053e383046ce8451140f5f06ec44265d214506d4
With enforce_domain = true, Grafana redirects any request not matching the configured domain (hosea.shire-zebra.ts.net) back to that hostname. Since the nginx proxy serves Grafana at grafana.thehellings.lan, every proxied request gets redirected to the Tailscale address, making the proxy useless for non-Tailscale clients. The domain setting is still correct for cookie scoping; enforce_domain is only needed if direct port access is a concern, which is mitigated by the firewall (port 3001 is not open on the LAN).
This is a unified repo to contain my personal configurations for NixOS machines.
How To Use This
Go through the normal process to setup a NixOS system during installation.
- Boot from an appropriate medium
- Parition the drives
- Mount them
- Before you generate out the configuration, clone this repoistory to your /etc/nixos folder
- Run the configuration generator. It should only genreate the hardware-configuration.nix file, which this repo gitignores
- Create a folder and file with the machine name in
hosts/<machine>/default.nix - Add
hosts/default.nixan appropriate entry for the machine you are building - Create a file
home/hosts/<machine>/default.nixwith the new machine name as well
Adding new hosts
To add a new host, create a folder in the directory hosts/ that matches the name of
the target system. Each host must contain, minimally, a default.nix file that serves
as the basis of configuring that host.
Test build a VM for your system
nom build ".#nixosConfigurations.<host>.config.system.build.vmexport QEMU_NET_OPTS="hostfwd=tcp::2221-:22"to export the SSH port./result/bin/run-<host>-vm
Languages
Nix
87.9%
Go
3.9%
Vim Script
2.7%
Xonsh
1.8%
Lua
1.5%
Other
2.2%