Compare commits

..

22 commits

Author SHA1 Message Date
Leonardo Eugênio c7e6b0bee3 flake: update lockfile 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 4500b28c27 syncthing: way for tray 2024-04-01 11:58:01 -03:00
Leonardo Eugênio f68302d648 kdenlive: fix theme 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 9a17b8fabd theme: improve qt theming 2024-04-01 11:58:01 -03:00
Leonardo Eugênio dbb566e7d2 syncthing: enable tray icon 2024-04-01 11:58:01 -03:00
Leonardo Eugênio f9128fc0ac mangohud: install patch to fix keybind crash 2024-04-01 11:58:01 -03:00
Leonardo Eugênio a4ab0eacfc gpg: simplify config 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 42bdb74d79 update 2024-04-01 11:58:01 -03:00
Leonardo Eugênio aafff2fb8f lsp: replace rnix-lsp with nil 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 931b038ae9 update 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 3b08527233 btop: enable gpu monitoring 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 43e59ebc54 update 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 98ecc58ee7 kak-lsp: update config to new format 2024-04-01 11:58:01 -03:00
Leonardo Eugênio e878c2f907 alacritty: update config 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 54d41bb917 update renamed xkb config 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 3485b4f0ed update 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 7c27e1e5af update 2024-04-01 11:58:01 -03:00
Leonardo Eugênio af1c623580 update 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 38315aea4c sway: disable adaptive sync 2024-04-01 11:58:01 -03:00
Leonardo Eugênio e318c3267b update 2024-04-01 11:58:01 -03:00
Leonardo Eugênio 8c93f6d974 update 2024-04-01 11:58:01 -03:00
Leonardo Eugênio e9a0e60eb0 switch to nixpkgs unstable 2024-04-01 11:58:01 -03:00
15 changed files with 6 additions and 111 deletions

View file

@ -123,7 +123,6 @@
modules = [
./hosts/monolith.nix
./system/monolith-gitlab-runner.nix
./system/monolith-forgejo-runner.nix
./system/nix-serve.nix
./system/steam.nix
] ++ common_modules;

View file

@ -12,7 +12,6 @@
./writefreely.nix
./renawiki.nix
./email.nix
./forgejo.nix
];
# # Enable networking

View file

@ -9,21 +9,13 @@
mailserver = {
enable = true;
fqdn = "mail.lelgenio.xyz";
domains = [
"lelgenio.xyz"
"git.lelgenio.xyz"
];
domains = [ "lelgenio.xyz" ];
certificateScheme = "acme-nginx";
# Create passwords with
# nix-shell -p mkpasswd --run 'mkpasswd -sm bcrypt'
loginAccounts = {
"lelgenio@lelgenio.xyz" = {
hashedPassword = "$2y$05$z5s7QCXcs5uTFsfyYpwNJeWzb3RmzgWxNgcPCr0zjSytkLFF/qZmS";
aliases = [ "postmaster@lelgenio.xyz" ];
};
"noreply@git.lelgenio.xyz" = {
hashedPassword = "$2b$05$TmR1R7ZwXfec7yrOfeBL7u3ZtyXf0up5dEO6uMWSvb/O7LPEm.j0.";
};
};
};

View file

@ -1,56 +0,0 @@
{ lib, pkgs, config, ... }:
let
cfg = config.services.forgejo;
srv = cfg.settings.server;
in
{
services.nginx = {
virtualHosts.${cfg.settings.server.DOMAIN} = {
forceSSL = true;
enableACME = true;
extraConfig = ''
client_max_body_size 512M;
'';
locations."/".proxyPass = "http://localhost:${toString srv.HTTP_PORT}";
};
};
services.openssh = {
authorizedKeysFiles = [
"${config.services.forgejo.stateDir}/.ssh/authorized_keys"
];
# Recommended by forgejo: https://forgejo.org/docs/latest/admin/recommendations/#git-over-ssh
settings.AcceptEnv = "GIT_PROTOCOL";
};
services.forgejo = {
enable = true;
database.type = "postgres";
lfs.enable = true;
settings = {
service.DISABLE_REGISTRATION = true;
actions = {
ENABLED = true;
DEFAULT_ACTIONS_URL = "github";
};
server = {
DOMAIN = "git.lelgenio.xyz";
HTTP_PORT = 3000;
ROOT_URL = "https://${srv.DOMAIN}/";
};
mailer = {
ENABLED = true;
SMTP_ADDR = "mail.lelgenio.xyz";
FROM = "noreply@git.lelgenio.xyz";
USER = "noreply@git.lelgenio.xyz";
};
};
mailerPasswordFile = config.age.secrets.phantom-forgejo-mailer-password.path;
};
age.secrets.phantom-forgejo-mailer-password = {
file = ../../secrets/phantom-forgejo-mailer-password.age;
mode = "400";
owner = "forgejo";
};
}

View file

@ -6,6 +6,5 @@
smtp.fromAddress = "lelgenio@disroot.org";
streamingProcesses = 2;
extraConfig.SINGLE_USER_MODE = "true";
mediaAutoRemove.olderThanDays = 10;
};
}

View file

@ -2,7 +2,7 @@
security.rtkit.enable = true;
services.openssh = {
enable = true;
ports = [ 9022 22 ];
ports = [ 9022 ];
settings = {
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;

View file

@ -13,8 +13,7 @@ let
"1.1.1.1"
"2606:4700:4700::1111"
];
in
{
in {
networking.nameservers = mkDefault nameservers;
services.resolved = mkDefault { fallbackDns = nameservers; };
networking.dhcpcd.extraConfig = "noipv4ll";

View file

@ -11,7 +11,7 @@
executable = true;
text = ''
systemctl --user import-environment
dbus-update-activation-environment --systemd DISPLAY WAYLAND_DISPLAY XDG_CURRENT_DESKTOP=sway SWAYSOCK
dbus-update-activation-environment --systemd WAYLAND_DISPLAY XDG_CURRENT_DESKTOP=sway
# systemctl --user stop pipewire wireplumber xdg-desktop-portal xdg-desktop-portal-wlr
# systemctl --user start pipewire wireplumber xdg-desktop-portal xdg-desktop-portal-wlr
'';

View file

@ -5,11 +5,9 @@ in
"rainbow-gitlab-runner-thoreb-itinerario-registrationConfigFile.age".publicKeys = [ main_ssh_public_key ];
"monolith-gitlab-runner-thoreb-itinerario-registrationConfigFile.age".publicKeys = [ main_ssh_public_key ];
"gitlab-runner-thoreb-telemetria-registrationConfigFile.age".publicKeys = [ main_ssh_public_key ];
"monolith-forgejo-runner-token.age".publicKeys = [ main_ssh_public_key ];
"lelgenio-cachix.age".publicKeys = [ main_ssh_public_key ];
"monolith-nix-serve-privkey.age".publicKeys = [ main_ssh_public_key ];
"phantom-nextcloud.age".publicKeys = [ main_ssh_public_key ];
"phantom-writefreely.age".publicKeys = [ main_ssh_public_key ];
"phantom-renawiki.age".publicKeys = [ main_ssh_public_key ];
"phantom-forgejo-mailer-password.age".publicKeys = [ main_ssh_public_key ];
}

View file

@ -1,12 +0,0 @@
#!/bin/sh
nix fmt
git diff
nixos-rebuild switch --flake .#phantom \
--update-input nixpkgs \
--no-write-lock-file \
--build-host phantom \
--target-host phantom \
"$@"

View file

@ -59,7 +59,7 @@
security.rtkit.enable = true;
services.openssh = {
enable = false;
enable = true;
ports = [ 9022 ];
settings = {
PermitRootLogin = "no";

View file

@ -1,19 +0,0 @@
{ pkgs, config, ... }: {
services.gitea-actions-runner = {
package = pkgs.forgejo-actions-runner;
instances.default = {
enable = true;
name = "monolith";
url = "https://git.lelgenio.xyz";
tokenFile = config.age.secrets.monolith-forgejo-runner-token.path;
labels = [
# provide a debian base with nodejs for actions
"debian-latest:docker://node:18-bullseye"
# fake the ubuntu name, because node provides no ubuntu builds
"ubuntu-latest:docker://node:18-bullseye"
# provide native execution on the host
#"native:host"
];
};
};
}

View file

@ -6,13 +6,9 @@
../secrets/monolith-gitlab-runner-thoreb-itinerario-registrationConfigFile.age;
secrets.gitlab-runner-thoreb-telemetria-registrationConfigFile.file =
../secrets/gitlab-runner-thoreb-telemetria-registrationConfigFile.age;
secrets.monolith-forgejo-runner-token.file =
../secrets/monolith-forgejo-runner-token.age;
secrets.rainbow-gitlab-runner-thoreb-itinerario-registrationConfigFile.file =
../secrets/rainbow-gitlab-runner-thoreb-itinerario-registrationConfigFile.age;
secrets.monolith-nix-serve-privkey.file =
../secrets/monolith-nix-serve-privkey.age;
secrets.phantom-forgejo-mailer-password.file =
../secrets/phantom-forgejo-mailer-password.age;
};
}