hardware rewrite

This commit is contained in:
bogale 2026-10-07 09:54:55 +09:00
commit 277291f346
8 changed files with 40 additions and 50 deletions

View file

@ -16,7 +16,7 @@
openssl grub2_efi openssl grub2_efi
]; ];
fileSystems = let fileSystems = let
noatime = { options = [ "noatime" ]; }; noatime.options = [ "noatime" ];
in { in {
"/" = noatime; "/" = noatime;
"/boot" = noatime; "/boot" = noatime;

View file

@ -1,6 +1,6 @@
{ config, lib, pkgs, ... }: { config, lib, pkgs, ... }:
{ {
imports = [ ../common.nix ./hardware-configuration.nix ]; imports = [ ../common.nix ./hardware.nix ];
users.users = { users.users = {
data = { data = {
uid = 1256; uid = 1256;

View file

@ -1,13 +1,8 @@
{ config, lib, pkgs, ... }: { config, lib, pkgs, ... }:
{ {
imports = [ ../common.nix ./hardware-configuration.nix boot.kernelParams = [ "consoleblank=60" ];
./mods/web.nix ./mods/mail.nix ./mods/sysd.nix ]; imports = [ ../common.nix ./hardware.nix
boot.kernelParams = [ ./mods/web.nix ./mods/mail.nix ./mods/system.nix ];
"consoleblank=60"
#TPM fix
"memmap=0x4000%0xbfb76000-4"
"memmap=0x4000%0xbfb7a000-4"
];
security.acme = { security.acme = {
acceptTerms = true; acceptTerms = true;
defaults.email = "letsencrypt@bogaledev.ru"; defaults.email = "letsencrypt@bogaledev.ru";
@ -20,7 +15,7 @@
}; };
}; };
systemd.tmpfiles.rules = [ systemd.tmpfiles.rules = [
"d /root/backup/server 0700 root root -" "d /root/backup/server"
"L /root/backup/server/http - - - - /srv/http" "L /root/backup/server/http - - - - /srv/http"
"L /root/backup/server/acme - - - - /var/lib/acme" "L /root/backup/server/acme - - - - /var/lib/acme"
"L /root/backup/server/mail - - - - /var/spool/mail" "L /root/backup/server/mail - - - - /var/spool/mail"
@ -35,9 +30,6 @@
}; };
users = { users = {
nginx.extraGroups = [ "php" "acme" ]; nginx.extraGroups = [ "php" "acme" ];
root.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow"
];
php = { php = {
uid = 1568; uid = 1568;
group = "php"; group = "php";
@ -48,6 +40,9 @@
group = "vmail"; group = "vmail";
isSystemUser = true; isSystemUser = true;
}; };
root.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow"
];
}; };
}; };
networking = { networking = {

View file

@ -1,33 +0,0 @@
# Do not modify this file! It was generated by ‘nixos-generate-config’
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/mapper/root";
fsType = "ext4";
};
boot.initrd.luks.devices."root".device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609";
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/86F4-A8F1";
fsType = "vfat";
options = [ "fmask=0077" "dmask=0077" ];
};
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}

27
server/hardware.nix Normal file
View file

@ -0,0 +1,27 @@
{ config, lib, pkgs, modulesPath, ... }:
{
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
boot = {
kernelParams = [
"memmap=0x4000%0xbfb76000-4"
"memmap=0x4000%0xbfb7a000-4"
];
initrd = {
availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ];
luks.devices.root.device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609";
};
};
fileSystems = {
"/" = {
fsType = "ext4";
device = "/dev/mapper/root";
};
"/boot" = {
fsType = "vfat";
device = "/dev/disk/by-uuid/86F4-A8F1";
options = [ "fmask=0077" "dmask=0077" ];
};
};
}

View file

@ -3,7 +3,7 @@ let
postfixDir = "/var/spool/postfix"; postfixDir = "/var/spool/postfix";
in { in {
systemd.tmpfiles.rules = [ systemd.tmpfiles.rules = [
"d ${postfixDir} 0700 postfix postfix -" "d ${postfixDir} 0700 postfix postfix"
]; ];
services = let services = let
sslCertDir = config.security.acme.certs."bogaledev.ru".directory; sslCertDir = config.security.acme.certs."bogaledev.ru".directory;

View file

@ -30,7 +30,7 @@
wantedBy = [ "timers.target" ]; wantedBy = [ "timers.target" ];
timerConfig = { timerConfig = {
Persistent = true; Persistent = true;
OnCalendar = "*-*-01 16:00:00"; OnCalendar = "*-*-01 16:00";
}; };
}; };
network-watchdog = { network-watchdog = {

View file

@ -5,6 +5,7 @@
in { in {
postgresqlBackup = { postgresqlBackup = {
enable = true; enable = true;
startAt = "16:00";
compression = "zstd"; compression = "zstd";
databases = [ "php" "vaultwarden" ]; databases = [ "php" "vaultwarden" ];
}; };
@ -19,7 +20,6 @@
phpfpm.pools.php = { phpfpm.pools.php = {
user = "php"; user = "php";
group = "php"; group = "php";
phpEnv = { PATH = "/run/current-system/sw/bin"; };
settings = { settings = {
"pm" = "ondemand"; "pm" = "ondemand";
"pm.max_children" = 4; "pm.max_children" = 4;
@ -48,6 +48,7 @@
dump = { dump = {
enable = true; enable = true;
type = "tar.zst"; type = "tar.zst";
interval = "16:00";
}; };
settings = { settings = {
service = { service = {