84 lines
2.9 KiB
Nix
84 lines
2.9 KiB
Nix
{
|
||
config,
|
||
pkgs,
|
||
...
|
||
}: {
|
||
boot.loader.grub.enable = true;
|
||
boot.loader.grub.version = 2;
|
||
boot.loader.grub.device = "/dev/sda";
|
||
|
||
networking.hostId = "94d2a920";
|
||
networking.hostName = "cornu-aspersum";
|
||
networking.interfaces.ens3.useDHCP = true;
|
||
|
||
settings.ssh.openOutsideVPN = true;
|
||
|
||
users.users = {
|
||
root = {
|
||
hashedPassword = "$6$Yb1gdlKIpY1hRW1X$uUcNFuNnK2JFFN55Tkc.fPV.4I7RJvIfLEQayVP1utfkmjF0f/EHjtypxq11jR5NUUIJFQLW6ffajjduA2689.";
|
||
};
|
||
};
|
||
|
||
sops.defaultSopsFile = ../secrets/hosts/cornu-aspersum/secrets.yaml;
|
||
sops.age.sshKeyPaths = ["/etc/ssh/ssh_host_ed25519_key"];
|
||
|
||
sops.secrets.gladosEnv = {};
|
||
services.glados = {
|
||
enable = true;
|
||
dataCollector.enable = true;
|
||
envFile = config.sops.secrets.gladosEnv.path;
|
||
};
|
||
|
||
# Run grafana, mainly for ccqcraft.de
|
||
services.grafanaWithNginx.enable = true;
|
||
|
||
# Run radicale with infcloud interface for me and Marie
|
||
services.radicaleWithInfcloud.enable = true;
|
||
|
||
systemd.services.glados.serviceConfig.SupplementaryGroups = [config.users.groups.keys.name];
|
||
|
||
services.qemuGuest.enable = true;
|
||
|
||
services.bind = {
|
||
enable = true;
|
||
cacheNetworks = ["any"];
|
||
forwarders = ["100.100.100.100"];
|
||
listenOn = ["any"];
|
||
listenOnIpv6 = ["any"];
|
||
zones."home" = {
|
||
master = true;
|
||
# TODO: Fix TTLs
|
||
file = pkgs.writeText "home-zone" ''
|
||
$TTL 1
|
||
@ IN SOA home. malte.home. (
|
||
5 ; Serial
|
||
1 ; Refresh
|
||
1 ; Retry
|
||
1 ; Expire
|
||
1) ; Negative Cache TTL
|
||
@ NS home.
|
||
home. AAAA fd7a:115c:a1e0:ab12:4843:cd96:6256:2a6e
|
||
home. A 100.86.42.110
|
||
foto CNAME elysia-clarki.maltet.github.beta.tailscale.net.
|
||
hydra CNAME elysia-clarki.maltet.github.beta.tailscale.net.
|
||
mc CNAME cornu-aspersum.maltet.github.beta.tailscale.net.
|
||
doc CNAME faunus-ater.maltet.github.beta.tailscale.net.
|
||
sheet CNAME faunus-ater.maltet.github.beta.tailscale.net.
|
||
media CNAME faunus-ater.maltet.github.beta.tailscale.net.
|
||
file CNAME faunus-ater.maltet.github.beta.tailscale.net.
|
||
stats CNAME faunus-ater.maltet.github.beta.tailscale.net.
|
||
'';
|
||
};
|
||
};
|
||
networking.firewall.allowedTCPPorts = [53];
|
||
networking.firewall.allowedUDPPorts = [53];
|
||
|
||
# This value determines the NixOS release from which the default
|
||
# settings for stateful data, like file locations and database versions
|
||
# on your system were taken. It‘s perfectly fine and recommended to leave
|
||
# this value at the release version of the first install of this system.
|
||
# Before changing this value read the documentation for this option
|
||
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
|
||
system.stateVersion = "21.05"; # Did you read the comment?
|
||
}
|