48 lines
1.2 KiB
Nix
48 lines
1.2 KiB
Nix
{ config, lib, pkgs, ... }:
|
|
{
|
|
imports = [ ../common.nix ./hardware-configuration.nix
|
|
./mods/web.nix ./mods/mail.nix ./mods/sysd.nix ];
|
|
boot.kernelParams = [
|
|
"consoleblank=60"
|
|
#TPM fix
|
|
"memmap=0x4000%0xbfb76000-4"
|
|
"memmap=0x4000%0xbfb7a000-4"
|
|
];
|
|
users = {
|
|
groups = {
|
|
php.gid = 1568;
|
|
vmail.gid = 1819;
|
|
};
|
|
users = {
|
|
nginx.extraGroups = [ "php" "acme" ];
|
|
root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB+wc+3rahpNa+OMS9gaWgMQIxXIKHy4Beku5LBDt+Ow" ];
|
|
php = {
|
|
uid = 1568;
|
|
group = "php";
|
|
isSystemUser = true;
|
|
};
|
|
vmail = {
|
|
uid = 1819;
|
|
group = "vmail";
|
|
isSystemUser = true;
|
|
};
|
|
};
|
|
};
|
|
networking = {
|
|
hostName = "nixos-server";
|
|
firewall = {
|
|
allowedTCPPorts = [ 25 443 465 993 ];
|
|
allowedUDPPorts = [ 443 ];
|
|
};
|
|
wg-quick.interfaces.awg0 = {
|
|
configFile = "/secrets/awg/1.conf";
|
|
address = [ "fc00::2/128" "10.0.0.2/32" ];
|
|
};
|
|
networkmanager.ensureProfiles.profiles.home-wifi = {
|
|
wifi.ssid = "bogale_2.4";
|
|
ipv6.addresses = "fc01::2/64";
|
|
ipv4.addresses = "10.1.0.2/16";
|
|
wifi-security.psk = "$BOGALE_2_4_PSK";
|
|
};
|
|
};
|
|
}
|