summaryrefslogtreecommitdiff
path: root/hostnix/weebnix/configuration.nix
blob: a0166f596392295af2fd9462e379d499f1f3c920 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
{ config, pkgs, ... }:

{
  imports = [
    ./dyndns.nix
    ./hardware-configuration.nix
    ./home-assistant.nix
    ./oidc.nix
    ./privacy-frontends.nix
    ./syncthing.nix
    ./system.nix
  ];

  nix.settings.experimental-features = [ "nix-command" "flakes" ];
  nix.settings.trusted-users = [ "joe" ];

  security.sudo.wheelNeedsPassword = false;

  security.acme.acceptTerms = true;
  security.acme.defaults.email = "hostmaster@mou.fo";
  # TODO switch to production certs
  security.acme.defaults.server = "https://acme-staging-v02.api.letsencrypt.org/directory";

  users.users.joe = {
    isNormalUser = true;
    extraGroups = [ "wheel" "syncthing" ];
    openssh.authorizedKeys.keys = [
      "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHcqQDnH0LcUWFV+cd9aABfM55+72UAn1ZY5x5bHwPL4IEgT1nagbi1X3FwCJkh2rEcDsHl4FflcNfh+IyU2VyuQfRIXl7CKP040ovXmPVzgU8JiEDrrRebpZ7aHCKk+4Q6cJ8dzAI1sRogVyYrV0hLB4yeMnVexkIcsQMt5pXQ1zodlzHfW1W7OWQDbKjIyh4pv1KJ/IIjiBIt7l+OCqi7wZK4ubmxyMhmZx1xpRC5mz2/29Mpt+1VgCmxC7Hv1SG7yu+U0s4eJ3kbzFKNcZ/bCYqFxK48dT66qhS3qZFg09omumG8IbEUcx+WqM1V7WhiJYig9x5ovmMToQXTJ5uxLtcovnxO/53IgwV7INvmr8+NhD+LlkQfSjjUAW09bhVj9sKIW2bbrIxlOT8z6CQY9zGXNXi8u1oxPt3Q7d3rMxoWhWnr2l3Ok7OIkWooOK3e0NdhgIAxZKlYJAmIYaX391sGTyiuwUy96mg5JcYsLYMfkEg/Sv+2vQp8kkvB0E= joe@sparky"
    ];
  };

  environment.systemPackages = with pkgs; [
    dig
    file
    gitFull
    jq
    libraspberrypi
    sqlite-interactive
    tmux
    tree
  ];

  programs.vim.defaultEditor = true;
  programs.nano.enable = false;

  services.openssh.enable = true;

  services.nginx = {
    enable = true;
    recommendedGzipSettings = true;
    recommendedOptimisation = true;
    recommendedProxySettings = true;
    recommendedTlsSettings = true;
    # Slightly crazy setup to SNI reverse proxy HTTPS to multiple upstreams.
    # We displace ourselves onto port 8443, and send requests that are not
    # intended for us to weeber. This is done because Apache running on weeber
    # cannot SNI reverse proxy, so we put weebnix in front of weeber on IPv4.
    # TODO get rid of all this when replacing weeber or maybe consider HAProxy
    defaultSSLListenPort = 8443;
    streamConfig = ''
      map $ssl_preread_server_name $selected_upstream {
        hostnames;
        weebnix.mou.fo self;
        *.weebnix.mou.fo self;
        default weeber;
      }
      upstream self { server 127.0.0.1:8443; }
      upstream weeber { server 192.168.0.168:443; }
      server {
        listen 0.0.0.0:443;
        listen [::0]:443;
        proxy_pass $selected_upstream;
        ssl_preread on;
      }
    '';
  };

  # TODO remove upon switching to production certs
  services.oauth2_proxy.extraConfig = {
    "ssl-insecure-skip-verify" = true;
    "ssl-upstream-insecure-skip-verify" = true;
  };

  networking.firewall.allowedTCPPorts = [ 80 443 ];

  # This value determines the NixOS release from which the default
  # settings for stateful data, like file locations and database versions
  # on your system were taken. It's perfectly fine and recommended to leave
  # this value at the release version of the first install of this system.
  # Before changing this value read the documentation for this option
  # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
  system.stateVersion = "23.05"; # Did you read the comment?
}