From e8b59f873b5600178d78b6c8503e8a7328b79d08 Mon Sep 17 00:00:00 2001 From: k3t Date: Thu, 12 Mar 2026 05:15:14 -0600 Subject: [PATCH] *actually* upload nixcloud configs --- hosts/nixcloud/configuration.nix | 73 ++++++++++ hosts/nixcloud/frontendfriendly.d/README.md | 1 + .../frontendfriendly.d/anonoverflow.nix | 127 ++++++++++++++++++ hosts/nixcloud/frontendfriendly.d/dumb.nix | 29 ++++ hosts/nixcloud/frontendfriendly.d/global.nix | 30 +++++ hosts/nixcloud/frontendfriendly.d/redlib.nix | 29 ++++ hosts/nixcloud/frontendfriendly.d/rimgo.nix | 31 +++++ hosts/nixcloud/hardware-configuration.nix | 37 +++++ hosts/nixcloud/services.d/caddy.nix | 14 ++ hosts/nixcloud/services.d/minecraft.nix | 41 ++++++ hosts/nixcloud/services.d/vaultwarden.nix | 38 ++++++ modules/vps-aarch64-common.nix | 21 +++ 12 files changed, 471 insertions(+) create mode 100644 hosts/nixcloud/configuration.nix create mode 100644 hosts/nixcloud/frontendfriendly.d/README.md create mode 100644 hosts/nixcloud/frontendfriendly.d/anonoverflow.nix create mode 100644 hosts/nixcloud/frontendfriendly.d/dumb.nix create mode 100644 hosts/nixcloud/frontendfriendly.d/global.nix create mode 100644 hosts/nixcloud/frontendfriendly.d/redlib.nix create mode 100644 hosts/nixcloud/frontendfriendly.d/rimgo.nix create mode 100644 hosts/nixcloud/hardware-configuration.nix create mode 100644 hosts/nixcloud/services.d/caddy.nix create mode 100644 hosts/nixcloud/services.d/minecraft.nix create mode 100644 hosts/nixcloud/services.d/vaultwarden.nix create mode 100755 modules/vps-aarch64-common.nix diff --git a/hosts/nixcloud/configuration.nix b/hosts/nixcloud/configuration.nix new file mode 100644 index 0000000..53dec04 --- /dev/null +++ b/hosts/nixcloud/configuration.nix @@ -0,0 +1,73 @@ +# Edit this configuration file to define what should be installed on +# your system. Help is available in the configuration.nix(5) man page, on +# https://search.nixos.org/options and in the NixOS manual (`nixos-help`). + +{ config, lib, pkgs, inputs, ... }: + +{ + imports = + (lib.filesystem.listFilesRecursive ./services.d) + ++ [ # Include the results of the hardware scan. + ./hardware-configuration.nix + ]; + + networking.hostName = "nixcloud"; # Define your hostname. + + + # Define a user account. Don't forget to set a password with ‘passwd’. + users.users = { + steward = { + isNormalUser = true; + extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user. + packages = with pkgs; [ + btop htop + nano + ]; + }; + kuro = { + isNormalUser = true; + extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user. + packages = with pkgs; [ + btop htop + nano + ]; + }; + }; + + # List packages installed in system profile. + # You can use https://search.nixos.org/ to find more packages (and options). + #environment.systemPackages = with pkgs; [ + # wget + #]; + + + # Open ports in the firewall. + networking.firewall.allowedTCPPorts = [ 80 443 25565 4433 9971 ]; + networking.firewall.allowedUDPPorts = [ 24454 4433 9971 ]; + + # Copy the NixOS configuration file and link it from the resulting system + # (/run/current-system/configuration.nix). This is useful in case you + # accidentally delete configuration.nix. + # system.copySystemConfiguration = true; + + # This option defines the first version of NixOS you have installed on this particular machine, + # and is used to maintain compatibility with application data (e.g. databases) created on older NixOS versions. + # + # Most users should NEVER change this value after the initial install, for any reason, + # even if you've upgraded your system to a new NixOS release. + # + # This value does NOT affect the Nixpkgs version your packages and OS are pulled from, + # so changing it will NOT upgrade your system - see https://nixos.org/manual/nixos/stable/#sec-upgrading for how + # to actually do that. + # + # This value being lower than the current NixOS release does NOT mean your system is + # out of date, out of support, or vulnerable. + # + # Do NOT change this value unless you have manually inspected all the changes it would make to your configuration, + # and migrated your data accordingly. + # + # For more information, see `man configuration.nix` or https://nixos.org/manual/nixos/stable/options#opt-system.stateVersion . + system.stateVersion = "25.05"; # Did you read the comment? + +} + diff --git a/hosts/nixcloud/frontendfriendly.d/README.md b/hosts/nixcloud/frontendfriendly.d/README.md new file mode 100644 index 0000000..0ebe18e --- /dev/null +++ b/hosts/nixcloud/frontendfriendly.d/README.md @@ -0,0 +1 @@ +this was the old configs for FrontendFriendly, a project of Team SDS, which i have since left. \ No newline at end of file diff --git a/hosts/nixcloud/frontendfriendly.d/anonoverflow.nix b/hosts/nixcloud/frontendfriendly.d/anonoverflow.nix new file mode 100644 index 0000000..075aad5 --- /dev/null +++ b/hosts/nixcloud/frontendfriendly.d/anonoverflow.nix @@ -0,0 +1,127 @@ +{ config, pkgs, lib, ... }: + +let + domain = "frontendfriendly.xyz"; + host = "stackoverflow.${domain}"; + upstreamPort = 7101; + + # 1) Fetch source from GitHub + anonymousOverflowSrc = pkgs.fetchFromGitHub { + owner = "httpjamesm"; + repo = "AnonymousOverflow"; + rev = "v1.13.0"; # pin a release tag + # TODO: replace with real hash after first build + sha256 = "sha256-hvcOJctvNswEws+cCoeGQSvFzZvnThhKk3fJ7TnNulY="; + }; + + # 2) Build the Go binary + anonymousOverflowPkg = pkgs.buildGoModule { + pname = "anonymousoverflow"; + version = "1.13.0"; + + src = anonymousOverflowSrc; + + # code is at repo root + subPackages = [ "." ]; + + # TODO: replace with real vendor hash after first build + vendorHash = "sha256-P3kUGFJhj/pTNeVTwtg4IqhoHBH9rROfkr+ZsrUtmdo="; + }; +in +{ + containers.anonymousoverflow = { + autoStart = true; + + # Simple veth connection between host and container + privateNetwork = true; + hostAddress = "10.250.0.1"; + localAddress = "10.250.0.2"; + + # Rootfs is generated from this NixOS config: + config = { config, pkgs, ... }: + + let + # 1) Fetch AnonymousOverflow source + anonymousOverflowSrc = pkgs.fetchFromGitHub { + owner = "httpjamesm"; + repo = "AnonymousOverflow"; + # Pin some tag or commit + rev = "v1.13.0"; + # TODO: replace with real hash after first build + sha256 = "sha256-hvcOJctvNswEws+cCoeGQSvFzZvnThhKk3fJ7TnNulY="; + }; + + # 2) Build the Go binary + anonymousOverflowPkg = pkgs.buildGoModule { + pname = "anonymousoverflow"; + version = "1.13.0"; + + src = anonymousOverflowSrc; + + # repo root + subPackages = [ "." ]; + + # TODO: replace with real vendor hash after first build + vendorHash = "sha256-P3kUGFJhj/pTNeVTwtg4IqhoHBH9rROfkr+ZsrUtmdo="; + }; + in + { + # Set this to match your host’s stateVersion + system.stateVersion = "24.11"; + + # Optional but nice: container firewall allowing port 80 + networking.firewall.allowedTCPPorts = [ 80 ]; + + systemd.services.anonymousoverflow = { + description = "AnonymousOverflow StackOverflow frontend (container)"; + wantedBy = [ "multi-user.target" ]; + after = [ "network-online.target" ]; + wants = [ "network-online.target" ]; + + serviceConfig = { + # Runs as root in container; that’s fine here, it needs port 80 + ExecStart = "${anonymousOverflowPkg}/bin/anonymousoverflow"; + + Restart = "always"; + RestartSec = 3; + }; + }; + + # If AO needs env vars / config, set them here: + # systemd.services.anonymousoverflow.serviceConfig.Environment = [ + # "PORT=80" + # "BIND_ADDR=0.0.0.0" + # ]; + }; + }; + + ################################# + ## Anubis in front of it ## + ################################# + + services.anubis.instances.anonymousoverflow = { + enable = true; + + settings = { + # Must use this prefix form: /run/anubis/anubis-/... + BIND = "/run/anubis/anubis-anonymousoverflow/anubis.sock"; + METRICS_BIND = "/run/anubis/anubis-anonymousoverflow/metrics.sock"; + + # If you keep the default :8080: + # TARGET = "http://127.0.0.1:8080"; + + # If you configure the app to listen on 127.0.0.1:${upstreamPort}: + TARGET = "http://10.250.0.2:${toString upstreamPort}"; + + SERVE_ROBOTS_TXT = true; + }; + }; + + ################################# + ## Caddy vhost ## + ################################# + + services.caddy.virtualHosts.${host}.extraConfig = '' + reverse_proxy unix//run/anubis/anubis-anonymousoverflow/anubis.sock + ''; +} diff --git a/hosts/nixcloud/frontendfriendly.d/dumb.nix b/hosts/nixcloud/frontendfriendly.d/dumb.nix new file mode 100644 index 0000000..b1b6bce --- /dev/null +++ b/hosts/nixcloud/frontendfriendly.d/dumb.nix @@ -0,0 +1,29 @@ +{ config, pkgs, lib, ... }: + +let + domain = "frontendfriendly.xyz"; + host = "dumb.${domain}"; + upstreamPort = 5555; +in +{ + virtualisation.oci-containers.containers.dumb = { + image = "ghcr.io/rramiachraf/dumb:latest"; + autoStart = true; + ports = [ "127.0.0.1:${toString upstreamPort}:5555" ]; + # environment = { ... } if Dumb needs configuration + }; + + services.anubis.instances.dumb = { + enable = true; + settings = { + BIND = "/run/anubis/anubis-dumb/anubis.sock"; + METRICS_BIND = "/run/anubis/anubis-dumb/metrics.sock"; + TARGET = "http://127.0.0.1:${toString upstreamPort}"; + SERVE_ROBOTS_TXT = true; + }; + }; + + services.caddy.virtualHosts.${host}.extraConfig = '' + reverse_proxy unix//run/anubis/anubis-dumb/anubis.sock + ''; +} diff --git a/hosts/nixcloud/frontendfriendly.d/global.nix b/hosts/nixcloud/frontendfriendly.d/global.nix new file mode 100644 index 0000000..2d5cc0d --- /dev/null +++ b/hosts/nixcloud/frontendfriendly.d/global.nix @@ -0,0 +1,30 @@ +{ config, pkgs, lib, ... }: + +{ + users.users.caddy.extraGroups = [ config.users.groups.anubis.name ]; + + # hacky fix since ssl was broken + + services.caddy.virtualHosts."frontendfriendly.xyz".extraConfig = '' + root /var/www/frontendfriendly.xyz + file_server + handle /webhook/828e8c10-af83-4a9b-a7ee-1b687ba12adc { + reverse_proxy https://n8n.teamsds.net { + transport http { + tls_insecure_skip_verify + } + header_up Host n8n.teamsds.net + } + } + handle /webhook-test/828e8c10-af83-4a9b-a7ee-1b687ba12adc { + reverse_proxy https://n8n.teamsds.net { + transport http { + tls_insecure_skip_verify + } + header_up Host n8n.teamsds.net + } + } + + ''; + +} diff --git a/hosts/nixcloud/frontendfriendly.d/redlib.nix b/hosts/nixcloud/frontendfriendly.d/redlib.nix new file mode 100644 index 0000000..ff734f3 --- /dev/null +++ b/hosts/nixcloud/frontendfriendly.d/redlib.nix @@ -0,0 +1,29 @@ +{ config, pkgs, lib, ... }: + +let + domain = "frontendfriendly.xyz"; + host = "redlib.${domain}"; + upstreamPort = 7105; +in +{ + services.redlib = { + enable = true; + address = "127.0.0.1"; + port = upstreamPort; + # extraSettings = { ... }; # if you want instance-specific options + }; + + services.anubis.instances.redlib = { + enable = true; + settings = { + BIND = "/run/anubis/anubis-redlib/anubis.sock"; + METRICS_BIND = "/run/anubis/anubis-redlib/metrics.sock"; + TARGET = "http://127.0.0.1:${toString upstreamPort}"; + SERVE_ROBOTS_TXT = true; + }; + }; + + services.caddy.virtualHosts.${host}.extraConfig = '' + reverse_proxy unix//run/anubis/anubis-redlib/anubis.sock + ''; +} diff --git a/hosts/nixcloud/frontendfriendly.d/rimgo.nix b/hosts/nixcloud/frontendfriendly.d/rimgo.nix new file mode 100644 index 0000000..2a806b0 --- /dev/null +++ b/hosts/nixcloud/frontendfriendly.d/rimgo.nix @@ -0,0 +1,31 @@ +{ config, pkgs, lib, ... }: + +let + domain = "frontendfriendly.xyz"; + host = "rimgo.${domain}"; + upstreamPort = 7104; +in +{ + services.rimgo = { + enable = true; + # Rimgo uses a port in its settings; set it to local only + settings = { + ADDRESS = "127.0.0.1"; + PORT = upstreamPort; + }; + }; + + services.anubis.instances.rimgo = { + enable = true; + settings = { + BIND = "/run/anubis/anubis-rimgo/anubis.sock"; + METRICS_BIND = "/run/anubis/anubis-rimgo/metrics.sock"; + TARGET = "http://127.0.0.1:${toString upstreamPort}"; + SERVE_ROBOTS_TXT = true; + }; + }; + + services.caddy.virtualHosts.${host}.extraConfig = '' + reverse_proxy unix//run/anubis/anubis-rimgo/anubis.sock + ''; +} diff --git a/hosts/nixcloud/hardware-configuration.nix b/hosts/nixcloud/hardware-configuration.nix new file mode 100644 index 0000000..702c256 --- /dev/null +++ b/hosts/nixcloud/hardware-configuration.nix @@ -0,0 +1,37 @@ +# Do not modify this file! It was generated by ‘nixos-generate-config’ +# and may be overwritten by future invocations. Please make changes +# to /etc/nixos/configuration.nix instead. +{ config, lib, pkgs, modulesPath, ... }: + +{ + imports = + [ (modulesPath + "/profiles/qemu-guest.nix") + ]; + + boot.initrd.availableKernelModules = [ "xhci_pci" "virtio_pci" "virtio_scsi" "usbhid" "sr_mod" ]; + boot.initrd.kernelModules = [ ]; + boot.kernelModules = [ ]; + boot.extraModulePackages = [ ]; + + fileSystems."/" = + { device = "/dev/disk/by-uuid/fa7b07d8-0648-4009-a26c-a3565ef06ba5"; + fsType = "btrfs"; + }; + + fileSystems."/boot" = + { device = "/dev/disk/by-uuid/ACF4-F854"; + fsType = "vfat"; + options = [ "fmask=0022" "dmask=0022" ]; + }; + + swapDevices = [ ]; + + # Enables DHCP on each ethernet and wireless interface. In case of scripted networking + # (the default) this is the recommended approach. When using systemd-networkd it's + # still possible to use this option, but it's recommended to use it in conjunction + # with explicit per-interface declarations with `networking.interfaces..useDHCP`. + networking.useDHCP = lib.mkDefault true; + # networking.interfaces.enp7s0.useDHCP = lib.mkDefault true; + + nixpkgs.hostPlatform = lib.mkDefault "aarch64-linux"; +} diff --git a/hosts/nixcloud/services.d/caddy.nix b/hosts/nixcloud/services.d/caddy.nix new file mode 100644 index 0000000..248403f --- /dev/null +++ b/hosts/nixcloud/services.d/caddy.nix @@ -0,0 +1,14 @@ +{ config, lib, pkgs, ... }: + + +{ + services.caddy = { + enable = true; + virtualHosts."k3t.dev".extraConfig = '' + encode zstd gzip + root /var/www/k3t.dev/ + file_server browse + ''; + }; + +} diff --git a/hosts/nixcloud/services.d/minecraft.nix b/hosts/nixcloud/services.d/minecraft.nix new file mode 100644 index 0000000..3cbcd3c --- /dev/null +++ b/hosts/nixcloud/services.d/minecraft.nix @@ -0,0 +1,41 @@ +{ config, pkgs, ... }: + +{ + virtualisation.podman = { + enable = true; + autoPrune.enable = true; + dockerCompat = true; # optional; lets you use `docker` CLI + }; + + systemd.services.minecraft-container = { + description = "Minecraft Server Container (GraalVM JVM 21)"; + after = [ "network-online.target" ]; + wants = [ "network-online.target" ]; + serviceConfig = { + ExecStart = '' + ${pkgs.podman}/bin/podman run \ + --rm \ + --name minecraft-server \ + -v /var/lib/minecraft:/data \ + -p 25565:25565 \ + -p 24454:24454/udp \ + ghcr.io/graalvm/graalvm-community:25 \ + /data/run.sh + ''; + ExecStop = "${pkgs.podman}/bin/podman stop minecraft-server"; + Restart = "always"; + RestartSec = "10s"; + }; + + # Ensure the directory exists + preStart = '' + mkdir -p /var/lib/minecraft + ''; + wantedBy = [ "multi-user.target" ]; + }; + + # Give Podman permission to access persistent storage + systemd.tmpfiles.rules = [ + "d /var/lib/minecraft 0755 root root" + ]; +} diff --git a/hosts/nixcloud/services.d/vaultwarden.nix b/hosts/nixcloud/services.d/vaultwarden.nix new file mode 100644 index 0000000..d2e5092 --- /dev/null +++ b/hosts/nixcloud/services.d/vaultwarden.nix @@ -0,0 +1,38 @@ +{ config, lib, pkgs, ... }: + +{ + services.vaultwarden = { + enable = true; + backupDir = "/var/local/vaultwarden/backup"; + # in order to avoid having ADMIN_TOKEN in the nix store it can be also set with the help of an environment file + # be aware that this file must be created by hand (or via secrets management like sops) + environmentFile = "/var/lib/vaultwarden/vaultwarden.env"; + config = { + # Refer to https://github.com/dani-garcia/vaultwarden/blob/main/.env.template + DOMAIN = "https://bitwarden.k3t.dev"; + SIGNUPS_ALLOWED = true; + + ROCKET_ADDRESS = "127.0.0.1"; + ROCKET_PORT = 8222; + ROCKET_LOG = "critical"; + + # This example assumes a mailserver running on localhost, + # thus without transport encryption. + # If you use an external mail server, follow: + # https://github.com/dani-garcia/vaultwarden/wiki/SMTP-configuration + #SMTP_HOST = "127.0.0.1"; + #SMTP_PORT = 25; + #SMTP_SSL = false; + + #SMTP_FROM = "admin@bitwarden.example.com"; + #SMTP_FROM_NAME = "example.com Bitwarden server"; + }; + }; + services.caddy.virtualHosts."bitwarden.k3t.dev".extraConfig = '' + encode zstd gzip + + reverse_proxy :${toString config.services.vaultwarden.config.ROCKET_PORT} { + header_up X-Real-IP {remote_host} + } + ''; +} diff --git a/modules/vps-aarch64-common.nix b/modules/vps-aarch64-common.nix new file mode 100755 index 0000000..371c25a --- /dev/null +++ b/modules/vps-aarch64-common.nix @@ -0,0 +1,21 @@ +{ pkgs, ... }: { + + boot.loader.systemd-boot.enable = true; + boot.loader.efi.canTouchEfiVariables = true; + boot.binfmt.emulatedSystems = ["x86_64-linux" "i386-linux"]; + + #environment.systemPackages = with pkgs; [ + #]; + + services.fail2ban.enable = true; + services.openssh = { + enable = true; + settings.PasswordAuthentication = true; + }; + + system.autoUpgrade = { + operation = "boot"; + allowReboot = true; + rebootWindow = { lower = "02:00"; upper = "05:00"; }; + }; +}