commit 73e4e00719e52a7cab3f95627f8d9a3f9dd00298
parent 11ad6c03e2795f0fdbfaf5d97ac73da06939a941
Author: Vineet Kumar <git@vineetk.net>
Date: Sat, 24 Jan 2026 12:47:40 -0500
saklas: update authorized key in saklas not base
Diffstat:
1 file changed, 111 insertions(+), 105 deletions(-)
diff --git a/epistemia/systems/saklas.scm b/epistemia/systems/saklas.scm
@@ -40,13 +40,13 @@
;; (host-name "saklas")
(host-name "162.55.242.220")
- (users (cons (user-account
- (name "vin")
- (comment "Vineet")
- (shell (file-append bash "/bin/bash"))
- (group "users")
- (supplementary-groups '("wheel")))
- %base-user-accounts))
+ (users (cons (user-account
+ (name "vin")
+ (comment "Vineet")
+ (shell (file-append bash "/bin/bash"))
+ (group "users")
+ (supplementary-groups '("wheel")))
+ %base-user-accounts))
(kernel linux-6.17)
(kernel-arguments (list "net.ifnames=0"))
@@ -98,67 +98,67 @@
zfs-linux)
%base-packages))
- (services (append (list (simple-service 'zfs-loader
- kernel-module-loader-service-type
- '("zfs"))
- (simple-service 'zfs-shepherd-services
- shepherd-root-service-type
- zfs-shepherd-services)
- (simple-service 'zfs-shepherd-services-user-processes
- user-processes-service-type
- '(zfs-automount))
- (service iptables-service-type)
- (service static-networking-service-type
- (list (static-networking
- (addresses
- (list (network-address
- (device "eth0")
- (value "162.55.242.220/26"))
- (network-address
- (device "eth0")
- (value "2a01:4f8:272:4fd3::/64"))))
- (routes
- (list (network-route
- (destination "default")
- (device "eth0")
- (gateway "162.55.242.193"))
- (network-route
- (destination "default")
- (device "eth0")
- (gateway "fe80::1")))))))
- (simple-service 'resolv-configuration
- etc-service-type
- `(("resolv.conf"
- ,(plain-file "resolv.conf"
- (string-append
- "nameserver 127.0.0.1\n"
- "search epistemia\n")))))
- (service (fail2ban-jail-service
- openssh-service-type
- (fail2ban-jail-configuration
- (name "sshd")
- (enabled? #t)))
- (openssh-configuration
- (permit-root-login 'prohibit-password)
- (password-authentication? #f)
- (authorized-keys
- `(("vin" ,(local-file "/data/ssh/id_ed25519.pub"))
- ("root" ,(local-file "/data/ssh/id_ed25519.pub"))))
- (extra-content "\
+ (services (modify-services (append (list (simple-service 'zfs-loader
+ kernel-module-loader-service-type
+ '("zfs"))
+ (simple-service 'zfs-shepherd-services
+ shepherd-root-service-type
+ zfs-shepherd-services)
+ (simple-service 'zfs-shepherd-services-user-processes
+ user-processes-service-type
+ '(zfs-automount))
+ (service iptables-service-type)
+ (service static-networking-service-type
+ (list (static-networking
+ (addresses
+ (list (network-address
+ (device "eth0")
+ (value "162.55.242.220/26"))
+ (network-address
+ (device "eth0")
+ (value "2a01:4f8:272:4fd3::/64"))))
+ (routes
+ (list (network-route
+ (destination "default")
+ (device "eth0")
+ (gateway "162.55.242.193"))
+ (network-route
+ (destination "default")
+ (device "eth0")
+ (gateway "fe80::1")))))))
+ (simple-service 'resolv-configuration
+ etc-service-type
+ `(("resolv.conf"
+ ,(plain-file "resolv.conf"
+ (string-append
+ "nameserver 127.0.0.1\n"
+ "search epistemia\n")))))
+ (service (fail2ban-jail-service
+ openssh-service-type
+ (fail2ban-jail-configuration
+ (name "sshd")
+ (enabled? #t)))
+ (openssh-configuration
+ (permit-root-login 'prohibit-password)
+ (password-authentication? #f)
+ (authorized-keys
+ `(("vin" ,(local-file "/data/ssh/id_ed25519.pub"))
+ ("root" ,(local-file "/data/ssh/id_ed25519.pub"))))
+ (extra-content "\
ListenAddress 127.0.0.1:22
ListenAddress 162.55.242.220:22
#ListenAddress 10.0.13.1:22
")))
- (service unbound-service-type
- (unbound-configuration
- (server
- (unbound-server
- (interface '("127.0.0.1"
- "::1"
- "10.0.13.1"))
- (hide-version #t)
- (hide-identity #t)))
- (extra-content "\
+ (service unbound-service-type
+ (unbound-configuration
+ (server
+ (unbound-server
+ (interface '("127.0.0.1"
+ "::1"
+ "10.0.13.1"))
+ (hide-version #t)
+ (hide-identity #t)))
+ (extra-content "\
server:
access-control: 127.0.0.0/8 allow
access-control: 10.0.13.0/24 allow
@@ -188,44 +188,50 @@ rpz:
name: \"hagezi.ultimate\"
zonefile: \"hagezi.ultimate\"
url: https://raw.githubusercontent.com/hagezi/dns-blocklists/main/rpz/ultimate.txt")))
- (service wireguard-service-type
- (wireguard-configuration
- (interface "wg1")
- (addresses '("10.0.13.1/24" "fd00:b0ba:cafe:babe::1/64 "))
- (port 51820)
- (bootstrap-private-key? #f)
- (private-key
- #~(string-append "<("
- #$(file-append age "/bin/age -d -i /etc/ssh/ssh_host_ed25519_key")
- " /data/src/public/guixsd-config/epistemia/secrets/wg1_saklas.age)"))
- (peers
- (list
- (wireguard-peer
- (name "demiurge.epistemia")
- (public-key "FMLvbSxY6vA8CRV4S1vl4+pMeCr/kR9n0G5w9buNqh4=")
- (allowed-ips '("10.0.13.2/32" "fd00:b0ba:cafe:babe::2/128"))
- (keep-alive 25))
- (wireguard-peer
- (name "hastur.epistemia")
- (public-key "1ketYziRhoUmpbrj/60O5DYbcPacvmEoFQqa/NntSnc=")
- (allowed-ips '("10.0.13.3/32" "fd00:b0ba:cafe:babe::3/128"))
- (keep-alive 25))
- (wireguard-peer
- (name "iphonebob.epistemia")
- (public-key "Xn0EmeRZdpMejBgzr98mYtb/2f5O58GAzQLNZV/SS30=")
- (allowed-ips '("10.0.13.4/32" "fd00:b0ba:cafe:babe::4/128"))
- (keep-alive 25))
- (wireguard-peer
- (name "lab.epistemia")
- (public-key "iMDEwvXjPAlQH8ZCmP63FM5ICYIFIX5XIyGxjnXoNVE=")
- (allowed-ips '("10.0.13.5/32" "fd00:b0ba:cafe:babe::5/128"))
- (keep-alive 25))))))
- (service nginx-service-type
- (nginx-configuration
- (server-blocks
- (list
- (nginx-reverse-proxy "searx.demiurge.epistemia" 8081)
- (nginx-reverse-proxy "redlib.demiurge.epistemia" 8085)
- (nginx-reverse-proxy "navidrome.demiurge.epistemia" 4533)
- (nginx-reverse-proxy "sdui.demiurge.epistemia" 5000))))))
- %base-services)))
+ (service wireguard-service-type
+ (wireguard-configuration
+ (interface "wg1")
+ (addresses '("10.0.13.1/24" "fd00:b0ba:cafe:babe::1/64 "))
+ (port 51820)
+ (bootstrap-private-key? #f)
+ (private-key
+ #~(string-append "<("
+ #$(file-append age "/bin/age -d -i /etc/ssh/ssh_host_ed25519_key")
+ " /data/src/public/guixsd-config/epistemia/secrets/wg1_saklas.age)"))
+ (peers
+ (list
+ (wireguard-peer
+ (name "demiurge.epistemia")
+ (public-key "FMLvbSxY6vA8CRV4S1vl4+pMeCr/kR9n0G5w9buNqh4=")
+ (allowed-ips '("10.0.13.2/32" "fd00:b0ba:cafe:babe::2/128"))
+ (keep-alive 25))
+ (wireguard-peer
+ (name "hastur.epistemia")
+ (public-key "1ketYziRhoUmpbrj/60O5DYbcPacvmEoFQqa/NntSnc=")
+ (allowed-ips '("10.0.13.3/32" "fd00:b0ba:cafe:babe::3/128"))
+ (keep-alive 25))
+ (wireguard-peer
+ (name "iphonebob.epistemia")
+ (public-key "Xn0EmeRZdpMejBgzr98mYtb/2f5O58GAzQLNZV/SS30=")
+ (allowed-ips '("10.0.13.4/32" "fd00:b0ba:cafe:babe::4/128"))
+ (keep-alive 25))
+ (wireguard-peer
+ (name "lab.epistemia")
+ (public-key "iMDEwvXjPAlQH8ZCmP63FM5ICYIFIX5XIyGxjnXoNVE=")
+ (allowed-ips '("10.0.13.5/32" "fd00:b0ba:cafe:babe::5/128"))
+ (keep-alive 25))))))
+ (service nginx-service-type
+ (nginx-configuration
+ (server-blocks
+ (list
+ (nginx-reverse-proxy "searx.demiurge.epistemia" 8081)
+ (nginx-reverse-proxy "redlib.demiurge.epistemia" 8085)
+ (nginx-reverse-proxy "navidrome.demiurge.epistemia" 4533)
+ (nginx-reverse-proxy "sdui.demiurge.epistemia" 5000))))))
+ %base-services)
+ (guix-service-type config =>
+ (guix-configuration
+ (inherit config)
+ (authorized-keys
+ (append (list (local-file "../../demiurge.pub"))
+ %default-authorized-guix-keys)))))))