diff --git a/flake.lock b/flake.lock index e0917c1..03b20b1 100644 --- a/flake.lock +++ b/flake.lock @@ -8,11 +8,11 @@ "systems": "systems" }, "locked": { - "lastModified": 1762618334, - "narHash": "sha256-wyT7Pl6tMFbFrs8Lk/TlEs81N6L+VSybPfiIgzU8lbQ=", + "lastModified": 1770165109, + "narHash": "sha256-9VnK6Oqai65puVJ4WYtCTvlJeXxMzAp/69HhQuTdl/I=", "owner": "ryantm", "repo": "agenix", - "rev": "fcdea223397448d35d9b31f798479227e80183f6", + "rev": "b027ee29d959fda4b60b57566d64c98a202e0feb", "type": "github" }, "original": { @@ -65,11 +65,11 @@ "nixpkgs": "nixpkgs_3" }, "locked": { - "lastModified": 1769889994, - "narHash": "sha256-uEn3WcpPHe3sMJMgIJ0XW3f4/+TRzZpNgv4vu5/gjmA=", + "lastModified": 1779822991, + "narHash": "sha256-r6e4eHEyQJEDhT6gkW3B9+OgB0pZebw2+du4bvN3vww=", "owner": "9001", "repo": "copyparty", - "rev": "9b436eb52e5cfe7a0a8e59dd9f1a37351f3a2abd", + "rev": "6e75faa62349a59f4df328a4939ba8626d89ee1a", "type": "github" }, "original": { @@ -107,11 +107,11 @@ ] }, "locked": { - "lastModified": 1769524058, - "narHash": "sha256-zygdD6X1PcVNR2PsyK4ptzrVEiAdbMqLos7utrMDEWE=", + "lastModified": 1780290312, + "narHash": "sha256-eTAlX0CwgB84Ts3GaBd944A3DRXVMzgA0EqroZBISUo=", "owner": "nix-community", "repo": "disko", - "rev": "71a3fc97d80881e91710fe721f1158d3b96ae14d", + "rev": "115e5211780054d8a890b41f0b7734cafad54dfe", "type": "github" }, "original": { @@ -155,15 +155,15 @@ "flake-compat_3": { "flake": false, "locked": { - "lastModified": 1761588595, - "narHash": "sha256-XKUZz9zewJNUj46b4AJdiRZJAvSZ0Dqj2BNfXvFlJC4=", - "owner": "edolstra", + "lastModified": 1767039857, + "narHash": "sha256-vNpUSpF5Nuw8xvDLj2KCwwksIbjua2LZCqhV1LNRDns=", + "owner": "NixOS", "repo": "flake-compat", - "rev": "f387cd2afec9419c8ee37694406ca490c3f34ee5", + "rev": "5edf11c44bc78a0d334f6334cdaf7d60d732daab", "type": "github" }, "original": { - "owner": "edolstra", + "owner": "NixOS", "repo": "flake-compat", "type": "github" } @@ -211,11 +211,11 @@ ] }, "locked": { - "lastModified": 1763988335, - "narHash": "sha256-QlcnByMc8KBjpU37rbq5iP7Cp97HvjRP0ucfdh+M4Qc=", + "lastModified": 1778507602, + "narHash": "sha256-kTwur1wV+01SdqskVMSo6JMEpg71ps3HpbFY2GsflKs=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "50b9238891e388c9fdc6a5c49e49c42533a1b5ce", + "rev": "61ab0e80d9c7ab14c256b5b453d8b3fb0189ba0a", "type": "github" }, "original": { @@ -295,11 +295,11 @@ "systems": "systems_2" }, "locked": { - "lastModified": 1770000653, - "narHash": "sha256-QO/twGynxjOSUDtxbqJLshc/Q5/wImLH5O6KV2p9eoE=", + "lastModified": 1780375694, + "narHash": "sha256-TznzgYVONg28KiSFB2rVdf/eLVIMtEQOxKt13Kzyrp8=", "owner": "Infinidoge", "repo": "nix-minecraft", - "rev": "6a2ddb643aaf7949caa6158e718c5efc3dda7dc1", + "rev": "e6f8bec35104ca5955efe73742da58d2823684f7", "type": "github" }, "original": { @@ -324,6 +324,22 @@ "type": "github" } }, + "nixpkgs-2505": { + "locked": { + "lastModified": 1767313136, + "narHash": "sha256-16KkgfdYqjaeRGBaYsNrhPRRENs0qzkQVUooNHtoy2w=", + "owner": "nixos", + "repo": "nixpkgs", + "rev": "ac62194c3917d5f474c1a844b6fd6da2db95077d", + "type": "github" + }, + "original": { + "owner": "nixos", + "ref": "nixos-25.05", + "repo": "nixpkgs", + "type": "github" + } + }, "nixpkgs_2": { "locked": { "lastModified": 1750134718, @@ -373,16 +389,16 @@ }, "nixpkgs_5": { "locked": { - "lastModified": 1770136044, - "narHash": "sha256-tlFqNG/uzz2++aAmn4v8J0vAkV3z7XngeIIB3rM3650=", + "lastModified": 1780203844, + "narHash": "sha256-K5sT4jTpGs15ADhviMKNBH38REpPf5Q6mM1+N6cArVE=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "e576e3c9cf9bad747afcddd9e34f51d18c855b4e", + "rev": "b51242d7d43689db2f3be91bd05d5b24fbb469c4", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-25.11", + "ref": "nixos-26.05", "repo": "nixpkgs", "type": "github" } @@ -403,11 +419,11 @@ }, "nixpkgs_7": { "locked": { - "lastModified": 1764374374, - "narHash": "sha256-naS7hg/D1yLKSZoENx9gvsPLFiNEOTcqamJSu0OEvCA=", + "lastModified": 1779630130, + "narHash": "sha256-RWn/gMXEy+p6yL5lKh51Z/w6RHC+5Px18Tarkuva99Y=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "6a49303095abc094ee77dc243a9e351b642e8e75", + "rev": "68ac0b94b449482d8a90f3e3791d61a8ee186f07", "type": "github" }, "original": { @@ -441,6 +457,7 @@ "disko": "disko", "nix-minecraft": "nix-minecraft", "nixpkgs": "nixpkgs_5", + "nixpkgs-2505": "nixpkgs-2505", "shoblog-front": "shoblog-front", "simple-mailserver": "simple-mailserver", "testing-grounds": "testing-grounds", @@ -473,11 +490,11 @@ "nixpkgs": "nixpkgs_7" }, "locked": { - "lastModified": 1766321686, - "narHash": "sha256-icOWbnD977HXhveirqA10zoqvErczVs3NKx8Bj+ikHY=", + "lastModified": 1780340963, + "narHash": "sha256-rQCWOQXN0/sQxwP7T2Y3hsC1KYxLQgul6l9LPbQdqi4=", "owner": "simple-nixos-mailserver", "repo": "nixos-mailserver", - "rev": "7d433bf89882f61621f95082e90a4ab91eb0bdd3", + "rev": "a61228e6918a9d673c3faf48ab23e92a55822012", "type": "gitlab" }, "original": { @@ -552,16 +569,15 @@ }, "unstable": { "locked": { - "lastModified": 1769789167, - "narHash": "sha256-kKB3bqYJU5nzYeIROI82Ef9VtTbu4uA3YydSk/Bioa8=", + "lastModified": 1780651739, + "narHash": "sha256-3VfA5BcsITQmorkCW/6ZF9usmLTkFTAfTj4QT7DG338=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "62c8382960464ceb98ea593cb8321a2cf8f9e3e5", + "rev": "e91830af5eb4b2394ddd405998dec32f0ef18a51", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-unstable", "repo": "nixpkgs", "type": "github" } diff --git a/flake.nix b/flake.nix index e3b92cc..96c04ff 100644 --- a/flake.nix +++ b/flake.nix @@ -3,8 +3,9 @@ # Flake inputs inputs = { - nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11"; - unstable.url = "github:NixOS/nixpkgs/nixos-unstable"; + nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05"; + nixpkgs-2505.url = "github:nixos/nixpkgs/nixos-25.05"; + unstable.url = "github:NixOS/nixpkgs"; colmena.url = "github:zhaofengli/colmena"; # commons @@ -81,22 +82,22 @@ }; }; thea = nixpkgs.lib.nixosSystem { - system = "x86_64-linux"; + system = "x86_64-linux"; - modules = [ - agenix.nixosModules.default - ./hosts/thea/configuration.nix - ./hosts/thea/hardware-configuration.nix - ] - ++ [ - # modules - ./modules/gitea/thea - ]; + modules = [ + agenix.nixosModules.default + ./hosts/thea/configuration.nix + ./hosts/thea/hardware-configuration.nix + ] + ++ [ + # modules + ./modules/gitea/thea + ]; - specialArgs = { - inherit inputs; - nodes = {inherit sin;}; - }; + specialArgs = { + inherit inputs; + nodes = { inherit sin; }; + }; }; }; colmenaHive = colmena.lib.makeHive { @@ -175,7 +176,7 @@ env = { }; # Add any shell logic you want executed any time the environment is activated - shellHook = ''''; + shellHook = ""; }; } ); diff --git a/hosts/sin/actual.nix b/hosts/sin/actual.nix new file mode 100644 index 0000000..4ef6e69 --- /dev/null +++ b/hosts/sin/actual.nix @@ -0,0 +1,12 @@ +{ inputs, pkgs, ... }: +let + unstable = import inputs.unstable { system = pkgs.stdenv.system; }; +in +{ + services.actual = { + package = unstable.actual-server; + enable = true; + openFirewall = true; + settings.port = 3001; + }; +} diff --git a/hosts/sin/configuration.nix b/hosts/sin/configuration.nix index 2404e01..e1a4568 100644 --- a/hosts/sin/configuration.nix +++ b/hosts/sin/configuration.nix @@ -18,6 +18,7 @@ ./coredns ./copyparty.nix ./trilium.nix + ./actual.nix ]; boot.initrd.kernelModules = [ "usb_storage" ]; diff --git a/hosts/sin/copyparty.nix b/hosts/sin/copyparty.nix index 541359b..c622f36 100644 --- a/hosts/sin/copyparty.nix +++ b/hosts/sin/copyparty.nix @@ -15,8 +15,8 @@ settings = { p = [ 8086 ]; - e2dsa = true; - e2ts = true; + e2dsa = true; # files indexing + e2ts = true; # multimedia indexing z = true; qr = true; xff-hdr = "X-Real-IP"; @@ -25,6 +25,13 @@ http-only = true; og = true; shr = "/shares"; + ansi = true; # color in log messages + re-maxage = 60 * 60 * 12; # reindex every 12h + + # idp-h-usr = "remote-user"; + # idp-h-grp = "remote-group"; + # idp-login = "https://auth.shobu.fr/?rd=https://files.shobu.fr"; + # idp-logout = "https://auth.shobu.fr/"; }; accounts = { @@ -54,9 +61,9 @@ }; }; "/mediacenter" = { - path = "/mnt/mediacenter/media"; + path = "/mnt/mediacenter/"; access = { - rw = ["serhao"]; + rw = [ "serhao" ]; }; flags = { e2d = true; @@ -65,12 +72,38 @@ "/data" = { path = "/mnt/data"; access = { - rwd = ["serhao"]; + rwd = [ "serhao" ]; }; flags = { e2d = true; }; }; + "/dump" = { + path = "/mnt/data/dump"; + access = { + rw = "*"; + rwd = [ "serhao" ]; + }; + flags = { + lifetime = 86400; + df = "100g"; + vmaxb = "10g"; + }; + }; + "/dump/quick" = { + path = "/mnt/data/dump/quick"; + access = { + rw = "*"; + rwd = [ "serhao" ]; + }; + flags = { + e2ds = true; + pk = "gz,9"; + lifetime = 300; + df = "100g"; + vmaxb = "10g"; + }; + }; }; }; diff --git a/hosts/sin/glances.nix b/hosts/sin/glances.nix index 6c70397..34114cb 100644 --- a/hosts/sin/glances.nix +++ b/hosts/sin/glances.nix @@ -4,6 +4,11 @@ enable = true; openFirewall = true; # TODO Change secrets - extraArgs = [ "--webserver" ]; + extraArgs = [ + "--webserver" + "--disable-webui" + "--disable-plugin" + "processcount" + ]; }; } diff --git a/hosts/sin/homepage.nix b/hosts/sin/homepage.nix index 2414d76..4216d7d 100644 --- a/hosts/sin/homepage.nix +++ b/hosts/sin/homepage.nix @@ -12,7 +12,6 @@ headerStyle = "boxed"; providers = { - "finnhub" = "cuvq5e9r01qub8tv03g0cuvq5e9r01qub8tv03gg"; }; layout = [ @@ -38,6 +37,20 @@ header = false; }; } + { + "admin" = { + tab = "Admin"; + header = false; + sin = { + style = "row"; + columns = 3; + }; + thea = { + style = "row"; + columns = 3; + }; + }; + } ]; }; @@ -56,9 +69,7 @@ } { glances = { - url = "https://zimablade-admin.shobu.fr"; - user = "shobu"; - password = "shobu"; + url = "http://sin.home:61208"; version = 4; disk = [ "/" @@ -154,7 +165,7 @@ widget = { type = "jellyseerr"; url = "https://jellyseerr.shobu.fr"; - key = "MTczNzkyNzMxMzgwODk4N2FlZWJkLTQ0N2QtNGU0MS1iOWE1LTJmZmE3OTI4ZGQ5OQ=="; + key = "MTc0OTMzOTE2MDMwODgxNzdlYjNlLTU4N2ItNDc0Mi1iZTY4LTM3NzVhMWZiMDUzZg=="; }; }; } @@ -227,7 +238,7 @@ href = "https://transmission.shobu.fr"; widget = { type = "transmission"; - url = "https://transmission.shobu.fr"; + url = "http://sin.home:9091"; }; }; } @@ -235,6 +246,152 @@ } ]; } + { + "admin" = [ + ( + let + name = "sin"; + address = "http://sin.home:61208"; + in + { + "${name}" = [ + { + "info" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "info"; + }; + }; + } + { + "main storage" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "fs:/mnt/fs"; + }; + }; + } + { + "system storage" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "fs:/"; + }; + }; + } + { + "memory" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "memory"; + }; + }; + } + { + "cpu" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "cpu"; + }; + }; + } + { + "network" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "network:enp2s0"; + }; + }; + } + ]; + } + ) + + ( + let + name = "thea"; + address = "http://thea.home:61208"; + in + { + "${name}" = [ + { + "info" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "info"; + }; + }; + } + { + "main storage" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "fs:/mnt/fs"; + }; + }; + } + { + "system storage" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "fs:/"; + }; + }; + } + { + "memory" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "memory"; + }; + }; + } + { + "cpu" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "cpu"; + }; + }; + } + { + "network" = { + widget = { + type = "glances"; + url = address; + version = 4; + metric = "network:enp2s0"; + }; + }; + } + ]; + } + ) + + ]; + } ]; }; } diff --git a/hosts/sin/jellyfin.nix b/hosts/sin/jellyfin.nix index 807d886..58ca94f 100644 --- a/hosts/sin/jellyfin.nix +++ b/hosts/sin/jellyfin.nix @@ -1,22 +1,44 @@ -{ pkgs, inputs, ... }: +{ + pkgs, + inputs, + ... +}: let - unstable = import inputs.unstable { system = pkgs.system; }; + nixpkgs-2505 = import inputs.nixpkgs-2505 { + system = pkgs.stdenv.system; + config.allowUnfree = true; + config.permittedInsecurePackages = [ "intel-media-sdk-23.2.2" ]; + }; in -{systemd.services.jellyfin.environment.LIBVA_DRIVER_NAME = "iHD"; # or i965 for older GPUs - environment.sessionVariables = { LIBVA_DRIVER_NAME = "iHD"; }; +{ + systemd.services.jellyfin.environment = { + LIBVA_DRIVER_NAME = "iHD"; # or i965 for older GPUs + NEOReadDebugKeys = "1"; + OverrideGpuAddressSpace = "48"; + }; + environment.sessionVariables = { + LIBVA_DRIVER_NAME = "iHD"; + NEOReadDebugKeys = "1"; + OverrideGpuAddressSpace = "48"; + }; hardware.graphics = { enable = true; extraPackages = with pkgs; [ intel-ocl # Generic OpenCL support - # For Broadwell and newer (ca. 2014+), use with LIBVA_DRIVER_NAME=iHD: + intel-compute-runtime-legacy1 intel-media-driver + nixpkgs-2505.intel-media-sdk ]; }; + hardware.enableRedistributableFirmware = true; + boot.kernelParams = [ "i915.enable_guc=3" ]; + nixpkgs.config.permittedInsecurePackages = [ - "dotnet-sdk-6.0.428" - "aspnetcore-runtime-6.0.36" + # "dotnet-sdk-6.0.428" + # "aspnetcore-runtime-6.0.36" + "intel-media-sdk-23.2.2" ]; users.users."starr" = { @@ -63,70 +85,81 @@ in "radarr" "sonarr" ]; + users.users.jellyfin.extraGroups = [ + "render" + "video" + ]; users.groups = { - starr = { }; - }; - - services = { - jellyfin = { - enable = true; - openFirewall = true; - }; - - sonarr = { - enable = true; - openFirewall = true; - group = "starr"; - settings = { - authentication.AuthenticationMethod = "external"; - authentication.AuthenticationType = "enabled"; - }; - }; - radarr = { - enable = true; - openFirewall = true; - group = "starr"; - settings = { - authentication.AuthenticationMethod = "external"; - authentication.AuthenticationType = "enabled"; - }; - }; - prowlarr = { - enable = true; - openFirewall = true; - settings = { - authentication.AuthenticationMethod = "external"; - authentication.AuthenticationType = "enabled"; - }; - }; - bazarr = { - enable = true; - openFirewall = true; - }; - lidarr = { - enable = true; - openFirewall = true; - settings = { - authentication.AuthenticationMethod = "external"; - authentication.AuthenticationType = "enabled"; - }; - }; - whisparr = { - enable = true; - openFirewall = true; - settings = { - authentication.AuthenticationMethod = "external"; - authentication.AuthenticationType = "enabled"; - }; - }; - - jellyseerr = { - enable = true; - openFirewall = true; + starr = { + gid = 990; }; }; + services = + let + mkEnvFile = + name: + (pkgs.writeText "${name}.env" '' + ${name}__AUTH__ENABLED=false + ${name}__AUTH__METHOD=External + ''); + in + { + jellyfin = { + enable = true; + openFirewall = true; + }; + + sonarr = { + enable = true; + openFirewall = true; + group = "starr"; + environmentFiles = [ + (mkEnvFile "SONARR") + ]; + }; + radarr = { + enable = true; + openFirewall = true; + group = "starr"; + environmentFiles = [ + (mkEnvFile "RADARR") + ]; + }; + prowlarr = { + enable = true; + openFirewall = true; + environmentFiles = [ + (mkEnvFile "PROWLARR") + ]; + }; + bazarr = { + enable = true; + openFirewall = true; + group = "starr"; + }; + lidarr = { + enable = true; + openFirewall = true; + environmentFiles = [ + (mkEnvFile "LIDARR") + ]; + }; + whisparr = { + enable = true; + openFirewall = true; + environmentFiles = [ + (mkEnvFile "WHISPARR") + ]; + }; + + jellyseerr = { + enable = true; + openFirewall = true; + }; + }; + environment.systemPackages = [ pkgs.jellyfin pkgs.jellyfin-web diff --git a/hosts/sin/mailserver.nix b/hosts/sin/mailserver.nix deleted file mode 100644 index 3157df7..0000000 --- a/hosts/sin/mailserver.nix +++ /dev/null @@ -1,37 +0,0 @@ -{ - inputs, - config, - lib, - ... -}: -let - inherit (lib) - mkDefault - ; -in -{ - imports = [ - inputs.simple-mailserver.default - ]; - - security.acme = { - acceptTerms = mkDefault true; - certs.${config.mailserver.fqdn} = { - }; - }; - - mailserver = { - enable = true; - stateVersion = 3; - fqdn = "mail.shobu.fr"; - domains = [ "shobu.fr" ]; - - x509.useACMEHost = config.mailserver.fqdn; - - loginAccounts = { - "auth@shobu.fr" = { - password = "$y$j9T$aLAZYUOUrc2jxcNYGy1qt/$B1ZdufZtzJJmnLYIYW11nk1BwIIy1Xkjxb7lx3ge/Z3"; - }; - }; - }; -} diff --git a/hosts/sin/transmission.nix b/hosts/sin/transmission.nix index 64f8406..0062133 100644 --- a/hosts/sin/transmission.nix +++ b/hosts/sin/transmission.nix @@ -86,7 +86,7 @@ ]; environment = { PUID = toString config.users.users.transmission.uid; - GUID = toString config.users.groups.transmission.gid; + PGID = toString config.users.groups.starr.gid; PEERPORT = peerport; }; }; diff --git a/hosts/sin/trilium.nix b/hosts/sin/trilium.nix index d00cbb2..0af5a0c 100644 --- a/hosts/sin/trilium.nix +++ b/hosts/sin/trilium.nix @@ -4,6 +4,7 @@ enable = true; port = 12783; host = "0.0.0.0"; - noAuthentication = true; + # noAuthentication = true; + environmentFile = "/secrets/trilium.env"; }; } diff --git a/hosts/thea/authelia.nix b/hosts/thea/authelia.nix index bb9c46b..32af57e 100644 --- a/hosts/thea/authelia.nix +++ b/hosts/thea/authelia.nix @@ -49,13 +49,13 @@ in access_control = { default_policy = "deny"; rules = [ - # { - # domain = "radarr.shobu.fr"; - # policy = "bypass"; - # } + { + domain = "auth.shobu.fr"; + policy = "bypass"; + } { domain = "*.shobu.fr"; - policy = "one_factor"; + policy = "two_factor"; } ]; }; @@ -68,6 +68,75 @@ in }; }; }; + identity_providers = { + oidc = { + hmac_secret = "this_is_a_secret_abc123abc123abc"; # 64+ character secret + jwks = [ + { + key = '' + -----BEGIN PRIVATE KEY----- + MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDBGxQpgV074AB1 + ee+JiDMxuiVooVuD8RzVISTy0tVNBFS5vydB1g5k072shMdCE8S2M4oTaW7ZG1h0 + A+XbgZj+wZFcdHA+lD6QRGSN03FlrRZBMv8BCKzctdgAW1Dtrho31+Nw+3jTrrbO + DiQaH2kzanET0GZJ+cD3AngWYV0KCkq8yws3T8AiK4oNghyv6Amknmbf7sJ+aZ8C + f8WCixiErT/TjEGKRxFTKw3LMrdrbljE8JP+f1sTpDZP6uOtH0YS0iJ4nWHvxKYH + LHLzrx3rO0zBrPiXK3eAtP2baPxS5y26kJcVL5bUSbDdB3NCznZc50OO14huX2s+ + GVct0FsLAgMBAAECggEAAUoZTy91wXa5gn8EzQVWzj9YfJDv2Pn4/hjLmRNHFADQ + gmtXfhNJiHte7qqdjB1ag8TgOcHd8oyRFmcgCs3BaL68uwEdtq/hT4FXvF37EKW+ + q/PyS38XNMWBIpfD+tmYGJHfzp2HsuPCz5tbSzG5qioZvMNHd4FtRXj6cGntjRAg + uW1Ns2h//BajftwD8RLHOvq7lWLaPWbdbte396KNBdNpceargISf9VEJik/dPWrT + jV5bNAm7chvEfjhLqFCJ/p6j7z4DLFGrhYnh50btfe9FnWRtUYAGxhfaobveDPVe + AI0lFN7IFU6+G6cYHTZAtAviWIutDwK0K9ACYCo1wQKBgQDiWEIdoYvjAh2J9K8f + 8YWa660YuvLSYQmvimr7E9FzoFdiUeFqlVCw/SIz7mRuDDCliDFxheekc8+jJB5U + kfR2C2o3llRy+wLVap6X5OmqVAjFuHXxntbK/zwyv4K5uecwtEgDyGdXW2eZDog7 + VohuWOD3cTDAkVFu/Mw/02/CqwKBgQDaZ/b1Rfu9QXLvgtf23PpqKb0VG6gOo/Sm + bpGnEBG9sAnsvDHBs85UTxzzr0qWOSguDh5NMxd0/IxKiLDRPvshhod9rWw0T8Qh + jBDYsDLBZlBT1AVKvkeELZx9DW1Iomx6bdtYRX3SkgBKVK43q17J3T37U/UJ36PQ + 5e1lBbDJIQKBgQDcEcP222MPTLc7stOy0zl77zlVmi8NrZulOYfapuI28ecEiWgK + ITNbYkMnCtpKxT9nMowgPHmEw7VWgX+b6m0teNvFQDzLrpKKvieEt+UY3qvI0hia + 3D0rEg6NqPaJbd8C08ZRJ0CTByQrBJ4gU3pDD9drvnoQQTpUFybfx8waEQKBgQDL + 6a1FKuXyuRyaSktgjMiwPe/vuTabFLDigvEyTWqC880QXlUGSN4nEQYy7kJxJ0RA + W6Ym5cDM1M4W+LA9bNQDZRszV6ti2+Z+e8tuxHNe5iuxWI7oTedvnTYx+0tBOYSW + eeME8zyaUP48Z/uQtkt1pT6tXKG3ajoEW+fdHgcEgQKBgCCTnBkASe21/n+D3c02 + vGekM3ioWNe9heIWv/7aWmMXb14DBCZMVXNyfOe7gQs2u3OX+IBW8UscGhY2LjVV + 5dKLMIWHw8Afccw4isYhequmJeai2Q3SSenWc7lIqOG4FDpwkcjW0VBBaU/p7ZnA + h3JJ7q49hdgOKpF/xZNwmmfI + -----END PRIVATE KEY-----''; # rsa private key + } + ]; + claims_policies = { + trilium = { + id_token = [ + "email" + "name" + ]; + }; + }; + clients = [ + { + client_id = "trilium"; + client_name = "Trilium Notes"; + client_secret = "$pbkdf2-sha512$310000$c8p78n7pUMln0jzvd4aK4Q$JNRBzwAo0ek5qKn50cFzzvE9RXV88h1wJn5KGiHrD0YKtZaR/nCb2CJPOsKaPK0hjf.9yHxzQGZziziccp6Yng"; + public = false; + authorization_policy = "two_factor"; + claims_policy = "trilium"; + require_pkce = false; + pkce_challenge_method = ""; + redirect_uris = [ "https://trilium.shobu.fr/callback" ]; + scopes = [ + "openid" + "profile" + "email" + ]; + response_types = [ "code" ]; + grant_types = [ "authorization_code" ]; + access_token_signed_response_alg = "none"; + userinfo_signed_response_alg = "none"; + token_endpoint_auth_method = "client_secret_basic"; + } + ]; + }; + }; }; }; }; diff --git a/hosts/thea/configuration.nix b/hosts/thea/configuration.nix index 3079e35..a01cbd2 100644 --- a/hosts/thea/configuration.nix +++ b/hosts/thea/configuration.nix @@ -17,10 +17,11 @@ in imports = [ ./nginx.nix # ./cybercoffee - ./ollama.nix - ./minecraft.nix + # ./ollama.nix + # ./minecraft.nix ./secrets ./authelia.nix + ./glances.nix ]; # Use the systemd-boot EFI boot loader. @@ -39,6 +40,7 @@ in firewall = { allowedTCPPorts = [ nodes.sin.config.services.gitea.settings.server.SSH_PORT + 993 # mail port ] ++ [ # minecraft ad hoc server ports @@ -57,6 +59,16 @@ in proto = "tcp"; destination = "${sin-address}:22"; } + { + sourcePort = 993; + proto = "tcp"; + destination = "${sin-address}:993"; + } + { + sourcePort = 8086; + proto = "tcp"; + destination = "${sin-address}:8086"; + } ]; }; }; @@ -87,13 +99,11 @@ in }; environment.systemPackages = with pkgs; [ - lunarvim wget httpie tmux git helix - python312 # lemonade ]; diff --git a/hosts/thea/glances.nix b/hosts/thea/glances.nix new file mode 100644 index 0000000..34114cb --- /dev/null +++ b/hosts/thea/glances.nix @@ -0,0 +1,14 @@ +{ ... }: +{ + services.glances = { + enable = true; + openFirewall = true; + # TODO Change secrets + extraArgs = [ + "--webserver" + "--disable-webui" + "--disable-plugin" + "processcount" + ]; + }; +} diff --git a/hosts/thea/minecraft.nix b/hosts/thea/minecraft.nix index 54f9997..a44ad13 100644 --- a/hosts/thea/minecraft.nix +++ b/hosts/thea/minecraft.nix @@ -9,10 +9,6 @@ let url = "file:///${inputs.testing-grounds.modpack}/pack.toml"; packHash = "sha256-+taYj4uroLNxM4Nia3n+5P1Y/g6dzE6Iq13TsZgk4mU="; }; - gregpack = pkgs.fetchPackwizModpack { - url = "https://raw.githubusercontent.com/GregTechCEu/GregTech-Modern-Community-Pack/refs/heads/main/pack.toml"; - packHash = "sha256-SE86gP15H/Aug6vTLmMxHuxF2/+iLmCI/wQlON1xasM="; - }; in { imports = [ inputs.nix-minecraft.nixosModules.minecraft-servers ]; @@ -24,7 +20,7 @@ in openFirewall = true; servers.testing-grounds = { - enable = true; + enable = false; package = inputs.testing-grounds.packages.x86_64-linux.forge-server; diff --git a/hosts/thea/nginx.nix b/hosts/thea/nginx.nix index fcefa09..36b20ad 100644 --- a/hosts/thea/nginx.nix +++ b/hosts/thea/nginx.nix @@ -2,6 +2,7 @@ inputs, pkgs, lib, + nodes, ... }: let @@ -34,7 +35,7 @@ in forceSSL = true; locations."/" = { - proxyPass = "http://${sin-address}:${port}"; + proxyPass = "http://${sin-address}:${toString port}"; }; }; }; @@ -106,9 +107,10 @@ in // mkStarr "lidarr.shobu.fr" "8686" // mkStarr "whisparr.shobu.fr" "6969" // mkVHost "jellyseerr.shobu.fr" "5055" - // mkVHost "transmission.shobu.fr" "9091" - // mkVHost "zimablade-admin.shobu.fr" "61208" - // (withWebsockets (withAuthelia (mkVHost "trilium.shobu.fr" "12783") "/") "/") + // withAuthelia (mkVHost "transmission.shobu.fr" "9091") "/" + // withAuthelia (mkVHost "zimablade-admin.shobu.fr" "61208") "/" + // withAuthelia (mkVHost "actual.shobu.fr" nodes.sin.config.services.actual.settings.port) "/" + // (withWebsockets (mkVHost "trilium.shobu.fr" "12783") "/") // { "shobu.fr" = { enableACME = true; @@ -165,6 +167,9 @@ in locations."/" = { proxyPass = "http://${sin-address}:3000"; + extraConfig = '' + client_max_body_size 100M; + ''; }; }; "files.shobu.fr" = { diff --git a/modules/gitea/thea/default.nix b/modules/gitea/thea/default.nix index 7bbe523..902646e 100644 --- a/modules/gitea/thea/default.nix +++ b/modules/gitea/thea/default.nix @@ -1,12 +1,9 @@ { nodes, - inputs, - pkgs, ... }: let sin-address = "192.168.1.14"; - unstable = import inputs.unstable { system = pkgs.system; }; in { imports = [ @@ -19,9 +16,6 @@ in destination = "${sin-address}:22"; } ]; - - services.gitea-actions-runner.package = unstable.gitea-actions-runner; - # services.gitea-actions-runner.instances = { # "gitea.shobu.fr-runner" = { # enable = true;