Merge branch 'server-setup'

This commit is contained in:
Bryan Ramos 2026-03-12 02:17:07 -04:00
commit c10f28c977
8 changed files with 162 additions and 45 deletions

View file

@ -61,6 +61,7 @@
server = nixpkgs.lib.nixosSystem { server = nixpkgs.lib.nixosSystem {
inherit system pkgs; inherit system pkgs;
modules = [ modules = [
disko.nixosModules.disko
./src/system/machines/server ./src/system/machines/server
home-manager.nixosModules.home-manager home-manager.nixosModules.home-manager
(import ./src/system/machines/server/modules/home-manager) (import ./src/system/machines/server/modules/home-manager)

View file

@ -1,26 +1,22 @@
{ config, lib, modulesPath, ... }: { config, lib, modulesPath, ... }:
{ {
imports = [ (modulesPath + "/installer/scan/not-detected.nix") ]; imports = [
(modulesPath + "/installer/scan/not-detected.nix")
./modules/disko
];
boot.initrd.availableKernelModules = [ "xhci_pci" "ehci_pci" "ahci" "usbhid" "sd_mod" "sr_mod" ]; boot = {
boot.initrd.kernelModules = [ "dm-snapshot" ]; initrd = {
boot.kernelModules = [ "kvm-intel" ]; availableKernelModules = [ "xhci_pci" "ehci_pci" "ahci" "usbhid" "sd_mod" "sr_mod" ];
boot.extraModulePackages = [ ]; kernelModules = [ ];
fileSystems = {
"/" = {
device = "/dev/disk/by-uuid/0fviSz-6z7Q-oH7Y-JOzH-nRxW-c029-2LxSqo";
fsType = "ext4";
};
"/boot" = {
device = "/dev/disk/by-uuid/3BAA-D9DC";
fsType = "vfat";
}; };
kernelModules = [ "kvm-intel" ];
extraModulePackages = [ ];
}; };
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
powerManagement.cpuFreqGovernor = lib.mkDefault "performance";
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware; hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
powerManagement.cpuFreqGovernor = lib.mkDefault "ondemand";
} }

View file

@ -0,0 +1,75 @@
{ lib, ... }:
{
disko.devices = {
disk = {
main = {
type = "disk";
device = "/dev/sda";
content = {
type = "gpt";
partitions = {
ESP = {
size = "512M";
type = "EF00";
content = {
type = "filesystem";
format = "vfat";
mountpoint = "/boot";
mountOptions = [ "umask=0077" ];
};
};
lvm = {
size = "100%";
content = {
type = "lvm_pv";
vg = "vg0";
};
};
};
};
};
};
lvm_vg = {
vg0 = {
type = "lvm_vg";
lvs = {
root = {
size = "200G";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/";
};
};
data = {
size = "1T";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/data";
};
};
bitcoin = {
size = "1T";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/var/lib/bitcoin";
};
};
frigate = {
size = "3T";
content = {
type = "filesystem";
format = "ext4";
mountpoint = "/var/lib/frigate";
};
};
# ~300GB left unallocated for future growth
};
};
};
};
}

View file

@ -8,7 +8,7 @@
programs.home-manager.enable = true; programs.home-manager.enable = true;
home.stateVersion = "23.11"; home.stateVersion = "25.11";
home.username = "${config.user.name}"; home.username = "${config.user.name}";
home.homeDirectory = "/home/${config.user.name}"; home.homeDirectory = "/home/${config.user.name}";
@ -17,6 +17,7 @@
user = { user = {
bash.enable = true; bash.enable = true;
git.enable = true; git.enable = true;
tmux.enable = true;
security = { security = {
gpg.enable = true; gpg.enable = true;

View file

@ -1,25 +1,28 @@
{ pkgs, lib, config, ... }: { pkgs, lib, config, ... }:
{ system.stateVersion = "23.11"; { system.stateVersion = "25.11";
imports = [ ../../modules ]; imports = [ ../../modules ];
modules = { # Modules disabled for base install
system = { # modules = {
nginx.enable = true; # system = {
forgejo.enable = true; # nginx.enable = true;
bitcoin = { # forgejo.enable = true;
enable = true; # bitcoin = {
electrum.enable = true; # enable = true;
}; # electrum.enable = true;
}; # };
}; # };
# };
users.users = { users.users = {
${config.user.name} = { ${config.user.name} = {
isNormalUser = true; isNormalUser = true;
extraGroups = config.user.groups; extraGroups = config.user.groups;
openssh.authorizedKeys.keys = [ "${config.user.keys.ssh.primary}" ]; openssh.authorizedKeys.keys = [
"${config.user.keys.ssh.desktop}"
];
}; };
}; };
@ -39,10 +42,9 @@
}; };
boot.loader = { boot.loader = {
timeout = null; timeout = 3;
grub = { grub = {
enable = true; enable = true;
useOSProber = true;
devices = [ "nodev" ]; devices = [ "nodev" ];
efiSupport = true; efiSupport = true;
configurationLimit = 5; configurationLimit = 5;
@ -58,11 +60,7 @@
wget wget
git git
vim vim
]; htop
fonts.packages = with pkgs; [
terminus_font
terminus-nerdfont
]; ];
security.sudo = { security.sudo = {
@ -87,27 +85,38 @@
i18n.defaultLocale = "en_US.UTF-8"; i18n.defaultLocale = "en_US.UTF-8";
console = { console.font = "Lat2-Terminus16";
font = "Lat2-Terminus16";
useXkbConfig = true;
};
networking = { networking = {
hostName = "server"; hostName = "server";
useDHCP = lib.mkDefault true; useDHCP = false;
networkmanager.enable = true; interfaces.eno1 = {
ipv4.addresses = [{
address = "192.168.0.154";
prefixLength = 24;
}];
};
defaultGateway = "192.168.0.1";
nameservers = [ "1.1.1.1" "8.8.8.8" ];
firewall = { firewall = {
enable = true; enable = true;
allowedTCPPorts = [ 22 80 443 ]; allowedTCPPorts = [ 22 ];
}; };
}; };
services.fail2ban = {
enable = true;
maxretry = 5;
bantime = "1h";
};
services.openssh = { services.openssh = {
enable = true; enable = true;
startWhenNeeded = true; startWhenNeeded = true;
settings = { settings = {
X11Forwarding = false; X11Forwarding = false;
PasswordAuthentication = false; PasswordAuthentication = false;
PermitRootLogin = "no";
}; };
}; };
} }

View file

@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOYXfu4Jc/HtdyhOfAdCXYzhqCubIq3Bz6Kl9NDUov76 bryan@desktop

View file

@ -29,7 +29,7 @@ case $- in
fi fi
''} ''}
${optionalString tmux.enable '' ${optionalString tmux.enable ''
if [ -z "$DISPLAY" ] && [ -z "$TMUX" ]; then if [ -z "$DISPLAY" ] && [ -z "$TMUX" ] && [ -z "$SSH_TTY" ]; then
exec tmux exec tmux
fi fi
''} ''}

View file

@ -1,10 +1,44 @@
'' ''
bind -n M-C source-file ~/.config/tmux/tmux.conf bind -n M-C source-file ~/.config/tmux/tmux.conf
# Navigation (matches hyprland Alt+hjkl)
bind-key -n M-h select-pane -L bind-key -n M-h select-pane -L
bind-key -n M-j select-pane -D bind-key -n M-j select-pane -D
bind-key -n M-k select-pane -U bind-key -n M-k select-pane -U
bind-key -n M-l select-pane -R bind-key -n M-l select-pane -R
# Move/swap pane (matches hyprland Alt+Shift+hjkl)
bind-key -n M-H swap-pane -s '{left-of}'
bind-key -n M-J swap-pane -s '{down-of}'
bind-key -n M-K swap-pane -s '{up-of}'
bind-key -n M-L swap-pane -s '{right-of}'
# Actions
bind-key -n M-q kill-pane bind-key -n M-q kill-pane
bind-key -n M-Return split-window -c "#{pane_current_path}"
bind-key -n M-f resize-pane -Z
# Windows (like workspaces)
bind-key -n M-1 select-window -t 1
bind-key -n M-2 select-window -t 2
bind-key -n M-3 select-window -t 3
bind-key -n M-4 select-window -t 4
bind-key -n M-5 select-window -t 5
bind-key -n M-6 select-window -t 6
bind-key -n M-7 select-window -t 7
bind-key -n M-8 select-window -t 8
bind-key -n M-9 select-window -t 9
bind-key -n M-0 select-window -t 10
# Move pane to window (like move to workspace)
bind-key -n M-! join-pane -t :1
bind-key -n M-@ join-pane -t :2
bind-key -n M-'#' join-pane -t :3
bind-key -n M-'$' join-pane -t :4
bind-key -n M-% join-pane -t :5
bind-key -n M-^ join-pane -t :6
bind-key -n M-& join-pane -t :7
bind-key -n M-* join-pane -t :8
bind-key -n M-( join-pane -t :9
bind-key -n M-) join-pane -t :10
'' ''