summaryrefslogtreecommitdiff
path: root/hostnix/elmo
AgeCommit message (Collapse)Author
2025-09-02Properly set nix build-dirJoe Mou
We had been setting TMPDIR for nix-daemon, but nixos-rebuild does not use that. Use the newer build-dir setting instead. See https://github.com/NixOS/nixpkgs/issues/293114#issuecomment-2663470083
2025-09-02make upgradeJoe Mou
2025-07-01Unattended local backupsJoe Mou
Needs /var/secrets/restic to be manually provisioned. Based on ~/.dotfiles/restic/run, as a starting point. Backing up /srv/Attic is huge (100s of GBs), redundant (same hard drive), and slow (hours). It probably makes sense to mirror it instead. The repo password is stored on the same hard drive in plaintext, which means our repo is not secure at rest. This is a bigger issue with the initial setup without full disk encryption, so we choose not to address it; however, this does expose all backups whereas previously just this server was exposed. The most important remaining tasks are to mirror the restic backups remotely, and to automate on a timer.
2025-06-27Configure ytdl-subJoe Mou
Not a big fan. It's obtuse to configure, the implementation is complicated (relative to just using the yt-dlp CLI), and difficult to debug. We would probably still need some additional automation to get the file layout we want. It might be more straightforward to just write our own automation on top of yt-dlp.
2025-06-27Stripped down git hosting with cgit and git-shellJoe Mou
Advantages over Gitea (and most other git forges): - Arbitrary repository hierarchies. - Repository aliases with symlinks. - No metadata to keep synchronized with repositories; simple automation. Create new repos like: $ sudo -u git git init --bare -b main /srv/git/2025/calmux.git Ideally we would not require authentication for whitelisted public repos. This is difficult with oauth2-proxy because to disable auth_request we need a new location clause which does not "inherit" the FastCGI configuration. Perhaps we could use cgit's built-in auth-filter. Considered gitolite instead of git-shell (which would allow multiuser authentication). This probably requires configuring each repo which complicates automation.
2025-06-16Upgrade to NixOS 25.05Joe Mou
2025-06-16make upgradeJoe Mou
Set boot.loader.grub.configurationLimit to avoid running out of space on /boot
2025-06-16Switch to flakesJoe Mou
2025-06-16Default web serving to UTF-8Joe Mou
2025-06-16Revert auth to ZitadelJoe Mou
Still don't love it but let's get things into a working state. Promising next steps: - Authlib (Python) - oidc-provider (Javascript) - Vouch Proxy, Ory Oauthkeeper, or IdP built-in forward auth Look at [[Authentication]]
2025-06-16Try setting up glauth LDAP, for some reasonJoe Mou
If we wanted an LDAP server, glauth seems like a pretty good pick. It's lightweight and can be configured entirely by a stateless text config (it also supports a sqlite backend; it doesn't appear they can be used together though). But do we really benefit from an LDAP server? It could help set up services that have LDAP authentication but not OIDC (most services that use oauth2-proxy). Perhaps we'll revisit this. glauth docs are spotty, but these are relevant for the config file: - https://glauth.github.io/docs/file.html - https://github.com/glauth/glauth/blob/master/v2/sample-simple.cfg Nix has envsubst and replace-secret to include secrets in the config. Information on setting up MFA: https://www.couchbase.com/blog/multi-factor-authentication-mfa-2fa/ If we bind to an address besides localhost we should also set up LDAPS.
2025-06-16In progress attempt to use Dex for OIDCJoe Mou
Dex really doesn't want to be the authoritative identity provider. Static users are not very configurable. The sub claim is a base64 internal representation that we can't use in backends directly. We could jury rig email, but never got that working. Basic authentication works, but Home Assistant fails to login the user.
2025-06-16Fix /srv/syncthing ACLsJoe Mou
Disable home directory creation, which clobbers directory permissions. Interestingly, after the ACLs are added the classic directory permissions appear as 770; but happily it works fine. Tip off was from https://discourse.nixos.org/t/home-facl-is-always-reset-in-21-05/13408 Also tried setting the ACL mask which wasn't the issue.
2025-06-16Replace iOS Mobius Sync with SynctrainJoe Mou
2025-04-21Komga for OPDSJoe Mou
Heavyweight for what I need and too opinionated about organization. OPDS layout is overcomplicated. Also tried Kavita but didn't like it (don't remember why). Still needs SSO. May try a simple OPDS-only server or build.
2025-04-16Squelch Home Assistant aiohomekit exceptionsJoe Mou
ModuleNotFoundError: No module named 'aiohomekit'
2025-04-16Remove danb/rss and host Miniflux on https://mf.mou.foJoe Mou
We still want SSO. It seems most promising to register Miniflux as an OIDC client, but this is pending switching to a different identity provider. Alternatively we could use oauth2-proxy and configure AUTH_PROXY_HEADER. We would want to bypass for API endpoints: - /accounts/ClientLogin - /reader/api/
2025-04-16Use ACLs to grant user access to /src/syncthingJoe Mou
2025-04-16Initial garage serviceJoe Mou
We don't want to use Nix for deployment because it's slow. Code must be manually deployed to /opt/garage.
2025-04-09Try minimal danb/rss aggregatorJoe Mou
Probably won't keep this, but playing with OCI containers and XSLT were interesting. Converting Feedly OPML to feeds.txt: $ nomad @xmlstarlet select -T -t -m '//outline[@type="rss"]' -v ./@xmlUrl -o $'\t' -v ./@title -o $'\t#' -v ../@text -o $'\n' Downloads/feedly-093988c0-b9a0-4bb7-97dc-6946128b509e-2025-03-30-d63a70cb-archive/subscriptions.opml | awk -F'\t' -v OFS=' ' '{gsub(/ /, "_", $2); gsub(/ /, "-", $3); $1=$1; print}'
2025-04-09Miniflux RSS aggregatorJoe Mou
Have not allocated the mf.mou.fo subdomain yet while testing the app. BASE_URL seems nonessential, but at least fixes the API endpoint given. To create the initial admin user: $ sudo -u miniflux env DATABASE_URL='user=miniflux host=/run/postgresql dbname=miniflux' miniflux -create-admin The UI is quite clunky. In particular it is very easy to get lost navigating between article list and detail views. It would also be nice to force opening articles on the external site (for Phoronix). Fetching original content (instead of using the RSS content) is nice though. To integrate with oauth2-proxy, probably need to set AUTH_PROXY_HEADER.
2025-04-09syncthing: Synctrain for iPad, add Steam Deck extra/Joe Mou
Still need to remove Möbius and migrate iPhone to Synctrain also. This should also properly set /srv/syncthing group permissions.
2025-04-08Tweak panel light automationsJoe Mou
Cooler midday color temperature and throttle reinitialization.
2025-04-08Synchronize /user served by nginx with SyncthingJoe Mou
Add ACLs for nginx that only allow read access. This is more limited than allowing all users read access to /srv/syncthing, or adding nginx as a writable user to the syncthing group.
2025-02-26Panel light reinitialize HA automationJoe Mou
Untested but ported from old HA config in commit 25f26a29a6255c5fe3ccf0ffa11f630bd63c60df
2025-02-26Remove "Game/Mass Effect" Syncthing folderJoe Mou
2024-12-23penguin SSH keyJoe Mou
2024-12-23Manual duperemove systemd serviceJoe Mou
Deduplicate btrfs files.
2024-12-23Use same dyndns retry limit as ansibleJoe Mou
2024-12-16WireguardJoe Mou
2024-12-13Upgrade to NixOS 24.11Joe Mou
2024-11-19Mount /var/log/journal on fast NVMEJoe Mou
Despite moving the original log files, reading historic logs does not appear to work.
2024-11-19Relay e-mail through smtp.mou.foJoe Mou
2024-11-17Update redlibJoe Mou
Fixes https://github.com/redlib-org/redlib/issues/229 Overrides Rust package per https://blog.mplanchard.com/posts/installing-a-specific-version-of-a-package-with-nix.html It appears packageOverrides are actually deprecated by overlays. See https://nixos.wiki/wiki/Overlays
2024-11-16Enable envfsJoe Mou
Quick fix for .dotfiles scripts
2024-11-16Separate /srv/restic subvolume and enable compressionJoe Mou
Simpler to enable compression on an entire filesystem; we use it for magnetic storage.
2024-10-18Jellyfin media server w/ VA-API hardware accelerationJoe Mou
Jellyfin uses its own authentication; it's probably not worthwhile to try to consolidate with SSO (and may break Jellyfin clients). We don't bother to allow UDP for DLNA nor Jellyfin auto detection.
2024-10-18Use Zitadel to replace KanidmJoe Mou
Kanidm development is kind of slow and conservative. Their frontend is lacking. The hope was Zitadel would solve some issues logging in to the Home Assistant app behind oauth2-proxy, but it doesn't really help. In particular, KeePassium is unable to password complete (login page reloads to username entry?). In any case, we probably prefer Zitadel so let's at least record it for now. Pocket ID is an interesting minimal alternative, but the Home Assistant app doesn't support passkeys. $ sudo rm -r /var/lib/kanidm/
2024-10-18Add upgrade make target, add packagesJoe Mou
2024-10-18Summer thermostat scheduleJoe Mou
Fixes /api to skip oauth2-proxy Not thoroughly tested; there are probably some issues.
2024-10-09Replace Keycloak with KanidmJoe Mou
Keycloak has always been heavyweight and cumbersome. Kanidm is meant to be an all-in-one Rust identity provider instead. $ sudo kanidmd recover-account idm_admin $ kanidm login --name idm_admin $ kanidm group account-policy credential-type-minimum idm_all_persons any $ kanidm person create joe Joe $ kanidm person credential update joe $ kanidm system oauth2 create oauth2-proxy 'OAuth2 Proxy' https://op.mou.fo $ kanidm system oauth2 update-scope-map oauth2-proxy idm_all_persons openid profile email $ kanidm system oauth2 show-basic-secret oauth2-proxy Passkeys don't work with KeePassXC on Firefox. They might work with Chrome or BitWarden. We disable TOTP for password authentication. Kanidm itself has considered and rejected forward auth support per https://github.com/kanidm/kanidm/issues/2774 With this arrangement session cookies are about 2k. While large these should fit within the default nginx buffers. Dex can be used as a simple identity provider, although it is more designed to facilitate app authentication. It can be configured to have a workable configuration with no persistent state and only staticClients and staticPasswords for resource servers and users. Vouch Proxy is comparable with oauth2-proxy. Both assume the user has an e-mail which we don't use. However oauth2-proxy seems to have better workarounds and is somewhat more actively maintained. Vouch Proxy also lacks a NixOS module. https://discourse.nixos.org/t/configuring-vouch-proxy-or-oauth2-proxy-nginx-nix/19337/2 https://github.com/vouch/vouch-proxy/issues/309
2024-10-09Try out GiteaJoe Mou
DISABLE_REGISTRATION needs to be set after the initial administrator account is manually registered. Considered the Forgejo community fork, but it doesn't seem to have attracted very much of the developer community. Despite concerns about copyright claims, Gitea does not have a CLA; it is MIT licensed. Still considering even lighter weight options that may be easier to programmatically control (just an HTTP server that speaks the smart protocol?). For managing groups of repositories, can use labels or organizations. Neither seem particularly convenient. Gitea defaults to public repositories.
2024-10-09Update Syncthing hostsJoe Mou
2024-10-09Refactor HA helper functionsJoe Mou
Based on https://github.com/nathan-gs/nix-conf/blob/main/lib/ha.nix (which goes further in using the module system; see https://nathan.gs/2023/12/09/adding-helper-functions-to-nixos/ )
2024-10-09Control AC with bedroom temperature sensorJoe Mou
2024-10-09Adjust adaptive_lighting parametersJoe Mou
2024-10-09Remove poor IPv6 support from dynamic DNSJoe Mou
2024-10-09sshguard whitelist to prevent lockoutJoe Mou
2024-10-09HA: adaptive_lighting custom component to follow daylightJoe Mou
2024-10-09Switch from unmaintained libreddit to redlibJoe Mou