grafana, prometheus
This commit is contained in:
parent
e94686a940
commit
5ee0a9c5cf
6 changed files with 69 additions and 30 deletions
|
|
@ -26,6 +26,7 @@
|
||||||
home-manager.useGlobalPkgs = true;
|
home-manager.useGlobalPkgs = true;
|
||||||
home-manager.useUserPackages = true;
|
home-manager.useUserPackages = true;
|
||||||
home-manager.extraSpecialArgs = { inherit inputs; };
|
home-manager.extraSpecialArgs = { inherit inputs; };
|
||||||
|
home-manager.users.data = ./home/desktop/data.nix;
|
||||||
home-manager.users.root = ./home/desktop/root.nix;
|
home-manager.users.root = ./home/desktop/root.nix;
|
||||||
home-manager.users.bogale = ./home/desktop/bogale.nix;
|
home-manager.users.bogale = ./home/desktop/bogale.nix;
|
||||||
}
|
}
|
||||||
|
|
|
||||||
8
home/desktop/data.nix
Normal file
8
home/desktop/data.nix
Normal file
|
|
@ -0,0 +1,8 @@
|
||||||
|
{ config, pkgs, ... }:
|
||||||
|
{
|
||||||
|
imports = [ ../common.nix ];
|
||||||
|
home = {
|
||||||
|
username = "data";
|
||||||
|
homeDirectory = "/home/data";
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
@ -15,7 +15,9 @@
|
||||||
};
|
};
|
||||||
users = {
|
users = {
|
||||||
nginx.extraGroups = [ "php" "acme" ];
|
nginx.extraGroups = [ "php" "acme" ];
|
||||||
root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ];
|
root.openssh.authorizedKeys.keys = [
|
||||||
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow"
|
||||||
|
];
|
||||||
php = {
|
php = {
|
||||||
uid = 1568;
|
uid = 1568;
|
||||||
group = "php";
|
group = "php";
|
||||||
|
|
@ -31,8 +33,8 @@
|
||||||
networking = {
|
networking = {
|
||||||
hostName = "nixos-server";
|
hostName = "nixos-server";
|
||||||
firewall = {
|
firewall = {
|
||||||
allowedTCPPorts = [ 25 443 465 993 ];
|
|
||||||
allowedUDPPorts = [ 443 ];
|
allowedUDPPorts = [ 443 ];
|
||||||
|
allowedTCPPorts = [ 25 443 465 993 ];
|
||||||
};
|
};
|
||||||
wg-quick.interfaces.awg0 = {
|
wg-quick.interfaces.awg0 = {
|
||||||
configFile = "/secrets/awg/1.conf";
|
configFile = "/secrets/awg/1.conf";
|
||||||
|
|
@ -45,4 +47,15 @@
|
||||||
wifi-security.psk = "$BOGALE_2_4_PSK";
|
wifi-security.psk = "$BOGALE_2_4_PSK";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
security.acme = {
|
||||||
|
acceptTerms = true;
|
||||||
|
defaults.email = "letsencrypt@bogaledev.ru";
|
||||||
|
certs."bogaledev.ru" = {
|
||||||
|
validMinDays = 3;
|
||||||
|
dnsProvider = "cloudflare";
|
||||||
|
extraDomainNames = [ "*.bogaledev.ru" ];
|
||||||
|
credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/secrets/cf-token"; };
|
||||||
|
reloadServices = [ "nginx.service" "dovecot.service" "postfix.service" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -15,9 +15,10 @@ in {
|
||||||
rspamd = {
|
rspamd = {
|
||||||
enable = true;
|
enable = true;
|
||||||
postfix.enable = true;
|
postfix.enable = true;
|
||||||
locals."redis.conf".text = ''
|
locals = {
|
||||||
servers = "${config.services.redis.servers.rspamd.unixSocket}";
|
"classifier-bayes.conf".text = "autolearn = true;";
|
||||||
'';
|
"redis.conf".text = ''servers = "${config.services.redis.servers.rspamd.unixSocket}";'';
|
||||||
|
};
|
||||||
};
|
};
|
||||||
postfix = {
|
postfix = {
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
@ -26,24 +27,23 @@ in {
|
||||||
mapFiles.smtp_passwd = "/secrets/smtp_passwd";
|
mapFiles.smtp_passwd = "/secrets/smtp_passwd";
|
||||||
virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru";
|
virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru";
|
||||||
submissionsOptions = {
|
submissionsOptions = {
|
||||||
|
smtpd_sasl_type = "dovecot";
|
||||||
smtpd_tls_wrappermode = true;
|
smtpd_tls_wrappermode = true;
|
||||||
smtpd_sasl_auth_enable = "yes";
|
smtpd_sasl_auth_enable = "yes";
|
||||||
|
smtpd_sasl_path = "${postfixDir}/auth";
|
||||||
milter_macro_daemon_name = "ORIGINATING";
|
milter_macro_daemon_name = "ORIGINATING";
|
||||||
smtpd_client_restrictions = "permit_sasl_authenticated,reject";
|
smtpd_client_restrictions = "permit_sasl_authenticated,reject";
|
||||||
|
smtpd_tls_chain_files = "${sslCertDir}/key.pem,${sslCertDir}/fullchain.pem";
|
||||||
};
|
};
|
||||||
settings.main = {
|
settings.main = {
|
||||||
smtpd_sasl_type = "dovecot";
|
|
||||||
smtp_tls_wrappermode = true;
|
smtp_tls_wrappermode = true;
|
||||||
smtp_sasl_auth_enable = true;
|
smtp_sasl_auth_enable = true;
|
||||||
smtpd_sasl_auth_enable = true;
|
|
||||||
smtp_tls_security_level = "verify";
|
smtp_tls_security_level = "verify";
|
||||||
relayhost = [ "smtp.resend.com:2465" ];
|
relayhost = [ "smtp.resend.com:2465" ];
|
||||||
smtpd_sasl_path = "${postfixDir}/auth";
|
|
||||||
virtual_mailbox_domains = "bogaledev.ru";
|
virtual_mailbox_domains = "bogaledev.ru";
|
||||||
smtp_sasl_tls_security_options = "noanonymous";
|
smtp_sasl_tls_security_options = "noanonymous";
|
||||||
|
virtual_transport = "lmtp:unix:${postfixDir}/lmtp";
|
||||||
smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd";
|
smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd";
|
||||||
virtual_transport = "lmtp:unix:${postfixDir}/dovecot-lmtp";
|
|
||||||
smtpd_tls_chain_files = [ "${sslCertDir}/key.pem" "${sslCertDir}/fullchain.pem" ];
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
dovecot2 = {
|
dovecot2 = {
|
||||||
|
|
@ -66,22 +66,22 @@ in {
|
||||||
user = "postfix";
|
user = "postfix";
|
||||||
group = "postfix";
|
group = "postfix";
|
||||||
};
|
};
|
||||||
"service lmtp"."unix_listener ${postfixDir}/dovecot-lmtp" = {
|
"service lmtp"."unix_listener ${postfixDir}/lmtp" = {
|
||||||
mode = "0600";
|
mode = "0600";
|
||||||
user = "postfix";
|
user = "postfix";
|
||||||
group = "postfix";
|
group = "postfix";
|
||||||
};
|
};
|
||||||
"namespace inbox" = let
|
"namespace inbox" = let
|
||||||
mailbox = name: {
|
mailbox = name: {
|
||||||
auto = "create";
|
auto = "subscribe";
|
||||||
mailbox_special_use = "\\${name}";
|
mailbox_special_use = "\\${name}";
|
||||||
};
|
};
|
||||||
in {
|
in {
|
||||||
inbox = true;
|
inbox = true;
|
||||||
"mailbox Sent" = mailbox "Sent";
|
"mailbox Sent" = mailbox "Sent";
|
||||||
"mailbox Archive" = mailbox "Archive";
|
"mailbox Archive" = mailbox "Archive";
|
||||||
"mailbox Flagged" = mailbox "Flagged";
|
"mailbox Important" = mailbox "Flagged";
|
||||||
"mailbox Junk" = mailbox "Junk" // { mailbox_autoexpunge = "45d"; };
|
"mailbox Spam" = mailbox "Junk" // { mailbox_autoexpunge = "45d"; };
|
||||||
"mailbox Trash" = mailbox "Trash" // { mailbox_autoexpunge = "45d"; };
|
"mailbox Trash" = mailbox "Trash" // { mailbox_autoexpunge = "45d"; };
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
|
||||||
|
|
@ -1,12 +1,36 @@
|
||||||
{ config, lib, pkgs, ... }:
|
{ config, lib, pkgs, ... }:
|
||||||
{
|
{
|
||||||
|
services = {
|
||||||
|
prometheus = {
|
||||||
|
enable = true;
|
||||||
|
exporters.node.enable = true;
|
||||||
|
scrapeConfigs = [ {
|
||||||
|
job_name = "node";
|
||||||
|
static_configs = [ { targets = [
|
||||||
|
"localhost:${toString config.services.prometheus.exporters.node.port}"
|
||||||
|
]; } ];
|
||||||
|
} ];
|
||||||
|
};
|
||||||
|
grafana = {
|
||||||
|
enable = true;
|
||||||
|
settings = {
|
||||||
|
security.secret_key = "$__file{/secrets/grafana-key}";
|
||||||
|
server = {
|
||||||
|
enable_gzip = true;
|
||||||
|
protocol = "socket";
|
||||||
|
socket_mode = "0666";
|
||||||
|
root_url = "https://bogaledev.ru/grafana";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
systemd = {
|
systemd = {
|
||||||
timers = {
|
timers = {
|
||||||
tgbot-send = {
|
tgbot-send = {
|
||||||
wantedBy = [ "timers.target" ];
|
wantedBy = [ "timers.target" ];
|
||||||
timerConfig = {
|
timerConfig = {
|
||||||
OnCalendar = "*-*-01 16:00:00";
|
|
||||||
Persistent = true;
|
Persistent = true;
|
||||||
|
OnCalendar = "*-*-01 16:00:00";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
network-watchdog = {
|
network-watchdog = {
|
||||||
|
|
@ -35,7 +59,7 @@
|
||||||
network-watchdog = {
|
network-watchdog = {
|
||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
Type = "oneshot";
|
Type = "oneshot";
|
||||||
LogLevelMax = "notice";
|
LogLevelMax = "warning";
|
||||||
};
|
};
|
||||||
script = ''
|
script = ''
|
||||||
if [ ! -e /run/network.failures ] || [ ! -e /run/network.limit ] || \
|
if [ ! -e /run/network.failures ] || [ ! -e /run/network.limit ] || \
|
||||||
|
|
@ -45,12 +69,11 @@
|
||||||
else
|
else
|
||||||
limit=$(cat /run/network.limit)
|
limit=$(cat /run/network.limit)
|
||||||
failures=$((1+$(cat /run/network.failures)))
|
failures=$((1+$(cat /run/network.failures)))
|
||||||
[ $failures -gt 1 ] && echo "<5>failures = $failures"
|
|
||||||
fi
|
fi
|
||||||
if [ $failures -ge $limit ]; then
|
if [ $failures -ge $limit ]; then
|
||||||
echo "<4>restarting NetworkManager"
|
echo "<4>restarting NetworkManager"
|
||||||
systemctl restart NetworkManager.service
|
systemctl restart NetworkManager.service
|
||||||
[ $limit -lt 60 ] && limit=$((4*$limit/3))
|
[ $limit -lt 360 ] && limit=$((2*$limit))
|
||||||
failures=0
|
failures=0
|
||||||
fi
|
fi
|
||||||
echo $limit > /run/network.limit
|
echo $limit > /run/network.limit
|
||||||
|
|
|
||||||
|
|
@ -1,16 +1,5 @@
|
||||||
{ config, lib, pkgs, ... }:
|
{ config, lib, pkgs, ... }:
|
||||||
{
|
{
|
||||||
security.acme = {
|
|
||||||
acceptTerms = true;
|
|
||||||
defaults.email = "letsencrypt@bogaledev.ru";
|
|
||||||
certs."bogaledev.ru" = {
|
|
||||||
validMinDays = 3;
|
|
||||||
dnsProvider = "cloudflare";
|
|
||||||
extraDomainNames = [ "*.bogaledev.ru" ];
|
|
||||||
credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/secrets/cf-token"; };
|
|
||||||
reloadServices = [ "nginx.service" "dovecot.service" "postfix.service" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
services = let
|
services = let
|
||||||
sslCertDir = config.security.acme.certs."bogaledev.ru".directory;
|
sslCertDir = config.security.acme.certs."bogaledev.ru".directory;
|
||||||
in {
|
in {
|
||||||
|
|
@ -34,8 +23,8 @@
|
||||||
settings = {
|
settings = {
|
||||||
"pm" = "ondemand";
|
"pm" = "ondemand";
|
||||||
"pm.max_children" = 4;
|
"pm.max_children" = 4;
|
||||||
"listen.owner" = "nginx";
|
|
||||||
"listen.group" = "nginx";
|
"listen.group" = "nginx";
|
||||||
|
"listen.owner" = "nginx";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
vaultwarden = {
|
vaultwarden = {
|
||||||
|
|
@ -107,6 +96,11 @@
|
||||||
"/".extraConfig = phpPool;
|
"/".extraConfig = phpPool;
|
||||||
"/local/".extraConfig = "${phpPool} ${localNetworks}";
|
"/local/".extraConfig = "${phpPool} ${localNetworks}";
|
||||||
"/git/".proxyPass = "http://unix:/run/forgejo/forgejo.sock:/";
|
"/git/".proxyPass = "http://unix:/run/forgejo/forgejo.sock:/";
|
||||||
|
"/grafana/" = {
|
||||||
|
proxyWebsockets = true;
|
||||||
|
extraConfig = localNetworks;
|
||||||
|
proxyPass = "http://unix:/run/grafana/grafana.sock:/";
|
||||||
|
};
|
||||||
"/local/net/".extraConfig = ''
|
"/local/net/".extraConfig = ''
|
||||||
allow fc01::/64;
|
allow fc01::/64;
|
||||||
allow 10.1.0.0/16;
|
allow 10.1.0.0/16;
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue