42 Commits
Author SHA1 Message Date
Greg Hellings a102ff29d3 fix: remove pgadmin from Kubernetes
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-08-10 14:31:49 -05:00
greg a8ba8f247d Merge pull request 'fix: correct too-aggressive HAProxy keep-alive timeout from #39' (#40) from emily/nixos:fix/haproxy-keepalive-timeout-too-aggressive into main 2026-08-10 17:54:44 +00:00
emily 6f63b38497 fix: correct too-aggressive HAProxy client keep-alive timeout from #39
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
DAVx5 (CalDAV/CardDAV) reported the exact same 'unexpected end of
stream' / EOFException error again at 2026-08-10T04:00:58Z, roughly
15 minutes after PR #39 deployed. That PR's backend-side fix (option
http-server-close on 'backend next') is confirmed working -
journalctl/nginx access logs show a completely clean, uninterrupted
request stream on the haproxy<->nginx leg through the exact failure
timestamp.

Root cause of the recurrence: PR #39 also added 'timeout
http-keep-alive 30s' to defaults, intended as an unrelated tidy-up
given maxconn=80. That value didn't account for client-side HTTP
connection pooling: DAVx5 runs on OkHttp, which holds idle pooled
connections open for up to 5 minutes by default before evicting them.
With haproxy closing idle client-facing keep-alive connections after
just 30s, any DAVx5 connection idle between 30s-300s got silently
closed by haproxy while the client still considered it live - the
client's next reuse attempt produced exactly the same class of error,
just relocated from the haproxy<->nginx leg to the client<->haproxy
leg instead of being fixed.

Fix:
- defaults: raise 'timeout http-keep-alive' from 30s to 6m, safely
  above OkHttp's 300s (5min) idle-eviction default, so a client's own
  pool always evicts a stale connection before haproxy would.
- backend next: add 'log-tag next' so this backend's haproxy log
  lines carry a distinct syslog tag ('journalctl -t next') instead of
  being interleaved with every other backend under the shared
  'haproxy' tag - this specific incident took significant manual
  grep/awk work to isolate 'next' traffic from git/matrix/immich noise
  in the same log stream, which a dedicated tag eliminates going
  forward.

Verified by comparing haproxy's own next/nextcloud access log lines
(all showing normal termination, no CD/SD flags) against nginx's
nginx_access journal (clean, continuous, no gap) across the exact
04:00:58 UTC failure window - confirming the backend-side legs were
healthy and the failure had to be on the client<->haproxy leg instead.

Could not run 'haproxy -c' locally (no toolchain in the agent
sandbox) - recommend confirming via CI/garnix before merge, same
caveat as prior PRs in this series (#37, #38, #39).
2026-08-09 23:09:31 -05:00
greg bc90eb34e4 Merge pull request 'fix: prevent HAProxy from reusing stale keep-alive conns to nginx/Nextcloud' (#39) from emily/nixos:fix/haproxy-stale-keepalive-nextcloud into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: #39
2026-08-10 03:24:39 +00:00
emily 2c3607f17c fix: prevent HAProxy from reusing stale keep-alive conns to nginx/Nextcloud
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
DAVx5 (CalDAV/CardDAV) on greg's phone was intermittently failing every
sync type (CONTACTS/EVENTS/TASKS/RefreshCollectionsWorker) against
next.thehellings.com with:

  java.io.IOException: unexpected end of stream
  Caused by: java.io.EOFException: \n not found: limit=0

This is the classic OkHttp/HTTP client signature of the far end
silently closing a pooled keep-alive connection: the client reuses a
socket it still believes is open, gets zero bytes back while reading
response headers, and throws exactly this exception.

Root cause: HAProxy's 'next' backend proxies to nginx on
127.0.0.1:8080, and HAProxy defaults to end-to-end keep-alive (both
client- and server-side) unless told otherwise. nginx's
keepalive_timeout is 65s, so any HAProxy<->nginx connection idle past
that gets closed by nginx without HAProxy's knowledge. A request that
lands on that now-dead pooled connection right after gets nothing back
- surfacing to the client as a bare socket EOF while reading headers.
The frontend's existing 'option http-server-close'/'http-keep-alive'
pair only governs the client-facing side of HAProxy and does nothing
for the HAProxy->nginx leg.

Fix:
- backend next: add 'option http-server-close' so HAProxy opens a
  fresh connection to nginx per request instead of pooling/reusing
  one. The backend is localhost, so the extra TCP handshake cost is
  negligible, and this removes the whole class of stale-connection EOF
  errors.
- defaults: add 'timeout http-keep-alive 30s' to bound how long an
  idle client-facing keep-alive connection is held open. Previously
  unset, it fell back to 'timeout client' (500s) - unnecessarily long
  given maxconn is only 80, and tightens client-side connection churn
  to be more predictable too.

Diagnosed by pulling the nginx_access journal (enabled in #37/#38) for
the failing sync window and cross-referencing nginx's
services.nginx.appendHttpConfig / generated nginx.conf keepalive
settings against HAProxy's request-level defaults. Could not run
'haproxy -c'/'nginx -t' locally (no toolchain in the agent sandbox) -
recommend confirming via CI/garnix before merge, same as #38.
2026-08-09 22:21:20 -05:00
greg daa33daa0c Merge pull request 'fix: nginx syslog tag must use underscore, not hyphen (fixes Nextcloud 503)' (#38) from emily/nixos:fix/nginx-syslog-tag-underscore into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: #38
Reviewed-by: greg <gitea@local.domain>
2026-08-10 02:42:55 +00:00
emily e4fe9e84bd fix: nginx syslog access_log tag must not contain a hyphen
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
The nginx_access syslog tag added in #37 (feat/emily-incident-logging)
used tag=nginx-access. nginx's syslog sink only accepts alphanumeric
characters and underscores in the tag field, so the generated
nginx.conf failed its config test on linode:

  nginx: [emerg] syslog "tag" only allows alphanumeric characters
  and underscore in .../nginx.conf:114

Because nginx-pre-start failed, nginx.service crash-looped until it
hit systemd's start-limit-hit and gave up entirely. Since Nextcloud is
proxied through nginx (127.0.0.1:8080, fronted by haproxy's 'next'
backend), this took next.thehellings.com down with a 503 from haproxy
(phpfpm-nextcloud/postgresql/redis backends were all healthy and
unaffected - purely an nginx config parse failure).

Fix: use an underscore (nginx_access) instead of a hyphen.
2026-08-09 21:38:53 -05:00
greg 7aa91491e4 Merge pull request 'chore: clean up builder2, Ceph module, normalize Darwin host symlinks' (#34) from emily/nixos:chore/cleanup-builder2-darwin-ceph-joel into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: #34
2026-08-09 21:36:35 +00:00
greg d1459a7f63 Merge pull request 'feat: enable request-level logging for bandwidth/traffic incident tracing' (#37) from emily/nixos:feat/emily-incident-logging into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: #37
2026-08-09 21:33:54 +00:00
emily 10cdf9408d feat: enable request-level logging for bandwidth/traffic incident tracing
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
Triggered by investigating a several-hour >10Mbps traffic spike to
linode. HAProxy's own IPAccounting confirmed ~121GB moved over ~19.6h
before it crash-looped, but with 'option httplog' commented out and no
per-backend request logs, there was no way to attribute that traffic
to a specific backend, host, or client.

- linode: enable HAProxy httplog + defaults 'log global' (was
  commented out) so every proxied HTTP request is now logged with
  timing/status/bytes.
- linode: add a haproxy 'stats' listener on 127.0.0.1:8404 for live
  per-backend/per-server connection and byte counters.
- linode: route nginx (Nextcloud's local vhost) access logs to
  journald via syslog, since the read-only monitoring account has no
  access to /var/log/nginx/*.
- linode: enable vnstat for historical per-interface bandwidth
  tracking (5-min granularity) so a reported 'traffic was high for N
  hours' can be confirmed/timestamped immediately instead of
  reconstructed after the fact from journal timestamps.
- k3s manifests: enable Traefik access logging (JSON) — this is the
  ingress layer HAProxy forwards :80 traffic to (git/matrix/immich),
  and lacked any per-request visibility.
- hosts/baseline.nix (fleet-wide): add a journald rate limit
  (2000 lines / 30s per unit). Found live while investigating that
  uptime-kuma on 'kuma' was logging a Prometheus label-validation
  error on every monitor beat (~100k lines/hour), which was itself
  degrading journalctl responsiveness on that host during the
  cross-host traffic scan.

Related but not otherwise addressed here: Nebula relay/handshake
churn on kuma's tunnel and the etcd read-latency warnings seen on
isaiah/zeke around the same incident window — noted for a future
investigation, not fixed by this PR.
2026-08-09 16:15:35 -05:00
greg 3995eee7b0 Merge pull request 'feat: add read-only emily monitoring account' (#36) from emily/nixos:feat/emily-monitoring-account into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: #36
2026-08-09 19:54:45 +00:00
emily 3cba4cbd86 feat: add read-only emily monitoring account
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
Adds a new NixOS module (greg.monitoring-access) that provisions a
dedicated, SSH-key-only 'emily' user account across all managed hosts.

The account is intentionally minimal-privilege:
- No password set (SSH key auth only)
- Not a member of wheel, no sudo/sudo-rs rules
- Only extra group membership is systemd-journal, granting read access
  to system logs for monitoring/analysis tasks
- Authorized key lives in home/ssh/emily_authorized_keys, mirroring the
  existing pattern used for the greg account's authorized_keys

This lets the Hermes agent (emily) log in read-only to inspect logs and
system state when asked, without any ability to modify configuration,
escalate privileges, or run destructive commands.

Module is imported unconditionally in modules/nixos/default.nix like
the other nixos modules, and defaults to enabled; it can be disabled
per-host via greg.monitoring-access.enable = false if ever needed.
2026-08-09 07:38:01 -05:00
emily 28977235a1 chore: clean up builder2, Ceph module, normalize Darwin host symlinks
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
- Remove builder2 (retired host): dangling network.json entry and
  empty home/hosts/builder2 stub. Its old IP (10.42.1.17) is already
  correctly owned by pve4.
- Remove the abandoned Ceph module (modules/nixos/ceph.nix) and its
  unencrypted plaintext keyring files under secrets/. No host ever
  enabled services.ceph-benaco; the keyrings were dead, unencrypted
  credentials sitting in the repo.
- Normalize Darwin host identity: IVR and Lithic are the only two
  physical Darwin machines. All other darwin/hosts/* names are now
  symlinks to whichever of the two they represent, matching the DHCP
  name variations nix-darwin sees depending on network:
    gregory -> ivr
    gregory.hellings-mbp -> ivr
    MacBook-Prolocal -> ivr
    gregs-MacBook-Pro-16-inch-Nov-2024 -> lithic
    li -> lithic (pre-existing)
  This lets each machine's config be maintained once regardless of
  what hostname it currently advertises.
2026-08-08 02:49:50 -05:00
Greg Hellings 7243c7b1c0 fix: update gitea base URL
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-08-08 01:00:46 -05:00
Greg Hellings e89b5ca5d1 fix: use IP address for nextcloud host 2026-08-08 01:00:12 -05:00
greg 076df9f924 Merge pull request 'fix: correct pve1 IP to 10.42.0.4, rename stale joel/opnsense refs' (#32) from emily/nixos:fix/pve1-ip-correction into main
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
Reviewed-on: #32
2026-08-08 05:58:50 +00:00
emily fcb5a89727 fix: correct pve1 IP to 10.42.0.4, rename stale joel/opnsense refs
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
pve1 is a static/DHCP-reserved Proxmox host at 10.42.0.4 (previously
mislabeled 'joel' in some places). 10.42.1.1 is the UDM Pro gateway
IP, not pve1 -- OPNsense was retired in favor of Ubiquiti. Removes
the stale duplicate PVE1 DHCP reservation at 10.42.1.1 and drops the
now-redundant 'joel' entry from network.json (consolidated into
pve1).
2026-08-08 00:44:21 -05:00
Greg Hellings c9671121dd fix: restore matrix well-known server
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-08-07 17:19:45 -05:00
Greg Hellings a00773c97a fix: remove builder2
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-08-06 22:53:34 -05:00
Greg Hellings 6bf0bcc0ef fix: restore immich access
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-builder2 Build done.
buildbot/nix-build Build done.
2026-08-06 21:43:28 -05:00
Greg Hellings 7619bf6258 chore: default actions packages 2026-08-06 20:36:41 -05:00
Greg Hellings 029b71d0d4 Pass traffic through genesis
* keepalived does not work with Nebula VPN
* update Genesis firewall to allow passing through local traffic
* target all traffic directly to the LAN IP using genesis's routing
2026-08-05 22:57:58 -05:00
Greg Hellings d779d275f2 Expose kubernetes on LAN 2026-08-05 20:07:35 -05:00
Greg Hellings 0196f1fd07 chore: re-enable linode gitea-runner
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-builder2 Build done.
buildbot/nix-build Build done.
2026-08-04 10:14:56 -05:00
Greg Hellings 6a13d843d7 chore: point homepage to new registry url
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-builder2 Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.nixos-hosea Build done.
buildbot/nix-build Build done.
2026-08-04 09:26:28 -05:00
Greg Hellings 8673d6193b chore: immich backup to Garage 2026-08-04 09:19:53 -05:00
Greg Hellings bbdfe1e1de chore: update Gitea to backup to Garage 2026-08-03 20:46:48 -05:00
Greg Hellings 71486e9ab3 chore: update Longhorn version 2026-08-03 20:46:20 -05:00
Greg Hellings 8a8664287f chore: remove gitea-runner 2026-08-03 18:56:23 -05:00
Greg Hellings 4965d42e59 chore: remove smokeping and donetick from k8s 2026-08-03 18:55:07 -05:00
Greg Hellings 03e174367d chore: uptimekuma migrated to NixOS 2026-08-03 18:52:01 -05:00
Greg Hellings 21cb84ac7a Major update for linode and Nebula
* Consolidate Linode into a single file
* Convert gitea and matrix to using Nebula connections
* Have Linode proxy to Nebula connections instead of Tailscale
* Update Acme to use DNS-01
* Update Flake to pull from branch that supports ACME 5.x client
2026-08-01 14:38:01 -05:00
Greg Hellings 1c52f8a6b9 chore: baseline nixos for proxmox configuration 2026-07-28 22:42:21 -05:00
Greg Hellings d9334a237d chore: first bit of local IP querying 2026-07-28 22:41:01 -05:00
Greg Hellings 93a847c658 chore: get kuma up and running 2026-07-28 22:40:17 -05:00
Greg Hellings b9051d017e chore: add java web start to exodus 2026-07-28 19:50:24 -05:00
Greg Hellings b9dcd227e8 chore: fix wait-forever bug in updater
buildbot/nix-eval Build done. (2 warnings)
buildbot/nix-build Build done.
buildbot/nix-effects Build done.
2026-07-27 07:27:34 -05:00
Greg Hellings 2d816d50e0 chore: update zim pins 2026-07-27 07:19:37 -05:00
Greg Hellings 5f951c6c12 chore: fix zims updater
Zims update script has been slightly mangled since nix-prefetch stopped
working.

Now it is updated to use nix-prefetch-url and no longer pulls from the
Torrent sources. That script exports a regular SHA256 hash and not an
SRI signature, so we now convert that to SRI as a second step in the
pre-fetch pipline

Also adding a cron to run the tool every month on the first, in order to
keep it up to date.
2026-07-26 21:36:46 -05:00
Greg Hellings 42efe476db chore: update framework firmware settings 2026-07-26 21:36:46 -05:00
greg 07e85d35ab Merge pull request 'chore: update flake.lock 2026-07-19' (#29) from auto/update-flake-lock-20260719 into main
buildbot/nix-eval Build done. (2 warnings)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-builder2 Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-exodus Build done.
buildbot/nix-build Build done.
Reviewed-on: https://src.thehellings.com/greg/nixos/pulls/29
2026-07-25 20:54:30 +00:00
klaatuandgreg 1d9921f1ae chore: update flake.lock 2026-07-19
buildbot/nix-eval Build done. (2 warnings)
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.pkg-setup-ssh Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-builder2 Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-icdm-root Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-hermes Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-linode Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-jeremiah Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-zeke Build done.
buildbot/nix-build gitea:greg/nixos#checks.x86_64-linux.hm-exodus Build done.
buildbot/nix-build Build done.
2026-07-25 17:06:07 +00:00
128 changed files with 1531 additions and 2809 deletions
+51
View File
@@ -0,0 +1,51 @@
name: Update zims pin
"on":
schedule:
- cron: "0 2 1 * *" # 0200 on the first of every month
workflow_dispatch:
jobs:
update-flake-lock:
runs-on: nix-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Update flake.lock
run: nix run .#zim-updater -- --output pkgs/zim/blobs.json
- name: Create PR if changed
env:
GITEA_TOKEN: ${{ secrets.KLAATU_TOKEN }}
GITEA_URL: https://src.thehellings.com
REPO: greg/nixos
run: |
if git diff --quiet pkgs/zim/blobs.json; then
echo "blobs.json unchanged, nothing to do"
exit 0
fi
BRANCH="auto/update-zims-$(date +%Y%m%d)"
git config user.email "klaatu@thehellings.com"
git config user.name "klaatu"
git checkout -b "$BRANCH"
git add pkgs/zim/blobs.json
git commit -m "chore: update zim blobs.json $(date +%Y-%m-%d)"
# Push branch using token auth
git remote set-url origin "https://klaatu:${GITEA_TOKEN}@${GITEA_URL#https://}/${REPO}.git"
git push origin "$BRANCH"
# Create PR via Gitea API
curl -s -X POST \
-H "Authorization: token ${GITEA_TOKEN}" \
-H "Content-Type: application/json" \
"${GITEA_URL}/api/v1/repos/${REPO}/pulls" \
-d "{
\"title\": \"chore: update zims $(date +%Y-%m-%d)\",
\"head\": \"$BRANCH\",
\"base\": \"main\",
\"body\": \"Automated monthly zims update.\\n\\nGenerated by Gitea Actions.\",
\"assignees\": [\"greg\"]
}"
+1 -1
View File
@@ -1 +1 @@
gregory
ivr
+1
View File
@@ -0,0 +1 @@
ivr
+1 -1
View File
@@ -1 +1 @@
gregory
ivr
+1
View File
@@ -0,0 +1 @@
lithic
-1
View File
@@ -1 +0,0 @@
gregory/
Generated
+57 -57
View File
@@ -31,11 +31,11 @@
"treefmt-nix": "treefmt-nix"
},
"locked": {
"lastModified": 1783231291,
"narHash": "sha256-iaoW3Enrb51mCT4AIixKXgkb1LdI/ikpCV9sV+zmkYU=",
"lastModified": 1783833875,
"narHash": "sha256-G+hRtNJ/Nnr6VFMQp2UZdx/ckJDR/RJoK0Fy/yx1/YY=",
"owner": "nix-community",
"repo": "buildbot-nix",
"rev": "d8a926f66587ed37df1a422205d7aeb1692700f8",
"rev": "147af587241e2af85399402da60a4f44fdb1e5d7",
"type": "github"
},
"original": {
@@ -53,11 +53,11 @@
"stable": "stable"
},
"locked": {
"lastModified": 1783265280,
"narHash": "sha256-n+TVzNkFtsW+ghl7JeFJYwIbXaZ2tn/WgjVMXwlzybI=",
"lastModified": 1783909498,
"narHash": "sha256-T9OfLPLuh1Bf1xojlpWXwooJ6IXapxvb8GM0p3YNy8g=",
"owner": "zhaofengli",
"repo": "colmena",
"rev": "e4250e61da7e007e19e8e17d8675b88ad27d6c06",
"rev": "76ba0daa542880b730faec81f4e87efcaa63bc57",
"type": "github"
},
"original": {
@@ -95,11 +95,11 @@
]
},
"locked": {
"lastModified": 1783395956,
"narHash": "sha256-AAbexQvDoK+6GFJdhY6kqjA+6ECKRkidgWxkn4gMwAA=",
"lastModified": 1784362797,
"narHash": "sha256-EP9b9b+OXDxHBPefFwMYCIaLq0fn3UkmrbfzbLUT7kQ=",
"owner": "lnl7",
"repo": "nix-darwin",
"rev": "d5bd9cd77aea4c0a8f49e7fd85545671a208ed15",
"rev": "b4cccbd4bc299c1f71ae185b79c3cf99aa82805c",
"type": "github"
},
"original": {
@@ -242,11 +242,11 @@
]
},
"locked": {
"lastModified": 1783436070,
"narHash": "sha256-F80z1JoiJgZyTT5D+3siLOVzqmCEphLR7t0Ym/I2CLI=",
"lastModified": 1784407317,
"narHash": "sha256-iZrxHToDJWnvt+5LGAtvuQMTy1NZYlNEKbKaVtBJNcc=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "f09af49406ffad37acb6538d3207189a1a1e0b7e",
"rev": "39411a8e12a5526d992e65bc7e3dc9a4414d6713",
"type": "github"
},
"original": {
@@ -284,11 +284,11 @@
"systems": "systems_3"
},
"locked": {
"lastModified": 1783397047,
"narHash": "sha256-aXPvDeF7F0sKg2MWglAtSz6h1R6a9+V7Y2k24At2Q9o=",
"lastModified": 1784344393,
"narHash": "sha256-yAo2ZzSIdeBZg7cOKUpQxwflL+DRYN+1DMObZk2lP2Q=",
"owner": "Infinidoge",
"repo": "nix-minecraft",
"rev": "ed748d3593082a7e02d2c49b7643ecac3a7efde4",
"rev": "7297d14c52ec8ef39c6aeff2c1818541fd030473",
"type": "github"
},
"original": {
@@ -303,11 +303,11 @@
"treefmt-nix": "treefmt-nix_2"
},
"locked": {
"lastModified": 1783166611,
"narHash": "sha256-8xyWfpItjSdMiR2bRdUf+Nj1T1Vdctgn4K7jVUyAaOk=",
"lastModified": 1784016977,
"narHash": "sha256-TydDba3YD2u15uS0L+PDs7lMqPopnzWggljTKDqOCSw=",
"owner": "Mic92",
"repo": "niks3",
"rev": "b45810677be67de714cbb4ff53f036bdb2e5f9a0",
"rev": "b306808bf381e7e66e33de1e9446a1be0935f4e3",
"type": "github"
},
"original": {
@@ -342,11 +342,11 @@
"nixpkgs": "nixpkgs_4"
},
"locked": {
"lastModified": 1783370751,
"narHash": "sha256-E+3MIMvKuo9k+K+qLQ9YXzsBzkgHuyVLnsEbN2DFfuc=",
"lastModified": 1784310968,
"narHash": "sha256-rkSPTePrKqs4dg+i7ZFCq93+HrClac6oSwXX927SVjA=",
"owner": "nixos",
"repo": "nixos-hardware",
"rev": "662bd6e312d2c8b212e32cb377abaee190749320",
"rev": "779c32a00155994c86cde8213a8dd4df139d4355",
"type": "github"
},
"original": {
@@ -357,11 +357,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1782723713,
"narHash": "sha256-oPXCU/SSUokcGaJREHibG1CBX3+s/W7orDWQOZDsEeQ=",
"lastModified": 1783224372,
"narHash": "sha256-8i/87eeoqiGE4yOTjwSA3Eh/ziJRQEmd/unYU+K27sk=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "b5aa0fbd538984f6e3d201be0005b4463d8b09f8",
"rev": "d407951447dcd00442e97087bf374aad70c04cea",
"type": "github"
},
"original": {
@@ -388,11 +388,11 @@
},
"nixpkgs-lib_2": {
"locked": {
"lastModified": 1783217952,
"narHash": "sha256-lItVCcSNUiL9NlB0+VoZwhtZk+0jAnfjJjch1g7U0bM=",
"lastModified": 1783821755,
"narHash": "sha256-eMPX9S6MKPyUnaOgeRfrG7OKUiAlc1AlcRinMbSB0WA=",
"owner": "nix-community",
"repo": "nixpkgs.lib",
"rev": "830143f1e74a5ce8aa6cdad9c41ae84b73e8b3be",
"rev": "228ab8523d81526e57a6ca342e1a919fb6d246a8",
"type": "github"
},
"original": {
@@ -419,11 +419,11 @@
},
"nixpkgs_3": {
"locked": {
"lastModified": 1782774429,
"narHash": "sha256-1tRFhlVVSBP2UAyJ4fWV3wRxofOZQCIWmbXJS/kQw7U=",
"lastModified": 1783978241,
"narHash": "sha256-7kK0Y/fIV2NTKArkd/eZGaFg+dEmgP8KDRsGK2vB5M4=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "c3db893991ef9cf1902c661c2d61249bcfb051dc",
"rev": "a8b81d3cc8d35af7bc98694696bea61ad4f8fca7",
"type": "github"
},
"original": {
@@ -448,11 +448,11 @@
},
"nixpkgs_5": {
"locked": {
"lastModified": 1783279667,
"narHash": "sha256-/NAkDSsve+GNM0Bt6tleJdCGfsTlK89nPjkVOzZMo0s=",
"lastModified": 1783915482,
"narHash": "sha256-FmieJB8/OUvNxbkboi7+IGfIuSXY3nF/hZQm8kD0r50=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "f205b5574fd0cb7da5b702a2da51507b7f4fdd1b",
"rev": "6cdc7fc76e8bf7fde9fa43a849fcaaa70e230dee",
"type": "github"
},
"original": {
@@ -464,11 +464,11 @@
},
"nixpkgs_6": {
"locked": {
"lastModified": 1783224372,
"narHash": "sha256-8i/87eeoqiGE4yOTjwSA3Eh/ziJRQEmd/unYU+K27sk=",
"lastModified": 1784356753,
"narHash": "sha256-12KrbMiWLcf8m7pCvAtZh1ZrgF85ZXDXvfR/fWTKy84=",
"owner": "nixos",
"repo": "nixpkgs",
"rev": "d407951447dcd00442e97087bf374aad70c04cea",
"rev": "61b7c44c4073f0b827768aff0049561b5110ea5a",
"type": "github"
},
"original": {
@@ -496,16 +496,16 @@
},
"nixunstable": {
"locked": {
"lastModified": 1783224372,
"narHash": "sha256-8i/87eeoqiGE4yOTjwSA3Eh/ziJRQEmd/unYU+K27sk=",
"owner": "nixos",
"lastModified": 1784700541,
"narHash": "sha256-LcCdjhqwjFVrFTNW6tHm3KNYRrD1TA6bYRea30yIIjw=",
"owner": "geri1701",
"repo": "nixpkgs",
"rev": "d407951447dcd00442e97087bf374aad70c04cea",
"rev": "3c598184d1f70c5d0beeea8b95d01ab0179e4ef7",
"type": "github"
},
"original": {
"owner": "nixos",
"ref": "nixos-unstable",
"owner": "geri1701",
"ref": "lego-v5-acme-spike",
"repo": "nixpkgs",
"type": "github"
}
@@ -517,11 +517,11 @@
"systems": "systems_4"
},
"locked": {
"lastModified": 1783349931,
"narHash": "sha256-aYE76ATiGBg7/cQ2dHASRq97WvNum4OOIPgZ8xIK0QI=",
"lastModified": 1784057377,
"narHash": "sha256-yycNej5//EsRbV10moBoh+/63vXEwZD1ZFEiRm6C9rQ=",
"owner": "nix-community",
"repo": "nixvim",
"rev": "4fd45857deecb90d2732c87e0315daa48505515e",
"rev": "07180a087e4a00720dc0731cbcd8dec796974381",
"type": "github"
},
"original": {
@@ -537,11 +537,11 @@
"nixpkgs": "nixpkgs_6"
},
"locked": {
"lastModified": 1783451984,
"narHash": "sha256-pOIx6pF9DJCeGuDostAegvtmWhbX0ze0bLCzXYHkt94=",
"lastModified": 1784417922,
"narHash": "sha256-19XZ56wJXArMKxjY25pKXkNp/FrYHGoo+HuQtW6teSM=",
"owner": "nix-community",
"repo": "NUR",
"rev": "9d0a05bf73440e7e870c011a6c16e7e8636d98fd",
"rev": "2c806d314605495dd7fd75b5950003a062e2b47a",
"type": "github"
},
"original": {
@@ -571,11 +571,11 @@
},
"stable": {
"locked": {
"lastModified": 1783021296,
"narHash": "sha256-WYOmcI0zSkkU4VpR7xda8o0AWNC9xuqkEM7n4tKjJY8=",
"lastModified": 1783625654,
"narHash": "sha256-pI1244/PJfTyKhlAr2QYQC55vR6UQdnGA0rJUgtO2IQ=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "d3474199ff806484bfccd1fdef7afc27fb8d74b5",
"rev": "a0230bd8d5cbd13893b2263918d396a2c7dd0407",
"type": "github"
},
"original": {
@@ -693,11 +693,11 @@
"nixpkgs": "nixpkgs_7"
},
"locked": {
"lastModified": 1783396462,
"narHash": "sha256-0Q3WQGlhzTb6QAXnmleX55Pqn+La4lcXupW1ElN/gZI=",
"lastModified": 1784343266,
"narHash": "sha256-EGkegdTz2n6ESyih8s3dUuPyJQWlYfPp7U41J05g8PY=",
"owner": "nix-community",
"repo": "nix-vscode-extensions",
"rev": "98798c612761584740eed894f3ca1e1a1a856ac0",
"rev": "472a3e862c76c64ac3ad75a24d332cb5cdd5f1bb",
"type": "github"
},
"original": {
@@ -714,11 +714,11 @@
]
},
"locked": {
"lastModified": 1783336371,
"narHash": "sha256-ZisTtweyb7JUwPP54HAXE9TypT8m89dIxDI36Ak0hAs=",
"lastModified": 1784058842,
"narHash": "sha256-3u3tvbCIAid3Mv7RrJx13jusIEQC/HeKYhO/SUSxR3A=",
"owner": "nix-community",
"repo": "NixOS-WSL",
"rev": "a9620cfa43f0c1c30a46c31ae3c6e58cdb124a14",
"rev": "24c8dc8e0f2170e1a377be24dfadc7d9d21dc1ad",
"type": "github"
},
"original": {
+3 -2
View File
@@ -28,7 +28,8 @@
nix-hardware.url = "github:nixos/nixos-hardware";
nixpkgs-lib.url = "github:nix-community/nixpkgs.lib";
nixvimunstable.url = "github:nix-community/nixvim/main";
nixunstable.url = "github:nixos/nixpkgs/nixos-unstable";
#nixunstable.url = "github:nixos/nixpkgs/nixos-unstable";
nixunstable.url = "github:geri1701/nixpkgs/lego-v5-acme-spike";
nurpkgs.url = "github:nix-community/NUR";
vsext.url = "github:nix-community/nix-vscode-extensions";
wsl = {
@@ -100,7 +101,7 @@
{
deployment = {
inherit (v) tags;
targetHost = if (v ? "nebulaIp") then v.nebulaIp else v.ts;
targetHost = if (v ? "connectAddr") then v.connectAddr else v.nebulaIp;
targetUser = "greg";
};
}
+4
View File
@@ -16,6 +16,10 @@ def nebulaIps [] {
open /etc/nixos/network.json | get hosts | items { |h, e| $e.nebulaIp? } | where $it != null | sort
}
def localIps [] {
open /etc/nixos/network.json | get hosts | items { |h, e| $e.ip? } | where $it != null | sort
}
def genNebulaCert [ --ips: string, --name: string ] {
let public = $'~/SynologyDrive/nebula/($name).key.pub' | path expand
let private = $'~/SynologyDrive/nebula/($name).key' | path expand
-1
View File
@@ -1 +0,0 @@
{...}: {}
+1
View File
@@ -25,6 +25,7 @@
mumble
nebula
nix-index
adoptopenjdk-icedtea-web
pre-commit
prismlauncher
rclone
+1
View File
@@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBUz4YsVKBERXDT9nl4lwWHoA7NkI7M1Wr3QEYtgz9hy emily-monitoring@thehellings.com
+13
View File
@@ -101,6 +101,19 @@
# Enable the OpenSSH daemon for remote control
services = {
locate.enable = true;
# Defensive rate-limit: cap any single misbehaving service's journal
# output fleet-wide. Discovered live on kuma (uptime-kuma logging a
# Prometheus-label validation error on every monitor beat, ~100k
# lines/hour) that a runaway logger can itself become the obstacle to
# incident investigation — journalctl becomes slow/unresponsive and
# disk fills — on top of drowning out genuinely useful log signal.
# This doesn't fix a specific app's bug, but bounds the blast radius.
journald.extraConfig = ''
RateLimitIntervalSec=30s
RateLimitBurst=2000
'';
niks3-auto-upload = {
enable = config.greg.nix.cache;
authTokenFile = config.age.secrets.niks3-api-token.path;
-19
View File
@@ -1,19 +0,0 @@
{ config, modulesPath, pkgs, lib, ... }:
{
imports = [ (modulesPath + "/virtualisation/proxmox-lxc.nix") ];
nix.settings = { sandbox = false; };
proxmoxLXC = {
manageNetwork = false;
privileged = true;
};
services.fstrim.enable = false; # Let Proxmox host handle fstrim
services.openssh = {
enable = true;
openFirewall = true;
settings = {
PermitRootLogin = "yes";
PasswordAuthentication = true;
PermitEmptyPasswords = "yes";
};
};
}
+1 -1
View File
@@ -9,7 +9,7 @@
{
imports = [
./hardware-configuration.nix
top.nix-hardware.nixosModules.framework-11th-gen-intel
top.nix-hardware.nixosModules.framework-intel-core-ultra-series1
];
boot = {
+4 -5
View File
@@ -1,12 +1,11 @@
# Local hosts
10.42.0.1 switch switch.thehellings.lan # Core switch for the network
10.42.0.3 ap ap.thehellings.lan # OpenWRT access point (static IP)
10.42.0.4 joel.thehellings.lan # Proxmox
10.42.0.4 pve1.thehellings.lan # Proxmox
10.42.0.5 sanswitch.thehellings.lan # Core switch for the SAN
# Home servers
10.42.1.1 pve1.thehellings.lan
10.42.1.2 opnsense router opnsense.thehellings.lan router.thehellings.lan
10.42.1.1 udm router udm.thehellings.lan router.thehellings.lan # Ubiquiti UDM gateway
10.42.1.3 printer.thehellings.lan
10.42.1.4 chronicles chronicles.thehellings.lan nas.thehellings.lan s3.thehellings.lan
10.42.1.5 genesis genesis.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan speedtest.thehellings.lan nixcache.thehellings.lan gitcache.thehellings.lan
@@ -24,7 +23,7 @@
10.42.4.1 matrix matrix.thehellings.lan
# VIP
10.42.5.1 longhorn.cluster matrix.cluster pgadmin.cluter postgres.cluster immich.cluster
10.42.5.1 longhorn.cluster matrix.cluster postgres.cluster immich.cluster
# IPMI
10.42.100.6 isaiahbmc isaiahbmc.thehellings.lan
@@ -36,7 +35,7 @@
100.70.99.91 exodus.home exodus.shire-zebra.ts.net
100.96.198.104 genesis.home genesis.shire-zebra.ts.net smart.home zwave.home nixcache.home gitcache.home dashy.home uptime.home speed.home
100.68.203.1 hosea.home hosea.shire-zebra.ts.net grafana.home
100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes longhorn.kubernetes
100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net longhorn.kubernetes
100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes immich.kubernetes postgres.kubernetes buildbot.home
100.90.74.19 zeke.home zeke.shire-zebra.ts.net
100.109.86.8 linode.home linode.shire-zebra.ts.net
+2 -2
View File
@@ -77,7 +77,7 @@ in
};
};
firewall = {
enable = false;
enable = true;
allowedUDPPorts = [
dhcpPort
dnsPort
@@ -88,7 +88,7 @@ in
80
];
};
nftables.enable = false;
nftables.enable = true;
};
environment.etc."hosts.d/local".text = extraHosts;
+1 -5
View File
@@ -60,7 +60,7 @@
reservations = [
# Static IPs for personal work
{
hw-address = "00:23:24:72:64:32"; # Joel
hw-address = "00:23:24:72:64:32"; # PVE1
ip-address = "10.42.0.4";
}
{
@@ -76,10 +76,6 @@
#ip-address = "10.42.2.253";
ip-address = "10.42.100.6";
}
{
hw-address = "7c:83:34:b9:ee:ec"; # PVE1
ip-address = "10.42.1.1";
}
{
hw-address = "74:ee:2a:66:b3:51"; # printer
ip-address = "10.42.1.3";
+4
View File
@@ -47,6 +47,10 @@
enable = true;
extraLabels = [ "bare-metal:host" ];
};
vmdev = {
enable = true;
host = "libvirt";
};
};
networking = {
+76
View File
@@ -0,0 +1,76 @@
{
config,
metadata,
modulesPath,
pkgs,
...
}:
{
imports = [ "${modulesPath}/virtualisation/proxmox-image.nix" ];
greg = {
home = true;
nebula.enable = true;
proxies =
let
tgt = {
target = "http://localhost:${config.services.uptime-kuma.settings.PORT}";
genAliases = false;
};
in
{
"kuma.nebula.thehellings.com" = tgt;
"kuma.thehellings.lan" = tgt;
"kuma.shire-zebra.ts.net" = tgt;
};
};
nix.settings = {
sandbox = false;
};
networking = {
defaultGateway = metadata.infra.gw;
nameservers = [ metadata.infra.dns ];
interfaces.ens18 = {
useDHCP = false;
ipv4.addresses = [
{
address = metadata.hosts."${config.networking.hostName}".ip;
prefixLength = 16;
}
];
};
};
proxmox.cloudInit.enable = false;
services = {
fstrim.enable = true;
mysql = {
enable = true;
ensureDatabases = [
config.services.uptime-kuma.settings.UPTIME_KUMA_DB_NAME
];
ensureUsers = [
{
name = config.services.uptime-kuma.settings.UPTIME_KUMA_DB_USERNAME;
ensurePermissions = {
"uptimekuma.*" = "ALL PRIVILEGES";
};
}
];
package = pkgs.mariadb;
};
openssh = {
enable = true;
openFirewall = true;
};
uptime-kuma = {
enable = true;
settings = {
PORT = "3001"; # Default, but this allows us to explicitly use it elsewhere
UPTIME_KUMA_DB_TYPE = "mariadb";
UPTIME_KUMA_DB_SOCKET = "/run/mysqld/mysqld.sock";
UPTIME_KUMA_DB_NAME = "uptimekuma";
UPTIME_KUMA_DB_USERNAME = "uptimekuma";
UPTIME_KUMA_DB_PASSWORD = "uptimekuma";
};
};
};
}
+391 -21
View File
@@ -1,34 +1,93 @@
{
pkgs,
lib,
config,
lib,
metadata,
pkgs,
pkgs',
...
}:
let
homepage = "127.0.0.1:30080";
nextcloudPort = 8080;
sshPort = 2222;
matrixServer = pkgs.writeText "matrix_server" (
builtins.toJSON {
"m.server" = "matrix.thehellings.com:443";
}
);
matrixClient = pkgs.writeText "matrix_client" (
builtins.toJSON {
"m.homeserver" = {
base_url = "https://matrix.thehellings.com";
};
"m.identity_server" = {
base_url = "https://vector.im";
};
}
);
in
{
imports = [
./git.nix
./hardware-configuration.nix
./podman.nix
./matrix.nix
./nextcloud.nix
./nginx.nix
./postgres.nix
];
age.secrets = {
acme.file = ../../../secrets/acme.age;
nextcloudadmin = {
file = ../../../secrets/nextcloudadmin.age;
owner = "nextcloud";
};
};
environment.systemPackages = with pkgs; [
bind
graphviz
nix-du
pgloader
podman-compose
pkgs'.upgrade-pg-cluster
];
# Historical per-interface bandwidth tracking (5-min granularity, kept for
# months). This is what's actually missing when diagnosing "traffic was
# high for the past several hours" reports after the fact — journalctl
# timestamps only tell you what else was happening, not the traffic curve
# itself. `vnstat -h`/`vnstat --json h` gives an immediate confirm/deny of
# a reported window without waiting on live sampling.
services.vnstat.enable = true;
greg = {
backup.jobs = {
nextcloud-bkup = {
src = "/var/lib/nextcloud";
dest = "nextcloud-backup";
pre = lib.getExe (
pkgs.writeShellApplication {
name = "nextcloud-backup-pre";
runtimeInputs = [ config.services.nextcloud.occ ];
text = "nextcloud-occ maintenance:mode --on";
}
);
post = lib.getExe (
pkgs.writeShellApplication {
name = "nextcloud-backup-post";
runtimeInputs = [ config.services.nextcloud.occ ];
text = "nextcloud-occ maintenance:mode --off";
}
);
};
greg-postgresql-backup = {
src = config.services.postgresqlBackup.location;
dest = "linode-postgres";
};
};
gitea-runner = {
enable = true;
extraLabels = [
labels = [
"vps:host"
"blog:host"
"nixos-linode:host"
];
};
home = false;
@@ -36,20 +95,29 @@
nebula = {
enable = true;
isLighthouse = true;
};
proxies."immich.thehellings.com" = {
genAliases = false;
target = "http://localhost:${builtins.toString config.services.immich-public-proxy.port}";
ssl = true;
unsafeRoutes = [
{
route = "10.42.0.0/16";
via = metadata.hosts.genesis.nebulaIp;
}
];
};
tailscale.enable = true;
};
networking = {
networkmanager.enable = lib.mkForce false;
hostName = "linode";
domain = "thehellings.com";
nameservers = [ "100.88.91.27" ];
firewall.allowedTCPPorts = [
sshPort
80
443
];
hostName = "linode";
nameservers = [
"10.157.0.2"
"100.96.198.104"
];
networkmanager.enable = lib.mkForce false;
};
programs.ssh.extraConfig = lib.strings.concatStringsSep "\n" [
@@ -60,10 +128,312 @@
" UserKnownHostsFile /dev/null"
];
services = {
immich-public-proxy = {
enable = true;
immichUrl = "https://immich.shire-zebra.ts.net";
security.acme = {
acceptTerms = true;
defaults = {
dnsPropagationCheck = false;
dnsResolver = "92.123.95.3:53,92.123.94.3:53,92.123.94.2:53,92.123.95.4:53,92.123.95.2:53";
email = "greg.hellings@gmail.com";
extraLegoRunFlags = [ "--ipv4only" ]; # Force IPv4 only
#server = "https://acme-staging-v02.api.letsencrypt.org/directory";
};
certs."thehellings.com" = {
dnsProvider = "linode";
environmentFile = config.age.secrets.acme.path;
extraDomainNames = [
"*.thehellings.com"
];
};
};
services = {
anubis = {
instances = {
git = {
enable = true;
settings = {
BIND = "/run/anubis/anubis-git/anubis.sock";
COOKIE_DOMAIN = "thehellings.com";
SERVE_ROBOTS_TXT = true;
SLOG_LEVEL = "DEBUG";
TARGET = "http://git.k3s.thehellings.lan";
};
};
};
};
haproxy = {
enable = true;
config = ''
global
nbthread 4
maxconn 80
log /dev/log local0
defaults
log global
timeout connect 500s
timeout client 500s
timeout server 1h
# HAProxy defaults to end-to-end keep-alive (client AND server side)
# unless a proxy overrides it. Bound how long an idle client-facing
# keep-alive connection is held rather than falling back to
# "timeout client" (500s).
#
# CORRECTION (see #39): this was originally set to 30s as a
# tidy-up given maxconn=80, without considering client-side
# connection pooling behavior. That was too aggressive: DAVx5 (and
# OkHttp-based HTTP clients generally) keep idle pooled
# connections open for up to 5 minutes client-side before
# eviction. With a 30s haproxy-side timeout, any client connection
# idle between 30s-300s got silently closed by haproxy, and the
# client's next reuse of it produced exactly the "unexpected end
# of stream"/EOFException class of error this investigation
# started from - just relocated from the haproxy<->nginx leg
# (fixed in `backend next` below) to the client<->haproxy leg.
# Set comfortably above OkHttp's 300s default so a client's own
# pool eviction always happens first and haproxy is never the one
# to close a connection the client still thinks is good.
timeout http-keep-alive 6m
listen gitsshd
bind *:${toString sshPort}
timeout client 1h
mode tcp
server git-isaiah isaiah.thehellings.lan:32222
server git-jeremiah jeremiah.thehellings.lan:32222
server git-zeke zeke.thehellings.lan:32222
listen stats
bind 127.0.0.1:8404
stats enable
stats uri /
stats refresh 10s
frontend https
bind *:80
bind *:443 ssl crt ${config.security.acme.certs."thehellings.com".directory}/full.pem
http-request redirect scheme https unless { ssl_fc }
http-request add-header X-Forwarded-Proto https
http-response replace-header ^Set-Cookie:\ (.*) Set-Cookie \1;\ Secure
option http-server-close
option http-keep-alive
option httplog
#declare capture response len 80
#http-response capture res.hdr(Location) id 0
use_backend git if { hdr(host) -i src.thehellings.com }
use_backend git if { req_ssl_sni -i src.thehellings.com }
use_backend next if { hdr(host) -i next.thehellings.com }
use_backend next if { req_ssl_sni -i next.thehellings.com }
use_backend matrix if { hdr(host) -i matrix.thehellings.com }
use_backend matrix if { req_ssl_sni -i matrix.thehellings.com }
use_backend immich if { hdr(host) -i immich.thehellings.com }
use_backend immich if { req_ssl_sni -i immich.thehellings.com }
use_backend web if { hdr(host) -i thehellings.com }
use_backend web if { req_ssl_sni -i thehellings.com }
backend git
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
http-request set-header Host git.k3s.thehellings.lan
server git-isaiah isaiah.thehellings.lan:80
server git-jeremiah jeremiah.thehellings.lan:80
server git-zeke zeke.thehellings.lan:80
backend immich
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
server immich-proxy 127.0.0.1:${builtins.toString config.services.immich-public-proxy.port}
backend matrix
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
http-request set-header Host matrix.k3s.thehellings.lan
server git-isaiah isaiah.thehellings.lan:80
server git-jeremiah jeremiah.thehellings.lan:80
server git-zeke zeke.thehellings.lan:80
backend web
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
http-request return status 200 content-type "application/json" file ${matrixClient} hdr "cache-control" "no-cache" if { path /.well-known/matrix/client }
http-request return status 200 content-type "application/json" file ${matrixServer} hdr "cache-control" "no-cache" if { path /.well-known/matrix/server }
server web-container ${homepage}
backend next
log global
log-tag next
mode http
balance roundrobin
option accept-unsafe-violations-in-http-response
retries 3
option forwardfor
# nginx (the actual listener on 127.0.0.1:8080) has
# keepalive_timeout 65s and will silently close an idle backend
# socket after that. HAProxy's default mode is end-to-end
# keep-alive, so without this it will happily try to reuse a
# backend connection nginx already closed once a mobile client's
# own (longer) keep-alive idle assumption outlives 65s - producing
# exactly the "unexpected end of stream" / EOFException the
# CalDAV/CardDAV client saw. Since the backend is localhost, the
# cost of a fresh TCP connection per request is negligible, so
# just don't try to reuse them here.
option http-server-close
#http-response replace-value Location http://localhost:${builtins.toString nextcloudPort}/(.*) https://next.thehellings.com/\2
server nextcloud 127.0.0.1:${builtins.toString nextcloudPort}
'';
};
immich-public-proxy = {
enable = true;
immichUrl = "http://immich.k3s.thehellings.lan";
};
logrotate = {
enable = true;
settings = {
postgresBackup = {
enable = true;
files = "${config.services.postgresqlBackup.location}/*.gz";
};
postgresLog = {
enable = true;
files = "/var/lib/postgresql/*/log/*.log";
compress = true;
compresscmd = "${pkgs.xz}/bin/xz";
};
};
};
nextcloud = {
enable = true;
package = pkgs.nextcloud33;
appstoreEnable = true;
hostName = "127.0.0.1";
https = false;
config = {
adminpassFile = config.age.secrets.nextcloudadmin.path;
adminuser = "greg";
dbhost = "/run/postgresql";
dbtype = "pgsql";
};
settings = {
default_phone_region = "US";
overwriteprotocol = "http";
trusted_domains = [ "next.thehellings.com" ];
trusted_proxies = [
"localhost"
"127.0.0.1"
];
};
};
# Move to :8080 so that we can run haproxy as the primary HTTP service
nginx = {
virtualHosts."${config.services.nextcloud.hostName}".listen = [
{
addr = "127.0.0.1";
port = nextcloudPort;
}
];
# Route nginx access logs through syslog/journald (rather than only to
# /var/log/nginx/access.log, which the read-only monitoring account
# can't read) so `journalctl -t nginx_access` gives visibility into
# Nextcloud request traffic during bandwidth investigations.
#
# NOTE: nginx's syslog "tag" only allows alphanumeric characters and
# underscores (no hyphens) - an earlier version of this used
# tag=nginx-access, which fails nginx's config test with:
# nginx: [emerg] syslog "tag" only allows alphanumeric characters
# and underscore in .../nginx.conf:114
# That broke nginx.service (and, transitively, Nextcloud/next.thehellings.com,
# which is proxied through nginx on 127.0.0.1:8080) until nginx hit its
# systemd restart limit and gave up (start-limit-hit).
appendHttpConfig = ''
access_log syslog:server=unix:/dev/log,tag=nginx_access combined;
'';
};
openssh.settings.PasswordAuthentication = false;
postgresql = {
enable = true;
package = pkgs.postgresql_15;
checkConfig = true;
ensureDatabases = [ "nextcloud" ];
#initialScript = pkgs.writeText "create-matrix-db.sql" ''
# CREATE ROLE "matrix-synapse" WITH LOGIN;
# CREATE DATABASE "synapse" WITH OWNER "matrix-synapse" TEMPLATE template0 LC_COLLATE = "C" LC_CTYPE = "C";
# GRANT ALL PRIVILEGES ON DATABASE "synapse" TO "matrix-synapse";
#''; # These are done manually in order to set the LC_COLLATE values properly
ensureUsers = [
{
name = "nextcloud";
ensureDBOwnership = true;
}
];
settings = {
log_connections = true;
log_statement = "all";
logging_collector = true;
log_filename = "postgresql.log";
};
identMap = ''
root root postgres
'';
};
postgresqlBackup = {
enable = true;
databases = [ "nextcloud" ];
};
};
systemd.services = {
haproxy = {
after = [
"nextcloud.service"
"network-online.target"
];
wants = [
"nextcloud.service"
"network-online.target"
];
};
};
users.users.haproxy.extraGroups = [ config.security.acme.certs."thehellings.com".group ];
# Actually serve the content from here
virtualisation.oci-containers = {
backend = "podman";
containers."homepage" = {
image = "src.thehellings.com/greg/homepage:latest";
ports = [ "${homepage}:80" ];
};
};
virtualisation.podman = {
enable = true;
dockerCompat = true;
dockerSocket.enable = true;
};
}
-148
View File
@@ -1,148 +0,0 @@
{ config, ... }:
let
srcDomain = "src.thehellings.com";
sshPort = 2222;
in
{
greg.proxies."${srcDomain}" = {
target = "http://unix:${config.services.anubis.instances.git.settings.BIND}";
ssl = true;
genAliases = false;
extraConfig = ''
#proxy_ssl_verify off;
#proxy_ssl_server_name on;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Http-Version $server_protocol;
proxy_set_header User-Agent $http_user_agent;
client_max_body_size 100000m;
#proxy_set_header Host $host;
#proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
#proxy_set_header X-Forwarded-Proto $scheme;
#proxy_set_header X-Forwarded-Ssl on;
# Ultimate AI Block List v1.7 20250924
# https://perishablepress.com/ultimate-ai-block-list/
if ($http_user_agent ~* "(openai\.com|\.ai|-ai|_ai|ai\.|ai-|ai_|ai=|AddSearchBot|Agentic|AgentQL|Agent\ 3|Agent\ API|AI\ Agent|AI\ Article\ Writer|AI\ Chat|AI\ Content\ Detector|AI\ Detection|AI\ Dungeon|AI\ Journalist|AI\ Legion)") {
return 444;
}
if ($http_user_agent ~* "(AI\ RAG|AI\ Search|AI\ SEO\ Crawler|AI\ Training|AI\ Web|AI\ Writer|AI2|AIBot|aiHitBot|AIMatrix|AISearch|AITraining|Alexa|Alice\ Yandex|AliGenie|AliyunSec|Alpha\ AI|AlphaAI|Amazon|Amelia)") {
return 444;
}
if ($http_user_agent ~* "(AndersPinkBot|AndiBot|Anonymous\ AI|Anthropic|AnyPicker|Anyword|Applebot|Aria\ AI|Aria\ Browse|Articoolo|Ask\ AI|AutoGen|AutoGLM|Automated\ Writer|AutoML|Autonomous\ RAG|AwarioRssBot|AwarioSmartBot|AWS\ Trainium|Azure)") {
return 444;
}
if ($http_user_agent ~* "(BabyAGI|BabyCatAGI|BardBot|Basic\ RAG|Bedrock|Big\ Sur|Bigsur|Botsonic|Brightbot|Browser\ MCP\ Agent|Browser\ Use|Bytebot|ByteDance|Bytespider|CarynAI|CatBoost|CC-Crawler|CCBot|Chai|Character)") {
return 444;
}
if ($http_user_agent ~* "(Charstar\ AI|Chatbot|ChatGLM|Chatsonic|ChatUser|Chinchilla|Claude|ClearScope|Clearview|Cognitive\ AI|Cohere|Common\ Crawl|CommonCrawl|Content\ Harmony|Content\ King|Content\ Optimizer|Content\ Samurai|ContentAtScale|ContentBot|Contentedge)") {
return 444;
}
if ($http_user_agent ~* "(ContentShake|Conversion\ AI|Copilot|CopyAI|Copymatic|Copyscape|CoreWeave|Corrective\ RAG|Cotoyogi|CRAB|Crawl4AI|CrawlQ\ AI|Crawlspace|Crew\ AI|CrewAI|Crushon\ AI|DALL-E|DarkBard|DataFor|DataProvider)") {
return 444;
}
if ($http_user_agent ~* "(Datenbank\ Crawler|DeepAI|Deep\ AI|DeepL|DeepMind|Deep\ Research|DeepResearch|DeepSeek|Devin|Diffbot|Doubao\ AI|DuckAssistBot|DuckDuckGo\ Chat|DuckDuckGo-Enhanced|Echobot|Echobox|Elixir|FacebookBot|FacebookExternalHit|Factset)") {
return 444;
}
if ($http_user_agent ~* "(Falcon|FIRE-1|Firebase|Firecrawl|Flux|Flyriver|Frase\ AI|FriendlyCrawler|Gato|Gemini|Gemma|Gen\ AI|GenAI|Generative|Genspark|Gentoo-chat|Ghostwriter|GigaChat|GLM|GodMode)") {
return 444;
}
if ($http_user_agent ~* "(Goose|GPT|Grammarly|Grendizer|Grok|GT\ Bot|GTBot|GTP|Hemingway\ Editor|Hetzner|Hugging|Hunyuan|Hybrid\ Search\ RAG|Hypotenuse\ AI|iAsk|ICC-Crawler|ImageGen|ImagesiftBot|img2dataset|imgproxy)") {
return 444;
}
if ($http_user_agent ~* "(INK\ Editor|INKforall|Instructor|IntelliSeek|Inferkit|ISSCyberRiskCrawler|Janitor\ AI|Jasper|Jenni\ AI|Julius\ AI|Kafkai|Kaggle|Kangaroo|Keyword\ Density\ AI|Kimi|Knowledge|KomoBot|Kruti|LangChain|Le\ Chat)") {
return 444;
}
if ($http_user_agent ~* "(Lensa|Lightpanda|LinerBot|LLaMA|LLM|Local\ RAG\ Agent|Lovable|Magistral|magpie-crawler|Manus|MarketMuse|Meltwater|Meta-AI|Meta-External|Meta-Webindexer|Meta\ AI|MetaAI|MetaTagBot|Middleware|Midjourney)") {
return 444;
}
if ($http_user_agent ~* "(Mini\ AGI|MiniMax|Mintlify|Mistral|Mixtral|model-training|Monica|Narrative|NeevaBot|netEstate|Neural\ Text|NeuralSEO|NinjaAI|NodeZero|Nova\ Act|NovaAct|OAI-SearchBot|OAI\ SearchBot|OASIS|Olivia)") {
return 444;
}
if ($http_user_agent ~* "(Omgili|Open\ AI|Open\ Interpreter|OpenAGI|OpenAI|OpenBot|OpenPi|OpenRouter|OpenText\ AI|Operator|Outwrite|Page\ Analyzer\ AI|PanguBot|Panscient|Paperlibot|Paraphraser\.io|peer39_crawler|Perflexity|Perplexity|Petal)") {
return 444;
}
if ($http_user_agent ~* "(Phind|PiplBot|PoeBot|PoeSearchBot|ProWritingAid|Proximic|Puppeteer|Python\ AI|Qualified|Quark|QuillBot|Qopywriter|Qwen|RAG\ Agent|RAG\ Azure\ AI|RAG\ Chatbot|RAG\ Database|RAG\ IS|RAG\ Pipeline|RAG\ Search)") {
return 444;
}
if ($http_user_agent ~* "(RAG\ with|RAG-|RAG_|Raptor|React\ Agent|Redis\ AI\ RAG|RobotSpider|Rytr|SaplingAI|SBIntuitionsBot|Scala|Scalenut|Scrap|ScriptBook|Seekr|SEObot|SEO\ Content\ Machine|SEO\ Robot|SemrushBot|Sentibot)") {
return 444;
}
if ($http_user_agent ~* "(Serper|ShapBot|Sidetrade|Simplified\ AI|Sitefinity|Skydancer|SlickWrite|SmartBot|Sonic|Sora|Spider/2|SpiderCreator|Spin\ Rewrite|Spinbot|Stability|StableDiffusionBot|Sudowrite|SummalyBot|Super\ Agent|Superagent)") {
return 444;
}
if ($http_user_agent ~* "(SuperAGI|Surfer\ AI|TerraCotta|Text\ Blaze|TextCortex|Thinkbot|Thordata|TikTokSpider|Timpibot|Tinybird|Together\ AI|Traefik|TurnitinBot|uAgents|VelenPublicWebCrawler|Venus\ Chub\ AI|Vidnami\ AI|Vision\ RAG|WebSurfer|WebText)") {
return 444;
}
if ($http_user_agent ~* "(Webzio|WeChat|Whisper|WordAI|Wordtune|WPBot|Writecream|WriterZen|Writescope|Writesonic|xAI|xBot|YaML|YandexAdditional|YouBot|Zendesk|Zero|Zhipu|Zhuque\ AI|Zimm)") {
return 444;
}
'';
};
#greg.proxies."registry.thehellings.com" = {
#target = "https://gitea.shire-zebra.ts.net:5000";
#ssl = true;
#genAliases = false;
#extraConfig = ''
#proxy_set_header X-Forwarded-Proto https;
#proxy_set_header X-Forwarded-Ssl on;
#client_max_body_size 25000m;
#'';
#};
networking.firewall.allowedTCPPorts = [ sshPort ];
services = {
anubis = {
instances = {
git = {
enable = true;
settings = {
BIND = "/run/anubis/anubis-git/anubis.sock";
COOKIE_DOMAIN = "thehellings.com";
SERVE_ROBOTS_TXT = true;
TARGET = "https://gitea.shire-zebra.ts.net/";
};
};
};
};
haproxy = {
enable = true;
config = ''
global
daemon
maxconn 20
defaults
timeout connect 500s
timeout client 500s
timeout server 1h
listen gitsshd
bind *:${toString sshPort}
timeout client 1h
mode tcp
server git-isaiah isaiah.shire-zebra.ts.net:32222
server git-jeremiah jeremiah.shire-zebra.ts.net:32222
server git-zeke zeke.shire-zebra.ts.net:32222
'';
};
};
systemd.services = {
haproxy = {
after = [
"network-online.target"
];
wants = [
"network-online.target"
];
};
};
users.users.nginx.extraGroups = [ config.users.groups.anubis.name ];
}
-70
View File
@@ -1,70 +0,0 @@
# Registration of new users is disabled for the public, but I can create
# them by the following commands:
# nix run nixpkgs.matrix-synapse
# register_new_matrix_user -k "B9EoPr2WV9hzwc7uL2Sx1JmvCeKDEOGCpB0uginQcQtEH4wzRtkSIdo7lltrjSQa" http://localhost:8448
{ config, ... }:
let
domain = "${config.networking.domain}";
fqdn = "matrix.${domain}";
in
{
greg.proxies."${fqdn}" = {
extraConfig = ''
error_log /var/log/nginx/debug.log debug;
proxy_ssl_verify off;
proxy_ssl_server_name on;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Ssl on;
'';
genAliases = false;
ssl = true;
target = "https://matrix.shire-zebra.ts.net";
};
services.nginx = {
virtualHosts = {
# Server the '.well-known' files to find the Matrix API server
"${domain}" = {
enableACME = true;
forceSSL = true;
# This is needed so that servers contacting hellings.com can find
# the actual application server at matrix.thehellings.com
locations."= /.well-known/matrix/server".extraConfig =
let
server = {
"m.server" = "${fqdn}:443";
};
in
''
add_header Content-Type application/json;
return 200 '${builtins.toJSON server}';
'';
locations."= /.well-known/matrix/client".extraConfig =
let
client = {
"m.homeserver" = {
"base_url" = "https://${fqdn}";
};
"m.identity_server" = {
"base_url" = "https://vector.im";
};
};
in
''
add_header Content-Type application/json;
add_header Access-Control-Allow-Origin *;
return 200 '${builtins.toJSON client}';
'';
};
};
};
# Open networking ports for the server
networking.firewall = {
enable = true;
allowedTCPPorts = [
80
443
];
};
}
-58
View File
@@ -1,58 +0,0 @@
{
config,
lib,
pkgs,
...
}:
{
age.secrets.nextcloudadmin = {
file = ../../../secrets/nextcloudadmin.age;
owner = "nextcloud";
};
services.nextcloud = {
enable = true;
package = pkgs.nextcloud33;
appstoreEnable = true;
hostName = "next.${config.networking.domain}";
https = true;
config = {
adminpassFile = config.age.secrets.nextcloudadmin.path;
adminuser = "greg";
dbhost = "/run/postgresql";
dbtype = "pgsql";
};
settings = {
default_phone_region = "US";
overwriteprotocol = "https";
};
};
services.nginx.virtualHosts."next.thehellings.com" = {
forceSSL = true;
enableACME = true;
};
# Otherwise nginx errors looking for the nextcloud sock file
systemd.services.nginx.after = [ "nextcloud.service" ];
greg.backup.jobs.nextcloud-bkup = {
src = "/var/lib/nextcloud";
dest = "nextcloud-backup";
pre = lib.getExe (
pkgs.writeShellApplication {
name = "nextcloud-backup-pre";
runtimeInputs = [ config.services.nextcloud.occ ];
text = "nextcloud-occ maintenance:mode --on";
}
);
post = lib.getExe (
pkgs.writeShellApplication {
name = "nextcloud-backup-post";
runtimeInputs = [ config.services.nextcloud.occ ];
text = "nextcloud-occ maintenance:mode --off";
}
);
};
}
-38
View File
@@ -1,38 +0,0 @@
{ ... }:
let
homepage = "127.0.0.1:30080";
in
{
security.acme = {
acceptTerms = true;
defaults.email = "greg.hellings@gmail.com";
};
services.nginx = {
enable = true;
clientMaxBodySize = "25000m"; # To help with uploading container images
# If there are recommended settings, let's use them!
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
};
# Actually serve the content from here
virtualisation.podman.enable = true;
virtualisation.oci-containers = {
backend = "podman";
containers."homepage" = {
image = "registry.thehellings.com:443/greg/homepage/gregs-homepage:latest";
ports = [ "${homepage}:80" ];
};
};
greg.proxies = {
"thehellings.com" = {
target = "http://${homepage}/";
ssl = true;
genAliases = false;
};
};
}
-13
View File
@@ -1,13 +0,0 @@
{ pkgs, ... }:
{
environment.systemPackages = with pkgs; [
podman-compose
];
virtualisation.podman = {
enable = true;
dockerCompat = true;
dockerSocket.enable = true;
};
}
-63
View File
@@ -1,63 +0,0 @@
{
config,
pkgs,
pkgs',
...
}:
{
environment.systemPackages = [ pkgs'.upgrade-pg-cluster ];
services.postgresql = {
enable = true;
package = pkgs.postgresql_15;
checkConfig = true;
ensureDatabases = [ "nextcloud" ];
#initialScript = pkgs.writeText "create-matrix-db.sql" ''
# CREATE ROLE "matrix-synapse" WITH LOGIN;
# CREATE DATABASE "synapse" WITH OWNER "matrix-synapse" TEMPLATE template0 LC_COLLATE = "C" LC_CTYPE = "C";
# GRANT ALL PRIVILEGES ON DATABASE "synapse" TO "matrix-synapse";
#''; # These are done manually in order to set the LC_COLLATE values properly
ensureUsers = [
{
name = "nextcloud";
ensureDBOwnership = true;
}
];
settings = {
log_connections = true;
log_statement = "all";
logging_collector = true;
log_filename = "postgresql.log";
};
identMap = ''
root root postgres
'';
};
services.postgresqlBackup = {
enable = true;
databases = [ "nextcloud" ];
};
services.logrotate = {
enable = true;
settings = {
postgresBackup = {
enable = true;
files = "${config.services.postgresqlBackup.location}/*.gz";
};
postgresLog = {
enable = true;
files = "/var/lib/postgresql/*/log/*.log";
compress = true;
compresscmd = "${pkgs.xz}/bin/xz";
};
};
};
greg.backup.jobs.greg-postgresql-backup = {
src = config.services.postgresqlBackup.location;
dest = "linode-postgres";
};
}
+4 -6
View File
@@ -32,6 +32,10 @@
enable = true;
tags = [ "home" ];
};
vmdev = {
enable = true;
host = "vbox";
};
};
hardware = {
@@ -71,10 +75,4 @@
users.users.greg.extraGroups = [
"podman"
];
# virtualisation.virtualbox.host = {
# enableExtensionPack = true;
# headless = true;
# enableWebService = true;
# };
}
-1
View File
@@ -4,6 +4,5 @@ resources:
- namespace.yaml
- secrets.yaml
- postgres-cluster.yaml
- postgres-pgadmin.yaml
- postgres-matrix.yaml
- ingress.yaml
@@ -11,13 +11,6 @@ spec:
managed:
roles:
- name: pgadmin
ensure: present
comment: PG Admin user
login: true
superuser: true
passwordSecret:
name: postgres-user-pgadmin
- name: matrix
ensure: present
comment: Matrix DB user
-103
View File
@@ -1,103 +0,0 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: config-pgadmin
data:
servers.json: |
{
"Servers": {
"1": {
"Name": "Postgres",
"Group": "Servers",
"Port": 5432,
"Username": "pgadmin",
"Host": "postgres-rw",
"SSLMode": "allow",
"MaintenanceDB": "postgres"
}
}
}
---
apiVersion: v1
kind: Service
metadata:
name: service-pgadmin
spec:
ports:
- protocol: TCP
port: 80
targetPort: http
selector:
app: pgadmin
type: ClusterIP
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: pgadmin
spec:
serviceName: service-pgadmin
podManagementPolicy: Parallel
replicas: 1
updateStrategy:
type: RollingUpdate
selector:
matchLabels:
app: pgadmin
template:
metadata:
labels:
app: pgadmin
spec:
terminationGracePeriodSeconds: 10
containers:
- name: pgadmin
image: "dpage/pgadmin4:9.3"
imagePullPolicy: Always
env:
- name: PGADMIN_DEFAULT_EMAIL
value: greg@thehellings.com
- name: PGADMIN_DEFAULT_PASSWORD
valueFrom:
secretKeyRef:
name: postgres-user-pgadmin
key: password
- name: PGADMIN_SERVER_JSON_FILE
value: /config-pgadmin-vol/servers.json
ports:
- name: http
containerPort: 80
protocol: TCP
volumeMounts:
- name: config-pgadmin-vol
mountPath: /config-pgadmin-vol/
readOnly: true
- name: pgadmin-data
mountPath: /var/lib/pgadmin
volumes:
- name: config-pgadmin-vol
configMap:
name: config-pgadmin
volumeClaimTemplates:
- metadata:
name: pgadmin-data
spec:
accessModes: ["ReadWriteOnce"]
resources:
requests:
storage: 3Gi
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: ingress-pgadmin
spec:
ingressClassName: tailscale
defaultBackend:
service:
name: service-pgadmin
port:
number: 80
tls:
- hosts:
- pgadmin
-34
View File
@@ -34,40 +34,6 @@ spec:
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: postgres-user-pgadmin
namespace: db
spec:
target:
name: postgres-user-pgadmin
deletionPolicy: Delete
template:
type: Opaque
data:
username: |-
{{ .username }}
password: |-
{{ .password }}
data:
- secretKey: username
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: f333d637-1667-499d-b9a0-b2e9012bd8b7
property: username
- secretKey: password
sourceRef:
storeRef:
name: bitwarden-login
kind: ClusterSecretStore
remoteRef:
key: f333d637-1667-499d-b9a0-b2e9012bd8b7
property: password
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: k3sbackup-externalsecret
namespace: db
-79
View File
@@ -1,79 +0,0 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: donetick-config
namespace: donetick
data:
# Value pulled from
# https://github.com/donetick/donetick/blob/main/config/selfhosted.yaml
selfhosted.yaml: |-
name: "selfhosted"
is_done_tick_dot_com: false
is_user_creation_disabled: false
telegram:
token: ""
pushover:
token: ""
database:
type: "sqlite"
migration: true
# these are only required for postgres
host: "secret"
port: 5432
user: "secret"
password: "secret"
name: "secret"
jwt:
secret: "This is really a secure JWT secret now!"
session_time: 168h
max_refresh: 168h
server:
port: 2021
read_timeout: 10s
write_timeout: 10s
rate_period: 60s
rate_limit: 300
cors_allow_origins:
- "http://localhost:5173"
- "http://localhost:7926"
# the below are required for the android app to work
- "https://localhost"
- "capacitor://localhost"
serve_frontend: true
logging:
level: "info"
encoding: "json"
development: false
scheduler_jobs:
due_job: 30m
overdue_job: 3h
pre_due_job: 3h
email:
host:
port:
key:
email:
appHost:
oauth2:
client_id:
client_secret:
auth_url:
token_url:
user_info_url:
redirect_url:
name:
# Real-time configuration
realtime:
enabled: true
sse_enabled: true
heartbeat_interval: 60s
connection_timeout: 120s
max_connections: 1000
max_connections_per_user: 5
event_queue_size: 2048
cleanup_interval: 2m
stale_threshold: 5m
enable_compression: true
enable_stats: true
allowed_origins:
- "*"
-38
View File
@@ -1,38 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: donetick
namespace: donetick
spec:
replicas: 1
selector:
matchLabels:
app: donetick
template:
metadata:
labels:
app: donetick
spec:
containers:
- name: donetick
image: donetick/donetick
ports:
- containerPort: 2021
name: http
env:
- name: DT_ENV
value: "selfhosted"
- name: DT_SQLITE_PATH
value: "/data/donetick.db"
volumeMounts:
- name: config
mountPath: /config
- name: data
mountPath: /data
volumes:
- name: config
configMap:
name: donetick-config
- name: data
persistentVolumeClaim:
claimName: donetick-data
-15
View File
@@ -1,15 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: donetick-tailscale
namespace: donetick
spec:
ingressClassName: tailscale
defaultBackend:
service:
name: donetick
port:
number: 2021
tls:
- hosts:
- todo
-9
View File
@@ -1,9 +0,0 @@
namespace: donetick
resources:
- namespace.yaml
- configmap.yaml
- pvc.yaml
- deployment.yaml
- service.yaml
- ingress.yaml
-4
View File
@@ -1,4 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: donetick
-11
View File
@@ -1,11 +0,0 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: donetick-data
namespace: donetick
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 5Gi
-13
View File
@@ -1,13 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: donetick
namespace: donetick
spec:
selector:
app: donetick
ports:
- name: http
port: 2021
targetPort: 2021
protocol: TCP
-56
View File
@@ -1,56 +0,0 @@
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: gitea
spec:
interval: "24h"
url: https://dl.gitea.com/charts/
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: gitea-runner
namespace: gitea-runner
spec:
interval: 10m
chart:
spec:
chart: actions
version: "0.0.4"
sourceRef:
kind: HelmRepository
name: gitea
interval: "1h"
values:
rbac:
create: true
serviceAccount:
create: true
gitea:
instanceURL: https://src.thehellings.com
runnerToken:
existingSecret: gitea-runner
existingSecretKey: token
imagePullSecrets:
- name: image-pull-secrets
config:
runner:
labels:
# Ubuntu
- "ubuntu-22.04:docker://ubuntu:22.04"
- "ubuntu-24.04:docker://ubuntu:24.04"
- "ubuntu-24.10:docker://ubuntu:24.10"
# Fedora
- "fedora-41:docker://fedora:41"
- "fedora-42:docker://fedora:42"
# CentOS Stream
- "centos-stream-9:docker://quay.io/centos/centos:stream9"
- "centos-stream-10:docker://quay.io/centos/centos:stream10"
# Nix
- "nix:docker://nixos/nix:latest"
# ci-images (internal registry: src.thehellings.com/greg)
- "ci-builder:docker://src.thehellings.com/greg/builder:latest"
- "ci-vm-test:docker://src.thehellings.com/greg/vm-test:latest"
- "ci-sword:docker://src.thehellings.com/greg/sword-container-builder:latest"
- "ci-bitwarden:docker://src.thehellings.com/greg/bitwarden:latest"
- "ci-immich:docker://src.thehellings.com/greg/immich:latest"
@@ -1,6 +0,0 @@
namespace: gitea-runner
resources:
- namespace.yaml
- secrets.yaml
- chart.yaml
-4
View File
@@ -1,4 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: gitea-runner
-18
View File
@@ -1,18 +0,0 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: gitea-runner
namespace: gitea-runner
spec:
refreshInterval: 1h
secretStoreRef:
name: bitwarden-login
kind: ClusterSecretStore
target:
name: gitea-runner
creationPolicy: Owner
data:
- secretKey: token
remoteRef:
key: 11419680-5338-4f19-bdd9-b422007046af
property: password
+9 -9
View File
@@ -15,7 +15,7 @@ spec:
chart:
spec:
chart: gitea
version: "12.6.0"
version: "12.7.0"
sourceRef:
kind: HelmRepository
name: gitea-repository
@@ -35,7 +35,7 @@ spec:
storageClass: longhorn-default
image:
tag: "1.26.2"
tag: "1.27.1"
replicaCount: 1
@@ -67,7 +67,7 @@ spec:
RUN_MODE: dev
server:
DOMAIN: "shire-zebra.ts.net"
ROOT_URL: "https://gitea.shire-zebra.ts.net"
ROOT_URL: "https://git.k3s.thehellings.lan"
SSH_PORT: "2222"
database:
DB_TYPE: postgres
@@ -85,15 +85,15 @@ spec:
DISABLE_REGISTRATION: "true"
storage:
STORAGE_TYPE: minio
MINIO_ENDPOINT: "nas1.shire-zebra.ts.net:9000"
MINIO_ENDPOINT: "nas1.shire-zebra.ts.net:30188"
MINIO_BUCKET: gitea
MINIO_LOCATION: us-east-1
MINIO_LOCATION: garage
# MINIO_ACCESS_KEY_ID: ""
# MINIO_SECRET_ACCESS_KEY: ""
MINIO_USE_SSL: "false"
MINIO_INSECURE_SKIP_VERIFY: "true"
webhook:
ALLOWED_HOST_LIST: loopback,private,*.shire-zebra.ts.net
security:
ALLOWED_HOST_LIST: loopback,private,*.shire-zebra.ts.net,*.nebula.thehellings.com,*.thehellings.lan
metrics:
enabled: false
@@ -102,8 +102,8 @@ spec:
persistence:
enabled: true
storageClass: longhorn-default
size: "50Gi"
create: false
claimName: gitea-new
# I will manage my Postgres externally
postgresql:
+7 -7
View File
@@ -18,12 +18,12 @@ spec:
volumes:
- name: gitea-data
persistentVolumeClaim:
claimName: gitea-shared-storage
claimName: gitea-new
- name: dump-staging
emptyDir: {}
initContainers:
- name: gitea-dump
image: "gitea/gitea:1.25.4"
image: "gitea/gitea:1.27.1"
command:
- /bin/sh
- "-c"
@@ -51,12 +51,12 @@ spec:
- |
set -e
# Configure mc alias for MinIO
mc alias set nas1 http://nas1.shire-zebra.ts.net:9000 \
mc alias set nas1 http://nas1.shire-zebra.ts.net:30188 \
"${MINIO_ACCESS_KEY}" "${MINIO_SECRET_KEY}"
# Upload dump to backup-gitea bucket
DUMP_FILE=$(ls /dump-staging/gitea-dump-*.zip | head -1)
mc cp "${DUMP_FILE}" "nas1/backup-gitea/$(basename ${DUMP_FILE})"
echo "Uploaded $(basename ${DUMP_FILE}) to backup-gitea"
mc cp "${DUMP_FILE}" "nas1/gitea-backup/$(basename ${DUMP_FILE})"
echo "Uploaded $(basename ${DUMP_FILE}) to gitea-backup"
# Set 30-day lifecycle on the bucket (idempotent)
mc ilm rule add --expire-days 30 nas1/backup-gitea 2>/dev/null || true
volumeMounts:
@@ -69,10 +69,10 @@ spec:
- name: MINIO_ACCESS_KEY
valueFrom:
secretKeyRef:
name: gitea-config
name: gitea-backup
key: minio_key
- name: MINIO_SECRET_KEY
valueFrom:
secretKeyRef:
name: gitea-config
name: gitea-backup
key: minio_secret
+17
View File
@@ -12,3 +12,20 @@ spec:
tls:
- hosts:
- gitea
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: gitea-direct
spec:
rules:
- host: git.k3s.thehellings.lan
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: gitea-release-http
port:
name: http
+29 -11
View File
@@ -1,5 +1,32 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: gitea-backup
spec:
target:
name: gitea-backup
deletionPolicy: Delete
template:
type: Opaque
data:
minio_key: "{{ .minio_key }}"
minio_secret: "{{ .minio_secret }}"
secretStoreRef:
name: bitwarden-login
kind: ClusterSecretStore
data:
# MinIO credentials
- secretKey: minio_key
remoteRef:
key: dfb2f0c8-110d-4e96-83a7-b49c001c0897
property: username
- secretKey: minio_secret
remoteRef:
key: dfb2f0c8-110d-4e96-83a7-b49c001c0897
property: password
---
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: gitea-config
spec:
@@ -21,23 +48,14 @@ spec:
name: bitwarden-login
kind: ClusterSecretStore
data:
# MinIO credentials
- secretKey: minio_key
remoteRef:
key: dcbcf704-7dce-48d7-bbd1-b3a801875b3d
property: username
- secretKey: minio_secret
remoteRef:
key: dcbcf704-7dce-48d7-bbd1-b3a801875b3d
property: password
# MinIO credentials for NAS1
- secretKey: minio_nas1_key
remoteRef:
key: c4c66ab3-2ade-4086-9c0d-b3a80172b1ba
key: 33e8e4e0-eb90-484c-9ec9-b3a8018077a3
property: username
- secretKey: minio_nas1_secret
remoteRef:
key: c4c66ab3-2ade-4086-9c0d-b3a80172b1ba
key: 33e8e4e0-eb90-484c-9ec9-b3a8018077a3
property: password
# Postgres credentials
- secretKey: dbuser
+5 -1
View File
@@ -27,7 +27,7 @@ spec:
chart:
spec:
chart: longhorn
version: "1.11.2"
version: "1.11.3"
sourceRef:
kind: HelmRepository
name: longhorn
@@ -141,6 +141,10 @@ spec:
number: 80
- <<: *host
host: longhorn.kubernetes
- <<: *host
host: longhorn.k3s.nebula.thehellings.com
- <<: *host
host: longhorn.k3s.thehellings.lan
---
apiVersion: storage.k8s.io/v1
kind: StorageClass
+11
View File
@@ -10,6 +10,16 @@ spec:
- "--api.dashboard=true"
- "--api.insecure=true"
- "--log.level=DEBUG"
# Access logging: gives per-request visibility (client IP, host,
# path, bytes, duration) for every ingress route Traefik terminates
# (git.k3s.thehellings.lan, matrix.k3s.thehellings.lan, immich, etc).
# This is the layer HAProxy on linode forwards :80 traffic to, so
# having request-level logs here is essential for tracing bandwidth
# spikes back to a specific host/path/client rather than just a
# backend-level byte count.
- "--accesslog=true"
- "--accesslog.format=json"
- "--accesslog.fields.headers.defaultmode=keep"
ports:
postgres:
expose:
@@ -20,3 +30,4 @@ spec:
traefik:
expose:
default: true
+6 -6
View File
@@ -33,24 +33,24 @@ spec:
access-key: "{{ .minio_key }}"
secret-key: "{{ .minio_secret }}"
rclone.conf: |
[nas1minio]
[garage]
type = s3
provider = Minio
endpoint = http://nas1.shire-zebra.ts.net:9000
endpoint = http://nas1.shire-zebra.ts.net:30188
access_key_id = {{ .minio_key }}
secret_access_key = {{ .minio_secret }}
region = us-east-1
region = garage
secretStoreRef:
name: bitwarden-login
kind: ClusterSecretStore
data:
- secretKey: minio_key
remoteRef:
key: c4c66ab3-2ade-4086-9c0d-b3a80172b1ba
key: 8fce2750-aa62-4892-b90c-b49c001f494b
property: username
- secretKey: minio_secret
remoteRef:
key: c4c66ab3-2ade-4086-9c0d-b3a80172b1ba
key: 8fce2750-aa62-4892-b90c-b49c001f494b
property: password
---
apiVersion: v1
@@ -128,7 +128,7 @@ spec:
--progress \
--transfers 4 \
--checkers 8 \
/staging nas1minio:immich
/staging garage:immich
volumeMounts:
- name: staging
mountPath: /staging
+1 -1
View File
@@ -32,7 +32,7 @@ spec:
containers:
main:
image:
tag: v2.7.5
tag: v3.1.0
env:
DB_HOSTNAME: immich-rw
DB_DATABASE_NAME: immich
+4
View File
@@ -22,6 +22,10 @@ spec:
name: immich-server
port:
name: http
- <<: *host
host: immich.k3s.nebula.thehellings.com
- <<: *host
host: immich.k3s.thehellings.lan
---
apiVersion: networking.k8s.io/v1
kind: Ingress
-3
View File
@@ -10,7 +10,4 @@ resources:
- immich
- monitoring
- pinchflat
- smokeping
- uptimekuma
- donetick
- gitea
+17
View File
@@ -13,3 +13,20 @@ spec:
tls:
- hosts:
- matrix
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: matrix-direct
spec:
rules:
- host: matrix.k3s.thehellings.lan
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: dendrite
port:
number: 8008
+2 -2
View File
@@ -51,8 +51,8 @@ data:
static_configs:
- targets:
- "10.42.0.3" # OpenWRT access point
- "10.42.0.4" # Joel (Proxmox)
- "10.42.1.1" # pve1 (Proxmox)
- "10.42.0.4" # pve1 (Proxmox)
- "10.42.1.1" # UDM gateway (Ubiquiti)
- "10.42.1.4" # chronicles (Synology NAS)
- "10.42.1.14" # nas1 (TrueNAS)
- "10.42.2.57" # odoo
-50
View File
@@ -1,50 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: smokeping
labels:
app: smokeping
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
app: smokeping
template:
metadata:
labels:
app: smokeping
spec:
containers:
- name: smokeping
image: docker.io/linuxserver/smokeping:2.9.0
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 80
protocol: TCP
volumeMounts:
- name: config
mountPath: /config
- name: data
mountPath: /data
env:
- name: PUID
value: "1000"
- name: PGID
value: "1000"
- name: TZ
value: "America/Chicago"
#- name: MASTER_URL
# value: "https://ping.shire-zebra.ts.net"
# SHARED_SECRET if you want to run a cluster
# CACHE_DIR if you need to explicitly state that
restartPolicy: Always
volumes:
- name: config
persistentVolumeClaim:
claimName: smokeping-config
- name: data
persistentVolumeClaim:
claimName: smokeping-data
-14
View File
@@ -1,14 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: smokeping-tailscale
spec:
ingressClassName: tailscale
defaultBackend:
service:
name: smokeping
port:
name: http
tls:
- hosts:
- ping
-8
View File
@@ -1,8 +0,0 @@
namespace: smokeping
resources:
- namespace.yaml
- pvc.yaml
- deployment.yaml
- service.yaml
- ingress.yaml
-4
View File
@@ -1,4 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: smokeping
-23
View File
@@ -1,23 +0,0 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: smokeping-config
spec:
accessModes:
- ReadWriteOnce
storageClassName: longhorn-default
resources:
requests:
storage: 1Gi
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: smokeping-data
spec:
accessModes:
- ReadWriteOnce
storageClassName: longhorn-default
resources:
requests:
storage: 25Gi
-15
View File
@@ -1,15 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: smokeping
labels:
app: smokeping
spec:
type: ClusterIP
ports:
- port: 80
targetPort: http
protocol: TCP
name: http
selector:
app: smokeping
-38
View File
@@ -1,38 +0,0 @@
apiVersion: source.toolkit.fluxcd.io/v1
kind: HelmRepository
metadata:
name: uptime-kuma
namespace: uptime-kuma
spec:
interval: "24h"
url: "https://helm.irsigler.cloud"
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: uptime-kuma
namespace: uptime-kuma
spec:
interval: 10m
chart:
spec:
chart: uptime-kuma
sourceRef:
kind: HelmRepository
name: uptime-kuma
interval: "1h"
dependsOn:
- name: longhorn
namespace: longhorn-system
- name: mariadb-cluster
namespace: mariadb-operator
values:
volume:
storageClassName: longhorn-default
image:
tag: "2.0.2"
externalDatabase:
enabled: true
hostname: mariadb-cluster.mariadb-operator.svc.cluster.local
database: uptimekuma
existingSecret: uptimekuma-mariadb-password
-15
View File
@@ -1,15 +0,0 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: uptime-kuma-tailscale
namespace: uptime-kuma
spec:
ingressClassName: tailscale
defaultBackend:
service:
name: uptime-kuma
port:
number: 3001
tls:
- hosts:
- kuma
-7
View File
@@ -1,7 +0,0 @@
namespace: uptimekuma
resources:
- namespace.yaml
- secrets.yaml
- chart.yaml
- ingress.yaml
-4
View File
@@ -1,4 +0,0 @@
apiVersion: v1
kind: Namespace
metadata:
name: uptimekuma
-27
View File
@@ -1,27 +0,0 @@
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: uptimekuma-mariadb-password
spec:
target:
name: uptimekuma-mariadb-password
deletionPolicy: Delete
template:
type: kubernetes.io/basic-auth
data:
username: |-
{{ .username }}
password: |-
{{ .password }}
secretStoreRef:
name: bitwarden-login
kind: ClusterSecretStore
data:
- secretKey: username
remoteRef:
key: 4df95656-9f9c-4916-8e34-b3a200376365
property: username
- secretKey: password
remoteRef:
key: 4df95656-9f9c-4916-8e34-b3a200376365
property: password
+1 -5
View File
@@ -230,7 +230,7 @@
bookmarks = [
{
name = "PVE1";
url = "https://10.42.1.1:8006/";
url = "https://10.42.0.4:8006/";
}
{
name = "Jeremiah";
@@ -253,10 +253,6 @@
name = "Longhorn";
url = "http://longhorn.shire-zebra.ts.net";
}
{
name = "PGAdmin4";
url = "http://pgadmin.shire-zebra.ts.net/";
}
];
}
{
-927
View File
@@ -1,927 +0,0 @@
# This is a good source for a Ceph dealio
# https://gist.github.com0/nh2/13425a1f18b4c1ce82edb63c10b163c9
{
config,
lib,
pkgs,
...
}:
with lib;
let
cfg = config.services.ceph-benaco;
commaSep = builtins.concatStringsSep ",";
ensureUnitExists =
c': name:
let
in
#unitName = (builtins.elemAt (builtins.split "\\." name) 0);
if c'.systemd.services ? unitName then name else name; # "Unable to locate ${name} at ${commaSep (builtins.attrNames c')}";
in
{
###### interface
options = {
services.ceph-benaco = {
enable = mkEnableOption "Ceph distributed filesystem";
package = mkOption {
type = types.package;
default = pkgs.ceph;
defaultText = literalExpression "pkgs.ceph-benaco";
description = "Ceph package to use.";
};
fsid = mkOption {
type = types.str;
description = "Unique cluster identifier.";
};
clusterName = mkOption {
type = types.str;
description = "Cluster name.";
default = "ceph";
};
initialMonitors = mkOption {
type = types.listOf (
types.submodule {
options = {
hostname = mkOption {
type = types.str;
description = "Initial monitor hostname.";
};
ipAddress = mkOption {
type = types.str;
description = "Initial monitor IP address.";
};
};
}
);
description = "Initial monitors.";
};
mdsNodes = mkOption {
type = types.listOf (
types.submodule {
options = {
hostname = mkOption {
type = types.str;
description = "MDS hostname.";
};
ipAddress = mkOption {
type = types.str;
description = "MDS IP address.";
};
};
}
);
description = "MDS nodes.";
};
publicNetworks = mkOption {
type = types.listOf types.str;
description = "Public network(s) of the cluster.";
};
clusterNetworks = mkOption {
type = types.listOf types.str;
description = "Cluster backend networks for OSD sync";
};
adminKeyring = mkOption {
type = types.path;
description = "Ceph admin keyring to install on the machine.";
};
monitor = {
enable = mkEnableOption "Activate a Ceph monitor on this machine.";
initialKeyring = mkOption {
type = types.path;
description = "Keyring file to use when initializing a new monitor";
example = "/path/to/ceph.mon.keyring";
};
nodeName = mkOption {
type = types.str;
description = "Ceph monitor node name.";
example = "node1";
};
bindAddr = mkOption {
type = types.str;
description = "IP address that the OSDs shall bind to.";
example = "10.0.0.1";
};
advertisedPublicAddr = mkOption {
type = types.str;
description = "IP address that the monitor shall advertise.";
example = "10.0.0.1";
};
};
manager = {
enable = mkEnableOption "Activate a Ceph manager on this machine.";
nodeName = mkOption {
type = types.str;
description = "Ceph manager node name.";
example = "node1";
};
};
osdBindAddr = mkOption {
type = types.str;
description = "IP address that the OSDs shall bind to.";
example = "10.0.0.1";
};
osdAdvertisedPublicAddr = mkOption {
type = types.str;
description = "IP address that the OSDs shall advertise.";
example = "10.0.0.1";
};
osds = mkOption {
default = { };
example = {
osd1 = {
enable = true;
bootstrapKeyring = "/path/to/ceph.client.bootstrap-osd.keyring";
id = 1;
uuid = "11111111-1111-1111-1111-111111111111";
blockDevice = "/dev/sdb";
blockDeviceUdevRuleMatcher = ''KERNEL=="sdb"'';
clusterAddress = "10.1.0.1";
};
osd2 = {
enable = true;
bootstrapKeyring = "/path/to/ceph.client.bootstrap-osd.keyring";
id = 2;
uuid = "22222222-2222-2222-2222-222222222222";
blockDevice = "/dev/sdc";
blockDeviceUdevRuleMatcher = ''KERNEL=="sdc"'';
clusterAddress = "10.1.0.2";
};
};
description = ''
This option allows you to define multiple Ceph OSDs.
A common idiom is to use one OSD per physical hard drive.
Note that the OSD names given as attributes of this key
are NOT what ceph calls OSD IDs (instead, those are defined
by the 'services.ceph-benaco.osds.*.id' fields).
Instead, the name is an identifier local and unique to the
current machine only, used only to name the systemd service
for that OSD.
'';
type = types.attrsOf (
types.submodule {
options = {
enable = mkEnableOption "Activate a Ceph OSD on this machine.";
bootstrapKeyring = mkOption {
type = types.path;
description = "Ceph OSD bootstrap keyring.";
example = "/path/to/ceph.client.bootstrap-osd.keyring";
};
id = mkOption {
type = types.int;
description = "The ID of this OSD. Must be unique in the Ceph cluster.";
example = 1;
};
uuid = mkOption {
type = types.str;
description = "The UUID of this OSD. Must be unique in the Ceph cluster.";
example = "abcdef12-abcd-1234-abcd-1234567890ab";
};
systemdExtraRequiresAfter = mkOption {
type = types.listOf types.str;
default = [ ];
description = ''
Add the specified systemd units to the "requires" and "after"
lists of the systemd service of this OSD.
Useful, for example, to decrypt the underlying block devices with LUKS first.
NixOS modules allow override those lists from outside, but for that
the names of the systemd services for the OSDs need to be known;
this option is a convenience to not have to know them from outside.
'';
example = "decrypt-my-disk.service";
};
skipZap = mkOption {
type = types.bool;
default = false;
description = ''
Whether to skip the zapping of the the OSD device on initial OSD
installation.
Skipping is needed because <command>ceph-volume</command> cannot
zap device-mapper devices:
<link xlink:href="https://tracker.ceph.com/issues/24504" />
In that case you need to wipe the device manually.
In the common case of placing the OSD on a cryptsetup LUKS device
(which is a device-mapper device), re-creating the encryption
from scratch with a new key zaps anything anyway, in which case
zapping can be skipped here.
'';
};
blockDevice = mkOption {
type = types.str;
description = "The block device used to store the OSD.";
example = "/dev/sdb";
};
blockDeviceUdevRuleMatcher = mkOption {
type = types.str;
description = ''
An udev rule matcher matching the block device used to store the OSD.
Will be spliced into the udev rule that is
used to set access permissions to the ceph user via an udev rule.
This is a matcher instead of just a device name to allow flexibility:
Normal disks can be easily matched with <code>KERNEL=="sda1"</code>, but
device-mapper may not; for example, decrypted cryptsetup LUKS devices
have a less useful <code>KERNEL=="dm-4"</code> and may better be matched
using <code>ENV{DM_NAME}=="mydisk-decrypted"</code>.
'';
example = ''KERNEL=="sdb"'';
};
dbBlockDevice = mkOption {
type = types.nullOr types.str;
default = null;
description = ''
The block device used to store the OSD's BlueStore DB device.
Put this on a faster device than <option>blockDevice</option> to improve performance.
See <link xlink:href="http://docs.ceph.com/docs/master/rados/configuration/bluestore-config-ref/" />
for details.
'';
example = "/dev/sdc";
};
dbBlockDeviceUdevRuleMatcher = mkOption {
type = types.nullOr types.str;
default = null;
description = ''
Like <option>blockDeviceUdevRuleMatcher</option> but for the
<option>dbBlockDevice</option>.
'';
example = ''KERNEL=="sdc"'';
};
clusterAddress = mkOption {
type = types.nullOr types.str;
default = null;
description = ''
The IP address on the dedicated cluster network that
is used by the backend communication for OSD communication.
'';
example = "10.1.0.1f";
};
};
}
);
};
mds = {
enable = mkEnableOption "Activate a Ceph MDS on this machine.";
nodeName = mkOption {
type = types.str;
description = "Ceph MDS node name.";
example = "node1";
};
listenAddr = mkOption {
type = types.str;
description = "IP address that the MDS shall advertise.";
example = "10.0.0.1";
};
};
extraConfig = mkOption {
type = types.str;
default = "";
description = ''
Additional ceph.conf settings.
See the sample file for inspiration:
<link xlink:href="https://github.com/ceph/ceph/blob/master/src/sample.ceph.conf" />
'';
};
};
};
###### implementation
config =
let
monDir = "/var/lib/ceph/mon/${cfg.clusterName}-${cfg.monitor.nodeName}";
mgrDir = "/var/lib/ceph/mgr/${cfg.clusterName}-${cfg.manager.nodeName}";
mdsDir = "/var/lib/ceph/mds/${cfg.clusterName}-${cfg.mds.nodeName}";
# File permissions for things that are on locations wiped at start
# (e.g. /run or its /var/run symlink).
ensureTransientCephDirs = ''
install -m 770 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/run/ceph
'';
# File permissions from cluster deployed with ceph-deploy.
ensureCephDirs = ''
install -m 3770 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/log/ceph
install -m 770 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/run/ceph
install -m 750 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph
install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/mon
install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/mgr
install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/osd
'';
# Utilities called by Ceph device health scraping, see:
# https://docs.ceph.com/en/latest/rados/operations/devices/#enabling-monitoring
# As per https://github.com/ceph/ceph-container/pull/1490/commits/c49e821599965ae92a88b2c78077ee03c4405895,
# both the OSDs and the `mon` need this.
# Ceph calls these utilities with `sudo`. That requires sudoers entries.
# Sudoers entries require absolute path; that exact (nix store) path needs to
# be used by Ceph, so it needs to be given to the systemd unit via `path`.
# This is why we pair each `sudoersExtraRule` with the `package` to put onto
# that `path`.
#
# Entries are based on:
# https://github.com/ceph/ceph/blob/a2f5a3c1dbfa4dce41e25da4f029a8fdb8c8d864/sudoers.d/ceph-smartctl
cephMonitoringSudoersCommandsAndPackages = [
{
package = pkgs.smartmontools;
sudoersExtraRule = {
# entry for `security.sudo.extraRules`
users = [ config.users.users.ceph.name ];
commands = [
{
command = "${lib.getBin pkgs.smartmontools}/bin/smartctl -x --json=o /dev/*";
options = [ "NOPASSWD" ];
}
];
};
}
{
package = pkgs.nvme-cli;
sudoersExtraRule = {
# entry for `security.sudo.extraRules`
users = [ config.users.users.ceph.name ];
commands = [
{
command = "${lib.getBin pkgs.nvme-cli}/bin/nvme * smart-log-add --json /dev/*";
options = [ "NOPASSWD" ];
}
];
};
}
];
cephDeviceHealthMonitoringPathsOrPackages =
with pkgs;
[
# Contains `sudo`. Ceph wraps this around the other health check programs.
# Cannot use `pkgs.sudo` because that one is not SUID, see:
# https://discourse.nixos.org/t/sudo-uid-issues/9133
"/run/wrappers" # `systemd.services.<name>.path` adds the `bin/` subdir of this
]
++ map ({ package, ... }: package) cephMonitoringSudoersCommandsAndPackages;
# Unused localOsdServiceName in the following line
# deadnix: skip
makeCephOsdSetupSystemdService =
_localOsdServiceName: osdConfig:
let
osdExistenceFile = "/var/lib/ceph/osd/.${toString osdConfig.id}.${osdConfig.uuid}.nix-existence";
in
mkIf osdConfig.enable {
description = "Initialize Ceph OSD";
requires = osdConfig.systemdExtraRequiresAfter;
after = osdConfig.systemdExtraRequiresAfter;
path = with pkgs; [
# The following are currently missing in Ceph's wrapping, see https://github.com/NixOS/nixpkgs/issues/147801#issue-1065600852
util-linux # for `lsblk`
lvm2 # for `lvs`
];
# TODO Use `udevadm trigger --settle` instead of the separate `udevadm settle`
# once that feature is available to us with systemd >= 238;
# see https://github.com/systemd/systemd/commit/792cc203a67edb201073351f5c766fce3d5eab45
preStart = ''
set -x
${ensureCephDirs}
install -m 755 -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} -d /var/lib/ceph/bootstrap-osd
# `install` is not atomic, see
# https://lists.gnu.org/archive/html/bug-coreutils/2010-02/msg00243.html
# so use `mktemp` + `mv` to make it atomic.
TMPFILE=$(mktemp --tmpdir=/var/lib/ceph/bootstrap-osd/)
install -o ${config.users.users.ceph.name} -g ${config.users.groups.ceph.name} ${osdConfig.bootstrapKeyring} "$TMPFILE"
mv "$TMPFILE" /var/lib/ceph/bootstrap-osd/ceph.keyring
# Trigger udev rules for permissions of block devices and wait for them to settle.
udevadm trigger --name-match=${osdConfig.blockDevice}
''
+ lib.optionalString (osdConfig.dbBlockDevice != null) ''
udevadm trigger --name-match=${osdConfig.dbBlockDevice}
''
+ ''
udevadm settle
''
+ (optionalString (!osdConfig.skipZap) (
''
# Zap OSD block devices, otherwise `ceph-osd` below will try to fsck if there's some old
# ceph data on the block device (see https://tracker.ceph.com/issues/24099).
${cfg.package}/bin/ceph-volume lvm zap ${osdConfig.blockDevice}
''
+ lib.optionalString (osdConfig.dbBlockDevice != null) ''
${cfg.package}/bin/ceph-volume lvm zap ${osdConfig.dbBlockDevice}
''
));
script = ''
set -euo pipefail
set -x
until [ -f /etc/ceph/${cfg.clusterName}.client.admin.keyring ]
do
sleep 1
done
OSD_SECRET=$(${cfg.package}/bin/ceph-authtool --gen-print-key)
echo "{\"cephx_secret\": \"$OSD_SECRET\"}" | \
${cfg.package}/bin/ceph --cluster ${cfg.clusterName} osd new ${osdConfig.uuid} ${toString osdConfig.id} -i - \
-n client.bootstrap-osd -k ${osdConfig.bootstrapKeyring}
mkdir -p /var/lib/ceph/osd/${cfg.clusterName}-${toString osdConfig.id}
ln -s ${osdConfig.blockDevice} /var/lib/ceph/osd/${cfg.clusterName}-${toString osdConfig.id}/block
''
+ lib.optionalString (osdConfig.dbBlockDevice != null) ''
ln -s ${osdConfig.dbBlockDevice} /var/lib/ceph/osd/${cfg.clusterName}-${toString osdConfig.id}/block.db
''
+ ''
${cfg.package}/bin/ceph-authtool --create-keyring /var/lib/ceph/osd/ceph-${toString osdConfig.id}/keyring \
--name osd.${toString osdConfig.id} --add-key $OSD_SECRET
${cfg.package}/bin/ceph-osd -i ${toString osdConfig.id} --mkfs --osd-uuid ${osdConfig.uuid} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} --osd-objectstore bluestore
touch ${osdExistenceFile}
'';
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
PermissionsStartOnly = true; # only run the script as ceph, preStart as root
User = config.users.users.ceph.name;
Group = config.users.groups.ceph.name;
};
unitConfig = {
ConditionPathExists = "!${osdExistenceFile}";
};
};
makeCephOsdSystemdService =
localOsdServiceName: osdConfig:
mkIf osdConfig.enable {
description = "Ceph OSD";
# Note we do not have to add `osdConfig.systemdExtraRequiresAfter` here because
# that's already a dependency of our dependency `ceph-osd-setup-*`.
requires = [ (ensureUnitExists config "ceph-osd-setup-${localOsdServiceName}.service") ];
requiredBy = [ "multi-user.target" ];
after = [
"network.target"
"local-fs.target"
"time-sync.target"
(ensureUnitExists config "ceph-osd-setup-${localOsdServiceName}.service")
];
wants = [
"network.target"
"local-fs.target"
"time-sync.target"
];
path = [
# TODO: use wrapProgram in the ceph package for this in the future
pkgs.getopt
]
++ cephDeviceHealthMonitoringPathsOrPackages;
restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ];
preStart = ''
${ensureTransientCephDirs}
${lib.getLib cfg.package}/libexec/ceph/ceph-osd-prestart.sh --cluster ${cfg.clusterName} --id ${toString osdConfig.id}
'';
serviceConfig =
let
clusterIpArg = lib.optionalString (
osdConfig.clusterAddress != null
) "--cluster_addr=${osdConfig.clusterAddress}";
in
{
LimitNOFILE = "1048576";
LimitNPROC = "1048576";
ExecStart = ''
${cfg.package}/bin/ceph-osd -f --cluster ${cfg.clusterName} --id ${toString osdConfig.id} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} "--public_bind_addr=${cfg.osdBindAddr}" "--public_addr=${cfg.osdAdvertisedPublicAddr}" "${clusterIpArg}"
'';
ExecReload = ''
${pkgs.coreutils}/bin/kill -HUP $MAINPID
'';
Restart = "on-failure";
ProtectHome = "true";
ProtectSystem = "full";
PrivateTmp = "true";
TasksMax = "infinity";
# StartLimitBurst="3";
};
# startLimitIntervalSec = 30 * 60;
};
in
mkIf cfg.enable {
environment.systemPackages = [ cfg.package ];
networking.firewall = {
allowedTCPPorts = [
# Ceph outside of VPN because it is very data heavy and causes packet loss.
# We enable msgr-v2 only because that allows its own on-wire encryption.
3300 # ceph msgr-v2
];
allowedTCPPortRanges = [
{
from = 6800;
to = 7300;
} # https://docs.ceph.com/en/pacific/rados/configuration/network-config-ref/
];
};
# Reminder of how `ceph.conf` works:
#
# * Ceph upstream docs now recommend to use underscores instead of spaces.
# * Options in more specific sections like `[mon]` override those in less
# specific sections like `[global]`. But all options can be written into all sections,
# and an option has the same name, no matter in which section it is written.
# Thus, put options in `[global]`, and only use a diffent section
# if you want to override an option you've set in `global`.
#
# Sample: https://github.com/ceph/ceph/blob/master/src/sample.ceph.conf
environment.etc."ceph/${cfg.clusterName}.conf".text = ''
[global]
fsid = ${cfg.fsid}
mon_initial_members = ${commaSep (map (mon: mon.hostname) cfg.initialMonitors)}
mon_host = ${commaSep (map (mon: mon.ipAddress) cfg.initialMonitors)}
# Ceph clusters go into WARN health mode, until
# the following setting is made strict by setting it to `false`:
# See: https://docs.ceph.com/en/latest/security/CVE-2021-20288/#recommendations
# As of writing, this setting is not documented outside of the CVE note :(
#
# While for new clusters the warning no longer seems to appear, it still
# appears in our existing clusters unless this option is set, see:
# https://tracker.ceph.com/issues/53751#note-7
auth_allow_insecure_global_id_reclaim = false
# Disable dirfrag prefetch on MDS restart to prevent out-of-memory after
# many files were opened.
# Note this option has no effect on Ceph < 15, because it doesn't exist there.
# TODO: Remove this once we're on a Ceph version that includes this default,
# see https://github.com/ceph/ceph/pull/44667.
# This is assuming that the commit fixes existing clusters, see
# https://github.com/ceph/ceph/pull/44667#issuecomment-1036103397
# If it doesn't this can only be removed once we have no existing
# cluster with the old default.
mds_oft_prefetch_dirfrags = false
# Disable sleep between HDD recovery operations, otherwise recovery
# will take forever when small objects (e.g. CephFS files) are on HDD.
# See https://tracker.ceph.com/issues/23595#note-12
osd_recovery_sleep_hdd = 0.0
# Increase scrub intervals by 4x.
# Since we store many small files on HDD, and scrubbing apparently
# iterates over all objects
# we have no chance to scrub at the default intervals.
#
# (This was written when we had 400M files across 30 HDDs.)
# Change this back once we have reduced our number of files per disk.
osd_scrub_min_interval = 345600
osd_scrub_max_interval = 2419200
osd_deep_scrub_interval = 2419200
public_network = ${commaSep cfg.publicNetworks}
cluster_network = ${commaSep cfg.clusterNetworks}
auth_cluster_required = cephx
auth_service_required = cephx
auth_client_required = cephx
# Enforce on-wire transport encryption.
ms_cluster_mode = secure
ms_service_mode = secure
ms_client_mode = secure
${cfg.extraConfig}
'';
environment.etc."ceph/${cfg.clusterName}.client.admin.keyring" = {
source = cfg.adminKeyring;
mode = "0600";
# Make ceph own this keyring so that it can use it to get keys for its daemons.
user = "ceph";
group = "ceph";
};
users.users.ceph = {
isNormalUser = false;
isSystemUser = true;
# TODO: Legacy UID / GID chosen from before we configured the UID declaratively.
# In the future, we whould change this whole module to use
# `config.ids.uids.ceph`, like the upstream nixpkgs Ceph module does.
# Switching away from `nogroup` would also be good as described there.
# For both cases, we'll have to `chown` all relevant existing files on
# deployments, such as `/var/lib/ceph`, and log files.
uid = 1001;
group = config.users.groups.nogroup.name;
};
users.groups.ceph = {
# TODO: Same TODO as above for the `uid`.
gid = 499;
};
# Allow ceph daemons (which run as user ceph) to collect device health metrics.
security.sudo.extraRules = map (
{ sudoersExtraRule, ... }: sudoersExtraRule
) cephMonitoringSudoersCommandsAndPackages;
# The udevadm trigger/settle in `makeCephOsdSetupSystemdService` waits for these rules rule to be applied.
services.udev.extraRules = lib.concatStringsSep "\n" (
lib.mapAttrsToList (
_localOsdServiceName: osdConfig:
''
SUBSYSTEM=="block", ${osdConfig.blockDeviceUdevRuleMatcher}, OWNER="${config.users.users.ceph.name}", GROUP="${config.users.groups.ceph.name}", MODE="0660"
''
+ lib.optionalString (osdConfig.dbBlockDeviceUdevRuleMatcher != null) (''
SUBSYSTEM=="block", ${osdConfig.dbBlockDeviceUdevRuleMatcher}, OWNER="${config.users.users.ceph.name}", GROUP="${config.users.groups.ceph.name}", MODE="0660"
'')
) cfg.osds
);
systemd.services = {
ceph-mon-setup = mkIf cfg.monitor.enable {
description = "Initialize ceph monitor";
preStart = ensureCephDirs;
script =
let
# `--addv` seems currently required to get msgr-v2 working, see:
# https://tracker.ceph.com/issues/53751#note-11
monmapNodes = builtins.concatStringsSep " " (
lib.concatMap (mon: [
"--addv"
mon.hostname
"[v2:${mon.ipAddress}:3300,v1:${mon.ipAddress}:6789]"
]) cfg.initialMonitors
);
in
# Monitors cannot simply be changed in config, one has to update the monmap, see note [replacing-ceph-monmap-ips-for-existing-cluster]
''
set -euo pipefail
rm -rf "${monDir}" # Start from scratch.
echo "Initializing monitor."
MONMAP_DIR=`mktemp -d`
${cfg.package}/bin/monmaptool --create ${monmapNodes} --fsid ${cfg.fsid} "$MONMAP_DIR/monmap"
${cfg.package}/bin/ceph-mon --cluster ${cfg.clusterName} --mkfs -i ${cfg.monitor.nodeName} --monmap "$MONMAP_DIR/monmap" --keyring ${cfg.monitor.initialKeyring}
rm -r "$MONMAP_DIR"
touch ${monDir}/done
'';
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
PermissionsStartOnly = true; # only run the script as ceph
User = config.users.users.ceph.name;
Group = config.users.groups.ceph.name;
};
unitConfig = {
ConditionPathExists = "!${monDir}/done";
};
};
ceph-mon = mkIf cfg.monitor.enable {
description = "Ceph monitor";
requires = [ (ensureUnitExists config "ceph-mon-setup.service") ];
requiredBy = [ "multi-user.target" ];
after = [
"network.target"
"local-fs.target"
"time-sync.target"
(ensureUnitExists config "ceph-mon-setup.service")
];
wants = [
"network.target"
"local-fs.target"
"time-sync.target"
];
restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ];
path = cephDeviceHealthMonitoringPathsOrPackages;
preStart = ensureTransientCephDirs;
serviceConfig = {
LimitNOFILE = "1048576";
LimitNPROC = "1048576";
ExecStart = ''
${cfg.package}/bin/ceph-mon -f --cluster ${cfg.clusterName} --id ${cfg.monitor.nodeName} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} "--public_bind_addr=${cfg.monitor.bindAddr}" "--public_addr=${cfg.monitor.advertisedPublicAddr}"
'';
ExecReload = ''
${pkgs.coreutils}/bin/kill -HUP $MAINPID
'';
PrivateDevices = "yes";
ProtectHome = "true";
ProtectSystem = "full";
PrivateTmp = "true";
TasksMax = "infinity";
Restart = "on-failure";
# StartLimitBurst="5";
RestartSec = "10";
};
# startLimitIntervalSec = 30 * 60;
};
ceph-mgr-setup = mkIf cfg.manager.enable {
description = "Initialize Ceph manager";
preStart = ensureCephDirs;
script = ''
set -euo pipefail
mkdir -p ${mgrDir}
until [ -f /etc/ceph/${cfg.clusterName}.client.admin.keyring ]
do
sleep 1
done
${cfg.package}/bin/ceph auth get-or-create mgr.${cfg.manager.nodeName} mon 'allow profile mgr' mds 'allow *' osd 'allow *' -o ${mgrDir}/keyring
touch "${mgrDir}/.nix_done"
'';
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
PermissionsStartOnly = true; # only run the script as ceph
User = config.users.users.ceph.name;
Group = config.users.groups.ceph.name;
};
unitConfig = {
ConditionPathExists = "!${mgrDir}/.nix_done";
};
};
ceph-mgr = mkIf cfg.manager.enable {
description = "Ceph manager";
requires = [ (ensureUnitExists config "ceph-mgr-setup.service") ];
requiredBy = [ "multi-user.target" ];
after = [
"network.target"
"local-fs.target"
"time-sync.target"
(ensureUnitExists config "ceph-mgr-setup.service")
];
wants = [
"network.target"
"local-fs.target"
"time-sync.target"
];
restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ];
preStart = ensureTransientCephDirs;
serviceConfig = {
LimitNOFILE = "1048576";
LimitNPROC = "1048576";
ExecStart = ''
${cfg.package}/bin/ceph-mgr -f --cluster ${cfg.clusterName} --id ${cfg.manager.nodeName} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name}
'';
ExecReload = ''
${pkgs.coreutils}/bin/kill -HUP $MAINPID
'';
Restart = "on-failure";
RestartSec = 10;
# StartLimitBurst="3";
};
# startLimitIntervalSec = 30 * 60;
};
ceph-mds-setup = mkIf cfg.mds.enable {
description = "Initialize Ceph MDS";
preStart = ensureCephDirs;
script = ''
set -euo pipefail
mkdir -p ${mdsDir}
until [ -f /etc/ceph/${cfg.clusterName}.client.admin.keyring ]
do
sleep 1
done
${cfg.package}/bin/ceph auth get-or-create mds.${cfg.mds.nodeName} osd 'allow rwx' mds 'allow' mon 'allow profile mds' -o ${mdsDir}/keyring
touch "${mdsDir}/.nix_done"
'';
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
PermissionsStartOnly = true; # only run the script as ceph
User = config.users.users.ceph.name;
Group = config.users.groups.ceph.name;
};
unitConfig = {
ConditionPathExists = "!${mdsDir}/.nix_done";
};
};
ceph-mds = mkIf cfg.mds.enable {
description = "Ceph MDS";
requires = [ (ensureUnitExists config "ceph-mds-setup.service") ];
requiredBy = [ "multi-user.target" ];
after = [
"network.target"
"local-fs.target"
"time-sync.target"
(ensureUnitExists config "ceph-mds-setup.service")
];
wants = [
"network.target"
"local-fs.target"
"time-sync.target"
];
restartTriggers = [ config.environment.etc."ceph/${cfg.clusterName}.conf".source ];
preStart = ensureTransientCephDirs;
serviceConfig = {
LimitNOFILE = "1048576";
LimitNPROC = "1048576";
ExecStart = ''
${cfg.package}/bin/ceph-mds -f --cluster ${cfg.clusterName} --id ${cfg.mds.nodeName} --setuser ${config.users.users.ceph.name} --setgroup ${config.users.groups.ceph.name} "--public_addr=${cfg.mds.listenAddr}"
'';
ExecReload = ''
${pkgs.coreutils}/bin/kill -HUP $MAINPID
'';
Restart = "on-failure";
# StartLimitBurst="3";
};
# startLimitIntervalSec = 30 * 60;
};
}
# Make one OSD service for each configured OSD.
// lib.mapAttrs' (
localOsdServiceName: osdConfig:
nameValuePair "ceph-osd-setup-${localOsdServiceName}" (
makeCephOsdSetupSystemdService localOsdServiceName osdConfig
)
) cfg.osds
// lib.mapAttrs' (
localOsdServiceName: osdConfig:
nameValuePair "ceph-osd-${localOsdServiceName}" (
makeCephOsdSystemdService localOsdServiceName osdConfig
)
) cfg.osds;
};
}
+1 -1
View File
@@ -7,7 +7,6 @@
./adblock-update.nix
./albyhub.nix
./backup.nix
./ceph.nix
./db.nix
./gitea-runner.nix
./gnome.nix
@@ -16,6 +15,7 @@
#./kiwix-serve.nix
./kubernetes.nix
./linode.nix
./monitoring-access.nix
./podman.nix
./print.nix
./proxy.nix
+13
View File
@@ -98,6 +98,19 @@ in
inherit labels;
inherit (cfg) name;
enable = true;
hostPackages = with pkgs; [
bash
buildah
coreutils
curl
gawk
gitMinimal
gnused
nix
nodejs
podman
wget
];
url = cfg.instanceURL;
tokenFile = config.age.secrets."gitea-runner-${host}-podman".path;
settings = {
-26
View File
@@ -15,8 +15,6 @@ let
sha256 = "sha256-Qs1qJmgZm8q9xZsORjT/N/wzpbWVVODXtzDpjnAYMuQ=";
};
keepaliveIp = "10.42.5.1";
nebulaName = "k3s.nebula.thehellings.com";
nebulaIp = "10.157.100.1";
in
{
options.greg = {
@@ -46,13 +44,6 @@ in
};
config = lib.mkIf cfg.enable {
assertions = [
{
assertion = config.greg.nebula.enable;
message = "Configure Nebula for this host, first";
}
];
age.secrets = {
bw_secret.file = ../../secrets/kubernetes/bw_secret.age;
dendrite_key.file = ../../secrets/dendrite_key.age;
@@ -106,8 +97,6 @@ in
"--tls-san ${config.networking.hostName}.thehellings.lan"
"--tls-san ${config.networking.hostName}.shire-zebra.ts.net"
"--tls-san ${keepaliveIp}"
"--tls-san ${nebulaName}"
"--tls-san ${nebulaIp}"
];
manifests = {
cert-manager.source = cert-manager;
@@ -139,21 +128,6 @@ in
advert_int 1
'';
};
k3s-nebula = {
interface = "nebula0";
priority = 1;
state = if (config.networking.hostName == "isaiah") then "MASTER" else "BACKUP";
virtualIps = [
{
addr = "${nebulaIp}/16";
dev = "nebula0";
}
];
virtualRouterId = 78;
extraConfig = ''
advert_int 1
'';
};
};
};
openiscsi = {
+53
View File
@@ -0,0 +1,53 @@
{
config,
lib,
pkgs,
...
}:
let
cfg = config.greg.monitoring-access;
in
with lib;
{
options.greg.monitoring-access = {
enable = mkOption {
type = types.bool;
default = true;
description = ''
Create a dedicated, read-only account (`emily`) for automated
monitoring and analysis by the Hermes agent. The account is
SSH-key-only (no password set), is not added to `wheel`, and is
granted no sudo rights. It only gets read access to the systemd
journal via group membership, which is sufficient for log
inspection and health/analysis tasks without any privileged
access to the rest of the system.
'';
};
sshKeys = mkOption {
type = types.listOf types.str;
default = lib.strings.splitString "\n" (
builtins.readFile ../../home/ssh/emily_authorized_keys
);
description = "SSH public keys authorized to log in as the monitoring account.";
};
};
config = mkIf cfg.enable {
users.groups.emily = { };
users.users.emily = {
isNormalUser = true;
createHome = true;
description = "Read-only monitoring/analysis account (Hermes agent)";
group = "emily";
# No password is set on purpose: this account is SSH-key-only.
extraGroups = [
"systemd-journal" # read access to the journal for log analysis
];
shell = pkgs.bashInteractive;
openssh.authorizedKeys.keys = cfg.sshKeys;
};
};
}
+13 -2
View File
@@ -23,6 +23,13 @@ with lib;
type = types.str;
description = "Kernel module type to install - amd, intel, etc";
};
host = mkOption {
type = types.enum [
"libvirt"
"vbox"
];
description = "Which VM hosting type to configure";
};
};
};
@@ -35,7 +42,6 @@ with lib;
nixos-generators
packer
swtpm
virt-manager
virtio-win
xorriso
];
@@ -44,7 +50,7 @@ with lib;
# Enable the virtualisation services
virtualisation = {
libvirtd = {
libvirtd = mkIf (cfg.host == "libvirt") {
enable = true;
onBoot = "ignore"; # Do not auto-restart VMs on boot, unless they are marked autostart
qemu = {
@@ -54,6 +60,11 @@ with lib;
};
};
};
virtualbox.host = mkIf (cfg.host == "vbox") {
enable = true;
enableExtensionPack = true;
headless = true;
};
};
boot.extraModprobeConfig = "options kvm_${cfg.system} nested=1";
+26 -21
View File
@@ -9,10 +9,6 @@
"tailscale": "100.64.0.0/10"
},
"hosts": {
"builder2": {
"ip": "10.42.1.17",
"system": "x86_64-linux"
},
"exodus": {
"ip": null,
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFxmnCj2E9DxcnefPW+n4yCuLShxqr0p024riogdeXA3",
@@ -28,6 +24,15 @@
"tags": ["router", "server"],
"nebulaIp": "10.157.0.2"
},
"gregory.hellings-mbp": {
"external": true,
"system": "aarch64-darwin",
"user": "gregory.hellings"
},
"gregs-MacBook-Pro-16-inch-Nov-2024": {
"external": true,
"system": "aarch64-darwin"
},
"hosea": {
"ip": "10.42.1.7",
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKLIwkTTXA56sUlUjEulXXZRvZy5H4a5ZwgKWLlpkQDz",
@@ -50,13 +55,12 @@
"external": true,
"system": "x86_64-linux"
},
"gregory.hellings-mbp": {
"ivr": {
"external": true,
"system": "aarch64-darwin",
"user": "gregory.hellings"
"system": "aarch64-darwin"
},
"jeremiah": {
"aliases": [ "buildbot" ],
"aliases": ["buildbot"],
"builder": true,
"ip": "10.42.1.8",
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOjQjXq9WYU2Ki27BR9WwJ4ZruS/lJXbjC1b0Q42Adi0",
@@ -66,15 +70,19 @@
"tags": ["builder", "kube", "server"],
"nebulaIp": "10.157.0.5"
},
"gregs-MacBook-Pro-16-inch-Nov-2024": {
"external": true,
"system": "aarch64-darwin"
"kuma": {
"ip": "10.42.1.19",
"nebulaIp": "10.157.0.8",
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIhr+LmYMOk4Hixxew2FiAvL8sycgQvnhK8PBGjfnkJb",
"system": "x86_64-linux",
"tags": ["server"]
},
"lithic": {
"external": true,
"system": "aarch64-darwin"
},
"linode": {
"connectAddr": "thehellings.com",
"ip": null,
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMv9Zud3kZOl86gtmkn+uj3D4kiXWDPtyUL02VVLNR4Q",
"ts": "100.109.86.8",
@@ -82,10 +90,6 @@
"tags": ["public", "server"],
"nebulaIp": "10.157.0.1"
},
"ivr": {
"external": true,
"system": "aarch64-darwin"
},
"MacBook-Pro.local": {
"external": true,
"system": "aarch64-darwin"
@@ -127,22 +131,22 @@
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILFYyzz/9i5rXprCQj9IL1ulrbQ6E9BOSeOcvf4D/b0G",
"tags": ["server"]
},
"joel": {
"ip": "10.42.0.4"
},
"k3s": {
"aliases": [ "*.k3s" ],
"aliases": ["*.k3s"],
"ip": "10.42.5.1",
"nebulaIp": "10.157.100.1"
},
"nas1": {
"aliases": [ "*.nas1" ],
"aliases": ["*.nas1"],
"ip": "10.42.1.14",
"ts": "100.114.187.61"
},
"printer": {
"ip": "10.42.1.3"
},
"pve1": {
"ip": "10.42.0.4"
},
"pve2": {
"ip": "10.42.1.15"
},
@@ -161,7 +165,8 @@
"ip": "10.42.1.17"
},
"pve4bmc": {
"ip": "10.42.6.4"
"ip": "10.42.6.4",
"mac": "00:25:90:4a:d8:2e"
}
}
}
+10 -6
View File
@@ -16,12 +16,15 @@ let
adblock_update = c ./adblock_update.nix { };
brew = c ./homebrew.nix { };
create_ssl = c ./create_ssl.nix { };
dockerCompat = pkgs.runCommand "docker-compat" {
nativeBuildInputs = [];
} ''
mkdir -p $out/bin
ln -s ${pkgs.podman}/bin/podman $out/bin/docker
'';
dockerCompat =
pkgs.runCommand "docker-compat"
{
nativeBuildInputs = [ ];
}
''
mkdir -p $out/bin
ln -s ${pkgs.podman}/bin/podman $out/bin/docker
'';
gcc-tune = c ./gcc-tune.nix { };
#gen-build = c ./gen-build { };
hms = c ./hms { };
@@ -29,6 +32,7 @@ let
inject = c ./inject.nix { };
setup-ssh = c ./setup-ssh { };
upgrade-pg-cluster = c ./upgrade-pg-cluster.nix { };
zim-updater = c ./zim/updater.nix { };
};
x86Linux = {
qemu-hook = c ./qemu-hook.nix { };
+28 -28
View File
@@ -2,18 +2,18 @@
"en": {
"gutenberg": {
"name": "gutenberg_en_all",
"version": "2023-08",
"hash": "sha256-OXmdHdsLZcW4nCUQsy7sMpUssS8NV7ztkCgS/nsISuw="
"version": "2025-11",
"hash": "sha256-AWd8jVVKHKssv9AgrJnryn3Wx0084NE/JmorpgPfryg="
},
"phet": {
"name": "phet_en_all",
"version": "2025-03",
"hash": "sha256-ARuUzU2o17J2/ZedHc2acXl33dtHCbQJEb72UQUEm1Y="
"version": "2026-05",
"hash": "sha256-zAAq/X5rjQUiYmjMpBtWP5z3J2ZHJMmIxFKnxLAhOlA="
},
"wikibooks": {
"name": "wikibooks_en_all_maxi",
"version": "2025-10",
"hash": "sha256-ONBh/ze1Fv2Ffm5b9vDzYS/i2cWSa4pM4MLZnozr2n8="
"version": "2026-04",
"hash": "sha256-wt7Zr+RkfCsFrOudMCYBADacu6IvPQDkZ6Y0VG2j9hA="
},
"wikipedia": {
"name": "wikipedia_en_all_maxi",
@@ -22,40 +22,40 @@
},
"wikisource": {
"name": "wikisource_en_all_maxi",
"version": "2025-11",
"hash": "sha256-p1Jio+PMTZVSLIDIOBeMG3acXJg83CwQM7zIWDUyozM="
"version": "2026-05",
"hash": "sha256-OA4b+U8mxpcX3fst6hrMyctucYTQOlG/b4qZDiVlcf4="
},
"wikiversity": {
"name": "wikiversity_en_all_maxi",
"version": "2025-11",
"hash": "sha256-IG/gAUdc/vHRrIWGHhw8vMJdLWwqrNbfh+SiclQRIAI="
"version": "2026-05",
"hash": "sha256-8mZ1CSUcF4QnDIyN0M2KedQ4pcSUCmzHBlOm93MYpCE="
},
"wiktionary": {
"name": "wiktionary_en_all_nopic",
"version": "2025-09",
"hash": "sha256-Ghcb60qeGaSJtTKQkJoMx/XucX7Lt1XY145lD3gHlMg="
"version": "2026-05",
"hash": "sha256-Dwiz+viVQt0zb077R9KQRgtUtxG9ixA/DeXAkCdD4rM="
}
},
"fr": {
"gutenberg": {
"name": "gutenberg_fr_all",
"version": "2025-10",
"hash": "sha256-gLHxLXJNwwcxM/mZHtoJ8ojbGQ1fugxgni/+RXccwhU="
"version": "2026-01",
"hash": "sha256-sGn1TeKwBK0+Er5YOJWq6g0itEm4gIGvKxv/PW0DIao="
},
"phet": {
"name": "phet_fr_all",
"version": "2025-03",
"hash": "sha256-CSboZNTIowLLhp1u9wkxH8xmu3LvQNx5q493AOYJRIc="
"version": "2026-05",
"hash": "sha256-bJmchFnaPcofE/hy3ZcRggMT9osHqXwLbwMLJ+cpF28="
},
"wikibooks": {
"name": "wikibooks_fr_all_maxi",
"version": "2025-09",
"hash": "sha256-KHCc/73L5Bd9iZ47SRV6vpI8fVM1v9hk1TpEvTro2uo="
"version": "2026-07",
"hash": "sha256-csI+E5UFGi42BLGWWHxQhVr5KSihCFc53KGKwo557Ck="
},
"wikipedia": {
"name": "wikipedia_fr_all_maxi",
"version": "2025-06",
"hash": "sha256-ve7Mbh96/ObNbV/KVNYZpfLN+HdWlJ7C5LItEdVkRH0="
"version": "2026-05",
"hash": "sha256-YUAbGzYYr+c2RQqGjHIF9XL1kNsxDgRKnHK1H7/PtDE="
},
"wikisource": {
"name": "wikisource_fr_all_maxi",
@@ -64,25 +64,25 @@
},
"wikiversity": {
"name": "wikiversity_fr_all_maxi",
"version": "2025-09",
"hash": "sha256-55fdtw/cRezq6nkRp6wuwkukBiqsQKdwh9QWVAgFcBI="
"version": "2026-05",
"hash": "sha256-nVDHtkWIOJkoiGixnA1zVR1QS58thjc12FJyagK3Ec0="
},
"wiktionary": {
"name": "wiktionary_fr_all_nopic",
"version": "2025-11",
"hash": "sha256-P0CJptee5rDzccxyRDBzyRLuuFOcaLsJYi6DkBFUfIc="
"version": "2026-05",
"hash": "sha256-7UXByW2IIL0hec8RPT39jpg5IEGvRMD47hc4Y4vFkJs="
}
},
"ht": {
"phet": {
"name": "phet_ht_all",
"version": "2025-03",
"hash": "sha256-bHrPzE8H7ptrP6r5wPlXSsXNlTiKxJ9KatABC4kwx+s="
"version": "2026-05",
"hash": "sha256-GiJ1jllhioyMYidQ7+Lcbdd9JN2yf04ZQgnO8XaGAqY="
},
"wikipedia": {
"name": "wikipedia_ht_all_maxi",
"version": "2026-04",
"hash": "sha256-qUX0pKxIyNsWX4V6kNIsP4Z9nc6TDhwdDR0MmpDOQFs="
"version": "2026-07",
"hash": "sha256-InS9cMRaIv9ArlKVwKUypz56m4DgSR7Tl6XpSTMzH+o="
}
}
}
+167 -112
View File
@@ -9,7 +9,7 @@ import (
"net/http"
"os"
"os/exec"
"path/filepath"
"reflect"
"regexp"
"sort"
"strings"
@@ -17,27 +17,144 @@ import (
const BASE = "https://download.kiwix.org/zim"
func getTypes() []string {
return []string{
"phet",
"wikipedia",
"wiktionary",
"wikiversity",
"wikisource",
"wikibooks",
"gutenberg",
"ted",
// ///////////////////////////////////////////////////////////////////////////
// //////////////// THE BLOB ITSELF /////////////////////////////////////////
// ///////////////////////////////////////////////////////////////////////////
type Blobs struct {
En Language `json:"en"`
Fr Language `json:"fr"`
Ht Language `json:"ht"`
dirty bool
}
func (b *Blobs) Populate() {
done := make(chan bool)
waitFor := 0
// Launch self-populating efforts
blobType := reflect.Indirect(reflect.ValueOf(b)).Type()
for f := range blobType.Fields() {
if f.IsExported() {
//fmt.Printf("%s:\tBeginning population efforts\n", f.Name)
waitFor += 1
go reflect.Indirect(reflect.ValueOf(b)).
FieldByName(f.Name).
Addr().
Interface().
(*Language).
Populate(strings.ToLower(f.Name), done)
}
}
// Wait until all languages are completed
for d := range done {
waitFor -= 1
if waitFor == 0 {
fmt.Println("Completed waiting for all languages")
close(done)
break
}
b.dirty = b.dirty || d
}
}
func getLanguages() []string {
return []string{
"ht",
"en",
"fr",
/////////////////////////////////////////////////////////////////////////////
//////////////////////// The Language ///////////////////////////////////////
/////////////////////////////////////////////////////////////////////////////
type Language struct {
Gutenberg *Zim `json:"gutenberg,omitempty"`
Phet *Zim `json:"phet,omitempty"`
Ted *Zim `json:"ted,omitempty"`
Wikibooks *Zim `json:"wikibooks,omitempty"`
Wikipedia *Zim `json:"wikipedia,omitempty"`
Wikisource *Zim `json:"wikisource,omitempty"`
Wikiversity *Zim `json:"wikiversity,omitempty"`
Wiktionary *Zim `json:"wiktionary,omitempty"`
dirty bool
}
func (l *Language) Populate(code string, done chan bool) {
childDone := make(chan bool)
waitFor := 0
languageType := reflect.Indirect(reflect.ValueOf(l)).Type()
l.dirty = false
for f := range languageType.Fields() {
if f.IsExported() {
ptrPtrZim := reflect.Indirect(reflect.ValueOf(l)).
FieldByName(f.Name)
if ptrPtrZim.IsValid() && !ptrPtrZim.IsNil() {
waitFor += 1
go reflect.Indirect(ptrPtrZim).
Addr().
Interface().
(*Zim).
Populate(strings.ToLower(f.Name), code, childDone)
} else {
// TODO: Figure out how to set a value over the nil pointer
// of the field, so we can auto-detect when these are available
// in the future
// waitFor += 1
//z := &Zim{Name: f.Name, Version: "1999-01-01", Hash: ""}
//ptrPtrZim.Set(reflect.ValueOf(z))
//go z.Populate(strings.ToLower(f.Name), code, childDone)
}
}
}
// Wait until children are all done
for d := range childDone {
waitFor -= 1
if waitFor == 0 {
close(childDone)
break
}
l.dirty = l.dirty || d
}
//fmt.Printf("%s\tFinished populate\n", code)
done <- l.dirty
}
// ///////////////////////////////////////////////////////////////////////////
// ////////////////////// A Single Zim ///////////////////////////////////////
// ///////////////////////////////////////////////////////////////////////////
type Zim struct {
Name string `json:"name"`
Version string `json:"version"`
Hash string `json:"hash"`
dirty bool
}
func (z *Zim) Populate(category string, language string, done chan bool) {
//fmt.Printf("%s:%s\tBeginning populate for\n", language, category)
// Look for a possible Zim file
links := getLinks(getPage(category))
link, err := getName(links, category, language)
if err != nil {
fmt.Printf("%s:%s\tNo zim found\n", language, category)
done <- false
return
}
//fmt.Printf("%s:%s\tFound link: %s\n", category, language, link)
// Extract name and version
re := regexp.MustCompilePOSIX("^([a-zA-Z_]+)_([0-9-]+)\\.zim$")
match := re.FindStringSubmatch(link)
if len(match) != 3 {
fmt.Printf("%s:%s Matches: %s", language, category, match)
os.Exit(1)
}
// Check if the name and version mismatch
if match[1] == z.Name && match[2] == z.Version {
fmt.Printf("Skipping existing hash: %s\n", link)
done <- false
} else {
z.Name = match[1]
z.Version = match[2]
// Fetch the Zim file, if it differs from what we currently have
z.UpdateHash(category)
done <- true
}
}
// Helper function to fetch the HTML of a given type page
func getPage(t string) string {
page, err := http.Get(fmt.Sprintf("%s/%s/", BASE, t))
if err != nil {
@@ -48,6 +165,7 @@ func getPage(t string) string {
return string(pageBytes)
}
// Helper function to parse out all the links from the page
func getLinks(page string) []string {
ret := []string{}
@@ -60,6 +178,7 @@ func getLinks(page string) []string {
return ret
}
// Helper function to get the most likely link for this particular entry
func getName(links []string, t, lang string) (string, error) {
candidates := []string{}
prefix := fmt.Sprintf("%s_%s_all", t, lang)
@@ -79,44 +198,39 @@ func getName(links []string, t, lang string) (string, error) {
}
}
func getHash(ch chan result, file, category, language string) {
// TODO: Only call this if the file doesn't already have a hash
// in the existing file
fmt.Printf("Fetching hash for %s\n", file)
cmd := exec.Command( "nix-prefetch-url", fmt.Sprintf("%s/%s/%s", BASE, category, file))
// Helper function to get the hash value from the resulting link
func (z *Zim) UpdateHash(category string) error {
file := fmt.Sprintf("%s_%s.zim", z.Name, z.Version)
// First fetch the file into our local Nix store
fmt.Printf("Fetching hash: %s\n", file)
cmd := exec.Command("nix-prefetch-url", fmt.Sprintf("%s/%s/%s", BASE, category, file))
out, err := cmd.Output()
if err != nil {
fmt.Printf("Error fetching hash for %s (category: %s, language: %s): %v\n", file, category, language, err)
fmt.Printf("%s: ERROR fetching hash: %v\n", file, err)
if exitErr, ok := err.(*exec.ExitError); ok {
fmt.Printf("Command stderr: %s\n", string(exitErr.Stderr))
}
ch <- result{category, language, ""}
return
return errors.New("Error fetching file")
}
hash := strings.TrimSpace(string(out))
fmt.Printf("Successfully fetched hash for %s (category: %s, language: %s)\n", file, category, language)
ch <- result{category, language, hash}
}
fmt.Printf("%s: Successfully fetched raw hash\n", file)
fmt.Printf("%s: Hash is: %s\n", file, hash)
func outputIsValid(o map[string]map[string]Zim) bool {
for a := range o {
for b := range o[a] {
if o[a][b].Hash == "" {
return false
}
// Then, convert the hash to SRI
cmd2 := exec.Command("nix", "hash", "convert", "--to", "sri", hash, "--hash-algo", "sha256")
out2, err2 := cmd2.Output()
if err2 != nil {
fmt.Printf("%s: Error converting hash to SRI: %v\n", file, err)
if exitErr, ok := err.(*exec.ExitError); ok {
fmt.Printf("%s: Command stderr: %s\n", file, string(exitErr.Stderr))
}
return errors.New("Error fetching file")
}
return true
}
type result struct {
category, language, hash string
}
type Zim struct {
Name string `json:"name"`
Version string `json:"version"`
Hash string `json:"hash"`
z.Hash = strings.TrimSpace(string(out2))
z.dirty = true
fmt.Printf("%s: Successfully convert hash to SRI: %s", file, out2)
return nil
}
func main() {
@@ -125,90 +239,31 @@ func main() {
// Determine the output file path
var outputPath string
if *outputFile != "" {
outputPath = *outputFile
} else {
// Get the directory where updater.go is located
execPath, err := os.Executable()
if err != nil {
// Fallback to current directory if we can't determine executable path
outputPath = "blobs.json"
} else {
dir := filepath.Dir(execPath)
outputPath = filepath.Join(dir, "blobs.json")
}
}
outputPath = *outputFile
fmt.Println("Writing file to ", outputPath)
// Read existing cache if it exists
cached := make(map[string]map[string]Zim)
var blobs Blobs
if data, err := os.ReadFile(outputPath); err == nil {
if err := json.Unmarshal(data, &cached); err != nil {
if err := json.Unmarshal(data, &blobs); err != nil {
fmt.Printf("Warning: could not parse existing cache file: %v\n", err)
} else {
fmt.Printf("Loaded existing cache from %s\n", outputPath)
}
} else {
fmt.Printf("Error reading file: %s", err)
os.Exit(1)
}
blobs.Populate()
output := make(map[string]map[string]Zim)
comms := make(chan result)
pendingHashes := 0
for _, t := range getTypes() {
page := getPage(t)
links := getLinks(page)
for _, lang := range getLanguages() {
if file, err := getName(links, t, lang); err == nil {
if _, ok := output[lang]; !ok {
output[lang] = make(map[string]Zim)
}
// Check if this file already exists in cache with same name
if cachedLang, ok := cached[lang]; ok {
if cachedEntry, ok := cachedLang[t]; ok && cachedEntry.Name == file {
// Reuse cached hash
fmt.Printf("Using cached hash for %s (category: %s, language: %s)\n", file, t, lang)
output[lang][t] = cachedEntry
continue
}
}
// File is new or name has changed, fetch hash
output[lang][t] = Zim{file, ""}
pendingHashes++
go getHash(comms, file, t, lang)
}
}
}
// Only wait for results if we actually spawned goroutines
if pendingHashes > 0 {
hashesReceived := 0
for r := range comms {
if entry, ok := output[r.language][r.category]; ok {
entry.Hash = r.hash
output[r.language][r.category] = entry
}
hashesReceived++
if hashesReceived >= pendingHashes {
close(comms)
break
}
}
}
// Verify all hashes are present
if !outputIsValid(output) {
fmt.Println("Warning: Some hashes are missing from the output")
}
ret, err := json.MarshalIndent(output, "", " ")
ret, err := json.MarshalIndent(&blobs, "", " ")
if err != nil {
fmt.Printf("Error marshaling JSON: %v\n", err)
os.Exit(1)
}
err = os.WriteFile(outputPath, ret, 0644)
err = os.WriteFile(outputPath, []byte(fmt.Sprintf("%s\n", ret)), 0644)
if err != nil {
fmt.Printf("Error writing to file %s: %v\n", outputPath, err)
os.Exit(1)
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+36 -38
View File
@@ -1,39 +1,37 @@
age-encryption.org/v1
-> ssh-ed25519 87huqg tRkWo/tXovX5ukc6DRiC55s28fMJvry4lgSWeGnQXHY
G266810Co/QUFWle5j9W8P2+cfoUmZ5gEKcCNg5jw1A
-> ssh-ed25519 8UnW5Q OqyBBxWRBBpAlS93lZ+TGl2O2NwhS5/ZsMbN/sUiUVI
N6csZzFJUU17JEsLUVRzBhM1at00bu9rUzXE5JAML9Q
-> ssh-ed25519 UFfTmg iuxAyKikNUPm9QJU9O8UYspvWjWe7Te26uzPN6s8yww
VCpWZVtTwHlOC7PXk6xIezNbIMgFObavv1AFinouU40
-> ssh-ed25519 KbVVUw pVU1pSoYn5SiePORWE9bJk+w8pn76xyhFrXi3PQJ0GE
d8Y2dt840M954ZrqRoSeUPDjPLoM4EJwKwu4+5ehddw
-> ssh-ed25519 xNtnoA L8MxfT93s2I42dirqXnf+VRWq26NPuZ6Ta+0vcbwYRs
0RyuZdK1sqCpuMDVpUpJkOs8OGhjz4vojNpmInX4a9o
-> ssh-ed25519 aY2AXA prgbsTVqCxDqX9fB1SwH0Pz3wHNNut2Kd/g2CT3pE1I
12LcMPa0xpx3vtrmNQ0JrJa5PUCcV+jj5s4c4ttRn18
-> ssh-ed25519 AQhf1g Tdph+xLV/TIYMxExaUo+xgqd2Cl5o+BCSEKHWhYpTio
ecuPMlwtgIbBoZ5mucYglIamW8FqeJT4ZXs84CcSaAM
-> ssh-ed25519 mOmPfg pmE+ZERem6G19KtQ339alV0mlSZxOdU0s/NSY9oykzQ
i57l9Oxl4mLYquHwFIsbPtmhyjyH62MereQzNf/vvhg
-> ssh-ed25519 YJiRbw 7Q2ue0YEapF+lK7204mDbRTOxU4BrWC/01umQw0DCCM
+Ulv7yL+02WvDmrtlujCD7zR6V2Npm3WMqvvSyIpOH0
-> ssh-ed25519 Nl/5yA 0FmOQ2WA+qXbhHy6WimadXJKVmgUsRBbOPsgFJ6Qtiw
xhJkG+SSdnYgMWeJk7ciLI9bS+c403p2PqVRObk9ezA
-> ssh-ed25519 GdLgCQ Ovn3zHYbFImNyPz07xjMDYnUCnHpejotNfVyD6olgGc
AfF78TueIj5jnz+q7vrXyu1BZ6VN0hkTpg1LItmnCYw
-> ssh-ed25519 tOH/HQ x9alUL3V2mHyQHt5vPIDBq+TNE0tYkJuP8KYE80VinI
se1kqe3o8bKr1AkgH55NTPMD6ZRkdcLIIZ0YhEVkTq8
-> ssh-ed25519 FpzvfQ W6oRWhWgbZjLrJTkFj9LJWcq3gapz6vRtdSjV4g/yzE
GYh8HSC0mPRGRu7jT7DGx3py0Gvu/zu3BzVdXL8gU1A
-> ssh-ed25519 2UotMw +XsUycMbAALayfAxF/SvkoWv5ubzWp/RvJcD9sWeSAY
j3lHaEJzFk7R48RNbGNzcMs97p12n88L9WjockK1N+g
-> ssh-ed25519 kdPvzQ X06P2aEDkUoSk0KVLZWC9DGyNnVlleeBft1xQPecDnA
6p3jxcHePWO+cf4hnALXxaa5bN8B9AZo+qodDyK/Evc
-> ssh-ed25519 onmXpg +9uXItde+0h/bBcSEwZ57y36bxwwoCWY2SvN1jG7rVM
2VyLiThmzYQeDOk7TaUUslec0qvr7UMSiBTHsEpR6ss
-> ssh-ed25519 CnhD0g feqQLfUYnakAiHJo+gWHrbd5o9WyQ/qluJ7/d/n7PGU
g5l7RvpeBRwnFRKhAED75QC0d6DiGlFho3D5tPumiIY
-> ssh-ed25519 4ep2UA nkc+pDUli0BTe7XoDAJEOLnBDeiekZSv7XVL3POXCTc
iWQSdc2hWP2UvyyISoUBKOhRotPCv2ySsfmoAAOLgFM
--- YRWXRvqVNx+YrIEW8vp0RcJLM/leQUhHD1WKnaEqprA
$f4jAjlÚaôp@™ e¢!(°^˜rˆèJ÷¾%h¼h@37üß1š+'žª´pŸ­œ†ÿbÿó1,¦jÂôA´n£€X¹ð‰¤3jýÈÇ[ìÑW#E\NÑÓÖ}¤
-> ssh-ed25519 8UnW5Q MDrURGpcaqY6DVIURK6dJs7xKCGLtFS8+hH0UCRT7G4
qsqMoWCrssVlJ2kP1cvP9+Fj+c07iFvbFs3Cs+RYVLM
-> ssh-ed25519 UFfTmg lTHOOV5/G7IPaYWqrAwM9Nb75//N9O1wMDFSUtyo1gI
kEWctDmQRHNzxMIwONsZo9EEIc/wkPxqX851BO6ohYo
-> ssh-ed25519 xNtnoA lm6OHoKNa8wB1ML5lA/xl13Xp8WUSF2UY89bP8BZP0E
iPDWUaoViQ7faVkUf2V1MQxrklAw8lJ2KXfJZTYN2X4
-> ssh-ed25519 aY2AXA 4E8FsRsfsEKsLNVvBRTAoxghfex8omAQcy8NKzJ17kw
uzZQp9nVfyVH3dz0UinqZjsZ0Kft7tPVSk1EkE6NvA8
-> ssh-ed25519 AQhf1g rgcA2UeG0s75kSpok9+VR4ixNyZUqD+8ye1TJsMMA3Q
rfM5/54WWHrnG1qfex57tGH97lbvKM+J6TGztYOrU+c
-> ssh-ed25519 r/3ipA 7pNJRvOFO5v2nlMPbXP9oad6jp1pPAsByfiEhdCTAWI
Vh+iyg2P6fvNWyCS+V4087zRf+pCIBj0jsPX0DtPp0c
-> ssh-ed25519 mOmPfg 9WuzH4QasTe0NNcIf+XSremq5GuBZoKP+7t4MJNAFA0
5E1Rbupw8IUnTuicTubXWmwkJ2xVg5K4BpkZCsUj5UU
-> ssh-ed25519 YJiRbw msPFM69Tuy/luxASGVA8ey77vqtvXNy7ytf2VxQWNi8
oD5vRs439A/YT5FxkSltl1Qf56NNhiKt17++vlFvwPA
-> ssh-ed25519 Nl/5yA C3zn641k6eFQePbp2q7dwlIu7Iiw2aU5dmSrH2HCai4
v1/XJRKIrIgHWfFtSDaFCvOKtcIR84abUZHPjaxP5bw
-> ssh-ed25519 GdLgCQ ZztOWiw1ao1pvJ9REB/wBuxq00uyO+JAkIWjLUMueSc
zXSv3MauG2E2el+Yv5oocTgDQjQ1fKXLpm6y2OTyIvw
-> ssh-ed25519 tOH/HQ /eEgAf2KH1Zgd4yQf+kzyESkvPI8GKJC0MAJl+8+WD4
H35T+ulGSCrWAuIsZs8ISRJRj2wqpRrOGlaoq9fnN5o
-> ssh-ed25519 FpzvfQ dRq/NtT/TxJ/k9WlaMl/PrLTvPzkhV8LpF/LxjqjGmM
LJN8xxnNF3EcMmXKdLhc70b2Y6n9qS3A5wdFXY6hUjw
-> ssh-ed25519 2UotMw I+kJsu4GAflSfMjzE/8+vp6AZb88OpiCREuxfAnQPis
hRu7IbLMdc3U+NQo1PDhc+O9uyd/wJZyPtfTv9z9TvI
-> ssh-ed25519 kdPvzQ uOLSQFzsGSNg1HsiJLCYi2Lp8pasc7H/jhUBlf6b0zg
KbUOl2WOsc6VuAC33SjEJS3tM3o82A3QO0bA9wd0rbA
-> ssh-ed25519 onmXpg NKdAvcN3TStWYtQeLW1oEn7+shQuuNBndHaQRAU4f1o
vCuDnPc3tayIwDbHJneLQNoENyfA6GRpQi6+OZ34Jjc
-> ssh-ed25519 CnhD0g Co6fy3fm8BUi2qn+xBY1X33N2m40jEM7CJhSQcLokR0
kwrOzTRiVe1aQH/P+ua3xZNgNRZh2pfQrQl2k2Y727Q
-> ssh-ed25519 4ep2UA /f1HxU62FqhDJyJ9fPMKiqJdw1m/UjASKuYhY5Aq8D8
tckIOvPq3Qid9Z5ud2v9syaed/h+3GrackXKZonDYEg
--- FHj/yA6RDV1VYPsi84z5Y3NrbfVUthwdtuRWqiKC57Q
Õ=Â7T÷Ü`6¦K./ ¾¿àO Ö¼‰R•Pá€K…2NYqWÖ¹£®ê0v{±µi'¢žÖVûÆ!+‘|ÎÕ0¿ŽšÆ¼ú´Ìi ½†Ä?QŽq¢2Ô5ÖÀéŽ gÜ/c_
+37 -39
View File
@@ -1,40 +1,38 @@
age-encryption.org/v1
-> ssh-ed25519 87huqg 42tvGwJ82PwlXbr+TqSz08omHABPqv1TH5plKNLLvkY
4Xwl0lc+zSL4k1PuIO9qF1Ci8mOOWciq5yGbbqW6nLE
-> ssh-ed25519 8UnW5Q gGcbBcV2tF2UaaYBvM/jiNH8Lc9Fl62NZIWSbNVZeX8
1TLxRM4e4/T/q/8Bdx/W3Sg5eeq3g6aUcka2kizF1O0
-> ssh-ed25519 UFfTmg oNyxvAIg2hYEJ6Z3r9MzuR5YgPW432T03/mcjLeLOgs
NZOFUzuaaxwGbQDkDinSzjbFPrFETbQOEJwrgyYtKpY
-> ssh-ed25519 KbVVUw annu9kT2zbKvaE3WwGtDGhvku/Pj8a4P5GEQLhahZiE
RKg/owcXYN5pqsDxjlaNPg6um/7/eoXxZ5oJxxouxjE
-> ssh-ed25519 xNtnoA tN13P6fRYHjVTmXo7w6y/ljzr/8nEqrlgZXpG5jA218
wg4SUSCWqE3iskGPE9qJ5Ot68pcvwCi9fmE5NXZqYCI
-> ssh-ed25519 aY2AXA VdvvL8lgjZBhflonEI96VSFgYaUX3Tfvjo148BA+Uks
ZljFDZ61GKr24lWG8z8sKke1TpTCiSeqyd05yxNFTVo
-> ssh-ed25519 AQhf1g jKvD41VnPGoCBEva5llD2NQo42TDnpp9M28BTBewuR8
TSBZqNLhG/PyToBnX2kwevA35QKmKcjwcPe8/JUcywM
-> ssh-ed25519 mOmPfg /yX7XUVozu8ZTCW9gJyoGd7EzBISb0c+i08HEsN7ODw
e1rAICTZajIF0AaWXBATDNuqQK4GAqxEjgxvaRzDark
-> ssh-ed25519 YJiRbw cy9m8KQln8ryxLEqx1tIoZRq4SiABQFT5IzmMlgkQjA
P4OLv+oTFhgnLzb4YrhFdV6jreAGhXBkMCe7pb31KTw
-> ssh-ed25519 Nl/5yA Nx8mErRdN8sIaj8ueWnDkSw5vBhfkOW5Rk2ND3gwZmY
6elVFcWQnwmh7NvRm17+WahOkvLmQbqBBKnruHT3yp0
-> ssh-ed25519 GdLgCQ WwKSzJsPG8vJjRjc+nkyvGKtqLvpKe3V158fRezWtzk
mKdk9Z2wOipmc6brgNWeIbxADdkkXAFcs8E956RdHTs
-> ssh-ed25519 tOH/HQ /CL2OxE6C8ZCfHgHTQQJmuACG5lZ8AdVpDe1YfG9mHw
7uaalUdP5vCjsLEYdp+LREaxU3Vo0VUCVXn/H0WAa4I
-> ssh-ed25519 FpzvfQ hE8FGN82H81RWUm+LgCuvQMWra0ulwMHuGSYTdQvc10
Eq/btSgef+2nkQGreBhqRKAt/6CFo5ahdRbBfCO5Bv8
-> ssh-ed25519 2UotMw mqdgTsPI9vockRACf/NdD466WkIyQvSLuEJSrT5mDwo
hyZQCiUCu8gfVTCZ8wMxo+i+CqjhE9t+hdJrJcm1dNs
-> ssh-ed25519 kdPvzQ fO2iL5QnWBxRFe88W488dkezFsMxJtMBc5GKACOZYjk
NPa4r9t7lPt3mMgHjT6soAK/RWLUe70Lh5i7LwRYlgE
-> ssh-ed25519 onmXpg 9N98xltPTCAb42chNAOb4hYr7equq0lk9nTqol3EKXU
tdQ7FSABTifm9sHKzOVFyoEbOjS9TYS7DPsFrBqmnLo
-> ssh-ed25519 CnhD0g 1oi9mdmL6ODCgi3pWGKEqU/QN/v41XQg7nUZiu5frWw
zXOUj1z6Z6DKyWr2ZqyFFZGNwKkz3NdyEUqWpnl1xI0
-> ssh-ed25519 4ep2UA RKc7+piJY2Fh4NnZGvEuAzJIMxr9NBQQBSMj3xQqrSc
yqLK6nR4b46QPwnH9DuZ5spzIu8fQMAxmLYNtj5jAu4
--- R87vMnH5oLHLJgD7rCGZwz6dpc/a0kpm/fi28jqVcT8
\_UvF9‘ˆ±gøË2Ä®Ôbá/0=íOÙµò´``lú©žµ^2&…àâWëñº‰W§¼
Pc,™häZO'kÒ2f'hB©ºp>¯l\M§¤;‰òouFü ë…œ¥X)P!hÂRo]¬Ø† Ù/{—¶6Ä•÷ƒt»¢¶Á<Þ$6tá[6ÑüAéaó7œÙ–òúhiç«d´Y-jëº »_ý)£“Ò‘b˜˜ƒpÉ ªÙ9Hå»\HBÂ6dß(}ˆ…~¨¦íåèq¡x5P{x…@ü°GE0x&0ðYÐÆgó¤¿4•—±z‡•n•! Ù¿ªðòˆÍÐ{ú9
-> ssh-ed25519 8UnW5Q 5p80c2oBsZh9KTXU+ZT2AKbbEMOKxlAouHew8KU8kns
ZvUnyZjn/HYmxHBth7ognoHB9zsUe43Y6c084D4xdHc
-> ssh-ed25519 UFfTmg 9ol6Gp3stU0jwPzkr9CcLLYftYTr614jBfba226E7xU
i7CZagRKOmUn2uVmzyuCJQdbtAJoDbJZxpMNDtrH7/M
-> ssh-ed25519 xNtnoA QZ/CQO4j7T5qC4ohLMEt0i1B8cuMGYgWOAwj6HSPDVs
Nh30qP0yZcAw2azpFA+Pi6746+kmM5D0fZUYL1uTzmU
-> ssh-ed25519 aY2AXA C+1SvOQKdrTk3UNOLdiHrK8e88BBztlMqE3Cofm6ZUI
F26HpuL7HY2nsC72KDgZMbfQ9Hbmvcr/nms/d8cCjro
-> ssh-ed25519 AQhf1g ZWLSoDJiiQswh4GyhL4P82X03SNSRnDPmZk3w5nyakU
r6k53tUfB/J6WJuGSmU23frSkcw3jpe76d6vlIfPXcw
-> ssh-ed25519 r/3ipA cH7gfgcgS8oRx/GKlolPIQ5WzbP+i+xGHfzjqCQ7NwI
Tv8lSRcUitEx3oWa8hT330K8DYt+PWR2mHetY1rzCPE
-> ssh-ed25519 mOmPfg sfr1m6QIkqpHLeunlYCc9LjVPC0XqXnH9z75IoSRgCs
heS/IaQwkt2IQRNcKeNfsAzKGGLEdiUzQxdPll4CRt8
-> ssh-ed25519 YJiRbw 9oF0E5s2LCHrjFozDq6GbYH8UkzSaPH/4ore75bwe24
8PHPtU/fDDFkcEPXHAyrp7LBDHwRtTX/u29+jJCzsXQ
-> ssh-ed25519 Nl/5yA 3xAZWLQ27UtB3kZiEbIBPlkO99ZsAD6k0oOTmXODLT4
ia6BrKBYSe3BM728ysyBfSjwtQoev/NrTq+Bnp+z7hM
-> ssh-ed25519 GdLgCQ otupOJf1nJV+w4BlivVEer7x4C1aEU8zIMLmLSlPiyM
BHv9OTNsxkYBlA2sI3x3cEXjr7GSyVlaQZIGBSua4+s
-> ssh-ed25519 tOH/HQ UnszNH3sEPqlpEuhJTzYG/gwBE7e4/P2VVRkroceZD0
L9HBZkhn3zbOIhrkBo3ezvp/Qv8Lc/BzS57npaH+nwQ
-> ssh-ed25519 FpzvfQ S8QZlLoN2FVpAajpsOqaEPHZGfXAr/k4ZXY8PKEiA28
hJsIvLf77JG87Gqe0dDq16dsSKSlJZZPGbYrWv1oBlU
-> ssh-ed25519 2UotMw kRIdExrBlEQToh6itvMGel7UIVDTEIVqb159d1CWmAI
Bkse9A2smfngBC5WmDmes3ALMvoxeZw3ypvVBxWjWcY
-> ssh-ed25519 kdPvzQ 4O3g6LMdWv6OiBP5mjZtWa6ERd4s3d1mawlW3ZjajjI
HqzRVYB5Vko0x2rK1d6DHcAQdla3gsTSyTXcZNeP2c4
-> ssh-ed25519 onmXpg grxgbmSfJvZ4lNpBOEsVUVnRXNmXe8GybiTg4BhzWBc
po3Ka11xxQobByCWHvzj4z2MT7AYtoUEvHPkdlVcyPw
-> ssh-ed25519 CnhD0g hwhHSq2AFrZelQtkfegSSLXbUVAERTH6yoiehI+xbHE
sGBl0wu73Refzt/k2iM5BFw5rhFiXV+PKO6L4PrDsJE
-> ssh-ed25519 4ep2UA aNkohdDISDwG6Tuqq9IStUqwIgC0gueGAiCh+gyDsl4
Kl0AQrVRSfvR8X1zT4ws2paVuZdb+xI4BYFJFMbYmDg
--- jS9nG8Wyoh+2f66Ew/ebH5LYRt73NIi+WnEJLHAoyTA
¥¯fŸ
ä(r¶OîŠërv,¸w\Rx¶ €§ÂÞ¶Ü¢ÚÇrq9Γ’uŒK•j1ÂàSÚa@“¾|pÔ‰Ãy»ª«³Ga¦ƒúfJÆEDޝ•]å, ÉjÎL¿äì¼v3Œ<y(õÛûiH›™x=‡ ú:“‰/Õ`üëÏ™h{¦ñÑN Á\·Í8ЇiJóêvaT…‹÷ÊÏ'¤4xÁÖ*áÏ+¹À=6{ˆŽùOÝKEØ' ýøÈ=Q¦!ÿÊI#.˜{yÚIrà´èêf/ÝwWª—âꎿè%ÊT£ÿ9x…#n ²:MhÏèÅ–µ~3G=¼øF=;9o,ó
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+37 -38
View File
@@ -1,39 +1,38 @@
age-encryption.org/v1
-> ssh-ed25519 87huqg dA1cGGZS6hZzglVHlyxZA6HAGBtZfXYHedZLebiJuxk
9jOUxFha5O0lOo/p09thxSrGBeABTiAtc9caKRCXvSs
-> ssh-ed25519 8UnW5Q sT/26ON89MZLDFoMec531z4jvN4zcwtocwKpsy1agm8
5lm9F/vDdN0do3Q02VYofWbXVv3v+POcVKe6hQBg4oM
-> ssh-ed25519 UFfTmg mBEIRRxLahorqsYdWRfLKG3Atb0+ks3UPTLZbN/p9Qs
DMGHYSpSQG+rhg0wB0MUJBVARCcu3fIPodQxEO/glXY
-> ssh-ed25519 KbVVUw Pbn4kkRR1xiVeGlHqNR3oHCpqVpftztRyyTRI7jbQDs
4Ep3S6WUDXipUdmxuWdZJGy20HWR8MeJ0qG92dkVqRo
-> ssh-ed25519 xNtnoA tqndUQdkCW7dc/tCVRNwC1953WC8/25J+CuNz7iFXy0
jkiSMT9RSIkhyypkhMtKMDAaZcEOfuOs8PN+Fm5RJho
-> ssh-ed25519 aY2AXA 8c4P/cE9ISbxW1h8j9eMSJ1+Y8mId5AMj6KVW90bHTc
Mn7nW8NRF+a/6d+Lv4RlxEkyH4GZnQjo+IrZQpjPscw
-> ssh-ed25519 AQhf1g yGuKYOPodxketnWOUwwsec93545XHR77DdBcSt0nQh4
78/c4+H8hGJFBkG+jHfL20W2rUSO6QeWR1s1YG9rEUE
-> ssh-ed25519 mOmPfg U+17chXPF1QtSBBS7KIZS2ye63ZnKd55CLspwRmVSig
nje/FT7zkwDr9/gEzyd5oFBpZ4XmmPbJq0u24eUhHeY
-> ssh-ed25519 YJiRbw z1WWdaDEbV46mo1s7c5COi8nsse9G7kZP82+ON8WznM
1sj1t9sM//HcTdaDJDG+sIz55jJ995qVtuE5v83q37M
-> ssh-ed25519 Nl/5yA kZzDe+hZVtexOK2cWp+xC+avuzOTVhw++MkfdQ/1wjY
XMfktagqBs1UE4iVPPx2rM3SnPns27m4KtqldWVFj+A
-> ssh-ed25519 GdLgCQ CDa6LXTJhViLliv5wOTxlh1bKVVdhW08cSFggxQAdA4
YzaJCQw5Bnh2buHVTFLCmgQ2+xta5BHvR08gwOxE4Lc
-> ssh-ed25519 tOH/HQ 4YF1ffsWDtKw/7A17kmFOVukG9K5jGL3gzVye0FzZ3c
BODYure5YmXASU5XhlfeksA4VqsKaKNp6Q0laeJ3z8s
-> ssh-ed25519 FpzvfQ H+dvG6G/fEDsLqHoHW4G8c0RSPooRhRgWUzL+5igAkM
BFe1mOGLLURn0I0LHjw4Zue+3s6Ta+GA9vCj+ZNSGpM
-> ssh-ed25519 2UotMw lSaXW+ve24TZnJf0RXdLEJ4FfGiYNZ67LqfkrUWo8Cw
45ZTeg1Y1P/DOa/yAbtrTLwNA897X9iuN3ZP/q0/rM0
-> ssh-ed25519 kdPvzQ XVaKM5korb9tfFDIYs4ueREKcw8U3VGRonwp/QmLK2E
RacYxiFK1vhTbJyfm0ffHxAq+JGFa9A5WtHWQ4iOEKg
-> ssh-ed25519 onmXpg apxJc3hLsgsudKiXwvXE59FDMW9H8qXtlRcdhqVvzxo
5RYr4G2YSLLSQKpgaB3g1HkcD7Xv+1Q2XKRp4SGKv5c
-> ssh-ed25519 CnhD0g iiUwUS6wpQTXCL0qR2nUzkuG9bytZoQGI+0Xhq5O/VE
OLhhRnnAJATapn2WGr9UepY62D6DjCaoprZqMAiisBs
-> ssh-ed25519 4ep2UA WOSiDKxTlL97otLBmox6lvMabltrvUy8IqNsNQOCDAA
4CY2Gq4E7iLbeqMup8mQEdOiOEbE9mWHNtwsaOOFWj0
--- ULVOLUkx4Hzk0DLOpFgD3ypoU+vv90TnWTIaPNWxyUk
˜iTSBý¥#õÛO×·Q¨Ödzia¸ÏjƒX ‡[dù†z¤å¢>AáúŽ*Ocîß…P°AErÐs“ø³YeföÛãœÌïÉÑù
-> ssh-ed25519 8UnW5Q FRrvjiuNlnu4/DkwfY2K5p3MdQ5bDF3+u+JKrYiHzGw
9dGLw4PT4OapoTW2GnoJ85GEWgO3Aepj7hl0LpPZylk
-> ssh-ed25519 UFfTmg uMTPiCPPoVqt/3SOr+y5oKGTxpFq2UNGrwaRVmnZT1Q
Rn7dRYCGZwYN7sCmAsne6kAuKmD6CFlGXR130ELiJCA
-> ssh-ed25519 xNtnoA FW0dLFehc2yVvpxIDEcVWD1zHspZuvwrn2qgYltdp1Y
1zYm+LF/8lvfEhQVr4cbyDF5CfhPu/fNBYZMQLtTrqw
-> ssh-ed25519 aY2AXA aNRD8OIqKluKhHQZCGkW+kS71vlU2N8K6k590eLO7HM
PZHX6fqbX0U+55MtJ2iSur7TSHFEgQBiAgpXiGlHbuU
-> ssh-ed25519 AQhf1g cIhfdle1UsPx86LETXhB46evMenWtypO4GmL2/oLbXs
ezwVMUSz5KbBymwnZlKuLD7RbNBJigfkb4sOpHAAnBk
-> ssh-ed25519 r/3ipA Gt94r1I1CUMKrGQKBVgq/FLlOa7V3weD6N1rv/dVIV0
UsBIZfHiU17IjzhcKc1kvSEIMIk7I/DizSdBGhXNwqA
-> ssh-ed25519 mOmPfg b3/Gwqh1kik/AuBzcpqsuSuFcK0Pko3hRu32wFB/yks
X9AXKVJ3d0IV7wkV2ZibScIV9En9uJNyUIPIk7WFKb0
-> ssh-ed25519 YJiRbw yDkwCFtGXgS18DwqMCBied8+Jt8u2GBWuFQSrajij1s
eSeFTNbeOT/tDb9iQo/YzThtQeMgNYmEK61o8hjG43k
-> ssh-ed25519 Nl/5yA ee68eLzrRi35az65YmfA/WF9VliRmnlPEbGQAet91nw
2KdTnyBTyJu8q03eH5s4oRyvhTQ6f/qvwrLabvk3C3o
-> ssh-ed25519 GdLgCQ DAlJqI0uIBSrFpPMfl4FkrpjCO5qkzvJU/PBOWFh+XQ
S5tkvMrTrYbOK3U3wWxLn3MuJTfrP8vUIYe6nBpixQo
-> ssh-ed25519 tOH/HQ zQMhFkG/vkqosDn3VvzuKt4xagkUWoqE/DW6AsYtBGE
MGQA/Jxv/YTny5CyqfQBorfwIUVPZFf/hAcUTFrX9vk
-> ssh-ed25519 FpzvfQ d4cgnsFfo5xGDUFyT65HJ6S6vtzLmvB0eugwq6t0nGg
0hEFjipS1Jbp6xycUsZYHzcjQVJ22JlGMUsjPCkDfbI
-> ssh-ed25519 2UotMw C8ukSysPTKrwKCVnqjBzspXLLyJyhn2YCHcr1n0ulRg
NErsgu49C3ElHmpsz4q+zR/0Oj+9jBPnC0BErB/48Fc
-> ssh-ed25519 kdPvzQ oreOkf0nFgkgm5KuEjP28nbbqRZTA/b+bj7SSBmAslc
OrQ99MlWePEk5IVeoC/X4UYLhK10oTLFrS4KqzoVOE0
-> ssh-ed25519 onmXpg v8MQUHZj5sSu2XqiUH+8wcvEJmrGWQqs0e9evQKkzHw
ffZTIoH8stR+ZLhoz8GjvGG61xVbv4+VkHbd25Jyc/w
-> ssh-ed25519 CnhD0g Ja9KftQBH93zJAl8nOMQZXHbXIFIs9W4UqXwYr9gdDI
StRE03gMP6QQ+fCuhE1Q5ptCpBrUxrWINgCrWzwSqxo
-> ssh-ed25519 4ep2UA fbcuNM4FWkTOVSNSJGAwncdkjLN1K2Uv3dxFsnC60VU
uVbHhoO/IXfakiYFJ4yrtReK9uvYLsj4BTILRBqbRgk
--- dYPR49CT7omcJ7jDRNUAoc4t7az/pEg00aqPF00OlA4
„Ï¿Ÿ ðç(C›Ø
I'ð^¿mc¶bßH…¹«CûK␍0ýĉwé¯;lú¿P<üH㛬õI¿{àÈ|øª·ý Páy(Oì«81åÐß
+36 -38
View File
@@ -1,39 +1,37 @@
age-encryption.org/v1
-> ssh-ed25519 87huqg wEnsPg/GBsOZp/g5+Wt5U86tA3LCSuuvqK3YKU22wgg
8H1eScTy08OWQ3Wm70UwpXkxQEJV//DDnKXO1Tsy3x8
-> ssh-ed25519 8UnW5Q 9McAlT3KjxwW4uA8JLW/IZ95NtyU8MB5XSzwJi00D08
jsJkSSVLMAhBrTSyjKg7q+ez6PnKdYP0GIOTG+BX6q8
-> ssh-ed25519 UFfTmg HxnyFdoHZMYBD+RZqTCGnzVv0y6KlHdvV5obWrzzzkc
l9LCV/K18AwxfNIaMDc3ES7TZgHzBpMwPaHY6Mpwxtc
-> ssh-ed25519 KbVVUw cZ7aPpgdgNGg7tAmV8efvkMgVDUIyqZjc/WQMkv52Bg
td9LF8Pp4dhz8coW/DWBdBgRkM6+FGbHzCqvrdbm9nE
-> ssh-ed25519 xNtnoA 2Gvn1fR8ufGGBkl8u8WdIb1Lo/UxkKkUXwEzmKK/VSU
s/4U7eALr0f8Yqk5SN5O2z0eZz8PslFZ7ikbmngvSX8
-> ssh-ed25519 aY2AXA e6nGnQE0/UTqUX12blfWq4CpNe/QkEMnztWQHyHuxjc
OdUQMd5+x/x6NAs0nbtr9pM7q+nF8ZybZBJD7mNNcg0
-> ssh-ed25519 AQhf1g qvmETHVucAF76fq+UkRyoK0Kw+nYVu18jn12ragg1T0
XEhKDlikdstmSSZOKs1Zhkm2XhtW19F4k+H+cKIvjzM
-> ssh-ed25519 mOmPfg Qb/Yfy6jl10V0wTr/61/GbbYhkBciOx1ryYvzyTBpRo
kHMnWdDA02C7rAyJ11JMbmJaCjKkj1fBXZqJdGES+IY
-> ssh-ed25519 YJiRbw m58K4+oJ8ike/v8bhpGveQF6UxEBTuqjiM5UpRZUpV8
Cq1BpdnViOmd0JwdZf2gBB2vpcafm54FIaZWOhviP6s
-> ssh-ed25519 Nl/5yA tNzmgsTG7d5xRhX6j5iwEnxtLYz8gJQmMWzBSOqaxwQ
WuYPgCAxhsHvXKty0dncAl9ejqF1b9ZHSFqtmOEDQAU
-> ssh-ed25519 GdLgCQ gyuGdMzsShKl1TPOt6IrJYJ383CCK33+BXo3sELKvkc
m02EYJ47DcH5wK+eDcvs5yyTwsH6cT8rWbf1BoGemQ8
-> ssh-ed25519 tOH/HQ EpuIe55eq9FvBnygY1gn9o+MSU0AjxDHeIPwqGWAkDQ
pypq4SL/0311MvwkilKPAI9Ho1gvOjsohnDwe4pDKPQ
-> ssh-ed25519 FpzvfQ EY3I/fZxRn9qxZz5KmXjf5MDfXt9lhMmsj9ZW3nTdBE
ktSKonkZwKcC7zvkddr8B0bg4M4pkeuukKOuZz9YauU
-> ssh-ed25519 2UotMw P+I74r2Z6TKpTehCrstz8bvG2sWPDmcKLYOwS20Smgo
zOGqtVouwCOiMi/D+XjitWtQGdRrfrJw3cYU5v30Kb4
-> ssh-ed25519 kdPvzQ JdHJ0HiJUO7h+fx86QJQvlwoLWjr1SWLll+sBHfmmic
tQQ+MEKgwYl/Ms76B1cPl8AA2HlrXqbF4cLmBdHBbck
-> ssh-ed25519 onmXpg KXbZQecpbZQLB/4slZl3hqOXldgyqHADIy6OkdnHbTA
GltoWSI3qht8w6Bb90K27qJdW/fB5GflCLQlnu9ffkc
-> ssh-ed25519 CnhD0g wpoGeyLxBfk8tJkJSwWnFXhFLXrU4ezFaxWGVrnPIgI
RVAJ8njeIBbQtHNM0hslbD8ft9VuRlqcSyyKRN9cxjA
-> ssh-ed25519 4ep2UA Ydu1eNy1WiHw8bRwMQc29UsN6l0Kvs0MknyeNnDx4z0
RjvAAe5nOkCHrZXn0u94NA7jWcNC9xAu9aly9tQC0q4
--- ZVJux6CJ52ghYaSl16+PH5uUQqk0T+VkMVDOHO7HKMI
¸ÐŽÕ%T–7]õ3¢¼D¼î·V!#NUžî~¸2·Ãc1duÁ6,¾Ÿ¿QDDDŸ{ß'êÉÕlý¯ïñx÷%JÏ +kõyiÝa
-> ssh-ed25519 8UnW5Q mCwgPdwCWzi8QXME7vc1nncnCjUdhXJfHgz5CI2ppWI
rnBpIQ9WYgFs65Rh4eMICoesrg76o46AjmtY9fTbCl4
-> ssh-ed25519 UFfTmg EW1P9WRcH6esoNH098Vj4E+udGzKWYw+HkxaHcRpF3M
t3AsT1kOCeDbpYotmYAFQA5/k0NA9KJ+R1DRnbLX63c
-> ssh-ed25519 xNtnoA shOVkNxHyvKcLRYAAIW1C6UPAGiwxZl0Y7i73DkA3j0
MgFo9Gy+24rWvIkqQKDogakf4q1nE+MTdmXg2nYMNR0
-> ssh-ed25519 aY2AXA dXi7BYpOVSGbbxI5KOQkElq0GQj3vmbU8AA9rzqGIE0
GlpXrUk11XX6zirXrTK3uIhLBwlTKwn4/cyCWjPBVTE
-> ssh-ed25519 AQhf1g qV41Qx3onxW0Z91xCiUwse51OoEU7tBAi9t6MrwF8Fw
rFXGO8JG1HE916LMS8xMLACVqHuQzP/SAgM5Ngi9tLQ
-> ssh-ed25519 r/3ipA u1cHvRRt6JrScsmCY6PtybjU80VuU7NuRwtBW+Omc28
ztXCVbWHTMBY/x6dDdSSPQmTWfLCGNG7xkYBtupKRQ0
-> ssh-ed25519 mOmPfg jCT547k33Dxx8nTS/WVe+Peo1eViKVSjLumucXempBc
X2SCtafedtleUTQoYtKN/85uUnWS3kuY9Bb90xHXXBM
-> ssh-ed25519 YJiRbw j16MQ20JnMktKiREpNRx5qed8jXXKCAq+8b5AvkW0gM
KovMsW55OvGyjSJuAN5M0Ga7ln0TOQoQEQKvCkODJJs
-> ssh-ed25519 Nl/5yA oYGAT0greb0CHjptVKt1vPBhBX1KXsJAVlU4WoV0vjo
SI4ZXY4pHqYEn2AKEX7MpcYT71LsVUGiZQd0LmwGywY
-> ssh-ed25519 GdLgCQ rEB3gHJ+MovVDQsQd3X4pGI03itwoUGeHg7aCQ9oUms
mAVXvwQqslqP4sm7uG9LXfNvD0XtnaB5W37esGyRsgU
-> ssh-ed25519 tOH/HQ XPExYlY9j8DKCZwviAAgSvJ2+xpx3lUBsktfMPwo8U4
v2PV6wtTTQINJ2XfCcA/0OpNkOHr4AER3lG73CJL7J8
-> ssh-ed25519 FpzvfQ RRpPZ5GIdzvRimAXe1ybhxs+lV+SSigyyvEn3qmkOUg
z7QV/M3zO3tnOO3XiabL62w7Uphs9OxARpGbND1tm1I
-> ssh-ed25519 2UotMw JfTnR9wed+1B9Hung4FdV3Zvx8eQ+lrweFiFrhX8B2g
k2KYxpsSoTBaHuXCCl5fBgn/jyi4KDKvg2QShU0Awpc
-> ssh-ed25519 kdPvzQ GrUGPXTVNTMafGGfn2xA5pTIBEnEfSKmDtQ+W/QYpUU
eDNGzwGWhnZ2kLXzDLVWJNvl6F6vZBTFZ16zrh87bxY
-> ssh-ed25519 onmXpg LiArSCT2VCCbEE02Q9n6fsWP1VtYL7OcahnM7CJyywU
LUKTMk2IAFpg7mPpHjBBw8NbpbgpDGnH9FCvjuF9qBw
-> ssh-ed25519 CnhD0g H2M/9h954AS4ROeJFDfOpwU2DsACwQ/20OdGVaeGxxE
tSMsZUT079DdPhW1yvFbk4DBlNd6Lvhk4SAarFjYfpY
-> ssh-ed25519 4ep2UA /FZ8+q7M90Iug7/qUkpmyL3uhUz2WTBSoc2O719JhBs
y0dpaERxrnygXbDhp6v/rIZsoKx7kv/aQI667jt+/t8
--- K04yLmYsJIXBing2v+tijM5K1vOLQy0hWu7TItk3xCM
‡t Hëw’÷ìgn$c\ÑØG >T¤b Ã,z¿ì|~u§Dhs±KP©íÜ0c‹ªŒ–÷ÙþÔ{™­w`ZªPODmüxOägƒ+FäCH
Binary file not shown.
Binary file not shown.
+38 -38
View File
@@ -1,39 +1,39 @@
age-encryption.org/v1
-> ssh-ed25519 87huqg Mee69P2bZ8khxGigG1Vl7emFQo/VzNHWtFIhDWGseCA
VLqtbTpir8TdVMxPeEx087c3joM84Mt8A+UTJxsRzp8
-> ssh-ed25519 8UnW5Q eAb4LVWqqgoIyQKoC78/ZnZx8aj5HH0ti9rO5B+UA1s
HVjKBLYj66fyfeq7wMNEZl61Lx2l3/d3/2+1sv9yLCc
-> ssh-ed25519 UFfTmg +xgy7TGSaxi5djSwYavqocqGdYpkmivs3JmE6MqsQSA
6Mn3jdSQPap//l6mAS9NBmvNQPmLPb+SbQtlWvwN3mI
-> ssh-ed25519 KbVVUw FfuBVEGAjQUdvkUKzktLOt3uQjsMyoVFTTrQprtpVSs
aolel9YqAYvFuQqe21l0Argp3KUPrlhxBjIn8KjGHq8
-> ssh-ed25519 xNtnoA kn7ZO/8ODnFJU6QazOVvOiwYWJYU+t1t9JQa9Nsifw0
0DBsts1m+FeyVtO4ygSZnphMj0o758wDFiX3DKnHVH0
-> ssh-ed25519 aY2AXA vuMeVWDvHPc13tNyDJq1IQnVXEgmWkGpj5JMMQcyljU
6ZWisLYylYryvYq062ve3YgboX5Zpb4VbJw1kiHXbi0
-> ssh-ed25519 AQhf1g kYsUrTF8sTTcTCz1Z3f2zWdp3FmFgaF71rY/uDxxDWw
4GQKIVIS/Qdi8PhH+RjHDQAQIJs68a8o/txGaSA1EEI
-> ssh-ed25519 mOmPfg qyNnz4x8l0RyVYZ1I+Xby6H4qpghX2rIC+OC2+q0AWY
he0iGH843fs+93tsMF/mU/oDMjxe8os6NxI7jdBrvGc
-> ssh-ed25519 YJiRbw TvHApjsVbTUUD+Xxdbb2OZXkpN8T1S7SFgR66GLr3lc
73dXSGSh4Tonajg/Ux+TQo/CSdWm8NfoWpmuCT1nQ4A
-> ssh-ed25519 Nl/5yA K3Qwv+HpwSzrt3L0wGOm8UnLST22gYtkNcmva1i1sAY
HFTnVYDdyFaCeuxadpRhRhvVzlJf0QJkzTSH6OBx3V4
-> ssh-ed25519 GdLgCQ K+6xSzErhvyDiEIWSH0LwCMRymyRp8qxxL6KZg1mtyk
daIC/jUY8etaJzKTk3ZyGaGFzmc1alo7avDtHkdAQ78
-> ssh-ed25519 tOH/HQ 8ovAhEqzIreGrBlOmwxH1s2W/ZJNk5alJWbP5XagF0A
j39E5SWyMGOtT/K2IKUJ1UNkcUhghdhtUXtoYiEssho
-> ssh-ed25519 FpzvfQ uxdXTR4oXg/IzujvLmRceFzGHmTp6OjF0zjLboqA5iw
JH3aYGksptbasR5695/5unh4k2NFNMPwUTEAwKlTnSs
-> ssh-ed25519 2UotMw 7ZaLT8Uh18XMPUKBk6KXqYpndQR0/YiwGjuw9YcyaXY
fVRD9iLC9Cof5Tw2luQLMPiCiqqhs7w9lsQqL9puxVs
-> ssh-ed25519 kdPvzQ q1O+1RqZmV1W/28K/JlkUzs+G5brmi59gwS6CRPkN10
KKiNVbg0FDiKdsV1HQ7BHdgNU52y/Qhnu87O9D0lntM
-> ssh-ed25519 onmXpg BUKYeyaXQjpVw6L/wiY7OuJMfyhFnW4S98nNofqVsXo
dMWTebeJi5azBo/RInB/XSF8BNElBlK0gH7qLBNmI6s
-> ssh-ed25519 CnhD0g 7cWyBDXml7SMfBaDb4MKMgrdgrzl38EGZi6ZGX8msS4
CI1eUlcgo60xIc5e2CIlTsWDWG4GINmvXcDCd4MoMnE
-> ssh-ed25519 4ep2UA i7ev8lkp+O9nNHb8f06QWNjM71UUWQMZVbKHXZLt4mo
BwZ9ouzTIm45LR+O7KySmsCbUIxwcDkRawBMyjlT0do
--- v8KgdgIDf+1iLNG08ZPZx9A0dz7JGbZrdpBW+lQaS6w
Œ#O5°ÚË\¼KÏ´m~•˜§>[ŒÂsp±×ÊT™ßÏd»EOOԦюMR¶CöÖ×yá¹6¢G€ÀÏ~¾^^yoyD«+µÓ[•Ë+ô␍E“™p†Ý!¶‹WnÆyœV»7™
-> ssh-ed25519 8UnW5Q AvtCfDMZZ51gAeWxQlfxp+AEZDM/54vKlH96kU+sgn8
IE9cWU99bJ8RJd/q1NCLwvjBozHsKNVLLxj4vX+f1nI
-> ssh-ed25519 UFfTmg jN40d8++rmq4aJ2MY7Mb2zrj4gWV67GqHjv29QRNxjs
jJJx3pTDSQ/0QescNSbnWmI4aJx/mvqXg7YJeYY384o
-> ssh-ed25519 xNtnoA MJrW1Ti4mAhq3b490wLp61PTe4IhEPokfeMxSek/7QY
AdgEkxhMRWcswzmLFzbbIKPW4a40Vlrct+ivvNGYhW0
-> ssh-ed25519 aY2AXA 5is/WyAjC4/oqlDIxAwq/Eaw6ZV9NLtQGFnBqWBm+mo
gadDw+GbSmtYxI7DZUIWOLaH2i67eaM1m1uJakDTg8o
-> ssh-ed25519 AQhf1g SSk081gv31ND5QM1V0KzlFQw05Hfx0UJ2EosCAzeS0k
wpefMRyZgwWcaP5mZBPVnL3MZ2k+L5a+ChLqRGCa/4g
-> ssh-ed25519 r/3ipA 5FoRCnYDLxjERHPTR+vY+2Y9ewOBZoXrvy+N6wnAS3Y
7Z+5IwEeM1iRlr/cUWt+sfv1QEOJmkvEG91xq1LmajA
-> ssh-ed25519 mOmPfg YMuWe/N8ZOrUdSnu2blap3HP+q1XJtVaK5pSUG44RBE
bvvZrMAGJ4hj83Kl6MYA5IXRgJidJGpYHVfqN1w3zBk
-> ssh-ed25519 YJiRbw fOo8kP29gbO6OI6Zq2YBvcX07Wjrm0qlZv+AS7KLcVI
7CCA1UgDtjmQi4L58TG2qVxxiDuxFm70LgOFpG18d/4
-> ssh-ed25519 Nl/5yA MZl/ydcywiEBzU2P396An7TVnTdtclNwsoItiSiUNRQ
upyVL3DUnmIE61NWVu0+gqaHNfmWIToOwJzLZOCsyo4
-> ssh-ed25519 GdLgCQ dva4KwyCz99k3Ah8WibFI2ez+hUdK6wFzMLS/bQJdAI
k5rNjS1IszxzKy3t8FFNoclyYRpkaWRgyzP5D/RAdc8
-> ssh-ed25519 tOH/HQ AL1zBCwXkMLNQWiD8eoGbTJKI6+ja22p5NH/dHitgFU
qJPaXsp4k5g/D0/wmcHtAAqqCeiFDpRhftXWAhxzr5o
-> ssh-ed25519 FpzvfQ 4IOwoeQE5od8jFEqWziCF2mzqCLoxOEdUM6sFOp8Zjw
Ea5bSCfza6i4cd8nL5p7tcoYyHC0B0V9lyuBM/PR3LI
-> ssh-ed25519 2UotMw 942H9PoyZwAfevk1yVlTLSUTQh17U/UjGfBcbHO0EEw
UMLFxLUf1Xv31JCyri1YcYKezAy9p/C5gc3EJMlSIvM
-> ssh-ed25519 kdPvzQ rYlwUzY8uJIe87A/x50Al3WMnPxnvxCOEZiYOvhPwF0
WmP5r+aWqNkmO2PQwLPdxIKIUr2BYzsU0I8U+kwhF+g
-> ssh-ed25519 onmXpg mIhPpC8xYbbf6DK0Upag73K7k+YfCE1S+ZgCfvu1fik
XgJ655mD/y8bWwrhjdMNH/v0J9DWJQiXVBgGTsSRr+8
-> ssh-ed25519 CnhD0g UvRupvnJ0zqie6y891Au6EBw+1YZ1Mc3rYWOOBZH5Ho
WMBj6BdYtIxgzSCVbqRXBIbFQhmXCPJMyLxG8OgZXAQ
-> ssh-ed25519 4ep2UA hyu7qF9mof2QhPfgMm2Xe/xsfJVQV03UK67b05ODeRw
tb54Ihc54Yeew4pRp0Y3aKAy9W7bpw++VeT9trHq4oQ
--- XXv9DYSwOiHB+rSASovGULreR0ZUVPr4MYYFrH9SnSw
7µ¾ø—Ó½{O¼™y —Ì?Ma§ß³2é‰yà£à‰§8¸E5¶jdµÀ ‚ŸBûn ôgþÞgb,NئH|
cA,<»XFãò(Ke7þ␍Ný
½ÁP‹Ò{&HK$
-6
View File
@@ -1,6 +0,0 @@
[client.admin]
key = AQBojDlmfnc8MBAAkr+PXbSewmq4OooESo2X1A==
caps mds = "allow *"
caps mgr = "allow *"
caps mon = "allow *"
caps osd = "allow *"
View File
-13
View File
@@ -1,13 +0,0 @@
[mon.]
key = AQAUijlm7emnJBAAKsHT1+2EzYRQxKsL4KwwkQ==
caps mon = "allow *"
[client.admin]
key = AQBojDlmfnc8MBAAkr+PXbSewmq4OooESo2X1A==
caps mds = "allow *"
caps mgr = "allow *"
caps mon = "allow *"
caps osd = "allow *"
[client.bootstrap-osd]
key = AQDvJDpm4BDlIhAAXISJWnrOtNDk0FqhSX0/YQ==
caps mgr = "allow r"
caps mon = "profile bootstrap-osd"
-4
View File
@@ -1,4 +0,0 @@
[client.bootstrap-osd]
key = AQDvJDpm4BDlIhAAXISJWnrOtNDk0FqhSX0/YQ==
caps mgr = "allow r"
caps mon = "profile bootstrap-osd"
+36 -38
View File
@@ -1,39 +1,37 @@
age-encryption.org/v1
-> ssh-ed25519 87huqg FT8+PzbWYp1G2XqxQh/wIV9cAUxZrLIdBZ2sMC+9szk
6TnThj3i7+q+JaJGgX9gtSOyLIqXwfqJhV7FXnffMFA
-> ssh-ed25519 8UnW5Q PgKl4RxTUiazuCkN8RcRKCO1+XyIQzfKz4SygoFojwU
O21D2VTrhKcz3H9yQ6v3HMg3yu6Oml6elssq4EZLOJY
-> ssh-ed25519 UFfTmg 64GTWzZguBnlbrkI37vPO4VHGq38ewzGJbf41fmFs20
SgbbJCitU6YS7xhyF5jvTRKgpd8JjQCn5goCDqGmP2o
-> ssh-ed25519 KbVVUw DWHG10kp4J0uQaU2UZLORMBrOkXXWL8hl9LmOQFHvVI
+5aIgcoPshO0m0Kkt15TmKOrw9fmYjA/CQBW78j5Rmo
-> ssh-ed25519 xNtnoA zNpZX9ymrcO0W6FfXgmQz9VcEa97s54DYdsb3ThhWwc
7F+/fHUNOAyFjBBEGfep9bSBQsPWehglpFoSniEYRJA
-> ssh-ed25519 aY2AXA qZFD9Sn7wSgZCEJ/bqdh8Pr1Bcalf0NU99Tq8aFGXB4
z9Q08OxS0sgPYMYBwJa1H8KMj3EU2nbyp3fB6+j6icM
-> ssh-ed25519 AQhf1g B4W2oj6J9B9ktt/QchkT7kQgRWOxHfEqFDyIka7ttDo
zAEaVCYNT+Ldk+2OMElMqN0WXCTnSgeV45f5QTocIps
-> ssh-ed25519 mOmPfg rGWRrIHZ7Hzys2X8hlSHis6eoH6bJWZYq2BR94gYexo
0kXY8xNmqshw4swmsIigJ3hUihlkoj8SSsLGdNB6Nbc
-> ssh-ed25519 YJiRbw RB2Ocz6kqAY7daf/cpHazgwuqK4WL7obmN1p24X/h1k
xV9OqnHeDJnLgmOYjbPDchp4uVlV05BwT/1eTBmXyMw
-> ssh-ed25519 Nl/5yA QqqZ3YRVdWt0bPCCTdtYipR8/c+YEx/J1Bdy2EdfMWg
leURB55yT6GyWO965kmBWeVwzGnHaPyGv88pcO7Yuq0
-> ssh-ed25519 GdLgCQ r1G2p2VwiSanA5qjASjCTfunoZ+y0UhNIAxm6Z8N/E4
tIku23bpxx0SG9iIh2h6UCWDQAq85Gj7YlMlk0Jdb2Y
-> ssh-ed25519 tOH/HQ IJee8JIPvGwIT9c7deikAyxAd8rvq4s67B3an9htvh0
VvGG/yilaEe8+bOqc72+rY87wv6F3Ss2b+RF5aOCOD8
-> ssh-ed25519 FpzvfQ S6qhDcpBEdrk7ydvID0iwmoY8CBtjP6tUhax/O8ORl4
wqkt0wEv3lXw8bpF/oMmCD7O1S2OXJJo3Y2xKhLgeD4
-> ssh-ed25519 2UotMw AVmF4uIN2reJA2pPg1KZT84pbnG3Y5laZalJ7sdD6GY
36Pdc0awqnlzZ13p19yqDnnikRV4NUaJ5LEMTzYzB6g
-> ssh-ed25519 kdPvzQ UvJj47WTQTM9VEzIdX+O7s7nMfO8TLAn3fTCYQl80mE
njyOgBl8LsaRKRRNeumQbYRHnUtT8SWtCT/RLoQ0ioo
-> ssh-ed25519 onmXpg jeup0qoEJhTYKJBNQkNf6frrP14xf4NeSWk2b3L0wUg
9HvGi1r/Wm2YRCpl+Bvp2t2L9q3ci/Mbg0N+5LgIz98
-> ssh-ed25519 CnhD0g Q+Q9n6e70v2Q+4UWPznvh0dot/hjHGnIPDOLIDsNDws
KnqhFsNIArU4JeK0Vqou4zewrO+ul0uJE6oVvTapaZg
-> ssh-ed25519 4ep2UA 4wTgnS1jJZzww5ktip5vzsDEA9ERi8v9l1RqjrPB7x4
t70NW6zcVLV2UXdacJ/tqxvEMS9MrumEKoy+F+UvnHE
--- 4WejiRlNCP3hQqi2+8WD53mX/lptc0N4AbhBkw7mt5o
—"åUÑMÄ„2Ç£%°ö×)»v oŸCo|>­šÐa†À†¡‹6¥äE˜ùnOV¬©HÖäßD6i .†C¦Ýs0sÂj]Ü ªÛ¿
-> ssh-ed25519 8UnW5Q zKwZaiVwcb3twBRyisICah2+RLb5NUStt0h3Ch7t/Tw
9O3yKkWIOiJy6ese/ytnDRvyNbytQKDXR7HSZLNWNjY
-> ssh-ed25519 UFfTmg erGwb0GnZV12BoEa1JYiYevuf3Uq0Tv73ObbDRvv+Tw
a0YD87ft8y3ZTYWw38GSwbmIUHe3HW6FuaGksF5pi3I
-> ssh-ed25519 xNtnoA KajAZC29v2JqZY+OPkeHpKv0biPJLDgnT2CN//WnjhM
GJdu44xGefwsI0g99wuwTmWGVQD8uwIcyINRCHMb6I4
-> ssh-ed25519 aY2AXA aQk0/BCQyyPCZCuaI8NiyjuDZBIRB+nAWZBKs+3Z8Wk
KSZxNCGThfNjoSZh9hIRjP9o5cQ1FjZP4G7GuLbBZn8
-> ssh-ed25519 AQhf1g 6usKpTxVUNIT92ugQl7Z8LFPFPStTgoPhEGdyXjmhwQ
QqGWtkb4Bom4sKMrV347/jf6YptbQIm78zzNwxZN1UU
-> ssh-ed25519 r/3ipA M77+oa8Kbvt6eGbAaq6/0oG9ggXSbYZeBOkced0F5zg
hkEFOfMRY4iIZ31X8ty11lGkouOxHm2r/tLwPRfQ050
-> ssh-ed25519 mOmPfg RohXdUXobV/fC3JYQ9IuVvDqdfnS2xodARJYmT1Ch3A
VdDNZFmvud6FGSX/I1c4iKg+6uhWgslPKAk0Uf5Vhds
-> ssh-ed25519 YJiRbw /xSl3swqNc5q0hsY+hO4nSk6PzPk9lRV7Hni/yNX4WE
GXD3wBcBf6k1mjr14vIP58bjRWOnnVBxm1zunv7SVo0
-> ssh-ed25519 Nl/5yA BAgdJDYBnUE0/8dR32V5D/ONiwLufRL9/9CY0YgpW1U
aUgdT4MPYEAVjSuWm2lqr+r3xwlX35UyrbYGh5v5C6s
-> ssh-ed25519 GdLgCQ fOAibyd4PSLdTsOM/ntG3/Jcz6TZFTlGk1oO9MLQWXc
HNyui1pe4ZcrjHafzZtCad6Nc3MbzFu8YSMS6qae+mo
-> ssh-ed25519 tOH/HQ oE4PbISWQe/kW2DxIkwqJKhKp/SNNa2OVje5iX21RA0
lx0r//kRfV5df3+5cApTmpE9zxFjKoNBSguhoeHqgjQ
-> ssh-ed25519 FpzvfQ L5a5UzaBYkaDLRKKu3z/9tou8SFmzL7615l8Ejyb23w
Z9G1pnjjBk7H+XoNGNiBUtsZVQYiXe6/crYjUb4LIFM
-> ssh-ed25519 2UotMw sw24R6i1jaa2t2NcPsXxeJz1FSNGY8dpTJQBPM4Y60M
t+fZa71iWWxAqfusahrNV/Gx4RvlklnmZHgz4VsxGRk
-> ssh-ed25519 kdPvzQ BevwDGBlvPar9elbiiFK5gnbF1qjXG4lsTSaOHdZwA4
DBYjAo0HLsF7GzGPAw5wGate8QIpFQ2F/FNEITQqOrk
-> ssh-ed25519 onmXpg XFXmGNe6X+JbLS6f26x8OEooWGCsSKdPXfNwFoSDknE
zEKhchCyQN+rMBGXpnwMeOoRLDPiQSRQbHeG3V9ifLE
-> ssh-ed25519 CnhD0g Cua/knFngt15egS+o7s848bfy9YM0/fFijrdkrreWi4
tSj9HuyLRTiLPFlkNUHQrmY2scEBQvzYIXUuuUuYyjc
-> ssh-ed25519 4ep2UA lZYn4isPidCnEz33aBI0Q+oONJqFy+a63slmhw2rBlo
i0zEbwLS3kXVoqfMpdnti0UIn5pDEd7OJjX1cA2idWs
--- H8Qm4uuJHlwWSBopEIN+ZUr0hZ5RndYYO2jQWAIDW4Q
‘g¡CèæPÖ•ê²¢dW\@Mïs¨×þ‡[‚Á_‹ü±®¶ÁNÇžBÜïo§Í,0ƒt…d8Þ"Ÿ“Ã#¥ŽET¯‡h=GTOh+Mú
Binary file not shown.

Some files were not shown because too many files have changed in this diff Show More