summaryrefslogtreecommitdiff
path: root/hostnix/elmo/configuration.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/configuration.nix')
-rw-r--r--hostnix/elmo/configuration.nix110
1 files changed, 110 insertions, 0 deletions
diff --git a/hostnix/elmo/configuration.nix b/hostnix/elmo/configuration.nix
new file mode 100644
index 0000000..c53e4c3
--- /dev/null
+++ b/hostnix/elmo/configuration.nix
@@ -0,0 +1,110 @@
+{ config, lib, pkgs, ... }:
+
+{
+ imports = [
+ ./acme.nix
+ ./backup.nix
+ ./bjj-booker.nix
+ ./cal.nix
+ ./cgithub.nix
+ ./clippersnip.nix
+ ./dns.nix
+ ./dyndns.nix
+ ./email.nix
+ ./garage.nix
+ ./git.nix
+ ./hardware-configuration.nix
+ ./home-assistant.nix
+ ./media.nix
+ ./oidc.nix
+ ./pinchflat.nix
+ ./rss.nix
+ ./syncthing.nix
+ ./system.nix
+ ./typetype.nix
+ ./usenet.nix
+ ./web.nix
+ ./wireguard.nix
+ ./yakatak.nix
+ ];
+
+ nix.settings.experimental-features = [ "nix-command" "flakes" ];
+
+ security.sudo.wheelNeedsPassword = false;
+
+ users.users.joe = {
+ isNormalUser = true;
+ description = "Joe Mou";
+ extraGroups = [ "networkmanager" "wheel" ];
+ packages = with pkgs; [
+ jq
+ sqlite-interactive
+ ];
+ openssh.authorizedKeys.keys = [
+ "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIvvJXGg1HVDU2z2osjq5FEAcwte8ZybuYj1wpTtwr1m joe@doughboy"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPsci2NPhPgg7T77vtcnkcv5Z9sbHAsmp9XC11WPePvL joe@Joes-Mac-mini.local"
+ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILU1pGPkl/6A2DXrEZd5elLCJ7OCnG9QCEvaopFW8gEg joe@penguin"
+ ];
+ };
+
+ # TODO make into a module
+ nixpkgs.config.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) [
+ "unrar" # from nzbget
+ ];
+
+ environment.systemPackages = with pkgs; [
+ dig
+ file
+ gitFull
+ openssl
+ psmisc
+ python3
+ restic
+ tmux
+ tree
+ unzip
+ ];
+
+ programs.vim = {
+ enable = true;
+ defaultEditor = true;
+ };
+ programs.nano.enable = false;
+
+ services.envfs.enable = true;
+ services.fstrim.enable = true;
+ services.openssh.enable = true;
+
+ services.sshguard = {
+ enable = true;
+ whitelist = [ "192.168.0.0/24" ];
+ };
+
+ services.locate.enable = true;
+
+ services.postgresql = {
+ enable = true;
+ package = pkgs.postgresql_15;
+ };
+
+ systemd.services.duperemove = {
+ serviceConfig = {
+ Type = "simple";
+ CacheDirectory = "duperemove";
+ };
+ script = ''
+ exec ${pkgs.duperemove}/bin/duperemove -dhrq --hashfile $CACHE_DIRECTORY/hashfile /srv /var
+ '';
+ };
+
+ networking.firewall.allowedTCPPorts = [ 80 443 ];
+
+ # This value determines the NixOS release from which the default
+ # settings for stateful data, like file locations and database versions
+ # on your system were taken. It's perfectly fine and recommended to leave
+ # this value at the release version of the first install of this system.
+ # Before changing this value read the documentation for this option
+ # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
+ system.stateVersion = "23.11"; # Did you read the comment?
+}