Commit graph

201 commits

Author SHA1 Message Date
Magic_RB 661c32b1fe
Remove 25565 from allowed ports on deck
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-04-03 01:32:01 +02:00
Magic_RB a55613fefa
Add tmpfiles configuration to hashicorp-vault-agent on blowhole
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-04-03 01:31:37 +02:00
Magic_RB 807f776c35
Add new uterranix config
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-04-03 01:29:47 +02:00
Magic_RB 1877d128b3
Add domain for influx
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-04-03 01:28:33 +02:00
Magic_RB 0bd14910e3
Fix consul and nomad reload on toothpick
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-04-03 01:28:14 +02:00
Magic_RB 3f7585af77
Use specific nixpkgs pin for Hashicorp stuff
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-04-03 01:26:58 +02:00
Magic_RB 2fffbad037
minor formatting
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-28 12:26:21 +02:00
Magic_RB eae03c9699
fix DNS
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-28 00:06:49 +02:00
Magic_RB 8bbce49068
Disable Serokell cache temporarily
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-10 00:16:55 +01:00
Magic_RB 00773af3d3
Add option to disable hot restart support in envoy
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-07 23:40:00 +01:00
Magic_RB 5532262053
Fix telegraf module
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-07 23:36:15 +01:00
Magic_RB dd2a8accba
Redo envoy module to be standalone
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-07 23:36:02 +01:00
Magic_RB 27f1978d23
Make module imports in blowhole relative
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-06 00:32:20 +01:00
Magic_RB 25a8e23045
Add new public modules: grafana, envoy, telegraf
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-06 00:31:31 +01:00
Magic_RB bbe1a2a6ad
Move secrets templates out of vault-agent module
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-06 00:30:29 +01:00
Magic_RB f39cea90f2
add dontUseConfig to hashicorp for config less things
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-06 00:29:58 +01:00
Magic_RB abad79541e
Simplify DNS zones
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-03-06 00:29:03 +01:00
Magic_RB e16e3fb2f5
Rebind omen key again according to upstream
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-26 15:41:58 +01:00
Magic_RB a0a3ae2656
Get rid off the wireguard RestartSec hack
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-19 01:11:03 +01:00
Magic_RB f923362537
Update inputs
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-19 01:03:49 +01:00
Magic_RB ceb38b807f
omen: fix network manager dispatcher scripts
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-16 14:47:04 +01:00
Magic_RB 084eb2edb6
fixup network mounting on omen
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-16 14:46:20 +01:00
Magic_RB 648e6cf8c1
basic hostap config
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-14 20:18:11 +01:00
Magic_RB 87d0a38d52
switch from antiquotation in roots to concatanation
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-14 15:28:51 +01:00
Magic_RB dac0d1a8da
Update the kernel on blowhole
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-10 00:34:17 +01:00
Magic_RB b9056bc6c1
omen: mount the volumes exported from blowhole
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-10 00:32:41 +01:00
Magic_RB 2942198a6f
Disable NVidia params on omen to increase stability
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-10 00:32:13 +01:00
Magic_RB 5643d663cd
Allow mounting certain shares from omen
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-10 00:31:50 +01:00
Magic_RB 45df9165a1
Increase file limit for nfs-mountd
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-10 00:31:23 +01:00
Magic_RB dd50adb45f
Switch to the 4port intel NIC
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-10 00:30:41 +01:00
Magic_RB 328c8b472c
Implement udp2tcp on/off based on WiFi network name
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-05 17:26:35 +01:00
Magic_RB 065bfdf651 Create secrets folder for vault-agent
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-02 19:00:04 +01:00
Magic_RB 103152b700
Fixup wireguard on UDP blocked networks
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-02 14:56:27 +01:00
Magic_RB 707716597a
Pin the registry on omen
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-02 10:19:00 +01:00
Magic_RB 6bafb7a736
Set minimum free space for ZFS ARC on omen
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-02 10:15:02 +01:00
Magic_RB 0f2139f5e5
Make a dummy interface on blowhole until I get a physical one
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-02 10:13:40 +01:00
Magic_RB ef04a738ab
Pin Nomad network interface on blowhole
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-02 10:13:15 +01:00
Magic_RB 47b1335adc
Fix font in xmobar and make fields fixed-width
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2023-02-02 10:08:37 +01:00
main 639e99f4c4
Add mine layout and bind omen control center key
Signed-off-by: main <magic_rb@redalder.org>
2023-01-15 01:19:19 +01:00
main 1abd585a78
Add a patch to omen's kernel which makes the control center key work
Signed-off-by: main <magic_rb@redalder.org>
2023-01-15 01:16:29 +01:00
main 5119e1b30b
mine layout
Signed-off-by: main <magic_rb@redalder.org>
2023-01-09 13:07:05 +01:00
main b1381511dd
Setup static IP support in dhcpd
Signed-off-by: main <magic_rb@redalder.org>
2022-12-21 23:19:13 +01:00
main 2852b5f562
Downgrade kernel of blowhole, nfsd use-after-free
Signed-off-by: main <magic_rb@redalder.org>
2022-12-21 23:18:45 +01:00
main 0756c15c56
Move bind directory to somewhere persistent
Fixs bind breaking on reboot, according to
https://github.com/NixOS/nixpkgs/issues/204391

Signed-off-by: main <magic_rb@redalder.org>
2022-12-18 23:48:43 +01:00
main 240d6de3e8
Unblock YouTube, I think I solved my addiction but I need it for music
Signed-off-by: main <magic_rb@redalder.org>
2022-12-18 23:26:18 +01:00
main 3e23308bf3
Fix Wireguard not being brought up after boot due to DNS failure
Signed-off-by: main <magic_rb@redalder.org>
2022-12-18 22:27:17 +01:00
main a8cd87e72f
Move mounts into secret :)
Signed-off-by: main <magic_rb@redalder.org>
2022-12-11 14:11:18 +01:00
main 2d3fe86f3f
Open port 80 on blowhole to vpn
Signed-off-by: main <magic_rb@redalder.org>
2022-12-07 23:01:44 +01:00
main 2f818f2963
Hopefully make the relmount happen on boot on blowhole
Signed-off-by: main <magic_rb@redalder.org>
2022-12-03 16:47:33 +01:00
main 6cb4ed2050
Enable sshdEmacs for blowhole
Signed-off-by: main <magic_rb@redalder.org>
2022-12-03 16:47:18 +01:00
main 7ecbeb6c98
Improvements to UDP blockade bypass
Signed-off-by: main <magic_rb@redalder.org>
2022-12-02 18:58:03 +01:00
Magic_RB e9a6573a4e
Add media bind mounts
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-11-30 23:05:52 +01:00
main b2ed5e07bc
Add a udp2tcp udp blocking bypass
Signed-off-by: main <magic_rb@redalder.org>
2022-11-28 16:41:33 +01:00
main 03c3647edf
Add secret override to tweedledee and tweedledum
Signed-off-by: main <magic_rb@redalder.org>
2022-11-28 01:35:45 +01:00
main 99eaf02dfb
Make toothpick behave closer to blowhole
Signed-off-by: main <magic_rb@redalder.org>
2022-11-28 01:35:33 +01:00
main 6f63c57842
Add htop to VPSs
Signed-off-by: main <magic_rb@redalder.org>
2022-11-28 01:35:20 +01:00
main debb9342cf Enable zswap
Signed-off-by: main <magic_rb@redalder.org>
2022-11-27 20:29:18 +01:00
main c7ed3a9471
Fix secret-lib
Signed-off-by: main <magic_rb@redalder.org>
2022-11-27 20:29:05 +01:00
main 4154559032
Fix GRUB installation
Signed-off-by: main <magic_rb@redalder.org>
2022-11-27 20:22:12 +01:00
main 51c3c162bc
Fix wireguard failing to start due to DNS being late
Signed-off-by: main <magic_rb@redalder.org>
2022-11-27 20:21:53 +01:00
main 0bff5525dd
Use latest compatible ZFS Linux for heater
Signed-off-by: main <magic_rb@redalder.org>
2022-11-23 20:49:16 +01:00
main 8b700b61cc
Make sure everything evaluates and builds even without secrets
Signed-off-by: main <magic_rb@redalder.org>
2022-11-23 20:48:59 +01:00
main b55540049e Add manpages to workstations
Signed-off-by: main <magic_rb@redalder.org>
2022-11-03 07:19:39 +01:00
Magic_RB 98da1998a6
Disable containerd on toothpick
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-11-03 00:24:03 +01:00
Magic_RB 3a100a4d52
Disable containerd on workstations
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-11-03 00:23:51 +01:00
Magic_RB 07e2de6840
Don't restart Hashicorp services if they change
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-11-03 00:20:52 +01:00
Magic_RB dccb75934a
Get rid of containerd on blowhole
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-10-30 15:45:41 +01:00
Magic_RB cf77bf433f
utillinux -> util-linux
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-10-30 15:28:04 +01:00
Magic_RB b8ac2fce89
Switch to stable Nix
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-10-30 15:27:47 +01:00
main 8f713ccc5b
Add PostgreSQL for Matrix
Signed-off-by: main <magic_rb@redalder.org>
2022-10-30 15:13:02 +01:00
main cc3eaff12f
Add database for home assistant
Signed-off-by: main <magic_rb@redalder.org>
2022-10-27 13:27:21 +02:00
main 60086123f3
Add Nomad-Docker Nix integration
Signed-off-by: main <magic_rb@redalder.org>
2022-10-27 13:23:08 +02:00
main b12b58fb5d
Disable syncthing in omen
Signed-off-by: main <magic_rb@redalder.org>
2022-10-22 16:15:10 +02:00
Magic_RB 6425857776
Setup acme.sh for Vault
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-10-11 07:55:42 +02:00
main e50e5b84df
Minor cleanup
Signed-off-by: main <magic_rb@redalder.org>
2022-10-07 22:05:56 +02:00
main 2bdc9cb22f
Pantalaimon and ement.el
Signed-off-by: main <magic_rb@redalder.org>
2022-10-07 22:05:31 +02:00
Magic_RB 50db004480
Nomad changes, reset and disabling of GPU
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-09-26 18:46:20 +02:00
Magic_RB 5ec1c33f60
DNS related networking changes
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-09-26 18:46:20 +02:00
Magic_RB 21c4058241
update NFS shares
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-09-26 18:46:20 +02:00
Magic_RB 3f835a36da
Block youtube.com
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-09-26 18:46:20 +02:00
Magic_RB 504c17a535
Initial deck support
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-09-17 12:00:01 +02:00
Magic_RB cacd4ac151
Change DNS
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-09-17 11:55:51 +02:00
Magic_RB 12783c0938
eID slovensko.sk
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-09-17 11:55:51 +02:00
main caab60ee5b Modify ical2org to handle homework well
Signed-off-by: main <magic_rb@redalder.org>
2022-09-17 11:34:45 +02:00
Magic_RB 6616c4f9a2
NFS exports
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-27 23:21:15 +02:00
Magic_RB 180902ae52
Fork nixinate again and add secret override to the options
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-27 22:41:36 +02:00
Magic_RB 9cb7a01750
Fix a little DNS issue on blowhole
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-27 22:41:10 +02:00
Magic_RB 8e32993960
Enable internet access for Docker containers
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-27 22:40:29 +02:00
Magic_RB 09edc911c7
Fix syncthing
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-27 22:40:16 +02:00
Magic_RB 06ffbac467
Add ical2org conversion for uni
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-27 22:37:52 +02:00
Magic_RB 2d342b2110
Firewall CNI compat
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-25 19:43:36 +02:00
Magic_RB 5446dd2549
Some more IP address updates
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-25 19:43:16 +02:00
Magic_RB 598de9bada
drm.modeset on omen
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-25 16:07:57 +02:00
Magic_RB ecfbcc4517
Firewall stuff
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-25 16:07:57 +02:00
Magic_RB bee31bea33
Firewall updates
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-25 16:07:57 +02:00
Magic_RB 2ad1383793
Better logging in bind9
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-25 16:07:57 +02:00
Magic_RB 58088e052b
Move blowhole to new IP
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-25 16:07:57 +02:00
Magic_RB 5294cd2714
Fix restic backup script cleanup operations
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-18 23:07:53 +02:00
Magic_RB 3fb5d945c0
stuff&things
Signed-off-by: Magic_RB <magic_rb@redalder.org>
2022-08-18 22:55:46 +02:00
main a5a651dbb9
Large rework and cleanup
Signed-off-by: main <magic_rb@redalder.org>
2022-07-31 11:03:59 +02:00