treewide: fixup stockholm lib, explicit dependencies and impure quirks
This commit is contained in:
parent
b66365e722
commit
1c4b5c4174
|
@ -1,11 +1,13 @@
|
||||||
{ config, ... }:
|
{ config, ... }:
|
||||||
# back up all state
|
# back up all state
|
||||||
let
|
let
|
||||||
sec = toString <secrets>;
|
sshkey = config.sops.secrets."borg.priv".path;
|
||||||
sshkey = sec + "/borg.priv";
|
phrase = config.sops.secrets."borg.pw".path;
|
||||||
phrase = sec + "/borg.pw";
|
|
||||||
in
|
in
|
||||||
{
|
{
|
||||||
|
sops.secrets."borg.priv" = {};
|
||||||
|
sops.secrets."borg.pw" = {};
|
||||||
|
|
||||||
services.borgbackup.jobs.state = {
|
services.borgbackup.jobs.state = {
|
||||||
repo = "borg-${config.krebs.build.host.name}@backup.makefu.r:.";
|
repo = "borg-${config.krebs.build.host.name}@backup.makefu.r:.";
|
||||||
paths = config.state;
|
paths = config.state;
|
||||||
|
|
|
@ -1,6 +1,5 @@
|
||||||
{ config, lib, pkgs, ... }:
|
{ config, lib, pkgs, stockholm, ... }:
|
||||||
# TODO: remove tv lib :)
|
with stockholm.lib;
|
||||||
with import <stockholm/lib>;
|
|
||||||
let
|
let
|
||||||
|
|
||||||
repos = krebs-repos;
|
repos = krebs-repos;
|
||||||
|
|
|
@ -20,6 +20,8 @@
|
||||||
drawThickness=0
|
drawThickness=0
|
||||||
filenamePattern=%F_%T_shot
|
filenamePattern=%F_%T_shot
|
||||||
'';
|
'';
|
||||||
|
|
||||||
|
users.users.${config.krebs.build.user.name}.packages = [ pkgs.clipit ];
|
||||||
systemd.user.services.clipit = {
|
systemd.user.services.clipit = {
|
||||||
Unit = {
|
Unit = {
|
||||||
Description = "clipboard manager";
|
Description = "clipboard manager";
|
||||||
|
|
|
@ -2,7 +2,7 @@
|
||||||
|
|
||||||
{
|
{
|
||||||
|
|
||||||
users.users.makefu.packages = with pkgs;[ bat direnv clipit ];
|
users.users.makefu.packages = with pkgs;[ bat direnv ];
|
||||||
home-manager.users.makefu = {
|
home-manager.users.makefu = {
|
||||||
programs.beets.enable = true;
|
programs.beets.enable = true;
|
||||||
programs.firefox = {
|
programs.firefox = {
|
||||||
|
@ -23,5 +23,5 @@
|
||||||
"kjacjjdnoddnpbbcjilcajfhhbdhkpgk" # forest
|
"kjacjjdnoddnpbbcjilcajfhhbdhkpgk" # forest
|
||||||
];
|
];
|
||||||
};
|
};
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,4 +1,6 @@
|
||||||
|
{ config, ... }:
|
||||||
{
|
{
|
||||||
|
sops.secrets."nixos-community" = {};
|
||||||
nix = {
|
nix = {
|
||||||
distributedBuilds = true;
|
distributedBuilds = true;
|
||||||
buildMachines = [
|
buildMachines = [
|
||||||
|
|
|
@ -1,4 +1,5 @@
|
||||||
|
{ config, ... }:
|
||||||
{
|
{
|
||||||
sops.defaultSopsFile = ../../secrets/common.yaml;
|
sops.defaultSopsFile = ../.. + "/secrets/${config.krebs.build.host.name}.yaml";
|
||||||
sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
|
sops.age.sshKeyPaths = [ "/etc/ssh/ssh_host_ed25519_key" ];
|
||||||
}
|
}
|
||||||
|
|
|
@ -3,8 +3,14 @@
|
||||||
imports = [ ./default.nix ];
|
imports = [ ./default.nix ];
|
||||||
|
|
||||||
sops.secrets = {
|
sops.secrets = {
|
||||||
"passwd/makefu".neededForUsers = true;
|
"passwd/makefu" = {
|
||||||
"passwd/root".neededForUsers = true;
|
neededForUsers = true;
|
||||||
|
sopsFile = ../../secrets/common.yaml;
|
||||||
|
};
|
||||||
|
"passwd/root" = {
|
||||||
|
neededForUsers = true;
|
||||||
|
sopsFile = ../../secrets/common.yaml;
|
||||||
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
users.users = {
|
users.users = {
|
||||||
|
|
|
@ -1,5 +1,5 @@
|
||||||
{ config, lib, ... }:
|
{ config, lib, stockholm, ... }:
|
||||||
with import <stockholm/lib>;
|
with stockholm.lib;
|
||||||
let
|
let
|
||||||
base-dir = config.services.rtorrent.downloadDir;
|
base-dir = config.services.rtorrent.downloadDir;
|
||||||
in {
|
in {
|
||||||
|
|
|
@ -20,7 +20,7 @@
|
||||||
# nix related
|
# nix related
|
||||||
nix-index
|
nix-index
|
||||||
nix-review
|
nix-review
|
||||||
brain
|
# brain
|
||||||
whatsupnix
|
whatsupnix
|
||||||
nixpkgs-pytools
|
nixpkgs-pytools
|
||||||
nixpkgs-fmt
|
nixpkgs-fmt
|
||||||
|
@ -28,7 +28,7 @@
|
||||||
# git-related
|
# git-related
|
||||||
git-preview
|
git-preview
|
||||||
tig
|
tig
|
||||||
(pkgs.callPackage ./init-host {})
|
# (pkgs.callPackage ./init-host {})
|
||||||
# used more than once
|
# used more than once
|
||||||
imagemagick
|
imagemagick
|
||||||
qrencode
|
qrencode
|
||||||
|
|
|
@ -5,7 +5,8 @@
|
||||||
# ./steam.nix
|
# ./steam.nix
|
||||||
];
|
];
|
||||||
users.users.makefu.packages = with pkgs; [
|
users.users.makefu.packages = with pkgs; [
|
||||||
games-user-env
|
# kaputt:
|
||||||
|
# games-user-env
|
||||||
wine
|
wine
|
||||||
pkg2zip
|
pkg2zip
|
||||||
steam
|
steam
|
||||||
|
|
|
@ -5,7 +5,8 @@
|
||||||
mosh
|
mosh
|
||||||
sshfs
|
sshfs
|
||||||
rclone
|
rclone
|
||||||
(pkgs.callPackage ./secrets.nix {})
|
|
||||||
|
# (pkgs.callPackage ./secrets.nix {})
|
||||||
|
|
||||||
opensc pcsctools libu2f-host
|
opensc pcsctools libu2f-host
|
||||||
];
|
];
|
||||||
|
|
|
@ -31,6 +31,9 @@ in mkIf (hasAttr "wiregrill" config.krebs.build.host.nets) {
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# host secret
|
||||||
|
sops.secrets."wiregrill.key" = {};
|
||||||
|
|
||||||
services.dnsmasq = mkIf isRouter {
|
services.dnsmasq = mkIf isRouter {
|
||||||
enable = true;
|
enable = true;
|
||||||
resolveLocalQueries = false;
|
resolveLocalQueries = false;
|
||||||
|
@ -87,7 +90,7 @@ in mkIf (hasAttr "wiregrill" config.krebs.build.host.nets) {
|
||||||
(optional (!isNull self.ip4) self.ip4.addr) ++
|
(optional (!isNull self.ip4) self.ip4.addr) ++
|
||||||
(optional (!isNull self.ip6) self.ip6.addr);
|
(optional (!isNull self.ip6) self.ip6.addr);
|
||||||
listenPort = self.wireguard.port;
|
listenPort = self.wireguard.port;
|
||||||
privateKeyFile = (toString <secrets>) + "/wiregrill.key";
|
privateKeyFile = config.sops.secrets."wiregrill.key".path;
|
||||||
allowedIPsAsRoutes = true;
|
allowedIPsAsRoutes = true;
|
||||||
peers = mapAttrsToList
|
peers = mapAttrsToList
|
||||||
(_: host: {
|
(_: host: {
|
||||||
|
|
Loading…
Reference in a new issue