Compare commits

..

No commits in common. "de5ad541b8a3f99ed7e0e66b66882bfd0f293468" and "30cff89a502bad8134dab3ec45d5d189ce1d00a9" have entirely different histories.

10 changed files with 114 additions and 138 deletions

View File

@ -68,14 +68,14 @@ in
"plugdev" "plugdev"
"bluetooth" "bluetooth"
]; ];
openssh.authorizedKeys.keyFiles = inputs.self.lib.getSshKeys [ openssh.authorizedKeys.keyFiles = [
"deacero" ../secrets/ssh/ed25519_deacero.pub
"workstation" ../secrets/ssh/ed25519_workstation.pub
"server" ../secrets/ssh/ed25519_server.pub
"miniserver" ../secrets/ssh/ed25519_miniserver.pub
"galaxy" ../secrets/ssh/ed25519_galaxy.pub
"phone" ../secrets/ssh/ed25519_phone.pub
"vps" ../secrets/ssh/ed25519_vps.pub
]; ];
}; };
} }

View File

@ -5,13 +5,13 @@
../../config/base.nix ../../config/base.nix
../../config/stylix.nix ../../config/stylix.nix
]; ];
my = import ./toggles.nix { inherit inputs; } // { my = import ./toggles.nix // {
nix.cores = 3; nix.cores = 3;
nix.maxJobs = 8; nix.maxJobs = 8;
users.nixremote.enable = true; users.nixremote.enable = true;
users.nixremote.authorizedKeys = inputs.self.lib.getSshKeys [ users.nixremote.authorizedKeys = [
"nixworkstation" ../../secrets/ssh/ed25519_nixworkstation.pub
"nixserver" ../../secrets/ssh/ed25519_nixserver.pub
]; ];
}; };
nix.buildMachines = nix.buildMachines =

View File

@ -1,6 +1,16 @@
{ inputs }:
let let
inherit (inputs.self.lib) mkEnabled mkEnabledWithProxy enableList; mkEnabled = name: {
inherit name;
value.enable = true;
};
mkEnabledWithProxy = name: {
inherit name;
value = {
enable = true;
enableProxy = true;
};
};
enableList = func: list: list |> map func |> builtins.listToAttrs;
in in
{ {
emacs.enable = true; emacs.enable = true;

View File

@ -10,12 +10,12 @@
../../config/base.nix ../../config/base.nix
../../config/stylix.nix ../../config/stylix.nix
]; ];
my = import ./toggles.nix { inherit config inputs; } // { my = import ./toggles.nix { inherit config; } // {
nix.cores = 6; nix.cores = 6;
users.nixremote.enable = true; users.nixremote.enable = true;
users.nixremote.authorizedKeys = inputs.self.lib.getSshKeys [ users.nixremote.authorizedKeys = [
"nixworkstation" ../../secrets/ssh/ed25519_nixworkstation.pub
"nixminiserver" ../../secrets/ssh/ed25519_nixminiserver.pub
]; ];
network.firewall.enabledServicePorts = true; network.firewall.enabledServicePorts = true;
network.firewall.additionalPorts = [ network.firewall.additionalPorts = [

View File

@ -1,7 +1,17 @@
{ config, inputs }: { config }:
let let
inherit (inputs.self.lib) mkEnabled enableList; mkEnabled = name: {
mkEnabledIp = inputs.self.lib.mkEnabledIp config.my.ips.wg-server; inherit name;
value.enable = true;
};
mkEnabledIp = name: {
inherit name;
value = {
enable = true;
ip = config.my.ips.wg-server;
};
};
enableList = func: list: list |> map func |> builtins.listToAttrs;
in in
{ {
mainServer = "server"; mainServer = "server";

View File

@ -22,13 +22,13 @@ in
../../config/stylix.nix ../../config/stylix.nix
../../environments/gnome.nix ../../environments/gnome.nix
]; ];
my = import ./toggles.nix { inherit inputs; } // { my = import ./toggles.nix // {
nix.cores = 8; nix.cores = 8;
nix.maxJobs = 8; nix.maxJobs = 8;
users.nixremote.enable = true; users.nixremote.enable = true;
users.nixremote.authorizedKeys = inputs.self.lib.getSshKeys [ users.nixremote.authorizedKeys = [
"nixserver" ../../secrets/ssh/ed25519_nixserver.pub
"nixminiserver" ../../secrets/ssh/ed25519_nixminiserver.pub
]; ];
}; };
home-manager.users.jawz = { home-manager.users.jawz = {

View File

@ -1,6 +1,9 @@
{ inputs }:
let let
inherit (inputs.self.lib) mkEnabled enableList; mkEnabled = name: {
inherit name;
value.enable = true;
};
enableList = func: list: list |> map func |> builtins.listToAttrs;
in in
{ {
stylix.enable = true; stylix.enable = true;

View File

@ -105,71 +105,65 @@ in
enableProxy = lib.mkEnableOption "nginx reverse proxy for services"; enableProxy = lib.mkEnableOption "nginx reverse proxy for services";
}; };
config = { config = {
assertions = assertions = [
# PostgreSQL dependency assertions {
inputs.self.lib.mkPostgresDependencies config [ assertion = config.my.servers.nextcloud.enable -> config.my.servers.postgres.enable;
{ message = "Nextcloud requires PostgreSQL to be enabled";
service = "nextcloud"; }
name = "Nextcloud"; {
} assertion = config.my.servers.vaultwarden.enable -> config.my.servers.postgres.enable;
{ message = "Vaultwarden requires PostgreSQL to be enabled";
service = "vaultwarden"; }
name = "Vaultwarden"; {
} assertion = config.my.servers.firefly-iii.enable -> config.my.servers.postgres.enable;
{ message = "Firefly III requires PostgreSQL to be enabled";
service = "firefly-iii"; }
name = "Firefly III"; {
} assertion = config.my.servers.mealie.enable -> config.my.servers.postgres.enable;
{ message = "Mealie requires PostgreSQL to be enabled";
service = "mealie"; }
name = "Mealie"; {
} assertion = config.my.servers.shiori.enable -> config.my.servers.postgres.enable;
{ message = "Shiori requires PostgreSQL to be enabled";
service = "shiori"; }
name = "Shiori"; {
} assertion = config.my.servers.ryot.enable -> config.my.servers.postgres.enable;
{ message = "Ryot requires PostgreSQL to be enabled";
service = "ryot"; }
name = "Ryot"; {
} assertion = config.my.servers.synapse.enable -> config.my.servers.postgres.enable;
{ message = "Matrix Synapse requires PostgreSQL to be enabled";
service = "synapse"; }
name = "Matrix Synapse"; {
} assertion = config.my.servers.gitea.enable -> config.my.servers.postgres.enable;
{ message = "Gitea requires PostgreSQL to be enabled";
service = "gitea"; }
name = "Gitea"; {
} assertion =
] config.my.enableProxy
++ -> (builtins.any (s: s.enableProxy or false) (builtins.attrValues config.my.servers));
# Other assertions message = "enableProxy is true but no services have enableProxy enabled";
[ }
{ {
assertion = assertion =
config.my.enableProxy config.my.enableContainers
-> (builtins.any (s: s.enableProxy or false) (builtins.attrValues config.my.servers)); || !(builtins.any (opt: opt) [
message = "enableProxy is true but no services have enableProxy enabled"; config.my.servers.ryot.enable
} config.my.servers.lidarr.enable
{ config.my.servers.prowlarr.enable
assertion = config.my.servers.maloja.enable
config.my.enableContainers config.my.servers.multi-scrobbler.enable
|| !(builtins.any (opt: opt) [ config.my.servers.flame.enable
config.my.servers.ryot.enable config.my.servers.flameSecret.enable
config.my.servers.lidarr.enable config.my.servers.metube.enable
config.my.servers.prowlarr.enable config.my.servers.go-vod.enable
config.my.servers.maloja.enable config.my.servers.tranga.enable
config.my.servers.multi-scrobbler.enable config.my.servers.drpp.enable
config.my.servers.flame.enable config.my.servers.plex-discord-bot.enable
config.my.servers.flameSecret.enable ]);
config.my.servers.metube.enable message = "Container services are enabled but enableContainers is false";
config.my.servers.go-vod.enable }
config.my.servers.tranga.enable ];
config.my.servers.drpp.enable
config.my.servers.plex-discord-bot.enable
]);
message = "Container services are enabled but enableContainers is false";
}
];
virtualisation = { virtualisation = {
containers.enable = true; containers.enable = true;
oci-containers.backend = "podman"; oci-containers.backend = "podman";

View File

@ -1,13 +1,13 @@
{ lib, config, inputs, ... }: { lib, config, ... }:
{ {
options.my.users.nixremote = { options.my.users.nixremote = {
enable = lib.mkEnableOption "nixremote user for distributed builds"; enable = lib.mkEnableOption "nixremote user for distributed builds";
authorizedKeys = lib.mkOption { authorizedKeys = lib.mkOption {
type = lib.types.listOf lib.types.path; type = lib.types.listOf lib.types.path;
default = inputs.self.lib.getSshKeys [ default = [
"nixworkstation" ../../secrets/ssh/ed25519_nixworkstation.pub
"nixserver" ../../secrets/ssh/ed25519_nixserver.pub
"nixminiserver" ../../secrets/ssh/ed25519_nixminiserver.pub
]; ];
description = "List of SSH public key files to authorize for nixremote user"; description = "List of SSH public key files to authorize for nixremote user";
}; };

View File

@ -171,47 +171,6 @@ in
|> lib.attrValues |> lib.attrValues
|> map (srv: srv.port) |> map (srv: srv.port)
); );
mkEnabled = name: {
inherit name;
value.enable = true;
};
mkEnabledWithProxy = name: {
inherit name;
value = {
enable = true;
enableProxy = true;
};
};
mkEnabledIp = ip: name: {
inherit name;
value = {
enable = true;
inherit ip;
};
};
enableList = func: list: list |> map func |> builtins.listToAttrs;
mkPostgresDependency = config: serviceName: displayName: {
assertion = config.my.servers.${serviceName}.enable -> config.my.servers.postgres.enable;
message = "${displayName} requires PostgreSQL to be enabled";
};
mkPostgresDependencies =
config: serviceMap:
serviceMap |> map (entry: inputs.self.lib.mkPostgresDependency config entry.service entry.name);
sshKeys = {
deacero = ../../secrets/ssh/ed25519_deacero.pub;
workstation = ../../secrets/ssh/ed25519_workstation.pub;
server = ../../secrets/ssh/ed25519_server.pub;
miniserver = ../../secrets/ssh/ed25519_miniserver.pub;
galaxy = ../../secrets/ssh/ed25519_galaxy.pub;
phone = ../../secrets/ssh/ed25519_phone.pub;
vps = ../../secrets/ssh/ed25519_vps.pub;
emacs = ../../secrets/ssh/ed25519_emacs.pub;
# Build user keys (nixremote)
nixworkstation = ../../secrets/ssh/ed25519_nixworkstation.pub;
nixserver = ../../secrets/ssh/ed25519_nixserver.pub;
nixminiserver = ../../secrets/ssh/ed25519_nixminiserver.pub;
};
getSshKeys = keyNames: keyNames |> map (name: inputs.self.lib.sshKeys.${name});
}; };
}; };
} }