Compare commits

..
12 changed files with 5 additions and 271 deletions

Binary file not shown.

Before

Width:  |  Height:  |  Size: 128 KiB

View file

@ -59,19 +59,9 @@
useXkbConfig= true;
};
<<<<<<< HEAD
users.users.root.openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICW1+Ml8R9x1LCJaZ8bIZ1qIV4HCuZ6x7DziFW+0Nn5T xengi@kanae_2022-12-09"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICmb+mJfo84IagUaRoDEqY9ROjjQUOQ7tMclpN6NDPrX xengi@kota_2022-01-16"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICyklb7dvEHH0VBEMmTUQFKHN6ekBQqkDKj09+EilUIQ xengi@lucy_2018-09-08"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICjv9W8WXq9QGkgmANNPQR24/I1Pm1ghxNIHftEI+jlZ xengi@mayu_2021-06-11"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGhyfD+8jMl6FDSADb11sfAsJk0KNoVzjjiDRZjUOtmf xengi@nana_2019-08-16"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMPtGqhV7io3mhIoZho4Yf7eCo0sUZvjT2NziM2PkXSo xengi@nyu_2017-10-11"
];
environment.systemPackages = with pkgs; [
git
vim
git
];
programs = {
@ -102,6 +92,5 @@
};
security.sudo.execWheelOnly = true;
system.stateVersion = "26.05";
}

View file

@ -1,5 +0,0 @@
{}:
{
imports = [../common.nix];
}

View file

@ -1,67 +0,0 @@
{ config, lib, pkgs, ... }:
{
boot = {
initrd.availableKernelModules = [ "ahci" "xhci_pci" "ehci_pci" "megaraid_sas" "nvme" "usb_storage" "usbhid" "sd_mod" "sr_mod" ];
kernelModules = [ "kvm-intel" ];
loader = {
systemd-boot.enable = true;
efi.canTouchEfiVariables = true;
};
kernelPackages = pkgs.linuxPackages_latest;
swraid = {
enable = true;
mdadmConf = ''
ARRAY /dev/md/ROOT metadata=1.2 UUID=41506d64-f386-474c-abe1-0142d9c57d84
MAILADDR root@localhost
'';
};
};
fileSystems = {
"/" = {
device = "/dev/disk/by-uuid/41506d64-f386-474c-abe1-0142d9c57d84";
fsType = "ext4";
options = [ "discard" "noatime" ];
};
"/boot" = {
device = "/dev/disk/by-uuid/49B7-9286";
fsType = "vfat";
options = [ "fmask=0022" "dmask=0022" "discard" "noatime" ];
};
};
swapDevices = [
{ device = "/dev/disk/by-uuid/5b53c0b9-ab57-4992-8e81-957e19c7b685"; }
{ device = "/dev/disk/by-uuid/e8825b01-f91e-4c4f-8916-bffeb6fac0cd"; }
];
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
time.timeZone = "Europe/Berlin";
console = {
font = "Lat2-Terminus16";
useXkbConfig= true;
};
environment.systemPackages = with pkgs; [
git
vim
];
virtualisation = {
#useEFIBoot = true;
libvirtd = {
enable = true;
nss.enableGuest = true;
startDelay = 1;
onShutdown = "shutdown";
};
};
#rootDevice = "/dev/disk/by-label/nixos";
#mountHostNixStore = true;
system.stateVersion = "26.05";
}

View file

@ -2,13 +2,7 @@
{
imports = [
<<<<<<< HEAD
./base.nix
./hardware.nix
./networking.nix
./users.nix
./programs.nix
./services.nix
../common.nix
../../services/openssh.nix
];
@ -85,3 +79,4 @@
system.stateVersion = "25.11";
}

View file

@ -1,49 +0,0 @@
{ ... }:
{
swapDevices = [];
hardware = {
graphics = {
enable = true;
extraPackages = with pkgs; [
intel-media-driver
intel-ocl
intel-vaapi-driver
];
};
nvidia = {
# Modesetting is required.
modesetting.enable = true;
# Nvidia power management. Experimental, and can cause sleep/suspend to fail.
powerManagement.enable = false;
# Fine-grained power management. Turns off GPU when not in use.
# Experimental and only works on modern Nvidia GPUs (Turing or newer).
powerManagement.finegrained = false;
# Use the NVidia open source kernel module (not to be confused with the
# independent third-party "nouveau" open source driver).
# Support is limited to the Turing and later architectures. Full list of
# supported GPUs is at:
# https://github.com/NVIDIA/open-gpu-kernel-modules#compatible-gpus
# Only available from driver 515.43.04+
# Do not disable this unless your GPU is unsupported or if you have a good reason to.
open = true;
# Enable the Nvidia settings menu,
# accessible via `nvidia-settings`.
nvidiaSettings = false;
# Update for NVIDA GPU headless mode, i.e. nvidia-persistenced.
# It ensures all GPUs stay awake even during headless mode.
nvidiaPersistenced = true;
# Optionally, you may need to select the appropriate driver version for your specific GPU.
package = config.boot.kernelPackages.nvidiaPackages.stable;
#package = config.boot.kernelPackages.nvidiaPackages.mkDriver {
# version = "565.57.01";
# sha256_64bit = "sha256-8pMskvrdQ8WyNBvkU/xPc/CtcYXCa7ekP73oGuKfH+M=";
# sha256_aarch64 = "sha256-s8ZAVKvRNXpjxRYqM3E5oss5FdqW+tv1qQC2pDjfG+s=";
# openSha256 = "sha256-/32Zf0dKrofTmPZ3Ratw4vDM7B+OgpC4p7s+RHUjCrg=";
# settingsSha256 = "sha256-kQsvDgnxis9ANFmwIwB7HX5MkIAcpEEAHc8IBOLdXvk=";
# persistencedSha256 = "sha256-E2J2wYYyRu7Kc3MMZz/8ZIemcZg68rkzvqEwFAL3fFs=";
#};
};
};
}

View file

@ -1,42 +0,0 @@
{ ... }:
{
networking = {
hostName = "k8s";
domain = "berlin.ccc.de";
search = [ "berlin.ccc.de" ];
useNetworkd = true;
dhcpcd.enable = false;
nftables.enable = true;
useDHCP = false;
nameservers = [
"2001:678:560:42::1"
];
defaultGateway6 = {
address = "fe80::6eb3:11ff:fe11:8f55";
interface = "eno4";
};
defaultGateway = {
address = "195.160.172.5";
interface = "eno4";
};
interfaces.eno3 = {
ipv6.addresses = [{ address = "2001:678:560:42::88"; prefixLength = 64; }];
ipv4.addresses = [{ address = "195.160.172.88"; prefixLength = 24; }];
};
firewall.enable = true;
};
services.resolved = {
enable = true;
settings.Resolve = {
DNSOverTLS = "opportunistic";
DNSSEC = "allow-downgrade";
FallbackDNS = [
"2606:4700:4700::1111#one.one.one.one"
"1.1.1.1#one.one.one.one"
];
LLMNR = true;
MulticastDNS = true;
};
};
}

View file

@ -1,29 +0,0 @@
{ pkgs, ... }:
{
programs = {
vim = {
enable = true;
defaultEditor = true;
};
htop = {
enable = true;
settings = {
highlight_base_name = true;
show_cpu_frequency = true;
show_cpu_temperature = true;
update_process_names = true;
color_scheme = "6";
};
};
tmux = {
enable = true;
terminal = "screen-256color";
shortcut = "a";
plugins = with pkgs.tmuxPlugins; [ sensible ];
newSession = true;
historyLimit = 10000;
clock24 = true;
};
};
}

View file

@ -1,24 +0,0 @@
{ ... }:
{
services = {
openssh = {
enable = true;
ports = [ 10022 ];
openFirewall = true;
banner = ''
__ __ __
/'__`\ /\ \ /'_ `\
___ /\_\L\ \\ \ \/'\ /\ \L\ \ ____
/'___\/_/_\_<_\ \ , < \/_> _ <_ /',__\
/\ \__/ /\ \L\ \\ \ \\`\ /\ \L\ \/\__, `\
\ \____\\ \____/ \ \_\ \_\ \____/\/\____/
\/____/ \/___/ \/_/\/_/\/___/ \/___/
'';
settings = {
PasswordAuthentication = false;
KbdInteractiveAuthentication = false;
};
};
};
}

View file

@ -1,5 +0,0 @@
{}:
{
imports = [../common.nix];
}

View file

@ -1,32 +1,8 @@
{ config, pkgs, ... }:
{ pkgs, ... }:
let
ip = (builtins.head config.networking.interfaces.enp1s0.ipv6.addresses).address;
controlPlaneIps = ["fd00::1" "fd00::2" "fd00::3"];
controlPlaneIpSet = builtins.concatStringsSep ", " controlPlaneIps;
in
{
services.etcd = {
enable = true;
package = pkgs.etcd_3_6;
trustedCaFile = config.age.secrets.etcd_ca_crt.path;
peerTrustedCaFile = config.age.secrets.etcd_peer_ca_crt.path;
peerClientCertAuth = true;
listenPeerUrls = ["https://[${ip}]:2380"];
listenClientUrls = ["https://[${ip}]:2379"];
initialCluster = ["${config.services.etcd.name}=https://${ip}:2380"];
clientCertAuth = true;
#peerKeyFile = config.age.secrets.etcd_peer_key.path;
#peerCertFile = config.age.secrets.etcd_peer_crt.path;
#keyFile = config.age.secrets.etcd_server_key.path;
#certFile = config.age.secrets.etcd_server_key.path;
};
<<<<<<< HEAD
networking.firewall.extraInputRules = ''
ip6 saddr {${controlPlaneIpSet} ip6 daddr ${ip} tcp dport 2380 accept comment "Allow etcd peers"
ip6 saddr {${controlPlaneIpSet} ip6 daddr ${ip} tcp dport 2379 accept comment "Allow etcd clients"
'';
=======
>>>>>>> b9de4f3c256492a785e296898739a5e4674025fc
}

5
vm.nix
View file

@ -1,5 +0,0 @@
{ ... }:
{
virtualisation.qemu.guestAgent.enable = true;
}