diff --git a/flake.lock b/flake.lock
index fd55397..7b497f1 100644
--- a/flake.lock
+++ b/flake.lock
@@ -108,7 +108,7 @@
},
"locked": {
"lastModified": 1745744468,
- "narHash": "sha256-S1vibZhzfZrZbjXCJIjzCXf4Gx/yHfPzGCzOJ9m0kWY=",
+ "narHash": "sha256-iM+uxKk3eaSr2WHqhBd+M1MQvEMLf0VIfs0Y8yYdC9E=",
"ref": "refs/heads/master",
"rev": "43939110959a719b0b346780e8f0d0c028320180",
"revCount": 1658,
@@ -567,11 +567,11 @@
"nixpkgs": "nixpkgs_6"
},
"locked": {
- "lastModified": 1746413188,
- "narHash": "sha256-i6BoiQP0PasExESQHszC0reQHfO6D4aI2GzOwZMOI20=",
+ "lastModified": 1746585355,
+ "narHash": "sha256-p+3fK8HEYC+0q4gPKSE4OSRxqt5H/tWZkB9wF7aaWOY=",
"owner": "nix-community",
"repo": "home-manager",
- "rev": "8a318641ac13d3bc0a53651feaee9560f9b2d89a",
+ "rev": "35535345be0be7dbae2e9b787c6cf790f8c893d5",
"type": "github"
},
"original": {
@@ -1035,13 +1035,29 @@
"type": "github"
}
},
+ "nixpkgs-DraupnirPkg": {
+ "locked": {
+ "lastModified": 1745024039,
+ "narHash": "sha256-6JGV5ki+kpUmbeYn/S4ywzY1UMo/83DnmJDBlulv5aM=",
+ "owner": "r-ryantm",
+ "repo": "nixpkgs",
+ "rev": "bc630c0863d93a44c60993a95ac71995849c8530",
+ "type": "github"
+ },
+ "original": {
+ "owner": "r-ryantm",
+ "ref": "auto-update/draupnir",
+ "repo": "nixpkgs",
+ "type": "github"
+ }
+ },
"nixpkgs-RoryNix": {
"locked": {
- "lastModified": 1746523602,
- "narHash": "sha256-wEJAnkNMUn0fWKFZ3M2PE0KCz/v2pP7p4Zev6YQYawg=",
+ "lastModified": 1746617143,
+ "narHash": "sha256-0NzKGiEH4lAD0Fn+TWNz0Lqo5sJLkIdTVtDWsgmKzuM=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "28fe7e08afe73bafcbe6ceacd831662ac142182b",
+ "rev": "fe965d2c054ce6283f857d57d9ba4e15f25bae22",
"type": "github"
},
"original": {
@@ -1069,11 +1085,11 @@
},
"nixpkgs-master": {
"locked": {
- "lastModified": 1746523602,
- "narHash": "sha256-wEJAnkNMUn0fWKFZ3M2PE0KCz/v2pP7p4Zev6YQYawg=",
+ "lastModified": 1746617143,
+ "narHash": "sha256-0NzKGiEH4lAD0Fn+TWNz0Lqo5sJLkIdTVtDWsgmKzuM=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "28fe7e08afe73bafcbe6ceacd831662ac142182b",
+ "rev": "fe965d2c054ce6283f857d57d9ba4e15f25bae22",
"type": "github"
},
"original": {
@@ -1117,11 +1133,11 @@
},
"nixpkgs-stable_3": {
"locked": {
- "lastModified": 1746422338,
- "narHash": "sha256-NTtKOTLQv6dPfRe00OGSywg37A1FYqldS6xiNmqBUYc=",
+ "lastModified": 1746557022,
+ "narHash": "sha256-QkNoyEf6TbaTW5UZYX0OkwIJ/ZMeKSSoOMnSDPQuol0=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "5b35d248e9206c1f3baf8de6a7683fee126364aa",
+ "rev": "1d3aeb5a193b9ff13f63f4d9cc169fb88129f860",
"type": "github"
},
"original": {
@@ -1245,11 +1261,11 @@
},
"nixpkgs_8": {
"locked": {
- "lastModified": 1746328495,
- "narHash": "sha256-uKCfuDs7ZM3QpCE/jnfubTg459CnKnJG/LwqEVEdEiw=",
+ "lastModified": 1746461020,
+ "narHash": "sha256-7+pG1I9jvxNlmln4YgnlW4o+w0TZX24k688mibiFDUE=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "979daf34c8cacebcd917d540070b52a3c2b9b16e",
+ "rev": "3730d8a308f94996a9ba7c7138ede69c1b9ac4ae",
"type": "github"
},
"original": {
@@ -1281,7 +1297,7 @@
},
"locked": {
"lastModified": 1737779835,
- "narHash": "sha256-iZ/kQ/XFqIx053AuSHhCwu3HA8627ognYiJl/LRNpD0=",
+ "narHash": "sha256-TY7cnYqhgxIXZCltcFxYuKQ6Hpt3gouuYn0rj9URsp4=",
"ref": "refs/heads/master",
"rev": "11cc65efa2909bdc7e3e978bf1f56f6d141bf82a",
"revCount": 11,
@@ -1350,12 +1366,14 @@
"nhekoSrc": "nhekoSrc",
"nixpkgs": "nixpkgs_8",
"nixpkgs-Draupnir": "nixpkgs-Draupnir",
+ "nixpkgs-DraupnirPkg": "nixpkgs-DraupnirPkg",
"nixpkgs-RoryNix": "nixpkgs-RoryNix",
"nixpkgs-keydb": "nixpkgs-keydb",
"nixpkgs-master": "nixpkgs-master",
"nixpkgs-stable": "nixpkgs-stable_3",
"ooye": "ooye",
- "sops-nix": "sops-nix"
+ "sops-nix": "sops-nix",
+ "synapseHttpAntispamSrc": "synapseHttpAntispamSrc"
}
},
"rust-analyzer-src": {
@@ -1410,6 +1428,22 @@
"type": "github"
}
},
+ "synapseHttpAntispamSrc": {
+ "flake": false,
+ "locked": {
+ "lastModified": 1746616438,
+ "narHash": "sha256-8tZ+jNm90UCIGccm0GHVs98//8o581lP43rJNSsISEY=",
+ "owner": "TheArcaneBrony",
+ "repo": "synapse-http-antispam",
+ "rev": "6fbe551c7d5c47d1779bed7ab15e5020a0573e69",
+ "type": "github"
+ },
+ "original": {
+ "owner": "TheArcaneBrony",
+ "repo": "synapse-http-antispam",
+ "type": "github"
+ }
+ },
"systems": {
"locked": {
"lastModified": 1681028828,
diff --git a/flake.nix b/flake.nix
index e71e348..7a43916 100755
--- a/flake.nix
+++ b/flake.nix
@@ -33,6 +33,7 @@
# Draupnir module/package
nixpkgs-Draupnir.url = "github:TheArcaneBrony/nixpkgs/module/draupnir";
+ nixpkgs-DraupnirPkg.url = "github:r-ryantm/nixpkgs/auto-update/draupnir";
nixpkgs-keydb.url = "github:NixOS/nixpkgs?rev=e0464e47880a69896f0fb1810f00e0de469f770a";
#MatrixContentFilter.url = "git+file:/home/Rory/git/matrix/MatrixContentFilter?submodules=1";
@@ -70,6 +71,10 @@
};
# Packages built from git
+ synapseHttpAntispamSrc = {
+ url = "github:TheArcaneBrony/synapse-http-antispam";
+ flake = false;
+ };
nhekoSrc = {
url = "github:Nheko-reborn/nheko/master";
flake = false;
@@ -143,8 +148,13 @@
nixpkgs.overlays = [
(final: prev: {
matrix-synapse-unwrapped = inputs.nixpkgs-master.legacyPackages.${pkgs.stdenv.hostPlatform.system}.matrix-synapse-unwrapped;
- draupnir = inputs.nixpkgs-master.legacyPackages.${pkgs.stdenv.hostPlatform.system}.draupnir;
+ #draupnir = inputs.nixpkgs-master.legacyPackages.${pkgs.stdenv.hostPlatform.system}.draupnir;
+ draupnir = inputs.nixpkgs-DraupnirPkg.legacyPackages.${pkgs.stdenv.hostPlatform.system}.draupnir;
keydb = inputs.nixpkgs-keydb.legacyPackages.${pkgs.stdenv.hostPlatform.system}.keydb;
+ matrix-synapse-plugins.synapse-http-antispam = prev.matrix-synapse-plugins.synapse-http-antispam.overrideAttrs (oldAttrs: {
+ src = inputs.synapseHttpAntispamSrc;
+ version = inputs.synapseHttpAntispamSrc.rev;
+ });
})
];
}
diff --git a/host/Rory-ovh/configuration.nix b/host/Rory-ovh/configuration.nix
index 81a824d..f457603 100755
--- a/host/Rory-ovh/configuration.nix
+++ b/host/Rory-ovh/configuration.nix
@@ -32,14 +32,14 @@
boot.loader.grub.devices = lib.mkForce [ "nodev" ];
networking = {
hostName = "Rory-ovh";
- interfaces.enp98s0f0.ipv4.addresses = [
- {
- address = "51.210.113.110";
- prefixLength = 24;
- }
- ];
- defaultGateway.interface = "enp98s0f0";
- defaultGateway.address = lib.mkForce "51.210.113.254";
+ #interfaces.enp98s0f0.ipv4.addresses = [
+ # {
+ # address = "51.210.113.110";
+ # prefixLength = 24;
+ # }
+ #];
+ #defaultGateway.interface = "enp98s0f0";
+ #defaultGateway.address = "51.210.113.254";
nat = {
enable = true;
internalInterfaces = [
@@ -54,6 +54,16 @@
firewall.enable = lib.mkForce true;
};
+ systemd.network = {
+ enable = true;
+ networks.enp98s0f0 = {
+ name = "enp98s0f0";
+ DHCP = "no";
+ gateway = [ "51.210.113.254" ];
+ address = [ "51.210.113.110" ];
+ };
+ };
+
monitoring = {
monitorAll = true;
localPrometheus = true;
diff --git a/host/Rory-ovh/services/email/autoconfig.nix b/host/Rory-ovh/services/email/autoconfig.nix
index d258046..5f3bce2 100644
--- a/host/Rory-ovh/services/email/autoconfig.nix
+++ b/host/Rory-ovh/services/email/autoconfig.nix
@@ -1,7 +1,7 @@
-{ ... }:
+{ config, ... }:
{
services.go-autoconfig = {
- enable = true;
+ enable = !config.virtualisation.isVmVariant;
settings = {
service_addr = ":1323";
domain = "autoconfig.rory.gay";
diff --git a/host/Rory-ovh/services/email/maddy.nix b/host/Rory-ovh/services/email/maddy.nix
index 7dbf004..548cb1a 100644
--- a/host/Rory-ovh/services/email/maddy.nix
+++ b/host/Rory-ovh/services/email/maddy.nix
@@ -1,68 +1,71 @@
{
+ lib,
pkgs,
options,
config,
...
}:
{
- services.maddy = {
- enable = true;
- primaryDomain = "rory.gay";
- hostname = "mail.rory.gay";
- ensureAccounts = [
- "root@rory.gay"
- ];
- ensureCredentials = {
- "root@rory.gay".passwordFile = "/var/lib/maddy/passwd/root";
- };
- config = builtins.readFile ./maddy.conf;
- # builtins.replaceStrings
- # [
- # "imap tcp://0.0.0.0:143"
- # "submission tcp://0.0.0.0:587"
- # "entry postmaster postmaster@$(primary_domain)"
- # ]
- # [
- # "imap tls://0.0.0.0:993 tcp://0.0.0.0:143"
- # "submission tls://0.0.0.0:465 tcp://0.0.0.0:587"
- # "entry postmaster root@$(primary_domain)"
- # ]
- # options.services.maddy.config.default;
-
- tls = {
- loader = "file";
- certificates = [
- {
-# certPath = "/var/lib/acme/mail.rory.gay/fullchain.pem";
-# keyPath = "/var/lib/acme/mail.rory.gay/key.pem";
- certPath = "/run/credentials/maddy.service/acme-fullchain.pem";
- keyPath = "/run/credentials/maddy.service/acme-key.pem";
- }
+ config = lib.mkIf (!config.virtualisation.isVmVariant) {
+ services.maddy = {
+ enable = true;
+ primaryDomain = "rory.gay";
+ hostname = "mail.rory.gay";
+ ensureAccounts = [
+ "root@rory.gay"
];
+ ensureCredentials = {
+ "root@rory.gay".passwordFile = "/var/lib/maddy/passwd/root";
+ };
+ config = builtins.readFile ./maddy.conf;
+ # builtins.replaceStrings
+ # [
+ # "imap tcp://0.0.0.0:143"
+ # "submission tcp://0.0.0.0:587"
+ # "entry postmaster postmaster@$(primary_domain)"
+ # ]
+ # [
+ # "imap tls://0.0.0.0:993 tcp://0.0.0.0:143"
+ # "submission tls://0.0.0.0:465 tcp://0.0.0.0:587"
+ # "entry postmaster root@$(primary_domain)"
+ # ]
+ # options.services.maddy.config.default;
+
+ tls = {
+ loader = "file";
+ certificates = [
+ {
+ # certPath = "/var/lib/acme/mail.rory.gay/fullchain.pem";
+ # keyPath = "/var/lib/acme/mail.rory.gay/key.pem";
+ certPath = "/run/credentials/maddy.service/acme-fullchain.pem";
+ keyPath = "/run/credentials/maddy.service/acme-key.pem";
+ }
+ ];
+ };
};
- };
- networking.firewall.allowedTCPPorts = [
- 25
- 143
- 465
- 587
- 993
- ];
+ networking.firewall.allowedTCPPorts = [
+ 25
+ 143
+ 465
+ 587
+ 993
+ ];
- users.users.maddy.extraGroups = [ "nginx" ];
+ users.users.maddy.extraGroups = [ "nginx" ];
- fileSystems."/var/lib/maddy" = {
- depends = [ "/" ];
- device = "/data/maddy";
- fsType = "none";
- options = [ "bind" ];
- };
-
- systemd.services.maddy.serviceConfig = {
- LoadCredential = [
- "acme-fullchain.pem:/var/lib/acme/rory.gay/fullchain.pem"
- "acme-key.pem:/var/lib/acme/rory.gay/key.pem"
- ];
+ fileSystems."/var/lib/maddy" = {
+ depends = [ "/" ];
+ device = "/data/maddy";
+ fsType = "none";
+ options = [ "bind" ];
+ };
+
+ systemd.services.maddy.serviceConfig = {
+ LoadCredential = [
+ "acme-fullchain.pem:/var/lib/acme/rory.gay/fullchain.pem"
+ "acme-key.pem:/var/lib/acme/rory.gay/key.pem"
+ ];
+ };
};
}
diff --git a/host/Rory-ovh/services/email/nginx.nix b/host/Rory-ovh/services/email/nginx.nix
index 812993a..5b04612 100644
--- a/host/Rory-ovh/services/email/nginx.nix
+++ b/host/Rory-ovh/services/email/nginx.nix
@@ -2,8 +2,8 @@
{
services.nginx.virtualHosts = {
"mta-sts.rory.gay" = {
- enableACME = true;
- forceSSL = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ forceSSL = !config.virtualisation.isVmVariant;
locations = {
"/.well-known/mta-sts.txt" = {
# age 604800
@@ -17,15 +17,15 @@
};
};
"mail.rory.gay" = {
- enableACME = true;
- forceSSL = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ forceSSL = !config.virtualisation.isVmVariant;
locations = {
"/".return = "200 'OK'";
};
};
"autoconfig.rory.gay" = {
- enableACME = true;
- forceSSL = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ forceSSL = !config.virtualisation.isVmVariant;
locations."/".proxyPass = "http://localhost:1323";
};
};
diff --git a/host/Rory-ovh/services/matrix/synapse/synapse-main.nix b/host/Rory-ovh/services/matrix/synapse/synapse-main.nix
index c6e5217..f4ca044 100755
--- a/host/Rory-ovh/services/matrix/synapse/synapse-main.nix
+++ b/host/Rory-ovh/services/matrix/synapse/synapse-main.nix
@@ -1,4 +1,4 @@
-{ pkgs, ... }:
+{ config, pkgs, ... }:
{
# Worker plumbing examples: https://github.com/element-hq/synapse/blob/master/docker/configure_workers_and_start.py
@@ -11,21 +11,21 @@
nginxVirtualHostName = "matrix.rory.gay";
enableWorkers = true;
- federationSenders = 16; # 16
- pushers = 1;
- mediaRepoWorkers = 2; # 4
- clientReaders = 2; # 4
- syncWorkers = 2; # 4
+ federationSenders = if config.virtualisation.isVmVariant then 0 else 16; # 16
+ pushers = if config.virtualisation.isVmVariant then 1 else 1;
+ mediaRepoWorkers = if config.virtualisation.isVmVariant then 1 else 2; # 4
+ clientReaders = if config.virtualisation.isVmVariant then 2 else 2; # 4
+ syncWorkers = if config.virtualisation.isVmVariant then 2 else 2; # 4
#authWorkers = 0;
- eventCreators = 16;
+ eventCreators = if config.virtualisation.isVmVariant then 2 else 16;
- federationReaders = 8; # 8
- federationInboundWorkers = 16; # 8
+ federationReaders = if config.virtualisation.isVmVariant then 0 else 8; # 8
+ federationInboundWorkers = if config.virtualisation.isVmVariant then 0 else 16; # 8
- enableAppserviceWorker = true;
- enableBackgroundWorker = true;
- enableUserDirWorker = true;
+ enableAppserviceWorker = if config.virtualisation.isVmVariant then true else true;
+ enableBackgroundWorker = if config.virtualisation.isVmVariant then true else true;
+ enableUserDirWorker = if config.virtualisation.isVmVariant then true else true;
accountDataStreamWriters = 1;
eventStreamWriters = 2; # 8
@@ -35,6 +35,10 @@
toDeviceStreamWriters = 1;
typingStreamWriters = 1;
+ plugins = with pkgs.matrix-synapse-plugins; [
+ synapse-http-antispam
+ ];
+
#untested:
#sharedStreamWriters = 1;
@@ -223,4 +227,46 @@
};
systemd.tmpfiles.rules = [ "D /run/redis-matrix-synapse 0755 matrix-synapse matrix-synapse" ];
+
+ virtualisation.vmVariant = {
+ systemd.tmpfiles.rules = [ "D /run/secrets 0755 nobody nobody" ];
+ systemd.services."matrix-synapse-generate-token" = {
+ # generate /data/secrets/synapse-shared-secret
+ description = "Generate Synapse shared secret";
+ wantedBy = [ "multi-user.target" ];
+ after = [ "network.target" ];
+ before = [ "matrix-synapse.service" ];
+ script = ''
+ set -e -x -o pipefail
+ echo "Starting key generation"
+ if [ ! -f "/data/secrets/synapse-shared-secret" ]
+ then
+ echo "Generating new key"
+ ${pkgs.openssl}/bin/openssl rand -base64 32 > /data/secrets/synapse-shared-secret
+ echo "Key generation complete"
+ else
+ echo "Not generating key, key exists"
+ fi
+ echo "Script complete"
+ '';
+ };
+ systemd.services."matrix-synapse-postgres-init" = {
+ description = "Generate synapse postgres user";
+ wantedBy = [ "multi-user.target" ];
+ after = [ "network.target" "postgresql.service" ];
+ before = [ "matrix-synapse.service" ];
+
+ script = ''
+ set -e -x -o pipefail
+ ${pkgs.postgresql}/bin/createuser ${config.services.matrix-synapse.settings.database.args.user} || true
+ ${pkgs.postgresql}/bin/createdb --encoding=UTF8 --locale=C --template=template0 --owner=${config.services.matrix-synapse.settings.database.args.user} ${config.services.matrix-synapse.settings.database.args.database} || true
+ '';
+ serviceConfig = {
+ User = "postgres";
+ Group = "postgres";
+ WorkingDirectory = config.services.postgresql.dataDir;
+ RemainAfterExit = true;
+ };
+ };
+ };
}
diff --git a/host/Rory-ovh/services/nginx/nginx.nix b/host/Rory-ovh/services/nginx/nginx.nix
index 3b58796..453816f 100755
--- a/host/Rory-ovh/services/nginx/nginx.nix
+++ b/host/Rory-ovh/services/nginx/nginx.nix
@@ -1,7 +1,7 @@
{ config, pkgs, ... }:
let
serveDir = config: {
- enableACME = if config ? ssl then config.ssl else true;
+ enableACME = if config ? ssl then config.ssl else !config.virtualisation.isVmVariant;
addSSL = if config ? ssl then config.ssl else true;
root = if config ? path then config.path else builtins.throw "path is required";
locations = {
@@ -60,22 +60,22 @@ in
# "sentry.thearcanebrony.net" = import ./thearcanebrony.net/sentry.nix;
# "search.thearcanebrony.net" = import ./thearcanebrony.net/search.nix;
#
- "rory.gay" = import ./rory.gay/root.nix;
+ "rory.gay" = import ./rory.gay/root.nix { inherit config; };
# "lfs.rory.gay" = serveDir { path = "/data/nginx/html_lfs"; };
#
# "awooradio.thearcanebrony.net" = import ./thearcanebrony.net/awooradio.nix;
- "cgit.rory.gay" = import ./rory.gay/cgit.nix;
+ "cgit.rory.gay" = import ./rory.gay/cgit.nix { inherit config; };
# #"jitsi.rory.gay" = import ./rory.gay/jitsi.nix;
#
# #matrix...
# "conduit.rory.gay" = import ./rory.gay/conduit.nix;
- "matrix.rory.gay" = import ./rory.gay/matrix.nix;
- "stream.rory.gay" = import ./rory.gay/stream.nix;
+ "matrix.rory.gay" = import ./rory.gay/matrix.nix { inherit config; };
+ "stream.rory.gay" = import ./rory.gay/stream.nix { inherit config; };
# "pcpoc.rory.gay" = import ./rory.gay/pcpoc.nix;
# "matrixunittests.rory.gay" = import ./rory.gay/matrixunittests.nix;
# "conduit.matrixunittests.rory.gay" = import ./rory.gay/conduit.matrixunittests.nix;
- "mru.rory.gay" = import ./rory.gay/mru.nix;
- "ec.rory.gay" = import ./rory.gay/ec.nix;
+ "mru.rory.gay" = import ./rory.gay/mru.nix { inherit config; };
+ "ec.rory.gay" = import ./rory.gay/ec.nix { inherit config; };
};
};
};
diff --git a/host/Rory-ovh/services/nginx/rory.gay/cgit.nix b/host/Rory-ovh/services/nginx/rory.gay/cgit.nix
index 35fc85b..7b49a42 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/cgit.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/cgit.nix
@@ -1,7 +1,8 @@
+{ config }:
{
+ enableACME = !config.virtualisation.isVmVariant;
+ addSSL = !config.virtualisation.isVmVariant;
root = "/data/git";
- enableACME = true;
- addSSL = true;
extraConfig = ''
autoindex on;
more_set_headers 'Access-Control-Allow-Origin: *';
diff --git a/host/Rory-ovh/services/nginx/rory.gay/conduit.matrixunittests.nix b/host/Rory-ovh/services/nginx/rory.gay/conduit.matrixunittests.nix
index 9503747..231d5e3 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/conduit.matrixunittests.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/conduit.matrixunittests.nix
@@ -1,6 +1,7 @@
+{ config }:
{
- enableACME = true;
- addSSL = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ addSSL = !config.virtualisation.isVmVariant;
http3 = true;
http3_hq = true;
kTLS = true;
diff --git a/host/Rory-ovh/services/nginx/rory.gay/ec.nix b/host/Rory-ovh/services/nginx/rory.gay/ec.nix
index 0985503..c50b1f9 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/ec.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/ec.nix
@@ -1,7 +1,7 @@
+{ config }:
{
- enableACME = true;
- addSSL = true;
- kTLS = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ addSSL = !config.virtualisation.isVmVariant;
root = "/data/nginx/html_ec";
reuseport = true;
extraConfig = ''
diff --git a/host/Rory-ovh/services/nginx/rory.gay/matrix-bak.nix b/host/Rory-ovh/services/nginx/rory.gay/matrix-bak.nix
index 5d44454..1af3669 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/matrix-bak.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/matrix-bak.nix
@@ -1,6 +1,7 @@
+{ config }:
{
- enableACME = true;
- addSSL = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ addSSL = !config.virtualisation.isVmVariant;
locations."/_matrix" = {
proxyPass = "http://192.168.1.5:8008";
extraConfig = ''
diff --git a/host/Rory-ovh/services/nginx/rory.gay/matrix.nix b/host/Rory-ovh/services/nginx/rory.gay/matrix.nix
index d48f4ca..45a507f 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/matrix.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/matrix.nix
@@ -1,6 +1,7 @@
+{ config }:
{
- enableACME = true;
- addSSL = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ addSSL = !config.virtualisation.isVmVariant;
locations."/" = {
#proxyPass = "http://127.0.0.1:9001";
proxyPass = "http://localhost:8008";
diff --git a/host/Rory-ovh/services/nginx/rory.gay/matrixunittests.nix b/host/Rory-ovh/services/nginx/rory.gay/matrixunittests.nix
index edb1704..f23f0dd 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/matrixunittests.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/matrixunittests.nix
@@ -1,9 +1,10 @@
+{ config }:
{
- enableACME = true;
- addSSL = true;
- http3 = true;
- http3_hq = true;
- kTLS = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ addSSL = !config.virtualisation.isVmVariant;
+ http3 = !config.virtualisation.isVmVariant;
+ http3_hq = !config.virtualisation.isVmVariant;
+ kTLS = !config.virtualisation.isVmVariant;
extraConfig = ''
brotli off;
'';
diff --git a/host/Rory-ovh/services/nginx/rory.gay/mru.nix b/host/Rory-ovh/services/nginx/rory.gay/mru.nix
index d1e1cd7..6e685de 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/mru.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/mru.nix
@@ -1,10 +1,11 @@
+{ config }:
{
- enableACME = true;
- addSSL = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ addSSL = !config.virtualisation.isVmVariant;
# quic = true;
- http3 = true;
- http3_hq = true;
- kTLS = true;
+ http3 = !config.virtualisation.isVmVariant;
+ http3_hq = !config.virtualisation.isVmVariant;
+ kTLS = !config.virtualisation.isVmVariant;
root = "/data/nginx/html_mru";
# reuseport = true;
extraConfig = ''
diff --git a/host/Rory-ovh/services/nginx/rory.gay/root.nix b/host/Rory-ovh/services/nginx/rory.gay/root.nix
index 11d06c0..a7720ec 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/root.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/root.nix
@@ -1,7 +1,8 @@
+{ config }:
{
+ enableACME = !config.virtualisation.isVmVariant;
+ addSSL = !config.virtualisation.isVmVariant;
root = "/data/nginx/html_rory_gay";
- enableACME = true;
- addSSL = true;
extraConfig = ''autoindex on;'';
locations."= /.well-known/matrix/server".extraConfig = ''
diff --git a/host/Rory-ovh/services/nginx/rory.gay/stream.nix b/host/Rory-ovh/services/nginx/rory.gay/stream.nix
index f382cc9..caed22f 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/stream.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/stream.nix
@@ -1,6 +1,7 @@
+{ config }:
{
- enableACME = true;
- addSSL = true;
+ enableACME = !config.virtualisation.isVmVariant;
+ addSSL = !config.virtualisation.isVmVariant;
locations = {
"/" = {
proxyPass = "http://localhost:1934";
diff --git a/host/Rory-ovh/services/nginx/rory.gay/wad-api.nix b/host/Rory-ovh/services/nginx/rory.gay/wad-api.nix
index 65e9bdb..ac07547 100755
--- a/host/Rory-ovh/services/nginx/rory.gay/wad-api.nix
+++ b/host/Rory-ovh/services/nginx/rory.gay/wad-api.nix
@@ -1,5 +1,5 @@
{
- enableACME = true;
+ enableACME = !config.virtualisation.isVmVariant;
addSSL = true;
locations = {
"/" = {
diff --git a/host/Rory-ovh/services/nginx/thearcanebrony.net/awooradio.nix b/host/Rory-ovh/services/nginx/thearcanebrony.net/awooradio.nix
index f13cb0c..c0ca8b0 100755
--- a/host/Rory-ovh/services/nginx/thearcanebrony.net/awooradio.nix
+++ b/host/Rory-ovh/services/nginx/thearcanebrony.net/awooradio.nix
@@ -1,5 +1,6 @@
+{ config }:
{
- enableACME = true;
+ enableACME = !config.virtualisation.isVmVariant;
addSSL = true;
locations = {
"/" = {
diff --git a/host/Rory-ovh/services/nginx/thearcanebrony.net/root.nix b/host/Rory-ovh/services/nginx/thearcanebrony.net/root.nix
index 86dddac..59cba43 100755
--- a/host/Rory-ovh/services/nginx/thearcanebrony.net/root.nix
+++ b/host/Rory-ovh/services/nginx/thearcanebrony.net/root.nix
@@ -1,5 +1,6 @@
+{ config }:
{
- enableACME = true;
+ enableACME = !config.virtualisation.isVmVariant;
addSSL = true;
root = "/data/nginx/html_thearcanebrony";
extraConfig = ''autoindex on;'';
diff --git a/host/Rory-ovh/services/nginx/thearcanebrony.net/search.nix b/host/Rory-ovh/services/nginx/thearcanebrony.net/search.nix
index cd655d8..cfb4e1c 100755
--- a/host/Rory-ovh/services/nginx/thearcanebrony.net/search.nix
+++ b/host/Rory-ovh/services/nginx/thearcanebrony.net/search.nix
@@ -1,5 +1,6 @@
+{ config }:
{
- enableACME = true;
+ enableACME = !config.virtualisation.isVmVariant;
addSSL = true;
locations = {
"/" = {
diff --git a/host/Rory-ovh/services/nginx/thearcanebrony.net/sentry.nix b/host/Rory-ovh/services/nginx/thearcanebrony.net/sentry.nix
index f496190..8cd0826 100755
--- a/host/Rory-ovh/services/nginx/thearcanebrony.net/sentry.nix
+++ b/host/Rory-ovh/services/nginx/thearcanebrony.net/sentry.nix
@@ -1,5 +1,6 @@
+{ config }:
{
- enableACME = true;
+ enableACME = !config.virtualisation.isVmVariant;
addSSL = true;
locations = {
"/" = {
diff --git a/host/Rory-ovh/services/postgres.nix b/host/Rory-ovh/services/postgres.nix
index 50dffa1..10d1cb7 100755
--- a/host/Rory-ovh/services/postgres.nix
+++ b/host/Rory-ovh/services/postgres.nix
@@ -1,4 +1,4 @@
-{ pkgs, ... }:
+{ config, pkgs, ... }:
{
systemd.tmpfiles.rules = [ "d /data/dedicated/postgres 0750 postgres postgres" ];
@@ -27,11 +27,11 @@
max_connections = 2500;
superuser_reserved_connections = 3;
- shared_buffers = "64GB";
- work_mem = "32GB";
- maintenance_work_mem = "8GB";
+ shared_buffers = if config.virtualisation.isVmVariant then "128MB" else "64GB";
+ work_mem = if config.virtualisation.isVmVariant then "64MB" else "32GB";
+ maintenance_work_mem = if config.virtualisation.isVmVariant then "512MB" else "8GB";
huge_pages = "try";
- effective_cache_size = "64GB"; # was 22
+ effective_cache_size = if config.virtualisation.isVmVariant then "1GB" else "64GB"; # was 22
effective_io_concurrency = 100;
random_page_cost = 1.1;
diff --git a/modules/base-server.nix b/modules/base-server.nix
index 0b05a9d..ccf4a77 100755
--- a/modules/base-server.nix
+++ b/modules/base-server.nix
@@ -51,18 +51,14 @@
networking = {
hostName = lib.mkDefault "Rory-nix-base-server";
networkmanager.enable = false;
- useNetworkd = true;
wireless.enable = false;
enableIPv6 = false;
firewall = {
enable = false;
- # allowedTCPPorts = [ ... ];
- # allowedUDPPorts = [ ... ];
allowedTCPPorts = [ 22 ];
};
useDHCP = false;
- # nameservers = [ "1.1.1.1" "1.0.0.1" "8.8.8.8" "8.4.4.8" ];
nameservers = [
"10.10.0.4"
"10.10.0.5"
@@ -71,7 +67,7 @@
"8.8.8.8"
"8.4.4.8"
];
- defaultGateway = "192.168.1.1";
+ defaultGateway = lib.mkDefault "192.168.1.1";
};
hardware.pulseaudio.enable = false;
@@ -81,51 +77,6 @@
hardware.enableRedistributableFirmware = false;
services = {
- # prometheus = {
- # exporters = {
- # node = {
- # enable = true;
- # port = 9100;
- # enabledCollectors = [
- # #"logind" #too slow
- # "systemd"
- # "processes"
- # "interrupts"
- # # Testing:
- # "buddyinfo"
- # "cgroups"
- # "ksmd"
- # "lnstat"
- # "mountstats"
- # "network_route"
- # #"perf" # requires sysctl change
- # "qdisc"
- # "sysctl"
- # "softirqs"
- # "tcpstat"
- # ];
- # disabledCollectors = [
- # "textfile"
- # "xfs"
- # "zfs"
- # "selinux"
- # "cpufreq"
- # "btrfs"
- # "powersupplyclass"
- # "mdadm"
- # "tapestats"
- # "fibrechannel"
- # "cpu_vulnerabilities"
- # "watchdog"
- # "thermal_zone"
- # "logind"
- # "nfs"
- # "nfsd"
- # "infiniband"
- # ];
- # };
- # };
- # };
promtail = {
enable = true;
configuration = {
diff --git a/modules/base.nix b/modules/base.nix
index 6119cdf..09f638a 100755
--- a/modules/base.nix
+++ b/modules/base.nix
@@ -65,8 +65,6 @@
hostName = lib.mkDefault "Rory-nix-base";
firewall = {
enable = false;
- # allowedTCPPorts = [ ... ];
- # allowedUDPPorts = [ ... ];
};
nameservers = lib.mkDefault [
"1.1.1.1"
@@ -175,13 +173,24 @@
virtualisation.vmVariant = {
services.getty.autologinUser = "root";
virtualisation = {
- memorySize = 4096;
- cores = 2;
+ memorySize = 8192;
+ cores = 6;
msize = 1*1024*1024;
bios = pkgs.qboot;
};
monitoring.monitorAll = lib.mkForce false;
services.promtail.enable = lib.mkForce false;
+ networking.useDHCP = lib.mkOverride 51 true;
+
+ environment.systemPackages = with pkgs; [
+ qutebrowser
+ gomuks
+ kdePackages.konqueror
+ weston
+ kitty
+ waybar
+ sway
+ ];
};
}
diff --git a/modules/users/Rory.nix b/modules/users/Rory.nix
index 545d2fa..56a30c3 100755
--- a/modules/users/Rory.nix
+++ b/modules/users/Rory.nix
@@ -48,7 +48,6 @@
mutableUsers = false;
users.Rory.password = "password";
};
- networking.interfaces.enp34s0 = lib.mkForce { };
};
home-manager.users.Rory = {
|