoint = "/boot/efi";
networking.hostName = "genesis"; # Define your hostname.
# Enable sound with pipewire.
sound.enable = true;
hardware.pulseaudio.enable = false;
security.rtkit.enable = true;
services.pipewire = {
enable = true;
alsa.enable = true;
alsa.support32Bit = true;
pulse.enable = true;
# If you want to use JACK applications, uncomment this
#jack.enable = true;
# use the example session manager (no others are packaged yet so this is enabled by default,
# no need to redefine it in your config for now)
#media-session.enable = true;
};
}
+80
View File
@@ -0,0 +1,80 @@
{ config, pkgs, ... }:
let
extraHosts = builtins.concatStringsSep "\n" [
# Local hosts
"10.42.0.1 switch"
"10.42.1.1 router"
"10.42.1.2 2maccabees 2maccabees.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan"
"10.42.1.3 printer"
"10.42.1.4 chronicles nas"
"10.42.1.12 tv"
# Tailscale hosts
"100.90.74.19 jude.me.ts"
"100.99.244.92 dns.me.ts 2maccabees.me.ts smart.me.ts jellyfin.me.ts"
"100.119.228.115 chronicles.me.ts nas.me.ts"
"100.115.57.8 linode.me.ts"
# Dev hosts
"10.42.101.1 icdm.lan wiki.icdm.lan *.icdm.lan"
];
extraConfig = builtins.concatStringsSep "\n" [
];
in
{
# Enable the service with its own configuration
services.dnsmasq = {
enable = true;
# Public AdGuard DNS servers
settings = {
domain = "thehellings.lan";
dhcp-range = [
# "eth0,10.42.0.1,10.42.1.255,255.255.0.0,static"
"eth0,10.42.2.1,10.42.2.255,255.255.0.0,12h"
"vlan66@eth0,192.168.66.3,192.168.66.150,255.255.255.0,12h"
"vlan67@eth0,192.168.67.3,192.168.67.150,12h"
];
dhcp-option = [
"eth0,option:router,10.42.1.1"
"eth0,option:dns-server,10.42.1.2,1.1.1.1"
"eth0,option:domain-search,thehellings.lan"
"vlan66@eth0,option:router,192.168.66.1"
"vlan66@eth0,option:dns-server,192.168.66.2"
"vlan67@eth0,option:router,192.168.67.1"
"vlan67@eth0,option:dns-server,192.168.67.2"
];
expand-hosts = true;
log-dhcp = true;
log-queries = true;
addn-hosts = "/etc/adblock_hosts";
server = [
"94.140.14.14"
"94.140.15.15"
];
};
extraConfig = "${extraConfig}";
};
environment.systemPackages = [ pkgs.curl ];
# Regularly update DNS block list
services.cron = {
enable = true;
systemCronJobs = [
"* * * * * root ( ${pkgs.curl}/bin/curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts && systemctl restart dnsmasq ) 2>&1 > /var/log/adblock.log"
];
};
# Allow traffic through
networking.firewall = {
enable = true;
allowedTCPPorts = [ 53 ];
allowedUDPPorts = [ 53 67 ];
};
# Custom host addition
networking.extraHosts = "${extraHosts}";
}
+42
View File
@@ -0,0 +1,42 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "nvme" "usb_storage" "sd_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/disk/by-uuid/a509426b-5af7-4d04-ac42-619674d932d9";
fsType = "btrfs";
options = [ "subvol=@" ];
};
fileSystems."/boot/efi" =
{ device = "/dev/disk/by-uuid/5AC6-50D7";
fsType = "vfat";
};
swapDevices =
[ { device = "/dev/disk/by-uuid/a57f8b82-dc0c-4906-8a48-56203d07556b"; }
];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.enp1s0.useDHCP = lib.mkDefault true;
# networking.interfaces.enp2s0.useDHCP = lib.mkDefault true;
# networking.interfaces.eth2.useDHCP = lib.mkDefault true;
powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
+90
View File
@@ -0,0 +1,90 @@
{ config, pkgs, ... }:
let
service_list = [ "podman-home-assistant.service" ];
in
{
virtualisation.podman.enable = true;
services.home-assistant = {
enable = true;
configDir = "/var/lib/hass";
package = (pkgs.home-assistant.override {
extraComponents = [
"accuweather"
"calendar"
"cast"
"eufy"
"lovelace"
"nextcloud"
"smart_meter_texas"
"solaredge"
"tplink"
"wiz"
"zwave_js"
];
}).overrideAttrs (oldAttrs: {
doInstallCheck = false;
});
config = {
default_config = {};
esphome = {}; # Get these things loaded, even if not configured
met = {};
tts = [ { platform = "google_translate"; } ];
http = {
use_x_forwarded_for = true;
trusted_proxies = [ "127.0.0.1" "::1" ];
server_host = "127.0.0.1";
};
#"automation manual" = *nix config here* and so on
"automation ui" = "!include automations.yaml";
"script ui" = "!include scripts.yaml";
"scene ui" = "!include scenes.yaml";
};
};
# Although NixOS has a package for Home Assistant, it is not kept as up to date as the container and the upstream
# is very vocal about only supporting their own container or the HAOS deployments. So we deploy the container here
# and avoid any potential messes from that
virtualisation.oci-containers = {
backend = "podman";
# I have ZWave devices. The easiest way to connect to them is the zwavejs2mqtt service running, so we spin up
# its container and map the ZWave device into it
containers.zwave = {
image = "zwavejs/zwavejs2mqtt:latest";
ports = [ "8091:8091" "3000:3000" ];
volumes = [ "/var/lib/zwave:/usr/src/app/store" ];
extraOptions = [
"--device" "/dev/serial/by-id/usb-0658_0200-if00:/dev/zwave"
"--pull=newer"
];
};
};
# Both of the above container need storage for their configuration and devices, but it is not created correctly by
# the container. So we add the creation of /var/lib/{zwave,hass} to the systemd Unit files
systemd.services = {
"podman-zwave".serviceConfig = {
StateDirectory = "zwave";
StateDirectoryMode = pkgs.lib.mkForce "0777";
};
};
greg.proxies."smart.thehellings.lan".target = "http://127.0.0.1:8123";
# Ensure that both ports are up and running. We keep 8123 directly open because we are on the LAN and sometimes want to connect
# directly for troubleshooting Nginx configuration
networking.firewall = {
enable = true;
allowedTCPPorts = [ 80 443 8091 8123 ];
};
greg.backup.jobs.zwave = {
src = "/var/lib/zwave";
dest = "zwave";
user = "root";
};
}
+75
View File
@@ -0,0 +1,75 @@
{ ... }:
{
greg.tailscale.enable = true;
networking = {
# This value is deprecated, you now set it per interface
useDHCP = false;
defaultGateway = "10.42.1.1";
# 100.100.100.100 is the tailscale DNS
nameservers = [ "100.100.100.100" "127.0.0.1" ];
interfaces = {
eth0.ipv4.addresses = [ {
address = "10.42.1.2";
prefixLength = 16;
} ];
wlan0.useDHCP = true;
vlan66.ipv4.addresses = [ {
address = "192.168.66.2";
prefixLength = 24;
} ];
};
vlans = {
vlan66 = {
id = 66;
interface = "eth0";
};
};
};
# Open ports in the firewall.
# networking.firewall.allowedTCPPorts = [ ... ];
# networking.firewall.allowedUDPPorts = [ ... ];
# Or disable the firewall altogether.
# networking.firewall.enable = false;
fileSystems."/media" = {
device = "10.42.1.4:/volume1/video/";
fsType = "nfs";
options = [ "ro" ];
};
services.jellyfin = {
enable = true;
openFirewall = true;
};
greg.proxies."jellyfin.thehellings.lan".target = "http://localhost:8096";
greg.proxies."jellyfin.me.ts".target = "http://localhost:8096";
#########
# Blind service proxy behind the walls of the VPN
########
services._3proxy = {
enable = true;
services = [ {
type = "socks";
auth = [ "strong" ];
bindPort = 3128;
acl = [ {
rule = "allow";
users = [ "greg" ];
} ];
} ];
usersFile = "/run/agenix/3proxy";
denyPrivate = false;
};
age.secrets."3proxy" = {
file = ../../secrets/3proxy.age;
mode = "777";
};
networking.firewall.allowedTCPPorts = [ 3128 ];
}
+15
View File
@@ -0,0 +1,15 @@
# Virtual hosts that don't seem to have any better place to live should go in here.
# There are others that are specific to their own purposese scattered about in the
# configuration in places where they more naturally live. This is more of a catchall
# for ones that do not have a better place to live
{ ... }:
{
greg.proxies."dns.thehellings.lan" = {
target = "http://127.0.0.1:8384/";
path = "/sync/";
};
# The module doesn't handle this
services.nginx.virtualHosts."dns.thehellings.lan".serverAliases = [ "dns" ];
}