Compare commits

...

4 Commits

Author SHA1 Message Date
oysteikt 3bcb178ae7 WIP: base/nginx: host well-known content on multiple subdomains
Eval nix flake / evals (push) Successful in 7m28s
2026-07-21 17:57:41 +09:00
oysteikt 9a837d210d bicep/postgres: log connections/disconnections
Build topology graph / evals (push) Successful in 3m23s
Eval nix flake / evals (push) Successful in 8m59s
2026-07-21 16:39:25 +09:00
oysteikt d3c9fabbc2 base/irqbalance: only start on multi-socket machines 2026-07-21 16:38:38 +09:00
oysteikt 950b163869 bicep/postgresql: use scram-sha-256 as default password algorithm 2026-07-21 16:32:49 +09:00
3 changed files with 91 additions and 18 deletions
+20 -2
View File
@@ -1,4 +1,22 @@
{ ... }:
{ config, pkgs, lib, ... }:
let
cfg = config.services.irqbalance;
in
{
services.irqbalance.enable = true;
}
# irqbalance only has meaningful work to do on multi-socket machines, so
# skip starting it pointlessly everywhere else.
systemd.services.irqbalance.serviceConfig.ExecCondition = let
isMultiSocket = pkgs.writeShellApplication {
name = "irqbalance-is-multi-socket";
runtimeInputs = [ pkgs.coreutils ];
text = ''
sockets=$(cat /sys/devices/system/cpu/cpu*/topology/physical_package_id | sort -u | wc -l)
[ "$sockets" -gt 1 ]
'';
};
in lib.mkIf cfg.enable [
(lib.getExe isMultiSocket)
];
}
+61 -16
View File
@@ -1,25 +1,70 @@
{ lib, ... }:
{
services.nginx.virtualHosts = lib.genAttrs [
"pvv.ntnu.no"
"www.pvv.ntnu.no"
"pvv.org"
"www.pvv.org"
] (_: {
locations = {
"^~ /.well-known/" = {
alias = (toString ./root) + "/";
};
# TODO: move this to base so that all virtualHosts take effect on their respecitve hosts
# Proxy the matrix well-known files
# Host has be set before proxy_pass
# The header must be set so nginx on the other side routes it to the right place
"^~ /.well-known/matrix/" = {
# NOTE: automatically hosting well-known files by looping over all existing `virtualHosts`
# unfortunately causes infinite recursuion due to submodule usage within the nginx
# module. For now, the easiest solution was to manually specify a list of virtualHosts
# here, but it would be nice to find a better solution in the future.
services.nginx.virtualHosts = lib.mkMerge [
(lib.genAttrs [
"pvv.ntnu.no"
"pvv.org"
"www.pvv.ntnu.no"
"www.pvv.org"
"www2.pvv.ntnu.no"
"www2.pvv.org"
# NOTE: this list is probably not complete
"alps.pvv.ntnu.no"
"chat.pvv.ntnu.no"
"grafana.pvv.ntnu.no"
"status.pvv.ntnu.no"
"matrix.pvv.ntnu.no"
"mirrors.pvv.ntnu.no"
"pages.pvv.ntnu.no"
"ooye.pvv.ntnu.no"
"ooye.pvv.ntnu.no"
"dav.pvv.ntnu.no"
"git.pvv.ntnu.no"
"idp.pvv.ntnu.no"
"minecraft.pvv.ntnu.no"
"pw.pvv.ntnu.no"
"snappymail.pvv.ntnu.no"
"webmail.pvv.ntnu.no"
"wiki.pvv.ntnu.no"
] (_: {
locations."^~ /.well-known/security.txt" = {
alias = toString ./root/security.txt;
};
}))
(lib.genAttrs [
"pvv.ntnu.no"
"pvv.org"
"mail.pvv.ntnu.no"
"mail.pvv.org"
"smtp.pvv.ntnu.no"
"smtp.pvv.org"
] (_: {
locations."^~ /.well-known/autoconfig/mail/" = {
root = toString ./root/autoconfig/mail;
};
}))
(lib.genAttrs [
"pvv.ntnu.no"
"pvv.org"
"www.pvv.ntnu.no"
"www.pvv.org"
] (_: {
locations."^~ /.well-known/matrix/" = {
extraConfig = ''
proxy_set_header Host matrix.pvv.ntnu.no;
proxy_pass https://matrix.pvv.ntnu.no/.well-known/matrix/;
'';
};
};
});
}))
];
}
@@ -14,6 +14,7 @@ in
extensions = ps: with ps; [ pg_repack ];
enableTCPIP = true;
# NOTE: md5 accepts both md5 and scram-sha-256
authentication = ''
host all all ${values.ipv4-space} md5
host all all ${values.ipv6-space} md5
@@ -76,6 +77,15 @@ in
maintenance_io_concurrency = 100;
wal_recycle = true;
# -------------------------------- #
# Authentication
password_encryption = "scram-sha-256";
# Logging
log_connections = "authorization";
log_disconnections = true;
# SSL
ssl = true;
ssl_cert_file = "/run/credentials/postgresql.service/cert";