From 4a1b145e60255c162f7928dfb69efe1f8d976c9d Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 25 Aug 2023 15:56:17 -0500 Subject: [PATCH 1/4] Only adblock from my own list --- hosts/genesis/dnsmasq.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/hosts/genesis/dnsmasq.nix b/hosts/genesis/dnsmasq.nix index e398ce7..9e7685e 100644 --- a/hosts/genesis/dnsmasq.nix +++ b/hosts/genesis/dnsmasq.nix @@ -86,8 +86,10 @@ in addn-hosts = "/etc/adblock_hosts"; # Public AdGuard DNS servers server = [ - "94.140.14.14" - "94.140.15.15" + "9.9.9.9" # Quad 9 + "1.1.1.1" # Cloudflare + "1.0.0.1" # Cloudflare + "149.112.112.112" # Quad 9 ]; }; extraConfig = "${extraConfig}"; From 014693cdcbb9b1f0b7330ce5499b112aa3d2650d Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Fri, 25 Aug 2023 15:59:48 -0500 Subject: [PATCH 2/4] Make exceptions to adblock easier --- hosts/genesis/adblockUpdate.sh | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/hosts/genesis/adblockUpdate.sh b/hosts/genesis/adblockUpdate.sh index 1f60fa8..69b8994 100644 --- a/hosts/genesis/adblockUpdate.sh +++ b/hosts/genesis/adblockUpdate.sh @@ -1,11 +1,11 @@ #!/usr/bin/env bash set -ex - curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts # Custom domains that I need to preserve for some reason -sed -i -e '/segment.com/d' /etc/adblock_hosts # Blocks Trelly content for house investors -sed -i -e '/segment.io/d' /etc/adblock_hosts # Blocks Trelly content for house investors +for f in "segment.com" "segment.io" "branch.io" "dev.visualwebsiteoptimizer.com"; do + sed -i -e "/${f}/d" /etc/adblock_hosts # Blocks Trelly content for house investors +done systemctl restart dnsmasq From 6cd8755e56e3ba0cd54c6370a19dcdac2603e924 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Sat, 26 Aug 2023 20:02:09 -0500 Subject: [PATCH 3/4] Make home-assistant import the UI bits --- hosts/genesis/home-assistant.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/hosts/genesis/home-assistant.nix b/hosts/genesis/home-assistant.nix index 357a5b8..12b2338 100755 --- a/hosts/genesis/home-assistant.nix +++ b/hosts/genesis/home-assistant.nix @@ -36,9 +36,9 @@ in server_host = "127.0.0.1"; }; #"automation manual" = *nix config here* and so on - "automation ui" = ""; - "script ui" = ""; - "scene ui" = ""; + "automation ui" = "!include automations.yaml"; + "script ui" = "!include scripts.yaml"; + "scene ui" = "!include scenes.yaml"; }; }; From 97da05553611883f8e2afbf0591414454d0e98c3 Mon Sep 17 00:00:00 2001 From: Greg Hellings Date: Tue, 29 Aug 2023 09:58:05 -0500 Subject: [PATCH 4/4] Upgrade most of the inputs, remove 2maccabees --- flake.lock | 97 +++++++-------------- flake.nix | 3 - home/hosts/2maccabees/default.nix | 5 -- hosts/2maccabees/default.nix | 13 --- hosts/2maccabees/dnsmasq.nix | 80 ----------------- hosts/2maccabees/hardware-configuration.nix | 31 ------- hosts/2maccabees/home-assistant.nix | 90 ------------------- hosts/2maccabees/networking.nix | 75 ---------------- hosts/2maccabees/vhosts.nix | 15 ---- 9 files changed, 31 insertions(+), 378 deletions(-) delete mode 100644 home/hosts/2maccabees/default.nix delete mode 100644 hosts/2maccabees/default.nix delete mode 100644 hosts/2maccabees/dnsmasq.nix delete mode 100755 hosts/2maccabees/hardware-configuration.nix delete mode 100755 hosts/2maccabees/home-assistant.nix delete mode 100644 hosts/2maccabees/networking.nix delete mode 100644 hosts/2maccabees/vhosts.nix diff --git a/flake.lock b/flake.lock index 97926ea..ff10790 100644 --- a/flake.lock +++ b/flake.lock @@ -7,11 +7,11 @@ "nixpkgs": "nixpkgs" }, "locked": { - "lastModified": 1684153753, - "narHash": "sha256-PVbWt3qrjYAK+T5KplFcO+h7aZWfEj1UtyoKlvcDxh0=", + "lastModified": 1690228878, + "narHash": "sha256-9Xe7JV0krp4RJC9W9W9WutZVlw6BlHTFMiUP/k48LQY=", "owner": "ryantm", "repo": "agenix", - "rev": "db5637d10f797bb251b94ef9040b237f4702cde3", + "rev": "d8c973fd228949736dedf61b7f8cc1ece3236792", "type": "github" }, "original": { @@ -63,24 +63,6 @@ "type": "github" } }, - "ffmac": { - "inputs": { - "nixpkgs": "nixpkgs_2" - }, - "locked": { - "lastModified": 1687135984, - "narHash": "sha256-rKYTpYAAqBA07bOKNxnQFDSQ9BjAFFMP3m6k3uNUAJ8=", - "owner": "bandithedoge", - "repo": "nixpkgs-firefox-darwin", - "rev": "31d984614fa8525646f29bfe1bb4cebe48906e8e", - "type": "github" - }, - "original": { - "owner": "bandithedoge", - "repo": "nixpkgs-firefox-darwin", - "type": "github" - } - }, "flake-compat": { "flake": false, "locked": { @@ -102,11 +84,11 @@ "systems": "systems" }, "locked": { - "lastModified": 1689068808, - "narHash": "sha256-6ixXo3wt24N/melDWjq70UuHQLxGV8jZvooRanIHXw0=", + "lastModified": 1692799911, + "narHash": "sha256-3eihraek4qL744EvQXsK1Ha6C3CR7nnT8X2qWap4RNk=", "owner": "numtide", "repo": "flake-utils", - "rev": "919d646de7be200f3bf08cb76ae1f09402b6f9b4", + "rev": "f9e7cf818399d17d347f847525c5a5a8032e4e44", "type": "github" }, "original": { @@ -120,11 +102,11 @@ "systems": "systems_2" }, "locked": { - "lastModified": 1689068808, - "narHash": "sha256-6ixXo3wt24N/melDWjq70UuHQLxGV8jZvooRanIHXw0=", + "lastModified": 1692799911, + "narHash": "sha256-3eihraek4qL744EvQXsK1Ha6C3CR7nnT8X2qWap4RNk=", "owner": "numtide", "repo": "flake-utils", - "rev": "919d646de7be200f3bf08cb76ae1f09402b6f9b4", + "rev": "f9e7cf818399d17d347f847525c5a5a8032e4e44", "type": "github" }, "original": { @@ -176,11 +158,11 @@ ] }, "locked": { - "lastModified": 1687871164, - "narHash": "sha256-bBFlPthuYX322xOlpJvkjUBz0C+MOBjZdDOOJJ+G2jU=", + "lastModified": 1693208669, + "narHash": "sha256-hHFaaUsZ860wvppPeiu7nJn/nXZjJfnqAQEu9SPFE9I=", "owner": "nix-community", "repo": "home-manager", - "rev": "07c347bb50994691d7b0095f45ebd8838cf6bc38", + "rev": "5bac4a1c06cd77cf8fc35a658ccb035a6c50cd2c", "type": "github" }, "original": { @@ -219,11 +201,11 @@ ] }, "locked": { - "lastModified": 1692260837, - "narHash": "sha256-2FpkX1zl+7ni7djK7NeE1ZGupRUwZgjW+RPCSBgDf4k=", + "lastModified": 1693108765, + "narHash": "sha256-U1btmyF7SMX+y80EXYva5Xj6lpn20xPbHbuoe/2bSIw=", "owner": "nix-community", "repo": "home-manager", - "rev": "6a94c1a59737783c282c4031555a289c28b961e4", + "rev": "9706fb8e441a7c56c68bb079480938ed505e8102", "type": "github" }, "original": { @@ -276,16 +258,16 @@ "home-manager": "home-manager_2", "nix-flake-tests": "nix-flake-tests", "nixneovimplugins": "nixneovimplugins", - "nixpkgs": "nixpkgs_3", + "nixpkgs": "nixpkgs_2", "nmd": "nmd", "nmt": "nmt" }, "locked": { - "lastModified": 1692281989, - "narHash": "sha256-b1WPbUNVWahAHvMxWnp+0zzswUj8lReX/c28O2Au2Og=", + "lastModified": 1693145871, + "narHash": "sha256-4ukNPl1wS8KVXDgGvzHdOVna2SmoMNEvSRG1+vJB4/0=", "owner": "NixNeovim", "repo": "NixNeovim", - "rev": "929c6c4a188947801ac354e1c5d110937fca9449", + "rev": "56bd12a614c6b4d58804eea617caa98040f4609b", "type": "github" }, "original": { @@ -307,11 +289,11 @@ "poetry2nix": "poetry2nix" }, "locked": { - "lastModified": 1692281871, - "narHash": "sha256-nyOnXgW1lyD+ngprSVrKAQdgcK+XSd0vvRaZm5PwRwk=", + "lastModified": 1692886753, + "narHash": "sha256-8trl3fqUXHSaRBj9db4dy8hDfS6dGEpeYlgKdScA1Zo=", "owner": "nixneovim", "repo": "nixneovimplugins", - "rev": "93da8f94aa765d8597d631ee5beafb6d26824777", + "rev": "bae2f935ea46475c9360edaca313a5cd5720e2d9", "type": "github" }, "original": { @@ -338,27 +320,11 @@ }, "nixpkgs_2": { "locked": { - "lastModified": 1639237670, - "narHash": "sha256-RTdL4rEQcgaZGpvtDgkp3oK/V+1LM3I53n0ACPSroAQ=", - "owner": "NixOS", - "repo": "nixpkgs", - "rev": "edfb969386ebe6c3cf8f878775a7975cd88f926d", - "type": "github" - }, - "original": { - "owner": "NixOS", - "ref": "master", - "repo": "nixpkgs", - "type": "github" - } - }, - "nixpkgs_3": { - "locked": { - "lastModified": 1692174805, - "narHash": "sha256-xmNPFDi/AUMIxwgOH/IVom55Dks34u1g7sFKKebxUm0=", + "lastModified": 1693003285, + "narHash": "sha256-5nm4yrEHKupjn62MibENtfqlP6pWcRTuSKrMiH9bLkc=", "owner": "nixos", "repo": "nixpkgs", - "rev": "caac0eb6bdcad0b32cb2522e03e4002c8975c62e", + "rev": "5690c4271f2998c304a45c91a0aeb8fb69feaea7", "type": "github" }, "original": { @@ -386,11 +352,11 @@ }, "nixunstable": { "locked": { - "lastModified": 1692174805, - "narHash": "sha256-xmNPFDi/AUMIxwgOH/IVom55Dks34u1g7sFKKebxUm0=", + "lastModified": 1693158576, + "narHash": "sha256-aRTTXkYvhXosGx535iAFUaoFboUrZSYb1Ooih/auGp0=", "owner": "nixos", "repo": "nixpkgs", - "rev": "caac0eb6bdcad0b32cb2522e03e4002c8975c62e", + "rev": "a999c1cc0c9eb2095729d5aa03e0d8f7ed256780", "type": "github" }, "original": { @@ -434,11 +400,11 @@ }, "nurpkgs": { "locked": { - "lastModified": 1691615229, - "narHash": "sha256-MdNFFmNAIM3kV3gQrui3RLcq8L6lbaj5JKBMFsphS38=", + "lastModified": 1693319998, + "narHash": "sha256-GjdunTxfEcvWn7N6RrDLE+X35M/nJfmZdK2Cq2Lvk/0=", "owner": "nix-community", "repo": "NUR", - "rev": "2366bfc7cf3caa0cbd6a05bb6f2c9befc30e80b8", + "rev": "f944f5befe39d7cf27cd0b41960ace172f9241b3", "type": "github" }, "original": { @@ -475,7 +441,6 @@ "inputs": { "agenix": "agenix", "darwin": "darwin_2", - "ffmac": "ffmac", "flake-utils": "flake-utils", "hm": "hm", "nixneovim": "nixneovim", diff --git a/flake.nix b/flake.nix index 8a1a855..44fb41b 100644 --- a/flake.nix +++ b/flake.nix @@ -10,7 +10,6 @@ url = "github:lnl7/nix-darwin/master"; inputs.nixpkgs.follows = "nixunstable"; }; - ffmac.url = "github:bandithedoge/nixpkgs-firefox-darwin"; flake-utils.url = "github:numtide/flake-utils"; hm = { url = "github:nix-community/home-manager/release-23.05"; @@ -29,7 +28,6 @@ outputs = { agenix, darwin, - ffmac, flake-utils, hm, nixneovim, @@ -53,7 +51,6 @@ local_overlay nixneovim.overlays.default nurpkgs.overlay - ffmac.overlay ]; in { diff --git a/home/hosts/2maccabees/default.nix b/home/hosts/2maccabees/default.nix deleted file mode 100644 index d8147ea..0000000 --- a/home/hosts/2maccabees/default.nix +++ /dev/null @@ -1,5 +0,0 @@ -{ ... }: - -{ - -} diff --git a/hosts/2maccabees/default.nix b/hosts/2maccabees/default.nix deleted file mode 100644 index 4f5c077..0000000 --- a/hosts/2maccabees/default.nix +++ /dev/null @@ -1,13 +0,0 @@ -{ config, pkgs, ... }: - -{ - imports = [ - ./hardware-configuration.nix - ./dnsmasq.nix - ./home-assistant.nix - ./networking.nix - ./vhosts.nix - ]; - networking.hostName = "2maccabees"; - greg.rpi4.enable = true; -} diff --git a/hosts/2maccabees/dnsmasq.nix b/hosts/2maccabees/dnsmasq.nix deleted file mode 100644 index 578cab0..0000000 --- a/hosts/2maccabees/dnsmasq.nix +++ /dev/null @@ -1,80 +0,0 @@ -{ config, pkgs, ... }: - -let - extraHosts = builtins.concatStringsSep "\n" [ - # Local hosts - "10.42.0.1 switch" - "10.42.1.1 router" - "10.42.1.2 2maccabees 2maccabees.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan jellyfin jellyfin.thehellings.lan" - "10.42.1.3 printer" - "10.42.1.4 chronicles nas" - "10.42.1.12 tv" - - # Tailscale hosts - "100.90.74.19 jude.me.ts" - "100.99.244.92 dns.me.ts 2maccabees.me.ts smart.me.ts jellyfin.me.ts" - "100.119.228.115 chronicles.me.ts nas.me.ts" - "100.115.57.8 linode.me.ts" - - # Dev hosts - "10.42.101.1 icdm.lan wiki.icdm.lan *.icdm.lan" - ]; - - extraConfig = builtins.concatStringsSep "\n" [ - ]; -in -{ - # Enable the service with its own configuration - services.dnsmasq = { - enable = true; - # Public AdGuard DNS servers - settings = { - domain = "thehellings.lan"; - dhcp-range = [ - # "eth0,10.42.0.1,10.42.1.255,255.255.0.0,static" - "eth0,10.42.2.1,10.42.2.255,255.255.0.0,12h" - "vlan66@eth0,192.168.66.3,192.168.66.150,255.255.255.0,12h" - "vlan67@eth0,192.168.67.3,192.168.67.150,12h" - ]; - dhcp-option = [ - "eth0,option:router,10.42.1.1" - "eth0,option:dns-server,10.42.1.2,1.1.1.1" - "eth0,option:domain-search,thehellings.lan" - - "vlan66@eth0,option:router,192.168.66.1" - "vlan66@eth0,option:dns-server,192.168.66.2" - - "vlan67@eth0,option:router,192.168.67.1" - "vlan67@eth0,option:dns-server,192.168.67.2" - ]; - expand-hosts = true; - log-dhcp = true; - log-queries = true; - addn-hosts = "/etc/adblock_hosts"; - server = [ - "94.140.14.14" - "94.140.15.15" - ]; - }; - extraConfig = "${extraConfig}"; - }; - environment.systemPackages = [ pkgs.curl ]; - - # Regularly update DNS block list - services.cron = { - enable = true; - systemCronJobs = [ - "* * * * * root ( ${pkgs.curl}/bin/curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts && systemctl restart dnsmasq ) 2>&1 > /var/log/adblock.log" - ]; - }; - - # Allow traffic through - networking.firewall = { - enable = true; - allowedTCPPorts = [ 53 ]; - allowedUDPPorts = [ 53 67 ]; - }; - - # Custom host addition - networking.extraHosts = "${extraHosts}"; -} diff --git a/hosts/2maccabees/hardware-configuration.nix b/hosts/2maccabees/hardware-configuration.nix deleted file mode 100755 index 242c146..0000000 --- a/hosts/2maccabees/hardware-configuration.nix +++ /dev/null @@ -1,31 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - -{ - imports = - [ (modulesPath + "/installer/scan/not-detected.nix") - ]; - - boot.initrd.availableKernelModules = [ "xhci_pci" "usbhid" "usb_storage" "uas" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ ]; - boot.extraModulePackages = [ ]; - - fileSystems."/" ={ - device = "/dev/disk/by-uuid/35f9a49a-b557-4eb3-a013-2afca7a990e4"; - fsType = "btrfs"; - }; - - fileSystems."/boot" = { - device = "/dev/disk/by-uuid/A982-C8A3"; - fsType = "vfat"; - }; - - swapDevices = [ { - device = "/dev/disk/by-uuid/4b6f2dc4-d845-4ec4-81f2-4f61bb3f282d"; - } ]; - - powerManagement.cpuFreqGovernor = lib.mkDefault "ondemand"; -} diff --git a/hosts/2maccabees/home-assistant.nix b/hosts/2maccabees/home-assistant.nix deleted file mode 100755 index bb014d8..0000000 --- a/hosts/2maccabees/home-assistant.nix +++ /dev/null @@ -1,90 +0,0 @@ -{ config, pkgs, ... }: - -let - service_list = [ "podman-home-assistant.service" ]; -in -{ - virtualisation.podman.enable = true; - - services.home-assistant = { - enable = true; - configDir = "/var/lib/hass"; - package = (pkgs.home-assistant.override { - extraComponents = [ - "accuweather" - "calendar" - "cast" - "eufy" - "lovelace" - "nextcloud" - "smart_meter_texas" - "solaredge" - "tplink" - "wiz" - "zwave_js" - ]; - }).overrideAttrs (oldAttrs: { - doInstallCheck = false; - }); - - config = { - default_config = {}; - esphome = {}; # Get these things loaded, even if not configured - met = {}; - tts = [ { platform = "google_translate"; } ]; - http = { - use_x_forwarded_for = true; - trusted_proxies = [ "127.0.0.1" "::1" ]; - server_host = "127.0.0.1"; - }; - #"automation manual" = *nix config here* and so on - "automation ui" = "!include automations.yaml"; - "script ui" = "!include scripts.yaml"; - "scene ui" = "!include scenes.yaml"; - }; - }; - - # Although NixOS has a package for Home Assistant, it is not kept as up to date as the container and the upstream - # is very vocal about only supporting their own container or the HAOS deployments. So we deploy the container here - # and avoid any potential messes from that - virtualisation.oci-containers = { - backend = "podman"; - - # I have ZWave devices. The easiest way to connect to them is the zwavejs2mqtt service running, so we spin up - # its container and map the ZWave device into it - containers.zwave = { - image = "zwavejs/zwavejs2mqtt:latest"; - ports = [ "8091:8091" "3000:3000" ]; - volumes = [ "/var/lib/zwave:/usr/src/app/store" ]; - extraOptions = [ - "--device" "/dev/serial/by-id/usb-0658_0200-if00:/dev/zwave" - "--pull=newer" - ]; - }; - }; - - # Both of the above container need storage for their configuration and devices, but it is not created correctly by - # the container. So we add the creation of /var/lib/{zwave,hass} to the systemd Unit files - systemd.services = { - "podman-zwave".serviceConfig = { - StateDirectory = "zwave"; - StateDirectoryMode = pkgs.lib.mkForce "0777"; - }; - }; - - - greg.proxies."smart.thehellings.lan".target = "http://127.0.0.1:8123"; - - # Ensure that both ports are up and running. We keep 8123 directly open because we are on the LAN and sometimes want to connect - # directly for troubleshooting Nginx configuration - networking.firewall = { - enable = true; - allowedTCPPorts = [ 80 443 8091 8123 ]; - }; - - greg.backup.jobs.zwave = { - src = "/var/lib/zwave"; - dest = "zwave"; - user = "root"; - }; -} diff --git a/hosts/2maccabees/networking.nix b/hosts/2maccabees/networking.nix deleted file mode 100644 index c2234f2..0000000 --- a/hosts/2maccabees/networking.nix +++ /dev/null @@ -1,75 +0,0 @@ -{ ... }: - -{ - greg.tailscale.enable = true; - - networking = { - # This value is deprecated, you now set it per interface - useDHCP = false; - defaultGateway = "10.42.1.1"; - # 100.100.100.100 is the tailscale DNS - nameservers = [ "100.100.100.100" "127.0.0.1" ]; - interfaces = { - eth0.ipv4.addresses = [ { - address = "10.42.1.2"; - prefixLength = 16; - } ]; - wlan0.useDHCP = true; - - vlan66.ipv4.addresses = [ { - address = "192.168.66.2"; - prefixLength = 24; - } ]; - }; - - vlans = { - vlan66 = { - id = 66; - interface = "eth0"; - }; - }; - }; - - # Open ports in the firewall. - # networking.firewall.allowedTCPPorts = [ ... ]; - # networking.firewall.allowedUDPPorts = [ ... ]; - # Or disable the firewall altogether. - # networking.firewall.enable = false; - - fileSystems."/media" = { - device = "10.42.1.4:/volume1/video/"; - fsType = "nfs"; - options = [ "ro" ]; - }; - - services.jellyfin = { - enable = true; - openFirewall = true; - }; - - greg.proxies."jellyfin.thehellings.lan".target = "http://localhost:8096"; - greg.proxies."jellyfin.me.ts".target = "http://localhost:8096"; - - ######### - # Blind service proxy behind the walls of the VPN - ######## - services._3proxy = { - enable = true; - services = [ { - type = "socks"; - auth = [ "strong" ]; - bindPort = 3128; - acl = [ { - rule = "allow"; - users = [ "greg" ]; - } ]; - } ]; - usersFile = "/run/agenix/3proxy"; - denyPrivate = false; - }; - age.secrets."3proxy" = { - file = ../../secrets/3proxy.age; - mode = "777"; - }; - networking.firewall.allowedTCPPorts = [ 3128 ]; -} diff --git a/hosts/2maccabees/vhosts.nix b/hosts/2maccabees/vhosts.nix deleted file mode 100644 index 1a2fd22..0000000 --- a/hosts/2maccabees/vhosts.nix +++ /dev/null @@ -1,15 +0,0 @@ -# Virtual hosts that don't seem to have any better place to live should go in here. -# There are others that are specific to their own purposese scattered about in the -# configuration in places where they more naturally live. This is more of a catchall -# for ones that do not have a better place to live -{ ... }: - -{ - greg.proxies."dns.thehellings.lan" = { - target = "http://127.0.0.1:8384/"; - path = "/sync/"; - }; - - # The module doesn't handle this - services.nginx.virtualHosts."dns.thehellings.lan".serverAliases = [ "dns" ]; -}