Compare commits

16 Commits
Author SHA1 Message Date
fen 68317127ba goyplex-vm: disable k3s network-policy controller (kube-router fwmark 0x20000 collides with netbird routing-peer mark 0x1bd20; no NetworkPolicies in use) 2026-09-09 20:29:43 -05:00
poslop 53b6e300d2 core: add netbird package 2026-09-05 09:32:39 -05:00
poslop 223b1c52f3 goyplex-vm: add fen user (key + NOPASSWD sudo), fix rebuild.sh host, retire hermes input 2026-09-05 09:16:55 -05:00
poslop 8ac8e29256 hermes: remove module, secrets, flake input, and host entry (VM to be decommissioned) 2026-09-04 15:05:49 -05:00
poslop 804764f874 hermes: retire agent service from hermes-vm (migrated to fen-vm) 2026-09-04 15:05:23 -05:00
poslop 564b974d34 flake: update lock (nixpkgs/aquamarine bumps) 2026-09-04 15:03:26 -05:00
poslop 9b9cdb1795 hosts: static IPs for goyplex-vm (10.0.1.47) and hermes-vm (10.0.1.140) via NM ensureProfiles in per-host custom.nix 2026-08-28 17:05:41 +00:00
poslop 1422f3ce5c Merge remote-tracking branch 'origin/dev' 2026-08-28 14:31:46 +00:00
poslop a6bea2a0e6 Merge branch 'dev' of https://git.archfox.org/poslop/rice-flakes into dev 2026-08-28 14:29:58 +00:00
poslop cce057cb6c agenix: use stdenv.hostPlatform.system, fixes eval warning 2026-08-28 14:29:46 +00:00
poslop 89b08bad3f Merge branch 'dev' of https://git.archfox.org/poslop/rice-flakes into dev 2026-08-28 09:23:09 -05:00
poslop 4f777a9b96 hermes: glm-5.3-flash delegation, drop auxiliary block; flake.lock bump (live system state) 2026-08-28 09:23:08 -05:00
poslop 041a8a36af remove write test file 2026-08-28 14:22:26 +00:00
poslop f885cd0e55 Merge branch 'dev' of https://git.archfox.org/poslop/rice-flakes into dev 2026-08-28 14:22:06 +00:00
poslop 3d15148c77 roles: add role-based host composition in flake
- mkHost now takes a role list, roles resolve to ./roles/<name>.nix
- roles/core.nix = shared baseline (modules/)
- roles/k3s-server.nix = core + k3s (goyplex-vm)
- roles/hermes.nix = core + hermes (hermes-vm)
- host configuration.nix trimmed to hardware + boot + stateVersion
- optional hosts/<name>/custom.nix loads last for per-host overrides
- new hosts: one flake line + hosts/<name>/ dir
2026-08-28 14:13:43 +00:00
poslop 35b065ec49 Merge pull request 'Dev' (#2) from dev into master
Reviewed-on: #2
2026-07-23 12:48:53 -05:00
26 changed files with 162 additions and 416 deletions
-1
View File
@@ -1 +0,0 @@
test
Generated
+26 -205
View File
@@ -41,11 +41,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464219, "lastModified": 1788444081,
"narHash": "sha256-WKqWL8r7CyTDYueTr2ffJ9ya50dellv6IR1JX5PghDY=", "narHash": "sha256-I8i97p9WBQaZQyyBaHFMt8e01VfgfFZSaO+vAUd0u0A=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "aquamarine", "repo": "aquamarine",
"rev": "f3d1804205e8158c15595cdda1b566f93349ffae", "rev": "36b66db4ddd708ad19f5db850af6a478d8a19b2a",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -92,51 +92,6 @@
"type": "github" "type": "github"
} }
}, },
"flake-parts": {
"inputs": {
"nixpkgs-lib": [
"hermes-agent",
"nixpkgs"
]
},
"locked": {
"lastModified": 1782949081,
"narHash": "sha256-vp6Y/Grm98ESt6ceOkWiHWyZRDV3J1RID4w+6NWK9yA=",
"owner": "hercules-ci",
"repo": "flake-parts",
"rev": "17c9d6cdfc60c64f4ee8d306f9bc0b4ccb51481e",
"type": "github"
},
"original": {
"owner": "hercules-ci",
"repo": "flake-parts",
"type": "github"
}
},
"hermes-agent": {
"inputs": {
"flake-parts": "flake-parts",
"home-manager": "home-manager_2",
"nixpkgs": "nixpkgs_2",
"npm-lockfile-fix": "npm-lockfile-fix",
"pyproject-build-systems": "pyproject-build-systems",
"pyproject-nix": "pyproject-nix",
"uv2nix": "uv2nix"
},
"locked": {
"lastModified": 1787314587,
"narHash": "sha256-oeFJlEoFybqKkbuWT4mW8PRauusjt3y44ZJXAcA7TPY=",
"owner": "NousResearch",
"repo": "hermes-agent",
"rev": "fcbd1076a93841fa88855acce810e342a5b78101",
"type": "github"
},
"original": {
"owner": "NousResearch",
"repo": "hermes-agent",
"type": "github"
}
},
"hjem": { "hjem": {
"inputs": { "inputs": {
"nixpkgs": [ "nixpkgs": [
@@ -144,11 +99,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1787194407, "lastModified": 1787500880,
"narHash": "sha256-hMgbN6InoW+S5G/cqGrVwHUmOJcGIT/yUg1Xe6y7t8Q=", "narHash": "sha256-UrAlku7KST0DT+j1bdVGYI8tCz23PWL88uGMer3IZ2U=",
"owner": "feel-co", "owner": "feel-co",
"repo": "hjem", "repo": "hjem",
"rev": "7cd7f1c567beaf5527781e0b51647a98acde54e6", "rev": "d248f0e4f7abd6e1f0eb9ace778dd7928481943e",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -201,27 +156,6 @@
"type": "github" "type": "github"
} }
}, },
"home-manager_2": {
"inputs": {
"nixpkgs": [
"hermes-agent",
"nixpkgs"
]
},
"locked": {
"lastModified": 1786487128,
"narHash": "sha256-ad60hrRVhH/bo3Jl1YLzO+QcS3mUNZr9LNJdzhMO2P4=",
"owner": "nix-community",
"repo": "home-manager",
"rev": "f404edbfa4117810c96b97048299242fc50e5362",
"type": "github"
},
"original": {
"owner": "nix-community",
"repo": "home-manager",
"type": "github"
}
},
"hyprcursor": { "hyprcursor": {
"inputs": { "inputs": {
"hyprlang": [ "hyprlang": [
@@ -291,17 +225,17 @@
"hyprutils": "hyprutils", "hyprutils": "hyprutils",
"hyprwayland-scanner": "hyprwayland-scanner", "hyprwayland-scanner": "hyprwayland-scanner",
"hyprwire": "hyprwire", "hyprwire": "hyprwire",
"nixpkgs": "nixpkgs_3", "nixpkgs": "nixpkgs_2",
"pre-commit-hooks": "pre-commit-hooks", "pre-commit-hooks": "pre-commit-hooks",
"systems": "systems_2", "systems": "systems_2",
"xdph": "xdph" "xdph": "xdph"
}, },
"locked": { "locked": {
"lastModified": 1787311583, "lastModified": 1788607141,
"narHash": "sha256-EXpfUX7oLzqwd+m/T1TvH/rHwnTNtZL+TZ5wiCwklMo=", "narHash": "sha256-yjVNYxNkV7KST+K1kW0i4uts2KvZDuK98oot12xHJQ0=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "Hyprland", "repo": "Hyprland",
"rev": "0f97a22d1172d8fbd77834ec932383ed18110edb", "rev": "2eb5180c6f258bb73c4b9b71a1361dede0e1453e",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -474,11 +408,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464080, "lastModified": 1786903207,
"narHash": "sha256-W1hxvumEM57yV+QwsZ4QdAHEqOkr7e4S8VAkLX60qDE=", "narHash": "sha256-QTwMqLLONRhv9iz6CVeuX6BqQNQCIqI8hL/cPYlR/24=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "hyprutils", "repo": "hyprutils",
"rev": "c157fe1e3092b980cc69315a6631f89aff09dcce", "rev": "6cf50415e06dc6bd9f1252f1b745eac6b4a1cc39",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -559,11 +493,11 @@
}, },
"nixpkgs_2": { "nixpkgs_2": {
"locked": { "locked": {
"lastModified": 1785318670, "lastModified": 1788404924,
"narHash": "sha256-dN6Ou5x/+23FZLEpYP3IffO+NyJFzUlGumt1uu3MMaY=", "narHash": "sha256-lhEhY8X5EgkQ/eg6IFz4cc8jRuSYSvnxx1al7d1dvZ0=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "0954f7ee2f6bb3dc7d4e3d0d8bcb8fd4bde4cfc5", "rev": "0968519e14f7aa7d3e9b389682bd74d2b51c8ce8",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -575,27 +509,11 @@
}, },
"nixpkgs_3": { "nixpkgs_3": {
"locked": { "locked": {
"lastModified": 1786247143, "lastModified": 1788531059,
"narHash": "sha256-8S3Kcxs7D4UtxJxSJZz0m14CGhuW0MxfrIwJxeGWGnQ=", "narHash": "sha256-hLD4l3QOGBQhkVp3mQ2lJ/YbEi99qUgKapb40KovZ88=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "279b4a8275f032c566576b3f181fa0f27197f588",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"nixpkgs_4": {
"locked": {
"lastModified": 1787135253,
"narHash": "sha256-RD2kNWCG+Bjo6h+JVjWVNntZs2GtRoeY2xHjts/FNkA=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "ffb3c9b700e759be2ef13237c9d8f953b32a1e46", "rev": "801bef6abd86b91e51083066b83fb354a11fc640",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -605,27 +523,6 @@
"type": "github" "type": "github"
} }
}, },
"npm-lockfile-fix": {
"inputs": {
"nixpkgs": [
"hermes-agent",
"nixpkgs"
]
},
"locked": {
"lastModified": 1775903712,
"narHash": "sha256-2GV79U6iVH4gKAPWYrxUReB0S41ty/Y3dBLquU8AlaA=",
"owner": "jeslie0",
"repo": "npm-lockfile-fix",
"rev": "c6093acb0c0548e0f9b8b3d82918823721930fe8",
"type": "github"
},
"original": {
"owner": "jeslie0",
"repo": "npm-lockfile-fix",
"type": "github"
}
},
"pre-commit-hooks": { "pre-commit-hooks": {
"inputs": { "inputs": {
"flake-compat": "flake-compat", "flake-compat": "flake-compat",
@@ -635,11 +532,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1784288435, "lastModified": 1788267358,
"narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=", "narHash": "sha256-nt+lUqYVpc9Y6JeMd2WmXzCDojasdadKo0mWcluvY2Y=",
"owner": "cachix", "owner": "cachix",
"repo": "git-hooks.nix", "repo": "git-hooks.nix",
"rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9", "rev": "27555e2624241fb116b49095df4caaee85a25691",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -648,64 +545,13 @@
"type": "github" "type": "github"
} }
}, },
"pyproject-build-systems": {
"inputs": {
"nixpkgs": [
"hermes-agent",
"nixpkgs"
],
"pyproject-nix": [
"hermes-agent",
"pyproject-nix"
],
"uv2nix": [
"hermes-agent",
"uv2nix"
]
},
"locked": {
"lastModified": 1785115949,
"narHash": "sha256-8AM37BfyGaL2v/SZyg4PupRxJ01Y4htvM+WrTjWrPpo=",
"owner": "pyproject-nix",
"repo": "build-system-pkgs",
"rev": "62c0d86027edb1c4f39a5facc09876348144f7c9",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "build-system-pkgs",
"type": "github"
}
},
"pyproject-nix": {
"inputs": {
"nixpkgs": [
"hermes-agent",
"nixpkgs"
]
},
"locked": {
"lastModified": 1784591072,
"narHash": "sha256-zP/WaDxrRu8GANZM61+V2LT/7ycEEdoyLWn7M6WzU7M=",
"owner": "pyproject-nix",
"repo": "pyproject.nix",
"rev": "e3b599ca2e7fcf93d4edf65d7f19bbf6491724f3",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "pyproject.nix",
"type": "github"
}
},
"root": { "root": {
"inputs": { "inputs": {
"agenix": "agenix", "agenix": "agenix",
"hermes-agent": "hermes-agent",
"hjem": "hjem", "hjem": "hjem",
"hjem-rum": "hjem-rum", "hjem-rum": "hjem-rum",
"hyprland": "hyprland", "hyprland": "hyprland",
"nixpkgs": "nixpkgs_4" "nixpkgs": "nixpkgs_3"
} }
}, },
"systems": { "systems": {
@@ -738,31 +584,6 @@
"type": "github" "type": "github"
} }
}, },
"uv2nix": {
"inputs": {
"nixpkgs": [
"hermes-agent",
"nixpkgs"
],
"pyproject-nix": [
"hermes-agent",
"pyproject-nix"
]
},
"locked": {
"lastModified": 1785277507,
"narHash": "sha256-9Tq3UDX2hD/aveW/HvkBlAmEwJTOlY5HQXJM+L5BGmE=",
"owner": "pyproject-nix",
"repo": "uv2nix",
"rev": "5a836d395cbf5fc22670eb98dd4aa4fc4d406977",
"type": "github"
},
"original": {
"owner": "pyproject-nix",
"repo": "uv2nix",
"type": "github"
}
},
"xdph": { "xdph": {
"inputs": { "inputs": {
"hyprland-protocols": [ "hyprland-protocols": [
@@ -791,11 +612,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786464334, "lastModified": 1788025068,
"narHash": "sha256-/TBQT5rhBB2Dm4HoZzhGDaCwYmRTs3W3DPhMXFWc/BU=", "narHash": "sha256-TBqronrrc/F2Ry/E37d/1TLldDLJDFNSwvJjgk+cXzU=",
"owner": "hyprwm", "owner": "hyprwm",
"repo": "xdg-desktop-portal-hyprland", "repo": "xdg-desktop-portal-hyprland",
"rev": "9f0e9ff02739cd538d39bd706422dc50e9ca60dd", "rev": "ba31964ee42b56bcb0d3b78a64ead5d8a1c3c6f6",
"type": "github" "type": "github"
}, },
"original": { "original": {
+20 -8
View File
@@ -3,7 +3,6 @@
nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable"; nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable";
hyprland.url = "github:hyprwm/Hyprland"; hyprland.url = "github:hyprwm/Hyprland";
hermes-agent.url = "github:NousResearch/hermes-agent";
agenix.url = "github:ryantm/agenix"; agenix.url = "github:ryantm/agenix";
hjem = { hjem = {
@@ -27,26 +26,39 @@
let let
system = "x86_64-linux"; system = "x86_64-linux";
username = "poslop"; username = "poslop";
lib = nixpkgs.lib;
# mkHost <hostname> <role list>
# roles resolve to ./roles/<name>.nix; list entries may also be
# inline attrsets or paths, which load after (and override) roles.
# hosts/<host>/custom.nix, if present, always loads last.
mkHost = mkHost =
host: modules: name: roles:
nixpkgs.lib.nixosSystem { nixpkgs.lib.nixosSystem {
modules = [ { nixpkgs.hostPlatform = system; } ] ++ modules; modules =
[ { nixpkgs.hostPlatform = system; } ]
++ [ ./hosts/${name}/configuration.nix ]
++ map (
role:
if builtins.isString role then ./roles/${role}.nix else role
) roles
++ lib.optional (builtins.pathExists ./hosts/${name}/custom.nix)
./hosts/${name}/custom.nix;
specialArgs = { specialArgs = {
inherit inherit
self self
inputs inputs
username username
host
; ;
host = name;
}; };
}; };
in in
{ {
nixosConfigurations = { nixosConfigurations = {
nixos-vm2 = mkHost "nixos-vm2" [ ./hosts/nixos-vm2/configuration.nix ]; nixos-vm2 = mkHost "nixos-vm2" [ "core" ];
qemu-vm = mkHost "qemu-vm" [ ./hosts/qemu-vm/configuration.nix ]; qemu-vm = mkHost "qemu-vm" [ "core" ];
goyplex-vm = mkHost "goyplex-vm" [ ./hosts/goyplex-vm/configuration.nix ]; goyplex-vm = mkHost "goyplex-vm" [ "k3s-server" ];
hermes-vm = mkHost "hermes-vm" [ ./hosts/hermes-vm/configuration.nix ];
}; };
}; };
} }
+4 -3
View File
@@ -1,10 +1,11 @@
{ pkgs, ... }: {
pkgs,
...
}:
{ {
imports = [ imports = [
./hardware-configuration.nix ./hardware-configuration.nix
../../modules
../../modules/k3s/k3s.nix
]; ];
boot.loader.systemd-boot.enable = true; boot.loader.systemd-boot.enable = true;
+23
View File
@@ -0,0 +1,23 @@
# per-host overrides: static IP for the k3s edge node
# LAN: 10.0.1.0/24, gw 10.0.1.1, DNS pas 10.0.1.45 + 1.1.1.1
{ ... }:
{
networking.networkmanager.ensureProfiles.environmentFiles = [ ];
networking.networkmanager.ensureProfiles.profiles = {
"ens18-static" = {
connection = {
id = "ens18-static";
type = "ethernet";
interface-name = "ens18";
};
ipv4 = {
method = "manual";
addresses = "10.0.1.47/24";
gateway = "10.0.1.1";
dns = "10.0.1.45;1.1.1.1;";
};
ipv6.method = "disabled";
};
};
}
+4 -3
View File
@@ -1,10 +1,11 @@
{ pkgs, ... }: {
pkgs,
...
}:
{ {
imports = [ imports = [
./hardware-configuration.nix ./hardware-configuration.nix
../../modules/core
../../modules/hermes
]; ];
boot.loader.systemd-boot.enable = true; boot.loader.systemd-boot.enable = true;
+23
View File
@@ -0,0 +1,23 @@
# per-host overrides: static IP for the hermes agent host
# LAN: 10.0.1.0/24, gw 10.0.1.1, DNS pas 10.0.1.45 + 1.1.1.1
{ ... }:
{
networking.networkmanager.ensureProfiles.environmentFiles = [ ];
networking.networkmanager.ensureProfiles.profiles = {
"ens18-static" = {
connection = {
id = "ens18-static";
type = "ethernet";
interface-name = "ens18";
};
ipv4 = {
method = "manual";
addresses = "10.0.1.140/24";
gateway = "10.0.1.1";
dns = "10.0.1.45;1.1.1.1;";
};
ipv6.method = "disabled";
};
};
}
-1
View File
@@ -5,7 +5,6 @@
{ {
imports = [ imports = [
./hardware-configuration.nix ./hardware-configuration.nix
../../modules
]; ];
boot.loader.grub.enable = true; boot.loader.grub.enable = true;
-1
View File
@@ -5,7 +5,6 @@
{ {
imports = [ imports = [
./hardware-configuration.nix ./hardware-configuration.nix
../../modules
]; ];
boot.loader.grub.enable = true; boot.loader.grub.enable = true;
+1 -1
View File
@@ -9,7 +9,7 @@
./timezone.nix ./timezone.nix
./nix.nix ./nix.nix
./program.nix ./program.nix
./user.nix ./users.nix
./ssh.nix ./ssh.nix
]; ];
} }
+3 -3
View File
@@ -1,5 +1,5 @@
{ {
nix.settings = { # nix.settings = {
experimental-features = "nix-command flakes"; # experimental-features = "nix-command flakes";
}; # };
} }
+1
View File
@@ -2,6 +2,7 @@
{ {
environment.systemPackages = with pkgs; [ environment.systemPackages = with pkgs; [
zsh zsh
netbird
]; ];
} }
-14
View File
@@ -1,14 +0,0 @@
{ username, pkgs, ... }:
{
users.users.${username} = {
isNormalUser = true;
description = "${username}";
extraGroups = [
"wheel"
"docker"
];
shell = pkgs.zsh;
};
nix.settings.allowed-users = [ "@wheel" ];
}
+35
View File
@@ -0,0 +1,35 @@
{ username, pkgs, ... }:
{
users.users.${username} = {
isNormalUser = true;
description = "${username}";
extraGroups = [
"wheel"
"docker"
];
shell = pkgs.zsh;
};
users.users.fen = {
isNormalUser = true;
extraGroups = [ "wheel" ];
openssh.authorizedKeys.keys = [
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ8nZT7pA+Wp7mnjKSJPpmYs+tFx5q+gtvOcSSMJt93D fen"
];
};
nix.settings.allowed-users = [ "@wheel" ];
security.sudo.extraRules = [
{
users = [ "fen" ];
commands = [
{
command = "ALL";
options = [ "NOPASSWD" ];
}
];
}
];
}
-7
View File
@@ -1,7 +0,0 @@
{
imports = [
./sudo.nix
./hermes.nix
./secrets
];
}
-128
View File
@@ -1,128 +0,0 @@
{
inputs,
config,
lib,
pkgs,
...
}:
{
imports = [ inputs.hermes-agent.nixosModules.default ];
services.hermes-agent = {
enable = true;
addToSystemPackages = true;
environmentFiles = [
config.age.secrets.hermes-env.path
];
environment = {
BW_SERVERURL = "https://vault.archfox.org";
};
container = {
image = "debian:bookworm";
backend = "docker";
enable = true;
hostUsers = [ "poslop" ];
extraOptions = [
"-p"
"9119:9119"
"-p"
"8642:8642"
"-p"
"9120:9120"
];
};
settings = {
approvals = {
mode = "off";
cron_mode = "deny";
mcp_reload_confirm = "false";
};
memory = {
memory_enabled = true;
user_profile_enabled = true;
};
display = {
credits_notices = true;
};
delegation = {
model = "us.anthropic.claude-sonnet-5";
provider = "bedrock";
};
discord = {
group_sessions_per_user = false;
reactions = false;
};
};
};
# Hermes serve (desktop app JSON-RPC backend, headless)
# Port 9120 avoids conflict with the gateway's API server on 9119.
systemd.services.hermes-serve = {
description = "Hermes Agent Serve (desktop remote backend)";
wantedBy = [ "multi-user.target" ];
after = [ "hermes-agent.service" "network-online.target" ];
wants = [ "network-online.target" ];
requires = [ "hermes-agent.service" ];
serviceConfig = {
Type = "simple";
Restart = "always";
RestartSec = 5;
TimeoutStopSec = 15;
};
script = ''
exec ${pkgs.docker}/bin/docker exec -i -u hermes \
-e HERMES_HOME=/data/.hermes \
-e HOME=/home/hermes \
hermes-agent \
/data/current-package/bin/hermes serve \
--host 0.0.0.0 \
--port 9120
'';
};
# Hermes dashboard (web UI for browser access)
# Port 9121, full web dashboard with login page.
systemd.services.hermes-dashboard = {
description = "Hermes Agent Dashboard (web UI)";
wantedBy = [ "multi-user.target" ];
after = [ "hermes-agent.service" "network-online.target" ];
wants = [ "network-online.target" ];
requires = [ "hermes-agent.service" ];
serviceConfig = {
Type = "simple";
Restart = "always";
RestartSec = 5;
TimeoutStopSec = 15;
};
script = ''
exec ${pkgs.docker}/bin/docker exec -i -u hermes \
-e HERMES_HOME=/data/.hermes \
-e HOME=/home/hermes \
hermes-agent \
/data/current-package/bin/hermes dashboard \
--host 0.0.0.0 \
--port 9121 \
--no-open
'';
};
networking.firewall.allowedTCPPorts = [
8080
9119
9120
9121
8642
];
}
-15
View File
@@ -1,15 +0,0 @@
{
inputs,
pkgs,
username,
...
}:
{
imports = [ inputs.agenix.nixosModules.default ];
age.secrets."hermes-env".file = ./hermes-env.age;
hjem.users.${username}.packages = with pkgs; [
inputs.agenix.packages."${system}".default
];
}
-5
View File
@@ -1,5 +0,0 @@
{
imports = [
./agenix.nix
];
}
Binary file not shown.
-6
View File
@@ -1,6 +0,0 @@
let
hermes-vm = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIFqtbtEYL4pPNvJV64FjDXT6zT2ew0IFK8XHJ9LP7ae";
in
{
"hermes-env.age".publicKeys = [ hermes-vm ];
}
-13
View File
@@ -1,13 +0,0 @@
{
security.sudo.extraRules = [
{
users = [ "poslop" ];
commands = [
{
command = "/run/current-system/sw/bin/docker";
options = [ "NOPASSWD" ];
}
];
}
];
}
+1 -1
View File
@@ -11,7 +11,7 @@
services.k3s = { services.k3s = {
enable = true; enable = true;
role = "server"; role = "server";
extraFlags = "--write-kubeconfig-mode 644"; extraFlags = "--write-kubeconfig-mode 644 --disable-network-policy";
}; };
fileSystems."/var/lib/rancher/k3s/server/manifests/apps" = { fileSystems."/var/lib/rancher/k3s/server/manifests/apps" = {
+1 -1
View File
@@ -1 +1 @@
sudo nixos-rebuild switch --flake ./#qemu-vm sudo nixos-rebuild switch --flake ./#goyplex-vm
+6
View File
@@ -0,0 +1,6 @@
{
# shared baseline: core system + home manager config
imports = [
../modules
];
}
+7
View File
@@ -0,0 +1,7 @@
{
# hermes agent retired (migrated to standalone debian VM fen-vm).
# Kept as core-only so the host still builds until it is decommissioned.
imports = [
./core.nix
];
}
+7
View File
@@ -0,0 +1,7 @@
{
# k3s server node (goyplex-vm): k3s + manifests + firewall
imports = [
./core.nix
../modules/k3s/k3s.nix
];
}