guixsd-config

GuixSD configs for my systems
Log | Files | Refs

commit 73e4e00719e52a7cab3f95627f8d9a3f9dd00298
parent 11ad6c03e2795f0fdbfaf5d97ac73da06939a941
Author: Vineet Kumar <git@vineetk.net>
Date:   Sat, 24 Jan 2026 12:47:40 -0500

saklas: update authorized key in saklas not base

Diffstat:
Mepistemia/systems/saklas.scm | 216+++++++++++++++++++++++++++++++++++++++++--------------------------------------
1 file changed, 111 insertions(+), 105 deletions(-)

diff --git a/epistemia/systems/saklas.scm b/epistemia/systems/saklas.scm @@ -40,13 +40,13 @@ ;; (host-name "saklas") (host-name "162.55.242.220") - (users (cons (user-account - (name "vin") - (comment "Vineet") - (shell (file-append bash "/bin/bash")) - (group "users") - (supplementary-groups '("wheel"))) - %base-user-accounts)) + (users (cons (user-account + (name "vin") + (comment "Vineet") + (shell (file-append bash "/bin/bash")) + (group "users") + (supplementary-groups '("wheel"))) + %base-user-accounts)) (kernel linux-6.17) (kernel-arguments (list "net.ifnames=0")) @@ -98,67 +98,67 @@ zfs-linux) %base-packages)) - (services (append (list (simple-service 'zfs-loader - kernel-module-loader-service-type - '("zfs")) - (simple-service 'zfs-shepherd-services - shepherd-root-service-type - zfs-shepherd-services) - (simple-service 'zfs-shepherd-services-user-processes - user-processes-service-type - '(zfs-automount)) - (service iptables-service-type) - (service static-networking-service-type - (list (static-networking - (addresses - (list (network-address - (device "eth0") - (value "162.55.242.220/26")) - (network-address - (device "eth0") - (value "2a01:4f8:272:4fd3::/64")))) - (routes - (list (network-route - (destination "default") - (device "eth0") - (gateway "162.55.242.193")) - (network-route - (destination "default") - (device "eth0") - (gateway "fe80::1"))))))) - (simple-service 'resolv-configuration - etc-service-type - `(("resolv.conf" - ,(plain-file "resolv.conf" - (string-append - "nameserver 127.0.0.1\n" - "search epistemia\n"))))) - (service (fail2ban-jail-service - openssh-service-type - (fail2ban-jail-configuration - (name "sshd") - (enabled? #t))) - (openssh-configuration - (permit-root-login 'prohibit-password) - (password-authentication? #f) - (authorized-keys - `(("vin" ,(local-file "/data/ssh/id_ed25519.pub")) - ("root" ,(local-file "/data/ssh/id_ed25519.pub")))) - (extra-content "\ + (services (modify-services (append (list (simple-service 'zfs-loader + kernel-module-loader-service-type + '("zfs")) + (simple-service 'zfs-shepherd-services + shepherd-root-service-type + zfs-shepherd-services) + (simple-service 'zfs-shepherd-services-user-processes + user-processes-service-type + '(zfs-automount)) + (service iptables-service-type) + (service static-networking-service-type + (list (static-networking + (addresses + (list (network-address + (device "eth0") + (value "162.55.242.220/26")) + (network-address + (device "eth0") + (value "2a01:4f8:272:4fd3::/64")))) + (routes + (list (network-route + (destination "default") + (device "eth0") + (gateway "162.55.242.193")) + (network-route + (destination "default") + (device "eth0") + (gateway "fe80::1"))))))) + (simple-service 'resolv-configuration + etc-service-type + `(("resolv.conf" + ,(plain-file "resolv.conf" + (string-append + "nameserver 127.0.0.1\n" + "search epistemia\n"))))) + (service (fail2ban-jail-service + openssh-service-type + (fail2ban-jail-configuration + (name "sshd") + (enabled? #t))) + (openssh-configuration + (permit-root-login 'prohibit-password) + (password-authentication? #f) + (authorized-keys + `(("vin" ,(local-file "/data/ssh/id_ed25519.pub")) + ("root" ,(local-file "/data/ssh/id_ed25519.pub")))) + (extra-content "\ ListenAddress 127.0.0.1:22 ListenAddress 162.55.242.220:22 #ListenAddress 10.0.13.1:22 "))) - (service unbound-service-type - (unbound-configuration - (server - (unbound-server - (interface '("127.0.0.1" - "::1" - "10.0.13.1")) - (hide-version #t) - (hide-identity #t))) - (extra-content "\ + (service unbound-service-type + (unbound-configuration + (server + (unbound-server + (interface '("127.0.0.1" + "::1" + "10.0.13.1")) + (hide-version #t) + (hide-identity #t))) + (extra-content "\ server: access-control: 127.0.0.0/8 allow access-control: 10.0.13.0/24 allow @@ -188,44 +188,50 @@ rpz: name: \"hagezi.ultimate\" zonefile: \"hagezi.ultimate\" url: https://raw.githubusercontent.com/hagezi/dns-blocklists/main/rpz/ultimate.txt"))) - (service wireguard-service-type - (wireguard-configuration - (interface "wg1") - (addresses '("10.0.13.1/24" "fd00:b0ba:cafe:babe::1/64 ")) - (port 51820) - (bootstrap-private-key? #f) - (private-key - #~(string-append "<(" - #$(file-append age "/bin/age -d -i /etc/ssh/ssh_host_ed25519_key") - " /data/src/public/guixsd-config/epistemia/secrets/wg1_saklas.age)")) - (peers - (list - (wireguard-peer - (name "demiurge.epistemia") - (public-key "FMLvbSxY6vA8CRV4S1vl4+pMeCr/kR9n0G5w9buNqh4=") - (allowed-ips '("10.0.13.2/32" "fd00:b0ba:cafe:babe::2/128")) - (keep-alive 25)) - (wireguard-peer - (name "hastur.epistemia") - (public-key "1ketYziRhoUmpbrj/60O5DYbcPacvmEoFQqa/NntSnc=") - (allowed-ips '("10.0.13.3/32" "fd00:b0ba:cafe:babe::3/128")) - (keep-alive 25)) - (wireguard-peer - (name "iphonebob.epistemia") - (public-key "Xn0EmeRZdpMejBgzr98mYtb/2f5O58GAzQLNZV/SS30=") - (allowed-ips '("10.0.13.4/32" "fd00:b0ba:cafe:babe::4/128")) - (keep-alive 25)) - (wireguard-peer - (name "lab.epistemia") - (public-key "iMDEwvXjPAlQH8ZCmP63FM5ICYIFIX5XIyGxjnXoNVE=") - (allowed-ips '("10.0.13.5/32" "fd00:b0ba:cafe:babe::5/128")) - (keep-alive 25)))))) - (service nginx-service-type - (nginx-configuration - (server-blocks - (list - (nginx-reverse-proxy "searx.demiurge.epistemia" 8081) - (nginx-reverse-proxy "redlib.demiurge.epistemia" 8085) - (nginx-reverse-proxy "navidrome.demiurge.epistemia" 4533) - (nginx-reverse-proxy "sdui.demiurge.epistemia" 5000)))))) - %base-services))) + (service wireguard-service-type + (wireguard-configuration + (interface "wg1") + (addresses '("10.0.13.1/24" "fd00:b0ba:cafe:babe::1/64 ")) + (port 51820) + (bootstrap-private-key? #f) + (private-key + #~(string-append "<(" + #$(file-append age "/bin/age -d -i /etc/ssh/ssh_host_ed25519_key") + " /data/src/public/guixsd-config/epistemia/secrets/wg1_saklas.age)")) + (peers + (list + (wireguard-peer + (name "demiurge.epistemia") + (public-key "FMLvbSxY6vA8CRV4S1vl4+pMeCr/kR9n0G5w9buNqh4=") + (allowed-ips '("10.0.13.2/32" "fd00:b0ba:cafe:babe::2/128")) + (keep-alive 25)) + (wireguard-peer + (name "hastur.epistemia") + (public-key "1ketYziRhoUmpbrj/60O5DYbcPacvmEoFQqa/NntSnc=") + (allowed-ips '("10.0.13.3/32" "fd00:b0ba:cafe:babe::3/128")) + (keep-alive 25)) + (wireguard-peer + (name "iphonebob.epistemia") + (public-key "Xn0EmeRZdpMejBgzr98mYtb/2f5O58GAzQLNZV/SS30=") + (allowed-ips '("10.0.13.4/32" "fd00:b0ba:cafe:babe::4/128")) + (keep-alive 25)) + (wireguard-peer + (name "lab.epistemia") + (public-key "iMDEwvXjPAlQH8ZCmP63FM5ICYIFIX5XIyGxjnXoNVE=") + (allowed-ips '("10.0.13.5/32" "fd00:b0ba:cafe:babe::5/128")) + (keep-alive 25)))))) + (service nginx-service-type + (nginx-configuration + (server-blocks + (list + (nginx-reverse-proxy "searx.demiurge.epistemia" 8081) + (nginx-reverse-proxy "redlib.demiurge.epistemia" 8085) + (nginx-reverse-proxy "navidrome.demiurge.epistemia" 4533) + (nginx-reverse-proxy "sdui.demiurge.epistemia" 5000)))))) + %base-services) + (guix-service-type config => + (guix-configuration + (inherit config) + (authorized-keys + (append (list (local-file "../../demiurge.pub")) + %default-authorized-guix-keys)))))))