Commit Graph

346 Commits

Author SHA1 Message Date
32a1aff6d9 add usbutils 2023-10-03 21:53:21 +03:00
6000be5584 nix gc: TTL 2d, run weekly 2023-10-02 00:21:04 +03:00
76d01af5c6 install sloccount 2023-10-02 00:00:30 +03:00
1dd4f04725 statix: fix bugs with inherit
now I know better what it does.
2023-10-02 00:00:30 +03:00
652ce88b76 install cloc and tokei 2023-10-02 00:00:30 +03:00
25e8191177 enable statx 2023-10-02 00:00:30 +03:00
5c83f7407a install entr 2023-10-02 00:00:30 +03:00
0e9f90a960 nix run github:astro/deadnix 2023-10-01 22:15:45 +03:00
ea49d06b24 profiles/desktop: add dev packages 2023-09-30 05:44:16 +03:00
95c4f94a25 certget 2023-09-23 22:56:43 +03:00
70e5230611 system users: use /bin/sh
Just learned about "bash security issue" when reading about rrsync.
2023-09-23 22:46:14 +03:00
3b1d1b439f more formatting 2023-09-23 22:29:50 +03:00
92f69eabfa nsd-acme: optionalString 2023-09-23 22:28:27 +03:00
46155b9cb8 cfg cosmetics 2023-09-23 22:25:58 +03:00
1525bdad40 rc: remove obsolete shell alias 2023-09-23 07:26:12 +03:00
be378bb40a wip gtimelog still 2023-09-22 10:35:25 +03:00
9a57670313 install gtimelog 2023-09-22 10:28:53 +03:00
397fcd4a44 jakstpub: nicer smb settings 2023-09-22 10:14:10 +03:00
9c1bfd1b24 add a share for snapshots 2023-09-22 10:06:04 +03:00
69da809527 desktop: sleep before blankscreening 2023-09-21 06:57:45 +03:00
0507fb3328 deployerbot and backups: move time around so they don't ovelap 2023-09-21 06:55:17 +03:00
4b1e8653b5 podman: remove docker alias 2023-09-21 06:35:34 +03:00
c04186a2a6 install distrobox 2023-09-21 06:34:38 +03:00
cfa653752a install distrobox 2023-09-21 06:23:18 +03:00
e3783b8c8b nix-index: use the prebuilt one 2023-09-21 06:06:10 +03:00
4dd83425cf workstation: nix-index and acpid 2023-09-21 05:58:09 +03:00
205aeec19d install iw and acpi; remove random latex 2023-09-20 21:28:15 +03:00
372e65aebf autorandr: remove from home-manager 2023-09-20 15:03:59 +03:00
21e96199bb deployerbot: use vpn for actual deploying anyway 2023-09-20 14:43:04 +03:00
bdcbcec533 forced lock/unlock now works, TBD suspend/resume 2023-09-20 14:25:41 +03:00
b5a947407c disable xautolock 2023-09-20 09:44:05 +03:00
603af72d4e xset: full path 2023-09-20 07:49:20 +03:00
b095b49818 pasystray --key-grabbing --notify-all 2023-09-19 15:20:53 +03:00
5b300e7752 slock 2023-09-19 07:52:20 +03:00
4973a1cdd4 deployerbot: fwminex allows vno1 2023-09-18 20:49:17 +03:00
ceb7fe191e ping 2023-09-18 20:32:22 +03:00
5a5ffd6f00 upgrading fwminex too 2023-09-18 19:50:24 +03:00
c822cc95c2 node_exporter: enable on vno1 subnet 2023-09-18 19:29:27 +03:00
563ccd613a openssh: allow X11 forwarding on desktops 2023-09-18 19:13:36 +03:00
d140360353 replace pasystray with volnoti 2023-09-18 15:16:08 +03:00
920001ce3a ipython and xev 2023-09-18 15:06:10 +03:00
49f5782109 enable volnoti 2023-09-18 15:04:22 +03:00
9ebeef43e3 logind: power key suspends 2023-09-18 14:58:40 +03:00
ac0950f1f8 desktop: autologin 2023-09-18 14:46:48 +03:00
b9b7f2aa3c move efibootmgr to desktop profile 2023-09-18 14:42:34 +03:00
40a1edb925 syncthing: do not share books with mxp10 2023-09-18 13:31:32 +03:00
89bfc8c459 add xss-lock and slock 2023-09-18 13:23:48 +03:00
4740904244 syncthing host missing 2023-09-18 12:48:22 +03:00
5a1745b6d9 add some hosts 2023-09-18 12:47:51 +03:00
0802e17eb1 nix fmt 2023-09-18 12:46:46 +03:00
031e85fa82 syncthing: more folders 2023-09-18 12:44:09 +03:00
e6a47f4420 syncthing: a few more folders 2023-09-18 12:38:17 +03:00
52b1aa4450 syncthing: starting abstractions 2023-09-18 12:13:45 +03:00
a9ec83c732 fwminex: start syncthing 2023-09-18 12:07:41 +03:00
9ece2a456e desktop: install borgbackup 2023-09-18 10:22:33 +03:00
537800ec59 zfsborg: sleep a bit before mounting 2023-09-18 10:06:44 +03:00
2c4598ba7b change snapshot dir 2023-09-18 07:51:47 +03:00
b1a66b6a74 firefox is lowercase 2023-09-17 22:47:21 +03:00
7f4fe7b001 firefox too 2023-09-17 22:46:38 +03:00
d0d09cb4a4 rc.lua: move some windows to screen 9 2023-09-17 22:45:42 +03:00
e039cd2ace rc.lua: lock a bit after turning off the screen 2023-09-17 22:32:41 +03:00
c84d618d97 jakstpub: fix a caddy error 2023-09-17 22:31:12 +03:00
ed8c51b45c syntax nitpicking 2023-09-17 22:16:11 +03:00
f38fd993d3 jakstpub: open up http 2023-09-17 22:13:33 +03:00
3216700d7d awesome: terminal is x-terminal-emulator 2023-09-17 16:16:44 +03:00
f571a87541 add awesome/rc.lua 2023-09-17 08:00:08 +03:00
74d3b2cb23 some autorandr 2023-09-17 07:12:05 +03:00
9f32c033a5 install two more browsers 2023-09-17 06:56:58 +03:00
3d258436a2 add a few packages 2023-09-17 06:48:00 +03:00
abd1d67c2c firefox: do not configure search for now
Sep 16 23:05:45 fwminex hm-activate-motiejus[52877]: Activating checkLinkTargets
    Sep 16 23:05:45 fwminex hm-activate-motiejus[52946]: Existing file '/home/motiejus/.mozilla/firefox/xdefault/search.json.mozlz4' is in the way of '/nix/store/pvmx5mz4gkffnbj826vql07dcqk56jga-home-manager-files/.mozilla/firefox/xdefault/search.json.mozlz4'
    Sep 16 23:05:45 fwminex hm-activate-motiejus[52946]: Please move the above files and try again or use 'home-manager switch -b backup' to back up existing files automatically.
    Sep 16 23:05:45 fwminex systemd[1]: home-manager-motiejus.service: Main process exited, code=exited, status=1/FAILURE
    Sep 16 23:05:45 fwminex systemd[1]: home-manager-motiejus.service: Failed with result 'exit-code'.
    Sep 16 23:05:45 fwminex systemd[1]: Failed to start Home Manager environment for motiejus.
2023-09-16 23:07:27 +03:00
0f9aa4ed0d deploy-rs: remove -- 2023-09-16 10:04:48 +03:00
a5d8ba9cdf deploy-rs: fix typo 2023-09-16 09:35:12 +03:00
fb4b54b24b deployerbot: use deploy-rs directly 2023-09-16 08:56:22 +03:00
b436195d49 hardware observability 2023-09-16 08:53:23 +03:00
948ce2da5a enable autorandr 2023-09-15 22:06:05 +03:00
1f14703f0b start with awesome 2023-09-15 22:04:03 +03:00
48c1bffcd3 add another kb layout 2023-09-15 15:53:07 +03:00
52a1c97f13 reduce number of packages on servers 2023-09-15 15:49:01 +03:00
2061294171 fwminex: add rox-filer 2023-09-15 15:06:55 +03:00
d196f85638 install gm 2023-09-15 15:04:25 +03:00
2bc7029395 joplin -> joplin-desktop 2023-09-15 14:59:00 +03:00
a083360516 firefox: some more settings and addons 2023-09-15 14:56:37 +03:00
fcc52c1297 remove obsolete comment 2023-09-15 14:44:17 +03:00
382ef7b0d7 install pdftk 2023-09-15 14:43:56 +03:00
9821b197c0 add system-wide firefox too 2023-09-15 14:42:55 +03:00
f93555770a firefox: back to standard 2023-09-15 14:41:56 +03:00
2bc3275dfc add some applications and extensions 2023-09-15 14:39:04 +03:00
d57b2e5a1b enable pcscd 2023-09-15 13:27:12 +03:00
e3c5f37b43 add some packages 2023-09-15 13:05:56 +03:00
b1e57c93f1 install parallel everywhere 2023-09-15 12:51:10 +03:00
d7888b000b fix gp 2023-09-15 12:48:14 +03:00
c5191372e8 install gpg 2023-09-15 12:46:10 +03:00
211f580539 gpg-agent: move to per-user 2023-09-15 12:35:59 +03:00
3b005f06cc add firefox 2023-09-15 12:33:09 +03:00
7ee6a0de71 zfsborg: remove the ${mountpoint}/.snapshot-latest prefix
The path in the filesystem is quite clear from the archive name.
2023-09-15 11:05:05 +03:00
30426ad89e zfsborg: mount the tmpfs on all units 2023-09-15 10:10:54 +03:00
c80b1a996a switch to lightdm/xfce4 + sound 2023-09-14 21:58:06 +03:00
09f1b62cc8 add a desktop profile 2023-09-14 21:53:59 +03:00
b38c4013e7 cosmetics: quoting
it's fine, there is overrides.conf
2023-09-14 15:15:27 +03:00
b73f671bc0 silenceLogs is not picked up
Result:
$ cat result/etc/systemd/system/tailscaled.service
[Unit]
Description=Tailscale node agent
Documentation=https://tailscale.com/kb/
Wants=network-pre.target
After=network-pre.target NetworkManager.service systemd-resolved.service

[Service]
ExecStartPre=/nix/store/gr38ww9sj0qbcs8sb17iq9871qvmhfjw-tailscale-1.42.0/bin/tailscaled --cleanup
ExecStart=/nix/store/gr38ww9sj0qbcs8sb17iq9871qvmhfjw-tailscale-1.42.0/bin/tailscaled --state=/var/lib/tailscale/tailscaled.state --socket=/run/tailscale/tailscaled.sock --port=
ExecStopPost=/nix/store/gr38ww9sj0qbcs8sb17iq9871qvmhfjw-tailscale-1.42.0/bin/tailscaled --cleanup

Restart=on-failure

RuntimeDirectory=tailscale
RuntimeDirectoryMode=0755
StateDirectory=tailscale
StateDirectoryMode=0700
CacheDirectory=tailscale
CacheDirectoryMode=0750
Type=notify

[Install]
WantedBy=multi-user.target
2023-09-14 15:10:18 +03:00
76c07129f3 re-add () 2023-09-14 14:51:36 +03:00
fb3c39d7dc re-enable tailscale, oops 2023-09-14 14:48:54 +03:00
9eb8147660 tailscale: silence logs on some machines 2023-09-14 14:37:55 +03:00
553cda8fc7 vno1-rp3b: enable vno3 2023-09-14 13:23:04 +03:00
b1b046d78a sudo: fix extraGroups of motiejus
this misses 'wheel'
2023-09-14 13:07:39 +03:00
e341092306 fwminex: enable redistributable firmware, remove docker volume 2023-09-14 11:31:53 +03:00
a7a6148d0f fwminex: allow nonfree 2023-09-14 10:53:01 +03:00
1430bf9d6d fwminex: swap 2023-09-14 07:43:18 +03:00
85917635fd sshguard is now optional 2023-09-14 06:41:16 +03:00
234933dee1 install smartmontools 2023-09-13 13:29:06 +03:00
e38f446793 add fwminex 2023-09-13 13:04:40 +03:00
e12e139128 samba: make file/dir masks a bit more restrictive 2023-09-13 09:00:28 +03:00
00a6a27b92 zfsborg: use TemporaryFileSystem for temp snapshots
Otherwise:

Sep 13 00:01:05 vno1-oh2 systemd[1]: Started BorgBackup job -var-lib-1.
Sep 13 00:01:06 vno1-oh2 borgbackup-job--var-lib-1-start[329228]: filesystem 'rpool/nixos/var/lib@autosnap_2023-09-12_21:00:06_hourly' is already mounted
Sep 13 00:01:06 vno1-oh2 borgbackup-job--var-lib-1-start[329209]: umount: /var/lib/.snapshot-latest: not mounted.
Sep 13 00:01:06 vno1-oh2 systemd[1]: borgbackup-job--var-lib-1.service: Main process exited, code=exited, status=32/n/a
Sep 13 00:01:06 vno1-oh2 systemd[1]: borgbackup-job--var-lib-1.service: Failed with result 'exit-code'.
Sep 13 00:01:06 vno1-oh2 systemd[1]: borgbackup-job--var-lib-1.service: Triggering OnFailure= dependencies.
2023-09-13 08:37:35 +03:00
4f152205ce samba: log level = 0 2023-09-12 23:27:23 +03:00
bef137b967 wsdd: specify existing hostname 2023-09-12 23:18:46 +03:00
53ce3910aa replace nmbd with wsdd
https://askubuntu.com/questions/661611/make-samba-share-visible-in-windows-network
2023-09-12 23:10:59 +03:00
e45573c8a6 fix samba config
works!
2023-09-12 22:55:17 +03:00
4f45d605e1 vno1-rp3b: some attempts at samba 2023-09-12 17:44:17 +03:00
7891663a65 jakstpub: change home dir to /var/empty 2023-09-12 17:27:11 +03:00
2dd8cda85a open up samba 2023-09-12 16:08:32 +03:00
e61944dfde rewrite firewall rules 2023-09-12 15:46:44 +03:00
2b5b9bc57f samba some progress 2023-09-12 13:31:46 +03:00
49d92971c9 pass BORG_HOST_ID correctly 2023-09-12 11:41:45 +03:00
b204d5532f zfsborg: add BORG_HOST_ID if nics change 2023-09-12 11:30:08 +03:00
563d340013 add lshw 2023-09-12 11:17:50 +03:00
94253212c6 networking.firewall.checkReversePath = "loose" for tailscale 2023-09-11 22:38:44 +03:00
f33f8b3d1b add bonnie++, remove nix-top 2023-09-11 22:01:59 +03:00
80aca1ede2 Revert "firewall: open iperf3 fully"
This reverts commit 56bc914934.
2023-09-11 21:59:43 +03:00
56bc914934 firewall: open iperf3 fully 2023-09-11 21:54:12 +03:00
24412cbfc7 iperf: open up port 2023-09-11 21:43:34 +03:00
99342a6bb9 all: add iperf 2023-09-11 21:32:34 +03:00
27d663e63a bugfix in attrset merging 2023-09-11 17:48:08 +03:00
a522300158 borgbackup: add numbers to jobs 2023-09-11 17:38:18 +03:00
5721531486 nitpicking 2023-09-11 17:27:14 +03:00
583f74cf3f zfsborg: restructure config
Preparing for 2 repo destinations.
2023-09-11 17:25:12 +03:00
866347b042 add borgstor 2023-09-11 15:51:33 +03:00
377030d0c0 headscale: remove ipv6 subnet
it's confusing: I couldn't find an easy way to get the ipv4 address on a client
2023-09-11 14:37:05 +03:00
20ccb666c8 smtp 2023-09-07 19:46:47 +03:00
c7643a20d8 home-manager git name 2023-09-07 19:46:46 +03:00
fd9f30f7d4 snmp exporter: maybe exposing the file will work now? 2023-09-05 14:58:30 +03:00
24e6aa333e snmp exporter: expose in vpn for all to see 2023-09-05 14:45:09 +03:00
5c1cccb8a4 snmp: from package back to module 2023-09-05 14:41:52 +03:00
2963f0a0d7 gc: every 7d 2023-09-03 07:20:49 +03:00
fe30f6c32a Add dl.jakstys.lt 2023-08-29 15:41:57 +03:00
cc11726ed7 remove hel1-a 2023-08-27 15:17:54 +03:00
617b829589 deployerbot: add fra1-a 2023-08-27 01:04:09 +03:00
1db9253ae6 fra1-a 2023-08-26 23:37:16 +03:00
23347f6952 matrix-synapse: listen on 127.0.0.1
reverse proxying is over
2023-08-25 17:00:30 +03:00
3687d7cd73 matrix-synapse listen on 0.0.0.0 2023-08-25 16:14:12 +03:00
2776f8c517 fix extraConfigFiles 2023-08-25 16:03:46 +03:00