202 Commits
Author SHA1 Message Date
Greg Hellings a00773c97a fix: remove builder2
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-08-06 22:53:34 -05:00
Greg Hellings 6bf0bcc0ef fix: restore immich access
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-builder2 Build done.
buildbot/nix-build Build done.
2026-08-06 21:43:28 -05:00
Greg Hellings 7619bf6258 chore: default actions packages 2026-08-06 20:36:41 -05:00
Greg Hellings 029b71d0d4 Pass traffic through genesis
* keepalived does not work with Nebula VPN
* update Genesis firewall to allow passing through local traffic
* target all traffic directly to the LAN IP using genesis's routing
2026-08-05 22:57:58 -05:00
Greg Hellings d779d275f2 Expose kubernetes on LAN 2026-08-05 20:07:35 -05:00
Greg Hellings 0196f1fd07 chore: re-enable linode gitea-runner
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-builder2 Build done.
buildbot/nix-build Build done.
2026-08-04 10:14:56 -05:00
Greg Hellings 6a13d843d7 chore: point homepage to new registry url
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-builder2 Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
buildbot/nix-build Build done.
2026-08-04 09:26:28 -05:00
Greg Hellings 8673d6193b chore: immich backup to Garage 2026-08-04 09:19:53 -05:00
Greg Hellings bbdfe1e1de chore: update Gitea to backup to Garage 2026-08-03 20:46:48 -05:00
Greg Hellings 71486e9ab3 chore: update Longhorn version 2026-08-03 20:46:20 -05:00
Greg Hellings 8a8664287f chore: remove gitea-runner 2026-08-03 18:56:23 -05:00
Greg Hellings 4965d42e59 chore: remove smokeping and donetick from k8s 2026-08-03 18:55:07 -05:00
Greg Hellings 03e174367d chore: uptimekuma migrated to NixOS 2026-08-03 18:52:01 -05:00
Greg Hellings 21cb84ac7a Major update for linode and Nebula
* Consolidate Linode into a single file
* Convert gitea and matrix to using Nebula connections
* Have Linode proxy to Nebula connections instead of Tailscale
* Update Acme to use DNS-01
* Update Flake to pull from branch that supports ACME 5.x client
2026-08-01 14:38:01 -05:00
Greg Hellings 1c52f8a6b9 chore: baseline nixos for proxmox configuration 2026-07-28 22:42:21 -05:00
Greg Hellings d9334a237d chore: first bit of local IP querying 2026-07-28 22:41:01 -05:00
Greg Hellings 93a847c658 chore: get kuma up and running 2026-07-28 22:40:17 -05:00
Greg Hellings b9051d017e chore: add java web start to exodus 2026-07-28 19:50:24 -05:00
Greg Hellings b9dcd227e8 chore: fix wait-forever bug in updater
buildbot/nix-eval Build done. (2 warnings)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-07-27 07:27:34 -05:00
Greg Hellings 2d816d50e0 chore: update zim pins 2026-07-27 07:19:37 -05:00
Greg Hellings 5f951c6c12 chore: fix zims updater
Zims update script has been slightly mangled since nix-prefetch stopped
working.

Now it is updated to use nix-prefetch-url and no longer pulls from the
Torrent sources. That script exports a regular SHA256 hash and not an
SRI signature, so we now convert that to SRI as a second step in the
pre-fetch pipline

Also adding a cron to run the tool every month on the first, in order to
keep it up to date.
2026-07-26 21:36:46 -05:00
Greg Hellings 42efe476db chore: update framework firmware settings 2026-07-26 21:36:46 -05:00
greg 07e85d35ab Merge pull request 'chore: update flake.lock 2026-07-19' (#29) from auto/update-flake-lock-20260719 into main
buildbot/nix-eval Build done. (2 warnings)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-builder2 Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-exodus Build done.
buildbot/nix-build Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/29
2026-07-25 20:54:30 +00:00
Greg Hellings b4ab1bde50 chore: cleanup defunct CA infra
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-07-25 15:49:49 -05:00
Greg Hellings 4e7ca2910a chore: remove compose files that are now unused 2026-07-25 15:48:26 -05:00
Greg Hellings 64a253e9e4 chore: remove proxmoxtemplate entries as well 2026-07-25 15:48:04 -05:00
Greg Hellings e4008a0beb chore: remove icdm-root as well
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux Build done.
2026-07-25 15:45:21 -05:00
Greg Hellings 363098c0a1 chore: remove references to hermes
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
2026-07-25 15:43:27 -05:00
Greg Hellings a07068a4fb chore: remove unused attic reference
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
2026-07-25 15:39:30 -05:00
Greg Hellings ec53199532 chore: remove attic-client 2026-07-25 15:38:40 -05:00
Greg Hellings 389798c4f0 chore: buildbot over Nebula 2026-07-25 15:38:28 -05:00
Greg Hellings 475fe50d19 Expand Nebula
* Add Nebula to Kubernetes node
* Update k3s nodes to support nebula keepalived
* Move external IPs to a separate structure
2026-07-25 15:18:15 -05:00
Greg Hellings 0d1d846884 chore: update deprecated nushell pipe 2026-07-25 13:49:47 -05:00
klaatuandgreg 1d9921f1ae chore: update flake.lock 2026-07-19
buildbot/nix-eval Build done. (2 warnings)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-setup-ssh Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-builder2 Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-icdm-root Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-hermes Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-exodus Build done.
buildbot/nix-build Build done.
2026-07-25 17:06:07 +00:00
Greg Hellings 7388715d30 chore: where possible, use nebula 2026-07-25 12:05:07 -05:00
Greg Hellings b3304c0ef5 chore: migrate to Garage 2026-07-25 11:40:35 -05:00
Greg Hellings e955ea82f3 fix: update hermes secrets
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-07-21 20:50:07 -05:00
Greg Hellings 067c00330b chore: enable Hermes agent Matrix connection
buildbot/nix-eval Build done.
2026-07-21 20:49:26 -05:00
Greg Hellings 60e2450c66 chore: proxy hermes dashboard
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hermes Build done.
2026-07-21 20:04:23 -05:00
Greg Hellings 3185a5a375 chore: add tools to Exodus 2026-07-21 19:21:10 -05:00
Greg Hellings 348a1d7301 fix: get Hermes host built
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hermes Build done.
2026-07-21 19:07:39 -05:00
Greg Hellings 33eda7d2cb chore: add hermes key secret
buildbot/nix-eval Build done.
2026-07-21 18:57:47 -05:00
Greg Hellings 34ca5aec6b chore: add nebluaIps nushell function
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hermes Build done.
buildbot/nix-build Build done.
2026-07-21 17:17:04 -05:00
Greg Hellings d2f7b85283 chore: bring hermes into nebula 2026-07-21 17:16:37 -05:00
Greg Hellings d12ef9faec chore: rekey to add hermes visibility 2026-07-21 16:15:32 -05:00
Greg Hellings 3e60f73251 chore: initial configuration for Hermes
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-hms Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-dockerCompat Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-create_ssl Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-adblock_update Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-gcc-tune Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-inject Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-inject-darwin Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-setup-ssh Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-upgrade-pg-cluster Build done.
2026-07-21 16:11:39 -05:00
Greg Hellings bc986f0e51 chore: add hermes
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-07-21 16:00:52 -05:00
Greg Hellings 214f6a4d2a chore: add bmc IP addresses
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-07-20 08:50:03 -05:00
Greg Hellings 41d02d19ea chore: forward ssh-agent 2026-07-13 20:04:00 -05:00
Greg Hellings 4f79033b04 chore: add Proxmox CT baseline
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-07-13 18:18:54 -05:00
Greg Hellings 9b99b2dd8c chore: bump flake pin
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-adblock_update Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-create_ssl Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-hms Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-upgrade-pg-cluster Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-inject Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-dockerCompat Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-setup-ssh Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-gcc-tune Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux.pkg-inject-darwin Build done.
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-setup-ssh Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-create_ssl Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-brew Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-phet-phet_fr_all.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-hms Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-adblock_update Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikipedia-wikipedia_en_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-gcc-tune Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-inject Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-gutenberg-gutenberg_fr_all.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-inject-darwin Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-vfio_startup Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-vfio_shutdown Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-gutenberg-gutenberg_en_all.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-phet-phet_en_all.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikibooks-wikibooks_fr_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-icdm-root Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-isaiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-iso Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-genesis Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-phet-phet_ht_all.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikibooks-wikibooks_en_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikipedia-wikipedia_fr_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-icdm-root Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-dockerCompat Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-upgrade-pg-cluster Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-qemu-hook Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-proxmoxtemplate Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-aacs Build done.
buildbot/nix-build Build done.
2026-07-07 23:29:53 -05:00
Greg Hellings a145f6ca43 feat: use colima on Lithic
buildbot/nix-eval Build done. (10 warnings)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-07-07 14:16:27 -05:00
Greg Hellings f77f46c4e5 feat: add procps to Darwin baseline 2026-07-07 14:15:59 -05:00
Greg Hellings c2ea5ff472 chore: convert from podman to docker 2026-07-07 14:15:19 -05:00
Greg Hellings 0e972936d3 chore: update macOS settings 2026-07-07 14:15:17 -05:00
Greg Hellings b35004a3ad chore: add ulimit raise to Darwin 2026-07-07 14:14:09 -05:00
Greg Hellings d7e98290c3 chore: add new pve hosts
buildbot/nix-eval Build done. (10 warnings)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-07-07 14:09:05 -05:00
Greg Hellings f5922887bf chore: clean up IP name duplication 2026-07-07 14:08:48 -05:00
Greg Hellings 879230dca7 feat: add nix-index to Exodus 2026-06-26 11:08:43 -05:00
Greg Hellings 1c7e2ff268 feat: rebuild optional targets 2026-06-24 12:49:32 -05:00
Greg Hellings b324ee5352 chore: update bookmarks 2026-06-15 22:43:24 -05:00
Greg Hellings d21cbcb85d feat: podman compat also on mbp
buildbot/nix-eval Build done. (10 warnings)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-06-11 13:13:43 -05:00
Greg Hellings 6a0c87b77d feat: add dockerCompat package from podman
buildbot/nix-eval Build done. (10 warnings)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-06-11 09:20:19 -05:00
Greg Hellings db5ef17dba chore: bump flake version
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-proxmoxtemplate Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-genesis Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-icdm-root Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-06-08 11:28:56 -05:00
Greg Hellings 251f2804c6 chore: transmission to deluge 2026-06-08 11:18:12 -05:00
Greg Hellings c8951f6da8 chore: add build tools
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-06-05 10:39:41 -05:00
Greg Hellings 394c2c2aba chore: arr to NAS
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-06-04 13:31:26 -05:00
Greg Hellings bb7a01f758 fix: point directly to pypi, not through simple
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-06-04 10:24:49 -05:00
Greg Hellings a6b46f9c74 chore: remove unused anubis container
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-06-03 21:02:00 -05:00
Greg Hellings e865d0832e chore: update longhorn and gitea versions 2026-06-01 15:56:06 -05:00
Greg Hellings 307dbbe044 fix: do not claim mastery of TS net
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build started.
2026-05-30 00:24:36 -05:00
Greg Hellings 69651258d6 chore: connect buildbot and gitea by tailscale 2026-05-28 16:57:05 -05:00
Greg Hellings 53c491f537 fix: buildbot domain name 2026-05-26 07:48:39 -05:00
klaatuandGreg Hellings a8ccb1b6ba chore: update flake.lock 2026-05-24
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build started.
2026-05-24 21:30:35 -05:00
rootandGreg Hellings e6217401f9 feat(gitea): add Anubis anti-crawler proxy
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Anubis (https://anubis.techaro.lol) is a lightweight proof-of-work
challenge that protects web services from AI crawlers and scrapers.
2026-05-24 21:25:50 -05:00
Greg Hellings d97fb37f0e chore: update SSH config for home-manager updates
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Update flake.lock / update-flake-lock (push) Successful in 1m46s
Update manifest chart versions / update-manifests (push) Successful in 29s
2026-05-21 13:19:26 -05:00
Greg Hellings 75e71f9ce9 fix: get Matrix running again
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-effects Build done.
buildbot/nix-build Build done.
2026-05-20 03:27:45 -05:00
Greg Hellings 19540ea1da chore: update mariadb-operator version 2026-05-20 03:26:37 -05:00
Greg Hellings 431f78f8af fix: enable minio access for gitea backups 2026-05-19 23:48:34 -05:00
Greg Hellings 95eea6fc26 fix: enable s3 DNS aliases 2026-05-19 23:47:42 -05:00
greg 387a34ffff Merge pull request 'chore: update flake.lock 2026-05-18' (#23) from auto/update-flake-lock-20260518 into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/23
Reviewed-by: klaatu <klaatu@thehellings.com>
2026-05-19 15:16:50 +00:00
greg 37a833887b Merge branch 'main' into auto/update-flake-lock-20260518
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
2026-05-19 07:53:55 +00:00
Greg Hellings a69fc4240a chore: build IVR home config
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-05-19 02:40:33 -05:00
Greg Hellings 15c586fbdb fix: build failures on darwin
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-05-19 02:37:25 -05:00
klaatu 2daf74d134 chore: update flake.lock 2026-05-18
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-hms Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-genesis Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-icdm-root Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-isaiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-icdm-root Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-iso Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-proxmoxtemplate Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-linode Build done.
buildbot/nix-build Build done.
2026-05-18 17:58:09 +00:00
Greg Hellings 1934787e80 chore: create desktop entry for prismlauncher
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-05-18 12:45:52 -05:00
Greg Hellings 2a476a7bfe chore: update refined-storage to release 2026-05-18 12:45:34 -05:00
Greg Hellings e94137ecbf fix: enable colmena building with new overlays 2026-05-18 12:45:04 -05:00
Greg Hellings d22f543043 chore: update niks3 pin to fix mega file problem 2026-05-18 12:44:34 -05:00
Greg Hellings e5e4a38cf1 chore: begin updating zim updater
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
Update manifest chart versions / update-manifests (push) Successful in 29s
Update flake.lock / update-flake-lock (push) Successful in 2m49s
2026-05-13 11:01:33 -05:00
Greg Hellings 89faa7d97d fix: update SHA hashes 2026-05-13 10:50:26 -05:00
Greg Hellings fc4430e4f1 fix: system build fixes for new package setup 2026-05-13 08:33:48 -05:00
Greg Hellings f735423d98 chore: make zims separate packages
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-icdm-root Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-genesis Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin.hm-gregs-MacBook-Pro-16-inch-Nov-2024 Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin.hm-ivr Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikipedia-wikipedia_ht_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-phet-phet_fr_all.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-phet-phet_en_all.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikiversity-wikiversity_fr_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikibooks-wikibooks_fr_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wiktionary-wiktionary_fr_all_nopic.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikiversity-wikiversity_en_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikibooks-wikibooks_en_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wiktionary-wiktionary_en_all_nopic.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-gutenberg-gutenberg_fr_all.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikisource-wikisource_en_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikisource-wikisource_fr_all_maxi.zim" Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikipedia-wikipedia_fr_all_maxi.zim" Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux."pkg-zim-wikipedia-wikipedia_en_all_maxi.zim" Build done.
2026-05-13 08:06:57 -05:00
Greg Hellings 985dd927c4 chore: move from attic to niks3
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-05-12 21:25:24 -05:00
Greg Hellings 10d6f85b5e chore: update pre-commit
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Update manifest chart versions / update-manifests (push) Successful in 3s
2026-05-10 01:48:45 -05:00
Greg Hellings 85cdfce6a9 fix: use proper runs-on for updates 2026-05-10 01:47:34 -05:00
Greg Hellings e62757cf1c chore: add Ubuntu 26.04 to matrix 2026-05-10 01:42:28 -05:00
Greg Hellings a1fb195bf4 chore: add podman-tui and other goodies
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Update flake.lock / update-flake-lock (push) Failing after 4s
2026-05-07 08:28:44 -05:00
Greg Hellings 9eb9fdec6c chore: try allowing nix darwin builds
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Update flake.lock / update-flake-lock (push) Failing after 3s
Update manifest chart versions / update-manifests (push) Successful in 4s
2026-04-30 17:18:36 -05:00
Greg Hellings a8323e2396 fix: unstick macOS builds for libdrm missing
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-30 16:13:36 -05:00
Greg Hellings 855ab6e277 chore: try forcing build of linux-builder packages
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-30 16:08:23 -05:00
Greg Hellings 2932e9e335 chore: remove vm-gitlab which is no longer in use 2026-04-30 16:06:58 -05:00
Greg Hellings 4940550c62 chore: enable linux-builder on Mac
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-30 14:42:55 -05:00
Greg Hellings 258934a46b chore: update Claude code usage 2026-04-30 14:42:29 -05:00
Greg Hellings 2476be3799 chore: make builder hostname more accessible
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-30 10:09:18 -05:00
Greg Hellings 08111e7a8a chore: add ssh key to remote-builder config 2026-04-30 10:08:57 -05:00
Greg Hellings 99cc8efea0 chore: add builders to darwin baseline
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-30 09:43:46 -05:00
Greg Hellings 09198fda28 Merge branch 'main' of srcpub:greg/nixos 2026-04-30 09:40:34 -05:00
Greg Hellings e16886c62c chore: add mcp-grafana to li 2026-04-30 09:40:25 -05:00
Greg Hellings c939d67cb6 chore: allow genesis to use its own DNS
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-29 16:11:20 -05:00
Greg Hellings 600aa885d4 chore: add minecraft server 2026-04-29 16:10:31 -05:00
Greg Hellings 8efd97599a chore: remove exodus, which is x86 linux
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-29 13:20:04 -05:00
Greg Hellings 686df31049 chore: make garnix builds an array
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-29 13:14:55 -05:00
Greg Hellings c3e3ca84a2 chore: cleanup unused packages on Darwin
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-29 13:02:12 -05:00
Greg Hellings f8cc47614f chore: remove unused genesis config bits
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin.pkg-adblock_update Build done.
buildbot/nix-build Build done.
Update flake.lock / update-flake-lock (push) Failing after 8s
Update manifest chart versions / update-manifests (push) Successful in 4s
2026-04-24 18:56:10 -05:00
Greg Hellings 904754e059 fix: re-enable scheduling on Zeke disk replacement
buildbot/nix-eval Build done.
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-24 06:46:29 -05:00
Greg Hellings 673f9b1f8b chore: expose credentials to Claude
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-setup-ssh Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-icdm-root Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-zeke Build done.
buildbot/nix-build Build done.
2026-04-22 21:59:30 -05:00
Greg Hellings 993385f1db chore: update flake pins 2026-04-22 21:59:16 -05:00
Greg Hellings 088c1a0033 chore: add new uuid for zeke
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-zim Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-icdm-root Build done.
2026-04-22 21:01:42 -05:00
Greg Hellings fcba03f3d0 chore: update Gitea to latest.
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-zim Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-icdm-root Build done.
2026-04-22 20:36:03 -05:00
Greg Hellings 8ba503ca5d chore: upgrade Immich db to PG 18 2026-04-21 16:22:21 -05:00
Greg Hellings 3b78dfec41 chore: add printer to network 2026-04-20 16:18:20 -05:00
Greg Hellings 8509fff746 chore: upgrade from dnsmasq to bind 2026-04-19 01:04:41 -05:00
Greg Hellings fb4c6966af chore: upgrade Nextcloud to 33
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-zim Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-icdm-root Build done.
Update manifest chart versions / update-manifests (push) Successful in 20s
Update flake.lock / update-flake-lock (push) Failing after 15s
2026-04-17 16:01:36 -05:00
Greg Hellings ec8c826565 chore: fix building
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-zim Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-icdm-root Build done.
2026-04-17 15:54:48 -05:00
Greg Hellings e84e03cd05 chore: move charts into manifests 2026-04-17 15:43:57 -05:00
Greg Hellings 2a81d137a8 chore: add linode to new home
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux Build done.
buildbot/nix-build Build done.
2026-04-17 18:42:41 +00:00
Greg Hellings 70934153ac chore: update lock and links 2026-04-16 13:00:36 -05:00
Greg Hellings db475b232f Merge branch 'main' of srcpub:greg/nixos 2026-04-15 13:56:51 -05:00
Greg Hellings 32a75d84cc chore: update locks and add pulumi plugins
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
buildbot/nix-build Build done.
2026-04-15 08:53:28 -05:00
Greg Hellings 640552e260 Revert "chore: update flake pins"
This reverts commit 6d1490bd28.
2026-04-13 17:35:21 -05:00
Greg Hellings b37f597eaa chore: fix pathing 2026-04-13 17:35:01 -05:00
Greg Hellings f8954fd200 fix: correct workflow runner
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
buildbot/nix-build Build done.
2026-04-13 16:08:44 -05:00
Greg Hellings 6d1490bd28 chore: update flake pins 2026-04-13 16:07:23 -05:00
Greg Hellings 234f000756 feat: claude code support 2026-04-13 16:00:26 -05:00
Greg Hellings 14c7f34108 chore: lithic stuff
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build Build done.
Update manifest chart versions / update-manifests (push) Has been cancelled
Update flake.lock / update-flake-lock (push) Has been cancelled
2026-04-08 08:00:35 -05:00
Greg Hellings f354c3f353 chore: add mcp servers and claude code
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build Build done.
2026-04-07 08:43:30 -05:00
Greg Hellings c0a0c64425 feat: add ~/.local/bin/ to nushell PATH
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-darwin Build done.
buildbot/nix-build gitea:greg/nixos#checks.aarch64-linux Build done.
buildbot/nix-build Build done.
2026-04-06 16:50:06 -05:00
Greg Hellings 05f3f118ac fix: simplify inject-darwin 2026-04-06 16:24:53 -05:00
Greg Hellings 21dbcb3113 feat: aws-cli and cargo on lithic 2026-04-06 16:23:03 -05:00
Greg Hellings 6b7f54d0a2 feat: pull dynamic names for Darwin/Home 2026-04-06 16:21:02 -05:00
Greg Hellings 0d70a9e018 feat: add li host
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-06 08:43:41 -05:00
Greg Hellings aee34e5b86 feat: more bookmarks 2026-04-05 20:03:51 -05:00
Greg Hellings 0460014b75 feat: Add minio-client and Discord to Exodus
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-05 19:45:36 -05:00
Greg Hellings 84d050fb0c fix: remove files before re-upload in Immich backup
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Update manifest chart versions / update-manifests (push) Has been cancelled
2026-04-05 16:52:04 -05:00
Greg Hellings 3847c7d92d fix: streamline Gitea runners 2026-04-05 16:51:31 -05:00
klaatu 81936ac524 feat: Gitea Actions shell runners + flake-lock workflow
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-isaiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-zeke Build done.
buildbot/nix-build Build done.
- Add modules/nixos/gitea-runner.nix: NixOS module for act_runner in
  shell mode, with options for enable, instanceURL, name, labels, and
  tokenFile (agenix secret path).
- Deploy gitea-runner to jeremiah, isaiah, zeke, and linode with
  appropriate labels. Agenix secret placeholders left with TODOs.
- Add .gitea/workflows/update-flake-lock.yaml: weekly workflow (Sunday
  midnight) that runs nix flake update and opens a PR if flake.lock
  changed, using GITEA_TOKEN secret for authentication.

Closes part of #15 (NixOS shell runners + flake-lock workflow).
2026-04-05 04:58:27 -05:00
Greg Hellings 45d8154a04 Merge remote-tracking branch 'origin/feat/gitea-actions'
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Update flake.lock / update-flake-lock (push) Has been cancelled
2026-04-04 14:18:22 -05:00
Greg Hellings 03400f1c93 fix: pull correct secrets 2026-04-04 14:14:23 -05:00
greg 603598a3f9 Merge branch 'main' into feat/gitea-actions
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
2026-04-04 19:13:31 +00:00
klaatu 757b07c22f fix: replace placeholder Secret with ExternalSecret via bitwarden-login
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
2026-04-04 19:05:17 +00:00
klaatu b7fba0e151 fix: chart name act_runner -> actions, version 0.2.5 -> 0.0.4 2026-04-04 19:05:06 +00:00
greg 75278cdb6a Merge pull request 'fix: set MC_CONFIG_DIR to /tmp/.mc so mc can write config as non-root' (#20) from klaatu/nixos:fix/mc-config-dir into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/20
Reviewed-by: greg <gitea@local.domain>
2026-04-04 18:23:42 +00:00
klaatu 67f12856e1 fix: set MC_CONFIG_DIR to /tmp/.mc so mc can write config as non-root
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
2026-04-04 18:18:43 +00:00
Greg Hellings 475c0eda64 fix: minio secrets exposed
buildbot/nix-effects Build done.
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
2026-04-04 13:11:31 -05:00
greg 828d61d818 Merge pull request 'feat: backup improvements — AlbyHub Restic, Gitea dump CronJob, Immich → MinIO' (#17) from klaatu/nixos:feature/backup-improvements into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/17
Reviewed-by: greg <gitea@local.domain>
2026-04-04 18:00:16 +00:00
klaatu 0218447008 fix: address review feedback on backup improvements
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
- manifests/gitea/dump-cronjob.yaml: Remove --skip-log, --skip-custom-dir,
  --skip-db flags to make backup complete
- manifests/gitea/dump-cronjob.yaml: Replace NFS volume + cleanup container
  with S3 upload to backup-gitea bucket using MinIO client (mc).
  30-day lifecycle set via mc ilm. Uses minio_key/minio_secret from
  existing gitea-config secret.
- hosts/unstable/hosea/default.nix: Replace raw services.restic.backups.albyhub
  block with greg.backup.jobs.albyhub using the greg.backup module.
  Remove manual age.secrets.restic-env and age.secrets.restic-pw entries
  since the greg.backup module declares them.
2026-04-04 02:05:03 -05:00
klaatu 2741be72c7 feat: add update-manifests workflow
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
2026-04-04 06:18:14 +00:00
klaatu e8beb7f2a9 feat: add update-flake-lock workflow 2026-04-04 06:18:12 +00:00
klaatu b2728bf1de feat: add gitea-runner NixOS module 2026-04-04 06:18:10 +00:00
klaatu d65dcb51a3 feat: add gitea-runner secret placeholder 2026-04-04 06:18:07 +00:00
klaatu 87bc9a21d9 feat: add gitea-runner kustomization 2026-04-04 06:18:04 +00:00
klaatu ca25dde780 feat: add gitea-runner FluxCD HelmRelease 2026-04-04 06:18:01 +00:00
klaatu c61900f9e6 feat: add gitea-runner namespace manifest 2026-04-04 06:17:59 +00:00
klaatu 1077d357ca feat(immich): switch backup to rclone sync → MinIO immich bucket on nas1 2026-04-04 06:13:43 +00:00
klaatu 6b84824a53 feat(gitea): add dump-cronjob to kustomization 2026-04-04 06:13:00 +00:00
klaatu c74d647ec3 feat(gitea): add daily dump CronJob writing to NAS1 NFS 2026-04-04 06:12:56 +00:00
klaatu 58a5c95c32 feat(hosea): add Restic backup for AlbyHub /chain/alby 2026-04-04 06:12:31 +00:00
Greg Hellings 9a26c75884 chore: allow outgoing webhooks
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-03 23:49:27 -05:00
Greg Hellings 276b939252 fix: expose buildbot 2026-04-03 23:49:12 -05:00
greg 3eb44f2958 Merge pull request 'feat: expose Buildbot via nginx proxy on LAN' (#13) from klaatu/nixos:feat/buildbot-proxy into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/13
2026-04-04 03:45:51 +00:00
klaatu 9bbdb74f85 fix: merge conflict — keep both nebula.enable and buildbot proxies
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
2026-04-03 22:18:17 -05:00
greg 35b6058c09 Merge pull request 'feat: Nebula mesh network overlay' (#12) from klaatu/nixos:feat/nebula-mesh into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/12
2026-04-04 03:03:53 +00:00
Greg Hellings 88d9234332 fix: no default routes 2026-04-02 08:11:32 -05:00
root eabead05ab feat: expose Buildbot via nginx proxy on LAN
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
Add greg.proxies entries on jeremiah for buildbot.home and
buildbot.thehellings.lan, both proxying to http://localhost:8010/.
Nginx handles auth passthrough - Buildbot's own Gitea OAuth applies.

Add DNS aliases in genesis hosts file:
- buildbot.thehellings.lan → 10.42.1.8 (LAN)
- buildbot.home → 100.102.186.39 (Tailscale)
2026-04-01 17:31:38 -05:00
Greg Hellings a1bef073cf fix: generate linode certs
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
2026-04-01 17:20:46 -05:00
root f35e8c755c fix: only set listen.port on lighthouse/relay nodes (regular nodes use OS-assigned port 0)
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-proxmoxtemplate Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-zeke Build done.
buildbot/nix-build Build done.
2026-04-01 17:14:12 -05:00
root 71ae25a58c fix: move unsafe_routes to settings.tun.unsafe_routes (correct NixOS nebula option path)
buildbot/nix-eval Build done.
2026-04-01 17:13:37 -05:00
root 0e61efe5b5 fix: rename tun.dev to tun.device (correct NixOS option name)
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-genesis Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-isaiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-jeremiah Build done.
buildbot/nix-build Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-linode Build done.
2026-04-01 17:07:47 -05:00
root 84e4c68f0e fix: move unsafeRoutes to module default, genesis overrides to []
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-genesis Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-isaiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-zeke Build done.
buildbot/nix-build Build done.
Per review feedback:
- nebula module now defaults unsafeRoutes to [{route=10.42.0.0/16 via=10.157.0.2}]
  so all regular nodes get home LAN routing automatically
- genesis overrides unsafeRoutes=[] since it IS the routing node (avoids loop)
- exodus and all k3s nodes (hosea, isaiah, jeremiah, zeke) simplified to
  nebula.enable = true only, relying on the new default
2026-04-01 16:45:59 -05:00
greg 559155d411 Merge branch 'main' into feat/nebula-mesh
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-jeremiah Build done.
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-isaiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-genesis Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
buildbot/nix-build Build done.
2026-04-01 21:36:08 +00:00
Greg Hellings 2bb0177ffa chore: add encrypted keys and unencrypted certs
buildbot/nix-eval Build done.
buildbot/nix-build Build started.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-genesis Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-isaiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-jeremiah Build done.
2026-04-01 16:33:59 -05:00
Greg Hellings 15ed4ae5f7 chore: allow click.discord.com
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-04-01 15:49:32 -05:00
root 792217f640 feat: add Nebula mesh network overlay
buildbot/nix-eval Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-exodus Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-isaiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-genesis Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
buildbot/nix-build Build done.
Introduces a greg.nebula NixOS module and enables it across all managed
hosts for the nebula.thehellings.com overlay (CIDR: 10.157.0.0/16).

Architecture:
- linode: lighthouse + relay (public internet, UDP 4242)
- genesis: regular node + unsafe_routes router for 10.42.0.0/16 (home LAN)
- hosea, isaiah, jeremiah, zeke, exodus: regular nodes with unsafe_routes
  pointing to genesis to reach the home LAN

Changes:
- modules/nixos/nebula.nix: new greg.nebula module
  - isLighthouse / isRelay options
  - unsafeRoutes option (tun.unsafe_routes)
  - routesSubnet option: enables IP forwarding + nftables masquerade NAT
    on the gateway host (genesis) so Nebula peers reach 10.42.0.0/16
  - agenix secret reference per-host (secrets/nebula/<name>.key.age)
  - opens UDP/4242 in the firewall
- modules/nixos/default.nix: import nebula.nix
- hosts/unstable/linode/default.nix: greg.nebula.isLighthouse = true
- hosts/unstable/genesis/default.nix: greg.nebula.routesSubnet = "10.42.0.0/16"
- hosts/unstable/{hosea,isaiah,jeremiah,zeke,exodus}/default.nix:
  greg.nebula.enable = true with unsafeRoutes via genesis
- network.json: add nebulaIp field for each managed host
- secrets/secrets.nix: declare nebula/<host>.key.age entries
- secrets/nebula/README.md: full PKI bootstrap guide (CA, certs, agenix)
2026-03-28 23:24:52 -05:00
greg ba1914e48c Merge pull request 'feat: add top-5 fullest PVs panel to Kubernetes dashboard' (#11) from klaatu/nixos:feat/k8s-volume-dashboard into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/11
2026-03-27 15:25:44 +00:00
root 07b3601206 feat: add top-5 fullest PVs panel to Kubernetes dashboard
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
Add a horizontal bar gauge showing the disk usage % of the 5 most-full
PersistentVolumes in the cluster, using kubelet volume stats already
scraped by Prometheus:

  topk(5, kubelet_volume_stats_used_bytes
           / kubelet_volume_stats_capacity_bytes * 100)

Labels show namespace/PVC name. Color thresholds: green <70%, yellow
70–90%, red >90%. Placed at the bottom of the dashboard (y=46).

Bump dashboard version to 3.
2026-03-27 09:06:19 -05:00
Greg Hellings 93458eb6d4 chore: slight updates to Network dashboard
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-03-27 09:03:07 -05:00
greg 6f7b3c238e Merge pull request 'fix: correct unpoller metric names in Network & UniFi dashboard' (#10) from klaatu/nixos:fix/network-dashboard-metrics into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/10
Reviewed-by: greg <gitea@local.domain>
2026-03-27 13:51:18 +00:00
root de0b8fb07e fix: correct unpoller metric names in network dashboard
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
All metrics had wrong prefix (unifipoller_ → unpoller_) and several
had incorrect names entirely. Corrected against unpoller master source
(pkg/promunifi/):

- unifipoller_device_uptime_seconds → unpoller_device_uptime_seconds
- unifipoller_port_receive_bytes_total → unpoller_device_port_receive_bytes_total
  (port metrics live under device_ namespace: unpoller_device_port_*)
- unifipoller_port_transmit_bytes_total → unpoller_device_port_transmit_bytes_total
- unifipoller_device_wan_receive_bytes_total → unpoller_wan_max_rx_bytes_rate
  (no per-device WAN bytes total counter; WAN ns is unpoller_wan_*;
   rate metrics are already instantaneous gauges, no rate() wrapper)
- unifipoller_device_wan_transmit_bytes_total → unpoller_wan_max_tx_bytes_rate
- unifipoller_client_wifi_tx_rate_bps → count(unpoller_client_uptime_seconds{wired="false"})
  (no wifi-specific rate metric; wired label distinguishes client types)
- unifipoller_client_wired_tx_rate_bps → count(unpoller_client_uptime_seconds{wired="true"})
- unifipoller_client_receive_bytes_total → unpoller_client_receive_bytes_total
- unifipoller_client_transmit_bytes_total → unpoller_client_transmit_bytes_total

Bump dashboard version to 3.
2026-03-27 08:44:12 -05:00
greg 3111548c99 Merge pull request 'feat: kube-state-metrics, Restic ExternalSecret, updated dashboards' (#9) from klaatu/nixos:fix/observability-complete into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/9
Reviewed-by: greg <gitea@local.domain>
2026-03-27 13:27:30 +00:00
Greg Hellings 841224b20f fix: update external-secrets apiVersion
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
2026-03-27 08:27:03 -05:00
klaatuandGreg Hellings 45536f4a8d feat: update kubernetes and network Grafana dashboards
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
2026-03-27 08:19:45 -05:00
klaatuandGreg Hellings 4717763fed feat: add restic ExternalSecret for Prometheus basic auth 2026-03-27 08:19:45 -05:00
klaatuandGreg Hellings 53f33eb13a feat: add kube-state-metrics 2026-03-27 08:19:45 -05:00
klaatuandGreg Hellings b18807b1ef feat: add kube-state-metrics.yaml and restic-secret.yaml to kustomization 2026-03-27 08:19:45 -05:00
klaatuandGreg Hellings 2c0b4b1472 feat: add kube_state_metrics job, restic basic_auth, remove kea job 2026-03-27 08:19:40 -05:00
klaatuandGreg Hellings d713e5104c feat: mount restic-credentials secret into Prometheus 2026-03-27 08:18:53 -05:00
Greg Hellings e9a4662620 fix: open kubelet/cadvisor prometheus ports
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-03-26 05:58:52 -05:00
Greg Hellings eba1a0c1ca fix: make restic https 2026-03-26 05:56:21 -05:00
Greg Hellings 4eb5d6873a chore: remove unused kea configuration
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-03-26 05:45:16 -05:00
greg 71f553a6f2 Merge pull request 'fix: add missing shire-zebra.ts.net DNS entries; update exodus Tailscale IP' (#8) from klaatu/nixos:fix/tailscale-dns-entries into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/8
2026-03-26 02:48:34 +00:00
root 8e218a71e0 fix: add missing shire-zebra.ts.net DNS entries; update exodus Tailscale IP
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
genesis, zeke, linode, and exodus were missing shire-zebra.ts.net
aliases in the genesis dnsmasq hosts file. Only hosea, isaiah,
jeremiah, gitlab, matrix, chronicles, and nas1 had them. Since
genesis is the DNS server for the whole network, Prometheus (and
everything else) couldn't resolve those four hostnames, causing
instant connection failures on scrape.

Also update exodus Tailscale IP from 100.80.99.48 to 100.70.99.91
(stale IP in both network.json and the hosts file).
2026-03-25 21:12:51 -05:00
220 changed files with 4019 additions and 4022 deletions
+51
View File
@@ -0,0 +1,51 @@
name: Update flake.lock
"on":
schedule:
- cron: "0 0 * * 0" # Every Sunday at midnight UTC
workflow_dispatch:
jobs:
update-flake-lock:
runs-on: nix-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Update flake.lock
run: nix flake update
- name: Create PR if changed
env:
GITEA_TOKEN: ${{ secrets.KLAATU_TOKEN }}
GITEA_URL: https://src.thehellings.com
REPO: greg/nixos
run: |
if git diff --quiet flake.lock; then
echo "flake.lock unchanged, nothing to do"
exit 0
fi
BRANCH="auto/update-flake-lock-$(date +%Y%m%d)"
git config user.email "klaatu@thehellings.com"
git config user.name "klaatu"
git checkout -b "$BRANCH"
git add flake.lock
git commit -m "chore: update flake.lock $(date +%Y-%m-%d)"
# Push branch using token auth
git remote set-url origin "https://klaatu:${GITEA_TOKEN}@${GITEA_URL#https://}/${REPO}.git"
git push origin "$BRANCH"
# Create PR via Gitea API
curl -s -X POST \
-H "Authorization: token ${GITEA_TOKEN}" \
-H "Content-Type: application/json" \
"${GITEA_URL}/api/v1/repos/${REPO}/pulls" \
-d "{
\"title\": \"chore: update flake.lock $(date +%Y-%m-%d)\",
\"head\": \"$BRANCH\",
\"base\": \"main\",
\"body\": \"Automated weekly flake.lock update.\\n\\nGenerated by Gitea Actions.\",
\"assignees\": [\"greg\"]
}"
+58
View File
@@ -0,0 +1,58 @@
name: Update manifest chart versions
on:
schedule:
- cron: "0 0 * * 1" # Every Monday at midnight UTC
workflow_dispatch:
jobs:
update-manifests:
runs-on: [bare-metal, nix-latest]
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Scan manifests for chart version updates
run: |
echo "TODO: implement manifest update scanning"
echo ""
echo "Planned implementation:"
echo " 1. Parse each manifests/*/chart.yaml for HelmRelease chart versions"
echo " 2. Query artifact hub or helm repo for latest versions"
echo " 3. Emit a diff of available updates"
echo ""
echo "Scanned manifests directories:"
ls manifests/
- name: Create PR if changes found
env:
GITEA_TOKEN: ${{ secrets.KLAATU_TOKEN }}
GITEA_URL: https://src.thehellings.com
REPO: greg/nixos
run: |
if git diff --quiet; then
echo "No manifest changes, nothing to do"
exit 0
fi
BRANCH="auto/update-manifests-$(date +%Y%m%d)"
git config user.email "klaatu@thehellings.com"
git config user.name "klaatu"
git checkout -b "$BRANCH"
git add manifests/
git commit -m "chore: update manifest chart versions $(date +%Y-%m-%d)"
git remote set-url origin "https://klaatu:${GITEA_TOKEN}@${GITEA_URL#https://}/${REPO}.git"
git push origin "$BRANCH"
curl -s -X POST \
-H "Authorization: token ${GITEA_TOKEN}" \
-H "Content-Type: application/json" \
"${GITEA_URL}/api/v1/repos/${REPO}/pulls" \
-d "{
\"title\": \"chore: update manifest chart versions $(date +%Y-%m-%d)\",
\"head\": \"$BRANCH\",
\"base\": \"main\",
\"body\": \"Automated weekly manifest chart version update.\\n\\nGenerated by Gitea Actions.\",
\"assignees\": [\"greg\"]
}"
+51
View File
@@ -0,0 +1,51 @@
name: Update zims pin
"on":
schedule:
- cron: "0 2 1 * *" # 0200 on the first of every month
workflow_dispatch:
jobs:
update-flake-lock:
runs-on: nix-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Update flake.lock
run: nix run .#zim-updater -- --output pkgs/zim/blobs.json
- name: Create PR if changed
env:
GITEA_TOKEN: ${{ secrets.KLAATU_TOKEN }}
GITEA_URL: https://src.thehellings.com
REPO: greg/nixos
run: |
if git diff --quiet pkgs/zim/blobs.json; then
echo "blobs.json unchanged, nothing to do"
exit 0
fi
BRANCH="auto/update-zims-$(date +%Y%m%d)"
git config user.email "klaatu@thehellings.com"
git config user.name "klaatu"
git checkout -b "$BRANCH"
git add pkgs/zim/blobs.json
git commit -m "chore: update zim blobs.json $(date +%Y-%m-%d)"
# Push branch using token auth
git remote set-url origin "https://klaatu:${GITEA_TOKEN}@${GITEA_URL#https://}/${REPO}.git"
git push origin "$BRANCH"
# Create PR via Gitea API
curl -s -X POST \
-H "Authorization: token ${GITEA_TOKEN}" \
-H "Content-Type: application/json" \
"${GITEA_URL}/api/v1/repos/${REPO}/pulls" \
-d "{
\"title\": \"chore: update zims $(date +%Y-%m-%d)\",
\"head\": \"$BRANCH\",
\"base\": \"main\",
\"body\": \"Automated monthly zims update.\\n\\nGenerated by Gitea Actions.\",
\"assignees\": [\"greg\"]
}"
-23
View File
@@ -1,23 +0,0 @@
stages:
- eval
- build
- push
"Evaluate for builds":
stage: eval
tags:
- kubernetes
image: "$CI_REGISTRY/greg/ci-images/builder:latest"
artifacts:
paths:
- gitlab-ci-continue.yml
script: nix run ".#gen-build" > gitlab-ci-continue.yml
"Trigger builds":
stage: build
trigger:
include:
- artifact: gitlab-ci-continue.yml
job: "Evaluate for builds"
variables:
PARENT_PIPELINE_ID: $CI_PIPELINE_ID
+3 -2
View File
@@ -17,7 +17,7 @@ repos:
- id: mixed-line-ending
- id: trailing-whitespace
- repo: https://github.com/adrienverge/yamllint.git
rev: v1.37.1
rev: v1.38.0
hooks:
- id: yamllint
args:
@@ -30,8 +30,9 @@ repos:
comments: false
comments-indentation: false
document-start: false
line-length: false
- repo: https://github.com/NixOS/nixfmt
rev: v1.1.0
rev: v1.2.0
hooks:
- id: nixfmt-nix
- repo: https://github.com/astro/deadnix
-12
View File
@@ -1,12 +0,0 @@
-----BEGIN CERTIFICATE-----
MIIByDCCAW+gAwIBAgIRANS+dPEH5Vqug7OWhCMmcx4wCgYIKoZIzj0EAwIwLjER
MA8GA1UEChMISGVsbGluZ3MxGTAXBgNVBAMTEEhlbGxpbmdzIFJvb3QgQ0EwHhcN
MjQwMjIwMjEyNzIxWhcNMzQwMjE3MjEyNzIxWjA2MREwDwYDVQQKEwhIZWxsaW5n
czEhMB8GA1UEAxMYSGVsbGluZ3MgSW50ZXJtZWRpYXRlIENBMFkwEwYHKoZIzj0C
AQYIKoZIzj0DAQcDQgAErZUhPfx5MpNbNVyqHDrIgUGnb6Hitl8hXlpH+kgjBzCi
7I/+TQnl9Tc0VVNOFOYLOfBi7hV3/QudUtLGk0FKeaNmMGQwDgYDVR0PAQH/BAQD
AgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFMZR8LDd+hNy+TmtEHvt
zRzXboh2MB8GA1UdIwQYMBaAFAlH11TwIFGB/K75qZ3e0S+fN3JUMAoGCCqGSM49
BAMCA0cAMEQCIBxHK6r8pMX5hrTwYKRfMmRIt44m0KtNejA2T5t09hs+AiBfvmHb
LfoE4qoC6NgpvXorAbx+O7xkem/9svF0Ob+RsA==
-----END CERTIFICATE-----
-11
View File
@@ -1,11 +0,0 @@
-----BEGIN CERTIFICATE-----
MIIBoTCCAUagAwIBAgIRAL/1mvE8+73nRFGsvzaaVSAwCgYIKoZIzj0EAwIwLjER
MA8GA1UEChMISGVsbGluZ3MxGTAXBgNVBAMTEEhlbGxpbmdzIFJvb3QgQ0EwHhcN
MjQwMjIwMjEyNzIwWhcNMzQwMjE3MjEyNzIwWjAuMREwDwYDVQQKEwhIZWxsaW5n
czEZMBcGA1UEAxMQSGVsbGluZ3MgUm9vdCBDQTBZMBMGByqGSM49AgEGCCqGSM49
AwEHA0IABEgNBjlT/7gmzNp9vKJvGPJn9/IizuMGVpucdrN9+J1u1ABkLNRzj5p2
g7s3e/BG+EJnnTf/2tuq3p/wPqmQkdujRTBDMA4GA1UdDwEB/wQEAwIBBjASBgNV
HRMBAf8ECDAGAQH/AgEBMB0GA1UdDgQWBBQJR9dU8CBRgfyu+amd3tEvnzdyVDAK
BggqhkjOPQQDAgNJADBGAiEA/uBclcFCOpkEgAeBAVurktYB82sMdIyyDGHcjlwi
pvkCIQC2kuZ/nXRjibeIebQIVTBskQ1LxlLxnx7zNSjtr3kFfQ==
-----END CERTIFICATE-----
-54
View File
@@ -1,54 +0,0 @@
services:
attic:
container_name: attic
image: ghcr.io/zhaofengli/attic:latest
command: ["-f", "/attic/server.toml"]
restart: unless-stopped
ports:
- 8080:8080
networks:
attic:
pgattic:
volumes:
- /mnt/all/configs/attic/server.toml:/attic/server.toml
- /mnt/all/containers/attic/data:/attic/storage
env_file:
- stack.env
depends_on:
pgattic:
condition: service_healthy
healthcheck:
test:
[
"CMD-SHELL",
"wget --no-verbose --tries=1 --spider http://attic:8080 || exit 1",
]
interval: 15s
timeout: 10s
retries: 10
start_period: 15s
deploy:
resources:
reservations:
cpus: 1.0
pgattic:
container_name: pgattic
image: postgres:17.6-alpine
restart: unless-stopped
ports: []
networks:
pgattic:
volumes:
- /mnt/all/containers/attic/postgres:/var/lib/postgresql/data
env_file:
- stack.env
healthcheck:
test: ["CMD-SHELL", "pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB}"]
interval: 10s
timeout: 5s
retries: 5
networks:
attic:
pgattic:
-9
View File
@@ -1,9 +0,0 @@
services:
pinchflat:
image: ghcr.io/kieraneglin/pinchflat:latest
ports:
- "8945:8945"
volumes:
- "/mnt/all/configs/pinchflat:/config"
- "/mnt/all/video/yt:/downloads"
restart: unless-stopped
-19
View File
@@ -1,19 +0,0 @@
# Demo of rest-server with prometheus and grafana
version: "2"
services:
restserver:
image: "restic/rest-server:0.14.0"
volumes:
- /mnt/all/backups:/data
- /mnt/all/configs/certs:/certs
environment:
OPTIONS: >-
--tls
--tls-cert /certs/nas1.shire-zebra.ts.net.crt
--tls-key /certs/nas1.shire-zebra.ts.net.key
--path /data
--prometheus
--debug
ports:
- "30248:8000"
+55 -26
View File
@@ -1,53 +1,82 @@
{
lib,
pkgs,
pkgs',
top,
...
}:
let
builder-config = {
darwin-aarch-builder = top.self.nixosConfigurations.builder-aarch;
darwin-x86-builder = top.self.nixosConfigurations.builder-x86;
system = builtins.replaceStrings [ "darwin" ] [ "linux" ] pkgs.stdenv.hostPlatform.system;
builderConfig = top.nixunstable.lib.nixosSystem {
inherit system;
modules = [
"${top.nixunstable}/nixos/modules/profiles/nix-builder-vm.nix"
{
virtualisation = {
host.pkgs = pkgs;
darwin-builder = {
workingDirectory = "/var/lib/darwin-builder";
hostPort = 22;
};
};
}
];
};
builder = arch: let
b = builder-config."darwin-${arch}-builder";
in {
command = "${b.config.system.build.macos-builder-installer}/bin/create-builder";
builder = {
command = "${builderConfig.config.system.build.macos-builder-installer}/bin/create-builder";
serviceConfig = {
KeepAlive = true;
RunAtLoad = true;
StandardOutPath = "/var/log/builder-vm-${arch}.log";
StandardErrorPath = "/var/log/builder-vm-${arch}.stderr.log";
StandardOutPath = "/var/log/builder-vm-${system}.log";
StandardErrorPath = "/var/log/builder-vm-${system}.stderr.log";
};
};
in
{
environment.systemPackages = with pkgs; [
hms
];
environment = {
launchDaemons = {
"limit.maxfiles.plist" = {
enable = true;
text = ''
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>Label</key>
<string>limit.maxfiles</string>
<key>ProgramArguments</key>
<array>
<string>launchctl</string>
<string>limit</string>
<string>maxfiles</string>
<string>524288</string>
<string>524288</string>
</array>
<key>RunAtLoad</key>
<true/>
</dict>
</plist>
'';
};
};
systemPackages = with pkgs; [
agenix
pkgs'.hms
procps # Includes tools like `watch`, `kill`, and `ps`
];
};
fonts.packages = with pkgs; [
dejavu_fonts
nerd-fonts.hack
];
launchd.daemons = lib.genAttrs' [ "x86" "aarch" ] (arch: lib.nameValuePair "builder-${arch}-machine" (builder arch));
#launchd.daemons.darwin-builder = builder;
nix = {
#buildMachines = [ { systems = ["aarch64-linux"]; sshUser = "builder"; sshKey = "/etc/nix/builder_ed25519"; hostName = "localhost:31022"; protocol = "ssh-ng"; }];
enable = true;
buildMachines = [
{
hostName = "ssh-ng://builder@localhost";
system = "aarch64-linux";
maxJobs = 4;
supportedFeatures = [
"kvm"
"benchmarch"
"big-parallel"
];
}
];
gc.interval.Hour = 3;
#linux-builder.enable = true;
settings.auto-optimise-store = false; # Darwin bugs?
};
+2 -4
View File
@@ -19,6 +19,7 @@ let
specialArgs = {
inherit metadata top;
inherit (top) self;
pkgs' = top.self.packages.${system};
};
modules = [
{
@@ -37,7 +38,4 @@ let
++ lib.optionals (builtins.pathExists ./hosts/${name}) [ ./hosts/${name} ];
};
in
{
"MacBook-Pro" = mac { name = "ivr"; };
"MacBook-Prolocal" = mac { name = "ivr"; };
}
(lib.genAttrs (builtins.attrNames (builtins.readDir ./hosts)) (name: mac { inherit name; }))
+1
View File
@@ -0,0 +1 @@
gregory
+1
View File
@@ -0,0 +1 @@
gregory
@@ -31,6 +31,7 @@ in
"bitwarden"
"bruno"
"chromium"
"claude"
"dbeaver-community"
"ghostty"
"firefox"
+1
View File
@@ -0,0 +1 @@
gregory/
+1
View File
@@ -0,0 +1 @@
lithic/
+53
View File
@@ -0,0 +1,53 @@
{ ... }:
let
username = "greg";
in
{
greg = {
nix.cache = false;
};
homebrew = {
enable = true;
brews = [
"bitwarden-cli"
"colima"
"direnv"
"github-mcp-server"
{
name = "libvirt";
restart_service = true;
}
"mcp-atlassian"
"notion-mcp-server"
"nushell"
"qemu"
"slack-mcp-server"
"zlib"
];
casks = [
"alt-tab"
"audacity"
"bitwarden"
"bruno"
"chromium"
"claude-code"
"dbeaver-community"
"ghostty"
"firefox"
"notion"
"notunes"
"onlyoffice"
"tabby"
"zed"
];
user = username;
};
system.primaryUser = username;
users.users."${username}" = {
name = username;
home = "/Users/${username}";
};
}
Generated
+234 -278
View File
@@ -25,19 +25,17 @@
},
"buildbot": {
"inputs": {
"flake-parts": "flake-parts",
"hercules-ci-effects": "hercules-ci-effects",
"nixpkgs": [
"nixunstable"
],
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1772467670,
"narHash": "sha256-DF/1VCg7Qmw5iaFhBeKBysOSTDCxZlKJHdbJc7Q2e1k=",
"lastModified": 1783833875,
"narHash": "sha256-G+hRtNJ/Nnr6VFMQp2UZdx/ckJDR/RJoK0Fy/yx1/YY=",
"owner": "nix-community",
"repo": "buildbot-nix",
"rev": "f927795b97474875738ac134525af560b2d4a8a5",
"rev": "147af587241e2af85399402da60a4f44fdb1e5d7",
"type": "github"
},
"original": {
@@ -46,44 +44,20 @@
"type": "github"
}
},
"charts": {
"inputs": {
"flake-utils": "flake-utils",
"haumea": "haumea",
"nix-kube-generators": "nix-kube-generators",
"nixpkgs": "nixpkgs",
"pyproject-build-systems": "pyproject-build-systems",
"pyproject-nix": "pyproject-nix",
"uv2nix": "uv2nix"
},
"locked": {
"lastModified": 1772676442,
"narHash": "sha256-bPxUBXS2mdT4BjMAmTap5TkXnUX807qo4Uho2oVb2Fg=",
"owner": "nix-community",
"repo": "nixhelm",
"rev": "19cdbb3a03554059165a25a18b32bd253e62c883",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixhelm",
"type": "github"
}
},
"colmena": {
"inputs": {
"flake-compat": "flake-compat",
"flake-utils": "flake-utils_2",
"flake-utils": "flake-utils",
"nix-github-actions": "nix-github-actions",
"nixpkgs": "nixpkgs_2",
"nixpkgs": "nixpkgs",
"stable": "stable"
},
"locked": {
"lastModified": 1762034856,
"narHash": "sha256-QVey3iP3UEoiFVXgypyjTvCrsIlA4ecx6Acaz5C8/PQ=",
"lastModified": 1783909498,
"narHash": "sha256-T9OfLPLuh1Bf1xojlpWXwooJ6IXapxvb8GM0p3YNy8g=",
"owner": "zhaofengli",
"repo": "colmena",
"rev": "349b035a5027f23d88eeb3bc41085d7ee29f18ed",
"rev": "76ba0daa542880b730faec81f4e87efcaa63bc57",
"type": "github"
},
"original": {
@@ -121,11 +95,11 @@
]
},
"locked": {
"lastModified": 1772379624,
"narHash": "sha256-NG9LLTWlz4YiaTAiRGChbrzbVxBfX+Auq4Ab/SWmk4A=",
"lastModified": 1784362797,
"narHash": "sha256-EP9b9b+OXDxHBPefFwMYCIaLq0fn3UkmrbfzbLUT7kQ=",
"owner": "lnl7",
"repo": "nix-darwin",
"rev": "52d061516108769656a8bd9c6e811c677ec5b462",
"rev": "b4cccbd4bc299c1f71ae185b79c3cf99aa82805c",
"type": "github"
},
"original": {
@@ -138,11 +112,11 @@
"flake-compat": {
"flake": false,
"locked": {
"lastModified": 1650374568,
"narHash": "sha256-Z+s0J8/r907g149rllvwhb4pKi8Wam5ij0st8PwAh+E=",
"lastModified": 1767039857,
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "b4a34015c698c7793d592d66adbab377907a2be8",
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github"
},
"original": {
@@ -152,6 +126,22 @@
}
},
"flake-compat_2": {
"flake": false,
"locked": {
"lastModified": 1747046372,
"narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_3": {
"flake": false,
"locked": {
"lastModified": 1767039857,
@@ -169,17 +159,14 @@
},
"flake-parts": {
"inputs": {
"nixpkgs-lib": [
"buildbot",
"nixpkgs"
]
"nixpkgs-lib": "nixpkgs-lib"
},
"locked": {
"lastModified": 1769996383,
"narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=",
"lastModified": 1782949081,
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "57928607ea566b5db3ad13af0e57e921e6b12381",
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
"type": "github"
},
"original": {
@@ -190,14 +177,17 @@
},
"flake-parts_2": {
"inputs": {
"nixpkgs-lib": "nixpkgs-lib"
"nixpkgs-lib": [
"nixvimunstable",
"nixpkgs"
]
},
"locked": {
"lastModified": 1772408722,
"narHash": "sha256-rHuJtdcOjK7rAHpHphUb1iCvgkU3GpfvicLMwwnfMT0=",
"lastModified": 1782949081,
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "f20dc5d9b8027381c474144ecabc9034d6a839a3",
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
"type": "github"
},
"original": {
@@ -207,27 +197,6 @@
}
},
"flake-parts_3": {
"inputs": {
"nixpkgs-lib": [
"nixvimunstable",
"nixpkgs"
]
},
"locked": {
"lastModified": 1769996383,
"narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "57928607ea566b5db3ad13af0e57e921e6b12381",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"flake-parts_4": {
"inputs": {
"nixpkgs-lib": [
"nurpkgs",
@@ -266,68 +235,6 @@
"type": "github"
}
},
"flake-utils_2": {
"locked": {
"lastModified": 1659877975,
"narHash": "sha256-zllb8aq3YO3h8B/U0/J1WBgAL8EX5yWf5pMj3G0NAmc=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "c0e246b9b83f637f4681389ecabcb2681b4f3af0",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"haumea": {
"inputs": {
"nixpkgs": [
"charts",
"nixpkgs"
]
},
"locked": {
"lastModified": 1685133229,
"narHash": "sha256-FePm/Gi9PBSNwiDFq3N+DWdfxFq0UKsVVTJS3cQPn94=",
"owner": "nix-community",
"repo": "haumea",
"rev": "34dd58385092a23018748b50f9b23de6266dffc2",
"type": "github"
},
"original": {
"owner": "nix-community",
"ref": "v0.2.2",
"repo": "haumea",
"type": "github"
}
},
"hercules-ci-effects": {
"inputs": {
"flake-parts": [
"buildbot",
"flake-parts"
],
"nixpkgs": [
"buildbot",
"nixpkgs"
]
},
"locked": {
"lastModified": 1771131391,
"narHash": "sha256-HPBNYf7HiKtBVy7/69vKpLYHX6wTcUxndxmybzDlXP8=",
"owner": "hercules-ci",
"repo": "hercules-ci-effects",
"rev": "0b152e0f7c5cc265a529cd63374b80e2771b207b",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "hercules-ci-effects",
"type": "github"
}
},
"hmunstable": {
"inputs": {
"nixpkgs": [
@@ -335,11 +242,11 @@
]
},
"locked": {
"lastModified": 1772633327,
"narHash": "sha256-jl+DJB2DUx7EbWLRng+6HNWW/1/VQOnf0NsQB4PlA7I=",
"lastModified": 1784407317,
"narHash": "sha256-iZrxHToDJWnvt+5LGAtvuQMTy1NZYlNEKbKaVtBJNcc=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "5a75730e6f21ee624cbf86f4915c6e7489c74acc",
"rev": "39411a8e12a5526d992e65bc7e3dc9a4414d6713",
"type": "github"
},
"original": {
@@ -370,6 +277,45 @@
"type": "github"
}
},
"minecraft": {
"inputs": {
"flake-compat": "flake-compat_2",
"nixpkgs": "nixpkgs_2",
"systems": "systems_3"
},
"locked": {
"lastModified": 1784344393,
"narHash": "sha256-yAo2ZzSIdeBZg7cOKUpQxwflL+DRYN+1DMObZk2lP2Q=",
"owner": "Infinidoge",
"repo": "nix-minecraft",
"rev": "7297d14c52ec8ef39c6aeff2c1818541fd030473",
"type": "github"
},
"original": {
"owner": "Infinidoge",
"repo": "nix-minecraft",
"type": "github"
}
},
"niks3": {
"inputs": {
"nixpkgs": "nixpkgs_3",
"treefmt-nix": "treefmt-nix_2"
},
"locked": {
"lastModified": 1784016977,
"narHash": "sha256-TydDba3YD2u15uS0L+PDs7lMqPopnzWggljTKDqOCSw=",
"owner": "Mic92",
"repo": "niks3",
"rev": "b306808bf381e7e66e33de1e9446a1be0935f4e3",
"type": "github"
},
"original": {
"owner": "Mic92",
"repo": "niks3",
"type": "github"
}
},
"nix-github-actions": {
"inputs": {
"nixpkgs": [
@@ -378,11 +324,11 @@
]
},
"locked": {
"lastModified": 1729742964,
"narHash": "sha256-B4mzTcQ0FZHdpeWcpDYPERtyjJd/NIuaQ9+BV1h+MpA=",
"lastModified": 1737420293,
"narHash": "sha256-F1G5ifvqTpJq7fdkT34e/Jy9VCyzd5XfJ9TO8fHhJWE=",
"owner": "nix-community",
"repo": "nix-github-actions",
"rev": "e04df33f62cdcf93d73e9a04142464753a16db67",
"rev": "f4158fa080ef4503c8f4c820967d946c2af31ec9",
"type": "github"
},
"original": {
@@ -392,12 +338,15 @@
}
},
"nix-hardware": {
"inputs": {
"nixpkgs": "nixpkgs_4"
},
"locked": {
"lastModified": 1771969195,
"narHash": "sha256-qwcDBtrRvJbrrnv1lf/pREQi8t2hWZxVAyeMo7/E9sw=",
"lastModified": 1784310968,
"narHash": "sha256-rkSPTePrKqs4dg+i7ZFCq93+HrClac6oSwXX927SVjA=",
"owner": "nixos",
"repo": "nixos-hardware",
"rev": "41c6b421bdc301b2624486e11905c9af7b8ec68e",
"rev": "779c32a00155994c86cde8213a8dd4df139d4355",
"type": "github"
},
"original": {
@@ -406,28 +355,13 @@
"type": "github"
}
},
"nix-kube-generators": {
"locked": {
"lastModified": 1762437901,
"narHash": "sha256-5yuJODagAq+aMXQAT2c0gfXKLqapmA6eUHR33jKNHuU=",
"owner": "farcaller",
"repo": "nix-kube-generators",
"rev": "810dcf792081790648ba9ae705b9a2286115ace8",
"type": "github"
},
"original": {
"owner": "farcaller",
"repo": "nix-kube-generators",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1767767207,
"narHash": "sha256-Mj3d3PfwltLmukFal5i3fFt27L6NiKXdBezC1EBuZs4=",
"lastModified": 1783224372,
"narHash": "sha256-8i/87eeoqiGE4yOTjwSA3Eh/ziJRQEmd/unYU+K27sk=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "5912c1772a44e31bf1c63c0390b90501e5026886",
"rev": "d407951447dcd00442e97087bf374aad70c04cea",
"type": "github"
},
"original": {
@@ -439,11 +373,26 @@
},
"nixpkgs-lib": {
"locked": {
"lastModified": 1772328832,
"narHash": "sha256-e+/T/pmEkLP6BHhYjx6GmwP5ivonQQn0bJdH9YrRB+Q=",
"lastModified": 1782614948,
"narHash": "sha256-ePjCwr1sNm9NYUqywL7QfK3JnlS015msC+eBu2zKlp8=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "c185c7a5e5dd8f9add5b2f8ebeff00888b070742",
"rev": "db3f255737b94216eb71cce308e2912cf6bc2d7c",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "nixpkgs.lib",
"type": "github"
}
},
"nixpkgs-lib_2": {
"locked": {
"lastModified": 1783821755,
"narHash": "sha256-eMPX9S6MKPyUnaOgeRfrG7OKUiAlc1AlcRinMbSB0WA=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "228ab8523d81526e57a6ca342e1a919fb6d246a8",
"type": "github"
},
"original": {
@@ -454,15 +403,15 @@
},
"nixpkgs_2": {
"locked": {
"lastModified": 1750134718,
"narHash": "sha256-v263g4GbxXv87hMXMCpjkIxd/viIF7p3JpJrwgKdNiI=",
"owner": "NixOS",
"lastModified": 1769461804,
"narHash": "sha256-msG8SU5WsBUfVVa/9RPLaymvi5bI8edTavbIq3vRlhI=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "9e83b64f727c88a7711a2c463a7b16eedb69a84c",
"rev": "bfc1b8a4574108ceef22f02bafcf6611380c100d",
"type": "github"
},
"original": {
"owner": "NixOS",
"owner": "nixos",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
@@ -470,43 +419,56 @@
},
"nixpkgs_3": {
"locked": {
"lastModified": 1772624091,
"narHash": "sha256-QKyJ0QGWBn6r0invrMAK8dmJoBYWoOWy7lN+UHzW1jc=",
"owner": "nixos",
"lastModified": 1783978241,
"narHash": "sha256-7kK0Y/fIV2NTKArkd/eZGaFg+dEmgP8KDRsGK2vB5M4=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "80bdc1e5ce51f56b19791b52b2901187931f5353",
"rev": "a8b81d3cc8d35af7bc98694696bea61ad4f8fca7",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-unstable",
"owner": "NixOS",
"ref": "nixos-unstable-small",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_4": {
"locked": {
"lastModified": 1766025857,
"narHash": "sha256-Lav5jJazCW4mdg1iHcROpuXqmM94BWJvabLFWaJVJp0=",
"owner": "nixos",
"lastModified": 1767892417,
"narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=",
"rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba",
"type": "tarball",
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz"
},
"original": {
"type": "tarball",
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
}
},
"nixpkgs_5": {
"locked": {
"lastModified": 1783915482,
"narHash": "sha256-FmieJB8/OUvNxbkboi7+IGfIuSXY3nF/hZQm8kD0r50=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "def3da69945bbe338c373fddad5a1bb49cf199ce",
"rev": "6cdc7fc76e8bf7fde9fa43a849fcaaa70e230dee",
"type": "github"
},
"original": {
"owner": "nixos",
"owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs",
"rev": "def3da69945bbe338c373fddad5a1bb49cf199ce",
"type": "github"
}
},
"nixunstable": {
"nixpkgs_6": {
"locked": {
"lastModified": 1772963539,
"narHash": "sha256-9jVDGZnvCckTGdYT53d/EfznygLskyLQXYwJLKMPsZs=",
"lastModified": 1784356753,
"narHash": "sha256-12KrbMiWLcf8m7pCvAtZh1ZrgF85ZXDXvfR/fWTKy84=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "9dcb002ca1690658be4a04645215baea8b95f31d",
"rev": "61b7c44c4073f0b827768aff0049561b5110ea5a",
"type": "github"
},
"original": {
@@ -516,20 +478,50 @@
"type": "github"
}
},
"nixpkgs_7": {
"locked": {
"lastModified": 1777207419,
"narHash": "sha256-V3bmPWAajDiC+1ClDOp55gianW2EyRJSJOyu1RUQibc=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "a7ecea3deccfbdbf22945a89984fcc5a169da8aa",
"type": "github"
},
"original": {
"owner": "nixos",
"repo": "nixpkgs",
"rev": "a7ecea3deccfbdbf22945a89984fcc5a169da8aa",
"type": "github"
}
},
"nixunstable": {
"locked": {
"lastModified": 1784700541,
"narHash": "sha256-LcCdjhqwjFVrFTNW6tHm3KNYRrD1TA6bYRea30yIIjw=",
"owner": "geri1701",
"repo": "nixpkgs",
"rev": "3c598184d1f70c5d0beeea8b95d01ab0179e4ef7",
"type": "github"
},
"original": {
"owner": "geri1701",
"ref": "lego-v5-acme-spike",
"repo": "nixpkgs",
"type": "github"
}
},
"nixvimunstable": {
"inputs": {
"flake-parts": "flake-parts_3",
"nixpkgs": [
"nixunstable"
],
"systems": "systems_3"
"flake-parts": "flake-parts_2",
"nixpkgs": "nixpkgs_5",
"systems": "systems_4"
},
"locked": {
"lastModified": 1772402258,
"narHash": "sha256-3DmCFOdmbkFML1/G9gj8Wb+rCCZFPOQtNoMCpqOF8SA=",
"lastModified": 1784057377,
"narHash": "sha256-yycNej5//EsRbV10moBoh+/63vXEwZD1ZFEiRm6C9rQ=",
"owner": "nix-community",
"repo": "nixvim",
"rev": "21ae25e13b01d3b4cdc750b5f9e7bad68b150c10",
"rev": "07180a087e4a00720dc0731cbcd8dec796974381",
"type": "github"
},
"original": {
@@ -541,15 +533,15 @@
},
"nurpkgs": {
"inputs": {
"flake-parts": "flake-parts_4",
"nixpkgs": "nixpkgs_3"
"flake-parts": "flake-parts_3",
"nixpkgs": "nixpkgs_6"
},
"locked": {
"lastModified": 1772717146,
"narHash": "sha256-x2nJlzpiHWHLkGDBvaiO1ysLhaxjQCLsG3XieRueJ/c=",
"lastModified": 1784417922,
"narHash": "sha256-19XZ56wJXArMKxjY25pKXkNp/FrYHGoo+HuQtW6teSM=",
"owner": "nix-community",
"repo": "NUR",
"rev": "2e1bffbdde931c4300a59418d0150c7457022f2d",
"rev": "2c806d314605495dd7fd75b5950003a062e2b47a",
"type": "github"
},
"original": {
@@ -558,66 +550,18 @@
"type": "github"
}
},
"pyproject-build-systems": {
"inputs": {
"nixpkgs": [
"charts",
"nixpkgs"
],
"pyproject-nix": [
"charts",
"pyproject-nix"
],
"uv2nix": [
"charts",
"uv2nix"
]
},
"locked": {
"lastModified": 1763662255,
"narHash": "sha256-4bocaOyLa3AfiS8KrWjZQYu+IAta05u3gYZzZ6zXbT0=",
"owner": "pyproject-nix",
"repo": "build-system-pkgs",
"rev": "042904167604c681a090c07eb6967b4dd4dae88c",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "build-system-pkgs",
"type": "github"
}
},
"pyproject-nix": {
"inputs": {
"nixpkgs": [
"charts",
"nixpkgs"
]
},
"locked": {
"lastModified": 1764134915,
"narHash": "sha256-xaKvtPx6YAnA3HQVp5LwyYG1MaN4LLehpQI8xEdBvBY=",
"owner": "pyproject-nix",
"repo": "pyproject.nix",
"rev": "2c8df1383b32e5443c921f61224b198a2282a657",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "pyproject.nix",
"type": "github"
}
},
"root": {
"inputs": {
"agenix": "agenix",
"buildbot": "buildbot",
"charts": "charts",
"colmena": "colmena",
"darwin": "darwin_2",
"flake-parts": "flake-parts_2",
"flake-parts": "flake-parts",
"hmunstable": "hmunstable",
"minecraft": "minecraft",
"niks3": "niks3",
"nix-hardware": "nix-hardware",
"nixpkgs-lib": "nixpkgs-lib_2",
"nixunstable": "nixunstable",
"nixvimunstable": "nixvimunstable",
"nurpkgs": "nurpkgs",
@@ -627,16 +571,16 @@
},
"stable": {
"locked": {
"lastModified": 1750133334,
"narHash": "sha256-urV51uWH7fVnhIvsZIELIYalMYsyr2FCalvlRTzqWRw=",
"lastModified": 1783625654,
"narHash": "sha256-pI1244/PJfTyKhlAr2QYQC55vR6UQdnGA0rJUgtO2IQ=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "36ab78dab7da2e4e27911007033713bab534187b",
"rev": "a0230bd8d5cbd13893b2263918d396a2c7dd0407",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-25.05",
"ref": "release-26.05",
"repo": "nixpkgs",
"type": "github"
}
@@ -686,6 +630,22 @@
"type": "github"
}
},
"systems_4": {
"locked": {
"lastModified": 1774449309,
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
"owner": "nix-systems",
"repo": "default",
"rev": "c29398b59d2048c4ab79345812849c9bd15e9150",
"type": "github"
},
"original": {
"owner": "nix-systems",
"ref": "future-26.11",
"repo": "default",
"type": "github"
}
},
"treefmt-nix": {
"inputs": {
"nixpkgs": [
@@ -694,11 +654,11 @@
]
},
"locked": {
"lastModified": 1770228511,
"narHash": "sha256-wQ6NJSuFqAEmIg2VMnLdCnUc0b7vslUohqqGGD+Fyxk=",
"lastModified": 1780220602,
"narHash": "sha256-eynAfOmbmxJnkp7YewvCEbShNnnYJ9gLLqkzsYtBPeM=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "337a4fe074be1042a35086f15481d763b8ddc0e7",
"rev": "db947814a175b7ca6ded66e21383d938df01c227",
"type": "github"
},
"original": {
@@ -707,41 +667,37 @@
"type": "github"
}
},
"uv2nix": {
"treefmt-nix_2": {
"inputs": {
"nixpkgs": [
"charts",
"niks3",
"nixpkgs"
],
"pyproject-nix": [
"charts",
"pyproject-nix"
]
},
"locked": {
"lastModified": 1767701098,
"narHash": "sha256-CJhKZnWb3gumR9oTRjFvCg/6lYTGbZRU7xtvcyWIRwU=",
"owner": "pyproject-nix",
"repo": "uv2nix",
"rev": "9d357f0d2ce6f5f35ec7959d7e704452352eb4da",
"lastModified": 1780220602,
"narHash": "sha256-eynAfOmbmxJnkp7YewvCEbShNnnYJ9gLLqkzsYtBPeM=",
"owner": "numtide",
"repo": "treefmt-nix",
"rev": "db947814a175b7ca6ded66e21383d938df01c227",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "uv2nix",
"owner": "numtide",
"repo": "treefmt-nix",
"type": "github"
}
},
"vsext": {
"inputs": {
"nixpkgs": "nixpkgs_4"
"nixpkgs": "nixpkgs_7"
},
"locked": {
"lastModified": 1772678592,
"narHash": "sha256-1VZ1hg1YHW+WyBXIOfrQ9Oq+qLL0w93lkdKAiRRHEuI=",
"lastModified": 1784343266,
"narHash": "sha256-EGkegdTz2n6ESyih8s3dUuPyJQWlYfPp7U41J05g8PY=",
"owner": "nix-community",
"repo": "nix-vscode-extensions",
"rev": "5521856f37c3d2654fe9b20b03331a6594f855c6",
"rev": "472a3e862c76c64ac3ad75a24d332cb5cdd5f1bb",
"type": "github"
},
"original": {
@@ -752,17 +708,17 @@
},
"wsl": {
"inputs": {
"flake-compat": "flake-compat_2",
"flake-compat": "flake-compat_3",
"nixpkgs": [
"nixunstable"
]
},
"locked": {
"lastModified": 1772386632,
"narHash": "sha256-sm6OpWZuoDwR53KNlsY482YOoHFWlWYwt0wHmqLkRGE=",
"lastModified": 1784058842,
"narHash": "sha256-3u3tvbCIAid3Mv7RrJx13jusIEQC/HeKYhO/SUSxR3A=",
"owner": "nix-community",
"repo": "NixOS-WSL",
"rev": "be894604b2aa2184c0b3d3b44995acd0da14dc0c",
"rev": "24c8dc8e0f2170e1a377be24dfadc7d9d21dc1ad",
"type": "github"
},
"original": {
+19 -13
View File
@@ -13,9 +13,6 @@
url = "github:nix-community/buildbot-nix";
inputs.nixpkgs.follows = "nixunstable";
};
charts = {
url = "github:nix-community/nixhelm";
};
colmena.url = "github:zhaofengli/colmena";
darwin = {
url = "github:lnl7/nix-darwin/master";
@@ -26,12 +23,13 @@
url = "github:nix-community/home-manager/master";
inputs.nixpkgs.follows = "nixunstable";
};
minecraft.url = "github:Infinidoge/nix-minecraft";
niks3.url = "github:Mic92/niks3";
nix-hardware.url = "github:nixos/nixos-hardware";
nixvimunstable = {
url = "github:nix-community/nixvim/main";
inputs.nixpkgs.follows = "nixunstable";
};
nixunstable.url = "github:nixos/nixpkgs/nixos-unstable";
nixpkgs-lib.url = "github:nix-community/nixpkgs.lib";
nixvimunstable.url = "github:nix-community/nixvim/main";
#nixunstable.url = "github:nixos/nixpkgs/nixos-unstable";
nixunstable.url = "github:geri1701/nixpkgs/lego-v5-acme-spike";
nurpkgs.url = "github:nix-community/NUR";
vsext.url = "github:nix-community/nix-vscode-extensions";
wsl = {
@@ -50,6 +48,7 @@
top.nixvimunstable.overlays.default
top.nurpkgs.overlays.default
top.vsext.overlays.default
top.minecraft.overlay
];
metadata = builtins.fromJSON (builtins.readFile ./network.json);
systems = [
@@ -64,10 +63,14 @@
config = {
allowUnfree = true;
allowUnfreePredicate = _: true;
permittedInsecurePackages = [ "ventoy-1.1.05" ];
permittedInsecurePackages = [
"ventoy-1.1.05"
"electron-39.8.10"
];
};
}
);
lib' = import ./lib { inherit (top.nixunstable) lib; };
in
top.flake-parts.lib.mkFlake { inputs = top; } {
inherit systems;
@@ -79,10 +82,12 @@
nixpkgs = imported_packages.x86_64-linux;
specialArgs = {
inherit
lib'
metadata
self
top
;
pkgs' = top.self.packages.x86_64-linux;
};
};
}
@@ -96,7 +101,7 @@
{
deployment = {
inherit (v) tags;
targetHost = v.ts;
targetHost = if (v ? "connectAddr") then v.connectAddr else v.nebulaIp;
targetUser = "greg";
};
}
@@ -115,7 +120,7 @@
nixosConfigurations = (
import ./hosts {
inherit top metadata;
inherit top metadata lib';
nixpkgs = imported_packages;
}
);
@@ -144,16 +149,17 @@
pkgs = imported_packages.${system};
};
packages = (import ./pkgs { inherit pkgs; });
packages = (import ./pkgs { inherit pkgs top; });
checks = import ./checks.nix {
inherit system top self';
inherit (pkgs) lib;
inherit (top.nixpkgs-lib) lib;
};
devShells = import ./shells.nix {
inherit pkgs;
inherit (top) colmena;
inherit (self') packages;
};
};
};
+22 -22
View File
@@ -1,23 +1,23 @@
builds:
exclude:
- "homeConfigurations.*"
- "nixosConfigurations.*"
- "packages.*"
# bitwarden-cli package is broken on aarch64-darwin
- "packages.aarch64-darwin.img-bitwarden"
# kmod-31 is not a thing on Darwin
- "packages.aarch64-darwin.qemu-hook"
- "packages.aarch64-darwin.vfio_shutdown"
- "packages.aarch64-darwin.vfio_startup"
# This one is a bit of a beast and shouldn't take up Garnix time
- "packages.aarch64-darwin.zim"
# These are just images which I will build when
# I feel like it
- "devShells.*"
include:
- "packages.aarch64-darwin.*"
- homeConfigurations.exodus
- darwinConfigurations.MacBook-Pro
- darwinConfigurations.MacBook-Prolocal
- nixosConfigurations.builder-x86
- nixosConfigurations.builder-aarch
# Exclude most things, as I locally build x86_64-linux and aarch64-linux
- exclude:
- "homeConfigurations.*"
- "nixosConfigurations.*"
- "packages.*"
# These are just images which I will build when
# I feel like it
- "devShells.*"
include:
- "packages.aarch64-darwin.*"
- darwinConfigurations.MacBook-Pro
- darwinConfigurations.MacBook-Prolocal
- darwinConfigurations.li
# Some specific includes which are not specific enough to override the rules
# above, due to the intrepretation of the glob excludes, but which I still
# need included
- include:
# These are Mac homeConfigurations, which I do not have the infra
# to build at home
- homeConfigurations."gregory.hellings-mbp"
- homeConfigurations.gregs-MacBook-Pro-16-inch-Nov-2024
- homeConfigurations.ivr
+47 -5
View File
@@ -1,5 +1,5 @@
# vim: set filetype=nushell :
let servers = [isaiah jeremiah zeke genesis vm-gitlab]
let servers = [isaiah jeremiah zeke genesis hosea]
def par-map [ items: list, c: closure ] {
let results = $items | par-each -k $c
@@ -12,15 +12,55 @@ def --env unlock [] {
}
}
def rebuild [] {
def nebulaIps [] {
open /etc/nixos/network.json | get hosts | items { |h, e| $e.nebulaIp? } | where $it != null | sort
}
def localIps [] {
open /etc/nixos/network.json | get hosts | items { |h, e| $e.ip? } | where $it != null | sort
}
def genNebulaCert [ --ips: string, --name: string ] {
let public = $'~/SynologyDrive/nebula/($name).key.pub' | path expand
let private = $'~/SynologyDrive/nebula/($name).key' | path expand
let cert = $'/etc/nixos/secrets/nebula/($name).crt'
let ca_cert = '~/SynologyDrive/nebula/ca.crt' | path expand
let ca_key = '~/SynologyDrive/nebula/ca.key' | path expand
# Generate public key if there isn't one already
if ( not ($public | path exists) ) {
nebula-cert keygen -out-key $private -out-pub $public
}
# Clear old cert if there is one
if ( $cert | path exists) {
rm $cert
}
# Create and sign certs
(nebula-cert sign
-ca-crt $ca_cert
-ca-key $ca_key
-name $name
-networks $ips
-out-crt $cert
-in-pub $public
)
# Agenix update
cd /etc/nixos/secrets
cat $private | agenix -e $'nebula/($name).key.age'
}
def rebuild [ $target: string = "switch" ] {
if (uname | get operating-system) == "Darwin" {
sudo darwin-rebuild switch
sudo darwin-rebuild $target
} else {
let hostname = uname | get nodename
let build = ^nom build --keep-going $"/etc/nixos#nixosConfigurations.($hostname).config.system.build.toplevel"
if $env.LAST_EXIT_CODE == 0 {
nvd diff /run/current-system result
run0 result/bin/switch-to-configuration switch
run0 result/bin/switch-to-configuration $target
} else {
print "Error during build"
}
@@ -35,7 +75,8 @@ def deploy [ $host: string, $build: string = "" ] {
if $buildhost == "linode" or $buildhost == "genesis" {
$buildhost = "isaiah"
}
nixos-rebuild switch --sudo --use-substitutes --target-host $host --build-host $buildhost
colmena apply --on $host
#nixos-rebuild switch --sudo --use-substitutes --target-host $host --build-host $buildhost
}
def ff [ $file: string ] {
@@ -72,3 +113,4 @@ def dc [ $cmd: string = "sh" ] {
if ("/usr/local/bin" | path exists) {
$env.PATH = $env.PATH | append "/usr/local/bin"
}
$env.PATH = $env.PATH | prepend "~/.local/bin"
+1
View File
@@ -26,6 +26,7 @@
nixcopy = "nix copy --to \"s3://binary-cache/?profile=default&endpoint=nas.home%3A9000&scheme=http\"";
r = "run0";
updateScript = "nix-shell maintainers/scripts/update.nix --argstr package";
p = "${lib.getExe pkgs.podman-tui}";
# General
k = "kubectl";
+27 -26
View File
@@ -5,7 +5,7 @@
# This allows things like SSH in distrobox to read the config file just fine
home.file.".ssh/config" = {
target = ".ssh/config_source";
onChange = ''cat ~/.ssh/config_source > ~/.ssh/config && chmod 600 ~/.ssh/config'';
onChange = "cat ~/.ssh/config_source > ~/.ssh/config && chmod 600 ~/.ssh/config";
};
programs.ssh = {
enable = true;
@@ -13,24 +13,25 @@
includes = [ "config.local" ];
enableDefaultConfig = false;
matchBlocks =
settings =
let
nas = {
user = "admin";
User = "admin";
};
owned = {
user = "greg";
User = "greg";
};
in
{
inherit nas;
"*" = {
dynamicForwards = [ { port = 10240; } ];
serverAliveInterval = 60;
extraOptions = {
LogLevel = "error";
SetEnv = "TERM=xterm-256color";
DynamicForward = [ "10240" ];
ForwardAgent = "yes";
LogLevel = "error";
ServerAliveInterval = 60;
SetEnv = {
TERM = "xterm-256color";
};
};
@@ -41,46 +42,46 @@
"chronicles.thehellings.lan" = lib.hm.dag.entryBefore [ "*.thehellings.lan" ] nas;
gh = {
user = "git";
hostname = "github.com";
User = "git";
Hostname = "github.com";
};
"src" = {
user = "git";
hostname = "jeremiah.shire-zebra.ts.net";
port = 32222;
User = "git";
Hostname = "jeremiah.shire-zebra.ts.net";
Port = 32222;
};
srcpub = {
user = "git";
hostname = "src.thehellings.com";
port = 2222;
User = "git";
Hostname = "src.thehellings.com";
Port = 2222;
};
ivr = {
user = "git";
hostname = "gitlab.com";
User = "git";
Hostname = "gitlab.com";
};
"ivr.thehellings.lan" = lib.hm.dag.entryBefore [ "ivr" ] {
user = "gregory.hellings";
User = "gregory.hellings";
};
"*.thehellings.lan" = owned;
"10.42.*" = owned;
"host.crosswire.org crosswire" = {
hostname = "host.crosswire.org";
user = "ghellings";
Hostname = "host.crosswire.org";
User = "ghellings";
};
fedpeople = {
hostname = "fedorapeople.org";
user = "greghellings";
Hostname = "fedorapeople.org";
User = "greghellings";
};
"src.fedoraproject.org pkgs.fedoraproject.org" = {
user = "greghellings";
User = "greghellings";
};
"127.*".extraOptions = {
"127.*" = {
PubkeyAcceptedAlgorithms = "+ssh-rsa";
HostkeyAlgorithms = "+ssh-rsa";
};
+1 -2
View File
@@ -8,11 +8,10 @@
home.packages =
with pkgs;
[
attic-client
dig
jqp
kubernetes-helm
iamb
#iamb
lazyssh
rainfrog
tenere
-5
View File
@@ -38,11 +38,6 @@ def _ivr2(args):
vpn("gregory_hellings@ra.ivrtechnology.com", "IVR Technology")
aliases['ivr2'] = _ivr2
def _glrestart(args):
sudo nixos-container run gitlab -- systemctl restart gitlab
sudo nixos-container run gitlab -- systemctl restart nginx
aliases['glrestart'] = _glrestart
def _aws_creds(args):
$AWS_ACCESS_KEY_ID=$(bw get username "AWS Access Key")
$AWS_SECRET_ACCESS_KEY=$(bw get password "AWS Access Key")
+7 -16
View File
@@ -4,11 +4,15 @@
top,
}:
let
inherit (top.nixunstable) lib;
user =
host: username:
host:
let
inherit (metadata.hosts.${host}) system;
pkgs = nixpkgs.${system};
pkgs' = top.self.packages.${system};
username =
if builtins.hasAttr "user" metadata.hosts.${host} then metadata.hosts.${host}.user else "greg";
in
top.hmunstable.lib.homeManagerConfiguration {
inherit pkgs;
@@ -22,25 +26,12 @@ let
host
username
metadata
pkgs'
;
nixvim = top.nixvimunstable;
gui = false;
gnome = false;
};
};
greg = host: (user host "greg");
in
{
"MacBook-Pro.local" = user "ivr" "gregory.hellings";
"MacBook-Prolocal.local" = user "ivr" "gregory.hellings";
"MacBook-Pro.thehellings.lan" = user "ivr" "gregory.hellings";
"gregory.hellings-mbp" = user "ivr" "gregory.hellings";
genesis = greg "genesis";
exodus = greg "exodus";
zeke = greg "zeke";
isaiah = greg "isaiah";
jeremiah = greg "jeremiah";
linode = greg "linode";
hosea = greg "hosea";
gitlab = greg "gitlab";
}
(lib.genAttrs (builtins.attrNames (builtins.readDir ./hosts)) user)
+9 -3
View File
@@ -1,5 +1,6 @@
{
pkgs,
pkgs',
lib,
host ? "most",
top,
@@ -19,9 +20,14 @@ in
imports = [
top.nixvimunstable.homeModules.nixvim
top.self.modules.homeManagerModule
top.agenix.homeManagerModules.default
./baseline
]
++ lib.optionals (builtins.pathExists ./hosts/${host}) [ ./hosts/${host} ];
++ lib.optionals (builtins.pathExists ./hosts/${host}/default.nix) [ ./hosts/${host} ];
age = {
identityPaths = [ "${homeDirectory}/.ssh/id_ed25519" ];
};
home = {
inherit homeDirectory username;
@@ -33,7 +39,7 @@ in
gh
git
gnupatch
hms
pkgs'.hms
btop
inetutils
jq
@@ -41,7 +47,7 @@ in
nix-prefetch
nmap
openssl
setup-ssh
pkgs'.setup-ssh
tmux
tree
unzip
+1
View File
@@ -0,0 +1 @@
{...}: {}
+22 -1
View File
@@ -1,4 +1,4 @@
{ pkgs, ... }:
{ lib, pkgs, ... }:
{
greg = {
@@ -21,11 +21,32 @@
kubectl
kubectl-cnpg
mattermost-desktop
minio-client
mumble
nebula
nix-index
adoptopenjdk-icedtea-web
pre-commit
prismlauncher
rclone
restic
restic-browser
tea
wineWow64Packages.stable
];
programs = {
discord = {
enable = true;
settings.SKIP_HOST_UPDATE = true;
};
};
xdg.desktopEntries = {
prismlauncher = {
name = "Prism Launcher - Minecraft";
actions.minecraft = {
name = "Minecraft";
exec = lib.getExe pkgs.prismlauncher;
};
};
};
}
@@ -1,21 +1,10 @@
{
pkgs,
pkgs',
lib,
username,
...
}:
let
username = "gregory.hellings";
x = pkgs.xonsh.override {
extraPackages = (
ps: [
pkgs.nur.repos.xonsh-xontribs.xonsh-direnv
pkgs.nur.repos.xonsh-xontribs.xontrib-vox
ps.xonsh-apipenv
pkgs.pipenv-ivr
]
);
};
in
{
# Disables hitting local cache
_module.args.cache = lib.mkForce false;
@@ -28,43 +17,43 @@ in
home = {
packages = with pkgs; [
aacs
ansible
claude-code
direnv
home-manager
pkgs'.dockerCompat
python3Packages.ipython
just
glab
go
gopls
k9s
kubectl
mariadb
minikube
mise
nil
nixVersions.stable
pipenv-ivr
pre-commit
python311
python3Packages.flake8
skaffold
twine
x
];
file = {
".pip/pip.conf".text = ''
[global]
retries = 1
index-url = https://pypi.python.org/simple
index-url = https://pypi.python.org/
extra-index-url =
https://pypidev.ivrtechnology.com/simple/
https://pypidev.ivrtechnology.com/
'';
".config/uv/uv.toml".text = ''
index-strategy = "unsafe-first-match"
[[index]]
url = "https://pypidev.ivrtechnology.com/simple/"
url = "https://pypidev.ivrtechnology.com/"
name = "pypidev"
ignore-error-codes = [403]
'';
};
sessionVariables = {
BW_GITLAB_ITEM = "7d3da4e9-5f9a-49d0-8e14-b39c010a4001";
BW_ANTHROPIC_ITEM = "e122fd08-3506-4f21-9c6a-b42b00fe5be1";
};
username = username;
homeDirectory = "/Users/${username}";
};
@@ -108,6 +97,5 @@ in
"web4"
]
);
tmux.shell = (lib.getExe x);
};
}
+1
View File
@@ -0,0 +1 @@
lithic/
-4
View File
@@ -1,4 +0,0 @@
{ ... }:
{
}
+1
View File
@@ -0,0 +1 @@
gregory.hellings-mbp/
View File
+80
View File
@@ -0,0 +1,80 @@
{
pkgs,
pkgs',
lib,
...
}:
let
python = pkgs.python312.withPackages (
p: with p; [
ipython
]
);
in
{
# Disables hitting local cache
_module.args.cache = lib.mkForce false;
greg = {
development = true;
gui = true;
nix.cache = false;
zed = true;
};
home = {
packages = with pkgs; [
ansible
awscli2
cargo
clippy
direnv
docker
docker-compose
docker-buildx
go
home-manager
just
mcp-grafana
nil
nixVersions.stable
poetry
pre-commit
(pulumi.withPackages (
p: with p; [
pulumi-aws-native
pulumi-command
pulumi-go
pulumi-nodejs
pulumi-python
]
))
python
rustc
rustfmt
terraform
];
};
programs = {
direnv = {
enable = true;
enableNushellIntegration = true;
};
nushell = {
enable = true;
};
starship = {
enable = true;
enableNushellIntegration = true;
settings = {
directory = {
home_symbol = "~";
truncate_to_repo = false;
truncation_length = 0;
use_os_path_sep = true;
};
};
};
};
}
-7
View File
@@ -1,7 +0,0 @@
{ pkgs, ... }:
{
greg.vscodium.enable = false;
home.packages = with pkgs; [ brew ];
}
+44 -12
View File
@@ -3,19 +3,24 @@
lib,
metadata,
pkgs,
top,
...
}:
{
imports = [
../modules/nix-conf.nix
top.niks3.nixosModules.niks3-auto-upload
];
age.secrets.niks3-api-token.file = ../secrets/niks3/api_token.age;
console = {
font = "Lat2-Terminus16";
keyMap = "us";
};
environment.systemPackages = with pkgs; [
top.niks3.packages.${pkgs.stdenv.hostPlatform.system}.niks3
agenix
bitwarden-cli
bmon
@@ -26,10 +31,9 @@
efibootmgr
findutils
file
gcc-tune
git
gnupatch
hms # My own home manager switcher
top.self.packages.${pkgs.stdenv.hostPlatform.system}.hms # My own home manager switcher
iperf
killall
nano
@@ -53,9 +57,25 @@
# Network Manager pulls in too many deps
networking = {
extraHosts =
let
onNetwork =
attr: _k: v:
(builtins.hasAttr attr v) && v.${attr} != null;
getIPs =
attr: domain:
(lib.mapAttrsToList (host: v: "${builtins.getAttr attr v} ${host}.${domain}") (
lib.filterAttrs (onNetwork attr) metadata.hosts
));
in
builtins.concatStringsSep "\n" (
(getIPs "ts" "shire-zebra.ts.net")
++ (getIPs "nebulaIp" "nebula.thehellings.com")
++ (getIPs "nebulaIp" "nebula")
++ (getIPs "ip" "thehellings.lan")
);
search = [
"thehellings.lan"
"home"
"nebula.thehellings.com"
];
networkmanager.enable = false;
};
@@ -81,6 +101,12 @@
# Enable the OpenSSH daemon for remote control
services = {
locate.enable = true;
niks3-auto-upload = {
enable = config.greg.nix.cache;
authTokenFile = config.age.secrets.niks3-api-token.path;
serverUrl = "http://hosea.nebula.thehellings.com:5751";
verifyS3Integrity = true;
};
openssh = {
enable = true;
settings.X11Forwarding = true;
@@ -114,17 +140,23 @@
};
};
security.sudo.extraRules = [
{
users = [ "greg" ];
commands = [
security = {
sudo-rs = {
enable = true;
extraRules = [
{
command = "ALL";
options = [ "NOPASSWD" ];
users = [ "greg" ];
commands = [
{
command = "ALL";
options = [ "NOPASSWD" ];
}
];
}
];
}
];
};
sudo.enable = false;
};
# Define a user account. Don't forget to set a password with passwd.
users.users.greg = {
+9 -33
View File
@@ -1,5 +1,6 @@
{
top,
lib',
metadata,
nixpkgs,
}:
@@ -14,15 +15,22 @@ let
}:
let
inherit (metadata.hosts.${name}) system;
pkgs' = top.self.packages.${system};
in
channel.lib.nixosSystem {
pkgs = nixpkgs.${system};
specialArgs = {
inherit metadata top;
inherit
metadata
top
lib'
pkgs'
;
};
modules = [
{
nixpkgs.hostPlatform = system;
networking.hostName = name;
}
# Imported ones
top.agenix.nixosModules.default
@@ -44,16 +52,6 @@ in
})
)
)
// (lib.genAttrs
(builtins.attrNames (lib.filterAttrs (_: v: v == "directory") (builtins.readDir ./vm)))
(
name:
(unstable {
inherit name;
extraMods = [ ./vm/${name} ];
})
)
)
// {
# nix build '.#nixosConfigurations.wsl.config.system.build.installer'
#nixos = wsl { name = "wsl"; };
@@ -62,26 +60,4 @@ in
# name = "wsl";
# system = "aarch64-linux";
#};
builder-aarch = lib.nixosSystem {
system = "aarch64-linux";
modules = [
"${top.nixunstable}/nixos/modules/profiles/nix-builder-vm.nix"
{
virtualisation.host.pkgs = import top.nixunstable { system = "aarch64-darwin"; };
boot.loader.grub.devices = [ "/dev/vda" ];
}
];
};
builder-x86 = lib.nixosSystem {
system = "x86_64-linux";
modules = [
"${top.nixunstable}/nixos/modules/profiles/nix-builder-vm.nix"
{
virtualisation.host.pkgs = import top.nixunstable { system = "aarch64-darwin"; };
boot.loader.grub.devices = [ "/dev/vda" ];
}
];
};
}
+9 -10
View File
@@ -9,16 +9,16 @@
{
imports = [
./hardware-configuration.nix
top.nix-hardware.nixosModules.framework-11th-gen-intel
top.nix-hardware.nixosModules.framework-intel-core-ultra-series1
];
age.secrets = {
compose-attic.file = ../../../secrets/compose/attic.env.age;
};
boot = {
loader = {
systemd-boot.enable = true;
systemd-boot = {
enable = true;
memtest86.enable = true;
netbootxyz.enable = true;
};
efi.canTouchEfiVariables = true;
};
binfmt.emulatedSystems = [
@@ -30,16 +30,15 @@
greg = {
home = true;
gnome.enable = true;
nebula = {
enable = true;
};
podman.enable = true;
print.enable = true;
tailscale = {
enable = true;
tags = [ "mobile" ];
};
runner = {
enable = true;
qemu = true;
};
};
hardware = {
+117 -38
View File
@@ -2,34 +2,18 @@
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{ lib, pkgs, ... }:
let
adblockUpdate = pkgs.writeShellApplication {
name = "adblock-update";
runtimeInputs = with pkgs; [
curl
gnused
systemd
];
text = ''
curl -s https://raw.githubusercontent.com/StevenBlack/hosts/master/hosts | sed '1,33d' > /etc/adblock_hosts
curl -s https://adaway.org/hosts.txt | sed '1,24d' | sed 's/127.0.0.1/0.0.0.0/' >> /etc/adblock_hosts
# Custom domains that I need to preserve for some reason
for f in "segment.com" "segment.io" "branch.io" "dev.visualwebsiteoptimizer.com"; do
sed -i -e "/''${f}/d" /etc/adblock_hosts # Blocks Trelly content for house investors
done
systemctl restart dnsmasq
'';
};
in
{
top,
pkgs,
pkgs',
...
}:
{
imports = [
# Include the results of the hardware scan.
./hardware-configuration.nix
./networking.nix
top.minecraft.nixosModules.minecraft-servers
];
greg = {
@@ -52,26 +36,121 @@ in
};
environment.systemPackages = with pkgs; [
create_ssl
pkgs'.create_ssl
step-ca
];
networking.hostName = "genesis"; # Define your hostname.
systemd = {
services.adblock-update = {
after = [ "network-online.target" ];
requires = [ "network-online.target" ];
script = lib.getExe adblockUpdate;
serviceConfig.Type = "oneshot";
};
timers.adblock-update = {
wantedBy = [ "multi-user.target" ];
after = [ "network-online.target" ];
requires = [ "network-online.target" ];
timerConfig = {
OnCalendar = "daily";
Unit = "adblock-update.service";
services = {
minecraft-servers = {
enable = true;
eula = true;
openFirewall = true;
servers = {
maya = {
enable = true;
operators = {
Almec = {
bypassesPlayerLimit = true;
uuid = "7884dc5a-ae21-43d5-9506-a934d59be19a";
};
};
package = pkgs.fabricServers.fabric.override { jre_headless = pkgs.openjdk25_headless; };
serverProperties = {
allow-flight = true;
motd = "Maya's Minecraft World";
online-mode = true;
};
whitelist = { };
jvmOpts = "-Xms4092M -Xmx4092M";
symlinks = {
mods = pkgs.linkFarmFromDrvs "mods" (
builtins.attrValues {
# Health info
appleskin = pkgs.fetchurl {
url = "https://cdn.modrinth.com/data/EsAfCjCV/versions/HwaLJe3v/appleskin-fabric-mc26.1-3.0.9.jar";
hash = "sha256-iNCycR/oxqFpbPGfIcfgfWOm7PzPiIu5AmBWb8asTb4=";
};
# Needed by survivalfly
balm = pkgs.fetchurl {
url = "https://mediafilez.forgecdn.net/files/7959/843/balm-fabric-26.1.2-26.1.2.4.jar";
hash = "sha256-zDtDxkxOftpW0wUIap7l6abGCjXNczwrF2wLZDztyA0=";
};
# Adds more diverse biomes
# https://www.curseforge.com/minecraft/mc-mods/biomes-o-plenty
biomes = pkgs.fetchurl {
url = "https://mediafilez.forgecdn.net/files/7977/180/BiomesOPlenty-fabric-26.1.2-26.1.2.0.3.jar";
hash = "sha256-0aPtsRep0ftbkKqbp69PgUnNJyOBLY9vcPsB1mhOy/M=";
};
# Automation engines
# https://www.curseforge.com/minecraft/mc-mods/create
#create = pkgs.fetchurl {
# url = "https://mediafilez.forgecdn.net/files/7963/363/create-1.21.1-6.0.10.jar";
# hash = "sha256-74f+Vwnxuh9bi7IKKSW1r7RmnheP1ti/EMFndZ7v43o=";
#};
fabric_api = pkgs.fetchurl {
url = "https://cdn.modrinth.com/data/P7dR8mSH/versions/tnmuHGZA/fabric-api-0.146.1%2B26.1.2.jar";
hash = "sha256-8Jy/xmxRtw4z4GJ+38wwbXHVn4NGYp4w/mFvW9cmvKg=";
};
# Required by biomes-o-plenty
# https://www.curseforge.com/minecraft/mc-mods/glitchcore
glitchcore = pkgs.fetchurl {
url = "https://mediafilez.forgecdn.net/files/7975/608/GlitchCore-fabric-26.1.2-26.1.2.0.0.jar";
hash = "sha256-IDz+TblWvgt4UxFg3L3DhFMEESoX7y5cTOvXhyccQm8=";
};
# Tooltips
# https://www.curseforge.com/minecraft/mc-mods/jade/
jade = pkgs.fetchurl {
url = "https://mediafilez.forgecdn.net/files/7886/518/Jade-mc26.1-Fabric-26.0.8.jar";
hash = "sha256-Pc3R5eO4Jf+94mNMPtY/vvpbomp+S+qnAUAVbQk1r2Y=";
};
# Gives info on crafting recipes
# https://www.curseforge.com/minecraft/mc-mods/jei
jei = pkgs.fetchurl {
url = "https://mediafilez.forgecdn.net/files/7920/925/jei-26.1.2-fabric-29.5.0.26.jar";
hash = "sha256-7nF7fXYPIg9the/mxi6pUYEmKtosZO6yL2b0Dgf8+fI=";
};
# Machines
# https://www.curseforge.com/minecraft/mc-mods/mekanism
#mekanism = pkgs.fetchurl {
# url = "https://mediafilez.forgecdn.net/files/7904/58/Mekanism-1.21.1-10.7.19.85.jar";
# hash = "sha256-AE28nzEG9NGSrqoe4RkN0W7JyoBZ7T0JO4ADT0xXT0M=";
#};
# Shows installed mods
modmenu = pkgs.fetchurl {
url = "https://cdn.modrinth.com/data/mOgUt4GM/versions/jvjwXH6l/modmenu-18.0.0-alpha.8.jar";
hash = "sha256-u0gtCOVAnNxyHcslo+y9l/jCGsFb+U/Y8soiUilhZDA=";
};
# Better storage engines
# https://www.curseforge.com/minecraft/mc-mods/refined-storage
refined-storage = pkgs.fetchurl {
url = "https://mediafilez.forgecdn.net/files/8086/588/refinedstorage-fabric-3.0.0.jar";
hash = "sha256-LuOF0aYQon78AQeD5fQ8OXHCnekfa+PNKpH7cqimFNs=";
};
# https://www.curseforge.com/minecraft/mc-mods/storage-drawers
#storagedrawers = pkgs.fetchurl {
#url = "https://mediafilez.forgecdn.net/files/7352/799/StorageDrawers-fabric-1.21.11-20.0.0.jar";
#hash = "sha256-eBKCmAtjAhdAjOyLMRneu/NZnNt+orIezxPy6V8g/S8=";
#};
survivalfly = pkgs.fetchurl {
url = "https://mediafilez.forgecdn.net/files/7870/312/survivalfly-1.3_fabric-mc26.1.1.jar";
hash = "sha256-Kai4wSxckpXbs1yLp8wJ4BmmjNkdDbeqerqWGIz3+Zk=";
};
# Also needed by biomes
# https://www.curseforge.com/minecraft/mc-mods/terrablender-fabric
terrablender = pkgs.fetchurl {
url = "https://mediafilez.forgecdn.net/files/7933/873/TerraBlender-fabric-26.1.2-26.1.2.0.1.jar";
hash = "sha256-lUrkmMIod54Qj78H0rzT4EYoEeiBG7w6sVOJlRvsnQ4=";
};
}
);
};
};
};
};
};
+6 -9
View File
@@ -12,7 +12,7 @@
10.42.1.5 genesis genesis.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan speedtest.thehellings.lan nixcache.thehellings.lan gitcache.thehellings.lan
10.42.1.6 isaiah isaiah.thehellings.lan minio-01.thehellings.lan
10.42.1.7 hosea hosea.thehellings.lan jellyfin jellyfin.thehellings.lan grafana grafana.thehellings.lan
10.42.1.8 jeremiah jeremiah.thehellings.lan minio-02.thehellings.lan
10.42.1.8 jeremiah jeremiah.thehellings.lan minio-02.thehellings.lan buildbot.thehellings.lan
10.42.1.9 ivr ivr.thehellings.lan
# 10 - monitor
# 11 - old jude
@@ -22,8 +22,6 @@
# VMs
10.42.4.1 matrix matrix.thehellings.lan
#10.42.4.2 vm-jellyfin vm-jellyfin.thehellings.lan
10.42.4.3 git gitlab git.thehellings.lan gitlab.thehellings.lan
# VIP
10.42.5.1 longhorn.cluster matrix.cluster pgadmin.cluter postgres.cluster immich.cluster
@@ -35,14 +33,13 @@
# Tailscale hosts
100.119.228.115 nas.home chronicles.shire-zebra.ts.net
100.88.91.27 dns.home
100.80.99.48 exodus.home
100.96.198.104 genesis.home smart.home zwave.home nixcache.home gitcache.home dashy.home uptime.home speed.home
100.117.28.111 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan
100.70.99.91 exodus.home exodus.shire-zebra.ts.net
100.96.198.104 genesis.home genesis.shire-zebra.ts.net smart.home zwave.home nixcache.home gitcache.home dashy.home uptime.home speed.home
100.68.203.1 hosea.home hosea.shire-zebra.ts.net grafana.home
100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes longhorn.kubernetes
100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes immich.kubernetes postgres.kubernetes
100.90.74.19 zeke.home
100.115.57.8 linode.home
100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes immich.kubernetes postgres.kubernetes buildbot.home
100.90.74.19 zeke.home zeke.shire-zebra.ts.net
100.109.86.8 linode.home linode.shire-zebra.ts.net
100.65.5.38 matrix.home matrix.shire-zebra.ts.net
#100.127.55.22 jellyfin.home
100.114.187.61 nas1.home nas1.shire-zebra.ts.net
+61 -46
View File
@@ -1,7 +1,9 @@
{
config,
pkgs,
lib,
lib',
metadata,
pkgs,
...
}:
let
@@ -9,7 +11,6 @@ let
lanIP = metadata.hosts.${config.networking.hostName}.ip;
iot = "enp2s0";
iotIP = "192.168.66.250";
routerIP = metadata.infra.gw;
extraHosts = builtins.readFile ./net/hosts;
proxyPort = 3128;
@@ -21,12 +22,24 @@ let
#"1.0.0.1" # Cloudflare
#"149.112.112.112" # Quad 9
metadata.infra.gw # Currently using our UniFi router for DNS as well
"100.100.100.100"
];
in
{
greg.tailscale = {
enable = true;
tags = [ "home" ];
greg = {
nebula = {
enable = true;
# genesis IS the routing node for the home LAN — it does not route through itself.
# Override the module default (which points at genesis) to avoid a routing loop.
unsafeRoutes = [ ];
# genesis routes the home LAN (10.42.0.0/16) into the Nebula overlay.
# Sign genesis's cert with -subnets '10.42.0.0/16' (see secrets/nebula/README.md).
routesSubnet = "10.42.0.0/16";
};
tailscale = {
enable = true;
tags = [ "home" ];
};
};
# Really, why do I still have to force-disable this crap?
@@ -64,7 +77,7 @@ in
};
};
firewall = {
enable = false;
enable = true;
allowedUDPPorts = [
dhcpPort
dnsPort
@@ -75,55 +88,57 @@ in
80
];
};
nftables.enable = false;
nftables.enable = true;
};
environment.etc."hosts.d/local".text = extraHosts;
services = {
kea = {
dhcp4 = (
import ./networking/dhcp.nix {
inherit
iot
lan
lanIP
routerIP
;
}
);
};
#########
# dnsmasq config
########
dnsmasq = {
bind = {
enable = true;
settings = {
domain = "thehellings.lan";
expand-hosts = true;
log-queries = true;
no-hosts = true; # Do not read /etc/hosts, which makes genesis resolve to 127.0.0.2
addn-hosts = "/etc/adblock_hosts";
hostsdir = "/etc/hosts.d/";
server = dnsServers;
};
};
prometheus.exporters = {
dnsmasq.enable = true;
blackbox = {
enable = true;
openFirewall = true;
configFile = pkgs.writeText "blackbox.yml" ''
modules:
icmp:
prober: icmp
timeout: 5s
icmp:
preferred_ip_protocol: ip4
'';
};
cacheNetworks = [
metadata.infra.lan
metadata.infra.tailscale
metadata.infra.nebula
"127.0.0.0/8"
];
zones =
let
makeZoneFile =
hosts: domain:
let
preamble = [
"$ORIGIN\t${domain}."
"$TTL\t1h"
"@\tIN\tSOA\t${config.networking.hostName}\tgreg@thehellings.com (1 1m 1m 1m 1m)"
"\tIN\tNS\t${config.networking.hostName}"
];
makeHost =
host:
[ "${host.name}\tIN\tA\t${host.address}" ]
++ lib.map (a: "${a}\tIN\tA\t${host.address}") (
if builtins.hasAttr "aliases" host then host.aliases else [ ]
);
in
pkgs.writeText "${domain}" (
builtins.concatStringsSep "\n" (preamble ++ (lib.flatten (lib.map makeHost hosts)) ++ [ "" ])
);
in
lib.mapAttrs
(domain: net: {
master = true;
file = makeZoneFile (lib'.hostsByNet net (metadata.hosts // metadata.external)) domain;
})
{
"shire-zebra.ts.net" = "tailscale";
"nebula.thehellings.com" = "nebula";
nebula = "nebula";
"thehellings.lan" = "lan";
lan = "lan";
};
};
}; # End of services configuration
-70
View File
@@ -1,70 +0,0 @@
{
lib,
metadata,
pkgs,
...
}:
let
ips = lib.filterAttrs (_k: v: v ? "ip" && v.ip != null) metadata.hosts;
tps = lib.filterAttrs (_k: v: v ? "ts" && v.ts != null) metadata.hosts;
get = field: set: lib.mapAttrsToList (_k: v: v.${field}) set;
getTS = get "ts" tps;
getIP = get "ip" ips;
whitelists = builtins.concatStringsSep "," (
[
"localhost"
"127.0.0.1"
]
++ getTS
++ getIP
);
in
{
services = {
prowlarr = {
enable = true;
dataDir = "/arr/prowlarr";
openFirewall = true;
};
radarr = {
enable = true;
openFirewall = true;
};
transmission = {
enable = true;
openPeerPorts = true;
openRPCPort = true;
package = pkgs.transmission_4;
settings = {
download-dir = "/arr/transmission/downloads";
rpc-bind-address = "0.0.0.0";
rpc-host-whitelist = whitelists;
rpc-host-whitelist-enabled = false;
rpc-whitelist = whitelists;
rpc-whitelist-enabled = false;
watch-dir-enabled = true;
watch-dir = "/arr/transmission/incoming";
};
};
};
systemd.mounts =
let
nfs = name: {
what = "nas1.shire-zebra.ts.net:/mnt/all/${name}";
type = "nfs";
name = "${name}.mount";
where = "/${name}";
requires = [ "tailscaled-autoconnect.service" ];
after = [ "tailscaled-autoconnect.service" ];
wantedBy = [ "multi-user.target" ];
mountConfig.Options = "_netdev,noexec,timeo=50,retrans=5,soft";
};
in
[
(nfs "arr")
(nfs "music")
(nfs "photos")
(nfs "video")
];
}
+122 -18
View File
@@ -6,6 +6,7 @@
config,
metadata,
pkgs,
top,
...
}:
let
@@ -17,13 +18,31 @@ in
{
imports = [
# Include the results of the hardware scan.
./arr.nix
./hardware-configuration.nix
top.niks3.nixosModules.niks3
];
age.secrets.grafana-secret-key = {
file = ../../../secrets/grafana-secret-key.age;
owner = "grafana";
age.secrets = {
cache-private-key = {
file = ../../../secrets/cache-private-key.age;
owner = "niks3";
};
grafana-secret-key = {
file = ../../../secrets/grafana-secret-key.age;
owner = "grafana";
};
niks3-access-key-id = {
file = ../../../secrets/niks3/access_key_id.age;
owner = "niks3";
};
niks3-api-token = {
file = ../../../secrets/niks3/api_token.age;
owner = "niks3";
};
niks3-secret-access-key = {
file = ../../../secrets/niks3/secret_access_key.age;
owner = "niks3";
};
};
# Bootloader
@@ -49,6 +68,7 @@ in
greg = {
home = true;
nebula.enable = true;
proxies = {
"jellyfin.home".target = "http://localhost:8096/";
"jellyfin.thehellings.lan".target = "http://localhost:8096/";
@@ -59,6 +79,12 @@ in
enable = true;
tags = [ "home" ];
};
backup.jobs.albyhub = {
src = "/chain/alby";
dest = "albyhub";
pre = "systemctl stop albyhub || true";
post = "systemctl start albyhub";
};
};
hardware = {
@@ -91,6 +117,7 @@ in
];
};
};
firewall.interfaces.nebula0.allowedTCPPorts = [ 5751 ];
nameservers = [ metadata.infra.dns ];
};
@@ -143,6 +170,27 @@ in
analytics.reporting_enabled = false;
};
};
niks3 = {
enable = true;
apiTokenFile = config.age.secrets.niks3-api-token.path;
gc.enable = false;
httpAddr = "${metadata.hosts.hosea.nebulaIp}:5751";
nginx = {
enable = true;
domain = "hosea.nebula";
enableACME = false;
forceSSL = false;
};
s3 = {
accessKeyFile = config.age.secrets.niks3-access-key-id.path;
bucket = "niks3";
endpoint = "nas1.shire-zebra.ts.net:30188";
secretKeyFile = config.age.secrets.niks3-secret-access-key.path;
useSSL = false;
};
signKeyFiles = [ config.age.secrets.cache-private-key.path ];
};
prometheus.exporters.graphite.enable = true;
# Configure keymap
xserver.xkb = {
@@ -151,6 +199,25 @@ in
};
};
systemd.mounts =
let
nfs = name: {
what = "nas1.shire-zebra.ts.net:/mnt/all/${name}";
type = "nfs";
name = "${name}.mount";
where = "/${name}";
requires = [ "tailscaled-autoconnect.service" ];
after = [ "tailscaled-autoconnect.service" ];
wantedBy = [ "multi-user.target" ];
mountConfig.Options = "_netdev,noexec,timeo=50,retrans=5,soft";
};
in
[
(nfs "music")
(nfs "photos")
(nfs "video")
];
# After first deploy: create a Grafana service account + API token for Klaatu
# via the Grafana UI, then encrypt it: agenix -e secrets/grafana-api-token.age
age.secrets.grafana-api-token = {
@@ -285,7 +352,7 @@ in
"uid": "kubernetes-overview",
"title": "Kubernetes Overview",
"schemaVersion": 38,
"version": 2,
"version": 3,
"refresh": "30s",
"time": {"from": "now-3h", "to": "now"},
"panels": [
@@ -390,6 +457,41 @@ in
"title": "Node Memory Usage %",
"gridPos": {"x": 12, "y": 38, "w": 12, "h": 8},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "(1 - (node_memory_MemAvailable_bytes / node_memory_MemTotal_bytes)) * 100", "refId": "A"}]
},
{
"id": 12,
"type": "bargauge",
"title": "Top 5 Fullest PersistentVolumes",
"gridPos": {"x": 0, "y": 46, "w": 24, "h": 8},
"targets": [
{
"datasource": {"type": "prometheus", "uid": "prometheus"},
"expr": "topk(5, kubelet_volume_stats_used_bytes / kubelet_volume_stats_capacity_bytes * 100)",
"legendFormat": "{{namespace}}/{{persistentvolumeclaim}}",
"refId": "A",
"instant": true
}
],
"options": {
"reduceOptions": {"calcs": ["lastNotNull"]},
"orientation": "horizontal",
"displayMode": "gradient"
},
"fieldConfig": {
"defaults": {
"unit": "percent",
"min": 0,
"max": 100,
"thresholds": {
"mode": "absolute",
"steps": [
{"color": "green", "value": null},
{"color": "yellow", "value": 70},
{"color": "red", "value": 90}
]
}
}
}
}
]
}
@@ -400,44 +502,44 @@ in
"uid": "network-overview",
"title": "Network & UniFi",
"schemaVersion": 38,
"version": 2,
"version": 3,
"refresh": "30s",
"time": {"from": "now-3h", "to": "now"},
"panels": [
{
"id": 1,
"type": "stat",
"title": "DNS Queries/s",
"type": "timeseries",
"title": "DNS Queries",
"gridPos": {"x": 0, "y": 0, "w": 6, "h": 4},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "rate(dnsmasq_queries_total[5m]) or vector(0)", "refId": "A"}]
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "rate(dnsmasq_servers_queries[5m]) or vector(0)", "refId": "A"}]
},
{
"id": 3,
"type": "stat",
"title": "UniFi Devices",
"gridPos": {"x": 6, "y": 0, "w": 6, "h": 4},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "count(unifipoller_device_uptime_seconds) or vector(0)", "refId": "A"}]
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "count(unpoller_device_uptime_seconds) or vector(0)", "refId": "A"}]
},
{
"id": 7,
"type": "stat",
"title": "WiFi Clients",
"gridPos": {"x": 12, "y": 0, "w": 6, "h": 4},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "count(unifipoller_client_wifi_tx_rate_bps) or vector(0)", "refId": "A"}]
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "count(unpoller_client_uptime_seconds{wired=\"false\"}) or vector(0)", "refId": "A"}]
},
{
"id": 8,
"type": "stat",
"title": "Wired Clients",
"gridPos": {"x": 18, "y": 0, "w": 6, "h": 4},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "count(unifipoller_client_wired_tx_rate_bps) or vector(0)", "refId": "A"}]
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "count(unpoller_client_uptime_seconds{wired=\"true\"}) or vector(0)", "refId": "A"}]
},
{
"id": 9,
"type": "timeseries",
"title": "WAN RX (bytes/s)",
"gridPos": {"x": 0, "y": 4, "w": 12, "h": 8},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "rate(unifipoller_device_wan_receive_bytes_total[5m])", "legendFormat": "{{name}}", "refId": "A"}],
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "unpoller_device_wan_receive_rate_bytes", "legendFormat": "{{name}}", "refId": "A"}],
"fieldConfig": {"defaults": {"unit": "Bps"}}
},
{
@@ -445,7 +547,7 @@ in
"type": "timeseries",
"title": "WAN TX (bytes/s)",
"gridPos": {"x": 12, "y": 4, "w": 12, "h": 8},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "rate(unifipoller_device_wan_transmit_bytes_total[5m])", "legendFormat": "{{name}}", "refId": "A"}],
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "unpoller_device_wan_transmit_rate_bytes", "legendFormat": "{{name}}", "refId": "A"}],
"fieldConfig": {"defaults": {"unit": "Bps"}}
},
{
@@ -453,21 +555,23 @@ in
"type": "timeseries",
"title": "UniFi Port RX (bytes/s)",
"gridPos": {"x": 0, "y": 12, "w": 12, "h": 8},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "rate(unifipoller_port_receive_bytes_total[5m])", "legendFormat": "{{port_id}} {{name}}", "refId": "A"}]
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "rate(unpoller_device_port_receive_bytes_total[5m])", "legendFormat": "{{port_id}} {{name}}", "refId": "A"}],
"fieldConfig": {"defaults": {"unit": "Bps"}}
},
{
"id": 5,
"type": "timeseries",
"title": "UniFi Port TX (bytes/s)",
"gridPos": {"x": 12, "y": 12, "w": 12, "h": 8},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "rate(unifipoller_port_transmit_bytes_total[5m])", "legendFormat": "{{port_id}} {{name}}", "refId": "A"}]
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "rate(unpoller_device_port_transmit_bytes_total[5m])", "legendFormat": "{{port_id}} {{name}}", "refId": "A"}],
"fieldConfig": {"defaults": {"unit": "Bps"}}
},
{
"id": 11,
"type": "timeseries",
"title": "Top Client Throughput (bytes/s)",
"gridPos": {"x": 0, "y": 20, "w": 24, "h": 8},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "topk(10, rate(unifipoller_client_receive_bytes_total[5m]) + rate(unifipoller_client_transmit_bytes_total[5m]))", "legendFormat": "{{name}} {{ip}}", "refId": "A"}],
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "topk(10, rate(unpoller_client_receive_bytes_total[5m]) + rate(unpoller_client_transmit_bytes_total[5m]))", "legendFormat": "{{name}} {{ip}}", "refId": "A"}],
"fieldConfig": {"defaults": {"unit": "Bps"}}
},
{
@@ -482,7 +586,7 @@ in
"type": "table",
"title": "Device Status",
"gridPos": {"x": 12, "y": 28, "w": 12, "h": 8},
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "unifipoller_device_uptime_seconds", "instant": true, "refId": "A"}],
"targets": [{"datasource": {"type": "prometheus", "uid": "prometheus"}, "expr": "unpoller_device_uptime_seconds", "instant": true, "refId": "A"}],
"fieldConfig": {"defaults": {"unit": "s"}}
}
]
-11
View File
@@ -1,11 +0,0 @@
{ ... }:
{
# Bootloader.
boot = {
loader.grub = {
enable = true;
device = "/dev/sda";
};
};
}
-28
View File
@@ -1,28 +0,0 @@
# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{ pkgs, ... }:
{
imports = [
# Include the results of the hardware scan.
./hardware-configuration.nix
./boot.nix
./filesystem.nix
./location.nix
./networking.nix
./wiki.nix
];
# Define a user account. Don't forget to set a password with passwd.
users.users.greg = {
isNormalUser = true;
description = "Gregory Hellings";
extraGroups = [
"networkmanager"
"wheel"
];
packages = with pkgs; [ ];
};
}
-13
View File
@@ -1,13 +0,0 @@
{ ... }:
let
in
{
fileSystems."serve" = {
#device = "10.42.1.4:/volume1/icdm-mysql/";
#fsType = "nfs";
device = "/dev/sdb1";
fsType = "auto";
mountPoint = "/srv";
};
}
@@ -1,53 +0,0 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{
config,
lib,
modulesPath,
...
}:
{
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
boot.initrd.availableKernelModules = [
"xhci_pci"
"ehci_pci"
"ahci"
"usbhid"
"usb_storage"
"sd_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
fileSystems."/" = {
device = "/dev/disk/by-uuid/dab0d455-e25e-4445-8fa4-5320047d7e7b";
fsType = "btrfs";
options = [ "subvol=@" ];
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/5aedbb07-5761-423b-909d-2560405eae32";
fsType = "ext4";
};
fileSystems."/var" = {
device = "/dev/disk/by-uuid/57968536-c29d-417d-997e-85223d1d1f65";
fsType = "btrfs";
};
swapDevices = [ { device = "/dev/disk/by-uuid/09691dce-375a-43c6-8d40-4498d20a6d9a"; } ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.eno1.useDHCP = lib.mkDefault true;
# networking.interfaces.wlp2s0.useDHCP = lib.mkDefault true;
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}
-15
View File
@@ -1,15 +0,0 @@
{ ... }:
{
# Set your time zone.
time.timeZone = "America/Chicago";
# Select internationalisation properties.
i18n.defaultLocale = "en_US.UTF-8";
# Configure keymap in X11
services.xserver.xkb = {
layout = "us";
variant = "";
};
}
-63
View File
@@ -1,63 +0,0 @@
{ ... }:
let
dnsHosts = builtins.concatStringsSep "\n" [ "wiki.icdm.lan 10.42.101.1" ];
in
{
# If we have to do proxying in Bayonnais, we can start to work on that here
# networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
networking = {
hostName = "icdm-root";
useDHCP = false;
defaultGateway = "10.42.1.1";
nameservers = [
"100.100.100.100"
"10.42.1.2"
];
enableIPv6 = false;
interfaces = {
eno1.ipv4.addresses = [
{
address = "10.42.101.1";
prefixLength = 16;
}
{
address = "10.77.1.2";
prefixLength = 16;
}
];
};
# Allow traffic through
firewall = {
enable = true;
allowedTCPPorts = [ 53 ];
allowedUDPPorts = [
53
67
];
};
extraHosts = "${dnsHosts}";
};
services.dnsmasq = {
enable = true;
settings = {
domain = "icdm.lan";
dhcp-range = [ "eno1,10.77.1.10,10.77.1.255,255.255.0.0,12h" ];
dhcp-option = [
"eno1,option:router,10.77.1.1"
"eno1,option:dns-server,10.77.1.2,1.1.1.1"
"eno1,option:domain-search,icdm.lan"
];
expand-hosts = true;
log-dhcp = true;
log-queries = true;
# Upstream servers
server = [
"1.1.1.1"
"8.8.4.4"
];
};
};
}
-17
View File
@@ -1,17 +0,0 @@
{ pkgs, ... }:
let
wikiHost = "wiki.icdm.lan";
kiwixport = 8080;
in
{
services.kiwix-serve = {
enable = true;
port = kiwixport;
library = {
inherit (pkgs) zim;
};
};
greg.proxies."${wikiHost}".target = "http://localhost:${toString kiwixport}";
networking.firewall.allowedTCPPorts = [ 80 ];
}
+7 -43
View File
@@ -9,12 +9,6 @@
./hardware-configuration.nix
];
age.secrets = {
gitea-runner-isaiah-podman.file = ../../../secrets/gitea/runner-isaiah-podman.age;
gitea-workerPassword.file = ../../../secrets/gitea/workerPassword.age;
runner-reg.file = ../../../secrets/gitlab/kubernetes-k3s-local.age;
};
boot = {
binfmt.emulatedSystems = [ "aarch64-linux" ];
extraModprobeConfig = "options kvm_amd nested=1";
@@ -42,15 +36,20 @@
vip = metadata.hosts.${config.networking.hostName}.ip;
priority = 255;
};
nebula.enable = true;
podman.enable = true;
tailscale = {
enable = true;
tags = [ "home" ];
};
remote-builder.enable = true;
runner = {
gitea-runner = {
enable = true;
qemu = true;
extraLabels = [ "bare-metal:host" ];
};
vmdev = {
enable = true;
host = "libvirt";
};
};
@@ -66,41 +65,6 @@
};
services = {
gitea-actions-runner.instances.podman = {
enable = true;
labels = [
"debian-latest:docker://node:25-trixie"
"ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
"ubuntu-24.04:docker://docker.gitea.com/runner-images:ubuntu-24.04"
"ubuntu-22.04:docker://docker.gitea.com/runner-images:ubuntu-22.04"
"ubuntu-full-latest:docker://ghcr.io/catthehacker/ubuntu:full-latest"
"ubuntu-full-24.04:docker://ghcr.io/catthehacker/ubuntu:full-24.04"
"ubuntu-full-22.04:docker://ghcr.io/catthehacker/ubuntu:full-22.04"
"ubuntu-act-latest:docker://ghcr.io/catthehacker/ubuntu:act-latest"
"ubuntu-act-24.04:docker://ghcr.io/catthehacker/ubuntu:act-24.04"
"ubuntu-act-22.04:docker://ghcr.io/catthehacker/ubuntu:act-22.04"
"ubuntu-runner-latest:docker://ghcr.io/catthehacker/ubuntu:runner-latest"
"ubuntu-runner-24.04:docker://ghcr.io/catthehacker/ubuntu:runner-24.04"
"ubuntu-runner-22.04:docker://ghcr.io/catthehacker/ubuntu:runner-22.04"
"ubuntu-rust-latest:docker://ghcr.io/catthehacker/ubuntu:rust-latest"
"ubuntu-rust-24.04:docker://ghcr.io/catthehacker/ubuntu:rust-24.04"
"ubuntu-rust-22.04:docker://ghcr.io/catthehacker/ubuntu:rust-22.04"
"nix-latest:docker://src.thehellings.com/greg/builder:latest"
];
name = "isaiah-podman";
settings = {
container.force_pull = true;
runner.capacity = 7;
};
tokenFile = config.age.secrets.gitea-runner-isaiah-podman.path;
url = "https://gitea.shire-zebra.ts.net";
};
k3s.clusterInit = true; # This is the first node in the cluster
openssh = {
enable = true;
+9 -9
View File
@@ -22,8 +22,6 @@ in
];
age.secrets = {
runner-reg.file = ../../../secrets/gitlab/nixos-qemu-shell.age;
gitea-buildbotWorkersFile = mk ../../../secrets/gitea/buildbotWorkersFile.age;
gitea-oauthToken = mk ../../../secrets/gitea/oauthToken.age;
gitea-oauthSecret = mk ../../../secrets/gitea/oauthSecret.age;
@@ -78,6 +76,10 @@ in
};
greg = {
gitea-runner = {
enable = true;
extraLabels = [ "bare-metal:host" ];
};
home = true;
kubernetes = {
enable = true;
@@ -85,16 +87,13 @@ in
vip = ip;
priority = 254;
};
nebula.enable = true;
proxies."buildbot.nebula.thehellings.com".target = "http://buildbot.nebula.thehellings.com:8010/";
tailscale = {
enable = true;
tags = [ "home" ];
};
remote-builder.enable = true;
runner = {
enable = true;
threads = 3;
qemu = true;
};
};
hardware = {
@@ -115,6 +114,7 @@ in
interface = "br0";
};
firewall.allowedTCPPorts = [
8010
3389
9989 # buildbot communications port
];
@@ -143,7 +143,7 @@ in
updateOutputs = false;
};
};
domain = "${config.networking.hostName}.shire-zebra.ts.net:8010";
domain = "buildbot.nebula.thehellings.com:8010";
evalMaxMemorySize = 8192;
evalWorkerCount = 4;
gitea = {
@@ -156,7 +156,7 @@ in
webhookSecretFile = config.age.secrets.gitea-webhookSecret.path;
};
showTrace = true;
#webhookBaseUrl = "http://${config.networking.hostName}.shire-zebra.ts.net:8010";
#webhookBaseUrl = "http://${config.networking.hostName}.nebula.thehellings.com:8010";
workersFile = config.age.secrets.gitea-buildbotWorkersFile.path;
};
worker = {
+76
View File
@@ -0,0 +1,76 @@
{
config,
metadata,
modulesPath,
pkgs,
...
}:
{
imports = [ "${modulesPath}/virtualisation/proxmox-image.nix" ];
greg = {
home = true;
nebula.enable = true;
proxies =
let
tgt = {
target = "http://localhost:${config.services.uptime-kuma.settings.PORT}";
genAliases = false;
};
in
{
"kuma.nebula.thehellings.com" = tgt;
"kuma.thehellings.lan" = tgt;
"kuma.shire-zebra.ts.net" = tgt;
};
};
nix.settings = {
sandbox = false;
};
networking = {
defaultGateway = metadata.infra.gw;
nameservers = [ metadata.infra.dns ];
interfaces.ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = metadata.hosts."${config.networking.hostName}".ip;
prefixLength = 16;
}
];
};
};
proxmox.cloudInit.enable = false;
services = {
fstrim.enable = true;
mysql = {
enable = true;
ensureDatabases = [
config.services.uptime-kuma.settings.UPTIME_KUMA_DB_NAME
];
ensureUsers = [
{
name = config.services.uptime-kuma.settings.UPTIME_KUMA_DB_USERNAME;
ensurePermissions = {
"uptimekuma.*" = "ALL PRIVILEGES";
};
}
];
package = pkgs.mariadb;
};
openssh = {
enable = true;
openFirewall = true;
};
uptime-kuma = {
enable = true;
settings = {
PORT = "3001"; # Default, but this allows us to explicitly use it elsewhere
UPTIME_KUMA_DB_TYPE = "mariadb";
UPTIME_KUMA_DB_SOCKET = "/run/mysqld/mysqld.sock";
UPTIME_KUMA_DB_NAME = "uptimekuma";
UPTIME_KUMA_DB_USERNAME = "uptimekuma";
UPTIME_KUMA_DB_PASSWORD = "uptimekuma";
};
};
};
}
+313 -31
View File
@@ -1,44 +1,100 @@
{
pkgs,
lib,
config,
lib,
metadata,
pkgs,
pkgs',
...
}:
let
homepage = "127.0.0.1:30080";
nextcloudPort = 8080;
sshPort = 2222;
in
{
imports = [
./git.nix
./hardware-configuration.nix
./podman.nix
./matrix.nix
./nextcloud.nix
./nginx.nix
./postgres.nix
];
age.secrets = {
acme.file = ../../../secrets/acme.age;
nextcloudadmin = {
file = ../../../secrets/nextcloudadmin.age;
owner = "nextcloud";
};
};
environment.systemPackages = with pkgs; [
bind
graphviz
nix-du
pgloader
podman-compose
pkgs'.upgrade-pg-cluster
];
greg = {
backup.jobs = {
nextcloud-bkup = {
src = "/var/lib/nextcloud";
dest = "nextcloud-backup";
pre = lib.getExe (
pkgs.writeShellApplication {
name = "nextcloud-backup-pre";
runtimeInputs = [ config.services.nextcloud.occ ];
text = "nextcloud-occ maintenance:mode --on";
}
);
post = lib.getExe (
pkgs.writeShellApplication {
name = "nextcloud-backup-post";
runtimeInputs = [ config.services.nextcloud.occ ];
text = "nextcloud-occ maintenance:mode --off";
}
);
};
greg-postgresql-backup = {
src = config.services.postgresqlBackup.location;
dest = "linode-postgres";
};
};
gitea-runner = {
enable = true;
labels = [
"vps:host"
"blog:host"
"nixos-linode:host"
];
};
home = false;
linode.enable = true;
proxies."immich.thehellings.com" = {
genAliases = false;
target = "http://localhost:${builtins.toString config.services.immich-public-proxy.port}";
ssl = true;
nebula = {
enable = true;
isLighthouse = true;
unsafeRoutes = [
{
route = "10.42.0.0/16";
via = metadata.hosts.genesis.nebulaIp;
}
];
};
tailscale.enable = true;
};
networking = {
networkmanager.enable = lib.mkForce false;
hostName = "linode";
domain = "thehellings.com";
nameservers = [ "100.88.91.27" ];
firewall.allowedTCPPorts = [
sshPort
80
443
];
hostName = "linode";
nameservers = [
"10.157.0.2"
"100.96.198.104"
];
networkmanager.enable = lib.mkForce false;
};
programs.ssh.extraConfig = lib.strings.concatStringsSep "\n" [
@@ -49,26 +105,252 @@
" UserKnownHostsFile /dev/null"
];
services = {
immich-public-proxy = {
enable = true;
immichUrl = "https://immich.shire-zebra.ts.net";
security.acme = {
acceptTerms = true;
defaults = {
dnsPropagationCheck = false;
dnsResolver = "92.123.95.3:53,92.123.94.3:53,92.123.94.2:53,92.123.95.4:53,92.123.95.2:53";
email = "greg.hellings@gmail.com";
extraLegoRunFlags = [ "--ipv4only" ]; # Force IPv4 only
#server = "https://acme-staging-v02.api.letsencrypt.org/directory";
};
certs."thehellings.com" = {
dnsProvider = "linode";
environmentFile = config.age.secrets.acme.path;
extraDomainNames = [
"*.thehellings.com"
];
};
};
security.sudo.extraRules = [
{
users = [ "gitlab-runner" ];
commands = [
services = {
anubis = {
instances = {
git = {
enable = true;
settings = {
BIND = "/run/anubis/anubis-git/anubis.sock";
COOKIE_DOMAIN = "thehellings.com";
SERVE_ROBOTS_TXT = true;
SLOG_LEVEL = "DEBUG";
TARGET = "http://git.k3s.thehellings.lan";
};
};
};
};
haproxy = {
enable = true;
config = ''
global
nbthread 4
maxconn 80
log /dev/log local0
defaults
timeout connect 500s
timeout client 500s
timeout server 1h
listen gitsshd
bind *:${toString sshPort}
timeout client 1h
mode tcp
server git-isaiah isaiah.thehellings.lan:32222
server git-jeremiah jeremiah.thehellings.lan:32222
server git-zeke zeke.thehellings.lan:32222
frontend https
bind *:80
bind *:443 ssl crt ${config.security.acme.certs."thehellings.com".directory}/full.pem
http-request redirect scheme https unless { ssl_fc }
http-request add-header X-Forwarded-Proto https
http-response replace-header ^Set-Cookie:\ (.*) Set-Cookie \1;\ Secure
option http-server-close
option http-keep-alive
#option httplog
#declare capture response len 80
#http-response capture res.hdr(Location) id 0
use_backend git if { hdr(host) -i src.thehellings.com }
use_backend git if { req_ssl_sni -i src.thehellings.com }
use_backend next if { hdr(host) -i next.thehellings.com }
use_backend next if { req_ssl_sni -i next.thehellings.com }
use_backend matrix if { hdr(host) -i matrix.thehellings.com }
use_backend matrix if { req_ssl_sni -i matrix.thehellings.com }
use_backend immich if { hdr(host) -i immich.thehellings.com }
use_backend immich if { req_ssl_sni -i immich.thehellings.com }
use_backend web if { hdr(host) -i thehellings.com }
use_backend web if { req_ssl_sni -i thehellings.com }
backend git
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
http-request set-header Host git.k3s.thehellings.lan
server git-isaiah isaiah.thehellings.lan:80
server git-jeremiah jeremiah.thehellings.lan:80
server git-zeke zeke.thehellings.lan:80
backend immich
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
server immich-proxy 127.0.0.1:${builtins.toString config.services.immich-public-proxy.port}
backend matrix
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
http-request set-header Host matrix.k3s.thehellings.lan
server git-isaiah isaiah.thehellings.lan:80
server git-jeremiah jeremiah.thehellings.lan:80
server git-zeke zeke.thehellings.lan:80
backend web
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
server web-container ${homepage}
backend next
log global
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
#http-response replace-value Location http://localhost:${builtins.toString nextcloudPort}/(.*) https://next.thehellings.com/\2
server nextcloud 127.0.0.1:${builtins.toString nextcloudPort}
'';
};
immich-public-proxy = {
enable = true;
immichUrl = "http://immich.k3s.thehellings.lan";
};
logrotate = {
enable = true;
settings = {
postgresBackup = {
enable = true;
files = "${config.services.postgresqlBackup.location}/*.gz";
};
postgresLog = {
enable = true;
files = "/var/lib/postgresql/*/log/*.log";
compress = true;
compresscmd = "${pkgs.xz}/bin/xz";
};
};
};
nextcloud = {
enable = true;
package = pkgs.nextcloud33;
appstoreEnable = true;
hostName = "localhost";
https = false;
config = {
adminpassFile = config.age.secrets.nextcloudadmin.path;
adminuser = "greg";
dbhost = "/run/postgresql";
dbtype = "pgsql";
};
settings = {
default_phone_region = "US";
overwriteprotocol = "http";
trusted_domains = [ "next.thehellings.com" ];
trusted_proxies = [
"localhost"
"127.0.0.1"
];
};
};
# Move to :8080 so that we can run haproxy as the primary HTTP service
nginx.virtualHosts."${config.services.nextcloud.hostName}".listen = [
{
addr = "127.0.0.1";
port = nextcloudPort;
}
];
openssh.settings.PasswordAuthentication = false;
postgresql = {
enable = true;
package = pkgs.postgresql_15;
checkConfig = true;
ensureDatabases = [ "nextcloud" ];
#initialScript = pkgs.writeText "create-matrix-db.sql" ''
# CREATE ROLE "matrix-synapse" WITH LOGIN;
# CREATE DATABASE "synapse" WITH OWNER "matrix-synapse" TEMPLATE template0 LC_COLLATE = "C" LC_CTYPE = "C";
# GRANT ALL PRIVILEGES ON DATABASE "synapse" TO "matrix-synapse";
#''; # These are done manually in order to set the LC_COLLATE values properly
ensureUsers = [
{
command = "/run/current-system/sw/bin/systemctl";
options = [ "NOPASSWD" ];
}
{
command = "/run/current-system/sw/bin/podman";
options = [ "NOPASSWD" ];
name = "nextcloud";
ensureDBOwnership = true;
}
];
}
];
settings = {
log_connections = true;
log_statement = "all";
logging_collector = true;
log_filename = "postgresql.log";
};
identMap = ''
root root postgres
'';
};
postgresqlBackup = {
enable = true;
databases = [ "nextcloud" ];
};
};
systemd.services = {
haproxy = {
after = [
"nextcloud.service"
"network-online.target"
];
wants = [
"nextcloud.service"
"network-online.target"
];
};
};
users.users.haproxy.extraGroups = [ config.security.acme.certs."thehellings.com".group ];
# Actually serve the content from here
virtualisation.oci-containers = {
backend = "podman";
containers."homepage" = {
image = "src.thehellings.com/greg/homepage:latest";
ports = [ "${homepage}:80" ];
};
};
virtualisation.podman = {
enable = true;
dockerCompat = true;
dockerSocket.enable = true;
};
}
-122
View File
@@ -1,122 +0,0 @@
{ ... }:
let
srcDomain = "src.thehellings.com";
sshPort = 2222;
in
{
greg.proxies."${srcDomain}" = {
target = "https://gitea.shire-zebra.ts.net";
ssl = true;
genAliases = false;
extraConfig = ''
proxy_ssl_verify off;
proxy_ssl_server_name on;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Ssl on;
client_max_body_size 100000m;
# Ultimate AI Block List v1.7 20250924
# https://perishablepress.com/ultimate-ai-block-list/
if ($http_user_agent ~* "(openai\.com|\.ai|-ai|_ai|ai\.|ai-|ai_|ai=|AddSearchBot|Agentic|AgentQL|Agent\ 3|Agent\ API|AI\ Agent|AI\ Article\ Writer|AI\ Chat|AI\ Content\ Detector|AI\ Detection|AI\ Dungeon|AI\ Journalist|AI\ Legion)") {
return 444;
}
if ($http_user_agent ~* "(AI\ RAG|AI\ Search|AI\ SEO\ Crawler|AI\ Training|AI\ Web|AI\ Writer|AI2|AIBot|aiHitBot|AIMatrix|AISearch|AITraining|Alexa|Alice\ Yandex|AliGenie|AliyunSec|Alpha\ AI|AlphaAI|Amazon|Amelia)") {
return 444;
}
if ($http_user_agent ~* "(AndersPinkBot|AndiBot|Anonymous\ AI|Anthropic|AnyPicker|Anyword|Applebot|Aria\ AI|Aria\ Browse|Articoolo|Ask\ AI|AutoGen|AutoGLM|Automated\ Writer|AutoML|Autonomous\ RAG|AwarioRssBot|AwarioSmartBot|AWS\ Trainium|Azure)") {
return 444;
}
if ($http_user_agent ~* "(BabyAGI|BabyCatAGI|BardBot|Basic\ RAG|Bedrock|Big\ Sur|Bigsur|Botsonic|Brightbot|Browser\ MCP\ Agent|Browser\ Use|Bytebot|ByteDance|Bytespider|CarynAI|CatBoost|CC-Crawler|CCBot|Chai|Character)") {
return 444;
}
if ($http_user_agent ~* "(Charstar\ AI|Chatbot|ChatGLM|Chatsonic|ChatUser|Chinchilla|Claude|ClearScope|Clearview|Cognitive\ AI|Cohere|Common\ Crawl|CommonCrawl|Content\ Harmony|Content\ King|Content\ Optimizer|Content\ Samurai|ContentAtScale|ContentBot|Contentedge)") {
return 444;
}
if ($http_user_agent ~* "(ContentShake|Conversion\ AI|Copilot|CopyAI|Copymatic|Copyscape|CoreWeave|Corrective\ RAG|Cotoyogi|CRAB|Crawl4AI|CrawlQ\ AI|Crawlspace|Crew\ AI|CrewAI|Crushon\ AI|DALL-E|DarkBard|DataFor|DataProvider)") {
return 444;
}
if ($http_user_agent ~* "(Datenbank\ Crawler|DeepAI|Deep\ AI|DeepL|DeepMind|Deep\ Research|DeepResearch|DeepSeek|Devin|Diffbot|Doubao\ AI|DuckAssistBot|DuckDuckGo\ Chat|DuckDuckGo-Enhanced|Echobot|Echobox|Elixir|FacebookBot|FacebookExternalHit|Factset)") {
return 444;
}
if ($http_user_agent ~* "(Falcon|FIRE-1|Firebase|Firecrawl|Flux|Flyriver|Frase\ AI|FriendlyCrawler|Gato|Gemini|Gemma|Gen\ AI|GenAI|Generative|Genspark|Gentoo-chat|Ghostwriter|GigaChat|GLM|GodMode)") {
return 444;
}
if ($http_user_agent ~* "(Goose|GPT|Grammarly|Grendizer|Grok|GT\ Bot|GTBot|GTP|Hemingway\ Editor|Hetzner|Hugging|Hunyuan|Hybrid\ Search\ RAG|Hypotenuse\ AI|iAsk|ICC-Crawler|ImageGen|ImagesiftBot|img2dataset|imgproxy)") {
return 444;
}
if ($http_user_agent ~* "(INK\ Editor|INKforall|Instructor|IntelliSeek|Inferkit|ISSCyberRiskCrawler|Janitor\ AI|Jasper|Jenni\ AI|Julius\ AI|Kafkai|Kaggle|Kangaroo|Keyword\ Density\ AI|Kimi|Knowledge|KomoBot|Kruti|LangChain|Le\ Chat)") {
return 444;
}
if ($http_user_agent ~* "(Lensa|Lightpanda|LinerBot|LLaMA|LLM|Local\ RAG\ Agent|Lovable|Magistral|magpie-crawler|Manus|MarketMuse|Meltwater|Meta-AI|Meta-External|Meta-Webindexer|Meta\ AI|MetaAI|MetaTagBot|Middleware|Midjourney)") {
return 444;
}
if ($http_user_agent ~* "(Mini\ AGI|MiniMax|Mintlify|Mistral|Mixtral|model-training|Monica|Narrative|NeevaBot|netEstate|Neural\ Text|NeuralSEO|NinjaAI|NodeZero|Nova\ Act|NovaAct|OAI-SearchBot|OAI\ SearchBot|OASIS|Olivia)") {
return 444;
}
if ($http_user_agent ~* "(Omgili|Open\ AI|Open\ Interpreter|OpenAGI|OpenAI|OpenBot|OpenPi|OpenRouter|OpenText\ AI|Operator|Outwrite|Page\ Analyzer\ AI|PanguBot|Panscient|Paperlibot|Paraphraser\.io|peer39_crawler|Perflexity|Perplexity|Petal)") {
return 444;
}
if ($http_user_agent ~* "(Phind|PiplBot|PoeBot|PoeSearchBot|ProWritingAid|Proximic|Puppeteer|Python\ AI|Qualified|Quark|QuillBot|Qopywriter|Qwen|RAG\ Agent|RAG\ Azure\ AI|RAG\ Chatbot|RAG\ Database|RAG\ IS|RAG\ Pipeline|RAG\ Search)") {
return 444;
}
if ($http_user_agent ~* "(RAG\ with|RAG-|RAG_|Raptor|React\ Agent|Redis\ AI\ RAG|RobotSpider|Rytr|SaplingAI|SBIntuitionsBot|Scala|Scalenut|Scrap|ScriptBook|Seekr|SEObot|SEO\ Content\ Machine|SEO\ Robot|SemrushBot|Sentibot)") {
return 444;
}
if ($http_user_agent ~* "(Serper|ShapBot|Sidetrade|Simplified\ AI|Sitefinity|Skydancer|SlickWrite|SmartBot|Sonic|Sora|Spider/2|SpiderCreator|Spin\ Rewrite|Spinbot|Stability|StableDiffusionBot|Sudowrite|SummalyBot|Super\ Agent|Superagent)") {
return 444;
}
if ($http_user_agent ~* "(SuperAGI|Surfer\ AI|TerraCotta|Text\ Blaze|TextCortex|Thinkbot|Thordata|TikTokSpider|Timpibot|Tinybird|Together\ AI|Traefik|TurnitinBot|uAgents|VelenPublicWebCrawler|Venus\ Chub\ AI|Vidnami\ AI|Vision\ RAG|WebSurfer|WebText)") {
return 444;
}
if ($http_user_agent ~* "(Webzio|WeChat|Whisper|WordAI|Wordtune|WPBot|Writecream|WriterZen|Writescope|Writesonic|xAI|xBot|YaML|YandexAdditional|YouBot|Zendesk|Zero|Zhipu|Zhuque\ AI|Zimm)") {
return 444;
}
'';
};
#greg.proxies."registry.thehellings.com" = {
#target = "https://gitea.shire-zebra.ts.net:5000";
#ssl = true;
#genAliases = false;
#extraConfig = ''
#proxy_set_header X-Forwarded-Proto https;
#proxy_set_header X-Forwarded-Ssl on;
#client_max_body_size 25000m;
#'';
#};
networking.firewall.allowedTCPPorts = [ sshPort ];
systemd.services = {
haproxy = {
after = [
"network-online.target"
];
wants = [
"network-online.target"
];
};
};
services.haproxy = {
enable = true;
config = ''
global
daemon
maxconn 20
defaults
timeout connect 500s
timeout client 500s
timeout server 1h
listen gitsshd
bind *:${toString sshPort}
timeout client 1h
mode tcp
server git-isaiah isaiah.shire-zebra.ts.net:32222
server git-jeremiah jeremiah.shire-zebra.ts.net:32222
server git-zeke zeke.shire-zebra.ts.net:32222
'';
};
}
-88
View File
@@ -1,88 +0,0 @@
# Registration of new users is disabled for the public, but I can create
# them by the following commands:
# nix run nixpkgs.matrix-synapse
# register_new_matrix_user -k "B9EoPr2WV9hzwc7uL2Sx1JmvCeKDEOGCpB0uginQcQtEH4wzRtkSIdo7lltrjSQa" http://localhost:8448
{ config, lib, ... }:
let
domain = "${config.networking.domain}";
fqdn = "matrix.${domain}";
in
{
services.nginx = {
virtualHosts = {
# Server the '.well-known' files to find the Matrix API server
"${domain}" = {
enableACME = true;
forceSSL = true;
# This is needed so that servers contacting hellings.com can find
# the actual application server at matrix.thehellings.com
locations."= /.well-known/matrix/server".extraConfig =
let
server = {
"m.server" = "${fqdn}:443";
};
in
''
add_header Content-Type application/json;
return 200 '${builtins.toJSON server}';
'';
locations."= /.well-known/matrix/client".extraConfig =
let
client = {
"m.homeserver" = {
"base_url" = "https://${fqdn}";
};
"m.identity_server" = {
"base_url" = "https://vector.im";
};
};
in
''
add_header Content-Type application/json;
add_header Access-Control-Allow-Origin *;
return 200 '${builtins.toJSON client}';
'';
};
# Reverse proxy in front of the actual Matrix server
"${fqdn}" = {
enableACME = true;
forceSSL = true;
extraConfig = ''
error_log /var/log/nginx/debug.log debug;
'';
# Not the appropriate place for the chat client
locations =
(builtins.listToAttrs (
builtins.map
(
val:
lib.nameValuePair "/_${val}" {
proxyPass = "http://matrix.kubernetes";
}
)
[
"matrix"
"synapse"
"dendrite"
]
))
// {
"/".extraConfig = "return 404;";
};
};
};
};
# Open networking ports for the server
networking.firewall = {
enable = true;
allowedTCPPorts = [
80
443
];
};
}
-58
View File
@@ -1,58 +0,0 @@
{
config,
lib,
pkgs,
...
}:
{
age.secrets.nextcloudadmin = {
file = ../../../secrets/nextcloudadmin.age;
owner = "nextcloud";
};
services.nextcloud = {
enable = true;
package = pkgs.nextcloud32;
appstoreEnable = true;
hostName = "next.${config.networking.domain}";
https = true;
config = {
adminpassFile = config.age.secrets.nextcloudadmin.path;
adminuser = "greg";
dbhost = "/run/postgresql";
dbtype = "pgsql";
};
settings = {
default_phone_region = "US";
overwriteprotocol = "https";
};
};
services.nginx.virtualHosts."next.thehellings.com" = {
forceSSL = true;
enableACME = true;
};
# Otherwise nginx errors looking for the nextcloud sock file
systemd.services.nginx.after = [ "nextcloud.service" ];
greg.backup.jobs.nextcloud-bkup = {
src = "/var/lib/nextcloud";
dest = "nextcloud-backup";
pre = lib.getExe (
pkgs.writeShellApplication {
name = "nextcloud-backup-pre";
runtimeInputs = [ config.services.nextcloud.occ ];
text = "nextcloud-occ maintenance:mode --on";
}
);
post = lib.getExe (
pkgs.writeShellApplication {
name = "nextcloud-backup-post";
runtimeInputs = [ config.services.nextcloud.occ ];
text = "nextcloud-occ maintenance:mode --off";
}
);
};
}
-44
View File
@@ -1,44 +0,0 @@
{ ... }:
let
homepage = "127.0.0.1:30080";
in
{
security.acme = {
acceptTerms = true;
defaults.email = "greg.hellings@gmail.com";
};
services.nginx = {
enable = true;
clientMaxBodySize = "25000m"; # To help with uploading container images
# If there are recommended settings, let's use them!
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
};
# Actually serve the content from here
virtualisation.podman.enable = true;
virtualisation.oci-containers = {
backend = "podman";
containers."homepage" = {
# needs explicit port to match what gitlab-runner sees when pulling
image = "registry.thehellings.com:443/greg/homepage/gregs-homepage:latest";
ports = [ "${homepage}:80" ];
};
};
greg.proxies = {
"thehellings.com" = {
target = "http://${homepage}/";
ssl = true;
genAliases = false;
};
"doubles.thehellings.com" = {
target = "http://localhost:8081";
ssl = true;
genAliases = false;
};
};
}
-13
View File
@@ -1,13 +0,0 @@
{ pkgs, ... }:
{
environment.systemPackages = with pkgs; [
podman-compose
];
virtualisation.podman = {
enable = true;
dockerCompat = true;
dockerSocket.enable = true;
};
}
-58
View File
@@ -1,58 +0,0 @@
{ config, pkgs, ... }:
{
environment.systemPackages = [ pkgs.upgrade-pg-cluster ];
services.postgresql = {
enable = true;
package = pkgs.postgresql_15;
checkConfig = true;
ensureDatabases = [ "nextcloud" ];
#initialScript = pkgs.writeText "create-matrix-db.sql" ''
# CREATE ROLE "matrix-synapse" WITH LOGIN;
# CREATE DATABASE "synapse" WITH OWNER "matrix-synapse" TEMPLATE template0 LC_COLLATE = "C" LC_CTYPE = "C";
# GRANT ALL PRIVILEGES ON DATABASE "synapse" TO "matrix-synapse";
#''; # These are done manually in order to set the LC_COLLATE values properly
ensureUsers = [
{
name = "nextcloud";
ensureDBOwnership = true;
}
];
settings = {
log_connections = true;
log_statement = "all";
logging_collector = true;
log_filename = "postgresql.log";
};
identMap = ''
root root postgres
'';
};
services.postgresqlBackup = {
enable = true;
databases = [ "nextcloud" ];
};
services.logrotate = {
enable = true;
settings = {
postgresBackup = {
enable = true;
files = "${config.services.postgresqlBackup.location}/*.gz";
};
postgresLog = {
enable = true;
files = "/var/lib/postgresql/*/log/*.log";
compress = true;
compresscmd = "${pkgs.xz}/bin/xz";
};
};
};
greg.backup.jobs.greg-postgresql-backup = {
src = config.services.postgresqlBackup.location;
dest = "linode-postgres";
};
}
@@ -1,60 +0,0 @@
# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{ pkgs, ... }:
{
imports = [
# Include the results of the hardware scan.
./hardware-configuration.nix
];
# Bootloader.
boot.loader = {
systemd-boot.enable = true;
efi.canTouchEfiVariables = true;
};
environment.systemPackages = with pkgs; [
];
greg = {
home = true;
tailscale = {
enable = true;
tags = [ "home" ];
};
};
networking = {
hostName = "proxmoxtemplate"; # Define your hostname.
# defaultGateway = {
# address = " 10.42.1.2";
# interface = "enp6s18";
# };
# interfaces = {
# enp6s18 = {
# ipv4.addresses = [
# {
# address = "10.42.1.8";
# prefixLength = 16;
# }
# ];
# };
# };
nameservers = [ "10.42.1.5" ];
};
services.qemuGuest.enable = true;
system.stateVersion = "24.11"; # Did you read the comment?
# Define a user account. Don't forget to set a password with passwd.
users.users.greg = {
isNormalUser = true;
description = "Greg Hellings";
extraGroups = [ "wheel" ];
packages = with pkgs; [ ];
};
}
@@ -1,50 +0,0 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{
lib,
modulesPath,
...
}:
{
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [
"uhci_hcd"
"ehci_pci"
"ahci"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" = {
device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/7115-EFA6";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.enp6s18.useDHCP = lib.mkDefault true;
}
+9 -14
View File
@@ -14,27 +14,28 @@
top.nix-hardware.nixosModules.system76
];
age.secrets = {
gitea-workerPassword.file = ../../../secrets/gitea/workerPassword.age;
};
boot.extraModulePackages = [ config.boot.kernelPackages.v4l2loopback ];
greg = {
gitea-runner = {
enable = true;
extraLabels = [ "bare-metal:host" ];
};
kubernetes = {
enable = true;
vipInterface = "enp12s0";
priority = 253;
};
nebula.enable = true;
remote-builder.enable = true;
runner = {
enable = true;
vbox = false;
};
tailscale = {
enable = true;
tags = [ "home" ];
};
vmdev = {
enable = true;
host = "vbox";
};
};
hardware = {
@@ -74,10 +75,4 @@
users.users.greg.extraGroups = [
"podman"
];
# virtualisation.virtualbox.host = {
# enableExtensionPack = true;
# headless = true;
# enableWebService = true;
# };
}
@@ -35,10 +35,11 @@
device = "/dev/nvme0n1p1";
fsType = "auto";
};
#"/mnt/disk1" = {
#device = "/dev/disk/by-uuid/0bb64e76-8811-499a-b60e-cc97808f2b0e";
#fsType = "btrfs";
#};
"/mnt/disk1" = {
device = "/dev/disk/by-uuid/bd04e868-034e-46e8-84ae-cd7347448bbd";
fsType = "xfs";
options = [ "nofail" ];
};
};
swapDevices = [ ];
-273
View File
@@ -1,273 +0,0 @@
# Edit this configuration file to define what should be installed on
# your system. Help is available in the configuration.nix(5) man page
# and in the NixOS manual (accessible by running nixos-help).
{
config,
pkgs,
lib,
...
}:
let
registryPort = 5000;
vpnIp = "100.117.28.111";
in
{
imports = [
./hardware-configuration.nix
];
age.secrets =
let
cfg = n: {
file = ../../../secrets/gitlab/${n}.age;
owner = "gitlab";
group = "gitlab";
mode = "0444";
};
in
{
gitlab-secret = cfg "secret";
gitlab-otp = cfg "otp";
gitlab-db = cfg "db";
gitlab-db-password = cfg "db-password";
gitlab-jws = cfg "jws";
gitlab-key = cfg "key";
gitlab-cert = cfg "cert";
gitlab-salt = cfg "salt";
gitlab-primary-key = cfg "primary-key";
gitlab-deterministic-key = cfg "deterministic-key";
minio_access_key_id = {
file = ../../../secrets/minio_access_key_id.age;
owner = "gitlab";
group = "gitlab";
mode = "0444";
};
minio_secret_access_key = {
file = ../../../secrets/minio_secret_access_key.age;
owner = "gitlab";
group = "gitlab";
mode = "0444";
};
};
greg = {
backup.jobs.nas-backup = {
src = "/var/gitlab/state/backup/";
dest = "gitlab";
};
home = true;
tailscale = {
enable = true;
tags = [ "home" ];
};
};
networking = {
hostName = "gitlab"; # Define your hostname.
firewall.allowedTCPPorts = [
80
registryPort
];
};
services = {
gitlab = {
enable = true;
backup = {
keepTime = 288;
startAt = [ "03:00" ];
};
databaseHost = "postgres.kubernetes";
databaseName = "gitlab";
databaseUsername = "gitlab";
databasePasswordFile = config.age.secrets.gitlab-db-password.path;
databaseCreateLocally = false;
extraConfig = {
registry.port = null;
gitlab = {
trustedProxies = [
"${vpnIp}/32" # The system itself
"100.109.86.8/32" # Public server's IP
];
};
object_store = {
enabled = true;
proxy_download = true; # Tell them to reach out to object storage themselves!
connection = {
provider = "AWS";
endpoint = "http://s3.thehellings.lan:9000";
region = "us-east-1";
aws_access_key_id = {
_secret = config.age.secrets.minio_access_key_id.path;
};
aws_secret_access_key = {
_secret = config.age.secrets.minio_secret_access_key.path;
};
path_style = true; # True for MinIO
aws_signature_version = 2;
};
#storage_options = ...;
objects = builtins.listToAttrs (
builtins.map
(
x: lib.attrsets.nameValuePair x { bucket = "gitlab-${builtins.replaceStrings [ "_" ] [ "-" ] x}"; }
)
[
"artifacts"
"ci_secure_files"
"dependency_proxy"
"external_diffs"
"lfs"
"packages"
"pages"
"terraform_state"
"uploads"
]
);
};
};
host = "src.thehellings.com";
https = true;
initialRootEmail = "greg@thehellings.com";
initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password";
pages = {
enable = true;
settings.pages-domain = "pages.thehellings.com";
};
port = 443;
puma = {
threadsMax = 6;
threadsMin = 2;
workers = 6;
};
redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}";
registry = {
enable = true;
certFile = config.age.secrets.gitlab-cert.path;
keyFile = config.age.secrets.gitlab-key.path;
externalAddress = "registry.thehellings.com";
externalPort = 443;
};
secrets = {
activeRecordDeterministicKeyFile = config.age.secrets.gitlab-deterministic-key.path;
activeRecordPrimaryKeyFile = config.age.secrets.gitlab-primary-key.path;
activeRecordSaltFile = config.age.secrets.gitlab-salt.path;
dbFile = config.age.secrets.gitlab-db.path;
jwsFile = config.age.secrets.gitlab-jws.path;
otpFile = config.age.secrets.gitlab-otp.path;
secretFile = config.age.secrets.gitlab-secret.path;
};
};
nginx = {
enable = true;
clientMaxBodySize = "25000m";
virtualHosts = {
"vm-gitlab.shire-zebra.ts.net" = {
listen = [
{
addr = "0.0.0.0";
port = 443;
ssl = true;
}
];
locations."/" = {
proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket";
recommendedProxySettings = true;
};
extraConfig = ''
ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ;
ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ;
client_max_body_size 10000m ;
'';
};
"registry" = {
listen = [
{
addr = "0.0.0.0";
port = registryPort;
ssl = true;
}
];
locations."/" = {
proxyPass = "http://127.0.0.1:4567/";
recommendedProxySettings = true;
};
extraConfig = ''
ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ;
ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ;
client_max_body_size 25000m ;
'';
serverAliases = [
"vm-gitlab.shire-zebra.ts.net"
];
};
};
};
openssh.enable = true;
postgresql.enable = true;
qemuGuest.enable = true;
redis.servers.gitlab = {
enable = true;
};
#resolved.enable = true;
};
# Do not start nginx until we have tailscaled up and running, so it can bind
# to the 100.* addresses
systemd = {
services = {
certRefresh =
let
script = pkgs.writeShellApplication {
name = "cert-refresh";
runtimeInputs = [ pkgs.tailscale ];
text = ''
cd /etc/certs
tailscale cert vm-gitlab.shire-zebra.ts.net
chown nginx ./*
systemctl reload nginx
'';
};
in
{
script = lib.getExe script;
serviceConfig = {
Type = "oneshot";
User = "root";
};
};
nginx = rec {
after = [ "network-online.target" ];
requires = [ "network-online.target" ];
wants = after;
serviceConfig = {
RestartMaxDelaySec = "30s";
RestartSteps = "5";
};
};
tailscaled.partOf = [ "network-online.target" ];
};
timers = {
"cert-refresh" = {
wantedBy = [ "cert-refresh.service" ];
timerConfig = {
OnCalendar = "monthly";
Persistent = true;
};
};
};
};
system.stateVersion = lib.mkForce "24.11";
}
@@ -1,58 +0,0 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{
lib,
modulesPath,
...
}:
{
imports = [
(modulesPath + "/profiles/qemu-guest.nix")
];
# Bootloader.
boot = {
extraModulePackages = [ ];
initrd = {
availableKernelModules = [
"uhci_hcd"
"ehci_pci"
"ahci"
"virtio_pci"
"virtio_scsi"
"sd_mod"
"sr_mod"
];
kernelModules = [ ];
};
loader = {
efi.canTouchEfiVariables = true;
systemd-boot.enable = true;
};
};
fileSystems."/" = {
device = lib.mkDefault "/dev/disk/by-uuid/1fdbe86e-ce6f-4af3-a876-aec35731adab";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-uuid/1E6A-C3BB";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
swapDevices = [ ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.enp6s18.useDHCP = lib.mkDefault true;
}
+25
View File
@@ -0,0 +1,25 @@
{ lib, ... }:
{
hostsByNet =
net: hosts:
let
netAttr =
{
lan = "ip";
nebula = "nebulaIp";
tailscale = "ts";
}
.${net};
in
lib.mapAttrsToList
(name: value: {
inherit name;
address = builtins.getAttr netAttr value;
aliases = lib.optionals (builtins.hasAttr "aliases" value) (builtins.getAttr "aliases" value);
})
(
lib.filterAttrs (
_host: settings: (builtins.hasAttr netAttr settings) && (builtins.getAttr netAttr settings) != null
) hosts
);
}
+1 -1
View File
@@ -40,7 +40,7 @@ metadata:
},
{
"path": "/mnt/disk1",
"allowScheduling": false,
"allowScheduling": true,
"tags": ["hdd", "large"]
}
]
-3
View File
@@ -21,9 +21,6 @@ spec:
spec:
containers:
- name: bitwarden-cli
# Since my gitlab instance depends on the database hosted in k3s, and
# the database depends on this image, I need a way to bootstrap the
# system if # I am doing disaster recovery. And this is it.
image: "ghcr.io/greg-hellings/nixos-config/img-bitwarden:latest"
#image: >-
# registry.thehellings.com/greg/nixos-config/img-bitwarden:latest
+5 -16
View File
@@ -1,32 +1,21 @@
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: kubernetes-dashboard
name: headlamp
spec:
url: https://kubernetes.github.io/dashboard/
url: "https://kubernetes-sigs.github.io/headlamp/"
interval: "24h"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: kubernetes-dashboard
name: headlamp
spec:
interval: "24h"
chart:
spec:
chart: kubernetes-dashboard
chart: headlamp
sourceRef:
kind: HelmRepository
name: kubernetes-dashboard
name: headlamp
interval: "24h"
values:
app:
settings:
global:
clusterName: Hellings Home
itemsPerPage: 25
ingress:
enabled: true
hosts:
- dashboard.shire-zebra.ts.net
ingressClassName: tailscale
@@ -1,15 +1,14 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: uptime-kuma-tailscale
namespace: uptime-kuma
name: dashboard-tailscale
spec:
ingressClassName: tailscale
defaultBackend:
service:
name: uptime-kuma
name: headlamp
port:
number: 3001
tls:
- hosts:
- kuma
- headlamp
+1
View File
@@ -4,3 +4,4 @@ resources:
- namespace.yaml
- chart.yaml
- user.yaml
- ingress.yaml
-89
View File
@@ -1,89 +0,0 @@
apiVersion: postgresql.cnpg.io/v1
kind: Cluster
metadata:
name: immich
spec:
imageName: "ghcr.io/corentingiraud/cnpg-pgvector-vectorchord:16-migration"
#imageName: "ghcr.io/tensorchord/cloudnative-pgvecto.rs:16-v0.3.0"
#postgresUID: 1
instances: 1
storage:
size: 60Gi
primaryUpdateStrategy: unsupervised
postgresql:
shared_preload_libraries:
- vectors.so
- vchord.so
bootstrap:
recovery:
source: origin
# initdb:
# database: immich
# owner: immich
# secret:
# name: postgres-user-immich
# dataChecksums: true
# postInitApplicationSQL:
# - ALTER SYSTEM SET search_path TO "$user", public, vectors;
# - SET search_path TO "$user", public, vectors;
# - CREATE EXTENSION IF NOT EXISTS "cube";
# - CREATE EXTENSION IF NOT EXISTS "earthdistance";
# - GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO "immich";
externalClusters:
- name: origin
plugin:
name: barman-cloud.cloudnative-pg.io
parameters:
barmanObjectName: k3sbackup-objectstore
serverName: pgvector
managed:
roles:
- name: immich
ensure: present
comment: Immich DB user
login: true
superuser: true
passwordSecret:
name: postgres-user-immich
plugins:
- name: barman-cloud.cloudnative-pg.io
isWALArchiver: true
parameters:
barmanObjectName: k3sbackup-objectstore
---
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: database-immich
spec:
name: immich
owner: immich
cluster:
name: immich
extensions:
- name: vectors
ensure: present
- name: vectorchord
ensure: present
- name: cube
ensure: present
- name: earthdistance
ensure: present
---
apiVersion: postgresql.cnpg.io/v1
kind: ScheduledBackup
metadata:
name: immich-backup
spec:
immediate: true # Create one when this is added to the cluster
schedule: "0 2 0 * * *" # 1AM, nightly
backupOwnerReference: self
cluster:
name: immich
method: plugin
pluginConfiguration:
name: barman-cloud.cloudnative-pg.io
-2
View File
@@ -14,14 +14,12 @@ spec:
- 100.88.91.27 # dns?
- 100.80.99.48 # exodus
- 100.88.91.27 # genesis
- 100.117.28.111 # gitlab
- 100.68.203.1 # hosea
- 100.84.183.79 # isaiah
- 100.102.186.39 # jeremiah
- 100.90.74.19 # zeke
- 100.115.57.8 # linode
- 100.65.5.38 # matrix
#- 100.127.55.22 # jellyfin
---
apiVersion: traefik.io/v1alpha1
kind: IngressRouteTCP
-2
View File
@@ -4,8 +4,6 @@ resources:
- namespace.yaml
- secrets.yaml
- postgres-cluster.yaml
- postgres-gitlab.yaml
- postgres-pgadmin.yaml
- postgres-matrix.yaml
- immich.yaml
- ingress.yaml
@@ -11,13 +11,6 @@ spec:
managed:
roles:
- name: gitlab
ensure: present
comment: Gitlab user
login: true
superuser: false
passwordSecret:
name: postgres-user-gitlab
- name: pgadmin
ensure: present
comment: PG Admin user
-9
View File
@@ -1,9 +0,0 @@
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: database-gitlab
spec:
name: gitlab
owner: gitlab
cluster:
name: postgres
-68
View File
@@ -1,39 +1,5 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: postgres-user-gitlab
namespace: db
spec:
target:
name: postgres-user-gitlab
deletionPolicy: Delete
template:
type: Opaque
data:
username: |-
{{ .username }}
password: |-
{{ .password }}
data:
- secretKey: username
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57
property: username
- secretKey: password
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57
property: password
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: postgres-user-matrix
namespace: db
@@ -133,37 +99,3 @@ spec:
remoteRef:
key: 685b29c6-9264-4e60-ba4a-b2ea005a5d7b
property: password
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: postgres-user-immich
namespace: db
spec:
target:
name: postgres-user-immich
deletionPolicy: Delete
template:
type: Opaque
data:
username: |-
{{ .username }}
password: |-
{{ .password }}
data:
- secretKey: username
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 5ce63e26-dd7f-46d4-b7ed-b310002ef93f
property: username
- secretKey: password
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: 5ce63e26-dd7f-46d4-b7ed-b310002ef93f
property: password
-79
View File
@@ -1,79 +0,0 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: donetick-config
namespace: donetick
data:
# Value pulled from
# https://github.com/donetick/donetick/blob/main/config/selfhosted.yaml
selfhosted.yaml: |-
name: "selfhosted"
is_done_tick_dot_com: false
is_user_creation_disabled: false
telegram:
token: ""
pushover:
token: ""
database:
type: "sqlite"
migration: true
# these are only required for postgres
host: "secret"
port: 5432
user: "secret"
password: "secret"
name: "secret"
jwt:
secret: "This is really a secure JWT secret now!"
session_time: 168h
max_refresh: 168h
server:
port: 2021
read_timeout: 10s
write_timeout: 10s
rate_period: 60s
rate_limit: 300
cors_allow_origins:
- "http://localhost:5173"
- "http://localhost:7926"
# the below are required for the android app to work
- "https://localhost"
- "capacitor://localhost"
serve_frontend: true
logging:
level: "info"
encoding: "json"
development: false
scheduler_jobs:
due_job: 30m
overdue_job: 3h
pre_due_job: 3h
email:
host:
port:
key:
email:
appHost:
oauth2:
client_id:
client_secret:
auth_url:
token_url:
user_info_url:
redirect_url:
name:
# Real-time configuration
realtime:
enabled: true
sse_enabled: true
heartbeat_interval: 60s
connection_timeout: 120s
max_connections: 1000
max_connections_per_user: 5
event_queue_size: 2048
cleanup_interval: 2m
stale_threshold: 5m
enable_compression: true
enable_stats: true
allowed_origins:
- "*"
-38
View File
@@ -1,38 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: donetick
namespace: donetick
spec:
replicas: 1
selector:
matchLabels:
app: donetick
template:
metadata:
labels:
app: donetick
spec:
containers:
- name: donetick
image: donetick/donetick
ports:
- containerPort: 2021
name: http
env:
- name: DT_ENV
value: "selfhosted"
- name: DT_SQLITE_PATH
value: "/data/donetick.db"
volumeMounts:
- name: config
mountPath: /config
- name: data
mountPath: /data
volumes:
- name: config
configMap:
name: donetick-config
- name: data
persistentVolumeClaim:
claimName: donetick-data
-15
View File
@@ -1,15 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: donetick-tailscale
namespace: donetick
spec:
ingressClassName: tailscale
defaultBackend:
service:
name: donetick
port:
number: 2021
tls:
- hosts:
- todo
-9
View File
@@ -1,9 +0,0 @@
namespace: donetick
resources:
- namespace.yaml
- configmap.yaml
- pvc.yaml
- deployment.yaml
- service.yaml
- ingress.yaml
-4
View File
@@ -1,4 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: donetick
-11
View File
@@ -1,11 +0,0 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: donetick-data
namespace: donetick
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 5Gi
-13
View File
@@ -1,13 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: donetick
namespace: donetick
spec:
selector:
app: donetick
ports:
- name: http
port: 2021
targetPort: 2021
protocol: TCP
+10 -8
View File
@@ -15,7 +15,7 @@ spec:
chart:
spec:
chart: gitea
version: "12.5.0"
version: "12.7.0"
sourceRef:
kind: HelmRepository
name: gitea-repository
@@ -35,7 +35,7 @@ spec:
storageClass: longhorn-default
image:
tag: "1.25.4"
tag: "1.27.1"
replicaCount: 1
@@ -66,8 +66,8 @@ spec:
APP_NAME: "Gitea: Greg's Cup of Git"
RUN_MODE: dev
server:
DOMAIN: "thehellings.com"
ROOT_URL: "https://src.thehellings.com"
DOMAIN: "shire-zebra.ts.net"
ROOT_URL: "https://gitea.shire-zebra.ts.net"
SSH_PORT: "2222"
database:
DB_TYPE: postgres
@@ -85,13 +85,15 @@ spec:
DISABLE_REGISTRATION: "true"
storage:
STORAGE_TYPE: minio
MINIO_ENDPOINT: "nas1.shire-zebra.ts.net:9000"
MINIO_ENDPOINT: "nas1.shire-zebra.ts.net:30188"
MINIO_BUCKET: gitea
MINIO_LOCATION: us-east-1
MINIO_LOCATION: garage
# MINIO_ACCESS_KEY_ID: ""
# MINIO_SECRET_ACCESS_KEY: ""
MINIO_USE_SSL: "false"
MINIO_INSECURE_SKIP_VERIFY: "true"
security:
ALLOWED_HOST_LIST: loopback,private,*.shire-zebra.ts.net,*.nebula.thehellings.com,*.thehellings.lan
metrics:
enabled: false
@@ -100,8 +102,8 @@ spec:
persistence:
enabled: true
storageClass: longhorn-default
size: "50Gi"
create: false
claimName: gitea-new
# I will manage my Postgres externally
postgresql:
+78
View File
@@ -0,0 +1,78 @@
apiVersion: batch/v1
kind: CronJob
metadata:
name: gitea-dump
spec:
schedule: "0 3 * * *"
successfulJobsHistoryLimit: 3
failedJobsHistoryLimit: 3
jobTemplate:
spec:
template:
spec:
restartPolicy: Never
securityContext:
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
volumes:
- name: gitea-data
persistentVolumeClaim:
claimName: gitea-new
- name: dump-staging
emptyDir: {}
initContainers:
- name: gitea-dump
image: "gitea/gitea:1.27.1"
command:
- /bin/sh
- "-c"
- |
set -e
TIMESTAMP=$(date +%Y%m%d-%H%M%S)
OUTFILE="/dump-staging/gitea-dump-${TIMESTAMP}.zip"
gitea dump \
--config /data/gitea/conf/app.ini \
--file "${OUTFILE}" \
--type zip
echo "Dump written to ${OUTFILE}"
volumeMounts:
- name: gitea-data
mountPath: /data
readOnly: true
- name: dump-staging
mountPath: /dump-staging
containers:
- name: upload-to-s3
image: "minio/mc:latest"
command:
- /bin/sh
- "-c"
- |
set -e
# Configure mc alias for MinIO
mc alias set nas1 http://nas1.shire-zebra.ts.net:30188 \
"${MINIO_ACCESS_KEY}" "${MINIO_SECRET_KEY}"
# Upload dump to backup-gitea bucket
DUMP_FILE=$(ls /dump-staging/gitea-dump-*.zip | head -1)
mc cp "${DUMP_FILE}" "nas1/gitea-backup/$(basename ${DUMP_FILE})"
echo "Uploaded $(basename ${DUMP_FILE}) to gitea-backup"
# Set 30-day lifecycle on the bucket (idempotent)
mc ilm rule add --expire-days 30 nas1/backup-gitea 2>/dev/null || true
volumeMounts:
- name: dump-staging
mountPath: /dump-staging
readOnly: true
env:
- name: MC_CONFIG_DIR
value: /tmp/.mc
- name: MINIO_ACCESS_KEY
valueFrom:
secretKeyRef:
name: gitea-backup
key: minio_key
- name: MINIO_SECRET_KEY
valueFrom:
secretKeyRef:
name: gitea-backup
key: minio_secret
+17
View File
@@ -12,3 +12,20 @@ spec:
tls:
- hosts:
- gitea
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: gitea-direct
spec:
rules:
- host: git.k3s.thehellings.lan
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: gitea-release-http
port:
name: http
+1
View File
@@ -6,3 +6,4 @@ resources:
- chart.yaml
- ingress.yaml
- secrets.yaml
- dump-cronjob.yaml
+36 -7
View File
@@ -1,5 +1,32 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: gitea-backup
spec:
target:
name: gitea-backup
deletionPolicy: Delete
template:
type: Opaque
data:
minio_key: "{{ .minio_key }}"
minio_secret: "{{ .minio_secret }}"
secretStoreRef:
name: bitwarden-login
kind: ClusterSecretStore
data:
# MinIO credentials
- secretKey: minio_key
remoteRef:
key: dfb2f0c8-110d-4e96-83a7-b49c001c0897
property: username
- secretKey: minio_secret
remoteRef:
key: dfb2f0c8-110d-4e96-83a7-b49c001c0897
property: password
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: gitea-config
spec:
@@ -13,20 +40,22 @@ spec:
USER={{ .dbuser }}
PASSWD="""{{ .dbpass }}"""
storage: |-
MINIO_ACCESS_KEY_ID={{ .minio_key }}
MINIO_SECRET_ACCESS_KEY={{ .minio_secret }}
MINIO_ACCESS_KEY_ID={{ .minio_nas1_key }}
MINIO_SECRET_ACCESS_KEY={{ .minio_nas1_secret }}
#minio_key: "{{ .minio_nas1_key }}"
#minio_secret: "{{ .minio_nas1_secret }}"
secretStoreRef:
name: bitwarden-login
kind: ClusterSecretStore
data:
# MinIO credentials
- secretKey: minio_key
# MinIO credentials for NAS1
- secretKey: minio_nas1_key
remoteRef:
key: dcbcf704-7dce-48d7-bbd1-b3a801875b3d
key: 33e8e4e0-eb90-484c-9ec9-b3a8018077a3
property: username
- secretKey: minio_secret
- secretKey: minio_nas1_secret
remoteRef:
key: dcbcf704-7dce-48d7-bbd1-b3a801875b3d
key: 33e8e4e0-eb90-484c-9ec9-b3a8018077a3
property: password
# Postgres credentials
- secretKey: dbuser
-64
View File
@@ -1,64 +0,0 @@
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: gitlab-runner
spec:
interval: "24h"
url: https://charts.gitlab.io
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: gitlab-runner
spec:
interval: 10m
chart:
spec:
chart: gitlab-runner
version: "0.83.1"
sourceRef:
kind: HelmRepository
name: gitlab-runner
interval: "1h"
dependsOn:
- name: external-secrets
namespace: external-secrets
- name: tailscae
namespace: tailscale
values:
crds:
create: true
includeCRDs: true
gitlabUrl: https://src.thehellings.com
runners:
secret: gitlab-runner
imagePullSecrets:
- name: image-pull-secrets
rbac:
create: true
serviceAccount:
create: true
metrics:
enabled: true
extraEnv:
CACHE_TYPE: s3
CACHE_SHARED: "true"
CACHE_S3_BUCKET_NAME: gitlab-runner-cache
CACHE_S3_INSECURE: "true"
extraEnvFrom:
PACKER_GITHUB_API_TOKEN:
secretKeyRef:
name: gitlab-runner
key: PACKER_GITHUB_API_TOKEN
CACHE_S3_SERVER_ADDRESS:
secretKeyRef:
name: gitlab-runner
key: CACHE_S3_SERVER_ADDRESS
CACHE_S3_ACCESS_KEY:
secretKeyRef:
name: s3-access
key: username
CACHE_S3_SECRET_KEY:
secretKeyRef:
name: s3-access
key: password
@@ -1,6 +0,0 @@
namespace: gitlab-runner
resources:
- namespace.yaml
- secrets.yaml
- chart.yaml
-4
View File
@@ -1,4 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: gitlab-runner
-101
View File
@@ -1,101 +0,0 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: gitlab-runner
namespace: gitlab-runner
spec:
secretStoreRef:
name: bitwarden-fields
kind: ClusterSecretStore
target:
name: gitlab-runner
deletionPolicy: Delete
template:
type: Opaque
data:
runner-registration-token: ""
runner-token: "{{ .runnerToken }}"
PACKER_GITHUB_API_TOKEN: "{{ .PACKER_GITHUB_API_TOKEN }}"
CACHE_S3_SERVER_ADDRESS: "{{ .CACHE_S3_SERVER_ADDRESS }}"
data:
- secretKey: runnerToken
remoteRef:
key: &key 53719920-b100-4355-8c80-b2f9002fad22
property: CI_SERVER_TOKEN
- secretKey: PACKER_GITHUB_API_TOKEN
remoteRef:
key: *key
property: PACKER_GITHUB_API_TOKEN
- secretKey: CACHE_S3_SERVER_ADDRESS
remoteRef:
key: *key
property: CACHE_S3_SERVER_ADDRESS
# Includes
# CI_SERVER_TOKEN
# PACKER_GITHUB_API_TOKEN
# CACHE_S3_SERVER_ADDRESS
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: s3-access
namespace: gitlab-runner
spec:
secretStoreRef:
name: bitwarden-login
kind: ClusterSecretStore
target:
name: s3-access
deletionPolicy: Delete
data:
- secretKey: username
remoteRef:
key: &key 04dd39c2-268d-4a33-aa4c-b1550166139f
property: username
- secretKey: password
remoteRef:
key: *key
property: password
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: image-pull-secrets
namespace: gitlab-runner
spec:
secretStoreRef:
name: bitwarden-login
kind: ClusterSecretStore
target:
deletionPolicy: Delete
template:
type: kubernetes.io/dockerconfigjson
data:
.dockerconfigjson: >-
{
"auths": {
"https://index.docker.io/v1/": {
"username": "{{ .user }}",
"password": "{{ .password }}",
"email": "greg.hellings@gmail.com",
"auth": "{{ .auth }}"
}
}
}
data:
- secretKey: user
remoteRef:
key: &key f560ae38-368c-4e58-898c-aeb90012d597
property: username
- secretKey: password
remoteRef:
key: *key
property: password
- secretKey: auth
sourceRef:
storeRef:
name: bitwarden-fields
kind: ClusterSecretStore
remoteRef:
key: *key
property: auth
+36
View File
@@ -0,0 +1,36 @@
apiVersion: v1
kind: Namespace
metadata:
name: external-secrets
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: external-secrets
namespace: external-secrets
spec:
interval: "24h"
url: "https://charts.external-secrets.io/"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: external-secrets
namespace: external-secrets
spec:
interval: 10m
chart:
spec:
chart: external-secrets
version: "2.3.0"
sourceRef:
kind: HelmRepository
name: external-secrets
interval: "1h"
values:
crds:
create: true
includeCRDs: true
webhook:
certManager:
enable: true
+3
View File
@@ -1,3 +1,6 @@
resources:
- kyverno.yaml
- external-secrets.yaml
- tailscale.yaml
- longhorn.yaml # Needed for storage
- traefik.yaml
+40
View File
@@ -0,0 +1,40 @@
apiVersion: v1
kind: Namespace
metadata:
name: kyverno-system
---
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: kyverno
namespace: kyverno-system
spec:
interval: "24h"
url: "https://kyverno.github.io/kyverno/"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: kyverno
namespace: kyverno-system
spec:
interval: 10m
chart:
spec:
chart: kyverno
version: "3.7.1"
sourceRef:
kind: HelmRepository
name: kyverno
interval: "1h"
values:
admissionController:
replicas: 3
backgroundController:
replicas: 3
cleanupController:
replicas: 2
reportsController:
replicas: 2
crds:
install: true
+10 -1
View File
@@ -19,10 +19,15 @@ metadata:
namespace: longhorn-system
spec:
interval: 10m
dependsOn:
- name: tailscale
namespace: tailscale
- name: kyverno
namespace: kyverno-system
chart:
spec:
chart: longhorn
version: "1.10.2"
version: "1.11.3"
sourceRef:
kind: HelmRepository
name: longhorn
@@ -136,6 +141,10 @@ spec:
number: 80
- <<: *host
host: longhorn.kubernetes
- <<: *host
host: longhorn.k3s.nebula.thehellings.com
- <<: *host
host: longhorn.k3s.thehellings.lan
---
apiVersion: storage.k8s.io/v1
kind: StorageClass

Some files were not shown because too many files have changed in this diff Show More