diff --git a/common.nix b/common.nix index 0ad1256..15dbef3 100644 --- a/common.nix +++ b/common.nix @@ -23,10 +23,7 @@ panicOnChecksumMismatch = true; }; }; - users = { - groups.secrets.gid = 1578; - users.root.hashedPasswordFile = "/secrets/user-root-pw"; - }; + users.users.root.hashedPasswordFile = "/secrets/user/root-pw"; networking = { firewall = { allowedTCPPorts = [ 53 80 ]; diff --git a/desktop/configuration.nix b/desktop/configuration.nix index 74f6ac4..19e88d3 100644 --- a/desktop/configuration.nix +++ b/desktop/configuration.nix @@ -5,11 +5,16 @@ hostName = "nixos-desktop"; }; users.users = { + data = { + isNormalUser = true; + home = "/home/data"; + hashedPasswordFile = "/secrets/user/data-pw"; + }; bogale = { isNormalUser = true; home = "/home/bogale"; extraGroups = [ "wheel" ]; - hashedPasswordFile = "/secrets/bogale.passwd"; + hashedPasswordFile = "/secrets/user/bogale-pw"; }; }; } diff --git a/home/common.nix b/home/common.nix index 113d1dc..dfc98a0 100644 --- a/home/common.nix +++ b/home/common.nix @@ -2,6 +2,9 @@ { home.stateVersion = "26.05"; services.ssh-agent.enable = true; + home.packages = with pkgs; [ + yt-dlp + ]; programs = { home-manager.enable = true; bash = { diff --git a/marks b/marks index 9c79fbc..c489329 100644 --- a/marks +++ b/marks @@ -12,5 +12,5 @@ nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 todo: -- mediawiki, wordpress +- mediawiki - email tracking diff --git a/server/configuration.nix b/server/configuration.nix index 42b3407..555f184 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -14,8 +14,7 @@ vmail.gid = 1819; }; users = { - nginx.extraGroups = [ "acme" ]; - dovecot2.extraGroups = [ "secrets" ]; + nginx.extraGroups = [ "php" "acme" ]; root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ]; php = { uid = 1568; diff --git a/server/mods/mail.nix b/server/mods/mail.nix index 67b93a1..49b2e4b 100644 --- a/server/mods/mail.nix +++ b/server/mods/mail.nix @@ -12,12 +12,9 @@ rspamd = { enable = true; postfix.enable = true; - locals = { - "classifier-bayes.conf".text = "autolearn = true;"; - "redis.conf".text = '' - servers = "${config.services.redis.servers.rspamd.unixSocket}"; - ''; - }; + locals."redis.conf".text = '' + servers = "${config.services.redis.servers.rspamd.unixSocket}"; + ''; }; dovecot2 = { enable = true; diff --git a/server/mods/sysd.nix b/server/mods/sysd.nix index 21b9f7a..565825e 100644 --- a/server/mods/sysd.nix +++ b/server/mods/sysd.nix @@ -31,9 +31,13 @@ serviceConfig.Type = "oneshot"; script = '' . /secrets/tgbot.env - ${pkgs.curl}/bin/curl "https://api.telegram.org/$BOT/sendMessage" \ - -X POST -d "chat_id=$CHAT_ID" -d "text=$TEXT" 2> /dev/null | \ - ${pkgs.jq}/bin/jq '.result.date |= strftime("%Y-%m-%d %H:%M:%S")' + for msg in "''${MESSAGES[@]}"; do + TEXT="''${msg#*:}" + CHAT_ID="''${msg%%:*}" + ${pkgs.curl}/bin/curl -X POST "https://api.telegram.org/$BOT/sendMessage" \ + -d "chat_id=$CHAT_ID" -d "text=$TEXT" 2> /dev/null | ${pkgs.jq}/bin/jq + sleep 1 + done ''; }; network-watchdog = { @@ -43,12 +47,10 @@ }; script = '' if [ ! -e /run/network.failures ] || \ - ${pkgs.iputils}/bin/ping -c 1 -W 3 1.1.1.1 &> /dev/null; then + ${pkgs.iputils}/bin/ping -c 1 -W 3 1.1.1.1; then failures=0 else failures=$((1+$(cat /run/network.failures))) - fi - if [ $failures -gt 0 ]; then echo "<5>failures = $failures" fi if [ $failures -ge 3 ]; then diff --git a/server/mods/web.nix b/server/mods/web.nix index e0ceb10..3320a33 100644 --- a/server/mods/web.nix +++ b/server/mods/web.nix @@ -59,11 +59,9 @@ ''; localNetworks = '' allow fc00::/64; - allow fc01::/64; - allow fc02::/64; + allow fc01::/120; allow 10.0.0.0/16; - allow 10.1.0.0/16; - allow 10.2.0.0/16; + allow 10.1.0.0/24; deny all; ''; in { @@ -76,7 +74,12 @@ locations = { "/app/".extraConfig = phpPool "default"; "/git/".proxyPass = "http://127.0.0.1:8039/"; - "/priv/".extraConfig = ''${localNetworks} ${phpPool "default"}''; + "/local/".extraConfig = ''${phpPool "default"} ${localNetworks}''; + "/local/net/".extraConfig = '' + allow fc01::/64; + allow 10.1.0.0/16; + deny all; + ''; "/vw/" = { proxyWebsockets = true; extraConfig = localNetworks;