Skyler Grey | 1e2187f | 2023-03-03 22:45:10 +0000 | [diff] [blame] | 1 | { |
| 2 | description = "A flake to deploy and configure Clicks' NixOS server"; |
| 3 | |
Skyler Grey | 07c947a | 2023-06-08 14:11:23 +0200 | [diff] [blame] | 4 | inputs.nixpkgs.url = "github:nixos/nixpkgs/nixos-23.05"; |
Skyler Grey | b30f5dd | 2023-09-01 21:02:44 +0000 | [diff] [blame] | 5 | inputs.nixpkgs-clicksforms.url = "github:nixos/nixpkgs/nixos-22.05"; |
Skyler Grey | 061574c | 2023-05-01 21:39:24 +0000 | [diff] [blame] | 6 | inputs.flake-utils.url = "github:numtide/flake-utils"; |
Skyler Grey | 1e2187f | 2023-03-03 22:45:10 +0000 | [diff] [blame] | 7 | inputs.deploy-rs.url = "github:serokell/deploy-rs"; |
Skyler Grey | 07c947a | 2023-06-08 14:11:23 +0200 | [diff] [blame] | 8 | inputs.home-manager.url = "github:nix-community/home-manager/release-23.05"; |
Skyler Grey | a7fbaee | 2023-05-12 00:29:20 +0000 | [diff] [blame] | 9 | inputs.sops-nix.url = "github:Mic92/sops-nix"; |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 10 | inputs.scalpel.url = "github:polygon/scalpel"; |
Skyler Grey | 1e2187f | 2023-03-03 22:45:10 +0000 | [diff] [blame] | 11 | |
Skyler Grey | fed0bb1 | 2023-05-01 21:42:03 +0000 | [diff] [blame] | 12 | inputs.home-manager.inputs.nixpkgs.follows = "nixpkgs"; |
Skyler Grey | fed0bb1 | 2023-05-01 21:42:03 +0000 | [diff] [blame] | 13 | |
Skyler Grey | a7fbaee | 2023-05-12 00:29:20 +0000 | [diff] [blame] | 14 | inputs.sops-nix.inputs.nixpkgs.follows = "nixpkgs"; |
| 15 | |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 16 | inputs.scalpel.inputs.nixpkgs.follows = "nixpkgs"; |
| 17 | inputs.scalpel.inputs.sops-nix.follows = "sops-nix"; |
| 18 | |
Skyler Grey | 9fe6128 | 2023-08-20 21:52:48 +0000 | [diff] [blame] | 19 | inputs.nixpkgs-privatebin.url = "github:e1mo/nixpkgs/privatebin"; |
| 20 | |
| 21 | outputs = |
| 22 | { self |
| 23 | , nixpkgs |
| 24 | , deploy-rs |
| 25 | , home-manager |
| 26 | , sops-nix |
| 27 | , scalpel |
| 28 | , nixpkgs-privatebin |
| 29 | , ... |
| 30 | }@inputs: |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 31 | let |
| 32 | system = "x86_64-linux"; |
| 33 | pkgs = import nixpkgs { |
| 34 | inherit system; |
| 35 | config.allowUnfree = true; |
Skyler Grey | 9fe6128 | 2023-08-20 21:52:48 +0000 | [diff] [blame] | 36 | overlays = [ |
| 37 | (final: prev: { inherit (nixpkgs-privatebin.legacyPackages.${system}) privatebin pbcli; }) |
| 38 | ]; |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 39 | }; |
| 40 | in |
Skyler Grey | b3516c2 | 2023-05-24 19:17:11 +0200 | [diff] [blame] | 41 | rec { |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 42 | nixosConfigurations.clicks = |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 43 | let |
| 44 | base = nixpkgs.lib.nixosSystem { |
| 45 | inherit system pkgs; |
| 46 | modules = [ |
| 47 | ./default/configuration.nix |
| 48 | ./default/hardware-configuration.nix |
Skyler Grey | 703e75a | 2023-06-08 13:39:50 +0200 | [diff] [blame] | 49 | ./modules/cache.nix |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 50 | ./modules/caddy.nix |
| 51 | ./modules/clamav.nix |
Skyler Grey | 5e2bc9e | 2023-08-24 21:58:52 +0000 | [diff] [blame] | 52 | ./modules/cloudflare-ddns.nix |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 53 | ./modules/dmarc.nix |
| 54 | ./modules/dnsmasq.nix |
| 55 | ./modules/doas.nix |
| 56 | ./modules/docker.nix |
Skyler Grey | 87a1155 | 2023-06-14 23:02:25 +0200 | [diff] [blame] | 57 | ./modules/drivePaths.nix |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 58 | ./modules/ecryptfs.nix |
| 59 | ./modules/fail2ban.nix |
| 60 | ./modules/fuck.nix |
| 61 | ./modules/git.nix |
| 62 | ./modules/grafana.nix |
| 63 | ./modules/home-manager-users.nix |
Skyler Grey | 0e05d26 | 2023-10-09 07:04:36 +0000 | [diff] [blame] | 64 | ./modules/keycloak.nix |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 65 | ./modules/kitty.nix |
Skyler Grey | 480fd8b | 2023-05-24 19:11:16 +0200 | [diff] [blame] | 66 | ./modules/loginctl-linger.nix |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 67 | ./modules/matrix.nix |
| 68 | ./modules/mongodb.nix |
Skyler Grey | 09c5cda | 2023-10-09 07:10:10 +0000 | [diff] [blame] | 69 | ./modules/nextcloud.nix |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 70 | ./modules/node.nix |
| 71 | ./modules/postgres.nix |
Skyler Grey | 9fe6128 | 2023-08-20 21:52:48 +0000 | [diff] [blame] | 72 | ./modules/privatebin.nix |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 73 | ./modules/samba.nix |
| 74 | ./modules/scalpel.nix |
Skyler Grey | 07c947a | 2023-06-08 14:11:23 +0200 | [diff] [blame] | 75 | ./modules/ssh.nix |
Skyler Grey | 5b2c038 | 2023-05-29 11:09:05 +0200 | [diff] [blame] | 76 | ./modules/static-ip.nix |
Skyler Grey | 87a1155 | 2023-06-14 23:02:25 +0200 | [diff] [blame] | 77 | ./modules/syncthing.nix |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 78 | ./modules/tesseract.nix |
Skyler Grey | 87a1155 | 2023-06-14 23:02:25 +0200 | [diff] [blame] | 79 | ./modules/vaultwarden.nix |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 80 | sops-nix.nixosModules.sops |
Skyler Grey | 9fe6128 | 2023-08-20 21:52:48 +0000 | [diff] [blame] | 81 | "${nixpkgs-privatebin}/nixos/modules/services/web-apps/privatebin.nix" |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 82 | { |
| 83 | users.mutableUsers = false; |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 84 | } |
| 85 | ]; |
TheCodedProf | d23784c | 2023-06-13 14:28:23 -0400 | [diff] [blame] | 86 | specialArgs = { base = null; drive_paths = import ./variables/drive_paths.nix; }; |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 87 | }; |
| 88 | in |
| 89 | base.extendModules { |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 90 | modules = [ |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 91 | scalpel.nixosModules.scalpel |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 92 | ]; |
Skyler Grey | a78aa67 | 2023-05-20 13:48:18 +0200 | [diff] [blame] | 93 | specialArgs = { inherit base; }; |
Skyler Grey | 4f3e606 | 2023-03-04 01:29:29 +0000 | [diff] [blame] | 94 | }; |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 95 | |
Skyler Grey | b3516c2 | 2023-05-24 19:17:11 +0200 | [diff] [blame] | 96 | nixosConfigurations.clicks-without-mongodb = |
| 97 | nixosConfigurations.clicks.extendModules { |
| 98 | modules = [ |
| 99 | { services.mongodb.enable = nixpkgs.lib.mkForce false; } |
| 100 | ]; |
| 101 | }; |
| 102 | |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 103 | deploy.nodes.clicks = { |
| 104 | sudo = "doas -u"; |
| 105 | profiles = { |
| 106 | system = { |
| 107 | remoteBuild = true; |
| 108 | user = "root"; |
| 109 | path = deploy-rs.lib.x86_64-linux.activate.nixos |
| 110 | self.nixosConfigurations.clicks; |
| 111 | }; |
| 112 | } // ( |
| 113 | let |
| 114 | mkServiceConfig = service: { |
| 115 | remoteBuild = true; |
| 116 | user = service; |
| 117 | |
| 118 | profilePath = "/nix/var/nix/profiles/per-user/${service}/home-manager"; |
| 119 | path = |
| 120 | deploy-rs.lib.x86_64-linux.activate.home-manager (home-manager.lib.homeManagerConfiguration |
| 121 | { |
| 122 | inherit pkgs; |
| 123 | modules = [ |
| 124 | { |
| 125 | home.homeDirectory = "/services/${service}"; |
| 126 | home.username = service; |
| 127 | home.stateVersion = "22.11"; |
| 128 | programs.home-manager.enable = true; |
| 129 | } |
| 130 | "${./services}/${service}" |
| 131 | ]; |
Skyler Grey | b30f5dd | 2023-09-01 21:02:44 +0000 | [diff] [blame] | 132 | extraSpecialArgs = { inherit (inputs) nixpkgs-clicksforms; inherit system; }; |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 133 | }); |
| 134 | }; |
| 135 | in |
| 136 | nixpkgs.lib.pipe ./services [ |
| 137 | builtins.readDir |
| 138 | (nixpkgs.lib.filterAttrs (_name: value: value == "directory")) |
| 139 | builtins.attrNames |
| 140 | (map (name: { |
| 141 | inherit name; value = mkServiceConfig name; |
| 142 | })) |
| 143 | builtins.listToAttrs |
| 144 | ] |
Skyler Grey | 5b2c038 | 2023-05-29 11:09:05 +0200 | [diff] [blame] | 145 | ) // ( |
| 146 | let |
| 147 | mkBlankConfig = username: |
| 148 | { |
| 149 | remoteBuild = true; |
| 150 | user = username; |
| 151 | |
| 152 | profilePath = "/nix/var/nix/profiles/per-user/${username}/home-manager"; |
| 153 | path = |
| 154 | deploy-rs.lib.x86_64-linux.activate.home-manager (home-manager.lib.homeManagerConfiguration |
| 155 | { |
| 156 | inherit pkgs; |
| 157 | modules = [ |
| 158 | { |
| 159 | home.username = username; |
| 160 | home.stateVersion = "22.11"; |
| 161 | programs.home-manager.enable = true; |
| 162 | } |
| 163 | "${./homes}/${username}" |
| 164 | ]; |
| 165 | }); |
| 166 | }; |
| 167 | in |
| 168 | nixpkgs.lib.pipe ./homes [ |
| 169 | builtins.readDir |
| 170 | (nixpkgs.lib.filterAttrs (_name: value: value == "directory")) |
| 171 | builtins.attrNames |
| 172 | (map (name: { |
| 173 | inherit name; value = mkBlankConfig name; |
| 174 | })) |
| 175 | builtins.listToAttrs |
| 176 | ] |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 177 | ); |
| 178 | hostname = "clicks"; |
| 179 | profilesOrder = [ "system" ]; |
Skyler Grey | 1e2187f | 2023-03-03 22:45:10 +0000 | [diff] [blame] | 180 | }; |
Skyler Grey | 1e2187f | 2023-03-03 22:45:10 +0000 | [diff] [blame] | 181 | |
Skyler Grey | b30f5dd | 2023-09-01 21:02:44 +0000 | [diff] [blame] | 182 | devShells.x86_64-linux.default = pkgs.mkShell { |
| 183 | packages = [ pkgs.deploy-rs ]; |
| 184 | }; |
| 185 | |
Skyler Grey | 07584fb | 2023-05-01 21:37:13 +0000 | [diff] [blame] | 186 | formatter.x86_64-linux = nixpkgs.legacyPackages.x86_64-linux.nixpkgs-fmt; |
Skyler Grey | 1e2187f | 2023-03-03 22:45:10 +0000 | [diff] [blame] | 187 | }; |
Skyler Grey | 1e2187f | 2023-03-03 22:45:10 +0000 | [diff] [blame] | 188 | } |