{ config, pkgs, ... }: { imports = [ ./dyndns.nix ./hardware-configuration.nix ./home-assistant.nix ./syncthing.nix ./system.nix ]; nix.settings.experimental-features = [ "nix-command" "flakes" ]; nix.settings.trusted-users = [ "joe" ]; security.sudo.wheelNeedsPassword = false; security.acme.acceptTerms = true; security.acme.defaults.email = "hostmaster@mou.fo"; # TODO switch to production certs security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory"; users.users.joe = { isNormalUser = true; extraGroups = [ "wheel" ]; openssh.authorizedKeys.keys = [ "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky" ]; }; environment.systemPackages = with pkgs; [ libraspberrypi tmux ]; programs.vim.defaultEditor = true; services.openssh.enable = true; services.keycloak = { enable = true; database.passwordFile = "/var/lib/secrets/keycloak.dbpass"; settings = { hostname = "kc.weebnix.mou.fo"; http-host = "127.0.0.1"; http-port = 7567; proxy = "edge"; }; }; services.nginx = { enable = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedTlsSettings = true; virtualHosts."kc.weebnix.mou.fo" = { enableACME = true; forceSSL = true; locations."/".proxyPass = "http://127.0.0.1:7567"; }; # Slightly crazy setup to SNI reverse proxy HTTPS to multiple upstreams. # We displace ourselves onto port 8443, and send requests that are not # intended for us to weeber. This is done because Apache running on weeber # cannot SNI reverse proxy, so we put weebnix in front of weeber on IPv4. # TODO get rid of all this when replacing weeber or maybe consider HAProxy defaultSSLListenPort = 8443; streamConfig = '' map $ssl_preread_server_name $selected_upstream { hostnames; weebnix.mou.fo self; *.weebnix.mou.fo self; default weeber; } upstream self { server 127.0.0.1:8443; } upstream weeber { server 192.168.0.168:443; } server { listen 0.0.0.0:443; listen [::0]:443; proxy_pass $selected_upstream; ssl_preread on; } ''; }; # TODO remove upon switching to production certs services.oauth2_proxy.extraConfig = { "ssl-insecure-skip-verify" = true; "ssl-upstream-insecure-skip-verify" = true; }; networking.firewall.allowedTCPPorts = [ 80 443 ]; # This value determines the NixOS release from which the default # settings for stateful data, like file locations and database versions # on your system were taken. It's perfectly fine and recommended to leave # this value at the release version of the first install of this system. # Before changing this value read the documentation for this option # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). system.stateVersion = "23.05"; # Did you read the comment? }