summary refs log tree commit diff
diff options
context:
space:
mode:
authorRory& <root@rory.gay>2025-05-07 17:33:35 +0200
committerRory& <root@rory.gay>2025-05-07 17:33:35 +0200
commit7cc9f2490cba971aab524e0c3ab29f69e5a3db97 (patch)
tree8b3224616e076700a19813e76ce2b974d0c6c874
parentExpose vm variant during builds (diff)
downloadRory-Open-Architecture-7cc9f2490cba971aab524e0c3ab29f69e5a3db97.tar.xz
Support for vmvariant builds of Rory-ovh, part of synapse antispam, move to draupnir beta
-rw-r--r--flake.lock70
-rwxr-xr-xflake.nix12
-rwxr-xr-xhost/Rory-ovh/configuration.nix26
-rw-r--r--host/Rory-ovh/services/email/autoconfig.nix4
-rw-r--r--host/Rory-ovh/services/email/maddy.nix111
-rw-r--r--host/Rory-ovh/services/email/nginx.nix12
-rwxr-xr-xhost/Rory-ovh/services/matrix/synapse/synapse-main.nix70
-rwxr-xr-xhost/Rory-ovh/services/nginx/nginx.nix14
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/cgit.nix5
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/conduit.matrixunittests.nix5
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/ec.nix6
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/matrix-bak.nix5
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/matrix.nix5
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/matrixunittests.nix11
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/mru.nix11
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/root.nix5
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/stream.nix5
-rwxr-xr-xhost/Rory-ovh/services/nginx/rory.gay/wad-api.nix2
-rwxr-xr-xhost/Rory-ovh/services/nginx/thearcanebrony.net/awooradio.nix3
-rwxr-xr-xhost/Rory-ovh/services/nginx/thearcanebrony.net/root.nix3
-rwxr-xr-xhost/Rory-ovh/services/nginx/thearcanebrony.net/search.nix3
-rwxr-xr-xhost/Rory-ovh/services/nginx/thearcanebrony.net/sentry.nix3
-rwxr-xr-xhost/Rory-ovh/services/postgres.nix10
-rwxr-xr-xmodules/base-server.nix51
-rwxr-xr-xmodules/base.nix17
-rwxr-xr-xmodules/users/Rory.nix1
26 files changed, 272 insertions, 198 deletions
diff --git a/flake.lock b/flake.lock

index fd55397..7b497f1 100644 --- a/flake.lock +++ b/flake.lock
@@ -108,7 +108,7 @@ }, "locked": { "lastModified": 1745744468, - "narHash": "sha256-S1vibZhzfZrZbjXCJIjzCXf4Gx/yHfPzGCzOJ9m0kWY=", + "narHash": "sha256-iM+uxKk3eaSr2WHqhBd+M1MQvEMLf0VIfs0Y8yYdC9E=", "ref": "refs/heads/master", "rev": "43939110959a719b0b346780e8f0d0c028320180", "revCount": 1658, @@ -567,11 +567,11 @@ "nixpkgs": "nixpkgs_6" }, "locked": { - "lastModified": 1746413188, - "narHash": "sha256-i6BoiQP0PasExESQHszC0reQHfO6D4aI2GzOwZMOI20=", + "lastModified": 1746585355, + "narHash": "sha256-p+3fK8HEYC+0q4gPKSE4OSRxqt5H/tWZkB9wF7aaWOY=", "owner": "nix-community", "repo": "home-manager", - "rev": "8a318641ac13d3bc0a53651feaee9560f9b2d89a", + "rev": "35535345be0be7dbae2e9b787c6cf790f8c893d5", "type": "github" }, "original": { @@ -1035,13 +1035,29 @@ "type": "github" } }, + "nixpkgs-DraupnirPkg": { + "locked": { + "lastModified": 1745024039, + "narHash": "sha256-6JGV5ki+kpUmbeYn/S4ywzY1UMo/83DnmJDBlulv5aM=", + "owner": "r-ryantm", + "repo": "nixpkgs", + "rev": "bc630c0863d93a44c60993a95ac71995849c8530", + "type": "github" + }, + "original": { + "owner": "r-ryantm", + "ref": "auto-update/draupnir", + "repo": "nixpkgs", + "type": "github" + } + }, "nixpkgs-RoryNix": { "locked": { - "lastModified": 1746523602, - "narHash": "sha256-wEJAnkNMUn0fWKFZ3M2PE0KCz/v2pP7p4Zev6YQYawg=", + "lastModified": 1746617143, + "narHash": "sha256-0NzKGiEH4lAD0Fn+TWNz0Lqo5sJLkIdTVtDWsgmKzuM=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "28fe7e08afe73bafcbe6ceacd831662ac142182b", + "rev": "fe965d2c054ce6283f857d57d9ba4e15f25bae22", "type": "github" }, "original": { @@ -1069,11 +1085,11 @@ }, "nixpkgs-master": { "locked": { - "lastModified": 1746523602, - "narHash": "sha256-wEJAnkNMUn0fWKFZ3M2PE0KCz/v2pP7p4Zev6YQYawg=", + "lastModified": 1746617143, + "narHash": "sha256-0NzKGiEH4lAD0Fn+TWNz0Lqo5sJLkIdTVtDWsgmKzuM=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "28fe7e08afe73bafcbe6ceacd831662ac142182b", + "rev": "fe965d2c054ce6283f857d57d9ba4e15f25bae22", "type": "github" }, "original": { @@ -1117,11 +1133,11 @@ }, "nixpkgs-stable_3": { "locked": { - "lastModified": 1746422338, - "narHash": "sha256-NTtKOTLQv6dPfRe00OGSywg37A1FYqldS6xiNmqBUYc=", + "lastModified": 1746557022, + "narHash": "sha256-QkNoyEf6TbaTW5UZYX0OkwIJ/ZMeKSSoOMnSDPQuol0=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "5b35d248e9206c1f3baf8de6a7683fee126364aa", + "rev": "1d3aeb5a193b9ff13f63f4d9cc169fb88129f860", "type": "github" }, "original": { @@ -1245,11 +1261,11 @@ }, "nixpkgs_8": { "locked": { - "lastModified": 1746328495, - "narHash": "sha256-uKCfuDs7ZM3QpCE/jnfubTg459CnKnJG/LwqEVEdEiw=", + "lastModified": 1746461020, + "narHash": "sha256-7+pG1I9jvxNlmln4YgnlW4o+w0TZX24k688mibiFDUE=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "979daf34c8cacebcd917d540070b52a3c2b9b16e", + "rev": "3730d8a308f94996a9ba7c7138ede69c1b9ac4ae", "type": "github" }, "original": { @@ -1281,7 +1297,7 @@ }, "locked": { "lastModified": 1737779835, - "narHash": "sha256-iZ/kQ/XFqIx053AuSHhCwu3HA8627ognYiJl/LRNpD0=", + "narHash": "sha256-TY7cnYqhgxIXZCltcFxYuKQ6Hpt3gouuYn0rj9URsp4=", "ref": "refs/heads/master", "rev": "11cc65efa2909bdc7e3e978bf1f56f6d141bf82a", "revCount": 11, @@ -1350,12 +1366,14 @@ "nhekoSrc": "nhekoSrc", "nixpkgs": "nixpkgs_8", "nixpkgs-Draupnir": "nixpkgs-Draupnir", + "nixpkgs-DraupnirPkg": "nixpkgs-DraupnirPkg", "nixpkgs-RoryNix": "nixpkgs-RoryNix", "nixpkgs-keydb": "nixpkgs-keydb", "nixpkgs-master": "nixpkgs-master", "nixpkgs-stable": "nixpkgs-stable_3", "ooye": "ooye", - "sops-nix": "sops-nix" + "sops-nix": "sops-nix", + "synapseHttpAntispamSrc": "synapseHttpAntispamSrc" } }, "rust-analyzer-src": { @@ -1410,6 +1428,22 @@ "type": "github" } }, + "synapseHttpAntispamSrc": { + "flake": false, + "locked": { + "lastModified": 1746616438, + "narHash": "sha256-8tZ+jNm90UCIGccm0GHVs98//8o581lP43rJNSsISEY=", + "owner": "TheArcaneBrony", + "repo": "synapse-http-antispam", + "rev": "6fbe551c7d5c47d1779bed7ab15e5020a0573e69", + "type": "github" + }, + "original": { + "owner": "TheArcaneBrony", + "repo": "synapse-http-antispam", + "type": "github" + } + }, "systems": { "locked": { "lastModified": 1681028828, diff --git a/flake.nix b/flake.nix
index e71e348..7a43916 100755 --- a/flake.nix +++ b/flake.nix
@@ -33,6 +33,7 @@ # Draupnir module/package nixpkgs-Draupnir.url = "github:TheArcaneBrony/nixpkgs/module/draupnir"; + nixpkgs-DraupnirPkg.url = "github:r-ryantm/nixpkgs/auto-update/draupnir"; nixpkgs-keydb.url = "github:NixOS/nixpkgs?rev=e0464e47880a69896f0fb1810f00e0de469f770a"; #MatrixContentFilter.url = "git+file:/home/Rory/git/matrix/MatrixContentFilter?submodules=1"; @@ -70,6 +71,10 @@ }; # Packages built from git + synapseHttpAntispamSrc = { + url = "github:TheArcaneBrony/synapse-http-antispam"; + flake = false; + }; nhekoSrc = { url = "github:Nheko-reborn/nheko/master"; flake = false; @@ -143,8 +148,13 @@ nixpkgs.overlays = [ (final: prev: { matrix-synapse-unwrapped = inputs.nixpkgs-master.legacyPackages.${pkgs.stdenv.hostPlatform.system}.matrix-synapse-unwrapped; - draupnir = inputs.nixpkgs-master.legacyPackages.${pkgs.stdenv.hostPlatform.system}.draupnir; + #draupnir = inputs.nixpkgs-master.legacyPackages.${pkgs.stdenv.hostPlatform.system}.draupnir; + draupnir = inputs.nixpkgs-DraupnirPkg.legacyPackages.${pkgs.stdenv.hostPlatform.system}.draupnir; keydb = inputs.nixpkgs-keydb.legacyPackages.${pkgs.stdenv.hostPlatform.system}.keydb; + matrix-synapse-plugins.synapse-http-antispam = prev.matrix-synapse-plugins.synapse-http-antispam.overrideAttrs (oldAttrs: { + src = inputs.synapseHttpAntispamSrc; + version = inputs.synapseHttpAntispamSrc.rev; + }); }) ]; } diff --git a/host/Rory-ovh/configuration.nix b/host/Rory-ovh/configuration.nix
index 81a824d..f457603 100755 --- a/host/Rory-ovh/configuration.nix +++ b/host/Rory-ovh/configuration.nix
@@ -32,14 +32,14 @@ boot.loader.grub.devices = lib.mkForce [ "nodev" ]; networking = { hostName = "Rory-ovh"; - interfaces.enp98s0f0.ipv4.addresses = [ - { - address = "51.210.113.110"; - prefixLength = 24; - } - ]; - defaultGateway.interface = "enp98s0f0"; - defaultGateway.address = lib.mkForce "51.210.113.254"; + #interfaces.enp98s0f0.ipv4.addresses = [ + # { + # address = "51.210.113.110"; + # prefixLength = 24; + # } + #]; + #defaultGateway.interface = "enp98s0f0"; + #defaultGateway.address = "51.210.113.254"; nat = { enable = true; internalInterfaces = [ @@ -54,6 +54,16 @@ firewall.enable = lib.mkForce true; }; + systemd.network = { + enable = true; + networks.enp98s0f0 = { + name = "enp98s0f0"; + DHCP = "no"; + gateway = [ "51.210.113.254" ]; + address = [ "51.210.113.110" ]; + }; + }; + monitoring = { monitorAll = true; localPrometheus = true; diff --git a/host/Rory-ovh/services/email/autoconfig.nix b/host/Rory-ovh/services/email/autoconfig.nix
index d258046..5f3bce2 100644 --- a/host/Rory-ovh/services/email/autoconfig.nix +++ b/host/Rory-ovh/services/email/autoconfig.nix
@@ -1,7 +1,7 @@ -{ ... }: +{ config, ... }: { services.go-autoconfig = { - enable = true; + enable = !config.virtualisation.isVmVariant; settings = { service_addr = ":1323"; domain = "autoconfig.rory.gay"; diff --git a/host/Rory-ovh/services/email/maddy.nix b/host/Rory-ovh/services/email/maddy.nix
index 7dbf004..548cb1a 100644 --- a/host/Rory-ovh/services/email/maddy.nix +++ b/host/Rory-ovh/services/email/maddy.nix
@@ -1,68 +1,71 @@ { + lib, pkgs, options, config, ... }: { - services.maddy = { - enable = true; - primaryDomain = "rory.gay"; - hostname = "mail.rory.gay"; - ensureAccounts = [ - "root@rory.gay" - ]; - ensureCredentials = { - "root@rory.gay".passwordFile = "/var/lib/maddy/passwd/root"; - }; - config = builtins.readFile ./maddy.conf; - # builtins.replaceStrings - # [ - # "imap tcp://0.0.0.0:143" - # "submission tcp://0.0.0.0:587" - # "entry postmaster postmaster@$(primary_domain)" - # ] - # [ - # "imap tls://0.0.0.0:993 tcp://0.0.0.0:143" - # "submission tls://0.0.0.0:465 tcp://0.0.0.0:587" - # "entry postmaster root@$(primary_domain)" - # ] - # options.services.maddy.config.default; - - tls = { - loader = "file"; - certificates = [ - { -# certPath = "/var/lib/acme/mail.rory.gay/fullchain.pem"; -# keyPath = "/var/lib/acme/mail.rory.gay/key.pem"; - certPath = "/run/credentials/maddy.service/acme-fullchain.pem"; - keyPath = "/run/credentials/maddy.service/acme-key.pem"; - } + config = lib.mkIf (!config.virtualisation.isVmVariant) { + services.maddy = { + enable = true; + primaryDomain = "rory.gay"; + hostname = "mail.rory.gay"; + ensureAccounts = [ + "root@rory.gay" ]; + ensureCredentials = { + "root@rory.gay".passwordFile = "/var/lib/maddy/passwd/root"; + }; + config = builtins.readFile ./maddy.conf; + # builtins.replaceStrings + # [ + # "imap tcp://0.0.0.0:143" + # "submission tcp://0.0.0.0:587" + # "entry postmaster postmaster@$(primary_domain)" + # ] + # [ + # "imap tls://0.0.0.0:993 tcp://0.0.0.0:143" + # "submission tls://0.0.0.0:465 tcp://0.0.0.0:587" + # "entry postmaster root@$(primary_domain)" + # ] + # options.services.maddy.config.default; + + tls = { + loader = "file"; + certificates = [ + { + # certPath = "/var/lib/acme/mail.rory.gay/fullchain.pem"; + # keyPath = "/var/lib/acme/mail.rory.gay/key.pem"; + certPath = "/run/credentials/maddy.service/acme-fullchain.pem"; + keyPath = "/run/credentials/maddy.service/acme-key.pem"; + } + ]; + }; }; - }; - networking.firewall.allowedTCPPorts = [ - 25 - 143 - 465 - 587 - 993 - ]; + networking.firewall.allowedTCPPorts = [ + 25 + 143 + 465 + 587 + 993 + ]; - users.users.maddy.extraGroups = [ "nginx" ]; + users.users.maddy.extraGroups = [ "nginx" ]; - fileSystems."/var/lib/maddy" = { - depends = [ "/" ]; - device = "/data/maddy"; - fsType = "none"; - options = [ "bind" ]; - }; - - systemd.services.maddy.serviceConfig = { - LoadCredential = [ - "acme-fullchain.pem:/var/lib/acme/rory.gay/fullchain.pem" - "acme-key.pem:/var/lib/acme/rory.gay/key.pem" - ]; + fileSystems."/var/lib/maddy" = { + depends = [ "/" ]; + device = "/data/maddy"; + fsType = "none"; + options = [ "bind" ]; + }; + + systemd.services.maddy.serviceConfig = { + LoadCredential = [ + "acme-fullchain.pem:/var/lib/acme/rory.gay/fullchain.pem" + "acme-key.pem:/var/lib/acme/rory.gay/key.pem" + ]; + }; }; } diff --git a/host/Rory-ovh/services/email/nginx.nix b/host/Rory-ovh/services/email/nginx.nix
index 812993a..5b04612 100644 --- a/host/Rory-ovh/services/email/nginx.nix +++ b/host/Rory-ovh/services/email/nginx.nix
@@ -2,8 +2,8 @@ { services.nginx.virtualHosts = { "mta-sts.rory.gay" = { - enableACME = true; - forceSSL = true; + enableACME = !config.virtualisation.isVmVariant; + forceSSL = !config.virtualisation.isVmVariant; locations = { "/.well-known/mta-sts.txt" = { # age 604800 @@ -17,15 +17,15 @@ }; }; "mail.rory.gay" = { - enableACME = true; - forceSSL = true; + enableACME = !config.virtualisation.isVmVariant; + forceSSL = !config.virtualisation.isVmVariant; locations = { "/".return = "200 'OK'"; }; }; "autoconfig.rory.gay" = { - enableACME = true; - forceSSL = true; + enableACME = !config.virtualisation.isVmVariant; + forceSSL = !config.virtualisation.isVmVariant; locations."/".proxyPass = "http://localhost:1323"; }; }; diff --git a/host/Rory-ovh/services/matrix/synapse/synapse-main.nix b/host/Rory-ovh/services/matrix/synapse/synapse-main.nix
index c6e5217..f4ca044 100755 --- a/host/Rory-ovh/services/matrix/synapse/synapse-main.nix +++ b/host/Rory-ovh/services/matrix/synapse/synapse-main.nix
@@ -1,4 +1,4 @@ -{ pkgs, ... }: +{ config, pkgs, ... }: { # Worker plumbing examples: https://github.com/element-hq/synapse/blob/master/docker/configure_workers_and_start.py @@ -11,21 +11,21 @@ nginxVirtualHostName = "matrix.rory.gay"; enableWorkers = true; - federationSenders = 16; # 16 - pushers = 1; - mediaRepoWorkers = 2; # 4 - clientReaders = 2; # 4 - syncWorkers = 2; # 4 + federationSenders = if config.virtualisation.isVmVariant then 0 else 16; # 16 + pushers = if config.virtualisation.isVmVariant then 1 else 1; + mediaRepoWorkers = if config.virtualisation.isVmVariant then 1 else 2; # 4 + clientReaders = if config.virtualisation.isVmVariant then 2 else 2; # 4 + syncWorkers = if config.virtualisation.isVmVariant then 2 else 2; # 4 #authWorkers = 0; - eventCreators = 16; + eventCreators = if config.virtualisation.isVmVariant then 2 else 16; - federationReaders = 8; # 8 - federationInboundWorkers = 16; # 8 + federationReaders = if config.virtualisation.isVmVariant then 0 else 8; # 8 + federationInboundWorkers = if config.virtualisation.isVmVariant then 0 else 16; # 8 - enableAppserviceWorker = true; - enableBackgroundWorker = true; - enableUserDirWorker = true; + enableAppserviceWorker = if config.virtualisation.isVmVariant then true else true; + enableBackgroundWorker = if config.virtualisation.isVmVariant then true else true; + enableUserDirWorker = if config.virtualisation.isVmVariant then true else true; accountDataStreamWriters = 1; eventStreamWriters = 2; # 8 @@ -35,6 +35,10 @@ toDeviceStreamWriters = 1; typingStreamWriters = 1; + plugins = with pkgs.matrix-synapse-plugins; [ + synapse-http-antispam + ]; + #untested: #sharedStreamWriters = 1; @@ -223,4 +227,46 @@ }; systemd.tmpfiles.rules = [ "D /run/redis-matrix-synapse 0755 matrix-synapse matrix-synapse" ]; + + virtualisation.vmVariant = { + systemd.tmpfiles.rules = [ "D /run/secrets 0755 nobody nobody" ]; + systemd.services."matrix-synapse-generate-token" = { + # generate /data/secrets/synapse-shared-secret + description = "Generate Synapse shared secret"; + wantedBy = [ "multi-user.target" ]; + after = [ "network.target" ]; + before = [ "matrix-synapse.service" ]; + script = '' + set -e -x -o pipefail + echo "Starting key generation" + if [ ! -f "/data/secrets/synapse-shared-secret" ] + then + echo "Generating new key" + ${pkgs.openssl}/bin/openssl rand -base64 32 > /data/secrets/synapse-shared-secret + echo "Key generation complete" + else + echo "Not generating key, key exists" + fi + echo "Script complete" + ''; + }; + systemd.services."matrix-synapse-postgres-init" = { + description = "Generate synapse postgres user"; + wantedBy = [ "multi-user.target" ]; + after = [ "network.target" "postgresql.service" ]; + before = [ "matrix-synapse.service" ]; + + script = '' + set -e -x -o pipefail + ${pkgs.postgresql}/bin/createuser ${config.services.matrix-synapse.settings.database.args.user} || true + ${pkgs.postgresql}/bin/createdb --encoding=UTF8 --locale=C --template=template0 --owner=${config.services.matrix-synapse.settings.database.args.user} ${config.services.matrix-synapse.settings.database.args.database} || true + ''; + serviceConfig = { + User = "postgres"; + Group = "postgres"; + WorkingDirectory = config.services.postgresql.dataDir; + RemainAfterExit = true; + }; + }; + }; } diff --git a/host/Rory-ovh/services/nginx/nginx.nix b/host/Rory-ovh/services/nginx/nginx.nix
index 3b58796..453816f 100755 --- a/host/Rory-ovh/services/nginx/nginx.nix +++ b/host/Rory-ovh/services/nginx/nginx.nix
@@ -1,7 +1,7 @@ { config, pkgs, ... }: let serveDir = config: { - enableACME = if config ? ssl then config.ssl else true; + enableACME = if config ? ssl then config.ssl else !config.virtualisation.isVmVariant; addSSL = if config ? ssl then config.ssl else true; root = if config ? path then config.path else builtins.throw "path is required"; locations = { @@ -60,22 +60,22 @@ in # "sentry.thearcanebrony.net" = import ./thearcanebrony.net/sentry.nix; # "search.thearcanebrony.net" = import ./thearcanebrony.net/search.nix; # - "rory.gay" = import ./rory.gay/root.nix; + "rory.gay" = import ./rory.gay/root.nix { inherit config; }; # "lfs.rory.gay" = serveDir { path = "/data/nginx/html_lfs"; }; # # "awooradio.thearcanebrony.net" = import ./thearcanebrony.net/awooradio.nix; - "cgit.rory.gay" = import ./rory.gay/cgit.nix; + "cgit.rory.gay" = import ./rory.gay/cgit.nix { inherit config; }; # #"jitsi.rory.gay" = import ./rory.gay/jitsi.nix; # # #matrix... # "conduit.rory.gay" = import ./rory.gay/conduit.nix; - "matrix.rory.gay" = import ./rory.gay/matrix.nix; - "stream.rory.gay" = import ./rory.gay/stream.nix; + "matrix.rory.gay" = import ./rory.gay/matrix.nix { inherit config; }; + "stream.rory.gay" = import ./rory.gay/stream.nix { inherit config; }; # "pcpoc.rory.gay" = import ./rory.gay/pcpoc.nix; # "matrixunittests.rory.gay" = import ./rory.gay/matrixunittests.nix; # "conduit.matrixunittests.rory.gay" = import ./rory.gay/conduit.matrixunittests.nix; - "mru.rory.gay" = import ./rory.gay/mru.nix; - "ec.rory.gay" = import ./rory.gay/ec.nix; + "mru.rory.gay" = import ./rory.gay/mru.nix { inherit config; }; + "ec.rory.gay" = import ./rory.gay/ec.nix { inherit config; }; }; }; }; diff --git a/host/Rory-ovh/services/nginx/rory.gay/cgit.nix b/host/Rory-ovh/services/nginx/rory.gay/cgit.nix
index 35fc85b..7b49a42 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/cgit.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/cgit.nix
@@ -1,7 +1,8 @@ +{ config }: { + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; root = "/data/git"; - enableACME = true; - addSSL = true; extraConfig = '' autoindex on; more_set_headers 'Access-Control-Allow-Origin: *'; diff --git a/host/Rory-ovh/services/nginx/rory.gay/conduit.matrixunittests.nix b/host/Rory-ovh/services/nginx/rory.gay/conduit.matrixunittests.nix
index 9503747..231d5e3 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/conduit.matrixunittests.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/conduit.matrixunittests.nix
@@ -1,6 +1,7 @@ +{ config }: { - enableACME = true; - addSSL = true; + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; http3 = true; http3_hq = true; kTLS = true; diff --git a/host/Rory-ovh/services/nginx/rory.gay/ec.nix b/host/Rory-ovh/services/nginx/rory.gay/ec.nix
index 0985503..c50b1f9 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/ec.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/ec.nix
@@ -1,7 +1,7 @@ +{ config }: { - enableACME = true; - addSSL = true; - kTLS = true; + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; root = "/data/nginx/html_ec"; reuseport = true; extraConfig = '' diff --git a/host/Rory-ovh/services/nginx/rory.gay/matrix-bak.nix b/host/Rory-ovh/services/nginx/rory.gay/matrix-bak.nix
index 5d44454..1af3669 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/matrix-bak.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/matrix-bak.nix
@@ -1,6 +1,7 @@ +{ config }: { - enableACME = true; - addSSL = true; + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; locations."/_matrix" = { proxyPass = "http://192.168.1.5:8008"; extraConfig = '' diff --git a/host/Rory-ovh/services/nginx/rory.gay/matrix.nix b/host/Rory-ovh/services/nginx/rory.gay/matrix.nix
index d48f4ca..45a507f 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/matrix.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/matrix.nix
@@ -1,6 +1,7 @@ +{ config }: { - enableACME = true; - addSSL = true; + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; locations."/" = { #proxyPass = "http://127.0.0.1:9001"; proxyPass = "http://localhost:8008"; diff --git a/host/Rory-ovh/services/nginx/rory.gay/matrixunittests.nix b/host/Rory-ovh/services/nginx/rory.gay/matrixunittests.nix
index edb1704..f23f0dd 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/matrixunittests.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/matrixunittests.nix
@@ -1,9 +1,10 @@ +{ config }: { - enableACME = true; - addSSL = true; - http3 = true; - http3_hq = true; - kTLS = true; + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; + http3 = !config.virtualisation.isVmVariant; + http3_hq = !config.virtualisation.isVmVariant; + kTLS = !config.virtualisation.isVmVariant; extraConfig = '' brotli off; ''; diff --git a/host/Rory-ovh/services/nginx/rory.gay/mru.nix b/host/Rory-ovh/services/nginx/rory.gay/mru.nix
index d1e1cd7..6e685de 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/mru.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/mru.nix
@@ -1,10 +1,11 @@ +{ config }: { - enableACME = true; - addSSL = true; + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; # quic = true; - http3 = true; - http3_hq = true; - kTLS = true; + http3 = !config.virtualisation.isVmVariant; + http3_hq = !config.virtualisation.isVmVariant; + kTLS = !config.virtualisation.isVmVariant; root = "/data/nginx/html_mru"; # reuseport = true; extraConfig = '' diff --git a/host/Rory-ovh/services/nginx/rory.gay/root.nix b/host/Rory-ovh/services/nginx/rory.gay/root.nix
index 11d06c0..a7720ec 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/root.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/root.nix
@@ -1,7 +1,8 @@ +{ config }: { + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; root = "/data/nginx/html_rory_gay"; - enableACME = true; - addSSL = true; extraConfig = ''autoindex on;''; locations."= /.well-known/matrix/server".extraConfig = '' diff --git a/host/Rory-ovh/services/nginx/rory.gay/stream.nix b/host/Rory-ovh/services/nginx/rory.gay/stream.nix
index f382cc9..caed22f 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/stream.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/stream.nix
@@ -1,6 +1,7 @@ +{ config }: { - enableACME = true; - addSSL = true; + enableACME = !config.virtualisation.isVmVariant; + addSSL = !config.virtualisation.isVmVariant; locations = { "/" = { proxyPass = "http://localhost:1934"; diff --git a/host/Rory-ovh/services/nginx/rory.gay/wad-api.nix b/host/Rory-ovh/services/nginx/rory.gay/wad-api.nix
index 65e9bdb..ac07547 100755 --- a/host/Rory-ovh/services/nginx/rory.gay/wad-api.nix +++ b/host/Rory-ovh/services/nginx/rory.gay/wad-api.nix
@@ -1,5 +1,5 @@ { - enableACME = true; + enableACME = !config.virtualisation.isVmVariant; addSSL = true; locations = { "/" = { diff --git a/host/Rory-ovh/services/nginx/thearcanebrony.net/awooradio.nix b/host/Rory-ovh/services/nginx/thearcanebrony.net/awooradio.nix
index f13cb0c..c0ca8b0 100755 --- a/host/Rory-ovh/services/nginx/thearcanebrony.net/awooradio.nix +++ b/host/Rory-ovh/services/nginx/thearcanebrony.net/awooradio.nix
@@ -1,5 +1,6 @@ +{ config }: { - enableACME = true; + enableACME = !config.virtualisation.isVmVariant; addSSL = true; locations = { "/" = { diff --git a/host/Rory-ovh/services/nginx/thearcanebrony.net/root.nix b/host/Rory-ovh/services/nginx/thearcanebrony.net/root.nix
index 86dddac..59cba43 100755 --- a/host/Rory-ovh/services/nginx/thearcanebrony.net/root.nix +++ b/host/Rory-ovh/services/nginx/thearcanebrony.net/root.nix
@@ -1,5 +1,6 @@ +{ config }: { - enableACME = true; + enableACME = !config.virtualisation.isVmVariant; addSSL = true; root = "/data/nginx/html_thearcanebrony"; extraConfig = ''autoindex on;''; diff --git a/host/Rory-ovh/services/nginx/thearcanebrony.net/search.nix b/host/Rory-ovh/services/nginx/thearcanebrony.net/search.nix
index cd655d8..cfb4e1c 100755 --- a/host/Rory-ovh/services/nginx/thearcanebrony.net/search.nix +++ b/host/Rory-ovh/services/nginx/thearcanebrony.net/search.nix
@@ -1,5 +1,6 @@ +{ config }: { - enableACME = true; + enableACME = !config.virtualisation.isVmVariant; addSSL = true; locations = { "/" = { diff --git a/host/Rory-ovh/services/nginx/thearcanebrony.net/sentry.nix b/host/Rory-ovh/services/nginx/thearcanebrony.net/sentry.nix
index f496190..8cd0826 100755 --- a/host/Rory-ovh/services/nginx/thearcanebrony.net/sentry.nix +++ b/host/Rory-ovh/services/nginx/thearcanebrony.net/sentry.nix
@@ -1,5 +1,6 @@ +{ config }: { - enableACME = true; + enableACME = !config.virtualisation.isVmVariant; addSSL = true; locations = { "/" = { diff --git a/host/Rory-ovh/services/postgres.nix b/host/Rory-ovh/services/postgres.nix
index 50dffa1..10d1cb7 100755 --- a/host/Rory-ovh/services/postgres.nix +++ b/host/Rory-ovh/services/postgres.nix
@@ -1,4 +1,4 @@ -{ pkgs, ... }: +{ config, pkgs, ... }: { systemd.tmpfiles.rules = [ "d /data/dedicated/postgres 0750 postgres postgres" ]; @@ -27,11 +27,11 @@ max_connections = 2500; superuser_reserved_connections = 3; - shared_buffers = "64GB"; - work_mem = "32GB"; - maintenance_work_mem = "8GB"; + shared_buffers = if config.virtualisation.isVmVariant then "128MB" else "64GB"; + work_mem = if config.virtualisation.isVmVariant then "64MB" else "32GB"; + maintenance_work_mem = if config.virtualisation.isVmVariant then "512MB" else "8GB"; huge_pages = "try"; - effective_cache_size = "64GB"; # was 22 + effective_cache_size = if config.virtualisation.isVmVariant then "1GB" else "64GB"; # was 22 effective_io_concurrency = 100; random_page_cost = 1.1; diff --git a/modules/base-server.nix b/modules/base-server.nix
index 0b05a9d..ccf4a77 100755 --- a/modules/base-server.nix +++ b/modules/base-server.nix
@@ -51,18 +51,14 @@ networking = { hostName = lib.mkDefault "Rory-nix-base-server"; networkmanager.enable = false; - useNetworkd = true; wireless.enable = false; enableIPv6 = false; firewall = { enable = false; - # allowedTCPPorts = [ ... ]; - # allowedUDPPorts = [ ... ]; allowedTCPPorts = [ 22 ]; }; useDHCP = false; - # nameservers = [ "1.1.1.1" "1.0.0.1" "8.8.8.8" "8.4.4.8" ]; nameservers = [ "10.10.0.4" "10.10.0.5" @@ -71,7 +67,7 @@ "8.8.8.8" "8.4.4.8" ]; - defaultGateway = "192.168.1.1"; + defaultGateway = lib.mkDefault "192.168.1.1"; }; hardware.pulseaudio.enable = false; @@ -81,51 +77,6 @@ hardware.enableRedistributableFirmware = false; services = { - # prometheus = { - # exporters = { - # node = { - # enable = true; - # port = 9100; - # enabledCollectors = [ - # #"logind" #too slow - # "systemd" - # "processes" - # "interrupts" - # # Testing: - # "buddyinfo" - # "cgroups" - # "ksmd" - # "lnstat" - # "mountstats" - # "network_route" - # #"perf" # requires sysctl change - # "qdisc" - # "sysctl" - # "softirqs" - # "tcpstat" - # ]; - # disabledCollectors = [ - # "textfile" - # "xfs" - # "zfs" - # "selinux" - # "cpufreq" - # "btrfs" - # "powersupplyclass" - # "mdadm" - # "tapestats" - # "fibrechannel" - # "cpu_vulnerabilities" - # "watchdog" - # "thermal_zone" - # "logind" - # "nfs" - # "nfsd" - # "infiniband" - # ]; - # }; - # }; - # }; promtail = { enable = true; configuration = { diff --git a/modules/base.nix b/modules/base.nix
index 6119cdf..09f638a 100755 --- a/modules/base.nix +++ b/modules/base.nix
@@ -65,8 +65,6 @@ hostName = lib.mkDefault "Rory-nix-base"; firewall = { enable = false; - # allowedTCPPorts = [ ... ]; - # allowedUDPPorts = [ ... ]; }; nameservers = lib.mkDefault [ "1.1.1.1" @@ -175,13 +173,24 @@ virtualisation.vmVariant = { services.getty.autologinUser = "root"; virtualisation = { - memorySize = 4096; - cores = 2; + memorySize = 8192; + cores = 6; msize = 1*1024*1024; bios = pkgs.qboot; }; monitoring.monitorAll = lib.mkForce false; services.promtail.enable = lib.mkForce false; + networking.useDHCP = lib.mkOverride 51 true; + + environment.systemPackages = with pkgs; [ + qutebrowser + gomuks + kdePackages.konqueror + weston + kitty + waybar + sway + ]; }; } diff --git a/modules/users/Rory.nix b/modules/users/Rory.nix
index 545d2fa..56a30c3 100755 --- a/modules/users/Rory.nix +++ b/modules/users/Rory.nix
@@ -48,7 +48,6 @@ mutableUsers = false; users.Rory.password = "password"; }; - networking.interfaces.enp34s0 = lib.mkForce { }; }; home-manager.users.Rory = {