summaryrefslogtreecommitdiff
path: root/hostnix/weebnix/configuration.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/weebnix/configuration.nix')
-rw-r--r--hostnix/weebnix/configuration.nix93
1 files changed, 93 insertions, 0 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix
new file mode 100644
index 0000000..a0166f5
--- /dev/null
+++ b/hostnix/weebnix/configuration.nix
@@ -0,0 +1,93 @@
+{ config, pkgs, ... }:
+
+{
+ imports = [
+ ./dyndns.nix
+ ./hardware-configuration.nix
+ ./home-assistant.nix
+ ./oidc.nix
+ ./privacy-frontends.nix
+ ./syncthing.nix
+ ./system.nix
+ ];
+
+ nix.settings.experimental-features = [ "nix-command" "flakes" ];
+ nix.settings.trusted-users = [ "joe" ];
+
+ security.sudo.wheelNeedsPassword = false;
+
+ security.acme.acceptTerms = true;
+ security.acme.defaults.email = "hostmaster@mou.fo";
+ # TODO switch to production certs
+ security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";
+
+ users.users.joe = {
+ isNormalUser = true;
+ extraGroups = [ "wheel" "syncthing" ];
+ openssh.authorizedKeys.keys = [
+ "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky"
+ ];
+ };
+
+ environment.systemPackages = with pkgs; [
+ dig
+ file
+ gitFull
+ jq
+ libraspberrypi
+ sqlite-interactive
+ tmux
+ tree
+ ];
+
+ programs.vim.defaultEditor = true;
+ programs.nano.enable = false;
+
+ services.openssh.enable = true;
+
+ services.nginx = {
+ enable = true;
+ recommendedGzipSettings = true;
+ recommendedOptimisation = true;
+ recommendedProxySettings = true;
+ recommendedTlsSettings = true;
+ # Slightly crazy setup to SNI reverse proxy HTTPS to multiple upstreams.
+ # We displace ourselves onto port 8443, and send requests that are not
+ # intended for us to weeber. This is done because Apache running on weeber
+ # cannot SNI reverse proxy, so we put weebnix in front of weeber on IPv4.
+ # TODO get rid of all this when replacing weeber or maybe consider HAProxy
+ defaultSSLListenPort = 8443;
+ streamConfig = ''
+ map $ssl_preread_server_name $selected_upstream {
+ hostnames;
+ weebnix.mou.fo self;
+ *.weebnix.mou.fo self;
+ default weeber;
+ }
+ upstream self { server 127.0.0.1:8443; }
+ upstream weeber { server 192.168.0.168:443; }
+ server {
+ listen 0.0.0.0:443;
+ listen [::0]:443;
+ proxy_pass $selected_upstream;
+ ssl_preread on;
+ }
+ '';
+ };
+
+ # TODO remove upon switching to production certs
+ services.oauth2_proxy.extraConfig = {
+ "ssl-insecure-skip-verify" = true;
+ "ssl-upstream-insecure-skip-verify" = true;
+ };
+
+ networking.firewall.allowedTCPPorts = [ 80 443 ];
+
+ # This value determines the NixOS release from which the default
+ # settings for stateful data, like file locations and database versions
+ # on your system were taken. It's perfectly fine and recommended to leave
+ # this value at the release version of the first install of this system.
+ # Before changing this value read the documentation for this option
+ # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
+ system.stateVersion = "23.05"; # Did you read the comment?
+}