blob: 241d64ef3f94877221e3937067625a3a6f6bfe56 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
|
{ pkgs, ... }:
{
imports = [
./hardware-configuration.nix
];
nix.settings.experimental-features = [ "nix-command" "flakes" ];
boot.loader.systemd-boot.enable = true;
# Raspberry Pi has no NVRAM.
boot.loader.efi.canTouchEfiVariables = false;
boot.kernelPackages = pkgs.linuxPackages_rpi4;
# https://github.com/NixOS/nixpkgs/issues/122130#issuecomment-1568815007
# It's unclear if these are strictly necessary with the downstream kernel,
# but let's leave them in to keep working with mainline.
boot.initrd.availableKernelModules = [ "uas" "pcie-brcmstb" "reset-raspberrypi" ];
networking.hostName = "creep";
networking.domain = "mou.fo";
networking.wireless.enable = true;
networking.wireless.networks = {
"Girls Gone Wireless".psk = "Paddlepops103!";
"Cali's internet".psk = "calibanthetempest2019";
};
time.timeZone = "Australia/Sydney";
users.users.joe = {
isNormalUser = true;
description = "Joe Mou";
extraGroups = [ "wheel" ];
openssh.authorizedKeys.keys = [
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky"
];
};
environment.systemPackages = with pkgs; [
dig
file
gitFull
libraspberrypi
psmisc
tmux
tree
];
programs.vim.defaultEditor = true;
programs.nano.enable = false;
services.openssh.enable = true;
systemd.services.reverse-ssh = {
description = "SSH reverse tunnel";
wantedBy = [ "multi-user.target" ];
after = [ "network-online.target" ];
serviceConfig = {
RestartSec = 60;
Restart = "always";
};
script = ''
${pkgs.openssh}/bin/ssh \
-o ServerAliveInterval=60 -o ExitOnForwardFailure=yes \
-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no \
-i /etc/ssh/ssh_host_ed25519_key \
-N -R 19422:localhost:22 joe@popfresh.mou.fo
'';
};
systemd.services.dyndns = {
description = "Dynamic DNS update";
after = [ "network-online.target" ];
serviceConfig = {
Type = "oneshot";
TimeoutStartSec = "60s";
};
script = ''
${pkgs.curl}/bin/curl -fsS https://dyn.dns.he.net/nic/update -d hostname=creep.he.mou.fo -d password=FriE83Y4HPWmwdYn
'';
};
systemd.timers.dyndns = {
wantedBy = [ "multi-user.target" ];
timerConfig = {
OnStartupSec = "10";
OnUnitActiveSec = "5min";
};
};
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. It's perfectly fine and recommended to leave
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system.stateVersion = "23.11"; # Did you read the comment?
}
|