Compare commits
15
Commits
7d6482587a
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9d2e52675e | ||
|
|
6c5c69945a | ||
|
|
9883f3d461 | ||
|
|
6d86bb8368 | ||
|
|
0dbc4792d4 | ||
|
|
753b763b6f | ||
|
|
2a690681cb | ||
|
|
82f4a2e1d4 | ||
|
|
eb18897355 | ||
|
|
00679a2c04 | ||
|
|
8e819e01ea | ||
|
|
cf4c179fc4 | ||
|
|
c991768cc2 | ||
|
|
268879ee01 | ||
|
|
7e9f617965 |
No files matched your search
Generated
+60
-167
@@ -7,11 +7,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1765794845,
|
"lastModified": 1779135526,
|
||||||
"narHash": "sha256-YD5QWlGnusNbZCqR3pxG8tRxx9yUXayLZfAJRWspq2s=",
|
"narHash": "sha256-glCununz6lmaK5fs2X946HA3EkNxB2JagdAAvInuRYU=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "disko",
|
"repo": "disko",
|
||||||
"rev": "7194cfe5b7a3660726b0fe7296070eaef601cae9",
|
"rev": "d405a179887d52b24c0ddd31e09a150bd1f66779",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -20,58 +20,6 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"flake-compat": {
|
|
||||||
"flake": false,
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1747046372,
|
|
||||||
"narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=",
|
|
||||||
"owner": "edolstra",
|
|
||||||
"repo": "flake-compat",
|
|
||||||
"rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "edolstra",
|
|
||||||
"repo": "flake-compat",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"flake-utils": {
|
|
||||||
"inputs": {
|
|
||||||
"systems": "systems"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1731533236,
|
|
||||||
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"flake-utils_2": {
|
|
||||||
"inputs": {
|
|
||||||
"systems": "systems_2"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1731533236,
|
|
||||||
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"home-manager": {
|
"home-manager": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
@@ -79,11 +27,32 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1765980955,
|
"lastModified": 1779157263,
|
||||||
"narHash": "sha256-rB45jv4uwC90vM9UZ70plfvY/2Kdygs+zlQ07dGQFk4=",
|
"narHash": "sha256-VbiyZkRf8/qr7ObmlyfOHJsNAW5tyZ4MB1+cUwAwdrw=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "home-manager",
|
"repo": "home-manager",
|
||||||
"rev": "89c9508bbe9b40d36b3dc206c2483ef176f15173",
|
"rev": "866412a19866b4a8e32d2306a118040afa2b840c",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nix-community",
|
||||||
|
"repo": "home-manager",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"home-manager_2": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"impermanence",
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1768598210,
|
||||||
|
"narHash": "sha256-kkgA32s/f4jaa4UG+2f8C225Qvclxnqs76mf8zvTVPg=",
|
||||||
|
"owner": "nix-community",
|
||||||
|
"repo": "home-manager",
|
||||||
|
"rev": "c47b2cc64a629f8e075de52e4742de688f930dc6",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -93,12 +62,16 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"impermanence": {
|
"impermanence": {
|
||||||
|
"inputs": {
|
||||||
|
"home-manager": "home-manager_2",
|
||||||
|
"nixpkgs": "nixpkgs"
|
||||||
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1737831083,
|
"lastModified": 1769548169,
|
||||||
"narHash": "sha256-LJggUHbpyeDvNagTUrdhe/pRVp4pnS6wVKALS782gRI=",
|
"narHash": "sha256-03+JxvzmfwRu+5JafM0DLbxgHttOQZkUtDWBmeUkN8Y=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "impermanence",
|
"repo": "impermanence",
|
||||||
"rev": "4b3e914cdf97a5b536a889e939fb2fd2b043a170",
|
"rev": "7b1d382faf603b6d264f58627330f9faa5cba149",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -107,76 +80,13 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"madd": {
|
|
||||||
"inputs": {
|
|
||||||
"flake-utils": "flake-utils",
|
|
||||||
"nixpkgs": [
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1754781336,
|
|
||||||
"narHash": "sha256-EUavinU3psYqVDx7Cjdypsf4dUymdu1yawbwRYv6wbM=",
|
|
||||||
"ref": "refs/heads/master",
|
|
||||||
"rev": "d490b648ac5acb65aa24c8e8314c1a6fa9e2c0c1",
|
|
||||||
"revCount": 8,
|
|
||||||
"type": "git",
|
|
||||||
"url": "https://git.bulthuis.dev/Jan/madd"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"type": "git",
|
|
||||||
"url": "https://git.bulthuis.dev/Jan/madd"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nix-minecraft": {
|
|
||||||
"inputs": {
|
|
||||||
"flake-compat": "flake-compat",
|
|
||||||
"flake-utils": "flake-utils_2",
|
|
||||||
"nixpkgs": [
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1751650156,
|
|
||||||
"narHash": "sha256-1gIPVDf159TQlcVg3WQBHMZVn8RllHOa8eT7AJPj2IE=",
|
|
||||||
"owner": "Jan-Bulthuis",
|
|
||||||
"repo": "nix-minecraft",
|
|
||||||
"rev": "d3b3779fd78bd55db24d25e896438b2b51cbb6cb",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "Jan-Bulthuis",
|
|
||||||
"repo": "nix-minecraft",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nix-modpack": {
|
|
||||||
"inputs": {
|
|
||||||
"nixpkgs": [
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1747559249,
|
|
||||||
"narHash": "sha256-+ygKEGMVcXNklO4RDYSd5XzydDmQOZWcOcxYZf/PH1U=",
|
|
||||||
"owner": "Jan-Bulthuis",
|
|
||||||
"repo": "nix-modpack",
|
|
||||||
"rev": "a093625c2847afc3ef257513161c7fe318c6be1c",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "Jan-Bulthuis",
|
|
||||||
"repo": "nix-modpack",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1765779637,
|
"lastModified": 1768564909,
|
||||||
"narHash": "sha256-KJ2wa/BLSrTqDjbfyNx70ov/HdgNBCBBSQP3BIzKnv4=",
|
"narHash": "sha256-Kell/SpJYVkHWMvnhqJz/8DqQg2b6PguxVWOuadbHCc=",
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "1306659b587dc277866c7b69eb97e5f07864d8c4",
|
"rev": "e4bae1bd10c9c57b2cf517953ab70060a828ee6f",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -188,11 +98,11 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs-stable": {
|
"nixpkgs-stable": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1765687488,
|
"lastModified": 1767313136,
|
||||||
"narHash": "sha256-7YAJ6xgBAQ/Nr+7MI13Tui1ULflgAdKh63m1tfYV7+M=",
|
"narHash": "sha256-16KkgfdYqjaeRGBaYsNrhPRRENs0qzkQVUooNHtoy2w=",
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "d02bcc33948ca19b0aaa0213fe987ceec1f4ebe1",
|
"rev": "ac62194c3917d5f474c1a844b6fd6da2db95077d",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -202,15 +112,28 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"nixpkgs_2": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1778869304,
|
||||||
|
"narHash": "sha256-30sZNZoA1cqF5JNO9fVX+wgiQYjB7HJqqJ4ztCDeBZE=",
|
||||||
|
"owner": "nixos",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "d233902339c02a9c334e7e593de68855ad26c4cb",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nixos",
|
||||||
|
"ref": "nixos-unstable",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
"root": {
|
"root": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"disko": "disko",
|
"disko": "disko",
|
||||||
"home-manager": "home-manager",
|
"home-manager": "home-manager",
|
||||||
"impermanence": "impermanence",
|
"impermanence": "impermanence",
|
||||||
"madd": "madd",
|
"nixpkgs": "nixpkgs_2",
|
||||||
"nix-minecraft": "nix-minecraft",
|
|
||||||
"nix-modpack": "nix-modpack",
|
|
||||||
"nixpkgs": "nixpkgs",
|
|
||||||
"nixpkgs-stable": "nixpkgs-stable",
|
"nixpkgs-stable": "nixpkgs-stable",
|
||||||
"secrets": "secrets",
|
"secrets": "secrets",
|
||||||
"sops-nix": "sops-nix"
|
"sops-nix": "sops-nix"
|
||||||
@@ -238,11 +161,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1765836173,
|
"lastModified": 1777944972,
|
||||||
"narHash": "sha256-hWRYfdH2ONI7HXbqZqW8Q1y9IRbnXWvtvt/ONZovSNY=",
|
"narHash": "sha256-VfGRo1qTBKOe3s2gOv8LSoA6Fk19PvBlwQ1ECN0Evn8=",
|
||||||
"owner": "Mic92",
|
"owner": "Mic92",
|
||||||
"repo": "sops-nix",
|
"repo": "sops-nix",
|
||||||
"rev": "443a7f2e7e118c4fc63b7fae05ab3080dd0e5c63",
|
"rev": "c591bf665727040c6cc5cb409079acb22dcce33c",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -250,36 +173,6 @@
|
|||||||
"repo": "sops-nix",
|
"repo": "sops-nix",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
|
||||||
"systems": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1681028828,
|
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"systems_2": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1681028828,
|
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"root": "root",
|
"root": "root",
|
||||||
|
|||||||
@@ -19,15 +19,20 @@
|
|||||||
impermanence.url = "github:nix-community/impermanence";
|
impermanence.url = "github:nix-community/impermanence";
|
||||||
|
|
||||||
# MADD
|
# MADD
|
||||||
madd.url = "git+https://git.bulthuis.dev/Jan/madd";
|
# madd.url = "git+https://git.bulthuis.dev/Jan/madd";
|
||||||
madd.inputs.nixpkgs.follows = "nixpkgs";
|
# madd.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
|
||||||
# For Minecraft VM
|
# For Minecraft VM
|
||||||
nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
|
# nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
|
||||||
nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
|
# nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
|
# nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
|
||||||
nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
|
# nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
};
|
};
|
||||||
|
|
||||||
outputs = inputs: import ./glue inputs;
|
outputs =
|
||||||
|
inputs:
|
||||||
|
import ./glue {
|
||||||
|
inherit inputs;
|
||||||
|
excludeHomeManagerModules = [ "impermanence" ];
|
||||||
|
};
|
||||||
}
|
}
|
||||||
+7
-2
@@ -1,4 +1,7 @@
|
|||||||
inputs:
|
{
|
||||||
|
inputs,
|
||||||
|
excludeHomeManagerModules ? [ ],
|
||||||
|
}:
|
||||||
let
|
let
|
||||||
flake = inputs.self;
|
flake = inputs.self;
|
||||||
nixpkgs = inputs.nixpkgs;
|
nixpkgs = inputs.nixpkgs;
|
||||||
@@ -113,7 +116,9 @@ let
|
|||||||
homeProfiles = collectModules "${flake}/profiles/home";
|
homeProfiles = collectModules "${flake}/profiles/home";
|
||||||
inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) (
|
inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) (
|
||||||
lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) (
|
lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) (
|
||||||
lib.attrValues inputs
|
lib.attrValues (
|
||||||
|
lib.attrsets.filterAttrs (name: entry: !(lib.elem name excludeHomeManagerModules)) inputs
|
||||||
|
)
|
||||||
)
|
)
|
||||||
);
|
);
|
||||||
|
|
||||||
|
|||||||
@@ -28,7 +28,7 @@
|
|||||||
# Include NFS client module
|
# Include NFS client module
|
||||||
boot.supportedFilesystems = [ "nfs" ];
|
boot.supportedFilesystems = [ "nfs" ];
|
||||||
|
|
||||||
# Set up K3S cluster with CoreDNS and FluxCD
|
# Set up K3S cluster with CoreDNS, FluxCD and Cilium
|
||||||
services.k3s = {
|
services.k3s = {
|
||||||
enable = true;
|
enable = true;
|
||||||
extraFlags = [
|
extraFlags = [
|
||||||
@@ -52,26 +52,12 @@
|
|||||||
sops-decrypt-key = {
|
sops-decrypt-key = {
|
||||||
source = config.sops.secrets."flux/sops-decrypt-key".path;
|
source = config.sops.secrets."flux/sops-decrypt-key".path;
|
||||||
};
|
};
|
||||||
# "0-secrets-backup-namespaces" = {
|
|
||||||
# source = "/opt/k3s-secrets-backup/namespaces.yaml";
|
|
||||||
# };
|
|
||||||
# "1-secrets-backup" = {
|
|
||||||
# source = "/opt/k3s-secrets-backup/secrets.yaml";
|
|
||||||
# };
|
|
||||||
# TODO: Move to flux config, once it is possible to easily install flux without CNI
|
|
||||||
cilium-secrets-namespace = {
|
|
||||||
content = {
|
|
||||||
apiVersion = "v1";
|
|
||||||
kind = "Namespace";
|
|
||||||
metadata.name = "cilium-secrets";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
# TODO: Move to flux config, once it is possible to easily install flux without CNI
|
# TODO: Move to flux config, once it is possible to easily install flux without CNI
|
||||||
gateway-api =
|
gateway-api =
|
||||||
let
|
let
|
||||||
manifest = pkgs.fetchurl {
|
manifest = pkgs.fetchurl {
|
||||||
url = "https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/experimental-install.yaml";
|
url = "https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.1/experimental-install.yaml";
|
||||||
hash = "sha256-08IN1MBDGTZWemkXypMfbc7RMQJCvmK57KB72YkuICU=";
|
hash = "sha256-VTMn4P8yoaK+RGv5OCPIQTz5JTrGptVAfuvR6NJp9p4=";
|
||||||
};
|
};
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
@@ -157,8 +143,8 @@
|
|||||||
cilium = {
|
cilium = {
|
||||||
name = "cilium";
|
name = "cilium";
|
||||||
repo = "oci://quay.io/cilium/charts/cilium";
|
repo = "oci://quay.io/cilium/charts/cilium";
|
||||||
version = "1.18.6";
|
version = "1.18.8";
|
||||||
hash = "sha256-+yr38lc5X1+eXCFE/rq/K0m4g/IiNFJHuhB+Nu24eUs=";
|
hash = "sha256-z1aDpWttEfQ+Af/l0Lxdafasm75QysRc8h7sPhWXr94=";
|
||||||
createNamespace = true;
|
createNamespace = true;
|
||||||
targetNamespace = "cilium-system";
|
targetNamespace = "cilium-system";
|
||||||
values = {
|
values = {
|
||||||
@@ -175,7 +161,6 @@
|
|||||||
gatewayAPI = {
|
gatewayAPI = {
|
||||||
enabled = true;
|
enabled = true;
|
||||||
gatewayClass.create = "true";
|
gatewayClass.create = "true";
|
||||||
secretsNamespace.create = false;
|
|
||||||
enableAlpn = true;
|
enableAlpn = true;
|
||||||
};
|
};
|
||||||
bgpControlPlane.enabled = true;
|
bgpControlPlane.enabled = true;
|
||||||
@@ -244,44 +229,9 @@
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
# Backup secrets to avoid reissueing them
|
|
||||||
modules.impermanence.directories = [
|
modules.impermanence.directories = [
|
||||||
"/opt/k3s-secrets-backup"
|
"/var/lib/rancher/k3s"
|
||||||
];
|
];
|
||||||
systemd.timers.k3s-secrets-backup-timer = {
|
|
||||||
wantedBy = [ "timers.target" ];
|
|
||||||
timerConfig = {
|
|
||||||
OnBootSec = "15m";
|
|
||||||
OnUnitActiveSec = "1h";
|
|
||||||
Unit = "k3s-secrets-backup.service";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
systemd.services.k3s-secrets-backup = {
|
|
||||||
script = ''
|
|
||||||
mkdir -p /opt/k3s-secrets-backup
|
|
||||||
touch /opt/k3s-secrets-backup/secrets.yaml
|
|
||||||
touch /opt/k3s-secrets-backup/namespaces.yaml
|
|
||||||
chmod 600 /opt/k3s-secrets-backup/secrets.yaml
|
|
||||||
chmod 600 /opt/k3s-secrets-backup/namespaces.yaml
|
|
||||||
|
|
||||||
${pkgs.k3s}/bin/kubectl get secrets -A -l controller.cert-manager\.io/fao=="true" -oyaml | ${pkgs.kubectl-neat}/bin/kubectl-neat > /opt/k3s-secrets-backup/secrets.yaml
|
|
||||||
|
|
||||||
echo "apiVersion: v1
|
|
||||||
kind: List
|
|
||||||
items:" > /opt/k3s-secrets-backup/namespaces.yaml
|
|
||||||
|
|
||||||
${pkgs.gnugrep}/bin/grep -oP '\snamespace: \K.*' /opt/k3s-secrets-backup/secrets.yaml | sort -u | while read -r ns; do
|
|
||||||
echo "- apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: $ns"
|
|
||||||
done >> /opt/k3s-secrets-backup/namespaces.yaml
|
|
||||||
'';
|
|
||||||
serviceConfig = {
|
|
||||||
Type = "oneshot";
|
|
||||||
User = "root";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
environment.variables = {
|
environment.variables = {
|
||||||
KUBECONFIG = "/etc/rancher/k3s/k3s.yaml";
|
KUBECONFIG = "/etc/rancher/k3s/k3s.yaml";
|
||||||
|
|||||||
@@ -7,6 +7,9 @@
|
|||||||
# Set hostid (required for ZFS)
|
# Set hostid (required for ZFS)
|
||||||
networking.hostId = "deadbeef";
|
networking.hostId = "deadbeef";
|
||||||
|
|
||||||
|
# Use thermald
|
||||||
|
services.thermald.ignoreCpuidCheck = true;
|
||||||
|
|
||||||
# Hardware configuration
|
# Hardware configuration
|
||||||
hardware.enableRedistributableFirmware = true;
|
hardware.enableRedistributableFirmware = true;
|
||||||
boot.initrd.availableKernelModules = [
|
boot.initrd.availableKernelModules = [
|
||||||
@@ -19,6 +22,7 @@
|
|||||||
boot.initrd.kernelModules = [ ];
|
boot.initrd.kernelModules = [ ];
|
||||||
boot.kernelModules = [ "kvm-intel" ];
|
boot.kernelModules = [ "kvm-intel" ];
|
||||||
boot.extraModulePackages = [ ];
|
boot.extraModulePackages = [ ];
|
||||||
|
boot.zfs.forceImportRoot = false;
|
||||||
hardware.cpu.intel.updateMicrocode = true;
|
hardware.cpu.intel.updateMicrocode = true;
|
||||||
|
|
||||||
# Filesystems
|
# Filesystems
|
||||||
|
|||||||
@@ -70,6 +70,7 @@ in
|
|||||||
mpris-label
|
mpris-label
|
||||||
pip-on-top
|
pip-on-top
|
||||||
rounded-window-corners-reborn
|
rounded-window-corners-reborn
|
||||||
|
caffeine
|
||||||
]);
|
]);
|
||||||
|
|
||||||
# Set up gnome terminal as changing the default terminal is a pain
|
# Set up gnome terminal as changing the default terminal is a pain
|
||||||
|
|||||||
@@ -39,7 +39,7 @@ in
|
|||||||
programs.git = {
|
programs.git = {
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|
||||||
extraConfig = {
|
settings = {
|
||||||
pull = {
|
pull = {
|
||||||
rebase = false;
|
rebase = false;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ in
|
|||||||
# Development packages
|
# Development packages
|
||||||
home.packages = with pkgs; [
|
home.packages = with pkgs; [
|
||||||
nix-tree
|
nix-tree
|
||||||
nixfmt-rfc-style
|
nixfmt
|
||||||
nixd
|
nixd
|
||||||
];
|
];
|
||||||
|
|
||||||
|
|||||||
@@ -2,11 +2,11 @@
|
|||||||
|
|
||||||
with lib;
|
with lib;
|
||||||
let
|
let
|
||||||
# cfg = config.modules.impermanence;
|
cfg = config.modules.impermanence;
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
options.modules.impermanence = {
|
options.modules.impermanence = {
|
||||||
# enable = mkEnableOption "Impermanence";
|
enable = mkEnableOption "Impermanence";
|
||||||
directories = mkOption {
|
directories = mkOption {
|
||||||
type = types.listOf types.str;
|
type = types.listOf types.str;
|
||||||
default = [ ];
|
default = [ ];
|
||||||
@@ -23,12 +23,12 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
# config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
# home.persistence."/persist/home/${config.home.username}" = {
|
home.persistence."/persist/home" = {
|
||||||
# enable = true;
|
enable = true;
|
||||||
# allowOther = true;
|
hideMounts = true;
|
||||||
# directories = cfg.directories;
|
directories = cfg.directories;
|
||||||
# files = cfg.files;
|
files = cfg.files;
|
||||||
# };
|
};
|
||||||
# };
|
};
|
||||||
}
|
}
|
||||||
@@ -57,6 +57,9 @@ in
|
|||||||
modules.networkmanager.enable = true;
|
modules.networkmanager.enable = true;
|
||||||
|
|
||||||
# Impermanence
|
# Impermanence
|
||||||
modules.impermanence.directories = [ "/etc/NetworkManager/system-connections" ];
|
modules.impermanence.directories = [
|
||||||
|
"/etc/NetworkManager/system-connections"
|
||||||
|
"/var/lib/bluetooth"
|
||||||
|
];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -16,7 +16,11 @@ in
|
|||||||
# TODO: Add nvidia settings back in
|
# TODO: Add nvidia settings back in
|
||||||
# TODO: Move to nvidia module
|
# TODO: Move to nvidia module
|
||||||
hardware.nvidia = {
|
hardware.nvidia = {
|
||||||
open = true;
|
open = false;
|
||||||
|
prime = {
|
||||||
|
intelBusId = "PCI:0@0:2:0";
|
||||||
|
nvidiaBusId = "PCI:1@0:0:0";
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -57,25 +57,25 @@ in
|
|||||||
directories = cfg.directories;
|
directories = cfg.directories;
|
||||||
files = cfg.files;
|
files = cfg.files;
|
||||||
};
|
};
|
||||||
"/persist/home" = {
|
# "/persist/home" = {
|
||||||
enable = true;
|
# enable = true;
|
||||||
hideMounts = true;
|
# hideMounts = true;
|
||||||
users = (
|
# users = (
|
||||||
lib.mapAttrs' (
|
# lib.mapAttrs' (
|
||||||
name: value:
|
# name: value:
|
||||||
let
|
# let
|
||||||
user = name;
|
# user = name;
|
||||||
homeDir = "/home/${user}";
|
# homeDir = "/home/${user}";
|
||||||
impConfig = value.modules.impermanence;
|
# impConfig = value.modules.impermanence;
|
||||||
in
|
# in
|
||||||
lib.nameValuePair user {
|
# lib.nameValuePair user {
|
||||||
home = homeDir;
|
# home = homeDir;
|
||||||
directories = impConfig.directories;
|
# directories = impConfig.directories;
|
||||||
files = impConfig.files;
|
# files = impConfig.files;
|
||||||
}
|
# }
|
||||||
) config.home-manager.users
|
# ) config.home-manager.users
|
||||||
);
|
# );
|
||||||
};
|
# };
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -16,6 +16,7 @@ in
|
|||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
modules = {
|
modules = {
|
||||||
|
impermanence.enable = true;
|
||||||
# btop.enable = true;
|
# btop.enable = true;
|
||||||
direnv.enable = true;
|
direnv.enable = true;
|
||||||
fish.enable = true;
|
fish.enable = true;
|
||||||
|
|||||||
@@ -44,7 +44,7 @@ in
|
|||||||
two-finger-scrolling-enabled = true;
|
two-finger-scrolling-enabled = true;
|
||||||
};
|
};
|
||||||
"org/gnome/mutter" = {
|
"org/gnome/mutter" = {
|
||||||
workspaces-only-on-primary = false;
|
workspaces-only-on-primary = true;
|
||||||
};
|
};
|
||||||
"org/gnome/nautilus/icon-view" = {
|
"org/gnome/nautilus/icon-view" = {
|
||||||
default-zoom-level = "small";
|
default-zoom-level = "small";
|
||||||
@@ -67,6 +67,7 @@ in
|
|||||||
"rounded-window-corners@fxgn"
|
"rounded-window-corners@fxgn"
|
||||||
"media-progress@krypion17"
|
"media-progress@krypion17"
|
||||||
"mprisLabel@moon-0xff.github.com"
|
"mprisLabel@moon-0xff.github.com"
|
||||||
|
"caffeube@patapon.info"
|
||||||
];
|
];
|
||||||
last-selected-power-profile = "power-saver";
|
last-selected-power-profile = "power-saver";
|
||||||
};
|
};
|
||||||
|
|||||||
+75
-3
@@ -25,7 +25,7 @@ in
|
|||||||
thunderbird
|
thunderbird
|
||||||
signal-desktop
|
signal-desktop
|
||||||
prusa-slicer
|
prusa-slicer
|
||||||
freecad-wayland
|
pkgs-stable.freecad-wayland
|
||||||
inkscape
|
inkscape
|
||||||
# ente-auth
|
# ente-auth
|
||||||
audacity
|
audacity
|
||||||
@@ -33,7 +33,7 @@ in
|
|||||||
# pkgs-stable.winbox
|
# pkgs-stable.winbox
|
||||||
winbox4
|
winbox4
|
||||||
# whatsapp-for-linux
|
# whatsapp-for-linux
|
||||||
wasistlos
|
karere
|
||||||
discord
|
discord
|
||||||
steam
|
steam
|
||||||
spotify
|
spotify
|
||||||
@@ -49,6 +49,11 @@ in
|
|||||||
# kicad
|
# kicad
|
||||||
vlc
|
vlc
|
||||||
authenticator
|
authenticator
|
||||||
|
hotspot
|
||||||
|
btop
|
||||||
|
winboat
|
||||||
|
hieroglyphic
|
||||||
|
shortwave
|
||||||
|
|
||||||
podman
|
podman
|
||||||
podman-compose
|
podman-compose
|
||||||
@@ -57,6 +62,14 @@ in
|
|||||||
gnome-logs
|
gnome-logs
|
||||||
];
|
];
|
||||||
|
|
||||||
|
programs.zathura = {
|
||||||
|
enable = true;
|
||||||
|
options = {
|
||||||
|
synctex = true;
|
||||||
|
synctex-editor-command = "${pkgs.texlab}/bin/texlab inverse-search -i %{input} -l %{line}";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
programs.helix = {
|
programs.helix = {
|
||||||
enable = true;
|
enable = true;
|
||||||
defaultEditor = true;
|
defaultEditor = true;
|
||||||
@@ -67,6 +80,34 @@ in
|
|||||||
# fallback = "default";
|
# fallback = "default";
|
||||||
# };
|
# };
|
||||||
# };
|
# };
|
||||||
|
settings =
|
||||||
|
let
|
||||||
|
move_line_up = [
|
||||||
|
"extend_to_line_bounds"
|
||||||
|
"delete_selection"
|
||||||
|
"move_line_up"
|
||||||
|
"paste_before"
|
||||||
|
];
|
||||||
|
move_line_down = [
|
||||||
|
"extend_to_line_bounds"
|
||||||
|
"delete_selection"
|
||||||
|
"paste_after"
|
||||||
|
];
|
||||||
|
in
|
||||||
|
{
|
||||||
|
keys.normal = {
|
||||||
|
"A-up" = move_line_up;
|
||||||
|
"A-down" = move_line_down;
|
||||||
|
"A-k" = move_line_up;
|
||||||
|
"A-j" = move_line_down;
|
||||||
|
};
|
||||||
|
keys.select = {
|
||||||
|
"A-up" = move_line_up;
|
||||||
|
"A-down" = move_line_down;
|
||||||
|
"A-k" = move_line_up;
|
||||||
|
"A-j" = move_line_down;
|
||||||
|
};
|
||||||
|
};
|
||||||
extraPackages = with pkgs; [
|
extraPackages = with pkgs; [
|
||||||
bash-language-server # Bash
|
bash-language-server # Bash
|
||||||
fish-lsp # Fish
|
fish-lsp # Fish
|
||||||
@@ -96,7 +137,8 @@ in
|
|||||||
ruff # Python
|
ruff # Python
|
||||||
basedpyright # Python
|
basedpyright # Python
|
||||||
|
|
||||||
helix-gpt # Copilot
|
#helix-gpt # Copilot
|
||||||
|
ltex-ls-plus # Spellchecking
|
||||||
|
|
||||||
# texlab # Latex, Bibtex
|
# texlab # Latex, Bibtex
|
||||||
# bibtex-tidy # Bibtex
|
# bibtex-tidy # Bibtex
|
||||||
@@ -115,6 +157,22 @@ in
|
|||||||
];
|
];
|
||||||
languages = {
|
languages = {
|
||||||
language-server = {
|
language-server = {
|
||||||
|
ltex = {
|
||||||
|
command = "ltex-ls-plus";
|
||||||
|
config.ltex = { };
|
||||||
|
};
|
||||||
|
texlab = {
|
||||||
|
command = "texlab";
|
||||||
|
config.texlab = {
|
||||||
|
build.onSave = true;
|
||||||
|
forwardSearch.executable = "${config.programs.zathura.package}/bin/zathura";
|
||||||
|
forwardSearch.args = [
|
||||||
|
"--synctex-forward"
|
||||||
|
"%l:1:%f"
|
||||||
|
"%p"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
basedpyright = {
|
basedpyright = {
|
||||||
command = "basedpyright-langserver";
|
command = "basedpyright-langserver";
|
||||||
args = [ "--stdio" ];
|
args = [ "--stdio" ];
|
||||||
@@ -132,6 +190,16 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
language = [
|
language = [
|
||||||
|
{
|
||||||
|
name = "latex";
|
||||||
|
# language-servers = [
|
||||||
|
# { name = "texlab"; }
|
||||||
|
# { name = "ltex"; }
|
||||||
|
# ];
|
||||||
|
soft-wrap = {
|
||||||
|
enable = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
{
|
{
|
||||||
name = "python";
|
name = "python";
|
||||||
language-servers = [
|
language-servers = [
|
||||||
@@ -154,6 +222,10 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
systemd.user.tmpfiles.rules = [
|
||||||
|
"d ${config.home.homeDirectory}/Downloads - - - - -"
|
||||||
|
];
|
||||||
|
|
||||||
modules = {
|
modules = {
|
||||||
profiles.gnome.enable = true;
|
profiles.gnome.enable = true;
|
||||||
|
|
||||||
|
|||||||
Reference in new issue
Block a user