diff options
Diffstat (limited to 'hostnix/weebnix/configuration.nix')
| -rw-r--r-- | hostnix/weebnix/configuration.nix | 93 |
1 files changed, 93 insertions, 0 deletions
diff --git a/hostnix/weebnix/configuration.nix b/hostnix/weebnix/configuration.nix new file mode 100644 index 0000000..a0166f5 --- /dev/null +++ b/hostnix/weebnix/configuration.nix @@ -0,0 +1,93 @@ +{ config, pkgs, ... }: + +{ + imports = [ + ./dyndns.nix + ./hardware-configuration.nix + ./home-assistant.nix + ./oidc.nix + ./privacy-frontends.nix + ./syncthing.nix + ./system.nix + ]; + + nix.settings.experimental-features = [ "nix-command" "flakes" ]; + nix.settings.trusted-users = [ "joe" ]; + + security.sudo.wheelNeedsPassword = false; + + security.acme.acceptTerms = true; + security.acme.defaults.email = "hostmaster@mou.fo"; + # TODO switch to production certs + security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory"; + + users.users.joe = { + isNormalUser = true; + extraGroups = [ "wheel" "syncthing" ]; + openssh.authorizedKeys.keys = [ + "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky" + ]; + }; + + environment.systemPackages = with pkgs; [ + dig + file + gitFull + jq + libraspberrypi + sqlite-interactive + tmux + tree + ]; + + programs.vim.defaultEditor = true; + programs.nano.enable = false; + + services.openssh.enable = true; + + services.nginx = { + enable = true; + recommendedGzipSettings = true; + recommendedOptimisation = true; + recommendedProxySettings = true; + recommendedTlsSettings = true; + # Slightly crazy setup to SNI reverse proxy HTTPS to multiple upstreams. + # We displace ourselves onto port 8443, and send requests that are not + # intended for us to weeber. This is done because Apache running on weeber + # cannot SNI reverse proxy, so we put weebnix in front of weeber on IPv4. + # TODO get rid of all this when replacing weeber or maybe consider HAProxy + defaultSSLListenPort = 8443; + streamConfig = '' + map $ssl_preread_server_name $selected_upstream { + hostnames; + weebnix.mou.fo self; + *.weebnix.mou.fo self; + default weeber; + } + upstream self { server 127.0.0.1:8443; } + upstream weeber { server 192.168.0.168:443; } + server { + listen 0.0.0.0:443; + listen [::0]:443; + proxy_pass $selected_upstream; + ssl_preread on; + } + ''; + }; + + # TODO remove upon switching to production certs + services.oauth2_proxy.extraConfig = { + "ssl-insecure-skip-verify" = true; + "ssl-upstream-insecure-skip-verify" = true; + }; + + networking.firewall.allowedTCPPorts = [ 80 443 ]; + + # This value determines the NixOS release from which the default + # settings for stateful data, like file locations and database versions + # on your system were taken. It's perfectly fine and recommended to leave + # this value at the release version of the first install of this system. + # Before changing this value read the documentation for this option + # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). + system.stateVersion = "23.05"; # Did you read the comment? +} |
