summaryrefslogtreecommitdiff
path: root/machines/apollo
diff options
context:
space:
mode:
Diffstat (limited to 'machines/apollo')
-rw-r--r--machines/apollo/default.nix132
-rw-r--r--machines/apollo/disko.nix66
-rw-r--r--machines/apollo/hardware-configuration.nix24
-rw-r--r--machines/apollo/reverse-proxy.nix11
4 files changed, 233 insertions, 0 deletions
diff --git a/machines/apollo/default.nix b/machines/apollo/default.nix
new file mode 100644
index 0000000..7e242bb
--- /dev/null
+++ b/machines/apollo/default.nix
@@ -0,0 +1,132 @@
+# Edit this configuration file to define what should be installed on
+# your system. Help is available in the configuration.nix(5) man page, on
+# https://search.nixos.org/options and in the NixOS manual (`nixos-help`).
+
+{ config, lib, pkgs, ... }:
+
+{
+ imports =
+ [ # Include the results of the hardware scan.
+ ./hardware-configuration.nix
+ ./disko.nix
+
+ ./reverse-proxy.nix
+ ../biski/portforward.nix
+
+ ../../modules/nixos/headscale.nix
+ ../../modules/nixos/cgit.nix
+ ];
+ nixpkgs.hostPlatform = "x86_64-linux";
+ # boot.loader.systemd-boot.enable = true;
+ # boot.loader.efi.efiSysMountPoint = "/boot";
+ # boot.loader.efi.canTouchEfiVariables = true;
+ boot.loader.grub = {
+ enable = true;
+ device = "nodev";
+ efiSupport = true;
+ efiInstallAsRemovable = true;
+ };
+ boot.loader.timeout = 3;
+
+ networking.hostName = "apollo"; # Define your hostname.
+
+ environment.shellInit = ''export NIXPATH="/nix/var/nix/profiles/per-user/$USER/channels:nixos-config=/etc/nixos/machines/apollo/configuration.nix"'';
+
+ # Set your time zone.
+ # time.timeZone = "Europe/Amsterdam";
+
+ # Configure network proxy if necessary
+ # networking.proxy.default = "http://user:password@proxy:port/";
+ # networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
+
+ # networking.usePredictableInterfaceNames = false;
+
+ networking.interfaces."eth0".ipv4 = {
+ addresses = [{
+ address = "23.131.76.82";
+ prefixLength = 32;
+ }
+ {
+ address = "172.16.101.82";
+ prefixLength = 24;
+ }];
+ };
+ networking.nameservers = [ "9.9.9.9" ];
+ networking.localCommands = ''
+ ip route add default via 172.16.101.1 src 23.131.76.82
+ ip addr del 172.16.101.82/24 dev eth0
+ '';
+ # ip addr add 23.131.76.82/32 dev ens18
+ # ip route del default
+
+ # Select internationalisation properties.
+ # i18n.defaultLocale = "en_US.UTF-8";
+ # console = {
+ # font = "Lat2-Terminus16";
+ # keyMap = "us";
+ # useXkbConfig = true; # use xkb.options in tty.
+ # };
+
+ # Enable the X11 windowing system.
+ # services.xserver.enable = true;
+
+ # Configure keymap in X11
+ # services.xserver.xkb.layout = "us";
+ # services.xserver.xkb.options = "eurosign:e,caps:escape";
+
+ # List packages installed in system profile. To search, run:
+ # $ nix search wget
+ environment.systemPackages = with pkgs; [
+ # ineutils
+ sysstat
+ ];
+
+ # Some programs need SUID wrappers, can be configured further or are
+ # started in user sessions.
+ programs.mtr.enable = true;
+ # programs.gnupg.agent = {
+ # enable = true;
+ # enableSSHSupport = true;
+ # };
+
+ # List services that you want to enable:
+
+ # Enable the OpenSSH daemon.
+ services.openssh = {
+ enable = true;
+ # settings.PermitRootLogin = "no";
+ ports = [ 22 ];
+ extraConfig = "LoginGraceTime = 0";
+ };
+
+ # Open ports in the firewall.
+ # networking.firewall.allowedTCPPorts = [ ... ];
+ # networking.firewall.allowedUDPPorts = [ ... ];
+ # Or disable the firewall altogether.
+ # networking.firewall.enable = false;
+
+ # Copy the NixOS configuration file and link it from the resulting system
+ # (/run/current-system/configuration.nix). This is useful in case you
+ # accidentally delete configuration.nix.
+ # system.copySystemConfiguration = true;
+
+ # This option defines the first version of NixOS you have installed on this particular machine,
+ # and is used to maintain compatibility with application data (e.g. databases) created on older NixOS versions.
+ #
+ # Most users should NEVER change this value after the initial install, for any reason,
+ # even if you've upgraded your system to a new NixOS release.
+ #
+ # This value does NOT affect the Nixpkgs version your packages and OS are pulled from,
+ # so changing it will NOT upgrade your system.
+ #
+ # This value being lower than the current NixOS release does NOT mean your system is
+ # out of date, out of support, or vulnerable.
+ #
+ # Do NOT change this value unless you have manually inspected all the changes it would make to your configuration,
+ # and migrated your data accordingly.
+ #
+ # For more information, see `man configuration.nix` or https://nixos.org/manual/nixos/stable/options#opt-system.stateVersion .
+ system.stateVersion = "25.11"; # Did you read the comment?
+
+}
+
diff --git a/machines/apollo/disko.nix b/machines/apollo/disko.nix
new file mode 100644
index 0000000..3b5d899
--- /dev/null
+++ b/machines/apollo/disko.nix
@@ -0,0 +1,66 @@
+{
+ # required by impermanence
+ fileSystems."/persist".neededForBoot = true;
+
+ disko.devices = {
+ disk.sda = {
+ type = "disk";
+ device = "/dev/sda";
+ content = {
+ type = "gpt";
+ partitions = {
+ boot = {
+ label = "boot";
+ name = "ESP";
+ # start = "1M";
+ size = "1G";
+ type = "EF00";
+ content = {
+ type = "filesystem";
+ format = "vfat";
+ mountpoint = "/boot";
+ # mountOptions = [ "umask 0077" ];
+ mountOptions = [
+ "defaults"
+ ];
+ };
+ };
+ root = {
+ size = "100%";
+ label = "root";
+ content = {
+ type = "btrfs";
+ extraArgs = [ "-L" "nixos" "-f"];
+ subvolumes = {
+ "@root" = {
+ mountpoint = "/";
+ mountOptions = [ "subvol=root" "compress-force=zstd:5" "nodatacow"];
+ };
+ "@home" = {
+ mountpoint = "/home";
+ mountOptions = [ "subvol=home" "compress-force=zstd:5" "nodatacow"];
+ };
+ "@nix" = {
+ mountpoint = "/nix";
+ mountOptions = [ "subvol=nix" "compress-force=zstd:5" "nodatacow"];
+ };
+ "@persist" = {
+ mountpoint = "/persist";
+ mountOptions = [ "subvol=persist" "compress-force=zstd:5"];
+ };
+ "@log" = {
+ mountpoint = "/var/log";
+ mountOptions = [ "subvol=log" "compress-force=zstd:5" "nodatacow"];
+ };
+ "@swap" = {
+ mountpoint = "/swap";
+ swap.swapfile.size = "4G";
+ };
+ };
+ };
+ };
+ };
+ };
+ };
+ };
+}
diff --git a/machines/apollo/hardware-configuration.nix b/machines/apollo/hardware-configuration.nix
new file mode 100644
index 0000000..ac2c0ba
--- /dev/null
+++ b/machines/apollo/hardware-configuration.nix
@@ -0,0 +1,24 @@
+# Do not modify this file! It was generated by ‘nixos-generate-config’
+# and may be overwritten by future invocations. Please make changes
+# to /etc/nixos/configuration.nix instead.
+{ config, lib, pkgs, modulesPath, ... }:
+
+{
+ imports =
+ [ (modulesPath + "/profiles/qemu-guest.nix")
+ ];
+
+ boot.initrd.availableKernelModules = [ "uhci_hcd" "ehci_pci" "ahci" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
+ boot.initrd.kernelModules = [ ];
+ boot.kernelModules = [ ];
+ boot.extraModulePackages = [ ];
+
+ # Enables DHCP on each ethernet and wireless interface. In case of scripted networking
+ # (the default) this is the recommended approach. When using systemd-networkd it's
+ # still possible to use this option, but it's recommended to use it in conjunction
+ # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
+ networking.useDHCP = lib.mkDefault true;
+ # networking.interfaces.ens18.useDHCP = lib.mkDefault true;
+
+ nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
+}
diff --git a/machines/apollo/reverse-proxy.nix b/machines/apollo/reverse-proxy.nix
new file mode 100644
index 0000000..9d3e382
--- /dev/null
+++ b/machines/apollo/reverse-proxy.nix
@@ -0,0 +1,11 @@
+{ config, ... }: {
+ services.caddy = {
+ enable = true;
+ virtualHosts."foolcreekwireless.com" = {
+ serverAliases = [ "www.foolcreekwireless.com" ];
+ extraConfig = ''
+ reverse_proxy http://doretta
+ '';
+ };
+ };
+}