Commit Graph

440 Commits

Author SHA1 Message Date
dc0c8dfc8d bicep/minecraft-heatmap: gate remaining config behind cfg.enable 2026-02-17 08:41:17 +01:00
fceb1099cb bicep/postgres: gate remaining config behind cfg.enable 2026-02-17 08:41:17 +01:00
9d3fd44f30 bicep/{postgres,mysql}: add rsync pull targets for backups 2026-02-17 08:41:17 +01:00
0ed3de8d4c kommode: use disko to configure disks 2026-02-17 08:41:17 +01:00
53d963e2d2 kommode/gitea: add rsync pull target for gitea dump dir 2026-02-17 08:41:17 +01:00
4552d4e6d3 bekkalokk/mediawiki, bicep/matrix/synapse: add keys for rsync targets 2026-02-17 08:41:17 +01:00
67b0353a2b bicep/mysql: use BindPaths to access dataDir 2026-02-17 08:41:17 +01:00
8f261c58a0 bekkalokk/well-known: add note about bug bounty program to security.txt 2026-02-17 08:41:17 +01:00
e0aa6d5f86 bicep/element: set default country code 2026-02-17 08:41:17 +01:00
c5bd241c65 hosts/various: bump stateVersion 2026-02-17 08:41:17 +01:00
ed8aeabe27 bicep: bump stateVersion from 22.11 -> 25.11 2026-02-17 08:41:17 +01:00
6f57e647a5 bekkalokk: bump stateVersion from 22.11 -> 25.11 2026-02-17 08:41:17 +01:00
20cef592b7 bekkalokk/mediawiki, bicep/matrix/synapse: leave principal rsync target stubs 2026-02-17 08:41:17 +01:00
4260c4adae modules/rsync-pull-targets: init, migrate bekkalokk/website/fetch-gallery 2026-02-17 08:41:17 +01:00
207a0dd8ec bicep/hookshot: add passkey to sops 2026-02-17 08:41:17 +01:00
61f560c1d2 bekkalokk/mediawiki: move secret.key to sops 2026-02-17 08:41:17 +01:00
c75468b275 skrott: yeet 700MB worth of firmware, leave raspberry-specific firmware be 2026-02-17 08:41:17 +01:00
fa70163e7a ildkule/prometheus: add temmie,gluttony, re-enable lupine-2 2026-02-17 08:41:17 +01:00
5c7c929975 ildkule/prometheus: scrape skrott 2026-02-17 08:41:17 +01:00
0673039e78 skrott: don't pull in nixpkgs/nixpkgs-unstable source tarballs 2026-02-17 08:41:17 +01:00
d0daafdf69 bakke: fix eval warnings about kernel packages 2026-02-17 08:41:17 +01:00
0383ac1696 bekkalokk/mediawiki: remove nonused module import 2026-02-17 08:41:17 +01:00
18e8b813b1 skrott: cross compile and further minimize 2026-02-17 08:41:16 +01:00
ca9247a325 skrott/dibbler: fix postgres url 2026-02-17 08:41:16 +01:00
9acddf5067 skrott: disable promtail, documentation 2026-02-17 08:41:16 +01:00
65318093eb skrott: disable thermald 2026-02-17 08:41:16 +01:00
5189d6772b skrott: disable zfs, udisks2 2026-02-17 08:41:16 +01:00
6fd6263693 skrott: disable smartd 2026-02-17 08:41:16 +01:00
a76be0d23a skrott: set gateway 2026-02-17 08:41:16 +01:00
1a90981060 skrott: bump stateVersion 2026-02-17 08:41:16 +01:00
0273344997 skrott: update dibbler + config 2026-02-17 08:41:16 +01:00
0648794360 use grub as bootloader because of no uefi support 2026-02-17 08:41:16 +01:00
4e6c05a08d skrott: fix sops file location 2026-02-17 08:41:16 +01:00
eff8ce7161 temmie: set up httpd 2026-02-17 08:41:16 +01:00
741e3a297f skrott: move networking config to values, add ipv6 address 2026-02-17 08:41:16 +01:00
bd402b8fd0 gluttony: fix eval 2026-02-17 08:41:16 +01:00
77971ce459 temmie/nfs-mounts: generate systemd units ourselves 2026-02-17 08:41:16 +01:00
07d9f76d5a base: configure sops 2026-02-17 08:41:16 +01:00
307c48b21c hosts/various: enable qemu guest agent, disable smartd for vms by default 2026-02-17 08:41:16 +01:00
efc4c164a3 hosts/various: formatting, add consistent warnings to stateVersion 2026-02-17 08:41:16 +01:00
0c5cb3c64f flake.nix: set default hostname for most nixos hosts 2026-02-17 08:41:16 +01:00
5bb13f4d06 bikkje: set hostName 2026-02-17 08:41:16 +01:00
ad74a3e377 hosts/various: use systemd-boot as default bootloader 2026-02-17 08:41:16 +01:00
0b5eb548c0 hosts/various: remove empty environment.systemPackages lists 2026-02-17 08:41:16 +01:00
9f3524e8dd base: disable fontconfig by default 2026-02-17 08:41:16 +01:00
4a328c3234 bekkalokk/well-known: reply to well-known for all domains 2026-02-17 08:41:16 +01:00
190a8334b4 bicep/element: fetch correct well-known file 2026-02-17 08:41:16 +01:00
c302d26a96 bicep/matrix: remove some whitespace lol 2026-02-17 08:41:16 +01:00
a1c06aae32 bicep/sshguard: disable
sshguard doesn't actually work as it currently stands, also the builtin
PerSourcePenalty functionality in SSH is more aggressive than sshguard
is able to catch anyway. It might've been reasonable if we were using it
for anything other than SSH, but it doesn't seem like we are.
2026-02-17 08:41:16 +01:00
1ac9fe5fbd bicep/matrix: use sops templates to render structured files 2026-02-17 08:41:16 +01:00