Compare commits
8
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4e8d983ba9 | ||
|
|
dc5f3fda2e | ||
|
|
e0a0ddc624 | ||
|
|
f6257fdcd2 | ||
|
|
681fc0f781 | ||
|
|
0aeebb5d98 | ||
|
|
e2a4506f94 | ||
|
|
9a46b316df |
@@ -2,14 +2,15 @@ name: Check
|
|||||||
on: [push]
|
on: [push]
|
||||||
jobs:
|
jobs:
|
||||||
"Lint Ansible Files":
|
"Lint Ansible Files":
|
||||||
runs-on: ubuntu-22.04
|
runs-on: node-22-bookworm
|
||||||
steps:
|
steps:
|
||||||
- run: apt-get update
|
- run: apt-get update
|
||||||
|
- run: apt-get upgrade -y
|
||||||
- run: apt-get install -y python3 python3-pip python3-venv
|
- run: apt-get install -y python3 python3-pip python3-venv
|
||||||
- run: python3 --version
|
- run: python3 --version
|
||||||
- name: Check out repo
|
- name: Check out repo
|
||||||
uses: actions/checkout@v3
|
uses: actions/checkout@v3
|
||||||
- run: python3 -m venv venv
|
- run: python3 -m venv venv
|
||||||
- run: venv/bin/pip --disable-pip-version-check install ansible==7.2.0 ansible-lint==6.16.1 > /dev/null 2> /dev/null
|
- run: venv/bin/pip --disable-pip-version-check install ansible==9.6.0 ansible-lint==24.2.2
|
||||||
- run: venv/bin/ansible-lint -c .ansible-lint ansible
|
- run: venv/bin/ansible-lint -c .ansible-lint ansible
|
||||||
# TODO: Reimplement ansible-play --check step from old drone config
|
# TODO: Reimplement ansible-play --check step from old drone config
|
||||||
|
|||||||
@@ -17,3 +17,7 @@ ansible-lint --offline
|
|||||||
```
|
```
|
||||||
|
|
||||||
to avoid checking for a new version every single run.
|
to avoid checking for a new version every single run.
|
||||||
|
|
||||||
|
## TODO
|
||||||
|
|
||||||
|
- [ ] Migrate to `community.docker.docker_compose_v2` (`v1` is deprecated)
|
||||||
|
|||||||
@@ -17,9 +17,6 @@
|
|||||||
- name: gitea
|
- name: gitea
|
||||||
uid: 42001
|
uid: 42001
|
||||||
state: present
|
state: present
|
||||||
- name: score
|
|
||||||
uid: 42003
|
|
||||||
state: present
|
|
||||||
- name: factorio
|
- name: factorio
|
||||||
uid: 845
|
uid: 845
|
||||||
state: present
|
state: present
|
||||||
@@ -33,6 +30,9 @@
|
|||||||
- name: bsa
|
- name: bsa
|
||||||
uid: 42002
|
uid: 42002
|
||||||
state: absent
|
state: absent
|
||||||
|
- name: score
|
||||||
|
uid: 42003
|
||||||
|
state: absent
|
||||||
# All services that are behind Caddy need to be in this network
|
# All services that are behind Caddy need to be in this network
|
||||||
- name: Create Caddy network
|
- name: Create Caddy network
|
||||||
become: true
|
become: true
|
||||||
@@ -68,6 +68,8 @@
|
|||||||
state: present
|
state: present
|
||||||
- name: gitea
|
- name: gitea
|
||||||
state: present
|
state: present
|
||||||
|
- name: vrnp
|
||||||
|
state: present
|
||||||
- name: Create directory for docker volumes
|
- name: Create directory for docker volumes
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
@@ -96,11 +98,11 @@
|
|||||||
owner: factorio
|
owner: factorio
|
||||||
group: factorio
|
group: factorio
|
||||||
mode: u=rwx,g=,o=
|
mode: u=rwx,g=,o=
|
||||||
- name: Create score data folder
|
- name: Delete score data folder
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: /var/lib/pbri/docker/score
|
path: /var/lib/pbri/docker/score
|
||||||
state: directory
|
state: absent
|
||||||
owner: score
|
owner: score
|
||||||
group: score
|
group: score
|
||||||
mode: u=rwx,g=,o=
|
mode: u=rwx,g=,o=
|
||||||
@@ -109,11 +111,11 @@
|
|||||||
# that Gitea is reachable before those configurations are deployed.
|
# that Gitea is reachable before those configurations are deployed.
|
||||||
- name: Set up caddy and gitea containers
|
- name: Set up caddy and gitea containers
|
||||||
become: true
|
become: true
|
||||||
community.docker.docker_compose:
|
community.docker.docker_compose_v2:
|
||||||
project_src: "/etc/pbri/docker/{{ item.name }}"
|
project_src: "/etc/pbri/docker/{{ item.name }}"
|
||||||
state: "{{ item.state }}"
|
state: "{{ item.state }}"
|
||||||
build: true
|
build: "always"
|
||||||
debug: true
|
pull: "always"
|
||||||
loop:
|
loop:
|
||||||
- name: caddy
|
- name: caddy
|
||||||
state: present
|
state: present
|
||||||
@@ -132,11 +134,11 @@
|
|||||||
delay: 5 # Retry every 5 seconds
|
delay: 5 # Retry every 5 seconds
|
||||||
- name: Set up other containers
|
- name: Set up other containers
|
||||||
become: true
|
become: true
|
||||||
community.docker.docker_compose:
|
community.docker.docker_compose_v2:
|
||||||
project_src: "/etc/pbri/docker/{{ item.name }}"
|
project_src: "/etc/pbri/docker/{{ item.name }}"
|
||||||
state: "{{ item.state }}"
|
state: "{{ item.state }}"
|
||||||
build: true
|
build: "always"
|
||||||
debug: true
|
pull: "always"
|
||||||
loop:
|
loop:
|
||||||
- name: drone
|
- name: drone
|
||||||
state: present
|
state: present
|
||||||
@@ -146,10 +148,13 @@
|
|||||||
state: present
|
state: present
|
||||||
- name: utoy
|
- name: utoy
|
||||||
state: present
|
state: present
|
||||||
- name: score
|
- name: vrnp
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
|
# Keep these to ensure they're down
|
||||||
- name: factorio
|
- name: factorio
|
||||||
state: absent
|
state: absent
|
||||||
- name: glebby
|
- name: glebby
|
||||||
state: absent
|
state: absent
|
||||||
|
- name: score
|
||||||
|
state: absent
|
||||||
|
|||||||
@@ -6,11 +6,11 @@
|
|||||||
ansible.builtin.include_role:
|
ansible.builtin.include_role:
|
||||||
name: checkout_static_sites
|
name: checkout_static_sites
|
||||||
vars:
|
vars:
|
||||||
checkout_static_sites:
|
checkout_static_sites_config:
|
||||||
checkouts:
|
checkouts:
|
||||||
- path: /home/paul/Sites/pbrinkmeier.de
|
- path: /home/paul/Sites/pbrinkmeier.de
|
||||||
url: https://git.pbrinkmeier.de/paul/pbrinkmeier.de
|
url: https://git.pbrinkmeier.de/paul/pbrinkmeier.de
|
||||||
commit: 680ac7d9c44752f57436d0ecb9c8018205a5fc0f
|
commit: bab3208e61972851a5e609930a05e0d4322f8a06
|
||||||
owner: paul
|
owner: paul
|
||||||
- path: /home/paul/Sites/tichy.click
|
- path: /home/paul/Sites/tichy.click
|
||||||
url: https://github.com/pbrinkmeier/tichy-clicker
|
url: https://github.com/pbrinkmeier/tichy-clicker
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
mode: '0755'
|
mode: '0755'
|
||||||
owner: "{{ item.owner }}"
|
owner: "{{ item.owner }}"
|
||||||
group: "{{ item.owner }}"
|
group: "{{ item.owner }}"
|
||||||
loop: "{{ checkout_static_sites.checkouts }}"
|
loop: "{{ checkout_static_sites_config.checkouts }}"
|
||||||
- name: Check out static site repositories
|
- name: Check out static site repositories
|
||||||
become: true
|
become: true
|
||||||
become_user: "{{ item.owner }}"
|
become_user: "{{ item.owner }}"
|
||||||
@@ -15,4 +15,5 @@
|
|||||||
dest: "{{ item.path }}"
|
dest: "{{ item.path }}"
|
||||||
repo: "{{ item.url }}"
|
repo: "{{ item.url }}"
|
||||||
version: "{{ item.commit }}"
|
version: "{{ item.commit }}"
|
||||||
loop: "{{ checkout_static_sites.checkouts }}"
|
force: true
|
||||||
|
loop: "{{ checkout_static_sites_config.checkouts }}"
|
||||||
|
|||||||
@@ -45,6 +45,6 @@ utoy.beany.club {
|
|||||||
reverse_proxy utoy:3000
|
reverse_proxy utoy:3000
|
||||||
}
|
}
|
||||||
|
|
||||||
score.brocke.net {
|
vrnp.beany.club {
|
||||||
reverse_proxy score:8080
|
reverse_proxy vrnp:8000
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,5 +1,3 @@
|
|||||||
version: "3"
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
# Webserver for static files and reverse proxy
|
# Webserver for static files and reverse proxy
|
||||||
web:
|
web:
|
||||||
|
|||||||
@@ -1,8 +1,6 @@
|
|||||||
version: "3"
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
codi:
|
codi:
|
||||||
image: hackmdio/hackmd:2.4.2
|
image: hackmdio/hackmd:2.5.4
|
||||||
user: hackmd
|
user: hackmd
|
||||||
environment:
|
environment:
|
||||||
# Admin stuff
|
# Admin stuff
|
||||||
|
|||||||
@@ -1,5 +1,3 @@
|
|||||||
version: "3"
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
drone:
|
drone:
|
||||||
image: drone/drone:2
|
image: drone/drone:2
|
||||||
|
|||||||
@@ -1,5 +1,3 @@
|
|||||||
version: "3"
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
gitea:
|
gitea:
|
||||||
image: pbrinkmeier/factorio
|
image: pbrinkmeier/factorio
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
FROM gitea/act_runner:0.2.5
|
FROM gitea/act_runner:0.2.10
|
||||||
|
|
||||||
COPY runner-config.yaml /opt/runner-config.yaml
|
COPY runner-config.yaml /opt/runner-config.yaml
|
||||||
|
|||||||
@@ -1,8 +1,6 @@
|
|||||||
version: "3"
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
gitea:
|
gitea:
|
||||||
image: gitea/gitea:1.20.3
|
image: gitea/gitea:1.21.11
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
# Ref: https://docs.gitea.io/en-us/config-cheat-sheet
|
# Ref: https://docs.gitea.io/en-us/config-cheat-sheet
|
||||||
@@ -66,7 +64,7 @@ services:
|
|||||||
- /var/lib/pbri/docker/gitea_db:/var/lib/postgresql/data
|
- /var/lib/pbri/docker/gitea_db:/var/lib/postgresql/data
|
||||||
|
|
||||||
gitea_runner:
|
gitea_runner:
|
||||||
image: pbrinkmeier/act_runner:0.2.5
|
image: pbrinkmeier/act_runner:0.2.10
|
||||||
build: .
|
build: .
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
environment:
|
environment:
|
||||||
|
|||||||
@@ -32,6 +32,8 @@ runner:
|
|||||||
# ubuntu:22.04 here is not enough.
|
# ubuntu:22.04 here is not enough.
|
||||||
labels:
|
labels:
|
||||||
- "ubuntu-22.04:docker://node:16-bullseye"
|
- "ubuntu-22.04:docker://node:16-bullseye"
|
||||||
|
- "node-22-bullseye:docker://node:22-bullseye"
|
||||||
|
- "node-22-bookworm:docker://node:22-bookworm"
|
||||||
|
|
||||||
cache:
|
cache:
|
||||||
# Enable cache server to use actions/cache.
|
# Enable cache server to use actions/cache.
|
||||||
|
|||||||
@@ -1,5 +1,3 @@
|
|||||||
version: "3"
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
glebby:
|
glebby:
|
||||||
image: git.pbrinkmeier.de/paul/glebby:1.1-prod
|
image: git.pbrinkmeier.de/paul/glebby:1.1-prod
|
||||||
|
|||||||
@@ -1,5 +1,3 @@
|
|||||||
version: "3"
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
jupyter:
|
jupyter:
|
||||||
image: git.pbrinkmeier.de/paul/jup:1.5
|
image: git.pbrinkmeier.de/paul/jup:1.5
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
# score
|
||||||
|
|
||||||
|
Seems to not be maintained anymore.
|
||||||
@@ -1,5 +1,3 @@
|
|||||||
version: "3"
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
score:
|
score:
|
||||||
image: ghcr.io/lbrocke/score:v1.0.2
|
image: ghcr.io/lbrocke/score:v1.0.2
|
||||||
|
|||||||
@@ -1,5 +1,3 @@
|
|||||||
version: "3"
|
|
||||||
|
|
||||||
services:
|
services:
|
||||||
utoy:
|
utoy:
|
||||||
image: git.pbrinkmeier.de/paul/utoy:0.6
|
image: git.pbrinkmeier.de/paul/utoy:0.6
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
services:
|
||||||
|
vrnp:
|
||||||
|
image: git.pbrinkmeier.de/paul/vrnp:0.0.3
|
||||||
|
restart: always
|
||||||
|
environment:
|
||||||
|
VRNP_PASSWORD: "${VRNP_PASSWORD}"
|
||||||
|
|
||||||
|
networks:
|
||||||
|
default:
|
||||||
|
name: caddy-network
|
||||||
|
external: true
|
||||||
+13
-13
@@ -1,14 +1,14 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
35623364633833623964623536646534373634663736613561333561343136333965306638396532
|
30626565616334613665623138613533653739333038643530636633393264393334373563326631
|
||||||
6162393239383936386338666565306132646230383066630a336337613636383431623738343663
|
3838333663306537326534333666316539383038363236650a613163643433653466666639666366
|
||||||
61343262363631376665383035323139313863626331666439336134613035663439376231343863
|
33653861613638653862393338386334643332633762666136613932343834333162303363373030
|
||||||
3032353139643138640a383365356630323835383538393734643134343133653033383663333464
|
6161323863316134340a646532386537313164643039353435633535363061616363363337663365
|
||||||
62386361633435633664306531623835353665326432393932336163316561653866343137323030
|
39343461356631383062353837383034653430373663323966373632323063636132613137643662
|
||||||
63643262323436356166373533363235366238393633336631336266373837373932313134303563
|
37373065313764626539396463376637353136613365366566363436356537343932376565633962
|
||||||
65633337393938623134636538653561356565333831356638373862376333336163363438626438
|
62316631663634316530623736613961623635303763633964386433333531626437303136363537
|
||||||
39343436383732313561396236656530303064363961663636353538346264633532633866333162
|
35393134643935316330396161303134626537643162393062636363376435636162393136373034
|
||||||
35303032303662646166333537373566316462633536333463323433353539623363323036643763
|
39636231626635643530313634333464653564353861656666633035623932336234303735386366
|
||||||
34376365613932303133366236613235636238643139666663356436326532616437383432303437
|
62303133326237613763336435323338623036663137333439613462333434303734303737363936
|
||||||
39376535656266383465373837643634383937656431323265386163373138336164383666383962
|
65333762376233396332633434353832373136383137336665623534356538636166303835376334
|
||||||
64623762613332363731323739666238613634646237396331666463363663313461313966356233
|
64346139656432633230386666653531333864333664393936366630346334323963343431346164
|
||||||
30653362353061333739303234336461373337346632646433623462623765353330
|
64376165666230386464303036303861653437646463633764343064376464396135
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
|
36643163613366383136326339346231373533373361633834663332343932356665303434333564
|
||||||
|
3936636366396233326664636137363134643066303432380a363662646465656130303431386530
|
||||||
|
37316138366239313038336664313661333632393333666539363565623032653431623935613631
|
||||||
|
3635323330363663610a353263663736653561666261636138336438666261613739346664393233
|
||||||
|
32323364346665633662663266626436343831386565663761393237346637376438613865363663
|
||||||
|
36613035376638653937633866613935343834633431393830303438363265656337343565323063
|
||||||
|
36303033323537666236633037656236656133396431326362303462353237326162626335363761
|
||||||
|
36636362306232333630613464393135383539666632343038393333353462336238663130326166
|
||||||
|
3061
|
||||||
Generated
+7
-87
@@ -1,57 +1,15 @@
|
|||||||
{
|
{
|
||||||
"nodes": {
|
"nodes": {
|
||||||
"agenix": {
|
|
||||||
"inputs": {
|
|
||||||
"darwin": "darwin",
|
|
||||||
"home-manager": "home-manager",
|
|
||||||
"nixpkgs": "nixpkgs"
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1696775529,
|
|
||||||
"narHash": "sha256-TYlE4B0ktPtlJJF9IFxTWrEeq+XKG8Ny0gc2FGEAdj0=",
|
|
||||||
"owner": "ryantm",
|
|
||||||
"repo": "agenix",
|
|
||||||
"rev": "daf42cb35b2dc614d1551e37f96406e4c4a2d3e4",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "ryantm",
|
|
||||||
"repo": "agenix",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"darwin": {
|
|
||||||
"inputs": {
|
|
||||||
"nixpkgs": [
|
|
||||||
"agenix",
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1673295039,
|
|
||||||
"narHash": "sha256-AsdYgE8/GPwcelGgrntlijMg4t3hLFJFCRF3tL5WVjA=",
|
|
||||||
"owner": "lnl7",
|
|
||||||
"repo": "nix-darwin",
|
|
||||||
"rev": "87b9d090ad39b25b2400029c64825fc2a8868943",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "lnl7",
|
|
||||||
"ref": "master",
|
|
||||||
"repo": "nix-darwin",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"flake-utils": {
|
"flake-utils": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"systems": "systems"
|
"systems": "systems"
|
||||||
},
|
},
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1685518550,
|
"lastModified": 1710146030,
|
||||||
"narHash": "sha256-o2d0KcvaXzTrPRIo0kOLV0/QXHhDQ5DTi+OxcjO8xqY=",
|
"narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=",
|
||||||
"owner": "numtide",
|
"owner": "numtide",
|
||||||
"repo": "flake-utils",
|
"repo": "flake-utils",
|
||||||
"rev": "a1720a10a6cfe8234c0e93907ffe81be440f4cef",
|
"rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -60,50 +18,13 @@
|
|||||||
"type": "github"
|
"type": "github"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"home-manager": {
|
|
||||||
"inputs": {
|
|
||||||
"nixpkgs": [
|
|
||||||
"agenix",
|
|
||||||
"nixpkgs"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1682203081,
|
|
||||||
"narHash": "sha256-kRL4ejWDhi0zph/FpebFYhzqlOBrk0Pl3dzGEKSAlEw=",
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "home-manager",
|
|
||||||
"rev": "32d3e39c491e2f91152c84f8ad8b003420eab0a1",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "nix-community",
|
|
||||||
"repo": "home-manager",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs": {
|
"nixpkgs": {
|
||||||
"locked": {
|
"locked": {
|
||||||
"lastModified": 1677676435,
|
"lastModified": 1719936093,
|
||||||
"narHash": "sha256-6FxdcmQr5JeZqsQvfinIMr0XcTyTuR7EXX0H3ANShpQ=",
|
"narHash": "sha256-oe5wiTSfxeDLisswomHcMGMV01hkBGuCJyMzjqCDdPY=",
|
||||||
"owner": "NixOS",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"rev": "a08d6979dd7c82c4cef0dcc6ac45ab16051c1169",
|
|
||||||
"type": "github"
|
|
||||||
},
|
|
||||||
"original": {
|
|
||||||
"owner": "NixOS",
|
|
||||||
"ref": "nixos-unstable",
|
|
||||||
"repo": "nixpkgs",
|
|
||||||
"type": "github"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"nixpkgs_2": {
|
|
||||||
"locked": {
|
|
||||||
"lastModified": 1686259070,
|
|
||||||
"narHash": "sha256-bJ2TqJHMdU27o3+AlYzsDooUzneFHwvK5LaRv5JYit4=",
|
|
||||||
"owner": "nixos",
|
"owner": "nixos",
|
||||||
"repo": "nixpkgs",
|
"repo": "nixpkgs",
|
||||||
"rev": "8a7d5c039cacc83bd1926aaabc04d541e04a1460",
|
"rev": "f593f9129f3cbf39261a8bbc86f6b4ceb4624881",
|
||||||
"type": "github"
|
"type": "github"
|
||||||
},
|
},
|
||||||
"original": {
|
"original": {
|
||||||
@@ -114,9 +35,8 @@
|
|||||||
},
|
},
|
||||||
"root": {
|
"root": {
|
||||||
"inputs": {
|
"inputs": {
|
||||||
"agenix": "agenix",
|
|
||||||
"flake-utils": "flake-utils",
|
"flake-utils": "flake-utils",
|
||||||
"nixpkgs": "nixpkgs_2"
|
"nixpkgs": "nixpkgs"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"systems": {
|
"systems": {
|
||||||
|
|||||||
@@ -5,10 +5,9 @@
|
|||||||
# lib
|
# lib
|
||||||
nixpkgs.url = github:nixos/nixpkgs;
|
nixpkgs.url = github:nixos/nixpkgs;
|
||||||
flake-utils.url = github:numtide/flake-utils;
|
flake-utils.url = github:numtide/flake-utils;
|
||||||
agenix.url = github:ryantm/agenix;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
outputs = { self, nixpkgs, flake-utils, agenix }: flake-utils.lib.eachDefaultSystem (system:
|
outputs = { self, nixpkgs, flake-utils }: flake-utils.lib.eachDefaultSystem (system:
|
||||||
let
|
let
|
||||||
pkgs = nixpkgs.legacyPackages.${system};
|
pkgs = nixpkgs.legacyPackages.${system};
|
||||||
in
|
in
|
||||||
@@ -17,7 +16,6 @@
|
|||||||
buildInputs = [
|
buildInputs = [
|
||||||
pkgs.ansible
|
pkgs.ansible
|
||||||
pkgs.ansible-lint
|
pkgs.ansible-lint
|
||||||
agenix.packages.${system}.default
|
|
||||||
];
|
];
|
||||||
|
|
||||||
shellHook = ''
|
shellHook = ''
|
||||||
|
|||||||
@@ -1,12 +0,0 @@
|
|||||||
# `gilgamesh`
|
|
||||||
|
|
||||||
> Old Thinkpad running a Minecraft server.
|
|
||||||
|
|
||||||
## TODO
|
|
||||||
|
|
||||||
- Figure out if there's some more powersaving options
|
|
||||||
- Add some doc for initial setup
|
|
||||||
- Install NixOS according to the official guide
|
|
||||||
- Check out this repo, build this `configuration.nix`
|
|
||||||
- Afterwards: Just build it locally then deploy
|
|
||||||
- Use Flakes, add doc for `./deploy.sh`
|
|
||||||
@@ -1,146 +0,0 @@
|
|||||||
{ config, pkgs, lib, ... }:
|
|
||||||
let
|
|
||||||
agenix = builtins.fetchTarball {
|
|
||||||
url = "https://github.com/ryantm/agenix/archive/daf42cb35b2dc614d1551e37f96406e4c4a2d3e4.tar.gz";
|
|
||||||
sha256 = "0gbn01hi8dh7s9rc66yawnmixcasadf20zci4ijzpd143ph492ad";
|
|
||||||
};
|
|
||||||
in {
|
|
||||||
imports =
|
|
||||||
[ # Include the results of the hardware scan.
|
|
||||||
./hardware-configuration.nix
|
|
||||||
"${agenix}/modules/age.nix"
|
|
||||||
../modules/spigot-server.nix
|
|
||||||
../modules/ionos-dyndns.nix
|
|
||||||
];
|
|
||||||
|
|
||||||
# Use the GRUB 2 boot loader.
|
|
||||||
boot.loader.grub.enable = true;
|
|
||||||
# boot.loader.grub.efiSupport = true;
|
|
||||||
# boot.loader.grub.efiInstallAsRemovable = true;
|
|
||||||
# boot.loader.efi.efiSysMountPoint = "/boot/efi";
|
|
||||||
# Define on which hard drive you want to install Grub.
|
|
||||||
boot.loader.grub.device = "/dev/sda";
|
|
||||||
|
|
||||||
networking.hostName = "gilgamesh"; # Define your hostname.
|
|
||||||
# Pick only one of the below networking options.
|
|
||||||
# networking.wireless.enable = true; # Enables wireless support via wpa_supplicant.
|
|
||||||
# networking.networkmanager.enable = true; # Easiest to use and most distros use this by default.
|
|
||||||
|
|
||||||
# Set your time zone.
|
|
||||||
time.timeZone = "Europe/Berlin";
|
|
||||||
|
|
||||||
# Configure network proxy if necessary
|
|
||||||
# networking.proxy.default = "http://user:password@proxy:port/";
|
|
||||||
# networking.proxy.noProxy = "127.0.0.1,localhost,internal.domain";
|
|
||||||
|
|
||||||
# Select internationalisation properties.
|
|
||||||
i18n.defaultLocale = "en_US.UTF-8";
|
|
||||||
console = {
|
|
||||||
font = "Lat2-Terminus16";
|
|
||||||
keyMap = "de-latin1";
|
|
||||||
};
|
|
||||||
|
|
||||||
# Define a user account. Don't forget to set a password with ‘passwd’.
|
|
||||||
users.users.paul = {
|
|
||||||
isNormalUser = true;
|
|
||||||
extraGroups = [ "wheel" ]; # Enable ‘sudo’ for the user.
|
|
||||||
openssh.authorizedKeys.keys = [
|
|
||||||
"ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIMFqREiw3EareYXntIrm1/numKDo113zx1WMOFO69LJ paul"
|
|
||||||
];
|
|
||||||
# packages = with pkgs; [];
|
|
||||||
};
|
|
||||||
|
|
||||||
# Users in group wheel may sudo without password
|
|
||||||
security.sudo.wheelNeedsPassword = false;
|
|
||||||
|
|
||||||
# Users in group wheel are special friends of the Nix daemon
|
|
||||||
nix.settings.trusted-users = [
|
|
||||||
"@wheel"
|
|
||||||
];
|
|
||||||
|
|
||||||
# List packages installed in system profile. To search, run:
|
|
||||||
# $ nix search wget
|
|
||||||
environment.systemPackages = with pkgs; [
|
|
||||||
vim
|
|
||||||
tmux
|
|
||||||
bottom
|
|
||||||
(pkgs.callPackage ../packages/ionos-dyndns.nix {})
|
|
||||||
];
|
|
||||||
|
|
||||||
# List services that you want to enable:
|
|
||||||
|
|
||||||
# Enable the OpenSSH daemon.
|
|
||||||
services.openssh = {
|
|
||||||
enable = true;
|
|
||||||
settings = {
|
|
||||||
PasswordAuthentication = false;
|
|
||||||
KbdInteractiveAuthentication = false;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
# Enable Avahi for mDNS (advertise hostname in LAN)
|
|
||||||
services.avahi = {
|
|
||||||
enable = true;
|
|
||||||
nssmdns = true;
|
|
||||||
};
|
|
||||||
|
|
||||||
services.spigot-server = {
|
|
||||||
enable = true;
|
|
||||||
user = "spigot";
|
|
||||||
};
|
|
||||||
|
|
||||||
# Secrets management
|
|
||||||
age.secrets = {
|
|
||||||
ionos-prefix = {
|
|
||||||
file = ../secrets/ionos-prefix.age;
|
|
||||||
owner = "ionos-dyndns";
|
|
||||||
group = "ionos-dyndns";
|
|
||||||
};
|
|
||||||
ionos-secret = {
|
|
||||||
file = ../secrets/ionos-secret.age;
|
|
||||||
owner = "ionos-dyndns";
|
|
||||||
group = "ionos-dyndns";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
# DynDNS stuff. IONOS has a (proprietary?) API for this,
|
|
||||||
# so we're using a Python script from the interwebs :shrug:
|
|
||||||
services.ionos-dyndns = {
|
|
||||||
enable = true;
|
|
||||||
# Must match the user owning the secrets below. See agenix config
|
|
||||||
# above for more details.
|
|
||||||
user = "ionos-dyndns";
|
|
||||||
apiPrefixPath = config.age.secrets.ionos-prefix.path;
|
|
||||||
apiSecretPath = config.age.secrets.ionos-secret.path;
|
|
||||||
aaaa = true;
|
|
||||||
fqdn = "blocks.beany.club";
|
|
||||||
interface = "enp0s25";
|
|
||||||
};
|
|
||||||
|
|
||||||
# Open ports in the firewall.
|
|
||||||
networking.firewall.allowedTCPPorts = [ 25565 ];
|
|
||||||
networking.firewall.allowedUDPPorts = [ 25565 ];
|
|
||||||
# Or disable the firewall altogether.
|
|
||||||
# networking.firewall.enable = false;
|
|
||||||
|
|
||||||
# TODO: Backups
|
|
||||||
|
|
||||||
# Practical hardware options
|
|
||||||
services.logind.lidSwitch = "ignore";
|
|
||||||
powerManagement.cpuFreqGovernor = lib.mkDefault "powersave";
|
|
||||||
|
|
||||||
# Copy the NixOS configuration file and link it from the resulting system
|
|
||||||
# (/run/current-system/configuration.nix). This is useful in case you
|
|
||||||
# accidentally delete configuration.nix.
|
|
||||||
# system.copySystemConfiguration = true;
|
|
||||||
|
|
||||||
# This value determines the NixOS release from which the default
|
|
||||||
# settings for stateful data, like file locations and database versions
|
|
||||||
# on your system were taken. It's perfectly fine and recommended to leave
|
|
||||||
# this value at the release version of the first install of this system.
|
|
||||||
# Before changing this value read the documentation for this option
|
|
||||||
# (e.g. man configuration.nix or on https://nixos.org/nixos/options.html).
|
|
||||||
system.stateVersion = "23.05"; # Did you read the comment?
|
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
#!/usr/bin/env bash
|
|
||||||
|
|
||||||
nixos-rebuild -I nixos-config=configuration.nix --target-host gilgamesh --use-remote-sudo switch
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
# Do not modify this file! It was generated by ‘nixos-generate-config’
|
|
||||||
# and may be overwritten by future invocations. Please make changes
|
|
||||||
# to /etc/nixos/configuration.nix instead.
|
|
||||||
{ config, lib, pkgs, modulesPath, ... }:
|
|
||||||
|
|
||||||
{
|
|
||||||
imports =
|
|
||||||
[ (modulesPath + "/installer/scan/not-detected.nix")
|
|
||||||
];
|
|
||||||
|
|
||||||
boot.initrd.availableKernelModules = [ "ehci_pci" "ahci" "usb_storage" "sd_mod" "sdhci_pci" ];
|
|
||||||
boot.initrd.kernelModules = [ ];
|
|
||||||
boot.kernelModules = [ "kvm-intel" ];
|
|
||||||
boot.extraModulePackages = [ ];
|
|
||||||
|
|
||||||
fileSystems."/" =
|
|
||||||
{ device = "/dev/disk/by-label/NIXROOT";
|
|
||||||
fsType = "ext4";
|
|
||||||
};
|
|
||||||
|
|
||||||
swapDevices = [ ];
|
|
||||||
|
|
||||||
# Enables DHCP on each ethernet and wireless interface. In case of scripted networking
|
|
||||||
# (the default) this is the recommended approach. When using systemd-networkd it's
|
|
||||||
# still possible to use this option, but it's recommended to use it in conjunction
|
|
||||||
# with explicit per-interface declarations with `networking.interfaces.<interface>.useDHCP`.
|
|
||||||
networking.useDHCP = lib.mkDefault true;
|
|
||||||
# networking.interfaces.enp0s25.useDHCP = lib.mkDefault true;
|
|
||||||
# networking.interfaces.wlp3s0.useDHCP = lib.mkDefault true;
|
|
||||||
|
|
||||||
nixpkgs.hostPlatform = lib.mkDefault "x86_64-linux";
|
|
||||||
hardware.cpu.intel.updateMicrocode = lib.mkDefault config.hardware.enableRedistributableFirmware;
|
|
||||||
}
|
|
||||||
@@ -1,118 +0,0 @@
|
|||||||
{ config, lib, pkgs, ... }:
|
|
||||||
with lib;
|
|
||||||
let
|
|
||||||
cfg = config.services.ionos-dyndns;
|
|
||||||
ionos-dyndns = pkgs.callPackage ../packages/ionos-dyndns.nix {};
|
|
||||||
|
|
||||||
command = lib.concatStringsSep " " (
|
|
||||||
[
|
|
||||||
"${ionos-dyndns}/bin/ionos-dyndns"
|
|
||||||
"--api-prefix"
|
|
||||||
"$(cat ${cfg.apiPrefixPath})"
|
|
||||||
"--api-secret"
|
|
||||||
"$(cat ${cfg.apiSecretPath})"
|
|
||||||
"--fqdn"
|
|
||||||
cfg.fqdn
|
|
||||||
"--interface"
|
|
||||||
cfg.interface
|
|
||||||
]
|
|
||||||
++ lib.optionals cfg.a [ "--A" ]
|
|
||||||
++ lib.optionals cfg.aaaa [ "--AAAA" ]
|
|
||||||
);
|
|
||||||
in {
|
|
||||||
options = {
|
|
||||||
services.ionos-dyndns = {
|
|
||||||
enable = mkOption {
|
|
||||||
type = types.bool;
|
|
||||||
default = false;
|
|
||||||
description = ''
|
|
||||||
Whether to turn on the IONOS DynDNS timer.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
user = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
default = "ionos-dyndns";
|
|
||||||
};
|
|
||||||
apiPrefixPath = mkOption {
|
|
||||||
type = types.path;
|
|
||||||
description = ''
|
|
||||||
Path of a file holding the API prefix.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
apiSecretPath = mkOption {
|
|
||||||
type = types.path;
|
|
||||||
description = ''
|
|
||||||
Path of a file holding the API secret.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
a = mkOption {
|
|
||||||
type = types.bool;
|
|
||||||
default = false;
|
|
||||||
description = ''
|
|
||||||
Whether to set the A record (IPv4).
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
aaaa = mkOption {
|
|
||||||
type = types.bool;
|
|
||||||
default = false;
|
|
||||||
description = ''
|
|
||||||
Whether to set the AAAA record (IPv6).
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
fqdn = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
description = ''
|
|
||||||
Fully qualified domain name for this host.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
interface = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
description = ''
|
|
||||||
Interface to get the IP address from.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
interval = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
default = "14min";
|
|
||||||
description = "How often to run the update script in systemd.timers notation.";
|
|
||||||
};
|
|
||||||
serviceName = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
default = "ionos-dyndns";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
config = mkIf cfg.enable {
|
|
||||||
users = {
|
|
||||||
users = {
|
|
||||||
${cfg.user} = {
|
|
||||||
isSystemUser = true;
|
|
||||||
group = cfg.user;
|
|
||||||
description = "IONOS DynDNS user.";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
groups = {
|
|
||||||
${cfg.user} = {
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
systemd = {
|
|
||||||
services.${cfg.serviceName} = {
|
|
||||||
serviceConfig = {
|
|
||||||
Type = "oneshot";
|
|
||||||
User = cfg.user;
|
|
||||||
# We assume that command doesn't contain any single quotes
|
|
||||||
ExecStart = "${pkgs.bash}/bin/bash -c '${command}'";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
timers.${cfg.serviceName} = {
|
|
||||||
wantedBy = [ "timers.target" ];
|
|
||||||
timerConfig = {
|
|
||||||
Unit = "${cfg.serviceName}.service";
|
|
||||||
OnBootSec = "30s";
|
|
||||||
OnActiveSec = cfg.interval;
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1,81 +0,0 @@
|
|||||||
{ config, lib, pkgs, ... }:
|
|
||||||
with lib;
|
|
||||||
let
|
|
||||||
spigot-server = pkgs.callPackage ../packages/spigot-server.nix {};
|
|
||||||
cfg = config.services.spigot-server;
|
|
||||||
StateDirectory = "spigot-server";
|
|
||||||
in {
|
|
||||||
options = {
|
|
||||||
services.spigot-server = {
|
|
||||||
enable = mkOption {
|
|
||||||
type = types.bool;
|
|
||||||
default = false;
|
|
||||||
description = ''
|
|
||||||
Whether to turn on the Spigot Minecraft server.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
|
|
||||||
user = mkOption {
|
|
||||||
type = types.str;
|
|
||||||
default = "spigot-server";
|
|
||||||
description = ''
|
|
||||||
The user account and group that Spigot runs as.
|
|
||||||
'';
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
config = mkIf cfg.enable {
|
|
||||||
users.users = {
|
|
||||||
${cfg.user} = {
|
|
||||||
isSystemUser = true;
|
|
||||||
group = cfg.user;
|
|
||||||
description = "Spigot Minecraft server user";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
users.groups = {
|
|
||||||
${cfg.user} = {
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
systemd = {
|
|
||||||
services.spigot-server = {
|
|
||||||
description = "Spigot Minecraft server";
|
|
||||||
wantedBy = [ "multi-user.target" ];
|
|
||||||
after = [ "network.target" ];
|
|
||||||
serviceConfig = {
|
|
||||||
User = "${cfg.user}";
|
|
||||||
|
|
||||||
Sockets = "spigot-server.socket";
|
|
||||||
StandardInput = "socket";
|
|
||||||
StandardOutput = "journal";
|
|
||||||
StandardError = "journal";
|
|
||||||
|
|
||||||
inherit StateDirectory;
|
|
||||||
WorkingDirectory = "/var/lib/${StateDirectory}";
|
|
||||||
ExecStart = "${spigot-server}/bin/spigot-server -nogui";
|
|
||||||
ExecStop = [
|
|
||||||
"${pkgs.bash}/bin/bash -c '${pkgs.coreutils}/bin/echo save-all > /run/spigot-server.stdin'"
|
|
||||||
"${pkgs.bash}/bin/bash -c '${pkgs.coreutils}/bin/echo stop > /run/spigot-server.stdin'"
|
|
||||||
# Wait for the main process to exit
|
|
||||||
# If we don't do this systemd tries to nudge Java to stop, causing a race condition
|
|
||||||
# that leads to an ungraceful shutdown
|
|
||||||
"${pkgs.coreutils}/bin/echo \"Waiting for \${MAINPID} to exit...\""
|
|
||||||
"${pkgs.bash}/bin/bash -c 'while ${pkgs.coreutils}/bin/kill -s 0 $MAINPID 2>/dev/null; do sleep 0.5; done'"
|
|
||||||
];
|
|
||||||
};
|
|
||||||
};
|
|
||||||
|
|
||||||
sockets.spigot-server = {
|
|
||||||
description = "Spigot Minecraft server socket for commands and stuff";
|
|
||||||
unitConfig = {
|
|
||||||
# Automatically start and stop socket along with the service
|
|
||||||
PartOf = "spigot-server.service";
|
|
||||||
};
|
|
||||||
socketConfig = {
|
|
||||||
ListenFIFO = "/run/spigot-server.stdin";
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
};
|
|
||||||
}
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
spigot-1.20.1.jar
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
# Packages
|
|
||||||
|
|
||||||
## `spigot-server`
|
|
||||||
|
|
||||||
In order to build `spigot-server.nix` you'll need a copy of the Spigot JAR.
|
|
||||||
For licensing reasons I won't check it into Git.
|
|
||||||
Just drop `spigot-${version}.jar` into this folder and change the `version = ` line in `spigot-server.nix` accordingly.
|
|
||||||
|
|
||||||
## TODO
|
|
||||||
|
|
||||||
- Make some more stuff in `spigot-server.nix` configurable
|
|
||||||
@@ -1,37 +0,0 @@
|
|||||||
{
|
|
||||||
fetchFromGitHub,
|
|
||||||
lib,
|
|
||||||
makeWrapper,
|
|
||||||
stdenv,
|
|
||||||
# Runtime Dependencies
|
|
||||||
python3,
|
|
||||||
# grep
|
|
||||||
gnugrep,
|
|
||||||
# ip
|
|
||||||
iproute2,
|
|
||||||
# hostname
|
|
||||||
hostname
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
pythonWithDeps = python3.withPackages (p: [p.requests]);
|
|
||||||
in stdenv.mkDerivation rec {
|
|
||||||
pname = "ionos-dyndns";
|
|
||||||
# Packaging time, not commit time
|
|
||||||
version = "20231118";
|
|
||||||
src = fetchFromGitHub {
|
|
||||||
owner = "lazaroblanc";
|
|
||||||
repo = "IONOS-DynDNS";
|
|
||||||
rev = "6c090ab928ce8d6eaa28b09614995b036ad60027";
|
|
||||||
hash = "sha256-rabDuKuPvzcMltnCSvc5kDjcDhv7sXxbDLWw3/hdSmk=";
|
|
||||||
};
|
|
||||||
|
|
||||||
nativeBuildInputs = [ makeWrapper ];
|
|
||||||
|
|
||||||
buildCommand = ''
|
|
||||||
install -Dm755 $src/ionos_dyndns.py $out/lib/ionos_dyndns.py
|
|
||||||
|
|
||||||
makeWrapper ${pythonWithDeps}/bin/python3 $out/bin/ionos-dyndns \
|
|
||||||
--set PATH ${lib.makeBinPath [ iproute2 gnugrep hostname ]} \
|
|
||||||
--add-flags $out/lib/ionos_dyndns.py
|
|
||||||
'';
|
|
||||||
}
|
|
||||||
@@ -1,26 +0,0 @@
|
|||||||
{
|
|
||||||
makeWrapper,
|
|
||||||
stdenv,
|
|
||||||
# Runtime Dependencies
|
|
||||||
jre
|
|
||||||
}:
|
|
||||||
let
|
|
||||||
# Copied from some forum thread without much thought.
|
|
||||||
# Let's see if they work out.
|
|
||||||
javaFlags = "-Xmx5G -XX:+UseG1GC -XX:+UnlockExperimentalVMOptions -XX:MaxGCPauseMillis=50 -XX:+DisableExplicitGC -XX:TargetSurvivorRatio=90 -XX:G1NewSizePercent=50 -XX:G1MaxNewSizePercent=80 -XX:InitiatingHeapOccupancyPercent=10 -XX:G1MixedGCLiveThresholdPercent=50";
|
|
||||||
in stdenv.mkDerivation rec {
|
|
||||||
pname = "spigot-server";
|
|
||||||
version = "1.20.1";
|
|
||||||
src = ./spigot-${version}.jar;
|
|
||||||
|
|
||||||
nativeBuildInputs = [ makeWrapper ];
|
|
||||||
|
|
||||||
buildCommand = ''
|
|
||||||
install -Dm644 $src $out/lib/spigot-${version}.jar
|
|
||||||
|
|
||||||
makeWrapper ${jre}/bin/java $out/bin/spigot-server \
|
|
||||||
--argv0 spigot-server \
|
|
||||||
--add-flags "${javaFlags}" \
|
|
||||||
--add-flags "-jar $out/lib/spigot-${version}.jar"
|
|
||||||
'';
|
|
||||||
}
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
# secrets
|
|
||||||
|
|
||||||
> Nix configuration secrets managed with [agenix](https://github.com/ryantm/agenix#tutorial).
|
|
||||||
|
|
||||||
Use `nix develop` in the repository root to drop into a shell with `agenix`.
|
|
||||||
|
|
||||||
## Editing files
|
|
||||||
|
|
||||||
```
|
|
||||||
agenix -e <thingamajig.age>
|
|
||||||
```
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
age-encryption.org/v1
|
|
||||||
-> ssh-ed25519 9V3MUQ 7+lohnPlQALVPEGo2LwS2fj5r2RCKaVeEFmi6EYEyCE
|
|
||||||
9U6eAthRVd5ry0ej79FEy3oRG3okJTwY6zSN1u68H1o
|
|
||||||
-> ssh-ed25519 CcM6/g QQX9SsgKkk8YdUPRKj9Tda8mf6qRJ7ywtP6IIpN9fxo
|
|
||||||
3Ml2+1+AQMwr5Lnv84pYOee/s5mzfVdsHRLaUIAKNFk
|
|
||||||
-> i)!b3gaJ-grease 7|bwS ?k2JgF E-G 2HI
|
|
||||||
0mFbZ22lqvLd
|
|
||||||
--- 0+CwYGJlJC7bRbokHSlv+V4JKppBo+/ocfjp2NQBD3Q
|
|
||||||
JDv�8ě ë�¶ÚŤÄ÷8é V/Ă'O”M¸x×é!ȸTÉA7ÍK5#É8©&•Ř-VqČ&}ů]ráÂ
|
|
||||||
Binary file not shown.
@@ -1,10 +0,0 @@
|
|||||||
let
|
|
||||||
# Users
|
|
||||||
paul = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIMFqREiw3EareYXntIrm1/numKDo113zx1WMOFO69LJ";
|
|
||||||
|
|
||||||
# Systems
|
|
||||||
gilgamesh = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPDmLWYK6/4/Fh+wsoiz9+PCHvNcP2/wu2GvfzrqXCGA";
|
|
||||||
in {
|
|
||||||
"ionos-prefix.age".publicKeys = [ paul gilgamesh ];
|
|
||||||
"ionos-secret.age".publicKeys = [ paul gilgamesh ];
|
|
||||||
}
|
|
||||||
Reference in New Issue
Block a user