From cf8875671e78626334e68fe230dbaa8397d572e9 Mon Sep 17 00:00:00 2001 From: bogale Date: Thu, 24 Sep 2026 19:56:31 +0900 Subject: [PATCH] rspamd-redis --- common.nix | 7 ++--- server/configuration.nix | 61 +++++++++++++++++++++++++--------------- 2 files changed, 42 insertions(+), 26 deletions(-) diff --git a/common.nix b/common.nix index 9f3d29d..0915164 100644 --- a/common.nix +++ b/common.nix @@ -19,7 +19,6 @@ extraModulePackages = [ config.boot.kernelPackages.amneziawg ]; loader.limine = { enable = true; - maxGenerations = 20; secureBoot.enable = true; panicOnChecksumMismatch = true; }; @@ -66,7 +65,7 @@ settings = { enable-ra = true; no-resolv = true; - cache-size = 1024; + cache-size = 8192; bogus-priv = true; enable-tftp = true; interface = "enp1s0"; @@ -75,8 +74,8 @@ dhcp-boot = "grubx64.efi"; dhcp-range = [ "10.2.0.2,10.2.255.254,12h" "fc02::2,fc02::ffff:ffff:ffff:ffff,12h" ]; - server = [ "1.0.0.1" "2606:4700:4700::1001" - "1.1.1.1" "2606:4700:4700::1111" ]; + server = [ "1.1.1.2" "2606:4700:4700::1112" + "1.0.0.2" "2606:4700:4700::1002" ]; }; }; }; diff --git a/server/configuration.nix b/server/configuration.nix index ca52c6e..4ffa59d 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -2,19 +2,20 @@ { imports = [ ../common.nix ./hardware-configuration.nix ]; boot.kernelParams = [ - "consoleblank=30" + "consoleblank=60" "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ]; users = { groups = { - php = { }; + php.gid = 1568; vmail.gid = 1819; }; users = { nginx.extraGroups = [ "acme" ]; root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ]; php = { + uid = 1568; group = "php"; isSystemUser = true; }; @@ -65,9 +66,9 @@ timers.network-watchdog = { wantedBy = [ "timers.target" ]; timerConfig = { - OnBootSec = 5; + OnBootSec = 30; AccuracySec = 1; - OnUnitActiveSec = 5; + OnUnitActiveSec = 10; Unit = "network-watchdog.service"; }; }; @@ -81,13 +82,13 @@ if [ ! -e /run/network.failures ] || ping -c 1 -W 3 1.1.1.1 &> /dev/null; then failures=0 else - failures=$(($(cat /run/network.failures)+1)) + failures=$((1+$(cat /run/network.failures))) fi if [ $failures -gt 0 ]; then echo "<5>failures = $failures" fi if [ $failures -ge 3 ]; then - echo "<5>restarting NetworkManager" + echo "<4>restarting NetworkManager" systemctl restart NetworkManager.service failures=0 fi @@ -130,17 +131,32 @@ dbBackend = "postgresql"; configurePostgres = true; package = pkgs.vaultwarden-postgresql; - environmentFile = "/secrets/vaultwarden.env"; + environmentFile = "/secrets/vw-token.env"; config = { ROCKET_PORT = 8032; SIGNUPS_ALLOWED = false; TRASH_AUTO_DELETE_DAYS = 90; PASSWORD_HINTS_ALLOWED = false; EMERGENCY_ACCESS_ALLOWED = false; - DOMAIN = "https://bogaledev.ru/vw"; + DOMAIN = "https://bogaledev.ru/vw/"; }; }; - nginx.virtualHosts."bogaledev.ru" = { + nginx.virtualHosts."bogaledev.ru" = let + phpPool = pool: '' + location ~ \.php$ { + fastcgi_pass unix:${config.services.phpfpm.pools.${pool}.socket}; + } + ''; + localNetworks = '' + allow fc00::/64; + allow fc01::/64; + allow fc02::/64; + allow 10.0.0.0/16; + allow 10.1.0.0/16; + allow 10.2.0.0/16; + deny all; + ''; + in { quic = true; default = true; forceSSL = true; @@ -148,29 +164,30 @@ useACMEHost = "bogaledev.ru"; extraConfig = ''add_header Alt-Svc 'h3=":443"; ma=86400' always;''; locations = { - "/".index = "index.php index.html"; - "~ \\.php$".extraConfig = '' - fastcgi_pass unix:${config.services.phpfpm.pools.default.socket}; - ''; + "/app/".extraConfig = phpPool "default"; "/git/".proxyPass = "http://127.0.0.1:8039/"; + "/priv/".extraConfig = ''${localNetworks} ${phpPool "default"}''; "/vw/" = { proxyWebsockets = true; + extraConfig = localNetworks; proxyPass = "http://127.0.0.1:8032"; - extraConfig = '' - allow fc00::/64; - allow fc01::/64; - allow fc02::/64; - allow 10.0.0.0/24; - allow 10.1.0.0/24; - allow 10.2.0.0/24; - deny all; - ''; }; }; }; + redis.servers.rspamd = { + enable = true; + user = "rspamd"; + }; rspamd = { enable = true; postfix.enable = true; + locals = { + "classifier-bayes.conf".text = "autolearn = true;"; + "worker-controller.inc".source = "/secrets/rspamd-pw"; + "redis.conf".text = '' + servers = "${config.services.redis.servers.rspamd.unixSocket}"; + ''; + }; }; dovecot2 = { enable = true;