-
Notifications
You must be signed in to change notification settings - Fork 0
/
common.nix
157 lines (141 loc) · 9.74 KB
/
common.nix
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
{ lib, pkgs, config, inputs, ... }:
with lib;
let
cfg = config.env;
sshKeys = [
"ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAiR1wVz1/m2KXNWIUy02/yftUz+P7B/ZsPQ34PoiyJ/+SFiZBOpAX5KJhdyXwDY1l631CyzYX/yI/6I78GB6qoZGjrLG6g0lk5k70VBsdN+YadaHKn4SEs7KKmf2yNPkVWnCrXnVIqZV/ixLtwzQAnIY11pr5vpwEJjydDvb1+imtT6hyTGvVR2f3ZtBl0LryAW3RisLq9G6m+dlJtLGPJcwsSzSh+dqO9DocLPHff8gEgXyP8TqDQM8iS4lkHQYNlFs6KcSHp7/JE1RShjMSoOYy2VfrpCRrzds0GYTzuirTYo5DL1s3vQuWH5gEWk1tWht8ObjYGondZ7anz4bgXQ== rsa-key-201401"
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDrI5nV45rGWmbU4NjYpyUKMmmPL9JQw+V1Sy+avJxYsqUQkQAd7niZoujNKP56l0Mm1SJPGMIGnyc/711dE1fz//lupNgZnjZbavR6JnklyqwKRvZZja7I8oWBS1Vo6U8ClZvl23yeVl6NZbu97POrgyZm1EljafY1xb7H0GHe55RU9W+I/Fn9hC6CO+15Erv8FwteyqWQqOT3OBqmzttS0Tv3pqucAUFhxG6kNro9N8/KBDmJzdyHMQqv/CzhP9+r+AGkBw4P7/zRhcPTKcXKCkRKWlYFmOkS7ztCY8s+leCJulT427K4riumjHEziQ6WXvZ4Nm0ZIxI2drvb/SbHJSaV5sAIp6QPGLjrRrRH5qkew+jJLIAt+MHiAXYcE5MFG/WdepP4dxcCFDPJV93RLqUDNQfsTLOThJr/8q68qwe6J3ELVMmj+Hg8kMAYSlsnk91jo/6UAO+6uWfYvspjICeFtxYvU+gZ9wXNsUL7e2jEqHC+hfBGq01UHqFPJTwjo7FC31L/EuQDvue5z+qJsuY9uGZzk1jgs/67kvGD5whiuwo6a0F4CHxiwvlJBddYpR1S02gqYv5gsDtZyeYpcnwmhR8oagrgYQ0lkjVTFKQNkrxVZHcjbsL5krLRyXZVRISOxxekLO566BIaBT6zUujBwmCJ3wtUrI9JAtqd0w== cardno:000609029473"
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC8wZwiCGx/LX3xJZ0Yr323Apl43SFG2ETZsCavU06WO1OnybJOrZ6KqYQiO9mmsPjjQYHJApaJPBV2xiuOynfTPrEwZyBl0WqyaicqdczxirIez+ktNM8y/CSQ6XpmhfI/+UtdtHvlikWVEKG6oSQOi+QenXmCnIjZSqMRCOj7x3DD+D7fhIN6I+Ssw6XuPdBzAvDlpJ7vDtL2We7gA2PipX1I7erGsL3CnJzk/7ui9ha7r6Fz4WWwgEMuwx+WUxUuy9kK25SMJWwtzaHbeW3CZoLO0s9Fz4w9Z71hON/j/5xh7ynulFEiuco8zfxW6ySRf1HjlzyUN9GO2OMqqiFs8UCtvLDicv8ooCX1UCUiuEr9TwvAPx2du86bXwKpd0pq0ZZD3ymPxajbPGLLT7FYgzxUXbCpY3OeyD85dJB/JZ+5sMdPyimK26w2abLC9VCOV/+BTf15VjL8qTbby+BQNW1vLPcxauhWXVfhVV8FEVri97fj7wa9z7BIBneiIxjzjkpEWRtR8NhCBczioog81EJAFafWhcLEKBwn05YpN92iLWysBBxefIiBoynkfm+1+Ztu3z351BWxFMBod9DmOE6jf2utD12lCm1KeZ+vhnSfsfsBbhJ7/XfKvZ9ZE3igWhFw3A8FzOuuExKEKQLEgn2gUUa9bfRhdCX7PTeFTw== cardno:000609769932"
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCqvCOuh+/tsBgxY8I9lYauzLAQgtHSSPBLgyFzM5W0jOKsf/ijNfIFbFsNHisNLJJKCM/x03uQ6o21RHxv4OlNw/0ivLES+ZEnWpLzcQ5HZwmv95LsQRSCTNJC7R60JJVdWXUHAMuCOTzt7mVICsBSLosAI+Nw0ynlUy0OMAmnbgmQHEzWQYcWXoajS06HliPq3VoQBbgcZxLSoBtK6y3imVCqkYUB+1UzghJpWN5U0GGgqau2PVLjsi7mrGMfttDbXrQ5/0ndeEQVJs/r9RpZ+C4qZtyRqCCRnjFr5dVNRb/7HIXpVd2AEN4rNMiBLXJ4iWWExk0GVq3pKp/YeJcesMrPLQn3s+xwAPJfRB49kdHafWCGMt8yhTxMTahUwsUQeX04Sa1Yk+fehHfsxvEk5mZ8viQH27pbSNGPxfvbvhXiMftai0mvtQwDYvp7xa78Ztfogea9yZk8QpQ/M/3B9HWF7bxTlR9Hx7g2hyMBngvmEzBjEgolDXuu++B3O/pOHUikdC6dteI3gdHMW9Vgs6QR94VTXVng5ioo0Ff3UlB1f7MwkBkny+AMwSTssTq/cDa53m/aekU9REZREwHla1p1lGA6vL7RQHO9p5j4bRJ3mqJbjC4H5o0O3cdUZZBkvzi/0Pwtl+NP7aa5JG3mCP3B/BCPCqq9STl7dVpqmQ== cardno:000606923500"
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCxFTnA13izw+opAN3UADYe7nLU8wxjAXkLHlG3mW95dY9T5Gw58nZhCEDl/8Ozl/768P8jtRqUp+Or95YPeF8Uq3zpjs6cB+0hxPiZwU5a9r7+1Bl3yZSwDr9UYkL+Bv+g7fPgyUNAzLQvvU2IpagP4LIj8V1pYJ97RdT5cJceEB3Q4CsMFks/6KW31JfIGaGjwmAgZobJ8h3vZrTg6FyXJxJm+bB3IB+HMEsdX9HS7WCD32tP/hg2ufn27MOINjepdomFWEFUwawLrqQsu7UXuLL53Lp1aD1K1VGH7KLA+pXRTkI8SsgUbrjADU0wbx5HdclTVYgZRyv5MjvXZbduFs8WdWEdDhOWi+vM+K/S9fMVrywQOHj1J6cszyjOy33KZNcuGd1b7KEPThZldbam6hnm7mHtkcuuBXrG0wUMIDCIBEuRQ7hn1QOV2cLLKMEUOEXDMWzmvY0oLGwfZSaebYOT/m8Z5rLnsOGZUXFubKB5iQ5i2wDuwrf8MSTptsvbuKOwIDU6jOe9VIz/Z0PZ561C8a73/AWpomQZ/dF7sZJks1Ecynwq62CO1edjpNoiac61MYAd7akQhuS8xQ45AAX13aczVgUR3tCLxxz3D54cSNuhZNEfQZ16tNfikum6spF3D6x3Ky+Al3RsojJOcqEx3Ega9tteNTl57G+wmw== cardno:000613146991"
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDsnJANRZDcM7GyCD8OLiJiksm5U6FyK53NDKf0nYzipI3bf2ux+9D7GqUKLbg8nw2XygSd+sO7VK/ZI5gGp1hBPyVMMljYReIZ5rY4qnidQn0j66SBY7kwLOGm/5Th/9fGjPyAJzkDJyjhF2r2HPxzojgaq3BNwMvNsnE3v401pMnOXlEY1Tz7vk2GBBS4F1aELVkCZGNzA+UGqqczbCPNFvM7Si7hayMsPBn0y0THydohvJr7yMZ/nADk7ZAK7Wpy6JpzGT8uQ0LeLrPdfo7wxf7Jkqb340e7ie1MBDjm5XYumIktH2un3Okdyq3mYBkCuGQd1lVfifsOrQKBAmU+fuQZwP4NbJvEUHEwO0k94o4VK0isHOpHhY+l8BGAGc6kZW6HrnNcMpHgWyxNib/LVfbz3qgOOdxqBv4TDlzXa2AQRplLgIm/eDLktUn8QSAQJ9jr31nd1Ec1lTIGbBVIaR0ZrtZUcFzNZ3L5MqqPP2ggPQGzW25qD+kWecy7zqW29jOX6WLeQwqbzWqNaotbPswYtKaBofp7M34wVh+3GO34lwKi0KQRqiNzbfBPcVf2jy1qqI46t3Z0nUJ4XMo5f2RhV4uSMFWkt+mTlh3HiQ2JcPr+Xec/aa/q8ZcEWJfvlM05HTv/cZCgNAbvTcS2d/6TwaMw14jxtK2WMsPOiw== cardno:000613146981"
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC/J+vzZtv/1CQzmHfgLGsLWowvSJRKr23N+NnBNg1l0dT/cPFTeDtr9kggPaHkdc587kziHFcUtkbewR8r4PgH4xMn272OPwd5r+HT1fffcE1SZO05GaxMvbXwrN6duK9EihtTpp/roitiJ/SmUX5S4YW0lzULUZG6sHDtJ7P5gPACdt/eLN50qwRVxq1yrfD2JfsI9hTFwud75HjPUDtPqL7yhfnuJ1xrbtP7Fzqs70eFQCtm7VcHa5b4azUytHBeHlf3OwBVopkiV7PUzH0UKZ+FMX3T19JyVAKPRvkuL4i2foxQthD4m/Wlr4szK2Z2yzXjAthxD2rwqlY+UiRCwWTIus12fSWS4lZWdkpqhRBXCL/fovkBWg9k4jO3Gkdt+CgbA47mcyBt5wRT013n4SPdAoIDxWRwW14T3urUoBUqjMgHlRy3s2i9cyb+dYzmeu8XIJ0YqvIUmXibTST8DOFKF16I5FqzC2SkVIrqwemqpL6Hk4BltWiZuhMu9ObBqjEKLDQ/JKvbHJH+vM2kS2JXWFfD8TUpS7nen7rTVnl2nwbBl2Ca7uchqIdQ+gOF+Mox1ncfUJ6bDAQ/QEyBCxa2u346hfvZ6Pcg1Dp8muXvkD27vLN7qUdYGnOG518gSTH4dAOYe9gaKYwDWMyH1FGNrW3052pNTN4TphEQpw== cardno:16 738 578"
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIXqBarGejSu6/XzblEbsWocVCIyPxuQUCVLnMtnfrvi"
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC6jrY1lhogYVDj73Nzr0aXROokQ2MxsgFzqrLIfO/VffBE78GdAOs2MiYD/EYPoG5azxblujH1Nd18ohShuW6GHGsHaX8/i6lg92Ukxp8aAzdiSZSoJz6UjY9JIAquMHx4wQLuVj7TzaQ6r3UFFCzQT3zVoD1xOo1Ajww5WCUp7sYu80htEPbDoPVfjWv7PJAIibVZatV8S6mlsXoIYDoTXD2uxMe6rlWsTeYWyIocg5SBqc0dsvkOx+ga1XcKHOBSjH31osQO7FRz7jhUC69IPr++ZSfHitG25CEVyhkStF5ZZ1cuo5I0gLTgaWXreF0kjcnUtqF0KViRfeBDB9Rbhv/k816WkVLBNEsy/Bw9Ly2eDYLmdBmdp91AropRvOaMDHtjBxn3Z+4WcA+PL9rcGtwPBwFHTD3RUJcpOmo8aR58xm7usLrwIn7Ulg+kEqTll+fuhpOmyCjC6K8/uPdRconJG+eGPMpYl5Oezz0a6gX7onugw9iQkMc9cTom2RmXLrGkPEPT1ARRRxsgYqFycoyuVP2vF19HzqI1y26CTf/zKrt9q2G95NVP1Pcx1yHlpfqwnWktih+iND5INrffXiKiFWVXTrkPZY99mcM1tkQ80cDff5q4xtQLDC/yO8iVSp1mY7T+J4tpA6FrCUk2FTT5yVIf6o1d4oJPwZxr4Q=="
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDEslktm9U3w1hQS3oDSBdoUNLCoB642tR2XcuwteUcFRW3VpQaCQgRtcHs9EjZlUB7EFoHuI00WYqPswi6UPHQhntIVWn6YRJeYtSAQEKBGEV+0zR7/0BNhW9wroTOwqO2+SAmhnalgHBXvhfbgKO0x7rs4fRiGHuVdQUh9/XHs3nfM8nz3mKRPXJ4uZU/6VHnquJF73fGZzs8UUf/kw65Qbx9E2Qqi4p6r7LQKeEs/EEGDMjnMDctlaey/u7mRsW4Emv7iTZdJxBBgry5LDcEwy1lY5z7i8/h2z7XfVBJKJBqFLm1n3CaGAjp5y/qyzAmMy39L9efKxfbp8N8W8aKkMLVk2lZgQiS8vqJyLzMJbG0kYF0O8rm2oxFm4jQ3sXQrBXfV60VYISBF2rWxsEjmf1W2YEkr7Fti5InyZn4aw7L6OCe4MafSV4tp0iUprniA526A9fYW3a/YfAHdBzw1nu5rWFY+NRkpzEU2keuNZOG7zFqllqnkQtQxs+kcRU="
];
in {
options.env = {
extraSshKeys = mkOption {
type = types.listOf types.str;
default = [ ];
};
dnsServer = mkOption {
type = types.str;
};
staticIpv4 = mkOption {
type = types.str;
};
ipv4DefaultDateway = mkOption {
type = types.nullOr types.str;
default = null;
};
enableDevelopmentNetworkInterface = mkEnableOption "DevelopmentNetworkInterface";
};
config = {
assertions = [{
assertion = (
(cfg.enableDevelopmentNetworkInterface == true -> cfg.ipv4DefaultDateway == null) &&
(cfg.enableDevelopmentNetworkInterface == false -> cfg.ipv4DefaultDateway != null)
);
message = ''
Please specify either
'env.enableDevelopmentNetworkInterface' or
'env.ipv4DefaultDateway'.
'';
}];
boot.tmp.cleanOnBoot = true;
networking.firewall.allowPing = true;
networking.firewall.logRefusedConnections = false;
services.openssh.enable = true;
programs.zsh.enable = true;
users.defaultUserShell = pkgs.zsh;
environment.systemPackages = with pkgs; [
# for dig
bind
inetutils
vim
tcpdump
];
# Service Discovery
services.lldpd.enable = true;
services.avahi = {
enable = true;
nssmdns4 = true;
ipv4 = true;
ipv6 = true;
publish = {
enable = true;
addresses = true;
workstation = true;
};
};
networking.useDHCP = false;
networking.tempAddresses = "disabled";
networking.interfaces.eth0.ipv4.addresses = [ {
address = cfg.staticIpv4;
prefixLength = 24;
} ];
networking.interfaces.eth1.useDHCP = lib.mkIf cfg.enableDevelopmentNetworkInterface (true);
networking.defaultGateway = lib.mkIf (cfg.ipv4DefaultDateway != null) (cfg.ipv4DefaultDateway);
networking.nameservers = [ cfg.dnsServer ];
users.users.root.openssh.authorizedKeys.keys = sshKeys
++ cfg.extraSshKeys;
services.prometheus.exporters.node = {
enable = true;
openFirewall = true;
listenAddress = "[::]";
enabledCollectors = [ "interrupts" "systemd" "tcpstat" "processes" ];
port = 9091;
};
services.promtail = {
enable = true;
configuration = {
server = {
http_listen_port = 3031;
grpc_listen_port = 0;
};
positions = {
filename = "/tmp/positions.yaml";
};
clients = [{
url = "http://172.16.2.5:3100/loki/api/v1/push";
}];
scrape_configs = [{
job_name = "journal";
journal = {
max_age = "12h";
labels = {
job = "systemd-journal";
host = config.networking.hostName;
};
};
relabel_configs = [{
source_labels = [ "__journal__systemd_unit" ];
target_label = "unit";
}];
}];
};
# extraFlags
};
nix = {
package = pkgs.nix;
extraOptions = ''
experimental-features = nix-command flakes
keep-outputs = true
keep-derivations = true
# nop out the global flake registry
flake-registry = ${builtins.toFile "flake-registry" (builtins.toJSON { version = 2; flakes = [ ]; })}
'';
# Pin nixpkgs for older Nix tools
nixPath = [ "nixpkgs=${pkgs.path}" ];
settings = {
trusted-users = [ "root" "@wheel" ];
};
registry = {
self.flake = inputs.self;
nixpkgs.flake = inputs.nixpkgs;
};
};
};
}