Compare commits
6
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dabfbc84cb | ||
|
|
1ccf5febc9 | ||
|
|
ec0ac3933b | ||
|
|
5053c766d1 | ||
|
|
4bc135b0ad | ||
|
|
fb26eef750 |
@@ -3,4 +3,3 @@
|
|||||||
result
|
result
|
||||||
result-*
|
result-*
|
||||||
run-vm-*
|
run-vm-*
|
||||||
.nixos-test-history
|
|
||||||
|
|||||||
Generated
+116
-685
@@ -1,121 +1,26 @@
|
|||||||
{
|
{
|
||||||
"nodes": {
|
"nodes": {
|
||||||
"arion": {
|
"androidPkgs": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"flake-parts": "flake-parts_2",
|
"devshell": "devshell_2",
|
||||||
"haskell-flake": "haskell-flake",
|
"flake-utils": "flake-utils",
|
||||||
"nixpkgs": [
|
"nixpkgs": "nixpkgs_2"
|
||||||
"frappix",
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1733918465,
|
"lastModified": 1750710155,
|
||||||
"narHash": "sha256-hSuGa8Hh67EHr2x812Ay6WFyFT2BGKn+zk+FJWeKXPg=",
|
"narHash": "sha256-2lBEwXgclOrSsrhubSfifU91+sXqikC8qbiZ6yFeaEY=",
|
||||||
"owner": "hercules-ci",
|
"owner": "tadfisher",
|
||||||
"repo": "arion",
|
"repo": "android-nixpkgs",
|
||||||
"rev": "f01c95c10f9d4f04bb08d97b3233b530b180f12e",
|
"rev": "0846fab1f060f646e1017053077ad38dedc5207b",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "hercules-ci",
|
"owner": "tadfisher",
|
||||||
"repo": "arion",
|
"ref": "stable",
|
||||||
|
"repo": "android-nixpkgs",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"blank": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1625557891,
|
|
||||||
"narHash": "sha256-O8/MWsPBGhhyPoPLHZAuoZiiHo9q6FLlEeIDEXuj6T4=",
|
|
||||||
"owner": "divnix",
|
|
||||||
"repo": "blank",
|
|
||||||
"rev": "5a5d2684073d9f563072ed07c871d577a6c614a8",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "divnix",
|
|
||||||
"repo": "blank",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"call-flake": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1687380775,
|
|
||||||
"narHash": "sha256-bmhE1TmrJG4ba93l9WQTLuYM53kwGQAjYHRvHOeuxWU=",
|
|
||||||
"owner": "divnix",
|
|
||||||
"repo": "call-flake",
|
|
||||||
"rev": "74061f6c241227cd05e79b702db9a300a2e4131a",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "divnix",
|
|
||||||
"repo": "call-flake",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"clan-community": {
|
|
||||||
"inputs": {
|
|
||||||
"clan-core": [
|
|
||||||
"clan-core"
|
|
||||||
],
|
|
||||||
"data-mesher": [
|
|
||||||
"clan-community",
|
|
||||||
"clan-core",
|
|
||||||
"data-mesher"
|
|
||||||
],
|
|
||||||
"disko": [
|
|
||||||
"clan-community",
|
|
||||||
"clan-core",
|
|
||||||
"disko"
|
|
||||||
],
|
|
||||||
"flake-parts": [
|
|
||||||
"flake-parts"
|
|
||||||
],
|
|
||||||
"nix-darwin": [
|
|
||||||
"clan-community",
|
|
||||||
"clan-core",
|
|
||||||
"nix-darwin"
|
|
||||||
],
|
|
||||||
"nix-github-actions": "nix-github-actions",
|
|
||||||
"nix-select": [
|
|
||||||
"clan-community",
|
|
||||||
"clan-core",
|
|
||||||
"nix-select"
|
|
||||||
],
|
|
||||||
"nix-unit": "nix-unit",
|
|
||||||
"nixpkgs": [
|
|
||||||
"clan-community",
|
|
||||||
"clan-core",
|
|
||||||
"nixpkgs"
|
|
||||||
],
|
|
||||||
"sops-nix": [
|
|
||||||
"clan-community",
|
|
||||||
"clan-core",
|
|
||||||
"sops-nix"
|
|
||||||
],
|
|
||||||
"systems": [
|
|
||||||
"clan-community",
|
|
||||||
"clan-core",
|
|
||||||
"systems"
|
|
||||||
],
|
|
||||||
"treefmt-nix": [
|
|
||||||
"treefmt-nix"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1784417092,
|
|
||||||
"narHash": "sha256-no5eDYWPUZZu4GtLufnA7b7CiZC4qAhCgf70gFiDLZk=",
|
|
||||||
"ref": "refs/heads/main",
|
|
||||||
"rev": "20371843d45f61217019e489d6857842dc8a0203",
|
|
||||||
"revCount": 73,
|
|
||||||
"type": "git",
|
|
||||||
"url": "https://git.clan.lol/clan/clan-community"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"type": "git",
|
|
||||||
"url": "https://git.clan.lol/clan/clan-community"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"clan-core": {
|
"clan-core": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"data-mesher": "data-mesher",
|
"data-mesher": "data-mesher",
|
||||||
@@ -135,11 +40,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781517972,
|
"lastModified": 1772411144,
|
||||||
"narHash": "sha256-G8bIXFqifs/y62GNPwg20Ksf71raYwzmyN99gf1tXak=",
|
"narHash": "sha256-WhXudztwPNnKXaqGX4DOqNfHzHdBSiGCvKGHM20pscw=",
|
||||||
"ref": "refs/heads/main",
|
"ref": "refs/heads/main",
|
||||||
"rev": "7fc62d0c25c7a97d7027a9c248e21c97c9b3acc1",
|
"rev": "92cc85bc24eb31ce5725e1e72753129810ce3fe9",
|
||||||
"revCount": 14604,
|
"revCount": 13201,
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "https://git.clan.lol/clan/clan-core"
|
"url": "https://git.clan.lol/clan/clan-core"
|
||||||
},
|
},
|
||||||
@@ -164,11 +69,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1778718524,
|
"lastModified": 1772273147,
|
||||||
"narHash": "sha256-pXLoI6Ax0EnUK6r34UM1vibVC7CfTu6j72R2692ZzPs=",
|
"narHash": "sha256-Wzhoc6ifjTDZi8aVRH3fuLJPdd4ouNTTwwVhgoMcMek=",
|
||||||
"rev": "12c552ad547d87254f33f33bddd1a2cdbeac754d",
|
"rev": "d5de7a8d9e5726e678c94e62fe8ac3a809fee5da",
|
||||||
"type": "tarball",
|
"type": "tarball",
|
||||||
"url": "https://git.clan.lol/api/v1/repos/clan/data-mesher/archive/12c552ad547d87254f33f33bddd1a2cdbeac754d.tar.gz"
|
"url": "https://git.clan.lol/api/v1/repos/clan/data-mesher/archive/d5de7a8d9e5726e678c94e62fe8ac3a809fee5da.tar.gz"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"type": "tarball",
|
"type": "tarball",
|
||||||
@@ -195,6 +100,28 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"devshell_2": {
|
||||||
|
"inputs": {
|
||||||
|
"nixpkgs": [
|
||||||
|
"robotnix",
|
||||||
|
"androidPkgs",
|
||||||
|
"nixpkgs"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1741473158,
|
||||||
|
"narHash": "sha256-kWNaq6wQUbUMlPgw8Y+9/9wP0F8SHkjy24/mN3UAppg=",
|
||||||
|
"owner": "numtide",
|
||||||
|
"repo": "devshell",
|
||||||
|
"rev": "7c9e793ebe66bcba8292989a68c0419b737a22a0",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "numtide",
|
||||||
|
"repo": "devshell",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
"disko": {
|
"disko": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
@@ -203,11 +130,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781152676,
|
"lastModified": 1771881364,
|
||||||
"narHash": "sha256-RxWs5ND31KzTG7wvMM+PMfUjyNpmIEr999lqNARaM5o=",
|
"narHash": "sha256-A5uE/hMium5of/QGC6JwF5TGoDAfpNtW00T0s9u/PN8=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "disko",
|
"repo": "disko",
|
||||||
"rev": "ff8702b4de27f72b4c78573dfb89ec74e36abdf1",
|
"rev": "a4cb7bf73f264d40560ba527f9280469f1f081c6",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -216,36 +143,18 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"dmerge": {
|
"flake-compat": {
|
||||||
"inputs": {
|
|
||||||
"haumea": [
|
|
||||||
"frappix",
|
|
||||||
"std",
|
|
||||||
"haumea"
|
|
||||||
],
|
|
||||||
"nixlib": [
|
|
||||||
"frappix",
|
|
||||||
"std",
|
|
||||||
"lib"
|
|
||||||
],
|
|
||||||
"yants": [
|
|
||||||
"frappix",
|
|
||||||
"std",
|
|
||||||
"yants"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1686862774,
|
"lastModified": 1746162366,
|
||||||
"narHash": "sha256-ojGtRQ9pIOUrxsQEuEPerUkqIJEuod9hIflfNkY+9CE=",
|
"narHash": "sha256-5SSSZ/oQkwfcAz/o/6TlejlVGqeK08wyREBQ5qFFPhM=",
|
||||||
"owner": "divnix",
|
"owner": "nix-community",
|
||||||
"repo": "dmerge",
|
"repo": "flake-compat",
|
||||||
"rev": "9f7f7a8349d33d7bd02e0f2b484b1f076e503a96",
|
"rev": "0f158086a2ecdbb138cd0429410e44994f1b7e4b",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "divnix",
|
"owner": "nix-community",
|
||||||
"ref": "0.2.1",
|
"repo": "flake-compat",
|
||||||
"repo": "dmerge",
|
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -269,28 +178,6 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"flake-parts_2": {
|
|
||||||
"inputs": {
|
|
||||||
"nixpkgs-lib": [
|
|
||||||
"frappix",
|
|
||||||
"arion",
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1733312601,
|
|
||||||
"narHash": "sha256-4pDvzqnegAfRkPwO3wmwBhVi/Sye1mzps0zHWYnP88c=",
|
|
||||||
"owner": "hercules-ci",
|
|
||||||
"repo": "flake-parts",
|
|
||||||
"rev": "205b12d8b7cd4802fbcb8e8ef6a0f1408781a4f9",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "hercules-ci",
|
|
||||||
"repo": "flake-parts",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"flake-utils": {
|
"flake-utils": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"systems": "systems_2"
|
"systems": "systems_2"
|
||||||
@@ -309,106 +196,6 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"flake-utils_2": {
|
|
||||||
"inputs": {
|
|
||||||
"systems": "systems_3"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1710146030,
|
|
||||||
"narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=",
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"flake-utils_3": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1653893745,
|
|
||||||
"narHash": "sha256-0jntwV3Z8//YwuOjzhV2sgJJPt+HY6KhU7VZUL0fKZQ=",
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"rev": "1ed9fb1935d260de5fe1c2f7ee0ebaae17ed2fa1",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "numtide",
|
|
||||||
"repo": "flake-utils",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"frappix": {
|
|
||||||
"inputs": {
|
|
||||||
"arion": "arion",
|
|
||||||
"devshell": [
|
|
||||||
"devshell"
|
|
||||||
],
|
|
||||||
"microvm": "microvm",
|
|
||||||
"n2c": "n2c",
|
|
||||||
"nixago": "nixago",
|
|
||||||
"nixpkgs": [
|
|
||||||
"nixpkgs"
|
|
||||||
],
|
|
||||||
"std": "std"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1782964989,
|
|
||||||
"narHash": "sha256-pU2Gye+1f+nvFleBTgXdeQfrQnKaJEuO2LT7PnsJ1p0=",
|
|
||||||
"owner": "kurogeek",
|
|
||||||
"repo": "frappix",
|
|
||||||
"rev": "ac5e2814fc1aca188080bf6b50504cd329790e56",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "kurogeek",
|
|
||||||
"repo": "frappix",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"haskell-flake": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1675296942,
|
|
||||||
"narHash": "sha256-u1X1sblozi5qYEcLp1hxcyo8FfDHnRUVX3dJ/tW19jY=",
|
|
||||||
"owner": "srid",
|
|
||||||
"repo": "haskell-flake",
|
|
||||||
"rev": "c2cafce9d57bfca41794dc3b99c593155006c71e",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "srid",
|
|
||||||
"ref": "0.1.0",
|
|
||||||
"repo": "haskell-flake",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"haumea": {
|
|
||||||
"inputs": {
|
|
||||||
"nixpkgs": [
|
|
||||||
"frappix",
|
|
||||||
"std",
|
|
||||||
"lib"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1685133229,
|
|
||||||
"narHash": "sha256-FePm/Gi9PBSNwiDFq3N+DWdfxFq0UKsVVTJS3cQPn94=",
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "haumea",
|
|
||||||
"rev": "34dd58385092a23018748b50f9b23de6266dffc2",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-community",
|
|
||||||
"ref": "v0.2.2",
|
|
||||||
"repo": "haumea",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"home-manager": {
|
"home-manager": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"nixpkgs": [
|
"nixpkgs": [
|
||||||
@@ -416,11 +203,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781557312,
|
"lastModified": 1768068402,
|
||||||
"narHash": "sha256-QOIRYSUFSq7L5mY3dZymaVhcnne3tPgoR9riB0WocjA=",
|
"narHash": "sha256-bAXnnJZKJiF7Xr6eNW6+PhBf1lg2P1aFUO9+xgWkXfA=",
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "home-manager",
|
"repo": "home-manager",
|
||||||
"rev": "c03e4752899e55705dfa63979abd885c582a5c48",
|
"rev": "8bc5473b6bc2b6e1529a9c4040411e1199c43b4c",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -444,99 +231,22 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"incl": {
|
|
||||||
"inputs": {
|
|
||||||
"nixlib": [
|
|
||||||
"frappix",
|
|
||||||
"std",
|
|
||||||
"lib"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1693483555,
|
|
||||||
"narHash": "sha256-Beq4WhSeH3jRTZgC1XopTSU10yLpK1nmMcnGoXO0XYo=",
|
|
||||||
"owner": "divnix",
|
|
||||||
"repo": "incl",
|
|
||||||
"rev": "526751ad3d1e23b07944b14e3f6b7a5948d3007b",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "divnix",
|
|
||||||
"repo": "incl",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"lib": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1722128034,
|
|
||||||
"narHash": "sha256-L8rwzYPsLo/TYtydPJoQyYOfetuiyQYnTWYcyB8UE/s=",
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nixpkgs.lib",
|
|
||||||
"rev": "d15f6f6021693898fcd2c6a9bb13707383da9bbc",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nixpkgs.lib",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"liminix": {
|
"liminix": {
|
||||||
"flake": false,
|
"flake": false,
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1777223456,
|
"lastModified": 1760426231,
|
||||||
"narHash": "sha256-yqZ9OFSXoKgdT6nWwt2d0OFwmfQXASl73hhjtvAD11A=",
|
"narHash": "sha256-r8c5PKtsxAvtQ/k17GH+WNvP47Lr+AbExLMPdLtvAKE=",
|
||||||
"ref": "refs/heads/main",
|
"ref": "refs/heads/fix-gl-ar750",
|
||||||
"rev": "5f2abc0d2b30eb5878d60488a72138958c228976",
|
"rev": "3f1f7c08d440130cce9262a93ce78ed7969d93cd",
|
||||||
"revCount": 1672,
|
"revCount": 1574,
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "https://gti.telent.net/dan/liminix"
|
"url": "https://git.b4l.co.th/newedge/liminix"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
"ref": "refs/heads/fix-gl-ar750",
|
||||||
|
"rev": "3f1f7c08d440130cce9262a93ce78ed7969d93cd",
|
||||||
"type": "git",
|
"type": "git",
|
||||||
"url": "https://gti.telent.net/dan/liminix"
|
"url": "https://git.b4l.co.th/newedge/liminix"
|
||||||
}
|
|
||||||
},
|
|
||||||
"microvm": {
|
|
||||||
"inputs": {
|
|
||||||
"flake-utils": "flake-utils",
|
|
||||||
"nixpkgs": [
|
|
||||||
"frappix",
|
|
||||||
"nixpkgs"
|
|
||||||
],
|
|
||||||
"spectrum": "spectrum"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1737981104,
|
|
||||||
"narHash": "sha256-7AGmPPBgLHHWgzzFYDJcyhv/NiuCrpgzg8IyA7Q/H9o=",
|
|
||||||
"owner": "astro",
|
|
||||||
"repo": "microvm.nix",
|
|
||||||
"rev": "3768f4937f38334898c67e03f40e244a57a74caa",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "astro",
|
|
||||||
"repo": "microvm.nix",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"n2c": {
|
|
||||||
"inputs": {
|
|
||||||
"flake-utils": "flake-utils_2",
|
|
||||||
"nixpkgs": "nixpkgs"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1730479402,
|
|
||||||
"narHash": "sha256-79NLeNjpCa4mSasmFsE3QA6obURezF0TUO5Pm+1daog=",
|
|
||||||
"owner": "nlewo",
|
|
||||||
"repo": "nix2container",
|
|
||||||
"rev": "5fb215a1564baa74ce04ad7f903d94ad6617e17a",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nlewo",
|
|
||||||
"repo": "nix2container",
|
|
||||||
"type": "github"
|
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nix-darwin": {
|
"nix-darwin": {
|
||||||
@@ -547,11 +257,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1781242433,
|
"lastModified": 1772379624,
|
||||||
"narHash": "sha256-bchLZZ3sRn740zyvD2icZSnNoTaanN0nw7l6fjVXO+E=",
|
"narHash": "sha256-NG9LLTWlz4YiaTAiRGChbrzbVxBfX+Auq4Ab/SWmk4A=",
|
||||||
"owner": "nix-darwin",
|
"owner": "nix-darwin",
|
||||||
"repo": "nix-darwin",
|
"repo": "nix-darwin",
|
||||||
"rev": "aabb2037edfc0f210723b72cd5f528aab5dd3f0b",
|
"rev": "52d061516108769656a8bd9c6e811c677ec5b462",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -560,49 +270,6 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nix-github-actions": {
|
|
||||||
"inputs": {
|
|
||||||
"nixpkgs": [
|
|
||||||
"clan-community",
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1737420293,
|
|
||||||
"narHash": "sha256-F1G5ifvqTpJq7fdkT34e/Jy9VCyzd5XfJ9TO8fHhJWE=",
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nix-github-actions",
|
|
||||||
"rev": "f4158fa080ef4503c8f4c820967d946c2af31ec9",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nix-github-actions",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nix-github-actions_2": {
|
|
||||||
"inputs": {
|
|
||||||
"nixpkgs": [
|
|
||||||
"clan-community",
|
|
||||||
"nix-unit",
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1737420293,
|
|
||||||
"narHash": "sha256-F1G5ifvqTpJq7fdkT34e/Jy9VCyzd5XfJ9TO8fHhJWE=",
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nix-github-actions",
|
|
||||||
"rev": "f4158fa080ef4503c8f4c820967d946c2af31ec9",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nix-github-actions",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nix-select": {
|
"nix-select": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1763303120,
|
"lastModified": 1763303120,
|
||||||
@@ -616,102 +283,13 @@
|
|||||||
"url": "https://git.clan.lol/clan/nix-select/archive/main.tar.gz"
|
"url": "https://git.clan.lol/clan/nix-select/archive/main.tar.gz"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nix-unit": {
|
|
||||||
"inputs": {
|
|
||||||
"nix-github-actions": "nix-github-actions_2",
|
|
||||||
"nixpkgs": [
|
|
||||||
"clan-community",
|
|
||||||
"nixpkgs"
|
|
||||||
],
|
|
||||||
"treefmt-nix": [
|
|
||||||
"clan-community",
|
|
||||||
"treefmt-nix"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1779338171,
|
|
||||||
"narHash": "sha256-affUbv/bwE8SLGhuWKniDr7SVO+Lo1XEPjCZdyU5kgQ=",
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nix-unit",
|
|
||||||
"rev": "6ab1f232562a01d18b40d5ed6a58718c4f3a74bc",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nix-unit",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixago": {
|
|
||||||
"inputs": {
|
|
||||||
"flake-utils": "flake-utils_3",
|
|
||||||
"nixago-exts": [
|
|
||||||
"frappix"
|
|
||||||
],
|
|
||||||
"nixpkgs": [
|
|
||||||
"frappix",
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1746801636,
|
|
||||||
"narHash": "sha256-dlcKfIXp/eqFHzFm+DzseXAWWlpVwyk9cTvCKGtVKkw=",
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nixago",
|
|
||||||
"rev": "8cc33f973ab3a891d8a41391e73ef451a783960b",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nixago",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixos-images": {
|
|
||||||
"inputs": {
|
|
||||||
"nixos-stable": [
|
|
||||||
"nixpkgs"
|
|
||||||
],
|
|
||||||
"nixos-unstable": [
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1784802994,
|
|
||||||
"narHash": "sha256-4PcD0Ibzdkh85G+70w5dLlR9YgQ2bmNIjiPPMSzO57w=",
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nixos-images",
|
|
||||||
"rev": "6ece16b0c97986fe085122e796044add4cc3ff64",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "nixos-images",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1712920918,
|
"lastModified": 1772173633,
|
||||||
"narHash": "sha256-1yxFvUcJfUphK9V91KufIQom7gCsztza0H4Rz2VCWUU=",
|
"narHash": "sha256-MOH58F4AIbCkh6qlQcwMycyk5SWvsqnS/TCfnqDlpj4=",
|
||||||
"owner": "NixOS",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"rev": "92323443a56f4e9fc4e4b712e3119f66d0969297",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "NixOS",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs_2": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1781359544,
|
|
||||||
"narHash": "sha256-iUuzKQcyXvopYDDzFpMK5eQKP3WIJExYny2kJtbgUcE=",
|
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "9f11f828c213641c2369a9f1fa31fe31557e3156",
|
"rev": "c0f3d81a7ddbc2b1332be0d8481a672b4f6004d6",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -721,104 +299,71 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"nosys": {
|
"nixpkgs_2": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1668010795,
|
"lastModified": 1750506804,
|
||||||
"narHash": "sha256-JBDVBnos8g0toU7EhIIqQ1If5m/nyBqtHhL3sicdPwI=",
|
"narHash": "sha256-VLFNc4egNjovYVxDGyBYTrvVCgDYgENp5bVi9fPTDYc=",
|
||||||
"owner": "divnix",
|
"owner": "NixOS",
|
||||||
"repo": "nosys",
|
"repo": "nixpkgs",
|
||||||
"rev": "feade0141487801c71ff55623b421ed535dbdefa",
|
"rev": "4206c4cb56751df534751b058295ea61357bbbaa",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "divnix",
|
"owner": "NixOS",
|
||||||
"repo": "nosys",
|
"ref": "nixos-unstable",
|
||||||
|
"repo": "nixpkgs",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"paisano": {
|
"nixpkgs_3": {
|
||||||
|
"locked": {
|
||||||
|
"lastModified": 1767313136,
|
||||||
|
"narHash": "sha256-16KkgfdYqjaeRGBaYsNrhPRRENs0qzkQVUooNHtoy2w=",
|
||||||
|
"owner": "NixOS",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"rev": "ac62194c3917d5f474c1a844b6fd6da2db95077d",
|
||||||
|
"type": "github"
|
||||||
|
},
|
||||||
|
"original": {
|
||||||
|
"owner": "NixOS",
|
||||||
|
"ref": "nixos-25.05",
|
||||||
|
"repo": "nixpkgs",
|
||||||
|
"type": "github"
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"robotnix": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"call-flake": "call-flake",
|
"androidPkgs": "androidPkgs",
|
||||||
"nixpkgs": [
|
"flake-compat": "flake-compat",
|
||||||
"frappix",
|
"nixpkgs": "nixpkgs_3",
|
||||||
"std",
|
"treefmt-nix": [
|
||||||
"nixpkgs"
|
"treefmt-nix"
|
||||||
],
|
|
||||||
"nosys": "nosys",
|
|
||||||
"yants": [
|
|
||||||
"frappix",
|
|
||||||
"std",
|
|
||||||
"yants"
|
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1708640854,
|
"lastModified": 1772653179,
|
||||||
"narHash": "sha256-EpcAmvIS4ErqhXtVEfd2GPpU/E/s8CCRSfYzk6FZ/fY=",
|
"narHash": "sha256-n+bUVGrgOpkuoHaAJ273wuvdrsrc68YKZWl8E1nMZJ0=",
|
||||||
"owner": "paisano-nix",
|
|
||||||
"repo": "core",
|
|
||||||
"rev": "adcf742bc9463c08764ca9e6955bd5e7dcf3a3fe",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "paisano-nix",
|
|
||||||
"ref": "0.2.0",
|
|
||||||
"repo": "core",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"paisano-tui": {
|
|
||||||
"flake": false,
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1708637035,
|
|
||||||
"narHash": "sha256-R19YURSK+MY/Rw6FZnojQS9zuDh+OoTAyngQAjjoubc=",
|
|
||||||
"owner": "paisano-nix",
|
|
||||||
"repo": "tui",
|
|
||||||
"rev": "231761b260587a64817e4ffae3afc15defaa15db",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "paisano-nix",
|
|
||||||
"ref": "v0.5.0",
|
|
||||||
"repo": "tui",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"plasma-manager": {
|
|
||||||
"inputs": {
|
|
||||||
"home-manager": [
|
|
||||||
"home-manager"
|
|
||||||
],
|
|
||||||
"nixpkgs": [
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1772361940,
|
|
||||||
"narHash": "sha256-B1Cz+ydL1iaOnGlwOFld/C8lBECPtzhiy/pP93/CuyY=",
|
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "plasma-manager",
|
"repo": "robotnix",
|
||||||
"rev": "a4b33606111c9c5dcd10009042bb710307174f51",
|
"rev": "b5e513ccb503c5bdb97bbaccca178d65082c01c1",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
"owner": "nix-community",
|
"owner": "nix-community",
|
||||||
"repo": "plasma-manager",
|
"repo": "robotnix",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"root": {
|
"root": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"clan-community": "clan-community",
|
|
||||||
"clan-core": "clan-core",
|
"clan-core": "clan-core",
|
||||||
"devshell": "devshell",
|
"devshell": "devshell",
|
||||||
"flake-parts": "flake-parts",
|
"flake-parts": "flake-parts",
|
||||||
"frappix": "frappix",
|
|
||||||
"home-manager": "home-manager",
|
"home-manager": "home-manager",
|
||||||
"import-tree": "import-tree",
|
"import-tree": "import-tree",
|
||||||
"liminix": "liminix",
|
"liminix": "liminix",
|
||||||
"nixos-images": "nixos-images",
|
"nixpkgs": "nixpkgs",
|
||||||
"nixpkgs": "nixpkgs_2",
|
"robotnix": "robotnix",
|
||||||
"plasma-manager": "plasma-manager",
|
|
||||||
"treefmt-nix": "treefmt-nix"
|
"treefmt-nix": "treefmt-nix"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
@@ -830,11 +375,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1780547341,
|
"lastModified": 1772340640,
|
||||||
"narHash": "sha256-Gq8KNx5A7hBB3uGJaj6eQfLDIz5YdLu92gqBcvHvoUo=",
|
"narHash": "sha256-1nq7+Kt5IUBD8Hu3nptVPbMf+22rNJoHT0t9L1X+GKA=",
|
||||||
"owner": "Mic92",
|
"owner": "Mic92",
|
||||||
"repo": "sops-nix",
|
"repo": "sops-nix",
|
||||||
"rev": "9ed65852b6257fbeae4355bc24ecfea307ca759a",
|
"rev": "dec4d8eac700dcd2fe3c020857d3ee220ec147f1",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -843,99 +388,7 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"spectrum": {
|
|
||||||
"flake": false,
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1733308308,
|
|
||||||
"narHash": "sha256-+RcbMAjSxV1wW5UpS9abIG1lFZC8bITPiFIKNnE7RLs=",
|
|
||||||
"ref": "refs/heads/main",
|
|
||||||
"rev": "80c9e9830d460c944c8f730065f18bb733bc7ee2",
|
|
||||||
"revCount": 792,
|
|
||||||
"type": "git",
|
|
||||||
"url": "https://spectrum-os.org/git/spectrum"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"type": "git",
|
|
||||||
"url": "https://spectrum-os.org/git/spectrum"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"std": {
|
|
||||||
"inputs": {
|
|
||||||
"arion": [
|
|
||||||
"frappix",
|
|
||||||
"arion"
|
|
||||||
],
|
|
||||||
"blank": "blank",
|
|
||||||
"devshell": [
|
|
||||||
"frappix",
|
|
||||||
"devshell"
|
|
||||||
],
|
|
||||||
"dmerge": "dmerge",
|
|
||||||
"haumea": "haumea",
|
|
||||||
"incl": "incl",
|
|
||||||
"lib": "lib",
|
|
||||||
"makes": [
|
|
||||||
"frappix",
|
|
||||||
"std",
|
|
||||||
"blank"
|
|
||||||
],
|
|
||||||
"microvm": [
|
|
||||||
"frappix",
|
|
||||||
"microvm"
|
|
||||||
],
|
|
||||||
"n2c": [
|
|
||||||
"frappix",
|
|
||||||
"n2c"
|
|
||||||
],
|
|
||||||
"nixago": [
|
|
||||||
"frappix",
|
|
||||||
"nixago"
|
|
||||||
],
|
|
||||||
"nixpkgs": [
|
|
||||||
"frappix",
|
|
||||||
"nixpkgs"
|
|
||||||
],
|
|
||||||
"paisano": "paisano",
|
|
||||||
"paisano-tui": "paisano-tui",
|
|
||||||
"terranix": [
|
|
||||||
"frappix",
|
|
||||||
"std",
|
|
||||||
"blank"
|
|
||||||
],
|
|
||||||
"yants": "yants"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1738072995,
|
|
||||||
"narHash": "sha256-jfwWnAVeQzIBS5Pex0xSUbGk88g1GFF2w+ohOtbRtcY=",
|
|
||||||
"owner": "divnix",
|
|
||||||
"repo": "std",
|
|
||||||
"rev": "2874513c4b76be4c4200779814993b546fe4a909",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "divnix",
|
|
||||||
"ref": "v0.33.4",
|
|
||||||
"repo": "std",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"systems": {
|
"systems": {
|
||||||
"locked": {
|
|
||||||
"lastModified": 1774449309,
|
|
||||||
"narHash": "sha256-brhZ8DmuGtzkCYHJg4HEd602amKm89Y9ytsFZ5uWD1w=",
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"repo": "default",
|
|
||||||
"rev": "c29398b59d2048c4ab79345812849c9bd15e9150",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-systems",
|
|
||||||
"ref": "future-26.11",
|
|
||||||
"repo": "default",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"systems_2": {
|
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1681028828,
|
"lastModified": 1681028828,
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||||
@@ -950,7 +403,7 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"systems_3": {
|
"systems_2": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1681028828,
|
"lastModified": 1681028828,
|
||||||
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
|
||||||
@@ -972,11 +425,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1775636079,
|
"lastModified": 1768158989,
|
||||||
"narHash": "sha256-pc20NRoMdiar8oPQceQT47UUZMBTiMdUuWrYu2obUP0=",
|
"narHash": "sha256-67vyT1+xClLldnumAzCTBvU0jLZ1YBcf4vANRWP3+Ak=",
|
||||||
"owner": "numtide",
|
"owner": "numtide",
|
||||||
"repo": "treefmt-nix",
|
"repo": "treefmt-nix",
|
||||||
"rev": "790751ff7fd3801feeaf96d7dc416a8d581265ba",
|
"rev": "e96d59dff5c0d7fddb9d113ba108f03c3ef99eca",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -984,28 +437,6 @@
|
|||||||
"repo": "treefmt-nix",
|
"repo": "treefmt-nix",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
|
||||||
"yants": {
|
|
||||||
"inputs": {
|
|
||||||
"nixpkgs": [
|
|
||||||
"frappix",
|
|
||||||
"std",
|
|
||||||
"lib"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1686863218,
|
|
||||||
"narHash": "sha256-kooxYm3/3ornWtVBNHM3Zh020gACUyFX2G0VQXnB+mk=",
|
|
||||||
"owner": "divnix",
|
|
||||||
"repo": "yants",
|
|
||||||
"rev": "8f0da0dba57149676aa4817ec0c880fbde7a648d",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "divnix",
|
|
||||||
"repo": "yants",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"root": "root",
|
"root": "root",
|
||||||
|
|||||||
@@ -7,12 +7,6 @@
|
|||||||
inputs.treefmt-nix.follows = "treefmt-nix";
|
inputs.treefmt-nix.follows = "treefmt-nix";
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
};
|
};
|
||||||
clan-community = {
|
|
||||||
url = "git+https://git.clan.lol/clan/clan-community";
|
|
||||||
inputs.clan-core.follows = "clan-core";
|
|
||||||
inputs.flake-parts.follows = "flake-parts";
|
|
||||||
inputs.treefmt-nix.follows = "treefmt-nix";
|
|
||||||
};
|
|
||||||
devshell = {
|
devshell = {
|
||||||
url = "github:numtide/devshell";
|
url = "github:numtide/devshell";
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
@@ -25,32 +19,20 @@
|
|||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
url = "github:nix-community/home-manager";
|
url = "github:nix-community/home-manager";
|
||||||
};
|
};
|
||||||
plasma-manager = {
|
|
||||||
url = "github:nix-community/plasma-manager";
|
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
|
||||||
inputs.home-manager.follows = "home-manager";
|
|
||||||
};
|
|
||||||
import-tree.url = "github:vic/import-tree";
|
import-tree.url = "github:vic/import-tree";
|
||||||
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
|
nixpkgs.url = "github:nixos/nixpkgs/nixpkgs-unstable";
|
||||||
|
robotnix = {
|
||||||
|
inputs.treefmt-nix.follows = "treefmt-nix";
|
||||||
|
url = "github:nix-community/robotnix";
|
||||||
|
};
|
||||||
treefmt-nix = {
|
treefmt-nix = {
|
||||||
url = "github:numtide/treefmt-nix";
|
url = "github:numtide/treefmt-nix";
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
inputs.nixpkgs.follows = "nixpkgs";
|
||||||
};
|
};
|
||||||
liminix = {
|
liminix = {
|
||||||
url = "git+https://gti.telent.net/dan/liminix";
|
url = "git+https://git.b4l.co.th/newedge/liminix?ref=refs/heads/fix-gl-ar750&rev=3f1f7c08d440130cce9262a93ce78ed7969d93cd";
|
||||||
flake = false;
|
flake = false;
|
||||||
};
|
};
|
||||||
frappix = {
|
|
||||||
url = "github:kurogeek/frappix";
|
|
||||||
inputs.nixpkgs.follows = "nixpkgs";
|
|
||||||
inputs.devshell.follows = "devshell";
|
|
||||||
};
|
|
||||||
|
|
||||||
nixos-images = {
|
|
||||||
url = "github:nix-community/nixos-images";
|
|
||||||
inputs.nixos-unstable.follows = "nixpkgs";
|
|
||||||
inputs.nixos-stable.follows = "nixpkgs";
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
outputs =
|
outputs =
|
||||||
{
|
{
|
||||||
@@ -67,9 +49,9 @@
|
|||||||
./fmt.nix
|
./fmt.nix
|
||||||
./shell.nix
|
./shell.nix
|
||||||
|
|
||||||
./overlays
|
|
||||||
./machines
|
./machines
|
||||||
./routers
|
./routers
|
||||||
|
./phones
|
||||||
./inventories
|
./inventories
|
||||||
./overlays
|
./overlays
|
||||||
./tests
|
./tests
|
||||||
@@ -89,20 +71,6 @@
|
|||||||
packages.think = pkgs.think-gtcm;
|
packages.think = pkgs.think-gtcm;
|
||||||
packages.think-be = pkgs.think-backend-gtcm;
|
packages.think-be = pkgs.think-backend-gtcm;
|
||||||
packages.file-uploader = pkgs.gtcm-file-uploader;
|
packages.file-uploader = pkgs.gtcm-file-uploader;
|
||||||
packages.installer =
|
|
||||||
(pkgs.nixos [
|
|
||||||
inputs.nixos-images.nixosModules.image-installer
|
|
||||||
{
|
|
||||||
users.users.root.openssh.authorizedKeys.keys = [
|
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAB/raxJR8gASmquP63weHelbi+da2WBJR1DgzHPNz/f"
|
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDuhpzDHBPvn8nv8RH1MRomDOaXyP4GziQm7r3MZ1Syk"
|
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcZ/p1Ofa9liwIzPWzNtONhJ7+FUWd2lCz33r81t8+w kurogeek@kurogeek"
|
|
||||||
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIOJDRQfb1+7VK5tOe8W40iryfBWYRO6Uf1r2viDjmsJtAAAABHNzaDo="
|
|
||||||
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIDgsWq+G/tcr6eUQYT7+sJeBtRmOMabgFiIgIV44XNc6AAAABHNzaDo="
|
|
||||||
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIJMi3TAuwDtIeO4MsORlBZ31HzaV5bji1fFBPcC9/tWuAAAABHNzaDo="
|
|
||||||
];
|
|
||||||
}
|
|
||||||
]).config.system.build.isoImage;
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|||||||
+80
-292
@@ -1,8 +1,5 @@
|
|||||||
{
|
{
|
||||||
imports = [
|
imports = [ ./personal-computer.nix ];
|
||||||
./personal-computer.nix
|
|
||||||
./emmie.nix
|
|
||||||
];
|
|
||||||
clan = {
|
clan = {
|
||||||
inventory = {
|
inventory = {
|
||||||
|
|
||||||
@@ -10,20 +7,16 @@
|
|||||||
glom = [
|
glom = [
|
||||||
"vega"
|
"vega"
|
||||||
"ramus"
|
"ramus"
|
||||||
"canopus"
|
|
||||||
];
|
|
||||||
poy = [
|
|
||||||
"deneb"
|
|
||||||
"bosona"
|
|
||||||
];
|
];
|
||||||
w = [ "sirius" ];
|
w = [ "sirius" ];
|
||||||
b4l = [
|
b4l = [
|
||||||
"rigel"
|
"rigel"
|
||||||
|
"neptune"
|
||||||
"rana"
|
"rana"
|
||||||
"petra"
|
"petra"
|
||||||
"alasia"
|
|
||||||
];
|
];
|
||||||
phonebox = [
|
phonebox = [
|
||||||
|
"neptune"
|
||||||
"rigel"
|
"rigel"
|
||||||
"almach"
|
"almach"
|
||||||
"alpheratz"
|
"alpheratz"
|
||||||
@@ -31,166 +24,24 @@
|
|||||||
"adhil"
|
"adhil"
|
||||||
"buna"
|
"buna"
|
||||||
];
|
];
|
||||||
|
global-network = [
|
||||||
prometheus = [
|
"rana"
|
||||||
"cursa"
|
"sirius"
|
||||||
"rigel"
|
|
||||||
"vega"
|
|
||||||
];
|
|
||||||
|
|
||||||
dm-bootstrapper = [
|
|
||||||
"rigel"
|
|
||||||
"cursa"
|
|
||||||
"deneb"
|
|
||||||
"bosona"
|
|
||||||
"canopus"
|
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
instances = {
|
instances = {
|
||||||
|
admin = {
|
||||||
borgbackup = {
|
|
||||||
module = {
|
module = {
|
||||||
name = "borgbackup";
|
name = "admin";
|
||||||
input = "clan-core";
|
input = "clan-core";
|
||||||
};
|
};
|
||||||
roles.client.machines."cursa".settings.destinations = {
|
roles.default.tags."all" = { };
|
||||||
alex = {
|
roles.default.settings.allowedKeys = {
|
||||||
repo = "ssh://borg@10.0.10.225:2222/backup/cursa/backup";
|
|
||||||
rsh = "ssh -i /run/secrets/vars/borgbackup/borgbackup.ssh";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
roles.client.machines."hadar".settings.destinations = {
|
|
||||||
alex = {
|
|
||||||
repo = "ssh://borg@10.0.10.225:2222/backup/hadar/backup";
|
|
||||||
rsh = "ssh -i /run/secrets/vars/borgbackup/borgbackup.ssh";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
roles.client.machines."procyon".settings.destinations = {
|
|
||||||
alex = {
|
|
||||||
repo = "ssh://borg@10.0.10.225:2222/backup/procyon/backup";
|
|
||||||
rsh = "ssh -i /run/secrets/vars/borgbackup/borgbackup.ssh";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
roles.client.machines."bosona".settings.destinations = {
|
|
||||||
alex = {
|
|
||||||
repo = "ssh://borg@10.0.10.225:2222/backup/bosona/backup";
|
|
||||||
rsh = "ssh -i /run/secrets/vars/borgbackup/borgbackup.ssh";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
roles.client.machines."canopus".settings.destinations = {
|
|
||||||
alex = {
|
|
||||||
repo = "ssh://borg@10.0.10.225:2222/backup/canopus/backup";
|
|
||||||
rsh = "ssh -i /run/secrets/vars/borgbackup/borgbackup.ssh";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
roles.client.machines."deneb".settings.destinations = {
|
|
||||||
alex = {
|
|
||||||
repo = "ssh://borg@10.0.10.225:2222/backup/deneb/backup";
|
|
||||||
rsh = "ssh -i /run/secrets/vars/borgbackup/borgbackup.ssh";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
roles.client.machines."alasia".settings.destinations = {
|
|
||||||
alex = {
|
|
||||||
repo = "ssh://borg@10.0.10.225:2222/backup/alasia/backup";
|
|
||||||
rsh = "ssh -i /run/secrets/vars/borgbackup/borgbackup.ssh";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
data-mesher = {
|
|
||||||
module = {
|
|
||||||
name = "data-mesher";
|
|
||||||
input = "clan-core";
|
|
||||||
};
|
|
||||||
roles.bootstrap.tags = [ "dm-bootstrapper" ];
|
|
||||||
roles.default.tags = [ "all" ];
|
|
||||||
roles.default.settings.interfaces = [ "ygg" ];
|
|
||||||
};
|
|
||||||
|
|
||||||
auto-pull-update = {
|
|
||||||
module = {
|
|
||||||
name = "dm-pull-deploy";
|
|
||||||
input = "clan-community";
|
|
||||||
};
|
|
||||||
roles.push.machines."rigel".settings = {
|
|
||||||
gitUrl = "https://git.b4l.co.th/newedge/infra.git";
|
|
||||||
branch = "main";
|
|
||||||
};
|
|
||||||
roles.push.extraModules = [
|
|
||||||
(
|
|
||||||
{ pkgs, config, ... }:
|
|
||||||
{
|
|
||||||
# work around until upstream is fixed
|
|
||||||
environment.systemPackages = [
|
|
||||||
(pkgs.writeShellApplication {
|
|
||||||
name = "custom-dm-send-deploy";
|
|
||||||
runtimeInputs = [
|
|
||||||
config.services.data-mesher.package
|
|
||||||
pkgs.git
|
|
||||||
pkgs.nix
|
|
||||||
pkgs.jq
|
|
||||||
];
|
|
||||||
text =
|
|
||||||
let
|
|
||||||
settings.gitUrl = "https://git.b4l.co.th/newedge/infra.git";
|
|
||||||
settings.branch = "main";
|
|
||||||
in
|
|
||||||
''
|
|
||||||
if [ $# -gt 1 ]; then
|
|
||||||
echo "Usage: dm-send-deploy [<flake-ref>]"
|
|
||||||
echo "Without arguments, sends the latest commit on '${settings.branch}' from ${settings.gitUrl}"
|
|
||||||
echo "Example: dm-send-deploy git+https://example.com/repo.git?rev=abc123..."
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
KEY="${config.clan.core.vars.generators.dm-pull-deploy-signing-key.files."signing.key".path}"
|
|
||||||
if [ ! -r "$KEY" ]; then
|
|
||||||
echo "Error: cannot read signing key at $KEY (are you root?)"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ $# -eq 1 ]; then
|
|
||||||
FLAKE_REF="$1"
|
|
||||||
else
|
|
||||||
REV=$(git ls-remote "${settings.gitUrl}" "refs/heads/${settings.branch}" | cut -f1)
|
|
||||||
if [ -z "$REV" ]; then
|
|
||||||
echo "Error: could not determine latest commit on ${settings.branch} from ${settings.gitUrl}"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
FLAKE_REF="git+${settings.gitUrl}?rev=$REV"
|
|
||||||
fi
|
|
||||||
|
|
||||||
TMPFILE=$(mktemp)
|
|
||||||
trap 'rm -f "$TMPFILE"' EXIT
|
|
||||||
|
|
||||||
printf '%s' "$FLAKE_REF" > "$TMPFILE"
|
|
||||||
|
|
||||||
NETWORK_ID="${config.clan.core.vars.generators.data-mesher-network.files."network.pub".path}"
|
|
||||||
|
|
||||||
data-mesher file update "$TMPFILE" \
|
|
||||||
--url http://localhost:7331 \
|
|
||||||
--network-id "$NETWORK_ID" \
|
|
||||||
--key "$KEY" \
|
|
||||||
--name "dm_pull_deploy/target"
|
|
||||||
|
|
||||||
echo "Deployment target pushed: $FLAKE_REF"
|
|
||||||
'';
|
|
||||||
})
|
|
||||||
];
|
|
||||||
}
|
|
||||||
)
|
|
||||||
];
|
|
||||||
roles.default.tags = [ "all" ];
|
|
||||||
roles.default.settings.action = "switch";
|
|
||||||
};
|
|
||||||
|
|
||||||
sshd = {
|
|
||||||
roles.server.tags."all" = { };
|
|
||||||
roles.server.settings = {
|
|
||||||
authorizedKeys = {
|
|
||||||
"berwn" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAB/raxJR8gASmquP63weHelbi+da2WBJR1DgzHPNz/f";
|
"berwn" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAB/raxJR8gASmquP63weHelbi+da2WBJR1DgzHPNz/f";
|
||||||
"davhau" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDuhpzDHBPvn8nv8RH1MRomDOaXyP4GziQm7r3MZ1Syk";
|
"davhau" = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDuhpzDHBPvn8nv8RH1MRomDOaXyP4GziQm7r3MZ1Syk";
|
||||||
|
"vi" =
|
||||||
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAmgyEGuY/r7SDlJgrzYmQqpcWS5W+fCzRi3OS59ne4W openpgp:0xFF687387";
|
||||||
"kurogeek" =
|
"kurogeek" =
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcZ/p1Ofa9liwIzPWzNtONhJ7+FUWd2lCz33r81t8+w kurogeek@kurogeek";
|
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEcZ/p1Ofa9liwIzPWzNtONhJ7+FUWd2lCz33r81t8+w kurogeek@kurogeek";
|
||||||
"matthewcroughan" =
|
"matthewcroughan" =
|
||||||
@@ -201,18 +52,6 @@
|
|||||||
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIJMi3TAuwDtIeO4MsORlBZ31HzaV5bji1fFBPcC9/tWuAAAABHNzaDo=";
|
"sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIJMi3TAuwDtIeO4MsORlBZ31HzaV5bji1fFBPcC9/tWuAAAABHNzaDo=";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
|
||||||
|
|
||||||
root-password = {
|
|
||||||
module = {
|
|
||||||
name = "users";
|
|
||||||
input = "clan-core";
|
|
||||||
};
|
|
||||||
roles.default.tags."all" = { };
|
|
||||||
roles.default.settings = {
|
|
||||||
user = "root";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
tor = {
|
tor = {
|
||||||
module = {
|
module = {
|
||||||
@@ -241,13 +80,7 @@
|
|||||||
name = "zerotier";
|
name = "zerotier";
|
||||||
input = "clan-core";
|
input = "clan-core";
|
||||||
};
|
};
|
||||||
roles.controller.machines."vega" = {
|
roles.controller.machines."vega" = { };
|
||||||
settings.allowedIds = [
|
|
||||||
"dbe44c0287" # Alex-gateway
|
|
||||||
"b0e0b84fd3" # Alex
|
|
||||||
"2bd36db8cc" # kurogeek-thinkpad
|
|
||||||
];
|
|
||||||
};
|
|
||||||
roles.peer.tags.glom = { };
|
roles.peer.tags.glom = { };
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -256,48 +89,16 @@
|
|||||||
name = "zerotier";
|
name = "zerotier";
|
||||||
input = "clan-core";
|
input = "clan-core";
|
||||||
};
|
};
|
||||||
roles.controller.machines."rigel" = {
|
roles.controller.machines."rigel" = { };
|
||||||
settings.allowedIds = [
|
|
||||||
"dbe44c0287" # Alex-gateway
|
|
||||||
"b0e0b84fd3" # Alex
|
|
||||||
"2bd36db8cc" # kurogeek-thinkpad
|
|
||||||
];
|
|
||||||
};
|
|
||||||
roles.peer.tags.b4l = { };
|
roles.peer.tags.b4l = { };
|
||||||
};
|
};
|
||||||
|
|
||||||
poy-network = {
|
|
||||||
module = {
|
|
||||||
name = "zerotier";
|
|
||||||
input = "clan-core";
|
|
||||||
};
|
|
||||||
roles.controller.machines."deneb" = {
|
|
||||||
settings.allowedIps = [
|
|
||||||
#kurogeek
|
|
||||||
"fdfe:7bf:a795:4524:4c99:932b:d36d:b8cc"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
roles.peer.tags."poy" = { };
|
|
||||||
};
|
|
||||||
|
|
||||||
internet = {
|
|
||||||
module.name = "internet";
|
|
||||||
roles.default.machines = {
|
|
||||||
ramus.settings.host = "5.223.63.55";
|
|
||||||
tangra.settings.host = "5.223.65.50";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
yggdrasil-global-network = {
|
yggdrasil-global-network = {
|
||||||
module = {
|
module = {
|
||||||
name = "yggdrasil";
|
name = "yggdrasil";
|
||||||
input = "clan-core";
|
input = "clan-core";
|
||||||
};
|
};
|
||||||
roles.default.tags."all" = { };
|
roles.default.tags."global-network" = { };
|
||||||
roles.default.settings.extraYggdrasilIPs = [
|
|
||||||
# kurogeek's laptop
|
|
||||||
"200:c8db:ea9b:5bdc:44ed:ad87:462a:6bd0"
|
|
||||||
];
|
|
||||||
roles.default.settings.extraPeers = [
|
roles.default.settings.extraPeers = [
|
||||||
"tls://ygg.jjolly.dev:3443"
|
"tls://ygg.jjolly.dev:3443"
|
||||||
"tls://[2602:fc24:18:7a42::1]:993"
|
"tls://[2602:fc24:18:7a42::1]:993"
|
||||||
@@ -306,22 +107,19 @@
|
|||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
|
||||||
newedge-headscale = {
|
yggdrasil-phone-network = {
|
||||||
module = {
|
module = {
|
||||||
name = "headscale";
|
name = "yggdrasil";
|
||||||
input = "self";
|
input = "clan-core";
|
||||||
};
|
};
|
||||||
roles.server.machines."alasia".settings = {
|
roles.default.tags."phonebox" = { };
|
||||||
public_url = "tailvpn.public.newedge.house";
|
roles.default.settings.extraPeers = [
|
||||||
base_domain = "tailnet.newedge.house";
|
"tls://ygg.jjolly.dev:3443"
|
||||||
advertise_routes = [ "10.0.10.0/24" ];
|
"tls://[2602:fc24:18:7a42::1]:993"
|
||||||
nameservers = [
|
"tcp://leo.node.3dt.net:9002"
|
||||||
"10.0.10.82"
|
"tcp://ygg-kcmo.incognet.io:8883"
|
||||||
"1.1.1.1"
|
|
||||||
"8.8.8.8"
|
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
};
|
|
||||||
|
|
||||||
phonebox = {
|
phonebox = {
|
||||||
module = {
|
module = {
|
||||||
@@ -332,15 +130,64 @@
|
|||||||
roles.default.machines."adhil".settings = {
|
roles.default.machines."adhil".settings = {
|
||||||
ata-ethernet-iface = "end0";
|
ata-ethernet-iface = "end0";
|
||||||
};
|
};
|
||||||
roles.default.machines."rigel".settings = {
|
|
||||||
extraClientNumbers = [
|
|
||||||
"01"
|
|
||||||
"02"
|
|
||||||
];
|
|
||||||
extraFixedIPClient = { };
|
|
||||||
};
|
|
||||||
};
|
};
|
||||||
|
|
||||||
|
pocket-id = {
|
||||||
|
module = {
|
||||||
|
name = "pocket-id";
|
||||||
|
input = "self";
|
||||||
|
};
|
||||||
|
roles.default.machines.b4l = { };
|
||||||
|
};
|
||||||
|
nextcloud = {
|
||||||
|
module = {
|
||||||
|
name = "nextcloud";
|
||||||
|
input = "self";
|
||||||
|
};
|
||||||
|
roles.default.machines.b4l = { };
|
||||||
|
};
|
||||||
|
stirling-pdf = {
|
||||||
|
module = {
|
||||||
|
name = "stirling-pdf";
|
||||||
|
input = "self";
|
||||||
|
};
|
||||||
|
roles.default.machines.b4l = { };
|
||||||
|
};
|
||||||
|
actual-budget = {
|
||||||
|
module = {
|
||||||
|
name = "actual-budget";
|
||||||
|
input = "self";
|
||||||
|
};
|
||||||
|
roles.default.machines.b4l = { };
|
||||||
|
};
|
||||||
|
victoriametrics = {
|
||||||
|
module = {
|
||||||
|
name = "victoriametrics";
|
||||||
|
input = "self";
|
||||||
|
};
|
||||||
|
roles.default.machines.b4l = { };
|
||||||
|
};
|
||||||
|
vikunja = {
|
||||||
|
module = {
|
||||||
|
name = "vikunja";
|
||||||
|
input = "self";
|
||||||
|
};
|
||||||
|
roles.default.machines.b4l = { };
|
||||||
|
};
|
||||||
|
grafana = {
|
||||||
|
module = {
|
||||||
|
name = "grafana";
|
||||||
|
input = "self";
|
||||||
|
};
|
||||||
|
roles.default.machines.b4l = { };
|
||||||
|
};
|
||||||
|
paperless = {
|
||||||
|
module = {
|
||||||
|
name = "paperless";
|
||||||
|
input = "self";
|
||||||
|
};
|
||||||
|
roles.default.machines.b4l = { };
|
||||||
|
};
|
||||||
pulse-stream = {
|
pulse-stream = {
|
||||||
module = {
|
module = {
|
||||||
name = "pulse-stream";
|
name = "pulse-stream";
|
||||||
@@ -433,65 +280,6 @@
|
|||||||
dataDir = "/mnt/hdd/samba";
|
dataDir = "/mnt/hdd/samba";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
wordpress = {
|
|
||||||
module = {
|
|
||||||
name = "wordpress";
|
|
||||||
input = "self";
|
|
||||||
};
|
|
||||||
roles.server.machines."tangra".settings = {
|
|
||||||
tenants = [
|
|
||||||
"poyfestival.com"
|
|
||||||
];
|
|
||||||
phpfpmOptions = ''
|
|
||||||
upload_max_filesize=64M
|
|
||||||
post_max_size=128M
|
|
||||||
'';
|
|
||||||
wpExtraConfig = ''
|
|
||||||
define('WP_MEMORY_LIMIT', '256M');
|
|
||||||
define('WP_DEBUG', false);
|
|
||||||
define('WP_DEBUG_DISPLAY', false);
|
|
||||||
define('WP_DEBUG_LOG', false);
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
prometheus-monitoring = {
|
|
||||||
module = {
|
|
||||||
name = "prometheus";
|
|
||||||
input = "self";
|
|
||||||
};
|
|
||||||
roles.server.machines."cursa".settings = {
|
|
||||||
matrix-alertmanager = {
|
|
||||||
enable = true;
|
|
||||||
homeserverUrl = "https://matrix-client.matrix.org";
|
|
||||||
matrixUser = "@nixapollo:matrix.org";
|
|
||||||
matrixRooms = [
|
|
||||||
{
|
|
||||||
receivers = [
|
|
||||||
"matrix"
|
|
||||||
];
|
|
||||||
roomId = "!rqIrWqPvsXqMgYpcNZ:matrix.org";
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
roles.nodes.machines = {
|
|
||||||
vega.settings = {
|
|
||||||
exporters.smartctl = { };
|
|
||||||
exporters.zfs = { };
|
|
||||||
};
|
|
||||||
rigel.settings = {
|
|
||||||
exporters.smartctl = { };
|
|
||||||
};
|
|
||||||
sirius.settings = {
|
|
||||||
exporters.smartctl = { };
|
|
||||||
exporters.zfs = { };
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,43 +0,0 @@
|
|||||||
{ config, ... }:
|
|
||||||
let
|
|
||||||
username = "emmie";
|
|
||||||
userhome = "/home/${username}";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
clan.inventory = {
|
|
||||||
tags = {
|
|
||||||
emmie = [ "rana" ];
|
|
||||||
};
|
|
||||||
|
|
||||||
instances = {
|
|
||||||
emmie-syncthing = {
|
|
||||||
module = {
|
|
||||||
name = "syncthing";
|
|
||||||
input = "clan-core";
|
|
||||||
};
|
|
||||||
roles.peer.tags.emmie = { };
|
|
||||||
roles.peer.settings = {
|
|
||||||
folders = {
|
|
||||||
Syncthing.path = "${userhome}/Share/Syncthing";
|
|
||||||
Desktop.path = "${userhome}/Desktop";
|
|
||||||
};
|
|
||||||
extraDevices = {
|
|
||||||
pixel7a = {
|
|
||||||
id = "CEUJMEG-SOHXIJF-G2FT5QB-6MZW3EN-PONI3QN-HPEIOSU-IMSLGW7-XUU6BQK";
|
|
||||||
name = "eris";
|
|
||||||
addresses = [ "dynamic" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
roles.peer.extraModules = [
|
|
||||||
{
|
|
||||||
config.services.syncthing = {
|
|
||||||
user = username;
|
|
||||||
dataDir = "${userhome}/Share";
|
|
||||||
};
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -14,9 +14,14 @@
|
|||||||
instances = {
|
instances = {
|
||||||
emmie-home = {
|
emmie-home = {
|
||||||
module = {
|
module = {
|
||||||
name = "emmie-home";
|
name = "home-user";
|
||||||
input = "self";
|
input = "self";
|
||||||
};
|
};
|
||||||
|
roles.default.settings = {
|
||||||
|
username = "emmie";
|
||||||
|
kbLayout = "us,th";
|
||||||
|
kbOptions = "grp:win_space_toggle,grp:alt_shift_toggle";
|
||||||
|
};
|
||||||
roles.default.machines."rana" = { };
|
roles.default.machines."rana" = { };
|
||||||
};
|
};
|
||||||
chocolate-home = {
|
chocolate-home = {
|
||||||
|
|||||||
+1
-25
@@ -22,37 +22,13 @@
|
|||||||
"installedAt": 1765343708
|
"installedAt": 1765343708
|
||||||
},
|
},
|
||||||
"rana": {
|
"rana": {
|
||||||
"installedAt": 1773134236
|
"installedAt": 1768294839
|
||||||
},
|
},
|
||||||
"petra": {
|
"petra": {
|
||||||
"installedAt": 1769064458
|
"installedAt": 1769064458
|
||||||
},
|
},
|
||||||
"sirius": {
|
"sirius": {
|
||||||
"installedAt": 1770974584
|
"installedAt": 1770974584
|
||||||
},
|
|
||||||
"deneb": {
|
|
||||||
"installedAt": 1775718970
|
|
||||||
},
|
|
||||||
"canopus": {
|
|
||||||
"installedAt": 1775793532
|
|
||||||
},
|
|
||||||
"hadar": {
|
|
||||||
"installedAt": 1774427255
|
|
||||||
},
|
|
||||||
"procyon": {
|
|
||||||
"installedAt": 1775458442
|
|
||||||
},
|
|
||||||
"alasia": {
|
|
||||||
"installedAt": 1778661666
|
|
||||||
},
|
|
||||||
"bosona": {
|
|
||||||
"installedAt": 1779098893
|
|
||||||
},
|
|
||||||
"tangra": {
|
|
||||||
"installedAt": 1779958921
|
|
||||||
},
|
|
||||||
"cursa": {
|
|
||||||
"installedAt": 1782187627
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -8,7 +8,6 @@
|
|||||||
# clan.core.networking.targetHost = "root@";
|
# clan.core.networking.targetHost = "root@";
|
||||||
|
|
||||||
clan.core.settings.name = "adhil";
|
clan.core.settings.name = "adhil";
|
||||||
clan.core.settings.machine.description =
|
# clan.meta.description = "Raspberry Pi 4 SBC board for one of w phone network. (With w office)";
|
||||||
"Raspberry Pi 4 SBC board for one of w phone network. (With w office)";
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,15 +0,0 @@
|
|||||||
{
|
|
||||||
clan.core.settings.machine.description = "VM machine to host headplane instance";
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = {
|
|
||||||
system = "x86_64-linux";
|
|
||||||
};
|
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [
|
|
||||||
80
|
|
||||||
443
|
|
||||||
];
|
|
||||||
|
|
||||||
system.stateVersion = "25.11";
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
|
||||||
}
|
|
||||||
@@ -1,85 +0,0 @@
|
|||||||
let
|
|
||||||
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
|
||||||
os = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
systemd-boot = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
efi = {
|
|
||||||
canTouchEfiVariables = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = false;
|
|
||||||
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
"os-${hashDisk os}" = {
|
|
||||||
type = "disk";
|
|
||||||
device = os;
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "1G";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
system = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "zfs";
|
|
||||||
pool = "zroot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
zpool = {
|
|
||||||
zroot = {
|
|
||||||
type = "zpool";
|
|
||||||
rootFsOptions = {
|
|
||||||
mountpoint = "none";
|
|
||||||
compression = "lz4";
|
|
||||||
acltype = "posixacl";
|
|
||||||
xattr = "sa";
|
|
||||||
"com.sun:auto-snapshot" = "true";
|
|
||||||
};
|
|
||||||
options.ashift = "12";
|
|
||||||
datasets = {
|
|
||||||
"root" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "none";
|
|
||||||
};
|
|
||||||
"root/nixos" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
"root/home" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/home";
|
|
||||||
mountpoint = "/home";
|
|
||||||
};
|
|
||||||
"root/tmp" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
options = {
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
sync = "disabled";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -8,6 +8,6 @@
|
|||||||
# clan.core.networking.targetHost = "root@";
|
# clan.core.networking.targetHost = "root@";
|
||||||
|
|
||||||
clan.core.settings.name = "almach";
|
clan.core.settings.name = "almach";
|
||||||
clan.core.settings.machine.description = "Radxa X4 SBC board for one of w phone network.";
|
# clan.meta.description = "Radxa X4 SBC board for one of w phone network.";
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,8 +14,6 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
disko.devices = {
|
||||||
disk = {
|
disk = {
|
||||||
"os-${hashDisk os}" = {
|
"os-${hashDisk os}" = {
|
||||||
|
|||||||
@@ -8,6 +8,6 @@
|
|||||||
# clan.core.networking.targetHost = "root@";
|
# clan.core.networking.targetHost = "root@";
|
||||||
|
|
||||||
clan.core.settings.name = "alpheratz";
|
clan.core.settings.name = "alpheratz";
|
||||||
clan.core.settings.machine.description = "Radxa X4 SBC board for one of w phone network.";
|
# clan.meta.description = "Radxa X4 SBC board for one of w phone network.";
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,8 +14,6 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
disko.devices = {
|
||||||
disk = {
|
disk = {
|
||||||
"os-${hashDisk os}" = {
|
"os-${hashDisk os}" = {
|
||||||
|
|||||||
@@ -1,15 +1,25 @@
|
|||||||
|
{ inputs, config, ... }:
|
||||||
{
|
{
|
||||||
system.stateVersion = "25.11";
|
imports = [
|
||||||
|
(inputs.import-tree ./services)
|
||||||
|
];
|
||||||
nixpkgs.hostPlatform = {
|
nixpkgs.hostPlatform = {
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
};
|
};
|
||||||
|
boot.loader.grub.devices = [ "/dev/disk/by-id/FIXME" ];
|
||||||
clan.core.settings.name = "tangra";
|
fileSystems = {
|
||||||
clan.core.settings.machine.description =
|
"/".device = "/dev/FIXME";
|
||||||
"A Hetzner VPS machine own by Alex. This is a machine for poyfestival.com";
|
};
|
||||||
|
networking.fqdn = "b4l.co.th";
|
||||||
|
system.stateVersion = "25.11";
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
clan.core.sops.defaultGroups = [ "admins" ];
|
||||||
|
|
||||||
|
security.acme.defaults.email = "admin@b4l.co.th";
|
||||||
|
security.acme.acceptTerms = true;
|
||||||
|
services.nginx.virtualHosts."${config.networking.fqdn}" = {
|
||||||
|
enableACME = true;
|
||||||
|
};
|
||||||
|
|
||||||
clan.core.vars.generators.acme = {
|
clan.core.vars.generators.acme = {
|
||||||
share = true;
|
share = true;
|
||||||
files.email.secret = false;
|
files.email.secret = false;
|
||||||
@@ -23,10 +33,4 @@
|
|||||||
cat $prompts/email > $out/email
|
cat $prompts/email > $out/email
|
||||||
'';
|
'';
|
||||||
};
|
};
|
||||||
|
|
||||||
users.users.nginx.extraGroups = [ "acme" ];
|
|
||||||
|
|
||||||
security.acme.acceptTerms = true;
|
|
||||||
|
|
||||||
imports = [ ];
|
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
{ config, ... }:
|
||||||
|
let
|
||||||
|
abDomain = "${config.clan.core.vars.generators.b4l-actual-budget.files.subdomain.value}.${config.networking.fqdn}";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
clan.core.vars.generators.b4l-actual-budget = {
|
||||||
|
files.subdomain.secret = false;
|
||||||
|
|
||||||
|
prompts = {
|
||||||
|
subdomain = {
|
||||||
|
persist = true;
|
||||||
|
type = "line";
|
||||||
|
description = "Sub-domain for Actual Budget app. Default:(budget)";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
script = ''cat $prompts/subdomain || echo -n "budget" > $out/subdomain'';
|
||||||
|
};
|
||||||
|
|
||||||
|
services.actual = {
|
||||||
|
settings = {
|
||||||
|
allowedLoginMethods = [
|
||||||
|
"password"
|
||||||
|
"openid"
|
||||||
|
];
|
||||||
|
trustedProxies = [ "127.0.0.1" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
services.nginx.virtualHosts."${abDomain}" = {
|
||||||
|
useACMEHost = "${config.networking.fqdn}";
|
||||||
|
forceSSL = true;
|
||||||
|
locations."/" = {
|
||||||
|
proxyPass = "http://localhost:${builtins.toString config.services.actual.settings.port}";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,79 @@
|
|||||||
|
{
|
||||||
|
pkgs,
|
||||||
|
config,
|
||||||
|
lib,
|
||||||
|
...
|
||||||
|
}:
|
||||||
|
with lib;
|
||||||
|
let
|
||||||
|
serviceName = "${config.networking.hostName}-grafana";
|
||||||
|
gfDomain = "${
|
||||||
|
config.clan.core.vars.generators."${serviceName}".files.subdomain.value
|
||||||
|
}.${config.networking.fqdn}";
|
||||||
|
|
||||||
|
settingsFormatIni = pkgs.formats.ini {
|
||||||
|
listToValue = concatMapStringsSep " " (generators.mkValueStringDefault { });
|
||||||
|
mkKeyValue = generators.mkKeyValueDefault {
|
||||||
|
mkValueString = v: if v == null then "" else generators.mkValueStringDefault { } v;
|
||||||
|
} "=";
|
||||||
|
};
|
||||||
|
configFile = settingsFormatIni.generate "config.ini" config.services.grafana.settings;
|
||||||
|
in
|
||||||
|
{
|
||||||
|
clan.core.vars.generators."${serviceName}" = {
|
||||||
|
files = {
|
||||||
|
adminpassword.secret = true;
|
||||||
|
subdomain.secret = false;
|
||||||
|
};
|
||||||
|
prompts = {
|
||||||
|
subdomain = {
|
||||||
|
persist = true;
|
||||||
|
type = "line";
|
||||||
|
description = "Sub-domain for Grafana. Default:(grafana)";
|
||||||
|
};
|
||||||
|
adminpassword = {
|
||||||
|
persist = true;
|
||||||
|
type = "hidden";
|
||||||
|
description = "Password for the admin user. Leave empty to auto-generate.";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
runtimeInputs = [
|
||||||
|
pkgs.xkcdpass
|
||||||
|
pkgs.coreutils
|
||||||
|
];
|
||||||
|
|
||||||
|
script = ''
|
||||||
|
prompt_domain=$(cat "$prompts"/subdomain)
|
||||||
|
if [[ -n "''${prompt_domain-}" ]]; then
|
||||||
|
echo $prompt_domain | tr -d "\n" > "$out"/subdomain
|
||||||
|
else
|
||||||
|
echo -n "grafana" > "$out"/subdomain
|
||||||
|
fi
|
||||||
|
|
||||||
|
prompt_password=$(cat "$prompts"/adminpassword)
|
||||||
|
if [[ -n "''${prompt_password-}" ]]; then
|
||||||
|
echo "$prompt_password" | tr -d "\n" > "$out"/adminpassword
|
||||||
|
else
|
||||||
|
xkcdpass --numwords 4 --delimiter - --count 1 | tr -d "\n" > "$out"/adminpassword
|
||||||
|
fi
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
systemd.services.grafana.serviceConfig.ExecStartPre = [
|
||||||
|
"+${pkgs.writeShellScript "grafana-set-password" ''
|
||||||
|
${pkgs.grafana}/bin/grafana cli --homepath ${config.services.grafana.dataDir} --config ${configFile} admin reset-admin-password $(cat ${
|
||||||
|
config.clan.core.vars.generators."${serviceName}".files.adminpassword.path
|
||||||
|
})
|
||||||
|
''}"
|
||||||
|
];
|
||||||
|
|
||||||
|
services.nginx.virtualHosts."${gfDomain}" = {
|
||||||
|
forceSSL = true;
|
||||||
|
useACMEHost = "${config.networking.fqdn}";
|
||||||
|
locations."/" = {
|
||||||
|
proxyPass = "http://localhost:${builtins.toString config.services.grafana.settings.server.http_port}";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
{ config, pkgs, ... }:
|
||||||
|
let
|
||||||
|
ncDomain = "${config.clan.core.vars.generators.b4l-nextcloud.files.subdomain.value}.${config.networking.fqdn}";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
clan.core.vars.generators.b4l-nextcloud = {
|
||||||
|
files.subdomain.secret = false;
|
||||||
|
|
||||||
|
prompts = {
|
||||||
|
subdomain = {
|
||||||
|
persist = true;
|
||||||
|
type = "line";
|
||||||
|
description = "Sub-domain for Nextcloud app. Default:(cloud)";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
script = ''cat $prompts/subdomain || echo -n "cloud" > $out/subdomain'';
|
||||||
|
};
|
||||||
|
|
||||||
|
services.nextcloud = {
|
||||||
|
hostName = ncDomain;
|
||||||
|
package = pkgs.nextcloud32;
|
||||||
|
|
||||||
|
settings = {
|
||||||
|
|
||||||
|
overwriteprotocol = "https";
|
||||||
|
trusted_domains = [ ];
|
||||||
|
trusted_proxies = [ ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
services.nginx.virtualHosts."${ncDomain}" = {
|
||||||
|
useACMEHost = "${config.networking.fqdn}";
|
||||||
|
forceSSL = true;
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,67 @@
|
|||||||
|
{ config, pkgs, ... }:
|
||||||
|
let
|
||||||
|
serviceName = "${config.networking.hostName}-paperless";
|
||||||
|
domain-name = "${
|
||||||
|
config.clan.core.vars.generators."${serviceName}".files.subdomain.value
|
||||||
|
}.${config.networking.fqdn}";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
clan.core.vars.generators."${serviceName}" = {
|
||||||
|
files = {
|
||||||
|
subdomain.secret = false;
|
||||||
|
adminpassword = {
|
||||||
|
secret = true;
|
||||||
|
owner = config.services.paperless.user;
|
||||||
|
group = config.services.paperless.user;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
prompts = {
|
||||||
|
subdomain = {
|
||||||
|
persist = true;
|
||||||
|
type = "line";
|
||||||
|
description = "Sub-domain for Paperless. Default:(paperless)";
|
||||||
|
};
|
||||||
|
adminpassword = {
|
||||||
|
persist = true;
|
||||||
|
type = "hidden";
|
||||||
|
description = "Password for the admin user. Leave empty to auto-generate.";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
runtimeInputs = [
|
||||||
|
pkgs.xkcdpass
|
||||||
|
pkgs.coreutils
|
||||||
|
];
|
||||||
|
|
||||||
|
script = ''
|
||||||
|
prompt_domain=$(cat "$prompts"/subdomain)
|
||||||
|
if [[ -n "''${prompt_domain-}" ]]; then
|
||||||
|
echo $prompt_domain | tr -d "\n" > "$out"/subdomain
|
||||||
|
else
|
||||||
|
echo -n "paperless" > "$out"/subdomain
|
||||||
|
fi
|
||||||
|
|
||||||
|
prompt_password=$(cat "$prompts"/adminpassword)
|
||||||
|
if [[ -n "''${prompt_password-}" ]]; then
|
||||||
|
echo "$prompt_password" | tr -d "\n" > "$out"/adminpassword
|
||||||
|
else
|
||||||
|
xkcdpass --numwords 4 --delimiter - --count 1 | tr -d "\n" > "$out"/adminpassword
|
||||||
|
fi
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
environment.systemPackages = [ pkgs.toybox ];
|
||||||
|
|
||||||
|
services.paperless = {
|
||||||
|
passwordFile = config.clan.core.vars.generators."${serviceName}".files.adminpassword.path;
|
||||||
|
};
|
||||||
|
|
||||||
|
services.nginx.virtualHosts."${domain-name}" = {
|
||||||
|
forceSSL = true;
|
||||||
|
useACMEHost = "${config.networking.fqdn}";
|
||||||
|
locations."/" = {
|
||||||
|
proxyPass = "http://localhost:${builtins.toString config.services.paperless.port}";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
{ config, ... }:
|
||||||
|
let
|
||||||
|
pidDomain = "${config.clan.core.vars.generators.b4l-pocket-id.files.subdomain.value}.${config.networking.fqdn}";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
clan.core.vars.generators.b4l-pocket-id = {
|
||||||
|
files.subdomain.secret = false;
|
||||||
|
|
||||||
|
prompts = {
|
||||||
|
subdomain = {
|
||||||
|
persist = true;
|
||||||
|
type = "line";
|
||||||
|
description = "Sub-domain for Pocket-ID app. Default:(auth)";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
script = ''cat $prompts/subdomain || echo -n "auth" > $out/subdomain'';
|
||||||
|
};
|
||||||
|
|
||||||
|
services.pocket-id = {
|
||||||
|
settings = {
|
||||||
|
APP_ENV = "production";
|
||||||
|
APP_URL = "https://${pidDomain}";
|
||||||
|
TRUST_PROXY = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
services.nginx.virtualHosts."${pidDomain}" = {
|
||||||
|
useACMEHost = "${config.networking.fqdn}";
|
||||||
|
forceSSL = true;
|
||||||
|
locations."/" = {
|
||||||
|
proxyPass = "http://localhost:${builtins.toString config.services.pocket-id.settings.PORT}";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
{ config, ... }:
|
||||||
|
let
|
||||||
|
stDomain = "${config.clan.core.vars.generators.b4l-stirling-pdf.files.subdomain.value}.${config.networking.fqdn}";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
clan.core.vars.generators.b4l-stirling-pdf = {
|
||||||
|
files.subdomain.secret = false;
|
||||||
|
|
||||||
|
prompts = {
|
||||||
|
subdomain = {
|
||||||
|
persist = true;
|
||||||
|
type = "line";
|
||||||
|
description = "Sub-domain for Stirling PDF app. Default:(pdf)";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
script = ''cat $prompts/subdomain || echo -n "pdf" > $out/subdomain'';
|
||||||
|
};
|
||||||
|
|
||||||
|
services.nginx.virtualHosts."${stDomain}" = {
|
||||||
|
forceSSL = true;
|
||||||
|
useACMEHost = "${config.networking.fqdn}";
|
||||||
|
locations."/" = {
|
||||||
|
proxyPass = "http://localhost:${builtins.toString config.services.stirling-pdf.environment.SERVER_PORT}";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,73 @@
|
|||||||
|
{ config, pkgs, ... }:
|
||||||
|
let
|
||||||
|
vmDomain = "${config.clan.core.vars.generators.b4l-victoriametrics.files.subdomain.value}.${config.networking.fqdn}";
|
||||||
|
in
|
||||||
|
{
|
||||||
|
clan.core.vars.generators.b4l-victoriametrics = {
|
||||||
|
files.subdomain.secret = false;
|
||||||
|
files.adminuser.secret = false;
|
||||||
|
files.adminpassword.secret = true;
|
||||||
|
|
||||||
|
prompts = {
|
||||||
|
subdomain = {
|
||||||
|
persist = true;
|
||||||
|
type = "line";
|
||||||
|
description = "Sub-domain for Victoria Metrics app. Default:(metrics)";
|
||||||
|
};
|
||||||
|
adminuser = {
|
||||||
|
persist = true;
|
||||||
|
type = "line";
|
||||||
|
description = "Username for an admin user. Default:(admin)";
|
||||||
|
};
|
||||||
|
adminpassword = {
|
||||||
|
persist = true;
|
||||||
|
type = "hidden";
|
||||||
|
description = "Password for the admin user. Leave empty to auto-generate.";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
runtimeInputs = [
|
||||||
|
pkgs.xkcdpass
|
||||||
|
pkgs.coreutils
|
||||||
|
];
|
||||||
|
|
||||||
|
script = ''
|
||||||
|
prompt_domain=$(cat "$prompts"/subdomain)
|
||||||
|
if [[ -n "''${prompt_domain-}" ]]; then
|
||||||
|
echo $prompt_domain | tr -d "\n" > "$out"/subdomain
|
||||||
|
else
|
||||||
|
echo -n "metrics" > "$out"/subdomain
|
||||||
|
fi
|
||||||
|
|
||||||
|
prompt_adminuser=$(cat "$prompts"/adminuser)
|
||||||
|
if [[ -n "''${prompt_adminuser-}" ]]; then
|
||||||
|
echo $prompt_adminuser | tr -d "\n" > "$out"/adminuser
|
||||||
|
else
|
||||||
|
echo -n "admin" > "$out"/adminuser
|
||||||
|
fi
|
||||||
|
|
||||||
|
prompt_password=$(cat "$prompts"/adminpassword)
|
||||||
|
if [[ -n "''${prompt_password-}" ]]; then
|
||||||
|
echo "$prompt_password" | tr -d "\n" > "$out"/adminpassword
|
||||||
|
else
|
||||||
|
xkcdpass --numwords 4 --delimiter - --count 1 | tr -d "\n" > "$out"/adminpassword
|
||||||
|
fi
|
||||||
|
'';
|
||||||
|
};
|
||||||
|
|
||||||
|
services.victoriametrics = {
|
||||||
|
extraOptions = [
|
||||||
|
"-httpAuth.username=file://${config.clan.core.vars.generators.b4l-victoriametrics.files.adminuser.path}"
|
||||||
|
"-httpAuth.password=file://${config.clan.core.vars.generators.b4l-victoriametrics.files.adminpassword.path}"
|
||||||
|
];
|
||||||
|
};
|
||||||
|
|
||||||
|
services.nginx.virtualHosts."${vmDomain}" = {
|
||||||
|
forceSSL = true;
|
||||||
|
useACMEHost = "${config.networking.fqdn}";
|
||||||
|
locations."/" = {
|
||||||
|
proxyPass = "http://localhost${builtins.toString config.services.victoriametrics.listenAddress}";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
}
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
{ config, ... }:
|
||||||
|
{
|
||||||
|
clan.core.vars.generators.b4l-vikunja = {
|
||||||
|
files.subdomain.secret = false;
|
||||||
|
|
||||||
|
prompts = {
|
||||||
|
subdomain = {
|
||||||
|
persist = true;
|
||||||
|
type = "line";
|
||||||
|
description = "Sub-domain for Vikunja todo app. Default:(todo)";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
script = ''cat $prompts/subdomain || echo "todo" > $out/subdomain'';
|
||||||
|
};
|
||||||
|
services.vikunja = {
|
||||||
|
frontendHostname = "${config.clan.core.vars.generators.b4l-vikunja.files.subdomain.value}.${config.networking.fqdn}";
|
||||||
|
};
|
||||||
|
services.nginx.virtualHosts."${config.services.vikunja.frontendHostname}" = {
|
||||||
|
useACMEHost = "${config.networking.fqdn}";
|
||||||
|
forceSSL = true;
|
||||||
|
locations."/" = {
|
||||||
|
proxyPass = "${config.services.vikunja.frontendScheme}://${config.services.vikunja.frontendHostname}:${builtins.toString config.services.vikunja.port}";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -1,105 +0,0 @@
|
|||||||
{
|
|
||||||
inputs,
|
|
||||||
pkgs,
|
|
||||||
config,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
sitename = "tempoerp.newedge.house";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
clan.core.settings.machine.description = "VM machine that host ERPNext for tempo";
|
|
||||||
imports = [
|
|
||||||
inputs.frappix.nixosModules.x86_64-linux.frappix
|
|
||||||
];
|
|
||||||
nixpkgs.overlays = [
|
|
||||||
inputs.self.overlays.frappixFrappeOverlay
|
|
||||||
inputs.self.overlays.frappixLibsOverlay
|
|
||||||
inputs.self.overlays.frappixPythonOverlay
|
|
||||||
inputs.self.overlays.frappixToolsOverlay
|
|
||||||
];
|
|
||||||
|
|
||||||
clan.core.vars.generators.frappix = {
|
|
||||||
files = {
|
|
||||||
sslCertificate.secret = false;
|
|
||||||
sslCertificateKey = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
adminPassword.secret = true;
|
|
||||||
};
|
|
||||||
runtimeInputs = with pkgs; [
|
|
||||||
openssl
|
|
||||||
xkcdpass
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
openssl req -x509 -newkey rsa:4096 -keyout $out/sslCertificateKey -out $out/sslCertificate -sha256 -days 3650 -nodes -subj "/C=TH/ST=ChiangMai/L=ChiangMai/O=kurogeek/CN=kurogeek.home"
|
|
||||||
xkcdpass --numwords 4 --delimiter - --count 1 | tr -d "\n" > "$out"/adminPassword
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
services.frappe = {
|
|
||||||
enable = true;
|
|
||||||
project = "poyerp";
|
|
||||||
gunicorn_workers = 2;
|
|
||||||
adminPassword = config.clan.core.vars.generators.frappix.files.adminPassword.path;
|
|
||||||
apps = [
|
|
||||||
pkgs.frappix.erpnext
|
|
||||||
pkgs.frappix.hrms
|
|
||||||
pkgs.frappix.crm
|
|
||||||
];
|
|
||||||
sites = {
|
|
||||||
"${sitename}" = {
|
|
||||||
domains = [ sitename ];
|
|
||||||
apps = [
|
|
||||||
"frappe"
|
|
||||||
"erpnext"
|
|
||||||
"hrms"
|
|
||||||
"crm"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
services.nginx.virtualHosts."${sitename}" = {
|
|
||||||
sslCertificate = config.clan.core.vars.generators.frappix.files.sslCertificate.path;
|
|
||||||
sslCertificateKey = config.clan.core.vars.generators.frappix.files.sslCertificateKey.path;
|
|
||||||
};
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = {
|
|
||||||
system = "x86_64-linux";
|
|
||||||
};
|
|
||||||
|
|
||||||
clan.core.vars.generators.nginx = {
|
|
||||||
files = {
|
|
||||||
sslCert = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
sslKey = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
runtimeInputs = [
|
|
||||||
pkgs.openssl
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 \
|
|
||||||
-keyout $out/sslKey \
|
|
||||||
-out $out/sslCert \
|
|
||||||
-subj "/CN=localhost"
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [
|
|
||||||
80
|
|
||||||
443
|
|
||||||
];
|
|
||||||
|
|
||||||
system.stateVersion = "25.11";
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
|
||||||
}
|
|
||||||
@@ -1,85 +0,0 @@
|
|||||||
let
|
|
||||||
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
|
||||||
os = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
systemd-boot = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
efi = {
|
|
||||||
canTouchEfiVariables = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
"os-${hashDisk os}" = {
|
|
||||||
type = "disk";
|
|
||||||
device = os;
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "1G";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
system = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "zfs";
|
|
||||||
pool = "zroot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
zpool = {
|
|
||||||
zroot = {
|
|
||||||
type = "zpool";
|
|
||||||
rootFsOptions = {
|
|
||||||
mountpoint = "none";
|
|
||||||
compression = "lz4";
|
|
||||||
acltype = "posixacl";
|
|
||||||
xattr = "sa";
|
|
||||||
"com.sun:auto-snapshot" = "true";
|
|
||||||
};
|
|
||||||
options.ashift = "12";
|
|
||||||
datasets = {
|
|
||||||
"root" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "none";
|
|
||||||
};
|
|
||||||
"root/nixos" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
"root/home" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/home";
|
|
||||||
mountpoint = "/home";
|
|
||||||
};
|
|
||||||
"root/tmp" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
options = {
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
sync = "disabled";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -8,7 +8,6 @@
|
|||||||
# clan.core.networking.targetHost = "root@";
|
# clan.core.networking.targetHost = "root@";
|
||||||
|
|
||||||
clan.core.settings.name = "buna";
|
clan.core.settings.name = "buna";
|
||||||
clan.core.settings.machine.description =
|
# clan.meta.description = "Radxa X4 SBC board for one of w phone network. (With w whitehouse)";
|
||||||
"Radxa X4 SBC board for one of w phone network. (With w whitehouse)";
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,109 +0,0 @@
|
|||||||
{
|
|
||||||
inputs,
|
|
||||||
pkgs,
|
|
||||||
config,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
sitename = "glomerp.newedge.house";
|
|
||||||
nbClientName = "netbird-b4l";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
clan.core.settings.machine.description = "VM machine that host ERPNext for glomglom";
|
|
||||||
|
|
||||||
imports = [ inputs.frappix.nixosModules.x86_64-linux.frappix ];
|
|
||||||
nixpkgs.overlays = [
|
|
||||||
inputs.self.overlays.frappixFrappeOverlay
|
|
||||||
inputs.self.overlays.frappixLibsOverlay
|
|
||||||
inputs.self.overlays.frappixPythonOverlay
|
|
||||||
inputs.self.overlays.frappixToolsOverlay
|
|
||||||
];
|
|
||||||
|
|
||||||
clan.core.vars.generators.frappix = {
|
|
||||||
files = {
|
|
||||||
sslCertificate.secret = false;
|
|
||||||
sslCertificateKey = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
adminPassword.secret = true;
|
|
||||||
};
|
|
||||||
runtimeInputs = with pkgs; [
|
|
||||||
openssl
|
|
||||||
xkcdpass
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
openssl req -x509 -newkey rsa:4096 -keyout $out/sslCertificateKey -out $out/sslCertificate -sha256 -days 3650 -nodes -subj "/C=TH/ST=ChiangMai/L=ChiangMai/O=kurogeek/CN=kurogeek.home"
|
|
||||||
xkcdpass --numwords 4 --delimiter - --count 1 | tr -d "\n" > "$out"/adminPassword
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
services.frappe = {
|
|
||||||
enable = true;
|
|
||||||
project = "glomerp";
|
|
||||||
gunicorn_workers = 2;
|
|
||||||
adminPassword = config.clan.core.vars.generators.frappix.files.adminPassword.path;
|
|
||||||
apps = [
|
|
||||||
pkgs.frappix.erpnext
|
|
||||||
pkgs.frappix.hrms
|
|
||||||
];
|
|
||||||
sites = {
|
|
||||||
"${sitename}" = {
|
|
||||||
domains = [ sitename ];
|
|
||||||
apps = [
|
|
||||||
"frappe"
|
|
||||||
"erpnext"
|
|
||||||
"hrms"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
services.nginx.virtualHosts."${sitename}" = {
|
|
||||||
sslCertificate = config.clan.core.vars.generators.frappix.files.sslCertificate.path;
|
|
||||||
sslCertificateKey = config.clan.core.vars.generators.frappix.files.sslCertificateKey.path;
|
|
||||||
};
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = {
|
|
||||||
system = "x86_64-linux";
|
|
||||||
};
|
|
||||||
|
|
||||||
clan.core.vars.generators.nginx = {
|
|
||||||
files = {
|
|
||||||
sslCert = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
sslKey = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
runtimeInputs = [
|
|
||||||
pkgs.openssl
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 \
|
|
||||||
-keyout $out/sslKey \
|
|
||||||
-out $out/sslCert \
|
|
||||||
-subj "/CN=localhost"
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [
|
|
||||||
80
|
|
||||||
443
|
|
||||||
];
|
|
||||||
|
|
||||||
# services.nginx.virtualHosts."${domain}" = {
|
|
||||||
# forceSSL = true;
|
|
||||||
# sslCertificate = config.clan.core.vars.generators.nginx.files.sslCert.path;
|
|
||||||
# sslCertificateKey = config.clan.core.vars.generators.nginx.files.sslKey.path;
|
|
||||||
# };
|
|
||||||
|
|
||||||
system.stateVersion = "25.11";
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
|
||||||
}
|
|
||||||
@@ -1,85 +0,0 @@
|
|||||||
let
|
|
||||||
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
|
||||||
os = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
systemd-boot = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
efi = {
|
|
||||||
canTouchEfiVariables = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
"os-${hashDisk os}" = {
|
|
||||||
type = "disk";
|
|
||||||
device = os;
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "1G";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
system = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "zfs";
|
|
||||||
pool = "zroot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
zpool = {
|
|
||||||
zroot = {
|
|
||||||
type = "zpool";
|
|
||||||
rootFsOptions = {
|
|
||||||
mountpoint = "none";
|
|
||||||
compression = "lz4";
|
|
||||||
acltype = "posixacl";
|
|
||||||
xattr = "sa";
|
|
||||||
"com.sun:auto-snapshot" = "true";
|
|
||||||
};
|
|
||||||
options.ashift = "12";
|
|
||||||
datasets = {
|
|
||||||
"root" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "none";
|
|
||||||
};
|
|
||||||
"root/nixos" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
"root/home" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/home";
|
|
||||||
mountpoint = "/home";
|
|
||||||
};
|
|
||||||
"root/tmp" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
options = {
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
sync = "disabled";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,14 +0,0 @@
|
|||||||
{
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
{
|
|
||||||
clan.core.settings.machine.description =
|
|
||||||
"VM machine for collecting prometheus metrics and fire alerts";
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = {
|
|
||||||
system = "x86_64-linux";
|
|
||||||
};
|
|
||||||
|
|
||||||
system.stateVersion = "25.11";
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
|
||||||
}
|
|
||||||
@@ -1,85 +0,0 @@
|
|||||||
let
|
|
||||||
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
|
||||||
os = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
systemd-boot = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
efi = {
|
|
||||||
canTouchEfiVariables = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
"os-${hashDisk os}" = {
|
|
||||||
type = "disk";
|
|
||||||
device = os;
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "1G";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
system = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "zfs";
|
|
||||||
pool = "zroot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
zpool = {
|
|
||||||
zroot = {
|
|
||||||
type = "zpool";
|
|
||||||
rootFsOptions = {
|
|
||||||
mountpoint = "none";
|
|
||||||
compression = "lz4";
|
|
||||||
acltype = "posixacl";
|
|
||||||
xattr = "sa";
|
|
||||||
"com.sun:auto-snapshot" = "true";
|
|
||||||
};
|
|
||||||
options.ashift = "12";
|
|
||||||
datasets = {
|
|
||||||
"root" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "none";
|
|
||||||
};
|
|
||||||
"root/nixos" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
"root/home" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/home";
|
|
||||||
mountpoint = "/home";
|
|
||||||
};
|
|
||||||
"root/tmp" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
options = {
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
sync = "disabled";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
+2
-14
@@ -1,23 +1,11 @@
|
|||||||
{
|
{ inputs, self, ... }:
|
||||||
inputs,
|
|
||||||
self,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
inputs.clan-core.flakeModules.default
|
inputs.clan-core.flakeModules.default
|
||||||
];
|
];
|
||||||
clan = {
|
clan = {
|
||||||
meta.name = "NewEdgeClan";
|
meta.name = "NewEdgeClan";
|
||||||
machines = {
|
machines = { };
|
||||||
cursa = { ... }: { clan.core.state."vars".folders = [ "/var/lib" ]; };
|
|
||||||
hadar = { ... }: { clan.core.state."vars".folders = [ "/var/lib" ]; };
|
|
||||||
procyon = { ... }: { clan.core.state."vars".folders = [ "/var/lib" ]; };
|
|
||||||
bosona = { ... }: { clan.core.state."vars".folders = [ "/var/lib" ]; };
|
|
||||||
canopus = { ... }: { clan.core.state."vars".folders = [ "/var/lib" ]; };
|
|
||||||
deneb = { ... }: { clan.core.state."vars".folders = [ "/var/lib" ]; };
|
|
||||||
alasia = { ... }: { clan.core.state."vars".folders = [ "/var/lib" ]; };
|
|
||||||
};
|
|
||||||
secrets.age.plugins = [
|
secrets.age.plugins = [
|
||||||
"age-plugin-yubikey"
|
"age-plugin-yubikey"
|
||||||
"age-plugin-fido2-hmac"
|
"age-plugin-fido2-hmac"
|
||||||
|
|||||||
@@ -1,121 +0,0 @@
|
|||||||
{
|
|
||||||
inputs,
|
|
||||||
pkgs,
|
|
||||||
config,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
sitename = "poyerp.newedge.house";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
clan.core.settings.machine.description = "VM machine that host ERPNext for poysound";
|
|
||||||
imports = [
|
|
||||||
inputs.frappix.nixosModules.x86_64-linux.frappix
|
|
||||||
|
|
||||||
# (import ../../lib/auto-accept-zerotier-members.nix {
|
|
||||||
# memberIds = [
|
|
||||||
# # Alex Caddy gateway
|
|
||||||
# "dbe44c0287"
|
|
||||||
# "e3d6559697"
|
|
||||||
# ];
|
|
||||||
# })
|
|
||||||
];
|
|
||||||
nixpkgs.overlays = [
|
|
||||||
inputs.self.overlays.frappixFrappeOverlay
|
|
||||||
inputs.self.overlays.frappixLibsOverlay
|
|
||||||
inputs.self.overlays.frappixPythonOverlay
|
|
||||||
inputs.self.overlays.frappixToolsOverlay
|
|
||||||
];
|
|
||||||
|
|
||||||
clan.core.vars.generators.frappix = {
|
|
||||||
files = {
|
|
||||||
sslCertificate.secret = false;
|
|
||||||
sslCertificateKey = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
adminPassword.secret = true;
|
|
||||||
};
|
|
||||||
runtimeInputs = with pkgs; [
|
|
||||||
openssl
|
|
||||||
xkcdpass
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
openssl req -x509 -newkey rsa:4096 -keyout $out/sslCertificateKey -out $out/sslCertificate -sha256 -days 3650 -nodes -subj "/C=TH/ST=ChiangMai/L=ChiangMai/O=kurogeek/CN=kurogeek.home"
|
|
||||||
xkcdpass --numwords 4 --delimiter - --count 1 | tr -d "\n" > "$out"/adminPassword
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
services.frappe = {
|
|
||||||
enable = true;
|
|
||||||
project = "poyerp";
|
|
||||||
gunicorn_workers = 2;
|
|
||||||
adminPassword = config.clan.core.vars.generators.frappix.files.adminPassword.path;
|
|
||||||
apps = [
|
|
||||||
pkgs.frappix.erpnext
|
|
||||||
pkgs.frappix.hrms
|
|
||||||
pkgs.frappix.crm
|
|
||||||
pkgs.frappix.posprinter
|
|
||||||
];
|
|
||||||
sites = {
|
|
||||||
"${sitename}" = {
|
|
||||||
domains = [ sitename ];
|
|
||||||
apps = [
|
|
||||||
"frappe"
|
|
||||||
"erpnext"
|
|
||||||
"hrms"
|
|
||||||
"crm"
|
|
||||||
"posprinter"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
services.nginx.virtualHosts."${sitename}" = {
|
|
||||||
sslCertificate = config.clan.core.vars.generators.frappix.files.sslCertificate.path;
|
|
||||||
sslCertificateKey = config.clan.core.vars.generators.frappix.files.sslCertificateKey.path;
|
|
||||||
};
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = {
|
|
||||||
system = "x86_64-linux";
|
|
||||||
};
|
|
||||||
|
|
||||||
clan.core.vars.generators.nginx = {
|
|
||||||
files = {
|
|
||||||
sslCert = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
sslKey = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
runtimeInputs = [
|
|
||||||
pkgs.openssl
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 \
|
|
||||||
-keyout $out/sslKey \
|
|
||||||
-out $out/sslCert \
|
|
||||||
-subj "/CN=localhost"
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [
|
|
||||||
80
|
|
||||||
443
|
|
||||||
];
|
|
||||||
|
|
||||||
# services.nginx.virtualHosts."${domain}" = {
|
|
||||||
# forceSSL = true;
|
|
||||||
# sslCertificate = config.clan.core.vars.generators.nginx.files.sslCert.path;
|
|
||||||
# sslCertificateKey = config.clan.core.vars.generators.nginx.files.sslKey.path;
|
|
||||||
# };
|
|
||||||
|
|
||||||
system.stateVersion = "25.11";
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
|
||||||
}
|
|
||||||
@@ -1,85 +0,0 @@
|
|||||||
let
|
|
||||||
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
|
||||||
os = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
systemd-boot = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
efi = {
|
|
||||||
canTouchEfiVariables = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
"os-${hashDisk os}" = {
|
|
||||||
type = "disk";
|
|
||||||
device = os;
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "1G";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
system = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "zfs";
|
|
||||||
pool = "zroot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
zpool = {
|
|
||||||
zroot = {
|
|
||||||
type = "zpool";
|
|
||||||
rootFsOptions = {
|
|
||||||
mountpoint = "none";
|
|
||||||
compression = "lz4";
|
|
||||||
acltype = "posixacl";
|
|
||||||
xattr = "sa";
|
|
||||||
"com.sun:auto-snapshot" = "true";
|
|
||||||
};
|
|
||||||
options.ashift = "12";
|
|
||||||
datasets = {
|
|
||||||
"root" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "none";
|
|
||||||
};
|
|
||||||
"root/nixos" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
"root/home" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/home";
|
|
||||||
mountpoint = "/home";
|
|
||||||
};
|
|
||||||
"root/tmp" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
options = {
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
sync = "disabled";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,86 +0,0 @@
|
|||||||
{
|
|
||||||
inputs,
|
|
||||||
config,
|
|
||||||
pkgs,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
domain = "poy-inventory.newedge.house";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
clan.core.settings.machine.description = "VM machine that host Inventree system for Poy";
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = {
|
|
||||||
system = "x86_64-linux";
|
|
||||||
};
|
|
||||||
|
|
||||||
clan.core.vars.generators.inventree = {
|
|
||||||
files = {
|
|
||||||
secret-key = {
|
|
||||||
owner = "inventree";
|
|
||||||
group = "inventree";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
oidc-key = {
|
|
||||||
owner = "inventree";
|
|
||||||
group = "inventree";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
admin-password = {
|
|
||||||
owner = "inventree";
|
|
||||||
group = "inventree";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
runtimeInputs = [
|
|
||||||
pkgs.pwgen
|
|
||||||
pkgs.xkcdpass
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
pwgen -s 32 1 > $out/secret-key
|
|
||||||
pwgen -s 32 1 > $out/oidc-key
|
|
||||||
xkcdpass --numwords 4 --delimiter - --count 1 | tr -d "\n" > "$out"/admin-password
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
clan.core.vars.generators.nginx = {
|
|
||||||
files = {
|
|
||||||
sslCert = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
sslKey = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
runtimeInputs = [
|
|
||||||
pkgs.openssl
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 \
|
|
||||||
-keyout $out/sslKey \
|
|
||||||
-out $out/sslCert \
|
|
||||||
-subj "/CN=localhost"
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [
|
|
||||||
80
|
|
||||||
443
|
|
||||||
];
|
|
||||||
|
|
||||||
services.inventree = {
|
|
||||||
enable = true;
|
|
||||||
inherit domain;
|
|
||||||
secretKeyFile = config.clan.core.vars.generators.inventree.files.secret-key.path;
|
|
||||||
adminPasswordFile = config.clan.core.vars.generators.inventree.files.admin-password.path;
|
|
||||||
settings.INVENTREE_SITE_URL = "https://${domain}";
|
|
||||||
};
|
|
||||||
|
|
||||||
system.stateVersion = "25.11";
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
|
||||||
}
|
|
||||||
@@ -1,85 +0,0 @@
|
|||||||
let
|
|
||||||
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
|
||||||
os = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
systemd-boot = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
efi = {
|
|
||||||
canTouchEfiVariables = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
"os-${hashDisk os}" = {
|
|
||||||
type = "disk";
|
|
||||||
device = os;
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "1G";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
system = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "zfs";
|
|
||||||
pool = "zroot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
zpool = {
|
|
||||||
zroot = {
|
|
||||||
type = "zpool";
|
|
||||||
rootFsOptions = {
|
|
||||||
mountpoint = "none";
|
|
||||||
compression = "lz4";
|
|
||||||
acltype = "posixacl";
|
|
||||||
xattr = "sa";
|
|
||||||
"com.sun:auto-snapshot" = "true";
|
|
||||||
};
|
|
||||||
options.ashift = "12";
|
|
||||||
datasets = {
|
|
||||||
"root" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "none";
|
|
||||||
};
|
|
||||||
"root/nixos" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
"root/home" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/home";
|
|
||||||
mountpoint = "/home";
|
|
||||||
};
|
|
||||||
"root/tmp" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
options = {
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
sync = "disabled";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -8,6 +8,6 @@
|
|||||||
# clan.core.networking.targetHost = "root@";
|
# clan.core.networking.targetHost = "root@";
|
||||||
|
|
||||||
clan.core.settings.name = "mirach";
|
clan.core.settings.name = "mirach";
|
||||||
clan.core.settings.machine.description = "Radxa X4 SBC board for one of w phone network.";
|
# clan.meta.description = "Radxa X4 SBC board for one of w phone network.";
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,8 +14,6 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
disko.devices = {
|
||||||
disk = {
|
disk = {
|
||||||
"os-${hashDisk os}" = {
|
"os-${hashDisk os}" = {
|
||||||
|
|||||||
@@ -10,6 +10,7 @@
|
|||||||
};
|
};
|
||||||
system.stateVersion = "25.11";
|
system.stateVersion = "25.11";
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
clan.core.sops.defaultGroups = [ "admins" ];
|
||||||
|
clan.core.networking.targetHost = "root@[${config.clan.core.vars.generators.zerotier.files.zerotier-ip.value}]";
|
||||||
|
|
||||||
networking.interfaces.enx00e04c106368.useDHCP = true; # recovery
|
networking.interfaces.enx00e04c106368.useDHCP = true; # recovery
|
||||||
|
|
||||||
@@ -56,6 +57,6 @@
|
|||||||
];
|
];
|
||||||
|
|
||||||
clan.core.settings.name = "neptune";
|
clan.core.settings.name = "neptune";
|
||||||
clan.core.settings.machine.description = "Radxa SBC board for testing. (With vi)";
|
# clan.meta.description = "Radxa SBC board for testing. (With vi)";
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,8 +14,6 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
disko.devices = {
|
||||||
disk = {
|
disk = {
|
||||||
"os-${hashDisk os}" = {
|
"os-${hashDisk os}" = {
|
||||||
|
|||||||
@@ -9,5 +9,4 @@
|
|||||||
};
|
};
|
||||||
system.stateVersion = "25.11";
|
system.stateVersion = "25.11";
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
clan.core.sops.defaultGroups = [ "admins" ];
|
||||||
clan.core.settings.machine.description = "A personal computer for Chocolate Shop";
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,8 +14,6 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
disko.devices = {
|
||||||
disk = {
|
disk = {
|
||||||
"os-${hashDisk os}" = {
|
"os-${hashDisk os}" = {
|
||||||
|
|||||||
@@ -1,86 +0,0 @@
|
|||||||
{
|
|
||||||
inputs,
|
|
||||||
config,
|
|
||||||
pkgs,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
domain = "glom-inventory.newedge.house";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
clan.core.settings.machine.description = "VM machine that host Inventree system for Glom";
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = {
|
|
||||||
system = "x86_64-linux";
|
|
||||||
};
|
|
||||||
|
|
||||||
clan.core.vars.generators.inventree = {
|
|
||||||
files = {
|
|
||||||
secret-key = {
|
|
||||||
owner = "inventree";
|
|
||||||
group = "inventree";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
oidc-key = {
|
|
||||||
owner = "inventree";
|
|
||||||
group = "inventree";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
admin-password = {
|
|
||||||
owner = "inventree";
|
|
||||||
group = "inventree";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
runtimeInputs = [
|
|
||||||
pkgs.pwgen
|
|
||||||
pkgs.xkcdpass
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
pwgen -s 32 1 > $out/secret-key
|
|
||||||
pwgen -s 32 1 > $out/oidc-key
|
|
||||||
xkcdpass --numwords 4 --delimiter - --count 1 | tr -d "\n" > "$out"/admin-password
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
clan.core.vars.generators.nginx = {
|
|
||||||
files = {
|
|
||||||
sslCert = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
sslKey = {
|
|
||||||
owner = "nginx";
|
|
||||||
group = "nginx";
|
|
||||||
secret = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
runtimeInputs = [
|
|
||||||
pkgs.openssl
|
|
||||||
];
|
|
||||||
script = ''
|
|
||||||
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 \
|
|
||||||
-keyout $out/sslKey \
|
|
||||||
-out $out/sslCert \
|
|
||||||
-subj "/CN=localhost"
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
networking.firewall.allowedTCPPorts = [
|
|
||||||
80
|
|
||||||
443
|
|
||||||
];
|
|
||||||
|
|
||||||
services.inventree = {
|
|
||||||
enable = true;
|
|
||||||
inherit domain;
|
|
||||||
secretKeyFile = config.clan.core.vars.generators.inventree.files.secret-key.path;
|
|
||||||
adminPasswordFile = config.clan.core.vars.generators.inventree.files.admin-password.path;
|
|
||||||
settings.INVENTREE_SITE_URL = "https://${domain}";
|
|
||||||
};
|
|
||||||
|
|
||||||
system.stateVersion = "25.11";
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
|
||||||
}
|
|
||||||
@@ -1,85 +0,0 @@
|
|||||||
let
|
|
||||||
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
|
||||||
os = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_drive-scsi0";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
systemd-boot = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
efi = {
|
|
||||||
canTouchEfiVariables = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
"os-${hashDisk os}" = {
|
|
||||||
type = "disk";
|
|
||||||
device = os;
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "1G";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
system = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "zfs";
|
|
||||||
pool = "zroot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
zpool = {
|
|
||||||
zroot = {
|
|
||||||
type = "zpool";
|
|
||||||
rootFsOptions = {
|
|
||||||
mountpoint = "none";
|
|
||||||
compression = "lz4";
|
|
||||||
acltype = "posixacl";
|
|
||||||
xattr = "sa";
|
|
||||||
"com.sun:auto-snapshot" = "true";
|
|
||||||
};
|
|
||||||
options.ashift = "12";
|
|
||||||
datasets = {
|
|
||||||
"root" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "none";
|
|
||||||
};
|
|
||||||
"root/nixos" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
"root/home" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/home";
|
|
||||||
mountpoint = "/home";
|
|
||||||
};
|
|
||||||
"root/tmp" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
options = {
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
sync = "disabled";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -6,9 +6,12 @@
|
|||||||
};
|
};
|
||||||
|
|
||||||
clan.core.settings.name = "ramus";
|
clan.core.settings.name = "ramus";
|
||||||
clan.core.settings.machine.description = "A Hetzner VPS machine own by Alex.";
|
# clan.meta.description = ''
|
||||||
|
# A Hetzner VPS machine own by Alex.
|
||||||
|
# '';
|
||||||
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
clan.core.sops.defaultGroups = [ "admins" ];
|
||||||
|
clan.core.networking.targetHost = "root@[${config.clan.core.vars.generators.zerotier.files.zerotier-ip.value}]";
|
||||||
|
|
||||||
clan.core.vars.generators.acme = {
|
clan.core.vars.generators.acme = {
|
||||||
share = true;
|
share = true;
|
||||||
|
|||||||
@@ -14,8 +14,6 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
disko.devices = {
|
||||||
disk = {
|
disk = {
|
||||||
"os-${hashDisk os}" = {
|
"os-${hashDisk os}" = {
|
||||||
|
|||||||
@@ -1,7 +1,5 @@
|
|||||||
{ self, pkgs, ... }:
|
{ self, ... }:
|
||||||
{
|
{
|
||||||
clan.core.settings.machine.description = "Emmie personal computer";
|
|
||||||
|
|
||||||
imports = [
|
imports = [
|
||||||
self.nixosModules.common
|
self.nixosModules.common
|
||||||
];
|
];
|
||||||
@@ -11,12 +9,4 @@
|
|||||||
};
|
};
|
||||||
system.stateVersion = "25.11";
|
system.stateVersion = "25.11";
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
clan.core.sops.defaultGroups = [ "admins" ];
|
||||||
|
|
||||||
boot.kernelParams = [
|
|
||||||
"amdgpu.dcdebugmask=0x10"
|
|
||||||
"amdgpu.cwsr_enable=0"
|
|
||||||
"amdgpu.gpu_recovery=1"
|
|
||||||
];
|
|
||||||
|
|
||||||
boot.kernelPackages = pkgs.linuxKernel.packages.linux_6_12;
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,8 +14,6 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
disko.devices = {
|
||||||
disk = {
|
disk = {
|
||||||
"os-${hashDisk os}" = {
|
"os-${hashDisk os}" = {
|
||||||
@@ -55,9 +53,6 @@ in
|
|||||||
zroot = {
|
zroot = {
|
||||||
type = "zpool";
|
type = "zpool";
|
||||||
rootFsOptions = {
|
rootFsOptions = {
|
||||||
encryption = "aes-256-gcm";
|
|
||||||
keyformat = "passphrase";
|
|
||||||
keylocation = "file:///tmp/secret.key";
|
|
||||||
mountpoint = "none";
|
mountpoint = "none";
|
||||||
compression = "lz4";
|
compression = "lz4";
|
||||||
acltype = "posixacl";
|
acltype = "posixacl";
|
||||||
|
|||||||
+681
-779
File diff suppressed because it is too large
Load Diff
@@ -1,7 +1,16 @@
|
|||||||
{ config, ... }:
|
{ config, ... }:
|
||||||
{
|
{
|
||||||
|
imports = [
|
||||||
|
(import ../../lib/auto-accept-zerotier-members.nix {
|
||||||
|
memberIds = [
|
||||||
|
"dbe44c0287" # Alex-gateway
|
||||||
|
"b0e0b84fd3" # Alex
|
||||||
|
"2bd36db8cc" # kurogeek-thinkpad
|
||||||
|
];
|
||||||
|
})
|
||||||
|
];
|
||||||
|
|
||||||
system.stateVersion = "25.11";
|
system.stateVersion = "25.11";
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
clan.core.sops.defaultGroups = [ "admins" ];
|
||||||
|
clan.core.networking.targetHost = "root@[${config.clan.core.vars.generators.zerotier.files.zerotier-ip.value}]";
|
||||||
clan.core.settings.machine.description = "Zima board computer for testing in B4L";
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,21 +0,0 @@
|
|||||||
## How to setup this machine.
|
|
||||||
|
|
||||||
This machine cannot be setup the same way as other machines are setup. Meaning that `clan machine install` won't work. Because of `disko` issue. So, below is how the machine is setup.
|
|
||||||
|
|
||||||
1. Build an image to flash to an sd-card using
|
|
||||||
|
|
||||||
```
|
|
||||||
nix build -L --show-trace .\#nixosConfigurations.sirius.config.system.build.images.sd-card
|
|
||||||
```
|
|
||||||
|
|
||||||
2. Import the `zdata`
|
|
||||||
|
|
||||||
```
|
|
||||||
zpool import zdata
|
|
||||||
```
|
|
||||||
|
|
||||||
3. Update configuration
|
|
||||||
|
|
||||||
```
|
|
||||||
clan machine update sirius
|
|
||||||
```
|
|
||||||
@@ -1,23 +1,13 @@
|
|||||||
{
|
{
|
||||||
|
config,
|
||||||
self,
|
self,
|
||||||
pkgs,
|
|
||||||
...
|
...
|
||||||
}:
|
}:
|
||||||
{
|
{
|
||||||
imports = [
|
imports = [
|
||||||
self.nixosModules.common
|
self.nixosModules.common
|
||||||
|
|
||||||
./hardware-configuration.nix
|
|
||||||
];
|
];
|
||||||
|
|
||||||
image.modules.sd-card = {
|
|
||||||
disabledModules = [
|
|
||||||
./hardware-configuration.nix
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
clan.core.settings.machine.description = "w NAS";
|
|
||||||
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
clan.core.sops.defaultGroups = [ "admins" ];
|
||||||
|
|
||||||
nixpkgs.hostPlatform = {
|
nixpkgs.hostPlatform = {
|
||||||
@@ -42,55 +32,4 @@
|
|||||||
options = "--delete-older-than 15d";
|
options = "--delete-older-than 15d";
|
||||||
};
|
};
|
||||||
|
|
||||||
boot.loader.grub.enable = false;
|
|
||||||
boot.loader.generic-extlinux-compatible.enable = true;
|
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = false;
|
|
||||||
|
|
||||||
boot.zfs.extraPools = [ "zdata" ];
|
|
||||||
boot.supportedFilesystems = [ "zfs" ];
|
|
||||||
boot.initrd.availableKernelModules = [
|
|
||||||
"usb_storage"
|
|
||||||
"sd_mod"
|
|
||||||
];
|
|
||||||
|
|
||||||
fileSystems."/mnt/hdd" = {
|
|
||||||
device = "zdata/nas";
|
|
||||||
fsType = "zfs";
|
|
||||||
mountPoint = "/mnt/hdd";
|
|
||||||
options = [
|
|
||||||
"nofail"
|
|
||||||
"zfsutil"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
fileSystems."/var/lib" = {
|
|
||||||
device = "zdata/service-data";
|
|
||||||
fsType = "zfs";
|
|
||||||
mountPoint = "/var/lib";
|
|
||||||
options = [
|
|
||||||
"x-initrd.mount"
|
|
||||||
"nofail"
|
|
||||||
"zfsutil"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
|
|
||||||
systemd.services.heartbeat-push = {
|
|
||||||
description = "Heartbeat push to uptime monitor";
|
|
||||||
serviceConfig = {
|
|
||||||
Type = "oneshot";
|
|
||||||
ExecStart = "${pkgs.curl}/bin/curl -s -o /dev/null https://uptime.b4l.co.th/api/push/X0WCHAcY5gPf1U8If7BT1FLjpacZqGZu?status=up&msg=OK&ping=";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
systemd.timers.heartbeat-push = {
|
|
||||||
description = "Heartbeat push timer";
|
|
||||||
wantedBy = [ "timers.target" ];
|
|
||||||
timerConfig = {
|
|
||||||
OnBootSec = "60s";
|
|
||||||
OnUnitActiveSec = "60s";
|
|
||||||
Unit = "heartbeat-push.service";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,150 +0,0 @@
|
|||||||
{ lib, pkgs, ... }:
|
|
||||||
let
|
|
||||||
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
|
||||||
# os = "/dev/disk/by-id/mmc-SD64G_0x8336354b";
|
|
||||||
vdev = [
|
|
||||||
"/dev/disk/by-id/ata-ST20000NM002H-3KV133_ZYDBVV7Z"
|
|
||||||
"/dev/disk/by-id/ata-ST20000NM002H-3KV133_ZYDBSJRE"
|
|
||||||
];
|
|
||||||
configTxt = pkgs.writeText "config.txt" ''
|
|
||||||
[pi4]
|
|
||||||
kernel=u-boot-rpi4.bin
|
|
||||||
enable_gic=1
|
|
||||||
|
|
||||||
# Otherwise the resolution will be weird in most cases, compared to
|
|
||||||
# what the pi3 firmware does by default.
|
|
||||||
disable_overscan=1
|
|
||||||
|
|
||||||
# Supported in newer board revisions
|
|
||||||
arm_boost=1
|
|
||||||
|
|
||||||
[all]
|
|
||||||
# Boot in 64-bit mode.
|
|
||||||
arm_64bit=1
|
|
||||||
|
|
||||||
# U-Boot needs this to work, regardless of whether UART is actually used or not.
|
|
||||||
# Look in arch/arm/mach-bcm283x/Kconfig in the U-Boot tree to see if this is still
|
|
||||||
# a requirement in the future.
|
|
||||||
enable_uart=1
|
|
||||||
|
|
||||||
# Prevent the firmware from smashing the framebuffer setup done by the mainline kernel
|
|
||||||
# when attempting to show low-voltage or overtemperature warnings.
|
|
||||||
avoid_warnings=1
|
|
||||||
'';
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
systemd-boot = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
efi = {
|
|
||||||
canTouchEfiVariables = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
# boot.tmp.useTmpfs = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
# "os-${hashDisk os}" = {
|
|
||||||
# type = "disk";
|
|
||||||
# device = os;
|
|
||||||
# content = {
|
|
||||||
# type = "gpt";
|
|
||||||
# partitions = {
|
|
||||||
# firmware = {
|
|
||||||
# size = "60M";
|
|
||||||
# priority = 1;
|
|
||||||
# type = "0700";
|
|
||||||
# content = {
|
|
||||||
# type = "filesystem";
|
|
||||||
# format = "vfat";
|
|
||||||
# mountpoint = "/firmware";
|
|
||||||
# postMountHook = toString (
|
|
||||||
# pkgs.writeScript "postMountHook.sh" ''
|
|
||||||
# (cd ${pkgs.raspberrypifw}/share/raspberrypi/boot && cp bootcode.bin fixup*.dat start*.elf *.dtb /mnt/firmware/)
|
|
||||||
# cp ${pkgs.ubootRaspberryPi4_64bit}/u-boot.bin /mnt/firmware/u-boot-rpi4.bin
|
|
||||||
# cp ${configTxt} /mnt/firmware/config.txt
|
|
||||||
# ''
|
|
||||||
# );
|
|
||||||
# };
|
|
||||||
# };
|
|
||||||
# ESP = {
|
|
||||||
# size = "2G";
|
|
||||||
# type = "EF00";
|
|
||||||
# content = {
|
|
||||||
# type = "filesystem";
|
|
||||||
# format = "vfat";
|
|
||||||
# mountpoint = "/boot";
|
|
||||||
# mountOptions = [ "umask=0077" ];
|
|
||||||
# };
|
|
||||||
# };
|
|
||||||
# root = {
|
|
||||||
# name = "root";
|
|
||||||
# end = "-0";
|
|
||||||
# content = {
|
|
||||||
# type = "filesystem";
|
|
||||||
# format = "f2fs";
|
|
||||||
# mountpoint = "/";
|
|
||||||
# extraArgs = [
|
|
||||||
# "-O"
|
|
||||||
# "extra_attr,inode_checksum,sb_checksum,compression"
|
|
||||||
# ];
|
|
||||||
# mountOptions = [ "compress_algorithm=zstd:6,compress_chksum,atgc,gc_merge,lazytime,nodiscard" ];
|
|
||||||
# };
|
|
||||||
# };
|
|
||||||
# };
|
|
||||||
# };
|
|
||||||
# };
|
|
||||||
}
|
|
||||||
// (lib.listToAttrs (
|
|
||||||
map (disk: {
|
|
||||||
name = "data-${hashDisk disk}";
|
|
||||||
value = {
|
|
||||||
type = "disk";
|
|
||||||
device = disk;
|
|
||||||
content = {
|
|
||||||
type = "zfs";
|
|
||||||
pool = "zdata";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}) vdev
|
|
||||||
));
|
|
||||||
zpool = {
|
|
||||||
zdata = {
|
|
||||||
type = "zpool";
|
|
||||||
options.ashift = "12";
|
|
||||||
rootFsOptions = {
|
|
||||||
mountpoint = "none";
|
|
||||||
compression = "lz4";
|
|
||||||
acltype = "posixacl";
|
|
||||||
xattr = "sa";
|
|
||||||
"com.sun:auto-snapshot" = "true";
|
|
||||||
};
|
|
||||||
mode = {
|
|
||||||
topology = {
|
|
||||||
type = "topology";
|
|
||||||
vdev = [
|
|
||||||
{
|
|
||||||
mode = "mirror";
|
|
||||||
members = vdev;
|
|
||||||
}
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
datasets = {
|
|
||||||
"nas" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/mnt/hdd";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
"service-data" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/var/lib";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,108 @@
|
|||||||
|
{ lib, ... }:
|
||||||
|
let
|
||||||
|
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
||||||
|
os = "/dev/disk/by-id/mmc-SD64G_0x8336354b";
|
||||||
|
vdev = [
|
||||||
|
"/dev/disk/by-id/ata-ST20000NM002H-3KV133_ZYDBVV7Z"
|
||||||
|
"/dev/disk/by-id/ata-ST20000NM002H-3KV133_ZYDBSJRE"
|
||||||
|
];
|
||||||
|
in
|
||||||
|
{
|
||||||
|
|
||||||
|
boot.loader = {
|
||||||
|
systemd-boot = {
|
||||||
|
enable = true;
|
||||||
|
};
|
||||||
|
efi = {
|
||||||
|
canTouchEfiVariables = true;
|
||||||
|
};
|
||||||
|
};
|
||||||
|
boot.tmp.useTmpfs = true;
|
||||||
|
|
||||||
|
disko.devices = {
|
||||||
|
disk = {
|
||||||
|
"os-${hashDisk os}" = {
|
||||||
|
type = "disk";
|
||||||
|
device = os;
|
||||||
|
content = {
|
||||||
|
type = "gpt";
|
||||||
|
partitions = {
|
||||||
|
ESP = {
|
||||||
|
end = "500M";
|
||||||
|
type = "EF00";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "vfat";
|
||||||
|
mountpoint = "/boot";
|
||||||
|
mountOptions = [ "umask=0077" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
root = {
|
||||||
|
name = "root";
|
||||||
|
end = "-0";
|
||||||
|
content = {
|
||||||
|
type = "filesystem";
|
||||||
|
format = "f2fs";
|
||||||
|
mountpoint = "/";
|
||||||
|
extraArgs = [
|
||||||
|
"-O"
|
||||||
|
"extra_attr,inode_checksum,sb_checksum,compression"
|
||||||
|
];
|
||||||
|
mountOptions = [ "compress_algorithm=zstd:6,compress_chksum,atgc,gc_merge,lazytime,nodiscard" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
|
// (lib.listToAttrs (
|
||||||
|
map (disk: {
|
||||||
|
name = "data-${hashDisk disk}";
|
||||||
|
value = {
|
||||||
|
type = "disk";
|
||||||
|
device = disk;
|
||||||
|
content = {
|
||||||
|
type = "zfs";
|
||||||
|
pool = "zdata";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}) vdev
|
||||||
|
));
|
||||||
|
zpool = {
|
||||||
|
zdata = {
|
||||||
|
type = "zpool";
|
||||||
|
options.ashift = "12";
|
||||||
|
rootFsOptions = {
|
||||||
|
mountpoint = "none";
|
||||||
|
compression = "lz4";
|
||||||
|
acltype = "posixacl";
|
||||||
|
xattr = "sa";
|
||||||
|
"com.sun:auto-snapshot" = "true";
|
||||||
|
};
|
||||||
|
mode = {
|
||||||
|
topology = {
|
||||||
|
type = "topology";
|
||||||
|
vdev = [
|
||||||
|
{
|
||||||
|
mode = "mirror";
|
||||||
|
members = vdev;
|
||||||
|
}
|
||||||
|
];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
datasets = {
|
||||||
|
"nas" = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/mnt/hdd";
|
||||||
|
mountOptions = [ "nofail" ];
|
||||||
|
};
|
||||||
|
"service-data" = {
|
||||||
|
type = "zfs_fs";
|
||||||
|
mountpoint = "/var/lib";
|
||||||
|
mountOptions = [ "nofail" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -1,6 +0,0 @@
|
|||||||
{
|
|
||||||
fileSystems."/" = {
|
|
||||||
device = "/dev/disk/by-uuid/44444444-4444-4444-8888-888888888888";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,86 +0,0 @@
|
|||||||
{ ... }:
|
|
||||||
let
|
|
||||||
hashDisk = disk: "os-${builtins.substring 0 5 (builtins.hashString "sha256" disk)}";
|
|
||||||
os = "/dev/disk/by-id/scsi-0QEMU_QEMU_HARDDISK_119349241";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
boot.loader = {
|
|
||||||
systemd-boot = {
|
|
||||||
enable = true;
|
|
||||||
};
|
|
||||||
efi = {
|
|
||||||
canTouchEfiVariables = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
|
||||||
disk = {
|
|
||||||
"os-${hashDisk os}" = {
|
|
||||||
type = "disk";
|
|
||||||
device = os;
|
|
||||||
content = {
|
|
||||||
type = "gpt";
|
|
||||||
partitions = {
|
|
||||||
ESP = {
|
|
||||||
size = "1G";
|
|
||||||
type = "EF00";
|
|
||||||
content = {
|
|
||||||
type = "filesystem";
|
|
||||||
format = "vfat";
|
|
||||||
mountpoint = "/boot";
|
|
||||||
mountOptions = [ "nofail" ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
system = {
|
|
||||||
size = "100%";
|
|
||||||
content = {
|
|
||||||
type = "zfs";
|
|
||||||
pool = "zroot";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
zpool = {
|
|
||||||
zroot = {
|
|
||||||
type = "zpool";
|
|
||||||
rootFsOptions = {
|
|
||||||
mountpoint = "none";
|
|
||||||
compression = "lz4";
|
|
||||||
acltype = "posixacl";
|
|
||||||
xattr = "sa";
|
|
||||||
"com.sun:auto-snapshot" = "true";
|
|
||||||
};
|
|
||||||
options.ashift = "12";
|
|
||||||
datasets = {
|
|
||||||
"root" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "none";
|
|
||||||
};
|
|
||||||
"root/nixos" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/";
|
|
||||||
mountpoint = "/";
|
|
||||||
};
|
|
||||||
"root/home" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
options.mountpoint = "/home";
|
|
||||||
mountpoint = "/home";
|
|
||||||
};
|
|
||||||
"root/tmp" = {
|
|
||||||
type = "zfs_fs";
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
options = {
|
|
||||||
mountpoint = "/tmp";
|
|
||||||
sync = "disabled";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -10,11 +10,17 @@
|
|||||||
|
|
||||||
(inputs.import-tree ./services)
|
(inputs.import-tree ./services)
|
||||||
|
|
||||||
|
(import ../../lib/auto-accept-zerotier-members.nix {
|
||||||
|
memberIds = [
|
||||||
|
"dbe44c0287" # Alex-gateway
|
||||||
|
"b0e0b84fd3" # Alex
|
||||||
|
"2bd36db8cc" # kurogeek-thinkpad
|
||||||
|
];
|
||||||
|
})
|
||||||
];
|
];
|
||||||
|
|
||||||
clan.core.sops.defaultGroups = [ "admins" ];
|
clan.core.sops.defaultGroups = [ "admins" ];
|
||||||
|
clan.core.networking.targetHost = "root@[${config.clan.core.vars.generators.zerotier.files.zerotier-ip.value}]";
|
||||||
clan.core.settings.machine.description = "Glom NAS";
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = {
|
nixpkgs.hostPlatform = {
|
||||||
system = "x86_64-linux";
|
system = "x86_64-linux";
|
||||||
|
|||||||
@@ -18,8 +18,6 @@ in
|
|||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
boot.zfs.forceImportRoot = true;
|
|
||||||
|
|
||||||
disko.devices = {
|
disko.devices = {
|
||||||
disk = {
|
disk = {
|
||||||
"os-${hashDisk os}" = {
|
"os-${hashDisk os}" = {
|
||||||
|
|||||||
@@ -5,7 +5,6 @@
|
|||||||
name = "service-actual-budget";
|
name = "service-actual-budget";
|
||||||
|
|
||||||
clan = {
|
clan = {
|
||||||
test.useContainers = false;
|
|
||||||
directory = ./.;
|
directory = ./.;
|
||||||
inventory = {
|
inventory = {
|
||||||
machines.server = { };
|
machines.server = { };
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
# Apple Network
|
|
||||||
|
|
||||||
This service allows atalkd instances to connect to each other over vxlan over Yggdrasil. We need to use vxlan due to the support of broadcasting it provides. The service will form a network of star-topology vxlan using the underlying Yggdrasil network. With this vxlan network, we can have a private Apple Talk network over the internet.
|
|
||||||
|
|
||||||
@@ -1,139 +0,0 @@
|
|||||||
{ clanLib, ... }:
|
|
||||||
{
|
|
||||||
_class = "clan.service";
|
|
||||||
manifest.name = "apple-network";
|
|
||||||
manifest.description = "This service will create an instance of `atalkd` for each peer to talk to Apple machines over Apple Talk protocol and automatically connect each peer using vxlan over Yggdrasil network to achieve Apple Talk over internet experience";
|
|
||||||
manifest.readme = builtins.readFile ./README.md;
|
|
||||||
manifest.categories = [ "Network" ];
|
|
||||||
|
|
||||||
roles.peer = {
|
|
||||||
description = "A gateway machine that allow classic Apple machines to connect to other Apple machines over the internet";
|
|
||||||
|
|
||||||
interface =
|
|
||||||
{ lib, ... }:
|
|
||||||
{
|
|
||||||
options = {
|
|
||||||
zone_name = lib.mkOption {
|
|
||||||
type = with lib.types; str;
|
|
||||||
description = "Zone name for Apple Talk protocol";
|
|
||||||
default = "Default";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
perInstance =
|
|
||||||
{ roles, settings, ... }:
|
|
||||||
{
|
|
||||||
nixosModule =
|
|
||||||
{
|
|
||||||
lib,
|
|
||||||
config,
|
|
||||||
pkgs,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
vxlanPort = 4789;
|
|
||||||
|
|
||||||
getYggdrasilIP =
|
|
||||||
machineName:
|
|
||||||
if config.clan.core.vars.generators.yggdrasil.files.address ? value then
|
|
||||||
clanLib.getPublicValue {
|
|
||||||
flake = config.clan.core.settings.directory;
|
|
||||||
machine = machineName;
|
|
||||||
generator = "yggdrasil";
|
|
||||||
file = "address";
|
|
||||||
default = null;
|
|
||||||
}
|
|
||||||
else
|
|
||||||
throw "clanService/yggdrasil is required";
|
|
||||||
|
|
||||||
noSelfPeers = builtins.filter (peerName: peerName != config.clan.core.settings.machine.name) (
|
|
||||||
lib.mapAttrsToList (machineName: _: machineName) roles.peer.machines
|
|
||||||
);
|
|
||||||
|
|
||||||
sortedPeers = builtins.sort (x: y: x < y) (
|
|
||||||
lib.mapAttrsToList (machineName: _: machineName) roles.peer.machines
|
|
||||||
);
|
|
||||||
|
|
||||||
getMachineIndex = machineName: lib.lists.findFirstIndex (x: x == machineName) null sortedPeers;
|
|
||||||
|
|
||||||
selfVXAddress = "192.168.254.${
|
|
||||||
lib.toString ((getMachineIndex config.clan.core.settings.machine.name) + 1)
|
|
||||||
}/24";
|
|
||||||
in
|
|
||||||
{
|
|
||||||
|
|
||||||
services.atalkd = {
|
|
||||||
enable = true;
|
|
||||||
interfaces = {
|
|
||||||
vxlan.config = ''
|
|
||||||
-router -phase 2 -net 1 -zone "${settings.zone_name}"
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
networking.useNetworkd = true;
|
|
||||||
|
|
||||||
networking.firewall.interfaces."ygg".allowedUDPPorts = [ vxlanPort ];
|
|
||||||
|
|
||||||
boot.kernelModules = [ "vxlan" ];
|
|
||||||
|
|
||||||
systemd.network.netdevs =
|
|
||||||
builtins.listToAttrs (
|
|
||||||
map (
|
|
||||||
peerName:
|
|
||||||
(lib.nameValuePair "10-apl-vxlan-${peerName}" {
|
|
||||||
enable = true;
|
|
||||||
netdevConfig = {
|
|
||||||
Name = "vxlan-${peerName}";
|
|
||||||
Kind = "vxlan";
|
|
||||||
};
|
|
||||||
vxlanConfig = {
|
|
||||||
VNI = (getMachineIndex config.clan.core.settings.machine.name) + (getMachineIndex peerName);
|
|
||||||
Remote = getYggdrasilIP peerName;
|
|
||||||
DestinationPort = vxlanPort;
|
|
||||||
Independent = true;
|
|
||||||
};
|
|
||||||
})
|
|
||||||
) noSelfPeers
|
|
||||||
)
|
|
||||||
// {
|
|
||||||
"10-apl-vxlan" = {
|
|
||||||
enable = true;
|
|
||||||
netdevConfig = {
|
|
||||||
Kind = "bridge";
|
|
||||||
Name = "vxlan";
|
|
||||||
};
|
|
||||||
bridgeConfig = {
|
|
||||||
STP = true;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
systemd.network.networks =
|
|
||||||
builtins.listToAttrs (
|
|
||||||
map (
|
|
||||||
peerName:
|
|
||||||
(lib.nameValuePair "10-apl-vxlan-${peerName}" {
|
|
||||||
enable = true;
|
|
||||||
matchConfig.Name = "vxlan-${peerName}";
|
|
||||||
networkConfig.Bridge = "vxlan";
|
|
||||||
})
|
|
||||||
) noSelfPeers
|
|
||||||
)
|
|
||||||
// {
|
|
||||||
"10-apl-vxlan" = {
|
|
||||||
enable = true;
|
|
||||||
matchConfig.Name = "vxlan";
|
|
||||||
address = [ selfVXAddress ];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
environment.systemPackages = [
|
|
||||||
pkgs.netatalk
|
|
||||||
pkgs.bridge-utils
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,19 +0,0 @@
|
|||||||
{ inputs, self, ... }:
|
|
||||||
let
|
|
||||||
module = ./default.nix;
|
|
||||||
in
|
|
||||||
{
|
|
||||||
clan.modules = {
|
|
||||||
apple-network = module;
|
|
||||||
};
|
|
||||||
perSystem =
|
|
||||||
{ ... }:
|
|
||||||
{
|
|
||||||
clan.nixosTests.service-apple-network = {
|
|
||||||
imports = [ ./tests/vm/default.nix ];
|
|
||||||
_module.args = { inherit self inputs; };
|
|
||||||
|
|
||||||
clan.modules."@clan/apple-network" = module;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,76 +0,0 @@
|
|||||||
{
|
|
||||||
self,
|
|
||||||
lib,
|
|
||||||
config,
|
|
||||||
hostPkgs,
|
|
||||||
...
|
|
||||||
}:
|
|
||||||
{
|
|
||||||
name = "service-apple-network";
|
|
||||||
|
|
||||||
result.update-vars =
|
|
||||||
let
|
|
||||||
relativeDir = lib.removePrefix "${self}/" (toString config.clan.directory);
|
|
||||||
in
|
|
||||||
hostPkgs.writeShellScriptBin "update-vars" ''
|
|
||||||
set -x
|
|
||||||
export PRJ_ROOT=$(git rev-parse --show-toplevel)
|
|
||||||
${
|
|
||||||
self.inputs.clan-core.packages.${hostPkgs.system}.clan-cli
|
|
||||||
}/bin/clan-generate-test-vars $PRJ_ROOT/${relativeDir} ${config.name}
|
|
||||||
'';
|
|
||||||
|
|
||||||
clan = {
|
|
||||||
directory = ./.;
|
|
||||||
test.useContainers = false;
|
|
||||||
|
|
||||||
inventory = {
|
|
||||||
meta.domain = "test.clan";
|
|
||||||
|
|
||||||
machines.peer1 = { };
|
|
||||||
machines.peer2 = { };
|
|
||||||
machines.peer3 = { };
|
|
||||||
|
|
||||||
instances = {
|
|
||||||
apple-network = {
|
|
||||||
module.name = "@clan/apple-network";
|
|
||||||
module.input = "self";
|
|
||||||
roles.peer.machines = {
|
|
||||||
peer1 = { };
|
|
||||||
peer2 = { };
|
|
||||||
peer3 = { };
|
|
||||||
};
|
|
||||||
};
|
|
||||||
yggdrasil = {
|
|
||||||
module.name = "yggdrasil";
|
|
||||||
roles.default.tags.all = { };
|
|
||||||
roles.default.settings.extraPeers = [
|
|
||||||
"tls://ygg.jjolly.dev:3443"
|
|
||||||
"tls://[2602:fc24:18:7a42::1]:993"
|
|
||||||
"tcp://leo.node.3dt.net:9002"
|
|
||||||
"tcp://ygg-kcmo.incognet.io:8883"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
nodes = {
|
|
||||||
peer1 = { };
|
|
||||||
peer2 = { };
|
|
||||||
peer3 = { };
|
|
||||||
};
|
|
||||||
|
|
||||||
testScript = _: ''
|
|
||||||
# cannot test connectivity due to Yggdrasil's establishment
|
|
||||||
start_all()
|
|
||||||
peer1.wait_for_unit("atalkd")
|
|
||||||
peer1.succeed("systemctl status atalkd")
|
|
||||||
|
|
||||||
peer2.wait_for_unit("atalkd")
|
|
||||||
peer2.succeed("systemctl status atalkd")
|
|
||||||
|
|
||||||
peer3.wait_for_unit("atalkd")
|
|
||||||
peer3.succeed("systemctl status atalkd")
|
|
||||||
'';
|
|
||||||
}
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
[
|
|
||||||
{
|
|
||||||
"publickey": "age1f92zl8y70z5w9gn0l5leg2fhyvxy6m93dfh7n6ltgvuu9nyg6epsrw6t8x",
|
|
||||||
"type": "age"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
[
|
|
||||||
{
|
|
||||||
"publickey": "age1u36fr87cru90vfznf5szasya9nhvvseh4atk8zsdj0rrsu0nnvwqsyt8g6",
|
|
||||||
"type": "age"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
[
|
|
||||||
{
|
|
||||||
"publickey": "age1rka3368ltqc787xw99uu762lqfk7qxld9265u2t62fpxnp9xhufsc2q5rw",
|
|
||||||
"type": "age"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
{
|
|
||||||
"data": "ENC[AES256_GCM,data:hC4Lle6mXuTFq//wBHUTyH3X778u/gYJSXJOiQ7xUb+gnC8beH1olxL2ZhtUiMkktzhsPM/j6cxhltPp25UTeJnUOcoYesqZcp8=,iv:WOx2P2Cu4v58xM9ePjAw1gdA0fFnGG2UqEXH2iksGoo=,tag:43n1ibVSy2AeS9f5qQBKNQ==,type:str]",
|
|
||||||
"sops": {
|
|
||||||
"age": [
|
|
||||||
{
|
|
||||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBtT244N1Q3Zk9pRjFFQlUr\ncDExSTBwSWk5UXVyMjhWclQwSFZaYnpTRFY0CnE5YStVdzMrS3BKYzYvc3V3QVFY\nbDVwVytoNERveU1xQllqNUFGV2hYbGMKLS0tIDJSUmkwMUQzL3Y0MU5qZTJ3eFN3\nNGdwamM1UDBPdzhvSWsyZzR6anZ0eFEKKnr1/7rf3fH1i7KUoZdilLDgb44K2qzn\nI9Y+7FbV4gzQUzKWjAQeFN37Z4Qiuy0xJVA0lw8KvM+NCxSZDfh3kw==\n-----END AGE ENCRYPTED FILE-----\n",
|
|
||||||
"recipient": "age1qm0p4vf9jvcnn43s6l4prk8zn6cx0ep9gzvevxecv729xz540v8qa742eg"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"lastmodified": "2026-07-03T10:46:56Z",
|
|
||||||
"mac": "ENC[AES256_GCM,data:hmpbOtra6EyNiPg7EsA3F4elHEO87JPUr4VKVppvzUwLX1HSj67WrU6k3rEoJT+k7Hq1lxnAzDEckSG1fUOap11rk8ksp1IAGR0+yqykC/Qj/Nl8wXqP84gr49bJK6xE/DDdCRCcBff2d6IpnehyEr8fGFEZbWGygblec8U8GPo=,iv:+M1C3rL22foowr0VD80jwrNFb5xz4k5JQ/DJm4ThKHk=,tag:wabFAC5NTCVGfIQQzm0yGg==,type:str]",
|
|
||||||
"version": "3.13.1"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
../../../users/admin
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
{
|
|
||||||
"data": "ENC[AES256_GCM,data:ndWIEOqP2ybCN7Ak5g+8q3YG5rLQ7OuSv/vCbnMA8AK6Lby2JMGRkRGysqJdyEF7eh4w7PpZ/AtKPtPbUucjeTB5+8g76PPJTBE=,iv:EYy0GGqEBmIc5rSWP7Zleb5eQ0JzTz84HqeJPpCSpxk=,tag:iMgTUb9+wxE9S2kKoOEvsQ==,type:str]",
|
|
||||||
"sops": {
|
|
||||||
"age": [
|
|
||||||
{
|
|
||||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBQTEF6OXN4K0dHdXhWWmt2\neG5wdkNIc2F0UnFEeHFLQkdTWkFpUWhTa0NBCmw2N2J1T0FJVE9JR3VBRWV0THh5\nVEZlbVZrcXAwK3BsYXFOZUF6c3lRSkUKLS0tIFRCQzNUaGFHdERWNWR4enVWRGpx\nbDEzRU9jWHgxWHovaENjbkFlZERIbkkKvAW31gTJg9izrWuAMeDHS9SWPQYtxRBY\necDCn8QORFrnDdxEusCnGJrAU4kmS3Y3CwSHCtEijs3JdIgg9wl/MA==\n-----END AGE ENCRYPTED FILE-----\n",
|
|
||||||
"recipient": "age1qm0p4vf9jvcnn43s6l4prk8zn6cx0ep9gzvevxecv729xz540v8qa742eg"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"lastmodified": "2026-07-03T10:47:04Z",
|
|
||||||
"mac": "ENC[AES256_GCM,data:y1U2vsdqR97fPAnp6iZiLY1KbWYmgDqgZ5bwIkWPCr7Gjjrn+qV+sc2T1BTVz3Zo0JOz4ScCc+f6snVsFKdCDU/NmDVFt/sqyH4NHUPRQ3StsQim8C7IkSwUtm3EhrqpLYFD21MEjrYYdHMHbWybxrOI0qI6mDwZymHJFeCLdQA=,iv:lVvPn69eQE/huwDmwePepfpi2l9ZOPQO7W20o4AJBFQ=,tag:7VPfjKZsBVJTZxNwTcI6sg==,type:str]",
|
|
||||||
"version": "3.13.1"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
../../../users/admin
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
{
|
|
||||||
"data": "ENC[AES256_GCM,data:JPdetkhtF9eSmgEfCO2exXlGQ5KWLeIM3mnW5BfyTY8r0PxWSEGAwBskC1SiDdRERWB2VEbPiPgCNXMnGaYlDqSdZN6R9wSFvsQ=,iv:qGveNhUtgxvKnmdsPoPpffKyi5srlq0Pd6aW283B5C0=,tag:TcJsCrBlzfjXvztcRaxYFQ==,type:str]",
|
|
||||||
"sops": {
|
|
||||||
"age": [
|
|
||||||
{
|
|
||||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAvdjNHa1RlcFJHazB5TXFu\nOUQ4REpCZm5Yc3ZhcVhwT1FqRHlvbnoxZWlFCnNrVUEyK2ZYSmlacmJ2b2QrclZl\nSDV1eWxXVmJxZlhMMXgrTWtjcjVhQlkKLS0tIHZPN3pCUVBLQmpRVGx6SDBQNDZo\nSitheGhXNGl5QW9HTGNsTTdTdWVwaE0KfuM5xZOPbR1lxkJPJUOVrtlW5Ujobemp\nid40reDqxKQxP3khJv8lf9ZoN8LAx2Iwh0DeAl+UJpsoVWgS7uI2qQ==\n-----END AGE ENCRYPTED FILE-----\n",
|
|
||||||
"recipient": "age1qm0p4vf9jvcnn43s6l4prk8zn6cx0ep9gzvevxecv729xz540v8qa742eg"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"lastmodified": "2026-07-07T04:54:10Z",
|
|
||||||
"mac": "ENC[AES256_GCM,data:Tt8yqzfAnSDe2n7KDt1Z/D73hkS1w7DsqIh+s5WljLzar9PEt5vUCLb8DIvBwITyzGAoHH1ym3v3NrnJWCdxajKExTMBf4aY3MJCtykeCG37701S/KxumjTW9/fJw74gcET5I6NafTWb6H5XHsrRaQX1Xnspcs8B7uLGZZ28dSM=,iv:Fo5UPVhnjuOx6Cp4grofHOiD2pm0TXuRRuoTwvxKn1s=,tag:VQ/TF1TiyJADj7/3RwPCAg==,type:str]",
|
|
||||||
"version": "3.13.1"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
../../../users/admin
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
{
|
|
||||||
"publickey": "age1qm0p4vf9jvcnn43s6l4prk8zn6cx0ep9gzvevxecv729xz540v8qa742eg",
|
|
||||||
"type": "age"
|
|
||||||
}
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
26.11
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
200:e6cc:c86:f02d:b0d5:fba9:9b2c:eb77
|
|
||||||
-1
@@ -1 +0,0 @@
|
|||||||
../../../../../../sops/machines/peer1
|
|
||||||
-18
@@ -1,18 +0,0 @@
|
|||||||
{
|
|
||||||
"data": "ENC[AES256_GCM,data:6YDp5S2TzEnhDgGhcz8cA3uBsfDt0Oc4JpztB1JUcg/+tDBbeaQN4MLxuZKstXn2Hb1mYtBLlX0vHw++T181Js2sIznyfC1lr68GOvQAp4NYgf23dXpdZk/CMPNUMiGOYVwKWQ/Z0/p0azJ6xV29dYQcM4Q9hys=,iv:Ijzz8hm0looCWoSpjg/rYKp9jhvzRuLboKWHrlwVeFA=,tag:kJcH/1Pu+9q9f2J68LETug==,type:str]",
|
|
||||||
"sops": {
|
|
||||||
"age": [
|
|
||||||
{
|
|
||||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBYNDNEL3kvdEpEMjYyOFJG\nMk5adU04M3hxa21jTTZNM2dQREpmUlVES1NvCjh6eDNFZ1hzUVlTY3Nidnp3TkYr\nRVl4TFlrNUE3dVIzZzg2VWMwTFBYUXMKLS0tIFE0dVFQQmxwOFJ6YkdaQlh6dUlW\nTi8rdXdQbGR1eXpLcTdOandqQmxka3cKImbmJQo2YMYMSQD8kNTgol3VJ4YGIaoz\nl3AY4u/fobg5qlzVQwV33G0/Wf72Z2aTjSLnP4thnasQ89PdYvs7hA==\n-----END AGE ENCRYPTED FILE-----\n",
|
|
||||||
"recipient": "age1f92zl8y70z5w9gn0l5leg2fhyvxy6m93dfh7n6ltgvuu9nyg6epsrw6t8x"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBiaWw5SU9KWmJnVVVmTVpr\nL1V6RnRYUGg2UnhXR1BnVTh5eFhnNFpidGdjCmdMeU1nZkZmTTVwbkNaVElFa0Z4\nVkdGdjc4c2lPWGNrVGxocE9iQUZ3QTAKLS0tIHIzTzRRbXVkM3I4ZVRxeSs5eHV5\nTUxOaytzb2MxQ2UybkVCYWVWVmVEcUEKPeK+CC7r3CP5BJqg9thWNHWjPBp/ueHU\nRif6T79kqf+c3B34qXwR0zfyM1+a0r9GAVVC2/q+Ha/As5sPJU39ww==\n-----END AGE ENCRYPTED FILE-----\n",
|
|
||||||
"recipient": "age1qm0p4vf9jvcnn43s6l4prk8zn6cx0ep9gzvevxecv729xz540v8qa742eg"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"lastmodified": "2026-07-03T10:46:56Z",
|
|
||||||
"mac": "ENC[AES256_GCM,data:PffiPU1GR9DojTb7TxzBkpivKV2ybmmq9h4pOOyq7p5BAIPF+JSe+BDtbItQ+Gn5LnitQRUVvhat8E2iYfz3JgNxNKcsNFU/mWtCz3PlqyiuRzUBtEL3zYfhdMi8hYYlVdfMumaK3VMk+b4uDGExR+MpURL97TFku47qRbzbILs=,iv:3//fj7WtIX2QNYB9ub1JKAFIn5vJeuZl6rqaEsX0oQc=,tag:njU+WAVq7xBgE0sna2dMKA==,type:str]",
|
|
||||||
"version": "3.13.1"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
-1
@@ -1 +0,0 @@
|
|||||||
../../../../../../sops/users/admin
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
8c99f9bc87e92795022b32698a440d6f9fe01d1110f867de8176bb190b92acab
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
26.11
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
200:eb95:7d1b:3ac3:62e7:24af:2274:3771
|
|
||||||
-1
@@ -1 +0,0 @@
|
|||||||
../../../../../../sops/machines/peer2
|
|
||||||
-18
@@ -1,18 +0,0 @@
|
|||||||
{
|
|
||||||
"data": "ENC[AES256_GCM,data:vOwMqT12A5ap5hRvCGTjTUX4sXKO3N7KE8eQ+/SCcBWndU9/b2AehiNgplWWMGcYdmeDL9qI8V2pPkgBkQ/tWH6N8DccSM/zQzrBUkXvRApl6hvNZAWuBVf/P4MW4/EbRGtMg2tEXkaPDtRn2TsDK7ygmXmqArI=,iv:FkxFx/ClAftLu85S6Uq3ZOom+YDOpeWGlYLOFBmFfnk=,tag:zprw62qiu+hmLZEZbnqYXA==,type:str]",
|
|
||||||
"sops": {
|
|
||||||
"age": [
|
|
||||||
{
|
|
||||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSA0WVB1M2ttd0FocGhTSjNo\nUDFIcmpsL051TndWbkJVakJHbUxjY3Q3NjM0CnkrbFlHS1E4bkZJQTIvMDJ3VDFv\nNW1OdmwvalBEelN2d3YwbHVqTW94OFEKLS0tIGtpOWxCM29xdXhQL2Yzb094OG1n\nT21mc25yU1dJL29vekRHdldzdDR3dEkKoZ1dPRaPg8iVsuec6IhV3cLPchokV2wv\nu6qb92hsLQuyPHDA01Oey0jxmaYMQGtAVjo2zEM+E+zrKY+f2pHIUQ==\n-----END AGE ENCRYPTED FILE-----\n",
|
|
||||||
"recipient": "age1qm0p4vf9jvcnn43s6l4prk8zn6cx0ep9gzvevxecv729xz540v8qa742eg"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSArcmo5d2x6c3J0YTkwMGJE\nanphd2FiUjdGdmdNeW0rL0FpcTVSM3dublZ3CnphajNVV2YrTGl2a3ZqMTJKeU4v\nTzZRS2F5MlA5Ny84cFFoNWZQZnpBZTgKLS0tIHVKQUJWcmlPdy9GNXNBYnpJcEVC\nNmJVMlpvSzZPdk1JY2hIZVEvc3cwV2MKE/cMJU/j5g62njJ49AfnLutmxkpz/gxX\nIqWe1m7Uxl/awVFa7F8N7TUkd0jLbAGXZaonDjiBxOTwg/jr/apnuQ==\n-----END AGE ENCRYPTED FILE-----\n",
|
|
||||||
"recipient": "age1u36fr87cru90vfznf5szasya9nhvvseh4atk8zsdj0rrsu0nnvwqsyt8g6"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"lastmodified": "2026-07-03T10:47:04Z",
|
|
||||||
"mac": "ENC[AES256_GCM,data:wiIkwEDwGJZe0u8qLHthPkCXubeIGyHV8yBo8CsSengLVTOtRZ877zTrFvE74ATF1pGE3DFJ5qGRrOGgKJ4VOl043LbEBs0bxZC495pPMPYszimp2UAf/XE3QWlNi9p4Ce/kbvUDd0W3SRt4hIv6HOLWApiRoqfS2qSMUnBQeW0=,iv:Hs7EysUnje/iWZRhJLlqf8wuFJnIMpWfXWHrilfmM5I=,tag:Rgj9x4ZOM2fihKKNQ4ux3g==,type:str]",
|
|
||||||
"version": "3.13.1"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
-1
@@ -1 +0,0 @@
|
|||||||
../../../../../../sops/users/admin
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
8a354172629e4e8c6da86ec5e447411e4238cf7bb439b798fae56509a82d7472
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
26.11
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
200:3dcd:9b0d:103c:f953:1e8:e3a2:ed90
|
|
||||||
-1
@@ -1 +0,0 @@
|
|||||||
../../../../../../sops/machines/peer3
|
|
||||||
-18
@@ -1,18 +0,0 @@
|
|||||||
{
|
|
||||||
"data": "ENC[AES256_GCM,data:7no9ZnfatNLEykz+JOUExxmaRzBr7B5PEcevETySJWHTCCjSULdRb2KLxbXP5OKWSuJbR8pJ+p+nZuyr7aOTyXrU+fgwf/Pff4KGaZbKf1t3HJun8wJ2q62uaFYu8ACbNFfwIzJ51SPGcO7IHxfjWn5k9zG7av4=,iv:+VNvFKAJ+HDCGZciug8SKHOcM1JZQUAbZpRT5en4xcU=,tag:3kcDHWIs9ITzTKDiyyYhnQ==,type:str]",
|
|
||||||
"sops": {
|
|
||||||
"age": [
|
|
||||||
{
|
|
||||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBvZ0VFcGhPR0NrMGU4dStU\nZGpnMHZmbUF0R0NFNWQzNGVpZXhYQ24xNXk0CnJIYmJYMnBmeURLZytBcXNRNG5u\nZzk4cXdPdnJIU0JVam1NWFA3TkhuWFkKLS0tIDZYUEVGMUtCQWdSM3k4WEZhdUt3\naElkc3o5SXlFYTJLNUpGZ0ptNm96M2MKYKW5emktK2M+IYX0v/swCV1fgrQXQVlb\nmz11rN5fJWV5wvLcTtyU9imgZLB9MfRMyIYlHzD2HPbW+zr8Fe+bBQ==\n-----END AGE ENCRYPTED FILE-----\n",
|
|
||||||
"recipient": "age1qm0p4vf9jvcnn43s6l4prk8zn6cx0ep9gzvevxecv729xz540v8qa742eg"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"enc": "-----BEGIN AGE ENCRYPTED FILE-----\nYWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBZVDVxY3JrWk1TY3ZsazNz\naVl4Vk1vRUdkRTdlaDU1TE15dC96ZHlxQ1ZBCmYvSmh1QlBNRnJyRy9kcDR0cXhY\neDdPUXZ6b2FkWnBXbzA4bzU1aFo3bEUKLS0tIHMrb05Oa3FrRzh5VHN1RWRmUU9W\ndGZUYTVVQkIzM3FRRHp6NXlEdEU0VTgK7ibTaEcvbVTQjcbgeylu2s5tmI5kAadM\nFGiOgJhDFuzbHxXIEQlsCBIaXe6LlGhBo41VZbMxme5py6nJFTBHKg==\n-----END AGE ENCRYPTED FILE-----\n",
|
|
||||||
"recipient": "age1rka3368ltqc787xw99uu762lqfk7qxld9265u2t62fpxnp9xhufsc2q5rw"
|
|
||||||
}
|
|
||||||
],
|
|
||||||
"lastmodified": "2026-07-07T04:54:10Z",
|
|
||||||
"mac": "ENC[AES256_GCM,data:gonhuGY61G3Gdtj7q23aTNYU95fjLMz2uVTsSX+Hw10LGUTEMM8LF/Phae9kr5BZKD8BYaIgH32As2+n0B9jZ4WV77A5hUe2NJze9d0A40P2MtMh9xFWWh7yEXXnx5dy1UDrthL2LBa7ebPspuaC0mFhRHdoJK3J2W1m41PGjZc=,iv:H4yNuE8i3UxVjAUIpnaFX6i8/DaO4uIlHrEY9VaSiRs=,tag:9lJtixSNv7tpox0V3ZoNnA==,type:str]",
|
|
||||||
"version": "3.13.1"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
-1
@@ -1 +0,0 @@
|
|||||||
../../../../../../sops/users/admin
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
e119327977e183567f0b8e2e8937c9d04708e296beed57792a1b6935eacf69d9
|
|
||||||
@@ -20,7 +20,6 @@
|
|||||||
'';
|
'';
|
||||||
|
|
||||||
clan = {
|
clan = {
|
||||||
test.useContainers = false;
|
|
||||||
directory = ./.;
|
directory = ./.;
|
||||||
inventory = {
|
inventory = {
|
||||||
machines.server = { };
|
machines.server = { };
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user