Compare commits

..
14 Commits
9 changed files with 118 additions and 81 deletions
Generated
+37 -37
View File
@@ -125,11 +125,11 @@
}, },
"locked": { "locked": {
"dir": "pkgs/firefox-addons", "dir": "pkgs/firefox-addons",
"lastModified": 1786420971, "lastModified": 1788840136,
"narHash": "sha256-irKN0AY5fDS96h7z3Cjp3EB7OwTJU1SeWFb1GxnFu3E=", "narHash": "sha256-ej5jnQIfjbw4wwPzy8Y4ntG9F3asdF6YBkLqpYeGUxc=",
"owner": "rycee", "owner": "rycee",
"repo": "nur-expressions", "repo": "nur-expressions",
"rev": "a56dfe072a448e664d208e9ed5f7f9dc9a720686", "rev": "555b23e68256c5abfb8a85a385231830d1d7ad1f",
"type": "gitlab" "type": "gitlab"
}, },
"original": { "original": {
@@ -174,11 +174,11 @@
"nixpkgs-lib": "nixpkgs-lib" "nixpkgs-lib": "nixpkgs-lib"
}, },
"locked": { "locked": {
"lastModified": 1785627969, "lastModified": 1788450739,
"narHash": "sha256-4dtXQk/NMePegK/nWp5NSeuZKLATItOq61lpEvmXqGw=", "narHash": "sha256-glZLQlzIn1fXH6PazR2iUmTo7kzzyYSshrWhLS9TqCU=",
"owner": "hercules-ci", "owner": "hercules-ci",
"repo": "flake-parts", "repo": "flake-parts",
"rev": "427bf4bd9435fdf21321c8cc628c24efc14c0f7a", "rev": "31729ca8cbdb4fa927b34e5f4353e6a83f39e993",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -311,11 +311,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1785119570, "lastModified": 1788642154,
"narHash": "sha256-Rgs2xKnGLFWQscxUaXX07oyZeuMDOHEbqDOsgliLFGM=", "narHash": "sha256-sPpQFVaFTDqO/4vvCAhuAhqTgqN/ygu+9eJcs5eB0js=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "d4fd24667c8cbef124bb70a20380cab75ec8474d", "rev": "fd0956c99c41ae3c13a73a638f1f7e963aebc4ab",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -327,11 +327,11 @@
}, },
"import-tree": { "import-tree": {
"locked": { "locked": {
"lastModified": 1784254960, "lastModified": 1788467110,
"narHash": "sha256-iI88R3wHz8wTKQb5orvpc51L/Xr64AJyxid/0MKa/b8=", "narHash": "sha256-ljEMTXP/rH0tOvDzc9gzwww6KcHRPRnEHzd9lK48V7s=",
"owner": "vic", "owner": "vic",
"repo": "import-tree", "repo": "import-tree",
"rev": "4ebb10ae17d5f1ad366e7aef5b92cb8eecf24f69", "rev": "eb1b52eaecc57f7c136d07ae8a93e724dfecac46",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -349,11 +349,11 @@
"systems": "systems" "systems": "systems"
}, },
"locked": { "locked": {
"lastModified": 1786414302, "lastModified": 1788840747,
"narHash": "sha256-FNGnUYud1D3BqE1JU2Uef+puLB2Rml7gKSdIGQOb550=", "narHash": "sha256-nZ6Yt+8u5NhPSP46VcYXEcu4cJpeOiR/K+lfyk3COVA=",
"owner": "Infinidoge", "owner": "Infinidoge",
"repo": "nix-minecraft", "repo": "nix-minecraft",
"rev": "cacc8cd89550f0cbec7103f3db5e96d1a66c58e7", "rev": "1e6052f5ecebddbbb2d372e0fe6f1b7bc4b95a9e",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -383,11 +383,11 @@
"nixpkgs": "nixpkgs" "nixpkgs": "nixpkgs"
}, },
"locked": { "locked": {
"lastModified": 1786437054, "lastModified": 1788860136,
"narHash": "sha256-I++HzBBAgQ17UaLVU6aSm1/7LDo6c9xr8rAbpByWywE=", "narHash": "sha256-MhPMOFV4pVkygWEbQ8t1De/uQ9cWF1u++tRe2L5tG48=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixos-hardware", "repo": "nixos-hardware",
"rev": "6ed13b1d888d5cb07dbb0723eb1df86bbacd0b9c", "rev": "62173785b9a18c78b4a15aca2623d02bceb9d077",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -412,11 +412,11 @@
}, },
"nixpkgs-lib": { "nixpkgs-lib": {
"locked": { "locked": {
"lastModified": 1785031560, "lastModified": 1788057806,
"narHash": "sha256-OmshNvn2vupOFpYinLUu+1Dnpu4n7Q5N3ggGVNHpkUI=", "narHash": "sha256-DTQSMxzDWmT0zhguthvegnVkn7CFqGCv4IHCzk5ZUpM=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nixpkgs.lib", "repo": "nixpkgs.lib",
"rev": "0e79af5e3d4dcfcd676ab5ba3f95d2e3352e078c", "rev": "596e2e3940e09b2abbeb03f75fa1828c57fcd72c",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -442,11 +442,11 @@
}, },
"nixpkgs-unstable": { "nixpkgs-unstable": {
"locked": { "locked": {
"lastModified": 1786247143, "lastModified": 1788752844,
"narHash": "sha256-8S3Kcxs7D4UtxJxSJZz0m14CGhuW0MxfrIwJxeGWGnQ=", "narHash": "sha256-VaWGJ6+cIYN2erfSecbRV+4ljI185Ty2wUrXyvQbgOw=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "279b4a8275f032c566576b3f181fa0f27197f588", "rev": "dc5d91f840324650bac8c379428c7037a416959a",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -458,11 +458,11 @@
}, },
"nixpkgs_2": { "nixpkgs_2": {
"locked": { "locked": {
"lastModified": 1786313170, "lastModified": 1788807765,
"narHash": "sha256-9BG7OgUWdu0ONDO5X2q6+K4bsuBITkX/3W4nNJu1Ito=", "narHash": "sha256-J9oC0bKnkXUrMegqRTXVkyDFJ0gn2U/Qpoo9HgGMQmA=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "fcb8fcd6bf2d0adecae5bd491afaaaf8311b758d", "rev": "93108a538f079596c9a16c72cf03e9322782b6dd",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -561,11 +561,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1786375908, "lastModified": 1788337237,
"narHash": "sha256-G7qDAT98nywA4EFmJCwIRO5wKvDlBBN3BWpsOnjAto8=", "narHash": "sha256-gkSH8VUtCo6hnysNmb9DbTuDepH2t5pv+QWjP75xKAk=",
"owner": "Mic92", "owner": "Mic92",
"repo": "sops-nix", "repo": "sops-nix",
"rev": "d1337e05ba0a8e88a75d2c0e1595d82f3b3e2ac4", "rev": "fbf759290e0cb0a98dfc813a4eb7d53ad1dacb57",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -582,11 +582,11 @@
"systems": "systems_2" "systems": "systems_2"
}, },
"locked": { "locked": {
"lastModified": 1786252193, "lastModified": 1788683578,
"narHash": "sha256-a9SbkJWloPso00G4zIUkerd9n2qRyDYoDPeUc4O3ME8=", "narHash": "sha256-bERpuakmPAC2b36zgXy6OXh+SkZUjbaV+vV2sPmm6p8=",
"owner": "Gerg-L", "owner": "Gerg-L",
"repo": "spicetify-nix", "repo": "spicetify-nix",
"rev": "a87616995724d27079b495ca07318512af799449", "rev": "a4ef43fb13e3615f36e5a0935aabe8cc29363dc9",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -635,11 +635,11 @@
"rust-overlay": "rust-overlay" "rust-overlay": "rust-overlay"
}, },
"locked": { "locked": {
"lastModified": 1787486435, "lastModified": 1788884686,
"narHash": "sha256-eGq8eI1lYFwID8NSrQLbouNIDXZbvLAbqbZ9vvBUMa4=", "narHash": "sha256-wl0NGoryP5veIaRn6azmejz1JsTbwHlBU/MT/icTKQ4=",
"ref": "refs/heads/main", "ref": "refs/heads/main",
"rev": "46e977acf5344bbf7b901df9e1b1aa69297ae8c7", "rev": "a827bd5eef0354f7e4fdca57383971ff6008b5d3",
"revCount": 37, "revCount": 42,
"type": "git", "type": "git",
"url": "https://git.jroeger.de/jonas/wordle-solver-rs" "url": "https://git.jroeger.de/jonas/wordle-solver-rs"
}, },
-5
View File
@@ -37,10 +37,6 @@
sopsFile = ../../secrets/harbor/hidden-matrix.yaml; sopsFile = ../../secrets/harbor/hidden-matrix.yaml;
key = "hostname"; key = "hostname";
}; };
sops.secrets.hidden-matrix-registration-secret = {
sopsFile = ../../secrets/harbor/hidden-matrix.yaml;
key = "registration_secret";
};
# gc settings and binary caches # gc settings and binary caches
nix = { nix = {
@@ -97,7 +93,6 @@
hive.matrix.enable = true; hive.matrix.enable = true;
hive.matrix.hiddenServiceSecret = config.sops.secrets.matrix-hs-secret.path; hive.matrix.hiddenServiceSecret = config.sops.secrets.matrix-hs-secret.path;
hive.matrix.hiddenServiceHostnameSopsKey = config.sops.secrets.hidden-matrix-hostname.name; hive.matrix.hiddenServiceHostnameSopsKey = config.sops.secrets.hidden-matrix-hostname.name;
hive.matrix.registrationSecretSopsKey = config.sops.secrets.hidden-matrix-registration-secret.name;
hive.calibre.enable = true; hive.calibre.enable = true;
hive.calibre.instanceFQDN = "calibre.jroeger.de"; hive.calibre.instanceFQDN = "calibre.jroeger.de";
hive.calibre.libraries = ["Rote Bücher" "Bürgerliche Bücher" "Brain Maxxing" "Technik" "Wissenschaft oder so" "Dokumente"]; hive.calibre.libraries = ["Rote Bücher" "Bürgerliche Bücher" "Brain Maxxing" "Technik" "Wissenschaft oder so" "Dokumente"];
+1 -1
View File
@@ -174,7 +174,7 @@
boot.plymouth.enable = true; boot.plymouth.enable = true;
boot.initrd.systemd.enable = true; boot.initrd.systemd.enable = true;
boot.supportedFilesystems = ["ntfs"]; boot.supportedFilesystems = ["ntfs"];
boot.kernelPackages = pkgs.linuxPackages_latest; boot.kernelPackages = pkgs.linuxPackages_7_1;
# Configure console keymap # Configure console keymap
console.keyMap = "de"; console.keyMap = "de";
+4 -7
View File
@@ -269,13 +269,10 @@
)) ))
(after! jj-mode (use-package! majutsu
(map! :leader :config (map! :leader
(:prefix ("j" . "Jujutsu") (:prefix ("j" . "majutsu")
:desc "Log" "j" #'jj-log :desc "Log" "j" #'majutsu-log
:desc "Describe" "d" #'jj-describe
:desc "Abandon" "a" #'jj-abandon
:desc "New" "n" #'jj-new
))) )))
+1 -1
View File
@@ -94,7 +94,7 @@
(package! tramp) (package! tramp)
(package! graphviz-dot-mode) (package! graphviz-dot-mode)
(package! rainbow-delimiters) (package! rainbow-delimiters)
(package! jj-mode :recipe (:host github :repo "bolivier/jj-mode.el")) (package! majutsu :recipe (:host github :repo "0WD0/majutsu"))
(let ((package-dir (expand-file-name "packages.d" doom-user-dir))) (let ((package-dir (expand-file-name "packages.d" doom-user-dir)))
(when (file-directory-p package-dir) (when (file-directory-p package-dir)
+25 -8
View File
@@ -2,6 +2,7 @@
flake.nixosModules.gitea-instance = { flake.nixosModules.gitea-instance = {
config, config,
lib, lib,
pkgs,
... ...
}: let }: let
cfg = config.hive.gitea-instance; cfg = config.hive.gitea-instance;
@@ -61,6 +62,14 @@
enableACME = true; enableACME = true;
locations."/" = { locations."/" = {
proxyPass = "http://unix:/run/gitea/gitea.sock"; proxyPass = "http://unix:/run/gitea/gitea.sock";
extraConfig = ''
client_max_body_size 1G;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
'';
}; };
}; };
@@ -77,13 +86,25 @@
}; };
# act_runner # act_runner
services.gitea-actions-runner = lib.mkIf cfg.nativeRunner { services.gitea-actions-runner.instances.nixoshost = {
instances.nixos-host = { enable = cfg.nativeRunner;
enable = true;
name = "nixos-host-runner"; name = "nixos-host-runner";
url = "https://${cfg.instanceFQDN}"; url = "https://${cfg.instanceFQDN}";
tokenFile = "/var/lib/gitea-registration/nixos-host"; tokenFile = "/var/lib/gitea-registration/nixos-host";
hostPackages = with pkgs; [
bash
coreutils
curl
gawk
gitMinimal
gnused
nix
nodejs
skopeo
wget
];
labels = ["nixos:host"]; labels = ["nixos:host"];
settings = { settings = {
@@ -92,13 +113,9 @@
}; };
}; };
}; };
}; systemd.services.gitea-runner-nixoshost = lib.mkIf cfg.nativeRunner {
systemd.services.gitea-runner-nixos-host = lib.mkIf cfg.nativeRunner {
after = ["gitea-runner-gen-token.service"]; after = ["gitea-runner-gen-token.service"];
requires = ["gitea-runner-gen-token.service"]; requires = ["gitea-runner-gen-token.service"];
serviceConfig.Environment = ''
PATH=/run/current-system/sw/bin:/usr/bin:/bin
'';
}; };
systemd.services.gitea-runner-gen-token = lib.mkIf cfg.nativeRunner { systemd.services.gitea-runner-gen-token = lib.mkIf cfg.nativeRunner {
wantedBy = ["multi-user.target"]; wantedBy = ["multi-user.target"];
+5 -1
View File
@@ -28,7 +28,11 @@ rustPlatform.buildRustPackage (finalAttrs: {
pkg-config pkg-config
]; ];
#cargoHash = "sha256-3oMPREUWwKNEeaf8FdWHdjPMLU5xMSMzxKrmrhU+iko="; checkFlags = [
"--skip"
"cli_should_start_server"
];
cargoLock.lockFile = "${finalAttrs.src}/Cargo.lock"; cargoLock.lockFile = "${finalAttrs.src}/Cargo.lock";
SSL_CERT_FILE = "${cacert}/etc/ssl/certs/ca-bundle.crt"; SSL_CERT_FILE = "${cacert}/etc/ssl/certs/ca-bundle.crt";
+31 -11
View File
@@ -2,10 +2,13 @@
flake.nixosModules.matrix = { flake.nixosModules.matrix = {
config, config,
lib, lib,
pkgs,
... ...
}: let }: let
cfg = config.hive.matrix; cfg = config.hive.matrix;
ketesa-web-root = fetchTarball {
url = "https://github.com/etkecc/ketesa/releases/download/v1.4.0/ketesa.tar.gz";
sha256 = "sha256:0za0rddcbxn2ra4xlykn7v8b4j0ddyacivyzp91m80r071ds1dk7";
};
in { in {
options.hive.matrix = { options.hive.matrix = {
enable = lib.mkEnableOption "Enable matrix server (synapse)"; enable = lib.mkEnableOption "Enable matrix server (synapse)";
@@ -16,24 +19,21 @@
description = "The internal port of the synapse server"; description = "The internal port of the synapse server";
}; };
registrationSecretSopsKey = lib.mkOption { ketesaLocalPort = lib.mkOption {
type = lib.types.str; type = lib.types.int;
description = "The sops key of the secret containing the registration secret"; default = 8475;
description = "The internal port of the ketesa virtual host";
}; };
hiddenServiceHostnameSopsKey = lib.mkOption { hiddenServiceHostnameSopsKey = lib.mkOption {
type = lib.types.str; type = lib.types.str;
description = "The sops key of the secret containing the hostname of the hidden service"; description = "The sops key of the secret containing the hostname of the hidden service";
}; };
hiddenServiceSecret = lib.mkOption { hiddenServiceSecret = lib.mkOption {
type = lib.types.path; type = lib.types.path;
description = "The file containing the hidden service's secret"; description = "The file containing the hidden service's secret";
}; };
instanceFQDN = lib.mkOption {
type = lib.types.str;
example = "nextcloud.example.com";
description = "Fully qualified domain name of the Nextcloud instance";
};
}; };
config = lib.mkIf cfg.enable { config = lib.mkIf cfg.enable {
@@ -57,16 +57,35 @@
port = cfg.localPort; port = cfg.localPort;
}; };
} }
{
port = 8080;
target = {
addr = "127.0.0.1";
port = cfg.ketesaLocalPort;
};
}
]; ];
}; };
}; };
# Virtual host for ketesa
services.nginx.virtualHosts."ketesa-localhost" = {
listen = [
{
addr = "127.0.0.1";
port = cfg.ketesaLocalPort;
}
];
forceSSL = false;
enableACME = false;
root = "${ketesa-web-root}";
};
# Secret hostname for matrix-synapse # Secret hostname for matrix-synapse
sops.templates."hidden-matrix-synapse".owner = "matrix-synapse"; sops.templates."hidden-matrix-synapse".owner = "matrix-synapse";
sops.templates."hidden-matrix-synapse".content = '' sops.templates."hidden-matrix-synapse".content = ''
server_name: "${config.sops.placeholder.${cfg.hiddenServiceHostnameSopsKey}}" server_name: "${config.sops.placeholder.${cfg.hiddenServiceHostnameSopsKey}}"
public_baseurl: "http://${config.sops.placeholder.${cfg.hiddenServiceHostnameSopsKey}}" public_baseurl: "http://${config.sops.placeholder.${cfg.hiddenServiceHostnameSopsKey}}"
registration_shared_secret: "${config.sops.placeholder.${cfg.registrationSecretSopsKey}}"
''; '';
# Synapse # Synapse
@@ -90,11 +109,12 @@
} }
]; ];
settings = { settings = {
enable_registration = false; enable_registration = true;
registration_requires_token = true; registration_requires_token = true;
report_stats = false; report_stats = false;
federation_domain_whitelist = []; federation_domain_whitelist = [];
federation_ip_range_blacklist = ["0.0.0.0/0"]; federation_ip_range_blacklist = ["0.0.0.0/0"];
matrix_static_files_file_matrix_support_enabled = true;
}; };
extraConfigFiles = [ extraConfigFiles = [
@@ -10,6 +10,8 @@ declare -rA presets=(
[storage-av1]="-c:v libsvtav1 -preset 6 -crf 28 -g 240 -svtav1-params tune=0:aq-mode=2 -c:a copy" [storage-av1]="-c:v libsvtav1 -preset 6 -crf 28 -g 240 -svtav1-params tune=0:aq-mode=2 -c:a copy"
[storage-av1-1080p]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libsvtav1 -preset 6 -crf 28 -g 240 -svtav1-params tune=0:aq-mode=2 -c:a copy" [storage-av1-1080p]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libsvtav1 -preset 6 -crf 28 -g 240 -svtav1-params tune=0:aq-mode=2 -c:a copy"
[storage-av1-nvenc]="-c:v av1_nvenc -cq 28 -preset slow -c:a copy" [storage-av1-nvenc]="-c:v av1_nvenc -cq 28 -preset slow -c:a copy"
[network-hevc]="-c:v libx265 -preset slower -crf 22 -x265-params aq-mode=3:aq-strength=1.0:psy-rd=1.8:psy-rdoq=1.0 -pix_fmt yuv420p -c:a aac -b:a 128k"
[network-hevc-faster]="-c:v libx265 -preset slow -crf 26 -x265-params aq-mode=3:aq-strength=1.0:psy-rd=1.8:psy-rdoq=1.0 -pix_fmt yuv420p -c:a aac -b:a 128k"
[network]="-c:v libx264 -preset slow -crf 22 -pix_fmt yuv420p -c:a aac -b:a 128k" [network]="-c:v libx264 -preset slow -crf 22 -pix_fmt yuv420p -c:a aac -b:a 128k"
[network-1080p]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libx264 -preset slow -crf 22 -pix_fmt yuv420p -c:a aac -b:a 128k" [network-1080p]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libx264 -preset slow -crf 22 -pix_fmt yuv420p -c:a aac -b:a 128k"
[whatsapp]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libx264 -preset slow -crf 30 -profile:v baseline -level 3.0 -pix_fmt yuv420p -r 25 -g 50 -c:a aac -b:a 160k -r:a 44100" [whatsapp]="-vf scale='if(gte(iw/ih,1),1920,-1)':'if(gte(iw/ih,1),-1,1920)' -c:v libx264 -preset slow -crf 30 -profile:v baseline -level 3.0 -pix_fmt yuv420p -r 25 -g 50 -c:a aac -b:a 160k -r:a 44100"
@@ -20,11 +22,13 @@ declare -rA containers=(
[instagram]="mp4" [instagram]="mp4"
[insta-4k]="mp4" [insta-4k]="mp4"
[network-hevc]="mp4" [network-hevc]="mp4"
[storage-hevc-faster]="mkv" [storage-hevc-faster]="mp4"
[storage-hevc]="mkv" [storage-hevc]="mp4"
[storage-av1]="mkv" [storage-av1]="mkv"
[storage-av1-1080p]="mkv" [storage-av1-1080p]="mkv"
[storage-av1-nvenc]="mkv" [storage-av1-nvenc]="mkv"
[network-hevc]="mp4"
[network-hevc-faster]="mp4"
[network]="mp4" [network]="mp4"
[network-1080p]="mp4" [network-1080p]="mp4"
[whatsapp]="mp4" [whatsapp]="mp4"