Compare commits

..
92 Commits
Author SHA1 Message Date
Jan-Bulthuis c8bf78999a Added test VM 2025-06-11 17:21:19 +02:00
Jan-Bulthuis 0d25c1deff Fixed wireguard VPNs 2025-06-11 17:13:53 +02:00
Jan-Bulthuis 3603fe28a7 Removed authorizedKeys integration from sssd 2025-06-11 14:27:16 +02:00
Jan-Bulthuis ce7c940f65 Switched to openssh package with kerberos support 2025-06-11 14:21:57 +02:00
Jan-Bulthuis d8327c3edf Updated SSH to use GSSAPI 2025-06-11 14:13:25 +02:00
Jan-Bulthuis af9f7e0ee0 Updated sssd dyndns config 2025-06-11 13:01:02 +02:00
Jan-Bulthuis 3285b483e2 Created standard local user hm config for VMs 2025-06-11 12:42:06 +02:00
Jan-Bulthuis affa333969 Moved to systemd for initrd, added integration for vmWithDisko 2025-06-11 11:58:54 +02:00
Jan-Bulthuis 3c20190709 Create additional directories 2025-06-10 03:27:46 +02:00
Jan-Bulthuis 0305b8d33a Moved to bind mounts 2025-06-10 03:23:30 +02:00
Jan-Bulthuis 5ade637e57 Included package path 2025-06-10 03:07:57 +02:00
Jan-Bulthuis 029ff0c9a3 Added link creation to activation script 2025-06-10 03:04:44 +02:00
Jan-Bulthuis db4bd8cfd9 Used persistence for mounting network folders 2025-06-10 02:37:26 +02:00
Jan-Bulthuis 41d25d9695 Updated autofs 2025-06-10 02:12:19 +02:00
Jan-Bulthuis 7e2e012f3a Changed autofs map 2025-06-10 01:56:23 +02:00
Jan-Bulthuis 071e904990 Updated autofs setup 2025-06-10 01:27:47 +02:00
Jan-Bulthuis b68ca558d8 Set up autofs 2025-06-10 01:15:50 +02:00
Jan-Bulthuis cf760b8b85 Simplified sude config 2025-06-10 00:07:58 +02:00
Jan-Bulthuis 7d4ee43283 Filter out locally defined users and groups 2025-06-10 00:07:22 +02:00
Jan-Bulthuis 4e08366901 Changed backup ID 2025-06-09 16:39:13 +02:00
Jan-Bulthuis a0ca155f7c Set backup id 2025-06-09 16:34:42 +02:00
Jan-Bulthuis 110aa4215f Added dependency on network for krb5 auth 2025-06-09 16:28:37 +02:00
Jan-Bulthuis 08a161ff0d Set up mount dependencies 2025-06-09 16:18:02 +02:00
Jan-Bulthuis f4472de631 Updated backup script 2025-06-09 16:13:25 +02:00
Jan-Bulthuis 3c154de819 Changed correct script 2025-06-09 16:00:05 +02:00
Jan-Bulthuis 709040c072 exported configuration 2025-06-09 15:55:53 +02:00
Jan-Bulthuis 28193823c8 Added backup cron job 2025-06-09 15:45:14 +02:00
Jan-Bulthuis dd25c9323d Reenabled kinit 2025-06-09 15:15:17 +02:00
Jan-Bulthuis 5796bee499 Removed unneeded dependencies 2025-06-09 15:11:13 +02:00
Jan-Bulthuis 986afe4b32 Added packages 2025-06-09 15:07:54 +02:00
Jan-Bulthuis 537e30a347 Move request-key configuration 2025-06-09 15:00:44 +02:00
Jan-Bulthuis 2fec5ead38 Use kinit from krb5 package 2025-06-09 14:28:54 +02:00
Jan-Bulthuis d4e6283c2f Added service to set up user keytab 2025-06-09 14:23:11 +02:00
Jan-Bulthuis 32e7d99292 Set up request-key.conf 2025-06-09 13:54:31 +02:00
Jan-Bulthuis d9dab5b9d3 Resource bashrc 2025-06-09 13:24:58 +02:00
Jan-Bulthuis cdd94eefb3 Enabled base profile for domain users 2025-06-09 13:06:29 +02:00
Jan-Bulthuis 209dbea02a Disable sanity checks 2025-06-09 13:01:56 +02:00
Jan-Bulthuis c683809a78 Added initial homeConfiguration for domain users 2025-06-09 12:50:30 +02:00
Jan-Bulthuis 739e335c28 Added test loginShellInit 2025-06-09 04:29:25 +02:00
Jan-Bulthuis 3c6758b343 Quick fix 2025-06-09 04:07:18 +02:00
Jan-Bulthuis 799b91a509 Update PAM 2025-06-09 04:05:52 +02:00
Jan-Bulthuis 50ff958d35 Setup strict ssh auth 2025-06-09 03:42:25 +02:00
Jan-Bulthuis ecc2779ce9 Made SSSD strict for login in PAM 2025-06-09 03:28:39 +02:00
Jan-Bulthuis 10dab81fb5 Disable PTR update 2025-06-09 03:09:14 +02:00
Jan-Bulthuis 03e96662cc Set ad_gpo_implicit_deny to true 2025-06-09 02:57:06 +02:00
Jan-Bulthuis d6d54e213e Implement SSH domain integration 2025-06-09 02:36:07 +02:00
Jan-Bulthuis f491be0ace Added sudo domain integration 2025-06-09 02:17:05 +02:00
Jan-Bulthuis fef1eff181 Simplified kerberos config 2025-06-09 01:54:39 +02:00
Jan-Bulthuis e869e5d790 Setup kerberos config 2025-06-09 01:47:48 +02:00
Jan-Bulthuis 48caacd9e5 Enforce GPO access control 2025-06-09 01:34:29 +02:00
Jan-Bulthuis ce4401033a Enabled dyndns 2025-06-08 03:45:33 +02:00
Jan-Bulthuis 8b331ad3ae Added SSSD config 2025-06-08 03:39:12 +02:00
Jan-Bulthuis 417383f89b Updated adcli script 2025-06-08 03:22:10 +02:00
Jan-Bulthuis cc75c95ad4 Moved domain config 2025-06-08 03:04:14 +02:00
Jan-Bulthuis a321251b93 Update secrets 2025-06-08 03:04:00 +02:00
Jan-Bulthuis 54677248af Installed some packages 2025-06-08 00:56:26 +02:00
Jan-Bulthuis d8f18016cd Added krb5 setup 2025-06-08 00:10:13 +02:00
Jan-Bulthuis 6522ebc15e Added krb5 as sec for smb mount 2025-06-07 23:47:20 +02:00
Jan-Bulthuis 10216784e8 Set correct hostname 2025-06-07 23:38:38 +02:00
Jan-Bulthuis f3abb6d2f3 Added samba mount 2025-06-07 23:36:21 +02:00
Jan-Bulthuis 936d654877 Added oddjob VM 2025-06-07 21:15:31 +02:00
Jan-Bulthuis 61d207db04 Installed obsidian 2025-06-07 21:15:14 +02:00
Jan-Bulthuis e7b66cb40c Added kerberos config 2025-06-07 21:14:59 +02:00
Jan-Bulthuis c9b18219af Updated secrets 2025-06-07 21:14:43 +02:00
Jan-Bulthuis d5c4a78fba Updated README.md 2025-06-07 21:14:28 +02:00
Jan-Bulthuis 369d655a38 Autologin to root for access from hypervisor 2025-05-30 16:44:23 +02:00
Jan-Bulthuis eab130b99d Removed swapfile 2025-05-30 16:38:25 +02:00
Jan-Bulthuis 5ce6b9bdf2 Added swap partition 2025-05-30 16:37:48 +02:00
Jan-Bulthuis 5db52a4f84 Removed need for password for local wheel group on VMs 2025-05-30 16:22:09 +02:00
Jan-Bulthuis 3524f6b038 Replaced key 2025-05-30 16:19:12 +02:00
Jan-Bulthuis 0cf53a97cf Restricted SSH access 2025-05-30 16:15:52 +02:00
Jan-Bulthuis 46fe5b8056 Set local password 2025-05-30 16:15:42 +02:00
Jan-Bulthuis ec3d9e6049 Updated modules 2025-05-30 16:08:51 +02:00
Jan-Bulthuis fc0476ca5a Added admin-pub secret 2025-05-30 16:08:39 +02:00
Jan-Bulthuis 4b7c62d00b Gave local passwordless sudo, rerolled and encrypted the authorized key. 2025-05-30 16:05:00 +02:00
Jan-Bulthuis cfc276184f Updated README.md 2025-05-30 15:37:19 +02:00
Jan-Bulthuis 87b50bfb4d Updated secrets 2025-05-30 15:26:05 +02:00
Jan-Bulthuis 1bc34518e1 Added deployment key to root account 2025-05-30 15:11:22 +02:00
Jan-Bulthuis f1dcb8c72b Updated sops-nix to also directly point at /persist 2025-05-30 14:35:59 +02:00
Jan-Bulthuis ec002467fa Updated secrets 2025-05-30 14:03:14 +02:00
Jan-Bulthuis 5a228cb375 Updated update script 2025-05-30 14:03:05 +02:00
Jan-Bulthuis d53e395d42 Added a module for SOPS 2025-05-30 13:56:50 +02:00
Jan-Bulthuis cb39f82a48 Updated flake.lock 2025-05-30 12:42:35 +02:00
Jan-Bulthuis 0efee5bceb Added dependency on nixos-secrets 2025-05-30 12:06:21 +02:00
Jan-Bulthuis 844118055c Updated README.md 2025-05-29 21:00:40 +02:00
Jan-Bulthuis 0ba9de0030 Set disk device for vm disko 2025-05-29 20:46:44 +02:00
Jan-Bulthuis a745b35c84 Added update script 2025-05-29 20:37:12 +02:00
Jan-Bulthuis 6c74dcbc22 Automatically login to user 2025-05-29 20:32:19 +02:00
Jan-Bulthuis 76e609372f Added persistence to ssh host keys 2025-05-29 20:28:07 +02:00
Jan-Bulthuis cd91944b1e Updated local user configuration 2025-05-29 20:20:18 +02:00
Jan-Bulthuis bebd2748d1 Moved bitwarden to a module 2025-05-29 19:23:52 +02:00
Jan 12a4ba0482 Merge pull request 'Add disko support' (#2) from disko into main
Reviewed-on: Jan/dotfiles#2
2025-05-29 16:33:31 +00:00
22 changed files with 601 additions and 52 deletions

No files matched your search

+33 -2
View File
@@ -4,8 +4,39 @@ My NixOS configuration.
## Installation ## Installation
For disk configuration we use disko, this means that installing the system from the configuration is just a single command: For disk configuration we use disko, but for secrets management we use sops-nix and the particular setup makes the installation process a bit more involved. It is required that the computer from which the installation is being run has access to the `nixos-secrets` repository, otherwise you will need to manually add the required ssh keys to the installation image.
```bash
# Load into the installer
sudo passwd # Set a root password
# From a machine with network access to the installer
# and access to the nixos-secrets repo
ssh -A root@(installer-ip)
# Set up disks
nix-shell -p disko
disko --mode disko --flake git+https://git.bulthuis.dev/Jan/nixos-config#(system)
exit
# Install NixOS
nixos-install --no-channel-copy --no-root-password --flake git+https://git.bulthuis.dev/Jan/nixos-config#(system)
# Set up host credentials for access to the secrets
cd /mnt/persist/system/etc/sops
touch sops_ed25519_key
chmod 600 sops_ed25519_key
nano sops_ed25519_key
``` ```
sudo nix --experimental-features "nix-command flakes" run "github:nix-community/disko/latest#disko-install" -- --flake git+https://git.bulthuis.dev/Jan/dotfiles#<hostname> --disk main /dev/sda If `nixos-install` is being stopped by the OOM-killer, you can try adding `-j 1` to limit the amount of jobs that will be executed at the same time to 1. It might require running nixos-install multiple times untill it has managed to download all requirements and slowly start building the rest of the system.
## Updating
To update the system configuration, it is a single command:
```bash
sudo system-update
``` ```
Or if this shell script has not been installed for some reason:
```bash
sudo nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/nixos-config
```
Sometimes it may be necessary to reboot of course.
Generated
+38 -1
View File
@@ -154,7 +154,44 @@
"impermanence": "impermanence", "impermanence": "impermanence",
"nix-minecraft": "nix-minecraft", "nix-minecraft": "nix-minecraft",
"nix-modpack": "nix-modpack", "nix-modpack": "nix-modpack",
"nixpkgs": "nixpkgs" "nixpkgs": "nixpkgs",
"secrets": "secrets",
"sops-nix": "sops-nix"
}
},
"secrets": {
"locked": {
"lastModified": 1749476519,
"narHash": "sha256-yzSsn2e+n4TQisd1PB7vZLcz9rhd8n5V4uoniWt+CP8=",
"ref": "refs/heads/main",
"rev": "890c1295ca6fea2a3aad5b7075dd5902f92beef0",
"revCount": 13,
"type": "git",
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
},
"original": {
"type": "git",
"url": "ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets"
}
},
"sops-nix": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1747603214,
"narHash": "sha256-lAblXm0VwifYCJ/ILPXJwlz0qNY07DDYdLD+9H+Wc8o=",
"owner": "Mic92",
"repo": "sops-nix",
"rev": "8d215e1c981be3aa37e47aeabd4e61bb069548fd",
"type": "github"
},
"original": {
"owner": "Mic92",
"repo": "sops-nix",
"type": "github"
} }
}, },
"systems": { "systems": {
+7
View File
@@ -6,6 +6,13 @@
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable"; nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
home-manager.url = "github:nix-community/home-manager"; home-manager.url = "github:nix-community/home-manager";
home-manager.inputs.nixpkgs.follows = "nixpkgs"; home-manager.inputs.nixpkgs.follows = "nixpkgs";
# Secrets
sops-nix.url = "github:Mic92/sops-nix";
sops-nix.inputs.nixpkgs.follows = "nixpkgs";
secrets.url = "git+ssh://gitea@git.bulthuis.dev/Jan/nixos-secrets";
# Disk setup
disko.url = "github:nix-community/disko"; disko.url = "github:nix-community/disko";
disko.inputs.nixpkgs.follows = "nixpkgs"; disko.inputs.nixpkgs.follows = "nixpkgs";
impermanence.url = "github:nix-community/impermanence"; impermanence.url = "github:nix-community/impermanence";
+12 -1
View File
@@ -1,4 +1,4 @@
{ flake, ... }: { inputs, ... }:
{ {
# State version # State version
@@ -13,6 +13,17 @@
"wireshark" "wireshark"
]; ];
# Set up kerberos
security.krb5 = {
enable = true;
settings = {
libdefaults = {
rdns = false;
};
realms = (inputs.secrets.gewis.krb5Realm);
};
};
# Enable virtualisation for VMs # Enable virtualisation for VMs
virtualisation.libvirtd.enable = true; virtualisation.libvirtd.enable = true;
-7
View File
@@ -1,7 +0,0 @@
{ ... }:
{
home.stateVersion = "24.11";
modules.profiles.base.enable = true;
}
-7
View File
@@ -1,7 +0,0 @@
{ ... }:
{
home.stateVersion = "24.11";
modules.profiles.base.enable = true;
}
+71
View File
@@ -0,0 +1,71 @@
{
inputs,
lib,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "24.11";
# Machine hostname
networking.hostName = "vm-oddjob";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
# Setup NAS backups
environment.systemPackages = with pkgs; [
keyutils
];
environment.etc."request-key.d/cifs.spnego.conf".text = ''
create cifs.spnego * * ${pkgs.cifs-utils}/bin/cifs.upcall -t %k
'';
environment.etc."request-key.d/cifs.idmap.conf".text = ''
create cifs.idmap * * ${pkgs.cifs-utils}/bin/cifs.idmap %k
'';
sops.secrets."smb-credentials" = {
sopsFile = "${inputs.secrets}/secrets/vm-oddjob.enc.yaml";
};
sops.secrets."backup-script-env" = {
sopsFile = "${inputs.secrets}/secrets/vm-oddjob.enc.yaml";
};
systemd.services.mnt-nas-krb5 = {
description = "Set up Kerberos credentials for mnt-nas";
before = [ "mnt-nas.mount" ];
requiredBy = [ "mnt-nas.mount" ];
after = [ "network-online.target" ];
requires = [ "network-online.target" ];
serviceConfig.Type = "oneshot";
script = ''
. ${config.sops.secrets."smb-credentials".path}
echo $password | ${pkgs.krb5}/bin/kinit $username
'';
};
services.cron = {
enable = true;
systemCronJobs =
let
script = pkgs.writeShellScript "backup-script" ''
. ${config.sops.secrets."backup-script-env".path}
export PBS_REPOSITORY=$PBS_REPOSITORY
export PBS_NAMESPACE=$PBS_NAMESPACE
export PBS_PASSWORD=$PBS_PASSWORD
export PBS_FINGERPRINT=$PBS_FINGERPRINT
${pkgs.proxmox-backup-client}/bin/proxmox-backup-client backup nfs.pxar:/mnt/nas --ns $PBS_NAMESPACE --backup-id nas-backup --change-detection-mode=metadata --exclude "#recycle"
'';
in
[
"0 0 * * * ${script} "
];
};
fileSystems."/mnt/nas" = {
device = "//${inputs.secrets.lab.nas.host}/Backup";
fsType = "cifs";
options = [ "sec=krb5,credentials=${config.sops.secrets."smb-credentials".path}" ];
};
}
+19
View File
@@ -0,0 +1,19 @@
{
lib,
pkgs,
config,
...
}:
{
# State version
system.stateVersion = "24.11";
# Machine hostname
networking.hostName = "vm-test";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
}
-7
View File
@@ -1,7 +0,0 @@
{ ... }:
{
home.stateVersion = "24.11";
modules.profiles.base.enable = true;
}
+22
View File
@@ -0,0 +1,22 @@
{
lib,
config,
pkgs,
...
}:
with lib;
let
cfg = config.modules.bitwarden;
in
{
options.modules.bitwarden = {
enable = mkEnableOption "Bitwarden";
};
config = mkIf cfg.enable {
home.packages = with pkgs; [
bitwarden-desktop
];
};
}
+43
View File
@@ -0,0 +1,43 @@
{
inputs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.secrets;
secrets = inputs.secrets;
in
{
options.modules.secrets = {
enable = mkEnableOption "secrets";
defaultFile = mkOption {
type = types.str;
default = "${secrets}/secrets/common.enc.yaml";
description = ''
The default file to use for SOPS.
'';
};
secrets = mkOption {
type = types.attrs;
default = { };
description = ''
All secrets that should be made available.
'';
};
};
config = mkIf cfg.enable {
# Set up SOPS
# TODO: Fix the key not being present in .config/sops before sops-nix runs
sops.defaultSopsFile = cfg.defaultFile;
sops.age.sshKeyPaths = [
"${config.home.homeDirectory}/.config/sops/sops_ed25519_key"
# "/persist/home/${config.home.username}/.config/sops/sops_ed25519_key"
];
sops.secrets = cfg.secrets;
modules.impermanence.directories = [ ".config/sops" ];
};
}
+3
View File
@@ -16,5 +16,8 @@ in
systemd-boot.editor = false; systemd-boot.editor = false;
efi.canTouchEfiVariables = true; efi.canTouchEfiVariables = true;
}; };
# Initrd
boot.initrd.systemd.enable = true;
}; };
} }
+3 -1
View File
@@ -20,5 +20,7 @@ in
}; };
}; };
config = mkIf cfg.enable { disko.devices = profile.disko.devices; }; config = mkIf cfg.enable {
disko.devices = profile.disko.devices;
};
} }
+211
View File
@@ -0,0 +1,211 @@
{
inputs,
lib,
pkgs,
config,
...
}:
with lib;
let
cfg = config.modules.domain;
domain = inputs.secrets.lab.domain;
domainUpper = lib.strings.toUpper domain;
in
{
options.modules.domain = {
enable = mkEnableOption "Domain Integration";
join = {
userFile = mkOption {
type = types.str;
description = "File containing the user used to join the computer.";
};
passwordFile = mkOption {
type = types.str;
description = "File containing the password for the join user.";
};
domainOUFile = mkOption {
type = types.str;
description = "The OU to join the computer to.";
};
};
};
config = mkIf cfg.enable {
# Set network domain
networking.domain = domain;
networking.search = [ domain ];
# Automatically join the domain
systemd.services.adcli-join = {
description = "Automatically join the domain";
wantedBy = [ "default.target" ];
before = [ "sssd.service" ];
requiredBy = [ "sssd.service" ];
after = [
"network-online.target"
];
requires = [
"network-online.target"
];
serviceConfig = {
Type = "oneshot";
};
script = ''
ADCLI_JOIN_USER=$(cat ${cfg.join.userFile})
ADCLI_JOIN_OU=$(cat ${cfg.join.domainOUFile})
${pkgs.adcli}/bin/adcli join -D ${domain} \
-U $ADCLI_JOIN_USER \
-O $ADCLI_JOIN_OU \
--dont-expire-password=true \
--stdin-password < ${cfg.join.passwordFile}
'';
};
# Set up Kerberos
security.krb5 = {
enable = true;
settings = {
libdefaults = {
default_realm = domainUpper;
};
realms.${domainUpper} = {
};
domain_realm = {
"${domain}" = domainUpper;
".${domain}" = domainUpper;
};
};
};
# Set up SSSD
services.sssd = {
enable = true;
config = ''
[sssd]
domains = ${domain}
config_file_version = 2
services = nss, pam
[nss]
filter_users = ${concatStringsSep "," (lib.attrNames config.users.users)}
filter_groups = ${concatStringsSep "," (lib.attrNames config.users.groups)}
[domain/${domain}]
enumerate = False
ad_domain = ${domain}
krb5_realm = ${domainUpper}H
id_provider = ad
auth_provider = ad
access_provider = ad
chpass_provider = ad
use_fully_qualified_names = False
ldap_schema = ad
ldap_id_mapping = True
ad_gpo_access_control = enforcing
ad_gpo_implicit_deny = True
dyndns_update = True
dyndns_update_ptr = False
dyndns_refresh_interval = 86400
dyndns_ttl = 3600
'';
};
security.pam.services.login.sssdStrictAccess = true;
security.pam.services.sshd.sssdStrictAccess = true;
security.pam.services.su.sssdStrictAccess = true;
# Set up Sudo
security.sudo =
let
admin_group = "host_${lib.replaceStrings [ "-" ] [ "_" ] config.networking.hostName}_admin";
in
{
extraConfig = ''
%${admin_group} ALL=(ALL) SETENV: ALL
'';
};
# Set up SSH
services.openssh = {
package = pkgs.opensshWithKerberos;
settings = {
GSSAPIAuthentication = true;
GSSAPICleanupCredentials = true;
GSSAPIStrictAcceptorCheck = true;
};
};
# Set up home directory
security.pam.services.login.makeHomeDir = true;
security.pam.services.sshd.makeHomeDir = true;
environment.etc.profile.text =
let
# TODO: Activate configuration based on AD group
homeConfiguration = inputs.home-manager.lib.homeManagerConfiguration {
inherit pkgs;
modules = [
(
{ lib, ... }:
{
home.stateVersion = "24.11";
home.username = "$USER";
home.homeDirectory = "/.$HOME";
modules.profiles.base.enable = true;
# Mount the directories from the network share
home.activation.dirMount =
let
bindScript = dir: ''
mkdir -p /network/$USER/${dir}
mkdir -p $HOME/${dir}
${pkgs.bindfs}/bin/bindfs /network/$USER/${dir} $HOME/${dir}
'';
in
lib.hm.dag.entryAfter [ "writeBoundary" ] ''
if ! ${pkgs.krb5}/bin/klist -s; then
echo "No kerberos ticket found"
${pkgs.krb5}/bin/kinit
fi
if ${pkgs.krb5}/bin/klist -s; then
echo "Kerberos ticket found, mounting home directory"
${bindScript "Documents"}
${bindScript "Music"}
${bindScript "Pictures"}
${bindScript "Video"}
else
echo "Still no kerberos ticket found, skipping home directory mount"
fi
'';
}
)
] ++ config.home-manager.sharedModules;
};
in
mkAfter ''
# Activate Home Manager configuration for domain users
if id | egrep -o 'groups=.*' | sed 's/,/\n/g' | cut -d'(' -f2 | sed 's/)//' | egrep -o "^domain users$"; then
echo "Setting up environment for domain user"
SKIP_SANITY_CHECKS=1 ${homeConfiguration.activationPackage}/activate
if test -f "$HOME/.bashrc"; then
. $HOME/.bashrc
fi
fi
'';
# Automatically mount home share
# Can be accessed at /network/$USER
services.autofs = {
enable = true;
autoMaster =
let
networkMap = pkgs.writeText "auto" ''
* -fstype=cifs,sec=krb5,user=&,uid=$UID,gid=$GID,cruid=$UID ://${inputs.secrets.lab.nas.host}/home
'';
in
''
/network ${networkMap} --timeout=30
'';
};
};
}
+16 -2
View File
@@ -24,18 +24,32 @@ in
resetScript = mkOption { resetScript = mkOption {
type = types.lines; type = types.lines;
description = '' description = ''
Script to run on boot that resets the root partition. Script to run in order to reset the system to a clean state.
''; '';
}; };
}; };
config = mkIf cfg.enable { config = mkIf cfg.enable {
# Filesystem setup
fileSystems."/persist".neededForBoot = true; fileSystems."/persist".neededForBoot = true;
boot.initrd.postResumeCommands = mkAfter cfg.resetScript; # boot.initrd.postResumeCommands = mkAfter cfg.resetScript;
# TODO: Reduce dependency on the root filesystem being ZFS?
boot.initrd.systemd.services.impermanence-rollback = {
description = "Rollback filesystem to clean state.";
wantedBy = [ "initrd.target" ];
after = [ "zfs-import.target" ];
before = [ "sysroot.mount" ];
unitConfig.DefaultDependencies = "no";
serviceConfig.Type = "oneshot";
script = cfg.resetScript;
};
# For home-manager persistence # For home-manager persistence
programs.fuse.userAllowOther = true; programs.fuse.userAllowOther = true;
# For testing purposes with VM
virtualisation.vmVariantWithDisko.virtualisation.fileSystems."/persist".neededForBoot = true;
environment.persistence."/persist/system" = { environment.persistence."/persist/system" = {
enable = true; enable = true;
hideMounts = true; hideMounts = true;
+2
View File
@@ -11,5 +11,7 @@ in
config = mkIf cfg.enable { config = mkIf cfg.enable {
# TODO: Add sudo users to the networkmanager group? # TODO: Add sudo users to the networkmanager group?
networking.networkmanager.enable = true; networking.networkmanager.enable = true;
networking.firewall.checkReversePath = false;
}; };
} }
+44
View File
@@ -0,0 +1,44 @@
{
inputs,
lib,
config,
...
}:
with lib;
let
cfg = config.modules.secrets;
secrets = inputs.secrets;
in
{
options.modules.secrets = {
enable = mkEnableOption "secrets";
defaultFile = mkOption {
type = types.str;
default = "${secrets}/secrets/common.enc.yaml";
description = ''
The default file to use for SOPS.
'';
};
secrets = mkOption {
type = types.attrs;
default = { };
description = ''
All secrets that should be made available.
'';
};
};
config = mkIf cfg.enable {
# Set up SOPS
# TODO: Fix the key not being present in /etc/sops before sops-nix runs
sops.defaultSopsFile = cfg.defaultFile;
sops.age.sshKeyPaths = [
"/etc/sops/sops_ed25519_key"
"/persist/system/etc/sops/sops_ed25519_key"
];
sops.secrets = cfg.secrets;
modules.impermanence.directories = [ "/etc/sops" ];
virtualisation.vmVariantWithDisko.sops.age.sshKeyPaths = [ "/tmp/shared/sops_ed25519_key" ];
};
}
+19 -2
View File
@@ -9,7 +9,24 @@ in
enable = mkEnableOption "ssh"; enable = mkEnableOption "ssh";
}; };
config = mkIf cfg.enable { config = mkIf cfg.enable {
services.openssh.enable = true; services.openssh = {
# TODO: Is this default configuration secure? enable = true;
settings = {
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
PermitRootLogin = "no";
};
hostKeys = mkIf (config.modules.impermanence.enable) [
{
type = "ed25519";
path = "/persist/system/etc/ssh/ssh_host_ed25519_key";
}
{
type = "rsa";
bits = 4096;
path = "/persist/system/etc/ssh/ssh_host_rsa_key";
}
];
};
}; };
} }
+10 -1
View File
@@ -3,6 +3,8 @@
disk = { disk = {
main = { main = {
type = "disk"; type = "disk";
device = "/dev/sda";
imageSize = "32G"; # For test VMs
content = { content = {
type = "gpt"; type = "gpt";
partitions = { partitions = {
@@ -17,12 +19,19 @@
}; };
}; };
zfs = { zfs = {
size = "100%"; end = "-4G";
content = { content = {
type = "zfs"; type = "zfs";
pool = "tank"; pool = "tank";
}; };
}; };
swap = {
size = "100%";
content = {
type = "swap";
discardPolicy = "both";
};
};
}; };
}; };
}; };
+2 -1
View File
@@ -24,7 +24,6 @@ in
freecad-wayland freecad-wayland
inkscape inkscape
ente-auth ente-auth
bitwarden
carla carla
winbox winbox
whatsapp-for-linux whatsapp-for-linux
@@ -39,6 +38,7 @@ in
prismlauncher prismlauncher
foliate foliate
wireshark wireshark
obsidian
]; ];
modules = { modules = {
@@ -61,6 +61,7 @@ in
"flake.lock" "flake.lock"
]; ];
}; };
bitwarden.enable = true;
xpra = { xpra = {
enable = true; enable = true;
hosts = [ hosts = [
+10 -5
View File
@@ -1,5 +1,4 @@
{ {
mkModule,
pkgs, pkgs,
lib, lib,
config, config,
@@ -20,13 +19,19 @@ in
bootloader.enable = mkDefault true; bootloader.enable = mkDefault true;
ssh.enable = mkDefault true; ssh.enable = mkDefault true;
# Setup sensible default persistent data
impermanence.directories = [ impermanence.directories = [
"/var/lib/nixos" "/var/lib/nixos"
]; ];
impermanence.files = [
"/etc/shadow" # TODO: Remove the secrets module and use sops directly?
]; secrets = {
enable = true;
secrets = {
"ssh-keys/deploy-priv" = {
path = "/root/.ssh/id_ed25519";
};
};
};
}; };
# Localization # Localization
+36 -15
View File
@@ -1,5 +1,4 @@
{ {
mkModule,
pkgs, pkgs,
lib, lib,
config, config,
@@ -30,17 +29,50 @@ in
zfs rollback -r tank/root@blank zfs rollback -r tank/root@blank
''; '';
}; };
domain = {
enable = true;
join = {
userFile = config.sops.secrets."vm-join/user".path;
passwordFile = config.sops.secrets."vm-join/password".path;
domainOUFile = config.sops.secrets."vm-join/ou".path;
};
};
ssh.enable = true; ssh.enable = true;
}; };
# Admin users # Initialize domain join secrets
sops.secrets."vm-join/user" = { };
sops.secrets."vm-join/password" = { };
sops.secrets."vm-join/ou" = { };
# Autologin to root for access from hypervisor
services.getty.autologinUser = "root";
# Local user
modules.secrets.secrets."passwords/local-hashed".neededForUsers = true;
users.mutableUsers = false;
users.users.local = { users.users.local = {
initialPassword = "local"; isNormalUser = true;
group = "local";
hashedPasswordFile = config.sops.secrets."passwords/local-hashed".path;
extraGroups = [ "wheel" ]; extraGroups = [ "wheel" ];
openssh.authorizedKeys.keys = [ openssh.authorizedKeys.keys = [
"ssh-ed25519 jan@bulthuis.dev" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKKxoQSxfYqf9ITN8Fhckk8WbY4dwtBAXOhC9jxihJvq Admin"
]; ];
}; };
users.groups.local = { };
home-manager.users.local =
{ ... }:
{
home.stateVersion = "24.11";
modules.profiles.base.enable = true;
};
# System packages
environment.systemPackages = with pkgs; [
# TODO: Make module for utilities/scripts
(writeShellScriptBin "system-update" "nixos-rebuild switch --flake git+https://git.bulthuis.dev/Jan/nixos-config")
];
# Enable qemu guest agent # Enable qemu guest agent
services.qemuGuest.enable = true; services.qemuGuest.enable = true;
@@ -61,17 +93,6 @@ in
"sd_mod" "sd_mod"
"sr_mod" "sr_mod"
]; ];
boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-intel" ]; boot.kernelModules = [ "kvm-intel" ];
boot.extraModulePackages = [ ];
hardware.cpu.intel.updateMicrocode = true;
# Swapfile
swapDevices = [
{
device = "/var/lib/swapfile";
size = 6 * 1024;
}
];
}; };
} }