hardware rewrite

This commit is contained in:
bogale 2026-10-07 14:09:53 +09:00
commit 4dd5416eb6
9 changed files with 40 additions and 52 deletions

View file

@ -16,7 +16,7 @@
openssl grub2_efi
];
fileSystems = let
noatime = { options = [ "noatime" ]; };
noatime.options = [ "noatime" ];
in {
"/" = noatime;
"/boot" = noatime;

View file

@ -1,6 +1,6 @@
{ config, lib, pkgs, ... }:
{
imports = [ ../common.nix ./hardware-configuration.nix ];
imports = [ ../common.nix ./hardware.nix ];
users.users = {
data = {
uid = 1256;

View file

@ -1,4 +1,3 @@
set -euo pipefail
gdisk $DISK
mkfs.fat -F 32 $ESPPART
cryptsetup luksFormat $ROOTPART
@ -9,7 +8,6 @@ mount $ESPPART --mkdir -o umask=077 /mnt/boot
mkdir /mnt/var
mkswap -F -s $SWAPSIZE /mnt/var/swapfile
swapon /mnt/var/swapfile
mkdir -p /mnt/etc/nixos
nixos-generate-config --root /mnt --kernel latest --flake
#copy backup
nixos-install --no-root-passwd --no-channel-copy --flake "/mnt/etc/nixos#nixos"

View file

@ -1,13 +1,8 @@
{ config, lib, pkgs, ... }:
{
imports = [ ../common.nix ./hardware-configuration.nix
./mods/web.nix ./mods/mail.nix ./mods/sysd.nix ];
boot.kernelParams = [
"consoleblank=60"
#TPM fix
"memmap=0x4000%0xbfb76000-4"
"memmap=0x4000%0xbfb7a000-4"
];
boot.kernelParams = [ "consoleblank=60" ];
imports = [ ../common.nix ./hardware.nix
./mods/web.nix ./mods/mail.nix ./mods/system.nix ];
security.acme = {
acceptTerms = true;
defaults.email = "letsencrypt@bogaledev.ru";
@ -20,7 +15,7 @@
};
};
systemd.tmpfiles.rules = [
"d /root/backup/server 0700 root root -"
"d /root/backup/server"
"L /root/backup/server/http - - - - /srv/http"
"L /root/backup/server/acme - - - - /var/lib/acme"
"L /root/backup/server/mail - - - - /var/spool/mail"
@ -35,9 +30,6 @@
};
users = {
nginx.extraGroups = [ "php" "acme" ];
root.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow"
];
php = {
uid = 1568;
group = "php";
@ -48,6 +40,9 @@
group = "vmail";
isSystemUser = true;
};
root.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow"
];
};
};
networking = {

View file

@ -1,33 +0,0 @@
# Do not modify this file! It was generated by ‘nixos-generate-config’
# and may be overwritten by future invocations. Please make changes
# to /etc/nixos/configuration.nix instead.
{ config, lib, pkgs, modulesPath, ... }:
{
imports =
[ (modulesPath + "/installer/scan/not-detected.nix")
];
boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ ];
boot.extraModulePackages = [ ];
fileSystems."/" =
{ device = "/dev/mapper/root";
fsType = "ext4";
};
boot.initrd.luks.devices."root".device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609";
fileSystems."/boot" =
{ device = "/dev/disk/by-uuid/86F4-A8F1";
fsType = "vfat";
options = [ "fmask=0077" "dmask=0077" ];
};
swapDevices = [ ];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
}

27
server/hardware.nix Normal file
View file

@ -0,0 +1,27 @@
{ config, lib, pkgs, modulesPath, ... }:
{
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ];
hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
boot = {
kernelParams = [
"memmap=0x4000%0xbfb76000-4"
"memmap=0x4000%0xbfb7a000-4"
];
initrd = {
availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ];
luks.devices.root.device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609";
};
};
fileSystems = {
"/" = {
fsType = "ext4";
device = "/dev/mapper/root";
};
"/boot" = {
fsType = "vfat";
device = "/dev/disk/by-uuid/86F4-A8F1";
options = [ "fmask=0077" "dmask=0077" ];
};
};
}

View file

@ -3,7 +3,7 @@ let
postfixDir = "/var/spool/postfix";
in {
systemd.tmpfiles.rules = [
"d ${postfixDir} 0700 postfix postfix -"
"d ${postfixDir} 0700 postfix postfix"
];
services = let
sslCertDir = config.security.acme.certs."bogaledev.ru".directory;

View file

@ -30,7 +30,7 @@
wantedBy = [ "timers.target" ];
timerConfig = {
Persistent = true;
OnCalendar = "*-*-01 16:00:00";
OnCalendar = "*-*-01 16:00";
};
};
network-watchdog = {

View file

@ -5,6 +5,7 @@
in {
postgresqlBackup = {
enable = true;
startAt = "16:00";
compression = "zstd";
databases = [ "php" "vaultwarden" ];
};
@ -19,7 +20,6 @@
phpfpm.pools.php = {
user = "php";
group = "php";
phpEnv = { PATH = "/run/current-system/sw/bin"; };
settings = {
"pm" = "ondemand";
"pm.max_children" = 4;
@ -48,6 +48,7 @@
dump = {
enable = true;
type = "tar.zst";
interval = "16:00";
};
settings = {
service = {