switched to unstable, amneziawg configured

This commit is contained in:
bogale 2026-09-17 23:30:14 +09:00
commit 26d383ea96
10 changed files with 110 additions and 75 deletions

View file

@ -13,11 +13,16 @@
"/boot" = { options = [ "noatime" ]; }; "/boot" = { options = [ "noatime" ]; };
}; };
swapDevices = [ { device = "/var/swapfile"; } ]; swapDevices = [ { device = "/var/swapfile"; } ];
boot.loader.limine = { boot = {
enable = true; kernelModules = [ "amneziawg" ];
maxGenerations = 20; kernelPackages = pkgs.linuxPackages_latest;
secureBoot.enable = true; extraModulePackages = [ config.boot.kernelPackages.amneziawg ];
panicOnChecksumMismatch = true; loader.limine = {
enable = true;
maxGenerations = 20;
secureBoot.enable = true;
panicOnChecksumMismatch = true;
};
}; };
users.users = { users.users = {
root = { root = {
@ -33,24 +38,25 @@
}; };
networking = { networking = {
nftables.enable = true; nftables.enable = true;
#networking.wg-quick.interfaces.awg0 = { wg-quick.interfaces.awg0 = {
#type = "amneziawg"; type = "amneziawg";
#configFile = "/root/secrets/awg0.conf"; configFile = "/root/secrets/awg0.conf";
#}; };
networkmanager = { networkmanager = {
enable = true; enable = true;
ensureProfiles.profiles.home-wifi = { ensureProfiles = {
wifi-security.key-mgmt = "sae"; environmentFiles = [ "/root/secrets/wifi.env" ];
connection = { profiles.home-wifi = {
id = "home-wifi"; wifi-security.key-mgmt = "sae";
type = "wifi"; connection = {
id = "home-wifi";
type = "wifi";
};
}; };
}; };
}; };
}; };
environment.systemPackages = with pkgs; [ environment.systemPackages = with pkgs; [
amneziawg-go
amneziawg-tools
sbctl sbctl
]; ];
services = { services = {

View file

@ -0,0 +1,7 @@
{ config, lib, pkgs, ... }:
{
imports = [ ../common.nix ./hardware-configuration.nix ];
networking = {
hostName = "nixos-desktop";
};
}

View file

@ -7,32 +7,31 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1789267039, "lastModified": 1789618856,
"narHash": "sha256-LWiBv9yAYFi2LPbUhDGHPGKYskJQjj2fw12OlyO1uQo=", "narHash": "sha256-OSqj7eOijvCZfN7owFWRxLWRhej5lZI+Kt82q3INLvc=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "ec172013fa62135f58fb58dd17ae9651e8f39727", "rev": "afa6821c70560bb19d1a8c577bff398f7f239869",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "nix-community", "owner": "nix-community",
"ref": "release-26.05",
"repo": "home-manager", "repo": "home-manager",
"type": "github" "type": "github"
} }
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1789459628, "lastModified": 1789546076,
"narHash": "sha256-JOaadoI/IC9qEvwlnjwAhwdcWkCDqEeOJ+cOtUH/8RQ=", "narHash": "sha256-zVxLZiSnmaaPLwnhj7pwmqe3axBg/C6nG5JZsJMh2g4=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "b67c7a60c3732edd4b947a7df8af06215851a614", "rev": "b1b875982b17dabde9b4a37f3e229e74913e6db3",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "NixOS", "owner": "NixOS",
"ref": "nixos-26.05", "ref": "nixos-unstable",
"repo": "nixpkgs", "repo": "nixpkgs",
"type": "github" "type": "github"
} }

37
flake.nix Normal file
View file

@ -0,0 +1,37 @@
{
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
home-manager = {
url = "github:nix-community/home-manager";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = inputs@{ self, nixpkgs, home-manager, ... }: {
nixosConfigurations = {
nixos-server = nixpkgs.lib.nixosSystem {
modules = [
./server/configuration.nix
home-manager.nixosModules.home-manager {
home-manager.useGlobalPkgs = true;
home-manager.useUserPackages = true;
home-manager.extraSpecialArgs = { inherit inputs; };
home-manager.users.root = ./home/server/root.nix;
home-manager.users.bogale = ./home/server/bogale.nix;
}
];
};
nixos-desktop = nixpkgs.lib.nixosSystem {
modules = [
./desktop/configuration.nix
home-manager.nixosModules.home-manager {
home-manager.useGlobalPkgs = true;
home-manager.useUserPackages = true;
home-manager.extraSpecialArgs = { inherit inputs; };
home-manager.users.root = ./home/desktop/root.nix;
home-manager.users.bogale = ./home/desktop/bogale.nix;
}
];
};
};
};
}

4
home/desktop/bogale.nix Normal file
View file

@ -0,0 +1,4 @@
{ config, pkgs, ... }:
{
imports = [ ./common.nix ../bogale.nix ];
}

7
home/desktop/common.nix Normal file
View file

@ -0,0 +1,7 @@
{ config, pkgs, ... }:
{
programs.tmux.extraConfig = ''
set -g prefix M-f
bind f send-prefix
'';
}

4
home/desktop/root.nix Normal file
View file

@ -0,0 +1,4 @@
{ config, pkgs, ... }:
{
imports = [ ./common.nix ../root.nix ];
}

View file

@ -1,7 +1,4 @@
{ config, pkgs, ... }: { config, pkgs, ... }:
{ {
imports = [ ./common.nix ../root.nix ]; imports = [ ./common.nix ../root.nix ];
programs.bash = {
shellAliases = { "nixos-rebuild" = "nixos-rebuild --impure --flake /etc/nixos/server#nixos-server"; };
};
} }

View file

@ -9,7 +9,7 @@
hostName = "nixos-server"; hostName = "nixos-server";
networkmanager.ensureProfiles.profiles.home-wifi = { networkmanager.ensureProfiles.profiles.home-wifi = {
wifi.ssid = "bogale_2.4"; wifi.ssid = "bogale_2.4";
wifi-security.psk = builtins.readFile "/root/secrets/home-wifi.psk"; wifi-security.psk = "$BOGALE_2_4_PSK";
}; };
firewall = { firewall = {
allowedTCPPorts = [ 80 ]; allowedTCPPorts = [ 80 ];
@ -18,9 +18,6 @@
''; '';
}; };
}; };
#environment.systemPackages = with pkgs; [
#php
#];
services = { services = {
postgresql.enable = true; postgresql.enable = true;
openssh = { openssh = {
@ -56,26 +53,26 @@
''; '';
}; };
}; };
vaultwarden = { #vaultwarden = {
enable = true; #enable = true;
configureNginx = true; #configureNginx = true;
dbBackend = "postgresql"; #dbBackend = "postgresql";
configurePostgres = true; #configurePostgres = true;
package = pkgs.vaultwarden-postgresql; #package = pkgs.vaultwarden-postgresql;
domain = "https://wg.bogaledev.ru/vault"; #domain = "https://wg.bogaledev.ru/vault";
environmentFile = "/root/secrets/vaultwarden.env"; #environmentFile = "/root/secrets/vaultwarden.env";
config = { #config = {
EMAIL_TOKEN_SIZE = 8; #EMAIL_TOKEN_SIZE = 8;
SMTP_SECURITY = "off"; #SMTP_SECURITY = "off";
SMTP_HOST = "localhost"; #SMTP_HOST = "localhost";
SIGNUPS_ALLOWED = false; #SIGNUPS_ALLOWED = false;
REQUIRE_DEVICE_EMAIL = true; #REQUIRE_DEVICE_EMAIL = true;
TRASH_AUTO_DELETE_DAYS = 90; #TRASH_AUTO_DELETE_DAYS = 90;
ROCKET_ADDRESS = "127.0.0.1"; #ROCKET_ADDRESS = "127.0.0.1";
PASSWORD_HINTS_ALLOWED = false; #PASSWORD_HINTS_ALLOWED = false;
EMERGENCY_ACCESS_ALLOWED = false; #EMERGENCY_ACCESS_ALLOWED = false;
SMTP_FROM = "vaultwarden@bogaledev.ru"; #SMTP_FROM = "vaultwarden@bogaledev.ru";
}; #};
}; #};
}; };
} }

View file

@ -1,23 +0,0 @@
{
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
home-manager = {
url = "github:nix-community/home-manager/release-26.05";
inputs.nixpkgs.follows = "nixpkgs";
};
};
outputs = inputs@{ self, nixpkgs, home-manager, ... }: {
nixosConfigurations.nixos-server = nixpkgs.lib.nixosSystem {
modules = [
./configuration.nix
home-manager.nixosModules.home-manager {
home-manager.useGlobalPkgs = true;
home-manager.useUserPackages = true;
home-manager.extraSpecialArgs = { inherit inputs; };
home-manager.users.root = ../home/server/root.nix;
home-manager.users.bogale = ../home/server/bogale.nix;
}
];
};
};
}