2
2
mirror of https://git.feal.no/felixalb/nixos-config.git synced 2025-01-25 03:04:46 +01:00
nixos-config/hosts/sarek/configuration.nix

55 lines
1.5 KiB
Nix
Raw Normal View History

2023-10-03 01:25:33 +02:00
{ config, pkgs, lib, modulesPath, ... }:
{
imports =
[
(modulesPath + "/virtualisation/proxmox-lxc.nix")
../../base.nix
../../common/metrics-exporters.nix
2023-10-05 22:14:29 +02:00
2023-12-16 16:45:59 +01:00
./services/flame.nix
./services/hedgedoc.nix
./services/nginx.nix
2023-10-05 22:14:29 +02:00
./services/postgresql.nix
2023-10-03 01:25:33 +02:00
];
2023-10-05 22:05:09 +02:00
# Boot and console is handled by proxmoxLXC.
2023-10-03 01:25:33 +02:00
boot.loader.systemd-boot.enable = lib.mkForce false; # Enabled in base.nix, forced off here.
2023-10-05 22:05:09 +02:00
# Override proxmox networking
proxmoxLXC.manageNetwork = true;
networking = {
hostName = "sarek";
defaultGateway = "192.168.10.1";
interfaces."eth0".ipv4 = {
addresses = [
{ address = "192.168.10.181"; prefixLength = 24; }
];
};
hostId = "15dd36bc";
};
2023-10-03 01:25:33 +02:00
sops.defaultSopsFile = ../../secrets/sarek/sarek.yaml;
2023-12-16 17:38:22 +01:00
virtualisation.docker.enable = true;
virtualisation.oci-containers.backend = "docker";
# Undo https://github.com/NixOS/nixpkgs/commit/59e37267556eb917146ca3110ab7c96905b9ffbd to work on unprivileged LXC containers
system.activationScripts.var = lib.mkForce ''
# Various log/runtime directories.
mkdir -p /var/tmp
chmod 1777 /var/tmp
# Empty, immutable home directory of many system accounts.
mkdir -p /var/empty
# Make sure it's really empty
${pkgs.e2fsprogs}/bin/chattr -f -i /var/empty || true
find /var/empty -mindepth 1 -delete
chmod 0555 /var/empty
chown root:root /var/empty
${pkgs.e2fsprogs}/bin/chattr -f +i /var/empty || true
'';
systemd.tmpfiles.rules = lib.mkForce [];
2023-10-03 01:25:33 +02:00
system.stateVersion = "23.05";
}