ssh-agent, rspamd
This commit is contained in:
parent
2e60504041
commit
0eccc75207
14 changed files with 80 additions and 85 deletions
26
common.nix
26
common.nix
|
|
@ -24,20 +24,12 @@
|
||||||
panicOnChecksumMismatch = true;
|
panicOnChecksumMismatch = true;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
users.users = {
|
users.users.root.hashedPasswordFile = "/secrets/root.passwd";
|
||||||
root = {
|
|
||||||
home = "/root";
|
|
||||||
hashedPasswordFile = "/secrets/root.passwd";
|
|
||||||
};
|
|
||||||
bogale = {
|
|
||||||
isNormalUser = true;
|
|
||||||
home = "/home/bogale";
|
|
||||||
extraGroups = [ "wheel" ];
|
|
||||||
hashedPasswordFile = "/secrets/bogale.passwd";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
networking = {
|
networking = {
|
||||||
nftables.enable = true;
|
firewall = {
|
||||||
|
allowedTCPPorts = [ 53 80 ];
|
||||||
|
allowedUDPPorts = [ 53 67 69 547 ];
|
||||||
|
};
|
||||||
wg-quick.interfaces.awg0 = {
|
wg-quick.interfaces.awg0 = {
|
||||||
type = "amneziawg";
|
type = "amneziawg";
|
||||||
configFile = "/secrets/awg0.conf";
|
configFile = "/secrets/awg0.conf";
|
||||||
|
|
@ -62,6 +54,14 @@
|
||||||
systemd.tmpfiles.rules = [ "d /srv/tftp 0755 root root -" ];
|
systemd.tmpfiles.rules = [ "d /srv/tftp 0755 root root -" ];
|
||||||
services = {
|
services = {
|
||||||
logind.settings.Login.HandleLidSwitch = "ignore";
|
logind.settings.Login.HandleLidSwitch = "ignore";
|
||||||
|
nginx = {
|
||||||
|
enable = true;
|
||||||
|
recommendedTlsSettings = true;
|
||||||
|
recommendedGzipSettings = true;
|
||||||
|
recommendedOptimisation = true;
|
||||||
|
recommendedProxySettings = true;
|
||||||
|
recommendedBrotliSettings = true;
|
||||||
|
};
|
||||||
dnsmasq = {
|
dnsmasq = {
|
||||||
enable = true;
|
enable = true;
|
||||||
settings = {
|
settings = {
|
||||||
|
|
|
||||||
|
|
@ -4,4 +4,12 @@
|
||||||
networking = {
|
networking = {
|
||||||
hostName = "nixos-desktop";
|
hostName = "nixos-desktop";
|
||||||
};
|
};
|
||||||
|
users.users = {
|
||||||
|
bogale = {
|
||||||
|
isNormalUser = true;
|
||||||
|
home = "/home/bogale";
|
||||||
|
extraGroups = [ "wheel" ];
|
||||||
|
hashedPasswordFile = "/secrets/bogale.passwd";
|
||||||
|
};
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -16,7 +16,6 @@
|
||||||
home-manager.useUserPackages = true;
|
home-manager.useUserPackages = true;
|
||||||
home-manager.extraSpecialArgs = { inherit inputs; };
|
home-manager.extraSpecialArgs = { inherit inputs; };
|
||||||
home-manager.users.root = ./home/server/root.nix;
|
home-manager.users.root = ./home/server/root.nix;
|
||||||
home-manager.users.bogale = ./home/server/bogale.nix;
|
|
||||||
}
|
}
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -1,6 +0,0 @@
|
||||||
{ config, pkgs, ... }:
|
|
||||||
{
|
|
||||||
imports = [ ./common.nix ];
|
|
||||||
home.username = "bogale";
|
|
||||||
home.homeDirectory = "/home/bogale";
|
|
||||||
}
|
|
||||||
|
|
@ -6,6 +6,7 @@
|
||||||
gh
|
gh
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
services.ssh-agent.enable = true;
|
||||||
programs = {
|
programs = {
|
||||||
home-manager.enable = true;
|
home-manager.enable = true;
|
||||||
bash = {
|
bash = {
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,8 @@
|
||||||
{ config, pkgs, ... }:
|
{ config, pkgs, ... }:
|
||||||
{
|
{
|
||||||
imports = [ ./common.nix ../bogale.nix ];
|
imports = [ ../common.nix ];
|
||||||
|
home = {
|
||||||
|
username = "bogale";
|
||||||
|
homeDirectory = "/home/bogale";
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,3 +0,0 @@
|
||||||
{ config, pkgs, ... }:
|
|
||||||
{
|
|
||||||
}
|
|
||||||
|
|
@ -1,4 +1,8 @@
|
||||||
{ config, pkgs, ... }:
|
{ config, pkgs, ... }:
|
||||||
{
|
{
|
||||||
imports = [ ./common.nix ../root.nix ];
|
imports = [ ../common.nix ];
|
||||||
|
home = {
|
||||||
|
username = "root";
|
||||||
|
homeDirectory = "/root";
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,6 +0,0 @@
|
||||||
{ config, pkgs, ... }:
|
|
||||||
{
|
|
||||||
imports = [ ./common.nix ];
|
|
||||||
home.username = "root";
|
|
||||||
home.homeDirectory = "/root";
|
|
||||||
}
|
|
||||||
|
|
@ -1,4 +0,0 @@
|
||||||
{ config, pkgs, ... }:
|
|
||||||
{
|
|
||||||
imports = [ ./common.nix ../bogale.nix ];
|
|
||||||
}
|
|
||||||
|
|
@ -1,3 +0,0 @@
|
||||||
{ config, pkgs, ... }:
|
|
||||||
{
|
|
||||||
}
|
|
||||||
|
|
@ -1,4 +1,8 @@
|
||||||
{ config, pkgs, ... }:
|
{ config, pkgs, ... }:
|
||||||
{
|
{
|
||||||
imports = [ ./common.nix ../root.nix ];
|
imports = [ ../common.nix ];
|
||||||
|
home = {
|
||||||
|
username = "root";
|
||||||
|
homeDirectory = "/root";
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
4
marks
4
marks
|
|
@ -12,6 +12,6 @@ nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd
|
||||||
systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 <LUKS_DEV>
|
systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 <LUKS_DEV>
|
||||||
|
|
||||||
todo:
|
todo:
|
||||||
- ssh-add, rspamd
|
|
||||||
- email tracking
|
|
||||||
- gitea, mediawiki
|
- gitea, mediawiki
|
||||||
|
- email tracking
|
||||||
|
- redirect randomizer
|
||||||
|
|
|
||||||
|
|
@ -6,7 +6,7 @@
|
||||||
groups.vmail.gid = 1819;
|
groups.vmail.gid = 1819;
|
||||||
users = {
|
users = {
|
||||||
nginx.extraGroups = [ "acme" ];
|
nginx.extraGroups = [ "acme" ];
|
||||||
bogale.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ];
|
root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ];
|
||||||
vmail = {
|
vmail = {
|
||||||
uid = 1819;
|
uid = 1819;
|
||||||
group = "vmail";
|
group = "vmail";
|
||||||
|
|
@ -17,7 +17,7 @@
|
||||||
networking = {
|
networking = {
|
||||||
hostName = "nixos-server";
|
hostName = "nixos-server";
|
||||||
firewall = {
|
firewall = {
|
||||||
allowedTCPPorts = [ 25 80 443 587 993 ];
|
allowedTCPPorts = [ 25 443 587 993 ];
|
||||||
allowedUDPPorts = [ 443 ];
|
allowedUDPPorts = [ 443 ];
|
||||||
};
|
};
|
||||||
networkmanager.ensureProfiles.profiles.home-wifi = {
|
networkmanager.ensureProfiles.profiles.home-wifi = {
|
||||||
|
|
@ -37,10 +37,10 @@
|
||||||
};
|
};
|
||||||
security.acme = {
|
security.acme = {
|
||||||
acceptTerms = true;
|
acceptTerms = true;
|
||||||
|
defaults.email = "letsencrypt@bogaledev.ru";
|
||||||
certs."bogaledev.ru" = {
|
certs."bogaledev.ru" = {
|
||||||
validMinDays = 3;
|
validMinDays = 3;
|
||||||
dnsProvider = "cloudflare";
|
dnsProvider = "cloudflare";
|
||||||
email = "letsencrypt@bogaledev.ru";
|
|
||||||
extraDomainNames = [ "*.bogaledev.ru" ];
|
extraDomainNames = [ "*.bogaledev.ru" ];
|
||||||
credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/secrets/cf-token"; };
|
credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/secrets/cf-token"; };
|
||||||
reloadServices = [ "nginx.service" "dovecot.service" "postfix.service" ];
|
reloadServices = [ "nginx.service" "dovecot.service" "postfix.service" ];
|
||||||
|
|
@ -53,8 +53,6 @@
|
||||||
];
|
];
|
||||||
timers.network-watchdog = {
|
timers.network-watchdog = {
|
||||||
wantedBy = [ "timers.target" ];
|
wantedBy = [ "timers.target" ];
|
||||||
after = [ "NetworkManager.service" ];
|
|
||||||
wants = [ "NetworkManager.service" ];
|
|
||||||
timerConfig = {
|
timerConfig = {
|
||||||
OnBootSec = 5;
|
OnBootSec = 5;
|
||||||
AccuracySec = 1;
|
AccuracySec = 1;
|
||||||
|
|
@ -64,7 +62,10 @@
|
||||||
};
|
};
|
||||||
services.network-watchdog = {
|
services.network-watchdog = {
|
||||||
path = [ pkgs.iputils ];
|
path = [ pkgs.iputils ];
|
||||||
serviceConfig.Type = "oneshot";
|
serviceConfig = {
|
||||||
|
Type = "oneshot";
|
||||||
|
LogLevelMax = "notice";
|
||||||
|
};
|
||||||
script = ''
|
script = ''
|
||||||
if [ ! -e /run/network.failures ] || ping -c 1 -W 3 1.1.1.1 &> /dev/null; then
|
if [ ! -e /run/network.failures ] || ping -c 1 -W 3 1.1.1.1 &> /dev/null; then
|
||||||
failures=0
|
failures=0
|
||||||
|
|
@ -76,6 +77,9 @@
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
echo $failures > /run/network.failures
|
echo $failures > /run/network.failures
|
||||||
|
if [ $failures -ge 0 ]; then
|
||||||
|
echo "<5>failures = $failures"
|
||||||
|
fi
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
@ -83,14 +87,11 @@
|
||||||
saslSocket = "/var/spool/postfix/private/auth";
|
saslSocket = "/var/spool/postfix/private/auth";
|
||||||
sslCertDir = config.security.acme.certs."bogaledev.ru".directory;
|
sslCertDir = config.security.acme.certs."bogaledev.ru".directory;
|
||||||
in {
|
in {
|
||||||
postgresql.enable = true;
|
|
||||||
openssh = {
|
openssh = {
|
||||||
enable = true;
|
enable = true;
|
||||||
settings = {
|
settings.PasswordAuthentication = false;
|
||||||
PermitRootLogin = "no";
|
|
||||||
PasswordAuthentication = false;
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
|
postgresql.enable = true;
|
||||||
phpfpm.pools.main = {
|
phpfpm.pools.main = {
|
||||||
user = "nginx";
|
user = "nginx";
|
||||||
group = "nginx";
|
group = "nginx";
|
||||||
|
|
@ -115,6 +116,35 @@
|
||||||
DOMAIN = "https://bogaledev.ru/vw";
|
DOMAIN = "https://bogaledev.ru/vw";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
nginx.virtualHosts."bogaledev.ru" = {
|
||||||
|
quic = true;
|
||||||
|
default = true;
|
||||||
|
forceSSL = true;
|
||||||
|
root = "/srv/http";
|
||||||
|
useACMEHost = "bogaledev.ru";
|
||||||
|
extraConfig = ''add_header Alt-Svc 'h3=":443"; ma=86400' always;'';
|
||||||
|
locations = {
|
||||||
|
"/".index = "index.php index.html";
|
||||||
|
"~ \\.php$".extraConfig = ''
|
||||||
|
fastcgi_pass unix:${config.services.phpfpm.pools.main.socket};
|
||||||
|
'';
|
||||||
|
"/vw" = {
|
||||||
|
proxyPass = "http://127.0.0.1:8000";
|
||||||
|
proxyWebsockets = true;
|
||||||
|
extraConfig = ''
|
||||||
|
allow fc00::/64;
|
||||||
|
allow fc01::/64;
|
||||||
|
allow 10.0.0.0/24;
|
||||||
|
allow 10.1.0.0/24;
|
||||||
|
deny all;
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
rspamd = {
|
||||||
|
enable = true;
|
||||||
|
postfix.enable = true;
|
||||||
|
};
|
||||||
dovecot2 = {
|
dovecot2 = {
|
||||||
enable = true;
|
enable = true;
|
||||||
settings = {
|
settings = {
|
||||||
|
|
@ -167,38 +197,5 @@
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
nginx = {
|
|
||||||
enable = true;
|
|
||||||
recommendedTlsSettings = true;
|
|
||||||
recommendedGzipSettings = true;
|
|
||||||
recommendedOptimisation = true;
|
|
||||||
recommendedProxySettings = true;
|
|
||||||
recommendedBrotliSettings = true;
|
|
||||||
virtualHosts."bogaledev.ru" = {
|
|
||||||
quic = true;
|
|
||||||
default = true;
|
|
||||||
forceSSL = true;
|
|
||||||
root = "/srv/http";
|
|
||||||
useACMEHost = "bogaledev.ru";
|
|
||||||
extraConfig = ''add_header Alt-Svc 'h3=":443"; ma=86400' always;'';
|
|
||||||
locations = {
|
|
||||||
"/".index = "index.php index.html";
|
|
||||||
"~ \\.php$".extraConfig = ''
|
|
||||||
fastcgi_pass unix:${config.services.phpfpm.pools.main.socket};
|
|
||||||
'';
|
|
||||||
"/vw" = {
|
|
||||||
proxyPass = "http://127.0.0.1:8000";
|
|
||||||
proxyWebsockets = true;
|
|
||||||
extraConfig = ''
|
|
||||||
allow fc00::/64;
|
|
||||||
allow fc01::/64;
|
|
||||||
allow 10.0.0.0/24;
|
|
||||||
allow 10.1.0.0/24;
|
|
||||||
deny all;
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue