From 3ccc7e784a0ed5b19910ab856f6d9774a6f27956 Mon Sep 17 00:00:00 2001 From: Kleidi Bujari Date: Sat, 23 Nov 2024 16:36:43 -0500 Subject: Initial scaffolding and layout Set up the modules of the flake. At this time, the flake is split into modules and machines. Considering that additional top-level sections -- such as packages and shells -- will also be added, it might make sense to keep all nix related things in one top-level directory, alongside the flake.nix file. This is all under the assumption that later amendments to the project will introduce other tech, such as terraform. --- modules/xnet/users/default.nix | 8 ++++++++ modules/xnet/users/radicale.nix | 28 ++++++++++++++++++++++++++++ modules/xnet/users/secret.yaml | 31 +++++++++++++++++++++++++++++++ 3 files changed, 67 insertions(+) create mode 100644 modules/xnet/users/default.nix create mode 100644 modules/xnet/users/radicale.nix create mode 100644 modules/xnet/users/secret.yaml (limited to 'modules/xnet/users') diff --git a/modules/xnet/users/default.nix b/modules/xnet/users/default.nix new file mode 100644 index 0000000..c567c23 --- /dev/null +++ b/modules/xnet/users/default.nix @@ -0,0 +1,8 @@ +{ ... }: { + imports = [ ./radicale.nix ]; + + security.sudo = { + execWheelOnly = true; + extraConfig = "Defaults lecture = never"; + }; +} diff --git a/modules/xnet/users/radicale.nix b/modules/xnet/users/radicale.nix new file mode 100644 index 0000000..7d752f0 --- /dev/null +++ b/modules/xnet/users/radicale.nix @@ -0,0 +1,28 @@ +{ config, ... }: +let path = "/persist/data/radicale"; in { + services.radicale = { + enable = false; + settings = { + server.hosts = [ "127.0.0.1:5232" ]; + storage.filesystem_folder = "${path}/collections"; + auth = { + type = "htpasswd"; + htpasswd_filename = "${path}/users"; + htpasswd_encryption = "plain"; + }; + }; + }; + + systemd.tmpfiles.rules = [ + "d ${path} 0700 radicale radicale -" + "Z ${path} 0700 radicale radicale - -" + ]; + + services.nginx.virtualHosts."dav.web.4kb.net" = { + useACMEHost = "4kb.net"; + forceSSL = true; + locations."/" = { + proxyPass = "http://127.0.0.1:5232/"; + }; + }; +} diff --git a/modules/xnet/users/secret.yaml b/modules/xnet/users/secret.yaml new file mode 100644 index 0000000..0381dea --- /dev/null +++ b/modules/xnet/users/secret.yaml @@ -0,0 +1,31 @@ +root: ENC[AES256_GCM,data:N0CdjX9uY9IeLX95SSzQYsV/6IVfs0r1rX0JTCbb6WD7/oID0/y9CwErPKhCP03x7aKS4mqwgU6dVECAqsEIs35AS/O84FELTw==,iv:8+jKwsBfUfiEkclW2moLtzwB6MDouNq7N4U24f18kiQ=,tag:Ekw+vOXyhMgw5oPRTzV/Qg==,type:str] +kleidi: ENC[AES256_GCM,data:r0C5/fuY/RwNv9FFCrDMr4UnDK4cA1vFcDPlGTHSKYExzd+T6zrw5Zl/YO98uB3WC4mEtIgfZQxGwMgYyCVU2piJeW40/wftLA==,iv:hRa2eUx7tgyoV/hh6H+e5QCrTtQc/rOYIYefs32yzNg=,tag:Z/m+f+SvOHGleLtWU49nsA==,type:str] +sops: + kms: [] + gcp_kms: [] + azure_kv: [] + hc_vault: [] + age: + - recipient: age15f6mcwjjav4z757kad8wksalgemael364wwxz7qsral5gmjzmd2qre78d5 + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBaRE85OWRmR1VtcWg0cnBz + SW9JRDJpN1RwRER5alAwUDBNM2ZrQ0Jna2tJClEweStEdmsyTnZNcXBsN3RIRXln + eUxUcUZwYU9CMDBjejlQRG0rdVRCUG8KLS0tIGt6MS9kN05MY0xhbWY5cjBBMlBG + dmpXeloxTDNydGRtd0ZFUVhKOWlMT1kKNj6BpUhgq6/AAHvFfNaEeHPsB2eRMzjS + lH7Vxn0mj00LdilatnWMajr8u3FWq+XYc2kPIo/XM8AmM/u17rMoag== + -----END AGE ENCRYPTED FILE----- + - recipient: age1nw5yklj57fegqllhqfjuy9f89cx9f9p0xptw9uv58rzleh8fdyssv0zyp4 + enc: | + -----BEGIN AGE ENCRYPTED FILE----- + YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBTWXBuWGZ3NzI4ZHJOZllm + UVJYYnB5RklPTkh3ODdhY3hXUnFnWnBEaTNvClQ4RXpkWDI0ZUF2NHdvT2lOZDUv + dmgvSWtXU3p0WjhWeHV3L0VjRGdweE0KLS0tIE1kSm4xajd6MVNsNUlsSHhlbXUz + c2NGY3luQ2prUFNLKytEVFlFdDhtWEUKl3tUxQIpJA9RJLs2Fvb7s4Cn21CEC3r6 + XZ1BXjXKxHoEPyTARvxDqJXJxSvaH76283rhSG1vcQzmGUm56LZcLw== + -----END AGE ENCRYPTED FILE----- + lastmodified: "2024-10-31T01:49:17Z" + mac: ENC[AES256_GCM,data:ye2kvRJCGn/h1QviQ+Zrhykau7gCSe78QWEd2QgvfIPMgcDh3COdhavsd9zDRmDMNJBAiDTWQkrgTtYDzx859TsxfJdEDp6X7xRWhI/2dU94aRVGQGxdKTRiswJR+RzHmO0Cf4tNqYYjIySym4v39yWKioQlV4Vm9BW2eUTYLNo=,iv:gSvqxLggrf085IY+u/VeNkYAho/gMC5U2xkqgfSpeTc=,tag:gRTfIoFqta+7udwANTqO2A==,type:str] + pgp: [] + unencrypted_suffix: _unencrypted + version: 3.9.1 -- cgit v1.3.1