diff --git a/nixos/flake.nix b/nixos/flake.nix new file mode 100644 index 0000000..437d19b --- /dev/null +++ b/nixos/flake.nix @@ -0,0 +1,16 @@ +{ + description = "Homelab NixOS hosts"; + + inputs = { + nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11"; + }; + + outputs = { nixpkgs, ... }: { + nixosConfigurations.cloud-pc = nixpkgs.lib.nixosSystem { + system = "x86_64-linux"; + modules = [ + ./hosts/cloud-pc.nix + ]; + }; + }; +} diff --git a/nixos/hosts/cloud-pc.nix b/nixos/hosts/cloud-pc.nix new file mode 100644 index 0000000..3710bce --- /dev/null +++ b/nixos/hosts/cloud-pc.nix @@ -0,0 +1,35 @@ +{ pkgs, ... }: + +{ + imports = [ + ../modules/base.nix + ../modules/docker.nix + ../modules/firewall.nix + ./hardware-configuration.nix + ]; + + networking.hostName = "cloud-pc"; + + boot.loader.systemd-boot.enable = true; + boot.loader.efi.canTouchEfiVariables = true; + + virtualisation.libvirtd = { + enable = true; + qemu = { + package = pkgs.qemu_kvm; + ovmf.enable = true; + ovmf.packages = [ + pkgs.OVMFFull.fd + ]; + }; + }; + + services.zerotierone = { + enable = true; + joinNetworks = [ + "743993800fa5a34c" + ]; + }; + + system.stateVersion = "26.05"; +} diff --git a/nixos/modules/base.nix b/nixos/modules/base.nix new file mode 100644 index 0000000..2f85918 --- /dev/null +++ b/nixos/modules/base.nix @@ -0,0 +1,72 @@ +{ pkgs, ... }: + +{ + nix.settings.experimental-features = [ + "nix-command" + "flakes" + ]; + + time.timeZone = "Europe/Moscow"; + + i18n.defaultLocale = "ru_RU.UTF-8"; + i18n.supportedLocales = [ + "ru_RU.UTF-8/UTF-8" + "en_US.UTF-8/UTF-8" + ]; + + users.users.ada = { + isNormalUser = true; + shell = pkgs.bashInteractive; + extraGroups = [ + "wheel" + "docker" + "libvirtd" + ]; + openssh.authorizedKeys.keys = [ + "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIWNsUQmppB6cQccXX1ZaBbFIcmM6RmghsTVbG9TgoZB ada@ada-x1" + ]; + }; + + services.openssh = { + enable = true; + settings = { + PasswordAuthentication = false; + KbdInteractiveAuthentication = false; + PermitRootLogin = "no"; + PubkeyAuthentication = true; + }; + }; + + environment.systemPackages = with pkgs; [ + git + restic + resticprofile + ]; + + systemd.tmpfiles.rules = [ + "d /opt/services 0755 ada users - -" + "d /opt/data 0755 ada users - -" + "d /opt/configs 0755 ada users - -" + "d /opt/data/postgres 0755 ada users - -" + "d /opt/data/nextcloud 0755 ada users - -" + "d /opt/data/gitea 0755 ada users - -" + "d /opt/data/gitea-runner 0755 ada users - -" + "d /opt/data/syncthing 0755 ada users - -" + "d /opt/data/zerotier 0755 ada users - -" + "d /opt/configs/nextcloud 0755 ada users - -" + "d /opt/configs/nextcloud/app 0755 ada users - -" + "d /opt/configs/syncthing 0755 ada users - -" + "d /opt/samba 0755 ada users - -" + "d /opt/samba/media 0755 ada users - -" + "d /opt/samba/documents 0755 ada users - -" + "d /opt/samba/backups_win 0755 ada users - -" + "d /mnt/backup 0755 ada users - -" + "d /mnt/backup/restic 0755 ada users - -" + "d /mnt/backup/restic/services 0755 ada users - -" + "d /mnt/backup/restic/samba 0755 ada users - -" + "d /mnt/backup/devices 0755 ada users - -" + "d /mnt/backup/devices/proxmox 0755 ada users - -" + "d /mnt/backup/devices/ada-x1 0755 ada users - -" + "d /mnt/yandex 0755 ada users - -" + ]; +} diff --git a/nixos/modules/docker.nix b/nixos/modules/docker.nix new file mode 100644 index 0000000..6c703d7 --- /dev/null +++ b/nixos/modules/docker.nix @@ -0,0 +1,17 @@ +{ pkgs, ... }: + +{ + virtualisation.docker = { + enable = true; + daemon.settings = { + registry-mirrors = [ + "https://mirror.gcr.io" + "https://dockerhub.timeweb.cloud" + ]; + }; + }; + + environment.systemPackages = with pkgs; [ + docker-compose + ]; +} diff --git a/nixos/modules/firewall.nix b/nixos/modules/firewall.nix new file mode 100644 index 0000000..80e7fae --- /dev/null +++ b/nixos/modules/firewall.nix @@ -0,0 +1,25 @@ +{ + networking.firewall = { + enable = true; + allowedTCPPorts = [ + 22 + 139 + 445 + 2222 + 3002 + 4567 + 5432 + 7080 + 8081 + 8384 + 22000 + ]; + allowedUDPPorts = [ + 137 + 138 + 9993 + 21027 + 22000 + ]; + }; +}