Compare commits
126
Commits
disko
...
081084648f
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
081084648f | ||
|
|
9d629c4656 | ||
|
|
4a65f64a20 | ||
|
|
d3b3e9be1c | ||
|
|
5224a6e4b6 | ||
|
|
dd0778e5f0 | ||
|
|
7247fc94ab | ||
|
|
655803bd1f | ||
|
|
9992039edb | ||
|
|
f31c0f92da | ||
|
|
307aac4ae0 | ||
|
|
160185ef20 | ||
|
|
42619807bc | ||
|
|
86c853de20 | ||
|
|
f52e880b4c | ||
|
|
e157071962 | ||
|
|
d324c957be | ||
|
|
1fa6092498 | ||
|
|
e43a91fe31 | ||
|
|
f06880d6d7 | ||
|
|
fa17ce5b03 | ||
|
|
cf42666c1f | ||
|
|
df49791fb7 | ||
|
|
cf4a324617 | ||
|
|
66b2662030 | ||
|
|
21045c3dd1 | ||
|
|
5f68b9b1e6 | ||
|
|
bb6edfdefd | ||
|
|
afebac0d46 | ||
|
|
06eaf13ec0 | ||
|
|
0b5beaf63d | ||
|
|
03604f9352 | ||
|
|
5047f1ab24 | ||
|
|
22271d33d1 | ||
|
|
c8bf78999a | ||
|
|
0d25c1deff | ||
|
|
3603fe28a7 | ||
|
|
ce7c940f65 | ||
|
|
d8327c3edf | ||
|
|
af9f7e0ee0 | ||
|
|
3285b483e2 | ||
|
|
affa333969 | ||
|
|
3c20190709 | ||
|
|
0305b8d33a | ||
|
|
5ade637e57 | ||
|
|
029ff0c9a3 | ||
|
|
db4bd8cfd9 | ||
|
|
41d25d9695 | ||
|
|
7e2e012f3a | ||
|
|
071e904990 | ||
|
|
b68ca558d8 | ||
|
|
cf760b8b85 | ||
|
|
7d4ee43283 | ||
|
|
4e08366901 | ||
|
|
a0ca155f7c | ||
|
|
110aa4215f | ||
|
|
08a161ff0d | ||
|
|
f4472de631 | ||
|
|
3c154de819 | ||
|
|
709040c072 | ||
|
|
28193823c8 | ||
|
|
dd25c9323d | ||
|
|
5796bee499 | ||
|
|
986afe4b32 | ||
|
|
537e30a347 | ||
|
|
2fec5ead38 | ||
|
|
d4e6283c2f | ||
|
|
32e7d99292 | ||
|
|
d9dab5b9d3 | ||
|
|
cdd94eefb3 | ||
|
|
209dbea02a | ||
|
|
c683809a78 | ||
|
|
739e335c28 | ||
|
|
3c6758b343 | ||
|
|
799b91a509 | ||
|
|
50ff958d35 | ||
|
|
ecc2779ce9 | ||
|
|
10dab81fb5 | ||
|
|
03e96662cc | ||
|
|
d6d54e213e | ||
|
|
f491be0ace | ||
|
|
fef1eff181 | ||
|
|
e869e5d790 | ||
|
|
48caacd9e5 | ||
|
|
ce4401033a | ||
|
|
8b331ad3ae | ||
|
|
417383f89b | ||
|
|
cc75c95ad4 | ||
|
|
a321251b93 | ||
|
|
54677248af | ||
|
|
d8f18016cd | ||
|
|
6522ebc15e | ||
|
|
10216784e8 | ||
|
|
f3abb6d2f3 | ||
|
|
936d654877 | ||
|
|
61d207db04 | ||
|
|
e7b66cb40c | ||
|
|
c9b18219af | ||
|
|
d5c4a78fba | ||
|
|
369d655a38 | ||
|
|
eab130b99d | ||
|
|
5ce6b9bdf2 | ||
|
|
5db52a4f84 | ||
|
|
3524f6b038 | ||
|
|
0cf53a97cf | ||
|
|
46fe5b8056 | ||
|
|
ec3d9e6049 | ||
|
|
fc0476ca5a | ||
|
|
4b7c62d00b | ||
|
|
cfc276184f | ||
|
|
87b50bfb4d | ||
|
|
1bc34518e1 | ||
|
|
f1dcb8c72b | ||
|
|
ec002467fa | ||
|
|
5a228cb375 | ||
|
|
d53e395d42 | ||
|
|
cb39f82a48 | ||
|
|
0efee5bceb | ||
|
|
844118055c | ||
|
|
0ba9de0030 | ||
|
|
a745b35c84 | ||
|
|
6c74dcbc22 | ||
|
|
76e609372f | ||
|
|
cd91944b1e | ||
|
|
bebd2748d1 | ||
|
|
12a4ba0482 |
No files matched your search
@@ -4,8 +4,39 @@ My NixOS configuration.
|
|||||||
|
|
||||||
## Installation
|
## Installation
|
||||||
|
|
||||||
For disk configuration we use disko, this means that installing the system from the configuration is just a single command:
|
For disk configuration we use disko, but for secrets management we use sops-nix and the particular setup makes the installation process a bit more involved. It is required that the computer from which the installation is being run has access to the `nixos-secrets` repository, otherwise you will need to manually add the required ssh keys to the installation image.
|
||||||
|
```bash
|
||||||
|
# Load into the installer
|
||||||
|
sudo passwd # Set a root password
|
||||||
|
|
||||||
|
# From a machine with network access to the installer
|
||||||
|
# and access to the nixos-secrets repo
|
||||||
|
ssh -A root@(installer-ip)
|
||||||
|
|
||||||
|
# Set up disks
|
||||||
|
nix-shell -p disko
|
||||||
|
disko --mode disko --flake git+https://git.bulthuis.dev/Jan/nixos-config#(system)
|
||||||
|
exit
|
||||||
|
|
||||||
|
# Install NixOS
|
||||||
|
nixos-install --no-channel-copy --no-root-password --flake git+https://git.bulthuis.dev/Jan/nixos-config#(system)
|
||||||
|
|
||||||
|
# Set up host credentials for access to the secrets
|
||||||
|
cd /mnt/persist/system/etc/sops
|
||||||
|
touch sops_ed25519_key
|
||||||
|
chmod 600 sops_ed25519_key
|
||||||
|
nano sops_ed25519_key
|
||||||
```
|
```
|
||||||
sudo nix --experimental-features "nix-command flakes" run "github:nix-community/disko/latest#disko-install" -- --flake git+https://git.bulthuis.dev/Jan/dotfiles#<hostname> --disk main /dev/sda
|
If `nixos-install` is being stopped by the OOM-killer, you can try adding `-j 1` to limit the amount of jobs that will be executed at the same time to 1. It might require running nixos-install multiple times untill it has managed to download all requirements and slowly start building the rest of the system.
|
||||||
|
|
||||||
|
## Updating
|
||||||
|
|
||||||
|
To update the system configuration, it is a single command:
|
||||||
|
```bash
|
||||||
|
sudo system-update
|
||||||
```
|
```
|
||||||
|
Or if this shell script has not been installed for some reason:
|
||||||
|
```bash
|
||||||
|
sudo nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/nixos-config
|
||||||
|
```
|
||||||
|
Sometimes it may be necessary to reboot of course.
|
||||||
Generated
+128
-19
@@ -7,11 +7,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1748225455,
|
"lastModified": 1758287904,
|
||||||
"narHash": "sha256-AzlJCKaM4wbEyEpV3I/PUq5mHnib2ryEy32c+qfj6xk=",
|
"narHash": "sha256-IGmaEf3Do8o5Cwp1kXBN1wQmZwQN3NLfq5t4nHtVtcU=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "disko",
|
"repo": "disko",
|
||||||
"rev": "a894f2811e1ee8d10c50560551e50d6ab3c392ba",
|
"rev": "67ff9807dd148e704baadbd4fd783b54282ca627",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -23,11 +23,11 @@
|
|||||||
"flake-compat": {
|
"flake-compat": {
|
||||||
"flake": false,
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1733328505,
|
"lastModified": 1747046372,
|
||||||
"narHash": "sha256-NeCCThCEP3eCl2l/+27kNNK7QrwZB1IJCrXfrbv5oqU=",
|
"narHash": "sha256-CIVLLkVgvHYbgI2UpXvIIBJ12HWgX+fjA8Xf8PUmqCY=",
|
||||||
"owner": "edolstra",
|
"owner": "edolstra",
|
||||||
"repo": "flake-compat",
|
"repo": "flake-compat",
|
||||||
"rev": "ff81ac966bb2cae68946d5ed5fc4994f96d0ffec",
|
"rev": "9100a0f413b0c601e0533d1d94ffd501ce2e7885",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -54,6 +54,24 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"flake-utils_2": {
|
||||||
|
"inputs": {
|
||||||
|
"systems": "systems_2"
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1731533236,
|
||||||
|
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
|
||||||
|
"owner": "numtide",
|
||||||
|
"repo": "flake-utils",
|
||||||
|
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "numtide",
|
||||||
|
"repo": "flake-utils",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
"home-manager": {
|
"home-manager": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
@@ -61,11 +79,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1748134483,
|
"lastModified": 1759853171,
|
||||||
"narHash": "sha256-5PBK1nV8X39K3qUj8B477Aa2RdbLq3m7wRxUKRtggX4=",
|
"narHash": "sha256-uqbhyXtqMbYIiMqVqUhNdSuh9AEEkiasoK3mIPIVRhk=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "home-manager",
|
"repo": "home-manager",
|
||||||
"rev": "c1e671036224089937e111e32ea899f59181c383",
|
"rev": "1a09eb84fa9e33748432a5253102d01251f72d6d",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -89,20 +107,41 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nix-minecraft": {
|
"madd": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"flake-compat": "flake-compat",
|
|
||||||
"flake-utils": "flake-utils",
|
"flake-utils": "flake-utils",
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
"nixpkgs"
|
"nixpkgs"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1747581338,
|
"lastModified": 1754781336,
|
||||||
"narHash": "sha256-/+H9qce+NPsEcAC31s3pbD64nB6GKC3+3ZNLV1+tffk=",
|
"narHash": "sha256-EUavinU3psYqVDx7Cjdypsf4dUymdu1yawbwRYv6wbM=",
|
||||||
|
"ref": "refs/heads/master",
|
||||||
|
"rev": "d490b648ac5acb65aa24c8e8314c1a6fa9e2c0c1",
|
||||||
|
"revCount": 8,
|
||||||
|
"type": "git",
|
||||||
|
"url": "https://git.bulthuis.dev/Jan/madd"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"type": "git",
|
||||||
|
"url": "https://git.bulthuis.dev/Jan/madd"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"nix-minecraft": {
|
||||||
|
"inputs": {
|
||||||
|
"flake-compat": "flake-compat",
|
||||||
|
"flake-utils": "flake-utils_2",
|
||||||
|
"nixpkgs": [
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1751650156,
|
||||||
|
"narHash": "sha256-1gIPVDf159TQlcVg3WQBHMZVn8RllHOa8eT7AJPj2IE=",
|
||||||
"owner": "Jan-Bulthuis",
|
"owner": "Jan-Bulthuis",
|
||||||
"repo": "nix-minecraft",
|
"repo": "nix-minecraft",
|
||||||
"rev": "44b6b40d7a3e0a114567b38a203029a5bc67e838",
|
"rev": "d3b3779fd78bd55db24d25e896438b2b51cbb6cb",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -133,16 +172,16 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1747958103,
|
"lastModified": 1759831965,
|
||||||
"narHash": "sha256-qmmFCrfBwSHoWw7cVK4Aj+fns+c54EBP8cGqp/yK410=",
|
"narHash": "sha256-vgPm2xjOmKdZ0xKA6yLXPJpjOtQPHfaZDRtH+47XEBo=",
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "fe51d34885f7b5e3e7b59572796e1bcb427eccb1",
|
"rev": "c9b6fb798541223bbb396d287d16f43520250518",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"ref": "nixpkgs-unstable",
|
"ref": "nixos-unstable",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
@@ -152,9 +191,64 @@
|
|||||||
"disko": "disko",
|
"disko": "disko",
|
||||||
"home-manager": "home-manager",
|
"home-manager": "home-manager",
|
||||||
"impermanence": "impermanence",
|
"impermanence": "impermanence",
|
||||||
|
"madd": "madd",
|
||||||
"nix-minecraft": "nix-minecraft",
|
"nix-minecraft": "nix-minecraft",
|
||||||
"nix-modpack": "nix-modpack",
|
"nix-modpack": "nix-modpack",
|
||||||
"nixpkgs": "nixpkgs"
|
"nixpkgs": "nixpkgs",
|
||||||
|
"secrets": "secrets",
|
||||||
|
"sops-nix": "sops-nix",
|
||||||
|
"stable-nixpkgs": "stable-nixpkgs"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"secrets": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1753885198,
|
||||||
|
"narHash": "sha256-UM57wnpaDbG/l4891u0LnYFgyyr9o3w9ot4gmjBL6mA=",
|
||||||
|
"ref": "refs/heads/main",
|
||||||
|
"rev": "9d5275538af75b1539faf16c478140aaf2ed6738",
|
||||||
|
"revCount": 15,
|
||||||
|
"type": "git",
|
||||||
|
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"type": "git",
|
||||||
|
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"sops-nix": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1759635238,
|
||||||
|
"narHash": "sha256-UvzKi02LMFP74csFfwLPAZ0mrE7k6EiYaKecplyX9Qk=",
|
||||||
|
"owner": "Mic92",
|
||||||
|
"repo": "sops-nix",
|
||||||
|
"rev": "6e5a38e08a2c31ae687504196a230ae00ea95133",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "Mic92",
|
||||||
|
"repo": "sops-nix",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"stable-nixpkgs": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1759735786,
|
||||||
|
"narHash": "sha256-a0+h02lyP2KwSNrZz4wLJTu9ikujNsTWIC874Bv7IJ0=",
|
||||||
|
"owner": "nixos",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "20c4598c84a671783f741e02bf05cbfaf4907cff",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nixos",
|
||||||
|
"ref": "nixos-25.05",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"systems": {
|
"systems": {
|
||||||
@@ -171,6 +265,21 @@
|
|||||||
"repo": "default",
|
"repo": "default",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
|
},
|
||||||
|
"systems_2": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1681028828,
|
||||||
|
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||||
|
"owner": "nix-systems",
|
||||||
|
"repo": "default",
|
||||||
|
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "nix-systems",
|
||||||
|
"repo": "default",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"root": "root",
|
"root": "root",
|
||||||
|
|||||||
@@ -3,13 +3,25 @@
|
|||||||
|
|
||||||
inputs = {
|
inputs = {
|
||||||
# General inputs
|
# General inputs
|
||||||
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
|
stable-nixpkgs.url = "github:nixos/nixpkgs/nixos-25.05";
|
||||||
|
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
|
||||||
home-manager.url = "github:nix-community/home-manager";
|
home-manager.url = "github:nix-community/home-manager";
|
||||||
home-manager.inputs.nixpkgs.follows = "nixpkgs";
|
home-manager.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
|
||||||
|
# Secrets
|
||||||
|
sops-nix.url = "github:Mic92/sops-nix";
|
||||||
|
sops-nix.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
secrets.url = "git+ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets";
|
||||||
|
|
||||||
|
# Disk setup
|
||||||
disko.url = "github:nix-community/disko";
|
disko.url = "github:nix-community/disko";
|
||||||
disko.inputs.nixpkgs.follows = "nixpkgs";
|
disko.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
impermanence.url = "github:nix-community/impermanence";
|
impermanence.url = "github:nix-community/impermanence";
|
||||||
|
|
||||||
|
# MADD
|
||||||
|
madd.url = "git+https://git.bulthuis.dev/Jan/madd";
|
||||||
|
madd.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
|
||||||
# For Minecraft VM
|
# For Minecraft VM
|
||||||
nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
|
nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
|
||||||
nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
|
nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
|
||||||
|
|||||||
+4
-1
@@ -143,8 +143,11 @@ let
|
|||||||
usersModule =
|
usersModule =
|
||||||
{ ... }:
|
{ ... }:
|
||||||
{
|
{
|
||||||
|
home-manager.extraSpecialArgs = {
|
||||||
|
inherit inputs;
|
||||||
|
};
|
||||||
home-manager.sharedModules = homeModules ++ homeProfiles ++ inputHomeModules;
|
home-manager.sharedModules = homeModules ++ homeProfiles ++ inputHomeModules;
|
||||||
home-manager.useUserPackages = false; # TODO: See if this should be changed to true?
|
home-manager.useUserPackages = true;
|
||||||
home-manager.useGlobalPkgs = true;
|
home-manager.useGlobalPkgs = true;
|
||||||
home-manager.users = homesConfiguration;
|
home-manager.users = homesConfiguration;
|
||||||
users.users = usersConfiguration;
|
users.users = usersConfiguration;
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
{ flake, ... }:
|
{ inputs, pkgs, ... }:
|
||||||
|
|
||||||
{
|
{
|
||||||
# State version
|
# State version
|
||||||
@@ -13,6 +13,25 @@
|
|||||||
"wireshark"
|
"wireshark"
|
||||||
];
|
];
|
||||||
|
|
||||||
|
# Set up kerberos
|
||||||
|
security.krb5 = {
|
||||||
|
enable = true;
|
||||||
|
settings = {
|
||||||
|
libdefaults = {
|
||||||
|
rdns = false;
|
||||||
|
};
|
||||||
|
realms = (inputs.secrets.gewis.krb5Realm);
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# TODO: Remove once laptop is properly integrated into domain
|
||||||
|
programs.ssh = {
|
||||||
|
package = pkgs.openssh_gssapi;
|
||||||
|
extraConfig = ''
|
||||||
|
GSSAPIAuthentication yes
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
# Enable virtualisation for VMs
|
# Enable virtualisation for VMs
|
||||||
virtualisation.libvirtd.enable = true;
|
virtualisation.libvirtd.enable = true;
|
||||||
|
|
||||||
@@ -23,12 +42,17 @@
|
|||||||
usbmon.enable = true;
|
usbmon.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# Enable Nix-LD
|
||||||
|
programs.nix-ld = {
|
||||||
|
enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
# Set up wstunnel client
|
# Set up wstunnel client
|
||||||
services.wstunnel = {
|
services.wstunnel = {
|
||||||
enable = true;
|
enable = true;
|
||||||
clients.wg-tunnel = {
|
clients.wg-tunnel = {
|
||||||
connectTo = "wss://tunnel.bulthuis.dev:443";
|
connectTo = "wss://tunnel.bulthuis.dev:443";
|
||||||
localToRemote = [
|
settings.local-to-remote = [
|
||||||
"udp://51820:10.10.40.100:51820"
|
"udp://51820:10.10.40.100:51820"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -77,7 +77,7 @@
|
|||||||
group = "mixer";
|
group = "mixer";
|
||||||
extraGroups = [ "systemd-journal" ];
|
extraGroups = [ "systemd-journal" ];
|
||||||
openssh.authorizedKeys.keys = [
|
openssh.authorizedKeys.keys = [
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq jan@bulthuis.dev"
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq Personal"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
users.groups.mixer = { };
|
users.groups.mixer = { };
|
||||||
|
|||||||
@@ -1,7 +0,0 @@
|
|||||||
{ ... }:
|
|
||||||
|
|
||||||
{
|
|
||||||
home.stateVersion = "24.11";
|
|
||||||
|
|
||||||
modules.profiles.base.enable = true;
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
{
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
# State version
|
||||||
|
system.stateVersion = "25.05";
|
||||||
|
|
||||||
|
# Machine hostname
|
||||||
|
networking.hostName = "vm-infra";
|
||||||
|
|
||||||
|
# Enabled modules
|
||||||
|
modules = {
|
||||||
|
profiles.vm.enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Setup Tayga NAT64
|
||||||
|
services.tayga = {
|
||||||
|
enable = true;
|
||||||
|
ipv4 = {
|
||||||
|
address = "10.64.0.0";
|
||||||
|
router = {
|
||||||
|
address = "10.64.0.1";
|
||||||
|
};
|
||||||
|
pool = {
|
||||||
|
address = "10.64.0.1";
|
||||||
|
prefixLength = 16;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
ipv6 = {
|
||||||
|
router = {
|
||||||
|
address = "fc00:6464::1";
|
||||||
|
};
|
||||||
|
pool = {
|
||||||
|
address = "fc00:6464::";
|
||||||
|
prefixLength = 96;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -25,14 +25,27 @@
|
|||||||
|
|
||||||
# Set up minecraft servers
|
# Set up minecraft servers
|
||||||
users.users.local.extraGroups = [ "minecraft" ];
|
users.users.local.extraGroups = [ "minecraft" ];
|
||||||
|
modules.impermanence.directories = [
|
||||||
|
"/srv/minecraft"
|
||||||
|
];
|
||||||
services.minecraft-servers = {
|
services.minecraft-servers = {
|
||||||
enable = true;
|
enable = true;
|
||||||
eula = true;
|
eula = true;
|
||||||
openFirewall = true;
|
openFirewall = true;
|
||||||
servers = {
|
servers = {
|
||||||
modpack = {
|
vanilla = {
|
||||||
enable = true;
|
enable = true;
|
||||||
autoStart = true;
|
autoStart = true;
|
||||||
|
serverProperties = {
|
||||||
|
white-list = true;
|
||||||
|
difficulty = "normal";
|
||||||
|
max-players = 5;
|
||||||
|
};
|
||||||
|
package = inputs.nix-minecraft.legacyPackages.${pkgs.system}.fabricServers.fabric-1_21_7;
|
||||||
|
};
|
||||||
|
modpack = {
|
||||||
|
enable = false;
|
||||||
|
autoStart = true;
|
||||||
serverProperties = { };
|
serverProperties = { };
|
||||||
package = inputs.nix-modpack.packages.${pkgs.system}.mkModpackServer {
|
package = inputs.nix-modpack.packages.${pkgs.system}.mkModpackServer {
|
||||||
packUrl = "https://raw.githubusercontent.com/Jan-Bulthuis/Modpack/refs/heads/master/pack.toml";
|
packUrl = "https://raw.githubusercontent.com/Jan-Bulthuis/Modpack/refs/heads/master/pack.toml";
|
||||||
|
|||||||
@@ -1,7 +0,0 @@
|
|||||||
{ ... }:
|
|
||||||
|
|
||||||
{
|
|
||||||
home.stateVersion = "24.11";
|
|
||||||
|
|
||||||
modules.profiles.base.enable = true;
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,143 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
lib,
|
||||||
|
pkgs,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
# State version
|
||||||
|
system.stateVersion = "24.11";
|
||||||
|
|
||||||
|
# Machine hostname
|
||||||
|
networking.hostName = "vm-oddjob";
|
||||||
|
|
||||||
|
# Enabled modules
|
||||||
|
modules = {
|
||||||
|
profiles.vm.enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# Omada Software Controller
|
||||||
|
users.users.omada = {
|
||||||
|
isSystemUser = true;
|
||||||
|
group = "omada";
|
||||||
|
};
|
||||||
|
users.groups.omada = { };
|
||||||
|
virtualisation.podman = {
|
||||||
|
enable = true;
|
||||||
|
dockerCompat = true;
|
||||||
|
defaultNetwork.settings.dns_enabled = true;
|
||||||
|
};
|
||||||
|
virtualisation.oci-containers = {
|
||||||
|
backend = "podman";
|
||||||
|
containers = {
|
||||||
|
omada-controller = {
|
||||||
|
volumes = [
|
||||||
|
"/var/lib/omada:/opt/tplink/EAPController/data"
|
||||||
|
];
|
||||||
|
environment = {
|
||||||
|
TZ = "Europe/Amsterdam";
|
||||||
|
};
|
||||||
|
extraOptions = [
|
||||||
|
"--network=host"
|
||||||
|
"--ulimit"
|
||||||
|
"nofile=4096:8192"
|
||||||
|
];
|
||||||
|
image = "mbentley/omada-controller:5.15";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
modules.impermanence.directories = [
|
||||||
|
"/var/lib/omada"
|
||||||
|
];
|
||||||
|
networking.firewall = {
|
||||||
|
allowedTCPPorts = [
|
||||||
|
8088
|
||||||
|
8043
|
||||||
|
8843
|
||||||
|
];
|
||||||
|
allowedTCPPortRanges = [
|
||||||
|
{
|
||||||
|
from = 29811;
|
||||||
|
to = 29816;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
allowedUDPPorts = [
|
||||||
|
19810
|
||||||
|
27001
|
||||||
|
29810
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
# Setup NAS backups
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
keyutils
|
||||||
|
];
|
||||||
|
environment.etc."request-key.d/cifs.spnego.conf".text = ''
|
||||||
|
create cifs.spnego * * ${pkgs.cifs-utils}/bin/cifs.upcall -t %k
|
||||||
|
'';
|
||||||
|
environment.etc."request-key.d/cifs.idmap.conf".text = ''
|
||||||
|
create cifs.idmap * * ${pkgs.cifs-utils}/bin/cifs.idmap %k
|
||||||
|
'';
|
||||||
|
sops.secrets."smb-credentials" = {
|
||||||
|
sopsFile = "${inputs.secrets}/secrets/vm-oddjob.enc.yaml";
|
||||||
|
};
|
||||||
|
sops.secrets."backup-script-env" = {
|
||||||
|
sopsFile = "${inputs.secrets}/secrets/vm-oddjob.enc.yaml";
|
||||||
|
};
|
||||||
|
services.cron = {
|
||||||
|
enable = true;
|
||||||
|
systemCronJobs =
|
||||||
|
let
|
||||||
|
script = pkgs.writeShellScript "backup-script" (
|
||||||
|
lib.concatStrings (
|
||||||
|
[
|
||||||
|
''
|
||||||
|
. ${config.sops.secrets."backup-script-env".path}
|
||||||
|
export PBS_REPOSITORY=$PBS_REPOSITORY
|
||||||
|
export PBS_NAMESPACE=$PBS_NAMESPACE
|
||||||
|
export PBS_PASSWORD=$PBS_PASSWORD
|
||||||
|
export PBS_FINGERPRINT=$PBS_FINGERPRINT
|
||||||
|
''
|
||||||
|
]
|
||||||
|
++ lib.map (share: ''
|
||||||
|
systemctl start mnt-${share}.mount
|
||||||
|
${pkgs.util-linux}/bin/prlimit --nofile=1024:1024 ${pkgs.proxmox-backup-client}/bin/proxmox-backup-client backup nfs.pxar:/mnt/${share} --ns $PBS_NAMESPACE --backup-id share-${share} --change-detection-mode=metadata --exclude "#recycle"
|
||||||
|
systemctl stop mnt-${share}.mount
|
||||||
|
'') inputs.secrets.lab.nas.backupShares
|
||||||
|
)
|
||||||
|
);
|
||||||
|
in
|
||||||
|
[
|
||||||
|
"0 0 * * * root ${script}"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
# Mount filesystems
|
||||||
|
systemd.services.krb5-mnt-credentials = {
|
||||||
|
description = "Set up Kerberos credentials for mounting shares";
|
||||||
|
before = map (share: "mnt-${share}.mount") inputs.secrets.lab.nas.backupShares;
|
||||||
|
requiredBy = map (share: "mnt-${share}.mount") inputs.secrets.lab.nas.backupShares;
|
||||||
|
after = [ "network-online.target" ];
|
||||||
|
requires = [ "network-online.target" ];
|
||||||
|
serviceConfig.Type = "oneshot";
|
||||||
|
script = ''
|
||||||
|
. ${config.sops.secrets."smb-credentials".path}
|
||||||
|
echo $password | ${pkgs.krb5}/bin/kinit $username
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
fileSystems = lib.listToAttrs (
|
||||||
|
lib.map (share: {
|
||||||
|
name = "/mnt/${share}";
|
||||||
|
value = {
|
||||||
|
device = "//${inputs.secrets.lab.nas.host}/${share}";
|
||||||
|
fsType = "cifs";
|
||||||
|
options = [
|
||||||
|
"noauto"
|
||||||
|
"sec=krb5,credentials=${config.sops.secrets."smb-credentials".path}"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}) inputs.secrets.lab.nas.backupShares
|
||||||
|
);
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
pkgs,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
{
|
||||||
|
# State version
|
||||||
|
system.stateVersion = "24.11";
|
||||||
|
|
||||||
|
# Machine hostname
|
||||||
|
networking.hostName = "vm-test";
|
||||||
|
|
||||||
|
# Enabled modules
|
||||||
|
modules = {
|
||||||
|
profiles.vm.enable = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
{ ... }:
|
|
||||||
|
|
||||||
{
|
|
||||||
home.stateVersion = "24.11";
|
|
||||||
|
|
||||||
modules.profiles.base.enable = true;
|
|
||||||
}
|
|
||||||
@@ -15,7 +15,7 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
# TODO: Enable extensions with dconf
|
# TODO: Enable extensions (declaratively) with dconf
|
||||||
|
|
||||||
home.pointerCursor = {
|
home.pointerCursor = {
|
||||||
name = "capitaine-cursors";
|
name = "capitaine-cursors";
|
||||||
@@ -50,18 +50,30 @@ in
|
|||||||
file-roller
|
file-roller
|
||||||
mission-center
|
mission-center
|
||||||
dconf-editor
|
dconf-editor
|
||||||
|
gnome-calendar
|
||||||
|
|
||||||
# For theming gtk3
|
# For theming gtk3
|
||||||
adw-gtk3
|
adw-gtk3
|
||||||
|
|
||||||
|
# More icons
|
||||||
|
morewaita-icon-theme
|
||||||
]
|
]
|
||||||
++ (with pkgs.gnomeExtensions; [
|
++ (with pkgs.gnomeExtensions; [
|
||||||
gsconnect
|
gsconnect
|
||||||
disable-workspace-animation
|
disable-workspace-animation
|
||||||
wallpaper-slideshow
|
wallpaper-slideshow
|
||||||
media-progress
|
media-progress
|
||||||
# luminus-desktop
|
|
||||||
]);
|
]);
|
||||||
|
|
||||||
|
# Set up gnome terminal as changing the default terminal is a pain
|
||||||
|
programs.gnome-terminal = {
|
||||||
|
enable = true;
|
||||||
|
profile."12d2da79-b36c-43d5-8e1f-cf70907b84b3" = {
|
||||||
|
visibleName = "Default";
|
||||||
|
default = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
# Enable and set the gtk themes
|
# Enable and set the gtk themes
|
||||||
gtk = {
|
gtk = {
|
||||||
enable = true;
|
enable = true;
|
||||||
|
|||||||
@@ -0,0 +1,42 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
config,
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
with lib;
|
||||||
|
let
|
||||||
|
cfg = config.modules.go;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
options.modules.go = {
|
||||||
|
enable = mkEnableOption "go";
|
||||||
|
};
|
||||||
|
|
||||||
|
config = mkIf cfg.enable {
|
||||||
|
# Development packages
|
||||||
|
home.packages = with pkgs; [
|
||||||
|
];
|
||||||
|
|
||||||
|
# VSCode configuration
|
||||||
|
programs.vscode = {
|
||||||
|
profiles.default = {
|
||||||
|
extensions = with pkgs.vscode-extensions; [
|
||||||
|
golang.go
|
||||||
|
|
||||||
|
];
|
||||||
|
|
||||||
|
userSettings = {
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Neovim configuration
|
||||||
|
# programs.nixvim = {
|
||||||
|
# plugins.rustaceanvim = {
|
||||||
|
# enable = true;
|
||||||
|
# };
|
||||||
|
# };
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
{
|
||||||
|
lib,
|
||||||
|
config,
|
||||||
|
pkgs,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
with lib;
|
||||||
|
let
|
||||||
|
cfg = config.modules.bitwarden;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
options.modules.bitwarden = {
|
||||||
|
enable = mkEnableOption "Bitwarden";
|
||||||
|
};
|
||||||
|
|
||||||
|
config = mkIf cfg.enable {
|
||||||
|
home.packages = with pkgs; [
|
||||||
|
bitwarden-desktop
|
||||||
|
];
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
lib,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
with lib;
|
||||||
|
let
|
||||||
|
cfg = config.modules.secrets;
|
||||||
|
secrets = inputs.secrets;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
options.modules.secrets = {
|
||||||
|
enable = mkEnableOption "secrets";
|
||||||
|
defaultFile = mkOption {
|
||||||
|
type = types.str;
|
||||||
|
default = "${secrets}/secrets/common.enc.yaml";
|
||||||
|
description = ''
|
||||||
|
The default file to use for SOPS.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
secrets = mkOption {
|
||||||
|
type = types.attrs;
|
||||||
|
default = { };
|
||||||
|
description = ''
|
||||||
|
All secrets that should be made available.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
config = mkIf cfg.enable {
|
||||||
|
# Set up SOPS
|
||||||
|
# TODO: Fix the key not being present in .config/sops before sops-nix runs
|
||||||
|
sops.defaultSopsFile = cfg.defaultFile;
|
||||||
|
sops.age.sshKeyPaths = [
|
||||||
|
"${config.home.homeDirectory}/.config/sops/sops_ed25519_key"
|
||||||
|
# "/persist/home/${config.home.username}/.config/sops/sops_ed25519_key"
|
||||||
|
];
|
||||||
|
sops.secrets = cfg.secrets;
|
||||||
|
modules.impermanence.directories = [ ".config/sops" ];
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -16,5 +16,8 @@ in
|
|||||||
systemd-boot.editor = false;
|
systemd-boot.editor = false;
|
||||||
efi.canTouchEfiVariables = true;
|
efi.canTouchEfiVariables = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# Initrd
|
||||||
|
boot.initrd.systemd.enable = true;
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -20,5 +20,7 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
config = mkIf cfg.enable { disko.devices = profile.disko.devices; };
|
config = mkIf cfg.enable {
|
||||||
|
disko.devices = profile.disko.devices;
|
||||||
|
};
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,218 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
lib,
|
||||||
|
pkgs,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
with lib;
|
||||||
|
let
|
||||||
|
cfg = config.modules.domain;
|
||||||
|
domain = inputs.secrets.lab.domain;
|
||||||
|
domainUpper = lib.strings.toUpper domain;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
options.modules.domain = {
|
||||||
|
enable = mkEnableOption "Domain Integration";
|
||||||
|
join = {
|
||||||
|
userFile = mkOption {
|
||||||
|
type = types.str;
|
||||||
|
description = "File containing the user used to join the computer.";
|
||||||
|
};
|
||||||
|
passwordFile = mkOption {
|
||||||
|
type = types.str;
|
||||||
|
description = "File containing the password for the join user.";
|
||||||
|
};
|
||||||
|
domainOUFile = mkOption {
|
||||||
|
type = types.str;
|
||||||
|
description = "The OU to join the computer to.";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
config = mkIf cfg.enable {
|
||||||
|
# Set network domain
|
||||||
|
networking.domain = domain;
|
||||||
|
networking.search = [ domain ];
|
||||||
|
|
||||||
|
# Automatically join the domain
|
||||||
|
systemd.services.adcli-join = {
|
||||||
|
description = "Automatically join the domain";
|
||||||
|
wantedBy = [ "default.target" ];
|
||||||
|
before = [ "sssd.service" ];
|
||||||
|
requiredBy = [ "sssd.service" ];
|
||||||
|
after = [
|
||||||
|
"network-online.target"
|
||||||
|
];
|
||||||
|
requires = [
|
||||||
|
"network-online.target"
|
||||||
|
];
|
||||||
|
serviceConfig = {
|
||||||
|
Type = "oneshot";
|
||||||
|
};
|
||||||
|
script = ''
|
||||||
|
ADCLI_JOIN_USER=$(cat ${cfg.join.userFile})
|
||||||
|
ADCLI_JOIN_OU=$(cat ${cfg.join.domainOUFile})
|
||||||
|
${pkgs.adcli}/bin/adcli join -D ${domain} \
|
||||||
|
-U $ADCLI_JOIN_USER \
|
||||||
|
-O $ADCLI_JOIN_OU \
|
||||||
|
--dont-expire-password=true \
|
||||||
|
--stdin-password < ${cfg.join.passwordFile}
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
# Set up Kerberos
|
||||||
|
security.krb5 = {
|
||||||
|
enable = true;
|
||||||
|
settings = {
|
||||||
|
libdefaults = {
|
||||||
|
default_realm = domainUpper;
|
||||||
|
};
|
||||||
|
realms.${domainUpper} = {
|
||||||
|
};
|
||||||
|
domain_realm = {
|
||||||
|
"${domain}" = domainUpper;
|
||||||
|
".${domain}" = domainUpper;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Set up SSSD
|
||||||
|
services.sssd = {
|
||||||
|
enable = true;
|
||||||
|
config = ''
|
||||||
|
[sssd]
|
||||||
|
domains = ${domain}
|
||||||
|
config_file_version = 2
|
||||||
|
services = nss, pam
|
||||||
|
|
||||||
|
[nss]
|
||||||
|
filter_users = ${concatStringsSep "," (lib.attrNames config.users.users)}
|
||||||
|
filter_groups = ${concatStringsSep "," (lib.attrNames config.users.groups)}
|
||||||
|
|
||||||
|
[domain/${domain}]
|
||||||
|
enumerate = False
|
||||||
|
ad_domain = ${domain}
|
||||||
|
krb5_realm = ${domainUpper}H
|
||||||
|
id_provider = ad
|
||||||
|
auth_provider = ad
|
||||||
|
access_provider = ad
|
||||||
|
chpass_provider = ad
|
||||||
|
use_fully_qualified_names = False
|
||||||
|
ldap_schema = ad
|
||||||
|
ldap_id_mapping = True
|
||||||
|
ad_gpo_access_control = enforcing
|
||||||
|
ad_gpo_implicit_deny = True
|
||||||
|
dyndns_update = True
|
||||||
|
dyndns_update_ptr = False
|
||||||
|
dyndns_refresh_interval = 86400
|
||||||
|
dyndns_ttl = 3600
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
security.pam.services.login.sssdStrictAccess = true;
|
||||||
|
security.pam.services.sshd.sssdStrictAccess = true;
|
||||||
|
security.pam.services.su.sssdStrictAccess = true;
|
||||||
|
|
||||||
|
# Set up Sudo
|
||||||
|
security.sudo =
|
||||||
|
let
|
||||||
|
admin_group = "host_${lib.replaceStrings [ "-" ] [ "_" ] config.networking.hostName}_admin";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
extraConfig = ''
|
||||||
|
%${admin_group} ALL=(ALL) SETENV: ALL
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
# Set up SSH
|
||||||
|
programs.ssh = {
|
||||||
|
package = pkgs.openssh_gssapi;
|
||||||
|
extraConfig = ''
|
||||||
|
GSSAPIAuthentication yes
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
services.openssh = {
|
||||||
|
package = pkgs.openssh_gssapi;
|
||||||
|
settings = {
|
||||||
|
GSSAPIAuthentication = true;
|
||||||
|
GSSAPICleanupCredentials = true;
|
||||||
|
GSSAPIStrictAcceptorCheck = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
# Set up home directory
|
||||||
|
security.pam.services.login.makeHomeDir = true;
|
||||||
|
security.pam.services.sshd.makeHomeDir = true;
|
||||||
|
security.pam.services.su.makeHomeDir = true;
|
||||||
|
environment.etc.profile.text =
|
||||||
|
let
|
||||||
|
# TODO: Activate configuration based on AD group
|
||||||
|
homeConfiguration = inputs.home-manager.lib.homeManagerConfiguration {
|
||||||
|
inherit pkgs;
|
||||||
|
modules = [
|
||||||
|
(
|
||||||
|
{ lib, ... }:
|
||||||
|
{
|
||||||
|
home.stateVersion = "24.11";
|
||||||
|
home.username = "$USER";
|
||||||
|
home.homeDirectory = "/.$HOME";
|
||||||
|
modules.profiles.base.enable = true;
|
||||||
|
|
||||||
|
# Mount the directories from the network share
|
||||||
|
# home.activation.dirMount =
|
||||||
|
# let
|
||||||
|
# bindScript = dir: ''
|
||||||
|
# mkdir -p /network/$USER/${dir}
|
||||||
|
# mkdir -p $HOME/${dir}
|
||||||
|
# ${pkgs.bindfs}/bin/bindfs /network/$USER/${dir} $HOME/${dir}
|
||||||
|
# '';
|
||||||
|
# in
|
||||||
|
# lib.hm.dag.entryAfter [ "writeBoundary" ] ''
|
||||||
|
# if ! ${pkgs.krb5}/bin/klist -s; then
|
||||||
|
# echo "No kerberos ticket found"
|
||||||
|
# ${pkgs.krb5}/bin/kinit
|
||||||
|
# fi
|
||||||
|
|
||||||
|
# if ${pkgs.krb5}/bin/klist -s; then
|
||||||
|
# echo "Kerberos ticket found, mounting home directory"
|
||||||
|
# ${bindScript "Documents"}
|
||||||
|
# ${bindScript "Music"}
|
||||||
|
# ${bindScript "Pictures"}
|
||||||
|
# ${bindScript "Video"}
|
||||||
|
# else
|
||||||
|
# echo "Still no kerberos ticket found, skipping home directory mount"
|
||||||
|
# fi
|
||||||
|
# '';
|
||||||
|
}
|
||||||
|
)
|
||||||
|
] ++ config.home-manager.sharedModules;
|
||||||
|
};
|
||||||
|
in
|
||||||
|
mkAfter ''
|
||||||
|
# Activate Home Manager configuration for domain users
|
||||||
|
if id | egrep -o 'groups=.*' | sed 's/,/\n/g' | cut -d'(' -f2 | sed 's/)//' | egrep -o "^domain users$"; then
|
||||||
|
echo "Setting up environment for domain user"
|
||||||
|
SKIP_SANITY_CHECKS=1 ${homeConfiguration.activationPackage}/activate
|
||||||
|
if test -f "$HOME/.bashrc"; then
|
||||||
|
. $HOME/.bashrc
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
'';
|
||||||
|
|
||||||
|
# Automatically mount home share
|
||||||
|
# Can be accessed at /network/$USER
|
||||||
|
# services.autofs = {
|
||||||
|
# enable = true;
|
||||||
|
# autoMaster =
|
||||||
|
# let
|
||||||
|
# networkMap = pkgs.writeText "auto" ''
|
||||||
|
# * -fstype=cifs,sec=krb5,user=&,uid=$UID,gid=$GID,cruid=$UID ://${inputs.secrets.lab.nas.host}/home
|
||||||
|
# '';
|
||||||
|
# in
|
||||||
|
# ''
|
||||||
|
# /network ${networkMap} --timeout=30
|
||||||
|
# '';
|
||||||
|
# };
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -17,10 +17,9 @@ in
|
|||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
# Enable GDM and Gnome
|
# Enable GDM and Gnome
|
||||||
services.xserver.enable = true;
|
services.displayManager.gdm.enable = true;
|
||||||
services.xserver.displayManager.gdm.enable = true;
|
services.desktopManager.gnome.enable = true;
|
||||||
services.xserver.desktopManager.gnome.enable = true;
|
services.gnome.core-apps.enable = false;
|
||||||
services.gnome.core-utilities.enable = false;
|
|
||||||
services.gnome.games.enable = false;
|
services.gnome.games.enable = false;
|
||||||
services.gnome.core-developer-tools.enable = false;
|
services.gnome.core-developer-tools.enable = false;
|
||||||
environment.gnome.excludePackages = with pkgs; [
|
environment.gnome.excludePackages = with pkgs; [
|
||||||
@@ -29,7 +28,6 @@ in
|
|||||||
gnome-backgrounds
|
gnome-backgrounds
|
||||||
gnome-bluetooth
|
gnome-bluetooth
|
||||||
gnome-color-manager
|
gnome-color-manager
|
||||||
gnome-control-center
|
|
||||||
gnome-shell-extensions
|
gnome-shell-extensions
|
||||||
gnome-tour
|
gnome-tour
|
||||||
gnome-user-docs
|
gnome-user-docs
|
||||||
|
|||||||
@@ -24,18 +24,32 @@ in
|
|||||||
resetScript = mkOption {
|
resetScript = mkOption {
|
||||||
type = types.lines;
|
type = types.lines;
|
||||||
description = ''
|
description = ''
|
||||||
Script to run on boot that resets the root partition.
|
Script to run in order to reset the system to a clean state.
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
|
# Filesystem setup
|
||||||
fileSystems."/persist".neededForBoot = true;
|
fileSystems."/persist".neededForBoot = true;
|
||||||
boot.initrd.postResumeCommands = mkAfter cfg.resetScript;
|
# boot.initrd.postResumeCommands = mkAfter cfg.resetScript;
|
||||||
|
# TODO: Reduce dependency on the root filesystem being ZFS?
|
||||||
|
boot.initrd.systemd.services.impermanence-rollback = {
|
||||||
|
description = "Rollback filesystem to clean state.";
|
||||||
|
wantedBy = [ "initrd.target" ];
|
||||||
|
after = [ "zfs-import.target" ];
|
||||||
|
before = [ "sysroot.mount" ];
|
||||||
|
unitConfig.DefaultDependencies = "no";
|
||||||
|
serviceConfig.Type = "oneshot";
|
||||||
|
script = cfg.resetScript;
|
||||||
|
};
|
||||||
|
|
||||||
# For home-manager persistence
|
# For home-manager persistence
|
||||||
programs.fuse.userAllowOther = true;
|
programs.fuse.userAllowOther = true;
|
||||||
|
|
||||||
|
# For testing purposes with VM
|
||||||
|
virtualisation.vmVariantWithDisko.virtualisation.fileSystems."/persist".neededForBoot = true;
|
||||||
|
|
||||||
environment.persistence."/persist/system" = {
|
environment.persistence."/persist/system" = {
|
||||||
enable = true;
|
enable = true;
|
||||||
hideMounts = true;
|
hideMounts = true;
|
||||||
|
|||||||
@@ -11,5 +11,7 @@ in
|
|||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
# TODO: Add sudo users to the networkmanager group?
|
# TODO: Add sudo users to the networkmanager group?
|
||||||
networking.networkmanager.enable = true;
|
networking.networkmanager.enable = true;
|
||||||
|
|
||||||
|
networking.firewall.checkReversePath = false;
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
{
|
||||||
|
inputs,
|
||||||
|
lib,
|
||||||
|
config,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
|
||||||
|
with lib;
|
||||||
|
let
|
||||||
|
cfg = config.modules.secrets;
|
||||||
|
secrets = inputs.secrets;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
options.modules.secrets = {
|
||||||
|
enable = mkEnableOption "secrets";
|
||||||
|
defaultFile = mkOption {
|
||||||
|
type = types.str;
|
||||||
|
default = "${secrets}/secrets/common.enc.yaml";
|
||||||
|
description = ''
|
||||||
|
The default file to use for SOPS.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
secrets = mkOption {
|
||||||
|
type = types.attrs;
|
||||||
|
default = { };
|
||||||
|
description = ''
|
||||||
|
All secrets that should be made available.
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
config = mkIf cfg.enable {
|
||||||
|
# Set up SOPS
|
||||||
|
# TODO: Fix the key not being present in /etc/sops before sops-nix runs
|
||||||
|
sops.defaultSopsFile = cfg.defaultFile;
|
||||||
|
sops.age.sshKeyPaths = [
|
||||||
|
"/etc/sops/sops_ed25519_key"
|
||||||
|
"/persist/system/etc/sops/sops_ed25519_key"
|
||||||
|
];
|
||||||
|
sops.secrets = cfg.secrets;
|
||||||
|
modules.impermanence.directories = [ "/etc/sops" ];
|
||||||
|
virtualisation.vmVariantWithDisko.sops.age.sshKeyPaths = [ "/tmp/shared/sops_ed25519_key" ];
|
||||||
|
};
|
||||||
|
}
|
||||||
+19
-2
@@ -9,7 +9,24 @@ in
|
|||||||
enable = mkEnableOption "ssh";
|
enable = mkEnableOption "ssh";
|
||||||
};
|
};
|
||||||
config = mkIf cfg.enable {
|
config = mkIf cfg.enable {
|
||||||
services.openssh.enable = true;
|
services.openssh = {
|
||||||
# TODO: Is this default configuration secure?
|
enable = true;
|
||||||
|
settings = {
|
||||||
|
PasswordAuthentication = false;
|
||||||
|
KbdInteractiveAuthentication = false;
|
||||||
|
PermitRootLogin = "no";
|
||||||
|
};
|
||||||
|
hostKeys = mkIf (config.modules.impermanence.enable) [
|
||||||
|
{
|
||||||
|
type = "ed25519";
|
||||||
|
path = "/persist/system/etc/ssh/ssh_host_ed25519_key";
|
||||||
|
}
|
||||||
|
{
|
||||||
|
type = "rsa";
|
||||||
|
bits = 4096;
|
||||||
|
path = "/persist/system/etc/ssh/ssh_host_rsa_key";
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
{ pkgs, ... }:
|
||||||
|
|
||||||
|
with pkgs;
|
||||||
|
rustPlatform.buildRustPackage {
|
||||||
|
pname = "carla_osc_bridge";
|
||||||
|
version = "master";
|
||||||
|
|
||||||
|
src = fetchFromGitea {
|
||||||
|
domain = "git.bulthuis.dev";
|
||||||
|
owner = "Jan";
|
||||||
|
repo = "carla_osc_bridge";
|
||||||
|
rev = "c037e2d2a1b29b785d8acc10fa0cb761afdb3fcf";
|
||||||
|
hash = "sha256-Wvdfm+4dfygZwkvaUhO9w7DrrUl3ZYvtD7nYrPSD0eA=";
|
||||||
|
};
|
||||||
|
|
||||||
|
cargoHash = "sha256-s1ZKbhHudgPOy7613zbT8TkbM6B7oloLEuTYHoWjX5o=";
|
||||||
|
|
||||||
|
useFetchCargoVendor = true;
|
||||||
|
}
|
||||||
+10
-1
@@ -3,6 +3,8 @@
|
|||||||
disk = {
|
disk = {
|
||||||
main = {
|
main = {
|
||||||
type = "disk";
|
type = "disk";
|
||||||
|
device = "/dev/sda";
|
||||||
|
imageSize = "32G"; # For test VMs
|
||||||
content = {
|
content = {
|
||||||
type = "gpt";
|
type = "gpt";
|
||||||
partitions = {
|
partitions = {
|
||||||
@@ -17,12 +19,19 @@
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
zfs = {
|
zfs = {
|
||||||
size = "100%";
|
end = "-4G";
|
||||||
content = {
|
content = {
|
||||||
type = "zfs";
|
type = "zfs";
|
||||||
pool = "tank";
|
pool = "tank";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
swap = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "swap";
|
||||||
|
discardPolicy = "both";
|
||||||
|
};
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,65 @@
|
|||||||
|
{
|
||||||
|
disko.devices = {
|
||||||
|
disk = {
|
||||||
|
main = {
|
||||||
|
type = "disk";
|
||||||
|
device = "/dev/sda"; # How do I handle this for laptops
|
||||||
|
imageSize = "64G"; # For test VMs
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
boot = {
|
||||||
|
size = "512M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
zfs = {
|
||||||
|
end = "-16G";
|
||||||
|
content = {
|
||||||
|
type = "zfs";
|
||||||
|
pool = "tank";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
swap = {
|
||||||
|
size = "100%";
|
||||||
|
content = {
|
||||||
|
type = "swap";
|
||||||
|
discardPolicy = "both";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
zpool = {
|
||||||
|
tank = {
|
||||||
|
type = "zpool";
|
||||||
|
rootFsOptions = {
|
||||||
|
compression = "zstd";
|
||||||
|
};
|
||||||
|
mountpoint = null;
|
||||||
|
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
|
||||||
|
|
||||||
|
datasets = {
|
||||||
|
root = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/";
|
||||||
|
};
|
||||||
|
nix = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/nix";
|
||||||
|
};
|
||||||
|
persist = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/persist";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -24,14 +24,13 @@ in
|
|||||||
freecad-wayland
|
freecad-wayland
|
||||||
inkscape
|
inkscape
|
||||||
ente-auth
|
ente-auth
|
||||||
bitwarden
|
|
||||||
carla
|
carla
|
||||||
winbox
|
winbox
|
||||||
whatsapp-for-linux
|
whatsapp-for-linux
|
||||||
discord
|
discord
|
||||||
steam
|
steam
|
||||||
spotify
|
spotify
|
||||||
# feishin # TODO: Fix or replace as insecure
|
feishin
|
||||||
eduvpn-client
|
eduvpn-client
|
||||||
river # TODO: Move
|
river # TODO: Move
|
||||||
ryubing
|
ryubing
|
||||||
@@ -39,6 +38,10 @@ in
|
|||||||
prismlauncher
|
prismlauncher
|
||||||
foliate
|
foliate
|
||||||
wireshark
|
wireshark
|
||||||
|
obsidian
|
||||||
|
devenv
|
||||||
|
kicad
|
||||||
|
vlc
|
||||||
];
|
];
|
||||||
|
|
||||||
modules = {
|
modules = {
|
||||||
@@ -61,6 +64,7 @@ in
|
|||||||
"flake.lock"
|
"flake.lock"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
bitwarden.enable = true;
|
||||||
xpra = {
|
xpra = {
|
||||||
enable = true;
|
enable = true;
|
||||||
hosts = [
|
hosts = [
|
||||||
@@ -82,6 +86,7 @@ in
|
|||||||
cpp.enable = true;
|
cpp.enable = true;
|
||||||
tex.enable = true;
|
tex.enable = true;
|
||||||
jupyter.enable = false;
|
jupyter.enable = false;
|
||||||
|
go.enable = true;
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
+10
-5
@@ -1,5 +1,4 @@
|
|||||||
{
|
{
|
||||||
mkModule,
|
|
||||||
pkgs,
|
pkgs,
|
||||||
lib,
|
lib,
|
||||||
config,
|
config,
|
||||||
@@ -20,13 +19,19 @@ in
|
|||||||
bootloader.enable = mkDefault true;
|
bootloader.enable = mkDefault true;
|
||||||
ssh.enable = mkDefault true;
|
ssh.enable = mkDefault true;
|
||||||
|
|
||||||
# Setup sensible default persistent data
|
|
||||||
impermanence.directories = [
|
impermanence.directories = [
|
||||||
"/var/lib/nixos"
|
"/var/lib/nixos"
|
||||||
];
|
];
|
||||||
impermanence.files = [
|
|
||||||
"/etc/shadow"
|
# TODO: Remove the secrets module and use sops directly?
|
||||||
];
|
secrets = {
|
||||||
|
enable = true;
|
||||||
|
secrets = {
|
||||||
|
"ssh-keys/deploy-priv" = {
|
||||||
|
path = "/root/.ssh/id_ed25519";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
# Localization
|
# Localization
|
||||||
|
|||||||
+48
-16
@@ -1,5 +1,4 @@
|
|||||||
{
|
{
|
||||||
mkModule,
|
|
||||||
pkgs,
|
pkgs,
|
||||||
lib,
|
lib,
|
||||||
config,
|
config,
|
||||||
@@ -30,17 +29,50 @@ in
|
|||||||
zfs rollback -r tank/root@blank
|
zfs rollback -r tank/root@blank
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
domain = {
|
||||||
|
enable = true;
|
||||||
|
join = {
|
||||||
|
userFile = config.sops.secrets."vm-join/user".path;
|
||||||
|
passwordFile = config.sops.secrets."vm-join/password".path;
|
||||||
|
domainOUFile = config.sops.secrets."vm-join/ou".path;
|
||||||
|
};
|
||||||
|
};
|
||||||
ssh.enable = true;
|
ssh.enable = true;
|
||||||
};
|
};
|
||||||
|
|
||||||
# Admin users
|
# Initialize domain join secrets
|
||||||
|
sops.secrets."vm-join/user" = { };
|
||||||
|
sops.secrets."vm-join/password" = { };
|
||||||
|
sops.secrets."vm-join/ou" = { };
|
||||||
|
|
||||||
|
# Autologin to root for access from hypervisor
|
||||||
|
services.getty.autologinUser = "root";
|
||||||
|
|
||||||
|
# Local user
|
||||||
|
sops.secrets."passwords/local-hashed".neededForUsers = true;
|
||||||
|
users.mutableUsers = false;
|
||||||
users.users.local = {
|
users.users.local = {
|
||||||
initialPassword = "local";
|
isNormalUser = true;
|
||||||
|
group = "local";
|
||||||
|
hashedPasswordFile = config.sops.secrets."passwords/local-hashed".path;
|
||||||
extraGroups = [ "wheel" ];
|
extraGroups = [ "wheel" ];
|
||||||
openssh.authorizedKeys.keys = [
|
openssh.authorizedKeys.keys = [
|
||||||
"ssh-ed25519 jan@bulthuis.dev"
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq Admin"
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
users.groups.local = { };
|
||||||
|
home-manager.users.local =
|
||||||
|
{ ... }:
|
||||||
|
{
|
||||||
|
home.stateVersion = "24.11";
|
||||||
|
modules.profiles.base.enable = true;
|
||||||
|
};
|
||||||
|
|
||||||
|
# System packages
|
||||||
|
environment.systemPackages = with pkgs; [
|
||||||
|
# TODO: Make module for utilities/scripts
|
||||||
|
(writeShellScriptBin "system-update" "nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/nixos-config")
|
||||||
|
];
|
||||||
|
|
||||||
# Enable qemu guest agent
|
# Enable qemu guest agent
|
||||||
services.qemuGuest.enable = true;
|
services.qemuGuest.enable = true;
|
||||||
@@ -48,7 +80,7 @@ in
|
|||||||
# Machine platform
|
# Machine platform
|
||||||
nixpkgs.hostPlatform = "x86_64-linux";
|
nixpkgs.hostPlatform = "x86_64-linux";
|
||||||
|
|
||||||
# Set hostid for ZFS
|
# Set hostid (required for ZFS)
|
||||||
networking.hostId = "deadbeef";
|
networking.hostId = "deadbeef";
|
||||||
|
|
||||||
# Hardware configuration
|
# Hardware configuration
|
||||||
@@ -56,22 +88,22 @@ in
|
|||||||
boot.initrd.availableKernelModules = [
|
boot.initrd.availableKernelModules = [
|
||||||
"ata_piix"
|
"ata_piix"
|
||||||
"uhci_hcd"
|
"uhci_hcd"
|
||||||
|
"virtio_net"
|
||||||
"virtio_pci"
|
"virtio_pci"
|
||||||
|
"virtio_mmio"
|
||||||
|
"virtio_blk"
|
||||||
"virtio_scsi"
|
"virtio_scsi"
|
||||||
|
"9p"
|
||||||
|
"9pnet_virtio"
|
||||||
"sd_mod"
|
"sd_mod"
|
||||||
"sr_mod"
|
"sr_mod"
|
||||||
];
|
];
|
||||||
boot.initrd.kernelModules = [ ];
|
boot.kernelModules = [
|
||||||
boot.kernelModules = [ "kvm-intel" ];
|
"kvm-intel"
|
||||||
boot.extraModulePackages = [ ];
|
"virtio_balloon"
|
||||||
hardware.cpu.intel.updateMicrocode = true;
|
"virtio_console"
|
||||||
|
"virtio_rng"
|
||||||
# Swapfile
|
"virtio_gpu"
|
||||||
swapDevices = [
|
|
||||||
{
|
|
||||||
device = "/var/lib/swapfile";
|
|
||||||
size = 6 * 1024;
|
|
||||||
}
|
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
Reference in new issue
Block a user