diff --git a/.gitattributes b/.gitattributes index 6d34fee..6f6b429 100644 --- a/.gitattributes +++ b/.gitattributes @@ -1,3 +1,4 @@ #pattern filter=crypt diff=crypt **/*.crypt filter=crypt diff=crypt home/ssh/id_rsa* filter=crypt diff=crypt +hosts/linode/ssh/id_* filter=crypt diff=crypt diff --git a/configuration.nix b/configuration.nix new file mode 100644 index 0000000..f860526 --- /dev/null +++ b/configuration.nix @@ -0,0 +1,120 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page +# and in the NixOS manual (accessible by running ‘nixos-help’). + +{ config, pkgs, ... }: + +{ + imports = + [ # Include the results of the hardware scan. + ./hardware-configuration.nix + ./modules/automatic/nix.nix + ]; + + # Bootloader. + boot.loader.systemd-boot.enable = true; + boot.loader.efi.canTouchEfiVariables = true; + boot.loader.efi.efiSysMountPoint = "/boot/efi"; + + networking.hostName = "lappy"; # Define your hostname. + # networking.wireless.enable = true; # Enables wireless support via wpa_supplicant. + + # Configure network proxy if necessary + # networking.proxy.default = "http://user:password@proxy:port/"; + # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain"; + + # Enable networking + networking.networkmanager.enable = true; + + # Set your time zone. + time.timeZone = "America/Chicago"; + + # Select internationalisation properties. + i18n.defaultLocale = "en_US.utf8"; + + # Enable the X11 windowing system. + services.xserver.enable = true; + + # Enable the GNOME Desktop Environment. + services.xserver.displayManager.gdm.enable = true; + services.xserver.desktopManager.gnome.enable = true; + + # Configure keymap in X11 + services.xserver = { + layout = "us"; + xkbVariant = ""; + }; + + # Enable CUPS to print documents. + services.printing.enable = true; + + # Enable sound with pipewire. + sound.enable = true; + hardware.pulseaudio.enable = false; + security.rtkit.enable = true; + services.pipewire = { + enable = true; + alsa.enable = true; + alsa.support32Bit = true; + pulse.enable = true; + # If you want to use JACK applications, uncomment this + #jack.enable = true; + + # use the example session manager (no others are packaged yet so this is enabled by default, + # no need to redefine it in your config for now) + #media-session.enable = true; + }; + + # Enable touchpad support (enabled default in most desktopManager). + # services.xserver.libinput.enable = true; + + # Define a user account. Don't forget to set a password with ‘passwd’. + users.users.greg = { + isNormalUser = true; + description = "Greg Hellings"; + extraGroups = [ "networkmanager" "wheel" ]; + packages = with pkgs; [ + firefox + # thunderbird + ]; + }; + + # Allow unfree packages + nixpkgs.config.allowUnfree = true; + + # List packages installed in system profile. To search, run: + # $ nix search wget + environment.systemPackages = with pkgs; [ + git + vim # Do not forget to add an editor to edit configuration.nix! The Nano editor is also installed by default. + wget + ]; + + # Some programs need SUID wrappers, can be configured further or are + # started in user sessions. + # programs.mtr.enable = true; + # programs.gnupg.agent = { + # enable = true; + # enableSSHSupport = true; + # }; + + # List services that you want to enable: + + # Enable the OpenSSH daemon. + # services.openssh.enable = true; + + # Open ports in the firewall. + # networking.firewall.allowedTCPPorts = [ ... ]; + # networking.firewall.allowedUDPPorts = [ ... ]; + # Or disable the firewall altogether. + # networking.firewall.enable = false; + + # This value determines the NixOS release from which the default + # settings for stateful data, like file locations and database versions + # on your system were taken. It‘s perfectly fine and recommended to leave + # this value at the release version of the first install of this system. + # Before changing this value read the documentation for this option + # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). + system.stateVersion = "22.05"; # Did you read the comment? + +} diff --git a/flake.nix b/flake.nix index b5a6d1c..a311e78 100644 --- a/flake.nix +++ b/flake.nix @@ -23,7 +23,6 @@ { nixpkgs.overlays = [ nurpkgs.overlay local_overlay ]; } agenix.nixosModule ./modules - ./profiles/base ./hosts/${hostname} home-manager.nixosModules.home-manager { home-manager.useGlobalPkgs = true; @@ -60,6 +59,8 @@ "jude" = machine "x86_64-linux" "jude"; + "lappy" = machine "x86_64-linux" "lappy"; + "iso" = machine "x86_64-linux" "iso"; }; diff --git a/hardware-configuration.nix b/hardware-configuration.nix new file mode 100644 index 0000000..19de254 --- /dev/null +++ b/hardware-configuration.nix @@ -0,0 +1,39 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "ehci_pci" "ahci" "usb_storage" "sd_mod" "sr_mod" "rtsx_usb_sdmmc" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/63bcc80e-0501-4aef-bb58-30bb83881055"; + fsType = "ext4"; + }; + + fileSystems."/boot/efi" = + { device = "/dev/disk/by-uuid/C617-B2B1"; + fsType = "vfat"; + }; + + swapDevices = + [ { device = "/dev/disk/by-uuid/bc4f24a3-5969-4bcb-95f4-f80109e36ebb"; } + ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.enp7s0.useDHCP = lib.mkDefault true; + # networking.interfaces.wlp6s0.useDHCP = lib.mkDefault true; + + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/home/gui/chat.nix b/home/gui/chat.nix index 3441407..ffc9f8b 100644 --- a/home/gui/chat.nix +++ b/home/gui/chat.nix @@ -1,5 +1,8 @@ { pkgs, ... }: { - home.packages = [ pkgs.element-desktop pkgs.nheko ]; + home.packages = with pkgs; [ + element-desktop + nheko + ]; } diff --git a/home/gui/default.nix b/home/gui/default.nix index 4ee5a48..8ce60ed 100644 --- a/home/gui/default.nix +++ b/home/gui/default.nix @@ -9,6 +9,10 @@ home.packages = with pkgs; [ bitwarden + gnucash + handbrake onlyoffice-bin + synology-drive-client + vlc ]; } diff --git a/home/home.nix b/home/home.nix index 50b7f6f..b9e007d 100644 --- a/home/home.nix +++ b/home/home.nix @@ -18,7 +18,11 @@ in { home.stateVersion = "22.05"; - home.packages = [ - pkgs.hms + home.packages = with pkgs; [ + cdrtools + ffmpeg + hms + libtheora + x265 ]; } diff --git a/hosts/jude/default.nix b/hosts/jude/default.nix index d85e8a1..3d80293 100644 --- a/hosts/jude/default.nix +++ b/hosts/jude/default.nix @@ -8,6 +8,7 @@ ./printing.nix ./virt.nix ]; + programs.steam.enable = true; networking.hostName = "jude"; greg.tailscale.enable = true; greg.gnome.enable= true; diff --git a/hosts/lappy/default.nix b/hosts/lappy/default.nix new file mode 100644 index 0000000..fb9dd7e --- /dev/null +++ b/hosts/lappy/default.nix @@ -0,0 +1,15 @@ +{ ... }: + +{ + imports = [ + ./hardware-configuration.nix + ]; + # Bootloader. + boot.loader.systemd-boot.enable = true; + boot.loader.efi.canTouchEfiVariables = true; + boot.loader.efi.efiSysMountPoint = "/boot/efi"; + # Graphics, please + greg.gnome.enable = true; + # Set host name + networking.hostName = "lappy"; +} diff --git a/hosts/lappy/hardware-configuration.nix b/hosts/lappy/hardware-configuration.nix new file mode 100644 index 0000000..19de254 --- /dev/null +++ b/hosts/lappy/hardware-configuration.nix @@ -0,0 +1,39 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/installer/scan/not-detected.nix") + ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "ehci_pci" "ahci" "usb_storage" "sd_mod" "sr_mod" "rtsx_usb_sdmmc" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/63bcc80e-0501-4aef-bb58-30bb83881055"; + fsType = "ext4"; + }; + + fileSystems."/boot/efi" = + { device = "/dev/disk/by-uuid/C617-B2B1"; + fsType = "vfat"; + }; + + swapDevices = + [ { device = "/dev/disk/by-uuid/bc4f24a3-5969-4bcb-95f4-f80109e36ebb"; } + ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.enp7s0.useDHCP = lib.mkDefault true; + # networking.interfaces.wlp6s0.useDHCP = lib.mkDefault true; + + hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; +} diff --git a/hosts/linode/default.nix b/hosts/linode/default.nix index ae0a13c..a947538 100644 --- a/hosts/linode/default.nix +++ b/hosts/linode/default.nix @@ -11,6 +11,7 @@ greg.home = false; greg.linode.enable = true; greg.tailscale.enable = true; + greg.backup.key = ./ssh/id_ed25519; networking.hostName = "linode"; networking.domain = "thehellings.com"; } diff --git a/hosts/linode/nextcloud.nix b/hosts/linode/nextcloud.nix index 068ec5a..9a87315 100644 --- a/hosts/linode/nextcloud.nix +++ b/hosts/linode/nextcloud.nix @@ -25,9 +25,9 @@ enableACME = true; }; - services.syncthing.folders."nextcloud-backup" = { - path = "${config.services.nextcloud.datadir}"; - enable = true; - devices = [ "nas" ]; + greg.backup.jobs.nextcloud = { + src = "/var/lib/nextcloud"; + dest = "nextcloud-backup"; + user = "nextcloud"; }; } diff --git a/hosts/linode/postgres.nix b/hosts/linode/postgres.nix index 319c962..fd2da32 100644 --- a/hosts/linode/postgres.nix +++ b/hosts/linode/postgres.nix @@ -31,23 +31,27 @@ root root postgres enable = true; databases = [ "nextcloud" - "matrix-synapse" + "synapse" ]; }; services.logrotate = { enable = true; settings = { - postgres = { + postgresBackup = { enable = true; files = "${config.services.postgresqlBackup.location}/*.gz"; }; + postgresLog = { + enable = true; + files = "/var/lib/postgresql/*/log/*.log"; + }; }; }; - services.syncthing.folders."postgres-backups" = { - path = "${config.services.postgresqlBackup.location}"; - enable = true; - devices = [ "nas" ]; + greg.backup.jobs.postgresql = { + src = "/var/backup/postgresql"; + dest = "linode-postgres"; + user = "postgres"; }; } diff --git a/hosts/linode/ssh/id_ed25519 b/hosts/linode/ssh/id_ed25519 new file mode 100644 index 0000000..5cf4acf --- /dev/null +++ b/hosts/linode/ssh/id_ed25519 @@ -0,0 +1,9 @@ +U2FsdGVkX1+5xhF/T+xJUHDp5c4sT1d0SHp/bwqJ0WXOsiCv7pGNuDBVV1rhItct +tRnfR7OKwrfK7DXFCTNJkcYhnNwma8ZBurmFCwMpAC6sXGhEIoxHNkWezjlGnZja +k1cVx8R17Eg4/3jzKPyaCGv1kZ9Nhxg8aHtXP5ow2e6C0dzkQaq3j9QEVjRUm+tf +JY4Aetg+ySXvKVfdj0JnSkAu4k8IznxzEqzkdF7gcTdiYJo54VQXzupAjwe6BBrh ++ncgfBWaFOfq9Jiawh8HFFm48cOwsKh3+18itI9t8snhyANFj3pFiTsoCZBdYIxR +UwbfcRjDsyplCpwQNZaioe3bh/UMOZsFrUm4Ch8kR6nbJjfonl4nmnrSLHCY9lrn +QWscukwrLcwsAh4B0q0bhUPa3qCj9KQyml/iSKbOboIigbPu9IhFCP23POnFl0Rc +ehf+WQ+xtu49YPbvGjn6lhklHMDlJAM3HGp+/7c0b0VQ98ZzRBjqmIsrDmVKR9ba +1lVm6C+ootFhXrTrejFh4zmMSynL3P179d9O0936uY4= diff --git a/hosts/linode/ssh/id_ed25519.pub b/hosts/linode/ssh/id_ed25519.pub new file mode 100644 index 0000000..26d8d1d --- /dev/null +++ b/hosts/linode/ssh/id_ed25519.pub @@ -0,0 +1,3 @@ +U2FsdGVkX1/RfYko8CbloOVbd2J9+eCw/UuUw8YJ0Rm/G/yUZNeLU2yngUky/vsk +XxXZBVO+ScNGwgzvb4iDqx01szQtrT8cIpkhaetyUY11CLEgPr8fbcHX/XOfGctV +bUnljF9ubnNcmRzAzXjsfQ== diff --git a/modules/automatic.nix b/modules/automatic.nix new file mode 100644 index 0000000..b8f2f38 --- /dev/null +++ b/modules/automatic.nix @@ -0,0 +1,12 @@ +{ ... }: + +{ + imports = [ + ./automatic/nix.nix + ./automatic/programs.nix + ./automatic/syncthing.nix + ./automatic/users.nix + ]; + # I am a fan of network manager, myself + networking.networkmanager.enable = true; +} diff --git a/profiles/base/nix.nix b/modules/automatic/nix.nix similarity index 93% rename from profiles/base/nix.nix rename to modules/automatic/nix.nix index 3a964da..3d71a48 100644 --- a/profiles/base/nix.nix +++ b/modules/automatic/nix.nix @@ -20,4 +20,5 @@ keep-derivations = true autoOptimiseStore = true; }; nixpkgs.config.allowUnfree = true; + system.stateVersion = "22.05"; } diff --git a/profiles/base/programs.nix b/modules/automatic/programs.nix similarity index 100% rename from profiles/base/programs.nix rename to modules/automatic/programs.nix diff --git a/profiles/base/syncthing.nix b/modules/automatic/syncthing.nix similarity index 80% rename from profiles/base/syncthing.nix rename to modules/automatic/syncthing.nix index dc46abc..1bd8471 100644 --- a/profiles/base/syncthing.nix +++ b/modules/automatic/syncthing.nix @@ -10,9 +10,9 @@ in { services.syncthing = { enable = true; - user = "root"; - group = "root"; - dataDir = "/root/sync"; + user = "greg"; + group = "users"; + dataDir = "/home/greg/sync"; devices = { nas = { addresses = [ @@ -35,5 +35,12 @@ in id = "ROZPUG5-G4IAXYA-JNRQXRD-5PFU2BQ-WVJTOGZ-DFMGJ5E-Q4IGXCJ-JHSNDQ6"; }; }; + folders = { + "mkrvy-tc6x9" = { + path = "/home/greg/drive"; + enable = true; + devices = syncs; + }; + }; }; } diff --git a/profiles/base/default.nix b/modules/automatic/users.nix old mode 100755 new mode 100644 similarity index 86% rename from profiles/base/default.nix rename to modules/automatic/users.nix index 5e6b5b9..e9f47a6 --- a/profiles/base/default.nix +++ b/modules/automatic/users.nix @@ -1,16 +1,6 @@ { config, pkgs, agenix, ... }: { - imports = [ - ./nix.nix - ./programs.nix - ./syncthing.nix - ]; - - - # I am a fan of network manager, myself - networking.networkmanager.enable = true; - # Enable the OpenSSH daemon for remote control services.openssh.enable = true; #services.openssh.permitRootLogin = "yes"; @@ -27,21 +17,10 @@ ]; }; - users.users.test = { - isNormalUser = true; - createHome = true; - extraGroups = [ ]; - shell = pkgs.xonsh; - }; - i18n.defaultLocale = "en_US.UTF-8"; console = { font = "Lat2-Terminus16"; keyMap = "us"; }; - - # The set of default values, which allow syou to keep system defaults set - # to a predictable value as you upgrade the system - system.stateVersion = "21.11"; } diff --git a/modules/backup.nix b/modules/backup.nix new file mode 100644 index 0000000..789b059 --- /dev/null +++ b/modules/backup.nix @@ -0,0 +1,107 @@ +{ lib, config, pkgs, ... }: + +let + cfg = config.greg.backup; + backup_key = "backup_keys/id_ed25519"; + + makeJob = name: job: { + paths = job.src; + encryption.mode = "none"; + environment.BORG_RSH = "ssh -i /etc/${backup_key} -o 'StrictHostKeyChecking=no' -o 'UserKnownHostsFile=/dev/null'"; + repo = "ssh://backup@nas.me.ts//volume1/NetBackup/${job.dest}"; + compression = "auto,zstd"; + startAt = "daily"; + + user = job.user; + group = job.group; + preHook = job.pre; + postHook = job.post; + }; + + cronJob = name: job: + let + binName = "backup-${name}"; + script = pkgs.writeShellScriptBin binName '' +exec 1> >(systemd-cat -t $(basename $0)) 2>&1 +set -ex +${job.pre} +${pkgs.rsync}/bin/rsync -avz --delete -e "${pkgs.openssh}/bin/ssh -i /etc/${backup_key} -o 'StrictHostKeyChecking=no' -o 'UserKnownHostsFile=/dev/null'" ${job.src}/* backup@nas.me.ts:/volume1/NetBackup/${job.dest}/ +${job.post} +''; + in { + inherit script; + cron = "0 1 * * * ${job.user} ${script}/bin/${binName}"; + }; + +in with lib; { + options = { + greg.backup = { + key = mkOption { + type = types.path; + description = "SSH key to use"; + default = null; + }; + + jobs = mkOption { + default = {}; + + type = with types; attrsOf (submodule ( + { name, config, options, ... }: + { + options = { + src = mkOption { + type = types.str; + description = "Local path (string form) to backup from"; + }; + + dest = mkOption { + type = types.str; + }; + + user = mkOption { + type = types.str; + default = "root"; + description = "User to run backup as"; + }; + + pre = mkOption { + type = types.str; + default = ""; + description = "Commands to run before backup"; + }; + + post = mkOption { + type = types.str; + default = ""; + description = "Commands to run after backup"; + }; + }; + } + )); + }; + }; + }; + + config = let + jobs = attrValues ( mapAttrs cronJob cfg.jobs ); + in mkIf ( ( attrValues cfg.jobs ) != [] ) + { + #services.borgbackup = { + # jobs = mapAttrs makeJob cfg.jobs; + #}; + services.cron = { + enable = true; + systemCronJobs = map (e: e.cron) jobs; + }; + + environment.etc = mkIf ( cfg.key != null ) { + "${backup_key}" = { + user = "nobody"; + mode = "0777"; + source = cfg.key; + }; + }; + + environment.systemPackages = map (e: e.script) jobs; + }; +} diff --git a/modules/default.nix b/modules/default.nix index 2a2d0c4..b766d39 100644 --- a/modules/default.nix +++ b/modules/default.nix @@ -2,6 +2,8 @@ { imports = [ + ./automatic.nix + ./backup.nix ./home.nix ./gnome.nix ./linode.nix diff --git a/modules/gnome.nix b/modules/gnome.nix index 45cd953..b168e8e 100644 --- a/modules/gnome.nix +++ b/modules/gnome.nix @@ -12,13 +12,28 @@ in with lib; { greg.xprograms.enable = true; # Sets up a basic Gnome installation - services.xserver = { - enable = true; - displayManager.gdm.enable = true; - desktopManager.gnome.enable = true; - layout = "us"; - # Trackpad support - libinput.enable = true; + services = { + xserver = { + enable = true; + displayManager.gdm.enable = true; + desktopManager.gnome.enable = true; + layout = "us"; + # Trackpad support + libinput.enable = true; + }; + + udev.packages = with pkgs; [ + gnome3.gnome-settings-daemon + ]; + + pipewire.enable = true; + + # Enablement for Firefox + gnome = { + chrome-gnome-shell.enable = true; + sushi.enable = true; + gnome-online-accounts.enable = true; + }; }; programs.dconf.enable = true; @@ -32,17 +47,11 @@ in with lib; { # Enable some Gnome plugins that I like environment.systemPackages = with pkgs; [ gnome3.adwaita-icon-theme + gnome3.gnome-tweaks + gnome3.dconf-editor gnomeExtensions.appindicator + gnomeExtensions.clipboard-indicator gnomeExtensions.dash-to-dock ]; - - services.udev.packages = with pkgs; [ - gnome3.gnome-settings-daemon - ]; - - services.pipewire.enable = true; - - # Enablement for Firefox - services.gnome.chrome-gnome-shell.enable = true; }; }