From 5894fa9aa58c68d2a9357ecd4ee70b3fa09208ae Mon Sep 17 00:00:00 2001 From: bogale Date: Mon, 21 Sep 2026 03:22:17 +0900 Subject: [PATCH] network-watchdog, dovecot --- common.nix | 8 +++--- home/common.nix | 4 +++ server/configuration.nix | 56 +++++++++++++++++++++++++++++++++------- 3 files changed, 55 insertions(+), 13 deletions(-) diff --git a/common.nix b/common.nix index e37a063..7f0551a 100644 --- a/common.nix +++ b/common.nix @@ -27,25 +27,25 @@ users.users = { root = { home = "/root"; - hashedPasswordFile = "/root/secrets/root.passwd"; + hashedPasswordFile = "/secrets/root.passwd"; }; bogale = { isNormalUser = true; home = "/home/bogale"; extraGroups = [ "wheel" ]; - hashedPasswordFile = "/root/secrets/bogale.passwd"; + hashedPasswordFile = "/secrets/bogale.passwd"; }; }; networking = { nftables.enable = true; wg-quick.interfaces.awg0 = { type = "amneziawg"; - configFile = "/root/secrets/awg0.conf"; + configFile = "/secrets/awg0.conf"; }; networkmanager = { enable = true; ensureProfiles = { - environmentFiles = [ "/root/secrets/wifi.env" ]; + environmentFiles = [ "/secrets/wifi.env" ]; profiles.home-wifi = { wifi-security.key-mgmt = "sae"; connection = { diff --git a/home/common.nix b/home/common.nix index f8166fb..cf7c093 100644 --- a/home/common.nix +++ b/home/common.nix @@ -3,6 +3,10 @@ home.stateVersion = "26.05"; programs = { home-manager.enable = true; + gh = { + enable = true; + settings.git_protocol = "ssh"; + }; bash = { enable = true; historyControl = [ "ignoreboth" ]; diff --git a/server/configuration.nix b/server/configuration.nix index 3cc16ec..95fe40f 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -21,7 +21,7 @@ wifi-security.psk = "$BOGALE_2_4_PSK"; }; firewall = { - allowedTCPPorts = [ 25 80 443 ]; + allowedTCPPorts = [ 25 80 443 993 ]; allowedUDPPorts = [ 443 ]; }; }; @@ -30,10 +30,37 @@ certs."bogaledev.ru" = { validMinDays = 3; dnsProvider = "cloudflare"; - email = "acme-tls@bogaledev.ru"; - reloadServices = [ "nginx.service" ]; + email = "letsencrypt@bogaledev.ru"; extraDomainNames = [ "*.bogaledev.ru" ]; - credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/root/secrets/cf-token"; }; + reloadServices = [ "nginx.service" "dovecot.service" "postfix.service" ]; + credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/secrets/cf-token"; }; + }; + }; + systemd = { + services.network-watchdog = { + path = [ pkgs.iputils ]; + serviceConfig.Type = "oneshot"; + script = '' + if [ ! -e /run/network.failures ] || ping -c 1 -W 3 1.1.1.1 &> /dev/null; then + failures=0 + else + failures=$(($(cat /run/network.failures)+1)) + if [ $failures -ge 3 ]; then + systemctl restart NetworkManager + failures=0 + fi + fi + echo $failures > /run/network.failures + ''; + }; + timers.network-watchdog = { + wantedBy = [ "timers.target" ]; + timerConfig = { + OnBootSec = 5; + AccuracySec = 1; + OnUnitActiveSec = 5; + Unit = "network-watchdog.service"; + }; }; }; services = { @@ -58,16 +85,27 @@ dovecot2 = { enable = true; settings = { - mail_uid = ; - mail_gid = ; + mail_path = "~"; + ssl = "required"; + mail_gid = "vmail"; + mail_uid = "vmail"; + protocols.imap = true; + mail_driver = "maildir"; + mail_home = "/var/mail/vmail"; + auth_mechanisms = [ "plain" ]; + dovecot_config_version = "2.4.5"; + dovecot_storage_version = "2.4.5"; + ssl_server_key_file = "/var/lib/acme/bogaledev.ru/key.pem"; + ssl_server_cert_file = "/var/lib/acme/bogaledev.ru/fullchain.pem"; + "passdb passwd-file".passwd_file_path = "/secrets/dovecot-passwd"; }; }; postfix = { enable = true; #enableSubmission = true; virtualMapType = "regexp"; - virtual = ''/.*@bogaledev.ru/ main@bogaledev.ru''; - mapFiles.mailbox = pkgs.writeText "mailbox" ''main@bogaledev.ru bogaledev.ru/''; + virtual = ''/.*@bogaledev.ru/ mail@bogaledev.ru''; + mapFiles.mailbox = pkgs.writeText "mailbox" ''mail@bogaledev.ru /''; settings.main = { virtual_uid_maps = "static:1819"; virtual_gid_maps = "static:1819"; @@ -89,7 +127,7 @@ configurePostgres = true; domain = "vw.bogaledev.ru"; package = pkgs.vaultwarden-postgresql; - environmentFile = "/root/secrets/vaultwarden.env"; + environmentFile = "/secrets/vaultwarden.env"; config = { #EMAIL_TOKEN_SIZE = 8; #SMTP_SECURITY = "off";