57 Commits

Author SHA1 Message Date
andromeda
d2ea8ab074 bump anki-cli 2026-04-19 10:37:59 +02:00
andromeda
faba184a58 update anki-cli 2026-04-18 08:22:09 +02:00
andromeda
055657e082 stash 2026-04-16 16:52:00 +02:00
andromeda
a6ad2a25be fix minor bug 2026-04-03 21:36:36 +02:00
andromeda
bc702e48eb update remote pub key 2026-04-03 21:32:52 +02:00
andromeda
2ef56f1479 tidy a bit 2026-04-03 21:26:04 +02:00
andromeda
de1879b9a0 idk prolly smt ig 2026-02-21 15:59:08 +01:00
andromeda
0647d9a8e0 fix certs? 2026-01-26 21:58:55 +01:00
andromeda
8c0db96ca4 robot, also continuwuity, also zram 2026-01-26 21:40:03 +01:00
andromeda
2386fea0eb split out phoenix overlay 2026-01-25 15:44:32 +01:00
andromeda
e1c510fc64 remove npins fr 2026-01-25 11:00:30 +01:00
andromeda
e4305c15ac failed to npins, patch phoenix 2026-01-25 10:59:20 +01:00
andromeda
5c99e52e09 patch phoenix to allow user to auto enable extensions 2026-01-25 10:58:15 +01:00
andromeda
ad7e25dce3 init npins? 2026-01-22 05:38:05 +01:00
andromeda
1a62299225 update nixpkgs 2026-01-22 05:37:51 +01:00
andromeda
6e7e52aecf init npins? 2026-01-22 05:35:49 +01:00
andromeda
a0fa657600 update nixpkgs 2026-01-22 05:13:18 +01:00
andromeda
580cbd1851 init nix-on-droid 2026-01-14 22:57:40 +01:00
andromeda
6fdcd13627 adjust brightness, disable touchpad sometimes 2026-01-14 20:18:25 +01:00
andromeda
6fb816f27c reenable ipv6; reconfigure browser 2026-01-14 05:31:48 +01:00
andromeda
c0e92a4ef3 typo 2026-01-13 10:55:24 +01:00
andromeda
b754a3d53f matrix-synapse? 2026-01-13 10:48:56 +01:00
andromeda
19d45ebd05 edit TODO.md 2026-01-13 06:29:18 +01:00
andromeda
312ee02d9e fix alias traversal 2026-01-13 06:21:08 +01:00
andromeda
c377598d5c conduit setup? 2026-01-13 06:16:27 +01:00
andromeda
dcb82ed361 add README, conduit 2026-01-13 05:53:57 +01:00
andromeda
b25ce469b6 persist zulip 2026-01-12 19:09:27 +01:00
andromeda
d2d370442b ssl port email? 2026-01-12 18:01:52 +01:00
andromeda
e05c9fe5a5 add tls (I don't know how this works) 2026-01-12 17:46:49 +01:00
andromeda
c1d8b4dff3 use non-tls ssl? [fix typo] 2026-01-12 17:37:55 +01:00
andromeda
a7e65a0943 use non-tls ssl? 2026-01-12 17:35:38 +01:00
andromeda
d2e95f2fb8 add EMAIL_HOST_USER? 2026-01-12 16:31:58 +01:00
andromeda
9b0944223f fix typo 2026-01-12 16:19:37 +01:00
andromeda
bea6414758 actually add zulip module 2026-01-12 15:45:38 +01:00
andromeda
90ad40e207 fix zulip? 2026-01-12 15:41:06 +01:00
andromeda
803bc95317 fix dkim perms? 2026-01-12 14:26:35 +01:00
andromeda
4bd6ddece1 declare dkim secrets 2026-01-12 13:30:25 +01:00
andromeda
3fa9a368bf update remote pub keys 2026-01-12 13:04:33 +01:00
andromeda
103ec86fc2 persist /etc/ssh 2026-01-12 13:03:02 +01:00
andromeda
d9a6791fa3 ready for new deployment 2026-01-12 12:55:20 +01:00
andromeda
70445c1c8c update ff search 2026-01-12 12:53:33 +01:00
andromeda
47aa29ba33 finally fix ipv6? 2026-01-12 10:06:28 +01:00
andromeda
0970f7d0ee fix finally? 2026-01-12 09:54:54 +01:00
andromeda
e5746332bb persist vpn conf 2026-01-12 09:49:13 +01:00
andromeda
e38e0b95dc disable ipv6 2026-01-12 09:36:48 +01:00
andromeda
e6669a9d88 add openvpn 2026-01-12 09:34:25 +01:00
andromeda
de911e358b disable forgejo as broken 2026-01-10 21:48:57 +01:00
andromeda
b76f6ba3d6 rekey 2026-01-10 20:51:27 +01:00
andromeda
45f5249165 fix ssh 2026-01-10 15:30:17 +01:00
andromeda
90dd0582b0 forgejo 2026-01-10 15:23:02 +01:00
andromeda
0781c8428d fix agenix boot problem on remote? 2026-01-10 10:33:06 +01:00
andromeda
2d1048b00f add roundcube persist 2026-01-10 10:21:04 +01:00
andromeda
58f011079c rekey 2026-01-10 10:08:40 +01:00
andromeda
d32f99baf5 persist acme, update public key 2026-01-10 10:07:01 +01:00
andromeda
13141933b4 enable roundcube, backup mailserver 2026-01-10 10:01:38 +01:00
andromeda
a57edbf3fd enable mailserver 2026-01-10 09:48:42 +01:00
andromeda
bf22a9de21 add /etc/ssh persist to remote 2026-01-10 09:02:24 +01:00
38 changed files with 554 additions and 314 deletions

2
.gitignore vendored Normal file
View File

@@ -0,0 +1,2 @@
result*
.gcroots

View File

@@ -1,3 +1,5 @@
see TODO.md for my aspirations
## usage ## usage
### install ### install

20
TODO.md Normal file
View File

@@ -0,0 +1,20 @@
- add other remote
- fully automate remote provisioning (remote keys)
- fix ipv6 on remotes
- modularize home manager
- add services?
- 0x0
- forgejo
- matrix homeserver
- matrix webclient
- radicale
- tor relay
- wireguard as vpn
- add home functionality
- better term emulator
- switch browser?
- chromium: much better sandboxing
- ladybird: be an early tester, contribute
- glide: sexier tridactyl implementation
- browsh: the GOAT
- get mouse out of here

324
flake.lock generated
View File

@@ -10,11 +10,11 @@
"systems": "systems" "systems": "systems"
}, },
"locked": { "locked": {
"lastModified": 1762618334, "lastModified": 1770165109,
"narHash": "sha256-wyT7Pl6tMFbFrs8Lk/TlEs81N6L+VSybPfiIgzU8lbQ=", "narHash": "sha256-9VnK6Oqai65puVJ4WYtCTvlJeXxMzAp/69HhQuTdl/I=",
"owner": "ryantm", "owner": "ryantm",
"repo": "agenix", "repo": "agenix",
"rev": "fcdea223397448d35d9b31f798479227e80183f6", "rev": "b027ee29d959fda4b60b57566d64c98a202e0feb",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -23,6 +23,28 @@
"type": "github" "type": "github"
} }
}, },
"anki-cli": {
"inputs": {
"fenix": "fenix",
"naersk": "naersk",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1776540672,
"narHash": "sha256-D43SN81mM21icdtK/9JDwaXsIhFv+gm4G8KXhJDCxsQ=",
"ref": "refs/heads/master",
"rev": "bcd83506ea691861562ade66ce23f57b27e57ee2",
"revCount": 12,
"type": "git",
"url": "https://git.mtgmonkey.net/Andromeda/anki-cli.git"
},
"original": {
"type": "git",
"url": "https://git.mtgmonkey.net/Andromeda/anki-cli.git"
}
},
"base16": { "base16": {
"inputs": { "inputs": {
"fromYaml": "fromYaml" "fromYaml": "fromYaml"
@@ -129,35 +151,59 @@
"type": "github" "type": "github"
} }
}, },
"disko": { "fenix": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
"anki-cli",
"nixpkgs" "nixpkgs"
] ],
"rust-analyzer-src": "rust-analyzer-src"
}, },
"locked": { "locked": {
"lastModified": 1746728054, "lastModified": 1776153734,
"narHash": "sha256-eDoSOhxGEm2PykZFa/x9QG5eTH0MJdiJ9aR00VAofXE=", "narHash": "sha256-QvkVX4Go+BnNgQQLc5Ma3WNBZOG5Jpdqsy8Ri0/CbSQ=",
"owner": "nix-community", "owner": "nix-community",
"repo": "disko", "repo": "fenix",
"rev": "ff442f5d1425feb86344c028298548024f21256d", "rev": "a8b0e62fb39299fbeb1aa365f4b57e2c258a178e",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "nix-community", "owner": "nix-community",
"ref": "latest", "repo": "fenix",
"repo": "disko", "type": "github"
}
},
"fenix_2": {
"inputs": {
"nixpkgs": [
"anki-cli",
"naersk",
"nixpkgs"
],
"rust-analyzer-src": "rust-analyzer-src_2"
},
"locked": {
"lastModified": 1752475459,
"narHash": "sha256-z6QEu4ZFuHiqdOPbYss4/Q8B0BFhacR8ts6jO/F/aOU=",
"owner": "nix-community",
"repo": "fenix",
"rev": "bf0d6f70f4c9a9cf8845f992105652173f4b617f",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "fenix",
"type": "github" "type": "github"
} }
}, },
"firefox-gnome-theme": { "firefox-gnome-theme": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1764724327, "lastModified": 1764873433,
"narHash": "sha256-OkFLrD3pFR952TrjQi1+Vdj604KLcMnkpa7lkW7XskI=", "narHash": "sha256-1XPewtGMi+9wN9Ispoluxunw/RwozuTRVuuQOmxzt+A=",
"owner": "rafaelmardojai", "owner": "rafaelmardojai",
"repo": "firefox-gnome-theme", "repo": "firefox-gnome-theme",
"rev": "66b7c635763d8e6eb86bd766de5a1e1fbfcc1047", "rev": "f7ffd917ac0d253dbd6a3bf3da06888f57c69f92",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -169,15 +215,15 @@
"flake-compat": { "flake-compat": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1761588595, "lastModified": 1767039857,
"narHash": "sha256-XKUZz9zewJNUj46b4AJdiRZJAvSZ0Dqj2BNfXvFlJC4=", "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=",
"owner": "edolstra", "owner": "NixOS",
"repo": "flake-compat", "repo": "flake-compat",
"rev": "f387cd2afec9419c8ee37694406ca490c3f34ee5", "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "edolstra", "owner": "NixOS",
"repo": "flake-compat", "repo": "flake-compat",
"type": "github" "type": "github"
} }
@@ -227,11 +273,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1760948891, "lastModified": 1769996383,
"narHash": "sha256-TmWcdiUUaWk8J4lpjzu4gCGxWY6/Ok7mOK4fIFfBuU4=", "narHash": "sha256-AnYjnFWgS49RlqX7LrC4uA+sCCDBj0Ry/WOJ5XWAsa0=",
"owner": "hercules-ci", "owner": "hercules-ci",
"repo": "flake-parts", "repo": "flake-parts",
"rev": "864599284fc7c0ba6357ed89ed5e2cd5040f0c04", "rev": "57928607ea566b5db3ad13af0e57e921e6b12381",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -248,11 +294,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1763759067, "lastModified": 1767609335,
"narHash": "sha256-LlLt2Jo/gMNYAwOgdRQBrsRoOz7BPRkzvNaI/fzXi2Q=", "narHash": "sha256-feveD98mQpptwrAEggBQKJTYbvwwglSbOv53uCfH9PY=",
"owner": "hercules-ci", "owner": "hercules-ci",
"repo": "flake-parts", "repo": "flake-parts",
"rev": "2cccadc7357c0ba201788ae99c4dfa90728ef5e0", "rev": "250481aafeb741edfe23d29195671c19b36b6dca",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -290,11 +336,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1763988335, "lastModified": 1772893680,
"narHash": "sha256-QlcnByMc8KBjpU37rbq5iP7Cp97HvjRP0ucfdh+M4Qc=", "narHash": "sha256-JDqZMgxUTCq85ObSaFw0HhE+lvdOre1lx9iI6vYyOEs=",
"owner": "cachix", "owner": "cachix",
"repo": "git-hooks.nix", "repo": "git-hooks.nix",
"rev": "50b9238891e388c9fdc6a5c49e49c42533a1b5ce", "rev": "8baab586afc9c9b57645a734c820e4ac0a604af9",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -329,11 +375,11 @@
"flake": false, "flake": false,
"locked": { "locked": {
"host": "gitlab.gnome.org", "host": "gitlab.gnome.org",
"lastModified": 1764524476, "lastModified": 1767737596,
"narHash": "sha256-bTmNn3Q4tMQ0J/P0O5BfTQwqEnCiQIzOGef9/aqAZvk=", "narHash": "sha256-eFujfIUQDgWnSJBablOuG+32hCai192yRdrNHTv0a+s=",
"owner": "GNOME", "owner": "GNOME",
"repo": "gnome-shell", "repo": "gnome-shell",
"rev": "c0e1ad9f0f703fd0519033b8f46c3267aab51a22", "rev": "ef02db02bf0ff342734d525b5767814770d85b49",
"type": "gitlab" "type": "gitlab"
}, },
"original": { "original": {
@@ -372,11 +418,32 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1766980997, "lastModified": 1774007980,
"narHash": "sha256-oegDNAvyQwaG3GqSi4U5jpKM7SYHGESGVIuKMRV/lbw=", "narHash": "sha256-FOnZjElEI8pqqCvB6K/1JRHTE8o4rer8driivTpq2uo=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "7a7b43c7231a439d248179ba8d561dd6cd81799b", "rev": "9670de2921812bc4e0452f6e3efd8c859696c183",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "home-manager",
"type": "github"
}
},
"home-manager_3": {
"inputs": {
"nixpkgs": [
"impermanence",
"nixpkgs"
]
},
"locked": {
"lastModified": 1768598210,
"narHash": "sha256-kkgA32s/f4jaa4UG+2f8C225Qvclxnqs76mf8zvTVPg=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "c47b2cc64a629f8e075de52e4742de688f930dc6",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -386,12 +453,16 @@
} }
}, },
"impermanence": { "impermanence": {
"inputs": {
"home-manager": "home-manager_3",
"nixpkgs": "nixpkgs"
},
"locked": { "locked": {
"lastModified": 1737831083, "lastModified": 1769548169,
"narHash": "sha256-LJggUHbpyeDvNagTUrdhe/pRVp4pnS6wVKALS782gRI=", "narHash": "sha256-03+JxvzmfwRu+5JafM0DLbxgHttOQZkUtDWBmeUkN8Y=",
"owner": "nix-community", "owner": "nix-community",
"repo": "impermanence", "repo": "impermanence",
"rev": "4b3e914cdf97a5b536a889e939fb2fd2b043a170", "rev": "7b1d382faf603b6d264f58627330f9faa5cba149",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -402,11 +473,11 @@
}, },
"mnw": { "mnw": {
"locked": { "locked": {
"lastModified": 1758834834, "lastModified": 1770419553,
"narHash": "sha256-Y7IvY4F8vajZyp3WGf+KaiIVwondEkMFkt92Cr9NZmg=", "narHash": "sha256-b1XqsH7AtVf2dXmq2iyRr2NC1yG7skY7Z6N2MpWHlK4=",
"owner": "Gerg-L", "owner": "Gerg-L",
"repo": "mnw", "repo": "mnw",
"rev": "cfbc7d1cc832e318d0863a5fc91d940a96034001", "rev": "2aaffa8030d0b262176146adbb6b0e6374ce2957",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -415,20 +486,46 @@
"type": "github" "type": "github"
} }
}, },
"ndg": { "naersk": {
"inputs": { "inputs": {
"nixpkgs": "nixpkgs_2" "fenix": "fenix_2",
"nixpkgs": [
"anki-cli",
"nixpkgs"
]
}, },
"locked": { "locked": {
"lastModified": 1765720983, "lastModified": 1776193198,
"narHash": "sha256-tWtukpABmux6EC/FuCJEgA1kmRjcRPtED44N+GGPq+4=", "narHash": "sha256-U4w4GpgYt72z8pBKMDaqzlnPJRxI9pn+8tr7SOAxocE=",
"owner": "nix-community",
"repo": "naersk",
"rev": "e4e2ee6c9af67ecd4abb102fc32b9e49c70d92ff",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "naersk",
"type": "github"
}
},
"ndg": {
"inputs": {
"nixpkgs": [
"nvf",
"nixpkgs"
]
},
"locked": {
"lastModified": 1768214250,
"narHash": "sha256-hnBZDQWUxJV3KbtvyGW5BKLO/fAwydrxm5WHCWMQTbw=",
"owner": "feel-co", "owner": "feel-co",
"repo": "ndg", "repo": "ndg",
"rev": "f399ace8bb8e1f705dd8942b24d207aa4d75c936", "rev": "a6bd3c1ce2668d096e4fdaaa03ad7f03ba1fbca8",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "feel-co", "owner": "feel-co",
"ref": "refs/tags/v2.6.0",
"repo": "ndg", "repo": "ndg",
"type": "github" "type": "github"
} }
@@ -436,11 +533,11 @@
"nix-zulip": { "nix-zulip": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1764583012, "lastModified": 1772926346,
"narHash": "sha256-6ht4dtI1TBDAaB/Tatq+FcPexaZTBWuRiJGnioCDx5c=", "narHash": "sha256-fk8lfYmpXtBLzpJb9f97fYzKXcNflA5CYdYEJD1SDoY=",
"ref": "refs/heads/main", "ref": "refs/heads/main",
"rev": "a9dd0f80d775745f1d88055f24d944562db97c5e", "rev": "995e67ff510f413bd0d21af2137159c283223985",
"revCount": 67, "revCount": 80,
"type": "git", "type": "git",
"url": "https://git.afnix.fr/nix-zulip/nix-zulip" "url": "https://git.afnix.fr/nix-zulip/nix-zulip"
}, },
@@ -459,11 +556,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1766321686, "lastModified": 1774001769,
"narHash": "sha256-icOWbnD977HXhveirqA10zoqvErczVs3NKx8Bj+ikHY=", "narHash": "sha256-6y8yLrMecnFq21wFlUSxHF7OsabVCCj2p104HEUosvI=",
"owner": "simple-nixos-mailserver", "owner": "simple-nixos-mailserver",
"repo": "nixos-mailserver", "repo": "nixos-mailserver",
"rev": "7d433bf89882f61621f95082e90a4ab91eb0bdd3", "rev": "05968d7978faaa501836d6d2eb7f6cffb4140829",
"type": "gitlab" "type": "gitlab"
}, },
"original": { "original": {
@@ -474,11 +571,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1766651565, "lastModified": 1768564909,
"narHash": "sha256-QEhk0eXgyIqTpJ/ehZKg9IKS7EtlWxF3N7DXy42zPfU=", "narHash": "sha256-Kell/SpJYVkHWMvnhqJz/8DqQg2b6PguxVWOuadbHCc=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "3e2499d5539c16d0d173ba53552a4ff8547f4539", "rev": "e4bae1bd10c9c57b2cf517953ab70060a828ee6f",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -490,40 +587,20 @@
}, },
"nixpkgs_2": { "nixpkgs_2": {
"locked": { "locked": {
"lastModified": 1764242076, "lastModified": 1773821835,
"narHash": "sha256-sKoIWfnijJ0+9e4wRvIgm/HgE27bzwQxcEmo2J/gNpI=", "narHash": "sha256-TJ3lSQtW0E2JrznGVm8hOQGVpXjJyXY2guAxku2O9A4=",
"owner": "NixOS", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "2fad6eac6077f03fe109c4d4eb171cf96791faa4", "rev": "b40629efe5d6ec48dd1efba650c797ddbd39ace0",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "NixOS", "owner": "nixos",
"ref": "nixos-unstable", "ref": "nixos-unstable",
"repo": "nixpkgs", "repo": "nixpkgs",
"type": "github" "type": "github"
} }
}, },
"noshell": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1717396029,
"narHash": "sha256-NPIhvnTYkJZqTY+aabbZ6CAaMAgG6IISvh7GZo1MTfQ=",
"owner": "viperML",
"repo": "noshell",
"rev": "4d194d838a50ea106cd0e47c024e47afc154ab42",
"type": "github"
},
"original": {
"owner": "viperML",
"repo": "noshell",
"type": "github"
}
},
"nur": { "nur": {
"inputs": { "inputs": {
"flake-parts": "flake-parts", "flake-parts": "flake-parts",
@@ -532,11 +609,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1767026366, "lastModified": 1774121134,
"narHash": "sha256-TqJXPpEPYfeFCbraquNdrB1dJYuEqV474Npv8UcNxrs=", "narHash": "sha256-2rY/WUuZEtQ7St3AcFw6dri4oYyBJvr/dnZdpOPe1oM=",
"owner": "nix-community", "owner": "nix-community",
"repo": "NUR", "repo": "NUR",
"rev": "1f8c02a96c58c0dd90f2de45440b9ef01571abc3", "rev": "4fe0420f495cdcd730969de67f75f44d2a5bb71f",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -557,11 +634,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1764773531, "lastModified": 1767810917,
"narHash": "sha256-mCBl7MD1WZ7yCG6bR9MmpPO2VydpNkWFgnslJRIT1YU=", "narHash": "sha256-ZKqhk772+v/bujjhla9VABwcvz+hB2IaRyeLT6CFnT0=",
"owner": "nix-community", "owner": "nix-community",
"repo": "NUR", "repo": "NUR",
"rev": "1d9616689e98beded059ad0384b9951e967a17fa", "rev": "dead29c804adc928d3a69dfe7f9f12d0eec1f1a4",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -582,11 +659,11 @@
"systems": "systems_2" "systems": "systems_2"
}, },
"locked": { "locked": {
"lastModified": 1766596669, "lastModified": 1774109759,
"narHash": "sha256-9C72hpMDa99n4MbqZqsBkrBQZe+HEN9lnu7Sme67nmU=", "narHash": "sha256-Ksvw+R+kwCr+liA4h+TtQaYSW/0Jl+NDMThU5TBsJIY=",
"owner": "notashelf", "owner": "notashelf",
"repo": "nvf", "repo": "nvf",
"rev": "ef1f22efaf4aa37ba9382a7d1807fa8ac9c097fd", "rev": "4f1074084eb86e8d8a32e19e78f3cf2adba0213e",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -602,11 +679,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1766543224, "lastModified": 1774120611,
"narHash": "sha256-96PBoNqh3sPU9t+IXxcB1OjjuQ8HOv42OOh9UtwFHbU=", "narHash": "sha256-QZ09cfZnPiF62BgNqVTxEbFtnBjYaBVuhZNdos9ggnE=",
"owner": "celenityy", "owner": "celenityy",
"repo": "Phoenix", "repo": "Phoenix",
"rev": "f09568c8a71af4fe42dd43c6f711c67daf605f1e", "rev": "df5a6d30c792c0b17017510b35db93e94fb9e6a1",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -618,19 +695,52 @@
"root": { "root": {
"inputs": { "inputs": {
"agenix": "agenix", "agenix": "agenix",
"disko": "disko", "anki-cli": "anki-cli",
"home-manager": "home-manager_2", "home-manager": "home-manager_2",
"impermanence": "impermanence", "impermanence": "impermanence",
"nix-zulip": "nix-zulip", "nix-zulip": "nix-zulip",
"nixos-mailserver": "nixos-mailserver", "nixos-mailserver": "nixos-mailserver",
"nixpkgs": "nixpkgs", "nixpkgs": "nixpkgs_2",
"noshell": "noshell",
"nur": "nur", "nur": "nur",
"nvf": "nvf", "nvf": "nvf",
"phoenix": "phoenix", "phoenix": "phoenix",
"stylix": "stylix" "stylix": "stylix"
} }
}, },
"rust-analyzer-src": {
"flake": false,
"locked": {
"lastModified": 1776115521,
"narHash": "sha256-N/R1//Xd8vr84LtyTy8CVz7V2n9NJXXlJEODSunLE9c=",
"owner": "rust-lang",
"repo": "rust-analyzer",
"rev": "5205b52ea60dd49c7e33dd2ad1a3e7ef55bb30ec",
"type": "github"
},
"original": {
"owner": "rust-lang",
"ref": "nightly",
"repo": "rust-analyzer",
"type": "github"
}
},
"rust-analyzer-src_2": {
"flake": false,
"locked": {
"lastModified": 1752428706,
"narHash": "sha256-EJcdxw3aXfP8Ex1Nm3s0awyH9egQvB2Gu+QEnJn2Sfg=",
"owner": "rust-lang",
"repo": "rust-analyzer",
"rev": "591e3b7624be97e4443ea7b5542c191311aa141d",
"type": "github"
},
"original": {
"owner": "rust-lang",
"ref": "nightly",
"repo": "rust-analyzer",
"type": "github"
}
},
"stylix": { "stylix": {
"inputs": { "inputs": {
"base16": "base16", "base16": "base16",
@@ -652,11 +762,11 @@
"tinted-zed": "tinted-zed" "tinted-zed": "tinted-zed"
}, },
"locked": { "locked": {
"lastModified": 1766603026, "lastModified": 1773792048,
"narHash": "sha256-J2DDdRqSU4w9NNgkMfmMeaLIof5PXtS9RG7y6ckDvQE=", "narHash": "sha256-Oy9PCLG3vtflFBWcJd8c/EB3h5RU7ABAIDWn6JrGf6o=",
"owner": "nix-community", "owner": "nix-community",
"repo": "stylix", "repo": "stylix",
"rev": "551df12ee3ebac52c5712058bd97fd9faa4c3430", "rev": "3f2f9d307fe58c6abe2a16eb9b62c42d53ef5ee1",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -746,11 +856,11 @@
"tinted-schemes": { "tinted-schemes": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1763914658, "lastModified": 1767710407,
"narHash": "sha256-Hju0WtMf3iForxtOwXqGp3Ynipo0EYx1AqMKLPp9BJw=", "narHash": "sha256-+W1EB79Jl0/gm4JqmO0Nuc5C7hRdp4vfsV/VdzI+des=",
"owner": "tinted-theming", "owner": "tinted-theming",
"repo": "schemes", "repo": "schemes",
"rev": "0f6be815d258e435c9b137befe5ef4ff24bea32c", "rev": "2800e2b8ac90f678d7e4acebe4fa253f602e05b2",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -762,11 +872,11 @@
"tinted-tmux": { "tinted-tmux": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1764465359, "lastModified": 1767489635,
"narHash": "sha256-lbSVPqLEk2SqMrnpvWuKYGCaAlfWFMA6MVmcOFJjdjE=", "narHash": "sha256-e6nnFnWXKBCJjCv4QG4bbcouJ6y3yeT70V9MofL32lU=",
"owner": "tinted-theming", "owner": "tinted-theming",
"repo": "tinted-tmux", "repo": "tinted-tmux",
"rev": "edf89a780e239263cc691a987721f786ddc4f6aa", "rev": "3c32729ccae99be44fe8a125d20be06f8d7d8184",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -778,11 +888,11 @@
"tinted-zed": { "tinted-zed": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1764464512, "lastModified": 1767488740,
"narHash": "sha256-rCD/pAhkMdCx6blsFwxIyvBJbPZZ1oL2sVFrH07lmqg=", "narHash": "sha256-wVOj0qyil8m+ouSsVZcNjl5ZR+1GdOOAooAatQXHbuU=",
"owner": "tinted-theming", "owner": "tinted-theming",
"repo": "base16-zed", "repo": "base16-zed",
"rev": "907dbba5fb8cf69ebfd90b00813418a412d0a29a", "rev": "11abb0b282ad3786a2aae088d3a01c60916f2e40",
"type": "github" "type": "github"
}, },
"original": { "original": {

View File

@@ -4,8 +4,8 @@
url = "github:ryantm/agenix"; url = "github:ryantm/agenix";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
disko = { anki-cli = {
url = "github:nix-community/disko/latest"; url = "git+https://git.mtgmonkey.net/Andromeda/anki-cli.git";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
home-manager = { home-manager = {
@@ -22,10 +22,6 @@
url = "git+https://git.afnix.fr/nix-zulip/nix-zulip"; url = "git+https://git.afnix.fr/nix-zulip/nix-zulip";
flake = false; flake = false;
}; };
noshell = {
url = "github:viperML/noshell";
inputs.nixpkgs.follows = "nixpkgs";
};
nur = { nur = {
url = "github:nix-community/NUR"; url = "github:nix-community/NUR";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
@@ -45,13 +41,12 @@
}; };
outputs = { outputs = {
agenix, agenix,
disko, anki-cli,
home-manager, home-manager,
impermanence, impermanence,
nixos-mailserver, nixos-mailserver,
nixpkgs, nixpkgs,
nix-zulip, nix-zulip,
noshell,
nur, nur,
nvf, nvf,
phoenix, phoenix,
@@ -71,19 +66,20 @@
./secrets.nix ./secrets.nix
./modules/nixos/common.nix ./modules/nixos/common.nix
agenix.nixosModules.default agenix.nixosModules.default
disko.nixosModules.disko
impermanence.nixosModules.impermanence impermanence.nixosModules.impermanence
nixos-mailserver.nixosModule nixos-mailserver.nixosModule
noshell.nixosModules.default
phoenix.nixosModules.default
nix-zulip'.nixosModules.zulip nix-zulip'.nixosModules.zulip
{ phoenix.nixosModules.default
({pkgs, ...}: {
nixpkgs.overlays = [ nixpkgs.overlays = [
agenix.overlays.default agenix.overlays.default
nur.overlays.default nur.overlays.default
nix-zulip'.overlays.default nix-zulip'.overlays.default
(self: super: {
anki-cli = anki-cli.packages.${machine.system}.default;
})
]; ];
} })
] ]
++ machine.modules; ++ machine.modules;
}; };
@@ -93,6 +89,7 @@
{ {
home-manager.useGlobalPkgs = true; home-manager.useGlobalPkgs = true;
home-manager.extraSpecialArgs = {inherit machine;}; home-manager.extraSpecialArgs = {inherit machine;};
home-manager.backupFileExtension = "bak";
home-manager.users = home-manager.users =
builtins.mapAttrs builtins.mapAttrs
(name: value: value) (name: value: value)

View File

@@ -0,0 +1,24 @@
# Do not modify this file! It was generated by nixos-generate-config
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/profiles/qemu-guest.nix")
];
boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true;
# networking.interfaces.ens18.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}

View File

@@ -11,6 +11,7 @@
# hardware configuration # hardware configuration
# includes `system.stateVersion` # includes `system.stateVersion`
./modules/nixos/machines/lenovo.nix ./modules/nixos/machines/lenovo.nix
./modules/nixos/zram.nix
# boot process # boot process
# systemd-boot # systemd-boot
@@ -19,6 +20,9 @@
# networking # networking
./modules/nixos/laptop.nix ./modules/nixos/laptop.nix
# vpn
# ./modules/nixos/openvpn-client.nix
# ly display manager # ly display manager
./modules/nixos/ly.nix ./modules/nixos/ly.nix
@@ -26,7 +30,18 @@
./modules/nixos/sway.nix ./modules/nixos/sway.nix
# apps # apps
# UNFREE
./modules/nixos/steam.nix ./modules/nixos/steam.nix
# substitutors
./substitutors.nix
{
services.guix = {
enable = true;
stateDir = "/gnu/var";
};
}
]; ];
}; };
"109-199-104-83" = { "109-199-104-83" = {
@@ -34,46 +49,33 @@
system = "x86_64-linux"; system = "x86_64-linux";
users = []; users = [];
modules = [ modules = [
# impermanence
./modules/nixos/impermanence.nix
# hardware configuration # hardware configuration
# verbatim as `nixos-generate-config` AND `system.stateVersion` # from gitlab:whitequark/nixos-bite
./modules/nixos/machines/109-199-104-83.nix ./modules/nixos/machines/109-199-104-83.nix
./modules/nixos/disko/remote.nix
# boot process
# grub boot on /dev/sda
./modules/nixos/boot/109-199-104-83.nix
# networking # networking
./modules/nixos/networking/domains/galaxious.de.nix ./modules/nixos/networking/domains/galaxious.de.nix
# uses cloud-init to network
./modules/nixos/networking/networks/109-199-104-83.nix
# ssh through port 5522 among other things # ssh through port 5522 among other things
# andromeda@lenovo is the only user allowed access # andromeda@lenovo is the only user allowed access
# ./modules/nixos/networking/hard-ssh.nix ./modules/nixos/networking/hard-ssh.nix
#./modules/nixos/networking/ssh-as-root.nix ({config, ...}: {users.users.root.openssh.authorizedKeys.keys = [config.pub-keys.ssh.andromeda];})
({config, ...}: {
services.openssh.enable = true;
users.users.root.openssh.authorizedKeys.keys = [config.pub-keys.ssh.andromeda];
})
# TODO add Impermanence to the following services
# simple-nixos-mailserver email server # simple-nixos-mailserver email server
# mail.domain # mail.domain
# ./modules/nixos/mailserver.nix ./modules/nixos/mailserver.nix
# roundcube webmail client # roundcube webmail client
# webmail.domain # webmail.domain
# ./modules/nixos/roundcube.nix ./modules/nixos/roundcube.nix
# BROKEN
# forgejo
# git.domain
# ./modules/nixos/forgejo.nix
# zulip chat client # zulip chat client
# chat.domain # chat.domain
# zulip chat server
# zulip.domain
# ./modules/nixos/zulip.nix # ./modules/nixos/zulip.nix
]; ];
}; };

View File

@@ -1,6 +0,0 @@
{
boot.loader.grub = {
efiSupport = true;
efiInstallAsRemovable = true;
};
}

View File

@@ -10,8 +10,8 @@
]; ];
# allows users to customize shell in `$XDG_CONFIG_HOME/shell` rather than # allows users to customize shell in `$XDG_CONFIG_HOME/shell` rather than
# needing /etc/shells. Useful for home-manager. Falls back. # needing /etc/shells. Useful for home-manager.
programs.noshell.enable = true; # programs.noshell.enable = true;
# cleans /tmp to maintain a tidy system # cleans /tmp to maintain a tidy system
boot.tmp.cleanOnBoot = true; boot.tmp.cleanOnBoot = true;

View File

@@ -1,64 +0,0 @@
{
disko.devices = {
disk = {
disk1 = {
device = "/dev/sda";
type = "disk";
content = {
type = "gpt";
partitions = {
# legacy boot
boot = {
name = "boot";
size = "1M";
type = "EF02";
};
# efi boot
esp = {
name = "ESP";
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
# btrfs
# root is on nodev
root = {
size = "100%";
content = {
extraArgs = ["-f"]; # internet told me to, works
type = "btrfs";
subvolumes = {
# nix store
"/nix" = {
mountpoint = "/nix";
};
# persistant directory
"/persist" = {
mountpoint = "/persist";
};
};
};
};
};
};
};
};
nodev = {
# root
"/" = {
fsType = "tmpfs";
mountOptions = [
"defaults"
"mode=755" # stops security complaints
];
};
};
};
}

27
modules/nixos/forgejo.nix Normal file
View File

@@ -0,0 +1,27 @@
{config, ...}: {
services.nginx = {
virtualHosts.${config.services.forgejo.settings.server.DOMAIN} = {
forceSSL = true;
enableACME = true;
extraConfig = ''
client_max_body_size 512M
'';
locations."/".proxyPass = "https://localhost:${builtins.toString config.services.forgejo.settings.server.HTTP_PORT}";
};
};
services.forgejo = {
enable = true;
database.type = "postgres";
lfs.enable = true;
settings = {
server = rec {
DOMAIN = "git.galaxious.de";
ROOT_URL = "https://${DOMAIN}";
HTTP_PORT = 4043;
SSH_PORT = 4022;
};
service.DISABLE_REGISTRATION = false;
};
};
services.openssh.ports = [config.services.forgejo.settings.server.SSH_PORT];
}

View File

@@ -7,6 +7,7 @@
"/var/log" "/var/log"
"/var/lib/nixos" "/var/lib/nixos"
"/var/lib/systemd/coredump" "/var/lib/systemd/coredump"
"/gnu"
]; ];
files = [ files = [
"/etc/machine-id" "/etc/machine-id"

View File

@@ -7,7 +7,7 @@
services.blueman.enable = true; services.blueman.enable = true;
# locale # locale
i18n.defaultLocale = "de_DE.UTF-8"; i18n.defaultLocale = "en_US.UTF-8";
time.timeZone = "Europe/Berlin"; time.timeZone = "Europe/Berlin";
# networking # networking

View File

@@ -1,25 +1,38 @@
# Do not modify this file! It was generated by nixos-generate-config {modulesPath, ...}: {
# and may be overwritten by future invocations. Please make changes system.stateVersion = "25.11";
# to /etc/nixos/configuration.nix instead.
# Hardware
imports = [(modulesPath + "/profiles/qemu-guest.nix")];
fileSystems."/" = {
device = "/dev/sda1";
fsType = "ext4";
};
boot.loader.grub.device = "/dev/sda";
boot.loader.timeout = 30;
boot.initrd.availableKernelModules = ["ata_piix" "uhci_hcd" "xen_blkfront"];
boot.initrd.kernelModules = ["nvme"];
boot.tmp.cleanOnBoot = true;
zramSwap.enable = true;
# Networking
networking = {
useNetworkd = true;
usePredictableInterfaceNames = true;
};
systemd.network = {
enable = true;
networks."40-wan" = {
matchConfig.Name = "enx0050565f4fff";
address = ["2a02:c207:2299:8419::1/64" "109.199.104.83/20"];
routes = [
{ {
config, Gateway = "109.199.96.1";
lib, GatewayOnLink = true;
pkgs, }
modulesPath, {Gateway = "fe80::1";}
... ];
}: { dns = ["2020:fe::10" "9.9.9.10"];
imports = [ };
(modulesPath + "/profiles/qemu-guest.nix") };
];
boot.initrd.availableKernelModules = ["ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod"];
boot.initrd.kernelModules = [];
boot.kernelModules = [];
boot.extraModulePackages = [];
swapDevices = [];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
system.stateVersion = "26.05";
} }

View File

@@ -2,10 +2,14 @@
mailserver = { mailserver = {
enable = true; enable = true;
stateVersion = 3; stateVersion = 3;
# domain bs
fqdn = "mail.${config.networking.domain}"; fqdn = "mail.${config.networking.domain}";
domains = ["${config.networking.domain}"]; domains = ["${config.networking.domain}"];
x509.useACMEHost = config.mailserver.fqdn; x509.useACMEHost = config.mailserver.fqdn;
loginAccounts = { loginAccounts = {
# test acc
"test@${config.networking.domain}" = { "test@${config.networking.domain}" = {
hashedPasswordFile = builtins.toString config.age.secrets.mailserver-acc-test-pw.path; hashedPasswordFile = builtins.toString config.age.secrets.mailserver-acc-test-pw.path;
}; };
@@ -15,6 +19,17 @@
}; };
}; };
}; };
# put dkim key into /etc for declarability
mailserver.dkimKeyDirectory = "/etc/dkim";
environment.etc."dkim/${config.networking.domain}.${config.mailserver.dkimSelector}.key" = {
source = config.age.secrets."dkim-${config.networking.domain}.${config.mailserver.dkimSelector}.key".path;
mode = "600";
user = config.services.rspamd.user;
group = config.services.rspamd.group;
};
# does acme for me
services.nginx = { services.nginx = {
enable = true; enable = true;
virtualHosts = { virtualHosts = {
@@ -22,6 +37,10 @@
forceSSL = true; forceSSL = true;
enableACME = true; enableACME = true;
}; };
"${config.networking.domain}" = {
forceSSL = true;
enableACME = true;
};
}; };
}; };
security.acme = { security.acme = {

View File

@@ -4,7 +4,6 @@
allowSFTP = false; allowSFTP = false;
ports = [5522]; ports = [5522];
settings = { settings = {
PermitRootLogin = "no";
PasswordAuthentication = false; PasswordAuthentication = false;
KbdInteractiveAuthentication = true; KbdInteractiveAuthentication = true;
}; };

View File

@@ -1,15 +0,0 @@
{
networking = {
useDHCP = false;
hostName = "109-199-104-83";
firewall = {
enable = true;
allowedTCPPorts = [80 443];
allowedUDPPorts = [80 443];
};
};
services.cloud-init = {
enable = true;
network.enable = true;
};
}

8
modules/nixos/zram.nix Normal file
View File

@@ -0,0 +1,8 @@
{
zramSwap = {
enable = true;
priority = 100;
algorithm = "zstd";
memoryPercent = 75;
};
}

View File

@@ -8,25 +8,47 @@
# host domain # host domain
host = "chat.${config.networking.domain}"; host = "chat.${config.networking.domain}";
# secrets # secrets; head rolled on keyboard for all :)
camoKeyFile = builtins.toString config.age.secrets.zulip-camoKey.path; camoKeyFile = builtins.toString config.age.secrets.zulip-camoKey.path;
rabbitmqPasswordFile = builtins.toString config.age.secrets.zulip-rabbitmqPassword.path; rabbitmqPasswordFile = builtins.toString config.age.secrets.zulip-rabbitmqPassword.path;
secretKeyFile = builtins.toString config.age.secrets.zulip-secretKey.path; secretKeyFile = builtins.toString config.age.secrets.zulip-secretKey.path;
sharedSecretKeyFile = builtins.toString config.age.secrets.zulip-sharedSecretKey.path; sharedSecretKeyFile = builtins.toString config.age.secrets.zulip-sharedSecretKey.path;
avatarSaltKeyFile = builtins.toString config.age.secrets.zulip-avatarSaltKey.path; avatarSaltKeyFile = builtins.toString config.age.secrets.zulip-avatarSaltKey.path;
extraSecrets = {
email_password = builtins.toString config.age.secrets.zulip-extraSecrets-email_password.path; # TODO check for parity with `mailserver-acc-admin-pw.age`
}; extraSecrets.email_password = builtins.toString config.age.secrets.zulip-extraSecrets-email_password.path;
# settings # settings
zulipSettings = rec { zulipSettings = rec {
EMAIL_USE_TLS = true; # email users
EMAIL_PORT = 587; ZULIP_ADMINISTRATOR = "admin@${config.networking.domain}";
EMAIL_HOST_USER = ZULIP_ADMINISTRATOR;
# configure mailserver port
EMAIL_HOST = config.mailserver.fqdn;
EMAIL_USE_SSL = true;
EMAIL_PORT = 465;
# setting to allow realm creation; probably unsafe, might delete later :3
OPEN_REALM_CREATION = true;
# send all noreply emails from `admin@galaxious.de`
# TODO configure admin to send from any address
ADD_TOKENS_TO_NOREPLY_ADDRESS = false; ADD_TOKENS_TO_NOREPLY_ADDRESS = false;
NOREPLY_EMAIL_ADDRESS = ZULIP_ADMINISTRATOR; NOREPLY_EMAIL_ADDRESS = ZULIP_ADMINISTRATOR;
OPEN_REALM_CREATION = true;
# domain name
EXTERNAL_HOST = config.services.zulip.host; EXTERNAL_HOST = config.services.zulip.host;
ZULIP_ADMINISTRATOR = "admin@${config.networking.domain}";
}; };
}; };
# persist
environment.persistence."/persist".directories = [
# messages
"/var/lib/rabbitmq"
# uploads
"/var/lib/zulip"
# contrived, but in the store a couple layers down
# "/var/lib/redis-zulip"
];
} }

View File

@@ -1,10 +1,12 @@
{ {
age.secrets = { age.secrets = {
andromeda-pw.file = ./secrets/andromeda-pw.age; andromeda-pw.file = ./secrets/andromeda-pw.age;
conduit-secretFile.file = ./secrets/conduit-secretFile.age;
"dkim-galaxious.de.mail.key".file = ./secrets/dkim-galaxious.de.mail.key.age;
mtgmonkey-pw.file = ./secrets/mtgmonkey-pw.age; mtgmonkey-pw.file = ./secrets/mtgmonkey-pw.age;
mailserver-acc-test-pw.file = ./secrets/mailserver-acc-test-pw.age; mailserver-acc-test-pw.file = ./secrets/mailserver-acc-test-pw.age;
mailserver-acc-admin-pw.file = ./secrets/mailserver-acc-admin-pw.age; mailserver-acc-admin-pw.file = ./secrets/mailserver-acc-admin-pw.age;
"mailserver-acc-zulip+admin-pw".file = ./secrets + "/mailserver-acc-zulip+admin-pw.age"; "mailserver-acc-zulip+admin-pw".file = "${./secrets}/mailserver-acc-zulip+admin-pw.age";
zulip-avatarSaltKey.file = ./secrets/zulip-avatarSaltKey.age; zulip-avatarSaltKey.file = ./secrets/zulip-avatarSaltKey.age;
zulip-camoKey.file = ./secrets/zulip-camoKey.age; zulip-camoKey.file = ./secrets/zulip-camoKey.age;
zulip-extraSecrets-email_password.file = ./secrets/zulip-extraSecrets-email_password.age; zulip-extraSecrets-email_password.file = ./secrets/zulip-extraSecrets-email_password.age;
@@ -16,7 +18,7 @@
ssh = { ssh = {
andromeda = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJy2VD362wUcu0lKj2d6OIU8dbAna0Lu/NaAYIj8gdIA andromeda@lenovo"; andromeda = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJy2VD362wUcu0lKj2d6OIU8dbAna0Lu/NaAYIj8gdIA andromeda@lenovo";
lenovo = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHG4eqsLTq2os2mxfwhys3BpVnowcJrqt2CbRFzN2pJb root@lenovo"; lenovo = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHG4eqsLTq2os2mxfwhys3BpVnowcJrqt2CbRFzN2pJb root@lenovo";
_109-199-104-83 = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJe5ol56yC23fivSEKeK4HZQm934ROX46AM7o0aE2hMq root@vmi2998419"; _109-199-104-83 = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPkg4vbyGDxrAtKFK7Pecr/qDK9cUjv+kfhQMjO6M/Ft root@vmi2998419";
}; };
}; };
} }

View File

@@ -1,7 +1,7 @@
age-encryption.org/v1 age-encryption.org/v1
-> ssh-ed25519 mT2fyg 4fCTrNibFdjnVfsIbXi6plbd56K8ZDDqtgryXPk2SUA -> ssh-ed25519 mT2fyg geMV+A9hasvKDnYiQMQWpz2o9mkUhX/Qmc1m4uvKIBs
vKlbDi+HpyYlSsN39GRh6GRwdHRSjypCEqguOaHPFDM 3vYZmwZPDVwqYRe2GHmxPXXx4qSWa3eqcWuH+sKWEYw
-> ssh-ed25519 UHxfvA RqrDa4xJoAy1Gdzvq6Z5eTSNTDtHzUmzRoLC+j+HxiI -> ssh-ed25519 UHxfvA FzNzq3yYNeDZ5x/g3cRVEaRu0txR3RORSeNFssrVuyc
+5CohUFSDB9oiLU0T25FKrQrz07DCviVuzZsVcUltOc dRQGhtVRMC65sHqlmxSXjwpsxtCqhifkVNWvBrrB4b8
--- SQ5zQx9lL5UdNinOgP6yG5WWiBdhSwFqJVt6u3SNpLA --- bHi+Q07PCpmPzalAkbaN+/H1tXLyJNbpBs3VMpDnSnU
î6<EFBFBD>© ç¥ UÛð¦pî<70>‡„øÚúQÙ]ÜNû;K;1yœµ™ +y¾2µÊZ4å<34>'RÔ”ÅÍPX—òR;HŠ”ÞHÆÏw‡éF7dÎñÖO¥<>߀•ïs«.„ó<E2809E>J<EFBFBD>èärXqB¬ûPÉ¢™XÖ<58>ËÈE£»%¿¡Öè+(ä^=øÙöeugïêS;“2

View File

@@ -0,0 +1,10 @@
age-encryption.org/v1
-> ssh-ed25519 mT2fyg k+ePDybTbw1Pwy6P8+5HlGg6oCWQsTKVT4j/WUpZcCI
F2ySmW8tJ1BDBvLbqtrTMrnPkESAtwXBgzcQ7nVh8+A
-> ssh-ed25519 UHxfvA /RzKa63+zOkHudFPCS1hLxj4PjGZCtZ2UIIK0mdItBQ
TqdH3kQgMCEtG+rxx+dR+5/tcw05s63Dc1UFflRkoMA
-> ssh-ed25519 ZwF9sQ FvquxZ8PsmsoV06o4dBsKZOq46S08Rn1aT3Aco9TuDg
UnBKQCYXPa897ahVsj90XsVPuU4RKQ8RmMStY8BuubQ
--- MbfHHesbaIlXIg5jziBe4YG95I85ZuikuJLc9F/TEeQ
L("Ùß%DYÅ$°Ový¤:G5ÏzèWsœ¡šÏpï<>/ËúðV¹}ëû2xˆ«gRT‰Ã3|Pµ°/§n¼•òÆcIq(7Q-W[ä»ÐØL]ØE¥LS%y3w}¶Œµ°€°“Ütµ/£¿äO /<<3C>þm ÜfþCôn4”ºÑPyÚ'%+NY´àB@>œF<>ÐÒ è`,æ-¯0Ox)<1D>á
Ä)kT”ÍVòBxYì

Binary file not shown.

Binary file not shown.

View File

@@ -1,9 +1,9 @@
age-encryption.org/v1 age-encryption.org/v1
-> ssh-ed25519 mT2fyg slLOkD/9TAYOuZ/g5U4NvPWUlmYZeie12xzggioviw0 -> ssh-ed25519 mT2fyg gUoqW4Oc/4kGV97GqzjBgoAGbDlPr30HQjCSi95IakU
E0uAj4RMgv7DTJpvtEO54G9XHNLFOgFflR54Cl6/X8g WLqdKLGAY//HKMhiWeOEbRkVTUm+bNcGCRwvZ+jxFiQ
-> ssh-ed25519 UHxfvA xHFujOdegur0PLNHZP+h5RxHhVD2K906NZx7nprMkUs -> ssh-ed25519 UHxfvA w82yDFitNUAnKzT/0mPNIm4Od9YLwDK+JIHBd6qRsSQ
PdDxzD5QBdE/yWPMnF+CDGROEpE4nYvg12v1G3QK9XI uHYX5DugH0tLqLR1phnyYBNiP2XOV2Hj9tw63+MD1JI
-> ssh-ed25519 Xoin5w YWsO9HtEFB79+aKr6eWi5Sg5geKfzT+IrDy2L5qEmx4 -> ssh-ed25519 ZwF9sQ 6dTsOKixioy+ypnpWm1YtKYPrHcS/RSKsoq3o2bnjk8
sXLRmcRDyAv64nSGs8QXcHmKYO+F11Pzea1EVGmpEys WYED7jkCVNLBaputl0JcfEz8GOX4doUNEihj6ZHx8Eo
--- Sjg8SqkkEEL4X0G1GOUoHO702ZtrM0hMniIdS7yIsDA --- XOUmVi4QpCXDy4yVCZuwiv8Sg+LOsX9vfydM6OqGfTM
'ÏBâÉ(<28>7DÏ“=ù³h•áÊh fëÉ®×xT Ž!K.»‰‚~سò,…ß“<C39F>D|éä+pû<70>ü"ÒtÝG¢yñQ¬ÏRcPÁQüúQßÐ »?A³Ý'©p…@¶cUØ£Ì8º“1&9aXgÔyj°(óýz+$ P36£<36>ºîƒÊrçRDÊŒ7ªß¥.óÖ\:Ãþ­pcß<63>œÇp¯Ø€GÓ&+”Öb¢|žß<E28099> éÝ»YŽ

View File

@@ -1,10 +1,9 @@
age-encryption.org/v1 age-encryption.org/v1
-> ssh-ed25519 mT2fyg JsKjySZOoC/xK6HFjgBSYumrg/Ak7EBjYCqa9uszXGo -> ssh-ed25519 mT2fyg vcICwHDjTfVHh0+Ip1XKs/6Fo0H1i5lTjBAw1M4NSHA
daQvoxsqkxA4OClbWm4YHes5zkky8wikEKg94ceeNWw ZzxDjKEUdmyhFjPivAslXxr7tZnj7CVTcffuIhVdekI
-> ssh-ed25519 UHxfvA yDtvX6SqI9HFN3v1teeRfVicMXpS0fYLiyxe391kIHY -> ssh-ed25519 UHxfvA UPc1hBrbx37a4wn/XBxjwQLOk1M0HnHbHpqAQFUhnn8
xpYokiMmAlFbZHuOIqxKeGXtgiB9yOvRquI8OY5mdqE girao3TUDhFe1knuCUtYOh39ukXumjd7s1qzXXLGPjQ
-> ssh-ed25519 Xoin5w 9ND7dZoaaLXVu7VN3fYF6bZa23QpCr29b4DNIOSRi2Q -> ssh-ed25519 ZwF9sQ O2QJh1Zsdu0tIA90pTv5NrfcXDAcYFyduq8AtTG7Ujs
L6oOEQ8XSZZuQyfxPwgGYycMqAKfslEtFRJbBHbomoY ahnpyUSFuSwW1Zx7WzqDXFJtYCaUfwJdCyyr5enLz5I
--- ewcxsNTgXUy+wlZ3MiSC2KYO0BowGOAn/JvvV7x3pBc --- fYyjQduWvTrenIiJtljSkEZXuyTRWJOvx9LeWoI3ew0
ýVÖ5aƒÐ.°B'Kì¸7¹ì²LR9h`™<>€ƒÕ·<C395>éª …ußߘLÒ8ïÎ:ÂT·$…<10> ñJë´+LÄ?„zÇÍü5rL(MìýÁÑiÀý˜<C3BD>ˆN±.W+ß·U28Èd$µ<>¯<EFBFBD>Á£8Üõm¡4:N´<g)©Š‰Ä&Í$Jþ=Ævœ
8cˆ%)ÅÛ£Ö5³‡<C2B3>ä¾ä©ÕKLR¢˜yÞ199Y?©vÛ¼2<E28098> ÐKûfãºÔ<C2BA>!€©{3,

Binary file not shown.

View File

@@ -8,6 +8,14 @@ in {
"andromeda-pw.age".publicKeys = [andromeda lenovo]; "andromeda-pw.age".publicKeys = [andromeda lenovo];
"mtgmonkey-pw.age".publicKeys = [andromeda lenovo]; "mtgmonkey-pw.age".publicKeys = [andromeda lenovo];
# contains the following env
# CONDUIT_JWT_SECRET
# CONDUIT_TURN_SECRET
"conduit-secretFile.age".publicKeys = [andromeda lenovo _109-199-104-83];
# dkim private keys
"dkim-galaxious.de.mail.key.age".publicKeys = [andromeda lenovo _109-199-104-83];
# mail account passwords # mail account passwords
"mailserver-acc-test-pw.age".publicKeys = [andromeda lenovo _109-199-104-83]; "mailserver-acc-test-pw.age".publicKeys = [andromeda lenovo _109-199-104-83];
"mailserver-acc-admin-pw.age".publicKeys = [andromeda lenovo _109-199-104-83]; "mailserver-acc-admin-pw.age".publicKeys = [andromeda lenovo _109-199-104-83];

Binary file not shown.

Binary file not shown.

View File

@@ -1,9 +1,9 @@
age-encryption.org/v1 age-encryption.org/v1
-> ssh-ed25519 mT2fyg N+K4UqHYGQTzqq5wMhEs5ijh8a8uXarYy2BpWH2GAUY -> ssh-ed25519 mT2fyg uUrI8E1hJ4i9HvhuiIOkS1mq3ndb0+XGKt28QxykWFo
7mWlRNsudiBCr34QMXkzwkyRZa9K6pAPLX0phQBIH1A pfgscE+abzJJCebpnwbJqwX44hpEalpAXqaxpFFZxZA
-> ssh-ed25519 UHxfvA i5e8E+FMsG+n+jl5ASBYbPvnME7X58sMMAlYelZAm3A -> ssh-ed25519 UHxfvA PHnGkUxtgDq7Ga+ncROQm9SL3Nuc1TsbMY6ygi8GHQ4
ARlV+vWRRsFVAsjdk+JgUMgp49muyGFF5g+iyzpyJQY oqkbG58Ic498g/WXAEyyqF3KiP/+3gHWPhq6YjE678w
-> ssh-ed25519 Xoin5w 0EH6bLW0DwwVi8GMjq4ZjlBak1QQ0cxh/+KK/e1rPTY -> ssh-ed25519 ZwF9sQ FI2MOOEgVUKaNh5kVzcB47uWkbVpqFEXguw9K+qER38
yIpSegzmBeJ86jApt23Kv9vZ2sVLC8dFYa9t43/x8MM t0TkUx2KcGh0VWs9rpWTEcQtDcnzFvf9JPtzi+xaJWI
--- c4PhDnZ271mJc2sc7DSIRqVF503JSsZhBj2ANwcT2po --- kaUIyFhjX4STKsMWF895pyYy8x2Jec4nkPJaZfm1hb0
PKŽF ª†!"¤š<>“Mgoí/¶úÁgF®Š0@ì‡gA³ŸÎ„åP¶úæm+uéLoŠ äí…'ñ*—9.°‰|¿ ¢ÚÛQ°Ô؇gr”ê†@Û*Λۅ`O)Ëœp'Z2Õ³W!ŽÌ÷a!²Þ?VäIÓ(€õ±zæ˜

Binary file not shown.

Binary file not shown.

8
substitutors.nix Normal file
View File

@@ -0,0 +1,8 @@
{
# spectrum
nix.settings.substituters = ["https://cache.dataaturservice.se/spectrum/"];
nix.settings.trusted-public-keys = [
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"spectrum-os.org-2:foQk3r7t2VpRx92CaXb5ROyy/NBdRJQG2uX2XJMYZfU="
];
}

View File

@@ -3,9 +3,7 @@
lib, lib,
machine, machine,
... ...
}: let }: {
machines = import ./machines.nix;
in {
users.users = users.users =
builtins.mapAttrs builtins.mapAttrs
(name: value: lib.mkIf (builtins.elem name machine.users) value) (name: value: lib.mkIf (builtins.elem name machine.users) value)
@@ -15,8 +13,9 @@ in {
description = "andromeda"; description = "andromeda";
hashedPasswordFile = builtins.toString config.age.secrets.andromeda-pw.path; hashedPasswordFile = builtins.toString config.age.secrets.andromeda-pw.path;
extraGroups = [ extraGroups = [
"networkmanager" "networkmanager" # network configuration
"wheel" "wheel" # serial
"dialout" # access to serial ports
]; ];
}; };
}; };
@@ -27,17 +26,22 @@ in {
"andromeda" = { "andromeda" = {
directories = [ directories = [
".backups" ".backups"
".gnupg"
".local/share/AAAAXY"
".local/share/Anki2" ".local/share/Anki2"
".local/share/chat.fluffy.fluffychat" ".local/share/chat.fluffy.fluffychat"
".local/share/Mindustry"
".local/share/Steam"
".local/share/zoxide" ".local/share/zoxide"
".ssh" ".ssh"
".steam"
"conf" "conf"
"Downloads" "Downloads"
"conf_v1"
"pp" "pp"
]; ];
files = [ files = [
".bash_history" ".bash_history"
".brush_history"
]; ];
}; };
} }

View File

@@ -18,7 +18,6 @@
}; };
in { in {
imports = [./stylix.nix]; imports = [./stylix.nix];
xdg.configFile."shell".source = lib.getExe pkgs.brush;
xdg.configFile."sway/config".source = lib.mkForce sway_config; xdg.configFile."sway/config".source = lib.mkForce sway_config;
wayland.windowManager.sway.enable = true; wayland.windowManager.sway.enable = true;
home = { home = {
@@ -26,25 +25,35 @@ in {
homeDirectory = "/home/${config.home.username}"; homeDirectory = "/home/${config.home.username}";
stateVersion = "26.05"; stateVersion = "26.05";
packages = [ packages = [
pkgs.aaaaxy
pkgs.acpi pkgs.acpi
pkgs.agenix pkgs.agenix
pkgs.alacritty pkgs.alacritty
pkgs.anki pkgs.anki
pkgs.anki-cli
pkgs.brightnessctl pkgs.brightnessctl
pkgs.brush
pkgs.dust pkgs.dust
pkgs.fluffychat pkgs.fluffychat
pkgs.fzf pkgs.fzf
pkgs.gdb
pkgs.geeqie
pkgs.glow pkgs.glow
pkgs.grim pkgs.grim
pkgs.hexdump
pkgs.http-server
pkgs.jmtpfs pkgs.jmtpfs
pkgs.mindustry-wayland
pkgs.nasm
pkgs.nix-output-monitor pkgs.nix-output-monitor
pkgs.npins
pkgs.ranger pkgs.ranger
pkgs.rip2 pkgs.rip2
pkgs.ripgrep pkgs.ripgrep
pkgs.slurp pkgs.slurp
pkgs.tokei
pkgs.tree pkgs.tree
pkgs.zoxide pkgs.wget
pkgs.xxd
]; ];
file.${background-path}.source = config.stylix.image; file.${background-path}.source = config.stylix.image;
}; };
@@ -52,6 +61,7 @@ in {
alacritty.enable = true; alacritty.enable = true;
bash = { bash = {
enable = true; enable = true;
enableCompletion = false;
shellAliases = { shellAliases = {
neofetch = "fastfetch"; neofetch = "fastfetch";
ls = lib.mkForce "lsd"; ls = lib.mkForce "lsd";
@@ -63,7 +73,6 @@ in {
}; };
bashrcExtra = '' bashrcExtra = ''
PS1="\u@\h:\w$" PS1="\u@\h:\w$"
eval "$(zoxide init bash)"
''; '';
}; };
btop = { btop = {
@@ -91,6 +100,30 @@ in {
}; };
}; };
fastfetch.enable = true; fastfetch.enable = true;
firefox = {
enable = true;
package = pkgs.firefox.override {
cfg.enableTridactylNative = true;
};
profiles.${config.home.username} = {
extensions = {
force = true;
packages = [
pkgs.nur.repos.rycee.firefox-addons.tridactyl
];
};
search = {
default = "DuckDuckGo (HTML)";
privateDefault = "DuckDuckGo (HTML)";
order = [
"DuckDuckGo (HTML)"
];
};
settings = {
"extensions.autoDisableScopes" = 0;
};
};
};
git = { git = {
enable = true; enable = true;
settings = { settings = {
@@ -102,20 +135,15 @@ in {
}; };
}; };
gh.enable = true; gh.enable = true;
home-manager.enable = true; gpg = {
firefox = {
enable = true; enable = true;
package = pkgs.firefox.override {
cfg.enableTridactylNative = true;
};
profiles.${config.home.username}.extensions.packages = [
pkgs.nur.repos.rycee.firefox-addons.tridactyl
];
}; };
home-manager.enable = true;
lsd.enable = true; lsd.enable = true;
nvf = { nvf = {
enable = true; enable = true;
settings.vim = { settings.vim = {
startPlugins = [pkgs.vimPlugins.parinfer-rust];
autocomplete.nvim-cmp.enable = false; autocomplete.nvim-cmp.enable = false;
formatter.conform-nvim = { formatter.conform-nvim = {
enable = true; enable = true;
@@ -183,6 +211,12 @@ in {
enable = true; enable = true;
lsp.enable = true; lsp.enable = true;
}; };
rust = {
enable = true;
format.enable = true;
lsp.enable = true;
treesitter.enable = true;
};
}; };
lineNumberMode = "relative"; lineNumberMode = "relative";
options = { options = {
@@ -199,5 +233,13 @@ in {
}; };
}; };
ssh.enable = true; ssh.enable = true;
zoxide = {
enable = true;
enableBashIntegration = true;
};
};
services.gpg-agent = {
enable = true;
pinentry.package = pkgs.pinentry-curses;
}; };
} }

View File

@@ -55,6 +55,12 @@ bindsym $mod+Shift+8 move container to workspace number 8
bindsym $mod+Shift+9 move container to workspace number 9 bindsym $mod+Shift+9 move container to workspace number 9
bindsym $mod+Shift+0 move container to workspace number 0 bindsym $mod+Shift+0 move container to workspace number 0
seat * hide_cursor 100
input type:touchpad events disabled
bindsym $mod+r exec 'swaymsg "seat * hide_cursor 100"; swaymsg "input type:touchpad events disabled"'
bindsym $mod+t exec 'swaymsg "seat * hide_cursor 0"; swaymsg "input type:touchpad events enabled"'
bindsym $mod+f fullscreen bindsym $mod+f fullscreen
bindsym $mod+Shift+space floating toggle bindsym $mod+Shift+space floating toggle
bindsym $mod+Shift+minus move scratchpad bindsym $mod+Shift+minus move scratchpad
@@ -64,8 +70,8 @@ bindsym --locked XF86AudioMute exec pactl set-sink-mute \@DEFAULT_SINK@ toggle
bindsym --locked XF86AudioLowerVolume exec pactl set-sink-volume \@DEFAULT_SINK@ -5% bindsym --locked XF86AudioLowerVolume exec pactl set-sink-volume \@DEFAULT_SINK@ -5%
bindsym --locked XF86AudioRaiseVolume exec pactl set-sink-volume \@DEFAULT_SINK@ +5% bindsym --locked XF86AudioRaiseVolume exec pactl set-sink-volume \@DEFAULT_SINK@ +5%
bindsym --locked XF86AudioMicMute exec pact set-source-mute \@DEFAULT_SOURCE@ toggle bindsym --locked XF86AudioMicMute exec pact set-source-mute \@DEFAULT_SOURCE@ toggle
bindsym --locked XF86MonBrightnessDown exec brightnessctl set 5%- bindsym --locked XF86MonBrightnessDown exec brightnessctl set 2%-
bindsym --locked XF86MonbrightnessUp exec brightnessctl set 5%+ bindsym --locked XF86MonbrightnessUp exec brightnessctl set 2%+
default_border none default_border none
font pango:monospace 0.001 font pango:monospace 0.001