diff options
Diffstat (limited to 'hostnix/elmo/configuration.nix')
| -rw-r--r-- | hostnix/elmo/configuration.nix | 110 |
1 files changed, 110 insertions, 0 deletions
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix new file mode 100644 index 0000000..c53e4c3 --- /dev/null +++ b/hostnix/elmo/configuration.nix @@ -0,0 +1,110 @@ +{ config, lib, pkgs, ... }: + +{ + imports = [ + ./acme.nix + ./backup.nix + ./bjj-booker.nix + ./cal.nix + ./cgithub.nix + ./clippersnip.nix + ./dns.nix + ./dyndns.nix + ./email.nix + ./garage.nix + ./git.nix + ./hardware-configuration.nix + ./home-assistant.nix + ./media.nix + ./oidc.nix + ./pinchflat.nix + ./rss.nix + ./syncthing.nix + ./system.nix + ./typetype.nix + ./usenet.nix + ./web.nix + ./wireguard.nix + ./yakatak.nix + ]; + + nix.settings.experimental-features = [ "nix-command" "flakes" ]; + + security.sudo.wheelNeedsPassword = false; + + users.users.joe = { + isNormalUser = true; + description = "Joe Mou"; + extraGroups = [ "networkmanager" "wheel" ]; + packages = with pkgs; [ + jq + sqlite-interactive + ]; + openssh.authorizedKeys.keys = [ + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIvvJXGg1HVDU2z2osjq5FEAcwte8ZybuYj1wpTtwr1m joe@doughboy" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPsci2NPhPgg7T77vtcnkcv5Z9sbHAsmp9XC11WPePvL joe@Joes-Mac-mini.local" + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILU1pGPkl/6A2DXrEZd5elLCJ7OCnG9QCEvaopFW8gEg joe@penguin" + ]; + }; + + # TODO make into a module + nixpkgs.config.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) [ + "unrar" # from nzbget + ]; + + environment.systemPackages = with pkgs; [ + dig + file + gitFull + openssl + psmisc + python3 + restic + tmux + tree + unzip + ]; + + programs.vim = { + enable = true; + defaultEditor = true; + }; + programs.nano.enable = false; + + services.envfs.enable = true; + services.fstrim.enable = true; + services.openssh.enable = true; + + services.sshguard = { + enable = true; + whitelist = [ "192.168.0.0/24" ]; + }; + + services.locate.enable = true; + + services.postgresql = { + enable = true; + package = pkgs.postgresql_15; + }; + + systemd.services.duperemove = { + serviceConfig = { + Type = "simple"; + CacheDirectory = "duperemove"; + }; + script = '' + exec ${pkgs.duperemove}/bin/duperemove -dhrq --hashfile $CACHE_DIRECTORY/hashfile /srv /var + ''; + }; + + networking.firewall.allowedTCPPorts = [ 80 443 ]; + + # This value determines the NixOS release from which the default + # settings for stateful data, like file locations and database versions + # on your system were taken. It's perfectly fine and recommended to leave + # this value at the release version of the first install of this system. + # Before changing this value read the documentation for this option + # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). + system.stateVersion = "23.11"; # Did you read the comment? +} |
