diff --git a/README.md b/README.md index 1aadc6d..c0e206f 100644 --- a/README.md +++ b/README.md @@ -1,3 +1,5 @@ +[![Please don't upload to GitHub](https://nogithub.codeberg.page/badge.svg)](https://nogithub.codeberg.page) + # iac diff --git a/hosts/common-vm.nix b/hosts/common-vm.nix new file mode 100644 index 0000000..835a9eb --- /dev/null +++ b/hosts/common-vm.nix @@ -0,0 +1,31 @@ +{ ... }: + +{ + boot = {}; # TODO: add kernel modules + + fileSystems = { + "/" = { + device = "/dev/disk/by-label/ROOT"; + fsType = "ext4"; + options = [ "discard" "noatime" ]; + }; + "/boot" = { + device = "/dev/disk/by-label/BOOT"; + fsType = "vfat"; + options = [ "fmask=0022" "dmask=0022" "discard" "noatime" ]; + }; + }; + + #swapDevices = [{ device = "/dev/disk/by-label/SWAP"; }]; + + networking = { + domain = "k8s.xengi.de"; + defaultGateway6 = { + address = "2a00:1328:e101:1300::1"; # TODO: use host network + interface = "ens3"; # TODO: use correct interface name + }; + }; + + virtualisation.qemu.guestAgent.enable = true; +} + diff --git a/hosts/common.nix b/hosts/common.nix index 60af7b9..8f94339 100644 --- a/hosts/common.nix +++ b/hosts/common.nix @@ -1,9 +1,21 @@ { config, lib, pkgs, ... }: { + nix = { + optimise = { + automatic = true; + }; + settings = { + auto-optimise-store = true; + experimental-features = [ "nix-command" "flakes" ]; + }; + gc = { + automatic = true; + options = "--delete-older-than 7d"; + }; + }; + boot = { - initrd.availableKernelModules = [ "ahci" "xhci_pci" "ehci_pci" "megaraid_sas" "nvme" "usbhid" "usb_storage" "sd_mod" "sr_mod" ]; - kernelModules = [ "kvm-intel" ]; loader = { systemd-boot.enable = true; efi.canTouchEfiVariables = true; @@ -11,23 +23,34 @@ kernelPackages = pkgs.linuxPackages_latest; }; - fileSystems = { - "/" = { - device = "/dev/disk/by-label/ROOT"; - fsType = "ext4"; - options = [ "discard" "noatime" ]; - }; - "/boot" = { - device = "/dev/disk/by-label/BOOT"; - fsType = "vfat"; - options = [ "fmask=0022" "dmask=0022" "discard" "noatime" ]; - }; + networking = { + search = [ "xengi.de" ]; + useNetworkd = true; + nftables.enable = true; + dhcpcd.enable = false; + useDHCP = false; + nameservers = [ + "2606:4700:4700::1111#one.one.one.one" + "2620:fe::fe#dns.quad9.net" + ]; + firewall.enable = true; }; - swapDevices = []; + services.resolved = { + enable = true; + fallbackDns = [ + "1.1.1.1#one.one.one.one" + "9.9.9.9#dns.quad9.net" + ]; + llmnr = "false"; + extraConfig = '' + MulticastDNS=false + ''; + dnssec = "allow-downgrade"; + dnsovertls = "true"; #"opportunistic"; + }; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; - hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; time.timeZone = "Europe/Berlin"; @@ -36,6 +59,7 @@ useXkbConfig= true; }; +<<<<<<< HEAD users.users.root.openssh.authorizedKeys.keys = [ "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICW1+Ml8R9x1LCJaZ8bIZ1qIV4HCuZ6x7DziFW+0Nn5T xengi@kanae_2022-12-09" "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICmb+mJfo84IagUaRoDEqY9ROjjQUOQ7tMclpN6NDPrX xengi@kota_2022-01-16" @@ -50,5 +74,34 @@ vim ]; + programs = { + vim = { + enable = true; + defaultEditor = true; + }; + mtr.enable = true; + htop = { + enable = true; + settings = { + highlight_base_name = true; + show_cpu_frequency = true; + show_cpu_temperature = true; + update_process_names = true; + color_scheme = "6"; + }; + }; + tmux = { + enable = true; + terminal = "screen-256color"; + shortcut = "a"; + plugins = with pkgs.tmuxPlugins; [ sensible ]; + newSession = true; + historyLimit = 10000; + clock24 = true; + }; + }; + + security.sudo.execWheelOnly = true; + system.stateVersion = "26.05"; } diff --git a/hosts/control-plane-01/default.nix b/hosts/control-plane-01/default.nix new file mode 100644 index 0000000..7939593 --- /dev/null +++ b/hosts/control-plane-01/default.nix @@ -0,0 +1,13 @@ +{ ... }: + +{ + imports = [ + ../common.nix + ../common-vm.nix + ../../services/openssh.nix + ../../services/etcd.nix + ]; + + nix.optimise.dates = [ "01:00" ]; +} + diff --git a/hosts/control-plane-02/default.nix b/hosts/control-plane-02/default.nix new file mode 100644 index 0000000..00342a7 --- /dev/null +++ b/hosts/control-plane-02/default.nix @@ -0,0 +1,13 @@ +{ ... }: + +{ + imports = [ + ../common.nix + ../common-vm.nix + ../../services/openssh.nix + ../../services/etcd.nix + ]; + + nix.optimise.dates = [ "02:00" ]; +} + diff --git a/hosts/control-plane-03/default.nix b/hosts/control-plane-03/default.nix new file mode 100644 index 0000000..93a191e --- /dev/null +++ b/hosts/control-plane-03/default.nix @@ -0,0 +1,13 @@ +{ ... }: + +{ + imports = [ + ../common.nix + ../common-vm.nix + ../../services/openssh.nix + ../../services/etcd.nix + ]; + + nix.optimise.dates = [ "03:00" ]; +} + diff --git a/hosts/kaede/default.nix b/hosts/kaede/default.nix index 5187f2d..eb9385e 100644 --- a/hosts/kaede/default.nix +++ b/hosts/kaede/default.nix @@ -1,12 +1,87 @@ -{ ... }: +{ config, lib, pkgs, ... }: { imports = [ +<<<<<<< HEAD ./base.nix ./hardware.nix ./networking.nix ./users.nix ./programs.nix ./services.nix + ../../services/openssh.nix ]; + + nix.optimise.dates = [ "00:00" ]; + + boot = { + initrd.availableKernelModules = [ "ahci" "xhci_pci" "ehci_pci" "megaraid_sas" "nvme" "usbhid" "usb_storage" "sd_mod" "sr_mod" ]; + kernelModules = [ "kvm-intel" ]; + swraid = { + enable = true; + mdadmConf = '' + ARRAY /dev/md/ROOT metadata=1.2 UUID=acd8260f-e30f-2f3f-74f7-e51ee905a498 + MAILADDR root@localhost + ''; + }; + #kernel.sysctl = { + # "net.ipv4.ip_forward" = true; + # "net.ipv4.conf.all.forwarding" = true; + #}; + }; + + networking = { + hostName = "kaede"; + domain = "xengi.de"; + search = [ "xengi.de" ]; + defaultGateway6 = { + address = "2a00:1328:e100:1::6c"; + interface = "eno3"; + }; + defaultGateway = { + address = "217.115.0.182"; + interface = "eno3"; + }; + interfaces.eno3 = { + ipv6.addresses = [{ address = "2a00:1328:e100:1::6d"; prefixLength = 127; }]; + ipv4.addresses = [{ address = "217.115.0.183"; prefixLength = 31; }]; + }; + }; + + fileSystems = { + "/" = { + device = "/dev/disk/by-uuid/e44cfa13-868e-4d26-b3de-5a8ae92bb055"; + fsType = "ext4"; + options = [ "discard" "noatime" ]; + }; + "/boot" = { + device = "/dev/disk/by-uuid/AD5C-950B"; + fsType = "vfat"; + options = [ "fmask=0022" "dmask=0022" "discard" "noatime" ]; + }; + }; + + swapDevices = [ + { device = "/dev/disk/by-uuid/e8825b01-f91e-4c4f-8916-bffeb6fac0cd"; } + { device = "/dev/disk/by-uuid/5b53c0b9-ab57-4992-8e81-957e19c7b685"; } + ]; + + virtualisation.libvirtd = { + enable = true; + nss.enableGuest = true; + startDelay = 1; + onShutdown = "shutdown"; + }; + + services.openssh.banner = '' + __ __ __ + /'__`\ /\ \ /'_ `\ + ___ /\_\L\ \\ \ \/'\ /\ \L\ \ ____ + /'___\/_/_\_<_\ \ , < \/_> _ <_ /',__\ + /\ \__/ /\ \L\ \\ \ \\`\ /\ \L\ \/\__, `\ + \ \____\\ \____/ \ \_\ \_\ \____/\/\____/ + \/____/ \/___/ \/_/\/_/\/___/ \/___/ + ''; + + system.stateVersion = "25.11"; } diff --git a/hosts/worker-01/default.nix b/hosts/worker-01/default.nix new file mode 100644 index 0000000..97fcc13 --- /dev/null +++ b/hosts/worker-01/default.nix @@ -0,0 +1,13 @@ +{ ... }: + +{ + imports = [ + ../common.nix + ../common-vm.nix + ../../services/openssh.nix + ../../services/etcd.nix + ]; + + nix.optimise.dates = [ "04:00" ]; +} + diff --git a/hosts/worker-02/default.nix b/hosts/worker-02/default.nix new file mode 100644 index 0000000..71ccf0a --- /dev/null +++ b/hosts/worker-02/default.nix @@ -0,0 +1,13 @@ +{ ... }: + +{ + imports = [ + ../common.nix + ../common-vm.nix + ../../services/openssh.nix + ../../services/etcd.nix + ]; + + nix.optimise.dates = [ "05:00" ]; +} + diff --git a/hosts/worker-03/default.nix b/hosts/worker-03/default.nix new file mode 100644 index 0000000..952ce5b --- /dev/null +++ b/hosts/worker-03/default.nix @@ -0,0 +1,13 @@ +{ ... }: + +{ + imports = [ + ../common.nix + ../common-vm.nix + ../../services/openssh.nix + ../../services/etcd.nix + ]; + + nix.optimise.dates = [ "06:00" ]; +} + diff --git a/hosts/worker-04/default.nix b/hosts/worker-04/default.nix new file mode 100644 index 0000000..bb4089f --- /dev/null +++ b/hosts/worker-04/default.nix @@ -0,0 +1,13 @@ +{ ... }: + +{ + imports = [ + ../common.nix + ../common-vm.nix + ../../services/openssh.nix + ../../services/etcd.nix + ]; + + nix.optimise.dates = [ "07:00" ]; +} + diff --git a/hosts/worker-05/default.nix b/hosts/worker-05/default.nix new file mode 100644 index 0000000..23b5991 --- /dev/null +++ b/hosts/worker-05/default.nix @@ -0,0 +1,13 @@ +{ ... }: + +{ + imports = [ + ../common.nix + ../common-vm.nix + ../../services/openssh.nix + ../../services/etcd.nix + ]; + + nix.optimise.dates = [ "08:00" ]; +} + diff --git a/nixosConfigurations.nix b/nixosConfigurations.nix index 7cc9cc9..2b1d4a2 100644 --- a/nixosConfigurations.nix +++ b/nixosConfigurations.nix @@ -21,7 +21,6 @@ let #}; }; } - ./hosts/common.nix ]; mkSystem = extraModules: @@ -32,21 +31,17 @@ let mkControlPlaneNode = extraModules: mkSystem ([ - #./services/etcd.nix - #./services/k8s.nix - #./services/k8s-apiserver.nix - #./services/k8s-controller-manager.nix - #./services/k8s-kubelet.nix - #./services/k8s-proxy.nix - #./services/k8s-scheduler.nix + { + age.secrets = {}; + } ] ++ extraModules); mkWorkerNode = extraModules: mkSystem ([ - #./services/k8s.nix - #./services/k8s-kubelet.nix - #./services/k8s-proxy.nix + { + age.secrets = {}; + } ] ++ extraModules); in @@ -58,12 +53,53 @@ in ./hosts/kaede ]; }; - "master-01" = mkControlPlaneNode [ ]; - "master-02" = mkControlPlaneNode [ ]; - "master-03" = mkControlPlaneNode [ ]; - "worker-01" = mkWorkerNode [ ]; - "worker-02" = mkWorkerNode [ ]; - "worker-03" = mkWorkerNode [ ]; - "worker-04" = mkWorkerNode [ ]; - "worker-05" = mkWorkerNode [ ]; + "control-plane-01" = mkControlPlaneNode [ + { + age.secrets = {}; + } + ./hosts/control-plane-01 + ]; + "control-plane-02" = mkControlPlaneNode [ + { + age.secrets = {}; + } + ./hosts/control-plane-02 + ]; + "control-plane-03" = mkControlPlaneNode [ + { + age.secrets = {}; + } + ./hosts/control-plane-03 + ]; + "worker-01" = mkWorkerNode [ + { + age.secrets = {}; + } + ./hosts/worker-01 + ]; + "worker-02" = mkWorkerNode [ + { + age.secrets = {}; + } + ./hosts/worker-02 + ]; + "worker-03" = mkWorkerNode [ + { + age.secrets = {}; + } + ./hosts/worker-03 + ]; + "worker-04" = mkWorkerNode [ + { + age.secrets = {}; + } + ./hosts/worker-04 + ]; + "worker-05" = mkWorkerNode [ + { + age.secrets = {}; + } + ./hosts/worker-05 + ]; } + diff --git a/services/etcd.nix b/services/etcd.nix index 4e19b07..d374a48 100644 --- a/services/etcd.nix +++ b/services/etcd.nix @@ -21,9 +21,12 @@ in #keyFile = config.age.secrets.etcd_server_key.path; #certFile = config.age.secrets.etcd_server_key.path; }; +<<<<<<< HEAD networking.firewall.extraInputRules = '' ip6 saddr {${controlPlaneIpSet} ip6 daddr ${ip} tcp dport 2380 accept comment "Allow etcd peers" ip6 saddr {${controlPlaneIpSet} ip6 daddr ${ip} tcp dport 2379 accept comment "Allow etcd clients" ''; +======= +>>>>>>> b9de4f3c256492a785e296898739a5e4674025fc } diff --git a/services/openssh.nix b/services/openssh.nix new file mode 100644 index 0000000..18fee9f --- /dev/null +++ b/services/openssh.nix @@ -0,0 +1,16 @@ +{ ... }: + +{ + services = { + openssh = { + enable = true; + ports = [ 10022 ]; + openFirewall = true; + settings = { + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + }; + }; + }; +} +