aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAkshay Nair <phenax5@gmail.com>2025-06-14 16:40:48 +0530
committerAkshay Nair <phenax5@gmail.com>2025-06-14 16:40:48 +0530
commit42df69164dbc74e5ddb54f5a7a01fd66260fef57 (patch)
treebc8b19c39df9edf16ca6827005b3d5e1ef564764
parent58519ea7b12e8ad58c0f97d9636d30572a789b41 (diff)
downloadhomeserver-nixos-config-42df69164dbc74e5ddb54f5a7a01fd66260fef57.tar.gz
homeserver-nixos-config-42df69164dbc74e5ddb54f5a7a01fd66260fef57.zip
Switch to coredns + refactor dns hosts mapping into service + more refactor
-rw-r--r--configuration.nix4
-rw-r--r--flake.lock37
-rw-r--r--flake.nix7
-rw-r--r--modules/dashboard/default.nix2
-rw-r--r--modules/hardware/default.nix (renamed from modules/hardware.nix)26
-rw-r--r--modules/hardware/fs.nix27
-rw-r--r--modules/network/default.nix19
-rw-r--r--modules/users/default.nix (renamed from modules/users.nix)2
-rw-r--r--services/bacchus-dashboard/bacchus-dashboard.service.nix (renamed from modules/dashboard/bacchus-dashboard.service.nix)0
-rw-r--r--services/bacchus-dashboard/dashboard-template.nix (renamed from modules/dashboard/dashboard-template.nix)0
-rw-r--r--services/bacchus-dns.service.nix39
-rw-r--r--services/service-router.service.nix (renamed from modules/network/service-router.service.nix)36
12 files changed, 98 insertions, 101 deletions
diff --git a/configuration.nix b/configuration.nix
index f1af667..ec0f1a0 100644
--- a/configuration.nix
+++ b/configuration.nix
@@ -1,8 +1,8 @@
{ pkgs, ... }:
{
imports = [
- ./modules/hardware.nix
- ./modules/users.nix
+ ./modules/hardware
+ ./modules/users
./modules/network
./modules/media
./modules/dashboard
diff --git a/flake.lock b/flake.lock
index f1c7fdc..ea98cc1 100644
--- a/flake.lock
+++ b/flake.lock
@@ -1,41 +1,5 @@
{
"nodes": {
- "dns": {
- "inputs": {
- "flake-utils": "flake-utils",
- "nixpkgs": [
- "nixpkgs"
- ]
- },
- "locked": {
- "lastModified": 1737653493,
- "narHash": "sha256-qTbv8Pm9WWF63M5Fj0Od9E54/lsbMSQUBHw/s30eFok=",
- "owner": "kirelagin",
- "repo": "dns.nix",
- "rev": "96e548ae8bd44883afc5bddb9dacd0502542276d",
- "type": "github"
- },
- "original": {
- "owner": "kirelagin",
- "repo": "dns.nix",
- "type": "github"
- }
- },
- "flake-utils": {
- "locked": {
- "lastModified": 1614513358,
- "narHash": "sha256-LakhOx3S1dRjnh0b5Dg3mbZyH0ToC9I8Y2wKSkBaTzU=",
- "owner": "numtide",
- "repo": "flake-utils",
- "rev": "5466c5bbece17adaab2d82fae80b46e807611bf3",
- "type": "github"
- },
- "original": {
- "owner": "numtide",
- "repo": "flake-utils",
- "type": "github"
- }
- },
"nixos-hardware": {
"locked": {
"lastModified": 1749195551,
@@ -69,7 +33,6 @@
},
"root": {
"inputs": {
- "dns": "dns",
"nixos-hardware": "nixos-hardware",
"nixpkgs": "nixpkgs"
}
diff --git a/flake.nix b/flake.nix
index b5163e9..d7154c2 100644
--- a/flake.nix
+++ b/flake.nix
@@ -2,16 +2,11 @@
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
nixos-hardware.url = "github:NixOS/nixos-hardware";
- dns = {
- url = "github:kirelagin/dns.nix";
- inputs.nixpkgs.follows = "nixpkgs";
- };
};
- outputs = { self, nixpkgs, nixos-hardware, dns, ... }: {
+ outputs = { self, nixpkgs, nixos-hardware, ... }: {
nixosConfigurations.bacchus = nixpkgs.lib.nixosSystem {
system = "x86_64-linux";
- specialArgs = { inherit dns; };
modules = [
"${nixos-hardware}/lenovo/ideapad"
./configuration.nix
diff --git a/modules/dashboard/default.nix b/modules/dashboard/default.nix
index 196eab1..c1de246 100644
--- a/modules/dashboard/default.nix
+++ b/modules/dashboard/default.nix
@@ -4,7 +4,7 @@ let
ports = settings.network.ports;
in
{
- imports = [ ./bacchus-dashboard.service.nix ];
+ imports = [ ../../services/bacchus-dashboard/bacchus-dashboard.service.nix ];
services.bacchus-dashboard = {
enable = true;
diff --git a/modules/hardware.nix b/modules/hardware/default.nix
index 7b11ca6..098b3cc 100644
--- a/modules/hardware.nix
+++ b/modules/hardware/default.nix
@@ -2,6 +2,7 @@
{
imports = [
(modulesPath + "/installer/scan/not-detected.nix")
+ ./fs.nix
];
boot.initrd = {
@@ -44,30 +45,5 @@
efi.canTouchEfiVariables = true;
};
- # File system
- fileSystems = {
- "/" = {
- device = "/dev/disk/by-label/nixos";
- fsType = "ext4";
- };
- "/boot" = {
- device = "/dev/disk/by-label/boot";
- fsType = "vfat";
- };
- "/media" = {
- device = "/dev/disk/by-label/media";
- fsType = "ext4";
- options = [ "rw" "nofail" "x-systemd.automount" "x-systemd.mount-timeout=30s" ];
- };
- };
- swapDevices = [{ device = "/dev/disk/by-label/swap"; }];
-
networking.useDHCP = lib.mkDefault true;
-
- systemd.extraConfig = ''DefaultLimitNOFILE=65536'';
- systemd.user.extraConfig = ''DefaultLimitNOFILE=65536'';
- boot.kernel.sysctl."fs.inotify.max_user_instances" = 8192;
- security.pam.loginLimits = [
- { domain = "*"; type = "-"; item = "nofile"; value = "65536"; }
- ];
}
diff --git a/modules/hardware/fs.nix b/modules/hardware/fs.nix
new file mode 100644
index 0000000..aaf67d6
--- /dev/null
+++ b/modules/hardware/fs.nix
@@ -0,0 +1,27 @@
+{ ... }:
+{
+ fileSystems = {
+ "/" = {
+ device = "/dev/disk/by-label/nixos";
+ fsType = "ext4";
+ };
+ "/boot" = {
+ device = "/dev/disk/by-label/boot";
+ fsType = "vfat";
+ };
+ "/media" = {
+ device = "/dev/disk/by-label/media";
+ fsType = "ext4";
+ options = [ "rw" "nofail" "x-systemd.automount" "x-systemd.mount-timeout=30s" ];
+ };
+ };
+ swapDevices = [{ device = "/dev/disk/by-label/swap"; }];
+
+ # Set high limits for file watching/file handles
+ systemd.extraConfig = ''DefaultLimitNOFILE=65536'';
+ systemd.user.extraConfig = ''DefaultLimitNOFILE=65536'';
+ boot.kernel.sysctl."fs.inotify.max_user_instances" = 8192;
+ security.pam.loginLimits = [
+ { domain = "*"; type = "-"; item = "nofile"; value = "65536"; }
+ ];
+}
diff --git a/modules/network/default.nix b/modules/network/default.nix
index 290c291..78fac75 100644
--- a/modules/network/default.nix
+++ b/modules/network/default.nix
@@ -8,9 +8,15 @@ in
imports = [
./wireless.nix
./ssh.nix
- ./service-router.service.nix
+ ../../services/service-router.service.nix
+ ../../services/bacchus-dns.service.nix
];
+ networking = {
+ hostName = "bacchus";
+ firewall.enable = true;
+ };
+
services.service-router = {
enable = true;
routes = {
@@ -23,12 +29,15 @@ in
"syncthing.local" = { inherit host; port = ports.syncthing; };
"lidarr.local" = { inherit host; port = ports.lidarr; };
"ntfy.local" = { inherit host; port = ports.ntfy; };
- "grafana.local" = { inherit host; port = ports.grafana; extraOptions.recommendedProxySettings = true; };
+ "grafana.local" = { inherit host; port = ports.grafana; extraNginxOptions.recommendedProxySettings = true; };
};
};
- networking = {
- hostName = "bacchus";
- firewall.enable = true;
+ # Host mappings defined by service-router
+ services.bacchus-dns = {
+ enable = true;
+ port = 53;
+ openFirewall = true;
+ fallback = [ "1.1.1.1" "8.8.8.8" ];
};
}
diff --git a/modules/users.nix b/modules/users/default.nix
index 223a2f8..7969496 100644
--- a/modules/users.nix
+++ b/modules/users/default.nix
@@ -1,6 +1,6 @@
{ pkgs, lib, ... }:
let
- settings = import ../settings.nix { inherit lib; };
+ settings = import ../../settings.nix { inherit lib; };
in
{
users.users.root.password = settings.passwords.root;
diff --git a/modules/dashboard/bacchus-dashboard.service.nix b/services/bacchus-dashboard/bacchus-dashboard.service.nix
index 8b0fcb9..8b0fcb9 100644
--- a/modules/dashboard/bacchus-dashboard.service.nix
+++ b/services/bacchus-dashboard/bacchus-dashboard.service.nix
diff --git a/modules/dashboard/dashboard-template.nix b/services/bacchus-dashboard/dashboard-template.nix
index 9883a1d..9883a1d 100644
--- a/modules/dashboard/dashboard-template.nix
+++ b/services/bacchus-dashboard/dashboard-template.nix
diff --git a/services/bacchus-dns.service.nix b/services/bacchus-dns.service.nix
new file mode 100644
index 0000000..d6f45f9
--- /dev/null
+++ b/services/bacchus-dns.service.nix
@@ -0,0 +1,39 @@
+{ lib, config, ... }:
+with lib;
+let
+ cfg = config.services.bacchus-dns;
+in
+{
+ options.services.bacchus-dns = {
+ enable = mkEnableOption "dns server mappings";
+ port = mkOption { type = types.int; default = 53; };
+ openFirewall = mkEnableOption "open required ports in firewall";
+ ttl = mkOption { type = types.int; default = 3600; };
+ fallback = mkOption { type = types.listOf types.str; default = [ "1.1.1.1" ]; };
+ hosts = mkOption { type = types.attrsOf types.str; default = {}; };
+ };
+
+ config = {
+ services.coredns = mkIf cfg.enable {
+ enable = true;
+ extraArgs = [ "-dns.port=${toString cfg.port}" ];
+ config = ''
+ . {
+ hosts {
+ ${concatStringsSep "\n" (
+ mapAttrsToList (domain: target: "${target} ${domain}") cfg.hosts)}
+ fallthrough
+ }
+ forward . ${concatStringsSep " " cfg.fallback}
+ cache ${toString cfg.ttl}
+ errors
+ }
+ '';
+ };
+
+ networking.firewall = mkIf cfg.openFirewall {
+ allowedTCPPorts = [ cfg.port ];
+ allowedUDPPorts = [ cfg.port ];
+ };
+ };
+}
diff --git a/modules/network/service-router.service.nix b/services/service-router.service.nix
index 14fc1b2..e52280f 100644
--- a/modules/network/service-router.service.nix
+++ b/services/service-router.service.nix
@@ -1,17 +1,12 @@
-{ config, lib, dns, ... }:
+{ config, lib, ... }:
with lib;
let
cfg = config.services.service-router;
- domainAZone = domain: record: {
- A = [ record ];
- SOA = {
- nameServer = "ns.${domain}.";
- adminEmail = "dont@email.me";
- serial = 2019030800;
- };
- NS = [ "ns.${domain}." ];
- };
in {
+ imports = [
+ ./bacchus-dns.service.nix
+ ];
+
options.services.service-router = {
enable = mkEnableOption "enable router";
routes = mkOption {
@@ -20,8 +15,7 @@ in {
host = mkOption { type = types.str; default = "127.0.0.1"; };
protocol = mkOption { type = types.str; default = "http"; };
basePath = mkOption { type = types.str; default = ""; };
- nginx = mkOption { type = types.attrs; default = {}; };
- extraOptions = mkOption { type = types.attrs; default = {}; };
+ extraNginxOptions = mkOption { type = types.attrs; default = {}; };
}; });
default = {};
};
@@ -33,27 +27,21 @@ in {
recommendedOptimisation = true;
virtualHosts = lib.mapAttrs (_: val:
let
- opts = if hasAttr "extraOptions" val then val.extraOptions else {};
+ opts = if hasAttr "extraNginxOptions" val then val.extraNginxOptions else {};
in {
- locations."/" = if val.nginx == {} then {
+ locations."/" = {
proxyPass =
"${val.protocol}://${val.host}:${toString val.port}${val.basePath}";
proxyWebsockets = true;
- } // opts else val.nginx;
+ } // opts;
}
) cfg.routes;
};
- services.nsd = {
+ # Hostname mapping
+ services.bacchus-dns = {
enable = true;
- interfaces = [ "0.0.0.0" ];
- zones = lib.mapAttrs (domain: val: {
- data = dns.lib.toString domain (domainAZone domain val.host);
- }) cfg.routes;
+ hosts = mapAttrs (_: val: val.host) cfg.routes;
};
- networking.firewall.allowedTCPPorts = [ 53 ];
- networking.firewall.allowedUDPPorts = [ 53 ];
-
- networking.hosts."127.0.0.1" = lib.mapAttrsToList (name: _: name) cfg.routes;
};
}