67 Commits
Author SHA1 Message Date
Gitea Actions 37401377a7 Update flake.lock 2025-04-28 2026-09-21 02:46:07 +00:00
Gitea Actions 2536d9e55e Update flake.lock 2025-04-27 2026-09-21 02:46:07 +00:00
Gitea Actions fc9377a34a Update flake.lock 2025-04-26 2026-09-21 02:46:07 +00:00
Gitea Actions 1098e43b9d Update flake.lock 2025-04-25 2026-09-21 02:46:07 +00:00
Gitea Actions 6e81f19db5 Update flake.lock 2025-04-24 2026-09-21 02:46:07 +00:00
Gitea Actions 45b1568950 Update flake.lock 2025-04-23 2026-09-21 02:46:07 +00:00
Gitea Actions dbae7fe154 Update flake.lock 2025-04-22 2026-09-21 02:46:07 +00:00
Gitea Actions 4cd20d172a Update flake.lock 2025-04-21 2026-09-21 02:46:07 +00:00
Gitea Actions 305077a0eb Update flake.lock 2025-04-20 2026-09-21 02:46:07 +00:00
Gitea Actions 2997243d4b Update flake.lock 2025-04-19 2026-09-21 02:46:07 +00:00
Gitea Actions bc94109e4b Update flake.lock 2025-04-18 2026-09-21 02:46:07 +00:00
Gitea Actions 38ceaa8a27 Update flake.lock 2025-04-17 2026-09-21 02:46:07 +00:00
Gitea Actions cd95a95037 Update flake.lock 2025-04-16 2026-09-21 02:46:07 +00:00
Gitea Actions 2dcc44ae09 Update flake.lock 2025-04-15 2026-09-21 02:46:07 +00:00
Gitea Actions 38906891d9 Update flake.lock 2025-04-14 2026-09-21 02:46:07 +00:00
Gitea Actions 286fe8bbbe Update flake.lock 2025-04-13 2026-09-21 02:46:07 +00:00
Gitea Actions aad0b8844c Update flake.lock 2025-04-12 2026-09-21 02:46:07 +00:00
Gitea Actions 729ab0586e Update flake.lock 2025-04-11 2026-09-21 02:46:07 +00:00
Gitea Actions a96f334dc6 Update flake.lock 2025-04-10 2026-09-21 02:46:07 +00:00
Gitea Actions 94cbd77a07 Update flake.lock 2025-04-09 2026-09-21 02:46:07 +00:00
Gitea Actions 32ab48a127 Update flake.lock 2025-04-08 2026-09-21 02:46:07 +00:00
Gitea Actions 0bf525f993 Update flake.lock 2025-04-07 2026-09-21 02:46:07 +00:00
Gitea Actions 115c7fc7f6 Update flake.lock 2025-04-06 2026-09-21 02:46:07 +00:00
Gitea Actions bc1832121f Update flake.lock 2025-04-05 2026-09-21 02:46:07 +00:00
Gitea Actions 39890e7cc4 Update flake.lock 2025-04-04 2026-09-21 02:46:07 +00:00
Gitea Actions 1ffd03dd8e Update flake.lock 2025-04-03 2026-09-21 02:46:07 +00:00
Gitea Actions f89b871952 Update flake.lock 2025-04-02 2026-09-21 02:46:07 +00:00
Gitea Actions 334f3c67e1 Update flake.lock 2025-04-01 2026-09-21 02:46:07 +00:00
Gitea Actions fd1e631a2a Update flake.lock 2025-03-31 2026-09-21 02:46:07 +00:00
Gitea Actions 915dc605fa Update flake.lock 2025-03-30 2026-09-21 02:46:07 +00:00
Gitea Actions 73bb186ba2 Update flake.lock 2025-03-29 2026-09-21 02:46:07 +00:00
Gitea Actions fdc5208c9e Update flake.lock 2025-03-28 2026-09-21 02:46:07 +00:00
Gitea Actions dd3d3fbfcc Update flake.lock 2025-03-27 2026-09-21 02:46:07 +00:00
Gitea Actions 2c6ec8f4f7 Update flake.lock 2025-03-26 2026-09-21 02:46:07 +00:00
Gitea Actions 001f609e80 Update flake.lock 2025-03-25 2026-09-21 02:46:07 +00:00
Gitea Actions 05ea7b1d4c Update flake.lock 2025-03-24 2026-09-21 02:46:07 +00:00
Gitea Actions 350e7a49ce Update flake.lock 2025-03-23 2026-09-21 02:46:07 +00:00
julian 14a06588b6 flake: update 2026-09-20 10:31:01 +02:00
julian da3e3d5f1b kardorf: add ausweisapp 2026-09-20 10:30:53 +02:00
julian 5e08f131c7 Merge branch 'master' of https://gitlab.julian-mutter.de/julian/configfiles 2026-09-19 06:46:28 +02:00
julian 544f47abd0 Kardorf: activate syncthing 2026-09-19 06:46:14 +02:00
julian af20072513 flake: update 2026-08-30 18:16:36 +02:00
julian 8759d71e1f aspi: add vortix 2026-08-30 18:16:29 +02:00
julian 3cc888b2a3 aspi: add ausweisapp 2026-08-30 18:16:13 +02:00
julian 6cce8363f7 desktop: add anki 2026-08-29 10:07:07 +02:00
julian 8340426ce2 Add japanese input method 2026-08-21 20:15:46 +02:00
julian 58b2d7fda9 atuin: configure accept on enter 2026-08-21 19:37:27 +02:00
julian af77c702db smath-studio: add meta and fix deprecation warning 2026-08-16 10:55:34 +02:00
julian 5b56cfbf94 smath: update 2026-08-16 10:24:54 +02:00
julian 015f47f36a smath: fix icon 2026-08-16 10:13:54 +02:00
julian b4824d3b71 update flake 2026-08-15 10:59:57 +02:00
julian d5b711f10a Install atuin with ai enabled 2026-08-15 10:59:47 +02:00
julian 4df37851d1 Install worktrunk 2026-08-15 10:59:39 +02:00
julian b6e2c6d0df Implement ssh keys protected with solokey 2026-08-15 10:59:22 +02:00
julian 121f79e048 flake: update 2026-07-19 14:48:40 +02:00
julian e85156235c builder: use correct ssh keys for age 2026-07-19 14:01:09 +02:00
julian e89908b592 builder: store nix-serve key in sops 2026-07-19 13:56:33 +02:00
julian 139402db48 readme: change builder install to remote flake 2026-07-19 13:21:01 +02:00
julian 0bbce5c85e builder: enable gitea-runner 2026-07-19 13:20:42 +02:00
julian 3fd5c34aa1 builder: change ssh key for sops 2026-07-19 13:18:47 +02:00
julian a7df51dbb8 readme: document nixos-anywhere install for builder 2026-07-19 12:59:59 +02:00
julian d89b8b51cc builder: fix config for installation 2026-07-19 12:59:50 +02:00
julian 6c301d87fd builder: allow using modules 2026-07-19 12:53:01 +02:00
julian 4b6c84e63d fix modules not detected 2026-07-19 12:50:16 +02:00
julian 59780f39d0 kardorf: do not use builder 2026-07-19 12:32:11 +02:00
julian 48d784a964 builder: massive config cleanup, breakdown into modules, use disko 2026-07-19 12:29:39 +02:00
julian 76ad137946 hyprland: make monitor config dependent on config.monitors 2026-07-19 09:08:50 +02:00
26 changed files with 1267 additions and 436 deletions
+1 -1
View File
@@ -1,7 +1,7 @@
keys: keys:
- &primary age1ee5udznhadk6m7jtglu4709rep080yjyd2ukzdl8jma4mm92y3psv0slpg - &primary age1ee5udznhadk6m7jtglu4709rep080yjyd2ukzdl8jma4mm92y3psv0slpg
- &aspi-ssh age1q8lc5340gz5xw2f57nglrss68wv0j0hf36py2pdtrl6ky3yrq9qqk0njr4 - &aspi-ssh age1q8lc5340gz5xw2f57nglrss68wv0j0hf36py2pdtrl6ky3yrq9qqk0njr4
- &builder-ssh age1kw4kmdm45zprvdkrrpvgq966l7585vhusmum083qlwnr0xxgd3uqatcyja - &builder-ssh age1vwanu6jm80jzwe78jzz7z9vuzlg94tl7rpdg34vjmxcrnhddxu9q5zaf49
- &kardorf-ssh age15lxw97z03q40xrdscnxqqugh5ky5aqrerg2t2rphkcqm6rnllurq8v98q5 - &kardorf-ssh age15lxw97z03q40xrdscnxqqugh5ky5aqrerg2t2rphkcqm6rnllurq8v98q5
creation_rules: creation_rules:
+8
View File
@@ -36,3 +36,11 @@ ssh-to-age < /etc/ssh/ssh_host_ed25519_key.pub
#+begin_src sh #+begin_src sh
sops updatekeys secrets/* sops updatekeys secrets/*
#+end_src #+end_src
* Installation of builder
- Start recent nixos installer in VM
- Set password for root
#+begin_src sh
nix run github:nix-community/nixos-anywhere -- --flake git+https://gitlab.julian-mutter.de/julian/dotfiles.git#builder --target-host root@<ip>
#+end_src
+15 -1
View File
@@ -1,4 +1,4 @@
{ {pkgs, ...}: {
# Select internationalisation properties. # Select internationalisation properties.
i18n.defaultLocale = "en_US.UTF-8"; i18n.defaultLocale = "en_US.UTF-8";
@@ -23,4 +23,18 @@
console.keyMap = "de"; console.keyMap = "de";
time.timeZone = "Europe/Berlin"; time.timeZone = "Europe/Berlin";
## Japanese input, env vars and servic start are configured in hyprland config
## Configure via program fcitx5-configuration
## There, add the mozc input for japanese
## This could also be done declaratively in this config, see: https://wiki.nixos.org/wiki/Fcitx5
i18n.inputMethod = {
enable = true;
type = "fcitx5";
fcitx5.addons = with pkgs; [
fcitx5-mozc
fcitx5-gtk # Ensures IME works in GTK applications
];
fcitx5.waylandFrontend = true; # compability with wayland
};
} }
+1 -1
View File
@@ -18,7 +18,7 @@
trusted-public-keys = [ trusted-public-keys = [
"nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs=" "nix-community.cachix.org-1:mB9FSh9qf2dCimDSUo8Zy7bkq5CX+/rkCWyvRCYg3Fs="
"hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc=" "hyprland.cachix.org-1:a7pgxzMz7+chwVL3/pzj6jIBMioiJM7ypFP8PwtkuGc="
"binarycache.julian-mutter.de:oJ67uRFwRhNPKL58CHzy3QQLv38Kx7OA1K+6xlEPu7E=" "binarycache.julian-mutter.de:7RB4Sif4WQU76XWIsRJ2KtKa45zg1QOTHEkUhi/JBe8="
"cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY=" "cache.nixos.org-1:6NCHdD59X431o0gWypbMrAURkbJ16ZPMQFGspcDShjY="
"devenv.cachix.org-1:w1cLUi8dv3hnoSPGAuibQv+f9TZLr6cv/Hm9XgU50cw=" "devenv.cachix.org-1:w1cLUi8dv3hnoSPGAuibQv+f9TZLr6cv/Hm9XgU50cw="
"noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4=" "noctalia.cachix.org-1:pCOR47nnMEo5thcxNDtzWpOxNFQsBRglJzxWPp3dkU4="
+49
View File
@@ -0,0 +1,49 @@
# Host hydra
{...}: {
services.hydra = {
enable = true;
hydraURL = "http://hydra.julian-mutter.de"; # externally visible URL
port = 3000;
notificationSender = "hydra@julian-mutter.de"; # e-mail of hydra service
# a standalone hydra will require you to unset the buildMachinesFiles list to avoid using a nonexistant /etc/nix/machines
# buildMachinesFiles = [ ];
# you will probably also want, otherwise *everything* will be built from scratch
useSubstitutes = true;
minimumDiskFree = 5; # in GB
minimumDiskFreeEvaluator = 4; # in GB
};
# Uris allowed as flake inputs, otherwise hydra does not fetch them
nix.settings.allowed-uris = [
"github:"
"gitlab:"
"git+https://github.com/hyprwm/Hyprland"
"https://github.com/hyprwm/Hyprland"
"https://github"
"https://gitlab"
"https://gitlab.julian-mutter.de"
"git+https://gitlab.julian-mutter.de"
];
services.nginx = {
enable = true;
recommendedProxySettings = true;
# recommendedTlsSettings = true;
# other Nginx options
virtualHosts."hydra.julian-mutter.de" = {
# enableACME = true;
# forceSSL = true;
locations."/" = {
proxyPass = "http://127.0.0.1:3000";
# proxyWebsockets = true; # needed if you need to use WebSocket
# extraConfig =
# # required when the target is also TLS server with multiple hosts
# "proxy_ssl_server_name on;" +
# # required when the server wants to use HTTP Authentication
# "proxy_pass_header Authorization;"
# ;
};
};
};
}
+52
View File
@@ -0,0 +1,52 @@
# Setup the device as a jenkins agent
{pkgs, ...}: {
services.openssh = {
enable = true;
# require public key authentication for better security
settings.PasswordAuthentication = false;
settings.KbdInteractiveAuthentication = false;
settings.PermitRootLogin = "yes";
# Add older algorithms for jenkins ssh-agents-plugin to be compatible
settings.Macs = [
"hmac-sha2-512-etm@openssh.com"
"hmac-sha2-256-etm@openssh.com"
"umac-128-etm@openssh.com"
"hmac-sha2-512"
"hmac-sha2-256"
"umac-128@openssh.com"
];
settings.KexAlgorithms = [
"diffie-hellman-group-exchange-sha1"
"diffie-hellman-group14-sha1"
"mlkem768x25519-sha256"
"sntrup761x25519-sha512"
"sntrup761x25519-sha512@openssh.com"
"curve25519-sha256"
"curve25519-sha256@libssh.org"
"diffie-hellman-group-exchange-sha256"
];
};
users.users.jenkins = {
createHome = true;
home = "/var/lib/jenkins";
group = "jenkins";
isNormalUser = true;
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ36sQhVz3kUEi8754G7r3rboihhG4iqFK/UvQm6SING jenkins@home"
];
packages = with pkgs; [
git
devenv
];
extraGroups = [
"docker"
];
};
users.groups.jenkins = {};
programs.java = {
enable = true;
package = pkgs.jdk21; # Same as jenkins version on home
};
}
+7
View File
@@ -0,0 +1,7 @@
# config to make solokey1 work for ssh
{...}: {
# services.pcscd.enable = true;
services.gnome.gcr-ssh-agent.enable = false;
programs.ssh.startAgent = true;
}
Generated
+815 -169
View File
File diff suppressed because it is too large Load Diff
+5
View File
@@ -25,6 +25,11 @@
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
}; };
vortix = {
url = "github:Harry-kp/vortix";
inputs.nixpkgs.follows = "nixpkgs";
};
home-manager = { home-manager = {
url = "github:nix-community/home-manager/release-26.05"; url = "github:nix-community/home-manager/release-26.05";
inputs.nixpkgs.follows = "nixpkgs"; inputs.nixpkgs.follows = "nixpkgs";
+24
View File
@@ -32,6 +32,30 @@ with lib; {
enableFishIntegration = true; enableFishIntegration = true;
}; };
programs.atuin = {
enable = true;
enableFishIntegration = true;
daemon.enable = true;
settings = {
auto_sync = false;
enter_accept = true; # execute directly on enter
ai = {
enabled = true;
capabilites = {
enable_file_tools = false;
enable_command_execution = false;
enable_history_output = false;
enable_history_search = true;
};
opening = {
# The context sent to the ai
send_cwd = false;
send_last_command = false;
};
};
};
};
programs.fish = { programs.fish = {
enable = true; enable = true;
+15 -2
View File
@@ -60,8 +60,12 @@
wf-recorder wf-recorder
wl-clipboard wl-clipboard
(pkgs.writeShellScriptBin "toggle-screen-mirroring" ( (pkgs.writeShellScriptBin "toggle-screen-mirroring"
builtins.readFile ./toggle-screen-mirroring.sh (
builtins.replaceStrings
["@INTERNAL_MONITOR@" "@EXTERNAL_MONITOR@"]
[(builtins.elemAt config.monitors 0).name (builtins.elemAt config.monitors 1).name]
(builtins.readFile ./toggle-screen-mirroring.sh)
)) ))
(pkgs.writeShellScriptBin "correct-workspace-locations" ( (pkgs.writeShellScriptBin "correct-workspace-locations" (
@@ -108,6 +112,15 @@
'' ''
+ "-- Main config from `hyprland.lua`\n" + "-- Main config from `hyprland.lua`\n"
+ builtins.readFile ./hyprland.lua + builtins.readFile ./hyprland.lua
+ "-- Monitor config\n"
+ lib.concatStringsSep "\n" (
map (
monitor: "hl.monitor({ output = \"${monitor.name}\", mode = \"preferred\", position = \"auto\", scale = \"auto\", mirror = \"\"})"
)
config.monitors
)
+ "\n-- For plugging in random monitors\n"
+ "hl.monitor({ output = \"\", mode = \"preferred\", position = \"auto\", scale = \"auto\", mirror = \"\"})\n"
+ "-- Assign workspaces to monitors\n" + "-- Assign workspaces to monitors\n"
+ lib.concatStringsSep "\n" ( + lib.concatStringsSep "\n" (
builtins.concatLists ( builtins.concatLists (
+5 -13
View File
@@ -1,16 +1,3 @@
------------------
---- MONITORS ----
------------------
-- See https://wiki.hypr.land/Configuring/Basics/Monitors/
hl.monitor({
output = "",
mode = "preferred",
position = "auto",
scale = "auto",
mirror = "",
})
------------------- -------------------
---- AUTOSTART ---- ---- AUTOSTART ----
------------------- -------------------
@@ -20,6 +7,7 @@ hl.on("hyprland.start", function()
-- hl.exec_cmd("waybar") -- hl.exec_cmd("waybar")
hl.exec_cmd("env QT_QPA_PLATFORMTHEME=qt5ct noctalia-shell") -- env ensures noctalia works alongside kde hl.exec_cmd("env QT_QPA_PLATFORMTHEME=qt5ct noctalia-shell") -- env ensures noctalia works alongside kde
hl.exec_cmd("firefox") hl.exec_cmd("firefox")
hl.exec_cmd("fcitx5 -d -r")
end) end)
hl.on("config.reloaded", function() hl.on("config.reloaded", function()
hl.exec_cmd("correct-workspace-locations") hl.exec_cmd("correct-workspace-locations")
@@ -31,6 +19,10 @@ end)
-- See https://wiki.hypr.land/Configuring/Advanced-and-Cool/Environment-variables/ -- See https://wiki.hypr.land/Configuring/Advanced-and-Cool/Environment-variables/
hl.env("TERMINAL", terminal) -- e.g. for emacs hl.env("TERMINAL", terminal) -- e.g. for emacs
-- Use fcitx for optional japanese input
hl.env("XMODIFIERS", "@im=fcitx")
hl.env("QT_IM_MODULE", "fcitx")
hl.env("SDL_IM_MODULE", "fcitx")
----------------------- -----------------------
----- PERMISSIONS ----- ----- PERMISSIONS -----
@@ -2,11 +2,10 @@
# A hyprland script for a laptop-external-monitor setup, toggling between which is in use # A hyprland script for a laptop-external-monitor setup, toggling between which is in use
# TODO: Detect these instead of hardcoding them INTERNAL_MONITOR="@INTERNAL_MONITOR@"
INTERNAL_MONITOR="eDP-1" EXTERNAL_MONITOR="@EXTERNAL_MONITOR@"
EXTERNAL_MONITOR="HDMI-A-1"
MIRROR_SETTING=$(hyprctl monitors all -j | jq -r '.[] | select(.name == "HDMI-A-1") | .mirrorOf') MIRROR_SETTING=$(hyprctl monitors all -j | jq -r --arg EXTERNAL "$EXTERNAL_MONITOR" '.[] | select(.name == $EXTERNAL) | .mirrorOf')
echo "current setting: " echo "current setting: "
echo $MIRROR_SETTING echo $MIRROR_SETTING
@@ -18,6 +18,11 @@
}; };
home.packages = with pkgs; [ home.packages = with pkgs; [
(anki.withAddons [
ankiAddons.anki-connect
ankiAddons.passfail2
ankiAddons.review-heatmap
])
arandr arandr
calibre # ebook manager and viewer calibre # ebook manager and viewer
# digikam # digikam
@@ -1,10 +1,18 @@
{pkgs, ...}: { {
pkgs,
inputs,
...
}: {
programs.opencode = { programs.opencode = {
enable = true; enable = true;
package = pkgs.unstable.opencode; package = pkgs.unstable.opencode;
}; };
home.packages = with pkgs; [ home.packages = with pkgs; [
inputs.vortix.packages.${pkgs.system}.default # tui for wireguard
worktrunk # interface for git worktrees
watchexec # Run command when any file in current dir changes watchexec # Run command when any file in current dir changes
android-tools # adb android-tools # adb
# shellcheck # Check bash scripts for common errors # shellcheck # Check bash scripts for common errors
+4
View File
@@ -24,6 +24,7 @@
"${pwd}/features-nixos/optional/k9s" "${pwd}/features-nixos/optional/k9s"
"${pwd}/features-nixos/optional/avahi.nix" "${pwd}/features-nixos/optional/avahi.nix"
"${pwd}/features-nixos/optional/solokey.nix"
]; ];
networking.hostName = "aspi"; networking.hostName = "aspi";
@@ -31,6 +32,9 @@
# networking.firewall.checkReversePath = false; # Makes wg interface with all ips work # networking.firewall.checkReversePath = false; # Makes wg interface with all ips work
programs.ausweisapp.enable = true;
programs.ausweisapp.openFirewall = true; # for pairing with smartphone
modules = { modules = {
syncthing = { syncthing = {
enable = true; enable = true;
+41 -183
View File
@@ -4,10 +4,16 @@
{ {
pwd, pwd,
config, config,
pkgs, inputs,
outputs,
lib,
... ...
}: { }: {
imports = [ imports =
[
inputs.disko.nixosModules.disko
./disko.nix
./hardware-configuration.nix ./hardware-configuration.nix
"${pwd}/features-nixos/global/fish.nix" # fish for admin "${pwd}/features-nixos/global/fish.nix" # fish for admin
@@ -15,7 +21,20 @@
"${pwd}/features-nixos/global/nix.nix" "${pwd}/features-nixos/global/nix.nix"
"${pwd}/features-nixos/global/sops.nix" "${pwd}/features-nixos/global/sops.nix"
"${pwd}/features-nixos/global/root.nix" "${pwd}/features-nixos/global/root.nix"
];
# "${pwd}/features-nixos/optional/hydra.nix"
# "${pwd}/features-nixos/optional/jenkins-agent.nix"
]
++ (builtins.attrValues outputs.nixosModules);
frajul.gitlab-runner = {
enable = false;
secretsFile = ./secrets.yaml;
};
frajul.gitea-runner = {
enable = true;
secretsFile = ./secrets.yaml;
};
networking.hostName = "builder"; networking.hostName = "builder";
system.stateVersion = "23.11"; system.stateVersion = "23.11";
@@ -66,22 +85,22 @@
fallback = true; fallback = true;
}; };
# system.autoUpgrade = { system.autoUpgrade = {
# enable = true; enable = true;
# flake = "git+https://gitlab.julian-mutter.de/julian/dotfiles"; flake = "git+https://gitlab.julian-mutter.de/julian/dotfiles";
# flags = [ flags = [
# "--recreate-lock-file" # update lock file "--recreate-lock-file" # update lock file
# ]; ];
# dates = "02:13"; dates = "02:13";
# }; };
# optimize store by hardlinking store files # optimize store by hardlinking store files
nix.optimise.automatic = true; nix.optimise.automatic = lib.mkForce true;
nix.optimise.dates = ["03:15"]; nix.optimise.dates = lib.mkForce ["03:15"];
# nix.gc.automatic = true; nix.gc.automatic = lib.mkForce true;
# nix.gc.dates = "daily"; nix.gc.dates = lib.mkForce "daily";
# nix.gc.options = "--delete-old"; nix.gc.options = lib.mkForce "--delete-old";
# nix.settings.keep-derivations = false; # nix.settings.keep-derivations = false;
# nix.settings.keep-outputs = true; # nix.settings.keep-outputs = true;
@@ -101,55 +120,12 @@
OOMScoreAdjust = 500; OOMScoreAdjust = 500;
}; };
# Ollama used by open-webui as llm backend
# services.ollama = {
# enable = true;
# # acceleration = "rocm";
# openFirewall = true;
# };
# services.nextjs-ollama-llm-ui = {
# enable = true;
# hostname = "192.168.3.118";
# port = 3001;
# };
# services.open-webui = {
# enable = true;
# port = 8080;
# openFirewall = true;
# host = "builder.julian-mutter.de";
# };
networking.firewall.allowedTCPPorts = [
80
3001 # ollama-ui
];
services.openssh = { services.openssh = {
enable = true; enable = true;
# require public key authentication for better security # require public key authentication for better security
settings.PasswordAuthentication = false; settings.PasswordAuthentication = false;
settings.KbdInteractiveAuthentication = false; settings.KbdInteractiveAuthentication = false;
settings.PermitRootLogin = "yes"; settings.PermitRootLogin = "yes";
# Add older algorithms for jenkins ssh-agents-plugin to be compatible
settings.Macs = [
"hmac-sha2-512-etm@openssh.com"
"hmac-sha2-256-etm@openssh.com"
"umac-128-etm@openssh.com"
"hmac-sha2-512"
"hmac-sha2-256"
"umac-128@openssh.com"
];
settings.KexAlgorithms = [
"diffie-hellman-group-exchange-sha1"
"diffie-hellman-group14-sha1"
"mlkem768x25519-sha256"
"sntrup761x25519-sha512"
"sntrup761x25519-sha512@openssh.com"
"curve25519-sha256"
"curve25519-sha256@libssh.org"
"diffie-hellman-group-exchange-sha256"
];
}; };
users.users."root".openssh.authorizedKeys.keys = [ users.users."root".openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFjSZYdoF/51F+ykcBAYVCzCPTF5EEigWBL1APiR0h+H julian@aspi" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFjSZYdoF/51F+ykcBAYVCzCPTF5EEigWBL1APiR0h+H julian@aspi"
@@ -163,20 +139,6 @@
# security.pam.sshAgentAuth.enable = true; # enable sudo via ssh # security.pam.sshAgentAuth.enable = true; # enable sudo via ssh
services.hydra = {
enable = true;
hydraURL = "http://hydra.julian-mutter.de"; # externally visible URL
port = 3000;
notificationSender = "hydra@julian-mutter.de"; # e-mail of hydra service
# a standalone hydra will require you to unset the buildMachinesFiles list to avoid using a nonexistant /etc/nix/machines
# buildMachinesFiles = [ ];
# you will probably also want, otherwise *everything* will be built from scratch
useSubstitutes = true;
minimumDiskFree = 5; # in GB
minimumDiskFreeEvaluator = 4; # in GB
};
# add builder itpwd as build machine so system emulation is properly supported # add builder itpwd as build machine so system emulation is properly supported
# nix.distributedBuilds = true; # nix.distributedBuilds = true;
nix.buildMachines = [ nix.buildMachines = [
@@ -199,97 +161,30 @@
} }
]; ];
# Uris allowed as flake inputs, otherwise hydra does not fetch them networking.firewall.allowedTCPPorts = [
nix.settings.allowed-uris = [ 80
"github:"
"gitlab:"
"git+https://github.com/hyprwm/Hyprland"
"https://github.com/hyprwm/Hyprland"
"https://github"
"https://gitlab"
"https://gitlab.julian-mutter.de"
"git+https://gitlab.julian-mutter.de"
]; ];
services.nginx = { services.nginx = {
enable = true; enable = true;
recommendedProxySettings = true; recommendedProxySettings = true;
# recommendedTlsSettings = true;
# other Nginx options
virtualHosts."hydra.julian-mutter.de" = {
# enableACME = true;
# forceSSL = true;
locations."/" = {
proxyPass = "http://127.0.0.1:3000";
# proxyWebsockets = true; # needed if you need to use WebSocket
# extraConfig =
# # required when the target is also TLS server with multiple hosts
# "proxy_ssl_server_name on;" +
# # required when the server wants to use HTTP Authentication
# "proxy_pass_header Authorization;"
# ;
};
};
# nix-serve
virtualHosts."binarycache.julian-mutter.de" = { virtualHosts."binarycache.julian-mutter.de" = {
locations."/".proxyPass = "http://${config.services.nix-serve.bindAddress}:${toString config.services.nix-serve.port}"; locations."/".proxyPass = "http://${config.services.nix-serve.bindAddress}:${toString config.services.nix-serve.port}";
}; };
# attic
clientMaxBodySize = "2G"; clientMaxBodySize = "2G";
virtualHosts."cache.julian-mutter.de" = { virtualHosts."cache.julian-mutter.de" = {
locations."/".proxyPass = "http://127.0.0.1:8080"; locations."/".proxyPass = "http://127.0.0.1:8080";
}; };
}; };
# =========== Gitea actions ==========
services.gitea-actions-runner.instances."builder" = {
enable = true;
url = "https://gitlab.julian-mutter.de";
name = "builder";
tokenFile = config.sops.secrets."gitea_token".path;
labels = [
# fake the ubuntu name, because node provides no ubuntu builds
"ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
# my custom nix+devenv ci container
"nix-ci:docker://gitlab.julian-mutter.de/julian/nix-ci-container:latest"
# devenv
"devenv:docker://ghcr.io/cachix/devenv/devenv:latest"
# provide native execution on the host
"nixos:host"
];
# Packages are intjected into PATH for "nixos:host"
hostPackages = with pkgs; [
bash
coreutils
curl
gawk
gitMinimal
nodejs # Required by many standard actions (like actions/checkout)
docker
devenv
wget
nix
];
};
virtualisation.docker.enable = true;
# TODO: podman fails with: "cannot resolve hostname"
# virtualisation.podman = {
# enable = true;
# dockerCompat = true;
# defaultNetwork.settings.dns_enabled = true;
# };
sops.secrets."gitea_token" = {
owner = config.users.users.nix.name;
sopsFile = ./secrets.yaml;
};
# =========== Binary Cache ========== # =========== Binary Cache ==========
sops.secrets."nix_serve_key".sopsFile = ./secrets.yaml;
services.nix-serve = { services.nix-serve = {
enable = true; enable = true;
secretKeyFile = "/var/cache-priv-key.pem"; secretKeyFile = config.sops.secrets."nix_serve_key".path;
}; };
# =========== Binary Cache with attic ========== # =========== Binary Cache with attic ==========
@@ -327,41 +222,4 @@
}; };
}; };
}; };
services.gitlab-runner.enable = true;
# runner for everything else
#
sops.secrets."gitlab_runner_token".sopsFile = ./secrets.yaml;
services.gitlab-runner.services.default = {
# File should contain at least these two variables:
authenticationTokenConfigFile = config.sops.secrets."gitlab_runner_token".path;
dockerImage = "alpine:latest";
dockerVolumes = [
"/var/run/docker.sock:/var/run/docker.sock"
];
};
### Jenkins node
users.users.jenkins = {
createHome = true;
home = "/var/lib/jenkins";
group = "jenkins";
isNormalUser = true;
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ36sQhVz3kUEi8754G7r3rboihhG4iqFK/UvQm6SING jenkins@home"
];
packages = with pkgs; [
git
devenv
];
extraGroups = [
"docker"
];
};
users.groups.jenkins = {};
programs.java = {
enable = true;
package = pkgs.jdk21; # Same as jenkins version on home
};
} }
+56
View File
@@ -0,0 +1,56 @@
# Example to create a bios compatible gpt partition
{ lib, ... }:
{
disko.devices = {
disk.disk1 = {
device = lib.mkDefault "/dev/sda";
type = "disk";
content = {
type = "gpt";
partitions = {
boot = {
name = "boot";
size = "1M";
type = "EF02";
};
esp = {
name = "ESP";
size = "500M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
};
};
root = {
name = "root";
size = "100%";
content = {
type = "lvm_pv";
vg = "pool";
};
};
};
};
};
lvm_vg = {
pool = {
type = "lvm_vg";
lvs = {
root = {
size = "100%FREE";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
mountOptions = [
"defaults"
];
};
};
};
};
};
};
}
-30
View File
@@ -7,43 +7,13 @@
"sd_mod" "sd_mod"
"sr_mod" "sr_mod"
]; ];
# boot.initrd.kernelModules = [ "amdgpu" ]; # GPU support
boot.kernelModules = []; boot.kernelModules = [];
boot.extraModulePackages = []; boot.extraModulePackages = [];
fileSystems."/" = {
device = "/dev/disk/by-uuid/f088fe8e-bf3d-4a89-98bd-ead9852d381f";
fsType = "ext4";
};
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
# (the default) this is the recommended approach. When using systemd-networkd it's
# still possible to use this option, but it's recommended to use it in conjunction
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
networking.useDHCP = lib.mkDefault true; networking.useDHCP = lib.mkDefault true;
# networking.interfaces.ens18.useDHCP = lib.mkDefault true;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
# hardware.graphics = {
# enable = true;
# extraPackages = with pkgs; [
# rocmPackages.clr.icd
# linuxPackages.amdgpu-pro
# ];
# };
# boot.kernelParams = [
# "radeon.si_support=0"
# "radeon.cik_support=1"
# "amdgpu.si_support=0"
# "amdgpu.cik_support=1"
# ];
# boot.extraModulePackages = with config.boot.kernelPackages; [ amdgpu-pro ];
# boot.blacklistedKernelModules = [ "radeon" ];
boot.loader.grub.enable = true; boot.loader.grub.enable = true;
boot.loader.grub.device = "/dev/sda";
# Emulated systems used as alternative to cross-compiling # Emulated systems used as alternative to cross-compiling
boot.binfmt.emulatedSystems = ["aarch64-linux"]; boot.binfmt.emulatedSystems = ["aarch64-linux"];
File diff suppressed because one or more lines are too long
+1
View File
@@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINgH+4xJMk4K5uBIq4hKwar4wt6GYCRE3Z2S4HETc4TK root@builder
+12 -1
View File
@@ -11,7 +11,7 @@
"${pwd}/features-nixos/users/wolfi" "${pwd}/features-nixos/users/wolfi"
"${pwd}/features-nixos/optional/binarycaches.nix" "${pwd}/features-nixos/optional/binarycaches.nix"
"${pwd}/features-nixos/optional/remote-builder.nix" # "${pwd}/features-nixos/optional/remote-builder.nix"
"${pwd}/features-nixos/optional/boot-efi.nix" "${pwd}/features-nixos/optional/boot-efi.nix"
"${pwd}/features-nixos/optional/greetd.nix" "${pwd}/features-nixos/optional/greetd.nix"
@@ -27,6 +27,7 @@
"${pwd}/features-nixos/optional/wireshark.nix" "${pwd}/features-nixos/optional/wireshark.nix"
"${pwd}/features-nixos/optional/flatpak.nix" "${pwd}/features-nixos/optional/flatpak.nix"
"${pwd}/features-nixos/optional/k9s" "${pwd}/features-nixos/optional/k9s"
"${pwd}/features-nixos/optional/solokey.nix"
]; ];
networking.hostName = "kardorf"; networking.hostName = "kardorf";
@@ -35,6 +36,16 @@
# Not using the drivers leads to way better results # Not using the drivers leads to way better results
# services.xserver.videoDrivers = [ "nvidia" ]; # services.xserver.videoDrivers = [ "nvidia" ];
programs.ausweisapp.enable = true;
programs.ausweisapp.openFirewall = true; # for pairing with smartphone
modules = {
syncthing = {
enable = true;
overrideSettings = false;
};
};
networking.networkmanager.insertNameservers = ["192.168.3.252"]; networking.networkmanager.insertNameservers = ["192.168.3.252"];
programs.kdeconnect.enable = true; programs.kdeconnect.enable = true;
+2
View File
@@ -3,4 +3,6 @@
syncthing = import ./syncthing.nix; syncthing = import ./syncthing.nix;
frajulAutoUpgrade = import ./frajul-auto-upgrade.nix; frajulAutoUpgrade = import ./frajul-auto-upgrade.nix;
pianoLEDVisualizer = import ./piano-led-visualizer.nix; pianoLEDVisualizer = import ./piano-led-visualizer.nix;
gitea-runner = import ./gitea-runner.nix;
gitlab-runner = import ./gitlab-runner.nix;
} }
+57
View File
@@ -0,0 +1,57 @@
{
config,
lib,
pkgs,
...
}: let
cfg = config.frajul.gitea-runner;
in {
options = {
frajul.gitea-runner = {
enable = lib.mkEnableOption "gitea-runner";
secretsFile = lib.mkOption {
type = lib.types.path;
description = "A sops encrpyted file containing a 'gitea_token' secret";
};
};
};
config = lib.mkIf cfg.enable {
virtualisation.docker.enable = true;
sops.secrets."gitea_token" = {
owner = config.users.users.nix.name;
sopsFile = cfg.secretsFile;
};
services.gitea-actions-runner.instances."builder" = {
enable = true;
url = "https://gitlab.julian-mutter.de";
name = "builder";
tokenFile = config.sops.secrets."gitea_token".path;
labels = [
# fake the ubuntu name, because node provides no ubuntu builds
"ubuntu-latest:docker://docker.gitea.com/runner-images:ubuntu-latest"
# my custom nix+devenv ci container
"nix-ci:docker://gitlab.julian-mutter.de/julian/nix-ci-container:latest"
# devenv
"devenv:docker://ghcr.io/cachix/devenv/devenv:latest"
# provide native execution on the host
"nixos:host"
];
# Packages are intjected into PATH for "nixos:host"
hostPackages = with pkgs; [
bash
coreutils
curl
gawk
gitMinimal
nodejs # Required by many standard actions (like actions/checkout)
docker
devenv
wget
nix
];
};
};
}
+31
View File
@@ -0,0 +1,31 @@
{
config,
lib,
...
}: let
cfg = config.frajul.gitlab-runner;
in {
options = {
frajul.gitlab-runner = {
enable = lib.mkEnableOption "gitlab-runner";
secretsFile = lib.mkOption {
type = lib.types.path;
description = "A sops encrpyted file containing a 'gitlab_runner_token' secret";
};
};
};
config = lib.mkIf cfg.enable {
services.gitlab-runner.enable = true;
sops.secrets."gitlab_runner_token".sopsFile = cfg.secretsFile;
services.gitlab-runner.services.default = {
# File should contain at least these two variables:
authenticationTokenConfigFile = config.sops.secrets."gitlab_runner_token".path;
dockerImage = "alpine:latest";
dockerVolumes = [
"/var/run/docker.sock:/var/run/docker.sock"
];
};
};
}
+23 -5
View File
@@ -1,17 +1,19 @@
{ {
lib,
appimageTools, appimageTools,
fetchurl, fetchurl,
libgdiplus, libgdiplus,
}: let }: let
pname = "smath-studio"; pname = "smath-studio";
version = "1.3.0.9126"; version = "1.5.0.9678";
src = fetchurl { src = fetchurl {
url = "https://smath.com/en-US/files/Download/cqSek/SMathStudioDesktop.1_3_0_9126.x86_64.ubuntu-22_04.glibc2.35.AppImage"; # The code after /Download/ changes per release
hash = "sha256-4FpdFGPFaPDK6WWSJHVtxcC8auaNkGmHyUtbegij6cQ="; url = "https://smath.com/en-US/files/Download/c4zCE/SMathStudioDesktop.1_5_0_9678.x86_64.ubuntu-22_04.glibc2.35.AppImage";
hash = "sha256-6lnuRnhoH6E+jIZXSgb/Pz9wE9nVAbduDHrkKCKKH+Y=";
}; };
appimageContents = appimageTools.extractType2 { appimageContents = appimageTools.extract {
inherit pname version src; inherit pname version src;
}; };
in in
@@ -30,6 +32,22 @@ in
extraInstallCommands = '' extraInstallCommands = ''
install -m 444 -D ${appimageContents}/*.desktop -t $out/share/applications install -m 444 -D ${appimageContents}/*.desktop -t $out/share/applications
sed -i "s|^Exec=.*|Exec=smath-studio %U|" $out/share/applications/*.desktop sed -i "s|^Exec=.*|Exec=smath-studio %U|" $out/share/applications/*.desktop
cp -r ${appimageContents}/usr/share/icons $out/share
# Package icons into /apps directory
for icon in ${appimageContents}/usr/share/icons/hicolor/*/*.png; do
if [ -f "$icon" ]; then
size=$(basename $(dirname "$icon"))
install -m 444 -D "$icon" "$out/share/icons/hicolor/$size/apps/smath.png"
fi
done
''; '';
meta = with lib; {
description = "Tiny, powerful, free mathematical program with WYSIWYG editor and complete units of measurements support";
homepage = "https://smath.com/";
license = licenses.unfree; # SMath is freeware, but closed source
# maintainers = with maintainers; [frajul];
mainProgram = "smath-studio";
platforms = ["x86_64-linux"];
};
} }