From 79d3f7e89d59817c1517cac7b08b28f5d740eea1 Mon Sep 17 00:00:00 2001 From: bogale Date: Sat, 26 Sep 2026 22:11:24 +0900 Subject: [PATCH] desktop preparing --- common.nix | 33 ++++++++++++++++++--------------- desktop/configuration.nix | 20 +++++++++++++++----- home/common.nix | 16 ++++++++++++++++ server/configuration.nix | 16 ++++++---------- server/mods/mail.nix | 4 ++++ server/mods/sysd.nix | 10 +--------- server/mods/web.nix | 13 +++++-------- 7 files changed, 65 insertions(+), 47 deletions(-) diff --git a/common.nix b/common.nix index e12445f..90f54db 100644 --- a/common.nix +++ b/common.nix @@ -31,7 +31,10 @@ }; wg-quick.interfaces.awg0 = { type = "amneziawg"; - configFile = "/secrets/awg0.conf"; + peers = [ { + endpoint = "bogaledev.ru"; + allowedIPs = [ "::/0" "0.0.0.0/0" ]; + } ]; }; networkmanager = { enable = true; @@ -43,6 +46,14 @@ id = "home-wifi"; type = "wifi"; }; + ipv6 = { + method = "manual"; + gateway = "fc01::1"; + }; + ipv4 = { + method = "manual"; + gateway = "10.1.0.1"; + }; }; }; }; @@ -51,20 +62,12 @@ jq sbctl ]; - programs = { - git = { - enable = true; - config = { - init.defaultbranch = "main"; - user = { - name = "bogale"; - email = "git@bogaledev.ru"; - }; - }; - }; - }; services = { logind.settings.Login.HandleLidSwitch = "ignore"; + openssh = { + enable = true; + settings.PasswordAuthentication = false; + }; nginx = { enable = true; recommendedTlsSettings = true; @@ -87,8 +90,8 @@ dhcp-boot = "grubx64.efi"; dhcp-range = [ "10.2.0.2,10.2.255.254,12h" "fc02::2,fc02::ffff:ffff:ffff:ffff,12h" ]; - server = [ "1.1.1.2" "2606:4700:4700::1112" - "1.0.0.2" "2606:4700:4700::1002" ]; + server = [ "2606:4700:4700::1112" "1.1.1.2" + "2606:4700:4700::1002" "1.0.0.2" ]; }; }; }; diff --git a/desktop/configuration.nix b/desktop/configuration.nix index 19e88d3..ccd0ac8 100644 --- a/desktop/configuration.nix +++ b/desktop/configuration.nix @@ -1,20 +1,30 @@ { config, lib, pkgs, ... }: { imports = [ ../common.nix ./hardware-configuration.nix ]; - networking = { - hostName = "nixos-desktop"; - }; users.users = { data = { + uid = 1256; isNormalUser = true; - home = "/home/data"; hashedPasswordFile = "/secrets/user/data-pw"; }; bogale = { + uid = 1551; isNormalUser = true; - home = "/home/bogale"; extraGroups = [ "wheel" ]; hashedPasswordFile = "/secrets/user/bogale-pw"; }; }; + networking = { + hostName = "nixos-desktop"; + wg-quick.interfaces.awg0 = { + configFile = "/secrets/awg/2.conf"; + address = [ "fc00::3/128" "10.0.0.3/32" ]; + }; + networkmanager.ensureProfiles.profiles.home-wifi = { + wifi.ssid = "bogale_5"; + ipv6.addresses = "fc01::3/64"; + ipv4.addresses = "10.1.0.3/16"; + wifi-security.psk = "$BOGALE_5_PSK"; + }; + }; } diff --git a/home/common.nix b/home/common.nix index a3a1645..2605fb0 100644 --- a/home/common.nix +++ b/home/common.nix @@ -3,6 +3,7 @@ home.stateVersion = "26.05"; services.ssh-agent.enable = true; home.packages = with pkgs; [ + ncdu yt-dlp ]; programs = { @@ -12,6 +13,21 @@ historyControl = [ "ignoreboth" ]; shellAliases = { la = "ls -lAtr"; }; }; + ssh = { + enable = true; + enableDefaultConfig = false; + settings."*".SetEnv.TERM = "xterm-256color"; + }; + git = { + enable = true; + settings = { + init.defaultbranch = "main"; + user = { + name = "bogale"; + email = "git@bogaledev.ru"; + }; + }; + }; neovim = { enable = true; defaultEditor = true; diff --git a/server/configuration.nix b/server/configuration.nix index 555f184..8e462ee 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -34,19 +34,15 @@ allowedTCPPorts = [ 25 443 587 993 ]; allowedUDPPorts = [ 443 ]; }; + wg-quick.interfaces.awg0 = { + configFile = "/secrets/awg/1.conf"; + address = [ "fc00::2/128" "10.0.0.2/32" ]; + }; networkmanager.ensureProfiles.profiles.home-wifi = { wifi.ssid = "bogale_2.4"; + ipv6.addresses = "fc01::2/64"; + ipv4.addresses = "10.1.0.2/16"; wifi-security.psk = "$BOGALE_2_4_PSK"; - ipv4 = { - method = "manual"; - gateway = "10.1.0.1"; - addresses = "10.1.0.2/16"; - }; - ipv6 = { - method = "manual"; - gateway = "fc01::1"; - addresses = "fc01::2/64"; - }; }; }; } diff --git a/server/mods/mail.nix b/server/mods/mail.nix index 49b2e4b..02bdfc8 100644 --- a/server/mods/mail.nix +++ b/server/mods/mail.nix @@ -1,5 +1,9 @@ { config, lib, pkgs, ... }: { + systemd.tmpfiles.rules = [ + "d /var/spool/postfix 0775 postfix postfix -" + "d /var/spool/postfix/private 0770 postfix postfix -" + ]; services = let mailBase = "/var/spool/mail/vmail"; saslSocket = "/var/spool/postfix/private/auth"; diff --git a/server/mods/sysd.nix b/server/mods/sysd.nix index 3d60e3f..fe15eb6 100644 --- a/server/mods/sysd.nix +++ b/server/mods/sysd.nix @@ -1,14 +1,6 @@ { config, lib, pkgs, ... }: { - services.openssh = { - enable = true; - settings.PasswordAuthentication = false; - }; systemd = { - tmpfiles.rules = [ - "d /var/spool/postfix 0755 postfix postfix -" - "d /var/spool/postfix/private 0755 postfix postfix -" - ]; timers = { tgbot-send = { wantedBy = [ "timers.target" ]; @@ -53,7 +45,7 @@ else limit=$(cat /run/network.limit) failures=$((1+$(cat /run/network.failures))) - echo "<5>failures = $failures" + [ $failures -gt 1 ] && echo "<5>failures = $failures" fi if [ $failures -ge $limit ]; then echo "<4>restarting NetworkManager" diff --git a/server/mods/web.nix b/server/mods/web.nix index cf8d1b7..3d4d24d 100644 --- a/server/mods/web.nix +++ b/server/mods/web.nix @@ -30,12 +30,9 @@ forgejo = { enable = true; database.type = "postgres"; - settings = { - service.DISABLE_REGISTRATION = true; - server = { - HTTP_PORT = 8039; - ROOT_URL = "https://bogaledev.ru/git/"; - }; + settings.server = { + HTTP_PORT = 8039; + ROOT_URL = "https://bogaledev.ru/git/"; }; }; phpfpm.pools.php = { @@ -44,7 +41,7 @@ phpEnv = { PATH = "/run/current-system/sw/bin"; }; settings = { "pm" = "ondemand"; - "pm.max_children" = 8; + "pm.max_children" = 4; "listen.owner" = "nginx"; "listen.group" = "nginx"; }; @@ -88,6 +85,7 @@ add_header X-Content-Type-Options "nosniff" always; ''; locations = { + "/git/".proxyPass = "http://127.0.0.1:8039/"; "/" = { extraConfig = phpPool; index = "index.php index.html"; @@ -101,7 +99,6 @@ allow 10.1.0.0/16; deny all; ''; - "/git/".proxyPass = "http://127.0.0.1:8039/"; "/vw/" = { proxyWebsockets = true; extraConfig = localNetworks;