diff --git a/.forgejo/workflows/activate.yml b/.forgejo/workflows/activate.yml index fab8702..29bfb2d 100644 --- a/.forgejo/workflows/activate.yml +++ b/.forgejo/workflows/activate.yml @@ -19,14 +19,24 @@ jobs: echo "$SSH_KEY" > ./ssh/deploy_key chmod 600 ./ssh/deploy_key - - name: Rebuild and switch + - name: Build and set boot configuration run: | ssh -i ./ssh/deploy_key \ -o PasswordAuthentication=no \ -o StrictHostKeyChecking=no \ -o UserKnownHostsFile=/dev/null \ root@localhost \ - "bash -lc 'nixos-rebuild switch --refresh --flake git+http://localhost:5080/satr14/nix-flake#homelab -L'" + "bash -lc 'nixos-rebuild boot --refresh --flake git+http://localhost:5080/satr14/nix-flake#homelab -L'" + + - name: Activate configuration + continue-on-error: true + run: | + ssh -i ./ssh/deploy_key \ + -o PasswordAuthentication=no \ + -o StrictHostKeyChecking=no \ + -o UserKnownHostsFile=/dev/null \ + root@localhost \ + "bash -lc 'setsid nohup /nix/var/nix/profiles/system/bin/switch-to-configuration switch > /var/log/nixos-switch.log 2>&1 < /dev/null & disown'" - name: Notify on failure if: failure() @@ -38,15 +48,6 @@ jobs: -H "Actions: view, Action Runs, https://git.satr14.my.id/${{ github.repository }}/actions?workflow=activate.yml; view, View Commit, https://git.satr14.my.id/${{ github.repository }}/commit/${{ github.sha }}" \ -d "${{ github.event.head_commit.message }}" - # - name: Notify on success - # if: success() - # run: | - # curl -s -X POST https://notify.proxy.satr14.my.id/git-flake-updates \ - # -H "Title: NixOS Homelab Rebuild Succeeded" \ - # -H "Tags: white_check_mark" \ - # -H "Actions: view, View Commit, https://git.satr14.my.id/${{ github.repository }}/commit/${{ github.sha }}" \ - # -d "${{ github.event.head_commit.message }}" - - name: Clean Up if: always() run: rm -f ./ssh/deploy_key \ No newline at end of file diff --git a/flake.lock b/flake.lock index 1b69fe1..c741025 100644 --- a/flake.lock +++ b/flake.lock @@ -5,11 +5,11 @@ "nixpkgs": "nixpkgs" }, "locked": { - "lastModified": 1783674541, - "narHash": "sha256-vmUhEF/jBCZJeK0dInOls+HOAR0yiiQusN1+FZKaJss=", + "lastModified": 1784366307, + "narHash": "sha256-VKatYOZwLQ+MuNkWH6/gZYxrNeSK1Mqb7mC0H1WSu+M=", "owner": "catppuccin", "repo": "nix", - "rev": "96799f24cf1366fe88e1293c3d27521a8f2129cf", + "rev": "673f730d0fc8db3468c51575f1d3d777cc55e51f", "type": "github" }, "original": { @@ -78,11 +78,11 @@ ] }, "locked": { - "lastModified": 1784129366, - "narHash": "sha256-N5JiyICSeQF14x+OQebNyPpYowOT9Rs1iKyeCylSzOA=", + "lastModified": 1784913159, + "narHash": "sha256-JWq0BfjO4ktpH5USfQNQzdvHpIDT8fSKD5K7LvdMRFs=", "owner": "nix-community", "repo": "home-manager", - "rev": "165228b0efefc3e635e5174020c40ea64271dc25", + "rev": "079a3b5d1aa6a719920a51316253b7d6dd22738d", "type": "github" }, "original": { @@ -99,11 +99,11 @@ "systems": "systems_2" }, "locked": { - "lastModified": 1784258664, - "narHash": "sha256-/1hkRunsSzVmbKKIS84k09ss8kqvNG/gYKqnIOUGkXA=", + "lastModified": 1784949919, + "narHash": "sha256-itGqjPYHqEUqabXbQb+eHguk1c6rBTRGZS4KImp45kM=", "owner": "Infinidoge", "repo": "nix-minecraft", - "rev": "0d9d58d2024d823ea167503e26d38a16be0d1e26", + "rev": "a58c1fa23ec0273eb085be1e7874e964aa3cd34f", "type": "github" }, "original": { @@ -122,11 +122,11 @@ "xwayland-satellite-unstable": "xwayland-satellite-unstable" }, "locked": { - "lastModified": 1784189744, - "narHash": "sha256-D8oh9imibOynWAOUnvgG3w2EKDYqf8OTTaLCcTA4ePg=", + "lastModified": 1784874881, + "narHash": "sha256-u4jhSIf/Un0qZB+Cn3hTTaHSI20XeAxYbA5o4faqdJs=", "owner": "sodiboo", "repo": "niri-flake", - "rev": "f4b479398c967d2c8d5a38b6d2c87283ae5078c4", + "rev": "ef7a2a3d719af46b906c22a3ebfb7d65627b2cd2", "type": "github" }, "original": { @@ -155,11 +155,11 @@ "niri-unstable": { "flake": false, "locked": { - "lastModified": 1783522755, - "narHash": "sha256-dI0HkX1djETia7cD/Y64h8BNIsSOfTRMzfNum2J6UhE=", + "lastModified": 1784570726, + "narHash": "sha256-9EMn69JBcFWFgUM7f0VBAX+jBby5b9H3M59U75+5yI4=", "owner": "YaLTeR", "repo": "niri", - "rev": "0777769e719b7c9b7c980d4ea66288bfbb4da5b3", + "rev": "7f26c3ee804fb6ed458ef7fb0e3c794f14e0b3bc", "type": "github" }, "original": { @@ -230,11 +230,11 @@ }, "nixpkgs_4": { "locked": { - "lastModified": 1784120854, - "narHash": "sha256-KesHgItiZPgGX740axSiQLcIQ8D24MDqNpkKYWIek8k=", + "lastModified": 1784796856, + "narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "753cc8a3a87467296ddd1fa93f0cc3e81120ee46", + "rev": "e2587caef70cea85dd97d7daab492899902dbf5d", "type": "github" }, "original": { @@ -246,11 +246,11 @@ }, "nixpkgs_5": { "locked": { - "lastModified": 1784120854, - "narHash": "sha256-KesHgItiZPgGX740axSiQLcIQ8D24MDqNpkKYWIek8k=", + "lastModified": 1784796856, + "narHash": "sha256-wWFrV5/Qbm+lyt5x20E/bSbfJiGKMo4RCxZV8cl/WZI=", "owner": "nixos", "repo": "nixpkgs", - "rev": "753cc8a3a87467296ddd1fa93f0cc3e81120ee46", + "rev": "e2587caef70cea85dd97d7daab492899902dbf5d", "type": "github" }, "original": { @@ -320,11 +320,11 @@ "xwayland-satellite-unstable": { "flake": false, "locked": { - "lastModified": 1783895132, - "narHash": "sha256-Dl0Gvrig3EpE962hzF3ETPhUztlfuRhcmlpd8ioHN54=", + "lastModified": 1784679892, + "narHash": "sha256-Mb7jpqnrcYCfNSItIkkHpuR3YxWFxPuIBfcwNKlRBkk=", "owner": "Supreeeme", "repo": "xwayland-satellite", - "rev": "a2b5c635d8c8c99b286967658d0d177044887eb8", + "rev": "8d135d3b2854b30fd01ea6cd6c27e523dd50a839", "type": "github" }, "original": { diff --git a/lib/options.nix b/lib/options.nix index cef1177..433cc0b 100644 --- a/lib/options.nix +++ b/lib/options.nix @@ -41,7 +41,7 @@ in { [ "PocketID" "authentik" "https://auth.${domain}" "http://localhost:1411/" ] [ "Forgejo" "forgejo" "https://git.${domain}" "http://localhost:5080/" ] [ "Copyparty" "files" "https://cdn.${domain}" "http://localhost:3923/" ] - [ "CryptPad" "cryptpad" "https://docs.${domain}" "http://localhost:7090/" ] + [ "Cockpit" "cockpit" "https://control.proxy.${domain}" "http://localhost:9090/" ] [ "CodeServer" "coder" "https://code.proxy.${domain}" "http://localhost:8443/" ] [ "AdGuardHome" "adguard" "https://dns.proxy.${domain}" "http://localhost:8088/" ] [ "Traefik" "traefikproxy" "https://dynamic.proxy.${domain}/dashboard/" "" ] @@ -56,9 +56,6 @@ in { routes = { "mc.${domain}" = "tcp://localhost:25565"; - "docs-sandbox.${domain}" = "http://localhost:7090"; - "docs.${domain}" = "http://localhost:7090"; - "cdn.${domain}" = selfSigned "https://localhost:3923"; "git.${domain}" = "http://localhost:5080"; @@ -74,6 +71,7 @@ in { "code" = da "http://localhost:8443"; "dns" = da "http://localhost:8088"; + "control" = d "https://localhost:9090"; "gallery" = d "http://localhost:2283"; "dynamic" = d "http://localhost:8082"; "search" = d "http://localhost:8091"; @@ -104,7 +102,7 @@ in { }; rice = { - font = "monospace"; # global font for rice GUIs, leave empty to use monospace + font = "DroidSansM Nerd Font"; # global font for rice GUIs, must be a Nerd Font for icon glyphs to render correctly bar = { top = true; # false will put the bar at the bottom fragmented = true; # enable fragmented bar, false will make it a single block diff --git a/modules/hardware/misc/battery-power.nix b/modules/hardware/misc/battery-power.nix index 8c529e1..80c6ec9 100644 --- a/modules/hardware/misc/battery-power.nix +++ b/modules/hardware/misc/battery-power.nix @@ -13,13 +13,14 @@ cron = { enable = true; systemCronJobs = [ - "* * * * * ${username} bash -x ${pkgs.writeShellScript "low-battery-notifier" '' - BAT_PCT=`${pkgs.acpi}/bin/acpi -b | ${pkgs.gnugrep}/bin/grep -P -o '[0-9]+(?=%)'` - BAT_STA=`${pkgs.acpi}/bin/acpi -b | ${pkgs.gnugrep}/bin/grep -P -o '\w+(?=,)'` + "*/2 * * * * ${username} bash ${pkgs.writeShellScript "low-battery-notifier" '' + ACPI_OUT=$(${pkgs.acpi}/bin/acpi -b) + BAT_PCT=`echo "$ACPI_OUT" | ${pkgs.gnugrep}/bin/grep -P -o '[0-9]+(?=%)'` + BAT_STA=`echo "$ACPI_OUT" | ${pkgs.gnugrep}/bin/grep -P -o '\w+(?=,)'` echo "`date` battery status:$BAT_STA percentage:$BAT_PCT" export DISPLAY=:0 export DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/$(id -u)/bus - test $BAT_PCT -le 30 && test $BAT_PCT -gt 15 && test $BAT_STA = "Discharging" && ${pkgs.libnotify}/bin/notify-send "Low Battery" "Battery remaining: $BAT_PCT%." + test $BAT_PCT -le 30 && test $BAT_PCT -gt 15 && test $BAT_STA = "Discharging" && ${pkgs.libnotify}/bin/notify-send "Low Battery" "Battery remaining: $BAT_PCT%." && brightnessctl s 30% test $BAT_PCT -le 15 && test $BAT_STA = "Discharging" && ${pkgs.libnotify}/bin/notify-send -u critical "Low Battery" "Shutdown at 10%." ''} > /tmp/cron.batt.log 2>&1" ]; diff --git a/modules/hardware/misc/cpu-freq.nix b/modules/hardware/misc/cpu-freq.nix index ad87022..63323a3 100644 --- a/modules/hardware/misc/cpu-freq.nix +++ b/modules/hardware/misc/cpu-freq.nix @@ -49,23 +49,27 @@ }; auto-cpufreq = { enable = true; # wait for fix: https://github.com/AdnanHodzic/auto-cpufreq/issues/906 - settings = { - charger = { - governor = "powersave"; # "performance"; + settings = let + performance = { + governor = "performance"; energy_performance_preference = "performance"; turbo = "always"; platform_profile = "performance"; scaling_min_freq = 800000; scaling_max_freq = 3600000; }; - battery = { + balanced = { governor = "powersave"; energy_performance_preference = "balance-power"; - platform_profile = "low-power"; turbo = "never"; + platform_profile = "balanced"; scaling_min_freq = 400000; scaling_max_freq = 1700000; }; + in { + battery = balanced; + charger = balanced; # performance; + # ^^ disable overclocking for purely productivity use so low temps and fan noise }; }; }; diff --git a/modules/home/core/apps.nix b/modules/home/core/apps.nix index 214a70c..974a602 100644 --- a/modules/home/core/apps.nix +++ b/modules/home/core/apps.nix @@ -28,6 +28,7 @@ home.packages = with pkgs; [ zed-editor opencode + github-copilot-cli slack discord @@ -45,8 +46,9 @@ gpu-screen-recorder gpu-screen-recorder-gtk - (prismlauncher.override { - jdks = with javaPackages.compiler.temurin-bin; [ jre-21 jdk-25 ]; - }) + # LOCK IN + # (prismlauncher.override { + # jdks = with javaPackages.compiler.temurin-bin; [ jre-21 jdk-25 ]; + # }) ]; } diff --git a/modules/home/core/cli.nix b/modules/home/core/cli.nix index 9e9b94e..2dc4b10 100644 --- a/modules/home/core/cli.nix +++ b/modules/home/core/cli.nix @@ -30,6 +30,9 @@ cursor_trail = 10; copy_on_select = true; }; + keybindings = { + "ctrl+backspace" = "send_text all \\x17"; + }; }; ranger = { enable = true; diff --git a/modules/home/core/code.nix b/modules/home/core/code.nix index 044f3a7..6803152 100644 --- a/modules/home/core/code.nix +++ b/modules/home/core/code.nix @@ -40,6 +40,7 @@ }; }; agent = { + sidebar_side = "right"; tool_permissions.default = "allow"; default_model = { provider = "copilot_chat"; diff --git a/modules/home/core/shell.nix b/modules/home/core/shell.nix index a26d6d1..70dab70 100644 --- a/modules/home/core/shell.nix +++ b/modules/home/core/shell.nix @@ -61,6 +61,9 @@ "wm-lock" = "wm-ctl dispatch exec loginctl lock-session && notify-send ${hostname} 'Manual lock triggered'"; "wm-disp" = "wm-ctl dispatch dpms"; + "gz-compress" = "tar -czhf"; + "gz-extract" = "tar -xzf"; + "gh-author-setup" = "git config user.name $(gh api -H \"Accept: application/vnd.github+json\" -H \"X-GitHub-Api-Version: 2022-11-28\" /user | jq -r .login) && git config user.email $(gh api -H \"Accept: application/vnd.github+json\" -H \"X-GitHub-Api-Version: 2022-11-28\" /user/emails | jq -r \".[1].email\")"; "fg-create-repo" = "git remote add origin ${git.server}/${git.username}/$(basename $PWDw).git && git push"; "convert-pdf" = "libreoffice --headless --convert-to pdf"; diff --git a/modules/home/rice/bar.nix b/modules/home/rice/bar.nix index 4360e9c..cc6b175 100644 --- a/modules/home/rice/bar.nix +++ b/modules/home/rice/bar.nix @@ -180,7 +180,7 @@ style = '' * { font-size: 12px; - font-family: Font Awesome, ${rice.font}; + font-family: ${rice.font}; font-weight: bold; color: @text; transition: none; diff --git a/modules/home/rice/compositor.nix b/modules/home/rice/compositor.nix index 10e0813..cca6797 100644 --- a/modules/home/rice/compositor.nix +++ b/modules/home/rice/compositor.nix @@ -25,7 +25,7 @@ XCURSOR_SIZE = "24"; XCURSOR_THEME = "catppuccin-${ctp-opt.flavor}-light-cursors"; - CLIPHIST_MAX_ITEMS = "36"; + CLIPHIST_MAX_ITEMS = "90"; GTK_APPLICATION_PREFER_DARK_THEME = "1"; GTK_THEME = "Adwaita:dark"; @@ -89,7 +89,6 @@ "wl-paste --type image --watch cliphist store" "uwsm app -s s -- waybar &" - "uwsm app -s b -- sunshine &" "uwsm app -s b -- blueman-applet &" "uwsm app -s b -- nm-applet &" "uwsm app -s b -- tailscale systray &" diff --git a/modules/home/rice/keybinds.nix b/modules/home/rice/keybinds.nix index 8e01baa..d63a7d3 100644 --- a/modules/home/rice/keybinds.nix +++ b/modules/home/rice/keybinds.nix @@ -1,7 +1,7 @@ { pkgs, lib, hostname, ... }: { programs.niri.settings.binds = { - "XF86AudioRaiseVolume" = { action.spawn = [ "wpctl" "set-volume" "-l" "1" "@DEFAULT_AUDIO_SINK@" "5%+" ]; allow-when-locked = true; }; - "XF86AudioLowerVolume" = { action.spawn = [ "wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "5%-" ]; allow-when-locked = true; }; + "XF86AudioRaiseVolume" = { action.spawn = [ "wpctl" "set-volume" "-l" "1" "@DEFAULT_AUDIO_SINK@" "2%+" ]; allow-when-locked = true; }; + "XF86AudioLowerVolume" = { action.spawn = [ "wpctl" "set-volume" "@DEFAULT_AUDIO_SINK@" "2%-" ]; allow-when-locked = true; }; "XF86AudioMute" = { action.spawn = [ "wpctl" "set-mute" "@DEFAULT_AUDIO_SINK@" "toggle" ]; allow-when-locked = true; }; "XF86AudioMicMute" = { action.spawn = [ "wpctl" "set-mute" "@DEFAULT_AUDIO_SOURCE@" "toggle" ]; allow-when-locked = true; }; "XF86MonBrightnessUp" = { action.spawn = [ "brightnessctl" "s" "10%+" ]; allow-when-locked = true; }; @@ -10,8 +10,9 @@ "Mod+Q".action.close-window = {}; "Mod+W".action.maximize-column = {}; "Mod+S".action.fullscreen-window = {}; - "Alt+Print".action.screenshot-window = {}; - "Print".action.screenshot-screen = {}; + "Ctrl+Print".action.screenshot-window = {}; + "Alt+Print".action.screenshot-screen = {}; + "Print".action.screenshot = {}; "Mod+Up".action.focus-workspace-up = {}; "Mod+Down".action.focus-workspace-down = {}; @@ -22,15 +23,18 @@ "Mod+Shift+Down".action.move-window-down-or-to-workspace-down = {}; "Mod+Shift+Left".action.move-column-left = {}; "Mod+Shift+Right".action.move-column-right = {}; - "Mod+Ctrl+Left".action.set-column-width = [ "-5%" ]; - "Mod+Ctrl+Right".action.set-column-width = [ "+5%" ]; + "Mod+Ctrl+Left".action.set-window-width = [ "-2%" ]; + "Mod+Ctrl+Right".action.set-window-width = [ "+2%" ]; + "Mod+Ctrl+Down".action.set-window-height = [ "+2%" ]; + "Mod+Ctrl+Up".action.set-window-height = [ "-2%" ]; "Mod+G".action.center-column = {}; "Mod+F".action.toggle-window-floating = {}; "Alt+Space".action.toggle-overview = {}; "Mod+Space" = { action.spawn = [ "playerctl" "play-pause" ]; allow-when-locked = true; }; - "Mod+R".action.spawn = [ "rofi" "-show" "drun" "-show-icons" "-display-drun" "" "-run-command" "uwsm app -- {cmd}" ]; + "Mod+R".action.spawn = [ "rofi" "-show" "drun" "-show-icons" "-display-drun" "" "-run-command" "{cmd}" ]; + "Mod+Shift+R".action.spawn = [ "rofi" "-show" "drun" "-show-icons" "-display-drun" "wayland-0" "-run-command" "sh -c 'WAYLAND_DISPLAY=wayland-0 DISPLAY=:1 exec {cmd}'" ]; "Mod+E".action.spawn = [ "pcmanfm-qt" ]; "Mod+T".action.spawn = [ "kitty" ]; diff --git a/modules/system/base.nix b/modules/system/base.nix index 2cdea36..d62b589 100644 --- a/modules/system/base.nix +++ b/modules/system/base.nix @@ -16,7 +16,14 @@ i18n.defaultLocale = locale; environment.localBinInPath = true; + powerManagement.cpuFreqGovernor = "powersave"; + boot.kernel.sysctl."vm.swappiness" = 10; # only swap when necessary + security = { + polkit = { + enable = true; + enablePkexecWrapper = true; + }; sudo.configFile = '' Defaults insults Defaults passwd_tries = 5 diff --git a/modules/system/core/bootloader.nix b/modules/system/core/bootloader.nix index cca3d3f..20d65ec 100644 --- a/modules/system/core/bootloader.nix +++ b/modules/system/core/bootloader.nix @@ -1,12 +1,11 @@ { pkgs, legacy-boot, ... }: { boot = { - plymouth.enable = true; loader = { efi.canTouchEfiVariables = true; systemd-boot = { enable = !legacy-boot; configurationLimit = 3; - sortKey = "z-nixos"; + sortKey = "nixos"; editor = false; }; grub = { diff --git a/modules/system/desktop.nix b/modules/system/desktop.nix index ec264eb..0aeb936 100644 --- a/modules/system/desktop.nix +++ b/modules/system/desktop.nix @@ -22,7 +22,7 @@ package = pkgs.niri-unstable; }; hyprland = { - enable = true; + enable = false; withUWSM = true; xwayland.enable = true; package = pkgs.hyprland; # if rice.enable then inputs.hl.packages."${pkgs.system}".hyprland else pkgs.hyprland; @@ -33,7 +33,7 @@ xdg.portal = { enable = true; extraPortals = [ - pkgs.xdg-desktop-portal-hyprland #inputs.hl.packages.${pkgs.system}.xdg-desktop-portal-hyprland + pkgs.xdg-desktop-portal-luminous pkgs.xdg-desktop-portal-gtk ]; }; diff --git a/modules/system/homelab/cdn.nix b/modules/system/homelab/cdn.nix index 407863e..28925f5 100644 --- a/modules/system/homelab/cdn.nix +++ b/modules/system/homelab/cdn.nix @@ -1,18 +1,25 @@ { pkgs, ... }: let - version = "v1.20.18"; - executable = pkgs.fetchurl { + python = pkgs.python3.withPackages (ps: with ps; [ pillow argon2-cffi ]); + script = let + version = "v1.20.18"; + in pkgs.fetchurl { url = "https://github.com/9001/copyparty/releases/download/${version}/copyparty-en.py"; hash = "sha256-8SBrKaLPat80n8sONKQYFeFSQXUnCYtwcOU7SR52h7E="; - }; + }; + executable = pkgs.writeShellScriptBin "copyparty" '' + exec ${python}/bin/python3 ${script} "$@" + ''; in { + environment.systemPackages = [ executable ]; systemd.services.copyparty = { description = "File Sharing Service"; enable = true; after = [ "network.target" ]; wantedBy = [ "multi-user.target" ]; + path = [ pkgs.ffmpeg ]; serviceConfig = { # ExecStart = "${pkgs.copyparty-most}/bin/copyparty -c /mnt/share/cfg/files.conf"; - ExecStart = "${pkgs.python3}/bin/python3 ${executable} -c /mnt/share/cfg/files.conf"; + ExecStart = "${python}/bin/python3 ${script} --ah-alg argon2 -c /mnt/share/cfg/files.conf"; Restart = "on-failure"; }; }; diff --git a/modules/system/homelab/control.nix b/modules/system/homelab/control.nix new file mode 100644 index 0000000..9522910 --- /dev/null +++ b/modules/system/homelab/control.nix @@ -0,0 +1,9 @@ +{ homelab, pkgs, ... }: { + services.cockpit = { + enable = true; + allowed-origins = [ "https://control.proxy.${homelab.domain}" ]; + plugins = with pkgs; [ + cockpit-files cockpit-machines + ]; + }; +} \ No newline at end of file diff --git a/modules/system/homelab/dns.nix b/modules/system/homelab/dns.nix index a1ddbb3..ee7e512 100644 --- a/modules/system/homelab/dns.nix +++ b/modules/system/homelab/dns.nix @@ -21,6 +21,13 @@ whitelist = [ "https://gist.githubusercontent.com/mul14/eb05e88fcec5bb195cbb/raw/75a1fe122a4502e8d5a5268c9d0ec28332b19d5d/hosts" ]; + blocked = [ + # LOCK IN + "instagram" + "youtube" + "minecraft" + "steam" + ]; in { services.adguardhome = { enable = true; @@ -37,6 +44,7 @@ in { enabled = true; }; filtering = { + blocked_services.ids = blocked; blocking_mode = "null_ip"; protection_enabled = true; safebrowsing_enabled = true; diff --git a/modules/system/homelab/docs.nix b/modules/system/homelab/docs.nix deleted file mode 100644 index 58d6738..0000000 --- a/modules/system/homelab/docs.nix +++ /dev/null @@ -1,46 +0,0 @@ -{ lib, pkgs, homelab, ... }: let - domain = "docs.${homelab.domain}"; - sandbox = "docs-sandbox.${homelab.domain}"; -in { - services.cryptpad = { - enable = true; - settings = { - websocketPort = 7091; - httpPort = 7090; - httpAddress = "127.0.0.1"; - httpUnsafeOrigin = "https://${domain}"; - httpSafeOrigin = "https://${sandbox}"; - blockDailyCheck = true; - disableIntegratedEviction = true; - adminKeys = [ - "[satr14@docs.satr14.my.id/f1A82fmBuqQka2bNqrCb1WbB9r2ex5A3rdys5xLX3Hc=]" - ]; - }; - }; - - systemd.tmpfiles.rules = lib.singleton "L+ /var/lib/cryptpad/customize/application_config.js - - - - ${pkgs.writeText "cryptpad-application-config.js" '' - (() => { - const factory = (AppConfig) => { - AppConfig.disableAnonymousPadCreation = true; - AppConfig.disableAnonymousStore = true; - AppConfig.defaultDarkTheme = true; - return AppConfig; - }; - - if (typeof(module) !== 'undefined' && module.exports) { - module.exports = factory( - require('../www/common/application_config_internal.js') - ); - } else if ((typeof(define) !== 'undefined' && define !== null) && (define.amd !== null)) { - define(['/common/application_config_internal.js'], factory); - } - })(); - ''}"; - - fileSystems."/var/lib/private/cryptpad" = { - device = "/mnt/data/apps/cryptpad"; - depends = [ "/mnt/data" ]; - options = [ "bind" "nofail" ]; - fsType = "none"; - }; -} diff --git a/modules/system/homelab/gallery.nix b/modules/system/homelab/gallery.nix index 1b52208..74d2ea2 100644 --- a/modules/system/homelab/gallery.nix +++ b/modules/system/homelab/gallery.nix @@ -1,4 +1,10 @@ -{ lib, ... }: { +{ pkgs, lib, ... }: { + # fix every update causing error: + # > microservices worker error: PostgresError: must be owner of function album_user_after_insert, stack: PostgresError: must be owner of function album_user_after_insert + systemd.services.postgresql.postStart = pkgs.lib.mkAfter '' + $PSQL -d immich -c "ALTER FUNCTION album_user_after_insert() OWNER TO immich;" || true + ''; + users.users.immich.extraGroups = [ "video" "render" ]; services = { diff --git a/modules/system/homelab/mc/default.nix b/modules/system/homelab/mc/default.nix index ae55545..a452cfd 100644 --- a/modules/system/homelab/mc/default.nix +++ b/modules/system/homelab/mc/default.nix @@ -5,12 +5,10 @@ inputs.mc.nixosModules.minecraft-servers ]; nixpkgs.overlays = [ inputs.mc.overlay ]; - - powerManagement.cpuFreqGovernor = "powersave"; # performance governor causes overheating and thermal throttling, works fine with powesave - boot.kernel.sysctl."vm.swappiness" = 10; # reduce swap usage and keep memory performance smooth services.minecraft-servers = { - enable = true; + # LOCK IN + enable = false; eula = true; managementSystem.systemd-socket.enable = true; # ^^^ https://github.com/Infinidoge/nix-minecraft/issues/119 diff --git a/modules/system/homelab/mc/mc0-vanilla-plus.nix b/modules/system/homelab/mc/mc0-vanilla-plus.nix index 79f86bc..5240835 100644 --- a/modules/system/homelab/mc/mc0-vanilla-plus.nix +++ b/modules/system/homelab/mc/mc0-vanilla-plus.nix @@ -3,6 +3,11 @@ ram-allocation-mb = 8192; headroom-allocation-mb = 1024; rcon-pass = "howdy"; + ports = { + minecraft = 25565; + rcon = 25575; + }; + modpack = let useLatest = false; commit = "86bf13316ed1352a676d9056d284448ea5e5a079"; @@ -18,13 +23,13 @@ in { }; services.minecraft-servers.servers.${name} = { - enable = true; + enable = false; autoStart = true; restart = "always"; serverProperties = { server-ip = "0.0.0.0"; - server-port = 25565; + server-port = ports.minecraft; server-name = name; motd = "§cCan't connect to server"; log-ips = false; @@ -49,7 +54,7 @@ in { enable-rcon = true; sync-chunk-writes = false; "rcon.password" = rcon-pass; - "rcon.port" = 25575; + "rcon.port" = ports.rcon; }; symlinks = inputs.mc.lib.collectFilesAt modpack "mods" // { diff --git a/modules/system/homelab/mc/mc1-pure-vanilla.nix b/modules/system/homelab/mc/mc1-pure-vanilla.nix index 6b64a85..9268e35 100644 --- a/modules/system/homelab/mc/mc1-pure-vanilla.nix +++ b/modules/system/homelab/mc/mc1-pure-vanilla.nix @@ -3,6 +3,10 @@ ram-allocation-mb = 8192; headroom-allocation-mb = 1024; rcon-pass = "howdy"; + ports = { + minecraft = 25566; + rcon = 25576; + }; modpack = pkgs.fetchModrinthModpack { url = "https://cdn.modrinth.com/data/2wkV8mHp/versions/mFGJP1Ye/Server%20Optimization%201.21.11-2.1.mrpack"; @@ -17,7 +21,7 @@ in { serverProperties = { server-ip = "0.0.0.0"; - server-port = 25566; + server-port = ports.minecraft; server-name = name; motd = "§cCan't connect to server"; log-ips = false; @@ -42,7 +46,7 @@ in { enable-rcon = true; sync-chunk-writes = false; "rcon.password" = rcon-pass; - "rcon.port" = 25576; + "rcon.port" = ports.rcon; }; files = inputs.mc.lib.collectFilesAt modpack "config"; diff --git a/modules/system/homelab/mc/mc2-create-aeronautics.nix b/modules/system/homelab/mc/mc2-create-aeronautics.nix new file mode 100644 index 0000000..03f96f8 --- /dev/null +++ b/modules/system/homelab/mc/mc2-create-aeronautics.nix @@ -0,0 +1,120 @@ +{ inputs, lib, pkgs, ... }: let + name = "mc2-create-aeronautics"; + ram-allocation-mb = 12288; + headroom-allocation-mb = 2048; + rcon-pass = "howdy"; + ports = { + minecraft = 25567; + rcon = 25577; + }; + + modpack = let + useLatest = true; + commit = ""; + path = if !useLatest then "commit/${commit}" else "branch/main"; + in pkgs.fetchPackwizModpack { + packHash = ""; + url = "https://git.satr14.my.id/satr14/create-modpack/raw/${path}/pack.toml"; + }; +in { + systemd.services."minecraft-server-${name}" = { + environment.LD_LIBRARY_PATH = "${pkgs.stdenv.cc.cc.lib}/lib"; # physics toys mod fix + # serviceConfig.Nice = -5; # higher scheduling priority (causes fan noise even when idle) + }; + + services.minecraft-servers.servers.${name} = { + enable = false; + autoStart = true; + restart = "always"; + + serverProperties = { + server-ip = "0.0.0.0"; + server-port = ports.minecraft; + server-name = name; + motd = "§cCan't connect to server"; + log-ips = false; + hide-online-players = true; + + difficulty = "normal"; + gamemode = "survival"; + max-world-size = 25000; + spawn-protection = 0; + pvp = true; + + online-mode = true; + enable-query = true; + enforce-secure-profile = false; + pevent-proxy-connections = false; + allow-flight = false; + player-idle-timeout = 0; + + view-distance = 12; + simulation-distance = 6; + + enable-rcon = true; + sync-chunk-writes = false; + "rcon.password" = rcon-pass; + "rcon.port" = ports.rcon; + }; + + symlinks = inputs.mc.lib.collectFilesAt modpack "mods" // { + "polymer/packsquash" = let packsquash-binary = pkgs.runCommand "packsquash" { + src = pkgs.fetchurl { + url = "https://github.com/ComunidadAylas/PackSquash/releases/download/v0.4.1/packsquash-x86_64-unknown-linux-gnu.zip"; + sha256 = "sha256-VsGZewoiO5MjhIhwjlLO5d5uHynlAK5Jh16jH2k2rPs="; + }; + nativeBuildInputs = [ pkgs.unzip ]; + } '' + mkdir -p $out/bin + unzip $src -d $out/bin + chmod +x $out/bin/packsquash + ''; in "${packsquash-binary}/bin/packsquash"; + }; + + files = inputs.mc.lib.collectFilesAt modpack "config" // { + "config/proxy_protocol_support.json".value = { + enableProxyProtocol = false; # polymer auto host has issues with proxy protocol + whitelistTCPShieldServers = false; + proxyServerIPs = [ "127.0.0.1" "::1" ]; + directAccessIPs = [ "127.0.0.0/8" "::1/128" ]; + }; + }; + + extraStartPre = let sed-commands = lib.concatStringsSep "\n" ( + lib.mapAttrsToList (substitution: file: + ''sed -i "s|${substitution}|''${${substitution}}|g" ${file}'' + ) { + "REPLACE_SVC_HOST" = "config/voicechat/voicechat-server.properties"; + "REPLACE_RP_LINK" = "config/welcomemessage.json5"; + "REPLACE_DC_BOT_TOKEN" = "config/simple-discord-link/simple-discord-link.toml"; + "REPLACE_DC_OWNER_ROLE" = "config/simple-discord-link/simple-discord-link.toml"; + } + ); in '' + # shellcheck disable=SC1091 + if [ -f modpack-config.env ]; then + source modpack-config.env + ${sed-commands} + fi + ''; + + package = pkgs.fabricServers.fabric-1_21_11.override { + jre_headless = pkgs.javaPackages.compiler.temurin-bin.jdk-25; + loaderVersion = "0.19.2"; + }; + + jvmOpts = let flags = [ + "-Xms${toString ram-allocation-mb}M" + "-Xmx${toString ram-allocation-mb}M" + + "-XX:+UseZGC" # Use ZGC (requires Java v25+, 8+ CPU cores, 10GB+ RAM) + "-XX:+ZGenerational" # Use generational ZGC (newer and better ZGC, requires Java v21+) + "-XX:+UseCompactObjectHeaders" # Use compact object headers (requires Java v16+, saves a couple of bits per object) + + "--add-modules=jdk.incubator.vector" # Exposes SIMD instructions (requires full JDK, useful with performance mods like C2ME) + "-XX:+AlwaysPreTouch" # Pre-allocates memory on startup, OS claims it immediately for JVM instead of negotiating it + "-XX:+DisableExplicitGC" # Disables mods from manually invoking the GC + "-XX:+PerfDisableSharedMem" # Disables constant /tmp writes for JVM metrics + "-XX:SoftMaxHeapSize=${toString (ram-allocation-mb - headroom-allocation-mb)}M" # Leave 2GB headroom + ]; in lib.concatStringsSep " " flags; + }; +} \ No newline at end of file diff --git a/modules/system/homelab/proxy.nix b/modules/system/homelab/proxy.nix index d977892..5a03057 100644 --- a/modules/system/homelab/proxy.nix +++ b/modules/system/homelab/proxy.nix @@ -8,6 +8,7 @@ proxy_cache off; send_timeout 600s; client_max_body_size 50000M; + proxy_ssl_session_reuse off; ''; in { users.users = { diff --git a/modules/system/misc/programs.nix b/modules/system/misc/programs.nix index 778858b..acc3a7e 100644 --- a/modules/system/misc/programs.nix +++ b/modules/system/misc/programs.nix @@ -16,7 +16,8 @@ }; programs = { - steam.enable = true; + # LOCK IN + # steam.enable = true; gdk-pixbuf.modulePackages = [ pkgs.librsvg ]; appimage = { enable = true; diff --git a/modules/system/server.nix b/modules/system/server.nix index 9db8dfa..7213cdc 100644 --- a/modules/system/server.nix +++ b/modules/system/server.nix @@ -11,6 +11,7 @@ in { ./homelab/containers.nix ./homelab/gallery.nix ./homelab/tunnels.nix + ./homelab/control.nix ./homelab/notify.nix ./homelab/search.nix ./homelab/media.nix @@ -19,7 +20,6 @@ in { ./homelab/pass.nix ./homelab/dash.nix ./homelab/code.nix - ./homelab/docs.nix ./homelab/dns.nix ./homelab/git.nix ./homelab/cdn.nix