From f88232875ec27e014099f41f112a7361cfa3b256 Mon Sep 17 00:00:00 2001 From: bogale Date: Thu, 24 Sep 2026 23:31:00 +0900 Subject: [PATCH] tgbot-send --- common.nix | 8 +++- marks | 3 +- server/configuration.nix | 87 +++++++++++++++++++++++++--------------- 3 files changed, 61 insertions(+), 37 deletions(-) diff --git a/common.nix b/common.nix index 0915164..0ad1256 100644 --- a/common.nix +++ b/common.nix @@ -23,7 +23,10 @@ panicOnChecksumMismatch = true; }; }; - users.users.root.hashedPasswordFile = "/secrets/root.passwd"; + users = { + groups.secrets.gid = 1578; + users.root.hashedPasswordFile = "/secrets/user-root-pw"; + }; networking = { firewall = { allowedTCPPorts = [ 53 80 ]; @@ -48,6 +51,7 @@ }; }; environment.systemPackages = with pkgs; [ + jq sbctl ]; services = { @@ -65,7 +69,7 @@ settings = { enable-ra = true; no-resolv = true; - cache-size = 8192; + cache-size = 4096; bogus-priv = true; enable-tftp = true; interface = "enp1s0"; diff --git a/marks b/marks index 8c99111..9c79fbc 100644 --- a/marks +++ b/marks @@ -12,6 +12,5 @@ nixos-install --flake "/mnt/etc/nixos#nixos" --no-channel-copy --no-root-passwd systemd-cryptenroll --tpm2-device=auto --tpm2-pcrs=0+2+7 todo: -- gitea, mediawiki +- mediawiki, wordpress - email tracking -- redirect randomizer diff --git a/server/configuration.nix b/server/configuration.nix index 4ffa59d..312c75a 100644 --- a/server/configuration.nix +++ b/server/configuration.nix @@ -3,6 +3,7 @@ imports = [ ../common.nix ./hardware-configuration.nix ]; boot.kernelParams = [ "consoleblank=60" + #TPM fix "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ]; @@ -13,6 +14,7 @@ }; users = { nginx.extraGroups = [ "acme" ]; + dovecot2.extraGroups = [ "secrets" ]; root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ]; php = { uid = 1568; @@ -63,40 +65,60 @@ "d /var/spool/postfix 0755 postfix postfix -" "d /var/spool/postfix/private 0755 postfix postfix -" ]; - timers.network-watchdog = { - wantedBy = [ "timers.target" ]; - timerConfig = { - OnBootSec = 30; - AccuracySec = 1; - OnUnitActiveSec = 10; - Unit = "network-watchdog.service"; + timers = { + tgbot-send = { + wantedBy = [ "timers.target" ]; + timerConfig = { + OnCalendar = "*-*-01 16:00:00"; + Persistent = true; + }; + }; + network-watchdog = { + wantedBy = [ "timers.target" ]; + timerConfig = { + OnBootSec = 30; + AccuracySec = 1; + OnUnitActiveSec = 10; + }; }; }; - services.network-watchdog = { - path = [ pkgs.iputils ]; - serviceConfig = { - Type = "oneshot"; - LogLevelMax = "notice"; + services = { + tgbot-send = { + serviceConfig.Type = "oneshot"; + script = '' + . /secrets/tgbot.env + ${pkgs.curl}/bin/curl "https://api.telegram.org/$BOT/sendMessage" \ + -X POST -d "chat_id=$CHAT_ID" -d "text=$TEXT" 2> /dev/null | \ + ${pkgs.jq}/bin/jq '.result.date |= strftime("%Y-%m-%d %H:%M:%S")' + ''; + }; + network-watchdog = { + serviceConfig = { + Type = "oneshot"; + LogLevelMax = "notice"; + }; + script = '' + if [ ! -e /run/network.failures ] || \ + ${pkgs.iputils}/bin/ping -c 1 -W 3 1.1.1.1 &> /dev/null; then + failures=0 + else + failures=$((1+$(cat /run/network.failures))) + fi + if [ $failures -gt 0 ]; then + echo "<5>failures = $failures" + fi + if [ $failures -ge 3 ]; then + echo "<4>restarting NetworkManager" + systemctl restart NetworkManager.service + failures=0 + fi + echo $failures > /run/network.failures + ''; }; - script = '' - if [ ! -e /run/network.failures ] || ping -c 1 -W 3 1.1.1.1 &> /dev/null; then - failures=0 - else - failures=$((1+$(cat /run/network.failures))) - fi - if [ $failures -gt 0 ]; then - echo "<5>failures = $failures" - fi - if [ $failures -ge 3 ]; then - echo "<4>restarting NetworkManager" - systemctl restart NetworkManager.service - failures=0 - fi - echo $failures > /run/network.failures - ''; }; }; services = let + mailBase = "/var/spool/mail/vmail"; saslSocket = "/var/spool/postfix/private/auth"; sslCertDir = config.security.acme.certs."bogaledev.ru".directory; in { @@ -183,7 +205,6 @@ postfix.enable = true; locals = { "classifier-bayes.conf".text = "autolearn = true;"; - "worker-controller.inc".source = "/secrets/rspamd-pw"; "redis.conf".text = '' servers = "${config.services.redis.servers.rspamd.unixSocket}"; ''; @@ -195,15 +216,15 @@ ssl = "required"; mail_gid = "vmail"; mail_uid = "vmail"; + mail_path = mailBase; protocols.imap = true; mail_driver = "maildir"; auth_mechanisms = [ "plain" ]; + dovecot_config_version = "2.4.5"; dovecot_storage_version = "2.4.5"; - mail_path = "/var/spool/mail/vmail"; ssl_server_key_file = "${sslCertDir}/key.pem"; ssl_server_cert_file = "${sslCertDir}/fullchain.pem"; - dovecot_config_version = config.services.dovecot2.package.version; - "passdb passwd-file".passwd_file_path = "/secrets/dovecot-passwd"; + "passdb passwd-file".passwd_file_path = "/secrets/dovecot-pw"; "service auth"."unix_listener ${saslSocket}" = { mode = "0660"; user = "postfix"; @@ -225,13 +246,13 @@ smtpd_sasl_path = saslSocket; smtp_sasl_auth_enable = "yes"; smtpd_sasl_auth_enable = "yes"; + virtual_mailbox_base = mailBase; virtual_uid_maps = "static:1819"; virtual_gid_maps = "static:1819"; smtp_tls_security_level = "encrypt"; smtpd_tls_security_level = "encrypt"; relayhost = [ "smtp.resend.com:2587" ]; virtual_mailbox_domains = "bogaledev.ru"; - virtual_mailbox_base = "/var/spool/mail/vmail"; smtp_sasl_tls_security_options = "noanonymous"; virtual_mailbox_maps = "hash:/etc/postfix/mailbox"; smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd";