Compare commits

...

4 Commits

Author SHA1 Message Date
oysteikt 361a23f4d3 base/postfix: remove, base:nullmailer: init
Eval nix flake / evals (push) Successful in 6m44s
Eval nix flake / evals (pull_request) Successful in 6m53s
2026-07-21 22:06:36 +09:00
oysteikt 9a837d210d bicep/postgres: log connections/disconnections
Build topology graph / evals (push) Successful in 3m23s
Eval nix flake / evals (push) Successful in 8m59s
2026-07-21 16:39:25 +09:00
oysteikt d3c9fabbc2 base/irqbalance: only start on multi-socket machines 2026-07-21 16:38:38 +09:00
oysteikt 950b163869 bicep/postgresql: use scram-sha-256 as default password algorithm 2026-07-21 16:32:49 +09:00
6 changed files with 47 additions and 34 deletions
+1 -1
View File
@@ -30,9 +30,9 @@
./services/journald-upload.nix
./services/logrotate.nix
./services/nginx.nix
./services/nullmailer.nix
./services/openssh.nix
./services/polkit.nix
./services/postfix.nix
./services/prometheus-flake-input-exporter.nix
./services/prometheus-node-exporter.nix
./services/prometheus-systemd-exporter.nix
+20 -2
View File
@@ -1,4 +1,22 @@
{ ... }:
{ config, pkgs, lib, ... }:
let
cfg = config.services.irqbalance;
in
{
services.irqbalance.enable = true;
}
# irqbalance only has meaningful work to do on multi-socket machines, so
# skip starting it pointlessly everywhere else.
systemd.services.irqbalance.serviceConfig.ExecCondition = let
isMultiSocket = pkgs.writeShellApplication {
name = "irqbalance-is-multi-socket";
runtimeInputs = [ pkgs.coreutils ];
text = ''
sockets=$(cat /sys/devices/system/cpu/cpu*/topology/physical_package_id | sort -u | wc -l)
[ "$sockets" -gt 1 ]
'';
};
in lib.mkIf cfg.enable [
(lib.getExe isMultiSocket)
];
}
+15
View File
@@ -0,0 +1,15 @@
{ config, lib, ... }:
{
services.nullmailer = {
enable = true;
config = {
adminaddr = "root@pvv.ntnu.no";
defaultdomain = "pvv.ntnu.no";
defaulthost = "pvv.ntnu.no";
me = lib.mkDefault config.networking.fqdn;
remotes = lib.mkDefault "smtp.pvv.ntnu.no smtp port=587 starttls";
};
};
}
-22
View File
@@ -1,22 +0,0 @@
{ config, pkgs, lib, ... }:
let
cfg = config.services.postfix;
in
{
services.postfix = {
enable = true;
settings.main = {
myhostname = "${config.networking.hostName}.pvv.ntnu.no";
mydomain = "pvv.ntnu.no";
# Nothing should be delivered to this machine
mydestination = [ ];
relayhost = [ "smtp.pvv.ntnu.no:465" ];
smtp_tls_wrappermode = "yes";
smtp_tls_security_level = "encrypt";
};
};
}
@@ -14,6 +14,7 @@ in
extensions = ps: with ps; [ pg_repack ];
enableTCPIP = true;
# NOTE: md5 accepts both md5 and scram-sha-256
authentication = ''
host all all ${values.ipv4-space} md5
host all all ${values.ipv6-space} md5
@@ -76,6 +77,15 @@ in
maintenance_io_concurrency = 100;
wal_recycle = true;
# -------------------------------- #
# Authentication
password_encryption = "scram-sha-256";
# Logging
log_connections = "authorization";
log_disconnections = true;
# SSL
ssl = true;
ssl_cert_file = "/run/credentials/postgresql.service/cert";
+1 -9
View File
@@ -1,14 +1,6 @@
{ config, lib, pkgs, ... }:
{
services.postfix.enable = lib.mkForce false;
services.nullmailer = {
enable = true;
config = {
me = config.networking.fqdn;
remotes = "mail.pvv.ntnu.no smtp --port=25";
};
};
services.nullmailer.enable = true;
services.bro = {
enable = true;