Compare commits

..
23 Commits
Author SHA1 Message Date
ShatteredMINT 781ea4f7b5 disable all but public key auth for ssh 2026-07-07 20:55:02 +02:00
ShatteredMINT 734f9db4ba working qemu bridges 2026-07-07 20:47:08 +02:00
ShatteredMINT 3cf8aff4d9 fix typo wg-client 2026-06-15 10:37:00 +02:00
ShatteredMINT 56d4fe4a3d remove redundant option (see cb8f7107) 2026-06-14 22:45:42 +02:00
ShatteredMINT cb8f7107f5 disable sudo password 2026-06-14 22:44:43 +02:00
ShatteredMINT f5991f624a update 2026-06-14 22:42:03 +02:00
ShatteredMINT 54bf93d7a0 switch to amd graphics 2026-06-03 21:39:57 +02:00
ShatteredMINT 335a6b3238 make kdeconnect part of graphical setup 2026-05-13 11:13:12 +02:00
ShatteredMINT 07531e3691 change wireguard config to include DNS 2026-05-13 11:11:43 +02:00
ShatteredMINT db8c11c83a update 2026-05-12 10:25:07 +02:00
ShatteredMINT b09bd7f9f8 create starting neovim config 2026-05-12 10:21:58 +02:00
ShatteredMINT 9ced8b9273 new defaults after update 2026-05-12 09:29:15 +02:00
ShatteredMINT 18fe700d10 update 2026-05-06 13:17:00 +02:00
ShatteredMINT d8c9cf955e add kde-connect 2026-05-06 13:16:54 +02:00
ShatteredMINT 815fefbb78 add option to prefer internal dns server 2026-04-05 19:28:07 +02:00
ShatteredMINT e0e857c533 add bind fs for docker 2026-04-02 16:29:38 +02:00
ShatteredMINT 53ac05664e update git config & remove old NFS shares 2026-04-02 14:44:59 +02:00
ShatteredMINT ced93fa07c Revert "make docker srv user accessible"
This reverts commit d8a15c8977.
2026-04-02 14:42:52 +02:00
ShatteredMINT d8a15c8977 make docker srv user accessible 2026-04-02 14:16:51 +02:00
ShatteredMINT b58746e679 add wg gateway config for nas 2026-04-02 10:03:26 +02:00
ShatteredMINT c23e63bda8 EXPERIMENT: make wireguard config customizable 2026-04-02 10:02:23 +02:00
ShatteredMINT 86b927b894 EXPERIMENT: wireguard config 2026-04-02 09:49:57 +02:00
ShatteredMINT 57d07bae2c update 2026-04-02 08:24:03 +02:00
12 changed files with 120 additions and 30 deletions
+9 -3
View File
@@ -83,6 +83,11 @@
htop htop
]; ];
programs.neovim = {
withRuby = false;
withPython3 = false;
};
# Some programs need SUID wrappers, can be configured further or are # Some programs need SUID wrappers, can be configured further or are
# started in user sessions. # started in user sessions.
# programs.mtr.enable = true; # programs.mtr.enable = true;
@@ -98,10 +103,9 @@
enable = true; enable = true;
ports = [ 22 ]; ports = [ 22 ];
settings = { settings = {
PasswordAuthentication = true; PasswordAuthentication = false;
KbdInteractiveAuthentication = false; KbdInteractiveAuthentication = false;
# AllowUsers = [ "backup" ]; AuthenticationMethods = "publickey";
# UseDns = true;
X11Forwarding = false; X11Forwarding = false;
PermitRootLogin = "no"; PermitRootLogin = "no";
}; };
@@ -133,5 +137,7 @@
system.stateVersion = "24.11"; # Did you read the comment? system.stateVersion = "24.11"; # Did you read the comment?
nix.settings.trusted-users = [ "shatteredmint" ]; nix.settings.trusted-users = [ "shatteredmint" ];
# if people get to that point we are fucked anyways
security.sudo.wheelNeedsPassword = false;
} }
+3
View File
@@ -12,6 +12,7 @@
boot.initrd.kernelModules = [ ]; boot.initrd.kernelModules = [ ];
boot.kernelModules = [ "kvm-amd sg" ]; boot.kernelModules = [ "kvm-amd sg" ];
boot.extraModulePackages = [ ]; boot.extraModulePackages = [ ];
boot.zfs.forceImportRoot = false;
fileSystems."/" = fileSystems."/" =
{ device = "NIX_CONV_POOL/root"; { device = "NIX_CONV_POOL/root";
@@ -62,6 +63,8 @@
# still possible to use this option, but it's recommended to use it in conjunction # still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`. # with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true; networking.useDHCP = lib.mkDefault true;
# make custom dns work while gracefully falling back on public servers
# networking.networkmanager.insertNameservers = [ "192.168.178.108" ];
# networking.interfaces.enp4s0f3u1u4u1.useDHCP = lib.mkDefault true; # networking.interfaces.enp4s0f3u1u4u1.useDHCP = lib.mkDefault true;
# networking.interfaces.wlp2s0.useDHCP = lib.mkDefault true; # networking.interfaces.wlp2s0.useDHCP = lib.mkDefault true;
+6
View File
@@ -14,6 +14,7 @@
boot.kernelModules = [ "kvm-amd" "sg" ]; boot.kernelModules = [ "kvm-amd" "sg" ];
boot.extraModulePackages = [ ]; boot.extraModulePackages = [ ];
boot.binfmt.emulatedSystems = [ "aarch64-linux" ]; boot.binfmt.emulatedSystems = [ "aarch64-linux" ];
boot.zfs.forceImportRoot = false;
fileSystems."/" = fileSystems."/" =
{ device = "NIX_DESK_POOL/root"; { device = "NIX_DESK_POOL/root";
@@ -59,4 +60,9 @@
networking.networkmanager.enable = true; # Easiest to use and most distros use this by default. networking.networkmanager.enable = true; # Easiest to use and most distros use this by default.
# required for ZFS # required for ZFS
networking.hostId = "00000001"; networking.hostId = "00000001";
hardware.graphics = {
enable = true;
enable32Bit = true;
};
} }
+6 -2
View File
@@ -14,8 +14,6 @@
boot.kernelModules = [ ]; boot.kernelModules = [ ];
boot.extraModulePackages = [ ]; boot.extraModulePackages = [ ];
security.sudo.wheelNeedsPassword = false;
fileSystems."/" = fileSystems."/" =
{ device = "/dev/disk/by-uuid/44444444-4444-4444-8888-888888888888"; { device = "/dev/disk/by-uuid/44444444-4444-4444-8888-888888888888";
fsType = "ext4"; fsType = "ext4";
@@ -25,6 +23,12 @@
{ device = "/dev/mapper/base--storage-Docker"; { device = "/dev/mapper/base--storage-Docker";
fsType = "ext4"; fsType = "ext4";
}; };
# bind to give easily accessible space on SSD for configuration
fileSystems."/home/shatteredmint/services" = {
device = "/srv/docker/services";
fsType = "none";
options = [ "bind" ];
};
fileSystems."/srv/private" = fileSystems."/srv/private" =
{ device = "/dev/mapper/base--storage-ShatteredMINT"; { device = "/dev/mapper/base--storage-ShatteredMINT";
Generated
+9 -9
View File
@@ -27,11 +27,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1772845525, "lastModified": 1781365335,
"narHash": "sha256-Dp5Ir2u4jJDGCgeMRviHvEQDe+U37hMxp6RSNOoMMPc=", "narHash": "sha256-zqDBhXMzfbdlO7F2bGHe7MOtB3xngd/+4ieMHDC+ZXo=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "27b93804fbef1544cb07718d3f0a451f4c4cd6c0", "rev": "5b6f5733726a1b2ccafb5dec6ac4ca7299fad66c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -42,11 +42,11 @@
}, },
"nix-flatpak": { "nix-flatpak": {
"locked": { "locked": {
"lastModified": 1768656715, "lastModified": 1780908363,
"narHash": "sha256-Sbh037scxKFm7xL0ahgSCw+X2/5ZKeOwI2clqrYr9j4=", "narHash": "sha256-llGS4y3Qh1eUkli3/Y2VY9FV3GOUKFZR1E2BDftt45Q=",
"owner": "gmodena", "owner": "gmodena",
"repo": "nix-flatpak", "repo": "nix-flatpak",
"rev": "123fe29340a5b8671367055b75a6e7c320d6f89a", "rev": "1df08625f0f8c7d6e300a0e5df7955bbb877d809",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -57,11 +57,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1772773019, "lastModified": 1781074563,
"narHash": "sha256-E1bxHxNKfDoQUuvriG71+f+s/NT0qWkImXsYZNFFfCs=", "narHash": "sha256-md8WlXOlfnIeHeOScMTTHFyf2d6iaTwPl2apR5EQ3P4=",
"owner": "NixOs", "owner": "NixOs",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "aca4d95fce4914b3892661bcb80b8087293536c6", "rev": "9ae611a455b90cf061d8f332b977e387bda8e1ca",
"type": "github" "type": "github"
}, },
"original": { "original": {
+4 -2
View File
@@ -26,7 +26,6 @@
specialArgs = inputs; specialArgs = inputs;
modules = [ modules = [
./devices/desk.nix ./devices/desk.nix
./hardware/nvidia.nix
./hardware/scanner.nix ./hardware/scanner.nix
./configuration.nix ./configuration.nix
@@ -37,7 +36,7 @@
./backup-target.nix ./backup-target.nix
./users/shatteredmint.nix ./users/shatteredmint.nix
# ./qemu-bridges.nix ./qemu-bridges.nix
]; ];
}; };
@@ -54,6 +53,8 @@
./software/default-graphical.nix ./software/default-graphical.nix
./users/shatteredmint.nix ./users/shatteredmint.nix
./network-shares.nix ./network-shares.nix
(import ./software/wireguard-client.nix {ip = 10;})
]; ];
}; };
nix-nas = lib.nixosSystem { nix-nas = lib.nixosSystem {
@@ -69,6 +70,7 @@
./users/shatteredmint.nix ./users/shatteredmint.nix
./software/samba.nix ./software/samba.nix
./software/docker.nix ./software/docker.nix
./software/wireguard-gw-site.nix
]; ];
}; };
}; };
-14
View File
@@ -20,18 +20,4 @@
in ["${automount_opts},credentials=/etc/nixos/smb-secrets,uid=${toString config.users.users.shatteredmint.uid},gid=${toString config.users.groups.users.gid}"]; in ["${automount_opts},credentials=/etc/nixos/smb-secrets,uid=${toString config.users.users.shatteredmint.uid},gid=${toString config.users.groups.users.gid}"];
}; };
# # mount network shares
# fileSystems."/mnt/nas/private" = {
# device = "dashboard.omv:/ShatteredMINT";
# fsType = "nfs";
# options = [ "x-systemd.automount" "noauto" ];
#
# };
# fileSystems."/mnt/nas/shared" = {
# device = "dashboard.omv:/default-nas";
# fsType = "nfs";
# options = [ "x-systemd.automount" "noauto" ];
#
# };
} }
+1
View File
@@ -8,6 +8,7 @@
networking.interfaces.virtbr0 = { networking.interfaces.virtbr0 = {
useDHCP = true; useDHCP = true;
macAddress = "04:92:26:c3:06:c2";
}; };
virtualisation.libvirtd = { virtualisation.libvirtd = {
+3
View File
@@ -18,6 +18,9 @@
makemkv makemkv
]; ];
}; };
programs.kdeconnect.enable = true;
# enable flatpak # enable flatpak
services.flatpak.enable = true; services.flatpak.enable = true;
home-manager.users.shatteredmint.imports = [ home-manager.users.shatteredmint.imports = [
+30
View File
@@ -0,0 +1,30 @@
# reference: https://www.procustodibus.com/blog/2022/06/multi-hop-wireguard/#site-gateway-as-a-spoke
# this configuration is for a device on the home network
# it exposes the entire home network to outside peers
{ip}: {
networking = {
firewall.allowedUDPPorts = [56878];
wg-quick = {
# enable = true;
interfaces.wg0 = {
address = [ ("192.168.87." + builtins.toString(ip) + "/32")];
listenPort = 56878;
privateKeyFile = "/root/wg.keys";
dns = [ "192.168.178.108" ];
peers = [
{
# name = "hub";
publicKey = "XEaJXQW+7llbreoK161NkMhFxlctL1UK8nFiY/GtuC0=";
allowedIPs = [ "192.168.178.0/24" "192.168.87.127/32" "192.168.87.128/25"];
endpoint = "173.249.36.74:56878";
persistentKeepalive = 20;
}
];
};
};
};
}
+38
View File
@@ -0,0 +1,38 @@
# reference: https://www.procustodibus.com/blog/2022/06/multi-hop-wireguard/#site-gateway-as-a-spoke
# this configuration is for a device on the home network
# it exposes the entire home network to outside peers
{config, pkgs, ...}@inputs: {
networking = {
firewall.allowedUDPPorts = [56878];
wireguard = {
enable = true;
interfaces.wg0 = {
ips = [ "192.168.87.250/32"];
listenPort = 56878;
privateKeyFile = "/root/wg.keys";
peers = [
{
name = "hub";
publicKey = "XEaJXQW+7llbreoK161NkMhFxlctL1UK8nFiY/GtuC0=";
allowedIPs = [ "192.168.87.0/25"];
endpoint = "173.249.36.74:56878";
persistentKeepalive = 20;
}
];
postSetup = ''
${pkgs.iptables}/bin/iptables -t mangle -A PREROUTING -i wg0 -j MARK --set-mark 0x30
${pkgs.iptables}/bin/iptables -t nat -A POSTROUTING ! -o wg0 -m mark --mark 0x30 -j MASQUERADE
'';
postShutdown = ''
${pkgs.iptables}/bin/iptables -t mangle -D PREROUTING -i wg0 -j MARK --set-mark 0x30
${pkgs.iptables}/bin/iptables -t nat -D POSTROUTING ! -o wg0 -m mark --mark 0x30 -j MASQUERADE
'';
};
};
};
}
+11
View File
@@ -57,13 +57,24 @@
init.defaultBranch = "main"; init.defaultBranch = "main";
pull.rebase = true; pull.rebase = true;
}; };
signing.format = null;
}; };
programs.neovim = { programs.neovim = {
enable = true; enable = true;
extraPackages = with pkgs; [ extraPackages = with pkgs; [
wl-clipboard wl-clipboard
vimPlugins.lazy-nvim
]; ];
withRuby = false;
withPython3 = false;
initLua = ''
vim.opt.rtp:prepend("${pkgs.vimPlugins.lazy-nvim.outPath}")
require ('config')
require ('plugins')
'';
}; };