diff --git a/flake.lock b/flake.lock index fb42aff..0f96491 100644 --- a/flake.lock +++ b/flake.lock @@ -604,6 +604,21 @@ "type": "github" } }, + "import-tree": { + "locked": { + "lastModified": 1773693634, + "narHash": "sha256-BtZ2dtkBdSUnFPPFc+n0kcMbgaTxzFNPv2iaO326Ffg=", + "owner": "vic", + "repo": "import-tree", + "rev": "c41e7d58045f9057880b0d85e1152d6a4430dbf1", + "type": "github" + }, + "original": { + "owner": "vic", + "repo": "import-tree", + "type": "github" + } + }, "inspect": { "flake": false, "locked": { @@ -1070,6 +1085,7 @@ "flake-compat": "flake-compat", "flake-parts": "flake-parts", "home-manager": "home-manager_2", + "import-tree": "import-tree", "nish": "nish", "nixinate": "nixinate", "nixpkgs": "nixpkgs", diff --git a/flake.nix b/flake.nix index 8fd892f..1ba6a58 100644 --- a/flake.nix +++ b/flake.nix @@ -21,6 +21,14 @@ nixpkgs.config.allowUnfree = true; nixpkgs.overlays = [self.overlays.default] ++ ovl; } + self.nixosModules.nix-config + self.nixosModules.boot + self.nixosModules.gpg-pinentry-wayland + self.nixosModules.keys + self.nixosModules.hm + self.nixosModules.secrets + self.nixosModules.tailscale + self.nixosModules.deploy ] ++ mod ++ mods.sharedModules; @@ -31,6 +39,7 @@ inputs.flake-parts.flakeModules.easyOverlay inputs.pre-commit-hooks.flakeModule inputs.treefmt-nix.flakeModule + (inputs.import-tree ./tree) ]; systems = import inputs.systems; @@ -40,10 +49,15 @@ # TODO: use ./hosts/ nixosConfigurations = { artemis = mkLinuxSystem [./hosts/artemis] []; - hermes = mkLinuxSystem [./hosts/hermes inputs.nocodb.nixosModules.nocodb inputs.copyparty.nixosModules.default] [inputs.copyparty.overlays.default]; + hermes = + mkLinuxSystem + [./hosts/hermes inputs.nocodb.nixosModules.nocodb inputs.copyparty.nixosModules.default] + [inputs.copyparty.overlays.default]; }; diskoConfigurations = {}; # maybe? - om.health.default = {nix-version.min-required = "2.18.5";}; + om.health.default = { + nix-version.min-required = "2.18.5"; + }; }; perSystem = { @@ -75,11 +89,26 @@ devShells.default = final.mkShell { meta.description = "Default dev shell"; - inputsFrom = [config.pre-commit.devShell config.treefmt.build.devShell]; - packages = with final; [just git nvf cachix jq devour-flake om agenix deadnix]; + inputsFrom = [ + config.pre-commit.devShell + config.treefmt.build.devShell + ]; + packages = with final; [ + just + git + nvf + cachix + jq + devour-flake + om + agenix + deadnix + ]; }; - apps = nixpkgs.lib.mapAttrs' (name: value: nixpkgs.lib.nameValuePair ("deploy-" + name) value) (inputs'.nixinate.packages self); + apps = nixpkgs.lib.mapAttrs' (name: value: nixpkgs.lib.nameValuePair ("deploy-" + name) value) ( + inputs'.nixinate.packages self + ); packages = import ./packages {inherit pkgs inputs inputs';}; }; @@ -190,5 +219,7 @@ url = "github:nocodb/nocodb?ref=bec1fa4"; #inputs.nixpkgs.follows = "unstable"; }; + + import-tree.url = "github:vic/import-tree"; }; } diff --git a/modules/default.nix b/modules/default.nix index 4962e20..8e44dab 100644 --- a/modules/default.nix +++ b/modules/default.nix @@ -1,6 +1,7 @@ let exportModules = args: - builtins.listToAttrs (map (arg: { + builtins.listToAttrs ( + map (arg: { name = let str = baseNameOf arg; suffix = ".nix"; @@ -13,30 +14,16 @@ let value = import arg; }) - args); + args + ); - nixosModules = exportModules [ - ./nix.nix - ./pinentry-fix.nix - ./hm.nix - ./boot.nix - ./keys.nix - ./deploy.nix - ./tailscale.nix - ./secret.nix - ]; + nixosModules = + exportModules [ + ]; homeManagerModules = exportModules [ ]; sharedModules = with nixosModules; [ - pinentry-fix - nix - hm - boot - keys - deploy - tailscale - secret ]; in { inherit nixosModules homeManagerModules sharedModules; diff --git a/tree/boot.nix b/tree/boot.nix new file mode 100644 index 0000000..6895f62 --- /dev/null +++ b/tree/boot.nix @@ -0,0 +1,23 @@ +{...}: { + flake.nixosModules.boot = { + boot = { + loader = { + efi.canTouchEfiVariables = true; + systemd-boot.enable = true; + }; + plymouth.enable = false; + # consoleLogLevel = 0; + # initrd.verbose = false; + # kernelParams = [ + # "quiet" + # "splash" + # "boot.shell_on_fail" + # "loglevel=3" + # "rd.systemd.show_status=false" + # "rd.udev.log_level=3" + # "udev.log_priority=3" + # ]; + }; + system.stateVersion = "24.05"; + }; +} diff --git a/tree/deploy.nix b/tree/deploy.nix new file mode 100644 index 0000000..a436425 --- /dev/null +++ b/tree/deploy.nix @@ -0,0 +1,84 @@ +{...}: { + flake.nixosModules.deploy = { + config, + pkgs, + lib, + ... + }: + with lib; let + cfg = config.c.services.remote-deploy; + in { + options.c.services.remote-deploy = { + enable = mkEnableOption "Enable remote deployment with nixinate."; + host = mkOption { + type = types.str; + description = "Hostname to connect to."; + }; + user = mkOption { + type = types.str; + default = "deploy"; + description = "Username for deploy account."; + }; + group = mkOption { + type = types.str; + default = "deploy"; + description = "Group for deploy account."; + }; + keys = mkOption { + type = types.listOf types.str; + description = "Authorised SSH keys for deployment"; + }; + port = mkOption { + type = types.port; + default = 22; + description = "SSH port to use."; + }; + buildOn = mkOption { + type = types.enum [ + "local" + "remote" + ]; + default = "local"; + description = "Where to build the config."; + }; + substituteOnTarget = mkOption { + type = types.bool; + default = true; + description = "Substitute closures and paths from remote"; + }; + }; + config = mkIf cfg.enable { + _module.args = { + nixinate = { + inherit + (cfg) + host + buildOn + port + substituteOnTarget + ; + sshUser = cfg.user; + }; + }; + users.groups."${cfg.group}" = {}; + users.users."${cfg.user}" = { + isSystemUser = true; + shell = pkgs.bash; + inherit (cfg) group; + openssh.authorizedKeys.keys = cfg.keys; + }; + nix.settings.trusted-users = [cfg.user]; + security.sudo.extraRules = [ + { + groups = [cfg.group]; + commands = [ + { + command = "ALL"; + options = ["NOPASSWD"]; + } + ]; + } + ]; + }; + }; +} diff --git a/tree/gpg-pinentry-wayland.nix b/tree/gpg-pinentry-wayland.nix new file mode 100644 index 0000000..72c2b18 --- /dev/null +++ b/tree/gpg-pinentry-wayland.nix @@ -0,0 +1,5 @@ +{...}: { + flake.nixosModules.gpg-pinentry-wayland = {pkgs, ...}: { + services.dbus.packages = [pkgs.gcr]; + }; +} diff --git a/tree/hm.nix b/tree/hm.nix new file mode 100644 index 0000000..9540cb1 --- /dev/null +++ b/tree/hm.nix @@ -0,0 +1,6 @@ +{...}: { + flake.nixosModules.hm = {...}: { + home-manager.useGlobalPkgs = true; + home-manager.useUserPackages = true; + }; +} diff --git a/tree/keys.nix b/tree/keys.nix new file mode 100644 index 0000000..e7f0d7d --- /dev/null +++ b/tree/keys.nix @@ -0,0 +1,7 @@ +{...}: { + flake.nixosModules.keys = {lib, ...}: { + options.keys = lib.mkOption { + default = import ../lib/keys.nix; + }; + }; +} diff --git a/tree/nix.nix b/tree/nix.nix new file mode 100644 index 0000000..4a44378 --- /dev/null +++ b/tree/nix.nix @@ -0,0 +1,31 @@ +{inputs, ...}: { + flake.nixosModules.nix-config = { + nix = { + registry.nixpkgs.flake = inputs.nixpkgs; + registry.unstable.flake = inputs.unstable; + gc = { + automatic = true; + dates = "weekly"; + options = "--delete-older-than 7d"; + }; + extraOptions = "gc-keep-outputs = true"; + settings = { + experimental-features = [ + "nix-command" + "flakes" + "auto-allocate-uids" + ]; + auto-optimise-store = true; + auto-allocate-uids = true; + substituters = [ + "https://nix-community.cachix.org" + "https://callumio-public.cachix.org" + ]; + trusted-public-keys = [ + "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" + "callumio-public.cachix.org-1:VucOSl7vh44GdqcILwMIeHlI0ufuAnHAl8cO1U/7yhg=" + ]; + }; + }; + }; +} diff --git a/tree/secrets.nix b/tree/secrets.nix new file mode 100644 index 0000000..4354f9e --- /dev/null +++ b/tree/secrets.nix @@ -0,0 +1,5 @@ +{...}: { + flake.nixosModules.secrets = {...}: { + imports = [../secrets/secrets-configuration.nix]; + }; +} diff --git a/tree/tailscale.nix b/tree/tailscale.nix new file mode 100644 index 0000000..9b682a9 --- /dev/null +++ b/tree/tailscale.nix @@ -0,0 +1,38 @@ +{...}: { + flake.nixosModules.tailscale = { + config, + lib, + ... + }: + with lib; let + cfg = config.c.services.mesh; + in { + options.c.services.mesh = { + enable = mkEnableOption "Enable tailscale daemon."; + exitNode = mkOption { + type = types.bool; + default = false; + description = "Enable advertising as an exit node."; + }; + keyFile = mkOption { + type = types.path; + description = "Path to key file."; + }; + }; + config = mkIf cfg.enable { + services.tailscale = { + enable = true; + openFirewall = true; + authKeyFile = cfg.keyFile; + extraUpFlags = [ + "--login-server" + "https://mesh.cleslie.uk" + ]; + extraSetFlags = [(mkIf cfg.exitNode "--advertise-exit-node")]; + }; + networking.firewall = { + trustedInterfaces = [config.services.tailscale.interfaceName]; + }; + }; + }; +}