nixos/server/mods/sysd.nix
2026-09-25 23:40:19 +09:00

66 lines
1.8 KiB
Nix

{ config, lib, pkgs, ... }:
{
services.openssh = {
enable = true;
settings.PasswordAuthentication = false;
};
systemd = {
tmpfiles.rules = [
"d /var/spool/postfix 0755 postfix postfix -"
"d /var/spool/postfix/private 0755 postfix postfix -"
];
timers = {
tgbot-send = {
wantedBy = [ "timers.target" ];
timerConfig = {
OnCalendar = "*-*-01 16:00:00";
Persistent = true;
};
};
network-watchdog = {
wantedBy = [ "timers.target" ];
timerConfig = {
OnBootSec = 30;
AccuracySec = 1;
OnUnitActiveSec = 10;
};
};
};
services = {
tgbot-send = {
serviceConfig.Type = "oneshot";
script = ''
. /secrets/tgbot.env
for msg in "''${MESSAGES[@]}"; do
TEXT="''${msg#*:}"
CHAT_ID="''${msg%%:*}"
${pkgs.curl}/bin/curl -X POST "https://api.telegram.org/$BOT/sendMessage" \
-d "chat_id=$CHAT_ID" -d "text=$TEXT" 2> /dev/null | ${pkgs.jq}/bin/jq
sleep 1
done
'';
};
network-watchdog = {
serviceConfig = {
Type = "oneshot";
LogLevelMax = "notice";
};
script = ''
if [ ! -e /run/network.failures ] || \
${pkgs.iputils}/bin/ping -c 1 -W 3 1.1.1.1; then
failures=0
else
failures=$((1+$(cat /run/network.failures)))
echo "<5>failures = $failures"
fi
if [ $failures -ge 3 ]; then
echo "<4>restarting NetworkManager"
systemctl restart NetworkManager.service
failures=0
fi
echo $failures > /run/network.failures
'';
};
};
};
}