diff --git a/flake.lock b/flake.lock index 88d0a3d..19a500d 100644 --- a/flake.lock +++ b/flake.lock @@ -476,11 +476,11 @@ "secrets": { "flake": false, "locked": { - "lastModified": 1781207988, - "narHash": "sha256-ZsPqHeeUXDR1fksT4EGlizv8RHPHp42kusVNhnenzxo=", + "lastModified": 1781738124, + "narHash": "sha256-fff++SWoSeZJk9wwns/XzCHGU5ZOTDie821At68gH9I=", "ref": "refs/heads/main", - "rev": "53c5bdca5f2ff22b4e950c38b4d8bb96ee03c80d", - "revCount": 40, + "rev": "fdf7619e52d6bea25224f19da87b6946a6f23cf7", + "revCount": 41, "type": "git", "url": "ssh://git@git.jfreudenberger.de/JuliusFreudenberger/nix-private.git" }, diff --git a/flake.nix b/flake.nix index 766bf60..3ff514b 100644 --- a/flake.nix +++ b/flake.nix @@ -173,6 +173,20 @@ ]; }; + busch-nixos-native = nixpkgs.lib.nixosSystem rec { + system = "x86_64-linux"; + + specialArgs = { + inherit inputs outputs; + }; + + modules = [ + ./hosts/busch-nixos-native + disko.nixosModules.disko + agenix.nixosModules.default + ]; + }; + srv01-hf = nixpkgs.lib.nixosSystem rec { system = "x86_64-linux"; diff --git a/hosts/busch-nixos-native/default.nix b/hosts/busch-nixos-native/default.nix new file mode 100644 index 0000000..e33ed9c --- /dev/null +++ b/hosts/busch-nixos-native/default.nix @@ -0,0 +1,73 @@ +{ inputs, outputs, config, lib, pkgs, ... }: + +{ + imports = + [ + ../../modules/disko/legacy-full-ext4.nix + ./secrets.nix + + ../../users/julius/nixos-server.nix + ../../modules/nix.nix + ../../modules/auto-upgrade.nix + ../../modules/qemu-guest.nix + ../../modules/locale.nix + ../../modules/server-cli.nix + ../../modules/sshd.nix + ../../modules/netbird-client.nix + "${inputs.secrets}/modules/opkssh.nix" + + # Include the results of the hardware scan. + ./hardware-configuration.nix + ]; + + # Use the GRUB 2 boot loader. + boot = { + loader.grub = { + enable = true; + }; + tmp.useTmpfs = true; + }; + networking.hostName = "busch-nixos-native"; # Define your hostname. + + services.netbird-client = { + enable = true; + managementUrl = "https://netbird.jfreudenberger.de"; + host.setupKey = "E182754A-F338-4DAE-8036-03404033D30E"; + }; + + services.beszel.agent = { + enable = true; + environment = { + HUB_URL = "https://beszel.jfreudenberger.de"; + DISABLE_SSH = "true"; + }; + environmentFile = config.age.secrets.beszel.path; + }; + + services.renovate = { + enable = true; + credentials = { + RENOVATE_TOKEN = config.age.secrets.renovate-token.path; + RENOVATE_GITHUB_COM_TOKEN = config.age.secrets.renovate-github-com-token.path; + }; + settings = { + gitAuthor = "Renovate Bot "; + platform = "forgejo"; + endpoint = "https://git.jfreudenberger.de"; + }; + }; + + # This option defines the first version of NixOS you have installed on this particular machine, + # and is used to maintain compatibility with application data (e.g. databases) created on older NixOS versions. + # Most users should NEVER change this value after the initial install, for any reason, + # even if you've upgraded your system to a new NixOS release. + # This value does NOT affect the Nixpkgs version your packages and OS are pulled from, + # so changing it will NOT upgrade your system - see https://nixos.org/manual/nixos/stable/#sec-upgrading for how + # to actually do that. + # This value being lower than the current NixOS release does NOT mean your system is + # out of date, out of support, or vulnerable. + # Do NOT change this value unless you have manually inspected all the changes it would make to your configuration, + # and migrated your data accordingly. + # For more information, see `man configuration.nix` or https://nixos.org/manual/nixos/stable/options#opt-system.stateVersion . + system.stateVersion = "25.05"; # Did you read the comment? +} diff --git a/hosts/busch-nixos-native/hardware-configuration.nix b/hosts/busch-nixos-native/hardware-configuration.nix new file mode 100644 index 0000000..54932ff --- /dev/null +++ b/hosts/busch-nixos-native/hardware-configuration.nix @@ -0,0 +1,17 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ "ata_piix" "uhci_hcd" "virtio_pci" "virtio_scsi" "sd_mod" "sr_mod" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ "kvm-intel" ]; + boot.extraModulePackages = [ ]; + + nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux"; +} diff --git a/hosts/busch-nixos-native/secrets.nix b/hosts/busch-nixos-native/secrets.nix new file mode 100644 index 0000000..5aa64a4 --- /dev/null +++ b/hosts/busch-nixos-native/secrets.nix @@ -0,0 +1,8 @@ +{ inputs, ... }: +{ + age.secrets = { + beszel.file = "${inputs.secrets}/secrets/busch-nixos-native/beszel"; + renovate-token.file = "${inputs.secrets}/secrets/busch-nixos-native/renovate-token"; + renovate-github-com-token.file = "${inputs.secrets}/secrets/busch-nixos-native/renovate-github-com-token"; + }; +}