| Age | Commit message (Collapse) | Author |
|
|
|
Some other minor adjustments to entity naming, fan, and grow light.
|
|
Use a disposable domain until thinking more about authentication.
|
|
|
|
|
|
$ nix flake update --override-input nixpkgs github:NixOS/nixpkgs/ea156c6c3a5b67b0120f92f664853914a58d3b05
Avoid cgit issue until fix lands on stable:
https://github.com/NixOS/nixpkgs/pull/477185
|
|
|
|
- More reliable smart plug on panel light
- SAD lamp timer
|
|
Replaces unmaintained header authentication behind oauth2-proxy.
Add OIDC client for Home Assistant:
- Callback URLs: https://ha.mou.fo/auth/oidc/callback
- Public Client
To link OIDC credentials with the existing joe user, temporarily set:
auth_oidc.features.automatic_user_linking = true;
See https://github.com/christiaangoossens/hass-oidc-auth/blob/main/docs/configuration.md#migrating-from-ha-usernamepassword-users-to-oidc-users
Must login through either:
- https://ha.mou.fo/auth/oidc/welcome
- https://ha.mou.fo/auth/oidc/redirect
Injecting directly into the landing login page is pending
https://github.com/christiaangoossens/hass-oidc-auth/issues/19
|
|
Much simpler to configure and use.
|
|
|
|
|
|
The auth_header Home Assistant custom component has been removed. For
now we use the last package from:
https://github.com/NixOS/nixpkgs/blob/7f88a8b9efaf0e08e63e3806b2b3f42fd83fde91/pkgs/servers/home-assistant/custom-components/auth-header/package.nix
|
|
NixOS 25.11 contains Nix 2.30 which now builds to /nix/var/nix/builds,
which is not space constrained like the previous default of /tmp. To
perform the upgrade to NixOS 25.11, we first must unset our build-dir
from a world writable directory.
See https://github.com/nixos/nix/issues/13701
|
|
|
|
|
|
Getting the right permissions set on the socket is quite awkward.
Perhaps listening on a port would have been preferable. systemd socket
activation would require us to support file descriptor handoff (which
would need to be changed in Nitro).
|
|
|
|
broadcom_sta WiFi driver is considered insecure. We weren't using WiFi
anyway, so remove it. It may be possible to use Broadcom open source
drivers for our BCM4360, but these may only support newer hardware.
Also use allowUnfreePredicate to explicitly whitelist packages.
|
|
|
|
Apparently packageOverrides are deprecated by overlays. Overlays
apparently can "increase eval time". If intel-vaapi-driver is a "leaf"
package then we can use the overridden package instance without
replacing it in nixpkgs. It seems like the only place this package
should be referenced is from hardware.graphics.extraPackages, and not as
a dependency of other packages.
See https://discourse.nixos.org/t/overriding-a-package/59565
|
|
We had been setting TMPDIR for nix-daemon, but nixos-rebuild does not
use that. Use the newer build-dir setting instead.
See https://github.com/NixOS/nixpkgs/issues/293114#issuecomment-2663470083
|
|
|
|
Needs /var/secrets/restic to be manually provisioned.
Based on ~/.dotfiles/restic/run, as a starting point.
Backing up /srv/Attic is huge (100s of GBs), redundant (same hard
drive), and slow (hours). It probably makes sense to mirror it instead.
The repo password is stored on the same hard drive in plaintext, which
means our repo is not secure at rest. This is a bigger issue with the
initial setup without full disk encryption, so we choose not to address
it; however, this does expose all backups whereas previously just this
server was exposed.
The most important remaining tasks are to mirror the restic backups
remotely, and to automate on a timer.
|
|
Not a big fan. It's obtuse to configure, the implementation is
complicated (relative to just using the yt-dlp CLI), and difficult to
debug. We would probably still need some additional automation to get
the file layout we want.
It might be more straightforward to just write our own automation on top
of yt-dlp.
|
|
Advantages over Gitea (and most other git forges):
- Arbitrary repository hierarchies.
- Repository aliases with symlinks.
- No metadata to keep synchronized with repositories; simple automation.
Create new repos like:
$ sudo -u git git init --bare -b main /srv/git/2025/calmux.git
Ideally we would not require authentication for whitelisted public
repos. This is difficult with oauth2-proxy because to disable
auth_request we need a new location clause which does not "inherit" the
FastCGI configuration. Perhaps we could use cgit's built-in auth-filter.
Considered gitolite instead of git-shell (which would allow multiuser
authentication). This probably requires configuring each repo which
complicates automation.
|
|
|
|
Set boot.loader.grub.configurationLimit to avoid running out of space on /boot
|
|
|
|
|
|
Still don't love it but let's get things into a working state.
Promising next steps:
- Authlib (Python)
- oidc-provider (Javascript)
- Vouch Proxy, Ory Oauthkeeper, or IdP built-in forward auth
Look at [[Authentication]]
|
|
If we wanted an LDAP server, glauth seems like a pretty good pick. It's
lightweight and can be configured entirely by a stateless text config
(it also supports a sqlite backend; it doesn't appear they can be used
together though).
But do we really benefit from an LDAP server? It could help set up
services that have LDAP authentication but not OIDC (most services that
use oauth2-proxy). Perhaps we'll revisit this.
glauth docs are spotty, but these are relevant for the config file:
- https://glauth.github.io/docs/file.html
- https://github.com/glauth/glauth/blob/master/v2/sample-simple.cfg
Nix has envsubst and replace-secret to include secrets in the config.
Information on setting up MFA:
https://www.couchbase.com/blog/multi-factor-authentication-mfa-2fa/
If we bind to an address besides localhost we should also set up LDAPS.
|
|
Dex really doesn't want to be the authoritative identity provider.
Static users are not very configurable. The sub claim is a base64
internal representation that we can't use in backends directly. We could
jury rig email, but never got that working.
Basic authentication works, but Home Assistant fails to login the user.
|
|
Disable home directory creation, which clobbers directory permissions.
Interestingly, after the ACLs are added the classic directory
permissions appear as 770; but happily it works fine.
Tip off was from https://discourse.nixos.org/t/home-facl-is-always-reset-in-21-05/13408
Also tried setting the ACL mask which wasn't the issue.
|
|
|
|
Heavyweight for what I need and too opinionated about organization. OPDS
layout is overcomplicated. Also tried Kavita but didn't like it (don't
remember why).
Still needs SSO. May try a simple OPDS-only server or build.
|
|
ModuleNotFoundError: No module named 'aiohomekit'
|
|
We still want SSO. It seems most promising to register Miniflux as an
OIDC client, but this is pending switching to a different identity
provider.
Alternatively we could use oauth2-proxy and configure AUTH_PROXY_HEADER.
We would want to bypass for API endpoints:
- /accounts/ClientLogin
- /reader/api/
|
|
|
|
We don't want to use Nix for deployment because it's slow. Code must be
manually deployed to /opt/garage.
|
|
Probably won't keep this, but playing with OCI containers and XSLT were
interesting.
Converting Feedly OPML to feeds.txt:
$ nomad @xmlstarlet select -T -t -m '//outline[@type="rss"]' -v ./@xmlUrl -o $'\t' -v ./@title -o $'\t#' -v ../@text -o $'\n' Downloads/feedly-093988c0-b9a0-4bb7-97dc-6946128b509e-2025-03-30-d63a70cb-archive/subscriptions.opml | awk -F'\t' -v OFS=' ' '{gsub(/ /, "_", $2); gsub(/ /, "-", $3); $1=$1; print}'
|
|
Have not allocated the mf.mou.fo subdomain yet while testing the app.
BASE_URL seems nonessential, but at least fixes the API endpoint given.
To create the initial admin user:
$ sudo -u miniflux env DATABASE_URL='user=miniflux host=/run/postgresql dbname=miniflux' miniflux -create-admin
The UI is quite clunky. In particular it is very easy to get lost
navigating between article list and detail views. It would also be nice
to force opening articles on the external site (for Phoronix). Fetching
original content (instead of using the RSS content) is nice though.
To integrate with oauth2-proxy, probably need to set AUTH_PROXY_HEADER.
|
|
Still need to remove Möbius and migrate iPhone to Synctrain also.
This should also properly set /srv/syncthing group permissions.
|
|
Cooler midday color temperature and throttle reinitialization.
|
|
Add ACLs for nginx that only allow read access. This is more limited
than allowing all users read access to /srv/syncthing, or adding nginx
as a writable user to the syncthing group.
|
|
Untested but ported from old HA config in
commit 25f26a29a6255c5fe3ccf0ffa11f630bd63c60df
|
|
|
|
|
|
Deduplicate btrfs files.
|
|
|