diff --git a/hosts/pi-server/default.nix b/hosts/pi-server/default.nix index eff5451..6761044 100644 --- a/hosts/pi-server/default.nix +++ b/hosts/pi-server/default.nix @@ -1,5 +1,11 @@ -{ inputs, outputs, lib, config, pkgs, ... }: -let +{ + inputs, + outputs, + lib, + config, + pkgs, + ... +}: let my-python-packages = python-packages: with python-packages; [ pip @@ -12,10 +18,10 @@ let in { nix = { settings = { - experimental-features = [ "nix-command" "flakes" ]; + experimental-features = ["nix-command" "flakes"]; warn-dirty = false; auto-optimise-store = true; - trusted-users = [ "root" "don" ]; + trusted-users = ["root" "don"]; }; gc = { automatic = true; @@ -26,7 +32,7 @@ in { imports = [ ../../home ./systemd.nix - ./tailscale.nix + ../vars.nix ./upgrade-diff.nix ../../modules/beszel-agent.nix ]; @@ -48,14 +54,14 @@ in { inputMethod = { enable = true; type = "fcitx5"; - fcitx5.addons = with pkgs; [ fcitx5-mozc fcitx5-gtk ]; + fcitx5.addons = with pkgs; [fcitx5-mozc fcitx5-gtk]; }; }; # Bootloader. boot = { kernelPackages = pkgs.linuxPackages_rpi4; - kernelParams = [ "consoleblank=60" ]; + kernelParams = ["consoleblank=60"]; #loader = { #systemd-boot = { #enable = true; @@ -65,34 +71,36 @@ in { #efiSysMountPoint = "/boot"; #}; #}; - plymouth = { enable = true; }; - kernel = { sysctl = { "vm.swappiness" = 10; }; }; + plymouth = {enable = true;}; + kernel = {sysctl = {"vm.swappiness" = 10;};}; }; security = { - polkit = { enable = true; }; + polkit = {enable = true;}; sudo.enable = false; doas = { enable = true; - extraRules = [{ - users = [ "don" ]; - keepEnv = true; - noPass = true; - }]; + extraRules = [ + { + users = ["don"]; + keepEnv = true; + noPass = true; + } + ]; }; }; services = { - pcscd = { enable = true; }; - beszel-agent = { enable = true; }; + pcscd = {enable = true;}; + beszel-agent = {enable = true;}; avahi = { enable = true; nssmdns4 = true; }; - printing = { enable = true; }; - udisks2 = { enable = true; }; - nscd = { enableNsncd = true; }; - tailscale = { enable = true; }; + printing = {enable = true;}; + udisks2 = {enable = true;}; + nscd = {enableNsncd = true;}; + tailscale = {enable = true;}; locate = { enable = true; package = pkgs.mlocate; @@ -176,8 +184,8 @@ in { ]; programs = { - dconf = { enable = true; }; - mtr = { enable = true; }; + dconf = {enable = true;}; + mtr = {enable = true;}; gnupg = { agent = { enable = true; @@ -189,7 +197,7 @@ in { nixpkgs.overlays = [ (final: super: { - khal = super.khal.overridePythonAttrs (_: { doCheck = false; }); + khal = super.khal.overridePythonAttrs (_: {doCheck = false;}); }) ]; @@ -197,35 +205,26 @@ in { networking.firewall = { enable = true; # always allow traffic from your Tailscale network - trustedInterfaces = [ "tailscale0" ]; + trustedInterfaces = ["tailscale0"]; checkReversePath = "loose"; # allow the Tailscale UDP port through the firewall - allowedUDPPorts = [ config.services.tailscale.port ]; - allowedTCPPortRanges = [{ - from = 1714; - to = 1764; - }]; - allowedUDPPortRanges = [{ - from = 1714; - to = 1764; - }]; + allowedUDPPorts = [config.services.tailscale.port]; + allowedTCPPortRanges = [ + { + from = 1714; + to = 1764; + } + ]; + allowedUDPPortRanges = [ + { + from = 1714; + to = 1764; + } + ]; # allow you to SSH in over the public internet - allowedTCPPorts = [ 22 ]; - interfaces = { - "tailscale0" = { - allowedTCPPorts = [ 22 8080 8443 ]; - allowedTCPPortRanges = [{ - from = 1714; - to = 1764; - }]; - allowedUDPPortRanges = [{ - from = 1714; - to = 1764; - }]; - }; - }; + allowedTCPPorts = [22]; }; # This value determines the NixOS release from which the default