2021-02-06 12:18:55 +01:00
|
|
|
|
{ config, lib, pkgs, ... }:
|
2021-05-01 16:30:48 +02:00
|
|
|
|
|
2021-02-01 17:33:29 +01:00
|
|
|
|
{
|
|
|
|
|
imports = [
|
|
|
|
|
./hardware-configuration.nix
|
|
|
|
|
../../modules
|
2021-02-07 12:29:22 +01:00
|
|
|
|
|
2021-03-31 12:08:35 +02:00
|
|
|
|
./services/coturn.nix
|
2021-02-28 16:16:06 +01:00
|
|
|
|
./services/element-web.nix
|
2021-02-01 17:33:29 +01:00
|
|
|
|
];
|
|
|
|
|
|
|
|
|
|
sbruder = {
|
2021-03-05 16:00:10 +01:00
|
|
|
|
nginx.hardening.enable = true;
|
2021-02-28 12:21:04 +01:00
|
|
|
|
restic.system.enable = true;
|
2021-02-20 19:03:40 +01:00
|
|
|
|
wireguard.home.enable = true;
|
2021-02-05 15:35:42 +01:00
|
|
|
|
full = false;
|
2021-02-06 12:18:55 +01:00
|
|
|
|
|
|
|
|
|
mailserver = {
|
|
|
|
|
enable = true;
|
|
|
|
|
fqdn = "vueko.sbruder.de";
|
|
|
|
|
domains = [
|
|
|
|
|
"kegelschiene.net"
|
|
|
|
|
"sbruder.de"
|
|
|
|
|
];
|
|
|
|
|
users = import ./secrets/mail-users.nix;
|
|
|
|
|
rejectSenders = import ./secrets/mail-reject-senders.nix;
|
|
|
|
|
};
|
2021-02-01 17:33:29 +01:00
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
networking.hostName = "vueko";
|
|
|
|
|
|
|
|
|
|
system.stateVersion = "20.09";
|
2021-02-06 12:18:55 +01:00
|
|
|
|
|
2021-02-10 14:22:00 +01:00
|
|
|
|
# sadly, too many (legitimate) mail servers have broken dnssec on reverse
|
|
|
|
|
# lookups
|
|
|
|
|
services.resolved.dnssec = "false";
|
|
|
|
|
|
2021-02-06 12:18:55 +01:00
|
|
|
|
services.nginx = {
|
|
|
|
|
enable = true;
|
|
|
|
|
|
|
|
|
|
recommendedGzipSettings = true;
|
2021-03-07 15:49:24 +01:00
|
|
|
|
recommendedOptimisation = true;
|
|
|
|
|
recommendedProxySettings = true;
|
|
|
|
|
recommendedTlsSettings = true;
|
2021-02-06 12:18:55 +01:00
|
|
|
|
|
|
|
|
|
virtualHosts = {
|
|
|
|
|
"vueko.sbruder.de" = {
|
|
|
|
|
enableACME = true;
|
|
|
|
|
forceSSL = true;
|
2021-02-14 19:49:05 +01:00
|
|
|
|
|
2021-03-07 15:50:52 +01:00
|
|
|
|
default = true;
|
|
|
|
|
|
2021-02-14 19:49:05 +01:00
|
|
|
|
root = pkgs.sbruder.imprint;
|
2021-02-06 12:18:55 +01:00
|
|
|
|
};
|
|
|
|
|
"dav.sbruder.de" = {
|
|
|
|
|
enableACME = true;
|
|
|
|
|
forceSSL = true;
|
|
|
|
|
|
|
|
|
|
locations."/".proxyPass = "http://localhost:5232";
|
|
|
|
|
};
|
2021-02-07 12:29:22 +01:00
|
|
|
|
"mumble.sbruder.de" = {
|
|
|
|
|
enableACME = true;
|
|
|
|
|
forceSSL = true;
|
|
|
|
|
};
|
2021-02-07 21:02:11 +01:00
|
|
|
|
"bangs.sbruder.de" = {
|
|
|
|
|
enableACME = true;
|
|
|
|
|
forceSSL = true;
|
|
|
|
|
locations."/".proxyPass = "http://localhost:8000";
|
|
|
|
|
};
|
2021-02-06 12:18:55 +01:00
|
|
|
|
};
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
networking.firewall.allowedTCPPorts = [
|
|
|
|
|
80 # HTTP
|
|
|
|
|
443 # HTTPS
|
|
|
|
|
];
|
|
|
|
|
|
|
|
|
|
services.radicale = {
|
|
|
|
|
enable = true;
|
2021-05-28 14:24:02 +02:00
|
|
|
|
settings = {
|
2021-02-06 12:18:55 +01:00
|
|
|
|
auth = {
|
|
|
|
|
type = "htpasswd";
|
|
|
|
|
htpasswd_encryption = "bcrypt";
|
|
|
|
|
htpasswd_filename = toString (pkgs.writeText
|
|
|
|
|
"radicale-htpasswd"
|
|
|
|
|
(lib.concatMapStringsSep
|
|
|
|
|
"\n"
|
|
|
|
|
({ address, passwordHash, ... }: "${address}:${passwordHash}")
|
|
|
|
|
config.sbruder.mailserver.users));
|
|
|
|
|
};
|
|
|
|
|
};
|
|
|
|
|
};
|
2021-02-07 12:29:22 +01:00
|
|
|
|
|
2021-03-01 15:27:18 +01:00
|
|
|
|
sops.secrets.murmur-superuser = {
|
|
|
|
|
owner = config.users.users.murmur.name;
|
|
|
|
|
sopsFile = ./secrets.yaml;
|
|
|
|
|
};
|
2021-02-07 12:29:22 +01:00
|
|
|
|
|
2021-05-28 14:24:25 +02:00
|
|
|
|
users.users.murmur.isSystemUser = true; # Infinisil’s module does not set that
|
2021-02-07 12:29:22 +01:00
|
|
|
|
services.murmur = {
|
|
|
|
|
enable = true;
|
|
|
|
|
openFirewall = true;
|
2021-03-01 15:27:18 +01:00
|
|
|
|
superuserPasswordFile = config.sops.secrets.murmur-superuser.path;
|
2021-02-07 12:29:22 +01:00
|
|
|
|
acmeDomain = "mumble.sbruder.de";
|
|
|
|
|
config = {
|
|
|
|
|
bandwidth = "128000";
|
|
|
|
|
obfuscate = true;
|
|
|
|
|
logfile = ""; # log to stdout
|
|
|
|
|
|
|
|
|
|
channelname = ''[ \\-=\\w\\#\\[\\]\\{\\}\\(\\)\\@\\|]+'';
|
|
|
|
|
};
|
|
|
|
|
};
|
2021-02-07 21:02:11 +01:00
|
|
|
|
|
|
|
|
|
services.bang-evaluator = {
|
|
|
|
|
enable = true;
|
|
|
|
|
listenAddress = ":8000";
|
|
|
|
|
};
|
2021-02-01 17:33:29 +01:00
|
|
|
|
}
|