Compare commits
89
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1ccd6b00a9 | ||
|
|
ae4457fc58 | ||
|
|
07e85d35ab | ||
|
|
b4ab1bde50 | ||
|
|
4e7ca2910a | ||
|
|
64a253e9e4 | ||
|
|
e4008a0beb | ||
|
|
363098c0a1 | ||
|
|
a07068a4fb | ||
|
|
ec53199532 | ||
|
|
389798c4f0 | ||
|
|
475fe50d19 | ||
|
|
0d1d846884 | ||
|
|
1d9921f1ae | ||
|
|
7388715d30 | ||
|
|
b3304c0ef5 | ||
|
|
e955ea82f3 | ||
|
|
067c00330b | ||
|
|
60e2450c66 | ||
|
|
3185a5a375 | ||
|
|
348a1d7301 | ||
|
|
33eda7d2cb | ||
|
|
34ca5aec6b | ||
|
|
d2f7b85283 | ||
|
|
d12ef9faec | ||
|
|
3e60f73251 | ||
|
|
bc986f0e51 | ||
|
|
214f6a4d2a | ||
|
|
41d02d19ea | ||
|
|
4f79033b04 | ||
|
|
9b99b2dd8c | ||
|
|
a145f6ca43 | ||
|
|
f77f46c4e5 | ||
|
|
c2ea5ff472 | ||
|
|
0e972936d3 | ||
|
|
b35004a3ad | ||
|
|
d7e98290c3 | ||
|
|
f5922887bf | ||
|
|
879230dca7 | ||
|
|
1c7e2ff268 | ||
|
|
b324ee5352 | ||
|
|
d21cbcb85d | ||
|
|
6a0c87b77d | ||
|
|
db5ef17dba | ||
|
|
251f2804c6 | ||
|
|
c8951f6da8 | ||
|
|
394c2c2aba | ||
|
|
bb7a01f758 | ||
|
|
a6b46f9c74 | ||
|
|
e865d0832e | ||
|
|
307dbbe044 | ||
|
|
69651258d6 | ||
|
|
53c491f537 | ||
|
|
a8ccb1b6ba | ||
|
|
e6217401f9 | ||
|
|
d97fb37f0e | ||
|
|
75e71f9ce9 | ||
|
|
19540ea1da | ||
|
|
431f78f8af | ||
|
|
95eea6fc26 | ||
|
|
387a34ffff | ||
|
|
37a833887b | ||
|
|
a69fc4240a | ||
|
|
15c586fbdb | ||
|
|
2daf74d134 | ||
|
|
1934787e80 | ||
|
|
2a476a7bfe | ||
|
|
e94137ecbf | ||
|
|
d22f543043 | ||
|
|
e5e4a38cf1 | ||
|
|
89faa7d97d | ||
|
|
fc4430e4f1 | ||
|
|
f735423d98 | ||
|
|
985dd927c4 | ||
|
|
10d6f85b5e | ||
|
|
85cdfce6a9 | ||
|
|
e62757cf1c | ||
|
|
a1fb195bf4 | ||
|
|
9eb9fdec6c | ||
|
|
a8323e2396 | ||
|
|
855ab6e277 | ||
|
|
2932e9e335 | ||
|
|
4940550c62 | ||
|
|
258934a46b | ||
|
|
2476be3799 | ||
|
|
08111e7a8a | ||
|
|
99cc8efea0 | ||
|
|
09198fda28 | ||
|
|
e16886c62c |
@@ -1,13 +1,13 @@
|
||||
name: Update flake.lock
|
||||
|
||||
on:
|
||||
"on":
|
||||
schedule:
|
||||
- cron: "0 0 * * 0" # Every Sunday at midnight UTC
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
update-flake-lock:
|
||||
runs-on: [bare-metal, nix-latest]
|
||||
runs-on: nix-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
@@ -1,23 +0,0 @@
|
||||
stages:
|
||||
- eval
|
||||
- build
|
||||
- push
|
||||
|
||||
"Evaluate for builds":
|
||||
stage: eval
|
||||
tags:
|
||||
- kubernetes
|
||||
image: "$CI_REGISTRY/greg/ci-images/builder:latest"
|
||||
artifacts:
|
||||
paths:
|
||||
- gitlab-ci-continue.yml
|
||||
script: nix run ".#gen-build" > gitlab-ci-continue.yml
|
||||
|
||||
"Trigger builds":
|
||||
stage: build
|
||||
trigger:
|
||||
include:
|
||||
- artifact: gitlab-ci-continue.yml
|
||||
job: "Evaluate for builds"
|
||||
variables:
|
||||
PARENT_PIPELINE_ID: $CI_PIPELINE_ID
|
||||
@@ -17,7 +17,7 @@ repos:
|
||||
- id: mixed-line-ending
|
||||
- id: trailing-whitespace
|
||||
- repo: https://github.com/adrienverge/yamllint.git
|
||||
rev: v1.37.1
|
||||
rev: v1.38.0
|
||||
hooks:
|
||||
- id: yamllint
|
||||
args:
|
||||
@@ -30,8 +30,9 @@ repos:
|
||||
comments: false
|
||||
comments-indentation: false
|
||||
document-start: false
|
||||
line-length: false
|
||||
- repo: https://github.com/NixOS/nixfmt
|
||||
rev: v1.1.0
|
||||
rev: v1.2.0
|
||||
hooks:
|
||||
- id: nixfmt-nix
|
||||
- repo: https://github.com/astro/deadnix
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIByDCCAW+gAwIBAgIRANS+dPEH5Vqug7OWhCMmcx4wCgYIKoZIzj0EAwIwLjER
|
||||
MA8GA1UEChMISGVsbGluZ3MxGTAXBgNVBAMTEEhlbGxpbmdzIFJvb3QgQ0EwHhcN
|
||||
MjQwMjIwMjEyNzIxWhcNMzQwMjE3MjEyNzIxWjA2MREwDwYDVQQKEwhIZWxsaW5n
|
||||
czEhMB8GA1UEAxMYSGVsbGluZ3MgSW50ZXJtZWRpYXRlIENBMFkwEwYHKoZIzj0C
|
||||
AQYIKoZIzj0DAQcDQgAErZUhPfx5MpNbNVyqHDrIgUGnb6Hitl8hXlpH+kgjBzCi
|
||||
7I/+TQnl9Tc0VVNOFOYLOfBi7hV3/QudUtLGk0FKeaNmMGQwDgYDVR0PAQH/BAQD
|
||||
AgEGMBIGA1UdEwEB/wQIMAYBAf8CAQAwHQYDVR0OBBYEFMZR8LDd+hNy+TmtEHvt
|
||||
zRzXboh2MB8GA1UdIwQYMBaAFAlH11TwIFGB/K75qZ3e0S+fN3JUMAoGCCqGSM49
|
||||
BAMCA0cAMEQCIBxHK6r8pMX5hrTwYKRfMmRIt44m0KtNejA2T5t09hs+AiBfvmHb
|
||||
LfoE4qoC6NgpvXorAbx+O7xkem/9svF0Ob+RsA==
|
||||
-----END CERTIFICATE-----
|
||||
@@ -1,11 +0,0 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIIBoTCCAUagAwIBAgIRAL/1mvE8+73nRFGsvzaaVSAwCgYIKoZIzj0EAwIwLjER
|
||||
MA8GA1UEChMISGVsbGluZ3MxGTAXBgNVBAMTEEhlbGxpbmdzIFJvb3QgQ0EwHhcN
|
||||
MjQwMjIwMjEyNzIwWhcNMzQwMjE3MjEyNzIwWjAuMREwDwYDVQQKEwhIZWxsaW5n
|
||||
czEZMBcGA1UEAxMQSGVsbGluZ3MgUm9vdCBDQTBZMBMGByqGSM49AgEGCCqGSM49
|
||||
AwEHA0IABEgNBjlT/7gmzNp9vKJvGPJn9/IizuMGVpucdrN9+J1u1ABkLNRzj5p2
|
||||
g7s3e/BG+EJnnTf/2tuq3p/wPqmQkdujRTBDMA4GA1UdDwEB/wQEAwIBBjASBgNV
|
||||
HRMBAf8ECDAGAQH/AgEBMB0GA1UdDgQWBBQJR9dU8CBRgfyu+amd3tEvnzdyVDAK
|
||||
BggqhkjOPQQDAgNJADBGAiEA/uBclcFCOpkEgAeBAVurktYB82sMdIyyDGHcjlwi
|
||||
pvkCIQC2kuZ/nXRjibeIebQIVTBskQ1LxlLxnx7zNSjtr3kFfQ==
|
||||
-----END CERTIFICATE-----
|
||||
@@ -1,54 +0,0 @@
|
||||
services:
|
||||
attic:
|
||||
container_name: attic
|
||||
image: ghcr.io/zhaofengli/attic:latest
|
||||
command: ["-f", "/attic/server.toml"]
|
||||
restart: unless-stopped
|
||||
ports:
|
||||
- 8080:8080
|
||||
networks:
|
||||
attic:
|
||||
pgattic:
|
||||
volumes:
|
||||
- /mnt/all/configs/attic/server.toml:/attic/server.toml
|
||||
- /mnt/all/containers/attic/data:/attic/storage
|
||||
env_file:
|
||||
- stack.env
|
||||
depends_on:
|
||||
pgattic:
|
||||
condition: service_healthy
|
||||
healthcheck:
|
||||
test:
|
||||
[
|
||||
"CMD-SHELL",
|
||||
"wget --no-verbose --tries=1 --spider http://attic:8080 || exit 1",
|
||||
]
|
||||
interval: 15s
|
||||
timeout: 10s
|
||||
retries: 10
|
||||
start_period: 15s
|
||||
deploy:
|
||||
resources:
|
||||
reservations:
|
||||
cpus: 1.0
|
||||
|
||||
pgattic:
|
||||
container_name: pgattic
|
||||
image: postgres:17.6-alpine
|
||||
restart: unless-stopped
|
||||
ports: []
|
||||
networks:
|
||||
pgattic:
|
||||
volumes:
|
||||
- /mnt/all/containers/attic/postgres:/var/lib/postgresql/data
|
||||
env_file:
|
||||
- stack.env
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB}"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
|
||||
networks:
|
||||
attic:
|
||||
pgattic:
|
||||
@@ -1,9 +0,0 @@
|
||||
services:
|
||||
pinchflat:
|
||||
image: ghcr.io/kieraneglin/pinchflat:latest
|
||||
ports:
|
||||
- "8945:8945"
|
||||
volumes:
|
||||
- "/mnt/all/configs/pinchflat:/config"
|
||||
- "/mnt/all/video/yt:/downloads"
|
||||
restart: unless-stopped
|
||||
@@ -1,19 +0,0 @@
|
||||
# Demo of rest-server with prometheus and grafana
|
||||
version: "2"
|
||||
|
||||
services:
|
||||
restserver:
|
||||
image: "restic/rest-server:0.14.0"
|
||||
volumes:
|
||||
- /mnt/all/backups:/data
|
||||
- /mnt/all/configs/certs:/certs
|
||||
environment:
|
||||
OPTIONS: >-
|
||||
--tls
|
||||
--tls-cert /certs/nas1.shire-zebra.ts.net.crt
|
||||
--tls-key /certs/nas1.shire-zebra.ts.net.key
|
||||
--path /data
|
||||
--prometheus
|
||||
--debug
|
||||
ports:
|
||||
- "30248:8000"
|
||||
+53
-25
@@ -1,54 +1,82 @@
|
||||
{
|
||||
lib,
|
||||
pkgs,
|
||||
pkgs',
|
||||
top,
|
||||
...
|
||||
}:
|
||||
let
|
||||
builder-config = {
|
||||
darwin-aarch-builder = top.self.nixosConfigurations.builder-aarch;
|
||||
darwin-x86-builder = top.self.nixosConfigurations.builder-x86;
|
||||
system = builtins.replaceStrings [ "darwin" ] [ "linux" ] pkgs.stdenv.hostPlatform.system;
|
||||
builderConfig = top.nixunstable.lib.nixosSystem {
|
||||
inherit system;
|
||||
modules = [
|
||||
"${top.nixunstable}/nixos/modules/profiles/nix-builder-vm.nix"
|
||||
{
|
||||
virtualisation = {
|
||||
host.pkgs = pkgs;
|
||||
darwin-builder = {
|
||||
workingDirectory = "/var/lib/darwin-builder";
|
||||
hostPort = 22;
|
||||
};
|
||||
builder = arch: let
|
||||
b = builder-config."darwin-${arch}-builder";
|
||||
in {
|
||||
command = "${b.config.system.build.macos-builder-installer}/bin/create-builder";
|
||||
};
|
||||
}
|
||||
];
|
||||
};
|
||||
builder = {
|
||||
command = "${builderConfig.config.system.build.macos-builder-installer}/bin/create-builder";
|
||||
serviceConfig = {
|
||||
KeepAlive = true;
|
||||
RunAtLoad = true;
|
||||
StandardOutPath = "/var/log/builder-vm-${arch}.log";
|
||||
StandardErrorPath = "/var/log/builder-vm-${arch}.stderr.log";
|
||||
StandardOutPath = "/var/log/builder-vm-${system}.log";
|
||||
StandardErrorPath = "/var/log/builder-vm-${system}.stderr.log";
|
||||
};
|
||||
};
|
||||
in
|
||||
{
|
||||
environment.systemPackages = with pkgs; [
|
||||
environment = {
|
||||
launchDaemons = {
|
||||
"limit.maxfiles.plist" = {
|
||||
enable = true;
|
||||
text = ''
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||||
<plist version="1.0">
|
||||
<dict>
|
||||
<key>Label</key>
|
||||
<string>limit.maxfiles</string>
|
||||
<key>ProgramArguments</key>
|
||||
<array>
|
||||
<string>launchctl</string>
|
||||
<string>limit</string>
|
||||
<string>maxfiles</string>
|
||||
<string>524288</string>
|
||||
<string>524288</string>
|
||||
</array>
|
||||
<key>RunAtLoad</key>
|
||||
<true/>
|
||||
</dict>
|
||||
</plist>
|
||||
'';
|
||||
};
|
||||
};
|
||||
systemPackages = with pkgs; [
|
||||
agenix
|
||||
hms
|
||||
pkgs'.hms
|
||||
procps # Includes tools like `watch`, `kill`, and `ps`
|
||||
];
|
||||
};
|
||||
|
||||
fonts.packages = with pkgs; [
|
||||
dejavu_fonts
|
||||
nerd-fonts.hack
|
||||
];
|
||||
|
||||
#launchd.daemons = lib.genAttrs' [ "x86" "aarch" ] (arch: lib.nameValuePair "builder-${arch}-machine" (builder arch));
|
||||
#launchd.daemons.darwin-builder = builder;
|
||||
|
||||
nix = {
|
||||
#buildMachines = [ { systems = ["aarch64-linux"]; sshUser = "builder"; sshKey = "/etc/nix/builder_ed25519"; hostName = "localhost:31022"; protocol = "ssh-ng"; }];
|
||||
enable = true;
|
||||
buildMachines = [
|
||||
{
|
||||
hostName = "ssh-ng://builder@localhost";
|
||||
system = "aarch64-linux";
|
||||
maxJobs = 4;
|
||||
supportedFeatures = [
|
||||
"kvm"
|
||||
"benchmarch"
|
||||
"big-parallel"
|
||||
];
|
||||
}
|
||||
];
|
||||
gc.interval.Hour = 3;
|
||||
#linux-builder.enable = true;
|
||||
settings.auto-optimise-store = false; # Darwin bugs?
|
||||
};
|
||||
|
||||
|
||||
+2
-8
@@ -19,6 +19,7 @@ let
|
||||
specialArgs = {
|
||||
inherit metadata top;
|
||||
inherit (top) self;
|
||||
pkgs' = top.self.packages.${system};
|
||||
};
|
||||
modules = [
|
||||
{
|
||||
@@ -37,11 +38,4 @@ let
|
||||
++ lib.optionals (builtins.pathExists ./hosts/${name}) [ ./hosts/${name} ];
|
||||
};
|
||||
in
|
||||
(
|
||||
lib.genAttrs
|
||||
(builtins.attrNames (builtins.readDir ./hosts))
|
||||
(
|
||||
name:
|
||||
mac { inherit name; }
|
||||
)
|
||||
)
|
||||
(lib.genAttrs (builtins.attrNames (builtins.readDir ./hosts)) (name: mac { inherit name; }))
|
||||
|
||||
@@ -31,6 +31,7 @@ in
|
||||
"bitwarden"
|
||||
"bruno"
|
||||
"chromium"
|
||||
"claude"
|
||||
"dbeaver-community"
|
||||
"ghostty"
|
||||
"firefox"
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
{ config, ... }:
|
||||
{ ... }:
|
||||
let
|
||||
username = "greg";
|
||||
in
|
||||
@@ -11,6 +11,7 @@ in
|
||||
enable = true;
|
||||
brews = [
|
||||
"bitwarden-cli"
|
||||
"colima"
|
||||
"direnv"
|
||||
"github-mcp-server"
|
||||
{
|
||||
@@ -37,7 +38,6 @@ in
|
||||
"notion"
|
||||
"notunes"
|
||||
"onlyoffice"
|
||||
"podman-desktop"
|
||||
"tabby"
|
||||
"zed"
|
||||
];
|
||||
|
||||
Generated
+208
-134
@@ -25,19 +25,17 @@
|
||||
},
|
||||
"buildbot": {
|
||||
"inputs": {
|
||||
"flake-parts": "flake-parts",
|
||||
"hercules-ci-effects": "hercules-ci-effects",
|
||||
"nixpkgs": [
|
||||
"nixunstable"
|
||||
],
|
||||
"treefmt-nix": "treefmt-nix"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1776626072,
|
||||
"narHash": "sha256-NF6x9h74mrA0Acl1JHWwuSSrwzyTm3KyV8a85QUqTW0=",
|
||||
"lastModified": 1784438381,
|
||||
"narHash": "sha256-OuKnPzVTpGYaUQp/GjR7NFY8ezVRlR2V2CUxkHkI2UU=",
|
||||
"owner": "nix-community",
|
||||
"repo": "buildbot-nix",
|
||||
"rev": "f298855ee69709374a25ae9543ad11bd549d7b8b",
|
||||
"rev": "72e12f1a1381321e07279b18f3d401c29871b50e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -55,11 +53,11 @@
|
||||
"stable": "stable"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1762034856,
|
||||
"narHash": "sha256-QVey3iP3UEoiFVXgypyjTvCrsIlA4ecx6Acaz5C8/PQ=",
|
||||
"lastModified": 1784448989,
|
||||
"narHash": "sha256-XC0OkWCiTM91msCp0o7zfM+iBv06mLlCzFxkP8vf+ac=",
|
||||
"owner": "zhaofengli",
|
||||
"repo": "colmena",
|
||||
"rev": "349b035a5027f23d88eeb3bc41085d7ee29f18ed",
|
||||
"rev": "e5eda626e459f7043868fd2e3b3bf8ce0d1992e6",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -97,11 +95,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1775037210,
|
||||
"narHash": "sha256-KM2WYj6EA7M/FVZVCl3rqWY+TFV5QzSyyGE2gQxeODU=",
|
||||
"lastModified": 1784500460,
|
||||
"narHash": "sha256-UvORnAxTRHax7RG74W8Z2t4GvIkX6AjJ5kk0QlwZomo=",
|
||||
"owner": "lnl7",
|
||||
"repo": "nix-darwin",
|
||||
"rev": "06648f4902343228ce2de79f291dd5a58ee12146",
|
||||
"rev": "57a3171f94705599a2499248ca5758d5eb47c0e0",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -114,11 +112,11 @@
|
||||
"flake-compat": {
|
||||
"flake": false,
|
||||
"locked": {
|
||||
"lastModified": 1650374568,
|
||||
"narHash": "sha256-Z+s0J8/r907g149rllvwhb4pKi8Wam5ij0st8PwAh+E=",
|
||||
"lastModified": 1767039857,
|
||||
"narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
|
||||
"owner": "edolstra",
|
||||
"repo": "flake-compat",
|
||||
"rev": "b4a34015c698c7793d592d66adbab377907a2be8",
|
||||
"rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -161,17 +159,14 @@
|
||||
},
|
||||
"flake-parts": {
|
||||
"inputs": {
|
||||
"nixpkgs-lib": [
|
||||
"buildbot",
|
||||
"nixpkgs"
|
||||
]
|
||||
"nixpkgs-lib": "nixpkgs-lib"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1775087534,
|
||||
"narHash": "sha256-91qqW8lhL7TLwgQWijoGBbiD4t7/q75KTi8NxjVmSmA=",
|
||||
"lastModified": 1782949081,
|
||||
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "3107b77cd68437b9a76194f0f7f9c55f2329ca5b",
|
||||
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -182,14 +177,17 @@
|
||||
},
|
||||
"flake-parts_2": {
|
||||
"inputs": {
|
||||
"nixpkgs-lib": "nixpkgs-lib"
|
||||
"nixpkgs-lib": [
|
||||
"nixvimunstable",
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1775087534,
|
||||
"narHash": "sha256-91qqW8lhL7TLwgQWijoGBbiD4t7/q75KTi8NxjVmSmA=",
|
||||
"lastModified": 1782949081,
|
||||
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "3107b77cd68437b9a76194f0f7f9c55f2329ca5b",
|
||||
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -199,27 +197,6 @@
|
||||
}
|
||||
},
|
||||
"flake-parts_3": {
|
||||
"inputs": {
|
||||
"nixpkgs-lib": [
|
||||
"nixvimunstable",
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1775087534,
|
||||
"narHash": "sha256-91qqW8lhL7TLwgQWijoGBbiD4t7/q75KTi8NxjVmSmA=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"rev": "3107b77cd68437b9a76194f0f7f9c55f2329ca5b",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "hercules-ci",
|
||||
"repo": "flake-parts",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"flake-parts_4": {
|
||||
"inputs": {
|
||||
"nixpkgs-lib": [
|
||||
"nurpkgs",
|
||||
@@ -241,42 +218,20 @@
|
||||
}
|
||||
},
|
||||
"flake-utils": {
|
||||
"locked": {
|
||||
"lastModified": 1659877975,
|
||||
"narHash": "sha256-zllb8aq3YO3h8B/U0/J1WBgAL8EX5yWf5pMj3G0NAmc=",
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"rev": "c0e246b9b83f637f4681389ecabcb2681b4f3af0",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"hercules-ci-effects": {
|
||||
"inputs": {
|
||||
"flake-parts": [
|
||||
"buildbot",
|
||||
"flake-parts"
|
||||
],
|
||||
"nixpkgs": [
|
||||
"buildbot",
|
||||
"nixpkgs"
|
||||
]
|
||||
"systems": "systems_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1776380511,
|
||||
"narHash": "sha256-3A2B8k6YCuzt5pT/CQEltUghtE6heSlk2tMYkg/fUWI=",
|
||||
"owner": "hercules-ci",
|
||||
"repo": "hercules-ci-effects",
|
||||
"rev": "4a80b7e95a298b7bb4418c0a2b55fe95a662c377",
|
||||
"lastModified": 1731533236,
|
||||
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "hercules-ci",
|
||||
"repo": "hercules-ci-effects",
|
||||
"owner": "numtide",
|
||||
"repo": "flake-utils",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
@@ -287,11 +242,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1776904464,
|
||||
"narHash": "sha256-sBUCj7/4d3Hoevpu3oQp8ccJNA1EDeVmFi1F8O6VJro=",
|
||||
"lastModified": 1784913159,
|
||||
"narHash": "sha256-JWq0BfjO4ktpH5USfQNQzdvHpIDT8fSKD5K7LvdMRFs=",
|
||||
"owner": "nix-community",
|
||||
"repo": "home-manager",
|
||||
"rev": "667b3c47325441e6a444faaf405bba76ec70338a",
|
||||
"rev": "079a3b5d1aa6a719920a51316253b7d6dd22738d",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -326,14 +281,14 @@
|
||||
"inputs": {
|
||||
"flake-compat": "flake-compat_2",
|
||||
"nixpkgs": "nixpkgs_2",
|
||||
"systems": "systems_2"
|
||||
"systems": "systems_3"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1777001712,
|
||||
"narHash": "sha256-9JX9msZU1NvHzjKM24PRorP76Ge8GBy6LAkJKA21mlY=",
|
||||
"lastModified": 1784949919,
|
||||
"narHash": "sha256-itGqjPYHqEUqabXbQb+eHguk1c6rBTRGZS4KImp45kM=",
|
||||
"owner": "Infinidoge",
|
||||
"repo": "nix-minecraft",
|
||||
"rev": "394d3bfd943458baf29e4798bc9b256d824a3bb9",
|
||||
"rev": "a58c1fa23ec0273eb085be1e7874e964aa3cd34f",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -342,6 +297,25 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"niks3": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_3",
|
||||
"treefmt-nix": "treefmt-nix_2"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1784621916,
|
||||
"narHash": "sha256-JGjvWpNNrbhiYhx+z9l/iDw1J48TrirfZC6R3yWjmU4=",
|
||||
"owner": "Mic92",
|
||||
"repo": "niks3",
|
||||
"rev": "abbc291d372d2d821327516b5f5224de03113204",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "Mic92",
|
||||
"repo": "niks3",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nix-github-actions": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
@@ -350,11 +324,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1729742964,
|
||||
"narHash": "sha256-B4mzTcQ0FZHdpeWcpDYPERtyjJd/NIuaQ9+BV1h+MpA=",
|
||||
"lastModified": 1737420293,
|
||||
"narHash": "sha256-F1G5ifvqTpJq7fdkT34e/Jy9VCyzd5XfJ9TO8fHhJWE=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nix-github-actions",
|
||||
"rev": "e04df33f62cdcf93d73e9a04142464753a16db67",
|
||||
"rev": "f4158fa080ef4503c8f4c820967d946c2af31ec9",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -364,12 +338,15 @@
|
||||
}
|
||||
},
|
||||
"nix-hardware": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_4"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1776830795,
|
||||
"narHash": "sha256-PAfvLwuHc1VOvsLcpk6+HDKgMEibvZjCNvbM1BJOA7o=",
|
||||
"lastModified": 1784723954,
|
||||
"narHash": "sha256-1CfD8ZUjCkTgjsneLZ/lxCHhgDfqxxE7/GX0MmsgiqA=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixos-hardware",
|
||||
"rev": "72674a6b5599e844c045ae7449ba91f803d44ebc",
|
||||
"rev": "a017f5b72210026af5b3ac5949f08d94380a6fbd",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -380,11 +357,11 @@
|
||||
},
|
||||
"nixpkgs": {
|
||||
"locked": {
|
||||
"lastModified": 1750134718,
|
||||
"narHash": "sha256-v263g4GbxXv87hMXMCpjkIxd/viIF7p3JpJrwgKdNiI=",
|
||||
"lastModified": 1783224372,
|
||||
"narHash": "sha256-8i/87eeoqiGE4yOTjwSA3Eh/ziJRQEmd/unYU+K27sk=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "9e83b64f727c88a7711a2c463a7b16eedb69a84c",
|
||||
"rev": "d407951447dcd00442e97087bf374aad70c04cea",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -396,11 +373,26 @@
|
||||
},
|
||||
"nixpkgs-lib": {
|
||||
"locked": {
|
||||
"lastModified": 1774748309,
|
||||
"narHash": "sha256-+U7gF3qxzwD5TZuANzZPeJTZRHS29OFQgkQ2kiTJBIQ=",
|
||||
"lastModified": 1782614948,
|
||||
"narHash": "sha256-ePjCwr1sNm9NYUqywL7QfK3JnlS015msC+eBu2zKlp8=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nixpkgs.lib",
|
||||
"rev": "333c4e0545a6da976206c74db8773a1645b5870a",
|
||||
"rev": "db3f255737b94216eb71cce308e2912cf6bc2d7c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-community",
|
||||
"repo": "nixpkgs.lib",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs-lib_2": {
|
||||
"locked": {
|
||||
"lastModified": 1785031560,
|
||||
"narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nixpkgs.lib",
|
||||
"rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -427,11 +419,56 @@
|
||||
},
|
||||
"nixpkgs_3": {
|
||||
"locked": {
|
||||
"lastModified": 1776548001,
|
||||
"narHash": "sha256-ZSK0NL4a1BwVbbTBoSnWgbJy9HeZFXLYQizjb2DPF24=",
|
||||
"lastModified": 1783978241,
|
||||
"narHash": "sha256-7kK0Y/fIV2NTKArkd/eZGaFg+dEmgP8KDRsGK2vB5M4=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "a8b81d3cc8d35af7bc98694696bea61ad4f8fca7",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixos-unstable-small",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_4": {
|
||||
"locked": {
|
||||
"lastModified": 1767892417,
|
||||
"narHash": "sha256-8bW3q88CEg2u4hSP66Vf4lpbLonHz7hqDNBMcCY7E9U=",
|
||||
"rev": "3497aa5c9457a9d88d71fa93a4a8368816fbeeba",
|
||||
"type": "tarball",
|
||||
"url": "https://releases.nixos.org/nixos/unstable/nixos-26.05pre924538.3497aa5c9457/nixexprs.tar.xz"
|
||||
},
|
||||
"original": {
|
||||
"type": "tarball",
|
||||
"url": "https://channels.nixos.org/nixos-unstable/nixexprs.tar.xz"
|
||||
}
|
||||
},
|
||||
"nixpkgs_5": {
|
||||
"locked": {
|
||||
"lastModified": 1784555310,
|
||||
"narHash": "sha256-/FCliTPgiuV1owejZFNx3Ch9irdvkOfOFl+HHZ+DrtM=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "421eebfd0ec7bccd4abe826ce62d7e6e83129493",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixpkgs-unstable",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_6": {
|
||||
"locked": {
|
||||
"lastModified": 1784796856,
|
||||
"narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "b12141ef619e0a9c1c84dc8c684040326f27cdcc",
|
||||
"rev": "e2587caef70cea85dd97d7daab492899902dbf5d",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -441,29 +478,29 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixpkgs_4": {
|
||||
"nixpkgs_7": {
|
||||
"locked": {
|
||||
"lastModified": 1766025857,
|
||||
"narHash": "sha256-Lav5jJazCW4mdg1iHcROpuXqmM94BWJvabLFWaJVJp0=",
|
||||
"lastModified": 1784564315,
|
||||
"narHash": "sha256-7OpsHHIZFUBLbeHNQ0oC40DZRQjsmGWodXge+OqgPgk=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "def3da69945bbe338c373fddad5a1bb49cf199ce",
|
||||
"rev": "0c2094806c9e542f31785ef3569ab9e900e3ce9c",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "def3da69945bbe338c373fddad5a1bb49cf199ce",
|
||||
"rev": "0c2094806c9e542f31785ef3569ab9e900e3ce9c",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"nixunstable": {
|
||||
"locked": {
|
||||
"lastModified": 1776548001,
|
||||
"narHash": "sha256-ZSK0NL4a1BwVbbTBoSnWgbJy9HeZFXLYQizjb2DPF24=",
|
||||
"lastModified": 1784796856,
|
||||
"narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=",
|
||||
"owner": "nixos",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "b12141ef619e0a9c1c84dc8c684040326f27cdcc",
|
||||
"rev": "e2587caef70cea85dd97d7daab492899902dbf5d",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -475,18 +512,16 @@
|
||||
},
|
||||
"nixvimunstable": {
|
||||
"inputs": {
|
||||
"flake-parts": "flake-parts_3",
|
||||
"nixpkgs": [
|
||||
"nixunstable"
|
||||
],
|
||||
"systems": "systems_3"
|
||||
"flake-parts": "flake-parts_2",
|
||||
"nixpkgs": "nixpkgs_5",
|
||||
"systems": "systems_4"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1776830812,
|
||||
"narHash": "sha256-L2q0bpa6evlzE4IfIQ7JWqhTAuINggUSIxMmOAxUsCg=",
|
||||
"lastModified": 1785001306,
|
||||
"narHash": "sha256-xWqmquUtqKXLeDZ1oQUO+rV4sjA9TShIJhLL8M5Bozo=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nixvim",
|
||||
"rev": "53aad7a9aaadaec21d740117ba0f0531b9a9b3cd",
|
||||
"rev": "48409beb41e8e28b64e8160ca82d8a93fb628963",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -498,15 +533,15 @@
|
||||
},
|
||||
"nurpkgs": {
|
||||
"inputs": {
|
||||
"flake-parts": "flake-parts_4",
|
||||
"nixpkgs": "nixpkgs_3"
|
||||
"flake-parts": "flake-parts_3",
|
||||
"nixpkgs": "nixpkgs_6"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1776910402,
|
||||
"narHash": "sha256-SvRshrmzz9SmiiflE+Ph2RQ2YJkmQRpluebVt94mHPQ=",
|
||||
"lastModified": 1785034246,
|
||||
"narHash": "sha256-/Wul0/XyCTasQ4WYUMHksMffgOOhwJudIzwWT9HpCY4=",
|
||||
"owner": "nix-community",
|
||||
"repo": "NUR",
|
||||
"rev": "b3ab759ea8da0d514dbbcb89e269fd59676a92ae",
|
||||
"rev": "8020cdf42a4c803d7e48bf1375177145deb6cfac",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -521,10 +556,12 @@
|
||||
"buildbot": "buildbot",
|
||||
"colmena": "colmena",
|
||||
"darwin": "darwin_2",
|
||||
"flake-parts": "flake-parts_2",
|
||||
"flake-parts": "flake-parts",
|
||||
"hmunstable": "hmunstable",
|
||||
"minecraft": "minecraft",
|
||||
"niks3": "niks3",
|
||||
"nix-hardware": "nix-hardware",
|
||||
"nixpkgs-lib": "nixpkgs-lib_2",
|
||||
"nixunstable": "nixunstable",
|
||||
"nixvimunstable": "nixvimunstable",
|
||||
"nurpkgs": "nurpkgs",
|
||||
@@ -534,16 +571,16 @@
|
||||
},
|
||||
"stable": {
|
||||
"locked": {
|
||||
"lastModified": 1750133334,
|
||||
"narHash": "sha256-urV51uWH7fVnhIvsZIELIYalMYsyr2FCalvlRTzqWRw=",
|
||||
"lastModified": 1783625654,
|
||||
"narHash": "sha256-pI1244/PJfTyKhlAr2QYQC55vR6UQdnGA0rJUgtO2IQ=",
|
||||
"owner": "NixOS",
|
||||
"repo": "nixpkgs",
|
||||
"rev": "36ab78dab7da2e4e27911007033713bab534187b",
|
||||
"rev": "a0230bd8d5cbd13893b2263918d396a2c7dd0407",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "NixOS",
|
||||
"ref": "nixos-25.05",
|
||||
"ref": "release-26.05",
|
||||
"repo": "nixpkgs",
|
||||
"type": "github"
|
||||
}
|
||||
@@ -593,6 +630,22 @@
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"systems_4": {
|
||||
"locked": {
|
||||
"lastModified": 1774449309,
|
||||
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
|
||||
"owner": "nix-systems",
|
||||
"repo": "default",
|
||||
"rev": "c29398b59d2048c4ab79345812849c9bd15e9150",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "nix-systems",
|
||||
"ref": "future-26.11",
|
||||
"repo": "default",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"treefmt-nix": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
@@ -601,11 +654,32 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1775636079,
|
||||
"narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=",
|
||||
"lastModified": 1784369104,
|
||||
"narHash": "sha256-47cxbcZODibHv3rELFQ9vZly0vUNkND/atn/U7HLeb0=",
|
||||
"owner": "numtide",
|
||||
"repo": "treefmt-nix",
|
||||
"rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba",
|
||||
"rev": "df3c0640565d04a0261253cdd89fce78ec50168a",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "numtide",
|
||||
"repo": "treefmt-nix",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"treefmt-nix_2": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"niks3",
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1780220602,
|
||||
"narHash": "sha256-eynAfOmbmxJnkp7YewvCEbShNnnYJ9gLLqkzsYtBPeM=",
|
||||
"owner": "numtide",
|
||||
"repo": "treefmt-nix",
|
||||
"rev": "db947814a175b7ca6ded66e21383d938df01c227",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -616,14 +690,14 @@
|
||||
},
|
||||
"vsext": {
|
||||
"inputs": {
|
||||
"nixpkgs": "nixpkgs_4"
|
||||
"nixpkgs": "nixpkgs_7"
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1776828494,
|
||||
"narHash": "sha256-gQ5+syn8ndyF/+c5g5ZpeAScNKhkTF4/63JsO2hqGHo=",
|
||||
"lastModified": 1784949765,
|
||||
"narHash": "sha256-MB+0noLfsYMoMsBkyG5CKYZmSk7dSXendvvjfQFUiPw=",
|
||||
"owner": "nix-community",
|
||||
"repo": "nix-vscode-extensions",
|
||||
"rev": "ea6764d22ff5478f5db39ede57eeafc70d14e8e6",
|
||||
"rev": "242a696abba55b45d577b5292e90b597284f5f85",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
@@ -640,11 +714,11 @@
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1776910211,
|
||||
"narHash": "sha256-0ku3gW8bZ9TTpEU2fQw86oU6ZLT2vF6pacF+cLaf7VY=",
|
||||
"lastModified": 1784642409,
|
||||
"narHash": "sha256-hcbDqFuySAJawljt5r0sKBCJKYnbtGD0T/ZIozH1Dq0=",
|
||||
"owner": "nix-community",
|
||||
"repo": "NixOS-WSL",
|
||||
"rev": "4e6cad241baa0115a7aae8c55b04c166da4997c9",
|
||||
"rev": "eaeb18da90024448a60eb1ec7132eafa4003404e",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
|
||||
@@ -24,11 +24,10 @@
|
||||
inputs.nixpkgs.follows = "nixunstable";
|
||||
};
|
||||
minecraft.url = "github:Infinidoge/nix-minecraft";
|
||||
niks3.url = "github:Mic92/niks3";
|
||||
nix-hardware.url = "github:nixos/nixos-hardware";
|
||||
nixvimunstable = {
|
||||
url = "github:nix-community/nixvim/main";
|
||||
inputs.nixpkgs.follows = "nixunstable";
|
||||
};
|
||||
nixpkgs-lib.url = "github:nix-community/nixpkgs.lib";
|
||||
nixvimunstable.url = "github:nix-community/nixvim/main";
|
||||
nixunstable.url = "github:nixos/nixpkgs/nixos-unstable";
|
||||
nurpkgs.url = "github:nix-community/NUR";
|
||||
vsext.url = "github:nix-community/nix-vscode-extensions";
|
||||
@@ -63,7 +62,10 @@
|
||||
config = {
|
||||
allowUnfree = true;
|
||||
allowUnfreePredicate = _: true;
|
||||
permittedInsecurePackages = [ "ventoy-1.1.05" ];
|
||||
permittedInsecurePackages = [
|
||||
"ventoy-1.1.05"
|
||||
"electron-39.8.10"
|
||||
];
|
||||
};
|
||||
}
|
||||
);
|
||||
@@ -84,6 +86,7 @@
|
||||
self
|
||||
top
|
||||
;
|
||||
pkgs' = top.self.packages.x86_64-linux;
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -97,7 +100,7 @@
|
||||
{
|
||||
deployment = {
|
||||
inherit (v) tags;
|
||||
targetHost = v.ts;
|
||||
targetHost = if (v ? "nebulaIp") then v.nebulaIp else v.ts;
|
||||
targetUser = "greg";
|
||||
};
|
||||
}
|
||||
@@ -145,16 +148,17 @@
|
||||
pkgs = imported_packages.${system};
|
||||
};
|
||||
|
||||
packages = (import ./pkgs { inherit pkgs; });
|
||||
packages = (import ./pkgs { inherit pkgs top; });
|
||||
|
||||
checks = import ./checks.nix {
|
||||
inherit system top self';
|
||||
inherit (pkgs) lib;
|
||||
inherit (top.nixpkgs-lib) lib;
|
||||
};
|
||||
|
||||
devShells = import ./shells.nix {
|
||||
inherit pkgs;
|
||||
inherit (top) colmena;
|
||||
inherit (self') packages;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
+6
-16
@@ -4,14 +4,6 @@ builds:
|
||||
- "homeConfigurations.*"
|
||||
- "nixosConfigurations.*"
|
||||
- "packages.*"
|
||||
# bitwarden-cli package is broken on aarch64-darwin
|
||||
- "packages.aarch64-darwin.img-bitwarden"
|
||||
# kmod-31 is not a thing on Darwin
|
||||
- "packages.aarch64-darwin.qemu-hook"
|
||||
- "packages.aarch64-darwin.vfio_shutdown"
|
||||
- "packages.aarch64-darwin.vfio_startup"
|
||||
# This one is a bit of a beast and shouldn't take up Garnix time
|
||||
- "packages.aarch64-darwin.zim"
|
||||
# These are just images which I will build when
|
||||
# I feel like it
|
||||
- "devShells.*"
|
||||
@@ -20,14 +12,12 @@ builds:
|
||||
- darwinConfigurations.MacBook-Pro
|
||||
- darwinConfigurations.MacBook-Prolocal
|
||||
- darwinConfigurations.li
|
||||
# Some specific includes which are not specific enough to override the rules above,
|
||||
# due to the intrepretation of the glob excludes, but which I still need included
|
||||
# Some specific includes which are not specific enough to override the rules
|
||||
# above, due to the intrepretation of the glob excludes, but which I still
|
||||
# need included
|
||||
- include:
|
||||
# These are Mac homeConfigurations, which I do not have the infra to build at home
|
||||
# These are Mac homeConfigurations, which I do not have the infra
|
||||
# to build at home
|
||||
- homeConfigurations."gregory.hellings-mbp"
|
||||
- homeConfigurations.gregs-MacBook-Pro-16-inch-Nov-2024
|
||||
# These are builder images used on my Macs, but they can't always access the cache
|
||||
# on my local infrastructure, so I build them in Garnix so they are accessible
|
||||
# outside of my network, too
|
||||
- nixosConfigurations.builder-x86
|
||||
- nixosConfigurations.builder-aarch
|
||||
- homeConfigurations.ivr
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
# vim: set filetype=nushell :
|
||||
let servers = [isaiah jeremiah zeke genesis vm-gitlab]
|
||||
let servers = [isaiah jeremiah zeke genesis hosea]
|
||||
|
||||
def par-map [ items: list, c: closure ] {
|
||||
let results = $items | par-each -k $c
|
||||
@@ -12,15 +12,51 @@ def --env unlock [] {
|
||||
}
|
||||
}
|
||||
|
||||
def rebuild [] {
|
||||
def nebulaIps [] {
|
||||
open /etc/nixos/network.json | get hosts | items { |h, e| $e.nebulaIp? } | where $it != null | sort
|
||||
}
|
||||
|
||||
def genNebulaCert [ --ips: string, --name: string ] {
|
||||
let public = $'~/SynologyDrive/nebula/($name).key.pub' | path expand
|
||||
let private = $'~/SynologyDrive/nebula/($name).key' | path expand
|
||||
let cert = $'/etc/nixos/secrets/nebula/($name).crt'
|
||||
let ca_cert = '~/SynologyDrive/nebula/ca.crt' | path expand
|
||||
let ca_key = '~/SynologyDrive/nebula/ca.key' | path expand
|
||||
|
||||
# Generate public key if there isn't one already
|
||||
if ( not ($public | path exists) ) {
|
||||
nebula-cert keygen -out-key $private -out-pub $public
|
||||
}
|
||||
# Clear old cert if there is one
|
||||
if ( $cert | path exists) {
|
||||
rm $cert
|
||||
}
|
||||
|
||||
# Create and sign certs
|
||||
(nebula-cert sign
|
||||
-ca-crt $ca_cert
|
||||
-ca-key $ca_key
|
||||
-name $name
|
||||
-networks $ips
|
||||
-out-crt $cert
|
||||
-in-pub $public
|
||||
)
|
||||
|
||||
# Agenix update
|
||||
cd /etc/nixos/secrets
|
||||
cat $private | agenix -e $'nebula/($name).key.age'
|
||||
}
|
||||
|
||||
|
||||
def rebuild [ $target: string = "switch" ] {
|
||||
if (uname | get operating-system) == "Darwin" {
|
||||
sudo darwin-rebuild switch
|
||||
sudo darwin-rebuild $target
|
||||
} else {
|
||||
let hostname = uname | get nodename
|
||||
let build = ^nom build --keep-going $"/etc/nixos#nixosConfigurations.($hostname).config.system.build.toplevel"
|
||||
if $env.LAST_EXIT_CODE == 0 {
|
||||
nvd diff /run/current-system result
|
||||
run0 result/bin/switch-to-configuration switch
|
||||
run0 result/bin/switch-to-configuration $target
|
||||
} else {
|
||||
print "Error during build"
|
||||
}
|
||||
@@ -35,7 +71,8 @@ def deploy [ $host: string, $build: string = "" ] {
|
||||
if $buildhost == "linode" or $buildhost == "genesis" {
|
||||
$buildhost = "isaiah"
|
||||
}
|
||||
nixos-rebuild switch --sudo --use-substitutes --target-host $host --build-host $buildhost
|
||||
colmena apply --on $host
|
||||
#nixos-rebuild switch --sudo --use-substitutes --target-host $host --build-host $buildhost
|
||||
}
|
||||
|
||||
def ff [ $file: string ] {
|
||||
@@ -69,13 +106,6 @@ def dc [ $cmd: string = "sh" ] {
|
||||
}
|
||||
}
|
||||
|
||||
def claude [ ] {
|
||||
unlock
|
||||
$env.GITLAB_TOKEN = ^bw get item 7d3da4e9-5f9a-49d0-8e14-b39c010a4001 | from json | get fields | find claudeapi | get value
|
||||
$env.ANTHROPIC_API_KEY = ^bw get item e122fd08-3506-4f21-9c6a-b42b00fe5be1 | from json | get login.password
|
||||
^claude
|
||||
}
|
||||
|
||||
if ("/usr/local/bin" | path exists) {
|
||||
$env.PATH = $env.PATH | append "/usr/local/bin"
|
||||
}
|
||||
|
||||
@@ -26,6 +26,7 @@
|
||||
nixcopy = "nix copy --to \"s3://binary-cache/?profile=default&endpoint=nas.home%3A9000&scheme=http\"";
|
||||
r = "run0";
|
||||
updateScript = "nix-shell maintainers/scripts/update.nix --argstr package";
|
||||
p = "${lib.getExe pkgs.podman-tui}";
|
||||
|
||||
# General
|
||||
k = "kubectl";
|
||||
|
||||
+26
-25
@@ -5,7 +5,7 @@
|
||||
# This allows things like SSH in distrobox to read the config file just fine
|
||||
home.file.".ssh/config" = {
|
||||
target = ".ssh/config_source";
|
||||
onChange = ''cat ~/.ssh/config_source > ~/.ssh/config && chmod 600 ~/.ssh/config'';
|
||||
onChange = "cat ~/.ssh/config_source > ~/.ssh/config && chmod 600 ~/.ssh/config";
|
||||
};
|
||||
programs.ssh = {
|
||||
enable = true;
|
||||
@@ -13,24 +13,25 @@
|
||||
includes = [ "config.local" ];
|
||||
enableDefaultConfig = false;
|
||||
|
||||
matchBlocks =
|
||||
settings =
|
||||
let
|
||||
nas = {
|
||||
user = "admin";
|
||||
User = "admin";
|
||||
};
|
||||
owned = {
|
||||
user = "greg";
|
||||
User = "greg";
|
||||
};
|
||||
in
|
||||
{
|
||||
inherit nas;
|
||||
|
||||
"*" = {
|
||||
dynamicForwards = [ { port = 10240; } ];
|
||||
serverAliveInterval = 60;
|
||||
extraOptions = {
|
||||
DynamicForward = [ "10240" ];
|
||||
ForwardAgent = "yes";
|
||||
LogLevel = "error";
|
||||
SetEnv = "TERM=xterm-256color";
|
||||
ServerAliveInterval = 60;
|
||||
SetEnv = {
|
||||
TERM = "xterm-256color";
|
||||
};
|
||||
};
|
||||
|
||||
@@ -41,46 +42,46 @@
|
||||
"chronicles.thehellings.lan" = lib.hm.dag.entryBefore [ "*.thehellings.lan" ] nas;
|
||||
|
||||
gh = {
|
||||
user = "git";
|
||||
hostname = "github.com";
|
||||
User = "git";
|
||||
Hostname = "github.com";
|
||||
};
|
||||
"src" = {
|
||||
user = "git";
|
||||
hostname = "jeremiah.shire-zebra.ts.net";
|
||||
port = 32222;
|
||||
User = "git";
|
||||
Hostname = "jeremiah.shire-zebra.ts.net";
|
||||
Port = 32222;
|
||||
};
|
||||
srcpub = {
|
||||
user = "git";
|
||||
hostname = "src.thehellings.com";
|
||||
port = 2222;
|
||||
User = "git";
|
||||
Hostname = "src.thehellings.com";
|
||||
Port = 2222;
|
||||
};
|
||||
ivr = {
|
||||
user = "git";
|
||||
hostname = "gitlab.com";
|
||||
User = "git";
|
||||
Hostname = "gitlab.com";
|
||||
};
|
||||
|
||||
"ivr.thehellings.lan" = lib.hm.dag.entryBefore [ "ivr" ] {
|
||||
user = "gregory.hellings";
|
||||
User = "gregory.hellings";
|
||||
};
|
||||
|
||||
"*.thehellings.lan" = owned;
|
||||
"10.42.*" = owned;
|
||||
|
||||
"host.crosswire.org crosswire" = {
|
||||
hostname = "host.crosswire.org";
|
||||
user = "ghellings";
|
||||
Hostname = "host.crosswire.org";
|
||||
User = "ghellings";
|
||||
};
|
||||
|
||||
fedpeople = {
|
||||
hostname = "fedorapeople.org";
|
||||
user = "greghellings";
|
||||
Hostname = "fedorapeople.org";
|
||||
User = "greghellings";
|
||||
};
|
||||
|
||||
"src.fedoraproject.org pkgs.fedoraproject.org" = {
|
||||
user = "greghellings";
|
||||
User = "greghellings";
|
||||
};
|
||||
|
||||
"127.*".extraOptions = {
|
||||
"127.*" = {
|
||||
PubkeyAcceptedAlgorithms = "+ssh-rsa";
|
||||
HostkeyAlgorithms = "+ssh-rsa";
|
||||
};
|
||||
|
||||
@@ -8,7 +8,6 @@
|
||||
home.packages =
|
||||
with pkgs;
|
||||
[
|
||||
attic-client
|
||||
dig
|
||||
jqp
|
||||
kubernetes-helm
|
||||
|
||||
@@ -38,11 +38,6 @@ def _ivr2(args):
|
||||
vpn("gregory_hellings@ra.ivrtechnology.com", "IVR Technology")
|
||||
aliases['ivr2'] = _ivr2
|
||||
|
||||
def _glrestart(args):
|
||||
sudo nixos-container run gitlab -- systemctl restart gitlab
|
||||
sudo nixos-container run gitlab -- systemctl restart nginx
|
||||
aliases['glrestart'] = _glrestart
|
||||
|
||||
def _aws_creds(args):
|
||||
$AWS_ACCESS_KEY_ID=$(bw get username "AWS Access Key")
|
||||
$AWS_SECRET_ACCESS_KEY=$(bw get password "AWS Access Key")
|
||||
|
||||
+5
-6
@@ -10,7 +10,9 @@ let
|
||||
let
|
||||
inherit (metadata.hosts.${host}) system;
|
||||
pkgs = nixpkgs.${system};
|
||||
username = if builtins.hasAttr "user" metadata.hosts.${host} then metadata.hosts.${host}.user else "greg";
|
||||
pkgs' = top.self.packages.${system};
|
||||
username =
|
||||
if builtins.hasAttr "user" metadata.hosts.${host} then metadata.hosts.${host}.user else "greg";
|
||||
in
|
||||
top.hmunstable.lib.homeManagerConfiguration {
|
||||
inherit pkgs;
|
||||
@@ -24,6 +26,7 @@ let
|
||||
host
|
||||
username
|
||||
metadata
|
||||
pkgs'
|
||||
;
|
||||
nixvim = top.nixvimunstable;
|
||||
gui = false;
|
||||
@@ -31,8 +34,4 @@ let
|
||||
};
|
||||
};
|
||||
in
|
||||
(
|
||||
lib.genAttrs
|
||||
(builtins.attrNames (builtins.readDir ./hosts))
|
||||
user
|
||||
)
|
||||
(lib.genAttrs (builtins.attrNames (builtins.readDir ./hosts)) user)
|
||||
|
||||
+3
-2
@@ -1,5 +1,6 @@
|
||||
{
|
||||
pkgs,
|
||||
pkgs',
|
||||
lib,
|
||||
host ? "most",
|
||||
top,
|
||||
@@ -38,7 +39,7 @@ in
|
||||
gh
|
||||
git
|
||||
gnupatch
|
||||
hms
|
||||
pkgs'.hms
|
||||
btop
|
||||
inetutils
|
||||
jq
|
||||
@@ -46,7 +47,7 @@ in
|
||||
nix-prefetch
|
||||
nmap
|
||||
openssl
|
||||
setup-ssh
|
||||
pkgs'.setup-ssh
|
||||
tmux
|
||||
tree
|
||||
unzip
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
{...}: {}
|
||||
@@ -1,4 +1,4 @@
|
||||
{ pkgs, ... }:
|
||||
{ lib, pkgs, ... }:
|
||||
|
||||
{
|
||||
greg = {
|
||||
@@ -23,8 +23,11 @@
|
||||
mattermost-desktop
|
||||
minio-client
|
||||
mumble
|
||||
nebula
|
||||
nix-index
|
||||
pre-commit
|
||||
prismlauncher
|
||||
rclone
|
||||
restic
|
||||
restic-browser
|
||||
tea
|
||||
@@ -36,4 +39,13 @@
|
||||
settings.SKIP_HOST_UPDATE = true;
|
||||
};
|
||||
};
|
||||
xdg.desktopEntries = {
|
||||
prismlauncher = {
|
||||
name = "Prism Launcher - Minecraft";
|
||||
actions.minecraft = {
|
||||
name = "Minecraft";
|
||||
exec = lib.getExe pkgs.prismlauncher;
|
||||
};
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
{
|
||||
pkgs,
|
||||
pkgs',
|
||||
lib,
|
||||
username,
|
||||
...
|
||||
@@ -20,6 +21,7 @@
|
||||
claude-code
|
||||
direnv
|
||||
home-manager
|
||||
pkgs'.dockerCompat
|
||||
python3Packages.ipython
|
||||
just
|
||||
glab
|
||||
@@ -36,18 +38,22 @@
|
||||
".pip/pip.conf".text = ''
|
||||
[global]
|
||||
retries = 1
|
||||
index-url = https://pypi.python.org/simple
|
||||
index-url = https://pypi.python.org/
|
||||
extra-index-url =
|
||||
https://pypidev.ivrtechnology.com/simple/
|
||||
https://pypidev.ivrtechnology.com/
|
||||
'';
|
||||
".config/uv/uv.toml".text = ''
|
||||
index-strategy = "unsafe-first-match"
|
||||
[[index]]
|
||||
url = "https://pypidev.ivrtechnology.com/simple/"
|
||||
url = "https://pypidev.ivrtechnology.com/"
|
||||
name = "pypidev"
|
||||
ignore-error-codes = [403]
|
||||
'';
|
||||
};
|
||||
sessionVariables = {
|
||||
BW_GITLAB_ITEM = "7d3da4e9-5f9a-49d0-8e14-b39c010a4001";
|
||||
BW_ANTHROPIC_ITEM = "e122fd08-3506-4f21-9c6a-b42b00fe5be1";
|
||||
};
|
||||
username = username;
|
||||
homeDirectory = "/Users/${username}";
|
||||
};
|
||||
|
||||
@@ -1,4 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
}
|
||||
@@ -1,12 +1,15 @@
|
||||
{
|
||||
pkgs,
|
||||
pkgs',
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
let
|
||||
python = pkgs.python312.withPackages (p: with p; [
|
||||
python = pkgs.python312.withPackages (
|
||||
p: with p; [
|
||||
ipython
|
||||
]);
|
||||
]
|
||||
);
|
||||
in
|
||||
{
|
||||
# Disables hitting local cache
|
||||
@@ -24,20 +27,32 @@ in
|
||||
ansible
|
||||
awscli2
|
||||
cargo
|
||||
clippy
|
||||
direnv
|
||||
docker
|
||||
docker-compose
|
||||
docker-buildx
|
||||
go
|
||||
home-manager
|
||||
just
|
||||
mcp-grafana
|
||||
nil
|
||||
nixVersions.stable
|
||||
poetry
|
||||
pre-commit
|
||||
(pulumi.withPackages (p: with p; [
|
||||
(pulumi.withPackages (
|
||||
p: with p; [
|
||||
pulumi-aws-native
|
||||
pulumi-command
|
||||
pulumi-go
|
||||
pulumi-nodejs
|
||||
pulumi-python
|
||||
]))
|
||||
]
|
||||
))
|
||||
python
|
||||
rustc
|
||||
rustfmt
|
||||
terraform
|
||||
];
|
||||
};
|
||||
|
||||
|
||||
+12
-2
@@ -3,19 +3,24 @@
|
||||
lib,
|
||||
metadata,
|
||||
pkgs,
|
||||
top,
|
||||
...
|
||||
}:
|
||||
{
|
||||
imports = [
|
||||
../modules/nix-conf.nix
|
||||
top.niks3.nixosModules.niks3-auto-upload
|
||||
];
|
||||
|
||||
age.secrets.niks3-api-token.file = ../secrets/niks3/api_token.age;
|
||||
|
||||
console = {
|
||||
font = "Lat2-Terminus16";
|
||||
keyMap = "us";
|
||||
};
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
top.niks3.packages.${pkgs.stdenv.hostPlatform.system}.niks3
|
||||
agenix
|
||||
bitwarden-cli
|
||||
bmon
|
||||
@@ -26,10 +31,9 @@
|
||||
efibootmgr
|
||||
findutils
|
||||
file
|
||||
gcc-tune
|
||||
git
|
||||
gnupatch
|
||||
hms # My own home manager switcher
|
||||
top.self.packages.${pkgs.stdenv.hostPlatform.system}.hms # My own home manager switcher
|
||||
iperf
|
||||
killall
|
||||
nano
|
||||
@@ -97,6 +101,12 @@
|
||||
# Enable the OpenSSH daemon for remote control
|
||||
services = {
|
||||
locate.enable = true;
|
||||
niks3-auto-upload = {
|
||||
enable = config.greg.nix.cache;
|
||||
authTokenFile = config.age.secrets.niks3-api-token.path;
|
||||
serverUrl = "http://hosea.nebula.thehellings.com:5751";
|
||||
verifyS3Integrity = true;
|
||||
};
|
||||
openssh = {
|
||||
enable = true;
|
||||
settings.X11Forwarding = true;
|
||||
|
||||
+8
-33
@@ -15,15 +15,22 @@ let
|
||||
}:
|
||||
let
|
||||
inherit (metadata.hosts.${name}) system;
|
||||
pkgs' = top.self.packages.${system};
|
||||
in
|
||||
channel.lib.nixosSystem {
|
||||
pkgs = nixpkgs.${system};
|
||||
specialArgs = {
|
||||
inherit metadata top lib';
|
||||
inherit
|
||||
metadata
|
||||
top
|
||||
lib'
|
||||
pkgs'
|
||||
;
|
||||
};
|
||||
modules = [
|
||||
{
|
||||
nixpkgs.hostPlatform = system;
|
||||
networking.hostName = name;
|
||||
}
|
||||
# Imported ones
|
||||
top.agenix.nixosModules.default
|
||||
@@ -45,16 +52,6 @@ in
|
||||
})
|
||||
)
|
||||
)
|
||||
// (lib.genAttrs
|
||||
(builtins.attrNames (lib.filterAttrs (_: v: v == "directory") (builtins.readDir ./vm)))
|
||||
(
|
||||
name:
|
||||
(unstable {
|
||||
inherit name;
|
||||
extraMods = [ ./vm/${name} ];
|
||||
})
|
||||
)
|
||||
)
|
||||
// {
|
||||
# nix build '.#nixosConfigurations.wsl.config.system.build.installer'
|
||||
#nixos = wsl { name = "wsl"; };
|
||||
@@ -63,26 +60,4 @@ in
|
||||
# name = "wsl";
|
||||
# system = "aarch64-linux";
|
||||
#};
|
||||
|
||||
builder-aarch = lib.nixosSystem {
|
||||
system = "aarch64-linux";
|
||||
modules = [
|
||||
"${top.nixunstable}/nixos/modules/profiles/nix-builder-vm.nix"
|
||||
{
|
||||
virtualisation.host.pkgs = import top.nixunstable { system = "aarch64-darwin"; };
|
||||
boot.loader.grub.devices = [ "/dev/vda" ];
|
||||
}
|
||||
];
|
||||
};
|
||||
|
||||
builder-x86 = lib.nixosSystem {
|
||||
system = "x86_64-linux";
|
||||
modules = [
|
||||
"${top.nixunstable}/nixos/modules/profiles/nix-builder-vm.nix"
|
||||
{
|
||||
virtualisation.host.pkgs = import top.nixunstable { system = "aarch64-darwin"; };
|
||||
boot.loader.grub.devices = [ "/dev/vda" ];
|
||||
}
|
||||
];
|
||||
};
|
||||
}
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
{ config, modulesPath, pkgs, lib, ... }:
|
||||
{
|
||||
imports = [ (modulesPath + "/virtualisation/proxmox-lxc.nix") ];
|
||||
nix.settings = { sandbox = false; };
|
||||
proxmoxLXC = {
|
||||
manageNetwork = false;
|
||||
privileged = true;
|
||||
};
|
||||
services.fstrim.enable = false; # Let Proxmox host handle fstrim
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
openFirewall = true;
|
||||
settings = {
|
||||
PermitRootLogin = "yes";
|
||||
PasswordAuthentication = true;
|
||||
PermitEmptyPasswords = "yes";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -12,10 +12,6 @@
|
||||
top.nix-hardware.nixosModules.framework-11th-gen-intel
|
||||
];
|
||||
|
||||
age.secrets = {
|
||||
compose-attic.file = ../../../secrets/compose/attic.env.age;
|
||||
};
|
||||
|
||||
boot = {
|
||||
loader = {
|
||||
systemd-boot = {
|
||||
@@ -43,10 +39,6 @@
|
||||
enable = true;
|
||||
tags = [ "mobile" ];
|
||||
};
|
||||
runner = {
|
||||
enable = true;
|
||||
qemu = true;
|
||||
};
|
||||
};
|
||||
|
||||
hardware = {
|
||||
|
||||
@@ -2,7 +2,12 @@
|
||||
# your system. Help is available in the configuration.nix(5) man page
|
||||
# and in the NixOS manual (accessible by running ‘nixos-help’).
|
||||
|
||||
{ top, pkgs, ... }:
|
||||
{
|
||||
top,
|
||||
pkgs,
|
||||
pkgs',
|
||||
...
|
||||
}:
|
||||
{
|
||||
imports = [
|
||||
# Include the results of the hardware scan.
|
||||
@@ -31,7 +36,7 @@
|
||||
};
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
create_ssl
|
||||
pkgs'.create_ssl
|
||||
step-ca
|
||||
];
|
||||
|
||||
@@ -57,6 +62,7 @@
|
||||
serverProperties = {
|
||||
allow-flight = true;
|
||||
motd = "Maya's Minecraft World";
|
||||
online-mode = true;
|
||||
};
|
||||
whitelist = { };
|
||||
|
||||
@@ -123,9 +129,14 @@
|
||||
# Better storage engines
|
||||
# https://www.curseforge.com/minecraft/mc-mods/refined-storage
|
||||
refined-storage = pkgs.fetchurl {
|
||||
url = "https://mediafilez.forgecdn.net/files/7961/605/refinedstorage-fabric-3.0.0-beta.5.jar";
|
||||
hash = "sha256-UiXNrGw/giCZAnCjFzFc9k4mrq6deTtL6Z00arSUFOU=";
|
||||
url = "https://mediafilez.forgecdn.net/files/8086/588/refinedstorage-fabric-3.0.0.jar";
|
||||
hash = "sha256-LuOF0aYQon78AQeD5fQ8OXHCnekfa+PNKpH7cqimFNs=";
|
||||
};
|
||||
# https://www.curseforge.com/minecraft/mc-mods/storage-drawers
|
||||
#storagedrawers = pkgs.fetchurl {
|
||||
#url = "https://mediafilez.forgecdn.net/files/7352/799/StorageDrawers-fabric-1.21.11-20.0.0.jar";
|
||||
#hash = "sha256-eBKCmAtjAhdAjOyLMRneu/NZnNt+orIezxPy6V8g/S8=";
|
||||
#};
|
||||
survivalfly = pkgs.fetchurl {
|
||||
url = "https://mediafilez.forgecdn.net/files/7870/312/survivalfly-1.3_fabric-mc26.1.1.jar";
|
||||
hash = "sha256-Kai4wSxckpXbs1yLp8wJ4BmmjNkdDbeqerqWGIz3+Zk=";
|
||||
|
||||
@@ -22,8 +22,6 @@
|
||||
|
||||
# VMs
|
||||
10.42.4.1 matrix matrix.thehellings.lan
|
||||
#10.42.4.2 vm-jellyfin vm-jellyfin.thehellings.lan
|
||||
10.42.4.3 git gitlab git.thehellings.lan gitlab.thehellings.lan
|
||||
|
||||
# VIP
|
||||
10.42.5.1 longhorn.cluster matrix.cluster pgadmin.cluter postgres.cluster immich.cluster
|
||||
@@ -37,7 +35,6 @@
|
||||
100.88.91.27 dns.home
|
||||
100.70.99.91 exodus.home exodus.shire-zebra.ts.net
|
||||
100.96.198.104 genesis.home genesis.shire-zebra.ts.net smart.home zwave.home nixcache.home gitcache.home dashy.home uptime.home speed.home
|
||||
100.117.28.111 gitlab.home gitlab.shire-zebra.ts.net gitlab.thehellings.lan registry.thehellings.lan git.thehellings.lan
|
||||
100.68.203.1 hosea.home hosea.shire-zebra.ts.net grafana.home
|
||||
100.84.183.79 isaiah.home isaiah.shire-zebra.ts.net pgadmin.kubernetes longhorn.kubernetes
|
||||
100.102.186.39 jeremiah.home jeremiah.shire-zebra.ts.net matrix.kubernetes immich.kubernetes postgres.kubernetes buildbot.home
|
||||
|
||||
@@ -22,6 +22,7 @@ let
|
||||
#"1.0.0.1" # Cloudflare
|
||||
#"149.112.112.112" # Quad 9
|
||||
metadata.infra.gw # Currently using our UniFi router for DNS as well
|
||||
"100.100.100.100"
|
||||
];
|
||||
in
|
||||
{
|
||||
@@ -115,16 +116,21 @@ in
|
||||
"@\tIN\tSOA\t${config.networking.hostName}\tgreg@thehellings.com (1 1m 1m 1m 1m)"
|
||||
"\tIN\tNS\t${config.networking.hostName}"
|
||||
];
|
||||
makeHost = host: "${host.name}\tIN\tA\t${host.address}";
|
||||
makeHost =
|
||||
host:
|
||||
[ "${host.name}\tIN\tA\t${host.address}" ]
|
||||
++ lib.map (a: "${a}\tIN\tA\t${host.address}") (
|
||||
if builtins.hasAttr "aliases" host then host.aliases else [ ]
|
||||
);
|
||||
in
|
||||
pkgs.writeText "${domain}" (
|
||||
builtins.concatStringsSep "\n" (preamble ++ (lib.map makeHost hosts) ++ [ "" ])
|
||||
builtins.concatStringsSep "\n" (preamble ++ (lib.flatten (lib.map makeHost hosts)) ++ [ "" ])
|
||||
);
|
||||
in
|
||||
lib.mapAttrs
|
||||
(domain: net: {
|
||||
master = true;
|
||||
file = makeZoneFile (lib'.hostsByNet net metadata.hosts) domain;
|
||||
file = makeZoneFile (lib'.hostsByNet net (metadata.hosts // metadata.external)) domain;
|
||||
})
|
||||
{
|
||||
"shire-zebra.ts.net" = "tailscale";
|
||||
|
||||
@@ -1,70 +0,0 @@
|
||||
{
|
||||
lib,
|
||||
metadata,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
let
|
||||
ips = lib.filterAttrs (_k: v: v ? "ip" && v.ip != null) metadata.hosts;
|
||||
tps = lib.filterAttrs (_k: v: v ? "ts" && v.ts != null) metadata.hosts;
|
||||
get = field: set: lib.mapAttrsToList (_k: v: v.${field}) set;
|
||||
getTS = get "ts" tps;
|
||||
getIP = get "ip" ips;
|
||||
whitelists = builtins.concatStringsSep "," (
|
||||
[
|
||||
"localhost"
|
||||
"127.0.0.1"
|
||||
]
|
||||
++ getTS
|
||||
++ getIP
|
||||
);
|
||||
in
|
||||
{
|
||||
services = {
|
||||
prowlarr = {
|
||||
enable = true;
|
||||
dataDir = "/arr/prowlarr";
|
||||
openFirewall = true;
|
||||
};
|
||||
radarr = {
|
||||
enable = true;
|
||||
openFirewall = true;
|
||||
};
|
||||
transmission = {
|
||||
enable = true;
|
||||
openPeerPorts = true;
|
||||
openRPCPort = true;
|
||||
package = pkgs.transmission_4;
|
||||
settings = {
|
||||
download-dir = "/arr/transmission/downloads";
|
||||
rpc-bind-address = "0.0.0.0";
|
||||
rpc-host-whitelist = whitelists;
|
||||
rpc-host-whitelist-enabled = false;
|
||||
rpc-whitelist = whitelists;
|
||||
rpc-whitelist-enabled = false;
|
||||
watch-dir-enabled = true;
|
||||
watch-dir = "/arr/transmission/incoming";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
systemd.mounts =
|
||||
let
|
||||
nfs = name: {
|
||||
what = "nas1.shire-zebra.ts.net:/mnt/all/${name}";
|
||||
type = "nfs";
|
||||
name = "${name}.mount";
|
||||
where = "/${name}";
|
||||
requires = [ "tailscaled-autoconnect.service" ];
|
||||
after = [ "tailscaled-autoconnect.service" ];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
mountConfig.Options = "_netdev,noexec,timeo=50,retrans=5,soft";
|
||||
};
|
||||
in
|
||||
[
|
||||
(nfs "arr")
|
||||
(nfs "music")
|
||||
(nfs "photos")
|
||||
(nfs "video")
|
||||
];
|
||||
}
|
||||
@@ -6,6 +6,7 @@
|
||||
config,
|
||||
metadata,
|
||||
pkgs,
|
||||
top,
|
||||
...
|
||||
}:
|
||||
let
|
||||
@@ -17,14 +18,32 @@ in
|
||||
{
|
||||
imports = [
|
||||
# Include the results of the hardware scan.
|
||||
./arr.nix
|
||||
./hardware-configuration.nix
|
||||
top.niks3.nixosModules.niks3
|
||||
];
|
||||
|
||||
age.secrets.grafana-secret-key = {
|
||||
age.secrets = {
|
||||
cache-private-key = {
|
||||
file = ../../../secrets/cache-private-key.age;
|
||||
owner = "niks3";
|
||||
};
|
||||
grafana-secret-key = {
|
||||
file = ../../../secrets/grafana-secret-key.age;
|
||||
owner = "grafana";
|
||||
};
|
||||
niks3-access-key-id = {
|
||||
file = ../../../secrets/niks3/access_key_id.age;
|
||||
owner = "niks3";
|
||||
};
|
||||
niks3-api-token = {
|
||||
file = ../../../secrets/niks3/api_token.age;
|
||||
owner = "niks3";
|
||||
};
|
||||
niks3-secret-access-key = {
|
||||
file = ../../../secrets/niks3/secret_access_key.age;
|
||||
owner = "niks3";
|
||||
};
|
||||
};
|
||||
|
||||
# Bootloader
|
||||
boot = {
|
||||
@@ -98,6 +117,7 @@ in
|
||||
];
|
||||
};
|
||||
};
|
||||
firewall.interfaces.nebula0.allowedTCPPorts = [ 5751 ];
|
||||
nameservers = [ metadata.infra.dns ];
|
||||
};
|
||||
|
||||
@@ -150,6 +170,27 @@ in
|
||||
analytics.reporting_enabled = false;
|
||||
};
|
||||
};
|
||||
niks3 = {
|
||||
enable = true;
|
||||
|
||||
apiTokenFile = config.age.secrets.niks3-api-token.path;
|
||||
gc.enable = false;
|
||||
httpAddr = "${metadata.hosts.hosea.nebulaIp}:5751";
|
||||
nginx = {
|
||||
enable = true;
|
||||
domain = "hosea.nebula";
|
||||
enableACME = false;
|
||||
forceSSL = false;
|
||||
};
|
||||
s3 = {
|
||||
accessKeyFile = config.age.secrets.niks3-access-key-id.path;
|
||||
bucket = "niks3";
|
||||
endpoint = "nas1.shire-zebra.ts.net:30188";
|
||||
secretKeyFile = config.age.secrets.niks3-secret-access-key.path;
|
||||
useSSL = false;
|
||||
};
|
||||
signKeyFiles = [ config.age.secrets.cache-private-key.path ];
|
||||
};
|
||||
prometheus.exporters.graphite.enable = true;
|
||||
# Configure keymap
|
||||
xserver.xkb = {
|
||||
@@ -158,6 +199,25 @@ in
|
||||
};
|
||||
};
|
||||
|
||||
systemd.mounts =
|
||||
let
|
||||
nfs = name: {
|
||||
what = "nas1.shire-zebra.ts.net:/mnt/all/${name}";
|
||||
type = "nfs";
|
||||
name = "${name}.mount";
|
||||
where = "/${name}";
|
||||
requires = [ "tailscaled-autoconnect.service" ];
|
||||
after = [ "tailscaled-autoconnect.service" ];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
mountConfig.Options = "_netdev,noexec,timeo=50,retrans=5,soft";
|
||||
};
|
||||
in
|
||||
[
|
||||
(nfs "music")
|
||||
(nfs "photos")
|
||||
(nfs "video")
|
||||
];
|
||||
|
||||
# After first deploy: create a Grafana service account + API token for Klaatu
|
||||
# via the Grafana UI, then encrypt it: agenix -e secrets/grafana-api-token.age
|
||||
age.secrets.grafana-api-token = {
|
||||
|
||||
@@ -1,11 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
# Bootloader.
|
||||
boot = {
|
||||
loader.grub = {
|
||||
enable = true;
|
||||
device = "/dev/sda";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -1,28 +0,0 @@
|
||||
# Edit this configuration file to define what should be installed on
|
||||
# your system. Help is available in the configuration.nix(5) man page
|
||||
# and in the NixOS manual (accessible by running ‘nixos-help’).
|
||||
|
||||
{ pkgs, ... }:
|
||||
|
||||
{
|
||||
imports = [
|
||||
# Include the results of the hardware scan.
|
||||
./hardware-configuration.nix
|
||||
./boot.nix
|
||||
./filesystem.nix
|
||||
./location.nix
|
||||
./networking.nix
|
||||
./wiki.nix
|
||||
];
|
||||
|
||||
# Define a user account. Don't forget to set a password with ‘passwd’.
|
||||
users.users.greg = {
|
||||
isNormalUser = true;
|
||||
description = "Gregory Hellings";
|
||||
extraGroups = [
|
||||
"networkmanager"
|
||||
"wheel"
|
||||
];
|
||||
packages = with pkgs; [ ];
|
||||
};
|
||||
}
|
||||
@@ -1,13 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
let
|
||||
in
|
||||
{
|
||||
fileSystems."serve" = {
|
||||
#device = "10.42.1.4:/volume1/icdm-mysql/";
|
||||
#fsType = "nfs";
|
||||
device = "/dev/sdb1";
|
||||
fsType = "auto";
|
||||
mountPoint = "/srv";
|
||||
};
|
||||
}
|
||||
@@ -1,53 +0,0 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
modulesPath,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
|
||||
|
||||
boot.initrd.availableKernelModules = [
|
||||
"xhci_pci"
|
||||
"ehci_pci"
|
||||
"ahci"
|
||||
"usbhid"
|
||||
"usb_storage"
|
||||
"sd_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ "kvm-intel" ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
fileSystems."/" = {
|
||||
device = "/dev/disk/by-uuid/dab0d455-e25e-4445-8fa4-5320047d7e7b";
|
||||
fsType = "btrfs";
|
||||
options = [ "subvol=@" ];
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/5aedbb07-5761-423b-909d-2560405eae32";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
fileSystems."/var" = {
|
||||
device = "/dev/disk/by-uuid/57968536-c29d-417d-997e-85223d1d1f65";
|
||||
fsType = "btrfs";
|
||||
};
|
||||
|
||||
swapDevices = [ { device = "/dev/disk/by-uuid/09691dce-375a-43c6-8d40-4498d20a6d9a"; } ];
|
||||
|
||||
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
|
||||
# (the default) this is the recommended approach. When using systemd-networkd it's
|
||||
# still possible to use this option, but it's recommended to use it in conjunction
|
||||
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
|
||||
networking.useDHCP = lib.mkDefault true;
|
||||
# networking.interfaces.eno1.useDHCP = lib.mkDefault true;
|
||||
# networking.interfaces.wlp2s0.useDHCP = lib.mkDefault true;
|
||||
|
||||
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
||||
}
|
||||
@@ -1,15 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
# Set your time zone.
|
||||
time.timeZone = "America/Chicago";
|
||||
|
||||
# Select internationalisation properties.
|
||||
i18n.defaultLocale = "en_US.UTF-8";
|
||||
|
||||
# Configure keymap in X11
|
||||
services.xserver.xkb = {
|
||||
layout = "us";
|
||||
variant = "";
|
||||
};
|
||||
}
|
||||
@@ -1,63 +0,0 @@
|
||||
{ ... }:
|
||||
let
|
||||
dnsHosts = builtins.concatStringsSep "\n" [ "wiki.icdm.lan 10.42.101.1" ];
|
||||
in
|
||||
{
|
||||
# If we have to do proxying in Bayonnais, we can start to work on that here
|
||||
# networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
|
||||
networking = {
|
||||
hostName = "icdm-root";
|
||||
useDHCP = false;
|
||||
defaultGateway = "10.42.1.1";
|
||||
nameservers = [
|
||||
"100.100.100.100"
|
||||
"10.42.1.2"
|
||||
];
|
||||
enableIPv6 = false;
|
||||
|
||||
interfaces = {
|
||||
eno1.ipv4.addresses = [
|
||||
{
|
||||
address = "10.42.101.1";
|
||||
prefixLength = 16;
|
||||
}
|
||||
{
|
||||
address = "10.77.1.2";
|
||||
prefixLength = 16;
|
||||
}
|
||||
];
|
||||
};
|
||||
# Allow traffic through
|
||||
firewall = {
|
||||
enable = true;
|
||||
allowedTCPPorts = [ 53 ];
|
||||
allowedUDPPorts = [
|
||||
53
|
||||
67
|
||||
];
|
||||
};
|
||||
|
||||
extraHosts = "${dnsHosts}";
|
||||
};
|
||||
|
||||
services.dnsmasq = {
|
||||
enable = true;
|
||||
settings = {
|
||||
domain = "icdm.lan";
|
||||
dhcp-range = [ "eno1,10.77.1.10,10.77.1.255,255.255.0.0,12h" ];
|
||||
dhcp-option = [
|
||||
"eno1,option:router,10.77.1.1"
|
||||
"eno1,option:dns-server,10.77.1.2,1.1.1.1"
|
||||
"eno1,option:domain-search,icdm.lan"
|
||||
];
|
||||
expand-hosts = true;
|
||||
log-dhcp = true;
|
||||
log-queries = true;
|
||||
# Upstream servers
|
||||
server = [
|
||||
"1.1.1.1"
|
||||
"8.8.4.4"
|
||||
];
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -1,17 +0,0 @@
|
||||
{ pkgs, ... }:
|
||||
let
|
||||
wikiHost = "wiki.icdm.lan";
|
||||
kiwixport = 8080;
|
||||
in
|
||||
{
|
||||
services.kiwix-serve = {
|
||||
enable = true;
|
||||
port = kiwixport;
|
||||
library = {
|
||||
inherit (pkgs) zim;
|
||||
};
|
||||
};
|
||||
|
||||
greg.proxies."${wikiHost}".target = "http://localhost:${toString kiwixport}";
|
||||
networking.firewall.allowedTCPPorts = [ 80 ];
|
||||
}
|
||||
@@ -43,10 +43,6 @@
|
||||
tags = [ "home" ];
|
||||
};
|
||||
remote-builder.enable = true;
|
||||
runner = {
|
||||
enable = true;
|
||||
qemu = true;
|
||||
};
|
||||
gitea-runner = {
|
||||
enable = true;
|
||||
extraLabels = [ "bare-metal:host" ];
|
||||
|
||||
@@ -22,8 +22,6 @@ in
|
||||
];
|
||||
|
||||
age.secrets = {
|
||||
runner-reg.file = ../../../secrets/gitlab/nixos-qemu-shell.age;
|
||||
|
||||
gitea-buildbotWorkersFile = mk ../../../secrets/gitea/buildbotWorkersFile.age;
|
||||
gitea-oauthToken = mk ../../../secrets/gitea/oauthToken.age;
|
||||
gitea-oauthSecret = mk ../../../secrets/gitea/oauthSecret.age;
|
||||
@@ -90,16 +88,12 @@ in
|
||||
priority = 254;
|
||||
};
|
||||
nebula.enable = true;
|
||||
proxies."buildbot.nebula.thehellings.com".target = "http://buildbot.nebula.thehellings.com:8010/";
|
||||
tailscale = {
|
||||
enable = true;
|
||||
tags = [ "home" ];
|
||||
};
|
||||
remote-builder.enable = true;
|
||||
runner = {
|
||||
enable = true;
|
||||
threads = 3;
|
||||
qemu = true;
|
||||
};
|
||||
};
|
||||
|
||||
hardware = {
|
||||
@@ -149,7 +143,7 @@ in
|
||||
updateOutputs = false;
|
||||
};
|
||||
};
|
||||
domain = "${config.networking.hostName}.shire-zebra.ts.net";
|
||||
domain = "buildbot.nebula.thehellings.com:8010";
|
||||
evalMaxMemorySize = 8192;
|
||||
evalWorkerCount = 4;
|
||||
gitea = {
|
||||
@@ -162,7 +156,7 @@ in
|
||||
webhookSecretFile = config.age.secrets.gitea-webhookSecret.path;
|
||||
};
|
||||
showTrace = true;
|
||||
#webhookBaseUrl = "http://${config.networking.hostName}.shire-zebra.ts.net:8010";
|
||||
#webhookBaseUrl = "http://${config.networking.hostName}.nebula.thehellings.com:8010";
|
||||
workersFile = config.age.secrets.gitea-buildbotWorkersFile.path;
|
||||
};
|
||||
worker = {
|
||||
|
||||
@@ -66,20 +66,4 @@
|
||||
immichUrl = "https://immich.shire-zebra.ts.net";
|
||||
};
|
||||
};
|
||||
|
||||
security.sudo.extraRules = [
|
||||
{
|
||||
users = [ "gitlab-runner" ];
|
||||
commands = [
|
||||
{
|
||||
command = "/run/current-system/sw/bin/systemctl";
|
||||
options = [ "NOPASSWD" ];
|
||||
}
|
||||
{
|
||||
command = "/run/current-system/sw/bin/podman";
|
||||
options = [ "NOPASSWD" ];
|
||||
}
|
||||
];
|
||||
}
|
||||
];
|
||||
}
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
{ ... }:
|
||||
{ config, ... }:
|
||||
|
||||
let
|
||||
srcDomain = "src.thehellings.com";
|
||||
@@ -6,15 +6,23 @@ let
|
||||
in
|
||||
{
|
||||
greg.proxies."${srcDomain}" = {
|
||||
target = "https://gitea.shire-zebra.ts.net";
|
||||
target = "http://unix:${config.services.anubis.instances.git.settings.BIND}";
|
||||
ssl = true;
|
||||
genAliases = false;
|
||||
extraConfig = ''
|
||||
proxy_ssl_verify off;
|
||||
proxy_ssl_server_name on;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header X-Forwarded-Ssl on;
|
||||
#proxy_ssl_verify off;
|
||||
#proxy_ssl_server_name on;
|
||||
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Http-Version $server_protocol;
|
||||
proxy_set_header User-Agent $http_user_agent;
|
||||
client_max_body_size 100000m;
|
||||
|
||||
#proxy_set_header Host $host;
|
||||
#proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
#proxy_set_header X-Forwarded-Proto $scheme;
|
||||
#proxy_set_header X-Forwarded-Ssl on;
|
||||
|
||||
# Ultimate AI Block List v1.7 20250924
|
||||
# https://perishablepress.com/ultimate-ai-block-list/
|
||||
|
||||
@@ -87,18 +95,22 @@ in
|
||||
|
||||
networking.firewall.allowedTCPPorts = [ sshPort ];
|
||||
|
||||
systemd.services = {
|
||||
haproxy = {
|
||||
after = [
|
||||
"network-online.target"
|
||||
];
|
||||
wants = [
|
||||
"network-online.target"
|
||||
];
|
||||
services = {
|
||||
anubis = {
|
||||
instances = {
|
||||
git = {
|
||||
enable = true;
|
||||
settings = {
|
||||
BIND = "/run/anubis/anubis-git/anubis.sock";
|
||||
COOKIE_DOMAIN = "thehellings.com";
|
||||
SERVE_ROBOTS_TXT = true;
|
||||
TARGET = "https://gitea.shire-zebra.ts.net/";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
services.haproxy = {
|
||||
haproxy = {
|
||||
enable = true;
|
||||
config = ''
|
||||
global
|
||||
@@ -119,4 +131,18 @@ in
|
||||
server git-zeke zeke.shire-zebra.ts.net:32222
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
systemd.services = {
|
||||
haproxy = {
|
||||
after = [
|
||||
"network-online.target"
|
||||
];
|
||||
wants = [
|
||||
"network-online.target"
|
||||
];
|
||||
};
|
||||
};
|
||||
|
||||
users.users.nginx.extraGroups = [ config.users.groups.anubis.name ];
|
||||
}
|
||||
|
||||
@@ -2,12 +2,24 @@
|
||||
# them by the following commands:
|
||||
# nix run nixpkgs.matrix-synapse
|
||||
# register_new_matrix_user -k "B9EoPr2WV9hzwc7uL2Sx1JmvCeKDEOGCpB0uginQcQtEH4wzRtkSIdo7lltrjSQa" http://localhost:8448
|
||||
{ config, lib, ... }:
|
||||
{ config, ... }:
|
||||
let
|
||||
domain = "${config.networking.domain}";
|
||||
fqdn = "matrix.${domain}";
|
||||
in
|
||||
{
|
||||
greg.proxies."${fqdn}" = {
|
||||
extraConfig = ''
|
||||
error_log /var/log/nginx/debug.log debug;
|
||||
proxy_ssl_verify off;
|
||||
proxy_ssl_server_name on;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header X-Forwarded-Ssl on;
|
||||
'';
|
||||
genAliases = false;
|
||||
ssl = true;
|
||||
target = "https://matrix.shire-zebra.ts.net";
|
||||
};
|
||||
services.nginx = {
|
||||
virtualHosts = {
|
||||
# Server the '.well-known' files to find the Matrix API server
|
||||
@@ -44,36 +56,6 @@ in
|
||||
return 200 '${builtins.toJSON client}';
|
||||
'';
|
||||
};
|
||||
|
||||
# Reverse proxy in front of the actual Matrix server
|
||||
"${fqdn}" = {
|
||||
enableACME = true;
|
||||
forceSSL = true;
|
||||
|
||||
extraConfig = ''
|
||||
error_log /var/log/nginx/debug.log debug;
|
||||
'';
|
||||
|
||||
# Not the appropriate place for the chat client
|
||||
locations =
|
||||
(builtins.listToAttrs (
|
||||
builtins.map
|
||||
(
|
||||
val:
|
||||
lib.nameValuePair "/_${val}" {
|
||||
proxyPass = "http://matrix.kubernetes";
|
||||
}
|
||||
)
|
||||
[
|
||||
"matrix"
|
||||
"synapse"
|
||||
"dendrite"
|
||||
]
|
||||
))
|
||||
// {
|
||||
"/".extraConfig = "return 404;";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -24,7 +24,6 @@ in
|
||||
virtualisation.oci-containers = {
|
||||
backend = "podman";
|
||||
containers."homepage" = {
|
||||
# needs explicit port to match what gitlab-runner sees when pulling
|
||||
image = "registry.thehellings.com:443/greg/homepage/gregs-homepage:latest";
|
||||
ports = [ "${homepage}:80" ];
|
||||
};
|
||||
@@ -35,10 +34,5 @@ in
|
||||
ssl = true;
|
||||
genAliases = false;
|
||||
};
|
||||
"doubles.thehellings.com" = {
|
||||
target = "http://localhost:8081";
|
||||
ssl = true;
|
||||
genAliases = false;
|
||||
};
|
||||
};
|
||||
}
|
||||
|
||||
@@ -1,7 +1,12 @@
|
||||
{ config, pkgs, ... }:
|
||||
{
|
||||
config,
|
||||
pkgs,
|
||||
pkgs',
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
environment.systemPackages = [ pkgs.upgrade-pg-cluster ];
|
||||
environment.systemPackages = [ pkgs'.upgrade-pg-cluster ];
|
||||
|
||||
services.postgresql = {
|
||||
enable = true;
|
||||
|
||||
@@ -1,60 +0,0 @@
|
||||
# Edit this configuration file to define what should be installed on
|
||||
# your system. Help is available in the configuration.nix(5) man page
|
||||
# and in the NixOS manual (accessible by running ‘nixos-help’).
|
||||
|
||||
{ pkgs, ... }:
|
||||
|
||||
{
|
||||
imports = [
|
||||
# Include the results of the hardware scan.
|
||||
./hardware-configuration.nix
|
||||
];
|
||||
|
||||
# Bootloader.
|
||||
boot.loader = {
|
||||
systemd-boot.enable = true;
|
||||
efi.canTouchEfiVariables = true;
|
||||
};
|
||||
|
||||
environment.systemPackages = with pkgs; [
|
||||
];
|
||||
|
||||
greg = {
|
||||
home = true;
|
||||
tailscale = {
|
||||
enable = true;
|
||||
tags = [ "home" ];
|
||||
};
|
||||
};
|
||||
|
||||
networking = {
|
||||
hostName = "proxmoxtemplate"; # Define your hostname.
|
||||
# defaultGateway = {
|
||||
# address = " 10.42.1.2";
|
||||
# interface = "enp6s18";
|
||||
# };
|
||||
# interfaces = {
|
||||
# enp6s18 = {
|
||||
# ipv4.addresses = [
|
||||
# {
|
||||
# address = "10.42.1.8";
|
||||
# prefixLength = 16;
|
||||
# }
|
||||
# ];
|
||||
# };
|
||||
# };
|
||||
nameservers = [ "10.42.1.5" ];
|
||||
};
|
||||
|
||||
services.qemuGuest.enable = true;
|
||||
|
||||
system.stateVersion = "24.11"; # Did you read the comment?
|
||||
|
||||
# Define a user account. Don't forget to set a password with ‘passwd’.
|
||||
users.users.greg = {
|
||||
isNormalUser = true;
|
||||
description = "Greg Hellings";
|
||||
extraGroups = [ "wheel" ];
|
||||
packages = with pkgs; [ ];
|
||||
};
|
||||
}
|
||||
@@ -1,50 +0,0 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{
|
||||
lib,
|
||||
modulesPath,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/profiles/qemu-guest.nix")
|
||||
];
|
||||
|
||||
boot.initrd.availableKernelModules = [
|
||||
"uhci_hcd"
|
||||
"ehci_pci"
|
||||
"ahci"
|
||||
"virtio_pci"
|
||||
"virtio_scsi"
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ ];
|
||||
boot.extraModulePackages = [ ];
|
||||
|
||||
fileSystems."/" = {
|
||||
device = "/dev/disk/by-uuid/507251f1-efe7-448d-8de8-91ee582a9afb";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/7115-EFA6";
|
||||
fsType = "vfat";
|
||||
options = [
|
||||
"fmask=0077"
|
||||
"dmask=0077"
|
||||
];
|
||||
};
|
||||
|
||||
swapDevices = [ ];
|
||||
|
||||
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
|
||||
# (the default) this is the recommended approach. When using systemd-networkd it's
|
||||
# still possible to use this option, but it's recommended to use it in conjunction
|
||||
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
|
||||
networking.useDHCP = lib.mkDefault true;
|
||||
# networking.interfaces.enp6s18.useDHCP = lib.mkDefault true;
|
||||
}
|
||||
@@ -28,10 +28,6 @@
|
||||
};
|
||||
nebula.enable = true;
|
||||
remote-builder.enable = true;
|
||||
runner = {
|
||||
enable = true;
|
||||
vbox = false;
|
||||
};
|
||||
tailscale = {
|
||||
enable = true;
|
||||
tags = [ "home" ];
|
||||
|
||||
@@ -1,273 +0,0 @@
|
||||
# Edit this configuration file to define what should be installed on
|
||||
# your system. Help is available in the configuration.nix(5) man page
|
||||
# and in the NixOS manual (accessible by running ‘nixos-help’).
|
||||
|
||||
{
|
||||
config,
|
||||
pkgs,
|
||||
lib,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
registryPort = 5000;
|
||||
vpnIp = "100.117.28.111";
|
||||
in
|
||||
{
|
||||
imports = [
|
||||
./hardware-configuration.nix
|
||||
];
|
||||
|
||||
age.secrets =
|
||||
let
|
||||
cfg = n: {
|
||||
file = ../../../secrets/gitlab/${n}.age;
|
||||
owner = "gitlab";
|
||||
group = "gitlab";
|
||||
mode = "0444";
|
||||
};
|
||||
in
|
||||
{
|
||||
gitlab-secret = cfg "secret";
|
||||
gitlab-otp = cfg "otp";
|
||||
gitlab-db = cfg "db";
|
||||
gitlab-db-password = cfg "db-password";
|
||||
gitlab-jws = cfg "jws";
|
||||
gitlab-key = cfg "key";
|
||||
gitlab-cert = cfg "cert";
|
||||
gitlab-salt = cfg "salt";
|
||||
gitlab-primary-key = cfg "primary-key";
|
||||
gitlab-deterministic-key = cfg "deterministic-key";
|
||||
|
||||
minio_access_key_id = {
|
||||
file = ../../../secrets/minio_access_key_id.age;
|
||||
owner = "gitlab";
|
||||
group = "gitlab";
|
||||
mode = "0444";
|
||||
};
|
||||
minio_secret_access_key = {
|
||||
file = ../../../secrets/minio_secret_access_key.age;
|
||||
owner = "gitlab";
|
||||
group = "gitlab";
|
||||
mode = "0444";
|
||||
};
|
||||
};
|
||||
|
||||
greg = {
|
||||
backup.jobs.nas-backup = {
|
||||
src = "/var/gitlab/state/backup/";
|
||||
dest = "gitlab";
|
||||
};
|
||||
home = true;
|
||||
tailscale = {
|
||||
enable = true;
|
||||
tags = [ "home" ];
|
||||
};
|
||||
};
|
||||
|
||||
networking = {
|
||||
hostName = "gitlab"; # Define your hostname.
|
||||
firewall.allowedTCPPorts = [
|
||||
80
|
||||
registryPort
|
||||
];
|
||||
};
|
||||
|
||||
services = {
|
||||
gitlab = {
|
||||
enable = true;
|
||||
backup = {
|
||||
keepTime = 288;
|
||||
startAt = [ "03:00" ];
|
||||
};
|
||||
databaseHost = "postgres.kubernetes";
|
||||
databaseName = "gitlab";
|
||||
databaseUsername = "gitlab";
|
||||
databasePasswordFile = config.age.secrets.gitlab-db-password.path;
|
||||
databaseCreateLocally = false;
|
||||
extraConfig = {
|
||||
registry.port = null;
|
||||
gitlab = {
|
||||
trustedProxies = [
|
||||
"${vpnIp}/32" # The system itself
|
||||
"100.109.86.8/32" # Public server's IP
|
||||
];
|
||||
};
|
||||
object_store = {
|
||||
enabled = true;
|
||||
proxy_download = true; # Tell them to reach out to object storage themselves!
|
||||
connection = {
|
||||
provider = "AWS";
|
||||
endpoint = "http://s3.thehellings.lan:9000";
|
||||
region = "us-east-1";
|
||||
aws_access_key_id = {
|
||||
_secret = config.age.secrets.minio_access_key_id.path;
|
||||
};
|
||||
aws_secret_access_key = {
|
||||
_secret = config.age.secrets.minio_secret_access_key.path;
|
||||
};
|
||||
path_style = true; # True for MinIO
|
||||
aws_signature_version = 2;
|
||||
};
|
||||
#storage_options = ...;
|
||||
objects = builtins.listToAttrs (
|
||||
builtins.map
|
||||
(
|
||||
x: lib.attrsets.nameValuePair x { bucket = "gitlab-${builtins.replaceStrings [ "_" ] [ "-" ] x}"; }
|
||||
)
|
||||
[
|
||||
"artifacts"
|
||||
"ci_secure_files"
|
||||
"dependency_proxy"
|
||||
"external_diffs"
|
||||
"lfs"
|
||||
"packages"
|
||||
"pages"
|
||||
"terraform_state"
|
||||
"uploads"
|
||||
]
|
||||
);
|
||||
};
|
||||
};
|
||||
host = "src.thehellings.com";
|
||||
https = true;
|
||||
initialRootEmail = "greg@thehellings.com";
|
||||
initialRootPasswordFile = pkgs.writeText "initialRootPassword" "root_password";
|
||||
pages = {
|
||||
enable = true;
|
||||
settings.pages-domain = "pages.thehellings.com";
|
||||
};
|
||||
port = 443;
|
||||
puma = {
|
||||
threadsMax = 6;
|
||||
threadsMin = 2;
|
||||
workers = 6;
|
||||
};
|
||||
redisUrl = "unix:${config.services.redis.servers.gitlab.unixSocket}";
|
||||
registry = {
|
||||
enable = true;
|
||||
certFile = config.age.secrets.gitlab-cert.path;
|
||||
keyFile = config.age.secrets.gitlab-key.path;
|
||||
externalAddress = "registry.thehellings.com";
|
||||
externalPort = 443;
|
||||
};
|
||||
secrets = {
|
||||
activeRecordDeterministicKeyFile = config.age.secrets.gitlab-deterministic-key.path;
|
||||
activeRecordPrimaryKeyFile = config.age.secrets.gitlab-primary-key.path;
|
||||
activeRecordSaltFile = config.age.secrets.gitlab-salt.path;
|
||||
dbFile = config.age.secrets.gitlab-db.path;
|
||||
jwsFile = config.age.secrets.gitlab-jws.path;
|
||||
otpFile = config.age.secrets.gitlab-otp.path;
|
||||
secretFile = config.age.secrets.gitlab-secret.path;
|
||||
};
|
||||
};
|
||||
|
||||
nginx = {
|
||||
enable = true;
|
||||
clientMaxBodySize = "25000m";
|
||||
virtualHosts = {
|
||||
"vm-gitlab.shire-zebra.ts.net" = {
|
||||
listen = [
|
||||
{
|
||||
addr = "0.0.0.0";
|
||||
port = 443;
|
||||
ssl = true;
|
||||
}
|
||||
];
|
||||
locations."/" = {
|
||||
proxyPass = "http://unix:/run/gitlab/gitlab-workhorse.socket";
|
||||
recommendedProxySettings = true;
|
||||
};
|
||||
extraConfig = ''
|
||||
ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ;
|
||||
ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ;
|
||||
client_max_body_size 10000m ;
|
||||
'';
|
||||
};
|
||||
"registry" = {
|
||||
listen = [
|
||||
{
|
||||
addr = "0.0.0.0";
|
||||
port = registryPort;
|
||||
ssl = true;
|
||||
}
|
||||
];
|
||||
locations."/" = {
|
||||
proxyPass = "http://127.0.0.1:4567/";
|
||||
recommendedProxySettings = true;
|
||||
};
|
||||
extraConfig = ''
|
||||
ssl_certificate /etc/certs/vm-gitlab.shire-zebra.ts.net.crt ;
|
||||
ssl_certificate_key /etc/certs/vm-gitlab.shire-zebra.ts.net.key ;
|
||||
client_max_body_size 25000m ;
|
||||
'';
|
||||
serverAliases = [
|
||||
"vm-gitlab.shire-zebra.ts.net"
|
||||
];
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
openssh.enable = true;
|
||||
|
||||
postgresql.enable = true;
|
||||
|
||||
qemuGuest.enable = true;
|
||||
|
||||
redis.servers.gitlab = {
|
||||
enable = true;
|
||||
};
|
||||
|
||||
#resolved.enable = true;
|
||||
};
|
||||
|
||||
# Do not start nginx until we have tailscaled up and running, so it can bind
|
||||
# to the 100.* addresses
|
||||
systemd = {
|
||||
services = {
|
||||
certRefresh =
|
||||
let
|
||||
script = pkgs.writeShellApplication {
|
||||
name = "cert-refresh";
|
||||
runtimeInputs = [ pkgs.tailscale ];
|
||||
|
||||
text = ''
|
||||
cd /etc/certs
|
||||
tailscale cert vm-gitlab.shire-zebra.ts.net
|
||||
chown nginx ./*
|
||||
systemctl reload nginx
|
||||
'';
|
||||
};
|
||||
in
|
||||
{
|
||||
script = lib.getExe script;
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
User = "root";
|
||||
};
|
||||
};
|
||||
|
||||
nginx = rec {
|
||||
after = [ "network-online.target" ];
|
||||
requires = [ "network-online.target" ];
|
||||
wants = after;
|
||||
serviceConfig = {
|
||||
RestartMaxDelaySec = "30s";
|
||||
RestartSteps = "5";
|
||||
};
|
||||
};
|
||||
tailscaled.partOf = [ "network-online.target" ];
|
||||
};
|
||||
|
||||
timers = {
|
||||
"cert-refresh" = {
|
||||
wantedBy = [ "cert-refresh.service" ];
|
||||
timerConfig = {
|
||||
OnCalendar = "monthly";
|
||||
Persistent = true;
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
system.stateVersion = lib.mkForce "24.11";
|
||||
}
|
||||
@@ -1,58 +0,0 @@
|
||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
||||
# and may be overwritten by future invocations. Please make changes
|
||||
# to /etc/nixos/configuration.nix instead.
|
||||
{
|
||||
lib,
|
||||
modulesPath,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
imports = [
|
||||
(modulesPath + "/profiles/qemu-guest.nix")
|
||||
];
|
||||
|
||||
# Bootloader.
|
||||
boot = {
|
||||
extraModulePackages = [ ];
|
||||
initrd = {
|
||||
availableKernelModules = [
|
||||
"uhci_hcd"
|
||||
"ehci_pci"
|
||||
"ahci"
|
||||
"virtio_pci"
|
||||
"virtio_scsi"
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
kernelModules = [ ];
|
||||
};
|
||||
loader = {
|
||||
efi.canTouchEfiVariables = true;
|
||||
systemd-boot.enable = true;
|
||||
};
|
||||
};
|
||||
|
||||
fileSystems."/" = {
|
||||
device = lib.mkDefault "/dev/disk/by-uuid/1fdbe86e-ce6f-4af3-a876-aec35731adab";
|
||||
fsType = "ext4";
|
||||
};
|
||||
|
||||
fileSystems."/boot" = {
|
||||
device = "/dev/disk/by-uuid/1E6A-C3BB";
|
||||
fsType = "vfat";
|
||||
options = [
|
||||
"fmask=0077"
|
||||
"dmask=0077"
|
||||
];
|
||||
};
|
||||
|
||||
swapDevices = [ ];
|
||||
|
||||
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
|
||||
# (the default) this is the recommended approach. When using systemd-networkd it's
|
||||
# still possible to use this option, but it's recommended to use it in conjunction
|
||||
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
|
||||
networking.useDHCP = lib.mkDefault true;
|
||||
# networking.interfaces.enp6s18.useDHCP = lib.mkDefault true;
|
||||
}
|
||||
@@ -15,6 +15,7 @@
|
||||
(name: value: {
|
||||
inherit name;
|
||||
address = builtins.getAttr netAttr value;
|
||||
aliases = lib.optionals (builtins.hasAttr "aliases" value) (builtins.getAttr "aliases" value);
|
||||
})
|
||||
(
|
||||
lib.filterAttrs (
|
||||
|
||||
@@ -21,9 +21,6 @@ spec:
|
||||
spec:
|
||||
containers:
|
||||
- name: bitwarden-cli
|
||||
# Since my gitlab instance depends on the database hosted in k3s, and
|
||||
# the database depends on this image, I need a way to bootstrap the
|
||||
# system if # I am doing disaster recovery. And this is it.
|
||||
image: "ghcr.io/greg-hellings/nixos-config/img-bitwarden:latest"
|
||||
#image: >-
|
||||
# registry.thehellings.com/greg/nixos-config/img-bitwarden:latest
|
||||
|
||||
@@ -14,14 +14,12 @@ spec:
|
||||
- 100.88.91.27 # dns?
|
||||
- 100.80.99.48 # exodus
|
||||
- 100.88.91.27 # genesis
|
||||
- 100.117.28.111 # gitlab
|
||||
- 100.68.203.1 # hosea
|
||||
- 100.84.183.79 # isaiah
|
||||
- 100.102.186.39 # jeremiah
|
||||
- 100.90.74.19 # zeke
|
||||
- 100.115.57.8 # linode
|
||||
- 100.65.5.38 # matrix
|
||||
#- 100.127.55.22 # jellyfin
|
||||
---
|
||||
apiVersion: traefik.io/v1alpha1
|
||||
kind: IngressRouteTCP
|
||||
|
||||
@@ -4,7 +4,6 @@ resources:
|
||||
- namespace.yaml
|
||||
- secrets.yaml
|
||||
- postgres-cluster.yaml
|
||||
- postgres-gitlab.yaml
|
||||
- postgres-pgadmin.yaml
|
||||
- postgres-matrix.yaml
|
||||
- ingress.yaml
|
||||
|
||||
@@ -11,13 +11,6 @@ spec:
|
||||
|
||||
managed:
|
||||
roles:
|
||||
- name: gitlab
|
||||
ensure: present
|
||||
comment: Gitlab user
|
||||
login: true
|
||||
superuser: false
|
||||
passwordSecret:
|
||||
name: postgres-user-gitlab
|
||||
- name: pgadmin
|
||||
ensure: present
|
||||
comment: PG Admin user
|
||||
|
||||
@@ -1,9 +0,0 @@
|
||||
apiVersion: postgresql.cnpg.io/v1
|
||||
kind: Database
|
||||
metadata:
|
||||
name: database-gitlab
|
||||
spec:
|
||||
name: gitlab
|
||||
owner: gitlab
|
||||
cluster:
|
||||
name: postgres
|
||||
@@ -1,39 +1,5 @@
|
||||
apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: postgres-user-gitlab
|
||||
namespace: db
|
||||
spec:
|
||||
target:
|
||||
name: postgres-user-gitlab
|
||||
deletionPolicy: Delete
|
||||
template:
|
||||
type: Opaque
|
||||
data:
|
||||
username: |-
|
||||
{{ .username }}
|
||||
password: |-
|
||||
{{ .password }}
|
||||
data:
|
||||
- secretKey: username
|
||||
sourceRef:
|
||||
storeRef:
|
||||
name: bitwarden-login
|
||||
kind: ClusterSecretStore
|
||||
remoteRef:
|
||||
key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57
|
||||
property: username
|
||||
- secretKey: password
|
||||
sourceRef:
|
||||
storeRef:
|
||||
name: bitwarden-login
|
||||
kind: ClusterSecretStore
|
||||
remoteRef:
|
||||
key: 5282ad16-c2dc-49d3-8fb3-b2e9012bab57
|
||||
property: password
|
||||
---
|
||||
apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: postgres-user-matrix
|
||||
namespace: db
|
||||
|
||||
@@ -15,7 +15,7 @@ spec:
|
||||
chart:
|
||||
spec:
|
||||
chart: gitea
|
||||
version: "12.5.3"
|
||||
version: "12.6.0"
|
||||
sourceRef:
|
||||
kind: HelmRepository
|
||||
name: gitea-repository
|
||||
@@ -35,7 +35,7 @@ spec:
|
||||
storageClass: longhorn-default
|
||||
|
||||
image:
|
||||
tag: "1.25.5"
|
||||
tag: "1.26.2"
|
||||
|
||||
replicaCount: 1
|
||||
|
||||
@@ -66,8 +66,8 @@ spec:
|
||||
APP_NAME: "Gitea: Greg's Cup of Git"
|
||||
RUN_MODE: dev
|
||||
server:
|
||||
DOMAIN: "thehellings.com"
|
||||
ROOT_URL: "https://src.thehellings.com"
|
||||
DOMAIN: "shire-zebra.ts.net"
|
||||
ROOT_URL: "https://gitea.shire-zebra.ts.net"
|
||||
SSH_PORT: "2222"
|
||||
database:
|
||||
DB_TYPE: postgres
|
||||
|
||||
@@ -76,4 +76,3 @@ spec:
|
||||
secretKeyRef:
|
||||
name: gitea-config
|
||||
key: minio_secret
|
||||
|
||||
|
||||
@@ -1,64 +0,0 @@
|
||||
apiVersion: source.toolkit.fluxcd.io/v1
|
||||
kind: HelmRepository
|
||||
metadata:
|
||||
name: gitlab-runner
|
||||
spec:
|
||||
interval: "24h"
|
||||
url: https://charts.gitlab.io
|
||||
---
|
||||
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||
kind: HelmRelease
|
||||
metadata:
|
||||
name: gitlab-runner
|
||||
spec:
|
||||
interval: 10m
|
||||
chart:
|
||||
spec:
|
||||
chart: gitlab-runner
|
||||
version: "0.83.1"
|
||||
sourceRef:
|
||||
kind: HelmRepository
|
||||
name: gitlab-runner
|
||||
interval: "1h"
|
||||
dependsOn:
|
||||
- name: external-secrets
|
||||
namespace: external-secrets
|
||||
- name: tailscae
|
||||
namespace: tailscale
|
||||
values:
|
||||
crds:
|
||||
create: true
|
||||
includeCRDs: true
|
||||
gitlabUrl: https://src.thehellings.com
|
||||
runners:
|
||||
secret: gitlab-runner
|
||||
imagePullSecrets:
|
||||
- name: image-pull-secrets
|
||||
rbac:
|
||||
create: true
|
||||
serviceAccount:
|
||||
create: true
|
||||
metrics:
|
||||
enabled: true
|
||||
extraEnv:
|
||||
CACHE_TYPE: s3
|
||||
CACHE_SHARED: "true"
|
||||
CACHE_S3_BUCKET_NAME: gitlab-runner-cache
|
||||
CACHE_S3_INSECURE: "true"
|
||||
extraEnvFrom:
|
||||
PACKER_GITHUB_API_TOKEN:
|
||||
secretKeyRef:
|
||||
name: gitlab-runner
|
||||
key: PACKER_GITHUB_API_TOKEN
|
||||
CACHE_S3_SERVER_ADDRESS:
|
||||
secretKeyRef:
|
||||
name: gitlab-runner
|
||||
key: CACHE_S3_SERVER_ADDRESS
|
||||
CACHE_S3_ACCESS_KEY:
|
||||
secretKeyRef:
|
||||
name: s3-access
|
||||
key: username
|
||||
CACHE_S3_SECRET_KEY:
|
||||
secretKeyRef:
|
||||
name: s3-access
|
||||
key: password
|
||||
@@ -1,6 +0,0 @@
|
||||
namespace: gitlab-runner
|
||||
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- secrets.yaml
|
||||
- chart.yaml
|
||||
@@ -1,4 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: gitlab-runner
|
||||
@@ -1,101 +0,0 @@
|
||||
apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: gitlab-runner
|
||||
namespace: gitlab-runner
|
||||
spec:
|
||||
secretStoreRef:
|
||||
name: bitwarden-fields
|
||||
kind: ClusterSecretStore
|
||||
target:
|
||||
name: gitlab-runner
|
||||
deletionPolicy: Delete
|
||||
template:
|
||||
type: Opaque
|
||||
data:
|
||||
runner-registration-token: ""
|
||||
runner-token: "{{ .runnerToken }}"
|
||||
PACKER_GITHUB_API_TOKEN: "{{ .PACKER_GITHUB_API_TOKEN }}"
|
||||
CACHE_S3_SERVER_ADDRESS: "{{ .CACHE_S3_SERVER_ADDRESS }}"
|
||||
data:
|
||||
- secretKey: runnerToken
|
||||
remoteRef:
|
||||
key: &key 53719920-b100-4355-8c80-b2f9002fad22
|
||||
property: CI_SERVER_TOKEN
|
||||
- secretKey: PACKER_GITHUB_API_TOKEN
|
||||
remoteRef:
|
||||
key: *key
|
||||
property: PACKER_GITHUB_API_TOKEN
|
||||
- secretKey: CACHE_S3_SERVER_ADDRESS
|
||||
remoteRef:
|
||||
key: *key
|
||||
property: CACHE_S3_SERVER_ADDRESS
|
||||
# Includes
|
||||
# CI_SERVER_TOKEN
|
||||
# PACKER_GITHUB_API_TOKEN
|
||||
# CACHE_S3_SERVER_ADDRESS
|
||||
---
|
||||
apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: s3-access
|
||||
namespace: gitlab-runner
|
||||
spec:
|
||||
secretStoreRef:
|
||||
name: bitwarden-login
|
||||
kind: ClusterSecretStore
|
||||
target:
|
||||
name: s3-access
|
||||
deletionPolicy: Delete
|
||||
data:
|
||||
- secretKey: username
|
||||
remoteRef:
|
||||
key: &key 04dd39c2-268d-4a33-aa4c-b1550166139f
|
||||
property: username
|
||||
- secretKey: password
|
||||
remoteRef:
|
||||
key: *key
|
||||
property: password
|
||||
---
|
||||
apiVersion: external-secrets.io/v1
|
||||
kind: ExternalSecret
|
||||
metadata:
|
||||
name: image-pull-secrets
|
||||
namespace: gitlab-runner
|
||||
spec:
|
||||
secretStoreRef:
|
||||
name: bitwarden-login
|
||||
kind: ClusterSecretStore
|
||||
target:
|
||||
deletionPolicy: Delete
|
||||
template:
|
||||
type: kubernetes.io/dockerconfigjson
|
||||
data:
|
||||
.dockerconfigjson: >-
|
||||
{
|
||||
"auths": {
|
||||
"https://index.docker.io/v1/": {
|
||||
"username": "{{ .user }}",
|
||||
"password": "{{ .password }}",
|
||||
"email": "greg.hellings@gmail.com",
|
||||
"auth": "{{ .auth }}"
|
||||
}
|
||||
}
|
||||
}
|
||||
data:
|
||||
- secretKey: user
|
||||
remoteRef:
|
||||
key: &key f560ae38-368c-4e58-898c-aeb90012d597
|
||||
property: username
|
||||
- secretKey: password
|
||||
remoteRef:
|
||||
key: *key
|
||||
property: password
|
||||
- secretKey: auth
|
||||
sourceRef:
|
||||
storeRef:
|
||||
name: bitwarden-fields
|
||||
kind: ClusterSecretStore
|
||||
remoteRef:
|
||||
key: *key
|
||||
property: auth
|
||||
@@ -27,7 +27,7 @@ spec:
|
||||
chart:
|
||||
spec:
|
||||
chart: longhorn
|
||||
version: "1.11.1"
|
||||
version: "1.11.2"
|
||||
sourceRef:
|
||||
kind: HelmRepository
|
||||
name: longhorn
|
||||
|
||||
@@ -7,7 +7,6 @@ resources:
|
||||
- mariadb-operator
|
||||
- databases
|
||||
- matrix
|
||||
#- gitlab-runner
|
||||
- immich
|
||||
- monitoring
|
||||
- pinchflat
|
||||
|
||||
@@ -19,6 +19,7 @@ spec:
|
||||
kind: HelmRepository
|
||||
name: mariadb-operator
|
||||
interval: "1h"
|
||||
version: "26.3.0"
|
||||
---
|
||||
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||
kind: HelmRelease
|
||||
@@ -33,6 +34,7 @@ spec:
|
||||
kind: HelmRepository
|
||||
name: mariadb-operator
|
||||
interval: "1h"
|
||||
version: "26.3.0"
|
||||
dependsOn:
|
||||
- name: mariadb-operator-crds
|
||||
- name: longhorn
|
||||
|
||||
@@ -11,6 +11,7 @@ spec:
|
||||
kind: HelmRepository
|
||||
name: mariadb-operator
|
||||
interval: "1h"
|
||||
version: "26.3.0"
|
||||
dependsOn:
|
||||
- name: mariadb-operator-crds
|
||||
- name: mariadb-operator
|
||||
|
||||
@@ -77,6 +77,7 @@ in
|
||||
|
||||
programs.firefox = {
|
||||
enable = true; # (!pkgs.stdenv.hostPlatform.isDarwin);
|
||||
configPath = if pkgs.stdenv.hostPlatform.isDarwin then "${config.home.homeDirectory}/Library/Application Support/Firefox" else "${config.xdg.configHome}/mozilla/firefox";
|
||||
package = pkgs.firefox-bin;
|
||||
policies = {
|
||||
DisableAppUpdate = true;
|
||||
|
||||
@@ -316,6 +316,26 @@
|
||||
name = "Buildbot";
|
||||
url = "http://jeremiah.shire-zebra.ts.net:8010/";
|
||||
}
|
||||
{
|
||||
name = "Garage WebUI";
|
||||
url = "http://nas1.shire-zebra.ts.net:30186/";
|
||||
}
|
||||
{
|
||||
name = "Garage RPC";
|
||||
url = "http://nas1.shire-zebra.ts.net:30187/";
|
||||
}
|
||||
{
|
||||
name = "Garage S3 API";
|
||||
url = "http://nas1.shire-zebra.ts.net:30188/";
|
||||
}
|
||||
{
|
||||
name = "Garage S3 Web";
|
||||
url = "http://nas1.shire-zebra.ts.net:30189/";
|
||||
}
|
||||
{
|
||||
name = "Garage Admin";
|
||||
url = "http://nas1.shire-zebra.ts.net:30190/";
|
||||
}
|
||||
];
|
||||
}
|
||||
{
|
||||
@@ -399,16 +419,24 @@
|
||||
name = "Media";
|
||||
bookmarks = [
|
||||
{
|
||||
name = "Prowlarr";
|
||||
url = "https://hosea.shire-zebra.ts.net:9696/";
|
||||
name = "Flaresolverr";
|
||||
url = "http://nas1.shire-zebra.ts.net:30098";
|
||||
}
|
||||
{
|
||||
name = "Transmission";
|
||||
url = "https://hosea.shire-zebra.ts.net:9091/";
|
||||
name = "Prowlarr";
|
||||
url = "http://nas1.shire-zebra.ts.net:30050/";
|
||||
}
|
||||
{
|
||||
name = "Sonarr (TV)";
|
||||
url = "http://nas1.shire-zebra.ts.net:30113/";
|
||||
}
|
||||
{
|
||||
name = "Radarr (Movies)";
|
||||
url = "https://hosea.shire-zebra.ts.net:7878/";
|
||||
url = "http://nas1.shire-zebra.ts.net:30025/";
|
||||
}
|
||||
{
|
||||
name = "Deluge";
|
||||
url = "http://nas1.shire-zebra.ts.net:30038/";
|
||||
}
|
||||
];
|
||||
}
|
||||
|
||||
+14
-6
@@ -9,6 +9,7 @@
|
||||
let
|
||||
builderHosts = lib.filterAttrs (_n: v: (builtins.hasAttr "builder" v) && v.builder) metadata.hosts;
|
||||
cfg = config.greg.nix;
|
||||
hostname = x: if cfg.cache then "${x}.shire-zebra.ts.net" else "${x}.thehellings.lan";
|
||||
in
|
||||
{
|
||||
options.greg.nix = {
|
||||
@@ -22,7 +23,7 @@ in
|
||||
programs.ssh.extraConfig = builtins.concatStringsSep "\n" (
|
||||
lib.map (x: ''
|
||||
Host ${x}-builder
|
||||
Hostname ${x}.shire-zebra.ts.net
|
||||
Hostname ${hostname x}
|
||||
User remote-builder-user
|
||||
'') (lib.attrNames builderHosts)
|
||||
);
|
||||
@@ -57,12 +58,18 @@ in
|
||||
"gregory.hellings"
|
||||
]; # For home and for work machines
|
||||
substituters =
|
||||
(if cfg.cache then [
|
||||
(
|
||||
if cfg.cache then
|
||||
[
|
||||
#"http://chronicles.shire-zebra.ts.net:9000/binary-cache/"
|
||||
"http://nas1.shire-zebra.ts.net:8080/default"
|
||||
] else [
|
||||
"http://nas1.thehellings.lan:8080/default"
|
||||
])
|
||||
"http://niks3.nas1.shire-zebra.ts.net:30189/"
|
||||
#"http://nas1.shire-zebra.ts.net:8080/default"
|
||||
]
|
||||
else
|
||||
[
|
||||
"http://niks3.nas1.thehellings.lan:30189/"
|
||||
]
|
||||
)
|
||||
++ [
|
||||
"https://ai.cachix.org"
|
||||
"https://nixpkgs-python.cachix.org"
|
||||
@@ -72,6 +79,7 @@ in
|
||||
"https://nixhelm.cachix.org"
|
||||
];
|
||||
trusted-public-keys = [
|
||||
"niks3:8iztr/NACwYEK5O7JJtGFGuv+ho/cmwql8NeoCiXNto="
|
||||
#"chronicles.shire-zebra.ts.net:0qWYHn3gGllXChhAaaxKlNZtRy6yG/XJs1RFSqV3nW8="
|
||||
"default:DTGxNijw2D8FrZJPT1pFTWcLqbt60tovL+9Z+VW0HRY="
|
||||
"ai.cachix.org-1:N9dzRK+alWwoKXQlnn0H6aUx0lU/mspIoz8hMvGvbbc="
|
||||
|
||||
@@ -10,7 +10,6 @@
|
||||
./ceph.nix
|
||||
./db.nix
|
||||
./gitea-runner.nix
|
||||
./gitlab-runner.nix
|
||||
./gnome.nix
|
||||
./home.nix
|
||||
./kde.nix
|
||||
|
||||
@@ -45,22 +45,27 @@ in
|
||||
"debian-latest:docker://node:25-trixie"
|
||||
|
||||
"ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
|
||||
"ubuntu-26.04:docker://docker.gitea.com/runner-images:ubuntu-26.04"
|
||||
"ubuntu-24.04:docker://docker.gitea.com/runner-images:ubuntu-24.04"
|
||||
"ubuntu-22.04:docker://docker.gitea.com/runner-images:ubuntu-22.04"
|
||||
|
||||
"ubuntu-full-latest:docker://ghcr.io/catthehacker/ubuntu:full-latest"
|
||||
"ubuntu-full-26.04:docker://ghcr.io/catthehacker/ubuntu:full-26.04"
|
||||
"ubuntu-full-24.04:docker://ghcr.io/catthehacker/ubuntu:full-24.04"
|
||||
"ubuntu-full-22.04:docker://ghcr.io/catthehacker/ubuntu:full-22.04"
|
||||
|
||||
"ubuntu-act-latest:docker://ghcr.io/catthehacker/ubuntu:act-latest"
|
||||
"ubuntu-act-26.04:docker://ghcr.io/catthehacker/ubuntu:act-26.04"
|
||||
"ubuntu-act-24.04:docker://ghcr.io/catthehacker/ubuntu:act-24.04"
|
||||
"ubuntu-act-22.04:docker://ghcr.io/catthehacker/ubuntu:act-22.04"
|
||||
|
||||
"ubuntu-runner-latest:docker://ghcr.io/catthehacker/ubuntu:runner-latest"
|
||||
"ubuntu-runner-26.04:docker://ghcr.io/catthehacker/ubuntu:runner-26.04"
|
||||
"ubuntu-runner-24.04:docker://ghcr.io/catthehacker/ubuntu:runner-24.04"
|
||||
"ubuntu-runner-22.04:docker://ghcr.io/catthehacker/ubuntu:runner-22.04"
|
||||
|
||||
"ubuntu-rust-latest:docker://ghcr.io/catthehacker/ubuntu:rust-latest"
|
||||
"ubuntu-rust-26.04:docker://ghcr.io/catthehacker/ubuntu:rust-26.04"
|
||||
"ubuntu-rust-24.04:docker://ghcr.io/catthehacker/ubuntu:rust-24.04"
|
||||
"ubuntu-rust-22.04:docker://ghcr.io/catthehacker/ubuntu:rust-22.04"
|
||||
|
||||
|
||||
@@ -1,82 +0,0 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
let
|
||||
cfg = config.greg.runner;
|
||||
environmentVariables = {
|
||||
EFI_DIR = "${pkgs.OVMF.fd}/FV/";
|
||||
STORAGE_URL = "s3.thehellings.lan:9000";
|
||||
};
|
||||
runnerCfg = file: {
|
||||
inherit environmentVariables;
|
||||
authenticationTokenConfigFile = file;
|
||||
executor = "shell";
|
||||
limit = cfg.threads;
|
||||
};
|
||||
in
|
||||
# We want exactly one of these to be true, but not both. Neither can both be false
|
||||
{
|
||||
options.greg.runner = {
|
||||
enable = lib.mkEnableOption "Enable as a gitlab-runner with both libvirt and virtualbox";
|
||||
|
||||
threads = lib.mkOption {
|
||||
default = 5;
|
||||
type = lib.types.int;
|
||||
description = "The maximum number of concurrent jobs";
|
||||
};
|
||||
|
||||
qemu = lib.mkEnableOption "Enable the qemu host (mutually exclusive with vbox)";
|
||||
vbox = lib.mkEnableOption "Enable the vbox host (mutually exclusive with qemu)";
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable ({
|
||||
# assertions = [
|
||||
# {
|
||||
# assertion = cfg.qemu || cfg.vbox && (cfg.qemu != cfg.vbox);
|
||||
# message = "You must enable exactly one of qemu or vbox";
|
||||
# }
|
||||
# ];
|
||||
# Shared configurations
|
||||
age.secrets = {
|
||||
qemu.file = ../../secrets/gitlab/nixos-qemu-shell.age;
|
||||
vbox.file = ../../secrets/gitlab/nixos-vbox-shell.age;
|
||||
};
|
||||
|
||||
services.gitlab-runner = {
|
||||
enable = false;
|
||||
settings.concurrent = cfg.threads;
|
||||
services = {
|
||||
qemu = lib.mkIf cfg.qemu (runnerCfg config.age.secrets.qemu.path);
|
||||
vbox = lib.mkIf cfg.vbox (runnerCfg config.age.secrets.vbox.path);
|
||||
};
|
||||
};
|
||||
|
||||
systemd.services.gitlab-runner = {
|
||||
serviceConfig = {
|
||||
DevicePolicy = lib.mkForce "auto";
|
||||
User = "root";
|
||||
DynamicUser = lib.mkForce false;
|
||||
};
|
||||
};
|
||||
|
||||
users.extraGroups.vboxusers.members = lib.optional cfg.vbox "greg";
|
||||
|
||||
virtualisation = {
|
||||
libvirtd = lib.mkIf cfg.qemu {
|
||||
enable = true;
|
||||
allowedBridges = [
|
||||
"br0"
|
||||
"virbr0"
|
||||
];
|
||||
onBoot = "ignore"; # only restart VMs labeled 'autostart'
|
||||
};
|
||||
virtualbox.host = lib.mkIf cfg.vbox {
|
||||
enable = true;
|
||||
enableExtensionPack = true;
|
||||
};
|
||||
};
|
||||
});
|
||||
}
|
||||
@@ -1,7 +1,6 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
@@ -18,35 +17,9 @@ with lib;
|
||||
};
|
||||
|
||||
config = mkIf cfg {
|
||||
age.secrets.attic.file = ../../secrets/attic.age;
|
||||
networking.domain = "thehellings.lan";
|
||||
time.timeZone = "America/Chicago";
|
||||
|
||||
systemd.services.attic-client = {
|
||||
enable = true;
|
||||
description = "Attic client watch-store service";
|
||||
after = [ "network.target" ];
|
||||
wantedBy = [ "multi-user.target" ];
|
||||
serviceConfig = {
|
||||
Type = "simple";
|
||||
Restart = "on-failure";
|
||||
RestartSec = "5s";
|
||||
};
|
||||
preStart = ''
|
||||
set -x
|
||||
mkdir -p $XDG_CONFIG_HOME/attic
|
||||
cp ${config.age.secrets.attic.path} $XDG_CONFIG_HOME/attic/config.toml
|
||||
'';
|
||||
script = "${pkgs.attic-client}/bin/attic watch-store --ignore-upstream-cache-filter default";
|
||||
environment = {
|
||||
XDG_CONFIG_HOME = "/var/lib/attic-client";
|
||||
};
|
||||
};
|
||||
|
||||
systemd.tmpfiles.rules = [
|
||||
"d /var/lib/attic-client 0755 root root -"
|
||||
];
|
||||
|
||||
# Open Prometheus exporter ports on LAN-connected hosts only.
|
||||
# NOT in baseline.nix to avoid exposing these on internet-facing hosts (e.g. linode).
|
||||
networking.firewall.allowedTCPPorts = [
|
||||
|
||||
@@ -14,6 +14,9 @@ let
|
||||
url = "https://github.com/fluxcd/flux2/releases/download/v2.7.2/install.yaml";
|
||||
sha256 = "sha256-Qs1qJmgZm8q9xZsORjT/N/wzpbWVVODXtzDpjnAYMuQ=";
|
||||
};
|
||||
keepaliveIp = "10.42.5.1";
|
||||
nebulaName = "k3s.nebula.thehellings.com";
|
||||
nebulaIp = "10.157.100.1";
|
||||
in
|
||||
{
|
||||
options.greg = {
|
||||
@@ -43,6 +46,13 @@ in
|
||||
};
|
||||
|
||||
config = lib.mkIf cfg.enable {
|
||||
assertions = [
|
||||
{
|
||||
assertion = config.greg.nebula.enable;
|
||||
message = "Configure Nebula for this host, first";
|
||||
}
|
||||
];
|
||||
|
||||
age.secrets = {
|
||||
bw_secret.file = ../../secrets/kubernetes/bw_secret.age;
|
||||
dendrite_key.file = ../../secrets/dendrite_key.age;
|
||||
@@ -95,6 +105,9 @@ in
|
||||
"--supervisor-metrics=true"
|
||||
"--tls-san ${config.networking.hostName}.thehellings.lan"
|
||||
"--tls-san ${config.networking.hostName}.shire-zebra.ts.net"
|
||||
"--tls-san ${keepaliveIp}"
|
||||
"--tls-san ${nebulaName}"
|
||||
"--tls-san ${nebulaIp}"
|
||||
];
|
||||
manifests = {
|
||||
cert-manager.source = cert-manager;
|
||||
@@ -110,13 +123,14 @@ in
|
||||
keepalived = {
|
||||
enable = true;
|
||||
openFirewall = true;
|
||||
vrrpInstances.kubernetes = {
|
||||
vrrpInstances = {
|
||||
kubernetes = {
|
||||
interface = cfg.vipInterface;
|
||||
priority = cfg.priority;
|
||||
state = if (config.networking.hostName == "isaiah") then "MASTER" else "BACKUP";
|
||||
virtualIps = [
|
||||
{
|
||||
addr = "10.42.5.1/16";
|
||||
addr = "${keepaliveIp}/16";
|
||||
dev = cfg.vipInterface;
|
||||
}
|
||||
];
|
||||
@@ -125,6 +139,22 @@ in
|
||||
advert_int 1
|
||||
'';
|
||||
};
|
||||
k3s-nebula = {
|
||||
interface = "nebula0";
|
||||
priority = 1;
|
||||
state = if (config.networking.hostName == "isaiah") then "MASTER" else "BACKUP";
|
||||
virtualIps = [
|
||||
{
|
||||
addr = "${nebulaIp}/16";
|
||||
dev = "nebula0";
|
||||
}
|
||||
];
|
||||
virtualRouterId = 78;
|
||||
extraConfig = ''
|
||||
advert_int 1
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
openiscsi = {
|
||||
enable = true;
|
||||
|
||||
@@ -27,7 +27,7 @@ let
|
||||
nebulaDomain = "nebula.thehellings.com";
|
||||
# Linode's public address — used by all non-lighthouse hosts to reach it.
|
||||
# Override with greg.nebula.lighthouseAddr if the public IP ever changes.
|
||||
defaultLighthouseAddr = "linode.${nebulaDomain}";
|
||||
defaultLighthouseAddr = "thehellings.com";
|
||||
in
|
||||
{
|
||||
options.greg.nebula = {
|
||||
|
||||
@@ -54,7 +54,7 @@ with lib;
|
||||
|
||||
target = mkOption {
|
||||
type = types.str;
|
||||
description = ''The destination that is being proxied.'';
|
||||
description = "The destination that is being proxied.";
|
||||
example = "http://localhost:8080";
|
||||
};
|
||||
|
||||
|
||||
@@ -57,6 +57,7 @@ with lib;
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBLOqwbp4hFYkiJpokh9i2RToa/6tQcwthDNQH69tyBF root@vm-matrix.thehellings.lan"
|
||||
# Mac
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBT5BFHQz1I5k/zkLQNLjL77EaqfdpRiF2Ci4eS9LMDK gregory.hellings@jude.thehellings.lan"
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPVlMoN2pkKRRwKNuMbMczki5ybR34wvjdgDNlgR74Wh greg@gregs-MacBook-Pro-16-inch-Nov-2024"
|
||||
];
|
||||
homeMode = "500";
|
||||
isNormalUser = true;
|
||||
|
||||
@@ -18,7 +18,6 @@ with lib;
|
||||
devices = {
|
||||
chronicles.id = "7FI6Y3M-C7YQEDI-IB345L6-RKLXMB6-AEIV57Y-3J2RCXQ-MK6QRNK-EINPXAE";
|
||||
genesis.id = "YDTH4SD-GUAC5AA-SSYWYPZ-YMJW5LK-LE7PZKJ-GV2UJFZ-CU7LZAD-GTYWCQK";
|
||||
gitlab.id = "GKNOZWI-CNC2Q2F-R5GGGDX-RYFGHK4-CCC37LC-GVOEMJI-46QPC6G-AWFEOQE";
|
||||
linode.id = "IJMMXPR-WNALZBD-FMJH5W5-WV7XGJY-HLJTKGT-5TKHJIH-75LT56D-UUZCYQE";
|
||||
};
|
||||
options = {
|
||||
|
||||
+55
-30
@@ -9,11 +9,9 @@
|
||||
"tailscale": "100.64.0.0/10"
|
||||
},
|
||||
"hosts": {
|
||||
"chronicles": {
|
||||
"ip": "10.42.1.4",
|
||||
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEBecZUva9OnZuXLaBun6/1ITo5f9p0YMLPD+q0egLRS",
|
||||
"external": true,
|
||||
"ts": "100.119.228.115"
|
||||
"builder2": {
|
||||
"ip": "10.42.1.17",
|
||||
"system": "x86_64-linux"
|
||||
},
|
||||
"exodus": {
|
||||
"ip": null,
|
||||
@@ -38,10 +36,6 @@
|
||||
"tags": ["server"],
|
||||
"nebulaIp": "10.157.0.3"
|
||||
},
|
||||
"icdm-root": {
|
||||
"external": true,
|
||||
"system": "x86_64-linux"
|
||||
},
|
||||
"isaiah": {
|
||||
"builder": true,
|
||||
"ip": "10.42.1.6",
|
||||
@@ -62,6 +56,7 @@
|
||||
"user": "gregory.hellings"
|
||||
},
|
||||
"jeremiah": {
|
||||
"aliases": [ "buildbot" ],
|
||||
"builder": true,
|
||||
"ip": "10.42.1.8",
|
||||
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOjQjXq9WYU2Ki27BR9WwJ4ZruS/lJXbjC1b0Q42Adi0",
|
||||
@@ -71,11 +66,6 @@
|
||||
"tags": ["builder", "kube", "server"],
|
||||
"nebulaIp": "10.157.0.5"
|
||||
},
|
||||
"joel": {
|
||||
"external": true,
|
||||
"ip": "10.42.0.4",
|
||||
"ts": null
|
||||
},
|
||||
"gregs-MacBook-Pro-16-inch-Nov-2024": {
|
||||
"external": true,
|
||||
"system": "aarch64-darwin"
|
||||
@@ -104,26 +94,10 @@
|
||||
"external": true,
|
||||
"system": "aarch64-darwin"
|
||||
},
|
||||
"nas1": {
|
||||
"external": true,
|
||||
"ip": "10.42.1.14",
|
||||
"ts": "100.114.187.61"
|
||||
},
|
||||
"nixos": {
|
||||
"external": true,
|
||||
"system": "x86_64-linux"
|
||||
},
|
||||
"printer": {
|
||||
"external": true,
|
||||
"ip": "10.42.1.3"
|
||||
},
|
||||
"proxmoxtemplate": {
|
||||
"external": true,
|
||||
"system": "x86_64-linux"
|
||||
},
|
||||
"gitlab": {
|
||||
"system": "x86_64-linux"
|
||||
},
|
||||
"wsl": {
|
||||
"external": true,
|
||||
"system": "aarch64-linux"
|
||||
@@ -138,5 +112,56 @@
|
||||
"tags": ["builder", "kube", "server"],
|
||||
"nebulaIp": "10.157.0.6"
|
||||
}
|
||||
},
|
||||
"external": {
|
||||
"chronicles": {
|
||||
"ip": "10.42.1.4",
|
||||
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEBecZUva9OnZuXLaBun6/1ITo5f9p0YMLPD+q0egLRS",
|
||||
"ts": "100.119.228.115",
|
||||
"aliases": ["s3"]
|
||||
},
|
||||
"hermes": {
|
||||
"ip": "10.42.1.18",
|
||||
"mac": "BC:24:11:E4:72:AB",
|
||||
"nebulaIp": "10.157.0.8",
|
||||
"pubkey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILFYyzz/9i5rXprCQj9IL1ulrbQ6E9BOSeOcvf4D/b0G",
|
||||
"tags": ["server"]
|
||||
},
|
||||
"joel": {
|
||||
"ip": "10.42.0.4"
|
||||
},
|
||||
"k3s": {
|
||||
"aliases": [ "*.k3s" ],
|
||||
"ip": "10.42.5.1",
|
||||
"nebulaIp": "10.157.100.1"
|
||||
},
|
||||
"nas1": {
|
||||
"aliases": [ "*.nas1" ],
|
||||
"ip": "10.42.1.14",
|
||||
"ts": "100.114.187.61"
|
||||
},
|
||||
"printer": {
|
||||
"ip": "10.42.1.3"
|
||||
},
|
||||
"pve2": {
|
||||
"ip": "10.42.1.15"
|
||||
},
|
||||
"pve2bmc": {
|
||||
"ip": "10.42.6.2",
|
||||
"mac": "00:25:90:4b:34:e8"
|
||||
},
|
||||
"pve3": {
|
||||
"ip": "10.42.1.16"
|
||||
},
|
||||
"pve3bmc": {
|
||||
"ip": "10.42.6.3",
|
||||
"mac": "00:25:90:4a:dc:2e"
|
||||
},
|
||||
"pve4": {
|
||||
"ip": "10.42.1.17"
|
||||
},
|
||||
"pve4bmc": {
|
||||
"ip": "10.42.6.4"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -30,4 +30,3 @@ final: prev:
|
||||
tpmSupport = true;
|
||||
};
|
||||
}
|
||||
// (import ../pkgs { pkgs = prev; })
|
||||
|
||||
+18
-11
@@ -1,13 +1,14 @@
|
||||
{
|
||||
pkgs,
|
||||
system ? pkgs.stdenv.hostPlatform.system,
|
||||
top,
|
||||
...
|
||||
}:
|
||||
|
||||
let
|
||||
c = pkgs.callPackage;
|
||||
in
|
||||
{
|
||||
c = pkgs.newScope packages;
|
||||
packages = if system == "x86_64-linux" then (allSys // x86Linux) else allSys;
|
||||
allSys = {
|
||||
#default = iso;
|
||||
#iso = top.self.nixosConfigurations.iso.config.system.build.isoImage;
|
||||
#iso-beta = self.nixosConfigurations.iso-beta.config.system.build.isoImage;
|
||||
@@ -15,6 +16,12 @@ in
|
||||
adblock_update = c ./adblock_update.nix { };
|
||||
brew = c ./homebrew.nix { };
|
||||
create_ssl = c ./create_ssl.nix { };
|
||||
dockerCompat = pkgs.runCommand "docker-compat" {
|
||||
nativeBuildInputs = [];
|
||||
} ''
|
||||
mkdir -p $out/bin
|
||||
ln -s ${pkgs.podman}/bin/podman $out/bin/docker
|
||||
'';
|
||||
gcc-tune = c ./gcc-tune.nix { };
|
||||
#gen-build = c ./gen-build { };
|
||||
hms = c ./hms { };
|
||||
@@ -22,15 +29,15 @@ in
|
||||
inject = c ./inject.nix { };
|
||||
setup-ssh = c ./setup-ssh { };
|
||||
upgrade-pg-cluster = c ./upgrade-pg-cluster.nix { };
|
||||
}
|
||||
// (
|
||||
if system == "x86_64-linux" then
|
||||
{
|
||||
};
|
||||
x86Linux = {
|
||||
qemu-hook = c ./qemu-hook.nix { };
|
||||
vfio_startup = c ./vfio_startup.nix { };
|
||||
vfio_shutdown = c ./vfio_shutdown.nix { };
|
||||
zim = c ./zim.nix { };
|
||||
}
|
||||
else
|
||||
{ }
|
||||
)
|
||||
// (import ./zim {
|
||||
inherit (top.nixpkgs-lib) lib;
|
||||
inherit pkgs;
|
||||
});
|
||||
in
|
||||
packages
|
||||
|
||||
+48
-32
@@ -1,72 +1,88 @@
|
||||
{
|
||||
"en": {
|
||||
"gutenberg": {
|
||||
"name": "gutenberg_en_all_2023-08.zim",
|
||||
"hash": "sha256-wWi0vTyMD/Es0w/jk9uyg4DN94080thPfT5uphEqbUc="
|
||||
"name": "gutenberg_en_all",
|
||||
"version": "2023-08",
|
||||
"hash": "sha256-OXmdHdsLZcW4nCUQsy7sMpUssS8NV7ztkCgS/nsISuw="
|
||||
},
|
||||
"phet": {
|
||||
"name": "phet_en_all_2025-03.zim",
|
||||
"hash": "sha256-HT/gVNydkOitny6oUl2A+JvbFDGAIeb0h+xbMeQ2Rqs="
|
||||
"name": "phet_en_all",
|
||||
"version": "2025-03",
|
||||
"hash": "sha256-ARuUzU2o17J2/ZedHc2acXl33dtHCbQJEb72UQUEm1Y="
|
||||
},
|
||||
"wikibooks": {
|
||||
"name": "wikibooks_en_all_maxi_2025-10.zim",
|
||||
"hash": "sha256-zmcvrvGO+LEHt7x8/SoguBDODUyRXy9x5LUGAkS+fF8="
|
||||
"name": "wikibooks_en_all_maxi",
|
||||
"version": "2025-10",
|
||||
"hash": "sha256-ONBh/ze1Fv2Ffm5b9vDzYS/i2cWSa4pM4MLZnozr2n8="
|
||||
},
|
||||
"wikipedia": {
|
||||
"name": "wikipedia_en_all_maxi_2025-08.zim",
|
||||
"hash": "sha256-r7Cd0vjEb84Ftw+EwZSlqb8qhqm8WA3LAPdHAav7wrg="
|
||||
"name": "wikipedia_en_all_maxi",
|
||||
"version": "2026-02",
|
||||
"hash": "sha256-vwhTv5TtjFNSTl7mcoi8SJiBm8nUlq8rP4UrZYir3Sc="
|
||||
},
|
||||
"wikisource": {
|
||||
"name": "wikisource_en_all_maxi_2025-11.zim",
|
||||
"hash": "sha256-jPHh/C20PARN6K7aPNw3k9fFHhpwzsREi/1o1DIISS4="
|
||||
"name": "wikisource_en_all_maxi",
|
||||
"version": "2025-11",
|
||||
"hash": "sha256-p1Jio+PMTZVSLIDIOBeMG3acXJg83CwQM7zIWDUyozM="
|
||||
},
|
||||
"wikiversity": {
|
||||
"name": "wikiversity_en_all_maxi_2025-11.zim",
|
||||
"hash": "sha256-0DaE2EUdHvaX3XqD3f0lwurSAaDZ4hEKtrMEutL5xt0="
|
||||
"name": "wikiversity_en_all_maxi",
|
||||
"version": "2025-11",
|
||||
"hash": "sha256-IG/gAUdc/vHRrIWGHhw8vMJdLWwqrNbfh+SiclQRIAI="
|
||||
},
|
||||
"wiktionary": {
|
||||
"name": "wiktionary_en_all_nopic_2025-09.zim",
|
||||
"hash": "sha256-EzrrruJQWY/3pP93WCTeCCfaPvpshqdkR0TFxVz7bEI="
|
||||
"name": "wiktionary_en_all_nopic",
|
||||
"version": "2025-09",
|
||||
"hash": "sha256-Ghcb60qeGaSJtTKQkJoMx/XucX7Lt1XY145lD3gHlMg="
|
||||
}
|
||||
},
|
||||
"fr": {
|
||||
"gutenberg": {
|
||||
"name": "gutenberg_fr_all_2025-10.zim",
|
||||
"hash": "sha256-1gU7v//LYX/2LyIRjO02A1fWPQz9Y7Qt5ftgeazd3G8="
|
||||
"name": "gutenberg_fr_all",
|
||||
"version": "2025-10",
|
||||
"hash": "sha256-gLHxLXJNwwcxM/mZHtoJ8ojbGQ1fugxgni/+RXccwhU="
|
||||
},
|
||||
"phet": {
|
||||
"name": "phet_fr_all_2025-03.zim",
|
||||
"hash": "sha256-K56i55WPu5EMQHIrnnqhgJ32WozZ6oYD9X3IBytGA0A="
|
||||
"name": "phet_fr_all",
|
||||
"version": "2025-03",
|
||||
"hash": "sha256-CSboZNTIowLLhp1u9wkxH8xmu3LvQNx5q493AOYJRIc="
|
||||
},
|
||||
"wikibooks": {
|
||||
"name": "wikibooks_fr_all_maxi_2025-09.zim",
|
||||
"hash": "sha256-PQSdPbBHwK3IfFPH5GsKaxkNGTlZVJNJEI8gNioBl1U="
|
||||
"name": "wikibooks_fr_all_maxi",
|
||||
"version": "2025-09",
|
||||
"hash": "sha256-KHCc/73L5Bd9iZ47SRV6vpI8fVM1v9hk1TpEvTro2uo="
|
||||
},
|
||||
"wikipedia": {
|
||||
"name": "wikipedia_fr_all_maxi_2025-06.zim",
|
||||
"hash": "sha256-zzDhITMd1nRMYTUlvn56l4VBnpFuhiNrhhYMcrrBuOQ="
|
||||
"name": "wikipedia_fr_all_maxi",
|
||||
"version": "2025-06",
|
||||
"hash": "sha256-ve7Mbh96/ObNbV/KVNYZpfLN+HdWlJ7C5LItEdVkRH0="
|
||||
},
|
||||
"wikisource": {
|
||||
"name": "wikisource_fr_all_maxi_2025-09.zim",
|
||||
"hash": "sha256-2gEY5nTBecrmg61VJerxO4/oV7dZJmRgzLkqrcocW/0="
|
||||
"name": "wikisource_fr_all_maxi",
|
||||
"version": "2025-09",
|
||||
"hash": "sha256-FdLYCjoT6Yk34AZKFND/NaBHNe+GzW9Ibpd6mVPWlxI="
|
||||
},
|
||||
"wikiversity": {
|
||||
"name": "wikiversity_fr_all_maxi_2025-09.zim",
|
||||
"hash": "sha256-4vOxYiX3TYht7ARY+PeCJ0ArVZZn9TeGtwCieqn3xUw="
|
||||
"name": "wikiversity_fr_all_maxi",
|
||||
"version": "2025-09",
|
||||
"hash": "sha256-55fdtw/cRezq6nkRp6wuwkukBiqsQKdwh9QWVAgFcBI="
|
||||
},
|
||||
"wiktionary": {
|
||||
"name": "wiktionary_fr_all_nopic_2025-11.zim",
|
||||
"hash": "sha256-oQS8DzKioceCER1p1oAvaS1gRooMLJLYnCqy1aLARi4="
|
||||
"name": "wiktionary_fr_all_nopic",
|
||||
"version": "2025-11",
|
||||
"hash": "sha256-P0CJptee5rDzccxyRDBzyRLuuFOcaLsJYi6DkBFUfIc="
|
||||
}
|
||||
},
|
||||
"ht": {
|
||||
"phet": {
|
||||
"name": "phet_ht_all_2025-03.zim",
|
||||
"hash": "sha256-UjC0REJ5d5wIKccutZADX74IxvZuF+CD/caVzZfHg9s="
|
||||
"name": "phet_ht_all",
|
||||
"version": "2025-03",
|
||||
"hash": "sha256-bHrPzE8H7ptrP6r5wPlXSsXNlTiKxJ9KatABC4kwx+s="
|
||||
},
|
||||
"wikipedia": {
|
||||
"name": "wikipedia_ht_all_maxi_2025-09.zim",
|
||||
"hash": "sha256-spT7EFXLnI0FWT9Vlvp7QEP0urntmQ2C+fQB5bVLoLE="
|
||||
"name": "wikipedia_ht_all_maxi",
|
||||
"version": "2026-04",
|
||||
"hash": "sha256-qUX0pKxIyNsWX4V6kNIsP4Z9nc6TDhwdDR0MmpDOQFs="
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
{ pkgs, lib, ... }:
|
||||
let
|
||||
zimMetadata = builtins.fromJSON (builtins.readFile ./blobs.json);
|
||||
oneZim =
|
||||
sourceType: info:
|
||||
pkgs.callPackage ./one_zim.nix {
|
||||
inherit sourceType;
|
||||
sourceName = info.name;
|
||||
sourceHash = info.hash;
|
||||
sourceVersion = info.version;
|
||||
};
|
||||
# Preserves structure in the blobs.json file, turning leaves into drvs
|
||||
zimFileDrvs = builtins.mapAttrs (
|
||||
_language: types: (builtins.mapAttrs (sourceType: info: oneZim sourceType info) types)
|
||||
) zimMetadata;
|
||||
# Flattens leaf drvs into the structure that flake packages expects
|
||||
zimFilePkgs = builtins.listToAttrs (
|
||||
lib.mapAttrsToListRecursiveCond (_path: x: !(x ? "name")) (_path: drv: {
|
||||
inherit (drv) name;
|
||||
value = drv;
|
||||
}) zimFileDrvs
|
||||
);
|
||||
in
|
||||
zimFilePkgs
|
||||
@@ -0,0 +1,33 @@
|
||||
{
|
||||
sourceType,
|
||||
sourceName,
|
||||
sourceVersion,
|
||||
sourceHash,
|
||||
|
||||
fetchurl,
|
||||
stdenvNoCC,
|
||||
}:
|
||||
|
||||
stdenvNoCC.mkDerivation (finalAttrs: {
|
||||
name = "zim-${sourceType}-${sourceName}.zim";
|
||||
version = sourceVersion;
|
||||
|
||||
src = (
|
||||
fetchurl {
|
||||
url = "https://download.kiwix.org/zim/${sourceType}/${sourceName}_${sourceVersion}.zim";
|
||||
hash = sourceHash;
|
||||
}
|
||||
# fetchtorrent {
|
||||
# inherit (val) hash;
|
||||
# url = "https://download.kiwix.org/zim/${type}/${val.name}.torrent";
|
||||
# backend = "transmission";
|
||||
# postUnpack = "mkdir -p $downloadedDirectory/tmp; mv $downloadedDirectory/*.zim $downloadedDirectory/tmp";
|
||||
# }
|
||||
);
|
||||
phases = [ "installPhase" ];
|
||||
preferLocalBuild = true;
|
||||
installPhase = ''
|
||||
set -x
|
||||
ln -s ${finalAttrs.src} $out
|
||||
'';
|
||||
})
|
||||
+2
-1
@@ -83,7 +83,7 @@ func getHash(ch chan result, file, category, language string) {
|
||||
// TODO: Only call this if the file doesn't already have a hash
|
||||
// in the existing file
|
||||
fmt.Printf("Fetching hash for %s\n", file)
|
||||
cmd := exec.Command( "nix-prefetch-url", fmt.Sprintf("%s/%s/%s.torrent", BASE, category, file))
|
||||
cmd := exec.Command( "nix-prefetch-url", fmt.Sprintf("%s/%s/%s", BASE, category, file))
|
||||
out, err := cmd.Output()
|
||||
if err != nil {
|
||||
fmt.Printf("Error fetching hash for %s (category: %s, language: %s): %v\n", file, category, language, err)
|
||||
@@ -115,6 +115,7 @@ type result struct {
|
||||
|
||||
type Zim struct {
|
||||
Name string `json:"name"`
|
||||
Version string `json:"version"`
|
||||
Hash string `json:"hash"`
|
||||
}
|
||||
|
||||
|
||||
@@ -1,38 +0,0 @@
|
||||
age-encryption.org/v1
|
||||
-> ssh-ed25519 87huqg HqGj+5hXjRLJcrRMC3biBE8K9B/OAJj68gqTqg9ja1k
|
||||
K25Z2YGlWnUK02EUQmdNo0QM13apME/mc5w0gydrEDc
|
||||
-> ssh-ed25519 8UnW5Q Pj4iDE8Q9FhzudZ341W+V2aaWuotfzOZzN18fRnPqh8
|
||||
kujFDr1mL/0YrsyoVpWQhkEwwjXr3l3AbbD2787z8zo
|
||||
-> ssh-ed25519 UFfTmg Ga4FQrnrejoa6uSNDh0VMgB7ntPrp4Z2Ic8n5XCosHM
|
||||
cquCWegeBg6Mtv3/t5RAEmh66p6oHBlQvbuJMaZTB6g
|
||||
-> ssh-ed25519 xNtnoA Mf9EJ6mB79mWBN383e8t/BZQVjB7mXuFKvhyJdT9GA0
|
||||
QnnrGVbZIHMDBS4ZZrj8BDwx6deSP10t2kLLzu2ewXs
|
||||
-> ssh-ed25519 aY2AXA 0Lop9E46qiaGNrFTVbgg0O1yKbqwCFmG9pjssoclMUM
|
||||
I5lOVEogB8XV9pkyqmYcFojvZlAX31ADlMyHgDluxjY
|
||||
-> ssh-ed25519 AQhf1g Ktn1BuWcwx0eJS0ZJugnRiTmvAht6ABOVzTDcw58HlM
|
||||
7Vm9rx9P+rXDvrxTQnxxpUBZbvNRgd6UafmzuG0ePwM
|
||||
-> ssh-ed25519 mOmPfg VhUpDomkduEthbPGMr4bFpLqVcXgn3OrQojPjA+s8k4
|
||||
1nrS2JxDSSe6PvPRK9VNBh7RTMiFChSiM3xbCQAQw/4
|
||||
-> ssh-ed25519 YJiRbw XVylSfHTRne3B5zWru6x+yhAPJEp9Jj27P0Y63Wp2SE
|
||||
APDEG5J9tBR1boxpsUBarSC8vN6q34KElRUK98fsQ+0
|
||||
-> ssh-ed25519 0/WsKg FVXUmVyse3msAkDSkznhcUw5VYd4vwsKd9PCDBJwLiM
|
||||
hRIDpMGWWFu127Q/jvxr+ieSM7KQfNagqhUZUnTwJMM
|
||||
-> ssh-ed25519 Nl/5yA qO4YJ4/gnfbLOdJFyGq1J4AJH5pMTPhR2IvEKMt4IlM
|
||||
Dyhj/RQQ3LxgJVc5drDdgw0cAJi1t3zCFnO1zWKaWIw
|
||||
-> ssh-ed25519 GdLgCQ GyVGc/nK0Zu3/Gm76KRvXHwjdnRvoM+WuY/psFaIv2Y
|
||||
1O56ZsNvSBzhcFRPoIOyUCMQCGQYn3w5ES2AfGP75uw
|
||||
-> ssh-ed25519 tOH/HQ wR3dxHjLSzkHIG/6UX45qiGFqX0cHA18/oEFatBthUc
|
||||
J/gpGWp8kOdmtFs9A65B68lsnD68gxfheiOZfp0AeI4
|
||||
-> ssh-ed25519 FpzvfQ 0sdlOKrumgCJedenPUNY/QSIDmhrP3J077qZxTwvdQE
|
||||
DdWxilImsFB/XXgbZNYXEjSCoqmVd0vaTH7rhR73fsw
|
||||
-> ssh-ed25519 kdPvzQ 9PxMQp7Y4Gh0V2uMa8K6SmldUhcqcBfYgVtMkzzzdAc
|
||||
sS8Fqm1p72IPOKNZfJKIJTxTLoNt3MQaOI6w8qYCTRo
|
||||
-> ssh-ed25519 onmXpg Ig9ABzLLazyW4wxkUmq87XR7hmUt6l5/X0R9Zf2qBlE
|
||||
n3DO7o4NdWRefqEkexyIJLeOQ8w1q9QN+wIslQNXIF4
|
||||
-> ssh-ed25519 CnhD0g wtGoi7CzfIAs8ezcIF7ecjTXshD96xG8ZLlhYYaM6HQ
|
||||
4hwG3V1Cf/iYDsNXT0RmzWJnW5kxnBWNvX3ECrP1/oE
|
||||
-> ssh-ed25519 4ep2UA AKSh5d04251XgyZKKscIJjU7RSpKclMqO5qPTEMQygo
|
||||
wSyIxArdlbLafOKmUyrlUqOZQbF1PXZND/PAFYCjClU
|
||||
--- DnRePhJDkX5QDmrkH5jiZkuljvOFaVm1BrqYMTDP3tg
|
||||
\bºîç:ý]3\ô<™rÔhމ׋|ÈFz.R{FEÝá<RòôœÊ'=ðY”v xˆ˜o½ßÌF
|
||||
q␍¤lî0¥ä»
|
||||
Binary file not shown.
@@ -1,38 +1,39 @@
|
||||
age-encryption.org/v1
|
||||
-> ssh-ed25519 87huqg FccJVul84RKDnR/TVE5Ev6SAi9wi5d3UjyAYNCmncHk
|
||||
335MAD56KCN4ZGZSyj65MygHEhvyunxooQEby+tjJJg
|
||||
-> ssh-ed25519 8UnW5Q lGN+NyMtGXFXkmpBHr6cnioq7ji4RQU6nSEA7IbVLjI
|
||||
9CPRIUIBJcY17pomQx4usFpywYYWBcb4DKVS3rrcW8c
|
||||
-> ssh-ed25519 UFfTmg RsrK6+eHpdGn42Aek2c+sWSqGEPQuPCQ1cltmSNJ1RY
|
||||
JLP7SKLeQXx+1EiVBSVb2eyFBC6f7rAmMx6c8MuRUuI
|
||||
-> ssh-ed25519 xNtnoA HBJnWH8buvy0uN0PWNBHWelQQcQ7sVuwX5PIxnmE71Y
|
||||
iPxler8tH9q3xvy/53Lz2wyyBtrQ+nCVZ/qRkK0LXZU
|
||||
-> ssh-ed25519 aY2AXA RaRgPcFOxKx/BvPt56IEDltUiFF1wxFERpxEmybg6yA
|
||||
ewJFmwI+3pTFwPDtPDitrEcK8dogu/4Y5dWIaCCSMWg
|
||||
-> ssh-ed25519 AQhf1g awiDTZLnt/wxMcz3Snn5rFV3irY0ma/cxYylmFx8uwY
|
||||
zOU3skyoRENDxJldzaLjA2WOv24vD41thPSfS9VN9B8
|
||||
-> ssh-ed25519 mOmPfg 7bx2mIA0YoeyHfY6HccoDJWLCEjz0XQW+C0XZi09bkE
|
||||
2H8+g+4+itKcwy4NfOo4rz5gG45FZ4ilqbPnw5p5Jp4
|
||||
-> ssh-ed25519 YJiRbw H7FN13mZ11Im4R0cJs6Y0qs2xkLLqjEAM+QMUlt1XFI
|
||||
xEak37igbuepX8/m5irRyJPUvYz+jMp1XENmsPLg6oU
|
||||
-> ssh-ed25519 0/WsKg FPuZmZPpjXVooyVhDZoqu7b6sqXXxN/Y3giiWmtfc0I
|
||||
rNRSpOubIcbm5V/yOgprZ/D0KqbmBAf47ySfnejK7xo
|
||||
-> ssh-ed25519 Nl/5yA 9D+4HJ14L5KX2FzGRhltE/pPePUgZSufkA/t+aN3Umo
|
||||
jVH3RgVxqNgxu/+8Y/09nUqlUezl0VaYlD6HdqzO5Jg
|
||||
-> ssh-ed25519 GdLgCQ kpfgJsFC+alhCcXyJzm4qrGO/WzY52PeUfPxBWNQshE
|
||||
pDrLxhlC6SZ0HoohQahcIMGf6yE/LX9qjIKvlfenABA
|
||||
-> ssh-ed25519 tOH/HQ ghzvgNIYF4NUN23+juvWcSF9a33kmMi3b14L1DijlBY
|
||||
p2SYIjMzVgMiRUkRidlfme9ZaANLL87phGWtMtvPd24
|
||||
-> ssh-ed25519 FpzvfQ CdGC9zHx5NTdevkHc0u0GUO/qWR9eoWK5gkqht6SvyA
|
||||
hJ2ZqqVISnPfBGt10H0m6d6ZuLglq5qGdZj/lMZxVxg
|
||||
-> ssh-ed25519 kdPvzQ sFoIh+4wud+wg0XTE/GvDchVyLsnd/QNS0FU5LFjBjU
|
||||
RGpXyV247iG28UonB97cE1I0pghwq0eVCoRoRdzxvJI
|
||||
-> ssh-ed25519 onmXpg 7NX8gGOL8gGli/gIIlItygEh6amLgUCEoNch6PrxyVk
|
||||
4Ysx7HznkM7yA3FE4f7rHIQYXTXzSHizT07bo0jCYqI
|
||||
-> ssh-ed25519 CnhD0g sU3lmlZuRMTCnDxoRfmmZUvZ4AkS0w/D38w3CTKfkQY
|
||||
usqUhcEZv/M7nIdPY85LVZLcp7aktiAopF/bvK7xu8I
|
||||
-> ssh-ed25519 4ep2UA 89XKS2W/kjrFZYLxWmKFpGfwvVo1r8kiRT27vU+Q9Wg
|
||||
b04KiZG/ucpSkJ+DFV+JHniYdzOMTKpR8zK/XVkUWGI
|
||||
--- C+p6CysdP9b8jPInNdYJrbQziDTry08D2okJRVngKMg
|
||||
µß±±úªc½ð¸±¸ò¹cÀ>‹Ù· ÂÂ�f_÷V³{sª¹âÿ–}EJ^6v<«õ¦è6�݉=Tk²A€O¬üögŸCËZâÂKê×rw ’ØXP½ég'm~û`-Ø|çKOƒ�n¸àD%7Ïa~¨¹|Œf�gîÆqËP G_£õ|çÕ–n^ñr‚µ�ü<ä°òH°æ¹²»¬-Ìûs]Øc™>}º›8G‡¿BM©Û„‡_¢-Ð q¶M‡�Šî§Þ2hÙñÙ€3nýáásrO< ò¥
|
||||
v` ËŠX;ǯ•n‘e°†<pÜ%š#Ø¥q&¿·â␍æ”?€I%�8ê␍oŒ8=R¤Çã@P]=U®Hð[ÄÕ7ú …‹% ¡ÏÞôÖÞ5Û¨üm¼»½ö-F�Á‹~±7)è`äÎ*Zo- @“²ÕþáëÈá
|
||||
-> ssh-ed25519 87huqg 2adw32Tmw7tjm3xy/PxRAukA4BkhHC6xMhP07hgP1R0
|
||||
ZxgOS1yxXmJ0fHcz1cRnChxcyby2BrNGcDNKXmJkB0Q
|
||||
-> ssh-ed25519 8UnW5Q LSb0iW8mFQp6R1EgpAeqPBnBYTffyQbnuHF4gbG9gwg
|
||||
t6KO1HrgctPwz+xooRgAt350MApIQQJkNfYLxFEBF0o
|
||||
-> ssh-ed25519 UFfTmg gxk9KLVLlYsX7ipfhxtoeRmU2LA50PsJ92hSUem+Sjk
|
||||
0IvqPWsOCUj7ViDWOzf49m+wDnq6ZD5FP2UXB1o43LU
|
||||
-> ssh-ed25519 KbVVUw yVOQRLw8aMcoi3Bq8zVisFHYK5Jua5TCsxUdRtqn4AY
|
||||
K7EJl3+WbqEmng14SIsDMcBRhO3MADuSD5Vvu4+/1+o
|
||||
-> ssh-ed25519 xNtnoA Zyqz/uE56D/KnED9zT5YZkN3fcBt4p9V4s4KItxC+Ag
|
||||
6jAtJ00gf+HLAWno+qjXbz+o+vl7BXuRuzJ6RUtKcIQ
|
||||
-> ssh-ed25519 aY2AXA yliUQYKNuq/Oo92SbaM9hh0COTZtLp2EES++JFQqaWQ
|
||||
ZkZGRr0cGp7JOsExxnq2YFTFETPiVS/dZfozVdeNdAQ
|
||||
-> ssh-ed25519 AQhf1g dhzGNjEsT7hhX/K/ta+dJbXI3v2p6IyVXHWaS8nuzz4
|
||||
Xab2y3S8AoLgnQNO4SdHx8ioG1DsWRJUfKM3RsmLkjQ
|
||||
-> ssh-ed25519 mOmPfg Wb+LA3666buEuwE7S5353mZdU5hkjRlB+zwe7niPCEY
|
||||
0+A9g3FFQYT4N8lM0d3KjPOGNlxJ8pKpuvOoTR960Oc
|
||||
-> ssh-ed25519 YJiRbw 7VQNPch30Ew5NAHh5Bmbe3JdCq7bTEG/ndCo2PC0Vx4
|
||||
TmhQJzu/m7DfLnzsKl7tcIHl0k+TGJ7OasFWgwaF+YA
|
||||
-> ssh-ed25519 Nl/5yA Jq1ncqj6vnygwCQeSdYttMmWkikpsQZVm8MpZgGlFwk
|
||||
mTz+IK0CYcBlqAJ7/eNYdYchQiyfK+ILAjraJaULGiE
|
||||
-> ssh-ed25519 GdLgCQ cRx9RTWXYDqtBDi9MKLVW6wRXjbwk8JZ8IWHwc3Xwww
|
||||
4VhHvHBVnKLo/8dqfMORCTEV4pGGvs7QaQjlJi97GTA
|
||||
-> ssh-ed25519 tOH/HQ CLzuVJ/C6CXqOHSTAwlHSSnHTQdhtZHOX6JN9DlXC3c
|
||||
HmPZ4REBwaJWcRMTyThIZ5ZKz6P167+Qf6gCIdozblw
|
||||
-> ssh-ed25519 FpzvfQ jx88nIHu2H8XJky3qAQhTr9wE54D1eZgaR82UrfJFxY
|
||||
pWIJCFJWoZq5ivah4Ynlo9ob9hGAkXJT5UyGbV5s0hk
|
||||
-> ssh-ed25519 2UotMw EOSb36AGm6JZYAVhCJAr+H77rGKLdMef2GwLRlH1GAI
|
||||
1ZaO3t5TAI9t0d7E4X5mSUjAmdqyQenjP65Mr8pITb4
|
||||
-> ssh-ed25519 kdPvzQ N0bGzFuEbcSdKk98BManPHjHM3rYrImzI6JdIOUTzho
|
||||
DV3TR0f25qcv9GJ5yuq1psKlcioXnwLyAcvXNsFq3Zg
|
||||
-> ssh-ed25519 onmXpg rHXkabxqIP99M1SZgwCOx5thK3ibguONh+42sGL5Uk0
|
||||
AF+sIC4kvcMMlTmjgsBNFjXnMkgnHI7lfq7tiUWz2zk
|
||||
-> ssh-ed25519 CnhD0g YFuDnyk5ML+8kqAZqznPkhrdlebgPO8ncatfLeDNNxY
|
||||
cnu39kgkX5CdCy9dmcYKvlQPu5NxqdKkbuoUkKb+FI0
|
||||
-> ssh-ed25519 4ep2UA q1lMSlB+P8mgPeHrMnlshDq0ckjAnHQ74Mp+2kwpzXg
|
||||
0Lhvb7tvDmLKoFhACmRtWKhSVtCc31IjSENhih5GVEc
|
||||
--- FjiOMHh95R2Q8Ft3G/7VUbojHcWC3JXZ+nXBnZ9fSk0
|
||||
h6~l|\fhIª¨ðå —,`•�¼5ÐÏ¥²Íkorä¥w˜ÆžqÊ \vIËû¹woÅ„geÓ¡»J)\+ÅY˜å»±&uP&¹Ã³Ú�êëݪR³ø¸<2™;Ãqþ¬ïtýRƒ¸²«qŸ'E’¢áUëþé)ø›ßµ5]!¸{’o!Ï#ætƒ×mÉu¯5ÝC™ªövÕ�1ÿRéÐ’ýš|óᤅ$ÁP¹”“ëßéË6€åºŽ„B␍óÀVéÅù@1LÉgÄð¼À¸‡_ŒƒÒÑ•;³tWý²yŽ`K␍�®®„z(Ç@}Ú?Üå~£¬¢8+¥‹„“7Ül¨Ë2†_^¦n“érˆë¢/¹ÜÀ‡€Êk«¢fMð)áÅ+6Ø)Ù²²ÞØÝÍÙîyë´Ñ ÏRTQ xn6•ï Þæ�Ó?-B×ìY�Z“F²~½WÖê'
|
||||
Binary file not shown.
Binary file not shown.
@@ -1,17 +1,41 @@
|
||||
age-encryption.org/v1
|
||||
-> ssh-ed25519 aY2AXA HU+4yVH3avBUxCMrDare7bCepx+4q8p2O/XNqjUSxyY
|
||||
Pe4scldjyE3qj7iingCerOJ88mCPf7dpPGyCbdC32t8
|
||||
-> ssh-ed25519 AQhf1g 02v5PhAfq3Em/ULRq2Rb7CqB1Ayw0USqmbWDAqGCzCc
|
||||
wJxmhi2P/ffPoCDMkzgcD+WJphRuWg6eyS/8pXjm4tc
|
||||
-> ssh-ed25519 YJiRbw wyOuC5ktkSHmu3jg1XW2ieUsKHPJeH0QhYAUj9ibVmI
|
||||
rw6I5S2Eu9U2qxGvdM0MwRyQ2JyEjvS4mnK7cpA0T9Y
|
||||
-> ssh-ed25519 CnhD0g 2Rh5MJAxo/VAy2yo9X6fCiGwnv8l0UWnBiUb3ecinEw
|
||||
+WemY5Ydy91b0udadcW7y5cv9wpTCsld/mL3BFlpx5U
|
||||
-> ssh-ed25519 kdPvzQ gCLwlt5M8LzpXlj8ARE0SG/FjDaIQfUdE5vR0UjkazA
|
||||
JG7Mb0JEXcXLvnOrQfKpvNnVaUFsjAJS/d4VKRckuZc
|
||||
-> ssh-ed25519 tOH/HQ W+HVeDX+2GdoCS0Tqlg+I5tbzPsdiQD5DvLQ20qk5BY
|
||||
v8hIW0lg9oqnYeJuU1CiP57Rr+P9e4D0kYX7oKuIFCU
|
||||
-> ssh-ed25519 4ep2UA BE2nO/96pduUhsUuEStqfuBth8DDp9duYjhnQUbbF1k
|
||||
pkTD/ekiGw5ipPj9bpqcLJOeVHz251mFfCpPq+T5ojo
|
||||
--- 9yrA+4m628mJZQPFhpIBDRwYJ4/dplnYBvzfqzCDCm4
|
||||
Ê_±{JOøŸIBq1)òr§Nã;VH�±ÝÕwYÅWºÞ¥–¶P„�&�îÓÀÏè(ŒÔF�€â1gyÝHÅáäÌ‚]ìë#éö÷w‡ÿ£‚‹¨kÃè¨MC½ª³à
¯‰ŠÈ`£ìÌPîo¼æH4µ›ö®˜¬³÷bv0
|
||||
-> ssh-ed25519 87huqg yQ+ChAVhaF2JUmR5l4XVxA15edPMM2mtfTIYskYxMA0
|
||||
XLQioeVlZvwEP4lonmbWK3XDtwuhZbtrJud+Tov3oY0
|
||||
-> ssh-ed25519 8UnW5Q w13QV7AO2a8PkB8ADjcGDsSy6CJmitnqeglHXuCCrXE
|
||||
iMkDqTBuTg6qxB8g0QVhR02Q1XhIpJJ+dmIkLSCEj48
|
||||
-> ssh-ed25519 UFfTmg 68xIf6Ws46UFsCGM60ZI+WWEw23tCLrS8txQobkxT1I
|
||||
pam9Uh9cUH/lTAT4SExDxVPVKMU21yKxvD/jFupNcjQ
|
||||
-> ssh-ed25519 KbVVUw zVGt6E/y6yo5Svg3pT/PFrJqdcDItTtY7iTtHw3xAAs
|
||||
pHAB9mcwcKNq8Qk1VWIMcG5gKS8B6hMbhAaT7J8zFBs
|
||||
-> ssh-ed25519 xNtnoA Q8qCsBO+xEbY8HKO2QjsrBASa3GMkN+/NhA4YloQh1A
|
||||
WOqB67PuMU3po5SPFEuskSw3QYz/80zKVlV2cR1wb/0
|
||||
-> ssh-ed25519 aY2AXA YxrS5wf4BgPdckDW+hpymBhBxBsiESkO+9IWI6xRjSU
|
||||
szYlR4jB+Vm43sMWoI6mt/pNi9K1ESCvvPvNtqXI5qo
|
||||
-> ssh-ed25519 AQhf1g CKzzFtvqdagNBkWsKifS/svWfp+TmEgKpv9RzaOZdzI
|
||||
pbjXLSY2s12MzwXXvwrFroJXRUvlxnL+/5afDmSB2es
|
||||
-> ssh-ed25519 mOmPfg OhqP2wxb9HMSnLY0I1tssQyDBveCXQZBQgOnbct1+yM
|
||||
1s7wbRP59hWGuREWNE3ReyyW4DuSC4B1W4ndwxRICzg
|
||||
-> ssh-ed25519 YJiRbw JqjGE7ty/3i2rouZmFoEfT2H4bpXtu+KdF2MLc4BAWI
|
||||
SyOG4VKq03clWTjYcSU2fGLLH9pG7jOwFxpVC4nMd7U
|
||||
-> ssh-ed25519 Nl/5yA paQvt0rjRYyT8rEJnlChUwuV0hEQuASE2TsNTPdIPx0
|
||||
jOo6mBsb3zG6NMG3LXHC+yaXqA6uakDSYtgRbLeLEXw
|
||||
-> ssh-ed25519 GdLgCQ W+GA/SL5OyVQPEF6SMJfRDPq+RWsjsqtQ3GTnKVMwWw
|
||||
edcakGvsIJ1rVbok9HPY70jQ2qPT24Fx05G3xCV8dUk
|
||||
-> ssh-ed25519 tOH/HQ 6DwpIUJxMTvG6zR1t7oJnDj3/CAGgWg0krlHtszKwFQ
|
||||
BbNzDSCCuA+hJE2fzpc8kkKgJRh+ssn8v33F6+fz9g4
|
||||
-> ssh-ed25519 FpzvfQ 14i56MD+qHFHYh84J+Y+H5KToSEtr+5PUIScS+8DOBQ
|
||||
YcmBoUTSpm2EBR3MADURIXyN9+UebGTiYBnp0q5V9gc
|
||||
-> ssh-ed25519 2UotMw AKa704qvbGtoTbKzCu7XTnBVfQJLjbeBjUaXGOs4+Xg
|
||||
gyKLbQr41mhHgBO6OsKBk2JAqylGxtW//gdbXFxk1+k
|
||||
-> ssh-ed25519 kdPvzQ YWTa8BfZjV6ke2JJ8T6H5mlQZXw3NJnJIzxOmlv2V1M
|
||||
jwnAs1aF7YIKKvVmNy1zBjwgtfJ6fP6sZ+UQq4IGlQ4
|
||||
-> ssh-ed25519 onmXpg VTK+oZBFFSTRW6C26nSIiz7GmdwHa5NCrlbE48H+dlY
|
||||
2mJjLtZy+d5ohpGs7CPsBrCcZvvakfyD8uqE2S5zcmk
|
||||
-> ssh-ed25519 CnhD0g aN7aF1nuz53x5u76zWhifAzKLmDWH+oG3ni/+CcHiDQ
|
||||
PunfAegiWVxfgP1deGTuueA3RV4LADBkhbQ4uiKKIfU
|
||||
-> ssh-ed25519 4ep2UA X/sVgcQpNxi3JDZPn6v5PmPnNT4AMP8g5Fw/PtxFFho
|
||||
8vtv6aV3Mcy/AjhlGcM8H5vcEcO7YHmYrD4SBZ8PVv4
|
||||
--- 550ZfMGzT3uBmP5NzcRZ5gtjeIpsr9+tZjigrw6eqZU
|
||||
uJ4NÒ00DÚåòx!c”?ò>Rh]üZxë=öe8…]æ„”ËE
|
||||
û\æ7-Ï@I‹côYj´mßùöÊÍŒ� )CÉPëVèK”Ê„ mØDuï©«Îç´)×зü
|
||||
p0ïßr+ûŸ§Z´p)z!3…—Õ�é–«Ú´
|
||||
Binary file not shown.
+38
-36
@@ -1,37 +1,39 @@
|
||||
age-encryption.org/v1
|
||||
-> ssh-ed25519 87huqg gv0jzWC7KtVxSEeepOckxiDwxN6VdPzYaXjZryNlUjE
|
||||
04mMQsL99xW+VbpELVdnWehgq/3u50l5f98ZFTscSwU
|
||||
-> ssh-ed25519 8UnW5Q GzZDPqTzZNU5Dun3u7rSane+MXkDcbIM3TlEEJr7cUI
|
||||
Dh/3ObCIG56797AvmSh5yrUk+MWqjxJ42/b4i2smnos
|
||||
-> ssh-ed25519 UFfTmg 7EWxx0WGxxAP2sErB6Rfteg2o1su5n1ELN7oCUsodEQ
|
||||
S5x8TAYvjxjtCJgmY4ttCxvoZDdHMxY2RbsAJ7DxfJY
|
||||
-> ssh-ed25519 xNtnoA 9mPAgc7YI355QYNlTlJWmMhaScCNbCH9EofQcJJDeWk
|
||||
QSlYi9COKd5ZjkC7Qxp8IcmmVJifJ1qy70VnExASqBM
|
||||
-> ssh-ed25519 aY2AXA JUIOcOAjshTPueqEo/GDXWzEubBt1JuMM4NLv89zfTA
|
||||
njcVfVgCmT374IdMqke8AWGyGcpCgpu5rGs2zrn/A2Y
|
||||
-> ssh-ed25519 AQhf1g faN3428QM/K0P7o6nlPxT3lHlx88PBIWxw1mSN07zy8
|
||||
6G8FARubsbz7TtQWeQ5biww7XoXZrs0xDFdxKwyov/U
|
||||
-> ssh-ed25519 mOmPfg b7LviVrLo50sU195qKNxtD6lEqq/QJBnHFkQ3WdKT2g
|
||||
USSSrAIA3v3Luzt2Kft6fpMx4fXHAPBtWQVAAliiV2o
|
||||
-> ssh-ed25519 YJiRbw QjrEHQL9zx6pIR/HzrKyM94JF7efjkMo+ArkVOjkQlU
|
||||
MfUl5yYO/LtxrENlcw2KgzyJiLpd/Xk0CbEJicxgG0E
|
||||
-> ssh-ed25519 0/WsKg ER1PXYwpONwb3U77qUoH2ZDFmfvRQ7SV8lkgHqRJQig
|
||||
MCRbKzFD72DdZwoVrV5DesMbNG6ikMlL5C6mTSVGtj8
|
||||
-> ssh-ed25519 Nl/5yA XKaH3S150ZwHo4uyLwaBrn2od5v6MRvc0bOR83Sz5Ag
|
||||
RqQn4/jo122fZA1oujOkwe4gbnGfn5BK8CJXi42NsDM
|
||||
-> ssh-ed25519 GdLgCQ XVrC/NooMQFg4bSPQ09avkJ2mwROHp8mYbBA7dWjSCs
|
||||
Q72VZnjs6Y574eRwheabzTW2GH8A2oEOEyk1Mkh+NzU
|
||||
-> ssh-ed25519 tOH/HQ b55WhSZiczkXRQQTxAFBeN4HKyi2orpR+ikGiSyaonU
|
||||
woTljkdrDmI6iCwUnJ7i1kLdfH3QaZgkxxQ+Upik6/E
|
||||
-> ssh-ed25519 FpzvfQ +kFO6lyChWKyGs1vN8XmRnp5wNUrOvKGAMtQB5gYJyQ
|
||||
xQbRbUfvk9Eoi/JLfzugHeUVbPGfFItkul33A7MVx3Y
|
||||
-> ssh-ed25519 kdPvzQ dv1xr07TrUQRGwl6jbxMQlocvvYlTmyzyZpbRAU5rg0
|
||||
IYO9Af8yAxY5499AArmWCy1aV/ZB3w3deBS4OAHq+LY
|
||||
-> ssh-ed25519 onmXpg 8cNof6Uwd2MpA3ydHLQHAQvFvl7Kk5moWMRD5qVFxGs
|
||||
hTMO0oPxHajokrzMIWB5ksbrVFcpQGo6Jje9FWoiPxE
|
||||
-> ssh-ed25519 CnhD0g kqhzl+91aQ7CDRrXzrLPo+P5GuEOSF0MGQlfZESPJDA
|
||||
64xA1PirxldhnScyJ0njwaOMZ/EgPRm1hQzojJIa+84
|
||||
-> ssh-ed25519 4ep2UA Zss5olMIbVxEJT8XdrFSrBOppplv8+x5ej3CktSUNDs
|
||||
ldPkN2iSBrU8M7WCZx+PlgUhEIZEoUmRWRgRHvG7+Dk
|
||||
--- emzp8uRGi0GDRt9HS6E6NvmwB7LyI8mWED2Mof9KFrA
|
||||
WK çƒ¾ÄÆý;m7…%‘cl4‹8Wáå‡÷'›D} ýœ.x÷l»fGºj�«yàÈI2ˆ~h•YKè‚Ͼ†Ù‡ÅƒÉº…"VÕ"(HQ>åEAG€æx1
|
||||
-> ssh-ed25519 87huqg tRkWo/tXovX5ukc6DRiC55s28fMJvry4lgSWeGnQXHY
|
||||
G266810Co/QUFWle5j9W8P2+cfoUmZ5gEKcCNg5jw1A
|
||||
-> ssh-ed25519 8UnW5Q OqyBBxWRBBpAlS93lZ+TGl2O2NwhS5/ZsMbN/sUiUVI
|
||||
N6csZzFJUU17JEsLUVRzBhM1at00bu9rUzXE5JAML9Q
|
||||
-> ssh-ed25519 UFfTmg iuxAyKikNUPm9QJU9O8UYspvWjWe7Te26uzPN6s8yww
|
||||
VCpWZVtTwHlOC7PXk6xIezNbIMgFObavv1AFinouU40
|
||||
-> ssh-ed25519 KbVVUw pVU1pSoYn5SiePORWE9bJk+w8pn76xyhFrXi3PQJ0GE
|
||||
d8Y2dt840M954ZrqRoSeUPDjPLoM4EJwKwu4+5ehddw
|
||||
-> ssh-ed25519 xNtnoA L8MxfT93s2I42dirqXnf+VRWq26NPuZ6Ta+0vcbwYRs
|
||||
0RyuZdK1sqCpuMDVpUpJkOs8OGhjz4vojNpmInX4a9o
|
||||
-> ssh-ed25519 aY2AXA prgbsTVqCxDqX9fB1SwH0Pz3wHNNut2Kd/g2CT3pE1I
|
||||
12LcMPa0xpx3vtrmNQ0JrJa5PUCcV+jj5s4c4ttRn18
|
||||
-> ssh-ed25519 AQhf1g Tdph+xLV/TIYMxExaUo+xgqd2Cl5o+BCSEKHWhYpTio
|
||||
ecuPMlwtgIbBoZ5mucYglIamW8FqeJT4ZXs84CcSaAM
|
||||
-> ssh-ed25519 mOmPfg pmE+ZERem6G19KtQ339alV0mlSZxOdU0s/NSY9oykzQ
|
||||
i57l9Oxl4mLYquHwFIsbPtmhyjyH62MereQzNf/vvhg
|
||||
-> ssh-ed25519 YJiRbw 7Q2ue0YEapF+lK7204mDbRTOxU4BrWC/01umQw0DCCM
|
||||
+Ulv7yL+02WvDmrtlujCD7zR6V2Npm3WMqvvSyIpOH0
|
||||
-> ssh-ed25519 Nl/5yA 0FmOQ2WA+qXbhHy6WimadXJKVmgUsRBbOPsgFJ6Qtiw
|
||||
xhJkG+SSdnYgMWeJk7ciLI9bS+c403p2PqVRObk9ezA
|
||||
-> ssh-ed25519 GdLgCQ Ovn3zHYbFImNyPz07xjMDYnUCnHpejotNfVyD6olgGc
|
||||
AfF78TueIj5jnz+q7vrXyu1BZ6VN0hkTpg1LItmnCYw
|
||||
-> ssh-ed25519 tOH/HQ x9alUL3V2mHyQHt5vPIDBq+TNE0tYkJuP8KYE80VinI
|
||||
se1kqe3o8bKr1AkgH55NTPMD6ZRkdcLIIZ0YhEVkTq8
|
||||
-> ssh-ed25519 FpzvfQ W6oRWhWgbZjLrJTkFj9LJWcq3gapz6vRtdSjV4g/yzE
|
||||
GYh8HSC0mPRGRu7jT7DGx3py0Gvu/zu3BzVdXL8gU1A
|
||||
-> ssh-ed25519 2UotMw +XsUycMbAALayfAxF/SvkoWv5ubzWp/RvJcD9sWeSAY
|
||||
j3lHaEJzFk7R48RNbGNzcMs97p12n88L9WjockK1N+g
|
||||
-> ssh-ed25519 kdPvzQ X06P2aEDkUoSk0KVLZWC9DGyNnVlleeBft1xQPecDnA
|
||||
6p3jxcHePWO+cf4hnALXxaa5bN8B9AZo+qodDyK/Evc
|
||||
-> ssh-ed25519 onmXpg +9uXItde+0h/bBcSEwZ57y36bxwwoCWY2SvN1jG7rVM
|
||||
2VyLiThmzYQeDOk7TaUUslec0qvr7UMSiBTHsEpR6ss
|
||||
-> ssh-ed25519 CnhD0g feqQLfUYnakAiHJo+gWHrbd5o9WyQ/qluJ7/d/n7PGU
|
||||
g5l7RvpeBRwnFRKhAED75QC0d6DiGlFho3D5tPumiIY
|
||||
-> ssh-ed25519 4ep2UA nkc+pDUli0BTe7XoDAJEOLnBDeiekZSv7XVL3POXCTc
|
||||
iWQSdc2hWP2UvyyISoUBKOhRotPCv2ySsfmoAAOLgFM
|
||||
--- YRWXRvqVNx+YrIEW8vp0RcJLM/leQUhHD1WKnaEqprA
|
||||
$f4jAjlÚaôp@™ e¢!(°^˜rˆèJ÷¾%h¼h@37üß1š+'žª´pŸœ†ÿbÿó1,¦jÂôA´n£€X¹ð‰¤3jýÈÇ[ìÑW#E\NÑÓÖ}¤
|
||||
+39
-37
@@ -1,38 +1,40 @@
|
||||
age-encryption.org/v1
|
||||
-> ssh-ed25519 87huqg +F2U3yjndWx1Xb0oDf09pUyd+xljCHWyt9xcT8mjWkM
|
||||
PcPUpkFUsc7gnAHZ+lkKqkHf4TWlrbQAjDRTCc2xXxg
|
||||
-> ssh-ed25519 8UnW5Q Xeq4SvJ6FYT1mIWhBUiNqqAF7aJKbjzRiIYBpnvDRlc
|
||||
zG8aAFlLimU0SqnC2z5bDQw2Zm1cW2vvYqnVjMcxNSY
|
||||
-> ssh-ed25519 UFfTmg 5FIJ9JJPIuMuK7BpVEZBbB0rztiLhu2G3dfRX52pYhs
|
||||
sbRMpJTh0ANEVIUUBAgr2i6Hs1cdy8r1wmMPkANE5DM
|
||||
-> ssh-ed25519 xNtnoA hQ0T/i4bj096xuY0GUYM4N6GhyyFUv/dajBD27SA/wA
|
||||
hmV8mKYGOR3WjAkH/mO8ZFyDGe3N6R3ze+dGVh7OGIM
|
||||
-> ssh-ed25519 aY2AXA QML1/v/gxLxdKa0zzKYPOWIAUVqcG8wRcx0HnM38B0A
|
||||
5hC6Si/IV1dmImIkn6SlIkWNRFgjNOmUTC6MjGTE0GA
|
||||
-> ssh-ed25519 AQhf1g 7h8ZokLoQFV3eUdzzt9qzRhxtP7U8Zl70ds+znsa8yg
|
||||
M1WUYlD+1ZzrkiSEQG1CyyViv5Z/gqPEa8j6AGSbyOA
|
||||
-> ssh-ed25519 mOmPfg xxbhbwb6mdf6q0G6TaXXSt8qN47ruYhDLCMnwYZyMS0
|
||||
fnsG3+N8DSQCxUGksvHmWQNdN00I0OO76YlDRFUW+no
|
||||
-> ssh-ed25519 YJiRbw Og85bpfNOPBZkIeD6qS022hxu/A9AyiS5rAodpblLzU
|
||||
qX3irxsnsRO55DCQvzIkxxpQeIhWhfUNjlONJuGmXeY
|
||||
-> ssh-ed25519 0/WsKg hDApnBntBbGhAJtVGVujL3kJDzFMpOh6zIsIowlJOF0
|
||||
wNTOOqR/tnZujRMlt/AqzTscsz46sbf6NSauj6uMunk
|
||||
-> ssh-ed25519 Nl/5yA O1CBq1B+yjgO5XW4zT1sQHXPX8QioIj1mbyWHDvtiyg
|
||||
L/Duen+XqSD+mwe51nZSxT5MIa4nnywvVsq/Jgrujn8
|
||||
-> ssh-ed25519 GdLgCQ 5Df3/IrcNYYFcSOyuDpHgtaJOtEPVaK++YhiUh1NvXw
|
||||
K2Dmj4jajj6Df7zcjquFtTKZvUo3cDwBcCOpBaizv6E
|
||||
-> ssh-ed25519 tOH/HQ FgS143ErZf0eA7522s0KwCQWz3CSxyMWYo2a0N+bZ1A
|
||||
byGgVzxGE9zfbg3aEgm3goeKGKvcgnYu/gmsi3aJZ9U
|
||||
-> ssh-ed25519 FpzvfQ +PrSsNewNU/exnAS9MD1IzqNar71A/4u89DaZvJCkF8
|
||||
FLDdWILk85mpwgQHnzPGltf1Ua2EVKfxhBxgpDhFPZs
|
||||
-> ssh-ed25519 kdPvzQ Tvto3BbEHZmOhEoRqDySQhVikIK3yn1+uCqoTC7kFxI
|
||||
cQBdUfwLrJf/7eRNsXzc3u2McgoOdQC0bfwprg2JJPo
|
||||
-> ssh-ed25519 onmXpg OHIlO+j2WYPOeNnZiQzH9uHL9ERpgmAXuy1pFF8i00Y
|
||||
6x8w3js70/Uk9BJJ62eXjxIkjEMs6hIL6lrnk+YMW+Y
|
||||
-> ssh-ed25519 CnhD0g EhEsiEqqpUuwmyrE2GIujh7sZf5/v7Ban5Lzx6sFOUY
|
||||
t9rI2DwfK8HRkSmGHsWMX+trPekWRRbLWQt/CFqwUCQ
|
||||
-> ssh-ed25519 4ep2UA DsFQi2CtVrLPUdC4ReFKWIXDFsGoBXGjyFYKSHkGjiY
|
||||
M/cGbVkMhKrTkPl5cMV64MyI4tHrhPcW5hgeys3Tphk
|
||||
--- or7WlSQMXGKm4n9gglHmDGy05/fieyJcU4ytHyqHWeI
|
||||
ÑrèM‘IqTd¿oŸ BX.%µ£Òµ�¦ÅvµL> %â"¯ÆæYxK²ÝÁÁ}s8ñM„9eŸ²NñË
>&£?’“I(\KB~ùù3ØôZ鼃µ$Wıu•±€`‚�€+Ùvˆieâü¼ÀÎÂÀÈ) =®�²99›ú_pHŸñçP×ÅAnOÄÄõc«FÌî½R±ƒ�)Ò_Ûd®ÈÞ(ûÖ%^S’ÊŽï¸õãX@ã,c«ÔKæ�¼ç Tþ§CkúõÆ
|
||||
öQˆ8Íp0~RˆÕh±‡ªaïƒlš�¬À)Œ"\LŠ-.©?à±DÄ®)/'W¸®Ô`iþé©´ª@%™UAÏûó[
|
||||
-> ssh-ed25519 87huqg 42tvGwJ82PwlXbr+TqSz08omHABPqv1TH5plKNLLvkY
|
||||
4Xwl0lc+zSL4k1PuIO9qF1Ci8mOOWciq5yGbbqW6nLE
|
||||
-> ssh-ed25519 8UnW5Q gGcbBcV2tF2UaaYBvM/jiNH8Lc9Fl62NZIWSbNVZeX8
|
||||
1TLxRM4e4/T/q/8Bdx/W3Sg5eeq3g6aUcka2kizF1O0
|
||||
-> ssh-ed25519 UFfTmg oNyxvAIg2hYEJ6Z3r9MzuR5YgPW432T03/mcjLeLOgs
|
||||
NZOFUzuaaxwGbQDkDinSzjbFPrFETbQOEJwrgyYtKpY
|
||||
-> ssh-ed25519 KbVVUw annu9kT2zbKvaE3WwGtDGhvku/Pj8a4P5GEQLhahZiE
|
||||
RKg/owcXYN5pqsDxjlaNPg6um/7/eoXxZ5oJxxouxjE
|
||||
-> ssh-ed25519 xNtnoA tN13P6fRYHjVTmXo7w6y/ljzr/8nEqrlgZXpG5jA218
|
||||
wg4SUSCWqE3iskGPE9qJ5Ot68pcvwCi9fmE5NXZqYCI
|
||||
-> ssh-ed25519 aY2AXA VdvvL8lgjZBhflonEI96VSFgYaUX3Tfvjo148BA+Uks
|
||||
ZljFDZ61GKr24lWG8z8sKke1TpTCiSeqyd05yxNFTVo
|
||||
-> ssh-ed25519 AQhf1g jKvD41VnPGoCBEva5llD2NQo42TDnpp9M28BTBewuR8
|
||||
TSBZqNLhG/PyToBnX2kwevA35QKmKcjwcPe8/JUcywM
|
||||
-> ssh-ed25519 mOmPfg /yX7XUVozu8ZTCW9gJyoGd7EzBISb0c+i08HEsN7ODw
|
||||
e1rAICTZajIF0AaWXBATDNuqQK4GAqxEjgxvaRzDark
|
||||
-> ssh-ed25519 YJiRbw cy9m8KQln8ryxLEqx1tIoZRq4SiABQFT5IzmMlgkQjA
|
||||
P4OLv+oTFhgnLzb4YrhFdV6jreAGhXBkMCe7pb31KTw
|
||||
-> ssh-ed25519 Nl/5yA Nx8mErRdN8sIaj8ueWnDkSw5vBhfkOW5Rk2ND3gwZmY
|
||||
6elVFcWQnwmh7NvRm17+WahOkvLmQbqBBKnruHT3yp0
|
||||
-> ssh-ed25519 GdLgCQ WwKSzJsPG8vJjRjc+nkyvGKtqLvpKe3V158fRezWtzk
|
||||
mKdk9Z2wOipmc6brgNWeIbxADdkkXAFcs8E956RdHTs
|
||||
-> ssh-ed25519 tOH/HQ /CL2OxE6C8ZCfHgHTQQJmuACG5lZ8AdVpDe1YfG9mHw
|
||||
7uaalUdP5vCjsLEYdp+LREaxU3Vo0VUCVXn/H0WAa4I
|
||||
-> ssh-ed25519 FpzvfQ hE8FGN82H81RWUm+LgCuvQMWra0ulwMHuGSYTdQvc10
|
||||
Eq/btSgef+2nkQGreBhqRKAt/6CFo5ahdRbBfCO5Bv8
|
||||
-> ssh-ed25519 2UotMw mqdgTsPI9vockRACf/NdD466WkIyQvSLuEJSrT5mDwo
|
||||
hyZQCiUCu8gfVTCZ8wMxo+i+CqjhE9t+hdJrJcm1dNs
|
||||
-> ssh-ed25519 kdPvzQ fO2iL5QnWBxRFe88W488dkezFsMxJtMBc5GKACOZYjk
|
||||
NPa4r9t7lPt3mMgHjT6soAK/RWLUe70Lh5i7LwRYlgE
|
||||
-> ssh-ed25519 onmXpg 9N98xltPTCAb42chNAOb4hYr7equq0lk9nTqol3EKXU
|
||||
tdQ7FSABTifm9sHKzOVFyoEbOjS9TYS7DPsFrBqmnLo
|
||||
-> ssh-ed25519 CnhD0g 1oi9mdmL6ODCgi3pWGKEqU/QN/v41XQg7nUZiu5frWw
|
||||
zXOUj1z6Z6DKyWr2ZqyFFZGNwKkz3NdyEUqWpnl1xI0
|
||||
-> ssh-ed25519 4ep2UA RKc7+piJY2Fh4NnZGvEuAzJIMxr9NBQQBSMj3xQqrSc
|
||||
yqLK6nR4b46QPwnH9DuZ5spzIu8fQMAxmLYNtj5jAu4
|
||||
--- R87vMnH5oLHLJgD7rCGZwz6dpc/a0kpm/fi28jqVcT8
|
||||
\_UvF9‘ˆ±gøË2�Ä®Ôbá/0=íOÙµò´``lú©žµ^2&…àâWëñº‰W§¼
|
||||
Pc–�‹,™häZO'kÒ2›f'hB©ºp>¯l\›M§¤;‰òouFü ë…œ¥X)P!hÂRo]¬Ø† Ù/{—¶6Ä•÷ƒt»¢¶Á<Þ$6tá[6ÑüAéaó7œÙ–òúhiç«d´Y-jëº »_ý)£“Ò‘b˜˜ƒpɪÙ9Hå»\HBÂ6dß(}ˆ…~¨¦íåèq¡x5P{x…@ü°G�E0x&0ðYÐÆgó¤¿4•—±z‡•n•!Ù¿ªðòˆÍ�Ð{ú9
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user