dc0c8dfc8d
bicep/minecraft-heatmap: gate remaining config behind cfg.enable
2026-02-17 08:41:17 +01:00
fceb1099cb
bicep/postgres: gate remaining config behind cfg.enable
2026-02-17 08:41:17 +01:00
9d3fd44f30
bicep/{postgres,mysql}: add rsync pull targets for backups
2026-02-17 08:41:17 +01:00
0ed3de8d4c
kommode: use disko to configure disks
2026-02-17 08:41:17 +01:00
53d963e2d2
kommode/gitea: add rsync pull target for gitea dump dir
2026-02-17 08:41:17 +01:00
4552d4e6d3
bekkalokk/mediawiki, bicep/matrix/synapse: add keys for rsync targets
2026-02-17 08:41:17 +01:00
67b0353a2b
bicep/mysql: use BindPaths to access dataDir
2026-02-17 08:41:17 +01:00
8f261c58a0
bekkalokk/well-known: add note about bug bounty program to security.txt
2026-02-17 08:41:17 +01:00
e0aa6d5f86
bicep/element: set default country code
2026-02-17 08:41:17 +01:00
c5bd241c65
hosts/various: bump stateVersion
2026-02-17 08:41:17 +01:00
ed8aeabe27
bicep: bump stateVersion from 22.11 -> 25.11
2026-02-17 08:41:17 +01:00
6f57e647a5
bekkalokk: bump stateVersion from 22.11 -> 25.11
2026-02-17 08:41:17 +01:00
20cef592b7
bekkalokk/mediawiki, bicep/matrix/synapse: leave principal rsync target stubs
2026-02-17 08:41:17 +01:00
4260c4adae
modules/rsync-pull-targets: init, migrate bekkalokk/website/fetch-gallery
2026-02-17 08:41:17 +01:00
207a0dd8ec
bicep/hookshot: add passkey to sops
2026-02-17 08:41:17 +01:00
61f560c1d2
bekkalokk/mediawiki: move secret.key to sops
2026-02-17 08:41:17 +01:00
c75468b275
skrott: yeet 700MB worth of firmware, leave raspberry-specific firmware be
2026-02-17 08:41:17 +01:00
fa70163e7a
ildkule/prometheus: add temmie,gluttony, re-enable lupine-2
2026-02-17 08:41:17 +01:00
5c7c929975
ildkule/prometheus: scrape skrott
2026-02-17 08:41:17 +01:00
0673039e78
skrott: don't pull in nixpkgs/nixpkgs-unstable source tarballs
2026-02-17 08:41:17 +01:00
d0daafdf69
bakke: fix eval warnings about kernel packages
2026-02-17 08:41:17 +01:00
0383ac1696
bekkalokk/mediawiki: remove nonused module import
2026-02-17 08:41:17 +01:00
18e8b813b1
skrott: cross compile and further minimize
2026-02-17 08:41:16 +01:00
ca9247a325
skrott/dibbler: fix postgres url
2026-02-17 08:41:16 +01:00
9acddf5067
skrott: disable promtail, documentation
2026-02-17 08:41:16 +01:00
65318093eb
skrott: disable thermald
2026-02-17 08:41:16 +01:00
5189d6772b
skrott: disable zfs, udisks2
2026-02-17 08:41:16 +01:00
6fd6263693
skrott: disable smartd
2026-02-17 08:41:16 +01:00
a76be0d23a
skrott: set gateway
2026-02-17 08:41:16 +01:00
1a90981060
skrott: bump stateVersion
2026-02-17 08:41:16 +01:00
0273344997
skrott: update dibbler + config
2026-02-17 08:41:16 +01:00
0648794360
use grub as bootloader because of no uefi support
2026-02-17 08:41:16 +01:00
4e6c05a08d
skrott: fix sops file location
2026-02-17 08:41:16 +01:00
eff8ce7161
temmie: set up httpd
2026-02-17 08:41:16 +01:00
741e3a297f
skrott: move networking config to values, add ipv6 address
2026-02-17 08:41:16 +01:00
bd402b8fd0
gluttony: fix eval
2026-02-17 08:41:16 +01:00
77971ce459
temmie/nfs-mounts: generate systemd units ourselves
2026-02-17 08:41:16 +01:00
07d9f76d5a
base: configure sops
2026-02-17 08:41:16 +01:00
307c48b21c
hosts/various: enable qemu guest agent, disable smartd for vms by default
2026-02-17 08:41:16 +01:00
efc4c164a3
hosts/various: formatting, add consistent warnings to stateVersion
2026-02-17 08:41:16 +01:00
0c5cb3c64f
flake.nix: set default hostname for most nixos hosts
2026-02-17 08:41:16 +01:00
5bb13f4d06
bikkje: set hostName
2026-02-17 08:41:16 +01:00
ad74a3e377
hosts/various: use systemd-boot as default bootloader
2026-02-17 08:41:16 +01:00
0b5eb548c0
hosts/various: remove empty environment.systemPackages lists
2026-02-17 08:41:16 +01:00
9f3524e8dd
base: disable fontconfig by default
2026-02-17 08:41:16 +01:00
4a328c3234
bekkalokk/well-known: reply to well-known for all domains
2026-02-17 08:41:16 +01:00
190a8334b4
bicep/element: fetch correct well-known file
2026-02-17 08:41:16 +01:00
c302d26a96
bicep/matrix: remove some whitespace lol
2026-02-17 08:41:16 +01:00
a1c06aae32
bicep/sshguard: disable
...
sshguard doesn't actually work as it currently stands, also the builtin
PerSourcePenalty functionality in SSH is more aggressive than sshguard
is able to catch anyway. It might've been reasonable if we were using it
for anything other than SSH, but it doesn't seem like we are.
2026-02-17 08:41:16 +01:00
1ac9fe5fbd
bicep/matrix: use sops templates to render structured files
2026-02-17 08:41:16 +01:00