chore: remove unused genesis config bits
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin.pkg-adblock_update Build done.
buildbot/nix-build Build done.
Update flake.lock / update-flake-lock (push) Failing after 8s
Update manifest chart versions / update-manifests (push) Successful in 4s
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin.pkg-adblock_update Build done.
buildbot/nix-build Build done.
Update flake.lock / update-flake-lock (push) Failing after 8s
Update manifest chart versions / update-manifests (push) Successful in 4s
This commit is contained in:
@@ -2,29 +2,7 @@
|
|||||||
# your system. Help is available in the configuration.nix(5) man page
|
# your system. Help is available in the configuration.nix(5) man page
|
||||||
# and in the NixOS manual (accessible by running ‘nixos-help’).
|
# and in the NixOS manual (accessible by running ‘nixos-help’).
|
||||||
|
|
||||||
{ lib, pkgs, ... }:
|
{ pkgs, ... }:
|
||||||
|
|
||||||
let
|
|
||||||
adblockUpdate = pkgs.writeShellApplication {
|
|
||||||
name = "adblock-update";
|
|
||||||
runtimeInputs = with pkgs; [
|
|
||||||
curl
|
|
||||||
gnused
|
|
||||||
systemd
|
|
||||||
];
|
|
||||||
text = ''
|
|
||||||
curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts
|
|
||||||
curl -s https://adaway.org/hosts.txt | sed '1,24d' | sed 's/127.0.0.1/0.0.0.0/' >> /etc/adblock_hosts
|
|
||||||
|
|
||||||
# Custom domains that I need to preserve for some reason
|
|
||||||
for f in "segment.com" "segment.io" "branch.io" "dev.visualwebsiteoptimizer.com" "click.discord.com"; do
|
|
||||||
sed -i -e "/''${f}/d" /etc/adblock_hosts # Blocks Trelly content for house investors
|
|
||||||
done
|
|
||||||
|
|
||||||
systemctl restart dnsmasq
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
in
|
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
# Include the results of the hardware scan.
|
# Include the results of the hardware scan.
|
||||||
@@ -35,15 +13,6 @@ in
|
|||||||
greg = {
|
greg = {
|
||||||
home = true;
|
home = true;
|
||||||
gnome.enable = false;
|
gnome.enable = false;
|
||||||
nebula = {
|
|
||||||
enable = true;
|
|
||||||
# genesis IS the routing node for the home LAN — it does not route through itself.
|
|
||||||
# Override the module default (which points at genesis) to avoid a routing loop.
|
|
||||||
unsafeRoutes = [ ];
|
|
||||||
# genesis routes the home LAN (10.42.0.0/16) into the Nebula overlay.
|
|
||||||
# Sign genesis's cert with -subnets '10.42.0.0/16' (see secrets/nebula/README.md).
|
|
||||||
routesSubnet = "10.42.0.0/16";
|
|
||||||
};
|
|
||||||
proxies = {
|
proxies = {
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
@@ -66,22 +35,4 @@ in
|
|||||||
];
|
];
|
||||||
|
|
||||||
networking.hostName = "genesis"; # Define your hostname.
|
networking.hostName = "genesis"; # Define your hostname.
|
||||||
|
|
||||||
systemd = {
|
|
||||||
services.adblock-update = {
|
|
||||||
after = [ "network-online.target" ];
|
|
||||||
requires = [ "network-online.target" ];
|
|
||||||
script = lib.getExe adblockUpdate;
|
|
||||||
serviceConfig.Type = "oneshot";
|
|
||||||
};
|
|
||||||
timers.adblock-update = {
|
|
||||||
wantedBy = [ "multi-user.target" ];
|
|
||||||
after = [ "network-online.target" ];
|
|
||||||
requires = [ "network-online.target" ];
|
|
||||||
timerConfig = {
|
|
||||||
OnCalendar = "daily";
|
|
||||||
Unit = "adblock-update.service";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -25,9 +25,20 @@ let
|
|||||||
];
|
];
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
greg.tailscale = {
|
greg = {
|
||||||
enable = true;
|
nebula = {
|
||||||
tags = [ "home" ];
|
enable = true;
|
||||||
|
# genesis IS the routing node for the home LAN — it does not route through itself.
|
||||||
|
# Override the module default (which points at genesis) to avoid a routing loop.
|
||||||
|
unsafeRoutes = [ ];
|
||||||
|
# genesis routes the home LAN (10.42.0.0/16) into the Nebula overlay.
|
||||||
|
# Sign genesis's cert with -subnets '10.42.0.0/16' (see secrets/nebula/README.md).
|
||||||
|
routesSubnet = "10.42.0.0/16";
|
||||||
|
};
|
||||||
|
tailscale = {
|
||||||
|
enable = true;
|
||||||
|
tags = [ "home" ];
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
# Really, why do I still have to force-disable this crap?
|
# Really, why do I still have to force-disable this crap?
|
||||||
@@ -122,22 +133,6 @@ in
|
|||||||
lan = "lan";
|
lan = "lan";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
prometheus.exporters = {
|
|
||||||
dnsmasq.enable = true;
|
|
||||||
blackbox = {
|
|
||||||
enable = true;
|
|
||||||
openFirewall = true;
|
|
||||||
configFile = pkgs.writeText "blackbox.yml" ''
|
|
||||||
modules:
|
|
||||||
icmp:
|
|
||||||
prober: icmp
|
|
||||||
timeout: 5s
|
|
||||||
icmp:
|
|
||||||
preferred_ip_protocol: ip4
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}; # End of services configuration
|
}; # End of services configuration
|
||||||
|
|
||||||
environment.systemPackages = with pkgs; [
|
environment.systemPackages = with pkgs; [
|
||||||
|
|||||||
@@ -0,0 +1,35 @@
|
|||||||
|
{
|
||||||
|
config,
|
||||||
|
lib,
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
let
|
||||||
|
cfg = config.greg.adblockUpdate;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
|
||||||
|
options.greg.adblockUpdate = {
|
||||||
|
enable = lib.mkEnableOption "Enable auto-update of block list";
|
||||||
|
};
|
||||||
|
|
||||||
|
config = lib.mkIf cfg.enable {
|
||||||
|
systemd = {
|
||||||
|
services.adblock-update = {
|
||||||
|
after = [ "network-online.target" ];
|
||||||
|
requires = [ "network-online.target" ];
|
||||||
|
script = lib.getExe pkgs.adblockUpdate;
|
||||||
|
serviceConfig.Type = "oneshot";
|
||||||
|
};
|
||||||
|
timers.adblock-update = {
|
||||||
|
wantedBy = [ "multi-user.target" ];
|
||||||
|
after = [ "network-online.target" ];
|
||||||
|
requires = [ "network-online.target" ];
|
||||||
|
timerConfig = {
|
||||||
|
OnCalendar = "daily";
|
||||||
|
Unit = "adblock-update.service";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -4,6 +4,7 @@
|
|||||||
|
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
|
./adblock-update.nix
|
||||||
./albyhub.nix
|
./albyhub.nix
|
||||||
./backup.nix
|
./backup.nix
|
||||||
./ceph.nix
|
./ceph.nix
|
||||||
|
|||||||
@@ -0,0 +1,25 @@
|
|||||||
|
{
|
||||||
|
writeShellApplication,
|
||||||
|
curl,
|
||||||
|
gnused,
|
||||||
|
systemd,
|
||||||
|
}:
|
||||||
|
writeShellApplication {
|
||||||
|
name = "adblock-update";
|
||||||
|
runtimeInputs = [
|
||||||
|
curl
|
||||||
|
gnused
|
||||||
|
systemd
|
||||||
|
];
|
||||||
|
text = ''
|
||||||
|
curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts
|
||||||
|
curl -s https://adaway.org/hosts.txt | sed '1,24d' | sed 's/127.0.0.1/0.0.0.0/' >> /etc/adblock_hosts
|
||||||
|
|
||||||
|
# Custom domains that I need to preserve for some reason
|
||||||
|
for f in "segment.com" "segment.io" "branch.io" "dev.visualwebsiteoptimizer.com" "click.discord.com"; do
|
||||||
|
sed -i -e "/''${f}/d" /etc/adblock_hosts # Blocks Trelly content for house investors
|
||||||
|
done
|
||||||
|
|
||||||
|
systemctl restart dnsmasq
|
||||||
|
'';
|
||||||
|
}
|
||||||
@@ -12,6 +12,7 @@ in
|
|||||||
#iso = top.self.nixosConfigurations.iso.config.system.build.isoImage;
|
#iso = top.self.nixosConfigurations.iso.config.system.build.isoImage;
|
||||||
#iso-beta = self.nixosConfigurations.iso-beta.config.system.build.isoImage;
|
#iso-beta = self.nixosConfigurations.iso-beta.config.system.build.isoImage;
|
||||||
aacs = c ./aacs.nix { };
|
aacs = c ./aacs.nix { };
|
||||||
|
adblock_update = c ./adblock_update.nix { };
|
||||||
brew = c ./homebrew.nix { };
|
brew = c ./homebrew.nix { };
|
||||||
create_ssl = c ./create_ssl.nix { };
|
create_ssl = c ./create_ssl.nix { };
|
||||||
gcc-tune = c ./gcc-tune.nix { };
|
gcc-tune = c ./gcc-tune.nix { };
|
||||||
|
|||||||
Reference in New Issue
Block a user