secureboot and stuff
This commit is contained in:
parent
cb42a4b357
commit
268910b783
1
.gitattributes
vendored
1
.gitattributes
vendored
@ -5,3 +5,4 @@ secrets/wg0.conf filter=git-crypt diff=git-crypt
|
|||||||
secrets/caddy_auth.nix filter=git-crypt diff=git-crypt
|
secrets/caddy_auth.nix filter=git-crypt diff=git-crypt
|
||||||
secrets/matrix_reg_token.nix filter=git-crypt diff=git-crypt
|
secrets/matrix_reg_token.nix filter=git-crypt diff=git-crypt
|
||||||
secrets/owntracks_caddy_auth.nix filter=git-crypt diff=git-crypt
|
secrets/owntracks_caddy_auth.nix filter=git-crypt diff=git-crypt
|
||||||
|
secrets/secureboot.tar filter=git-crypt diff=git-crypt
|
||||||
|
|||||||
18
flake.lock
generated
18
flake.lock
generated
@ -64,11 +64,11 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1737510347,
|
"lastModified": 1737683037,
|
||||||
"narHash": "sha256-wEEkmpmd5FF0HEBeA3upQg2W1yI7jGJ7xg2dmKuZE7o=",
|
"narHash": "sha256-1J2Pf6ub2DkkoqRq2xEFrusJKR4XHnnFk0wyOPrV2PM=",
|
||||||
"owner": "Infinidoge",
|
"owner": "Infinidoge",
|
||||||
"repo": "nix-minecraft",
|
"repo": "nix-minecraft",
|
||||||
"rev": "ed6d2231a22a507f9a32d5661ef17c76eab8404d",
|
"rev": "f80c70946d3e27a466b8b9e65b24e36d571eac8b",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@ -79,11 +79,11 @@
|
|||||||
},
|
},
|
||||||
"nixos-hardware": {
|
"nixos-hardware": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1737359802,
|
"lastModified": 1737751639,
|
||||||
"narHash": "sha256-utplyRM6pqnN940gfaLFBb9oUCSzkan86IvmkhsVlN8=",
|
"narHash": "sha256-ZEbOJ9iT72iwqXsiEMbEa8wWjyFvRA9Ugx8utmYbpz4=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixos-hardware",
|
"repo": "nixos-hardware",
|
||||||
"rev": "61c79181e77ef774ab0468b28a24bc2647d498d6",
|
"rev": "dfad538f751a5aa5d4436d9781ab27a6128ec9d4",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@ -95,11 +95,11 @@
|
|||||||
},
|
},
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1737299813,
|
"lastModified": 1737672001,
|
||||||
"narHash": "sha256-Qw2PwmkXDK8sPQ5YQ/y/icbQ+TYgbxfjhgnkNJyT1X8=",
|
"narHash": "sha256-YnHJJ19wqmibLQdUeq9xzE6CjrMA568KN/lFPuSVs4I=",
|
||||||
"owner": "NixOS",
|
"owner": "NixOS",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "107d5ef05c0b1119749e381451389eded30fb0d5",
|
"rev": "035f8c0853c2977b24ffc4d0a42c74f00b182cd8",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
|
|||||||
BIN
secrets/secureboot.tar
Normal file
BIN
secrets/secureboot.tar
Normal file
Binary file not shown.
@ -39,7 +39,7 @@ in
|
|||||||
}
|
}
|
||||||
'';
|
'';
|
||||||
|
|
||||||
${service_configs.gitea.domain}.extraConfig = ''
|
"${service_configs.gitea.domain}".extraConfig = ''
|
||||||
reverse_proxy :${builtins.toString config.services.gitea.settings.server.HTTP_PORT}
|
reverse_proxy :${builtins.toString config.services.gitea.settings.server.HTTP_PORT}
|
||||||
'';
|
'';
|
||||||
|
|
||||||
@ -78,7 +78,7 @@ in
|
|||||||
};
|
};
|
||||||
|
|
||||||
systemd.tmpfiles.rules = [
|
systemd.tmpfiles.rules = [
|
||||||
"d ${service_configs.https.data_dir} 0750 ${config.services.caddy.user} ${config.services.caddy.group}"
|
"d ${service_configs.https.data_dir} g+rwx ${config.services.caddy.user} ${config.services.caddy.group}"
|
||||||
];
|
];
|
||||||
|
|
||||||
systemd.packages = with pkgs; [ nssTools ];
|
systemd.packages = with pkgs; [ nssTools ];
|
||||||
|
|||||||
@ -12,9 +12,6 @@
|
|||||||
services.matrix-conduit = {
|
services.matrix-conduit = {
|
||||||
enable = true;
|
enable = true;
|
||||||
package = pkgs.conduwuit;
|
package = pkgs.conduwuit;
|
||||||
# package = pkgs.conduwuit.overrideAttrs (old: {
|
|
||||||
# cargoBuildFeatures = pkgs.lib.remove "release_max_log_level" old.cargoBuildFeatures;
|
|
||||||
# });
|
|
||||||
|
|
||||||
settings.global = {
|
settings.global = {
|
||||||
port = 6167;
|
port = 6167;
|
||||||
|
|||||||
@ -59,7 +59,11 @@
|
|||||||
IncludeOverheadInLimits = false;
|
IncludeOverheadInLimits = false;
|
||||||
|
|
||||||
GlobalMaxRatio = 2;
|
GlobalMaxRatio = 2;
|
||||||
QueueingSystemEnabled = false; # seed all torrents all the time
|
QueueingSystemEnabled = false; # seed all torrents all the timei
|
||||||
|
|
||||||
|
# add a few trackers TODO! add a script so I can just do a list
|
||||||
|
AddTrackersEnabled = true;
|
||||||
|
AdditionalTrackers = "udp://tracker.opentrackr.org:1337/announce\\nudp://open.stealth.si:80/announce\\nudp://open.demonii.com:1337\\nudp://exodus.desync.com:6969/announce";
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user