Compare commits

...

4 Commits

Author SHA1 Message Date
oysteikt 2bb0d725fc modules/drumknotty: wrap services in infinite loops
Eval nix flake / evals (pull_request) Successful in 8m54s
Eval nix flake / evals (push) Successful in 9m26s
2026-07-21 22:59:12 +09:00
oysteikt 9a837d210d bicep/postgres: log connections/disconnections
Build topology graph / evals (push) Successful in 3m23s
Eval nix flake / evals (push) Successful in 8m59s
2026-07-21 16:39:25 +09:00
oysteikt d3c9fabbc2 base/irqbalance: only start on multi-socket machines 2026-07-21 16:38:38 +09:00
oysteikt 950b163869 bicep/postgresql: use scram-sha-256 as default password algorithm 2026-07-21 16:32:49 +09:00
3 changed files with 41 additions and 5 deletions
+20 -2
View File
@@ -1,4 +1,22 @@
{ ... }:
{ config, pkgs, lib, ... }:
let
cfg = config.services.irqbalance;
in
{
services.irqbalance.enable = true;
}
# irqbalance only has meaningful work to do on multi-socket machines, so
# skip starting it pointlessly everywhere else.
systemd.services.irqbalance.serviceConfig.ExecCondition = let
isMultiSocket = pkgs.writeShellApplication {
name = "irqbalance-is-multi-socket";
runtimeInputs = [ pkgs.coreutils ];
text = ''
sockets=$(cat /sys/devices/system/cpu/cpu*/topology/physical_package_id | sort -u | wc -l)
[ "$sockets" -gt 1 ]
'';
};
in lib.mkIf cfg.enable [
(lib.getExe isMultiSocket)
];
}
@@ -14,6 +14,7 @@ in
extensions = ps: with ps; [ pg_repack ];
enableTCPIP = true;
# NOTE: md5 accepts both md5 and scram-sha-256
authentication = ''
host all all ${values.ipv4-space} md5
host all all ${values.ipv6-space} md5
@@ -76,6 +77,15 @@ in
maintenance_io_concurrency = 100;
wal_recycle = true;
# -------------------------------- #
# Authentication
password_encryption = "scram-sha-256";
# Logging
log_connections = "authorization";
log_disconnections = true;
# SSL
ssl = true;
ssl_cert_file = "/run/credentials/postgresql.service/cert";
+11 -3
View File
@@ -138,6 +138,15 @@ in
ExecStart =
let
mkRespawningCommand = name: command: pkgs.writeShellScript "drumknotty-${name}-watchdog" ''
while true; do
${command}
echo
echo "${name} exited, restarting in 3s..." >&2
sleep 3
done
'';
screenrc = let
convertToFile = lines: lib.pipe lines [
lib.concatLists
@@ -157,8 +166,7 @@ in
config = "/etc/dibbler/dibbler.toml";
};
in lib.optionals cfg.dibbler.enable [
"screen -t dibbler ${lib.getExe cfg.dibbler.package} ${dibblerArgs} loop"
"screen -t dibbler ${mkRespawningCommand "dibbler" "${lib.getExe cfg.dibbler.package} ${dibblerArgs} loop"}"
])
(let
@@ -166,7 +174,7 @@ in
config = "/etc/worblehat/config.toml";
};
in lib.optionals cfg.worblehat.enable [
"screen -t worblehat ${lib.getExe cfg.worblehat.package} ${worblehatArgs} cli"
"screen -t worblehat ${mkRespawningCommand "worblehat" "${lib.getExe cfg.worblehat.package} ${worblehatArgs} cli"}"
])
[ "select 0" ]