network-watchdog, dovecot
This commit is contained in:
parent
8967478f21
commit
5894fa9aa5
3 changed files with 55 additions and 13 deletions
|
|
@ -27,25 +27,25 @@
|
||||||
users.users = {
|
users.users = {
|
||||||
root = {
|
root = {
|
||||||
home = "/root";
|
home = "/root";
|
||||||
hashedPasswordFile = "/root/secrets/root.passwd";
|
hashedPasswordFile = "/secrets/root.passwd";
|
||||||
};
|
};
|
||||||
bogale = {
|
bogale = {
|
||||||
isNormalUser = true;
|
isNormalUser = true;
|
||||||
home = "/home/bogale";
|
home = "/home/bogale";
|
||||||
extraGroups = [ "wheel" ];
|
extraGroups = [ "wheel" ];
|
||||||
hashedPasswordFile = "/root/secrets/bogale.passwd";
|
hashedPasswordFile = "/secrets/bogale.passwd";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
networking = {
|
networking = {
|
||||||
nftables.enable = true;
|
nftables.enable = true;
|
||||||
wg-quick.interfaces.awg0 = {
|
wg-quick.interfaces.awg0 = {
|
||||||
type = "amneziawg";
|
type = "amneziawg";
|
||||||
configFile = "/root/secrets/awg0.conf";
|
configFile = "/secrets/awg0.conf";
|
||||||
};
|
};
|
||||||
networkmanager = {
|
networkmanager = {
|
||||||
enable = true;
|
enable = true;
|
||||||
ensureProfiles = {
|
ensureProfiles = {
|
||||||
environmentFiles = [ "/root/secrets/wifi.env" ];
|
environmentFiles = [ "/secrets/wifi.env" ];
|
||||||
profiles.home-wifi = {
|
profiles.home-wifi = {
|
||||||
wifi-security.key-mgmt = "sae";
|
wifi-security.key-mgmt = "sae";
|
||||||
connection = {
|
connection = {
|
||||||
|
|
|
||||||
|
|
@ -3,6 +3,10 @@
|
||||||
home.stateVersion = "26.05";
|
home.stateVersion = "26.05";
|
||||||
programs = {
|
programs = {
|
||||||
home-manager.enable = true;
|
home-manager.enable = true;
|
||||||
|
gh = {
|
||||||
|
enable = true;
|
||||||
|
settings.git_protocol = "ssh";
|
||||||
|
};
|
||||||
bash = {
|
bash = {
|
||||||
enable = true;
|
enable = true;
|
||||||
historyControl = [ "ignoreboth" ];
|
historyControl = [ "ignoreboth" ];
|
||||||
|
|
|
||||||
|
|
@ -21,7 +21,7 @@
|
||||||
wifi-security.psk = "$BOGALE_2_4_PSK";
|
wifi-security.psk = "$BOGALE_2_4_PSK";
|
||||||
};
|
};
|
||||||
firewall = {
|
firewall = {
|
||||||
allowedTCPPorts = [ 25 80 443 ];
|
allowedTCPPorts = [ 25 80 443 993 ];
|
||||||
allowedUDPPorts = [ 443 ];
|
allowedUDPPorts = [ 443 ];
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
@ -30,10 +30,37 @@
|
||||||
certs."bogaledev.ru" = {
|
certs."bogaledev.ru" = {
|
||||||
validMinDays = 3;
|
validMinDays = 3;
|
||||||
dnsProvider = "cloudflare";
|
dnsProvider = "cloudflare";
|
||||||
email = "acme-tls@bogaledev.ru";
|
email = "letsencrypt@bogaledev.ru";
|
||||||
reloadServices = [ "nginx.service" ];
|
|
||||||
extraDomainNames = [ "*.bogaledev.ru" ];
|
extraDomainNames = [ "*.bogaledev.ru" ];
|
||||||
credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/root/secrets/cf-token"; };
|
reloadServices = [ "nginx.service" "dovecot.service" "postfix.service" ];
|
||||||
|
credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/secrets/cf-token"; };
|
||||||
|
};
|
||||||
|
};
|
||||||
|
systemd = {
|
||||||
|
services.network-watchdog = {
|
||||||
|
path = [ pkgs.iputils ];
|
||||||
|
serviceConfig.Type = "oneshot";
|
||||||
|
script = ''
|
||||||
|
if [ ! -e /run/network.failures ] || ping -c 1 -W 3 1.1.1.1 &> /dev/null; then
|
||||||
|
failures=0
|
||||||
|
else
|
||||||
|
failures=$(($(cat /run/network.failures)+1))
|
||||||
|
if [ $failures -ge 3 ]; then
|
||||||
|
systemctl restart NetworkManager
|
||||||
|
failures=0
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
echo $failures > /run/network.failures
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
timers.network-watchdog = {
|
||||||
|
wantedBy = [ "timers.target" ];
|
||||||
|
timerConfig = {
|
||||||
|
OnBootSec = 5;
|
||||||
|
AccuracySec = 1;
|
||||||
|
OnUnitActiveSec = 5;
|
||||||
|
Unit = "network-watchdog.service";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
services = {
|
services = {
|
||||||
|
|
@ -58,16 +85,27 @@
|
||||||
dovecot2 = {
|
dovecot2 = {
|
||||||
enable = true;
|
enable = true;
|
||||||
settings = {
|
settings = {
|
||||||
mail_uid = ;
|
mail_path = "~";
|
||||||
mail_gid = ;
|
ssl = "required";
|
||||||
|
mail_gid = "vmail";
|
||||||
|
mail_uid = "vmail";
|
||||||
|
protocols.imap = true;
|
||||||
|
mail_driver = "maildir";
|
||||||
|
mail_home = "/var/mail/vmail";
|
||||||
|
auth_mechanisms = [ "plain" ];
|
||||||
|
dovecot_config_version = "2.4.5";
|
||||||
|
dovecot_storage_version = "2.4.5";
|
||||||
|
ssl_server_key_file = "/var/lib/acme/bogaledev.ru/key.pem";
|
||||||
|
ssl_server_cert_file = "/var/lib/acme/bogaledev.ru/fullchain.pem";
|
||||||
|
"passdb passwd-file".passwd_file_path = "/secrets/dovecot-passwd";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
postfix = {
|
postfix = {
|
||||||
enable = true;
|
enable = true;
|
||||||
#enableSubmission = true;
|
#enableSubmission = true;
|
||||||
virtualMapType = "regexp";
|
virtualMapType = "regexp";
|
||||||
virtual = ''/.*@bogaledev.ru/ main@bogaledev.ru'';
|
virtual = ''/.*@bogaledev.ru/ mail@bogaledev.ru'';
|
||||||
mapFiles.mailbox = pkgs.writeText "mailbox" ''main@bogaledev.ru bogaledev.ru/'';
|
mapFiles.mailbox = pkgs.writeText "mailbox" ''mail@bogaledev.ru /'';
|
||||||
settings.main = {
|
settings.main = {
|
||||||
virtual_uid_maps = "static:1819";
|
virtual_uid_maps = "static:1819";
|
||||||
virtual_gid_maps = "static:1819";
|
virtual_gid_maps = "static:1819";
|
||||||
|
|
@ -89,7 +127,7 @@
|
||||||
configurePostgres = true;
|
configurePostgres = true;
|
||||||
domain = "vw.bogaledev.ru";
|
domain = "vw.bogaledev.ru";
|
||||||
package = pkgs.vaultwarden-postgresql;
|
package = pkgs.vaultwarden-postgresql;
|
||||||
environmentFile = "/root/secrets/vaultwarden.env";
|
environmentFile = "/secrets/vaultwarden.env";
|
||||||
config = {
|
config = {
|
||||||
#EMAIL_TOKEN_SIZE = 8;
|
#EMAIL_TOKEN_SIZE = 8;
|
||||||
#SMTP_SECURITY = "off";
|
#SMTP_SECURITY = "off";
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue