Commit graph

378 commits

Author SHA1 Message Date
5f0e99e48d fix sigma router dhcp dns
Instead of explicitly overwriting the DNS in the DHCPServer config we
ignore the upstream DNS from DHCP on the upstream interface so
networkctl/resolvectl understands the right DNS server, and can forward
it to DHCP clients.
2024-06-13 01:02:38 +02:00
Casper V. Kristensen
5f2d0ddf00 fix rofimoji 2024-06-12 12:00:22 +02:00
6a8a9c57d0 sigma router 2024-06-12 03:12:04 +02:00
60acca7687 make systemd networkd config closer to upstream 2024-06-11 23:39:21 +02:00
Casper V. Kristensen
bbce0b8d4e rofimoji 2024-06-11 17:55:28 +02:00
602f27b0ca cursor 2024-06-11 02:10:36 +02:00
843f2358f1 networking.useDHCP is true by default 2024-06-11 01:18:47 +02:00
f68a64f966 disable wait-online 2024-06-11 01:13:51 +02:00
c549159d10 sorting is hard 2024-06-11 01:13:12 +02:00
cba3b31df3 dont use net.ipv4.ip_forward
`net.ipv4.conf.all.forwarding` is sufficient.
2024-06-11 00:46:56 +02:00
snowflake
1a33f3791c flake.lock: Update
Flake lock file updates:

• Updated input 'home-manager':
    'github:nix-community/home-manager/a631666f5ec18271e86a5cde998cba68c33d9ac6?narHash=sha256-rNObca6dm7Qs524O4st8VJH6pZ/Xe1gxl%2BRx6mcWYo0%3D' (2024-05-26)
  → 'github:nix-community/home-manager/845a5c4c073f74105022533907703441e0464bc3?narHash=sha256-vWSkg6AMok1UUQiSYVdGMOXKD2cDFnajITiSi0Zjd1A%3D' (2024-06-04)
• Updated input 'home-manager-unstable':
    'github:nix-community/home-manager/9b53a10f4c91892f5af87cf55d08fba59ca086af?narHash=sha256-Xi0EpZcu39N0eW7apLjFfUOR9y80toyjYizez7J1wMI%3D' (2024-06-02)
  → 'github:nix-community/home-manager/3d65009effd77cb0d6e7520b68b039836a7606cf?narHash=sha256-Sz8Wh9cAiD5FhL8UWvZxBfnvxETSCVZlqWSYWaCPyu0%3D' (2024-06-09)
• Updated input 'impermanence':
    'github:nix-community/impermanence/a33ef102a02ce77d3e39c25197664b7a636f9c30?narHash=sha256-VUXLaPusCBvwM3zhGbRIJVeYluh2uWuqtj4WirQ1L9Y%3D' (2024-02-26)
  → 'github:nix-community/impermanence/27979f1c3a0d3b9617a3563e2839114ba7d48d3f?narHash=sha256-7C5lCpiWiyPoIACOcu2mukn/1JRtz6HC/1aEMhUdcw0%3D' (2024-06-09)
• Updated input 'nix-index-database':
    'github:nix-community/nix-index-database/972a52bee3991ae1f1899e6452e0d7c01ee566d9?narHash=sha256-43UmlS1Ifx17y93/Vc258U7bOlAAIZbu8dsGDHOIIr0%3D' (2024-06-02)
  → 'github:nix-community/nix-index-database/88ad3d7501e22b2401dd72734b032b7baa794434?narHash=sha256-sFXI%2BZANp/OC%2BMwfJoZgPSf4xMdtzQMe1pS3FGti4C8%3D' (2024-06-10)
• Updated input 'nixos-hardware':
    'github:NixOS/nixos-hardware/7b49d3967613d9aacac5b340ef158d493906ba79?narHash=sha256-e8X2eWjAHJQT82AAN%2BmCI0B68cIDBJpqJ156%2BVRrFO0%3D' (2024-06-01)
  → 'github:NixOS/nixos-hardware/58b52b0dd191af70f538c707c66c682331cfdffc?narHash=sha256-lQJXEFHHVsFdFLx0bvoRbZH3IXUBsle6EWj9JroTJ/s%3D' (2024-06-10)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/805a384895c696f802a9bf5bf4720f37385df547?narHash=sha256-F/TKWETwB5RaR8owkPPi%2BSPJh83AQsm6KrQAlJ8v/uA%3D' (2024-05-31)
  → 'github:NixOS/nixpkgs/9b5328b7f761a7bbdc0e332ac4cf076a3eedb89b?narHash=sha256-1%2Bua0ggXlYYPLTmMl3YeYYsBXDSCqT%2BGw3u6l4gvMhA%3D' (2024-06-06)
• Updated input 'nixpkgs-unstable':
    'github:NixOS/nixpkgs/57610d2f8f0937f39dbd72251e9614b1561942d8?narHash=sha256-yZKhxVIKd2lsbOqYd5iDoUIwsRZFqE87smE2Vzf6Ck0%3D' (2024-05-31)
  → 'github:NixOS/nixpkgs/051f920625ab5aabe37c920346e3e69d7d34400e?narHash=sha256-4q0s6m0GUcN7q%2BY2DqD27iLvbcd1G50T2lv08kKxkSI%3D' (2024-06-07)
• Updated input 'simple-nixos-mailserver':
    'gitlab:simple-nixos-mailserver/nixos-mailserver/1e456aff45e3ae5c0b37c31ea6f677aaea081d26?narHash=sha256-lGyLGBU4cxd309uyoT%2BX1RiM5WOGE%2BjGLwfEw1FhnpY%3D' (2024-06-03)
  → 'gitlab:simple-nixos-mailserver/nixos-mailserver/62afb98ef6385bcb745d7b189ef4efdce2044030?narHash=sha256-woG0M/WIrYDQeYd%2BaXRvGGMyojLmXND04Pi9XqE7ZxU%3D' (2024-06-08)
2024-06-10 15:24:55 +00:00
a751a2a517 matrix: give up on security 2024-06-06 23:01:11 +02:00
45fcd8fb07 base utils 2024-06-03 23:51:16 +02:00
ee49f70387 alpha: enable proxy arp 2024-06-03 23:51:16 +02:00
snowflake
0dce6bd4ec flake.lock: Update
Flake lock file updates:

• Updated input 'nixpkgs-unstable':
    'github:NixOS/nixpkgs/ad57eef4ef0659193044870c731987a6df5cf56b?narHash=sha256-SzDKxseEcHR5KzPXLwsemyTR/kaM9whxeiJohbL04rs%3D' (2024-05-29)
  → 'github:NixOS/nixpkgs/57610d2f8f0937f39dbd72251e9614b1561942d8?narHash=sha256-yZKhxVIKd2lsbOqYd5iDoUIwsRZFqE87smE2Vzf6Ck0%3D' (2024-05-31)
2024-06-03 23:51:16 +02:00
c6ac11de29 element desktop 2024-06-03 23:51:16 +02:00
c3550746ef nixos v24.05 2024-06-03 23:51:16 +02:00
a311a16c78 Revert "temporarily allow mu ssh access to servers"
This reverts commit 7ee93857ac.
2024-06-02 18:09:26 +02:00
1289e3dc3b matrix sliding sync 2024-05-31 14:19:29 +02:00
de401a9e5c flake.lock: Update
Flake lock file updates:

• Updated input 'home-manager-unstable':
    'github:nix-community/home-manager/5d151429e1e79107acf6d06dcc5ace4e642ec239' (2024-05-26)
  → 'github:nix-community/home-manager/0eb314b4f0ba337e88123e0b1e57ef58346aafd9' (2024-05-30)
• Updated input 'nixos-hardware':
    'github:NixOS/nixos-hardware/9a20e17a73b052d6be912adcee220cb483477094' (2024-05-27)
  → 'github:NixOS/nixos-hardware/8251761f93d6f5b91cee45ac09edb6e382641009' (2024-05-29)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/9d29cd266cebf80234c98dd0b87256b6be0af44e' (2024-05-25)
  → 'github:NixOS/nixpkgs/25cf937a30bf0801447f6bf544fc7486c6309234' (2024-05-29)
• Updated input 'nixpkgs-unstable':
    'github:NixOS/nixpkgs/bfb7a882678e518398ce9a31a881538679f6f092' (2024-05-24)
  → 'github:NixOS/nixpkgs/ad57eef4ef0659193044870c731987a6df5cf56b' (2024-05-29)
• Updated input 'secrets':
    'git+ssh://git@git.caspervk.net/caspervk/nixos-secrets.git?ref=refs/heads/master&rev=51391a0e689b523d1213f6c6019a18631489cc91' (2024-05-13)
  → 'git+ssh://git@git.caspervk.net/caspervk/nixos-secrets.git?ref=refs/heads/master&rev=3369fe960dfa17dc4b3a3f84f10fd30e49fee75f' (2024-05-31)
2024-05-31 14:18:35 +02:00
2c97e3150e matrix synapse 2024-05-31 11:42:39 +02:00
03bd00c76a acme domain -> extraDomainNames 2024-05-31 10:33:45 +02:00
Casper V. Kristensen
0882ea8c27 foot: scrollback 10.000 lines 2024-05-28 17:01:07 +02:00
Casper V. Kristensen
7ee93857ac temporarily allow mu ssh access to servers 2024-05-27 17:40:48 +02:00
Casper V. Kristensen
ee22e5e001 hardware: remove common-gpu-intel -- it is included in common-cpu-intel
See https://github.com/NixOS/nixos-hardware/issues/940.
2024-05-27 17:40:48 +02:00
snowflake
63ca8fca0e flake.lock: Update
Flake lock file updates:

• Updated input 'agenix':
    'github:ryantm/agenix/8d37c5bdeade12b6479c85acd133063ab53187a0?narHash=sha256-2T7CHTqBXJJ3ZC6R/4TXTcKoXWHcvubKNj9SfomURnw%3D' (2024-05-09)
  → 'github:ryantm/agenix/c2fc0762bbe8feb06a2e59a364fa81b3a57671c9?narHash=sha256-UIGtLO89RxKt7RF2iEgPikSdU53r6v/6WYB0RW3k89I%3D' (2024-05-24)
• Updated input 'home-manager':
    'github:nix-community/home-manager/ab5542e9dbd13d0100f8baae2bc2d68af901f4b4?narHash=sha256-wPuqrAQGdv3ISs74nJfGb%2BYprm23U/rFpcHFFNWgM94%3D' (2024-05-10)
  → 'github:nix-community/home-manager/2c78a57c544dd19b07442350727ced097e1aa6e6?narHash=sha256-Y3bOjoh2cFBqZN0Jw1zUdyr7tjygyxl2bD/QY73GZP0%3D' (2024-05-26)
• Updated input 'home-manager-unstable':
    'github:nix-community/home-manager/e3ad5108f54177e6520535768ddbf1e6af54b59d?narHash=sha256-W9pyM3/vePxrffHtzlJI6lDS3seANQ%2BNqp%2Bi58O46LI%3D' (2024-05-17)
  → 'github:nix-community/home-manager/5d151429e1e79107acf6d06dcc5ace4e642ec239?narHash=sha256-h3RmnNknKYtVA%2BEvUSra6QAwfZjC2q1G8YA7W0gat8Y%3D' (2024-05-26)
• Updated input 'nix-index-database':
    'github:nix-community/nix-index-database/e0638db3db43b582512a7de8c0f8363a162842b9?narHash=sha256-fCAiox/TuzWGVaAz16PxrR4Jtf9lN5dwWL2W74DS0yI%3D' (2024-05-20)
  → 'github:nix-community/nix-index-database/ff80cb4a11bb87f3ce8459be6f16a25ac86eb2ac?narHash=sha256-Idcye44UW%2BEgjbjCoklf2IDF%2BXrehV6CVYvxR1omst4%3D' (2024-05-27)
• Updated input 'nixos-hardware':
    'github:NixOS/nixos-hardware/d9e0b26202fd500cf3e79f73653cce7f7d541191?narHash=sha256-FC21Bn4m6ctajMjiUof30awPBH/7WjD0M5yqrWepZbY%3D' (2024-05-20)
  → 'github:NixOS/nixos-hardware/9a20e17a73b052d6be912adcee220cb483477094?narHash=sha256-s8%2BOhT1WSPMoqbTawT30hj4NVMg%2Bw03/a%2B2HVqcNhY0%3D' (2024-05-27)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/e7cc61784ddf51c81487637b3031a6dd2d6673a2?narHash=sha256-H0eCta7ahEgloGIwE/ihkyGstOGu%2BkQwAiHvwVoXaA0%3D' (2024-05-18)
  → 'github:NixOS/nixpkgs/9d29cd266cebf80234c98dd0b87256b6be0af44e?narHash=sha256-xim1b5/HZYbWaZKyI7cn9TJCM6ewNVZnesRr00mXeS4%3D' (2024-05-25)
• Updated input 'nixpkgs-unstable':
    'github:NixOS/nixpkgs/6c0b7a92c30122196a761b440ac0d46d3d9954f1?narHash=sha256-sowPU%2BtLQv8GlqtVtsXioTKeaQvlMz/pefcdwg8MvfM%3D' (2024-05-19)
  → 'github:NixOS/nixpkgs/bfb7a882678e518398ce9a31a881538679f6f092?narHash=sha256-4zSIhSRRIoEBwjbPm3YiGtbd8HDWzFxJjw5DYSDy1n8%3D' (2024-05-24)
2024-05-27 15:24:48 +00:00
0c1181e51a alacritty -> foot 2024-05-25 04:09:40 +02:00
318c1de7dd fix waybar calendar weekdays 2024-05-25 00:04:43 +02:00
Casper V. Kristensen
f6d3c84ebb desktop: spelling dictionaries 2024-05-22 17:56:13 +02:00
Casper V. Kristensen
b9174f1cf1 desktop: add xdg-utils for xdg-open 2024-05-22 17:54:42 +02:00
Casper V. Kristensen
80c4bf3e8a 'nix shell' fish alias 2024-05-22 17:54:10 +02:00
e9be19a073 sway: chill outputOff 2024-05-22 01:28:56 +02:00
snowflake
a398c1ef09 flake.lock: Update
Flake lock file updates:

• Updated input 'home-manager-unstable':
    'github:nix-community/home-manager/44677a1c96810a8e8c4ffaeaad10c842402647c1?narHash=sha256-4pRuzsHZOW5W4CsXI9uhKtiJeQSUoe1d2M9mWU98HC4%3D' (2024-05-12)
  → 'github:nix-community/home-manager/e3ad5108f54177e6520535768ddbf1e6af54b59d?narHash=sha256-W9pyM3/vePxrffHtzlJI6lDS3seANQ%2BNqp%2Bi58O46LI%3D' (2024-05-17)
• Updated input 'nix-index-database':
    'github:nix-community/nix-index-database/f9027322f48b427da23746aa359a6510dfcd0228?narHash=sha256-WMDuQj7J5jbpXI/X/E6FZRKgBFGcaSTvYyVxPnKE6KU%3D' (2024-05-12)
  → 'github:nix-community/nix-index-database/e0638db3db43b582512a7de8c0f8363a162842b9?narHash=sha256-fCAiox/TuzWGVaAz16PxrR4Jtf9lN5dwWL2W74DS0yI%3D' (2024-05-20)
• Updated input 'nixos-hardware':
    'github:NixOS/nixos-hardware/a4e2b7909fc1bdf30c30ef21d388fde0b5cdde4a?narHash=sha256-lRxjTxY3103LGMjWdVqntKZHhlmMX12QUjeFrQMmGaE%3D' (2024-05-08)
  → 'github:NixOS/nixos-hardware/d9e0b26202fd500cf3e79f73653cce7f7d541191?narHash=sha256-FC21Bn4m6ctajMjiUof30awPBH/7WjD0M5yqrWepZbY%3D' (2024-05-20)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/44072e24566c5bcc0b7aa9178a0104f4cfffab19?narHash=sha256-FF593AtlzQqa8JpzrXyRws4CeKbc5W86o8tHt4nRfIg%3D' (2024-05-12)
  → 'github:NixOS/nixpkgs/e7cc61784ddf51c81487637b3031a6dd2d6673a2?narHash=sha256-H0eCta7ahEgloGIwE/ihkyGstOGu%2BkQwAiHvwVoXaA0%3D' (2024-05-18)
• Updated input 'nixpkgs-unstable':
    'github:NixOS/nixpkgs/2057814051972fa1453ddfb0d98badbea9b83c06?narHash=sha256-5ZSVkFadZbFP1THataCaSf0JH2cAH3S29hU9rrxTEqk%3D' (2024-05-12)
  → 'github:NixOS/nixpkgs/6c0b7a92c30122196a761b440ac0d46d3d9954f1?narHash=sha256-sowPU%2BtLQv8GlqtVtsXioTKeaQvlMz/pefcdwg8MvfM%3D' (2024-05-19)
2024-05-20 15:24:33 +00:00
d1562bef16 archiveteam-warrior 2024-05-18 02:23:00 +02:00
9b48143208 podman auto update 2024-05-18 01:38:48 +02:00
Casper V. Kristensen
47017b65f2 _JAVA_AWT_WM_NONREPARENTING=1 2024-05-16 17:34:09 +02:00
Casper V. Kristensen
8c0eeabfff programs: ascii 2024-05-15 13:30:53 +02:00
Casper V. Kristensen
e0d64d1e68 packages.nix -> programs.nix 2024-05-15 13:30:27 +02:00
867a64f141 fogejo actions runner: use host networking (for now) 2024-05-14 01:29:35 +02:00
snowflake
31c13a2a51 flake.lock: Update
Flake lock file updates:

• Updated input 'home-manager':
    'github:nix-community/home-manager/86853e31dc1b62c6eeed11c667e8cdd0285d4411?narHash=sha256-Xn2r0Jv95TswvPlvamCC46wwNo8ALjRCMBJbGykdhcM%3D' (2024-04-25)
  → 'github:nix-community/home-manager/ab5542e9dbd13d0100f8baae2bc2d68af901f4b4?narHash=sha256-wPuqrAQGdv3ISs74nJfGb%2BYprm23U/rFpcHFFNWgM94%3D' (2024-05-10)
• Updated input 'home-manager-unstable':
    'github:nix-community/home-manager/f2c5ba5e720fd584d83f2f97399dac0d26ae60b9?narHash=sha256-FJYyXqulIbCdsUCTFBTu/bIH4aN%2B7jzjQAn52Qc6qPg%3D' (2024-05-10)
  → 'github:nix-community/home-manager/44677a1c96810a8e8c4ffaeaad10c842402647c1?narHash=sha256-4pRuzsHZOW5W4CsXI9uhKtiJeQSUoe1d2M9mWU98HC4%3D' (2024-05-12)
• Updated input 'nix-index-database':
    'github:nix-community/nix-index-database/a362555e9dbd4ecff3bb98969bbdb8f79fe87f10?narHash=sha256-E68C03sYRsYFsK7wiGHUIJm8IsyPRALOrFoTL0glXnI%3D' (2024-05-05)
  → 'github:nix-community/nix-index-database/f9027322f48b427da23746aa359a6510dfcd0228?narHash=sha256-WMDuQj7J5jbpXI/X/E6FZRKgBFGcaSTvYyVxPnKE6KU%3D' (2024-05-12)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/9a9960b98418f8c385f52de3b09a63f9c561427a?narHash=sha256-R98WOBHkk8wIi103JUVQF3ei3oui4HvoZcz9tYOAwlk%3D' (2024-05-09)
  → 'github:NixOS/nixpkgs/44072e24566c5bcc0b7aa9178a0104f4cfffab19?narHash=sha256-FF593AtlzQqa8JpzrXyRws4CeKbc5W86o8tHt4nRfIg%3D' (2024-05-12)
• Updated input 'nixpkgs-unstable':
    'github:NixOS/nixpkgs/f1010e0469db743d14519a1efd37e23f8513d714?narHash=sha256-doPgfj%2B7FFe9rfzWo1siAV2mVCasW%2BBh8I1cToAXEE4%3D' (2024-05-09)
  → 'github:NixOS/nixpkgs/2057814051972fa1453ddfb0d98badbea9b83c06?narHash=sha256-5ZSVkFadZbFP1THataCaSf0JH2cAH3S29hU9rrxTEqk%3D' (2024-05-12)
• Updated input 'secrets':
    'git+ssh://git@git.caspervk.net/caspervk/nixos-secrets.git?ref=refs/heads/master&rev=091960dcd90f1a8900ceea4399d955d9ff4611fa' (2024-05-10)
  → 'git+ssh://git@git.caspervk.net/caspervk/nixos-secrets.git?ref=refs/heads/master&rev=51391a0e689b523d1213f6c6019a18631489cc91' (2024-05-13)
2024-05-13 23:19:42 +00:00
95a9d94855 forgejo actions runner fetch interval 5m -> 1m 2024-05-14 00:52:40 +02:00
Casper V. Kristensen
508cfbdcf2 nix-ld 2024-05-13 17:19:21 +02:00
2b7ec9c034 flake.lock: Update
Flake lock file updates:

• Updated input 'home-manager-unstable':
    'github:nix-community/home-manager/e6a315900db775da3bb3138bab8caa70dafdaf9e' (2024-05-10)
  → 'github:nix-community/home-manager/f2c5ba5e720fd584d83f2f97399dac0d26ae60b9' (2024-05-10)
• Updated input 'secrets':
    'git+ssh://git@git.caspervk.net/caspervk/nixos-secrets.git?ref=refs/heads/master&rev=aacc223f82da32d9f8a7b336679966b1272ce0e7' (2024-05-10)
  → 'git+ssh://git@git.caspervk.net/caspervk/nixos-secrets.git?ref=refs/heads/master&rev=091960dcd90f1a8900ceea4399d955d9ff4611fa' (2024-05-10)
2024-05-10 21:22:33 +02:00
471c194a54 lambda: remove 2024-05-10 21:21:37 +02:00
d5b9bef71d syncthing 2024-05-10 20:34:38 +02:00
a1855c9b1f flake.lock: Update
Flake lock file updates:

• Updated input 'home-manager-unstable':
    'github:nix-community/home-manager/223743313bab8b0b44a57eaf9573de9f69082b4d' (2024-05-10)
  → 'github:nix-community/home-manager/e6a315900db775da3bb3138bab8caa70dafdaf9e' (2024-05-10)
• Updated input 'secrets':
    'git+ssh://git@git.caspervk.net/caspervk/nixos-secrets.git?ref=refs/heads/master&rev=a3eefc6a111b5db8884b2bed54d166a0f63d35be' (2024-05-08)
  → 'git+ssh://git@git.caspervk.net/caspervk/nixos-secrets.git?ref=refs/heads/master&rev=aacc223f82da32d9f8a7b336679966b1272ce0e7' (2024-05-10)
2024-05-10 19:49:41 +02:00
a990c2ea3a secrets.hosts 2024-05-10 18:50:22 +02:00
aec0ac95d5 sigma: routingPolicyRules priorities
Without this, the rule to allow local network hosts direct access to the
sigma-public address might be shadowed by the rule to send traffic from
that address out through wireguard.
2024-05-10 16:44:08 +02:00
c2dc5cb7aa flake.lock: Update
Flake lock file updates:

• Updated input 'agenix':
    'github:ryantm/agenix/07479c2e7396acaaaac5925483498154034ea80a' (2024-05-07)
  → 'github:ryantm/agenix/8d37c5bdeade12b6479c85acd133063ab53187a0' (2024-05-09)
• Updated input 'home-manager-unstable':
    'github:nix-community/home-manager/6e277d9566de9976f47228dd8c580b97488734d4' (2024-05-07)
  → 'github:nix-community/home-manager/223743313bab8b0b44a57eaf9573de9f69082b4d' (2024-05-10)
• Updated input 'nixpkgs':
    'github:NixOS/nixpkgs/8be0d8a1ed4f96d99b09aa616e2afd47acc3da89' (2024-05-07)
  → 'github:NixOS/nixpkgs/9a9960b98418f8c385f52de3b09a63f9c561427a' (2024-05-09)
• Updated input 'nixpkgs-unstable':
    'github:NixOS/nixpkgs/b211b392b8486ee79df6cdfb1157ad2133427a29' (2024-05-07)
  → 'github:NixOS/nixpkgs/f1010e0469db743d14519a1efd37e23f8513d714' (2024-05-09)
2024-05-10 16:36:15 +02:00
a18d647cb3 sigma: allow ad hoc ports in firewall 2024-05-10 16:36:10 +02:00