Files
nixos-config/servers/hetzner/modules/system/env.nix
T
jory e0453b0123
CI / Flake check (aarch64-linux) (push) Failing after 8s
CI / Flake check (x86_64-linux) (push) Failing after 2s
CI / Pre-commit checks (aarch64-linux) (push) Failing after 2s
CI / Pre-commit checks (x86_64-linux) (push) Failing after 2s
Harden server and add Nix-native CI + self-hosted Gitea Actions
- caddy: security headers (X-Content-Type-Options/X-XSS-Protection/
  X-Frame-Options) on all vhosts + baseline CSP; strip SnappyMail
  upstream copies via header_down on mail.severijnse.eu
- tlsa-updater: compute TLSA 3 1 1 from cert SPKI (SHA-256), sync
  _25/_465/_993, fail-safe placeholders; coredns zone updated
- pre-commit: wire cachix/git-hooks.nix (alejandra, statix, actionlint,
  ...); CI pre-commit job over x86_64 + aarch64 matrix
- gitea: enable Gitea Actions + self-hosted runner (native:host,
  aarch64 via binfmt); add .gitea/workflows/ci.yml and local hook
- fix statix warnings (merge repeated systemd/database/configFile keys,
  inherit, bool-compare guards); add missing trailing newlines
2026-07-12 01:58:12 +02:00

24 lines
370 B
Nix

{pkgs, ...}: {
time.timeZone = "Europe/Amsterdam";
i18n.defaultLocale = "en_US.UTF-8";
environment.systemPackages = with pkgs; [
vim
git
curl
wget
htop
iotop
btop
bind.dnsutils # provides dig, nslookup, host
jq
yq
fish
podman-compose
];
programs.fish.enable = true;
programs.bash.enableCompletion = true;
}