Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
361a23f4d3
|
|||
|
9a837d210d
|
|||
|
d3c9fabbc2
|
|||
|
950b163869
|
+1
-1
@@ -30,9 +30,9 @@
|
||||
./services/journald-upload.nix
|
||||
./services/logrotate.nix
|
||||
./services/nginx.nix
|
||||
./services/nullmailer.nix
|
||||
./services/openssh.nix
|
||||
./services/polkit.nix
|
||||
./services/postfix.nix
|
||||
./services/prometheus-flake-input-exporter.nix
|
||||
./services/prometheus-node-exporter.nix
|
||||
./services/prometheus-systemd-exporter.nix
|
||||
|
||||
@@ -1,4 +1,22 @@
|
||||
{ ... }:
|
||||
{ config, pkgs, lib, ... }:
|
||||
let
|
||||
cfg = config.services.irqbalance;
|
||||
in
|
||||
{
|
||||
services.irqbalance.enable = true;
|
||||
}
|
||||
|
||||
# irqbalance only has meaningful work to do on multi-socket machines, so
|
||||
# skip starting it pointlessly everywhere else.
|
||||
systemd.services.irqbalance.serviceConfig.ExecCondition = let
|
||||
isMultiSocket = pkgs.writeShellApplication {
|
||||
name = "irqbalance-is-multi-socket";
|
||||
runtimeInputs = [ pkgs.coreutils ];
|
||||
text = ''
|
||||
sockets=$(cat /sys/devices/system/cpu/cpu*/topology/physical_package_id | sort -u | wc -l)
|
||||
[ "$sockets" -gt 1 ]
|
||||
'';
|
||||
};
|
||||
in lib.mkIf cfg.enable [
|
||||
(lib.getExe isMultiSocket)
|
||||
];
|
||||
}
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
{ config, lib, ... }:
|
||||
{
|
||||
services.nullmailer = {
|
||||
enable = true;
|
||||
|
||||
config = {
|
||||
adminaddr = "root@pvv.ntnu.no";
|
||||
defaultdomain = "pvv.ntnu.no";
|
||||
defaulthost = "pvv.ntnu.no";
|
||||
|
||||
me = lib.mkDefault config.networking.fqdn;
|
||||
remotes = lib.mkDefault "smtp.pvv.ntnu.no smtp port=587 starttls";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -1,22 +0,0 @@
|
||||
{ config, pkgs, lib, ... }:
|
||||
let
|
||||
cfg = config.services.postfix;
|
||||
in
|
||||
{
|
||||
services.postfix = {
|
||||
enable = true;
|
||||
|
||||
settings.main = {
|
||||
myhostname = "${config.networking.hostName}.pvv.ntnu.no";
|
||||
mydomain = "pvv.ntnu.no";
|
||||
|
||||
# Nothing should be delivered to this machine
|
||||
mydestination = [ ];
|
||||
|
||||
relayhost = [ "smtp.pvv.ntnu.no:465" ];
|
||||
|
||||
smtp_tls_wrappermode = "yes";
|
||||
smtp_tls_security_level = "encrypt";
|
||||
};
|
||||
};
|
||||
}
|
||||
@@ -14,6 +14,7 @@ in
|
||||
extensions = ps: with ps; [ pg_repack ];
|
||||
enableTCPIP = true;
|
||||
|
||||
# NOTE: md5 accepts both md5 and scram-sha-256
|
||||
authentication = ''
|
||||
host all all ${values.ipv4-space} md5
|
||||
host all all ${values.ipv6-space} md5
|
||||
@@ -76,6 +77,15 @@ in
|
||||
maintenance_io_concurrency = 100;
|
||||
wal_recycle = true;
|
||||
|
||||
# -------------------------------- #
|
||||
|
||||
# Authentication
|
||||
password_encryption = "scram-sha-256";
|
||||
|
||||
# Logging
|
||||
log_connections = "authorization";
|
||||
log_disconnections = true;
|
||||
|
||||
# SSL
|
||||
ssl = true;
|
||||
ssl_cert_file = "/run/credentials/postgresql.service/cert";
|
||||
|
||||
@@ -1,14 +1,6 @@
|
||||
{ config, lib, pkgs, ... }:
|
||||
{
|
||||
services.postfix.enable = lib.mkForce false;
|
||||
|
||||
services.nullmailer = {
|
||||
enable = true;
|
||||
config = {
|
||||
me = config.networking.fqdn;
|
||||
remotes = "mail.pvv.ntnu.no smtp --port=25";
|
||||
};
|
||||
};
|
||||
services.nullmailer.enable = true;
|
||||
|
||||
services.bro = {
|
||||
enable = true;
|
||||
|
||||
Reference in New Issue
Block a user