97798d7781
rest-server (append-only, tailnet-only on ${hostname}:8008) with a native prune-only job and an offsite restic copy; shared client module backing all hosts into galadriel's repo. Galadriel runs both modules, dataDir on /lorien/backup/restic, service-only paths. Adds sops secrets.
92 lines
2.8 KiB
Nix
92 lines
2.8 KiB
Nix
# Edit this configuration file to define what should be installed on
|
|
# your system. Help is available in the configuration.nix(5) man page, on
|
|
# https://search.nixos.org/options and in the NixOS manual (`nixos-help`).
|
|
|
|
{
|
|
config,
|
|
lib,
|
|
pkgs,
|
|
...
|
|
}:
|
|
|
|
{
|
|
imports = [
|
|
# Include the results of the hardware scan.
|
|
./hardware-configuration.nix
|
|
#./nvidia.nix #we have intel gpu now
|
|
../../modules/boot.nix
|
|
../../modules/zram.nix
|
|
../../modules/zfs.nix
|
|
../../modules/polkit.nix
|
|
../../modules/nix.nix
|
|
../../modules/openssh.nix
|
|
../../modules/gunalx.nix
|
|
../../secrets/sops.nix
|
|
../../secrets/sopsconf.nix
|
|
../../modules/pam.nix
|
|
../../modules/tailscale.nix
|
|
../../modules/podman.nix
|
|
../../modules/basePackages.nix
|
|
../../modules/develPackages.nix
|
|
|
|
../../modules/snakeoil-certs.nix
|
|
../../modules/vaultvarden.nix
|
|
../../modules/immich.nix
|
|
../../modules/qbittorrent.nix
|
|
../../modules/jellyfin.nix
|
|
../../modules/mealie.nix
|
|
../../modules/miniflux.nix
|
|
../../modules/jupyterhub.nix
|
|
../../modules/openwebui.nix
|
|
../../modules/llama-swap.nix
|
|
../../modules/restic-server.nix
|
|
../../modules/restic-client.nix
|
|
|
|
];
|
|
|
|
networking.hostId = "1ccccd3a";
|
|
|
|
## Load zfs pool
|
|
boot.zfs.extraPools = [
|
|
"lorien"
|
|
];
|
|
boot.zfs.requestEncryptionCredentials = true;
|
|
|
|
# Use the systemd-boot EFI boot loader.
|
|
boot.loader.systemd-boot.enable = true;
|
|
boot.loader.efi.canTouchEfiVariables = true;
|
|
|
|
networking.hostName = "galadriel";
|
|
networking.networkmanager.enable = true;
|
|
|
|
services.restic.server.dataDir = "/lorien/backup/restic";
|
|
|
|
services.restic.backups.main.paths = [
|
|
"/var/lib"
|
|
"/lorien/media/pictures"
|
|
"/var/backup"
|
|
];
|
|
|
|
time.timeZone = "Europe/Amsterdam";
|
|
|
|
# This option defines the first version of NixOS you have installed on this particular machine,
|
|
# and is used to maintain compatibility with application data (e.g. databases) created on older NixOS versions.
|
|
#
|
|
# Most users should NEVER change this value after the initial install, for any reason,
|
|
# even if you've upgraded your system to a new NixOS release.
|
|
#
|
|
# This value does NOT affect the Nixpkgs version your packages and OS are pulled from,
|
|
# so changing it will NOT upgrade your system - see https://nixos.org/manual/nixos/stable/#sec-upgrading for how
|
|
# to actually do that.
|
|
#
|
|
# This value being lower than the current NixOS release does NOT mean your system is
|
|
# out of date, out of support, or vulnerable.
|
|
#
|
|
# Do NOT change this value unless you have manually inspected all the changes it would make to your configuration,
|
|
# and migrated your data accordingly.
|
|
#
|
|
# For more information, see `man configuration.nix` or https://nixos.org/manual/nixos/stable/options#opt-system.stateVersion .
|
|
system.stateVersion = "25.05"; # Did you read the comment?
|
|
|
|
}
|