Compare commits
90
Commits
disko
...
3603fe28a7
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3603fe28a7 | ||
|
|
ce7c940f65 | ||
|
|
d8327c3edf | ||
|
|
af9f7e0ee0 | ||
|
|
3285b483e2 | ||
|
|
affa333969 | ||
|
|
3c20190709 | ||
|
|
0305b8d33a | ||
|
|
5ade637e57 | ||
|
|
029ff0c9a3 | ||
|
|
db4bd8cfd9 | ||
|
|
41d25d9695 | ||
|
|
7e2e012f3a | ||
|
|
071e904990 | ||
|
|
b68ca558d8 | ||
|
|
cf760b8b85 | ||
|
|
7d4ee43283 | ||
|
|
4e08366901 | ||
|
|
a0ca155f7c | ||
|
|
110aa4215f | ||
|
|
08a161ff0d | ||
|
|
f4472de631 | ||
|
|
3c154de819 | ||
|
|
709040c072 | ||
|
|
28193823c8 | ||
|
|
dd25c9323d | ||
|
|
5796bee499 | ||
|
|
986afe4b32 | ||
|
|
537e30a347 | ||
|
|
2fec5ead38 | ||
|
|
d4e6283c2f | ||
|
|
32e7d99292 | ||
|
|
d9dab5b9d3 | ||
|
|
cdd94eefb3 | ||
|
|
209dbea02a | ||
|
|
c683809a78 | ||
|
|
739e335c28 | ||
|
|
3c6758b343 | ||
|
|
799b91a509 | ||
|
|
50ff958d35 | ||
|
|
ecc2779ce9 | ||
|
|
10dab81fb5 | ||
|
|
03e96662cc | ||
|
|
d6d54e213e | ||
|
|
f491be0ace | ||
|
|
fef1eff181 | ||
|
|
e869e5d790 | ||
|
|
48caacd9e5 | ||
|
|
ce4401033a | ||
|
|
8b331ad3ae | ||
|
|
417383f89b | ||
|
|
cc75c95ad4 | ||
|
|
a321251b93 | ||
|
|
54677248af | ||
|
|
d8f18016cd | ||
|
|
6522ebc15e | ||
|
|
10216784e8 | ||
|
|
f3abb6d2f3 | ||
|
|
936d654877 | ||
|
|
61d207db04 | ||
|
|
e7b66cb40c | ||
|
|
c9b18219af | ||
|
|
d5c4a78fba | ||
|
|
369d655a38 | ||
|
|
eab130b99d | ||
|
|
5ce6b9bdf2 | ||
|
|
5db52a4f84 | ||
|
|
3524f6b038 | ||
|
|
0cf53a97cf | ||
|
|
46fe5b8056 | ||
|
|
ec3d9e6049 | ||
|
|
fc0476ca5a | ||
|
|
4b7c62d00b | ||
|
|
cfc276184f | ||
|
|
87b50bfb4d | ||
|
|
1bc34518e1 | ||
|
|
f1dcb8c72b | ||
|
|
ec002467fa | ||
|
|
5a228cb375 | ||
|
|
d53e395d42 | ||
|
|
cb39f82a48 | ||
|
|
0efee5bceb | ||
|
|
844118055c | ||
|
|
0ba9de0030 | ||
|
|
a745b35c84 | ||
|
|
6c74dcbc22 | ||
|
|
76e609372f | ||
|
|
cd91944b1e | ||
|
|
bebd2748d1 | ||
|
|
12a4ba0482 |
No files matched your search
@@ -4,8 +4,39 @@ My NixOS configuration.
|
||||
|
||||
## Installation
|
||||
|
||||
For disk configuration we use disko, this means that installing the system from the configuration is just a single command:
|
||||
For disk configuration we use disko, but for secrets management we use sops-nix and the particular setup makes the installation process a bit more involved. It is required that the computer from which the installation is being run has access to the `nixos-secrets` repository, otherwise you will need to manually add the required ssh keys to the installation image.
|
||||
```bash
|
||||
# Load into the installer
|
||||
sudo passwd # Set a root password
|
||||
|
||||
# From a machine with network access to the installer
|
||||
# and access to the nixos-secrets repo
|
||||
ssh -A root@(installer-ip)
|
||||
|
||||
# Set up disks
|
||||
nix-shell -p disko
|
||||
disko --mode disko --flake git+https://git.bulthuis.dev/Jan/nixos-config#(system)
|
||||
exit
|
||||
|
||||
# Install NixOS
|
||||
nixos-install --no-channel-copy --no-root-password --flake git+https://git.bulthuis.dev/Jan/nixos-config#(system)
|
||||
|
||||
# Set up host credentials for access to the secrets
|
||||
cd /mnt/persist/system/etc/sops
|
||||
touch sops_ed25519_key
|
||||
chmod 600 sops_ed25519_key
|
||||
nano sops_ed25519_key
|
||||
```
|
||||
sudo nix --experimental-features "nix-command flakes" run "github:nix-community/disko/latest#disko-install" -- --flake git+https://git.bulthuis.dev/Jan/dotfiles#<hostname> --disk main /dev/sda
|
||||
If `nixos-install` is being stopped by the OOM-killer, you can try adding `-j 1` to limit the amount of jobs that will be executed at the same time to 1. It might require running nixos-install multiple times untill it has managed to download all requirements and slowly start building the rest of the system.
|
||||
|
||||
## Updating
|
||||
|
||||
To update the system configuration, it is a single command:
|
||||
```bash
|
||||
sudo system-update
|
||||
```
|
||||
Or if this shell script has not been installed for some reason:
|
||||
```bash
|
||||
sudo nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/nixos-config
|
||||
```
|
||||
Sometimes it may be necessary to reboot of course.
|
||||
Generated
+38
-1
@@ -154,7 +154,44 @@
|
||||
"impermanence": "impermanence",
|
||||
"nix-minecraft": "nix-minecraft",
|
||||
"nix-modpack": "nix-modpack",
|
||||
"nixpkgs": "nixpkgs"
|
||||
"nixpkgs": "nixpkgs",
|
||||
"secrets": "secrets",
|
||||
"sops-nix": "sops-nix"
|
||||
}
|
||||
},
|
||||
"secrets": {
|
||||
"locked": {
|
||||
"lastModified": 1749476519,
|
||||
"narHash": "sha256-yzSsn2e+n4TQisd1PB7vZLcz9rhd8n5V4uoniWt+CP8=",
|
||||
"ref": "refs/heads/main",
|
||||
"rev": "890c1295ca6fea2a3aad5b7075dd5902f92beef0",
|
||||
"revCount": 13,
|
||||
"type": "git",
|
||||
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
|
||||
},
|
||||
"original": {
|
||||
"type": "git",
|
||||
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
|
||||
}
|
||||
},
|
||||
"sops-nix": {
|
||||
"inputs": {
|
||||
"nixpkgs": [
|
||||
"nixpkgs"
|
||||
]
|
||||
},
|
||||
"locked": {
|
||||
"lastModified": 1747603214,
|
||||
"narHash": "sha256-lAblXm0VwifYCJ/ILPXJwlz0qNY07DDYdLD+9H+Wc8o=",
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"rev": "8d215e1c981be3aa37e47aeabd4e61bb069548fd",
|
||||
"type": "github"
|
||||
},
|
||||
"original": {
|
||||
"owner": "Mic92",
|
||||
"repo": "sops-nix",
|
||||
"type": "github"
|
||||
}
|
||||
},
|
||||
"systems": {
|
||||
|
||||
@@ -6,6 +6,13 @@
|
||||
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
|
||||
home-manager.url = "github:nix-community/home-manager";
|
||||
home-manager.inputs.nixpkgs.follows = "nixpkgs";
|
||||
|
||||
# Secrets
|
||||
sops-nix.url = "github:Mic92/sops-nix";
|
||||
sops-nix.inputs.nixpkgs.follows = "nixpkgs";
|
||||
secrets.url = "git+ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets";
|
||||
|
||||
# Disk setup
|
||||
disko.url = "github:nix-community/disko";
|
||||
disko.inputs.nixpkgs.follows = "nixpkgs";
|
||||
impermanence.url = "github:nix-community/impermanence";
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
{ flake, ... }:
|
||||
{ inputs, ... }:
|
||||
|
||||
{
|
||||
# State version
|
||||
@@ -13,6 +13,17 @@
|
||||
"wireshark"
|
||||
];
|
||||
|
||||
# Set up kerberos
|
||||
security.krb5 = {
|
||||
enable = true;
|
||||
settings = {
|
||||
libdefaults = {
|
||||
rdns = false;
|
||||
};
|
||||
realms = (inputs.secrets.gewis.krb5Realm);
|
||||
};
|
||||
};
|
||||
|
||||
# Enable virtualisation for VMs
|
||||
virtualisation.libvirtd.enable = true;
|
||||
|
||||
|
||||
@@ -1,7 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
home.stateVersion = "24.11";
|
||||
|
||||
modules.profiles.base.enable = true;
|
||||
}
|
||||
@@ -1,7 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
home.stateVersion = "24.11";
|
||||
|
||||
modules.profiles.base.enable = true;
|
||||
}
|
||||
@@ -0,0 +1,71 @@
|
||||
{
|
||||
inputs,
|
||||
lib,
|
||||
pkgs,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
|
||||
{
|
||||
# State version
|
||||
system.stateVersion = "24.11";
|
||||
|
||||
# Machine hostname
|
||||
networking.hostName = "vm-oddjob";
|
||||
|
||||
# Enabled modules
|
||||
modules = {
|
||||
profiles.vm.enable = true;
|
||||
};
|
||||
|
||||
# Setup NAS backups
|
||||
environment.systemPackages = with pkgs; [
|
||||
keyutils
|
||||
];
|
||||
environment.etc."request-key.d/cifs.spnego.conf".text = ''
|
||||
create cifs.spnego * * ${pkgs.cifs-utils}/bin/cifs.upcall -t %k
|
||||
'';
|
||||
environment.etc."request-key.d/cifs.idmap.conf".text = ''
|
||||
create cifs.idmap * * ${pkgs.cifs-utils}/bin/cifs.idmap %k
|
||||
'';
|
||||
sops.secrets."smb-credentials" = {
|
||||
sopsFile = "${inputs.secrets}/secrets/vm-oddjob.enc.yaml";
|
||||
};
|
||||
sops.secrets."backup-script-env" = {
|
||||
sopsFile = "${inputs.secrets}/secrets/vm-oddjob.enc.yaml";
|
||||
};
|
||||
systemd.services.mnt-nas-krb5 = {
|
||||
description = "Set up Kerberos credentials for mnt-nas";
|
||||
before = [ "mnt-nas.mount" ];
|
||||
requiredBy = [ "mnt-nas.mount" ];
|
||||
after = [ "network-online.target" ];
|
||||
requires = [ "network-online.target" ];
|
||||
serviceConfig.Type = "oneshot";
|
||||
script = ''
|
||||
. ${config.sops.secrets."smb-credentials".path}
|
||||
echo $password | ${pkgs.krb5}/bin/kinit $username
|
||||
'';
|
||||
};
|
||||
services.cron = {
|
||||
enable = true;
|
||||
systemCronJobs =
|
||||
let
|
||||
script = pkgs.writeShellScript "backup-script" ''
|
||||
. ${config.sops.secrets."backup-script-env".path}
|
||||
export PBS_REPOSITORY=$PBS_REPOSITORY
|
||||
export PBS_NAMESPACE=$PBS_NAMESPACE
|
||||
export PBS_PASSWORD=$PBS_PASSWORD
|
||||
export PBS_FINGERPRINT=$PBS_FINGERPRINT
|
||||
${pkgs.proxmox-backup-client}/bin/proxmox-backup-client backup nfs.pxar:/mnt/nas --ns $PBS_NAMESPACE --backup-id nas-backup --change-detection-mode=metadata --exclude "#recycle"
|
||||
'';
|
||||
in
|
||||
[
|
||||
"0 0 * * * ${script} "
|
||||
];
|
||||
};
|
||||
fileSystems."/mnt/nas" = {
|
||||
device = "//${inputs.secrets.lab.nas.host}/Backup";
|
||||
fsType = "cifs";
|
||||
options = [ "sec=krb5,credentials=${config.sops.secrets."smb-credentials".path}" ];
|
||||
};
|
||||
}
|
||||
@@ -1,7 +0,0 @@
|
||||
{ ... }:
|
||||
|
||||
{
|
||||
home.stateVersion = "24.11";
|
||||
|
||||
modules.profiles.base.enable = true;
|
||||
}
|
||||
@@ -0,0 +1,22 @@
|
||||
{
|
||||
lib,
|
||||
config,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
|
||||
with lib;
|
||||
let
|
||||
cfg = config.modules.bitwarden;
|
||||
in
|
||||
{
|
||||
options.modules.bitwarden = {
|
||||
enable = mkEnableOption "Bitwarden";
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
home.packages = with pkgs; [
|
||||
bitwarden-desktop
|
||||
];
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,43 @@
|
||||
{
|
||||
inputs,
|
||||
lib,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
|
||||
with lib;
|
||||
let
|
||||
cfg = config.modules.secrets;
|
||||
secrets = inputs.secrets;
|
||||
in
|
||||
{
|
||||
options.modules.secrets = {
|
||||
enable = mkEnableOption "secrets";
|
||||
defaultFile = mkOption {
|
||||
type = types.str;
|
||||
default = "${secrets}/secrets/common.enc.yaml";
|
||||
description = ''
|
||||
The default file to use for SOPS.
|
||||
'';
|
||||
};
|
||||
secrets = mkOption {
|
||||
type = types.attrs;
|
||||
default = { };
|
||||
description = ''
|
||||
All secrets that should be made available.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
# Set up SOPS
|
||||
# TODO: Fix the key not being present in .config/sops before sops-nix runs
|
||||
sops.defaultSopsFile = cfg.defaultFile;
|
||||
sops.age.sshKeyPaths = [
|
||||
"${config.home.homeDirectory}/.config/sops/sops_ed25519_key"
|
||||
# "/persist/home/${config.home.username}/.config/sops/sops_ed25519_key"
|
||||
];
|
||||
sops.secrets = cfg.secrets;
|
||||
modules.impermanence.directories = [ ".config/sops" ];
|
||||
};
|
||||
}
|
||||
@@ -16,5 +16,8 @@ in
|
||||
systemd-boot.editor = false;
|
||||
efi.canTouchEfiVariables = true;
|
||||
};
|
||||
|
||||
# Initrd
|
||||
boot.initrd.systemd.enable = true;
|
||||
};
|
||||
}
|
||||
@@ -20,5 +20,7 @@ in
|
||||
};
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable { disko.devices = profile.disko.devices; };
|
||||
config = mkIf cfg.enable {
|
||||
disko.devices = profile.disko.devices;
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,211 @@
|
||||
{
|
||||
inputs,
|
||||
lib,
|
||||
pkgs,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
|
||||
with lib;
|
||||
let
|
||||
cfg = config.modules.domain;
|
||||
domain = inputs.secrets.lab.domain;
|
||||
domainUpper = lib.strings.toUpper domain;
|
||||
in
|
||||
{
|
||||
options.modules.domain = {
|
||||
enable = mkEnableOption "Domain Integration";
|
||||
join = {
|
||||
userFile = mkOption {
|
||||
type = types.str;
|
||||
description = "File containing the user used to join the computer.";
|
||||
};
|
||||
passwordFile = mkOption {
|
||||
type = types.str;
|
||||
description = "File containing the password for the join user.";
|
||||
};
|
||||
domainOUFile = mkOption {
|
||||
type = types.str;
|
||||
description = "The OU to join the computer to.";
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
# Set network domain
|
||||
networking.domain = domain;
|
||||
networking.search = [ domain ];
|
||||
|
||||
# Automatically join the domain
|
||||
systemd.services.adcli-join = {
|
||||
description = "Automatically join the domain";
|
||||
wantedBy = [ "default.target" ];
|
||||
before = [ "sssd.service" ];
|
||||
requiredBy = [ "sssd.service" ];
|
||||
after = [
|
||||
"network-online.target"
|
||||
];
|
||||
requires = [
|
||||
"network-online.target"
|
||||
];
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
};
|
||||
script = ''
|
||||
ADCLI_JOIN_USER=$(cat ${cfg.join.userFile})
|
||||
ADCLI_JOIN_OU=$(cat ${cfg.join.domainOUFile})
|
||||
${pkgs.adcli}/bin/adcli join -D ${domain} \
|
||||
-U $ADCLI_JOIN_USER \
|
||||
-O $ADCLI_JOIN_OU \
|
||||
--dont-expire-password=true \
|
||||
--stdin-password < ${cfg.join.passwordFile}
|
||||
'';
|
||||
};
|
||||
|
||||
# Set up Kerberos
|
||||
security.krb5 = {
|
||||
enable = true;
|
||||
settings = {
|
||||
libdefaults = {
|
||||
default_realm = domainUpper;
|
||||
};
|
||||
realms.${domainUpper} = {
|
||||
};
|
||||
domain_realm = {
|
||||
"${domain}" = domainUpper;
|
||||
".${domain}" = domainUpper;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
# Set up SSSD
|
||||
services.sssd = {
|
||||
enable = true;
|
||||
config = ''
|
||||
[sssd]
|
||||
domains = ${domain}
|
||||
config_file_version = 2
|
||||
services = nss, pam
|
||||
|
||||
[nss]
|
||||
filter_users = ${concatStringsSep "," (lib.attrNames config.users.users)}
|
||||
filter_groups = ${concatStringsSep "," (lib.attrNames config.users.groups)}
|
||||
|
||||
[domain/${domain}]
|
||||
enumerate = False
|
||||
ad_domain = ${domain}
|
||||
krb5_realm = ${domainUpper}H
|
||||
id_provider = ad
|
||||
auth_provider = ad
|
||||
access_provider = ad
|
||||
chpass_provider = ad
|
||||
use_fully_qualified_names = False
|
||||
ldap_schema = ad
|
||||
ldap_id_mapping = True
|
||||
ad_gpo_access_control = enforcing
|
||||
ad_gpo_implicit_deny = True
|
||||
dyndns_update = True
|
||||
dyndns_update_ptr = False
|
||||
dyndns_refresh_interval = 86400
|
||||
dyndns_ttl = 3600
|
||||
'';
|
||||
};
|
||||
security.pam.services.login.sssdStrictAccess = true;
|
||||
security.pam.services.sshd.sssdStrictAccess = true;
|
||||
security.pam.services.su.sssdStrictAccess = true;
|
||||
|
||||
# Set up Sudo
|
||||
security.sudo =
|
||||
let
|
||||
admin_group = "host_${lib.replaceStrings [ "-" ] [ "_" ] config.networking.hostName}_admin";
|
||||
in
|
||||
{
|
||||
extraConfig = ''
|
||||
%${admin_group} ALL=(ALL) SETENV: ALL
|
||||
'';
|
||||
};
|
||||
|
||||
# Set up SSH
|
||||
services.openssh = {
|
||||
package = pkgs.opensshWithKerberos;
|
||||
settings = {
|
||||
GSSAPIAuthentication = true;
|
||||
GSSAPICleanupCredentials = true;
|
||||
GSSAPIStrictAcceptorCheck = true;
|
||||
};
|
||||
};
|
||||
|
||||
# Set up home directory
|
||||
security.pam.services.login.makeHomeDir = true;
|
||||
security.pam.services.sshd.makeHomeDir = true;
|
||||
environment.etc.profile.text =
|
||||
let
|
||||
# TODO: Activate configuration based on AD group
|
||||
homeConfiguration = inputs.home-manager.lib.homeManagerConfiguration {
|
||||
inherit pkgs;
|
||||
modules = [
|
||||
(
|
||||
{ lib, ... }:
|
||||
{
|
||||
home.stateVersion = "24.11";
|
||||
home.username = "$USER";
|
||||
home.homeDirectory = "/.$HOME";
|
||||
modules.profiles.base.enable = true;
|
||||
|
||||
# Mount the directories from the network share
|
||||
home.activation.dirMount =
|
||||
let
|
||||
bindScript = dir: ''
|
||||
mkdir -p /network/$USER/${dir}
|
||||
mkdir -p $HOME/${dir}
|
||||
${pkgs.bindfs}/bin/bindfs /network/$USER/${dir} $HOME/${dir}
|
||||
'';
|
||||
in
|
||||
lib.hm.dag.entryAfter [ "writeBoundary" ] ''
|
||||
if ! ${pkgs.krb5}/bin/klist -s; then
|
||||
echo "No kerberos ticket found"
|
||||
${pkgs.krb5}/bin/kinit
|
||||
fi
|
||||
|
||||
if ${pkgs.krb5}/bin/klist -s; then
|
||||
echo "Kerberos ticket found, mounting home directory"
|
||||
${bindScript "Documents"}
|
||||
${bindScript "Music"}
|
||||
${bindScript "Pictures"}
|
||||
${bindScript "Video"}
|
||||
else
|
||||
echo "Still no kerberos ticket found, skipping home directory mount"
|
||||
fi
|
||||
'';
|
||||
}
|
||||
)
|
||||
] ++ config.home-manager.sharedModules;
|
||||
};
|
||||
in
|
||||
mkAfter ''
|
||||
# Activate Home Manager configuration for domain users
|
||||
if id | egrep -o 'groups=.*' | sed 's/,/\n/g' | cut -d'(' -f2 | sed 's/)//' | egrep -o "^domain users$"; then
|
||||
echo "Setting up environment for domain user"
|
||||
SKIP_SANITY_CHECKS=1 ${homeConfiguration.activationPackage}/activate
|
||||
if test -f "$HOME/.bashrc"; then
|
||||
. $HOME/.bashrc
|
||||
fi
|
||||
fi
|
||||
'';
|
||||
|
||||
# Automatically mount home share
|
||||
# Can be accessed at /network/$USER
|
||||
services.autofs = {
|
||||
enable = true;
|
||||
autoMaster =
|
||||
let
|
||||
networkMap = pkgs.writeText "auto" ''
|
||||
* -fstype=cifs,sec=krb5,user=&,uid=$UID,gid=$GID,cruid=$UID ://${inputs.secrets.lab.nas.host}/home
|
||||
'';
|
||||
in
|
||||
''
|
||||
/network ${networkMap} --timeout=30
|
||||
'';
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -24,18 +24,32 @@ in
|
||||
resetScript = mkOption {
|
||||
type = types.lines;
|
||||
description = ''
|
||||
Script to run on boot that resets the root partition.
|
||||
Script to run in order to reset the system to a clean state.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
# Filesystem setup
|
||||
fileSystems."/persist".neededForBoot = true;
|
||||
boot.initrd.postResumeCommands = mkAfter cfg.resetScript;
|
||||
# boot.initrd.postResumeCommands = mkAfter cfg.resetScript;
|
||||
# TODO: Reduce dependency on the root filesystem being ZFS?
|
||||
boot.initrd.systemd.services.impermanence-rollback = {
|
||||
description = "Rollback filesystem to clean state.";
|
||||
wantedBy = [ "initrd.target" ];
|
||||
after = [ "zfs-import.target" ];
|
||||
before = [ "sysroot.mount" ];
|
||||
unitConfig.DefaultDependencies = "no";
|
||||
serviceConfig.Type = "oneshot";
|
||||
script = cfg.resetScript;
|
||||
};
|
||||
|
||||
# For home-manager persistence
|
||||
programs.fuse.userAllowOther = true;
|
||||
|
||||
# For testing purposes with VM
|
||||
virtualisation.vmVariantWithDisko.virtualisation.fileSystems."/persist".neededForBoot = true;
|
||||
|
||||
environment.persistence."/persist/system" = {
|
||||
enable = true;
|
||||
hideMounts = true;
|
||||
|
||||
@@ -0,0 +1,44 @@
|
||||
{
|
||||
inputs,
|
||||
lib,
|
||||
config,
|
||||
...
|
||||
}:
|
||||
|
||||
with lib;
|
||||
let
|
||||
cfg = config.modules.secrets;
|
||||
secrets = inputs.secrets;
|
||||
in
|
||||
{
|
||||
options.modules.secrets = {
|
||||
enable = mkEnableOption "secrets";
|
||||
defaultFile = mkOption {
|
||||
type = types.str;
|
||||
default = "${secrets}/secrets/common.enc.yaml";
|
||||
description = ''
|
||||
The default file to use for SOPS.
|
||||
'';
|
||||
};
|
||||
secrets = mkOption {
|
||||
type = types.attrs;
|
||||
default = { };
|
||||
description = ''
|
||||
All secrets that should be made available.
|
||||
'';
|
||||
};
|
||||
};
|
||||
|
||||
config = mkIf cfg.enable {
|
||||
# Set up SOPS
|
||||
# TODO: Fix the key not being present in /etc/sops before sops-nix runs
|
||||
sops.defaultSopsFile = cfg.defaultFile;
|
||||
sops.age.sshKeyPaths = [
|
||||
"/etc/sops/sops_ed25519_key"
|
||||
"/persist/system/etc/sops/sops_ed25519_key"
|
||||
];
|
||||
sops.secrets = cfg.secrets;
|
||||
modules.impermanence.directories = [ "/etc/sops" ];
|
||||
virtualisation.vmVariantWithDisko.sops.age.sshKeyPaths = [ "/tmp/shared/sops_ed25519_key" ];
|
||||
};
|
||||
}
|
||||
+19
-2
@@ -9,7 +9,24 @@ in
|
||||
enable = mkEnableOption "ssh";
|
||||
};
|
||||
config = mkIf cfg.enable {
|
||||
services.openssh.enable = true;
|
||||
# TODO: Is this default configuration secure?
|
||||
services.openssh = {
|
||||
enable = true;
|
||||
settings = {
|
||||
PasswordAuthentication = false;
|
||||
KbdInteractiveAuthentication = false;
|
||||
PermitRootLogin = "no";
|
||||
};
|
||||
hostKeys = mkIf (config.modules.impermanence.enable) [
|
||||
{
|
||||
type = "ed25519";
|
||||
path = "/persist/system/etc/ssh/ssh_host_ed25519_key";
|
||||
}
|
||||
{
|
||||
type = "rsa";
|
||||
bits = 4096;
|
||||
path = "/persist/system/etc/ssh/ssh_host_rsa_key";
|
||||
}
|
||||
];
|
||||
};
|
||||
};
|
||||
}
|
||||
+10
-1
@@ -3,6 +3,8 @@
|
||||
disk = {
|
||||
main = {
|
||||
type = "disk";
|
||||
device = "/dev/sda";
|
||||
imageSize = "32G"; # For test VMs
|
||||
content = {
|
||||
type = "gpt";
|
||||
partitions = {
|
||||
@@ -17,12 +19,19 @@
|
||||
};
|
||||
};
|
||||
zfs = {
|
||||
size = "100%";
|
||||
end = "-4G";
|
||||
content = {
|
||||
type = "zfs";
|
||||
pool = "tank";
|
||||
};
|
||||
};
|
||||
swap = {
|
||||
size = "100%";
|
||||
content = {
|
||||
type = "swap";
|
||||
discardPolicy = "both";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
@@ -24,7 +24,6 @@ in
|
||||
freecad-wayland
|
||||
inkscape
|
||||
ente-auth
|
||||
bitwarden
|
||||
carla
|
||||
winbox
|
||||
whatsapp-for-linux
|
||||
@@ -39,6 +38,7 @@ in
|
||||
prismlauncher
|
||||
foliate
|
||||
wireshark
|
||||
obsidian
|
||||
];
|
||||
|
||||
modules = {
|
||||
@@ -61,6 +61,7 @@ in
|
||||
"flake.lock"
|
||||
];
|
||||
};
|
||||
bitwarden.enable = true;
|
||||
xpra = {
|
||||
enable = true;
|
||||
hosts = [
|
||||
|
||||
+10
-5
@@ -1,5 +1,4 @@
|
||||
{
|
||||
mkModule,
|
||||
pkgs,
|
||||
lib,
|
||||
config,
|
||||
@@ -20,13 +19,19 @@ in
|
||||
bootloader.enable = mkDefault true;
|
||||
ssh.enable = mkDefault true;
|
||||
|
||||
# Setup sensible default persistent data
|
||||
impermanence.directories = [
|
||||
"/var/lib/nixos"
|
||||
];
|
||||
impermanence.files = [
|
||||
"/etc/shadow"
|
||||
];
|
||||
|
||||
# TODO: Remove the secrets module and use sops directly?
|
||||
secrets = {
|
||||
enable = true;
|
||||
secrets = {
|
||||
"ssh-keys/deploy-priv" = {
|
||||
path = "/root/.ssh/id_ed25519";
|
||||
};
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
# Localization
|
||||
|
||||
+36
-15
@@ -1,5 +1,4 @@
|
||||
{
|
||||
mkModule,
|
||||
pkgs,
|
||||
lib,
|
||||
config,
|
||||
@@ -30,17 +29,50 @@ in
|
||||
zfs rollback -r tank/root@blank
|
||||
'';
|
||||
};
|
||||
domain = {
|
||||
enable = true;
|
||||
join = {
|
||||
userFile = config.sops.secrets."vm-join/user".path;
|
||||
passwordFile = config.sops.secrets."vm-join/password".path;
|
||||
domainOUFile = config.sops.secrets."vm-join/ou".path;
|
||||
};
|
||||
};
|
||||
ssh.enable = true;
|
||||
};
|
||||
|
||||
# Admin users
|
||||
# Initialize domain join secrets
|
||||
sops.secrets."vm-join/user" = { };
|
||||
sops.secrets."vm-join/password" = { };
|
||||
sops.secrets."vm-join/ou" = { };
|
||||
|
||||
# Autologin to root for access from hypervisor
|
||||
services.getty.autologinUser = "root";
|
||||
|
||||
# Local user
|
||||
modules.secrets.secrets."passwords/local-hashed".neededForUsers = true;
|
||||
users.mutableUsers = false;
|
||||
users.users.local = {
|
||||
initialPassword = "local";
|
||||
isNormalUser = true;
|
||||
group = "local";
|
||||
hashedPasswordFile = config.sops.secrets."passwords/local-hashed".path;
|
||||
extraGroups = [ "wheel" ];
|
||||
openssh.authorizedKeys.keys = [
|
||||
"ssh-ed25519 jan@bulthuis.dev"
|
||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq Admin"
|
||||
];
|
||||
};
|
||||
users.groups.local = { };
|
||||
home-manager.users.local =
|
||||
{ ... }:
|
||||
{
|
||||
home.stateVersion = "24.11";
|
||||
modules.profiles.base.enable = true;
|
||||
};
|
||||
|
||||
# System packages
|
||||
environment.systemPackages = with pkgs; [
|
||||
# TODO: Make module for utilities/scripts
|
||||
(writeShellScriptBin "system-update" "nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/nixos-config")
|
||||
];
|
||||
|
||||
# Enable qemu guest agent
|
||||
services.qemuGuest.enable = true;
|
||||
@@ -61,17 +93,6 @@ in
|
||||
"sd_mod"
|
||||
"sr_mod"
|
||||
];
|
||||
boot.initrd.kernelModules = [ ];
|
||||
boot.kernelModules = [ "kvm-intel" ];
|
||||
boot.extraModulePackages = [ ];
|
||||
hardware.cpu.intel.updateMicrocode = true;
|
||||
|
||||
# Swapfile
|
||||
swapDevices = [
|
||||
{
|
||||
device = "/var/lib/swapfile";
|
||||
size = 6 * 1024;
|
||||
}
|
||||
];
|
||||
};
|
||||
}
|
||||
Reference in new issue
Block a user