2 Commits
Author SHA1 Message Date
Greg Hellings ec8c826565 chore: fix building
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-zim Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-icdm-root Build done.
2026-04-17 15:54:48 -05:00
Greg Hellings e84e03cd05 chore: move charts into manifests 2026-04-17 15:43:57 -05:00
12 changed files with 170 additions and 257 deletions
Generated
+9 -195
View File
@@ -46,36 +46,12 @@
"type": "github"
}
},
"charts": {
"inputs": {
"flake-utils": "flake-utils",
"haumea": "haumea",
"nix-kube-generators": "nix-kube-generators",
"nixpkgs": "nixpkgs",
"pyproject-build-systems": "pyproject-build-systems",
"pyproject-nix": "pyproject-nix",
"uv2nix": "uv2nix"
},
"locked": {
"lastModified": 1776307304,
"narHash": "sha256-JrIt6c4GPl5V7JFMlv4E78JA+cOVV/akmP0MXCAd7cs=",
"owner": "nix-community",
"repo": "nixhelm",
"rev": "5194fa4b3f8a09d74978057cd9ef70b28a910543",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixhelm",
"type": "github"
}
},
"colmena": {
"inputs": {
"flake-compat": "flake-compat",
"flake-utils": "flake-utils_2",
"flake-utils": "flake-utils",
"nix-github-actions": "nix-github-actions",
"nixpkgs": "nixpkgs_2",
"nixpkgs": "nixpkgs",
"stable": "stable"
},
"locked": {
@@ -249,24 +225,6 @@
}
},
"flake-utils": {
"inputs": {
"systems": "systems_2"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"flake-utils_2": {
"locked": {
"lastModified": 1659877975,
"narHash": "sha256-zllb8aq3YO3h8B/U0/J1WBgAL8EX5yWf5pMj3G0NAmc=",
@@ -281,28 +239,6 @@
"type": "github"
}
},
"haumea": {
"inputs": {
"nixpkgs": [
"charts",
"nixpkgs"
]
},
"locked": {
"lastModified": 1685133229,
"narHash": "sha256-FePm/Gi9PBSNwiDFq3N+DWdfxFq0UKsVVTJS3cQPn94=",
"owner": "nix-community",
"repo": "haumea",
"rev": "34dd58385092a23018748b50f9b23de6266dffc2",
"type": "github"
},
"original": {
"owner": "nix-community",
"ref": "v0.2.2",
"repo": "haumea",
"type": "github"
}
},
"hercules-ci-effects": {
"inputs": {
"flake-parts": [
@@ -406,28 +342,13 @@
"type": "github"
}
},
"nix-kube-generators": {
"locked": {
"lastModified": 1762437901,
"narHash": "sha256-5yuJODagAq+aMXQAT2c0gfXKLqapmA6eUHR33jKNHuU=",
"owner": "farcaller",
"repo": "nix-kube-generators",
"rev": "810dcf792081790648ba9ae705b9a2286115ace8",
"type": "github"
},
"original": {
"owner": "farcaller",
"repo": "nix-kube-generators",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1767767207,
"narHash": "sha256-Mj3d3PfwltLmukFal5i3fFt27L6NiKXdBezC1EBuZs4=",
"lastModified": 1750134718,
"narHash": "sha256-v263g4GbxXv87hMXMCpjkIxd/viIF7p3JpJrwgKdNiI=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "5912c1772a44e31bf1c63c0390b90501e5026886",
"rev": "9e83b64f727c88a7711a2c463a7b16eedb69a84c",
"type": "github"
},
"original": {
@@ -453,22 +374,6 @@
}
},
"nixpkgs_2": {
"locked": {
"lastModified": 1750134718,
"narHash": "sha256-v263g4GbxXv87hMXMCpjkIxd/viIF7p3JpJrwgKdNiI=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "9e83b64f727c88a7711a2c463a7b16eedb69a84c",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_3": {
"locked": {
"lastModified": 1776169885,
"narHash": "sha256-l/iNYDZ4bGOAFQY2q8y5OAfBBtrDAaPuRQqWaFHVRXM=",
@@ -484,7 +389,7 @@
"type": "github"
}
},
"nixpkgs_4": {
"nixpkgs_3": {
"locked": {
"lastModified": 1766025857,
"narHash": "sha256-Lav5jJazCW4mdg1iHcROpuXqmM94BWJvabLFWaJVJp0=",
@@ -522,7 +427,7 @@
"nixpkgs": [
"nixunstable"
],
"systems": "systems_3"
"systems": "systems_2"
},
"locked": {
"lastModified": 1776350339,
@@ -542,7 +447,7 @@
"nurpkgs": {
"inputs": {
"flake-parts": "flake-parts_4",
"nixpkgs": "nixpkgs_3"
"nixpkgs": "nixpkgs_2"
},
"locked": {
"lastModified": 1776350162,
@@ -558,61 +463,10 @@
"type": "github"
}
},
"pyproject-build-systems": {
"inputs": {
"nixpkgs": [
"charts",
"nixpkgs"
],
"pyproject-nix": [
"charts",
"pyproject-nix"
],
"uv2nix": [
"charts",
"uv2nix"
]
},
"locked": {
"lastModified": 1763662255,
"narHash": "sha256-4bocaOyLa3AfiS8KrWjZQYu+IAta05u3gYZzZ6zXbT0=",
"owner": "pyproject-nix",
"repo": "build-system-pkgs",
"rev": "042904167604c681a090c07eb6967b4dd4dae88c",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "build-system-pkgs",
"type": "github"
}
},
"pyproject-nix": {
"inputs": {
"nixpkgs": [
"charts",
"nixpkgs"
]
},
"locked": {
"lastModified": 1764134915,
"narHash": "sha256-xaKvtPx6YAnA3HQVp5LwyYG1MaN4LLehpQI8xEdBvBY=",
"owner": "pyproject-nix",
"repo": "pyproject.nix",
"rev": "2c8df1383b32e5443c921f61224b198a2282a657",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "pyproject.nix",
"type": "github"
}
},
"root": {
"inputs": {
"agenix": "agenix",
"buildbot": "buildbot",
"charts": "charts",
"colmena": "colmena",
"darwin": "darwin_2",
"flake-parts": "flake-parts_2",
@@ -671,21 +525,6 @@
"type": "github"
}
},
"systems_3": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
},
"treefmt-nix": {
"inputs": {
"nixpkgs": [
@@ -707,34 +546,9 @@
"type": "github"
}
},
"uv2nix": {
"inputs": {
"nixpkgs": [
"charts",
"nixpkgs"
],
"pyproject-nix": [
"charts",
"pyproject-nix"
]
},
"locked": {
"lastModified": 1767701098,
"narHash": "sha256-CJhKZnWb3gumR9oTRjFvCg/6lYTGbZRU7xtvcyWIRwU=",
"owner": "pyproject-nix",
"repo": "uv2nix",
"rev": "9d357f0d2ce6f5f35ec7959d7e704452352eb4da",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "uv2nix",
"type": "github"
}
},
"vsext": {
"inputs": {
"nixpkgs": "nixpkgs_4"
"nixpkgs": "nixpkgs_3"
},
"locked": {
"lastModified": 1776310443,
-3
View File
@@ -13,9 +13,6 @@
url = "github:nix-community/buildbot-nix";
inputs.nixpkgs.follows = "nixunstable";
};
charts = {
url = "github:nix-community/nixhelm";
};
colmena.url = "github:zhaofengli/colmena";
darwin = {
url = "github:lnl7/nix-darwin/master";
-7
View File
@@ -1,7 +0,0 @@
{ pkgs, ... }:
{
greg.vscodium.enable = false;
home.packages = with pkgs; [ brew ];
}
+32 -10
View File
@@ -53,9 +53,25 @@
# Network Manager pulls in too many deps
networking = {
extraHosts =
let
onNetwork =
attr: _k: v:
(builtins.hasAttr attr v) && v.${attr} != null;
getIPs =
attr: domain:
(lib.mapAttrsToList (host: v: "${builtins.getAttr attr v} ${host}.${domain}") (
lib.filterAttrs (onNetwork attr) metadata.hosts
));
in
builtins.concatStringsSep "\n" (
(getIPs "ts" "shire-zebra.ts.net")
++ (getIPs "nebulaIp" "nebula.thehellings.com")
++ (getIPs "nebulaIp" "nebula")
++ (getIPs "ip" "thehellings.lan")
);
search = [
"thehellings.lan"
"home"
"nebula.thehellings.com"
];
networkmanager.enable = false;
};
@@ -114,17 +130,23 @@
};
};
security.sudo.extraRules = [
{
users = [ "greg" ];
commands = [
security = {
sudo-rs = {
enable = true;
extraRules = [
{
command = "ALL";
options = [ "NOPASSWD" ];
users = [ "greg" ];
commands = [
{
command = "ALL";
options = [ "NOPASSWD" ];
}
];
}
];
}
];
};
sudo.enable = false;
};
# Define a user account. Don't forget to set a password with passwd.
users.users.greg = {
+5 -1
View File
@@ -18,7 +18,11 @@
boot = {
loader = {
systemd-boot.enable = true;
systemd-boot = {
enable = true;
memtest86.enable = true;
netbootxyz.enable = true;
};
efi.canTouchEfiVariables = true;
};
binfmt.emulatedSystems = [
+33
View File
@@ -0,0 +1,33 @@
apiVersion: v1
kind: Namespace
metadata:
name: external-secrets
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: external-secrets
namespace: external-secrets
spec:
interval: "24h"
url: "https://charts.external-secrets.io/"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: external-secrets
namespace: external-secrets
spec:
interval: 10m
chart:
spec:
chart: external-secrets
version: "2.3.0"
sourceRef:
kind: HelmRepository
name: external-secrets
interval: "1h"
values:
crds:
create: true
includeCRDs: true
+3
View File
@@ -1,3 +1,6 @@
resources:
- kyverno.yaml
- external-secrets.yaml
- tailscale.yaml
- longhorn.yaml # Needed for storage
- traefik.yaml
+40
View File
@@ -0,0 +1,40 @@
apiVersion: v1
kind: Namespace
metadata:
name: kyverno-system
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: kyverno
namespace: kyverno-system
spec:
interval: "24h"
url: "https://kyverno.github.io/kyverno/"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: kyverno
namespace: kyverno-system
spec:
interval: 10m
chart:
spec:
chart: kyverno
version: "1.17.1"
sourceRef:
kind: HelmRepository
name: kyverno
interval: "1h"
values:
admissionController:
replicas: 3
backgroundController:
replicas: 3
cleanupController:
replicas: 2
reportsController:
replicas: 2
crds:
install: true
+5
View File
@@ -19,6 +19,11 @@ metadata:
namespace: longhorn-system
spec:
interval: 10m
dependsOn:
- name: tailscale-operator
namespace: tailscale
- name: kyverno
namespace: kyverno
chart:
spec:
chart: longhorn
@@ -1,3 +1,36 @@
apiVersion: v1
kind: Namespace
metadata:
name: tailscale
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: tailscale
namespace: tailscale
spec:
interval: "24h"
url: "https://pkgs.tailscale.com/helmcharts"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: tailscale
namespace: tailscale
spec:
interval: 10m
dependsOn:
- name: external-secrets
namespace: external-secrets
chart:
spec:
chart: tailscale-operator
version: "1.96.5"
sourceRef:
kind: HelmRepository
name: tailscale
interval: "1h"
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
-39
View File
@@ -2,7 +2,6 @@
config,
lib,
pkgs,
top,
...
}:
let
@@ -86,43 +85,6 @@ in
services = {
k3s = {
enable = true;
autoDeployCharts = {
external-secrets = {
inherit (top.charts.chartsMetadata.external-secrets.external-secrets) repo version;
enable = true;
name = top.charts.chartsMetadata.external-secrets.external-secrets.chart;
hash = "sha256-dPuUWthwN6L0jdAKRpkDtDedGyDUxUlJrwkvUNwLsrU=";
createNamespace = true;
targetNamespace = "external-secrets";
values = {
crds.create = true;
includeCRDs = true;
};
};
kyverno = {
inherit (top.charts.chartsMetadata.kyverno.kyverno) repo version;
enable = true;
name = top.charts.chartsMetadata.kyverno.kyverno.chart;
hash = "sha256-sNdFEupwfnYSo2iGqKwTadPtXfcbyM1kuisavpiGUyU=";
createNamespace = true;
targetNamespace = "kyverno-system";
values = {
admissionController.replicas = 3;
backgroundController.replicas = 3;
cleanupController.replicas = 2;
reportsController.replicas = 2;
crds.install = true;
};
};
tailscale = {
inherit (top.charts.chartsMetadata.tailscale.tailscale-operator) repo version;
enable = true;
name = top.charts.chartsMetadata.tailscale.tailscale-operator.chart;
hash = "sha256-BtZ24mCT2GMHE9iR+2xuIkB+4m1r2OC3WLkY3jC3i3I=";
createNamespace = true;
targetNamespace = "tailscale";
};
};
extraFlags = [
"--cluster-cidr=10.211.0.0/16"
"--service-cidr=10.221.0.0/16"
@@ -138,7 +100,6 @@ in
cert-manager.source = cert-manager;
flux.source = flux;
node-annotations.source = ../../manifests/auto/nodes.yaml;
operator-oauth.source = ../../manifests/auto/operator-oauth.yaml;
};
role = if cfg.agentOnly then "agent" else "server";
serverAddr = lib.mkIf (
+10 -2
View File
@@ -77,6 +77,10 @@
"external": true,
"system": "aarch64-darwin"
},
"lithic": {
"external": true,
"system": "aarch64-darwin"
},
"linode": {
"ip": null,
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMv9Zud3kZOl86gtmkn+uj3D4kiXWDPtyUL02VVLNR4Q",
@@ -85,13 +89,17 @@
"tags": ["public", "server"],
"nebulaIp": "10.157.0.1"
},
"ivr": {
"external": true,
"system": "aarch64-darwin"
},
"MacBook-Pro.local": {
"external": true,
"system": "aarc64-darwin"
"system": "aarch64-darwin"
},
"MacBook-Prolocal.local": {
"external": true,
"system": "aarc64-darwin"
"system": "aarch64-darwin"
},
"nas1": {
"external": true,