summaryrefslogtreecommitdiff
path: root/hostnix/elmo/configuration.nix
AgeCommit message (Collapse)Author
2025-12-28Add doughboyJoe Mou
2025-12-24yakatak serviceJoe Mou
Getting the right permissions set on the socket is quite awkward. Perhaps listening on a port would have been preferable. systemd socket activation would require us to support file descriptor handoff (which would need to be changed in Nitro).
2025-09-02make upgrade, remove broadcom_sta WiFiJoe Mou
broadcom_sta WiFi driver is considered insecure. We weren't using WiFi anyway, so remove it. It may be possible to use Broadcom open source drivers for our BCM4360, but these may only support newer hardware. Also use allowUnfreePredicate to explicitly whitelist packages.
2025-09-02Minimal n8n serving (no HTTPS)Joe Mou
2025-07-01Unattended local backupsJoe Mou
Needs /var/secrets/restic to be manually provisioned. Based on ~/.dotfiles/restic/run, as a starting point. Backing up /srv/Attic is huge (100s of GBs), redundant (same hard drive), and slow (hours). It probably makes sense to mirror it instead. The repo password is stored on the same hard drive in plaintext, which means our repo is not secure at rest. This is a bigger issue with the initial setup without full disk encryption, so we choose not to address it; however, this does expose all backups whereas previously just this server was exposed. The most important remaining tasks are to mirror the restic backups remotely, and to automate on a timer.
2025-06-16Upgrade to NixOS 25.05Joe Mou
2025-04-16Use ACLs to grant user access to /src/syncthingJoe Mou
2025-04-16Initial garage serviceJoe Mou
We don't want to use Nix for deployment because it's slow. Code must be manually deployed to /opt/garage.
2025-04-09Miniflux RSS aggregatorJoe Mou
Have not allocated the mf.mou.fo subdomain yet while testing the app. BASE_URL seems nonessential, but at least fixes the API endpoint given. To create the initial admin user: $ sudo -u miniflux env DATABASE_URL='user=miniflux host=/run/postgresql dbname=miniflux' miniflux -create-admin The UI is quite clunky. In particular it is very easy to get lost navigating between article list and detail views. It would also be nice to force opening articles on the external site (for Phoronix). Fetching original content (instead of using the RSS content) is nice though. To integrate with oauth2-proxy, probably need to set AUTH_PROXY_HEADER.
2025-04-08Synchronize /user served by nginx with SyncthingJoe Mou
Add ACLs for nginx that only allow read access. This is more limited than allowing all users read access to /srv/syncthing, or adding nginx as a writable user to the syncthing group.
2024-12-23penguin SSH keyJoe Mou
2024-12-23Manual duperemove systemd serviceJoe Mou
Deduplicate btrfs files.
2024-12-16WireguardJoe Mou
2024-12-13Upgrade to NixOS 24.11Joe Mou
2024-11-16Enable envfsJoe Mou
Quick fix for .dotfiles scripts
2024-10-18Jellyfin media server w/ VA-API hardware accelerationJoe Mou
Jellyfin uses its own authentication; it's probably not worthwhile to try to consolidate with SSO (and may break Jellyfin clients). We don't bother to allow UDP for DLNA nor Jellyfin auto detection.
2024-10-18Use Zitadel to replace KanidmJoe Mou
Kanidm development is kind of slow and conservative. Their frontend is lacking. The hope was Zitadel would solve some issues logging in to the Home Assistant app behind oauth2-proxy, but it doesn't really help. In particular, KeePassium is unable to password complete (login page reloads to username entry?). In any case, we probably prefer Zitadel so let's at least record it for now. Pocket ID is an interesting minimal alternative, but the Home Assistant app doesn't support passkeys. $ sudo rm -r /var/lib/kanidm/
2024-10-18Add upgrade make target, add packagesJoe Mou
2024-10-09Try out GiteaJoe Mou
DISABLE_REGISTRATION needs to be set after the initial administrator account is manually registered. Considered the Forgejo community fork, but it doesn't seem to have attracted very much of the developer community. Despite concerns about copyright claims, Gitea does not have a CLA; it is MIT licensed. Still considering even lighter weight options that may be easier to programmatically control (just an HTTP server that speaks the smart protocol?). For managing groups of repositories, can use labels or organizations. Neither seem particularly convenient. Gitea defaults to public repositories.
2024-10-09sshguard whitelist to prevent lockoutJoe Mou
2024-06-11locate/updatedbJoe Mou
2024-04-26elmo: E-mail on certain systemd failuresJoe Mou
2024-04-26elmo: postfix with client certificatesJoe Mou
2024-04-26elmo: Enable sshguardJoe Mou
2024-04-26ACME with DNS challengeJoe Mou
2024-04-26elmo: blocky ad-blocking DNSJoe Mou
2024-04-26elmo: nzbgetJoe Mou
2024-04-26elmo: Enable fstrimJoe Mou
Initial run trimmed nearly the entire volume. May be quite important since Nix churns through storage.
2024-02-18Add mac mini SSH key and SyncthingJoe Mou
2024-02-15Port configs from weebnixJoe Mou
2024-02-13Refactor elmo default configsJoe Mou
2024-02-13Low-level reconfigurationJoe Mou
- btrfs subvolumes - hostname - SSH
2024-02-13Initial mac mini NixOS configurationJoe Mou