diff --git a/.forgejo/workflows/activate.yml b/.forgejo/workflows/activate.yml index 29bfb2d..fab8702 100644 --- a/.forgejo/workflows/activate.yml +++ b/.forgejo/workflows/activate.yml @@ -19,24 +19,14 @@ jobs: echo "$SSH_KEY" > ./ssh/deploy_key chmod 600 ./ssh/deploy_key - - name: Build and set boot configuration + - name: Rebuild and switch run: | ssh -i ./ssh/deploy_key \ -o PasswordAuthentication=no \ -o StrictHostKeyChecking=no \ -o UserKnownHostsFile=/dev/null \ root@localhost \ - "bash -lc 'nixos-rebuild boot --refresh --flake git+http://localhost:5080/satr14/nix-flake#homelab -L'" - - - name: Activate configuration - continue-on-error: true - run: | - ssh -i ./ssh/deploy_key \ - -o PasswordAuthentication=no \ - -o StrictHostKeyChecking=no \ - -o UserKnownHostsFile=/dev/null \ - root@localhost \ - "bash -lc 'setsid nohup /nix/var/nix/profiles/system/bin/switch-to-configuration switch > /var/log/nixos-switch.log 2>&1 < /dev/null & disown'" + "bash -lc 'nixos-rebuild switch --refresh --flake git+http://localhost:5080/satr14/nix-flake#homelab -L'" - name: Notify on failure if: failure() @@ -48,6 +38,15 @@ jobs: -H "Actions: view, Action Runs, https://git.satr14.my.id/${{ github.repository }}/actions?workflow=activate.yml; view, View Commit, https://git.satr14.my.id/${{ github.repository }}/commit/${{ github.sha }}" \ -d "${{ github.event.head_commit.message }}" + # - name: Notify on success + # if: success() + # run: | + # curl -s -X POST https://notify.proxy.satr14.my.id/git-flake-updates \ + # -H "Title: NixOS Homelab Rebuild Succeeded" \ + # -H "Tags: white_check_mark" \ + # -H "Actions: view, View Commit, https://git.satr14.my.id/${{ github.repository }}/commit/${{ github.sha }}" \ + # -d "${{ github.event.head_commit.message }}" + - name: Clean Up if: always() run: rm -f ./ssh/deploy_key \ No newline at end of file diff --git a/flake.lock b/flake.lock index c741025..1b69fe1 100644 --- a/flake.lock +++ b/flake.lock @@ -5,11 +5,11 @@ "nixpkgs": "nixpkgs" }, "locked": { - "lastModified": 1784366307, - "narHash": "sha256-VKatYOZwLQ+MuNkWH6/gZYxrNeSK1Mqb7mC0H1WSu+M=", + "lastModified": 1783674541, + "narHash": "sha256-vmUhEF/jBCZJeK0dInOls+HOAR0yiiQusN1+FZKaJss=", "owner": "catppuccin", "repo": "nix", - "rev": "673f730d0fc8db3468c51575f1d3d777cc55e51f", + "rev": "96799f24cf1366fe88e1293c3d27521a8f2129cf", "type": "github" }, "original": { @@ -78,11 +78,11 @@ ] }, "locked": { - "lastModified": 1784913159, - "narHash": "sha256-JWq0BfjO4ktpH5USfQNQzdvHpIDT8fSKD5K7LvdMRFs=", + "lastModified": 1784129366, + "narHash": "sha256-N5JiyICSeQF14x+OQebNyPpYowOT9Rs1iKyeCylSzOA=", "owner": "nix-community", "repo": "home-manager", - "rev": "079a3b5d1aa6a719920a51316253b7d6dd22738d", + "rev": "165228b0efefc3e635e5174020c40ea64271dc25", "type": "github" }, "original": { @@ -99,11 +99,11 @@ "systems": "systems_2" }, "locked": { - "lastModified": 1784949919, - "narHash": "sha256-itGqjPYHqEUqabXbQb+eHguk1c6rBTRGZS4KImp45kM=", + "lastModified": 1784258664, + "narHash": "sha256-/1hkRunsSzVmbKKIS84k09ss8kqvNG/gYKqnIOUGkXA=", "owner": "Infinidoge", "repo": "nix-minecraft", - "rev": "a58c1fa23ec0273eb085be1e7874e964aa3cd34f", + "rev": "0d9d58d2024d823ea167503e26d38a16be0d1e26", "type": "github" }, "original": { @@ -122,11 +122,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1784874881, - "narHash": "sha256-u4jhSIf/Un0qZB+Cn3hTTaHSI20XeAxYbA5o4faqdJs=", + "lastModified": 1784189744, + "narHash": "sha256-D8oh9imibOynWAOUnvgG3w2EKDYqf8OTTaLCcTA4ePg=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "ef7a2a3d719af46b906c22a3ebfb7d65627b2cd2", + "rev": "f4b479398c967d2c8d5a38b6d2c87283ae5078c4", "type": "github" }, "original": { @@ -155,11 +155,11 @@ "niri-unstable": { "flake": false, "locked": { - "lastModified": 1784570726, - "narHash": "sha256-9EMn69JBcFWFgUM7f0VBAX+jBby5b9H3M59U75+5yI4=", + "lastModified": 1783522755, + "narHash": "sha256-dI0HkX1djETia7cD/Y64h8BNIsSOfTRMzfNum2J6UhE=", "owner": "YaLTeR", "repo": "niri", - "rev": "7f26c3ee804fb6ed458ef7fb0e3c794f14e0b3bc", + "rev": "0777769e719b7c9b7c980d4ea66288bfbb4da5b3", "type": "github" }, "original": { @@ -230,11 +230,11 @@ }, "nixpkgs_4": { "locked": { - "lastModified": 1784796856, - "narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=", + "lastModified": 1784120854, + "narHash": "sha256-KesHgItiZPgGX740axSiQLcIQ8D24MDqNpkKYWIek8k=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "e2587caef70cea85dd97d7daab492899902dbf5d", + "rev": "753cc8a3a87467296ddd1fa93f0cc3e81120ee46", "type": "github" }, "original": { @@ -246,11 +246,11 @@ }, "nixpkgs_5": { "locked": { - "lastModified": 1784796856, - "narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=", + "lastModified": 1784120854, + "narHash": "sha256-KesHgItiZPgGX740axSiQLcIQ8D24MDqNpkKYWIek8k=", "owner": "nixos", "repo": "nixpkgs", - "rev": "e2587caef70cea85dd97d7daab492899902dbf5d", + "rev": "753cc8a3a87467296ddd1fa93f0cc3e81120ee46", "type": "github" }, "original": { @@ -320,11 +320,11 @@ "xwayland-satellite-unstable": { "flake": false, "locked": { - "lastModified": 1784679892, - "narHash": "sha256-Mb7jpqnrcYCfNSItIkkHpuR3YxWFxPuIBfcwNKlRBkk=", + "lastModified": 1783895132, + "narHash": "sha256-Dl0Gvrig3EpE962hzF3ETPhUztlfuRhcmlpd8ioHN54=", "owner": "Supreeeme", "repo": "xwayland-satellite", - "rev": "8d135d3b2854b30fd01ea6cd6c27e523dd50a839", + "rev": "a2b5c635d8c8c99b286967658d0d177044887eb8", "type": "github" }, "original": { diff --git a/lib/options.nix b/lib/options.nix index 433cc0b..cef1177 100644 --- a/lib/options.nix +++ b/lib/options.nix @@ -41,7 +41,7 @@ in { [ "PocketID" "authentik" "https://auth.${domain}" "http://localhost:1411/" ] [ "Forgejo" "forgejo" "https://git.${domain}" "http://localhost:5080/" ] [ "Copyparty" "files" "https://cdn.${domain}" "http://localhost:3923/" ] - [ "Cockpit" "cockpit" "https://control.proxy.${domain}" "http://localhost:9090/" ] + [ "CryptPad" "cryptpad" "https://docs.${domain}" "http://localhost:7090/" ] [ "CodeServer" "coder" "https://code.proxy.${domain}" "http://localhost:8443/" ] [ "AdGuardHome" "adguard" "https://dns.proxy.${domain}" "http://localhost:8088/" ] [ "Traefik" "traefikproxy" "https://dynamic.proxy.${domain}/dashboard/" "" ] @@ -56,6 +56,9 @@ in { routes = { "mc.${domain}" = "tcp://localhost:25565"; + "docs-sandbox.${domain}" = "http://localhost:7090"; + "docs.${domain}" = "http://localhost:7090"; + "cdn.${domain}" = selfSigned "https://localhost:3923"; "git.${domain}" = "http://localhost:5080"; @@ -71,7 +74,6 @@ in { "code" = da "http://localhost:8443"; "dns" = da "http://localhost:8088"; - "control" = d "https://localhost:9090"; "gallery" = d "http://localhost:2283"; "dynamic" = d "http://localhost:8082"; "search" = d "http://localhost:8091"; @@ -102,7 +104,7 @@ in { }; rice = { - font = "DroidSansM Nerd Font"; # global font for rice GUIs, must be a Nerd Font for icon glyphs to render correctly + font = "monospace"; # global font for rice GUIs, leave empty to use monospace bar = { top = true; # false will put the bar at the bottom fragmented = true; # enable fragmented bar, false will make it a single block diff --git a/modules/hardware/misc/battery-power.nix b/modules/hardware/misc/battery-power.nix index 80c6ec9..8c529e1 100644 --- a/modules/hardware/misc/battery-power.nix +++ b/modules/hardware/misc/battery-power.nix @@ -13,14 +13,13 @@ cron = { enable = true; systemCronJobs = [ - "*/2 * * * * ${username} bash ${pkgs.writeShellScript "low-battery-notifier" '' - ACPI_OUT=$(${pkgs.acpi}/bin/acpi -b) - BAT_PCT=`echo "$ACPI_OUT" | ${pkgs.gnugrep}/bin/grep -P -o '[0-9]+(?=%)'` - BAT_STA=`echo "$ACPI_OUT" | ${pkgs.gnugrep}/bin/grep -P -o '\w+(?=,)'` + "* * * * * ${username} bash -x ${pkgs.writeShellScript "low-battery-notifier" '' + BAT_PCT=`${pkgs.acpi}/bin/acpi -b | ${pkgs.gnugrep}/bin/grep -P -o '[0-9]+(?=%)'` + BAT_STA=`${pkgs.acpi}/bin/acpi -b | ${pkgs.gnugrep}/bin/grep -P -o '\w+(?=,)'` echo "`date` battery status:$BAT_STA percentage:$BAT_PCT" export DISPLAY=:0 export DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/$(id -u)/bus - test $BAT_PCT -le 30 && test $BAT_PCT -gt 15 && test $BAT_STA = "Discharging" && ${pkgs.libnotify}/bin/notify-send "Low Battery" "Battery remaining: $BAT_PCT%." && brightnessctl s 30% + test $BAT_PCT -le 30 && test $BAT_PCT -gt 15 && test $BAT_STA = "Discharging" && ${pkgs.libnotify}/bin/notify-send "Low Battery" "Battery remaining: $BAT_PCT%." test $BAT_PCT -le 15 && test $BAT_STA = "Discharging" && ${pkgs.libnotify}/bin/notify-send -u critical "Low Battery" "Shutdown at 10%." ''} > /tmp/cron.batt.log 2>&1" ]; diff --git a/modules/hardware/misc/cpu-freq.nix b/modules/hardware/misc/cpu-freq.nix index 63323a3..ad87022 100644 --- a/modules/hardware/misc/cpu-freq.nix +++ b/modules/hardware/misc/cpu-freq.nix @@ -49,27 +49,23 @@ }; auto-cpufreq = { enable = true; # wait for fix: https://github.com/AdnanHodzic/auto-cpufreq/issues/906 - settings = let - performance = { - governor = "performance"; + settings = { + charger = { + governor = "powersave"; # "performance"; energy_performance_preference = "performance"; turbo = "always"; platform_profile = "performance"; scaling_min_freq = 800000; scaling_max_freq = 3600000; }; - balanced = { + battery = { governor = "powersave"; energy_performance_preference = "balance-power"; + platform_profile = "low-power"; turbo = "never"; - platform_profile = "balanced"; scaling_min_freq = 400000; scaling_max_freq = 1700000; }; - in { - battery = balanced; - charger = balanced; # performance; - # ^^ disable overclocking for purely productivity use so low temps and fan noise }; }; }; diff --git a/modules/home/core/apps.nix b/modules/home/core/apps.nix index 974a602..214a70c 100644 --- a/modules/home/core/apps.nix +++ b/modules/home/core/apps.nix @@ -28,7 +28,6 @@ home.packages = with pkgs; [ zed-editor opencode - github-copilot-cli slack discord @@ -46,9 +45,8 @@ gpu-screen-recorder gpu-screen-recorder-gtk - # LOCK IN - # (prismlauncher.override { - # jdks = with javaPackages.compiler.temurin-bin; [ jre-21 jdk-25 ]; - # }) + (prismlauncher.override { + jdks = with javaPackages.compiler.temurin-bin; [ jre-21 jdk-25 ]; + }) ]; } diff --git a/modules/home/core/cli.nix b/modules/home/core/cli.nix index 2dc4b10..9e9b94e 100644 --- a/modules/home/core/cli.nix +++ b/modules/home/core/cli.nix @@ -30,9 +30,6 @@ cursor_trail = 10; copy_on_select = true; }; - keybindings = { - "ctrl+backspace" = "send_text all \\x17"; - }; }; ranger = { enable = true; diff --git a/modules/home/core/code.nix b/modules/home/core/code.nix index 6803152..044f3a7 100644 --- a/modules/home/core/code.nix +++ b/modules/home/core/code.nix @@ -40,7 +40,6 @@ }; }; agent = { - sidebar_side = "right"; tool_permissions.default = "allow"; default_model = { provider = "copilot_chat"; diff --git a/modules/home/core/shell.nix b/modules/home/core/shell.nix index 70dab70..a26d6d1 100644 --- a/modules/home/core/shell.nix +++ b/modules/home/core/shell.nix @@ -61,9 +61,6 @@ "wm-lock" = "wm-ctl dispatch exec loginctl lock-session && notify-send ${hostname} 'Manual lock triggered'"; "wm-disp" = "wm-ctl dispatch dpms"; - "gz-compress" = "tar -czhf"; - "gz-extract" = "tar -xzf"; - "gh-author-setup" = "git config user.name $(gh api -H \"Accept: application/vnd.github+json\" -H \"X-GitHub-Api-Version: 2022-11-28\" /user | jq -r .login) && git config user.email $(gh api -H \"Accept: application/vnd.github+json\" -H \"X-GitHub-Api-Version: 2022-11-28\" /user/emails | jq -r \".[1].email\")"; "fg-create-repo" = "git remote add origin ${git.server}/${git.username}/$(basename $PWDw).git && git push"; "convert-pdf" = "libreoffice --headless --convert-to pdf"; diff --git a/modules/home/rice/bar.nix b/modules/home/rice/bar.nix index cc6b175..4360e9c 100644 --- a/modules/home/rice/bar.nix +++ b/modules/home/rice/bar.nix @@ -180,7 +180,7 @@ style = '' * { font-size: 12px; - font-family: ${rice.font}; + font-family: Font Awesome, ${rice.font}; font-weight: bold; color: @text; transition: none; diff --git a/modules/home/rice/compositor.nix b/modules/home/rice/compositor.nix index cca6797..10e0813 100644 --- a/modules/home/rice/compositor.nix +++ b/modules/home/rice/compositor.nix @@ -25,7 +25,7 @@ XCURSOR_SIZE = "24"; XCURSOR_THEME = "catppuccin-${ctp-opt.flavor}-light-cursors"; - CLIPHIST_MAX_ITEMS = "90"; + CLIPHIST_MAX_ITEMS = "36"; GTK_APPLICATION_PREFER_DARK_THEME = "1"; GTK_THEME = "Adwaita:dark"; @@ -89,6 +89,7 @@ "wl-paste --type image --watch cliphist store" "uwsm app -s s -- waybar &" + "uwsm app -s b -- sunshine &" "uwsm app -s b -- blueman-applet &" "uwsm app -s b -- nm-applet &" "uwsm app -s b -- tailscale systray &" diff --git a/modules/home/rice/keybinds.nix b/modules/home/rice/keybinds.nix index d63a7d3..8e01baa 100644 --- a/modules/home/rice/keybinds.nix +++ b/modules/home/rice/keybinds.nix @@ -1,7 +1,7 @@ { pkgs, lib, hostname, ... }: { programs.niri.settings.binds = { - "XF86AudioRaiseVolume" = { action.spawn = [ "wpctl" "set-volume" "-l" "1" "@DEFAULT_AUDIO_SINK@" "2%+" ]; allow-when-locked = true; }; - "XF86AudioLowerVolume" = { action.spawn = [ "wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "2%-" ]; allow-when-locked = true; }; + "XF86AudioRaiseVolume" = { action.spawn = [ "wpctl" "set-volume" "-l" "1" "@DEFAULT_AUDIO_SINK@" "5%+" ]; allow-when-locked = true; }; + "XF86AudioLowerVolume" = { action.spawn = [ "wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "5%-" ]; allow-when-locked = true; }; "XF86AudioMute" = { action.spawn = [ "wpctl" "set-mute" "@DEFAULT_AUDIO_SINK@" "toggle" ]; allow-when-locked = true; }; "XF86AudioMicMute" = { action.spawn = [ "wpctl" "set-mute" "@DEFAULT_AUDIO_SOURCE@" "toggle" ]; allow-when-locked = true; }; "XF86MonBrightnessUp" = { action.spawn = [ "brightnessctl" "s" "10%+" ]; allow-when-locked = true; }; @@ -10,9 +10,8 @@ "Mod+Q".action.close-window = {}; "Mod+W".action.maximize-column = {}; "Mod+S".action.fullscreen-window = {}; - "Ctrl+Print".action.screenshot-window = {}; - "Alt+Print".action.screenshot-screen = {}; - "Print".action.screenshot = {}; + "Alt+Print".action.screenshot-window = {}; + "Print".action.screenshot-screen = {}; "Mod+Up".action.focus-workspace-up = {}; "Mod+Down".action.focus-workspace-down = {}; @@ -23,18 +22,15 @@ "Mod+Shift+Down".action.move-window-down-or-to-workspace-down = {}; "Mod+Shift+Left".action.move-column-left = {}; "Mod+Shift+Right".action.move-column-right = {}; - "Mod+Ctrl+Left".action.set-window-width = [ "-2%" ]; - "Mod+Ctrl+Right".action.set-window-width = [ "+2%" ]; - "Mod+Ctrl+Down".action.set-window-height = [ "+2%" ]; - "Mod+Ctrl+Up".action.set-window-height = [ "-2%" ]; + "Mod+Ctrl+Left".action.set-column-width = [ "-5%" ]; + "Mod+Ctrl+Right".action.set-column-width = [ "+5%" ]; "Mod+G".action.center-column = {}; "Mod+F".action.toggle-window-floating = {}; "Alt+Space".action.toggle-overview = {}; "Mod+Space" = { action.spawn = [ "playerctl" "play-pause" ]; allow-when-locked = true; }; - "Mod+R".action.spawn = [ "rofi" "-show" "drun" "-show-icons" "-display-drun" "" "-run-command" "{cmd}" ]; - "Mod+Shift+R".action.spawn = [ "rofi" "-show" "drun" "-show-icons" "-display-drun" "wayland-0" "-run-command" "sh -c 'WAYLAND_DISPLAY=wayland-0 DISPLAY=:1 exec {cmd}'" ]; + "Mod+R".action.spawn = [ "rofi" "-show" "drun" "-show-icons" "-display-drun" "" "-run-command" "uwsm app -- {cmd}" ]; "Mod+E".action.spawn = [ "pcmanfm-qt" ]; "Mod+T".action.spawn = [ "kitty" ]; diff --git a/modules/system/base.nix b/modules/system/base.nix index d62b589..2cdea36 100644 --- a/modules/system/base.nix +++ b/modules/system/base.nix @@ -16,14 +16,7 @@ i18n.defaultLocale = locale; environment.localBinInPath = true; - powerManagement.cpuFreqGovernor = "powersave"; - boot.kernel.sysctl."vm.swappiness" = 10; # only swap when necessary - security = { - polkit = { - enable = true; - enablePkexecWrapper = true; - }; sudo.configFile = '' Defaults insults Defaults passwd_tries = 5 diff --git a/modules/system/core/bootloader.nix b/modules/system/core/bootloader.nix index 20d65ec..cca3d3f 100644 --- a/modules/system/core/bootloader.nix +++ b/modules/system/core/bootloader.nix @@ -1,11 +1,12 @@ { pkgs, legacy-boot, ... }: { boot = { + plymouth.enable = true; loader = { efi.canTouchEfiVariables = true; systemd-boot = { enable = !legacy-boot; configurationLimit = 3; - sortKey = "nixos"; + sortKey = "z-nixos"; editor = false; }; grub = { diff --git a/modules/system/desktop.nix b/modules/system/desktop.nix index 0aeb936..ec264eb 100644 --- a/modules/system/desktop.nix +++ b/modules/system/desktop.nix @@ -22,7 +22,7 @@ package = pkgs.niri-unstable; }; hyprland = { - enable = false; + enable = true; withUWSM = true; xwayland.enable = true; package = pkgs.hyprland; # if rice.enable then inputs.hl.packages."${pkgs.system}".hyprland else pkgs.hyprland; @@ -33,7 +33,7 @@ xdg.portal = { enable = true; extraPortals = [ - pkgs.xdg-desktop-portal-luminous + pkgs.xdg-desktop-portal-hyprland #inputs.hl.packages.${pkgs.system}.xdg-desktop-portal-hyprland pkgs.xdg-desktop-portal-gtk ]; }; diff --git a/modules/system/homelab/cdn.nix b/modules/system/homelab/cdn.nix index 28925f5..407863e 100644 --- a/modules/system/homelab/cdn.nix +++ b/modules/system/homelab/cdn.nix @@ -1,25 +1,18 @@ { pkgs, ... }: let - python = pkgs.python3.withPackages (ps: with ps; [ pillow argon2-cffi ]); - script = let - version = "v1.20.18"; - in pkgs.fetchurl { + version = "v1.20.18"; + executable = pkgs.fetchurl { url = "https://github.com/9001/copyparty/releases/download/${version}/copyparty-en.py"; hash = "sha256-8SBrKaLPat80n8sONKQYFeFSQXUnCYtwcOU7SR52h7E="; - }; - executable = pkgs.writeShellScriptBin "copyparty" '' - exec ${python}/bin/python3 ${script} "$@" - ''; + }; in { - environment.systemPackages = [ executable ]; systemd.services.copyparty = { description = "File Sharing Service"; enable = true; after = [ "network.target" ]; wantedBy = [ "multi-user.target" ]; - path = [ pkgs.ffmpeg ]; serviceConfig = { # ExecStart = "${pkgs.copyparty-most}/bin/copyparty -c /mnt/share/cfg/files.conf"; - ExecStart = "${python}/bin/python3 ${script} --ah-alg argon2 -c /mnt/share/cfg/files.conf"; + ExecStart = "${pkgs.python3}/bin/python3 ${executable} -c /mnt/share/cfg/files.conf"; Restart = "on-failure"; }; }; diff --git a/modules/system/homelab/control.nix b/modules/system/homelab/control.nix deleted file mode 100644 index 9522910..0000000 --- a/modules/system/homelab/control.nix +++ /dev/null @@ -1,9 +0,0 @@ -{ homelab, pkgs, ... }: { - services.cockpit = { - enable = true; - allowed-origins = [ "https://control.proxy.${homelab.domain}" ]; - plugins = with pkgs; [ - cockpit-files cockpit-machines - ]; - }; -} \ No newline at end of file diff --git a/modules/system/homelab/dns.nix b/modules/system/homelab/dns.nix index ee7e512..a1ddbb3 100644 --- a/modules/system/homelab/dns.nix +++ b/modules/system/homelab/dns.nix @@ -21,13 +21,6 @@ whitelist = [ "https://gist.githubusercontent.com/mul14/eb05e88fcec5bb195cbb/raw/75a1fe122a4502e8d5a5268c9d0ec28332b19d5d/hosts" ]; - blocked = [ - # LOCK IN - "instagram" - "youtube" - "minecraft" - "steam" - ]; in { services.adguardhome = { enable = true; @@ -44,7 +37,6 @@ in { enabled = true; }; filtering = { - blocked_services.ids = blocked; blocking_mode = "null_ip"; protection_enabled = true; safebrowsing_enabled = true; diff --git a/modules/system/homelab/docs.nix b/modules/system/homelab/docs.nix new file mode 100644 index 0000000..58d6738 --- /dev/null +++ b/modules/system/homelab/docs.nix @@ -0,0 +1,46 @@ +{ lib, pkgs, homelab, ... }: let + domain = "docs.${homelab.domain}"; + sandbox = "docs-sandbox.${homelab.domain}"; +in { + services.cryptpad = { + enable = true; + settings = { + websocketPort = 7091; + httpPort = 7090; + httpAddress = "127.0.0.1"; + httpUnsafeOrigin = "https://${domain}"; + httpSafeOrigin = "https://${sandbox}"; + blockDailyCheck = true; + disableIntegratedEviction = true; + adminKeys = [ + "[satr14@docs.satr14.my.id/f1A82fmBuqQka2bNqrCb1WbB9r2ex5A3rdys5xLX3Hc=]" + ]; + }; + }; + + systemd.tmpfiles.rules = lib.singleton "L+ /var/lib/cryptpad/customize/application_config.js - - - - ${pkgs.writeText "cryptpad-application-config.js" '' + (() => { + const factory = (AppConfig) => { + AppConfig.disableAnonymousPadCreation = true; + AppConfig.disableAnonymousStore = true; + AppConfig.defaultDarkTheme = true; + return AppConfig; + }; + + if (typeof(module) !== 'undefined' && module.exports) { + module.exports = factory( + require('../www/common/application_config_internal.js') + ); + } else if ((typeof(define) !== 'undefined' && define !== null) && (define.amd !== null)) { + define(['/common/application_config_internal.js'], factory); + } + })(); + ''}"; + + fileSystems."/var/lib/private/cryptpad" = { + device = "/mnt/data/apps/cryptpad"; + depends = [ "/mnt/data" ]; + options = [ "bind" "nofail" ]; + fsType = "none"; + }; +} diff --git a/modules/system/homelab/gallery.nix b/modules/system/homelab/gallery.nix index 74d2ea2..1b52208 100644 --- a/modules/system/homelab/gallery.nix +++ b/modules/system/homelab/gallery.nix @@ -1,10 +1,4 @@ -{ pkgs, lib, ... }: { - # fix every update causing error: - # > microservices worker error: PostgresError: must be owner of function album_user_after_insert, stack: PostgresError: must be owner of function album_user_after_insert - systemd.services.postgresql.postStart = pkgs.lib.mkAfter '' - $PSQL -d immich -c "ALTER FUNCTION album_user_after_insert() OWNER TO immich;" || true - ''; - +{ lib, ... }: { users.users.immich.extraGroups = [ "video" "render" ]; services = { diff --git a/modules/system/homelab/mc/default.nix b/modules/system/homelab/mc/default.nix index a452cfd..ae55545 100644 --- a/modules/system/homelab/mc/default.nix +++ b/modules/system/homelab/mc/default.nix @@ -5,10 +5,12 @@ inputs.mc.nixosModules.minecraft-servers ]; nixpkgs.overlays = [ inputs.mc.overlay ]; + + powerManagement.cpuFreqGovernor = "powersave"; # performance governor causes overheating and thermal throttling, works fine with powesave + boot.kernel.sysctl."vm.swappiness" = 10; # reduce swap usage and keep memory performance smooth services.minecraft-servers = { - # LOCK IN - enable = false; + enable = true; eula = true; managementSystem.systemd-socket.enable = true; # ^^^ https://github.com/Infinidoge/nix-minecraft/issues/119 diff --git a/modules/system/homelab/mc/mc0-vanilla-plus.nix b/modules/system/homelab/mc/mc0-vanilla-plus.nix index 5240835..79f86bc 100644 --- a/modules/system/homelab/mc/mc0-vanilla-plus.nix +++ b/modules/system/homelab/mc/mc0-vanilla-plus.nix @@ -3,11 +3,6 @@ ram-allocation-mb = 8192; headroom-allocation-mb = 1024; rcon-pass = "howdy"; - ports = { - minecraft = 25565; - rcon = 25575; - }; - modpack = let useLatest = false; commit = "86bf13316ed1352a676d9056d284448ea5e5a079"; @@ -23,13 +18,13 @@ in { }; services.minecraft-servers.servers.${name} = { - enable = false; + enable = true; autoStart = true; restart = "always"; serverProperties = { server-ip = "0.0.0.0"; - server-port = ports.minecraft; + server-port = 25565; server-name = name; motd = "§cCan't connect to server"; log-ips = false; @@ -54,7 +49,7 @@ in { enable-rcon = true; sync-chunk-writes = false; "rcon.password" = rcon-pass; - "rcon.port" = ports.rcon; + "rcon.port" = 25575; }; symlinks = inputs.mc.lib.collectFilesAt modpack "mods" // { diff --git a/modules/system/homelab/mc/mc1-pure-vanilla.nix b/modules/system/homelab/mc/mc1-pure-vanilla.nix index 9268e35..6b64a85 100644 --- a/modules/system/homelab/mc/mc1-pure-vanilla.nix +++ b/modules/system/homelab/mc/mc1-pure-vanilla.nix @@ -3,10 +3,6 @@ ram-allocation-mb = 8192; headroom-allocation-mb = 1024; rcon-pass = "howdy"; - ports = { - minecraft = 25566; - rcon = 25576; - }; modpack = pkgs.fetchModrinthModpack { url = "https://cdn.modrinth.com/data/2wkV8mHp/versions/mFGJP1Ye/Server%20Optimization%201.21.11-2.1.mrpack"; @@ -21,7 +17,7 @@ in { serverProperties = { server-ip = "0.0.0.0"; - server-port = ports.minecraft; + server-port = 25566; server-name = name; motd = "§cCan't connect to server"; log-ips = false; @@ -46,7 +42,7 @@ in { enable-rcon = true; sync-chunk-writes = false; "rcon.password" = rcon-pass; - "rcon.port" = ports.rcon; + "rcon.port" = 25576; }; files = inputs.mc.lib.collectFilesAt modpack "config"; diff --git a/modules/system/homelab/mc/mc2-create-aeronautics.nix b/modules/system/homelab/mc/mc2-create-aeronautics.nix deleted file mode 100644 index 03f96f8..0000000 --- a/modules/system/homelab/mc/mc2-create-aeronautics.nix +++ /dev/null @@ -1,120 +0,0 @@ -{ inputs, lib, pkgs, ... }: let - name = "mc2-create-aeronautics"; - ram-allocation-mb = 12288; - headroom-allocation-mb = 2048; - rcon-pass = "howdy"; - ports = { - minecraft = 25567; - rcon = 25577; - }; - - modpack = let - useLatest = true; - commit = ""; - path = if !useLatest then "commit/${commit}" else "branch/main"; - in pkgs.fetchPackwizModpack { - packHash = ""; - url = "https://git.satr14.my.id/satr14/create-modpack/raw/${path}/pack.toml"; - }; -in { - systemd.services."minecraft-server-${name}" = { - environment.LD_LIBRARY_PATH = "${pkgs.stdenv.cc.cc.lib}/lib"; # physics toys mod fix - # serviceConfig.Nice = -5; # higher scheduling priority (causes fan noise even when idle) - }; - - services.minecraft-servers.servers.${name} = { - enable = false; - autoStart = true; - restart = "always"; - - serverProperties = { - server-ip = "0.0.0.0"; - server-port = ports.minecraft; - server-name = name; - motd = "§cCan't connect to server"; - log-ips = false; - hide-online-players = true; - - difficulty = "normal"; - gamemode = "survival"; - max-world-size = 25000; - spawn-protection = 0; - pvp = true; - - online-mode = true; - enable-query = true; - enforce-secure-profile = false; - pevent-proxy-connections = false; - allow-flight = false; - player-idle-timeout = 0; - - view-distance = 12; - simulation-distance = 6; - - enable-rcon = true; - sync-chunk-writes = false; - "rcon.password" = rcon-pass; - "rcon.port" = ports.rcon; - }; - - symlinks = inputs.mc.lib.collectFilesAt modpack "mods" // { - "polymer/packsquash" = let packsquash-binary = pkgs.runCommand "packsquash" { - src = pkgs.fetchurl { - url = "https://github.com/ComunidadAylas/PackSquash/releases/download/v0.4.1/packsquash-x86_64-unknown-linux-gnu.zip"; - sha256 = "sha256-VsGZewoiO5MjhIhwjlLO5d5uHynlAK5Jh16jH2k2rPs="; - }; - nativeBuildInputs = [ pkgs.unzip ]; - } '' - mkdir -p $out/bin - unzip $src -d $out/bin - chmod +x $out/bin/packsquash - ''; in "${packsquash-binary}/bin/packsquash"; - }; - - files = inputs.mc.lib.collectFilesAt modpack "config" // { - "config/proxy_protocol_support.json".value = { - enableProxyProtocol = false; # polymer auto host has issues with proxy protocol - whitelistTCPShieldServers = false; - proxyServerIPs = [ "127.0.0.1" "::1" ]; - directAccessIPs = [ "127.0.0.0/8" "::1/128" ]; - }; - }; - - extraStartPre = let sed-commands = lib.concatStringsSep "\n" ( - lib.mapAttrsToList (substitution: file: - ''sed -i "s|${substitution}|''${${substitution}}|g" ${file}'' - ) { - "REPLACE_SVC_HOST" = "config/voicechat/voicechat-server.properties"; - "REPLACE_RP_LINK" = "config/welcomemessage.json5"; - "REPLACE_DC_BOT_TOKEN" = "config/simple-discord-link/simple-discord-link.toml"; - "REPLACE_DC_OWNER_ROLE" = "config/simple-discord-link/simple-discord-link.toml"; - } - ); in '' - # shellcheck disable=SC1091 - if [ -f modpack-config.env ]; then - source modpack-config.env - ${sed-commands} - fi - ''; - - package = pkgs.fabricServers.fabric-1_21_11.override { - jre_headless = pkgs.javaPackages.compiler.temurin-bin.jdk-25; - loaderVersion = "0.19.2"; - }; - - jvmOpts = let flags = [ - "-Xms${toString ram-allocation-mb}M" - "-Xmx${toString ram-allocation-mb}M" - - "-XX:+UseZGC" # Use ZGC (requires Java v25+, 8+ CPU cores, 10GB+ RAM) - "-XX:+ZGenerational" # Use generational ZGC (newer and better ZGC, requires Java v21+) - "-XX:+UseCompactObjectHeaders" # Use compact object headers (requires Java v16+, saves a couple of bits per object) - - "--add-modules=jdk.incubator.vector" # Exposes SIMD instructions (requires full JDK, useful with performance mods like C2ME) - "-XX:+AlwaysPreTouch" # Pre-allocates memory on startup, OS claims it immediately for JVM instead of negotiating it - "-XX:+DisableExplicitGC" # Disables mods from manually invoking the GC - "-XX:+PerfDisableSharedMem" # Disables constant /tmp writes for JVM metrics - "-XX:SoftMaxHeapSize=${toString (ram-allocation-mb - headroom-allocation-mb)}M" # Leave 2GB headroom - ]; in lib.concatStringsSep " " flags; - }; -} \ No newline at end of file diff --git a/modules/system/homelab/proxy.nix b/modules/system/homelab/proxy.nix index 5a03057..d977892 100644 --- a/modules/system/homelab/proxy.nix +++ b/modules/system/homelab/proxy.nix @@ -8,7 +8,6 @@ proxy_cache off; send_timeout 600s; client_max_body_size 50000M; - proxy_ssl_session_reuse off; ''; in { users.users = { diff --git a/modules/system/misc/programs.nix b/modules/system/misc/programs.nix index acc3a7e..778858b 100644 --- a/modules/system/misc/programs.nix +++ b/modules/system/misc/programs.nix @@ -16,8 +16,7 @@ }; programs = { - # LOCK IN - # steam.enable = true; + steam.enable = true; gdk-pixbuf.modulePackages = [ pkgs.librsvg ]; appimage = { enable = true; diff --git a/modules/system/server.nix b/modules/system/server.nix index 7213cdc..9db8dfa 100644 --- a/modules/system/server.nix +++ b/modules/system/server.nix @@ -11,7 +11,6 @@ in { ./homelab/containers.nix ./homelab/gallery.nix ./homelab/tunnels.nix - ./homelab/control.nix ./homelab/notify.nix ./homelab/search.nix ./homelab/media.nix @@ -20,6 +19,7 @@ in { ./homelab/pass.nix ./homelab/dash.nix ./homelab/code.nix + ./homelab/docs.nix ./homelab/dns.nix ./homelab/git.nix ./homelab/cdn.nix