Compare commits
	
		
			21 Commits
		
	
	
		
			nom
			...
			gitea-runn
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 043099eb37 | |||
| 59969b9ec8 | |||
| febc0940f8 | |||
| 76c251c277 | |||
| 1d48a63e3d | |||
| ddd405f534 | |||
| a2dcd3019f | |||
| 410d4e44a8 | |||
| 195163fd7b | |||
| 4fa544b430 | |||
| 7601734651 | |||
| cafeef827f | |||
| 9e00d143f8 | |||
| eceb2ce4c7 | |||
| 518008527d | |||
| 9e82ca3d15 | |||
| da7cb17f9e | |||
| 5d704840ce | |||
| 43d3ef1fed | |||
| e8df081894 | |||
| f40f2ae89d | 
							
								
								
									
										21
									
								
								.sops.yaml
									
									
									
									
									
								
							
							
						
						
									
										21
									
								
								.sops.yaml
									
									
									
									
									
								
							| @@ -15,6 +15,11 @@ keys: | |||||||
|   - &host_bicep age1sl43gc9cw939z5tgha2lpwf0xxxgcnlw7w4xem4sqgmt2pt264vq0dmwx2 |   - &host_bicep age1sl43gc9cw939z5tgha2lpwf0xxxgcnlw7w4xem4sqgmt2pt264vq0dmwx2 | ||||||
|   - &host_ustetind age1hffjafs4slznksefmtqrlj7rdaqgzqncn4un938rhr053237ry8s3rs0v8 |   - &host_ustetind age1hffjafs4slznksefmtqrlj7rdaqgzqncn4un938rhr053237ry8s3rs0v8 | ||||||
|   - &host_kommode age1mt4d0hg5g76qp7j0884llemy0k2ymr5up8vfudz6vzvsflk5nptqqd32ly |   - &host_kommode age1mt4d0hg5g76qp7j0884llemy0k2ymr5up8vfudz6vzvsflk5nptqqd32ly | ||||||
|  |   - &host_lupine-1 age1fkrypl6fu4ldsa7te4g3v4qsegnk7sd6qhkquuwzh04vguy96qus08902e | ||||||
|  |   - &host_lupine-2 age1mu0ej57n4s30ghealhyju3enls83qyjua69986la35t2yh0q2s0seruz5n | ||||||
|  |   - &host_lupine-3 age1j2u876z8hu87q5npfxzzpfgllyw8ypj66d7cgelmzmnrf3xud34qzkntp9 | ||||||
|  |   - &host_lupine-4 age1t8zlawqkmhye737pn8yx0z3p9cl947d9ktv2cajdc6hnvn52d3fsc59s2k | ||||||
|  |   - &host_lupine-5 age199zkqq4jp4yc3d0hx2q0ksxdtp42xhmjsqwyngh8tswuck34ke3smrfyqu | ||||||
|  |  | ||||||
| creation_rules: | creation_rules: | ||||||
|   # Global secrets |   # Global secrets | ||||||
| @@ -104,3 +109,19 @@ creation_rules: | |||||||
|       - *user_pederbs_bjarte |       - *user_pederbs_bjarte | ||||||
|       pgp: |       pgp: | ||||||
|       - *user_oysteikt |       - *user_oysteikt | ||||||
|  |  | ||||||
|  |   - path_regex: secrets/lupine/[^/]+\.yaml$ | ||||||
|  |     key_groups: | ||||||
|  |     - age: | ||||||
|  |       - *host_lupine-1 | ||||||
|  |       - *host_lupine-2 | ||||||
|  |       - *host_lupine-3 | ||||||
|  |       - *host_lupine-4 | ||||||
|  |       - *host_lupine-5 | ||||||
|  |       - *user_danio | ||||||
|  |       - *user_felixalb | ||||||
|  |       - *user_pederbs_sopp | ||||||
|  |       - *user_pederbs_nord | ||||||
|  |       - *user_pederbs_bjarte | ||||||
|  |       pgp: | ||||||
|  |       - *user_oysteikt | ||||||
|   | |||||||
							
								
								
									
										11
									
								
								base/nix.nix
									
									
									
									
									
								
							
							
						
						
									
										11
									
								
								base/nix.nix
									
									
									
									
									
								
							| @@ -1,4 +1,4 @@ | |||||||
| { inputs, ... }: | { lib, config, inputs, ... }: | ||||||
| { | { | ||||||
|   nix = { |   nix = { | ||||||
|     gc = { |     gc = { | ||||||
| @@ -21,11 +21,16 @@ | |||||||
|     ** use the same channel the system |     ** use the same channel the system | ||||||
|     ** was built with |     ** was built with | ||||||
|     */ |     */ | ||||||
|     registry = { |     registry = lib.mkMerge [ | ||||||
|  |       { | ||||||
|         "nixpkgs".flake = inputs.nixpkgs; |         "nixpkgs".flake = inputs.nixpkgs; | ||||||
|         "nixpkgs-unstable".flake = inputs.nixpkgs-unstable; |         "nixpkgs-unstable".flake = inputs.nixpkgs-unstable; | ||||||
|  |       } | ||||||
|  |       # We avoid the reference to self in vmVariant to get a stable system .outPath for equivalence testing | ||||||
|  |       (lib.mkIf (!config.virtualisation.isVmVariant) { | ||||||
|         "pvv-nix".flake = inputs.self; |         "pvv-nix".flake = inputs.self; | ||||||
|     }; |       }) | ||||||
|  |     ]; | ||||||
|     nixPath = [ |     nixPath = [ | ||||||
|       "nixpkgs=${inputs.nixpkgs}" |       "nixpkgs=${inputs.nixpkgs}" | ||||||
|       "unstable=${inputs.nixpkgs-unstable}" |       "unstable=${inputs.nixpkgs-unstable}" | ||||||
|   | |||||||
| @@ -1,4 +1,4 @@ | |||||||
| { inputs, pkgs, lib, ... }: | { config, inputs, pkgs, lib, ... }: | ||||||
|  |  | ||||||
| let | let | ||||||
|   inputUrls = lib.mapAttrs (input: value: value.url) (import "${inputs.self}/flake.nix").inputs; |   inputUrls = lib.mapAttrs (input: value: value.url) (import "${inputs.self}/flake.nix").inputs; | ||||||
| @@ -26,7 +26,8 @@ in | |||||||
|  |  | ||||||
|   # workaround for https://github.com/NixOS/nix/issues/6895 |   # workaround for https://github.com/NixOS/nix/issues/6895 | ||||||
|   # via https://git.lix.systems/lix-project/lix/issues/400 |   # via https://git.lix.systems/lix-project/lix/issues/400 | ||||||
|   environment.etc."current-system-flake-inputs.json".source |   environment.etc = lib.mkIf (!config.virtualisation.isVmVariant) { | ||||||
|  |     "current-system-flake-inputs.json".source | ||||||
|       = pkgs.writers.writeJSON "flake-inputs.json" ( |       = pkgs.writers.writeJSON "flake-inputs.json" ( | ||||||
|         lib.flip lib.mapAttrs inputs (name: input: |         lib.flip lib.mapAttrs inputs (name: input: | ||||||
|           # inputs.*.sourceInfo sans outPath, since writeJSON will otherwise serialize sourceInfo like a derivation |           # inputs.*.sourceInfo sans outPath, since writeJSON will otherwise serialize sourceInfo like a derivation | ||||||
| @@ -34,4 +35,5 @@ in | |||||||
|             // { store-path = input.outPath; } # comment this line if you don't want to retain a store reference to the flake inputs |             // { store-path = input.outPath; } # comment this line if you don't want to retain a store reference to the flake inputs | ||||||
|         ) |         ) | ||||||
|       ); |       ); | ||||||
|  |   }; | ||||||
| } | } | ||||||
|   | |||||||
							
								
								
									
										60
									
								
								flake.lock
									
									
									
										generated
									
									
									
								
							
							
						
						
									
										60
									
								
								flake.lock
									
									
									
										generated
									
									
									
								
							| @@ -7,11 +7,11 @@ | |||||||
|         ] |         ] | ||||||
|       }, |       }, | ||||||
|       "locked": { |       "locked": { | ||||||
|         "lastModified": 1745502102, |         "lastModified": 1752113600, | ||||||
|         "narHash": "sha256-LqhRwzvIVPEjH0TaPgwzqpyhW6DtCrvz7FnUJDoUZh8=", |         "narHash": "sha256-7LYDxKxZgBQ8LZUuolAQ8UkIB+jb4A2UmiR+kzY9CLI=", | ||||||
|         "owner": "nix-community", |         "owner": "nix-community", | ||||||
|         "repo": "disko", |         "repo": "disko", | ||||||
|         "rev": "ca27b88c88948d96feeee9ed814cbd34f53d0d70", |         "rev": "79264292b7e3482e5702932949de9cbb69fedf6d", | ||||||
|         "type": "github" |         "type": "github" | ||||||
|       }, |       }, | ||||||
|       "original": { |       "original": { | ||||||
| @@ -48,11 +48,11 @@ | |||||||
|         "rust-overlay": "rust-overlay" |         "rust-overlay": "rust-overlay" | ||||||
|       }, |       }, | ||||||
|       "locked": { |       "locked": { | ||||||
|         "lastModified": 1746563623, |         "lastModified": 1752258704, | ||||||
|         "narHash": "sha256-5DxgNFpSgxft/sWraZnHIUlb4S3Io73SVS7FZCbWSUY=", |         "narHash": "sha256-pRK99+MCgkeVptbJxXhVMXIXl8uwSdkZDpQzFi3OgkA=", | ||||||
|         "ref": "refs/heads/main", |         "ref": "refs/heads/main", | ||||||
|         "rev": "4e0408887f80e61a90286ff630a7855b828ae421", |         "rev": "9ff525339b62855d53a44b4dc0154a33ac19e44d", | ||||||
|         "revCount": 45, |         "revCount": 48, | ||||||
|         "type": "git", |         "type": "git", | ||||||
|         "url": "https://git.pvv.ntnu.no/Grzegorz/greg-ng.git" |         "url": "https://git.pvv.ntnu.no/Grzegorz/greg-ng.git" | ||||||
|       }, |       }, | ||||||
| @@ -139,24 +139,24 @@ | |||||||
|     }, |     }, | ||||||
|     "nixpkgs": { |     "nixpkgs": { | ||||||
|       "locked": { |       "locked": { | ||||||
|         "lastModified": 1748615477, |         "lastModified": 1752439653, | ||||||
|         "narHash": "sha256-8sjG4sNIonQPK2olCGvq3/j1qtjwPaTOFU5nkz1gj2Q=", |         "narHash": "sha256-mG27U2CFuggpAuozOu/4XAMKaOtJxzJVzdEemjQEBgg=", | ||||||
|         "rev": "97d3ce1ceb663a24184aac92b7e9e8f5452111c1", |         "rev": "dfcd5b901dbab46c9c6e80b265648481aafb01f8", | ||||||
|         "type": "tarball", |         "type": "tarball", | ||||||
|         "url": "https://releases.nixos.org/nixos/24.11-small/nixos-24.11.718472.97d3ce1ceb66/nixexprs.tar.xz?rev=97d3ce1ceb663a24184aac92b7e9e8f5452111c1" |         "url": "https://releases.nixos.org/nixos/25.05-small/nixos-25.05.806304.dfcd5b901dba/nixexprs.tar.xz" | ||||||
|       }, |       }, | ||||||
|       "original": { |       "original": { | ||||||
|         "type": "tarball", |         "type": "tarball", | ||||||
|         "url": "https://nixos.org/channels/nixos-24.11-small/nixexprs.tar.xz" |         "url": "https://nixos.org/channels/nixos-25.05-small/nixexprs.tar.xz" | ||||||
|       } |       } | ||||||
|     }, |     }, | ||||||
|     "nixpkgs-unstable": { |     "nixpkgs-unstable": { | ||||||
|       "locked": { |       "locked": { | ||||||
|         "lastModified": 1748588304, |         "lastModified": 1752439402, | ||||||
|         "narHash": "sha256-YCnUqO9k39p0oMIBndxYTbu8m0fOA/KVcq3IekXPy9c=", |         "narHash": "sha256-xDfOnjnKStgsgcn9SFPgOV6qzwac4JvGKYyfR++49Pw=", | ||||||
|         "rev": "b8af95f4cf511c5f056b463c3a45d2b63c7cfb03", |         "rev": "b47d4f01d4213715a1f09b999bab96bb6a5b675e", | ||||||
|         "type": "tarball", |         "type": "tarball", | ||||||
|         "url": "https://releases.nixos.org/nixos/unstable-small/nixos-25.11pre807945.b8af95f4cf51/nixexprs.tar.xz?rev=b8af95f4cf511c5f056b463c3a45d2b63c7cfb03" |         "url": "https://releases.nixos.org/nixos/unstable-small/nixos-25.11pre829909.b47d4f01d421/nixexprs.tar.xz" | ||||||
|       }, |       }, | ||||||
|       "original": { |       "original": { | ||||||
|         "type": "tarball", |         "type": "tarball", | ||||||
| @@ -170,11 +170,11 @@ | |||||||
|         ] |         ] | ||||||
|       }, |       }, | ||||||
|       "locked": { |       "locked": { | ||||||
|         "lastModified": 1723850344, |         "lastModified": 1742225512, | ||||||
|         "narHash": "sha256-aT37O9l9eclWEnqxASVNBL1dKwDHZUOqdbA4VO9DJvw=", |         "narHash": "sha256-OB0ndlrGLE5wMUeYP4lmxly9JUEpPCeZRQyMzITKCB0=", | ||||||
|         "ref": "refs/heads/main", |         "ref": "refs/heads/main", | ||||||
|         "rev": "38b66677ab8c01aee10cd59e745af9ce3ea88092", |         "rev": "c4a6a02c84d8227abf00305dc995d7242176e6f6", | ||||||
|         "revCount": 19, |         "revCount": 21, | ||||||
|         "type": "git", |         "type": "git", | ||||||
|         "url": "https://git.pvv.ntnu.no/Projects/calendar-bot.git" |         "url": "https://git.pvv.ntnu.no/Projects/calendar-bot.git" | ||||||
|       }, |       }, | ||||||
| @@ -190,11 +190,11 @@ | |||||||
|         ] |         ] | ||||||
|       }, |       }, | ||||||
|       "locked": { |       "locked": { | ||||||
|         "lastModified": 1741738148, |         "lastModified": 1752865540, | ||||||
|         "narHash": "sha256-cJo6nbcJEOjkazkZ194NDnlsZe0W0wpxeUh2/886uC8=", |         "narHash": "sha256-VYLXcV8FsaMTsmxISOejvBq76eA41yi7BCRNW1qGbV0=", | ||||||
|         "ref": "refs/heads/main", |         "ref": "refs/heads/main", | ||||||
|         "rev": "c1802e7cf27c7cf8b4890354c982a4eef5b11593", |         "rev": "f732582d0d1389721ea2c91ab370ba2fb824d644", | ||||||
|         "revCount": 486, |         "revCount": 496, | ||||||
|         "type": "git", |         "type": "git", | ||||||
|         "url": "https://git.pvv.ntnu.no/Projects/nettsiden.git" |         "url": "https://git.pvv.ntnu.no/Projects/nettsiden.git" | ||||||
|       }, |       }, | ||||||
| @@ -227,11 +227,11 @@ | |||||||
|         ] |         ] | ||||||
|       }, |       }, | ||||||
|       "locked": { |       "locked": { | ||||||
|         "lastModified": 1746498961, |         "lastModified": 1752201818, | ||||||
|         "narHash": "sha256-rp+oh/N88JKHu7ySPuGiA3lBUVIsrOtHbN2eWJdYCgk=", |         "narHash": "sha256-d8KczaVT8WFEZdWg//tMAbv8EDyn2YTWcJvSY8gqKBU=", | ||||||
|         "owner": "oxalica", |         "owner": "oxalica", | ||||||
|         "repo": "rust-overlay", |         "repo": "rust-overlay", | ||||||
|         "rev": "24b00064cdd1d7ba25200c4a8565dc455dc732ba", |         "rev": "bd8f8329780b348fedcd37b53dbbee48c08c496d", | ||||||
|         "type": "github" |         "type": "github" | ||||||
|       }, |       }, | ||||||
|       "original": { |       "original": { | ||||||
| @@ -247,11 +247,11 @@ | |||||||
|         ] |         ] | ||||||
|       }, |       }, | ||||||
|       "locked": { |       "locked": { | ||||||
|         "lastModified": 1745310711, |         "lastModified": 1751606940, | ||||||
|         "narHash": "sha256-ePyTpKEJTgX0gvgNQWd7tQYQ3glIkbqcW778RpHlqgA=", |         "narHash": "sha256-KrDPXobG7DFKTOteqdSVeL1bMVitDcy7otpVZWDE6MA=", | ||||||
|         "owner": "Mic92", |         "owner": "Mic92", | ||||||
|         "repo": "sops-nix", |         "repo": "sops-nix", | ||||||
|         "rev": "5e3e92b16d6fdf9923425a8d4df7496b2434f39c", |         "rev": "3633fc4acf03f43b260244d94c71e9e14a2f6e0d", | ||||||
|         "type": "github" |         "type": "github" | ||||||
|       }, |       }, | ||||||
|       "original": { |       "original": { | ||||||
|   | |||||||
							
								
								
									
										64
									
								
								flake.nix
									
									
									
									
									
								
							
							
						
						
									
										64
									
								
								flake.nix
									
									
									
									
									
								
							| @@ -2,7 +2,7 @@ | |||||||
|   description = "PVV System flake"; |   description = "PVV System flake"; | ||||||
|  |  | ||||||
|   inputs = { |   inputs = { | ||||||
|     nixpkgs.url = "https://nixos.org/channels/nixos-24.11-small/nixexprs.tar.xz"; |     nixpkgs.url = "https://nixos.org/channels/nixos-25.05-small/nixexprs.tar.xz"; | ||||||
|     nixpkgs-unstable.url = "https://nixos.org/channels/nixos-unstable-small/nixexprs.tar.xz"; |     nixpkgs-unstable.url = "https://nixos.org/channels/nixos-unstable-small/nixexprs.tar.xz"; | ||||||
|  |  | ||||||
|     sops-nix.url = "github:Mic92/sops-nix"; |     sops-nix.url = "github:Mic92/sops-nix"; | ||||||
| @@ -55,46 +55,63 @@ | |||||||
|  |  | ||||||
|     nixosConfigurations = let |     nixosConfigurations = let | ||||||
|       unstablePkgs = nixpkgs-unstable.legacyPackages.x86_64-linux; |       unstablePkgs = nixpkgs-unstable.legacyPackages.x86_64-linux; | ||||||
|       nixosConfig = nixpkgs: name: config: lib.nixosSystem (lib.recursiveUpdate |  | ||||||
|         rec { |       nixosConfig = | ||||||
|  |         nixpkgs: | ||||||
|  |         name: | ||||||
|  |         configurationPath: | ||||||
|  |         extraArgs: | ||||||
|  |         lib.nixosSystem (lib.recursiveUpdate | ||||||
|  |         (let | ||||||
|           system = "x86_64-linux"; |           system = "x86_64-linux"; | ||||||
|  |         in { | ||||||
|  |           inherit system; | ||||||
|  |  | ||||||
|           specialArgs = { |           specialArgs = { | ||||||
|             inherit unstablePkgs inputs; |             inherit unstablePkgs inputs; | ||||||
|             values = import ./values.nix; |             values = import ./values.nix; | ||||||
|             fp = path: ./${path}; |             fp = path: ./${path}; | ||||||
|           }; |           } // extraArgs.specialArgs or { }; | ||||||
|  |  | ||||||
|           modules = [ |           modules = [ | ||||||
|             ./hosts/${name}/configuration.nix |             configurationPath | ||||||
|             sops-nix.nixosModules.sops |             sops-nix.nixosModules.sops | ||||||
|           ] ++ config.modules or []; |           ] ++ extraArgs.modules or []; | ||||||
|  |  | ||||||
|           pkgs = import nixpkgs { |           pkgs = import nixpkgs { | ||||||
|             inherit system; |             inherit system; | ||||||
|             config.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) |             extraArgs.allowUnfreePredicate = pkg: builtins.elem (lib.getName pkg) | ||||||
|               [ |               [ | ||||||
|                 "nvidia-x11" |                 "nvidia-x11" | ||||||
|                 "nvidia-settings" |                 "nvidia-settings" | ||||||
|               ]; |               ]; | ||||||
|             overlays = [ |             overlays = [ | ||||||
|               # Global overlays go here |               # Global overlays go here | ||||||
|             ] ++ config.overlays or [ ]; |             ] ++ extraArgs.overlays or [ ]; | ||||||
|           }; |           }; | ||||||
|         } |         }) | ||||||
|         (removeAttrs config [ "modules" "overlays" ]) |         (builtins.removeAttrs extraArgs [ | ||||||
|  |           "modules" | ||||||
|  |           "overlays" | ||||||
|  |           "specialArgs" | ||||||
|  |         ]) | ||||||
|       ); |       ); | ||||||
|  |  | ||||||
|       stableNixosConfig = nixosConfig nixpkgs; |       stableNixosConfig = name: extraArgs: | ||||||
|       unstableNixosConfig = nixosConfig nixpkgs-unstable; |           nixosConfig nixpkgs name ./hosts/${name}/configuration.nix extraArgs; | ||||||
|     in { |     in { | ||||||
|       bicep = stableNixosConfig "bicep" { |       bicep = stableNixosConfig "bicep" { | ||||||
|         modules = [ |         modules = [ | ||||||
|           inputs.matrix-next.nixosModules.default |           inputs.matrix-next.nixosModules.default | ||||||
|           inputs.pvv-calendar-bot.nixosModules.default |           inputs.pvv-calendar-bot.nixosModules.default | ||||||
|           self.nixosModules.gickup |           self.nixosModules.gickup | ||||||
|  |           self.nixosModules.matrix-ooye | ||||||
|         ]; |         ]; | ||||||
|         overlays = [ |         overlays = [ | ||||||
|           inputs.pvv-calendar-bot.overlays.x86_64-linux.default |           inputs.pvv-calendar-bot.overlays.x86_64-linux.default | ||||||
|  |           (final: prev: { | ||||||
|  |             inherit (self.packages.${prev.system}) out-of-your-element; | ||||||
|  |           }) | ||||||
|         ]; |         ]; | ||||||
|       }; |       }; | ||||||
|       bekkalokk = stableNixosConfig "bekkalokk" { |       bekkalokk = stableNixosConfig "bekkalokk" { | ||||||
| @@ -111,12 +128,6 @@ | |||||||
|           inputs.pvv-nettsiden.nixosModules.default |           inputs.pvv-nettsiden.nixosModules.default | ||||||
|         ]; |         ]; | ||||||
|       }; |       }; | ||||||
|       bob = stableNixosConfig "bob" { |  | ||||||
|         modules = [ |  | ||||||
|           disko.nixosModules.disko |  | ||||||
|           { disko.devices.disk.disk1.device = "/dev/vda"; } |  | ||||||
|         ]; |  | ||||||
|       }; |  | ||||||
|       ildkule = stableNixosConfig "ildkule" { }; |       ildkule = stableNixosConfig "ildkule" { }; | ||||||
|       #ildkule-unstable = unstableNixosConfig "ildkule" { }; |       #ildkule-unstable = unstableNixosConfig "ildkule" { }; | ||||||
|       shark = stableNixosConfig "shark" { }; |       shark = stableNixosConfig "shark" { }; | ||||||
| @@ -159,19 +170,29 @@ | |||||||
|           inputs.gergle.overlays.default |           inputs.gergle.overlays.default | ||||||
|         ]; |         ]; | ||||||
|       }; |       }; | ||||||
|     }; |     } | ||||||
|  |     // | ||||||
|  |     (let | ||||||
|  |       machineNames = map (i: "lupine-${toString i}") (lib.range 1 5); | ||||||
|  |       stableLupineNixosConfig = name: extraArgs: | ||||||
|  |           nixosConfig nixpkgs name ./hosts/lupine/configuration.nix extraArgs; | ||||||
|  |     in lib.genAttrs machineNames (name: stableLupineNixosConfig name { | ||||||
|  |       modules = [{ networking.hostName = name; }]; | ||||||
|  |       specialArgs.lupineName = name; | ||||||
|  |     })); | ||||||
|  |  | ||||||
|     nixosModules = { |     nixosModules = { | ||||||
|       snakeoil-certs = ./modules/snakeoil-certs.nix; |       snakeoil-certs = ./modules/snakeoil-certs.nix; | ||||||
|       snappymail = ./modules/snappymail.nix; |       snappymail = ./modules/snappymail.nix; | ||||||
|       robots-txt = ./modules/robots-txt.nix; |       robots-txt = ./modules/robots-txt.nix; | ||||||
|       gickup = ./modules/gickup; |       gickup = ./modules/gickup; | ||||||
|  |       matrix-ooye = ./modules/matrix-ooye.nix; | ||||||
|     }; |     }; | ||||||
|  |  | ||||||
|     devShells = forAllSystems (system: { |     devShells = forAllSystems (system: { | ||||||
|       default = nixpkgs.legacyPackages.${system}.callPackage ./shell.nix { }; |       default = nixpkgs-unstable.legacyPackages.${system}.callPackage ./shell.nix { }; | ||||||
|       cuda = let |       cuda = let | ||||||
|         cuda-pkgs = import nixpkgs { |         cuda-pkgs = import nixpkgs-unstable { | ||||||
|           inherit system; |           inherit system; | ||||||
|           config = { |           config = { | ||||||
|             allowUnfree = true; |             allowUnfree = true; | ||||||
| @@ -193,6 +214,7 @@ | |||||||
|  |  | ||||||
|         simplesamlphp = pkgs.callPackage ./packages/simplesamlphp { }; |         simplesamlphp = pkgs.callPackage ./packages/simplesamlphp { }; | ||||||
|  |  | ||||||
|  |         out-of-your-element = pkgs.callPackage ./packages/out-of-your-element.nix { }; | ||||||
|       } // |       } // | ||||||
|       (lib.pipe null [ |       (lib.pipe null [ | ||||||
|         (_: pkgs.callPackage ./packages/mediawiki-extensions { }) |         (_: pkgs.callPackage ./packages/mediawiki-extensions { }) | ||||||
|   | |||||||
| @@ -9,7 +9,8 @@ | |||||||
|     ./coturn.nix |     ./coturn.nix | ||||||
|     ./mjolnir.nix |     ./mjolnir.nix | ||||||
|  |  | ||||||
|     ./discord.nix |     # ./discord.nix | ||||||
|  |     ./out-of-your-element.nix | ||||||
|     ./hookshot |     ./hookshot | ||||||
|   ]; |   ]; | ||||||
|  |  | ||||||
|   | |||||||
| @@ -45,7 +45,7 @@ in | |||||||
|   }; |   }; | ||||||
|  |  | ||||||
|  |  | ||||||
|   services.mx-puppet-discord.enable = true; |   services.mx-puppet-discord.enable = false; | ||||||
|   services.mx-puppet-discord.settings = { |   services.mx-puppet-discord.settings = { | ||||||
|     bridge = { |     bridge = { | ||||||
|       bindAddress = "localhost"; |       bindAddress = "localhost"; | ||||||
|   | |||||||
							
								
								
									
										66
									
								
								hosts/bicep/services/matrix/out-of-your-element.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										66
									
								
								hosts/bicep/services/matrix/out-of-your-element.nix
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,66 @@ | |||||||
|  | { config, pkgs, fp, ... }: | ||||||
|  | let | ||||||
|  |   cfg = config.services.matrix-ooye; | ||||||
|  | in | ||||||
|  | { | ||||||
|  |   users.groups.keys-matrix-registrations = { }; | ||||||
|  |  | ||||||
|  |   sops.secrets = { | ||||||
|  |     "matrix/ooye/as_token" = { | ||||||
|  |       sopsFile = fp /secrets/bicep/matrix.yaml; | ||||||
|  |       key = "ooye/as_token"; | ||||||
|  |     }; | ||||||
|  |     "matrix/ooye/hs_token" = { | ||||||
|  |       sopsFile = fp /secrets/bicep/matrix.yaml; | ||||||
|  |       key = "ooye/hs_token"; | ||||||
|  |     }; | ||||||
|  |     "matrix/ooye/discord_token" = { | ||||||
|  |       sopsFile = fp /secrets/bicep/matrix.yaml; | ||||||
|  |       key = "ooye/discord_token"; | ||||||
|  |     }; | ||||||
|  |     "matrix/ooye/discord_client_secret" = { | ||||||
|  |       sopsFile = fp /secrets/bicep/matrix.yaml; | ||||||
|  |       key = "ooye/discord_client_secret"; | ||||||
|  |     }; | ||||||
|  |   }; | ||||||
|  |  | ||||||
|  |   services.matrix-ooye = { | ||||||
|  |     enable = true; | ||||||
|  |     homeserver = "https://matrix.pvv.ntnu.no"; | ||||||
|  |     homeserverName = "pvv.ntnu.no"; | ||||||
|  |     discordTokenPath = config.sops.secrets."matrix/ooye/discord_token".path; | ||||||
|  |     discordClientSecretPath = config.sops.secrets."matrix/ooye/discord_client_secret".path; | ||||||
|  |     bridgeOrigin = "https://ooye.pvv.ntnu.no"; | ||||||
|  |  | ||||||
|  |     enableSynapseIntegration = false; | ||||||
|  |   }; | ||||||
|  |  | ||||||
|  |   systemd.services."matrix-synapse" = { | ||||||
|  |     after = [ | ||||||
|  |       "matrix-ooye-pre-start.service" | ||||||
|  |       "network-online.target" | ||||||
|  |     ]; | ||||||
|  |     requires = [ "matrix-ooye-pre-start.service" ]; | ||||||
|  |     serviceConfig = { | ||||||
|  |       LoadCredential = [ | ||||||
|  |         "matrix-ooye-registration:/var/lib/matrix-ooye/registration.yaml" | ||||||
|  |       ]; | ||||||
|  |       ExecStartPre = [ | ||||||
|  |         "+${pkgs.coreutils}/bin/cp /run/credentials/matrix-synapse.service/matrix-ooye-registration ${config.services.matrix-synapse-next.dataDir}/ooye-registration.yaml" | ||||||
|  |         "+${pkgs.coreutils}/bin/chown matrix-synapse:keys-matrix-registrations ${config.services.matrix-synapse-next.dataDir}/ooye-registration.yaml" | ||||||
|  |       ]; | ||||||
|  |     }; | ||||||
|  |   }; | ||||||
|  |  | ||||||
|  |   services.matrix-synapse-next.settings = { | ||||||
|  |     app_service_config_files = [ | ||||||
|  |       "${config.services.matrix-synapse-next.dataDir}/ooye-registration.yaml" | ||||||
|  |     ]; | ||||||
|  |   }; | ||||||
|  |  | ||||||
|  |   services.nginx.virtualHosts."ooye.pvv.ntnu.no" = { | ||||||
|  |     forceSSL = true; | ||||||
|  |     enableACME = true; | ||||||
|  |     locations."/".proxyPass = "http://localhost:${cfg.socket}"; | ||||||
|  |   }; | ||||||
|  | } | ||||||
| @@ -1,46 +0,0 @@ | |||||||
| { config, fp, pkgs, values, ... }: |  | ||||||
| { |  | ||||||
|   imports = [ |  | ||||||
|       # Include the results of the hardware scan. |  | ||||||
|       ./hardware-configuration.nix |  | ||||||
|       (fp /base) |  | ||||||
|       (fp /misc/metrics-exporters.nix) |  | ||||||
|       ./disks.nix |  | ||||||
|  |  | ||||||
|       (fp /misc/builder.nix) |  | ||||||
|     ]; |  | ||||||
|  |  | ||||||
|   sops.defaultSopsFile = fp /secrets/bob/bob.yaml; |  | ||||||
|   sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; |  | ||||||
|   sops.age.keyFile = "/var/lib/sops-nix/key.txt"; |  | ||||||
|   sops.age.generateKey = true; |  | ||||||
|  |  | ||||||
|   boot.loader.grub = { |  | ||||||
|     enable = true; |  | ||||||
|     efiSupport = true; |  | ||||||
|     efiInstallAsRemovable = true; |  | ||||||
|   }; |  | ||||||
|  |  | ||||||
|   networking.hostName = "bob"; # Define your hostname. |  | ||||||
|  |  | ||||||
|   systemd.network.networks."30-all" = values.defaultNetworkConfig // { |  | ||||||
|     matchConfig.Name = "en*"; |  | ||||||
|     DHCP = "yes"; |  | ||||||
|     gateway = [ ]; |  | ||||||
|   }; |  | ||||||
|  |  | ||||||
|   # List packages installed in system profile |  | ||||||
|   environment.systemPackages = with pkgs; [ |  | ||||||
|   ]; |  | ||||||
|  |  | ||||||
|   # List services that you want to enable: |  | ||||||
|  |  | ||||||
|   # This value determines the NixOS release from which the default |  | ||||||
|   # settings for stateful data, like file locations and database versions |  | ||||||
|   # on your system were taken. It‘s perfectly fine and recommended to leave |  | ||||||
|   # this value at the release version of the first install of this system. |  | ||||||
|   # Before changing this value read the documentation for this option |  | ||||||
|   # (e.g. man configuration.nix or on https://nixos.org/nixos/options.html). |  | ||||||
|   system.stateVersion = "23.05"; # Did you read the comment? |  | ||||||
|  |  | ||||||
| } |  | ||||||
| @@ -1,39 +0,0 @@ | |||||||
| # Example to create a bios compatible gpt partition |  | ||||||
| { lib, ... }: |  | ||||||
| { |  | ||||||
|   disko.devices = { |  | ||||||
|     disk.disk1 = { |  | ||||||
|       device = lib.mkDefault "/dev/sda"; |  | ||||||
|       type = "disk"; |  | ||||||
|       content = { |  | ||||||
|         type = "gpt"; |  | ||||||
|         partitions = { |  | ||||||
|           boot = { |  | ||||||
|             name = "boot"; |  | ||||||
|             size = "1M"; |  | ||||||
|             type = "EF02"; |  | ||||||
|           }; |  | ||||||
|           esp = { |  | ||||||
|             name = "ESP"; |  | ||||||
|             size = "500M"; |  | ||||||
|             type = "EF00"; |  | ||||||
|             content = { |  | ||||||
|               type = "filesystem"; |  | ||||||
|               format = "vfat"; |  | ||||||
|               mountpoint = "/boot"; |  | ||||||
|             }; |  | ||||||
|           }; |  | ||||||
|           root = { |  | ||||||
|             name = "root"; |  | ||||||
|             size = "100%"; |  | ||||||
|             content = { |  | ||||||
|               type = "filesystem"; |  | ||||||
|               format = "ext4"; |  | ||||||
|               mountpoint = "/"; |  | ||||||
|             }; |  | ||||||
|           }; |  | ||||||
|         }; |  | ||||||
|       }; |  | ||||||
|     }; |  | ||||||
|   }; |  | ||||||
| } |  | ||||||
| @@ -8,7 +8,7 @@ | |||||||
|  |  | ||||||
|       (fp /modules/grzegorz.nix) |       (fp /modules/grzegorz.nix) | ||||||
|     ]; |     ]; | ||||||
|   services.spotifyd.enable = true; |  | ||||||
|   boot.loader.systemd-boot.enable = true; |   boot.loader.systemd-boot.enable = true; | ||||||
|   boot.loader.efi.canTouchEfiVariables = true; |   boot.loader.efi.canTouchEfiVariables = true; | ||||||
|  |  | ||||||
| @@ -25,6 +25,26 @@ | |||||||
|  |  | ||||||
|   # List services that you want to enable: |   # List services that you want to enable: | ||||||
|  |  | ||||||
|  |  | ||||||
|  |  | ||||||
|  |   services.spotifyd = { | ||||||
|  |     enable = true; | ||||||
|  |     settings.global = { | ||||||
|  |       device_name = "georg"; | ||||||
|  |       use_mpris = false; | ||||||
|  |       #dbus_type = "system"; | ||||||
|  |       #zeroconf_port = 1234; | ||||||
|  |     }; | ||||||
|  |   }; | ||||||
|  |  | ||||||
|  |   networking.firewall.allowedTCPPorts = [ | ||||||
|  |     # config.services.spotifyd.settings.zeroconf_port | ||||||
|  |     5353 # spotifyd is its own mDNS service wtf | ||||||
|  |   ]; | ||||||
|  |  | ||||||
|  |  | ||||||
|  |  | ||||||
|  |  | ||||||
|   # This value determines the NixOS release from which the default |   # This value determines the NixOS release from which the default | ||||||
|   # settings for stateful data, like file locations and database versions |   # settings for stateful data, like file locations and database versions | ||||||
|   # on your system were taken. It‘s perfectly fine and recommended to leave |   # on your system were taken. It‘s perfectly fine and recommended to leave | ||||||
|   | |||||||
							
								
								
									
										35
									
								
								hosts/lupine/configuration.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										35
									
								
								hosts/lupine/configuration.nix
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,35 @@ | |||||||
|  | { fp, values, lupineName, ... }: | ||||||
|  | { | ||||||
|  |   imports = [ | ||||||
|  |     ./hardware-configuration/${lupineName}.nix | ||||||
|  |  | ||||||
|  |     (fp /base) | ||||||
|  |     (fp /misc/metrics-exporters.nix) | ||||||
|  |  | ||||||
|  |     ./services/gitea-runner.nix | ||||||
|  |   ]; | ||||||
|  |  | ||||||
|  |   sops.defaultSopsFile = fp /secrets/lupine/lupine.yaml; | ||||||
|  |   sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ]; | ||||||
|  |   sops.age.keyFile = "/var/lib/sops-nix/key.txt"; | ||||||
|  |   sops.age.generateKey = true; | ||||||
|  |  | ||||||
|  |   boot.loader.systemd-boot.enable = true; | ||||||
|  |   boot.loader.efi.canTouchEfiVariables = true; | ||||||
|  |  | ||||||
|  |   systemd.network.networks."30-enp0s31f6" = values.defaultNetworkConfig // { | ||||||
|  |     matchConfig.Name = "enp0s31f6"; | ||||||
|  |     address = with values.hosts.${lupineName}; [ (ipv4 + "/25") (ipv6 + "/64") ]; | ||||||
|  |     networkConfig.LLDP = false; | ||||||
|  |   }; | ||||||
|  |   systemd.network.wait-online = { | ||||||
|  |     anyInterface = true; | ||||||
|  |   }; | ||||||
|  |  | ||||||
|  |   # There are no smart devices | ||||||
|  |   services.smartd.enable = false; | ||||||
|  |  | ||||||
|  |   # Do not change, even during upgrades. | ||||||
|  |   # See https://search.nixos.org/options?show=system.stateVersion | ||||||
|  |   system.stateVersion = "25.05"; | ||||||
|  | } | ||||||
							
								
								
									
										40
									
								
								hosts/lupine/hardware-configuration/lupine-1.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										40
									
								
								hosts/lupine/hardware-configuration/lupine-1.nix
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,40 @@ | |||||||
|  | # Do not modify this file!  It was generated by ‘nixos-generate-config’ | ||||||
|  | # and may be overwritten by future invocations.  Please make changes | ||||||
|  | # to /etc/nixos/configuration.nix instead. | ||||||
|  | { config, lib, pkgs, modulesPath, ... }: | ||||||
|  |  | ||||||
|  | { | ||||||
|  |   imports = | ||||||
|  |     [ (modulesPath + "/installer/scan/not-detected.nix") | ||||||
|  |     ]; | ||||||
|  |  | ||||||
|  |   boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "sd_mod" ]; | ||||||
|  |   boot.initrd.kernelModules = [ ]; | ||||||
|  |   boot.kernelModules = [ "kvm-intel" ]; | ||||||
|  |   boot.extraModulePackages = [ ]; | ||||||
|  |  | ||||||
|  |   fileSystems."/" = | ||||||
|  |     { device = "/dev/disk/by-uuid/a949e2e8-d973-4925-83e4-bcd815e65af7"; | ||||||
|  |       fsType = "ext4"; | ||||||
|  |     }; | ||||||
|  |  | ||||||
|  |   fileSystems."/boot" = | ||||||
|  |     { device = "/dev/disk/by-uuid/81D6-38D3"; | ||||||
|  |       fsType = "vfat"; | ||||||
|  |       options = [ "fmask=0077" "dmask=0077" ]; | ||||||
|  |     }; | ||||||
|  |  | ||||||
|  |   swapDevices = | ||||||
|  |     [ { device = "/dev/disk/by-uuid/82c2d7fa-7cd0-4398-8cf6-c892bc56264b"; } | ||||||
|  |     ]; | ||||||
|  |  | ||||||
|  |   # Enables DHCP on each ethernet and wireless interface. In case of scripted networking | ||||||
|  |   # (the default) this is the recommended approach. When using systemd-networkd it's | ||||||
|  |   # still possible to use this option, but it's recommended to use it in conjunction | ||||||
|  |   # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`. | ||||||
|  |   networking.useDHCP = lib.mkDefault true; | ||||||
|  |   # networking.interfaces.enp0s31f6.useDHCP = lib.mkDefault true; | ||||||
|  |  | ||||||
|  |   nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; | ||||||
|  |   hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; | ||||||
|  | } | ||||||
							
								
								
									
										40
									
								
								hosts/lupine/hardware-configuration/lupine-2.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										40
									
								
								hosts/lupine/hardware-configuration/lupine-2.nix
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,40 @@ | |||||||
|  | # Do not modify this file!  It was generated by ‘nixos-generate-config’ | ||||||
|  | # and may be overwritten by future invocations.  Please make changes | ||||||
|  | # to /etc/nixos/configuration.nix instead. | ||||||
|  | { config, lib, pkgs, modulesPath, ... }: | ||||||
|  |  | ||||||
|  | { | ||||||
|  |   imports = | ||||||
|  |     [ (modulesPath + "/installer/scan/not-detected.nix") | ||||||
|  |     ]; | ||||||
|  |  | ||||||
|  |   boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "sd_mod" ]; | ||||||
|  |   boot.initrd.kernelModules = [ ]; | ||||||
|  |   boot.kernelModules = [ "kvm-intel" ]; | ||||||
|  |   boot.extraModulePackages = [ ]; | ||||||
|  |  | ||||||
|  |   fileSystems."/" = | ||||||
|  |     { device = "/dev/disk/by-uuid/aa81d439-800b-403d-ac10-9d2aac3619d0"; | ||||||
|  |       fsType = "ext4"; | ||||||
|  |     }; | ||||||
|  |  | ||||||
|  |   fileSystems."/boot" = | ||||||
|  |     { device = "/dev/disk/by-uuid/4A34-6AE5"; | ||||||
|  |       fsType = "vfat"; | ||||||
|  |       options = [ "fmask=0077" "dmask=0077" ]; | ||||||
|  |     }; | ||||||
|  |  | ||||||
|  |   swapDevices = | ||||||
|  |     [ { device = "/dev/disk/by-uuid/efb7cd0c-c1ae-4a86-8bc2-8e7fd0066650"; } | ||||||
|  |     ]; | ||||||
|  |  | ||||||
|  |   # Enables DHCP on each ethernet and wireless interface. In case of scripted networking | ||||||
|  |   # (the default) this is the recommended approach. When using systemd-networkd it's | ||||||
|  |   # still possible to use this option, but it's recommended to use it in conjunction | ||||||
|  |   # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`. | ||||||
|  |   networking.useDHCP = lib.mkDefault true; | ||||||
|  |   # networking.interfaces.enp0s31f6.useDHCP = lib.mkDefault true; | ||||||
|  |  | ||||||
|  |   nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; | ||||||
|  |   hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; | ||||||
|  | } | ||||||
							
								
								
									
										40
									
								
								hosts/lupine/hardware-configuration/lupine-3.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										40
									
								
								hosts/lupine/hardware-configuration/lupine-3.nix
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,40 @@ | |||||||
|  | # Do not modify this file!  It was generated by ‘nixos-generate-config’ | ||||||
|  | # and may be overwritten by future invocations.  Please make changes | ||||||
|  | # to /etc/nixos/configuration.nix instead. | ||||||
|  | { config, lib, pkgs, modulesPath, ... }: | ||||||
|  |  | ||||||
|  | { | ||||||
|  |   imports = | ||||||
|  |     [ (modulesPath + "/installer/scan/not-detected.nix") | ||||||
|  |     ]; | ||||||
|  |  | ||||||
|  |   boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "sd_mod" ]; | ||||||
|  |   boot.initrd.kernelModules = [ ]; | ||||||
|  |   boot.kernelModules = [ "kvm-intel" ]; | ||||||
|  |   boot.extraModulePackages = [ ]; | ||||||
|  |  | ||||||
|  |   fileSystems."/" = | ||||||
|  |     { device = "/dev/disk/by-uuid/39ba059b-3205-4701-a832-e72c0122cb88"; | ||||||
|  |       fsType = "ext4"; | ||||||
|  |     }; | ||||||
|  |  | ||||||
|  |   fileSystems."/boot" = | ||||||
|  |     { device = "/dev/disk/by-uuid/63FA-297B"; | ||||||
|  |       fsType = "vfat"; | ||||||
|  |       options = [ "fmask=0077" "dmask=0077" ]; | ||||||
|  |     }; | ||||||
|  |  | ||||||
|  |   swapDevices = | ||||||
|  |     [ { device = "/dev/disk/by-uuid/9c72eb54-ea8c-4b09-808a-8be9b9a33869"; } | ||||||
|  |     ]; | ||||||
|  |  | ||||||
|  |   # Enables DHCP on each ethernet and wireless interface. In case of scripted networking | ||||||
|  |   # (the default) this is the recommended approach. When using systemd-networkd it's | ||||||
|  |   # still possible to use this option, but it's recommended to use it in conjunction | ||||||
|  |   # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`. | ||||||
|  |   networking.useDHCP = lib.mkDefault true; | ||||||
|  |   # networking.interfaces.enp0s31f6.useDHCP = lib.mkDefault true; | ||||||
|  |  | ||||||
|  |   nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; | ||||||
|  |   hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; | ||||||
|  | } | ||||||
| @@ -5,20 +5,30 @@ | |||||||
| 
 | 
 | ||||||
| { | { | ||||||
|   imports = |   imports = | ||||||
|     [ (modulesPath + "/profiles/qemu-guest.nix") |     [ (modulesPath + "/installer/scan/not-detected.nix") | ||||||
|     ]; |     ]; | ||||||
| 
 | 
 | ||||||
|   boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_blk" ]; |   boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "sd_mod" ]; | ||||||
|   boot.initrd.kernelModules = [ ]; |   boot.initrd.kernelModules = [ ]; | ||||||
|   boot.kernelModules = [ ]; |   boot.kernelModules = [ "kvm-intel" ]; | ||||||
|   boot.extraModulePackages = [ ]; |   boot.extraModulePackages = [ ]; | ||||||
| 
 | 
 | ||||||
|  |   fileSystems."/" = | ||||||
|  |     { device = "/dev/disk/by-uuid/c7bbb293-a0a3-4995-8892-0ec63e8c67dd"; | ||||||
|  |       fsType = "ext4"; | ||||||
|  |     }; | ||||||
|  | 
 | ||||||
|  |   swapDevices = | ||||||
|  |     [ { device = "/dev/disk/by-uuid/a86ffda8-8ecb-42a1-bf9f-926072e90ca5"; } | ||||||
|  |     ]; | ||||||
|  | 
 | ||||||
|   # Enables DHCP on each ethernet and wireless interface. In case of scripted networking |   # Enables DHCP on each ethernet and wireless interface. In case of scripted networking | ||||||
|   # (the default) this is the recommended approach. When using systemd-networkd it's |   # (the default) this is the recommended approach. When using systemd-networkd it's | ||||||
|   # still possible to use this option, but it's recommended to use it in conjunction |   # still possible to use this option, but it's recommended to use it in conjunction | ||||||
|   # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`. |   # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`. | ||||||
|   networking.useDHCP = lib.mkDefault true; |   networking.useDHCP = lib.mkDefault true; | ||||||
|   # networking.interfaces.ens3.useDHCP = lib.mkDefault true; |   # networking.interfaces.enp0s31f6.useDHCP = lib.mkDefault true; | ||||||
| 
 | 
 | ||||||
|   nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; |   nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; | ||||||
|  |   hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; | ||||||
| } | } | ||||||
							
								
								
									
										40
									
								
								hosts/lupine/hardware-configuration/lupine-5.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										40
									
								
								hosts/lupine/hardware-configuration/lupine-5.nix
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,40 @@ | |||||||
|  | # Do not modify this file!  It was generated by ‘nixos-generate-config’ | ||||||
|  | # and may be overwritten by future invocations.  Please make changes | ||||||
|  | # to /etc/nixos/configuration.nix instead. | ||||||
|  | { config, lib, pkgs, modulesPath, ... }: | ||||||
|  |  | ||||||
|  | { | ||||||
|  |   imports = | ||||||
|  |     [ (modulesPath + "/installer/scan/not-detected.nix") | ||||||
|  |     ]; | ||||||
|  |  | ||||||
|  |   boot.initrd.availableKernelModules = [ "xhci_pci" "ahci" "usbhid" "sd_mod" ]; | ||||||
|  |   boot.initrd.kernelModules = [ ]; | ||||||
|  |   boot.kernelModules = [ "kvm-intel" ]; | ||||||
|  |   boot.extraModulePackages = [ ]; | ||||||
|  |  | ||||||
|  |   fileSystems."/" = | ||||||
|  |     { device = "/dev/disk/by-uuid/5f8418ad-8ec1-4f9e-939e-f3a4c36ef343"; | ||||||
|  |       fsType = "ext4"; | ||||||
|  |     }; | ||||||
|  |  | ||||||
|  |   fileSystems."/boot" = | ||||||
|  |     { device = "/dev/disk/by-uuid/F372-37DF"; | ||||||
|  |       fsType = "vfat"; | ||||||
|  |       options = [ "fmask=0077" "dmask=0077" ]; | ||||||
|  |     }; | ||||||
|  |  | ||||||
|  |   swapDevices = | ||||||
|  |     [ { device = "/dev/disk/by-uuid/27bf292d-bbb3-48c4-a86e-456e0f1f648f"; } | ||||||
|  |     ]; | ||||||
|  |  | ||||||
|  |   # Enables DHCP on each ethernet and wireless interface. In case of scripted networking | ||||||
|  |   # (the default) this is the recommended approach. When using systemd-networkd it's | ||||||
|  |   # still possible to use this option, but it's recommended to use it in conjunction | ||||||
|  |   # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`. | ||||||
|  |   networking.useDHCP = lib.mkDefault true; | ||||||
|  |   # networking.interfaces.enp0s31f6.useDHCP = lib.mkDefault true; | ||||||
|  |  | ||||||
|  |   nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; | ||||||
|  |   hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; | ||||||
|  | } | ||||||
							
								
								
									
										45
									
								
								hosts/lupine/services/gitea-runner.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										45
									
								
								hosts/lupine/services/gitea-runner.nix
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,45 @@ | |||||||
|  | { config, lupineName, ... }: | ||||||
|  | { | ||||||
|  |   # This is unfortunately state, and has to be generated one at a time :( | ||||||
|  |   # To do that, comment out all except one of the runners, fill in its token | ||||||
|  |   # inside the sops file, rebuild the system, and only after this runner has | ||||||
|  |   # successfully registered will gitea give you the next token. | ||||||
|  |   # - oysteikt Sep 2023 | ||||||
|  |   sops = { | ||||||
|  |     secrets."gitea/runners/token" = { | ||||||
|  |       key = "gitea/runners/${lupineName}"; | ||||||
|  |     }; | ||||||
|  |  | ||||||
|  |     templates."gitea-runner-envfile" = { | ||||||
|  |       restartUnits = [ | ||||||
|  |         "gitea-runner-${lupineName}.service" | ||||||
|  |       ]; | ||||||
|  |       content = '' | ||||||
|  |         TOKEN="${config.sops.placeholder."gitea/runners/token"}" | ||||||
|  |       ''; | ||||||
|  |     }; | ||||||
|  |   }; | ||||||
|  |  | ||||||
|  |   services.gitea-actions-runner.instances = { | ||||||
|  |     ${lupineName} = { | ||||||
|  |       enable = true; | ||||||
|  |       name = "git-runner-${lupineName}"; | ||||||
|  |       url = "https://git.pvv.ntnu.no"; | ||||||
|  |       labels = [ | ||||||
|  |         "debian-latest:docker://node:current-bookworm" | ||||||
|  |         "ubuntu-latest:docker://node:current-bookworm" | ||||||
|  |       ]; | ||||||
|  |       tokenFile = config.sops.templates."gitea-runner-envfile".path; | ||||||
|  |     }; | ||||||
|  |   }; | ||||||
|  |  | ||||||
|  |   virtualisation.podman = { | ||||||
|  |     enable = true; | ||||||
|  |     defaultNetwork.settings.dns_enabled = true; | ||||||
|  |     autoPrune.enable = true; | ||||||
|  |   }; | ||||||
|  |  | ||||||
|  |   networking.dhcpcd.IPv6rs = false; | ||||||
|  |  | ||||||
|  |   networking.firewall.interfaces."podman+".allowedUDPPorts = [53 5353]; | ||||||
|  | } | ||||||
| @@ -46,6 +46,15 @@ in { | |||||||
|         allow 2001:700:300:1900::/64; |         allow 2001:700:300:1900::/64; | ||||||
|         deny all; |         deny all; | ||||||
|       ''; |       ''; | ||||||
|  |  | ||||||
|  |       locations."/docs" = { | ||||||
|  |         proxyPass = "http://${grg.settings.host}:${toString grg.settings.port}"; | ||||||
|  |       }; | ||||||
|  |  | ||||||
|  |       locations."/api" = { | ||||||
|  |         proxyPass = "http://${grg.settings.host}:${toString grg.settings.port}"; | ||||||
|  |         proxyWebsockets = true; | ||||||
|  |       }; | ||||||
|     }; |     }; | ||||||
|  |  | ||||||
|     "${machine}-backend.pvv.ntnu.no" = { |     "${machine}-backend.pvv.ntnu.no" = { | ||||||
|   | |||||||
							
								
								
									
										211
									
								
								modules/matrix-ooye.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										211
									
								
								modules/matrix-ooye.nix
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,211 @@ | |||||||
|  | # Original from: https://cgit.rory.gay/nix/OOYE-module.git/ | ||||||
|  |  | ||||||
|  | { | ||||||
|  |   config, | ||||||
|  |   lib, | ||||||
|  |   pkgs, | ||||||
|  |   ... | ||||||
|  | }: | ||||||
|  | let | ||||||
|  |   cfg = config.services.matrix-ooye; | ||||||
|  |   mkStringOption = | ||||||
|  |     name: default: | ||||||
|  |     lib.mkOption { | ||||||
|  |       type = lib.types.str; | ||||||
|  |       default = default; | ||||||
|  |     }; | ||||||
|  | in | ||||||
|  | { | ||||||
|  |   options = { | ||||||
|  |     services.matrix-ooye = { | ||||||
|  |       enable = lib.mkEnableOption "Enable OOYE service"; | ||||||
|  |       package = lib.mkOption { | ||||||
|  |         type = lib.types.package; | ||||||
|  |         default = pkgs.out-of-your-element; | ||||||
|  |       }; | ||||||
|  |       appserviceId = mkStringOption "The ID of the appservice." "ooye"; | ||||||
|  |       homeserver = mkStringOption "The homeserver to connect to." "http://localhost:8006"; | ||||||
|  |       homeserverName = mkStringOption "The name of the homeserver to connect to." "localhost"; | ||||||
|  |       namespace = mkStringOption "The prefix to use for the MXIDs/aliases of bridged users/rooms. Should end with a _!" "_ooye_"; | ||||||
|  |       discordTokenPath = mkStringOption "The path to the discord token file." "/etc/ooye-discord-token"; | ||||||
|  |       discordClientSecretPath = mkStringOption "The path to the discord token file." "/etc/ooye-discord-client-secret"; | ||||||
|  |       socket = mkStringOption "The socket to listen on, can either be a port number or a unix socket path." "6693"; | ||||||
|  |       bridgeOrigin = mkStringOption "The web frontend URL for the bridge, defaults to http://localhost:{socket}" ""; | ||||||
|  |  | ||||||
|  |       enableSynapseIntegration = lib.mkEnableOption "Enable Synapse integration"; | ||||||
|  |     }; | ||||||
|  |   }; | ||||||
|  |   config = lib.mkIf cfg.enable ( | ||||||
|  |     let | ||||||
|  |       baseConfig = pkgs.writeText "matrix-ooye-config.json" ( | ||||||
|  |         builtins.toJSON { | ||||||
|  |           id = cfg.appserviceId; | ||||||
|  |           namespaces = { | ||||||
|  |             users = [ | ||||||
|  |               { | ||||||
|  |                 exclusive = true; | ||||||
|  |                 regex = "@${cfg.namespace}.*:${cfg.homeserverName}"; | ||||||
|  |               } | ||||||
|  |             ]; | ||||||
|  |             aliases = [ | ||||||
|  |               { | ||||||
|  |                 exclusive = true; | ||||||
|  |                 regex = "#${cfg.namespace}.*:${cfg.homeserverName}"; | ||||||
|  |               } | ||||||
|  |             ]; | ||||||
|  |           }; | ||||||
|  |           protocols = [ "discord" ]; | ||||||
|  |           sender_localpart = "${cfg.namespace}bot"; | ||||||
|  |           rate_limited = false; | ||||||
|  |           socket = cfg.socket; # Can either be a TCP port or a unix socket path | ||||||
|  |           url = if (lib.hasPrefix "/" cfg.socket) then "unix:${cfg.socket}" else "http://localhost:${cfg.socket}"; | ||||||
|  |           ooye = { | ||||||
|  |             server_name = cfg.homeserverName; | ||||||
|  |             namespace_prefix = cfg.namespace; | ||||||
|  |             max_file_size = 5000000; | ||||||
|  |             content_length_workaround = false; | ||||||
|  |             include_user_id_in_mxid = true; | ||||||
|  |             server_origin = cfg.homeserver; | ||||||
|  |             bridge_origin = if (cfg.bridgeOrigin == "") then "http://localhost:${cfg.socket}" else cfg.bridgeOrigin; | ||||||
|  |           }; | ||||||
|  |         } | ||||||
|  |       ); | ||||||
|  |  | ||||||
|  |       script = pkgs.writeScript "matrix-ooye-pre-start.sh" '' | ||||||
|  |         #!${lib.getExe pkgs.bash} | ||||||
|  |         REGISTRATION_FILE=registration.yaml | ||||||
|  |  | ||||||
|  |         id | ||||||
|  |         echo "Before if statement" | ||||||
|  |         stat ''${REGISTRATION_FILE} | ||||||
|  |  | ||||||
|  |         if [[ ! -f ''${REGISTRATION_FILE} ]]; then | ||||||
|  |           echo "No registration file found at '$REGISTRATION_FILE'" | ||||||
|  |           cp --no-preserve=mode,ownership ${baseConfig} ''${REGISTRATION_FILE} | ||||||
|  |         fi | ||||||
|  |  | ||||||
|  |         echo "After if statement" | ||||||
|  |         stat ''${REGISTRATION_FILE} | ||||||
|  |  | ||||||
|  |         AS_TOKEN=$(${lib.getExe pkgs.jq} -r .as_token ''${REGISTRATION_FILE}) | ||||||
|  |         HS_TOKEN=$(${lib.getExe pkgs.jq} -r .hs_token ''${REGISTRATION_FILE}) | ||||||
|  |         DISCORD_TOKEN=$(cat /run/credentials/matrix-ooye-pre-start.service/discord_token) | ||||||
|  |         DISCORD_CLIENT_SECRET=$(cat /run/credentials/matrix-ooye-pre-start.service/discord_client_secret) | ||||||
|  |  | ||||||
|  |         # Check if we have all required tokens | ||||||
|  |         if [[ -z "$AS_TOKEN" || "$AS_TOKEN" == "null" ]]; then | ||||||
|  |           AS_TOKEN=$(${lib.getExe pkgs.openssl} rand -hex 64) | ||||||
|  |           echo "Generated new AS token: ''${AS_TOKEN}" | ||||||
|  |         fi | ||||||
|  |  | ||||||
|  |         if [[ -z "$HS_TOKEN" || "$HS_TOKEN" == "null" ]]; then | ||||||
|  |           HS_TOKEN=$(${lib.getExe pkgs.openssl} rand -hex 64) | ||||||
|  |           echo "Generated new HS token: ''${HS_TOKEN}" | ||||||
|  |         fi | ||||||
|  |  | ||||||
|  |         if [[ -z "$DISCORD_TOKEN" ]]; then | ||||||
|  |           echo "No Discord token found at '${cfg.discordTokenPath}'" | ||||||
|  |           echo "You can find this on the 'Bot' tab of your Discord application." | ||||||
|  |           exit 1 | ||||||
|  |         fi | ||||||
|  |  | ||||||
|  |         if [[ -z "$DISCORD_CLIENT_SECRET" ]]; then | ||||||
|  |           echo "No Discord client secret found at '${cfg.discordTokenPath}'" | ||||||
|  |           echo "You can find this on the 'OAuth2' tab of your Discord application." | ||||||
|  |           exit 1 | ||||||
|  |         fi | ||||||
|  |  | ||||||
|  |         shred -u ''${REGISTRATION_FILE} | ||||||
|  |         cp --no-preserve=mode,ownership ${baseConfig} ''${REGISTRATION_FILE} | ||||||
|  |  | ||||||
|  |         ${lib.getExe pkgs.jq} '.as_token = "'$AS_TOKEN'" | .hs_token = "'$HS_TOKEN'" | .ooye.discord_token = "'$DISCORD_TOKEN'" | .ooye.discord_client_secret = "'$DISCORD_CLIENT_SECRET'"' ''${REGISTRATION_FILE} > ''${REGISTRATION_FILE}.tmp | ||||||
|  |  | ||||||
|  |         shred -u ''${REGISTRATION_FILE} | ||||||
|  |         mv ''${REGISTRATION_FILE}.tmp ''${REGISTRATION_FILE} | ||||||
|  |       ''; | ||||||
|  |  | ||||||
|  |     in | ||||||
|  |     { | ||||||
|  |       warnings = | ||||||
|  |         lib.optionals ((builtins.substring (lib.stringLength cfg.namespace - 1) 1 cfg.namespace) != "_") [ | ||||||
|  |           "OOYE namespace does not end with an underscore! This is recommended to have better ID formatting. Provided: '${cfg.namespace}'" | ||||||
|  |         ] | ||||||
|  |         ++ lib.optionals ((builtins.substring 0 1 cfg.namespace) != "_") [ | ||||||
|  |           "OOYE namespace does not start with an underscore! This is recommended to avoid conflicts with registered users. Provided: '${cfg.namespace}'" | ||||||
|  |         ]; | ||||||
|  |  | ||||||
|  |       environment.systemPackages = [ cfg.package ]; | ||||||
|  |  | ||||||
|  |       systemd.services."matrix-ooye-pre-start" = { | ||||||
|  |         enable = true; | ||||||
|  |         wantedBy = [ "multi-user.target" ]; | ||||||
|  |         serviceConfig = { | ||||||
|  |           ExecStart = script; | ||||||
|  |           WorkingDirectory = "/var/lib/matrix-ooye"; | ||||||
|  |           StateDirectory = "matrix-ooye"; | ||||||
|  |           DynamicUser = true; | ||||||
|  |           RemainAfterExit = true; | ||||||
|  |           Type = "oneshot"; | ||||||
|  |  | ||||||
|  |           LoadCredential = [ | ||||||
|  |             "discord_token:${cfg.discordTokenPath}" | ||||||
|  |             "discord_client_secret:${cfg.discordClientSecretPath}" | ||||||
|  |           ]; | ||||||
|  |         }; | ||||||
|  |       }; | ||||||
|  |  | ||||||
|  |       systemd.services."matrix-ooye" = { | ||||||
|  |         enable = true; | ||||||
|  |         description = "Out of Your Element - a Discord bridge for Matrix."; | ||||||
|  |  | ||||||
|  |         wants = [ | ||||||
|  |           "network-online.target" | ||||||
|  |           "matrix-synapse.service" | ||||||
|  |           "conduit.service" | ||||||
|  |           "dendrite.service" | ||||||
|  |         ]; | ||||||
|  |         after = [ | ||||||
|  |           "matrix-ooye-pre-start.service" | ||||||
|  |           "network-online.target" | ||||||
|  |         ]; | ||||||
|  |         requires = [ "matrix-ooye-pre-start.service" ]; | ||||||
|  |         wantedBy = [ "multi-user.target" ]; | ||||||
|  |  | ||||||
|  |         serviceConfig = { | ||||||
|  |           ExecStart = lib.getExe config.services.matrix-ooye.package; | ||||||
|  |           WorkingDirectory = "/var/lib/matrix-ooye"; | ||||||
|  |           StateDirectory = "matrix-ooye"; | ||||||
|  |           #ProtectSystem = "strict"; | ||||||
|  |           #ProtectHome = true; | ||||||
|  |           #PrivateTmp = true; | ||||||
|  |           #NoNewPrivileges = true; | ||||||
|  |           #PrivateDevices = true; | ||||||
|  |           Restart = "on-failure"; | ||||||
|  |           DynamicUser = true; | ||||||
|  |         }; | ||||||
|  |       }; | ||||||
|  |  | ||||||
|  |       systemd.services."matrix-synapse" = lib.mkIf cfg.enableSynapseIntegration { | ||||||
|  |  | ||||||
|  |         after = [ | ||||||
|  |           "matrix-ooye-pre-start.service" | ||||||
|  |           "network-online.target" | ||||||
|  |         ]; | ||||||
|  |         requires = [ "matrix-ooye-pre-start.service" ]; | ||||||
|  |         serviceConfig = { | ||||||
|  |           LoadCredential = [ | ||||||
|  |             "matrix-ooye-registration:/var/lib/matrix-ooye/registration.yaml" | ||||||
|  |           ]; | ||||||
|  |           ExecStartPre = [ | ||||||
|  |             "+${pkgs.coreutils}/bin/cp /run/credentials/matrix-synapse.service/matrix-ooye-registration ${config.services.matrix-synapse.dataDir}/ooye-registration.yaml" | ||||||
|  |             "+${pkgs.coreutils}/bin/chown matrix-synapse:matrix-synapse ${config.services.matrix-synapse.dataDir}/ooye-registration.yaml" | ||||||
|  |           ]; | ||||||
|  |         }; | ||||||
|  |       }; | ||||||
|  |  | ||||||
|  |       services.matrix-synapse.settings.app_service_config_files = lib.mkIf cfg.enableSynapseIntegration [ | ||||||
|  |         "${config.services.matrix-synapse.dataDir}/ooye-registration.yaml" | ||||||
|  |       ]; | ||||||
|  |     } | ||||||
|  |   ); | ||||||
|  | } | ||||||
							
								
								
									
										42
									
								
								packages/out-of-your-element.nix
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										42
									
								
								packages/out-of-your-element.nix
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,42 @@ | |||||||
|  | { | ||||||
|  |   lib, | ||||||
|  |   fetchgit, | ||||||
|  |   makeWrapper, | ||||||
|  |   nodejs, | ||||||
|  |   buildNpmPackage, | ||||||
|  | }: | ||||||
|  | buildNpmPackage { | ||||||
|  |   pname = "delete-your-element"; | ||||||
|  |   version = "3.1-unstable-2025-06-23"; | ||||||
|  |   src = fetchgit { | ||||||
|  |     url = "https://git.pvv.ntnu.no/Drift/delete-your-element.git"; | ||||||
|  |     rev = "67658bf68026918163a2e5c2a30007364c9b2d2d"; | ||||||
|  |     sha256 = "sha256-jSQ588kwvAYCe6ogmO+jDB6Hi3ACJ/3+rC8M94OVMNw="; | ||||||
|  |   }; | ||||||
|  |   npmDepsHash = "sha256-HNHEGez8X7CsoGYXqzB49o1pcCImfmGYIw9QKF2SbHo="; | ||||||
|  |   dontNpmBuild = true; | ||||||
|  |  | ||||||
|  |   nativeBuildInputs = [makeWrapper]; | ||||||
|  |  | ||||||
|  |   installPhase = '' | ||||||
|  |     runHook preInstall | ||||||
|  |  | ||||||
|  |     mkdir -p $out/share | ||||||
|  |     cp -a . $out/share/ooye | ||||||
|  |     makeWrapper ${nodejs}/bin/node $out/bin/matrix-ooye --add-flags $out/share/ooye/start.js | ||||||
|  |     makeWrapper ${nodejs}/bin/node $out/bin/matrix-ooye-addbot --add-flags $out/share/ooye/addbot.js | ||||||
|  |  | ||||||
|  |     runHook postInstall | ||||||
|  |   ''; | ||||||
|  |  | ||||||
|  |   meta = with lib; { | ||||||
|  |     description = "Matrix-Discord bridge with modern features."; | ||||||
|  |     homepage = "https://gitdab.com/cadence/out-of-your-element"; | ||||||
|  |     longDescription = '' | ||||||
|  |       Modern Matrix-to-Discord appservice bridge, created by @cadence:cadence.moe. | ||||||
|  |     ''; | ||||||
|  |     license = licenses.gpl3; | ||||||
|  |     # maintainers = with maintainers; [ RorySys ]; | ||||||
|  |     mainProgram = "matrix-ooye"; | ||||||
|  |   }; | ||||||
|  | } | ||||||
| @@ -9,14 +9,15 @@ mjolnir: | |||||||
| discord: | discord: | ||||||
|     as_token: ENC[AES256_GCM,data:cnPZjBbODZUA1p0kLNeWpKh1oGkDPxDw/g7163XnoRCIgpqk,iv:Uu4L36uDPMBgzdXE2Lt9U0qrBSl3Xuufh1313BD8B/U=,tag:nTm6s7IGd4vNzZ95mfxDpA==,type:str] |     as_token: ENC[AES256_GCM,data:cnPZjBbODZUA1p0kLNeWpKh1oGkDPxDw/g7163XnoRCIgpqk,iv:Uu4L36uDPMBgzdXE2Lt9U0qrBSl3Xuufh1313BD8B/U=,tag:nTm6s7IGd4vNzZ95mfxDpA==,type:str] | ||||||
|     hs_token: ENC[AES256_GCM,data:UzcaNsJtJPKvFT4gQDNfat0nmyJzmQ6OcSI73pANibzOVrWl,iv:ujgRM2jb1rbeloPB4UPLBEvQ7uue4a+bHiqsZAHIqtk=,tag:uIfuaTWSTeVvpQx5o28HPA==,type:str] |     hs_token: ENC[AES256_GCM,data:UzcaNsJtJPKvFT4gQDNfat0nmyJzmQ6OcSI73pANibzOVrWl,iv:ujgRM2jb1rbeloPB4UPLBEvQ7uue4a+bHiqsZAHIqtk=,tag:uIfuaTWSTeVvpQx5o28HPA==,type:str] | ||||||
|  | ooye: | ||||||
|  |     hs_token: ENC[AES256_GCM,data:QBrdRt4ozAh2XYJtssm82uHlk9aGO1Nr0fEZetmWfLvmw52FZEq8ijyKOgwS6uTcndMi4gGKkq9r4eapLwcMdQ==,iv:VHOAqxR1WGzZ9dmNx+FmjGAKRpUFjWOwyOVmgDswpE0=,tag:k5it/yx7pOfGbJXZUlV69Q==,type:str] | ||||||
|  |     as_token: ENC[AES256_GCM,data:RMkY0xVj14FwDbYaAysSmzB0IlJuk0ucicNhhTmVAEgiU05PxWG+qk3/elFcaFwaXRFgQQtVyGFZEcK5gpE9hA==,iv:8JgNrTe7GQqPMdUCxEaxJ9qV7Uec2fkYBmF9LmH4X3o=,tag:tRnFpRAZs9kO3u2SDMwNnA==,type:str] | ||||||
|  |     discord_token: ENC[AES256_GCM,data:6rzv3glW03jcYiJ7sAvDcvDmQHs9iVbV11tIFwgD3GuTkVn6mbAoQhjUaz3zpb/OeoGt+j/pCBRlZgk=,iv:JwkqLpeGYhgwLX7SACNh0AUO53XSx9IKgncI0+KkvyU=,tag:30C0X9nVSlEYPITVzuN0qA==,type:str] | ||||||
|  |     discord_client_secret: ENC[AES256_GCM,data:wbM7bPZCWa2+UNUqXi27fP0ppdinRkEC4N9KB68TJzg=,iv:Y2j+8oI+kI7DMrBfFU3G5HtFWguNxDpxbNvJkpK5lQs=,tag:GntocbTCybCVqZ2T3lNSIQ==,type:str] | ||||||
| hookshot: | hookshot: | ||||||
|     as_token: ENC[AES256_GCM,data:L4vEw5r4RhcgritOeDTLHN5E/dM=,iv:pC8BLzxf6NaVAGsotoq6chOceBVdMLvrsQn1LGw9H9w=,tag:SI3CDFHAvgQZEvf/oms3EA==,type:str] |     as_token: ENC[AES256_GCM,data:L4vEw5r4RhcgritOeDTLHN5E/dM=,iv:pC8BLzxf6NaVAGsotoq6chOceBVdMLvrsQn1LGw9H9w=,tag:SI3CDFHAvgQZEvf/oms3EA==,type:str] | ||||||
|     hs_token: ENC[AES256_GCM,data:2ufSJfYzzAB5IO+edwKSra5d/+M=,iv:cmTycGzNL+IeRRKZGbkhTtiksYTtbxED0k0B5haFw7k=,tag:FmWe5sGi9rlapUeAE6lKvg==,type:str] |     hs_token: ENC[AES256_GCM,data:2ufSJfYzzAB5IO+edwKSra5d/+M=,iv:cmTycGzNL+IeRRKZGbkhTtiksYTtbxED0k0B5haFw7k=,tag:FmWe5sGi9rlapUeAE6lKvg==,type:str] | ||||||
| sops: | sops: | ||||||
|     kms: [] |  | ||||||
|     gcp_kms: [] |  | ||||||
|     azure_kv: [] |  | ||||||
|     hc_vault: [] |  | ||||||
|     age: |     age: | ||||||
|         - recipient: age1sl43gc9cw939z5tgha2lpwf0xxxgcnlw7w4xem4sqgmt2pt264vq0dmwx2 |         - recipient: age1sl43gc9cw939z5tgha2lpwf0xxxgcnlw7w4xem4sqgmt2pt264vq0dmwx2 | ||||||
|           enc: | |           enc: | | ||||||
| @@ -72,8 +73,8 @@ sops: | |||||||
|             WEh5NFN6SFF1TlltdWFWTGw4MHRHUkUKrKIvC87xjEmwxPQhH8dN+ZuaJTCgPY28 |             WEh5NFN6SFF1TlltdWFWTGw4MHRHUkUKrKIvC87xjEmwxPQhH8dN+ZuaJTCgPY28 | ||||||
|             pR62KxmoKFICLTHPpYP3euiAx5M9BWvgvCnA/US/5klpk8MtlreNFA== |             pR62KxmoKFICLTHPpYP3euiAx5M9BWvgvCnA/US/5klpk8MtlreNFA== | ||||||
|             -----END AGE ENCRYPTED FILE----- |             -----END AGE ENCRYPTED FILE----- | ||||||
|     lastmodified: "2024-10-13T23:30:01Z" |     lastmodified: "2025-06-21T21:23:24Z" | ||||||
|     mac: ENC[AES256_GCM,data:vdsAZmg7gPqzeucBhLhPemtRVkcxRecIdB6PXZ4paU+Uv5UorBKcTZ3jseN2cLi6ot3ycTIm+UI6uhlCy87vAJVynVJhuJS+ICFRS2+DfoVyuttLjZQGC2sr3+dEBHxIH7sZJSo9PIzbIWw3qHrpOPAZj0//1pFyp/k15k3vidM=,iv:jWtV+WAPt08lgdrVvtXOl35rDB4QflkZWuGBW1+ESyw=,tag:YxSHncZZOAW5uDxXtb/krw==,type:str] |     mac: ENC[AES256_GCM,data:bEJoCzxph/MOnTOJKdrRiQmbVWmAgsKy8vbD5YBeWagWUCJPDAZNDFLzEzmPvt0jDBol04JosrSIKZS1JzJIIm0zRkcOWSqERQCgjgtGdAYmfp0V6ddseDUVfKlZYJDkt6Bdkqg+9LzrP8dDVm2tMDXpo8vzs02o9dTYFm7imVQ=,iv:buP/297JMfvEm9+IdMWRGV7AgZwF0+G6Z2YIeYw/z1o=,tag:+zG612MJA4Ui8CZBgxM+AQ==,type:str] | ||||||
|     pgp: |     pgp: | ||||||
|         - created_at: "2024-08-04T00:03:46Z" |         - created_at: "2024-08-04T00:03:46Z" | ||||||
|           enc: |- |           enc: |- | ||||||
| @@ -96,4 +97,4 @@ sops: | |||||||
|             -----END PGP MESSAGE----- |             -----END PGP MESSAGE----- | ||||||
|           fp: F7D37890228A907440E1FD4846B9228E814A2AAC |           fp: F7D37890228A907440E1FD4846B9228E814A2AAC | ||||||
|     unencrypted_suffix: _unencrypted |     unencrypted_suffix: _unencrypted | ||||||
|     version: 3.8.1 |     version: 3.10.2 | ||||||
|   | |||||||
							
								
								
									
										124
									
								
								secrets/lupine/lupine.yaml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										124
									
								
								secrets/lupine/lupine.yaml
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,124 @@ | |||||||
|  | gitea: | ||||||
|  |     runners: | ||||||
|  |         lupine-1: ENC[AES256_GCM,data:UcZB2p/dInvcl0yNBEohzbmcVxg/QQPXlIsaVB3M3hyxFg1gtGfUGA==,iv:OigyPfPoRIjvyiId7hiiWdNrZqyZqI3OonvJC+zYEzI=,tag:SjBsvo/IJKhFQs+PiI596g==,type:str] | ||||||
|  |         lupine-2: null | ||||||
|  |         lupine-3: null | ||||||
|  |         lupine-4: null | ||||||
|  |         lupine-5: null | ||||||
|  | sops: | ||||||
|  |     age: | ||||||
|  |         - recipient: age1fkrypl6fu4ldsa7te4g3v4qsegnk7sd6qhkquuwzh04vguy96qus08902e | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBncnd2NVdqdjU1WWx4YWJr | ||||||
|  |             RUVuSThBWWdyVnpFT0kzZjBrVjZiN1FiU0ZBCmNCbGVZK09YaFNGSUE2QWpidEFw | ||||||
|  |             aEZEVndkODRzYmNLWDRzSGMzOWZKajAKLS0tIE00b3NiclFrOEk3R1lkeWM0VHY3 | ||||||
|  |             dUFQcG04bWNwYjRjTlNWV0pXNnlTN28KEc8nM7jzMuh2B6Q9vDS9apmVZDH9fAGi | ||||||
|  |             dyze2SHCvfbr6So6GtJnZQy5J7tPoHBd3zwjojYV11kR9Ci1GszrVw== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |         - recipient: age1mu0ej57n4s30ghealhyju3enls83qyjua69986la35t2yh0q2s0seruz5n | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBuVzdFdXdETEN3bjdIY0hi | ||||||
|  |             TUV3YjFSUHBhNTIyUDd6MC93R2xRZmZGTkd3CkZuNWRZY25nY1FMZjV1QzJuUUZN | ||||||
|  |             d0hzMUplY0w4c0hVK0dCbHVzVURvUm8KLS0tIGt2UEozYTdzMDRGUlRYeWpLY0Q3 | ||||||
|  |             bmFMZGRhWGZQZlpwMFZsV3VwdEljRUkKwS1gGaLCY/+wv2blCiDWHXOTl7eRVDPH | ||||||
|  |             NPk33fXDa0y4AxFmwJ9caHL+UHWhSCVvi6odl1F6OA4blNLHRZAyzQ== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |         - recipient: age1j2u876z8hu87q5npfxzzpfgllyw8ypj66d7cgelmzmnrf3xud34qzkntp9 | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBDdmZXREhrUk5kWHgyMzI0 | ||||||
|  |             RnR0bVE1cm9GQkpwc0VWZ3ZmUjMxMzF2WVhFCkcrcEI4enlRN09wNzF4M0tTNXZi | ||||||
|  |             TWg1TTkwUlNYUU1ReUVSU1dTdFoxeWcKLS0tIGZaMmVmZ1kxbFVVMmsxTzczYU9j | ||||||
|  |             N3Y3Qm9SQ2Z0bWNhM043czdnWC9RR0kK61W5sqXybAbjTUR8D05dYMInLl683Rzj | ||||||
|  |             G+0MZEzvfYONGU1gduRB5quHAwZLG5b9N6zorRSFON1meni+v/Ciww== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |         - recipient: age1t8zlawqkmhye737pn8yx0z3p9cl947d9ktv2cajdc6hnvn52d3fsc59s2k | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBod1RDR1NLZlhQQWw4Nk8z | ||||||
|  |             TTZHZitTNjFxUHVIZWY3N2VDd3pXRGt4N0JFClNzQ2REbSt5T0FXaVBhS09zcS9y | ||||||
|  |             TW5PTW1mSzlyOHppSm1yMWp6by9ZUWMKLS0tIFVsYkJZbHE3K3B5TS95amJhbDYy | ||||||
|  |             dFV1REdKYmIweWw1MDJ4L3p0cW9nVWMKQndDoniGQOn01SnscX7u7y6l119Eb++q | ||||||
|  |             JoTZELALPIyGdI4pXd6zCfRyLFaqWd4CO0RFtl8FTcm75W+ETmqqlQ== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |         - recipient: age199zkqq4jp4yc3d0hx2q0ksxdtp42xhmjsqwyngh8tswuck34ke3smrfyqu | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBjdlhET094ZGJsZU9tZnhz | ||||||
|  |             d20wcnltVU1MS09Qb3lzV2RjNi9OZjhDdFRBCndRY3hwQ3VHQWF2MVRFUU1MQkhh | ||||||
|  |             bGRQdEVaSzF0YTgxTGdITGN2dDlYc1kKLS0tIEw1MmFkUHJaKzZGRU93T2VTTkxK | ||||||
|  |             VU0xV0gwQ1NnbVIrS3lHTnJ5bU9IcGMKDWSWfA7iBQ+8iclmXDVf5Qjv67D2WbJg | ||||||
|  |             ovrYcT1F5+qE4xkuUkzVaGn9vgT+/kkzFucBz0c0iD5KCoa52z5AlQ== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |         - recipient: age17tagmpwqjk3mdy45rfesrfey6h863x8wfq38wh33tkrlrywxducs0k6tpq | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBtV2R5VzdCbkFDTGRJUG81 | ||||||
|  |             bUk3Y3F6NkJGYUk1VW1XQnFOSTlwMTduL0Y0CjJ4N1Q5MXZjQXhsTk5Hbk40U1pU | ||||||
|  |             aFNxeFIyaGJpd3dMZFpQL0R2M1dHbk0KLS0tIGpUVGMyRSt6aDZVOERRWnRSY1Ns | ||||||
|  |             dXptcUNmeGRHcEs3WStpL3BuZUtJbjAKhqJEec4vjSC18oRl1dTNkF2Ev4YtudE4 | ||||||
|  |             Lp2vbcSHXwrZhqbFlQ8stCpUJvjCBEr2cT/shrG38aP0MzgeSmMacQ== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |         - recipient: age1mrnldl334l2nszuta6ywvewng0fswv2dz9l5g4qcwe3nj4yxf92qjskdx6 | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBURXhRWEFHU2Rtd0pyZGUw | ||||||
|  |             b09VQ1JhYjhJYlpnY2FCZndEcU1Ed3k1K0UwCit1NVIyL2xuZlAzbEJwY3V0UTB3 | ||||||
|  |             Unk1L3p6cHlVWjllMjcvcTdDcnlxcGcKLS0tIGdGa3MvTmJiSGF4YnBZbE1wdGEv | ||||||
|  |             eFArZE5MaXlvOE9XN1I4eEtNMEpzcU0KVNUfcUJM+IVY/+b8mQiHKvuFnsih+zHx | ||||||
|  |             ZdUD+FPjghqrzJB4MOl/PYAxJ4lga6gPbcRWD5UUDuyDGOUwRpOt7w== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |         - recipient: age1hmpdk4h69wxpwqk9tkud39f66hprhehxtzhgw97r6dvr7v0mx5jscsuhkn | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBNUnhIOHVLUG1meWFlZ24w | ||||||
|  |             SVlFenR1aWZXK21HSXpHU1NSZ2llQ1EwSnpnCmJYRXR3b3IvclZvaGpGdEpOUk9D | ||||||
|  |             eDg2eFFJQ0M4TEJqZDVUQUZGa2h3V3cKLS0tIEhWTzhoMVg1UEM2M1k1TVZTUDlL | ||||||
|  |             RDE1RCtUV2dDR3haclBMZDFhYXcyV2sKjwEI2dY4rluumihyEggLYDDvZZAK4SZw | ||||||
|  |             FWkwIUpMCZzg2fCeDMnTSAWfAZbiDcPLoCieJ2bpGXPTzyasRlOakg== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |         - recipient: age1wrssr4z4g6vl3fd3qme5cewchmmhm0j2xe6wf2meu4r6ycn37anse98mfs | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBxamdXMXJ4K3hMV2g1WmUy | ||||||
|  |             Ry80dG5wdWlLc1paY1VoSE8vWk1ra1g5cldFClN1eXlVUGVndnovQ3dxQTdzQjRV | ||||||
|  |             Wm9NNWg5VVR4NVNsRjM0VHFya1FQeWsKLS0tIG43bTdKVjNrQlBUWHJoNjIyOW85 | ||||||
|  |             TGd1Tng1akExRDd0TFZmQ3JnS3FtK3cKn2t7/4yIDZT2oy8fyJibF62usPjhuBOb | ||||||
|  |             9qQjChRm5h5mNSWdAzyf48wID7czzJiZjqtfE4vjLYLsWKMzz9j3xg== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |         - recipient: age1zhxul786an743u0fascv4wtc5xduu7qfy803lfs539yzhgmlq5ds2lznt5 | ||||||
|  |           enc: | | ||||||
|  |             -----BEGIN AGE ENCRYPTED FILE----- | ||||||
|  |             YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBKQm5UalBhV1NWa2ZQNzVQ | ||||||
|  |             OEZXODkrYXRGR2lRMzMwSk5KV01WK3pLZlZ3ClNwZTV6aGRvZlV2UXJaNm9IOVVR | ||||||
|  |             VFZscVZhVkFaMlk5a1ZCcWJReVN5YWcKLS0tIEhHMnRKdWJvTkREbFlWb25YRXg3 | ||||||
|  |             YU5mMDlRckJCMDAzcHYyMWN1clRJRVEK77PiAQP+2+WblGYEgAf6bx6RTh0JHiSZ | ||||||
|  |             /jPIN/rbAKNv36wpZDbuLV8tcMuvhleNMRSSqbIloLSzww+Z5nOU4A== | ||||||
|  |             -----END AGE ENCRYPTED FILE----- | ||||||
|  |     lastmodified: "2025-07-30T18:29:08Z" | ||||||
|  |     mac: ENC[AES256_GCM,data:47cki5ucPTVd4JuEyK0QkDCCEqj1pW6SA5I6ihC/MEja6TIuHTcEPFpje8+LvpGjpP9uobKX4g3UcyvkJ63j/k3hU0xPYQX3Z1ee00KIMKB0GHNjUR8ENtnwd3TU7kp5ohtXeCtcyzCjdFFuXp8AINGv3vpbU2MzauctUxn5B1Y=,iv:1mpk/f1QlRtHfA9dqyNLBrvfVPgtLnZ7ibj8qNrEGD8=,tag:drEK1+qeJy97rgeQJyqucA==,type:str] | ||||||
|  |     pgp: | ||||||
|  |         - created_at: "2025-07-30T18:27:50Z" | ||||||
|  |           enc: |- | ||||||
|  |             -----BEGIN PGP MESSAGE----- | ||||||
|  |  | ||||||
|  |             hQIMA0av/duuklWYAQ/9HdDiIXAQjcAbokD7yliGC+p7j+RxD2FDh5aXtDIS14dM | ||||||
|  |             pF7wdTdY7PvcXoSCQ5ZC7bjIY86MDfD+BT63MwjOczIgBJJ9wrGDZ2o9DnzzYsI1 | ||||||
|  |             XdUgQscjtbAycNlaczI6IXrYlWqjt6qpp/OADXdMXZo3W+pTR3aSdrj/FcMzJad1 | ||||||
|  |             AMQt8raqrD5LxIj0yWEYvob5z7NA6slBvVJRszsbYgz3aJWqG2DhlUBph6j2Rgmq | ||||||
|  |             /W796+fywrunmY/dmzptT5Epp5gZ55BAqg09qHj/+crTxIt7SNpsfps2ki8JBVq0 | ||||||
|  |             4ooaUktBBMnhsZBA8NIauesokZkLO0MvyvjMBPGR8jun2EXoNtFmWZqUqD1fb0B5 | ||||||
|  |             xe0SVg8XIzS/AFnKVAWfj6h9lM4guLL/kxu3aPAJwOj+YtIAXx4vojs81Led8nlQ | ||||||
|  |             jXvfy7Y94EQhKTLWuK12QC+bw2vy4V9L98nyDKB3ZuN2l3A2CN1ZLXArk/oez56d | ||||||
|  |             5t/0C43qEPfzQH87kygGuuQmlZvQupnHN4iCvExmoiX362/3S9h1wS5QcKdC3Lk/ | ||||||
|  |             f3yr0+r1uOYuoQuofwitLZaq66aCmqYUmXhLvGujPjg8YuNXQ5k1MlOilDqoZnxk | ||||||
|  |             0V8RQbTpvUcqRLgczofC0ovgE2W13khS2BGxG3ZPmAbUGiaIP9OkfebI7hJJE7LS | ||||||
|  |             XgE4cU06C5jj4wLkOj3y4nEKwaFrEGRO3YQa1kl5/sExOg0Jd7fehozVh8+opGOZ | ||||||
|  |             MhmVHghd/RYZzBi3NZL28xnAvsawE1m6h6WEGk6JaVEdJh9W009AQCtVyChs9Og= | ||||||
|  |             =4gbo | ||||||
|  |             -----END PGP MESSAGE----- | ||||||
|  |           fp: F7D37890228A907440E1FD4846B9228E814A2AAC | ||||||
|  |     unencrypted_suffix: _unencrypted | ||||||
|  |     version: 3.10.2 | ||||||
							
								
								
									
										24
									
								
								values.nix
									
									
									
									
									
								
							
							
						
						
									
										24
									
								
								values.nix
									
									
									
									
									
								
							| @@ -41,10 +41,6 @@ in rec { | |||||||
|       ipv4 = pvv-ipv4 209; |       ipv4 = pvv-ipv4 209; | ||||||
|       ipv6 = pvv-ipv6 209; |       ipv6 = pvv-ipv6 209; | ||||||
|     }; |     }; | ||||||
|     bob = { |  | ||||||
|       ipv4 = "129.241.152.254"; |  | ||||||
|       # ipv6 = ; |  | ||||||
|     }; |  | ||||||
|     knutsen = { |     knutsen = { | ||||||
|       ipv4 = pvv-ipv4 191; |       ipv4 = pvv-ipv4 191; | ||||||
|     }; |     }; | ||||||
| @@ -72,6 +68,26 @@ in rec { | |||||||
|       ipv4 = pvv-ipv4 240; |       ipv4 = pvv-ipv4 240; | ||||||
|       ipv6 = pvv-ipv6 240; |       ipv6 = pvv-ipv6 240; | ||||||
|     }; |     }; | ||||||
|  |     lupine-1 = { | ||||||
|  |       ipv4 = pvv-ipv4 224; | ||||||
|  |       ipv6 = pvv-ipv6 224; | ||||||
|  |     }; | ||||||
|  |     lupine-2 = { | ||||||
|  |       ipv4 = pvv-ipv4 225; | ||||||
|  |       ipv6 = pvv-ipv6 225; | ||||||
|  |     }; | ||||||
|  |     lupine-3 = { | ||||||
|  |       ipv4 = pvv-ipv4 226; | ||||||
|  |       ipv6 = pvv-ipv6 226; | ||||||
|  |     }; | ||||||
|  |     lupine-4 = { | ||||||
|  |       ipv4 = pvv-ipv4 227; | ||||||
|  |       ipv6 = pvv-ipv6 227; | ||||||
|  |     }; | ||||||
|  |     lupine-5 = { | ||||||
|  |       ipv4 = pvv-ipv4 228; | ||||||
|  |       ipv6 = pvv-ipv6 228; | ||||||
|  |     }; | ||||||
|   }; |   }; | ||||||
|  |  | ||||||
|   defaultNetworkConfig = { |   defaultNetworkConfig = { | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user