diff --git a/common.nix b/common.nix index 90a8a9e..48e228f 100644 --- a/common.nix +++ b/common.nix @@ -16,7 +16,7 @@ openssl grub2_efi ]; fileSystems = let - noatime = { options = [ "noatime" ]; }; + noatime.options = [ "noatime" ]; in { "/" = noatime; "/boot" = noatime; diff --git a/desktop/configuration.nix b/desktop/configuration.nix index 5ad287a..5865f22 100644 --- a/desktop/configuration.nix +++ b/desktop/configuration.nix @@ -1,6 +1,6 @@ { config, lib, pkgs, ... }: { - imports = [ ../common.nix ./hardware-configuration.nix ]; + imports = [ ../common.nix ./hardware.nix ]; users.users = { data = { uid = 1256; diff --git a/install.sh b/install.sh index 2e87fac..c105463 100644 --- a/install.sh +++ b/install.sh @@ -1,4 +1,3 @@ -set -euo pipefail gdisk $DISK mkfs.fat -F 32 $ESPPART cryptsetup luksFormat $ROOTPART @@ -9,7 +8,6 @@ mount $ESPPART --mkdir -o umask=077 /mnt/boot mkdir /mnt/var mkswap -F -s $SWAPSIZE /mnt/var/swapfile swapon /mnt/var/swapfile -mkdir -p /mnt/etc/nixos nixos-generate-config --root /mnt --kernel latest --flake #copy backup nixos-install --no-root-passwd --no-channel-copy --flake "/mnt/etc/nixos#nixos" diff --git a/server/configuration.nix b/server/configuration.nix index e85bec7..bc2308c 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -1,13 +1,8 @@ { config, lib, pkgs, ... }: { - imports = [ ../common.nix ./hardware-configuration.nix - ./mods/web.nix ./mods/mail.nix ./mods/sysd.nix ]; - boot.kernelParams = [ - "consoleblank=60" - #TPM fix - "memmap=0x4000%0xbfb76000-4" - "memmap=0x4000%0xbfb7a000-4" - ]; + boot.kernelParams = [ "consoleblank=60" ]; + imports = [ ../common.nix ./hardware.nix + ./mods/web.nix ./mods/mail.nix ./mods/system.nix ]; security.acme = { acceptTerms = true; defaults.email = "letsencrypt@bogaledev.ru"; @@ -20,7 +15,7 @@ }; }; systemd.tmpfiles.rules = [ - "d /root/backup/server 0700 root root -" + "d /root/backup/server" "L /root/backup/server/http - - - - /srv/http" "L /root/backup/server/acme - - - - /var/lib/acme" "L /root/backup/server/mail - - - - /var/spool/mail" @@ -35,9 +30,6 @@ }; users = { nginx.extraGroups = [ "php" "acme" ]; - root.openssh.authorizedKeys.keys = [ - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" - ]; php = { uid = 1568; group = "php"; @@ -48,6 +40,9 @@ group = "vmail"; isSystemUser = true; }; + root.openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" + ]; }; }; networking = { diff --git a/server/hardware-configuration.nix b/server/hardware-configuration.nix deleted file mode 100644 index 6b53763..0000000 --- a/server/hardware-configuration.nix +++ /dev/null @@ -1,33 +0,0 @@ -# Do not modify this file! It was generated by ‘nixos-generate-config’ -# and may be overwritten by future invocations. Please make changes -# to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: - -{ - imports = - [ (modulesPath + "/installer/scan/not-detected.nix") - ]; - - boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ]; - boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ ]; - boot.extraModulePackages = [ ]; - - fileSystems."/" = - { device = "/dev/mapper/root"; - fsType = "ext4"; - }; - - boot.initrd.luks.devices."root".device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609"; - - fileSystems."/boot" = - { device = "/dev/disk/by-uuid/86F4-A8F1"; - fsType = "vfat"; - options = [ "fmask=0077" "dmask=0077" ]; - }; - - swapDevices = [ ]; - - nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; - hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; -} diff --git a/server/hardware.nix b/server/hardware.nix new file mode 100644 index 0000000..f76336e --- /dev/null +++ b/server/hardware.nix @@ -0,0 +1,27 @@ +{ config, lib, pkgs, modulesPath, ... }: +{ + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; + imports = [ (modulesPath + "/installer/scan/not-detected.nix") ]; + hardware.cpu.amd.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; + boot = { + kernelParams = [ + "memmap=0x4000%0xbfb76000-4" + "memmap=0x4000%0xbfb7a000-4" + ]; + initrd = { + availableKernelModules = [ "xhci_pci" "ahci" "ehci_pci" "sd_mod" "sdhci_pci" ]; + luks.devices.root.device = "/dev/disk/by-uuid/e0288e5e-87eb-453f-ab22-0d6e54576609"; + }; + }; + fileSystems = { + "/" = { + fsType = "ext4"; + device = "/dev/mapper/root"; + }; + "/boot" = { + fsType = "vfat"; + device = "/dev/disk/by-uuid/86F4-A8F1"; + options = [ "fmask=0077" "dmask=0077" ]; + }; + }; +} diff --git a/server/mods/mail.nix b/server/mods/mail.nix index 0630e99..1b9e8a8 100644 --- a/server/mods/mail.nix +++ b/server/mods/mail.nix @@ -3,7 +3,7 @@ let postfixDir = "/var/spool/postfix"; in { systemd.tmpfiles.rules = [ - "d ${postfixDir} 0700 postfix postfix -" + "d ${postfixDir} 0700 postfix postfix" ]; services = let sslCertDir = config.security.acme.certs."bogaledev.ru".directory; diff --git a/server/mods/sysd.nix b/server/mods/system.nix similarity index 98% rename from server/mods/sysd.nix rename to server/mods/system.nix index e569309..2695b23 100644 --- a/server/mods/sysd.nix +++ b/server/mods/system.nix @@ -30,7 +30,7 @@ wantedBy = [ "timers.target" ]; timerConfig = { Persistent = true; - OnCalendar = "*-*-01 16:00:00"; + OnCalendar = "*-*-01 16:00"; }; }; network-watchdog = { diff --git a/server/mods/web.nix b/server/mods/web.nix index 6ee8b24..f23d552 100644 --- a/server/mods/web.nix +++ b/server/mods/web.nix @@ -5,6 +5,7 @@ in { postgresqlBackup = { enable = true; + startAt = "16:00"; compression = "zstd"; databases = [ "php" "vaultwarden" ]; }; @@ -19,7 +20,6 @@ phpfpm.pools.php = { user = "php"; group = "php"; - phpEnv = { PATH = "/run/current-system/sw/bin"; }; settings = { "pm" = "ondemand"; "pm.max_children" = 4; @@ -48,6 +48,7 @@ dump = { enable = true; type = "tar.zst"; + interval = "16:00"; }; settings = { service = {