nixos-configs/hosts/rpi3/default.nix

93 lines
1.8 KiB
Nix
Raw Permalink Normal View History

2024-08-20 22:58:24 +02:00
{ inputs, pkgs, ... }:
{
2023-03-28 16:34:46 +02:00
nix = {
registry.nixpkgs.flake = inputs.nixpkgs;
nixPath = [ "nixpkgs=${inputs.nixpkgs}" ];
};
2023-03-20 22:35:11 +01:00
2024-08-20 22:58:24 +02:00
boot = {
loader.grub.enable = false;
loader.generic-extlinux-compatible.enable = true;
kernelParams = [ "cma=256M" ];
};
2023-03-20 22:35:11 +01:00
2023-03-28 16:34:46 +02:00
fileSystems."/" = {
device = "/dev/disk/by-label/NIXOS_SD";
fsType = "ext4";
};
2023-03-20 22:35:11 +01:00
2024-08-20 22:58:24 +02:00
swapDevices = [
{
device = "/swapfile";
size = 1024;
}
];
2023-03-20 22:35:11 +01:00
services.openssh.enable = true;
users.users.root.openssh.authorizedKeys.keyFiles = [
../../ssh_keys/phfroidmont-desktop.pub
2025-12-23 14:46:30 +01:00
../../ssh_keys/phfroidmont-stellaris.pub
2023-03-20 22:35:11 +01:00
];
services.adguardhome = {
enable = true;
openFirewall = true;
mutableSettings = false;
settings = {
2024-08-20 22:58:24 +02:00
http = {
address = "0.0.0.0:80";
};
2023-03-20 22:35:11 +01:00
auth_attempts = 5;
block_auth_min = 15;
dns = {
2024-03-12 02:10:22 +01:00
bind_hosts = [ "0.0.0.0" ];
2023-03-20 22:35:11 +01:00
port = 53;
statistics_interval = 90;
2024-08-20 22:58:24 +02:00
upstream_dns = [
"tls://doh.mullvad.net"
"[/lan/]192.168.1.1"
"[//]192.168.1.1"
];
2023-03-20 22:35:11 +01:00
local_ptr_upstreams = [ "192.168.1.1" ];
use_private_ptr_resolvers = true;
resolve_clients = true;
bootstrap_dns = [ "9.9.9.10" ];
rewrites = [
{
domain = "rpi3";
answer = "192.168.1.2";
}
{
domain = "rpi3.lan";
answer = "192.168.1.2";
}
];
};
2024-03-12 02:10:22 +01:00
querylog = {
enabled = true;
interval = "2160h";
};
2023-03-20 22:35:11 +01:00
};
};
2024-08-20 22:58:24 +02:00
networking = {
hostName = "rpi3";
firewall.allowedTCPPorts = [
53
80
];
firewall.allowedUDPPorts = [ 53 ];
};
2023-03-20 22:35:11 +01:00
2024-08-20 22:58:24 +02:00
environment.systemPackages = with pkgs; [
vim
htop-vim
];
2023-03-20 22:35:11 +01:00
system.stateVersion = "22.05";
}