Upgrade most of the inputs, remove 2maccabees
This commit is contained in:
Generated
+31
-66
@@ -7,11 +7,11 @@
|
||||
"nixpkgs": "nixpkgs"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1684153753,
|
||||
"narHash": "sha256-PVbWt3qrjYAK+T5KplFcO+h7aZWfEj1UtyoKlvcDxh0=",
|
||||
"lastModified": 1690228878,
|
||||
"narHash": "sha256-9Xe7JV0krp4RJC9W9W9WutZVlw6BlHTFMiUP/k48LQY=",
|
||||
"owner": "ryantm",
|
||||
"repo": "agenix",
|
||||
"rev": "db5637d10f797bb251b94ef9040b237f4702cde3",
|
||||
"rev": "d8c973fd228949736dedf61b7f8cc1ece3236792",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -63,24 +63,6 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"ffmac": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1687135984,
|
||||
"narHash": "sha256-rKYTpYAAqBA07bOKNxnQFDSQ9BjAFFMP3m6k3uNUAJ8=",
|
||||
"owner": "bandithedoge",
|
||||
"repo": "nixpkgs-firefox-darwin",
|
||||
"rev": "31d984614fa8525646f29bfe1bb4cebe48906e8e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "bandithedoge",
|
||||
"repo": "nixpkgs-firefox-darwin",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"flake-compat": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
@@ -102,11 +84,11 @@
|
||||
"systems": "systems"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1689068808,
|
||||
"narHash": "sha256-6ixXo3wt24N/melDWjq70UuHQLxGV8jZvooRanIHXw0=",
|
||||
"lastModified": 1692799911,
|
||||
"narHash": "sha256-3eihraek4qL744EvQXsK1Ha6C3CR7nnT8X2qWap4RNk=",
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"rev": "919d646de7be200f3bf08cb76ae1f09402b6f9b4",
|
||||
"rev": "f9e7cf818399d17d347f847525c5a5a8032e4e44",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -120,11 +102,11 @@
|
||||
"systems": "systems_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1689068808,
|
||||
"narHash": "sha256-6ixXo3wt24N/melDWjq70UuHQLxGV8jZvooRanIHXw0=",
|
||||
"lastModified": 1692799911,
|
||||
"narHash": "sha256-3eihraek4qL744EvQXsK1Ha6C3CR7nnT8X2qWap4RNk=",
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"rev": "919d646de7be200f3bf08cb76ae1f09402b6f9b4",
|
||||
"rev": "f9e7cf818399d17d347f847525c5a5a8032e4e44",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -176,11 +158,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1687871164,
|
||||
"narHash": "sha256-bBFlPthuYX322xOlpJvkjUBz0C+MOBjZdDOOJJ+G2jU=",
|
||||
"lastModified": 1693208669,
|
||||
"narHash": "sha256-hHFaaUsZ860wvppPeiu7nJn/nXZjJfnqAQEu9SPFE9I=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "07c347bb50994691d7b0095f45ebd8838cf6bc38",
|
||||
"rev": "5bac4a1c06cd77cf8fc35a658ccb035a6c50cd2c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -219,11 +201,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1692260837,
|
||||
"narHash": "sha256-2FpkX1zl+7ni7djK7NeE1ZGupRUwZgjW+RPCSBgDf4k=",
|
||||
"lastModified": 1693108765,
|
||||
"narHash": "sha256-U1btmyF7SMX+y80EXYva5Xj6lpn20xPbHbuoe/2bSIw=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "6a94c1a59737783c282c4031555a289c28b961e4",
|
||||
"rev": "9706fb8e441a7c56c68bb079480938ed505e8102",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -276,16 +258,16 @@
|
||||
"home-manager": "home-manager_2",
|
||||
"nix-flake-tests": "nix-flake-tests",
|
||||
"nixneovimplugins": "nixneovimplugins",
|
||||
"nixpkgs": "nixpkgs_3",
|
||||
"nixpkgs": "nixpkgs_2",
|
||||
"nmd": "nmd",
|
||||
"nmt": "nmt"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1692281989,
|
||||
"narHash": "sha256-b1WPbUNVWahAHvMxWnp+0zzswUj8lReX/c28O2Au2Og=",
|
||||
"lastModified": 1693145871,
|
||||
"narHash": "sha256-4ukNPl1wS8KVXDgGvzHdOVna2SmoMNEvSRG1+vJB4/0=",
|
||||
"owner": "NixNeovim",
|
||||
"repo": "NixNeovim",
|
||||
"rev": "929c6c4a188947801ac354e1c5d110937fca9449",
|
||||
"rev": "56bd12a614c6b4d58804eea617caa98040f4609b",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -307,11 +289,11 @@
|
||||
"poetry2nix": "poetry2nix"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1692281871,
|
||||
"narHash": "sha256-nyOnXgW1lyD+ngprSVrKAQdgcK+XSd0vvRaZm5PwRwk=",
|
||||
"lastModified": 1692886753,
|
||||
"narHash": "sha256-8trl3fqUXHSaRBj9db4dy8hDfS6dGEpeYlgKdScA1Zo=",
|
||||
"owner": "nixneovim",
|
||||
"repo": "nixneovimplugins",
|
||||
"rev": "93da8f94aa765d8597d631ee5beafb6d26824777",
|
||||
"rev": "bae2f935ea46475c9360edaca313a5cd5720e2d9",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -338,27 +320,11 @@
|
||||
},
|
||||
"nixpkgs_2": {
|
||||
"locked": {
|
||||
"lastModified": 1639237670,
|
||||
"narHash": "sha256-RTdL4rEQcgaZGpvtDgkp3oK/V+1LM3I53n0ACPSroAQ=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "edfb969386ebe6c3cf8f878775a7975cd88f926d",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "master",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_3": {
|
||||
"locked": {
|
||||
"lastModified": 1692174805,
|
||||
"narHash": "sha256-xmNPFDi/AUMIxwgOH/IVom55Dks34u1g7sFKKebxUm0=",
|
||||
"lastModified": 1693003285,
|
||||
"narHash": "sha256-5nm4yrEHKupjn62MibENtfqlP6pWcRTuSKrMiH9bLkc=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "caac0eb6bdcad0b32cb2522e03e4002c8975c62e",
|
||||
"rev": "5690c4271f2998c304a45c91a0aeb8fb69feaea7",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -386,11 +352,11 @@
|
||||
},
|
||||
"nixunstable": {
|
||||
"locked": {
|
||||
"lastModified": 1692174805,
|
||||
"narHash": "sha256-xmNPFDi/AUMIxwgOH/IVom55Dks34u1g7sFKKebxUm0=",
|
||||
"lastModified": 1693158576,
|
||||
"narHash": "sha256-aRTTXkYvhXosGx535iAFUaoFboUrZSYb1Ooih/auGp0=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "caac0eb6bdcad0b32cb2522e03e4002c8975c62e",
|
||||
"rev": "a999c1cc0c9eb2095729d5aa03e0d8f7ed256780",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -434,11 +400,11 @@
|
||||
},
|
||||
"nurpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1691615229,
|
||||
"narHash": "sha256-MdNFFmNAIM3kV3gQrui3RLcq8L6lbaj5JKBMFsphS38=",
|
||||
"lastModified": 1693319998,
|
||||
"narHash": "sha256-GjdunTxfEcvWn7N6RrDLE+X35M/nJfmZdK2Cq2Lvk/0=",
|
||||
"owner": "nix-community",
|
||||
"repo": "NUR",
|
||||
"rev": "2366bfc7cf3caa0cbd6a05bb6f2c9befc30e80b8",
|
||||
"rev": "f944f5befe39d7cf27cd0b41960ace172f9241b3",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -475,7 +441,6 @@
|
||||
"inputs": {
|
||||
"agenix": "agenix",
|
||||
"darwin": "darwin_2",
|
||||
"ffmac": "ffmac",
|
||||
"flake-utils": "flake-utils",
|
||||
"hm": "hm",
|
||||
"nixneovim": "nixneovim",
|
||||
|
||||
@@ -10,7 +10,6 @@
|
||||
url = "github:lnl7/nix-darwin/master";
|
||||
inputs.nixpkgs.follows = "nixunstable";
|
||||
};
|
||||
ffmac.url = "github:bandithedoge/nixpkgs-firefox-darwin";
|
||||
flake-utils.url = "github:numtide/flake-utils";
|
||||
hm = {
|
||||
url = "github:nix-community/home-manager/release-23.05";
|
||||
@@ -29,7 +28,6 @@
|
||||
outputs = {
|
||||
agenix,
|
||||
darwin,
|
||||
ffmac,
|
||||
flake-utils,
|
||||
hm,
|
||||
nixneovim,
|
||||
@@ -53,7 +51,6 @@
|
||||
local_overlay
|
||||
nixneovim.overlays.default
|
||||
nurpkgs.overlay
|
||||
ffmac.overlay
|
||||
];
|
||||
|
||||
in {
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
|
||||
}
|
||||
@@ -1,13 +0,0 @@
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
./dnsmasq.nix
|
||||
./home-assistant.nix
|
||||
./networking.nix
|
||||
./vhosts.nix
|
||||
];
|
||||
networking.hostName = "2maccabees";
|
||||
greg.rpi4.enable = true;
|
||||
}
|
||||
@@ -1,80 +0,0 @@
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
let
|
||||
extraHosts = builtins.concatStringsSep "\n" [
|
||||
# Local hosts
|
||||
"10.42.0.1 switch"
|
||||
"10.42.1.1 router"
|
||||
"10.42.1.2 2maccabees 2maccabees.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan"
|
||||
"10.42.1.3 printer"
|
||||
"10.42.1.4 chronicles nas"
|
||||
"10.42.1.12 tv"
|
||||
|
||||
# Tailscale hosts
|
||||
"100.90.74.19 jude.me.ts"
|
||||
"100.99.244.92 dns.me.ts 2maccabees.me.ts smart.me.ts jellyfin.me.ts"
|
||||
"100.119.228.115 chronicles.me.ts nas.me.ts"
|
||||
"100.115.57.8 linode.me.ts"
|
||||
|
||||
# Dev hosts
|
||||
"10.42.101.1 icdm.lan wiki.icdm.lan *.icdm.lan"
|
||||
];
|
||||
|
||||
extraConfig = builtins.concatStringsSep "\n" [
|
||||
];
|
||||
in
|
||||
{
|
||||
# Enable the service with its own configuration
|
||||
services.dnsmasq = {
|
||||
enable = true;
|
||||
# Public AdGuard DNS servers
|
||||
settings = {
|
||||
domain = "thehellings.lan";
|
||||
dhcp-range = [
|
||||
# "eth0,10.42.0.1,10.42.1.255,255.255.0.0,static"
|
||||
"eth0,10.42.2.1,10.42.2.255,255.255.0.0,12h"
|
||||
"vlan66@eth0,192.168.66.3,192.168.66.150,255.255.255.0,12h"
|
||||
"vlan67@eth0,192.168.67.3,192.168.67.150,12h"
|
||||
];
|
||||
dhcp-option = [
|
||||
"eth0,option:router,10.42.1.1"
|
||||
"eth0,option:dns-server,10.42.1.2,1.1.1.1"
|
||||
"eth0,option:domain-search,thehellings.lan"
|
||||
|
||||
"vlan66@eth0,option:router,192.168.66.1"
|
||||
"vlan66@eth0,option:dns-server,192.168.66.2"
|
||||
|
||||
"vlan67@eth0,option:router,192.168.67.1"
|
||||
"vlan67@eth0,option:dns-server,192.168.67.2"
|
||||
];
|
||||
expand-hosts = true;
|
||||
log-dhcp = true;
|
||||
log-queries = true;
|
||||
addn-hosts = "/etc/adblock_hosts";
|
||||
server = [
|
||||
"94.140.14.14"
|
||||
"94.140.15.15"
|
||||
];
|
||||
};
|
||||
extraConfig = "${extraConfig}";
|
||||
};
|
||||
environment.systemPackages = [ pkgs.curl ];
|
||||
|
||||
# Regularly update DNS block list
|
||||
services.cron = {
|
||||
enable = true;
|
||||
systemCronJobs = [
|
||||
"* * * * * root ( ${pkgs.curl}/bin/curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts && systemctl restart dnsmasq ) 2>&1 > /var/log/adblock.log"
|
||||
];
|
||||
};
|
||||
|
||||
# Allow traffic through
|
||||
networking.firewall = {
|
||||
enable = true;
|
||||
allowedTCPPorts = [ 53 ];
|
||||
allowedUDPPorts = [ 53 67 ];
|
||||
};
|
||||
|
||||
# Custom host addition
|
||||
networking.extraHosts = "${extraHosts}";
|
||||
}
|
||||
@@ -1,31 +0,0 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{ config, lib, pkgs, modulesPath, ... }:
|
||||
|
||||
{
|
||||
imports =
|
||||
[ (modulesPath + "/installer/scan/not-detected.nix")
|
||||
];
|
||||
|
||||
boot.initrd.availableKernelModules = [ "xhci_pci" "usbhid" "usb_storage" "uas" ];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
fileSystems."/" ={
|
||||
device = "/dev/disk/by-uuid/35f9a49a-b557-4eb3-a013-2afca7a990e4";
|
||||
fsType = "btrfs";
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/A982-C8A3";
|
||||
fsType = "vfat";
|
||||
};
|
||||
|
||||
swapDevices = [ {
|
||||
device = "/dev/disk/by-uuid/4b6f2dc4-d845-4ec4-81f2-4f61bb3f282d";
|
||||
} ];
|
||||
|
||||
powerManagement.cpuFreqGovernor = lib.mkDefault "ondemand";
|
||||
}
|
||||
@@ -1,90 +0,0 @@
|
||||
{ config, pkgs, ... }:
|
||||
|
||||
let
|
||||
service_list = [ "podman-home-assistant.service" ];
|
||||
in
|
||||
{
|
||||
virtualisation.podman.enable = true;
|
||||
|
||||
services.home-assistant = {
|
||||
enable = true;
|
||||
configDir = "/var/lib/hass";
|
||||
package = (pkgs.home-assistant.override {
|
||||
extraComponents = [
|
||||
"accuweather"
|
||||
"calendar"
|
||||
"cast"
|
||||
"eufy"
|
||||
"lovelace"
|
||||
"nextcloud"
|
||||
"smart_meter_texas"
|
||||
"solaredge"
|
||||
"tplink"
|
||||
"wiz"
|
||||
"zwave_js"
|
||||
];
|
||||
}).overrideAttrs (oldAttrs: {
|
||||
doInstallCheck = false;
|
||||
});
|
||||
|
||||
config = {
|
||||
default_config = {};
|
||||
esphome = {}; # Get these things loaded, even if not configured
|
||||
met = {};
|
||||
tts = [ { platform = "google_translate"; } ];
|
||||
http = {
|
||||
use_x_forwarded_for = true;
|
||||
trusted_proxies = [ "127.0.0.1" "::1" ];
|
||||
server_host = "127.0.0.1";
|
||||
};
|
||||
#"automation manual" = *nix config here* and so on
|
||||
"automation ui" = "!include automations.yaml";
|
||||
"script ui" = "!include scripts.yaml";
|
||||
"scene ui" = "!include scenes.yaml";
|
||||
};
|
||||
};
|
||||
|
||||
# Although NixOS has a package for Home Assistant, it is not kept as up to date as the container and the upstream
|
||||
# is very vocal about only supporting their own container or the HAOS deployments. So we deploy the container here
|
||||
# and avoid any potential messes from that
|
||||
virtualisation.oci-containers = {
|
||||
backend = "podman";
|
||||
|
||||
# I have ZWave devices. The easiest way to connect to them is the zwavejs2mqtt service running, so we spin up
|
||||
# its container and map the ZWave device into it
|
||||
containers.zwave = {
|
||||
image = "zwavejs/zwavejs2mqtt:latest";
|
||||
ports = [ "8091:8091" "3000:3000" ];
|
||||
volumes = [ "/var/lib/zwave:/usr/src/app/store" ];
|
||||
extraOptions = [
|
||||
"--device" "/dev/serial/by-id/usb-0658_0200-if00:/dev/zwave"
|
||||
"--pull=newer"
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
# Both of the above container need storage for their configuration and devices, but it is not created correctly by
|
||||
# the container. So we add the creation of /var/lib/{zwave,hass} to the systemd Unit files
|
||||
systemd.services = {
|
||||
"podman-zwave".serviceConfig = {
|
||||
StateDirectory = "zwave";
|
||||
StateDirectoryMode = pkgs.lib.mkForce "0777";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
greg.proxies."smart.thehellings.lan".target = "http://127.0.0.1:8123";
|
||||
|
||||
# Ensure that both ports are up and running. We keep 8123 directly open because we are on the LAN and sometimes want to connect
|
||||
# directly for troubleshooting Nginx configuration
|
||||
networking.firewall = {
|
||||
enable = true;
|
||||
allowedTCPPorts = [ 80 443 8091 8123 ];
|
||||
};
|
||||
|
||||
greg.backup.jobs.zwave = {
|
||||
src = "/var/lib/zwave";
|
||||
dest = "zwave";
|
||||
user = "root";
|
||||
};
|
||||
}
|
||||
@@ -1,75 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
greg.tailscale.enable = true;
|
||||
|
||||
networking = {
|
||||
# This value is deprecated, you now set it per interface
|
||||
useDHCP = false;
|
||||
defaultGateway = "10.42.1.1";
|
||||
# 100.100.100.100 is the tailscale DNS
|
||||
nameservers = [ "100.100.100.100" "127.0.0.1" ];
|
||||
interfaces = {
|
||||
eth0.ipv4.addresses = [ {
|
||||
address = "10.42.1.2";
|
||||
prefixLength = 16;
|
||||
} ];
|
||||
wlan0.useDHCP = true;
|
||||
|
||||
vlan66.ipv4.addresses = [ {
|
||||
address = "192.168.66.2";
|
||||
prefixLength = 24;
|
||||
} ];
|
||||
};
|
||||
|
||||
vlans = {
|
||||
vlan66 = {
|
||||
id = 66;
|
||||
interface = "eth0";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
# Open ports in the firewall.
|
||||
# networking.firewall.allowedTCPPorts = [ ... ];
|
||||
# networking.firewall.allowedUDPPorts = [ ... ];
|
||||
# Or disable the firewall altogether.
|
||||
# networking.firewall.enable = false;
|
||||
|
||||
fileSystems."/media" = {
|
||||
device = "10.42.1.4:/volume1/video/";
|
||||
fsType = "nfs";
|
||||
options = [ "ro" ];
|
||||
};
|
||||
|
||||
services.jellyfin = {
|
||||
enable = true;
|
||||
openFirewall = true;
|
||||
};
|
||||
|
||||
greg.proxies."jellyfin.thehellings.lan".target = "http://localhost:8096";
|
||||
greg.proxies."jellyfin.me.ts".target = "http://localhost:8096";
|
||||
|
||||
#########
|
||||
# Blind service proxy behind the walls of the VPN
|
||||
########
|
||||
services._3proxy = {
|
||||
enable = true;
|
||||
services = [ {
|
||||
type = "socks";
|
||||
auth = [ "strong" ];
|
||||
bindPort = 3128;
|
||||
acl = [ {
|
||||
rule = "allow";
|
||||
users = [ "greg" ];
|
||||
} ];
|
||||
} ];
|
||||
usersFile = "/run/agenix/3proxy";
|
||||
denyPrivate = false;
|
||||
};
|
||||
age.secrets."3proxy" = {
|
||||
file = ../../secrets/3proxy.age;
|
||||
mode = "777";
|
||||
};
|
||||
networking.firewall.allowedTCPPorts = [ 3128 ];
|
||||
}
|
||||
@@ -1,15 +0,0 @@
|
||||
# Virtual hosts that don't seem to have any better place to live should go in here.
|
||||
# There are others that are specific to their own purposese scattered about in the
|
||||
# configuration in places where they more naturally live. This is more of a catchall
|
||||
# for ones that do not have a better place to live
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
greg.proxies."dns.thehellings.lan" = {
|
||||
target = "http://127.0.0.1:8384/";
|
||||
path = "/sync/";
|
||||
};
|
||||
|
||||
# The module doesn't handle this
|
||||
services.nginx.virtualHosts."dns.thehellings.lan".serverAliases = [ "dns" ];
|
||||
}
|
||||
Reference in New Issue
Block a user