{ config, lib, pkgs, ... }: { imports = [ ../common.nix ./hardware-configuration.nix ]; boot.kernelParams = [ "memmap=0x4000%0xbfb76000-4" "memmap=0x4000%0xbfb7a000-4" ]; users = { groups.vmail.gid = 1819; users = { nginx.extraGroups = [ "acme" ]; bogale.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ]; vmail = { uid = 1819; group = "vmail"; isSystemUser = true; }; }; }; networking = { hostName = "nixos-server"; firewall = { allowedTCPPorts = [ 25 80 443 587 993 ]; allowedUDPPorts = [ 443 ]; }; networkmanager.ensureProfiles.profiles.home-wifi = { wifi.ssid = "bogale_2.4"; wifi-security.psk = "$BOGALE_2_4_PSK"; ipv4 = { method = "manual"; gateway = "10.1.0.1"; addresses = "10.1.0.2/16"; }; ipv6 = { method = "manual"; gateway = "fc01::1"; addresses = "fc01::2/64"; }; }; }; security.acme = { acceptTerms = true; certs."bogaledev.ru" = { validMinDays = 3; dnsProvider = "cloudflare"; email = "letsencrypt@bogaledev.ru"; extraDomainNames = [ "*.bogaledev.ru" ]; credentialFiles = { "CF_DNS_API_TOKEN_FILE" = "/secrets/cf-token"; }; reloadServices = [ "nginx.service" "dovecot.service" "postfix.service" ]; }; }; systemd = { tmpfiles.rules = [ "d /var/spool/postfix 0755 postfix postfix -" "d /var/spool/postfix/private 0755 postfix postfix -" ]; timers.network-watchdog = { wantedBy = [ "timers.target" ]; after = [ "NetworkManager.service" ]; wants = [ "NetworkManager.service" ]; timerConfig = { OnBootSec = 5; AccuracySec = 1; OnUnitActiveSec = 5; Unit = "network-watchdog.service"; }; }; services.network-watchdog = { path = [ pkgs.iputils ]; serviceConfig.Type = "oneshot"; script = '' if [ ! -e /run/network.failures ] || ping -c 1 -W 3 1.1.1.1 &> /dev/null; then failures=0 else failures=$(($(cat /run/network.failures)+1)) if [ $failures -ge 3 ]; then systemctl restart NetworkManager.service failures=0 fi fi echo $failures > /run/network.failures ''; }; }; services = let saslSocket = "/var/spool/postfix/private/auth"; sslCertDir = config.security.acme.certs."bogaledev.ru".directory; in { postgresql.enable = true; openssh = { enable = true; settings = { PermitRootLogin = "no"; PasswordAuthentication = false; }; }; phpfpm.pools.main = { user = "nginx"; group = "nginx"; settings = { "pm" = "ondemand"; "pm.max_children" = 8; "listen.owner" = "nginx"; "listen.group" = "nginx"; }; }; vaultwarden = { enable = true; dbBackend = "postgresql"; configurePostgres = true; package = pkgs.vaultwarden-postgresql; environmentFile = "/secrets/vaultwarden.env"; config = { SIGNUPS_ALLOWED = false; TRASH_AUTO_DELETE_DAYS = 90; PASSWORD_HINTS_ALLOWED = false; EMERGENCY_ACCESS_ALLOWED = false; DOMAIN = "https://bogaledev.ru/vw"; }; }; dovecot2 = { enable = true; settings = { ssl = "required"; mail_gid = "vmail"; mail_uid = "vmail"; protocols.imap = true; mail_driver = "maildir"; auth_mechanisms = [ "plain" ]; dovecot_storage_version = "2.4.5"; mail_path = "/var/spool/mail/vmail"; ssl_server_key_file = "${sslCertDir}/key.pem"; ssl_server_cert_file = "${sslCertDir}/fullchain.pem"; dovecot_config_version = config.services.dovecot2.package.version; "passdb passwd-file".passwd_file_path = "/secrets/dovecot-passwd"; "service auth"."unix_listener ${saslSocket}" = { mode = "0660"; user = "postfix"; group = "postfix"; }; }; }; postfix = { enable = true; enableSubmission = true; virtualMapType = "regexp"; virtual = "/.*@bogaledev.ru/ mail@bogaledev.ru"; mapFiles = { smtp_passwd = "/secrets/smtp_passwd"; mailbox = pkgs.writeText "mailbox" "mail@bogaledev.ru /"; }; settings.main = { smtpd_sasl_type = "dovecot"; smtpd_sasl_path = saslSocket; smtp_sasl_auth_enable = "yes"; smtpd_sasl_auth_enable = "yes"; virtual_uid_maps = "static:1819"; virtual_gid_maps = "static:1819"; smtp_tls_security_level = "encrypt"; smtpd_tls_security_level = "encrypt"; relayhost = [ "smtp.resend.com:2587" ]; virtual_mailbox_domains = "bogaledev.ru"; virtual_mailbox_base = "/var/spool/mail/vmail"; smtp_sasl_tls_security_options = "noanonymous"; virtual_mailbox_maps = "hash:/etc/postfix/mailbox"; smtp_sasl_password_maps = "hash:/etc/postfix/smtp_passwd"; smtpd_tls_chain_files = [ "${sslCertDir}/key.pem" "${sslCertDir}/fullchain.pem" ]; }; }; nginx = { enable = true; recommendedTlsSettings = true; recommendedGzipSettings = true; recommendedOptimisation = true; recommendedProxySettings = true; recommendedBrotliSettings = true; virtualHosts."bogaledev.ru" = { quic = true; default = true; forceSSL = true; root = "/srv/http"; useACMEHost = "bogaledev.ru"; extraConfig = ''add_header Alt-Svc 'h3=":443"; ma=86400' always;''; locations = { "/".index = "index.php index.html"; "~ \\.php$".extraConfig = '' fastcgi_pass unix:${config.services.phpfpm.pools.main.socket}; ''; "/vw" = { proxyPass = "http://127.0.0.1:8000"; proxyWebsockets = true; extraConfig = '' allow fc00::/64; allow fc01::/64; allow 10.0.0.0/24; allow 10.1.0.0/24; deny all; ''; }; }; }; }; }; }