From f373e772781c9d1cdbe2f97ef3791a7b41ac0657 Mon Sep 17 00:00:00 2001 From: Jakub Stachurski Date: Wed, 11 Feb 2026 15:36:27 +0100 Subject: Nixfmt --- hosts/omega-relay/default.nix | 23 +++--- hosts/omega-relay/firewall.nix | 100 +++++++++++++++------------ hosts/omega-relay/hardware-configuration.nix | 18 +++-- 3 files changed, 81 insertions(+), 60 deletions(-) (limited to 'hosts') diff --git a/hosts/omega-relay/default.nix b/hosts/omega-relay/default.nix index 3c7272c..95e03e4 100644 --- a/hosts/omega-relay/default.nix +++ b/hosts/omega-relay/default.nix @@ -24,14 +24,13 @@ desktop.xfce.enable = lib.mkForce false; gpg.enable = true; - virtualisation.guest = true; + virtualisation.guest = true; }; boot.loader.grub = { enable = true; efiSupport = false; }; - environment.systemPackages = with pkgs; [ lynx chawan @@ -77,22 +76,22 @@ }; services.fail2ban = { - enable = true; + enable = true; maxretry = 5; ignoreIP = [ - "192.168.80.0/24" "192.168.80.0/24" - ]; - bantime = "24h"; + "192.168.80.0/24" + ]; + bantime = "24h"; bantime-increment = { enable = true; # Enable increment of bantime after each violation formula = "ban.Time * math.exp(float(ban.Count+1)*banFactor)/math.exp(1*banFactor)"; # multipliers = "1 2 4 8 16 32 64"; maxtime = "168h"; # Do not ban for more than 1 week overalljails = true; # Calculate the bantime based on all the violations - }; + }; }; - + # TODO: Make a nginx module security.acme = lib.mkIf (!config.addons.virtualisation.isTestVM) { acceptTerms = true; @@ -109,10 +108,10 @@ enableACME = !isVM; addSSL = !isVM; root = "/srv/www/wilkuu.xyz/"; - locations."/" = { - index = "index.html"; - tryFiles = "$uri $uri/ =404"; - }; + locations."/" = { + index = "index.html"; + tryFiles = "$uri $uri/ =404"; + }; }; }; diff --git a/hosts/omega-relay/firewall.nix b/hosts/omega-relay/firewall.nix index c90a903..086a86e 100644 --- a/hosts/omega-relay/firewall.nix +++ b/hosts/omega-relay/firewall.nix @@ -1,4 +1,4 @@ -{ config, lib, pkgs, ... }: +{ config, lib, ... }: let wgHomePort = 16888; baseTCP = [ @@ -34,59 +34,73 @@ let ]; in { - sops.secrets = let - secrets = [ - "wg/home/privateKey" - "wg/home/chrono/PSK" - "wg/home/chrono/PK" - "wg/home/chrono/endpoint" - ]; - in lib.genAttrs secrets (name: { - sopsFile = ../../secrets/${config.networking.hostName}/wireguard.yaml; - key = lib.removePrefix "wg/" name; - }); + sops.secrets = + let + secrets = [ + "wg/home/privateKey" + "wg/home/chrono/PSK" + "wg/home/chrono/PK" + "wg/home/chrono/endpoint" + ]; + in + lib.genAttrs secrets (name: { + sopsFile = ../../secrets/${config.networking.hostName}/wireguard.yaml; + key = lib.removePrefix "wg/" name; + }); networking.wireguard = { - enable = true; - useNetworkd = true; - interfaces = { - wg-home = { - ips = ["192.168.80.100/24"]; - extraOptions = { - DNS = "192.168.88.1"; - }; - privateKeyFile = config.sops.secrets."wg/home/privateKey".path; - listenPort = wgHomePort; - dynamicEndpointRefreshSeconds = 45; - - peers = [ - { - allowedIPs = ["192.168.88.0/24" "192.168.80.0/24"]; - presharedKeyFile = config.sops.secrets."wg/home/chrono/PSK".path; - publicKey = "rP5lJY6ea7BKX40edzqNMJbhfLkSlSwG1FipEufeflk="; - # endpoint = "45.138.54.155:16556"; - endpoint = "wilkuu.duckdns.org:16556"; - name = "wg-home-chronosphere"; + enable = true; + useNetworkd = true; + interfaces = { + wg-home = { + ips = [ "192.168.80.100/24" ]; + extraOptions = { + DNS = "192.168.88.1"; + }; + privateKeyFile = config.sops.secrets."wg/home/privateKey".path; + listenPort = wgHomePort; + dynamicEndpointRefreshSeconds = 45; + + peers = [ + { + allowedIPs = [ + "192.168.88.0/24" + "192.168.80.0/24" + ]; + presharedKeyFile = config.sops.secrets."wg/home/chrono/PSK".path; + publicKey = "rP5lJY6ea7BKX40edzqNMJbhfLkSlSwG1FipEufeflk="; + # endpoint = "45.138.54.155:16556"; + endpoint = "wilkuu.duckdns.org:16556"; + name = "wg-home-chronosphere"; - } - ]; - }; - }; - }; - systemd.network.networks."40-wg-home".dns = ["192.168.88.1"]; + } + ]; + }; + }; + }; + systemd.network.networks."40-wg-home".dns = [ "192.168.88.1" ]; systemd.network.enable = true; systemd.network.networks."10-uplink" = { matchConfig.Name = "ens18"; # TODO: Cloudinit - address = ["45.136.141.133/26" "2a12:bec0:650:128::133/64"]; - gateway = ["45.136.141.129" "2a12:bec0:650:128::"]; - dns = ["1.1.1.1" "2606:4700:4700:0000:0000:0000:0000:1002"]; - linkConfig.RequiredForOnline="yes"; + address = [ + "45.136.141.133/26" + "2a12:bec0:650:128::133/64" + ]; + gateway = [ + "45.136.141.129" + "2a12:bec0:650:128::" + ]; + dns = [ + "1.1.1.1" + "2606:4700:4700:0000:0000:0000:0000:1002" + ]; + linkConfig.RequiredForOnline = "yes"; }; systemd.network.networks."99-fallback" = { matchConfig.Type = "ether"; networkConfig.DHCP = "ipv4"; - linkConfig.RequiredForOnline="routable"; + linkConfig.RequiredForOnline = "routable"; }; networking.useDHCP = false; diff --git a/hosts/omega-relay/hardware-configuration.nix b/hosts/omega-relay/hardware-configuration.nix index aaf9d00..cb7c84c 100644 --- a/hosts/omega-relay/hardware-configuration.nix +++ b/hosts/omega-relay/hardware-configuration.nix @@ -1,14 +1,22 @@ # Do not modify this file! It was generated by ‘nixos-generate-config’ # and may be overwritten by future invocations. Please make changes # to /etc/nixos/configuration.nix instead. -{ config, lib, pkgs, modulesPath, ... }: +{ lib, modulesPath, ... }: { - imports = - [ (modulesPath + "/profiles/qemu-guest.nix") - ]; + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; - boot.initrd.availableKernelModules = [ "uhci_hcd" "ehci_pci" "ahci" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ]; + boot.initrd.availableKernelModules = [ + "uhci_hcd" + "ehci_pci" + "ahci" + "virtio_pci" + "virtio_scsi" + "sd_mod" + "sr_mod" + ]; boot.initrd.kernelModules = [ ]; boot.kernelModules = [ "kvm-intel" ]; boot.extraModulePackages = [ ]; -- cgit v1.3.1