authorTheArcaneBrony <>2023-03-28 21:03:46 +0200
committerRory& <>2024-06-05 15:49:34 +0200
commit7010d98995fea8eda3c578fbfd13aecca918b7d9
Initial commit
+#!/usr/bin/env sh
+if [ $# -ne 2 ]; then
+    echo "Usage: $0 <root> <config>"
+    echo "NOTE: hardware config will be generated from root!"
+    echo "Defined configs:"
+    cat flake.nix | grep 'nixpkgs.lib.nixosSystem' | sed 's/ =.*//' | sed 's/^[ \t]*//;s/[ \t]*$//' | while read cfg; do echo " - $cfg"; done
+    exit 1
+if [ "$1" = "/" ]; then
+    nixos-generate-config --show-hardware-config > hardware-configuration.nix
+    git add -f hardware-configuration.nix
+    nixos-rebuild switch --flake ".#${2}" -j`nproc` --upgrade-all
+    git rm --cached hardware-configuration.nix
+    exit
+    nixos-generate-config --show-hardware-config --root "${1}" > hardware-configuration.nix
+    git add -f hardware-configuration.nix
+    nixos-install --root "${1}" --flake ".#${2}" 
+    git rm --cached hardware-configuration.nix
+    cp . "${1}/Spacebar-Open-Architecture" -r
+    exit
+  description = "Spacebar's services";
+  inputs = {
+    nixpkgs = {
+      url = "github:NixOS/nixpkgs/nixos-unstable";
+    };
+    home-manager =  {
+      url = "github:nix-community/home-manager/master";
+    };
+  };
+  outputs = { self, nixpkgs, home-manager }: {
+    nixosConfigurations = {
+      Spacebar-nginx = nixpkgs.lib.nixosSystem {
+        system = "x86_64-linux";
+        modules = [
+          ./host/Spacebar-nginx/configuration.nix
+          ./hardware-configuration.nix
+          home-manager.nixosModules.home-manager
+        ];
+        specialArgs = {
+          inherit home-manager;
+        };
+      };     
+    };
+  };
+{ config, pkgs, lib, ... }:
+  imports =
+    [
+      ../../modules/base.nix
+    ];
+  networking = {
+    hostName = "Spacebar-postgres";
+    interfaces.ens18.ipv4.addresses = [ { 
+      address = "";
+      prefixLength = 24;
+    } ];
+    interfaces.ens19.ipv4.addresses = [ {
+      address = "";
+      prefixLength = 16;
+    } ];
+  };
+  systemd.tmpfiles.rules = [  "d /data/pg 0750 postgres postgres" ];
+  services.postgresql = {
+    enable = true;
+    package = pkgs.postgresql_14;
+    enableTCPIP = true;
+    authentication = pkgs.lib.mkOverride 10 ''
+      local all all trust
+      host all all trust
+      host all all ::1/128 trust
+      host matrix-synapse-spacebar-chat matrix-synapse-spacebar-chat trust
+      host all all md5
+    '';
+    initialScript = pkgs.writeText "backend-initScript" ''
+      CREATE ROLE matrix-synapse-spacebar-chat WITH LOGIN PASSWORD '${pkgs.postgresql_14}' CREATEDB;
+      CREATE DATABASE matrix-synapse-spacebar-chat;
+      GRANT ALL PRIVILEGES ON DATABASE matrix-synapse-spacebar-chat TO matrix-synapse-spacebar-chat;
+    '';
+    dataDir = "/data/pg";
+    settings = {
+      "max_connections" = "100";
+      "shared_buffers" = "128MB";
+      "max_wal_size" = "1GB";
+      "min_wal_size" = "80MB";
+    };
+  };
+  system.stateVersion = "22.11"; # DO NOT EDIT!
+{ config, pkgs, lib, ... }:
+  imports =
+    [
+      ../../modules/base-server.nix
+    ];
+  networking = {
+    hostName = "Spacebar-nginx";
+    interfaces.ens18.ipv4.addresses = [ { 
+      address = "";
+      prefixLength = 24;
+    } ];
+    interfaces.ens19.ipv4.addresses = [ {
+      address = "";
+      prefixLength = 16;
+    } ];
+  };
+  services = {
+    nginx = {
+      enable = true;
+      package = pkgs.nginxQuic;
+      recommendedProxySettings = true;
+      recommendedTlsSettings = true;
+      virtualHosts = {
+        "" = import ./hosts/;
+      };
+    };
+  };
+ = [ "data.mount" ];
+  security.acme.acceptTerms = true;
+ = "";
+  system.stateVersion = "22.11"; # DO NOT EDIT!
+  root = "/data/nginx/html_boorunav";
+  enableACME = true;
+  addSSL = true;
+  locations = {
+    "/" = {
+      index = "index.html";
+    };
+  };
+{ config, pkgs, lib, ... }:
+  imports =
+    [
+      ../../modules/base-server.nix
+    ];
+  networking = {
+    hostName = "Spacebar-synapse";
+    interfaces.ens18.ipv4.addresses = [ { 
+      address = "";
+      prefixLength = 24;
+    } ];
+    interfaces.ens19.ipv4.addresses = [ {
+      address = "";
+      prefixLength = 16;
+    } ];
+  };
+  # Discord bridge
+  services.matrix-appservice-discord = {
+    enable = false; # Alicia - figure out secret first...
+    environmentFile = /etc/keyring/matrix-appservice-discord/tokens.env;
+    settings = {
+      bridge = {
+        domain = "";
+        homeserverUrl = "";
+      };
+      database = {
+        connString = "postgres://postgres@";
+      };
+    };
+  };
+  services.matrix-synapse = {
+    enable = true;
+    settings = {
+      server_name = "";
+      enable_registration = false;
+      registration_shared_secret_path = "/var/lib/matrix-synapse/registration_shared_secret.txt";
+      # Alicia - types:
+      listeners = [
+        { 
+          port = 8008;
+          bind_addresses = [ "" "" ];
+          type = "http";
+          tls = false;
+          x_forwarded = true;
+          resources = [ {
+            names = [ "client" "federation" ];
+            compress = true;
+          } ];
+        }
+      ];
+      dynamic_thumbnails = true;
+      presence = {
+        enable = true;
+        update_interval = 60;
+      };
+      url_preview_enabled = true;
+      database = {
+        name = "psycopg2";
+        args = {
+          user = "matrix-synapse-spacebar-chat";
+          password = "somepassword";
+          database = "matrix-synapse-spacebar-chat";
+          host = "";
+        };
+      };
+      app_service_config_files = [ ];
+    };
+    plugins = with pkgs.matrix-synapse-plugins; [ ];
+  };
+  # Alicia - doesnt work yet... until in nixpkgs...
+  services.draupnir = {
+    enable = true;
+    pantalaimon = {
+      enable = true;
+      username = "draupnir";
+      passwordFile = "/etc/draupnir-password";
+      options = {
+        homeserver = "http://localhost:8008";
+        ssl = false;
+      };
+    };
+    managementRoom = "";
+    homeserverUrl = "http://localhost:8008";
+    verboseLogging = false;
+    settings = {
+      recordIgnoredInvites = false;
+      automaticallyRedactForReasons = [ "*" ];
+      fasterMembershipChecks = true;
+      backgroundDelayMS = 100;
+      pollReports = true;
+      admin.enableMakeRoomAdminCommand = true;
+      commands.ban.defaultReasons = [
+        "spam"
+        "harassment"
+        "transphobia"
+        "scam"
+      ];
+      protections = {
+        wordlist = {
+          words = [
+            "tranny"
+            "faggot"
+          ];
+          minutesBeforeTrusting = 0;
+        };
+      };
+    };
+  };
+  system.stateVersion = "22.11"; # DO NOT EDIT!
+#!/usr/bin/env nix-shell
+#!nix-shell -i bash -p curl gnused nix coreutils jq openssl
+#set -x
+REG_KEY=`cat /var/lib/matrix-synapse/registration_shared_secret.txt`
+# -- LICENSE: CNPL v7+ -
+# Modified from Nyaaori ( <>
+# Explicit authorisation to use the code has been granted by the original author
+#  for use by members of the Rory system (
+# the magic function:
+	echo "Registering $1 with password $2"
+	_nonce=`curl http://localhost:8008/_synapse/admin/v1/register | jq -r .nonce`
+	#data: nonce, domain, username, password
+	_hmac=`printf '%s\0%s\0%s\0%s' "$_nonce" "$1" "$2" "admin" |  openssl dgst -sha1 -hmac "$REG_KEY" |  awk '{print $2}'`
+	curl -XPOST -d '{"nonce": "'"$_nonce"'", "username": "'"$1"'", "displayname": "'"$1"'", "password": "'"$2"'", "admin": true, "mac": "'"$_hmac"'"}' $REACHABLE_DOMAIN/_synapse/admin/v1/register | tee -a matrix-user-tokens.txt
+PASSWD=`cat /etc/matrix-user-pass`
+for u in {draupnir,rory,chris,maddy,cat}
+	register $u $PASSWD
+#!/usr/bin/env sh
+set -x
+mkdir -p /var/lib/matrix-synapse
+if [ ! -f "/var/lib/matrix-synapse/registration_shared_secret.txt" ]
+    cat /dev/urandom | tr -dc a-zA-Z0-9 | fold -w 256 | head -n 1 | tee /var/lib/matrix-synapse/registration_shared_secret.txt
+    echo Not generating key, key exists
+{ config, pkgs, lib, ... }:
+  imports =
+    [
+      ./monitoring.nix
+      ./users/Rory.nix
+      ./users/chris.nix
+    ];
+  boot = {
+    kernelPackages = pkgs.linuxPackages_latest;
+    kernelParams = [ "memory_hotplug.memmap_on_memory=1" "memhp_default_state=online" ];
+    loader = {
+      grub = {
+        enable = true;
+        version = 2;
+        devices = [ "/dev/sda" ]; # nodev for EFI only
+        # EFI
+        efiSupport = false;
+        efiInstallAsRemovable = false;
+      };
+      timeout = 1;
+    };
+  };
+  networking = {
+    hostName = lib.mkDefault "Spacebar-nix-base-server";
+    firewall = {
+      enable = false;
+      # allowedTCPPorts = [ ... ];
+      # allowedUDPPorts = [ ... ];
+    };
+    networkmanager.enable = false;
+    wireless.enable = false;
+    enableIPv6 = false;
+    useDHCP = false;
+    nameservers = [ "" ];
+    defaultGateway = "";
+  };
+  services = {
+    openssh = {
+      enable = true;
+    };	
+  };
+  environment.systemPackages = with pkgs; [
+    wget
+    neofetch
+    lnav
+    git
+    lsd
+    htop
+    btop
+    duf
+    kitty.terminfo
+    neovim
+  ];
+  systemd.coredump.extraConfig = lib.mkDefault ''
+    Storage=none
+  '';
+  documentation.nixos.enable = false;
+  hardware.pulseaudio.enable = false;
+  i18n.defaultLocale = "en_US.UTF-8";
+  nix.settings.experimental-features = [ "nix-command" "flakes" ];
+  nixpkgs.config.allowUnfree = true;
+  security.sudo.wheelNeedsPassword = false;
+  security.polkit.enable = true;
+  sound.enable = false;
+  system.stateVersion = "22.11"; # DO NOT EDIT!
+{ config, pkgs, lib, ... }:
+  services = {
+    prometheus = {
+      exporters = {
+        node = {
+          enable = true;
+          port = 9100;
+          enabledCollectors = [
+            "logind"
+            "systemd"
+          ];
+          disabledCollectors = [
+            #"textfile"
+          ];
+        };
+      };
+    };
+    promtail = {
+      enable = true;
+      configuration = {
+        server = {
+          http_listen_port = 3031;
+          grpc_listen_port = 0;
+        };
+        positions = {
+          filename = "/tmp/positions.yaml";
+        };
+        clients = [{
+          url = "";
+        }];
+        scrape_configs = [{
+          job_name = "journal";
+          journal = {
+            max_age = "12h";
+            labels = {
+              job = "systemd-journal";
+              host = "${toString config.networking.hostName}";
+            };
+          };
+          relabel_configs = [{
+            source_labels = [ "__journal__systemd_unit" ];
+            target_label = "unit";
+          }];
+        }];
+      };
+    };
+  };
+{ config, pkgs, home-manager, ... }:
+  users.users.Rory = {
+    isNormalUser = true;
+    extraGroups = [ "wheel" ];
+    packages = with pkgs; [
+    ];
+    initialPassword = "password";
+    openssh.authorizedKeys.keys = [
+      "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILF2IuNu//0DP/wKMuDvBgVT3YBS2uULsipbdrhJCTM7 Rory-desktop"
+      "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIN/kNkY/E5b6rvCQLMaSbpLQ/xoyywIwVVu9uo2j/B6p Rory@RoryNix"
+    ];
+  };
+  home-manager.users.Rory = {
+    programs.git = {
+      enable = true;
+      userName = "TheArcaneBrony";
+      userEmail = "";
+      extraConfig = {
+        safe = {
+          directory = "/";
+        };
+      };
+    };
+    home.stateVersion = "22.11";
+  };
+{ config, pkgs, ... }:
+  users.users.chris = {
+    isNormalUser = true;
+    extraGroups = [ "wheel" ];
+    packages = with pkgs; [
+      nano
+    ];
+    openssh.authorizedKeys.keys = [
+      "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMd9U0+wKjBG3Q9Qg249xJY+ybYeRV9/VMPjuwKvFBEI"
+    ];
+  };
+#!/usr/bin/env sh
+#!/usr/bin/env sh
+nix flake update
