This commit is contained in:
bogale 2026-09-21 23:34:50 +09:00
commit 2e60504041
3 changed files with 54 additions and 23 deletions

View file

@ -59,7 +59,26 @@
environment.systemPackages = with pkgs; [
sbctl
];
systemd.tmpfiles.rules = [ "d /srv/tftp 0755 root root -" ];
services = {
logind.settings.Login.HandleLidSwitch = "ignore";
dnsmasq = {
enable = true;
settings = {
enable-ra = true;
no-resolv = true;
cache-size = 1024;
bogus-priv = true;
enable-tftp = true;
interface = "enp1s0";
domain-needed = true;
tftp-root = "/srv/tftp";
dhcp-boot = "grubx64.efi";
dhcp-range = [ "10.2.0.2,10.2.255.254,12h"
"fc02::2,fc02::ffff:ffff:ffff:ffff,12h" ];
server = [ "1.0.0.1" "2606:4700:4700::1001"
"1.1.1.1" "2606:4700:4700::1111" ];
};
};
};
}

3
marks
View file

@ -12,5 +12,6 @@ nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd
systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 <LUKS_DEV>
todo:
- postfix, dovecot, rspamd
- ssh-add, rspamd
- email tracking
- gitea, mediawiki

View file

@ -16,14 +16,24 @@
};
networking = {
hostName = "nixos-server";
networkmanager.ensureProfiles.profiles.home-wifi = {
wifi.ssid = "bogale_2.4";
wifi-security.psk = "$BOGALE_2_4_PSK";
};
firewall = {
allowedTCPPorts = [ 25 80 443 587 993 ];
allowedUDPPorts = [ 443 ];
};
networkmanager.ensureProfiles.profiles.home-wifi = {
wifi.ssid = "bogale_2.4";
wifi-security.psk = "$BOGALE_2_4_PSK";
ipv4 = {
method = "manual";
gateway = "10.1.0.1";
addresses = "10.1.0.2/16";
};
ipv6 = {
method = "manual";
gateway = "fc01::1";
addresses = "fc01::2/64";
};
};
};
security.acme = {
acceptTerms = true;
@ -32,8 +42,8 @@
dnsProvider = "cloudflare";
email = "letsencrypt@bogaledev.ru";
extraDomainNames = [ "*.bogaledev.ru" ];
reloadServices = [ "nginx.service" "dovecot.service" "postfix.service" ];
credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/secrets/cf-token"; };
reloadServices = [ "nginx.service" "dovecot.service" "postfix.service" ];
};
};
systemd = {
@ -91,6 +101,20 @@
"listen.group" = "nginx";
};
};
vaultwarden = {
enable = true;
dbBackend = "postgresql";
configurePostgres = true;
package = pkgs.vaultwarden-postgresql;
environmentFile = "/secrets/vaultwarden.env";
config = {
SIGNUPS_ALLOWED = false;
TRASH_AUTO_DELETE_DAYS = 90;
PASSWORD_HINTS_ALLOWED = false;
EMERGENCY_ACCESS_ALLOWED = false;
DOMAIN = "https://bogaledev.ru/vw";
};
};
dovecot2 = {
enable = true;
settings = {
@ -99,12 +123,12 @@
mail_uid = "vmail";
protocols.imap = true;
mail_driver = "maildir";
mail_path = "/var/mail/vmail";
auth_mechanisms = [ "plain" ];
dovecot_config_version = "2.4.5";
dovecot_storage_version = "2.4.5";
mail_path = "/var/spool/mail/vmail";
ssl_server_key_file = "${sslCertDir}/key.pem";
ssl_server_cert_file = "${sslCertDir}/fullchain.pem";
dovecot_config_version = config.services.dovecot2.package.version;
"passdb passwd-file".passwd_file_path = "/secrets/dovecot-passwd";
"service auth"."unix_listener ${saslSocket}" = {
mode = "0660";
@ -143,20 +167,6 @@
];
};
};
vaultwarden = {
enable = true;
dbBackend = "postgresql";
configurePostgres = true;
package = pkgs.vaultwarden-postgresql;
environmentFile = "/secrets/vaultwarden.env";
config = {
SIGNUPS_ALLOWED = false;
TRASH_AUTO_DELETE_DAYS = 90;
PASSWORD_HINTS_ALLOWED = false;
EMERGENCY_ACCESS_ALLOWED = false;
DOMAIN = "https://bogaledev.ru/vw";
};
};
nginx = {
enable = true;
recommendedTlsSettings = true;
@ -181,8 +191,9 @@
proxyWebsockets = true;
extraConfig = ''
allow fc00::/64;
allow fc01::/64;
allow 10.0.0.0/24;
allow 192.168.1.0/24;
allow 10.1.0.0/24;
deny all;
'';
};