diff --git a/home/ssh/authorized_keys b/home/ssh/authorized_keys index a657b83..e388d30 100644 --- a/home/ssh/authorized_keys +++ b/home/ssh/authorized_keys @@ -4,3 +4,4 @@ ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQDUd5LQVl/spIfJ3mh/MERlCfSIHCh3jXnaNVnyHY2A ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQCoGGV3eD1oF0O62JZfCWNxmViRjRGQsfOhRkQfzQROkwDlFZ7S1+02fudD9t7mPtZE6dQ4yS2+6Q3NIfGW8NBbZAlWwsQ6PnrpuAhWpWc+ng/IDQd9CH/rBCt5bWSLL8AGHa4c+qde7iyoFGK0l9jXVD9wATBFQ274WTmPacVQVHmIAmJS6ISmR6vlq9eaDj1fX8wixao6WvzfwAUvXIs8nhPEfmtyu4T/1Eev9rVIxOw3ODQjk/E0VWV4Koeptsyc+V+j+XMyA91v8f20T4Uwe5LGnJHSQS0WavHnCMWHb1tzkmiKdaNCymoDUcUF2rywMYry7JN0kZo2mp2d7OzE/RP3bz/IsAI33+DwRlDYDNzgeLsLVmOJij61AtqBZque6WDcyCF8HN0ZaY0KJPOtNlN92+GUBRF/Faei0MXZ7wW2BZL5Bc7qnXc9USyhPNsm2vQ7LLhh/NtBGqB88+C+AidTTZ/xiIHKWZJXPkWLPRcK5cfaFqHFqcVMk4U+b0FYB95vYPKmjURlAZ6WrU6dNaNaMH9hJSE6/03is4hb4t8RCRiNaR41pEACDZbATjY0DInFn1LxxpUV66xfpOVg5hKm5ScIks3KxWJ8i3v4/cX7WvbDC/UzWb2UygpsqR7/1n5LV1SNPl+/qxFfdaOyZ8WVvx7DKGxkKfkPBgGwdpSthdv7BY+SC4sT9WXQAPGnvOIk6HwKhHjJYX7AIKK64ACfGZbjBC2gg7Ocl4HkgwpYYlUWLRJdJUhHOCi3VhPZDspYhw/UxPnUhYa8lxq5l7kgkks/tFe1qHOvPe3QRW6brg3EdJNkwtMrlrstW4/nph/KFqSshzNVDlEqTAnhE1cjbBZNmlHt1Un4ixcW1b8b86mE+472pSsIEfO8vxP26brQhxepJFZGOFv2vs3XDrrtn6IMJok4e+AQSCCY0kCcgfG5nMYXUoWpGyTpN/JLG0joJuhPWt58OaOzzKNPq2+rCVAbS7/UmDCqkwxjCywxOZRwluBsEWbZaLEdOwQOfIZQGwSDBM0hfHJJxMSaLN3rCe6VZb+c/5mFXUZ46L5mOGkRlO1TOEAe4jqawAQnuGaHN8mMWSw1gKM+UBXTKa0tBR6Aj/OSfPW0jU+mz/YzzJkzNnlRFiSrLxWvL4eXaBsMZvgKdpA41+E4JG8Vu+9D9KNGRnLASOCxRknV18MubZlEEyKby9A6TaKoPrz7GVQZP+36V9DtAJAza74nHSDNAQG/4w2BLOw9+VrDNdXwjMbgG+SN4f1K+e554OirtSMVB73VXjdwoH/FyX+7+dcUZRQ7V2n37jIVOE6CcuEPjzdnkvKSqBsdTO3Bt66+QtS9BwGHu5c01+Q7jvIl greg@nixos ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQDR4vmc5TiymSjMB7E+oYsiTxOg+2xwnLAILYjQKPA7dIvz/A/HW31R1aVVxNEgkHm8qeqmgE1bUysMMl128zvdKmwkMmq2uagx9hboyfCwOYRaQOtpS0dlgSllhM654vL9553t94sTuMIfNUiXBD3EV2Z5JJ1RteCkBTJjzmXQnV9he0xozBYOdGv35UGneQzAr7Pps9iK81mR4yW+vLcW3pAaPmDBbN7C6WFxqcEBWsaJZK0rLCTrQo+6B130XgH6gPgh4GyDaRmtRJl63yANiP/RfkDFTPKOh87slLLZaHJUe94P2CTZw0e9xSzWuzx71nBp9JhkoZkI9XD+AnbHIZ9X3twIADUf+D0fivzOH+Yzne0gNRFa+O4x8xd/xj8QeM+Rr1ATikBf/FRfyx+RzHgHS1ZyOKfIpQbrm44E8Smv7FzS5RcCfAScSn0npOqP0cilYjtDCEoeMVsx4XQy4+iYLOA/EaMICSz2PwQFG/KXe7NK30Cc5flq5qUiz8TX1Mzlxuro4qTktYSXZBs5YyEg3Za/hcqMV52kVn0W8S1DatHOL4TlRKYeKsg1hWNvtm2MRqJvWkqK9vNNL86Ew5D5hgXdCk+AiRzOhQxfprPYMea2Vx1Mkaq3VYHWmJBWc/m4aOKUSajhFu8KG7l8bc4IkgC+qQCYzr6pCUDlCaCEF1iQ3lItSkbJJmRBHKEOb85lsIJ/SZ0bhsMl8bc9z33zY+bwv2NezG/aKVGrny4ZTAI1BKkZN/60L0yzJihyKamEa442jjnvG1jzC2wEtd/0gCGWScfZsQWqDu97spbeq8jrc67U9xqlGTrWyyNsCW2lpu26cQWWRC8ufl5zBNRDFDSYKceBaJ2+sx1GPj3YYdJSlTt5JvxNyBg0BGfGqCTd0w4IXF3KP9IZRWWAKPaOZcil2MRZwYhWEd7p+CtKVAL93uW0sE+0C13+iFMnBUkFBJ2dZH+tWpywCRYcrVNvrBlsHe2XniwBwvQHUFgKaQAB8upFTK1xBWTh2S+CVyNed/fckAUrPDj4sI2NERGcyPC5Oi6r0fUPtcWvKRfA/yXx5A0iNWc6acTqd5wwSO3s8rOCjIwdczZmkmnjAf3UKhmtDnwRd9rbO5Hanom80re9Dk0W+z9E2+70b9iYvZ60pbw+cG4WqEQnr02RS8hKvU0CsYFoDMTzV4snqTKNrl0IeD+Fmjl7oDkcC4YQbZd2902qVL3WHHvW+p0WQ1B/rk8BPVRYVmrUQbqwPFCQlmTe3Zy+LpqbWYemhQJGVSiEiioVNCc7pHO6RyWLCoEQKwKHAoNleKtkG94hT/d0z+1RYpB/nbJ51BPihK5EMlXbw/Hu1SVaaDLOSL6p greg@mm ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINAX6pNx5mbwIa8X+GzktyNijfYmJUpgROFpRxSW9js0 greg@linode +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAEAQCXP9nxL5Hg1R1AtT78zJl+ObCDZsnWWAqAYhTVjpRvYpiTbODvCf2IImvUsLGMdgo/xdSSzNqQcK6+KZVeNbvRSsw0ssWw7ggYnhw/yyv/KDZwnqXsppeucicnwpQNvts154yOqAvuuMaOYCTTQoOVvecDdgtA3svIpfxL3vVB/Mq/Ns/NwoE9XKz3NBYlWytqDcvSwR6Les7RzbMIs6axSfMVNwm9w41dG1NqDMteLjKlQ8bFfrtWXZ4QHKlnEWatOgJIzbP1hU91JvvzfypjleGuE9EBCSayqhu9PuxJ1/yxMJKSMaXUl8SoPMLsPNr1ZS5ZNjkNCvZK4fI+CqyAXtbgeSGKIKqZhg9z6/fR9SG0l3Gh3Prtw+AEuE+Xzb99Bi4IAe8lTaL+lw+z+CmsXR+kcJ4nnNrmf1fnDsI4l1EctVGb3Yt3tutV6GjB4mDjIYKwNBxuIx8hlugmZIy3oEUGrh85o5wnXlJQzmhszS4eas99dj1L5tj5dF4O/ED7SyQI5e7V9Pb5AgolcvLLXcFzDuy43oU8kWvQJMMvbEIFr6qPXWmp8MvrSTucRQCCzWJVudhrYhodXA56tRoJvFIRs0s12p/YXzsmJbKxPiVwLGOlCd2CqbdM2rCqN2LkUeOAQitb/8wv4njRKZ4lgqhjyXnBtoD2Nm/NmuIERoUY9J21dOhc2tg0zLvH120xVKa+WN5HVOOG9LyKl7koyc8nqdSDKFhcN4joYmnZKfyJUJzQIhiQayEfvWfTNJiNVkMIE2OqQ4O64s/7QzOHeHSMzY4TCO7+5bK9ecOqPxCDHLHhO0xVA3/w4FscRkObjkQ6zv3UCFJTSbr4YkdUIk8OtRR2KN9y9txrt/OS1l1DigVyuYUdz/L83+Y8E8d3l0hq/S1YLMwlkCbHE8hm0HxlLuyTA3OqXizRxNk7w4ku9OC4+nHrj03i2apNG0Z/ojcGsJxSBLhPGlPWbDJ2h7YL+lkDZFitdhBZHjIQKC2dNoretA8zEzNk48Pi829NFRuXqjSsq3iOJ1sXP/lMAZvdzbZOQ8CrH5SWb9GDeWR0uh76RXzKXvv5UTtu1PpYj/BHToApc8kUAxpUh3ypjt6bS7XLYtk74PEZHD3HXbpBYBnMNPUp2ecDw6rxpLxq3rnzROriX4Uvy0sOx8Q13ZgrZwxLeEWImlK9qQT4SYytGGxt4vwG0R2B8zS1xNiNC/B8jnBrK4GwnYSuJwNMrJ8vk1u9gn1pCj51RslBsldVzVB30jxNU74iD/WQGJudJrUAYkQ5EpArKZK0GQfaRXM6VzsvyLBA02CZJkeIU0jUc6Q1Nms+C8teKrP8+EKXONT/igsLXwfLMiR2CqVP greg@nixos diff --git a/hosts/default.nix b/hosts/default.nix index 9311317..00c6e45 100644 --- a/hosts/default.nix +++ b/hosts/default.nix @@ -36,7 +36,15 @@ let ] ++ extraMods; }; in { - "2maccabees" = unstable { name = "2maccabees"; system = "aarch64-linux"; }; + "2maccabees" = unstable { + system = "aarch64-linux"; + name = "2maccabees"; + }; + genesis = unstable { + name = "genesis"; + gnome = true; + gui = true; + }; jude = unstable { name = "jude"; gnome = true; diff --git a/hosts/genesis/default.nix b/hosts/genesis/default.nix new file mode 100644 index 0000000..955543c --- /dev/null +++ b/hosts/genesis/default.nix @@ -0,0 +1,43 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page +# and in the NixOS manual (accessible by running ‘nixos-help’). + +{ config, pkgs, ... }: + +{ + imports = + [ # Include the results of the hardware scan. + ./dnsmasq.nix + ./hardware-configuration.nix + ./home-assistant.nix + ./networking.nix + ./vhosts.nix + ]; + + greg.home = true; + greg.gnome.enable = true; + + # Bootloader. + boot.loader.systemd-boot.enable = true; + boot.loader.efi.canTouchEfiVariables = true; + boot.loader.efi.efiSysMountPoint = "/boot/efi"; + + networking.hostName = "genesis"; # Define your hostname. + + # Enable sound with pipewire. + sound.enable = true; + hardware.pulseaudio.enable = false; + security.rtkit.enable = true; + services.pipewire = { + enable = true; + alsa.enable = true; + alsa.support32Bit = true; + pulse.enable = true; + # If you want to use JACK applications, uncomment this + #jack.enable = true; + + # use the example session manager (no others are packaged yet so this is enabled by default, + # no need to redefine it in your config for now) + #media-session.enable = true; + }; +} diff --git a/hosts/genesis/dnsmasq.nix b/hosts/genesis/dnsmasq.nix new file mode 100644 index 0000000..578cab0 --- /dev/null +++ b/hosts/genesis/dnsmasq.nix @@ -0,0 +1,80 @@ +{ config, pkgs, ... }: + +let + extraHosts = builtins.concatStringsSep "\n" [ + # Local hosts + "10.42.0.1 switch" + "10.42.1.1 router" + "10.42.1.2 2maccabees 2maccabees.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan" + "10.42.1.3 printer" + "10.42.1.4 chronicles nas" + "10.42.1.12 tv" + + # Tailscale hosts + "100.90.74.19 jude.me.ts" + "100.99.244.92 dns.me.ts 2maccabees.me.ts smart.me.ts jellyfin.me.ts" + "100.119.228.115 chronicles.me.ts nas.me.ts" + "100.115.57.8 linode.me.ts" + + # Dev hosts + "10.42.101.1 icdm.lan wiki.icdm.lan *.icdm.lan" + ]; + + extraConfig = builtins.concatStringsSep "\n" [ + ]; +in +{ + # Enable the service with its own configuration + services.dnsmasq = { + enable = true; + # Public AdGuard DNS servers + settings = { + domain = "thehellings.lan"; + dhcp-range = [ + # "eth0,10.42.0.1,10.42.1.255,255.255.0.0,static" + "eth0,10.42.2.1,10.42.2.255,255.255.0.0,12h" + "vlan66@eth0,192.168.66.3,192.168.66.150,255.255.255.0,12h" + "vlan67@eth0,192.168.67.3,192.168.67.150,12h" + ]; + dhcp-option = [ + "eth0,option:router,10.42.1.1" + "eth0,option:dns-server,10.42.1.2,1.1.1.1" + "eth0,option:domain-search,thehellings.lan" + + "vlan66@eth0,option:router,192.168.66.1" + "vlan66@eth0,option:dns-server,192.168.66.2" + + "vlan67@eth0,option:router,192.168.67.1" + "vlan67@eth0,option:dns-server,192.168.67.2" + ]; + expand-hosts = true; + log-dhcp = true; + log-queries = true; + addn-hosts = "/etc/adblock_hosts"; + server = [ + "94.140.14.14" + "94.140.15.15" + ]; + }; + extraConfig = "${extraConfig}"; + }; + environment.systemPackages = [ pkgs.curl ]; + + # Regularly update DNS block list + services.cron = { + enable = true; + systemCronJobs = [ + "* * * * * root ( ${pkgs.curl}/bin/curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts && systemctl restart dnsmasq ) 2>&1 > /var/log/adblock.log" + ]; + }; + + # Allow traffic through + networking.firewall = { + enable = true; + allowedTCPPorts = [ 53 ]; + allowedUDPPorts = [ 53 67 ]; + }; + + # Custom host addition + networking.extraHosts = "${extraHosts}"; +} diff --git a/hosts/genesis/hardware-configuration.nix b/hosts/genesis/hardware-configuration.nix new file mode 100644 index 0000000..e8f467d --- /dev/null +++ b/hosts/genesis/hardware-configuration.nix @@ -0,0 +1,42 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "nvme" "usb_storage" "sd_mod" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/a509426b-5af7-4d04-ac42-619674d932d9"; + fsType = "btrfs"; + options = [ "subvol=@" ]; + }; + + fileSystems."/boot/efi" = + { device = "/dev/disk/by-uuid/5AC6-50D7"; + fsType = "vfat"; + }; + + swapDevices = + [ { device = "/dev/disk/by-uuid/a57f8b82-dc0c-4906-8a48-56203d07556b"; } + ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.enp1s0.useDHCP = lib.mkDefault true; + # networking.interfaces.enp2s0.useDHCP = lib.mkDefault true; + # networking.interfaces.eth2.useDHCP = lib.mkDefault true; + + powerManagement.cpuFreqGovernor = lib.mkDefault "powersave"; + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/hosts/genesis/home-assistant.nix b/hosts/genesis/home-assistant.nix new file mode 100755 index 0000000..bb014d8 --- /dev/null +++ b/hosts/genesis/home-assistant.nix @@ -0,0 +1,90 @@ +{ config, pkgs, ... }: + +let + service_list = [ "podman-home-assistant.service" ]; +in +{ + virtualisation.podman.enable = true; + + services.home-assistant = { + enable = true; + configDir = "/var/lib/hass"; + package = (pkgs.home-assistant.override { + extraComponents = [ + "accuweather" + "calendar" + "cast" + "eufy" + "lovelace" + "nextcloud" + "smart_meter_texas" + "solaredge" + "tplink" + "wiz" + "zwave_js" + ]; + }).overrideAttrs (oldAttrs: { + doInstallCheck = false; + }); + + config = { + default_config = {}; + esphome = {}; # Get these things loaded, even if not configured + met = {}; + tts = [ { platform = "google_translate"; } ]; + http = { + use_x_forwarded_for = true; + trusted_proxies = [ "127.0.0.1" "::1" ]; + server_host = "127.0.0.1"; + }; + #"automation manual" = *nix config here* and so on + "automation ui" = "!include automations.yaml"; + "script ui" = "!include scripts.yaml"; + "scene ui" = "!include scenes.yaml"; + }; + }; + + # Although NixOS has a package for Home Assistant, it is not kept as up to date as the container and the upstream + # is very vocal about only supporting their own container or the HAOS deployments. So we deploy the container here + # and avoid any potential messes from that + virtualisation.oci-containers = { + backend = "podman"; + + # I have ZWave devices. The easiest way to connect to them is the zwavejs2mqtt service running, so we spin up + # its container and map the ZWave device into it + containers.zwave = { + image = "zwavejs/zwavejs2mqtt:latest"; + ports = [ "8091:8091" "3000:3000" ]; + volumes = [ "/var/lib/zwave:/usr/src/app/store" ]; + extraOptions = [ + "--device" "/dev/serial/by-id/usb-0658_0200-if00:/dev/zwave" + "--pull=newer" + ]; + }; + }; + + # Both of the above container need storage for their configuration and devices, but it is not created correctly by + # the container. So we add the creation of /var/lib/{zwave,hass} to the systemd Unit files + systemd.services = { + "podman-zwave".serviceConfig = { + StateDirectory = "zwave"; + StateDirectoryMode = pkgs.lib.mkForce "0777"; + }; + }; + + + greg.proxies."smart.thehellings.lan".target = "http://127.0.0.1:8123"; + + # Ensure that both ports are up and running. We keep 8123 directly open because we are on the LAN and sometimes want to connect + # directly for troubleshooting Nginx configuration + networking.firewall = { + enable = true; + allowedTCPPorts = [ 80 443 8091 8123 ]; + }; + + greg.backup.jobs.zwave = { + src = "/var/lib/zwave"; + dest = "zwave"; + user = "root"; + }; +} diff --git a/hosts/genesis/networking.nix b/hosts/genesis/networking.nix new file mode 100644 index 0000000..c2234f2 --- /dev/null +++ b/hosts/genesis/networking.nix @@ -0,0 +1,75 @@ +{ ... }: + +{ + greg.tailscale.enable = true; + + networking = { + # This value is deprecated, you now set it per interface + useDHCP = false; + defaultGateway = "10.42.1.1"; + # 100.100.100.100 is the tailscale DNS + nameservers = [ "100.100.100.100" "127.0.0.1" ]; + interfaces = { + eth0.ipv4.addresses = [ { + address = "10.42.1.2"; + prefixLength = 16; + } ]; + wlan0.useDHCP = true; + + vlan66.ipv4.addresses = [ { + address = "192.168.66.2"; + prefixLength = 24; + } ]; + }; + + vlans = { + vlan66 = { + id = 66; + interface = "eth0"; + }; + }; + }; + + # Open ports in the firewall. + # networking.firewall.allowedTCPPorts = [ ... ]; + # networking.firewall.allowedUDPPorts = [ ... ]; + # Or disable the firewall altogether. + # networking.firewall.enable = false; + + fileSystems."/media" = { + device = "10.42.1.4:/volume1/video/"; + fsType = "nfs"; + options = [ "ro" ]; + }; + + services.jellyfin = { + enable = true; + openFirewall = true; + }; + + greg.proxies."jellyfin.thehellings.lan".target = "http://localhost:8096"; + greg.proxies."jellyfin.me.ts".target = "http://localhost:8096"; + + ######### + # Blind service proxy behind the walls of the VPN + ######## + services._3proxy = { + enable = true; + services = [ { + type = "socks"; + auth = [ "strong" ]; + bindPort = 3128; + acl = [ { + rule = "allow"; + users = [ "greg" ]; + } ]; + } ]; + usersFile = "/run/agenix/3proxy"; + denyPrivate = false; + }; + age.secrets."3proxy" = { + file = ../../secrets/3proxy.age; + mode = "777"; + }; + networking.firewall.allowedTCPPorts = [ 3128 ]; +} diff --git a/hosts/genesis/vhosts.nix b/hosts/genesis/vhosts.nix new file mode 100644 index 0000000..1a2fd22 --- /dev/null +++ b/hosts/genesis/vhosts.nix @@ -0,0 +1,15 @@ +# Virtual hosts that don't seem to have any better place to live should go in here. +# There are others that are specific to their own purposese scattered about in the +# configuration in places where they more naturally live. This is more of a catchall +# for ones that do not have a better place to live +{ ... }: + +{ + greg.proxies."dns.thehellings.lan" = { + target = "http://127.0.0.1:8384/"; + path = "/sync/"; + }; + + # The module doesn't handle this + services.nginx.virtualHosts."dns.thehellings.lan".serverAliases = [ "dns" ]; +}