11 Commits

Author SHA1 Message Date
andromeda
2114c6c347 rename secrets 2026-01-05 14:35:42 +01:00
andromeda
0fee255cbf add mailserver to devline 2026-01-02 22:22:06 +01:00
andromeda
3fc40529c8 remove user on server 2026-01-02 22:14:04 +01:00
andromeda
2ed0cade4d use mkpasswd -s rather than mkpasswd? 2026-01-02 21:06:04 +01:00
andromeda
1d17664e7a reset mail password 2026-01-02 20:48:50 +01:00
andromeda
c632cd20c6 roundcube? 2026-01-02 20:33:21 +01:00
andromeda
5366c48991 use nginx for acme 2026-01-02 20:21:46 +01:00
andromeda
6db05df6a7 add firewall xD 2026-01-02 18:37:27 +01:00
andromeda
52a906919d change cert email to a real email :'( 2026-01-02 18:24:00 +01:00
andromeda
e665bb0b14 attempt mailserver? 2026-01-02 18:05:01 +01:00
andromeda
33814b565d add tridactyl to ff 2026-01-02 01:10:56 +01:00
13 changed files with 191 additions and 43 deletions

124
flake.lock generated
View File

@@ -91,6 +91,22 @@
"type": "github" "type": "github"
} }
}, },
"blobs": {
"flake": false,
"locked": {
"lastModified": 1604995301,
"narHash": "sha256-wcLzgLec6SGJA8fx1OEN1yV/Py5b+U5iyYpksUY/yLw=",
"owner": "simple-nixos-mailserver",
"repo": "blobs",
"rev": "2cccdf1ca48316f2cfd1c9a0017e8de5a7156265",
"type": "gitlab"
},
"original": {
"owner": "simple-nixos-mailserver",
"repo": "blobs",
"type": "gitlab"
}
},
"darwin": { "darwin": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
@@ -130,6 +146,22 @@
} }
}, },
"flake-compat": { "flake-compat": {
"flake": false,
"locked": {
"lastModified": 1761588595,
"narHash": "sha256-XKUZz9zewJNUj46b4AJdiRZJAvSZ0Dqj2BNfXvFlJC4=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "f387cd2afec9419c8ee37694406ca490c3f34ee5",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_2": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1751685974, "lastModified": 1751685974,
@@ -224,6 +256,54 @@
"type": "github" "type": "github"
} }
}, },
"git-hooks": {
"inputs": {
"flake-compat": [
"nixos-mailserver",
"flake-compat"
],
"gitignore": "gitignore",
"nixpkgs": [
"nixos-mailserver",
"nixpkgs"
]
},
"locked": {
"lastModified": 1763988335,
"narHash": "sha256-QlcnByMc8KBjpU37rbq5iP7Cp97HvjRP0ucfdh+M4Qc=",
"owner": "cachix",
"repo": "git-hooks.nix",
"rev": "50b9238891e388c9fdc6a5c49e49c42533a1b5ce",
"type": "github"
},
"original": {
"owner": "cachix",
"repo": "git-hooks.nix",
"type": "github"
}
},
"gitignore": {
"inputs": {
"nixpkgs": [
"nixos-mailserver",
"git-hooks",
"nixpkgs"
]
},
"locked": {
"lastModified": 1709087332,
"narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=",
"owner": "hercules-ci",
"repo": "gitignore.nix",
"rev": "637db329424fd7e46cf4185293b9cc8c88c95394",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "gitignore.nix",
"type": "github"
}
},
"gnome-shell": { "gnome-shell": {
"flake": false, "flake": false,
"locked": { "locked": {
@@ -332,6 +412,29 @@
"type": "github" "type": "github"
} }
}, },
"nixos-mailserver": {
"inputs": {
"blobs": "blobs",
"flake-compat": "flake-compat",
"git-hooks": "git-hooks",
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1766321686,
"narHash": "sha256-icOWbnD977HXhveirqA10zoqvErczVs3NKx8Bj+ikHY=",
"owner": "simple-nixos-mailserver",
"repo": "nixos-mailserver",
"rev": "7d433bf89882f61621f95082e90a4ab91eb0bdd3",
"type": "gitlab"
},
"original": {
"owner": "simple-nixos-mailserver",
"repo": "nixos-mailserver",
"type": "gitlab"
}
},
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1766651565, "lastModified": 1766651565,
@@ -432,7 +535,7 @@
}, },
"nvf": { "nvf": {
"inputs": { "inputs": {
"flake-compat": "flake-compat", "flake-compat": "flake-compat_2",
"flake-parts": "flake-parts_2", "flake-parts": "flake-parts_2",
"mnw": "mnw", "mnw": "mnw",
"ndg": "ndg", "ndg": "ndg",
@@ -462,17 +565,17 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1767512451, "lastModified": 1766543224,
"narHash": "sha256-ig5p+D8ruePISv0bbU3XUhMg4mOtpvpxYXZBKwanh2g=", "narHash": "sha256-96PBoNqh3sPU9t+IXxcB1OjjuQ8HOv42OOh9UtwFHbU=",
"ref": "refs/heads/home-manager", "owner": "celenityy",
"rev": "5b227c1bd23728d57376fe9009c6e1c5569593e1", "repo": "Phoenix",
"revCount": 2515, "rev": "f09568c8a71af4fe42dd43c6f711c67daf605f1e",
"type": "git", "type": "github"
"url": "file:///home/andromeda/pp/forks/phoenix"
}, },
"original": { "original": {
"type": "git", "owner": "celenityy",
"url": "file:///home/andromeda/pp/forks/phoenix" "repo": "Phoenix",
"type": "github"
} }
}, },
"root": { "root": {
@@ -480,6 +583,7 @@
"agenix": "agenix", "agenix": "agenix",
"home-manager": "home-manager_2", "home-manager": "home-manager_2",
"impermanence": "impermanence", "impermanence": "impermanence",
"nixos-mailserver": "nixos-mailserver",
"nixpkgs": "nixpkgs", "nixpkgs": "nixpkgs",
"noshell": "noshell", "noshell": "noshell",
"nur": "nur", "nur": "nur",

View File

@@ -9,6 +9,10 @@
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
impermanence.url = "github:nix-community/impermanence"; impermanence.url = "github:nix-community/impermanence";
nixos-mailserver = {
url = "gitlab:simple-nixos-mailserver/nixos-mailserver";
inputs.nixpkgs.follows = "nixpkgs";
};
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable"; nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
noshell = { noshell = {
url = "github:viperML/noshell"; url = "github:viperML/noshell";
@@ -23,7 +27,7 @@
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
phoenix = { phoenix = {
url = "git+file:///home/andromeda/pp/forks/phoenix"; url = "github:celenityy/Phoenix";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
stylix = { stylix = {
@@ -35,6 +39,7 @@
agenix, agenix,
home-manager, home-manager,
impermanence, impermanence,
nixos-mailserver,
nixpkgs, nixpkgs,
noshell, noshell,
nur, nur,
@@ -56,6 +61,8 @@
./secrets.nix ./secrets.nix
impermanence.nixosModules.impermanence impermanence.nixosModules.impermanence
agenix.nixosModules.default agenix.nixosModules.default
nixos-mailserver.nixosModule
phoenix.nixosModules.default
]; ];
}; };
configurationWithHomeManager = machine: (configuration machine configurationWithHomeManager = machine: (configuration machine
@@ -65,7 +72,6 @@
nixpkgs.overlays = [ nixpkgs.overlays = [
agenix.overlays.default agenix.overlays.default
nur.overlays.default nur.overlays.default
phoenix.overlays.default
]; ];
home-manager.useGlobalPkgs = true; home-manager.useGlobalPkgs = true;
home-manager.extraSpecialArgs = {inherit machine;}; home-manager.extraSpecialArgs = {inherit machine;};
@@ -79,7 +85,6 @@
name: { name: {
imports = [ imports = [
agenix.homeManagerModules.default agenix.homeManagerModules.default
phoenix.homeModules.default
stylix.homeModules.stylix stylix.homeModules.stylix
nvf.homeManagerModules.default nvf.homeManagerModules.default
./users/${name}/home.nix ./users/${name}/home.nix

View File

@@ -10,8 +10,6 @@
"109-199-104-83" = { "109-199-104-83" = {
hostname = "109-199-104-83"; hostname = "109-199-104-83";
system = "x86_64-linux"; system = "x86_64-linux";
users = [ users = [];
"mtgmonkey"
];
}; };
} }

View File

@@ -4,6 +4,46 @@
machine, machine,
... ...
}: { }: {
# roundcube config
services.roundcube = {
enable = true;
hostName = "webmail.${config.networking.domain}";
extraConfig = ''
$config['imap_host'] = "ssl://${config.mailserver.fqdn}";
$config['smtp_host'] = "ssl://${config.mailserver.fqdn}";
$config['smtp_user'] = "%u";
$config['smtp_pass'] = "%p";
'';
};
# mailserver config
mailserver = {
enable = true;
stateVersion = 3;
fqdn = "mail.${config.networking.domain}";
domains = ["${config.networking.domain}"];
x509.useACMEHost = config.mailserver.fqdn;
loginAccounts = {
"test@${config.networking.domain}" = {
hashedPasswordFile = builtins.toString config.age.secrets.mailserver-acc-test-pw.path;
};
};
};
# cert config
security.acme = {
acceptTerms = true;
defaults.email = "mtgmonket@gmail.com";
};
services.nginx = {
enable = true;
virtualHosts."mail.${config.networking.domain}" = {
forceSSL = true;
enableACME = true;
};
};
# system config
system.stateVersion = "25.11"; system.stateVersion = "25.11";
nix.settings.experimental-features = ["flakes" "nix-command"]; nix.settings.experimental-features = ["flakes" "nix-command"];
imports = [(modulesPath + "/profiles/qemu-guest.nix")]; imports = [(modulesPath + "/profiles/qemu-guest.nix")];
@@ -22,6 +62,11 @@
usePredictableInterfaceNames = true; usePredictableInterfaceNames = true;
hostName = machine.hostname; hostName = machine.hostname;
domain = "galaxious.de"; domain = "galaxious.de";
firewall = {
enable = true;
allowedTCPPorts = [80 443];
allowedUDPPorts = [80 443];
};
}; };
systemd.network = { systemd.network = {
enable = true; enable = true;

View File

@@ -9,10 +9,6 @@
./impermanence.nix ./impermanence.nix
(modulesPath + "/installer/scan/not-detected.nix") (modulesPath + "/installer/scan/not-detected.nix")
]; ];
age.secrets = {
secret0.file = ../../secrets/secret0.age;
secret1.file = ../../secrets/secret1.age;
};
boot.loader = { boot.loader = {
efi.canTouchEfiVariables = true; efi.canTouchEfiVariables = true;
systemd-boot.enable = true; systemd-boot.enable = true;

View File

@@ -1,8 +1,8 @@
{ {
age.secrets = { age.secrets = {
secret0.file = ./secrets/secret0.age; andromeda-pw.file = ./secrets/andromeda-pw.age;
secret1.file = ./secrets/secret1.age; mtgmonkey-pw.file = ./secrets/mtgmonkey-pw.age;
secret2.file = ./secrets/secret2.age; mailserver-acc-test-pw.file = ./secrets/mailserver-acc-test-pw.age;
}; };
pub-keys = { pub-keys = {
ssh = { ssh = {

View File

@@ -0,0 +1,9 @@
age-encryption.org/v1
-> ssh-ed25519 mT2fyg slLOkD/9TAYOuZ/g5U4NvPWUlmYZeie12xzggioviw0
E0uAj4RMgv7DTJpvtEO54G9XHNLFOgFflR54Cl6/X8g
-> ssh-ed25519 UHxfvA xHFujOdegur0PLNHZP+h5RxHhVD2K906NZx7nprMkUs
PdDxzD5QBdE/yWPMnF+CDGROEpE4nYvg12v1G3QK9XI
-> ssh-ed25519 Xoin5w YWsO9HtEFB79+aKr6eWi5Sg5geKfzT+IrDy2L5qEmx4
sXLRmcRDyAv64nSGs8QXcHmKYO+F11Pzea1EVGmpEys
--- Sjg8SqkkEEL4X0G1GOUoHO702ZtrM0hMniIdS7yIsDA
'<27>B<EFBFBD><42>(<28><>7Dϓ=<3D><>h<EFBFBD><10><>h f<>ɮ<13>xT<78><54>!K.<2E><1D><><>,<2C>ߓ<>D|<7C><>+p<><70><EFBFBD>"<22>t<EFBFBD><74>G<EFBFBD>y<EFBFBD>Q<EFBFBD><51>RcP<63>Q<EFBFBD><51>Q<><51>

Binary file not shown.

View File

@@ -4,7 +4,7 @@ let
lenovo = pub-keys.ssh.lenovo; lenovo = pub-keys.ssh.lenovo;
_109-199-104-83 = pub-keys.ssh._109-199-104-83; _109-199-104-83 = pub-keys.ssh._109-199-104-83;
in { in {
"secret0.age".publicKeys = [andromeda lenovo]; "andromeda-pw.age".publicKeys = [andromeda lenovo];
"secret1.age".publicKeys = [andromeda lenovo]; "mtgmonkey-pw.age".publicKeys = [andromeda lenovo];
"secret2.age".publicKeys = [andromeda lenovo _109-199-104-83]; "mailserver-acc-test-pw.age".publicKeys = [andromeda lenovo _109-199-104-83];
} }

View File

@@ -13,7 +13,7 @@ in {
"andromeda" = { "andromeda" = {
isNormalUser = true; isNormalUser = true;
description = "andromeda"; description = "andromeda";
hashedPasswordFile = builtins.toString config.age.secrets.secret0.path; hashedPasswordFile = builtins.toString config.age.secrets.andromeda-pw.path;
extraGroups = [ extraGroups = [
"networkmanager" "networkmanager"
"wheel" "wheel"
@@ -22,7 +22,7 @@ in {
"mtgmonkey" = { "mtgmonkey" = {
isNormalUser = true; isNormalUser = true;
description = "mtgmonkey"; description = "mtgmonkey";
hashedPasswordFile = builtins.toString config.age.secrets.secret1.path; hashedPasswordFile = builtins.toString config.age.secrets.mtgmonkey-pw.path;
extraGroups = [ extraGroups = [
(lib.mkIf (lib.mkIf
(machine == machines.lenovo) (machine == machines.lenovo)

View File

@@ -181,22 +181,13 @@ in {
home-manager.enable = true; home-manager.enable = true;
firefox = { firefox = {
enable = true; enable = true;
profiles."andromeda".name = "andromeda"; package = pkgs.firefox.override {
package = pkgs.withPhoenix pkgs.firefox; cfg.enableTridactylNative = true;
}; };
firefox.phoenix = { profiles.${config.home.username}.extensions.packages = [
enable = true; pkgs.nur.repos.rycee.firefox-addons.tridactyl
profiles = ["andromeda"]; ];
}; };
# librewolf = {
# enable = true;
# package = pkgs.librewolf.override {
# cfg.enableTridactylNative = true;
# };
# profiles.${config.home.username}.extensions.packages = [
# pkgs.nur.repos.rycee.firefox-addons.tridactyl
# ];
# };
lsd.enable = true; lsd.enable = true;
nvf = { nvf = {
enable = true; enable = true;