22f5345026
tsuki/hydra: harden server unit
2024-01-23 05:36:39 +01:00
ce5c3666b9
tsuki/jupyter: set up tmpdirs for notebooks
2024-01-23 05:35:58 +01:00
1ea23dc42e
tsuki: set system.stateVersion
2024-01-23 05:35:20 +01:00
1cd0f1188e
modules/machineVars: types.string -> types.str
2024-01-23 05:34:01 +01:00
56df2f5e10
tsuki: lowercase hostname
2024-01-23 05:33:48 +01:00
8ce9100913
kanidm: explicitly bind to localhost
2024-01-23 05:32:34 +01:00
d629eedaaf
tsuki/navidrome: conditional config
2024-01-23 05:31:26 +01:00
72e7626e9d
tsuki/postgres: tune for bare metal setup
2024-01-23 05:31:06 +01:00
f49d3665fc
tsuki/vaultwarden: disable invitations
2024-01-23 05:30:14 +01:00
fe50d92f8c
tsuki/vaultwarden: conditional config
2024-01-23 05:29:57 +01:00
3d2825d1ec
tsuki/samba: init
2024-01-23 05:29:17 +01:00
1efd3d4f0a
tsuki/kanidm: set up backups
2024-01-23 05:27:43 +01:00
851d0c1fd0
tsuki/prometehus: set up slice for exporters
2024-01-23 05:26:22 +01:00
0d3e805611
tsuki: move to bare metal, set up zfs
2024-01-23 05:24:47 +01:00
3a52ba8901
treewide: update to nixos 23.11
2023-12-18 20:59:48 +01:00
fe30e15f5b
home: setup tealdeer
2023-12-18 14:56:18 +01:00
067f663ac6
home: get rid of secrets
2023-12-18 14:52:34 +01:00
82bcb7d46d
firefox: port bookmarks and engines from secrets
2023-12-18 14:47:40 +01:00
f7b893b10c
home/ssh: port matchblocks from secrets
2023-12-18 14:47:40 +01:00
e5ce5fdcf2
home/newsboat: port sources from secrets
2023-12-18 14:47:40 +01:00
6289b53ff7
home: split up ssh into blocks, and add more targets
2023-12-11 13:34:14 +01:00
b1650e91a6
kasei: split services into services
directory
2023-12-11 13:27:40 +01:00
7193a12ac2
tsuki/services: remove some uses of secret ports
2023-10-06 18:27:21 +02:00
6cd17fb71c
README: big update ( 👍 ᐛ ) 👍
2023-10-06 18:27:20 +02:00
3d613d1ac9
tsuki/invidious: use socket activation
2023-10-06 18:27:19 +02:00
424fea0dc8
tsuki/jupyter: use socket activation
2023-10-06 18:27:18 +02:00
5bb10df9e1
tsuki/borg: partial systemd hardening
...
There's still quite a bit to do, but the service fails on a weird option
that I've not been able to pin down. At least this is better than
nothing ¯\_(ツ)_/¯
2023-10-06 18:27:17 +02:00
450d26cf4b
tsuki/atuin: use socket activation
2023-10-06 18:27:16 +02:00
aca2962eec
tsuki/vaultwarden: use socket activation
2023-10-06 18:27:15 +02:00
caedfe1810
tsuki/matrix/stickers: use new module and add lots of stickerpacks
2023-10-06 18:27:14 +02:00
87eeb522a2
home/shell: make mainProgram selection better
2023-10-06 17:19:50 +02:00
550b9f1b1b
home/gdb: init
2023-10-06 17:18:49 +02:00
ad262195f6
home/packages: add lots of unused packages
2023-10-06 17:17:15 +02:00
5a2e34b89e
home/shell: add aliases for ofborg evals
2023-10-06 17:16:38 +02:00
9038f3ea54
home/git: add rebase-author alias
2023-10-06 17:14:02 +02:00
92eb44e7ad
home/shell: remove and update a few aliases
2023-07-29 12:59:23 +02:00
f85724dea0
home/shell: split alias tree functionality into module and config
2023-07-29 12:49:17 +02:00
6663a8f280
tsuki/atuin: systemd harden
2023-07-28 22:25:50 +02:00
dec150ae98
gpg agent: systemwide -> homemanager
2023-07-28 22:23:43 +02:00
5f7eb0c8a5
tsuki/prometheus: add exporters for hedgedoc and gitea
2023-07-28 22:09:43 +02:00
f7e25149c7
home: remove a few unused packages and services
2023-07-28 22:05:23 +02:00
d74ed2d045
tsuki/grafana: enable oauth2, misc hardening
2023-07-28 22:05:23 +02:00
816a46603a
tsuki/vaultwarden: systemd harden
2023-07-28 22:05:22 +02:00
0137f4f5a9
lib: remove upstreamed function repeat
(replicate
)
2023-07-28 22:05:22 +02:00
b5874e2bcd
tsuki/navidrome: init
2023-07-28 22:05:22 +02:00
c2026eefeb
tsuki/nginx: small refactor
2023-07-28 22:05:22 +02:00
e6605b3a73
common/sshd: socket activate
2023-07-28 22:05:21 +02:00
c98a1a0541
tsuki/jupyter: harden security with sops and systemd
2023-07-28 22:00:07 +02:00
fdace82c2f
modules: move colors to home/modules
, explicitly import all
2023-07-28 21:48:15 +02:00
4456244f2d
modules: add modules for socket activation
2023-07-28 21:32:13 +02:00