Merge branch 'main' of vm-gitlab.shire-zebra.ts.net:greg/nixos-config

This commit is contained in:
Greg Hellings
2025-10-15 00:01:35 -05:00
48 changed files with 782 additions and 13225 deletions
-9
View File
@@ -11,17 +11,11 @@ in
enable = true;
brews = [
"bitwarden-cli"
{
name = "colima";
restart_service = true;
}
"direnv"
"docker-compose"
{
name = "libvirt";
restart_service = true;
}
"mysql"
"nushell"
"poetry"
{
@@ -38,17 +32,14 @@ in
"bruno"
"chromium"
"dbeaver-community"
"docker"
"ghostty"
"firefox"
"microsoft-teams"
"mysqlworkbench"
"notunes"
"onlyoffice"
"pgadmin4"
"podman-desktop"
"tabby"
"twine"
"vagrant"
"virtualbox"
"visual-studio-code"
Generated
+296 -71
View File
@@ -31,11 +31,11 @@
"nixpkgs-unstable": "nixpkgs-unstable"
},
"locked": {
"lastModified": 1753079037,
"narHash": "sha256-c1MvgF+0dU75CmowEAez8oC+M9dtXZ5WKfDZzuFTkP0=",
"lastModified": 1757876184,
"narHash": "sha256-ezKJm8vzMb6bZf2lG+/s4AGhXtMvshEYBYqDT2PLtIU=",
"owner": "fort-nix",
"repo": "nix-bitcoin",
"rev": "5031e254696c72f36a7e41ddf70dacdf6bd83e46",
"rev": "0c961fa789d69ccd9503d2548dca1a9285acf2ff",
"type": "github"
},
"original": {
@@ -45,6 +45,28 @@
"type": "github"
}
},
"charts": {
"inputs": {
"flake-utils": "flake-utils_2",
"haumea": "haumea",
"nix-kube-generators": "nix-kube-generators",
"nixpkgs": "nixpkgs_2",
"poetry2nix": "poetry2nix"
},
"locked": {
"lastModified": 1759023284,
"narHash": "sha256-yYVUjuExr0v0bmM9qTGt0Chhw5eLHJLAFlqQOwVWVVM=",
"owner": "nix-community",
"repo": "nixhelm",
"rev": "b69e7f1e2dbdd67707f60ad02bf436325ce0b160",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixhelm",
"type": "github"
}
},
"darwin": {
"inputs": {
"nixpkgs": [
@@ -74,11 +96,11 @@
]
},
"locked": {
"lastModified": 1755275010,
"narHash": "sha256-lEApCoWUEWh0Ifc3k1JdVjpMtFFXeL2gG1qvBnoRc2I=",
"lastModified": 1758805352,
"narHash": "sha256-BHdc43Lkayd+72W/NXRKHzX5AZ+28F3xaUs3a88/Uew=",
"owner": "lnl7",
"repo": "nix-darwin",
"rev": "7220b01d679e93ede8d7b25d6f392855b81dd475",
"rev": "c48e963a5558eb1c3827d59d21c5193622a1477c",
"type": "github"
},
"original": {
@@ -166,11 +188,11 @@
"nixpkgs-lib": "nixpkgs-lib"
},
"locked": {
"lastModified": 1754487366,
"narHash": "sha256-pHYj8gUBapuUzKV/kN/tR3Zvqc7o6gdFB9XKXIp1SQ8=",
"lastModified": 1756770412,
"narHash": "sha256-+uWLQZccFHwqpGqr2Yt5VsW/PbeJVTn9Dk6SHWhNRPw=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "af66ad14b28a127c5c0f3bbb298218fc63528a18",
"rev": "4524271976b625a4a605beefd893f270620fd751",
"type": "github"
},
"original": {
@@ -187,11 +209,11 @@
]
},
"locked": {
"lastModified": 1754487366,
"narHash": "sha256-pHYj8gUBapuUzKV/kN/tR3Zvqc7o6gdFB9XKXIp1SQ8=",
"lastModified": 1756770412,
"narHash": "sha256-+uWLQZccFHwqpGqr2Yt5VsW/PbeJVTn9Dk6SHWhNRPw=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "af66ad14b28a127c5c0f3bbb298218fc63528a18",
"rev": "4524271976b625a4a605beefd893f270620fd751",
"type": "github"
},
"original": {
@@ -251,13 +273,30 @@
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"id": "flake-utils",
"type": "indirect"
}
},
"flake-utils_3": {
"inputs": {
"systems": "systems_4"
},
"locked": {
"lastModified": 1726560853,
"narHash": "sha256-X6rJYSESBVr3hBoH0WbKE5KvhPU5bloyZ2L4K60/fPQ=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "c1dfcf08411b08f6b8615f7d8971a2bfa81d5e8a",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"flake-utils_3": {
"flake-utils_4": {
"inputs": {
"systems": "systems_6"
},
@@ -275,6 +314,24 @@
"type": "github"
}
},
"flake-utils_5": {
"inputs": {
"systems": "systems_9"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"gitignore": {
"inputs": {
"nixpkgs": [
@@ -296,6 +353,28 @@
"type": "github"
}
},
"haumea": {
"inputs": {
"nixpkgs": [
"charts",
"nixpkgs"
]
},
"locked": {
"lastModified": 1685133229,
"narHash": "sha256-FePm/Gi9PBSNwiDFq3N+DWdfxFq0UKsVVTJS3cQPn94=",
"owner": "nix-community",
"repo": "haumea",
"rev": "34dd58385092a23018748b50f9b23de6266dffc2",
"type": "github"
},
"original": {
"owner": "nix-community",
"ref": "v0.2.2",
"repo": "haumea",
"type": "github"
}
},
"hmunstable": {
"inputs": {
"nixpkgs": [
@@ -303,11 +382,11 @@
]
},
"locked": {
"lastModified": 1755442500,
"narHash": "sha256-RHK4H6SWzkAtW/5WBHsyugaXJX25yr5y7FAZznxcBJs=",
"lastModified": 1759043321,
"narHash": "sha256-Efi3THvsIS6Qd97s52/PSSHWybDlSbtUZXP8l3AR9Ps=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "d2ffdedfc39c591367b1ddf22b4ce107f029dcc3",
"rev": "c75fd8e300b79502b8eecdacd8a426b12fadb460",
"type": "github"
},
"original": {
@@ -342,14 +421,14 @@
"inputs": {
"flake-compat": "flake-compat",
"gitignore": "gitignore",
"nixpkgs": "nixpkgs_2"
"nixpkgs": "nixpkgs_3"
},
"locked": {
"lastModified": 1755446520,
"narHash": "sha256-I0Ok1OGDwc1jPd8cs2VvAYZsHriUVFGIUqW+7uSsOUM=",
"lastModified": 1758108966,
"narHash": "sha256-ytw7ROXaWZ7OfwHrQ9xvjpUWeGVm86pwnEd1QhzawIo=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "4b04db83821b819bbbe32ed0a025b31e7971f22e",
"rev": "54df955a695a84cd47d4a43e08e1feaf90b1fd9b",
"type": "github"
},
"original": {
@@ -372,27 +451,49 @@
]
},
"locked": {
"lastModified": 1748294338,
"narHash": "sha256-FVO01jdmUNArzBS7NmaktLdGA5qA3lUMJ4B7a05Iynw=",
"lastModified": 1754860581,
"narHash": "sha256-EM0IE63OHxXCOpDHXaTyHIOk2cNvMCGPqLt/IdtVxgk=",
"owner": "NuschtOS",
"repo": "ixx",
"rev": "cc5f390f7caf265461d4aab37e98d2292ebbdb85",
"rev": "babfe85a876162c4acc9ab6fb4483df88fa1f281",
"type": "github"
},
"original": {
"owner": "NuschtOS",
"ref": "v0.0.8",
"ref": "v0.1.1",
"repo": "ixx",
"type": "github"
}
},
"nix-github-actions": {
"inputs": {
"nixpkgs": [
"charts",
"poetry2nix",
"nixpkgs"
]
},
"locked": {
"lastModified": 1729742964,
"narHash": "sha256-B4mzTcQ0FZHdpeWcpDYPERtyjJd/NIuaQ9+BV1h+MpA=",
"owner": "nix-community",
"repo": "nix-github-actions",
"rev": "e04df33f62cdcf93d73e9a04142464753a16db67",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nix-github-actions",
"type": "github"
}
},
"nix-hardware": {
"locked": {
"lastModified": 1755330281,
"narHash": "sha256-aJHFJWP9AuI8jUGzI77LYcSlkA9wJnOIg4ZqftwNGXA=",
"lastModified": 1758663926,
"narHash": "sha256-6CFdj7Xs616t1W4jLDH7IohAAvl5Dyib3qEv/Uqw1rk=",
"owner": "nixos",
"repo": "nixos-hardware",
"rev": "3dac8a872557e0ca8c083cdcfc2f218d18e113b0",
"rev": "170ff93c860b2a9868ed1e1102d4e52cb3d934e1",
"type": "github"
},
"original": {
@@ -401,6 +502,21 @@
"type": "github"
}
},
"nix-kube-generators": {
"locked": {
"lastModified": 1729269463,
"narHash": "sha256-8jDDpC99fYl5CSHjZyPwb5PK7nQSknhkpfe8+DXI910=",
"owner": "farcaller",
"repo": "nix-kube-generators",
"rev": "2be4f3cb99e179d9f94e6c8723862421437f8efb",
"type": "github"
},
"original": {
"owner": "farcaller",
"repo": "nix-kube-generators",
"type": "github"
}
},
"nixlib": {
"locked": {
"lastModified": 1736643958,
@@ -439,11 +555,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1752866191,
"narHash": "sha256-NV4S2Lf2hYmZQ3Qf4t/YyyBaJNuxLPyjzvDma0zPp/M=",
"lastModified": 1757545623,
"narHash": "sha256-mCxPABZ6jRjUQx3bPP4vjA68ETbPLNz9V2pk9tO7pRQ=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "f01fe91b0108a7aff99c99f2e9abbc45db0adc2a",
"rev": "8cd5ce828d5d1d16feff37340171a98fc3bf6526",
"type": "github"
},
"original": {
@@ -455,11 +571,11 @@
},
"nixpkgs-lib": {
"locked": {
"lastModified": 1753579242,
"narHash": "sha256-zvaMGVn14/Zz8hnp4VWT9xVnhc8vuL3TStRqwk22biA=",
"lastModified": 1754788789,
"narHash": "sha256-x2rJ+Ovzq0sCMpgfgGaaqgBSwY+LST+WbZ6TytnT9Rk=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "0f36c44e01a6129be94e3ade315a5883f0228a6e",
"rev": "a73b9c743612e4244d865a2fdee11865283c04e6",
"type": "github"
},
"original": {
@@ -485,11 +601,11 @@
},
"nixpkgs-unstable": {
"locked": {
"lastModified": 1752900028,
"narHash": "sha256-dPALCtmik9Wr14MGqVXm+OQcv7vhPBXcWNIOThGnB/Q=",
"lastModified": 1757584362,
"narHash": "sha256-XeTX/w16rUNUNBsfaOVCDoMMa7Xu7KvIMT7tn1zIEcg=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "6b4955211758ba47fac850c040a27f23b9b4008f",
"rev": "d33e926c80e6521a55da380a4c4c44a7462af405",
"type": "github"
},
"original": {
@@ -516,11 +632,27 @@
},
"nixpkgs_2": {
"locked": {
"lastModified": 1754340878,
"narHash": "sha256-lgmUyVQL9tSnvvIvBp7x1euhkkCho7n3TMzgjdvgPoU=",
"lastModified": 1739020877,
"narHash": "sha256-mIvECo/NNdJJ/bXjNqIh8yeoSjVLAuDuTUzAo7dzs8Y=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "cab778239e705082fe97bb4990e0d24c50924c04",
"rev": "a79cfe0ebd24952b580b1cf08cd906354996d547",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_3": {
"locked": {
"lastModified": 1758029226,
"narHash": "sha256-TjqVmbpoCqWywY9xIZLTf6ANFvDCXdctCjoYuYPYdMI=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "08b8f92ac6354983f5382124fef6006cade4a1c1",
"type": "github"
},
"original": {
@@ -530,13 +662,13 @@
"type": "github"
}
},
"nixpkgs_3": {
"nixpkgs_4": {
"locked": {
"lastModified": 1755186698,
"narHash": "sha256-wNO3+Ks2jZJ4nTHMuks+cxAiVBGNuEBXsT29Bz6HASo=",
"lastModified": 1758690382,
"narHash": "sha256-NY3kSorgqE5LMm1LqNwGne3ZLMF2/ILgLpFr1fS4X3o=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "fbcf476f790d8a217c3eab4e12033dc4a0f6d23c",
"rev": "e643668fd71b949c53f8626614b21ff71a07379d",
"type": "github"
},
"original": {
@@ -546,7 +678,7 @@
"type": "github"
}
},
"nixpkgs_4": {
"nixpkgs_5": {
"locked": {
"lastModified": 1744868846,
"narHash": "sha256-5RJTdUHDmj12Qsv7XOhuospjAjATNiTMElplWnJE9Hs=",
@@ -564,11 +696,11 @@
},
"nixunstable": {
"locked": {
"lastModified": 1755186698,
"narHash": "sha256-wNO3+Ks2jZJ4nTHMuks+cxAiVBGNuEBXsT29Bz6HASo=",
"lastModified": 1758690382,
"narHash": "sha256-NY3kSorgqE5LMm1LqNwGne3ZLMF2/ILgLpFr1fS4X3o=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "fbcf476f790d8a217c3eab4e12033dc4a0f6d23c",
"rev": "e643668fd71b949c53f8626614b21ff71a07379d",
"type": "github"
},
"original": {
@@ -585,14 +717,14 @@
"nixunstable"
],
"nuschtosSearch": "nuschtosSearch",
"systems": "systems_4"
"systems": "systems_7"
},
"locked": {
"lastModified": 1755095763,
"narHash": "sha256-cFwtMaONA4uKYk/rBrmFvIAQieZxZytoprzIblTn1HA=",
"lastModified": 1759016999,
"narHash": "sha256-UhQmUPSWYpKJQutTzy9TKiRBMg/qVJn6AoNsFR+5Zmc=",
"owner": "nix-community",
"repo": "nixvim",
"rev": "ecc7880e00a2a735074243d8a664a931d73beace",
"rev": "4cec67651a6dfdab9a79e68741282e3be8231a61",
"type": "github"
},
"original": {
@@ -605,14 +737,14 @@
"nurpkgs": {
"inputs": {
"flake-parts": "flake-parts_3",
"nixpkgs": "nixpkgs_3"
"nixpkgs": "nixpkgs_4"
},
"locked": {
"lastModified": 1755452770,
"narHash": "sha256-oc8xrqvVIoDxbfTlbkE1XQ7O88TgNZn5FOZKLiuIEmg=",
"lastModified": 1759077554,
"narHash": "sha256-W4ZnOzeVSbokayX7Hz+aIOemXXm/lUZRB4S/Bptn6XM=",
"owner": "nix-community",
"repo": "NUR",
"rev": "eab62298402c7cdfdefda647a4046befa3a84051",
"rev": "669ab83f6fe35cae4bee00e9a66e79b1936612cd",
"type": "github"
},
"original": {
@@ -623,7 +755,7 @@
},
"nuschtosSearch": {
"inputs": {
"flake-utils": "flake-utils_2",
"flake-utils": "flake-utils_4",
"ixx": "ixx",
"nixpkgs": [
"nixvimunstable",
@@ -631,11 +763,11 @@
]
},
"locked": {
"lastModified": 1754301638,
"narHash": "sha256-aRgzcPDd2axHFOuMlPLuzmDptUM2JU8mUL3jfgbBeyc=",
"lastModified": 1758662783,
"narHash": "sha256-igrxT+/MnmcftPOHEb+XDwAMq3Xg1Xy7kVYQaHhPlAg=",
"owner": "NuschtOS",
"repo": "search",
"rev": "a60091045273484c040a91f5c229ba298f8ecc27",
"rev": "7d4c0fc4ffe3bd64e5630417162e9e04e64b27a4",
"type": "github"
},
"original": {
@@ -644,6 +776,31 @@
"type": "github"
}
},
"poetry2nix": {
"inputs": {
"flake-utils": "flake-utils_3",
"nix-github-actions": "nix-github-actions",
"nixpkgs": [
"charts",
"nixpkgs"
],
"systems": "systems_5",
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1738741221,
"narHash": "sha256-UiTOA89yQV5YNlO1ZAp4IqJUGWOnTyBC83netvt8rQE=",
"owner": "nix-community",
"repo": "poetry2nix",
"rev": "be1fe795035d3d36359ca9135b26dcc5321b31fb",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "poetry2nix",
"type": "github"
}
},
"proxmox": {
"inputs": {
"flake-compat": "flake-compat_2",
@@ -652,11 +809,11 @@
"utils": "utils"
},
"locked": {
"lastModified": 1754428470,
"narHash": "sha256-Sxf8gf+vfGeFaJMW3D+8pwH/+WwYTQOg47Lrm42+kTc=",
"lastModified": 1758650077,
"narHash": "sha256-ZeRtJimtk0Faiq7DPZEQNGipda3TaR4QXp0TAzu934Q=",
"owner": "SaumonNet",
"repo": "proxmox-nixos",
"rev": "6faed2845ef5f0bb05c9519b75097bbe7fb39327",
"rev": "ce8768f43b4374287cd8b88d8fa9c0061e749d9a",
"type": "github"
},
"original": {
@@ -669,6 +826,7 @@
"inputs": {
"agenix": "agenix",
"btc": "btc",
"charts": "charts",
"darwin": "darwin_2",
"flake-parts": "flake-parts",
"hmunstable": "hmunstable",
@@ -773,9 +931,76 @@
"type": "github"
}
},
"systems_7": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_8": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"systems_9": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"treefmt-nix": {
"inputs": {
"nixpkgs": [
"charts",
"poetry2nix",
"nixpkgs"
]
},
"locked": {
"lastModified": 1730120726,
"narHash": "sha256-LqHYIxMrl/1p3/kvm2ir925tZ8DkI0KA10djk8wecSk=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "9ef337e492a5555d8e17a51c911ff1f02635be15",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "treefmt-nix",
"type": "github"
}
},
"utils": {
"inputs": {
"systems": "systems_5"
"systems": "systems_8"
},
"locked": {
"lastModified": 1710146030,
@@ -793,15 +1018,15 @@
},
"vsext": {
"inputs": {
"flake-utils": "flake-utils_3",
"nixpkgs": "nixpkgs_4"
"flake-utils": "flake-utils_5",
"nixpkgs": "nixpkgs_5"
},
"locked": {
"lastModified": 1755396877,
"narHash": "sha256-92gZRDz3zEsodraI0ZxPzZrpjSqc2qjxTW9HOflzKFw=",
"lastModified": 1759024939,
"narHash": "sha256-4HEtZ+hVr8c/rbr1xXb9yq7YA/Ued5KrixAvhuIAg/4=",
"owner": "nix-community",
"repo": "nix-vscode-extensions",
"rev": "0cf076c0bafbe7cbd33a3b7377ed24827674e8be",
"rev": "6db4b0a9395b1002b6d18c6967d4cd2566e8bd16",
"type": "github"
},
"original": {
@@ -818,11 +1043,11 @@
]
},
"locked": {
"lastModified": 1755261305,
"narHash": "sha256-EOqCupB5X5WoGVHVcfOZcqy0SbKWNuY3kq+lj1wHdu8=",
"lastModified": 1758785683,
"narHash": "sha256-mRn51IeEBXeNh5a6xNLylk4PKBX0s/QQxgkEbYoPq/w=",
"owner": "nix-community",
"repo": "NixOS-WSL",
"rev": "203a7b463f307c60026136dd1191d9001c43457f",
"rev": "1bfb978f2f6261b6086e04af17f9418e1fe36d70",
"type": "github"
},
"original": {
+11
View File
@@ -21,6 +21,9 @@
btc = {
url = "github:fort-nix/nix-bitcoin/release";
};
charts = {
url = "github:nix-community/nixhelm";
};
darwin = {
url = "github:lnl7/nix-darwin/master";
inputs.nixpkgs.follows = "nixunstable";
@@ -63,12 +66,20 @@
pkgs = prev;
})
);
charts_overlay = (
_f: _p: {
chartsDerivations = top.charts.chartsDerivations."${_p.stdenv.hostPlatform.system}";
kubelib = top.nix-kube-generators.lib;
}
);
overlays = [
top.agenix.overlays.default
charts_overlay
local_overlay
packages_overlay
top.nurpkgs.overlays.default
top.vsext.overlays.default
top.nixvimunstable.overlays.default
];
in
+1 -33
View File
@@ -38,11 +38,7 @@ in
path add /run/current-system/sw/bin
path add ${config.home.homeDirectory}/.nix-profile/bin
def --env unlock [] {
if "BW_SESSION" not-in $env {
$env.BW_SESSION = ^bw unlock --raw
}
}
source ${./nushell/functions.nu}
def --env vpn [] {
unlock
@@ -51,34 +47,6 @@ in
let otp = ^bw get totp 10371487-7f40-4b08-9a45-b33e00de318b
osascript ${vpn} $username $"($password)($otp)"
}
def rebuild [] {
if (uname | get operating-system) == "Darwin" {
sudo darwin-rebuild switch
} else {
let hostname = uname | get nodename
let build = ^nom build $"/etc/nixos#nixosConfigurations.($hostname).config.system.build.toplevel" | complete
if build.exit_code == 0 {
nvd diff /run/current-system result
sudo nixos-rebuild switch
}
}
}
def deploy [ $host: string, $build: string = "" ] {
mut buildhost = $build
if $build == "" {
$buildhost = $host
}
if $buildhost == "linode" {
$buildhost = "isaiah"
}
nixos-rebuild switch --use-remote-sudo --use-substitutes --target-host $host --build-host $buildhost
}
def ff [ $file: string ] {
ls **/* | where name =~ $file
}
'';
settings = {
buffer_editor = lib.getExe config.programs.nixvim.package;
+57
View File
@@ -0,0 +1,57 @@
# vim: set filetype=nushell :
let servers = [isaiah jeremiah zeke genesis vm-gitlab vm-jellyfin]
def par-map [ items: list, c: closure ] {
let results = $items | par-each -k $c
$items | enumerate | reduce -f {} {|e, a| $a | upsert $e.item { $results | get $e.index }}
}
def --env unlock [] {
if "BW_SESSION" not-in $env {
$env.BW_SESSION = ^bw unlock --raw
}
}
def rebuild [] {
if (uname | get operating-system) == "Darwin" {
sudo darwin-rebuild switch
} else {
let hostname = uname | get nodename
let build = ^nom build --keep-going $"/etc/nixos#nixosConfigurations.($hostname).config.system.build.toplevel"
if $env.LAST_EXIT_CODE == 0 {
nvd diff /run/current-system result
run0 nixos-rebuild switch
} else {
print "Error during build"
}
}
}
def deploy [ $host: string, $build: string = "" ] {
mut buildhost = $build
if $build == "" {
$buildhost = $host
}
if $buildhost == "linode" or $buildhost == "genesis" {
$buildhost = "isaiah"
}
nixos-rebuild switch --sudo --use-substitutes --target-host $host --build-host $buildhost
}
def ff [ $file: string ] {
ls **/* | where name =~ $file
}
def update_all [] {
par-map $servers {|e| deploy $e | complete} | explore
}
def bake [template: string] {
let copier = "~/.copier-templates" | path expand
if not ($copier | path exists) {
git clone srcpub:greg/copier-templates.git $copier
}
let srcdir = [$copier $template] | path join
print $srcdir
copier copy $srcdir .
}
+1 -1
View File
@@ -25,13 +25,13 @@
nixup = "nix flake lock update";
nixcopy = "nix copy --to \"s3://binary-cache/?profile=default&endpoint=nas.home%3A9000&scheme=http\"";
r = "run0";
s = "nix run \".#runserver\"";
updateScript = "nix-shell maintainers/scripts/update.nix --argstr package";
# General
k = "kubectl";
kn = "kubectl get nodes -o wide";
kp = "kubectl get pods -o wide";
s = "lazyssh";
win = "sudo virsh start win10";
yaml2js = "python -c 'import sys, yaml, json; json.dump(yaml.load(sys.stdin), sys.stdout, indent=4)'";
z = "zeditor .";
+6 -1
View File
@@ -9,9 +9,9 @@
};
programs.ssh = {
enable = true;
serverAliveInterval = 60;
includes = [ "config.local" ];
enableDefaultConfig = false;
matchBlocks =
let
@@ -27,6 +27,11 @@
"*" = {
dynamicForwards = [ { port = 10240; } ];
serverAliveInterval = 60;
extraOptions = {
LogLevel = "error";
SetEnv = "TERM=xterm-256color";
};
};
"10.42.1.4" = lib.hm.dag.entryBefore [ "10.42.*" ] nas;
+3 -1
View File
@@ -4,11 +4,13 @@
with pkgs;
[
dig
dnsutils
jqp
kubernetes-helm
iamb
lazyssh
rainfrog
tenere
uv
wiki-tui
]
++ (lib.optionals pkgs.stdenv.hostPlatform.isLinux [
+1 -2
View File
@@ -115,11 +115,11 @@
lsp = {
enable = true;
servers = {
ansiblels.enable = true;
cmake.enable = true;
gopls.enable = true;
html.enable = true;
nixd.enable = true;
nushell.enable = true;
pylsp.enable = true;
pyright.enable = true;
rust_analyzer = {
@@ -149,7 +149,6 @@
extraConfigVim = builtins.readFile ./extra.vimrc;
extraPlugins = with pkgs.vimPlugins; [
bufexplorer
context-vim
vim-indent-guides
];
+12 -2
View File
@@ -1,7 +1,8 @@
{
config,
pkgs,
lib,
nixvim,
pkgs,
...
}:
@@ -10,7 +11,16 @@
fonts.fontconfig.enable = true;
home.packages = with pkgs.nerd-fonts; [ hack ];
programs.nixvim = (import ./config.nix { inherit config pkgs lib; }) // {
programs.nixvim =
(import ./config.nix {
inherit
config
nixvim
pkgs
lib
;
})
// {
enable = true;
};
}
+1 -1
View File
@@ -59,7 +59,7 @@ local lspconfig = require('lspconfig')
-- capabilities = capabilities
--}
--lspconfig.pyright.setup { capabilities = capabilities }
lspconfig.ansiblels.setup { capabilities = capabilities }
--lspconfig.ansiblels.setup { capabilities = capabilities }
--lspconfig.jedi_language_server.setup { capabilities }
-- ======================================================================
+1 -1
View File
@@ -88,7 +88,7 @@ lua <<EOF
-- capabilities = capabilities
--}
--lspconfig.pyright.setup { capabilities = capabilities }
lspconfig.ansiblels.setup { capabilities = capabilities }
--lspconfig.ansiblels.setup { capabilities = capabilities }
lspconfig.jedi_language_server.setup { capabilities = capabilities }
EOF
" Set filetype to the way I want it
+2 -1
View File
@@ -33,7 +33,7 @@ in
{
"MacBook-Pro.local" = user "aarch64-darwin" "ivr" "gregory.hellings";
"MacBook-Prolocal.local" = user "aarch64-darwin" "ivr" "gregory.hellings";
"jude.thehellings.lan" = user "aarch64-darwin" "ivr" "gregory.hellings"; # This is annoying, but DNS is a pain for the shared docking station
genesis = greg "genesis";
exodus = greg "exodus";
zeke = greg "zeke";
isaiah = greg "isaiah";
@@ -41,4 +41,5 @@ in
linode = greg "linode";
hosea = greg "hosea";
vm-gitlab = greg "vm-gitlab";
vm-jellyfin = greg "vm-jellyfin";
}
+2
View File
@@ -13,12 +13,14 @@
cargo
freeciv
gimp
gnucash
k9s
kdePackages.kdenlive
kubernetes-helm
kubectl
kubectl-cnpg
mumble
pre-commit
wineWowPackages.stable
];
}
+13
View File
@@ -36,6 +36,7 @@ in
just
k9s
kubectl
mariadb
minikube
mise
nil
@@ -81,6 +82,18 @@ in
};
};
};
ssh.matchBlocks = lib.listToAttrs (lib.map (key: { name = "${key}.ivrtechnology.com"; value = {}; }) [
"apidev1"
"asdev1"
"agidev1"
"kdev1"
"kdev2"
"kdev3"
"webdev4"
"webdev5"
"web4"
]);
tmux.shell = (lib.getExe x);
};
}
+1
View File
@@ -36,6 +36,7 @@ in
efibootmgr
findutils
file
gcc-tune
git
gnupatch
hms # My own home manager switcher
+4 -1
View File
@@ -35,7 +35,10 @@
};
};
nix.settings.extra-platforms = config.boot.binfmt.emulatedSystems;
nix.settings = {
extra-platforms = config.boot.binfmt.emulatedSystems;
system-features = [ "gccarch-x86-64-v3" ];
};
networking = {
hostName = "exodus";
+1 -98
View File
@@ -2,10 +2,9 @@
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{ config, pkgs, ... }:
{ pkgs, ... }:
let
dashy_port = "8080";
speedtest_port = "19472";
in
{
@@ -22,7 +21,6 @@ in
proxies = {
"speed.home".target = "http://localhost:${speedtest_port}";
"speedtest.thehellings.lan".target = "http://localhost:${speedtest_port}";
"dashy.home".target = "http://localhost:${dashy_port}";
};
};
@@ -41,102 +39,7 @@ in
networking.hostName = "genesis"; # Define your hostname.
services = {
dashy = {
enable = true;
settings = {
appConfig = {
enableFontAwesome = true;
statusCheck = true;
statusCheckInterval = 20;
theme = "callisto";
};
pageInfo = {
description = "Hellings Lab";
navLinks = [
{
path = "/";
title = "Home";
}
{
path = "http://speed.home";
title = "Local Speedtest";
}
];
};
sections = [
{
name = "Hosting";
displayData = {
sortBy = "alphabetical";
rows = 1;
cols = 1;
collapsed = false;
hideForGusts = false;
};
items = [
{
title = "Romans";
description = "Core Proxmox";
icon = "favicon";
url = "https://10.42.1.1:8006";
target = "newtab";
statusCheckAllowInsecure = true;
}
{
title = "Isaiah";
description = "Isaiah Proxmox";
icon = "favicon";
url = "https://isaiah.thehellings.lan:8006";
target = "newtab";
statusCheckAllowInsecure = true;
}
{
title = "Linode";
icon = "favicon";
url = "https://login.linode.com/login";
target = "newtab";
}
];
}
{
name = "Services";
displayData = {
sortBy = "alphabetical";
rows = 1;
cols = 1;
collapsed = false;
hideForGusts = false;
};
items = [
{
title = "Jellyfin";
description = "Home Jellyfin Server";
icon = "favicon";
url = "http://jellyfin.home";
target = "newtab";
}
{
title = "Speedtest";
description = "Local Speedtest";
icon = "favicon";
url = "http://speed.home";
target = "newtab";
}
];
}
];
};
};
};
virtualisation.oci-containers.containers = {
dashy = {
image = "lissy93/dashy:latest";
hostname = "dashy";
ports = [ "${dashy_port}:${dashy_port}" ];
volumes = [ "${config.services.dashy.finalDrv}/conf.yml:/app/user-data/conf.yml" ];
};
speedtest = {
image = "ghcr.io/librespeed/speedtest";
hostname = "speedtest";
+6 -3
View File
@@ -17,6 +17,7 @@
# 11 - old jude
10.42.1.12 tv
10.42.1.13 zeke zeke.thehellings.lan
10.42.1.14 nas1 nas1.thehellings.lan
# VMs
10.42.4.1 matrix matrix.thehellings.lan
@@ -28,20 +29,22 @@
# IPMI
10.42.100.6 isaiahbmc isaiahbmc.thehellings.lan
10.42.100.14 nas1bmc nas1bmc.thehellings.lan
# Tailscale hosts
100.119.228.115 chronicles.home nas.home chronicles.shire-zebra.ts.net
100.88.91.27 dns.home
100.80.99.48 exodus.home
100.88.91.27 genesis.home smart.home zwave.home nixcache.home gitcache.home dashy.home uptime.home speed.home
100.91.131.66 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan
100.117.28.111 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan
100.68.203.1 hosea.home hosea.shire-zebra.ts.net
100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes postgres.kubernetes longhorn.kubernetes
100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes immich.kubernetes
100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes longhorn.kubernetes
100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes immich.kubernetes postgres.kubernetes
100.90.74.19 zeke.home
100.115.57.8 linode.home
100.65.5.38 matrix.home matrix.shire-zebra.ts.net
100.127.55.22 jellyfin.home
100.114.187.61 nas1.home nas1.shire-zebra.ts.net
# Dev hosts
10.42.101.1 icdm.lan wiki.icdm.lan *.icdm.lan
-1
View File
@@ -33,6 +33,5 @@
greg.backup.jobs.nextcloud-bkup = {
src = "/var/lib/nextcloud";
dest = "nextcloud-backup";
id = "nextcloud-backup";
};
}
-1
View File
@@ -54,6 +54,5 @@
greg.backup.jobs.greg-postgresql-backup = {
src = config.services.postgresqlBackup.location;
dest = "linode-postgres";
id = "linode-postgres";
};
}
+36 -10
View File
@@ -57,7 +57,7 @@ in
backup.jobs.nas-backup = {
src = "/var/gitlab/state/backup/";
dest = "gitlab";
id = "container-gitlab";
id = "gitlab";
};
home = true;
tailscale.enable = true;
@@ -72,14 +72,6 @@ in
};
services = {
# Fetch the SSL certificates for nginx to use
cron = {
enable = true;
systemCronJobs = [
"0 0 1 */2 * cd /etc/certs && tailscale cert vm-gitlab.shire-zebra.ts.net && chown nginx * && systemctl reload nginx"
];
};
gitlab = {
enable = true;
backup = {
@@ -228,7 +220,30 @@ in
# Do not start nginx until we have tailscaled up and running, so it can bind
# to the 100.* addresses
systemd.services = {
systemd = {
services = {
certRefresh =
let
script = pkgs.writeShellApplication {
name = "cert-refresh";
runtimeInputs = [ pkgs.tailscale ];
text = ''
cd /etc/certs
tailscale cert vm-gitlab.shire-zebra.ts.net
chown nginx ./*
systemctl reload nginx
'';
};
in
{
script = lib.getExe script;
serviceConfig = {
Type = "oneshot";
User = "root";
};
};
nginx = rec {
after = [ "network-online.target" ];
requires = [ "network-online.target" ];
@@ -240,5 +255,16 @@ in
};
tailscaled.partOf = [ "network-online.target" ];
};
timers = {
"cert-refresh" = {
wantedBy = [ "cert-refresh.service" ];
timerConfig = {
OnCalendar = "monthly";
Persistent = true;
};
};
};
};
system.stateVersion = lib.mkForce "24.11";
}
+3 -3
View File
@@ -30,17 +30,17 @@
fileSystems = {
"/music" = {
device = "10.42.1.4:/volume1/music";
device = "nas1.shire-zebra.ts.net:/mnt/all/music";
fsType = "nfs";
options = [ "ro" ];
};
"/photo" = {
device = "10.42.1.4:/volume1/photo";
device = "nas1.shire-zebra.ts.net:/mnt/all/photos";
fsType = "nfs";
options = [ "ro" ];
};
"/video" = {
device = "10.42.1.4:/volume1/video/";
device = "nas1.shire-zebra.ts.net:/mnt/all/video/";
fsType = "nfs";
options = [ "ro" ];
};
+1 -21
View File
@@ -6,26 +6,6 @@ SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )"
# Change to the script directory
cd "$SCRIPT_DIR"
# First, label the nodes to control Longhorn rollout
for n in isaiah jeremiah zeke; do
kubectl label nodes "${n}" "node.longhorn.io/create-default-disk=config"
done
# Now, configure longhorn settings for each node
kubectl annotate nodes --overwrite isaiah 'node.longhorn.io/default-disks-config=[
{ "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]}
]'
kubectl annotate nodes --overwrite jeremiah 'node.longhorn.io/default-disks-config=[
{ "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]}
]'
kubectl annotate nodes --overwrite zeke 'node.longhorn.io/default-disks-config=[
{ "path": "/var/lib/longhorn", "allowScheduling" : trues, "tags": ["ssd", "fast"]}
]'
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.18.2/cert-manager.yaml
kubectl apply -f helm/flux.yaml
sleep 5
kubectl apply -f helm/kyverno.yaml
sleep 15
kubectl apply -k helm
sleep 5
# https://cloudnative-pg.io
@@ -36,7 +16,7 @@ helm upgrade --install cnpg \
-f values/cnpg.yaml \
--wait
sleep 5
./tailscale/apply.sh
kubectl apply -k .
./immich/apply.sh
./tailscale/apply.sh
+12
View File
@@ -0,0 +1,12 @@
It should not be necessary to deploy these files as, ostensibly, they are
configured to be auto-deployed on the nodes at startup time.
nodes.yaml contains things like annotations for the nodes and other similar
hubub that makes the code deploy in a friendly manner.
operator-oauth.yaml includes the secrets that need to be defined before the
tailscale operator can be deployed. But, of course, it also needs things like
the external-secrets helm chart before it is fully deployed in the proper
manner. There is a little bit of a chicken and egg type of problem here, but
if you just keep applying everyting, over and over, it will eventually be
installed and configured correctly.
+29
View File
@@ -0,0 +1,29 @@
apiVersion: v1
kind: Node
metadata:
name: isaiah
annotations:
"node.longhorn.io/default-disks-config": |-
[
{ "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]}
]
---
apiVersion: v1
kind: Node
metadata:
name: jeremiah
annotations:
"node.longhorn.io/default-disks-config": |-
[
{ "path": "/var/lib/longhorn", "allowScheduling" : true, "tags": ["hdd", "large"]}
]
---
apiVersion: v1
kind: Node
metadata:
name: zeke
annotations:
"node.longhorn.io/default-disks-config": |-
[
{ "path": "/var/lib/longhorn", "allowScheduling" : trues, "tags": ["ssd", "fast"]}
]
+33
View File
@@ -0,0 +1,33 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: operator-oauth
namespace: tailscale
spec:
target:
name: operator-oauth
deletionPolicy: Delete
template:
type: kubernetes.io/basic-auth
data:
username: |-
{{ .username }}
password: |-
{{ .password }}
data:
- secretKey: username
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: ffa188a4-63b2-4926-99f0-b33b0021a4f4
property: username
- secretKey: password
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: ffa188a4-63b2-4926-99f0-b33b0021a4f4
property: password
+36 -7
View File
@@ -3,7 +3,8 @@ kind: Cluster
metadata:
name: postgres
spec:
instances: 3
instances: 2
enablePDB: false
storage:
size: 20Gi
primaryUpdateStrategy: unsupervised
@@ -31,17 +32,45 @@ spec:
superuser: false
passwordSecret:
name: postgres-user-matrix
backup:
retentionPolicy: "30d"
barmanObjectStore:
plugins:
- name: barman-cloud.cloudnative-pg.io
isWALArchiver: false
parameters:
barmanObjectName: k3sbackup-objectstore
# Use this as the target of the bootstrap recovery process
# It is important that the `externalClusters` serverName matches
# the old name of the original cluster that you are upgrading.
# When restoring, set the targetTime to the latest backup that you
# want to restore to
# bootstrap:
# recovery:
# source: origin
# recoveryTarget:
# targetTime: "2025-08-25 19:00:40+05"
# externalClusters:
# - name: origin
# plugin:
# name: barman-cloud.cloudnative-pg.io
# parameters:
# barmanObjectName: k3sbackup-objectstore
# serverName: postgres
---
apiVersion: barmancloud.cnpg.io/v1
kind: ObjectStore
metadata:
name: k3sbackup-objectstore
spec:
configuration:
destinationPath: "s3://k3sbackup/postgres"
endpointURL: "http://s3.thehellings.lan:9000/"
s3Credentials:
accessKeyId:
name: k3sbackup
name: k3sbackup-secret
key: username
secretAccessKey:
name: k3sbackup
name: k3sbackup-secret
key: password
wal:
compression: gzip
@@ -52,7 +81,7 @@ metadata:
name: postgres-backup
spec:
immediate: true # Create one when this is added to the cluster
schedule: "0 0 0 * * *" # Midnight, nightly
schedule: "0 1 0 * * *" # 1AM, nightly
backupOwnerReference: self
cluster:
name: postgres
+2 -2
View File
@@ -103,11 +103,11 @@ spec:
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: k3sbackup
name: k3sbackup-externalsecret
namespace: db
spec:
target:
name: k3sbackup
name: k3sbackup-secret
deletionPolicy: Delete
template:
type: Opaque
+4 -2
View File
@@ -15,7 +15,7 @@ spec:
chart:
spec:
chart: gitlab-runner
version: "0.74.1"
version: "0.80.1"
sourceRef:
kind: HelmRepository
name: gitlab-runner
@@ -28,9 +28,11 @@ spec:
runners:
secret: gitlab-runner
imagePullSecrets:
- image-pull-secrets
- name: image-pull-secrets
rbac:
create: true
serviceAccount:
create: true
extraEnv:
CACHE_TYPE: s3
CACHE_SHARED: "true"
-33
View File
@@ -1,33 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: external-secrets
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: external-secrets
namespace: external-secrets
spec:
interval: "24h"
url: "https://charts.external-secrets.io/"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: external-secrets
namespace: external-secrets
spec:
interval: 10m
chart:
spec:
chart: external-secrets
version: "0.17.0"
sourceRef:
kind: HelmRepository
name: external-secrets
interval: "1h"
values:
crds:
create: true
includeCRDs: true
File diff suppressed because it is too large Load Diff
-3
View File
@@ -1,6 +1,3 @@
resources:
- flux.yaml
- kyverno.yaml # Needed to configure Longhorn
- longhorn.yaml # Needed for storage
- traefik.yaml
- external-secrets.yaml
-40
View File
@@ -1,40 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: kyverno-system
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: kyverno
namespace: kyverno-system
spec:
interval: "24h"
url: "https://kyverno.github.io/kyverno/"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: kyverno
namespace: kyverno-system
spec:
interval: 10m
chart:
spec:
chart: kyverno
version: "3.4.4"
sourceRef:
kind: HelmRepository
name: kyverno
interval: "1h"
values:
admissionController:
replicas: 3
backgroundController:
replicas: 3
cleanupController:
replicas: 2
reportsController:
replicas: 2
crds:
install: true
+5
View File
@@ -30,6 +30,11 @@ spec:
values:
defaultSettings:
createDefaultDiskLabeledNodes: true
# This should go back to null when I have more cluster
replicaSoftAntiAffinity: null
persistence:
# This should go back to 3 when I have more cluster
defaultClassReplicaCount: 2
---
apiVersion: v1
kind: ConfigMap
+61
View File
@@ -0,0 +1,61 @@
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: hellings
spec:
interval: "24h"
url: https://src.thehellings.com/greg/helm-chart
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: kanboard
spec:
interval: 1h
chart:
spec:
chart: hellings
version: "1.0.0"
sourceRef:
kind: HelmRepository
name: hellings
interval: "1h"
values:
fullnameOverride: kanboard
image:
repository: kanboard
tag: v1.2.47
database:
postgres:
enabled: true
readinessProbe:
httpGet:
path: /healthcheck.php
pvc:
- name: kanboard-data
path: /var/www/app/data
size: 10Gi
- name: kanboard-plugins
path: /var/www/app/plugins
size: 10Gi
environment:
- name: DB_DRIVER
value: postgres
- name: DB_HOSTNAME
value: cluster.db.svc.local
- name: DB_NAME
value: kanboard
- name: DB_USERNAME
valueFrom:
secretKeyRef:
name: kanboard-postgres-user
key: username
- name: DB_PASSWORD
valueFrom:
secretKeyRef:
name: kanboard-postgres-user
key: password
- name: LOG_DRIVER
value: stdout
- name: PLUGIN_INSTALLER
value: "true"
+5
View File
@@ -0,0 +1,5 @@
namespace: kanboard
resources:
- namespace.yaml
- helm.yaml
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: kanboard
-2
View File
@@ -10,6 +10,4 @@ helm upgrade \
tailscale/tailscale-operator \
--namespace=tailscale \
--create-namespace \
--set-string oauth.clientId="$(bw get username 'ffa188a4-63b2-4926-99f0-b33b0021a4f4')" \
--set-string oauth.clientSecret="$(bw get password 'ffa188a4-63b2-4926-99f0-b33b0021a4f4')" \
--wait
+2 -1
View File
@@ -49,7 +49,8 @@ in
[
bitwarden
endeavour
jellyfin-media-player
# Is removed because it depends on qt5-qtwebengine
# jellyfin-media-player
nextcloud-client
slack
(pkgs.zoom-us.overrideAttrs {
+26
View File
@@ -3,6 +3,20 @@
name = "Toolbar";
toolbar = true;
bookmarks = [
{
name = "Allow Paste";
url = ''
javascript: (function () {
allowCopyAndPaste = function (e) {
e.stopImmediatePropagation();
return true;
};
document.addEventListener("copy", allowCopyAndPaste, true);
document.addEventListener("paste", allowCopyAndPaste, true);
document.addEventListener("onpaste", allowCopyAndPaste, true);
})();
'';
}
{
name = "Ansible";
bookmarks = [
@@ -232,6 +246,18 @@
name = "Syncthing - nas";
url = "http://nas.home:8384/#";
}
{
name = "Pinchflat";
url = "http://nas1.shire-zebra.ts.net:8945";
}
{
name = "Portainer";
url = "http://nas1.shire-zebra.ts.net:31015";
}
{
name = "Restic";
url = "http://nas1.shire-zebra.ts.net:30248";
}
];
}
{
+2 -2
View File
@@ -46,10 +46,10 @@ in
installRemoteServer = true;
userKeymaps = [
{
context = "Editor && (showing_completions || showing code actions)";
context = "Editor && (showing_completions || showing_code_actions)";
bindings = {
enter = "editor::Newline";
escape = "editor:Cancel";
escape = "editor::Cancel";
};
}
];
+4
View File
@@ -42,6 +42,7 @@ in
substituters =
(lib.optionals cfg.cache [
"http://chronicles.shire-zebra.ts.net:9000/binary-cache/"
"http://nas1.shire-zebra.ts.net:8080/nixos"
])
++ [
"https://ai.cachix.org"
@@ -49,14 +50,17 @@ in
"https://greg-hellings.cachix.org"
"https://nix-community.cachix.org"
"https://cache.nixos.org"
"https://nixhelm.cachix.org"
];
trusted-public-keys = [
"chronicles.shire-zebra.ts.net:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8="
"nixos:1018vqYZeLLOFt+XPiB8k49w2yX8/MT7UbPLCXB92F0="
"ai.cachix.org-1:N9dzRK+alWwoKXQlnn0H6aUx0lU/mspIoz8hMvGvbbc="
"nixpkgs-python.cachix.org-1:hxjI7pFxTyuTHn2NkvWCrAUcNZLNS3ZAvfYNuYifcEU="
"greg-hellings.cachix.org-1:y01Jl/L5evlhxdnUW6n56AiI1k8g1wxWhTxJCe7XSco="
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"nixhelm.cachix.org-1:esqauAsR4opRF0UsGrA6H3gD21OrzMnBBYvJXeddjtY="
];
};
};
+14 -41
View File
@@ -1,33 +1,24 @@
{
lib,
config,
pkgs,
...
}:
let
cfg = config.greg.backup;
where = j: "${config.services.syncthing.dataDir}/daily.0/${j.dest}";
postexec = pkgs.writeShellApplication {
name = "postexec";
runtimeInputs = [ pkgs.coreutils ];
text = ''
chown -R ${config.services.syncthing.user} ${config.services.syncthing.dataDir}
'';
};
makeSyncFolders = _: job: {
devices = [ "chronicles" ];
enable = true;
id = job.id;
label = job.dest;
path = where job;
type = "sendonly";
inherit (job) user;
initialize = true;
passwordFile = config.age.secrets.restic-pw.path;
paths = [ job.src ];
pruneOpts = [
"--keep-daily 7"
"--keep-weekly 5"
"--keep-monthly 12"
];
repository = "rest:nas1.shire-zebra.ts.net:30248/${job.dest}";
};
makeRsnapshot = _: job: "backup ${job.src}/ ${job.dest}/";
in
with lib;
{
@@ -50,9 +41,10 @@ with lib;
dest = mkOption { type = types.str; };
id = mkOption {
user = mkOption {
type = types.str;
description = "The unique folder ID for this";
default = "root";
description = "User to run backup as - defaults to root";
};
};
}
@@ -67,27 +59,8 @@ with lib;
restic-pw.file = ../../secrets/restic-pw.age;
restic-env.file = ../../secrets/restic-env.age;
};
greg.syncthing = {
enable = true;
};
services = {
syncthing.settings.folders = mapAttrs makeSyncFolders cfg.jobs;
rsnapshot = {
enable = true;
enableManualRsnapshot = true;
extraConfig =
''
snapshot_root ${config.services.syncthing.dataDir}/
retain daily 7
retain weekly 2
cmd_postexec ${lib.getExe postexec}
''
+ (builtins.concatStringsSep "\n" (mapAttrsToList makeRsnapshot cfg.jobs));
cronIntervals = {
daily = "19 02 * * *"; # At 2:19 am every day
weekly = "19 01 * * 1"; # At 1:19 am every Monday
};
};
restic.backups = mapAttrs makeSyncFolders cfg.jobs;
};
};
}
+48 -2
View File
@@ -6,6 +6,14 @@
}:
let
cfg = config.greg.kubernetes;
cert-manager = pkgs.fetchurl {
url = "https://github.com/cert-manager/cert-manager/releases/download/v1.18.2/cert-manager.yaml";
sha256 = "0vx1nfyhl0rzb6psfxplq8pfp18mrrdk83n8rj2ph8q6r15vcih5";
};
flux = pkgs.fetchurl {
url = "https://github.com/fluxcd/flux2/releases/download/v2.5.1/install.yaml";
sha256 = "1cjpxfgnzycwnac58gd3naxgmwsj5bdrx0vzh56aiq1m5c0h3dhs";
};
in
{
options.greg = {
@@ -70,19 +78,57 @@ in
services = {
k3s = {
enable = true;
role = if cfg.agentOnly then "agent" else "server";
tokenFile = config.age.secrets.kubernetesToken.path;
autoDeployCharts = {
external-secrets = {
enable = true;
createNamespace = true;
package = pkgs.chartsDerivations.external-secrets.external-secrets;
targetNamespace = "external-secrets";
values = {
crds.create = true;
includeCRDs = true;
};
};
kyverno = {
enable = true;
createNamespace = true;
package = pkgs.chartsDerivations.kyverno.kyverno;
targetNamespace = "kyverno-system";
values = {
admissionController.replicas = 3;
backgroundController.replicas = 3;
cleanupController.replicas = 2;
reportsController.replicas = 2;
crds.install = true;
};
};
tailscale = {
enable = true;
createNamespace = true;
package = pkgs.chartsDerivations.tailscale.tailscale-operator;
targetNamespace = "tailscale";
};
};
extraFlags = [
"--cluster-cidr=10.211.0.0/16"
"--service-cidr=10.221.0.0/16"
"--write-kubeconfig-mode 0640"
"--write-kubeconfig-group kubeconfig"
"--resolv-conf=/etc/resolv.conf"
"--node-label node.longhorn.io/create-default-disk=config"
"--tls-san ${config.networking.hostName}.home"
"--tls-san ${config.networking.hostName}.thehellings.lan"
"--tls-san ${config.networking.hostName}.shire-zebra.ts.net"
];
manifests = {
cert-manager.source = cert-manager;
flux.source = flux;
node-annotations.source = ../../manifests/auto/nodes.yaml;
operator-oauth.source = ../../manifests/auto/operator-oauth.yaml;
};
role = if cfg.agentOnly then "agent" else "server";
serverAddr = lib.mkIf (config.networking.hostName != "isaiah") "https://isaiah.home:6443";
tokenFile = config.age.secrets.kubernetesToken.path;
};
keepalived =
let
+1
View File
@@ -10,6 +10,7 @@ in
aacs = c ./aacs.nix { };
brew = c ./homebrew.nix { };
create_ssl = c ./create_ssl.nix { };
gcc-tune = c ./gcc-tune.nix { };
gen-build = c ./gen-build { };
hms = c ./hms { };
inject-darwin = c ./inject-darwin.nix { };
+16
View File
@@ -0,0 +1,16 @@
{
writeShellApplication,
gcc,
gnugrep,
}:
writeShellApplication {
name = "gcc-tune";
runtimeInputs = [
gcc
gnugrep
];
text = ''
gcc -march=native -Q --help=target | grep 'mtune='
'';
}
Binary file not shown.