Archived
Check NixOS configurations / eval-hosts (pull_request) Successful in 17m29s
The previous commit's networking.search fix was wrong. Confirmed live
on lxc-docker (vmid 105) after redeploying with it: `resolvectl query
server.sweet.home` started failing again, even though
`resolvectl query --interface=eth0 server.sweet.home` still resolved
correctly to the right IP via the LAN's real DNS server. The debug log
showed why -- adding a *global* search domain via networking.search
gave systemd-resolved a domain-matched but server-less "global" scope,
which it now prioritizes over eth0's correctly-configured scope for
every "*.sweet.home" query, silently sending them to public fallback
DNS (1.1.1.1 et al) instead, which of course returns NXDOMAIN for an
internal-only name. Bare single-label names (e.g. "server") were never
going to work either way -- systemd-resolved only ever tries LLMNR for
those, never DNS search-suffixing, regardless of configuration.
Reverts the networking.search addition and instead has
modules/docker/mount-data.nix build each NFS device string from
"${vars.nfsServerHost}.${vars.homeDomain}" (a plain FQDN, no dependency
on search-domain behavior at all) -- the same pattern
modules/raspi/mount-data.nix already uses for the Raspberry Pi's share
and for the identical reason.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T48qgH3VTvs8wvwj44FEbE
105 lines
2.9 KiB
Nix
105 lines
2.9 KiB
Nix
{ config, lib, pkgs, vars, ... }:
|
||
|
||
{
|
||
imports =
|
||
[
|
||
# Include the results of the hardware scan.
|
||
# ./hardware-configuration.nix
|
||
./set-locale.nix
|
||
];
|
||
# Use the GRUB 2 boot loader.
|
||
# boot.loader.grub.enable = true;
|
||
#boot.loader.grub.device = "/dev/sda"; # or "nodev" for efi only
|
||
|
||
networking.networkmanager.enable = true; # Easiest to use and most distros use this by default.
|
||
|
||
# Recommended over the true default (bypasses ZFS's own import safeguards)
|
||
# per the option's own docs; matches hosts/docker/host.nix and
|
||
# modules/services/zfs/enable-service.nix, which already set this
|
||
# explicitly. Harmless no-op on hosts that don't use ZFS at all.
|
||
boot.zfs.forceImportRoot = false;
|
||
|
||
# Set your time zone.
|
||
time.timeZone = vars.timeZone;
|
||
|
||
# Enable QEMU agent
|
||
services.qemuGuest.enable = true;
|
||
|
||
# Enable docker-compose
|
||
environment.systemPackages = with pkgs; [
|
||
vim
|
||
btop
|
||
git
|
||
gcr
|
||
];
|
||
|
||
# Secrets shared by every host, decrypted at activation via each host's
|
||
# existing SSH host key (sops-nix derives the age key from
|
||
# /etc/ssh/ssh_host_ed25519_key automatically — see modules/common/README
|
||
# or docs/ for the sops workflow). hashedPassword/hashedPasswordFile need
|
||
# neededForUsers so they're available before the normal secret-activation
|
||
# step, since user creation happens very early in boot.
|
||
sops = {
|
||
defaultSopsFile = ../../secrets/common.yaml;
|
||
|
||
secrets = {
|
||
"root-hashedPassword".neededForUsers = true;
|
||
"nixos-hashedPassword".neededForUsers = true;
|
||
"nix-github-token" = { };
|
||
};
|
||
|
||
# nix.conf doesn't support a *File-style option for access-tokens, so the
|
||
# token is rendered into a runtime-only file (never touches the Nix store)
|
||
# and pulled in via nix.conf's native !include directive.
|
||
templates."nix-github-token.conf".content = ''
|
||
access-tokens = github.com=${config.sops.placeholder."nix-github-token"}
|
||
'';
|
||
};
|
||
|
||
nix.extraOptions = ''
|
||
!include ${config.sops.templates."nix-github-token.conf".path}
|
||
'';
|
||
|
||
#Set root password
|
||
users.users.root = {
|
||
hashedPasswordFile = config.sops.secrets."root-hashedPassword".path;
|
||
};
|
||
|
||
# Define a user account. Don't forget to set a password with ‘passwd’.
|
||
users.users.${vars.primaryUser} = {
|
||
isNormalUser = true;
|
||
extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user.
|
||
packages = with pkgs; [
|
||
tree
|
||
];
|
||
hashedPasswordFile = config.sops.secrets."nixos-hashedPassword".path;
|
||
openssh.authorizedKeys.keys = [
|
||
vars.adminSshKey
|
||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICMJhrfFayLBG+gWtO6oAvgambw5nWWgztiTFEaaaVRH debian@surface"
|
||
];
|
||
};
|
||
|
||
|
||
# Enable the OpenSSH daemon.
|
||
services.openssh.enable = true;
|
||
|
||
#Enable flakes
|
||
|
||
nix.settings = {
|
||
experimental-features = [ "nix-command" "flakes" ];
|
||
auto-optimise-store = true;
|
||
};
|
||
|
||
|
||
programs.git = {
|
||
enable = true;
|
||
package = pkgs.git;
|
||
config = {
|
||
credential.helper = "store";
|
||
};
|
||
};
|
||
|
||
|
||
|
||
}
|