# Edit this configuration file to define what should be installed on # your system. Help is available in the configuration.nix(5) man page # and in the NixOS manual (accessible by running `nixos-help`). { config, pkgs, ... }: { imports = [ # Include the results of the hardware scan. ./hardware-configuration.nix ]; nix.settings.experimental-features = [ "nix-command" "flakes" ]; nix.settings.trusted-users = [ "joe" ]; boot.loader.systemd-boot.enable = true; # Raspberry Pi has no NVRAM. boot.loader.efi.canTouchEfiVariables = false; boot.kernelPackages = pkgs.linuxPackages_rpi4; # https://github.com/NixOS/nixpkgs/issues/122130#issuecomment-1568815007 # It's unclear if these are strictly necessary with the downstream kernel, # but let's leave them in to keep working with mainline. boot.initrd.availableKernelModules = [ "uas" "pcie-brcmstb" "reset-raspberrypi" ]; networking.hostName = "weebnix"; networking.domain = "mou.fo"; # TODO secrets management or switch to wired networking.wireless = { enable = true; networks."oldschool".psk = builtins.readFile /var/lib/secrets/oldschool.wpa-psk; }; time.timeZone = "America/New_York"; # Select internationalisation properties. # i18n.defaultLocale = "en_US.UTF-8"; # console = { # font = "Lat2-Terminus16"; # keyMap = "us"; # useXkbConfig = true; # use xkbOptions in tty. # }; security.sudo.wheelNeedsPassword = false; users.users.joe = { isNormalUser = true; extraGroups = [ "wheel" ]; openssh.authorizedKeys.keys = [ "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky" ]; # packages = with pkgs; [ # firefox # tree # ]; }; environment.systemPackages = with pkgs; [ libraspberrypi tmux vim ]; # Some programs need SUID wrappers, can be configured further or are # started in user sessions. # programs.mtr.enable = true; # programs.gnupg.agent = { # enable = true; # enableSSHSupport = true; # }; # Needs to be started manually, and the key added to nameservers. # Based on https://nixos.org/manual/nixos/stable/index.html#module-security-acme-config-dns systemd.services.sig0-keygen = { unitConfig = { ConditionPathExists = "!/var/lib/secrets/${config.networking.fqdn}.id"; }; serviceConfig = { Type = "oneshot"; }; path = [ pkgs.bind ]; scriptArgs = config.networking.fqdn; script = '' mkdir -p /var/lib/secrets chmod 755 /var/lib/secrets cd /var/lib/secrets dnssec-keygen -a RSASHA512 -b 2048 -n HOST -T KEY $1. > $1.id ''; }; systemd.services.dyndns = { requires = [ "network-online.target" ]; after = [ "network-online.target" ]; unitConfig = { AssertPathExists = "/var/lib/secrets/${config.networking.fqdn}.id"; # Defer errors for ~45min, throttle e-mails to ~hourly. StartLimitIntervalSec = "1hr"; StartLimitBurst = "45"; }; serviceConfig = { Type = "oneshot"; Restart = "on-failure"; RestartSec = "1min"; }; path = [ pkgs.dnsutils ]; scriptArgs = config.networking.fqdn; script = '' RR=''${1%%.*}.dynamic.''${1#*.} IP=`dig +short @1.1.1.1 ch txt whoami.cloudflare | tr -d \"` if [ -z "$IP" ]; then echo "Missing IP: $IP" >&2 exit 100 fi OLDIP=`dig +short @popfresh.mou.fo $RR A 2> /dev/null` [ "x$IP" = "x$OLDIP" ] && exit 0 # no update nsupdate -v -k /var/lib/secrets/`< /var/lib/secrets/$1.id`.private <<. update delete $RR. A update add $RR. 300 A $IP update delete $RR. TXT update add $RR. 300 TXT "v=spf1 include:_spf.mou.fo ~all" send . ''; }; systemd.timers.dyndns = { wantedBy = [ "multi-user.target" ]; timerConfig = { OnStartupSec = "10"; OnUnitActiveSec = "1min"; }; }; services.avahi = { enable = true; nssmdns = true; }; services.openssh.enable = true; # Open ports in the firewall. # networking.firewall.allowedTCPPorts = [ ... ]; # networking.firewall.allowedUDPPorts = [ ... ]; # Or disable the firewall altogether. # networking.firewall.enable = false; # Copy the NixOS configuration file and link it from the resulting system # (/run/current-system/configuration.nix). This is useful in case you # accidentally delete configuration.nix. # system.copySystemConfiguration = true; # This value determines the NixOS release from which the default # settings for stateful data, like file locations and database versions # on your system were taken. It's perfectly fine and recommended to leave # this value at the release version of the first install of this system. # Before changing this value read the documentation for this option # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). system.stateVersion = "23.05"; # Did you read the comment? }