]>
Git — Sourcephile - sourcephile-nix.git/log
Julien Moutinho [Wed, 15 Jul 2020 00:12:58 +0000 (02:12 +0200)]
systemd: fix reload of services
Julien Moutinho [Wed, 15 Jul 2020 00:11:16 +0000 (02:11 +0200)]
transmission: fix and improve the hardening
Julien Moutinho [Fri, 10 Jul 2020 07:26:44 +0000 (09:26 +0200)]
transmission: fix umask
Julien Moutinho [Fri, 10 Jul 2020 01:21:48 +0000 (03:21 +0200)]
nginx: install on losurdo
Julien Moutinho [Thu, 9 Jul 2020 22:31:11 +0000 (00:31 +0200)]
sanoid: add missing cleanup of remote backups
Julien Moutinho [Thu, 9 Jul 2020 02:34:44 +0000 (04:34 +0200)]
sanoid: cleanup
Julien Moutinho [Wed, 8 Jul 2020 23:59:09 +0000 (01:59 +0200)]
postgresql: add openconcerto database labascule
Julien Moutinho [Wed, 8 Jul 2020 17:23:36 +0000 (19:23 +0200)]
initrd: fix SSH host key location
Julien Moutinho [Tue, 7 Jul 2020 15:03:21 +0000 (17:03 +0200)]
fail2ban: update whitelist
Julien Moutinho [Tue, 7 Jul 2020 15:02:53 +0000 (17:02 +0200)]
kernel: set only vm.swappiness=10
Julien Moutinho [Tue, 7 Jul 2020 13:25:24 +0000 (15:25 +0200)]
nix: upgrade to latests nixos-unstable-small, fix boot.initrd.network.ssh.hostKeys
Julien Moutinho [Tue, 7 Jul 2020 01:50:09 +0000 (03:50 +0200)]
postgresql: allow pg_dump and tune for ZFS
Julien Moutinho [Wed, 1 Jul 2020 13:40:58 +0000 (15:40 +0200)]
transmission: improve the service
Julien Moutinho [Mon, 29 Jun 2020 02:06:50 +0000 (04:06 +0200)]
nix: add julm to some meta.maintainers
Julien Moutinho [Mon, 29 Jun 2020 01:56:48 +0000 (03:56 +0200)]
transmission: improve the service module
Julien Moutinho [Fri, 26 Jun 2020 18:22:52 +0000 (20:22 +0200)]
nix: update to latest nixos-unstable-small
Julien Moutinho [Thu, 25 Jun 2020 17:07:22 +0000 (19:07 +0200)]
dovecot: silence error revealed by scudo, by disabling scudo
Julien Moutinho [Wed, 24 Jun 2020 23:16:36 +0000 (01:16 +0200)]
fail2ban: reduce findtime to reduce RAM footprint and startup time
Julien Moutinho [Wed, 24 Jun 2020 22:46:50 +0000 (00:46 +0200)]
fail2ban: enable on mermet too
Julien Moutinho [Wed, 24 Jun 2020 22:36:12 +0000 (00:36 +0200)]
nix: use the hardened profile on mermet too
Julien Moutinho [Wed, 24 Jun 2020 22:18:43 +0000 (00:18 +0200)]
nftables: replace shorewall on mermet too
Julien Moutinho [Wed, 24 Jun 2020 20:45:26 +0000 (22:45 +0200)]
rspamd: use --no-block to avoid deadlocking services
Julien Moutinho [Wed, 24 Jun 2020 18:50:04 +0000 (20:50 +0200)]
nix: deploy security.pass to mermet too
Julien Moutinho [Wed, 24 Jun 2020 16:52:55 +0000 (18:52 +0200)]
nix: security.pass re-add convenient postStart
Julien Moutinho [Wed, 24 Jun 2020 16:09:51 +0000 (18:09 +0200)]
gnupg: create remaining servers' key
Julien Moutinho [Wed, 24 Jun 2020 15:52:30 +0000 (17:52 +0200)]
nix: rename install to install.ssh-nixos
Julien Moutinho [Wed, 24 Jun 2020 15:08:06 +0000 (17:08 +0200)]
nix: fix install and security.pass
Julien Moutinho [Wed, 24 Jun 2020 01:36:55 +0000 (03:36 +0200)]
nix: fix security.pass services
Julien Moutinho [Tue, 23 Jun 2020 17:16:49 +0000 (19:16 +0200)]
nix: add module security.pass
Julien Moutinho [Sat, 20 Jun 2020 17:12:04 +0000 (19:12 +0200)]
postgresql: log connections
Julien Moutinho [Sat, 20 Jun 2020 16:20:28 +0000 (18:20 +0200)]
postgresql: fix pg_adduser
Julien Moutinho [Sat, 20 Jun 2020 16:08:12 +0000 (18:08 +0200)]
postgresql: add openconcerto databases lbec and lbm
Julien Moutinho [Sat, 20 Jun 2020 09:19:06 +0000 (11:19 +0200)]
nix: revamp nixos/{base => profiles}/
Julien Moutinho [Fri, 19 Jun 2020 17:45:33 +0000 (19:45 +0200)]
fail2ban: increase findtime to 15d
Julien Moutinho [Fri, 19 Jun 2020 16:59:57 +0000 (18:59 +0200)]
shorewall: remove configs on losurdo
Julien Moutinho [Fri, 19 Jun 2020 16:56:42 +0000 (18:56 +0200)]
fail2ban: enable sshd and postgresql on losurdo
Julien Moutinho [Thu, 18 Jun 2020 03:28:22 +0000 (05:28 +0200)]
nftables: only use unbound for DNS resolving
Julien Moutinho [Thu, 18 Jun 2020 02:46:50 +0000 (04:46 +0200)]
nftables: replace shorewall on losurdo
Julien Moutinho [Wed, 17 Jun 2020 13:40:35 +0000 (15:40 +0200)]
losurdo: enable hardened profile
Julien Moutinho [Wed, 17 Jun 2020 13:39:29 +0000 (15:39 +0200)]
ssh: add mermet to losurdo
Julien Moutinho [Wed, 17 Jun 2020 13:35:54 +0000 (15:35 +0200)]
public-inbox: fix nntpd restart
Julien Moutinho [Sun, 14 Jun 2020 17:23:54 +0000 (19:23 +0200)]
acme: fix propagation timeout
Julien Moutinho [Sun, 14 Jun 2020 17:21:14 +0000 (19:21 +0200)]
networking: fix hostname --fqdn
Julien Moutinho [Sun, 14 Jun 2020 16:48:28 +0000 (18:48 +0200)]
postgresql: lower the allowed connection rate
Julien Moutinho [Fri, 12 Jun 2020 21:41:01 +0000 (23:41 +0200)]
postgresql: install for openconcerto1 database
Julien Moutinho [Fri, 12 Jun 2020 15:16:41 +0000 (17:16 +0200)]
polish code
Julien Moutinho [Fri, 12 Jun 2020 00:35:07 +0000 (02:35 +0200)]
acme: setup on losurdo too
Julien Moutinho [Thu, 11 Jun 2020 15:31:16 +0000 (17:31 +0200)]
public-inbox: fix reloading on X.509 renewal
Julien Moutinho [Wed, 10 Jun 2020 11:59:28 +0000 (13:59 +0200)]
public-inbox: add coderepos
Julien Moutinho [Sat, 6 Jun 2020 13:50:01 +0000 (15:50 +0200)]
sanoid: backup public-inbox
Julien Moutinho [Sat, 6 Jun 2020 12:49:42 +0000 (14:49 +0200)]
zramSwap: enable on mermet too
Julien Moutinho [Sat, 6 Jun 2020 10:34:28 +0000 (12:34 +0200)]
zramSwap: enable on losurdo
Julien Moutinho [Sat, 6 Jun 2020 10:34:07 +0000 (12:34 +0200)]
stig: update to 0.11.0a
Julien Moutinho [Wed, 3 Jun 2020 12:01:12 +0000 (14:01 +0200)]
public-inbox: hide test@sourcephile.fr
Julien Moutinho [Tue, 2 Jun 2020 23:58:35 +0000 (01:58 +0200)]
public-inbox: rename inboxes
Julien Moutinho [Tue, 2 Jun 2020 22:11:33 +0000 (00:11 +0200)]
public-inbox: move to mails.sourcephile.fr
Julien Moutinho [Tue, 2 Jun 2020 21:23:44 +0000 (23:23 +0200)]
public-inbox: fix CSS and environment
Julien Moutinho [Mon, 1 Jun 2020 02:56:18 +0000 (04:56 +0200)]
gitolite: update
Julien Moutinho [Mon, 1 Jun 2020 02:56:08 +0000 (04:56 +0200)]
nginx: sourcephile.fr: www: add location
Julien Moutinho [Mon, 1 Jun 2020 02:54:53 +0000 (04:54 +0200)]
public-inbox: allow (X)HTML mails
Julien Moutinho [Sun, 31 May 2020 01:44:52 +0000 (03:44 +0200)]
public-inbox: remove linky inbox and add more generic inboxes
Julien Moutinho [Sat, 30 May 2020 20:33:16 +0000 (22:33 +0200)]
public-inbox: add linky@public-inbox.sourcephile.fr
Julien Moutinho [Sat, 30 May 2020 20:11:23 +0000 (22:11 +0200)]
nix: revamp directories to put nixpkgs-overlays in the store
Julien Moutinho [Thu, 28 May 2020 14:50:32 +0000 (16:50 +0200)]
public-inbox: NNTP, et version 1.5.0
Julien Moutinho [Wed, 27 May 2020 01:07:46 +0000 (03:07 +0200)]
public-inbox: test sur mermet
Julien Moutinho [Fri, 22 May 2020 18:19:26 +0000 (20:19 +0200)]
nix: enable nix run servers.$server.install
Julien Moutinho [Fri, 22 May 2020 15:29:25 +0000 (17:29 +0200)]
public-inbox: fetch the PR to be tested someday
Julien Moutinho [Fri, 22 May 2020 15:27:27 +0000 (17:27 +0200)]
nix: polish install code
Julien Moutinho [Mon, 18 May 2020 06:32:25 +0000 (08:32 +0200)]
syncoid: fix root access and keep bookmarks to avoid destroying the dataset when there is no common snapshot
Julien Moutinho [Mon, 18 May 2020 03:14:32 +0000 (05:14 +0200)]
nix: rewrite deploy.sh into an install nix attribute
Julien Moutinho [Mon, 18 May 2020 01:40:19 +0000 (03:40 +0200)]
gitolite: update
Julien Moutinho [Mon, 18 May 2020 01:26:04 +0000 (03:26 +0200)]
nginx: fix error_log off no longer working and remove boring indent
Julien Moutinho [Mon, 18 May 2020 01:24:28 +0000 (03:24 +0200)]
nix: polish deployment scripts
Julien Moutinho [Mon, 18 May 2020 00:01:15 +0000 (02:01 +0200)]
nix: replace nixops by shell scripts
Julien Moutinho [Sun, 17 May 2020 22:20:30 +0000 (00:20 +0200)]
nix: deploy without nixops
Julien Moutinho [Sun, 17 May 2020 22:19:49 +0000 (00:19 +0200)]
nix: comment .envrc
Julien Moutinho [Sun, 17 May 2020 02:32:39 +0000 (04:32 +0200)]
nix: remove boring indent
Julien Moutinho [Sun, 17 May 2020 02:28:46 +0000 (04:28 +0200)]
nginx: factorize domain
Julien Moutinho [Sun, 17 May 2020 02:17:47 +0000 (04:17 +0200)]
nix: remove old conf
Julien Moutinho [Sun, 17 May 2020 01:59:08 +0000 (03:59 +0200)]
nix: split configuration.nix into alternative toplevels
Julien Moutinho [Sun, 17 May 2020 01:55:02 +0000 (03:55 +0200)]
acme: fix reloading of services, using postRun
Julien Moutinho [Fri, 15 May 2020 20:15:25 +0000 (22:15 +0200)]
gnupg: remove use-tor for now
Julien Moutinho [Fri, 15 May 2020 01:53:46 +0000 (03:53 +0200)]
nix: add tests.nix
Julien Moutinho [Thu, 14 May 2020 15:52:57 +0000 (17:52 +0200)]
nix: add default.nix for debugging builds
Julien Moutinho [Thu, 14 May 2020 12:44:36 +0000 (14:44 +0200)]
nix: remove old comment
Julien Moutinho [Thu, 14 May 2020 12:44:13 +0000 (14:44 +0200)]
dovecot: fix list.sieve
Julien Moutinho [Thu, 14 May 2020 12:42:55 +0000 (14:42 +0200)]
openldap: fix julm by using groups.users
Julien Moutinho [Thu, 14 May 2020 12:26:21 +0000 (14:26 +0200)]
nix: fix nixpkgs-overlays=
Julien Moutinho [Sat, 9 May 2020 12:27:46 +0000 (14:27 +0200)]
dovecot: update fts_xapian
Julien Moutinho [Thu, 7 May 2020 01:34:24 +0000 (03:34 +0200)]
nix: add members/*.nix
Julien Moutinho [Sun, 3 May 2020 15:23:16 +0000 (17:23 +0200)]
dovecot: sieve: fix List-Id filter with 3 components
Julien Moutinho [Wed, 29 Apr 2020 12:01:28 +0000 (14:01 +0200)]
openldap: no SHA2 anor PBKDF2 password modules by default
Julien Moutinho [Tue, 28 Apr 2020 14:34:58 +0000 (16:34 +0200)]
nix: remove upstreamed PR patches
Julien Moutinho [Tue, 28 Apr 2020 14:32:13 +0000 (16:32 +0200)]
sanoid: update PR#83904
Julien Moutinho [Sun, 26 Apr 2020 13:20:28 +0000 (15:20 +0200)]
knot: add whoami4.sourcephile.fr
Julien Moutinho [Sun, 26 Apr 2020 05:28:29 +0000 (07:28 +0200)]
backup: mermet: ~julm/log/
Julien Moutinho [Fri, 17 Apr 2020 14:21:24 +0000 (16:21 +0200)]
nix: update to latest nixos-unstable-small channel
Julien Moutinho [Fri, 17 Apr 2020 14:20:29 +0000 (16:20 +0200)]
losurdo: add transmission
Julien Moutinho [Sat, 11 Apr 2020 02:08:13 +0000 (04:08 +0200)]
nginx: covid19: fix access_log
Julien Moutinho [Sat, 11 Apr 2020 01:39:22 +0000 (03:39 +0200)]
shorewall: allow Whois queries