Compare commits
	
		
			1 Commits
		
	
	
		
			dagali-hei
			...
			setup-open
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 
						
						
							
						
						9dce4f58b1
	
				 | 
					
					
						
@@ -3,10 +3,6 @@
 | 
				
			|||||||
  systemd.network.enable = true;
 | 
					  systemd.network.enable = true;
 | 
				
			||||||
  networking.domain = "pvv.ntnu.no";
 | 
					  networking.domain = "pvv.ntnu.no";
 | 
				
			||||||
  networking.useDHCP = false;
 | 
					  networking.useDHCP = false;
 | 
				
			||||||
  # networking.search = [ "pvv.ntnu.no" "pvv.org" ];
 | 
					 | 
				
			||||||
  # networking.nameservers = lib.mkDefault [ "129.241.0.200" "129.241.0.201" ];
 | 
					 | 
				
			||||||
  # networking.tempAddresses = lib.mkDefault "disabled";
 | 
					 | 
				
			||||||
  # networking.defaultGateway = values.hosts.gateway;
 | 
					 | 
				
			||||||
 | 
					
 | 
				
			||||||
  # The rest of the networking configuration is usually sourced from /values.nix
 | 
					  # The rest of the networking configuration is usually sourced from /values.nix
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -7,7 +7,7 @@
 | 
				
			|||||||
      # --update-input is deprecated since nix 2.22, and removed in lix 2.90
 | 
					      # --update-input is deprecated since nix 2.22, and removed in lix 2.90
 | 
				
			||||||
      # https://git.lix.systems/lix-project/lix/issues/400
 | 
					      # https://git.lix.systems/lix-project/lix/issues/400
 | 
				
			||||||
      "--refresh"
 | 
					      "--refresh"
 | 
				
			||||||
      "--override-input" "nixpkgs" "github:nixos/nixpkgs/nixos-24.11-small"
 | 
					      "--override-input" "nixpkgs" "github:nixos/nixpkgs/nixos-24.05-small"
 | 
				
			||||||
      "--override-input" "nixpkgs-unstable" "github:nixos/nixpkgs/nixos-unstable-small"
 | 
					      "--override-input" "nixpkgs-unstable" "github:nixos/nixpkgs/nixos-unstable-small"
 | 
				
			||||||
      "--no-write-lock-file"
 | 
					      "--no-write-lock-file"
 | 
				
			||||||
    ];
 | 
					    ];
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -1,8 +1,42 @@
 | 
				
			|||||||
{ ... }:
 | 
					{ ... }:
 | 
				
			||||||
{
 | 
					{
 | 
				
			||||||
 | 
					  # source: https://github.com/logrotate/logrotate/blob/main/examples/logrotate.service
 | 
				
			||||||
  systemd.services.logrotate = {
 | 
					  systemd.services.logrotate = {
 | 
				
			||||||
    documentation = [ "man:logrotate(8)" "man:logrotate.conf(5)" ];
 | 
					    documentation = [ "man:logrotate(8)" "man:logrotate.conf(5)" ];
 | 
				
			||||||
    unitConfig.RequiresMountsFor = "/var/log";
 | 
					    unitConfig.RequiresMountsFor = "/var/log";
 | 
				
			||||||
    serviceConfig.ReadWritePaths = [ "/var/log" ];
 | 
					    serviceConfig = {
 | 
				
			||||||
 | 
					      Nice = 19;
 | 
				
			||||||
 | 
					      IOSchedulingClass = "best-effort";
 | 
				
			||||||
 | 
					      IOSchedulingPriority = 7;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      ReadWritePaths = [ "/var/log" ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      AmbientCapabilities = [ "" ];
 | 
				
			||||||
 | 
					      CapabilityBoundingSet = [ "" ];
 | 
				
			||||||
 | 
					      DeviceAllow = [ "" ];
 | 
				
			||||||
 | 
					      LockPersonality = true;
 | 
				
			||||||
 | 
					      MemoryDenyWriteExecute = true;
 | 
				
			||||||
 | 
					      NoNewPrivileges = true; # disable for third party rotate scripts
 | 
				
			||||||
 | 
					      PrivateDevices = true;
 | 
				
			||||||
 | 
					      PrivateNetwork = true; # disable for mail delivery
 | 
				
			||||||
 | 
					      PrivateTmp = true;
 | 
				
			||||||
 | 
					      ProtectClock = true;
 | 
				
			||||||
 | 
					      ProtectControlGroups = true;
 | 
				
			||||||
 | 
					      ProtectHome = true; # disable for userdir logs
 | 
				
			||||||
 | 
					      ProtectHostname = true;
 | 
				
			||||||
 | 
					      ProtectKernelLogs = true;
 | 
				
			||||||
 | 
					      ProtectKernelModules = true;
 | 
				
			||||||
 | 
					      ProtectKernelTunables = true;
 | 
				
			||||||
 | 
					      ProtectProc = "invisible";
 | 
				
			||||||
 | 
					      ProtectSystem = "full";
 | 
				
			||||||
 | 
					      RestrictNamespaces = true;
 | 
				
			||||||
 | 
					      RestrictRealtime = true;
 | 
				
			||||||
 | 
					      RestrictSUIDSGID = true; # disable for creating setgid directories
 | 
				
			||||||
 | 
					      SocketBindDeny = [ "any" ];
 | 
				
			||||||
 | 
					      SystemCallArchitectures = "native";
 | 
				
			||||||
 | 
					      SystemCallFilter = [
 | 
				
			||||||
 | 
					        "@system-service"
 | 
				
			||||||
 | 
					      ];
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
}
 | 
					}
 | 
				
			||||||
@@ -33,10 +33,6 @@
 | 
				
			|||||||
 | 
					
 | 
				
			||||||
  systemd.services.nginx.serviceConfig = lib.mkIf config.services.nginx.enable {
 | 
					  systemd.services.nginx.serviceConfig = lib.mkIf config.services.nginx.enable {
 | 
				
			||||||
    LimitNOFILE = 65536;
 | 
					    LimitNOFILE = 65536;
 | 
				
			||||||
    # We use jit my dudes
 | 
					 | 
				
			||||||
    MemoryDenyWriteExecute = lib.mkForce false;
 | 
					 | 
				
			||||||
    # What the fuck do we use that where the defaults are not enough???
 | 
					 | 
				
			||||||
    SystemCallFilter = lib.mkForce null;
 | 
					 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  services.nginx.virtualHosts."_" = lib.mkIf config.services.nginx.enable {
 | 
					  services.nginx.virtualHosts."_" = lib.mkIf config.services.nginx.enable {
 | 
				
			||||||
 
 | 
				
			|||||||
							
								
								
									
										104
									
								
								flake.lock
									
									
									
										generated
									
									
									
								
							
							
						
						
									
										104
									
								
								flake.lock
									
									
									
										generated
									
									
									
								
							@@ -7,11 +7,11 @@
 | 
				
			|||||||
        ]
 | 
					        ]
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "locked": {
 | 
					      "locked": {
 | 
				
			||||||
        "lastModified": 1740485968,
 | 
					        "lastModified": 1731746438,
 | 
				
			||||||
        "narHash": "sha256-WK+PZHbfDjLyveXAxpnrfagiFgZWaTJglewBWniTn2Y=",
 | 
					        "narHash": "sha256-f3SSp1axoOk0NAI7oFdRzbxG2XPBSIXC+/DaAXnvS1A=",
 | 
				
			||||||
        "owner": "nix-community",
 | 
					        "owner": "nix-community",
 | 
				
			||||||
        "repo": "disko",
 | 
					        "repo": "disko",
 | 
				
			||||||
        "rev": "19c1140419c4f1cdf88ad4c1cfb6605597628940",
 | 
					        "rev": "cb64993826fa7a477490be6ccb38ba1fa1e18fa8",
 | 
				
			||||||
        "type": "github"
 | 
					        "type": "github"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "original": {
 | 
					      "original": {
 | 
				
			||||||
@@ -20,26 +20,6 @@
 | 
				
			|||||||
        "type": "github"
 | 
					        "type": "github"
 | 
				
			||||||
      }
 | 
					      }
 | 
				
			||||||
    },
 | 
					    },
 | 
				
			||||||
    "gergle": {
 | 
					 | 
				
			||||||
      "inputs": {
 | 
					 | 
				
			||||||
        "nixpkgs": [
 | 
					 | 
				
			||||||
          "nixpkgs"
 | 
					 | 
				
			||||||
        ]
 | 
					 | 
				
			||||||
      },
 | 
					 | 
				
			||||||
      "locked": {
 | 
					 | 
				
			||||||
        "lastModified": 1736621371,
 | 
					 | 
				
			||||||
        "narHash": "sha256-45UIQSQA7R5iU4YWvilo7mQbhY1Liql9bHBvYa3qRI0=",
 | 
					 | 
				
			||||||
        "ref": "refs/heads/main",
 | 
					 | 
				
			||||||
        "rev": "3729796c1213fe76e568ac28f1df8de4e596950b",
 | 
					 | 
				
			||||||
        "revCount": 20,
 | 
					 | 
				
			||||||
        "type": "git",
 | 
					 | 
				
			||||||
        "url": "https://git.pvv.ntnu.no/Grzegorz/gergle.git"
 | 
					 | 
				
			||||||
      },
 | 
					 | 
				
			||||||
      "original": {
 | 
					 | 
				
			||||||
        "type": "git",
 | 
					 | 
				
			||||||
        "url": "https://git.pvv.ntnu.no/Grzegorz/gergle.git"
 | 
					 | 
				
			||||||
      }
 | 
					 | 
				
			||||||
    },
 | 
					 | 
				
			||||||
    "greg-ng": {
 | 
					    "greg-ng": {
 | 
				
			||||||
      "inputs": {
 | 
					      "inputs": {
 | 
				
			||||||
        "nixpkgs": [
 | 
					        "nixpkgs": [
 | 
				
			||||||
@@ -48,17 +28,17 @@
 | 
				
			|||||||
        "rust-overlay": "rust-overlay"
 | 
					        "rust-overlay": "rust-overlay"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "locked": {
 | 
					      "locked": {
 | 
				
			||||||
        "lastModified": 1736545379,
 | 
					        "lastModified": 1730249639,
 | 
				
			||||||
        "narHash": "sha256-PeTTmGumdOX3rd6OKI7QMCrZovCDkrckZbcHr+znxWA=",
 | 
					        "narHash": "sha256-G3URSlqCcb+GIvGyki+HHrDM5ZanX/dP9BtppD/SdfI=",
 | 
				
			||||||
        "ref": "refs/heads/main",
 | 
					        "ref": "refs/heads/main",
 | 
				
			||||||
        "rev": "74f5316121776db2769385927ec0d0c2cc2b23e4",
 | 
					        "rev": "80e0447bcb79adad4f459ada5610f3eae987b4e3",
 | 
				
			||||||
        "revCount": 42,
 | 
					        "revCount": 34,
 | 
				
			||||||
        "type": "git",
 | 
					        "type": "git",
 | 
				
			||||||
        "url": "https://git.pvv.ntnu.no/Grzegorz/greg-ng.git"
 | 
					        "url": "https://git.pvv.ntnu.no/Projects/greg-ng.git"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "original": {
 | 
					      "original": {
 | 
				
			||||||
        "type": "git",
 | 
					        "type": "git",
 | 
				
			||||||
        "url": "https://git.pvv.ntnu.no/Grzegorz/greg-ng.git"
 | 
					        "url": "https://git.pvv.ntnu.no/Projects/greg-ng.git"
 | 
				
			||||||
      }
 | 
					      }
 | 
				
			||||||
    },
 | 
					    },
 | 
				
			||||||
    "grzegorz-clients": {
 | 
					    "grzegorz-clients": {
 | 
				
			||||||
@@ -68,17 +48,17 @@
 | 
				
			|||||||
        ]
 | 
					        ]
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "locked": {
 | 
					      "locked": {
 | 
				
			||||||
        "lastModified": 1736178795,
 | 
					        "lastModified": 1726861934,
 | 
				
			||||||
        "narHash": "sha256-mPdi8cgvIDYcgG3FRG7A4BOIMu2Jef96TPMnV00uXlM=",
 | 
					        "narHash": "sha256-lOzPDwktd+pwszUTbpUdQg6iCzInS11fHLfkjmnvJrM=",
 | 
				
			||||||
        "ref": "refs/heads/master",
 | 
					        "ref": "refs/heads/master",
 | 
				
			||||||
        "rev": "fde738910de1fd8293535a6382c2f0c2749dd7c1",
 | 
					        "rev": "546d921ec46735dbf876e36f4af8df1064d09432",
 | 
				
			||||||
        "revCount": 79,
 | 
					        "revCount": 78,
 | 
				
			||||||
        "type": "git",
 | 
					        "type": "git",
 | 
				
			||||||
        "url": "https://git.pvv.ntnu.no/Grzegorz/grzegorz-clients.git"
 | 
					        "url": "https://git.pvv.ntnu.no/Projects/grzegorz-clients.git"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "original": {
 | 
					      "original": {
 | 
				
			||||||
        "type": "git",
 | 
					        "type": "git",
 | 
				
			||||||
        "url": "https://git.pvv.ntnu.no/Grzegorz/grzegorz-clients.git"
 | 
					        "url": "https://git.pvv.ntnu.no/Projects/grzegorz-clients.git"
 | 
				
			||||||
      }
 | 
					      }
 | 
				
			||||||
    },
 | 
					    },
 | 
				
			||||||
    "matrix-next": {
 | 
					    "matrix-next": {
 | 
				
			||||||
@@ -124,11 +104,11 @@
 | 
				
			|||||||
        ]
 | 
					        ]
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "locked": {
 | 
					      "locked": {
 | 
				
			||||||
        "lastModified": 1736531400,
 | 
					        "lastModified": 1714416973,
 | 
				
			||||||
        "narHash": "sha256-+X/HVI1AwoPcud28wI35XRrc1kDgkYdDUGABJBAkxDI=",
 | 
					        "narHash": "sha256-aZUcvXjdETUC6wVQpWDVjLUzwpDAEca8yR0ITDeK39o=",
 | 
				
			||||||
        "ref": "refs/heads/main",
 | 
					        "ref": "refs/heads/main",
 | 
				
			||||||
        "rev": "e4dafd06b3d7e9e6e07617766e9c3743134571b7",
 | 
					        "rev": "2b23c0ba8aae68d3cb6789f0f6e4891cef26cc6d",
 | 
				
			||||||
        "revCount": 7,
 | 
					        "revCount": 6,
 | 
				
			||||||
        "type": "git",
 | 
					        "type": "git",
 | 
				
			||||||
        "url": "https://git.pvv.ntnu.no/oysteikt/nix-gitea-themes.git"
 | 
					        "url": "https://git.pvv.ntnu.no/oysteikt/nix-gitea-themes.git"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
@@ -139,27 +119,43 @@
 | 
				
			|||||||
    },
 | 
					    },
 | 
				
			||||||
    "nixpkgs": {
 | 
					    "nixpkgs": {
 | 
				
			||||||
      "locked": {
 | 
					      "locked": {
 | 
				
			||||||
        "lastModified": 1740782485,
 | 
					        "lastModified": 1731663789,
 | 
				
			||||||
        "narHash": "sha256-GkDJDqHYlPKZFdyxzZHtljxNRsosKB1GCrblqlvLFgo=",
 | 
					        "narHash": "sha256-x07g4NcqGP6mQn6AISXJaks9sQYDjZmTMBlKIvajvyc=",
 | 
				
			||||||
        "owner": "NixOS",
 | 
					        "owner": "NixOS",
 | 
				
			||||||
        "repo": "nixpkgs",
 | 
					        "repo": "nixpkgs",
 | 
				
			||||||
        "rev": "dd5c2540983641bbaabdfc665931592d4c9989e8",
 | 
					        "rev": "035d434d48f4375ac5d3a620954cf5fda7dd7c36",
 | 
				
			||||||
        "type": "github"
 | 
					        "type": "github"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "original": {
 | 
					      "original": {
 | 
				
			||||||
        "owner": "NixOS",
 | 
					        "owner": "NixOS",
 | 
				
			||||||
        "ref": "nixos-24.11-small",
 | 
					        "ref": "nixos-24.05-small",
 | 
				
			||||||
 | 
					        "repo": "nixpkgs",
 | 
				
			||||||
 | 
					        "type": "github"
 | 
				
			||||||
 | 
					      }
 | 
				
			||||||
 | 
					    },
 | 
				
			||||||
 | 
					    "nixpkgs-stable": {
 | 
				
			||||||
 | 
					      "locked": {
 | 
				
			||||||
 | 
					        "lastModified": 1730602179,
 | 
				
			||||||
 | 
					        "narHash": "sha256-efgLzQAWSzJuCLiCaQUCDu4NudNlHdg2NzGLX5GYaEY=",
 | 
				
			||||||
 | 
					        "owner": "NixOS",
 | 
				
			||||||
 | 
					        "repo": "nixpkgs",
 | 
				
			||||||
 | 
					        "rev": "3c2f1c4ca372622cb2f9de8016c9a0b1cbd0f37c",
 | 
				
			||||||
 | 
					        "type": "github"
 | 
				
			||||||
 | 
					      },
 | 
				
			||||||
 | 
					      "original": {
 | 
				
			||||||
 | 
					        "owner": "NixOS",
 | 
				
			||||||
 | 
					        "ref": "release-24.05",
 | 
				
			||||||
        "repo": "nixpkgs",
 | 
					        "repo": "nixpkgs",
 | 
				
			||||||
        "type": "github"
 | 
					        "type": "github"
 | 
				
			||||||
      }
 | 
					      }
 | 
				
			||||||
    },
 | 
					    },
 | 
				
			||||||
    "nixpkgs-unstable": {
 | 
					    "nixpkgs-unstable": {
 | 
				
			||||||
      "locked": {
 | 
					      "locked": {
 | 
				
			||||||
        "lastModified": 1740848276,
 | 
					        "lastModified": 1731745710,
 | 
				
			||||||
        "narHash": "sha256-bYeI3FEs824X+MJYksKboNlmglehzplqzn+XvcojWMc=",
 | 
					        "narHash": "sha256-SVeiClbgqL071JpAspOu0gCkPSAL51kSIRwo4C/pghA=",
 | 
				
			||||||
        "owner": "NixOS",
 | 
					        "owner": "NixOS",
 | 
				
			||||||
        "repo": "nixpkgs",
 | 
					        "repo": "nixpkgs",
 | 
				
			||||||
        "rev": "e9b0ff70ddc61c42548501b0fafb86bb49cca858",
 | 
					        "rev": "dfaa4cb76c2d450d8f396bb6b9f43cede3ade129",
 | 
				
			||||||
        "type": "github"
 | 
					        "type": "github"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "original": {
 | 
					      "original": {
 | 
				
			||||||
@@ -196,11 +192,11 @@
 | 
				
			|||||||
        ]
 | 
					        ]
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "locked": {
 | 
					      "locked": {
 | 
				
			||||||
        "lastModified": 1737151758,
 | 
					        "lastModified": 1725212759,
 | 
				
			||||||
        "narHash": "sha256-yZBsefIarFUEhFRj+rCGMp9Zvag3MCafqV/JfGVRVwc=",
 | 
					        "narHash": "sha256-yZBsefIarFUEhFRj+rCGMp9Zvag3MCafqV/JfGVRVwc=",
 | 
				
			||||||
        "ref": "refs/heads/master",
 | 
					        "ref": "refs/heads/master",
 | 
				
			||||||
        "rev": "a4ebe6ded0c8c124561a41cb329ff30891914b5e",
 | 
					        "rev": "e7b66b4bc6a89bab74bac45b87e9434f5165355f",
 | 
				
			||||||
        "revCount": 475,
 | 
					        "revCount": 473,
 | 
				
			||||||
        "type": "git",
 | 
					        "type": "git",
 | 
				
			||||||
        "url": "https://git.pvv.ntnu.no/Projects/nettsiden.git"
 | 
					        "url": "https://git.pvv.ntnu.no/Projects/nettsiden.git"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
@@ -212,7 +208,6 @@
 | 
				
			|||||||
    "root": {
 | 
					    "root": {
 | 
				
			||||||
      "inputs": {
 | 
					      "inputs": {
 | 
				
			||||||
        "disko": "disko",
 | 
					        "disko": "disko",
 | 
				
			||||||
        "gergle": "gergle",
 | 
					 | 
				
			||||||
        "greg-ng": "greg-ng",
 | 
					        "greg-ng": "greg-ng",
 | 
				
			||||||
        "grzegorz-clients": "grzegorz-clients",
 | 
					        "grzegorz-clients": "grzegorz-clients",
 | 
				
			||||||
        "matrix-next": "matrix-next",
 | 
					        "matrix-next": "matrix-next",
 | 
				
			||||||
@@ -250,14 +245,15 @@
 | 
				
			|||||||
      "inputs": {
 | 
					      "inputs": {
 | 
				
			||||||
        "nixpkgs": [
 | 
					        "nixpkgs": [
 | 
				
			||||||
          "nixpkgs"
 | 
					          "nixpkgs"
 | 
				
			||||||
        ]
 | 
					        ],
 | 
				
			||||||
 | 
					        "nixpkgs-stable": "nixpkgs-stable"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "locked": {
 | 
					      "locked": {
 | 
				
			||||||
        "lastModified": 1739262228,
 | 
					        "lastModified": 1731748189,
 | 
				
			||||||
        "narHash": "sha256-7JAGezJ0Dn5qIyA2+T4Dt/xQgAbhCglh6lzCekTVMeU=",
 | 
					        "narHash": "sha256-Zd/Uukvpcu26M6YGhpbsgqm6LUSLz+Q8mDZ5LOEGdiE=",
 | 
				
			||||||
        "owner": "Mic92",
 | 
					        "owner": "Mic92",
 | 
				
			||||||
        "repo": "sops-nix",
 | 
					        "repo": "sops-nix",
 | 
				
			||||||
        "rev": "07af005bb7d60c7f118d9d9f5530485da5d1e975",
 | 
					        "rev": "d2bd7f433b28db6bc7ae03d5eca43564da0af054",
 | 
				
			||||||
        "type": "github"
 | 
					        "type": "github"
 | 
				
			||||||
      },
 | 
					      },
 | 
				
			||||||
      "original": {
 | 
					      "original": {
 | 
				
			||||||
 
 | 
				
			|||||||
							
								
								
									
										26
									
								
								flake.nix
									
									
									
									
									
								
							
							
						
						
									
										26
									
								
								flake.nix
									
									
									
									
									
								
							@@ -2,7 +2,7 @@
 | 
				
			|||||||
  description = "PVV System flake";
 | 
					  description = "PVV System flake";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  inputs = {
 | 
					  inputs = {
 | 
				
			||||||
    nixpkgs.url = "github:NixOS/nixpkgs/nixos-24.11-small"; # remember to also update the url in base/services/auto-upgrade.nix
 | 
					    nixpkgs.url = "github:NixOS/nixpkgs/nixos-24.05-small"; # remember to also update the url in base/services/auto-upgrade.nix
 | 
				
			||||||
    nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixos-unstable-small";
 | 
					    nixpkgs-unstable.url = "github:NixOS/nixpkgs/nixos-unstable-small";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    sops-nix.url = "github:Mic92/sops-nix";
 | 
					    sops-nix.url = "github:Mic92/sops-nix";
 | 
				
			||||||
@@ -23,11 +23,9 @@
 | 
				
			|||||||
    nix-gitea-themes.url = "git+https://git.pvv.ntnu.no/oysteikt/nix-gitea-themes.git";
 | 
					    nix-gitea-themes.url = "git+https://git.pvv.ntnu.no/oysteikt/nix-gitea-themes.git";
 | 
				
			||||||
    nix-gitea-themes.inputs.nixpkgs.follows = "nixpkgs";
 | 
					    nix-gitea-themes.inputs.nixpkgs.follows = "nixpkgs";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    greg-ng.url = "git+https://git.pvv.ntnu.no/Grzegorz/greg-ng.git";
 | 
					    greg-ng.url = "git+https://git.pvv.ntnu.no/Projects/greg-ng.git";
 | 
				
			||||||
    greg-ng.inputs.nixpkgs.follows = "nixpkgs";
 | 
					    greg-ng.inputs.nixpkgs.follows = "nixpkgs";
 | 
				
			||||||
    gergle.url = "git+https://git.pvv.ntnu.no/Grzegorz/gergle.git";
 | 
					    grzegorz-clients.url = "git+https://git.pvv.ntnu.no/Projects/grzegorz-clients.git";
 | 
				
			||||||
    gergle.inputs.nixpkgs.follows = "nixpkgs";
 | 
					 | 
				
			||||||
    grzegorz-clients.url = "git+https://git.pvv.ntnu.no/Grzegorz/grzegorz-clients.git";
 | 
					 | 
				
			||||||
    grzegorz-clients.inputs.nixpkgs.follows = "nixpkgs";
 | 
					    grzegorz-clients.inputs.nixpkgs.follows = "nixpkgs";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    minecraft-data.url = "git+https://git.pvv.ntnu.no/Drift/minecraft-data.git";
 | 
					    minecraft-data.url = "git+https://git.pvv.ntnu.no/Drift/minecraft-data.git";
 | 
				
			||||||
@@ -126,27 +124,35 @@
 | 
				
			|||||||
      brzeczyszczykiewicz = stableNixosConfig "brzeczyszczykiewicz" {
 | 
					      brzeczyszczykiewicz = stableNixosConfig "brzeczyszczykiewicz" {
 | 
				
			||||||
        modules = [
 | 
					        modules = [
 | 
				
			||||||
          inputs.grzegorz-clients.nixosModules.grzegorz-webui
 | 
					          inputs.grzegorz-clients.nixosModules.grzegorz-webui
 | 
				
			||||||
          inputs.gergle.nixosModules.default
 | 
					 | 
				
			||||||
          inputs.greg-ng.nixosModules.default
 | 
					          inputs.greg-ng.nixosModules.default
 | 
				
			||||||
        ];
 | 
					        ];
 | 
				
			||||||
        overlays = [
 | 
					        overlays = [
 | 
				
			||||||
          inputs.greg-ng.overlays.default
 | 
					          inputs.greg-ng.overlays.default
 | 
				
			||||||
          inputs.gergle.overlays.default
 | 
					 | 
				
			||||||
        ];
 | 
					        ];
 | 
				
			||||||
      };
 | 
					      };
 | 
				
			||||||
      georg = stableNixosConfig "georg" {
 | 
					      georg = stableNixosConfig "georg" {
 | 
				
			||||||
        modules = [
 | 
					        modules = [
 | 
				
			||||||
          inputs.grzegorz-clients.nixosModules.grzegorz-webui
 | 
					          inputs.grzegorz-clients.nixosModules.grzegorz-webui
 | 
				
			||||||
          inputs.gergle.nixosModules.default
 | 
					 | 
				
			||||||
          inputs.greg-ng.nixosModules.default
 | 
					          inputs.greg-ng.nixosModules.default
 | 
				
			||||||
        ];
 | 
					        ];
 | 
				
			||||||
        overlays = [
 | 
					        overlays = [
 | 
				
			||||||
          inputs.greg-ng.overlays.default
 | 
					          inputs.greg-ng.overlays.default
 | 
				
			||||||
          inputs.gergle.overlays.default
 | 
					 | 
				
			||||||
        ];
 | 
					        ];
 | 
				
			||||||
      };
 | 
					      };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
      dagali = unstableNixosConfig "dagali" { };
 | 
					      grevling = stableNixosConfig "grevling" {
 | 
				
			||||||
 | 
					        modules = [
 | 
				
			||||||
 | 
					          ./hosts/grevling/configuration.nix
 | 
				
			||||||
 | 
					          sops-nix.nixosModules.sops
 | 
				
			||||||
 | 
					        ];
 | 
				
			||||||
 | 
					      };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      tuba = stableNixosConfig "grevling" {
 | 
				
			||||||
 | 
					        modules = [
 | 
				
			||||||
 | 
					          ./hosts/tuba/configuration.nix
 | 
				
			||||||
 | 
					          sops-nix.nixosModules.sops
 | 
				
			||||||
 | 
					        ];
 | 
				
			||||||
 | 
					      };
 | 
				
			||||||
    };
 | 
					    };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    nixosModules = {
 | 
					    nixosModules = {
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -6,15 +6,13 @@ in {
 | 
				
			|||||||
    ./module.nix # From danio, pending upstreaming
 | 
					    ./module.nix # From danio, pending upstreaming
 | 
				
			||||||
  ];
 | 
					  ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  disabledModules = [ "services/web-apps/bluemap.nix" ];
 | 
					  disabledModules = [ "services/web-servers/bluemap.nix" ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  sops.secrets."bluemap/ssh-key" = { };
 | 
					  sops.secrets."bluemap/ssh-key" = { };
 | 
				
			||||||
  sops.secrets."bluemap/ssh-known-hosts" = { };
 | 
					  sops.secrets."bluemap/ssh-known-hosts" = { };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  services.bluemap = {
 | 
					  services.bluemap = {
 | 
				
			||||||
    enable = true;
 | 
					    enable = true;
 | 
				
			||||||
    package = pkgs.callPackage ./package.nix { };
 | 
					 | 
				
			||||||
    
 | 
					 | 
				
			||||||
    eula = true;
 | 
					    eula = true;
 | 
				
			||||||
    onCalendar = "*-*-* 05:45:00"; # a little over an hour after auto-upgrade
 | 
					    onCalendar = "*-*-* 05:45:00"; # a little over an hour after auto-upgrade
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -26,6 +26,7 @@ let
 | 
				
			|||||||
    "webapp.conf" = webappConfig;
 | 
					    "webapp.conf" = webappConfig;
 | 
				
			||||||
    "webserver.conf" = webserverConfig;
 | 
					    "webserver.conf" = webserverConfig;
 | 
				
			||||||
    "packs" = cfg.resourcepacks;
 | 
					    "packs" = cfg.resourcepacks;
 | 
				
			||||||
 | 
					    "addons" = cfg.resourcepacks; # TODO
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  renderConfigFolder = name: value: pkgs.linkFarm "bluemap-${name}-config" {
 | 
					  renderConfigFolder = name: value: pkgs.linkFarm "bluemap-${name}-config" {
 | 
				
			||||||
@@ -37,13 +38,13 @@ let
 | 
				
			|||||||
    "webapp.conf" = format.generate "webapp.conf" (cfg.webappSettings // { "update-settings-file" = false; });
 | 
					    "webapp.conf" = format.generate "webapp.conf" (cfg.webappSettings // { "update-settings-file" = false; });
 | 
				
			||||||
    "webserver.conf" = webserverConfig;
 | 
					    "webserver.conf" = webserverConfig;
 | 
				
			||||||
    "packs" = value.resourcepacks;
 | 
					    "packs" = value.resourcepacks;
 | 
				
			||||||
 | 
					    "addons" = cfg.resourcepacks; # TODO
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  inherit (lib) mkOption;
 | 
					  inherit (lib) mkOption;
 | 
				
			||||||
in {
 | 
					in {
 | 
				
			||||||
  options.services.bluemap = {
 | 
					  options.services.bluemap = {
 | 
				
			||||||
    enable = lib.mkEnableOption "bluemap";
 | 
					    enable = lib.mkEnableOption "bluemap";
 | 
				
			||||||
    package = lib.mkPackageOption pkgs "bluemap" { };
 | 
					 | 
				
			||||||
 | 
					
 | 
				
			||||||
    eula = mkOption {
 | 
					    eula = mkOption {
 | 
				
			||||||
      type = lib.types.bool;
 | 
					      type = lib.types.bool;
 | 
				
			||||||
@@ -158,7 +159,7 @@ in {
 | 
				
			|||||||
            type = lib.types.path;
 | 
					            type = lib.types.path;
 | 
				
			||||||
            default = cfg.resourcepacks;
 | 
					            default = cfg.resourcepacks;
 | 
				
			||||||
            defaultText = lib.literalExpression "config.services.bluemap.resourcepacks";
 | 
					            defaultText = lib.literalExpression "config.services.bluemap.resourcepacks";
 | 
				
			||||||
            description = "A set of resourcepacks/mods/bluemap-addons to extract models from loaded in alphabetical order";
 | 
					            description = "A set of resourcepacks/mods to extract models from loaded in alphabetical order";
 | 
				
			||||||
          };
 | 
					          };
 | 
				
			||||||
          settings = mkOption {
 | 
					          settings = mkOption {
 | 
				
			||||||
            type = (lib.types.submodule {
 | 
					            type = (lib.types.submodule {
 | 
				
			||||||
@@ -309,18 +310,9 @@ in {
 | 
				
			|||||||
        Group = "nginx";
 | 
					        Group = "nginx";
 | 
				
			||||||
        UMask = "026";
 | 
					        UMask = "026";
 | 
				
			||||||
      };
 | 
					      };
 | 
				
			||||||
      script = ''
 | 
					      script = lib.strings.concatStringsSep "\n" ((lib.attrsets.mapAttrsToList
 | 
				
			||||||
        # If web folder doesnt exist generate it
 | 
					        (name: value: "${lib.getExe pkgs.bluemap} -c ${renderConfigFolder name value} -r")
 | 
				
			||||||
        test -f "${cfg.webRoot}" || ${lib.getExe cfg.package} -c ${webappConfigFolder} -gs
 | 
					        cfg.maps) ++ [ "${lib.getExe pkgs.bluemap} -c ${webappConfigFolder} -gs" ]);
 | 
				
			||||||
 | 
					 | 
				
			||||||
        # Render each minecraft map
 | 
					 | 
				
			||||||
        ${lib.strings.concatStringsSep "\n" (lib.attrsets.mapAttrsToList
 | 
					 | 
				
			||||||
          (name: value: "${lib.getExe cfg.package} -c ${renderConfigFolder name value} -r")
 | 
					 | 
				
			||||||
          cfg.maps)}
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
        # Generate updated webapp
 | 
					 | 
				
			||||||
        ${lib.getExe cfg.package} -c ${webappConfigFolder} -gs
 | 
					 | 
				
			||||||
      '';
 | 
					 | 
				
			||||||
    };
 | 
					    };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    systemd.timers."render-bluemap-maps" = lib.mkIf cfg.enableRender {
 | 
					    systemd.timers."render-bluemap-maps" = lib.mkIf cfg.enableRender {
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -1,30 +0,0 @@
 | 
				
			|||||||
{ lib, stdenvNoCC, fetchurl, makeWrapper, jre }:
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
stdenvNoCC.mkDerivation rec {
 | 
					 | 
				
			||||||
  pname = "bluemap";
 | 
					 | 
				
			||||||
  version = "5.7";
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  src = fetchurl {
 | 
					 | 
				
			||||||
    url = "https://github.com/BlueMap-Minecraft/BlueMap/releases/download/v${version}/BlueMap-${version}-cli.jar";
 | 
					 | 
				
			||||||
    hash = "sha256-8udZYJgrr4bi2mjRYrASd8JwUoUVZW1tZpOLRgafAIw=";
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  dontUnpack = true;
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  nativeBuildInputs = [ makeWrapper ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  installPhase = ''
 | 
					 | 
				
			||||||
    runHook preInstall
 | 
					 | 
				
			||||||
    makeWrapper ${jre}/bin/java $out/bin/bluemap --add-flags "-jar $src"
 | 
					 | 
				
			||||||
    runHook postInstall
 | 
					 | 
				
			||||||
  '';
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  meta = {
 | 
					 | 
				
			||||||
    description = "3D minecraft map renderer";
 | 
					 | 
				
			||||||
    homepage = "https://bluemap.bluecolored.de/";
 | 
					 | 
				
			||||||
    sourceProvenance = with lib.sourceTypes; [ binaryBytecode ];
 | 
					 | 
				
			||||||
    license = lib.licenses.mit;
 | 
					 | 
				
			||||||
    maintainers = with lib.maintainers; [ dandellion h7x4 ];
 | 
					 | 
				
			||||||
    mainProgram = "bluemap";
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
}
 | 
					 | 
				
			||||||
@@ -1,52 +0,0 @@
 | 
				
			|||||||
{ config, pkgs, lib, fp, ... }:
 | 
					 | 
				
			||||||
let
 | 
					 | 
				
			||||||
  cfg = config.services.gitea;
 | 
					 | 
				
			||||||
in
 | 
					 | 
				
			||||||
{
 | 
					 | 
				
			||||||
  services.gitea-themes.monokai = pkgs.gitea-theme-monokai;
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  systemd.services.gitea-customization = lib.mkIf cfg.enable {
 | 
					 | 
				
			||||||
    description = "Install extra customization in gitea's CUSTOM_DIR";
 | 
					 | 
				
			||||||
    wantedBy = [ "gitea.service" ];
 | 
					 | 
				
			||||||
    requiredBy = [ "gitea.service" ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    serviceConfig =  {
 | 
					 | 
				
			||||||
      Type = "oneshot";
 | 
					 | 
				
			||||||
      User = cfg.user;
 | 
					 | 
				
			||||||
      Group = cfg.group;
 | 
					 | 
				
			||||||
    };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    script = let
 | 
					 | 
				
			||||||
      logo-svg = fp /assets/logo_blue_regular.svg;
 | 
					 | 
				
			||||||
      logo-png = fp /assets/logo_blue_regular.png;
 | 
					 | 
				
			||||||
      extraLinks = pkgs.writeText "gitea-extra-links.tmpl" ''
 | 
					 | 
				
			||||||
        <a class="item" href="https://www.pvv.ntnu.no/">PVV</a>
 | 
					 | 
				
			||||||
        <a class="item" href="https://wiki.pvv.ntnu.no/">Wiki</a>
 | 
					 | 
				
			||||||
        <a class="item" href="https://git.pvv.ntnu.no/Drift/-/projects/4">Tokyo Drift Issues</a>
 | 
					 | 
				
			||||||
      '';
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      project-labels = (pkgs.formats.yaml { }).generate "gitea-project-labels.yaml" {
 | 
					 | 
				
			||||||
        labels = lib.importJSON ./labels/projects.json;
 | 
					 | 
				
			||||||
      };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      customTemplates = pkgs.runCommandLocal "gitea-templates" {
 | 
					 | 
				
			||||||
        nativeBuildInputs = with pkgs; [
 | 
					 | 
				
			||||||
          coreutils
 | 
					 | 
				
			||||||
          gnused
 | 
					 | 
				
			||||||
        ];
 | 
					 | 
				
			||||||
      } ''
 | 
					 | 
				
			||||||
        # Bigger icons
 | 
					 | 
				
			||||||
        install -Dm444 "${cfg.package.src}/templates/repo/icon.tmpl" "$out/repo/icon.tmpl"
 | 
					 | 
				
			||||||
        sed -i -e 's/24/48/g' "$out/repo/icon.tmpl"
 | 
					 | 
				
			||||||
      '';
 | 
					 | 
				
			||||||
    in ''
 | 
					 | 
				
			||||||
      install -Dm444 ${logo-svg} ${cfg.customDir}/public/assets/img/logo.svg
 | 
					 | 
				
			||||||
      install -Dm444 ${logo-png} ${cfg.customDir}/public/assets/img/logo.png
 | 
					 | 
				
			||||||
      install -Dm444 ${./loading.apng} ${cfg.customDir}/public/assets/img/loading.png
 | 
					 | 
				
			||||||
      install -Dm444 ${extraLinks} ${cfg.customDir}/templates/custom/extra_links.tmpl
 | 
					 | 
				
			||||||
      install -Dm444 ${project-labels} ${cfg.customDir}/options/label/project-labels.yaml
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      "${lib.getExe pkgs.rsync}" -a "${customTemplates}/" ${cfg.customDir}/templates/
 | 
					 | 
				
			||||||
    '';
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
}
 | 
					 | 
				
			||||||
@@ -1,11 +1,10 @@
 | 
				
			|||||||
{ config, values, lib, ... }:
 | 
					{ config, values, fp, pkgs, lib, ... }:
 | 
				
			||||||
let
 | 
					let
 | 
				
			||||||
  cfg = config.services.gitea;
 | 
					  cfg = config.services.gitea;
 | 
				
			||||||
  domain = "git.pvv.ntnu.no";
 | 
					  domain = "git.pvv.ntnu.no";
 | 
				
			||||||
  sshPort  = 2222;
 | 
					  sshPort  = 2222;
 | 
				
			||||||
in {
 | 
					in {
 | 
				
			||||||
  imports = [
 | 
					  imports = [
 | 
				
			||||||
    ./customization.nix
 | 
					 | 
				
			||||||
    ./gpg.nix
 | 
					    ./gpg.nix
 | 
				
			||||||
    ./import-users
 | 
					    ./import-users
 | 
				
			||||||
    ./web-secret-provider
 | 
					    ./web-secret-provider
 | 
				
			||||||
@@ -131,11 +130,6 @@ in {
 | 
				
			|||||||
      };
 | 
					      };
 | 
				
			||||||
      "ui.meta".DESCRIPTION = "Bokstavelig talt programvareverkstedet";
 | 
					      "ui.meta".DESCRIPTION = "Bokstavelig talt programvareverkstedet";
 | 
				
			||||||
    };
 | 
					    };
 | 
				
			||||||
 | 
					 | 
				
			||||||
    dump = {
 | 
					 | 
				
			||||||
      enable = true;
 | 
					 | 
				
			||||||
      type = "tar.gz";
 | 
					 | 
				
			||||||
    };
 | 
					 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  environment.systemPackages = [ cfg.package ];
 | 
					  environment.systemPackages = [ cfg.package ];
 | 
				
			||||||
@@ -162,4 +156,35 @@ in {
 | 
				
			|||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  networking.firewall.allowedTCPPorts = [ sshPort ];
 | 
					  networking.firewall.allowedTCPPorts = [ sshPort ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Extra customization
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  services.gitea-themes.monokai = pkgs.gitea-theme-monokai;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  systemd.services.install-gitea-customization = {
 | 
				
			||||||
 | 
					    description = "Install extra customization in gitea's CUSTOM_DIR";
 | 
				
			||||||
 | 
					    wantedBy = [ "gitea.service" ];
 | 
				
			||||||
 | 
					    requiredBy = [ "gitea.service" ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					    serviceConfig =  {
 | 
				
			||||||
 | 
					      Type = "oneshot";
 | 
				
			||||||
 | 
					      User = cfg.user;
 | 
				
			||||||
 | 
					      Group = cfg.group;
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					    script = let
 | 
				
			||||||
 | 
					      logo-svg = fp /assets/logo_blue_regular.svg;
 | 
				
			||||||
 | 
					      logo-png = fp /assets/logo_blue_regular.png;
 | 
				
			||||||
 | 
					      extraLinks = pkgs.writeText "gitea-extra-links.tmpl" ''
 | 
				
			||||||
 | 
					        <a class="item" href="https://www.pvv.ntnu.no/">PVV</a>
 | 
				
			||||||
 | 
					        <a class="item" href="https://wiki.pvv.ntnu.no/">Wiki</a>
 | 
				
			||||||
 | 
					        <a class="item" href="https://git.pvv.ntnu.no/Drift/-/projects/4">Tokyo Drift Issues</a>
 | 
				
			||||||
 | 
					      '';
 | 
				
			||||||
 | 
					    in ''
 | 
				
			||||||
 | 
					      install -Dm444 ${logo-svg} ${cfg.customDir}/public/assets/img/logo.svg
 | 
				
			||||||
 | 
					      install -Dm444 ${logo-png} ${cfg.customDir}/public/assets/img/logo.png
 | 
				
			||||||
 | 
					      install -Dm444 ${./loading.apng} ${cfg.customDir}/public/assets/img/loading.png
 | 
				
			||||||
 | 
					      install -Dm444 ${extraLinks} ${cfg.customDir}/templates/custom/extra_links.tmpl
 | 
				
			||||||
 | 
					    '';
 | 
				
			||||||
 | 
					  };
 | 
				
			||||||
}
 | 
					}
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -177,7 +177,6 @@ def ensure_gitea_user_is_part_of_team(
 | 
				
			|||||||
# List of teams that all users should be part of by default
 | 
					# List of teams that all users should be part of by default
 | 
				
			||||||
COMMON_USER_TEAMS = [
 | 
					COMMON_USER_TEAMS = [
 | 
				
			||||||
    ("Projects", "Members"),
 | 
					    ("Projects", "Members"),
 | 
				
			||||||
    ("Grzegorz", "Members"),
 | 
					 | 
				
			||||||
    ("Kurs", "Members"),
 | 
					    ("Kurs", "Members"),
 | 
				
			||||||
]
 | 
					]
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -1,116 +0,0 @@
 | 
				
			|||||||
[
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "art",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#006b75",
 | 
					 | 
				
			||||||
    "description": "Requires some creativity"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "big",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#754bc4",
 | 
					 | 
				
			||||||
    "description": "This is gonna take a while"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "blocked",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#850021",
 | 
					 | 
				
			||||||
    "description": "This issue/PR depends on one or more other issues/PRs"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "bug",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#f05048",
 | 
					 | 
				
			||||||
    "description": "Something brokey"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "ci-cd",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#d1ff78",
 | 
					 | 
				
			||||||
    "description": "Continuous integrals and continuous derivation"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "crash report",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#ed1111",
 | 
					 | 
				
			||||||
    "description": "Report an oopsie"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "disputed",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#5319e7",
 | 
					 | 
				
			||||||
    "description": "Kranglefanter"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "documentation",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#fbca04",
 | 
					 | 
				
			||||||
    "description": "Documentation changes required"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "duplicate",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#cccccc",
 | 
					 | 
				
			||||||
    "description": "This issue or pull request already exists"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "feature request",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#0052cc",
 | 
					 | 
				
			||||||
    "description": ""
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "good first issue",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#009800",
 | 
					 | 
				
			||||||
    "description": "Get your hands dirty with a new project here"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "me gusta",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#30ff36",
 | 
					 | 
				
			||||||
    "description": "( ͡° ͜ʖ ͡°)"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "packaging",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#bf642b",
 | 
					 | 
				
			||||||
    "description": ""
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "question",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#cc317c",
 | 
					 | 
				
			||||||
    "description": ""
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "security",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#ed1111",
 | 
					 | 
				
			||||||
    "description": "Skommel"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "techdebt spring cleaning",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#8c6217",
 | 
					 | 
				
			||||||
    "description": "The code is smelly 👃"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "testing",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#52b373",
 | 
					 | 
				
			||||||
    "description": "Poke it and see if it explodes"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "ui/ux",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#f28852",
 | 
					 | 
				
			||||||
    "description": "User complaints about ergonomics and economics and whatever"
 | 
					 | 
				
			||||||
  },
 | 
					 | 
				
			||||||
  {
 | 
					 | 
				
			||||||
    "name": "wontfix",
 | 
					 | 
				
			||||||
    "exclusive": false,
 | 
					 | 
				
			||||||
    "color": "#ffffff",
 | 
					 | 
				
			||||||
    "description": "Nei, vil ikke"
 | 
					 | 
				
			||||||
  }
 | 
					 | 
				
			||||||
]
 | 
					 | 
				
			||||||
@@ -3,7 +3,6 @@ let
 | 
				
			|||||||
  organizations = [
 | 
					  organizations = [
 | 
				
			||||||
    "Drift"
 | 
					    "Drift"
 | 
				
			||||||
    "Projects"
 | 
					    "Projects"
 | 
				
			||||||
    "Grzegorz"
 | 
					 | 
				
			||||||
    "Kurs"
 | 
					    "Kurs"
 | 
				
			||||||
  ];
 | 
					  ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
@@ -28,7 +27,6 @@ in
 | 
				
			|||||||
  users.users."gitea-web" = {
 | 
					  users.users."gitea-web" = {
 | 
				
			||||||
    group = "gitea-web";
 | 
					    group = "gitea-web";
 | 
				
			||||||
    isSystemUser = true;
 | 
					    isSystemUser = true;
 | 
				
			||||||
    shell = pkgs.bash;
 | 
					 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  sops.secrets."gitea/web-secret-provider/token" = {
 | 
					  sops.secrets."gitea/web-secret-provider/token" = {
 | 
				
			||||||
@@ -60,7 +58,6 @@ in
 | 
				
			|||||||
          key-dir = "/var/lib/gitea-web/keys/%i";
 | 
					          key-dir = "/var/lib/gitea-web/keys/%i";
 | 
				
			||||||
          authorized-keys-path = "/var/lib/gitea-web/authorized_keys.d/%i";
 | 
					          authorized-keys-path = "/var/lib/gitea-web/authorized_keys.d/%i";
 | 
				
			||||||
          rrsync-script = pkgs.writeShellScript "rrsync-chown" ''
 | 
					          rrsync-script = pkgs.writeShellScript "rrsync-chown" ''
 | 
				
			||||||
            mkdir -p "$1"
 | 
					 | 
				
			||||||
            ${lib.getExe pkgs.rrsync} -wo "$1"
 | 
					            ${lib.getExe pkgs.rrsync} -wo "$1"
 | 
				
			||||||
            ${pkgs.coreutils}/bin/chown -R gitea-web:gitea-web "$1"
 | 
					            ${pkgs.coreutils}/bin/chown -R gitea-web:gitea-web "$1"
 | 
				
			||||||
          '';
 | 
					          '';
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -34,21 +34,7 @@ def get_org_repo_list(args: argparse.Namespace, token: str):
 | 
				
			|||||||
        f"{args.api_url}/orgs/{args.org}/repos",
 | 
					        f"{args.api_url}/orgs/{args.org}/repos",
 | 
				
			||||||
        headers = { 'Authorization': 'token ' + token },
 | 
					        headers = { 'Authorization': 'token ' + token },
 | 
				
			||||||
    )
 | 
					    )
 | 
				
			||||||
 | 
					    return [repo["name"] for repo in result.json()]
 | 
				
			||||||
    results = [repo["name"] for repo in result.json()]
 | 
					 | 
				
			||||||
    target = int(result.headers['X-Total-Count'])
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    i = 2
 | 
					 | 
				
			||||||
    while len(results) < target:
 | 
					 | 
				
			||||||
        result = requests.get(
 | 
					 | 
				
			||||||
            f"{args.api_url}/orgs/{args.org}/repos",
 | 
					 | 
				
			||||||
            params = { 'page': i },
 | 
					 | 
				
			||||||
            headers = { 'Authorization': 'token ' + token },
 | 
					 | 
				
			||||||
        )
 | 
					 | 
				
			||||||
        results += [repo["name"] for repo in result.json()]
 | 
					 | 
				
			||||||
        i += 1
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    return results
 | 
					 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					
 | 
				
			||||||
def generate_ssh_key(args: argparse.Namespace, repository: str):
 | 
					def generate_ssh_key(args: argparse.Namespace, repository: str):
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -83,6 +83,7 @@ in {
 | 
				
			|||||||
      ProtectKernelLogs = true;
 | 
					      ProtectKernelLogs = true;
 | 
				
			||||||
      ProtectKernelModules = true;
 | 
					      ProtectKernelModules = true;
 | 
				
			||||||
      ProtectKernelTunables = true;
 | 
					      ProtectKernelTunables = true;
 | 
				
			||||||
 | 
					      ProtectProc = "invisible";
 | 
				
			||||||
      RestrictAddressFamilies = [
 | 
					      RestrictAddressFamilies = [
 | 
				
			||||||
        "AF_INET"
 | 
					        "AF_INET"
 | 
				
			||||||
        "AF_INET6"
 | 
					        "AF_INET6"
 | 
				
			||||||
@@ -97,6 +98,7 @@ in {
 | 
				
			|||||||
        "@system-service"
 | 
					        "@system-service"
 | 
				
			||||||
        "~@privileged"
 | 
					        "~@privileged"
 | 
				
			||||||
      ];
 | 
					      ];
 | 
				
			||||||
 | 
					      UMask = "0007";
 | 
				
			||||||
    };
 | 
					    };
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
}
 | 
					}
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -21,7 +21,7 @@ in
 | 
				
			|||||||
      custom_from
 | 
					      custom_from
 | 
				
			||||||
    ]);
 | 
					    ]);
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    dicts = with pkgs.aspellDicts; [ en en-computers nb nn fr de it ];
 | 
					    dicts = with pkgs.aspellDicts; [ en en-science en-computers nb nn fr de it ];
 | 
				
			||||||
    maxAttachmentSize = 20;
 | 
					    maxAttachmentSize = 20;
 | 
				
			||||||
    hostName = "roundcubeplaceholder.example.com";
 | 
					    hostName = "roundcubeplaceholder.example.com";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -48,9 +48,6 @@
 | 
				
			|||||||
 | 
					
 | 
				
			||||||
  users.users.turnserver.extraGroups = [ "acme" ];
 | 
					  users.users.turnserver.extraGroups = [ "acme" ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  # It needs this to be allowed to access the files with the acme group
 | 
					 | 
				
			||||||
  systemd.services.coturn.serviceConfig.PrivateUsers = lib.mkForce false;
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  systemd.services."acme-${config.services.coturn.realm}".serviceConfig = {
 | 
					  systemd.services."acme-${config.services.coturn.realm}".serviceConfig = {
 | 
				
			||||||
    AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ];
 | 
					    AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ];
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
@@ -69,7 +66,7 @@
 | 
				
			|||||||
 | 
					
 | 
				
			||||||
    listening-ips = [
 | 
					    listening-ips = [
 | 
				
			||||||
      values.services.turn.ipv4
 | 
					      values.services.turn.ipv4
 | 
				
			||||||
      values.services.turn.ipv6
 | 
					      # values.services.turn.ipv6
 | 
				
			||||||
    ];
 | 
					    ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
    tls-listening-port = 443;
 | 
					    tls-listening-port = 443;
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -6,6 +6,10 @@ let
 | 
				
			|||||||
  webhookListenPort = 8435;
 | 
					  webhookListenPort = 8435;
 | 
				
			||||||
in
 | 
					in
 | 
				
			||||||
{
 | 
					{
 | 
				
			||||||
 | 
					  imports = [
 | 
				
			||||||
 | 
					    ./module.nix
 | 
				
			||||||
 | 
					  ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  sops.secrets."matrix/hookshot/as_token" = {
 | 
					  sops.secrets."matrix/hookshot/as_token" = {
 | 
				
			||||||
    sopsFile = fp /secrets/bicep/matrix.yaml;
 | 
					    sopsFile = fp /secrets/bicep/matrix.yaml;
 | 
				
			||||||
    key = "hookshot/as_token";
 | 
					    key = "hookshot/as_token";
 | 
				
			||||||
 
 | 
				
			|||||||
							
								
								
									
										127
									
								
								hosts/bicep/services/matrix/hookshot/module.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										127
									
								
								hosts/bicep/services/matrix/hookshot/module.nix
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,127 @@
 | 
				
			|||||||
 | 
					{
 | 
				
			||||||
 | 
					  config,
 | 
				
			||||||
 | 
					  pkgs,
 | 
				
			||||||
 | 
					  lib,
 | 
				
			||||||
 | 
					  ...
 | 
				
			||||||
 | 
					}:
 | 
				
			||||||
 | 
					let
 | 
				
			||||||
 | 
					  cfg = config.services.matrix-hookshot;
 | 
				
			||||||
 | 
					  settingsFormat = pkgs.formats.yaml { };
 | 
				
			||||||
 | 
					  configFile = settingsFormat.generate "matrix-hookshot-config.yml" cfg.settings;
 | 
				
			||||||
 | 
					in
 | 
				
			||||||
 | 
					{
 | 
				
			||||||
 | 
					  options = {
 | 
				
			||||||
 | 
					    services.matrix-hookshot = {
 | 
				
			||||||
 | 
					      enable = lib.mkEnableOption "matrix-hookshot, a bridge between Matrix and project management services";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      package = lib.mkPackageOption pkgs "matrix-hookshot" { };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      registrationFile = lib.mkOption {
 | 
				
			||||||
 | 
					        type = lib.types.path;
 | 
				
			||||||
 | 
					        description = ''
 | 
				
			||||||
 | 
					          Appservice registration file.
 | 
				
			||||||
 | 
					          As it contains secret tokens, you may not want to add this to the publicly readable Nix store.
 | 
				
			||||||
 | 
					        '';
 | 
				
			||||||
 | 
					        example = lib.literalExpression ''
 | 
				
			||||||
 | 
					          pkgs.writeText "matrix-hookshot-registration" \'\'
 | 
				
			||||||
 | 
					            id: matrix-hookshot
 | 
				
			||||||
 | 
					            as_token: aaaaaaaaaa
 | 
				
			||||||
 | 
					            hs_token: aaaaaaaaaa
 | 
				
			||||||
 | 
					            namespaces:
 | 
				
			||||||
 | 
					              rooms: []
 | 
				
			||||||
 | 
					              users:
 | 
				
			||||||
 | 
					                - regex: "@_webhooks_.*:foobar"
 | 
				
			||||||
 | 
					                  exclusive: true
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					            sender_localpart: hookshot
 | 
				
			||||||
 | 
					            url: "http://localhost:9993"
 | 
				
			||||||
 | 
					            rate_limited: false
 | 
				
			||||||
 | 
					            \'\'
 | 
				
			||||||
 | 
					        '';
 | 
				
			||||||
 | 
					      };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      settings = lib.mkOption {
 | 
				
			||||||
 | 
					        description = ''
 | 
				
			||||||
 | 
					          {file}`config.yml` configuration as a Nix attribute set.
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					          For details please see the [documentation](https://matrix-org.github.io/matrix-hookshot/latest/setup/sample-configuration.html).
 | 
				
			||||||
 | 
					        '';
 | 
				
			||||||
 | 
					        example = {
 | 
				
			||||||
 | 
					          bridge = {
 | 
				
			||||||
 | 
					            domain = "example.com";
 | 
				
			||||||
 | 
					            url = "http://localhost:8008";
 | 
				
			||||||
 | 
					            mediaUrl = "https://example.com";
 | 
				
			||||||
 | 
					            port = 9993;
 | 
				
			||||||
 | 
					            bindAddress = "127.0.0.1";
 | 
				
			||||||
 | 
					          };
 | 
				
			||||||
 | 
					          listeners = [
 | 
				
			||||||
 | 
					            {
 | 
				
			||||||
 | 
					              port = 9000;
 | 
				
			||||||
 | 
					              bindAddress = "0.0.0.0";
 | 
				
			||||||
 | 
					              resources = [ "webhooks" ];
 | 
				
			||||||
 | 
					            }
 | 
				
			||||||
 | 
					            {
 | 
				
			||||||
 | 
					              port = 9001;
 | 
				
			||||||
 | 
					              bindAddress = "localhost";
 | 
				
			||||||
 | 
					              resources = [
 | 
				
			||||||
 | 
					                "metrics"
 | 
				
			||||||
 | 
					                "provisioning"
 | 
				
			||||||
 | 
					              ];
 | 
				
			||||||
 | 
					            }
 | 
				
			||||||
 | 
					          ];
 | 
				
			||||||
 | 
					        };
 | 
				
			||||||
 | 
					        default = { };
 | 
				
			||||||
 | 
					        type = lib.types.submodule {
 | 
				
			||||||
 | 
					          freeformType = settingsFormat.type;
 | 
				
			||||||
 | 
					          options = {
 | 
				
			||||||
 | 
					            passFile = lib.mkOption {
 | 
				
			||||||
 | 
					              type = lib.types.path;
 | 
				
			||||||
 | 
					              default = "/var/lib/matrix-hookshot/passkey.pem";
 | 
				
			||||||
 | 
					              description = ''
 | 
				
			||||||
 | 
					                A passkey used to encrypt tokens stored inside the bridge.
 | 
				
			||||||
 | 
					                File will be generated if not found.
 | 
				
			||||||
 | 
					              '';
 | 
				
			||||||
 | 
					            };
 | 
				
			||||||
 | 
					          };
 | 
				
			||||||
 | 
					        };
 | 
				
			||||||
 | 
					      };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      serviceDependencies = lib.mkOption {
 | 
				
			||||||
 | 
					        type = with lib.types; listOf str;
 | 
				
			||||||
 | 
					        default = lib.optional config.services.matrix-synapse.enable config.services.matrix-synapse.serviceUnit;
 | 
				
			||||||
 | 
					        defaultText = lib.literalExpression ''
 | 
				
			||||||
 | 
					          lib.optional config.services.matrix-synapse.enable config.services.matrix-synapse.serviceUnit
 | 
				
			||||||
 | 
					        '';
 | 
				
			||||||
 | 
					        description = ''
 | 
				
			||||||
 | 
					          List of Systemd services to require and wait for when starting the application service,
 | 
				
			||||||
 | 
					          such as the Matrix homeserver if it's running on the same host.
 | 
				
			||||||
 | 
					        '';
 | 
				
			||||||
 | 
					      };
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  config = lib.mkIf cfg.enable {
 | 
				
			||||||
 | 
					    systemd.services.matrix-hookshot = {
 | 
				
			||||||
 | 
					      description = "a bridge between Matrix and multiple project management services";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      wantedBy = [ "multi-user.target" ];
 | 
				
			||||||
 | 
					      wants = [ "network-online.target" ] ++ cfg.serviceDependencies;
 | 
				
			||||||
 | 
					      after = [ "network-online.target" ] ++ cfg.serviceDependencies;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      preStart = ''
 | 
				
			||||||
 | 
					        if [ ! -f '${cfg.settings.passFile}' ]; then
 | 
				
			||||||
 | 
					          mkdir -p $(dirname '${cfg.settings.passFile}')
 | 
				
			||||||
 | 
					          ${pkgs.openssl}/bin/openssl genpkey -out '${cfg.settings.passFile}' -outform PEM -algorithm RSA -pkeyopt rsa_keygen_bits:4096
 | 
				
			||||||
 | 
					        fi
 | 
				
			||||||
 | 
					      '';
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      serviceConfig = {
 | 
				
			||||||
 | 
					        Type = "simple";
 | 
				
			||||||
 | 
					        Restart = "always";
 | 
				
			||||||
 | 
					        ExecStart = "${cfg.package}/bin/matrix-hookshot ${configFile} ${cfg.registrationFile}";
 | 
				
			||||||
 | 
					      };
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  meta.maintainers = with lib.maintainers; [ flandweber ];
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
@@ -1,78 +0,0 @@
 | 
				
			|||||||
# Tracking document for new PVV kerberos auth stack
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||

 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
<div align="center">
 | 
					 | 
				
			||||||
  Bensinstasjon på heimdal
 | 
					 | 
				
			||||||
</div>
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
### TODO:
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
- [ ] setup heimdal
 | 
					 | 
				
			||||||
  - [x] ensure running with systemd
 | 
					 | 
				
			||||||
  - [x] compile smbk5pwd (part of openldap)
 | 
					 | 
				
			||||||
  - [ ] set `modify -a -disallow-all-tix,requires-pre-auth default` declaratively
 | 
					 | 
				
			||||||
  - [ ] fully initialize PVV.NTNU.NO
 | 
					 | 
				
			||||||
    - [x] `kadmin -l init PVV.NTNU.NO`
 | 
					 | 
				
			||||||
    - [x] add oysteikt/admin@PVV.NTNU.NO principal
 | 
					 | 
				
			||||||
    - [x] add oysteikt@PVV.NTNU.NO principal
 | 
					 | 
				
			||||||
    - [x] add krbtgt/PVV.NTNU.NO@PVV.NTNU.NO principal?
 | 
					 | 
				
			||||||
      - why is this needed, and where is it documented?
 | 
					 | 
				
			||||||
      - `kadmin check` seems to work under sudo?
 | 
					 | 
				
			||||||
      - (it is included by default, just included as error message
 | 
					 | 
				
			||||||
         in a weird state)
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    - [x] Ensure client is working correctly
 | 
					 | 
				
			||||||
      - [x] Ensure kinit works on darbu
 | 
					 | 
				
			||||||
      - [x] Ensure kpasswd works on darbu
 | 
					 | 
				
			||||||
      - [x] Ensure kadmin get <user> (and other restricted commands) works on darbu
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    - [ ] Ensure kdc is working correctly
 | 
					 | 
				
			||||||
      - [x] Ensure kinit works on dagali
 | 
					 | 
				
			||||||
      - [x] Ensure kpasswd works on dagali
 | 
					 | 
				
			||||||
      - [ ] Ensure kadmin get <user> (and other restricte commands) works on dagali
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    - [x] Fix FQDN
 | 
					 | 
				
			||||||
      - https://github.com/NixOS/nixpkgs/issues/94011
 | 
					 | 
				
			||||||
      - https://github.com/NixOS/nixpkgs/issues/261269
 | 
					 | 
				
			||||||
      - Possibly fixed by disabling systemd-resolved
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
- [ ] setup cyrus sasl
 | 
					 | 
				
			||||||
  - [x] ensure running with systemd 
 | 
					 | 
				
			||||||
  - [x] verify GSSAPI support plugin is installed
 | 
					 | 
				
			||||||
    - `nix-shell -p cyrus_sasl --command pluginviewer`
 | 
					 | 
				
			||||||
  - [x] create "host/localhost@PVV.NTNU.NO" and export to keytab
 | 
					 | 
				
			||||||
  - [x] verify cyrus sasl is able to talk to heimdal
 | 
					 | 
				
			||||||
    - `sudo testsaslauthd -u oysteikt -p <password>`
 | 
					 | 
				
			||||||
  - [ ] provide ldap principal to cyrus sasl through keytab
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
- [ ] setup openldap
 | 
					 | 
				
			||||||
  - [x] ensure running with systemd
 | 
					 | 
				
			||||||
  - [ ] verify openldap is able to talk to cyrus sasl
 | 
					 | 
				
			||||||
  - [ ] create user for oysteikt in openldap
 | 
					 | 
				
			||||||
  - [ ] authenticate openldap login through sasl
 | 
					 | 
				
			||||||
    - does this require creating an ldap user?
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
- [ ] fix smbk5pwd integration
 | 
					 | 
				
			||||||
  - [x] add smbk5pwd schemas to openldap
 | 
					 | 
				
			||||||
  - [x] create openldap db for smbk5pwd with overlays
 | 
					 | 
				
			||||||
  - [ ] test to ensure that user sync is working
 | 
					 | 
				
			||||||
  - [ ] test as user source (replace passwd)
 | 
					 | 
				
			||||||
  - [ ] test as PAM auth source
 | 
					 | 
				
			||||||
  - [ ] test as auth source for 3rd party appliation
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
- [ ] Set up ldap administration panel
 | 
					 | 
				
			||||||
  - Doesn't seem like there are many good ones out there. Maybe phpLDAPAdmin?
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
- [ ] Set up kerberos SRV DNS entry
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
### Information and URLS
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
- OpenLDAP SASL: https://www.openldap.org/doc/admin24/sasl.html
 | 
					 | 
				
			||||||
- Use a keytab: https://kb.iu.edu/d/aumh
 | 
					 | 
				
			||||||
- 2 ways for openldap to auth: https://security.stackexchange.com/questions/65093/how-to-test-ldap-that-authenticates-with-kerberos
 | 
					 | 
				
			||||||
- Cyrus guide OpenLDAP + SASL + GSSAPI: https://www.cyrusimap.org/sasl/sasl/faqs/openldap-sasl-gssapi.html
 | 
					 | 
				
			||||||
- Configuring GSSAPI and Cyrus SASL: https://web.mit.edu/darwin/src/modules/passwordserver_sasl/cyrus_sasl/doc/gssapi.html
 | 
					 | 
				
			||||||
- PVV Kerberos docs: https://wiki.pvv.ntnu.no/wiki/Drift/Kerberos
 | 
					 | 
				
			||||||
- OpenLDAP smbk5pwd source: https://git.openldap.org/nivanova/openldap/-/tree/master/contrib/slapd-modules/smbk5pwd
 | 
					 | 
				
			||||||
- saslauthd(8): https://linux.die.net/man/8/saslauthd
 | 
					 | 
				
			||||||
@@ -1,51 +0,0 @@
 | 
				
			|||||||
 | 
					 | 
				
			||||||
{ config, pkgs, values, lib, ... }:
 | 
					 | 
				
			||||||
{
 | 
					 | 
				
			||||||
  imports = [
 | 
					 | 
				
			||||||
    ./hardware-configuration.nix
 | 
					 | 
				
			||||||
    ../../base.nix
 | 
					 | 
				
			||||||
    ../../misc/metrics-exporters.nix
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    ./services/heimdal.nix
 | 
					 | 
				
			||||||
    #./services/openldap.nix
 | 
					 | 
				
			||||||
    ./services/cyrus-sasl.nix
 | 
					 | 
				
			||||||
  ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  # buskerud does not support efi?
 | 
					 | 
				
			||||||
  # boot.loader.systemd-boot.enable = true;
 | 
					 | 
				
			||||||
  # boot.loader.efi.canTouchEfiVariables = true;
 | 
					 | 
				
			||||||
  boot.loader.grub.enable = true;
 | 
					 | 
				
			||||||
  boot.loader.grub.device = "/dev/sda";
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  # resolved messes up FQDN coming from nscd
 | 
					 | 
				
			||||||
  services.resolved.enable = false;
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  networking.hostName = "dagali";
 | 
					 | 
				
			||||||
  networking.domain = lib.mkForce "pvv.local";
 | 
					 | 
				
			||||||
  networking.hosts = {
 | 
					 | 
				
			||||||
    "129.241.210.185" = [ "dagali.pvv.local" ];
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
  #networking.search = [ "pvv.ntnu.no" "pvv.org" ];
 | 
					 | 
				
			||||||
  networking.nameservers = [ "129.241.0.200" "129.241.0.201" ];
 | 
					 | 
				
			||||||
  networking.tempAddresses = "disabled";
 | 
					 | 
				
			||||||
  networking.networkmanager.enable = true;
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  systemd.network.networks."ens18" = values.defaultNetworkConfig // {
 | 
					 | 
				
			||||||
    matchConfig.Name = "ens18";
 | 
					 | 
				
			||||||
    address = with values.hosts.dagali; [ (ipv4 + "/25") (ipv6 + "/64") ];
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  # List packages installed in system profile
 | 
					 | 
				
			||||||
  environment.systemPackages = with pkgs; [
 | 
					 | 
				
			||||||
    # TODO: consider adding to base.nix
 | 
					 | 
				
			||||||
    nix-output-monitor
 | 
					 | 
				
			||||||
  ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  # This value determines the NixOS release from which the default
 | 
					 | 
				
			||||||
  # settings for stateful data, like file locations and database versions
 | 
					 | 
				
			||||||
  # on your system were taken. It‘s perfectly fine and recommended to leave
 | 
					 | 
				
			||||||
  # this value at the release version of the first install of this system.
 | 
					 | 
				
			||||||
  # Before changing this value read the documentation for this option
 | 
					 | 
				
			||||||
  # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
 | 
					 | 
				
			||||||
  system.stateVersion = "24.05"; # Did you read the comment?
 | 
					 | 
				
			||||||
}
 | 
					 | 
				
			||||||
@@ -1,21 +0,0 @@
 | 
				
			|||||||
{ config, ... }:
 | 
					 | 
				
			||||||
let
 | 
					 | 
				
			||||||
  cfg = config.services.saslauthd;
 | 
					 | 
				
			||||||
in
 | 
					 | 
				
			||||||
{
 | 
					 | 
				
			||||||
  # TODO: This is seemingly required for openldap to authenticate
 | 
					 | 
				
			||||||
  #       against kerberos, but I have no idea how to configure it as
 | 
					 | 
				
			||||||
  #       such. Does it need a keytab? There's a binary "testsaslauthd"
 | 
					 | 
				
			||||||
  #       that follows with `pkgs.cyrus_sasl` that might be useful.
 | 
					 | 
				
			||||||
  services.saslauthd = {
 | 
					 | 
				
			||||||
    enable = true;
 | 
					 | 
				
			||||||
    mechanism = "kerberos5";
 | 
					 | 
				
			||||||
    config = ''
 | 
					 | 
				
			||||||
      mech_list: gs2-krb5 gssapi
 | 
					 | 
				
			||||||
      keytab: /etc/krb5.keytab
 | 
					 | 
				
			||||||
    '';
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  # TODO: maybe the upstream module should consider doing this?
 | 
					 | 
				
			||||||
  environment.systemPackages = [ cfg.package ];
 | 
					 | 
				
			||||||
}
 | 
					 | 
				
			||||||
@@ -1,100 +0,0 @@
 | 
				
			|||||||
{ config, pkgs, lib, ... }:
 | 
					 | 
				
			||||||
let
 | 
					 | 
				
			||||||
  realm = "PVV.LOCAL";
 | 
					 | 
				
			||||||
  cfg = config.security.krb5;
 | 
					 | 
				
			||||||
in
 | 
					 | 
				
			||||||
{
 | 
					 | 
				
			||||||
  security.krb5 = {
 | 
					 | 
				
			||||||
    enable = true;
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    # NOTE: This is required in order to build smbk5pwd, because of some nested includes.
 | 
					 | 
				
			||||||
    #       We should open an issue upstream (heimdal, not nixpkgs), but this patch
 | 
					 | 
				
			||||||
    #       will do for now.
 | 
					 | 
				
			||||||
    package = pkgs.heimdal.overrideAttrs (prev: {
 | 
					 | 
				
			||||||
      postInstall = prev.postInstall + ''
 | 
					 | 
				
			||||||
        cp include/heim_threads.h $dev/include
 | 
					 | 
				
			||||||
      '';
 | 
					 | 
				
			||||||
    });
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    settings = {
 | 
					 | 
				
			||||||
      realms.${realm} = {
 | 
					 | 
				
			||||||
        kdc = [ "dagali.${lib.toLower realm}" ];
 | 
					 | 
				
			||||||
        admin_server = "dagali.${lib.toLower realm}";
 | 
					 | 
				
			||||||
        kpasswd_server = "dagali.${lib.toLower realm}";
 | 
					 | 
				
			||||||
        default_domain = lib.toLower realm;
 | 
					 | 
				
			||||||
        primary_kdc = "dagali.${lib.toLower realm}";
 | 
					 | 
				
			||||||
      };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      kadmin.default_keys = lib.concatStringsSep " " [
 | 
					 | 
				
			||||||
        "aes256-cts-hmac-sha1-96:pw-salt"
 | 
					 | 
				
			||||||
        "aes128-cts-hmac-sha1-96:pw-salt"
 | 
					 | 
				
			||||||
      ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      libdefaults.default_etypes = lib.concatStringsSep " " [
 | 
					 | 
				
			||||||
        "aes256-cts-hmac-sha1-96"
 | 
					 | 
				
			||||||
        "aes128-cts-hmac-sha1-96"
 | 
					 | 
				
			||||||
      ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      libdefaults = {
 | 
					 | 
				
			||||||
        default_realm = realm;
 | 
					 | 
				
			||||||
        dns_lookup_kdc = false;
 | 
					 | 
				
			||||||
        dns_lookup_realm = false;
 | 
					 | 
				
			||||||
      };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      domain_realm = {
 | 
					 | 
				
			||||||
        "${lib.toLower realm}" = realm;
 | 
					 | 
				
			||||||
        ".${lib.toLower realm}" = realm;
 | 
					 | 
				
			||||||
      };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      logging = {
 | 
					 | 
				
			||||||
        # kdc = "CONSOLE";
 | 
					 | 
				
			||||||
        kdc = "SYSLOG:DEBUG:AUTH";
 | 
					 | 
				
			||||||
        admin_server = "SYSLOG:DEBUG:AUTH";
 | 
					 | 
				
			||||||
        default = "SYSLOG:DEBUG:AUTH";
 | 
					 | 
				
			||||||
      };
 | 
					 | 
				
			||||||
    };
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  services.kerberos_server = {
 | 
					 | 
				
			||||||
    enable = true;
 | 
					 | 
				
			||||||
    settings = {
 | 
					 | 
				
			||||||
      realms.${realm} = {
 | 
					 | 
				
			||||||
        dbname = "/var/lib/heimdal/heimdal";
 | 
					 | 
				
			||||||
        mkey = "/var/lib/heimdal/m-key";
 | 
					 | 
				
			||||||
        acl = [
 | 
					 | 
				
			||||||
          {
 | 
					 | 
				
			||||||
            principal = "kadmin/admin";
 | 
					 | 
				
			||||||
            access = "all";
 | 
					 | 
				
			||||||
          }
 | 
					 | 
				
			||||||
          {
 | 
					 | 
				
			||||||
            principal = "felixalb/admin";
 | 
					 | 
				
			||||||
            access = "all";
 | 
					 | 
				
			||||||
          }
 | 
					 | 
				
			||||||
          {
 | 
					 | 
				
			||||||
            principal = "oysteikt/admin";
 | 
					 | 
				
			||||||
            access = "all";
 | 
					 | 
				
			||||||
          }
 | 
					 | 
				
			||||||
        ];
 | 
					 | 
				
			||||||
      };
 | 
					 | 
				
			||||||
      # kadmin.default_keys = lib.concatStringsSep " " [
 | 
					 | 
				
			||||||
      #   "aes256-cts-hmac-sha1-96:pw-salt"
 | 
					 | 
				
			||||||
      #   "aes128-cts-hmac-sha1-96:pw-salt"
 | 
					 | 
				
			||||||
      # ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      # libdefaults.default_etypes = lib.concatStringsSep " " [
 | 
					 | 
				
			||||||
      #   "aes256-cts-hmac-sha1-96"
 | 
					 | 
				
			||||||
      #   "aes128-cts-hmac-sha1-96"
 | 
					 | 
				
			||||||
      # ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      # password_quality.min_length = 8;
 | 
					 | 
				
			||||||
    };
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  networking.firewall.allowedTCPPorts = [ 88 464 749 ];
 | 
					 | 
				
			||||||
  networking.firewall.allowedUDPPorts = [ 88 464 749 ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  networking.hosts = {
 | 
					 | 
				
			||||||
    "127.0.0.2" = lib.mkForce [ ];
 | 
					 | 
				
			||||||
    "::1" = lib.mkForce [ ];
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
}
 | 
					 | 
				
			||||||
@@ -1,121 +0,0 @@
 | 
				
			|||||||
{ config, pkgs, lib, ... }:
 | 
					 | 
				
			||||||
{
 | 
					 | 
				
			||||||
  services.openldap = let
 | 
					 | 
				
			||||||
    dn = "dc=pvv,dc=ntnu,dc=no";
 | 
					 | 
				
			||||||
    cfg = config.services.openldap;
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    heimdal = config.security.krb5.package;
 | 
					 | 
				
			||||||
  in {
 | 
					 | 
				
			||||||
    enable = true;
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    # NOTE: this is a custom build of openldap with support for
 | 
					 | 
				
			||||||
    #       perl and kerberos.
 | 
					 | 
				
			||||||
    package = pkgs.openldap.overrideAttrs (prev: {
 | 
					 | 
				
			||||||
      # https://github.com/openldap/openldap/blob/master/configure
 | 
					 | 
				
			||||||
      configureFlags = prev.configureFlags ++ [
 | 
					 | 
				
			||||||
        # Connect to slapd via UNIX socket
 | 
					 | 
				
			||||||
        "--enable-local"
 | 
					 | 
				
			||||||
        # Cyrus SASL
 | 
					 | 
				
			||||||
        "--enable-spasswd"
 | 
					 | 
				
			||||||
        # Reverse hostname lookups
 | 
					 | 
				
			||||||
        "--enable-rlookups"
 | 
					 | 
				
			||||||
        # perl
 | 
					 | 
				
			||||||
        "--enable-perl"
 | 
					 | 
				
			||||||
      ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      buildInputs = prev.buildInputs ++ [
 | 
					 | 
				
			||||||
        pkgs.perl
 | 
					 | 
				
			||||||
	# NOTE: do not upstream this, it might not work with
 | 
					 | 
				
			||||||
	#       MIT in the same way
 | 
					 | 
				
			||||||
        heimdal
 | 
					 | 
				
			||||||
      ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      extraContribModules = prev.extraContribModules ++ [
 | 
					 | 
				
			||||||
        # https://git.openldap.org/openldap/openldap/-/tree/master/contrib/slapd-modules
 | 
					 | 
				
			||||||
        "smbk5pwd"
 | 
					 | 
				
			||||||
      ];
 | 
					 | 
				
			||||||
    });
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    settings = {
 | 
					 | 
				
			||||||
      attrs = {
 | 
					 | 
				
			||||||
        olcLogLevel = [ "stats" "config" "args" ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
        # olcAuthzRegexp = ''
 | 
					 | 
				
			||||||
        #   gidNumber=.*\\\+uidNumber=0,cn=peercred,cn=external,cn=auth
 | 
					 | 
				
			||||||
        #         "uid=heimdal,${dn2}"
 | 
					 | 
				
			||||||
        # '';
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
        # olcSaslSecProps = "minssf=0";
 | 
					 | 
				
			||||||
      };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      children = {
 | 
					 | 
				
			||||||
        "cn=schema".includes = let
 | 
					 | 
				
			||||||
          # NOTE: needed for smbk5pwd.so module
 | 
					 | 
				
			||||||
          schemaToLdif = name: path: pkgs.runCommandNoCC name {
 | 
					 | 
				
			||||||
            buildInputs = with pkgs; [ schema2ldif ];
 | 
					 | 
				
			||||||
          } ''
 | 
					 | 
				
			||||||
            schema2ldif "${path}" > $out
 | 
					 | 
				
			||||||
          '';
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
          hdb-ldif = schemaToLdif "hdb.ldif" "${heimdal.src}/lib/hdb/hdb.schema";
 | 
					 | 
				
			||||||
          samba-ldif = schemaToLdif "samba.ldif" "${heimdal.src}/tests/ldap/samba.schema";
 | 
					 | 
				
			||||||
        in [
 | 
					 | 
				
			||||||
           "${cfg.package}/etc/schema/core.ldif"
 | 
					 | 
				
			||||||
           "${cfg.package}/etc/schema/cosine.ldif"
 | 
					 | 
				
			||||||
           "${cfg.package}/etc/schema/nis.ldif"
 | 
					 | 
				
			||||||
           "${cfg.package}/etc/schema/inetorgperson.ldif"
 | 
					 | 
				
			||||||
           "${hdb-ldif}"
 | 
					 | 
				
			||||||
           "${samba-ldif}"
 | 
					 | 
				
			||||||
        ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
        # NOTE: installation of smbk5pwd.so module
 | 
					 | 
				
			||||||
        #       https://git.openldap.org/openldap/openldap/-/tree/master/contrib/slapd-modules/smbk5pwd
 | 
					 | 
				
			||||||
        "cn=module{0}".attrs = {
 | 
					 | 
				
			||||||
          objectClass = [ "olcModuleList" ];
 | 
					 | 
				
			||||||
          olcModuleLoad = [ "${cfg.package}/lib/modules/smbk5pwd.so" ];
 | 
					 | 
				
			||||||
        };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
        # NOTE: activation of smbk5pwd.so module for {1}mdb
 | 
					 | 
				
			||||||
        "olcOverlay={0}smbk5pwd,olcDatabase={1}mdb".attrs = {
 | 
					 | 
				
			||||||
          objectClass = [ "olcOverlayConfig" "olcSmbK5PwdConfig" ];
 | 
					 | 
				
			||||||
          olcOverlay = "{0}smbk5pwd";
 | 
					 | 
				
			||||||
          olcSmbK5PwdEnable = [ "krb5" "samba" ];
 | 
					 | 
				
			||||||
          olcSmbK5PwdMustChange = toString (60 * 60 * 24 * 10000);
 | 
					 | 
				
			||||||
        };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
        "olcDatabase={1}mdb".attrs = {
 | 
					 | 
				
			||||||
          objectClass = [ "olcDatabaseConfig" "olcMdbConfig" ];
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
          olcDatabase = "{1}mdb";
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
          olcSuffix = dn;
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
          # TODO: PW is supposed to be a secret, but it's probably fine for testing
 | 
					 | 
				
			||||||
          olcRootDN = "cn=users,${dn}";
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
          # TODO: replace with proper secret
 | 
					 | 
				
			||||||
          olcRootPW.path = pkgs.writeText "olcRootPW" "pass";
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
          olcDbDirectory = "/var/lib/openldap/test-smbk5pwd-db";
 | 
					 | 
				
			||||||
          olcDbIndex = "objectClass eq";
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
          olcAccess = [
 | 
					 | 
				
			||||||
            ''{0}to attrs=userPassword,shadowLastChange
 | 
					 | 
				
			||||||
                by dn.exact=cn=users,${dn} write
 | 
					 | 
				
			||||||
                by self write
 | 
					 | 
				
			||||||
                by anonymous auth
 | 
					 | 
				
			||||||
                by * none''
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
            ''{1}to dn.base=""
 | 
					 | 
				
			||||||
                by * read''
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
            /* allow read on anything else */
 | 
					 | 
				
			||||||
            # ''{2}to *
 | 
					 | 
				
			||||||
            #     by cn=users,${dn} write by dn.exact=gidNumber=0+uidNumber=0+cn=peercred,cn=external write
 | 
					 | 
				
			||||||
            #     by * read''
 | 
					 | 
				
			||||||
          ];
 | 
					 | 
				
			||||||
        };
 | 
					 | 
				
			||||||
      };
 | 
					 | 
				
			||||||
    };
 | 
					 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
}
 | 
					 | 
				
			||||||
							
								
								
									
										36
									
								
								hosts/grevling/configuration.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										36
									
								
								hosts/grevling/configuration.nix
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,36 @@
 | 
				
			|||||||
 | 
					{ config, pkgs, values, ... }:
 | 
				
			||||||
 | 
					{
 | 
				
			||||||
 | 
					  imports = [
 | 
				
			||||||
 | 
					      # Include the results of the hardware scan.
 | 
				
			||||||
 | 
					      ./hardware-configuration.nix
 | 
				
			||||||
 | 
					      ../../base.nix
 | 
				
			||||||
 | 
					      ../../misc/metrics-exporters.nix
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      ./services/openvpn
 | 
				
			||||||
 | 
					    ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  boot.loader.systemd-boot.enable = true;
 | 
				
			||||||
 | 
					  boot.loader.efi.canTouchEfiVariables = true;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  networking.hostName = "grevling";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # systemd.network.networks."30-eno1" = values.defaultNetworkConfig // {
 | 
				
			||||||
 | 
					  #   matchConfig.Name = "eno1";
 | 
				
			||||||
 | 
					  #   address = with values.hosts.georg; [ (ipv4 + "/25") (ipv6 + "/64") ];
 | 
				
			||||||
 | 
					  # };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # List packages installed in system profile
 | 
				
			||||||
 | 
					  environment.systemPackages = with pkgs; [
 | 
				
			||||||
 | 
					  ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # List services that you want to enable:
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # This value determines the NixOS release from which the default
 | 
				
			||||||
 | 
					  # settings for stateful data, like file locations and database versions
 | 
				
			||||||
 | 
					  # on your system were taken. It‘s perfectly fine and recommended to leave
 | 
				
			||||||
 | 
					  # this value at the release version of the first install of this system.
 | 
				
			||||||
 | 
					  # Before changing this value read the documentation for this option
 | 
				
			||||||
 | 
					  # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
 | 
				
			||||||
 | 
					  system.stateVersion = "23.05"; # Did you read the comment?
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
@@ -5,21 +5,26 @@
 | 
				
			|||||||
 | 
					
 | 
				
			||||||
{
 | 
					{
 | 
				
			||||||
  imports =
 | 
					  imports =
 | 
				
			||||||
    [ (modulesPath + "/profiles/qemu-guest.nix")
 | 
					    [ (modulesPath + "/installer/scan/not-detected.nix")
 | 
				
			||||||
    ];
 | 
					    ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ];
 | 
					  boot.initrd.availableKernelModules = [ "xhci_pci" "ehci_pci" "ahci" "usb_storage" "usbhid" "sd_mod" ];
 | 
				
			||||||
  boot.initrd.kernelModules = [ ];
 | 
					  boot.initrd.kernelModules = [ ];
 | 
				
			||||||
  boot.kernelModules = [ ];
 | 
					  boot.kernelModules = [ "kvm-intel" ];
 | 
				
			||||||
  boot.extraModulePackages = [ ];
 | 
					  boot.extraModulePackages = [ ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  fileSystems."/" =
 | 
					  fileSystems."/" =
 | 
				
			||||||
    { device = "/dev/disk/by-uuid/4de345e2-be41-4d10-9b90-823b2c77e9b3";
 | 
					    { device = "/dev/disk/by-uuid/33825f0d-5a63-40fc-83db-bfa1ebb72ba0";
 | 
				
			||||||
      fsType = "ext4";
 | 
					      fsType = "ext4";
 | 
				
			||||||
    };
 | 
					    };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  fileSystems."/boot" =
 | 
				
			||||||
 | 
					    { device = "/dev/disk/by-uuid/145E-7362";
 | 
				
			||||||
 | 
					      fsType = "vfat";
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  swapDevices =
 | 
					  swapDevices =
 | 
				
			||||||
    [ { device = "/dev/disk/by-uuid/aa4b9a97-a7d8-4608-9f67-4ad084f1baf7"; }
 | 
					    [ { device = "/dev/disk/by-uuid/7ed27e21-3247-44cd-8bcc-5d4a2efebf57"; }
 | 
				
			||||||
    ];
 | 
					    ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  # Enables DHCP on each ethernet and wireless interface. In case of scripted networking
 | 
					  # Enables DHCP on each ethernet and wireless interface. In case of scripted networking
 | 
				
			||||||
@@ -27,7 +32,9 @@
 | 
				
			|||||||
  # still possible to use this option, but it's recommended to use it in conjunction
 | 
					  # still possible to use this option, but it's recommended to use it in conjunction
 | 
				
			||||||
  # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
 | 
					  # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
 | 
				
			||||||
  networking.useDHCP = lib.mkDefault true;
 | 
					  networking.useDHCP = lib.mkDefault true;
 | 
				
			||||||
  # networking.interfaces.ens18.useDHCP = lib.mkDefault true;
 | 
					  # networking.interfaces.eno1.useDHCP = lib.mkDefault true;
 | 
				
			||||||
 | 
					  # networking.interfaces.enp2s2.useDHCP = lib.mkDefault true;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
 | 
					  nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
 | 
				
			||||||
 | 
					  hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
 | 
				
			||||||
}
 | 
					}
 | 
				
			||||||
							
								
								
									
										77
									
								
								hosts/grevling/services/openvpn/default.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										77
									
								
								hosts/grevling/services/openvpn/default.nix
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,77 @@
 | 
				
			|||||||
 | 
					{ pkgs, lib, values, ... }:
 | 
				
			||||||
 | 
					{
 | 
				
			||||||
 | 
					  services.openvpn.servers."ov-tunnel" = {
 | 
				
			||||||
 | 
					    config = let
 | 
				
			||||||
 | 
					      conf = {
 | 
				
			||||||
 | 
					        # TODO: use aliases
 | 
				
			||||||
 | 
					        local = "129.241.210.191";
 | 
				
			||||||
 | 
					        port = 1194;
 | 
				
			||||||
 | 
					        proto = "udp";
 | 
				
			||||||
 | 
					        dev = "tap";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        # TODO: set up
 | 
				
			||||||
 | 
					        ca = "";
 | 
				
			||||||
 | 
					        cert = "";
 | 
				
			||||||
 | 
					        key = "";
 | 
				
			||||||
 | 
					        dh = "";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        # Maintain a record of client <-> virtual IP address
 | 
				
			||||||
 | 
					        # associations in this file.  If OpenVPN goes down or
 | 
				
			||||||
 | 
					        # is restarted, reconnecting clients can be assigned
 | 
				
			||||||
 | 
					        # the same virtual IP address from the pool that was
 | 
				
			||||||
 | 
					        # previously assigned.
 | 
				
			||||||
 | 
					        ifconfig-pool-persist = ./ipp.txt;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        server-bridge = builtins.concatStringsSep " " [
 | 
				
			||||||
 | 
					          "129.241.210.129"
 | 
				
			||||||
 | 
					          "255.255.255.128"
 | 
				
			||||||
 | 
					          "129.241.210.253"
 | 
				
			||||||
 | 
					          "129.241.210.254"
 | 
				
			||||||
 | 
					        ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        keepalive = "10 120";
 | 
				
			||||||
 | 
					        cipher = "none";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        user = "nobody";
 | 
				
			||||||
 | 
					        group = "nobody";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        status = "/var/log/openvpn-status.log";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        client-config-dir = pkgs.writeTextDir "tuba" ''
 | 
				
			||||||
 | 
					          # Sett IP-adr. for tap0 til tubas PVV-adr.
 | 
				
			||||||
 | 
					          ifconfig-push ${values.services.tuba-tap} 255.255.255.128
 | 
				
			||||||
 | 
					          # Hvordan skal man faa dette til aa funke, tro?
 | 
				
			||||||
 | 
					          #ifconfig-ipv6-push 2001:700:300:1900::xxx/64
 | 
				
			||||||
 | 
					          
 | 
				
			||||||
 | 
					          # La tuba bruke std. PVV-gateway til all trafikk (unntatt
 | 
				
			||||||
 | 
					          # VPN-tunnellen).
 | 
				
			||||||
 | 
					          push "redirect-gateway"
 | 
				
			||||||
 | 
					        '';
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        persist-key = true;
 | 
				
			||||||
 | 
					        persist-tun = true;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        verb = 5;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        explicit-exit-notify = 1;
 | 
				
			||||||
 | 
					      };
 | 
				
			||||||
 | 
					    in lib.pipe conf [
 | 
				
			||||||
 | 
					      (lib.filterAttrs (_: value: !(builtins.isNull value || value == false)))
 | 
				
			||||||
 | 
					      (builtins.mapAttrs (_: value:
 | 
				
			||||||
 | 
					        if builtins.isList value then builtins.concatStringsSep " " (map toString value)
 | 
				
			||||||
 | 
					        else if value == true then value
 | 
				
			||||||
 | 
					        else if builtins.any (f: f value) [
 | 
				
			||||||
 | 
					          builtins.isString
 | 
				
			||||||
 | 
					          builtins.isInt
 | 
				
			||||||
 | 
					          builtins.isFloat
 | 
				
			||||||
 | 
					          lib.isPath
 | 
				
			||||||
 | 
					          lib.isDerivation
 | 
				
			||||||
 | 
					        ] then toString value
 | 
				
			||||||
 | 
					        else throw "Unknown value in grevling openvpn config, deading now\n${value}"
 | 
				
			||||||
 | 
					      ))
 | 
				
			||||||
 | 
					      (lib.mapAttrsToList (name: value: if value == true then name else "${name} ${value}"))
 | 
				
			||||||
 | 
					      (builtins.concatStringsSep "\n")
 | 
				
			||||||
 | 
					      (x: x + "\n\n")
 | 
				
			||||||
 | 
					    ];
 | 
				
			||||||
 | 
					  };
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
							
								
								
									
										0
									
								
								hosts/grevling/services/openvpn/ipp.txt
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										0
									
								
								hosts/grevling/services/openvpn/ipp.txt
									
									
									
									
									
										Normal file
									
								
							
							
								
								
									
										36
									
								
								hosts/tuba/configuration.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										36
									
								
								hosts/tuba/configuration.nix
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,36 @@
 | 
				
			|||||||
 | 
					{ config, pkgs, values, ... }:
 | 
				
			||||||
 | 
					{
 | 
				
			||||||
 | 
					  imports = [
 | 
				
			||||||
 | 
					      # Include the results of the hardware scan.
 | 
				
			||||||
 | 
					      ./hardware-configuration.nix
 | 
				
			||||||
 | 
					      ../../base.nix
 | 
				
			||||||
 | 
					      ../../misc/metrics-exporters.nix
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					      ./services/openvpn
 | 
				
			||||||
 | 
					    ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  boot.loader.systemd-boot.enable = true;
 | 
				
			||||||
 | 
					  boot.loader.efi.canTouchEfiVariables = true;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  networking.hostName = "tuba";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # systemd.network.networks."30-eno1" = values.defaultNetworkConfig // {
 | 
				
			||||||
 | 
					  #   matchConfig.Name = "eno1";
 | 
				
			||||||
 | 
					  #   address = with values.hosts.georg; [ (ipv4 + "/25") (ipv6 + "/64") ];
 | 
				
			||||||
 | 
					  # };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # List packages installed in system profile
 | 
				
			||||||
 | 
					  environment.systemPackages = with pkgs; [
 | 
				
			||||||
 | 
					  ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # List services that you want to enable:
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # This value determines the NixOS release from which the default
 | 
				
			||||||
 | 
					  # settings for stateful data, like file locations and database versions
 | 
				
			||||||
 | 
					  # on your system were taken. It‘s perfectly fine and recommended to leave
 | 
				
			||||||
 | 
					  # this value at the release version of the first install of this system.
 | 
				
			||||||
 | 
					  # Before changing this value read the documentation for this option
 | 
				
			||||||
 | 
					  # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
 | 
				
			||||||
 | 
					  system.stateVersion = "23.05"; # Did you read the comment?
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
							
								
								
									
										40
									
								
								hosts/tuba/hardware-configuration.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										40
									
								
								hosts/tuba/hardware-configuration.nix
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,40 @@
 | 
				
			|||||||
 | 
					# Do not modify this file!  It was generated by ‘nixos-generate-config’
 | 
				
			||||||
 | 
					# and may be overwritten by future invocations.  Please make changes
 | 
				
			||||||
 | 
					# to /etc/nixos/configuration.nix instead.
 | 
				
			||||||
 | 
					{ config, lib, pkgs, modulesPath, ... }:
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					{
 | 
				
			||||||
 | 
					  imports =
 | 
				
			||||||
 | 
					    [ (modulesPath + "/installer/scan/not-detected.nix")
 | 
				
			||||||
 | 
					    ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  boot.initrd.availableKernelModules = [ "xhci_pci" "ehci_pci" "ahci" "usb_storage" "usbhid" "sd_mod" ];
 | 
				
			||||||
 | 
					  boot.initrd.kernelModules = [ ];
 | 
				
			||||||
 | 
					  boot.kernelModules = [ "kvm-intel" ];
 | 
				
			||||||
 | 
					  boot.extraModulePackages = [ ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  fileSystems."/" =
 | 
				
			||||||
 | 
					    { device = "/dev/disk/by-uuid/33825f0d-5a63-40fc-83db-bfa1ebb72ba0";
 | 
				
			||||||
 | 
					      fsType = "ext4";
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  fileSystems."/boot" =
 | 
				
			||||||
 | 
					    { device = "/dev/disk/by-uuid/145E-7362";
 | 
				
			||||||
 | 
					      fsType = "vfat";
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  swapDevices =
 | 
				
			||||||
 | 
					    [ { device = "/dev/disk/by-uuid/7ed27e21-3247-44cd-8bcc-5d4a2efebf57"; }
 | 
				
			||||||
 | 
					    ];
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  # Enables DHCP on each ethernet and wireless interface. In case of scripted networking
 | 
				
			||||||
 | 
					  # (the default) this is the recommended approach. When using systemd-networkd it's
 | 
				
			||||||
 | 
					  # still possible to use this option, but it's recommended to use it in conjunction
 | 
				
			||||||
 | 
					  # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
 | 
				
			||||||
 | 
					  networking.useDHCP = lib.mkDefault true;
 | 
				
			||||||
 | 
					  # networking.interfaces.eno1.useDHCP = lib.mkDefault true;
 | 
				
			||||||
 | 
					  # networking.interfaces.enp2s2.useDHCP = lib.mkDefault true;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					  nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
 | 
				
			||||||
 | 
					  hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
							
								
								
									
										54
									
								
								hosts/tuba/services/openvpn/default.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										54
									
								
								hosts/tuba/services/openvpn/default.nix
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,54 @@
 | 
				
			|||||||
 | 
					{ lib, values, ... }:
 | 
				
			||||||
 | 
					{
 | 
				
			||||||
 | 
					  services.openvpn.servers."ov-tunnel" = {
 | 
				
			||||||
 | 
					    config = let
 | 
				
			||||||
 | 
					      conf = {
 | 
				
			||||||
 | 
					        # TODO: use aliases
 | 
				
			||||||
 | 
					        client = true;
 | 
				
			||||||
 | 
					        dev = "tap";
 | 
				
			||||||
 | 
					        proto = "udp";
 | 
				
			||||||
 | 
					        remote = "129.241.210.191 1194";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        resolv-retry = "infinite";
 | 
				
			||||||
 | 
					        nobind = true;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        # # TODO: set up
 | 
				
			||||||
 | 
					        ca = "";
 | 
				
			||||||
 | 
					        cert = "";
 | 
				
			||||||
 | 
					        key = "";
 | 
				
			||||||
 | 
					        remote-cert-tls = "server";
 | 
				
			||||||
 | 
					        cipher = "none";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        user = "nobody";
 | 
				
			||||||
 | 
					        group = "nobody";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        status = "/var/log/openvpn-status.log";
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        persist-key = true;
 | 
				
			||||||
 | 
					        persist-tun = true;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        verb = 5;
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					        # script-security = 2;
 | 
				
			||||||
 | 
					        # up = "systemctl restart rwhod";
 | 
				
			||||||
 | 
					      };
 | 
				
			||||||
 | 
					    in lib.pipe conf [
 | 
				
			||||||
 | 
					      (lib.filterAttrs (_: value: !(builtins.isNull value || value == false)))
 | 
				
			||||||
 | 
					      (builtins.mapAttrs (_: value:
 | 
				
			||||||
 | 
					        if builtins.isList value then builtins.concatStringsSep " " (map toString value)
 | 
				
			||||||
 | 
					        else if value == true then value
 | 
				
			||||||
 | 
					        else if builtins.any (f: f value) [
 | 
				
			||||||
 | 
					          builtins.isString
 | 
				
			||||||
 | 
					          builtins.isInt
 | 
				
			||||||
 | 
					          builtins.isFloat
 | 
				
			||||||
 | 
					          lib.isPath
 | 
				
			||||||
 | 
					          lib.isDerivation
 | 
				
			||||||
 | 
					        ] then toString value
 | 
				
			||||||
 | 
					        else throw "Unknown value in tuba openvpn config, deading now\n${value}"
 | 
				
			||||||
 | 
					      ))
 | 
				
			||||||
 | 
					      (lib.mapAttrsToList (name: value: if value == true then name else "${name} ${value}"))
 | 
				
			||||||
 | 
					      (builtins.concatStringsSep "\n")
 | 
				
			||||||
 | 
					      (x: x + "\n\n")
 | 
				
			||||||
 | 
					    ];
 | 
				
			||||||
 | 
					  };
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
@@ -15,8 +15,8 @@ let
 | 
				
			|||||||
        enable = true;
 | 
					        enable = true;
 | 
				
			||||||
        name = "git-runner-${name}"; url = "https://git.pvv.ntnu.no";
 | 
					        name = "git-runner-${name}"; url = "https://git.pvv.ntnu.no";
 | 
				
			||||||
        labels = [
 | 
					        labels = [
 | 
				
			||||||
          "debian-latest:docker://node:current-bookworm"
 | 
					          "debian-latest:docker://node:18-bullseye"
 | 
				
			||||||
          "ubuntu-latest:docker://node:current-bookworm"
 | 
					          "ubuntu-latest:docker://node:18-bullseye"
 | 
				
			||||||
        ];
 | 
					        ];
 | 
				
			||||||
        tokenFile = config.sops.secrets."gitea/runners/${name}".path;
 | 
					        tokenFile = config.sops.secrets."gitea/runners/${name}".path;
 | 
				
			||||||
      };
 | 
					      };
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -2,8 +2,6 @@
 | 
				
			|||||||
let
 | 
					let
 | 
				
			||||||
  grg = config.services.greg-ng;
 | 
					  grg = config.services.greg-ng;
 | 
				
			||||||
  grgw = config.services.grzegorz-webui;
 | 
					  grgw = config.services.grzegorz-webui;
 | 
				
			||||||
 | 
					 | 
				
			||||||
  machine = config.networking.hostName;
 | 
					 | 
				
			||||||
in {
 | 
					in {
 | 
				
			||||||
  services.greg-ng = {
 | 
					  services.greg-ng = {
 | 
				
			||||||
    enable = true;
 | 
					    enable = true;
 | 
				
			||||||
@@ -18,56 +16,17 @@ in {
 | 
				
			|||||||
    listenAddr = "localhost";
 | 
					    listenAddr = "localhost";
 | 
				
			||||||
    listenPort = 42069;
 | 
					    listenPort = 42069;
 | 
				
			||||||
    listenWebsocketPort = 42042;
 | 
					    listenWebsocketPort = 42042;
 | 
				
			||||||
    hostName = "${machine}-old.pvv.ntnu.no";
 | 
					    hostName = "${config.networking.fqdn}";
 | 
				
			||||||
    apiBase = "https://${machine}-backend.pvv.ntnu.no/api";
 | 
					    apiBase = "http://${grg.settings.host}:${toString grg.settings.port}/api";
 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
  services.gergle = {
 | 
					 | 
				
			||||||
    enable = true;
 | 
					 | 
				
			||||||
    virtualHost = config.networking.fqdn;
 | 
					 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  services.nginx.enable = true;
 | 
					  services.nginx.enable = true;
 | 
				
			||||||
  services.nginx.virtualHosts = {
 | 
					  services.nginx.virtualHosts."${config.networking.fqdn}" = {
 | 
				
			||||||
    ${config.networking.fqdn} = {
 | 
					 | 
				
			||||||
    forceSSL = true;
 | 
					    forceSSL = true;
 | 
				
			||||||
    enableACME = true;
 | 
					    enableACME = true;
 | 
				
			||||||
    kTLS = true;
 | 
					    kTLS = true;
 | 
				
			||||||
    serverAliases = [
 | 
					    serverAliases = [
 | 
				
			||||||
        "${machine}.pvv.org"
 | 
					      "${config.networking.hostName}.pvv.org"
 | 
				
			||||||
      ];
 | 
					 | 
				
			||||||
      extraConfig = ''
 | 
					 | 
				
			||||||
        allow 129.241.210.128/25;
 | 
					 | 
				
			||||||
        allow 2001:700:300:1900::/64;
 | 
					 | 
				
			||||||
        deny all;
 | 
					 | 
				
			||||||
      '';
 | 
					 | 
				
			||||||
    };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    "${machine}-backend.pvv.ntnu.no" = {
 | 
					 | 
				
			||||||
      forceSSL = true;
 | 
					 | 
				
			||||||
      enableACME = true;
 | 
					 | 
				
			||||||
      kTLS = true;
 | 
					 | 
				
			||||||
      serverAliases = [
 | 
					 | 
				
			||||||
        "${machine}-backend.pvv.org"
 | 
					 | 
				
			||||||
      ];
 | 
					 | 
				
			||||||
      extraConfig = ''
 | 
					 | 
				
			||||||
        allow 129.241.210.128/25;
 | 
					 | 
				
			||||||
        allow 2001:700:300:1900::/64;
 | 
					 | 
				
			||||||
        deny all;
 | 
					 | 
				
			||||||
      '';
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
      locations."/" = {
 | 
					 | 
				
			||||||
        proxyPass = "http://${grg.settings.host}:${toString grg.settings.port}";
 | 
					 | 
				
			||||||
        proxyWebsockets = true;
 | 
					 | 
				
			||||||
      };
 | 
					 | 
				
			||||||
    };
 | 
					 | 
				
			||||||
 | 
					 | 
				
			||||||
    "${machine}-old.pvv.ntnu.no" = {
 | 
					 | 
				
			||||||
      forceSSL = true;
 | 
					 | 
				
			||||||
      enableACME = true;
 | 
					 | 
				
			||||||
      kTLS = true;
 | 
					 | 
				
			||||||
      serverAliases = [
 | 
					 | 
				
			||||||
        "${machine}-old.pvv.org"
 | 
					 | 
				
			||||||
    ];
 | 
					    ];
 | 
				
			||||||
    extraConfig = ''
 | 
					    extraConfig = ''
 | 
				
			||||||
      allow 129.241.210.128/25;
 | 
					      allow 129.241.210.128/25;
 | 
				
			||||||
@@ -90,6 +49,5 @@ in {
 | 
				
			|||||||
      proxyPass = "http://${grg.settings.host}:${toString grg.settings.port}";
 | 
					      proxyPass = "http://${grg.settings.host}:${toString grg.settings.port}";
 | 
				
			||||||
    };
 | 
					    };
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
  };
 | 
					 | 
				
			||||||
}
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -12,7 +12,7 @@ let
 | 
				
			|||||||
    name
 | 
					    name
 | 
				
			||||||
  , commit
 | 
					  , commit
 | 
				
			||||||
  , hash
 | 
					  , hash
 | 
				
			||||||
  , tracking-branch ? "REL1_42"
 | 
					  , tracking-branch ? "REL1_41"
 | 
				
			||||||
  , kebab-name ? kebab-case-name name
 | 
					  , kebab-name ? kebab-case-name name
 | 
				
			||||||
  , fetchgit ? pkgs.fetchgit
 | 
					  , fetchgit ? pkgs.fetchgit
 | 
				
			||||||
  }:
 | 
					  }:
 | 
				
			||||||
@@ -33,63 +33,63 @@ in
 | 
				
			|||||||
lib.mergeAttrsList [
 | 
					lib.mergeAttrsList [
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "CodeEditor";
 | 
					    name = "CodeEditor";
 | 
				
			||||||
    commit = "9f69f2cf7616342d236726608a702d651b611938";
 | 
					    commit = "7d8447035e381d76387e38b92e4d1e2b8d373a01";
 | 
				
			||||||
    hash = "sha256-sRaYj34+7aghJUw18RoowzEiMx0aOANU1a7YT8jivBw=";
 | 
					    hash = "sha256-v2AlbP0vZma3qZyEAWGjZ/rLcvOpIMroyc1EixKjlAU=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "CodeMirror";
 | 
					    name = "CodeMirror";
 | 
				
			||||||
    commit = "1a1048c770795789676adcf8a33c1b69f6f5d3ae";
 | 
					    commit = "a7b4541089f9b88a0b722d9d790e4cf0f13aa328";
 | 
				
			||||||
    hash = "sha256-Y5ePrtLNiko2uU/sesm8jdYmxZkYzQDHfkIG1Q0v47I=";
 | 
					    hash = "sha256-clyzN3v3+J4GjdyhrCsytBrH7VR1tq5yd0rB+32eWCg=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "DeleteBatch";
 | 
					    name = "DeleteBatch";
 | 
				
			||||||
    commit = "b76bb482e026453079104d00f9675b4ab851947e";
 | 
					    commit = "cad869fbd95637902673f744581b29e0f3e3f61a";
 | 
				
			||||||
    hash = "sha256-GebF9B3RVwpPw8CYKDDT6zHv/MrrzV6h2TEIvNlRmcw=";
 | 
					    hash = "sha256-M1ek1WdO1/uTjeYlrk3Tz+nlb/fFZH+O0Ok7b10iKak=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "PluggableAuth";
 | 
					    name = "PluggableAuth";
 | 
				
			||||||
    commit = "1da98f447fd8321316d4286d8106953a6665f1cc";
 | 
					    commit = "4111a57c34e25bde579cce5d14ea094021e450c8";
 | 
				
			||||||
    hash = "sha256-DKDVcAfWL90FmZbSsdx1J5PkGu47EsDQmjlCpcgLCn4=";
 | 
					    hash = "sha256-aPtN8A9gDxLlq2+EloRZBO0DfHtE0E5kbV/adk82jvM=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "Popups";
 | 
					    name = "Popups";
 | 
				
			||||||
    commit = "9b9e986316b9662b1b45ce307a58dd0320dd33cf";
 | 
					    commit = "f1bcadbd8b868f32ed189feff232c47966c2c49e";
 | 
				
			||||||
    hash = "sha256-rSOZHT3yFIxA3tPhIvztwMSmSef/XHKmNfQl1JtGrUA=";
 | 
					    hash = "sha256-PQAjq/X4ZYwnnZ6ADCp3uGWMIucJy0ZXxsTTbAyxlSE=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "Scribunto";
 | 
					    name = "Scribunto";
 | 
				
			||||||
    commit = "eb6a987e90db47b09b0454fd06cddb69fdde9c40";
 | 
					    commit = "7b99c95f588b06635ee3c487080d6cb04617d4b5";
 | 
				
			||||||
    hash = "sha256-Nr0ZLIrS5jnpiBgGnd90lzi6KshcsxeC+xGmNsB/g88=";
 | 
					    hash = "sha256-pviueRHQAsSlv4AtnUpo2Cjci7CbJ5aM75taEXY+WrI=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "SimpleSAMLphp";
 | 
					    name = "SimpleSAMLphp";
 | 
				
			||||||
    kebab-name = "simple-saml-php";
 | 
					    kebab-name = "simple-saml-php";
 | 
				
			||||||
    commit = "fd4d49cf48d16efdb91ae8128cdd507efe84d311";
 | 
					    commit = "ecb47191fecd1e0dc4c9d8b90a9118e393d82c23";
 | 
				
			||||||
    hash = "sha256-Qdtroew2j3AsZYlhAAUKQXXS2kUzUeQFnuR6ZHdFhAQ=";
 | 
					    hash = "sha256-gKu+O49XrAVt6hXdt36Ru7snjsKX6g2CYJ0kk/d+CI8=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "TemplateData";
 | 
					    name = "TemplateData";
 | 
				
			||||||
    commit = "836e3ca277301addd2578b2e746498ff6eb8e574";
 | 
					    commit = "1ec66ce80f8a4322138efa56864502d0ee069bad";
 | 
				
			||||||
    hash = "sha256-UMcRLYxYn+AormwTYjKjjZZjA806goMY2TRQ4KoS5fY=";
 | 
					    hash = "sha256-Lv3Lq9dYAtdgWcwelveTuOhkP38MTu0m5kmW8+ltRis=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "TemplateStyles";
 | 
					    name = "TemplateStyles";
 | 
				
			||||||
    commit = "06a2587689eba0a17945fd9bd4bb61674d3a7853";
 | 
					    commit = "581180e898d6a942e2a65c8f13435a5d50fffa67";
 | 
				
			||||||
    hash = "sha256-C7j0jCkMeVZiLKpk+55X+lLnbG4aeH+hWIm3P5fF4fw=";
 | 
					    hash = "sha256-zW8O0mzG4jYfQoKi2KzsP+8iwRCLnWgH7qfmDE2R+HU=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "UserMerge";
 | 
					    name = "UserMerge";
 | 
				
			||||||
    commit = "41759d0c61377074d159f7d84130a095822bc7a3";
 | 
					    commit = "c17c919bdb9b67bb69f80df43e9ee9d33b1ecf1b";
 | 
				
			||||||
    hash = "sha256-pGjA7r30StRw4ff0QzzZYUhgD3dC3ZuiidoSEz8kA8Q=";
 | 
					    hash = "sha256-+mkzTCo8RVlGoFyfCrSb5YMh4J6Pbi1PZLFu5ps8bWY=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "VisualEditor";
 | 
					    name = "VisualEditor";
 | 
				
			||||||
    commit = "a128b11fe109aa882de5a40d2be0cdd0947ab11b";
 | 
					    commit = "90bb3d455892e25317029ffd4bda93159e8faac8";
 | 
				
			||||||
    hash = "sha256-bv1TkomouOxe+DKzthyLyppdEUFSXJ9uE0zsteVU+D4=";
 | 
					    hash = "sha256-SZAVELQUKZtwSM6NVlxvIHdFPodko8fhZ/uwB0LCFDA=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
  (mw-ext {
 | 
					  (mw-ext {
 | 
				
			||||||
    name = "WikiEditor";
 | 
					    name = "WikiEditor";
 | 
				
			||||||
    commit = "21383e39a4c9169000acd03edfbbeec4451d7974";
 | 
					    commit = "8dba5b13246d7ae09193f87e6273432b3264de5f";
 | 
				
			||||||
    hash = "sha256-aPVpE6e4qLLliN9U5TA36e8tFrIt7Fl8RT1cGPUWoNI=";
 | 
					    hash = "sha256-vF9PBuM+VfOIs/a2X1JcPn6WH4GqP/vUJDFkfXzWyFU=";
 | 
				
			||||||
  })
 | 
					  })
 | 
				
			||||||
]
 | 
					]
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -1,8 +1,8 @@
 | 
				
			|||||||
gitea:
 | 
					gitea:
 | 
				
			||||||
    runners:
 | 
					    runners:
 | 
				
			||||||
        alpha: ENC[AES256_GCM,data:Hnq2guka4oERPIFCv1/ggrLjaePA7907VHXMStDQ7ll3hntTioT76qGOUJgfIw==,iv:wDPYuuL6VAWJakrz6asVRrzwRxqw0JDRes13MgJIT6E=,tag:ogFUeUirHVkCLN63nctxOw==,type:str]
 | 
					        alpha: ENC[AES256_GCM,data:aAFv+/ygC7oxGT3qnoEf+AZL3Nk1yOq3HupL9l0j8P913GefPKqlBt/mbuRVug==,iv:usXElENwbOHxUdoqHScK7PjeZavXUwoxpQWEMjxU2u4=,tag:E8OzZ9pmxIru7Glgh7v0lg==,type:str]
 | 
				
			||||||
        beta: ENC[AES256_GCM,data:HmdjBvW8eO5MkzXf7KEzSNQAptF/RKN8Bh03Ru7Ru/Ky+eJJtk91aqSSIjFa+Q==,iv:Hz9HE3U6CFfZFcPmYMd6wSzZkSvszt92L2gV+pUlMis=,tag:LG3NfsS7B1EdRFvnP3XESQ==,type:str]
 | 
					        beta: ENC[AES256_GCM,data:riRSBDzX9DAxKl2UCds1ANddl3ij+byAgigOafJ5RjWl8cNVlowK21klBiKTxw==,iv:clijEUKX9o52p5A94eEW0f8qGGhFpy/LFe+uQG/iQLg=,tag:PchXbsZMnW//O7brEAEeWw==,type:str]
 | 
				
			||||||
        epsilon: ENC[AES256_GCM,data:wfGxwWwDzb6AJaFnxe/93WNZGtuTpCkLci/Cc5MTCTKJz6XlNuy3m/1Xsnw0hA==,iv:I6Zl+4BBAUTXym2qUlFfdnoLTHShu+VyxPMjRlFzMis=,tag:jjTyZs1Nzqlhjd8rAldxDw==,type:str]
 | 
					        epsilon: ENC[AES256_GCM,data:lUt8uaqh9eC1IdIUfiw3dzxcDErSWaiT9lzg4ONf/QZeXj7Do7Es0GXBFd41Hw==,iv:hPm5Lez5ISHIlw1+i4z/oBsh4H5ZXPVYnXXSGq1eal0=,tag:/KcmPw30622tN9ruMUwfUw==,type:str]
 | 
				
			||||||
sops:
 | 
					sops:
 | 
				
			||||||
    kms: []
 | 
					    kms: []
 | 
				
			||||||
    gcp_kms: []
 | 
					    gcp_kms: []
 | 
				
			||||||
@@ -63,8 +63,8 @@ sops:
 | 
				
			|||||||
            aU4xWjVYYlNvSmYxajVGdzk5dTQ4WG8Klq12bSegsW29xp4qteuCB5Tzis6EhVCk
 | 
					            aU4xWjVYYlNvSmYxajVGdzk5dTQ4WG8Klq12bSegsW29xp4qteuCB5Tzis6EhVCk
 | 
				
			||||||
            53jqtYe5UG9MjFVQYiSi2jJz5/dxfqSINMZ/Y/EB5LxbwgbFws8Yuw==
 | 
					            53jqtYe5UG9MjFVQYiSi2jJz5/dxfqSINMZ/Y/EB5LxbwgbFws8Yuw==
 | 
				
			||||||
            -----END AGE ENCRYPTED FILE-----
 | 
					            -----END AGE ENCRYPTED FILE-----
 | 
				
			||||||
    lastmodified: "2024-12-12T12:20:19Z"
 | 
					    lastmodified: "2024-12-09T21:17:40Z"
 | 
				
			||||||
    mac: ENC[AES256_GCM,data:D9/NAd/zrF6pHFdZjTUqI+u4WiwJqt0w5Y+SYCS1o/dAXJE/ajHzse/vCSGXZIjP0yqe+S/NyTvhf+stw2B4dk6Njtabjd+PhG0hR4L0X07FtFqzB3u5pLHCb0bH9QLG5zWcyMkwNiNTCvhRUZzbcqLEGqqJ7ZjZAEUfYSR+Jls=,iv:5xPfODPxtQjgbl8delUHsmhD0TI2gHjrxpHV+qiFE00=,tag:HHLo5G8jhy/sKB3R+sKmwQ==,type:str]
 | 
					    mac: ENC[AES256_GCM,data:HensJbPU1Kx9aQNUhdtFkX/6qdxj7yby6GeSruOT+HYEtoq0py/zvMtdCqmfjc4AOptYlXdgK7w30P976dG1esjlYwF07qtVvAbUqvExkksuV4zp81VKHMXUOAyiQK79kLe3rx6cvEdUDbOjZOsxN02eRrcanN+7rJS6f7vNN88=,iv:PlePCik6JcOtVBQhhOj9khhp2LwwfXBwAGpzu4ywhTA=,tag:Clz+xX1Cffs8Zpv2LdsGVA==,type:str]
 | 
				
			||||||
    pgp:
 | 
					    pgp:
 | 
				
			||||||
        - created_at: "2024-12-09T21:17:27Z"
 | 
					        - created_at: "2024-12-09T21:17:27Z"
 | 
				
			||||||
          enc: |-
 | 
					          enc: |-
 | 
				
			||||||
@@ -87,4 +87,4 @@ sops:
 | 
				
			|||||||
            -----END PGP MESSAGE-----
 | 
					            -----END PGP MESSAGE-----
 | 
				
			||||||
          fp: F7D37890228A907440E1FD4846B9228E814A2AAC
 | 
					          fp: F7D37890228A907440E1FD4846B9228E814A2AAC
 | 
				
			||||||
    unencrypted_suffix: _unencrypted
 | 
					    unencrypted_suffix: _unencrypted
 | 
				
			||||||
    version: 3.9.2
 | 
					    version: 3.8.1
 | 
				
			||||||
 
 | 
				
			|||||||
							
								
								
									
										18
									
								
								values.nix
									
									
									
									
									
								
							
							
						
						
									
										18
									
								
								values.nix
									
									
									
									
									
								
							@@ -21,6 +21,12 @@ in rec {
 | 
				
			|||||||
      ipv4 = pvv-ipv4 213;
 | 
					      ipv4 = pvv-ipv4 213;
 | 
				
			||||||
      ipv6 = pvv-ipv6 213;
 | 
					      ipv6 = pvv-ipv6 213;
 | 
				
			||||||
    };
 | 
					    };
 | 
				
			||||||
 | 
					    grevling-tap = {
 | 
				
			||||||
 | 
					      ipv4 = pvv-ipv4 251;
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
 | 
					    tuba-tap = {
 | 
				
			||||||
 | 
					      ipv4 = pvv-ipv4 252;
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  hosts = {
 | 
					  hosts = {
 | 
				
			||||||
@@ -31,10 +37,6 @@ in rec {
 | 
				
			|||||||
      ipv4 = pvv-ipv4 168;
 | 
					      ipv4 = pvv-ipv4 168;
 | 
				
			||||||
      ipv6 = pvv-ipv6 168;
 | 
					      ipv6 = pvv-ipv6 168;
 | 
				
			||||||
    };
 | 
					    };
 | 
				
			||||||
    dagali = {
 | 
					 | 
				
			||||||
      ipv4 = pvv-ipv4 185;
 | 
					 | 
				
			||||||
      ipv6 = pvv-ipv6 185;
 | 
					 | 
				
			||||||
    };
 | 
					 | 
				
			||||||
    ildkule = {
 | 
					    ildkule = {
 | 
				
			||||||
      ipv4 = "129.241.153.213";
 | 
					      ipv4 = "129.241.153.213";
 | 
				
			||||||
      ipv4_internal = "192.168.12.209";
 | 
					      ipv4_internal = "192.168.12.209";
 | 
				
			||||||
@@ -68,6 +70,14 @@ in rec {
 | 
				
			|||||||
      ipv4 = pvv-ipv4 234;
 | 
					      ipv4 = pvv-ipv4 234;
 | 
				
			||||||
      ipv6 = pvv-ipv6 234;
 | 
					      ipv6 = pvv-ipv6 234;
 | 
				
			||||||
    };
 | 
					    };
 | 
				
			||||||
 | 
					    grevling = {
 | 
				
			||||||
 | 
					      ipv4 = pvv-ipv4 198;
 | 
				
			||||||
 | 
					      ipv6 = pvv-ipv6 198;
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
 | 
					    tuba = {
 | 
				
			||||||
 | 
					      ipv4 = pvv-ipv4 199;
 | 
				
			||||||
 | 
					      ipv6 = pvv-ipv6 199;
 | 
				
			||||||
 | 
					    };
 | 
				
			||||||
  };
 | 
					  };
 | 
				
			||||||
 | 
					
 | 
				
			||||||
  defaultNetworkConfig = {
 | 
					  defaultNetworkConfig = {
 | 
				
			||||||
 
 | 
				
			|||||||
		Reference in New Issue
	
	Block a user