summaryrefslogtreecommitdiff
path: root/hostnix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix')
-rw-r--r--hostnix/elmo/email.nix15
-rw-r--r--hostnix/elmo/flake.lock8
-rw-r--r--hostnix/elmo/flake.nix2
-rw-r--r--hostnix/elmo/home-assistant.nix3
-rw-r--r--hostnix/elmo/home-assistant/auth_header.nix29
-rw-r--r--hostnix/elmo/oidc.nix5
6 files changed, 44 insertions, 18 deletions
diff --git a/hostnix/elmo/email.nix b/hostnix/elmo/email.nix
index ee169f2..71f85c9 100644
--- a/hostnix/elmo/email.nix
+++ b/hostnix/elmo/email.nix
@@ -81,19 +81,20 @@
services.postfix = {
enable = true;
- hostname = config.networking.fqdn;
- relayHost = "smtp.mou.fo";
- relayPort = 587;
- sslCert = "/var/lib/postfix/tls/live/fullchain.pem";
- sslKey = "/var/lib/postfix/tls/live/key.pem";
extraAliases = ''
root: joe
joe: joe@mou.fo
'';
- config = {
+ settings.main = {
+ myhostname = config.networking.fqdn;
+ relayhost = [ "smtp.mou.fo:587" ];
+ smtp_tls_chain_files = [
+ "/var/lib/postfix/tls/live/key.pem"
+ "/var/lib/postfix/tls/live/fullchain.pem"
+ ];
smtp_tls_security_level = "encrypt";
smtp_tls_session_cache_database = "btree:\${data_directory}/smtp_scache";
- message_size_limit = "51200000";
+ message_size_limit = 51200000;
default_destination_rate_delay = "1s";
};
};
diff --git a/hostnix/elmo/flake.lock b/hostnix/elmo/flake.lock
index 705f76d..fc1308c 100644
--- a/hostnix/elmo/flake.lock
+++ b/hostnix/elmo/flake.lock
@@ -2,16 +2,16 @@
"nodes": {
"nixpkgs": {
"locked": {
- "lastModified": 1764939437,
- "narHash": "sha256-4TLFHUwXraw9Df5mXC/vCrJgb50CRr3CzUzF0Mn3CII=",
+ "lastModified": 1764983851,
+ "narHash": "sha256-y7RPKl/jJ/KAP/VKLMghMgXTlvNIJMHKskl8/Uuar7o=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "00d2457e2f608b4be6fe8b470b0a36816324b0ae",
+ "rev": "d9bc5c7dceb30d8d6fafa10aeb6aa8a48c218454",
"type": "github"
},
"original": {
"owner": "NixOS",
- "ref": "nixos-25.05",
+ "ref": "nixos-25.11",
"repo": "nixpkgs",
"type": "github"
}
diff --git a/hostnix/elmo/flake.nix b/hostnix/elmo/flake.nix
index 0d81931..3928b11 100644
--- a/hostnix/elmo/flake.nix
+++ b/hostnix/elmo/flake.nix
@@ -1,6 +1,6 @@
{
inputs = {
- nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.05";
+ nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11";
};
outputs = { self, nixpkgs }: {
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index f667361..a3cc2f1 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -22,7 +22,8 @@
];
customComponents = with pkgs.home-assistant-custom-components; [
adaptive_lighting
- auth-header
+ # TODO replace with auth_oidc https://github.com/christiaangoossens/hass-oidc-auth
+ (pkgs.callPackage ./home-assistant/auth_header.nix {})
tuya_local
];
diff --git a/hostnix/elmo/home-assistant/auth_header.nix b/hostnix/elmo/home-assistant/auth_header.nix
new file mode 100644
index 0000000..480598e
--- /dev/null
+++ b/hostnix/elmo/home-assistant/auth_header.nix
@@ -0,0 +1,29 @@
+{
+ lib,
+ buildHomeAssistantComponent,
+ fetchFromGitHub,
+}:
+
+buildHomeAssistantComponent rec {
+ owner = "BeryJu";
+ domain = "auth_header";
+ version = "1.12";
+
+ src = fetchFromGitHub {
+ inherit owner;
+ repo = "hass-auth-header";
+ tag = "v${version}";
+ hash = "sha256-BPG/G6IM95g9ip2OsPmcAebi2ZvKHUpFzV4oquOFLPM=";
+ };
+
+ # isort: command not found
+ dontBuild = true;
+
+ meta = with lib; {
+ changelog = "https://github.com/BeryJu/hass-auth-header/releases/tag/v${version}";
+ description = "Home Assistant custom component which allows you to delegate authentication to a reverse proxy";
+ homepage = "https://github.com/BeryJu/hass-auth-header";
+ maintainers = with maintainers; [ mjm ];
+ license = licenses.gpl3;
+ };
+}
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index d7c6f0e..c3c2c0d 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -9,11 +9,6 @@
}];
};
- # CVE-2024-41952 as of 24.05. Leaks existence of usernames.
- nixpkgs.config.permittedInsecurePackages = [
- "zitadel"
- ];
-
services.zitadel = {
enable = true;
settings = {