4f6e2c3369
use s0
Check Flake / check-flake (push) Successful in 2m49s
2023-04-29 18:18:52 -06:00
832894edfc
Gitea runner
2023-04-23 10:29:18 -06:00
feb6270952
Update options for newer nixpkgs
2023-04-23 10:28:55 -06:00
38c2e5aece
Fix properties.nix path loading
2023-04-21 23:24:05 -06:00
e72e19b7e8
Fix auto upgrade
2023-04-21 18:58:54 -06:00
03603119e5
Fix invalid import issue.
2023-04-21 18:57:06 -06:00
71baa09bd2
Refactor imports and secrets. Add per system properties and role based secret access.
...
Highlights
- No need to update flake for every machine anymore, just add a properties.nix file.
- Roles are automatically generated from all machine configurations.
- Roles and their secrets automatically are grouped and show up in agenix secrets.nix
- Machines and their service configs may now query the properties of all machines.
- Machine configuration and secrets are now competely isolated into each machine's directory.
- Safety checks to ensure no mixing of luks unlocking secrets and hosts with primary ones.
- SSH pubkeys no longer centrally stored but instead per machine where the private key lies for better cleanup.
2023-04-21 12:58:11 -06:00
40f0e5d2ac
Add Phil
2023-04-19 18:12:42 -06:00
260bbc1ffd
Use doas instead of sudo
2023-04-10 22:03:57 -06:00
c8132a67d0
Use lf as terminal file explorer
2023-04-10 22:03:29 -06:00
3412d5caf9
Use hashed passwordfile just to be safe
2023-04-09 23:00:10 -06:00
1065cc4b59
Enable gitea email notifications
2023-04-09 22:05:23 -06:00
a34238b3a9
Easily run restic commands on a backup group
2023-04-09 13:06:15 -06:00
42e2ebd294
Allow marking folders as omitted from backup
2023-04-09 12:35:20 -06:00
378cf47683
restic backups
2023-04-08 21:25:55 -06:00
f68a4f4431
nixpkgs-fmt everything
2023-04-04 23:30:28 -06:00
68bd70b525
Basic router working using the wip hostapd module from upstream
2023-04-04 12:57:16 -06:00
2189ab9a1b
Improve cifs mounts. Newer protocol version, helpful commands, better network connection resiliency.
2023-03-31 11:43:12 -06:00
acbbb8a37a
encrypted samba vault with gocryptfs
2023-03-25 15:49:07 -06:00
1a98e039fe
Cleanup fio tests
2023-03-25 15:48:24 -06:00
3459ce5058
Add joplin
2023-03-18 22:04:31 -06:00
c48b1995f8
Remove zerotier
2023-03-18 20:41:09 -06:00
53c0e7ba1f
Add Webmail
2023-03-14 23:28:07 -06:00
820cd392f1
Choose random PIA server in a specified region instead of hardcoded. And more TODOs addressed.
2023-03-12 22:55:46 -06:00
759fe04185
with lib;
2023-03-12 21:50:46 -06:00
db441fcf98
Add ability to refuse PIA ports
2023-03-12 21:46:36 -06:00
83e9280bb4
Use the NixOS firewall instead to block unwanted PIA VPN traffic
2023-03-12 20:49:39 -06:00
478235fe32
Enable firewall for PIA VPN wireguard interface
2023-03-12 20:29:20 -06:00
42c0dcae2d
Port forwarding for transmission
2023-03-12 19:50:29 -06:00
7159868b57
update todo's
2023-03-12 19:46:51 -06:00
ab2cc0cc0a
Cleanup services
2023-03-12 17:51:10 -06:00
aaa1800d0c
Cleanup mail domains
2023-03-12 13:29:12 -06:00
a795c65c32
Cleanup mail domains
2023-03-12 13:25:34 -06:00
5ed02e924d
Remove liza
2023-03-12 00:15:06 -07:00
1d620372b8
Remove leftovers of removed compute nodes
2023-03-12 00:14:49 -07:00
9684a975e2
Migrate nextcloud to ponyo
2023-03-12 00:10:14 -07:00
ecb6d1ef63
Migrate mailserver to ponyo
2023-03-11 23:40:36 -07:00
a5f7bb8a22
Fix vpn systemd service restart issues
2023-03-09 13:07:20 -07:00
cea9b9452b
Initial prototype for Wireguard based PIA VPN - not quite 'ready' yet
2023-03-08 23:49:02 -07:00
b53f03bb7d
Fix typo
2023-03-08 23:45:49 -07:00
dee0243268
Peer to peer connection keepalive task
2023-03-07 22:55:37 -07:00
8b6bc354bd
Peer to peer connection keepalive task
2023-03-07 22:54:26 -07:00
aff5611cdb
Update renamed nixos options
2023-03-07 22:52:31 -07:00
90a3549237
use comma and pregenerated nix-index
2023-03-03 00:18:20 -07:00
0cc39bfbe0
deploy-rs initial PoC
2023-03-03 00:16:23 -07:00
bba4f27465
add picocom for serial
2023-03-03 00:12:35 -07:00
987919417d
allow root login over ssh using trusted key
2023-02-11 23:07:48 -07:00
3e0cde40b8
Cleanup remote LUKS unlock
2023-02-11 18:40:08 -07:00
9bcf7cc50d
VPN using its own DNS resolver is unstable
2023-02-11 16:09:02 -07:00
c649b04bdd
Update ssh keys and allow easy ssh LUKS unlocking
2023-02-11 15:05:20 -07:00