mirror of
https://github.com/ryan4yin/nix-config.git
synced 2026-08-27 05:44:00 +02:00
* security: make firewall secure-by-default, disable explicitly on servers
Flip the base firewall default to ON so new hosts are protected by default. Servers keep the firewall off (trusted internal LAN, WAN protected at the router) via explicit overrides in modules/nixos/server/{server,server-aarch64}.nix. Behavior-preserving for all 18 current hosts; adds a security-firewall eval test guarding the per-host state.
* test: fix security-firewall eval test to scalar per-host values
* security: enable AppArmor (complain) on all Linux hosts
* security: bind aquamarine metrics exporters to loopback
* security: restrict k3s kubeconfig file mode to 600
* security: disable SSH X11 forwarding on servers, keep on desktops
* security: add conservative systemd hardening to aquamarine services
* docs(apparmor): correct FHS-alias comment (nixpkgs has no broad FHS layer)
nixpkgs only creates /run/current-system, /usr/bin/env and /bin/sh; it does not
provide a broad FHS->store alias tree, so FHS-oriented abstractions are incomplete
on NixOS. They are safe only because the profiles run in complain mode.
* fix(aquamarine): scrape same-host exporters over loopback
The v2ray/postgres/sftpgo exporters were bound to 127.0.0.1 but VictoriaMetrics
scraped them via the host's routable IP, so those scrapes refused connections.
Point the three same-host scrape targets at 127.0.0.1 (VM runs on the same host).
node-exporter keeps the host IP since it binds 0.0.0.0.
* Revert "security: add conservative systemd hardening to aquamarine services"
This reverts commit f9cf99dadb.
Library
This directory contains helper functions used by flake.nix to reduce code duplication and make it
easier to add new machines.
Current Functions
Core System Generators
attrs.nix- Attribute set manipulation utilitiesmacosSystem.nix- macOS configuration generator for nix-darwinnixosSystem.nix- NixOS configuration generatorcolmenaSystem.nix- Remote deployment configuration for colmena
Specialized Module Generators
genK3sAgentModule.nix- K3s agent node configuration generatorgenK3sServerModule.nix- K3s server node configuration generatorgenKubeVirtGuestModule.nix- KubeVirt guest VM configuration generatorgenKubeVirtHostModule.nix- KubeVirt host configuration generator
Entry Point
default.nix- Main entry point that imports all functions and exports them as a single attribute set
Usage
These functions are designed to:
- Generate consistent configurations across different architectures
- Provide type-safe configuration for complex systems
- Enable easy scaling of the infrastructure
- Support both local development and production deployments
Architecture Support
- x86_64-linux: Primary desktop systems
- aarch64-linux: ARM64 Linux systems (Apple Silicon, SBCs)
- aarch64-darwin: Apple Silicon macOS systems