{ config, lib, pkgs, ... }: with import ; let external-ip = config.krebs.build.host.nets.internet.ip4.addr; ext-if = config.makefu.server.primary-itf; allDisks = [ "/dev/sda" "/dev/sdb" ]; in { imports = [ ./hetznercloud { users.users.lass = { uid = 19002; isNormalUser = true; createHome = true; useDefaultShell = true; openssh.authorizedKeys.keys = with config.krebs.users; [ lass.pubkey makefu.pubkey ]; }; } # # # Security # Tools # # # networking # # # # { # bonus retiolum config for connecting more hosts krebs.tinc.retiolum = { #extraConfig = lib.mkForce '' # ListenAddress = ${external-ip} 53 # ListenAddress = ${external-ip} 655 # ListenAddress = ${external-ip} 21031 # StrictSubnets = yes # LocalDiscovery = no #''; connectTo = [ "prism" "ni" "enklave" "eve" "dishfire" ]; }; networking.firewall = { allowedTCPPorts = [ 53 655 21031 ]; allowedUDPPorts = [ 53 655 21031 ]; }; } # ci # ### systemdUltras ### ###### Shack ##### # # # services # # { krebs.exim.enable = mkDefault true; } # sharing # samba sahre # { nixpkgs.config.allowUnfree = true; } # ## # # # ## network # # { makefu.backup.server.repo = "/var/backup/borg"; } # { # recent changes mediawiki bot networking.firewall.allowedUDPPorts = [ 5005 5006 ]; } # Removed until move: no extra mails # # Removed until move: avoid letsencrypt ban ### Web # ## # # # # # # # # # # # # # # sharing { krebs.airdcpp.dcpp.shares = { download.path = config.makefu.dl-dir + "/finished"; sorted.path = config.makefu.dl-dir + "/sorted"; }; } ## Temporary: # # # # krebs infrastructure services # ]; # makefu.dl-dir = "/var/download"; makefu.dl-dir = "/media/cloud/download/finished"; services.openssh.hostKeys = lib.mkForce [ { bits = 4096; path = (toString ); type = "rsa"; } { path = (toString ); type = "ed25519"; } ]; ###### stable security.acme.certs."cgit.euer.krebsco.de" = { email = "letsencrypt@syntax-fehler.de"; webroot = "/var/lib/acme/acme-challenge"; group = "nginx"; }; services.nginx.virtualHosts."cgit" = { serverAliases = [ "cgit.euer.krebsco.de" ]; addSSL = true; sslCertificate = "/var/lib/acme/cgit.euer.krebsco.de/fullchain.pem"; sslCertificateKey = "/var/lib/acme/cgit.euer.krebsco.de/key.pem"; locations."/.well-known/acme-challenge".extraConfig = '' root /var/lib/acme/acme-challenge; ''; }; krebs.build.host = config.krebs.hosts.gum; # Network networking = { firewall = { allowedTCPPorts = [ 80 443 28967 # storj ]; allowPing = true; logRefusedConnections = false; }; nameservers = [ "8.8.8.8" ]; }; users.users.makefu.extraGroups = [ "download" "nginx" ]; state = [ "/home/makefu/.weechat" ]; }