From 3c8807e38f663a20b2f754c7fcbb27fd4acbf03e Mon Sep 17 00:00:00 2001 From: bogale Date: Thu, 17 Sep 2026 17:26:25 +0900 Subject: [PATCH] php-fpm, vaultwarden --- common.nix | 2 ++ marks | 4 ++- server/configuration.nix | 56 +++++++++++++++++++++++++++++++++++----- 3 files changed, 54 insertions(+), 8 deletions(-) diff --git a/common.nix b/common.nix index 759a349..5091582 100644 --- a/common.nix +++ b/common.nix @@ -15,7 +15,9 @@ swapDevices = [ { device = "/var/swapfile"; } ]; boot.loader.limine = { enable = true; + maxGenerations = 20; secureBoot.enable = true; + panicOnChecksumMismatch = true; }; users.users = { root = { diff --git a/marks b/marks index 6101e34..bfff643 100644 --- a/marks +++ b/marks @@ -12,4 +12,6 @@ nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 todo: -- lanzaboote +- php-fpm, postgresql, certbot +- postfix, dovecot, rspamd +- vaultwarden, gitea, mediawiki diff --git a/server/configuration.nix b/server/configuration.nix index 8e8891e..bbe3a86 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -18,21 +18,63 @@ ''; }; }; + #environment.systemPackages = with pkgs; [ + #php + #]; services = { + postgresql.enable = true; openssh = { enable = true; openFirewall = false; + settings = { + PermitRootLogin = "no"; + PasswordAuthentication = false; + }; + }; + phpfpm.pools.main = { + user = "nginx"; + group = "nginx"; + settings = { + "pm" = "ondemand"; + "pm.max_children" = 8; + "listen.owner" = "nginx"; + "listen.group" = "nginx"; + }; }; nginx = { enable = true; - virtualHosts."_".default = true; + recommendedTlsSettings = true; + recommendedGzipSettings = true; + recommendedOptimisation = true; + recommendedProxySettings = true; + recommendedBrotliSettings = true; virtualHosts."_" = { - locations."/" = { - return = "200 'It works'"; - extraConfig = '' - default_type text/html; - ''; - }; + default = true; + root = "/srv/http/_"; + locations."~ \\.php$".extraConfig = '' + fastcgi_pass unix:${config.services.phpfpm.pools.main.socket}; + ''; + }; + }; + vaultwarden = { + enable = true; + configureNginx = true; + dbBackend = "postgresql"; + configurePostgres = true; + package = pkgs.vaultwarden-postgresql; + domain = "https://wg.bogaledev.ru/vault"; + environmentFile = "/root/secrets/vaultwarden.env"; + config = { + EMAIL_TOKEN_SIZE = 8; + SMTP_SECURITY = "off"; + SMTP_HOST = "localhost"; + SIGNUPS_ALLOWED = false; + REQUIRE_DEVICE_EMAIL = true; + TRASH_AUTO_DELETE_DAYS = 90; + ROCKET_ADDRESS = "127.0.0.1"; + PASSWORD_HINTS_ALLOWED = false; + EMERGENCY_ACCESS_ALLOWED = false; + SMTP_FROM = "vaultwarden@bogaledev.ru"; }; }; };