diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..e69de29 diff --git a/flake.lock b/flake.lock index 33ff08e..2fc079a 100644 --- a/flake.lock +++ b/flake.lock @@ -1,5 +1,26 @@ { "nodes": { + "agenix": { + "inputs": { + "darwin": "darwin", + "home-manager": "home-manager", + "nixpkgs": "nixpkgs", + "systems": "systems" + }, + "locked": { + "lastModified": 1770165109, + "narHash": "sha256-9VnK6Oqai65puVJ4WYtCTvlJeXxMzAp/69HhQuTdl/I=", + "owner": "ryantm", + "repo": "agenix", + "rev": "b027ee29d959fda4b60b57566d64c98a202e0feb", + "type": "github" + }, + "original": { + "owner": "ryantm", + "repo": "agenix", + "type": "github" + } + }, "aquamarine": { "inputs": { "hyprutils": [ @@ -20,11 +41,11 @@ ] }, "locked": { - "lastModified": 1767024902, - "narHash": "sha256-sMdk6QkMDhIOnvULXKUM8WW8iyi551SWw2i6KQHbrrU=", + "lastModified": 1784368054, + "narHash": "sha256-zF1iJkBQSDWmRO4/LEeHR1SpKY0lqZaxkoQJpPS9K9U=", "owner": "hyprwm", "repo": "aquamarine", - "rev": "b8a0c5ba5a9fbd2c660be7dd98bdde0ff3798556", + "rev": "9b5f14d9483445e766294eb8fbe0b8f370269ed0", "type": "github" }, "original": { @@ -33,6 +54,28 @@ "type": "github" } }, + "darwin": { + "inputs": { + "nixpkgs": [ + "agenix", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1744478979, + "narHash": "sha256-dyN+teG9G82G+m+PX/aSAagkC+vUv0SgUw3XkPhQodQ=", + "owner": "lnl7", + "repo": "nix-darwin", + "rev": "43975d782b418ebf4969e9ccba82466728c2851b", + "type": "github" + }, + "original": { + "owner": "lnl7", + "ref": "master", + "repo": "nix-darwin", + "type": "github" + } + }, "flake-compat": { "flake": false, "locked": { @@ -49,42 +92,62 @@ "type": "github" } }, - "gitignore": { + "flake-parts": { "inputs": { - "nixpkgs": [ - "hyprland", - "pre-commit-hooks", + "nixpkgs-lib": [ + "hermes-agent", "nixpkgs" ] }, "locked": { - "lastModified": 1709087332, - "narHash": "sha256-HG2cCnktfHsKV0s4XW83gU3F57gaTljL9KNSuG6bnQs=", + "lastModified": 1772408722, + "narHash": "sha256-rHuJtdcOjK7rAHpHphUb1iCvgkU3GpfvicLMwwnfMT0=", "owner": "hercules-ci", - "repo": "gitignore.nix", - "rev": "637db329424fd7e46cf4185293b9cc8c88c95394", + "repo": "flake-parts", + "rev": "f20dc5d9b8027381c474144ecabc9034d6a839a3", "type": "github" }, "original": { "owner": "hercules-ci", - "repo": "gitignore.nix", + "repo": "flake-parts", + "type": "github" + } + }, + "hermes-agent": { + "inputs": { + "flake-parts": "flake-parts", + "nixpkgs": "nixpkgs_2", + "npm-lockfile-fix": "npm-lockfile-fix", + "pyproject-build-systems": "pyproject-build-systems", + "pyproject-nix": "pyproject-nix", + "uv2nix": "uv2nix" + }, + "locked": { + "lastModified": 1784644108, + "narHash": "sha256-WFwNw701EOVHRwEpgifbYQaT68LOxATKDTXaep82yN4=", + "owner": "NousResearch", + "repo": "hermes-agent", + "rev": "d604141d097eec4a49493ad1eaceb9b2ca1e496d", + "type": "github" + }, + "original": { + "owner": "NousResearch", + "repo": "hermes-agent", "type": "github" } }, "hjem": { "inputs": { - "nix-darwin": "nix-darwin", "nixpkgs": [ "nixpkgs" - ], - "smfh": "smfh" + ] }, "locked": { - "lastModified": 1769053318, - "narHash": "sha256-cKETEBrseo7Iz+bOzflwy1xTpDuUj3QaLA+P49yJw8k=", + "lastModified": 1784601896, + "narHash": "sha256-rkpUOBv9pVG+GxhK90ebCrFpvjnfP4u2y/iGrzA42K4=", "owner": "feel-co", "repo": "hjem", - "rev": "9d0c8d4b44f661910595b07e6480557644c1431c", + "rev": "35e95ebb9557ac41a72fe00dd55218d1a7f21679", "type": "github" }, "original": { @@ -98,18 +161,17 @@ "hjem": [ "hjem" ], - "ndg": "ndg", + "nix-darwin": "nix-darwin", "nixpkgs": [ "nixpkgs" - ], - "treefmt-nix": "treefmt-nix" + ] }, "locked": { - "lastModified": 1766394058, - "narHash": "sha256-P+59TbVusYqdx2Jt2liwvQ+hslUzU6M1ezRDy6c66Tc=", + "lastModified": 1784361899, + "narHash": "sha256-QIzbnJIwy5cMYvPmLYPA4ar0lhficYLKZ6ytcHK90Uo=", "owner": "snugnug", "repo": "hjem-rum", - "rev": "edac54b7d57ad72cc4b124da2f44e7b2e584f3c6", + "rev": "73f6d1c01fe94e3de1cb3a84b9346da52f483c60", "type": "github" }, "original": { @@ -121,16 +183,16 @@ "home-manager": { "inputs": { "nixpkgs": [ - "zen-browser", + "agenix", "nixpkgs" ] }, "locked": { - "lastModified": 1768434960, - "narHash": "sha256-cJbFn17oyg6qAraLr+NVeNJrXsrzJdrudkzI4H2iTcg=", + "lastModified": 1745494811, + "narHash": "sha256-YZCh2o9Ua1n9uCvrvi5pRxtuVNml8X2a03qIFfRKpFs=", "owner": "nix-community", "repo": "home-manager", - "rev": "b4d88c9ac42ae1a745283f6547701da43b6e9f9b", + "rev": "abfad3d2958c9e6300a883bd443512c55dfeb1be", "type": "github" }, "original": { @@ -155,11 +217,11 @@ ] }, "locked": { - "lastModified": 1753964049, - "narHash": "sha256-lIqabfBY7z/OANxHoPeIrDJrFyYy9jAM4GQLzZ2feCM=", + "lastModified": 1776511930, + "narHash": "sha256-fCpwFiTW0rT7oKJqr3cqHMnkwypSwQKpbtUEtxdkgrM=", "owner": "hyprwm", "repo": "hyprcursor", - "rev": "44e91d467bdad8dcf8bbd2ac7cf49972540980a5", + "rev": "39435900785d0c560c6ae8777d29f28617d031ef", "type": "github" }, "original": { @@ -184,11 +246,11 @@ ] }, "locked": { - "lastModified": 1766946335, - "narHash": "sha256-MRD+Jr2bY11MzNDfenENhiK6pvN+nHygxdHoHbZ1HtE=", + "lastModified": 1782566056, + "narHash": "sha256-haEZcHzYrePnjFOYSWTbxm/Nrla0aPslJfmvdCvqtVc=", "owner": "hyprwm", "repo": "hyprgraphics", - "rev": "4af02a3925b454deb1c36603843da528b67ded6c", + "rev": "c6e7b9f673f4360bc813d3dc75028f75ee88d3f8", "type": "github" }, "original": { @@ -208,17 +270,17 @@ "hyprutils": "hyprutils", "hyprwayland-scanner": "hyprwayland-scanner", "hyprwire": "hyprwire", - "nixpkgs": "nixpkgs_2", + "nixpkgs": "nixpkgs_3", "pre-commit-hooks": "pre-commit-hooks", "systems": "systems_2", "xdph": "xdph" }, "locked": { - "lastModified": 1769548913, - "narHash": "sha256-b9WwbhMj/MmUSSiZOeBbwlpDRXac+hdZRBSG2QTk2ew=", + "lastModified": 1784641930, + "narHash": "sha256-j1c/65skFvp1WPbHBlAfVWaeCz0Bgwr/WPwIg0H+Ncg=", "owner": "hyprwm", "repo": "Hyprland", - "rev": "c8b5023bb0610be4d1d2987ef05168834b2661ba", + "rev": "1a3606234c59842340ad9a42baeeffe44a9d6cda", "type": "github" }, "original": { @@ -260,11 +322,11 @@ ] }, "locked": { - "lastModified": 1767023960, - "narHash": "sha256-R2HgtVS1G3KSIKAQ77aOZ+Q0HituOmPgXW9nBNkpp3Q=", + "lastModified": 1784196523, + "narHash": "sha256-ahtKMGXFJdlQNhatQm1+BBU/pGfGYnAqQt3vWvq4p8s=", "owner": "hyprwm", "repo": "hyprland-guiutils", - "rev": "c2e906261142f5dd1ee0bfc44abba23e2754c660", + "rev": "a6ccb6cb112ed5a244c0191fb972347ecfa893e0", "type": "github" }, "original": { @@ -285,11 +347,11 @@ ] }, "locked": { - "lastModified": 1765214753, - "narHash": "sha256-P9zdGXOzToJJgu5sVjv7oeOGPIIwrd9hAUAP3PsmBBs=", + "lastModified": 1772460177, + "narHash": "sha256-/6G/MsPvtn7bc4Y32pserBT/Z4SUUdBd4XYJpOEKVR4=", "owner": "hyprwm", "repo": "hyprland-protocols", - "rev": "3f3860b869014c00e8b9e0528c7b4ddc335c21ab", + "rev": "1cb6db5fd6bb8aee419f4457402fa18293ace917", "type": "github" }, "original": { @@ -314,11 +376,11 @@ ] }, "locked": { - "lastModified": 1764612430, - "narHash": "sha256-54ltTSbI6W+qYGMchAgCR6QnC1kOdKXN6X6pJhOWxFg=", + "lastModified": 1777320127, + "narHash": "sha256-Qu+Wf2Bp5qUjyn2YpZNq8a7JyzTGowhT1knrwE38a9U=", "owner": "hyprwm", "repo": "hyprlang", - "rev": "0d00dc118981531aa731150b6ea551ef037acddd", + "rev": "090117506ddc3d7f26e650ff344d378c2ec329cc", "type": "github" }, "original": { @@ -366,11 +428,11 @@ ] }, "locked": { - "lastModified": 1764592794, - "narHash": "sha256-7CcO+wbTJ1L1NBQHierHzheQGPWwkIQug/w+fhTAVuU=", + "lastModified": 1782554491, + "narHash": "sha256-+p3MlyN/nqRefcf2IckPlGRUn9+hielqpS9XClbLleM=", "owner": "hyprwm", "repo": "hyprtoolkit", - "rev": "5cfe0743f0e608e1462972303778d8a0859ee63e", + "rev": "bdba25ced39ea39ab004a8f31593ba0b0ff1ca35", "type": "github" }, "original": { @@ -391,11 +453,11 @@ ] }, "locked": { - "lastModified": 1766253372, - "narHash": "sha256-1+p4Kw8HdtMoFSmJtfdwjxM4bPxDK9yg27SlvUMpzWA=", + "lastModified": 1784323413, + "narHash": "sha256-XnAVV+H4f8Xdv0yZcSwJ5kCjLyE8fHxPeLX6a3HSrAU=", "owner": "hyprwm", "repo": "hyprutils", - "rev": "51a4f93ce8572e7b12b7284eb9e6e8ebf16b4be9", + "rev": "5f03477ab3a005ff27c527486f551883535aea2f", "type": "github" }, "original": { @@ -416,11 +478,11 @@ ] }, "locked": { - "lastModified": 1763640274, - "narHash": "sha256-Uan1Nl9i4TF/kyFoHnTq1bd/rsWh4GAK/9/jDqLbY5A=", + "lastModified": 1777159683, + "narHash": "sha256-Jxixw6wZphUp+nHYxOKUYSckL17QMBx2d5Zp0rJHr1g=", "owner": "hyprwm", "repo": "hyprwayland-scanner", - "rev": "f6cf414ca0e16a4d30198fd670ec86df3c89f671", + "rev": "b8632713a6beaf28b56f2a7b0ab2fb7088dbb404", "type": "github" }, "original": { @@ -445,11 +507,11 @@ ] }, "locked": { - "lastModified": 1767473322, - "narHash": "sha256-RGOeG+wQHeJ6BKcsSB8r0ZU77g9mDvoQzoTKj2dFHwA=", + "lastModified": 1778410714, + "narHash": "sha256-o6RzFj4nJXaPRY7EM01siuCQeT41RfwwmcmFQqwFJJg=", "owner": "hyprwm", "repo": "hyprwire", - "rev": "d5e7d6b49fe780353c1cf9a1cf39fa8970bd9d11", + "rev": "85148a8e612808cf5ddb25d0b3c5840f3498a7dc", "type": "github" }, "original": { @@ -458,38 +520,19 @@ "type": "github" } }, - "ndg": { - "inputs": { - "nixpkgs": "nixpkgs" - }, - "locked": { - "lastModified": 1766342086, - "narHash": "sha256-vKuCSU8BCUxG8S2/EyOXrCbIQjmY07Jb5Cq3ehnLsnY=", - "owner": "feel-co", - "repo": "ndg", - "rev": "696647a8f0ea1451c02de21b6bdf2a2c9f238d85", - "type": "github" - }, - "original": { - "owner": "feel-co", - "ref": "v2.5.1", - "repo": "ndg", - "type": "github" - } - }, "nix-darwin": { "inputs": { "nixpkgs": [ - "hjem", + "hjem-rum", "nixpkgs" ] }, "locked": { - "lastModified": 1765065051, - "narHash": "sha256-b7W9WsvyMOkUScNxbzS45KEJp0iiqRPyJ1I3JBE+oEE=", + "lastModified": 1779036909, + "narHash": "sha256-zXcwYQGCT6pzinK+1dBB2ekTVtfxGZAapb3Evdcu4fY=", "owner": "nix-darwin", "repo": "nix-darwin", - "rev": "7e22bf538aa3e0937effcb1cee73d5f1bcc26f79", + "rev": "56c666e108467d87d13508936aade6d567f2a501", "type": "github" }, "original": { @@ -500,27 +543,27 @@ }, "nixpkgs": { "locked": { - "lastModified": 1766070988, - "narHash": "sha256-G/WVghka6c4bAzMhTwT2vjLccg/awmHkdKSd2JrycLc=", + "lastModified": 1754028485, + "narHash": "sha256-IiiXB3BDTi6UqzAZcf2S797hWEPCRZOwyNThJIYhUfk=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "c6245e83d836d0433170a16eb185cefe0572f8b8", + "rev": "59e69648d345d6e8fef86158c555730fa12af9de", "type": "github" }, "original": { "owner": "NixOS", - "ref": "nixos-unstable", + "ref": "nixos-25.05", "repo": "nixpkgs", "type": "github" } }, "nixpkgs_2": { "locked": { - "lastModified": 1767379071, - "narHash": "sha256-EgE0pxsrW9jp9YFMkHL9JMXxcqi/OoumPJYwf+Okucw=", + "lastModified": 1775036866, + "narHash": "sha256-ZojAnPuCdy657PbTq5V0Y+AHKhZAIwSIT2cb8UgAz/U=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "fb7944c166a3b630f177938e478f0378e64ce108", + "rev": "6201e203d09599479a3b3450ed24fa81537ebc4e", "type": "github" }, "original": { @@ -532,15 +575,15 @@ }, "nixpkgs_3": { "locked": { - "lastModified": 1769170682, - "narHash": "sha256-oMmN1lVQU0F0W2k6OI3bgdzp2YOHWYUAw79qzDSjenU=", - "owner": "nixos", + "lastModified": 1784356753, + "narHash": "sha256-12KrbMiWLcf8m7pCvAtZh1ZrgF85ZXDXvfR/fWTKy84=", + "owner": "NixOS", "repo": "nixpkgs", - "rev": "c5296fdd05cfa2c187990dd909864da9658df755", + "rev": "61b7c44c4073f0b827768aff0049561b5110ea5a", "type": "github" }, "original": { - "owner": "nixos", + "owner": "NixOS", "ref": "nixos-unstable", "repo": "nixpkgs", "type": "github" @@ -548,11 +591,11 @@ }, "nixpkgs_4": { "locked": { - "lastModified": 1768127708, - "narHash": "sha256-1Sm77VfZh3mU0F5OqKABNLWxOuDeHIlcFjsXeeiPazs=", + "lastModified": 1784497964, + "narHash": "sha256-vlHUuqAcbcH2RKmHbPiuQzbv1pnzzavXnI62RD0bqCU=", "owner": "nixos", "repo": "nixpkgs", - "rev": "ffbc9f8cbaacfb331b6017d5a5abb21a492c9a38", + "rev": "241313f4e8e508cb9b13278c2b0fa25b9ca27163", "type": "github" }, "original": { @@ -562,21 +605,41 @@ "type": "github" } }, + "npm-lockfile-fix": { + "inputs": { + "nixpkgs": [ + "hermes-agent", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1775903712, + "narHash": "sha256-2GV79U6iVH4gKAPWYrxUReB0S41ty/Y3dBLquU8AlaA=", + "owner": "jeslie0", + "repo": "npm-lockfile-fix", + "rev": "c6093acb0c0548e0f9b8b3d82918823721930fe8", + "type": "github" + }, + "original": { + "owner": "jeslie0", + "repo": "npm-lockfile-fix", + "type": "github" + } + }, "pre-commit-hooks": { "inputs": { "flake-compat": "flake-compat", - "gitignore": "gitignore", "nixpkgs": [ "hyprland", "nixpkgs" ] }, "locked": { - "lastModified": 1767281941, - "narHash": "sha256-6MkqajPICgugsuZ92OMoQcgSHnD6sJHwk8AxvMcIgTE=", + "lastModified": 1784288435, + "narHash": "sha256-ReRHaLgr/uVqdD8afFSn+myXIfpHeOhP0yYe0TJqAA8=", "owner": "cachix", "repo": "git-hooks.nix", - "rev": "f0927703b7b1c8d97511c4116eb9b4ec6645a0fa", + "rev": "43b3c1ab9d40fb1dbb008f451988a91e375825e9", "type": "github" }, "original": { @@ -585,58 +648,64 @@ "type": "github" } }, + "pyproject-build-systems": { + "inputs": { + "nixpkgs": [ + "hermes-agent", + "nixpkgs" + ], + "pyproject-nix": [ + "hermes-agent", + "pyproject-nix" + ], + "uv2nix": [ + "hermes-agent", + "uv2nix" + ] + }, + "locked": { + "lastModified": 1772555609, + "narHash": "sha256-3BA3HnUvJSbHJAlJj6XSy0Jmu7RyP2gyB/0fL7XuEDo=", + "owner": "pyproject-nix", + "repo": "build-system-pkgs", + "rev": "c37f66a953535c394244888598947679af231863", + "type": "github" + }, + "original": { + "owner": "pyproject-nix", + "repo": "build-system-pkgs", + "type": "github" + } + }, + "pyproject-nix": { + "inputs": { + "nixpkgs": [ + "hermes-agent", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1772865871, + "narHash": "sha256-/ZTSg97aouL0SlPHaokA4r3iuH9QzHVuWPACD2CUCFY=", + "owner": "pyproject-nix", + "repo": "pyproject.nix", + "rev": "e537db02e72d553cea470976b9733581bcf5b3ed", + "type": "github" + }, + "original": { + "owner": "pyproject-nix", + "repo": "pyproject.nix", + "type": "github" + } + }, "root": { "inputs": { + "agenix": "agenix", + "hermes-agent": "hermes-agent", "hjem": "hjem", "hjem-rum": "hjem-rum", "hyprland": "hyprland", - "nixpkgs": "nixpkgs_3", - "zen-browser": "zen-browser" - } - }, - "rust-overlay": { - "inputs": { - "nixpkgs": [ - "hjem", - "smfh", - "nixpkgs" - ] - }, - "locked": { - "lastModified": 1763347184, - "narHash": "sha256-6QH8hpCYJxifvyHEYg+Da0BotUn03BwLIvYo3JAxuqQ=", - "owner": "oxalica", - "repo": "rust-overlay", - "rev": "08895cce80433978d5bfd668efa41c5e24578cbd", - "type": "github" - }, - "original": { - "owner": "oxalica", - "repo": "rust-overlay", - "type": "github" - } - }, - "smfh": { - "inputs": { - "nixpkgs": [ - "hjem", - "nixpkgs" - ], - "rust-overlay": "rust-overlay", - "systems": "systems" - }, - "locked": { - "lastModified": 1763430012, - "narHash": "sha256-06G7pXUdpMnUqR0JWWvV7sA8oNGOZU1cSLqQS1GMf7Y=", - "owner": "feel-co", - "repo": "smfh", - "rev": "eddda76e3dd4c6deaea5f819f174fc16dbe70f90", - "type": "github" - }, - "original": { - "owner": "feel-co", - "repo": "smfh", - "type": "github" + "nixpkgs": "nixpkgs_4" } }, "systems": { @@ -669,24 +738,28 @@ "type": "github" } }, - "treefmt-nix": { + "uv2nix": { "inputs": { "nixpkgs": [ - "hjem-rum", + "hermes-agent", "nixpkgs" + ], + "pyproject-nix": [ + "hermes-agent", + "pyproject-nix" ] }, "locked": { - "lastModified": 1746216483, - "narHash": "sha256-4h3s1L/kKqt3gMDcVfN8/4v2jqHrgLIe4qok4ApH5x4=", - "owner": "numtide", - "repo": "treefmt-nix", - "rev": "29ec5026372e0dec56f890e50dbe4f45930320fd", + "lastModified": 1773039484, + "narHash": "sha256-+boo33KYkJDw9KItpeEXXv8+65f7hHv/earxpcyzQ0I=", + "owner": "pyproject-nix", + "repo": "uv2nix", + "rev": "b68be7cfeacbed9a3fa38a2b5adc0cfb81d9bb1f", "type": "github" }, "original": { - "owner": "numtide", - "repo": "treefmt-nix", + "owner": "pyproject-nix", + "repo": "uv2nix", "type": "github" } }, @@ -718,11 +791,11 @@ ] }, "locked": { - "lastModified": 1761431178, - "narHash": "sha256-xzjC1CV3+wpUQKNF+GnadnkeGUCJX+vgaWIZsnz9tzI=", + "lastModified": 1784371182, + "narHash": "sha256-S8A1lezEalltWcCp3gAic5lssS0xTSISK6fKODefhOk=", "owner": "hyprwm", "repo": "xdg-desktop-portal-hyprland", - "rev": "4b8801228ff958d028f588f0c2b911dbf32297f9", + "rev": "08d99f727944dd15e4740090305e31c5fb92a50a", "type": "github" }, "original": { @@ -730,25 +803,6 @@ "repo": "xdg-desktop-portal-hyprland", "type": "github" } - }, - "zen-browser": { - "inputs": { - "home-manager": "home-manager", - "nixpkgs": "nixpkgs_4" - }, - "locked": { - "lastModified": 1769491693, - "narHash": "sha256-bbqeCDML1yXI6kpy8q8BshKRV1szk3xV0StAbzw4Z+o=", - "owner": "0xc000022070", - "repo": "zen-browser-flake", - "rev": "708e0f10aba5de7d0f55883d06fa08aa6a7cd462", - "type": "github" - }, - "original": { - "owner": "0xc000022070", - "repo": "zen-browser-flake", - "type": "github" - } } }, "root": "root", diff --git a/flake.nix b/flake.nix index 6370c32..65dd8a0 100644 --- a/flake.nix +++ b/flake.nix @@ -1,7 +1,10 @@ { inputs = { nixpkgs.url = "github:nixos/nixpkgs/nixos-unstable"; + hyprland.url = "github:hyprwm/Hyprland"; + hermes-agent.url = "github:NousResearch/hermes-agent"; + agenix.url = "github:ryantm/agenix"; hjem = { url = "github:feel-co/hjem"; @@ -13,29 +16,37 @@ inputs.nixpkgs.follows = "nixpkgs"; inputs.hjem.follows = "hjem"; }; - - zen-browser = { - url = "github:0xc000022070/zen-browser-flake"; - }; }; outputs = - { self, nixpkgs, ... }@inputs: + { + self, + nixpkgs, + ... + }@inputs: let system = "x86_64-linux"; username = "poslop"; + mkHost = + host: modules: + nixpkgs.lib.nixosSystem { + modules = [ { nixpkgs.hostPlatform = system; } ] ++ modules; + specialArgs = { + inherit + self + inputs + username + host + ; + }; + }; in { nixosConfigurations = { - nixos-vm2 = nixpkgs.lib.nixosSystem { - inherit system; - modules = [ ./hosts/nixos-vm2/configuration.nix ]; - specialArgs = { - host = "nixos-vm2"; - inherit self inputs username; - }; - }; + nixos-vm2 = mkHost "nixos-vm2" [ ./hosts/nixos-vm2/configuration.nix ]; + qemu-vm = mkHost "qemu-vm" [ ./hosts/qemu-vm/configuration.nix ]; + goyplex-vm = mkHost "goyplex-vm" [ ./hosts/goyplex-vm/configuration.nix ]; + hermes-vm = mkHost "hermes-vm" [ ./hosts/hermes-vm/configuration.nix ]; }; - }; } diff --git a/hosts/goyplex-vm/configuration.nix b/hosts/goyplex-vm/configuration.nix new file mode 100644 index 0000000..ec77758 --- /dev/null +++ b/hosts/goyplex-vm/configuration.nix @@ -0,0 +1,19 @@ +{ pkgs, ... }: + +{ + imports = [ + ./hardware-configuration.nix + ../../modules + ../../modules/k3s/k3s.nix + ]; + + boot.loader.systemd-boot.enable = true; + boot.loader.efi.canTouchEfiVariables = true; + + boot.kernelPackages = pkgs.linuxPackages_latest; + + services.spice-vdagentd.enable = true; + services.qemuGuest.enable = true; + + system.stateVersion = "25.11"; +} diff --git a/hosts/nixos-vm1/hardware-configuration.nix b/hosts/goyplex-vm/hardware-configuration.nix similarity index 53% rename from hosts/nixos-vm1/hardware-configuration.nix rename to hosts/goyplex-vm/hardware-configuration.nix index 9149754..a97c9d6 100644 --- a/hosts/nixos-vm1/hardware-configuration.nix +++ b/hosts/goyplex-vm/hardware-configuration.nix @@ -2,33 +2,46 @@ # and may be overwritten by future invocations. Please make changes # to /etc/nixos/configuration.nix instead. { + config, lib, + pkgs, modulesPath, ... }: { - imports = [ (modulesPath + "/profiles/qemu-guest.nix") ]; + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; boot.initrd.availableKernelModules = [ + "uhci_hcd" + "ehci_pci" "ahci" - "xhci_pci" "virtio_pci" + "virtio_scsi" + "sd_mod" "sr_mod" - "virtio_blk" ]; boot.initrd.kernelModules = [ ]; - boot.kernelModules = [ "kvm-amd" ]; + boot.kernelModules = [ ]; boot.extraModulePackages = [ ]; fileSystems."/" = { - device = "/dev/disk/by-uuid/39b3801f-ffcd-421f-966f-46625fb8d4ca"; + device = "/dev/disk/by-uuid/4a546e61-4a4d-4e09-8b00-3f56acc14ccb"; fsType = "ext4"; }; - swapDevices = [ { device = "/dev/disk/by-uuid/7043d338-93f0-40a7-9033-6616685e32f3"; } ]; + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/C838-5FC2"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; - networking.useDHCP = lib.mkDefault true; + swapDevices = [ ]; nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; } diff --git a/hosts/hermes-vm/configuration.nix b/hosts/hermes-vm/configuration.nix new file mode 100644 index 0000000..9203c1e --- /dev/null +++ b/hosts/hermes-vm/configuration.nix @@ -0,0 +1,19 @@ +{ pkgs, ... }: + +{ + imports = [ + ./hardware-configuration.nix + ../../modules + ../../modules/hermes + ]; + + boot.loader.systemd-boot.enable = true; + boot.loader.efi.canTouchEfiVariables = true; + + boot.kernelPackages = pkgs.linuxPackages_latest; + + services.spice-vdagentd.enable = true; + services.qemuGuest.enable = true; + + system.stateVersion = "25.11"; +} diff --git a/hosts/hermes-vm/hardware-configuration.nix b/hosts/hermes-vm/hardware-configuration.nix new file mode 100644 index 0000000..a97c9d6 --- /dev/null +++ b/hosts/hermes-vm/hardware-configuration.nix @@ -0,0 +1,47 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ + config, + lib, + pkgs, + modulesPath, + ... +}: + +{ + imports = [ + (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ + "uhci_hcd" + "ehci_pci" + "ahci" + "virtio_pci" + "virtio_scsi" + "sd_mod" + "sr_mod" + ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = { + device = "/dev/disk/by-uuid/4a546e61-4a4d-4e09-8b00-3f56acc14ccb"; + fsType = "ext4"; + }; + + fileSystems."/boot" = { + device = "/dev/disk/by-uuid/C838-5FC2"; + fsType = "vfat"; + options = [ + "fmask=0077" + "dmask=0077" + ]; + }; + + swapDevices = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +} diff --git a/hosts/nixos-vm1/configuration.nix b/hosts/nixos-vm1/configuration.nix deleted file mode 100644 index 20db7d5..0000000 --- a/hosts/nixos-vm1/configuration.nix +++ /dev/null @@ -1,42 +0,0 @@ -{ - pkgs, - ... -}: - -{ - nix.settings = { - experimental-features = "nix-command flakes"; - }; - - imports = [ - ./hardware-configuration.nix - ./modules - ]; - - programs.hyprland.enable = true; - - boot.loader.grub.enable = true; - boot.loader.grub.device = "/dev/vda"; - networking.hostName = "poslop-nixvm"; - networking.networkmanager.enable = true; - - time.timeZone = "America/Chicago"; - - services.printing.enable = true; - - services.pipewire = { - enable = true; - pulse.enable = true; - }; - - environment.systemPackages = with pkgs; [ - kitty - vim - wget - git - curl - zsh - ]; - - system.stateVersion = "24.11"; -} diff --git a/hosts/qemu-vm/configuration.nix b/hosts/qemu-vm/configuration.nix new file mode 100644 index 0000000..866fe4e --- /dev/null +++ b/hosts/qemu-vm/configuration.nix @@ -0,0 +1,18 @@ +{ + ... +}: + +{ + imports = [ + ./hardware-configuration.nix + ../../modules + ]; + + boot.loader.grub.enable = true; + boot.loader.grub.device = "/dev/vda"; + + services.spice-vdagentd.enable = true; + services.qemuGuest.enable = true; + + system.stateVersion = "24.11"; +} diff --git a/hosts/qemu-vm/hardware-configuration.nix b/hosts/qemu-vm/hardware-configuration.nix new file mode 100644 index 0000000..de7894a --- /dev/null +++ b/hosts/qemu-vm/hardware-configuration.nix @@ -0,0 +1,33 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ "ahci" "xhci_pci" "virtio_pci" "virtio_blk" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-amd" ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/b8c66f3c-759d-4d4f-9d1a-3f2e04d91e23"; + fsType = "ext4"; + }; + + swapDevices = + [ { device = "/dev/disk/by-uuid/b7d73851-7f85-44fa-b62a-e35deb0ea98a"; } + ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.enp8s0.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +} diff --git a/modules/core/default.nix b/modules/core/default.nix index 258d0e0..d1be68c 100644 --- a/modules/core/default.nix +++ b/modules/core/default.nix @@ -5,10 +5,9 @@ ./git.nix ./hjem.nix ./network.nix - ./packages.nix + ./packages ./timezone.nix ./nix.nix - ./pipewire.nix ./program.nix ./user.nix ./ssh.nix diff --git a/modules/core/network.nix b/modules/core/network.nix index d30c0dc..c102531 100644 --- a/modules/core/network.nix +++ b/modules/core/network.nix @@ -1,4 +1,6 @@ +{ host, ... }: + { - networking.hostName = "poslop-nixvm2"; + networking.hostName = host; networking.networkmanager.enable = true; } diff --git a/modules/core/nvim.nix b/modules/core/nvim.nix index 0ad4c48..e6a07f9 100644 --- a/modules/core/nvim.nix +++ b/modules/core/nvim.nix @@ -1,6 +1,8 @@ -{ config, pkgs, ... }: +{ pkgs, ... }: { + environment.variables.EDITOR = "nvim"; + systemd.user.services."nvim-config" = { description = "Clone Neovim config into ~/.config/nvim"; after = [ "network.target" ]; diff --git a/modules/core/packages.nix b/modules/core/packages.nix deleted file mode 100644 index b74f0b3..0000000 --- a/modules/core/packages.nix +++ /dev/null @@ -1,24 +0,0 @@ -{ pkgs, username, inputs, ... }: -{ - environment.systemPackages = with pkgs; [ - zsh - ]; - - hjem.users.${username}.packages = with pkgs; [ - clang - lld - llvmPackages.bintools - tlrc - rustc - cargo - unzip - neovim - btop - curl - git - neofetch - statix - wget - wl-clipboard - ]; -} diff --git a/modules/core/packages/default.nix b/modules/core/packages/default.nix new file mode 100644 index 0000000..9193ec7 --- /dev/null +++ b/modules/core/packages/default.nix @@ -0,0 +1,7 @@ +{ + imports = [ + ./dev.nix + ./system.nix + ./utils.nix + ]; +} diff --git a/modules/core/packages/dev.nix b/modules/core/packages/dev.nix new file mode 100644 index 0000000..ee70dcc --- /dev/null +++ b/modules/core/packages/dev.nix @@ -0,0 +1,19 @@ +{ pkgs, username, ... }: +{ + hjem.users.${username}.packages = with pkgs; [ + # general + neovim + git + tree-sitter + gcc + + # lua + stylua + lua-language-server + + # nix + nixd + nixfmt + statix + ]; +} diff --git a/modules/core/packages/system.nix b/modules/core/packages/system.nix new file mode 100644 index 0000000..b25fb19 --- /dev/null +++ b/modules/core/packages/system.nix @@ -0,0 +1,7 @@ +{ pkgs, ... }: +{ + environment.systemPackages = with pkgs; [ + zsh + ]; + +} diff --git a/modules/core/packages/utils.nix b/modules/core/packages/utils.nix new file mode 100644 index 0000000..e16056b --- /dev/null +++ b/modules/core/packages/utils.nix @@ -0,0 +1,11 @@ +{ pkgs, username, ... }: +{ + hjem.users.${username}.packages = with pkgs; [ + btop + curl + tlrc + unzip + wget + wl-clipboard + ]; +} diff --git a/modules/core/user.nix b/modules/core/user.nix index 72bbdc2..b5e290f 100644 --- a/modules/core/user.nix +++ b/modules/core/user.nix @@ -4,7 +4,10 @@ users.users.${username} = { isNormalUser = true; description = "${username}"; - extraGroups = [ "wheel" ]; + extraGroups = [ + "wheel" + "docker" + ]; shell = pkgs.zsh; }; nix.settings.allowed-users = [ "@wheel" ]; diff --git a/modules/core/zsh/.zshrc b/modules/core/zsh/.zshrc index 17f236d..3274b22 100644 --- a/modules/core/zsh/.zshrc +++ b/modules/core/zsh/.zshrc @@ -10,3 +10,35 @@ zstyle :compinstall filename '/home/poslop/.zshrc' autoload -Uz compinit compinit + +alias gc='git commit' +alias gp='git push' +alias gs='git status' + +alias hermes='docker exec -it -u hermes hermes-agent /data/current-package/bin/hermes' + +alias hermes-age='cd /etc/rice-flakes/modules/hermes/secrets && sudo EDITOR=nvim agenix -e ./hermes-env.age -i /etc/ssh/ssh_host_ed25519_key' + +ga() { + if [[ -z "$1" ]]; then + git add -u + else + git add "$1" + fi +} + +rerice() { + local flake_dir="/etc/rice-flakes" + local host="$(hostname -s)" + local OPTIND=1 + + while getopts ":h:" opt; do + case $opt in + h) host="$OPTARG" ;; + :) echo "Option -$OPTARG requires an argument." >&2; return 1 ;; + \?) echo "Unknown option: -$OPTARG" >&2; return 1 ;; + esac + done + + sudo nixos-rebuild switch --flake "${flake_dir}#${host}" +} diff --git a/modules/hermes/default.nix b/modules/hermes/default.nix new file mode 100644 index 0000000..b68e8b4 --- /dev/null +++ b/modules/hermes/default.nix @@ -0,0 +1,7 @@ +{ + imports = [ + ./sudo.nix + ./hermes.nix + ./secrets + ]; +} diff --git a/modules/hermes/hermes.nix b/modules/hermes/hermes.nix new file mode 100644 index 0000000..acdb3dc --- /dev/null +++ b/modules/hermes/hermes.nix @@ -0,0 +1,63 @@ +{ + inputs, + config, + ... +}: + +{ + imports = [ inputs.hermes-agent.nixosModules.default ]; + + services.hermes-agent = { + enable = true; + addToSystemPackages = true; + environmentFiles = [ + config.age.secrets.hermes-env.path + ]; + + container = { + image = "debian:bookworm"; + backend = "docker"; + enable = true; + hostUsers = [ "poslop" ]; + extraOptions = [ + "-p" + "9119:9119" + "-p" + "8642:8642" + ]; + }; + + settings = { + approvals = { + mode = "off"; + cron_mode = "deny"; + mcp_reload_confirm = "false"; + }; + + memory = { + memory_enabled = true; + user_profile_enabled = true; + }; + + display = { + credits_notices = true; + }; + + delegation = { + model = "openai/gpt-5.6-luna"; + provider = "nous"; + }; + + discord = { + group_sessions_per_user = false; + reactions = false; + }; + }; + }; + + networking.firewall.allowedTCPPorts = [ + 8080 + 9119 + 8642 + ]; +} diff --git a/modules/hermes/secrets/agenix.nix b/modules/hermes/secrets/agenix.nix new file mode 100644 index 0000000..182b916 --- /dev/null +++ b/modules/hermes/secrets/agenix.nix @@ -0,0 +1,15 @@ +{ + inputs, + pkgs, + username, + ... +}: + +{ + imports = [ inputs.agenix.nixosModules.default ]; + age.secrets."hermes-env".file = ./hermes-env.age; + + hjem.users.${username}.packages = with pkgs; [ + inputs.agenix.packages."${system}".default + ]; +} diff --git a/modules/hermes/secrets/default.nix b/modules/hermes/secrets/default.nix new file mode 100644 index 0000000..6d00db9 --- /dev/null +++ b/modules/hermes/secrets/default.nix @@ -0,0 +1,5 @@ +{ + imports = [ + ./agenix.nix + ]; +} diff --git a/modules/hermes/secrets/hermes-env.age b/modules/hermes/secrets/hermes-env.age new file mode 100644 index 0000000..1583299 Binary files /dev/null and b/modules/hermes/secrets/hermes-env.age differ diff --git a/modules/hermes/secrets/secrets.nix b/modules/hermes/secrets/secrets.nix new file mode 100644 index 0000000..529f7ad --- /dev/null +++ b/modules/hermes/secrets/secrets.nix @@ -0,0 +1,6 @@ +let + hermes-vm = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIFqtbtEYL4pPNvJV64FjDXT6zT2ew0IFK8XHJ9LP7ae"; +in +{ + "hermes-env.age".publicKeys = [ hermes-vm ]; +} diff --git a/modules/hermes/sudo.nix b/modules/hermes/sudo.nix new file mode 100644 index 0000000..cb8b5c6 --- /dev/null +++ b/modules/hermes/sudo.nix @@ -0,0 +1,13 @@ +{ + security.sudo.extraRules = [ + { + users = [ "poslop" ]; + commands = [ + { + command = "/run/current-system/sw/bin/docker"; + options = [ "NOPASSWD" ]; + } + ]; + } + ]; +} diff --git a/modules/home/default.nix b/modules/home/default.nix index 65c11b5..ec5e862 100644 --- a/modules/home/default.nix +++ b/modules/home/default.nix @@ -1,6 +1,7 @@ { imports = [ ./hyprland + ./pipewire.nix ./packages.nix ./fonts.nix ]; diff --git a/modules/home/hyprland/hyprland.nix b/modules/home/hyprland/hyprland.nix index 9de7508..0531411 100644 --- a/modules/home/hyprland/hyprland.nix +++ b/modules/home/hyprland/hyprland.nix @@ -1,7 +1,7 @@ { programs.hyprland.enable = true; hj = { - rum.programs.hyprland.enable = true; + rum.desktops.hyprland.enable = true; files = { ".config/hypr".source = ./hypr; diff --git a/modules/home/packages.nix b/modules/home/packages.nix index e6c19f2..ddd5622 100644 --- a/modules/home/packages.nix +++ b/modules/home/packages.nix @@ -1,13 +1,11 @@ { pkgs, username, - inputs, ... }: { hjem.users.${username}.packages = with pkgs; [ - inputs.zen-browser.packages."${system}".default kitty foot ]; diff --git a/modules/core/pipewire.nix b/modules/home/pipewire.nix similarity index 100% rename from modules/core/pipewire.nix rename to modules/home/pipewire.nix diff --git a/modules/k3s/k3s.nix b/modules/k3s/k3s.nix new file mode 100644 index 0000000..8eaa99c --- /dev/null +++ b/modules/k3s/k3s.nix @@ -0,0 +1,22 @@ +{ + networking.firewall.allowedTCPPorts = [ 6443 80 443 33073 ]; + networking.firewall.allowedUDPPorts = [ 3479 ]; + + services.k3s = { + enable = true; + role = "server"; + extraFlags = "--write-kubeconfig-mode 644"; + manifests = { + traefik-namespace = { source = ./traefik/namespace.yaml; }; + traefik-rbac = { source = ./traefik/rbac.yaml; }; + traefik-pvc = { source = ./traefik/pvc.yaml; }; + traefik-deployment = { source = ./traefik/deployment.yaml; }; + traefik-service = { source = ./traefik/service.yaml; }; + netbird-namespace = { source = ./netbird/namespace.yaml; }; + netbird-config = { source = ./netbird/config.yaml; }; + netbird-server = { source = ./netbird/server.yaml; }; + netbird-dashboard = { source = ./netbird/dashboard.yaml; }; + netbird-ingress = { source = ./netbird/ingress.yaml; }; + }; + }; +} diff --git a/modules/k3s/netbird/config.yaml b/modules/k3s/netbird/config.yaml new file mode 100644 index 0000000..285a2b9 --- /dev/null +++ b/modules/k3s/netbird/config.yaml @@ -0,0 +1,45 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: netbird-server-config + namespace: netbird +data: + config.yaml: | + server: + listenAddress: ":80" + exposedAddress: "https://netbird.archfox.org:443" + metricsPort: 9090 + healthcheckAddress: ":9000" + logLevel: "info" + logFile: "console" + stunPorts: + - 3479 + tls: + certFile: "" + keyFile: "" + letsencrypt: + enabled: false + dataDir: "" + domains: [] + email: "" + awsRoute53: false + authSecret: "182c13eec94ba6ef89ce8f3e33b4694b051fe4b0bf6d2c9188f738d1c000b6d7" + dataDir: "/var/lib/netbird/" + disableAnonymousMetrics: false + disableGeoliteUpdate: false + auth: + issuer: "https://netbird.archfox.org/oauth2" + localAuthDisabled: false + signKeyRefreshEnabled: true + dashboardRedirectURIs: + - "https://netbird.archfox.org/nb-auth" + - "https://netbird.archfox.org/nb-silent-auth" + cliRedirectURIs: + - "http://localhost:53000/" + store: + engine: "sqlite" + dsn: "" + encryptionKey: "" + reverseProxy: + trustedHTTPProxies: + - "10.0.1.45/32" diff --git a/modules/k3s/netbird/dashboard.yaml b/modules/k3s/netbird/dashboard.yaml new file mode 100644 index 0000000..3766dfa --- /dev/null +++ b/modules/k3s/netbird/dashboard.yaml @@ -0,0 +1,56 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: dashboard + namespace: netbird +spec: + replicas: 1 + selector: + matchLabels: + app: dashboard + template: + metadata: + labels: + app: dashboard + spec: + containers: + - name: dashboard + image: netbirdio/dashboard:latest + ports: + - containerPort: 80 + env: + - name: NETBIRD_MGMT_API_ENDPOINT + value: "https://netbird.archfox.org" + - name: NETBIRD_MGMT_GRPC_API_ENDPOINT + value: "https://netbird.archfox.org" + - name: AUTH_AUDIENCE + value: "netbird-dashboard" + - name: AUTH_CLIENT_ID + value: "netbird-dashboard" + - name: AUTH_CLIENT_SECRET + value: "" + - name: AUTH_AUTHORITY + value: "https://netbird.archfox.org/oauth2" + - name: USE_AUTH0 + value: "false" + - name: AUTH_SUPPORTED_SCOPES + value: "openid profile email groups" + - name: AUTH_REDIRECT_URI + value: "/nb-auth" + - name: AUTH_SILENT_REDIRECT_URI + value: "/nb-silent-auth" + - name: LETSENCRYPT_DOMAIN + value: "none" +--- +apiVersion: v1 +kind: Service +metadata: + name: dashboard + namespace: netbird +spec: + selector: + app: dashboard + ports: + - name: http + port: 80 + targetPort: 80 diff --git a/modules/k3s/netbird/ingress.yaml b/modules/k3s/netbird/ingress.yaml new file mode 100644 index 0000000..0a8c46d --- /dev/null +++ b/modules/k3s/netbird/ingress.yaml @@ -0,0 +1,26 @@ +apiVersion: traefik.io/v1alpha1 +kind: IngressRoute +metadata: + name: netbird + namespace: netbird +spec: + entryPoints: + - web + routes: + - match: Host(`netbird.archfox.org`) && (PathPrefix(`/management.ManagementService/`) || PathPrefix(`/signalexchange.SignalExchange/`) || PathPrefix(`/management.ProxyService/`)) + kind: Rule + services: + - name: netbird-server + port: 80 + scheme: h2c + - match: Host(`netbird.archfox.org`) && (PathPrefix(`/relay`) || PathPrefix(`/ws-proxy/`) || PathPrefix(`/api`) || PathPrefix(`/oauth2`)) + kind: Rule + services: + - name: netbird-server + port: 80 + - match: Host(`netbird.archfox.org`) + kind: Rule + priority: 1 + services: + - name: dashboard + port: 80 diff --git a/modules/k3s/netbird/namespace.yaml b/modules/k3s/netbird/namespace.yaml new file mode 100644 index 0000000..db05a13 --- /dev/null +++ b/modules/k3s/netbird/namespace.yaml @@ -0,0 +1,4 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: netbird diff --git a/modules/k3s/netbird/server.yaml b/modules/k3s/netbird/server.yaml new file mode 100644 index 0000000..4b954e2 --- /dev/null +++ b/modules/k3s/netbird/server.yaml @@ -0,0 +1,74 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: netbird-server + namespace: netbird +spec: + replicas: 1 + selector: + matchLabels: + app: netbird-server + template: + metadata: + labels: + app: netbird-server + spec: + containers: + - name: netbird-server + image: netbirdio/netbird-server:latest + args: ["--config", "/etc/netbird/config.yaml"] + ports: + - containerPort: 80 + - containerPort: 3479 + protocol: UDP + - containerPort: 33073 + env: + - name: NETBIRD_STORE_ENCRYPTION_KEY + valueFrom: + secretKeyRef: + name: netbird-encryption + key: encryptionKey + volumeMounts: + - name: config + mountPath: /etc/netbird + - name: data + mountPath: /var/lib/netbird + volumes: + - name: config + configMap: + name: netbird-server-config + - name: data + persistentVolumeClaim: + claimName: netbird-data +--- +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: netbird-data + namespace: netbird +spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 2Gi +--- +apiVersion: v1 +kind: Service +metadata: + name: netbird-server + namespace: netbird +spec: + selector: + app: netbird-server + ports: + - name: http + port: 80 + targetPort: 80 + - name: grpc-compat + port: 33073 + targetPort: 33073 + - name: stun + port: 3479 + targetPort: 3479 + protocol: UDP diff --git a/modules/k3s/traefik/deployment.yaml b/modules/k3s/traefik/deployment.yaml new file mode 100644 index 0000000..7dcca15 --- /dev/null +++ b/modules/k3s/traefik/deployment.yaml @@ -0,0 +1,35 @@ +apiVersion: apps/v1 +kind: Deployment +metadata: + name: traefik + namespace: traefik +spec: + replicas: 1 + selector: + matchLabels: + app: traefik + template: + metadata: + labels: + app: traefik + spec: + serviceAccountName: traefik + containers: + - name: traefik + image: traefik:v3.4 + args: + - --log.level=INFO + - --api.dashboard=true + - --entrypoints.web.address=:80 + - --providers.kubernetescrd=true + - --providers.kubernetesingress=true + ports: + - name: web + containerPort: 80 + volumeMounts: + - name: acme-storage + mountPath: /data + volumes: + - name: acme-storage + persistentVolumeClaim: + claimName: traefik-acme diff --git a/modules/k3s/traefik/namespace.yaml b/modules/k3s/traefik/namespace.yaml new file mode 100644 index 0000000..c088a91 --- /dev/null +++ b/modules/k3s/traefik/namespace.yaml @@ -0,0 +1,4 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: traefik diff --git a/modules/k3s/traefik/pvc.yaml b/modules/k3s/traefik/pvc.yaml new file mode 100644 index 0000000..46187de --- /dev/null +++ b/modules/k3s/traefik/pvc.yaml @@ -0,0 +1,11 @@ +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: traefik-acme + namespace: traefik +spec: + accessModes: + - ReadWriteOnce + resources: + requests: + storage: 128Mi diff --git a/modules/k3s/traefik/rbac.yaml b/modules/k3s/traefik/rbac.yaml new file mode 100644 index 0000000..a10b9eb --- /dev/null +++ b/modules/k3s/traefik/rbac.yaml @@ -0,0 +1,41 @@ +apiVersion: v1 +kind: ServiceAccount +metadata: + name: traefik + namespace: traefik +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRole +metadata: + name: traefik +rules: + - apiGroups: [""] + resources: ["services", "endpoints", "secrets", "configmaps", "nodes", "namespaces", "pods"] + verbs: ["get", "list", "watch"] + - apiGroups: ["discovery.k8s.io"] + resources: ["endpointslices"] + verbs: ["get", "list", "watch"] + - apiGroups: ["extensions", "networking.k8s.io"] + resources: ["ingresses", "ingressclasses"] + verbs: ["get", "list", "watch"] + - apiGroups: ["extensions", "networking.k8s.io"] + resources: ["ingresses/status"] + verbs: ["update"] + - apiGroups: ["traefik.io"] + resources: ["ingressroutes", "ingressroutetcps", "ingressrouteudps", "middlewares", + "middlewaretcps", "tlsoptions", "tlsstores", "traefikservices", + "serverstransports", "serverstransporttcps"] + verbs: ["get", "list", "watch"] +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: ClusterRoleBinding +metadata: + name: traefik +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: ClusterRole + name: traefik +subjects: + - kind: ServiceAccount + name: traefik + namespace: traefik diff --git a/modules/k3s/traefik/service.yaml b/modules/k3s/traefik/service.yaml new file mode 100644 index 0000000..04377c8 --- /dev/null +++ b/modules/k3s/traefik/service.yaml @@ -0,0 +1,16 @@ +apiVersion: v1 +kind: Service +metadata: + name: traefik + namespace: traefik +spec: + type: LoadBalancer + selector: + app: traefik + ports: + - name: web + port: 80 + targetPort: 80 + - name: websecure + port: 443 + targetPort: 443 diff --git a/rebuild.sh b/rebuild.sh index 60c6ba7..54d1c55 100755 --- a/rebuild.sh +++ b/rebuild.sh @@ -1 +1 @@ -sudo nixos-rebuild switch --flake ./#nixos-vm2 +sudo nixos-rebuild switch --flake ./#qemu-vm