summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2024-04-26elmo: postfix with client certificatesJoe Mou
2024-04-26elmo: Enable sshguardJoe Mou
2024-04-26ACME with DNS challengeJoe Mou
2024-04-26elmo: blocky ad-blocking DNSJoe Mou
2024-04-26elmo: simplify SIG(0) key managementJoe Mou
2024-04-26elmo: nzbgetJoe Mou
2024-04-26elmo: move syncthing to /srvJoe Mou
2024-04-26elmo: /srv subvolumeJoe Mou
The intention is to separate user-managed data, like backups and file shares. Still need to move syncthing over. An implication is /srv will probably not participate in restic backups but be replicated in some other way.
2024-04-26elmo: Enable fstrimJoe Mou
Initial run trimmed nearly the entire volume. May be quite important since Nix churns through storage.
2024-04-26elmo: Move secrets to /var/secretsJoe Mou
Clarifies that they are not managed by a distribution package.
2024-04-26Use SSH host alias for elmoJoe Mou
2024-04-26libreddit tweaksJoe Mou
2024-04-23Panel light and thermostat HA automationsJoe Mou
2024-04-23Initial HA automations (panel light & bedroom thermostat)Joe Mou
2024-04-15commentsJoe Mou
2024-03-20creep: configure WiFi AP that tunnels over VPNJoe Mou
2024-03-12creep: ensure IPv4 dyndns updatesJoe Mou
2024-03-12creep: static network configuration instead of NetworkManagerJoe Mou
2024-03-12creep: reverse SSH tunnel and dynamic DNSJoe Mou
2024-03-12creep: add swapJoe Mou
Contravenes guidance to avoid edits to hardware-configuration.nix
2024-03-12Streamline elmo configJoe Mou
2024-03-11creep: initial configurationJoe Mou
2024-02-18Enable mDNSJoe Mou
2024-02-18use tmpfs for /tmpJoe Mou
2024-02-18Add mac mini SSH key and SyncthingJoe Mou
2024-02-18Update and fix up tuya-local packagingJoe Mou
2024-02-18Boot after power failure (server mode)Joe Mou
2024-02-15Move /var to larger hard driveJoe Mou
2024-02-15Kludgy fix for oauth2_proxy on bootJoe Mou
2024-02-15Port configs from weebnixJoe Mou
2024-02-13Simplify elmo/system.nixJoe Mou
2024-02-13Refactor elmo default configsJoe Mou
2024-02-13Low-level reconfigurationJoe Mou
- btrfs subvolumes - hostname - SSH
2024-02-13Initial mac mini NixOS configurationJoe Mou
2024-02-13Leftover weebnix configs (hard drive died?)Joe Mou
2023-12-22Adopt new services.home-assistant.customComponentsJoe Mou
2023-12-22Revert "Switch to production ACME certs"Joe Mou
This reverts commit 18148c3dec9154f43c5be6f2ed9e427e990c6a06.
2023-12-21Upgrade to NixOS 23.11Joe Mou
2023-10-02Add remaining Syncthing sharesJoe Mou
2023-10-01Add libreddit serviceJoe Mou
2023-10-01Syncthing exposed frontend and added devicesJoe Mou
2023-10-01Adjust OpenId Connect / OAuth2 config for use across subdomainsJoe Mou
2023-10-01Switch to production ACME certsJoe Mou
2023-10-01Initial configuration of Home Assistant w/ oauth2-proxy for KeyCloak ↵Joe Mou
authentication
2023-09-29Disable DNSSEC validationJoe Mou
There may be more than one issue. Most distributions do not seem to enable DNSSEC verification, so we'll disable for now too. Related: https://github.com/systemd/systemd/pull/18563
2023-09-29Add KeycloakJoe Mou
2023-09-29Refactor system and dyndns modulesJoe Mou
2023-09-28IPv6 dynamic dns, systemd-networkd for RFC 7217 stable private addressesJoe Mou
systemd-networkd is a bit opaque. In particular there doesn't seem to be a way to verify that the generated IPv6 addresses are stable private. An alternative may be to set net.ipv6.conf.default.addr_gen_mode = 2. systemd.network.wait-online.anyInterface does not seem to work properly; systemd-networkd-wait-online.service should be generated with --any flag but appears to be from upstream.
2023-09-28Initial Syncthing moduleJoe Mou
2023-09-27Mount /nix with noatimeJoe Mou