]> Git — Sourcephile - sourcephile-nix.git/log
sourcephile-nix.git
3 years agoudev: add rules for MTP
Julien Moutinho [Wed, 25 Nov 2020 21:03:32 +0000 (22:03 +0100)]
udev: add rules for MTP

3 years agozfs: let zfs-mount.service handle /home
Julien Moutinho [Wed, 25 Nov 2020 21:02:16 +0000 (22:02 +0100)]
zfs: let zfs-mount.service handle /home

3 years agonix: factorize security.gnupg.store
Julien Moutinho [Wed, 25 Nov 2020 20:56:45 +0000 (21:56 +0100)]
nix: factorize security.gnupg.store

3 years agozfs: add lzop and mbuffer for syncoid
Julien Moutinho [Wed, 25 Nov 2020 20:54:52 +0000 (21:54 +0100)]
zfs: add lzop and mbuffer for syncoid

3 years agonetns: improve the service
Julien Moutinho [Sun, 22 Nov 2020 02:32:58 +0000 (03:32 +0100)]
netns: improve the service

3 years agonix: update patches
Julien Moutinho [Sun, 22 Nov 2020 02:31:10 +0000 (03:31 +0100)]
nix: update patches

3 years agossh: enable compression
Julien Moutinho [Sun, 22 Nov 2020 02:25:30 +0000 (03:25 +0100)]
ssh: enable compression

3 years agocoredump: set MaxUse=
Julien Moutinho [Sat, 21 Nov 2020 06:54:39 +0000 (07:54 +0100)]
coredump: set MaxUse=

3 years agofail2ban: relax some LAN IPv4
Julien Moutinho [Sat, 21 Nov 2020 06:54:00 +0000 (07:54 +0100)]
fail2ban: relax some LAN IPv4

3 years agonixpkgs: upstream public-inbox #104457 and freeciv #104460
Julien Moutinho [Sat, 21 Nov 2020 06:53:08 +0000 (07:53 +0100)]
nixpkgs: upstream public-inbox #104457 and freeciv #104460

3 years agopublic-inbox: rewrite the module
Julien Moutinho [Wed, 18 Nov 2020 19:05:46 +0000 (20:05 +0100)]
public-inbox: rewrite the module

3 years agopublic-inbox: update to 1.6.0
Julien Moutinho [Tue, 17 Nov 2020 16:20:27 +0000 (17:20 +0100)]
public-inbox: update to 1.6.0

3 years agoopenvpn: add riseup in net namespace
Julien Moutinho [Mon, 16 Nov 2020 03:39:37 +0000 (04:39 +0100)]
openvpn: add riseup in net namespace

3 years agofreeciv: add experimental service
Julien Moutinho [Sat, 14 Nov 2020 04:44:22 +0000 (05:44 +0100)]
freeciv: add experimental service

3 years agomurmur: add mumble server on mermet
Julien Moutinho [Sat, 14 Nov 2020 04:40:13 +0000 (05:40 +0100)]
murmur: add mumble server on mermet

3 years agonix: polish comments
Julien Moutinho [Thu, 12 Nov 2020 00:52:44 +0000 (01:52 +0100)]
nix: polish comments

3 years agonginx: change paths and config on losurdo
Julien Moutinho [Thu, 12 Nov 2020 00:51:21 +0000 (01:51 +0100)]
nginx: change paths and config on losurdo

3 years agounbound: no longer use nixos/profiles
Julien Moutinho [Fri, 6 Nov 2020 21:57:41 +0000 (22:57 +0100)]
unbound: no longer use nixos/profiles

3 years agosyncoid: fix keys rights and known_hosts
Julien Moutinho [Fri, 6 Nov 2020 21:42:25 +0000 (22:42 +0100)]
syncoid: fix keys rights and known_hosts

3 years agojmtpfs: add MTP support to losurdo
Julien Moutinho [Fri, 6 Nov 2020 17:29:58 +0000 (18:29 +0100)]
jmtpfs: add MTP support to losurdo

3 years agorspamd: fix paths to DKIM keys
Julien Moutinho [Fri, 6 Nov 2020 12:26:34 +0000 (13:26 +0100)]
rspamd: fix paths to DKIM keys

3 years agohostapd: enable WiFi on losurdo
Julien Moutinho [Fri, 6 Nov 2020 11:33:56 +0000 (12:33 +0100)]
hostapd: enable WiFi on losurdo

3 years agonginx: fix binding of paths
Julien Moutinho [Wed, 4 Nov 2020 15:01:16 +0000 (16:01 +0100)]
nginx: fix binding of paths

3 years agonftables: allow gemini output
Julien Moutinho [Wed, 4 Nov 2020 15:00:34 +0000 (16:00 +0100)]
nftables: allow gemini output

3 years agoupnpc: fix port opening and dynamic DNS
Julien Moutinho [Wed, 4 Nov 2020 15:00:01 +0000 (16:00 +0100)]
upnpc: fix port opening and dynamic DNS

3 years agoupnpc: use DHCP and UPnP on losurdo
Julien Moutinho [Tue, 3 Nov 2020 14:31:58 +0000 (15:31 +0100)]
upnpc: use DHCP and UPnP on losurdo

3 years agoknot: setup knsupdate on losurdo
Julien Moutinho [Tue, 3 Nov 2020 07:39:02 +0000 (08:39 +0100)]
knot: setup knsupdate on losurdo

3 years agonginx: small config modifs on losurdo
Julien Moutinho [Thu, 29 Oct 2020 11:24:36 +0000 (12:24 +0100)]
nginx: small config modifs on losurdo

3 years agodovecot: set ssl_min_protocol = TLSv1.2
Julien Moutinho [Wed, 28 Oct 2020 10:58:12 +0000 (11:58 +0100)]
dovecot: set ssl_min_protocol = TLSv1.2

3 years agosyncoid: update PR#98455
Julien Moutinho [Wed, 28 Oct 2020 10:55:04 +0000 (11:55 +0100)]
syncoid: update PR#98455

3 years agof3: enable on losurdo
Julien Moutinho [Sun, 25 Oct 2020 04:27:34 +0000 (05:27 +0100)]
f3: enable on losurdo

3 years agonix: relax GC to weekly on losurdo
Julien Moutinho [Sun, 25 Oct 2020 04:27:03 +0000 (05:27 +0100)]
nix: relax GC to weekly on losurdo

3 years agonginx: reduce open_file_cache_valid on losurdo
Julien Moutinho [Sun, 25 Oct 2020 04:26:06 +0000 (05:26 +0100)]
nginx: reduce open_file_cache_valid on losurdo

3 years agoapparmor: rebase upon latest nixpkgs
Julien Moutinho [Sun, 25 Oct 2020 04:25:15 +0000 (05:25 +0100)]
apparmor: rebase upon latest nixpkgs

3 years agotransmission: update PR#96655
Julien Moutinho [Sat, 24 Oct 2020 04:43:02 +0000 (06:43 +0200)]
transmission: update PR#96655

3 years agolosurdo: fix initrd networking
Julien Moutinho [Mon, 19 Oct 2020 14:53:10 +0000 (16:53 +0200)]
losurdo: fix initrd networking

3 years agoapparmor: PR#93457 has been reverted
Julien Moutinho [Sun, 18 Oct 2020 23:52:06 +0000 (01:52 +0200)]
apparmor: PR#93457 has been reverted

3 years agoneomutt: fix neomuch
Julien Moutinho [Thu, 8 Oct 2020 16:50:39 +0000 (18:50 +0200)]
neomutt: fix neomuch

3 years agonginx: bufferize cryptpad's log
Julien Moutinho [Mon, 5 Oct 2020 22:15:44 +0000 (00:15 +0200)]
nginx: bufferize cryptpad's log

3 years agonftables: specify wg-intra public IPv4 in fw2net
Julien Moutinho [Mon, 5 Oct 2020 22:15:15 +0000 (00:15 +0200)]
nftables: specify wg-intra public IPv4 in fw2net

3 years agonix: update to latest nixpkgs
Julien Moutinho [Mon, 5 Oct 2020 22:13:55 +0000 (00:13 +0200)]
nix: update to latest nixpkgs

3 years agolosurdo: revert to static IPv4 to see if DHCP is the problem after an electric failure
Julien Moutinho [Mon, 5 Oct 2020 22:13:08 +0000 (00:13 +0200)]
losurdo: revert to static IPv4 to see if DHCP is the problem after an electric failure

3 years agozfs: revert to stable version
Julien Moutinho [Mon, 5 Oct 2020 22:09:13 +0000 (00:09 +0200)]
zfs: revert to stable version

3 years agonotmuch: disable broken tests
Julien Moutinho [Mon, 5 Oct 2020 22:05:26 +0000 (00:05 +0200)]
notmuch: disable broken tests

3 years agonix: register shell.root
Julien Moutinho [Mon, 5 Oct 2020 22:01:33 +0000 (00:01 +0200)]
nix: register shell.root

3 years agozerobin: upstream changes in #98734
Julien Moutinho [Sun, 27 Sep 2020 09:47:22 +0000 (11:47 +0200)]
zerobin: upstream changes in #98734

3 years agosmem: add to systemPackages
Julien Moutinho [Fri, 25 Sep 2020 12:18:14 +0000 (14:18 +0200)]
smem: add to systemPackages

3 years agonix: add support for flake.nix's legacyPackages
Julien Moutinho [Fri, 25 Sep 2020 12:17:58 +0000 (14:17 +0200)]
nix: add support for flake.nix's legacyPackages

3 years agozerobin: update to v1.0.5
Julien Moutinho [Fri, 25 Sep 2020 12:17:41 +0000 (14:17 +0200)]
zerobin: update to v1.0.5

3 years agopass: update
Julien Moutinho [Fri, 25 Sep 2020 08:00:00 +0000 (10:00 +0200)]
pass: update

3 years agozfs: avoid mismatch between zfs-user and zfs-kmod
Julien Moutinho [Fri, 25 Sep 2020 07:35:28 +0000 (09:35 +0200)]
zfs: avoid mismatch between zfs-user and zfs-kmod

3 years agotor: fix dependencies and disable at boot for now
Julien Moutinho [Fri, 25 Sep 2020 07:34:45 +0000 (09:34 +0200)]
tor: fix dependencies and disable at boot for now

3 years agonix: remove useless abstraction
Julien Moutinho [Fri, 25 Sep 2020 07:33:50 +0000 (09:33 +0200)]
nix: remove useless abstraction

3 years agolosurdo: do not fail if USB key can't be mounted
Julien Moutinho [Fri, 25 Sep 2020 07:32:55 +0000 (09:32 +0200)]
losurdo: do not fail if USB key can't be mounted

3 years agonix: remove old files
Julien Moutinho [Fri, 25 Sep 2020 07:31:35 +0000 (09:31 +0200)]
nix: remove old files

3 years agozfs: add a mirror SSD disk
Julien Moutinho [Fri, 25 Sep 2020 04:28:58 +0000 (06:28 +0200)]
zfs: add a mirror SSD disk

3 years agocryptpad: fix backup
Julien Moutinho [Thu, 24 Sep 2020 15:14:24 +0000 (17:14 +0200)]
cryptpad: fix backup

3 years agocryptpad: add service
Julien Moutinho [Thu, 24 Sep 2020 14:37:29 +0000 (16:37 +0200)]
cryptpad: add service

3 years agosanoid: less data retention
Julien Moutinho [Wed, 23 Sep 2020 12:56:52 +0000 (14:56 +0200)]
sanoid: less data retention

3 years agoredis: fix sysctl
Julien Moutinho [Wed, 23 Sep 2020 12:26:28 +0000 (14:26 +0200)]
redis: fix sysctl

3 years agogitolite: update
Julien Moutinho [Wed, 23 Sep 2020 12:26:16 +0000 (14:26 +0200)]
gitolite: update

3 years agosyncoid: add service dependencies
Julien Moutinho [Wed, 23 Sep 2020 12:12:26 +0000 (14:12 +0200)]
syncoid: add service dependencies

3 years agowireguard: setup external vpn
Julien Moutinho [Wed, 23 Sep 2020 06:52:07 +0000 (08:52 +0200)]
wireguard: setup external vpn

3 years agonetworking: change losurdo's IPv6 to addr_gen_mode=1
Julien Moutinho [Tue, 22 Sep 2020 14:19:36 +0000 (16:19 +0200)]
networking: change losurdo's IPv6 to addr_gen_mode=1

3 years agonftables: reject uncaught IPv6
Julien Moutinho [Tue, 22 Sep 2020 14:11:58 +0000 (16:11 +0200)]
nftables: reject uncaught IPv6

3 years agotraceroute: enable for julm and root
Julien Moutinho [Tue, 22 Sep 2020 14:07:13 +0000 (16:07 +0200)]
traceroute: enable for julm and root

3 years agonix: make separate sendkeys command
Julien Moutinho [Tue, 22 Sep 2020 14:00:37 +0000 (16:00 +0200)]
nix: make separate sendkeys command

3 years agosyncoid: add nixpkgs#98455
Julien Moutinho [Tue, 22 Sep 2020 13:56:51 +0000 (15:56 +0200)]
syncoid: add nixpkgs#98455

3 years agogitolite: push and add upstream fix
Julien Moutinho [Sat, 19 Sep 2020 05:55:34 +0000 (07:55 +0200)]
gitolite: push and add upstream fix

3 years agosyncoid: polish conf while debugging
Julien Moutinho [Wed, 16 Sep 2020 01:54:09 +0000 (03:54 +0200)]
syncoid: polish conf while debugging

Current config of syncoid transfers only the oldest new snapshot
at each run. This causes the following error message:
> cannot receive incremental stream: most recent snapshot of
> losurdo/backup/mermet/home/julm/log
> does not match incremental source
after the transfer of that snapshot until there is no newer snapshots.
But when a snapshot is taken each hour and a transfer only happens each hour,
syncoid never catches up, and thus keeps issuing the error message.

3 years agojournald: limit logs to 1 month
Julien Moutinho [Mon, 14 Sep 2020 20:44:02 +0000 (22:44 +0200)]
journald: limit logs to 1 month

3 years agotor: improve type-checking and hardening (ter)
Julien Moutinho [Mon, 14 Sep 2020 05:33:58 +0000 (07:33 +0200)]
tor: improve type-checking and hardening (ter)

3 years agonix: fix PASSWORD_STORE_DIR
Julien Moutinho [Sun, 13 Sep 2020 18:03:16 +0000 (20:03 +0200)]
nix: fix PASSWORD_STORE_DIR

3 years agonetworking: try net.ipv6.conf.*.addr_gen_mode = 3
Julien Moutinho [Sun, 13 Sep 2020 18:02:42 +0000 (20:02 +0200)]
networking: try net.ipv6.conf.*.addr_gen_mode = 3

3 years agotor: improve type-checking and hardening (bis)
Julien Moutinho [Sun, 13 Sep 2020 17:55:57 +0000 (19:55 +0200)]
tor: improve type-checking and hardening (bis)

3 years agotor: improve type-checking and hardening
Julien Moutinho [Fri, 11 Sep 2020 07:29:38 +0000 (09:29 +0200)]
tor: improve type-checking and hardening

3 years agonftables: remote debugging ICMPv6 rule
Julien Moutinho [Tue, 8 Sep 2020 15:27:35 +0000 (17:27 +0200)]
nftables: remote debugging ICMPv6 rule

3 years agoknot: fix serial and gandi IPv6
Julien Moutinho [Tue, 8 Sep 2020 15:26:48 +0000 (17:26 +0200)]
knot: fix serial and gandi IPv6

3 years agonix: update to latest nixpkgs-unstable
Julien Moutinho [Tue, 8 Sep 2020 15:25:41 +0000 (17:25 +0200)]
nix: update to latest nixpkgs-unstable

3 years agonftables: fix biboumi IPv6 output
Julien Moutinho [Sun, 6 Sep 2020 17:29:18 +0000 (19:29 +0200)]
nftables: fix biboumi IPv6 output

3 years agonftables: retake at ICMPv6 and other stuffs
Julien Moutinho [Sun, 6 Sep 2020 15:43:20 +0000 (17:43 +0200)]
nftables: retake at ICMPv6 and other stuffs

3 years agotor: preparation
Julien Moutinho [Sat, 5 Sep 2020 06:23:00 +0000 (08:23 +0200)]
tor: preparation

3 years agonix: add a GC root for each machine
Julien Moutinho [Fri, 4 Sep 2020 00:47:09 +0000 (02:47 +0200)]
nix: add a GC root for each machine

3 years agonix: update remote patches
Julien Moutinho [Fri, 4 Sep 2020 00:46:34 +0000 (02:46 +0200)]
nix: update remote patches

3 years agonix: rename flakes to inputs
Julien Moutinho [Sun, 30 Aug 2020 00:51:35 +0000 (02:51 +0200)]
nix: rename flakes to inputs

3 years agozfs: allow sending backup from losurdo to mermet
Julien Moutinho [Sat, 29 Aug 2020 01:21:19 +0000 (03:21 +0200)]
zfs: allow sending backup from losurdo to mermet

3 years agonginx: sourcephile.fr: www: fix redirection
Julien Moutinho [Sat, 29 Aug 2020 00:58:56 +0000 (02:58 +0200)]
nginx: sourcephile.fr: www: fix redirection

3 years agozfs: increase zfs_arc_max to 1.5G
Julien Moutinho [Sat, 29 Aug 2020 00:53:05 +0000 (02:53 +0200)]
zfs: increase zfs_arc_max to 1.5G

3 years agonix: polish shell exports
Julien Moutinho [Thu, 27 Aug 2020 20:39:29 +0000 (22:39 +0200)]
nix: polish shell exports

3 years agonix: re-add smartctl-tbw to the environment
Julien Moutinho [Thu, 27 Aug 2020 16:33:58 +0000 (18:33 +0200)]
nix: re-add smartctl-tbw to the environment

3 years agosyncoid: use a dedicated backup user
Julien Moutinho [Thu, 27 Aug 2020 08:19:14 +0000 (10:19 +0200)]
syncoid: use a dedicated backup user

3 years agonix: fix minor things
Julien Moutinho [Thu, 27 Aug 2020 04:39:30 +0000 (06:39 +0200)]
nix: fix minor things

3 years agonix: polish flake.nix
Julien Moutinho [Thu, 27 Aug 2020 04:36:01 +0000 (06:36 +0200)]
nix: polish flake.nix

3 years agonftables: harden input checks on mermet
Julien Moutinho [Thu, 27 Aug 2020 04:32:01 +0000 (06:32 +0200)]
nftables: harden input checks on mermet

3 years agomalloc: disable unstable scudo hardening
Julien Moutinho [Wed, 26 Aug 2020 18:16:59 +0000 (20:16 +0200)]
malloc: disable unstable scudo hardening

3 years agonix: fix PASSWORD_STORE_DIR
Julien Moutinho [Wed, 26 Aug 2020 18:15:44 +0000 (20:15 +0200)]
nix: fix PASSWORD_STORE_DIR

3 years agonftables: harden input checks on losurdo
Julien Moutinho [Wed, 26 Aug 2020 01:23:05 +0000 (03:23 +0200)]
nftables: harden input checks on losurdo

3 years agodoc: explain tributes in naming the machines
Julien Moutinho [Tue, 25 Aug 2020 20:37:18 +0000 (22:37 +0200)]
doc: explain tributes in naming the machines

3 years agonix: disable fix for /etc/ld-nix.so.preload, too much rebuilds
Julien Moutinho [Tue, 25 Aug 2020 20:36:36 +0000 (22:36 +0200)]
nix: disable fix for /etc/ld-nix.so.preload, too much rebuilds

3 years agonix: fix /etc/ld-nix.so.preload sharing
Julien Moutinho [Tue, 25 Aug 2020 13:12:37 +0000 (15:12 +0200)]
nix: fix /etc/ld-nix.so.preload sharing