Compare commits

...
25 Commits
Author SHA1 Message Date
Jan-Bulthuis 68c241f31a Changed location of some persistence files 2025-05-29 18:32:08 +02:00
Jan-Bulthuis 81c37abadd Fixed impermanence not mounting persist 2025-05-29 17:05:15 +02:00
Jan-Bulthuis 85c962fd6d Updated REAME.md 2025-05-29 17:04:58 +02:00
Jan-Bulthuis b0a8874a93 Set up impermanence 2025-05-29 16:34:24 +02:00
Jan-Bulthuis 01021d179d Fixed hold command 2025-05-29 15:49:24 +02:00
Jan-Bulthuis b8a607c3d0 Fixed hold command 2025-05-29 15:31:46 +02:00
Jan-Bulthuis 793015646d Updated base vm config 2025-05-29 15:10:10 +02:00
Jan-Bulthuis 43f472fe88 Fixed reference to incorrect zfs pool 2025-05-29 14:36:07 +02:00
Jan-Bulthuis 51ab89cd98 Better disko setup 2025-05-29 14:19:19 +02:00
Jan-Bulthuis f0d56df191 Addid disko config for zfs 2025-05-29 13:06:13 +02:00
Jan-Bulthuis 9a97168950 Moved profiles to dedicated directory 2025-05-29 12:16:38 +02:00
Jan-Bulthuis cdffa07675 Reenable timeout 2025-05-29 09:59:09 +02:00
Jan-Bulthuis 13fbcea361 Disabled https 2025-05-28 19:26:11 +02:00
Jan-Bulthuis 36c2c907d5 Fixed tls private key file name 2025-05-28 16:46:25 +02:00
Jan-Bulthuis 11bc7221e3 Added batch flag 2025-05-28 16:39:52 +02:00
Jan-Bulthuis 3a6122784b Generate self-signed tls for wstunnel 2025-05-28 16:35:59 +02:00
Jan-Bulthuis d4338f1861 Added local to the minecraft group 2025-05-28 16:15:38 +02:00
Jan-Bulthuis ea290d9158 Install tmux 2025-05-28 16:13:49 +02:00
Jan-Bulthuis 9cc07cdfaf Created a minecraft server vm 2025-05-28 15:59:22 +02:00
Jan-Bulthuis 33b9cee6a0 Installed wireshark 2025-05-28 15:59:13 +02:00
Jan-Bulthuis 47479f40d1 Installed wireshark 2025-05-28 15:58:52 +02:00
Jan-Bulthuis e1cc2342b2 Added certificates back in 2025-05-28 14:12:00 +02:00
Jan-Bulthuis 092b3551c1 Remove tls certificates 2025-05-28 14:06:31 +02:00
Jan-Bulthuis 9d50a66388 Set up admin user 2025-05-28 13:59:30 +02:00
Jan-Bulthuis 4a644607c6 Restructured glue 2025-05-28 13:39:00 +02:00
21 changed files with 478 additions and 222 deletions

No files matched your search

+6 -2
View File
@@ -2,6 +2,10 @@
My NixOS configuration. My NixOS configuration.
## Usage ## Installation
Clone the repository to some directory. And build with `sudo nixos-rebuild switch --flake /directory/containing/flake.nix/`. For disk configuration we use disko, this means that installing the system from the configuration is just a single command:
```
sudo nix --experimental-features "nix-command flakes" run "github:nix-community/disko/latest#disko-install" -- --flake git+https://git.bulthuis.dev/Jan/dotfiles#<hostname> --disk main /dev/sda
```
Generated
+37 -12
View File
@@ -1,5 +1,25 @@
{ {
"nodes": { "nodes": {
"disko": {
"inputs": {
"nixpkgs": [
"nixpkgs"
]
},
"locked": {
"lastModified": 1748225455,
"narHash": "sha256-AzlJCKaM4wbEyEpV3I/PUq5mHnib2ryEy32c+qfj6xk=",
"owner": "nix-community",
"repo": "disko",
"rev": "a894f2811e1ee8d10c50560551e50d6ab3c392ba",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "disko",
"type": "github"
}
},
"flake-compat": { "flake-compat": {
"flake": false, "flake": false,
"locked": { "locked": {
@@ -34,17 +54,6 @@
"type": "github" "type": "github"
} }
}, },
"glue": {
"locked": {
"path": "./glue",
"type": "path"
},
"original": {
"path": "./glue",
"type": "path"
},
"parent": []
},
"home-manager": { "home-manager": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
@@ -65,6 +74,21 @@
"type": "github" "type": "github"
} }
}, },
"impermanence": {
"locked": {
"lastModified": 1737831083,
"narHash": "sha256-LJggUHbpyeDvNagTUrdhe/pRVp4pnS6wVKALS782gRI=",
"owner": "nix-community",
"repo": "impermanence",
"rev": "4b3e914cdf97a5b536a889e939fb2fd2b043a170",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "impermanence",
"type": "github"
}
},
"nix-minecraft": { "nix-minecraft": {
"inputs": { "inputs": {
"flake-compat": "flake-compat", "flake-compat": "flake-compat",
@@ -125,8 +149,9 @@
}, },
"root": { "root": {
"inputs": { "inputs": {
"glue": "glue", "disko": "disko",
"home-manager": "home-manager", "home-manager": "home-manager",
"impermanence": "impermanence",
"nix-minecraft": "nix-minecraft", "nix-minecraft": "nix-minecraft",
"nix-modpack": "nix-modpack", "nix-modpack": "nix-modpack",
"nixpkgs": "nixpkgs" "nixpkgs": "nixpkgs"
+7 -2
View File
@@ -2,15 +2,20 @@
description = "System configuration for NixOS"; description = "System configuration for NixOS";
inputs = { inputs = {
glue.url = "./glue"; # General inputs
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable"; nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
home-manager.url = "github:nix-community/home-manager"; home-manager.url = "github:nix-community/home-manager";
home-manager.inputs.nixpkgs.follows = "nixpkgs"; home-manager.inputs.nixpkgs.follows = "nixpkgs";
disko.url = "github:nix-community/disko";
disko.inputs.nixpkgs.follows = "nixpkgs";
impermanence.url = "github:nix-community/impermanence";
# For Minecraft VM
nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft"; nix-minecraft.url = "github:Jan-Bulthuis/nix-minecraft";
nix-minecraft.inputs.nixpkgs.follows = "nixpkgs"; nix-minecraft.inputs.nixpkgs.follows = "nixpkgs";
nix-modpack.url = "github:Jan-Bulthuis/nix-modpack"; nix-modpack.url = "github:Jan-Bulthuis/nix-modpack";
nix-modpack.inputs.nixpkgs.follows = "nixpkgs"; nix-modpack.inputs.nixpkgs.follows = "nixpkgs";
}; };
outputs = inputs: inputs.glue inputs; outputs = inputs: import ./glue inputs;
} }
+170
View File
@@ -0,0 +1,170 @@
inputs:
let
flake = inputs.self;
nixpkgs = inputs.nixpkgs;
lib = nixpkgs.lib;
importDir =
path: fn:
let
entries = builtins.readDir path;
# Get paths to directories
dirs = lib.filterAttrs (_: type: type == "directory") entries;
dirPaths = lib.mapAttrs (name: type: {
path = "${path}/${name}";
type = type;
}) dirs;
# Get paths to nix files
nixName = name: builtins.match "(.*)\\.nix" name;
files = lib.filterAttrs (name: type: (type != "directory") && ((nixName name) != null)) entries;
filePaths = lib.mapAttrs' (name: type: {
name = builtins.head (nixName name);
value = {
path = "${path}/${name}";
type = type;
};
}) files;
combined = dirPaths // filePaths;
in
fn (lib.optionalAttrs (builtins.pathExists path) combined);
# Split out into getNixFiles, getNixFilesRecursive, getDirs
importDirRecursive =
path: fn:
let
entries = importDir path lib.id;
# Dig down recursively
dirs = lib.filterAttrs (_: entry: entry.type == "directory") entries;
recursedEntries = lib.mapAttrs (name: entry: (importDirRecursive entry.path lib.id)) dirs;
in
fn (entries // recursedEntries);
eachSystem = fn: lib.genAttrs lib.systems.flakeExposed fn;
systemArgs = eachSystem (system: {
pkgs = (
import inputs.nixpkgs {
inherit system;
}
);
});
allPackages = importDir "${flake}/packages" (
attrs:
lib.mapAttrs (
name: entry: (if entry.type == "directory" then "${entry.path}/default.nix" else entry.path)
) attrs
);
packages =
let
# TODO: Filter out packages that are not supported on the platform?
mkPackages =
system:
let
args = systemArgs."${system}";
pkgs = args.pkgs;
in
lib.mapAttrs (name: package: pkgs.callPackage package { }) allPackages;
in
eachSystem mkPackages;
overlay = final: prev: (lib.mapAttrs (name: package: prev.callPackage package { }) allPackages);
collectEntries =
attrs:
lib.attrsets.collect (
entry: (lib.isAttrs entry) && (lib.hasAttr "path" entry) && (lib.hasAttr "type" entry)
) attrs;
collectModules =
path:
importDirRecursive path (
attrs:
map (entry: if entry.type == "directory" then entry.path + "/default.nix" else entry.path) (
collectEntries attrs
)
);
nixosModules = collectModules "${flake}/modules/nixos";
nixosProfiles = collectModules "${flake}/profiles/nixos";
inputNixosModules = lib.map (flake: flake.outputs.nixosModules.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "nixosModules" "default" ] flake) (
lib.attrValues inputs
)
);
homeModules = collectModules "${flake}/modules/home";
homeProfiles = collectModules "${flake}/profiles/home";
inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) (
lib.attrValues inputs
)
);
inputOverlays = lib.map (flake: flake.outputs.overlays.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "overlays" "default" ] flake) (
lib.attrValues inputs
)
);
overlayModule =
{ ... }:
{
nixpkgs.overlays = [ overlay ] ++ inputOverlays;
};
nixosConfigurations = importDir "${flake}/hosts" (
attrs:
lib.mapAttrs (
name: entry:
lib.nixosSystem {
specialArgs = {
inherit inputs;
};
modules =
let
systemPath = "${entry.path}/configuration.nix";
userEntries = importDir "${entry.path}/users" lib.id;
usersConfiguration = lib.mapAttrs (name: entry: {
isNormalUser = true;
group = name;
}) userEntries;
groupsConfiguration = lib.mapAttrs (name: entry: {
}) userEntries;
homesConfiguration = lib.mapAttrs (name: entry: entry.path) userEntries;
usersModule =
{ ... }:
{
home-manager.sharedModules = homeModules ++ homeProfiles ++ inputHomeModules;
home-manager.useUserPackages = false; # TODO: See if this should be changed to true?
home-manager.useGlobalPkgs = true;
home-manager.users = homesConfiguration;
users.users = usersConfiguration;
users.groups = groupsConfiguration;
};
in
[
systemPath
overlayModule
usersModule
]
++ nixosModules
++ nixosProfiles
++ inputNixosModules;
}
) (lib.attrsets.filterAttrs (name: entry: entry.type == "directory") attrs)
);
in
{
inherit packages nixosConfigurations overlay;
overlays.default = overlay;
}
-14
View File
@@ -1,14 +0,0 @@
{
description = "Some glue";
inputs = { };
outputs =
inputs:
let
glue = import ./lib { inherit inputs; };
in
{
__functor = _: glue;
};
}
-173
View File
@@ -1,173 +0,0 @@
{ ... }:
let
mkGlue =
inputs:
let
flake = inputs.self;
nixpkgs = inputs.nixpkgs;
lib = nixpkgs.lib;
importDir =
path: fn:
let
entries = builtins.readDir path;
# Get paths to directories
dirs = lib.filterAttrs (_: type: type == "directory") entries;
dirPaths = lib.mapAttrs (name: type: {
path = "${path}/${name}";
type = type;
}) dirs;
# Get paths to nix files
nixName = name: builtins.match "(.*)\\.nix" name;
files = lib.filterAttrs (name: type: (type != "directory") && ((nixName name) != null)) entries;
filePaths = lib.mapAttrs' (name: type: {
name = builtins.head (nixName name);
value = {
path = "${path}/${name}";
type = type;
};
}) files;
combined = dirPaths // filePaths;
in
fn (lib.optionalAttrs (builtins.pathExists path) combined);
# Split out into getNixFiles, getNixFilesRecursive, getDirs
importDirRecursive =
path: fn:
let
entries = importDir path lib.id;
# Dig down recursively
dirs = lib.filterAttrs (_: entry: entry.type == "directory") entries;
recursedEntries = lib.mapAttrs (name: entry: (importDirRecursive entry.path lib.id)) dirs;
in
fn (entries // recursedEntries);
eachSystem = fn: lib.genAttrs lib.systems.flakeExposed fn;
systemArgs = eachSystem (system: {
pkgs = (
import inputs.nixpkgs {
inherit system;
}
);
});
allPackages = importDir "${flake}/packages" (
attrs:
lib.mapAttrs (
name: entry: (if entry.type == "directory" then "${entry.path}/default.nix" else entry.path)
) attrs
);
packages =
let
# TODO: Filter out packages that are not supported on the platform?
mkPackages =
system:
let
args = systemArgs."${system}";
pkgs = args.pkgs;
in
lib.mapAttrs (name: package: pkgs.callPackage package { }) allPackages;
in
eachSystem mkPackages;
overlay = final: prev: (lib.mapAttrs (name: package: prev.callPackage package { }) allPackages);
collectEntries =
attrs:
lib.attrsets.collect (
entry: (lib.isAttrs entry) && (lib.hasAttr "path" entry) && (lib.hasAttr "type" entry)
) attrs;
collectModules =
path:
importDirRecursive path (
attrs:
map (entry: if entry.type == "directory" then entry.path + "/default.nix" else entry.path) (
collectEntries attrs
)
);
nixosModules = collectModules "${flake}/modules/nixos";
inputNixosModules = lib.map (flake: flake.outputs.nixosModules.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "nixosModules" "default" ] flake) (
lib.attrValues inputs
)
);
homeModules = collectModules "${flake}/modules/home";
inputHomeModules = lib.map (flake: flake.outputs.homeManagerModules.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "homeManagerModules" "default" ] flake) (
lib.attrValues inputs
)
);
inputOverlays = lib.map (flake: flake.outputs.overlays.default) (
lib.filter (flake: lib.hasAttrByPath [ "outputs" "overlays" "default" ] flake) (
lib.attrValues inputs
)
);
overlayModule =
{ ... }:
{
nixpkgs.overlays = [ overlay ] ++ inputOverlays;
};
nixosConfigurations = importDir "${flake}/hosts" (
attrs:
lib.mapAttrs (
name: entry:
lib.nixosSystem {
specialArgs = {
inherit inputs;
};
modules =
let
systemPath = "${entry.path}/configuration.nix";
userEntries = importDir "${entry.path}/users" lib.id;
usersConfiguration = lib.mapAttrs (name: entry: {
isNormalUser = true;
group = name;
}) userEntries;
groupsConfiguration = lib.mapAttrs (name: entry: {
}) userEntries;
homesConfiguration = lib.mapAttrs (name: entry: entry.path) userEntries;
usersModule =
{ ... }:
{
home-manager.sharedModules = homeModules ++ inputHomeModules;
home-manager.useUserPackages = false; # TODO: See if this should be changed to true?
home-manager.useGlobalPkgs = true;
home-manager.users = homesConfiguration;
users.users = usersConfiguration;
users.groups = groupsConfiguration;
};
in
[
systemPath
overlayModule
usersModule
]
++ nixosModules
++ inputNixosModules;
}
) (lib.attrsets.filterAttrs (name: entry: entry.type == "directory") attrs)
);
in
{
inherit packages nixosConfigurations;
overlays.default = overlay;
};
in
mkGlue
+11 -1
View File
@@ -8,11 +8,21 @@
networking.hostName = "20212060"; networking.hostName = "20212060";
# Admin users # Admin users
users.users.jan.extraGroups = [ "wheel" ]; users.users.jan.extraGroups = [
"wheel"
"wireshark"
];
# Enable virtualisation for VMs # Enable virtualisation for VMs
virtualisation.libvirtd.enable = true; virtualisation.libvirtd.enable = true;
# Enable wireshark
programs.wireshark = {
enable = true;
dumpcap.enable = true;
usbmon.enable = true;
};
# Set up wstunnel client # Set up wstunnel client
services.wstunnel = { services.wstunnel = {
enable = true; enable = true;
+45
View File
@@ -0,0 +1,45 @@
{
lib,
pkgs,
config,
inputs,
...
}:
{
# State version
system.stateVersion = "24.11";
# Import the nix-minecraft modules
imports = [
inputs.nix-minecraft.nixosModules.minecraft-servers
];
# Machine hostname
networking.hostName = "vm-minecraft";
# Enabled modules
modules = {
profiles.vm.enable = true;
};
# Set up minecraft servers
users.users.local.extraGroups = [ "minecraft" ];
services.minecraft-servers = {
enable = true;
eula = true;
openFirewall = true;
servers = {
modpack = {
enable = true;
autoStart = true;
serverProperties = { };
package = inputs.nix-modpack.packages.${pkgs.system}.mkModpackServer {
packUrl = "https://raw.githubusercontent.com/Jan-Bulthuis/Modpack/refs/heads/master/pack.toml";
server = inputs.nix-minecraft.legacyPackages.${pkgs.system}.neoForgeServers.neoforge-20_1_106;
};
jvmOpts = "-Xms6144M -Xmx8192M";
};
};
};
}
+7
View File
@@ -0,0 +1,7 @@
{ ... }:
{
home.stateVersion = "24.11";
modules.profiles.base.enable = true;
}
+1 -3
View File
@@ -21,7 +21,7 @@
services.wstunnel = { services.wstunnel = {
enable = true; enable = true;
servers.wg-tunnel = { servers.wg-tunnel = {
enableHTTPS = true; enableHTTPS = false;
listen = { listen = {
host = "0.0.0.0"; host = "0.0.0.0";
port = 8080; port = 8080;
@@ -32,8 +32,6 @@
port = 51820; port = 51820;
} }
]; ];
tlsCertificate = "/var/lib/secrets/fullchain.pem";
tlsKey = "/var/lib/secrets/key.pem";
}; };
}; };
networking.firewall = { networking.firewall = {
+35
View File
@@ -0,0 +1,35 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.impermanence;
in
{
options.modules.impermanence = {
enable = mkEnableOption "Impermanence";
directories = mkOption {
type = types.listOf types.str;
default = [ ];
description = ''
Directories that should be stored in persistent storage.
'';
};
files = mkOption {
type = types.listOf types.str;
default = [ ];
description = ''
Files that should be stored in persistent storage.
'';
};
};
config = mkIf cfg.enable {
home.persistence."/persist/home/${config.home.username}" = {
enable = true;
hideMounts = true;
allowOther = true;
directories = cfg.directories;
files = cfg.files;
};
};
}
+24
View File
@@ -0,0 +1,24 @@
{
lib,
config,
inputs,
...
}:
with lib;
let
cfg = config.modules.disko;
profile = import "${inputs.self}/profiles/disko/${cfg.profile}.nix";
in
{
options.modules.disko = {
enable = mkEnableOption "Disko module";
profile = mkOption {
type = types.str;
default = null;
description = "The profile to use for the disko module.";
};
};
config = mkIf cfg.enable { disko.devices = profile.disko.devices; };
}
+46
View File
@@ -0,0 +1,46 @@
{ lib, config, ... }:
with lib;
let
cfg = config.modules.impermanence;
in
{
options.modules.impermanence = {
enable = mkEnableOption "Impermanence";
directories = mkOption {
type = types.listOf types.str;
default = [ ];
description = ''
Directories that should be stored in persistent storage.
'';
};
files = mkOption {
type = types.listOf types.str;
default = [ ];
description = ''
Files that should be stored in persistent storage.
'';
};
resetScript = mkOption {
type = types.lines;
description = ''
Script to run on boot that resets the root partition.
'';
};
};
config = mkIf cfg.enable {
fileSystems."/persist".neededForBoot = true;
boot.initrd.postResumeCommands = mkAfter cfg.resetScript;
# For home-manager persistence
programs.fuse.userAllowOther = true;
environment.persistence."/persist/system" = {
enable = true;
hideMounts = true;
directories = cfg.directories;
files = cfg.files;
};
};
}
+56
View File
@@ -0,0 +1,56 @@
{
disko.devices = {
disk = {
main = {
type = "disk";
content = {
type = "gpt";
partitions = {
boot = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
zfs = {
size = "100%";
content = {
type = "zfs";
pool = "tank";
};
};
};
};
};
};
zpool = {
tank = {
type = "zpool";
rootFsOptions = {
compression = "zstd";
};
mountpoint = null;
postCreateHook = "zfs snapshot -r tank@blank && zfs hold -r blank tank@blank";
datasets = {
root = {
type = "zfs_fs";
mountpoint = "/";
};
nix = {
type = "zfs_fs";
mountpoint = "/nix";
};
persist = {
type = "zfs_fs";
mountpoint = "/persist";
};
};
};
};
};
}
File renamed without changes.
File renamed without changes.
@@ -38,6 +38,7 @@ in
bottles bottles
prismlauncher prismlauncher
foliate foliate
wireshark
]; ];
modules = { modules = {
@@ -19,6 +19,14 @@ in
modules = { modules = {
bootloader.enable = mkDefault true; bootloader.enable = mkDefault true;
ssh.enable = mkDefault true; ssh.enable = mkDefault true;
# Setup sensible default persistent data
impermanence.directories = [
"/var/lib/nixos"
];
impermanence.files = [
"/etc/shadow"
];
}; };
# Localization # Localization
@@ -56,6 +64,7 @@ in
pciutils pciutils
zip zip
unzip unzip
tmux
]; ];
}; };
} }
File renamed without changes.
File renamed without changes.
@@ -19,15 +19,38 @@ in
# Enabled modules # Enabled modules
modules = { modules = {
profiles.base.enable = true; profiles.base.enable = true;
disko = {
enable = true;
profile = "vm";
};
impermanence = {
enable = true;
resetScript = ''
# Revert to the blank state for the root directory
zfs rollback -r tank/root@blank
'';
};
ssh.enable = true; ssh.enable = true;
}; };
# Admin users
users.users.local = {
initialPassword = "local";
extraGroups = [ "wheel" ];
openssh.authorizedKeys.keys = [
"ssh-ed25519 jan@bulthuis.dev"
];
};
# Enable qemu guest agent # Enable qemu guest agent
services.qemuGuest.enable = true; services.qemuGuest.enable = true;
# Machine platform # Machine platform
nixpkgs.hostPlatform = "x86_64-linux"; nixpkgs.hostPlatform = "x86_64-linux";
# Set hostid for ZFS
networking.hostId = "deadbeef";
# Hardware configuration # Hardware configuration
hardware.enableRedistributableFirmware = true; hardware.enableRedistributableFirmware = true;
boot.initrd.availableKernelModules = [ boot.initrd.availableKernelModules = [
@@ -43,21 +66,6 @@ in
boot.extraModulePackages = [ ]; boot.extraModulePackages = [ ];
hardware.cpu.intel.updateMicrocode = true; hardware.cpu.intel.updateMicrocode = true;
# Filesystems
fileSystems."/" = {
device = "/dev/disk/by-partlabel/root";
fsType = "ext4";
};
fileSystems."/boot" = {
device = "/dev/disk/by-partlabel/EFI";
fsType = "vfat";
options = [
"fmask=0077"
"dmask=0077"
];
};
# Swapfile # Swapfile
swapDevices = [ swapDevices = [
{ {