desktop preparing

This commit is contained in:
bogale 2026-09-26 22:11:24 +09:00
commit 79d3f7e89d
7 changed files with 65 additions and 47 deletions

View file

@ -34,19 +34,15 @@
allowedTCPPorts = [ 25 443 587 993 ];
allowedUDPPorts = [ 443 ];
};
wg-quick.interfaces.awg0 = {
configFile = "/secrets/awg/1.conf";
address = [ "fc00::2/128" "10.0.0.2/32" ];
};
networkmanager.ensureProfiles.profiles.home-wifi = {
wifi.ssid = "bogale_2.4";
ipv6.addresses = "fc01::2/64";
ipv4.addresses = "10.1.0.2/16";
wifi-security.psk = "$BOGALE_2_4_PSK";
ipv4 = {
method = "manual";
gateway = "10.1.0.1";
addresses = "10.1.0.2/16";
};
ipv6 = {
method = "manual";
gateway = "fc01::1";
addresses = "fc01::2/64";
};
};
};
}

View file

@ -1,5 +1,9 @@
{ config, lib, pkgs, ... }:
{
systemd.tmpfiles.rules = [
"d /var/spool/postfix 0775 postfix postfix -"
"d /var/spool/postfix/private 0770 postfix postfix -"
];
services = let
mailBase = "/var/spool/mail/vmail";
saslSocket = "/var/spool/postfix/private/auth";

View file

@ -1,14 +1,6 @@
{ config, lib, pkgs, ... }:
{
services.openssh = {
enable = true;
settings.PasswordAuthentication = false;
};
systemd = {
tmpfiles.rules = [
"d /var/spool/postfix 0755 postfix postfix -"
"d /var/spool/postfix/private 0755 postfix postfix -"
];
timers = {
tgbot-send = {
wantedBy = [ "timers.target" ];
@ -53,7 +45,7 @@
else
limit=$(cat /run/network.limit)
failures=$((1+$(cat /run/network.failures)))
echo "<5>failures = $failures"
[ $failures -gt 1 ] && echo "<5>failures = $failures"
fi
if [ $failures -ge $limit ]; then
echo "<4>restarting NetworkManager"

View file

@ -30,12 +30,9 @@
forgejo = {
enable = true;
database.type = "postgres";
settings = {
service.DISABLE_REGISTRATION = true;
server = {
HTTP_PORT = 8039;
ROOT_URL = "https://bogaledev.ru/git/";
};
settings.server = {
HTTP_PORT = 8039;
ROOT_URL = "https://bogaledev.ru/git/";
};
};
phpfpm.pools.php = {
@ -44,7 +41,7 @@
phpEnv = { PATH = "/run/current-system/sw/bin"; };
settings = {
"pm" = "ondemand";
"pm.max_children" = 8;
"pm.max_children" = 4;
"listen.owner" = "nginx";
"listen.group" = "nginx";
};
@ -88,6 +85,7 @@
add_header X-Content-Type-Options "nosniff" always;
'';
locations = {
"/git/".proxyPass = "http://127.0.0.1:8039/";
"/" = {
extraConfig = phpPool;
index = "index.php index.html";
@ -101,7 +99,6 @@
allow 10.1.0.0/16;
deny all;
'';
"/git/".proxyPass = "http://127.0.0.1:8039/";
"/vw/" = {
proxyWebsockets = true;
extraConfig = localNetworks;