blob: 7b340549f5f2d7fa77327efb730475217edf175e (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
|
{ config, pkgs, ... }:
{
imports = [
./acme.nix
./dns.nix
./dyndns.nix
./email.nix
./git.nix
./hardware-configuration.nix
./home-assistant.nix
./media.nix
./oidc.nix
./privacy-frontends.nix
./syncthing.nix
./system.nix
./usenet.nix
./wireguard.nix
];
nix.settings.experimental-features = [ "nix-command" "flakes" ];
security.sudo.wheelNeedsPassword = false;
users.users.joe = {
isNormalUser = true;
description = "Joe Mou";
extraGroups = [ "networkmanager" "wheel" "syncthing" ];
packages = with pkgs; [
jq
sqlite-interactive
];
openssh.authorizedKeys.keys = [
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPsci2NPhPgg7T77vtcnkcv5Z9sbHAsmp9XC11WPePvL joe@Joes-Mac-mini.local"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILU1pGPkl/6A2DXrEZd5elLCJ7OCnG9QCEvaopFW8gEg joe@penguin"
];
};
nixpkgs.config.allowUnfree = true;
environment.systemPackages = with pkgs; [
dig
file
gitFull
openssl
psmisc
restic
tmux
tree
unzip
];
programs.vim = {
enable = true;
defaultEditor = true;
};
programs.nano.enable = false;
services.envfs.enable = true;
services.fstrim.enable = true;
services.openssh.enable = true;
services.sshguard = {
enable = true;
whitelist = [ "192.168.0.0/24" ];
};
services.locate = {
enable = true;
package = pkgs.plocate;
localuser = null; # silence warning
};
services.postgresql = {
enable = true;
package = pkgs.postgresql_15;
};
services.nginx = {
enable = true;
recommendedGzipSettings = true;
recommendedOptimisation = true;
recommendedProxySettings = true;
recommendedTlsSettings = true;
virtualHosts."elmo.mou.fo" = {
default = true;
enableACME = true;
forceSSL = true;
root = "/var/www";
};
};
systemd.services.duperemove = {
serviceConfig = {
Type = "simple";
CacheDirectory = "duperemove";
};
script = ''
exec ${pkgs.duperemove}/bin/duperemove -dhrq --hashfile $CACHE_DIRECTORY/hashfile /srv /var
'';
};
networking.firewall.allowedTCPPorts = [ 80 443 ];
# This value determines the NixOS release from which the default
# settings for stateful data, like file locations and database versions
# on your system were taken. It's perfectly fine and recommended to leave
# this value at the release version of the first install of this system.
# Before changing this value read the documentation for this option
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
system.stateVersion = "23.11"; # Did you read the comment?
}
|