5116faf0d3
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/ X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail upstream copies via header_down on mail.severijnse.eu - tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync _25/_465/_993, fail-safe placeholders; coredns zone updated - pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint, deadnix); CI pre-commit job over x86_64 + aarch64 matrix - gitea: enable Gitea Actions + self-hosted runner (native:host, aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook - fix statix warnings (merge repeated systemd/database/configFile keys) + disable empty_pattern via statix.toml (nixpkgs standard) - Clean up unused lambda patterns across 38 .nix files via deadnix - Format whole repo with alejandra (27 files) - Remove .github/workflows/ci.yml (Gitea shadows .github; runner labels differ) - Fix CI nix-not-found: export /run/current-system/sw/bin in PATH - Trim aarch64 from pre-commit matrix (no QEMU binfmt deployed yet)
69 lines
1.8 KiB
Nix
69 lines
1.8 KiB
Nix
{
|
|
self,
|
|
inputs,
|
|
...
|
|
}: let
|
|
# shorten paths
|
|
inherit (inputs.nixpkgs.lib) nixosSystem;
|
|
# Server uses its own pinned 24.05 nixpkgs (kept isolated from the laptop's unstable)
|
|
nixosSystem24 = inputs.nixos-24-05.lib.nixosSystem;
|
|
unstablePkgs = import inputs.nixpkgs-unstable {system = "x86_64-linux";};
|
|
mod = "${self}/system";
|
|
home = "${self}/home";
|
|
|
|
# get the basic config to build on top of
|
|
inherit (import "${self}/system") tty desktop laptop;
|
|
|
|
# get these into the module system
|
|
specialArgs = {inherit inputs self;};
|
|
|
|
# shared modules for all configurations
|
|
sharedModules = [
|
|
./aesthetic
|
|
"${mod}/services/gnome-services.nix"
|
|
"${mod}/core/limine.nix"
|
|
"${home}"
|
|
inputs.agenix.nixosModules.default
|
|
];
|
|
in {
|
|
flake.nixosConfigurations = {
|
|
# TTY: desktop headless (no GUI)
|
|
tty = nixosSystem {
|
|
inherit specialArgs;
|
|
modules = tty ++ sharedModules;
|
|
};
|
|
|
|
# Desktop: desktop with GUI
|
|
desktop = nixosSystem {
|
|
inherit specialArgs;
|
|
modules = desktop ++ sharedModules;
|
|
};
|
|
|
|
# Laptop: laptop with GUI + battery + bluetooth
|
|
laptop = nixosSystem {
|
|
inherit specialArgs;
|
|
modules =
|
|
laptop
|
|
++ sharedModules
|
|
++ [
|
|
"${mod}/services/location.nix"
|
|
];
|
|
};
|
|
|
|
# Server: severijnse.eu (Hetzner) — fully isolated under servers/hetzner/.
|
|
# Uses nixos-24.05 + disko + sops-nix and does NOT inherit the laptop's shared modules.
|
|
hetzner = nixosSystem24 {
|
|
system = "x86_64-linux";
|
|
specialArgs = {
|
|
inherit inputs self unstablePkgs;
|
|
};
|
|
modules = [
|
|
inputs.disko.nixosModules.disko
|
|
inputs.sops-nix.nixosModules.sops
|
|
"${self}/servers/hetzner/hosts/hetzner/hardware-configuration.nix"
|
|
"${self}/servers/hetzner/hosts/hetzner/default.nix"
|
|
];
|
|
};
|
|
};
|
|
}
|