summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDevin Finlinson <devin.finlinson@pm.me>2026-08-25 15:23:30 -0600
committerDevin Finlinson <devin.finlinson@pm.me>2026-08-25 15:23:30 -0600
commit3fb6b1f841bfae880375f6cf5bf7872c67913e8d (patch)
tree2879404bb9f7de3062601630d06069755c3c3694
parent704e34461dd3464ff5dd89718d7194154117c170 (diff)
parentc87672dc1d12deec86c91db7fc7fa85fd57e991b (diff)
Merge branch 'master' of ssh://myrmexia.xyz:/srv/git/.flake
-rw-r--r--flake.lock44
-rw-r--r--flake.nix7
-rw-r--r--home-manager/default.nix4
-rw-r--r--home-manager/home.nix2
-rw-r--r--machines/apollo/default.nix132
-rw-r--r--machines/apollo/disko.nix66
-rw-r--r--machines/apollo/hardware-configuration.nix24
-rw-r--r--machines/apollo/reverse-proxy.nix11
-rw-r--r--machines/bosco/default.nix53
-rw-r--r--machines/bosco/hardware-configuration.nix17
-rw-r--r--modules/nixos/headscale.nix2
-rw-r--r--modules/nixos/system-packages.nix2
-rw-r--r--modules/users/jerry.nix6
13 files changed, 302 insertions, 68 deletions
diff --git a/flake.lock b/flake.lock
index b97070a..e41a96f 100644
--- a/flake.lock
+++ b/flake.lock
@@ -271,7 +271,7 @@
"hugo-congo": {
"flake": false,
"locked": {
- "narHash": "sha256-uzbWnPli+psABRQK3VeDr1qfXVcyh5UpXFB3mvBP/d8=",
+ "narHash": "sha256-blGpEDOYrSj6RWiKEBPxusBFzR5Jyy/LU8+pdXTDgok=",
"type": "file",
"url": "https://github.com/jpanther/congo"
},
@@ -357,11 +357,11 @@
"xdph": "xdph"
},
"locked": {
- "lastModified": 1785885008,
- "narHash": "sha256-0106k5WJEakA/CyRCBa5NbYPVMtYhXANxyEV6rOCE40=",
+ "lastModified": 1786298417,
+ "narHash": "sha256-nJZCCA1YXQqnLQSNVrtY+IxK0pnVLV5qJSw79axtpCo=",
"owner": "hyprwm",
"repo": "Hyprland",
- "rev": "91f29f23bb691462f8aa6171b964069aebc37910",
+ "rev": "f7daeb7f79d48745a2894367e9e73229ac162abe",
"type": "github"
},
"original": {
@@ -625,11 +625,11 @@
"spectrum": "spectrum"
},
"locked": {
- "lastModified": 1785843289,
- "narHash": "sha256-H/0YgQ+3BtNbdeSVuqjU7ElneBzPPuIKcuWOi0ZUktQ=",
+ "lastModified": 1786300091,
+ "narHash": "sha256-4UFJOVGpaYtHW5yasSv80MaJxTBYdk2zyf3jhKtt0wA=",
"owner": "astro",
"repo": "microvm.nix",
- "rev": "e615e23267bf10d483fb44f759d4e61c354cc0f4",
+ "rev": "71beea0076cd46dafcee97a5a2e7d00cbba5bd2f",
"type": "github"
},
"original": {
@@ -705,11 +705,11 @@
]
},
"locked": {
- "lastModified": 1785650611,
- "narHash": "sha256-q4kR7g+pCcz6NASvoVPYu+CWWUurX03wogtBqGmR4h0=",
+ "lastModified": 1786249295,
+ "narHash": "sha256-Y2mSr+HLKYoOsjiackgilxkHXe8gkJ3z4hFFekjQX3I=",
"owner": "nix-community",
"repo": "nix-index-database",
- "rev": "dbc756c9d7287de19b3e0e38c928c47510d42c3e",
+ "rev": "14d55b8069119e3b88da7aa2f6c97f86a2cd3cd6",
"type": "github"
},
"original": {
@@ -725,11 +725,11 @@
"systems": "systems_3"
},
"locked": {
- "lastModified": 1785813727,
- "narHash": "sha256-18ojrPZu0LJLueWRclbJ/HiNBIqA73XhpXnSK1Ct3Tk=",
+ "lastModified": 1786154692,
+ "narHash": "sha256-+KyMg7tMfMcfFjUg59BD3OMUzehv9xsNK7ZMY3ZepGc=",
"owner": "Infinidoge",
"repo": "nix-minecraft",
- "rev": "bfab3c659caabb138f61dc96a5319bcdbdc51d54",
+ "rev": "fad712d66c18a08c582214c3f52c3d12e0cc16f9",
"type": "github"
},
"original": {
@@ -823,11 +823,11 @@
},
"nixpkgs-unstable": {
"locked": {
- "lastModified": 1785828668,
- "narHash": "sha256-8fsyqeO+mJqvIzeO4xIpgJe/f7MTbbVTEC6RT6WSXNs=",
+ "lastModified": 1786106723,
+ "narHash": "sha256-zDSUbpoeo/9ZmD2+wXnzxoo1+uhL8vxc0b8yuYMKYq0=",
"owner": "nixos",
"repo": "nixpkgs",
- "rev": "e72e4f299401a3689d4b3d5fc6496b11db7064eb",
+ "rev": "f13ff45afd1bb73e640eaa08a7066dbed07e3238",
"type": "github"
},
"original": {
@@ -871,11 +871,11 @@
},
"nixpkgs_4": {
"locked": {
- "lastModified": 1785858998,
- "narHash": "sha256-fKCq5jphd6l/Ms6gc3dptkw/TcKLYub9lQE5g6rbbkc=",
+ "lastModified": 1786201459,
+ "narHash": "sha256-CiOTEjmwAmG2AWnaIno9YaCJJmpca2FXPhMAsnrolCg=",
"owner": "nixos",
"repo": "nixpkgs",
- "rev": "04607e1165ac22c5fde6dcc54c9e0b3c0487c555",
+ "rev": "8b8c811c7c2541c30382c5de7ed26be055569c60",
"type": "github"
},
"original": {
@@ -1095,11 +1095,11 @@
]
},
"locked": {
- "lastModified": 1785846792,
- "narHash": "sha256-sNIGmqZJiOM/lCWUuslV53zuk/p5sGCRcS3kHKfxQvA=",
+ "lastModified": 1786032767,
+ "narHash": "sha256-C5K27sF/jaQe1BgB1/575r01oTAvw6mrDWPS1qUl6X0=",
"owner": "hyprwm",
"repo": "xdg-desktop-portal-hyprland",
- "rev": "b653ab53a435e92cc00f34771e6823bc59f2f740",
+ "rev": "688feb3d88404598f12440a668136e74044391de",
"type": "github"
},
"original": {
diff --git a/flake.nix b/flake.nix
index e48ef38..f421e00 100644
--- a/flake.nix
+++ b/flake.nix
@@ -379,6 +379,13 @@
}
];
};
+ apollo = lib.nixosSystem { # networking server
+ modules = minimalModuleConfig ++ [ ./machines/apollo
+ # lix-module.nixosModules.default
+ disko.nixosModules.disko
+ home-manager.nixosModules.home-manager { home-manager.users.defin = import ./home-manager/default.nix; }
+ ];
+ };
bosco = lib.nixosSystem { # networking server
modules = minimalModuleConfig ++ [ ./machines/bosco
# lix-module.nixosModules.default
diff --git a/home-manager/default.nix b/home-manager/default.nix
index 38dd60c..2227d13 100644
--- a/home-manager/default.nix
+++ b/home-manager/default.nix
@@ -85,11 +85,11 @@
matchBlocks = {
serverAliveCountMax = 6;
serverAliveInterval = 30;
- port = 2200;
+ # port = 2200;
"git.wormcar.gay" = {
user = "devinf";
host = "git.wormcar.gay";
- port = 2200;
+ # port = 2200;
};
};
};
diff --git a/home-manager/home.nix b/home-manager/home.nix
index 819e684..85fd7c9 100644
--- a/home-manager/home.nix
+++ b/home-manager/home.nix
@@ -189,7 +189,7 @@ in {
"git.wormcar.gay" = {
user = "devinf";
host = "git.wormcar.gay";
- port = 2200;
+ # port = 2200;
};
};
};
diff --git a/machines/apollo/default.nix b/machines/apollo/default.nix
new file mode 100644
index 0000000..7e242bb
--- /dev/null
+++ b/machines/apollo/default.nix
@@ -0,0 +1,132 @@
+# Edit this configuration file to define what should be installed on
+# your system. Help is available in the configuration.nix(5) man page, on
+# https://search.nixos.org/options and in the NixOS manual (`nixos-help`).
+
+{ config, lib, pkgs, ... }:
+
+{
+ imports =
+ [ # Include the results of the hardware scan.
+ ./hardware-configuration.nix
+ ./disko.nix
+
+ ./reverse-proxy.nix
+ ../biski/portforward.nix
+
+ ../../modules/nixos/headscale.nix
+ ../../modules/nixos/cgit.nix
+ ];
+ nixpkgs.hostPlatform = "x86_64-linux";
+ # boot.loader.systemd-boot.enable = true;
+ # boot.loader.efi.efiSysMountPoint = "/boot";
+ # boot.loader.efi.canTouchEfiVariables = true;
+ boot.loader.grub = {
+ enable = true;
+ device = "nodev";
+ efiSupport = true;
+ efiInstallAsRemovable = true;
+ };
+ boot.loader.timeout = 3;
+
+ networking.hostName = "apollo"; # Define your hostname.
+
+ environment.shellInit = ''export NIXPATH="/nix/var/nix/profiles/per-user/$USER/channels:nixos-config=/etc/nixos/machines/apollo/configuration.nix"'';
+
+ # Set your time zone.
+ # time.timeZone = "Europe/Amsterdam";
+
+ # Configure network proxy if necessary
+ # networking.proxy.default = "http://user:password@proxy:port/";
+ # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
+
+ # networking.usePredictableInterfaceNames = false;
+
+ networking.interfaces."eth0".ipv4 = {
+ addresses = [{
+ address = "23.131.76.82";
+ prefixLength = 32;
+ }
+ {
+ address = "172.16.101.82";
+ prefixLength = 24;
+ }];
+ };
+ networking.nameservers = [ "9.9.9.9" ];
+ networking.localCommands = ''
+ ip route add default via 172.16.101.1 src 23.131.76.82
+ ip addr del 172.16.101.82/24 dev eth0
+ '';
+ # ip addr add 23.131.76.82/32 dev ens18
+ # ip route del default
+
+ # Select internationalisation properties.
+ # i18n.defaultLocale = "en_US.UTF-8";
+ # console = {
+ # font = "Lat2-Terminus16";
+ # keyMap = "us";
+ # useXkbConfig = true; # use xkb.options in tty.
+ # };
+
+ # Enable the X11 windowing system.
+ # services.xserver.enable = true;
+
+ # Configure keymap in X11
+ # services.xserver.xkb.layout = "us";
+ # services.xserver.xkb.options = "eurosign:e,caps:escape";
+
+ # List packages installed in system profile. To search, run:
+ # $ nix search wget
+ environment.systemPackages = with pkgs; [
+ # ineutils
+ sysstat
+ ];
+
+ # Some programs need SUID wrappers, can be configured further or are
+ # started in user sessions.
+ programs.mtr.enable = true;
+ # programs.gnupg.agent = {
+ # enable = true;
+ # enableSSHSupport = true;
+ # };
+
+ # List services that you want to enable:
+
+ # Enable the OpenSSH daemon.
+ services.openssh = {
+ enable = true;
+ # settings.PermitRootLogin = "no";
+ ports = [ 22 ];
+ extraConfig = "LoginGraceTime = 0";
+ };
+
+ # Open ports in the firewall.
+ # networking.firewall.allowedTCPPorts = [ ... ];
+ # networking.firewall.allowedUDPPorts = [ ... ];
+ # Or disable the firewall altogether.
+ # networking.firewall.enable = false;
+
+ # Copy the NixOS configuration file and link it from the resulting system
+ # (/run/current-system/configuration.nix). This is useful in case you
+ # accidentally delete configuration.nix.
+ # system.copySystemConfiguration = true;
+
+ # This option defines the first version of NixOS you have installed on this particular machine,
+ # and is used to maintain compatibility with application data (e.g. databases) created on older NixOS versions.
+ #
+ # Most users should NEVER change this value after the initial install, for any reason,
+ # even if you've upgraded your system to a new NixOS release.
+ #
+ # This value does NOT affect the Nixpkgs version your packages and OS are pulled from,
+ # so changing it will NOT upgrade your system.
+ #
+ # This value being lower than the current NixOS release does NOT mean your system is
+ # out of date, out of support, or vulnerable.
+ #
+ # Do NOT change this value unless you have manually inspected all the changes it would make to your configuration,
+ # and migrated your data accordingly.
+ #
+ # For more information, see `man configuration.nix` or https://nixos.org/manual/nixos/stable/options#opt-system.stateVersion .
+ system.stateVersion = "25.11"; # Did you read the comment?
+
+}
+
diff --git a/machines/apollo/disko.nix b/machines/apollo/disko.nix
new file mode 100644
index 0000000..3b5d899
--- /dev/null
+++ b/machines/apollo/disko.nix
@@ -0,0 +1,66 @@
+{
+ # required by impermanence
+ fileSystems."/persist".neededForBoot = true;
+
+ disko.devices = {
+ disk.sda = {
+ type = "disk";
+ device = "/dev/sda";
+ content = {
+ type = "gpt";
+ partitions = {
+ boot = {
+ label = "boot";
+ name = "ESP";
+ # start = "1M";
+ size = "1G";
+ type = "EF00";
+ content = {
+ type = "filesystem";
+ format = "vfat";
+ mountpoint = "/boot";
+ # mountOptions = [ "umask 0077" ];
+ mountOptions = [
+ "defaults"
+ ];
+ };
+ };
+ root = {
+ size = "100%";
+ label = "root";
+ content = {
+ type = "btrfs";
+ extraArgs = [ "-L" "nixos" "-f"];
+ subvolumes = {
+ "@root" = {
+ mountpoint = "/";
+ mountOptions = [ "subvol=root" "compress-force=zstd:5" "nodatacow"];
+ };
+ "@home" = {
+ mountpoint = "/home";
+ mountOptions = [ "subvol=home" "compress-force=zstd:5" "nodatacow"];
+ };
+ "@nix" = {
+ mountpoint = "/nix";
+ mountOptions = [ "subvol=nix" "compress-force=zstd:5" "nodatacow"];
+ };
+ "@persist" = {
+ mountpoint = "/persist";
+ mountOptions = [ "subvol=persist" "compress-force=zstd:5"];
+ };
+ "@log" = {
+ mountpoint = "/var/log";
+ mountOptions = [ "subvol=log" "compress-force=zstd:5" "nodatacow"];
+ };
+ "@swap" = {
+ mountpoint = "/swap";
+ swap.swapfile.size = "4G";
+ };
+ };
+ };
+ };
+ };
+ };
+ };
+ };
+}
diff --git a/machines/apollo/hardware-configuration.nix b/machines/apollo/hardware-configuration.nix
new file mode 100644
index 0000000..ac2c0ba
--- /dev/null
+++ b/machines/apollo/hardware-configuration.nix
@@ -0,0 +1,24 @@
+# Do not modify this file! It was generated by ‘nixos-generate-config’
+# and may be overwritten by future invocations. Please make changes
+# to /etc/nixos/configuration.nix instead.
+{ config, lib, pkgs, modulesPath, ... }:
+
+{
+ imports =
+ [ (modulesPath + "/profiles/qemu-guest.nix")
+ ];
+
+ boot.initrd.availableKernelModules = [ "uhci_hcd" "ehci_pci" "ahci" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
+ boot.initrd.kernelModules = [ ];
+ boot.kernelModules = [ ];
+ boot.extraModulePackages = [ ];
+
+ # Enables DHCP on each ethernet and wireless interface. In case of scripted networking
+ # (the default) this is the recommended approach. When using systemd-networkd it's
+ # still possible to use this option, but it's recommended to use it in conjunction
+ # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
+ networking.useDHCP = lib.mkDefault true;
+ # networking.interfaces.ens18.useDHCP = lib.mkDefault true;
+
+ nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
+}
diff --git a/machines/apollo/reverse-proxy.nix b/machines/apollo/reverse-proxy.nix
new file mode 100644
index 0000000..9d3e382
--- /dev/null
+++ b/machines/apollo/reverse-proxy.nix
@@ -0,0 +1,11 @@
+{ config, ... }: {
+ services.caddy = {
+ enable = true;
+ virtualHosts."foolcreekwireless.com" = {
+ serverAliases = [ "www.foolcreekwireless.com" ];
+ extraConfig = ''
+ reverse_proxy http://doretta
+ '';
+ };
+ };
+}
diff --git a/machines/bosco/default.nix b/machines/bosco/default.nix
index 143db1d..a4e338f 100644
--- a/machines/bosco/default.nix
+++ b/machines/bosco/default.nix
@@ -8,25 +8,26 @@
imports =
[ # Include the results of the hardware scan.
./hardware-configuration.nix
- ./disko.nix
-
./reverse-proxy.nix
- ../biski/portforward.nix
../../modules/nixos/headscale.nix
../../modules/nixos/cgit.nix
];
- nixpkgs.hostPlatform = "x86_64-linux";
- # boot.loader.systemd-boot.enable = true;
- # boot.loader.efi.efiSysMountPoint = "/boot";
- # boot.loader.efi.canTouchEfiVariables = true;
- boot.loader.grub = {
- enable = true;
- device = "nodev";
- efiSupport = true;
- efiInstallAsRemovable = true;
- };
- boot.loader.timeout = 3;
+
+ # Use the GRUB 2 boot loader.
+ boot.loader.grub.enable = true;
+ # boot.loader.grub.efiSupport = true;
+ # boot.loader.grub.efiInstallAsRemovable = true;
+ # boot.loader.efi.efiSysMountPoint = "/boot/efi";
+ # Define on which hard drive you want to install Grub.
+ boot.loader.grub.device = "nodev";
+ boot.loader.timeout = 10;
+ boot.loader.grub.forceInstall = true;
+ boot.loader.grub.extraConfig = ''
+ serial --speed=19200 --unit=0 --word=8 --parity=no --stop=1;
+ terminal_input serial;
+ terminal_output serial
+ '';
networking.hostName = "bosco"; # Define your hostname.
@@ -39,25 +40,7 @@
# networking.proxy.default = "http://user:password@proxy:port/";
# networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
- # networking.usePredictableInterfaceNames = false;
-
- networking.interfaces."eth0".ipv4 = {
- addresses = [{
- address = "23.131.76.82";
- prefixLength = 32;
- }
- {
- address = "172.16.101.82";
- prefixLength = 24;
- }];
- };
- networking.nameservers = [ "9.9.9.9" ];
- networking.localCommands = ''
- ip route add default via 172.16.101.1 src 23.131.76.82
- ip addr del 172.16.101.82/24 dev eth0
- '';
- # ip addr add 23.131.76.82/32 dev ens18
- # ip route del default
+ networking.usePredictableInterfaceNames = false;
# Select internationalisation properties.
# i18n.defaultLocale = "en_US.UTF-8";
@@ -94,7 +77,7 @@
# Enable the OpenSSH daemon.
services.openssh = {
enable = true;
- # settings.PermitRootLogin = "no";
+ settings.PermitRootLogin = "no";
ports = [ 22 ];
extraConfig = "LoginGraceTime = 0";
};
@@ -126,7 +109,7 @@
# and migrated your data accordingly.
#
# For more information, see `man configuration.nix` or https://nixos.org/manual/nixos/stable/options#opt-system.stateVersion .
- system.stateVersion = "25.11"; # Did you read the comment?
+ system.stateVersion = "23.11"; # Did you read the comment?
}
diff --git a/machines/bosco/hardware-configuration.nix b/machines/bosco/hardware-configuration.nix
index ac2c0ba..34dd9bf 100644
--- a/machines/bosco/hardware-configuration.nix
+++ b/machines/bosco/hardware-configuration.nix
@@ -8,17 +8,28 @@
[ (modulesPath + "/profiles/qemu-guest.nix")
];
- boot.initrd.availableKernelModules = [ "uhci_hcd" "ehci_pci" "ahci" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
+ boot.initrd.availableKernelModules = [ "virtio_pci" "virtio_scsi" "ahci" "sd_mod" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
+ fileSystems."/" =
+ { device = "/dev/sda";
+ fsType = "ext4";
+ };
+
+ swapDevices =
+ [ { device = "/dev/sdb"; }
+ ];
+
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
- networking.useDHCP = lib.mkDefault true;
- # networking.interfaces.ens18.useDHCP = lib.mkDefault true;
+ # networking.useDHCP = lib.mkDefault true;
+ networking.interfaces.enp0s5.useDHCP = lib.mkDefault true;
+ # required for ssh?
+ networking.interfaces.eth0.useDHCP = true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
}
diff --git a/modules/nixos/headscale.nix b/modules/nixos/headscale.nix
index f951043..3e00089 100644
--- a/modules/nixos/headscale.nix
+++ b/modules/nixos/headscale.nix
@@ -35,7 +35,7 @@ in {
];
};
prefixes = {
- v4 = "${ipv4}0/10";
+ v4 = "${ipv4}0/16";
v6 = "${ipv6}/48";
};
};
diff --git a/modules/nixos/system-packages.nix b/modules/nixos/system-packages.nix
index 6430915..2061064 100644
--- a/modules/nixos/system-packages.nix
+++ b/modules/nixos/system-packages.nix
@@ -1,5 +1,5 @@
{ pkgs, ...}: {
- # programs.partition-manager.enable = true;
+ programs.partition-manager.enable = true;
environment.systemPackages = with pkgs; [
#For root
age
diff --git a/modules/users/jerry.nix b/modules/users/jerry.nix
index b9f8b95..11963db 100644
--- a/modules/users/jerry.nix
+++ b/modules/users/jerry.nix
@@ -16,7 +16,7 @@
# services.sudo.sshAgentAuth = true;
};
# I can't think of a better spot to put this rn.
- services.openssh = {
- ports = [ 22 2200 ]; # needed because isp blocks ssh over 22
- };
+ # services.openssh = {
+ # ports = [ 22 ]; # needed because isp blocks ssh over 22
+ # };
}