From 4ee6c7957ca8ad919f18391eb8b004fa29fc18c7 Mon Sep 17 00:00:00 2001 From: bogale Date: Mon, 21 Sep 2026 14:11:36 +0900 Subject: [PATCH] submission configured, vaultwarden url changed --- home/common.nix | 11 ++--- server/configuration.nix | 96 +++++++++++++++++++++++----------------- 2 files changed, 61 insertions(+), 46 deletions(-) diff --git a/home/common.nix b/home/common.nix index cf7c093..7ef07d1 100644 --- a/home/common.nix +++ b/home/common.nix @@ -1,12 +1,13 @@ { config, pkgs, ... }: { - home.stateVersion = "26.05"; + home = { + stateVersion = "26.05"; + packages = with pkgs; [ + gh + ]; + }; programs = { home-manager.enable = true; - gh = { - enable = true; - settings.git_protocol = "ssh"; - }; bash = { enable = true; historyControl = [ "ignoreboth" ]; diff --git a/server/configuration.nix b/server/configuration.nix index 95fe40f..66f156c 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -21,7 +21,7 @@ wifi-security.psk = "$BOGALE_2_4_PSK"; }; firewall = { - allowedTCPPorts = [ 25 80 443 993 ]; + allowedTCPPorts = [ 25 80 443 587 993 ]; allowedUDPPorts = [ 443 ]; }; }; @@ -37,6 +37,21 @@ }; }; systemd = { + tmpfiles.rules = [ + "d /var/spool/postfix 0755 postfix postfix -" + "d /var/spool/postfix/private 0755 postfix postfix -" + ]; + timers.network-watchdog = { + wantedBy = [ "timers.target" ]; + after = [ "NetworkManager.service" ]; + wants = [ "NetworkManager.service" ]; + timerConfig = { + OnBootSec = 5; + AccuracySec = 1; + OnUnitActiveSec = 5; + Unit = "network-watchdog.service"; + }; + }; services.network-watchdog = { path = [ pkgs.iputils ]; serviceConfig.Type = "oneshot"; @@ -46,24 +61,18 @@ else failures=$(($(cat /run/network.failures)+1)) if [ $failures -ge 3 ]; then - systemctl restart NetworkManager + systemctl restart NetworkManager.service failures=0 fi fi echo $failures > /run/network.failures ''; }; - timers.network-watchdog = { - wantedBy = [ "timers.target" ]; - timerConfig = { - OnBootSec = 5; - AccuracySec = 1; - OnUnitActiveSec = 5; - Unit = "network-watchdog.service"; - }; - }; }; - services = { + services = let + saslSocket = "/var/spool/postfix/private/auth"; + sslCertDir = config.security.acme.certs."bogaledev.ru".directory; + in { postgresql.enable = true; openssh = { enable = true; @@ -85,59 +94,67 @@ dovecot2 = { enable = true; settings = { - mail_path = "~"; ssl = "required"; mail_gid = "vmail"; mail_uid = "vmail"; protocols.imap = true; mail_driver = "maildir"; - mail_home = "/var/mail/vmail"; + mail_path = "/var/mail/vmail"; auth_mechanisms = [ "plain" ]; dovecot_config_version = "2.4.5"; dovecot_storage_version = "2.4.5"; - ssl_server_key_file = "/var/lib/acme/bogaledev.ru/key.pem"; - ssl_server_cert_file = "/var/lib/acme/bogaledev.ru/fullchain.pem"; + ssl_server_key_file = "${sslCertDir}/key.pem"; + ssl_server_cert_file = "${sslCertDir}/fullchain.pem"; "passdb passwd-file".passwd_file_path = "/secrets/dovecot-passwd"; + "service auth"."unix_listener ${saslSocket}" = { + mode = "0660"; + user = "postfix"; + group = "postfix"; + }; }; }; postfix = { enable = true; - #enableSubmission = true; + enableSubmission = true; virtualMapType = "regexp"; - virtual = ''/.*@bogaledev.ru/ mail@bogaledev.ru''; - mapFiles.mailbox = pkgs.writeText "mailbox" ''mail@bogaledev.ru /''; + virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru"; + mapFiles = { + smtp_passwd = "/secrets/smtp_passwd"; + mailbox = pkgs.writeText "mailbox" "mail@bogaledev.ru /"; + }; settings.main = { + smtpd_sasl_type = "dovecot"; + smtpd_sasl_path = saslSocket; + smtp_sasl_auth_enable = "yes"; + smtpd_sasl_auth_enable = "yes"; virtual_uid_maps = "static:1819"; virtual_gid_maps = "static:1819"; smtp_tls_security_level = "encrypt"; smtpd_tls_security_level = "encrypt"; + relayhost = [ "smtp.resend.com:2587" ]; virtual_mailbox_domains = "bogaledev.ru"; virtual_mailbox_base = "/var/spool/mail/vmail"; + smtp_sasl_tls_security_options = "noanonymous"; virtual_mailbox_maps = "hash:/etc/postfix/mailbox"; + smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd"; smtpd_tls_chain_files = [ - "/var/lib/acme/bogaledev.ru/key.pem" - "/var/lib/acme/bogaledev.ru/fullchain.pem" + "${sslCertDir}/key.pem" + "${sslCertDir}/fullchain.pem" ]; }; }; vaultwarden = { enable = true; - configureNginx = true; dbBackend = "postgresql"; configurePostgres = true; - domain = "vw.bogaledev.ru"; package = pkgs.vaultwarden-postgresql; environmentFile = "/secrets/vaultwarden.env"; config = { - #EMAIL_TOKEN_SIZE = 8; - #SMTP_SECURITY = "off"; - #SMTP_HOST = "localhost"; SIGNUPS_ALLOWED = false; - #REQUIRE_DEVICE_EMAIL = true; TRASH_AUTO_DELETE_DAYS = 90; PASSWORD_HINTS_ALLOWED = false; EMERGENCY_ACCESS_ALLOWED = false; - #SMTP_FROM = "vaultwarden@bogaledev.ru"; + DOMAIN = "https://bogaledev.ru/vw"; }; }; nginx = { @@ -159,21 +176,18 @@ "~ \\.php$".extraConfig = '' fastcgi_pass unix:${config.services.phpfpm.pools.main.socket}; ''; + "/vw" = { + proxyPass = "http://127.0.0.1:8000"; + proxyWebsockets = true; + extraConfig = '' + allow fc00::/64; + allow 10.0.0.0/24; + allow 192.168.1.0/24; + deny all; + ''; + }; }; }; - virtualHosts."vw.bogaledev.ru" = { - quic = true; - forceSSL = true; - useACMEHost = "bogaledev.ru"; - serverAliases = [ "vw-wl.bogaledev.ru" ]; - extraConfig = '' - allow fc00::/64; - allow 10.0.0.0/24; - allow 192.168.1.0/24; - deny all; - add_header Alt-Svc 'h3=":443"; ma=86400' always; - ''; - }; }; }; }