Archived
remove commented lines
This commit is contained in:
@@ -4,16 +4,11 @@
|
||||
|
||||
{ config, lib, pkgs, inputs,... }:
|
||||
{
|
||||
# Note this might jump back and forth as kernels are added or removed.
|
||||
# boot.kernelPackages = config.boot.zfs.package.latestCompatibleLinuxPackages;
|
||||
#boot.kernelModules = [ "zfs" ];
|
||||
imports =
|
||||
imports =
|
||||
[ # Include the results of the hardware scan.
|
||||
../../common/configuration.nix
|
||||
../../modules/nix-cache/client.nix
|
||||
../../modules/remote-builder-client.nix
|
||||
# ../../modules/nix/tailscale-exit-node.nix
|
||||
# ../../modules/nix/enable-ip-forwarding.nix
|
||||
../../modules/beszel/enable-agent.nix
|
||||
../../modules/services/enable-rpcbind.nix
|
||||
../../modules/services/zfs/enable-service.nix
|
||||
@@ -23,12 +18,7 @@
|
||||
|
||||
networking.hostName = "server"; # Define your hostname.
|
||||
networking.hostId = "6689f93e";
|
||||
# Pick only one of the below networking options.
|
||||
# networking.wireless.enable = true; # Enables wireless support via wpa_supplicant.
|
||||
# boot.supportedFilesystems = [ "zfs" ];
|
||||
# boot.zfs.forceImportRoot = false;
|
||||
# boot.zfs.package = pkgs.zfs_unstable;
|
||||
|
||||
|
||||
services.beszel.agent.environment = {
|
||||
#DOCKER_HOST = "tcp://docker-socket-proxy:2375";
|
||||
#HUB_URL = "http://docker.sweet.home:8090";
|
||||
@@ -36,30 +26,6 @@ KEY = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFPR9kwtC4TAeTRu46A7+opZsYpxqkRJ+x/Zy
|
||||
TOKEN = "48e71783-35df-4ea0-a8c2-05bc5e020d2e";
|
||||
};
|
||||
|
||||
#Add sym links to data on users home folder
|
||||
#system.userActivationScripts.createDockerSymlink.text = ''
|
||||
# ln -sf /srv/scripts /home/nixos/scripts
|
||||
#'';
|
||||
#system.userActivationScripts.createSetupSymlink.text = ''
|
||||
# ln -sf /mnt/docker-persistent-data/setup /home/nixos/setup
|
||||
#'';
|
||||
# boot.postBootCommands = ''
|
||||
# echo "=== STARTING ZPOOL IMPORT ==="
|
||||
# ${pkgs.zfs_unstable}/bin/zpool import -a -N -d /dev/disk/by-path
|
||||
# ${pkgs.zfs_unstable}/bin/zpool status
|
||||
# ${pkgs.zfs_unstable}/bin/zfs mount -a
|
||||
# ${pkgs.zfs_unstable}/bin/zfs list
|
||||
# echo "=== ZPOOL IMPORT COMPLETE ==="
|
||||
# '';
|
||||
# services.zfs = {
|
||||
# autoScrub.enable = true;
|
||||
# autoSnapshot.enable = true;
|
||||
# trim.enable = true;
|
||||
# };
|
||||
|
||||
# systemd.services.zfs-import-cache.enable = true;
|
||||
# systemd.services.zfs-mount.enable = true;
|
||||
# boot.zfs.devNodes = "/dev/disk/by-id";
|
||||
|
||||
systemd.services.nfs-server = {
|
||||
after = [ "zfs-mount.service" ];
|
||||
@@ -76,87 +42,6 @@ services.nfs.server = {
|
||||
'';
|
||||
};
|
||||
|
||||
# security.sudo = {
|
||||
# enable = true;
|
||||
# extraRules = [
|
||||
# {
|
||||
# users = [ "nixos" ];
|
||||
# commands = [
|
||||
# {
|
||||
# command = "/run/current-system/sw/bin/rsync";
|
||||
# options = [ "NOPASSWD" ];
|
||||
# }
|
||||
# ];
|
||||
# }
|
||||
# ];
|
||||
# };
|
||||
|
||||
|
||||
# systemd.services.backup = {
|
||||
# description = "Backup data";
|
||||
# wantedBy = [ "multi-user.target" ];
|
||||
|
||||
# serviceConfig = {
|
||||
# Type = "oneshot";
|
||||
# User = "root";
|
||||
# WorkingDirectory = "/home/nixos/scripts";
|
||||
# ExecStart = "${pkgs.bash}/bin/bash -e /srv/scripts/rsync.sh";
|
||||
# StandardOutput = "journal";
|
||||
# StandardError = "journal";
|
||||
# };
|
||||
#path = with pkgs; [ bash rsync openssh coreutils ];
|
||||
# };
|
||||
|
||||
|
||||
#systemd.timers.backup = {
|
||||
# description = "Daily backup";
|
||||
# wantedBy = [ "timers.target" ];
|
||||
# timerConfig = {
|
||||
# OnUnitActiveSec = "1d"; # Run every day after last run
|
||||
# Persistent = true; # Catch up if system was off
|
||||
# };
|
||||
#};
|
||||
|
||||
# networking.wireguard.enable = true;
|
||||
# networking.wireguard.interfaces.wg0 = {
|
||||
# ips = [ "10.100.0.254/24" ];
|
||||
# listenPort = 51820;
|
||||
# privateKeyFile = "/etc/wireguard/server.key";
|
||||
|
||||
# peers = [
|
||||
# {
|
||||
# publicKey = "cA30PTE/2gMbIhtAXaRPJkQeDc7/UWoA6eK3K+Xpsww=";
|
||||
# allowedIPs = [ "10.100.0.2/32" ];
|
||||
# }
|
||||
# ];
|
||||
# };
|
||||
|
||||
# Allow WireGuard UDP port in firewall
|
||||
# networking.firewall.allowedUDPPorts = [ 51820 ];
|
||||
|
||||
# Enable IPv4 forwarding
|
||||
# boot.kernel.sysctl = {
|
||||
# "net.ipv4.ip_forward" = 1;
|
||||
# };
|
||||
|
||||
# NAT: lets LAN devices reply to the Pi without needing routes on the LAN router
|
||||
# networking.nat = {
|
||||
# enable = true;
|
||||
# externalInterface = "enp0s18";
|
||||
# internalInterfaces = [ "wg0" ];
|
||||
# };
|
||||
#services.prometheus.exporters.node = {
|
||||
# enable = true;
|
||||
# openFirewall = true;
|
||||
#};
|
||||
|
||||
# services.openssh.settings.PermitRootLogin = "yes";
|
||||
# Open ports in the firewall.
|
||||
# networking.firewall.allowedTCPPorts = [ 2049 ];
|
||||
# networking.firewall.allowedUDPPorts = [ 111 2049 20048 ];
|
||||
# Or disable the firewall altogether.
|
||||
# networking.firewall.enable = false;
|
||||
|
||||
# Copy the NixOS configuration file and link it from the resulting system
|
||||
# (/run/current-system/configuration.nix). This is useful in case you
|
||||
# accidentally delete configuration.nix.
|
||||
|
||||
Reference in New Issue
Block a user