infra/hosts/bagel-box/default.nix

59 lines
1.5 KiB
Nix
Raw Permalink Normal View History

{ config, lib, ... }:
2024-06-23 04:41:53 +00:00
{
boot.isContainer = true;
# XXX: There's currently no way to remove the "problematic" entries (trying
# to override the /proc, /sys, /dev, ... mounts from systemd-nspawn) while
# also keeping the entry for the wrappers dir.
boot.specialFileSystems = lib.mkForce {
"/run/wrappers" = {
fsType = "tmpfs";
options = [ "nodev" "mode=755" "size=${config.security.wrapperDirSize}" ];
};
};
2024-06-23 04:41:53 +00:00
boot.loader.initScript.enable = true;
networking = {
useNetworkd = true;
useHostResolvConf = false;
hostName = "bagel-box";
domain = "infra.forkos.org";
2024-06-23 04:41:53 +00:00
nameservers = [ "2001:4860:4860::8844" ];
interfaces.host0.ipv6.addresses = [
{ address = "2001:bc8:38ee:100:100::1"; prefixLength = 64; }
];
interfaces.host1.ipv4.addresses = [
{ address = "172.16.100.2"; prefixLength = 24; }
];
defaultGateway = { address = "172.16.100.1"; interface = "host1"; };
2024-06-23 04:41:53 +00:00
firewall.allowPing = true;
};
2024-06-24 14:45:59 +00:00
bagel.services = {
postgres.enable = true;
hydra.enable = true;
hydra.dbi = "dbi:Pg:dbname=hydra;user=hydra";
# Takes 10 builders (0 → 9).
hydra.builders = lib.genList (i: "builder-${builtins.toString i}") 10;
ofborg.enable = true;
2024-06-24 14:45:59 +00:00
};
bagel.sysadmin.enable = true;
2024-06-24 14:45:59 +00:00
security.acme.acceptTerms = true;
security.acme.defaults.email = "infra@forkos.org";
2024-06-24 14:45:59 +00:00
2024-06-23 04:41:53 +00:00
services.openssh.enable = true;
2024-07-18 22:49:17 +00:00
system.stateVersion = "24.11";
deployment.targetHost = "bagel-box.infra.forkos.org";
2024-06-23 04:41:53 +00:00
}